vl: fix max_cpus check
[qemu/ar7.git] / hw / block / onenand.c
blob348630d9055077e8d2baac5cf10b40ece9832f48
1 /*
2 * OneNAND flash memories emulation.
4 * Copyright (C) 2008 Nokia Corporation
5 * Written by Andrzej Zaborowski <andrew@openedhand.com>
7 * This program is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License as
9 * published by the Free Software Foundation; either version 2 or
10 * (at your option) version 3 of the License.
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
17 * You should have received a copy of the GNU General Public License along
18 * with this program; if not, see <http://www.gnu.org/licenses/>.
21 #include "qemu-common.h"
22 #include "hw/hw.h"
23 #include "hw/block/flash.h"
24 #include "hw/irq.h"
25 #include "sysemu/block-backend.h"
26 #include "sysemu/blockdev.h"
27 #include "exec/memory.h"
28 #include "exec/address-spaces.h"
29 #include "hw/sysbus.h"
30 #include "qemu/error-report.h"
32 /* 11 for 2kB-page OneNAND ("2nd generation") and 10 for 1kB-page chips */
33 #define PAGE_SHIFT 11
35 /* Fixed */
36 #define BLOCK_SHIFT (PAGE_SHIFT + 6)
38 #define TYPE_ONE_NAND "onenand"
39 #define ONE_NAND(obj) OBJECT_CHECK(OneNANDState, (obj), TYPE_ONE_NAND)
41 typedef struct OneNANDState {
42 SysBusDevice parent_obj;
44 struct {
45 uint16_t man;
46 uint16_t dev;
47 uint16_t ver;
48 } id;
49 int shift;
50 hwaddr base;
51 qemu_irq intr;
52 qemu_irq rdy;
53 BlockBackend *blk;
54 BlockBackend *blk_cur;
55 uint8_t *image;
56 uint8_t *otp;
57 uint8_t *current;
58 MemoryRegion ram;
59 MemoryRegion mapped_ram;
60 uint8_t current_direction;
61 uint8_t *boot[2];
62 uint8_t *data[2][2];
63 MemoryRegion iomem;
64 MemoryRegion container;
65 int cycle;
66 int otpmode;
68 uint16_t addr[8];
69 uint16_t unladdr[8];
70 int bufaddr;
71 int count;
72 uint16_t command;
73 uint16_t config[2];
74 uint16_t status;
75 uint16_t intstatus;
76 uint16_t wpstatus;
78 ECCState ecc;
80 int density_mask;
81 int secs;
82 int secs_cur;
83 int blocks;
84 uint8_t *blockwp;
85 } OneNANDState;
87 enum {
88 ONEN_BUF_BLOCK = 0,
89 ONEN_BUF_BLOCK2 = 1,
90 ONEN_BUF_DEST_BLOCK = 2,
91 ONEN_BUF_DEST_PAGE = 3,
92 ONEN_BUF_PAGE = 7,
95 enum {
96 ONEN_ERR_CMD = 1 << 10,
97 ONEN_ERR_ERASE = 1 << 11,
98 ONEN_ERR_PROG = 1 << 12,
99 ONEN_ERR_LOAD = 1 << 13,
102 enum {
103 ONEN_INT_RESET = 1 << 4,
104 ONEN_INT_ERASE = 1 << 5,
105 ONEN_INT_PROG = 1 << 6,
106 ONEN_INT_LOAD = 1 << 7,
107 ONEN_INT = 1 << 15,
110 enum {
111 ONEN_LOCK_LOCKTIGHTEN = 1 << 0,
112 ONEN_LOCK_LOCKED = 1 << 1,
113 ONEN_LOCK_UNLOCKED = 1 << 2,
116 static void onenand_mem_setup(OneNANDState *s)
118 /* XXX: We should use IO_MEM_ROMD but we broke it earlier...
119 * Both 0x0000 ... 0x01ff and 0x8000 ... 0x800f can be used to
120 * write boot commands. Also take note of the BWPS bit. */
121 memory_region_init(&s->container, OBJECT(s), "onenand",
122 0x10000 << s->shift);
123 memory_region_add_subregion(&s->container, 0, &s->iomem);
124 memory_region_init_alias(&s->mapped_ram, OBJECT(s), "onenand-mapped-ram",
125 &s->ram, 0x0200 << s->shift,
126 0xbe00 << s->shift);
127 memory_region_add_subregion_overlap(&s->container,
128 0x0200 << s->shift,
129 &s->mapped_ram,
133 static void onenand_intr_update(OneNANDState *s)
135 qemu_set_irq(s->intr, ((s->intstatus >> 15) ^ (~s->config[0] >> 6)) & 1);
138 static void onenand_pre_save(void *opaque)
140 OneNANDState *s = opaque;
141 if (s->current == s->otp) {
142 s->current_direction = 1;
143 } else if (s->current == s->image) {
144 s->current_direction = 2;
145 } else {
146 s->current_direction = 0;
150 static int onenand_post_load(void *opaque, int version_id)
152 OneNANDState *s = opaque;
153 switch (s->current_direction) {
154 case 0:
155 break;
156 case 1:
157 s->current = s->otp;
158 break;
159 case 2:
160 s->current = s->image;
161 break;
162 default:
163 return -1;
165 onenand_intr_update(s);
166 return 0;
169 static const VMStateDescription vmstate_onenand = {
170 .name = "onenand",
171 .version_id = 1,
172 .minimum_version_id = 1,
173 .pre_save = onenand_pre_save,
174 .post_load = onenand_post_load,
175 .fields = (VMStateField[]) {
176 VMSTATE_UINT8(current_direction, OneNANDState),
177 VMSTATE_INT32(cycle, OneNANDState),
178 VMSTATE_INT32(otpmode, OneNANDState),
179 VMSTATE_UINT16_ARRAY(addr, OneNANDState, 8),
180 VMSTATE_UINT16_ARRAY(unladdr, OneNANDState, 8),
181 VMSTATE_INT32(bufaddr, OneNANDState),
182 VMSTATE_INT32(count, OneNANDState),
183 VMSTATE_UINT16(command, OneNANDState),
184 VMSTATE_UINT16_ARRAY(config, OneNANDState, 2),
185 VMSTATE_UINT16(status, OneNANDState),
186 VMSTATE_UINT16(intstatus, OneNANDState),
187 VMSTATE_UINT16(wpstatus, OneNANDState),
188 VMSTATE_INT32(secs_cur, OneNANDState),
189 VMSTATE_PARTIAL_VBUFFER(blockwp, OneNANDState, blocks),
190 VMSTATE_UINT8(ecc.cp, OneNANDState),
191 VMSTATE_UINT16_ARRAY(ecc.lp, OneNANDState, 2),
192 VMSTATE_UINT16(ecc.count, OneNANDState),
193 VMSTATE_BUFFER_POINTER_UNSAFE(otp, OneNANDState, 0,
194 ((64 + 2) << PAGE_SHIFT)),
195 VMSTATE_END_OF_LIST()
199 /* Hot reset (Reset OneNAND command) or warm reset (RP pin low) */
200 static void onenand_reset(OneNANDState *s, int cold)
202 memset(&s->addr, 0, sizeof(s->addr));
203 s->command = 0;
204 s->count = 1;
205 s->bufaddr = 0;
206 s->config[0] = 0x40c0;
207 s->config[1] = 0x0000;
208 onenand_intr_update(s);
209 qemu_irq_raise(s->rdy);
210 s->status = 0x0000;
211 s->intstatus = cold ? 0x8080 : 0x8010;
212 s->unladdr[0] = 0;
213 s->unladdr[1] = 0;
214 s->wpstatus = 0x0002;
215 s->cycle = 0;
216 s->otpmode = 0;
217 s->blk_cur = s->blk;
218 s->current = s->image;
219 s->secs_cur = s->secs;
221 if (cold) {
222 /* Lock the whole flash */
223 memset(s->blockwp, ONEN_LOCK_LOCKED, s->blocks);
225 if (s->blk_cur && blk_read(s->blk_cur, 0, s->boot[0], 8) < 0) {
226 hw_error("%s: Loading the BootRAM failed.\n", __func__);
231 static void onenand_system_reset(DeviceState *dev)
233 OneNANDState *s = ONE_NAND(dev);
235 onenand_reset(s, 1);
238 static inline int onenand_load_main(OneNANDState *s, int sec, int secn,
239 void *dest)
241 if (s->blk_cur) {
242 return blk_read(s->blk_cur, sec, dest, secn) < 0;
243 } else if (sec + secn > s->secs_cur) {
244 return 1;
247 memcpy(dest, s->current + (sec << 9), secn << 9);
249 return 0;
252 static inline int onenand_prog_main(OneNANDState *s, int sec, int secn,
253 void *src)
255 int result = 0;
257 if (secn > 0) {
258 uint32_t size = (uint32_t)secn * 512;
259 const uint8_t *sp = (const uint8_t *)src;
260 uint8_t *dp = 0;
261 if (s->blk_cur) {
262 dp = g_malloc(size);
263 if (!dp || blk_read(s->blk_cur, sec, dp, secn) < 0) {
264 result = 1;
266 } else {
267 if (sec + secn > s->secs_cur) {
268 result = 1;
269 } else {
270 dp = (uint8_t *)s->current + (sec << 9);
273 if (!result) {
274 uint32_t i;
275 for (i = 0; i < size; i++) {
276 dp[i] &= sp[i];
278 if (s->blk_cur) {
279 result = blk_write(s->blk_cur, sec, dp, secn) < 0;
282 if (dp && s->blk_cur) {
283 g_free(dp);
287 return result;
290 static inline int onenand_load_spare(OneNANDState *s, int sec, int secn,
291 void *dest)
293 uint8_t buf[512];
295 if (s->blk_cur) {
296 if (blk_read(s->blk_cur, s->secs_cur + (sec >> 5), buf, 1) < 0) {
297 return 1;
299 memcpy(dest, buf + ((sec & 31) << 4), secn << 4);
300 } else if (sec + secn > s->secs_cur) {
301 return 1;
302 } else {
303 memcpy(dest, s->current + (s->secs_cur << 9) + (sec << 4), secn << 4);
306 return 0;
309 static inline int onenand_prog_spare(OneNANDState *s, int sec, int secn,
310 void *src)
312 int result = 0;
313 if (secn > 0) {
314 const uint8_t *sp = (const uint8_t *)src;
315 uint8_t *dp = 0, *dpp = 0;
316 if (s->blk_cur) {
317 dp = g_malloc(512);
318 if (!dp
319 || blk_read(s->blk_cur, s->secs_cur + (sec >> 5), dp, 1) < 0) {
320 result = 1;
321 } else {
322 dpp = dp + ((sec & 31) << 4);
324 } else {
325 if (sec + secn > s->secs_cur) {
326 result = 1;
327 } else {
328 dpp = s->current + (s->secs_cur << 9) + (sec << 4);
331 if (!result) {
332 uint32_t i;
333 for (i = 0; i < (secn << 4); i++) {
334 dpp[i] &= sp[i];
336 if (s->blk_cur) {
337 result = blk_write(s->blk_cur, s->secs_cur + (sec >> 5),
338 dp, 1) < 0;
341 g_free(dp);
343 return result;
346 static inline int onenand_erase(OneNANDState *s, int sec, int num)
348 uint8_t *blankbuf, *tmpbuf;
349 blankbuf = g_malloc(512);
350 if (!blankbuf) {
351 return 1;
353 tmpbuf = g_malloc(512);
354 if (!tmpbuf) {
355 g_free(blankbuf);
356 return 1;
358 memset(blankbuf, 0xff, 512);
359 for (; num > 0; num--, sec++) {
360 if (s->blk_cur) {
361 int erasesec = s->secs_cur + (sec >> 5);
362 if (blk_write(s->blk_cur, sec, blankbuf, 1) < 0) {
363 goto fail;
365 if (blk_read(s->blk_cur, erasesec, tmpbuf, 1) < 0) {
366 goto fail;
368 memcpy(tmpbuf + ((sec & 31) << 4), blankbuf, 1 << 4);
369 if (blk_write(s->blk_cur, erasesec, tmpbuf, 1) < 0) {
370 goto fail;
372 } else {
373 if (sec + 1 > s->secs_cur) {
374 goto fail;
376 memcpy(s->current + (sec << 9), blankbuf, 512);
377 memcpy(s->current + (s->secs_cur << 9) + (sec << 4),
378 blankbuf, 1 << 4);
382 g_free(tmpbuf);
383 g_free(blankbuf);
384 return 0;
386 fail:
387 g_free(tmpbuf);
388 g_free(blankbuf);
389 return 1;
392 static void onenand_command(OneNANDState *s)
394 int b;
395 int sec;
396 void *buf;
397 #define SETADDR(block, page) \
398 sec = (s->addr[page] & 3) + \
399 ((((s->addr[page] >> 2) & 0x3f) + \
400 (((s->addr[block] & 0xfff) | \
401 (s->addr[block] >> 15 ? \
402 s->density_mask : 0)) << 6)) << (PAGE_SHIFT - 9));
403 #define SETBUF_M() \
404 buf = (s->bufaddr & 8) ? \
405 s->data[(s->bufaddr >> 2) & 1][0] : s->boot[0]; \
406 buf += (s->bufaddr & 3) << 9;
407 #define SETBUF_S() \
408 buf = (s->bufaddr & 8) ? \
409 s->data[(s->bufaddr >> 2) & 1][1] : s->boot[1]; \
410 buf += (s->bufaddr & 3) << 4;
412 switch (s->command) {
413 case 0x00: /* Load single/multiple sector data unit into buffer */
414 SETADDR(ONEN_BUF_BLOCK, ONEN_BUF_PAGE)
416 SETBUF_M()
417 if (onenand_load_main(s, sec, s->count, buf))
418 s->status |= ONEN_ERR_CMD | ONEN_ERR_LOAD;
420 #if 0
421 SETBUF_S()
422 if (onenand_load_spare(s, sec, s->count, buf))
423 s->status |= ONEN_ERR_CMD | ONEN_ERR_LOAD;
424 #endif
426 /* TODO: if (s->bufaddr & 3) + s->count was > 4 (2k-pages)
427 * or if (s->bufaddr & 1) + s->count was > 2 (1k-pages)
428 * then we need two split the read/write into two chunks.
430 s->intstatus |= ONEN_INT | ONEN_INT_LOAD;
431 break;
432 case 0x13: /* Load single/multiple spare sector into buffer */
433 SETADDR(ONEN_BUF_BLOCK, ONEN_BUF_PAGE)
435 SETBUF_S()
436 if (onenand_load_spare(s, sec, s->count, buf))
437 s->status |= ONEN_ERR_CMD | ONEN_ERR_LOAD;
439 /* TODO: if (s->bufaddr & 3) + s->count was > 4 (2k-pages)
440 * or if (s->bufaddr & 1) + s->count was > 2 (1k-pages)
441 * then we need two split the read/write into two chunks.
443 s->intstatus |= ONEN_INT | ONEN_INT_LOAD;
444 break;
445 case 0x80: /* Program single/multiple sector data unit from buffer */
446 SETADDR(ONEN_BUF_BLOCK, ONEN_BUF_PAGE)
448 SETBUF_M()
449 if (onenand_prog_main(s, sec, s->count, buf))
450 s->status |= ONEN_ERR_CMD | ONEN_ERR_PROG;
452 #if 0
453 SETBUF_S()
454 if (onenand_prog_spare(s, sec, s->count, buf))
455 s->status |= ONEN_ERR_CMD | ONEN_ERR_PROG;
456 #endif
458 /* TODO: if (s->bufaddr & 3) + s->count was > 4 (2k-pages)
459 * or if (s->bufaddr & 1) + s->count was > 2 (1k-pages)
460 * then we need two split the read/write into two chunks.
462 s->intstatus |= ONEN_INT | ONEN_INT_PROG;
463 break;
464 case 0x1a: /* Program single/multiple spare area sector from buffer */
465 SETADDR(ONEN_BUF_BLOCK, ONEN_BUF_PAGE)
467 SETBUF_S()
468 if (onenand_prog_spare(s, sec, s->count, buf))
469 s->status |= ONEN_ERR_CMD | ONEN_ERR_PROG;
471 /* TODO: if (s->bufaddr & 3) + s->count was > 4 (2k-pages)
472 * or if (s->bufaddr & 1) + s->count was > 2 (1k-pages)
473 * then we need two split the read/write into two chunks.
475 s->intstatus |= ONEN_INT | ONEN_INT_PROG;
476 break;
477 case 0x1b: /* Copy-back program */
478 SETBUF_S()
480 SETADDR(ONEN_BUF_BLOCK, ONEN_BUF_PAGE)
481 if (onenand_load_main(s, sec, s->count, buf))
482 s->status |= ONEN_ERR_CMD | ONEN_ERR_PROG;
484 SETADDR(ONEN_BUF_DEST_BLOCK, ONEN_BUF_DEST_PAGE)
485 if (onenand_prog_main(s, sec, s->count, buf))
486 s->status |= ONEN_ERR_CMD | ONEN_ERR_PROG;
488 /* TODO: spare areas */
490 s->intstatus |= ONEN_INT | ONEN_INT_PROG;
491 break;
493 case 0x23: /* Unlock NAND array block(s) */
494 s->intstatus |= ONEN_INT;
496 /* XXX the previous (?) area should be locked automatically */
497 for (b = s->unladdr[0]; b <= s->unladdr[1]; b ++) {
498 if (b >= s->blocks) {
499 s->status |= ONEN_ERR_CMD;
500 break;
502 if (s->blockwp[b] == ONEN_LOCK_LOCKTIGHTEN)
503 break;
505 s->wpstatus = s->blockwp[b] = ONEN_LOCK_UNLOCKED;
507 break;
508 case 0x27: /* Unlock All NAND array blocks */
509 s->intstatus |= ONEN_INT;
511 for (b = 0; b < s->blocks; b ++) {
512 if (b >= s->blocks) {
513 s->status |= ONEN_ERR_CMD;
514 break;
516 if (s->blockwp[b] == ONEN_LOCK_LOCKTIGHTEN)
517 break;
519 s->wpstatus = s->blockwp[b] = ONEN_LOCK_UNLOCKED;
521 break;
523 case 0x2a: /* Lock NAND array block(s) */
524 s->intstatus |= ONEN_INT;
526 for (b = s->unladdr[0]; b <= s->unladdr[1]; b ++) {
527 if (b >= s->blocks) {
528 s->status |= ONEN_ERR_CMD;
529 break;
531 if (s->blockwp[b] == ONEN_LOCK_LOCKTIGHTEN)
532 break;
534 s->wpstatus = s->blockwp[b] = ONEN_LOCK_LOCKED;
536 break;
537 case 0x2c: /* Lock-tight NAND array block(s) */
538 s->intstatus |= ONEN_INT;
540 for (b = s->unladdr[0]; b <= s->unladdr[1]; b ++) {
541 if (b >= s->blocks) {
542 s->status |= ONEN_ERR_CMD;
543 break;
545 if (s->blockwp[b] == ONEN_LOCK_UNLOCKED)
546 continue;
548 s->wpstatus = s->blockwp[b] = ONEN_LOCK_LOCKTIGHTEN;
550 break;
552 case 0x71: /* Erase-Verify-Read */
553 s->intstatus |= ONEN_INT;
554 break;
555 case 0x95: /* Multi-block erase */
556 qemu_irq_pulse(s->intr);
557 /* Fall through. */
558 case 0x94: /* Block erase */
559 sec = ((s->addr[ONEN_BUF_BLOCK] & 0xfff) |
560 (s->addr[ONEN_BUF_BLOCK] >> 15 ? s->density_mask : 0))
561 << (BLOCK_SHIFT - 9);
562 if (onenand_erase(s, sec, 1 << (BLOCK_SHIFT - 9)))
563 s->status |= ONEN_ERR_CMD | ONEN_ERR_ERASE;
565 s->intstatus |= ONEN_INT | ONEN_INT_ERASE;
566 break;
567 case 0xb0: /* Erase suspend */
568 break;
569 case 0x30: /* Erase resume */
570 s->intstatus |= ONEN_INT | ONEN_INT_ERASE;
571 break;
573 case 0xf0: /* Reset NAND Flash core */
574 onenand_reset(s, 0);
575 break;
576 case 0xf3: /* Reset OneNAND */
577 onenand_reset(s, 0);
578 break;
580 case 0x65: /* OTP Access */
581 s->intstatus |= ONEN_INT;
582 s->blk_cur = NULL;
583 s->current = s->otp;
584 s->secs_cur = 1 << (BLOCK_SHIFT - 9);
585 s->addr[ONEN_BUF_BLOCK] = 0;
586 s->otpmode = 1;
587 break;
589 default:
590 s->status |= ONEN_ERR_CMD;
591 s->intstatus |= ONEN_INT;
592 fprintf(stderr, "%s: unknown OneNAND command %x\n",
593 __func__, s->command);
596 onenand_intr_update(s);
599 static uint64_t onenand_read(void *opaque, hwaddr addr,
600 unsigned size)
602 OneNANDState *s = (OneNANDState *) opaque;
603 int offset = addr >> s->shift;
605 switch (offset) {
606 case 0x0000 ... 0xc000:
607 return lduw_le_p(s->boot[0] + addr);
609 case 0xf000: /* Manufacturer ID */
610 return s->id.man;
611 case 0xf001: /* Device ID */
612 return s->id.dev;
613 case 0xf002: /* Version ID */
614 return s->id.ver;
615 /* TODO: get the following values from a real chip! */
616 case 0xf003: /* Data Buffer size */
617 return 1 << PAGE_SHIFT;
618 case 0xf004: /* Boot Buffer size */
619 return 0x200;
620 case 0xf005: /* Amount of buffers */
621 return 1 | (2 << 8);
622 case 0xf006: /* Technology */
623 return 0;
625 case 0xf100 ... 0xf107: /* Start addresses */
626 return s->addr[offset - 0xf100];
628 case 0xf200: /* Start buffer */
629 return (s->bufaddr << 8) | ((s->count - 1) & (1 << (PAGE_SHIFT - 10)));
631 case 0xf220: /* Command */
632 return s->command;
633 case 0xf221: /* System Configuration 1 */
634 return s->config[0] & 0xffe0;
635 case 0xf222: /* System Configuration 2 */
636 return s->config[1];
638 case 0xf240: /* Controller Status */
639 return s->status;
640 case 0xf241: /* Interrupt */
641 return s->intstatus;
642 case 0xf24c: /* Unlock Start Block Address */
643 return s->unladdr[0];
644 case 0xf24d: /* Unlock End Block Address */
645 return s->unladdr[1];
646 case 0xf24e: /* Write Protection Status */
647 return s->wpstatus;
649 case 0xff00: /* ECC Status */
650 return 0x00;
651 case 0xff01: /* ECC Result of main area data */
652 case 0xff02: /* ECC Result of spare area data */
653 case 0xff03: /* ECC Result of main area data */
654 case 0xff04: /* ECC Result of spare area data */
655 hw_error("%s: imeplement ECC\n", __FUNCTION__);
656 return 0x0000;
659 fprintf(stderr, "%s: unknown OneNAND register %x\n",
660 __FUNCTION__, offset);
661 return 0;
664 static void onenand_write(void *opaque, hwaddr addr,
665 uint64_t value, unsigned size)
667 OneNANDState *s = (OneNANDState *) opaque;
668 int offset = addr >> s->shift;
669 int sec;
671 switch (offset) {
672 case 0x0000 ... 0x01ff:
673 case 0x8000 ... 0x800f:
674 if (s->cycle) {
675 s->cycle = 0;
677 if (value == 0x0000) {
678 SETADDR(ONEN_BUF_BLOCK, ONEN_BUF_PAGE)
679 onenand_load_main(s, sec,
680 1 << (PAGE_SHIFT - 9), s->data[0][0]);
681 s->addr[ONEN_BUF_PAGE] += 4;
682 s->addr[ONEN_BUF_PAGE] &= 0xff;
684 break;
687 switch (value) {
688 case 0x00f0: /* Reset OneNAND */
689 onenand_reset(s, 0);
690 break;
692 case 0x00e0: /* Load Data into Buffer */
693 s->cycle = 1;
694 break;
696 case 0x0090: /* Read Identification Data */
697 memset(s->boot[0], 0, 3 << s->shift);
698 s->boot[0][0 << s->shift] = s->id.man & 0xff;
699 s->boot[0][1 << s->shift] = s->id.dev & 0xff;
700 s->boot[0][2 << s->shift] = s->wpstatus & 0xff;
701 break;
703 default:
704 fprintf(stderr, "%s: unknown OneNAND boot command %"PRIx64"\n",
705 __FUNCTION__, value);
707 break;
709 case 0xf100 ... 0xf107: /* Start addresses */
710 s->addr[offset - 0xf100] = value;
711 break;
713 case 0xf200: /* Start buffer */
714 s->bufaddr = (value >> 8) & 0xf;
715 if (PAGE_SHIFT == 11)
716 s->count = (value & 3) ?: 4;
717 else if (PAGE_SHIFT == 10)
718 s->count = (value & 1) ?: 2;
719 break;
721 case 0xf220: /* Command */
722 if (s->intstatus & (1 << 15))
723 break;
724 s->command = value;
725 onenand_command(s);
726 break;
727 case 0xf221: /* System Configuration 1 */
728 s->config[0] = value;
729 onenand_intr_update(s);
730 qemu_set_irq(s->rdy, (s->config[0] >> 7) & 1);
731 break;
732 case 0xf222: /* System Configuration 2 */
733 s->config[1] = value;
734 break;
736 case 0xf241: /* Interrupt */
737 s->intstatus &= value;
738 if ((1 << 15) & ~s->intstatus)
739 s->status &= ~(ONEN_ERR_CMD | ONEN_ERR_ERASE |
740 ONEN_ERR_PROG | ONEN_ERR_LOAD);
741 onenand_intr_update(s);
742 break;
743 case 0xf24c: /* Unlock Start Block Address */
744 s->unladdr[0] = value & (s->blocks - 1);
745 /* For some reason we have to set the end address to by default
746 * be same as start because the software forgets to write anything
747 * in there. */
748 s->unladdr[1] = value & (s->blocks - 1);
749 break;
750 case 0xf24d: /* Unlock End Block Address */
751 s->unladdr[1] = value & (s->blocks - 1);
752 break;
754 default:
755 fprintf(stderr, "%s: unknown OneNAND register %x\n",
756 __FUNCTION__, offset);
760 static const MemoryRegionOps onenand_ops = {
761 .read = onenand_read,
762 .write = onenand_write,
763 .endianness = DEVICE_NATIVE_ENDIAN,
766 static int onenand_initfn(SysBusDevice *sbd)
768 DeviceState *dev = DEVICE(sbd);
769 OneNANDState *s = ONE_NAND(dev);
770 uint32_t size = 1 << (24 + ((s->id.dev >> 4) & 7));
771 void *ram;
773 s->base = (hwaddr)-1;
774 s->rdy = NULL;
775 s->blocks = size >> BLOCK_SHIFT;
776 s->secs = size >> 9;
777 s->blockwp = g_malloc(s->blocks);
778 s->density_mask = (s->id.dev & 0x08)
779 ? (1 << (6 + ((s->id.dev >> 4) & 7))) : 0;
780 memory_region_init_io(&s->iomem, OBJECT(s), &onenand_ops, s, "onenand",
781 0x10000 << s->shift);
782 if (!s->blk) {
783 s->image = memset(g_malloc(size + (size >> 5)),
784 0xff, size + (size >> 5));
785 } else {
786 if (blk_is_read_only(s->blk)) {
787 error_report("Can't use a read-only drive");
788 return -1;
790 s->blk_cur = s->blk;
792 s->otp = memset(g_malloc((64 + 2) << PAGE_SHIFT),
793 0xff, (64 + 2) << PAGE_SHIFT);
794 memory_region_init_ram(&s->ram, OBJECT(s), "onenand.ram",
795 0xc000 << s->shift, &error_abort);
796 vmstate_register_ram_global(&s->ram);
797 ram = memory_region_get_ram_ptr(&s->ram);
798 s->boot[0] = ram + (0x0000 << s->shift);
799 s->boot[1] = ram + (0x8000 << s->shift);
800 s->data[0][0] = ram + ((0x0200 + (0 << (PAGE_SHIFT - 1))) << s->shift);
801 s->data[0][1] = ram + ((0x8010 + (0 << (PAGE_SHIFT - 6))) << s->shift);
802 s->data[1][0] = ram + ((0x0200 + (1 << (PAGE_SHIFT - 1))) << s->shift);
803 s->data[1][1] = ram + ((0x8010 + (1 << (PAGE_SHIFT - 6))) << s->shift);
804 onenand_mem_setup(s);
805 sysbus_init_irq(sbd, &s->intr);
806 sysbus_init_mmio(sbd, &s->container);
807 vmstate_register(dev,
808 ((s->shift & 0x7f) << 24)
809 | ((s->id.man & 0xff) << 16)
810 | ((s->id.dev & 0xff) << 8)
811 | (s->id.ver & 0xff),
812 &vmstate_onenand, s);
813 return 0;
816 static Property onenand_properties[] = {
817 DEFINE_PROP_UINT16("manufacturer_id", OneNANDState, id.man, 0),
818 DEFINE_PROP_UINT16("device_id", OneNANDState, id.dev, 0),
819 DEFINE_PROP_UINT16("version_id", OneNANDState, id.ver, 0),
820 DEFINE_PROP_INT32("shift", OneNANDState, shift, 0),
821 DEFINE_PROP_DRIVE("drive", OneNANDState, blk),
822 DEFINE_PROP_END_OF_LIST(),
825 static void onenand_class_init(ObjectClass *klass, void *data)
827 DeviceClass *dc = DEVICE_CLASS(klass);
828 SysBusDeviceClass *k = SYS_BUS_DEVICE_CLASS(klass);
830 k->init = onenand_initfn;
831 dc->reset = onenand_system_reset;
832 dc->props = onenand_properties;
835 static const TypeInfo onenand_info = {
836 .name = TYPE_ONE_NAND,
837 .parent = TYPE_SYS_BUS_DEVICE,
838 .instance_size = sizeof(OneNANDState),
839 .class_init = onenand_class_init,
842 static void onenand_register_types(void)
844 type_register_static(&onenand_info);
847 void *onenand_raw_otp(DeviceState *onenand_device)
849 OneNANDState *s = ONE_NAND(onenand_device);
851 return s->otp;
854 type_init(onenand_register_types)