1.apt-get install mingw32
2. build/envsetup.sh
3.choosecombo. config your settings
4.make USE_MINGW=y adb
make USE_MINGW=y fastboot
5.check out/host/windows-x86/bin for adb.exe/fastboot.exe
Showing posts with label kernel debug. Show all posts
Showing posts with label kernel debug. Show all posts
12/19/2012
6/02/2012
Accessory ( Headset , Headphone , ANC Headset etc ) Detection in 8660,8260 ( 8x60) Android Builds
The Accessories that can be detected by PMIC 8058 OTHC used in 8x60 are listed in
LINUX/android/kernel/include/linux/pmic8058-othc.h
enum othc_accessory_type {
OTHC_NO_DEVICE = 0,
OTHC_HEADSET = 1 << 0,
OTHC_HEADPHONE = 1 << 1,
OTHC_MICROPHONE = 1 << 2,
OTHC_ANC_HEADSET = 1 << 3,
OTHC_ANC_HEADPHONE = 1 << 4,
OTHC_ANC_MICROPHONE = 1 << 5,
OTHC_SVIDEO_OUT = 1 << 6,
};
The Logic to decide the type of accessory is based on the detect_flags that idetifies the Accessory type and other parameters as
specified in the othc_accessories array found in the file /LINUX/android/kernel/arch/arm/mach-msm/board-msm8x60.c
The Logic to decide the type of accessory is based on the detect_flags that idetifies the Accessory type and other parameters as
specified in the othc_accessories array found in the file /LINUX/android/kernel/arch/arm/mach-msm/board-msm8x60.c
static struct othc_accessory_info othc_accessories[] = {
{
.accessory = OTHC_SVIDEO_OUT,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_SWITCH_DETECT
| OTHC_ADC_DETECT,
.key_code = SW_VIDEOOUT_INSERT,
.enabled = false,
.adc_thres = {
.min_threshold = 20,
.max_threshold = 40,
},
},
{
.accessory = OTHC_ANC_HEADPHONE,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_GPIO_DETECT |
OTHC_SWITCH_DETECT,
.gpio = PM8058_LINE_IN_DET_GPIO,
.active_low = 1,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_ANC_HEADSET,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_GPIO_DETECT,
.gpio = PM8058_LINE_IN_DET_GPIO,
.active_low = 1,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_HEADPHONE,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_SWITCH_DETECT,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_MICROPHONE,
.detect_flags = OTHC_GPIO_DETECT,
.gpio = PM8058_LINE_IN_DET_GPIO,
.active_low = 1,
.key_code = SW_MICROPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_HEADSET,
.detect_flags = OTHC_MICBIAS_DETECT,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
};
If OEM want to disable the detection of any accessory then they can set .enabled = false for the Accessory they dont want to support in the above table .
The decision about which Acessory is inserted or removed is done in the function
static int pm8058_accessory_report(struct pm8058_othc *dd, int status) present in the file
LINUX/android/kernel/drivers/input/misc/pmic8058-othc.c
LINUX/android/kernel/include/linux/pmic8058-othc.h
enum othc_accessory_type {
OTHC_NO_DEVICE = 0,
OTHC_HEADSET = 1 << 0,
OTHC_HEADPHONE = 1 << 1,
OTHC_MICROPHONE = 1 << 2,
OTHC_ANC_HEADSET = 1 << 3,
OTHC_ANC_HEADPHONE = 1 << 4,
OTHC_ANC_MICROPHONE = 1 << 5,
OTHC_SVIDEO_OUT = 1 << 6,
};
The Logic to decide the type of accessory is based on the detect_flags that idetifies the Accessory type and other parameters as
specified in the othc_accessories array found in the file /LINUX/android/kernel/arch/arm/mach-msm/board-msm8x60.c
The Logic to decide the type of accessory is based on the detect_flags that idetifies the Accessory type and other parameters as
specified in the othc_accessories array found in the file /LINUX/android/kernel/arch/arm/mach-msm/board-msm8x60.c
static struct othc_accessory_info othc_accessories[] = {
{
.accessory = OTHC_SVIDEO_OUT,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_SWITCH_DETECT
| OTHC_ADC_DETECT,
.key_code = SW_VIDEOOUT_INSERT,
.enabled = false,
.adc_thres = {
.min_threshold = 20,
.max_threshold = 40,
},
},
{
.accessory = OTHC_ANC_HEADPHONE,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_GPIO_DETECT |
OTHC_SWITCH_DETECT,
.gpio = PM8058_LINE_IN_DET_GPIO,
.active_low = 1,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_ANC_HEADSET,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_GPIO_DETECT,
.gpio = PM8058_LINE_IN_DET_GPIO,
.active_low = 1,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_HEADPHONE,
.detect_flags = OTHC_MICBIAS_DETECT | OTHC_SWITCH_DETECT,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_MICROPHONE,
.detect_flags = OTHC_GPIO_DETECT,
.gpio = PM8058_LINE_IN_DET_GPIO,
.active_low = 1,
.key_code = SW_MICROPHONE_INSERT,
.enabled = true,
},
{
.accessory = OTHC_HEADSET,
.detect_flags = OTHC_MICBIAS_DETECT,
.key_code = SW_HEADPHONE_INSERT,
.enabled = true,
},
};
If OEM want to disable the detection of any accessory then they can set .enabled = false for the Accessory they dont want to support in the above table .
The decision about which Acessory is inserted or removed is done in the function
static int pm8058_accessory_report(struct pm8058_othc *dd, int status) present in the file
LINUX/android/kernel/drivers/input/misc/pmic8058-othc.c
9x15 LE - How can one create global #define in the APSS?
This solution addresses the requirement to set
#ifdef CONFIG_XXX around a piece of code
For the kernel:
Create a kernel config (in Kconfig) and enable that in the defconfig file for the product.
The config could be called CONFIG_XXX and in code you can do #ifdef CONFIG_XXX
If you are making changes in the board file, ideally � you should be using a different board file for your device/board altogether.
For Userspace:
You can add TARGET_C{PP}FLAGS to:
meta-msm/conf/machine/9615-cdp.conf
If it should be 9615-cdp specific.
meta-msm/conf/distro/msm.conf
If it's for any image that defines msm to be its distro.
#ifdef CONFIG_XXX around a piece of code
For the kernel:
Create a kernel config (in Kconfig) and enable that in the defconfig file for the product.
The config could be called CONFIG_XXX and in code you can do #ifdef CONFIG_XXX
If you are making changes in the board file, ideally � you should be using a different board file for your device/board altogether.
For Userspace:
You can add TARGET_C{PP}FLAGS to:
meta-msm/conf/machine/9615-cdp.conf
If it should be 9615-cdp specific.
meta-msm/conf/distro/msm.conf
If it's for any image that defines msm to be its distro.
How to get FW log in MDM9x15 with AR6003
Method 1:
run "recEvent -f /usr/dbg.log -b" at adb shell and FW log will be store at /usr/dbg.log with binary format
Method 2:
1. Push dbglog.h and dbglog_id.h at /etc
2. run "recEvent -f /usr/dbglog.txt -d /etc/ at adb shell and FW log will be store at /usr/dbglog.txt with text format
Hint: run "recEvent" to get help for usage.
run "recEvent -f /usr/dbg.log -b" at adb shell and FW log will be store at /usr/dbg.log with binary format
Method 2:
1. Push dbglog.h and dbglog_id.h at /etc
2. run "recEvent -f /usr/dbglog.txt -d /etc/ at adb shell and FW log will be store at /usr/dbglog.txt with text format
Hint: run "recEvent" to get help for usage.
Hot to change the regulatory setting of WCN1312 driver
WCN1312 Android driver ignore the set request of regulatory domain from WiFi UI.
The default setting of regulatory domain in WCN1312 driver is "US".
To support different regulatory domain, user can enable 802.11d feature of WCN1312 driver by changing below setting in qcom_cfg.ini,
g11dSupportEnabled=1
if the AP supports 802.11d. the AP shall broadcast its country code in beacon IE element. Driver will parse the IE and use the country code as its regulatory domain.
If you want to enforce regulatory domain, you can follow below steps:
1. read document 80-VU238-1, use nv.exe tool to generate a new qcom_wlan_nv.bin which change the default country setting:
eg: use nv.exe -s to generate a sample ini file; in the ini file, change the defaultCountry, like below example
defaultCountry=2, JPI
you also need to un-comment those setting for the regulatory region.
follow above example, you need to un-comment those setting which start with
JAPAN.XXX
After you create new qcom_wlan_nv.bin, adb push it into system/etc/firmware/wlan/ and overwrite existing one.
2. in the qcom_cfg.ini, enable gEnforceDefaultDomain:
gEnforceDefaultDomain=1
The default setting of regulatory domain in WCN1312 driver is "US".
To support different regulatory domain, user can enable 802.11d feature of WCN1312 driver by changing below setting in qcom_cfg.ini,
g11dSupportEnabled=1
if the AP supports 802.11d. the AP shall broadcast its country code in beacon IE element. Driver will parse the IE and use the country code as its regulatory domain.
If you want to enforce regulatory domain, you can follow below steps:
1. read document 80-VU238-1, use nv.exe tool to generate a new qcom_wlan_nv.bin which change the default country setting:
eg: use nv.exe -s to generate a sample ini file; in the ini file, change the defaultCountry, like below example
defaultCountry=2, JPI
you also need to un-comment those setting for the regulatory region.
follow above example, you need to un-comment those setting which start with
JAPAN.XXX
After you create new qcom_wlan_nv.bin, adb push it into system/etc/firmware/wlan/ and overwrite existing one.
2. in the qcom_cfg.ini, enable gEnforceDefaultDomain:
gEnforceDefaultDomain=1
2/16/2012
Display graphic bitmap data with JTAG Trace32.
Command syntax
Data.IMAGE <address> <horiz> <vert> [/<format> | <options>]
<format>: MONO, CGA, GrayScale8, JPEG
Palette256 <red> <green> <blue> …
Palette256X6 <address>
Palette256X12 <address>
Palette256X24 <address>
RGB111, RGB555, RGB555LE, RGB565, RGB565LE,
RGB888, RGB888LE, RGBX888, RGBX888LE,
YUV420, YUV422, YUV422P, YUV422PS, YUV422W, YUV422WS
<options>: BottomUp
FullUpdate
<format>: MONO, CGA, GrayScale8, JPEG
Palette256 <red> <green> <blue> …
Palette256X6 <address>
Palette256X12 <address>
Palette256X24 <address>
RGB111, RGB555, RGB555LE, RGB565, RGB565LE,
RGB888, RGB888LE, RGBX888, RGBX888LE,
YUV420, YUV422, YUV422P, YUV422PS, YUV422W, YUV422WS
<options>: BottomUp
FullUpdate
Example commands to display buffers :
Data.IMAGE C:0x40a4b0bc 320. 240. /YUV420
Data.IMAGE a:0x60000000 1920. 1080. /STRIDE 0x4000 /GS8
Data.IMAGE a:0x68001000 960. 540. /STRIDE 0x8000 /RGB565
Data.IMAGE a:0x68001000 960. 540. /STRIDE 0x8000 /RGB565
2/09/2012
Android Board Bring-up
Boot Architecture on MSM™
- ARM9™/AMSS boot
- On-chip PBL
- qcsbl.mbn
- oemsbl.mbn
- amss.mbn
- –
- Configures initial hardware config
(TLMM GPIO Configuration)
- –
- Configures modem's
multiprocessor subsystem
(SMEM, SMD, RPC)
- –
- Modem automatically connects to 3G network
- Application processor/Linux boot
- Android Bootloader
- –
- In /bootable/bootloader/legacy
- Linux OS image
- –
- Mounts system and user file system
- –
- Starts up Android components via system/core/rootdir, starts up initial Dalvik process
Boot Architecture on MSM (cont.)
- When power is applied to MSM, mARM executes the Primary Boot Loader (PBL) from on-chip ROM
- PBL loads Qualcomm Secondary Boot Loader (QCSBL) into memory and transitions to secondary boot stage
- System fully boots after QCSBL execution and enters operational software download mode
- Modem image is loaded on mARM
- Applications boot image, i.e., Android bootloader, is loaded into memory for aARM execution, which continues loading Android OS
Boot Architecture on QSD
- ARM9™/AMSS boot
- On-chip PBL
- dbl.mbn/fsbl.mbn
- osbl.mbn
- amss.mbn
- –
- Configures initial hardware config
(TLMM GPIO Configuration)
- –
- Configures modem's
multiprocessor subsystem
(SMEM, SMD, RPC)
- –
- Modem automatically connects
to 3G network
- Application processor/Linux boot
- Android Bootloader
- –
- In bootable/bootloader/legacy
- Linux OS image
- –
- Mounts system and user file system
- –
- Starts up Android components via system/core/rootdir, starts up initial Dalvik process

Android Bootloader Configuration~
Android Bootloader
- For MSM7xxx and QSD, modem processor plays master role and handles memory configuration and clock/voltage setting for entire system
- Android bootloader entry point (in /android/bootable/bootloader/legacy/usbloader/main.c)
- Initialize ARM11 clock speed from TCXO to 600 MHz
- Create partition table and initialize basic peripherals, such as UART, keypad, panel, USB, and flash controller
- Parse or generate ATAGs
- Load kernel and hand over to kernel init code
- Handle image download, if needed
Bootloader File Structure
- Bootloader located in:
- /android/bootable/bootloader/legacy/usbloader
- Bootloader libraries come from three categories:
- Generic
- Architecture
- Board
Bootloader File Structure –Generic Category
- Generic category contains code useful to any bootloader
- Common bootloader libraries and base architectures
- bootable/bootloader/legacy/include/boot/*.*
- bootable/bootloader/legacy/libboot/*.*
- bootable/bootloader/legacy/libc/*.*
- bootable/bootloader/legacy/arch_armv6/*.*
- Generated library and object located at:
- out/target/product/msm7627_surf/obj/STATIC_LIBRARIES/libboot_intermediates/libboot.a
- out/target/product/msm7627_surf/obj/STATIC_LIBRARIES/libboot_c_intermediates/libboot_c.a
- out/target/product/msm7627_surf/obj/STATIC_LIBRARIES/libboot_arch_armv6_intermediates/libboot_arch_armv6.a
Bootloader File Structure –Architecture Category
- Architecture category contains code useful to specific CPU, system-on-chip, etc.
- Libraries and base architectures –Headers
- bootable/bootloader/legacy/include/msm7k/*.*
- bootable/bootloader/legacy/ arch_msm7k /*.*
- Generated library and object file located at:
- out/target/product/msm7627_surf/obj/STATIC_LIBRARIES/libboot_arch_msm7k_intermediates/libboot_arch_msm7k.a
Bootloader File Structure –Board Category
- Board category contains code useful to a single, specific device
- Libraries and base architectures –Configuration
- vendor/qcom/msm7627_surf/*.*
- vendor/qcom/msm7627_surf/boot/*.*
- Generated library and object file located at:
- out/target/product/msm7627_surf/obj/STATIC_LIBRARIES/libboot_board_surf_intermediates/libboot_board_surf.a
Bootloader File Structure –Board Configuration
- The BoardConfig.mk defines important build variables:
- TARGET_BOOTLOADER_LIBS := \libboot_board_surf \libboot_arch_msm7k\libboot_arch_armv6
- TARGET_BOOTLOADER_LINK_SCRIPT := \vendor/qcom/$(TARGET_PRODUCT)/boot/boot.ld
- BOARD_KERNEL_CMDLINE := mem=203M console=ttyMSM2,115200n8 androidboot.hardware=qcom
Bootloader Configuration
- The following primary files require modification for SURF boards:
- vendor/qcom/msm7627_surf/boot/board.c –Defines flash partitions and atags, provides board-specific initialization
- vendor/qcom/msm7627_surf/boot/panel.c –Panel driver for outputting console messages
- vendor/qcom/msm7627_surf/boot/keypad.c –Keypad driver for hot-key controlling
- arch_msm7k/android/nand.c –Flash driver for NAND devices
- arch_msm7k/hsusb.c –USB driver for fast boot
- arch_msm7k/clock.c –Clock driver for setting frequency of ARM11 and AHB
- arch_msm7k/uart.c –Serial port driver
- arch_msm7k/gpio.c –GPIO driver for bootloader
Note:For QSD, similar modifications would be made under the appropriate QSD architecture subdirectory.
Flash Layout –board.c
- Flash partition table (unit –block); the partition in PTABLE must refer to allocation in /AMSS/products/7600/tools/headergen/partition.c
ptentry PTABLE[] = {
{
.start = 300,
.length = 40,
.name = "boot",
},
{
.start = 356,
.length = 512,
.name = "system"
},
{
.start = 868,
.length = 155 + 1024,
.name = "userdata",
},
{
.name = "",
},
};
Partition table
|
Range
|
Android partitions
|
0:APPSBL
|
230 –233
(1 MB)
|
Android
Bootloader
|
0:APPS +
0:FTL +
0:EFS2APPS
|
300 –339
(5 MB)
|
boot (kernel)
|
356 –867
(64 MB)
|
system
| |
868 –2046
(147 MB)
|
user data
|
Command Line –board.c
- Use Linux kernel command line (default kernel command line) or specify command line in BoardConfig.mk
const char *board_cmdline(void)
{
return "mem=201M console=ttyMSM2,115200n8";
}
- Board machine type
unsigned board_machtype(void)
{
return 1439;
}
- To register machine type, see [R1]
Keypad Configuration –keypad.c
- android/bootable/bootloader/legacy/arch_msm7k/keypad.c
- Configure GPIO for keypad
static unsigned int halibut_row_gpios[] = { 31, 32, 33, 34, 35, 41 };
static unsigned int halibut_col_gpios[] = { 36, 37, 38, 39, 40 };
- Configure special key to stop booting Linux
- –
- The following example shows two different stop boot key mappings used by two different targets –SURF and FFA
static unsigned int halibut_key_map[] = {
[11] = BOOT_KEY_CONTINUE_BOOT, /* FA on SURF, B on FFA */
[23] = BOOT_KEY_STOP_BOOT, /* FB on SURF */
[27] = BOOT_KEY_STOP_BOOT, /* 2 on FFA */
};
- On SURF, pressing the [FB] key will stop booting Linux and the system will enter Fastboot mode; the FFA's special key is [2]
Keypad Configuration –keypad.c (cont.)
- Register keypad information
static gpio_keypad_info halibut_keypad = {
.output_gpios = halibut_row_gpios,
.input_gpios = halibut_col_gpios,
.noutputs = ARRAY_SIZE(halibut_row_gpios),
.ninputs = ARRAY_SIZE(halibut_col_gpios),
.key_map = halibut_key_map,
.settle_time = 5000,
.polarity = 0,
.drive_inactive_outputs = 1
};
Panel Configuration –panel.c
- The following interfaces are implemented for the Toshiba VGA panel on SURF:
- panel_init( ) –Panel ID detection
- panel_poweron( ) –Power-on panel
- panel_backlight( ) –Control backlight of panel
- The MDDI console is implemented to output messages
- bootable/bootloader/legacy/arch_msm7k/mddi_console.c
- console_init()
- console_putc()
- console_clear()
Bootloader Framebuffer
- console_putc() calls drawglyph() to draw the character on LCD
- drawglyph(pixels + cy * 12 * fb_width + cx * 6, FGCOLOR,fb_width, font5x12 + (c -32) * 2);
- The font5x12[] is character pattern file
unsigned font5x12[] = {0x00000000, 0x00000000,0x08421080, 0x000200840x00052940, 0x00000000,0x15f52800, 0x0000295f,0x1c52f880, 0x00023e94,0x08855640, 0x0004d542,.......}
Bootloader Framebuffer (cont.)
- Default resolution in bootloader is 800 (fb_width) x 480(fb_height)
- Color format –565RGB
- bit[0:4] –Blue
- bit[5:10] –Green
- bit[11:15] –Red
- Example to splash RGB color on LCD
void splash_image(){
unsigned short *dst = mddi_framebuffer();
unsigned short color,rgb[3] = {0xf800, 0x07E0, 0x001f};
unsigned j,k;
for (j = 0; j < fb_height; j++) {
if ( !(j % (fb_height/3) ) )
color = rgb[ j/(fb_height/3) ];
for (k = 0; k < fb_width; k++ )
*dst++ = color;
}
console_flush();
}
UART Configuration –uart.c
- bootable/bootloader/legacy/arch_msm7k/uart.c
- uart_init() –Configure UART base address and init UART configuration, uart_init (n) , n = 0 (UART1), 1 (UART2), 2 (UART3)
- In uart_init()uwr(UART_CSR_115200, UART_CSR); // to change baud rate
- uart_getc() –Get input character from console
- uart_putc() –Send output character to console
- uart_put() –Send output string to console
USB Driver
- bootable/bootloader/legacy/arch_msm7k/hsusb.c
- Supports fastboot protocol to download image
- Supports Fastboot mode
- Protocol defined over USB
- Used for flashing Android bootloader, system image, and file system
- Mode normally triggered by special key sequence upon startup
- Fastboot application
- –
- Source files –system/core/fastboot
- –
- Fastboot available on Linux, Mac OSX, and Windows versions; for information regarding how to build the fastboot application, refer to [Q3]
- –
- Flashes new Android code much faster than JTAG
Bootloader MSM7x27 Clock Configuration –clock.c
- bootable/bootloader/legacy/arch_msm7k/clock.c
- ARM11 core clock source is determined by A11S_CLK_CNTL (0xC0100100) CLK_SRC1_SEL[12:14] or CLK_SRC0_SEL[4:6] and A11S_CLK_SEL (0xC0100104) CLK_SEL_SRC1N0[0]
- MSM7x27 pll speed of Dual mode frequency plan

Bootloader MSM7x27 Clock Configuration –clock.c (cont.)
- arm11_clock_init() increases the ARM11 core speed from 19.2 MHz to 600 MHz
- C = > A11S_CLK_CNTL, S => A11S_CLK_SEL
C,(CLK_SRC_TCXO << 12) | (DIV_1 << 8) | \
(CLK_SRC_TCXO << 4) | (DIV_1)),
S, ((DIV_4 << 1) | (CLK_SRC0)),
|
ARM11 : 19.2 MHz / 1 = 19.2 MHz
|
C, (CLK_SRC_TCXO << 12) | (DIV_1 << 8) | \
(CLK_SRC_PLL2 << 4) | (DIV_5)),
S, ((DIV_4 << 1) | (CLK_SRC1)),
|
ARM11 : 1200 MHz / 5 = 240 MHz
|
C, (CLK_SRC_PLL2 << 12) | (DIV_3 << 8) | \
(CLK_SRC_PLL2 << 4) | (DIV_5)),
S, ((DIV_4 << 1) | (CLK_SRC0)),
|
ARM11 : 1200 MHz / 3 = 400 MHz
|
C, (CLK_SRC_PLL2 << 12) | (DIV_3 << 8) | \
(CLK_SRC_PLL2 << 4) | (DIV_2)),
S, ((DIV_3 << 1) | (CLK_SRC1)),
|
ARM11 : 1200 MHz / 2 = 600 MHz
|
Bootloader QSD Clock Configuration –clock.c
- bootable/bootloader/legacy/arch_qsd8k/clock.c
- Scorpion core clock source is determined by SPSS_CLK_SEL (0xAC100104) register [2:1]; reset clock source is AXI Bus Clock
- arm11_clock_init() sets the Scorpion core clock source to 01: Unbuffered Snapdragon core processor PLL
val = readl(A11S_CLK_SEL);
val &= ~(0x3 << 1); // reset the clock source
val |= (1 << 1);//set clock source to SPLL
writel(val, A11S_CLK_SEL);
- The formula for SPLL is CLOCK = TCXO * L * 2, and the value of L can be configured in PLL_FSM_CTL_EXT(0xA8800010)[8:3]
val = readl(SCPLL_CTLE);
val &= ~(0x3F << 3);
val |= (0x14 << 3); //Use 0x1A instead of 0x14 for 998 MHz
writel(val, SCPLL_CTLE); //19.2 MHz*20*2=768 MHz, 19.2 MHz*26*2=998 MHz
Android Images
- Output folder is android/out/target/product/msm7627_surf
- usbloader –Android bootloader; for compliance with MIBIB architecture, a header is needed
- –
- MSM7K –appsboot.mbn (usbloader) and appsboothd.mbn
- –
- QSD8K –appsboot.mbn (40 bytes header + usbloader)
- boot.img –Image containing (boot header + Linux kernel + ramdisk/rootfs)
- system.img –Image containing Android user space applications and libraries, including libc.
Android Images –Bootimage Header
struct boot_img_hdr {
unsigned char magic[BOOT_MAGIC_SIZE];
unsigned kernel_size; /* size in bytes */
unsigned kernel_addr; /* physical load addr 0x10008000 */
unsigned ramdisk_size; /* size in bytes */
unsigned ramdisk_addr; /* physical load addr 0x11000000 */
unsigned tags_addr; /* physical addr for kernel tags
0x10000100 */
unsigned page_size; /* flash page size we assume */
unsigned unused[2]; /* future expansion: should be 0 */
unsigned char cmdline[BOOT_ARGS_SIZE];
unsigned id[8]; /* timestamp / checksum / sha1 / etc */
}
Android Kernel Configuration~
Kernel Boot Sequence
- Kernel initializing procedure
- zImage decompression
- –
- /kernel/arch/arm/boot/compressed/head.S
- ARM architecture specific kernel code
- –
- /kernel/arch/arm/kernel/head.S
- –
- /kernel/arch/arm/kernel/head-common.S
- Processor-independent kernel code
- –
- /kernel/init/main.c
- –
- start_kernel()
Memory Map Requirements of Linux Kernel on MSM
- Kernel physical memory start address recommended on 2 MB alignment
- In file /kernel/arch/arm/kernel/head.S
#if (PHYS_OFFSET & 0x001fffff)
#error "PHYS_OFFSET must be at an even 2MiB boundary!"
2/08/2012
How to increase the android dmesg buffer
dmesg - print or control the kernel ring buffer
From the code, you shoud increase the value of " CONFIG_LOG_BUF_SHIFT " . It is in arch/arm/configs/xxx-defconfig.
#define __LOG_BUF_LEN (1 << CONFIG_LOG_BUF_SHIFT) static char __log_buf[__LOG_BUF_LEN]; static int log_buf_len = __LOG_BUF_LEN;
12/30/2011
How to mount the USB disk storage decies in android device
in device/qcom/msm7627_7x_surf/vold.fstab
change:
dev_mount sdcard /mnt/sdcard auto /devices/platform/msm_sdcc.1/mmc_host
to
dev_mount sdcard /mnt/sdcard auto /devices/platform/msm_hsusb_host.0/usb1
How to get the max frequency of CPU var ADB shell
get the max:
cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
get the current:
cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq
Daisy-chain on primary JTAG, USB Trace32 for qualcomm msm7x27A
To use a daisy-chain JTAG configuration and a USB connection to the debugger, perform the steps described in this section. This configuration has not been extensively tested with 3 AMSS 76xx, and is provided for reference only.
1. Copy the following files from the release products\76XX\tools\T32 directory to C:\T32:
config-chain-arm9-usb.t32
config-chain-cortex-usb.t32
startup-chain-arm9.cmm
startup-chain-cortex.cmm
config-chain-arm9-usb.t32
config-chain-cortex-usb.t32
startup-chain-arm9.cmm
startup-chain-cortex.cmm
2. Create a shortcut to start the ARM9 Trace32 session with the following properties:
Name: Trace32 ARM9 USB Daisy-Chain
Target: C:\T32\t32marm.exe -c config-chain-arm9-usb.t32, startup-chain-arm9.cmm
Start in: C:\T32
Note that there is a comma between the configuration filename and the startup filename, but no comma between the startup filename and the debugger name.
3. Create a shortcut to start the CORTEX A5 Trace32 session with the following properties:
Name: Trace32 CORTEX A5 USB Daisy-Chain
Target: C:\T32\t32marm.exe -c config-chain-cortex-usb.t32, startup-24 chain-cortex.cmm
Start in: C:\T32
4. Start the ARM9 Trace32 session by opening the Trace32 ARM9 USB Daisy-Chain shortcut.
5. Start the CORTEX A5 session by opening the Trace32 CORTEX A5 USB Daisy-Chain shortcut.
12/09/2011
Daisy-chain on primary JTAG, USB Trace32 for qualcomm msm8x55
3 To operate properly in a dual-processor environment, Trace32 requires a special configuration
4 file and startup script. There must be a different set of these files for each processor. The files are
5 also dependent on the JTAG configuration. Example files are included in the AMSS release, in
6 the directory AMSS\products\<asic>\tools\t32.
7 By default, the Trace32 configuration file config.t32 is located in the Trace32 install directory.
8 The default startup script is t32.cmm and is also located in the same directory. For this
9 description, it is assumed that the Trace32 install directory is C:\T32.
10 Perform the following steps to install Trace32 and Qualcomm hardware support:
11 1. Follow vendor instructions to install Trace32 software to the Windows host.
12 2. Copy all of the files from the AMSS\products\<asic>\tools\T32 directory to C:\T32.
The MSM7x30 shortcuts include the following:
8 Trace32 Modem chain
9 Target – C:\T32\t32marm.exe -c C:\T32\config-chain-modem.t32,
10 startup-chain-modem.cmm
11 Start in – C:\T32
Trace32 Applications chain
17 Target – C:\T32\t32marm.exe -c c:\T32\config-chain-apps.t32,
18 startup-chain-apps.cmm
19 Start in – C:\T32
Lauterbach JTAG debugger equipment 5
6 The Modem JTAG and Applications processor JTAG can be set up in the following
7 configurations:
8 Daisy-chain Modem and Applications processor on primary JTAG – In this configuration,
9 the Modem and Applications processor JTAG tap controllers are internally daisy-chained
10 and appear on the primary JTAG port. In this configuration, the following equipment is
11 required:
12 LA-7699 Power Debug II ETH
13 LA-7742 JTAG ARM9™ with the following license extensions:
14 – LA-7765X JTAG Debugger Extension for ARM11
15 – LA-7843X JTAG Debugger Extension for Cortex
16 Primary Modem JTAG and auxiliary Applications processor JTAG – In this configuration,
17 the Modem JTAG tap controller appears on the primary JTAG port, and the Applications
18 processor appears on the auxiliary JTAG port. The following additional equipment is
19 required:
20 LA-7699 Power Debug II ETH
21 LA-7705 Debug ETH
22 LA-7742 JTAG ARM9 with the following license extension:
23 – LA-7843X JTAG Debugger Extension for Cortex
24 LA-7765 JTAG ARM11
25 NOTE: In the primary Modem JTAG and auxiliary Applications processor JTAG configuration, the
26 auxiliary JTAG port pins are the GPIO pins, whereas the primary port has dedicated pins.
4 file and startup script. There must be a different set of these files for each processor. The files are
5 also dependent on the JTAG configuration. Example files are included in the AMSS release, in
6 the directory AMSS\products\<asic>\tools\t32.
7 By default, the Trace32 configuration file config.t32 is located in the Trace32 install directory.
8 The default startup script is t32.cmm and is also located in the same directory. For this
9 description, it is assumed that the Trace32 install directory is C:\T32.
10 Perform the following steps to install Trace32 and Qualcomm hardware support:
11 1. Follow vendor instructions to install Trace32 software to the Windows host.
12 2. Copy all of the files from the AMSS\products\<asic>\tools\T32 directory to C:\T32.
The MSM7x30 shortcuts include the following:
8 Trace32 Modem chain
9 Target – C:\T32\t32marm.exe -c C:\T32\config-chain-modem.t32,
10 startup-chain-modem.cmm
11 Start in – C:\T32
Trace32 Applications chain
17 Target – C:\T32\t32marm.exe -c c:\T32\config-chain-apps.t32,
18 startup-chain-apps.cmm
19 Start in – C:\T32
Lauterbach JTAG debugger equipment 5
6 The Modem JTAG and Applications processor JTAG can be set up in the following
7 configurations:
8 Daisy-chain Modem and Applications processor on primary JTAG – In this configuration,
9 the Modem and Applications processor JTAG tap controllers are internally daisy-chained
10 and appear on the primary JTAG port. In this configuration, the following equipment is
11 required:
12 LA-7699 Power Debug II ETH
13 LA-7742 JTAG ARM9™ with the following license extensions:
14 – LA-7765X JTAG Debugger Extension for ARM11
15 – LA-7843X JTAG Debugger Extension for Cortex
16 Primary Modem JTAG and auxiliary Applications processor JTAG – In this configuration,
17 the Modem JTAG tap controller appears on the primary JTAG port, and the Applications
18 processor appears on the auxiliary JTAG port. The following additional equipment is
19 required:
20 LA-7699 Power Debug II ETH
21 LA-7705 Debug ETH
22 LA-7742 JTAG ARM9 with the following license extension:
23 – LA-7843X JTAG Debugger Extension for Cortex
24 LA-7765 JTAG ARM11
25 NOTE: In the primary Modem JTAG and auxiliary Applications processor JTAG configuration, the
26 auxiliary JTAG port pins are the GPIO pins, whereas the primary port has dedicated pins.
11/03/2011
Daisy-chain on primary JTAG, USB Trace32 for qualcomm msm7x27
Daisy-chain on primary JTAG, USBTrace32
11 To use a daisy-chain JTAG configuration and a USB connection to the debugger, perform the
12 steps described in this section. This configuration has not been extensively tested with
13 AMSS 76xx, and is provided for reference only.
14 1. Copy the following files from the release products\76XX\tools\T32 directory to C:\T32:
15
16 config-chain-arm9-usb.t32
17 config-chain-arm11-usb.t32
18 startup-chain-arm11.cmm
19 startup-chain-arm9.cmm
20
21 2. Create a shortcut to start the ARM9 Trace32 session with the following properties:
22
23 Name: Trace32 ARM9 USB Daisy-Chain
24 Target: C:\T32\t32marm.exe -c config-chain-arm9-usb.t32, startup-chain-arm9.cmm
25 Start in: C:\T32
26
27 Note that there is a comma between the configuration filename and the startup filename, but
28 no comma between the startup filename and the debugger name.
29 3. Create a shortcut to start the ARM11 Trace32 session with the following properties:
30
31 Name: Trace32 ARM11 USB Daisy-Chain
32 Target: C:\T32\t32marm.exe -c config-chain-arm11-usb.t32, startup-chain-arm11.cmm
33 Start in: C:\T32
34
35 4. Start the ARM9 Trace32 session by opening the Trace32 ARM9 USB Daisy-Chain shortcut.
36 5. Start the ARM11 session by opening the Trace32 ARM11 USB Daisy-Chain shortcut.
11 To use a daisy-chain JTAG configuration and a USB connection to the debugger, perform the
12 steps described in this section. This configuration has not been extensively tested with
13 AMSS 76xx, and is provided for reference only.
14 1. Copy the following files from the release products\76XX\tools\T32 directory to C:\T32:
15
16 config-chain-arm9-usb.t32
17 config-chain-arm11-usb.t32
18 startup-chain-arm11.cmm
19 startup-chain-arm9.cmm
20
21 2. Create a shortcut to start the ARM9 Trace32 session with the following properties:
22
23 Name: Trace32 ARM9 USB Daisy-Chain
24 Target: C:\T32\t32marm.exe -c config-chain-arm9-usb.t32, startup-chain-arm9.cmm
25 Start in: C:\T32
26
27 Note that there is a comma between the configuration filename and the startup filename, but
28 no comma between the startup filename and the debugger name.
29 3. Create a shortcut to start the ARM11 Trace32 session with the following properties:
30
31 Name: Trace32 ARM11 USB Daisy-Chain
32 Target: C:\T32\t32marm.exe -c config-chain-arm11-usb.t32, startup-chain-arm11.cmm
33 Start in: C:\T32
34
35 4. Start the ARM9 Trace32 session by opening the Trace32 ARM9 USB Daisy-Chain shortcut.
36 5. Start the ARM11 session by opening the Trace32 ARM11 USB Daisy-Chain shortcut.
5.4.5 AMSS Trace32 scripts
2 This section describes how to use the AMSS Trace32 development scripts. Unless otherwise
3 mentioned, all scripts are located in the <root>\AMSS\products\76XX\build\ms directory.
4 5.4.5.1 JTAG load
5 Steps to program the Flash and load build on the SURF or FFA with Trace32 are:
6 1. Start the ARM9 Trace32 session. Start the ARM11 Trace32 session if you want to load the
7 ARM11 image.
8 2. Run dev_mjnload_android.cmm from the ARM9 and select the modem ELF. It will prompt
9 for the apps product directory; select LINUX/android/vendor/qcom/msm7627_surf. It will
10 then prompt for vmlinux; select it by going through out/target/product/msm7627_surf/obj/
11 KERNEL_OBJ. Wait for ARM9 image loading to complete.
12 3. If the ARM11 Trace32 session is running, then the ARM11 loading process will begin.
NOTE It may be necessary to hold down the FB key after the ARM11 loads the boot image, to prevent
the bootloader from attempting to boot into the kernel. This will result in system image flashing
errors.
13 4. Wait for the ARM9 to stop at the soft_breakpoints_enabled breakpoint. Execute "do sync",
14 then "go". ARM9 and ARM11 kernel symbols will be loaded.
15 To individually load the modem symbols, use the m_jload_dev_flash.cmm script.
16 To individually load kernel symbols, load vmlinux with d.load.elf.
17 Android user space debugging may only be performed using Eclipse/ADB.
18 It is only necessary to run dev_mjnload_android.cmm when the Flash must be programmed. If
19 you have already run one of these scripts to load your build into the Flash, then you can use
20 jload.cmm to only reload the symbols, or reset.cmm to reset without reloading the symbols. Both
21 scripts are described in later sections.
22
NOTE If you rebuild, then you must run dev_mjnload_android.cmm to load the new build into the
Flash.
23
24 If you wish to debug the L4 kernel, then run the debug_kernel.cmm script. This will cause the
25 jload process to stop the ARM9 and ARM11 processors at the kernel entry point, instead of at the
26 soft_breakpoints_enabled breakpoint. At the kernel entry, the MMU is disabled, so software
27 breakpoints cannot be used. On-chip hardware breakpoints must be set instead. Note that there are
28 only two available within each ARM core. It is not until soft_breakpoints_enabled that software
29 breakpoints can be enabled. When kernel debug is enabled, it will remain enabled until it is
30 disabled or Trace32 is closed
2 This section describes how to use the AMSS Trace32 development scripts. Unless otherwise
3 mentioned, all scripts are located in the <root>\AMSS\products\76XX\build\ms directory.
4 5.4.5.1 JTAG load
5 Steps to program the Flash and load build on the SURF or FFA with Trace32 are:
6 1. Start the ARM9 Trace32 session. Start the ARM11 Trace32 session if you want to load the
7 ARM11 image.
8 2. Run dev_mjnload_android.cmm from the ARM9 and select the modem ELF. It will prompt
9 for the apps product directory; select LINUX/android/vendor/qcom/msm7627_surf. It will
10 then prompt for vmlinux; select it by going through out/target/product/msm7627_surf/obj/
11 KERNEL_OBJ. Wait for ARM9 image loading to complete.
12 3. If the ARM11 Trace32 session is running, then the ARM11 loading process will begin.
NOTE It may be necessary to hold down the FB key after the ARM11 loads the boot image, to prevent
the bootloader from attempting to boot into the kernel. This will result in system image flashing
errors.
13 4. Wait for the ARM9 to stop at the soft_breakpoints_enabled breakpoint. Execute "do sync",
14 then "go". ARM9 and ARM11 kernel symbols will be loaded.
15 To individually load the modem symbols, use the m_jload_dev_flash.cmm script.
16 To individually load kernel symbols, load vmlinux with d.load.elf.
17 Android user space debugging may only be performed using Eclipse/ADB.
18 It is only necessary to run dev_mjnload_android.cmm when the Flash must be programmed. If
19 you have already run one of these scripts to load your build into the Flash, then you can use
20 jload.cmm to only reload the symbols, or reset.cmm to reset without reloading the symbols. Both
21 scripts are described in later sections.
22
NOTE If you rebuild, then you must run dev_mjnload_android.cmm to load the new build into the
Flash.
23
24 If you wish to debug the L4 kernel, then run the debug_kernel.cmm script. This will cause the
25 jload process to stop the ARM9 and ARM11 processors at the kernel entry point, instead of at the
26 soft_breakpoints_enabled breakpoint. At the kernel entry, the MMU is disabled, so software
27 breakpoints cannot be used. On-chip hardware breakpoints must be set instead. Note that there are
28 only two available within each ARM core. It is not until soft_breakpoints_enabled that software
29 breakpoints can be enabled. When kernel debug is enabled, it will remain enabled until it is
30 disabled or Trace32 is closed
Subscribe to:
Posts (Atom)





