diff options
Diffstat (limited to 'utils/atj2137/adfuload/adfuload.c')
-rw-r--r-- | utils/atj2137/adfuload/adfuload.c | 467 |
1 files changed, 467 insertions, 0 deletions
diff --git a/utils/atj2137/adfuload/adfuload.c b/utils/atj2137/adfuload/adfuload.c new file mode 100644 index 0000000000..5e32a9354b --- /dev/null +++ b/utils/atj2137/adfuload/adfuload.c | |||
@@ -0,0 +1,467 @@ | |||
1 | /*************************************************************************** | ||
2 | * __________ __ ___. | ||
3 | * Open \______ \ ____ ____ | | _\_ |__ _______ ___ | ||
4 | * Source | _// _ \_/ ___\| |/ /| __ \ / _ \ \/ / | ||
5 | * Jukebox | | ( <_> ) \___| < | \_\ ( <_> > < < | ||
6 | * Firmware |____|_ /\____/ \___ >__|_ \|___ /\____/__/\_ \ | ||
7 | * \/ \/ \/ \/ \/ | ||
8 | * | ||
9 | * Copyright (C) 2013 by Marcin Bukat | ||
10 | * | ||
11 | * This program is free software; you can redistribute it and/or | ||
12 | * modify it under the terms of the GNU General Public License | ||
13 | * as published by the Free Software Foundation; either version 2 | ||
14 | * of the License, or (at your option) any later version. | ||
15 | * | ||
16 | * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY | ||
17 | * KIND, either express or implied. | ||
18 | * | ||
19 | ****************************************************************************/ | ||
20 | |||
21 | #include <stdlib.h> | ||
22 | #include <libusb.h> | ||
23 | #include <stdint.h> | ||
24 | #include <stdio.h> | ||
25 | #include <string.h> | ||
26 | #include <stdbool.h> | ||
27 | |||
28 | #include "encrypt.h" | ||
29 | |||
30 | #define VERSION "v0.1" | ||
31 | |||
32 | #define RETRY_MAX 5 | ||
33 | #define USB_TIMEOUT 512 | ||
34 | #define VENDORID 0x10d6 | ||
35 | #define PRODUCTID 0xff96 | ||
36 | |||
37 | #define OUT_EP 0x01 | ||
38 | #define IN_EP 0x82 | ||
39 | |||
40 | #define CBW_SIGNATURE 0x43425355 | ||
41 | #define CSW_SIGNATURE 0x53425355 | ||
42 | |||
43 | struct CBWCB_t | ||
44 | { | ||
45 | uint8_t cbCode; | ||
46 | uint8_t cbLun; | ||
47 | uint32_t LBA; | ||
48 | uint32_t cbLen; | ||
49 | uint8_t reseved; | ||
50 | uint8_t control; | ||
51 | } __attribute__((__packed__)); | ||
52 | |||
53 | struct CBW_t | ||
54 | { | ||
55 | uint32_t dCBWSignature; | ||
56 | uint32_t dCBWTag; | ||
57 | uint32_t dCBWDataTransferLength; | ||
58 | uint8_t bmCBWFlags; | ||
59 | uint8_t bCBWLUN; | ||
60 | uint8_t bCBWCBLength; | ||
61 | uint8_t CBWCB[16]; | ||
62 | } __attribute__((__packed__)); | ||
63 | |||
64 | struct CSW_t | ||
65 | { | ||
66 | uint32_t dCSWSignature; | ||
67 | uint32_t dCSWTag; | ||
68 | uint32_t dCSWDataResidue; | ||
69 | uint8_t bCSWStatus; | ||
70 | } __attribute__((__packed__)); | ||
71 | |||
72 | static int send_msc_cmd(libusb_device_handle *hdev, void *cbwcb, uint32_t data_len, uint32_t *reftag) | ||
73 | { | ||
74 | struct CBW_t cbw; | ||
75 | int ret, repeat, transferred; | ||
76 | |||
77 | memset(&cbw, 0, sizeof(cbw)); | ||
78 | cbw.dCBWSignature = CBW_SIGNATURE; | ||
79 | cbw.dCBWTag = 0; | ||
80 | cbw.dCBWDataTransferLength = data_len; | ||
81 | cbw.bmCBWFlags = 0; | ||
82 | cbw.bCBWLUN = 0; | ||
83 | cbw.bCBWCBLength = ((((char *)cbwcb)[0] == 0x10) ? 0 : 0x10); | ||
84 | memcpy(cbw.CBWCB, cbwcb, sizeof(struct CBWCB_t)); | ||
85 | |||
86 | *reftag = cbw.dCBWTag; | ||
87 | do | ||
88 | { | ||
89 | /* transfer command to the device */ | ||
90 | ret = libusb_bulk_transfer(hdev, OUT_EP, (unsigned char*)&cbw, 31, &transferred, USB_TIMEOUT); | ||
91 | if (ret == LIBUSB_ERROR_PIPE) | ||
92 | { | ||
93 | libusb_clear_halt(hdev, OUT_EP); | ||
94 | } | ||
95 | repeat++; | ||
96 | } while ((ret == LIBUSB_ERROR_PIPE) && (repeat < RETRY_MAX)); | ||
97 | |||
98 | if (ret != LIBUSB_SUCCESS) | ||
99 | { | ||
100 | printf("error: command transfer error\n"); | ||
101 | return -1; | ||
102 | } | ||
103 | |||
104 | return 0; | ||
105 | } | ||
106 | |||
107 | static int get_msc_csw(libusb_device_handle *hdev, uint32_t reftag) | ||
108 | { | ||
109 | struct CSW_t csw; | ||
110 | int ret, repeat, transferred; | ||
111 | |||
112 | /* get CSW response from device */ | ||
113 | repeat = 0; | ||
114 | do | ||
115 | { | ||
116 | ret = libusb_bulk_transfer(hdev, IN_EP, (unsigned char *)&csw, 13, &transferred, USB_TIMEOUT); | ||
117 | if (ret == LIBUSB_ERROR_PIPE) | ||
118 | { | ||
119 | libusb_clear_halt(hdev, IN_EP); | ||
120 | } | ||
121 | repeat++; | ||
122 | } while ((ret == LIBUSB_ERROR_PIPE) && (repeat < RETRY_MAX)); | ||
123 | |||
124 | if (ret != LIBUSB_SUCCESS) | ||
125 | { | ||
126 | printf("error reading CSW\n"); | ||
127 | return -3; | ||
128 | } | ||
129 | |||
130 | if (transferred != 13) | ||
131 | { | ||
132 | printf("error wrong size of CSW packet\n"); | ||
133 | return -4; | ||
134 | } | ||
135 | |||
136 | if (csw.dCSWSignature != CSW_SIGNATURE) | ||
137 | { | ||
138 | printf("error: wrong CSW signature.\n"); | ||
139 | return -5; | ||
140 | } | ||
141 | if (csw.dCSWTag != reftag) | ||
142 | { | ||
143 | printf("error: CSW dCSWTag mismatch. Is 0x%x, expected 0x%x\n", csw.dCSWTag, reftag); | ||
144 | return -6; | ||
145 | } | ||
146 | |||
147 | if (csw.bCSWStatus) | ||
148 | { | ||
149 | /* In case of CSW indicating error dump the content of the packet */ | ||
150 | printf ("dCSWSignature: 0x%0x\n", csw.dCSWSignature); | ||
151 | printf ("dCSWTag: 0x%0x\n", csw.dCSWTag); | ||
152 | printf ("dCSWDataResidue: 0x%0x\n", csw.dCSWDataResidue); | ||
153 | printf ("bCSWStatus: 0x%0x\n", csw.bCSWStatus); | ||
154 | } | ||
155 | |||
156 | return csw.bCSWStatus; | ||
157 | } | ||
158 | |||
159 | static void adfu_upload(libusb_device_handle *hdev, unsigned char *buf, int size, uint32_t address) | ||
160 | { | ||
161 | uint8_t cmdbuf[16]; | ||
162 | uint32_t reftag; | ||
163 | int transferred; | ||
164 | |||
165 | memset(cmdbuf, 0, sizeof(cmdbuf)); | ||
166 | |||
167 | fprintf(stderr,"[info]: loading binary @ 0x%08x size %d bytes\n", address, size); | ||
168 | |||
169 | cmdbuf[0] = 0x05; /* transfer */ | ||
170 | |||
171 | cmdbuf[1] = address & 0xff; /* addr LSB */ | ||
172 | cmdbuf[2] = (address >> 8) & 0xff; | ||
173 | cmdbuf[3] = (address >> 16) & 0xff; | ||
174 | cmdbuf[4] = (address >> 24) & 0xff; /* addr MSB */ | ||
175 | |||
176 | cmdbuf[5] = size & 0xff; /* len LSB */ | ||
177 | cmdbuf[6] = (size >> 8) & 0xff; | ||
178 | cmdbuf[7] = (size >> 16) & 0xff; | ||
179 | cmdbuf[8] = (size >> 24) & 0xff; /* len MSB */ | ||
180 | |||
181 | send_msc_cmd(hdev, (void *)cmdbuf, size, &reftag); | ||
182 | |||
183 | libusb_bulk_transfer(hdev, OUT_EP, buf, size, &transferred, USB_TIMEOUT); | ||
184 | fprintf(stderr, "[info]: actual xfered data: %d bytes\n", transferred); | ||
185 | |||
186 | /* get CSW from device*/ | ||
187 | fprintf(stderr, "[info]: CSW status: %d\n", get_msc_csw(hdev, reftag)); | ||
188 | } | ||
189 | |||
190 | #if 0 | ||
191 | /* unused, I'll leve it here for reference */ | ||
192 | static void adfu_download(libusb_device_handle *hdev, unsigned char *buf, int size, uint32_t address) | ||
193 | { | ||
194 | uint8_t cmdbuf[16]; | ||
195 | int transferred, ret, repeat; | ||
196 | uint32_t reftag; | ||
197 | |||
198 | fprintf(stderr, "[info]: downloading %d bytes from 0x%08x\n", size, address); | ||
199 | memset(cmdbuf, 0, sizeof(cmdbuf)); | ||
200 | |||
201 | cmdbuf[0] = 0x05; | ||
202 | |||
203 | cmdbuf[1] = address & 0xff; /* addr LSB */ | ||
204 | cmdbuf[2] = (address >> 8) & 0xff; | ||
205 | cmdbuf[3] = (address >> 16) & 0xff; | ||
206 | cmdbuf[4] = (address >> 24) & 0xff; /* addr MSB */ | ||
207 | |||
208 | cmdbuf[5] = size & 0xff; /* len LSB */ | ||
209 | cmdbuf[6] = (size >> 8) & 0xff; | ||
210 | cmdbuf[7] = (size >> 16) & 0xff; | ||
211 | cmdbuf[8] = (size >> 24) & 0xff; /* len MSB */ | ||
212 | |||
213 | cmdbuf[9] = 0x80; /* send data from device */ | ||
214 | |||
215 | send_msc_cmd(hdev, (void *)cmdbuf, size, &reftag); | ||
216 | |||
217 | memset(buf, 0, sizeof(buf)); | ||
218 | |||
219 | /* get data from device */ | ||
220 | repeat = 0; | ||
221 | do | ||
222 | { | ||
223 | ret = libusb_bulk_transfer(hdev, IN_EP, buf, size, &transferred, USB_TIMEOUT); | ||
224 | if (ret == LIBUSB_ERROR_PIPE) | ||
225 | { | ||
226 | libusb_clear_halt(hdev, IN_EP); | ||
227 | } | ||
228 | repeat++; | ||
229 | } while ((ret == LIBUSB_ERROR_PIPE) && (repeat < RETRY_MAX)); | ||
230 | |||
231 | fprintf(stderr, "[info]: actual xfered data: %d bytes\n", transferred); | ||
232 | |||
233 | /* get CSW from device*/ | ||
234 | fprintf(stderr, "[info]: CSW status: %d\n", get_msc_csw(hdev, reftag)); | ||
235 | } | ||
236 | #endif | ||
237 | |||
238 | static void adfu_execute(libusb_device_handle *hdev, uint32_t address) | ||
239 | { | ||
240 | uint8_t cmdbuf[16]; | ||
241 | uint32_t reftag; | ||
242 | |||
243 | fprintf(stderr, "[info]: jumping to address 0x%08x\n", address); | ||
244 | memset(cmdbuf, 0, sizeof(cmdbuf)); | ||
245 | |||
246 | cmdbuf[0] = 0x10; /* execute */ | ||
247 | |||
248 | cmdbuf[1] = address & 0xff; /* addr LSB */ | ||
249 | cmdbuf[2] = (address >> 8) & 0xff; | ||
250 | cmdbuf[3] = (address >> 16) & 0xff; | ||
251 | cmdbuf[4] = (address >> 24) & 0xff; /* addr MSB */ | ||
252 | |||
253 | send_msc_cmd(hdev, (void *)cmdbuf, 0, &reftag); | ||
254 | |||
255 | /* get CSW from device*/ | ||
256 | fprintf(stderr, "[info]: CSW status: %d\n", get_msc_csw(hdev, reftag)); | ||
257 | } | ||
258 | |||
259 | static void usage(char *name) | ||
260 | { | ||
261 | printf("usage: (sudo) %s [-e] -s1 stage1.bin -s2 stage2.bin\n", name); | ||
262 | printf("stage1.bin - binary of the stage1 (ADEC_N63.BIN for example)\n"); | ||
263 | printf("stage2.bin - binary of the custom user code\n"); | ||
264 | printf("\n"); | ||
265 | printf("options:\n"); | ||
266 | printf("-e - encode stage1 binary as needed by brom adfu mode\n"); | ||
267 | } | ||
268 | |||
269 | int main (int argc, char **argv) | ||
270 | { | ||
271 | libusb_device_handle *hdev; | ||
272 | int ret = 0; | ||
273 | int i = 1; | ||
274 | uint8_t *buf; | ||
275 | uint32_t filesize, filesize_round; | ||
276 | char *s1_filename, *s2_filename; | ||
277 | bool encode = false; | ||
278 | FILE *fp; | ||
279 | |||
280 | while (i < argc) | ||
281 | { | ||
282 | if (strcmp(argv[i],"-e") == 0) | ||
283 | { | ||
284 | encode = true; | ||
285 | i++; | ||
286 | } | ||
287 | else if (strcmp(argv[i],"-s1") == 0) | ||
288 | { | ||
289 | i++; | ||
290 | if (i == argc) | ||
291 | { | ||
292 | usage(argv[0]); | ||
293 | return -1; | ||
294 | } | ||
295 | s1_filename = argv[i]; | ||
296 | i++; | ||
297 | } | ||
298 | else if (strcmp(argv[i],"-s2") == 0) | ||
299 | { | ||
300 | i++; | ||
301 | if (i == argc) | ||
302 | { | ||
303 | usage(argv[0]); | ||
304 | return -2; | ||
305 | } | ||
306 | s2_filename = argv[i]; | ||
307 | i++; | ||
308 | } | ||
309 | else | ||
310 | { | ||
311 | usage(argv[0]); | ||
312 | return -3; | ||
313 | } | ||
314 | } | ||
315 | |||
316 | /* print banner */ | ||
317 | fprintf(stderr,"adfuload " VERSION "\n"); | ||
318 | fprintf(stderr,"(C) Marcin Bukat 2013\n"); | ||
319 | fprintf(stderr,"This is free software; see the source for copying conditions. There is NO\n"); | ||
320 | fprintf(stderr,"warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\n\n"); | ||
321 | |||
322 | /* initialize libusb */ | ||
323 | libusb_init(NULL); | ||
324 | |||
325 | hdev = libusb_open_device_with_vid_pid(NULL, VENDORID, PRODUCTID); | ||
326 | if (hdev == NULL) | ||
327 | { | ||
328 | fprintf(stderr, "[error]: can't open device with VID:PID=0x%0x:0x%0x\n", VENDORID, PRODUCTID); | ||
329 | libusb_exit(NULL); | ||
330 | return -4; | ||
331 | } | ||
332 | |||
333 | ret = libusb_kernel_driver_active(hdev, 0); | ||
334 | |||
335 | if (ret < 0) | ||
336 | { | ||
337 | fprintf(stderr, "[error]: checking kernel driver active\n"); | ||
338 | ret = -5; | ||
339 | goto end; | ||
340 | } | ||
341 | else | ||
342 | { | ||
343 | if (ret) | ||
344 | libusb_detach_kernel_driver(hdev, 0); | ||
345 | } | ||
346 | |||
347 | ret = libusb_set_configuration(hdev, 1); | ||
348 | if (ret < 0) | ||
349 | { | ||
350 | fprintf(stderr, "[error]: could not select configuration (1)\n"); | ||
351 | ret = -6; | ||
352 | goto end; | ||
353 | } | ||
354 | |||
355 | ret = libusb_claim_interface(hdev, 0); | ||
356 | if (ret < 0) | ||
357 | { | ||
358 | fprintf(stderr, "[error]: could not claim interface #0\n"); | ||
359 | ret = -7; | ||
360 | goto end; | ||
361 | } | ||
362 | |||
363 | ret = libusb_set_interface_alt_setting(hdev, 0, 0); | ||
364 | if ( ret != LIBUSB_SUCCESS) | ||
365 | { | ||
366 | fprintf(stderr, "[error]: could not set alt setting for interface #0\n"); | ||
367 | ret = -8; | ||
368 | goto end; | ||
369 | } | ||
370 | |||
371 | fp = fopen(s1_filename, "rb"); | ||
372 | |||
373 | if (fp == NULL) | ||
374 | { | ||
375 | fprintf(stderr, "[error]: Could not open file \"%s\"\n", s1_filename); | ||
376 | ret = -10; | ||
377 | goto end; | ||
378 | } | ||
379 | |||
380 | fseek(fp, 0, SEEK_END); | ||
381 | filesize = (uint32_t)ftell(fp); | ||
382 | fseek(fp, 0, SEEK_SET); | ||
383 | |||
384 | filesize_round = ( (filesize + 511) / 512 ) * 512; | ||
385 | |||
386 | buf = malloc(filesize_round); | ||
387 | |||
388 | if (buf == NULL) | ||
389 | { | ||
390 | fprintf(stderr, "[error]: Cannot allocate %d bytes of memory\n", filesize_round); | ||
391 | ret = -11; | ||
392 | goto end_fclose; | ||
393 | } | ||
394 | |||
395 | if (fread(buf, 1, filesize, fp) != filesize) | ||
396 | { | ||
397 | fprintf(stderr, "[error]: can't read file: %s\n", s1_filename); | ||
398 | ret = -12; | ||
399 | goto end_free; | ||
400 | } | ||
401 | |||
402 | fclose(fp); | ||
403 | |||
404 | fprintf(stderr, "[info]: file %s\n", s2_filename); | ||
405 | |||
406 | if (encode) | ||
407 | { | ||
408 | fprintf(stderr, "[info]: encrypting binary\n"); | ||
409 | ret = encrypt(buf, filesize_round); | ||
410 | |||
411 | if (ret) | ||
412 | { | ||
413 | fprintf(stderr, "[error]: can't encrypt binary\n"); | ||
414 | ret = -13; | ||
415 | goto end_free; | ||
416 | } | ||
417 | } | ||
418 | |||
419 | adfu_upload(hdev, buf, filesize_round, 0xb4040000); | ||
420 | adfu_execute(hdev, 0xb4040000); | ||
421 | /* Now ADEC_N63.BIN should be operational */ | ||
422 | |||
423 | /* upload custom binary and run it */ | ||
424 | fp = fopen(s2_filename, "rb"); | ||
425 | |||
426 | if (fp == NULL) | ||
427 | { | ||
428 | fprintf(stderr, "[error]: could not open file \"%s\"\n", s2_filename); | ||
429 | ret = -20; | ||
430 | goto end; | ||
431 | } | ||
432 | |||
433 | fseek(fp, 0, SEEK_END); | ||
434 | filesize = (uint32_t)ftell(fp); | ||
435 | fseek(fp, 0, SEEK_SET); | ||
436 | |||
437 | buf = realloc(buf, filesize); | ||
438 | |||
439 | if (buf == NULL) | ||
440 | { | ||
441 | fprintf(stderr, "[error]: can't allocate %d bytes of memory\n", filesize); | ||
442 | ret = -21; | ||
443 | goto end_fclose; | ||
444 | } | ||
445 | |||
446 | if (fread(buf, 1, filesize, fp) != filesize) | ||
447 | { | ||
448 | fprintf(stderr, "[error]: can't read file: %s\n", s2_filename); | ||
449 | ret = -22; | ||
450 | goto end_free; | ||
451 | } | ||
452 | |||
453 | fprintf(stderr, "[info]: file %s\n", s2_filename); | ||
454 | /* upload binary to the begining of DRAM */ | ||
455 | adfu_upload(hdev, buf, filesize, 0xa0000000); | ||
456 | adfu_execute(hdev, 0xa0000000); | ||
457 | |||
458 | end_free: | ||
459 | free(buf); | ||
460 | end_fclose: | ||
461 | fclose(fp); | ||
462 | end: | ||
463 | libusb_close(hdev); | ||
464 | libusb_exit(NULL); | ||
465 | |||
466 | return ret; | ||
467 | } | ||