This source file includes following definitions.
- save_romlog2
- spytask_my
- spytask
- CreateTask_spytask
- boot
- CreateTask_my
- sub_fc062f48_my
- sub_fc0630d9_my
- sub_fc0634e2_my
- sub_fc06347d_my
- sub_fc083bea_my
- init_file_modules_task
- kbd_p2_f_my
- sub_fc074e8a_my
- wrap_kbd_p1_f
- sub_fc0839d8_my
- sub_fc07507e_my
- agent_orange
1 #include "lolevel.h"
2 #include "platform.h"
3 #include "core.h"
4 #include "dryos31.h"
5 #include "core.h"
6 #include "callfunc.h"
7
8
9 #define offsetof(TYPE, MEMBER) ((int) &((TYPE *)0)->MEMBER)
10
11 const char * const new_sa = &_end;
12
13
14 extern volatile int jogdial_stopped;
15 void JogDial_task_my(void);
16
17 extern void task_CaptSeq();
18 extern void task_InitFileModules();
19 extern void task_RotaryEncoder();
20 extern void task_MovieRecord();
21 extern void task_ExpDrv();
22
23 extern unsigned _ExecuteEventProcedure(const char *name,...);
24
25
26 extern unsigned _LCDMsg_Create (unsigned, unsigned, unsigned);
27 extern void _LCDMsg_SetStr (unsigned, char * );
28
29
30
31
32 #ifdef BOOT_ROMLOG_SHORTCUT
33 void save_romlog2(void)
34 {
35 unsigned args[4];
36 args[0] = (unsigned)"SystemEventInit";
37 call_func_ptr(_ExecuteEventProcedure,args,1);
38 args[0] = (unsigned)"UI.CreatePublic";
39 call_func_ptr(_ExecuteEventProcedure,args,1);
40 args[0] = (unsigned)"System.Create";
41 call_func_ptr(_ExecuteEventProcedure,args,1);
42 args[0] = (unsigned)"Driver.Create";
43 call_func_ptr(_ExecuteEventProcedure,args,1);
44
45 args[0] = (unsigned)"GetLogToFile";
46 args[1] = (unsigned)"A/ROMLOG.LOG";
47 args[2] = 1;
48 call_func_ptr(_ExecuteEventProcedure,args,3);
49
50 args[0] = (unsigned)"BeepDrive";
51 args[1] = (unsigned) 0x02;
52 call_func_ptr(_ExecuteEventProcedure,args,2);
53
54
55
56 }
57
58
59
60
61
62 void spytask_my(long ua, long ub, long uc, long ud, long ue, long uf)
63 {
64 (void)ua; (void)ub; (void)uc; (void)ud; (void)ue; (void)uf;
65
66 _SleepTask(2800);
67 save_romlog2();
68
69 while (1){
70 _SleepTask(300);
71 }
72 }
73 #endif
74
75
76
77
78 void spytask(long ua, long ub, long uc, long ud, long ue, long uf)
79 {
80 (void)ua; (void)ub; (void)uc; (void)ud; (void)ue; (void)uf;
81 core_spytask();
82 }
83
84
85
86
87
88 void CreateTask_spytask()
89 {
90
91
92 if ( *(int*)(0x9e78) & 0x00600000 )
93 {
94 #ifdef BOOT_ROMLOG_SHORTCUT
95 if (( *(int*)(0xD20BF4A0) & 0x00002000) == 0) _CreateTask("SpyTaskMY", 0x19, 0x2000, spytask_my, 0);
96 #endif
97 _CreateTask("SpyTask", 0x19, 0x2000, spytask, 0);
98 }
99 }
100
101
102
103
104
105
106
107
108
109
110
111
112
113 void __attribute__((naked,noinline)) boot() {
114 asm volatile (
115 " mov r0, #0x4000\n"
116 " mov sp, r0\n"
117 " bl sub_fc02007e\n"
118 " ldr r2, =0xc0242010\n"
119 " ldr r1, [r2]\n"
120 " orr.w r1, r1, #1\n"
121 " str r1, [r2]\n"
122 " ldr r0, =0xfcc98870\n"
123 " ldr r1, =0x10e1000\n"
124 " ldr r3, =0x11074ac\n"
125 " loc_fc02002a:\n"
126 " cmp r1, r3\n"
127 " itt cc\n"
128 " ldrcc.w r2, [r0],#4\n"
129 " strcc.w r2, [r1],#4\n"
130 " bcc loc_fc02002a\n"
131 " ldr r0, =0x10e1000\n"
132 " ldr r1, =0x264ac\n"
133 " bl sub_fc13019a\n"
134 " ldr r0, =0xfccbed1c\n"
135 " ldr r1, =0xbfe10800\n"
136 " ldr r3, =0xbfe17391\n"
137 " loc_fc020046:\n"
138 " cmp r1, r3\n"
139 " itt cc\n"
140 " ldrcc.w r2, [r0],#4\n"
141 " strcc.w r2, [r1],#4\n"
142 " bcc loc_fc020046\n"
143 " ldr r0, =0xfcc50100\n"
144 " ldr r1, =0x8000\n"
145 " ldr r3, =0x50770\n"
146 " loc_fc02005a:\n"
147 " cmp r1, r3\n"
148 " itt cc\n"
149 " ldrcc.w r2, [r0],#4\n"
150 " strcc.w r2, [r1],#4\n"
151 " bcc loc_fc02005a\n"
152
153
154
155
156
157 " ldr r3, =0x50770\n"
158 " ldr r1, =0x3a7cc8\n"
159 " mov.w r2, #0\n"
160 " loc_fc020070:\n"
161 " cmp r3, r1\n"
162 " it cc\n"
163 " strcc.w r2, [r3],#4\n"
164 " bcc loc_fc020070\n"
165
166
167 "adr r0, patch_CreateTask\n"
168 "ldm r0, {r1,r2}\n"
169 "ldr r0, =orig_CreateTask\n"
170 "bic r0, #1\n"
171 "stm r0, {r1,r2}\n"
172
173 "b.w sub_fc062f48_my\n"
174
175 "patch_CreateTask:\n"
176 "ldr.w pc, [pc,#0]\n"
177 ".long CreateTask_my + 1\n"
178 );
179 }
180
181
182 void __attribute__((naked,noinline)) CreateTask_my() {
183
184
185 asm volatile (
186 " push {r0}\n"
187
188
189
190
191
192
193
194
195
196
197 " ldr r0, =task_CaptSeq\n"
198 " cmp r0, r3\n"
199 " itt eq\n"
200 " ldreq r3, =capt_seq_task\n"
201 " orreq r3, #1\n"
202 " beq exitHook\n"
203
204
205 " LDR R0, =task_ExpDrv\n"
206 " CMP R0, R3\n"
207 " itt eq\n"
208 " LDREQ R3, =exp_drv_task\n"
209 " orreq r3, #1\n"
210 " BEQ exitHook\n"
211
212
213
214
215
216
217
218
219
220
221
222 " LDR R0, =task_FileWrite\n"
223 " CMP R0, R3\n"
224 " itt eq\n"
225 " LDREQ R3, =filewritetask\n"
226 " orreq r3, #1\n"
227 " BEQ exitHook\n"
228
229 " LDR R0, =0xFC2623F1\n"
230 " CMP R0, R3\n"
231 " itt eq\n"
232 " LDREQ R3, =task_cocoa0\n"
233 " orreq r3, #1\n"
234 " BEQ exitHook\n"
235
236 " LDR R0, =task_MovieRecord\n"
237 " CMP R0, R3\n"
238 " itt eq\n"
239 " LDREQ R3, =movie_record_task\n"
240 " orreq r3, #1\n"
241 " BEQ exitHook\n"
242
243 " ldr r0, =task_InitFileModules\n"
244 " cmp r0, r3\n"
245 " itt eq\n"
246 " ldreq r3, =init_file_modules_task\n"
247 " orreq r3, #1\n"
248 "exitHook:\n"
249
250
251
252 " pop {r0}\n"
253
254 " stmdb sp!, {r1, r2, r3, r4, r5, r6, r7, r8, r9, lr}\n"
255 " mov r4, r0\n"
256 " ldr r0, =0x8160\n"
257 " ldr.w pc, =(orig_CreateTask + 8) \n"
258 ".ltorg\n"
259 );
260 }
261
262
263 void __attribute__((naked,noinline)) sub_fc062f48_my() {
264
265 asm volatile (
266 "push {r4, lr}\n"
267 #if defined(CHDK_NOT_IN_CANON_HEAP)
268 " ldr r4, =0x3a7cc8\n"
269 #else
270 "ldr r4, =new_sa\n"
271 "ldr r4, [r4]\n"
272 #endif
273 " sub sp, sp, #0x78\n"
274 " ldr r0, =0x74e000\n"
275 " ldr r1, =0xafd8c\n"
276 " subs r0, r0, r4\n"
277 " cmp r0, r1\n"
278 " bcs loc_fc062f5a\n"
279 " loc_fc062f58:\n"
280 " b loc_fc062f58\n"
281 " loc_fc062f5a:\n"
282 " ldr r1, =0x8074\n"
283 " mov.w r0, #0x80000\n"
284 " str r0, [r1]\n"
285 " ldr r1, =0x8078\n"
286 " ldr r0, =0x42a41000\n"
287 " str r0, [r1]\n"
288 " ldr r1, =0x807c\n"
289 " ldr r0, =0x42a43000\n"
290 " str r0, [r1]\n"
291 " movs r1, #0x78\n"
292 " mov r0, sp\n"
293 " blx sub_fc30243c\n"
294 " ldr r0, =0x68e000\n"
295 " mov.w r1, #0xc0000\n"
296 " stmea.w sp, {r0,r1,r4}\n"
297 " ldr r1, =0x682274\n"
298 " subs r2, r1, r4\n"
299 " strd.w r2, r1, [sp,#0xc]\n"
300 " str r0, [sp,#0x14]\n"
301 " movs r0, #0x22\n"
302 " str r0, [sp,#0x18]\n"
303 " movs r0, #0x98\n"
304 " str r0, [sp,#0x1c]\n"
305 " movw r0, #0x24c\n"
306 " str r0, [sp,#0x20]\n"
307 " movs r0, #0xfa\n"
308 " str r0, [sp,#0x24]\n"
309 " movs r0, #0xe8\n"
310 " str r0, [sp,#0x28]\n"
311 " movs r0, #0x85\n"
312 " str r0, [sp,#0x2c]\n"
313 " movs r0, #0x40\n"
314 " str r0, [sp,#0x30]\n"
315 " movs r0, #4\n"
316 " str r0, [sp,#0x34]\n"
317 " movs r0, #0\n"
318 " str r0, [sp,#0x38]\n"
319 " movs r0, #0x10\n"
320 " str r0, [sp,#0x5c]\n"
321 " movs r2, #0\n"
322 " lsls r0, r0, #8\n"
323 " str r0, [sp,#0x60]\n"
324 " ldr r1, =sub_fc0630d9_my\n"
325 " asrs r0, r0, #4\n"
326 " str r0, [sp,#0x64]\n"
327 " lsls r0, r0, #5\n"
328 " str r0, [sp,#0x68]\n"
329 " mov r0, sp\n"
330 " blx sub_fc301ba0\n"
331 " add sp, sp, #0x78\n"
332 " pop {r4,pc}\n"
333 ".ltorg\n"
334 );
335 }
336
337
338 void __attribute__((naked,noinline)) sub_fc0630d9_my() {
339 asm volatile (
340 " push {r4,lr}\n"
341 " ldr r4, =0xfc063180\n"
342 " bl sub_fc0643d4\n"
343 " ldr r0, =0x80ec\n"
344 " ldr r1, [r0]\n"
345 " ldr r0, =0x8074\n"
346 " ldr r0, [r0]\n"
347 " adds r0, #0x10\n"
348 " cmp r1, r0\n"
349 " bcs loc_fc0630f4\n"
350 " ldr r0, =0xfc063190\n"
351 " bl sub_fc06316a\n"
352 " loc_fc0630f4:\n"
353 " bl sub_fc130274\n"
354 " ldr r1, =0xbfe10000\n"
355 " mov.w r2, #0xeeeeeeee\n"
356 " ldr r3, =0xbfe10800\n"
357 " loc_fc063100:\n"
358 " stmia r1!, {r2}\n"
359 " cmp r1, r3\n"
360 " bcc loc_fc063100\n"
361 " bl sub_fc130286\n"
362 " bl sub_fc1edfbc\n"
363 " cmp r0, #0\n"
364 " bge loc_fc063118\n"
365 " ldr r0, =0xfc0631b0\n"
366 " bl sub_fc06316a\n"
367 " loc_fc063118:\n"
368 " bl sub_fc063964\n"
369 " cmp r0, #0\n"
370 " bge loc_fc063126\n"
371 " ldr r0, =0xfc0631b8\n"
372 " bl sub_fc06316a\n"
373 " loc_fc063126:\n"
374 " mov r0, r4\n"
375 " bl sub_fc0639f2\n"
376 " cmp r0, #0\n"
377 " bge loc_fc063136\n"
378 " ldr r0, =0xfc0631c8\n"
379 " bl sub_fc06316a\n"
380 " loc_fc063136:\n"
381 " mov r0, r4\n"
382 " bl sub_fc063314\n"
383 " cmp r0, #0\n"
384 " bge loc_fc063146\n"
385 " ldr r0, =0xfc0631dc\n"
386 " bl sub_fc06316a\n"
387 " loc_fc063146:\n"
388 " bl sub_fc063458\n"
389 " cmp r0, #0\n"
390 " bge loc_fc063154\n"
391 " ldr r0, =0xfc0631e8\n"
392 " bl sub_fc06316a\n"
393 " loc_fc063154:\n"
394 " bl sub_fc0665ac\n"
395 " cmp r0, #0\n"
396 " bge loc_fc063162\n"
397 " ldr r0, =0xfc0631f4\n"
398 " bl sub_fc06316a\n"
399 " loc_fc063162:\n"
400 " pop.w {r4,lr}\n"
401 " b.w sub_fc0634e2_my\n"
402 ".ltorg\n"
403 );
404 }
405
406 void __attribute__((naked,noinline)) sub_fc0634e2_my() {
407 asm volatile (
408 " push {r3,lr}\n"
409 " bl sub_fc0635fc\n"
410 " bl sub_fc13131c\n"
411 " cbnz r0, loc_fc0634f8\n"
412 " bl sub_fc07803e\n"
413 " cbz r0, loc_fc0634f8\n"
414 " movs r0, #1\n"
415 " b loc_fc0634fa\n"
416 " loc_fc0634f8:\n"
417 " movs r0, #0\n"
418 " loc_fc0634fa:\n"
419 " bl sub_fc083cc4\n"
420 " cbnz r0, loc_fc063506\n"
421 " bl sub_fc0635ea\n"
422 " loc_fc063504:\n"
423 " b loc_fc063504\n"
424 " loc_fc063506:\n"
425 " blx sub_fc301bf8\n"
426 " ldr r1, =0x74e000\n"
427 " movs r0, #0\n"
428 " bl sub_fc37a758\n"
429 " blx sub_fc301fdc\n"
430 " movs r3, #0\n"
431 " str r3, [sp]\n"
432 " ldr r3, =sub_fc06347d_my\n"
433 " movs r2, #0\n"
434 " movs r1, #0x19\n"
435 " ldr r0, =0xfc063534\n"
436 " blx sub_fc3021d4\n"
437 " movs r0, #0\n"
438 " pop {r3,pc}\n"
439 ".ltorg\n"
440 );
441 }
442
443
444 void __attribute__((naked,noinline)) sub_fc06347d_my() {
445 asm volatile (
446 " push {r4,lr}\n"
447 " bl sub_fc131030\n"
448 " bl sub_fc0635c8\n"
449
450 " bl sub_fc0f41f0\n"
451
452 " bl sub_010e16c8\n"
453 " bl sub_fc36dfa6\n"
454 " bl sub_fc0f4348\n"
455 " bl sub_fc0638a4\n"
456 " bl sub_fc0636dc\n"
457 " bl sub_fc0f4222\n"
458 " bl sub_fc1ee770\n"
459 " bl sub_fc0f434e\n"
460 " bl CreateTask_spytask\n"
461 " bl sub_fc083bea_my\n"
462 " bl sub_fc0a9870\n"
463 " bl sub_fc0f4364\n"
464 " bl sub_fc0d2610\n"
465 " bl sub_fc130de8\n"
466 " bl sub_fc1311da\n"
467 " bl sub_fc0f41a2\n"
468 " bl sub_fc130da4\n"
469
470 " bl sub_fc363020\n"
471 " bl sub_fc130d78\n"
472
473 " pop.w {r4,lr}\n"
474
475 "ldr pc, =0xfc131007\n"
476 ".ltorg\n"
477 );
478 }
479
480
481 void __attribute__((naked,noinline)) sub_fc083bea_my() {
482 asm volatile (
483 " push {r3-r5,lr}\n"
484 " bl sub_fc0763a4\n"
485 " bl sub_fc077fbc\n"
486 " cbnz r0, loc_fc083bfa\n"
487 " bl sub_fc076348\n"
488 " loc_fc083bfa:\n"
489 " ldr r4, =0x82cc\n"
490 " ldr r0, [r4,#4]\n"
491 " cmp r0, #0\n"
492 " bne locret_fc083c16\n"
493 " movs r3, #0\n"
494 " str r3, [sp]\n"
495 " ldr r3, =mykbd_task\n"
496
497 " movs r1, #0x17\n"
498 " ldr r0, =0xfc083f2c\n"
499 " movw r2, #0x2000\n"
500 " blx sub_fc3022e4\n"
501 " str r0, [r4,#4]\n"
502 " locret_fc083c16:\n"
503 " pop {r3-r5,pc}\n"
504 ".ltorg\n"
505 );
506 }
507
508 void __attribute__((naked,noinline)) init_file_modules_task() {
509 asm volatile (
510 " push {r4-r6,lr}\n"
511 " bl sub_fc0f9dec\n"
512 " movs r4, r0\n"
513 " movw r5, #0x5006\n"
514 " beq loc_fc0f79b6\n"
515 " movs r1, #0\n"
516 " mov r0, r5\n"
517 " bl sub_fc37eba4\n"
518 " loc_fc0f79b6:\n"
519 " bl sub_fc0f9e16\n"
520 " BL core_spytask_can_start\n"
521 " cmp r4, #0\n"
522 " bne locret_fc0f79ca\n"
523 " mov r0, r5\n"
524 " pop.w {r4-r6,lr}\n"
525 " movs r1, #0\n"
526 " b.w sub_fc37eba4\n"
527 " locret_fc0f79ca:\n"
528 " pop {r4-r6,pc}\n"
529 ".ltorg\n"
530 );
531 }
532
533 void __attribute__((naked,noinline)) kbd_p2_f_my() {
534 asm volatile(
535 " push.w {r4-r8,lr}\n"
536 " ldr r6, =0x520ec\n"
537 " sub sp, sp, #0x18\n"
538 " add r7, sp, #8\n"
539 " subs r6, #0xc\n"
540 " b loc_fc083956\n"
541 " loc_fc083922:\n"
542 " ldr r1, =0x520ec\n"
543 " add r3, sp, #0x8\n"
544 " ldrb.w r0, [sp,#0x4]\n"
545 " add r2, sp, #0x14\n"
546 " subs r1, #0x18\n"
547 " bl sub_fc075420\n"
548 " cbnz r0, loc_fc08393c\n"
549 " ldr r1, [sp,#0x14]\n"
550 " movs r0, #0\n"
551 " bl sub_fc083886\n"
552 " loc_fc08393c:\n"
553 " movs r0, #2\n"
554 " loc_fc08393e:\n"
555 " ldr.w r1, [r7,r0,lsl#2]\n"
556 " cbz r1, loc_fc08394e\n"
557 " ldr.w r2, [r6,r0,lsl#2]\n"
558 " bics r2, r1\n"
559 " str.w r2, [r6,r0,lsl#2]\n"
560 " loc_fc08394e:\n"
561 " subs r0, r0, #1\n"
562 " sxtb r0, r0\n"
563 " cmp r0, #0\n"
564 " bge loc_fc08393e\n"
565 " loc_fc083956:\n"
566 " ldr r0, =0x520ec\n"
567 " add r1, sp, #0x4\n"
568 " subs r0, #0xc\n"
569 " bl sub_fc0750d2\n"
570 " cmp r0, #0\n"
571 " bne loc_fc083922\n"
572 " ldr.w r8, =0x520ec\n"
573 " movs r4, #0\n"
574 " loc_fc08396a:\n"
575 " movs r5, #0\n"
576 " ldr.w r0, [r6,r4,lsl#2]\n"
577 " ldr.w r1, [r8,r4,lsl#2]\n"
578 " ands r0, r1\n"
579 " str.w r0, [r6,r4,lsl#2]\n"
580 " b loc_fc0839c2\n"
581 " loc_fc08397c:\n"
582 " lsrs r0, r5\n"
583 " lsls r0, r0, #0x1f\n"
584 " beq loc_fc0839ba\n"
585 " ldr r1, =0x520ec\n"
586 " add.w r0, r5, r4,lsl#5\n"
587 " add r3, sp, #0x8\n"
588 " subs r1, #0x18\n"
589 " add r2, sp, #0x14\n"
590 " uxtb r0, r0\n"
591 " bl sub_fc075420\n"
592 " cbnz r0, loc_fc08399e\n"
593 " ldr r1, [sp,#0x14]\n"
594 " movs r0, #1\n"
595 " bl sub_fc083886\n"
596 " loc_fc08399e:\n"
597 " mov r0, r4\n"
598 " b loc_fc0839b6\n"
599 " loc_fc0839a2:\n"
600 " ldr.w r1, [r7,r0,lsl#2]\n"
601 " cbz r1, loc_fc0839b2\n"
602 " ldr.w r2, [r6,r0,lsl#2]\n"
603 " bics r2, r1\n"
604 " str.w r2, [r6,r0,lsl#2]\n"
605 " loc_fc0839b2:\n"
606 " adds r0, r0, #1\n"
607 " sxtb r0, r0\n"
608 " loc_fc0839b6:\n"
609 " cmp r0, #3\n"
610 " blt loc_fc0839a2\n"
611 " loc_fc0839ba:\n"
612 " ldr.w r0, [r6,r4,lsl#2]\n"
613 " adds r5, r5, #1\n"
614 " uxtb r5, r5\n"
615 " loc_fc0839c2:\n"
616 " cmp r0, #0\n"
617 " bne loc_fc08397c\n"
618 " adds r4, r4, #1\n"
619 " sxtb r4, r4\n"
620 " cmp r4, #3\n"
621 " blt loc_fc08396a\n"
622 " bl sub_fc074e8a_my\n"
623 " add sp, sp, #0x18\n"
624 " pop.w {r4-r8,pc}\n"
625 ".ltorg\n"
626 );
627 }
628
629 void __attribute__((naked,noinline)) sub_fc074e8a_my() {
630 asm volatile(
631 " push {r4,lr}\n"
632 " ldr r4, =0x9e6c\n"
633 " ldr r0, [r4,#0x10]\n"
634 " bl sub_fc0765e4\n"
635 " ldr r0, [r4,#0x14]\n"
636 " bl sub_fc07666e\n"
637 " bl sub_fc0766f6\n"
638 " bl sub_fc17b378\n"
639 " ldr r0, [r4,#0x18]\n"
640 " bl sub_fc076500\n"
641 " ldr r0, [r4,#0x1C]\n"
642 " bl sub_fc076500\n"
643
644
645
646 " bl handle_jogdial\n"
647 " cmp r0, #0\n"
648 " beq no_scroll\n"
649 " b.w sub_fc076948\n"
650 "no_scroll:\n"
651 " pop {r4, pc}\n"
652 );
653 }
654
655
656 long __attribute__((naked,noinline)) wrap_kbd_p1_f() {
657
658 asm volatile(
659 " push {r1-r7,lr}\n"
660 " movs r4, #0\n"
661 " bl my_kbd_read_keys\n"
662 " kbd_p1_f_cont:\n"
663 " ldr r3, =physw_status\n"
664 " movs r0, #2\n"
665 " mov r5, sp\n"
666 " add.w r6, r3, #0x24\n"
667 " loc_fc083ebe:\n"
668 " add.w r1, r6, r0,lsl#2\n"
669 " ldr.w r2, [r3,r0,lsl#2]\n"
670 " ldr r7, [r1,#0xc]\n"
671 " ldr r1, [r1,#0x18]\n"
672 " and.w r2, r2, r7\n"
673 " eor.w r2, r2, r1\n"
674 " str.w r2, [r5,r0,lsl#2]\n"
675 " subs r0, r0, #1\n"
676 " bpl loc_fc083ebe\n"
677 " ldr r2, =physw_status\n"
678 " mov r0, sp\n"
679 " adds r2, #0x18\n"
680 " sub.w r1, r2, #0xc\n"
681 " bl sub_fc0839d8_my\n"
682 " ldr r0, =physw_status\n"
683 " adds r0, #0xc\n"
684 " bl sub_fc074e34\n"
685 " cmp r0, #1\n"
686 " bne loc_fc083ef6\n"
687 " movs r4, #1\n"
688 " loc_fc083ef6:\n"
689 " ldr r2, =physw_status\n"
690 " movs r0, #2\n"
691 " adds r2, #0x18\n"
692 " sub.w r3, r2, #0xc\n"
693 " loc_fc083f00:\n"
694 " ldr.w r1, [r2,r0,lsl#2]\n"
695 " cbz r1, loc_fc083f1a\n"
696 " ldr.w r4, [r3,r0,lsl#2]\n"
697 " ldr.w r6, [r5,r0,lsl#2]\n"
698 " bics r4, r1\n"
699 " ands r1, r6\n"
700 " orrs r4, r1\n"
701 " str.w r4, [r3,r0,lsl#2]\n"
702 " movs r4, #1\n"
703 " loc_fc083f1a:\n"
704 " subs r0, r0, #1\n"
705 " bpl loc_fc083f00\n"
706 " mov r0, r4\n"
707 " pop {r1-r7,pc}\n"
708 ".ltorg\n"
709 );
710 return 0;
711 }
712
713 void __attribute__((naked,noinline)) sub_fc0839d8_my() {
714 asm volatile(
715 " push.w {r0-r12,lr}\n"
716 " ldr r7, =0x520ec\n"
717 " mov r5, r0\n"
718 " mov.w r0, #0xffffffff\n"
719 " mov r9, r1\n"
720 " str r0, [sp]\n"
721 " movs r0, #2\n"
722 " adds r7, #0x24\n"
723 " mov r6, r2\n"
724 " loc_fc0839ee:\n"
725 " ldr.w r1, [r5,r0,lsl#2]\n"
726 " ldr.w r2, [r9,r0,lsl#2]\n"
727 " eors r1, r2\n"
728 " add.w r2, r7, r0,lsl#2\n"
729 " ldr.w r2, [r2,#0xc0]\n"
730 " ands r1, r2\n"
731 " str.w r1, [r6,r0,lsl#2]\n"
732 " subs r0, r0, #1\n"
733 " sxtb r0, r0\n"
734 " cmp r0, #0\n"
735 " bge loc_fc0839ee\n"
736 " movs r0, #2\n"
737 " loc_fc083a10:\n"
738 " ldrh r1, [r7,#0x30]\n"
739 " add.w r1, r1, r1,lsl#1\n"
740 " ldr.w r2, [r5,r0,lsl#2]\n"
741 " add.w r1, r7, r1,lsl#2\n"
742 " add.w r1, r1, r0,lsl#2\n"
743 " subs r0, r0, #1\n"
744 " sxtb r0, r0\n"
745 " cmp r0, #0\n"
746 " str r2, [r1,#0xc]\n"
747 " bge loc_fc083a10\n"
748 " ldrh r0, [r7,#0x30]\n"
749 " mov.w r12, #0\n"
750 " adds r0, r0, #1\n"
751 " cmp r0, #3\n"
752 " bcc loc_fc083a3e\n"
753 " strh.w r12, [r7,#0x30]\n"
754 " b loc_fc083a40\n"
755 " loc_fc083a3e:\n"
756 " strh r0, [r7,#0x30]\n"
757 " loc_fc083a40:\n"
758 " movs r0, #2\n"
759 " loc_fc083a42:\n"
760 " movs r2, #0\n"
761 " mov r1, r2\n"
762 " loc_fc083a46:\n"
763 " add.w r3, r1, r1,lsl#1\n"
764 " adds r1, r1, #1\n"
765 " add.w r3, r7, r3,lsl#2\n"
766 " add.w r3, r3, r0,lsl#2\n"
767 " sxtb r1, r1\n"
768 " ldr r4, [r3,#0xc]\n"
769 " ldr r3, [r3,#0x18]\n"
770 " eors r4, r3\n"
771 " orrs r2, r4\n"
772 " cmp r1, #2\n"
773 " blt loc_fc083a46\n"
774 " ldr.w r1, [r5,r0,lsl#2]\n"
775 " ldr.w r3, [r9,r0,lsl#2]\n"
776 " eors r1, r3\n"
777 " bics r1, r2\n"
778 " ldr.w r2, [r7,r0,lsl#2]\n"
779 " ands r1, r2\n"
780 " ldr.w r2, [r6,r0,lsl#2]\n"
781 " orrs r1, r2\n"
782 " str.w r1, [r6,r0,lsl#2]\n"
783 " subs r0, r0, #1\n"
784 " sxtb r0, r0\n"
785 " cmp r0, #0\n"
786 " bge loc_fc083a42\n"
787 " add.w r10, sp, #4\n"
788 " mov.w r8, #4\n"
789 " mov r11, r12\n"
790 " loc_fc083a90:\n"
791 " ldr r3, =0x520ec\n"
792 " movs r1, #0\n"
793 " mov r12, r10\n"
794 " movs r0, #2\n"
795 " rsb.w r2, r8, r8,lsl#3\n"
796 " adds r3, #0x24\n"
797 " add.w r4, r3, r2,lsl#2\n"
798 " loc_fc083aa2:\n"
799 " mov r10, r12\n"
800 " add.w r2, r4, r0,lsl#2\n"
801 " str.w r11, [r12,r0,lsl#2]\n"
802 " ldr r2, [r2,#0x38]\n"
803 " cbz r2, loc_fc083ac2\n"
804 " ldr.w r3, [r9,r0,lsl#2]\n"
805 " ldr.w r7, [r5,r0,lsl#2]\n"
806 " eors r3, r7\n"
807 " ands r3, r2\n"
808 " orrs r1, r3\n"
809 " str.w r3, [r10,r0,lsl#2]\n"
810 " loc_fc083ac2:\n"
811 " subs r0, r0, #1\n"
812 " sxtb r0, r0\n"
813 " cmp r0, #0\n"
814 " bge loc_fc083aa2\n"
815 " cbnz r1, loc_fc083ad2\n"
816 " strb.w r11, [r4,#0x36]\n"
817 " b loc_fc083b86\n"
818 " loc_fc083ad2:\n"
819 " ldrb.w r0, [r4,#0x36]\n"
820 " cbz r0, loc_fc083afa\n"
821 " movs r0, #2\n"
822 " loc_fc083ada:\n"
823 " add.w r1, r4, r0,lsl#2\n"
824 " ldr.w r3, [r5,r0,lsl#2]\n"
825 " ldr r2, [r1,#0x44]\n"
826 " ldr r1, [r1,#0x38]\n"
827 " eors r2, r3\n"
828 " tst r2, r1\n"
829 " beq loc_fc083af2\n"
830 " strb.w r11, [r4,#0x36]\n"
831 " b loc_fc083afa\n"
832 " loc_fc083af2:\n"
833 " subs r0, r0, #1\n"
834 " sxtb r0, r0\n"
835 " cmp r0, #0\n"
836 " bge loc_fc083ada\n"
837 " loc_fc083afa:\n"
838 " add.w r4, r4, #0x34\n"
839 " ldrb r0, [r4,#2]\n"
840 " add.w r0, r0, #1\n"
841 " strb r0, [r4,#2]\n"
842 " ldrb.w r0, [r4],#-0x34\n"
843 " lsls r0, r0, #0x18\n"
844 " bpl loc_fc083b34\n"
845 " ldr r0, [r5]\n"
846 " ldr r1, [r4,#0x38]\n"
847 " ldr r2, [r4,#0x3c]\n"
848 " ands r0, r1\n"
849 " ldr r1, [r5,#4]\n"
850 " ands r1, r2\n"
851 " ldr r2, [r4,#0x40]\n"
852 " orrs r0, r1\n"
853 " ldr r1, [r5,#8]\n"
854 " ands r1, r2\n"
855 " orrs r0, r1\n"
856 " ldrb.w r0, [r4,#0x35]\n"
857 " beq loc_fc083b2e\n"
858 " lsrs r7, r0, #4\n"
859 " b loc_fc083b38\n"
860 " loc_fc083b2e:\n"
861 " and.w r7, r0, #0xf\n"
862 " b loc_fc083b38\n"
863 " loc_fc083b34:\n"
864 " ldrsb.w r7, [r4,#0x35]\n"
865 " loc_fc083b38:\n"
866 " cmp r7, #1\n"
867 " bne loc_fc083b4a\n"
868 " ldr r2, =0x520ec\n"
869 " add.w r3, r4, #0x34\n"
870 " mov r1, r5\n"
871 " mov r0, sp\n"
872 " bl sub_fc07507e_my\n"
873 " loc_fc083b4a:\n"
874 " ldrb.w r0, [r4,#0x36]\n"
875 " cmp r0, r7\n"
876 " blt loc_fc083b72\n"
877 " movs r0, #2\n"
878 " mov r2, r10\n"
879 " loc_fc083b56:\n"
880 " ldr.w r1, [r2,r0,lsl#2]\n"
881 " cbz r1, loc_fc083b66\n"
882 " ldr.w r3, [r6,r0,lsl#2]\n"
883 " orrs r3, r1\n"
884 " str.w r3, [r6,r0,lsl#2]\n"
885 " loc_fc083b66:\n"
886 " subs r0, r0, #1\n"
887 " sxtb r0, r0\n"
888 " cmp r0, #0\n"
889 " bge loc_fc083b56\n"
890 " strb.w r11, [r4,#0x36]\n"
891 " loc_fc083b72:\n"
892 " movs r0, #2\n"
893 " loc_fc083b74:\n"
894 " add.w r2, r4, r0,lsl#2\n"
895 " ldr.w r1, [r5,r0,lsl#2]\n"
896 " subs r0, r0, #1\n"
897 " sxtb r0, r0\n"
898 " cmp r0, #0\n"
899 " str r1, [r2,#0x44]\n"
900 " bge loc_fc083b74\n"
901 " loc_fc083b86:\n"
902 " sub.w r0, r8, #1\n"
903 " sxtb.w r8, r0\n"
904 " cmp.w r8, #0\n"
905 " bge.w loc_fc083a90\n"
906 " pop.w {r0-r12,pc}\n"
907 ".ltorg\n"
908 );
909 }
910
911
912 void __attribute__((naked,noinline)) sub_fc07507e_my() {
913
914 extern long kbd_mod_state[];
915 (void)kbd_mod_state;
916 asm volatile(
917 " push {r4-r8,lr}\n"
918 " ldr r4, [r0]\n"
919 " adds r4, r4, #1\n"
920 " bne loc_fc075090\n"
921 " ldr r4, =0xd20bf4a0\n"
922 " ldr r4, [r4]\n"
923 " ldr r5, =0x43ff9\n"
924 "ldr r8, =kbd_mod_state\n"
925 "ldr r8, [r8,#4]\n"
926 "ands r4, r8\n"
927 " ands r4, r5\n"
928 " str r4, [r0]\n"
929 " loc_fc075090:\n"
930 " movs r4, #2\n"
931 " loc_fc075092:\n"
932 " add.w r5, r3, r4,lsl#2\n"
933 " ldr r5, [r5,#4]\n"
934 " cbnz r5, loc_fc07509e\n"
935 " subs r4, r4, #1\n"
936 " bpl loc_fc075092\n"
937 " loc_fc07509e:\n"
938 " ldr r5, [r0]\n"
939 " add.w r0, r2, r4,lsl#2\n"
940 " add.w r7, r3, r4,lsl#2\n"
941 " ldr r2, [r0,#0xc]\n"
942 " ldr r0, [r0,#0x18]\n"
943 " ands r5, r2\n"
944 " ldr.w r2, [r1,r4,lsl#2]\n"
945 " eors r5, r0\n"
946 " ldr r0, [r7,#4]\n"
947 " ands r5, r0\n"
948 " and.w r6, r2, r0\n"
949 " cmp r6, r5\n"
950 " beq locret_fc0750d0\n"
951 " ldr r5, [r7,#0x10]\n"
952 " bics r2, r0\n"
953 " ands r5, r0\n"
954 " orrs r2, r5\n"
955 " str.w r2, [r1,r4,lsl#2]\n"
956 " movs r0, #0\n"
957 " strb r0, [r3,#2]\n"
958 " locret_fc0750d0:\n"
959 " pop {r4-r8,pc}\n"
960 ".ltorg\n"
961 );
962 }
963
964 void agent_orange(){
965 *(int*)0xd20b0810 = 0x4d0002;
966 }
967