qemu-arm projects/CYW20819A1/gen/execute.exe does now run until thread switch (since thread symbols are still wrong)
This commit is contained in:
+22
-1
@@ -248,11 +248,32 @@ arm-none-eabi-ld: cannot find gen/internalBlue_11.07.2019_13.52.37/Segment_0x420
|
||||
make: *** [Makefile:28: gen/execute.exe] Error 1
|
||||
```
|
||||
|
||||
Happens due to executing as root to access hci0 on Linux:
|
||||
Happens due to executing as root to access hci0 on Linux, we need to change permissions on this file:
|
||||
```
|
||||
'./segment_groups/internalBlue_11.07.2019_13.52.37': Permission denied
|
||||
```
|
||||
|
||||
Afterwards, the following registers are missing:
|
||||
|
||||
```
|
||||
dc_nbtc_clk = 0x00318088;
|
||||
dc_x_clk = 0x003186ac;
|
||||
pcx_btclk = 0x0031822c;
|
||||
pcx2_btclk = 0x0031823c;
|
||||
pcx2_pbtclk = 0x00318238;
|
||||
phy_status = 0x00314004;
|
||||
pkt_hdr_status = 0x00318b28;
|
||||
pkt_log = 0x00318b2c;
|
||||
rtx_dma_ctl = 0x00314018;
|
||||
rtx_mem_start1 = 0x00370400;
|
||||
rtx_rx_buffer = 0x00370c00;
|
||||
sr_status = 0x0031400c;
|
||||
sr_ptu_status_adr4 = 0x00360084;
|
||||
tx_pkt_info = 0x00318acc;
|
||||
tx_pkt_pyld_hdr = 0x00318ad0;
|
||||
```
|
||||
|
||||
|
||||
Debugging notes
|
||||
---------------
|
||||
|
||||
|
||||
@@ -0,0 +1,407 @@
|
||||
#ifndef BCS_H
|
||||
#define BCS_H
|
||||
|
||||
|
||||
#define HW_PHY_STATUS_RX_DONE 0x0001
|
||||
#define HW_PHY_STATUS_RX_HEADER_DONE 0x0002
|
||||
#define HW_PHY_STATUS_TX_DONE 0x0004
|
||||
#define HW_PHY_STATUS_PROG_INT0 0x0008 //Slot11 + Timer + bcs_kernel
|
||||
#define HW_PHY_STATUS_PROG_INT1 0x0010 //Slot01
|
||||
#define HW_PHY_STATUS_PROG_INT2 0x0020
|
||||
#define HW_PHY_STATUS_PROG_INT3 0x0040
|
||||
#define HW_PHY_STATUS_WCS_COEX_INT 0x0100
|
||||
#define HW_PHY_STATUS_WCS_COEX_DEFERRED 0x0200
|
||||
#define HW_PHY_STATUS_PROG_INT_ALL 0x0078
|
||||
|
||||
|
||||
extern char* dmaActiveRxBuffer;
|
||||
char *tx_dma_data;
|
||||
int tx_dma_len;
|
||||
|
||||
|
||||
int wait_for_ack = 1;
|
||||
void bcs_dma_hook(struct saved_regs *regs, void *arg) {
|
||||
int data, len;
|
||||
if ((int)arg & 2) {
|
||||
print("Eir ");
|
||||
data = regs->r0;
|
||||
len = regs->r1;
|
||||
}
|
||||
else {
|
||||
data = *(uint32_t *)(regs->r0 + 16);
|
||||
len = (*(uint32_t *)(regs->r0 + 10) >> 3 & 0x3ff);
|
||||
}
|
||||
if ((int)arg & 1) print ("Tx: ")
|
||||
else {
|
||||
/*
|
||||
print("Rx: ");
|
||||
print_ptr(data);
|
||||
print(" | ");
|
||||
print_ptr(len);
|
||||
print("\n");
|
||||
*/
|
||||
return;
|
||||
}
|
||||
|
||||
/*
|
||||
hexdump(&pc_acscd_lo, 4);
|
||||
hexdump(&pc_acscd_hi, 4);
|
||||
print(" | ");
|
||||
*/
|
||||
hexdump(&tx_pkt_info, 4);
|
||||
print(" | ");
|
||||
hexdump(&tx_pkt_pyld_hdr, 2);
|
||||
print(" | ");
|
||||
hexdump(data, len);
|
||||
print("\n");
|
||||
tx_dma_len = len;
|
||||
tx_dma_data = data;
|
||||
|
||||
wait_for_ack = 1;
|
||||
|
||||
/*
|
||||
Rx Test
|
||||
*/
|
||||
}
|
||||
|
||||
#ifdef EMULATED
|
||||
void clear_phy_status(struct saved_regs *regs, void *arg) {
|
||||
int intmask = regs->r0;
|
||||
if (intmask & 0x7800) phy_status &= ~((intmask>>8) & 0x78);
|
||||
if (intmask & 0x400000) phy_status &= ~HW_PHY_STATUS_RX_HEADER_DONE;
|
||||
if (intmask & 0x400) phy_status &= ~HW_PHY_STATUS_RX_DONE;
|
||||
if (intmask & 1) phy_status &= ~HW_PHY_STATUS_TX_DONE;
|
||||
if (intmask & 0xe) sr_status &= ~((intmask>>1) & 0x7);
|
||||
}
|
||||
|
||||
#endif
|
||||
|
||||
void print_bcs_list_entry(uint32_t *current) {
|
||||
print("-----------------------------------\n");
|
||||
print_var(current);
|
||||
print_var(current[-1]);
|
||||
print_var(current[0]); //next
|
||||
print_var(current[1]); //prev
|
||||
print_var(current[2]);
|
||||
print_var(current[3]);
|
||||
print_var(current[4]);
|
||||
print_var(current[5]); //end of struct?
|
||||
print_var(((char*)current)[0x10]);
|
||||
print_var(((char*)current)[0x11]);
|
||||
}
|
||||
|
||||
extern int eci_status;
|
||||
extern int eci_status_b;
|
||||
void bcs_info() {
|
||||
uint32_t *current;
|
||||
if (tb) {
|
||||
print_var(tb);
|
||||
print_var(bcs_taskGetTaskType(tb));
|
||||
}
|
||||
|
||||
//print_var(eci_status);
|
||||
//print_var(eci_status_b);
|
||||
//print_var(rtx_dma_ctl);
|
||||
print_var(dlist_count(taskTimerList));
|
||||
print_var(dlist_count(taskTransientStateList));
|
||||
print_var(dlist_count(taskReadyList));
|
||||
print_var(dlist_count(taskActiveList));
|
||||
print_var(dlist_count(slotCbEntryList));
|
||||
|
||||
print("-----------------------------------\n");
|
||||
print("current_task\n");
|
||||
print_bcs_list_entry(tb);
|
||||
|
||||
print("-----------------------------------\n");
|
||||
print("active_list\n");
|
||||
for (current = (uint32_t*) taskActiveList; current != &taskActiveList; current = current[0])
|
||||
print_bcs_list_entry(current);
|
||||
|
||||
print("-----------------------------------\n");
|
||||
print("taskTransientStateList\n");
|
||||
for (current = (uint32_t*) taskTransientStateList; current != &taskTransientStateList; current = current[0])
|
||||
print_bcs_list_entry(current);
|
||||
|
||||
print("-----------------------------------\n");
|
||||
print("taskReadyList\n");
|
||||
for (current = (uint32_t*) taskReadyList; current != &taskReadyList; current = current[0])
|
||||
print_bcs_list_entry(current);
|
||||
|
||||
|
||||
print("-----------------------------------\n");
|
||||
print("timer\n")
|
||||
current = (uint32_t*) taskTimerList;
|
||||
while (current != &taskTimerList) {
|
||||
print("-----------------------------------\n");
|
||||
print_var(current);
|
||||
print_var(current[-2]);
|
||||
print_var(current[-1]);
|
||||
print_var(current[0]); //next
|
||||
print_var(current[1]); //prev
|
||||
print_var(current[2]);
|
||||
print_var(current[3]);
|
||||
print_var(current[4]);
|
||||
print_var(current[5]);
|
||||
print_var(current[6]);
|
||||
print_var(current[7]);
|
||||
print_var(current[8]);
|
||||
print_var(current[9]); //maybe callback
|
||||
print_var(current[10]);
|
||||
print_var(current[11]);
|
||||
print_var(current[12]);
|
||||
print_var(current[13]);
|
||||
|
||||
current = current[0];
|
||||
|
||||
}
|
||||
|
||||
print("-----------------------------------\n");
|
||||
print("slotcb\n")
|
||||
current = (uint32_t*) slotCbEntryList;
|
||||
while (current != &slotCbEntryList) {
|
||||
print("-----------------------------------\n");
|
||||
print_var(current);
|
||||
print_var(current[-1]);
|
||||
print_var(current[0]);
|
||||
print_var(current[1]);
|
||||
print_var(current[2]);
|
||||
print_var(current[3]);
|
||||
print_var(current[4]);
|
||||
print_var(current[5]);
|
||||
print_var(current[6]);
|
||||
current = current[0];
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
/*
|
||||
Advance bt clock by one tick (312.5 us)
|
||||
*/
|
||||
|
||||
extern int pcx2_pbtclk;
|
||||
extern int pcx2_btclk;
|
||||
extern int dc_nbtc_pclk;
|
||||
|
||||
void bcs_advance_clock() {
|
||||
pcx_btclk ++; //*(int*) (0x31822c) += 1;
|
||||
pcx2_pbtclk ++;
|
||||
pcx2_btclk ++;
|
||||
dc_nbtc_clk ++; //*(int*) (0x318088) += 1;
|
||||
dc_x_clk ++;
|
||||
//dc_nbtc_pclk ++;
|
||||
}
|
||||
|
||||
|
||||
|
||||
/*
|
||||
Dummy task performing random actions
|
||||
*/
|
||||
void bcs_dummy() {
|
||||
read(0, 0x370000, 16);
|
||||
read(0, &sr_status, 2);
|
||||
read(0, &phy_status, 2);
|
||||
read(0, &pkt_hdr_status, 2);
|
||||
read(0, &pkt_log, 2);
|
||||
pkt_hdr_status |= 0x40000;
|
||||
pkt_log |= 0x40000;
|
||||
|
||||
print_var(pkt_hdr_status);
|
||||
print_var(pkt_log);
|
||||
print_var(phy_status);
|
||||
print_var(sr_status);
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
#include "bcs/inq.h"
|
||||
#include "bcs/acl.h"
|
||||
#include "bcs/page.h"
|
||||
#include "bcs/le.h"
|
||||
void bcs_tick() {
|
||||
/*
|
||||
srstatus
|
||||
1 = fsmdone
|
||||
0x10 = lcuSubstate Active
|
||||
|
||||
*/
|
||||
|
||||
bcs_advance_clock();
|
||||
|
||||
//bcs_info();
|
||||
if (tb == 0x2822e0) //TODO
|
||||
{ print("tb = pageScan\n"); pagescan(); }
|
||||
else if (tb == 0x20a9c8) //TODO
|
||||
{print("tb = page\n"); page(); }
|
||||
else if (tb == 0x282250) //TODO
|
||||
print("tb = inqScan\n")
|
||||
else if (tb == 0x20a8e8) //TODO
|
||||
{ print("tb = inq\n"); inquiry(); }
|
||||
else if (tb == 0x205914) //TODO
|
||||
{ print("tb = tca\n"); bcs_dummy(); }
|
||||
else if (tb == 0x281068) //TODO
|
||||
{ print("tb = acl\n"); acl(); }
|
||||
else if (tb == 0x22539c) //TODO
|
||||
{ print("tb = conntask?\n"); bcs_dummy(); }
|
||||
else if (tb == 0x28218c) //TODO
|
||||
{ print("tb = afhRssiScan\n");}
|
||||
|
||||
//LE
|
||||
else if (tb == 0x2828b0) //TODO
|
||||
{ print("tb = adv\n"); adv();}
|
||||
else if (tb == 0x283300) //TODO
|
||||
{ print("tb = bcsulp_scan\n"); le_scan();}
|
||||
else if (tb == 0x283278) //TODO
|
||||
{ print("tb = bcsulp_init\n"); le_scan();}//page_fd = 0; pagescan(); page_fd=-1;}
|
||||
else if (tb == 0x281618) //TODO
|
||||
{ print("tb = le_conn\n"); le_conn();}
|
||||
else
|
||||
print_var(tb);
|
||||
|
||||
|
||||
//Slot01 / Slot11
|
||||
if ((pcx_btclk & 3) == 0b01){
|
||||
print("Slot01\n");
|
||||
sr_status = (tb == 0x281068) ? 0x1d8 : 0x1c8;
|
||||
phy_status = 0x10;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
if ((pcx_btclk & 3) == 0b11){
|
||||
print("Slot11\n");
|
||||
sr_status = (tb == 0x281068) ? 0x1d8 : 0x1c8;
|
||||
phy_status = 0x68;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
void _dhmulp_getTxLcp();
|
||||
|
||||
|
||||
void bcs_add_hooks() {
|
||||
#ifdef EMULATED
|
||||
add_hook(intctl_ClrPendingInt, clear_phy_status, NULL, NULL);
|
||||
#endif
|
||||
|
||||
patch_return(btclk_DelayXus);
|
||||
patch_return(btclk_AdvanceNatClk_clkpclkHWWA);
|
||||
patch_return(0x0009b104); //TODO
|
||||
patch_return(0x0009b38a); //TODO
|
||||
patch_return(0x0009b35c); //TODO
|
||||
patch_return(0x9b414); //TODO
|
||||
patch_return(0x9b3da); //TODO
|
||||
patch_return(0x40cda); //TODO
|
||||
//patch_return(&_afhPipelineRssiScanTaskSlotInt);
|
||||
|
||||
trace(bcs_dmaGetRxBuffer, 3, false);
|
||||
trace(bcs_dmaRxEnableEir, 2, false);
|
||||
trace(bcs_dmaTxEnableEir, 2, false);
|
||||
trace(bcs_dmaRxEnable, 2, true);
|
||||
trace(bcs_dmaTxEnable, 1, false);
|
||||
trace(bcs_dmaRxDisable, 0, true);
|
||||
trace(bcs_dmaGetRxBuffer, 1, true);
|
||||
trace(bcs_utilBbRxPyldHdr, 2, true);
|
||||
trace(bcs_dmaRxBufferRecycle, 1, false);
|
||||
trace(btclk_AdvanceNatClk_clkpclkHWWA, 1, false);
|
||||
|
||||
trace(bcs_kernelTimerTick, 0, false); //called at 0x95693 0x40637
|
||||
trace(bcs_kernelRxHeaderDone, 0, false);
|
||||
trace(bcs_kernelRxDone, 0, false);
|
||||
trace(bcs_kernelSlotCbFunctions, 0, false);
|
||||
|
||||
//Called quite often, therefore disabled
|
||||
//trace(bcs_isrFsmDoneInt, 0, false);
|
||||
//trace(bcs_isrSlot01Int, 0, false);
|
||||
//trace(bcs_isrSlot11Int, 0, false);
|
||||
//trace(bcs_isrTxDoneInt, 0, false);
|
||||
//trace(bcs_isrRxDoneInt, 0, false);
|
||||
//trace(bcs_isrRxHeaderDoneInt, 0, false);
|
||||
|
||||
|
||||
trace(bcs_pageTaskCreate, 3, false);
|
||||
trace(dhmulp_LcpTx, 3, false);
|
||||
trace(DHM_TxDataAvail,0,false);
|
||||
trace(dhmulp_getTxBuffer, 3, false);
|
||||
trace(DHM_GetBasebandTxData, 2, false);
|
||||
trace(bcs_utilBbRxPktHdrCheck, 2, false);
|
||||
trace(DHM_ACLAckRcvd, 1, false);
|
||||
trace(DHM_SetAclTxPktAckRcvd, 1, false);
|
||||
trace(DHM_isTxLmpListEmpty, 1, true);
|
||||
trace(DHM_GetBasebandRxBuffer, 2, false);
|
||||
trace(DHM_releaseTxLmpList, 4, false);
|
||||
trace(_dhmSlotCbFunc, 1, false);
|
||||
|
||||
//acl
|
||||
trace(bcs_aclTaskCreate, 2, false);
|
||||
trace(_aclTaskSetupTxBuffer, 4, false);
|
||||
trace(_aclTaskRxHeaderDone, 1, false);
|
||||
trace(_aclTaskRxDone, 1, false);
|
||||
trace(_aclTaskLcuCmd, 1, false);
|
||||
trace(_aclTaskFsmSetup, 1, false);
|
||||
trace(_aclTaskProcessRxPacket, 1, false);
|
||||
trace(_aclTaskSwitch, 1, false);
|
||||
|
||||
//eir
|
||||
trace(eir_handleRx, 1, false);
|
||||
trace(eir_handleTx, 1, false);
|
||||
|
||||
trace(_inqTaskRxHeaderDone, 1, false);
|
||||
trace(_inqTaskRxDone, 1, false);
|
||||
|
||||
trace(_dmaReqSend, 1, false);
|
||||
trace(dma_RequestTransfer, 1, false);
|
||||
|
||||
add_hook(bcs_dmaRxEnable, bcs_dma_hook, NULL, 0);
|
||||
add_hook(bcs_dmaTxEnable, bcs_dma_hook, NULL, 1);
|
||||
add_hook(bcs_dmaRxEnableEir, bcs_dma_hook, NULL, 2);
|
||||
add_hook(bcs_dmaTxEnableEir, bcs_dma_hook, NULL, 3);
|
||||
trace(bcs_dmaIsTransferComplete, 2, false);
|
||||
|
||||
trace(_pageTaskFsmDone, 3, false);
|
||||
trace(_pageScanTaskFsmDone, 3, false);
|
||||
trace(bcs_newConnTaskCreate, 3, false);
|
||||
|
||||
//Methods are actually too short to set hooks
|
||||
//trace(bluerf_Wr, 2, false);
|
||||
//trace(bluerf_Rd, 1, true);
|
||||
trace(bpl_lcu_Cmd, 2, false);
|
||||
trace(bpl_lcu_setPHY, 4, false);
|
||||
trace(bcs_kernelBtProgIntEnable, 4, false);
|
||||
|
||||
trace(bcs_pageTaskCreate, 3, false);
|
||||
trace(bcs_pageScanTaskCreate, 3, false);
|
||||
trace(bcs_SlotCbFunctions, 0, false);
|
||||
|
||||
//LE
|
||||
trace(_advTaskRxDone, 3, false);
|
||||
trace(_scanTaskRxDone, 3, false);
|
||||
trace(bcsulp_passRxPktUp, 3, false);
|
||||
trace(bcsulp_procRxPayload, 2, false);
|
||||
trace(bcsulp_getPktLength, 2, true);
|
||||
trace(bcsulp_setupRxBuffer, 0, true);
|
||||
trace(bcsulp_returnRxBuffer, 0, false);
|
||||
trace(mmulp_allocACLUp, 1, true);
|
||||
trace(mmulp_allocACLDown, 1, true);
|
||||
trace(dhmulp_getRxBuffer, 1, true);
|
||||
//trace(_connTaskLcuCmd_addin, 3, true); //Does no longer exist in CYW20819A1
|
||||
trace(_connTaskLcuCmd, 3, true);
|
||||
trace(_connTaskSlotInt, 3, true);
|
||||
trace(mmulp_freeLEABuffer, 1, true);
|
||||
trace(dhmulp_returnRxBuffer, 1, false);
|
||||
trace(_dhmulp_getTxLcp, 2, true);
|
||||
|
||||
//Inquiry
|
||||
trace(eir_eirInqFHS, 1, false);
|
||||
trace(eir_getReceivedEIR, 1, false);
|
||||
trace(bthci_event_SendInquiryResultEvent, 1, false);
|
||||
trace(lm_sendInqFHS, 1, false);
|
||||
trace(lm_handleInqFHS, 1, false);
|
||||
trace(lc_handleInqResult, 1, false);
|
||||
trace(inqfilter_isBdAddrRegistered, 2, false);
|
||||
trace(inqfilter_registerBdAddr, 2, false);
|
||||
|
||||
}
|
||||
#endif
|
||||
@@ -0,0 +1,206 @@
|
||||
int acl_fd = 0;
|
||||
|
||||
#define ACL_ROLE_MASTER 0
|
||||
#define ACL_ROLE_SLAVE 1
|
||||
|
||||
int acl_role = ACL_ROLE_SLAVE; //the snapshot I've taken had an open acl slave connection
|
||||
|
||||
int injected = 0;
|
||||
|
||||
void acl() {
|
||||
if (acl_fd == -1) return;
|
||||
|
||||
if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b10 ) ||
|
||||
( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b00 ) ){
|
||||
|
||||
|
||||
print("Tx Done\n");
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x4;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
|
||||
print("TxDone: ");
|
||||
print_ptr(tx_pkt_info & 0xffff);
|
||||
print(" | ");
|
||||
print_ptr(tx_pkt_pyld_hdr & 0xffff);
|
||||
print(" | ");
|
||||
hexdump(tx_dma_data, tx_dma_len);
|
||||
print("\n");
|
||||
hexdump(rtx_mem_start1, 32);
|
||||
print("\n");
|
||||
|
||||
int pyld_hdr = tx_pkt_pyld_hdr << 2;
|
||||
write(acl_fd, &tx_pkt_info, 2);
|
||||
write(acl_fd, &pyld_hdr, 2);
|
||||
write(acl_fd, tx_dma_data, 512);
|
||||
print_var((tx_pkt_pyld_hdr >> 2) & 0x3ff)
|
||||
}
|
||||
|
||||
//Rx Hdr Int
|
||||
if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b00 ) ||
|
||||
( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b10 ) ){
|
||||
print("Rx Hdr Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x3;
|
||||
|
||||
pkt_hdr_status = pkt_log = 0;
|
||||
if ( read(acl_fd, &pkt_hdr_status, 2) == 0) exit(1);
|
||||
read(acl_fd, &pkt_log, 2);
|
||||
pkt_hdr_status |= 0x40000;
|
||||
pkt_log |= 0x40000;
|
||||
|
||||
//if (rtx_dma_ctl == 1) {
|
||||
// sr_status = 0x1d8;
|
||||
// phy_status = 0x2;
|
||||
|
||||
// ////Acknowledge Packet ACL Specific?
|
||||
// ////print_var(wait_for_ack)
|
||||
// //if (wait_for_ack) {
|
||||
// // wait_for_ack = 0;
|
||||
|
||||
// // pkt_hdr_status = tx_pkt_info | 0x40000;
|
||||
// // pkt_hdr_status |= 0x1 << 8; //ARQN
|
||||
// // pkt_hdr_status ^= 0x1 << 9; //SEQ
|
||||
|
||||
// // pkt_log = tx_pkt_pyld_hdr;
|
||||
// // pkt_log = pkt_log << 2;
|
||||
// // if (tx_pkt_pyld_hdr == 0x11a && (pcx_btclk & 0xff) == 0)
|
||||
// // pkt_log = pkt_log | 0x40000;
|
||||
// //}
|
||||
// ////ACL Inject packet
|
||||
// //else if(!injected) {
|
||||
// // pkt_hdr_status = 0x40000;
|
||||
// // pkt_hdr_status |= 0x0; //LT_ADDR
|
||||
// // pkt_hdr_status |= 0x3 << 3; //Type
|
||||
// // pkt_hdr_status |= 0x1 << 7; //Flow
|
||||
// // pkt_hdr_status |= 0x1 << 8; //ARQN
|
||||
// // pkt_hdr_status |= 0x1 << 9; //SEQ
|
||||
// // pkt_hdr_status |= 0xf00; //HEC
|
||||
// // pkt_log = 0x1f << 2 | 0x40000; //payload_hdr
|
||||
// // injected = 1;
|
||||
// //} else {
|
||||
// // injected --;
|
||||
// //}
|
||||
//}
|
||||
|
||||
|
||||
print_var(pkt_hdr_status);
|
||||
print_var(pkt_log);
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Interrupt
|
||||
//if(rtx_dma_ctl == 1 && (pcx_btclk & 3) == 0b01) {
|
||||
int len;
|
||||
//if((pcx_btclk & 3) == 0b01) {
|
||||
if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b01 ) ||
|
||||
( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b11 ) ){
|
||||
print("Rx Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x1;
|
||||
|
||||
//len = (pkt_log >> 5) & 0x1f;
|
||||
len = (pkt_log >> 5) & 0x3ff;
|
||||
len = 128;
|
||||
print_var(len);
|
||||
|
||||
if (rtx_dma_ctl != 3 && dmaActiveRxBuffer) {
|
||||
if (read(acl_fd, dmaActiveRxBuffer+4, len) < 1) exit(1);
|
||||
print_var(dmaActiveRxBuffer);
|
||||
//for (unsigned char i=0; i < 240; i++) dmaActiveRxBuffer[i] = i;
|
||||
print("pcktdata (DMA): ");
|
||||
hexdump(dmaActiveRxBuffer, len);
|
||||
print("\n");
|
||||
}
|
||||
else {
|
||||
print("pcktdata: ");
|
||||
read(acl_fd, 0x370000, len);
|
||||
hexdump(0x370000, len);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
void acl_over_tcp() {
|
||||
if (acl_fd == -1) return;
|
||||
|
||||
if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b10 ) ||
|
||||
( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b00 ) ){
|
||||
|
||||
print("Tx Done\n");
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x4;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
|
||||
print("TxDone: ");
|
||||
hexdump(&tx_pkt_info, 4);
|
||||
print(" | ");
|
||||
hexdump(&tx_pkt_pyld_hdr, 2);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
//Rx Hdr Int
|
||||
if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b00 ) ||
|
||||
( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b10 ) ){
|
||||
print("Rx Hdr Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x3;
|
||||
|
||||
if ( read(acl_fd, &pkt_hdr_status, 2) == 0) exit(1);
|
||||
read(acl_fd, &pkt_log, 2);
|
||||
pkt_hdr_status |= 0x40000;
|
||||
pkt_log |= 0x40000;
|
||||
|
||||
if (rtx_dma_ctl == 1) {
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x2;
|
||||
|
||||
}
|
||||
|
||||
print_var(pkt_hdr_status);
|
||||
print_var(pkt_log);
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Interrupt
|
||||
//if(rtx_dma_ctl == 1 && (pcx_btclk & 3) == 0b01) {
|
||||
int len;
|
||||
//if((pcx_btclk & 3) == 0b01) {
|
||||
if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b01 ) ||
|
||||
( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b11 ) ){
|
||||
print("Rx Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x1;
|
||||
|
||||
//len = (pkt_log >> 5) & 0x1f;
|
||||
len = (pkt_log >> 5) & 0x3ff;
|
||||
len = 128;
|
||||
|
||||
if (rtx_dma_ctl != 3 && dmaActiveRxBuffer) {
|
||||
if (read(0, dmaActiveRxBuffer, len) < 1) exit(1);
|
||||
print_var(dmaActiveRxBuffer);
|
||||
//for (unsigned char i=0; i < 240; i++) dmaActiveRxBuffer[i] = i;
|
||||
print("pcktdata: ");
|
||||
hexdump(dmaActiveRxBuffer, len);
|
||||
print("\n");
|
||||
}
|
||||
else {
|
||||
print("pcktdata: ");
|
||||
read(0, 0x370000, len);
|
||||
hexdump(0x370000, len);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
}
|
||||
*/
|
||||
@@ -0,0 +1,98 @@
|
||||
int inq_fd = 0;
|
||||
|
||||
int timeout = 10;
|
||||
void inquiry() {
|
||||
if (inq_fd == -1) return;
|
||||
|
||||
//hci_tx_fd = -1;
|
||||
//hci_rx_fd = -1;
|
||||
//xmit_state_emu("gen/inq.exe");
|
||||
//if (timeout-- < 0) exit(0);
|
||||
|
||||
|
||||
if ((pcx_btclk & 3) == 0b10){
|
||||
print("Tx Done\n");
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x4;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
if ((pcx_btclk & 3) == 0b00){
|
||||
print("Rx Hdr Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x3;
|
||||
|
||||
read(0, &pkt_hdr_status, 2);
|
||||
read(0, &pkt_log, 2);
|
||||
pkt_hdr_status |= 0x40000;
|
||||
pkt_log |= 0x40000;
|
||||
|
||||
//Eir inject test FHS
|
||||
/*
|
||||
if (pcx_btclk & 0x8 == 0) {
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x2;
|
||||
|
||||
pkt_hdr_status = 0x40000;
|
||||
pkt_hdr_status |= 0x0; //LT_ADDR
|
||||
pkt_hdr_status |= 0x2 << 3; //Type
|
||||
pkt_hdr_status |= 0x1 << 7; //Flow
|
||||
pkt_hdr_status |= 0x1 << 8; //ARQN
|
||||
pkt_hdr_status |= 0x1 << 9; //SEQ
|
||||
pkt_hdr_status |= 0xf00; //HEC
|
||||
pkt_log = 0xd336 | 0x40000; //payload_hdr
|
||||
}
|
||||
//Eir inject Eir
|
||||
if (pcx_btclk & 0x8) {
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x2;
|
||||
|
||||
pkt_hdr_status = 0x40000;
|
||||
pkt_hdr_status |= 0x0; //LT_ADDR
|
||||
pkt_hdr_status |= 0xa << 3; //Type
|
||||
pkt_hdr_status |= 0x1 << 7; //Flow
|
||||
pkt_hdr_status |= 0x1 << 8; //ARQN
|
||||
pkt_hdr_status |= 0x1 << 9; //SEQ
|
||||
pkt_hdr_status |= 0xf00; //HEC
|
||||
pkt_log = 0xf5c2 | 0x40000; //payload_hdr
|
||||
}
|
||||
/**/
|
||||
|
||||
print_var(pkt_hdr_status);
|
||||
print_var(pkt_log);
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Interrupt
|
||||
if((pcx_btclk & 3) == 0b01) {
|
||||
print("Rx Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x1;
|
||||
|
||||
if (rtx_dma_ctl != 3 && dmaActiveRxBuffer) {
|
||||
if (read(0, dmaActiveRxBuffer, 240) < 1) exit(1);
|
||||
print_var(dmaActiveRxBuffer);
|
||||
for (unsigned char i=0; i < 240; i++) dmaActiveRxBuffer[i] = i;
|
||||
print("pcktdata: ");
|
||||
hexdump(dmaActiveRxBuffer, 240);
|
||||
print("\n");
|
||||
}
|
||||
else {
|
||||
print("pcktdata: ");
|
||||
read(0, 0x370000, 16);
|
||||
hexdump(0x370000, 16);
|
||||
print("\n");
|
||||
//char fhs[] = "\x70\x21\xc9\x74\xaf\x83\xc0\x6c\xff\x5a\x48\x8d\x5a";
|
||||
//memcpy(0x370000, fhs, sizeof(fhs));
|
||||
//read(0, 0x370000 + 9, 2); //some bt addr part
|
||||
//read(0, 0x370000 + sizeof(fhs), 240);
|
||||
//hexdump(0x370000, 240);
|
||||
}
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,136 @@
|
||||
int le_fd = 0;
|
||||
|
||||
int wib_rx_status;
|
||||
int wib_pkt_log;
|
||||
|
||||
void adv() {
|
||||
if (le_fd == -1) return;
|
||||
|
||||
if ((pcx_btclk & 3) == 0b10){
|
||||
print("Tx Done\n");
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x4;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
|
||||
/*
|
||||
print("TxDone: ");
|
||||
hexdump(&tx_pkt_info, 4);
|
||||
print(" | ");
|
||||
hexdump(&tx_pkt_pyld_hdr, 2);
|
||||
print("\n");
|
||||
*/
|
||||
}
|
||||
|
||||
//Rx Hdr Int
|
||||
if ((pcx_btclk & 3) == 0b00){
|
||||
print("Rx Hdr Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x3;
|
||||
|
||||
read(le_fd, &wib_rx_status, 4);
|
||||
read(le_fd, &wib_pkt_log, 4);
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Interrupt
|
||||
if((pcx_btclk & 3) == 0b01) {
|
||||
print("Rx Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x1;
|
||||
|
||||
read(le_fd, 0x370c00, 32);
|
||||
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
}
|
||||
|
||||
void le_scan() {
|
||||
if ((pcx_btclk & 3) == 0b10){
|
||||
print("Tx Done\n");
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x4;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Hdr Int
|
||||
if ((pcx_btclk & 3) == 0b00){
|
||||
print("Rx Hdr Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x3;
|
||||
|
||||
read(le_fd, &wib_rx_status, 4);
|
||||
read(le_fd, &wib_pkt_log, 4);
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Interrupt
|
||||
if((pcx_btclk & 3) == 0b01) {
|
||||
print("Rx Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x1;
|
||||
|
||||
print_var(wib_rx_status)
|
||||
print_var(wib_pkt_log)
|
||||
read(le_fd, 0x370c00, 256);
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
}
|
||||
|
||||
//#include <xmit_state_emu.h>
|
||||
void le_conn() {
|
||||
//xmit_state_emu("gen/xmited_le");
|
||||
//hci_rx_fd = -1;
|
||||
//hci_tx_fd = -1;
|
||||
|
||||
if ((pcx_btclk & 3) == 0b10){
|
||||
print("Tx Done\n");
|
||||
sr_status = 0x1d8;
|
||||
phy_status = 0x4;
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Hdr Int
|
||||
if ((pcx_btclk & 3) == 0b00){
|
||||
print("Rx Hdr Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x3;
|
||||
|
||||
wib_rx_status = 0;
|
||||
read(le_fd, &wib_rx_status, 4);
|
||||
read(le_fd, &wib_pkt_log, 4);
|
||||
|
||||
//LE heap BoF fix
|
||||
//wib_rx_status &= 0xffff;
|
||||
//if (wib_rx_status >= 0xfc00) wib_rx_status = 0xfc00 | (wib_rx_status & 0xff);
|
||||
//wib_rx_status |= wib_rx_status << 16;
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
|
||||
//Rx Interrupt
|
||||
if((pcx_btclk & 3) == 0b01) {
|
||||
print("Rx Done\n");
|
||||
sr_status = 0x1c8;
|
||||
phy_status = 0x1;
|
||||
|
||||
print_var(wib_rx_status)
|
||||
print_var(wib_pkt_log)
|
||||
read(le_fd, rtx_rx_buffer, 256);
|
||||
//for (int i=0; i < 0x100; i++) ((char *)0x370c00)[i] = (char)(i&0xff);
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
int page_fd = 0;
|
||||
|
||||
int page_idx = 0;
|
||||
|
||||
|
||||
/*
|
||||
Accept any connection attempt
|
||||
*/
|
||||
void page() {
|
||||
//if (acl_fd == 0 || acl_fd == -1) acl_fd = tcp_connect(127,0,0,1,31338);
|
||||
|
||||
switch(page_idx) {
|
||||
case 0:
|
||||
if ( (pcx_btclk & 3) != 0b10) page_idx = page_idx - 1 % 4;
|
||||
|
||||
case 1:
|
||||
pkt_hdr_status = 0x04e98d; //TODO are these function callbacks?
|
||||
pkt_log = 0x2404e878;
|
||||
phy_status = 1;
|
||||
sr_status = 0xcb3a;
|
||||
break;
|
||||
case 2:
|
||||
pkt_hdr_status = 0x0438f2; //TODO
|
||||
pkt_log = 0x24040225;
|
||||
phy_status = 0x1;
|
||||
sr_status = 0xc99a;
|
||||
break;
|
||||
case 3:
|
||||
pkt_hdr_status = 0x04e0b5; //TODO
|
||||
pkt_log = 0x2404303e;
|
||||
phy_status = 5;
|
||||
sr_status = 0x227f;
|
||||
|
||||
acl_role = ACL_ROLE_MASTER;
|
||||
break;
|
||||
}
|
||||
page_idx = page_idx + 1 % 4;
|
||||
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
void pagescan() {
|
||||
//bcs_info();
|
||||
if (page_fd == -1) return;
|
||||
//if (acl_fd == 0 || acl_fd == -1) acl_fd = tcp_connect(127,0,0,1,31337);
|
||||
acl_role = ACL_ROLE_SLAVE;
|
||||
|
||||
read(page_fd, 0x370000, 16);
|
||||
read(page_fd, &sr_status, 2);
|
||||
read(page_fd, &phy_status, 2);
|
||||
read(page_fd, &pkt_hdr_status, 2);
|
||||
read(page_fd, &pkt_log, 2);
|
||||
pkt_hdr_status |= 0x40000;
|
||||
pkt_log |= 0x40000;
|
||||
|
||||
print_var(pkt_hdr_status);
|
||||
print_var(pkt_log);
|
||||
print_var(phy_status);
|
||||
print_var(sr_status);
|
||||
bluetoothCoreInt_C();
|
||||
contextswitch();
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,155 @@
|
||||
#ifndef _COMMON_H
|
||||
#define _COMMON_H
|
||||
void cont();
|
||||
|
||||
#define EMULATED
|
||||
|
||||
//utils
|
||||
int ret1() { return 1; }
|
||||
int ret0() { return 0; }
|
||||
void die() { print_caller(); print(" die();\n"); exit(-1);}
|
||||
void clean_exit() { exit(0);}
|
||||
|
||||
#include <frankenstein/xmit_state_emu.h>
|
||||
#include "fwdefs.h"
|
||||
#include <frankenstein/hook.h>
|
||||
#include "hci.h"
|
||||
#include "lm.h"
|
||||
#include "timer.h"
|
||||
#include "dynamic_memory.h"
|
||||
|
||||
#include <frankenstein/threadx/threading.h>
|
||||
|
||||
/*
|
||||
Hook for Peripheral UART
|
||||
*/
|
||||
void puart_write_hook(char c) {
|
||||
print("\033[;34m");
|
||||
write(2, &c, 1);
|
||||
print("\033[;00m");
|
||||
}
|
||||
|
||||
|
||||
/*
|
||||
Queu
|
||||
*/
|
||||
|
||||
//probably mpaf timer/event
|
||||
struct queue_entry {
|
||||
void *next;
|
||||
int maybe_flags;
|
||||
void *sometimes_callback;
|
||||
void *callback_arg;
|
||||
char unknwn[];
|
||||
} *queue_entry;
|
||||
|
||||
void msgqueue_Put_hook(struct saved_regs *regs, void *arg) {
|
||||
void *queue = (void *)regs->r0;
|
||||
struct queue_entry *item = (void *)regs->r1;
|
||||
print_caller();
|
||||
print(" msgqueue_Put_hook(");
|
||||
print_ptr(queue);
|
||||
print(", ");
|
||||
print_ptr(item);
|
||||
print(");\n");
|
||||
print(" ");print_var(item->maybe_flags)
|
||||
print(" ");print_var(item->sometimes_callback)
|
||||
print(" ");print_var(item->callback_arg)
|
||||
print(" "); hexdump(item, 32);
|
||||
}
|
||||
|
||||
/*
|
||||
This
|
||||
*/
|
||||
//TODO get thread list
|
||||
void print_thrd_bcmbt(uint32_t thrd) {
|
||||
switch (thrd) {
|
||||
case 0x249e58:
|
||||
print("bttransport");
|
||||
break;
|
||||
|
||||
case 0x20beb4:
|
||||
print("lm");
|
||||
break;
|
||||
|
||||
case 0x20a578:
|
||||
print("idle");
|
||||
break;
|
||||
|
||||
case 0x20a1fc:
|
||||
print("mpaf")
|
||||
break;
|
||||
|
||||
default:
|
||||
print_ptr(_tx_thread_current_ptr);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/*
|
||||
global code patching
|
||||
*/
|
||||
|
||||
#define idle_loop (*(uint32_t*)0x024de64) //TODO
|
||||
|
||||
uint32_t _tx_v7m_get_and_disable_int();
|
||||
void _tx_v7m_set_int(uint32_t);
|
||||
uint32_t _tx_v7m_get_int();
|
||||
|
||||
|
||||
void synch_GetXSPRExceptionNum();
|
||||
void osapi_interruptContext();
|
||||
void btclk_AdvanceNatClk_clkpclk();
|
||||
|
||||
void patch_code() {
|
||||
//ThreadX basics
|
||||
patch_return(_tx_v7m_get_and_disable_int);
|
||||
patch_return(_tx_v7m_set_int);
|
||||
patch_return(_tx_v7m_get_int);
|
||||
patch_jump(_tx_thread_system_return, _tx_thread_system_return_hook);
|
||||
|
||||
patch_return(osapi_interruptContext);
|
||||
//patch_jump(osapi_interruptContext, _tx_thread_system_return);
|
||||
//patch_return(osapi_interruptContext);
|
||||
|
||||
//Functions, we do not support
|
||||
patch_return(0xa43ee); //synch_GetXSPRExceptionNum //TODO
|
||||
patch_return(0x20ffb2); //get_and_disable_int 2nd ed?! //TODO
|
||||
patch_return(btclk_DelayXus);
|
||||
patch_return(btclk_Wait4PclkChange);
|
||||
patch_return(btclk_AdvanceNatClk_clkpclkHWWA);
|
||||
patch_return(btclk_AdvanceNatClk_clkpclk);
|
||||
|
||||
//Show thread names
|
||||
print_thrd = print_thrd_bcmbt;
|
||||
|
||||
//Relplace return from interrupt addr with exit
|
||||
if(idle_loop == 0xfffffffd)
|
||||
idle_loop = clean_exit;
|
||||
|
||||
//Watchdog HW Reset
|
||||
patch_jump(&wdog_generate_hw_reset, &die);
|
||||
//Enable Peripheral UART
|
||||
patch_jump(&puart_write, &puart_write_hook);
|
||||
//Trace dbfw Assert Fatals
|
||||
trace(dbfw_assert_fatal, 1, false);
|
||||
|
||||
//Disable NV RAM
|
||||
patch_return(wiced_hal_read_nvram);
|
||||
trace(wiced_hal_read_nvram, 4, true);
|
||||
patch_return(wiced_hal_write_nvram);
|
||||
trace(wiced_hal_write_nvram, 4, true);
|
||||
|
||||
//Enable Osapi Timers
|
||||
add_timer_hooks();
|
||||
|
||||
hci_install_hooks();
|
||||
|
||||
add_lm_hooks();
|
||||
|
||||
|
||||
//add heap sanitizer
|
||||
init_dynamic_memory_sanitizer();
|
||||
}
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,72 @@
|
||||
#ifndef DYNAMIC_MEMORY_H
|
||||
#define DYNAMIC_MEMORY_H
|
||||
|
||||
|
||||
#include "common.h"
|
||||
#include <frankenstein/BCMBT/dynamic_memory.h>
|
||||
|
||||
|
||||
//void *memcpy_r(void *dest, const void *src, size_t n);
|
||||
void *utils_memcpy8(void *dest, const void *src, size_t n);
|
||||
void *sfi_memcpy(void *dest, const void *src, size_t n);
|
||||
void *utils_memcpy10(void *dest, const void *src, size_t n);
|
||||
void *utils_memcpy8_postinc(void *dest, const void *src, size_t n);
|
||||
void *__aeabi_memcpy(void *dest, const void *src, size_t n);
|
||||
void *utils_memcpy3dword(void *dest, const void *src, size_t n);
|
||||
void *__rt_memcpy_w(void *dest, const void *src, size_t n);
|
||||
void *__aeabi_memcpy8(void *dest, const void *src, size_t n);
|
||||
void *__aeabi_memcpy4(void *dest, const void *src, size_t n);
|
||||
void *__ARM_common_memcpy4_5(void *dest, const void *src, size_t n);
|
||||
void *__ARM_common_memcpy4_10(void *dest, const void *src, size_t n);
|
||||
void *mpaf_memcpy(void *dest, const void *src, size_t n);
|
||||
void *memcpy(void *dest, const void *src, size_t n);
|
||||
void *_memcpy_lastbytes(void *dest, const void *src, size_t n);
|
||||
void *_memcpy_lastbytes_aligned(void *dest, const void *src, size_t n);
|
||||
void *__rt_memcpy(void *dest, const void *src, size_t n);
|
||||
|
||||
void *__rt_memmove_w(void *dest, const void *src, size_t n);
|
||||
void *memmove(void *dest, const void *src, size_t n);
|
||||
void *__memmove_aligned(void *dest, const void *src, size_t n);
|
||||
void *mpaf_memmove(void *dest, const void *src, size_t n);
|
||||
void *__rt_memmove(void *dest, const void *src, size_t n);
|
||||
void *__memmove_lastfew(void *dest, const void *src, size_t n);
|
||||
void *__memmove_aligned(void *dest, const void *src, size_t n);
|
||||
void *__aeabi_memmove8(void *dest, const void *src, size_t n);
|
||||
void *__aeabi_memmove4(void *dest, const void *src, size_t n);
|
||||
void *__aeabi_memmove(void *dest, const void *src, size_t n);
|
||||
void *__memmove_lastfew_aligned(void *dest, const void *src, size_t n);
|
||||
|
||||
void *memset(void *dest, int c, size_t n);
|
||||
void *_memset(void *dest, const size_t n, int c);
|
||||
|
||||
|
||||
|
||||
|
||||
void init_dynamic_memory_sanitizer() {
|
||||
//clear_heap();
|
||||
|
||||
dynamic_memory_check_free_list(1);
|
||||
|
||||
dynamic_memory_sanitize_trace_function(dynamic_memory_Release, 1, false);
|
||||
dynamic_memory_sanitize_trace_function(dynamic_memory_AllocatePrivate, 3, false);
|
||||
|
||||
//dynamic_memory_sanitize_trace_function(memcpy_r, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(utils_memcpy8, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(sfi_memcpy, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(utils_memcpy10, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(utils_memcpy8_postinc, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__aeabi_memcpy, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(utils_memcpy3dword, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__rt_memcpy_w, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__aeabi_memcpy8, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__aeabi_memcpy4, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__ARM_common_memcpy4_5, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__ARM_common_memcpy4_10, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(mpaf_memcpy, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(memcpy, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(_memcpy_lastbytes, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(_memcpy_lastbytes_aligned, 3, false);
|
||||
dynamic_memory_sanitize_trace_function(__rt_memcpy, 3, false);
|
||||
}
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,19 @@
|
||||
#include <frankenstein/utils.h>
|
||||
#include <frankenstein/hook.h>
|
||||
#include <frankenstein/xmit_state_emu.h>
|
||||
#include "common.h"
|
||||
#include "queue.h"
|
||||
|
||||
|
||||
#include <sys/stat.h>
|
||||
#include <fcntl.h>
|
||||
|
||||
void do_exit() {
|
||||
exit(0);
|
||||
}
|
||||
|
||||
void _start() {
|
||||
patch_code();
|
||||
idle_loop = do_exit;
|
||||
cont();
|
||||
}
|
||||
@@ -0,0 +1,439 @@
|
||||
#ifndef FWDEFS_H
|
||||
#define FWDEFS_H
|
||||
|
||||
|
||||
#ifdef EMULATED
|
||||
typedef uint16_t wiced_result_t;
|
||||
#endif
|
||||
|
||||
/*
|
||||
NVRAM
|
||||
*/
|
||||
uint16_t wiced_hal_read_nvram( uint16_t vs_id, uint16_t data_length, uint8_t* p_data, wiced_result_t * p_status);
|
||||
uint16_t wiced_hal_write_nvram( uint16_t vs_id, uint16_t data_length, uint8_t* p_data, wiced_result_t * p_status);
|
||||
void wiced_hal_delete_nvram( uint16_t vs_id, wiced_result_t * p_status);
|
||||
|
||||
void _send_acl_segment(int s, char *buff, int len);
|
||||
|
||||
/*
|
||||
Queue
|
||||
*/
|
||||
|
||||
void *msgqueue_GetNonblock(void *queue);
|
||||
void *msgqueue_Get(void *queue);
|
||||
//called by msgqueue_Get after queue event
|
||||
void *msgqueue_PrivateGet(void *queue, int x);
|
||||
|
||||
void msgqueue_Put(void *queue, void *item);
|
||||
void msgqueue_PutInFront(void *queue, void *item);
|
||||
|
||||
void *osapi_getQueueItem(void *queue);
|
||||
void osapi_sendQueueItem(void *queue, void *item);
|
||||
void osapi_sendQueueItemToFront(void *queue, void *item);
|
||||
|
||||
void *osapi_getQueueItem_tx(void *queue);
|
||||
void osapi_sendQueueItem_tx(void *queue);
|
||||
void osapi_sendQueueItemToFront_tx(void *queue, void *item);
|
||||
|
||||
void *_tx_queue_receive(void *tx_queue, void *item);
|
||||
void _tx_queue_send(void *tx_queue, void *item);
|
||||
void _tx_queue_front_send(void *tx_queue, void *item);
|
||||
void _tx_event_flags_set(void *event_group, int a, int b);
|
||||
void _tx_thread_system_resume(void *);
|
||||
|
||||
/*
|
||||
slist
|
||||
*/
|
||||
void *slist_get(void *slist);
|
||||
void *slist_tail(void *slist);
|
||||
void *slist_front(void *slist);
|
||||
|
||||
void *slist_del_front(void *slist);
|
||||
void *slist_del(void *slist); //XXX item?
|
||||
|
||||
void slist_add_after( void* slist, void *item);
|
||||
void slist_add_front( void* slist, void *item);
|
||||
void slist_add_tail( void* slist, void *item);
|
||||
void slist_add_before( void* slist, void *item);
|
||||
|
||||
|
||||
/*
|
||||
Utils
|
||||
*/
|
||||
int rand();
|
||||
int rbg_rand(int);
|
||||
|
||||
/*
|
||||
Uart
|
||||
*/
|
||||
extern int sr_ptu_status_adr4;
|
||||
|
||||
void puart_write(char c);
|
||||
void *btuartcommon_SendHCICommandBackToTransportThread(int);
|
||||
//For some reason, this always send 0x19 before any hci packet
|
||||
void uart_SendSynchHeaderBeforeAsynch(void *some_struct, char *data, int len, int x);
|
||||
// thrd=0x249e58 lr=0x019265 uart_SendAsynch(0x249f70, 0x249e00, 0x01, 0x2117c8)
|
||||
void uart_SendAsynch(void *uart_struct, char *data, int len, int x);
|
||||
void uart_SendSynch(void *uart_struct, char *data, int len);
|
||||
void btuarth4_getpti();
|
||||
void uart_SetAndCheckReceiveAFF();
|
||||
void uart_SetAndCheckTransmitAEF();
|
||||
void btuarth4_InitiateTransmit_help();
|
||||
void bttransport_SendMsgToThread();
|
||||
void btu_hcif_hardware_error_evt();
|
||||
void uart_RunTransmitStateMachine(void*);
|
||||
void btuarth4_RunTxStateMachines(int, int, int, int);
|
||||
|
||||
void bthci_lm_thread_SendMessageToThread(void *msg);
|
||||
void bthci_event_SendConnectionRequestEvent();
|
||||
|
||||
/*
|
||||
Interrupt Vectors
|
||||
*/
|
||||
void interruptvector_PTU(); //uart
|
||||
void interruptvector_DMA_DONE();
|
||||
void interruptvector_WAKEUP();
|
||||
void interruptvector_TIMER1_DONE();
|
||||
void interruptvector_TIMER2_DONE();
|
||||
|
||||
|
||||
extern int g_ptu_ISR;
|
||||
extern int g_uart_DriverState;
|
||||
void *uart_ReceiveSynch();
|
||||
void *uart_ReceiveAsynch();
|
||||
void *uart_ReceiveAsynchTerminate();
|
||||
void btuarth4_getpti();
|
||||
void btuarth4_RunRxStateMachines();
|
||||
void btuarth4_HandleRXFullMsgDone();
|
||||
void uart_RunReceiveStateMachine();
|
||||
void uart_SetupForRXDMA(void *);
|
||||
void bttransport_Main(void *driver_state);
|
||||
|
||||
void dma_StartTransfer();
|
||||
void dma_RequestTransfer(int);
|
||||
|
||||
int mpaf_hci_EventFilter(void *);
|
||||
extern int mpaf_flags;
|
||||
extern int mpaf_suppress_hci_rx_to_host;
|
||||
void mpaf_thread_PostMsgToHandler(void *, void *);
|
||||
|
||||
|
||||
void *uart_TransmitDMADoneInterrupt();
|
||||
void *uart_ReceiveDMADoneInterrupt();
|
||||
void *uart_DirectWrite();
|
||||
void *uart_DirectRead();
|
||||
|
||||
/*
|
||||
Hardware
|
||||
*/
|
||||
extern int pkt_hdr_status; //Rx
|
||||
extern int pkt_log;
|
||||
|
||||
extern int tx_pkt_info;
|
||||
extern int tx_pkt_pyld_hdr; //maybe acl header, length + 3 bits
|
||||
|
||||
|
||||
extern int pc_acscd_lo; //Piconet Access Code
|
||||
extern int pc_acscd_hi;
|
||||
|
||||
extern int dc_fhout;
|
||||
extern int dc_ind_d_ptr;
|
||||
|
||||
/*
|
||||
Exception
|
||||
*/
|
||||
void wdog_generate_hw_reset();
|
||||
void dbfw_assert_fatal();
|
||||
|
||||
/*
|
||||
Os
|
||||
*/
|
||||
|
||||
struct thread_dvdn {
|
||||
uint32_t magic;
|
||||
uint32_t x1;
|
||||
uint32_t sp;
|
||||
};
|
||||
|
||||
extern struct thread_dvdn g_pmu_idle_IdleThread;
|
||||
|
||||
extern int g_bthci_lm_thread_Thread;
|
||||
|
||||
void _tx_thread_system_suspend();
|
||||
void _tx_thread_system_return(void);
|
||||
void _tx_thread_suspend(void);
|
||||
int osapi_waitEvent(void *dvdn, int mask, int x);
|
||||
void interrupt_DisableInterrupts();
|
||||
void interrupt_EnableInterrupts();
|
||||
|
||||
/*
|
||||
Timer
|
||||
*/
|
||||
struct osapi_timer {
|
||||
void *next;
|
||||
void *callback;
|
||||
int maybe_type;
|
||||
int i2;
|
||||
void *mpaf_exec_timer_arg;
|
||||
int i3;
|
||||
uint32_t time_offset_low;
|
||||
uint32_t time_offset_high;
|
||||
int i6;
|
||||
int i7;
|
||||
char unknwn[];
|
||||
};
|
||||
|
||||
void osapi_activateTimer(void *timer, uint32_t time_us);
|
||||
void osapi_getTimerRemain(void *timer);
|
||||
void *g_pmu_private_IdleMsgQueue;
|
||||
void mpaf_osapi_timerCb(void *timer);
|
||||
uint32_t clock_SystemTimeMicroseconds32();
|
||||
uint32_t clock_SystemTimeMicroseconds64();
|
||||
uint32_t clock_SystemTimeMicroseconds32_nolock();
|
||||
uint32_t clock_SystemTimeMicroseconds64_nolock();
|
||||
void clock_serviceTimers();
|
||||
void clock_ResetTimer2();
|
||||
|
||||
extern struct osapi_timer *lm_osTimer;
|
||||
uint32_t timer1value; //current system time
|
||||
|
||||
/*
|
||||
Connection
|
||||
*/
|
||||
int createConnection();
|
||||
void lm_HandleLmpBBAck();
|
||||
void lm_HandleLmpReceivedPdu(int *i);
|
||||
void lm_HandleLmpHostConnReqNotAccepted();
|
||||
void lm_HandleLmpHostConnReqAccepted();
|
||||
void *ber_startBerPerTest(char *);
|
||||
void *rm_getConnFromBdAddress(char *);
|
||||
void rm_setLocalBdAddr(char *);
|
||||
|
||||
/*
|
||||
LM
|
||||
*/
|
||||
|
||||
extern int lm_curCmd;
|
||||
extern int lm_curCmdPayload; //XXX custom symbol
|
||||
|
||||
void lm_sendCmd(void *event);
|
||||
void lm_sendCmdWithId(void *event);
|
||||
void lm_handleCmd();
|
||||
void lm_handleHciResetWithAclLinks();
|
||||
int rm_getBBConnectedACLUsage();
|
||||
void lm_LmpBBAcked(void *); //called if sent packet is acked
|
||||
|
||||
/*
|
||||
bpl
|
||||
*/
|
||||
void bpl_lcu_Cmd(int, int);
|
||||
void bpl_lcu_setPHY(int, int, int, int);
|
||||
int lb;
|
||||
|
||||
/*
|
||||
LMP
|
||||
*/
|
||||
extern int diag_sendLmpPktFlag;
|
||||
void *rm_getACLConnPtr(int i);
|
||||
void *rm_getDHMAclPtr(int i);
|
||||
void *rm_allocateACLConnPtr(int i);
|
||||
void *rm_allocateLTCH(int i);
|
||||
void lm_LmpReceived(void *acl_conn, void *lmp_msg);
|
||||
int DHM_LMPTx(int id, void *buff);
|
||||
int DHM_TxDataAvail();
|
||||
void DHM_releaseTxLmpList(int, int, int, int);
|
||||
void *DHM_GetBasebandTxData(int, int);
|
||||
void *DHM_GetBasebandRxBuffer(int, int);
|
||||
void *DHM_BasebandRx(int, int, int);
|
||||
void DHM_ACLAckRcvd(int);
|
||||
void DHM_SetAclTxPktAckRcvd(int);
|
||||
int DHM_isTxLmpListEmpty(void *adhm_acl);
|
||||
void *DHM_getFrontTxLmp(void *adhm_acl);
|
||||
void _dhmSlotCbFunc(void *x);
|
||||
|
||||
/*
|
||||
ACL Task
|
||||
*/
|
||||
void _aclTaskSetupTxBuffer();
|
||||
void _aclTaskLcuCmd();
|
||||
void _aclTaskRxHeaderDone();
|
||||
void _aclTaskRxDone();
|
||||
void _aclTaskTxDone();
|
||||
void _aclTaskFsmSetup();
|
||||
void _aclTaskQosSlotIntCB();
|
||||
void _aclTaskProcessRxPacket();
|
||||
void _aclTaskSwitch();
|
||||
|
||||
/*
|
||||
Inquiry
|
||||
*/
|
||||
void _inqTaskRxHeaderDone(int);
|
||||
void _inqTaskRxDone(int);
|
||||
void eir_handleTx(int);
|
||||
void eir_handleRx(int);
|
||||
void bcs_inqScanPauseNonBlock();
|
||||
void bcs_inqScanPause();
|
||||
void _inqTaskFsmDone(int, int);
|
||||
void _inqTaskFsmSetup(int, int);
|
||||
void eir_eirInqFHS(int);
|
||||
void lm_sendInqFHS(int);
|
||||
void lm_handleInqFHS(int);
|
||||
void eir_getReceivedEIR(int, int);
|
||||
void bthci_event_SendInquiryResultEvent(int);
|
||||
void lc_handleInqResult(int);
|
||||
void bcs_utilExtractFhsInfo(int);
|
||||
void inqfilter_isBdAddrRegistered(int, int);
|
||||
void inqfilter_registerBdAddr(int, int);
|
||||
extern int eir_fhs;
|
||||
|
||||
/*
|
||||
Page
|
||||
*/
|
||||
void _pageTaskFsmDone();
|
||||
void _pageScanTaskFsmDone();
|
||||
void bcs_newConnTaskCreate();
|
||||
void bcs_pageScanTaskCreate();
|
||||
|
||||
/*
|
||||
LE
|
||||
*/
|
||||
void _advTaskRxDone();
|
||||
void _scanTaskRxDone();
|
||||
void bcsulp_passRxPktUp();
|
||||
void bcsulp_procRxPayload(int, int);
|
||||
void bcsulp_progTxBuffer(int);
|
||||
void bcsulp_getPktLength(int, int);
|
||||
void bcsulp_fillTxBuffer(int dst, int src, int len);
|
||||
void bcsulp_setupRxBuffer();
|
||||
void bcsulp_returnRxBuffer(void);
|
||||
void *mmulp_allocACLUp(int );
|
||||
void *mmulp_allocACLDown(int );
|
||||
int mmulp_freeLEABuffer(void *);
|
||||
void *dhmulp_getRxBuffer(int);
|
||||
void dhmulp_returnRxBuffer(void *);
|
||||
void _connTaskLcuCmd_addin();
|
||||
void _connTaskLcuCmd();
|
||||
void _connTaskSlotInt();
|
||||
void _connTaskRxDone();
|
||||
void _connTaskRxHeaderDone();
|
||||
|
||||
/*
|
||||
LCP
|
||||
*/
|
||||
extern void diag_logLcpPkt(int, int);
|
||||
|
||||
|
||||
/*
|
||||
clk
|
||||
*/
|
||||
int btclk_GetSysClk_slot(void *);
|
||||
int btclk_GetSysClk_clk(void *);
|
||||
|
||||
/*
|
||||
bcs
|
||||
*/
|
||||
extern int bcsProfilingData;
|
||||
extern int pcx_btclk;
|
||||
extern int dc_nbtc_clk; //ca 1 unit pre 312us
|
||||
extern int dc_x_clk; //ca 1 unit pre 312us
|
||||
extern uint32_t *tb; //current task
|
||||
extern int taskTimerList;
|
||||
extern int slotCbEntryList;
|
||||
extern int btProgIntStatus;
|
||||
extern int taskTransientStateList;
|
||||
extern int taskActiveList;
|
||||
extern int taskReadyList;
|
||||
extern void *taskEventGroup;
|
||||
extern int phy_status;
|
||||
extern int sr_status;
|
||||
extern int sr_status_shadow;
|
||||
extern int phy_status_shadow;
|
||||
extern char rm_deviceInfo[];
|
||||
extern char rm_deviceLocalName[];
|
||||
void bcs_isrSlot11Int();
|
||||
void bcs_isrSlot01Int();
|
||||
void bcs_utilBbRxPktHdrCheck(int, int);
|
||||
void bcs_dmaRxEnableEir(int, int);
|
||||
void bcs_dmaTxEnableEir(int, int);
|
||||
void bcs_dmaRxEnable(int, int);
|
||||
void bcs_dmaTxEnable(int, int);
|
||||
void *bcs_dmaRxDisable(int, int);
|
||||
void bcs_dmaBlockEnable();
|
||||
void bcs_dmaIsTransferComplete();
|
||||
void *bcs_dmaGetRxBuffer();
|
||||
void bcs_dmaRxBufferRecycle(void *);
|
||||
void _dmaReqSend();
|
||||
void bcs_SlotCbFunctions();
|
||||
extern int dmacinttcclr;
|
||||
extern int rtx_dma_ctl;
|
||||
extern int dmacinttcstat;
|
||||
extern int g_dma_ActiveChannels;
|
||||
|
||||
int bcs_taskGetTaskType(int);
|
||||
void bcs_aclTaskCreate();
|
||||
extern int bcs_isrEnableProfiling;
|
||||
void BtIntDone();
|
||||
extern int bcsDataToCrunch;
|
||||
void pmu_idle_Main();
|
||||
void *pmu_idle_MsgHandlersPoll();
|
||||
void dbfw_proc_in_idle();
|
||||
void bluetoothCoreInt_C();
|
||||
|
||||
void *bcs_isrRxDoneInt();
|
||||
void *bcs_isrTxDoneInt();
|
||||
void *bcs_timeline_CrunchData();
|
||||
void *bcs_isrRxHeaderDoneInt();
|
||||
void bcs_isrFsmDoneInt();
|
||||
|
||||
void bcs_kernelSlotCbFunctions();
|
||||
void bcs_kernelRxDone();
|
||||
void bcs_kernelRxHeaderDone();
|
||||
void bcs_kernelTimerTick();
|
||||
void bcs_kernelBlock();
|
||||
void bcs_kernelFsmSetup();
|
||||
void bcs_kernelBtProgIntEnable();
|
||||
|
||||
void bcs_taskUnblock(int);
|
||||
void bcs_SlotCbFunctions();
|
||||
void *bcs_dmaGetRxBuffer();
|
||||
int btclk_DelayXus(int us);
|
||||
void bcs_utilBbRxPyldHdr();
|
||||
|
||||
void btclk_Wait4PclkChange(int, int);
|
||||
void btclk_AdvanceNatClk_clkpclkHWWA();
|
||||
void intctl_ClrPendingInt();
|
||||
void *dhmulp_getTxBuffer();
|
||||
void dhmulp_LcpTx();
|
||||
|
||||
void bluerf_Wr(void *addr, int val);
|
||||
int bluerf_Rd(void *addr);
|
||||
|
||||
void eir_handleTx(int);
|
||||
void _afhPipelineRssiScanTaskSlotInt();
|
||||
|
||||
/*
|
||||
paging
|
||||
*/
|
||||
void bcs_pageTaskCreate();
|
||||
void lc_pageStart(int);
|
||||
|
||||
extern int dc_n_pg;
|
||||
extern int dc_pg_to;
|
||||
extern int dc_pg_respto;
|
||||
|
||||
|
||||
/*
|
||||
HCI
|
||||
*/
|
||||
void bthci_processingHCIReset();
|
||||
void bthci_processingHCIResetFlag();
|
||||
void bthci_lm_thread_Reset();
|
||||
void bthci_acl_Reset();
|
||||
void bthci_event_AttemptToEnqueueEventToTransport();
|
||||
void bthci_event_SendCommandCompleteEventWithStatus();
|
||||
void bthci_cmd_lc_HandleCreate_Connection();
|
||||
void bthci_cmd_lc_HandleDisconnect(char *);
|
||||
|
||||
void bt_Reset();
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,209 @@
|
||||
#ifndef HCI_H
|
||||
#define HCI_H
|
||||
|
||||
|
||||
#include "common.h"
|
||||
|
||||
|
||||
int hci_tx_fd = -1;
|
||||
int hci_rx_fd = -1;
|
||||
int hci_dump_raw_enable = 0; //we wait until the first hci cmd before dumping events
|
||||
|
||||
/*
|
||||
Sending hci Events
|
||||
*/
|
||||
|
||||
void uart_SendSynch_hook(void *some_struct, char *data, int len) {
|
||||
print("\033[;32mHCI Event (Synch)");
|
||||
hexdump(data,len);
|
||||
print("\033[;00m");
|
||||
|
||||
return; //XXX called in send header before ...
|
||||
if (hci_tx_fd != -1 && hci_dump_raw_enable) {
|
||||
write(hci_tx_fd, data, len);
|
||||
}
|
||||
}
|
||||
|
||||
void uart_SendAsynch_hook(struct saved_regs *regs, void *arg) {
|
||||
uint32_t size = *(uint32_t*) regs->sp;
|
||||
print("\033[;32mHCI Event (Asynch)");
|
||||
hexdump(regs->r1, regs->r2); //header aka type
|
||||
hexdump(regs->r3, size); //hci packet
|
||||
print("\033[;00m\n");
|
||||
|
||||
//dump raw packets
|
||||
if (hci_tx_fd != -1 && hci_dump_raw_enable) {
|
||||
write(hci_tx_fd, regs->r1, regs->r2);
|
||||
write(hci_tx_fd, regs->r3, size);
|
||||
}
|
||||
}
|
||||
|
||||
void uart_DirectWrite_hook(char *data, int len) {
|
||||
return; //not needed
|
||||
print("\033[;32mHCI Event (Direct Write)");
|
||||
hexdump(data, len);
|
||||
print("\033[;00m\n");
|
||||
|
||||
return;
|
||||
if (hci_tx_fd != -1 && hci_dump_raw_enable) {
|
||||
write(hci_tx_fd, data, len);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
//0x249f70 = g_uart_DriverState
|
||||
//print_var(*(char*)(0x249e58+429)); //rx state
|
||||
|
||||
|
||||
|
||||
/*
|
||||
Reading HCI packets
|
||||
*/
|
||||
|
||||
/*
|
||||
This is called in the interrupt handler to complete a Asynch read
|
||||
*/
|
||||
|
||||
void uart_DirectRead_hook(char *data, int len) {
|
||||
int ret;
|
||||
print("\033[;32mHCI Direct Read ");
|
||||
for (ret = -1; ret < 0; ret = read(hci_rx_fd, data, len));
|
||||
hexdump(data, len);
|
||||
print("\033[;00m\n");
|
||||
|
||||
hci_dump_raw_enable = 1;
|
||||
if (ret == 0) exit(1); //no more to read, exit
|
||||
return ret;
|
||||
}
|
||||
|
||||
/*
|
||||
This method tries to receive directly from the uart and loops forever, as there are no data to read
|
||||
Therefore, wee hook it
|
||||
*/
|
||||
int uart_ReceiveSynch_hook(void *uart_struct, char *data, int len) {
|
||||
print("\033[;32mHCI ReceiveSynch ");
|
||||
int ret;
|
||||
for (ret = -1; ret < 0; ret = read(hci_rx_fd, data, len));
|
||||
hexdump(data, len);
|
||||
print("\033[;00m\n");
|
||||
|
||||
hci_dump_raw_enable = 1;
|
||||
return 8;
|
||||
}
|
||||
|
||||
/*
|
||||
Some debug stuff, deprecated
|
||||
*/ /*
|
||||
void dump_rx_state(){
|
||||
print_var(*(int*)(0x249e58+429));
|
||||
print_var(g_uart_DriverState);
|
||||
print_var(g_ptu_ISR);
|
||||
print_var(*(int*)(0x360084));
|
||||
print_var(*(int*)(0x3600a8));
|
||||
print_var(*(int*)(0x3600cc));
|
||||
print_var(*(int*)(0x3382d8));
|
||||
print_var(*(char*)(0x249f70+13));
|
||||
print_var(*(char*)(0x249f70+14));
|
||||
// *(int*)(0x360084) = 0x0a;
|
||||
} */
|
||||
|
||||
|
||||
/*
|
||||
If the firmware goes to an idle state, we execute the interrupt
|
||||
and notify the firmware for new HCI data
|
||||
*/
|
||||
void hci_rx_poll(int timeout_ms) {
|
||||
if (hci_rx_fd == -1) return;
|
||||
struct pollfd ufds;
|
||||
int ret = 0;
|
||||
|
||||
//setup poll for hci rx fd
|
||||
ufds.fd = hci_rx_fd;
|
||||
ufds.events = POLLIN;
|
||||
ret = poll(&ufds, 1, timeout_ms);
|
||||
|
||||
//No Data Available
|
||||
if (ret <= 0) return;
|
||||
|
||||
//classical receive
|
||||
sr_ptu_status_adr4 |= 0x04; //set register to data available
|
||||
interruptvector_PTU();
|
||||
|
||||
//the UART interface seems to have a DMA like receive
|
||||
char state = *(char *)(0x249f70 + 0xd); //rx_machine state //TODO
|
||||
print_var(state);
|
||||
if (state == 6) {
|
||||
void *data_ptr = *(void **)(0x249f70 + 0x10); //rx_data_ptr //TODO
|
||||
uint32_t len = *(uint32_t *)(0x249f70 + 0x14); //rx_len //TODO
|
||||
int ret;
|
||||
print_var(data_ptr);
|
||||
print_var(len);
|
||||
print("\033[;32mRx DMA ");
|
||||
for (ret = -1; ret < 0; ret = read(hci_rx_fd, data_ptr, len));
|
||||
*(uint32_t*)(0x249f70 + 0x3c) = ret; //TODO
|
||||
hexdump(data_ptr, len);
|
||||
print("\033[;00m\n");
|
||||
print_var(*(uint32_t*)(0x249f70 + 0x3c)); //TODO
|
||||
//interruptvector_DMA_DONE(); //XXX this is the actual interrupt handler called invoking uart_ReceiveDMADoneInterrupt
|
||||
uart_ReceiveDMADoneInterrupt(0x249f70); //Invoking isr directly //TODO
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
void hci_attach() {
|
||||
//open ptmx
|
||||
int ptmx = ptmx_open();
|
||||
char *pts_name = ptmx_name(ptmx);
|
||||
print("Pts:");
|
||||
puts(pts_name);
|
||||
print("\n");
|
||||
ptmx_btattach(ptmx);
|
||||
|
||||
hci_tx_fd = ptmx;
|
||||
hci_rx_fd = ptmx;
|
||||
|
||||
//wait for Data
|
||||
struct pollfd ufds;
|
||||
ufds.fd = ptmx;
|
||||
ufds.events = POLLIN;
|
||||
while (poll(&ufds, 1, 100) <= 0);
|
||||
|
||||
}
|
||||
|
||||
|
||||
|
||||
void hci_install_hooks() {
|
||||
//trace uart
|
||||
trace(btuartcommon_SendHCICommandBackToTransportThread, 2, true);
|
||||
|
||||
//hci uart tx
|
||||
patch_jump(&uart_DirectWrite, &uart_DirectWrite_hook); //not required
|
||||
patch_jump(&uart_SendSynch, &uart_SendSynch_hook); //notr required
|
||||
//ret0 is needed to notify the state machine, that the data has been sent immediately
|
||||
add_hook(uart_SendAsynch, &uart_SendAsynch_hook, ret0, NULL); //XXX Working
|
||||
|
||||
//hci uart rx
|
||||
patch_jump(&mpaf_hci_EventFilter, &ret0); //we dont want any hci events to be droped
|
||||
patch_jump(&uart_SetAndCheckReceiveAFF, &ret0); //there is never data available on uart
|
||||
patch_jump(&uart_DirectRead, &uart_DirectRead_hook);
|
||||
patch_jump(&uart_ReceiveSynch, &uart_ReceiveSynch_hook);
|
||||
|
||||
trace(uart_ReceiveAsynch, 3, true);
|
||||
trace(uart_DirectRead, 3, true);
|
||||
trace(uart_SendSynchHeaderBeforeAsynch, 4, false);
|
||||
trace(uart_SendAsynch, 4, true);
|
||||
trace(uart_SendSynch, 4, false);
|
||||
trace(uart_DirectWrite, 2, true);
|
||||
|
||||
|
||||
trace(btuarth4_RunTxStateMachines, 4, true);
|
||||
trace(bttransport_SendMsgToThread,2,false);
|
||||
trace(btu_hcif_hardware_error_evt,2,false);
|
||||
trace(mpaf_thread_PostMsgToHandler, 1, false);
|
||||
trace(bthci_lm_thread_SendMessageToThread, 1, false);
|
||||
trace(uart_SetupForRXDMA, 1, false);
|
||||
}
|
||||
|
||||
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,98 @@
|
||||
#include <frankenstein/hook.h>
|
||||
|
||||
#ifndef __LM_H
|
||||
#define __LM_H
|
||||
|
||||
|
||||
struct lm_cmd {
|
||||
short type;
|
||||
short maybe_subtype;
|
||||
void *arg;
|
||||
};
|
||||
|
||||
struct lcp_pckt {
|
||||
uint32_t unknwn0; //0x00
|
||||
uint32_t unknwn1; //0x4
|
||||
uint32_t unknwn2; //0x8
|
||||
unsigned char len; //0xd
|
||||
unsigned char unknwn3; //0xc
|
||||
uint16_t unknwn4; //0xe
|
||||
char data[];
|
||||
};
|
||||
|
||||
void lm_hook(struct saved_regs *regs, void *arg) {
|
||||
struct lm_cmd *lm_cmd = regs->r0;
|
||||
struct lcp_pckt *lcp;
|
||||
|
||||
//rssi report
|
||||
if (lm_cmd->type == 0xc) return;
|
||||
|
||||
//inthexdump(regs->r0, 8);
|
||||
print("lr = ");
|
||||
print_ptr(regs->lr);
|
||||
print(" lm_sendCmd(");
|
||||
print_ptr(lm_cmd->type);
|
||||
print(" | ");
|
||||
print_ptr(lm_cmd->maybe_subtype);
|
||||
print(" | ");
|
||||
print_ptr(lm_cmd->arg);
|
||||
print(");\n");
|
||||
|
||||
//lmulp_handleRxLcp
|
||||
if (lm_cmd->type == 0xe) {
|
||||
lcp = lm_cmd->arg;
|
||||
print("LCP: ");
|
||||
hexdump(lm_cmd->arg, 16); //hdr
|
||||
hexdump(lcp->data, lcp->len);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
void lmp_rx_hook(struct saved_regs *regs, void *arg) {
|
||||
print("lr = ");
|
||||
print_ptr(regs->lr);
|
||||
print(" lm_LmpReceived(");
|
||||
print_ptr(regs->r0);
|
||||
print(", ");
|
||||
hexdump(regs->r1, 4);
|
||||
print(" | ");
|
||||
hexdump(regs->r1 + 4, 24);
|
||||
print(");\n");
|
||||
}
|
||||
|
||||
void lmp_tx_hook(struct saved_regs *regs, void *arg) {
|
||||
print("lr = ");
|
||||
print_ptr(regs->lr);
|
||||
print(" DHM_LMPTx(");
|
||||
print_ptr(regs->r0);
|
||||
print(", ");
|
||||
hexdump(regs->r1, 12);
|
||||
print(" | ");
|
||||
hexdump(regs->r1 +12, 19);
|
||||
print(");\n");
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
void add_lm_hooks() {
|
||||
add_hook(lm_sendCmd, lm_hook, NULL, NULL);
|
||||
add_hook(lm_LmpReceived, lmp_rx_hook, NULL, NULL);
|
||||
add_hook(DHM_LMPTx, lmp_tx_hook, NULL, NULL);
|
||||
|
||||
trace(lm_LmpBBAcked, 2, false);
|
||||
trace(lm_HandleLmpBBAck, 2, false);
|
||||
trace(lm_sendCmdWithId, 1, false);
|
||||
trace(lm_LmpReceived, 2 ,false);
|
||||
trace(lm_HandleLmpReceivedPdu, 1, false);
|
||||
trace(rm_allocateACLConnPtr, 1, true);
|
||||
trace(rm_allocateLTCH, 1, true);
|
||||
trace(DHM_LMPTx, 2, false);
|
||||
trace(DHM_GetBasebandTxData, 2, true);
|
||||
trace(DHM_BasebandRx, 3, true);
|
||||
trace(lc_pageStart, 1, false);
|
||||
|
||||
bcs_add_hooks();
|
||||
}
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,142 @@
|
||||
#include <frankenstein/hook.h>
|
||||
|
||||
struct queue_access {
|
||||
uint32_t thread;
|
||||
uint32_t queue;
|
||||
uint32_t lr;
|
||||
};
|
||||
|
||||
|
||||
struct queue_access queue_read[1024];
|
||||
int queue_read_n = 0;
|
||||
void queue_read_access(struct saved_regs *regs, void *arg) {
|
||||
for (int i = 0; i < queue_read_n; i++)
|
||||
if ( queue_read[i].thread == _tx_thread_current_ptr &&
|
||||
queue_read[i].queue == regs->r0 &&
|
||||
queue_read[i].lr == regs->lr ) return;
|
||||
|
||||
//add access
|
||||
queue_read[queue_read_n].thread = _tx_thread_current_ptr;
|
||||
queue_read[queue_read_n].queue = regs->r0;
|
||||
queue_read[queue_read_n].lr = regs->lr;
|
||||
queue_read_n ++;
|
||||
|
||||
//dump
|
||||
print("queue read thread=");
|
||||
print_ptr(_tx_thread_current_ptr);
|
||||
print(" queue=");
|
||||
print_ptr(regs->r0);
|
||||
print(" lr=");
|
||||
print_ptr(regs->lr);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
struct queue_access queue_write[1024];
|
||||
int queue_write_n = 0;
|
||||
void queue_write_access(struct saved_regs *regs, void *arg) {
|
||||
for (int i = 0; i < queue_write_n; i++)
|
||||
if ( queue_write[i].thread == _tx_thread_current_ptr &&
|
||||
queue_write[i].queue == regs->r0 &&
|
||||
queue_write[i].lr == regs->lr ) return;
|
||||
|
||||
//add access
|
||||
queue_write[queue_write_n].thread = _tx_thread_current_ptr;
|
||||
queue_write[queue_write_n].queue = regs->r0;
|
||||
queue_write[queue_write_n].lr = regs->lr;
|
||||
queue_write_n ++;
|
||||
|
||||
//dump
|
||||
print("queue write thread=");
|
||||
print_ptr(_tx_thread_current_ptr);
|
||||
print(" queue=");
|
||||
print_ptr(regs->r0);
|
||||
print(" lr=");
|
||||
print_ptr(regs->lr);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
struct queue_access slist_read[1024];
|
||||
int slist_read_n = 0;
|
||||
void slist_read_access(struct saved_regs *regs, void *arg) {
|
||||
for (int i = 0; i < slist_read_n; i++)
|
||||
if ( slist_read[i].thread == _tx_thread_current_ptr &&
|
||||
slist_read[i].queue == regs->r0 &&
|
||||
slist_read[i].lr == regs->lr ) return;
|
||||
|
||||
//add access
|
||||
slist_read[slist_read_n].thread = _tx_thread_current_ptr;
|
||||
slist_read[slist_read_n].queue = regs->r0;
|
||||
slist_read[slist_read_n].lr = regs->lr;
|
||||
slist_read_n ++;
|
||||
|
||||
//dump
|
||||
print("slist read thread=");
|
||||
print_ptr(_tx_thread_current_ptr);
|
||||
print(" slist=");
|
||||
print_ptr(regs->r0);
|
||||
print(" lr=");
|
||||
print_ptr(regs->lr);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
struct queue_access slist_write[1024];
|
||||
int slist_write_n = 0;
|
||||
void slist_write_access(struct saved_regs *regs, void *arg) {
|
||||
for (int i = 0; i < slist_write_n; i++)
|
||||
if ( slist_write[i].thread == _tx_thread_current_ptr &&
|
||||
slist_write[i].queue == regs->r1 &&
|
||||
slist_write[i].lr == regs->lr ) return;
|
||||
|
||||
//add access
|
||||
slist_write[slist_write_n].thread = _tx_thread_current_ptr;
|
||||
slist_write[slist_write_n].queue = regs->r1;
|
||||
slist_write[slist_write_n].lr = regs->lr;
|
||||
slist_write_n ++;
|
||||
|
||||
//dump
|
||||
print("slist write thread=");
|
||||
print_ptr(_tx_thread_current_ptr);
|
||||
print(" slist=");
|
||||
print_ptr(regs->r1);
|
||||
print(" lr=");
|
||||
print_ptr(regs->lr);
|
||||
print("\n");
|
||||
}
|
||||
|
||||
void queue_add_hooks() {
|
||||
trace(msgqueue_Put, 2, false);
|
||||
trace(msgqueue_PutInFront, 2, false);
|
||||
trace(msgqueue_Get, 1, true);
|
||||
trace(msgqueue_GetNonblock, 1, true);
|
||||
|
||||
add_hook(&msgqueue_Get, &queue_read_access, NULL, NULL);
|
||||
add_hook(&msgqueue_PrivateGet, &queue_read_access, NULL, NULL);
|
||||
add_hook(&msgqueue_GetNonblock, &queue_read_access, NULL, NULL);
|
||||
add_hook(msgqueue_PrivateGet, queue_read_access, NULL, NULL);
|
||||
|
||||
|
||||
add_hook(&msgqueue_Put, &queue_write_access, NULL, NULL);
|
||||
add_hook(&msgqueue_PutInFront, &queue_write_access, NULL, NULL);
|
||||
|
||||
add_hook(osapi_sendQueueItem, &queue_read_access, NULL, NULL);
|
||||
add_hook(osapi_getQueueItem, &queue_write_access, NULL, NULL);
|
||||
add_hook(osapi_sendQueueItemToFront, &queue_write_access, NULL, NULL);
|
||||
|
||||
add_hook(osapi_getQueueItem_tx, &queue_read_access, NULL, NULL);
|
||||
add_hook(osapi_sendQueueItem_tx, &queue_write_access, NULL, NULL);
|
||||
add_hook(osapi_sendQueueItemToFront_tx, &queue_write_access, NULL, NULL);
|
||||
|
||||
add_hook(_tx_queue_receive, &queue_read_access, NULL, NULL);
|
||||
add_hook(_tx_queue_send, &queue_write_access, NULL, NULL);
|
||||
add_hook(_tx_queue_front_send, &queue_write_access, NULL, NULL);
|
||||
|
||||
|
||||
//add_hook(&slist_get, &slist_read_access, NULL, NULL); //Too short + misaligned
|
||||
//add_hook(&slist_tail, &slist_read_access, NULL, NULL); // Function too short
|
||||
add_hook(&slist_front, &slist_read_access, NULL, NULL);
|
||||
|
||||
add_hook(&slist_add_after, &slist_write_access, NULL, NULL);
|
||||
add_hook(&slist_add_front, &slist_write_access, NULL, NULL);
|
||||
add_hook(&slist_add_tail, &slist_write_access, NULL, NULL);
|
||||
add_hook(&slist_add_before, &slist_write_access, NULL, NULL);
|
||||
}
|
||||
@@ -0,0 +1,64 @@
|
||||
#ifndef TIMER_H
|
||||
#define TIMER_H
|
||||
#include "bcs.h"
|
||||
|
||||
//dump osapi timers
|
||||
void show_timers() {
|
||||
return;
|
||||
struct osapi_timer *timer = lm_osTimer;
|
||||
print("-------------------------\n");
|
||||
while (timer) {
|
||||
print_var(timer);
|
||||
print_var(timer->next);
|
||||
print_var(timer->callback);
|
||||
print_var(timer->maybe_type);
|
||||
print_var(timer->i2);
|
||||
print_var(timer->mpaf_exec_timer_arg);
|
||||
print_var(timer->i3);
|
||||
print_var(timer->time_offset_low);
|
||||
print_var(timer->time_offset_high);
|
||||
print_var(timer->i6);
|
||||
print_var(timer->i7);
|
||||
timer = timer->next;
|
||||
print("-------------------------\n");
|
||||
}
|
||||
//bcs_info();
|
||||
}
|
||||
|
||||
//hwo many us to wait unti next timer
|
||||
uint32_t next_timer_timestamp_us() {
|
||||
struct osapi_timer *timer = lm_osTimer;
|
||||
uint32_t current_time = clock_SystemTimeMicroseconds32_nolock();
|
||||
int32_t next_timer = lm_osTimer->time_offset_low - current_time;
|
||||
//print_var(current_time);
|
||||
//print_var(lm_osTimer->time_offset_low);
|
||||
//print_var(next_timer);
|
||||
return next_timer;
|
||||
}
|
||||
|
||||
|
||||
void check_and_handle_timers(uint32_t elapsed_time_us) {
|
||||
timer1value -= elapsed_time_us;
|
||||
if (next_timer_timestamp_us() < timer1value) return;
|
||||
print("\033[;31mTimer 2\033[;00m\n");
|
||||
show_timers();
|
||||
interruptvector_TIMER2_DONE();
|
||||
print("\033[;31mTimer 2 Done\033[;00m\n");
|
||||
}
|
||||
|
||||
|
||||
void add_timer_hooks() {
|
||||
trace(osapi_activateTimer, 2, false);
|
||||
trace(osapi_getTimerRemain, 1, true);
|
||||
trace(mpaf_osapi_timerCb, 1, false);
|
||||
//trace(clock_SystemTimeMicroseconds32, 1, false);
|
||||
//trace(clock_SystemTimeMicroseconds64, 1, true);
|
||||
//trace(clock_SystemTimeMicroseconds32_nolock, 1, false);
|
||||
//trace(clock_SystemTimeMicroseconds64_nolock, 1, true);
|
||||
trace(clock_serviceTimers,2 ,false);
|
||||
trace(mpaf_thread_PostMsgToHandler, 2, false);
|
||||
//trace(bcs_kernelTimerTick, 0 , false);
|
||||
trace(bcs_taskUnblock, 1, false);
|
||||
}
|
||||
|
||||
#endif
|
||||
@@ -7,7 +7,7 @@ MEMORY {
|
||||
Segment_0x440000 (rwx) : ORIGIN = 0x440000, LENGTH = 0x4000
|
||||
Segment_0x338000 (rwx) : ORIGIN = 0x338000, LENGTH = 0x8000
|
||||
Segment_0x650000 (rwx) : ORIGIN = 0x650000, LENGTH = 0x1000
|
||||
Segment_0x326000 (rwx) : ORIGIN = 0x326000, LENGTH = 0xa000
|
||||
Segment_0x450000 (rwx) : ORIGIN = 0x450000, LENGTH = 0x4000
|
||||
Segment_0x341000 (rwx) : ORIGIN = 0x341000, LENGTH = 0x1000
|
||||
Segment_0xe0000000 (rwx) : ORIGIN = 0xe0000000, LENGTH = 0x100000
|
||||
Segment_0x430000 (rwx) : ORIGIN = 0x430000, LENGTH = 0x4000
|
||||
@@ -16,7 +16,7 @@ MEMORY {
|
||||
Segment_0x370000 (rwx) : ORIGIN = 0x370000, LENGTH = 0x10000
|
||||
Segment_0x500000 (rwx) : ORIGIN = 0x500000, LENGTH = 0x41000
|
||||
Segment_0x350000 (rwx) : ORIGIN = 0x350000, LENGTH = 0x18000
|
||||
Segment_0x450000 (rwx) : ORIGIN = 0x450000, LENGTH = 0x4000
|
||||
Segment_0x326000 (rwx) : ORIGIN = 0x326000, LENGTH = 0xa000
|
||||
Segment_0x640000 (rwx) : ORIGIN = 0x640000, LENGTH = 0x800
|
||||
Segment_0x0 (rwx) : ORIGIN = 0x0, LENGTH = 0x280000
|
||||
Segment_0x390000 (rwx) : ORIGIN = 0x390000, LENGTH = 0x8000
|
||||
@@ -29,7 +29,7 @@ SECTIONS {
|
||||
.Segment_0x440000 0x440000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x440000.segment.o} > Segment_0x440000
|
||||
.Segment_0x338000 0x338000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x338000.segment.o} > Segment_0x338000
|
||||
.Segment_0x650000 0x650000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x650000.segment.o} > Segment_0x650000
|
||||
.Segment_0x326000 0x326000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x326000.segment.o} > Segment_0x326000
|
||||
.Segment_0x450000 0x450000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x450000.segment.o} > Segment_0x450000
|
||||
.Segment_0x341000 0x341000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x341000.segment.o} > Segment_0x341000
|
||||
.Segment_0xe0000000 0xe0000000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0xe0000000.segment.o} > Segment_0xe0000000
|
||||
.Segment_0x430000 0x430000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x430000.segment.o} > Segment_0x430000
|
||||
@@ -38,7 +38,7 @@ SECTIONS {
|
||||
.Segment_0x370000 0x370000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x370000.segment.o} > Segment_0x370000
|
||||
.Segment_0x500000 0x500000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x500000.segment.o} > Segment_0x500000
|
||||
.Segment_0x350000 0x350000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x350000.segment.o} > Segment_0x350000
|
||||
.Segment_0x450000 0x450000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x450000.segment.o} > Segment_0x450000
|
||||
.Segment_0x326000 0x326000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x326000.segment.o} > Segment_0x326000
|
||||
.Segment_0x640000 0x640000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x640000.segment.o} > Segment_0x640000
|
||||
.Segment_0x0 0x0:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x0.segment.o} > Segment_0x0
|
||||
.Segment_0x390000 0x390000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x390000.segment.o} > Segment_0x390000
|
||||
|
||||
@@ -6,6 +6,7 @@ gatt_find_bg_dev = 0x67a75;
|
||||
a2dp_findConn = 0x51c33;
|
||||
sdp_server_handle_client_req = 0xa2fb;
|
||||
lite_host_proc_start_req = 0xad3a7;
|
||||
pcx2_pbtclk = 0x318238;
|
||||
wiced_bt_avrc_msg_req = 0xd292d;
|
||||
ulp_advContentFilter = 0xa99e9;
|
||||
wiced_rtos_create_thread = 0xd33c9;
|
||||
@@ -4996,6 +4997,7 @@ wiced_audio_suspend = 0x468b3;
|
||||
SAM_SWITCH_INSTANT = 0x206828;
|
||||
afh_okToResumeConnection = 0x3f379;
|
||||
base64_encode = 0xd978b;
|
||||
pcx2_btclk = 0x31823c;
|
||||
puart_checkTxdPortPin = 0xbfeaf;
|
||||
lrm_FindOffsetWithMethod = 0x6e54f;
|
||||
slopeRxMon_lsb = 0x200e9a;
|
||||
@@ -5050,6 +5052,7 @@ bcsulp_mr4p_updateRssiRangeInfo = 0x64343;
|
||||
bcs_taskGetActivateSlot = 0x79dcf;
|
||||
lm_handleHciExitSniffMode = 0xb8427;
|
||||
bleconn_orig_secur_start = 0x36ff9;
|
||||
wiced_attach_sink_hci_channel = 0x5832d;
|
||||
bcsDataIdx = 0x201f1c;
|
||||
avct_ccb_dealloc = 0xcec83;
|
||||
bthci_cmd_cbb_HandleSet_Reserved_Lt_Addr = 0x149b7;
|
||||
@@ -5817,6 +5820,7 @@ pb_field_iter_begin = 0xc8931;
|
||||
bcs_afhHssiTaskDelete = 0x4be77;
|
||||
pwm_setInversion = 0xc19db;
|
||||
DHM_GetBBPktInfoPtr = 0x8741f;
|
||||
sr_ptu_status_adr4 = 0x360084;
|
||||
bthci_cmd_lc_HandleMaster_Link_Key = 0x2ec1d;
|
||||
g_chipspecific_config_Table = 0xe57e0;
|
||||
btm_ble_read_remote_features_complete = 0x35c9b;
|
||||
@@ -5922,6 +5926,7 @@ ulp_advFilterCheckLocName = 0xa9a7d;
|
||||
wiced_bt_ble_get_available_tx_buffers = 0xd32f5;
|
||||
lechan2_setChanInitChan2Bit = 0x969d1;
|
||||
BTMUtil_SetPktHwRegs = 0xb15b5;
|
||||
tx_pkt_info = 0x318acc;
|
||||
avdt_scb_chk_snd_pkt = 0xd16f9;
|
||||
rm_getMasterPiconetCountAllSecureConnections = 0x76089;
|
||||
avrc_proc_far_msg = 0xcb7dd;
|
||||
@@ -6032,6 +6037,7 @@ DHM_ProcLmpQueueAfterMss = 0x16fc9;
|
||||
gatt_sr_get_attr_ptr = 0x582af;
|
||||
bleconn_start_conn_with_peer = 0x36ee9;
|
||||
bthci_cmd_vs_HandleWrite_RAM = 0xa0169;
|
||||
rtx_dma_ctl = 0x314018;
|
||||
spiffy_exchangeData = 0x9ed5f;
|
||||
g_mws_type6_subframe_mask = 0x206a10;
|
||||
PORT_ParNegInd = 0x262f1;
|
||||
@@ -6107,6 +6113,7 @@ ape_g = 0xbac41;
|
||||
lmulp_handleRxLcpVSFeatureRsp = 0x9a307;
|
||||
wiced_bt_mesh_create_event_ptr = 0x205ebc;
|
||||
port_rfc_send_tx_data = 0x26631;
|
||||
phy_status = 0x314004;
|
||||
avrc_bld_set_addr_player_cmd = 0xcc5fb;
|
||||
_printf_x = 0xe5733;
|
||||
_sniffTaskLcuSoftReset = 0x84357;
|
||||
@@ -6937,6 +6944,7 @@ GATTC_ConfigureMTU = 0x4fb6d;
|
||||
bt_config_RegisterGroup = 0x1c4b9;
|
||||
ef_system_power_mode_notification_callback_patch = 0x272c7f;
|
||||
pb_decode_varint = 0xc8b51;
|
||||
dc_x_clk = 0x3186ac;
|
||||
rmulp_multiAdvReset = 0x7c2c3;
|
||||
wiced_rtos_init_mutex = 0xd344f;
|
||||
wiced_audio_set_sinwave = 0x51181;
|
||||
@@ -7256,6 +7264,7 @@ bthci_event_vs_Sam_SendLocalSlotmapDiagnosticData = 0x1342f;
|
||||
pmu_PeriodicTimerLeft = 0x2139f;
|
||||
spiPortConfig = 0x2065a4;
|
||||
lmulp_sendStartEncryptionReq = 0x9a7b5;
|
||||
sr_status = 0x31400c;
|
||||
mpaf_tran_ResumeHost = 0x94487;
|
||||
LeAudioOffloadingSetting = 0x2074dc;
|
||||
btm_ble_set_ext_adv_params = 0x4905b;
|
||||
@@ -7373,7 +7382,7 @@ wiced_rtos_push_to_queue = 0xd34c5;
|
||||
ape_isDebugPublicKey = 0xbaee3;
|
||||
_micro_bcsEstimateSdsSbTime = 0x7e1f1;
|
||||
btu_hcif_connection_request_evt = 0x22989;
|
||||
wiced_attach_sink_hci_channel = 0x5832d;
|
||||
pcx_btclk = 0x31822c;
|
||||
last_bt_sig_type_7_byte = 0x20696d;
|
||||
wiced_bt_dev_get_security_state = 0x82dc5;
|
||||
pcm2_down = 0x9aae9;
|
||||
@@ -8575,6 +8584,7 @@ bthci_cmd_status_HandleRead_Rssi = 0x14c27;
|
||||
vadBurstCount = 0x2067d0;
|
||||
btm_ble_periodic_advertising_terminate_sync = 0x493d3;
|
||||
lculp_handleResolvingReport = 0x8c137;
|
||||
dc_nbtc_clk = 0x318088;
|
||||
bcsTaskWakeupTaskSwitchPclk = 0x205d84;
|
||||
ConvertLmpOffsetToRealOffset = 0xbeeb5;
|
||||
lculp_advGetType = 0xac87f;
|
||||
@@ -8778,6 +8788,7 @@ lower_transport_layer_handle_ptr = 0x205ea8;
|
||||
bthci_cmd_vs_SetupRSSLocalCommands = 0xa1941;
|
||||
lm_sam_SendLmpSamDefineMap = 0x98b25;
|
||||
bthci_cmd_vs_SleepForeverMode = 0x9fc45;
|
||||
pkt_log = 0x318b2c;
|
||||
quad_enableInterrupt = 0x4aab;
|
||||
rom_newConnTaskCallback = 0xf75bc;
|
||||
friend_has_nid_ptr = 0x205e94;
|
||||
@@ -9684,6 +9695,7 @@ KeyscanInt_C = 0x9b997;
|
||||
bcs_pmuWaitForBtClock = 0x76b57;
|
||||
rss_le2m_flush_num = 0x207575;
|
||||
_connTaskTxDone = 0x72769;
|
||||
rtx_mem_start1 = 0x370400;
|
||||
_antTaskCheckScheduleLate = 0x20105;
|
||||
inqScanTask_iac = 0x202238;
|
||||
lmulp_cbTerminateINDAcked = 0xbd909;
|
||||
@@ -10153,6 +10165,7 @@ bcsulp_connTaskSlaveActive = 0x72c9d;
|
||||
btm_ble_deq_resolving_pending = 0x2b29d;
|
||||
SBC_Decoder_Update_PLC = 0x89645;
|
||||
lculp_advSetMinInterval = 0xac85d;
|
||||
pkt_hdr_status = 0x318b28;
|
||||
gatt_send_error_rsp = 0x674d3;
|
||||
bthci_cmd_status_HandleWrite_Remote_Amp_assoc = 0x14db7;
|
||||
g_lrmHIDBlockInfo = 0x20ec84;
|
||||
@@ -10673,6 +10686,7 @@ _afhRssiScanTaskDelete = 0x4c24b;
|
||||
bbPorInq_accCode = 0x200d90;
|
||||
_lm_sam_InitializeSlotmapsForESam = 0x98699;
|
||||
avdt_ccb_hdl_start_cmd = 0xd2451;
|
||||
tx_pkt_pyld_hdr = 0x318ad0;
|
||||
COEX_BLE_3_2_T1_TIME_CONN_FIRST_TXN = 0x2068a3;
|
||||
bcs_aclInit = 0x187d5;
|
||||
mcsTaskCallback = 0x206a68;
|
||||
@@ -12178,6 +12192,7 @@ ulp_brcmFilter_delListItem = 0xa9e33;
|
||||
apipe_unMuteFunc = 0x5400d;
|
||||
_printf_string = 0xc3609;
|
||||
scanRssiThresholdDeviceListSize = 0x206cce;
|
||||
rtx_rx_buffer = 0x370c00;
|
||||
sdpu_build_attrib_entry = 0xa6f9;
|
||||
iqcal_mainReplace = 0x207178;
|
||||
smp_sl_wait_app_rsp_table = 0xe7c68;
|
||||
|
||||
@@ -107,19 +107,8 @@ void xmit_memory(struct saved_regs *regs, int cont) {
|
||||
Found Map 0x23dc1900 - 0x23dc2000
|
||||
Found Map 0x23dc3400 - 0x23dc4a00
|
||||
Found Map 0x23dc4e00 - 0x23dc5700
|
||||
|
||||
TODO i think it was running until 0x41.... without further results
|
||||
TODO restarted it at 0x40000000 and it didn't find something
|
||||
*/
|
||||
|
||||
//Those segments seem not to be relevant
|
||||
//hci_xmit_segment(0x20000000, 0x20250000);
|
||||
//hci_xmit_segment(0x20270000, 0x20284000);
|
||||
//hci_xmit_segment(0x20500000, 0x20600000);
|
||||
//hci_xmit_segment(0x22000000, 0x24000000);
|
||||
//hci_xmit_segment(0x40000000, 0x40004000); //base_ToRam_alias_adr
|
||||
//hci_xmit_segment(0x42000000, 0x42080000); //base_ToRam_bit_band_adr
|
||||
|
||||
hci_xmit_segment(0xe0000000, 0xe0100000); //ppb
|
||||
|
||||
//Notify Done
|
||||
|
||||
@@ -6278,7 +6278,9 @@
|
||||
"dbfw_warning_flag": 2120552,
|
||||
"dbguart_read": 160315,
|
||||
"dcSmplCtlDefault": 2107796,
|
||||
"dc_nbtc_clk": 3244168,
|
||||
"dc_ptu_uart_lsr": 3540004,
|
||||
"dc_x_clk": 3245740,
|
||||
"deactivate_threadX_tick_timer": 48673,
|
||||
"debugPrintMissed": 2127324,
|
||||
"debuguart_Enable": 160265,
|
||||
@@ -10063,6 +10065,9 @@
|
||||
"pcm_scoLinkUp": 525691,
|
||||
"pcmfifo_getRxDataSize": 552155,
|
||||
"pcmfifo_getTxDataSize": 552217,
|
||||
"pcx2_btclk": 3244604,
|
||||
"pcx2_pbtclk": 3244600,
|
||||
"pcx_btclk": 3244588,
|
||||
"pcx_reg_backup": 2129040,
|
||||
"pds_PreSleepControlSettingsHW": 565249,
|
||||
"pds_RestoreControlSettingsHW": 565317,
|
||||
@@ -10072,6 +10077,7 @@
|
||||
"pds_pre_sleep_data": 2119560,
|
||||
"peripheralUart_HandleTxEvent": 785897,
|
||||
"permute": 804093,
|
||||
"phy_status": 3227652,
|
||||
"phy_status_shadow": 2104364,
|
||||
"pic_config_Group": 2109844,
|
||||
"pic_config_HandleDynReloTable": 2558065,
|
||||
@@ -10108,6 +10114,8 @@
|
||||
"pktErrIns": 2105176,
|
||||
"pktTypeOffsets": 1013560,
|
||||
"pktTypeSlotCount": 1011244,
|
||||
"pkt_hdr_status": 3246888,
|
||||
"pkt_log": 3246892,
|
||||
"plcApuFilter": 2125984,
|
||||
"plcConfig": 2125957,
|
||||
"plcHandleRxData": 370627,
|
||||
@@ -10961,6 +10969,9 @@
|
||||
"rtc_sec2RtcTime": 54607,
|
||||
"rtc_setRTCTime": 54563,
|
||||
"rtc_setReferenceTime": 54545,
|
||||
"rtx_dma_ctl": 3227672,
|
||||
"rtx_mem_start1": 3605504,
|
||||
"rtx_rx_buffer": 3607552,
|
||||
"rxCordicBaseHi_adr_save": 2115660,
|
||||
"rxCordicBaseLo_adr_save": 2115656,
|
||||
"rxHeaderDoneDelayTime": 2126906,
|
||||
@@ -11636,6 +11647,8 @@
|
||||
"spiffyd_txHalfWord": 567563,
|
||||
"spiffyd_txWord": 567585,
|
||||
"split_proxy_ptr": 2121480,
|
||||
"sr_ptu_status_adr4": 3539076,
|
||||
"sr_status": 3227660,
|
||||
"sr_status_shadow": 2104368,
|
||||
"srand": 939641,
|
||||
"ssl_mac_md5": 897981,
|
||||
@@ -11824,6 +11837,8 @@
|
||||
"tssical_wrPadgc": 796703,
|
||||
"txDirectModFreqAdj1_reg": 2123372,
|
||||
"tx_application_define": 4297,
|
||||
"tx_pkt_info": 3246796,
|
||||
"tx_pkt_pyld_hdr": 3246800,
|
||||
"txnCollisionTbl": 996728,
|
||||
"u16toHexStr": 519933,
|
||||
"u32toHexStr": 519955,
|
||||
|
||||
Reference in New Issue
Block a user