This errata document describes corrections to the
MCF54455 Reference Manual, order number
MC54455RM. For convenience, the addenda items are
grouped by revision. Please check our website at
http://www.freescale.com for the latest updates.
The current available version of the MCF54455 Reference Manual is Revision 6.
Add pin N7 to the VSS pin list for the 360 TEPBGA.
2Revision History
Table 2 provides a revision history for this document.
Table 2. Revision History Table
Rev. NumberSubstantive ChangesDate of Release
1.0Initial release. Correct errors in section 16.2, “External Signal Description”.11/2011
MCF54455 Reference Manual Errata, Rev. 1
Freescale Semiconductor2
Page 4
THIS PAGE IS INTENTIONALLY LEFT BLANK
MCF54455 Reference Manual Errata, Rev. 1
Freescale Semiconductor3
Page 5
How to Reach Us:
Home Page:
www.freescale.com
Web Support:
http://www.freescale.com/support
USA/Europe or Locations Not Listed:
Freescale Semiconductor, Inc.
Technical Information Center, EL516
2100 East Elliot Road
Tempe, Arizona 85284
1-800-521-6274 or +1-480-768-2130
www.freescale.com/support
Europe, Middle East, and Africa:
Freescale Halbleiter Deutschland GmbH
Technical Information Center
Schatzbogen 7
81829 Muenchen, Germany
+44 1296 380 456 (English)
+46 8 52200080 (English)
+49 89 92103 559 (German)
+33 1 69 35 48 48 (French)
www.freescale.com/support
Japan:
Freescale Semiconductor Japan Ltd. Headquarters
ARCO Tower 15F
1-8-1, Shimo-Meguro, Meguro-ku,
Tokyo 153-0064
Japan
0120 191014 or +81 3 5437 9125
[email protected]
Asia/Pacific:
Freescale Semiconductor China Ltd.
Exchange Building 23F
No. 118 Jianguo Road
Chaoyang District
Beijing 100022
China
+86 10 5879 8000
[email protected]
Information in this document is provided solely to enable system and
software implementers to use Freescale Semiconductor products. There are
no express or implied copyright licenses granted hereunder to design or
fabricate any integrated circuits or integrated circuits based on the
information in this document.
Freescale Semiconductor reserves the right to make changes without further
notice to any products herein. Freescale Semiconductor makes no warranty,
representation or guarantee regarding the suitability of its products for any
particular purpose, nor does Freescale Semiconductor assume any liability
arising out of the application or use of any product or circuit, and specifically
disclaims any and all liability, including without limitation consequential or
incidental damages. “Typical” parameters that may be provided in Freescale
Semiconductor data sheets and/or specifications can and do vary in different
applications and actual performance may vary over time. All operating
parameters, including “Typicals”, must be validated for each customer
application by customer’s technical exper ts. Freescale Semiconductor does
not convey any license under its patent rights nor the rights of others.
Freescale Semiconductor products are not designed, intended, or authorized
for use as components in systems intended for surgical implant into the body,
or other applications intended to support or sustain life, or for any other
application in which the failure of the Freescale Semico nductor product could
create a situation where personal injury or death may occur. Should Buyer
purchase or use Freescale Semicondu ctor products for any such unintended
or unauthorized application, Buyer shall indemnify and hold Freescale
Semiconductor and its officers, employees, subsidiaries, affiliates, and
distributors harmless against all claims, costs, damages, and expenses, and
reasonable attorney fees arising out of, directly or indirectly, any claim of
personal injury or death associated with such unintended or unauthorized
use, even if such claim alleges that Freescale Semiconductor was negligent
regarding the design or manufacture of the part.
Freescale Semiconductor Literature Distribution Center
1-800-441-2447 or +1-303-675-2140
Fax: +1-303-675-2150
[email protected]
Freescale™ and the Freescale logo are trademarks of Freescale
Semiconductor, Inc. The described product contains a PowerPC processor
core. The PowerPC name is a trademark of IBM Corp. and used under license.
All other product or service names are the property of their respective owners.
Freescale Semiconductor
Technical Information Center, CH370
1300 N. Alma School Road
Chandler, Arizona 85224
+1-800-521-6274 or +1-480-768-2130
[email protected]
Freescale Semiconductor Japan Ltd.
Headquarters
ARCO Tower 15F
1-8-1, Shimo-Meguro, Meguro-ku,
Tokyo 153-0064, Japan
0120 191014 or +81 3 5437 9125
[email protected]
Asia/Pacific:
Freescale Semiconductor China Ltd.
Exchange Building 23F
No. 118 Jianguo Road
Chaoyang District
Beijing 100022
China
+86 10 5879 8000
[email protected]
For Literature Requests Only:
Freescale Semiconductor Literature Distribution Center
1-800-441-2447 or 303-675-2140
Fax: 303-675-2150
[email protected]
Information in this document is provided solely to enable system and
software implementers to use Freescale Semiconductor products. There are
no express or implied copyright licenses granted hereunder to design or
fabricate any integrated circuits or integrated circuits based on the
information in this document.
Freescale Semiconductor reserves the right to make changes without further
notice to any products herein. Freescale Semiconductor makes no warranty,
representation or guarantee regarding the suitability of its products for any
particular purpose, nor does Freescale Semiconductor assume any liability
arising out of the application or use of any product or circuit, and specifically
disclaims any and all liability, including without limitation consequential or
incidental damages. “Typical” parameters that may be provided in Freescale
Semiconductor data sheets and/or specifications can and do vary in different
applications and actual performance may vary over time. All operating
parameters, including “Typicals”, must be validated for each customer
application by customer’s technical exper ts. Freescale Semiconductor does
not convey any license under its patent rights nor the rights of others.
Freescale Semiconductor products are not designed, intended, or authorized
for use as components in systems intended for surgical implant into the body,
or other applications intended to support or sustain life, or for any other
application in which the failure of the Freescale Semico nductor product could
create a situation where personal injury or death may occur. Should Buyer
purchase or use Freescale Semicondu ctor products for any such unintended
or unauthorized application, Buyer shall indemnify and hold Freescale
Semiconductor and its officers, employees, subsidiaries, affiliates, and
distributors harmless against all claims, costs, damages, and expenses, and
reasonable attorney fees arising out of, directly or indirectly, any claim of
personal injury or death associated with such unintended or unauthorized
use, even if such claim alleges that Freescale Semiconductor was negligent
regarding the design or manufacture of the part.
The primary objective of this reference manual is to define the processor for software and hardware
developers. The information in this book is subject to change without notice, as described in the
disclaimers on the title page. As with any technical documentation, the reader must use the most recent
version of the documentation.
To locate any published errata or updates for this document, refer to the world-wide web at
http://www.freescale.com/coldfire.
Portions of Chapter 23, “Universal Serial Bus Interface – Host Module,” and Chapter 10, “Universal Serial
1999-2001. The EHCI specification is provided “As Is” with no warranties whatsoever, including any
warranty of merchantability, non-infringement, fitness for any particular purpose, or any warranty
otherwise arising out of any proposal, specification or sample. Intel disclaims all liability, including
liability for infringement of any proprietary rights, relating to use of information in the EHCI specification.
Intel may make changes to the EHCI specifications at any time, without notice.
Audience
This manual is intended for system software and hardware developers and applications programmers who
want to develop products with this ColdFire processor. It is assumed that the reader understands operating
systems, microprocessor system design, basic principles of software and hardware, and basic details of the
ColdFire® architecture.
Suggested Reading
This section lists additional reading that provides background for the information in this manual as well as
general information about ColdFire architecture.
General Information
Useful information about the ColdFire architecture and computer architecture in general:
•Using Microprocessors and Microcomputers: The Motorola Family, William C. Wray, Ross
Bannatyne, Joseph D. Greenfield
•Computer Architecture: A Quantitative Approach, Second Edition, by John L. Hennessy and David
A. Patterson.
•Computer Organization and Design: The Hardware/Software Interface, Second Edition, David A.
Patterson and John L. Hennessy.
Freescale Semiconductorxxv
Page 31
ColdFire Documentation
ColdFire documentation is available from the sources listed on the back cover of this manual, as well as
our web site, http://www.freescale.com/coldfire.
•Reference manuals — These books provide details about individual ColdFire implementations and
are intended to be used in conjunction with the ColdFire Programmers Reference Manual.
•Data sheets — Data sheets provide specific data regarding pin-out diagrams, bus timing, signal
behavior, and AC, DC, and thermal characteristics, as well as other design considerations.
•Product briefs — Each device has a product brief that provides an overview of its features. This
document is roughly equivalent to the overview (Chapter 1) of an device’s reference manual.
•Application notes — These short documents address specific design issues useful to programmers
and engineers working with Freescale Semiconductor processors.
Additional literature is published as new processors become available. For a current list of ColdFire
documentation, refer to http://www.freescale.com/coldfire.
Conventions
This document uses the following notational conventions:
cleared/setWhen a bit takes the value zero, it is said to be cleared; when it takes a value of
one, it is said to be set.
MNEMONICSIn text, instruction mnemonics are shown in uppercase.
mnemonicsIn code and tables, instruction mnemonics are shown in lowercase.
REG[FIELD]Abbreviations for registers are shown in uppercase. Specific bits, fields, or ranges
appear in brackets. For example, RAMBAR[BA] identifies the base address field
in the RAM base address register.
nibble A 4-bit data unit
byte An 8-bit data unit
word A 16-bit data unit
1
longword A 32-bit data unit
xIn some contexts, such as signal encodings, x indicates a don’t care.
nUsed to express an undefined numerical value
~NOT logical operator
&AND logical operator
|OR logical operator
1
The only exceptions to this appear in the discussion of serial communication modules that support variable-length data
transmission units. To simplify the discussion these units are referred to as words regardless of length.
xxviFreescale Semiconductor
Page 32
||Field concatenation operator
OVERBARAn overbar indicates that a signal is active-low.
Register Figure Conventions
This document uses the following conventions for the register reset values:
—Undefined at reset.
uUnaffected by reset.
[signal_name]Reset value is determined by the polarity of the indicated signal.
The following register fields are used:
R0Indicates a reserved bit field in a memory-mapped register. These bits are always read as zeros.
W
R1Indicates a reserved bit field in a memory-mapped register. These bits are always read as ones.
W
R FIELDNAMEIndicates a read/write bit.
W
R FIELDNAMEIndicates a read-only bit field in a memory-mapped register.
W
RIndicates a write-only bit field in a memory-mapped register.
W FIELDNAME
R FIELDNAMEWrite 1 to clear: indicates that writing a 1 to this bit field clears it.
Ww1c
R0Indicates a self-clearing bit.
W FIELDNAME
Freescale Semiconductorxxvii
Page 33
xxviiiFreescale Semiconductor
Page 34
Chapter 1
Overview
The MCF5445x devices are a family of highly-integrated 32-bit microprocessors based on the Version 4
ColdFire microarchitecture. This product line is well suited for secure networked applications in factory
automation, process control, and motion control. The rich feature set and flexibility make it attractive to
many different applications in consumer and industrial markets.
All MCF5445x devices contain a Version 4 ColdFire core, 32-Kbyte internal SRAM, USB On-the-Go
controllers, a 2-bank DDR/DDR2/mobile-DDR SDRAM controller, a 16-channel DMA controller, a serial
boot facility, an SSI interface, and other serial interfaces. Optional peripherals include a PCI bus controller,
ATA controller, Fast Ethernet controllers, and an encryption coprocessor.
1.1MCF5445x Family Comparison
The following table compares the various device derivatives available within the MCF5445x family.
ATA– Advanced Technology Attachment Controller
BDM– Background debug module
CAU– Cryptography acceleration unit
DSPI– DMA serial peripheral interface
eDMA– Enhanced direct memory access
EMAC– Enchance multiply-accumulate unit
EPORT– Edge port module
FEC– Fast Ethernet controller
GPIO– General Purpose Input/Output
I
2
C– Inter-Intergrated Circuit
INTC– Interrupt controller
JTAG– Joint Test Action Group interface
MMU– Memory management unit
PCI– Peripheral Component Interconnect
PIT– Programmable interrupt timers
PLL– Phase locked loop module
RNG– Random Number Generator
RTC– Real time clock
SSI– Synchronous Serial Interface
USB OTG – Universal Serial Bus On-the-Go controller
MCF54455
EMAC
2 FECs
Crossbar Switch (XBS)
32K
SRAM
Peripheral Bridge
CAU
16K
Instruction
Cache
16K
Data
Cache
Timers
BDM
ATA
SDRAM
Controller
FlexBus
eDMA
USB OTG
4 PITs
SSIRNGGPIO
MMU
Hardware
Divide
OscillatorPLLJTAG
PCISerial Boot
1.2Block Diagram
Figure 1-1 shows a top-level block diagram of the MCF54455 superset device.
Overview
Freescale Semiconductor1-3
Figure 1-1. MCF54455 Block Diagram
Page 37
Overview
1.3Operating Parameters
•0ºC to 70ºC and –40ºC to 85ºC junction temperature devices are available
•1.5V Core, 3.3V I/O, 1.8V/2.5V/3.3V external memory bus
1.4Packages
Depending on device, the MCF5445x family is available in the following packages:
•256-pin molded array process ball grid array (MAPBGA)
•360-pin plastic ball grid array (TEPBGA)
1.5Chip Level Features
•Version 4 ColdFire core with MMU and EMAC
•Up to 410 Dhrystone 2.1 MIPS @ 266 MHz
•16 Kbytes instruction cache and 16 Kbytes data cache
•32 Kbytes internal SRAM
•Support for booting from SPI-compatible flash, EEPROM, and FRAM devices
•Crossbar switch technology (XBS) for concurrent access to peripherals or RAM from multiple bus
masters
•16 channel DMA controller
•16-bit 133MHz DDR/mobile-DDR/DDR2 Controller
•USB 2.0 On-the-Go controller with ULPI support
•32-bit PCI controller at 66 MHz
•ATA/ ATAPI c o n troller
•2 10/100 Ethernet MACs
•Coprocessor for acceleration of the DES, 3DES, AES, MD5, and SHA-1 algorithms
•Random number generator
•Synchronous serial interface (SSI)
•4 periodic interrupt timers (PIT)
•4 32-bit timers with DMA support
•DMA supported serial peripheral interface (DSPI)
•3 UARTs
2
C bus interface
•I
1.6Module-by-Module Feature List
The following is a brief summary of the functional blocks in the MCF54455 superset device. For more
details refer to the MCF54455 ColdFire Microprocessor Reference Manual (MCF54455RM).
•Maximum 266 MHz processor core, 133 MHz internal peripheral, and 66 MHz external FlexBus
frequency
•Sixteen total general-purpose 32-bit registers data and address
•Enhanced multiply-accumulate unit (EMAC) for DSP and fast multiply operations
•Hardware divide execution unit supporting various 32-bit operations
•Implements the ColdFire Instruction Set Architecture, ISA_C
•Cryptography acceleration unit (CAU)
— DES and AES block cipher engines
— MD5, SHA-1, and HMAC hash accelerator
1.6.2On-chip Memories
•32 Kbyte dual-ported SRAM on CPU internal bus
— Accessible to non-core bus masters (e.g. FEC, DMA, USB OTG, and PCI controllers) via the
crossbar switch
•Non-blocking, independent 16 Kbyte data and instruction caches organized as 4-way set
associative with 16 bytes per cache line and 1024 cache lines, supporting copy-back and
write-through modes of operation
Overview
1.6.3Phase Locked Loop (PLL)
•16–40 MHz reference crystal
•Loss-of-lock detection
1.6.4Power Management
•Fully static operation with processor sleep and whole chip stop modes
•Very rapid response to interrupts from the low-power sleep mode (wake-up feature)
•Peripheral power management register to enable/disable clocks to most modules
•Software controlled disable of external clock input for low power consumption
1.6.5Chip Configuration Module (CCM)
•System configuration during reset
•Bus monitor, abort monitor
•Configurable output pad drive strength control
•Unique part identification and part revision numbers
•Serial boot capability
Freescale Semiconductor1-5
Page 39
Overview
— Supports SPI-compatible EEPROM, flash, and FRAM
— Configurable boot clock frequency
1.6.6Reset Controller
•Separate reset in and reset out signals
•Six sources of reset: power-on reset (POR), external, software, watchdog timer, loss of lock, JTAG
instruction
•Status flag indication of source of last reset
1.6.7System Control Module
•Access control registers
•Core watchdog timer with a 2n (where n = 8–31) clock cycle selectable timeout period
•Core fault reporting
1.6.8Crossbar Switch
•Concurrent access from different masters to different slaves
•Slave arbitration attributes configured on a slave by slave basis
•Fixed or round-robin arbitration
1.6.9Peripheral Component Interconnect (PCI) Bus
•Compatible with PCI 2.2 specification
•Supports up to 4 external PCI masters
•32-bit target and intiator operation
•33–66 MHz operation with PCI bus to internal bus divider ratios of 1:1, 1:2, 1:3, 2:3, and 1:4
1.6.10Universal Serial Bus (USB) 2.0 On-The-Go (OTG) Controller
•Support for full speed (FS) and low speed (LS) via a serial interface or on-chip FS/LS transceiver
•Optional UTMI+ Low Pin Count Interface (ULPI) on some packages to support high speed (HS)
transfers
•Uses 60 MHz reference clock based off of the system clock or from an external pin
1.6.11DDR SDRAM Controller
•Supports a glueless interface to DDR, DDR2, and mobile/low-power DDR SDRAM devices
•Support for 16-bit fixed memory port width
•16-byte critical word first burst transfer
•Up to 14 lines of row address, up to 11 column address lines (16-bit bus), 2 bits of bank address,
and two pinned-out chip selects. The maximum row bits plus column bits equals 25.
1-6Freescale Semiconductor
Page 40
•Supports up to 512 MByte of memory; minimum memory configuration of 8 MByte
•Supports page mode to maximize the data rate
•Supports sleep mode and self-refresh mode
1.6.12FlexBus (External Interface)
•Glueless connections to 16-, and 32-bit external memory devices (SRAM, flash, ROM, etc.)
•Support for independent primary and secondary wait states per chip select
•Programmable address setup and hold time with respect to chip-select assertion, per transfer
direction
•Glueless interface to SRAM devices with or without byte strobe inputs
•Programmable wait state generator
•32-bit external bidirectional data bus and 24-bit address bus
•Up to four chip selects available
•Byte/write enables (byte strobes)
•Ability to boot from external memories that are 8, 16, or 32 bits wide
Overview
1.6.13Synchronous Serial Interface (SSI)
•Supports shared (synchronous) transmit and receive sections
•Normal mode operation using frame sync
•Network mode operation allowing multiple devices to share the port with as many as 32 time slots
•Gated clock mode operation requiring no frame sync
•Programmable data interface modes such as I2S, LSB aligned, and MSB aligned
•Programmable word length up to 24 bits
•AC97 support
1.6.14ATA Controller
•Compliant with ATA-6 specification
•Supports PIO modes 0, 1, 2, 3 and 4
•Supports multiword DMA modes 0, 1 and 2
•Supports ultra DMA modes 0, 1, 2, 3 and 4 with an internal bus clock of at least 50 Mhz
•Supports ultra DMA mode 5 with an internal bus clock of at least 80 Mhz
•128 byte FIFO part of interface
•FIFO receive alarm, FIFO transmit alarm and FIFO end of transmission alarm to DMA unit
•Zero-wait cycles transfer between DMA bus and FIFO allows fast FIFO reading/writing
1.6.15Fast Ethernet Media Access Controller (FEC MAC)
•10/100 BaseT/TX capability, half duplex or full duplex
Freescale Semiconductor1-7
Page 41
Overview
•On-chip transmit and receive FIFOs
•Built-in dedicated DMA controller
•Memory-based flexible descriptor rings
•Media independent interface (MII) to external transceiver (PHY)
•Separate RMII gasket to interface with RMII-compatible PHY
1.6.16Random Number Generator (RNG)
•FIPS-140 compliant for randomness and non-determinism
1.6.17Real Time Clock
•Full clock: days, hours, minutes, seconds
•Minute countdown timer with interrupt
•Programmable daily alarm with interrupt
•Sampling timer with interrupt
•Once-per-day, once-per-hour, once-per-minute, and once-per-second interrupts
•Operation determined by reference input oscillator clock frequency and value programmed into
user-accessible registers
•Ability to wake the processor from low-power modes (wait, doze, and stop) via the RTC interrupts
1.6.18Software Watchdog Timer
•16-bit down-counter which resets the device if not serviced
1.6.19Programmable Interrupt Timers (PIT)
•Four programmable interrupt timers each with a 16-bit counter
•Configurable as a down counter or free-running counter
1.6.20DMA Timers
•Four 32-bit timers with DMA and interrupt request trigger capability
•Input capture and reference compare modes
1.6.21DMA Serial Peripheral Interface (DSPI)
•Full-duplex, three-wire synchronous transfer
•Up to five chip selects available
•Master and slave modes with programmable master bit-rates
This memory map provides two disjoint regions mapped to the FlexBus
controller to support glueless connections to external memories (e.g., flash
and SRAM), as well as a second space with one (or more) unique
chip-selects that can be used for non-cacheable, non-memory devices
(addresses 0xC000_0000 – 0xDFFF_FFFF). Additionally, this mapping is
selected because it easily maps into the ColdFire access control registers,
which provide a coarse association between memory addresses and their
attributes (e.g., cacheable, non-cacheable). For this device, one possible
configuration defines the default memory attribute as non-chacheable, and
one ACR is then used to identify cacheable addresses. For example,
ADDR[31] equaling 0 identifies the cacheable space.
1.7.1Internal Peripheral Space
The internal peripheral space contains locations for all internal registers used to program and control the
device’s functional blocks and external interfaces. Table 1-3 summarizes the various register spaces and
their base addresses. Each slot is 16 kB in size, which is not necessarily taken up entirely by the functional
blocks. Any slot not illustrated is reserved. See corresponding chapter for details on their individual
memory maps.
Table 1-3. Internal Peripheral Space Memory Map
Base AddressSlot NumberPeripheral
0xFC00_00000SCM (MPR and PACRs)
0xFC00_40001Crossbar switch
0xFC00_80002FlexBus
0xFC03_000012FEC0
0xFC03_400013FEC1
0xFC03_C00015Real-Time Clock
0xFC04_000016SCM (CWT and Core Fault Registers)
0xFC04_400017eDMA Controller
0xFC04_800018Interrupt Controller 0
0xFC04_C00019Interrupt Controller 1
0xFC05_400021Interrupt Controller IACK
2
0xFC05_800022I
0xFC05_C00023DSPI
0xFC06_000024UART0
C
0xFC06_400025UART1
0xFC06_800026UART2
0xFC07_000028DMA Timer 0
Freescale Semiconductor1-11
Page 45
Overview
Table 1-3. Internal Peripheral Space Memory Map (continued)
Base AddressSlot NumberPeripheral
0xFC07_400029DMA Timer 1
0xFC07_800030DMA Timer 2
0xFC07_C00031DMA Timer 3
0xFC08_000032PIT 0
0xFC08_400033PIT 1
0xFC08_800034PIT 2
0xFC08_C00035PIT 3
0xFC09_400037Edge Port
0xFC0A_000040CCM, Reset Controller, Power Management
0xFC0A_400041Pin Multiplexing and Control (GPIO)
0xFC0A_800042PCI Controller
0xFC0A_C00043PCI Arbiter
0xFC0B_000044USB On-the-Go
0xFC0B_400045RNG
0xFC0B_800046SDRAM Controller
0xFC0B_C00047SSI
0xFC0C_400049PLL
1.8Documentation
Documentation is available from a local Freescale distributor, a Freescale sales office, the Freescale
Literature Distribution Center, or through the Freescale world-wide web address at
http://www.freescale.com/coldfire.
1-12Freescale Semiconductor
Page 46
Chapter 2
Signal Descriptions
2.1Introduction
This chapter describes the external signals on the device. It includes an alphabetical signal listing of signals
that characterizes each signal as an input or output, defines its state at reset, and identifies whether a
pull-up resistor should be used.
NOTE
The terms assertion and negation are used to avoid confusion when dealing
with a mixture of active-low and active-high signals. The term asserted
indicates that a signal is active, independent of the voltage level. The term
negated indicates that a signal is inactive.
Active-low signals, such as SD_SRAS and TA, are indicated with an
overbar.
2.2Signal Properties Summary
The below table lists the signals grouped by functionality.
NOTE
In this table and throughout this document, a single signal within a group is
designated without square brackets (i.e., FB_AD23), while designations for
multiple signals within a group use brackets (i.e., FB_AD[23:21]) and is
meant to include all signals within the two bracketed numbers when these
numbers are separated by a colon.
NOTE
The primary functionality of a pin is not necessarily its default functionality.
Most pins that are muxed with GPIO default to their GPIO functionality. See
Table 2-1 for a list of the exceptions.
Table 2-1. Special-Case Default Signal Functionality
Pin256 MAPBGA360 TEPBGA
FB_AD[31:0]FB_AD[31:0] except when serial boot selects 0-bit
boot port size.
FB_BE/BWE
FB_CS[3:1]FB_CS[3:1]
[3:0]FB_BE/BWE[3:0]
Freescale Semiconductor2-1
Page 47
Signal Descriptions
Table 2-1. Special-Case Default Signal Functionality (continued)
Pin256 MAPBGA360 TEPBGA
FB_OE
FB_OE
FB_R/WFB_R/W
FB_TAFB_TA
FB_TSFB_TS
PCI_GNT[3:0]GPIOPCI_GNT[3:0]
PCI_REQ[3:0]GPIOPCI_REQ[3:0]
IRQ1GPIOPCI_INTA and
configured as an agent.
ATA_RESETGPIOATA reset
Tabl e 2 - 2. MCF5445 x Signal Information and Muxing
Signal NameGPIOAlternate 1Alternate 2
Reset
RESET———U
RSTOUT————
1
2
Pull-up (U)
Pull-down (D)
IEVDDL4Y18
OEVDDM15B17
Direction
MCF54450
MCF54451
256 MAPBGA
Voltag e
Domain
MCF54452
MCF54453
MCF54454
MCF54455
360 TEPBGA
Clock
EXTAL/PCI_CLK————
XTAL———U
Mode Selection
BOOTMOD[1:0]————
FlexBus
4
FB_AD[31:24]PFBADH[7:0]
FB_AD[23:16]PFBADMH[7:0]
FB_AD[15:8]PFBADML[7:0]
FB_AD[7:0]PFBADL[7:0]
FB_D[31:24]——
4
FB_D[23:16]——
4
FB_D[15:8]——
4
FB_D[7:0]——
FB_BE/BWE[3:2]PBE[3:2]FB_TSIZ[1:0]——
FB_BE/BWE[1:0]PBE[1:0]———
IEVDDM16A16
3
OEVDDL16A17
IEVDDM5, M7AB17, AB21
I/OEVDDA14, A13, D12,
I/OEVDDB11, A11, D10,
I/OEVDDB9, A9, D8, C8,
I/OEVDDB7, A7, D6, C6,
OEVDDB5, A5Y1, W2
OEVDDB4, A4W3, Y2
C12, B12, A12,
D11, C11
C10, B10, A10,
D9, C9
B8, A8, D7, C7
B6, A6, D5, C5
J2, K4, J1, K1–3,
L1, L4
L2, L3, M1–4,
N1–2
P1–2, R1–3, P4,
T1–2
T3–4, U1–3,
V1–2, W1
2-2Freescale Semiconductor
Page 48
Table 2-2. MCF5445x Signal Information and Muxing (continued)
Signal Descriptions
1
Signal NameGPIOAlternate 1Alternate 2
Pull-up (U)
FB_CLK———
—
FB_CS[3:1]PCS[3:1]———
FB_CS0—— ——
FB_OEPFBCTL3———
FB_R/WPFBCTL2———
FB_TAPFBCTL1——U
FB_TSPFBCTL0FB_ALEFB_TBST—
PCI Controller
5
PCI_AD[31:0]—FB_A[31:0]——
——FB_A[23:0]——
PCI_CBE[3:0]————
PCI_DEVSEL—— ——
PCI_FRAME—— ——
PCI_GNT3PPCI7ATA_DMACK——
PCI_GNT[2:1]PPCI[6:5]———
PCI_GNT0/
PPCI4———
PCI_EXTREQ
PCI_IDSEL————
PCI_IRDY—— ——
PCI_PAR————
PCI_PERR—— ——
PCI_REQ3PPCI3ATA_INTRQ——
PCI_REQ[2:1]PPCI[2:1]———
PCI_REQ0/
PPCI0———
PCI_EXTGNT
2
MCF54450
MCF54451
256 MAPBGA
Voltag e
Direction
Pull-down (D)
OEVDDB13J3
OEVDDC2, D4, C3W5, AA4, AB3
OEVDDC4Y4
OEVDDA2AA1
OEVDDB2AA3
IEVDDB1AB2
OEVDDA3Y3
I/OEVDD—C11, D11, A10,
I/OEVDD K14–13, J15–13,
I/OEVDD—G4, E4, D1, B1
OEVDD—F2
I/OEVDD—B2
OEVDD—B7
OEVDD—C8, C9
OEVDD—A9
IEVDD—D5
I/OEVDD—C3
I/OEVDD—C4
I/OEVDD—B4
IEVDD—C7
IEVDD—D7, C5
IEVDD—A2
Domain
H13–15, G15–13,
F14–13, E15–13,
D16, B16, C15,
B15, C14, D15,
C16, D14
MCF54452
MCF54453
MCF54454
MCF54455
360 TEPBGA
B10, J4, G2, G3,
F1, D12, C12,
B12, A11, B11,
B9, D9, D10, A8,
B8, A5, B5, A4,
A3, B3, D4, D3,
E3–E1, F3, C2,
D2, C1
—
Freescale Semiconductor2-3
Page 49
Signal Descriptions
Table 2-2. MCF5445x Signal Information and Muxing (continued)
1
Signal NameGPIOAlternate 1Alternate 2
PCI_RST
—— ——
PCI_SERR—— ——
PCI_STOP—— ——
PCI_TRDY—— ——
SDRAM Controller
SD_A[13:0]———
—
SD_BA[1:0]————
SD_CAS—— ——
SD_CKE————
SD_CLK————
SD_CLK—— ——
SD_CS[1:0]————
SD_D[31:16]————
SD_DM[3:2]————
SD_DQS[3:2]————
SD_RAS—— ——
SD_VREF————
SD_WE—— ——
External Interrupts Port
6
2
MCF54450
MCF54451
256 MAPBGA
Voltag e
Pull-up (U)
Direction
Pull-down (D)
OEVDD—B6
I/OEVDD—A6
I/OEVDD—A7
I/OEVDD—C10
OSDVDD R1, P1, N2, P2,
OSDVDDP4, T5P22, P19
OSDVDDT6L19
OSDVDDN5N22
OSDVDDT9L22
OSDVDDT8M22
OSDVDDP6, R6L20, M20
I/O SDVDDN6, T7, N7, P7,
OSDVDDP9, N12H21, E21
OSDVDDR9, N11H22, E22
OSDVDDP5N21
ISDVDDM8M21
OSDVDDR5N20
Domain
R2, T2, M4, N3,
P3, R3, T3, T4,
R4, N4
R7, R8, P8, N8,
N9, T10, R10,
P10, N10, T11,
R11, P11
MCF54452
MCF54453
MCF54454
MCF54455
360 TEPBGA
V22, U20–22,
T19–22, R20–22,
N19, P20–21
L21, K22, K21,
K20, J20, J19,
J21, J22, H20,
G22, G21, G20,
G19, F22, F21,
F20
IRQ7PIRQ7———
IRQ4PIRQ4—SSI_CLKIN—
IRQ3PIRQ3———
IRQ1PIRQ1PCI_INTA——
IEVDDL1ABB13
IEVDDL2ABB13
IEVDDL3AB14
IEVDDF15C6
FEC0
FEC0_MDCPFECI2C3———
FEC0_MDIOPFECI2C2———
OEVDDF3AB8
I/OEVDDF2Y7
2-4Freescale Semiconductor
Page 50
Table 2-2. MCF5445x Signal Information and Muxing (continued)
Signal Descriptions
1
Signal NameGPIOAlternate 1Alternate 2
Pull-up (U)
FEC0_COLPFEC0H4—ULPI_DATA7—
FEC0_CRSPFEC0H0—ULPI_DATA6—
FEC0_RXCLKPFEC0H3—ULPI_DATA1—
FEC0_RXDVPFEC0H2FEC0_RMII_
——
CRS_DV
FEC0_RXD[3:2]PFEC0L[3:2]—ULPI_DATA[5:4]—
FEC0_RXD1PFEC0L1FEC0_RMII_RXD1——
FEC0_RXD0PFEC0H1FEC0_RMII_RXD0——
FEC0_RXERPFEC0L0FEC0_RMII_RXER——
FEC0_TXCLKPFEC0H7FEC0_RMII_
——
REF_CLK
FEC0_TXD[3:2]PFEC0L[7:6]—ULPI_DATA[3:2]—
FEC0_TXD1PFEC0L5FEC0_RMII_TXD1——
FEC0_TXD0PFEC0H5FEC0_RMII_TXD0——
FEC0_TXENPFEC0H6FEC0_RMII_TXEN——
FEC0_TXERPFEC0L4—ULPI_DATA0—
2
MCF54450
MCF54451
256 MAPBGA
Voltag e
Direction
Pull-down (D)
IEVDDE1AB7
IEVDDF1AA7
IEVDDG1AA8
IEVDDG2Y8
IEVDDG3, G4AB9, Y9
IEVDDH1W9
IEVDDH2AB10
IEVDDH3AA10
IEVDDH4Y10
OEVDDJ1, J2W10, AB11
OEVDDJ3AA11
OEVDDJ4Y11
OEVDDK1W11
OEVDDK2AB12
Domain
360 TEPBGA
MCF54452
MCF54453
MCF54454
MCF54455
FEC1
FEC1_MDCPFECI2C5—ATA _D I O R—
FEC1_MDIOPFECI2C4—ATA _ D IO W—
FEC1_COLPFEC1H4—ATA _ DATA 7—
FEC1_CRSPFEC1H0—ATA _ D ATA6—
FEC1_RXCLKPFEC1H3—ATA _ DATA 5—
FEC1_RXDVPFEC1H2FEC1_RMII_
ATA _DATA 1 5—
CRS_DV
FEC1_RXD[3:2]PFEC1L[3:2]—ATA_DATA[4:3]—
FEC1_RXD1PFEC1L1FEC1_RMII_RXD1ATA _ DATA 1 4—
FEC1_RXD0PFEC1H1FEC1_RMII_RXD0ATA _ DATA 1 3—
FEC1_RXERPFEC1L0FEC1_RMII_RXERATA _DATA 1 2—
FEC1_TXCLKPFEC1H7FEC1_RMII_
ATA _DATA 1 1—
REF_CLK
FEC1_TXD[3:2]PFEC1L[7:6]—ATA_DATA[2:1]—
OEVDD—W20
I/OEVDD—Y22
IEVDD—AB18
IEVDD—AA18
IEVDD—W14
IEVDD—AB15
IEVDD—AA15, Y15
IEVDD—AA17
IEVDD—Y17
IEVDD—W17
IEVDD—AB19
OEVDD—Y19, W18
Freescale Semiconductor2-5
Page 51
Signal Descriptions
Table 2-2. MCF5445x Signal Information and Muxing (continued)
1
Signal NameGPIOAlternate 1Alternate 2
FEC1_TXD1PFEC1L5FEC1_RMII_TXD1ATA _ DATA 1 0—
FEC1_TXD0PFEC1H5FEC1_RMII_TXD0ATA _ DATA 9—
FEC1_TXENPFEC1H6FEC1_RMII_TXENATA _ DATA 8—
FEC1_TXERPFEC1L4—ATA _ DATA 0—
USB On-the-Go
USB_DM————
USB_DP————
USB_VBUS_ENPUSB1USB_PULLUPULPI_NXT—
USB_VBUS_OCPUSB0—ULPI_STPUD
ATA
ATA _BU FF E R _E NPATA H 5———
ATA _ CS [1:0]PATAH[4:3]———
ATA_DA[2:0]PATAH[2:0]———
ATA_RESETPATA L 2———
ATA_DMARQPATA L1———
ATA _I OR DYPATA L 0———
2
MCF54450
MCF54451
256 MAPBGA
Voltag e
Pull-up (U)
Direction
Pull-down (D)
OEVDD—AA19
OEVDD—Y20
OEVDD—AA21
OEVDD—AA22
OUSB
OUSB
OUSB
7
IUSB
OEVDD—Y13
OEVDD—W21, W22
OEVDD—V19–21
OEVDD—W13
IEVDD—AA14
IEVDD—Y14
Domain
F16A14
VDD
E16A15
VDD
E5AA2
VDD
B3V4
VDD
MCF54452
MCF54453
MCF54454
MCF54455
360 TEPBGA
Real Time Clock
EXTAL32K————
XTAL32K————
IEVDDJ16A13
OEVDDH16A12
SSI
SSI_MCLKPSSI4———
SSI_BCLKPSSI3U1CTS——
SSI_FSPSSI2U1RTS——
SSI_RXDPSSI1U1RXD—UD
SSI_TXDPSSI0U1TXD—UD
OEVDDT13D20
I/OEVDDR13E19
I/OEVDDP12E20
IEVDDT12D21
OEVDDR12D22
I2C
I2C_SCLPFECI2C1—U2TXDU
I/OEVDDK3AA12
2-6Freescale Semiconductor
Page 52
Table 2-2. MCF5445x Signal Information and Muxing (continued)
Signal Descriptions
1
Signal NameGPIOAlternate 1Alternate 2
I2C_SDAPFECI2C0—U2RXDU
DMA
DACK1PDMA3—ULPI_DIR—
DREQ1PDMA2—USB_CLKINU
DACK0PDMA1DSPI_PCS3——
DREQ0PDMA0——U
DSPI
DSPI_PCS5/PCSSPDSPI6———
DSPI_PCS2PDSPI5———
DSPI_PCS1PDSPI4SBF_CS——
DSPI_PCS0/SSPDSPI3——U
DSPI_SCKPDSPI2SBF_CK——
DSPI_SINPDSPI1SBF_DI—
DSPI_SOUTPDSPI0SBF_DO——
2
MCF54450
MCF54451
256 MAPBGA
Voltag e
Pull-up (U)
8
Direction
Pull-down (D)
I/OEVDDK4Y12
O
I
O
I
OEVDDN14D18
OEVDDL13A19
OEVDDP14B20
I/OEVDDR16D17
I/OEVDDR15A20
IEVDDP15B19
OEVDDN13C20
Domain
EVDDM14C17
EVDDP16C18
EVDDN15A18
EVDDN16B18
MCF54452
MCF54453
MCF54454
MCF54455
360 TEPBGA
UARTs
U1CTSPUART7———
U1RTSPUART6———
U1RXDPUART5———
U1TXDPUART4———
U0CTSPUART3———
U0RTSPUART2———
U0RXDPUART1———
U0TXDPUART0———
Note: The UART1 and UART 2 signals are multiplexed on the DMA timers and I2C pins.
DMA Timers
DT3INPTIMER3DT3OUTU2RXD—
DT2INPTIMER2DT2OUTU2TXD—
DT1INPTIMER1DT1OUTU2CTS—
DT0INPTIMER0DT0OUTU2RTS—
IEVDD—V3
OEVDD—U4
IEVDD—P3
OEVDD—N3
IEVDDM3Y16
OEVDDM2AA16
IEVDDN1AB16
OEVDDM1W15
IEVDDC13H2
IEVDDD13H1
IEVDDB14H3
IEVDDA15G1
Freescale Semiconductor2-7
Page 53
Signal Descriptions
Table 2-2. MCF5445x Signal Information and Muxing (continued)
1
Signal NameGPIOAlternate 1Alternate 2
BDM/JTAG
9
PSTDDATA[7:0]————
JTAG_EN———D
PSTCLK—TCLK——
DSI—TDI—U
DSO—TDO——
BKPT—TMS—U
DSCLK—TRST—U
Test
TEST———D
PLLTEST————
Power Supplies
2
MCF54450
MCF54451
256 MAPBGA
Voltag e
Pull-up (U)
Direction
Pull-down (D)
OEVDDE2, D1, F4, E3,
IEVDDM11C21
IEVDDP13C22
IEVDDT15C19
OEVDDT14A21
IEVDDR14B21
IEVDDM13B22
IEVDDM6AB20
OEVDDK16D15
Domain
D2, C1, E4, D3
MCF54452
MCF54453
MCF54454
MCF54455
360 TEPBGA
AA6, AB6, AB5,
W6, Y6, AA5,
AB4, Y5
IVDD——————
EVDD——————
SD_VDD——————
VDD_OSC——————
VDD_A_PLL——————
VDD_RTC——————
VSS——————
VSS_OSC——————
1
Pull-ups are generally only enabled on pins with their primary function, except as noted.
2
Refers to pin’s primary function.
E6–12, F5, F12D6, D8, D14, F4,
G5, G12, H5, H12,
J5, J12, K5, K12,
L5–6, L12
L7–11, M9, M10F19, H19, K19,
L14B16
K15C14
M12C13
A1, A16, F6–11,
G6–11, H6–11,
J6–11, K6–11, T1,
T16
L15C16
H4, N4, R4, W4,
W7, W8, W12,
W16, W19
D13, D19, G8,
G11, G14, G16,
J7, J16, L7, L16,
N16, P7, R16, T8,
T12, T14, T16
M19, R19, U19
A1, A22, B14, G7,
G9–10, G12–13,
G15, H7, H16,
J9–14, K7, K9–14,
K16, L9–14, M7,
M9–M14, M16,
N9–14, P9–14,
P16, R7, T7,
T9–11, T13, T15,
AB1, AB22
2-8Freescale Semiconductor
Page 54
Signal Descriptions
3
Enabled only in oscillator bypass mode (internal crystal oscillator is disabled).
4
Serial boot must select 0-bit boot port size to enable the GPIO mode on these pins.
5
When the PCI is enabled, all PCI bus pins come up configured as such. This includes the PCI_GNT and PCI_REQ lines, which have
GPIO. The IRQ1/PCI_INTA signal is a special case. It comes up as PCI_INTA when booting as a PCI agent and as GPIO when booting
as a PCI host.
For the 360 TEPBGA, booting with PCI disabled results in all dedicated PCI pins being safe-stated. The PCI_GNT
and IRQ1/PCI_INTA
6
GPIO functionality is determined by the edge port module. The pin multiplexing and control module is only responsible for assigning
the alternate functions.
7
Depends on programmed polarity of the USB_VBUS_OC signal.
8
Pull-up when the serial boot facility (SBF) controls the pin
9
If JTAG_EN is asserted, these pins default to Alternate 1 (JTAG) functionality. The pin multiplexing and control module is not
responsible for assigning these pins.
come up as GPIO.
and PCI_REQ lines
NOTE
2.3Signal Primary Functions
2.3.1Reset Signals
Table 2-3 describes signals used to reset the chip or to indicate a reset.
Table 2-3. Reset Signals
Signal NameAbbreviationFunctionI/O
Reset InRESETPrimary reset input to the device. Asserting RESET resets the core and
peripherals after four FB_CLK cycles. Asserting RESET
RSTOUT to be asserted.
Reset OutRSTOUTReset output (RSTOUT) is an indicator that the chip is in reset.
RSTOUT is asserted at least 512 internal system bus clock cycles (256
FB_CLK cycles) in response to any internal or external reset. (The
exact time depends on how long it takes for the PLL to lock and/or the
serial boot sequence to complete.)
also causes
I
O
Freescale Semiconductor2-9
Page 55
Signal Descriptions
2.3.2PLL and Clock Signals
Table 2-4 describes signals that are used to support the on-chip clock generation circuitry.
Table 2-4. PLL and Clock Signals
Signal NameAbbreviationFunctionI/O
External Clock InEXTALAlways driven by an external clock input except when used as a
connection to the external crystal if the internal oscillator circuit is
used. Clock source may be configured during reset. See Chapter 11,
“Chip Configuration Module (CCM),” for more details.
Note: This signal is also PCI_CLK (33 or 66 MHz) when running from
an external oscillator with PCI enabled.
CrystalXTALUsed as a connection to the external crystal when the internal
oscillator circuit is used to drive the crystal.
RTC External Clock In EXTAL32KCrystal input clock for the real-time clock module. I
RTC CrystalXTAL32KOscillator output to EXTAL RTC crystal.O
FlexBus Clock OutFB_CLKReflects one-half of the internal bus clock (or one-fourth the
core/system clock). (f
USB Clock InUSB_CLKIN This pin allows the user to drive the reference clock to the USB module
as an alternate method of generating the USB reference clock during
FS/LS operation. This pin should be driven only with a 60 MHz clock.
When using the ULPI USB interface, this pin is the ULPI input clock.
SSI Clock InSSI_CLKINThis pin allows the user to drive a specific clock frequency to the SSI
module.
sys/4
)
2.3.3Mode Selection
Table 2-5. Mode Selection Signals
I
O
O
I
I
Signal NameAbbreviationFunctionI/O
Boot modeBOOTMOD[1:0] Indicates the device’s boot mode and chip configuration at reset. See
Chapter 11, “Chip Configuration Module (CCM),” for the signal
encodings.
2-10Freescale Semiconductor
I
Page 56
2.3.4FlexBus Signals
Table 2-6 describes signals that are used for performing transactions on the external bus.
Tabl e 2 - 6. Flex B u s Signals
Signal NameAbbreviationFunctionI/O
Signal Descriptions
Address/Data BusFB_AD[31:0]Defines address and data of external byte, word, and longword
accesses. This three-state, bi-directional bus is the general-purpose
address/data path to external SRAM and flash devices.
Byte EnablesFB_BE/BWE
Output EnableFB_OEIndicates when an external device can drive data during external read
Transfer AcknowledgeFB_TAIndicates external data transfer is complete. During a read cycle, when
Read/WriteFB_R/WIndicates direction of the data transfer on the bus for SRAM (R/W)
[3:0] Defines flow of data on data bus. During peripheral accesses, these
output signals indicate that data is to be latched or driven onto a byte
of the data bus when driven low. The BE/BWE
asserted only to the memory bytes used during a read or write access.
BE/BWE0 controls access to the most significant byte lane of data,
and BE/BWE
data.
For SRAM or Flash devices, the BE/BWE
connected to individual byte strobe signals.
The BE/BWE
peripherals, but not to on-chip SRAM or cache.
cycles.
the processor recognizes TA
the bus cycle. During a write cycle, when the processor recognizes TA,
the bus cycle is terminated.
accesses. A logic 1 indicates a read from a slave device and a logic 0
indicates a write to a slave device.
3 controls access to the least significant byte lane of
n signals are asserted during accesses to on-chip
, it latches the data and then terminates
[3:0] signals are
n outputs should be
I/O
O
O
I
O
Transfer SizeFB_TSIZ[1:0]Indicates bus width (8, 16, or 32 bits) for each chip select. The initial
width for the bootstrap program chip select is determined by the initial
state of TSIZ[1:0].
Transfer BurstFB_TBST
Transfer StartFB_TSBus control output signal indicating the start of a transfer.O
Address Latch EnableFB_ALEIndicates device has begun a bus transaction and the address and
Chip SelectsFB_CS
Freescale Semiconductor2-11
[3:0]Select external devices for external bus transactions.O
Indicates external bus access is a burst access.O
attributes are valid. FB_ALE is asserted for one bus clock cycle. In
multiplexed mode, ALE is used externally as an address latch enable
to capture the address phase of the bus transfer.
O
O
Page 57
Signal Descriptions
2.3.5SDRAM Controller Signals
Table 2-7 describes signals used for SDRAM accesses.
Table 2-7. SDRAM Controller Signals
Signal NameAbbreviationFunctionI/O
SDRAM Address BusSD_A[13:0]Address bus used for multiplexed row and column addresses during
SDRAM bus cycles.
SDRAM Data BusSD_D[31:16]Bidirectional, non-multiplexed data bus for SDRAM accesses.I/O
SDRAM Bank AddressSD_BA[1:0]Selects one of the four SDRAM row banks.O
DDR SDRAM Data Strobes SD_DQS[3:2]Indicates when valid data is on data bus.I/O
SDRAM Write Data Byte
Mask
SDRAM Column Address
Strobe
SDRAM Row Address
Strobe
SDRAM Write EnableSD_WE
SD_DQM[3:2] Used to determine which byte lanes of data bus should be latched
SD_CAS
SD_RASSDRAM row address strobe.O
Inverted output clock for DDR SDRAM.O
during a write cycle.
The SD_DQMn should be connected to individual SDRAM DQM
signals. Most SDRAMs associate DQM3 with the MSB, in which case
SD_DQM3 should be connected to the SDRAM's DQM3 input.
SDRAM column address strobe.O
Indicates direction of data transfer on bus for SDRAM accesses. A
logic 1 indicates a read from a slave device and a logic 0 indicates a
write to a slave device.
O
O
O
SDRAM Voltage Reference SD_VREFReference voltage for differential I/O pad cells. Should be half the
voltage of the memory used in the system. For example, 2.5 V DDR
results in an SD_VREF of 1.25 V. See the device’s datasheet for the
voltages and tolerances for the various memory modes.
2-12Freescale Semiconductor
I
Page 58
Signal Descriptions
2.3.6PCI Controller Signals
Table 2-8 describes the external interrupt signals used on the external PCI bus.
Table 2-8. PCI Controller Signals
Signal NameAbbreviationFunctionI/O
PCI Address/Data Bus PCI_AD[31:0] Multiplexed address/data bus.I/O
PCI Command/Byte
Enables
PCI Device SelectPCI_DEVSEL
PCI FramePCI_FRAMEAsserted by a PCI initiator to indicate the beginning of a transaction.
PCI External Bus Grant PCI_GNT
PCI External Bus
Grant/Request
PCI Initialization Device
Select
PCI Initiator ReadyPCI_IRDY
PCI ParityPCI_PARIndicates the parity of the data on the PCI_AD[31:0] and
PCI_CBE[3:0] Multiplexed PCI command and byte enables. The PCI command is
present during address phase; the byte enables are present during
data phase.
Indicates processor has recognized itself as the target of a PCI
transaction from address presented on the PCI bus.
It is negated when initiator is ready to complete final data phase.
[3:1] Asserted to an external master to give it control of PCI bus. If internal
PCI arbiter is enabled, it asserts one of the PCI_GNT[3:1] signals to
grant ownership of PCI bus to external master. When PCI arbiter is
disabled, PCI_GNT
PCI_GNT0/
PCI_EXTREQ
PCI_IDSELAsserted during a PCI type-0 configuration cycle to address the PCI
Asserted to external master device 0 to give it control of the PCI bus.
When the PCI arbiter is disabled, the signal operates as the
PCI_EXTREQ output, which is asserted when the processor needs to
initiate a PCI transaction.
configuration header.
Indicates that PCI initiator is ready to transfer data. During a write
operation, assertion indicates the master is driving valid data on bus.
During a read operation assertion indicates that master is ready to
accept data.
PCI_CBE
[3:0] signals.
[3:1] are driven high and should be ignored.
I/O
O
I/O
O
O
O
I/O
I/O
PCI Parity ErrorPCI_PERRAsserted when data phase parity error is detected if enabled.I/O
PCI External Bus
Request
PCI External Bus
Request/Grant
PCI ResetPCI_RSTAsserted by processor to reset PCI bus. It is asserted when processor
PCI System ErrorPCI_SERR
PCI StopPCI_STOPIndicates that the currently addressed target wishes to stop the
PCI Target ReadyPCI_TRDYIndicates currently addressed target is ready to complete the current
PCI Interrupt APCI_INTA
Freescale Semiconductor2-13
PCI_REQ[3:1] Asserted by an external PCI master when it requires access to the PCI
bus.
/
PCI_REQ0
PCI_EXTGNT
Asserted by external PCI master device 0 when it requires access to
the PCI bus. When internal PCI arbiter is disabled, this signal is used
as a grant input for PCI bus, which is driven by an external PCI arbiter.
is reset and must be negated to enable usage on PCI bus.
Indicates detection of an address-phase-parity error.I/O
current transaction.
data phase.
This output is the PCI interrupt A signal.O
I
I
O
I/O
I/O
Page 59
Signal Descriptions
2.3.7Serial Boot Facility Signals
Table 2-9. SBF Signals
Signal NameAbbreviationFunctionI/O
SBF Chip SelectSBF_CS
SBF ClockSBF_CK25 MHz clock source for external SPI memory.O
SBF Data InSBF_DIData being driven by SPI memory.I
SBF Data OutSBF_DOData out to SPI memory. SBF uses this output solely for the purpose
DMA AcknowledgeDACK[1:0]Asserted by processor to indicate DMA request has been recognized.O
[1:0]Asserted by an external device to request a DMA transfer.I
O
2.3.10Fast Ethernet Controller (FEC0 and FEC1) Signals
The following signals are used by the two Ethernet modules.
Table 2-12. Ethernet Module (FEC) Signals
Signal NameAbbreviationFunctionI/O
Management DataFECn_MDIOTransfers control information between external PHY and the
media-access controller. Data is synchronous to FECn_MDC. Applies
to MII mode operation. This signal is an input after reset. When the
FEC is operated in 10Mbps 7-wire interface mode, this signal should
be connected to VSS.
Management Data
Clock
CollisionFECn_COLAsserted upon collision detection and remains asser ted while collision
Carrier Receive Sense FECn_CRSWhen asserted, indicates transmit or receive medium is not idle.
2-14Freescale Semiconductor
FECn_MDCIn Ethernet mode, FECn_MDC is an output clock that provides a
timing reference to PHY for data transfers on FECn_MDIO signal.
Applies to MII mode operation.
persists. This signal is not defined for full-duplex mode.
Transmit ClockFECn_TXCLKInput clock providing a timing reference for FECn_TXEN,
FECn_TXD[3:0] and FECn_TXER
Transmit EnableFECn_TXENIndicates when valid nibbles are present on MII. This signal is
asserted with the first nibble of a preamble and is negated before the
first FECn_TXCLK following the final nibble of the frame.
Transmit Data 0FECn_TXD0FECn_TXD0 is the serial output Ethernet data and is valid only during
the assertion of FECn_TXEN. This signal is used for 10-Mbps
Ethernet data. Also used for MII mode data in conjunction with
FECn_TXD[3:1].
Transmit Data 1–3FECn_TXD[3:1] In Ethernet mode, these pins contain serial output Ethernet data and
are valid only during assertion of FECn_TXEN in MII mode.
Transmit ErrorFECn_TXERIn Ethernet mode, when FECn_TXER is asserted for one or more
clock cycles while FECn_TXEN is also asserted, the PHY sends one
or more illegal symbols. FECn_TXER has no effect at 10 Mbps or
when FECn_TXEN is negated. Applies to MII mode operation.
Receive ClockFECn_RXCLKProvides a timing reference for FECn_RXDV, FECn_RXD[3:0], and
FECn_RXER.
Receive Data ValidFECn_RXDVAsserting the FECn_RXDV input indicates that the PHY has valid
nibbles present on the MII. FECn_RXDV should remain asserted from
the first recovered nibble of the frame through to the last. Assertion of
FECn_RXDV must start no later than the SFD and exclude any EOF.
Receive Data 0FECn_RXD0FECn_RXD0 is the Ethernet input data transferred from the PHY to
the media-access controller when FECn_RXDV is asserted. This
signal is used for 10-Mbps Ethernet data. This signal is also used for
MII mode Ethernet data in conjunction with FECn_RXD[3:1].
I
O
O
O
O
I
I
I
Receive Data 1–3FECn_RXD[3:1] In Ethernet mode, these pins contain Ethernet input data transferred
from the PHY to the media access controller when FECn
asserted in MII mode operation.
Receive ErrorFECn_RXERIn Ethernet mode, when asserted with FECn_RXDV, FECn_RXER
indicates that the PHY has detected an error in current frame. When
FECn_RXDV is not asserted FECn_RXER has no effect. Applies to
MII mode operation.
_RXDV is
2.3.11I2C I/O Signals
Table 2-13. I2C I/O Signals
Signal NameAbbreviationFunctionI/O
Serial ClockI2C_SCLOpen-drain clock signal for I
when the bus is in master mode, or it becomes the clock input when
2
C is in slave mode.
the I
Serial DataI2C_SDAOpen-drain signal serving as the data input/output for the I2C
interface.
2
C interface. It is driven by the I2C module
I
I
I/O
I/O
Freescale Semiconductor2-15
Page 61
Signal Descriptions
2.3.12ATA Controller Signals
Table 2-14. ATA Controller Signals
Signal NameAbbreviationFunctionI/O
ATA Data BusATA_DATA[15:0]The bi-directional, three-state ATA data bus.I/O
ATA Buffer EnableATA_BUFFER_EN This output signal is the ATA transceiver direction-control signal.O
ATA Chip SelectsATA_CS
ATA AddressATA_DA[2:0]These output signals are ATA bus address group.O
ATA ResetATA_RESETThis output signal is ATA reset signal. When asserted, ATA bus is in
ATA DMA RequestATA_DMARQThis input signal is the ATA bus device DMA request. It is asserted by
ATA DMA Acknowledge ATA_DMACK
ATA I/O Ready InATA_IORDYThis input is the ATA IORDY line. It has three functions:
ATA DIO ReadATA_DIOR
ATA DIO WriteATA_DIOW
[1:0]These output signals ATA bus chip selects.O
reset state. When negated, no reset. ATA bus is in reset when the
appropriate bit in the control register is cleared. After system reset,
ATA bus is in reset.
the device if it wants to transfer data using multiword DMA or ultra
DMA mode
This output signal is the ATA bus host DMA acknowledge. It is
asserted by the host when it grants the DMA request.
• IORDY—active low wait during PIO cycles,
• DDMARDY—active low device ready during ultra DMA out
transfers
• DSTROBE—device strobe during ultra DMA in transfers
This output signal corresponds to ATA signal DIOR. During PIO and
multiword DMA transfers, its function is read strobe. During ultra DMA
IN burst, its function is HDMARDY. During ultra DMA OUT burst, its
function is host strobe (HSTROBE).
This output signal corresponds to ATA signal DIOW. During PIO and
multiword DMA transfers, its function is write strobe. During ultra DMA
burst, its function is STOP, signalling when the host wants to terminate
an ultra DMA transfer.
O
I
O
I
O
O
ATA Interrupt RequestATA_INTRQThis input signal is the ATA bus interrupt request. It is asserted by the
device when it wants to interrupt.
2-16Freescale Semiconductor
I
Page 62
2.3.13DMA Serial Peripheral Interface (DSPI) Signals
Table 2-15. DMA Serial Peripheral Interface (DSPI) Signals
Signal NameAbbreviationFunctionI/O
Signal Descriptions
DSPI Synchronous
Serial Output
DSPI Synchronous
Serial Data Input
DSPI Serial ClockDSPI_SCKProvides the serial clock from the DSPI. In master mode, the
DSPI_SOUTProvides the serial data from the DSPI and can be programmed to be
driven on the rising or falling edge of DSPI_SCK. Each byte is sent
msb first.
DSPI_SINProvides the serial data to the DSPI and can be programmed to be
sampled on the rising or falling edge of DSPI_SCK. Each byte is
written to RAM lsb first.
processor generates DSPI_SCK, while in slave mode, DSPI_SCK is
an input from an external bus master.
DSPI_PCS5/
DSPI_PCSS
DSPI_PCS[3:1] Provide DSPI peripheral chip selects that can be programmed to be
DSPI_PCS0/
DSPI_SS
When in master mode and the DSPI_MCR[PCSSE] bit cleared,
DSPI_PCS5 is a peripheral chip select output that selects which slave
device the current transmission is intended.
DSPI_PCSS
external demultiplexer for deglitching of the DSPI_PCSn signals.
When in master mode and the DSPI_MCR[PCSSE] bit is set,
DSPI_PCSS
DSPI_PCS[3:0] signals, which prevents glitches from occurring.
In slave mode, this signal is not used.
active high or low.
In master mode, DSPI_PCS0 is a peripheral chip select output that
selects which slave device the current transmission is intended.
In slave mode, the SS signal is a slave select input that allows an SPI
master to select the processor as the target for transmission.
provides a strobe signal that can be used with an
provides the appropriate timing for the decoding of the
O
I
I/O
O
O
I/O
2.3.14Synchronous Serial Interface (SSI) Signals
Table 2-16. SSI Module Signals
Signal NameAbbreviationFunctionI/O
Serial Bit ClockSSI_BCLKUsed by the receive and transmit blocks. In gated clock mode,
SSI_BCLK is only valid during transmission of data, otherwise it is
pulled to an inactive state.
Serial Master ClockSSI_MCLKThis clock signal is output from the device when it is the master. When
Serial Frame SyncSSI_FSUsed by transmitter/receiver to synchronize the transfer of data. In
Serial Receive DataSSI_RXDReceives data into the receive data shift registerI
Serial Transmit DataSSI_TXDTransmits data from the serial transmit shift register. O
Freescale Semiconductor2-17
2
S master mode, this signal is referred to as the oversampling
in I
clock. The frequency of SSI_MCLK is a multiple of the frame clock.
gated clock mode, this signal is not used. When configured as an
input, the external device should drive SSI_FS during the rising edge
of SSI_BCLK.
I/O
O
I/O
Page 63
Signal Descriptions
2.3.15Universal Serial Bus (USB) Signals
Table 2-17. USB Module Signals
Signal NameAbbreviationFunctionI/O
USB D-USB_DMD- output of the dual-speed transceiver for the On-the-Go module.O
USB D+USB_DPD+ output of the dual-speed transceiver for the On-the-Go module.O
USB VBUS EnableUSB_VBUS_ENEnables the off-chip VBUS charge pump when USB OTG module is
configured as a host.
USB VBUS over-current USB_VBUS_OCIndicates to the processor that a short has occurred on USB data
bus.
USB External Pull-up
Enable
ULPI Data BusULPI_DATA[7:0]These bi-directional signals are ULPI data bus. Synchronous to
ULPI Next DataULPI_NXTThis input is the ULPI next data. Synchronous to USB_CLKIN.I
ULPI Stop DataULPI_STPThis output is the ULPI stop data. Synchronous to USB_CLKIN.O
ULPI Data Bus
Direction
USB_PULLUPEither use this pullup enable output signal, or turn it off in the CCM’s
MISCCR[USBPUE] bit. If internal pullup (and not this output signal)
is used, the internal pullup automatically switches impedances
based on whether USB is transmitting or receiving.
USB_CLKIN.
ULPI_DIRThis input is the ULPI data bus direction. Synchronous to
USB_CLKIN.
O
I
O
I/O
I
2.3.16UART Module Signals
Table 2-18 describes the signals of the three UART modules, where n equals 0 – 2. Baud-rate clock inputs
are not supported.
Table 2-18. UART Module Signals
Signal NameAbbreviationFunctionI/O
Transmit Serial Data
Output
Receive Serial Data
Input
Clear-to-SendU
Request-to-SendUnRTSAutomatic request-to-send outputs from UART modules. They may
2-18Freescale Semiconductor
UnTXDData is shifted out lsb first at the falling edge of the serial clock source.
Output is held high when transmitter is disabled, idle, or in local
loopback mode.
UnRXDData is sampled Isb first at the serial clock source’s rising edge. When
the UART clock is stopped for power-down mode, any transition on this
pin restarts it.
nCTSIndicates UART modules can begin data transmissionI
also be asserted and negated as a function of the received FIFO level.
O
I
O
Page 64
2.3.17DMA Timer Signals
Table 2-19 describes the signals of the four DMA timer modules, where n equals 0 – 3.
Table 2-19. DMA Timer Signals
Signal NameAbbreviationFunctionI/O
Signal Descriptions
DMA Timer n InputDTnINCan be programmed to cause events in the respective timer. It can
clock the event counter or provide a trigger to the timer value capture
logic.
DMA Timer n OutputDTnOUTOutput from respective timer.O
I
2.3.18Debug Support Signals
These signals are used as the interface to the on-chip JTAG controller and the BDM logic. Pin functionality
between JTAG and BDM is dependent upon the JTAG_EN pin.
Table 2-20. Debug Support Signals
Signal NameAbbreviationFunctionI/O
JTAG EnableJTAG_ENEnables JTAG (asserted) or BDM (negated) operation.I
JTAG Signals
Test ResetTRST
Test ClockTCLKUsed to synchronize the JTAG logic.I
Test Mode SelectTMSUsed to sequence the JTAG state machine. TMS is sampled on the
Test Data InputTDISerial input for test instructions and data. TDI is sampled on the rising
Active-low signal used to initialize the JTAG logic asynchronously.I
I
rising edge of TCLK.
I
edge of TCLK.
Test Data OutputTDOSerial output for test instructions and data. TDO is three-stateable and
actively driven in the shift-IR and shift-DR controller states. TDO
changes on the falling edge of TCLK.
BDM Signals
Development Serial
Clock
BreakpointBKPT
Development Serial
Input
Development Serial
Output
Processor Status Clock PSTCLKUsed by the development system to know when to sample DDATA and
Processor Status/
Debug Data
Freescale Semiconductor2-19
DSCLKClocks the serial communication port to the BDM module during
packet transfers.
Used to request a manual breakpoint.I
DSIInternally-synchronized signal provides data input for the serial
communication port to the BDM module.
DSOInternally-registered signal provides serial output communication for
BDM module responses.
PST signals.
PSTDDATA[7:0] Display captured processor status and captured address/data values.
These outputs change on the negative edge of PSTCLK.
O
I
I
O
O
O
Page 65
Signal Descriptions
Table 2-21. Processor Status
PST[3:0]Processor Status
0000Continue execution
0001Begin execution of one instruction
0010Reserved
0011Entry into user mode
0100Begin execution of PULSE and WDDATA instructions
0101Begin execution of taken branch
0110Reserved
0111Begin execution of RTE instruction
1000Begin one-byte transfer on PSTDDATA
1001Begin two-byte transfer on PSTDDATA
1010Begin three-byte transfer on PSTDDATA
1011Begin four-byte transfer on PSTDDATA
1100Exception processing
1101Reserved
1110Processor is stopped
1111Processor is halted
2.3.19Test Signals
Table 2-22 describes test signals reserved for factory testing.
Table 2-22. Test Signals
Signal NameAbbreviationFunctionI/O
TestTESTReserved for factory testing only and in normal modes of operation
should be connected to VSS to prevent unintentional activation of test
functions.
PLL TestPLL_TESTReserved for factory testing only and should be treated as a
no-connect (NC).
I
O
2-20Freescale Semiconductor
Page 66
Signal Descriptions
2.3.20Power and Ground Pins
The pins described in Table 2-23 provide system power and ground to the device. Multiple pins are
provided for adequate current capability. All power supply pins must have adequate bypass capacitance
for high-frequency noise suppression.
Table 2-23. Power and Ground Pins
Signal NameAbbreviationFunctionI/O
PLL Analog SupplyVDD_A_PLLDedicated power supply signal to isolate the sensitive PLL analog
(VCO) circuitry from the normal levels of noise present on the digital
power supply.
OscillatorVDD_OSC
VSS_OSC
Positive I/O SupplyEVDDThese pins supply positive power to the I/O pads
Positive Core SupplyIVDDThese pins supply positive power to the core logic.—
SDRAMC SupplySD_VDDThese pins supply positive power to the SDRAM controller.—
USB SupplyUSB_VDDThese pins supply positive power to the USB controller.—
Real-time clock Supply RTC_VDDThese pins supply positive power to the RTC module.—
GroundVSSThese pins are the negative supply (ground) for the device.—
Dedicated power supply signals to isolate the sensitive oscillator
circuitry from the normal levels of noise present on the digital power
supply.
.—
—
—
2.4External Boot Mode
After reset the address bus, data bus, FlexBus control signals, and SDRAM control signals default to their
bus functionalities. All other signals default to GPIO inputs (if applicable).
Freescale Semiconductor2-21
Page 67
Freescale Semiconductor-1
Page 68
Chapter 3
ColdFire Core
3.1Introduction
This section describes the organization of the Version 4 (V4) ColdFire® processor core and an overview
of the program-visible registers. For detailed information on instructions, see the ISA_C definition in the
ColdFire Family Programmer’s Reference Manual. The V4 ColdFire core includes the enhanced
multiply-accumulate unit (EMAC), and memory management unit (MMU), which are explained in detail
in their own chapters. This chapter also includes a full description of exception handling, data formats, an
instruction set summary, and a table of instruction timings.
3.1.1Overview
As with all ColdFire cores, the V4 ColdFire core is comprised of two separate pipelines decoupled by an
instruction buffer.
Freescale Semiconductor3-2
Page 69
ColdFire Core
Internal
IAG
IC1
IC2
IED
IB
DS
OAG
OC1
OC2
EX
DA
Branch
Cache
Branch
Accel.
PSTDDATADSODSCLK DSI
DDATA Debug
Instruction Fetch
Pipeline
Operand Execution
Pipeline
Instruction
Memory
Data
Misalignment
(Operand)
Memory
Module
PSTCLK
secDS
Bus
The instruction fetch pipeline (IFP) is a four-stage pipeline for prefetching instructions. The prefetched
instruction stream is then gated into the five-stage operand execution pipeline (OEP), that decodes the
Figure 3-1. V4 ColdFire Core Pipelines
instruction, fetches the required operands, and then executes the required function. Because the IFP and
OEP pipelines are decoupled by an instruction buffer serving as a FIFO queue, the IFP is able to prefetch
instructions in advance of their actual use by the OEP thereby minimizing time stalled waiting for
instructions.
3-3Freescale Semiconductor
Page 70
The V4 ColdFire core pipeline stages include the following:
— Operand fetch cycle 1 (OC1) — Initiates memory operand fetch on the processor’s local bus
— Operand fetch cycle 2 (OC2) — Completes memory operand fetch on the processor’s local bus,
as well as immediate and/or register operand fetches
— Execute (EX) — Performs prescribed operations on previously fetched data operands
— Write data available (DA) — Makes data available for operand write operations only
ColdFire Core
— Store data (ST) — Updates memory element for operand write operations only
When the instruction buffer is empty, opcodes are loaded directly from the IED cycle into the operand
execution pipeline. If the buffer is not empty, the IFP stores the contents of the fetched instruction and its
early decode information in the IB until it is required by the OEP.
The five stage operand execution pipeline structure is a key factor in the performance of the Version 4
ColdFire design. The pipeline structure is termed a limited superscalar design because there are certain,
heavily-used instruction constructs that support multiple-instruction dispatch. In particular, folding two
consecutive instructions into a single pipeline issue effectively creates zero-cycle execution times for
certain instructions.
With the increased performance, the bandwidth needed to support operand references requires a split bus
(or Harvard architecture) where there are separate instruction and operand memory connections. These
connections may be accessed concurrently to double the amount of available bandwidth to the processor's
pipelines.
The resulting pipeline and local bus structure allow the V4 ColdFire core to deliver sustained high
performance across a variety of demanding embedded applications.
3.1.1.1Change-of-Flow Acceleration
To maximize the performance of conditional branch instructions, the IFP implements a sophisticated
two-level acceleration mechanism. The first level is an 8-entry, direct-mapped branch cache with 2 bits for
indicating four prediction states (strongly or weakly; taken or not-taken) for each entry. The branch cache
also provides the association between instruction addresses and the corresponding target address. In the
event of a branch cache hit, if the branch is predicted as taken, the branch cache sources the target address
Freescale Semiconductor3-4
Page 71
ColdFire Core
from the IC1 stage back into the IAG to redirect the prefetch stream to the new location as shown in
Figure 3-1.
The branch cache implements instruction folding, so conditional branch instructions correctly predicted as
taken can execute in zero cycles. For conditional branches with no information in the branch cache, a
second-level, direct-mapped prediction table is accessed. Each of its 128 entries uses the same 2-bit
prediction mechanism as the branch cache.
If a branch is predicted as taken, branch acceleration logic in the IED stage generates the target address.
Other change-of-flow instructions, including unconditional branches, jumps, and subroutine calls, use a
similar mechanism where the IFP calculates the target address. The performance of the subroutine return
instruction (RTS) is improved through the use of a four-entry, LIFO hardware return stack. In all cases,
these mechanisms allow the IFP to redirect the fetch stream down the predicted path ahead of instruction
execution.
3.1.1.2Operand Execution Pipeline (OEP)
The two instruction registers in the decode stage (DS) of the OEP are loaded from the FIFO instruction
buffer or are bypassed directly from the instruction early decode (IED). The OEP consists of two
traditional, two-stage RISC compute engines with a dual-ported register file access feeding an arithmetic
logic unit (ALU).
The compute engine at the top of the OEP (the address ALU) is used typically for operand address
calculations; the execution ALU at the bottom is used for instruction execution. The resulting structure
provides almost 4 GB/s read operand bandwidth (at 250 MHz) to the two compute engines and supports
single-cycle execution speeds for most instructions, including all load and store operations and most
embedded-load operations. The V4 OEP supports the ColdFire instruction set architecture (ISA)
revision C.
Advanced performance features implemented by the OEP:
•Stalls are minimized by dynamically basing the choice between the address ALU or execution
ALU for instruction execution on the pipeline state.
•The address ALU and register renaming resources together can execute heavily used opcodes and
forward results to subsequent instructions with no pipeline stalls.
•Instruction folding involving MOVE instructions allows two instructions to be issued in one cycle.
The resulting microarchitecture approaches full superscalar performance at a much lower silicon
cost.
3.2Memory Map/Register Description
The following sections describe the processor registers in the user and supervisor programming models.
The programming model is selected based on the processor privilege level (user mode or supervisor mode)
as defined by the S bit of the status register (SR). Table 3 -1 lists the processor registers.
The user-programming model consists of the following registers:
(described fully in Chapter 5, “Enhanced Multiply-Accumulate Unit (EMAC
•One 32-bit memory base address register (RAMBAR)
•8-bit condition code register (CCR)
•EMAC registers
— Four 48-bit accumulator registers partitioned as follows:
– Four 32-bit accumulators (ACC0–ACC3)
– Eight 8-bit accumulator extension bytes (two per accumulator). These are grouped into two
32-bit values for load and store operations (ACCEXT01 and ACCEXT23).
Accumulators and extension bytes can be loaded, copied, and stored; results from EMAC
arithmetic operations generally affect the entire 48-bit destination.
— One 16-bit mask register (MASK)
— One 32-bit Status register (MACSR) including four indicator bits signaling product or
accumulation overflow (one for each accumulator: PAV0–PAV3)
The supervisor programming model is to be used only by system control software to implement restricted
operating system functions, I/O control, and memory management. All accesses that affect the control
features of ColdFire processors are in the supervisor programming model, that consists of registers
available in user mode as well as the following control registers:
•16-bit status register (SR)
•32-bit supervisor stack pointer (SSP)
•32-bit vector base register (VBR)
•32-bit cache control register (CACR)
•32-bit access control registers (ACR0, ACR1, ... ACR3)
•32-bit address space ID register (ASID)
•32-bit MMU base address register (MMUBAR)
Table 3-1. ColdFire Core Programming Model
1
BDM
Load: 0x080
Store: 0x180
Load: 0x081
Store: 0x181
Load: 0x082–7
Store: 0x182–7
Load: 0x088–8E
Store: 0x188–8E
Load: 0x08F
Store: 0x18F
Register
Supervisor/User Access Registers
Data Register 0 (D0)32R/W0xCF42_602BNo3.2.1/3-7
Data Register 1 (D1)32R/W0x0600_2670No3.2.1/3-7
Data Register 2–7 (D2–D7)32R/WUndefinedNo3.2.1/3-7
0x002Cache Control Register (CACR)32R/W0x0000_0000Yes3.2.6/3-10
0x003Address Space Identifier (ASID)8R/W0x00Yes4.2.1/4-4
0x004–7Access Control Register 0–3 (ACR0–3)32R/WSee SectionYes6.3.2/6-8
0x008MMU Base Address Register (MMUBAR)32R/W0x0000_0000Yes4.2.2/4-4
0x800User/Supervisor A7 Stack Pointer
MAC Accumulators 0–3 (ACC0–3)32R/WUndefinedNo5.2.3/5-8
(ACCext01)
(ACCext23)
(OTHER_A7)
Register
Supervisor Access Only Registers
Width
(bits)
AccessReset Value
32R/WUndefinedNo5.2.4/5-8
32R/WUndefinedNo5.2.4/5-8
location
0x0000_0004
32R/WContents of
location
0x0000_0000
Written with
MOVEC
No3.2.5/3-10
No3.2.3/3-8
Section/Page
0x801Vector Base Register (VBR)32R/W0x0000_0000Yes3.2.8/3-10
0x80EStatus Register (SR)16R/W0x27--No3.2.9/3-11
0xC05RAM Base Address Register (RAMBAR)32R/WSee SectionYes3.2.10/3-12
1
The values listed in this column represent the Rc field used when accessing the core registers via the BDM port. For more
information see Chapter 34, “Debug Module”.
3.2.1Data Registers (D0–D7)
D0–D7 data registers are for bit (1-bit), byte (8-bit), word (16-bit) and longword (32-bit) operations; they
can also be used as index registers.
NOTE
Registers D0 and D1 contain hardware configuration details after reset. See
Section 3.3.4.15, “Reset Exception” for more details.
These registers can be used as software stack pointers, index registers, or base address registers. They can
also be used for word and longword operations.
3.2.3Supervisor/User Stack Pointers (A7 and OTHER_A7)
The ColdFire architecture supports two independent stack pointer (A7) registers—the supervisor stack
pointer (SSP) and the user stack pointer (USP). The hardware implementation of these two
program-visible 32-bit registers does not identify one as the SSP and the other as the USP. Instead, the
hardware uses one 32-bit register as the active A7 and the other as OTHER_A7. Thus, the register contents
are a function of the processor operation mode, as shown in the following:
if SR[S] = 1
thenA7 = Supervisor Stack Pointer
OTHER_A7 = User Stack Pointer
elseA7 = User Stack Pointer
OTHER_A7 = Supervisor Stack Pointer
The BDM programming model supports direct reads and writes to the (active) A7 and OTHER_A7. It is
the responsibility of the external development system to determine, based on the setting of SR[S], the
mapping of A7 and OTHER_A7 to the two program-visible definitions (SSP and USP). This functionality
is enabled by setting the enable user stack pointer bit, CACR[EUSP]. If this bit is cleared, only a single
stack pointer (A7), originally defined for ColdFire ISA_A, is available. EUSP is cleared at reset.
To support dual stack pointers, the following two supervisor instructions are included in the ColdFire
instruction set architecture to load/store the USP:
move.l Ay,USP;move to USP
Freescale Semiconductor3-8
Page 75
ColdFire Core
move.l USP,Ax;move from USP
These instructions are described in the ColdFire Family Programmer’s Reference Manual. All other
instruction references to the stack pointer, explicit or implicit, access the active A7 register.
NOTE
The SSP is loaded during reset exception processing with the contents of
location 0x0000_0000.
Figure 3-4. Stack Pointer Registers (A7 and OTHER_A7)
3.2.4Condition Code Register (CCR)
The CCR is the LSB of the processor status register (SR). Bits 4–0 act as indicator flags for results
generated by processor operations. The extend bit (X) is also an input operand during multiprecision
arithmetic computations.
NOTE
The CCR register must be explicitly loaded after reset and before any
compare (CMP), Bcc, or Scc instructions are executed.
BDM: LSB of Status Register (SR)Access: User read/write
BDM read/write
76543210
R000
W
Reset:0 0 0 —————
XNZVC
Figure 3-5. Condition Code Register (CCR)
Table 3-2. CCR Field Descriptions
FieldDescription
7–5Reserved, must be cleared.
4
Extend condition code bit. Set to the C-bit value for arithmetic operations; otherwise not affected or set to a specified
X
result.
3
Negative condition code bit. Set if most significant bit of the result is set; otherwise cleared.
N
3-9Freescale Semiconductor
Page 76
ColdFire Core
Table 3-2. CCR Field Descriptions (continued)
FieldDescription
2
Zero condition code bit. Set if result equals zero; otherwise cleared.
Z
1
Overflow condition code bit. Set if an arithmetic overflow occurs implying the result cannot be represented in operand
V
size; otherwise cleared.
0
Carry condition code bit. Set if a carry out of the operand msb occurs for an addition or if a borrow occurs in a
C
subtraction; otherwise cleared.
3.2.5Program Counter (PC)
The PC contains the currently executing instruction address. During instruction execution and exception
processing, the processor automatically increments PC contents or places a new value in the PC. The PC
is a base address for PC-relative operand addressing.
The PC is initially loaded during reset exception processing with the contents at location 0x0000_0004.
The registers in the cache portion of the programming model are described in Chapter 6, “Cache.”
3.2.7MMU Programming Model
The registers in the MMU portion of the programming model are described in Chapter 4, “Memory
Management Unit (MMU).”
3.2.8Vector Base Register (VBR)
The VBR contains the base address of the exception vector table in the memory. To access the vector table,
the displacement of an exception vector is added to the value in VBR. The lower 20 bits of the VBR are
not implemented by ColdFire processors. They are assumed to be zero, forcing the table to be aligned on
a 1 MB boundary.
The SR stores the processor status and includes the CCR, the interrupt priority mask, and other control
bits. In supervisor mode, software can access the entire SR. In user mode, only the lower 8 bits (CCR) are
accessible. The control bits indicate the following states for the processor: trace mode (T bit), supervisor
or user mode (S bit), and master or interrupt state (M bit). All defined bits in the SR have read/write access
when in supervisor mode.
NOTE
The lower byte of the SR (the CCR) must be loaded explicitly after reset and
before any compare (CMP), Bcc, or Scc instructions execute.
BDM: 0x80E (SR)Access: Supervisor read/write
BDM read/write
System ByteCondition Code Register (CCR)
1514131211109876543210
R
W
Reset00100111000—————
0
T
SM
0
I
000
XNZVC
Figure 3-8. Status Register (SR)
Table 3-3. SR Field Descriptions
FieldDescription
15TTrace enable. When set, the processor performs a trace exception after every instruction.
14Reserved, must be cleared.
13SSupervisor/user state.
0User mode
1 Supervisor mode
12MMaster/interrupt state. Bit is cleared by an interrupt exception and software can set it during execution of the RTE or
move to SR instructions.
11Reserved, must be cleared.
3-11Freescale Semiconductor
Page 78
ColdFire Core
3.2.10Memory Base Address Register (RAMBAR)
The memory base address register is used to specify the base address of the internal SRAM module and
indicates the types of references mapped to it. The base address register includes a base address,
write-protect bit, address space mask bits, and an enable bit. RAMBAR determines the base address of
the on-chip RAM. For more information, refer to Section 7.2.1, “SRAM Base Address Register
(RAMBAR)”.
Table 3-3. SR Field Descriptions (continued)
FieldDescription
10–8IInterrupt level mask. Defines current interrupt level. Interrupt requests are inhibited for all priority levels less than or
equal to current level, except edge-sensitive level 7 requests, which cannot be masked.
7–0
CCR
Refer to Section 3.2.4, “Condition Code Register (CCR)”.
3.3Functional Description
3.3.1Version 4 ColdFire Microarchitecture
As previously discussed, the unrolling of the operand execution pipeline into a five-stage structure is a key
factor in the improved performance of the Version 4 ColdFire design. The resulting pipeline structure is
termed a limited superscalar design because there are certain, heavily-used instruction constructs that
support multiple-instruction dispatch. The following figure presents the top-level spatial block diagram of
the Version 4 ColdFire operand execution pipeline, where the major hardware structures associated with
each pipeline stage are clearly visible.
Freescale Semiconductor3-12
Page 79
ColdFire Core
OAG
OC1
OC2
EX
DS
IndexBase
Register File
EMACBSUDIV
Operand
Memory
OpwordExtension 1
Extension 2
Extended
Opword
Figure 3-9. Version 4 ColdFire Processor Operand Execution Pipeline Diagram
3-13Freescale Semiconductor
Page 80
ColdFire Core
3.3.2Instruction Set Architecture (ISA_C)
The original ColdFire instruction set architecture (ISA_A) was derived from the M68000 family opcodes
based on extensive analysis of embedded application code. The ISA was optimized for code compiled
from high-level languages where the dominant operand size was the 32-bit integer declaration. This
approach minimized processor complexity and cost, while providing excellent performance for compiled
applications.
After the initial ColdFire compilers were created, developers noted there were certain ISA additions that
would enhance code density and overall performance. Additionally, as users implemented ColdFire-based
designs into a wide range of embedded systems, they found certain frequently-used instruction sequences
that could be improved by the creation of additional instructions.
The original ISA definition minimized support for instructions referencing byte- and word-sized operands.
Full support for the move byte and move word instructions was provided, but the only other opcodes
supporting these data types are CLR (clear) and TST (test). A set of instruction enhancements has been
implemented in subsequent ISA revisions, ISA_B and ISA_C. The added opcodes primarily addressed
three areas:
1. Enhanced support for byte and word-sized operands
2. Enhanced support for position-independent code
3. Miscellaneous instruction additions to address new functionality
Table 3-4 summarizes the instructions added to revision ISA_A to form revision ISA_C. For more details
see the ColdFire Family Programmer’s Reference Manual.
Table 3-4. Instruction Enhancements over Revision ISA_A
InstructionDescription
BITREVThe contents of the destination data register are bit-reversed; that is, new Dn[31] equals old
Dn[0], new Dn[30] equals old Dn[1], ..., new Dn[0] equals old Dn[31].
BYTEREVThe contents of the destination data register are byte-reversed; that is, new Dn[31:24] equals
old Dn[7:0], ..., new Dn[7:0] equals old Dn[31:24].
FF1The data register, Dn, is scanned, beginning from the most-significant bit (Dn[31]) and ending
with the least-significant bit (Dn[0]), searching for the first set bit. The data register is then
loaded with the offset count from bit 31 where the first set bit appears.
INTOUCHLoads blocks of instructions to be locked in the instruction cache.
MOV3Q.LMoves 3-bit immediate data to the destination location.
Move from USPUser Stack Pointer Destination register
Move to USPSource register User Stack Pointer
MVS.{B,W}Sign-extends source operand and moves it to destination register.
MVZ.{B,W}Zero-fills source operand and moves it to destination register.
SATS.LPerforms saturation operation for signed arithmetic and updates destination register,
depending on CCR[V] and bit 31 of the register.
TAS.BPerforms indivisible read-modify-write cycle to test and set addressed memory byte.
Bcc.LBranch conditionally, longword
Freescale Semiconductor3-14
Page 81
ColdFire Core
2. The processor determines the exception vector number. For all faults except interrupts, the
processor performs this calculation based on exception type. For interrupts, the processor
performs an interrupt-acknowledge (IACK) bus cycle to obtain the vector number from the
interrupt controller. The IACK cycle is mapped to special locations within the interrupt
controller’s address space with the interrupt level encoded in the address.
Table 3-4. Instruction Enhancements over Revision ISA_A (continued)
InstructionDescription
BSR.LBranch to sub-routine, longword
CMP.{B,W}Compare, byte and word
CMPA.WCompare address, word
CMPI.{B,W}Compare immediate, byte and word
MOVEIMove immediate, byte and word to memory using Ax with displacement
3.3.3Exception Processing Overview
Exception processing for ColdFire processors is streamlined for performance. The ColdFire processors
differ from the M68000 family because they include:
•A simplified exception vector table
•Reduced relocation capabilities using the vector-base register
•A single exception stack frame format
•A precise instruction restart model for translation (TLB miss) and access faults. This functionality
extends the existing ColdFire access error fault vector in the exception stack frames.
All ColdFire processors use an instruction restart exception model. Exception processing includes all
actions from fault condition detection to the initiation of fetch for first handler instruction. Exception
processing is comprised of four major steps:
1. The processor makes an internal copy of the SR and then enters supervisor mode by setting the S
bit and disabling trace mode by clearing the T bit. The interrupt exception also forces the M bit to
be cleared and the interrupt priority mask to set to current interrupt request level.
3. The processor saves the current context by creating an exception stack frame on the system stack.
The exception stack frame is created at a 0-modulo-4 address on top of the system stack pointed to
by the supervisor stack pointer (SSP). As shown in Figure 3-10, the processor uses a simplified
fixed-length stack frame for all exceptions with additional fault status (FS) encodings to support
the MMU. The exception type determines whether the program counter placed in the exception
stack frame defines the location of the faulting instruction (fault) or the address of the next
instruction to be executed (next).
4. The processor calculates the address of the first instruction of the exception handler. By definition,
the exception vector table is aligned on a 1 MB boundary. This instruction address is generated by
fetching an exception vector from the table located at the address defined in the vector base register.
3-15Freescale Semiconductor
Page 82
ColdFire Core
All ColdFire processors support a 1024-byte vector table aligned on any 1 Mbyte address boundary (see
Table 3-5).
The index into the exception table is calculated as (4 vector number). After the exception vector
has been fetched, the vector contents determine the address of the first instruction of the desired
handler. After the instruction fetch for the first opcode of the handler has initiated, exception
processing terminates and normal instruction processing continues in the handler.
The table contains 256 exception vectors; the first 64 are defined for the core and the remaining 192 are
device-specific peripheral interrupt vectors. See Chapter 17, “Interrupt Controller Modules” for details on
the device-specific interrupt sources.
Fault refers to the PC of the instruction that caused the exception. Next refers to the PC
of the instruction that follows the instruction that caused the fault.
Freescale Semiconductor3-16
Page 83
ColdFire Core
All ColdFire processors inhibit interrupt sampling during the first instruction of all exception handlers.
This allows any handler to disable interrupts effectively, if necessary, by raising the interrupt mask level
contained in the status register. For more details, see ColdFire Family Programmer’s Reference Manual.
3.3.3.1Exception Stack Frame Definition
Figure 3-10 shows exception stack frame. The first longword contains the 16-bit format/vector word (F/V)
and the 16-bit status register, and the second longword contains the 32-bit program counter address.
The 16-bit format/vector word contains three unique fields:
•A 4-bit format field at the top of the system stack is always written with a value of 4, 5, 6, or 7 by
the processor, indicating a two-longword frame format. See Table 3-6.
Table 3-6. Format Field Encodings
Program Counter
Original SSP @ Time
of Exception, Bits 1:0
00Original SSP - 80100
01Original SSP - 90101
10Original SSP - 100110
11Original SSP - 110111
SSP @ 1st
Instruction of
Handler
Format Field
•There is a 4-bit fault status field, FS[3:0], at the top of the system stack. This field is defined for
access and address errors only and written as zeros for all other exceptions. See Tabl e 3-7.
Table 3-7. Fault Status Encodings
FS[3:0]Definition
0000Not an access or address error nor an interrupted debug service routine
0001Reserved
0010Interrupt during a debug service routine for faults other than access errors
0011Reserved
0100Error on instruction fetch
0101TLB miss on opword of instruction fetch
1
0110TLB miss on extension word of instruction fetch
0111IFP access error while executing in emulator mode
1000Error on operand write
1001Attempted write to write-protected space
3-17Freescale Semiconductor
Page 84
Table 3-7. Fault Status Encodings (continued)
FS[3:0]Definition
1010TLB miss on data write
1011Reserved
1100Error on operand read
1101Attempted read, read-modify-write of protected space
1110TLB miss on data read, or read-modify-write
ColdFire Core
1111
1
This refers to taking an I/O interrupt during a debug service routine. If an access error occurs
during a debug service routine, FS is set to 0111 if it is due to an instruction fetch or to 1111
for a data access.
OEP access error while executing in emulator mode
•The 8-bit vector number, vector[7:0], defines the exception type and is calculated by the processor
for all internal faults and represents the value supplied by the interrupt controller in case of an
interrupt. See Table 3 -5.
3.3.4Processor Exceptions
3.3.4.1Access Error Exception
The exact processor response to an access error depends on the memory reference being performed. For
an instruction fetch, the processor postpones the error reporting until the faulted reference is needed by an
instruction for execution. Therefore, faults during instruction prefetches followed by a change of
instruction flow do not generate an exception. When the processor attempts to execute an instruction with
a faulted opword and/or extension words, the access error is signaled and the instruction is aborted. For
this type of exception, the programming model has not been altered by the instruction generating the access
error.
If the access error occurs on an operand read, the processor immediately aborts the current instruction’s
execution and initiates exception processing. The operand execution pipeline includes logic to fully
recover program-visible register updates in the event of a bus transfer error acknowledge on an operand
memory reference. This allows for a precise instruction restart from this class of exceptions. See
Section 3.3.4.16, “Precise Faults”, for additional information.
If the MMU is disabled, access errors are reported only with an attempted store to write-protected memory.
Therefore, access errors associated with instruction fetch or operand read accesses are not possible. The
Version 4 ColdFire processor, unlike the Version 2 and 3 ColdFire processors, updates the condition code
register if a write-protect error occurs during a CLR or MOV3Q operation to memory.
Internal memory accesses that fault (terminate with an internal memory transfer error acknowledge)
generate an access error exception. MMU TLB misses and access violations use the same fault. If the
MMU is enabled, all TLB misses and protection violations generate an access error exception. To
determine if a fault is due to a TLB miss or another type of access error, new FS encodings (described in
Table 3-7) signal TLB misses on instruction fetch, instruction extension fetch, and data read and writes.
Freescale Semiconductor3-18
Page 85
ColdFire Core
3.3.4.2Address Error Exception
Any attempted execution transferring control to an odd instruction address (if bit 0 of the target address is
set) results in an address error exception.
Any attempted use of a word-sized index register (Xn.w) or a scale factor of eight on an indexed effective
addressing mode generates an address error, as does an attempted execution of a full-format indexed
addressing mode, which is defined by bit 8 of extension word 1 being set.
If an address error occurs on a JSR instruction, the Version 4 ColdFire processor first pushes the return
address onto the stack and then calculates the target address. If an address error occurs on an RTS
instruction, the Version 4 ColdFire processor preserves the original return PC and writes the exception
stack frame above this value.
3.3.4.3Illegal Instruction Exception
The ColdFire variable-length instruction set architecture supports three instruction sizes: 16, 32, or 48 bits.
The first instruction word is known as the operation word (or opword), while the optional words are known
as extension word 1 and extension word 2. The opword is further subdivided into three sections: the upper
four bits segment the entire ISA into 16 instruction lines, the next 6 bits define the operation mode
(opmode), and the low-order 6 bits define the effective address. See Figure 3-11. The opword line
definition is shown in Table 3-8.
1514131211109876543210
LineOpModeEffective Address
ModeRegister
Figure 3-11. ColdFire Instruction Operation Word (Opword) Format
Table 3-8. ColdFire Opword Line Definition
Opword[Line]Instruction Class
0x0Bit manipulation, Arithmetic and Logical Immediate
0x1Move Byte
0x2Move Long
0x3Move Word
0x4Miscellaneous
0x5Add (ADDQ) and Subtract Quick (SUBQ), Set according to Condition Codes (Scc)
0x6PC-relative change-of-flow instructions
Conditional (Bcc) and unconditional (BRA) branches, subroutine calls (BSR)
0x7Move Quick (MOVEQ), Move with sign extension (MVS) and zero fill (MVZ)
0x8Logical OR (OR)
0x9Subtract (SUB), Subtract Extended (SUBX)
0xAEMAC, Move 3-bit Quick (MOV3Q)
0xBCompare (CMP), Exclusive-OR (EOR)
3-19Freescale Semiconductor
Page 86
ColdFire Core
Table 3-8. ColdFire Opword Line Definition (continued)
Opword[Line]Instruction Class
0xCLogical AND (AND), Multiply Word (MUL)
0xDAdd (ADD), Add Extended (ADDX)
0xEArithmetic and logical shifts (ASL, ASR, LSL, LSR)
In the original M68000 ISA definition, lines A and F were effectively reserved for user-defined operations
(line A) and co-processor instructions (line F). Accordingly, there are two unique exception vectors
associated with illegal opwords in these two lines.
Any attempted execution of an illegal 16-bit opcode (except for line-A and line-F opcodes) generates an
illegal instruction exception (vector 4). Additionally, any attempted execution of any non-MAC line-A and
most line-F opcodes generate their unique exception types, vector numbers 10 and 11, respectively.
ColdFire cores do not provide illegal instruction detection on the extension words on any instruction,
including MOVEC.
3.3.4.4Divide-By-Zero
Attempting to divide by zero causes an exception (vector 5, offset equal 0x014).
3.3.4.5Privilege Violation
The attempted execution of a supervisor mode instruction while in user mode generates a privilege
violation exception. See ColdFire Programmer’s Reference Manual for a list of supervisor-mode
instructions.
There is one special case involving the HALT instruction. Normally, this opcode is a supervisor mode
instruction, but if the debug module's CSR[UHE] is set, then this instruction can be also be executed in
user mode for debugging purposes.
3.3.4.6Trace Exception
To aid in program development, all ColdFire processors provide an instruction-by-instruction tracing
capability. While in trace mode, indicated by setting of the SR[T] bit, the completion of an instruction
execution (for all but the stop instruction) signals a trace exception. This functionality allows a debugger
to monitor program execution.
The stop instruction has the following effects:
1. The instruction before the stop executes and then generates a trace exception. In the exception stack
frame, the PC points to the stop opcode.
2. When the trace handler is exited, the stop instruction executes, loading the SR with the immediate
operand from the instruction.
3. The processor then generates a trace exception. The PC in the exception stack frame points to the
instruction after the stop, and the SR reflects the value loaded in the previous step.
Freescale Semiconductor3-20
Page 87
ColdFire Core
If the processor is not in trace mode and executes a stop instruction where the immediate operand sets
SR[T], hardware loads the SR and generates a trace exception. The PC in the exception stack frame points
to the instruction after the stop, and the SR reflects the value loaded in step 2.
Because ColdFire processors do not support any hardware stacking of multiple exceptions, it is the
responsibility of the operating system to check for trace mode after processing other exception types. As
an example, consider a TRAP instruction execution while in trace mode. The processor initiates the trap
exception and then passes control to the corresponding handler. If the system requires that a trace exception
be processed, it is the responsibility of the trap exception handler to check for this condition (SR[T] in the
exception stack frame set) and pass control to the trace handler before returning from the original
exception.
3.3.4.7Unimplemented Line-A Opcode
A line-A opcode is defined when bits 15-12 of the opword are 0b1010. This exception is generated by the
attempted execution of an undefined line-A opcode.
3.3.4.8Unimplemented Line-F Opcode
A line-F opcode is defined when bits 15-12 of the opword are 0b1111. This exception is generated when
attempting to execute an undefined line-F opcode.
3.3.4.9Debug Interrupts
See Chapter 34, “Debug Module,” for a detailed explanation of these exceptions, which are generated in
response to hardware breakpoint register triggers. The processor does not generate an IACK cycle, but
rather calculates the vector number internally (vector number 12 or 13, depending on the type of
breakpoint trigger). Additionally, SR[M,I] are unaffected by the interrupt.
Separate exception vectors are provided for PC breakpoints and for address/data breakpoints. In the case
of a two-level trigger, the last breakpoint determines the vector. There are two unique vectors for these
exceptions: vector 0x030 corresponds to non-PC breakpoints and vector 0x034 corresponds to PC
breakpoints.
3.3.4.10RTE and Format Error Exception
When an RTE instruction is executed, the processor first examines the 4-bit format field to validate the
frame type. For a ColdFire core, any attempted RTE execution (where the format is not equal to {4,5,6,7})
generates a format error. The exception stack frame for the format error is created without disturbing the
original RTE frame and the stacked PC pointing to the RTE instruction.
The selection of the format value provides some limited debug support for porting code from M68000
applications. On M68000 family processors, the SR was located at the top of the stack. On those
processors, bit 30 of the longword addressed by the system stack pointer is typically zero. Thus, if an RTE
is attempted using this old format, it generates a format error on a ColdFire processor.
If the format field defines a valid type, the processor: (1) reloads the SR operand, (2) fetches the second
longword operand, (3) adjusts the stack pointer by adding the format value to the auto-incremented address
3-21Freescale Semiconductor
Page 88
ColdFire Core
after the fetch of the first longword, and then (4) transfers control to the instruction address defined by the
second longword operand within the stack frame.
3.3.4.11TRAP Instruction Exception
The TRAP #n instruction always forces an exception as part of its execution and is useful for implementing
system calls. The TRAP instruction may be used to change from user to supervisor mode.
3.3.4.12Unsupported Instruction Exception
If execution of a valid instruction is attempted but the required hardware is not present in the processor, an
unsupported instruction exception is generated. The instruction functionality can then be emulated in the
exception handler, if desired.
All ColdFire cores record the processor hardware configuration in the D0 register immediately after the
negation of RESET. See Section 3.3.4.15, “Reset Exception,” for details.
3.3.4.13Interrupt Exception
Interrupt exception processing includes interrupt recognition and the fetch of the appropriate vector from
the interrupt controller using an IACK cycle. See Chapter 17, “Interrupt Controller Modules,” for details
on the interrupt controller.
3.3.4.14Fault-on-Fault Halt
If a ColdFire processor encounters any type of fault during the exception processing of another fault, the
processor immediately halts execution with the catastrophic fault-on-fault condition. A reset is required to
to exit this state.
3.3.4.15Reset Exception
Asserting the reset input signal (RESET) to the processor causes a reset exception. The reset exception has
the highest priority of any exception; it provides for system initialization and recovery from catastrophic
failure. Reset also aborts any processing in progress when the reset input is recognized. Processing cannot
be recovered.
The reset exception places the processor in the supervisor mode by setting the SR[S] bit and disables
tracing by clearing the SR[T] bit. This exception also clears the SR[M] bit and sets the processor’s SR[I]
field to the highest level (level 7, 0b111). Next, the VBR is initialized to zero (0x0000_0000). The control
registers specifying the operation of any memories (e.g., cache and/or RAM modules) connected directly
to the processor are disabled.
NOTE
Other implementation-specific registers are also affected. Refer to each
module in this reference manual for details on these registers.
After the processor is granted the bus, it performs two longword read-bus cycles. The first longword at
address 0x0000_0000 is loaded into the supervisor stack pointer and the second longword at address
Freescale Semiconductor3-22
Page 89
ColdFire Core
(This is the value used for this device.)
0x0000_0004 is loaded into the program counter. After the initial instruction is fetched from memory,
program execution begins at the address in the PC. If an access error or address error occurs before the first
instruction is executed, the processor enters the fault-on-fault state.
ColdFire processors load hardware configuration information into the D0 and D1 general-purpose
registers after system reset. The hardware configuration information is loaded immediately after the
reset-in signal is negated. This allows an emulator to read out the contents of these registers via the BDM
to determine the hardware configuration.
Information loaded into D0 defines the processor hardware configuration as shown in Figure 3-12.
BDM: Load: 0x080 (D0)
Store: 0x180 (D0)
31302928272625242322212019181716
RPFVERREV
W
Reset1100111101000010
1514131211109876543210
R MACDIVEMACFPU0000ISADEBUG
W
Reset0110000000101011
Access: User read-only
BDM read-only
Figure 3-12. D0 Hardware Configuration Info
Table 3-9. D0 Hardware Configuration Info Field Description
FieldDescription
31–24PFProcessor family. This field is fixed to a hex value of 0xCF indicating a ColdFire core is present.
23–20
VER
ColdFire core version number. Defines the hardware microarchitecture version of ColdFire core.
0001 V1 ColdFire core
0010 V2 ColdFire core
0011 V3 ColdFire core
0100 V4 ColdFire core (This is the value used for this device.)
0101 V5 ColdFire core
Else Reserved for future use
19–16
REV
MAC
EMAC
3-23Freescale Semiconductor
Processor revision number. The default is 0b0010.
15
MAC present. This bit signals if the optional multiply-accumulate (MAC) execution engine is present in processor core.
0 MAC execute engine not present in core. (This is the value used for this device.)
1 MAC execute engine is present in core.
14
Divide present. This bit signals if the hardware divider (DIV) is present in the processor core.
DIV
0 Divide execute engine not present in core.
1 Divide execute engine is present in core.
13
EMAC present. This bit signals if the optional enhanced multiply-accumulate (EMAC) execution engine is present in
processor core.
0 EMAC execute engine not present in core.
1 EMAC execute engine is present in core. (This is the value used for this device.)
Page 90
Table 3-9. D0 Hardware Configuration Info Field Description (continued)
FieldDescription
12
FPU present. This bit signals if the optional floating-point (FPU) execution engine is present in processor core.
FPU
11–8Reserved.
DEBUG
0 FPU execute engine not present in core. (This is the value used for this device.)
1 FPU execute engine is present in core.
7–4
ISA revision. Defines the instruction-set architecture (ISA) revision level implemented in ColdFire processor core.
ISA
0000 ISA_A
0001 ISA_B
0010 ISA_C (This is the value used for this device.)
1000 ISA_A+
Else Reserved
3–0
Debug module revision number. Defines revision level of the debug module used in the ColdFire processor core.
0000 DEBUG_A
0001 DEBUG_B
0010 DEBUG_C
0011 DEBUG_D
0100 DEBUG_E
1001 DEBUG_B+
1011 DEBUG_D+ (This is the value used for this device.)
1111 DEBUG_D+PST Buffer
Else Reserved
ColdFire Core
Information loaded into D1 defines the local memory hardware configuration as shown in the figure below.
BDM: Load: 0x081 (D1)
Store: 0x181 (D1)
31302928272625242322212019181716
RCLSZICASICSZ00000000
W
Reset0000011000000000
1514131211109876543210
RMBSZCPES DCASDCSZSRAMSZ000
W
Reset0010011001110000
Figure 3-13. D1 Hardware Configuration Info
Access: User read-only
BDM read-only
Freescale Semiconductor3-24
Page 91
ColdFire Core
Table 3-10. D1 Hardware Configuration Information Field Description
FieldDescription
31–30
Cache line size. This field is fixed to a hex value of 0x0 indicating a 16-byte cache line size.
CLSZ
29–28
ICAS
Instruction cache associativity.
00Four-way (This is the value used for this device)
01Direct mapped
Else Reserved for future use
27–24
ICSZ
Instruction cache size. Indicates the amount of instruction cache.
0000 No instruction cache
0001 512 B instruction cache
0010 1 KB instruction cache
0011 2 KB instruction cache
0100 4 KB instruction cache
0101 8 KB instruction cache
0110 16 KB instruction cache (This is the value used for this device)
0111 32 KB instruction cache
1000 64 KB instruction cache
Else Reserved
23–16Reserved.
15–14
MBSZ
Bus size. Defines the width of the ColdFire master bus datapath.
0032-bit system bus datapath (This is the value used for this device)
0164-bit system bus datapath
Else Reserved
13
CPES
CPUSHL enhancements supported. Specifies whether the enhancements to the CPUSHL instructions are
supported by the processor core. See Section 6.4.8, “CPUSHL Enhancements,” for details.
0 CPUSHL instruction enhancements are not supported
1 CPUSHL instruction enhancements are supported (This is the value used for this device)
12
DCAS
11–8
DCSZ
Data cache associativity. Defines the data cache set-associativity.
0Four-way (This is the value used for this device)
1Direct mapped
Data cache size. Indicates the size of the unified cache.
0000 No data cache
0001 512 bytes
0010 1 KB
0011 2 KB
0100 4 KB
0101 8 KB
0110 16 KB (This is the value used for this device)
0111 32 KB
Else Reserved for future use
3-25Freescale Semiconductor
Page 92
Table 3-10. D1 Hardware Configuration Information Field Description (continued)
FieldDescription
ColdFire Core
7–3
SRAMSZ
2–0Reserved.
SRAM bank size.
00000 No SRAM
00010 512 bytes
00100 1 KB
00110 2 KB
01000 4 KB
01010 8 KB
01100 16 KB
01111 24 KB
01110 32 KB (This is the value used for this device)
10000 64 KB
10010 128 KB
Else Reserved for future use
3.3.4.16Precise Faults
To support a demand-paged virtual-memory environment, all memory references require precise,
recoverable faults. The ColdFire instruction restart mechanism ensures that a faulted instruction restarts
from the execution beginning. No internal state information is saved when an exception occurs nor is any
restored when the handler ends. Given the PC address defined in the exception stack frame, the processor
re-establishes program execution by transferring control to the given location as part of the RTE (return
from exception) instruction.
The instruction restart recovery model requires program-visible register changes made during execution
to be undone if that instruction subsequently faults.
The Version 4 (and later) ColdFire OEP structure naturally supports this concept for most instructions;
program-visible registers are updated only in the final OEP stage when fault collection is complete. If any
exception occurs, pending register updates are discarded.
For V4 ColdFire cores and later, most single-cycle instructions naturally support precise faults and
instruction restart, while complex instruction do not. Consider the following memory-to-memory move:
move.l(Ay)+,(Ax)+# copy 4 bytes from source to destination
This instruction takes one cycle to read the source operand (Ay) and one to write the data into Ax. Source
and destination address pointers are updated as part of execution. Table 3-11 lists the operations performed
in execute stage (EX).
Freescale Semiconductor3-26
Page 93
ColdFire Core
Table 3-11. OEP EX Cycle Operations
EX CycleOperations
1Read source operand from memory @ (Ay), update Ay, new Ay = old Ay + 4
2Write operand into destination memory @ (Ax), update Ax, new Ax = old Ax + 4, update CCR
A fault detected with the destination memory write is reported during the second cycle. At this point,
operations performed in the first cycle are complete, so if the destination write takes any type of access
error, Ay is updated. After the access error handler executes and the faulting instruction restarts, the
processor’s operation would be incorrect (without the special register recovery hardware) because the
source-address register has an incorrect (post-incremented) value.
To recover the original state of the programming model for all instructions, the Version 4 ColdFire core
adds the needed hardware to support full-register recovery. This hardware allows program-visible registers
to be restored to their original state for multi-cycle instructions so that the instruction restart mechanism
is supported. Memory-to-memory moves and move-multiple loads are representative of the complex
instructions needing the special recovery support.
Recall the IFP and OEP are decoupled by a FIFO instruction buffer. In the V4 ColdFire IFP, each buffer
entry includes 48 bits of instruction data fetched from memory and 64 bits of early decode and branch
prediction information. This datapath also includes IFP fault-status information. Therefore, every IFP
access can be tagged if an instruction fetch terminates with an error acknowledge. IFP access errors are
recognized after the buffered instruction enters the OEP.
NOTE
For access errors signaled on instruction prefetches, an access error
exception is generated only if instruction execution is attempted. If an
instruction fetch access error exception is generated and the FS field
indicates the fault occurred on an extension word, it may be necessary for
the exception PC to be rounded-up to the next page address to determine the
faulting instruction fetch address.
3.3.5Instruction Execution Timing
This section presents processor instruction execution times in terms of processor-core clock cycles. The
number of operand references for each instruction is enclosed in parentheses following the number of
processor clock cycles. Each timing entry is presented as C(R/W) where:
•C is the number of processor clock cycles, including all applicable operand fetches and writes, and
all internal core cycles required to complete the instruction execution.
•R/W is the number of operand reads (R) and writes (W) required by the instruction. An operation
performing a read-modify-write function is denoted as (1/1).
This section includes the assumptions concerning the timing values and the execution time details.
3-27Freescale Semiconductor
Page 94
ColdFire Core
3.3.5.1Timing Assumptions
For the timing data presented in this section, these assumptions apply:
1. The OEP is loaded with the opword and all required extension words at the beginning of each
instruction execution. This implies that the OEP does not wait for the IFP to supply opwords and/or
extension words.
2. Execution times for individual instructions make no assumptions concerning the OEP’s ability to
dispatch multiple instructions in one machine cycle. For sequences where instruction pairs are
issued, the execution time of the first instruction defines the execution time of pair; the second
instruction effectively executes in zero cycles.
3. The OEP does not experience any sequence-related pipeline stalls. The most common example of
stall occurs when a register is modified in the EX engine and a subsequent instruction generates an
address that uses the previously modified register. The second instruction stalls in the OEP until
the previous instruction updates the register. For example, in the following code:
muls.l#<data>,d0
move.l(a0,d0.l*4),d1
the move.l instruction waits three cycles for the muls.l to update D0. If consecutive instructions
update a register and use that register as a base of index value with a scale factor of 1 (Xi.l*1) in
an address calculation, a 2-cycle pipeline stall occurs. If the destination register is used as an index
register with any other scale factor (Xi.l*2, Xi.l*4), a 3-cycle stall occurs.
NOTE
Address register results from post-increment and pre-decrement modes are
available to subsequent instructions without stalls.
4. The OEP completes all memory accesses without any stall conditions caused by the memory itself.
Thus, the timing details provided in this section assume that an infinite zero-wait state memory is
attached to the processor core.
5. All operand data accesses are aligned on the same byte boundary as the operand size; for example,
16-bit operands aligned on 0-modulo-2 addresses, 32-bit operands aligned on 0-modulo-4
addresses.
The processor core decomposes misaligned operand references into a series of aligned accesses as
shown in Table 3-12.
Table 3-12. Misaligned Operand References
address[1:0]Size
01 or 11WordByte, Byte2(1/0) if read
01 or 11LongByte, Word,
10LongWord, Word2(1/0) if read
Bus
Operations
Byte
Additional
C(R/W)
1(0/1) if write
3(2/0) if read
2(0/2) if write
1(0/1) if write
Freescale Semiconductor3-28
Page 95
ColdFire Core
3.3.5.2MOVE Instruction Execution Times
Table 3-13 lists execution times for MOVE.{B,W} instructions; Table 3-14 lists timings for MOVE.L.
NOTE
For all tables in this section, the execution time of any instruction using the
PC-relative effective addressing modes is the same for the comparable
An-relative mode.
ET with {<ea> = (d16,PC)}equals ET with {<ea> = (d16,An)}
ET with {<ea> = (d8,PC,Xi*SF)}equals ET with {<ea> = (d8,An,Xi*SF)}
The nomenclature xxx.wl refers to both forms of absolute addressing, xxx.w
and xxx.l.
Table 3-13. MOVE Byte and Word Execution Times
Destination
Source
Rx(Ax)(Ax)+-(Ax)(d16,Ax) (d8,Ax,Xi*SF) xxx.wl
Dy1(0/0)1(0/1)1(0/1)1(0/1)1(0/1)2(0/1)1(0/1)
Ay1(0/0)1(0/1)1(0/1)1(0/1)1(0/1)2(0/1)1(0/1)
(Ay)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)3(1/1))2(1/1)
(Ay)+1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)3(1/1))2(1/1)
-(Ay)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)3(1/1))2(1/1)
(d16,Ay)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)——
(d8,Ay,Xi*SF)2(1/0)3(1/1)3(1/1)3(1/1)———
xxx.w1(1/0)2(1/1)2(1/1)2(1/1)———
xxx.l1(1/0)2(1/1)2(1/1)2(1/1)———
(d16,PC)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)——
(d8,PC,Xi*SF)2(1/0)3(1/1)3(1/1)3(1/1))———
#xxx1(0/0)1(0/1)1(0/1)1(0/1)1(0/1)——
Table 3-14. MOVE Long Execution Times
Destination
Source
Rx(Ax)(Ax)+-(Ax)(d16,Ax)(d8,Ax,Xi*SF) xxx.wl
Dy1(0/0)1(0/1)1(0/1)1(0/1)1(0/1)2(0/1)1(0/1)
Ay1(0/0)1(0/1)1(0/1)1(0/1)1(0/1)2(0/1)1(0/1)
(Ay)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)3(1/1)2(1/1)
(Ay)+1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)3(1/1)2(1/1)
-(Ay)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)3(1/1)2(1/1)
(d16,Ay)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)——
3-29Freescale Semiconductor
Page 96
ColdFire Core
Table 3-14. MOVE Long Execution Times (continued)
Destination
Source
Rx(Ax)(Ax)+-(Ax)(d16,Ax)(d8,Ax,Xi*SF) xxx.wl
(d8,Ay,Xi*SF)2(1/0)3(1/1)3(1/1)3(1/1)———
xxx.w1(1/0)2(1/1)2(1/1)2(1/1)———
xxx.l1(1/0)2(1/1)2(1/1)2(1/1)———
(d16,PC)1(1/0)2(1/1)2(1/1)2(1/1)2(1/1)——
(d8,PC,Xi*SF)2(1/0)3(1/1)3(1/1)3(1/1)———
#xxx1(0/0)1(0/1)1(0/1)1(0/1)———
3.3.5.3Standard One Operand Instruction Execution Times
Table 3-15. One Operand Instruction Execution Times
Storing an accumulator requires one additional processor clock cycle when saturation is enabled, or fractional
rounding is performed (MACSR[7:4] equals 1---, -11-, --11)
NOTE
The execution times for moving the contents of the Racc, Raccext[01,23],
MACSR, or Rmask into a destination location <ea>x shown in this table
represent the best-case scenario when the store instruction is executed and
there are no load or M{S}AC instructions in the EMAC execution pipeline.
In general, these store operations require only a single cycle for execution,
but if preceded immediately by a load, MAC, or MSAC instruction, the
depth of the EMAC pipeline is exposed and the execution time is four
cycles.
3.3.5.7Branch Instruction Execution Times
Table 3-19. General Branch Instruction Execution Times
Effective Address
Opcode<EA>
Rn(An)(An)+-(An)
BRA————1(0/1)
BSR————1(0/1)
(d16,An)
(d16,PC)
1
2
(d8,An,Xi*SF)
(d8,PC,Xi*SF)
———
———
xxx.wl#xxx
Freescale Semiconductor3-34
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.