root/platform/sx730hs/sub/100d/boot.c

/* [<][>][^][v][top][bottom][index][help] */

DEFINITIONS

This source file includes following definitions.
  1. spytask
  2. CreateTask_spytask
  3. boot
  4. CreateTask_low_my
  5. sub_fc05c938_my
  6. sub_fc05cacc_my
  7. sub_fc05cd70_my
  8. sub_fc589910_my
  9. task_Startup_my
  10. sub_fc589826_my
  11. init_file_modules_task
  12. init_required_fw_features
  13. kbd_p1_f_cont_my
  14. sub_fc589620_my
  15. TricInitTask_my
  16. kbd_p2_f_my
  17. sub_fc505f82_my

   1 #include "lolevel.h"
   2 #include "platform.h"
   3 #include "core.h"
   4 
   5 const char * const new_sa = &_end;
   6 
   7 // Forward declarations
   8 
   9 extern void task_CaptSeq();
  10 extern void task_InitFileModules();
  11 extern void task_RotaryEncoder();
  12 extern void task_MovieRecord();
  13 extern void task_ExpDrv();
  14 extern void task_TricInitTask();
  15 
  16 extern void handle_jogdial();
  17 
  18 /*----------------------------------------------------------------------
  19     spytask
  20 -----------------------------------------------------------------------*/
  21 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
  22 {
  23     (void)ua; (void)ub; (void)uc; (void)ud; (void)ue; (void)uf;
  24     core_spytask();
  25 }
  26 
  27 /*----------------------------------------------------------------------
  28     CreateTask_spytask
  29 -----------------------------------------------------------------------*/
  30 void CreateTask_spytask()
  31 {
  32     _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
  33 }
  34 
  35 /*
  36 //unsigned rbval=0;
  37 void task_blinker()
  38 {
  39 #if 0
  40     unsigned v=*(volatile unsigned *)(0x9808);
  41     unsigned pat=0;
  42     if(v & 0x80000){
  43         pat |=1;
  44     }
  45     if(v & 0x100000){
  46         pat |=2;
  47     }
  48     if(v & 0x200000){
  49         pat |=4;
  50     }
  51     if(v & 0x400000){
  52         pat |=8;
  53     }
  54     if(v & 0x800000){
  55         pat |=0x10;
  56     }
  57     while(1) {
  58         int i;
  59         for(i=0;i<5;i++) {
  60             *(volatile int*)0xd20b0994 = 0x4d0002;
  61             if((pat >> i) & 1) {
  62                 msleep(1000);
  63             } else {
  64                 msleep(250);
  65             }
  66             *(volatile int*)0xd20b0994 = 0x4c0003;
  67             msleep(500);
  68         }
  69         msleep(5000);
  70     }
  71 #endif
  72 #if 0
  73     int delay=1000;
  74     if(rbval == 0x12345678) {
  75         delay=100;
  76     }
  77     while(1) {
  78         *(volatile int*)0xd20b0994 = 0x4d0002;
  79         msleep(delay);
  80         *(volatile int*)0xd20b0994 = 0x4c0003;
  81         msleep(delay);
  82     }
  83 #endif
  84     while(1) {
  85         *(volatile int*)0xd20b0994 = 0x4d0002;
  86         msleep(250);
  87         *(volatile int*)0xd20b0994 = 0x4c0003;
  88         msleep(250);
  89     }
  90 }
  91 
  92 void CreateTask_blinker()
  93 {
  94     _CreateTask("blinker", 0x19, 0x200, task_blinker, 0);
  95 }
  96 */
  97 
  98 /*----------------------------------------------------------------------
  99     boot()
 100 
 101     Main entry point for the CHDK code
 102 -----------------------------------------------------------------------*/
 103 
 104 /*************************************************************/
 105 //  -f=chdk -s=0xfc02000d -c=43
 106 void __attribute__((naked,noinline)) boot() {
 107     asm volatile ( // 0xfc02000c
 108 "    movw    r0, #0x4000\n"
 109 "    movt    r0, #0\n"
 110 "    mov     sp, r0\n"
 111 "    bl      sub_fc02007e\n"
 112 "    ldr     r2, =0xc0242010\n"
 113 "    ldr     r1, [r2]\n"
 114 "    orr     r1, r1, #1\n"
 115 "    str     r1, [r2]\n"
 116 "    ldr     r0, =0xfcdcd810\n" // code copied from ROM
 117 "    ldr     r1, =0x010e1000\n" // to RAM
 118 "    ldr     r3, =0x010fc278\n"
 119 "loc_fc02002a:\n"
 120 "    cmp     r1, r3\n"
 121 "    itt     lo\n"
 122 "    ldrlo   r2, [r0], #4\n"
 123 "    strlo   r2, [r1], #4\n"
 124 "    blo     loc_fc02002a\n"
 125 "    ldr     r0, =0x010e1000\n"
 126 "    ldr     r1, =0x0001b278\n"
 127 "    bl      sub_fc0db23e\n"    // cache stuff for RAM code
 128 "    ldr     r0, =0xfcde8a88\n" // code copied from ROM
 129 "    ldr     r1, =0xbfe10800\n" // to TCM
 130 "    ldr     r3, =0xbfe1633d\n"
 131 "loc_fc020046:\n"
 132 "    cmp     r1, r3\n"
 133 "    itt     lo\n"
 134 "    ldrlo   r2, [r0], #4\n"
 135 "    strlo   r2, [r1], #4\n"
 136 "    blo     loc_fc020046\n"
 137 // Install CreateTask patch
 138 // use half words in case source or destination not word aligned
 139 // CreateTask is in ROM :(, use CreateTask_Low (bfe10b84) instead
 140         "adr     r0, patch_CreateTask\n"    // src: Patch data
 141         "ldr     r1, =hook_CreateTask_low\n"    // dest: Address to patch (hook_ has thumb bit off)
 142         "add     r2, r0, #8\n" // two words - note may clobber more than 2 instructions!
 143 "task_hook_loop:\n"
 144         "ldrh   r3, [r0],#2\n"
 145         "strh   r3, [r1],#2\n"
 146         "cmp    r0,r2\n"
 147         "blo    task_hook_loop\n"
 148 "    ldr     r0, =0xfcda103c\n" // DATA copied
 149 "    ldr     r1, =0x00008000\n" // to RAM
 150 "    ldr     r3, =0x000347d4\n"
 151 "loc_fc02005a:\n"
 152 "    cmp     r1, r3\n"
 153 "    itt     lo\n"
 154 "    ldrlo   r2, [r0], #4\n"
 155 "    strlo   r2, [r1], #4\n"
 156 "    blo     loc_fc02005a\n"
 157 "    ldr     r3, =0x000347d4\n" // BSS
 158 "    ldr     r1, =0x003976c0\n"
 159 "    mov.w   r2, #0\n"
 160 "loc_fc020070:\n"
 161 "    cmp     r3, r1\n"
 162 "    it      lo\n"
 163 "    strlo   r2, [r3], #4\n"
 164 "    blo     loc_fc020070\n"
 165 //"    ldr pc,=0xfc05c939\n" // -> fw
 166 "    b.w     sub_fc05c938_my\n" // ->
 167 
 168         "patch_CreateTask:\n"
 169         "ldr.w   pc, [pc,#0]\n"             // Do jump to absolute address CreateTask_my
 170         ".long   CreateTask_low_my + 1\n"           // has to be a thumb address
 171 );
 172 }
 173 
 174 /*************************************************************/
 175 void __attribute__((naked,noinline)) CreateTask_low_my() {
 176 asm volatile (
 177 // CreateTask_low has entry point in r0, use r1 
 178 "    push   {r1}\n"
 179 //R0 = Pointer to task function to create
 180 "    ldr     r1, =task_CaptSeq\n"       // DryOS original code function ptr.
 181 "    cmp     r1, r0\n"                  // is the given taskptr equal to our searched function?
 182 "    itt     eq\n"                      // EQ block
 183 "    ldreq   r0, =capt_seq_task\n"      // if so replace with our task function base ptr.
 184 "    orreq   r0, #1\n"                  // make sure it's a thumb address (may not be needed?)
 185 "    beq     exitHook\n"                // below compares not necessary if this check has found something.
 186 
 187 "    LDR     R1, =task_TricInitTask\n"
 188 "    CMP     R1, R0\n"
 189 "    itt     eq\n"
 190 "    LDREQ   R0, =TricInitTask_my\n"
 191 "    orreq   r0, #1\n"
 192 "    BEQ     exitHook\n"
 193 
 194 // exp_drv probably not needed for extended exposure, probably works up to 1024s, but required for < 1/3200
 195 "    LDR     R1, =task_ExpDrv\n"
 196 "    CMP     R1, R0\n"
 197 "    itt     eq\n"
 198 "    LDREQ   R0, =exp_drv_task\n"
 199 "    orreq   r0, #1\n"
 200 "    BEQ     exitHook\n"
 201 
 202 // note FileWrite does not exist on sx730
 203 
 204 // not implemented
 205 /*
 206 "    LDR     R0, =task_MovieRecord\n"
 207 "    CMP     R0, R3\n"
 208 "    LDREQ   R3, =movie_record_task\n"
 209 "    BEQ     exitHook\n"
 210 */
 211 
 212 "    ldr     r1, =task_InitFileModules\n"
 213 "    cmp     r1, r0\n"
 214 "    itt     eq\n"
 215 "    ldreq   r0, =init_file_modules_task\n"
 216 "    orreq   r0, #1\n"
 217 "exitHook:\n" 
 218 // restore overwritten register(s)
 219 "    pop    {r1}\n"
 220 // Execute overwritten instructions from original code, then jump to firmware
 221 // NOTE number of instructions duplicated here depends on size of original ROM code
 222 // instructions. Must replace 8 bytes + any paritially overwritten instructions
 223 // -s=CreateTask_low -c=3 -f=chdk
 224 "    push.w  {r4, r5, r6, r7, r8, lr}\n" // 32 bit + 4
 225 "    sub     sp, #0x20\n" // 16 bit, + 2
 226 "    ldrd    r7, r8, [sp, #0x3c]\n" // 32 bit + 4 = 10
 227 "    ldr.w   pc, =(hook_CreateTask_low + 10 + 1) \n"  // Continue in firmware (thumb bit set)
 228 ".ltorg\n"
 229 );
 230 }
 231 //
 232 // -f=chdk -s=0xfc05c939 -eret
 233 void __attribute__((naked,noinline)) sub_fc05c938_my() {
 234 // startup key checks handled in sub_fc589910_my
 235     asm volatile (
 236 "    push    {r4, lr}\n"
 237 #if defined(CHDK_NOT_IN_CANON_HEAP)
 238 "    ldr     r4, =0x003976c0\n"
 239 #else
 240     "ldr     r4, =new_sa\n"             // +
 241     "ldr     r4, [r4]\n"                // +
 242 #endif
 243 "    sub     sp, #0x78\n"
 244 "    ldr     r0, =0x006ce000\n"
 245 "    ldr     r1, =0x000adf44\n"
 246 "    subs    r0, r0, r4\n"
 247 "    cmp     r0, r1\n"
 248 "    bhs     loc_fc05c94a\n"
 249 "loc_fc05c948:\n"
 250 "    b       loc_fc05c948\n"
 251 "loc_fc05c94a:\n"
 252 "    ldr     r1, =0x00008078\n"
 253 "    mov.w   r0, #0x80000\n"
 254 "    str     r0, [r1]\n"
 255 "    ldr     r1, =0x0000807c\n"
 256 "    ldr     r0, =0x42281000\n"
 257 "    str     r0, [r1]\n"
 258 "    ldr     r1, =0x00008080\n"
 259 "    ldr     r0, =0x42283000\n"
 260 "    str     r0, [r1]\n"
 261 "    movs    r1, #0x78\n"
 262 "    mov     r0, sp\n"
 263 "    blx     sub_fc301dfc\n" // j_bzero
 264 "    ldr     r0, =0x0060ff00\n"
 265 "    ldr     r1, =0x000be100\n"
 266 "    stm.w   sp, {r0, r1, r4}\n"
 267 "    ldr     r1, =0x00601fbc\n"
 268 "    subs    r2, r1, r4\n"
 269 "    strd    r2, r1, [sp, #0xc]\n"
 270 "    str     r0, [sp, #0x14]\n"
 271 "    movs    r0, #0x22\n"
 272 "    str     r0, [sp, #0x18]\n"
 273 "    movs    r0, #0xc8\n"
 274 "    str     r0, [sp, #0x1c]\n"
 275 "    movw    r0, #0x2b0\n"
 276 "    str     r0, [sp, #0x20]\n"
 277 "    movs    r0, #0xfa\n"
 278 "    str     r0, [sp, #0x24]\n"
 279 "    movw    r0, #0x11a\n"
 280 "    str     r0, [sp, #0x28]\n"
 281 "    movs    r0, #0x85\n"
 282 "    str     r0, [sp, #0x2c]\n"
 283 "    movs    r0, #0x40\n"
 284 "    str     r0, [sp, #0x30]\n"
 285 "    movs    r0, #4\n"
 286 "    str     r0, [sp, #0x34]\n"
 287 "    movs    r0, #0\n"
 288 "    str     r0, [sp, #0x38]\n"
 289 "    movs    r0, #0x10\n"
 290 "    str     r0, [sp, #0x5c]\n"
 291 "    movs    r2, #0\n"
 292 "    lsls    r0, r0, #8\n"
 293 "    str     r0, [sp, #0x60]\n"
 294 //"    ldr     r1, =0xfc05cacd\n"
 295 "    ldr     r1, =sub_fc05cacc_my\n" // ->
 296 "    asrs    r0, r0, #4\n"
 297 "    str     r0, [sp, #0x64]\n"
 298 "    lsls    r0, r0, #5\n"
 299 "    str     r0, [sp, #0x68]\n"
 300 "    mov     r0, sp\n"
 301 "    blx     sub_fc3017dc\n"
 302 "    add     sp, #0x78\n"
 303 "    pop     {r4, pc}\n"
 304 ".ltorg\n"
 305     );
 306 }
 307 
 308 // -f=chdk -s=0xfc05cacd -c=54
 309 void __attribute__((naked,noinline)) sub_fc05cacc_my() {
 310     asm volatile (
 311 "    push    {r4, lr}\n"
 312 "    ldr     r4, =0xfc05cb74\n" //  *"/_term"
 313 "    bl      sub_fc05d9c0\n"
 314 "    ldr     r0, =0x00008310\n"
 315 "    ldr     r1, [r0]\n"
 316 "    ldr     r0, =0x00008078\n"
 317 "    ldr     r0, [r0]\n"
 318 "    adds    r0, #8\n"
 319 "    cmp     r1, r0\n"
 320 "    bhs     loc_fc05cae8\n"
 321 "    ldr     r0, =0xfc05cb84\n" //  *"USER_MEM size checking"
 322 "    bl      sub_fc05cb5e\n"
 323 "loc_fc05cae8:\n"
 324 "    bl      sub_fc074640\n"
 325 "    ldr     r1, =0xbfe10000\n"
 326 // note capdis bad output
 327 //"    mov.w   r2, #-0x11111112\n"
 328 "    mov.w   r2, #0xeeeeeeee\n"
 329 "    ldr     r3, =0xbfe10800\n"
 330 "loc_fc05caf4:\n"
 331 "    stm     r1!, {r2}\n"
 332 "    cmp     r1, r3\n"
 333 "    blo     loc_fc05caf4\n"
 334 "    bl      sub_fc074652\n"
 335 "    bl      sub_fc3a8c68\n"
 336 "    cmp     r0, #0\n"
 337 "    bge     loc_fc05cb0c\n"
 338 "    ldr     r0, =0xfc05cba4\n" //  *"dmSetup"
 339 "    bl      sub_fc05cb5e\n"
 340 "loc_fc05cb0c:\n"
 341 "    bl      sub_fc05e23c\n"
 342 "    cmp     r0, #0\n"
 343 "    bge     loc_fc05cb1a\n"
 344 "    ldr     r0, =0xfc05cbac\n" //  *"termDriverInit"
 345 "    bl      sub_fc05cb5e\n"
 346 "loc_fc05cb1a:\n"
 347 "    mov     r0, r4\n"
 348 "    bl      sub_fc05e2ca\n"
 349 "    cmp     r0, #0\n"
 350 "    bge     loc_fc05cb2a\n"
 351 "    ldr     r0, =0xfc05cbbc\n" //  *"termDeviceCreate"
 352 "    bl      sub_fc05cb5e\n"
 353 "loc_fc05cb2a:\n"
 354 "    mov     r0, r4\n"
 355 "    bl      sub_fc05cdcc\n"
 356 "    cmp     r0, #0\n"
 357 "    bge     loc_fc05cb3a\n"
 358 "    ldr     r0, =0xfc05cbd0\n" //  *"stdioSetup"
 359 "    bl      sub_fc05cb5e\n"
 360 "loc_fc05cb3a:\n"
 361 "    bl      sub_fc05cf10\n"
 362 "    cmp     r0, #0\n"
 363 "    bge     loc_fc05cb48\n"
 364 "    ldr     r0, =0xfc05cbdc\n" //  *"stdlibSetup"
 365 "    bl      sub_fc05cb5e\n"
 366 "loc_fc05cb48:\n"
 367 "    bl      sub_fc061684\n"
 368 "    cmp     r0, #0\n"
 369 "    bge     loc_fc05cb56\n"
 370 "    ldr     r0, =0xfc05cbe8\n" //  *"extlib_setup"
 371 "    bl      sub_fc05cb5e\n"
 372 "loc_fc05cb56:\n"
 373 "    pop.w   {r4, lr}\n"
 374 //"    b.w     loc_fc05cd70\n"
 375 "    b.w     sub_fc05cd70_my\n" // ->
 376     ".ltorg\n"
 377     );
 378 }
 379 
 380 //  -f=chdk -s=0xfc05cd71 -eret
 381 void __attribute__((naked,noinline)) sub_fc05cd70_my() {
 382     asm volatile (
 383 "    push    {r3, lr}\n"
 384 "    bl      sub_fc05d018\n"
 385 "    bl      sub_fc05cf34\n"
 386 "    bl      sub_fc0648f0\n" // IsNormalCameraMode_FW
 387 "    bl      sub_fc589910_my\n" // -> startup key checks, like sx710 fc0cf0ee
 388 "    cbnz    r0, loc_fc05cd8a\n"
 389 "    bl      sub_fc05d006\n"
 390 "loc_fc05cd88:\n"
 391 "    b       loc_fc05cd88\n"
 392 "loc_fc05cd8a:\n"
 393 "    bl      sub_fc369126\n"
 394 "    ldr     r1, =0x006ce000\n"
 395 "    movs    r0, #0\n"
 396 "    bl      sub_fc3519e8\n"
 397 "    movs    r3, #0\n"
 398 "    str     r3, [sp]\n"
 399 //"    ldr     r3, =0xfc05ccf5\n" //  task_Startup
 400 "    ldr     r3, =task_Startup_my\n" //  ->
 401 "    movs    r2, #0\n"
 402 "    movs    r1, #0x19\n"
 403 "    ldr     r0, =0xfc05cdc4\n" //  *"Startup"
 404 "    bl      _CreateTask\n"
 405 "    movs    r0, #0\n"
 406 "    pop     {r3, pc}\n"
 407     ".ltorg\n"
 408     );
 409 }
 410 
 411 // -f=chdk -s=0xfc589911 -eret
 412 void __attribute__((naked,noinline)) sub_fc589910_my() {
 413     asm volatile (
 414 "    push.w  {r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 415 "    movs    r4, #0\n"
 416 "    mov     fp, r0\n"
 417 "    mov     r5, r4\n"
 418 //"    bl      sub_fc505e80\n" // nullsub
 419 "    movs    r0, #0x97\n"
 420 "    bl      sub_fc506672\n" // MMIO 0xd20b025c (sub = return (*(0xd20b0000 + r0*4) << 15) < 0 )
 421 "    movs    r6, #1\n"
 422 "    bic.w   sb, r6, r0\n"
 423 "    movs    r0, #0x8a\n"
 424 "    bl      sub_fc506672\n" // MMIO 0xd20b0228
 425 "    bic.w   r8, r6, r0\n"
 426 "    movs    r0, #0\n"
 427 "    bl      sub_fc505e7c\n" // return 1
 428 "    cbz     r0, loc_fc589946\n"
 429 "    movs    r0, #0x98\n"
 430 "    bl      sub_fc506672\n" // MMIO 0xd20b0260
 431 "    bic.w   r4, r6, r0\n"
 432 "loc_fc589946:\n"
 433 "    movw    r0, #0x10e\n"
 434 "    bl      sub_fc506672\n" // MMIO 0xd20b0438
 435 "    bic.w   r7, r6, r0\n"
 436 "    movs    r0, #1\n"
 437 "    bl      sub_fc505e7c\n" // return 1
 438 "    cbz     r0, loc_fc589964\n"
 439 "    movs    r0, #2\n"
 440 "    bl      sub_fc506672\n" // MMIO 0xd20b0008
 441 "    bic.w   r5, r6, r0\n"
 442 "loc_fc589964:\n"
 443 "    movw    r0, #0x186\n"
 444 "    bl      sub_fc506672\n" // MMIO 0xd20b0618
 445 "    mov     sl, r6\n"
 446 "    bics    r6, r0\n"
 447 "    cmp.w   fp, #0\n"
 448 "    beq     loc_fc58999a\n" // this section not present in sx710, possibly related to USB wake / charge?
 449 "    cbz     r4, loc_fc58998a\n"
 450 "    movw    r0, #0x12c\n" 
 451 "    bl      _SleepTask\n" // Sleep(300)
 452 "    movs    r0, #0x98\n"
 453 "    bl      sub_fc506672\n" // MMIO 0xd20b0260 (again)
 454 "    bic.w   r4, sl, r0\n"
 455 "loc_fc58998a:\n"
 456 "    orr.w   r0, sb, r8\n"
 457 "    orr.w   r1, r4, r7\n"
 458 "    orrs    r0, r1\n"
 459 "    orrs    r0, r5\n"
 460 "    orrs    r0, r6\n"         // check all hardware related bits checked above
 461 //"    beq     loc_fc5899b0\n" // old behavior, skip to return if none set
 462 "    bne     loc_fc58999a\n"   // new behavior, go to final code if any set
 463     "mov  r8, #1\n"            // otherwise, act as if play was held (r8 guessed based on sx710)
 464 "loc_fc58999a:\n"
 465 "    strd    r5, r6, [sp]\n"
 466 "    mov     r3, r7\n"
 467 "    mov     r2, r4\n"
 468 "    mov     r1, r8\n"
 469 "    mov     r0, sb\n"
 470 "    bl      sub_fc505e84\n"
 471 //"    bl      sub_fc505e82\n" // nullsub
 472 "    movs    r0, #1\n"
 473 //"loc_fc5899b0:\n"
 474 "    pop.w   {r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, pc}\n"
 475     ".ltorg\n"
 476     );
 477 }
 478 
 479 // -f=chdk -s=task_Startup -c=34
 480 void __attribute__((naked,noinline)) task_Startup_my() {
 481     asm volatile (
 482 // task_Startup 0xfc05ccf5
 483 "    push    {r4, lr}\n"
 484 "    bl      sub_fc0dc368\n" // CreateTask ClockSave
 485 "    ldr     r0, =0x41121000\n"
 486 "    mov.w   r1, #0x20000\n"
 487 "    bl      sub_fc3a8790\n" // unknown, similar to sx710 fc38df1c
 488 "    cbz     r0, loc_fc05cd10\n"
 489 "    movs    r2, #0x95\n"
 490 "    movs    r0, #0\n"
 491 "    ldr     r1, =0xfc05cdb0\n" //  *"Startup.c"
 492 "    bl      _DebugAssert\n"
 493 "loc_fc05cd10:\n"
 494 "    bl      sub_fc05cfe0\n" // manipulates MMIOs, related to ClkEnabler_DUKE.c (like sx710 fc055f00)
 495 //"    bl      sub_fc0dc400\n" // nullsub
 496 "    bl      sub_fc081478\n" // ?
 497 // SD startup reset for UHS support https://chdk.setepontos.com/index.php?topic=13089.msg132583#msg132583
 498 "    bl      sub_010e19de\n" // similar to sx710 010e182c, called from func following func which creates SD1stinit task
 499 //"    bl      sub_fc0dc486\n" // StartDiskboot
 500 //"    bl      CreateTask_blinker\n"
 501 "    bl      sub_fc3a88be\n"
 502 "    bl      sub_fc074688\n"
 503 "    bl      sub_fc05d134\n"
 504 "    bl      sub_fc05d0c8\n" // "InitExDrivers.c", Omar init
 505 "    bl      sub_fc0814ae\n" // StartWDT (and a lot of other stuff)
 506 "    bl      sub_fc3a8818\n"
 507 "    bl      sub_fc07468e\n" // UiMemory.C Ctrl*
 508 //"    bl      sub_fc589826\n" // CreateTask PhySw
 509 "    bl      sub_fc589826_my\n" // CreateTask PhySw
 510 "    bl      CreateTask_spytask\n" 
 511 "    bl      init_required_fw_features\n" // added
 512 "    bl      sub_fc27ec44\n" // SsTask etc
 513 "    bl      sub_fc0746a4\n"
 514 "    bl      sub_fc093948\n"
 515 "    bl      sub_fc0dbeda\n" // Battery.c
 516 "    bl      sub_fc093a78\n" // task_Bye
 517 "    bl      sub_fc0dc288\n"
 518 "    bl      sub_fc0dbe96\n" // BatteryTask
 519 //"    bl      sub_fc05d138\n" // nullsub
 520 "    bl      sub_fc32d346\n"
 521 "    bl      sub_fc0dbe68\n"
 522 "    pop.w   {r4, lr}\n"
 523 //"    b.w     loc_fc0dc33e\n"
 524 "    ldr     pc,=0xfc0dc33f\n"
 525     ".ltorg\n"
 526     );
 527 }
 528 
 529 // -f=chdk -s=0xfc589827 -c=19
 530 void __attribute__((naked,noinline)) sub_fc589826_my() {
 531     asm volatile (
 532 "    push    {r2, r3, r4, lr}\n"
 533 "    bl      sub_fc0fd7ac\n"
 534 "    bl      sub_fc06486e\n" // IsFactoryMode_FW
 535 "    cbnz    r0, loc_fc589836\n"
 536 "    bl      sub_fc0fd750\n" // OpLog.Start_FW
 537 "loc_fc589836:\n"
 538 "    ldr     r4, =0x00008190\n" //  physw_run
 539 "    ldr     r0, [r4, #4]\n"
 540 "    cmp     r0, #0\n"
 541 "    bne     loc_fc589856\n"
 542 "    movs    r3, #1\n"
 543 "    movs    r2, #0\n"
 544 "    movs    r1, #0x13\n"
 545 "    strd    r2, r3, [sp]\n"
 546 //"    ldr     r3, =0xfc589801\n" //  task_PhySw
 547 "    ldr     r3, =mykbd_task\n"
 548 "    ldr     r0, =0xfc589bc4\n" //  *"PhySw"
 549 //"    movw    r2, #0x800\n"
 550 "    movw    r2, #0x2000\n" // adjusted 0x800 -> 0x2000
 551 "    bl      sub_fc34b9c2\n" // CreateTaskStrictly_alt
 552 "    str     r0, [r4, #4]\n"
 553 "loc_fc589856:\n"
 554 //"    b       loc_fc589554\n" // jumps over unrelated code to pop in stock firmware
 555 "    pop     {r2, r3, r4, pc}\n"
 556     ".ltorg\n"
 557     );
 558 }
 559 
 560 // -f=chdk -s=task_InitFileModules -eret
 561 void __attribute__((naked,noinline)) init_file_modules_task() {
 562     asm volatile (
 563 // task_InitFileModules 0xfc0972a5
 564 "    push    {r4, r5, r6, lr}\n"
 565 "    movs    r0, #6\n"
 566 //"    bl      sub_fc32ca18\n" //  return
 567 "    bl      sub_fc099270\n"
 568 "    movs    r4, r0\n"
 569 "    movw    r5, #0x5006\n"
 570 "    beq     loc_fc0972c0\n"
 571 "    movs    r1, #0\n"
 572 "    mov     r0, r5\n"
 573 "    bl      _PostLogicalEventToUI\n"
 574 "loc_fc0972c0:\n"
 575 "    bl      sub_fc09929a\n"
 576 "    BL      core_spytask_can_start\n" // + CHDK: Set "it's-safe-to-start" flag for spytask
 577 "    cmp     r4, #0\n"
 578 "    bne     loc_fc0972d4\n" //  return
 579 "    mov     r0, r5\n"
 580 "    pop.w   {r4, r5, r6, lr}\n"
 581 "    movs    r1, #1\n"
 582 "    b.w     _PostLogicalEventToUI\n"
 583 "loc_fc0972d4:\n"
 584 "    pop     {r4, r5, r6, pc}\n"
 585     ".ltorg\n"
 586     );
 587 }
 588 
 589 /*
 590     *** workaround ***
 591     Init stuff to avoid asserts on cameras running DryOS r54+
 592     https://chdk.setepontos.com/index.php?topic=12516.0
 593     Execute this only once
 594  */
 595 void init_required_fw_features(void) {
 596     extern void _init_focus_eventflag();
 597 
 598     _init_focus_eventflag();
 599     extern int av_override_semaphore;
 600     extern int _CreateBinarySemaphoreStrictly(int x, int y);
 601     av_override_semaphore = _CreateBinarySemaphoreStrictly(0,0);
 602 }
 603 
 604 void __attribute__((naked,noinline)) kbd_p1_f_cont_my ()
 605 {
 606 // -f=chdk -s=kbd_p1_f_cont -c=18 -jfw
 607     asm volatile(
 608 // kbd_p1_f_cont 0xfc589b4f
 609 "    ldr     r3, =0x0003578c\n" //  physw_status
 610 "    movs    r0, #2\n"
 611 "    mov     r5, sp\n"
 612 "    add.w   r6, r3, #0x24\n"
 613 "loc_fc589b58:\n"
 614 "    add.w   r1, r6, r0, lsl #2\n"
 615 "    ldr.w   r2, [r3, r0, lsl #2]\n"
 616 "    ldr     r7, [r1, #0xc]\n"
 617 "    ldr     r1, [r1, #0x18]\n"
 618 "    and.w   r2, r2, r7\n"
 619 "    eor.w   r2, r2, r1\n"
 620 "    str.w   r2, [r5, r0, lsl #2]\n"
 621 "    subs    r0, r0, #1\n"
 622 "    bpl     loc_fc589b58\n"
 623 "    ldr     r2, =0x0003578c\n" //  physw_status
 624 "    mov     r0, sp\n"
 625 "    adds    r2, #0x18\n"
 626 "    sub.w   r1, r2, #0xc\n"
 627 //"    bl      sub_fc589620\n"
 628 "    bl      sub_fc589620_my\n" // + 
 629 "    ldr     pc, =0xfc589b83\n" // Continue in firmware
 630     ".ltorg\n"
 631     );
 632 }
 633 
 634 extern int physw_override;
 635 // -f=chdk -s=0xfc589621 -c=4 -jfw
 636 void __attribute__((naked,noinline)) sub_fc589620_my()
 637 {
 638     asm volatile(
 639 "    push.w  {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 640 "    ldr     r4, =0x000357b0\n"
 641 "    mov     r5, r0\n"
 642 "    ldr     r0, =physw_override\n" // +
 643 "    ldr.w   r0, [r0]\n" // + use CHDK override value
 644 //"    mov.w   r0, #-1\n"
 645 "    ldr     pc, =0xfc58962d\n" // Continue in firmware
 646     );
 647 }
 648 
 649 // fix for FI2 boot, see https://chdk.setepontos.com/index.php?topic=11316.msg136622#msg136622
 650 // -f=chdk -s=task_TricInitTask -c=35
 651 void __attribute__((naked,noinline)) TricInitTask_my()
 652 {
 653     asm volatile(
 654 // task_TricInitTask 0xfc521929
 655 "    push.w  {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, lr}\n"
 656 "    movs    r0, #8\n"
 657 "    ldr     r1, =0xfc521b54\n" //  *"InitTskStart"
 658 "    bl      sub_fc350df2\n"
 659 "    ldr.w   sl, =0x0001c440\n"
 660 "    movw    fp, #0x1000\n"
 661 "    ldr     r4, =0x0001c43c\n"
 662 "    movs    r2, #0\n"
 663 "    ldr     r1, =0x0703870f\n"
 664 "    ldr     r0, [r4]\n"
 665 "    bl      sub_fc3699c0\n" // WaitForAnyEventFlag
 666 "    lsls    r0, r0, #0x1f\n"
 667 "    beq     loc_fc52195e\n"
 668 "    movs    r0, #8\n"
 669 "    ldr     r1, =0xfc521b6c\n" //  *"ER IniTskWait"
 670 "    bl      sub_fc350e52\n"
 671 "    ldr     r1, =0x0001c428\n"
 672 "    movs    r0, #0\n"
 673 "    str     r0, [r1]\n"
 674 "    pop.w   {r0, r1, r2, r3, r4, r5, r6, r7, r8, sb, sl, fp, ip, pc}\n"
 675 "loc_fc52195e:\n"
 676 "    ldr     r4, =0x0001c43c\n"
 677 "    add     r1, sp, #0xc\n"
 678 "    ldr     r0, [r4]\n"
 679 "    bl      sub_fc369c1a\n" // GetEventFlagValue
 680 "    ldr     r1, [sp, #0xc]\n"
 681 "    ldr     r0, [r4]\n"
 682 "    bl      sub_fc369bea\n" // ClearEventFlag
 683 "    ldr     r0, =0x02000003\n"
 684 "    ldr     r7, [sp, #0xc]\n"
 685 "    tst     r7, r0\n"
 686 "    beq     sub_fc521a62\n" // loc -> sub
 687 "    lsls    r0, r7, #0x1f\n"
 688 "    beq     sub_fc521982\n" // loc -> sub
 689 
 690 "    ldr     r0, =0xd2020074\n" // + MMIO ref'd from fc412414, via end of fc521e06
 691 "    ldr     r0, [r0]\n"        // + nonzero when core already running
 692 "    subs    r0, #0\n"          // +
 693 "    beq     tric1\n"           // +
 694 "    ldr     r0, [r4]\n"        // +
 695 "    mov     r1, #0x80\n"       // +
 696 "    bl      _SetEventFlag\n"   // + core already initialized, set the SmacIdleCmp eventflag here
 697 "tric1:\n"                      // +
 698 
 699 "    bl      sub_fc521e06\n"
 700 "    ldr     pc,=0xfc5219ef\n" // b to ldr pc
 701     ".ltorg\n"
 702     );
 703 }
 704 #ifdef CAM_HAS_JOGDIAL
 705 // -f=chdk -s=kbd_p2_f -eret
 706 void __attribute__((naked,noinline)) kbd_p2_f_my() {
 707     asm volatile(
 708 // kbd_p2_f 0xfc58955d
 709 "loc_fc58955c:\n"
 710 "    push.w  {r4, r5, r6, r7, r8, lr}\n"
 711 "    ldr     r6, =0x000357b0\n"
 712 "    sub     sp, #0x18\n"
 713 "    add     r7, sp, #8\n"
 714 "    subs    r6, #0xc\n"
 715 "    b       loc_fc58959e\n"
 716 "loc_fc58956a:\n"
 717 "    ldr     r1, =0x000357b0\n"
 718 "    add     r3, sp, #8\n"
 719 "    ldrb.w  r0, [sp, #4]\n"
 720 "    add     r2, sp, #0x14\n"
 721 "    subs    r1, #0x18\n"
 722 "    bl      sub_fc5064a4\n"
 723 "    cbnz    r0, loc_fc589584\n"
 724 "    ldr     r1, [sp, #0x14]\n"
 725 "    movs    r0, #0\n"
 726 "    bl      sub_fc5894ce\n"
 727 "loc_fc589584:\n"
 728 "    movs    r0, #2\n"
 729 "loc_fc589586:\n"
 730 "    ldr.w   r1, [r7, r0, lsl #2]\n"
 731 "    cbz     r1, loc_fc589596\n"
 732 "    ldr.w   r2, [r6, r0, lsl #2]\n"
 733 "    bics    r2, r1\n"
 734 "    str.w   r2, [r6, r0, lsl #2]\n"
 735 "loc_fc589596:\n"
 736 "    subs    r0, r0, #1\n"
 737 "    sxtb    r0, r0\n"
 738 "    cmp     r0, #0\n"
 739 "    bge     loc_fc589586\n"
 740 "loc_fc58959e:\n"
 741 "    ldr     r0, =0x000357b0\n"
 742 "    add     r1, sp, #4\n"
 743 "    subs    r0, #0xc\n"
 744 "    bl      sub_fc5061d2\n"
 745 "    cmp     r0, #0\n"
 746 "    bne     loc_fc58956a\n"
 747 "    ldr.w   r8, =0x000357b0\n"
 748 "    movs    r4, #0\n"
 749 "loc_fc5895b2:\n"
 750 "    movs    r5, #0\n"
 751 "    ldr.w   r0, [r6, r4, lsl #2]\n"
 752 "    ldr.w   r1, [r8, r4, lsl #2]\n"
 753 "    ands    r0, r1\n"
 754 "    str.w   r0, [r6, r4, lsl #2]\n"
 755 "    b       loc_fc58960a\n"
 756 "loc_fc5895c4:\n"
 757 "    lsrs    r0, r5\n"
 758 "    lsls    r0, r0, #0x1f\n"
 759 "    beq     loc_fc589602\n"
 760 "    ldr     r1, =0x000357b0\n"
 761 "    add.w   r0, r5, r4, lsl #5\n"
 762 "    add     r3, sp, #8\n"
 763 "    subs    r1, #0x18\n"
 764 "    add     r2, sp, #0x14\n"
 765 "    uxtb    r0, r0\n"
 766 "    bl      sub_fc5064a4\n"
 767 "    cbnz    r0, loc_fc5895e6\n"
 768 "    ldr     r1, [sp, #0x14]\n"
 769 "    movs    r0, #1\n"
 770 "    bl      sub_fc5894ce\n"
 771 "loc_fc5895e6:\n"
 772 "    mov     r0, r4\n"
 773 "    b       loc_fc5895fe\n"
 774 "loc_fc5895ea:\n"
 775 "    ldr.w   r1, [r7, r0, lsl #2]\n"
 776 "    cbz     r1, loc_fc5895fa\n"
 777 "    ldr.w   r2, [r6, r0, lsl #2]\n"
 778 "    bics    r2, r1\n"
 779 "    str.w   r2, [r6, r0, lsl #2]\n"
 780 "loc_fc5895fa:\n"
 781 "    adds    r0, r0, #1\n"
 782 "    sxtb    r0, r0\n"
 783 "loc_fc5895fe:\n"
 784 "    cmp     r0, #3\n"
 785 "    blt     loc_fc5895ea\n"
 786 "loc_fc589602:\n"
 787 "    ldr.w   r0, [r6, r4, lsl #2]\n"
 788 "    adds    r5, r5, #1\n"
 789 "    uxtb    r5, r5\n"
 790 "loc_fc58960a:\n"
 791 "    cmp     r0, #0\n"
 792 "    bne     loc_fc5895c4\n"
 793 "    adds    r4, r4, #1\n"
 794 "    sxtb    r4, r4\n"
 795 "    cmp     r4, #3\n"
 796 "    blt     loc_fc5895b2\n"
 797 //"    bl      sub_fc505f82\n"
 798 "    bl      sub_fc505f82_my\n"
 799 "    add     sp, #0x18\n"
 800 "    pop.w   {r4, r5, r6, r7, r8, pc}\n" 
 801 ".ltorg\n"
 802     );
 803 }
 804 // -f=chdk -s=0xfc505f83 -c=9
 805 void __attribute__((naked,noinline)) sub_fc505f82_my() {
 806     asm volatile(
 807 "    push    {r4, lr}\n"
 808 "    ldr     r4, =0x00009ad8\n"
 809 "    ldr     r0, [r4, #8]\n"
 810 "    bl      sub_fc50a904\n"
 811 "    bl      sub_fc3d45a0\n"
 812 "    ldr     r0, [r4, #0xc]\n"
 813 "    bl      sub_fc50a834\n"
 814 "    bl      handle_jogdial\n"  // +
 815 "    cmp     r0, #0\n"          // +
 816 "    beq     no_scroll\n"       // +
 817 "    bl      sub_fc50addc\n"    // handles scrollwheel(s), void function, no args
 818 //"    pop.w   {r4, lr}\n"
 819 "no_scroll:\n"                  // +
 820 "    pop   {r4, pc}\n"          // +
 821 //"    b.w     loc_fc50addc\n"
 822 ".ltorg\n"
 823     );
 824 }
 825 #endif

/* [<][>][^][v][top][bottom][index][help] */