Beware that this post is related to an SDK in maintenance mode
More Info: Consider nRF Connect SDK for new designs
This post is older than 2 years and might not be relevant anymore
More Info: Consider searching for newer posts

DFU with external QSPI memory

Hi,

   I am working on project, in which we using nordic nRF52840 chip. We need to flash the app+SD+BL image file in external QSPI memory.

After prevalidation, the DFU controller starts to send flash image package, we need to receive this and need to save in external QSPI memory. Once the postvalidation is successful, then read all the flash image package stored in external QSPI memory and write it to internal flash memory.

For that we use secure bootloader example code as reference file. I need to know where i need to modify the secure bootloader code.

I noticed that after prevalidation, the flash is erased in on_data_obj_create_request() function in nrf_dfu_req_handler.c file, and flash is written in on_data_obj_write_request() under the same c file. Is that right?

Thanks & Regards

Mohammad Gouse

Parents
  • Hi Hung Bui,

      I have modified the files nrf_fstorage_nvmc.c, nrf_flash.c, nrf_dfu_flash.c (with their corresponding header file) to have external qspi memory interface.

    Once the device enter into DFU mode, it initialize the nrf_dfu_req_handler_init(), so I modified this function by adding nrf_dfu_qspi_init() in it.

      In this project, MX25R6435F used as external QSPI memory. The memory map of this will be same as Nordic system memory map, but without MBR and Bootloader (In our case bootloader in internal flash memory).

    Step 1: After pre-validation, I need to copy the image file (SD + APP) to external QSPI. Now I need to know where I need to change the code to proceed to next step.

  • Hi Mohammad, 

    I assume you are familiar with the DFU procedure as described here

    After you pass the pre-validation (received the init packet and then got the NRF_DFU_OP_OBJECT_WRITE to execute it), you will receive the data objects. 

    They will be handled inside nrf_dfu_data_req(). It will start with the NRF_DFU_OP_OBJECT_CREATE and the page will be erased with the call to nrf_dfu_flash_erase() inside on_data_obj_create_request(). You would need to modify that function to erase the QSPI flash page instead. 

    Next is NRF_DFU_OP_OBJECT_WRITE , which handled in on_data_obj_write_request(). You need to modify nrf_dfu_flash_store() to store on QSPI. And so on. 

    I'm not 100% sure why you would need to make the addressing on QSPI the same as on the internal chip. But it's up to you. You can have a look at our discussion with TomWS above to know about other stuff you need to modify. 

  • I assume you don't have the softdevice ? 

    Where do you put the application to ? 

    You can try to do a hex dump (nrfjprog --readcode) to read the flash after you do DFU, and compare it with when you flash only the MBR and the blinky. 

  • Hi Hung,

    I assume you don't have the softdevice ?  yes correct

    Where do you put the application to ?  In blinky_pca10056_mbr project i have set the FLASH_START = 0x26000

  • Hi Hung,

    I compared the blinky_pca10056_mbr.hex with the data written into QSPI, couple of data is mismatch with hex.

    In blinky_pca10056_mbr.hex at 4th line before end of hex file as follows

    :0E1698000D0E0F10000000000338FDD8704743
    :0416A8000090D003DB

    Data from end of the QSPI file

    d e f 10 0 0 0 0 3 38 fd d8 70 47 ff ff 0 90 d0 3 

    If you compare the above two extra two bytes 0xFF and 0xFF is read from QSPI, but remaining all are same. 

    I dont know why 0xFF, 0xFF is there after d e f 10 0 0 0 0 3 38 fd d8 70 47. 

    0 0 4 20 75 13 0 0 5d 13 0 0 5f 13 0 0 61 13 0 0 63 13 0 0 65 13 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 67 13 0 0 69 13 0 0 0 0 0 0 6b 13 0 0 6d 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 0 0 0 0 0 0 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 6f 13 0 0 0 0 0 0 0 0 0 0 6f 13 0 0 0 0 0 0 6f 13 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 35 49 36 48 a 1a 2 d0 7 22 91 43 8d 46 34 49 34 48 a 1a 6 d0 7 22 91 43 81 f3 9 88 2 22 82 f3 14 88 30 48 31 49 31 4a 0 f0 44 f8 31 48 31 49 32 4a 0 f0 3f f8 31 48 32 49 32 4a 0 f0 3a f8 32 48 32 49 33 4a 0 f0 35 f8 32 48 33 49 33 4a 0 f0 30 f8 33 48 33 49 34 4a 0 f0 2b f8 33 48 34 49 34 4a 0 f0 26 f8 34 48 34 49 0 22 0 f0 2c f8 33 48 34 49 0 22 0 f0 27 f8 33 48 33 49 9 1a 8 29 2 db 0 22 2 60 41 60 31 4a 90 47 1f 48 1f 49 88 42 5 d0 2 68 4 30 3 b4 90 47 3 bc f7 e7 0 20 86 46 ec 46 0 20 0 21 29 4a 90 47 fe e7 88 42 7 d0 52 1a 5 d0 3 78 1 30 b 70 1 31 1 3a f9 d1 70 47 88 42 2 d0 2 70 1 30 fa e7 70 47 0 0 4 20 0 e0 3 20 0 0 4 20 0 0 4 20 a8 16 0 0 8 0 0 20 c 0 0 20 d4 13 0 0 d4 13 0 0 98 16 0 0 a8 16 0 0 8 0 0 20 8 0 0 20 98 16 0 0 98 16 0 0 98 16 0 0 98 16 0 0 98 16 0 0 98 16 0 0 98 16 0 0 98 16 0 0 a6 16 0 0 ac 16 0 0 c 0 0 20 c 0 0 20 c 0 0 20 c 0 0 20 c 0 0 20 c 0 0 20 c 0 0 20 c 20 0 20 9d 13 0 0 91 14 0 0 fe e7 fe e7 fe e7 fe e7 fe e7 fe e7 fe e7 fe e7 fe e7 fe e7 70 47 0 bf 10 48 80 47 10 48 4f f0 7 1 88 43 85 46 f 48 80 47 f 48 1 68 41 f4 70 1 1 60 bf f3 4f 8f bf f3 6f 8f ff f7 32 bf a 48 b 49 b 4a 88 42 7 d0 52 1a 5 d0 3 78 1 30 b 70 1 31 1 3a f9 d1 70 47 71 13 0 0 0 0 4 20 e1 14 0 0 88 ed 0 e0 98 16 0 0 8 0 0 20 8 0 0 20 7 4b 1b 5c 1f 2b 86 bf 3 f0 1f 3 5 49 4f f0 a0 41 1 22 2 fa 3 f3 c1 f8 8 35 70 47 0 bf 98 16 0 0 0 3 0 50 8 b5 0 20 ff f7 e8 ff 1 20 ff f7 e5 ff 2 20 ff f7 e2 ff 3 20 bd e8 8 40 ff f7 dd bf 0 0 a 4b 18 5c 1f 28 8a bf 9 4b 4f f0 a0 43 0 f0 1f 0 d3 f8 4 25 1 21 81 40 21 ea 2 0 a 40 c3 f8 8 5 c3 f8 c 25 70 47 0 bf 98 16 0 0 0 3 0 50 c2 7 10 b5 4 46 c d5 4f f0 a0 43 3 22 c3 f8 34 27 c3 f8 38 27 c3 f8 3c 27 c3 f8 40 27 ff f7 c5 ff a3 7 a d5 4f f0 a0 43 c 22 c3 f8 2c 27 c3 f8 30 27 c3 f8 60 27 c3 f8 64 27 10 bd 0 0 70 b5 1 20 9 4d ff f7 db ff 45 f0 1 5 0 24 20 46 ff f7 bb ff 4f f4 fa 76 4f f4 7a 40 a8 47 1 3e fa d1 1 34 3 2c f2 d1 f0 e7 a0 16 0 0 5 4b 1b 68 8 2b 1 bf 4 4b 18 68 b0 fa 80 f0 40 9 18 bf 0 20 70 47 30 1 0 10 34 1 0 10 8 b5 4f f0 80 43 0 22 c3 f8 c 21 c3 f8 10 21 c3 f8 38 25 4f f0 80 52 3 f5 40 43 d2 f8 4 14 c3 f8 20 15 d2 f8 8 14 c3 f8 24 15 d2 f8 c 14 c3 f8 28 15 d2 f8 10 14 c3 f8 2c 15 d2 f8 14 14 c3 f8 30 15 d2 f8 18 14 c3 f8 34 15 d2 f8 1c 14 c3 f8 40 15 d2 f8 20 14 c3 f8 44 15 d2 f8 24 14 c3 f8 48 15 d2 f8 28 14 c3 f8 4c 15 d2 f8 2c 14 c3 f8 50 15 d2 f8 30 14 c3 f8 54 15 d2 f8 34 14 c3 f8 60 15 d2 f8 38 14 c3 f8 64 15 d2 f8 3c 14 c3 f8 68 15 d2 f8 40 14 c3 f8 6c 15 d2 f8 44 24 c3 f8 70 25 ff f7 9c ff 10 b1 38 4b 38 4a 1a 60 ff f7 96 ff 18 b1 37 4b fb 22 c3 f8 18 25 ff f7 8f ff 48 b1 34 49 35 4b a 68 1b 68 22 f0 f 2 3 f0 f 3 13 43 b 60 ff f7 82 ff 18 b1 30 4b 4f f4 0 72 1a 60 4f f0 80 43 d3 f8 0 24 d2 7 44 bf 6f f0 1 2 c3 f8 0 24 2a 4a d2 f8 88 30 43 f4 70 3 c2 f8 88 30 bf f3 4f 8f bf f3 6f 8f 4f f0 10 23 d3 f8 0 22 0 2a 3 db d3 f8 4 32 0 2b 2f da 20 4b 1 22 c3 f8 4 25 d3 f8 0 24 0 2a fb d0 4f f0 10 22 12 21 c2 f8 0 12 d3 f8 0 24 0 2a fb d0 4f f0 10 23 12 22 c3 f8 4 22 15 4b 1a 46 d3 f8 0 14 0 29 fb d0 0 21 c3 f8 4 15 d2 f8 0 34 0 2b fb d0 bf f3 4f 8f d 49 e 4b ca 68 2 f4 e0 62 13 43 cb 60 bf f3 4f 8f 0 bf fd e7 a 4b b 4a 1a 60 8 bd 8c 56 0 40 48 81 3 0 0 f0 0 40 e4 e 0 40 58 2 0 10 40 96 2 40 0 ed 0 e0 0 e0 1 40 4 0 fa 5 8 0 0 20 0 90 d0 3 d e f 10 0 0 0 0 3 38 fd d8 70 47 ff ff 0 90 d0 3
    This makes the hash verification fails.blinky_pca10056_mbr.hex

  • Hi Mohammad, 

    I'm sorry for late response, I was on vacation last week. 

    If you don't have the example, the application is supposed to start at address 0x1000. I'm not sure why you set the Flash Start to 0x26000

    You may want to check how the last packet is written to QSPI.

    But please clarify how you have "  Hash verification succeed " did you remove the hash checking ? 

  • @Mohammad, the Hex file line you're referencing is only 14 bytes of data.  Consequently the next two bytes of QSPI flash are not written and hence are 0xff in value.  The hash calculation may be assuming that the extra two bytes are padded with zeroes to make it a full word write (to Flash Memory).

    From what I've seen with the BLE data transfers to the DFU code, all data blocks have always been full word multiples so I'm not sure how the raw Hex data would appear on the DFU end of the transfer.

Reply
  • @Mohammad, the Hex file line you're referencing is only 14 bytes of data.  Consequently the next two bytes of QSPI flash are not written and hence are 0xff in value.  The hash calculation may be assuming that the extra two bytes are padded with zeroes to make it a full word write (to Flash Memory).

    From what I've seen with the BLE data transfers to the DFU code, all data blocks have always been full word multiples so I'm not sure how the raw Hex data would appear on the DFU end of the transfer.

Children
  • Hi TomWS

    Actually i have problem in reading QSPI data for hash calculation. I have decalred a array 

    uint8_t m_buffer_rx[CODE_PAGE_SIZE];

    In which reading data from QSPI  read,

    NRF_LOG_DEBUG("Reading buffer at address = 0x%x with size = 0x%x", src_addr, bytes);
    nrf_dfu_qspi_read(src_addr, &m_buffer_rx, ALIGN_NUM(sizeof(uint32_t), bytes));

    Error is thrown after the nrf_dfu_qspi_read is called,

    <info> nrf_dfu_validation: Hash verification. start address: 0x5000, size: 0x6AC
    <debug> nrf_dfu_qspi: nrf_qspistorage_read(addr=0x5000, src=0x200084FD, len=1708 bytes), queue usage: 1
    <error> app: Received a fault! id: 0x00004002, pc: 0x00000000, info: 0x2003FD80


    NRFX_ASSERT(nrfx_is_word_aligned(p_rx_buffer)) is thrown error because address of m_buffer_rx = 0x200084FD.

    ((((uint32_t)p_object) & 0x3u) == 0u);  ==> 1

    How to solve this issue??

  • I find it odd (no pun intended) that the buffer isn't aligned on a 32bit boundary, but the modifier __ALIGN(4) can be used to force it on a 4 byte boundary as in:

    __ALIGN(4) uint8_t m_buffer_rx[CODE_PAGE_SIZE];

  • Hi TomWS,

    Thanks for your response.

    Hash test is passed. But still the blinky_pca10056_mbr.hex is not written into flash memory because the image_copy throws,

    <debug> app: No copy needed.

    I dont understand why the (src_addr == dst_addr) are identical. 

    waiting for reply.

    =========================================================================

    <info> nrf_dfu_req_handler: Whole firmware image received. Postvalidating.
    <info> nrf_dfu_validation: Convert to hash to big-endian format for use in nrf_crypto
    <info> nrf_dfu_validation: Hash verification. start address: 0x1000, size: 0x6AC
    <debug> nrf_dfu_validation: Source address = 0x1000 and destination address = 0x16AC
    <debug> nrf_dfu_validation: Reading buffer at address = 0x1000 with size = 0x6AC
    <debug> nrf_dfu_qspi: nrf_qspistorage_read(addr=0x1000, src=0x200084F8, len=1708 bytes), queue usage: 1
    <warning> nrf_dfu_validation: Hash verification Passed!!!!!!
    <info> nrf_dfu_validation: Expected FW hash:
    <info> nrf_dfu_validation: 84 5F 42 4A E0 E9 54 C9|._BJ..T.
    <info> nrf_dfu_validation: 7C 95 6F CE E7 C1 D9 7B||.o....{
    <info> nrf_dfu_validation: 08 6A D9 E9 4A 44 C6 46|.j..JD.F
    <info> nrf_dfu_validation: F7 E8 9F A1 A5 BE 18 46|.......F
    <info> nrf_dfu_validation: Actual FW hash:
    <info> nrf_dfu_validation: 84 5F 42 4A E0 E9 54 C9|._BJ..T.
    <info> nrf_dfu_validation: 7C 95 6F CE E7 C1 D9 7B||.o....{
    <info> nrf_dfu_validation: 08 6A D9 E9 4A 44 C6 46|.j..JD.F
    <info> nrf_dfu_validation: F7 E8 9F A1 A5 BE 18 46|.......F
    <info> nrf_dfu_validation: Invalidating old application in bank 0.
    <debug> nrf_dfu_serial: Sending Response: [0x4, 0x1]
    <debug> nrf_dfu_settings: Writing settings...
    <debug> nrf_dfu_settings: Erasing old settings at: 0x000FF000
    <debug> nrf_dfu_flash: nrf_fstorage_erase(addr=0x0x000FF000, len=1 pages), queue usage: 1
    <debug> nrf_dfu_flash: Flash erase success: addr=0x000FF000, pending 0
    <debug> nrf_dfu_flash: nrf_fstorage_write(addr=0x000FF000, src=0x20009504, len=896 bytes), queue usage: 1
    <debug> nrf_dfu_flash: Flash write success: addr=0x000FF000, pending 0
    <debug> nrf_dfu_settings: Backing up settings page to address 0xFE000.
    <debug> nrf_dfu_settings: Writing settings...
    <debug> nrf_dfu_settings: Erasing old settings at: 0x000FE000
    <debug> nrf_dfu_flash: nrf_fstorage_erase(addr=0x0x000FE000, len=1 pages), queue usage: 1
    <debug> nrf_dfu_flash: Flash erase success: addr=0x000FE000, pending 0
    <debug> nrf_dfu_flash: nrf_fstorage_write(addr=0x000FE000, src=0x20009884, len=896 bytes), queue usage: 1
    <debug> nrf_dfu_flash: Flash write success: addr=0x000FE000, pending 0
    <info> nrf_dfu_req_handler: All flash operations have completed. DFU completed.
    <debug> app: Shutting down transports (found: 1)
    <info> app: Resetting bootloader.
    <debug> nrf_dfu_settings: Backing up settings page to address 0xFE000.
    <debug> nrf_dfu_settings: Destination settings are identical to source, write not needed. Skipping.
    <info> app: Inside main, Bootloader size = 73728
    <debug> app: In nrf_bootloader_init
    <debug> nrf_dfu_settings: Calling nrf_dfu_settings_init()...
    <debug> nrf_dfu_flash: Initializing nrf_fstorage_nvmc backend.
    <debug> nrf_dfu_settings: Using settings page.
    <debug> nrf_dfu_settings: Copying forbidden parts from backup page.
    <debug> nrf_dfu_settings: Destination settings are identical to source, write not needed. Skipping.
    <debug> nrf_dfu_settings: Backing up settings page to address 0xFE000.
    <debug> nrf_dfu_settings: Destination settings are identical to source, write not needed. Skipping.
    <info> app: Enter nrf_bootloader_fw_activate
    <info> app: Valid App
    <info> app: Enter nrf_dfu_app_continue
    <debug> app: No copy needed
    <info> app: Setting app as valid
    <debug> nrf_dfu_settings: Writing settings...
    <debug> nrf_dfu_settings: Erasing old settings at: 0x000FF000
    <debug> nrf_dfu_flash: nrf_fstorage_erase(addr=0x0x000FF000, len=1 pages), queue usage: 0
    <debug> nrf_dfu_flash: Flash erase success: addr=0x000FF000, pending 0
    <debug> nrf_dfu_flash: nrf_fstorage_write(addr=0x000FF000, src=0x20009504, len=896 bytes), queue usage: 1
    <debug> nrf_dfu_flash: Flash write success: addr=0x000FF000, pending 0
    <debug> nrf_dfu_settings: Backing up settings page to address 0xFE000.
    <debug> nrf_dfu_settings: Writing settings...
    <debug> nrf_dfu_settings: Erasing old settings at: 0x000FE000
    <debug> nrf_dfu_flash: nrf_fstorage_erase(addr=0x0x000FE000, len=1 pages), queue usage: 1
    <debug> nrf_dfu_flash: Flash erase success: addr=0x000FE000, pending 0
    <debug> nrf_dfu_flash: nrf_fstorage_write(addr=0x000FE000, src=0x20009884, len=896 bytes), queue usage: 1
    <debug> nrf_dfu_flash: Flash write success: addr=0x000FE000, pending 0
    <info> app: Resetting bootloader.
    <debug> nrf_dfu_settings: Backing up settings page to address 0xFE000.
    <debug> nrf_dfu_settings: Destination settings are identical to source, write not needed. Skipping.
    <info> app: Inside main, Bootloader size = 73728

  • There are multiple phases in the firmware download. 

    In the first phase (after checking that the image is valid and will fit), the image is downloaded in chunks, with each chunk either stored directly at the firmware final destination (if you are single buffering or if there isn't a valid image in place already), or to the backup buffer.  The 'settings' blocks record where the incoming image is stored and also it's final destination.

    Once the image is completely downloaded and verified, the settings blocks are saved with the corresponding addresses and the next phase (where the image is copied, IF NECESSARY, from its buffer to its final destination) is begun.

    In the next phase the settings are checked and, if the final destination AND the stored address are exactly the same, the DFU code 'knows' that the image is already in it's intended location and therefore does not need to copy the image.

    In your case, since you are using the same address in QSPI memory as the final destination, hence the copy code thinks there is nothing to do. 

    The 'trick' is to have the QSPI buffer address mapped outside of the normal range of program memory so the settings blocks can distinguish between buffered image and a properly loaded image.  You can still use '1000' as a starting address in QSPI memory, but the code sets and strips off the address field used to distinguish between internal vs external memory.  In my case, I used:

    EXTERNAL_FLASH_ADDRESS=0x0A00000;

    So address 0x1000 would map to 0x0A01000 in the code.

  • Hi TomWS,

    Thanks for your reply.

    Can you pls let me know where i need to use this,

    EXTERNAL_FLASH_ADDRESS=0x0A00000;

Related