root/platform/ixus240_elph320hs/sub/102a/boot.c

/* [<][>][^][v][top][bottom][index][help] */

DEFINITIONS

This source file includes following definitions.
  1. taskHook
  2. CreateTask_spytask
  3. boot
  4. sub_FF00038C_my
  5. sub_FF0011E4_my
  6. sub_FF0042DC_my
  7. sub_FF00D03C_my
  8. taskcreate_Startup_my
  9. task_Startup_my
  10. taskcreatePhySw_my
  11. init_file_modules_task
  12. task_TouchPanel_my
  13. sub_FF069F28_my
  14. sub_FF069E08_my
  15. process_TouchCoords_my

   1 /*
   2  * boot.c - auto-generated by CHDK code_gen.
   3  */
   4 #include "lolevel.h"
   5 #include "platform.h"
   6 #include "core.h"
   7 #include "dryos31.h"
   8 
   9 #define offsetof(TYPE, MEMBER) ((int) &((TYPE *)0)->MEMBER)
  10 
  11 const char * const new_sa = &_end;
  12 
  13 // Forward declarations
  14 void task_TouchPanel_my(void);
  15 
  16 extern void task_CaptSeq();
  17 extern void task_InitFileModules();
  18 extern void task_TouchPanel();
  19 extern void task_MovieRecord();
  20 extern void task_ExpDrv();
  21 extern void task_FileWrite();
  22 
  23 void taskHook(context_t **context)
  24 {
  25     task_t *tcb=(task_t*)((char*)context-offsetof(task_t, context));
  26 
  27     // Replace firmware task addresses with ours
  28     if(tcb->entry == (void*)task_CaptSeq)          tcb->entry = (void*)capt_seq_task;
  29     if(tcb->entry == (void*)task_InitFileModules)  tcb->entry = (void*)init_file_modules_task;
  30     if(tcb->entry == (void*)task_TouchPanel)       tcb->entry = (void*)task_TouchPanel_my;
  31     if(tcb->entry == (void*)task_MovieRecord)      tcb->entry = (void*)movie_record_task;
  32     if(tcb->entry == (void*)task_ExpDrv)           tcb->entry = (void*)exp_drv_task;
  33     if(tcb->entry == (void*)task_FileWrite)        tcb->entry = (void*)filewritetask;
  34 }
  35 
  36 /*----------------------------------------------------------------------
  37     CreateTask_spytask
  38 -----------------------------------------------------------------------*/
  39 void CreateTask_spytask() {
  40     _CreateTask("SpyTask", 0x19, 0x2000, core_spytask, 0);
  41 }
  42 
  43 /*----------------------------------------------------------------------
  44     boot()
  45 
  46     Main entry point for the CHDK code
  47 -----------------------------------------------------------------------*/
  48 
  49 /*************************************************************/
  50 //** boot @ 0xFF00000C - 0xFF000184, length=95
  51 void __attribute__((naked,noinline)) boot() {
  52 asm volatile (
  53 "    LDR     R1, =0xC0410000 \n"
  54 "    MOV     R0, #0 \n"
  55 "    STR     R0, [R1] \n"
  56 "    MOV     R1, #0x78 \n"
  57 "    MCR     p15, 0, R1, c1, c0 \n"
  58 "    MOV     R1, #0 \n"
  59 "    MCR     p15, 0, R1, c7, c10, 4 \n"
  60 "    MCR     p15, 0, R1, c7, c5 \n"
  61 "    MCR     p15, 0, R1, c7, c6 \n"
  62 "    MOV     R0, #0x3D \n"
  63 "    MCR     p15, 0, R0, c6, c0 \n"
  64 "    MOV     R0, #0xC000002F \n"
  65 "    MCR     p15, 0, R0, c6, c1 \n"
  66 "    MOV     R0, #0x37 \n"
  67 "    MCR     p15, 0, R0, c6, c2 \n"
  68 "    MOV     R0, #0x40000037 \n"
  69 "    MCR     p15, 0, R0, c6, c3 \n"
  70 "    MOV     R0, #0x80000017 \n"
  71 "    MCR     p15, 0, R0, c6, c4 \n"
  72 "    LDR     R0, =0xFF00002F \n"
  73 "    MCR     p15, 0, R0, c6, c5 \n"
  74 "    LDR     R0, =0xD000002B \n"
  75 "    MCR     p15, 0, R0, c6, c7 \n"
  76 "    MOV     R0, #0x34 \n"
  77 "    MCR     p15, 0, R0, c2, c0 \n"
  78 "    MOV     R0, #0x34 \n"
  79 "    MCR     p15, 0, R0, c2, c0, 1 \n"
  80 "    MOV     R0, #0x34 \n"
  81 "    MCR     p15, 0, R0, c3, c0 \n"
  82 "    LDR     R0, =0x33333330 \n"
  83 "    MCR     p15, 0, R0, c5, c0, 2 \n"
  84 "    LDR     R0, =0x33333330 \n"
  85 "    MCR     p15, 0, R0, c5, c0, 3 \n"
  86 "    MRC     p15, 0, R0, c1, c0 \n"
  87 "    ORR     R0, R0, #0x1000 \n"
  88 "    ORR     R0, R0, #4 \n"
  89 "    ORR     R0, R0, #1 \n"
  90 "    MCR     p15, 0, R0, c1, c0 \n"
  91 "    MOV     R1, #0x80000006 \n"
  92 "    MCR     p15, 0, R1, c9, c1 \n"
  93 "    MOV     R1, #6 \n"
  94 "    MCR     p15, 0, R1, c9, c1, 1 \n"
  95 "    MRC     p15, 0, R1, c1, c0 \n"
  96 "    ORR     R1, R1, #0x50000 \n"
  97 "    MCR     p15, 0, R1, c1, c0 \n"
  98 "    LDR     R2, =0xC0200000 \n"
  99 "    MOV     R1, #1 \n"
 100 "    STR     R1, [R2, #0x10C] \n"
 101 "    MOV     R1, #0xFF \n"
 102 "    STR     R1, [R2, #0xC] \n"
 103 "    STR     R1, [R2, #0x1C] \n"
 104 "    STR     R1, [R2, #0x2C] \n"
 105 "    STR     R1, [R2, #0x3C] \n"
 106 "    STR     R1, [R2, #0x4C] \n"
 107 "    STR     R1, [R2, #0x5C] \n"
 108 "    STR     R1, [R2, #0x6C] \n"
 109 "    STR     R1, [R2, #0x7C] \n"
 110 "    STR     R1, [R2, #0x8C] \n"
 111 "    STR     R1, [R2, #0x9C] \n"
 112 "    STR     R1, [R2, #0xAC] \n"
 113 "    STR     R1, [R2, #0xBC] \n"
 114 "    STR     R1, [R2, #0xCC] \n"
 115 "    STR     R1, [R2, #0xDC] \n"
 116 "    STR     R1, [R2, #0xEC] \n"
 117 "    STR     R1, [R2, #0xFC] \n"
 118 "    LDR     R1, =0xC0400008 \n"
 119 "    LDR     R2, =0x430005 \n"
 120 "    STR     R2, [R1] \n"
 121 "    MOV     R1, #1 \n"
 122 "    LDR     R2, =0xC0243100 \n"
 123 "    STR     R2, [R1] \n"
 124 "    LDR     R2, =0xC0242010 \n"
 125 "    LDR     R1, [R2] \n"
 126 "    ORR     R1, R1, #1 \n"
 127 "    STR     R1, [R2] \n"
 128 "    LDR     R0, =0xFF887998 \n"
 129 "    LDR     R1, =0x685000 \n"
 130 "    LDR     R3, =0x6B309C \n"
 131 
 132 "loc_FF000144:\n"
 133 "    CMP     R1, R3 \n"
 134 "    LDRCC   R2, [R0], #4 \n"
 135 "    STRCC   R2, [R1], #4 \n"
 136 "    BCC     loc_FF000144 \n"
 137 "    LDR     R0, =0xFF86FBDC \n"
 138 "    LDR     R1, =0x1900 \n"
 139 "    LDR     R3, =0x196BC \n"
 140 
 141 "loc_FF000160:\n"
 142 "    CMP     R1, R3 \n"
 143 "    LDRCC   R2, [R0], #4 \n"
 144 "    STRCC   R2, [R1], #4 \n"
 145 "    BCC     loc_FF000160 \n"
 146 "    LDR     R1, =0x281D28 \n"
 147 "    MOV     R2, #0 \n"
 148 
 149 "loc_FF000178:\n"
 150 "    CMP     R3, R1 \n"
 151 "    STRCC   R2, [R3], #4 \n"
 152 "    BCC     loc_FF000178 \n"
 153 "    B       sub_FF00038C_my \n"  // --> Patched. Old value = 0xFF00038C.
 154 );
 155 }
 156 
 157 /*************************************************************/
 158 //** sub_FF00038C_my @ 0xFF00038C - 0xFF0003F4, length=27
 159 void __attribute__((naked,noinline)) sub_FF00038C_my() {
 160 
 161     //http://chdk.setepontos.com/index.php/topic,4194.0.html
 162     *(int*)0x1938=(int)taskHook;
 163     *(int*)0x193C=(int)taskHook;
 164 
 165     // Replacement of sub_FF0257D4 (sub_FF065650) for correct power-on.
 166     // (short press = playback mode, long press = record mode)
 167     // look at power-on switch @ 0xFF00D08C
 168     *(int*)(0x28D4) = (*(int*)0xC022C30C)&1 ? 0x200000 : 0x100000;
 169 
 170 asm volatile (
 171 "    LDR     R0, =0xFF000404 \n"
 172 "    MOV     R1, #0 \n"
 173 "    LDR     R3, =0xFF00043C \n"
 174 
 175 "loc_FF000398:\n"
 176 "    CMP     R0, R3 \n"
 177 "    LDRCC   R2, [R0], #4 \n"
 178 "    STRCC   R2, [R1], #4 \n"
 179 "    BCC     loc_FF000398 \n"
 180 "    LDR     R0, =0xFF00043C \n"
 181 "    MOV     R1, #0x4B0 \n"
 182 "    LDR     R3, =0xFF000650 \n"
 183 
 184 "loc_FF0003B4:\n"
 185 "    CMP     R0, R3 \n"
 186 "    LDRCC   R2, [R0], #4 \n"
 187 "    STRCC   R2, [R1], #4 \n"
 188 "    BCC     loc_FF0003B4 \n"
 189 "    MOV     R0, #0xD2 \n"
 190 "    MSR     CPSR_cxsf, R0 \n"
 191 "    MOV     SP, #0x1000 \n"
 192 "    MOV     R0, #0xD3 \n"
 193 "    MSR     CPSR_cxsf, R0 \n"
 194 "    MOV     SP, #0x1000 \n"
 195 "    LDR     R0, =0x6C4 \n"
 196 "    LDR     R2, =0xEEEEEEEE \n"
 197 "    MOV     R3, #0x1000 \n"
 198 
 199 "loc_FF0003E8:\n"
 200 "    CMP     R0, R3 \n"
 201 "    STRCC   R2, [R0], #4 \n"
 202 "    BCC     loc_FF0003E8 \n"
 203 "    BL      sub_FF0011E4_my \n"  // --> Patched. Old value = 0xFF0011E4.
 204 );
 205 }
 206 
 207 /*************************************************************/
 208 //** sub_FF0011E4_my @ 0xFF0011E4 - 0xFF001284, length=41
 209 void __attribute__((naked,noinline)) sub_FF0011E4_my() {
 210 asm volatile (
 211 "    STR     LR, [SP, #-4]! \n"
 212 "    SUB     SP, SP, #0x74 \n"
 213 "    MOV     R1, #0x74 \n"
 214 "    MOV     R0, SP \n"
 215 "    BL      sub_006AB8C8 \n"
 216 "    MOV     R0, #0x83000 \n"
 217 "    STR     R0, [SP, #4] \n"
 218 
 219 #if defined(CHDK_NOT_IN_CANON_HEAP) // use original heap offset if CHDK is loaded in high memory
 220 "    LDR     R0, =0x281D28 \n"
 221 #else
 222 "    LDR     R0, =new_sa\n"   // otherwise use patched value
 223 "    LDR     R0, [R0]\n"      //
 224 #endif
 225 
 226 "    LDR     R2, =0x53F15C \n"
 227 "    STR     R0, [SP, #8] \n"
 228 "    SUB     R0, R2, R0 \n"
 229 "    STR     R0, [SP, #0xC] \n"
 230 "    MOV     R0, #0x22 \n"
 231 "    STR     R0, [SP, #0x18] \n"
 232 "    MOV     R0, #0x98 \n"
 233 "    STR     R0, [SP, #0x1C] \n"
 234 "    LDR     R0, =0x1E2 \n"
 235 "    LDR     R1, =0x549C00 \n"
 236 "    STR     R2, [SP, #0x10] \n"
 237 "    STR     R0, [SP, #0x20] \n"
 238 "    MOV     R0, #0xF6 \n"
 239 "    STR     R1, [SP] \n"
 240 "    STR     R1, [SP, #0x14] \n"
 241 "    STR     R0, [SP, #0x24] \n"
 242 "    MOV     R0, #0xB6 \n"
 243 "    STR     R0, [SP, #0x28] \n"
 244 "    MOV     R0, #0x85 \n"
 245 "    STR     R0, [SP, #0x2C] \n"
 246 "    MOV     R0, #0x40 \n"
 247 "    STR     R0, [SP, #0x30] \n"
 248 "    MOV     R0, #4 \n"
 249 "    STR     R0, [SP, #0x34] \n"
 250 "    MOV     R0, #0x10 \n"
 251 "    STR     R0, [SP, #0x5C] \n"
 252 "    MOV     R0, #0x800 \n"
 253 "    STR     R0, [SP, #0x60] \n"
 254 "    MOV     R0, #0xA0 \n"
 255 "    STR     R0, [SP, #0x64] \n"
 256 "    MOV     R0, #0x280 \n"
 257 "    STR     R0, [SP, #0x68] \n"
 258 "    LDR     R1, =sub_FF0042DC_my \n"  // --> Patched. Old value = 0xFF0042DC.
 259 "    LDR     PC, =0xFF001288 \n"  // Continue in firmware
 260 );
 261 }
 262 
 263 /*************************************************************/
 264 //** sub_FF0042DC_my @ 0xFF0042DC - 0xFF004380, length=42
 265 void __attribute__((naked,noinline)) sub_FF0042DC_my() {
 266 asm volatile (
 267 "    STMFD   SP!, {R4,LR} \n"
 268 "    BL      sub_FF000B5C \n"
 269 "    BL      sub_FF0054B0 \n"
 270 "    CMP     R0, #0 \n"
 271 "    LDRLT   R0, =0xFF00444C /*'dmSetup'*/ \n"
 272 "    BLLT    _err_init_task \n"
 273 "    BL      sub_FF003F14 \n"
 274 "    CMP     R0, #0 \n"
 275 "    LDRLT   R0, =0xFF004454 /*'termDriverInit'*/ \n"
 276 "    BLLT    _err_init_task \n"
 277 "    LDR     R0, =0xFF004464 /*'/_term'*/ \n"
 278 "    BL      sub_FF003FFC \n"
 279 "    CMP     R0, #0 \n"
 280 "    LDRLT   R0, =0xFF00446C /*'termDeviceCreate'*/ \n"
 281 "    BLLT    _err_init_task \n"
 282 "    LDR     R0, =0xFF004464 /*'/_term'*/ \n"
 283 "    BL      sub_FF002A1C \n"
 284 "    CMP     R0, #0 \n"
 285 "    LDRLT   R0, =0xFF004480 /*'stdioSetup'*/ \n"
 286 "    BLLT    _err_init_task \n"
 287 "    BL      sub_FF004E4C \n"
 288 "    CMP     R0, #0 \n"
 289 "    LDRLT   R0, =0xFF00448C /*'stdlibSetup'*/ \n"
 290 "    BLLT    _err_init_task \n"
 291 "    BL      sub_FF0079F0 \n"
 292 "    CMP     R0, #0 \n"
 293 "    LDRLT   R0, =0xFF004498 /*'posixSetup'*/ \n"
 294 "    BLLT    _err_init_task \n"
 295 "    BL      sub_FF007AB0 \n"
 296 "    CMP     R0, #0 \n"
 297 "    LDRLT   R0, =0xFF0044A4 /*'pthreadSetup'*/ \n"
 298 "    BLLT    _err_init_task \n"
 299 "    BL      sub_FF006920 \n"
 300 "    CMP     R0, #0 \n"
 301 "    LDRLT   R0, =0xFF0044B4 /*'dhcpc_setup'*/ \n"
 302 "    BLLT    _err_init_task \n"
 303 "    BL      sub_FF0016DC \n"
 304 "    CMP     R0, #0 \n"
 305 "    LDRLT   R0, =0xFF0044C0 /*'armlib_setup'*/ \n"
 306 "    BLLT    _err_init_task \n"
 307 "    LDMFD   SP!, {R4,LR} \n"
 308 "    B       sub_FF00D03C_my \n"  // --> Patched. Old value = 0xFF00D03C.
 309 );
 310 }
 311 
 312 /*************************************************************/
 313 //** sub_FF00D03C_my @ 0xFF00D03C - 0xFF00D04C, length=5
 314 void __attribute__((naked,noinline)) sub_FF00D03C_my() {
 315 asm volatile (
 316 "    STMFD   SP!, {R4,LR} \n"
 317 //"  BL      _sub_FF065648 \n"  // --> Nullsub call removed.
 318 "    BL      taskcreate_Startup_my \n"  // --> Patched. Old value = 0xFF00D050.
 319 "    MOV     R0, #0 \n"
 320 "    LDMFD   SP!, {R4,PC} \n"
 321 );
 322 }
 323 
 324 /*************************************************************/
 325 //** taskcreate_Startup_my @ 0xFF00D050 - 0xFF00D120, length=53
 326 void __attribute__((naked,noinline)) taskcreate_Startup_my() {
 327 asm volatile (
 328 "    STMFD   SP!, {R3-R7,LR} \n"
 329 "    BL      sub_FF03CBF0 \n"
 330 "    MOVS    R6, R0 \n"
 331 "    BNE     loc_FF00D0B4 \n"
 332 "    BL      sub_FF0272C0 /*_IsNormalCameraMode_FW*/ \n"
 333 "    CMP     R0, #0 \n"
 334 "    BEQ     loc_FF00D0B4 \n"
 335 "    MOV     R0, #0x38 \n"
 336 "    BL      sub_FF03B1B8 \n"
 337 "    RSBS    R5, R0, #1 \n"
 338 "    MOVCC   R5, #0 \n"
 339 "    MOV     R0, #0x37 \n"
 340 "    BL      sub_FF03B1B8 \n"
 341 "    RSBS    R4, R0, #1 \n"
 342 "    MOVCC   R4, #0 \n"
 343 "    ORRS    R0, R4, R5 \n"
 344 "    BNE     loc_FF00D0D4 \n"
 345 "    BL      sub_FF024BCC \n"
 346 "    BL      sub_0068A7F8 /*_GetSRAndDisableInterrupt*/ \n"
 347 "    LDR     R2, =0xC022C000 \n"
 348 "    LDR     R1, [R2, #0x30C] \n"
 349 "    BIC     R1, R1, #0x300 \n"
 350 "    STR     R1, [R2, #0x30C] \n"
 351 "    BL      sub_0068A7FC /*_SetSR*/ \n"
 352 
 353 "loc_FF00D0B0:\n"
 354 "    B       loc_FF00D0B0 \n"
 355 
 356 "loc_FF00D0B4:\n"
 357 "    MOV     R0, #0x37 \n"
 358 "    BL      sub_FF03B1B8 \n"
 359 "    RSBS    R4, R0, #1 \n"
 360 "    MOVCC   R4, #0 \n"
 361 "    MOV     R0, #0x38 \n"
 362 "    BL      sub_FF03B1B8 \n"
 363 "    RSBS    R5, R0, #1 \n"
 364 "    MOVCC   R5, #0 \n"
 365 
 366 "loc_FF00D0D4:\n"
 367 "    MOV     R3, #0 \n"
 368 "    MOV     R2, R6 \n"
 369 "    MOV     R1, R5 \n"
 370 "    MOV     R0, R4 \n"
 371 //"  BL      _sub_FF065650 \n"  // See begin of sub_FF00038C_my
 372 //"  BL      _sub_FF06564C \n"  // --> Nullsub call removed.
 373 "    BL      sub_0068F4A0 \n"
 374 "    LDR     R1, =0x5CE000 \n"
 375 "    MOV     R0, #0 \n"
 376 "    BL      sub_FF03AFA4 \n"
 377 "    BL      sub_0068F6B8 \n"
 378 "    MOV     R3, #0 \n"
 379 "    STR     R3, [SP] \n"
 380 "    LDR     R3, =task_Startup_my \n"  // --> Patched. Old value = 0xFF00CFD4.
 381 "    MOV     R2, #0 \n"
 382 "    MOV     R1, #0x19 \n"
 383 "    LDR     R0, =0xFF00D130 /*'Startup'*/ \n"
 384 "    BL      _CreateTask \n"
 385 "    MOV     R0, #0 \n"
 386 "    LDMFD   SP!, {R3-R7,PC} \n"
 387 );
 388 }
 389 
 390 /*************************************************************/
 391 //** task_Startup_my @ 0xFF00CFD4 - 0xFF00D02C, length=23
 392 void __attribute__((naked,noinline)) task_Startup_my() {
 393 asm volatile (
 394 "    STMFD   SP!, {R4,LR} \n"
 395 "    BL      sub_FF0049CC \n"
 396 "    BL      sub_FF02698C \n"
 397 "    BL      sub_FF024A40 \n"
 398 //"  BL      _sub_FF065E60 \n"  // --> Nullsub call removed.
 399 "    BL      sub_FF03CE24 \n"
 400 //"  BL      _sub_FF03CCCC \n"  // start diskboot.bin
 401 "    BL      sub_FF03CF9C \n"
 402 "    BL      sub_FF03D168 \n"
 403 //"  BL      _sub_FF03CF90 \n"  // --> Nullsub call removed.
 404 "    BL      sub_FF03CE54 \n"
 405 "    BL      sub_FF03AED8 \n"
 406 "    BL      sub_FF03D170 \n"
 407 
 408 "    BL      CreateTask_spytask\n"  // added
 409 
 410 "    BL      taskcreatePhySw_my \n"  // --> Patched. Old value = 0xFF025678.
 411 "    LDR     PC, =0xFF00D00C \n"  // Continue in firmware
 412 );
 413 }
 414 
 415 /*************************************************************/
 416 //** taskcreatePhySw_my @ 0xFF025678 - 0xFF025698, length=9
 417 void __attribute__((naked,noinline)) taskcreatePhySw_my() {
 418 asm volatile (
 419 "    STMFD   SP!, {R3-R5,LR} \n"
 420 "    LDR     R4, =0x1D34 \n"
 421 "    LDR     R0, [R4, #4] \n"
 422 "    CMP     R0, #0 \n"
 423 "    BNE     sub_FF0256AC \n"
 424 "    MOV     R3, #0 \n"
 425 "    STR     R3, [SP] \n"
 426 "    LDR     R3, =mykbd_task \n"  // --> Patched. Old value = 0xFF025644.
 427 "    MOV     R2, #0x2000 \n"  // --> Patched. Old value = 0x800. stack size for new task_PhySw
 428 "    LDR     PC, =0xFF02569C \n"  // Continue in firmware
 429 );
 430 }
 431 
 432 /*************************************************************/
 433 //** init_file_modules_task @ 0xFF0BF930 - 0xFF0BF94C, length=8
 434 void __attribute__((naked,noinline)) init_file_modules_task() {
 435 asm volatile (
 436 "    STMFD   SP!, {R4-R6,LR} \n"
 437 "    BL      sub_FF0B6F74 \n"
 438 "    LDR     R5, =0x5006 \n"
 439 "    MOVS    R4, R0 \n"
 440 "    MOVNE   R1, #0 \n"
 441 "    MOVNE   R0, R5 \n"
 442 "    BLNE    _PostLogicalEventToUI \n"
 443 "    BL      sub_FF0B6FA0 \n"
 444 "    BL      core_spytask_can_start\n"  // CHDK: Set "it's-safe-to-start" flag for spytask
 445 "    LDR     PC, =0xFF0BF950 \n"  // Continue in firmware
 446 );
 447 }
 448 
 449 /*************************************************************/
 450 //** task_TouchPanel_my @ 0xFF069FF8 - 0xFF06A178, length=97
 451 void __attribute__((naked,noinline)) task_TouchPanel_my() {
 452 asm volatile (
 453 "    STMFD   SP!, {R3-R7,LR} \n"
 454 "    MOV     R0, #0 \n"
 455 "    LDR     R1, =0xC0221000 \n"
 456 "    MOV     R4, R0 \n"
 457 "    STR     R0, [SP] \n"
 458 "    MOV     R0, #4 \n"
 459 "    STR     R0, [R1, #0x314] \n"
 460 "    MOV     R0, #0x1C \n"
 461 "    SUB     R1, R1, #0x1E000 \n"
 462 "    STR     R0, [R1, #0x40] \n"
 463 "    MOV     R3, #0 \n"
 464 "    LDR     R2, =0xFF069CF8 \n"
 465 "    MOV     R1, #0x55 \n"
 466 "    MOV     R0, R3 \n"
 467 "    BL      sub_0068A7BC /*_RegisterInterruptHandler*/ \n"
 468 "    BL      sub_FF06A440 \n"
 469 "    LDR     R5, =0x2B60 \n"
 470 "    MOV     R1, #0x10 \n"
 471 "    LDR     R0, [R5, #0x30] \n"
 472 "    BL      sub_0068ED10 /*_ClearEventFlag*/ \n"
 473 "    MOV     R6, #7 \n"
 474 
 475 "loc_FF06A04C:\n"
 476 "    LDR     R0, [R5, #0x30] \n"
 477 "    MOV     R2, #0 \n"
 478 "    MOV     R1, #0x17 \n"
 479 "    BL      sub_0068EB38 /*_WaitForAnyEventFlag*/ \n"
 480 "    CMP     R0, #0 \n"
 481 "    LDRNE   R1, =0x2B3 \n"
 482 "    LDRNE   R0, =0xFF069CD0 /*'TouchPanelDriver_AD7879.c'*/ \n"
 483 "    BLNE    _DebugAssert \n"
 484 "    LDR     R0, [R5, #0x30] \n"
 485 "    MOV     R1, SP \n"
 486 "    BL      sub_0068ED48 /*_GetEventFlagValue*/ \n"
 487 "    CMP     R0, #0 \n"
 488 "    MOVNE   R1, #0x2B4 \n"
 489 "    LDRNE   R0, =0xFF069CD0 /*'TouchPanelDriver_AD7879.c'*/ \n"
 490 "    BLNE    _DebugAssert \n"
 491 "    LDR     R0, [SP] \n"
 492 "    TST     R0, #1 \n"
 493 "    BEQ     loc_FF06A0CC \n"
 494 "    LDR     R0, [R5, #0x10] \n"
 495 "    CMP     R0, #7 \n"
 496 "    BEQ     loc_FF06A0A8 \n"
 497 "    BL      _CancelHPTimer \n"
 498 "    STR     R6, [R5, #0x10] \n"
 499 
 500 "loc_FF06A0A8:\n"
 501 "    LDR     R0, [R5, #0x30] \n"
 502 "    MOV     R1, #5 \n"
 503 "    BL      sub_0068ED10 /*_ClearEventFlag*/ \n"
 504 "    BL      sub_FF069D08 \n"
 505 "    MOV     R4, #0 \n"
 506 "    BL      sub_FF06A440 \n"
 507 "    LDR     R0, [R5, #0x30] \n"
 508 "    MOV     R1, #0x80000000 \n"
 509 "    BL      sub_0068ECDC /*_SetEventFlag*/ \n"
 510 
 511 "loc_FF06A0CC:\n"
 512 "    LDR     R0, [SP] \n"
 513 "    TST     R0, #2 \n"
 514 "    BEQ     loc_FF06A0FC \n"
 515 "    LDR     R0, [R5, #0x30] \n"
 516 "    MOV     R1, #2 \n"
 517 "    BL      sub_0068ED10 /*_ClearEventFlag*/ \n"
 518 "    CMP     R4, #0 \n"
 519 "    BNE     loc_FF06A04C \n"
 520 "    LDR     R0, =0xBB8 \n"
 521 "    BL      sub_FF069A64 \n"
 522 "    MOV     R4, #1 \n"
 523 "    BL      sub_FF06A42C \n"
 524 
 525 "loc_FF06A0FC:\n"
 526 "    LDR     R0, [SP] \n"
 527 "    TST     R0, #0x10 \n"
 528 "    BEQ     loc_FF06A144 \n"
 529 "    LDR     R0, [R5, #0x10] \n"
 530 "    CMP     R0, #7 \n"
 531 "    BEQ     loc_FF06A11C \n"
 532 "    BL      _CancelHPTimer \n"
 533 "    STR     R6, [R5, #0x10] \n"
 534 
 535 "loc_FF06A11C:\n"
 536 "    BL      sub_FF06A440 \n"
 537 "    LDR     R0, [R5, #0x30] \n"
 538 "    MOV     R1, #0x14 \n"
 539 "    BL      sub_0068ED10 /*_ClearEventFlag*/ \n"
 540 "    CMP     R4, #0 \n"
 541 "    BEQ     loc_FF06A04C \n"
 542 "    BL      sub_FF069F28_my \n"  // --> Patched. Old value = 0xFF069F28.
 543 "    LDR     R0, [R5, #0x18] \n"
 544 "    CMP     R0, #0 \n"
 545 "    BLNE    sub_FF06A408 \n"
 546 
 547 "loc_FF06A144:\n"
 548 "    LDR     R0, [SP] \n"
 549 "    TST     R0, #4 \n"
 550 "    BEQ     loc_FF06A04C \n"
 551 "    STR     R6, [R5, #0x10] \n"
 552 "    LDR     R0, [R5, #0x30] \n"
 553 "    MOV     R1, #4 \n"
 554 "    BL      sub_0068ED10 /*_ClearEventFlag*/ \n"
 555 "    CMP     R4, #0 \n"
 556 "    BEQ     loc_FF06A04C \n"
 557 "    BL      sub_FF069F28_my \n"  // --> Patched. Old value = 0xFF069F28.
 558 "    LDR     R0, [R5, #0x18] \n"
 559 "    CMP     R0, #0 \n"
 560 "    BLNE    sub_FF06A408 \n"
 561 "    B       loc_FF06A04C \n"
 562 );
 563 }
 564 
 565 /*************************************************************/
 566 //** sub_FF069F28_my @ 0xFF069F28 - 0xFF069FD4, length=44
 567 void __attribute__((naked,noinline)) sub_FF069F28_my() {
 568 asm volatile (
 569 "    STMFD   SP!, {R4-R6,LR} \n"
 570 "    LDR     R4, =0x2B60 \n"
 571 "    LDR     R0, [R4, #0x18] \n"
 572 "    CMP     R0, #0 \n"
 573 "    BEQ     loc_FF069F60 \n"
 574 "    CMP     R0, #1 \n"
 575 "    BEQ     loc_FF069F80 \n"
 576 "    CMP     R0, #2 \n"
 577 "    LDMEQFD SP!, {R4-R6,LR} \n"
 578 "    BEQ     sub_FF069E08_my \n"  // --> Patched. Old value = 0xFF069E08.
 579 "    LDMNEFD SP!, {R4-R6,LR} \n"
 580 "    LDRNE   R1, =0x29E \n"
 581 "    LDRNE   R0, =0xFF069CD0 /*'TouchPanelDriver_AD7879.c'*/ \n"
 582 "    BNE     _DebugAssert \n"
 583 
 584 "loc_FF069F60:\n"
 585 "    MOV     R0, #4 \n"
 586 "    BL      sub_FF03B1B8 \n"
 587 "    CMP     R0, #0 \n"
 588 "    LDMNEFD SP!, {R4-R6,LR} \n"
 589 "    BNE     sub_FF06A42C \n"
 590 "    MOV     R0, #1 \n"
 591 "    STR     R0, [R4, #0x18] \n"
 592 "    LDMFD   SP!, {R4-R6,PC} \n"
 593 
 594 "loc_FF069F80:\n"
 595 "    MOV     R0, #4 \n"
 596 "    BL      sub_FF03B1B8 \n"
 597 "    CMP     R0, #0 \n"
 598 "    LDMNEFD SP!, {R4-R6,LR} \n"
 599 "    BNE     sub_FF069D08 \n"
 600 "    LDR     R1, =0x2B9C \n"
 601 "    MOV     R2, #2 \n"
 602 "    MOV     R0, #8 \n"
 603 "    BL      sub_FF069B0C \n"
 604 "    LDR     R5, =0x2B9C \n"
 605 "    MOV     R2, #2 \n"
 606 "    ADD     R1, R5, #4 \n"
 607 "    MOV     R0, #0xA \n"
 608 "    BL      sub_FF069B0C \n"
 609 "    BL      process_TouchCoords_my \n"  // --> Patched. Old value = 0xFF069D58.
 610 "    MOV     R0, #3 \n"
 611 "    STR     R0, [R4, #0x1C] \n"
 612 "    MOV     R0, #2 \n"
 613 "    STR     R0, [R4, #0x18] \n"
 614 "    MVN     R0, #0x8000 \n"
 615 "    STRH    R0, [R5] \n"
 616 "    LDMFD   SP!, {R4-R6,PC} \n"
 617 );
 618 }
 619 
 620 /*************************************************************/
 621 //** sub_FF069E08_my @ 0xFF069E08 - 0xFF069F24, length=72
 622 void __attribute__((naked,noinline)) sub_FF069E08_my() {
 623 asm volatile (
 624 "    STMFD   SP!, {R3-R7,LR} \n"
 625 "    MOV     R0, #4 \n"
 626 "    BL      sub_FF03B1B8 \n"
 627 "    LDR     R6, =0x2B60 \n"
 628 "    CMP     R0, #0 \n"
 629 "    LDR     R7, =0x1388 \n"
 630 "    LDR     R0, [R6, #0x1C] \n"
 631 "    BEQ     loc_FF069E3C \n"
 632 "    SUBS    R0, R0, #1 \n"
 633 "    STR     R0, [R6, #0x1C] \n"
 634 "    LDMEQFD SP!, {R3-R7,LR} \n"
 635 "    BEQ     sub_FF069D08 \n"
 636 "    B       loc_FF069E64 \n"
 637 
 638 "loc_FF069E3C:\n"
 639 "    SUB     R1, R0, #1 \n"
 640 "    LDR     R4, =0x2B9C \n"
 641 "    LDR     R5, =0x7FFF \n"
 642 "    MOV     R0, #3 \n"
 643 "    CMP     R1, #2 \n"
 644 "    STR     R0, [R6, #0x1C] \n"
 645 "    BCS     loc_FF069E70 \n"
 646 "    LDRH    R0, [R4] \n"
 647 "    CMP     R0, R5 \n"
 648 "    BNE     loc_FF069F1C \n"
 649 
 650 "loc_FF069E64:\n"
 651 "    MOV     R0, R7 \n"
 652 "    LDMFD   SP!, {R3-R7,LR} \n"
 653 "    B       sub_FF069A64 \n"
 654 
 655 "loc_FF069E70:\n"
 656 "    LDR     R1, =0x2B9C \n"
 657 "    MOV     R2, #2 \n"
 658 "    MOV     R0, #8 \n"
 659 "    BL      sub_FF069B0C \n"
 660 "    MOV     R2, #2 \n"
 661 "    ADD     R1, R4, #4 \n"
 662 "    MOV     R0, #0xA \n"
 663 "    BL      sub_FF069B0C \n"
 664 "    MOV     R0, R7 \n"
 665 "    BL      sub_FF069A64 \n"
 666 "    MOV     R0, #4 \n"
 667 "    BL      sub_FF03B1B8 \n"
 668 "    CMP     R0, #0 \n"
 669 "    BEQ     loc_FF069F1C \n"
 670 "    LDRH    R1, [R4] \n"
 671 "    LDRSH   R3, [R6, #6] \n"
 672 "    LDRH    R2, [R4, #2] \n"
 673 "    SUB     R0, R3, R1 \n"
 674 "    MUL     R7, R0, R0 \n"
 675 "    LDRSH   R0, [R6, #8] \n"
 676 "    CMP     R3, R5 \n"
 677 "    SUB     R12, R0, R2 \n"
 678 "    MUL     R0, R12, R12 \n"
 679 "    BEQ     loc_FF069EEC \n"
 680 "    SUB     R3, R7, #0x19000 \n"
 681 "    CMP     R3, #0xE7000 \n"
 682 "    BHI     loc_FF069EEC \n"
 683 "    CMP     R0, #0x19000 \n"
 684 "    BCC     loc_FF069EEC \n"
 685 "    CMP     R0, #0x100000 \n"
 686 "    BLS     loc_FF069F1C \n"
 687 
 688 "loc_FF069EEC:\n"
 689 "    LDR     R0, =0x3FF \n"
 690 "    MOV     R3, #0 \n"
 691 "    STR     R3, [SP] \n"
 692 "    LDR     R12, [R6, #0x24] \n"
 693 "    EOR     R2, R0, R2, LSR#2 \n"
 694 "    EOR     R1, R0, R1, LSR#2 \n"
 695 "    MOV     R0, R3 \n"
 696 "    BLX     R12 \n"
 697 "    LDR     R0, [R6, #0x1C] \n"
 698 "    SUB     R0, R0, #1 \n"
 699 "    STR     R0, [R6, #0x1C] \n"
 700 "    LDMFD   SP!, {R3-R7,PC} \n"
 701 
 702 "loc_FF069F1C:\n"
 703 "    BL      process_TouchCoords_my \n"  // --> Patched. Old value = 0xFF069D58.
 704 "    STRH    R5, [R4] \n"
 705 "    LDMFD   SP!, {R3-R7,PC} \n"
 706 );
 707 }
 708 
 709 /*************************************************************/
 710 //** process_TouchCoords_my @ 0xFF069D58 - 0xFF069D58, length=1
 711 void __attribute__((naked,noinline)) process_TouchCoords_my() {
 712 asm volatile (
 713 "    STMFD   SP!, {R4,R5,LR} \n"
 714 "    BL      chdk_process_touch \n"
 715 "    LDMFD   SP!, {R4,R5,LR} \n"
 716 "    CMP     R0, #0 \n"
 717 "    BXNE    LR \n"
 718 "    LDR     PC, =0xFF069D58 \n"  // Continue in firmware
 719 );
 720 }

/* [<][>][^][v][top][bottom][index][help] */