root/platform/ixus175_elph180/sub/100c/filewrite.c

/* [<][>][^][v][top][bottom][index][help] */

DEFINITIONS

This source file includes following definitions.
  1. log_fwt_msg
  2. log_fwt_start
  3. filewritetask
  4. sub_FFAC87E0_my
  5. sub_FFAC9088_my
  6. sub_FFAC89B8_my

   1 /*
   2  * filewrite.c - auto-generated by CHDK code_gen.
   3  */
   4 #include "lolevel.h"
   5 #include "platform.h"
   6 
   7 // debug
   8 //#define FILEWRITE_DEBUG_LOG 1
   9 extern void _LogCameraEvent(int id,const char *fmt,...);
  10 
  11 typedef struct {
  12     unsigned int address;
  13     unsigned int length;
  14 } cam_ptp_data_chunk; //camera specific structure
  15 
  16 #define MAX_CHUNKS_FOR_FWT 7 // filewritetask is prepared for this many chunks
  17 
  18 
  19 /*
  20  * fwt_data_struct: defined here as it's camera dependent
  21  * unneeded members are designated with unkn
  22  * file_offset, full_size, seek_flag only needs to be defined for cameras with CAM_FILEWRITETASK_SEEK/CAM_FILEWRITETASK_MULTIPASS
  23  * pdc is always required
  24  * name is not currently used
  25  */
  26 typedef struct
  27 {
  28     int unkn1; // message number
  29     int file_offset;
  30     int maybe_full_size; // maybe, on g7x wasn't always full size
  31     int unkn2, unkn3;
  32     int unkn4;
  33     cam_ptp_data_chunk pdc[MAX_CHUNKS_FOR_FWT];
  34     int maybe_seek_flag;      // 0x2083 jpeg, 0x100 create dir, 0x200 CacheFlush
  35     int unkn5, unkn6;
  36     char name[32];      // offset from start 0x5c, from Open case
  37 } fwt_data_struct;
  38 /*
  39 observed message sequences
  40 JPEG
  41 12 maybe_full_size = 0x004437ac (=actual size), seek_flag = 0x2083
  42  0 chunk 0-0x004437ac
  43  1 chunk 0-0
  44  7 close
  45 
  46 new directory
  47 11 seek_flag = 0x100
  48 before m 12 for shot, after raw hook in capt_seq
  49 
  50 after shot
  51 10 A/ seek_flag 0x200
  52 */
  53 
  54 #include "../../../generic/filewrite.c"
  55 
  56 #ifdef FILEWRITE_DEBUG_LOG
  57 void log_fwt_msg(fwt_data_struct *fwd)
  58 {
  59     int m=fwd->unkn1;
  60     _LogCameraEvent(0x60,"fw m:%d o:0x%08x fs:0x%08x sf:0x%x",m,fwd->file_offset,fwd->maybe_full_size,fwd->maybe_seek_flag);
  61     _LogCameraEvent(0x60,"fw %s",fwd->name);
  62     if(m >= 0 && m <=6) {
  63         _LogCameraEvent(0x60,"fw chunk adr:0x%08x l:0x%08x",fwd->pdc[m].address,fwd->pdc[m].length);
  64     }
  65     _LogCameraEvent(0x60,"fw u %08x %08x %08x %08x %08x %08x",fwd->unkn2,fwd->unkn3,fwd->unkn4,fwd->unkn5,fwd->unkn6);
  66 }
  67 
  68 void log_fwt_start(void)
  69 {
  70     _LogCameraEvent(0x60,"fw start");
  71 }
  72 #endif
  73 
  74 
  75 /*************************************************************/
  76 //** filewritetask @ 0xFFAC8BB8 - 0xFFAC8CF8, length=81
  77 void __attribute__((naked,noinline)) filewritetask() {
  78 asm volatile (
  79 "    STMFD   SP!, {R1-R5,LR} \n"
  80 #ifdef FILEWRITE_DEBUG_LOG
  81 "bl log_fwt_start\n"
  82 #endif
  83 "    LDR     R5, =0xAE3C \n"
  84 
  85 "loc_FFAC8BC0:\n"
  86 "    MOV     R2, #0 \n"
  87 "    LDR     R0, [R5, #0x14] \n"
  88 "    ADD     R1, SP, #8 \n"
  89 "    BL      sub_006B8568 /*_ReceiveMessageQueue*/ \n"
  90 "    CMP     R0, #0 \n"
  91 "    LDRNE   R2, =0x476 \n"
  92 "    LDRNE   R1, =0xFFAC8D2C /*'dwFWrite.c'*/ \n"
  93 "    MOVNE   R0, #0 \n"
  94 "    BLNE    _DebugAssert \n"
  95 #ifdef FILEWRITE_DEBUG_LOG
  96 "ldr     r0, [sp,#8]\n"
  97 "bl log_fwt_msg\n"
  98 #endif
  99 "    LDR     R0, [SP, #8] \n"
 100 "    LDR     R1, [R0] \n"
 101 "    CMP     R1, #0xD \n"
 102 "    ADDCC   PC, PC, R1, LSL#2 \n"
 103 "    B       loc_FFAC8BC0 \n"
 104 "    B       loc_FFAC8CEC \n"
 105 "    B       loc_FFAC8CEC \n"
 106 "    B       loc_FFAC8CEC \n"
 107 "    B       loc_FFAC8CEC \n"
 108 "    B       loc_FFAC8CEC \n"
 109 "    B       loc_FFAC8CEC \n"
 110 "    B       loc_FFAC8CEC \n"
 111 "    B       loc_FFAC8CF4 \n"
 112 "    B       loc_FFAC8C2C \n"
 113 "    B       loc_FFAC8CB4 \n"
 114 "    B       loc_FFAC8CE4 \n"
 115 "    B       loc_FFAC8CA4 \n"
 116 "    B       loc_FFAC8CAC \n"
 117 
 118 "loc_FFAC8C2C:\n"
 119 "    MOV     R0, #0 \n"
 120 "    STR     R0, [SP] \n"
 121 
 122 "loc_FFAC8C34:\n"
 123 "    LDR     R0, [R5, #0x14] \n"
 124 "    MOV     R1, SP \n"
 125 "    BL      sub_006B87F0 /*_GetNumberOfPostedMessages*/ \n"
 126 "    LDR     R0, [SP] \n"
 127 "    CMP     R0, #0 \n"
 128 "    BEQ     loc_FFAC8C60 \n"
 129 "    LDR     R0, [R5, #0x14] \n"
 130 "    MOV     R2, #0 \n"
 131 "    ADD     R1, SP, #4 \n"
 132 "    BL      sub_006B8568 /*_ReceiveMessageQueue*/ \n"
 133 "    B       loc_FFAC8C34 \n"
 134 
 135 "loc_FFAC8C60:\n"
 136 "    LDR     R0, [R5, #8] \n"
 137 "    MOV     R4, R5 \n"
 138 "    CMN     R0, #1 \n"
 139 "    BEQ     loc_FFAC8C98 \n"
 140 "    BL      _Close \n"
 141 "    MVN     R0, #0 \n"
 142 "    STR     R0, [R4, #8] \n"
 143 "    MOV     R1, #0 \n"
 144 "    MOV     R0, #0x48 \n"
 145 "    BL      sub_FF8B394C \n"
 146 "    LDR     R0, =0xFC8C4 \n"
 147 "    BL      sub_FF830778 \n"
 148 "    MOV     R1, #0 \n"
 149 "    BL      sub_FF82E5F8 \n"
 150 
 151 "loc_FFAC8C98:\n"
 152 "    LDR     R0, [R4, #0x10] \n"
 153 "    BL      _GiveSemaphore \n"
 154 "    B       loc_FFAC8BC0 \n"
 155 
 156 "loc_FFAC8CA4:\n"
 157 "    BL      sub_FFAC8F4C \n"
 158 "    B       loc_FFAC8BC0 \n"
 159 
 160 "loc_FFAC8CAC:\n"
 161 "    BL      sub_FFAC87E0_my \n"  // --> Patched. Old value = 0xFFAC87E0. msg 12 - open, main hook
 162 "    B       loc_FFAC8BC0 \n"
 163 
 164 "loc_FFAC8CB4:\n"
 165 "    LDR     R1, [R0, #4] \n"
 166 "    MOV     R4, R0 \n"
 167 "    LDR     R0, [R5, #8] \n"
 168 "    MOV     R2, #0 \n"
 169 "    BL      _lseek \n"
 170 "    CMN     R0, #1 \n"
 171 "    LDREQ   R0, =0x9200013 \n"
 172 "    MOVEQ   R1, R4 \n"
 173 "    STREQ   R0, [R4, #0x14] \n"
 174 "    MOVEQ   R0, #7 \n"
 175 "    BLEQ    sub_FFAC8718 \n"
 176 "    B       loc_FFAC8BC0 \n"
 177 
 178 "loc_FFAC8CE4:\n"
 179 "    BL      sub_FFAC8FEC \n"
 180 "    B       loc_FFAC8BC0 \n"
 181 
 182 "loc_FFAC8CEC:\n"
 183 "    BL      sub_FFAC9088_my \n"  // --> Patched. Old value = 0xFFAC9088. msg 0-6 - write chunk
 184 "    B       loc_FFAC8BC0 \n"
 185 
 186 "loc_FFAC8CF4:\n"
 187 "    BL      sub_FFAC89B8_my \n"  // --> Patched. Old value = 0xFFAC89B8. msg 0-7 - close
 188 "    B       loc_FFAC8BC0 \n"
 189 );
 190 }
 191 
 192 /*************************************************************/
 193 //** sub_FFAC87E0_my @ 0xFFAC87E0 - 0xFFAC89B4, length=118
 194 void __attribute__((naked,noinline)) sub_FFAC87E0_my() {
 195 asm volatile (
 196 "    STMFD   SP!, {R4-R9,LR} \n"
 197 "    MOV     R4, R0 \n"
 198 //hook placed here to avoid conditional branch a few instructions below (watch out for registers!)
 199 //"  MOV   R0, R4\n"      //data block start, commented out as R0 is already holding what we need
 200 "    BL filewrite_main_hook\n"
 201 "    MOV     R0, R4\n"      //restore register(s)
 202 "    LDR     R0, [R0, #0x50] \n"
 203 "    LDR     R7, =0xAE3C \n"
 204 "    TST     R0, #5 \n"
 205 "    SUB     SP, SP, #0x3C \n"
 206 "    BEQ     loc_FFAC8824 \n"
 207 "    LDR     R0, [R7, #0x1C] \n"
 208 "    CMP     R0, #0 \n"
 209 "    BLXNE   R0 \n"
 210 "    ADD     R0, R4, #0x5C \n"
 211 "    BL      sub_FF830778 \n"
 212 "    MOV     R1, #0 \n"
 213 "    BL      sub_FF82E4B8 \n"
 214 "    MOV     R1, #0 \n"
 215 "    MOV     R0, #0x47 \n"
 216 "    BL      sub_FF8B394C \n"
 217 
 218 "loc_FFAC8824:\n"
 219 "    LDR     R0, [R4, #0x50] \n"
 220 "    TST     R0, #1 \n"
 221 "    BEQ     loc_FFAC8988 \n"
 222 "    LDR     R0, [R4, #0x10] \n"
 223 "    BL      sub_FF82D538 \n"
 224 "    LDR     R0, [R4, #0x50] \n"
 225 "    LDR     R5, =0x301 \n"
 226 "    TST     R0, #0x10 \n"
 227 "    MOVNE   R5, #9 \n"
 228 "    BNE     loc_FFAC8854 \n"
 229 "    TST     R0, #0x40 \n"
 230 "    MOVNE   R5, #1 \n"
 231 
 232 "loc_FFAC8854:\n"
 233 "    TST     R0, #0x20 \n"
 234 "    BNE     loc_FFAC8868 \n"
 235 "    LDR     R0, [R4, #0x58] \n"
 236 "    CMP     R0, #1 \n"
 237 "    BNE     loc_FFAC886C \n"
 238 
 239 "loc_FFAC8868:\n"
 240 "    ORR     R5, R5, #0x8000 \n"
 241 
 242 "loc_FFAC886C:\n"
 243 "    LDR     R9, =0x1B6 \n"
 244 "    ADD     R8, R4, #0x5C \n"
 245 "    LDR     R6, [R4, #0x10] \n"
 246 "    MOV     R2, R9 \n"
 247 "    MOV     R1, R5 \n"
 248 "    MOV     R0, R8 \n"
 249 "    BL      fwt_open \n"  // --> Patched. Old value = _Open.
 250 "    CMN     R0, #1 \n"
 251 "    BNE     loc_FFAC88EC \n"
 252 "    MOV     R0, R8 \n"
 253 "    BL      sub_FF827994 \n"
 254 "    MOV     R2, #0xF \n"
 255 "    MOV     R1, R8 \n"
 256 "    ADD     R0, SP, #4 \n"
 257 "    BL      sub_006BCFE0 \n"
 258 "    MOV     R0, #0 \n"
 259 "    LDR     R1, =0x41FF \n"
 260 "    STRB    R0, [SP, #0x13] \n"
 261 "    STR     R1, [SP, #0x24] \n"
 262 "    MOV     R1, #0x10 \n"
 263 "    STR     R0, [SP, #0x2C] \n"
 264 "    STR     R1, [SP, #0x28] \n"
 265 "    ADD     R1, SP, #0x24 \n"
 266 "    ADD     R0, SP, #4 \n"
 267 "    STR     R6, [SP, #0x30] \n"
 268 "    STR     R6, [SP, #0x34] \n"
 269 "    STR     R6, [SP, #0x38] \n"
 270 "    BL      sub_FF82DE1C \n"
 271 "    MOV     R2, R9 \n"
 272 "    MOV     R1, R5 \n"
 273 "    MOV     R0, R8 \n"
 274 "    BL      _Open \n"
 275 
 276 "loc_FFAC88EC:\n"
 277 "    CMN     R0, #1 \n"
 278 "    MOV     R5, R0 \n"
 279 "    STR     R0, [R7, #8] \n"
 280 "    BNE     loc_FFAC8948 \n"
 281 "    MOV     R1, #0 \n"
 282 "    MOV     R0, #0x48 \n"
 283 "    BL      sub_FF8B394C \n"
 284 "    ADD     R0, R4, #0x5C \n"
 285 "    BL      sub_FF830778 \n"
 286 "    LDR     R1, [R7, #0x20] \n"
 287 "    BL      sub_FF82E5F8 \n"
 288 "    LDR     R0, [R7, #0x18] \n"
 289 "    CMP     R0, #0 \n"
 290 "    BEQ     loc_FFAC89B0 \n"
 291 "    LDR     R5, =0x9200001 \n"
 292 "    MOV     R0, R4 \n"
 293 "    MOV     R1, R5 \n"
 294 "    BL      sub_FFAC86B4 \n"
 295 "    LDR     R1, [R7, #0x18] \n"
 296 "    MOV     R0, R5 \n"
 297 "    ADD     SP, SP, #0x3C \n"
 298 "    LDMFD   SP!, {R4-R9,LR} \n"
 299 "    BX      R1 \n"
 300 
 301 "loc_FFAC8948:\n"
 302 "    LDR     R0, =0xFC8C4 \n"
 303 "    MOV     R2, #0x20 \n"
 304 "    ADD     R1, R4, #0x5C \n"
 305 "    BL      sub_006BD1C8 \n"
 306 "    LDR R3, =current_write_ignored\n"
 307 "    LDR R3, [R3]\n"
 308 "    CMP R3, #0\n"
 309 "    BNE loc_C\n" // jump over the next block
 310 "    LDR     R0, [R4, #0x50] \n"
 311 "    TST     R0, #0x80 \n"
 312 "    BEQ     loc_FFAC8988 \n"
 313 "    LDR     R1, [R4, #0xC] \n"
 314 "    MOV     R0, R5 \n"
 315 "    BL      sub_FF827664 \n"
 316 "    CMP     R0, #0 \n"
 317 "    LDREQ   R0, =0x9200017 \n"
 318 "    MOVEQ   R1, R4 \n"
 319 "    STREQ   R0, [R4, #0x14] \n"
 320 "    MOVEQ   R0, #7 \n"
 321 "    BEQ     loc_FFAC89AC \n"
 322 
 323 "loc_FFAC8988:\n"
 324 "loc_C:\n"
 325 "    LDR     R0, [R4, #0x50] \n"
 326 "    TST     R0, #0x40 \n"
 327 "    LDREQ   R0, [R4, #4] \n"
 328 "    CMPEQ   R0, #0 \n"
 329 "    MOVNE   R1, R4 \n"
 330 "    MOVNE   R0, #9 \n"
 331 "    BLNE    sub_FFAC8718 \n"
 332 "    MOV     R1, R4 \n"
 333 "    MOV     R0, #0 \n"
 334 
 335 "loc_FFAC89AC:\n"
 336 "    BL      sub_FFAC8718 \n"
 337 
 338 "loc_FFAC89B0:\n"
 339 "    ADD     SP, SP, #0x3C \n"
 340 "    LDMFD   SP!, {R4-R9,PC} \n"
 341 );
 342 }
 343 
 344 /*************************************************************/
 345 //** sub_FFAC9088_my @ 0xFFAC9088 - 0xFFAC916C, length=58
 346 void __attribute__((naked,noinline)) sub_FFAC9088_my() {
 347 asm volatile (
 348 "    STMFD   SP!, {R4-R10,LR} \n"
 349 "    MOV     R5, R0 \n"
 350 "    LDR     R0, [R0] \n"
 351 "    CMP     R0, #6 \n"
 352 "    BHI     loc_FFAC90B4 \n"
 353 "    ADD     R0, R5, R0, LSL#3 \n"
 354 "    LDR     R8, [R0, #0x18]! \n"
 355 "    LDR     R7, [R0, #4] \n"
 356 "    CMP     R7, #0 \n"
 357 "    BNE     loc_FFAC90D0 \n"
 358 "    B       loc_FFAC90C4 \n"
 359 
 360 "loc_FFAC90B4:\n"
 361 "    LDR     R2, =0x3B5 \n"
 362 "    LDR     R1, =0xFFAC8D2C /*'dwFWrite.c'*/ \n"
 363 "    MOV     R0, #0 \n"
 364 "    BL      _DebugAssert \n"
 365 
 366 "loc_FFAC90C4:\n"
 367 "    MOV     R1, R5 \n"
 368 "    MOV     R0, #7 \n"
 369 "    B       loc_FFAC9168 \n"
 370 
 371 "loc_FFAC90D0:\n"
 372 "    LDR     R9, =0xAE3C \n"
 373 "    MOV     R4, R7 \n"
 374 
 375 "loc_FFAC90D8:\n"
 376 "    LDR     R0, [R5, #4] \n"
 377 "    CMP     R4, #0x1000000 \n"
 378 "    MOVLS   R6, R4 \n"
 379 "    MOVHI   R6, #0x1000000 \n"
 380 "    BIC     R1, R0, #0xFF000000 \n"
 381 "    CMP     R1, #0 \n"
 382 "    BICNE   R0, R0, #0xFF000000 \n"
 383 "    RSBNE   R0, R0, #0x1000000 \n"
 384 "    CMPNE   R6, R0 \n"
 385 "    MOVHI   R6, R0 \n"
 386 "    LDR     R0, [R9, #8] \n"
 387 "    MOV     R2, R6 \n"
 388 "    MOV     R1, R8 \n"
 389 "    BL      fwt_write \n"  // --> Patched. Old value = _Write.
 390 "    LDR     R1, [R5, #4] \n"
 391 "    CMP     R6, R0 \n"
 392 "    ADD     R1, R1, R0 \n"
 393 "    STR     R1, [R5, #4] \n"
 394 "    BEQ     loc_FFAC9138 \n"
 395 "    CMN     R0, #1 \n"
 396 "    LDRNE   R0, =0x9200015 \n"
 397 "    LDREQ   R0, =0x9200005 \n"
 398 "    STR     R0, [R5, #0x14] \n"
 399 "    B       loc_FFAC90C4 \n"
 400 
 401 "loc_FFAC9138:\n"
 402 "    SUB     R4, R4, R0 \n"
 403 "    CMP     R4, R7 \n"
 404 "    LDRCS   R2, =0x3DF \n"
 405 "    LDRCS   R1, =0xFFAC8D2C /*'dwFWrite.c'*/ \n"
 406 "    ADD     R8, R8, R0 \n"
 407 "    MOVCS   R0, #0 \n"
 408 "    BLCS    _DebugAssert \n"
 409 "    CMP     R4, #0 \n"
 410 "    BNE     loc_FFAC90D8 \n"
 411 "    LDR     R0, [R5] \n"
 412 "    MOV     R1, R5 \n"
 413 "    ADD     R0, R0, #1 \n"
 414 
 415 "loc_FFAC9168:\n"
 416 "    LDMFD   SP!, {R4-R10,LR} \n"
 417 "    B       sub_FFAC8718 \n"
 418 );
 419 }
 420 
 421 /*************************************************************/
 422 //** sub_FFAC89B8_my @ 0xFFAC89B8 - 0xFFAC8A4C, length=38
 423 void __attribute__((naked,noinline)) sub_FFAC89B8_my() {
 424 asm volatile (
 425 "    STMFD   SP!, {R4-R6,LR} \n"
 426 "    MOV     R4, R0 \n"
 427 "    LDR     R0, [R0, #0x50] \n"
 428 "    LDR     R5, =0xAE3C \n"
 429 "    TST     R0, #0xA \n"
 430 "    SUB     SP, SP, #0x38 \n"
 431 "    BEQ     sub_FFAC8B84 \n"
 432 "    TST     R0, #2 \n"
 433 "    BEQ     sub_FFAC8A60 \n"
 434 "    TST     R0, #0x80 \n"
 435 "    LDRNE   R0, [R4, #0xC] \n"
 436 "    LDRNE   R1, [R4, #8] \n"
 437 "    CMPNE   R1, R0 \n"
 438 "    BEQ     loc_FFAC8A28 \n"
 439 "    LDR     R0, [R5, #8] \n"
 440 "    BL      sub_FF827664 \n"
 441 "    CMP     R0, #0 \n"
 442 "    LDREQ   R0, =0x9200017 \n"
 443 "    STREQ   R0, [R4, #0x14] \n"
 444 "    BEQ     loc_FFAC8A28 \n"
 445 "    LDR     R0, [R4, #8] \n"
 446 "    ADD     R1, SP, #0x20 \n"
 447 "    STR     R0, [R4, #4] \n"
 448 "    ADD     R0, R4, #0x5C \n"
 449 "    BL      sub_FF82DD64 \n"
 450 "    CMP     R0, #1 \n"
 451 "    LDREQ   R0, [R4, #4] \n"
 452 "    STREQ   R0, [SP, #0x28] \n"
 453 
 454 "loc_FFAC8A28:\n"
 455 "    LDR     R0, [R5, #8] \n"
 456 "    CMN     R0, #1 \n"
 457 "    BEQ     sub_FFAC8A60 \n"
 458 "    LDR     R1, [R4, #0x58] \n"
 459 "    LDR     R6, =0x9200003 \n"
 460 "    CMP     R1, #1 \n"
 461 "    BNE     loc_FFAC8A4C \n"
 462 "    LDR R3, =current_write_ignored\n"
 463 "    LDR R3, [R3]\n"
 464 "    CMP R3, #0\n"
 465 "    BNE loc_D\n" // jump over the next block
 466 "    BL      sub_FF827264 \n"
 467 "    B       sub_FFAC8A50 \n"
 468 
 469 "loc_FFAC8A4C:\n"
 470 "loc_D:\n"
 471 "    BL      fwt_close \n"  // --> Patched. Old value = _Close.
 472 "    LDR     PC, =0xFFAC8A50 \n"  // Continue in firmware
 473 );
 474 }

/* [<][>][^][v][top][bottom][index][help] */