1 /* -*- tab-width:8 -*- */
4 Copyright (C) 2011 Peter Zotov <whitequark@whitequark.org>
5 Use of this source code is governed by a BSD-style
6 license that can be found in the LICENSE file.
14 #include <sys/types.h>
15 #include <sys/socket.h>
16 #include <netinet/in.h>
17 #include <arpa/inet.h>
20 #include <stlink-common.h>
22 #include "gdb-remote.h"
24 #define DEFAULT_LOGGING_LEVEL 50
25 #define DEFAULT_GDB_LISTEN_PORT 4242
27 #define STRINGIFY_inner(name) #name
28 #define STRINGIFY(name) STRINGIFY_inner(name)
30 #define FLASH_BASE 0x08000000
31 #define FLASH_PAGE (sl->flash_pgsz)
32 #define FLASH_PAGE_MASK (~((1 << 10) - 1))
33 #define FLASH_SIZE (FLASH_PAGE * 128)
35 static const char hex[] = "0123456789abcdef";
37 static const char* current_memory_map = NULL;
40 * Chip IDs are explained in the appropriate programming manual for the
41 * DBGMCU_IDCODE register (0xE0042000)
44 #define CORE_M3_R1 0x1BA00477
45 #define CORE_M3_R2 0x4BA00477
46 #define CORE_M4_R0 0x2BA01477
48 typedef struct _st_state_t {
49 // things from command line, bleh
51 // "/dev/serial/by-id/usb-FTDI_TTL232R-3V3_FTE531X6-if00-port0" is only 58 chars
58 int serve(stlink_t *sl, int port);
59 char* make_memory_map(stlink_t *sl);
62 int parse_options(int argc, char** argv, st_state_t *st) {
63 static struct option long_options[] = {
64 {"help", no_argument, NULL, 'h'},
65 {"verbose", optional_argument, NULL, 'v'},
66 {"device", required_argument, NULL, 'd'},
67 {"stlink_version", required_argument, NULL, 's'},
68 {"stlinkv1", no_argument, NULL, '1'},
69 {"listen_port", required_argument, NULL, 'p'},
72 const char * help_str = "%s - usage:\n\n"
73 " -h, --help\t\tPrint this help\n"
74 " -vXX, --verbose=XX\tspecify a specific verbosity level (0..99)\n"
75 " -v, --verbose\tspecify generally verbose logging\n"
76 " -d <device>, --device=/dev/stlink2_1\n"
77 "\t\t\tWhere is your stlink device connected?\n"
78 " -s X, --stlink_version=X\n"
79 "\t\t\tChoose what version of stlink to use, (defaults to 2)\n"
80 " -1, --stlinkv1\tForce stlink version 1\n"
81 " -p 4242, --listen_port=1234\n"
82 "\t\t\tSet the gdb server listen port. "
83 "(default port: " STRINGIFY(DEFAULT_GDB_LISTEN_PORT) ")\n"
90 while ((c = getopt_long(argc, argv, "hv::d:s:1p:", long_options, &option_index)) != -1) {
93 printf("XXXXX Shouldn't really normally come here, only if there's no corresponding option\n");
94 printf("option %s", long_options[option_index].name);
96 printf(" with arg %s", optarg);
101 printf(help_str, argv[0]);
106 st->logging_level = atoi(optarg);
108 st->logging_level = DEFAULT_LOGGING_LEVEL;
112 if (strlen(optarg) > sizeof (st->devicename)) {
113 fprintf(stderr, "device name too long: %zd\n", strlen(optarg));
115 strcpy(st->devicename, optarg);
119 st->stlink_version = 1;
122 sscanf(optarg, "%i", &q);
123 if (q < 0 || q > 2) {
124 fprintf(stderr, "stlink version %d unknown!\n", q);
127 st->stlink_version = q;
130 sscanf(optarg, "%i", &q);
132 fprintf(stderr, "Can't use a negative port to listen on: %d\n", q);
141 printf("non-option ARGV-elements: ");
142 while (optind < argc)
143 printf("%s ", argv[optind++]);
150 int main(int argc, char** argv) {
155 memset(&state, 0, sizeof(state));
157 state.stlink_version = 2;
158 state.logging_level = DEFAULT_LOGGING_LEVEL;
159 state.listen_port = DEFAULT_GDB_LISTEN_PORT;
160 parse_options(argc, argv, &state);
161 switch (state.stlink_version) {
163 sl = stlink_open_usb(state.logging_level);
164 if(sl == NULL) return 1;
167 sl = stlink_v1_open(state.logging_level);
168 if(sl == NULL) return 1;
172 uint32_t chip_id = sl->chip_id;
173 uint32_t core_id = sl->core_id;
175 /* Fix chip_id for F4 */
176 if (((chip_id & 0xFFF) == 0x411) && (core_id == CORE_M4_R0)) {
177 printf("Fixing wrong chip_id for STM32F4 Rev A errata\n");
181 printf("Chip ID is %08x, Core ID is %08x.\n", chip_id, core_id);
183 current_memory_map = make_memory_map(sl);
185 while(serve(sl, state.listen_port) == 0);
187 /* Switch back to mass storage mode before closing. */
189 stlink_exit_debug_mode(sl);
195 static const char* const memory_map_template =
196 "<?xml version=\"1.0\"?>"
197 "<!DOCTYPE memory-map PUBLIC \"+//IDN gnu.org//DTD GDB Memory Map V1.0//EN\""
198 " \"http://sourceware.org/gdb/gdb-memory-map.dtd\">"
200 " <memory type=\"rom\" start=\"0x00000000\" length=\"0x%x\"/>" // code = sram, bootrom or flash; flash is bigger
201 " <memory type=\"ram\" start=\"0x20000000\" length=\"0x%x\"/>" // sram 8k
202 " <memory type=\"flash\" start=\"0x08000000\" length=\"0x%x\">"
203 " <property name=\"blocksize\">0x%x</property>"
205 " <memory type=\"ram\" start=\"0x40000000\" length=\"0x1fffffff\"/>" // peripheral regs
206 " <memory type=\"ram\" start=\"0xe0000000\" length=\"0x1fffffff\"/>" // cortex regs
207 " <memory type=\"rom\" start=\"0x%08x\" length=\"0x%x\"/>" // bootrom
208 " <memory type=\"rom\" start=\"0x1ffff800\" length=\"0x8\"/>" // option byte area
211 char* make_memory_map(stlink_t *sl) {
212 /* This will be freed in serve() */
213 char* map = malloc(4096);
216 snprintf(map, 4096, memory_map_template,
219 sl->flash_size, sl->flash_pgsz,
220 sl->sys_base, sl->sys_size);
227 * DWT_COMP0 0xE0001020
228 * DWT_MASK0 0xE0001024
229 * DWT_FUNCTION0 0xE0001028
230 * DWT_COMP1 0xE0001030
231 * DWT_MASK1 0xE0001034
232 * DWT_FUNCTION1 0xE0001038
233 * DWT_COMP2 0xE0001040
234 * DWT_MASK2 0xE0001044
235 * DWT_FUNCTION2 0xE0001048
236 * DWT_COMP3 0xE0001050
237 * DWT_MASK3 0xE0001054
238 * DWT_FUNCTION3 0xE0001058
241 #define DATA_WATCH_NUM 4
243 enum watchfun { WATCHDISABLED = 0, WATCHREAD = 5, WATCHWRITE = 6, WATCHACCESS = 7 };
245 struct code_hw_watchpoint {
251 struct code_hw_watchpoint data_watches[DATA_WATCH_NUM];
253 static void init_data_watchpoints(stlink_t *sl) {
255 printf("init watchpoints\n");
258 // set trcena in debug command to turn on dwt unit
259 stlink_read_mem32(sl, 0xE000EDFC, 4);
261 stlink_write_mem32(sl, 0xE000EDFC, 4);
263 // make sure all watchpoints are cleared
264 memset(sl->q_buf, 0, 4);
265 for(int i = 0; i < DATA_WATCH_NUM; i++) {
266 data_watches[i].fun = WATCHDISABLED;
267 stlink_write_mem32(sl, 0xe0001028 + i * 16, 4);
271 static int add_data_watchpoint(stlink_t *sl, enum watchfun wf, stm32_addr_t addr, unsigned int len)
277 // find a free watchpoint
287 if((mask != -1) && (mask < 16)) {
288 for(i = 0; i < DATA_WATCH_NUM; i++) {
289 // is this an empty slot ?
290 if(data_watches[i].fun == WATCHDISABLED) {
292 printf("insert watchpoint %d addr %x wf %u mask %u len %d\n", i, addr, wf, mask, len);
295 data_watches[i].fun = wf;
296 data_watches[i].addr = addr;
297 data_watches[i].mask = mask;
299 // insert comparator address
300 sl->q_buf[0] = (addr & 0xff);
301 sl->q_buf[1] = ((addr >> 8) & 0xff);
302 sl->q_buf[2] = ((addr >> 16) & 0xff);
303 sl->q_buf[3] = ((addr >> 24) & 0xff);
305 stlink_write_mem32(sl, 0xE0001020 + i * 16, 4);
308 memset(sl->q_buf, 0, 4);
310 stlink_write_mem32(sl, 0xE0001024 + i * 16, 4);
313 memset(sl->q_buf, 0, 4);
315 stlink_write_mem32(sl, 0xE0001028 + i * 16, 4);
317 // just to make sure the matched bit is clear !
318 stlink_read_mem32(sl, 0xE0001028 + i * 16, 4);
325 printf("failure: add watchpoints addr %x wf %u len %u\n", addr, wf, len);
330 static int delete_data_watchpoint(stlink_t *sl, stm32_addr_t addr)
334 for(i = 0 ; i < DATA_WATCH_NUM; i++) {
335 if((data_watches[i].addr == addr) && (data_watches[i].fun != WATCHDISABLED)) {
337 printf("delete watchpoint %d addr %x\n", i, addr);
340 memset(sl->q_buf, 0, 4);
341 data_watches[i].fun = WATCHDISABLED;
342 stlink_write_mem32(sl, 0xe0001028 + i * 16, 4);
349 printf("failure: delete watchpoint addr %x\n", addr);
355 #define CODE_BREAK_NUM 6
356 #define CODE_BREAK_LOW 0x01
357 #define CODE_BREAK_HIGH 0x02
359 struct code_hw_breakpoint {
364 struct code_hw_breakpoint code_breaks[CODE_BREAK_NUM];
366 static void init_code_breakpoints(stlink_t *sl) {
367 memset(sl->q_buf, 0, 4);
368 sl->q_buf[0] = 0x03; // KEY | ENABLE
369 stlink_write_mem32(sl, CM3_REG_FP_CTRL, 4);
370 printf("KARL - should read back as 0x03, not 60 02 00 00\n");
371 stlink_read_mem32(sl, CM3_REG_FP_CTRL, 4);
373 memset(sl->q_buf, 0, 4);
374 for(int i = 0; i < CODE_BREAK_NUM; i++) {
375 code_breaks[i].type = 0;
376 stlink_write_mem32(sl, CM3_REG_FP_COMP0 + i * 4, 4);
380 static int update_code_breakpoint(stlink_t *sl, stm32_addr_t addr, int set) {
381 stm32_addr_t fpb_addr = addr & ~0x3;
382 int type = addr & 0x2 ? CODE_BREAK_HIGH : CODE_BREAK_LOW;
385 fprintf(stderr, "update_code_breakpoint: unaligned address %08x\n", addr);
390 for(int i = 0; i < CODE_BREAK_NUM; i++) {
391 if(fpb_addr == code_breaks[i].addr ||
392 (set && code_breaks[i].type == 0)) {
399 if(set) return -1; // Free slot not found
400 else return 0; // Breakpoint is already removed
403 struct code_hw_breakpoint* brk = &code_breaks[id];
405 brk->addr = fpb_addr;
407 if(set) brk->type |= type;
408 else brk->type &= ~type;
410 memset(sl->q_buf, 0, 4);
414 printf("clearing hw break %d\n", id);
417 stlink_write_mem32(sl, 0xe0002008 + id * 4, 4);
419 sl->q_buf[0] = ( brk->addr & 0xff) | 1;
420 sl->q_buf[1] = ((brk->addr >> 8) & 0xff);
421 sl->q_buf[2] = ((brk->addr >> 16) & 0xff);
422 sl->q_buf[3] = ((brk->addr >> 24) & 0xff) | (brk->type << 6);
425 printf("setting hw break %d at %08x (%d)\n",
426 id, brk->addr, brk->type);
427 printf("reg %02x %02x %02x %02x\n",
428 sl->q_buf[3], sl->q_buf[2], sl->q_buf[1], sl->q_buf[0]);
431 stlink_write_mem32(sl, 0xe0002008 + id * 4, 4);
443 struct flash_block* next;
446 static struct flash_block* flash_root;
448 static int flash_add_block(stm32_addr_t addr, unsigned length,
450 if(addr < FLASH_BASE || addr + length > FLASH_BASE + FLASH_SIZE) {
451 fprintf(stderr, "flash_add_block: incorrect bounds\n");
455 if(addr % FLASH_PAGE != 0 || length % FLASH_PAGE != 0) {
456 fprintf(stderr, "flash_add_block: unaligned block\n");
460 struct flash_block* new = malloc(sizeof(struct flash_block));
461 new->next = flash_root;
464 new->length = length;
465 new->data = calloc(length, 1);
472 static int flash_populate(stm32_addr_t addr, uint8_t* data, unsigned length) {
473 int fit_blocks = 0, fit_length = 0;
475 for(struct flash_block* fb = flash_root; fb; fb = fb->next) {
476 /* Block: ------X------Y--------
480 * Block intersects with data, if:
484 unsigned X = fb->addr, Y = fb->addr + fb->length;
485 unsigned a = addr, b = addr + length;
487 // from start of the block
488 unsigned start = (a > X ? a : X) - X;
489 unsigned end = (b > Y ? Y : b) - X;
491 memcpy(fb->data + start, data, end - start);
494 fit_length += end - start;
498 if(fit_blocks == 0) {
499 fprintf(stderr, "Unfit data block %08x -> %04x\n", addr, length);
503 if(fit_length != length) {
504 fprintf(stderr, "warning: data block %08x -> %04x truncated to %04x\n",
505 addr, length, fit_length);
506 fprintf(stderr, "(this is not an error, just a GDB glitch)\n");
512 static int flash_go(stlink_t *sl) {
515 // Some kinds of clock settings do not allow writing to flash.
518 for(struct flash_block* fb = flash_root; fb; fb = fb->next) {
520 printf("flash_do: block %08x -> %04x\n", fb->addr, fb->length);
523 unsigned length = fb->length;
524 for(stm32_addr_t page = fb->addr; page < fb->addr + fb->length; page += FLASH_PAGE) {
526 printf("flash_do: page %08x\n", page);
529 stlink_erase_flash_page(sl, page);
531 if(stlink_write_flash(sl, page, fb->data + (page - fb->addr),
532 length > FLASH_PAGE ? FLASH_PAGE : length) < 0)
543 for(struct flash_block* fb = flash_root, *next; fb; fb = next) {
554 int serve(stlink_t *sl, int port) {
555 int sock = socket(AF_INET, SOCK_STREAM, 0);
561 unsigned int val = 1;
562 setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &val, sizeof(val));
564 struct sockaddr_in serv_addr = {0};
565 serv_addr.sin_family = AF_INET;
566 serv_addr.sin_addr.s_addr = inet_addr("127.0.0.1");
567 serv_addr.sin_port = htons(port);
569 if(bind(sock, (struct sockaddr *) &serv_addr, sizeof(serv_addr)) < 0) {
574 if(listen(sock, 5) < 0) {
579 stlink_force_debug(sl);
581 init_code_breakpoints(sl);
582 init_data_watchpoints(sl);
584 printf("Listening at *:%d...\n", port);
586 int client = accept(sock, NULL, NULL);
587 signal (SIGINT, SIG_DFL);
595 printf("GDB connected.\n");
598 * To allow resetting the chip from GDB it is required to
599 * emulate attaching and detaching to target.
601 unsigned int attached = 1;
606 int status = gdb_recv_packet(client, &packet);
608 fprintf(stderr, "cannot recv: %d\n", status);
613 printf("recv: %s\n", packet);
621 if(packet[1] == 'P' || packet[1] == 'C' || packet[1] == 'L') {
626 char *separator = strstr(packet, ":"), *params = "";
627 if(separator == NULL) {
628 separator = packet + strlen(packet);
630 params = separator + 1;
633 unsigned queryNameLength = (separator - &packet[1]);
634 char* queryName = calloc(queryNameLength + 1, 1);
635 strncpy(queryName, &packet[1], queryNameLength);
638 printf("query: %s;%s\n", queryName, params);
641 if(!strcmp(queryName, "Supported")) {
642 reply = strdup("PacketSize=3fff;qXfer:memory-map:read+");
643 } else if(!strcmp(queryName, "Xfer")) {
644 char *type, *op, *s_addr, *s_length;
646 char *annex __attribute__((unused));
648 type = strsep(&tok, ":");
649 op = strsep(&tok, ":");
650 annex = strsep(&tok, ":");
651 s_addr = strsep(&tok, ",");
654 unsigned addr = strtoul(s_addr, NULL, 16),
655 length = strtoul(s_length, NULL, 16);
658 printf("Xfer: type:%s;op:%s;annex:%s;addr:%d;length:%d\n",
659 type, op, annex, addr, length);
662 const char* data = NULL;
664 if(!strcmp(type, "memory-map") && !strcmp(op, "read"))
665 data = current_memory_map;
668 unsigned data_length = strlen(data);
669 if(addr + length > data_length)
670 length = data_length - addr;
675 reply = calloc(length + 2, 1);
677 strncpy(&reply[1], data, length);
692 char *cmdName = strtok_r(packet, ":;", ¶ms);
694 cmdName++; // vCommand -> Command
696 if(!strcmp(cmdName, "FlashErase")) {
697 char *s_addr, *s_length;
700 s_addr = strsep(&tok, ",");
703 unsigned addr = strtoul(s_addr, NULL, 16),
704 length = strtoul(s_length, NULL, 16);
707 printf("FlashErase: addr:%08x,len:%04x\n",
711 if(flash_add_block(addr, length, sl) < 0) {
712 reply = strdup("E00");
714 reply = strdup("OK");
716 } else if(!strcmp(cmdName, "FlashWrite")) {
720 s_addr = strsep(&tok, ":");
723 unsigned addr = strtoul(s_addr, NULL, 16);
724 unsigned data_length = status - (data - packet);
726 // Length of decoded data cannot be more than
727 // encoded, as escapes are removed.
728 // Additional byte is reserved for alignment fix.
729 uint8_t *decoded = calloc(data_length + 1, 1);
730 unsigned dec_index = 0;
731 for(int i = 0; i < data_length; i++) {
732 if(data[i] == 0x7d) {
734 decoded[dec_index++] = data[i] ^ 0x20;
736 decoded[dec_index++] = data[i];
741 if(dec_index % 2 != 0)
745 printf("binary packet %d -> %d\n", data_length, dec_index);
748 if(flash_populate(addr, decoded, dec_index) < 0) {
749 reply = strdup("E00");
751 reply = strdup("OK");
753 } else if(!strcmp(cmdName, "FlashDone")) {
754 if(flash_go(sl) < 0) {
755 reply = strdup("E00");
757 reply = strdup("OK");
759 } else if(!strcmp(cmdName, "Kill")) {
762 reply = strdup("OK");
775 int status = gdb_check_for_interrupt(client);
777 fprintf(stderr, "cannot check for int: %d\n", status);
782 stlink_force_debug(sl);
787 if(sl->core_stat == STLINK_CORE_HALTED) {
794 reply = strdup("S05"); // TRAP
800 reply = strdup("S05"); // TRAP
805 reply = strdup("S05"); // TRAP
807 /* Stub shall reply OK if not attached. */
808 reply = strdup("OK");
813 stlink_read_all_regs(sl, ®p);
815 reply = calloc(8 * 16 + 1, 1);
816 for(int i = 0; i < 16; i++)
817 sprintf(&reply[i * 8], "%08x", htonl(regp.r[i]));
822 unsigned id = strtoul(&packet[1], NULL, 16);
823 unsigned myreg = 0xDEADDEAD;
826 stlink_read_reg(sl, id, ®p);
827 myreg = htonl(regp.r[id]);
828 } else if(id == 0x19) {
829 stlink_read_reg(sl, 16, ®p);
830 myreg = htonl(regp.xpsr);
832 reply = strdup("E00");
835 reply = calloc(8 + 1, 1);
836 sprintf(reply, "%08x", myreg);
842 char* s_reg = &packet[1];
843 char* s_value = strstr(&packet[1], "=") + 1;
845 unsigned reg = strtoul(s_reg, NULL, 16);
846 unsigned value = strtoul(s_value, NULL, 16);
849 stlink_write_reg(sl, ntohl(value), reg);
850 } else if(reg == 0x19) {
851 stlink_write_reg(sl, ntohl(value), 16);
853 reply = strdup("E00");
857 reply = strdup("OK");
864 for(int i = 0; i < 16; i++) {
866 strncpy(str, &packet[1 + i * 8], 8);
867 uint32_t reg = strtoul(str, NULL, 16);
868 stlink_write_reg(sl, ntohl(reg), i);
871 reply = strdup("OK");
875 char* s_start = &packet[1];
876 char* s_count = strstr(&packet[1], ",") + 1;
878 stm32_addr_t start = strtoul(s_start, NULL, 16);
879 unsigned count = strtoul(s_count, NULL, 16);
881 unsigned adj_start = start % 4;
883 stlink_read_mem32(sl, start - adj_start, (count % 4 == 0) ?
884 count : count + 4 - (count % 4));
886 reply = calloc(count * 2 + 1, 1);
887 for(int i = 0; i < count; i++) {
888 reply[i * 2 + 0] = hex[sl->q_buf[i + adj_start] >> 4];
889 reply[i * 2 + 1] = hex[sl->q_buf[i + adj_start] & 0xf];
896 char* s_start = &packet[1];
897 char* s_count = strstr(&packet[1], ",") + 1;
898 char* hexdata = strstr(packet, ":") + 1;
900 stm32_addr_t start = strtoul(s_start, NULL, 16);
901 unsigned count = strtoul(s_count, NULL, 16);
903 for(int i = 0; i < count; i ++) {
904 char hex[3] = { hexdata[i*2], hexdata[i*2+1], 0 };
905 uint8_t byte = strtoul(hex, NULL, 16);
909 if((count % 4) == 0 && (start % 4) == 0) {
910 stlink_write_mem32(sl, start, count);
912 stlink_write_mem8(sl, start, count);
915 reply = strdup("OK");
922 stm32_addr_t addr = strtoul(&packet[3], &endptr, 16);
923 stm32_addr_t len = strtoul(&endptr[1], NULL, 16);
927 if(update_code_breakpoint(sl, addr, 1) < 0) {
928 reply = strdup("E00");
930 reply = strdup("OK");
934 case '2': // insert write watchpoint
935 case '3': // insert read watchpoint
936 case '4': // insert access watchpoint
939 if(packet[1] == '2') {
941 } else if(packet[1] == '3') {
945 if(add_data_watchpoint(sl, wf, addr, len) < 0) {
946 reply = strdup("E00");
948 reply = strdup("OK");
961 stm32_addr_t addr = strtoul(&packet[3], &endptr, 16);
962 //stm32_addr_t len = strtoul(&endptr[1], NULL, 16);
965 case '1': // remove breakpoint
966 update_code_breakpoint(sl, addr, 0);
967 reply = strdup("OK");
970 case '2' : // remove write watchpoint
971 case '3' : // remove read watchpoint
972 case '4' : // remove access watchpoint
973 if(delete_data_watchpoint(sl, addr) < 0) {
974 reply = strdup("E00");
976 reply = strdup("OK");
988 * Enter extended mode which allows restarting.
989 * We do support that always.
992 reply = strdup("OK");
998 /* Reset the core. */
1001 init_code_breakpoints(sl);
1002 init_data_watchpoints(sl);
1006 reply = strdup("OK");
1017 printf("send: %s\n", reply);
1020 int result = gdb_send_packet(client, reply);
1022 fprintf(stderr, "cannot send: %d\n", result);