2 * i.MX6 nand boot control block(bcb).
4 * Based on the common/imx-bbu-nand-fcb.c from barebox and imx kobs-ng
6 * Copyright (C) 2017 Jagan Teki <jagan@amarulasolutions.com>
7 * Copyright (C) 2016 Sergey Kubushyn <ksi@koi8.net>
9 * SPDX-License-Identifier: GPL-2.0+
15 #include <dm/devres.h>
18 #include <jffs2/jffs2.h>
19 #include <linux/bch.h>
20 #include <linux/mtd/mtd.h>
22 #include <asm/arch/sys_proto.h>
23 #include <asm/mach-imx/imx-nandbcb.h>
24 #include <asm/mach-imx/imximage.cfg>
26 #include <linux/mtd/mtd.h>
29 #include "../../../cmd/legacy-mtd-utils.h"
31 #define BF_VAL(v, bf) (((v) & bf##_MASK) >> bf##_OFFSET)
32 #define GETBIT(v, n) (((v) >> (n)) & 0x1)
34 #if defined(CONFIG_MX6UL) || defined(CONFIG_MX6ULL)
35 static uint8_t reverse_bit(uint8_t b)
37 b = (b & 0xf0) >> 4 | (b & 0x0f) << 4;
38 b = (b & 0xcc) >> 2 | (b & 0x33) << 2;
39 b = (b & 0xaa) >> 1 | (b & 0x55) << 1;
44 static void encode_bch_ecc(void *buf, struct fcb_block *fcb, int eccbits)
49 int ecc_buf_size = (m * eccbits + 7) / 8;
50 struct bch_control *bch = init_bch(m, eccbits, 0);
51 u8 *ecc_buf = kzalloc(ecc_buf_size, GFP_KERNEL);
52 u8 *tmp_buf = kzalloc(blocksize * numblocks, GFP_KERNEL);
56 * The blocks here are bit aligned. If eccbits is a multiple of 8,
57 * we just can copy bytes. Otherwiese we must move the blocks to
58 * the next free bit position.
62 memcpy(tmp_buf, fcb, sizeof(*fcb));
64 for (i = 0; i < numblocks; i++) {
65 memset(ecc_buf, 0, ecc_buf_size);
66 psrc = tmp_buf + i * blocksize;
67 pdst = buf + i * (blocksize + ecc_buf_size);
69 /* copy data byte aligned to destination buf */
70 memcpy(pdst, psrc, blocksize);
73 * imx-kobs use a modified encode_bch which reverse the
74 * bit order of the data before calculating bch.
75 * Do this in the buffer and use the bch lib here.
77 for (j = 0; j < blocksize; j++)
78 psrc[j] = reverse_bit(psrc[j]);
80 encode_bch(bch, psrc, blocksize, ecc_buf);
83 for (j = 0; j < ecc_buf_size; j++)
84 ecc_buf[j] = reverse_bit(ecc_buf[j]);
86 /* Here eccbuf is byte aligned and we can just copy it */
87 memcpy(pdst + blocksize, ecc_buf, ecc_buf_size);
96 static u8 calculate_parity_13_8(u8 d)
100 p |= (GETBIT(d, 6) ^ GETBIT(d, 5) ^ GETBIT(d, 3) ^ GETBIT(d, 2)) << 0;
101 p |= (GETBIT(d, 7) ^ GETBIT(d, 5) ^ GETBIT(d, 4) ^ GETBIT(d, 2) ^
103 p |= (GETBIT(d, 7) ^ GETBIT(d, 6) ^ GETBIT(d, 5) ^ GETBIT(d, 1) ^
105 p |= (GETBIT(d, 7) ^ GETBIT(d, 4) ^ GETBIT(d, 3) ^ GETBIT(d, 0)) << 3;
106 p |= (GETBIT(d, 6) ^ GETBIT(d, 4) ^ GETBIT(d, 3) ^ GETBIT(d, 2) ^
107 GETBIT(d, 1) ^ GETBIT(d, 0)) << 4;
112 static void encode_hamming_13_8(void *_src, void *_ecc, size_t size)
118 for (i = 0; i < size; i++)
119 ecc[i] = calculate_parity_13_8(src[i]);
123 static u32 calc_chksum(void *buf, size_t size)
129 for (i = 0; i < size; i++)
135 static void fill_fcb(struct fcb_block *fcb, struct mtd_info *mtd,
136 u32 fw1_start, u32 fw2_start, u32 fw_pages)
138 struct nand_chip *chip = mtd_to_nand(mtd);
139 struct mxs_nand_info *nand_info = nand_get_controller_data(chip);
140 struct mxs_nand_layout l;
142 mxs_nand_get_layout(mtd, &l);
144 fcb->fingerprint = FCB_FINGERPRINT;
145 fcb->version = FCB_VERSION_1;
147 fcb->pagesize = mtd->writesize;
148 fcb->oob_pagesize = mtd->writesize + mtd->oobsize;
149 fcb->sectors = mtd->erasesize / mtd->writesize;
151 fcb->meta_size = l.meta_size;
152 fcb->nr_blocks = l.nblocks;
153 fcb->ecc_nr = l.data0_size;
154 fcb->ecc_level = l.ecc0;
155 fcb->ecc_size = l.datan_size;
156 fcb->ecc_type = l.eccn;
157 fcb->bchtype = l.gf_len;
159 /* Also hardcoded in kobs-ng */
163 fcb->addr_setup = 25;
164 fcb->dsample_time = 6;
165 } else if (is_mx7()) {
168 fcb->addr_setup = 15;
169 fcb->dsample_time = 6;
172 /* DBBT search area starts at second page on first block */
175 fcb->bb_byte = nand_info->bch_geometry.block_mark_byte_offset;
176 fcb->bb_start_bit = nand_info->bch_geometry.block_mark_bit_offset;
178 fcb->phy_offset = mtd->writesize;
180 fcb->nr_blocks = mtd->writesize / fcb->ecc_nr - 1;
183 fcb->disbbm_search = 0;
185 fcb->fw1_start = fw1_start; /* Firmware image starts on this sector */
186 fcb->fw2_start = fw2_start; /* Secondary FW Image starting Sector */
187 fcb->fw1_pages = fw_pages; /* Number of sectors in firmware image */
188 fcb->fw2_pages = fw_pages; /* Number of sector in secondary FW image */
190 fcb->checksum = calc_chksum((void *)fcb + 4, sizeof(*fcb) - 4);
193 static int dbbt_fill_data(struct mtd_info *mtd, void *buf, int num_blocks)
195 int n, n_bad_blocks = 0;
197 u32 *n_bad_blocksp = buf + 0x4;
199 for (n = 0; n < num_blocks; n++) {
200 loff_t offset = n * mtd->erasesize;
201 if (mtd_block_isbad(mtd, offset)) {
208 *n_bad_blocksp = n_bad_blocks;
213 static int write_fcb_dbbt(struct mtd_info *mtd, struct fcb_block *fcb,
214 struct dbbt_block *dbbt, void *dbbt_data_page,
217 void *fcb_raw_page = 0;
222 * We prepare raw page only for i.MX6, for i.MX7 we
223 * leverage BCH hw module instead
227 fcb_raw_page = kzalloc(mtd->writesize + mtd->oobsize,
230 debug("failed to allocate fcb_raw_page\n");
235 #if defined(CONFIG_MX6UL) || defined(CONFIG_MX6ULL)
236 /* 40 bit BCH, for i.MX6UL(L) */
237 encode_bch_ecc(fcb_raw_page + 32, fcb, 40);
239 memcpy(fcb_raw_page + 12, fcb, sizeof(struct fcb_block));
240 encode_hamming_13_8(fcb_raw_page + 12,
241 fcb_raw_page + 12 + 512, 512);
244 * Set the first and second byte of OOB data to 0xFF,
245 * not 0x00. These bytes are used as the Manufacturers Bad
246 * Block Marker (MBBM). Since the FCB is mostly written to
247 * the first page in a block, a scan for
248 * factory bad blocks will detect these blocks as bad, e.g.
249 * when function nand_scan_bbt() is executed to build a new
252 memset(fcb_raw_page + mtd->writesize, 0xFF, 2);
254 for (i = 0; i < 2; i++) {
255 if (mtd_block_isbad(mtd, off)) {
256 printf("Block %d is bad, skipped\n", i);
261 * User BCH ECC hardware module for i.MX7
264 u32 off = i * mtd->erasesize;
265 size_t rwsize = sizeof(*fcb);
267 printf("Writing %d bytes to 0x%x: ", rwsize, off);
269 /* switch nand BCH to FCB compatible settings */
270 mxs_nand_mode_fcb(mtd);
271 ret = nand_write(mtd, off, &rwsize,
272 (unsigned char *)fcb);
273 mxs_nand_mode_normal(mtd);
275 printf("%s\n", ret ? "ERROR" : "OK");
276 } else if (is_mx6()) {
278 mtd_oob_ops_t ops = {
279 .datbuf = (u8 *)fcb_raw_page,
280 .oobbuf = ((u8 *)fcb_raw_page) +
282 .len = mtd->writesize,
283 .ooblen = mtd->oobsize,
287 ret = mtd_write_oob(mtd, mtd->erasesize * i, &ops);
289 goto fcb_raw_page_err;
290 debug("NAND fcb write: 0x%x offset 0x%x written: %s\n",
291 mtd->erasesize * i, ops.len, ret ?
295 ret = mtd_write(mtd, mtd->erasesize * i + mtd->writesize,
296 mtd->writesize, &dummy, (void *)dbbt);
298 goto fcb_raw_page_err;
299 debug("NAND dbbt write: 0x%x offset, 0x%x bytes written: %s\n",
300 mtd->erasesize * i + mtd->writesize, dummy,
301 ret ? "ERROR" : "OK");
303 /* dbbtpages == 0 if no bad blocks */
304 if (dbbt->dbbtpages > 0) {
305 loff_t to = (mtd->erasesize * i + mtd->writesize * 5);
307 ret = mtd_write(mtd, to, mtd->writesize, &dummy,
310 goto fcb_raw_page_err;
321 static int nandbcb_update(struct mtd_info *mtd, loff_t off, size_t size,
322 size_t maxsize, const u_char *buf)
324 nand_erase_options_t opts;
325 struct fcb_block *fcb;
326 struct dbbt_block *dbbt;
328 void *fwbuf, *dbbt_page, *dbbt_data_page;
329 u32 fw1_start, fw1_pages;
330 int nr_blks, nr_blks_fcb, fw1_blk;
335 memset(&opts, 0, sizeof(opts));
337 opts.length = maxsize - 1;
338 ret = nand_erase_opts(mtd, &opts);
340 printf("%s: erase failed (ret = %d)\n", __func__, ret);
345 * Reference documentation from i.MX6DQRM section 8.5.2.2
347 * Nand Boot Control Block(BCB) contains two data structures,
348 * - Firmware Configuration Block(FCB)
349 * - Discovered Bad Block Table(DBBT)
353 * - DBBT search page address,
354 * - start page address of primary firmware
355 * - start page address of secondary firmware
358 * - number of blocks = mtd partition size / mtd erasesize
359 * - two firmware blocks, primary and secondary
360 * - first 4 block for FCB/DBBT
361 * - rest split in half for primary and secondary firmware
362 * - same firmware will write two times
365 nr_blks = maxsize / mtd->erasesize;
366 fw1_blk = nr_blks_fcb;
369 fwsize = ALIGN(size + FLASH_OFFSET_STANDARD + mtd->writesize,
371 fwbuf = kzalloc(fwsize, GFP_KERNEL);
373 debug("failed to allocate fwbuf\n");
378 memcpy(fwbuf + FLASH_OFFSET_STANDARD, buf, size);
379 fw1_off = fw1_blk * mtd->erasesize;
380 ret = nand_write_skip_bad(mtd, fw1_off, &fwsize, NULL, maxsize,
381 (u_char *)fwbuf, WITH_WR_VERIFY);
382 printf("NAND fw write: 0x%llx offset, 0x%x bytes written: %s\n",
383 fw1_off, fwsize, ret ? "ERROR" : "OK");
388 fcb = kzalloc(sizeof(*fcb), GFP_KERNEL);
390 debug("failed to allocate fcb\n");
395 fw1_start = (fw1_blk * mtd->erasesize) / mtd->writesize;
396 fw1_pages = size / mtd->writesize + 1;
397 fill_fcb(fcb, mtd, fw1_start, 0, fw1_pages);
400 dbbt_page = kzalloc(mtd->writesize, GFP_KERNEL);
402 debug("failed to allocate dbbt_page\n");
407 dbbt_data_page = kzalloc(mtd->writesize, GFP_KERNEL);
408 if (!dbbt_data_page) {
409 debug("failed to allocate dbbt_data_page\n");
416 dbbt->fingerprint = DBBT_FINGERPRINT2;
417 dbbt->version = DBBT_VERSION_1;
418 ret = dbbt_fill_data(mtd, dbbt_data_page, nr_blks);
420 goto dbbt_data_page_err;
424 /* write fcb and dbbt to nand */
425 ret = write_fcb_dbbt(mtd, fcb, dbbt, dbbt_data_page, off);
427 printf("failed to write FCB/DBBT\n");
430 kfree(dbbt_data_page);
441 static int do_nandbcb_bcbonly(int argc, char * const argv[])
443 struct fcb_block *fcb;
444 struct dbbt_block *dbbt;
445 u32 fw_len, fw1_off, fw2_off;
446 struct mtd_info *mtd;
447 void *dbbt_page, *dbbt_data_page;
450 dev = nand_curr_device;
451 if ((dev < 0) || (dev >= CONFIG_SYS_MAX_NAND_DEVICE) ||
452 (!get_nand_dev_by_index(dev))) {
453 puts("No devices available\n");
454 return CMD_RET_FAILURE;
457 mtd = get_nand_dev_by_index(dev);
460 return CMD_RET_FAILURE;
462 fw_len = simple_strtoul(argv[1], NULL, 16);
463 fw1_off = simple_strtoul(argv[2], NULL, 16);
466 fw2_off = simple_strtoul(argv[3], NULL, 16);
471 fcb = kzalloc(sizeof(*fcb), GFP_KERNEL);
473 debug("failed to allocate fcb\n");
475 return CMD_RET_FAILURE;
478 fill_fcb(fcb, mtd, fw1_off / mtd->writesize,
479 fw2_off / mtd->writesize, fw_len / mtd->writesize);
482 dbbt_page = kzalloc(mtd->writesize, GFP_KERNEL);
484 debug("failed to allocate dbbt_page\n");
489 dbbt_data_page = kzalloc(mtd->writesize, GFP_KERNEL);
490 if (!dbbt_data_page) {
491 debug("failed to allocate dbbt_data_page\n");
498 dbbt->fingerprint = DBBT_FINGERPRINT2;
499 dbbt->version = DBBT_VERSION_1;
500 ret = dbbt_fill_data(mtd, dbbt_data_page, 0);
502 goto dbbt_data_page_err;
506 /* write fcb and dbbt to nand */
507 ret = write_fcb_dbbt(mtd, fcb, dbbt, dbbt_data_page, 0);
509 kfree(dbbt_data_page);
516 printf("failed to write FCB/DBBT\n");
517 return CMD_RET_FAILURE;
520 return CMD_RET_SUCCESS;
523 static int do_nandbcb_update(int argc, char * const argv[])
525 struct mtd_info *mtd;
526 loff_t addr, offset, size, maxsize;
533 return CMD_RET_USAGE;
535 dev = nand_curr_device;
537 printf("failed to get nand_curr_device, run nand device\n");
538 return CMD_RET_FAILURE;
541 addr = simple_strtoul(argv[1], &endp, 16);
542 if (*argv[1] == 0 || *endp != 0)
543 return CMD_RET_FAILURE;
545 mtd = get_nand_dev_by_index(dev);
546 if (mtd_arg_off_size(argc - 2, argv + 2, &dev, &offset, &size,
547 &maxsize, MTD_DEV_TYPE_NAND, mtd->size))
548 return CMD_RET_FAILURE;
550 buf = map_physmem(addr, size, MAP_WRBACK);
552 puts("failed to map physical memory\n");
553 return CMD_RET_FAILURE;
556 ret = nandbcb_update(mtd, offset, size, maxsize, buf);
558 return ret == 0 ? CMD_RET_SUCCESS : CMD_RET_FAILURE;
561 static int do_nandbcb(cmd_tbl_t *cmdtp, int flag, int argc,
574 if (strcmp(cmd, "update") == 0) {
575 ret = do_nandbcb_update(argc, argv);
579 if (strcmp(cmd, "bcbonly") == 0) {
580 ret = do_nandbcb_bcbonly(argc, argv);
588 return CMD_RET_USAGE;
591 #ifdef CONFIG_SYS_LONGHELP
592 static char nandbcb_help_text[] =
593 "update addr off|partition len - update 'len' bytes starting at\n"
594 " 'off|part' to memory address 'addr', skipping bad blocks\n"
595 "bcbonly fw-size fw1-off [fw2-off] - write only BCB (FCB and DBBT)\n"
596 " where `fw-size` is fw sizes in bytes, `fw1-off`\n"
597 " and `fw2-off` - firmware offsets\n"
598 " FIY, BCB isn't erased automatically, so mtd erase should\n"
599 " be called in advance before writing new BCB:\n"
600 " > mtd erase mx7-bcb";
603 U_BOOT_CMD(nandbcb, 5, 1, do_nandbcb,
604 "i.MX6/i.MX7 NAND Boot Control Blocks write",