NAND Memory Layout: Difference between revisions
(Description of the CX NAND + incomplete description of the CM NAND) |
(initial manuf description) |
||
Line 4: | Line 4: | ||
* pages 0000 to 001F (Nspire) or 0000 to 003F (CX/CM): written to /phoenix/manuf.dat at each boot | * pages 0000 to 001F (Nspire) or 0000 to 003F (CX/CM): written to /phoenix/manuf.dat at each boot | ||
** Offset 000-003: 3C B0 6E 79 | |||
** Offset 804-805: model ID (in little-endian): 0x0C for TI-Nspire CAS, 0x0D for TI-Nspire Lab Cradle, 0x0E for TI-Nspire, 0x0F for TI-Nspire CX CAS, 0x10 for TI-Nspire CX, 0x11 for TI-Nspire CM CAS, 0x12 for TI-Nspire CM | |||
** Offset 806-807: unknown - 00 00 or 10 00 | |||
** Offset 808-80F: optional default language (CX/CM) - ISO 639 supported language string padded with 0 (for exemple fr, en, ar, zh_CN for TI-Nspire CX-C or CM-C...) | |||
* pages 0020 to 0A7F (Nspire) or 0040 to 057F (CX/CM): boot2 image | * pages 0020 to 0A7F (Nspire) or 0040 to 057F (CX/CM): boot2 image | ||
* pages 0A80 to 0AFF (Nspire) or 0580 to 063F (CX/CM): "bootdata" (every time this is modified, the next available page is used; if all 128 pages are in use, then the whole area is erased first) | * pages 0A80 to 0AFF (Nspire) or 0580 to 063F (CX/CM): "bootdata" (every time this is modified, the next available page is used; if all 128 pages are in use, then the whole area is erased first) |
Revision as of 13:23, 9 July 2013
NAND Flash
NAND pages are 528-bytes long (512 + 16-bytes header) on TI-Nspire and 2048-bytes long (2048 + 48-bytes header) on TI-Nspire CX/CM.
- pages 0000 to 001F (Nspire) or 0000 to 003F (CX/CM): written to /phoenix/manuf.dat at each boot
- Offset 000-003: 3C B0 6E 79
- Offset 804-805: model ID (in little-endian): 0x0C for TI-Nspire CAS, 0x0D for TI-Nspire Lab Cradle, 0x0E for TI-Nspire, 0x0F for TI-Nspire CX CAS, 0x10 for TI-Nspire CX, 0x11 for TI-Nspire CM CAS, 0x12 for TI-Nspire CM
- Offset 806-807: unknown - 00 00 or 10 00
- Offset 808-80F: optional default language (CX/CM) - ISO 639 supported language string padded with 0 (for exemple fr, en, ar, zh_CN for TI-Nspire CX-C or CM-C...)
- pages 0020 to 0A7F (Nspire) or 0040 to 057F (CX/CM): boot2 image
- pages 0A80 to 0AFF (Nspire) or 0580 to 063F (CX/CM): "bootdata" (every time this is modified, the next available page is used; if all 128 pages are in use, then the whole area is erased first)
- Offset 00-03: Marker AA C6 8C 92
- Offset 04-07: Downgrade protection: minimum OS version allowed as a 4-bytes word (major-minor-lower1-lower2). Written during OS installation with the value found in the second field 8020 of the OS upgrade file
- Offset 08-0F: Seems to hold the press-to-test status (word, word, long word)
- Offset 10-13: If nonzero, BOOT1 will attempt to run DIAGS by default; if zero, it will skip straight to BOOT2. (Either behavior can be overridden with the Esc+Menu+G key combination.)
- Offset 14-1A: TI-84 Plus emulator 0A1 certificate field
- Offset 1B-1E: TI-84 Plus emulator 041 certificate field
- Offset 1F-61: TI-84 Plus emulator 0A2 certificate field
- Offset 64-67: (OS 1.6+) Default LCD contrast (if not in range from 0x76 to 0x8A, assumed to be 0x80)
- pages 0B00 to 0F7F (Nspire) or 0640 to 079F (CX): diags software
- pages 0F80 to 0FFF (Nspire) or 07A0 to 07FF (CX): diags test results
- pages from 1000 (Nspire) or 0800 (CX) or 07C0 (CM): factory images or filesystem
Factory images
At startup, boot2 checks the NAND flash for a pre-loaded factory image. The format is a 32-byte header followed by the .tnc/.tno file contents:
- Offset 00-13: String "***PRELOAD_IMAGE***"
- Offset 14-17: 55 F0 01 55
- Offset 18-1B: (unknown)
- Offset 1C-1F: Size of image (in big-endian)
If boot2 finds this header, the user is prompted to press 'I' on the keypad. After that, the image is copied to RAM before creating the filesystem (The filesystem also starts at page 0x1000, so it cannot co-exist with a factory image), and is installed the same as if it had been received from the serial port.
Misc notes
32MB are available in the flash memory used for storage. As in other TI calculator models with flash memory, it is used to store both the Operating System and what was called the "archive memory" on the previous models (this term loses its sense with the TI-Nspire as we'll see).
The TI-Nspire OS advertises 27.8MB of what it calls "storage capacity", which is the flash memory which can be filled with TI-Nspire documents. The storage capacity of the TI-Nspire CAS is 24.4MB. Saved documents are always stored in the storage memory. Documents being edited probably have a working copy in RAM, copied to the storage memory when the document is saved. In the ~4300KB left on the TI-Nspire, we find the OS image (3020KB for the .tno), and 1280KB of perhaps certificates, parts of the boot code which wouldn't be stored in the NOR flash (although 512KB seems more than enough for a boot code), and more... On the TI-NSspire CAS, ~7782KB are left for this. The OS image (.tnc) is 2577.5KB, which leaves 5204.5KB for the unknown part.
The Handheld Status dialog shows 5.7MB of "spaced used" on the TI-Nspire after a reset (i.e without any documents in memory), and 3.4MB on the TI-Nspire CAS. The system space of the TI-Nspire contains at least 1.57MB of archive memory + 24KB of RAM for the TI-84 Plus emulation, or even the whole ROM image (certificates, boot code, OS code and archive memory, 2MB + 24KB of RAM). This last option seems possible since the difference between the "spaced used" of the TI-NSpire and the TI-Nspire CAS is 2.3MB. We are not sure about the remaining 4.11MB/3.68MB. It is clear that the archive memory and the RAM of the TI-84 Plus is stored in flash memory at shutdown and not kept in RAM because they survive a keypad swap and battery replacement.
Since 32MB of RAM is available, which is quite a lot, the whole OS code is decrypted from the OS image and copied to RAM at boot time, when the message "Loading Operating System..." is displayed during ~8 seconds. The RAM is also used as temporary storage transparently for the user as described above.