LPC1778 checksum in vector table invalid need recover

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

LPC1778 checksum in vector table invalid need recover

355 Views
BianHaopeng1
Contributor II

你好,我在调试LPC1778的FLM时,调用FLM向0x0-0x400写入数据之后发现数据不正确。现在我的调试器无法连接芯片,我查阅了资料,认为是vector table写入的数据出错了,和我想要写入的数据不一致,导致checksum不合法。资料显示checksum不合法会导致芯片进入ISP模式等待下载程序。

1.我想知道这个状态要怎么恢复?

2.为什么FLM写0x0-0x400会引发问题,我尝试了写0x400-0x7FFFF都是正常的。翻看FLM源码,其中有个SET_VALID_CODE的参数会自动修改校验和,是不是这部分有什么问题?

Tags (1)
0 Kudos
Reply
2 Replies

17 Views
tracy74crawford
Contributor I

To recover the LPC1778, force ISP mode by holding P2.10 low during reset, then connect through UART0 and erase/reprogram the flash. An invalid vector-table checksum should cause the ROM bootloader to enter ISP, but if 0x2FC (CRP) was accidentally programmed with a CRP value, SWD/JTAG may be disabled and ISP access can also be restricted. The 0x0000–0x0400 region is special because it contains the vector table, the checksum at 0x1C, and CRP at 0x2FC; therefore, writing it as ordinary data can cause exactly this problem. SET_VALID_CODE is intended to correct the vector checksum, so it is not inherently wrong, but you should verify that your FLM applies it to the correct vector-table format/address and that the CRP word at 0x2FC is preserved correctly. Writing 0x400–0x7FFFF works because it avoids these bootloader-sensitive locations.

0 Kudos
Reply

326 Views
Harry_Zhang
NXP Employee
NXP Employee

Hi @BianHaopeng1 

0x0000–0x0400 不只是普通 flash 数据区,它包含启动向量表、0x1C 的 valid-code checksum,以及 0x2FC 的 CRP 配置字 。checksum 错会让 ROM bootloader 判定 user code invalid 并进入 ISP;如果 0x2FC 被误写成 CRP pattern,还会导致 JTAG/SWD 访问受限甚至不可恢复到普通调试状态。

您可以优先按 ISP 恢复 处理:

拉低 P2[10],然后复位芯片 ,bootloader 接管并进入 ISP mode。

通过 UART0:P0[2] / P0[3] 连接 FlashMagic 或等价 ISP 工具,执行全片擦除或重新下载一个有效镜像。

如果只是 checksum 不合法 ,进入 ISP 后应能擦除并恢复;如果误写了 CRP1/CRP2 ,JTAG 会被禁用,但 ISP 仍有受限恢复路径;如果误写成 CRP3 ,文档说明它会完全禁止 JTAG 和 ISP,这种情况下基本不能再通过常规 ISP/JTAG 恢复。

BR

Harry

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2389468%22%20slang%3D%22zh-CN%22%20mode%3D%22CREATE%22%3ELPC1778%20checksum%20in%20vector%20table%20invalid%20need%20recover%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2389468%22%20slang%3D%22zh-CN%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%20when%20debugging%20the%20FLM%20of%20the%20LPC1778%2C%20I%20found%20that%20the%20data%20was%20incorrect%20after%20writing%20data%20to%200x0-0x400%20using%20the%20FLM.%20Now%20my%20debugger%20cannot%20connect%20to%20the%20chip.%20I%20have%20consulted%20the%20documentation%20and%20believe%20that%20the%20data%20written%20to%20the%20vector%20table%20is%20incorrect%20and%20does%20not%20match%20the%20data%20I%20want%20to%20write%2C%20resulting%20in%20an%20invalid%20checksum.%20The%20documentation%20indicates%20that%20an%20invalid%20checksum%20will%20cause%20the%20chip%20to%20enter%20ISP%20mode%20and%20wait%20for%20program%20download.%3C%2FP%3E%3CP%3E1.%20I%20want%20to%20know%20how%20to%20recover%20from%20this%20state%3F%3C%2FP%3E%3CP%3E2.%20Why%20does%20writing%200x0-0x400%20cause%20problems%20in%20FLM%2C%20while%20writing%200x400-0x7FFFF%20works%20fine%3F%20Looking%20at%20the%20FLM%20source%20code%2C%20there's%20a%20parameter%20called%20SET_VALID_CODE%20that%20automatically%20modifies%20the%20checksum.%20Is%20there%20something%20wrong%20with%20this%20part%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2389685%22%20slang%3D%22zh-CN%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20LPC1778%20checksum%20in%20vector%20table%20invalid%20need%20recover%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2389685%22%20slang%3D%22zh-CN%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F262795%22%20target%3D%22_blank%22%3E%40BianHaopeng1%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThe%200x0000%E2%80%930x0400%20area%20is%20not%20just%20a%20regular%20flash%20data%20area%3B%20it%20contains%20the%20boot%20vector%20table%2C%20the%20valid-code%20checksum%20at%200x1C%2C%20and%20the%20CRP%20configuration%20word%20at%200x2FC.%20An%20incorrect%20checksum%20will%20cause%20the%20ROM%20bootloader%20to%20determine%20that%20the%20user%20code%20is%20invalid%20and%20enter%20the%20ISP%20(In-Service%20Module).%20If%200x2FC%20is%20mistakenly%20written%20as%20the%20CRP%20pattern%2C%20it%20will%20also%20cause%20JTAG%2FSWD%20access%20to%20be%20restricted%20or%20even%20make%20it%20impossible%20to%20return%20to%20normal%20debug%20mode.%3C%2FP%3E%0A%3CP%3EYou%20can%20prioritize%20recovery%20by%20ISP%3A%3C%2FP%3E%0A%3CP%3EP2%5B10%5D%20is%20pulled%20low%2C%20then%20the%20chip%20is%20reset%2C%20the%20bootloader%20takes%20over%20and%20enters%20ISP%20mode.%3C%2FP%3E%0A%3CP%3EConnect%20to%20FlashMagic%20or%20an%20equivalent%20ISP%20tool%20via%20UART0%3AP0%5B2%5D%20%2F%20P0%5B3%5D%20to%20perform%20a%20full%20wipe%20or%20re-download%20a%20valid%20image.%3C%2FP%3E%0A%3CP%3EIf%20only%20the%20checksum%20is%20invalid%2C%20it%20should%20be%20able%20to%20be%20erased%20and%20restored%20after%20entering%20the%20ISP%3B%20if%20CRP1%2FCRP2%20is%20mistakenly%20written%2C%20JTAG%20will%20be%20disabled%2C%20but%20the%20ISP%20still%20has%20a%20limited%20recovery%20path%3B%20if%20CRP3%20is%20mistakenly%20written%2C%20the%20documentation%20states%20that%20it%20will%20completely%20block%20JTAG%20and%20the%20ISP%2C%20in%20which%20case%20it%20is%20basically%20impossible%20to%20recover%20through%20the%20regular%20ISP%2FJTAG.%3C%2FP%3E%0A%3CP%3EBR%3C%2FP%3E%0A%3CP%3EHarry%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2410904%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20LPC1778%20checksum%20in%20vector%20table%20invalid%20need%20recover%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2410904%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3ETo%20recover%20the%20LPC1778%2C%20force%20ISP%20mode%20by%20holding%20P2.10%20low%20during%20reset%2C%20then%20connect%20through%20UART0%20and%20erase%2Freprogram%20the%20flash.%20An%20invalid%20vector-table%20checksum%20should%20cause%20the%20ROM%20bootloader%20to%20enter%20ISP%2C%20but%20if%200x2FC%20(CRP)%20was%20accidentally%20programmed%20with%20a%20CRP%20value%2C%20SWD%2FJTAG%20may%20be%20disabled%20and%20ISP%20access%20can%20also%20be%20restricted.%26nbsp%3BThe%200x0000%E2%80%930x0400%20region%20is%20special%20because%20it%20contains%20the%20vector%20table%2C%20the%20checksum%20at%200x1C%2C%20and%20CRP%20at%200x2FC%3B%20therefore%2C%20writing%20it%20as%20ordinary%20data%20can%20cause%20exactly%20this%20problem.%20SET_VALID_CODE%20is%20intended%20to%20correct%20the%20vector%20checksum%2C%20so%20it%20is%20not%20inherently%20wrong%2C%20but%20you%20should%20verify%20that%20your%20FLM%20applies%20it%20to%20the%20correct%20vector-table%20format%2Faddress%20and%20that%20the%20CRP%20word%20at%200x2FC%20is%20preserved%20correctly.%20Writing%200x400%E2%80%930x7FFFF%20works%20because%20it%20avoids%20these%20bootloader-sensitive%20locations.%3C%2FP%3E%3C%2FLINGO-BODY%3E