1 /***************************************************************************
2 * Copyright (C) 2013 by Andrey Yurovsky *
3 * Andrey Yurovsky <yurovsky@gmail.com> *
5 * This program is free software; you can redistribute it and/or modify *
6 * it under the terms of the GNU General Public License as published by *
7 * the Free Software Foundation; either version 2 of the License, or *
8 * (at your option) any later version. *
10 * This program is distributed in the hope that it will be useful, *
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
13 * GNU General Public License for more details. *
15 * You should have received a copy of the GNU General Public License *
16 * along with this program. If not, see <http://www.gnu.org/licenses/>. *
17 ***************************************************************************/
24 #include "helper/binarybuffer.h"
26 #include <target/cortex_m.h>
28 #define SAMD_NUM_SECTORS 16
29 #define SAMD_PAGE_SIZE_MAX 1024
31 #define SAMD_FLASH ((uint32_t)0x00000000) /* physical Flash memory */
32 #define SAMD_USER_ROW ((uint32_t)0x00804000) /* User Row of Flash */
33 #define SAMD_PAC1 0x41000000 /* Peripheral Access Control 1 */
34 #define SAMD_DSU 0x41002000 /* Device Service Unit */
35 #define SAMD_NVMCTRL 0x41004000 /* Non-volatile memory controller */
37 #define SAMD_DSU_STATUSA 1 /* DSU status register */
38 #define SAMD_DSU_DID 0x18 /* Device ID register */
40 #define SAMD_NVMCTRL_CTRLA 0x00 /* NVM control A register */
41 #define SAMD_NVMCTRL_CTRLB 0x04 /* NVM control B register */
42 #define SAMD_NVMCTRL_PARAM 0x08 /* NVM parameters register */
43 #define SAMD_NVMCTRL_INTFLAG 0x18 /* NVM Interupt Flag Status & Clear */
44 #define SAMD_NVMCTRL_STATUS 0x18 /* NVM status register */
45 #define SAMD_NVMCTRL_ADDR 0x1C /* NVM address register */
46 #define SAMD_NVMCTRL_LOCK 0x20 /* NVM Lock section register */
48 #define SAMD_CMDEX_KEY 0xA5UL
49 #define SAMD_NVM_CMD(n) ((SAMD_CMDEX_KEY << 8) | (n & 0x7F))
51 /* NVMCTRL commands. See Table 20-4 in 42129F–SAM–10/2013 */
52 #define SAMD_NVM_CMD_ER 0x02 /* Erase Row */
53 #define SAMD_NVM_CMD_WP 0x04 /* Write Page */
54 #define SAMD_NVM_CMD_EAR 0x05 /* Erase Auxilary Row */
55 #define SAMD_NVM_CMD_WAP 0x06 /* Write Auxilary Page */
56 #define SAMD_NVM_CMD_LR 0x40 /* Lock Region */
57 #define SAMD_NVM_CMD_UR 0x41 /* Unlock Region */
58 #define SAMD_NVM_CMD_SPRM 0x42 /* Set Power Reduction Mode */
59 #define SAMD_NVM_CMD_CPRM 0x43 /* Clear Power Reduction Mode */
60 #define SAMD_NVM_CMD_PBC 0x44 /* Page Buffer Clear */
61 #define SAMD_NVM_CMD_SSB 0x45 /* Set Security Bit */
62 #define SAMD_NVM_CMD_INVALL 0x46 /* Invalidate all caches */
65 #define SAMD_NVM_CTRLB_MANW 0x80
67 /* Known identifiers */
68 #define SAMD_PROCESSOR_M0 0x01
69 #define SAMD_FAMILY_D 0x00
70 #define SAMD_FAMILY_L 0x01
71 #define SAMD_FAMILY_C 0x02
72 #define SAMD_SERIES_20 0x00
73 #define SAMD_SERIES_21 0x01
74 #define SAMD_SERIES_22 0x02
75 #define SAMD_SERIES_10 0x02
76 #define SAMD_SERIES_11 0x03
77 #define SAMD_SERIES_09 0x04
79 /* Device ID macros */
80 #define SAMD_GET_PROCESSOR(id) (id >> 28)
81 #define SAMD_GET_FAMILY(id) (((id >> 23) & 0x1F))
82 #define SAMD_GET_SERIES(id) (((id >> 16) & 0x3F))
83 #define SAMD_GET_DEVSEL(id) (id & 0xFF)
92 /* Known SAMD09 parts. DID reset values missing in RM, see
93 * https://github.com/avrxml/asf/blob/master/sam0/utils/cmsis/samd09/include/ */
94 static const struct samd_part samd09_parts[] = {
95 { 0x0, "SAMD09D14A", 16, 4 },
96 { 0x7, "SAMD09C13A", 8, 4 },
99 /* Known SAMD10 parts */
100 static const struct samd_part samd10_parts[] = {
101 { 0x0, "SAMD10D14AMU", 16, 4 },
102 { 0x1, "SAMD10D13AMU", 8, 4 },
103 { 0x2, "SAMD10D12AMU", 4, 4 },
104 { 0x3, "SAMD10D14ASU", 16, 4 },
105 { 0x4, "SAMD10D13ASU", 8, 4 },
106 { 0x5, "SAMD10D12ASU", 4, 4 },
107 { 0x6, "SAMD10C14A", 16, 4 },
108 { 0x7, "SAMD10C13A", 8, 4 },
109 { 0x8, "SAMD10C12A", 4, 4 },
112 /* Known SAMD11 parts */
113 static const struct samd_part samd11_parts[] = {
114 { 0x0, "SAMD11D14AMU", 16, 4 },
115 { 0x1, "SAMD11D13AMU", 8, 4 },
116 { 0x2, "SAMD11D12AMU", 4, 4 },
117 { 0x3, "SAMD11D14ASU", 16, 4 },
118 { 0x4, "SAMD11D13ASU", 8, 4 },
119 { 0x5, "SAMD11D12ASU", 4, 4 },
120 { 0x6, "SAMD11C14A", 16, 4 },
121 { 0x7, "SAMD11C13A", 8, 4 },
122 { 0x8, "SAMD11C12A", 4, 4 },
125 /* Known SAMD20 parts. See Table 12-8 in 42129F–SAM–10/2013 */
126 static const struct samd_part samd20_parts[] = {
127 { 0x0, "SAMD20J18A", 256, 32 },
128 { 0x1, "SAMD20J17A", 128, 16 },
129 { 0x2, "SAMD20J16A", 64, 8 },
130 { 0x3, "SAMD20J15A", 32, 4 },
131 { 0x4, "SAMD20J14A", 16, 2 },
132 { 0x5, "SAMD20G18A", 256, 32 },
133 { 0x6, "SAMD20G17A", 128, 16 },
134 { 0x7, "SAMD20G16A", 64, 8 },
135 { 0x8, "SAMD20G15A", 32, 4 },
136 { 0x9, "SAMD20G14A", 16, 2 },
137 { 0xA, "SAMD20E18A", 256, 32 },
138 { 0xB, "SAMD20E17A", 128, 16 },
139 { 0xC, "SAMD20E16A", 64, 8 },
140 { 0xD, "SAMD20E15A", 32, 4 },
141 { 0xE, "SAMD20E14A", 16, 2 },
144 /* Known SAMD21 parts. */
145 static const struct samd_part samd21_parts[] = {
146 { 0x0, "SAMD21J18A", 256, 32 },
147 { 0x1, "SAMD21J17A", 128, 16 },
148 { 0x2, "SAMD21J16A", 64, 8 },
149 { 0x3, "SAMD21J15A", 32, 4 },
150 { 0x4, "SAMD21J14A", 16, 2 },
151 { 0x5, "SAMD21G18A", 256, 32 },
152 { 0x6, "SAMD21G17A", 128, 16 },
153 { 0x7, "SAMD21G16A", 64, 8 },
154 { 0x8, "SAMD21G15A", 32, 4 },
155 { 0x9, "SAMD21G14A", 16, 2 },
156 { 0xA, "SAMD21E18A", 256, 32 },
157 { 0xB, "SAMD21E17A", 128, 16 },
158 { 0xC, "SAMD21E16A", 64, 8 },
159 { 0xD, "SAMD21E15A", 32, 4 },
160 { 0xE, "SAMD21E14A", 16, 2 },
161 /* Below are B Variants (Table 3-7 from rev I of datasheet) */
162 { 0x20, "SAMD21J16B", 64, 8 },
163 { 0x21, "SAMD21J15B", 32, 4 },
164 { 0x23, "SAMD21G16B", 64, 8 },
165 { 0x24, "SAMD21G15B", 32, 4 },
166 { 0x26, "SAMD21E16B", 64, 8 },
167 { 0x27, "SAMD21E15B", 32, 4 },
170 /* Known SAMR21 parts. */
171 static const struct samd_part samr21_parts[] = {
172 { 0x19, "SAMR21G18A", 256, 32 },
173 { 0x1A, "SAMR21G17A", 128, 32 },
174 { 0x1B, "SAMR21G16A", 64, 32 },
175 { 0x1C, "SAMR21E18A", 256, 32 },
176 { 0x1D, "SAMR21E17A", 128, 32 },
177 { 0x1E, "SAMR21E16A", 64, 32 },
180 /* Known SAML21 parts. */
181 static const struct samd_part saml21_parts[] = {
182 { 0x00, "SAML21J18A", 256, 32 },
183 { 0x01, "SAML21J17A", 128, 16 },
184 { 0x02, "SAML21J16A", 64, 8 },
185 { 0x05, "SAML21G18A", 256, 32 },
186 { 0x06, "SAML21G17A", 128, 16 },
187 { 0x07, "SAML21G16A", 64, 8 },
188 { 0x0A, "SAML21E18A", 256, 32 },
189 { 0x0B, "SAML21E17A", 128, 16 },
190 { 0x0C, "SAML21E16A", 64, 8 },
191 { 0x0D, "SAML21E15A", 32, 4 },
192 { 0x0F, "SAML21J18B", 256, 32 },
193 { 0x10, "SAML21J17B", 128, 16 },
194 { 0x11, "SAML21J16B", 64, 8 },
195 { 0x14, "SAML21G18B", 256, 32 },
196 { 0x15, "SAML21G17B", 128, 16 },
197 { 0x16, "SAML21G16B", 64, 8 },
198 { 0x19, "SAML21E18B", 256, 32 },
199 { 0x1A, "SAML21E17B", 128, 16 },
200 { 0x1B, "SAML21E16B", 64, 8 },
201 { 0x1C, "SAML21E15B", 32, 4 },
204 /* Known SAML22 parts. */
205 static const struct samd_part saml22_parts[] = {
206 { 0x00, "SAML22N18A", 256, 32 },
207 { 0x01, "SAML22N17A", 128, 16 },
208 { 0x02, "SAML22N16A", 64, 8 },
209 { 0x05, "SAML22J18A", 256, 32 },
210 { 0x06, "SAML22J17A", 128, 16 },
211 { 0x07, "SAML22J16A", 64, 8 },
212 { 0x0A, "SAML22G18A", 256, 32 },
213 { 0x0B, "SAML22G17A", 128, 16 },
214 { 0x0C, "SAML22G16A", 64, 8 },
217 /* Known SAMC20 parts. */
218 static const struct samd_part samc20_parts[] = {
219 { 0x00, "SAMC20J18A", 256, 32 },
220 { 0x01, "SAMC20J17A", 128, 16 },
221 { 0x02, "SAMC20J16A", 64, 8 },
222 { 0x03, "SAMC20J15A", 32, 4 },
223 { 0x05, "SAMC20G18A", 256, 32 },
224 { 0x06, "SAMC20G17A", 128, 16 },
225 { 0x07, "SAMC20G16A", 64, 8 },
226 { 0x08, "SAMC20G15A", 32, 4 },
227 { 0x0A, "SAMC20E18A", 256, 32 },
228 { 0x0B, "SAMC20E17A", 128, 16 },
229 { 0x0C, "SAMC20E16A", 64, 8 },
230 { 0x0D, "SAMC20E15A", 32, 4 },
233 /* Known SAMC21 parts. */
234 static const struct samd_part samc21_parts[] = {
235 { 0x00, "SAMC21J18A", 256, 32 },
236 { 0x01, "SAMC21J17A", 128, 16 },
237 { 0x02, "SAMC21J16A", 64, 8 },
238 { 0x03, "SAMC21J15A", 32, 4 },
239 { 0x05, "SAMC21G18A", 256, 32 },
240 { 0x06, "SAMC21G17A", 128, 16 },
241 { 0x07, "SAMC21G16A", 64, 8 },
242 { 0x08, "SAMC21G15A", 32, 4 },
243 { 0x0A, "SAMC21E18A", 256, 32 },
244 { 0x0B, "SAMC21E17A", 128, 16 },
245 { 0x0C, "SAMC21E16A", 64, 8 },
246 { 0x0D, "SAMC21E15A", 32, 4 },
249 /* Each family of parts contains a parts table in the DEVSEL field of DID. The
250 * processor ID, family ID, and series ID are used to determine which exact
251 * family this is and then we can use the corresponding table. */
256 const struct samd_part *parts;
260 /* Known SAMD families */
261 static const struct samd_family samd_families[] = {
262 { SAMD_PROCESSOR_M0, SAMD_FAMILY_D, SAMD_SERIES_20,
263 samd20_parts, ARRAY_SIZE(samd20_parts) },
264 { SAMD_PROCESSOR_M0, SAMD_FAMILY_D, SAMD_SERIES_21,
265 samd21_parts, ARRAY_SIZE(samd21_parts) },
266 { SAMD_PROCESSOR_M0, SAMD_FAMILY_D, SAMD_SERIES_21,
267 samr21_parts, ARRAY_SIZE(samr21_parts) },
268 { SAMD_PROCESSOR_M0, SAMD_FAMILY_D, SAMD_SERIES_09,
269 samd09_parts, ARRAY_SIZE(samd09_parts) },
270 { SAMD_PROCESSOR_M0, SAMD_FAMILY_D, SAMD_SERIES_10,
271 samd10_parts, ARRAY_SIZE(samd10_parts) },
272 { SAMD_PROCESSOR_M0, SAMD_FAMILY_D, SAMD_SERIES_11,
273 samd11_parts, ARRAY_SIZE(samd11_parts) },
274 { SAMD_PROCESSOR_M0, SAMD_FAMILY_L, SAMD_SERIES_21,
275 saml21_parts, ARRAY_SIZE(saml21_parts) },
276 { SAMD_PROCESSOR_M0, SAMD_FAMILY_L, SAMD_SERIES_22,
277 saml22_parts, ARRAY_SIZE(saml22_parts) },
278 { SAMD_PROCESSOR_M0, SAMD_FAMILY_C, SAMD_SERIES_20,
279 samc20_parts, ARRAY_SIZE(samc20_parts) },
280 { SAMD_PROCESSOR_M0, SAMD_FAMILY_C, SAMD_SERIES_21,
281 samc21_parts, ARRAY_SIZE(samc21_parts) },
290 struct target *target;
291 struct samd_info *next;
294 static struct samd_info *samd_chips;
298 static const struct samd_part *samd_find_part(uint32_t id)
300 uint8_t processor = SAMD_GET_PROCESSOR(id);
301 uint8_t family = SAMD_GET_FAMILY(id);
302 uint8_t series = SAMD_GET_SERIES(id);
303 uint8_t devsel = SAMD_GET_DEVSEL(id);
305 for (unsigned i = 0; i < ARRAY_SIZE(samd_families); i++) {
306 if (samd_families[i].processor == processor &&
307 samd_families[i].series == series &&
308 samd_families[i].family == family) {
309 for (unsigned j = 0; j < samd_families[i].num_parts; j++) {
310 if (samd_families[i].parts[j].id == devsel)
311 return &samd_families[i].parts[j];
319 static int samd_protect_check(struct flash_bank *bank)
324 res = target_read_u16(bank->target,
325 SAMD_NVMCTRL + SAMD_NVMCTRL_LOCK, &lock);
329 /* Lock bits are active-low */
330 for (int i = 0; i < bank->num_sectors; i++)
331 bank->sectors[i].is_protected = !(lock & (1<<i));
336 static int samd_get_flash_page_info(struct target *target,
337 uint32_t *sizep, int *nump)
342 res = target_read_u32(target, SAMD_NVMCTRL + SAMD_NVMCTRL_PARAM, ¶m);
343 if (res == ERROR_OK) {
344 /* The PSZ field (bits 18:16) indicate the page size bytes as 2^(3+n)
345 * so 0 is 8KB and 7 is 1024KB. */
347 *sizep = (8 << ((param >> 16) & 0x7));
348 /* The NVMP field (bits 15:0) indicates the total number of pages */
350 *nump = param & 0xFFFF;
352 LOG_ERROR("Couldn't read NVM Parameters register");
358 static int samd_probe(struct flash_bank *bank)
362 struct samd_info *chip = (struct samd_info *)bank->driver_priv;
363 const struct samd_part *part;
368 res = target_read_u32(bank->target, SAMD_DSU + SAMD_DSU_DID, &id);
369 if (res != ERROR_OK) {
370 LOG_ERROR("Couldn't read Device ID register");
374 part = samd_find_part(id);
376 LOG_ERROR("Couldn't find part corresponding to DID %08" PRIx32, id);
380 bank->size = part->flash_kb * 1024;
382 chip->sector_size = bank->size / SAMD_NUM_SECTORS;
384 res = samd_get_flash_page_info(bank->target, &chip->page_size,
386 if (res != ERROR_OK) {
387 LOG_ERROR("Couldn't determine Flash page size");
391 /* Sanity check: the total flash size in the DSU should match the page size
392 * multiplied by the number of pages. */
393 if (bank->size != chip->num_pages * chip->page_size) {
394 LOG_WARNING("SAMD: bank size doesn't match NVM parameters. "
395 "Identified %" PRIu32 "KB Flash but NVMCTRL reports %u %" PRIu32 "B pages",
396 part->flash_kb, chip->num_pages, chip->page_size);
399 /* Allocate the sector table */
400 bank->num_sectors = SAMD_NUM_SECTORS;
401 bank->sectors = calloc(bank->num_sectors, sizeof((bank->sectors)[0]));
405 /* Fill out the sector information: all SAMD sectors are the same size and
406 * there is always a fixed number of them. */
407 for (int i = 0; i < bank->num_sectors; i++) {
408 bank->sectors[i].size = chip->sector_size;
409 bank->sectors[i].offset = i * chip->sector_size;
410 /* mark as unknown */
411 bank->sectors[i].is_erased = -1;
412 bank->sectors[i].is_protected = -1;
415 samd_protect_check(bank);
420 LOG_INFO("SAMD MCU: %s (%" PRIu32 "KB Flash, %" PRIu32 "KB RAM)", part->name,
421 part->flash_kb, part->ram_kb);
426 static bool samd_check_error(struct target *target)
432 ret = target_read_u16(target,
433 SAMD_NVMCTRL + SAMD_NVMCTRL_STATUS, &status);
434 if (ret != ERROR_OK) {
435 LOG_ERROR("Can't read NVM status");
439 if (status & 0x001C) {
440 if (status & (1 << 4)) /* NVME */
441 LOG_ERROR("SAMD: NVM Error");
442 if (status & (1 << 3)) /* LOCKE */
443 LOG_ERROR("SAMD: NVM lock error");
444 if (status & (1 << 2)) /* PROGE */
445 LOG_ERROR("SAMD: NVM programming error");
452 /* Clear the error conditions by writing a one to them */
453 ret = target_write_u16(target,
454 SAMD_NVMCTRL + SAMD_NVMCTRL_STATUS, status);
456 LOG_ERROR("Can't clear NVM error conditions");
461 static int samd_issue_nvmctrl_command(struct target *target, uint16_t cmd)
465 if (target->state != TARGET_HALTED) {
466 LOG_ERROR("Target not halted");
467 return ERROR_TARGET_NOT_HALTED;
470 /* Issue the NVM command */
471 res = target_write_u16(target,
472 SAMD_NVMCTRL + SAMD_NVMCTRL_CTRLA, SAMD_NVM_CMD(cmd));
476 /* Check to see if the NVM command resulted in an error condition. */
477 if (samd_check_error(target))
483 static int samd_erase_row(struct target *target, uint32_t address)
487 /* Set an address contained in the row to be erased */
488 res = target_write_u32(target,
489 SAMD_NVMCTRL + SAMD_NVMCTRL_ADDR, address >> 1);
491 /* Issue the Erase Row command to erase that row. */
493 res = samd_issue_nvmctrl_command(target,
494 address == SAMD_USER_ROW ? SAMD_NVM_CMD_EAR : SAMD_NVM_CMD_ER);
496 if (res != ERROR_OK) {
497 LOG_ERROR("Failed to erase row containing %08" PRIx32, address);
504 static bool is_user_row_reserved_bit(uint8_t bit)
506 /* See Table 9-3 in the SAMD20 datasheet for more information. */
511 /* Voltage regulator internal configuration with default value of 0x70,
512 * may not be changed. */
514 /* 41 is voltage regulator internal configuration and must not be
515 * changed. 42 through 47 are reserved. */
525 /* Modify the contents of the User Row in Flash. These are described in Table
526 * 9-3 of the SAMD20 datasheet. The User Row itself has a size of one page
527 * and contains a combination of "fuses" and calibration data in bits 24:17.
528 * We therefore try not to erase the row's contents unless we absolutely have
529 * to and we don't permit modifying reserved bits. */
530 static int samd_modify_user_row(struct target *target, uint32_t value,
531 uint8_t startb, uint8_t endb)
535 if (is_user_row_reserved_bit(startb) || is_user_row_reserved_bit(endb)) {
536 LOG_ERROR("Can't modify bits in the requested range");
540 /* Retrieve the MCU's page size, in bytes. This is also the size of the
541 * entire User Row. */
543 res = samd_get_flash_page_info(target, &page_size, NULL);
544 if (res != ERROR_OK) {
545 LOG_ERROR("Couldn't determine Flash page size");
549 /* Make sure the size is sane before we allocate. */
550 assert(page_size > 0 && page_size <= SAMD_PAGE_SIZE_MAX);
552 /* Make sure we're within the single page that comprises the User Row. */
553 if (startb >= (page_size * 8) || endb >= (page_size * 8)) {
554 LOG_ERROR("Can't modify bits outside the User Row page range");
558 uint8_t *buf = malloc(page_size);
562 /* Read the user row (comprising one page) by half-words. */
563 res = target_read_memory(target, SAMD_USER_ROW, 2, page_size / 2, buf);
567 /* We will need to erase before writing if the new value needs a '1' in any
568 * position for which the current value had a '0'. Otherwise we can avoid
570 uint32_t cur = buf_get_u32(buf, startb, endb - startb + 1);
571 if ((~cur) & value) {
572 res = samd_erase_row(target, SAMD_USER_ROW);
573 if (res != ERROR_OK) {
574 LOG_ERROR("Couldn't erase user row");
580 buf_set_u32(buf, startb, endb - startb + 1, value);
582 /* Write the page buffer back out to the target. A Flash write will be
583 * triggered automatically. */
584 res = target_write_memory(target, SAMD_USER_ROW, 4, page_size / 4, buf);
588 if (samd_check_error(target)) {
602 static int samd_protect(struct flash_bank *bank, int set, int first, int last)
604 struct samd_info *chip = (struct samd_info *)bank->driver_priv;
606 /* We can issue lock/unlock region commands with the target running but
607 * the settings won't persist unless we're able to modify the LOCK regions
608 * and that requires the target to be halted. */
609 if (bank->target->state != TARGET_HALTED) {
610 LOG_ERROR("Target not halted");
611 return ERROR_TARGET_NOT_HALTED;
616 for (int s = first; s <= last; s++) {
617 if (set != bank->sectors[s].is_protected) {
618 /* Load an address that is within this sector (we use offset 0) */
619 res = target_write_u32(bank->target,
620 SAMD_NVMCTRL + SAMD_NVMCTRL_ADDR,
621 ((s * chip->sector_size) >> 1));
625 /* Tell the controller to lock that sector */
626 res = samd_issue_nvmctrl_command(bank->target,
627 set ? SAMD_NVM_CMD_LR : SAMD_NVM_CMD_UR);
633 /* We've now applied our changes, however they will be undone by the next
634 * reset unless we also apply them to the LOCK bits in the User Page. The
635 * LOCK bits start at bit 48, corresponding to Sector 0 and end with bit 63,
636 * corresponding to Sector 15. A '1' means unlocked and a '0' means
637 * locked. See Table 9-3 in the SAMD20 datasheet for more details. */
639 res = samd_modify_user_row(bank->target, set ? 0x0000 : 0xFFFF,
640 48 + first, 48 + last);
642 LOG_WARNING("SAMD: protect settings were not made persistent!");
647 samd_protect_check(bank);
652 static int samd_erase(struct flash_bank *bank, int first, int last)
656 struct samd_info *chip = (struct samd_info *)bank->driver_priv;
658 if (bank->target->state != TARGET_HALTED) {
659 LOG_ERROR("Target not halted");
661 return ERROR_TARGET_NOT_HALTED;
665 if (samd_probe(bank) != ERROR_OK)
666 return ERROR_FLASH_BANK_NOT_PROBED;
669 /* The SAMD NVM has row erase granularity. There are four pages in a row
670 * and the number of rows in a sector depends on the sector size, which in
671 * turn depends on the Flash capacity as there is a fixed number of
673 rows_in_sector = chip->sector_size / (chip->page_size * 4);
675 /* For each sector to be erased */
676 for (int s = first; s <= last; s++) {
677 if (bank->sectors[s].is_protected) {
678 LOG_ERROR("SAMD: failed to erase sector %d. That sector is write-protected", s);
679 return ERROR_FLASH_OPERATION_FAILED;
682 /* For each row in that sector */
683 for (int r = s * rows_in_sector; r < (s + 1) * rows_in_sector; r++) {
684 res = samd_erase_row(bank->target, r * chip->page_size * 4);
685 if (res != ERROR_OK) {
686 LOG_ERROR("SAMD: failed to erase sector %d", s);
696 static int samd_write(struct flash_bank *bank, const uint8_t *buffer,
697 uint32_t offset, uint32_t count)
705 struct samd_info *chip = (struct samd_info *)bank->driver_priv;
709 if (bank->target->state != TARGET_HALTED) {
710 LOG_ERROR("Target not halted");
711 return ERROR_TARGET_NOT_HALTED;
715 if (samd_probe(bank) != ERROR_OK)
716 return ERROR_FLASH_BANK_NOT_PROBED;
719 /* Check if we need to do manual page write commands */
720 res = target_read_u32(bank->target, SAMD_NVMCTRL + SAMD_NVMCTRL_CTRLB, &nvm_ctrlb);
725 if (nvm_ctrlb & SAMD_NVM_CTRLB_MANW)
730 res = samd_issue_nvmctrl_command(bank->target, SAMD_NVM_CMD_PBC);
731 if (res != ERROR_OK) {
732 LOG_ERROR("%s: %d", __func__, __LINE__);
737 nb = chip->page_size - offset % chip->page_size;
741 address = bank->base + offset;
742 pg_offset = offset % chip->page_size;
744 if (offset % 4 || (offset + nb) % 4) {
745 /* Either start or end of write is not word aligned */
747 pb = malloc(chip->page_size);
752 /* Set temporary page buffer to 0xff and overwrite the relevant part */
753 memset(pb, 0xff, chip->page_size);
754 memcpy(pb + pg_offset, buffer, nb);
756 /* Align start address to a word boundary */
757 address -= offset % 4;
758 pg_offset -= offset % 4;
759 assert(pg_offset % 4 == 0);
761 /* Extend length to whole words */
762 nw = (nb + offset % 4 + 3) / 4;
763 assert(pg_offset + 4 * nw <= chip->page_size);
765 /* Now we have original data extended by 0xff bytes
766 * to the nearest word boundary on both start and end */
767 res = target_write_memory(bank->target, address, 4, nw, pb + pg_offset);
771 assert(pg_offset + 4 * nw <= chip->page_size);
773 /* Word aligned data, use direct write from buffer */
774 res = target_write_memory(bank->target, address, 4, nw, buffer);
776 if (res != ERROR_OK) {
777 LOG_ERROR("%s: %d", __func__, __LINE__);
781 /* Devices with errata 13134 have automatic page write enabled by default
782 * For other devices issue a write page CMD to the NVM
783 * If the page has not been written up to the last word
784 * then issue CMD_WP always */
785 if (manual_wp || pg_offset + 4 * nw < chip->page_size) {
786 res = samd_issue_nvmctrl_command(bank->target, SAMD_NVM_CMD_WP);
787 if (res != ERROR_OK) {
788 LOG_ERROR("%s: %d", __func__, __LINE__);
793 /* Access through AHB is stalled while flash is being programmed */
796 if (samd_check_error(bank->target)) {
797 LOG_ERROR("%s: write failed at address 0x%08" PRIx32, __func__, address);
802 /* We're done with the page contents */
815 FLASH_BANK_COMMAND_HANDLER(samd_flash_bank_command)
817 struct samd_info *chip = samd_chips;
820 if (chip->target == bank->target)
826 /* Create a new chip */
827 chip = calloc(1, sizeof(*chip));
831 chip->target = bank->target;
832 chip->probed = false;
834 bank->driver_priv = chip;
836 /* Insert it into the chips list (at head) */
837 chip->next = samd_chips;
841 if (bank->base != SAMD_FLASH) {
842 LOG_ERROR("Address 0x%08" PRIx32 " invalid bank address (try 0x%08" PRIx32
843 "[at91samd series] )",
844 bank->base, SAMD_FLASH);
851 COMMAND_HANDLER(samd_handle_info_command)
856 COMMAND_HANDLER(samd_handle_chip_erase_command)
858 struct target *target = get_current_target(CMD_CTX);
861 /* Enable access to the DSU by disabling the write protect bit */
862 target_write_u32(target, SAMD_PAC1, (1<<1));
863 /* Tell the DSU to perform a full chip erase. It takes about 240ms to
864 * perform the erase. */
865 target_write_u8(target, SAMD_DSU, (1<<4));
867 command_print(CMD_CTX, "chip erased");
873 COMMAND_HANDLER(samd_handle_set_security_command)
876 struct target *target = get_current_target(CMD_CTX);
878 if (CMD_ARGC < 1 || (CMD_ARGC >= 1 && (strcmp(CMD_ARGV[0], "enable")))) {
879 command_print(CMD_CTX, "supply the \"enable\" argument to proceed.");
880 return ERROR_COMMAND_SYNTAX_ERROR;
884 if (target->state != TARGET_HALTED) {
885 LOG_ERROR("Target not halted");
886 return ERROR_TARGET_NOT_HALTED;
889 res = samd_issue_nvmctrl_command(target, SAMD_NVM_CMD_SSB);
891 /* Check (and clear) error conditions */
893 command_print(CMD_CTX, "chip secured on next power-cycle");
895 command_print(CMD_CTX, "failed to secure chip");
901 COMMAND_HANDLER(samd_handle_eeprom_command)
904 struct target *target = get_current_target(CMD_CTX);
907 if (target->state != TARGET_HALTED) {
908 LOG_ERROR("Target not halted");
909 return ERROR_TARGET_NOT_HALTED;
913 int val = atoi(CMD_ARGV[0]);
919 /* Try to match size in bytes with corresponding size code */
920 for (code = 0; code <= 6; code++) {
921 if (val == (2 << (13 - code)))
926 command_print(CMD_CTX, "Invalid EEPROM size. Please see "
927 "datasheet for a list valid sizes.");
928 return ERROR_COMMAND_SYNTAX_ERROR;
932 res = samd_modify_user_row(target, code, 4, 6);
935 res = target_read_u16(target, SAMD_USER_ROW, &val);
936 if (res == ERROR_OK) {
937 uint32_t size = ((val >> 4) & 0x7); /* grab size code */
940 command_print(CMD_CTX, "EEPROM is disabled");
942 /* Otherwise, 6 is 256B, 0 is 16KB */
943 command_print(CMD_CTX, "EEPROM size is %u bytes",
953 COMMAND_HANDLER(samd_handle_bootloader_command)
956 struct target *target = get_current_target(CMD_CTX);
959 if (target->state != TARGET_HALTED) {
960 LOG_ERROR("Target not halted");
961 return ERROR_TARGET_NOT_HALTED;
964 /* Retrieve the MCU's page size, in bytes. */
966 res = samd_get_flash_page_info(target, &page_size, NULL);
967 if (res != ERROR_OK) {
968 LOG_ERROR("Couldn't determine Flash page size");
973 int val = atoi(CMD_ARGV[0]);
979 /* Try to match size in bytes with corresponding size code */
980 for (code = 0; code <= 6; code++) {
981 if ((unsigned int)val == (2UL << (8UL - code)) * page_size)
986 command_print(CMD_CTX, "Invalid bootloader size. Please "
987 "see datasheet for a list valid sizes.");
988 return ERROR_COMMAND_SYNTAX_ERROR;
993 res = samd_modify_user_row(target, code, 0, 2);
996 res = target_read_u16(target, SAMD_USER_ROW, &val);
997 if (res == ERROR_OK) {
998 uint32_t size = (val & 0x7); /* grab size code */
1004 nb = (2 << (8 - size)) * page_size;
1006 /* There are 4 pages per row */
1007 command_print(CMD_CTX, "Bootloader size is %" PRIu32 " bytes (%" PRIu32 " rows)",
1008 nb, (uint32_t)(nb / (page_size * 4)));
1018 COMMAND_HANDLER(samd_handle_reset_deassert)
1020 struct target *target = get_current_target(CMD_CTX);
1021 struct armv7m_common *armv7m = target_to_armv7m(target);
1022 int retval = ERROR_OK;
1023 enum reset_types jtag_reset_config = jtag_get_reset_config();
1025 /* In case of sysresetreq, debug retains state set in cortex_m_assert_reset()
1026 * so we just release reset held by DSU
1028 * n_RESET (srst) clears the DP, so reenable debug and set vector catch here
1030 * After vectreset DSU release is not needed however makes no harm
1032 if (target->reset_halt && (jtag_reset_config & RESET_HAS_SRST)) {
1033 retval = mem_ap_write_u32(armv7m->debug_ap, DCB_DHCSR, DBGKEY | C_HALT | C_DEBUGEN);
1034 if (retval == ERROR_OK)
1035 retval = mem_ap_write_u32(armv7m->debug_ap, DCB_DEMCR,
1036 TRCENA | VC_HARDERR | VC_BUSERR | VC_CORERESET);
1037 /* do not return on error here, releasing DSU reset is more important */
1040 /* clear CPU Reset Phase Extension bit */
1041 int retval2 = target_write_u8(target, SAMD_DSU + SAMD_DSU_STATUSA, (1<<1));
1042 if (retval2 != ERROR_OK)
1048 static const struct command_registration at91samd_exec_command_handlers[] = {
1050 .name = "dsu_reset_deassert",
1051 .handler = samd_handle_reset_deassert,
1052 .mode = COMMAND_EXEC,
1053 .help = "deasert internal reset held by DSU"
1057 .handler = samd_handle_info_command,
1058 .mode = COMMAND_EXEC,
1059 .help = "Print information about the current at91samd chip"
1060 "and its flash configuration.",
1063 .name = "chip-erase",
1064 .handler = samd_handle_chip_erase_command,
1065 .mode = COMMAND_EXEC,
1066 .help = "Erase the entire Flash by using the Chip"
1067 "Erase feature in the Device Service Unit (DSU).",
1070 .name = "set-security",
1071 .handler = samd_handle_set_security_command,
1072 .mode = COMMAND_EXEC,
1073 .help = "Secure the chip's Flash by setting the Security Bit."
1074 "This makes it impossible to read the Flash contents."
1075 "The only way to undo this is to issue the chip-erase"
1080 .usage = "[size_in_bytes]",
1081 .handler = samd_handle_eeprom_command,
1082 .mode = COMMAND_EXEC,
1083 .help = "Show or set the EEPROM size setting, stored in the User Row."
1084 "Please see Table 20-3 of the SAMD20 datasheet for allowed values."
1085 "Changes are stored immediately but take affect after the MCU is"
1089 .name = "bootloader",
1090 .usage = "[size_in_bytes]",
1091 .handler = samd_handle_bootloader_command,
1092 .mode = COMMAND_EXEC,
1093 .help = "Show or set the bootloader size, stored in the User Row."
1094 "Please see Table 20-2 of the SAMD20 datasheet for allowed values."
1095 "Changes are stored immediately but take affect after the MCU is"
1098 COMMAND_REGISTRATION_DONE
1101 static const struct command_registration at91samd_command_handlers[] = {
1104 .mode = COMMAND_ANY,
1105 .help = "at91samd flash command group",
1107 .chain = at91samd_exec_command_handlers,
1109 COMMAND_REGISTRATION_DONE
1112 struct flash_driver at91samd_flash = {
1114 .commands = at91samd_command_handlers,
1115 .flash_bank_command = samd_flash_bank_command,
1116 .erase = samd_erase,
1117 .protect = samd_protect,
1118 .write = samd_write,
1119 .read = default_flash_read,
1120 .probe = samd_probe,
1121 .auto_probe = samd_probe,
1122 .erase_check = default_flash_blank_check,
1123 .protect_check = samd_protect_check,