root/platform/a3000/sub/100c/boot.c

/* [<][>][^][v][top][bottom][index][help] */

DEFINITIONS

This source file includes following definitions.
  1. taskCreateHook
  2. taskCreateHook2
  3. boot
  4. sub_FFC00358_my
  5. sub_FFC0119C_my
  6. sub_FFC05E5C_my
  7. taskcreate_Startup_my
  8. task_Startup_my
  9. spytask
  10. CreateTask_spytask
  11. CreateTask_PhySw
  12. init_file_modules_task
  13. sub_FFC6CF5C_my
  14. sub_FFC52014_my
  15. sub_FFC51C3C_my
  16. sub_FFC5195C_my

   1 #include "lolevel.h"
   2 #include "platform.h"
   3 #include "core.h"
   4 #include "stdlib.h"
   5 #include "dryos31.h"
   6 #define offsetof(TYPE, MEMBER) ((int) &((TYPE *)0)->MEMBER)
   7 const char * const new_sa = &_end;
   8 
   9 
  10 // Forward declarations
  11 void CreateTask_PhySw();
  12 void CreateTask_spytask();
  13 void task_CaptSeqTask_my();
  14 void taskCreateHook(int *p) { 
  15 p-=17;
  16 if (p[0]==0xFFC736C4)  p[0]=(int)init_file_modules_task; // 1.00c *
  17 if (p[0]==0xFFC5C1E8)  p[0]=(int)task_CaptSeqTask_my; // 1.00c *
  18 if (p[0]==0xFFC95048)  p[0]=(int)exp_drv_task; // 1.00c *
  19 if (p[0]==0xFFD138CC)  p[0]=(int)movie_record_task; // 1.00c *
  20 }
  21 
  22 void taskCreateHook2(int *p) { 
  23 p-=17;
  24 if (p[0]==0xFFC736C4)  p[0]=(int)init_file_modules_task;
  25 if (p[0]==0xFFC95048)  p[0]=(int)exp_drv_task;
  26 }
  27 
  28 
  29 void __attribute__((naked,noinline)) boot() {
  30 
  31     asm volatile (
  32         "LDR     R1, =0xC0410000\n"
  33         "MOV     R0, #0\n"
  34         "STR     R0, [R1]\n"
  35         "MOV     R1, #0x78\n"
  36 "loc_FFC0001C:\n"
  37         "MCR     p15, 0, R1,c1,c0\n"
  38         "MOV     R1, #0\n"
  39         "MCR     p15, 0, R1,c7,c10, 4\n"
  40 "loc_FFC00028:\n"
  41         "MCR     p15, 0, R1,c7,c5\n"
  42         "MCR     p15, 0, R1,c7,c6\n"
  43         "MOV     R0, #0x3D\n"
  44         "MCR     p15, 0, R0,c6,c0\n"
  45         "MOV     R0, #0xC000002F\n"
  46         "MCR     p15, 0, R0,c6,c1\n"
  47         "MOV     R0, #0x31\n"
  48         "MCR     p15, 0, R0,c6,c2\n"
  49         "LDR     R0, =0x10000031\n"
  50         "MCR     p15, 0, R0,c6,c3\n"
  51         "MOV     R0, #0x40000017\n"
  52         "MCR     p15, 0, R0,c6,c4\n"
  53         "LDR     R0, =0xFFC0002B\n"
  54         "MCR     p15, 0, R0,c6,c5\n"
  55         "MOV     R0, #0x34\n"
  56         "MCR     p15, 0, R0,c2,c0\n"
  57         "MOV     R0, #0x34\n"
  58         "MCR     p15, 0, R0,c2,c0, 1\n"
  59         "MOV     R0, #0x34\n"
  60         "MCR     p15, 0, R0,c3,c0\n"
  61         "LDR     R0, =0x3333330\n"
  62         "MCR     p15, 0, R0,c5,c0, 2\n"
  63         "LDR     R0, =0x3333330\n"
  64         "MCR     p15, 0, R0,c5,c0, 3\n"
  65         "MRC     p15, 0, R0,c1,c0\n"
  66         "ORR     R0, R0, #0x1000\n"
  67         "ORR     R0, R0, #4\n"
  68         "ORR     R0, R0, #1\n"
  69         "MCR     p15, 0, R0,c1,c0\n"
  70         "MOV     R1, #0x40000006\n"
  71         "MCR     p15, 0, R1,c9,c1\n"
  72         "MOV     R1, #6\n"
  73         "MCR     p15, 0, R1,c9,c1, 1\n"
  74         "MRC     p15, 0, R1,c1,c0\n"
  75         "ORR     R1, R1, #0x50000\n"
  76         "MCR     p15, 0, R1,c1,c0\n"
  77         "LDR     R2, =0xC0200000\n"
  78         "MOV     R1, #1\n"
  79         "STR     R1, [R2,#0x10C]\n"
  80         "MOV     R1, #0xFF\n"
  81         "STR     R1, [R2,#0xC]\n"
  82         "STR     R1, [R2,#0x1C]\n"
  83         "STR     R1, [R2,#0x2C]\n"
  84         "STR     R1, [R2,#0x3C]\n"
  85         "STR     R1, [R2,#0x4C]\n"
  86         "STR     R1, [R2,#0x5C]\n"
  87         "STR     R1, [R2,#0x6C]\n"
  88         "STR     R1, [R2,#0x7C]\n"
  89         "STR     R1, [R2,#0x8C]\n"
  90         "STR     R1, [R2,#0x9C]\n"
  91         "STR     R1, [R2,#0xAC]\n"
  92         "STR     R1, [R2,#0xBC]\n"
  93         "STR     R1, [R2,#0xCC]\n"
  94         "STR     R1, [R2,#0xDC]\n"
  95         "STR     R1, [R2,#0xEC]\n"
  96         "STR     R1, [R2,#0xFC]\n"
  97         "LDR     R1, =0xC0400008\n"
  98         "LDR     R2, =0x430005\n"
  99         "STR     R2, [R1]\n"
 100         "MOV     R1, #1\n"
 101         "LDR     R2, =0xC0243100\n"
 102         "STR     R2, [R1]\n"
 103         "LDR     R2, =0xC0242010\n"
 104         "LDR     R1, [R2]\n"
 105         "ORR     R1, R1, #1\n"
 106         "STR     R1, [R2]\n"
 107         "LDR     R0, =0xFFF036C8\n"
 108         "LDR     R1, =0x1900\n"
 109         "LDR     R3, =0xB294\n"
 110 "loc_FFC0013C:\n"
 111         "CMP     R1, R3\n"
 112         "LDRCC   R2, [R0],#4\n"
 113         "STRCC   R2, [R1],#4\n"
 114         "BCC     loc_FFC0013C\n"
 115         "LDR     R1, =0x133D38\n"
 116         "MOV     R2, #0\n"
 117 "loc_FFC00154:\n"
 118         "CMP     R3, R1\n"
 119         "STRCC   R2, [R3],#4\n"
 120         "BCC     loc_FFC00154\n"
 121 //        "B       loc_FFC00358\n"
 122                 "B       sub_FFC00358_my\n" // ---------------->
 123     );
 124 };
 125 
 126 void __attribute__((naked,noinline)) sub_FFC00358_my() {
 127     *(int*)0x1930=(int)taskCreateHook; 
 128     *(int*)0x1934=(int)taskCreateHook2; 
 129     *(int*)0x1938=(int)taskCreateHook;          
 130 
 131     /* Power ON/OFF detection */
 132         *(int*)(0x21B4)= (*(int*)0xC02200A8)&1 ? 0x200000 : 0x100000; // @ FFC43E14 replacement  for correct power-on.
 133 
 134                 asm volatile (
 135 "loc_FFC00358:\n"
 136         "LDR     R0, =0xFFC003D0\n"
 137         "MOV     R1, #0\n"
 138         "LDR     R3, =0xFFC00408\n"
 139 "loc_FFC00364:\n"
 140         "CMP     R0, R3\n"
 141         "LDRCC   R2, [R0],#4\n"
 142         "STRCC   R2, [R1],#4\n"
 143         "BCC     loc_FFC00364\n"
 144         "LDR     R0, =0xFFC00408\n"
 145         "MOV     R1, #0x4B0\n"
 146         "LDR     R3, =0xFFC0061C\n"
 147 "loc_FFC00380:\n"
 148         "CMP     R0, R3\n"
 149         "LDRCC   R2, [R0],#4\n"
 150         "STRCC   R2, [R1],#4\n"
 151         "BCC     loc_FFC00380\n"
 152         "MOV     R0, #0xD2\n"
 153         "MSR     CPSR_cxsf, R0\n"
 154         "MOV     SP, #0x1000\n"
 155         "MOV     R0, #0xD3\n"
 156         "MSR     CPSR_cxsf, R0\n"
 157         "MOV     SP, #0x1000\n"
 158         "LDR     R0, =0x6C4\n"
 159         "LDR     R2, =0xEEEEEEEE\n"
 160         "MOV     R3, #0x1000\n"
 161 "loc_FFC003B4:\n"
 162         "CMP     R0, R3\n"
 163         "STRCC   R2, [R0],#4\n"
 164         "BCC     loc_FFC003B4\n"
 165         //"BL      sub_FFC0119C\n"
 166         "BL      sub_FFC0119C_my\n"
 167 /*
 168 "loc_FFC003C4:\n"
 169         "ANDEQ   R0, R0, R4,ASR#13\n"
 170 "loc_FFC003C8:\n"
 171         "ANDEQ   R0, R0, R0,ROR R6\n"
 172 "loc_FFC003CC:\n"
 173         "ANDEQ   R0, R0, R4,ROR R6\n"
 174         "NOP\n"
 175         "LDR     PC, =0xFFC0061C\n"
 176 */
 177   );                            
 178 };
 179 
 180 
 181 void __attribute__((naked,noinline)) sub_FFC0119C_my() { 
 182         asm volatile (
 183         "STR     LR, [SP,#-4]!\n"
 184         "SUB     SP, SP, #0x74\n"
 185         "MOV     R0, SP\n"
 186         "MOV     R1, #0x74\n"
 187         "BL      sub_FFE8D838\n"
 188         "MOV     R0, #0x53000\n"
 189         "STR     R0, [SP,#4]\n"
 190 #if defined(CHDK_NOT_IN_CANON_HEAP)
 191         "LDR     R0, =0x133D38\n"
 192 #else
 193                  "LDR     R0, =new_sa\n"        // +
 194                  "LDR     R0, [R0]\n"           // +    
 195 #endif
 196         "LDR     R2, =0x279C00\n"
 197         "LDR     R1, =0x2724A8\n"
 198         "STR     R0, [SP,#8]\n"
 199         "SUB     R0, R1, R0\n"
 200         "ADD     R3, SP, #0xC\n"
 201         "STR     R2, [SP]\n"
 202         "STMIA   R3, {R0-R2}\n"
 203         "MOV     R0, #0x22\n"
 204         "STR     R0, [SP,#0x18]\n"
 205         "MOV     R0, #0x68\n"
 206         "STR     R0, [SP,#0x1C]\n"
 207         "LDR     R0, =0x19B\n"
 208         //"LDR     R1, =sub_FFC05E5C\n"
 209                 "LDR     R1, =sub_FFC05E5C_my\n"
 210         "LDR     PC, =0xffc011f0\n" // jump back to fw
 211 /*
 212         "STR     R0, [SP,#0x20]\n"
 213         "MOV     R0, #0x96\n"
 214         "STR     R0, [SP,#0x24]\n"
 215         "MOV     R0, #0x78\n"
 216         "STR     R0, [SP,#0x28]\n"
 217         "MOV     R0, #0x64\n"
 218         "STR     R0, [SP,#0x2C]\n"
 219         "MOV     R0, #0\n"
 220         "STR     R0, [SP,#0x30]\n"
 221         "STR     R0, [SP,#0x34]\n"
 222         "MOV     R0, #0x10\n"
 223         "STR     R0, [SP,#0x5C]\n"
 224         "MOV     R0, #0x800\n"
 225         "STR     R0, [SP,#0x60]\n"
 226         "MOV     R0, #0xA0\n"
 227         "STR     R0, [SP,#0x64]\n"
 228         "MOV     R0, #0x280\n"
 229         "STR     R0, [SP,#0x68]\n"
 230         "MOV     R0, SP\n"
 231         "MOV     R2, #0\n"
 232         "BL      sub_FFC03408\n"
 233         "ADD     SP, SP, #0x74\n"
 234         "LDR     PC, [SP],#4\n"
 235 */
 236         );
 237 }; 
 238 
 239 void __attribute__((naked,noinline)) sub_FFC05E5C_my() {
 240         asm volatile (
 241         "STMFD   SP!, {R4,LR}\n"
 242         "BL      sub_FFC00B24\n"
 243         "BL      sub_FFC0A838\n"
 244         "CMP     R0, #0\n"
 245         "LDRLT   R0, =0xFFC05F70\n"
 246         "BLLT    sub_FFC05F50\n"
 247         "BL      sub_FFC05A98\n"
 248         "CMP     R0, #0\n"
 249         "LDRLT   R0, =0xFFC05F78\n"
 250         "BLLT    sub_FFC05F50\n"
 251         "LDR     R0, =0xFFC05F88\n"
 252         "BL      sub_FFC05B80\n"
 253         "CMP     R0, #0\n"
 254         "LDRLT   R0, =0xFFC05F90\n"
 255         "BLLT    sub_FFC05F50\n"
 256         "LDR     R0, =0xFFC05F88\n"
 257         "BL      sub_FFC03BF4\n"
 258         "CMP     R0, #0\n"
 259         "LDRLT   R0, =0xFFC05FA4\n"
 260         "BLLT    sub_FFC05F50\n"
 261         "BL      sub_FFC0A230\n"
 262         "CMP     R0, #0\n"
 263         "LDRLT   R0, =0xFFC05FB0\n"
 264         "BLLT    sub_FFC05F50\n"
 265         "BL      sub_FFC01680\n"
 266         "CMP     R0, #0\n"
 267         "LDRLT   R0, =0xFFC05FBC\n"
 268         "BLLT    sub_FFC05F50\n"
 269         "LDMFD   SP!, {R4,LR}\n"
 270 //      "B       sub_FFC105BC\n"
 271                 "B       taskcreate_Startup_my\n" //---------->    
 272                         );     
 273 }; 
 274 
 275 
 276 void __attribute__((naked,noinline)) taskcreate_Startup_my() { 
 277         asm volatile (  
 278         "STMFD   SP!, {R3,LR}\n"
 279         "BL      sub_FFC23A78\n"
 280         "BL      sub_FFC2AF84\n"
 281         "CMP     R0, #0\n"
 282         "BNE     loc_FFC105F8\n"
 283         "BL      sub_FFC2526C\n"
 284         "CMP     R0, #0\n"
 285         "BEQ     loc_FFC105F8\n"
 286         "BL      sub_FFC23A74\n"
 287         "CMP     R0, #0\n"
 288         "BNE     loc_FFC105F8\n"
 289         "LDR     R1, =0xC0220000\n"
 290         "MOV     R0, #0x44\n"
 291         "STR     R0, [R1,#0x48]\n"
 292 "loc_FFC105F4:\n"
 293         "B       loc_FFC105F4\n"
 294 "loc_FFC105F8:\n"
 295         //"BL      sub_FFC23A80\n" // removed, see boot() function              
 296         "BL      sub_FFC23A7C\n"
 297         "BL      sub_FFC293A8\n"
 298         "LDR     R1, =0x2CE000\n"
 299         "MOV     R0, #0\n"
 300         "BL      sub_FFC295F0\n"
 301         "BL      sub_FFC2959C    \n"
 302         "MOV     R3, #0\n"
 303         "STR     R3, [SP]\n"
 304         //"ADR     R3, sub_FFC10560\n"
 305         "LDR     R3, =task_Startup_my\n" //+ ----------->                       
 306         "MOV     R2, #0\n"
 307         "MOV     R1, #0x19\n"
 308         "LDR     R0, =0xFFC10640\n"
 309         "BL      sub_FFC0F110    \n"
 310         "MOV     R0, #0\n"
 311         "LDMFD   SP!, {R12,PC}\n"
 312  );
 313 }; 
 314 
 315 
 316 void __attribute__((naked,noinline)) task_Startup_my() { 
 317         asm volatile (
 318         "STMFD   SP!, {R4,LR}\n"
 319         "BL      sub_FFC06228\n"
 320         "BL      sub_FFC24B7C\n"
 321         "BL      sub_FFC23414\n"
 322         "BL      sub_FFC2AFC4\n"
 323         "BL      sub_FFC2B1B0\n"
 324         //"BL      sub_FFC2B058\n" // Skip starting diskboot.bin again
 325         "BL      sub_FFC2B34C\n"
 326         "BL      sub_FFC2B1E0\n"
 327         "BL      sub_FFC28840\n"
 328         "BL      sub_FFC2B350\n"
 329         //"BL      sub_FFC23968\n"
 330         );               
 331         CreateTask_PhySw(); // +
 332         CreateTask_spytask();  // +
 333     asm volatile (              
 334         "BL      sub_FFC26EA8\n"
 335         "BL      sub_FFC2B368\n"
 336         "BL      sub_FFC222BC\n"
 337         "BL      sub_FFC22E6C    \n"
 338         "BL      sub_FFC2AD5C\n"
 339         "BL      sub_FFC233C8\n"
 340         "BL      sub_FFC22E08\n"
 341         "BL      sub_FFC2BDCC\n"
 342         "BL      sub_FFC22DE0\n"
 343         "LDMFD   SP!, {R4,LR}\n"
 344         "B       sub_FFC06128    \n"
 345         );
 346 }; 
 347 
 348 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
 349 {
 350     core_spytask();
 351 }
 352 void CreateTask_spytask() { 
 353         _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
 354 };
 355 
 356 void __attribute__((naked,noinline)) CreateTask_PhySw() {
 357         asm volatile ( 
 358         "STMFD   SP!, {R3-R5,LR}\n"
 359         "LDR     R4, =0x1BE4\n"
 360         "LDR     R0, [R4,#0x10]\n"
 361         "CMP     R0, #0\n"
 362         "BNE     loc_FFC2399C\n"
 363         "MOV     R3, #0\n"
 364         "STR     R3, [SP]\n"
 365         //"ADR     R3, sub_FFC23934\n"
 366         //"MOV     R2, #0x800\n"
 367         "LDR     R3, =mykbd_task\n"  // task_phySw
 368                     "MOV     R2, #0x2000\n"             // greater Stacksize        
 369         "MOV     R1, #0x17\n"
 370         "LDR     R0, =0xFFC23B70\n"
 371         "BL      sub_FFC0F3E8    \n"
 372         "STR     R0, [R4,#0x10]\n"
 373 "loc_FFC2399C:\n"
 374         "BL      sub_FFC6AA64\n"
 375         "BL      sub_FFC251E4\n"
 376         "CMP     R0, #0\n"
 377         "LDREQ   R1, =0x2EEE0\n"
 378         "LDMEQFD SP!, {R3-R5,LR}\n"
 379         "BEQ     sub_FFC6A9EC\n"
 380         "LDMFD   SP!, {R3-R5,PC}\n"
 381         );
 382 };
 383 
 384 void __attribute__((naked,noinline)) init_file_modules_task() { 
 385   asm volatile (
 386         "STMFD   SP!, {R4-R6,LR}\n"
 387         "BL      sub_FFC6CF30\n"
 388         "LDR     R5, =0x5006\n"
 389         "MOVS    R4, R0\n"
 390         "MOVNE   R1, #0\n"
 391         "MOVNE   R0, R5\n"
 392         "BLNE    sub_FFC6F7EC\n"
 393         //"BL      sub_FFC6CF5C\n"
 394         "BL      sub_FFC6CF5C_my\n"
 395                         "BL      core_spytask_can_start\n"      // +                    
 396         "CMP     R4, #0\n"
 397         "MOVEQ   R0, R5\n"
 398         "LDMEQFD SP!, {R4-R6,LR}\n"
 399         "MOVEQ   R1, #0\n"
 400         "BEQ     sub_FFC6F7EC\n"
 401         "LDMFD   SP!, {R4-R6,PC}\n"
 402  );
 403 }; 
 404 
 405 void __attribute__((naked,noinline)) sub_FFC6CF5C_my() { 
 406  asm volatile (
 407         "STMFD   SP!, {R4,LR}\n"
 408         "MOV     R0, #3\n"
 409         //"BL      sub_FFC52014    \n"
 410                                 "BL      sub_FFC52014_my\n"        
 411         "LDR     PC,=0xffc6cf68\n" // jump back to firmware
 412         /*
 413         "BL      sub_FFCFE338\n"
 414         "LDR     R4, =0x2B70\n"
 415         "LDR     R0, [R4,#4]\n"
 416         "CMP     R0, #0\n"
 417         "BNE     loc_FFC6CF94\n"
 418         "BL      sub_FFC5125C\n"
 419         "BL      sub_FFCF4908\n"
 420         "BL      sub_FFC5125C\n"
 421         "BL      sub_FFC4DCD4\n"
 422         "BL      sub_FFC5115C\n"
 423         "BL      sub_FFCF499C\n"
 424 "loc_FFC6CF94:\n"
 425         "MOV     R0, #1\n"
 426         "STR     R0, [R4]\n"
 427         "LDMFD   SP!, {R4,PC}\n"
 428 */
 429  );
 430 }; 
 431 
 432 
 433 void __attribute__((naked,noinline)) sub_FFC52014_my() {
 434  asm volatile (
 435         "STMFD   SP!, {R4-R8,LR}\n"
 436         "MOV     R8, R0\n"
 437         "BL      sub_FFC51F94    \n"
 438         "LDR     R1, =0x33688\n"
 439         "MOV     R6, R0\n"
 440         "ADD     R4, R1, R0,LSL#7\n"
 441         "LDR     R0, [R4,#0x6C]\n"
 442         "CMP     R0, #4\n"
 443         "LDREQ   R1, =0x817\n"
 444         "LDREQ   R0, =0xFFC51AD4\n"
 445         "BLEQ    sub_FFC0F5E8\n"
 446         "MOV     R1, R8\n"
 447         "MOV     R0, R6\n"
 448         "BL      sub_FFC5184C    \n"
 449         "LDR     R0, [R4,#0x38]\n"
 450         "BL      sub_FFC526B4\n"
 451         "CMP     R0, #0\n"
 452         "STREQ   R0, [R4,#0x6C]\n"
 453         "MOV     R0, R6\n"
 454         "BL      sub_FFC518DC\n"
 455         "MOV     R0, R6\n"
 456         //"BL      sub_FFC51C3C\n"
 457                                 "BL      sub_FFC51C3C_my\n" //------------->                    
 458         "LDR     PC, =0xffc5206c\n" // jump back to firmware
 459 /*
 460         "MOV     R5, R0\n"
 461         "MOV     R0, R6\n"
 462         "BL      sub_FFC51E6C    \n"
 463         "LDR     R6, [R4,#0x3C]\n"
 464         "AND     R7, R5, R0\n"
 465         "CMP     R6, #0\n"
 466         "LDR     R1, [R4,#0x38]\n"
 467         "MOVEQ   R0, #0x80000001\n"
 468         "MOV     R5, #0\n"
 469         "BEQ     loc_FFC520C4\n"
 470         "MOV     R0, R1\n"
 471         "BL      sub_FFC513C4\n"
 472         "CMP     R0, #0\n"
 473         "MOVNE   R5, #4\n"
 474         "CMP     R6, #5\n"
 475         "ORRNE   R0, R5, #1\n"
 476         "BICEQ   R0, R5, #1\n"
 477         "CMP     R7, #0\n"
 478         "BICEQ   R0, R0, #2\n"
 479         "ORREQ   R0, R0, #0x80000000\n"
 480         "BICNE   R0, R0, #0x80000000\n"
 481         "ORRNE   R0, R0, #2\n"
 482 "loc_FFC520C4:\n"
 483         "CMP     R8, #7\n"
 484         "STR     R0, [R4,#0x40]\n"
 485         "LDMNEFD SP!, {R4-R8,PC}\n"
 486         "MOV     R0, R8\n"
 487         "BL      sub_FFC51FE4\n"
 488         "CMP     R0, #0\n"
 489         "LDMEQFD SP!, {R4-R8,LR}\n"
 490         "LDREQ   R0, =0xFFC52110\n"
 491         "BEQ     sub_FFC01780\n"
 492         "LDMFD   SP!, {R4-R8,PC}\n"
 493 */
 494  );
 495 }; 
 496 
 497 void __attribute__((naked,noinline)) sub_FFC51C3C_my() {
 498 
 499  asm volatile (
 500         "STMFD   SP!, {R4-R6,LR}\n"
 501         "MOV     R5, R0\n"
 502         "LDR     R0, =0x33688\n"
 503         "ADD     R4, R0, R5,LSL#7\n"
 504         "LDR     R0, [R4,#0x6C]\n"
 505         "TST     R0, #2\n"
 506         "MOVNE   R0, #1\n"
 507         "LDMNEFD SP!, {R4-R6,PC}\n"
 508         "LDR     R0, [R4,#0x38]\n"
 509         "MOV     R1, R5\n"
 510         //"BL      sub_FFC5195C    \n"
 511         "BL      sub_FFC5195C_my\n" // ------------------>                      
 512         "LDR     PC,=0xffc51c68\n" // jump back to fw
 513 /*
 514         "CMP     R0, #0\n"
 515         "LDRNE   R0, [R4,#0x38]\n"
 516         "MOVNE   R1, R5\n"
 517         "BLNE    sub_FFC51AF8    \n"
 518         "LDR     R2, =0x33708\n"
 519         "ADD     R1, R5, R5,LSL#4\n"
 520         "LDR     R1, [R2,R1,LSL#2]\n"
 521         "CMP     R1, #4\n"
 522         "BEQ     loc_FFC51C9C\n"
 523         "CMP     R0, #0\n"
 524         "LDMEQFD SP!, {R4-R6,PC}\n"
 525         "MOV     R0, R5\n"
 526         "BL      sub_FFC51454\n"
 527 "loc_FFC51C9C:\n"
 528         "CMP     R0, #0\n"
 529         "LDRNE   R1, [R4,#0x6C]\n"
 530         "ORRNE   R1, R1, #2\n"
 531         "STRNE   R1, [R4,#0x6C]\n"
 532         "LDMFD   SP!, {R4-R6,PC}\n"
 533 */
 534  );
 535 };
 536 
 537 
 538 void __attribute__((naked,noinline)) sub_FFC5195C_my() {
 539  asm volatile ( 
 540         "STMFD   SP!, {R4-R10,LR}\n"
 541         "MOV     R9, R0\n"
 542         "LDR     R0, =0x33688\n"
 543         "MOV     R8, #0\n"
 544         "ADD     R5, R0, R1,LSL#7\n"
 545         "LDR     R0, [R5,#0x3C]\n"
 546         "MOV     R7, #0\n"
 547         "CMP     R0, #7\n"
 548         "MOV     R6, #0\n"
 549         "ADDLS   PC, PC, R0,LSL#2\n"
 550         "B       loc_FFC51AB4\n"
 551 "loc_FFC51988:\n"
 552         "B       loc_FFC519C0\n"
 553 "loc_FFC5198C:\n"
 554         "B       loc_FFC519A8\n"
 555 "loc_FFC51990:\n"
 556         "B       loc_FFC519A8\n"
 557 "loc_FFC51994:\n"
 558         "B       loc_FFC519A8\n"
 559 "loc_FFC51998:\n"
 560         "B       loc_FFC519A8\n"
 561 "loc_FFC5199C:\n"
 562         "B       loc_FFC51AAC\n"
 563 "loc_FFC519A0:\n"
 564         "B       loc_FFC519A8\n"
 565 "loc_FFC519A4:\n"
 566         "B       loc_FFC519A8\n"
 567 "loc_FFC519A8:\n"
 568         "MOV     R2, #0\n"
 569         "MOV     R1, #0x200\n"
 570         "MOV     R0, #2\n"
 571         "BL      sub_FFC6715C\n"
 572         "MOVS    R4, R0\n"
 573         "BNE     loc_FFC519C8\n"
 574 "loc_FFC519C0:\n"
 575         "MOV     R0, #0\n"
 576         "LDMFD   SP!, {R4-R10,PC}\n"
 577 "loc_FFC519C8:\n"
 578         "LDR     R12, [R5,#0x50]\n"
 579         "MOV     R3, R4\n"
 580         "MOV     R2, #1\n"
 581         "MOV     R1, #0\n"
 582         "MOV     R0, R9\n"
 583         "BLX     R12\n"
 584         "CMP     R0, #1\n"
 585         "BNE     loc_FFC519F4\n"
 586         "MOV     R0, #2\n"
 587         "BL      sub_FFC672A8    \n"
 588         "B       loc_FFC519C0\n"
 589 "loc_FFC519F4:\n"
 590         "LDR     R1, [R5,#0x64]\n"
 591         "MOV     R0, R9\n"
 592         "BLX     R1\n"
 593                 
 594                "MOV   R1, R4\n"           //  pointer to MBR in R1
 595 //                              "BL    mbr_read_dryos\n"   //  total sectors count in R0 before and after call
 596 
 597                 // Start of DataGhost's FAT32 autodetection code
 598                 // Policy: If there is a partition which has type W95 FAT32, use the first one of those for image storage
 599                 // According to the code below, we can use R1, R2, R3 and R12.
 600                 // LR wasn't really used anywhere but for storing a part of the partition signature. This is the only thing
 601                 // that won't work with an offset, but since we can load from LR+offset into LR, we can use this to do that :)
 602                 "MOV     R12, R4\n"                    // Copy the MBR start address so we have something to work with
 603                 "MOV     LR, R4\n"                     // Save old offset for MBR signature
 604                 "MOV     R1, #1\n"                     // Note the current partition number
 605                 "B       dg_sd_fat32_enter\n"          // We actually need to check the first partition as well, no increments yet!
 606            "dg_sd_fat32:\n"
 607                 "CMP     R1, #4\n"                     // Did we already see the 4th partition?
 608                 "BEQ     dg_sd_fat32_end\n"            // Yes, break. We didn't find anything, so don't change anything.
 609                 "ADD     R12, R12, #0x10\n"            // Second partition
 610                 "ADD     R1, R1, #1\n"                 // Second partition for the loop
 611            "dg_sd_fat32_enter:\n"
 612                 "LDRB    R2, [R12, #0x1BE]\n"          // Partition status
 613                 "LDRB    R3, [R12, #0x1C2]\n"          // Partition type (FAT32 = 0xB)
 614                 "CMP     R3, #0xB\n"                   // Is this a FAT32 partition?
 615                 "CMPNE   R3, #0xC\n"                   // Not 0xB, is it 0xC (FAT32 LBA) then?
 616                 "BNE     dg_sd_fat32\n"                // No, it isn't.
 617                 "CMP     R2, #0x00\n"                  // It is, check the validity of the partition type
 618                 "CMPNE   R2, #0x80\n"
 619                 "BNE     dg_sd_fat32\n"                // Invalid, go to next partition
 620                                                        // This partition is valid, it's the first one, bingo!
 621                 "MOV     R4, R12\n"                    // Move the new MBR offset for the partition detection.
 622                 
 623            "dg_sd_fat32_end:\n"
 624                 // End of DataGhost's FAT32 autodetection code    
 625                 
 626         "LDRB    R1, [R4,#0x1C9]\n"
 627         "LDRB    R3, [R4,#0x1C8]\n"
 628         "LDRB    R12, [R4,#0x1CC]\n"
 629         "MOV     R1, R1,LSL#24\n"
 630         "ORR     R1, R1, R3,LSL#16\n"
 631         "LDRB    R3, [R4,#0x1C7]\n"
 632         "LDRB    R2, [R4,#0x1BE]\n"
 633         //"LDRB    LR, [R4,#0x1FF]\n" // replaced, see below            
 634         "ORR     R1, R1, R3,LSL#8\n"
 635         "LDRB    R3, [R4,#0x1C6]\n"
 636         "CMP     R2, #0\n"
 637         "CMPNE   R2, #0x80\n"
 638         "ORR     R1, R1, R3\n"
 639         "LDRB    R3, [R4,#0x1CD]\n"
 640         "MOV     R3, R3,LSL#24\n"
 641         "ORR     R3, R3, R12,LSL#16\n"
 642         "LDRB    R12, [R4,#0x1CB]\n"
 643         "ORR     R3, R3, R12,LSL#8\n"
 644         "LDRB    R12, [R4,#0x1CA]\n"
 645         "ORR     R3, R3, R12\n"
 646         //"LDRB    R12, [R4,#0x1FE]\n" // replaced, see below
 647         "LDRB    R12, [LR,#0x1FE]\n"        // New! First MBR signature byte (0x55)
 648         "LDRB    LR, [LR,#0x1FF]\n"         //      Last MBR signature byte (0xAA)      
 649         "BNE     loc_FFC51A80\n"
 650         "CMP     R0, R1\n"
 651         "BCC     loc_FFC51A80\n"
 652         "ADD     R2, R1, R3\n"
 653         "CMP     R2, R0\n"
 654         "CMPLS   R12, #0x55\n"
 655         "CMPEQ   LR, #0xAA\n"
 656         "MOVEQ   R7, R1\n"
 657         "MOVEQ   R6, R3\n"
 658         "MOVEQ   R4, #1\n"
 659         "BEQ     loc_FFC51A84\n"
 660 "loc_FFC51A80:\n"
 661         "MOV     R4, R8\n"
 662 "loc_FFC51A84:\n"
 663         "MOV     R0, #2\n"
 664         "BL      sub_FFC672A8    \n"
 665         "CMP     R4, #0\n"
 666         "BNE     loc_FFC51AC0\n"
 667         "LDR     R1, [R5,#0x64]\n"
 668         "MOV     R7, #0\n"
 669         "MOV     R0, R9\n"
 670         "BLX     R1\n"
 671         "MOV     R6, R0\n"
 672         "B       loc_FFC51AC0\n"
 673 "loc_FFC51AAC:\n"
 674         "MOV     R6, #0x40\n"
 675         "B       loc_FFC51AC0\n"
 676 "loc_FFC51AB4:\n"
 677         "LDR     R1, =0x572\n"
 678         "LDR     R0, =0xFFC51AD4\n"
 679         "BL      sub_FFC0F5E8\n"
 680 "loc_FFC51AC0:\n"
 681         "STR     R7, [R5,#0x44]!\n"
 682         "STMIB   R5, {R6,R8}\n"
 683         "MOV     R0, #1\n"
 684         "LDMFD   SP!, {R4-R10,PC}\n"
 685  );
 686 }; 
 687 

/* [<][>][^][v][top][bottom][index][help] */