Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
000000
User Flash
Code Memory
(48K x 24-bit)
017FFE
018000
User Memory
Space
Reserved
7FFFFE
800000
Executive Code Memory
(Reserved)
8005BE
8005C0
Unit ID
(32 x 24-bit) 8005FE
800600
Reserved
Configuration Memory
Space
F7FFFE
Configuration Registers F80000
(8 x 16-bit) F8000E
F80010
Reserved
FEFFFE
Device ID FF0000
(2 x 16-bit) FF0002
FF0004
Reserved
FFFFFE
Note: The address boundaries for user Flash code memory are device specific.
3.3 Programming Executive Data RAM Prog. Executive is Prog. Executive must
Resident in Memory be Programmed
The programming executive uses the device’s data
RAM for variable storage and program execution. Once
the programming executive is run, no assumptions
should be made about the contents of data RAM.
Finish
P6
P17 P7
P12
VIH VIH
MCLR
VDD
Program/Verify Entry Code = 0x4D434850
0 1 0 0 1 ... 0 0 0 0
PGD
b31 b30 b29 b28 b27 b3 b2 b1 b0
PGC
P16 P2B
P2A
PGC
PGD = Input
Start
ConfigAddress = 0xF80000
Send PROGC
Command
Is No
PROGC Response
PASS?
Yes
Is
ConfigAddress = No
ConfigAddress
ConfigAddress+2
0xF8000C?
Yes
Failure
Finish
Report Error
6.1 Erasing Memory For modification of code-protect bits, the entire chip
must first be erased with the ERASEB command. The
Memory is erased by using an ERASEB or ERASEP code-protect bits can be reprogrammed using the
command, as detailed in Section 8.5 “Command PROGC command.
Descriptions”. Code memory can be erased by row
Note: If read or write code protection is enabled,
using the ERASEP command. When memory is erased,
no modifications can be made to any
the affected memory locations are set to ‘1’s.
region of code memory until code
The ERASEB command provides several Bulk Erase protection is disabled. Code protection
options. Performing a Chip Erase with the ERASEB can only be disabled by performing a Chip
command clears all code memory and code protection Erase with the ERASEB command.
registers. Alternatively, the ERASEB command can be
used to selectively erase individual program memory
6.3 Reading Memory
segments.Table 6-1 summarizes the Erase options.
The READD command reads the Configuration bits and
TABLE 6-1: ERASE OPTIONS device ID of the device. This command only returns
16-bit data and operates on 16-bit registers.
Command Affected Region
The READP command reads the code memory of the
ERASEB Entire chip(1) or all code memory device. This command only returns 24-bit data packed
ERASEP(2) Specified rows of code memory as described in Section 8.3 “Packed Data Format”.
Note 1: The system operation Configuration The READP command can be used to read up to 32K
registers and device ID registers are not instruction words of code memory (only 4K instruction
erasable. words are present on the dsPIC30F SMPS devices).
2: ERASEP can not be used to erase Note: Reading an unimplemented memory
code-protect Configuration bits. These bits location causes the programming
must be erased using ERASEB. executive to reset. All READD and READP
commands must specify only valid
6.2 Modifying Memory memory locations.
Instead of bulk-erasing the device before starting to 6.4 Programming Executive Software
program, it is possible that you may want to modify only
Version
a section of an already programmed device. In this
situation, Chip Erase is not a realistic option. At times, it may be necessary to determine the version
Instead, you can erase selective rows of code memory of programming executive stored in executive memory.
using the ERASEP command. You can then reprogram The QVER command performs this function. See
the modified rows with the PROGP command pairs. Section 8.5.9 “QVER Command” for details of QVER
command.
1 2 15 16 1 2 15 16 1 2 15 16
PGC
15 8 7 0
8.2 Command Format
lsw1
All programming executive commands have a general MSB2 MSB1
format consisting of a 16-bit header and any required
lsw2
data for the command (see Figure 8-1). The 16-bit
header consists of a 4-bit opcode field, which is used to lswx: Least significant 16-bits of instruction word
identify the command, followed by a 12-bit command MSBx: Most significant byte of instruction word
length field.
Field Description
Opcode 0xB 15 12 11 8 7 0
Length 0x1 Opcode QE_Code
The QVER command queries the version of the Last_Cmd
programming executive software stored in test
Length
memory. The “version.revision” information is returned
in the response’s QE_Code using a single byte with the D_1 (if applicable)
following format: main version in upper nibble and
revision in the lower nibble (i.e., 0x23 means version ...
2.3 of programming executive software).
D_N (if applicable)
Expected Response (2 words):
0x1BMN (where “MN” stands for version M.N)
0x0002
Field Description
9.0 PROGRAMMING EXECUTIVE Opcode Response opcode.
RESPONSES Last_Cmd Programmer command that
generated the response.
9.1 Overview QE_Code Query code or Error code.
The programming executive sends a response to the Length Response length in 16-bit words
programmer for each command that it receives. The (includes 2 header words.)
response indicates if the command was processed D_1 First 16-bit data word (if applicable).
correctly, and includes any required response, or error,
D_N Last 16-bit data word (if applicable).
data.
The programming executive response set is shown in 9.2.1 Opcode FIELD
Table 9-1. This table contains the opcode, mnemonic
The Opcode is a 4-bit field in the first word of the
and description for each response. The response
response. The Opcode indicates how the command is
format is described in Section 9.2 “Response
processed (see Table 9-1). If the command is
Format”.
processed successfully, the response opcode is PASS.
If there is an error in processing the command, the
TABLE 9-1: PROGRAMMING EXECUTIVE response opcode is FAIL, and the QE_Code indicates
RESPONSE SET the reason for the failure. If the command sent to
Opcode Mnemonic Description the programming executive is not identified, the
programming executive returns a NACK response.
0x1 PASS Command successfully
processed. 9.2.2 Last_Cmd FIELD
0x2 FAIL Command unsuccessfully The Last_Cmd is a 4-bit field in the first word of
processed. the response and indicates the command that the
0x3 NACK Command not known. programming executive processed. Since the
programming executive can only process one
command at a time, this field is technically not required.
However, it can be used to verify that the programming
executive correctly received the command that the
programmer transmitted.
PGD = Input
1 2 3 4 1 2 7 8 1 2 3 4 5 6 11 12 13 14 15 16 1 2 3 4
PGC
P4 P5 P4a
Execute Previous Instruction, CPU Held In Idle Shift Out VISI Register <15:0> No Execution Takes Place,
Fetch REGOUT Control Code Fetch Next Control Code
11.3 Entering ICSP Mode Once the key sequence is complete, VIH must be
applied to MCLR and held at that level for as long as
Figure 11-3 shows the three required steps to enter Program/Verify mode has to be maintained. An interval
the ICSP Program/Verify mode: of at least time P17 and P7 must elapse before
1. MCLR is briefly driven high then low. presenting data on PGD. Signals appearing on PGD
2. A 32-bit key sequence is clocked into PGD. before P7 has elapsed will not be interpreted as valid.
3. MCLR is then driven high within a specified On successful entry, the program memory can be
period of time and held. accessed and programmed in serial fashion. While in
ICSP mode, all unused I/Os are placed in the
The programming voltage applied to MCLR is VIH,
high-impedance state.
which is essentially VDD in the case of dsPIC30F
SMPS devices. There is no minimum time requirement
for holding at VIH. After VIH is removed, an interval of at
least P16 must elapse before presenting the key
sequence on PGD.
The key sequence is a specific 32-bit pattern,
‘0100 1101 0100 0011 0100 1000 0101 0001’
(more easily remembered as 0x4D434851 in
hexadecimal). The device will enter Program/Verify
mode only if the sequence is valid. The Most Significant
bit (MSb) of the most significant nibble must be shifted
in first.
P6
P12 P17 P7
VIH VIH
MCLR
VDD
Program/Verify Entry Code = 0x4D434851
0 1 0 0 1 ... 0 0 0 1
PGD
b31 b30 b29 b28 b27 b3 b2 b1 b0
PGC
P16 P2B
P2A
TABLE 11-4: SERIAL INSTRUCTION EXECUTION FOR BULK ERASING PROGRAM MEMORY
Command Data
Description
(Binary) (Hex)
Step 1: Exit the Reset vector.
0000 040100 GOTO 0x100
0000 040100 GOTO 0x100
0000 000000 NOP
Step 2: Set the NVMCON to erase all Program Memory.
00000 2407FA MOV #0x407F, W10
0000 883B0A MOV W10, NVMCON
Step 3: Unlock the NVMCON for programming.
0000 200558 MOV #0x55, W8
0000 883B38 MOV W8, NVMKEY
0000 200AA9 MOV #0xAA, W9
0000 883B39 MOV W9, NVMKEY
Step 4: Initiate the erase cycle.
0000 A8E761 BSET NVMCON, #WR
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
— — Externally time 200 msec
0000 A9E761 BCLR NVMCON, #WR
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
TABLE 11-5: SERIAL INSTRUCTION EXECUTION FOR ROW ERASING PROGRAM MEMORY
Command Data
Description
(Binary) (Hex)
Step 1: Exit the Reset vector.
0000 040100 GOTO 0x100
0000 040100 GOTO 0x100
0000 000000 NOP
Step 2: Initialize NVMADR and NVMADRU to erase code memory and initialize W7 for row address updates.
0000 EB0300 CLR W6
0000 883B16 MOV W6, NVMADR
0000 883B26 MOV W6, NVMADRU
0000 200407 MOV #0x40, W7
Step 3: Set NVMCON to erase 1 row of code memory.
0000 24071A MOV #0x4071, W10
0000 883B0A MOV W10, NVMCON
Step 4: Unlock the NVMCON to erase 1 row of code memory.
0000 200558 MOV #0x55, W8
0000 883B38 MOV W8, NVMKEY
0000 200AA9 MOV #0xAA, W9
0000 883B39 MOV W9, NVMKEY
Step 5: Initiate the erase cycle.
0000 A8E761 BSET NVMCON, #WR
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
— — Externally time 2 msec
0000 A9E761 BCLR NVMCON, #WR
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
0000 000000 NOP
TABLE 11-10: SERIAL INSTRUCTION EXECUTION FOR READING ALL CONFIGURATION MEMORY
Command Data
Description
(Binary) (Hex)
Step 1: Exit the Reset vector.
0000 040100 GOTO 0x100
0000 040100 GOTO 0x100
0000 000000 NOP
Step 2: Initialize TBLPAG, and the read pointer (W6) and the write pointer (W7) for TBLRD instruction.
0000 200F80 MOV #0xF8, W0
0000 880190 MOV W0, TBLPAG
0000 EB0300 CLR W6
0000 EB0380 CLR W7
Step 3: Read the Configuration register and write it to the VISI register (located at 0x784).
0000 BA0BB6 TBLRDL [W6++], [W7]
0000 000000 NOP
0000 000000 NOP
0000 883C20 MOV W0, VISI
0000 000000 NOP
Step 4: Output the VISI register using the REGOUT command.
0001 <VISI> Clock out contents of VISI register
0000 000000 NOP
Step 5: Reset device internal PC.
0000 040100 GOTO 0x100
0000 000000 NOP
Step 6: Repeat steps 3-5 until all desired code memory is read.
TABLE 11-11: SERIAL INSTRUCTION EXECUTION FOR READING THE APPLICATION ID WORD
Command Data
Description
(Binary) (Hex)
Step 1: Exit the Reset vector.
0000 040100 GOTO 0x100
0000 040100 GOTO 0x100
0000 000000 NOP
Step 2: Initialize TBLPAG and the read pointer (W0) for TBLRD instruction.
0000 200800 MOV #0x80, W0
0000 880190 MOV W0, TBLPAG
0000 205BE0 MOV #0x5BE, W0
0000 207841 MOV VISI, W1
0000 BA0890 TBLRDL [W0], [W1]
0000 000000 NOP
0000 000000 NOP
Step 3: Output the VISI register using the REGOUT command.
0001 <VISI> Clock out contents of the VISI register
0000 000000 NOP
— 30 mA Bulk Erase
D001 VDD Supply voltage 3.0 5.5 V
D002 VDDBULK Supply voltage for Bulk Erase 3.0 5.5 V
programming
D031 VIL Input Low Voltage VSS 0.2 VSS V
D041 VIH Input High Voltage 0.8 VDD VDD V
D080 VOL Output Low Voltage — 0.6 V IOL = 8.5 mA
D090 VOH Output High Voltage VDD – 0.7 — V IOH = -3.0 mA
D012 CIO Capacitive Loading on I/O Pin (PGD) — 50 pF To meet AC
specifications
P1 TPGC Serial Clock (PGC) Period 100 — ns
P1A TPGCL Serial Clock (PGC) Low Time 40 — ns
P1B TPGCH Serial Clock (PGC) High Time 40 — ns
P2 TSET1 Input Data Setup Time to Serial Clock ↓ 15 — ns
P3 THLD1 Input Data Hold Time from PGC ↓ 15 — ns
P4 TDLY1 Delay between 4-bit Command and 40 — ns
Command Operand
P4A TDLY1A Delay between 4-bit Command Operand 40 — ns
and Next 4-bit Command
P5 TDLY2 Delay between Last PGC ↓ of Command 20 — ns
Byte to First PGC ↑ of Read of Data Word
P6 TSET2 VDD ↑ Setup Time to MCLR ↑ 100 — ns
P7 THLD2 Input Data Hold Time from MCLR ↑ 500 — ns
P8 TDLY3 Delay between Last PGC ↓ of Command 20 — ms
Byte to PGD ↑ by Programming
Executive
P9a TDLY4 Programming Executive Command 10 — ms
Processing Time
P9b TDLY5 Delay between PGD ↓ by Programming 15 — ms
Executive to PGD Released by
Programming Executive
P10 TDLY6 PGC Low Time After Programming 400 — ns
APPENDIX A: HEX FILE FORMAT Because the Intel hex file format is byte-oriented, and
the 16-bit program counter is not, program memory
Flash programmers process the standard HEX format sections require special treatment. Each 24-bit
used by the Microchip development tools. The format program word is extended to 32 bits by inserting a so-
supported is the Intel® HEX 32 Format (INHX32). called “phantom byte”. Each program memory
Please refer to Appendix A in the “MPASM™ address is multiplied by 2 to yield a byte address.
Assembler, MPLINK™ Linker, MPLIB™ Object
As an example, a section that is located at 0x100 in
Librarian User’s Guide” (DS33014) for more
program memory will be represented in the hex file as
information about hex file formats.
0x200.
The basic format of the hex file is:
The hex file will be produced with the following
:BBAAAATTHHHH...HHHHCC contents:
Each data record begins with a 9-character prefix and :020000040000fa
always ends with a 2-character checksum. All records
:040200003322110096
begin with ':' regardless of the format. The individual
elements are described below. :00000001FF
• BB - is a two-digit hexadecimal byte count Notice that the data record (line 2) has a load address
representing the number of data bytes that of 0200, while the source code specified address
appear on the line. Divide this number by two to 0x100. Note also that the data is represented in “little-
get the number of words per line. endian” format, meaning the least significant byte
• AAAA - is a four-digit hexadecimal address appears first. The phantom byte appears last, just
representing the starting address of the data before the checksum.
record. Format is high byte first followed by low
byte. The address is doubled because this format
only supports 8-bits. Divide the value by two to
find the real device address.
• TT - is a two-digit record type that will be '00' for
data records, '01' for end-of-file records and '04'
for extended-address record.
• HHHH - is a four-digit hexadecimal data word.
Format is low byte followed by high byte. There
will be BB/2 data words following TT.
• CC - is a two-digit hexadecimal checksum that is
the two's complement of the sum of all the
preceding bytes in the line record.
APPENDIX B: REVISION HISTORY • Replaced the number 9 with the word seven in the
last sentence of the last paragraph of
Revision A (February 2007) Section 11.7 “Writing Configuration Memory”.
• Initial release of this document. • Changed the max values for parameters TPROG
Revision B (September 2007) and TERA in Table 13-11.
• Added Appendix A: “Hex File Format”.
• Updated paragraph in Section 2.2 “Pins Used
During Programming” to include reference to
location of complete pin diagrams
• Removed all pin diagrams
• Modified the first sentence in Section 5.7.1
“Overview” to read as follows: The dsPIC30F
SMPS has Configuration bits stored in seven 16-
bit registers. Bold text denotes the change.
• Added the following note after the second
paragraph in Section 5.7.1 “Overview”:
Note: If user software performs an erase opera-
tion on the configuration fuse, it must be
followed by a write operation to this fuse
with the desired value, even if the desired
value is the same as the state of the
erased fuse.
• Added the following sentence to the end of the
paragraph in Section 5.7.5 “User Unit ID”:
Programming the UNIT ID is similar to
programming the Programming Executive (see
Section 12.0 “Programming the Programming
Executive to Memory” for details).
• Updated instructions in the following tables:
- Table 11-4 (removed two NOPs before the
GOTO instruction in Step 1 and added two
NOPs after BSET and BCLR in Step 12)
- Table 11-5 (removed two NOPs before the
GOTO instruction in Step 1 and added two
NOPs after BSET and BCLR in Step 5 and
Step 12)
- Table 11-7 (removed two NOPs before the
GOTO instruction in Step 1, changed BB1B96
to BB1B86 in Step 6, added two NOPs after
BSET and BCLR in Step 8, and changed 9 to
seven in Step 10)
- Table 11-8 (removed two NOPs before the
GOTO instruction in Step 1)
- Table 11-9 (removed two NOPs before the
GOTO instruction in Step 1)
- Table 11-10 (removed two NOPs before the
GOTO instruction in Step 1)
- Table 11-11 (removed two NOPs before the
GOTO instruction in Step 1)
- Table 12-1 (removed two NOPs before the GOTO
instruction in Step 1 and added two NOPs after
BSET and BCLR in Step 4 and Step 11)
- Table 12-2 (removed two NOPs before the
GOTO instruction in Step 1)
• Microchip believes that its family of products is one of the most secure families of its kind on the market today, when used in the
intended manner and under normal conditions.
• There are dishonest and possibly illegal methods used to breach the code protection feature. All of these methods, to our
knowledge, require using the Microchip products in a manner outside the operating specifications contained in Microchip’s Data
Sheets. Most likely, the person doing so is engaged in theft of intellectual property.
• Microchip is willing to work with the customer who is concerned about the integrity of their code.
• Neither Microchip nor any other semiconductor manufacturer can guarantee the security of their code. Code protection does not
mean that we are guaranteeing the product as “unbreakable.”
Code protection is constantly evolving. We at Microchip are committed to continuously improving the code protection features of our
products. Attempts to break Microchip’s code protection feature may be a violation of the Digital Millennium Copyright Act. If such acts
allow unauthorized access to your software or other copyrighted work, you may have a right to sue for relief under that Act.
09/10/07