root/platform/sx710hs/sub/100a/boot.c

/* [<][>][^][v][top][bottom][index][help] */

DEFINITIONS

This source file includes following definitions.
  1. spytask
  2. CreateTask_spytask
  3. boot
  4. CreateTask_my
  5. sub_fc055894_my
  6. sub_fc055a24_my
  7. sub_fc055e2e_my
  8. sub_fc0cf0ee_my
  9. task_Startup_my
  10. sub_fc0cf014_my
  11. init_file_modules_task
  12. init_required_fw_features
  13. TricInitTask_my
  14. kbd_p2_f_my
  15. sub_fc086af2_my

   1 #include "lolevel.h"
   2 #include "platform.h"
   3 #include "core.h"
   4 
   5 const char * const new_sa = &_end;
   6 
   7 // Forward declarations
   8 
   9 extern void task_CaptSeq();
  10 extern void task_InitFileModules();
  11 extern void task_RotaryEncoder();
  12 extern void task_MovieRecord();
  13 extern void task_ExpDrv();
  14 extern void task_TricInitTask();
  15 
  16 extern void handle_jogdial();
  17 
  18 /*----------------------------------------------------------------------
  19     spytask
  20 -----------------------------------------------------------------------*/
  21 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
  22 {
  23     core_spytask();
  24 }
  25 
  26 /*----------------------------------------------------------------------
  27     CreateTask_spytask
  28 -----------------------------------------------------------------------*/
  29 void CreateTask_spytask()
  30 {
  31     _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
  32 }
  33 
  34 //unsigned rbval=0;
  35 /*
  36 void task_blinker()
  37 {
  38 #if 0
  39     unsigned v=*(volatile unsigned *)(0x9808);
  40     unsigned pat=0;
  41     if(v & 0x80000){
  42         pat |=1;
  43     }
  44     if(v & 0x100000){
  45         pat |=2;
  46     }
  47     if(v & 0x200000){
  48         pat |=4;
  49     }
  50     if(v & 0x400000){
  51         pat |=8;
  52     }
  53     if(v & 0x800000){
  54         pat |=0x10;
  55     }
  56     while(1) {
  57         int i;
  58         for(i=0;i<5;i++) {
  59             *(volatile int*)0xd20b0994 = 0x4d0002;
  60             if((pat >> i) & 1) {
  61                 msleep(1000);
  62             } else {
  63                 msleep(250);
  64             }
  65             *(volatile int*)0xd20b0994 = 0x4c0003;
  66             msleep(500);
  67         }
  68         msleep(5000);
  69     }
  70 #endif
  71 #if 0
  72     int delay=1000;
  73     if(rbval == 0x12345678) {
  74         delay=100;
  75     }
  76     while(1) {
  77         *(volatile int*)0xd20b0994 = 0x4d0002;
  78         msleep(delay);
  79         *(volatile int*)0xd20b0994 = 0x4c0003;
  80         msleep(delay);
  81     }
  82 #endif
  83     while(1) {
  84         *(volatile int*)0xd20b0994 = 0x4d0002;
  85         msleep(250);
  86         *(volatile int*)0xd20b0994 = 0x4c0003;
  87         msleep(250);
  88     }
  89 }
  90 
  91 void CreateTask_blinker()
  92 {
  93     _CreateTask("blinker", 0x19, 0x200, task_blinker, 0);
  94 }
  95 */
  96 
  97 /*----------------------------------------------------------------------
  98     boot()
  99 
 100     Main entry point for the CHDK code
 101 -----------------------------------------------------------------------*/
 102 
 103 /*************************************************************/
 104 //  -f=chdk -s=0xfc02000d -c=43
 105 void __attribute__((naked,noinline)) boot() {
 106     asm volatile ( // 0xfc02000c
 107 "    movw    r0, #0x4000\n"
 108 "    movt    r0, #0\n"
 109 "    mov     sp, r0\n"
 110 "    bl      sub_fc02007e\n"
 111 "    ldr     r2, =0xc0242010\n"
 112 "    ldr     r1, [r2]\n"
 113 "    orr     r1, r1, #1\n"
 114 "    str     r1, [r2]\n"
 115 "    ldr     r0, =0xfcd4740c\n" // code copied from ROM
 116 "    ldr     r1, =0x010e1000\n" // to RAM
 117 "    ldr     r3, =0x01107bd0\n"
 118 "loc_fc02002a:\n"
 119 "    cmp     r1, r3\n"
 120 "    itt     lo\n"
 121 "    ldrlo   r2, [r0], #4\n"
 122 "    strlo   r2, [r1], #4\n"
 123 "    blo     loc_fc02002a\n"
 124 "    ldr     r0, =0x010e1000\n"
 125 "    ldr     r1, =0x00026bd0\n"
 126 "    bl      sub_fc11f606\n"    // cache stuff for RAM code
 127 "    ldr     r0, =0xfcd6dfdc\n" // code copied from ROM
 128 "    ldr     r1, =0xbfe10800\n" // to TCM
 129 "    ldr     r3, =0xbfe17419\n"
 130 "loc_fc020046:\n"
 131 "    cmp     r1, r3\n"
 132 "    itt     lo\n"
 133 "    ldrlo   r2, [r0], #4\n"
 134 "    strlo   r2, [r1], #4\n"
 135 "    blo     loc_fc020046\n"
 136 // Install CreateTask patch
 137 // use half words in case source or destination not word aligned
 138         "adr     r0, patch_CreateTask\n"    // src: Patch data
 139         "ldr     r1, =hook_CreateTask\n"    // dest: Address to patch (hook_ has thumb bit off)
 140         "add     r2, r0, #8\n" // two words
 141 "task_hook_loop:\n"
 142         "ldrh   r3, [r0],#2\n"
 143         "strh   r3, [r1],#2\n"
 144         "cmp    r0,r2\n"
 145         "blo    task_hook_loop\n"
 146 "    ldr     r0, =0xfcd1e5b4\n"
 147 "    ldr     r1, =0x00008000\n" // DATA copied
 148 "    ldr     r3, =0x00030e58\n" // to RAM
 149 "loc_fc02005a:\n"
 150 "    cmp     r1, r3\n"
 151 "    itt     lo\n"
 152 "    ldrlo   r2, [r0], #4\n"
 153 "    strlo   r2, [r1], #4\n"
 154 "    blo     loc_fc02005a\n"
 155 "    ldr     r3, =0x00030e58\n" // BSS
 156 "    ldr     r1, =0x003c3998\n"
 157 "    mov.w   r2, #0\n"
 158 "loc_fc020070:\n"
 159 "    cmp     r3, r1\n"
 160 "    it      lo\n"
 161 "    strlo   r2, [r3], #4\n"
 162 "    blo     loc_fc020070\n"
 163 "    b.w     sub_fc055894_my\n"
 164 
 165         "patch_CreateTask:\n"
 166         "ldr.w   pc, [pc,#0]\n"             // Do jump to absolute address CreateTask_my
 167         ".long   CreateTask_my + 1\n"           // has to be a thumb address
 168 );
 169 }
 170 
 171 /*************************************************************/
 172 void __attribute__((naked,noinline)) CreateTask_my() {
 173 asm volatile (
 174 "    push   {r0}\n"
 175 //R3 = Pointer to task function to create
 176 "    ldr     r0, =task_CaptSeq\n"       // DryOS original code function ptr.
 177 "    cmp     r0, r3\n"                  // is the given taskptr equal to our searched function?
 178 "    itt     eq\n"                      // EQ block
 179 "    ldreq   r3, =capt_seq_task\n"      // if so replace with our task function base ptr.
 180 "    orreq   r3, #1\n"                  // make sure it's a thumb address (may not be needed?)
 181 "    beq     exitHook\n"                // below compares not necessary if this check has found something.
 182 
 183 // exp_drv not needed for extended exposure, probably works up to 1024s, but required for < 1/3200
 184 "    LDR     R0, =task_ExpDrv\n"
 185 "    CMP     R0, R3\n"
 186 "    itt     eq\n"
 187 "    LDREQ   R3, =exp_drv_task\n"
 188 "    orreq   r3, #1\n"
 189 "    BEQ     exitHook\n"
 190 
 191 // not needed in sx710
 192 /*
 193 "    LDR     R0, =task_DvlpSeqTask\n"
 194 "    CMP     R0, R3\n"
 195 "    itt     eq\n"
 196 "    LDREQ   R3, =developseq_task\n"
 197 "    orreq   r3, #1\n"
 198 "    BEQ     exitHook\n"
 199 */
 200 
 201 "    ldr     r0, =task_FileWrite\n"
 202 "    cmp     r0, r3\n"
 203 "    itt     eq\n"
 204 "    ldreq   r3, =filewritetask\n"
 205 "    orreq   r3, #1\n"
 206 "    beq     exitHook\n"
 207 
 208 // not implemented
 209 /*
 210 "    LDR     R0, =task_MovieRecord\n"
 211 "    CMP     R0, R3\n"
 212 "    LDREQ   R3, =movie_record_task\n"
 213 "    BEQ     exitHook\n"
 214 */
 215 
 216 "    ldr     r0, =task_TricInitTask\n"
 217 "    cmp     r0, r3\n"
 218 "    itt     eq\n"
 219 "    ldreq   r3, =TricInitTask_my\n"
 220 "    orreq   r3, #1\n"
 221 "    beq     exitHook\n"
 222 
 223 "    ldr     r0, =task_InitFileModules\n"
 224 "    cmp     r0, r3\n"
 225 "    itt     eq\n"
 226 "    ldreq   r3, =init_file_modules_task\n"
 227 "    orreq   r3, #1\n"
 228 "exitHook:\n" 
 229 // restore overwritten register(s)
 230 "    pop    {r0}\n"
 231 // Execute overwritten instructions from original code, then jump to firmware
 232 // NOTE number of instructions duplicated here depends on size of original ROM code
 233 // instructions. Must replace 8 bytes!
 234 "    stmdb   sp!, {r1, r2, r3, r4, r5, r6, r7, r8, r9, lr}\n"
 235 "    mov     r4, r0\n"
 236 "    ldr     r0, =0x8160\n"
 237 "    ldr.w   pc, =(hook_CreateTask + 8 + 1) \n"  // Continue in firmware (thumb bit set)
 238 ".ltorg\n"
 239 );
 240 }
 241 
 242 // -f=chdk -s=0xfc055895 -c=60
 243 void __attribute__((naked,noinline)) sub_fc055894_my() {
 244 // startup key checks handled in sub_fc0cf0ee_my
 245     asm volatile (
 246 "    push    {r4, lr}\n"
 247 #if defined(CHDK_NOT_IN_CANON_HEAP)
 248 "    ldr     r4, =0x003c3998\n"
 249 #else
 250     "ldr     r4, =new_sa\n"             // +
 251     "ldr     r4, [r4]\n"                // +
 252 #endif
 253 "    sub     sp, #0x78\n"
 254 "    ldr     r0, =0x006ce000\n"
 255 "    ldr     r1, =0x000b1fec\n"
 256 "    subs    r0, r0, r4\n"
 257 "    cmp     r0, r1\n"
 258 "    bhs     loc_fc0558a6\n"
 259 "loc_fc0558a4:\n"
 260 "    b       loc_fc0558a4\n"
 261 "loc_fc0558a6:\n"
 262 "    ldr     r1, =0x00008074\n"
 263 "    mov.w   r0, #0x80000\n"
 264 "    str     r0, [r1]\n"
 265 "    ldr     r1, =0x00008078\n"
 266 "    ldr     r0, =0x421bcb00\n"
 267 "    str     r0, [r1]\n"
 268 "    ldr     r1, =0x0000807c\n"
 269 "    ldr     r0, =0x421beb00\n"
 270 "    str     r0, [r1]\n"
 271 "    movs    r1, #0x78\n"
 272 "    mov     r0, sp\n"
 273 "    blx     sub_fc2c7d98\n" // j_bzero
 274 "    ldr     r0, =0x0060e000\n"
 275 "    mov.w   r1, #0xc0000\n"
 276 "    stm.w   sp, {r0, r1, r4}\n"
 277 "    ldr     r1, =0x00600014\n"
 278 "    subs    r2, r1, r4\n"
 279 "    strd    r2, r1, [sp, #0xc]\n"
 280 "    str     r0, [sp, #0x14]\n"
 281 "    movs    r0, #0x22\n"
 282 "    str     r0, [sp, #0x18]\n"
 283 "    movs    r0, #0xca\n"
 284 "    str     r0, [sp, #0x1c]\n"
 285 "    movw    r0, #0x2b0\n"
 286 "    str     r0, [sp, #0x20]\n"
 287 "    movs    r0, #0xfa\n"
 288 "    str     r0, [sp, #0x24]\n"
 289 "    movw    r0, #0x11a\n"
 290 "    str     r0, [sp, #0x28]\n"
 291 "    movs    r0, #0x85\n"
 292 "    str     r0, [sp, #0x2c]\n"
 293 "    movs    r0, #0x40\n"
 294 "    str     r0, [sp, #0x30]\n"
 295 "    movs    r0, #4\n"
 296 "    str     r0, [sp, #0x34]\n"
 297 "    movs    r0, #0\n"
 298 "    str     r0, [sp, #0x38]\n"
 299 "    movs    r0, #0x10\n"
 300 "    str     r0, [sp, #0x5c]\n"
 301 "    movs    r2, #0\n"
 302 "    lsls    r0, r0, #8\n"
 303 "    str     r0, [sp, #0x60]\n"
 304 //"    ldr     r1, =0xfc055a25\n"
 305 "    ldr     r1, =sub_fc055a24_my\n"
 306 "    asrs    r0, r0, #4\n"
 307 "    str     r0, [sp, #0x64]\n"
 308 "    lsls    r0, r0, #5\n"
 309 "    str     r0, [sp, #0x68]\n"
 310 "    mov     r0, sp\n"
 311 "    blx     sub_fc2c755c\n"
 312 "    add     sp, #0x78\n"
 313 "    pop     {r4, pc}\n"
 314 ".ltorg\n"
 315     );
 316 }
 317 
 318 //  -f=chdk -s=0xfc055a25 -c=62
 319 void __attribute__((naked,noinline)) sub_fc055a24_my() {
 320     asm volatile (
 321 "    push    {r4, lr}\n"
 322 "    ldr     r4, =0xfc055acc\n" //  *"/_term"
 323 "    bl      sub_fc056cc8\n"
 324 "    ldr     r0, =0x000080ec\n"
 325 "    ldr     r1, [r0]\n"
 326 "    ldr     r0, =0x00008074\n"
 327 "    ldr     r0, [r0]\n"
 328 "    adds    r0, #0x10\n"
 329 "    cmp     r1, r0\n"
 330 "    bhs     loc_fc055a40\n"
 331 "    ldr     r0, =0xfc055adc\n" //  *"USER_MEM size checking"
 332 "    bl      sub_fc055ab6\n"
 333 "loc_fc055a40:\n"
 334 "    bl      sub_fc11f6e0\n"
 335 "    ldr     r1, =0xbfe10000\n"
 336 // note capdis bad output
 337 //"    mov.w   r2, #-0x11111112\n"
 338 "    mov.w   r2, #0xeeeeeeee\n"
 339 "    ldr     r3, =0xbfe10800\n"
 340 "loc_fc055a4c:\n"
 341 "    stm     r1!, {r2}\n"
 342 "    cmp     r1, r3\n"
 343 "    blo     loc_fc055a4c\n"
 344 "    bl      sub_fc11f6f2\n"
 345 "    bl      sub_fc38d1bc\n"
 346 "    cmp     r0, #0\n"
 347 "    bge     loc_fc055a64\n"
 348 "    ldr     r0, =0xfc055afc\n" //  *"dmSetup"
 349 "    bl      sub_fc055ab6\n"
 350 "loc_fc055a64:\n"
 351 "    bl      sub_fc056268\n"
 352 "    cmp     r0, #0\n"
 353 "    bge     loc_fc055a72\n"
 354 "    ldr     r0, =0xfc055b04\n" //  *"termDriverInit"
 355 "    bl      sub_fc055ab6\n"
 356 "loc_fc055a72:\n"
 357 "    mov     r0, r4\n"
 358 "    bl      sub_fc0562f6\n"
 359 "    cmp     r0, #0\n"
 360 "    bge     loc_fc055a82\n"
 361 "    ldr     r0, =0xfc055b14\n" //  *"termDeviceCreate"
 362 "    bl      sub_fc055ab6\n"
 363 "loc_fc055a82:\n"
 364 "    mov     r0, r4\n"
 365 "    bl      sub_fc055c60\n"
 366 "    cmp     r0, #0\n"
 367 "    bge     loc_fc055a92\n"
 368 "    ldr     r0, =0xfc055b28\n" //  *"stdioSetup"
 369 "    bl      sub_fc055ab6\n"
 370 "loc_fc055a92:\n"
 371 "    bl      sub_fc055da4\n"
 372 "    cmp     r0, #0\n"
 373 "    bge     loc_fc055aa0\n"
 374 "    ldr     r0, =0xfc055b34\n" //  *"stdlibSetup"
 375 "    bl      sub_fc055ab6\n"
 376 "loc_fc055aa0:\n"
 377 "    bl      sub_fc058e3c\n"
 378 "    cmp     r0, #0\n"
 379 "    bge     loc_fc055aae\n"
 380 "    ldr     r0, =0xfc055b40\n" //  *"extlib_setup"
 381 "    bl      sub_fc055ab6\n"
 382 "loc_fc055aae:\n"
 383 "    pop.w   {r4, lr}\n"
 384 //"    b.w     loc_fc055e2e\n"
 385 "    b.w     sub_fc055e2e_my\n" // +
 386     ".ltorg\n"
 387     );
 388 }
 389 
 390 //  -f=chdk -s=0xfc055e2f -c=20
 391 void __attribute__((naked,noinline)) sub_fc055e2e_my() {
 392     asm volatile (
 393 "    push    {r3, lr}\n"
 394 "    bl      sub_fc055f34\n"
 395 "    bl      sub_fc078bfc\n" // IsNormalCameraMode_FW
 396 "    bl      sub_fc0cf0ee_my\n" // startup checks equivalent of g7x fc0781f4, but doesn't seem affected by *(0x4ffc)=0x12345678
 397 "    cbnz    r0, loc_fc055e44\n"
 398 "    bl      sub_fc055f22\n"
 399 "loc_fc055e42:\n"
 400 "    b       loc_fc055e42\n"
 401 "loc_fc055e44:\n"
 402 "    blx     sub_fc2c75b4\n"
 403 "    ldr     r1, =0x006ce000\n"
 404 "    movs    r0, #0\n"
 405 "    bl      sub_fc329100\n"
 406 "    movs    r3, #0\n"
 407 "    str     r3, [sp]\n"
 408 //"    ldr     r3, =0xfc055dc9\n" //  task_Startup
 409 "    ldr     r3, =task_Startup_my\n" //  ->
 410 "    movs    r2, #0\n"
 411 "    movs    r1, #0x19\n"
 412 "    ldr     r0, =0xfc055e6c\n" //  *"Startup"
 413 "    bl      _CreateTask\n"
 414 //"    blx     sub_fc2c79a8\n" // j_CreateTask
 415 "    movs    r0, #0\n"
 416 "    pop     {r3, pc}\n"
 417     ".ltorg\n"
 418     );
 419 }
 420 // -f=chdk -s=0xfc0cf0ef -c=40
 421 void __attribute__((naked,noinline)) sub_fc0cf0ee_my() {
 422     asm volatile (
 423 "    push.w  {r3, r4, r5, r6, r7, r8, sb, sl, fp, lr}\n"
 424 "    movs    r4, #0\n"
 425 "    mov     sl, r0\n"
 426 "    mov     r5, r4\n"
 427 "    mov     sb, r4\n"
 428 //"    bl      sub_fc086a00\n" // nullsub
 429 "    movs    r0, #0x10\n"
 430 "    bl      sub_fc0847ea\n"
 431 "    movs    r6, #1\n"
 432 "    bic.w   r8, r6, r0\n"
 433 "    movs    r0, #0xf\n"
 434 "    bl      sub_fc0847ea\n"
 435 "    bic.w   r7, r6, r0\n"
 436 "    movs    r0, #0\n"
 437 "    bl      sub_fc0869fc\n"
 438 "    cbz     r0, loc_fc0cf126\n"
 439 "    movs    r0, #0x17\n"
 440 "    bl      sub_fc0847ea\n"
 441 "    bic.w   r5, r6, r0\n"
 442 "loc_fc0cf126:\n"
 443 "    movs    r0, #1\n"
 444 "    bl      sub_fc0869fc\n"
 445 "    cbz     r0, loc_fc0cf13a\n"
 446 "    movw    r0, #0x1d8\n"
 447 "    bl      sub_fc0847ea\n"
 448 "    bic.w   r4, r6, r0\n"
 449 "loc_fc0cf13a:\n"
 450 "    cmp.w   sl, #0\n"
 451 "    beq     loc_fc0cf14a\n" // skips checks if not IsNormalCameraMode
 452 "    orr.w   r0, r8, r7\n"
 453 "    orrs    r0, r5\n"
 454 "    orrs    r0, r4\n" // check all hardware related bits checked above
 455 //"    beq     loc_fc0cf15e\n" // old behavior, skip to return if none set
 456 "    bne     loc_fc0cf14a\n" // new behavior, go to final code if any set
 457 // otherwise, act as if play was held
 458     "mov  r7, #1\n"
 459 "loc_fc0cf14a:\n"
 460 "    mov     r3, sb\n"
 461 "    mov     r2, r5\n"
 462 "    mov     r1, r7\n"
 463 "    mov     r0, r8\n"
 464 "    str     r4, [sp]\n"
 465 "    bl      sub_fc086a04\n"
 466 //"    bl      sub_fc086a02\n" // nullsub
 467 "    movs    r0, #1\n"
 468 //"loc_fc0cf15e:\n"
 469 "    pop.w   {r3, r4, r5, r6, r7, r8, sb, sl, fp, pc}\n"
 470     ".ltorg\n"
 471     );
 472 }
 473 
 474 // -f=chdk -s=task_Startup -c=26
 475 void __attribute__((naked,noinline)) task_Startup_my() {
 476     asm volatile (
 477 // task_Startup 0xfc055dc9
 478 "    push    {r4, lr}\n"
 479 "    bl      sub_fc0cf4d8\n" // CreateTask ClockSave
 480 "    bl      sub_fc055f00\n" // ??
 481 //"    bl      sub_fc056060\n" // ->nullsub
 482 "    bl      sub_fc38d970\n"
 483 // added for SD card UHS detection https://chdk.setepontos.com/index.php?topic=13089.msg132583#msg132583
 484 "bl sub_010e173f\n" // ref in sub_010e182c following SD1stInit create
 485 //"    bl      sub_fc0560b6\n" StartDiskboot
 486 //"    bl      CreateTask_blinker\n"
 487 "    bl      sub_fc0b337a\n"
 488 "    bl      sub_fc0cf7dc\n"
 489 "    bl      sub_fc0561a8\n"
 490 "    bl      sub_fc055ff0\n"
 491 "    bl      sub_fc38d9ae\n"
 492 "    bl      sub_fc0917c4\n"
 493 "    bl      sub_fc0cf7e2\n"
 494 "    bl      sub_fc0cf014_my\n" // CreateTask PhySw
 495 "    bl      CreateTask_spytask\n" 
 496 "    bl      init_required_fw_features\n" // added
 497 "    bl      sub_fc267314\n"
 498 "    bl      sub_fc0cf7f8\n"
 499 "    bl      sub_fc11fac8\n"
 500 "    bl      sub_fc0b2fb0\n"
 501 "    bl      sub_fc0cf636\n"
 502 "    bl      sub_fc0b332a\n"
 503 "    bl      sub_fc0b2f6c\n"
 504 "    bl      sub_fc0561ac\n"
 505 "    bl      sub_fc2d3370\n"
 506 "    bl      sub_fc0b2f40\n"
 507 "    pop.w   {r4, lr}\n"
 508 //"    b.w     loc_fc0cf4ae\n"
 509 "    ldr     pc,=0xfc0cf4af\n"
 510     ".ltorg\n"
 511     );
 512 }
 513 
 514 // -f=chdk -s=0xfc0cf015 -c=18
 515 //taskcreate_physw
 516 void __attribute__((naked,noinline)) sub_fc0cf014_my() {
 517     asm volatile (
 518 "    push    {r3, r4, r5, lr}\n"
 519 "    bl      sub_fc087d58\n"
 520 "    bl      sub_fc078b7a\n" // IsFactoryMode_FW
 521 "    cbnz    r0, loc_fc0cf024\n"
 522 "    bl      sub_fc087cfc\n" // OpLog.Start_FW
 523 "loc_fc0cf024:\n"
 524 "    ldr     r4, =0x000082c8\n" //  physw_run
 525 "    ldr     r0, [r4, #4]\n"
 526 "    cmp     r0, #0\n"
 527 "    bne     loc_fc0cf040\n"
 528 "    movs    r3, #0\n"
 529 "    str     r3, [sp]\n"
 530 //"    ldr     r3, =0xfc0cefc7\n" //  task_PhySw
 531 "    ldr     r3, =mykbd_task\n"
 532 "    movs    r1, #0x17\n"
 533 "    ldr     r0, =0xfc0cf36c\n" //  *"PhySw"
 534 //"    movw    r2, #0x800\n"
 535 "    movw    r2, #0x2000\n" // adjusted 0x800 -> 0x2000
 536 "    blx     sub_fc2c7cc0\n" // j_CreateTaskStrictly
 537 "    str     r0, [r4, #4]\n"
 538 "loc_fc0cf040:\n"
 539 "    pop     {r3, r4, r5, pc}\n"
 540     ".ltorg\n"
 541     );
 542 }
 543  
 544 // -f=chdk -s=task_InitFileModules -c=16
 545 void __attribute__((naked,noinline)) init_file_modules_task() {
 546     asm volatile (
 547 // task_InitFileModules 0xfc0d4309
 548 "    push    {r4, r5, r6, lr}\n"
 549 "    bl      sub_fc0d985c\n"
 550 "    movs    r4, r0\n"
 551 "    movw    r5, #0x5006\n"
 552 "    beq     loc_fc0d431e\n"
 553 "    movs    r1, #0\n"
 554 "    mov     r0, r5\n"
 555 "    bl      _PostLogicalEventToUI\n"
 556 "loc_fc0d431e:\n"
 557 "    bl      sub_fc0d9886\n"
 558 "    BL      core_spytask_can_start\n" // + CHDK: Set "it's-safe-to-start" flag for spytask
 559 "    cmp     r4, #0\n"
 560 "    bne     loc_fc0d4332\n"
 561 "    mov     r0, r5\n"
 562 "    pop.w   {r4, r5, r6, lr}\n"
 563 "    movs    r1, #0\n"
 564 "    b.w     _PostLogicalEventToUI\n"
 565 "loc_fc0d4332:\n"
 566 "    pop     {r4, r5, r6, pc}\n"
 567     ".ltorg\n"
 568     );
 569 }
 570 /*
 571     *** workaround ***
 572     Init stuff to avoid asserts on cameras running DryOS r54+
 573     https://chdk.setepontos.com/index.php?topic=12516.0
 574     Execute this only once
 575  */
 576 void init_required_fw_features(void) {
 577     extern void _init_focus_eventflag();
 578 
 579     _init_focus_eventflag();
 580     // for MoveIrisWithAv, based on fc540574 from Mecha.Create (but without registering eventprocs)
 581     extern int av_override_semaphore;
 582     extern int _CreateBinarySemaphoreStrictly(int x, int y);
 583     av_override_semaphore = _CreateBinarySemaphoreStrictly(0,0);
 584 }
 585 
 586 // fix for FI2 boot, see https://chdk.setepontos.com/index.php?topic=11316.msg136622#msg136622
 587 // -f=chdk -s=task_TricInitTask -c=36
 588 void __attribute__((naked,noinline)) TricInitTask_my()
 589 {
 590     asm volatile(
 591    // task_TricInitTask 0xfc4417a1
 592 "    push.w  {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 593 "    blx     sub_fc2c7d30\n"
 594 "    movs    r0, #8\n"
 595 "    ldr     r1, =0xfc4419d0\n" //  *"InitTskStart"
 596 "    bl      sub_fc315ec6\n"
 597 "    ldr.w   sl, =0x00020bb0\n"
 598 "    movw    fp, #0x1000\n"
 599 "    ldr     r4, =0x00020bac\n"
 600 "    movs    r2, #0\n"
 601 "    ldr     r1, =0x0703870f\n"
 602 "    ldr     r0, [r4]\n"
 603 "    blx     sub_fc2c7dd0\n" // j_WaitForAnyEventFlag
 604 "    lsls    r0, r0, #0x1f\n"
 605 "    beq     loc_fc4417da\n"
 606 "    movs    r0, #8\n"
 607 "    ldr     r1, =0xfc4419e8\n" //  *"ER IniTskWait"
 608 "    bl      sub_fc315f26\n"
 609 "    ldr     r1, =0x00020b98\n"
 610 "    movs    r0, #0\n"
 611 "    str     r0, [r1]\n"
 612 "    pop.w   {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, pc}\n"
 613 "loc_fc4417da:\n"
 614 "    ldr     r4, =0x00020bac\n"
 615 "    add     r1, sp, #0xc\n"
 616 "    ldr     r0, [r4]\n"
 617 "    blx     sub_fc2c7ba0\n" // j_GetEventFlagValue
 618 "    ldr     r1, [sp, #0xc]\n"
 619 "    ldr     r0, [r4]\n"
 620 "    blx     sub_fc2c7dc8\n" // j_ClearEventFlag
 621 "    ldr     r0, =0x02000003\n"
 622 "    ldr     r7, [sp, #0xc]\n"
 623 "    tst     r7, r0\n"
 624 "    beq     sub_fc4418de\n" // loc -> sub
 625 "    lsls    r0, r7, #0x1f\n"
 626 "    beq     sub_fc4417fe\n" // loc -> sub
 627 
 628 "    ldr     r0, =0xd2020074\n" // + MMIO ref'd from code jumped to at end of fc441c82
 629 "    ldr     r0, [r0]\n"        // + nonzero when core already running
 630 "    subs    r0, #0\n"          // +
 631 "    beq     tric1\n"           // +
 632 "    ldr     r0, [r4]\n"        // +
 633 "    mov     r1, #0x80\n"       // +
 634 "    bl      _SetEventFlag\n"   // + core already initialized, set the SmacIdleCmp eventflag here
 635 "tric1:\n"                      // +
 636 
 637 "    bl      sub_fc441c82\n"
 638 //"    b       loc_fc44186a\n"
 639 "    ldr     pc, =0xfc44186b\n" // b to ldr pc, continue in fw
 640 ".ltorg\n"
 641     );
 642 }
 643 
 644 #ifdef CAM_HAS_JOGDIAL
 645 // jogdial override code called from kbd task
 646 // -f=chdk -s=kbd_p2_f -c=77
 647 // kbd_p2_f 0xfc0ced65
 648 void __attribute__((naked,noinline)) kbd_p2_f_my() {
 649     asm volatile(
 650 "    push.w  {r4, r5, r6, r7, r8, lr}\n"
 651 "    ldr     r6, =0x00032734\n"
 652 "    sub     sp, #0x18\n"
 653 "    add     r7, sp, #8\n"
 654 "    subs    r6, #0xc\n"
 655 "    b       loc_fc0ceda6\n"
 656 "loc_fc0ced72:\n"
 657 "    ldr     r1, =0x00032734\n"
 658 "    add     r3, sp, #8\n"
 659 "    ldrb.w  r0, [sp, #4]\n"
 660 "    add     r2, sp, #0x14\n"
 661 "    subs    r1, #0x18\n"
 662 "    bl      sub_fc086f30\n"
 663 "    cbnz    r0, loc_fc0ced8c\n"
 664 "    ldr     r1, [sp, #0x14]\n"
 665 "    movs    r0, #0\n"
 666 "    bl      sub_fc0cecd6\n"
 667 "loc_fc0ced8c:\n"
 668 "    movs    r0, #2\n"
 669 "loc_fc0ced8e:\n"
 670 "    ldr.w   r1, [r7, r0, lsl #2]\n"
 671 "    cbz     r1, loc_fc0ced9e\n"
 672 "    ldr.w   r2, [r6, r0, lsl #2]\n"
 673 "    bics    r2, r1\n"
 674 "    str.w   r2, [r6, r0, lsl #2]\n"
 675 "loc_fc0ced9e:\n"
 676 "    subs    r0, r0, #1\n"
 677 "    sxtb    r0, r0\n"
 678 "    cmp     r0, #0\n"
 679 "    bge     loc_fc0ced8e\n"
 680 "loc_fc0ceda6:\n"
 681 "    ldr     r0, =0x00032734\n"
 682 "    add     r1, sp, #4\n"
 683 "    subs    r0, #0xc\n"
 684 "    bl      sub_fc086c7c\n"
 685 "    cmp     r0, #0\n"
 686 "    bne     loc_fc0ced72\n"
 687 "    ldr.w   r8, =0x00032734\n"
 688 "    movs    r4, #0\n"
 689 "loc_fc0cedba:\n"
 690 "    movs    r5, #0\n"
 691 "    ldr.w   r0, [r6, r4, lsl #2]\n"
 692 "    ldr.w   r1, [r8, r4, lsl #2]\n"
 693 "    ands    r0, r1\n"
 694 "    str.w   r0, [r6, r4, lsl #2]\n"
 695 "    b       loc_fc0cee12\n"
 696 "loc_fc0cedcc:\n"
 697 "    lsrs    r0, r5\n"
 698 "    lsls    r0, r0, #0x1f\n"
 699 "    beq     loc_fc0cee0a\n"
 700 "    ldr     r1, =0x00032734\n"
 701 "    add.w   r0, r5, r4, lsl #5\n"
 702 "    add     r3, sp, #8\n"
 703 "    subs    r1, #0x18\n"
 704 "    add     r2, sp, #0x14\n"
 705 "    uxtb    r0, r0\n"
 706 "    bl      sub_fc086f30\n"
 707 "    cbnz    r0, loc_fc0cedee\n"
 708 "    ldr     r1, [sp, #0x14]\n"
 709 "    movs    r0, #1\n"
 710 "    bl      sub_fc0cecd6\n"
 711 "loc_fc0cedee:\n"
 712 "    mov     r0, r4\n"
 713 "    b       loc_fc0cee06\n"
 714 "loc_fc0cedf2:\n"
 715 "    ldr.w   r1, [r7, r0, lsl #2]\n"
 716 "    cbz     r1, loc_fc0cee02\n"
 717 "    ldr.w   r2, [r6, r0, lsl #2]\n"
 718 "    bics    r2, r1\n"
 719 "    str.w   r2, [r6, r0, lsl #2]\n"
 720 "loc_fc0cee02:\n"
 721 "    adds    r0, r0, #1\n"
 722 "    sxtb    r0, r0\n"
 723 "loc_fc0cee06:\n"
 724 "    cmp     r0, #3\n"
 725 "    blt     loc_fc0cedf2\n"
 726 "loc_fc0cee0a:\n"
 727 "    ldr.w   r0, [r6, r4, lsl #2]\n"
 728 "    adds    r5, r5, #1\n"
 729 "    uxtb    r5, r5\n"
 730 "loc_fc0cee12:\n"
 731 "    cmp     r0, #0\n"
 732 "    bne     loc_fc0cedcc\n"
 733 "    adds    r4, r4, #1\n"
 734 "    sxtb    r4, r4\n"
 735 "    cmp     r4, #3\n"
 736 "    blt     loc_fc0cedba\n"
 737 //"    bl      sub_fc086af2\n"
 738 "    bl      sub_fc086af2_my\n"
 739 "    add     sp, #0x18\n"
 740 "    pop.w   {r4, r5, r6, r7, r8, pc}\n"
 741 ".ltorg\n"
 742     );
 743 }
 744 
 745 // -f=chdk -s=0xfc086af3 -c=10
 746 void __attribute__((naked,noinline)) sub_fc086af2_my() {
 747     asm volatile(
 748 "    push    {r4, lr}\n"
 749 "    ldr     r4, =0x0000960c\n"
 750 "    subs    r4, #0x10\n"
 751 "    ldr     r0, [r4, #8]\n"
 752 "    bl      sub_fc08b410\n"
 753 "    bl      sub_fc0f232c\n"
 754 "    ldr     r0, [r4, #0xc]\n"
 755 "    bl      sub_fc08b340\n"
 756 // re-ordered
 757 //"    pop.w   {r4, lr}\n"
 758 //"    b.w     loc_fc08b6f6\n"
 759 "    bl      handle_jogdial\n"  // +
 760 "    cmp     r0, #0\n"          // +
 761 "    beq     no_scroll\n"       // +
 762 "    bl      sub_fc08b6f6\n"    // handles scrollwheel(s), void function, no args
 763 "no_scroll:\n"                  // +
 764 "    pop     {r4, pc}\n"        // +
 765 ".ltorg\n"
 766     );
 767 }
 768 #endif

/* [<][>][^][v][top][bottom][index][help] */