This source file includes following definitions.
- spytask
- CreateTask_spytask
- boot
- CreateTask_my
- sub_fc04f194_my
- sub_fc04f324_my
- sub_fc04f72a_my
- sub_fc060338_my
- sub_fc04f6c4_my
- sub_fc06021a_my
- init_file_modules_task
- kbd_p2_f_my
- sub_fc060900_my
- tricinittask
- update_url
- agps_downloader_task
1
2 #include "lolevel.h"
3 #include "platform.h"
4 #include "core.h"
5 #include "dryos31.h"
6
7 #define offsetof(TYPE, MEMBER) ((int) &((TYPE *)0)->MEMBER)
8
9 const char * const new_sa = &_end;
10
11
12 extern volatile int jogdial_stopped;
13 void JogDial_task_my(void);
14
15 extern void task_CaptSeq();
16 extern void task_InitFileModules();
17 extern void task_RotaryEncoder();
18 extern void task_MovieRecord();
19 extern void task_ExpDrv();
20 extern void task_AGPSDownloader();
21
22
23
24
25 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
26 {
27 (void)ua; (void)ub; (void)uc; (void)ud; (void)ue; (void)uf;
28 core_spytask();
29 }
30
31
32
33
34 void CreateTask_spytask()
35 {
36 _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
37 }
38
39
40
41
42
43
44
45
46
47
48
49
50
51 void __attribute__((naked,noinline)) boot() {
52 asm volatile (
53 " ldr.w sp, =0x80010000\n"
54 " BL sub_fc020064\n"
55 " ldr r2, =0xc0242010\n"
56 " ldr r1, [r2, #0]\n"
57 " orr.w r1, r1, #1\n"
58 " str r1, [r2, #0]\n"
59 " ldr r0, =0xfc953974\n"
60 " ldr r1, =0x010c1000\n"
61 " ldr r3, =0x010e03c4\n"
62 " loc_fc020024:\n"
63 " cmp r1, r3\n"
64 " itt cc\n"
65 " ldrcc.w r2, [r0], #4\n"
66 " strcc.w r2, [r1], #4\n"
67 " bcc.n loc_fc020024\n"
68
69
70
71 "adr r0, patch_CreateTask\n"
72 "ldr r1, =hook_CreateTask\n"
73 "add r2, r0, #8\n"
74 "task_hook_loop:\n"
75 "ldrh r3, [r0],#2\n"
76 "strh r3, [r1],#2\n"
77 "cmp r0,r2\n"
78 "blo task_hook_loop\n"
79
80 " ldr r0, =0x010c1000\n"
81 " ldr r1, =0x0001f3c4\n"
82 " BL sub_fc12dd3a\n"
83 " ldr r0, =0xfc932514\n"
84 " ldr r1, =0x00008000\n"
85 " ldr r3, =0x00029460\n"
86 " loc_fc020040:\n"
87 " cmp r1, r3\n"
88 " itt cc\n"
89 " ldrcc.w r2, [r0], #4\n"
90 " strcc.w r2, [r1], #4\n"
91 " bcc.n loc_fc020040\n"
92 " ldr r3, =0x00029460\n"
93 " ldr r1, =0x002bd558\n"
94 " mov.w r2, #0\n"
95 " loc_fc020056:\n"
96 " cmp r3, r1\n"
97 " it cc\n"
98 " strcc.w r2, [r3], #4\n"
99 " bcc.n loc_fc020056\n"
100 " b.w sub_fc04f194_my\n"
101
102 "patch_CreateTask:\n"
103 "ldr.w pc, [pc,#0]\n"
104 ".long CreateTask_my + 1\n"
105 );
106 }
107
108
109 void __attribute__((naked,noinline)) CreateTask_my() {
110 asm volatile (
111 " push {r0}\n"
112
113 " ldr r0, =task_CaptSeq\n"
114 " cmp r0, r3\n"
115 " itt eq\n"
116 " ldreq r3, =capt_seq_task\n"
117 " orreq r3, #1\n"
118 " beq exitHook\n"
119
120 " LDR R0, =task_ExpDrv\n"
121 " CMP R0, R3\n"
122 " itt eq\n"
123 " LDREQ R3, =exp_drv_task\n"
124 " orreq r3, #1\n"
125 " BEQ exitHook\n"
126
127 " LDR R0, =task_DvlpSeqTask\n"
128 " CMP R0, R3\n"
129 " itt eq\n"
130 " LDREQ R3, =developseq_task\n"
131 " orreq r3, #1\n"
132 " BEQ exitHook\n"
133
134 " LDR R0, =task_TricInitTask\n"
135 " CMP R0, R3\n"
136 " itt eq\n"
137 " LDREQ R3, =tricinittask\n"
138 " orreq r3, #1\n"
139 " BEQ exitHook\n"
140
141 " LDR R0, =task_FileWrite\n"
142 " CMP R0, R3\n"
143 " itt eq\n"
144 " LDREQ R3, =filewritetask\n"
145 " orreq r3, #1\n"
146 " BEQ exitHook\n"
147
148 #if PLATFORMID == 12895
149 " LDR R0, =task_AGPSDownloader\n"
150 " CMP R0, R3\n"
151 " itt eq\n"
152 " LDREQ R3, =agps_downloader_task\n"
153 " orreq r3, #1\n"
154 " BEQ exitHook\n"
155 #endif
156
157
158 " LDR R0, =task_MovieRecord\n"
159 " CMP R0, R3\n"
160 " itt eq\n"
161 " LDREQ R3, =movie_record_task\n"
162 " orreq r3, #1\n"
163 " BEQ exitHook\n"
164
165
166 " ldr r0, =task_InitFileModules\n"
167 " cmp r0, r3\n"
168 " itt eq\n"
169 " ldreq r3, =init_file_modules_task\n"
170 " orreq r3, #1\n"
171 "exitHook:\n"
172
173 " pop {r0}\n"
174
175 " stmdb sp!, {r1, r2, r3, r4, r5, r6, r7, r8, r9, lr}\n"
176 " mov r4, r0\n"
177 " ldr r0, =0x8154\n"
178 " ldr.w pc, =(hook_CreateTask + 8 + 1) \n"
179 ".ltorg\n"
180 );
181 }
182
183
184 void __attribute__((naked,noinline)) sub_fc04f194_my() {
185
186 if (*(int*)(0xd20b0000 + 0x10 * 4) & 0x10000) {
187
188
189 *(int*)(0x92a0+0x4) = 0x200000;
190 }
191 else {
192
193 *(int*)(0x92a0+0x4) = 0x100000;
194 }
195 asm volatile (
196 "push {r4, lr}\n"
197 #if defined(CHDK_NOT_IN_CANON_HEAP)
198 "ldr r4, =0x002bd558\n"
199 #else
200 "ldr r4, =new_sa\n"
201 "ldr r4, [r4]\n"
202 #endif
203 "sub sp, #0x78\n"
204 "ldr r0, =0x005ce000\n"
205 "ldr r1, =0x00071b34\n"
206 "subs r0, r0, r4\n"
207 "cmp r0, r1\n"
208 "bcs.n loc_fc04f1a6\n"
209 "loc_fc04f1a4:\n"
210 "b.n loc_fc04f1a4\n"
211 "loc_fc04f1a6:\n"
212 "ldr r1, =0x00008070\n"
213 "mov.w r0, #0x80000\n"
214 "str r0, [r1, #0]\n"
215 "ldr r1, =0x00008074\n"
216 "ldr r0, =0x42b21000\n"
217 "str r0, [r1, #0]\n"
218 "ldr r1, =0x00008078 \n"
219 "ldr r0, =0x42b23000\n"
220 "str r0, [r1, #0]\n"
221 "movs r1, #0x74\n"
222 "add r0, sp, #4\n"
223 "blx sub_fc251dcc\n"
224 "add r2, sp, #4\n"
225 "ldr r0, =0x0054b000\n"
226 "mov.w r1, #0x83000\n"
227 "stmia r2!, {r0, r1, r4}\n"
228 "ldr r1, =0x005404cc\n"
229 "str r0, [sp, #24]\n"
230 "movs r0, #0x22\n"
231 "subs r2, r1, r4\n"
232 "str r0, [sp, #28]\n"
233 "movs r0, #0x98\n"
234 "str r0, [sp, #32]\n"
235 "strd r2, r1, [sp, #16]\n"
236 "movw r0, #0x1e8\n"
237 "str r0, [sp, #36]\n"
238 "movs r0, #0xf6\n"
239 "str r0, [sp, #40]\n"
240 "movs r0, #0xb6\n"
241 "str r0, [sp, #44]\n"
242 "movs r0, #0x85\n"
243 "str r0, [sp, #48]\n"
244 "movs r0, #0x40\n"
245 "str r0, [sp, #52]\n"
246 "movs r0, #4\n"
247 "str r0, [sp, #56]\n"
248 "movs r0, #0\n"
249 "str r0, [sp, #60]\n"
250 "movs r0, #16\n"
251 "str r0, [sp, #96]\n"
252 "ldr r1, =sub_fc04f324_my\n"
253 "movs r2, #0\n"
254 "lsls r0, r0, #7\n"
255 "str r0, [sp, #100]\n"
256 "asrs r0, r0, #3\n"
257 "str r0, [sp, #104]\n"
258 "lsls r0, r0, #5\n"
259 "str r0, [sp, #108]\n"
260 "add r0, sp, #4\n"
261 "blx sub_fc251414\n"
262 "add sp, #0x78\n"
263 "pop {r4, pc}\n"
264 ".ltorg\n"
265 );
266 }
267
268
269 void __attribute__((naked,noinline)) sub_fc04f324_my() {
270 asm volatile (
271 "push {r4, lr}\n"
272 "ldr r4, =0xfc04f3d0\n"
273 "bl sub_fc050c14\n"
274 "ldr r0, =0x000080e8\n"
275 "ldr r1, [r0, #0]\n"
276 "ldr r0, =0x00008070\n"
277 "ldr r0, [r0, #0]\n"
278 "adds r0, #16\n"
279 "cmp r1, r0\n"
280 "bcs.n loc_fc04f340\n"
281 "ldr r0, =0xfc04f3e0\n"
282 "bl sub_fc04f3b8\n"
283 "loc_fc04f340:\n"
284 "bl sub_fc12de14\n"
285 "ldr r3, =0x80000800\n"
286 "mov.w r1, #0x80000000\n"
287 "mov.w r2, #0xeeeeeeee\n"
288 "loc_fc04f34e:\n"
289 "stmia r1!, {r2}\n"
290 "cmp r1, r3\n"
291 "bcc.n loc_fc04f34e\n"
292 "bl sub_fc12de26\n"
293 "bl sub_fc0b9f4c\n"
294 "cmp r0, #0\n"
295 "bge.n loc_fc04f366\n"
296 "ldr r0, =0xfc04f3fc\n"
297 "bl sub_fc04f3b8\n"
298 "loc_fc04f366:\n"
299 "bl sub_fc04fb90\n"
300 "cmp r0, #0\n"
301 "bge.n loc_fc04f374\n"
302 "ldr r0, =0xfc04f404\n"
303 "bl sub_fc04f3b8\n"
304 "loc_fc04f374:\n"
305 "mov r0, r4\n"
306 "bl sub_fc04fc24\n"
307 "cmp r0, #0\n"
308 "bge.n loc_fc04f384\n"
309 "ldr r0, =0xfc04f414\n"
310 "bl sub_fc04f3b8\n"
311 "loc_fc04f384:\n"
312 "mov r0, r4\n"
313 "bl sub_fc04f55c\n"
314 "cmp r0, #0\n"
315 "bge.n loc_fc04f394\n"
316 "ldr r0, =0xfc04f428\n"
317 "bl sub_fc04f3b8\n"
318 "loc_fc04f394:\n"
319 "bl sub_fc04f6a0\n"
320 "cmp r0, #0\n"
321 "bge.n loc_fc04f3a2\n"
322 "ldr r0, =0xfc04f434\n"
323 "bl sub_fc04f3b8\n"
324 "loc_fc04f3a2:\n"
325 "bl sub_fc053604\n"
326 "cmp r0, #0\n"
327 "bge.n loc_fc04f3b0\n"
328 "ldr r0, =0xfc04f440\n"
329 "bl sub_fc04f3b8\n"
330 "loc_fc04f3b0:\n"
331 "ldmia.w sp!, {r4, lr}\n"
332 "b.w sub_fc04f72a_my\n"
333 ".ltorg\n"
334 );
335 }
336
337 void __attribute__((naked,noinline)) sub_fc04f72a_my() {
338 asm volatile (
339 "push {r3, lr}\n"
340 "bl sub_fc04f82c\n"
341 "bl sub_fc095cbe\n"
342 "cbnz r0, loc_fc04f740\n"
343 "bl sub_fc07205c\n"
344 "cbz r0, loc_fc04f740\n"
345 "movs r0, #1\n"
346 "b.n loc_fc04f742\n"
347 "loc_fc04f740:\n"
348 "movs r0, #0\n"
349 "loc_fc04f742:\n"
350 "bl sub_fc060338_my\n"
351 "cbnz r0, loc_fc04f74e\n"
352 "bl sub_fc04f81a\n"
353 "loc_fc04f74c:\n"
354 "b.n loc_fc04f74c\n"
355 "loc_fc04f74e:\n"
356 "blx sub_fc251474\n"
357 "ldr r1, =0x005ce000\n"
358 "movs r0, #0\n"
359 "bl sub_fc2b7bf4\n"
360 "blx sub_fc251b9c\n"
361 "movs r3, #0\n"
362 "str r3, [sp, #0]\n"
363 "ldr r3, =sub_fc04f6c4_my\n"
364 "movs r2, #0\n"
365 "movs r1, #25\n"
366 "ldr r0, =0xfc04f77c\n"
367 "blx sub_fc25198c\n"
368 "movs r0, #0\n"
369 "pop {r3, pc}\n"
370 ".ltorg\n"
371 );
372 }
373
374 void __attribute__((naked,noinline)) sub_fc060338_my() {
375 asm volatile (
376 "stmdb sp!, {r2, r3, r4, r5, r6, r7, r8, lr}\n"
377 "mov.w r8, #0\n"
378 "mov r7, r0\n"
379 "mov r6, r8\n"
380 "bl sub_fc060826\n"
381 "movs r0, #16\n"
382 "bl sub_fc05f5c2\n"
383 "movs r4, #1\n"
384 "bic.w r5, r4, r0\n"
385 "movs r0, #15\n"
386 "bl sub_fc05f5c2\n"
387 "bics r4, r0\n"
388 "cbz r7, loc_fc060364\n"
389 "orrs.w r0, r5, r4\n"
390
391 "loc_fc060364:\n"
392 "bl sub_fc095cbe\n"
393 "movs r3, #0\n"
394 "mov r2, r0\n"
395 "strd r8, r6, [sp]\n"
396 "mov r1, r4\n"
397 "mov r0, r5\n"
398
399
400 "movs r0, #1\n"
401 "loc_fc06037e:\n"
402 "ldmia.w sp!, {r2, r3, r4, r5, r6, r7, r8, pc}\n"
403 ".ltorg\n"
404 );
405 }
406
407
408
409 void __attribute__((naked,noinline)) sub_fc04f6c4_my() {
410 asm volatile (
411 "push {r4, lr}\n"
412 "bl sub_fc0ba768\n"
413 "bl sub_fc04f7f8\n"
414 "bl sub_fc04f96c\n"
415 "bl sub_fc095d10\n"
416
417 "bl sub_fc07aff2\n"
418 "bl sub_fc0ba800\n"
419 "bl sub_fc04fad0\n"
420 "bl sub_fc04f908\n"
421 "bl sub_fc095d4e\n"
422 "bl sub_fc095998\n"
423 "bl sub_fc0ba806\n"
424 "BL CreateTask_spytask\n"
425 "bl sub_fc06021a_my\n"
426 "bl sub_fc20d318\n"
427 "bl sub_fc0ba81c\n"
428 "bl sub_fc095750\n"
429
430 #if defined(OPT_RUN_WITH_BATT_COVER_OPEN)
431 " mov r0, #0x100000 \n"
432 "batt_loop1: \n"
433 " nop\n"
434 " SUBS R0,R0,#1 \n"
435 " BNE batt_loop1 \n"
436 #endif
437
438 "bl sub_fc12ed44\n"
439 "bl sub_fc095b24\n"
440 "bl sub_fc09594a\n"
441 "bl sub_fc12ed04\n"
442 "bl sub_fc04fad4\n"
443 "bl sub_fc2a3c36\n"
444 "bl sub_fc12ecde\n"
445 "ldmia.w sp!, {r4, lr}\n"
446
447 "ldr pc, =0xfc0ba73f\n"
448 ".ltorg\n"
449 );
450 }
451
452
453 void __attribute__((naked,noinline)) sub_fc06021a_my() {
454 asm volatile (
455 "push {r3, r4, r5, lr}\n"
456 "ldr r4, =0x8328\n"
457 "ldr r0, [r4, #4]\n"
458 "cbnz r0, loc_fc060236\n"
459 "movs r3, #0\n"
460 "str r3, [sp, #0]\n"
461 "ldr r3, =mykbd_task\n"
462 "movs r1, #23\n"
463 "ldr r0, =0xfc06027c\n"
464 "movw r2, #0x2000\n"
465 "blx sub_fc251c94\n"
466 "str r0, [r4, #4]\n"
467 "loc_fc060236:\n"
468 "bl sub_fc061aac\n"
469 "bl sub_fc071fe6\n"
470 "cmp r0, #0\n"
471 "bne.n loc_fc06024e\n"
472 "ldr r1, =0x2ae94\n"
473 "ldmia.w sp!, {r3, r4, r5, lr}\n"
474 "subs r1, #24\n"
475
476 "ldr pc, =0xfc061a55\n"
477 "loc_fc06024e:\n"
478 "pop {r3, r4, r5, pc}\n"
479 ".ltorg\n"
480 );
481 }
482
483 void __attribute__((naked,noinline)) init_file_modules_task() {
484 asm volatile (
485 " push {r4, r5, r6, lr}\n"
486 " bl sub_fc09ad60\n"
487 " movs r4, r0\n"
488 " movw r5, #0x5006\n"
489 " beq.n loc_fc088236\n"
490 " movs r1, #0\n"
491 " mov r0, r5\n"
492 " bl sub_fc2a6188\n"
493 "loc_fc088236:\n"
494 " bl sub_fc09ad96\n"
495 " BL core_spytask_can_start\n"
496 " cmp r4, #0\n"
497 " bne.n loc_fc08824a\n"
498 " mov r0, r5\n"
499 " ldmia.w sp!, {r4, r5, r6, lr}\n"
500 " movs r1, #0\n"
501 " b.w sub_fc2a6188\n"
502 "loc_fc08824a:\n"
503 " pop {r4, r5, r6, pc}\n"
504 );
505 }
506
507 void __attribute__((naked,noinline)) kbd_p2_f_my() {
508 asm volatile(
509 " stmdb sp!, {r4, r5, r6, r7, r8, lr}\n"
510 " ldr r6, =0x2ae94\n"
511 " sub sp, #0x18\n"
512 " add r7, sp, #8\n"
513 " subs r6, #0xc\n"
514 " b.n loc_fc060002\n"
515 "loc_fc05ffce:\n"
516 " ldr r1, =0x2ae94\n"
517 " add r3, sp, #8\n"
518 " ldrb.w r0, [sp, #4]\n"
519 " add r2, sp, #0x14\n"
520 " subs r1, #0x18\n"
521 " bl sub_fc060ca4\n"
522 " cbnz r0, loc_fc05ffe8\n"
523 " ldr r1, [sp, #0x14]\n"
524 " movs r0, #0\n"
525 " bl sub_fc05ff32\n"
526 "loc_fc05ffe8:\n"
527 " movs r0, #2\n"
528 "loc_fc05ffea:\n"
529 " ldr.w r1, [r7, r0, lsl #2]\n"
530 " cbz r1, loc_fc05fffa\n"
531 " ldr.w r2, [r6, r0, lsl #2]\n"
532 " bics r2, r1\n"
533 " str.w r2, [r6, r0, lsl #2]\n"
534 "loc_fc05fffa:\n"
535 " subs r0, r0, #1\n"
536 " sxtb r0, r0\n"
537 " cmp r0, #0\n"
538 " bge.n loc_fc05ffea\n"
539 "loc_fc060002:\n"
540 " ldr r0, =0x2ae94\n"
541 " add r1, sp, #4\n"
542 " subs r0, #0xc\n"
543 " bl sub_fc0609d6\n"
544 " cmp r0, #0\n"
545 " bne.n loc_fc05ffce\n"
546 " ldr r8, =0x2ae94\n"
547 " movs r4, #0\n"
548 "loc_fc060016:\n"
549 " movs r5, #0\n"
550 " ldr.w r0, [r6, r4, lsl #2]\n"
551 " ldr.w r1, [r8, r4, lsl #2]\n"
552 " ands r0, r1\n"
553 " str.w r0, [r6, r4, lsl #2]\n"
554 " b.n loc_fc06006e\n"
555 "loc_fc060028:\n"
556 " lsrs r0, r5\n"
557 " lsls r0, r0, #0x1f\n"
558 " beq.n loc_fc060066\n"
559 " ldr r1, =0x2ae94\n"
560 " add.w r0, r5, r4, lsl #5\n"
561 " add r3, sp, #8\n"
562 " subs r1, #0x18\n"
563 " add r2, sp, #0x14\n"
564 " uxtb r0, r0\n"
565 " bl sub_fc060ca4\n"
566 " cbnz r0, loc_fc06004a\n"
567 " ldr r1, [sp, #0x14]\n"
568 " movs r0, #1\n"
569 " bl sub_fc05ff32\n"
570 "loc_fc06004a:\n"
571 " mov r0, r4\n"
572 " b.n loc_fc060062\n"
573 "loc_fc06004e:\n"
574 " ldr.w r1, [r7, r0, lsl #2]\n"
575 " cbz r1, loc_fc06005e\n"
576 " ldr.w r2, [r6, r0, lsl #2]\n"
577 " bics r2, r1\n"
578 " str.w r2, [r6, r0, lsl #2]\n"
579 "loc_fc06005e:\n"
580 " adds r0, r0, #1\n"
581 " sxtb r0, r0\n"
582 "loc_fc060062:\n"
583 " cmp r0, #3\n"
584 " blt.n loc_fc06004e\n"
585 "loc_fc060066:\n"
586 " ldr.w r0, [r6, r4, lsl #2]\n"
587 " adds r5, r5, #1\n"
588 " uxtb r5, r5\n"
589 "loc_fc06006e:\n"
590 " cmp r0, #0\n"
591 " bne.n loc_fc060028\n"
592 " adds r4, r4, #1\n"
593 " sxtb r4, r4\n"
594 " cmp r4, #3\n"
595 " blt.n loc_fc060016\n"
596 " bl sub_fc060900_my\n"
597 " add sp, #0x18\n"
598 " ldmia.w sp!, {r4, r5, r6, r7, r8, pc}\n"
599 ".ltorg\n"
600 );
601 }
602
603 void __attribute__((naked,noinline)) sub_fc060900_my() {
604 asm volatile(
605 " push {r4, lr}\n"
606 " ldr r4, =0x92a0\n"
607 " ldr r0, [r4, #8]\n"
608 " bl sub_fc0629f4\n"
609 " bl sub_fc0a0fa0\n"
610 " ldr r0, [r4, #12]\n"
611 " bl sub_fc062910\n"
612
613
614 " bl handle_jogdial\n"
615 " cmp r0, #0\n"
616 " beq no_scroll\n"
617 " bl sub_fc05cbf6\n"
618 "no_scroll:\n"
619 " pop {r4, pc}\n"
620 );
621 }
622
623
624
625 void __attribute__((naked,noinline)) tricinittask() {
626 asm volatile(
627
628
629 " push.w {r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, lr}\n"
630 " blx sub_fc251ad4\n"
631 " movs r0, #8\n"
632 " ldr r1, =0xfc374010\n"
633 " bl sub_fc28b7ee\n"
634 " ldr.w fp, =0x0001bf74\n"
635 " movw sl, #0x1000\n"
636 " ldr r4, =0x0001bf70\n"
637 " movs r2, #0\n"
638 " ldr r1, =0x0003830f\n"
639 " ldr r0, [r4]\n"
640 " blx sub_fc251d4c\n"
641 " lsls r0, r0, #0x1f\n"
642 " beq loc_fc373dfa\n"
643 " movs r0, #8\n"
644 " ldr r1, =0xfc374028\n"
645 " bl sub_fc28b84a\n"
646 " ldr r1, =0x0001bf5c\n"
647 " movs r0, #0\n"
648 " str r0, [r1]\n"
649 " pop.w {r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, pc}\n"
650 "loc_fc373dfa:\n"
651 " ldr r4, =0x0001bf70\n"
652 " add r1, sp, #8\n"
653 " ldr r0, [r4]\n"
654 " blx sub_fc251bec\n"
655 " ldr r1, [sp, #8]\n"
656 " ldr r0, [r4]\n"
657 " blx sub_fc251c1c\n"
658 " ldr r6, [sp, #8]\n"
659 " lsls r0, r6, #0x1e\n"
660 " beq sub_fc373ed2\n"
661 " lsls r0, r6, #0x1f\n"
662 " beq sub_fc373e1c\n"
663
664 " ldr r0, =0xd2020074\n"
665 " ldr r0, [r0]\n"
666 " subs r0, #0\n"
667 " beq tric1\n"
668 " ldr r0, [r4]\n"
669 " mov r1, #0x80\n"
670 " bl _SetEventFlag\n"
671 "tric1:\n"
672
673 " bl sub_fc374160\n"
674
675 " ldr pc, =0xfc373e5f\n"
676 );
677 }
678
679 #if PLATFORMID == 12895
680
681
682 void update_url() {
683 strcpy(*(char**)(0xd1bc+0x1c),"http://epodownload.mediatek.com/EPO.DAT");
684 }
685
686 void __attribute__((naked,noinline)) agps_downloader_task() {
687 asm volatile(
688
689
690 " push {r3, r4, r5, r6, r7, lr}\n"
691 " movs r4, #0\n"
692 " ldr r7, =0x0000d1bc\n"
693 " subs r6, r4, #1\n"
694 " b loc_fc07bad6\n"
695 "loc_fc07ba70:\n"
696 " ldr r0, [r7]\n"
697 " movs r2, #0\n"
698 " mov r1, sp\n"
699 " blx sub_fc251c84\n"
700 " mov r4, r0\n"
701 " lsls r0, r0, #0x1f\n"
702 " beq loc_fc07ba8a\n"
703 " movs r2, #0xf2\n"
704 " movs r0, #0\n"
705 " ldr r1, =0xfc07bc48\n"
706 " blx sub_fc251d9c\n"
707 "loc_fc07ba8a:\n"
708 " ldr r0, [r7, #0x14]\n"
709 " adds r0, r0, #1\n"
710 " bne loc_fc07ba94\n"
711 " mov r5, r6\n"
712 " b loc_fc07ba98\n"
713 "loc_fc07ba94:\n"
714 " ldr r0, [sp]\n"
715 " ldr r5, [r0]\n"
716 "loc_fc07ba98:\n"
717 " ldr r0, [sp]\n"
718 " bl sub_fc2b7bfc\n"
719 " cmp r5, #7\n"
720 " bhs loc_fc07bad6\n"
721 " tbb [pc, r5]\n"
722 "branchtable_fc07baa6:\n"
723 " .byte((loc_fc07baae - branchtable_fc07baa6) / 2)\n"
724 " .byte((loc_fc07bab4 - branchtable_fc07baa6) / 2)\n"
725 " .byte((loc_fc07baba - branchtable_fc07baa6) / 2)\n"
726 " .byte((loc_fc07bac0 - branchtable_fc07baa6) / 2)\n"
727 " .byte((loc_fc07bac6 - branchtable_fc07baa6) / 2)\n"
728 " .byte((loc_fc07bacc - branchtable_fc07baa6) / 2)\n"
729 " .byte((loc_fc07bad2 - branchtable_fc07baa6) / 2)\n"
730 ".align 1\n"
731 "loc_fc07baae:\n"
732 " bl sub_fc07b9bc\n"
733 " bl update_url\n"
734 " b loc_fc07bad6\n"
735 "loc_fc07bab4:\n"
736 " bl sub_fc07b918\n"
737 " b loc_fc07bad6\n"
738 "loc_fc07baba:\n"
739 " bl sub_fc07b848\n"
740 " b loc_fc07bad6\n"
741 "loc_fc07bac0:\n"
742 " bl sub_fc07b70e\n"
743 " b loc_fc07bad6\n"
744 "loc_fc07bac6:\n"
745 " bl sub_fc07b5b8\n"
746 " b loc_fc07bad6\n"
747 "loc_fc07bacc:\n"
748 " bl sub_fc07bb5c\n"
749 " b loc_fc07bad6\n"
750 "loc_fc07bad2:\n"
751 " bl sub_fc07b4d0\n"
752 "loc_fc07bad6:\n"
753 " lsls r0, r4, #0x1f\n"
754 " beq loc_fc07ba70\n"
755 " pop {r3, r4, r5, r6, r7, pc}\n"
756 );
757 }
758 #endif
759