X-Git-Url: http://git.rot13.org/?a=blobdiff_plain;ds=sidebyside;f=firmware%2Fgoodfet.c;h=69436a14065405a07e83a19240aa7424f599b66a;hb=b6d999dedf6b66a435091e45a7d1bf69100e4b3d;hp=aa3a3f58206f9640747c162769a66dc3bb413235;hpb=ccbb5f9f7ae6fee33ba360030ecdaa76e7967024;p=goodfet diff --git a/firmware/goodfet.c b/firmware/goodfet.c index aa3a3f5..69436a1 100644 --- a/firmware/goodfet.c +++ b/firmware/goodfet.c @@ -13,11 +13,9 @@ #include "glitch.h" -//LED on P1.0 -//IO on P5 - //! Initialize registers and all that jazz. void init(){ + int i; WDTCTL = WDTPW + WDTHOLD; // Stop watchdog timer //LED out and on. @@ -28,6 +26,31 @@ void init(){ msp430_init_dco(); msp430_init_uart(); + //DAC should be at full voltage if it exists. +#ifdef DAC12IR + //glitchvoltages(0xfff,0xfff); + ADC12CTL0 = REF2_5V + REFON; // Internal 2.5V ref on + for(i=0;i!=0xFFFF;i++) asm("nop"); + DAC12_0CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1 + DAC12_0DAT = 0xFFF; //Max voltage 0xfff + DAC12_1CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1 + DAC12_1DAT = 0x000; //Min voltage 0x000 +#endif + + /** FIXME + + This part is really ugly. GSEL (P5.7) must be high to select + normal voltage, but a lot of applications light to swing it low + to be a nuissance. To get around this, we assume that anyone + with a glitching FET will also have a DAC, then we set that DAC + to a high voltage. + + At some point, each target must be sanitized to show that it + doesn't clear P5OUT or P5DIR. + */ + P5DIR|=BIT7; P5OUT=BIT7; //Normal Supply + P5DIR&=~BIT7; //Glitch Supply + //Enable Interrupts. //eint(); } @@ -61,6 +84,9 @@ void handle(unsigned char app, case JTAG: jtaghandle(app,verb,len); break; + case EJTAG: + ejtaghandle(app,verb,len); + break; case JTAG430: //Also JTAG430X, JTAG430X2 jtag430x2handle(app,verb,len); break; @@ -69,9 +95,9 @@ void handle(unsigned char app, pluginhandle(app,verb,len); }else{ debugstr("Plugin missing."); + debughex(app); txdata(app,NOK,0); } - break; } } @@ -82,6 +108,9 @@ int main(void) volatile unsigned int i; unsigned char app, verb; unsigned long len; + // MSP reboot count for reset input & reboot function located at 0xFFFE + volatile unsigned int reset_count = 0; + void (*reboot_function)(void) = (void *) 0xFFFE; init(); @@ -92,6 +121,25 @@ int main(void) while(1){ //Magic 3 app=serial_rx(); + + // If the app is the reset byte (0x80) increment and loop + if (app == 0x80) { + reset_count++; + + if (reset_count > 4) { + // We could trigger the WDT with either: + // WDTCTL = 0; + // or + // WDTCTL = WDTPW + WDTCNTCL + WDTSSEL + 0x00; + // but instead we'll jump to our reboot function pointer + (*reboot_function)(); + } + + continue; + } else { + reset_count = 0; + } + verb=serial_rx(); //len=serial_rx(); len=rxword();