Statistics
| Branch: | Revision:

root / hw / sd.c @ a350e694

History | View | Annotate | Download (44.5 kB)

1 5fafdf24 ths
/*
2 a1bb27b1 pbrook
 * SD Memory Card emulation as defined in the "SD Memory Card Physical
3 a1bb27b1 pbrook
 * layer specification, Version 1.10."
4 a1bb27b1 pbrook
 *
5 a1bb27b1 pbrook
 * Copyright (c) 2006 Andrzej Zaborowski  <balrog@zabor.org>
6 a1bb27b1 pbrook
 * Copyright (c) 2007 CodeSourcery
7 a1bb27b1 pbrook
 *
8 a1bb27b1 pbrook
 * Redistribution and use in source and binary forms, with or without
9 a1bb27b1 pbrook
 * modification, are permitted provided that the following conditions
10 a1bb27b1 pbrook
 * are met:
11 a1bb27b1 pbrook
 *
12 a1bb27b1 pbrook
 * 1. Redistributions of source code must retain the above copyright
13 a1bb27b1 pbrook
 *    notice, this list of conditions and the following disclaimer.
14 a1bb27b1 pbrook
 * 2. Redistributions in binary form must reproduce the above copyright
15 a1bb27b1 pbrook
 *    notice, this list of conditions and the following disclaimer in
16 a1bb27b1 pbrook
 *    the documentation and/or other materials provided with the
17 a1bb27b1 pbrook
 *    distribution.
18 a1bb27b1 pbrook
 *
19 a1bb27b1 pbrook
 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS''
20 a1bb27b1 pbrook
 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
21 a1bb27b1 pbrook
 * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
22 a1bb27b1 pbrook
 * PARTICULAR PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR
23 a1bb27b1 pbrook
 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
24 a1bb27b1 pbrook
 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
25 a1bb27b1 pbrook
 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
26 a1bb27b1 pbrook
 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
27 a1bb27b1 pbrook
 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
28 a1bb27b1 pbrook
 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
29 a1bb27b1 pbrook
 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
30 a1bb27b1 pbrook
 */
31 a1bb27b1 pbrook
32 87ecb68b pbrook
#include "hw.h"
33 87ecb68b pbrook
#include "block.h"
34 a1bb27b1 pbrook
#include "sd.h"
35 a1bb27b1 pbrook
36 a1bb27b1 pbrook
//#define DEBUG_SD 1
37 a1bb27b1 pbrook
38 a1bb27b1 pbrook
#ifdef DEBUG_SD
39 a1bb27b1 pbrook
#define DPRINTF(fmt, args...) \
40 827df9f3 balrog
do { fprintf(stderr, "SD: " fmt , ##args); } while (0)
41 a1bb27b1 pbrook
#else
42 a1bb27b1 pbrook
#define DPRINTF(fmt, args...) do {} while(0)
43 a1bb27b1 pbrook
#endif
44 a1bb27b1 pbrook
45 a1bb27b1 pbrook
typedef enum {
46 a1bb27b1 pbrook
    sd_r0 = 0,    /* no response */
47 a1bb27b1 pbrook
    sd_r1,        /* normal response command */
48 a1bb27b1 pbrook
    sd_r2_i,      /* CID register */
49 a1bb27b1 pbrook
    sd_r2_s,      /* CSD register */
50 a1bb27b1 pbrook
    sd_r3,        /* OCR register */
51 a1bb27b1 pbrook
    sd_r6 = 6,    /* Published RCA response */
52 1b088995 balrog
    sd_r7,        /* Operating voltage */
53 a1bb27b1 pbrook
    sd_r1b = -1,
54 a1bb27b1 pbrook
} sd_rsp_type_t;
55 a1bb27b1 pbrook
56 a1bb27b1 pbrook
struct SDState {
57 a1bb27b1 pbrook
    enum {
58 a1bb27b1 pbrook
        sd_inactive,
59 a1bb27b1 pbrook
        sd_card_identification_mode,
60 a1bb27b1 pbrook
        sd_data_transfer_mode,
61 a1bb27b1 pbrook
    } mode;
62 a1bb27b1 pbrook
    enum {
63 a1bb27b1 pbrook
        sd_inactive_state = -1,
64 a1bb27b1 pbrook
        sd_idle_state = 0,
65 a1bb27b1 pbrook
        sd_ready_state,
66 a1bb27b1 pbrook
        sd_identification_state,
67 a1bb27b1 pbrook
        sd_standby_state,
68 a1bb27b1 pbrook
        sd_transfer_state,
69 a1bb27b1 pbrook
        sd_sendingdata_state,
70 a1bb27b1 pbrook
        sd_receivingdata_state,
71 a1bb27b1 pbrook
        sd_programming_state,
72 a1bb27b1 pbrook
        sd_disconnect_state,
73 a1bb27b1 pbrook
    } state;
74 a1bb27b1 pbrook
    uint32_t ocr;
75 a1bb27b1 pbrook
    uint8_t scr[8];
76 a1bb27b1 pbrook
    uint8_t cid[16];
77 a1bb27b1 pbrook
    uint8_t csd[16];
78 a1bb27b1 pbrook
    uint16_t rca;
79 a1bb27b1 pbrook
    uint32_t card_status;
80 a1bb27b1 pbrook
    uint8_t sd_status[64];
81 1b088995 balrog
    uint32_t vhs;
82 a1bb27b1 pbrook
    int wp_switch;
83 a1bb27b1 pbrook
    int *wp_groups;
84 a1bb27b1 pbrook
    uint32_t size;
85 a1bb27b1 pbrook
    int blk_len;
86 a1bb27b1 pbrook
    uint32_t erase_start;
87 a1bb27b1 pbrook
    uint32_t erase_end;
88 a1bb27b1 pbrook
    uint8_t pwd[16];
89 a1bb27b1 pbrook
    int pwd_len;
90 a1bb27b1 pbrook
    int function_group[6];
91 a1bb27b1 pbrook
92 775616c3 pbrook
    int spi;
93 a1bb27b1 pbrook
    int current_cmd;
94 a1bb27b1 pbrook
    int blk_written;
95 a1bb27b1 pbrook
    uint32_t data_start;
96 a1bb27b1 pbrook
    uint32_t data_offset;
97 a1bb27b1 pbrook
    uint8_t data[512];
98 02ce600c balrog
    qemu_irq readonly_cb;
99 02ce600c balrog
    qemu_irq inserted_cb;
100 a1bb27b1 pbrook
    BlockDriverState *bdrv;
101 33f00271 balrog
    uint8_t *buf;
102 827df9f3 balrog
103 827df9f3 balrog
    int enable;
104 a1bb27b1 pbrook
};
105 a1bb27b1 pbrook
106 a1bb27b1 pbrook
static void sd_set_status(SDState *sd)
107 a1bb27b1 pbrook
{
108 a1bb27b1 pbrook
    switch (sd->state) {
109 a1bb27b1 pbrook
    case sd_inactive_state:
110 a1bb27b1 pbrook
        sd->mode = sd_inactive;
111 a1bb27b1 pbrook
        break;
112 a1bb27b1 pbrook
113 a1bb27b1 pbrook
    case sd_idle_state:
114 a1bb27b1 pbrook
    case sd_ready_state:
115 a1bb27b1 pbrook
    case sd_identification_state:
116 a1bb27b1 pbrook
        sd->mode = sd_card_identification_mode;
117 a1bb27b1 pbrook
        break;
118 a1bb27b1 pbrook
119 a1bb27b1 pbrook
    case sd_standby_state:
120 a1bb27b1 pbrook
    case sd_transfer_state:
121 a1bb27b1 pbrook
    case sd_sendingdata_state:
122 a1bb27b1 pbrook
    case sd_receivingdata_state:
123 a1bb27b1 pbrook
    case sd_programming_state:
124 a1bb27b1 pbrook
    case sd_disconnect_state:
125 a1bb27b1 pbrook
        sd->mode = sd_data_transfer_mode;
126 a1bb27b1 pbrook
        break;
127 a1bb27b1 pbrook
    }
128 a1bb27b1 pbrook
129 a1bb27b1 pbrook
    sd->card_status &= ~CURRENT_STATE;
130 a1bb27b1 pbrook
    sd->card_status |= sd->state << 9;
131 a1bb27b1 pbrook
}
132 a1bb27b1 pbrook
133 1b088995 balrog
static const sd_cmd_type_t sd_cmd_type[64] = {
134 a1bb27b1 pbrook
    sd_bc,   sd_none, sd_bcr,  sd_bcr,  sd_none, sd_none, sd_none, sd_ac,
135 1b088995 balrog
    sd_bcr,  sd_ac,   sd_ac,   sd_adtc, sd_ac,   sd_ac,   sd_none, sd_ac,
136 a1bb27b1 pbrook
    sd_ac,   sd_adtc, sd_adtc, sd_none, sd_none, sd_none, sd_none, sd_none,
137 a1bb27b1 pbrook
    sd_adtc, sd_adtc, sd_adtc, sd_adtc, sd_ac,   sd_ac,   sd_adtc, sd_none,
138 a1bb27b1 pbrook
    sd_ac,   sd_ac,   sd_none, sd_none, sd_none, sd_none, sd_ac,   sd_none,
139 a1bb27b1 pbrook
    sd_none, sd_none, sd_bc,   sd_none, sd_none, sd_none, sd_none, sd_none,
140 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_ac,
141 a1bb27b1 pbrook
    sd_adtc, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none,
142 a1bb27b1 pbrook
};
143 a1bb27b1 pbrook
144 1b088995 balrog
static const sd_cmd_type_t sd_acmd_type[64] = {
145 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_ac,   sd_none,
146 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_adtc, sd_none, sd_none,
147 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_adtc, sd_ac,
148 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none,
149 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none,
150 a1bb27b1 pbrook
    sd_none, sd_bcr,  sd_ac,   sd_none, sd_none, sd_none, sd_none, sd_none,
151 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_adtc, sd_none, sd_none, sd_none, sd_none,
152 a1bb27b1 pbrook
    sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none, sd_none,
153 a1bb27b1 pbrook
};
154 a1bb27b1 pbrook
155 a1bb27b1 pbrook
static const int sd_cmd_class[64] = {
156 a1bb27b1 pbrook
    0,  0,  0,  0,  0,  9, 10,  0,  0,  0,  0,  1,  0,  0,  0,  0,
157 a1bb27b1 pbrook
    2,  2,  2,  2,  3,  3,  3,  3,  4,  4,  4,  4,  6,  6,  6,  6,
158 a1bb27b1 pbrook
    5,  5, 10, 10, 10, 10,  5,  9,  9,  9,  7,  7,  7,  7,  7,  7,
159 a1bb27b1 pbrook
    7,  7, 10,  7,  9,  9,  9,  8,  8, 10,  8,  8,  8,  8,  8,  8,
160 a1bb27b1 pbrook
};
161 a1bb27b1 pbrook
162 a1bb27b1 pbrook
static uint8_t sd_crc7(void *message, size_t width)
163 a1bb27b1 pbrook
{
164 a1bb27b1 pbrook
    int i, bit;
165 a1bb27b1 pbrook
    uint8_t shift_reg = 0x00;
166 a1bb27b1 pbrook
    uint8_t *msg = (uint8_t *) message;
167 a1bb27b1 pbrook
168 a1bb27b1 pbrook
    for (i = 0; i < width; i ++, msg ++)
169 a1bb27b1 pbrook
        for (bit = 7; bit >= 0; bit --) {
170 a1bb27b1 pbrook
            shift_reg <<= 1;
171 a1bb27b1 pbrook
            if ((shift_reg >> 7) ^ ((*msg >> bit) & 1))
172 a1bb27b1 pbrook
                shift_reg ^= 0x89;
173 a1bb27b1 pbrook
        }
174 a1bb27b1 pbrook
175 a1bb27b1 pbrook
    return shift_reg;
176 a1bb27b1 pbrook
}
177 a1bb27b1 pbrook
178 a1bb27b1 pbrook
static uint16_t sd_crc16(void *message, size_t width)
179 a1bb27b1 pbrook
{
180 a1bb27b1 pbrook
    int i, bit;
181 a1bb27b1 pbrook
    uint16_t shift_reg = 0x0000;
182 a1bb27b1 pbrook
    uint16_t *msg = (uint16_t *) message;
183 a1bb27b1 pbrook
    width <<= 1;
184 a1bb27b1 pbrook
185 a1bb27b1 pbrook
    for (i = 0; i < width; i ++, msg ++)
186 a1bb27b1 pbrook
        for (bit = 15; bit >= 0; bit --) {
187 a1bb27b1 pbrook
            shift_reg <<= 1;
188 a1bb27b1 pbrook
            if ((shift_reg >> 15) ^ ((*msg >> bit) & 1))
189 a1bb27b1 pbrook
                shift_reg ^= 0x1011;
190 a1bb27b1 pbrook
        }
191 a1bb27b1 pbrook
192 a1bb27b1 pbrook
    return shift_reg;
193 a1bb27b1 pbrook
}
194 a1bb27b1 pbrook
195 a1bb27b1 pbrook
static void sd_set_ocr(SDState *sd)
196 a1bb27b1 pbrook
{
197 1b088995 balrog
    /* All voltages OK, card power-up OK, Standard Capacity SD Memory Card */
198 54215f7d balrog
    sd->ocr = 0x80ffff80;
199 a1bb27b1 pbrook
}
200 a1bb27b1 pbrook
201 a1bb27b1 pbrook
static void sd_set_scr(SDState *sd)
202 a1bb27b1 pbrook
{
203 a1bb27b1 pbrook
    sd->scr[0] = 0x00;                /* SCR Structure */
204 a1bb27b1 pbrook
    sd->scr[1] = 0x2f;                /* SD Security Support */
205 a1bb27b1 pbrook
    sd->scr[2] = 0x00;
206 a1bb27b1 pbrook
    sd->scr[3] = 0x00;
207 a1bb27b1 pbrook
    sd->scr[4] = 0x00;
208 a1bb27b1 pbrook
    sd->scr[5] = 0x00;
209 a1bb27b1 pbrook
    sd->scr[6] = 0x00;
210 a1bb27b1 pbrook
    sd->scr[7] = 0x00;
211 a1bb27b1 pbrook
}
212 a1bb27b1 pbrook
213 a1bb27b1 pbrook
#define MID        0xaa
214 a1bb27b1 pbrook
#define OID        "XY"
215 a1bb27b1 pbrook
#define PNM        "QEMU!"
216 a1bb27b1 pbrook
#define PRV        0x01
217 a1bb27b1 pbrook
#define MDT_YR        2006
218 a1bb27b1 pbrook
#define MDT_MON        2
219 a1bb27b1 pbrook
220 a1bb27b1 pbrook
static void sd_set_cid(SDState *sd)
221 a1bb27b1 pbrook
{
222 a1bb27b1 pbrook
    sd->cid[0] = MID;                /* Fake card manufacturer ID (MID) */
223 a1bb27b1 pbrook
    sd->cid[1] = OID[0];        /* OEM/Application ID (OID) */
224 a1bb27b1 pbrook
    sd->cid[2] = OID[1];
225 a1bb27b1 pbrook
    sd->cid[3] = PNM[0];        /* Fake product name (PNM) */
226 a1bb27b1 pbrook
    sd->cid[4] = PNM[1];
227 a1bb27b1 pbrook
    sd->cid[5] = PNM[2];
228 a1bb27b1 pbrook
    sd->cid[6] = PNM[3];
229 a1bb27b1 pbrook
    sd->cid[7] = PNM[4];
230 a1bb27b1 pbrook
    sd->cid[8] = PRV;                /* Fake product revision (PRV) */
231 a1bb27b1 pbrook
    sd->cid[9] = 0xde;                /* Fake serial number (PSN) */
232 a1bb27b1 pbrook
    sd->cid[10] = 0xad;
233 a1bb27b1 pbrook
    sd->cid[11] = 0xbe;
234 a1bb27b1 pbrook
    sd->cid[12] = 0xef;
235 a1bb27b1 pbrook
    sd->cid[13] = 0x00 |        /* Manufacture date (MDT) */
236 a1bb27b1 pbrook
        ((MDT_YR - 2000) / 10);
237 a1bb27b1 pbrook
    sd->cid[14] = ((MDT_YR % 10) << 4) | MDT_MON;
238 a1bb27b1 pbrook
    sd->cid[15] = (sd_crc7(sd->cid, 15) << 1) | 1;
239 a1bb27b1 pbrook
}
240 a1bb27b1 pbrook
241 a1bb27b1 pbrook
#define HWBLOCK_SHIFT        9                        /* 512 bytes */
242 a1bb27b1 pbrook
#define SECTOR_SHIFT        5                        /* 16 kilobytes */
243 a1bb27b1 pbrook
#define WPGROUP_SHIFT        7                        /* 2 megs */
244 a1bb27b1 pbrook
#define CMULT_SHIFT        9                        /* 512 times HWBLOCK_SIZE */
245 a1bb27b1 pbrook
#define BLOCK_SIZE        (1 << (HWBLOCK_SHIFT))
246 a1bb27b1 pbrook
#define SECTOR_SIZE        (1 << (HWBLOCK_SHIFT + SECTOR_SHIFT))
247 a1bb27b1 pbrook
#define WPGROUP_SIZE        (1 << (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT))
248 a1bb27b1 pbrook
249 a1bb27b1 pbrook
static const uint8_t sd_csd_rw_mask[16] = {
250 a1bb27b1 pbrook
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
251 a1bb27b1 pbrook
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xfc, 0xfe,
252 a1bb27b1 pbrook
};
253 a1bb27b1 pbrook
254 a1bb27b1 pbrook
static void sd_set_csd(SDState *sd, uint32_t size)
255 a1bb27b1 pbrook
{
256 a1bb27b1 pbrook
    uint32_t csize = (size >> (CMULT_SHIFT + HWBLOCK_SHIFT)) - 1;
257 a1bb27b1 pbrook
    uint32_t sectsize = (1 << (SECTOR_SHIFT + 1)) - 1;
258 a1bb27b1 pbrook
    uint32_t wpsize = (1 << (WPGROUP_SHIFT + 1)) - 1;
259 a1bb27b1 pbrook
260 a1bb27b1 pbrook
    sd->csd[0] = 0x00;                /* CSD structure */
261 a1bb27b1 pbrook
    sd->csd[1] = 0x26;                /* Data read access-time-1 */
262 a1bb27b1 pbrook
    sd->csd[2] = 0x00;                /* Data read access-time-2 */
263 a1bb27b1 pbrook
    sd->csd[3] = 0x5a;                /* Max. data transfer rate */
264 a1bb27b1 pbrook
    sd->csd[4] = 0x5f;                /* Card Command Classes */
265 a1bb27b1 pbrook
    sd->csd[5] = 0x50 |                /* Max. read data block length */
266 a1bb27b1 pbrook
        HWBLOCK_SHIFT;
267 a1bb27b1 pbrook
    sd->csd[6] = 0xe0 |                /* Partial block for read allowed */
268 a1bb27b1 pbrook
        ((csize >> 10) & 0x03);
269 a1bb27b1 pbrook
    sd->csd[7] = 0x00 |                /* Device size */
270 a1bb27b1 pbrook
        ((csize >> 2) & 0xff);
271 a1bb27b1 pbrook
    sd->csd[8] = 0x3f |                /* Max. read current */
272 a1bb27b1 pbrook
        ((csize << 6) & 0xc0);
273 a1bb27b1 pbrook
    sd->csd[9] = 0xfc |                /* Max. write current */
274 a1bb27b1 pbrook
        ((CMULT_SHIFT - 2) >> 1);
275 a1bb27b1 pbrook
    sd->csd[10] = 0x40 |        /* Erase sector size */
276 a1bb27b1 pbrook
        (((CMULT_SHIFT - 2) << 7) & 0x80) | (sectsize >> 1);
277 a1bb27b1 pbrook
    sd->csd[11] = 0x00 |        /* Write protect group size */
278 a1bb27b1 pbrook
        ((sectsize << 7) & 0x80) | wpsize;
279 a1bb27b1 pbrook
    sd->csd[12] = 0x90 |        /* Write speed factor */
280 a1bb27b1 pbrook
        (HWBLOCK_SHIFT >> 2);
281 a1bb27b1 pbrook
    sd->csd[13] = 0x20 |        /* Max. write data block length */
282 a1bb27b1 pbrook
        ((HWBLOCK_SHIFT << 6) & 0xc0);
283 a1bb27b1 pbrook
    sd->csd[14] = 0x00;                /* File format group */
284 a1bb27b1 pbrook
    sd->csd[15] = (sd_crc7(sd->csd, 15) << 1) | 1;
285 a1bb27b1 pbrook
}
286 a1bb27b1 pbrook
287 a1bb27b1 pbrook
static void sd_set_rca(SDState *sd)
288 a1bb27b1 pbrook
{
289 a1bb27b1 pbrook
    sd->rca += 0x4567;
290 a1bb27b1 pbrook
}
291 a1bb27b1 pbrook
292 a1bb27b1 pbrook
#define CARD_STATUS_A        0x02004100
293 a1bb27b1 pbrook
#define CARD_STATUS_B        0x00c01e00
294 a1bb27b1 pbrook
#define CARD_STATUS_C        0xfd39a028
295 a1bb27b1 pbrook
296 a1bb27b1 pbrook
static void sd_set_cardstatus(SDState *sd)
297 a1bb27b1 pbrook
{
298 a1bb27b1 pbrook
    sd->card_status = 0x00000100;
299 a1bb27b1 pbrook
}
300 a1bb27b1 pbrook
301 a1bb27b1 pbrook
static void sd_set_sdstatus(SDState *sd)
302 a1bb27b1 pbrook
{
303 a1bb27b1 pbrook
    memset(sd->sd_status, 0, 64);
304 a1bb27b1 pbrook
}
305 a1bb27b1 pbrook
306 a1bb27b1 pbrook
static int sd_req_crc_validate(struct sd_request_s *req)
307 a1bb27b1 pbrook
{
308 a1bb27b1 pbrook
    uint8_t buffer[5];
309 a1bb27b1 pbrook
    buffer[0] = 0x40 | req->cmd;
310 a1bb27b1 pbrook
    buffer[1] = (req->arg >> 24) & 0xff;
311 a1bb27b1 pbrook
    buffer[2] = (req->arg >> 16) & 0xff;
312 a1bb27b1 pbrook
    buffer[3] = (req->arg >> 8) & 0xff;
313 a1bb27b1 pbrook
    buffer[4] = (req->arg >> 0) & 0xff;
314 a1bb27b1 pbrook
    return 0;
315 a1bb27b1 pbrook
    return sd_crc7(buffer, 5) != req->crc;        /* TODO */
316 a1bb27b1 pbrook
}
317 a1bb27b1 pbrook
318 9596ebb7 pbrook
static void sd_response_r1_make(SDState *sd,
319 9596ebb7 pbrook
                                uint8_t *response, uint32_t last_status)
320 a1bb27b1 pbrook
{
321 a1bb27b1 pbrook
    uint32_t mask = CARD_STATUS_B ^ ILLEGAL_COMMAND;
322 a1bb27b1 pbrook
    uint32_t status;
323 a1bb27b1 pbrook
324 a1bb27b1 pbrook
    status = (sd->card_status & ~mask) | (last_status & mask);
325 a1bb27b1 pbrook
    sd->card_status &= ~CARD_STATUS_C | APP_CMD;
326 a1bb27b1 pbrook
327 a1bb27b1 pbrook
    response[0] = (status >> 24) & 0xff;
328 a1bb27b1 pbrook
    response[1] = (status >> 16) & 0xff;
329 a1bb27b1 pbrook
    response[2] = (status >> 8) & 0xff;
330 a1bb27b1 pbrook
    response[3] = (status >> 0) & 0xff;
331 a1bb27b1 pbrook
}
332 a1bb27b1 pbrook
333 9596ebb7 pbrook
static void sd_response_r3_make(SDState *sd, uint8_t *response)
334 a1bb27b1 pbrook
{
335 a1bb27b1 pbrook
    response[0] = (sd->ocr >> 24) & 0xff;
336 a1bb27b1 pbrook
    response[1] = (sd->ocr >> 16) & 0xff;
337 a1bb27b1 pbrook
    response[2] = (sd->ocr >> 8) & 0xff;
338 a1bb27b1 pbrook
    response[3] = (sd->ocr >> 0) & 0xff;
339 a1bb27b1 pbrook
}
340 a1bb27b1 pbrook
341 9596ebb7 pbrook
static void sd_response_r6_make(SDState *sd, uint8_t *response)
342 a1bb27b1 pbrook
{
343 a1bb27b1 pbrook
    uint16_t arg;
344 a1bb27b1 pbrook
    uint16_t status;
345 a1bb27b1 pbrook
346 a1bb27b1 pbrook
    arg = sd->rca;
347 a1bb27b1 pbrook
    status = ((sd->card_status >> 8) & 0xc000) |
348 a1bb27b1 pbrook
             ((sd->card_status >> 6) & 0x2000) |
349 a1bb27b1 pbrook
              (sd->card_status & 0x1fff);
350 a1bb27b1 pbrook
351 a1bb27b1 pbrook
    response[0] = (arg >> 8) & 0xff;
352 a1bb27b1 pbrook
    response[1] = arg & 0xff;
353 a1bb27b1 pbrook
    response[2] = (status >> 8) & 0xff;
354 a1bb27b1 pbrook
    response[3] = status & 0xff;
355 a1bb27b1 pbrook
}
356 a1bb27b1 pbrook
357 1b088995 balrog
static void sd_response_r7_make(SDState *sd, uint8_t *response)
358 1b088995 balrog
{
359 1b088995 balrog
    response[0] = (sd->vhs >> 24) & 0xff;
360 1b088995 balrog
    response[1] = (sd->vhs >> 16) & 0xff;
361 1b088995 balrog
    response[2] = (sd->vhs >>  8) & 0xff;
362 1b088995 balrog
    response[3] = (sd->vhs >>  0) & 0xff;
363 1b088995 balrog
}
364 1b088995 balrog
365 a1bb27b1 pbrook
static void sd_reset(SDState *sd, BlockDriverState *bdrv)
366 a1bb27b1 pbrook
{
367 a1bb27b1 pbrook
    uint32_t size;
368 a1bb27b1 pbrook
    uint64_t sect;
369 a1bb27b1 pbrook
370 a1bb27b1 pbrook
    bdrv_get_geometry(bdrv, &sect);
371 a1bb27b1 pbrook
    sect <<= 9;
372 a1bb27b1 pbrook
373 a1bb27b1 pbrook
    if (sect > 0x40000000)
374 a1bb27b1 pbrook
        size = 0x40000000;        /* 1 gig */
375 a1bb27b1 pbrook
    else
376 a1bb27b1 pbrook
        size = sect + 1;
377 a1bb27b1 pbrook
378 a1bb27b1 pbrook
    sect = (size >> (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT)) + 1;
379 a1bb27b1 pbrook
380 a1bb27b1 pbrook
    sd->state = sd_idle_state;
381 a1bb27b1 pbrook
    sd->rca = 0x0000;
382 a1bb27b1 pbrook
    sd_set_ocr(sd);
383 a1bb27b1 pbrook
    sd_set_scr(sd);
384 a1bb27b1 pbrook
    sd_set_cid(sd);
385 a1bb27b1 pbrook
    sd_set_csd(sd, size);
386 a1bb27b1 pbrook
    sd_set_cardstatus(sd);
387 a1bb27b1 pbrook
    sd_set_sdstatus(sd);
388 a1bb27b1 pbrook
389 a1bb27b1 pbrook
    sd->bdrv = bdrv;
390 a1bb27b1 pbrook
391 257514dd pbrook
    if (sd->wp_groups)
392 257514dd pbrook
        qemu_free(sd->wp_groups);
393 a1bb27b1 pbrook
    sd->wp_switch = bdrv_is_read_only(bdrv);
394 a1bb27b1 pbrook
    sd->wp_groups = (int *) qemu_mallocz(sizeof(int) * sect);
395 a1bb27b1 pbrook
    memset(sd->function_group, 0, sizeof(int) * 6);
396 a1bb27b1 pbrook
    sd->erase_start = 0;
397 a1bb27b1 pbrook
    sd->erase_end = 0;
398 a1bb27b1 pbrook
    sd->size = size;
399 a1bb27b1 pbrook
    sd->blk_len = 0x200;
400 a1bb27b1 pbrook
    sd->pwd_len = 0;
401 a1bb27b1 pbrook
}
402 a1bb27b1 pbrook
403 a1bb27b1 pbrook
static void sd_cardchange(void *opaque)
404 a1bb27b1 pbrook
{
405 a1bb27b1 pbrook
    SDState *sd = opaque;
406 02ce600c balrog
    qemu_set_irq(sd->inserted_cb, bdrv_is_inserted(sd->bdrv));
407 a1bb27b1 pbrook
    if (bdrv_is_inserted(sd->bdrv)) {
408 a1bb27b1 pbrook
        sd_reset(sd, sd->bdrv);
409 257514dd pbrook
        qemu_set_irq(sd->readonly_cb, sd->wp_switch);
410 a1bb27b1 pbrook
    }
411 a1bb27b1 pbrook
}
412 a1bb27b1 pbrook
413 775616c3 pbrook
/* We do not model the chip select pin, so allow the board to select
414 8ef6367e balrog
   whether card should be in SSI or MMC/SD mode.  It is also up to the
415 775616c3 pbrook
   board to ensure that ssi transfers only occur when the chip select
416 775616c3 pbrook
   is asserted.  */
417 775616c3 pbrook
SDState *sd_init(BlockDriverState *bs, int is_spi)
418 a1bb27b1 pbrook
{
419 a1bb27b1 pbrook
    SDState *sd;
420 a1bb27b1 pbrook
421 a1bb27b1 pbrook
    sd = (SDState *) qemu_mallocz(sizeof(SDState));
422 33f00271 balrog
    sd->buf = qemu_memalign(512, 512);
423 775616c3 pbrook
    sd->spi = is_spi;
424 a1bb27b1 pbrook
    sd_reset(sd, bs);
425 02ce600c balrog
    bdrv_set_change_cb(sd->bdrv, sd_cardchange, sd);
426 a1bb27b1 pbrook
    return sd;
427 a1bb27b1 pbrook
}
428 a1bb27b1 pbrook
429 02ce600c balrog
void sd_set_cb(SDState *sd, qemu_irq readonly, qemu_irq insert)
430 a1bb27b1 pbrook
{
431 02ce600c balrog
    sd->readonly_cb = readonly;
432 02ce600c balrog
    sd->inserted_cb = insert;
433 02ce600c balrog
    qemu_set_irq(readonly, bdrv_is_read_only(sd->bdrv));
434 02ce600c balrog
    qemu_set_irq(insert, bdrv_is_inserted(sd->bdrv));
435 a1bb27b1 pbrook
}
436 a1bb27b1 pbrook
437 a1bb27b1 pbrook
static void sd_erase(SDState *sd)
438 a1bb27b1 pbrook
{
439 a1bb27b1 pbrook
    int i, start, end;
440 a1bb27b1 pbrook
    if (!sd->erase_start || !sd->erase_end) {
441 a1bb27b1 pbrook
        sd->card_status |= ERASE_SEQ_ERROR;
442 a1bb27b1 pbrook
        return;
443 a1bb27b1 pbrook
    }
444 a1bb27b1 pbrook
445 a1bb27b1 pbrook
    start = sd->erase_start >>
446 a1bb27b1 pbrook
            (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT);
447 a1bb27b1 pbrook
    end = sd->erase_end >>
448 a1bb27b1 pbrook
            (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT);
449 a1bb27b1 pbrook
    sd->erase_start = 0;
450 a1bb27b1 pbrook
    sd->erase_end = 0;
451 a1bb27b1 pbrook
    sd->csd[14] |= 0x40;
452 a1bb27b1 pbrook
453 a1bb27b1 pbrook
    for (i = start; i <= end; i ++)
454 a1bb27b1 pbrook
        if (sd->wp_groups[i])
455 a1bb27b1 pbrook
            sd->card_status |= WP_ERASE_SKIP;
456 a1bb27b1 pbrook
}
457 a1bb27b1 pbrook
458 a1bb27b1 pbrook
static uint32_t sd_wpbits(SDState *sd, uint32_t addr)
459 a1bb27b1 pbrook
{
460 a1bb27b1 pbrook
    uint32_t i, wpnum;
461 a1bb27b1 pbrook
    uint32_t ret = 0;
462 a1bb27b1 pbrook
463 a1bb27b1 pbrook
    wpnum = addr >> (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT);
464 a1bb27b1 pbrook
465 a1bb27b1 pbrook
    for (i = 0; i < 32; i ++, wpnum ++, addr += WPGROUP_SIZE)
466 a1bb27b1 pbrook
        if (addr < sd->size && sd->wp_groups[wpnum])
467 a1bb27b1 pbrook
            ret |= (1 << i);
468 a1bb27b1 pbrook
469 a1bb27b1 pbrook
    return ret;
470 a1bb27b1 pbrook
}
471 a1bb27b1 pbrook
472 a1bb27b1 pbrook
static void sd_function_switch(SDState *sd, uint32_t arg)
473 a1bb27b1 pbrook
{
474 a1bb27b1 pbrook
    int i, mode, new_func, crc;
475 a1bb27b1 pbrook
    mode = !!(arg & 0x80000000);
476 a1bb27b1 pbrook
477 a1bb27b1 pbrook
    sd->data[0] = 0x00;                /* Maximum current consumption */
478 a1bb27b1 pbrook
    sd->data[1] = 0x01;
479 a1bb27b1 pbrook
    sd->data[2] = 0x80;                /* Supported group 6 functions */
480 a1bb27b1 pbrook
    sd->data[3] = 0x01;
481 a1bb27b1 pbrook
    sd->data[4] = 0x80;                /* Supported group 5 functions */
482 a1bb27b1 pbrook
    sd->data[5] = 0x01;
483 a1bb27b1 pbrook
    sd->data[6] = 0x80;                /* Supported group 4 functions */
484 a1bb27b1 pbrook
    sd->data[7] = 0x01;
485 a1bb27b1 pbrook
    sd->data[8] = 0x80;                /* Supported group 3 functions */
486 a1bb27b1 pbrook
    sd->data[9] = 0x01;
487 a1bb27b1 pbrook
    sd->data[10] = 0x80;        /* Supported group 2 functions */
488 a1bb27b1 pbrook
    sd->data[11] = 0x43;
489 a1bb27b1 pbrook
    sd->data[12] = 0x80;        /* Supported group 1 functions */
490 a1bb27b1 pbrook
    sd->data[13] = 0x03;
491 a1bb27b1 pbrook
    for (i = 0; i < 6; i ++) {
492 a1bb27b1 pbrook
        new_func = (arg >> (i * 4)) & 0x0f;
493 a1bb27b1 pbrook
        if (mode && new_func != 0x0f)
494 a1bb27b1 pbrook
            sd->function_group[i] = new_func;
495 a1bb27b1 pbrook
        sd->data[14 + (i >> 1)] = new_func << ((i * 4) & 4);
496 a1bb27b1 pbrook
    }
497 a1bb27b1 pbrook
    memset(&sd->data[17], 0, 47);
498 a1bb27b1 pbrook
    crc = sd_crc16(sd->data, 64);
499 a1bb27b1 pbrook
    sd->data[65] = crc >> 8;
500 a1bb27b1 pbrook
    sd->data[66] = crc & 0xff;
501 a1bb27b1 pbrook
}
502 a1bb27b1 pbrook
503 a1bb27b1 pbrook
static inline int sd_wp_addr(SDState *sd, uint32_t addr)
504 a1bb27b1 pbrook
{
505 a1bb27b1 pbrook
    return sd->wp_groups[addr >>
506 a1bb27b1 pbrook
            (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT)];
507 a1bb27b1 pbrook
}
508 a1bb27b1 pbrook
509 a1bb27b1 pbrook
static void sd_lock_command(SDState *sd)
510 a1bb27b1 pbrook
{
511 a1bb27b1 pbrook
    int erase, lock, clr_pwd, set_pwd, pwd_len;
512 a1bb27b1 pbrook
    erase = !!(sd->data[0] & 0x08);
513 a1bb27b1 pbrook
    lock = sd->data[0] & 0x04;
514 a1bb27b1 pbrook
    clr_pwd = sd->data[0] & 0x02;
515 a1bb27b1 pbrook
    set_pwd = sd->data[0] & 0x01;
516 a1bb27b1 pbrook
517 a1bb27b1 pbrook
    if (sd->blk_len > 1)
518 a1bb27b1 pbrook
        pwd_len = sd->data[1];
519 a1bb27b1 pbrook
    else
520 a1bb27b1 pbrook
        pwd_len = 0;
521 a1bb27b1 pbrook
522 a1bb27b1 pbrook
    if (erase) {
523 a1bb27b1 pbrook
        if (!(sd->card_status & CARD_IS_LOCKED) || sd->blk_len > 1 ||
524 a1bb27b1 pbrook
                        set_pwd || clr_pwd || lock || sd->wp_switch ||
525 a1bb27b1 pbrook
                        (sd->csd[14] & 0x20)) {
526 a1bb27b1 pbrook
            sd->card_status |= LOCK_UNLOCK_FAILED;
527 a1bb27b1 pbrook
            return;
528 a1bb27b1 pbrook
        }
529 a1bb27b1 pbrook
        memset(sd->wp_groups, 0, sizeof(int) * (sd->size >>
530 a1bb27b1 pbrook
                        (HWBLOCK_SHIFT + SECTOR_SHIFT + WPGROUP_SHIFT)));
531 a1bb27b1 pbrook
        sd->csd[14] &= ~0x10;
532 a1bb27b1 pbrook
        sd->card_status &= ~CARD_IS_LOCKED;
533 a1bb27b1 pbrook
        sd->pwd_len = 0;
534 a1bb27b1 pbrook
        /* Erasing the entire card here! */
535 827df9f3 balrog
        fprintf(stderr, "SD: Card force-erased by CMD42\n");
536 a1bb27b1 pbrook
        return;
537 a1bb27b1 pbrook
    }
538 a1bb27b1 pbrook
539 a1bb27b1 pbrook
    if (sd->blk_len < 2 + pwd_len ||
540 a1bb27b1 pbrook
                    pwd_len <= sd->pwd_len ||
541 a1bb27b1 pbrook
                    pwd_len > sd->pwd_len + 16) {
542 a1bb27b1 pbrook
        sd->card_status |= LOCK_UNLOCK_FAILED;
543 a1bb27b1 pbrook
        return;
544 a1bb27b1 pbrook
    }
545 a1bb27b1 pbrook
546 a1bb27b1 pbrook
    if (sd->pwd_len && memcmp(sd->pwd, sd->data + 2, sd->pwd_len)) {
547 a1bb27b1 pbrook
        sd->card_status |= LOCK_UNLOCK_FAILED;
548 a1bb27b1 pbrook
        return;
549 a1bb27b1 pbrook
    }
550 a1bb27b1 pbrook
551 a1bb27b1 pbrook
    pwd_len -= sd->pwd_len;
552 a1bb27b1 pbrook
    if ((pwd_len && !set_pwd) ||
553 a1bb27b1 pbrook
                    (clr_pwd && (set_pwd || lock)) ||
554 a1bb27b1 pbrook
                    (lock && !sd->pwd_len && !set_pwd) ||
555 a1bb27b1 pbrook
                    (!set_pwd && !clr_pwd &&
556 a1bb27b1 pbrook
                     (((sd->card_status & CARD_IS_LOCKED) && lock) ||
557 a1bb27b1 pbrook
                      (!(sd->card_status & CARD_IS_LOCKED) && !lock)))) {
558 a1bb27b1 pbrook
        sd->card_status |= LOCK_UNLOCK_FAILED;
559 a1bb27b1 pbrook
        return;
560 a1bb27b1 pbrook
    }
561 a1bb27b1 pbrook
562 a1bb27b1 pbrook
    if (set_pwd) {
563 a1bb27b1 pbrook
        memcpy(sd->pwd, sd->data + 2 + sd->pwd_len, pwd_len);
564 a1bb27b1 pbrook
        sd->pwd_len = pwd_len;
565 a1bb27b1 pbrook
    }
566 a1bb27b1 pbrook
567 a1bb27b1 pbrook
    if (clr_pwd) {
568 a1bb27b1 pbrook
        sd->pwd_len = 0;
569 a1bb27b1 pbrook
    }
570 a1bb27b1 pbrook
571 a1bb27b1 pbrook
    if (lock)
572 a1bb27b1 pbrook
        sd->card_status |= CARD_IS_LOCKED;
573 a1bb27b1 pbrook
    else
574 a1bb27b1 pbrook
        sd->card_status &= ~CARD_IS_LOCKED;
575 a1bb27b1 pbrook
}
576 a1bb27b1 pbrook
577 a1bb27b1 pbrook
static sd_rsp_type_t sd_normal_command(SDState *sd,
578 a1bb27b1 pbrook
                                       struct sd_request_s req)
579 a1bb27b1 pbrook
{
580 a1bb27b1 pbrook
    uint32_t rca = 0x0000;
581 a1bb27b1 pbrook
582 a1bb27b1 pbrook
    if (sd_cmd_type[req.cmd] == sd_ac || sd_cmd_type[req.cmd] == sd_adtc)
583 a1bb27b1 pbrook
        rca = req.arg >> 16;
584 a1bb27b1 pbrook
585 a1bb27b1 pbrook
    DPRINTF("CMD%d 0x%08x state %d\n", req.cmd, req.arg, sd->state);
586 a1bb27b1 pbrook
    switch (req.cmd) {
587 a1bb27b1 pbrook
    /* Basic commands (Class 0 and Class 1) */
588 a1bb27b1 pbrook
    case 0:        /* CMD0:   GO_IDLE_STATE */
589 a1bb27b1 pbrook
        switch (sd->state) {
590 a1bb27b1 pbrook
        case sd_inactive_state:
591 775616c3 pbrook
            return sd->spi ? sd_r1 : sd_r0;
592 a1bb27b1 pbrook
593 a1bb27b1 pbrook
        default:
594 a1bb27b1 pbrook
            sd->state = sd_idle_state;
595 a1bb27b1 pbrook
            sd_reset(sd, sd->bdrv);
596 775616c3 pbrook
            return sd->spi ? sd_r1 : sd_r0;
597 a1bb27b1 pbrook
        }
598 a1bb27b1 pbrook
        break;
599 a1bb27b1 pbrook
600 775616c3 pbrook
    case 1:        /* CMD1:   SEND_OP_CMD */
601 775616c3 pbrook
        if (!sd->spi)
602 775616c3 pbrook
            goto bad_cmd;
603 775616c3 pbrook
604 775616c3 pbrook
        sd->state = sd_transfer_state;
605 775616c3 pbrook
        return sd_r1;
606 775616c3 pbrook
607 a1bb27b1 pbrook
    case 2:        /* CMD2:   ALL_SEND_CID */
608 775616c3 pbrook
        if (sd->spi)
609 775616c3 pbrook
            goto bad_cmd;
610 a1bb27b1 pbrook
        switch (sd->state) {
611 a1bb27b1 pbrook
        case sd_ready_state:
612 a1bb27b1 pbrook
            sd->state = sd_identification_state;
613 a1bb27b1 pbrook
            return sd_r2_i;
614 a1bb27b1 pbrook
615 a1bb27b1 pbrook
        default:
616 a1bb27b1 pbrook
            break;
617 a1bb27b1 pbrook
        }
618 a1bb27b1 pbrook
        break;
619 a1bb27b1 pbrook
620 a1bb27b1 pbrook
    case 3:        /* CMD3:   SEND_RELATIVE_ADDR */
621 775616c3 pbrook
        if (sd->spi)
622 775616c3 pbrook
            goto bad_cmd;
623 a1bb27b1 pbrook
        switch (sd->state) {
624 a1bb27b1 pbrook
        case sd_identification_state:
625 a1bb27b1 pbrook
        case sd_standby_state:
626 a1bb27b1 pbrook
            sd->state = sd_standby_state;
627 a1bb27b1 pbrook
            sd_set_rca(sd);
628 a1bb27b1 pbrook
            return sd_r6;
629 a1bb27b1 pbrook
630 a1bb27b1 pbrook
        default:
631 a1bb27b1 pbrook
            break;
632 a1bb27b1 pbrook
        }
633 a1bb27b1 pbrook
        break;
634 a1bb27b1 pbrook
635 a1bb27b1 pbrook
    case 4:        /* CMD4:   SEND_DSR */
636 775616c3 pbrook
        if (sd->spi)
637 775616c3 pbrook
            goto bad_cmd;
638 a1bb27b1 pbrook
        switch (sd->state) {
639 a1bb27b1 pbrook
        case sd_standby_state:
640 a1bb27b1 pbrook
            break;
641 a1bb27b1 pbrook
642 a1bb27b1 pbrook
        default:
643 a1bb27b1 pbrook
            break;
644 a1bb27b1 pbrook
        }
645 a1bb27b1 pbrook
        break;
646 a1bb27b1 pbrook
647 a1bb27b1 pbrook
    case 6:        /* CMD6:   SWITCH_FUNCTION */
648 775616c3 pbrook
        if (sd->spi)
649 775616c3 pbrook
            goto bad_cmd;
650 a1bb27b1 pbrook
        switch (sd->mode) {
651 a1bb27b1 pbrook
        case sd_data_transfer_mode:
652 a1bb27b1 pbrook
            sd_function_switch(sd, req.arg);
653 a1bb27b1 pbrook
            sd->state = sd_sendingdata_state;
654 a1bb27b1 pbrook
            sd->data_start = 0;
655 a1bb27b1 pbrook
            sd->data_offset = 0;
656 a1bb27b1 pbrook
            return sd_r1;
657 a1bb27b1 pbrook
658 a1bb27b1 pbrook
        default:
659 a1bb27b1 pbrook
            break;
660 a1bb27b1 pbrook
        }
661 a1bb27b1 pbrook
        break;
662 a1bb27b1 pbrook
663 a1bb27b1 pbrook
    case 7:        /* CMD7:   SELECT/DESELECT_CARD */
664 775616c3 pbrook
        if (sd->spi)
665 775616c3 pbrook
            goto bad_cmd;
666 a1bb27b1 pbrook
        switch (sd->state) {
667 a1bb27b1 pbrook
        case sd_standby_state:
668 a1bb27b1 pbrook
            if (sd->rca != rca)
669 a1bb27b1 pbrook
                return sd_r0;
670 a1bb27b1 pbrook
671 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
672 a1bb27b1 pbrook
            return sd_r1b;
673 a1bb27b1 pbrook
674 a1bb27b1 pbrook
        case sd_transfer_state:
675 a1bb27b1 pbrook
        case sd_sendingdata_state:
676 a1bb27b1 pbrook
            if (sd->rca == rca)
677 a1bb27b1 pbrook
                break;
678 a1bb27b1 pbrook
679 a1bb27b1 pbrook
            sd->state = sd_standby_state;
680 a1bb27b1 pbrook
            return sd_r1b;
681 a1bb27b1 pbrook
682 a1bb27b1 pbrook
        case sd_disconnect_state:
683 a1bb27b1 pbrook
            if (sd->rca != rca)
684 a1bb27b1 pbrook
                return sd_r0;
685 a1bb27b1 pbrook
686 a1bb27b1 pbrook
            sd->state = sd_programming_state;
687 a1bb27b1 pbrook
            return sd_r1b;
688 a1bb27b1 pbrook
689 a1bb27b1 pbrook
        case sd_programming_state:
690 a1bb27b1 pbrook
            if (sd->rca == rca)
691 a1bb27b1 pbrook
                break;
692 a1bb27b1 pbrook
693 a1bb27b1 pbrook
            sd->state = sd_disconnect_state;
694 a1bb27b1 pbrook
            return sd_r1b;
695 a1bb27b1 pbrook
696 a1bb27b1 pbrook
        default:
697 a1bb27b1 pbrook
            break;
698 a1bb27b1 pbrook
        }
699 a1bb27b1 pbrook
        break;
700 a1bb27b1 pbrook
701 1b088995 balrog
    case 8:        /* CMD8:   SEND_IF_COND */
702 1b088995 balrog
        /* Physical Layer Specification Version 2.00 command */
703 1b088995 balrog
        switch (sd->state) {
704 1b088995 balrog
        case sd_idle_state:
705 1b088995 balrog
            sd->vhs = 0;
706 1b088995 balrog
707 1b088995 balrog
            /* No response if not exactly one VHS bit is set.  */
708 1b088995 balrog
            if (!(req.arg >> 8) || (req.arg >> ffs(req.arg & ~0xff)))
709 1b088995 balrog
                return sd->spi ? sd_r7 : sd_r0;
710 1b088995 balrog
711 1b088995 balrog
            /* Accept.  */
712 1b088995 balrog
            sd->vhs = req.arg;
713 1b088995 balrog
            return sd_r7;
714 1b088995 balrog
715 1b088995 balrog
        default:
716 1b088995 balrog
            break;
717 1b088995 balrog
        }
718 1b088995 balrog
        break;
719 1b088995 balrog
720 a1bb27b1 pbrook
    case 9:        /* CMD9:   SEND_CSD */
721 a1bb27b1 pbrook
        switch (sd->state) {
722 a1bb27b1 pbrook
        case sd_standby_state:
723 a1bb27b1 pbrook
            if (sd->rca != rca)
724 a1bb27b1 pbrook
                return sd_r0;
725 a1bb27b1 pbrook
726 a1bb27b1 pbrook
            return sd_r2_s;
727 a1bb27b1 pbrook
728 775616c3 pbrook
        case sd_transfer_state:
729 775616c3 pbrook
            if (!sd->spi)
730 775616c3 pbrook
                break;
731 775616c3 pbrook
            sd->state = sd_sendingdata_state;
732 775616c3 pbrook
            memcpy(sd->data, sd->csd, 16);
733 775616c3 pbrook
            sd->data_start = req.arg;
734 775616c3 pbrook
            sd->data_offset = 0;
735 775616c3 pbrook
            return sd_r1;
736 775616c3 pbrook
737 a1bb27b1 pbrook
        default:
738 a1bb27b1 pbrook
            break;
739 a1bb27b1 pbrook
        }
740 a1bb27b1 pbrook
        break;
741 a1bb27b1 pbrook
742 a1bb27b1 pbrook
    case 10:        /* CMD10:  SEND_CID */
743 a1bb27b1 pbrook
        switch (sd->state) {
744 a1bb27b1 pbrook
        case sd_standby_state:
745 a1bb27b1 pbrook
            if (sd->rca != rca)
746 a1bb27b1 pbrook
                return sd_r0;
747 a1bb27b1 pbrook
748 a1bb27b1 pbrook
            return sd_r2_i;
749 a1bb27b1 pbrook
750 775616c3 pbrook
        case sd_transfer_state:
751 775616c3 pbrook
            if (!sd->spi)
752 775616c3 pbrook
                break;
753 775616c3 pbrook
            sd->state = sd_sendingdata_state;
754 775616c3 pbrook
            memcpy(sd->data, sd->cid, 16);
755 775616c3 pbrook
            sd->data_start = req.arg;
756 775616c3 pbrook
            sd->data_offset = 0;
757 775616c3 pbrook
            return sd_r1;
758 775616c3 pbrook
759 a1bb27b1 pbrook
        default:
760 a1bb27b1 pbrook
            break;
761 a1bb27b1 pbrook
        }
762 a1bb27b1 pbrook
        break;
763 a1bb27b1 pbrook
764 a1bb27b1 pbrook
    case 11:        /* CMD11:  READ_DAT_UNTIL_STOP */
765 775616c3 pbrook
        if (sd->spi)
766 775616c3 pbrook
            goto bad_cmd;
767 a1bb27b1 pbrook
        switch (sd->state) {
768 a1bb27b1 pbrook
        case sd_transfer_state:
769 a1bb27b1 pbrook
            sd->state = sd_sendingdata_state;
770 a1bb27b1 pbrook
            sd->data_start = req.arg;
771 a1bb27b1 pbrook
            sd->data_offset = 0;
772 a1bb27b1 pbrook
773 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size)
774 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
775 a1bb27b1 pbrook
            return sd_r0;
776 a1bb27b1 pbrook
777 a1bb27b1 pbrook
        default:
778 a1bb27b1 pbrook
            break;
779 a1bb27b1 pbrook
        }
780 a1bb27b1 pbrook
        break;
781 a1bb27b1 pbrook
782 a1bb27b1 pbrook
    case 12:        /* CMD12:  STOP_TRANSMISSION */
783 a1bb27b1 pbrook
        switch (sd->state) {
784 a1bb27b1 pbrook
        case sd_sendingdata_state:
785 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
786 a1bb27b1 pbrook
            return sd_r1b;
787 a1bb27b1 pbrook
788 a1bb27b1 pbrook
        case sd_receivingdata_state:
789 a1bb27b1 pbrook
            sd->state = sd_programming_state;
790 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
791 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
792 a1bb27b1 pbrook
            return sd_r1b;
793 a1bb27b1 pbrook
794 a1bb27b1 pbrook
        default:
795 a1bb27b1 pbrook
            break;
796 a1bb27b1 pbrook
        }
797 a1bb27b1 pbrook
        break;
798 a1bb27b1 pbrook
799 a1bb27b1 pbrook
    case 13:        /* CMD13:  SEND_STATUS */
800 a1bb27b1 pbrook
        switch (sd->mode) {
801 a1bb27b1 pbrook
        case sd_data_transfer_mode:
802 a1bb27b1 pbrook
            if (sd->rca != rca)
803 a1bb27b1 pbrook
                return sd_r0;
804 a1bb27b1 pbrook
805 a1bb27b1 pbrook
            return sd_r1;
806 a1bb27b1 pbrook
807 a1bb27b1 pbrook
        default:
808 a1bb27b1 pbrook
            break;
809 a1bb27b1 pbrook
        }
810 a1bb27b1 pbrook
        break;
811 a1bb27b1 pbrook
812 a1bb27b1 pbrook
    case 15:        /* CMD15:  GO_INACTIVE_STATE */
813 775616c3 pbrook
        if (sd->spi)
814 775616c3 pbrook
            goto bad_cmd;
815 a1bb27b1 pbrook
        switch (sd->mode) {
816 a1bb27b1 pbrook
        case sd_data_transfer_mode:
817 a1bb27b1 pbrook
            if (sd->rca != rca)
818 a1bb27b1 pbrook
                return sd_r0;
819 a1bb27b1 pbrook
820 a1bb27b1 pbrook
            sd->state = sd_inactive_state;
821 a1bb27b1 pbrook
            return sd_r0;
822 a1bb27b1 pbrook
823 a1bb27b1 pbrook
        default:
824 a1bb27b1 pbrook
            break;
825 a1bb27b1 pbrook
        }
826 a1bb27b1 pbrook
        break;
827 a1bb27b1 pbrook
828 a1bb27b1 pbrook
    /* Block read commands (Classs 2) */
829 a1bb27b1 pbrook
    case 16:        /* CMD16:  SET_BLOCKLEN */
830 a1bb27b1 pbrook
        switch (sd->state) {
831 a1bb27b1 pbrook
        case sd_transfer_state:
832 a1bb27b1 pbrook
            if (req.arg > (1 << HWBLOCK_SHIFT))
833 a1bb27b1 pbrook
                sd->card_status |= BLOCK_LEN_ERROR;
834 a1bb27b1 pbrook
            else
835 a1bb27b1 pbrook
                sd->blk_len = req.arg;
836 a1bb27b1 pbrook
837 a1bb27b1 pbrook
            return sd_r1;
838 a1bb27b1 pbrook
839 a1bb27b1 pbrook
        default:
840 a1bb27b1 pbrook
            break;
841 a1bb27b1 pbrook
        }
842 a1bb27b1 pbrook
        break;
843 a1bb27b1 pbrook
844 a1bb27b1 pbrook
    case 17:        /* CMD17:  READ_SINGLE_BLOCK */
845 a1bb27b1 pbrook
        switch (sd->state) {
846 a1bb27b1 pbrook
        case sd_transfer_state:
847 a1bb27b1 pbrook
            sd->state = sd_sendingdata_state;
848 a1bb27b1 pbrook
            sd->data_start = req.arg;
849 a1bb27b1 pbrook
            sd->data_offset = 0;
850 a1bb27b1 pbrook
851 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size)
852 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
853 a1bb27b1 pbrook
            return sd_r1;
854 a1bb27b1 pbrook
855 a1bb27b1 pbrook
        default:
856 a1bb27b1 pbrook
            break;
857 a1bb27b1 pbrook
        }
858 a1bb27b1 pbrook
        break;
859 a1bb27b1 pbrook
860 a1bb27b1 pbrook
    case 18:        /* CMD18:  READ_MULTIPLE_BLOCK */
861 a1bb27b1 pbrook
        switch (sd->state) {
862 a1bb27b1 pbrook
        case sd_transfer_state:
863 a1bb27b1 pbrook
            sd->state = sd_sendingdata_state;
864 a1bb27b1 pbrook
            sd->data_start = req.arg;
865 a1bb27b1 pbrook
            sd->data_offset = 0;
866 a1bb27b1 pbrook
867 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size)
868 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
869 a1bb27b1 pbrook
            return sd_r1;
870 a1bb27b1 pbrook
871 a1bb27b1 pbrook
        default:
872 a1bb27b1 pbrook
            break;
873 a1bb27b1 pbrook
        }
874 a1bb27b1 pbrook
        break;
875 a1bb27b1 pbrook
876 a1bb27b1 pbrook
    /* Block write commands (Class 4) */
877 a1bb27b1 pbrook
    case 24:        /* CMD24:  WRITE_SINGLE_BLOCK */
878 775616c3 pbrook
        if (sd->spi)
879 775616c3 pbrook
            goto unimplemented_cmd;
880 a1bb27b1 pbrook
        switch (sd->state) {
881 a1bb27b1 pbrook
        case sd_transfer_state:
882 775616c3 pbrook
            /* Writing in SPI mode not implemented.  */
883 775616c3 pbrook
            if (sd->spi)
884 775616c3 pbrook
                break;
885 a1bb27b1 pbrook
            sd->state = sd_receivingdata_state;
886 a1bb27b1 pbrook
            sd->data_start = req.arg;
887 a1bb27b1 pbrook
            sd->data_offset = 0;
888 a1bb27b1 pbrook
            sd->blk_written = 0;
889 a1bb27b1 pbrook
890 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size)
891 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
892 a1bb27b1 pbrook
            if (sd_wp_addr(sd, sd->data_start))
893 a1bb27b1 pbrook
                sd->card_status |= WP_VIOLATION;
894 a1bb27b1 pbrook
            if (sd->csd[14] & 0x30)
895 a1bb27b1 pbrook
                sd->card_status |= WP_VIOLATION;
896 a1bb27b1 pbrook
            return sd_r1;
897 a1bb27b1 pbrook
898 a1bb27b1 pbrook
        default:
899 a1bb27b1 pbrook
            break;
900 a1bb27b1 pbrook
        }
901 a1bb27b1 pbrook
        break;
902 a1bb27b1 pbrook
903 a1bb27b1 pbrook
    case 25:        /* CMD25:  WRITE_MULTIPLE_BLOCK */
904 775616c3 pbrook
        if (sd->spi)
905 775616c3 pbrook
            goto unimplemented_cmd;
906 a1bb27b1 pbrook
        switch (sd->state) {
907 a1bb27b1 pbrook
        case sd_transfer_state:
908 775616c3 pbrook
            /* Writing in SPI mode not implemented.  */
909 775616c3 pbrook
            if (sd->spi)
910 775616c3 pbrook
                break;
911 a1bb27b1 pbrook
            sd->state = sd_receivingdata_state;
912 a1bb27b1 pbrook
            sd->data_start = req.arg;
913 a1bb27b1 pbrook
            sd->data_offset = 0;
914 a1bb27b1 pbrook
            sd->blk_written = 0;
915 a1bb27b1 pbrook
916 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size)
917 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
918 a1bb27b1 pbrook
            if (sd_wp_addr(sd, sd->data_start))
919 a1bb27b1 pbrook
                sd->card_status |= WP_VIOLATION;
920 a1bb27b1 pbrook
            if (sd->csd[14] & 0x30)
921 a1bb27b1 pbrook
                sd->card_status |= WP_VIOLATION;
922 a1bb27b1 pbrook
            return sd_r1;
923 a1bb27b1 pbrook
924 a1bb27b1 pbrook
        default:
925 a1bb27b1 pbrook
            break;
926 a1bb27b1 pbrook
        }
927 a1bb27b1 pbrook
        break;
928 a1bb27b1 pbrook
929 a1bb27b1 pbrook
    case 26:        /* CMD26:  PROGRAM_CID */
930 775616c3 pbrook
        if (sd->spi)
931 775616c3 pbrook
            goto bad_cmd;
932 a1bb27b1 pbrook
        switch (sd->state) {
933 a1bb27b1 pbrook
        case sd_transfer_state:
934 a1bb27b1 pbrook
            sd->state = sd_receivingdata_state;
935 a1bb27b1 pbrook
            sd->data_start = 0;
936 a1bb27b1 pbrook
            sd->data_offset = 0;
937 a1bb27b1 pbrook
            return sd_r1;
938 a1bb27b1 pbrook
939 a1bb27b1 pbrook
        default:
940 a1bb27b1 pbrook
            break;
941 a1bb27b1 pbrook
        }
942 a1bb27b1 pbrook
        break;
943 a1bb27b1 pbrook
944 a1bb27b1 pbrook
    case 27:        /* CMD27:  PROGRAM_CSD */
945 775616c3 pbrook
        if (sd->spi)
946 775616c3 pbrook
            goto unimplemented_cmd;
947 a1bb27b1 pbrook
        switch (sd->state) {
948 a1bb27b1 pbrook
        case sd_transfer_state:
949 a1bb27b1 pbrook
            sd->state = sd_receivingdata_state;
950 a1bb27b1 pbrook
            sd->data_start = 0;
951 a1bb27b1 pbrook
            sd->data_offset = 0;
952 a1bb27b1 pbrook
            return sd_r1;
953 a1bb27b1 pbrook
954 a1bb27b1 pbrook
        default:
955 a1bb27b1 pbrook
            break;
956 a1bb27b1 pbrook
        }
957 a1bb27b1 pbrook
        break;
958 a1bb27b1 pbrook
959 a1bb27b1 pbrook
    /* Write protection (Class 6) */
960 a1bb27b1 pbrook
    case 28:        /* CMD28:  SET_WRITE_PROT */
961 a1bb27b1 pbrook
        switch (sd->state) {
962 a1bb27b1 pbrook
        case sd_transfer_state:
963 a1bb27b1 pbrook
            if (req.arg >= sd->size) {
964 a1bb27b1 pbrook
                sd->card_status = ADDRESS_ERROR;
965 a1bb27b1 pbrook
                return sd_r1b;
966 a1bb27b1 pbrook
            }
967 a1bb27b1 pbrook
968 a1bb27b1 pbrook
            sd->state = sd_programming_state;
969 a1bb27b1 pbrook
            sd->wp_groups[req.arg >> (HWBLOCK_SHIFT +
970 a1bb27b1 pbrook
                            SECTOR_SHIFT + WPGROUP_SHIFT)] = 1;
971 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
972 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
973 a1bb27b1 pbrook
            return sd_r1b;
974 a1bb27b1 pbrook
975 a1bb27b1 pbrook
        default:
976 a1bb27b1 pbrook
            break;
977 a1bb27b1 pbrook
        }
978 a1bb27b1 pbrook
        break;
979 a1bb27b1 pbrook
980 a1bb27b1 pbrook
    case 29:        /* CMD29:  CLR_WRITE_PROT */
981 a1bb27b1 pbrook
        switch (sd->state) {
982 a1bb27b1 pbrook
        case sd_transfer_state:
983 a1bb27b1 pbrook
            if (req.arg >= sd->size) {
984 a1bb27b1 pbrook
                sd->card_status = ADDRESS_ERROR;
985 a1bb27b1 pbrook
                return sd_r1b;
986 a1bb27b1 pbrook
            }
987 a1bb27b1 pbrook
988 a1bb27b1 pbrook
            sd->state = sd_programming_state;
989 a1bb27b1 pbrook
            sd->wp_groups[req.arg >> (HWBLOCK_SHIFT +
990 a1bb27b1 pbrook
                            SECTOR_SHIFT + WPGROUP_SHIFT)] = 0;
991 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
992 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
993 a1bb27b1 pbrook
            return sd_r1b;
994 a1bb27b1 pbrook
995 a1bb27b1 pbrook
        default:
996 a1bb27b1 pbrook
            break;
997 a1bb27b1 pbrook
        }
998 a1bb27b1 pbrook
        break;
999 a1bb27b1 pbrook
1000 a1bb27b1 pbrook
    case 30:        /* CMD30:  SEND_WRITE_PROT */
1001 a1bb27b1 pbrook
        switch (sd->state) {
1002 a1bb27b1 pbrook
        case sd_transfer_state:
1003 a1bb27b1 pbrook
            sd->state = sd_sendingdata_state;
1004 a1bb27b1 pbrook
            *(uint32_t *) sd->data = sd_wpbits(sd, req.arg);
1005 a1bb27b1 pbrook
            sd->data_start = req.arg;
1006 a1bb27b1 pbrook
            sd->data_offset = 0;
1007 a1bb27b1 pbrook
            return sd_r1b;
1008 a1bb27b1 pbrook
1009 a1bb27b1 pbrook
        default:
1010 a1bb27b1 pbrook
            break;
1011 a1bb27b1 pbrook
        }
1012 a1bb27b1 pbrook
        break;
1013 a1bb27b1 pbrook
1014 a1bb27b1 pbrook
    /* Erase commands (Class 5) */
1015 a1bb27b1 pbrook
    case 32:        /* CMD32:  ERASE_WR_BLK_START */
1016 a1bb27b1 pbrook
        switch (sd->state) {
1017 a1bb27b1 pbrook
        case sd_transfer_state:
1018 a1bb27b1 pbrook
            sd->erase_start = req.arg;
1019 a1bb27b1 pbrook
            return sd_r1;
1020 a1bb27b1 pbrook
1021 a1bb27b1 pbrook
        default:
1022 a1bb27b1 pbrook
            break;
1023 a1bb27b1 pbrook
        }
1024 a1bb27b1 pbrook
        break;
1025 a1bb27b1 pbrook
1026 a1bb27b1 pbrook
    case 33:        /* CMD33:  ERASE_WR_BLK_END */
1027 a1bb27b1 pbrook
        switch (sd->state) {
1028 a1bb27b1 pbrook
        case sd_transfer_state:
1029 a1bb27b1 pbrook
            sd->erase_end = req.arg;
1030 a1bb27b1 pbrook
            return sd_r1;
1031 a1bb27b1 pbrook
1032 a1bb27b1 pbrook
        default:
1033 a1bb27b1 pbrook
            break;
1034 a1bb27b1 pbrook
        }
1035 a1bb27b1 pbrook
        break;
1036 a1bb27b1 pbrook
1037 a1bb27b1 pbrook
    case 38:        /* CMD38:  ERASE */
1038 a1bb27b1 pbrook
        switch (sd->state) {
1039 a1bb27b1 pbrook
        case sd_transfer_state:
1040 a1bb27b1 pbrook
            if (sd->csd[14] & 0x30) {
1041 a1bb27b1 pbrook
                sd->card_status |= WP_VIOLATION;
1042 a1bb27b1 pbrook
                return sd_r1b;
1043 a1bb27b1 pbrook
            }
1044 a1bb27b1 pbrook
1045 a1bb27b1 pbrook
            sd->state = sd_programming_state;
1046 a1bb27b1 pbrook
            sd_erase(sd);
1047 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
1048 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1049 a1bb27b1 pbrook
            return sd_r1b;
1050 a1bb27b1 pbrook
1051 a1bb27b1 pbrook
        default:
1052 a1bb27b1 pbrook
            break;
1053 a1bb27b1 pbrook
        }
1054 a1bb27b1 pbrook
        break;
1055 a1bb27b1 pbrook
1056 a1bb27b1 pbrook
    /* Lock card commands (Class 7) */
1057 a1bb27b1 pbrook
    case 42:        /* CMD42:  LOCK_UNLOCK */
1058 775616c3 pbrook
        if (sd->spi)
1059 775616c3 pbrook
            goto unimplemented_cmd;
1060 a1bb27b1 pbrook
        switch (sd->state) {
1061 a1bb27b1 pbrook
        case sd_transfer_state:
1062 a1bb27b1 pbrook
            sd->state = sd_receivingdata_state;
1063 a1bb27b1 pbrook
            sd->data_start = 0;
1064 a1bb27b1 pbrook
            sd->data_offset = 0;
1065 a1bb27b1 pbrook
            return sd_r1;
1066 a1bb27b1 pbrook
1067 a1bb27b1 pbrook
        default:
1068 a1bb27b1 pbrook
            break;
1069 a1bb27b1 pbrook
        }
1070 a1bb27b1 pbrook
        break;
1071 a1bb27b1 pbrook
1072 a1bb27b1 pbrook
    /* Application specific commands (Class 8) */
1073 a1bb27b1 pbrook
    case 55:        /* CMD55:  APP_CMD */
1074 a1bb27b1 pbrook
        if (sd->rca != rca)
1075 a1bb27b1 pbrook
            return sd_r0;
1076 a1bb27b1 pbrook
1077 a1bb27b1 pbrook
        sd->card_status |= APP_CMD;
1078 a1bb27b1 pbrook
        return sd_r1;
1079 a1bb27b1 pbrook
1080 a1bb27b1 pbrook
    case 56:        /* CMD56:  GEN_CMD */
1081 827df9f3 balrog
        fprintf(stderr, "SD: GEN_CMD 0x%08x\n", req.arg);
1082 a1bb27b1 pbrook
1083 a1bb27b1 pbrook
        switch (sd->state) {
1084 a1bb27b1 pbrook
        case sd_transfer_state:
1085 a1bb27b1 pbrook
            sd->data_offset = 0;
1086 a1bb27b1 pbrook
            if (req.arg & 1)
1087 a1bb27b1 pbrook
                sd->state = sd_sendingdata_state;
1088 a1bb27b1 pbrook
            else
1089 a1bb27b1 pbrook
                sd->state = sd_receivingdata_state;
1090 a1bb27b1 pbrook
            return sd_r1;
1091 a1bb27b1 pbrook
1092 a1bb27b1 pbrook
        default:
1093 a1bb27b1 pbrook
            break;
1094 a1bb27b1 pbrook
        }
1095 a1bb27b1 pbrook
        break;
1096 a1bb27b1 pbrook
1097 a1bb27b1 pbrook
    default:
1098 775616c3 pbrook
    bad_cmd:
1099 a1bb27b1 pbrook
        sd->card_status |= ILLEGAL_COMMAND;
1100 a1bb27b1 pbrook
1101 827df9f3 balrog
        fprintf(stderr, "SD: Unknown CMD%i\n", req.cmd);
1102 a1bb27b1 pbrook
        return sd_r0;
1103 775616c3 pbrook
1104 775616c3 pbrook
    unimplemented_cmd:
1105 775616c3 pbrook
        /* Commands that are recognised but not yet implemented in SPI mode.  */
1106 775616c3 pbrook
        sd->card_status |= ILLEGAL_COMMAND;
1107 827df9f3 balrog
        fprintf(stderr, "SD: CMD%i not implemented in SPI mode\n", req.cmd);
1108 775616c3 pbrook
        return sd_r0;
1109 a1bb27b1 pbrook
    }
1110 a1bb27b1 pbrook
1111 a1bb27b1 pbrook
    sd->card_status |= ILLEGAL_COMMAND;
1112 827df9f3 balrog
    fprintf(stderr, "SD: CMD%i in a wrong state\n", req.cmd);
1113 a1bb27b1 pbrook
    return sd_r0;
1114 a1bb27b1 pbrook
}
1115 a1bb27b1 pbrook
1116 a1bb27b1 pbrook
static sd_rsp_type_t sd_app_command(SDState *sd,
1117 a1bb27b1 pbrook
                                    struct sd_request_s req) {
1118 a1bb27b1 pbrook
    uint32_t rca;
1119 a1bb27b1 pbrook
1120 a1bb27b1 pbrook
    if (sd_cmd_type[req.cmd] == sd_ac || sd_cmd_type[req.cmd] == sd_adtc)
1121 a1bb27b1 pbrook
        rca = req.arg >> 16;
1122 a1bb27b1 pbrook
1123 a1bb27b1 pbrook
    DPRINTF("ACMD%d 0x%08x\n", req.cmd, req.arg);
1124 a1bb27b1 pbrook
    switch (req.cmd) {
1125 a1bb27b1 pbrook
    case 6:        /* ACMD6:  SET_BUS_WIDTH */
1126 a1bb27b1 pbrook
        switch (sd->state) {
1127 a1bb27b1 pbrook
        case sd_transfer_state:
1128 a1bb27b1 pbrook
            sd->sd_status[0] &= 0x3f;
1129 a1bb27b1 pbrook
            sd->sd_status[0] |= (req.arg & 0x03) << 6;
1130 a1bb27b1 pbrook
            return sd_r1;
1131 a1bb27b1 pbrook
1132 a1bb27b1 pbrook
        default:
1133 a1bb27b1 pbrook
            break;
1134 a1bb27b1 pbrook
        }
1135 a1bb27b1 pbrook
        break;
1136 a1bb27b1 pbrook
1137 a1bb27b1 pbrook
    case 13:        /* ACMD13: SD_STATUS */
1138 a1bb27b1 pbrook
        switch (sd->state) {
1139 a1bb27b1 pbrook
        case sd_transfer_state:
1140 a1bb27b1 pbrook
            sd->data_start = 0;
1141 a1bb27b1 pbrook
            sd->data_offset = 0;
1142 a1bb27b1 pbrook
            return sd_r1;
1143 a1bb27b1 pbrook
1144 a1bb27b1 pbrook
        default:
1145 a1bb27b1 pbrook
            break;
1146 a1bb27b1 pbrook
        }
1147 a1bb27b1 pbrook
        break;
1148 a1bb27b1 pbrook
1149 a1bb27b1 pbrook
    case 22:        /* ACMD22: SEND_NUM_WR_BLOCKS */
1150 a1bb27b1 pbrook
        switch (sd->state) {
1151 a1bb27b1 pbrook
        case sd_transfer_state:
1152 a1bb27b1 pbrook
            *(uint32_t *) sd->data = sd->blk_written;
1153 a1bb27b1 pbrook
1154 a1bb27b1 pbrook
            sd->data_start = 0;
1155 a1bb27b1 pbrook
            sd->data_offset = 0;
1156 a1bb27b1 pbrook
            return sd_r1;
1157 a1bb27b1 pbrook
1158 a1bb27b1 pbrook
        default:
1159 a1bb27b1 pbrook
            break;
1160 a1bb27b1 pbrook
        }
1161 a1bb27b1 pbrook
        break;
1162 a1bb27b1 pbrook
1163 a1bb27b1 pbrook
    case 23:        /* ACMD23: SET_WR_BLK_ERASE_COUNT */
1164 a1bb27b1 pbrook
        switch (sd->state) {
1165 a1bb27b1 pbrook
        case sd_transfer_state:
1166 a1bb27b1 pbrook
            return sd_r1;
1167 a1bb27b1 pbrook
1168 a1bb27b1 pbrook
        default:
1169 a1bb27b1 pbrook
            break;
1170 a1bb27b1 pbrook
        }
1171 a1bb27b1 pbrook
        break;
1172 a1bb27b1 pbrook
1173 a1bb27b1 pbrook
    case 41:        /* ACMD41: SD_APP_OP_COND */
1174 775616c3 pbrook
        if (sd->spi) {
1175 775616c3 pbrook
            /* SEND_OP_CMD */
1176 775616c3 pbrook
            sd->state = sd_transfer_state;
1177 775616c3 pbrook
            return sd_r1;
1178 775616c3 pbrook
        }
1179 a1bb27b1 pbrook
        switch (sd->state) {
1180 a1bb27b1 pbrook
        case sd_idle_state:
1181 a1bb27b1 pbrook
            /* We accept any voltage.  10000 V is nothing.  */
1182 a1bb27b1 pbrook
            if (req.arg)
1183 a1bb27b1 pbrook
                sd->state = sd_ready_state;
1184 a1bb27b1 pbrook
1185 a1bb27b1 pbrook
            return sd_r3;
1186 a1bb27b1 pbrook
1187 a1bb27b1 pbrook
        default:
1188 a1bb27b1 pbrook
            break;
1189 a1bb27b1 pbrook
        }
1190 a1bb27b1 pbrook
        break;
1191 a1bb27b1 pbrook
1192 a1bb27b1 pbrook
    case 42:        /* ACMD42: SET_CLR_CARD_DETECT */
1193 a1bb27b1 pbrook
        switch (sd->state) {
1194 a1bb27b1 pbrook
        case sd_transfer_state:
1195 a1bb27b1 pbrook
            /* Bringing in the 50KOhm pull-up resistor... Done.  */
1196 a1bb27b1 pbrook
            return sd_r1;
1197 a1bb27b1 pbrook
1198 a1bb27b1 pbrook
        default:
1199 a1bb27b1 pbrook
            break;
1200 a1bb27b1 pbrook
        }
1201 a1bb27b1 pbrook
        break;
1202 a1bb27b1 pbrook
1203 a1bb27b1 pbrook
    case 51:        /* ACMD51: SEND_SCR */
1204 a1bb27b1 pbrook
        switch (sd->state) {
1205 a1bb27b1 pbrook
        case sd_transfer_state:
1206 a1bb27b1 pbrook
            sd->state = sd_sendingdata_state;
1207 a1bb27b1 pbrook
            sd->data_start = 0;
1208 a1bb27b1 pbrook
            sd->data_offset = 0;
1209 a1bb27b1 pbrook
            return sd_r1;
1210 a1bb27b1 pbrook
1211 a1bb27b1 pbrook
        default:
1212 a1bb27b1 pbrook
            break;
1213 a1bb27b1 pbrook
        }
1214 a1bb27b1 pbrook
        break;
1215 a1bb27b1 pbrook
1216 a1bb27b1 pbrook
    default:
1217 a1bb27b1 pbrook
        /* Fall back to standard commands.  */
1218 a1bb27b1 pbrook
        sd->card_status &= ~APP_CMD;
1219 a1bb27b1 pbrook
        return sd_normal_command(sd, req);
1220 a1bb27b1 pbrook
    }
1221 a1bb27b1 pbrook
1222 827df9f3 balrog
    fprintf(stderr, "SD: ACMD%i in a wrong state\n", req.cmd);
1223 a1bb27b1 pbrook
    return sd_r0;
1224 a1bb27b1 pbrook
}
1225 a1bb27b1 pbrook
1226 a1bb27b1 pbrook
int sd_do_command(SDState *sd, struct sd_request_s *req,
1227 a1bb27b1 pbrook
                  uint8_t *response) {
1228 a1bb27b1 pbrook
    uint32_t last_status = sd->card_status;
1229 a1bb27b1 pbrook
    sd_rsp_type_t rtype;
1230 a1bb27b1 pbrook
    int rsplen;
1231 a1bb27b1 pbrook
1232 827df9f3 balrog
    if (!bdrv_is_inserted(sd->bdrv) || !sd->enable) {
1233 a1bb27b1 pbrook
        return 0;
1234 a1bb27b1 pbrook
    }
1235 a1bb27b1 pbrook
1236 a1bb27b1 pbrook
    if (sd_req_crc_validate(req)) {
1237 a1bb27b1 pbrook
        sd->card_status &= ~COM_CRC_ERROR;
1238 a1bb27b1 pbrook
        return 0;
1239 a1bb27b1 pbrook
    }
1240 a1bb27b1 pbrook
1241 a1bb27b1 pbrook
    sd->card_status &= ~CARD_STATUS_B;
1242 a1bb27b1 pbrook
    sd_set_status(sd);
1243 a1bb27b1 pbrook
1244 a1bb27b1 pbrook
    if (last_status & CARD_IS_LOCKED)
1245 a1bb27b1 pbrook
        if (((last_status & APP_CMD) &&
1246 a1bb27b1 pbrook
                                 req->cmd == 41) ||
1247 a1bb27b1 pbrook
                        (!(last_status & APP_CMD) &&
1248 a1bb27b1 pbrook
                         (sd_cmd_class[req->cmd] == 0 ||
1249 a1bb27b1 pbrook
                          sd_cmd_class[req->cmd] == 7 ||
1250 a1bb27b1 pbrook
                          req->cmd == 16 || req->cmd == 55))) {
1251 a1bb27b1 pbrook
            sd->card_status |= ILLEGAL_COMMAND;
1252 827df9f3 balrog
            fprintf(stderr, "SD: Card is locked\n");
1253 a1bb27b1 pbrook
            return 0;
1254 a1bb27b1 pbrook
        }
1255 a1bb27b1 pbrook
1256 724d3a8f balrog
    if (last_status & APP_CMD) {
1257 a1bb27b1 pbrook
        rtype = sd_app_command(sd, *req);
1258 724d3a8f balrog
        sd->card_status &= ~APP_CMD;
1259 724d3a8f balrog
    } else
1260 a1bb27b1 pbrook
        rtype = sd_normal_command(sd, *req);
1261 a1bb27b1 pbrook
1262 a1bb27b1 pbrook
    sd->current_cmd = req->cmd;
1263 a1bb27b1 pbrook
1264 a1bb27b1 pbrook
    switch (rtype) {
1265 a1bb27b1 pbrook
    case sd_r1:
1266 a1bb27b1 pbrook
    case sd_r1b:
1267 a1bb27b1 pbrook
        sd_response_r1_make(sd, response, last_status);
1268 a1bb27b1 pbrook
        rsplen = 4;
1269 a1bb27b1 pbrook
        break;
1270 a1bb27b1 pbrook
1271 a1bb27b1 pbrook
    case sd_r2_i:
1272 a1bb27b1 pbrook
        memcpy(response, sd->cid, sizeof(sd->cid));
1273 a1bb27b1 pbrook
        rsplen = 16;
1274 a1bb27b1 pbrook
        break;
1275 a1bb27b1 pbrook
1276 a1bb27b1 pbrook
    case sd_r2_s:
1277 a1bb27b1 pbrook
        memcpy(response, sd->csd, sizeof(sd->csd));
1278 a1bb27b1 pbrook
        rsplen = 16;
1279 a1bb27b1 pbrook
        break;
1280 a1bb27b1 pbrook
1281 a1bb27b1 pbrook
    case sd_r3:
1282 a1bb27b1 pbrook
        sd_response_r3_make(sd, response);
1283 a1bb27b1 pbrook
        rsplen = 4;
1284 a1bb27b1 pbrook
        break;
1285 a1bb27b1 pbrook
1286 a1bb27b1 pbrook
    case sd_r6:
1287 a1bb27b1 pbrook
        sd_response_r6_make(sd, response);
1288 a1bb27b1 pbrook
        rsplen = 4;
1289 a1bb27b1 pbrook
        break;
1290 a1bb27b1 pbrook
1291 1b088995 balrog
    case sd_r7:
1292 1b088995 balrog
        sd_response_r7_make(sd, response);
1293 1b088995 balrog
        rsplen = 4;
1294 1b088995 balrog
        break;
1295 1b088995 balrog
1296 a1bb27b1 pbrook
    case sd_r0:
1297 a1bb27b1 pbrook
    default:
1298 a1bb27b1 pbrook
        rsplen = 0;
1299 a1bb27b1 pbrook
        break;
1300 a1bb27b1 pbrook
    }
1301 a1bb27b1 pbrook
1302 a1bb27b1 pbrook
    if (sd->card_status & ILLEGAL_COMMAND)
1303 a1bb27b1 pbrook
        rsplen = 0;
1304 a1bb27b1 pbrook
1305 a1bb27b1 pbrook
#ifdef DEBUG_SD
1306 a1bb27b1 pbrook
    if (rsplen) {
1307 a1bb27b1 pbrook
        int i;
1308 a1bb27b1 pbrook
        DPRINTF("Response:");
1309 a1bb27b1 pbrook
        for (i = 0; i < rsplen; i++)
1310 a1bb27b1 pbrook
            printf(" %02x", response[i]);
1311 a1bb27b1 pbrook
        printf(" state %d\n", sd->state);
1312 a1bb27b1 pbrook
    } else {
1313 a1bb27b1 pbrook
        DPRINTF("No response %d\n", sd->state);
1314 a1bb27b1 pbrook
    }
1315 a1bb27b1 pbrook
#endif
1316 a1bb27b1 pbrook
1317 a1bb27b1 pbrook
    return rsplen;
1318 a1bb27b1 pbrook
}
1319 a1bb27b1 pbrook
1320 a1bb27b1 pbrook
/* No real need for 64 bit addresses here */
1321 33f00271 balrog
static void sd_blk_read(SDState *sd, uint32_t addr, uint32_t len)
1322 a1bb27b1 pbrook
{
1323 a1bb27b1 pbrook
    uint32_t end = addr + len;
1324 a1bb27b1 pbrook
1325 33f00271 balrog
    if (!sd->bdrv || bdrv_read(sd->bdrv, addr >> 9, sd->buf, 1) == -1) {
1326 827df9f3 balrog
        fprintf(stderr, "sd_blk_read: read error on host side\n");
1327 a1bb27b1 pbrook
        return;
1328 a1bb27b1 pbrook
    }
1329 a1bb27b1 pbrook
1330 a1bb27b1 pbrook
    if (end > (addr & ~511) + 512) {
1331 33f00271 balrog
        memcpy(sd->data, sd->buf + (addr & 511), 512 - (addr & 511));
1332 a1bb27b1 pbrook
1333 33f00271 balrog
        if (bdrv_read(sd->bdrv, end >> 9, sd->buf, 1) == -1) {
1334 827df9f3 balrog
            fprintf(stderr, "sd_blk_read: read error on host side\n");
1335 a1bb27b1 pbrook
            return;
1336 a1bb27b1 pbrook
        }
1337 33f00271 balrog
        memcpy(sd->data + 512 - (addr & 511), sd->buf, end & 511);
1338 a1bb27b1 pbrook
    } else
1339 33f00271 balrog
        memcpy(sd->data, sd->buf + (addr & 511), len);
1340 a1bb27b1 pbrook
}
1341 a1bb27b1 pbrook
1342 33f00271 balrog
static void sd_blk_write(SDState *sd, uint32_t addr, uint32_t len)
1343 a1bb27b1 pbrook
{
1344 a1bb27b1 pbrook
    uint32_t end = addr + len;
1345 a1bb27b1 pbrook
1346 a1bb27b1 pbrook
    if ((addr & 511) || len < 512)
1347 33f00271 balrog
        if (!sd->bdrv || bdrv_read(sd->bdrv, addr >> 9, sd->buf, 1) == -1) {
1348 827df9f3 balrog
            fprintf(stderr, "sd_blk_write: read error on host side\n");
1349 a1bb27b1 pbrook
            return;
1350 a1bb27b1 pbrook
        }
1351 a1bb27b1 pbrook
1352 a1bb27b1 pbrook
    if (end > (addr & ~511) + 512) {
1353 33f00271 balrog
        memcpy(sd->buf + (addr & 511), sd->data, 512 - (addr & 511));
1354 33f00271 balrog
        if (bdrv_write(sd->bdrv, addr >> 9, sd->buf, 1) == -1) {
1355 827df9f3 balrog
            fprintf(stderr, "sd_blk_write: write error on host side\n");
1356 a1bb27b1 pbrook
            return;
1357 a1bb27b1 pbrook
        }
1358 a1bb27b1 pbrook
1359 33f00271 balrog
        if (bdrv_read(sd->bdrv, end >> 9, sd->buf, 1) == -1) {
1360 827df9f3 balrog
            fprintf(stderr, "sd_blk_write: read error on host side\n");
1361 a1bb27b1 pbrook
            return;
1362 a1bb27b1 pbrook
        }
1363 33f00271 balrog
        memcpy(sd->buf, sd->data + 512 - (addr & 511), end & 511);
1364 33f00271 balrog
        if (bdrv_write(sd->bdrv, end >> 9, sd->buf, 1) == -1)
1365 827df9f3 balrog
            fprintf(stderr, "sd_blk_write: write error on host side\n");
1366 a1bb27b1 pbrook
    } else {
1367 33f00271 balrog
        memcpy(sd->buf + (addr & 511), sd->data, len);
1368 33f00271 balrog
        if (!sd->bdrv || bdrv_write(sd->bdrv, addr >> 9, sd->buf, 1) == -1)
1369 827df9f3 balrog
            fprintf(stderr, "sd_blk_write: write error on host side\n");
1370 a1bb27b1 pbrook
    }
1371 a1bb27b1 pbrook
}
1372 a1bb27b1 pbrook
1373 33f00271 balrog
#define BLK_READ_BLOCK(a, len)        sd_blk_read(sd, a, len)
1374 33f00271 balrog
#define BLK_WRITE_BLOCK(a, len)        sd_blk_write(sd, a, len)
1375 a1bb27b1 pbrook
#define APP_READ_BLOCK(a, len)        memset(sd->data, 0xec, len)
1376 a1bb27b1 pbrook
#define APP_WRITE_BLOCK(a, len)
1377 a1bb27b1 pbrook
1378 a1bb27b1 pbrook
void sd_write_data(SDState *sd, uint8_t value)
1379 a1bb27b1 pbrook
{
1380 a1bb27b1 pbrook
    int i;
1381 a1bb27b1 pbrook
1382 827df9f3 balrog
    if (!sd->bdrv || !bdrv_is_inserted(sd->bdrv) || !sd->enable)
1383 a1bb27b1 pbrook
        return;
1384 a1bb27b1 pbrook
1385 a1bb27b1 pbrook
    if (sd->state != sd_receivingdata_state) {
1386 827df9f3 balrog
        fprintf(stderr, "sd_write_data: not in Receiving-Data state\n");
1387 a1bb27b1 pbrook
        return;
1388 a1bb27b1 pbrook
    }
1389 a1bb27b1 pbrook
1390 a1bb27b1 pbrook
    if (sd->card_status & (ADDRESS_ERROR | WP_VIOLATION))
1391 a1bb27b1 pbrook
        return;
1392 a1bb27b1 pbrook
1393 a1bb27b1 pbrook
    switch (sd->current_cmd) {
1394 a1bb27b1 pbrook
    case 24:        /* CMD24:  WRITE_SINGLE_BLOCK */
1395 a1bb27b1 pbrook
        sd->data[sd->data_offset ++] = value;
1396 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len) {
1397 a1bb27b1 pbrook
            /* TODO: Check CRC before committing */
1398 a1bb27b1 pbrook
            sd->state = sd_programming_state;
1399 a1bb27b1 pbrook
            BLK_WRITE_BLOCK(sd->data_start, sd->data_offset);
1400 a1bb27b1 pbrook
            sd->blk_written ++;
1401 a1bb27b1 pbrook
            sd->csd[14] |= 0x40;
1402 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
1403 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1404 a1bb27b1 pbrook
        }
1405 a1bb27b1 pbrook
        break;
1406 a1bb27b1 pbrook
1407 a1bb27b1 pbrook
    case 25:        /* CMD25:  WRITE_MULTIPLE_BLOCK */
1408 a1bb27b1 pbrook
        sd->data[sd->data_offset ++] = value;
1409 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len) {
1410 a1bb27b1 pbrook
            /* TODO: Check CRC before committing */
1411 a1bb27b1 pbrook
            sd->state = sd_programming_state;
1412 a1bb27b1 pbrook
            BLK_WRITE_BLOCK(sd->data_start, sd->data_offset);
1413 a1bb27b1 pbrook
            sd->blk_written ++;
1414 a1bb27b1 pbrook
            sd->data_start += sd->blk_len;
1415 a1bb27b1 pbrook
            sd->data_offset = 0;
1416 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size) {
1417 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
1418 a1bb27b1 pbrook
                break;
1419 a1bb27b1 pbrook
            }
1420 a1bb27b1 pbrook
            if (sd_wp_addr(sd, sd->data_start)) {
1421 a1bb27b1 pbrook
                sd->card_status |= WP_VIOLATION;
1422 a1bb27b1 pbrook
                break;
1423 a1bb27b1 pbrook
            }
1424 a1bb27b1 pbrook
            sd->csd[14] |= 0x40;
1425 a1bb27b1 pbrook
1426 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
1427 a1bb27b1 pbrook
            sd->state = sd_receivingdata_state;
1428 a1bb27b1 pbrook
        }
1429 a1bb27b1 pbrook
        break;
1430 a1bb27b1 pbrook
1431 a1bb27b1 pbrook
    case 26:        /* CMD26:  PROGRAM_CID */
1432 a1bb27b1 pbrook
        sd->data[sd->data_offset ++] = value;
1433 a1bb27b1 pbrook
        if (sd->data_offset >= sizeof(sd->cid)) {
1434 a1bb27b1 pbrook
            /* TODO: Check CRC before committing */
1435 a1bb27b1 pbrook
            sd->state = sd_programming_state;
1436 a1bb27b1 pbrook
            for (i = 0; i < sizeof(sd->cid); i ++)
1437 a1bb27b1 pbrook
                if ((sd->cid[i] | 0x00) != sd->data[i])
1438 a1bb27b1 pbrook
                    sd->card_status |= CID_CSD_OVERWRITE;
1439 a1bb27b1 pbrook
1440 a1bb27b1 pbrook
            if (!(sd->card_status & CID_CSD_OVERWRITE))
1441 a1bb27b1 pbrook
                for (i = 0; i < sizeof(sd->cid); i ++) {
1442 a1bb27b1 pbrook
                    sd->cid[i] |= 0x00;
1443 a1bb27b1 pbrook
                    sd->cid[i] &= sd->data[i];
1444 a1bb27b1 pbrook
                }
1445 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
1446 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1447 a1bb27b1 pbrook
        }
1448 a1bb27b1 pbrook
        break;
1449 a1bb27b1 pbrook
1450 a1bb27b1 pbrook
    case 27:        /* CMD27:  PROGRAM_CSD */
1451 a1bb27b1 pbrook
        sd->data[sd->data_offset ++] = value;
1452 a1bb27b1 pbrook
        if (sd->data_offset >= sizeof(sd->csd)) {
1453 a1bb27b1 pbrook
            /* TODO: Check CRC before committing */
1454 a1bb27b1 pbrook
            sd->state = sd_programming_state;
1455 a1bb27b1 pbrook
            for (i = 0; i < sizeof(sd->csd); i ++)
1456 a1bb27b1 pbrook
                if ((sd->csd[i] | sd_csd_rw_mask[i]) !=
1457 a1bb27b1 pbrook
                    (sd->data[i] | sd_csd_rw_mask[i]))
1458 a1bb27b1 pbrook
                    sd->card_status |= CID_CSD_OVERWRITE;
1459 a1bb27b1 pbrook
1460 a1bb27b1 pbrook
            /* Copy flag (OTP) & Permanent write protect */
1461 a1bb27b1 pbrook
            if (sd->csd[14] & ~sd->data[14] & 0x60)
1462 a1bb27b1 pbrook
                sd->card_status |= CID_CSD_OVERWRITE;
1463 a1bb27b1 pbrook
1464 a1bb27b1 pbrook
            if (!(sd->card_status & CID_CSD_OVERWRITE))
1465 a1bb27b1 pbrook
                for (i = 0; i < sizeof(sd->csd); i ++) {
1466 a1bb27b1 pbrook
                    sd->csd[i] |= sd_csd_rw_mask[i];
1467 a1bb27b1 pbrook
                    sd->csd[i] &= sd->data[i];
1468 a1bb27b1 pbrook
                }
1469 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
1470 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1471 a1bb27b1 pbrook
        }
1472 a1bb27b1 pbrook
        break;
1473 a1bb27b1 pbrook
1474 a1bb27b1 pbrook
    case 42:        /* CMD42:  LOCK_UNLOCK */
1475 a1bb27b1 pbrook
        sd->data[sd->data_offset ++] = value;
1476 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len) {
1477 a1bb27b1 pbrook
            /* TODO: Check CRC before committing */
1478 a1bb27b1 pbrook
            sd->state = sd_programming_state;
1479 a1bb27b1 pbrook
            sd_lock_command(sd);
1480 a1bb27b1 pbrook
            /* Bzzzzzzztt .... Operation complete.  */
1481 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1482 a1bb27b1 pbrook
        }
1483 a1bb27b1 pbrook
        break;
1484 a1bb27b1 pbrook
1485 a1bb27b1 pbrook
    case 56:        /* CMD56:  GEN_CMD */
1486 a1bb27b1 pbrook
        sd->data[sd->data_offset ++] = value;
1487 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len) {
1488 a1bb27b1 pbrook
            APP_WRITE_BLOCK(sd->data_start, sd->data_offset);
1489 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1490 a1bb27b1 pbrook
        }
1491 a1bb27b1 pbrook
        break;
1492 a1bb27b1 pbrook
1493 a1bb27b1 pbrook
    default:
1494 827df9f3 balrog
        fprintf(stderr, "sd_write_data: unknown command\n");
1495 a1bb27b1 pbrook
        break;
1496 a1bb27b1 pbrook
    }
1497 a1bb27b1 pbrook
}
1498 a1bb27b1 pbrook
1499 a1bb27b1 pbrook
uint8_t sd_read_data(SDState *sd)
1500 a1bb27b1 pbrook
{
1501 a1bb27b1 pbrook
    /* TODO: Append CRCs */
1502 a1bb27b1 pbrook
    uint8_t ret;
1503 a1bb27b1 pbrook
1504 827df9f3 balrog
    if (!sd->bdrv || !bdrv_is_inserted(sd->bdrv) || !sd->enable)
1505 a1bb27b1 pbrook
        return 0x00;
1506 a1bb27b1 pbrook
1507 a1bb27b1 pbrook
    if (sd->state != sd_sendingdata_state) {
1508 827df9f3 balrog
        fprintf(stderr, "sd_read_data: not in Sending-Data state\n");
1509 a1bb27b1 pbrook
        return 0x00;
1510 a1bb27b1 pbrook
    }
1511 a1bb27b1 pbrook
1512 a1bb27b1 pbrook
    if (sd->card_status & (ADDRESS_ERROR | WP_VIOLATION))
1513 a1bb27b1 pbrook
        return 0x00;
1514 a1bb27b1 pbrook
1515 a1bb27b1 pbrook
    switch (sd->current_cmd) {
1516 a1bb27b1 pbrook
    case 6:        /* CMD6:   SWITCH_FUNCTION */
1517 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1518 a1bb27b1 pbrook
1519 a1bb27b1 pbrook
        if (sd->data_offset >= 64)
1520 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1521 a1bb27b1 pbrook
        break;
1522 a1bb27b1 pbrook
1523 775616c3 pbrook
    case 9:        /* CMD9:   SEND_CSD */
1524 775616c3 pbrook
    case 10:        /* CMD10:  SEND_CID */
1525 775616c3 pbrook
        ret = sd->data[sd->data_offset ++];
1526 775616c3 pbrook
1527 775616c3 pbrook
        if (sd->data_offset >= 16)
1528 775616c3 pbrook
            sd->state = sd_transfer_state;
1529 775616c3 pbrook
        break;
1530 775616c3 pbrook
1531 a1bb27b1 pbrook
    case 11:        /* CMD11:  READ_DAT_UNTIL_STOP */
1532 a1bb27b1 pbrook
        if (sd->data_offset == 0)
1533 a1bb27b1 pbrook
            BLK_READ_BLOCK(sd->data_start, sd->blk_len);
1534 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1535 a1bb27b1 pbrook
1536 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len) {
1537 a1bb27b1 pbrook
            sd->data_start += sd->blk_len;
1538 a1bb27b1 pbrook
            sd->data_offset = 0;
1539 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size) {
1540 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
1541 a1bb27b1 pbrook
                break;
1542 a1bb27b1 pbrook
            }
1543 a1bb27b1 pbrook
        }
1544 a1bb27b1 pbrook
        break;
1545 a1bb27b1 pbrook
1546 a1bb27b1 pbrook
    case 13:        /* ACMD13: SD_STATUS */
1547 a1bb27b1 pbrook
        ret = sd->sd_status[sd->data_offset ++];
1548 a1bb27b1 pbrook
1549 a1bb27b1 pbrook
        if (sd->data_offset >= sizeof(sd->sd_status))
1550 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1551 a1bb27b1 pbrook
        break;
1552 a1bb27b1 pbrook
1553 a1bb27b1 pbrook
    case 17:        /* CMD17:  READ_SINGLE_BLOCK */
1554 a1bb27b1 pbrook
        if (sd->data_offset == 0)
1555 a1bb27b1 pbrook
            BLK_READ_BLOCK(sd->data_start, sd->blk_len);
1556 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1557 a1bb27b1 pbrook
1558 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len)
1559 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1560 a1bb27b1 pbrook
        break;
1561 a1bb27b1 pbrook
1562 a1bb27b1 pbrook
    case 18:        /* CMD18:  READ_MULTIPLE_BLOCK */
1563 a1bb27b1 pbrook
        if (sd->data_offset == 0)
1564 a1bb27b1 pbrook
            BLK_READ_BLOCK(sd->data_start, sd->blk_len);
1565 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1566 a1bb27b1 pbrook
1567 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len) {
1568 a1bb27b1 pbrook
            sd->data_start += sd->blk_len;
1569 a1bb27b1 pbrook
            sd->data_offset = 0;
1570 a1bb27b1 pbrook
            if (sd->data_start + sd->blk_len > sd->size) {
1571 a1bb27b1 pbrook
                sd->card_status |= ADDRESS_ERROR;
1572 a1bb27b1 pbrook
                break;
1573 a1bb27b1 pbrook
            }
1574 a1bb27b1 pbrook
        }
1575 a1bb27b1 pbrook
        break;
1576 a1bb27b1 pbrook
1577 a1bb27b1 pbrook
    case 22:        /* ACMD22: SEND_NUM_WR_BLOCKS */
1578 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1579 a1bb27b1 pbrook
1580 a1bb27b1 pbrook
        if (sd->data_offset >= 4)
1581 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1582 a1bb27b1 pbrook
        break;
1583 a1bb27b1 pbrook
1584 a1bb27b1 pbrook
    case 30:        /* CMD30:  SEND_WRITE_PROT */
1585 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1586 a1bb27b1 pbrook
1587 a1bb27b1 pbrook
        if (sd->data_offset >= 4)
1588 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1589 a1bb27b1 pbrook
        break;
1590 a1bb27b1 pbrook
1591 a1bb27b1 pbrook
    case 51:        /* ACMD51: SEND_SCR */
1592 a1bb27b1 pbrook
        ret = sd->scr[sd->data_offset ++];
1593 a1bb27b1 pbrook
1594 a1bb27b1 pbrook
        if (sd->data_offset >= sizeof(sd->scr))
1595 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1596 a1bb27b1 pbrook
        break;
1597 a1bb27b1 pbrook
1598 a1bb27b1 pbrook
    case 56:        /* CMD56:  GEN_CMD */
1599 a1bb27b1 pbrook
        if (sd->data_offset == 0)
1600 a1bb27b1 pbrook
            APP_READ_BLOCK(sd->data_start, sd->blk_len);
1601 a1bb27b1 pbrook
        ret = sd->data[sd->data_offset ++];
1602 a1bb27b1 pbrook
1603 a1bb27b1 pbrook
        if (sd->data_offset >= sd->blk_len)
1604 a1bb27b1 pbrook
            sd->state = sd_transfer_state;
1605 a1bb27b1 pbrook
        break;
1606 a1bb27b1 pbrook
1607 a1bb27b1 pbrook
    default:
1608 827df9f3 balrog
        fprintf(stderr, "sd_read_data: unknown command\n");
1609 a1bb27b1 pbrook
        return 0x00;
1610 a1bb27b1 pbrook
    }
1611 a1bb27b1 pbrook
1612 a1bb27b1 pbrook
    return ret;
1613 a1bb27b1 pbrook
}
1614 a1bb27b1 pbrook
1615 a1bb27b1 pbrook
int sd_data_ready(SDState *sd)
1616 a1bb27b1 pbrook
{
1617 a1bb27b1 pbrook
    return sd->state == sd_sendingdata_state;
1618 a1bb27b1 pbrook
}
1619 827df9f3 balrog
1620 827df9f3 balrog
void sd_enable(SDState *sd, int enable)
1621 827df9f3 balrog
{
1622 827df9f3 balrog
    sd->enable = enable;
1623 827df9f3 balrog
}