QSPI Command sends extra byte in Instruction Only mode - STM32L452
I'm having a doozy of a time writing to some external flash. I am able to read the MFG ID and the status registers, but I cannot write to it. I believe this is because of an issue with the write enable command. Here's how I'm configuring the command:
.InstructionMode = QSPI_INSTRUCTION_1_LINE,
.AlternateByteMode = QSPI_ALTERNATE_BYTES_NONE,
.DataMode = QSPI_DATA_NONE,
.DdrMode = QSPI_DDR_MODE_DISABLE,
.DdrHoldHalfCycle = QSPI_DDR_HHC_ANALOG_DELAY,
.SIOOMode = QSPI_SIOO_INST_EVERY_CMD,
.AddressMode = QSPI_ADDRESS_NONE,
.Instruction = CMD_WRITE_ENABLE; // 0x06
.Address = 0x000000;
.DummyCycles = 0;
.NbData = 0;I'm sending it with
status = HAL_QSPI_Command(&hqspi, cmd, DEFAULT_TIMEOUT_MS);For good measure, here's my QSPI base config
hqspi.Instance = QUADSPI;
hqspi.Init.ClockPrescaler = 1;
hqspi.Init.FifoThreshold = 8;
hqspi.Init.SampleShifting = QSPI_SAMPLE_SHIFTING_NONE;
hqspi.Init.FlashSize = 23; // 128 Mb = 16MB -> 24 bits of address space. 24 - 1 = 23
hqspi.Init.ChipSelectHighTime = QSPI_CS_HIGH_TIME_1_CYCLE;
hqspi.Init.ClockMode = QSPI_CLOCK_MODE_0;
hqspi.Init.FlashID = QSPI_FLASH_ID_1;
hqspi.Init.DualFlash = QSPI_DUALFLASH_DISABLE;While I can read from the registers just fine (which otherwise indicates the connections and configuration is sound) here's what shows up on my scope when I issue the write enable command. An extra byte is sent before CS goes high again, which I believe is causing the write enable command to fail. I know it fails because subsequent register reads via auto-polling show the write enable bit has not latched. I've been at this for hours and cannot find a way to just sent a single instruction byte! 
The flash datasheet (Winbond W25Q128JV) clearly specifies that the write enable command should be 0x06 bounded by CS transitions

Finally, this part had the Quad Enable bit baked in high, so the WP pin is not used, but I have tried this with the WP pin pulled up just to be sure.
Even configuring the command as QSPI_INSTRUCTION_NONE with QSPI_DATA_1_LINE then trying to manually send the 0x06 as a 1 byte transfer with the HAL_QSPI_Transmit function just sends those in reverse. It's like the HAL_QSPI_Command function is determined to send a byte of 0x00 no matter how it is configured. Really hoping this can be answered by someone.
Thank you!
