1 /*
2  * Driver for NAND support, Rick Bronson
3  * borrowed heavily from:
4  * (c) 1999 Machine Vision Holdings, Inc.
5  * (c) 1999, 2000 David Woodhouse <dwmw2@infradead.org>
6  *
7  * Ported 'dynenv' to 'nand env.oob' command
8  * (C) 2010 Nanometrics, Inc.
9  * 'dynenv' -- Dynamic environment offset in NAND OOB
10  * (C) Copyright 2006-2007 OpenMoko, Inc.
11  * Added 16-bit nand support
12  * (C) 2004 Texas Instruments
13  *
14  * Copyright 2010, 2012 Freescale Semiconductor
15  * The portions of this file whose copyright is held by Freescale and which
16  * are not considered a derived work of GPL v2-only code may be distributed
17  * and/or modified under the terms of the GNU General Public License as
18  * published by the Free Software Foundation; either version 2 of the
19  * License, or (at your option) any later version.
20  *
21  * The function nand_biterror() in this file is inspired from
22  * mtd-utils/nand-utils/nandflipbits.c which was released under GPLv2
23  * only
24  */
25 
26 #include <bootstage.h>
27 #include <image.h>
28 #include <asm/cache.h>
29 #include <linux/mtd/mtd.h>
30 #include <linux/mtd/rawnand.h>
31 #include <command.h>
32 #include <console.h>
33 #include <env.h>
34 #include <watchdog.h>
35 #include <malloc.h>
36 #include <mapmem.h>
37 #include <asm/byteorder.h>
38 #include <jffs2/jffs2.h>
39 #include <nand.h>
40 
41 #include "legacy-mtd-utils.h"
42 
43 #if defined(CONFIG_CMD_MTDPARTS)
44 
45 /* partition handling routines */
46 int mtdparts_init(void);
47 int find_dev_and_part(const char *id, struct mtd_device **dev,
48 		      u8 *part_num, struct part_info **part);
49 #endif
50 
51 #define MAX_NUM_PAGES 64
52 
nand_biterror(struct mtd_info * mtd,ulong off,int bit)53 static int nand_biterror(struct mtd_info *mtd, ulong off, int bit)
54 {
55 	int ret = 0;
56 	int page = 0;
57 	ulong  block_off;
58 	u_char *datbuf[MAX_NUM_PAGES]; /* Data and OOB */
59 	u_char data;
60 	int pages_per_blk = mtd->erasesize / mtd->writesize;
61 	struct erase_info einfo;
62 
63 	if (pages_per_blk > MAX_NUM_PAGES) {
64 		printf("Too many pages in one erase block\n");
65 		return 1;
66 	}
67 
68 	if (bit < 0 || bit > 7) {
69 		printf("bit position 0 to 7 is allowed\n");
70 		return 1;
71 	}
72 
73 	/* Allocate memory */
74 	memset(datbuf, 0, sizeof(datbuf));
75 	for (page = 0; page < pages_per_blk ; page++) {
76 		datbuf[page] = malloc(mtd->writesize + mtd->oobsize);
77 		if (!datbuf[page]) {
78 			printf("No memory for page buffer\n");
79 			ret = -ENOMEM;
80 			goto free_memory;
81 		}
82 	}
83 
84 	/* Align to erase block boundary */
85 	block_off = off & (~(mtd->erasesize - 1));
86 
87 	/* Read out memory as first step */
88 	for (page = 0; page < pages_per_blk ; page++) {
89 		struct mtd_oob_ops ops;
90 		loff_t addr = (loff_t)block_off;
91 
92 		memset(&ops, 0, sizeof(ops));
93 		ops.datbuf = datbuf[page];
94 		ops.oobbuf = datbuf[page] + mtd->writesize;
95 		ops.len = mtd->writesize;
96 		ops.ooblen = mtd->oobsize;
97 		ops.mode = MTD_OPS_RAW;
98 		ret = mtd_read_oob(mtd, addr, &ops);
99 		if (ret < 0) {
100 			printf("Error (%d) reading page %08lx\n",
101 			       ret, block_off);
102 			ret = 1;
103 			goto free_memory;
104 		}
105 		block_off += mtd->writesize;
106 	}
107 
108 	/* Erase the block */
109 	memset(&einfo, 0, sizeof(einfo));
110 	einfo.mtd = mtd;
111 	/* Align to erase block boundary */
112 	einfo.addr = (loff_t)(off & (~(mtd->erasesize - 1)));
113 	einfo.len = mtd->erasesize;
114 	ret = mtd_erase(mtd, &einfo);
115 	if (ret < 0) {
116 		printf("Error (%d) nand_erase_nand page %08llx\n",
117 		       ret, einfo.addr);
118 		ret = 1;
119 		goto free_memory;
120 	}
121 
122 	/* Twist a bit in data part */
123 	block_off = off & (mtd->erasesize - 1);
124 	data = datbuf[block_off / mtd->writesize][block_off % mtd->writesize];
125 	data ^= (1 << bit);
126 	datbuf[block_off / mtd->writesize][block_off % mtd->writesize] = data;
127 
128 	printf("Flip data at 0x%lx with xor 0x%02x (bit=%d) to value=0x%02x\n",
129 	       off, (1 << bit), bit, data);
130 
131 	/* Write back twisted data and unmodified OOB */
132 	/* Align to erase block boundary */
133 	block_off = off & (~(mtd->erasesize - 1));
134 	for (page = 0; page < pages_per_blk; page++) {
135 		struct mtd_oob_ops ops;
136 		loff_t addr = (loff_t)block_off;
137 
138 		memset(&ops, 0, sizeof(ops));
139 		ops.datbuf = datbuf[page];
140 		ops.oobbuf = datbuf[page] + mtd->writesize;
141 		ops.len = mtd->writesize;
142 		ops.ooblen = mtd->oobsize;
143 		ops.mode = MTD_OPS_RAW;
144 		ret = mtd_write_oob(mtd, addr, &ops);
145 		if (ret < 0) {
146 			printf("Error (%d) write page %08lx\n", ret, block_off);
147 			ret = 1;
148 			goto free_memory;
149 		}
150 		block_off += mtd->writesize;
151 	}
152 
153 free_memory:
154 	for (page = 0; page < pages_per_blk ; page++) {
155 		if (datbuf[page])
156 			free(datbuf[page]);
157 	}
158 	return ret;
159 }
160 
nand_dump(struct mtd_info * mtd,ulong off,int only_oob,int repeat)161 static int nand_dump(struct mtd_info *mtd, ulong off, int only_oob,
162 		     int repeat)
163 {
164 	int i;
165 	u_char *datbuf, *oobbuf, *p;
166 	static loff_t last;
167 	int ret = 0;
168 
169 	if (repeat)
170 		off = last + mtd->writesize;
171 
172 	last = off;
173 
174 	datbuf = memalign(ARCH_DMA_MINALIGN, mtd->writesize);
175 	if (!datbuf) {
176 		puts("No memory for page buffer\n");
177 		return 1;
178 	}
179 
180 	oobbuf = memalign(ARCH_DMA_MINALIGN, mtd->oobsize);
181 	if (!oobbuf) {
182 		puts("No memory for page buffer\n");
183 		ret = 1;
184 		goto free_dat;
185 	}
186 	off &= ~(mtd->writesize - 1);
187 	loff_t addr = (loff_t) off;
188 	struct mtd_oob_ops ops;
189 	memset(&ops, 0, sizeof(ops));
190 	ops.datbuf = datbuf;
191 	ops.oobbuf = oobbuf;
192 	ops.len = mtd->writesize;
193 	ops.ooblen = mtd->oobsize;
194 	ops.mode = MTD_OPS_RAW;
195 	i = mtd_read_oob(mtd, addr, &ops);
196 	if (i < 0) {
197 		printf("Error (%d) reading page %08lx\n", i, off);
198 		ret = 1;
199 		goto free_all;
200 	}
201 	printf("Page %08lx dump:\n", off);
202 
203 	if (!only_oob) {
204 		i = mtd->writesize >> 4;
205 		p = datbuf;
206 
207 		while (i--) {
208 			printf("\t%02x %02x %02x %02x %02x %02x %02x %02x"
209 			       "  %02x %02x %02x %02x %02x %02x %02x %02x\n",
210 			       p[0], p[1], p[2], p[3], p[4], p[5], p[6], p[7],
211 			       p[8], p[9], p[10], p[11], p[12], p[13], p[14],
212 			       p[15]);
213 			p += 16;
214 		}
215 	}
216 
217 	puts("OOB:\n");
218 	i = mtd->oobsize >> 3;
219 	p = oobbuf;
220 	while (i--) {
221 		printf("\t%02x %02x %02x %02x %02x %02x %02x %02x\n",
222 		       p[0], p[1], p[2], p[3], p[4], p[5], p[6], p[7]);
223 		p += 8;
224 	}
225 
226 free_all:
227 	free(oobbuf);
228 free_dat:
229 	free(datbuf);
230 
231 	return ret;
232 }
233 
234 #ifdef CONFIG_CMD_NAND_WATCH
nand_watch_bf(struct mtd_info * mtd,ulong off,ulong size,bool quiet)235 static int nand_watch_bf(struct mtd_info *mtd, ulong off, ulong size, bool quiet)
236 {
237 	unsigned int max_bf = 0, pages_wbf = 0;
238 	unsigned int first_page, pages, i;
239 	struct mtd_oob_ops ops = {};
240 	u_char *buf;
241 	int ret;
242 
243 	buf = memalign(ARCH_DMA_MINALIGN, mtd->writesize);
244 	if (!buf) {
245 		puts("No memory for page buffer\n");
246 		return 1;
247 	}
248 
249 	first_page = off / mtd->writesize;
250 	pages = size / mtd->writesize;
251 
252 	ops.datbuf = buf;
253 	ops.len = mtd->writesize;
254 	for (i = first_page; i < first_page + pages; i++) {
255 		ulong addr = mtd->writesize * i;
256 		ret = mtd_read_oob_bf(mtd, addr, &ops);
257 		if (ret < 0) {
258 			if (quiet)
259 				continue;
260 
261 			printf("Page %7d (0x%08lx) -> error %d\n",
262 			       i, addr, ret);
263 		} else if (ret) {
264 			max_bf = max(max_bf, (unsigned int)ret);
265 			pages_wbf++;
266 			if (quiet)
267 				continue;
268 			printf("Page %7d (0x%08lx) -> up to %2d bf/chunk\n",
269 			       i, addr, ret);
270 		}
271 	}
272 
273 	printf("Maximum number of bitflips: %u\n", max_bf);
274 	printf("Pages with bitflips: %u/%u\n", pages_wbf, pages);
275 
276 	free(buf);
277 
278 	return 0;
279 }
280 #endif
281 
282 /* ------------------------------------------------------------------------- */
283 
set_dev(int dev)284 static int set_dev(int dev)
285 {
286 	struct mtd_info *mtd = get_nand_dev_by_index(dev);
287 
288 	if (!mtd)
289 		return -ENODEV;
290 
291 	if (nand_curr_device == dev)
292 		return 0;
293 
294 	printf("Device %d: %s", dev, mtd->name);
295 	puts("... is now current device\n");
296 	nand_curr_device = dev;
297 
298 #ifdef CONFIG_SYS_NAND_SELECT_DEVICE
299 	board_nand_select_device(mtd_to_nand(mtd), dev);
300 #endif
301 
302 	return 0;
303 }
304 
305 #ifdef CONFIG_CMD_NAND_LOCK_UNLOCK
print_status(ulong start,ulong end,ulong erasesize,int status)306 static void print_status(ulong start, ulong end, ulong erasesize, int status)
307 {
308 	/*
309 	 * Micron NAND flash (e.g. MT29F4G08ABADAH4) BLOCK LOCK READ STATUS is
310 	 * not the same as others.  Instead of bit 1 being lock, it is
311 	 * #lock_tight. To make the driver support either format, ignore bit 1
312 	 * and use only bit 0 and bit 2.
313 	 */
314 	printf("%08lx - %08lx: %08lx blocks %s%s%s\n",
315 		start,
316 		end - 1,
317 		(end - start) / erasesize,
318 		((status & NAND_LOCK_STATUS_TIGHT) ?  "TIGHT " : ""),
319 		(!(status & NAND_LOCK_STATUS_UNLOCK) ?  "LOCK " : ""),
320 		((status & NAND_LOCK_STATUS_UNLOCK) ?  "UNLOCK " : ""));
321 }
322 
do_nand_status(struct mtd_info * mtd)323 static void do_nand_status(struct mtd_info *mtd)
324 {
325 	ulong block_start = 0;
326 	ulong off;
327 	int last_status = -1;
328 
329 	struct nand_chip *nand_chip = mtd_to_nand(mtd);
330 	/* check the WP bit */
331 	nand_chip->cmdfunc(mtd, NAND_CMD_STATUS, -1, -1);
332 	printf("device is %swrite protected\n",
333 		(nand_chip->read_byte(mtd) & 0x80 ?
334 		 "NOT " : ""));
335 
336 	for (off = 0; off < mtd->size; off += mtd->erasesize) {
337 		int s = nand_get_lock_status(mtd, off);
338 
339 		/* print message only if status has changed */
340 		if (s != last_status && off != 0) {
341 			print_status(block_start, off, mtd->erasesize,
342 					last_status);
343 			block_start = off;
344 		}
345 		last_status = s;
346 	}
347 	/* Print the last block info */
348 	print_status(block_start, off, mtd->erasesize, last_status);
349 }
350 #endif
351 
352 #ifdef CONFIG_ENV_OFFSET_OOB
353 unsigned long nand_env_oob_offset;
354 
do_nand_env_oob(struct cmd_tbl * cmdtp,int argc,char * const argv[])355 int do_nand_env_oob(struct cmd_tbl *cmdtp, int argc, char *const argv[])
356 {
357 	int ret;
358 	uint32_t oob_buf[ENV_OFFSET_SIZE/sizeof(uint32_t)];
359 	struct mtd_info *mtd = get_nand_dev_by_index(0);
360 	char *cmd = argv[1];
361 
362 	if (CONFIG_SYS_MAX_NAND_DEVICE == 0 || !mtd) {
363 		puts("no devices available\n");
364 		return 1;
365 	}
366 
367 	set_dev(0);
368 
369 	if (!strcmp(cmd, "get")) {
370 		ret = get_nand_env_oob(mtd, &nand_env_oob_offset);
371 		if (ret)
372 			return 1;
373 
374 		printf("0x%08lx\n", nand_env_oob_offset);
375 	} else if (!strcmp(cmd, "set")) {
376 		loff_t addr;
377 		loff_t maxsize;
378 		struct mtd_oob_ops ops;
379 		int idx = 0;
380 
381 		if (argc < 3)
382 			goto usage;
383 
384 		mtd = get_nand_dev_by_index(idx);
385 		/* We don't care about size, or maxsize. */
386 		if (mtd_arg_off(argv[2], &idx, &addr, &maxsize, &maxsize,
387 				MTD_DEV_TYPE_NAND, mtd->size)) {
388 			puts("Offset or partition name expected\n");
389 			return 1;
390 		}
391 		if (set_dev(idx)) {
392 			puts("Offset or partition name expected\n");
393 			return 1;
394 		}
395 
396 		if (idx != 0) {
397 			puts("Partition not on first NAND device\n");
398 			return 1;
399 		}
400 
401 		if (mtd->oobavail < ENV_OFFSET_SIZE) {
402 			printf("Insufficient available OOB bytes:\n"
403 			       "%d OOB bytes available but %d required for "
404 			       "env.oob support\n",
405 			       mtd->oobavail, ENV_OFFSET_SIZE);
406 			return 1;
407 		}
408 
409 		if ((addr & (mtd->erasesize - 1)) != 0) {
410 			printf("Environment offset must be block-aligned\n");
411 			return 1;
412 		}
413 
414 		ops.datbuf = NULL;
415 		ops.mode = MTD_OOB_AUTO;
416 		ops.ooboffs = 0;
417 		ops.ooblen = ENV_OFFSET_SIZE;
418 		ops.oobbuf = (void *) oob_buf;
419 
420 		oob_buf[0] = ENV_OOB_MARKER;
421 		oob_buf[1] = addr / mtd->erasesize;
422 
423 		ret = mtd->write_oob(mtd, ENV_OFFSET_SIZE, &ops);
424 		if (ret) {
425 			printf("Error writing OOB block 0\n");
426 			return ret;
427 		}
428 
429 		ret = get_nand_env_oob(mtd, &nand_env_oob_offset);
430 		if (ret) {
431 			printf("Error reading env offset in OOB\n");
432 			return ret;
433 		}
434 
435 		if (addr != nand_env_oob_offset) {
436 			printf("Verification of env offset in OOB failed: "
437 			       "0x%08llx expected but got 0x%08lx\n",
438 			       (unsigned long long)addr, nand_env_oob_offset);
439 			return 1;
440 		}
441 	} else {
442 		goto usage;
443 	}
444 
445 	return ret;
446 
447 usage:
448 	return CMD_RET_USAGE;
449 }
450 
451 #endif
452 
nand_print_and_set_info(int idx)453 static void nand_print_and_set_info(int idx)
454 {
455 	struct mtd_info *mtd;
456 	struct nand_chip *chip;
457 
458 	mtd = get_nand_dev_by_index(idx);
459 	if (!mtd)
460 		return;
461 
462 	chip = mtd_to_nand(mtd);
463 	printf("Device %d: ", idx);
464 	if (chip->numchips > 1)
465 		printf("%dx ", chip->numchips);
466 	printf("%s, sector size %u KiB\n",
467 	       mtd->name, mtd->erasesize >> 10);
468 	printf("  Page size     %8d b\n", mtd->writesize);
469 	printf("  OOB size      %8d b\n", mtd->oobsize);
470 	printf("  Erase size    %8d b\n", mtd->erasesize);
471 	printf("  ecc strength  %8d bits\n", mtd->ecc_strength);
472 	printf("  ecc step size %8d b\n", mtd->ecc_step_size);
473 	printf("  subpagesize   %8d b\n", chip->subpagesize);
474 	printf("  options       0x%08x\n", chip->options);
475 	printf("  bbt options   0x%08x\n", chip->bbt_options);
476 
477 	/* Set geometry info */
478 	env_set_hex("nand_writesize", mtd->writesize);
479 	env_set_hex("nand_oobsize", mtd->oobsize);
480 	env_set_hex("nand_erasesize", mtd->erasesize);
481 }
482 
raw_access(struct mtd_info * mtd,void * buf,loff_t off,ulong count,int read,int no_verify)483 static int raw_access(struct mtd_info *mtd, void *buf, loff_t off,
484 		      ulong count, int read, int no_verify)
485 {
486 	int ret = 0;
487 
488 	while (count--) {
489 		/* Raw access */
490 		mtd_oob_ops_t ops = {
491 			.datbuf = buf,
492 			.oobbuf = buf + mtd->writesize,
493 			.len = mtd->writesize,
494 			.ooblen = mtd->oobsize,
495 			.mode = MTD_OPS_RAW
496 		};
497 
498 		if (read) {
499 			ret = mtd_read_oob(mtd, off, &ops);
500 		} else {
501 			ret = mtd_write_oob(mtd, off, &ops);
502 			if (!ret && !no_verify)
503 				ret = nand_verify_page_oob(mtd, &ops, off);
504 		}
505 
506 		if (ret) {
507 			printf("%s: error at offset %llx, ret %d\n",
508 				__func__, (long long)off, ret);
509 			break;
510 		}
511 
512 		buf += mtd->writesize + mtd->oobsize;
513 		off += mtd->writesize;
514 	}
515 
516 	return ret;
517 }
518 
519 /* Adjust a chip/partition size down for bad blocks so we don't
520  * read/write past the end of a chip/partition by accident.
521  */
adjust_size_for_badblocks(loff_t * size,loff_t offset,int dev)522 static void adjust_size_for_badblocks(loff_t *size, loff_t offset, int dev)
523 {
524 	/* We grab the nand info object here fresh because this is usually
525 	 * called after arg_off_size() which can change the value of dev.
526 	 */
527 	struct mtd_info *mtd = get_nand_dev_by_index(dev);
528 	loff_t maxoffset = offset + *size;
529 	int badblocks = 0;
530 
531 	/* count badblocks in NAND from offset to offset + size */
532 	for (; offset < maxoffset; offset += mtd->erasesize) {
533 		if (nand_block_isbad(mtd, offset))
534 			badblocks++;
535 	}
536 	/* adjust size if any bad blocks found */
537 	if (badblocks) {
538 		*size -= badblocks * mtd->erasesize;
539 		printf("size adjusted to 0x%llx (%d bad blocks)\n",
540 		       (unsigned long long)*size, badblocks);
541 	}
542 }
543 
do_nand(struct cmd_tbl * cmdtp,int flag,int argc,char * const argv[])544 static int do_nand(struct cmd_tbl *cmdtp, int flag, int argc,
545 		   char *const argv[])
546 {
547 	int i, ret = 0;
548 	ulong addr;
549 	loff_t off, size, maxsize;
550 	char *cmd, *s;
551 	struct mtd_info *mtd;
552 #ifdef CONFIG_SYS_NAND_QUIET
553 	int quiet = CONFIG_SYS_NAND_QUIET;
554 #else
555 	int quiet = 0;
556 #endif
557 	const char *quiet_str = env_get("quiet");
558 	int dev = nand_curr_device;
559 	int repeat = flag & CMD_FLAG_REPEAT;
560 
561 	/* at least two arguments please */
562 	if (argc < 2)
563 		goto usage;
564 
565 	if (quiet_str)
566 		quiet = simple_strtoul(quiet_str, NULL, 0) != 0;
567 
568 	cmd = argv[1];
569 
570 	/* Only "dump" is repeatable. */
571 	if (repeat && strcmp(cmd, "dump"))
572 		return 0;
573 
574 	if (strcmp(cmd, "info") == 0) {
575 
576 		putc('\n');
577 		for (i = 0; i < CONFIG_SYS_MAX_NAND_DEVICE; i++)
578 			nand_print_and_set_info(i);
579 		return 0;
580 	}
581 
582 	if (strcmp(cmd, "device") == 0) {
583 		if (argc < 3) {
584 			putc('\n');
585 			if (dev < 0 || dev >= CONFIG_SYS_MAX_NAND_DEVICE)
586 				puts("no devices available\n");
587 			else
588 				nand_print_and_set_info(dev);
589 			return 0;
590 		}
591 
592 		dev = (int)dectoul(argv[2], NULL);
593 		set_dev(dev);
594 
595 		return 0;
596 	}
597 
598 #ifdef CONFIG_ENV_OFFSET_OOB
599 	/* this command operates only on the first nand device */
600 	if (strcmp(cmd, "env.oob") == 0)
601 		return do_nand_env_oob(cmdtp, argc - 1, argv + 1);
602 #endif
603 
604 	/* The following commands operate on the current device, unless
605 	 * overridden by a partition specifier.  Note that if somehow the
606 	 * current device is invalid, it will have to be changed to a valid
607 	 * one before these commands can run, even if a partition specifier
608 	 * for another device is to be used.
609 	 */
610 	mtd = get_nand_dev_by_index(dev);
611 	if (!mtd) {
612 		puts("\nno devices available\n");
613 		return 1;
614 	}
615 
616 	if (strcmp(cmd, "bad") == 0) {
617 		printf("\nDevice %d bad blocks:\n", dev);
618 		for (off = 0; off < mtd->size; off += mtd->erasesize) {
619 			ret = nand_block_isbad(mtd, off);
620 			if (ret)
621 				printf("  0x%08llx%s\n", (unsigned long long)off,
622 				       ret == 2 ? "\t (bbt reserved)" : "");
623 		}
624 		return 0;
625 	}
626 
627 	/*
628 	 * Syntax is:
629 	 *   0    1     2       3    4
630 	 *   nand erase [clean] [off size]
631 	 */
632 	if (strncmp(cmd, "erase", 5) == 0 || strncmp(cmd, "scrub", 5) == 0) {
633 		nand_erase_options_t opts;
634 		/* "clean" at index 2 means request to write cleanmarker */
635 		int clean = argc > 2 && !strcmp("clean", argv[2]);
636 		int scrub_yes = argc > 2 && !strcmp("-y", argv[2]);
637 		int o = (clean || scrub_yes) ? 3 : 2;
638 		int scrub = !strncmp(cmd, "scrub", 5);
639 		int spread = 0;
640 		int args = 2;
641 		const char *scrub_warn =
642 			"Warning: "
643 			"scrub option will erase all factory set bad blocks!\n"
644 			"         "
645 			"There is no reliable way to recover them.\n"
646 			"         "
647 			"Use this command only for testing purposes if you\n"
648 			"         "
649 			"are sure of what you are doing!\n"
650 			"\nReally scrub this NAND flash? <y/N>\n";
651 
652 		if (cmd[5] != 0) {
653 			if (!strcmp(&cmd[5], ".spread")) {
654 				spread = 1;
655 			} else if (!strcmp(&cmd[5], ".part")) {
656 				args = 1;
657 			} else if (!strcmp(&cmd[5], ".chip")) {
658 				args = 0;
659 			} else {
660 				goto usage;
661 			}
662 		}
663 
664 		/*
665 		 * Don't allow missing arguments to cause full chip/partition
666 		 * erases -- easy to do accidentally, e.g. with a misspelled
667 		 * variable name.
668 		 */
669 		if (argc != o + args)
670 			goto usage;
671 
672 		printf("\nNAND %s: ", cmd);
673 		/* skip first two or three arguments, look for offset and size */
674 		if (mtd_arg_off_size(argc - o, argv + o, &dev, &off, &size,
675 				     &maxsize, MTD_DEV_TYPE_NAND,
676 				     mtd->size) != 0)
677 			return 1;
678 
679 		if (set_dev(dev))
680 			return 1;
681 
682 		mtd = get_nand_dev_by_index(dev);
683 
684 		memset(&opts, 0, sizeof(opts));
685 		opts.offset = off;
686 		opts.length = size;
687 		opts.jffs2  = clean;
688 		opts.quiet  = quiet;
689 		opts.spread = spread;
690 
691 		if (scrub) {
692 			if (scrub_yes) {
693 				opts.scrub = 1;
694 			} else {
695 				puts(scrub_warn);
696 				if (confirm_yesno()) {
697 					opts.scrub = 1;
698 				} else {
699 					puts("scrub aborted\n");
700 					return 1;
701 				}
702 			}
703 		}
704 		ret = nand_erase_opts(mtd, &opts);
705 		printf("%s\n", ret ? "ERROR" : "OK");
706 
707 		return ret == 0 ? 0 : 1;
708 	}
709 
710 	if (strncmp(cmd, "dump", 4) == 0) {
711 		if (argc < 3)
712 			goto usage;
713 
714 		off = (int)hextoul(argv[2], NULL);
715 		ret = nand_dump(mtd, off, !strcmp(&cmd[4], ".oob"), repeat);
716 
717 		return ret == 0 ? 1 : 0;
718 	}
719 
720 	if (strncmp(cmd, "read", 4) == 0 || strncmp(cmd, "write", 5) == 0) {
721 		size_t rwsize;
722 		ulong pagecount = 1;
723 		int read;
724 		int raw = 0;
725 		int no_verify = 0;
726 		void *buf;
727 
728 		if (argc < 4)
729 			goto usage;
730 
731 		addr = (ulong)hextoul(argv[2], NULL);
732 
733 		read = strncmp(cmd, "read", 4) == 0; /* 1 = read, 0 = write */
734 		printf("\nNAND %s: ", read ? "read" : "write");
735 
736 		s = strchr(cmd, '.');
737 
738 		if (s && !strncmp(s, ".raw", 4)) {
739 			raw = 1;
740 
741 			if (!strcmp(s, ".raw.noverify"))
742 				no_verify = 1;
743 
744 			if (mtd_arg_off(argv[3], &dev, &off, &size, &maxsize,
745 					MTD_DEV_TYPE_NAND,
746 					mtd->size))
747 				return 1;
748 
749 			if (set_dev(dev))
750 				return 1;
751 
752 			mtd = get_nand_dev_by_index(dev);
753 
754 			if (argc > 4 && !str2long(argv[4], &pagecount)) {
755 				printf("'%s' is not a number\n", argv[4]);
756 				return 1;
757 			}
758 
759 			if (pagecount * mtd->writesize > size) {
760 				puts("Size exceeds partition or device limit\n");
761 				return -1;
762 			}
763 
764 			rwsize = pagecount * (mtd->writesize + mtd->oobsize);
765 		} else {
766 			if (mtd_arg_off_size(argc - 3, argv + 3, &dev, &off,
767 					     &size, &maxsize,
768 					     MTD_DEV_TYPE_NAND,
769 					     mtd->size) != 0)
770 				return 1;
771 
772 			if (set_dev(dev))
773 				return 1;
774 
775 			/* size is unspecified */
776 			if (argc < 5)
777 				adjust_size_for_badblocks(&size, off, dev);
778 			rwsize = size;
779 		}
780 
781 		mtd = get_nand_dev_by_index(dev);
782 		buf = map_sysmem(addr, maxsize);
783 
784 		if (!s || !strcmp(s, ".jffs2") ||
785 		    !strcmp(s, ".e") || !strcmp(s, ".i")) {
786 			if (read)
787 				ret = nand_read_skip_bad(mtd, off, &rwsize,
788 							 NULL, maxsize, buf);
789 			else
790 				ret = nand_write_skip_bad(mtd, off, &rwsize,
791 							  NULL, maxsize, buf,
792 							  WITH_WR_VERIFY);
793 #ifdef CONFIG_CMD_NAND_TRIMFFS
794 		} else if (!strcmp(s, ".trimffs")) {
795 			if (read) {
796 				printf("Unknown nand command suffix '%s'\n", s);
797 				unmap_sysmem(buf);
798 				return 1;
799 			}
800 			ret = nand_write_skip_bad(mtd, off, &rwsize, NULL,
801 						maxsize, buf,
802 						WITH_DROP_FFS | WITH_WR_VERIFY);
803 #endif
804 		} else if (!strcmp(s, ".oob")) {
805 			/* out-of-band data */
806 			mtd_oob_ops_t ops = {
807 				.oobbuf = buf,
808 				.ooblen = rwsize,
809 				.mode = MTD_OPS_RAW
810 			};
811 
812 			if (read)
813 				ret = mtd_read_oob(mtd, off, &ops);
814 			else
815 				ret = mtd_write_oob(mtd, off, &ops);
816 		} else if (raw) {
817 			ret = raw_access(mtd, buf, off, pagecount, read,
818 					 no_verify);
819 		} else {
820 			printf("Unknown nand command suffix '%s'.\n", s);
821 			unmap_sysmem(buf);
822 			return 1;
823 		}
824 
825 		unmap_sysmem(buf);
826 		printf(" %zu bytes %s: %s\n", rwsize,
827 		       read ? "read" : "written", ret ? "ERROR" : "OK");
828 
829 		return ret == 0 ? 0 : 1;
830 	}
831 
832 #ifdef CONFIG_CMD_NAND_WATCH
833 	if (strncmp(cmd, "watch", 5) == 0) {
834 		int args = 2;
835 
836 		if (cmd[5]) {
837 			if (!strncmp(&cmd[5], ".part", 5)) {
838 				args = 1;
839 			} else if (!strncmp(&cmd[5], ".chip", 5)) {
840 				args = 0;
841 			} else {
842 				goto usage;
843 			}
844 		}
845 
846 		if (cmd[10])
847 			if (!strncmp(&cmd[10], ".quiet", 6))
848 				quiet = true;
849 
850 		if (argc != 2 + args)
851 			goto usage;
852 
853 		ret = mtd_arg_off_size(argc - 2, argv + 2, &dev, &off, &size,
854 				       &maxsize, MTD_DEV_TYPE_NAND, mtd->size);
855 		if (ret)
856 			return ret;
857 
858 		/* size is unspecified */
859 		if (argc < 4)
860 			adjust_size_for_badblocks(&size, off, dev);
861 
862 		if ((off & (mtd->writesize - 1)) ||
863 		    (size & (mtd->writesize - 1))) {
864 			printf("Attempt to read non page-aligned data\n");
865 			return -EINVAL;
866 		}
867 
868 		ret = set_dev(dev);
869 		if (ret)
870 			return ret;
871 
872 		mtd = get_nand_dev_by_index(dev);
873 
874 		printf("\nNAND watch for bitflips in area 0x%llx-0x%llx:\n",
875 		       off, off + size);
876 
877 		return nand_watch_bf(mtd, off, size, quiet);
878 	}
879 #endif
880 
881 #ifdef CONFIG_CMD_NAND_TORTURE
882 	if (strcmp(cmd, "torture") == 0) {
883 		loff_t endoff;
884 		unsigned int failed = 0, passed = 0;
885 
886 		if (argc < 3)
887 			goto usage;
888 
889 		if (!str2off(argv[2], &off)) {
890 			puts("Offset is not a valid number\n");
891 			return 1;
892 		}
893 
894 		size = mtd->erasesize;
895 		if (argc > 3) {
896 			if (!str2off(argv[3], &size)) {
897 				puts("Size is not a valid number\n");
898 				return 1;
899 			}
900 		}
901 
902 		endoff = off + size;
903 		if (endoff > mtd->size) {
904 			puts("Arguments beyond end of NAND\n");
905 			return 1;
906 		}
907 
908 		off = round_down(off, mtd->erasesize);
909 		endoff = round_up(endoff, mtd->erasesize);
910 		size = endoff - off;
911 		printf("\nNAND torture: device %d offset 0x%llx size 0x%llx (block size 0x%x)\n",
912 		       dev, off, size, mtd->erasesize);
913 		while (off < endoff) {
914 			ret = nand_torture(mtd, off);
915 			if (ret) {
916 				failed++;
917 				printf("  block at 0x%llx failed\n", off);
918 			} else {
919 				passed++;
920 			}
921 			off += mtd->erasesize;
922 		}
923 		printf(" Passed: %u, failed: %u\n", passed, failed);
924 		return failed != 0;
925 	}
926 #endif
927 
928 	if (strcmp(cmd, "markbad") == 0) {
929 		argc -= 2;
930 		argv += 2;
931 
932 		if (argc <= 0)
933 			goto usage;
934 
935 		while (argc > 0) {
936 			addr = hextoul(*argv, NULL);
937 
938 			if (mtd_block_markbad(mtd, addr)) {
939 				printf("block 0x%08lx NOT marked "
940 					"as bad! ERROR %d\n",
941 					addr, ret);
942 				ret = 1;
943 			} else {
944 				printf("block 0x%08lx successfully "
945 					"marked as bad\n",
946 					addr);
947 			}
948 			--argc;
949 			++argv;
950 		}
951 		return ret;
952 	}
953 
954 	if (strcmp(cmd, "biterr") == 0) {
955 		int bit;
956 
957 		if (argc != 4)
958 			goto usage;
959 
960 		off = (int)simple_strtoul(argv[2], NULL, 16);
961 		bit = (int)simple_strtoul(argv[3], NULL, 10);
962 		ret = nand_biterror(mtd, off, bit);
963 		return ret;
964 	}
965 
966 #ifdef CONFIG_CMD_NAND_LOCK_UNLOCK
967 	if (strcmp(cmd, "lock") == 0) {
968 		int tight = 0;
969 		int status = 0;
970 		if (argc == 3) {
971 			if (!strcmp("tight", argv[2]))
972 				tight = 1;
973 			if (!strcmp("status", argv[2]))
974 				status = 1;
975 		}
976 		if (status) {
977 			do_nand_status(mtd);
978 		} else {
979 			if (!nand_lock(mtd, tight)) {
980 				puts("NAND flash successfully locked\n");
981 			} else {
982 				puts("Error locking NAND flash\n");
983 				return 1;
984 			}
985 		}
986 		return 0;
987 	}
988 
989 	if (strncmp(cmd, "unlock", 5) == 0) {
990 		int allexcept = 0;
991 
992 		s = strchr(cmd, '.');
993 
994 		if (s && !strcmp(s, ".allexcept"))
995 			allexcept = 1;
996 
997 		if (mtd_arg_off_size(argc - 2, argv + 2, &dev, &off, &size,
998 				     &maxsize, MTD_DEV_TYPE_NAND,
999 				     mtd->size) < 0)
1000 			return 1;
1001 
1002 		if (set_dev(dev))
1003 			return 1;
1004 
1005 		mtd = get_nand_dev_by_index(dev);
1006 
1007 		if (!nand_unlock(mtd, off, size, allexcept)) {
1008 			puts("NAND flash successfully unlocked\n");
1009 		} else {
1010 			puts("Error unlocking NAND flash, "
1011 			     "write and erase will probably fail\n");
1012 			return 1;
1013 		}
1014 		return 0;
1015 	}
1016 #endif
1017 
1018 usage:
1019 	return CMD_RET_USAGE;
1020 }
1021 
1022 U_BOOT_LONGHELP(nand,
1023 	"info - show available NAND devices\n"
1024 	"nand device [dev] - show or set current device\n"
1025 	"nand read - addr off|partition size\n"
1026 	"nand write - addr off|partition size\n"
1027 	"    read/write 'size' bytes starting at offset 'off'\n"
1028 	"    to/from memory address 'addr', skipping bad blocks.\n"
1029 	"nand read.raw - addr off|partition [count]\n"
1030 	"nand write.raw[.noverify] - addr off|partition [count]\n"
1031 	"    Use read.raw/write.raw to avoid ECC and access the flash as-is.\n"
1032 #ifdef CONFIG_CMD_NAND_TRIMFFS
1033 	"nand write.trimffs - addr off|partition size\n"
1034 	"    write 'size' bytes starting at offset 'off' from memory address\n"
1035 	"    'addr', skipping bad blocks and dropping any pages at the end\n"
1036 	"    of eraseblocks that contain only 0xFF\n"
1037 #endif
1038 	"nand erase[.spread] [clean] off size - erase 'size' bytes "
1039 	"from offset 'off'\n"
1040 	"    With '.spread', erase enough for given file size, otherwise,\n"
1041 	"    'size' includes skipped bad blocks.\n"
1042 	"nand erase.part [clean] partition - erase entire mtd partition'\n"
1043 	"nand erase.chip [clean] - erase entire chip'\n"
1044 	"nand bad - show bad blocks\n"
1045 	"nand dump[.oob] off - dump page\n"
1046 #ifdef CONFIG_CMD_NAND_WATCH
1047 	"nand watch <off> <size> - check an area for bitflips\n"
1048 	"nand watch.part <part> - check a partition for bitflips\n"
1049 	"nand watch.chip - check the whole device for bitflips\n"
1050 	"\t\t.quiet - Query only the summary, not the details\n"
1051 #endif
1052 #ifdef CONFIG_CMD_NAND_TORTURE
1053 	"nand torture off - torture one block at offset\n"
1054 	"nand torture off [size] - torture blocks from off to off+size\n"
1055 #endif
1056 	"nand scrub [-y] off size | scrub.part partition | scrub.chip\n"
1057 	"    really clean NAND erasing bad blocks (UNSAFE)\n"
1058 	"nand markbad off [...] - mark bad block(s) at offset (UNSAFE)\n"
1059 	"nand biterr off bit - make a bit error at offset and bit position (UNSAFE)"
1060 #ifdef CONFIG_CMD_NAND_LOCK_UNLOCK
1061 	"\n"
1062 	"nand lock [tight] [status]\n"
1063 	"    bring nand to lock state or display locked pages\n"
1064 	"nand unlock[.allexcept] [offset] [size] - unlock section"
1065 #endif
1066 #ifdef CONFIG_ENV_OFFSET_OOB
1067 	"\n"
1068 	"nand env.oob - environment offset in OOB of block 0 of"
1069 	"    first device.\n"
1070 	"nand env.oob set off|partition - set enviromnent offset\n"
1071 	"nand env.oob get - get environment offset"
1072 #endif
1073 	);
1074 
1075 U_BOOT_CMD(
1076 	nand, CONFIG_SYS_MAXARGS, 1, do_nand,
1077 	"NAND sub-system", nand_help_text
1078 );
1079 
nand_load_image(struct cmd_tbl * cmdtp,struct mtd_info * mtd,ulong offset,ulong addr,char * cmd)1080 static int nand_load_image(struct cmd_tbl *cmdtp, struct mtd_info *mtd,
1081 			   ulong offset, ulong addr, char *cmd)
1082 {
1083 	int r;
1084 	char *s;
1085 	size_t cnt;
1086 #if defined(CONFIG_LEGACY_IMAGE_FORMAT)
1087 	struct legacy_img_hdr *hdr;
1088 #endif
1089 #if defined(CONFIG_FIT)
1090 	const void *fit_hdr = NULL;
1091 #endif
1092 
1093 	s = strchr(cmd, '.');
1094 	if (s != NULL &&
1095 	    (strcmp(s, ".jffs2") && strcmp(s, ".e") && strcmp(s, ".i"))) {
1096 		printf("Unknown nand load suffix '%s'\n", s);
1097 		bootstage_error(BOOTSTAGE_ID_NAND_SUFFIX);
1098 		return 1;
1099 	}
1100 
1101 	printf("\nLoading from %s, offset 0x%lx\n", mtd->name, offset);
1102 
1103 	cnt = mtd->writesize;
1104 	r = nand_read_skip_bad(mtd, offset, &cnt, NULL, mtd->size,
1105 			       (u_char *)addr);
1106 	if (r) {
1107 		puts("** Read error\n");
1108 		bootstage_error(BOOTSTAGE_ID_NAND_HDR_READ);
1109 		return 1;
1110 	}
1111 	bootstage_mark(BOOTSTAGE_ID_NAND_HDR_READ);
1112 
1113 	switch (genimg_get_format ((void *)addr)) {
1114 #if defined(CONFIG_LEGACY_IMAGE_FORMAT)
1115 	case IMAGE_FORMAT_LEGACY:
1116 		hdr = (struct legacy_img_hdr *)addr;
1117 
1118 		bootstage_mark(BOOTSTAGE_ID_NAND_TYPE);
1119 		image_print_contents (hdr);
1120 
1121 		cnt = image_get_image_size (hdr);
1122 		break;
1123 #endif
1124 #if defined(CONFIG_FIT)
1125 	case IMAGE_FORMAT_FIT:
1126 		fit_hdr = (const void *)addr;
1127 		puts ("Fit image detected...\n");
1128 
1129 		cnt = fit_get_size (fit_hdr);
1130 		break;
1131 #endif
1132 	default:
1133 		bootstage_error(BOOTSTAGE_ID_NAND_TYPE);
1134 		puts ("** Unknown image type\n");
1135 		return 1;
1136 	}
1137 	bootstage_mark(BOOTSTAGE_ID_NAND_TYPE);
1138 
1139 	r = nand_read_skip_bad(mtd, offset, &cnt, NULL, mtd->size,
1140 			       (u_char *)addr);
1141 	if (r) {
1142 		puts("** Read error\n");
1143 		bootstage_error(BOOTSTAGE_ID_NAND_READ);
1144 		return 1;
1145 	}
1146 	bootstage_mark(BOOTSTAGE_ID_NAND_READ);
1147 
1148 #if defined(CONFIG_FIT)
1149 	/* This cannot be done earlier, we need complete FIT image in RAM first */
1150 	if (genimg_get_format ((void *)addr) == IMAGE_FORMAT_FIT) {
1151 		if (fit_check_format(fit_hdr, IMAGE_SIZE_INVAL)) {
1152 			bootstage_error(BOOTSTAGE_ID_NAND_FIT_READ);
1153 			puts ("** Bad FIT image format\n");
1154 			return 1;
1155 		}
1156 		bootstage_mark(BOOTSTAGE_ID_NAND_FIT_READ_OK);
1157 		fit_print_contents (fit_hdr);
1158 	}
1159 #endif
1160 
1161 	/* Loading ok, update default load address */
1162 
1163 	image_load_addr = addr;
1164 
1165 	return bootm_maybe_autostart(cmdtp, cmd);
1166 }
1167 
do_nandboot(struct cmd_tbl * cmdtp,int flag,int argc,char * const argv[])1168 static int do_nandboot(struct cmd_tbl *cmdtp, int flag, int argc,
1169 		       char *const argv[])
1170 {
1171 	char *boot_device = NULL;
1172 	int idx;
1173 	ulong addr, offset = 0;
1174 	struct mtd_info *mtd;
1175 #if defined(CONFIG_CMD_MTDPARTS)
1176 	struct mtd_device *dev;
1177 	struct part_info *part;
1178 	u8 pnum;
1179 
1180 	if (argc >= 2) {
1181 		char *p = (argc == 2) ? argv[1] : argv[2];
1182 		if (!(str2long(p, &addr)) && (mtdparts_init() == 0) &&
1183 		    (find_dev_and_part(p, &dev, &pnum, &part) == 0)) {
1184 			if (dev->id->type != MTD_DEV_TYPE_NAND) {
1185 				puts("Not a NAND device\n");
1186 				return 1;
1187 			}
1188 			if (argc > 3)
1189 				goto usage;
1190 			if (argc == 3)
1191 				addr = hextoul(argv[1], NULL);
1192 			else
1193 				addr = CONFIG_SYS_LOAD_ADDR;
1194 
1195 			mtd = get_nand_dev_by_index(dev->id->num);
1196 			return nand_load_image(cmdtp, mtd, part->offset,
1197 					       addr, argv[0]);
1198 		}
1199 	}
1200 #endif
1201 
1202 	bootstage_mark(BOOTSTAGE_ID_NAND_PART);
1203 	switch (argc) {
1204 	case 1:
1205 		addr = CONFIG_SYS_LOAD_ADDR;
1206 		boot_device = env_get("bootdevice");
1207 		break;
1208 	case 2:
1209 		addr = hextoul(argv[1], NULL);
1210 		boot_device = env_get("bootdevice");
1211 		break;
1212 	case 3:
1213 		addr = hextoul(argv[1], NULL);
1214 		boot_device = argv[2];
1215 		break;
1216 	case 4:
1217 		addr = hextoul(argv[1], NULL);
1218 		boot_device = argv[2];
1219 		offset = hextoul(argv[3], NULL);
1220 		break;
1221 	default:
1222 #if defined(CONFIG_CMD_MTDPARTS)
1223 usage:
1224 #endif
1225 		bootstage_error(BOOTSTAGE_ID_NAND_SUFFIX);
1226 		return CMD_RET_USAGE;
1227 	}
1228 	bootstage_mark(BOOTSTAGE_ID_NAND_SUFFIX);
1229 
1230 	if (!boot_device) {
1231 		puts("\n** No boot device **\n");
1232 		bootstage_error(BOOTSTAGE_ID_NAND_BOOT_DEVICE);
1233 		return 1;
1234 	}
1235 	bootstage_mark(BOOTSTAGE_ID_NAND_BOOT_DEVICE);
1236 
1237 	idx = hextoul(boot_device, NULL);
1238 
1239 	mtd = get_nand_dev_by_index(idx);
1240 	if (!mtd) {
1241 		printf("\n** Device %d not available\n", idx);
1242 		bootstage_error(BOOTSTAGE_ID_NAND_AVAILABLE);
1243 		return 1;
1244 	}
1245 	bootstage_mark(BOOTSTAGE_ID_NAND_AVAILABLE);
1246 
1247 	return nand_load_image(cmdtp, mtd, offset, addr, argv[0]);
1248 }
1249 
1250 U_BOOT_CMD(nboot, 4, 1, do_nandboot,
1251 	"boot from NAND device",
1252 	"[partition] | [[[loadAddr] dev] offset]"
1253 );
1254