Skip to content

OpenOCD Config

OpenOCD Configuration and Usage

OpenOCD (Open On-Chip Debugger) is a critical tool for interacting with JTAG-enabled devices during firmware analysis. It provides a bridge between hardware debug interfaces (like JTAG) and software tools such as GDB, enabling low-level control of embedded systems. Proper configuration and usage of OpenOCD are essential for successful hardware hacking and firmware reverse engineering.


Installation

Install OpenOCD on your host system using package managers or source code. The exact steps depend on your OS:

Linux (Debian/Ubuntu)

sudo apt update
sudo apt install openocd

macOS (Homebrew)

brew install openocd

Windows

Use MSYS2 or WSL (Windows Subsystem for Linux) for native support. For Windows, install via MSYS2 and run:

pacman -S mingw-w64-x86_64-openocd

Note: Some platforms may require compiling from source if prebuilt packages are unavailable. Ensure your system has dependencies like libftdi, libusb, and libtool.


Configuration

OpenOCD uses TCL scripts to define hardware interfaces, target devices, and debug protocols. Configuration files are typically stored in /usr/share/openocd/ or custom paths. A minimal configuration file (openocd.cfg) might look like this:

# Interface configuration (e.g., USB Blaster)
interface usbblaster
transport select jtag
jtag_khz 1000

# Target device configuration (e.g., STM32F4)
source [find interface/ft2232.cfg]
source [find target/stm32f4x.cfg]

Key Parameters: - interface: Specifies the JTAG adapter (e.g., ft223, usbblaster). - transport: Defines the communication protocol (jtag, swd). - jtag_khz: Sets the JTAG clock speed. - source: Includes device-specific configuration files.

Tip: Consult your device’s datasheet to determine correct interface parameters and target-specific scripts.


Basic Usage

Start OpenOCD with a configuration file:

openocd -f openocd.cfg

Once running, connect to the target device using GDB:

arm-none-eabi-gdb
(gdb) target remote localhost:3333
(gdb) monitor reset
(gdb) monitor scan_chain

Common Commands: - monitor reset: Resets the target device. - monitor scan_chain: Verifies JTAG chain connectivity. - monitor halt: Halts the target CPU. - monitor help: Lists available commands.

Example Workflow: 1. Power on the target device. 2. Run monitor scan_chain to confirm JTAG chain detection. 3. Use monitor reset to initialize the device. 4. Load firmware or memory dumps via GDB.


Advanced Topics

Scripting with TCL

Automate tasks using TCL scripts. For example, a script to flash firmware:

# flash_script.tcl
if {[info exists ::env(OPENOCD_SCRIPTS)]} {
    source [file join $::env(OPENOCD_SCRIPTS) interface/ft2232.cfg]
}
set OCD_PORT 3333
set OCD_HOST localhost

# Flash firmware
monitor reset
monitor halt
flash write_image flash.bin 0x08000000
monitor reset

Run the script with:

openocd -f openocd.cfg -f flash_script.tcl

Multi-Device Support

For devices with multiple JTAG targets, use jtag newtap to define separate chains:

jtag newtap cpu1 -irl 0 -irl 1
jtag newtap cpu2 -irl 0 -irl 2

Troubleshooting

  • Connection Errors: Ensure the JTAG adapter is properly connected and drivers are installed.
  • Incorrect Configuration: Verify interface and target parameters match your hardware.
  • Timing Issues: Adjust jtag_khz if communication fails.

Key takeaways

  • Installation: Use package managers or compile from source, ensuring dependencies are met.
  • Configuration: Tailor TCL scripts to your JTAG adapter and target device, referencing datasheets.
  • Basic Commands: Use monitor and GDB to reset, scan, and control the target.
  • Advanced Use: Leverage TCL scripting for automation and handle multi-device setups.
  • Troubleshoot: Validate hardware connections, configuration parameters, and timing settings.