b24 scaffold: S12 + poll-bit2 baked, default b24
This commit is contained in:
@@ -103,3 +103,7 @@
|
||||
- Дальше: clock-fn `0x800E960` (udiv-подсчёты) с голым выходом
|
||||
`pop{r4,pc}` (без push, tail-chain через NOP-идиому) → S11 (b24):
|
||||
вход → `bx lr` (lr = брошенный-но-валидный `0x80076CD`).
|
||||
- Poll `[0x73A100]` (lsls#29+bpl = проверка bit2!): SBL только читает →
|
||||
фабрикация bit2=1 (b24 scaffold, обе стороны).
|
||||
- `blx #0x8006964` в файловые нули паддинга (PBL scratch) → S12 (b24
|
||||
scaffold, без ELF): `bx lr` (caller игнорирует r0).
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
set -e
|
||||
cd "$(dirname "$0")/.."
|
||||
QEMU=~/qemu-src/qemu-8.2.2/build/qemu-system-arm
|
||||
B=${1:-b23}
|
||||
B=${1:-b24}
|
||||
IMG=fw/img/emmc-real.img
|
||||
if [ ! -f "$IMG" ]; then
|
||||
echo "no $IMG — сначала: python3 tools/ffu_extract.py fw/dl/RM1127_059X5R5_orig.ffu --emmc-user fw/img/user-real.bin"
|
||||
|
||||
@@ -698,6 +698,11 @@ static void saimaa_machine_init(MachineState *machine)
|
||||
uint32_t v = 0x08006B8D;
|
||||
cpu_physical_memory_write(0x080528D0, &v, 4);
|
||||
}
|
||||
/* HW-ready bit (b25): [0x073A100] bit2 (SBL read-only poll). */
|
||||
{
|
||||
uint32_t v = 0x00000004;
|
||||
cpu_physical_memory_write(0x073A100, &v, 4);
|
||||
}
|
||||
/* PBL world-switch Thumb-stub (b24, 4B @0x00221EF8):
|
||||
* movs r0,#0; bx lr (return 0 to dispatcher, TZ deferred).
|
||||
* Overwrites ARM trampoline head (recoverable from ELF). */
|
||||
@@ -705,6 +710,12 @@ static void saimaa_machine_init(MachineState *machine)
|
||||
uint32_t v = 0x47702000;
|
||||
cpu_physical_memory_write(0x00221EF8, &v, 4);
|
||||
}
|
||||
/* S12-stub (b25, 2B @0x08006964): blx-to-padding becomes
|
||||
* bx lr (caller ignores r0). PBL would place ARM helper. */
|
||||
{
|
||||
uint16_t v = 0x4770;
|
||||
cpu_physical_memory_write(0x08006964, &v, 2);
|
||||
}
|
||||
{
|
||||
uint32_t fill = 0x08006B8D;
|
||||
uint32_t a;
|
||||
|
||||
@@ -335,12 +335,20 @@ def main():
|
||||
# PBL version-table fabrication (b23): [0x080528D0] = STUBV so the
|
||||
# rollback query's blx calls maze (returns 0 = versions OK).
|
||||
W32(0x080528D0, STUBV)
|
||||
# HW-ready bit fabrication (b25): [0x073A100] bit2 = peripheral
|
||||
# status done-bit (SBL only reads it, never writes; HW would set it).
|
||||
# Poll is lsls#29+bpl (checks bit2, NOT bit31!).
|
||||
W32(0x073A100, 0x00000004)
|
||||
# PBL world-switch Thumb-stub (b24): the ARM trampoline at 0x221EF8
|
||||
# is entered in Thumb (mode confusion at dispatch); real ARM would
|
||||
# save regs/CPS to MON and call TZ (not loaded yet). Stub returns 0
|
||||
# to the dispatcher via stale lr (TZ bringup deferred).
|
||||
# NOTE: overwrites 4B of real ARM trampoline (recoverable from ELF).
|
||||
mu.mem_write(0x00221EF8, bytes([0x00, 0x20, 0x70, 0x47]))
|
||||
# S12-stub (b25): blx #0x8006964 lands in file-zero padding (PBL
|
||||
# would place an ARM helper there at runtime). Caller ignores r0
|
||||
# (movs r0,#0 after), so bx lr no-op return is safe.
|
||||
mu.mem_write(0x08006964, bytes([0x70, 0x47]))
|
||||
# stack zone fill (STUBV odd)
|
||||
mu.mem_write(0x085F0000, struct.pack("<I", STUBV) * (0x10000 // 4))
|
||||
# pop-site slots (sp values from traces)
|
||||
|
||||
Reference in New Issue
Block a user