This source file includes following definitions.
- spytask
- CreateTask_spytask
- init_required_fw_features
- boot
- CreateTask_my
- sub_fc05eec0_my
- sub_fc05f050_my
- sub_fc05f0e4_my
- sub_fc05f456_my
- task_Startup_my
- sub_fc07308e_my
- init_file_modules_task
- kbd_p2_f_my
- sub_fc0706e8_my
1 #include "lolevel.h"
2 #include "platform.h"
3 #include "core.h"
4
5
6 #define offsetof(TYPE, MEMBER) ((int) &((TYPE *)0)->MEMBER)
7
8 const char * const new_sa = &_end;
9
10
11 extern volatile int jogdial_stopped;
12 void JogDial_task_my(void);
13
14 extern void task_CaptSeq();
15 extern void task_InitFileModules();
16 extern void task_RotaryEncoder();
17 extern void task_MovieRecord();
18 extern void task_ExpDrv();
19
20
21
22
23 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
24 {
25 (void)ua; (void)ub; (void)uc; (void)ud; (void)ue; (void)uf;
26 core_spytask();
27 }
28
29
30
31
32 void CreateTask_spytask()
33 {
34
35
36 _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
37 }
38
39
40
41
42
43
44
45 void init_required_fw_features(void) {
46 extern void _init_focus_eventflag();
47 extern void _init_nd_eventflag();
48
49
50
51 _init_focus_eventflag();
52 _init_nd_eventflag();
53
54 extern int av_override_semaphore;
55 extern int _CreateBinarySemaphoreStrictly(int x, int y);
56 av_override_semaphore = _CreateBinarySemaphoreStrictly(0,0);
57
58 }
59
60
61
62
63
64
65
66
67
68
69
70
71 void __attribute__((naked,noinline)) boot() {
72
73 asm volatile (
74 " ldr.w sp, =0x80010000\n"
75 " bl sub_fc020064\n"
76 " ldr r2, =0xc0242010\n"
77 " ldr r1, [r2]\n"
78 " orr r1, r1, #1\n"
79 " str r1, [r2]\n"
80 " ldr r0, =0xfcd16b64\n"
81 " ldr r1, =0x010e1000\n"
82 " ldr r3, =0x0110daa4\n"
83 "loc_fc020024:\n"
84 " cmp r1, r3\n"
85 " itt lo\n"
86 " ldrlo r2, [r0], #4\n"
87 " strlo r2, [r1], #4\n"
88 " blo loc_fc020024\n"
89
90
91 "adr r0, patch_CreateTask\n"
92 "ldr r1, =hook_CreateTask\n"
93 "add r2, r0, #8\n"
94 "task_hook_loop:\n"
95 "ldrh r3, [r0],#2\n"
96 "strh r3, [r1],#2\n"
97 "cmp r0,r2\n"
98 "blo task_hook_loop\n"
99 " ldr r0, =0x010e1000\n"
100 " ldr r1, =0x0002caa4\n"
101 " bl sub_fc1361ce\n"
102 " ldr r0, =0xfccec558\n"
103 " ldr r1, =0x00008000\n"
104 " ldr r3, =0x0003260c\n"
105 "loc_fc020040:\n"
106 " cmp r1, r3\n"
107 " itt lo\n"
108 " ldrlo r2, [r0], #4\n"
109 " strlo r2, [r1], #4\n"
110 " blo loc_fc020040\n"
111 " ldr r3, =0x0003260c\n"
112 " ldr r1, =0x003a8bb0\n"
113 " mov.w r2, #0\n"
114 "loc_fc020056:\n"
115 " cmp r3, r1\n"
116 " it lo\n"
117 " strlo r2, [r3], #4\n"
118 " blo loc_fc020056\n"
119
120 " b.w sub_fc05eec0_my\n"
121
122 "patch_CreateTask:\n"
123 "ldr.w pc, [pc,#0]\n"
124 ".long CreateTask_my + 1\n"
125
126
127 );
128 }
129
130
131 void __attribute__((naked,noinline)) CreateTask_my() {
132
133 asm volatile (
134 " push {r0}\n"
135
136 " ldr r0, =task_CaptSeq\n"
137 " cmp r0, r3\n"
138 " itt eq\n"
139 " ldreq r3, =capt_seq_task\n"
140 " orreq r3, #1\n"
141 " beq exitHook\n"
142
143 " LDR R0, =task_ExpDrv\n"
144 " CMP R0, R3\n"
145 " itt eq\n"
146 " LDREQ R3, =exp_drv_task\n"
147 " orreq r3, #1\n"
148 " BEQ exitHook\n"
149
150
151
152
153
154
155
156
157
158 " ldr r0, =task_FileWrite\n"
159 " cmp r0, r3\n"
160 " itt eq\n"
161 " ldreq r3, =filewritetask\n"
162 " orreq r3, #1\n"
163 " beq exitHook\n"
164
165
166
167
168
169
170
171
172 " ldr r0, =task_InitFileModules\n"
173 " cmp r0, r3\n"
174 " itt eq\n"
175 " ldreq r3, =init_file_modules_task\n"
176 " orreq r3, #1\n"
177
178 "exitHook:\n"
179
180
181 " pop {r0}\n"
182
183
184
185
186
187
188
189
190 " stmdb sp!, {r1, r2, r3, r4, r5, r6, r7, r8, r9, lr}\n"
191
192 " mov r4, r0\n"
193 " ldr r0, =0x8160\n"
194
195
196 " ldr.w pc, =(hook_CreateTask + 8 + 1) \n"
197 ".ltorg\n"
198 );
199 }
200
201
202 void __attribute__((naked,noinline)) sub_fc05eec0_my() {
203
204
205
206
207
208
209
210
211
212
213
214
215
216 asm volatile (
217 "push {r4, lr}\n"
218
219 #if defined(CHDK_NOT_IN_CANON_HEAP)
220 "ldr r4, =0x003a8bb0\n"
221 #else
222 "ldr r4, =new_sa\n"
223 "ldr r4, [r4]\n"
224 #endif
225 " sub sp, #0x78\n"
226 " ldr r0, =0x006ce000\n"
227 " ldr r1, =0x0008fd8c\n"
228 " subs r0, r0, r4\n"
229 " cmp r0, r1\n"
230 " bhs loc_fc05eed2\n"
231 "loc_fc05eed0:\n"
232 " b loc_fc05eed0\n"
233 "loc_fc05eed2:\n"
234 " ldr r1, =0x00008074\n"
235 " mov.w r0, #0x80000\n"
236 " str r0, [r1]\n"
237 " ldr r1, =0x00008078\n"
238 " ldr r0, =0x42a41000\n"
239 " str r0, [r1]\n"
240 " ldr r1, =0x0000807c\n"
241 " ldr r0, =0x42a43000\n"
242 " str r0, [r1]\n"
243 " movs r1, #0x78\n"
244 " mov r0, sp\n"
245 " blx sub_fc2cf43c\n"
246 " ldr r0, =0x0062e000\n"
247 " mov.w r1, #0xa0000\n"
248 " stm.w sp, {r0, r1, r4}\n"
249 " ldr r1, =0x00622274\n"
250 " subs r2, r1, r4\n"
251 " strd r2, r1, [sp, #0xc]\n"
252 " str r0, [sp, #0x14]\n"
253 " movs r0, #0x22\n"
254 " str r0, [sp, #0x18]\n"
255 " movs r0, #0x98\n"
256 " str r0, [sp, #0x1c]\n"
257 " movw r0, #0x24c\n"
258 " str r0, [sp, #0x20]\n"
259 " movs r0, #0xfa\n"
260 " str r0, [sp, #0x24]\n"
261 " movs r0, #0xe8\n"
262 " str r0, [sp, #0x28]\n"
263 " movs r0, #0x85\n"
264 " str r0, [sp, #0x2c]\n"
265 " movs r0, #0x40\n"
266 " str r0, [sp, #0x30]\n"
267 " movs r0, #4\n"
268 " str r0, [sp, #0x34]\n"
269 " movs r0, #0\n"
270 " str r0, [sp, #0x38]\n"
271 " movs r0, #0x10\n"
272 " str r0, [sp, #0x5c]\n"
273 " movs r2, #0\n"
274 " lsls r0, r0, #8\n"
275 " str r0, [sp, #0x60]\n"
276
277 "ldr r1, =sub_fc05f050_my\n"
278 " asrs r0, r0, #4\n"
279 " str r0, [sp, #0x64]\n"
280 " lsls r0, r0, #5\n"
281 " str r0, [sp, #0x68]\n"
282 " mov r0, sp\n"
283 " blx sub_fc2ce9a8\n"
284 " add sp, #0x78\n"
285 " pop {r4, pc}\n"
286 ".ltorg\n"
287
288 );
289
290
291 }
292
293
294
295 void __attribute__((naked,noinline)) sub_fc05f050_my() {
296
297
298 asm volatile (
299 " push {r4, lr}\n"
300 " ldr r4, =0xfc05f0fc\n"
301 " bl sub_fc0602ec\n"
302 " ldr r0, =0x000080ec\n"
303 " ldr r1, [r0]\n"
304 " ldr r0, =0x00008074\n"
305 " ldr r0, [r0]\n"
306 " adds r0, #0x10\n"
307 " cmp r1, r0\n"
308 " bhs loc_fc05f06c\n"
309 " ldr r0, =0xfc05f10c\n"
310 " bl sub_fc05f0e4\n"
311 "loc_fc05f06c:\n"
312 " bl sub_fc1362a8\n"
313 " ldr r3, =0x80000800\n"
314
315
316 "mov.w r1, #0x80000000\n"
317 "mov.w r2, #0xeeeeeeee\n"
318 "loc_fc05f07a:\n"
319 " stm r1!, {r2}\n"
320 " cmp r1, r3\n"
321 " blo loc_fc05f07a\n"
322 " bl sub_fc1362ba\n"
323 " bl sub_fc136890\n"
324 " cmp r0, #0\n"
325 " bge loc_fc05f092\n"
326 " ldr r0, =0xfc05f128\n"
327 " bl sub_fc05f0e4\n"
328 "loc_fc05f092:\n"
329 " bl sub_fc05f8c4\n"
330 " cmp r0, #0\n"
331 " bge loc_fc05f0a0\n"
332 " ldr r0, =0xfc05f130\n"
333 " bl sub_fc05f0e4\n"
334 "loc_fc05f0a0:\n"
335 " mov r0, r4\n"
336 " bl sub_fc05f952\n"
337 " cmp r0, #0\n"
338 " bge loc_fc05f0b0\n"
339 " ldr r0, =0xfc05f140\n"
340 " bl sub_fc05f0e4\n"
341 "loc_fc05f0b0:\n"
342 " mov r0, r4\n"
343 " bl sub_fc05f288\n"
344 " cmp r0, #0\n"
345 " bge loc_fc05f0c0\n"
346 " ldr r0, =0xfc05f154\n"
347 " bl sub_fc05f0e4\n"
348 "loc_fc05f0c0:\n"
349 " bl sub_fc05f3cc\n"
350 " cmp r0, #0\n"
351 " bge loc_fc05f0ce\n"
352 " ldr r0, =0xfc05f160\n"
353 " bl sub_fc05f0e4\n"
354 "loc_fc05f0ce:\n"
355 " bl sub_fc0623e8\n"
356 " cmp r0, #0\n"
357 " bge loc_fc05f0dc\n"
358 " ldr r0, =0xfc05f16c\n"
359 " bl sub_fc05f0e4\n"
360 "loc_fc05f0dc:\n"
361 " pop.w {r4, lr}\n"
362
363 "b.w sub_fc05f456_my\n"
364 ".ltorg\n"
365
366 );
367
368 }
369
370 void __attribute__((naked,noinline)) sub_fc05f0e4_my() {
371
372
373 }
374 void __attribute__((naked,noinline)) sub_fc05f456_my() {
375
376
377
378 asm volatile (
379 " push {r3, lr}\n"
380 " bl sub_fc05f570\n"
381 " bl sub_fc0b9738\n"
382 " cbnz r0, loc_fc05f46c\n"
383 " bl sub_fc07f062\n"
384 " cbz r0, loc_fc05f46c\n"
385 " movs r0, #1\n"
386 " b loc_fc05f46e\n"
387 "loc_fc05f46c:\n"
388 " movs r0, #0\n"
389 "loc_fc05f46e:\n"
390 " bl sub_fc07319c\n"
391 " cbnz r0, loc_fc05f47a\n"
392 " bl sub_fc05f55e\n"
393 "loc_fc05f478:\n"
394 " b loc_fc05f478\n"
395 "loc_fc05f47a:\n"
396 " blx sub_fc2cea00\n"
397 " ldr r1, =0x006ce000\n"
398 " movs r0, #0\n"
399 " bl sub_fc336500\n"
400 " blx sub_fc2cefd4\n"
401 " movs r3, #0\n"
402 " str r3, [sp]\n"
403
404 "ldr r3, =task_Startup_my\n"
405 " movs r2, #0\n"
406 " movs r1, #0x19\n"
407 " ldr r0, =0xfc05f4a8\n"
408
409 "bl _CreateTask\n"
410 " movs r0, #0\n"
411 " pop {r3, pc}\n"
412 ".ltorg\n"
413 );
414 }
415
416
417
418 void __attribute__((naked,noinline)) task_Startup_my() {
419
420 asm volatile (
421
422 " push {r4, lr}\n"
423 " bl sub_fc137ad4\n"
424 " bl sub_fc05f53c\n"
425
426 " bl sub_fc0daedc\n"
427 "bl sub_010e6355\n"
428
429 " bl sub_fc08da46\n"
430 " bl sub_fc0db028\n"
431 " bl sub_fc05f804\n"
432 " bl sub_fc05f650\n"
433 " bl sub_fc0daf1a\n"
434 " bl sub_fc0b947c\n"
435 " bl sub_fc0db02e\n"
436 " bl sub_fc07308e_my\n"
437 " bl CreateTask_spytask\n"
438 " bl init_required_fw_features\n"
439 " bl sub_fc275708\n"
440 " bl sub_fc0db044\n"
441 " bl sub_fc0b9230\n"
442 " bl sub_fc13788e\n"
443 " bl sub_fc0b95e4\n"
444 " bl sub_fc0b942e\n"
445 " bl sub_fc13784a\n"
446 " bl sub_fc05f808\n"
447 " bl sub_fc32f65a\n"
448 " bl sub_fc13781e\n"
449 " pop.w {r4, lr}\n"
450 " b.w sub_fc137aaa\n"
451 ".ltorg\n"
452 );
453 }
454
455 void __attribute__((naked,noinline)) sub_fc07308e_my() {
456
457 asm volatile (
458 " push {r3, r4, r5, lr}\n"
459 " bl sub_fc07202c\n"
460 " bl sub_fc07efe0\n"
461 " cbnz r0, loc_fc07309e\n"
462 " bl sub_fc071fd0\n"
463 "loc_fc07309e:\n"
464 " ldr r4, =0x000082c8\n"
465 " ldr r0, [r4, #4]\n"
466 " cmp r0, #0\n"
467 " bne loc_fc0730ba\n"
468 " movs r3, #0\n"
469 " str r3, [sp]\n"
470
471 "ldr r3, =mykbd_task\n"
472 " movs r1, #0x17\n"
473 " ldr r0, =0xfc0730e8\n"
474 " movw r2, #0x2000\n"
475 " blx sub_fc2cf344\n"
476 " str r0, [r4, #4]\n"
477 "loc_fc0730ba:\n"
478 " pop {r3, r4, r5, pc}\n"
479 ".ltorg\n"
480 );
481 }
482
483 void __attribute__((naked,noinline)) init_file_modules_task() {
484
485
486 asm volatile (
487
488 " push {r4, r5, r6, lr}\n"
489 " bl sub_fc0e5238\n"
490 " movs r4, r0\n"
491 " movw r5, #0x5006\n"
492 " beq loc_fc0bda26\n"
493 " movs r1, #0\n"
494 " mov r0, r5\n"
495 " bl _PostLogicalEventToUI\n"
496 "loc_fc0bda26:\n"
497 " bl sub_fc0e5262\n"
498 " BL core_spytask_can_start\n"
499 " cmp r4, #0\n"
500 " bne loc_fc0bda3a\n"
501 " mov r0, r5\n"
502 " pop.w {r4, r5, r6, lr}\n"
503 " movs r1, #0\n"
504 " b.w _PostLogicalEventToUI\n"
505 "loc_fc0bda3a:\n"
506 " pop {r4, r5, r6, pc}\n"
507 " .ltorg\n"
508 );
509
510 }
511
512
513 void __attribute__((naked,noinline)) kbd_p2_f_my() {
514
515
516
517 asm volatile(
518 " stmdb sp!, {r4, r5, r6, r7, r8, lr}\n"
519
520 " ldr r6, =0x00033f88\n"
521 " sub sp, #0x18\n"
522 " add r7, sp, #8\n"
523 " subs r6, #0xc\n"
524 " b loc_fc072e76\n"
525 "loc_fc072e42:\n"
526 " ldr r1, =0x00033f88\n"
527 " add r3, sp, #8\n"
528 " ldrb.w r0, [sp, #4]\n"
529 " add r2, sp, #0x14\n"
530 " subs r1, #0x18\n"
531 " bl sub_fc070b4e\n"
532 " cbnz r0, loc_fc072e5c\n"
533 " ldr r1, [sp, #0x14]\n"
534 " movs r0, #0\n"
535 " bl sub_fc072da6\n"
536 "loc_fc072e5c:\n"
537 " movs r0, #2\n"
538 "loc_fc072e5e:\n"
539 " ldr.w r1, [r7, r0, lsl #2]\n"
540 " cbz r1, loc_fc072e6e\n"
541 " ldr.w r2, [r6, r0, lsl #2]\n"
542 " bics r2, r1\n"
543 " str.w r2, [r6, r0, lsl #2]\n"
544 "loc_fc072e6e:\n"
545 " subs r0, r0, #1\n"
546 " sxtb r0, r0\n"
547 " cmp r0, #0\n"
548 " bge loc_fc072e5e\n"
549 "loc_fc072e76:\n"
550 " ldr r0, =0x00033f88\n"
551 " add r1, sp, #4\n"
552 " subs r0, #0xc\n"
553 " bl sub_fc07084c\n"
554 " cmp r0, #0\n"
555 " bne loc_fc072e42\n"
556 " ldr.w r8, =0x00033f88\n"
557 " movs r4, #0\n"
558 "loc_fc072e8a:\n"
559 " movs r5, #0\n"
560 " ldr.w r0, [r6, r4, lsl #2]\n"
561 " ldr.w r1, [r8, r4, lsl #2]\n"
562 " ands r0, r1\n"
563 " str.w r0, [r6, r4, lsl #2]\n"
564 " b loc_fc072ee2\n"
565 "loc_fc072e9c:\n"
566 " lsrs r0, r5\n"
567 " lsls r0, r0, #0x1f\n"
568 " beq loc_fc072eda\n"
569 " ldr r1, =0x00033f88\n"
570 " add.w r0, r5, r4, lsl #5\n"
571 " add r3, sp, #8\n"
572 " subs r1, #0x18\n"
573 " add r2, sp, #0x14\n"
574 " uxtb r0, r0\n"
575 " bl sub_fc070b4e\n"
576 " cbnz r0, loc_fc072ebe\n"
577 " ldr r1, [sp, #0x14]\n"
578 " movs r0, #1\n"
579 " bl sub_fc072da6\n"
580 "loc_fc072ebe:\n"
581 " mov r0, r4\n"
582 " b loc_fc072ed6\n"
583 "loc_fc072ec2:\n"
584 " ldr.w r1, [r7, r0, lsl #2]\n"
585 " cbz r1, loc_fc072ed2\n"
586 " ldr.w r2, [r6, r0, lsl #2]\n"
587 " bics r2, r1\n"
588 " str.w r2, [r6, r0, lsl #2]\n"
589 "loc_fc072ed2:\n"
590 " adds r0, r0, #1\n"
591 " sxtb r0, r0\n"
592 "loc_fc072ed6:\n"
593 " cmp r0, #3\n"
594 " blt loc_fc072ec2\n"
595 "loc_fc072eda:\n"
596 " ldr.w r0, [r6, r4, lsl #2]\n"
597 " adds r5, r5, #1\n"
598 " uxtb r5, r5\n"
599 "loc_fc072ee2:\n"
600 " cmp r0, #0\n"
601 " bne loc_fc072e9c\n"
602 " adds r4, r4, #1\n"
603 " sxtb r4, r4\n"
604 " cmp r4, #3\n"
605 " blt loc_fc072e8a\n"
606
607 " bl sub_fc0706e8_my\n"
608 " add sp, #0x18\n"
609 " pop.w {r4, r5, r6, r7, r8, pc}\n"
610 ".ltorg\n"
611 );
612
613 }
614
615 void __attribute__((naked,noinline)) sub_fc0706e8_my() {
616 asm volatile(
617 " push {r4, lr}\n"
618 " ldr r4, =0x0000970c\n"
619 " ldr r0, [r4, #0xc]\n"
620 " bl sub_fc072250\n"
621 " bl sub_fc0f9118\n"
622 " ldr r0, [r4, #0x10]\n"
623 " bl sub_fc07216c\n"
624 " bl handle_jogdial\n"
625 " cmp r0, #0\n"
626 " beq no_scroll\n"
627 " bl sub_fc072490\n"
628 "no_scroll:\n"
629 " pop {r4, pc}\n"
630 );
631 }
632
633
634
635