標籤

顯示具有 Memory 標籤的文章。 顯示所有文章
顯示具有 Memory 標籤的文章。 顯示所有文章

2010年8月18日 星期三

DDR2 DIMM SPD Definition

FROM
http://www.simmtester.com/page/news/showpubnews.asp?title=DDR2+DIMM+SPD+Definition&num=139


Friday, August 25, 2006
Introduction

Since I wrote “Understanding DDR Serial Presence Detect (SPD) Table” in 2003, I have been getting a lot a feedback from readers. Some of you told me that you are using this article to train your employees,
and to introduce the mysteries SPD concept to your customers. I feel honored by your responses.

Lately, some of you had encouraged me to add the DDR2 SPD Table. Since the DDR2 DIMM has taken mainstream recently, I think this is the time to add an article for the DDR2 SPD Table. Due to the many more years of development, the DDR2 SPD table has definitely got more sophisticated than the original DDR SPD table. Your attention is required to understand and follow through. I will try to use as much layman language, as I can to accommodate you all.

Picture of a 8pin-SPD EEPROM made by Atmel

Serial Presence Detect (SPD) data is probably the most misunderstood subject in the memory module industry.
Most people only know it as the little Eprom device on the DIMM that often kept the module from working properly in the computer. On the contrary, it is quite the opposite. The SPD data actually provide vital information to the
system Bios to keep the system working in optimal condition with the memory DIMM. This article attempts to guide you through the construction of an SPD table with “Turbo-Tax” type of multiple choices questions. I hope you’ll find it interesting and useful.




Byte 0
Number of Serial PD Bytes written during module production
This field describes the total number of bytes used by the module manufacturer for the SPD data and any (optional)
specific supplier information. The byte count includes the fields for all required and optional data.
For most manufacturers, they do not insert optional data and the resulting data (in hex) would normally be:
128Byte:    80h      256Byte:    FFh 

Byte 1Total number of Bytes in Serial PD device
This field describes the total size of the serial memory used to hold the Serial Presence Detect data,
device used is usually 128 Bytes or 256 Bytes with 256 Bytes as the most common.

256 Byte (24C02)
         (34C02)  with Software Write Protect function
         (34C02B)with Reversible Software Write Protect function    :   08h
     
128 Byte (24C01):       07h    


Byte 2
Fundamental Memory Type
This refers to the DRAM type. In this case, we are only dealing with DDR2 SDRAM.
DDR2  SDRAM:     08h    

Byte 3
Number of Row Addresses on this assembly
This relates to the DRAM size as well as the Refresh scheme of the DRAM.
The best way to discover this is to use the AutoID function of the CST DIMM tester.
You would first run the AutoID on the tester. You then use the [Edit] [AdrDat] function to display the Row and Column Address counts.
15:  0Fh    14:  0Eh   13:  0Dh 12:  0Ch 

Byte 4
Number of Column Addresses on this assembly
This relates to the DRAM size as well as the Refresh scheme of the DRAM.
The best way to discover this is to use the AutoID function of the CST DIMM tester.
You would first run the AutoID on the tester. You then use the [Edit] [AdrDat] function
to display the Row and Column Address counts. 13:  0Dh   12:  0Ch   11:  0Bh  10:  0Ah   09:  09h
Byte 5
Module Attributes - Number of Physical Banks on DIMM, Package and Height
This is a multi-purpose field that involves calculations and bit combination.
A Flash program combine them together and give you an automatic result after
you have selected the different attributes.



Byte 6
Module Data Width of this assembly
This refers to the number of data bit width on the module. For a standard 8 byte DIMM, 64 bits
would be most common while an 8 byte ECC module would have 72 bits. Some special module might
even have up to 144 bits. In any case, a CST tester Auto ID function would tell you this number
in plain English.
32 bit:    20h     64 bit:   40h    72 bit:    48h    144 bit:    90h
Byte 7
Reserved
Not available: 00h      
Byte 8
Voltage Interface Level of this assembly
This refers to the power supply voltage Vdd of the DIMM. Standard DDR2 SDRAM module would be SSTL 1.8V
1.8V DDR2:   05h       Recommended Default

Byte 9
SDRAM Device Cycle time
This commonly referred to the clock frequency of the DIMM. Running at its specified CL latency.

5.0 ns (400Mhz): 50h        3.75 ns (533Mhz): 3Dh       3.0 ns    (667Mhz):      30h2.5 ns (800Mhz): 25h
Byte 10
SDRAM Device Access from Clock (tAC)
This byte defines the maximum clock to data out time for the SDRAM module. You can normally
read off the tAC specification on the Timing Parameter table.
+/-0.6 ns:            60h+/-0.5 ns:            50h+/-0.45 ns:          45h+/-0.40 ns:          40h

Byte 11
DIMM Configuration Type
This is to identify the DIMM as ECC, Parity, or Non-parity. Normally non-parity is related to
64 bit module, Parity and ECC are related to 72 bit or higher memory bit width on the module.
NonECC:     00h                       
ECC:           02hAddress/Command Parity with ECC:      06h
Byte 12
Refresh Rate
This byte describes the module's refresh rate and if it is self-refreshing or non-self refreshing.
Today, most standard modules would be capable of self-refreshing. The refresh time is easily read
from the DRAM manufacturer data sheet. Refresh time can be listed in two different ways.
1. In Refresh Interval Time. For example: 15.6usec. or 7.8usec.
2. In milli-seconds per x Refresh Cycles. For example: 62.4ms in 8K refresh
This can be converted back into refresh interval time with the equation:
Refresh Interval = Total Refresh Period/number of refresh cycles.
15.6 us Self-refresh (4K):     80h    7.8 us Self-refresh (8K):         82h 15.6 us non Self-refresh :     00h    7.8 us non Self-refresh :         02h
Byte 13
Primary SDRAM Width
This refers to the bit width of the primary data SDRAM.
For a standard DIMM module. 4 bits: 04h   8 bits: 08h    16 bits: 10h
Byte 14
Error Checking SDRAM Width
This refers to the bit width of the error checking DRAM. For a standard module,
it is either no ECC bit, or 8 bits on a regular 8 byte module. It can also be 16 bits on
a 144 bit (16 byte) module.
No-ECC:    00h      8bits:    08h    16bits:    10h
Byte 15
Reserved
Not available:  00h
Byte 16
Burst Lengths Supported
This is indicates the burst length supported. In DDR2, standard DRAM are all 4, 8 burst supported.
4, 8 Burst length supported:     0Ch          

Byte 17
Number of Banks on SDRAM Device
This is referring to the internal bank on the DRAM chip. All modern DDR2 chips under 1Gbit have
4 internal banks. For chips at 1Gbit or above, they have 8 internal banks.
4 Internal Banks:   04h         8 Internal Banks (for 1Gb or 2Gb chips only):   08h
Byte 18
CAS Latency (CL)
This refers to the all the different Cas Latency supported by your chip. This can vary with the
frequency you operate your DIMM. This number can be read off your DRAM data sheet.
CL=3 and 4 supported:                    18h
CL=4 and 5 supported:                    30h
CL=5 and 6 supported:                    60h
CL=5    supported:                          20h
CL=6    supported:                          40h

Byte 19
DIMM Mechanical Characteristics
This defines the module thickness where the maximum thickness includes all assembly parts: devices,
heat spreaders, or other mechanical components. This information together with the DIMM type, allows
the system to adjust for thermal operation specifications.

Byte 20DIMM type information
This byte identifies the DDR2 SDRAM memory module type.
Each module type specified in this Byte 20 defines a unique index for module thickness specified in Byte 19,
which may be used in conjunction with thermal specifications in Bytes 21 and 47-61 to adjust system operation
conditions based on installed modules.
 Undefined                                                 00h
 Regular Registered DIMM:                         01h
 Regular Unbuffered DIMM:                         02h
 SO-DIMM:                                               04h
 Micro-DIMM:                                            08h
 Mini-Registered DIMM:                             10h
 Mini-Unbuffered DIMM:                              20h

Byte 21
SDRAM Module Attributes
This byte involves 4 main items. Bit 0-1 signifies the number of registers on the DIMM. Bit 2-3 signifies
the number of PLL’s on the DIMM. Bit 4 indicates if any on board FET switch is enabled. Bit 6 indicates
if an analysis probe is installed. In most cases, Bit 4 and Bit 6 are not used. 
The resulting hex code is calculated as follows:

0 PLL chip and  1 Register chip            00h
0 PLL chip and  2 Register chip            01h1 PLL chip and  1 Register chip            04h1 PLL chip and  2 Register chip            05h
2 PLL chip and  1 Register chip            08h
2 PLL chip and  2 Register chip            09h


Byte 22
SDRAM Device Attributes –General
This byte is a multi-purpose byte. It includes PASR (Partial Array Self Refresh) , 50 ohm ODT enable and
also support of Weak Driver. The resultant hex code is calculated based on the selection you made.

Supports PASR                   Supports 50 ohm            Supports weak driver         HEX


No                                            No                                         No                          00hNo                                            No                                         Yes                        01h
No                                            Yes                                       No                          02h
No                                            Yes                                       Yes                        03h
Yes                                          No                                         No                          04h
Yes                                          No                                         Yes                        05h
Yes                                          Yes                                        No                         06h
Yes                                          Yes                                       Yes                        07h
  
Byte 23
SDRAM Min Clock Cycle at CLX-1
This is referred to the speed (or frequency) the DRAM can run at when the Cas Latency
is reduced by 1 clock. This data can be looked up from the datasheet of the DRAM.
This is usually listed at the first page of the data sheet where it mentioned highest
frequency it can run at a certain Cas latency setting.
De-rated latency
3.0ns (667 Mhz):      30h    
3.75 ns (533Mhz) :   3Dh
5.0 ns (400Mhz)       50h   
Undefined:               00h

Byte 24
Max Data Access Time(tAC) at CLX-1
This is referred to DQ output access time from CK/CK* at when the Cas Latency is reduced by 1 clock.
This data can be looked up from the datasheet of the DRAM. This is usually listed as tAC on the data
sheet where it mention maximum frequency it can run at a certain CAS latency setting.
+/-0.45ns:      45h          +/-0.5 ns:        50h           +/-0.6 ns:       60h     Undefined:     00h

Byte 25
SDRAM Min Clock Cycle at CLX-2
This is referred to the speed the DRAM can run at when the Cas Latency is forced to reduce by two notches.
This data can be looked up from the datasheet of the DRAM. This is usually listed at the first page of the
data sheet where it mentioned the frequency it can run at a certain Cas latency setting.
3.75 ns (533Mhz):      3Dh       5.0 ns (400Mhz):      50h         Undefined:     00h

Byte 26
Max Data Access Time(tAC)CLX-2
This is referred to DQ output access time from CK/CK* at when the Cas Latency is reduced by 2 clock.
This data can be looked up from the datasheet of the DRAM. This is usually listed as tAC on the data
sheet where it mention maximum frequency it can run at a certain CAS latency setting.
+/-0.45ns:      45h          +/-0.5 ns:        50h             +/-0.6 ns:       60h

Byte 27 Minimum Row Pre-charge Time (tRP)
This is tRP min read off the DRAM data sheet.
15 ns:   3Ch

Byte 28
Minimum Row to Row Access Delay (tRRD)
This is the tRRD min time read off the DRAM data sheet.
(x4,x8) 7.5ns:      lEh     (x16) 10 ns:       28h

Byte 29
Minimum Ras to Cas Delay (tRCD)
This is the tRCD min time read off the DRAM data sheet
15 ns:   3Ch

Byte 30
Minimum Active to Pre-charge Time (tRAS)
This is the tRAS min time read of the DRAM data sheet.
40 ns:    28h    (For DDR2 533/400Mhz)
39 ns     27h    (For DDR2 667 Mhz)

Byte 31
Module Bank Density
This refers to the Mega-Byte in each physical bank (per rank) on the DIMM.
For example: if a 256MB module has two physical banks, then each physical bank
should have 128MB.
128MB:   20h    256MB: 40h     512MB:  80h
1G:         01h    2G:       02h      4G:       04h

Byte 32

Address and Command Input Setup Time Before Clock (tIS)
This refers to the time of the address and command lines have to occur before the
next clock edge. It is labeled as tIS min in the case of DDR2.
DDR2 (tIS) 0.2ns:   20h    0.25 ns: 25h    0.30 ns: 30h     0.35 ns:  35h
Byte 33
Address and Command Input Hold Time After Clock (tIH)
This refers to the period of time the address and command lines have to hold after
the last clock edge has appeared. It is labeled as tIH min in the case of DDR2.
0.275 ns:    27h       0.325ns:    32h       0.375 ns:  37h      0.475 ns:  47h
Byte 34
SDRAM Device Data/Data Mask Input setup Time Before Data Strobe (tDS)
This refers to the time of the Data and Data Mask lines have to occur before the
next clock edge. It is labeled as tDS min in the case of DDR2.
DDR2(tDS) 0.05ns:     05h    0.10 ns: 10h     0.15 ns: 15h
Byte 35
Address and Command Input Hold Time After Clock (tDH)
This refers to the period of time the Data and Data Mask lines have to hold after
the last clock edge has appeared. It is labeled as tDH min in the case of DDR2.
DDR2(tDH)0.175ns:    17h     0.225 ns:   22h     0.275 ns:    27h

Byte 36
Write recovery time (tWR)
This byte describes the write recovery time(tWR)min
15.0 ns:   3Ch
Byte 37
Internal write to read command delay (tWTR)
This byte describes the internal write to read command delay (tWTR)min
7.5 ns:   1Eh         10.0 ns: 28h
Byte 38
Internal read to pre-charge command delay (tRTP)
This byte describes internal read to precharge command delay
(tRTP) 7.5 ns:   1Eh

Byte 39
Memory Analysis Probe Characteristics
This byte describes various functional and parametric characteristics of the memory
analysis probe connected to this DIMM slot. These characteristics may be consulted
by the BIOS to determine proper bus drive strength to account for additional bus
loading of the probe. It also describes functional characteristics of the probe that
may be used to configure the memory controller to drive proper diagnostic signals to
the probe, such as via the TEST,NC pin
Not available:    00h            Default value if probe is not described

Byte 40
Extension of Byte 41 tRC and Byte 42 tRFC
This byte serves as an extension when Byte 41 or Byte 42 has run out of space to
accommodate the bigger value
When tRFC (byte 42) is 127.5ns, byte 40 is:     06hWhen tRFC (byte 42) is 327.5ns, byte 40 is:     07hWhen tRC  (byte 41) is 63.75ns,  byte 40 is:     50hWhen tRC  (byte 41) is 65ns,      byte 40 is:      00h
Byte 41
Minimum Active to Active Auto Refresh Time (tRCmin)
53ns:     35h        54ns:      36h        55 ns:    37h            60 ns:    3Ch
63.75ns:   8Eh     65ns:      41h

Byte 42
Minimum Auto Refresh to Active Auto Refresh Time (tRFC)
This byte identifies the minimum Auto-Refresh to Active/Auto-Refresh Command Period (tRFC).
(256Mb)75 ns:     4Bh         (512Mb)105 ns:          69h
(1Gb) 127.5ns:    7Fh          (2Gb)  195ns:            C3h
(4Gb) 327.5ns:    47h

Byte 43
Maximum Device Cycle time (tCKmax)
8 ns:    80h

Byte 44
Maximum Skew Between DQS and DQ (tDQSQ)
Maximum DQS tolerance.
0.24 ns:  18h     0.30 ns: 1Eh     0.35 ns: 23h
Byte 45
Maximum Read DataHold Skew Factor (tQHS)
Maximum DOS and DO window tolerance.
0.34 ns:  22h     0.40 ns: 28h     0.45 ns: 2Dh

Byte 46
PLL Relock Time
This refers to the lock time on the PLL IC used in the registered module.
You can read this off the PLL device datasheet.
Undefined:      00h       8us:         08h          10us:          0Ah            
12us:           0Ch       15 us:       0Fh

Byte 47 to Byte 61
These bytes describe the thermal characteristic of the memory chips and the logic
chips used on the module. These are complex thermal data used in calculating the
thermal throttling of the microprocessor speed under overstress conditions. In most systems,
these data are ignored (or not available).

Byte 47
Tcasemax
Bits 7:4: Tcasemax Delta, the baseline maximum case temperature is 85 OC. Bits 3:0: DT4R4W Delta.
Not available:        00h
Byte 48
Psi T-A DRAM
Thermal resistance of DRAM device package from top (case) to ambient (Psi T-A DRAM)
Not available:        00h
Byte 49
DTO/Tcase Mode Bits
Bits 7:2:Case temperature rises from ambient due to IDDO/activate-pre- charge operation minus 2.8 OC
offset temperature. Bit 1: Double Refresh mode bit. BitO High Temperature self-refresh rate support
indication
Not available:        00h
Byte 50
DT2N/DT2Q
Case temperature rises from ambient due to IDD2N/precharge standby operation for UDIMM and due to
IDD20/precharge quiet standby operation for RDIMM.
Not available:        00h
Byte 51
DT2P
Case temperature rises from ambient due to IDD2N/precharge standby operation for UDIMM and due to
IDD20/precharge quiet standby operation for RDIMM.
Not available:        00h
Byte 52
DT3N
Case temperature rises from ambient due to IDD2P/precharge power-down operation
Not available:        00h
Byte 53
DT3Pfas
Case temperature rises from ambient due to IDD3P Fast PDN Exit/active power-down with Fast PDN
Exit operation
Not available:        00h
Byte 54
DT3Pslow
Case temperature rises from ambient due to IDD3P Slow PDN Exit/active power-down with Slow PDN
Exit operation
Not available:        00h
Byte 55
DT4R/Mode Bit
Bits 7:1: Case temperature rises from ambient due to IDD4R/page open burst read operation.
Bit 0: Mode bit to specify if DT4W is greater or less than DT4R
Not available:        00h
Byte 56
DT56
Bits 7:1: Case temperature rises from ambient due to IDD4R/page open burst read operation.
Bit 0: Mode bit to specify if DT4W is greater or less than DT4R
Not available:        00h

Byte 57
DT7
Case temperature rise from ambient due to IDD7/bank interleave read mode operation
Not available:        00h

Byte 58
Psi T-A PLL
Thermal resistance of PLL device package from top (case) to ambient (Psi T-A PLL)
Not available:        00h

Byte 59
Psi T-A Register
Thermal resistance of register device package from top (case) to ambient (Psi T-A Register)
Mot available:        00h

Byte 60
DT PLL Active
Case temperature rises from ambient due to PLLin active mode atVCC = 1.9 V the PLL loading is the DIMM loading
Not available:        00h

Byte 61
DT Register Active/Mode Bit
Bits 7:1: Case temperature rises from ambient due to register in active mode at VCC = 1.9 V,
the register loading is the RDIMM loading. Bit 0: mode bit to specify register data output toggle rate 50% or 100%
Not available:        00h

Byte 62
SPD Data Revision Code
Revision 1.0:    10h     Revision 1.1:    11 h      Revision 1.2:    12h

Byte 63
Checksum for Byte 0 to 62
Checksum is calculated and placed into this byte. All CST testers have automatic checksum calculation for this byte.
All you have to do is to fill in and audit byte 0-62, the tester will automatically fill in byte 63 for you
through the auto-checksum calculation.

Byte 64-71
Manufacturer’s JEDEC ID Code
This is a code obtained through manufacturer’s registration with JEDEC ( the standard setting committee).
A small fee is charged by JEDEC to support and maintain this record. Please contact JEDEC office.
Byte 64 is the most significant byte. If the ID is not larger then one byte (in hex), byte 65-71 should be
filled with 00h.

Byte 72
Module manufacturing Location
Optional manufacturer assigned code.

Byte 73-90
Module Part Number
Optional manufacturer assigned part number.
The manufacturer’s part number is written in ASCII format within these bytes. Byte 73 is the most
significant digit in ASCII while byte 90 is the least significant digit in ASCII. Unused digits are
coded as ASCII blanks (20h).

Byte 91-92
Module Revision Code
Optional manufacturer assigned code.

Byte 93-94
Module Manufacturing Date
Byte 93 is the year:   2005        69h       2006        6Ah        2007        6Bh
Byte 94 is the week of the year:        wk1-wk15        01h – 0Fh
                                                      wk16-wk31      10h – 1Fh
                                                      wk32-wk47      20h – 2Fh
                                                      wk48-wk52      30h – 34h

Byte 95-98
Module Serial Number
Optional manufacturer assigned number.
On the serial number setting, JEDEC has no specification on the data format nor dictates
the location of Most Significant Bit. Therefore, it’s up to individual manufacturer to
assign his numbering system. All CST testers and EZ-SPD programmers have the option for
user to select either byte 95 or byte 98 as the MSB (most significant bit). The testers
assume the use of ASCII format; which is the most commonly used. The CST testers also have
the function to automatically increment the serial number on each module tested.

Byte 99-127
Manufacturer’s Specific Data
Optional manufacturer assigned data.

Byte 128-255
Open for Customer Use
Optional for any information codes.

Final Note:

Everything in the above article and more are now implemented into the CST EZ-SPD DDR2
Programmer software. The new features are:

1. Pop up window of explanation on each Byte.
2. Clickable selection right from the illustration window.
3. Auto checksum on byte 62.
4. Text input on "manufacturer code" and "serial number". User define MSB/LSB format.
5. Auto JEDEC week and year coding from PC clock.
6. Software write protect function.

.....just to name a few.

For further information, please view : www.simmtester.com

 DDR2 SPD table reference from Micron Technology


 Byte 21- 27

Byte 28 -40

Byte 41 - 63

Byte 64- 127

2009年11月16日 星期一

讀寫SMRAM

http://bbs.pediy.com/showthread.php?t=84835



標 題: 【原創】SMM Rootkit初步 - 讀寫SMRAM(帶你邁入CPU級Rootkit之門)

作 者: 木樁

時 間: 2009-03-29,14:37

鏈 接: http://bbs.pediy.com/showthread.php?t=84835


好吧,我承認標題有點誇大,不介意的都進來BS我把

就像 qihoocom 大俠說的,「SMM XX早就幾萬年前就不是什麼秘密了」,不過國內討論這個的到是鮮見,希望這篇文章能拋磚引玉吧。


之前看到rootkit.com上 Implementing SMM PS/2 Keyboard sniffer 那個代碼,狠狠震撼了一把。於是開始研究SMM,半月下來總算有些收穫。這裡將如何讀寫SMRAM的方法拿出來科普一下,希望更多人能邁入編寫SMM Rootkit的大門。

文章後面提供可以在VPC和VMware兩大虛擬機中運行的代碼,將演示如何在WinXP(SP2)中讀寫SMRAM。(本文只考慮最簡單的系統環境,不涉及 SMM Space Locked(D_LCK)=1 時無法讀寫SMRAM的情況)另外,按 Ivanov 大牛的說法,這種方法侷限性很大,只能在沒有執行 Intel 修補方案的主板上運用(感謝兩大VM模擬的都是I440BX )。


對硬件方面接觸尚淺,文中若有疏漏之處,歡迎指正。



--------------------------------------------------------------------------------------------------------


首先放下PCI相關的諸多知識,我用最短的篇幅敘述讀寫SMRAM的過程。希望這篇文章能帶你邁出SMM Rootkit的第一步。

首先說說什麼是SMM(System Management Mode)。System Management Mode Hack中說:SMM是專門為電源管理設計的執行規則。當進入SMM後,系統的各個部件可以被關閉或者使用最低的功耗。SMM獨立於其他的系統軟件,也可以被用在其他目的...  該文章中文版點這裡


瞭解SMM是什麼東西就夠了,這篇文章不會涉及太多SMM的東西。相反,讀寫SMRAM更需要的是PCI配置空間(PCI Configuration Space)方面的知識。

先講講兩個訪問PCI配置空間的I/O端口:CF8h 和 CFCh

通過向 CF8h 端口寫一個特殊的地址,我們就可以在 CFCh 端口上讀寫指定寄存器的值。這裡要讀的寄存器是位於配置空間偏移為 72h 的8bit寄存器——SMRAM (System Management RAM Control Register)


首先要介紹一下 CF8h 這個I/O端口。實際上 I/O CF8h 寫的是CONFIG_ADDRESS寄存器,所以 CF8h又叫CONFIG_ADDRESS。其佈局如下[1]:

名稱: CONFIG_ADDRESS寄存器結構.gif 查看次數: 1684 文件大小: 7.6 KB

按上圖格式,31位置1(enable),假設I440BX的北橋82443BX位於Bus: 0, Device:0, Func:0(後面將教你如何確定芯片類型以及取得這幾個值),這樣配置空間的基址就是0x80000000。


通過I/O指令向CF8h寫入0x80000000,就可以從 CFCh(CONFIG_DATA)中讀出82443BX配置空間偏移為0的一個DWORD值了。而這個DWORD的高低16位分別是VendorID和DeviceID,如圖:

名稱: PCI配置空間頭部_cut.gif 查看次數: 1675 文件大小: 8.9 KB


下面在我們去讀配置空間偏移為72h的SMRAM前,首先注意一個特性。不知道你注意到沒有,回頭看看CONFIG_ADDRESS的低2位,它們被定義為 0。且不談PCI規範上的大道理,說白了這個地方為0是為了限制你給出的地址——必須為4的整數倍。瞭解到這一點再看那個Register Number 就比較好理解了,原來這個寄存器編號和偏移是這麼對應的。



好了,那麼偏移為72h (01110010) 的SMRAM,最後兩位置零是70h (01110000),即位於編號為1C (11100)的寄存器上。所以只要向 CF8h 裡寫入0x80000070這個地址,此時從 CFCh 端口讀出的數據就是包含SMRAM的一個DWORD了。


名稱: 82443BX Register Map_SMRAM.gif 查看次數: 1686 文件大小: 24.2 KB


假設讀出來的數據為DWORD 380A0000h (00 00 0A 38),對照上面82443BX寄存器表可知:


代碼:

70h    00
71h    00
72h    0A    SMRAM
73h    38    ESMRAMC



好了,SMRAM寄存器讀出來了,下面進入正題:如何將SMRAM內容映射到0xA0000。

從文獻[2]中瞭解到,只要D_OPEN=1時,對物理內存0xA0000的訪問會變成這樣:

名稱: SMRAM_D_OPEN.jpg 查看次數: 1684 文件大小: 23.0 KB


D_OPEN位在哪?SMRAM = 0Ah又代表什麼?根據文獻[1]記載,SMRAM的各位意義如下(關於SMRAM更詳細解釋,見文章末尾補充資料不部分):

代碼:

   7    6      5     4       3      2 - 0
   0  D_OPEN D_CLS D_LCK G_SMRAME C_BASE_SEG
        |                    1       010
        |-> 我們就是要設置 D_OPEN = 1

原來的0Ah就是 0000 1010。只要第四位的D_LCK不為1,好了,向SMRAM寫入4Ah (0100 1010),於是飛躍光明之巔!



附帶程序中整個映射SMRAM過如下:

1. 首先遍歷PCI設備,找到I440BX的82443BX Host Bridge Controller。

    (VMware Workstation 6.0.x中82443BX 的VendorID: 8086h  DeviceID: 7190h)

    (Virtual PC 2007 6.0.x 中82443BX 的VendorID: 8086h  DeviceID: 7192h)

    很幸運,這兩個虛擬機中,82443BX都位於Bus:0, Device:0, Func:0,所以PCI配置空間基址都是0x80000000。

2. 以I/O偽代碼為例,讀SMRAM:

    out( CF8h, 80000070h )   // 還記得0x80000070怎麼來的嗎?

    in( CFCh, eax )          // 讀出包含SMRAM的一個DWORD,如 380A0000h

    shr eax, 10h             // SMRAM的8bit在第三個字節處,右移16位(2字節)

    // 此時AL中就是SMRAM內容了(0Ah)

3. 置D_OPEN為1,並且C_BASE_SEG設為010

    (C_BASE_SEG在初始化時就是010了,不過為了防止意外,最好重設一下)

    out( CF8h, 80000070h )

    mov eax, 384A0000h       // 寫回D_OPEN置1後的SMRAM(4Ah)

    out( CFCh, eax )

4. 此時對物理內存0xA0000-0xBFFFF讀寫,就是在SMRAM中了。寫完試試D_OPEN=0隱藏看看,讀0xA0000是不是又回到顯存了?

注意:當SMM Space Lock(D_LCK)為1時,這種方法是無法修改SMRAM的,只能另闢蹊徑。



另外,關於讀出的SMRAM內容,一定會有人質疑0xA0000處真的是SMRAM?關於這點,可以去看看SMRAM的佈局http://www.sandpile.org/ia32/smm.htm。

我一般是通過7FF0h (EIP) 和7FF4h (EFLAGS) 這兩個DWORD判斷的(SMBASE默認是0xA0000):

> dump [000A7FC0 - 000A8000]

000A7FC0   00 00 00 00 28 00 00 00 00 04 00 00 F0 0F FF FF

000A7FD0   E1 BB 7E 81 83 A0 00 00 B2 00 00 00 00 00 00 00

000A7FE0   20 42 E6 F9 20 42 E6 F9 80 C2 A1 F9 E0 E0 6E 80

000A7FF0   47 8B A1 F9 46 02 00 00 00 90 03 00 31 00 01 80

               EIP       EFLAGS




引用:

補充資料:

這裡是 Intel 440BX AGPset: 82443BX Host Bridge Controller[1] 中關於SMRAM的詳細解釋:

名稱: SMRAM描述-System Management RAM Control Register.gif 查看次數: 1655 文件大小: 16.2 KB

名稱: 內容System Management RAM Control Register.gif 查看次數: 1651 文件大小: 81.5 KB


還有些相關知識,有時間再補上...


參考文獻:

[1] Intel 440BX AGPset: 82443BX Host Bridge Controller

    http://download.intel.com/design/chi...s/29063301.pdf

[2] Shawn Embleton, Sherri Sparks, Cliff Zou.

    SMM Rootkits: A New Breed of OS Independent Malware

[3] Loic Duflot, Daniel Etiemble, Olivier Grumelard.

    Using CPU System Management Mode to Circumvent Operating System Security Functions

[4] Intel 64 and IA-32 Architectures Software Developer's Manual Volume 3B: System Programming Guide

    http://www.intel.com/products/processor/manuals/

[5] A tool for FreeBSD to discover SMRAM on i440BX based motherboards

    http://unix.derkeiler.com/Mailing-Li...att-0448/smm.c



測試環境:

Intel Pentium D 3.0GHz 雙核 + Virtual PC 2007(6.0.192.0) + WinXP(SP2)

Intel Pentium D 3.0GHz 雙核 + VMware Workstation (6.0.4-93057) + WinXP(SP2)

AMD Athlon 64 X2 Dual 4000+ + Virtual PC 2007(6.0.192.0) + WinXP(SP2)


Virtual PC 2007下的運行截圖:

名稱: VPC運行截圖.gif 查看次數: 1684 文件大小: 23.2 KB


由於手頭沒有I440BX的主板,無法使用真實機器測試。另外 AMD64 Architecture Programmer's Manual Volume 2: System Programming 也提及了SMM的相關細節,目前還沒有仔細看。

如果你在其他芯片組上測試成功,歡迎給我來信:upbit@126.com


ps: 忘補上一個開發庫了,程序裡用到了WinIO,可以到這裡http://www.internals.com/

    WinIO這個開發庫附帶C和VB的例子,理論上我這裡給的代碼都能翻譯成C或VB的,有興趣的不妨試試

什麼是SYSTEM MANAGEMENT MODE (SMM)


System Management Mode (SMM) is intended to be used for advanced power-management features and other operating-system-independent functions. The chipset is programmed to recognize many types of events and timeouts. When such an event occurs, the chipset asserts the SMI# input pin. At the next instruction boundary, the microprocessor saves its entire state and enters SMM.

一、概述
只有SMI才會引起進入SMM,處理器保護現場,切換到SMRAM裡的一個獨立位址空間執行SMM代碼,RSM指令會使系統返回到原來的正常模式。SMM相當於實模式,沒有特權級和位址映射,可定址4GB,可執行所有I/O和可用系統指令。
SMI優先順序在所有中斷裡最高。當處於SMM狀態,處理器不識別後繼的SMI請求,但第一個SMI請求可以被鎖存,並在系統退出SMM後被處理。
RSM指令只能在SMM狀態下執行,否則會產生「操作符無效」異常(exception)。RSM把SMRAM裡的處理器內容存回處理器,接著把控制權還給被中斷程式。若處理器在SMRAM中偵測到無效狀態,會shut down並產生一特殊匯流排週期以標識該狀態。
當收到SMI時,若處理器處於HALT狀態,處理器從SMM返回會稍有不同,SMBASE位址也會有所改變。
 
二、SMRAM
SMM時,處理器在SMRAM裡執行代碼和存儲資料,也用其來存儲系統管理資訊(如系統配置和power-down設備的特殊資訊)及OEM SPEC資訊。SMRAM被映射到物理空間,最大是4GB,默認是64KB,開始於物理空間裡的SMBASE(硬體RESET後,預設值是3000H)。
處理器在[SMBASE+8000H]尋找SMI處理程式的第一條指令。[SMBASE+FE00H]:[SMBASE+FFFFH]存放處理器狀態,即處理器的所有寄存器值。

SMRAM

SMBASE+FFFFH:
Start of State Aave Area
SMBASE+FE00H:

SMI Handler Entry Point
SMBASE+8000H:



SMBASE+8000H
三、SMI執行環境
SMM與實模相似但有所不同,它可以定址4GB,加上「E」首碼就可以訪問1MB以上空間,DATA和STACK可以在4GB的任何地方。
                                      寄存器初始值:
EFLAGS

0000 0002H

EIP

0000 8000H

CS

SMBase(default: 3000h)

DS、ES、FS、GS、SS

0000H

CR0

Set PE、EM、TS、PG to 0,其他不變

DR7

0400H


四、SMM中的中斷和exception
進入SMM後,所有HW中斷都被禁止(包括可遮罩硬體中斷、單步中斷、中斷點陷阱、NMI、SMI和A20M中斷)。軟體中斷和exception能發生,但建議不要,否則可能會產生不可預料的後果。
NMI會被堵在SMI服務程式入口處,且只有第一個NMI會被鎖存並在退出SMM後被執行。但也可以通過使能INTR引腳並有效INTR的方式來在SMM中使能NMI。在一般情況下,NMI是不可嵌套的,但也有例外。若從NMI處理程式進入SMM,同時有收到新的NMI,就可以在退出SMM後實現嵌套,也就是在老的NMI處理程式裡處理新的NMI。
 
五、在SMM裡保存FPU狀態
有時在SMM裡有必要保存FPU狀態,最安全的辦法是先置處理器於保護模式下再存FPU,儘管FSAVE可以以四種格式中任一種來存PFU內容。一般默認是在實模方式下進行,但若在非16位實模下發生SMI就必須進入保護模式執行FSAVE和FRSTOR,否則無法正確保存和恢復相關FPU資訊。但存完FPU資訊後,SMI處理程式可以繼續在保護模式下執行,但建議其主要在16/32實模下運行。
 
六、SMM版本識別
31                                                        18 17 16 15                                                                  0
Reserved



SMM版本標識



Bit 17 =1 : SMBASE重定位使能
Bit 16=1 :
支援I/O指令重啟
1)
SMBASE
重定位
SMBASE默認是30000H,放在處理器內部的SMBASE寄存器裡,我們可以通過在[SMBASE+FEF8H]處設置SMBASE區來重定位SMRAM。後續SMI請求會在新位址處執行SMI處理程式和存放狀態記憶體(系統重啟後會把SMBASE寄存器又寫成30000H,但INIT不會改變它)。
若SMBASE重定位到1MB以上位址,實模下的軟體操作就不能初始化段寄存器到SMBASE。
SMBASE可用「E」首碼來訪問32位元位址大小。
2)
I/O
指令重啟
就是允許從SMM狀態返回時從被中斷I/O指令處重新執行。I/O指令重啟區[SMBASE+FF00H]控制I/O指令重啟,值為FFH時允許重啟。但該I/O指令並不是造成SMI的原因。
若從I/O指令進入SMM又收到SMI,處理器會先處理新的SMI再重啟該I/O指令。
 
七、自動HALT重啟
         若處理器在HALT狀態進入SMM,要在[SMBASE+FF02]處置自動HALT重啟標誌位元。SMI處理程式可將它清零或不予理睬,這樣返回時就相應地執行HLT指令後的下一條指令或仍回到HALT狀態。
自動HALT重啟標誌值


進入SMM後的值

退出SMM後標誌值

退出SMM狀態後處理器行為

0

0

1

1

0

1

0

1

返回到被中斷程式或任務的下一條指令
不可預料
返回到HLT指令後的下一條指令
回到HALT狀態

八、多處理器SMM注意事項


MP系統中任一處理器都要能回應SMI。


每個處理器都有自己的SMRAM空間。


不同處理器的SMRAM可在同一記憶體空間重疊,但它們的狀態存儲區和動態資料存儲區卻要彼此獨立,代碼和靜態資料可共用。


SMI處理程式要為每個處理器初始化SMBASE。


處理器可通過自己的SMI引腳或從APIC介面收到的SMI來響應本地SMI(APIC介面可將SMI分給不同的處理器)。

2009年7月4日 星期六

Corel Netwinder Memory Map-7C00

Corel Netwinder Memory Map-7C00

IDE I/O space

Address

Name

Width

Meaning

7C00.01F0

b[8]

IDE
you can do word and dword access to 01F0 for data transfer

7C00.0000,2,4,6

b[4]

DMA base and current address (4 channels)
read or write this address twice to set the 16 bit value

7C00.0001,3,5,7

b[4]

DMA base and current count (4 channels)
read or write this address twict to get/set the 16 bit value

7C00.0008

b (write)

DMA command
4=controller enable
0x10=rotating scheme
0x40=DRQ active low
0x80=DACK active hi

7C00.0008

b (read)

DMA status
1=channel 0 terminal count
2=channel 1 terminal count
4=channel 2 terminal count
8=channel 3 terminal count
0x10=channel 0 request
0x20=channel 1 request
0x40=channel 2 request
0x80=channel 3 request

7C00.0009

b (write)

DMA control
0,1,2,3=channel select
4=set request

7C00.000A

b (write)

DMA mask register
0,1,2,3=channel select
4=set mask bit

7C00.000B

b (write)

DMA mode register
0,1,2,3=channel select
transfer type: 4=write, 8=read
0x10=auto-initialize
0x20=decrement address
transfer mode:0=demand, 0x40=single, 0x80=block, 0xC0=cascade

7C00.000C

b (write)

clear the toggle address bit for 7C030000 & 7C030001

7C00.000D

b (write)

DMA hardware reset

7C00.000E

b (write)

DMA clear all mask bits

7C00.000F

b (write)

DMA set maks bits
1,2,4,8 for channels 0,1,2,3

7C00.0087, 83, 81,82

b

DMA page registers
8 bits that set the ISA address bits A23:16

7C00.040B

b

DMA extended mode
0,1,2,3=select channel
timing:0=compatible, 0x10=A type, 0x20-B type, 0x30=F type

7C00.0020

ICW1

b (write) (first write)

Irq Controller command (ICW1)
0x10 selects this register (ICW1), use 0 for the others
default is ok

7C00.0020

OCW2

b (write) (same addr)

Irq controller command (OCW2)
irq rotate modes

7C00.0020

OCW2

b (write) (same addr)

Irq controller command (OCW2)
8 selects this register
spcial mask mode, poll mode

7C00.0021

ICW2

b (write)

Irq init command (ICW2)
8-0xF8 sets high bits of interrupt vector

7C00.0021

ICW3

b (write) (same addr)

Irq init command (ICW3)
0-7 sets the link from Irq controller 2 into Irq controller 1

7C00.0021

ICW4

b (write) (same addr)

Irq init command (ICW4)
buffer and nest modes

7C00.0021

OCW1

b (write) (same addr)

Irq control reg (OCW1) (all further writes)
a 1 in a bit position masks that irq channel

7C00.04D0

b (write)

Irq edge/level control
a 1 in a bit position means level sensitve
a 0 means edge sensitive

Timers

Address

Name

Width

Meaning

7C00.0040,41,42

b (read twice)

Counter values
read/write the low-then-high bytes of the 16 bit timers 0,1,2

7C00.0040,41,42

b (read back)

Counter status
1=BCD count, 0=binary count
0xE reads back the mode selection bits
0x30 reads back the read/write selection status
0x80 reads back the OUT pin

7C00.0043

b (write)

Counter control (common to all three)
1=BCD count
0=count to end, 2=harware-retrigger one-shot, 4=rate generator, 6=square wave gen, 8=software-triggered strobe, 0xA=hardware triggered strobe
0=counter latch, 0x10=read write LSB in 7C03004x, 0x20=read/write MSB in 7C03004x, 0x30-read/write LSB then MSB in 7X03004x
0=select timer 0, 0x40=select timer 1, 0x80=select timer 2, 0xC0=select Counter Status readback

7C00.007B

s

Bios timer
a value written here will be decremented on every BCLK until 0

Misc

Address

Width

Meaning

7C00.0061

this looks incorrect!

b

NMI status/control
1=timer 2 enable
2=speaker enable
4=SERR NMI enable
8=IOCHK NMI enable
0x10=refresh on ISA bus
0x20=timer 2 output
0x40=IOCHK status
0x80=SERR status

7C00.0070

b

RTC address
0-0x7E=RTC address
0x80=NMI enable

7C00.0071

b

RTC data
first, set the RTC address (7C00.0070), then read/write the data (7C00.0071)

7C00.0810

b (write)

RTC CMOS RAM Proect 1
write this to block any writes to 0x20-0x2F of RTC space

7C00.0812

b (write)

RTC CMOS RAM Protect 2
write this to block any writes to 0x30-0x3F of RTC space

Super I/O Space

Address

Name

Width

Meaning

7C00.0378

b

Parallel port data

7C00.0379

b (read)

Parallel port print status
1=timeout
8=error-
0x10=select
0x20=paper jam
0x40=ack-
0x80=busy-

7C00.037A

b (write)

Parallel port control
1=strobe
2=auto feed
4=init-
8=select in
0x10=irq enable
0x20=set data direction to 'in'

7C00.037A

b (read)

Parallel port control swapper

7C00.037B

b

EPP address port

7C00.037C-F

b[4]

EPP dataports 0-3

7C00.03F8

BLL/BHL

b

UART divisor register; ! counts down from 24 MHz !
Note: the other UART is at 7C00.02F8

7C00.03F8

RBR/TBR

b

UART data reg: reads the rx byte, writes the tx byte

7C00.03F9

ICR

b

UART Irq control
1=rx data irq enable
2=tx buffer irq enable
4=rx status irq enable
8=handshake status irq enable

7C00.03FA

ISR

b (read)

UART Irq status
1=no irq pending, 0=irq pending
6=UART rx status, error bit set
4=rx data ready or FIFO nearly full
0xC=tx FIFO ready and waiting (timout occurred)
2=tx buffer ready
0=handshake status changed
0xC0=FIFO's enabled

7C00.03FA

UFR

b (write)

UART Fifo control
1=fifo enable
2=reset rx fifo
4=reset tx fifo
8=DMA mode select
0,0x40,0x80,0xC0 sets FIFO fill threshold

7C00.03FB

UCR

b

UART control reg
0=5 bit, 1=6 bit, 2=7 bit,3=8 bit data
4=two stop bits
8=enable parity
0x10=even parity
0x20=fixed parity
0x40=inhibit tx
0x80=enable access to baud-divisor

7C00.03FC

HCR

b

UART handshake control
1=DTR set
2=RTS set
4=loopback enabled
8=Irq enabled
0x10=internal loopback enabled

7C00.03FD

USR

b

UART status reg
1=rx data ready
2=overrun
4=parity error
8=no stop bit error
0x10=silent byte detect
0x20=tx buffer empty
0x40=tx empty
0x80=rx fifo error
any read clears the bits

7C00.03FE

HSR

b

UART handshake status
1=CTS changed
2=DSR changed
4=RI falling edge
8=DCD changed
0x10=CTS sense
0x20=DSR sense
0x40=RI sense
0x80=DCD sense

7C00.03FF

UDR

b

UART user register

7C00.0370

b

Super IO config register
write 0x87 twice to wake it up
write ext-config-register number
write 0xAA to lock it

7C00.0371

b

ext-config-register data

Misc IO

Several IO points are accessed through the "general purpose" pins on the superIO chip. We have programmed these registers to be at 0x330-0x33f in the IO space.

Physical Address

Virtual Address

Width

Meaning

7c00.0330

E000.0330 (io: 330)

16b

Misc IO registers

338

b write

0x80=turns on the red power LED
0x20=clock to serial register; data should be valid on rising edge
0x10=data to serial register
8=done signal to 5204 Xilinx (modem PCI control chip)
4=fan on; when tri-stated, fan is on by default
2=green power LED

338

b read

1=do-it button is pushed

33a

b

1=copy data from serial register to output pins: set to 1, then set to 0

The "serial register" mentioned above is an external 4 bit register which holds:
first-shifted-bit=reset the termerature chip
second-shifted-bit=enable the mono speaker (0 to mute the speaker)
third-shifted-bit=enable flash write
last-shifted-bit=turn on front panel green LED

Ext-config-register

Register (at 7C00.0370)

Width

Data (at 7C00.0371)

2

b

CR02
1=soft reset

7

b

CR07
logical device number
write this number, and then program CR30-CR71
0=FDC (we don't use this)
1=parallel
2=serialUART
3=consoleUART
4=RTC
5=keyboard
6=IR
7=aux i/o
8=aux i/o

20

b (read)

CR20 device id
assert(id==0x97)

21

b (read)

CR21 rev
assert(rev==0x71)

22

b

CR22 section power down
1=floppy power up
4=IR power up
8=parallel power up
0x10=serialUART power up
0x20=consoleUART power up

23

b

CR23 auto-power-down
0=power on, 1=stop clock incl PLL's, 2=standby for auto-power-down, 4=stop clock PLLs running
0x10-0x38=timeout to auto-power-down

24

b

CR24 PnP modes
use default

25

b

CR25
1-0x40 set TRI mode ??

26

b

CR26
1=disable consoleUART legacy irq mode
2=disable serialUART legacy irq mode
4=disable parallel legacy irq mode
0x20=lock config registers

28

b

CR28
0=parallel port normal, 5=parallel port acts as FDC
0x10=enable irq sharing

29

b

CR29
PnP id setting

2A

b

CR2A option pin assignments
0=pin 3S1 is DRVDEN, 1=pin is GP10, 2=pin is 8042 p12, 3=pin is DSRC-
0=pin 39S1 is IRRXH, 4=pin is IRSL0, 8=pin is GP25, 0xC=pin is CTSC-
0=pin 40S1 is CIRRX, 0x10=pin is GP24, 0x20=pin is 8042 p13
also pins 56S and 57S

2B

b

CR2B more option pin assignments

2C

b

CR2C more option pin assignments

30

b

CR30 section enable
1=activate this device

31

b

CR31
1=enable i/o read
2=enable i/o decoding

60, 61

b

CR60, CR61 address
set i/o address, from 0x100...0xFF8, CR60 is high byte
use defaults

70

b

CR70 interrupt control
0-0xF selects interrupt channel

71

b

CR71 interrupt control
1=level trigger, 0=edge trigger

74

b

CR74 DMA select
0-3 selects DMA channel (parallel, IR only)

F0

b

CRF0 clock select
parallel:
4=standard printer port, 0=SPP mode, 1=EPP/SPP mode, 2=ECP mode, 3=ECP/EPP mode, 5=EPP/SPP mode, 7=ECP/EPP mode
UARTs:
0=clock source is 1.8MHz, 1=clock source is 2MHz, 2=clock source is 24MHz, 3=clock source is 14.8MHz
RTC:
1=lock ram 80-9F
2=lock ram A0-BF
4=lock ram C0-DF
8=lock ram E0-FF
0x10=select bank 1 of ram, 0x20=select bank 2 of ram
KBC:
1=kb reset speed up
0=kb clk is 6MHz, 0x40=kb clk is 8MHz, 0x80=kb clk is 12MHz, 0xC0=kb clk is 16MHz
IR:
1=enable IR bank selection
2=append hardware CRC in FIR mode
4=add 4 char delay during turn-around
8=add 4 char delay during turn-around

RTC data reg's

Register (at 7C00.0070)

Width

Data (at 7c00.0071)

0-9

b[10]

RTC (bank 0)
seconds, seconds alarm, minutes, minutes alarm, hours, hours alarm, day-of-week, day-of-month, month, year

A

b

RTC control (bank 0)
0=no irq, 1=4ms irq, 2=8ms irq, 7=2ms irq, 0xB=31.24ms irq, 0xC=62.5ms, 0xD=125ms, 0xE=250ms, 0xF=500ms
0x80=update in progress

B

b

RTC control (bank 0)
1=daylight savings
2=set 24 hour mode
4=use binary mode for time
0x10=enable update-flag
0x20=enable alarm
0x40=enable periodic interupt
0x80=disable timer updates

C

b

RTC status (bank 0)

D

b

RTC status (bank 0)
0x80=ram and time are valid

E-7F

b[72]

RTC user ram (bank 0)

80-F7

b

see W83977AF manual

Super IO (cont'd)

The SuperIO contains a separate microprocessor controlling the keyboard and mouse. Communications to/from it are through this narrow portal....

Virtual Address

Width

Meaning

e000.0060

b

Keyboard controller
input/output buffer

e000.0064

b(write)

Keyboard command
20=read command
60=write command
A4=test password
A5=load password
A6=enable password
A7=disable mouse
A8=enable mouse
A9,AB=interface test
AA=self test
AD=disable keyboard
AE=enable keyboard

e000.0064

b(read)

Keyboard status
1=output buffer full
2=input buffer full
8=command byte
0x10=no inhibit
0x20=mouse output buffer full
0x40=timout error
0x80=parity error

Sound

There are many "mixer" type functions which can be programmed in the sound chip; please refer to the data sheet.

Virtual Address

Width

Meaning

E000.0250 (io: 250)

16b

Wave Artist sound device

250

b

command register
some commands: 0=get id; 0x10=set input format; 0x11=set input channel.....up to 0x29

251

b read

0x20=phone present & offhook
0x10=handset inserted
1=joystick timer finished; front panel slider is connected to joystick port

251

b write

init joystick timer

252

b

data register

254

b

control register
0x80=cmd write irq enable
0x40=cmd read irq enable
0x20=data write irq enable
0x10=data read irq enable
8=reset
4=dma1 irq enable
2=dma0 irq enable
1=int ack

255

b

status register
0x80=cmd write ready
0x40=cmd read full
0x20=data write ready
0x10=data read full
8=irq
4=dma1
2=dma0

25c

b

interrupt status

Ether10

This is a NE2000 clone, with some extensions in Bank3.

Virtual Address

Width

Meaning

e000.0300

b

command register
2=run, 1=stop controller
4=send packet
8=remote read, 0x10=remote write, 0x18=send packet,0x20=remoteDMA complete/abort
0,0x40,0x80,0xC0 sets the register bank

Bank 0

e000.0301

b (read)

DMA address lo
these two registers can be read to get the current local DMA address

e000.0301

b (write)

page start
the Page Start register sets the start page address of the receive buffer ring.

e000.0302

b (read)

DMA address hi

e000.0302

b (write)

page end
the Page Stop register sets the stop page address of the receive buffer ring.

e000.0303

b

boundary pointer
this register is used to prevent overwrite of the receive buffer ring; it is typically used as a pointer indicating the last receive buffer page the host has read.

e000.0304

b (read)

tx status
1=tx complete ok
4=collision
8=abort due to collisions
0x10=carrier lost
0x40=heartbeat miss
0x80=late collision

e000.0304

b (write)

tx page start
this register sets the start page address of the packet to the transmitted.

e000.0305

b (read)

collision count
the register records the number of collisions a node experiences during a packet transmission.

e000.0305

b (write)

tx byte count lo
these two registers set the byte counts of the packet to be transmitted.

e000.0306

b (read)

FIFO data
this register allows the host to examine the contents of the FIFO after loopback.

e000.0306

b (write)

tx byte count hi

e000.0307

b

irq status
1=rx data ready ok
2=tx data sent ok
4=rx data with error
8=tx data with error
0x10=rx data overflow
0x20=tally count overflow
0x40=remoteDMA done
0x80=reset state

e000.0308

b (read)

DMA address lo
these two registers contain the current address of remote DMA.

e000.0308

b (write)

remote start address lo
these two registers set the start address of remote DMA.

e000.0309

b (read)

DMA address hi

e000.0309

b (write)

remote start address hi

e000.030A

b (write)

remote byte count lo
these two registers set the data byte counts of remote DMA.

e000.030B

b (write)

remote byte count hi

e000.030C

b (read)

rx status
1=rx data ok
2=crc error
4=framing error
0x10=missed packet
0x20=broadcast or multicast rx
0x40=in monitor mode
0x80=collision detected

e000.030C

b (write)

rx config
1=accept bad packets
2=accept short packets (64 bytes)
4=accept broadcast
8=accept multicast
0x10=accept all addresses
0x20=monitor mode; packets not saved in ram

e000.030D

b (read)

frame align error count

e000.030D

b (write)

tx config
1=inhibit CRC append
0=normal, 2=int. loopback, 4=extern loopback
8=auto transmit disable
0x10=collisiton offset enable

e000.030E

b (read)

crc error count

e000.030E

b (write)

data config register
1=read Ether10 chip word wide
2=byte order
8=disable loopback mode
0x10=auto initialize send packet
0x20-0x60=FIFO thresh

e000.030F

b (read)

missed packet error count

e000.030F

b (write)

irq mask

Bank 1

e000.0301-6

b[5]

physical address
tthese registers contain my Ethernet node address and are used to compare the destination address of incoming packets for acceptation or rejection.

e000.0307

b

current page
this register points to the page address of the first receive buffer page to be used for packet reception.

e000.0308-F

b[8]

multicast address
these registers provide filtering bits of multicast addresses hashed by the CRC logic.

Bank 2

e000.0301

b (read)

page start

e000.0301

b (write)

current DMA addr 0

e000.0302

b (read)

page stop

e000.0302

b (write)

current DMA addr 1

e000.0303

b

remote next packet pointer

e000.0304

b (read)

tx page start address

e000.0305

b

local next packet pointer

e000.0306

b

address counter hi

e000.0307

b

address counter lo

e000.030C

b (read)

rx config

e000.030D

b

tx config

e000.030E

b (read)

data config

e000.030F

b (read)

irq mask

Bank 3

e000.030A

b

hardware config register
0=UTP/twisted pair, 3=UTP/twisted pair with "quiet" signals
4=link ok
0x10=fast ram installed

all banks

e000.0310-7

b[8]

data buffer (nominally "remote DMA")

e000.0318

b (read)

resets the Ether10 chip


Top level of memory map