皮质从RAM执行

时间:2015-07-24 09:10:21

标签: cortex-m

我需要在Cortex-M1处理器的RAM中执行固件来擦除和重写闪存。我正在使用eclipse和launchpad的工具链。 MDK-ARM也有类似的问题:How do I execute a function from RAM on a Cortex-M3 (STM32)?

要从闪存运行固件,我配置链接描述文件:

MEMORY
{
    FLASH (rx) : ORIGIN = 0x00000000, LENGTH = 8K
    RAM (rw)   : ORIGIN = 0x20004000, LENGTH = 16K
}

然后使用JLink.exe实用程序,我得到:

J-Link>r
Reset delay: 0 ms
Reset type NORMAL: Resets core & peripherals via SYSRESETREQ & VECTRESET bit.
J-Link>mem32 0x00,2
00000000 = 20008000 00000101
J-Link>SetPC 0x0101
Info: Cortex-M: Debugger tries to set PC to odd value. Corrected register value from 0x00000101 to 0x00000100
J-Link>wreg MSP 0x20008000
MSP = 0x20008000
J-Link>halt
PC = 00000100, CycleCnt = 00000000
R0 = 00000300, R1 = 00000300, R2 = 00000010, R3 = 400A8000
R4 = 00001000, R5 = 2010108C, R6 = 00002040, R7 = 00000021
R8 = 00000000, R9 = 00000000, R10= 00000008, R11= 00000000
R12= 00000000
SP(R13)= 20008000, MSP= 20008000, PSP= 00000000, R14(LR) = FFFFFFFF
XPSR = 01000000: APSR = nzcvq, EPSR = 01000000, IPSR = 000 (NoException)
CFBP = 00000000, CONTROL = 00, FAULTMASK = 00, BASEPRI = 00, PRIMASK = 00
J-Link>s
00000100:  09 49              LDR     R1, [PC, #+0x24]
J-Link>s
00000102:  0A 4A              LDR     R2, [PC, #+0x28]
J-Link>s
00000104:  0A 4B              LDR     R3, [PC, #+0x28]
J-Link>s
00000106:  00 F0 07 F8        BL      #+0x0E
J-Link>s
00000118:  9B 1A              SUB     R3, R3, R2
J-Link>

然后我想从RAM运行固件。为此,我配置链接器脚本:

MEMORY
{
    FLASH (rx) : ORIGIN = 0x20001000, LENGTH = 8K
    RAM (rw)   : ORIGIN = 0x20004000, LENGTH = 16K
}

这是我在执行时遇到错误:

 J-Link>r
Reset delay: 0 ms
Reset type NORMAL: Resets core & peripherals via SYSRESETREQ & VECTRESET bit.
J-Link>loadbin milandr-template.bin 0x20001000
Downloading file [milandr-template.bin]...O.K.
J-Link>mem32 0x20001000,2
20001000 = 20008000 20001101
J-Link>SetPC 0x20001101
Info: Cortex-M: Debugger tries to set PC to odd value. Corrected register value from 0x20001101 to 0x20001100
J-Link>wreg MSP 0x20008000
MSP = 0x20008000
J-Link>halt
PC = 20001100, CycleCnt = 00000000
R0 = 00000300, R1 = 00000300, R2 = 00000010, R3 = 400A8000
R4 = 00000648, R5 = 00000001, R6 = 00000648, R7 = 00000064
R8 = 00000800, R9 = 00000000, R10= 01000008, R11= 00000000
R12= 00000000
SP(R13)= 20008000, MSP= 20008000, PSP= 00000000, R14(LR) = FFFFFFFF
XPSR = 01000000: APSR = nzcvq, EPSR = 01000000, IPSR = 000 (NoException)
CFBP = 00000000, CONTROL = 00, FAULTMASK = 00, BASEPRI = 00, PRIMASK = 00
J-Link>s
20001100:  09 49              LDR     R1, [PC, #+0x24]
J-Link>s
00000140:  FE E7              B       #-0x04
J-Link>

这是位于闪存区域的处理器跳转到地址 - 0x00000140。 不要按预期0x20000102。 两种情况的十六进制文件都是类似的一对一。 看起来我需要检查执行第一条指令的结果有何不同:

00000100:  09 49              LDR     R1, [PC, #+0x24]

也许有人已经面对它,并且说出错误。

1 个答案:

答案 0 :(得分:1)

LDR指令在从RAM执行时生成错误。大多数默认故障处理程序如下所示:

B .

您需要查看故障寄存器以获取更多信息。但由于您的原始RAM似乎从0x20004000开始,因此地址0x20001000可能没有RAM。

您可以尝试这样的链接器文件:

MEMORY
{
    FLASH (rx) : ORIGIN = 0x20004000, LENGTH = 8K
    RAM (rw)   : ORIGIN = 0x20006000, LENGTH = 8K
}