root/platform/sx730hs/sub/100d/boot.c

/* [<][>][^][v][top][bottom][index][help] */

DEFINITIONS

This source file includes following definitions.
  1. spytask
  2. CreateTask_spytask
  3. boot
  4. CreateTask_low_my
  5. sub_fc05c938_my
  6. sub_fc05cacc_my
  7. sub_fc05cd70_my
  8. sub_fc589910_my
  9. task_Startup_my
  10. sub_fc589826_my
  11. init_file_modules_task
  12. init_required_fw_features
  13. kbd_p1_f_cont_my
  14. sub_fc589620_my
  15. TricInitTask_my
  16. kbd_p2_f_my
  17. sub_fc505f82_my

   1 #include "lolevel.h"
   2 #include "platform.h"
   3 #include "core.h"
   4 
   5 const char * const new_sa = &_end;
   6 
   7 // Forward declarations
   8 
   9 extern void task_CaptSeq();
  10 extern void task_InitFileModules();
  11 extern void task_RotaryEncoder();
  12 extern void task_MovieRecord();
  13 extern void task_ExpDrv();
  14 extern void task_TricInitTask();
  15 
  16 extern void handle_jogdial();
  17 
  18 /*----------------------------------------------------------------------
  19     spytask
  20 -----------------------------------------------------------------------*/
  21 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
  22 {
  23     core_spytask();
  24 }
  25 
  26 /*----------------------------------------------------------------------
  27     CreateTask_spytask
  28 -----------------------------------------------------------------------*/
  29 void CreateTask_spytask()
  30 {
  31     _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
  32 }
  33 
  34 /*
  35 //unsigned rbval=0;
  36 void task_blinker()
  37 {
  38 #if 0
  39     unsigned v=*(volatile unsigned *)(0x9808);
  40     unsigned pat=0;
  41     if(v & 0x80000){
  42         pat |=1;
  43     }
  44     if(v & 0x100000){
  45         pat |=2;
  46     }
  47     if(v & 0x200000){
  48         pat |=4;
  49     }
  50     if(v & 0x400000){
  51         pat |=8;
  52     }
  53     if(v & 0x800000){
  54         pat |=0x10;
  55     }
  56     while(1) {
  57         int i;
  58         for(i=0;i<5;i++) {
  59             *(volatile int*)0xd20b0994 = 0x4d0002;
  60             if((pat >> i) & 1) {
  61                 msleep(1000);
  62             } else {
  63                 msleep(250);
  64             }
  65             *(volatile int*)0xd20b0994 = 0x4c0003;
  66             msleep(500);
  67         }
  68         msleep(5000);
  69     }
  70 #endif
  71 #if 0
  72     int delay=1000;
  73     if(rbval == 0x12345678) {
  74         delay=100;
  75     }
  76     while(1) {
  77         *(volatile int*)0xd20b0994 = 0x4d0002;
  78         msleep(delay);
  79         *(volatile int*)0xd20b0994 = 0x4c0003;
  80         msleep(delay);
  81     }
  82 #endif
  83     while(1) {
  84         *(volatile int*)0xd20b0994 = 0x4d0002;
  85         msleep(250);
  86         *(volatile int*)0xd20b0994 = 0x4c0003;
  87         msleep(250);
  88     }
  89 }
  90 
  91 void CreateTask_blinker()
  92 {
  93     _CreateTask("blinker", 0x19, 0x200, task_blinker, 0);
  94 }
  95 */
  96 
  97 /*----------------------------------------------------------------------
  98     boot()
  99 
 100     Main entry point for the CHDK code
 101 -----------------------------------------------------------------------*/
 102 
 103 /*************************************************************/
 104 //  -f=chdk -s=0xfc02000d -c=43
 105 void __attribute__((naked,noinline)) boot() {
 106     asm volatile ( // 0xfc02000c
 107 "    movw    r0, #0x4000\n"
 108 "    movt    r0, #0\n"
 109 "    mov     sp, r0\n"
 110 "    bl      sub_fc02007e\n"
 111 "    ldr     r2, =0xc0242010\n"
 112 "    ldr     r1, [r2]\n"
 113 "    orr     r1, r1, #1\n"
 114 "    str     r1, [r2]\n"
 115 "    ldr     r0, =0xfcdcd810\n" // code copied from ROM
 116 "    ldr     r1, =0x010e1000\n" // to RAM
 117 "    ldr     r3, =0x010fc278\n"
 118 "loc_fc02002a:\n"
 119 "    cmp     r1, r3\n"
 120 "    itt     lo\n"
 121 "    ldrlo   r2, [r0], #4\n"
 122 "    strlo   r2, [r1], #4\n"
 123 "    blo     loc_fc02002a\n"
 124 "    ldr     r0, =0x010e1000\n"
 125 "    ldr     r1, =0x0001b278\n"
 126 "    bl      sub_fc0db23e\n"    // cache stuff for RAM code
 127 "    ldr     r0, =0xfcde8a88\n" // code copied from ROM
 128 "    ldr     r1, =0xbfe10800\n" // to TCM
 129 "    ldr     r3, =0xbfe1633d\n"
 130 "loc_fc020046:\n"
 131 "    cmp     r1, r3\n"
 132 "    itt     lo\n"
 133 "    ldrlo   r2, [r0], #4\n"
 134 "    strlo   r2, [r1], #4\n"
 135 "    blo     loc_fc020046\n"
 136 // Install CreateTask patch
 137 // use half words in case source or destination not word aligned
 138 // CreateTask is in ROM :(, use CreateTask_Low (bfe10b84) instead
 139         "adr     r0, patch_CreateTask\n"    // src: Patch data
 140         "ldr     r1, =hook_CreateTask_low\n"    // dest: Address to patch (hook_ has thumb bit off)
 141         "add     r2, r0, #8\n" // two words - note may clobber more than 2 instructions!
 142 "task_hook_loop:\n"
 143         "ldrh   r3, [r0],#2\n"
 144         "strh   r3, [r1],#2\n"
 145         "cmp    r0,r2\n"
 146         "blo    task_hook_loop\n"
 147 "    ldr     r0, =0xfcda103c\n" // DATA copied
 148 "    ldr     r1, =0x00008000\n" // to RAM
 149 "    ldr     r3, =0x000347d4\n"
 150 "loc_fc02005a:\n"
 151 "    cmp     r1, r3\n"
 152 "    itt     lo\n"
 153 "    ldrlo   r2, [r0], #4\n"
 154 "    strlo   r2, [r1], #4\n"
 155 "    blo     loc_fc02005a\n"
 156 "    ldr     r3, =0x000347d4\n" // BSS
 157 "    ldr     r1, =0x003976c0\n"
 158 "    mov.w   r2, #0\n"
 159 "loc_fc020070:\n"
 160 "    cmp     r3, r1\n"
 161 "    it      lo\n"
 162 "    strlo   r2, [r3], #4\n"
 163 "    blo     loc_fc020070\n"
 164 //"    ldr pc,=0xfc05c939\n" // -> fw
 165 "    b.w     sub_fc05c938_my\n" // ->
 166 
 167         "patch_CreateTask:\n"
 168         "ldr.w   pc, [pc,#0]\n"             // Do jump to absolute address CreateTask_my
 169         ".long   CreateTask_low_my + 1\n"           // has to be a thumb address
 170 );
 171 }
 172 
 173 /*************************************************************/
 174 void __attribute__((naked,noinline)) CreateTask_low_my() {
 175 asm volatile (
 176 // CreateTask_low has entry point in r0, use r1 
 177 "    push   {r1}\n"
 178 //R0 = Pointer to task function to create
 179 "    ldr     r1, =task_CaptSeq\n"       // DryOS original code function ptr.
 180 "    cmp     r1, r0\n"                  // is the given taskptr equal to our searched function?
 181 "    itt     eq\n"                      // EQ block
 182 "    ldreq   r0, =capt_seq_task\n"      // if so replace with our task function base ptr.
 183 "    orreq   r0, #1\n"                  // make sure it's a thumb address (may not be needed?)
 184 "    beq     exitHook\n"                // below compares not necessary if this check has found something.
 185 
 186 "    LDR     R1, =task_TricInitTask\n"
 187 "    CMP     R1, R0\n"
 188 "    itt     eq\n"
 189 "    LDREQ   R0, =TricInitTask_my\n"
 190 "    orreq   r0, #1\n"
 191 "    BEQ     exitHook\n"
 192 
 193 // exp_drv probably not needed for extended exposure, probably works up to 1024s, but required for < 1/3200
 194 "    LDR     R1, =task_ExpDrv\n"
 195 "    CMP     R1, R0\n"
 196 "    itt     eq\n"
 197 "    LDREQ   R0, =exp_drv_task\n"
 198 "    orreq   r0, #1\n"
 199 "    BEQ     exitHook\n"
 200 
 201 // note FileWrite does not exist on sx730
 202 
 203 // not implemented
 204 /*
 205 "    LDR     R0, =task_MovieRecord\n"
 206 "    CMP     R0, R3\n"
 207 "    LDREQ   R3, =movie_record_task\n"
 208 "    BEQ     exitHook\n"
 209 */
 210 
 211 "    ldr     r1, =task_InitFileModules\n"
 212 "    cmp     r1, r0\n"
 213 "    itt     eq\n"
 214 "    ldreq   r0, =init_file_modules_task\n"
 215 "    orreq   r0, #1\n"
 216 "exitHook:\n" 
 217 // restore overwritten register(s)
 218 "    pop    {r1}\n"
 219 // Execute overwritten instructions from original code, then jump to firmware
 220 // NOTE number of instructions duplicated here depends on size of original ROM code
 221 // instructions. Must replace 8 bytes + any paritially overwritten instructions
 222 // -s=CreateTask_low -c=3 -f=chdk
 223 "    push.w  {r4, r5, r6, r7, r8, lr}\n" // 32 bit + 4
 224 "    sub     sp, #0x20\n" // 16 bit, + 2
 225 "    ldrd    r7, r8, [sp, #0x3c]\n" // 32 bit + 4 = 10
 226 "    ldr.w   pc, =(hook_CreateTask_low + 10 + 1) \n"  // Continue in firmware (thumb bit set)
 227 ".ltorg\n"
 228 );
 229 }
 230 //
 231 // -f=chdk -s=0xfc05c939 -eret
 232 void __attribute__((naked,noinline)) sub_fc05c938_my() {
 233 // startup key checks handled in sub_fc589910_my
 234     asm volatile (
 235 "    push    {r4, lr}\n"
 236 #if defined(CHDK_NOT_IN_CANON_HEAP)
 237 "    ldr     r4, =0x003976c0\n"
 238 #else
 239     "ldr     r4, =new_sa\n"             // +
 240     "ldr     r4, [r4]\n"                // +
 241 #endif
 242 "    sub     sp, #0x78\n"
 243 "    ldr     r0, =0x006ce000\n"
 244 "    ldr     r1, =0x000adf44\n"
 245 "    subs    r0, r0, r4\n"
 246 "    cmp     r0, r1\n"
 247 "    bhs     loc_fc05c94a\n"
 248 "loc_fc05c948:\n"
 249 "    b       loc_fc05c948\n"
 250 "loc_fc05c94a:\n"
 251 "    ldr     r1, =0x00008078\n"
 252 "    mov.w   r0, #0x80000\n"
 253 "    str     r0, [r1]\n"
 254 "    ldr     r1, =0x0000807c\n"
 255 "    ldr     r0, =0x42281000\n"
 256 "    str     r0, [r1]\n"
 257 "    ldr     r1, =0x00008080\n"
 258 "    ldr     r0, =0x42283000\n"
 259 "    str     r0, [r1]\n"
 260 "    movs    r1, #0x78\n"
 261 "    mov     r0, sp\n"
 262 "    blx     sub_fc301dfc\n" // j_bzero
 263 "    ldr     r0, =0x0060ff00\n"
 264 "    ldr     r1, =0x000be100\n"
 265 "    stm.w   sp, {r0, r1, r4}\n"
 266 "    ldr     r1, =0x00601fbc\n"
 267 "    subs    r2, r1, r4\n"
 268 "    strd    r2, r1, [sp, #0xc]\n"
 269 "    str     r0, [sp, #0x14]\n"
 270 "    movs    r0, #0x22\n"
 271 "    str     r0, [sp, #0x18]\n"
 272 "    movs    r0, #0xc8\n"
 273 "    str     r0, [sp, #0x1c]\n"
 274 "    movw    r0, #0x2b0\n"
 275 "    str     r0, [sp, #0x20]\n"
 276 "    movs    r0, #0xfa\n"
 277 "    str     r0, [sp, #0x24]\n"
 278 "    movw    r0, #0x11a\n"
 279 "    str     r0, [sp, #0x28]\n"
 280 "    movs    r0, #0x85\n"
 281 "    str     r0, [sp, #0x2c]\n"
 282 "    movs    r0, #0x40\n"
 283 "    str     r0, [sp, #0x30]\n"
 284 "    movs    r0, #4\n"
 285 "    str     r0, [sp, #0x34]\n"
 286 "    movs    r0, #0\n"
 287 "    str     r0, [sp, #0x38]\n"
 288 "    movs    r0, #0x10\n"
 289 "    str     r0, [sp, #0x5c]\n"
 290 "    movs    r2, #0\n"
 291 "    lsls    r0, r0, #8\n"
 292 "    str     r0, [sp, #0x60]\n"
 293 //"    ldr     r1, =0xfc05cacd\n"
 294 "    ldr     r1, =sub_fc05cacc_my\n" // ->
 295 "    asrs    r0, r0, #4\n"
 296 "    str     r0, [sp, #0x64]\n"
 297 "    lsls    r0, r0, #5\n"
 298 "    str     r0, [sp, #0x68]\n"
 299 "    mov     r0, sp\n"
 300 "    blx     sub_fc3017dc\n"
 301 "    add     sp, #0x78\n"
 302 "    pop     {r4, pc}\n"
 303 ".ltorg\n"
 304     );
 305 }
 306 
 307 // -f=chdk -s=0xfc05cacd -c=54
 308 void __attribute__((naked,noinline)) sub_fc05cacc_my() {
 309     asm volatile (
 310 "    push    {r4, lr}\n"
 311 "    ldr     r4, =0xfc05cb74\n" //  *"/_term"
 312 "    bl      sub_fc05d9c0\n"
 313 "    ldr     r0, =0x00008310\n"
 314 "    ldr     r1, [r0]\n"
 315 "    ldr     r0, =0x00008078\n"
 316 "    ldr     r0, [r0]\n"
 317 "    adds    r0, #8\n"
 318 "    cmp     r1, r0\n"
 319 "    bhs     loc_fc05cae8\n"
 320 "    ldr     r0, =0xfc05cb84\n" //  *"USER_MEM size checking"
 321 "    bl      sub_fc05cb5e\n"
 322 "loc_fc05cae8:\n"
 323 "    bl      sub_fc074640\n"
 324 "    ldr     r1, =0xbfe10000\n"
 325 // note capdis bad output
 326 //"    mov.w   r2, #-0x11111112\n"
 327 "    mov.w   r2, #0xeeeeeeee\n"
 328 "    ldr     r3, =0xbfe10800\n"
 329 "loc_fc05caf4:\n"
 330 "    stm     r1!, {r2}\n"
 331 "    cmp     r1, r3\n"
 332 "    blo     loc_fc05caf4\n"
 333 "    bl      sub_fc074652\n"
 334 "    bl      sub_fc3a8c68\n"
 335 "    cmp     r0, #0\n"
 336 "    bge     loc_fc05cb0c\n"
 337 "    ldr     r0, =0xfc05cba4\n" //  *"dmSetup"
 338 "    bl      sub_fc05cb5e\n"
 339 "loc_fc05cb0c:\n"
 340 "    bl      sub_fc05e23c\n"
 341 "    cmp     r0, #0\n"
 342 "    bge     loc_fc05cb1a\n"
 343 "    ldr     r0, =0xfc05cbac\n" //  *"termDriverInit"
 344 "    bl      sub_fc05cb5e\n"
 345 "loc_fc05cb1a:\n"
 346 "    mov     r0, r4\n"
 347 "    bl      sub_fc05e2ca\n"
 348 "    cmp     r0, #0\n"
 349 "    bge     loc_fc05cb2a\n"
 350 "    ldr     r0, =0xfc05cbbc\n" //  *"termDeviceCreate"
 351 "    bl      sub_fc05cb5e\n"
 352 "loc_fc05cb2a:\n"
 353 "    mov     r0, r4\n"
 354 "    bl      sub_fc05cdcc\n"
 355 "    cmp     r0, #0\n"
 356 "    bge     loc_fc05cb3a\n"
 357 "    ldr     r0, =0xfc05cbd0\n" //  *"stdioSetup"
 358 "    bl      sub_fc05cb5e\n"
 359 "loc_fc05cb3a:\n"
 360 "    bl      sub_fc05cf10\n"
 361 "    cmp     r0, #0\n"
 362 "    bge     loc_fc05cb48\n"
 363 "    ldr     r0, =0xfc05cbdc\n" //  *"stdlibSetup"
 364 "    bl      sub_fc05cb5e\n"
 365 "loc_fc05cb48:\n"
 366 "    bl      sub_fc061684\n"
 367 "    cmp     r0, #0\n"
 368 "    bge     loc_fc05cb56\n"
 369 "    ldr     r0, =0xfc05cbe8\n" //  *"extlib_setup"
 370 "    bl      sub_fc05cb5e\n"
 371 "loc_fc05cb56:\n"
 372 "    pop.w   {r4, lr}\n"
 373 //"    b.w     loc_fc05cd70\n"
 374 "    b.w     sub_fc05cd70_my\n" // ->
 375     ".ltorg\n"
 376     );
 377 }
 378 
 379 //  -f=chdk -s=0xfc05cd71 -eret
 380 void __attribute__((naked,noinline)) sub_fc05cd70_my() {
 381     asm volatile (
 382 "    push    {r3, lr}\n"
 383 "    bl      sub_fc05d018\n"
 384 "    bl      sub_fc05cf34\n"
 385 "    bl      sub_fc0648f0\n" // IsNormalCameraMode_FW
 386 "    bl      sub_fc589910_my\n" // -> startup key checks, like sx710 fc0cf0ee
 387 "    cbnz    r0, loc_fc05cd8a\n"
 388 "    bl      sub_fc05d006\n"
 389 "loc_fc05cd88:\n"
 390 "    b       loc_fc05cd88\n"
 391 "loc_fc05cd8a:\n"
 392 "    bl      sub_fc369126\n"
 393 "    ldr     r1, =0x006ce000\n"
 394 "    movs    r0, #0\n"
 395 "    bl      sub_fc3519e8\n"
 396 "    movs    r3, #0\n"
 397 "    str     r3, [sp]\n"
 398 //"    ldr     r3, =0xfc05ccf5\n" //  task_Startup
 399 "    ldr     r3, =task_Startup_my\n" //  ->
 400 "    movs    r2, #0\n"
 401 "    movs    r1, #0x19\n"
 402 "    ldr     r0, =0xfc05cdc4\n" //  *"Startup"
 403 "    bl      _CreateTask\n"
 404 "    movs    r0, #0\n"
 405 "    pop     {r3, pc}\n"
 406     ".ltorg\n"
 407     );
 408 }
 409 
 410 // -f=chdk -s=0xfc589911 -eret
 411 void __attribute__((naked,noinline)) sub_fc589910_my() {
 412     asm volatile (
 413 "    push.w  {r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 414 "    movs    r4, #0\n"
 415 "    mov     fp, r0\n"
 416 "    mov     r5, r4\n"
 417 //"    bl      sub_fc505e80\n" // nullsub
 418 "    movs    r0, #0x97\n"
 419 "    bl      sub_fc506672\n" // MMIO 0xd20b025c (sub = return (*(0xd20b0000 + r0*4) << 15) < 0 )
 420 "    movs    r6, #1\n"
 421 "    bic.w   sb, r6, r0\n"
 422 "    movs    r0, #0x8a\n"
 423 "    bl      sub_fc506672\n" // MMIO 0xd20b0228
 424 "    bic.w   r8, r6, r0\n"
 425 "    movs    r0, #0\n"
 426 "    bl      sub_fc505e7c\n" // return 1
 427 "    cbz     r0, loc_fc589946\n"
 428 "    movs    r0, #0x98\n"
 429 "    bl      sub_fc506672\n" // MMIO 0xd20b0260
 430 "    bic.w   r4, r6, r0\n"
 431 "loc_fc589946:\n"
 432 "    movw    r0, #0x10e\n"
 433 "    bl      sub_fc506672\n" // MMIO 0xd20b0438
 434 "    bic.w   r7, r6, r0\n"
 435 "    movs    r0, #1\n"
 436 "    bl      sub_fc505e7c\n" // return 1
 437 "    cbz     r0, loc_fc589964\n"
 438 "    movs    r0, #2\n"
 439 "    bl      sub_fc506672\n" // MMIO 0xd20b0008
 440 "    bic.w   r5, r6, r0\n"
 441 "loc_fc589964:\n"
 442 "    movw    r0, #0x186\n"
 443 "    bl      sub_fc506672\n" // MMIO 0xd20b0618
 444 "    mov     sl, r6\n"
 445 "    bics    r6, r0\n"
 446 "    cmp.w   fp, #0\n"
 447 "    beq     loc_fc58999a\n" // this section not present in sx710, possibly related to USB wake / charge?
 448 "    cbz     r4, loc_fc58998a\n"
 449 "    movw    r0, #0x12c\n" 
 450 "    bl      _SleepTask\n" // Sleep(300)
 451 "    movs    r0, #0x98\n"
 452 "    bl      sub_fc506672\n" // MMIO 0xd20b0260 (again)
 453 "    bic.w   r4, sl, r0\n"
 454 "loc_fc58998a:\n"
 455 "    orr.w   r0, sb, r8\n"
 456 "    orr.w   r1, r4, r7\n"
 457 "    orrs    r0, r1\n"
 458 "    orrs    r0, r5\n"
 459 "    orrs    r0, r6\n"         // check all hardware related bits checked above
 460 //"    beq     loc_fc5899b0\n" // old behavior, skip to return if none set
 461 "    bne     loc_fc58999a\n"   // new behavior, go to final code if any set
 462     "mov  r8, #1\n"            // otherwise, act as if play was held (r8 guessed based on sx710)
 463 "loc_fc58999a:\n"
 464 "    strd    r5, r6, [sp]\n"
 465 "    mov     r3, r7\n"
 466 "    mov     r2, r4\n"
 467 "    mov     r1, r8\n"
 468 "    mov     r0, sb\n"
 469 "    bl      sub_fc505e84\n"
 470 //"    bl      sub_fc505e82\n" // nullsub
 471 "    movs    r0, #1\n"
 472 //"loc_fc5899b0:\n"
 473 "    pop.w   {r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, pc}\n"
 474     ".ltorg\n"
 475     );
 476 }
 477 
 478 // -f=chdk -s=task_Startup -c=34
 479 void __attribute__((naked,noinline)) task_Startup_my() {
 480     asm volatile (
 481 // task_Startup 0xfc05ccf5
 482 "    push    {r4, lr}\n"
 483 "    bl      sub_fc0dc368\n" // CreateTask ClockSave
 484 "    ldr     r0, =0x41121000\n"
 485 "    mov.w   r1, #0x20000\n"
 486 "    bl      sub_fc3a8790\n" // unknown, similar to sx710 fc38df1c
 487 "    cbz     r0, loc_fc05cd10\n"
 488 "    movs    r2, #0x95\n"
 489 "    movs    r0, #0\n"
 490 "    ldr     r1, =0xfc05cdb0\n" //  *"Startup.c"
 491 "    bl      _DebugAssert\n"
 492 "loc_fc05cd10:\n"
 493 "    bl      sub_fc05cfe0\n" // manipulates MMIOs, related to ClkEnabler_DUKE.c (like sx710 fc055f00)
 494 //"    bl      sub_fc0dc400\n" // nullsub
 495 "    bl      sub_fc081478\n" // ?
 496 // SD startup reset for UHS support https://chdk.setepontos.com/index.php?topic=13089.msg132583#msg132583
 497 "    bl      sub_010e19de\n" // similar to sx710 010e182c, called from func following func which creates SD1stinit task
 498 //"    bl      sub_fc0dc486\n" // StartDiskboot
 499 //"    bl      CreateTask_blinker\n"
 500 "    bl      sub_fc3a88be\n"
 501 "    bl      sub_fc074688\n"
 502 "    bl      sub_fc05d134\n"
 503 "    bl      sub_fc05d0c8\n" // "InitExDrivers.c", Omar init
 504 "    bl      sub_fc0814ae\n" // StartWDT (and a lot of other stuff)
 505 "    bl      sub_fc3a8818\n"
 506 "    bl      sub_fc07468e\n" // UiMemory.C Ctrl*
 507 //"    bl      sub_fc589826\n" // CreateTask PhySw
 508 "    bl      sub_fc589826_my\n" // CreateTask PhySw
 509 "    bl      CreateTask_spytask\n" 
 510 "    bl      init_required_fw_features\n" // added
 511 "    bl      sub_fc27ec44\n" // SsTask etc
 512 "    bl      sub_fc0746a4\n"
 513 "    bl      sub_fc093948\n"
 514 "    bl      sub_fc0dbeda\n" // Battery.c
 515 "    bl      sub_fc093a78\n" // task_Bye
 516 "    bl      sub_fc0dc288\n"
 517 "    bl      sub_fc0dbe96\n" // BatteryTask
 518 //"    bl      sub_fc05d138\n" // nullsub
 519 "    bl      sub_fc32d346\n"
 520 "    bl      sub_fc0dbe68\n"
 521 "    pop.w   {r4, lr}\n"
 522 //"    b.w     loc_fc0dc33e\n"
 523 "    ldr     pc,=0xfc0dc33f\n"
 524     ".ltorg\n"
 525     );
 526 }
 527 
 528 // -f=chdk -s=0xfc589827 -c=19
 529 void __attribute__((naked,noinline)) sub_fc589826_my() {
 530     asm volatile (
 531 "    push    {r2, r3, r4, lr}\n"
 532 "    bl      sub_fc0fd7ac\n"
 533 "    bl      sub_fc06486e\n" // IsFactoryMode_FW
 534 "    cbnz    r0, loc_fc589836\n"
 535 "    bl      sub_fc0fd750\n" // OpLog.Start_FW
 536 "loc_fc589836:\n"
 537 "    ldr     r4, =0x00008190\n" //  physw_run
 538 "    ldr     r0, [r4, #4]\n"
 539 "    cmp     r0, #0\n"
 540 "    bne     loc_fc589856\n"
 541 "    movs    r3, #1\n"
 542 "    movs    r2, #0\n"
 543 "    movs    r1, #0x13\n"
 544 "    strd    r2, r3, [sp]\n"
 545 //"    ldr     r3, =0xfc589801\n" //  task_PhySw
 546 "    ldr     r3, =mykbd_task\n"
 547 "    ldr     r0, =0xfc589bc4\n" //  *"PhySw"
 548 //"    movw    r2, #0x800\n"
 549 "    movw    r2, #0x2000\n" // adjusted 0x800 -> 0x2000
 550 "    bl      sub_fc34b9c2\n" // CreateTaskStrictly_alt
 551 "    str     r0, [r4, #4]\n"
 552 "loc_fc589856:\n"
 553 //"    b       loc_fc589554\n" // jumps over unrelated code to pop in stock firmware
 554 "    pop     {r2, r3, r4, pc}\n"
 555     ".ltorg\n"
 556     );
 557 }
 558 
 559 // -f=chdk -s=task_InitFileModules -eret
 560 void __attribute__((naked,noinline)) init_file_modules_task() {
 561     asm volatile (
 562 // task_InitFileModules 0xfc0972a5
 563 "    push    {r4, r5, r6, lr}\n"
 564 "    movs    r0, #6\n"
 565 //"    bl      sub_fc32ca18\n" //  return
 566 "    bl      sub_fc099270\n"
 567 "    movs    r4, r0\n"
 568 "    movw    r5, #0x5006\n"
 569 "    beq     loc_fc0972c0\n"
 570 "    movs    r1, #0\n"
 571 "    mov     r0, r5\n"
 572 "    bl      _PostLogicalEventToUI\n"
 573 "loc_fc0972c0:\n"
 574 "    bl      sub_fc09929a\n"
 575 "    BL      core_spytask_can_start\n" // + CHDK: Set "it's-safe-to-start" flag for spytask
 576 "    cmp     r4, #0\n"
 577 "    bne     loc_fc0972d4\n" //  return
 578 "    mov     r0, r5\n"
 579 "    pop.w   {r4, r5, r6, lr}\n"
 580 "    movs    r1, #1\n"
 581 "    b.w     _PostLogicalEventToUI\n"
 582 "loc_fc0972d4:\n"
 583 "    pop     {r4, r5, r6, pc}\n"
 584     ".ltorg\n"
 585     );
 586 }
 587 
 588 /*
 589     *** workaround ***
 590     Init stuff to avoid asserts on cameras running DryOS r54+
 591     https://chdk.setepontos.com/index.php?topic=12516.0
 592     Execute this only once
 593  */
 594 void init_required_fw_features(void) {
 595     extern void _init_focus_eventflag();
 596 
 597     _init_focus_eventflag();
 598     extern int av_override_semaphore;
 599     extern int _CreateBinarySemaphoreStrictly(int x, int y);
 600     av_override_semaphore = _CreateBinarySemaphoreStrictly(0,0);
 601 }
 602 
 603 void __attribute__((naked,noinline)) kbd_p1_f_cont_my ()
 604 {
 605 // -f=chdk -s=kbd_p1_f_cont -c=18 -jfw
 606     asm volatile(
 607 // kbd_p1_f_cont 0xfc589b4f
 608 "    ldr     r3, =0x0003578c\n" //  physw_status
 609 "    movs    r0, #2\n"
 610 "    mov     r5, sp\n"
 611 "    add.w   r6, r3, #0x24\n"
 612 "loc_fc589b58:\n"
 613 "    add.w   r1, r6, r0, lsl #2\n"
 614 "    ldr.w   r2, [r3, r0, lsl #2]\n"
 615 "    ldr     r7, [r1, #0xc]\n"
 616 "    ldr     r1, [r1, #0x18]\n"
 617 "    and.w   r2, r2, r7\n"
 618 "    eor.w   r2, r2, r1\n"
 619 "    str.w   r2, [r5, r0, lsl #2]\n"
 620 "    subs    r0, r0, #1\n"
 621 "    bpl     loc_fc589b58\n"
 622 "    ldr     r2, =0x0003578c\n" //  physw_status
 623 "    mov     r0, sp\n"
 624 "    adds    r2, #0x18\n"
 625 "    sub.w   r1, r2, #0xc\n"
 626 //"    bl      sub_fc589620\n"
 627 "    bl      sub_fc589620_my\n" // + 
 628 "    ldr     pc, =0xfc589b83\n" // Continue in firmware
 629     ".ltorg\n"
 630     );
 631 }
 632 
 633 extern int physw_override;
 634 // -f=chdk -s=0xfc589621 -c=4 -jfw
 635 void __attribute__((naked,noinline)) sub_fc589620_my()
 636 {
 637     asm volatile(
 638 "    push.w  {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 639 "    ldr     r4, =0x000357b0\n"
 640 "    mov     r5, r0\n"
 641 "    ldr     r0, =physw_override\n" // +
 642 "    ldr.w   r0, [r0]\n" // + use CHDK override value
 643 //"    mov.w   r0, #-1\n"
 644 "    ldr     pc, =0xfc58962d\n" // Continue in firmware
 645     );
 646 }
 647 
 648 // fix for FI2 boot, see https://chdk.setepontos.com/index.php?topic=11316.msg136622#msg136622
 649 // -f=chdk -s=task_TricInitTask -c=35
 650 void __attribute__((naked,noinline)) TricInitTask_my()
 651 {
 652     asm volatile(
 653 // task_TricInitTask 0xfc521929
 654 "    push.w  {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 655 "    movs    r0, #8\n"
 656 "    ldr     r1, =0xfc521b54\n" //  *"InitTskStart"
 657 "    bl      sub_fc350df2\n"
 658 "    ldr.w   sl, =0x0001c440\n"
 659 "    movw    fp, #0x1000\n"
 660 "    ldr     r4, =0x0001c43c\n"
 661 "    movs    r2, #0\n"
 662 "    ldr     r1, =0x0703870f\n"
 663 "    ldr     r0, [r4]\n"
 664 "    bl      sub_fc3699c0\n" // WaitForAnyEventFlag
 665 "    lsls    r0, r0, #0x1f\n"
 666 "    beq     loc_fc52195e\n"
 667 "    movs    r0, #8\n"
 668 "    ldr     r1, =0xfc521b6c\n" //  *"ER IniTskWait"
 669 "    bl      sub_fc350e52\n"
 670 "    ldr     r1, =0x0001c428\n"
 671 "    movs    r0, #0\n"
 672 "    str     r0, [r1]\n"
 673 "    pop.w   {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, pc}\n"
 674 "loc_fc52195e:\n"
 675 "    ldr     r4, =0x0001c43c\n"
 676 "    add     r1, sp, #0xc\n"
 677 "    ldr     r0, [r4]\n"
 678 "    bl      sub_fc369c1a\n" // GetEventFlagValue
 679 "    ldr     r1, [sp, #0xc]\n"
 680 "    ldr     r0, [r4]\n"
 681 "    bl      sub_fc369bea\n" // ClearEventFlag
 682 "    ldr     r0, =0x02000003\n"
 683 "    ldr     r7, [sp, #0xc]\n"
 684 "    tst     r7, r0\n"
 685 "    beq     sub_fc521a62\n" // loc -> sub
 686 "    lsls    r0, r7, #0x1f\n"
 687 "    beq     sub_fc521982\n" // loc -> sub
 688 
 689 "    ldr     r0, =0xd2020074\n" // + MMIO ref'd from fc412414, via end of fc521e06
 690 "    ldr     r0, [r0]\n"        // + nonzero when core already running
 691 "    subs    r0, #0\n"          // +
 692 "    beq     tric1\n"           // +
 693 "    ldr     r0, [r4]\n"        // +
 694 "    mov     r1, #0x80\n"       // +
 695 "    bl      _SetEventFlag\n"   // + core already initialized, set the SmacIdleCmp eventflag here
 696 "tric1:\n"                      // +
 697 
 698 "    bl      sub_fc521e06\n"
 699 "    ldr     pc,=0xfc5219ef\n" // b to ldr pc
 700     ".ltorg\n"
 701     );
 702 }
 703 #ifdef CAM_HAS_JOGDIAL
 704 // -f=chdk -s=kbd_p2_f -eret
 705 void __attribute__((naked,noinline)) kbd_p2_f_my() {
 706     asm volatile(
 707 // kbd_p2_f 0xfc58955d
 708 "loc_fc58955c:\n"
 709 "    push.w  {r4, r5, r6, r7, r8, lr}\n"
 710 "    ldr     r6, =0x000357b0\n"
 711 "    sub     sp, #0x18\n"
 712 "    add     r7, sp, #8\n"
 713 "    subs    r6, #0xc\n"
 714 "    b       loc_fc58959e\n"
 715 "loc_fc58956a:\n"
 716 "    ldr     r1, =0x000357b0\n"
 717 "    add     r3, sp, #8\n"
 718 "    ldrb.w  r0, [sp, #4]\n"
 719 "    add     r2, sp, #0x14\n"
 720 "    subs    r1, #0x18\n"
 721 "    bl      sub_fc5064a4\n"
 722 "    cbnz    r0, loc_fc589584\n"
 723 "    ldr     r1, [sp, #0x14]\n"
 724 "    movs    r0, #0\n"
 725 "    bl      sub_fc5894ce\n"
 726 "loc_fc589584:\n"
 727 "    movs    r0, #2\n"
 728 "loc_fc589586:\n"
 729 "    ldr.w   r1, [r7, r0, lsl #2]\n"
 730 "    cbz     r1, loc_fc589596\n"
 731 "    ldr.w   r2, [r6, r0, lsl #2]\n"
 732 "    bics    r2, r1\n"
 733 "    str.w   r2, [r6, r0, lsl #2]\n"
 734 "loc_fc589596:\n"
 735 "    subs    r0, r0, #1\n"
 736 "    sxtb    r0, r0\n"
 737 "    cmp     r0, #0\n"
 738 "    bge     loc_fc589586\n"
 739 "loc_fc58959e:\n"
 740 "    ldr     r0, =0x000357b0\n"
 741 "    add     r1, sp, #4\n"
 742 "    subs    r0, #0xc\n"
 743 "    bl      sub_fc5061d2\n"
 744 "    cmp     r0, #0\n"
 745 "    bne     loc_fc58956a\n"
 746 "    ldr.w   r8, =0x000357b0\n"
 747 "    movs    r4, #0\n"
 748 "loc_fc5895b2:\n"
 749 "    movs    r5, #0\n"
 750 "    ldr.w   r0, [r6, r4, lsl #2]\n"
 751 "    ldr.w   r1, [r8, r4, lsl #2]\n"
 752 "    ands    r0, r1\n"
 753 "    str.w   r0, [r6, r4, lsl #2]\n"
 754 "    b       loc_fc58960a\n"
 755 "loc_fc5895c4:\n"
 756 "    lsrs    r0, r5\n"
 757 "    lsls    r0, r0, #0x1f\n"
 758 "    beq     loc_fc589602\n"
 759 "    ldr     r1, =0x000357b0\n"
 760 "    add.w   r0, r5, r4, lsl #5\n"
 761 "    add     r3, sp, #8\n"
 762 "    subs    r1, #0x18\n"
 763 "    add     r2, sp, #0x14\n"
 764 "    uxtb    r0, r0\n"
 765 "    bl      sub_fc5064a4\n"
 766 "    cbnz    r0, loc_fc5895e6\n"
 767 "    ldr     r1, [sp, #0x14]\n"
 768 "    movs    r0, #1\n"
 769 "    bl      sub_fc5894ce\n"
 770 "loc_fc5895e6:\n"
 771 "    mov     r0, r4\n"
 772 "    b       loc_fc5895fe\n"
 773 "loc_fc5895ea:\n"
 774 "    ldr.w   r1, [r7, r0, lsl #2]\n"
 775 "    cbz     r1, loc_fc5895fa\n"
 776 "    ldr.w   r2, [r6, r0, lsl #2]\n"
 777 "    bics    r2, r1\n"
 778 "    str.w   r2, [r6, r0, lsl #2]\n"
 779 "loc_fc5895fa:\n"
 780 "    adds    r0, r0, #1\n"
 781 "    sxtb    r0, r0\n"
 782 "loc_fc5895fe:\n"
 783 "    cmp     r0, #3\n"
 784 "    blt     loc_fc5895ea\n"
 785 "loc_fc589602:\n"
 786 "    ldr.w   r0, [r6, r4, lsl #2]\n"
 787 "    adds    r5, r5, #1\n"
 788 "    uxtb    r5, r5\n"
 789 "loc_fc58960a:\n"
 790 "    cmp     r0, #0\n"
 791 "    bne     loc_fc5895c4\n"
 792 "    adds    r4, r4, #1\n"
 793 "    sxtb    r4, r4\n"
 794 "    cmp     r4, #3\n"
 795 "    blt     loc_fc5895b2\n"
 796 //"    bl      sub_fc505f82\n"
 797 "    bl      sub_fc505f82_my\n"
 798 "    add     sp, #0x18\n"
 799 "    pop.w   {r4, r5, r6, r7, r8, pc}\n" 
 800 ".ltorg\n"
 801     );
 802 }
 803 // -f=chdk -s=0xfc505f83 -c=9
 804 void __attribute__((naked,noinline)) sub_fc505f82_my() {
 805     asm volatile(
 806 "    push    {r4, lr}\n"
 807 "    ldr     r4, =0x00009ad8\n"
 808 "    ldr     r0, [r4, #8]\n"
 809 "    bl      sub_fc50a904\n"
 810 "    bl      sub_fc3d45a0\n"
 811 "    ldr     r0, [r4, #0xc]\n"
 812 "    bl      sub_fc50a834\n"
 813 "    bl      handle_jogdial\n"  // +
 814 "    cmp     r0, #0\n"          // +
 815 "    beq     no_scroll\n"       // +
 816 "    bl      sub_fc50addc\n"    // handles scrollwheel(s), void function, no args
 817 //"    pop.w   {r4, lr}\n"
 818 "no_scroll:\n"                  // +
 819 "    pop   {r4, pc}\n"          // +
 820 //"    b.w     loc_fc50addc\n"
 821 ".ltorg\n"
 822     );
 823 }
 824 #endif

/* [<][>][^][v][top][bottom][index][help] */