blob: 2fba6bce02bd86e79d9ebb985bf5eb5a627792fe [file] [log] [blame]
Nikolai Artemievadbae0e2020-10-06 16:59:51 +11001/*
2 * This file is part of the flashrom project.
3 *
4 * Copyright (C) 2014 Google LLC.
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 */
16
17/*
18 * s25f.c - Helper functions for Spansion S25FL and S25FS SPI flash chips.
19 * Uses 24 bit addressing for the FS chips and 32 bit addressing for the FL
20 * chips (which is required by the overlayed sector size devices).
21 * TODO: Implement fancy hybrid sector architecture helpers.
22 */
23
24#include <string.h>
25
26#include "chipdrivers.h"
27#include "spi.h"
28#include "writeprotect.h"
29
30/*
31 * RDAR and WRAR are supported on chips which have more than one set of status
32 * and control registers and take an address of the register to read/write.
33 * WRR, RDSR2, and RDCR are used on chips with a more limited set of control/
34 * status registers.
35 *
36 * WRR is somewhat peculiar. It shares the same opcode as JEDEC_WRSR, and if
37 * given one data byte (following the opcode) it acts the same way. If it's
38 * given two data bytes, the first data byte overwrites status register 1
39 * and the second data byte overwrites config register 1.
40 */
41#define CMD_WRR 0x01
42#define CMD_WRDI 0x04
43#define CMD_RDSR2 0x07 /* note: read SR1 with JEDEC RDSR opcode */
44#define CMD_RDCR 0x35
45#define CMD_RDAR 0x65
46#define CMD_WRAR 0x71
47
48/* TODO: For now, commands which use an address assume 24-bit addressing */
49#define CMD_WRR_LEN 3
50#define CMD_WRDI_LEN 1
51#define CMD_RDAR_LEN 4
52#define CMD_WRAR_LEN 5
53
54#define CMD_RSTEN 0x66
55#define CMD_RST 0x99
56
57#define CR1NV_ADDR 0x000002
58#define CR1_BPNV_O (1 << 3)
59#define CR1_TBPROT_O (1 << 5)
60#define CR3NV_ADDR 0x000004
61#define CR3NV_20H_NV (1 << 3)
62
63/* See "Embedded Algorithm Performance Tables for additional timing specs. */
64#define T_W 145 * 1000 /* NV register write time (145ms) */
65#define T_RPH 35 /* Reset pulse hold time (35us) */
66#define S25FS_T_SE 145 * 1000 /* Sector Erase Time (145ms) */
67#define S25FL_T_SE 130 * 1000 /* Sector Erase Time (130ms) */
68
69static int s25f_legacy_software_reset(const struct flashctx *flash)
70{
71 struct spi_command cmds[] = {
72 {
73 .writecnt = 1,
74 .writearr = (const uint8_t[]){ CMD_RSTEN },
75 .readcnt = 0,
76 .readarr = NULL,
77 }, {
78 .writecnt = 1,
79 .writearr = (const uint8_t[]){ 0xf0 },
80 .readcnt = 0,
81 .readarr = NULL,
82 }, {
83 .writecnt = 0,
84 .writearr = NULL,
85 .readcnt = 0,
86 .readarr = NULL,
87 }};
88
89 int result = spi_send_multicommand(flash, cmds);
90 if (result) {
91 msg_cerr("%s failed during command execution\n", __func__);
92 return result;
93 }
94
95 /* Allow time for reset command to execute. The datasheet specifies
96 * Trph = 35us, double that to be safe. */
97 programmer_delay(T_RPH * 2);
98
99 return 0;
100}
101
102/* "Legacy software reset" is disabled by default on S25FS, use this instead. */
103static int s25fs_software_reset(struct flashctx *flash)
104{
105 struct spi_command cmds[] = {
106 {
107 .writecnt = 1,
108 .writearr = (const uint8_t[]){ CMD_RSTEN },
109 .readcnt = 0,
110 .readarr = NULL,
111 }, {
112 .writecnt = 1,
113 .writearr = (const uint8_t[]){ CMD_RST },
114 .readcnt = 0,
115 .readarr = NULL,
116 }, {
117 .writecnt = 0,
118 .writearr = NULL,
119 .readcnt = 0,
120 .readarr = NULL,
121 }};
122
123 int result = spi_send_multicommand(flash, cmds);
124 if (result) {
125 msg_cerr("%s failed during command execution\n", __func__);
126 return result;
127 }
128
129 /* Allow time for reset command to execute. Double tRPH to be safe. */
130 programmer_delay(T_RPH * 2);
131
132 return 0;
133}
134
135static int s25f_poll_status(const struct flashctx *flash)
136{
137 uint8_t tmp = spi_read_status_register(flash);
138
139 while (tmp & SPI_SR_WIP) {
140 /*
141 * The WIP bit on S25F chips remains set to 1 if erase or
142 * programming errors occur, so we must check for those
143 * errors here. If an error is encountered, do a software
144 * reset to clear WIP and other volatile bits, otherwise
145 * the chip will be unresponsive to further commands.
146 */
147 if (tmp & SPI_SR_ERA_ERR) {
148 msg_cerr("Erase error occurred\n");
149 s25f_legacy_software_reset(flash);
150 return -1;
151 }
152
153 if (tmp & (1 << 6)) {
154 msg_cerr("Programming error occurred\n");
155 s25f_legacy_software_reset(flash);
156 return -1;
157 }
158
159 programmer_delay(1000 * 10);
160 tmp = spi_read_status_register(flash);
161 }
162
163 return 0;
164}
165
166/* "Read Any Register" instruction only supported on S25FS */
167static int s25fs_read_cr(const struct flashctx *flash, uint32_t addr)
168{
169 uint8_t cfg;
170 /* By default, 8 dummy cycles are necessary for variable-latency
171 commands such as RDAR (see CR2NV[3:0]). */
172 uint8_t read_cr_cmd[] = {
173 CMD_RDAR,
174 (addr >> 16) & 0xff,
175 (addr >> 8) & 0xff,
176 (addr & 0xff),
177 0x00, 0x00, 0x00, 0x00,
178 0x00, 0x00, 0x00, 0x00,
179 };
180
181 int result = spi_send_command(flash, sizeof(read_cr_cmd), 1, read_cr_cmd, &cfg);
182 if (result) {
183 msg_cerr("%s failed during command execution at address 0x%x\n",
184 __func__, addr);
185 return -1;
186 }
187
188 return cfg;
189}
190
191/* "Write Any Register" instruction only supported on S25FS */
192static int s25fs_write_cr(const struct flashctx *flash,
193 uint32_t addr, uint8_t data)
194{
195 struct spi_command cmds[] = {
196 {
197 .writecnt = JEDEC_WREN_OUTSIZE,
198 .writearr = (const uint8_t[]){ JEDEC_WREN },
199 .readcnt = 0,
200 .readarr = NULL,
201 }, {
202 .writecnt = CMD_WRAR_LEN,
203 .writearr = (const uint8_t[]){
204 CMD_WRAR,
205 (addr >> 16) & 0xff,
206 (addr >> 8) & 0xff,
207 (addr & 0xff),
208 data
209 },
210 .readcnt = 0,
211 .readarr = NULL,
212 }, {
213 .writecnt = 0,
214 .writearr = NULL,
215 .readcnt = 0,
216 .readarr = NULL,
217 }};
218
219 int result = spi_send_multicommand(flash, cmds);
220 if (result) {
221 msg_cerr("%s failed during command execution at address 0x%x\n",
222 __func__, addr);
223 return -1;
224 }
225
226 programmer_delay(T_W);
227 return s25f_poll_status(flash);
228}
229
230static int s25fs_restore_cr3nv(struct flashctx *flash, uint8_t cfg)
231{
232 int ret = 0;
233
234 msg_cdbg("Restoring CR3NV value to 0x%02x\n", cfg);
235 ret |= s25fs_write_cr(flash, CR3NV_ADDR, cfg);
236 ret |= s25fs_software_reset(flash);
237 return ret;
238}
239
Angel Ponsbc99e062021-04-17 17:42:53 +0200240int s25fs_block_erase_d8(struct flashctx *flash, unsigned int addr, unsigned int blocklen)
Nikolai Artemievadbae0e2020-10-06 16:59:51 +1100241{
242 static int cr3nv_checked = 0;
243
244 struct spi_command erase_cmds[] = {
245 {
246 .writecnt = JEDEC_WREN_OUTSIZE,
247 .writearr = (const uint8_t[]){ JEDEC_WREN },
248 .readcnt = 0,
249 .readarr = NULL,
250 }, {
251 .writecnt = JEDEC_BE_D8_OUTSIZE,
252 .writearr = (const uint8_t[]){
253 JEDEC_BE_D8,
254 (addr >> 16) & 0xff,
255 (addr >> 8) & 0xff,
256 (addr & 0xff)
257 },
258 .readcnt = 0,
259 .readarr = NULL,
260 }, {
261 .writecnt = 0,
262 .writearr = NULL,
263 .readcnt = 0,
264 .readarr = NULL,
265 }};
266
267 /* Check if hybrid sector architecture is in use and, if so,
268 * switch to uniform sectors. */
269 if (!cr3nv_checked) {
270 uint8_t cfg = s25fs_read_cr(flash, CR3NV_ADDR);
271 if (!(cfg & CR3NV_20H_NV)) {
272 s25fs_write_cr(flash, CR3NV_ADDR, cfg | CR3NV_20H_NV);
273 s25fs_software_reset(flash);
274
275 cfg = s25fs_read_cr(flash, CR3NV_ADDR);
276 if (!(cfg & CR3NV_20H_NV)) {
277 msg_cerr("%s: Unable to enable uniform "
278 "block sizes.\n", __func__);
279 return 1;
280 }
281
282 msg_cdbg("\n%s: CR3NV updated (0x%02x -> 0x%02x)\n",
283 __func__, cfg,
284 s25fs_read_cr(flash, CR3NV_ADDR));
285 /* Restore CR3V when flashrom exits */
286 register_chip_restore(s25fs_restore_cr3nv, flash, cfg);
287 }
288
289 cr3nv_checked = 1;
290 }
291
292 int result = spi_send_multicommand(flash, erase_cmds);
293 if (result) {
294 msg_cerr("%s failed during command execution at address 0x%x\n",
295 __func__, addr);
296 return result;
297 }
298
299 programmer_delay(S25FS_T_SE);
300 return s25f_poll_status(flash);
301}
302
Angel Ponsbc99e062021-04-17 17:42:53 +0200303int s25fl_block_erase(struct flashctx *flash, unsigned int addr, unsigned int blocklen)
Nikolai Artemievadbae0e2020-10-06 16:59:51 +1100304{
305 struct spi_command erase_cmds[] = {
306 {
307 .writecnt = JEDEC_WREN_OUTSIZE,
308 .writearr = (const uint8_t[]){
309 JEDEC_WREN
310 },
311 .readcnt = 0,
312 .readarr = NULL,
313 }, {
314 .writecnt = JEDEC_BE_DC_OUTSIZE,
315 .writearr = (const uint8_t[]){
316 JEDEC_BE_DC,
317 (addr >> 24) & 0xff,
318 (addr >> 16) & 0xff,
319 (addr >> 8) & 0xff,
320 (addr & 0xff)
321 },
322 .readcnt = 0,
323 .readarr = NULL,
324 }, {
325 .writecnt = 0,
326 .readcnt = 0,
327 }
328 };
329
330 int result = spi_send_multicommand(flash, erase_cmds);
331 if (result) {
332 msg_cerr("%s failed during command execution at address 0x%x\n",
333 __func__, addr);
334 return result;
335 }
336
337 programmer_delay(S25FL_T_SE);
338 return s25f_poll_status(flash);
339}
340
341
342int probe_spi_big_spansion(struct flashctx *flash)
343{
344 uint8_t cmd = JEDEC_RDID;
345 uint8_t dev_id[6]; /* We care only about 6 first bytes */
346
347 if (spi_send_command(flash, sizeof(cmd), sizeof(dev_id), &cmd, dev_id))
348 return 0;
349
350 msg_gdbg("Read id bytes: ");
351 for (size_t i = 0; i < sizeof(dev_id); i++)
352 msg_gdbg(" 0x%02x", dev_id[i]);
353 msg_gdbg(".\n");
354
355 /*
356 * The structure of the RDID output is as follows:
357 *
358 * offset value meaning
359 * 00h 01h Manufacturer ID for Spansion
360 * 01h 20h 128 Mb capacity
361 * 01h 02h 256 Mb capacity
362 * 02h 18h 128 Mb capacity
363 * 02h 19h 256 Mb capacity
364 * 03h 4Dh Full size of the RDID output (ignored)
365 * 04h 00h FS: 256-kB physical sectors
366 * 04h 01h FS: 64-kB physical sectors
367 * 04h 00h FL: 256-kB physical sectors
368 * 04h 01h FL: Mix of 64-kB and 4KB overlayed sectors
369 * 05h 80h FL family
370 * 05h 81h FS family
371 *
372 * Need to use bytes 1, 2, 4, and 5 to properly identify one of eight
373 * possible chips:
374 *
375 * 2 types * 2 possible sizes * 2 possible sector layouts
376 *
377 */
378
379 uint32_t model_id =
380 dev_id[1] << 24 |
381 dev_id[2] << 16 |
382 dev_id[4] << 8 |
383 dev_id[5] << 0;
384
385 if (dev_id[0] == flash->chip->manufacture_id && model_id == flash->chip->model_id)
386 return 1;
387
388 return 0;
389}