S12v4 smart dispatcher baked
This commit is contained in:
+9
-7
@@ -385,14 +385,16 @@ def main():
|
||||
# to the dispatcher via stale lr (TZ bringup deferred).
|
||||
# NOTE: overwrites 4B of real ARM trampoline (recoverable from ELF).
|
||||
mu.mem_write(0x00221EF8, bytes([0x00, 0x20, 0x70, 0x47]))
|
||||
# S12-stub (b25): blx #0x8006964 (BLX-imm to even => ARM mode!) lands
|
||||
# in file-zero padding (PBL would place an ARM helper). ARM version:
|
||||
# ldr ip,[sp,#4] (=pushed lr, for the B66 bx-ip chain); ldr r3,[pc]
|
||||
# (literal [0x8006980] = 0x073A100); ACK peripheral bit1 (the real
|
||||
# helper's side effect that poll#2 waits for); bx lr.
|
||||
# S12-stub (b27, 84B @0x08006964, ARM): blx-to-padding becomes
|
||||
# smart dispatcher: ldr ip,[sp,#4] (=pushed lr); ip==STUBV/even/
|
||||
# non-code => ip=poll resumption 0x8007779; else keep pushed-lr;
|
||||
# then ACK peripheral bit1 ([literal 0x073A100]); bx lr.
|
||||
# PBL would place the real ARM helper here.
|
||||
mu.mem_write(0x08006964, bytes.fromhex(
|
||||
"04c09de50c309fe5002093e5022082e3002083e51eff2fe1"
|
||||
"00a17300"))
|
||||
"04c09de58d3b06e3003840e303005ce10700000a0100"
|
||||
"1ce30500000a2c3ca0e1080053e30400000a2c3ea0e1"
|
||||
"080053e30100000a79c707e300c840e30c309fe50020"
|
||||
"93e5022082e3002083e51eff2fe100a17300"))
|
||||
# S16-stublet (b27, 64B @0x08006CC0): smart return for B66 bx ip.
|
||||
# ip==STUBV (fill/maze, never a legit return) => default;
|
||||
# ip odd + top 8 (code) => add sp,#8 (pop the helper frame B66
|
||||
|
||||
Reference in New Issue
Block a user