diff --git a/NewProject.md b/NewProject.md index 0932d92..0ed699d 100644 --- a/NewProject.md +++ b/NewProject.md @@ -248,11 +248,32 @@ arm-none-eabi-ld: cannot find gen/internalBlue_11.07.2019_13.52.37/Segment_0x420 make: *** [Makefile:28: gen/execute.exe] Error 1 ``` -Happens due to executing as root to access hci0 on Linux: +Happens due to executing as root to access hci0 on Linux, we need to change permissions on this file: ``` './segment_groups/internalBlue_11.07.2019_13.52.37': Permission denied ``` +Afterwards, the following registers are missing: + +``` +dc_nbtc_clk = 0x00318088; +dc_x_clk = 0x003186ac; +pcx_btclk = 0x0031822c; +pcx2_btclk = 0x0031823c; +pcx2_pbtclk = 0x00318238; +phy_status = 0x00314004; +pkt_hdr_status = 0x00318b28; +pkt_log = 0x00318b2c; +rtx_dma_ctl = 0x00314018; +rtx_mem_start1 = 0x00370400; +rtx_rx_buffer = 0x00370c00; +sr_status = 0x0031400c; +sr_ptu_status_adr4 = 0x00360084; +tx_pkt_info = 0x00318acc; +tx_pkt_pyld_hdr = 0x00318ad0; +``` + + Debugging notes --------------- diff --git a/projects/CYW20819A1/emulation/bcs.h b/projects/CYW20819A1/emulation/bcs.h new file mode 100644 index 0000000..b88f13f --- /dev/null +++ b/projects/CYW20819A1/emulation/bcs.h @@ -0,0 +1,407 @@ +#ifndef BCS_H +#define BCS_H + + +#define HW_PHY_STATUS_RX_DONE 0x0001 +#define HW_PHY_STATUS_RX_HEADER_DONE 0x0002 +#define HW_PHY_STATUS_TX_DONE 0x0004 +#define HW_PHY_STATUS_PROG_INT0 0x0008 //Slot11 + Timer + bcs_kernel +#define HW_PHY_STATUS_PROG_INT1 0x0010 //Slot01 +#define HW_PHY_STATUS_PROG_INT2 0x0020 +#define HW_PHY_STATUS_PROG_INT3 0x0040 +#define HW_PHY_STATUS_WCS_COEX_INT 0x0100 +#define HW_PHY_STATUS_WCS_COEX_DEFERRED 0x0200 +#define HW_PHY_STATUS_PROG_INT_ALL 0x0078 + + +extern char* dmaActiveRxBuffer; +char *tx_dma_data; +int tx_dma_len; + + +int wait_for_ack = 1; +void bcs_dma_hook(struct saved_regs *regs, void *arg) { + int data, len; + if ((int)arg & 2) { + print("Eir "); + data = regs->r0; + len = regs->r1; + } + else { + data = *(uint32_t *)(regs->r0 + 16); + len = (*(uint32_t *)(regs->r0 + 10) >> 3 & 0x3ff); + } + if ((int)arg & 1) print ("Tx: ") + else { + /* + print("Rx: "); + print_ptr(data); + print(" | "); + print_ptr(len); + print("\n"); + */ + return; + } + + /* + hexdump(&pc_acscd_lo, 4); + hexdump(&pc_acscd_hi, 4); + print(" | "); + */ + hexdump(&tx_pkt_info, 4); + print(" | "); + hexdump(&tx_pkt_pyld_hdr, 2); + print(" | "); + hexdump(data, len); + print("\n"); + tx_dma_len = len; + tx_dma_data = data; + + wait_for_ack = 1; + + /* + Rx Test + */ +} + +#ifdef EMULATED +void clear_phy_status(struct saved_regs *regs, void *arg) { + int intmask = regs->r0; + if (intmask & 0x7800) phy_status &= ~((intmask>>8) & 0x78); + if (intmask & 0x400000) phy_status &= ~HW_PHY_STATUS_RX_HEADER_DONE; + if (intmask & 0x400) phy_status &= ~HW_PHY_STATUS_RX_DONE; + if (intmask & 1) phy_status &= ~HW_PHY_STATUS_TX_DONE; + if (intmask & 0xe) sr_status &= ~((intmask>>1) & 0x7); +} + +#endif + +void print_bcs_list_entry(uint32_t *current) { + print("-----------------------------------\n"); + print_var(current); + print_var(current[-1]); + print_var(current[0]); //next + print_var(current[1]); //prev + print_var(current[2]); + print_var(current[3]); + print_var(current[4]); + print_var(current[5]); //end of struct? + print_var(((char*)current)[0x10]); + print_var(((char*)current)[0x11]); +} + +extern int eci_status; +extern int eci_status_b; +void bcs_info() { + uint32_t *current; + if (tb) { + print_var(tb); + print_var(bcs_taskGetTaskType(tb)); + } + + //print_var(eci_status); + //print_var(eci_status_b); + //print_var(rtx_dma_ctl); + print_var(dlist_count(taskTimerList)); + print_var(dlist_count(taskTransientStateList)); + print_var(dlist_count(taskReadyList)); + print_var(dlist_count(taskActiveList)); + print_var(dlist_count(slotCbEntryList)); + + print("-----------------------------------\n"); + print("current_task\n"); + print_bcs_list_entry(tb); + + print("-----------------------------------\n"); + print("active_list\n"); + for (current = (uint32_t*) taskActiveList; current != &taskActiveList; current = current[0]) + print_bcs_list_entry(current); + + print("-----------------------------------\n"); + print("taskTransientStateList\n"); + for (current = (uint32_t*) taskTransientStateList; current != &taskTransientStateList; current = current[0]) + print_bcs_list_entry(current); + + print("-----------------------------------\n"); + print("taskReadyList\n"); + for (current = (uint32_t*) taskReadyList; current != &taskReadyList; current = current[0]) + print_bcs_list_entry(current); + + + print("-----------------------------------\n"); + print("timer\n") + current = (uint32_t*) taskTimerList; + while (current != &taskTimerList) { + print("-----------------------------------\n"); + print_var(current); + print_var(current[-2]); + print_var(current[-1]); + print_var(current[0]); //next + print_var(current[1]); //prev + print_var(current[2]); + print_var(current[3]); + print_var(current[4]); + print_var(current[5]); + print_var(current[6]); + print_var(current[7]); + print_var(current[8]); + print_var(current[9]); //maybe callback + print_var(current[10]); + print_var(current[11]); + print_var(current[12]); + print_var(current[13]); + + current = current[0]; + + } + + print("-----------------------------------\n"); + print("slotcb\n") + current = (uint32_t*) slotCbEntryList; + while (current != &slotCbEntryList) { + print("-----------------------------------\n"); + print_var(current); + print_var(current[-1]); + print_var(current[0]); + print_var(current[1]); + print_var(current[2]); + print_var(current[3]); + print_var(current[4]); + print_var(current[5]); + print_var(current[6]); + current = current[0]; + } + +} + +/* +Advance bt clock by one tick (312.5 us) +*/ + +extern int pcx2_pbtclk; +extern int pcx2_btclk; +extern int dc_nbtc_pclk; + +void bcs_advance_clock() { + pcx_btclk ++; //*(int*) (0x31822c) += 1; + pcx2_pbtclk ++; + pcx2_btclk ++; + dc_nbtc_clk ++; //*(int*) (0x318088) += 1; + dc_x_clk ++; + //dc_nbtc_pclk ++; +} + + + +/* +Dummy task performing random actions +*/ +void bcs_dummy() { + read(0, 0x370000, 16); + read(0, &sr_status, 2); + read(0, &phy_status, 2); + read(0, &pkt_hdr_status, 2); + read(0, &pkt_log, 2); + pkt_hdr_status |= 0x40000; + pkt_log |= 0x40000; + + print_var(pkt_hdr_status); + print_var(pkt_log); + print_var(phy_status); + print_var(sr_status); + bluetoothCoreInt_C(); + contextswitch(); + + return; +} + +#include "bcs/inq.h" +#include "bcs/acl.h" +#include "bcs/page.h" +#include "bcs/le.h" +void bcs_tick() { + /* + srstatus + 1 = fsmdone + 0x10 = lcuSubstate Active + + */ + + bcs_advance_clock(); + + //bcs_info(); + if (tb == 0x2822e0) //TODO + { print("tb = pageScan\n"); pagescan(); } + else if (tb == 0x20a9c8) //TODO + {print("tb = page\n"); page(); } + else if (tb == 0x282250) //TODO + print("tb = inqScan\n") + else if (tb == 0x20a8e8) //TODO + { print("tb = inq\n"); inquiry(); } + else if (tb == 0x205914) //TODO + { print("tb = tca\n"); bcs_dummy(); } + else if (tb == 0x281068) //TODO + { print("tb = acl\n"); acl(); } + else if (tb == 0x22539c) //TODO + { print("tb = conntask?\n"); bcs_dummy(); } + else if (tb == 0x28218c) //TODO + { print("tb = afhRssiScan\n");} + + //LE + else if (tb == 0x2828b0) //TODO + { print("tb = adv\n"); adv();} + else if (tb == 0x283300) //TODO + { print("tb = bcsulp_scan\n"); le_scan();} + else if (tb == 0x283278) //TODO + { print("tb = bcsulp_init\n"); le_scan();}//page_fd = 0; pagescan(); page_fd=-1;} + else if (tb == 0x281618) //TODO + { print("tb = le_conn\n"); le_conn();} + else + print_var(tb); + + + //Slot01 / Slot11 + if ((pcx_btclk & 3) == 0b01){ + print("Slot01\n"); + sr_status = (tb == 0x281068) ? 0x1d8 : 0x1c8; + phy_status = 0x10; + bluetoothCoreInt_C(); + contextswitch(); + } + if ((pcx_btclk & 3) == 0b11){ + print("Slot11\n"); + sr_status = (tb == 0x281068) ? 0x1d8 : 0x1c8; + phy_status = 0x68; + bluetoothCoreInt_C(); + contextswitch(); + } + return; +} + +void _dhmulp_getTxLcp(); + + +void bcs_add_hooks() { + #ifdef EMULATED + add_hook(intctl_ClrPendingInt, clear_phy_status, NULL, NULL); + #endif + + patch_return(btclk_DelayXus); + patch_return(btclk_AdvanceNatClk_clkpclkHWWA); + patch_return(0x0009b104); //TODO + patch_return(0x0009b38a); //TODO + patch_return(0x0009b35c); //TODO + patch_return(0x9b414); //TODO + patch_return(0x9b3da); //TODO + patch_return(0x40cda); //TODO + //patch_return(&_afhPipelineRssiScanTaskSlotInt); + + trace(bcs_dmaGetRxBuffer, 3, false); + trace(bcs_dmaRxEnableEir, 2, false); + trace(bcs_dmaTxEnableEir, 2, false); + trace(bcs_dmaRxEnable, 2, true); + trace(bcs_dmaTxEnable, 1, false); + trace(bcs_dmaRxDisable, 0, true); + trace(bcs_dmaGetRxBuffer, 1, true); + trace(bcs_utilBbRxPyldHdr, 2, true); + trace(bcs_dmaRxBufferRecycle, 1, false); + trace(btclk_AdvanceNatClk_clkpclkHWWA, 1, false); + + trace(bcs_kernelTimerTick, 0, false); //called at 0x95693 0x40637 + trace(bcs_kernelRxHeaderDone, 0, false); + trace(bcs_kernelRxDone, 0, false); + trace(bcs_kernelSlotCbFunctions, 0, false); + + //Called quite often, therefore disabled + //trace(bcs_isrFsmDoneInt, 0, false); + //trace(bcs_isrSlot01Int, 0, false); + //trace(bcs_isrSlot11Int, 0, false); + //trace(bcs_isrTxDoneInt, 0, false); + //trace(bcs_isrRxDoneInt, 0, false); + //trace(bcs_isrRxHeaderDoneInt, 0, false); + + + trace(bcs_pageTaskCreate, 3, false); + trace(dhmulp_LcpTx, 3, false); + trace(DHM_TxDataAvail,0,false); + trace(dhmulp_getTxBuffer, 3, false); + trace(DHM_GetBasebandTxData, 2, false); + trace(bcs_utilBbRxPktHdrCheck, 2, false); + trace(DHM_ACLAckRcvd, 1, false); + trace(DHM_SetAclTxPktAckRcvd, 1, false); + trace(DHM_isTxLmpListEmpty, 1, true); + trace(DHM_GetBasebandRxBuffer, 2, false); + trace(DHM_releaseTxLmpList, 4, false); + trace(_dhmSlotCbFunc, 1, false); + + //acl + trace(bcs_aclTaskCreate, 2, false); + trace(_aclTaskSetupTxBuffer, 4, false); + trace(_aclTaskRxHeaderDone, 1, false); + trace(_aclTaskRxDone, 1, false); + trace(_aclTaskLcuCmd, 1, false); + trace(_aclTaskFsmSetup, 1, false); + trace(_aclTaskProcessRxPacket, 1, false); + trace(_aclTaskSwitch, 1, false); + + //eir + trace(eir_handleRx, 1, false); + trace(eir_handleTx, 1, false); + + trace(_inqTaskRxHeaderDone, 1, false); + trace(_inqTaskRxDone, 1, false); + + trace(_dmaReqSend, 1, false); + trace(dma_RequestTransfer, 1, false); + + add_hook(bcs_dmaRxEnable, bcs_dma_hook, NULL, 0); + add_hook(bcs_dmaTxEnable, bcs_dma_hook, NULL, 1); + add_hook(bcs_dmaRxEnableEir, bcs_dma_hook, NULL, 2); + add_hook(bcs_dmaTxEnableEir, bcs_dma_hook, NULL, 3); + trace(bcs_dmaIsTransferComplete, 2, false); + + trace(_pageTaskFsmDone, 3, false); + trace(_pageScanTaskFsmDone, 3, false); + trace(bcs_newConnTaskCreate, 3, false); + + //Methods are actually too short to set hooks + //trace(bluerf_Wr, 2, false); + //trace(bluerf_Rd, 1, true); + trace(bpl_lcu_Cmd, 2, false); + trace(bpl_lcu_setPHY, 4, false); + trace(bcs_kernelBtProgIntEnable, 4, false); + + trace(bcs_pageTaskCreate, 3, false); + trace(bcs_pageScanTaskCreate, 3, false); + trace(bcs_SlotCbFunctions, 0, false); + + //LE + trace(_advTaskRxDone, 3, false); + trace(_scanTaskRxDone, 3, false); + trace(bcsulp_passRxPktUp, 3, false); + trace(bcsulp_procRxPayload, 2, false); + trace(bcsulp_getPktLength, 2, true); + trace(bcsulp_setupRxBuffer, 0, true); + trace(bcsulp_returnRxBuffer, 0, false); + trace(mmulp_allocACLUp, 1, true); + trace(mmulp_allocACLDown, 1, true); + trace(dhmulp_getRxBuffer, 1, true); + //trace(_connTaskLcuCmd_addin, 3, true); //Does no longer exist in CYW20819A1 + trace(_connTaskLcuCmd, 3, true); + trace(_connTaskSlotInt, 3, true); + trace(mmulp_freeLEABuffer, 1, true); + trace(dhmulp_returnRxBuffer, 1, false); + trace(_dhmulp_getTxLcp, 2, true); + + //Inquiry + trace(eir_eirInqFHS, 1, false); + trace(eir_getReceivedEIR, 1, false); + trace(bthci_event_SendInquiryResultEvent, 1, false); + trace(lm_sendInqFHS, 1, false); + trace(lm_handleInqFHS, 1, false); + trace(lc_handleInqResult, 1, false); + trace(inqfilter_isBdAddrRegistered, 2, false); + trace(inqfilter_registerBdAddr, 2, false); + +} +#endif diff --git a/projects/CYW20819A1/emulation/bcs/acl.h b/projects/CYW20819A1/emulation/bcs/acl.h new file mode 100644 index 0000000..0b364ec --- /dev/null +++ b/projects/CYW20819A1/emulation/bcs/acl.h @@ -0,0 +1,206 @@ +int acl_fd = 0; + +#define ACL_ROLE_MASTER 0 +#define ACL_ROLE_SLAVE 1 + +int acl_role = ACL_ROLE_SLAVE; //the snapshot I've taken had an open acl slave connection + +int injected = 0; + +void acl() { + if (acl_fd == -1) return; + + if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b10 ) || + ( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b00 ) ){ + + + print("Tx Done\n"); + sr_status = 0x1d8; + phy_status = 0x4; + bluetoothCoreInt_C(); + contextswitch(); + + print("TxDone: "); + print_ptr(tx_pkt_info & 0xffff); + print(" | "); + print_ptr(tx_pkt_pyld_hdr & 0xffff); + print(" | "); + hexdump(tx_dma_data, tx_dma_len); + print("\n"); + hexdump(rtx_mem_start1, 32); + print("\n"); + + int pyld_hdr = tx_pkt_pyld_hdr << 2; + write(acl_fd, &tx_pkt_info, 2); + write(acl_fd, &pyld_hdr, 2); + write(acl_fd, tx_dma_data, 512); + print_var((tx_pkt_pyld_hdr >> 2) & 0x3ff) + } + + //Rx Hdr Int + if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b00 ) || + ( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b10 ) ){ + print("Rx Hdr Done\n"); + sr_status = 0x1c8; + phy_status = 0x3; + + pkt_hdr_status = pkt_log = 0; + if ( read(acl_fd, &pkt_hdr_status, 2) == 0) exit(1); + read(acl_fd, &pkt_log, 2); + pkt_hdr_status |= 0x40000; + pkt_log |= 0x40000; + + //if (rtx_dma_ctl == 1) { + // sr_status = 0x1d8; + // phy_status = 0x2; + + // ////Acknowledge Packet ACL Specific? + // ////print_var(wait_for_ack) + // //if (wait_for_ack) { + // // wait_for_ack = 0; + + // // pkt_hdr_status = tx_pkt_info | 0x40000; + // // pkt_hdr_status |= 0x1 << 8; //ARQN + // // pkt_hdr_status ^= 0x1 << 9; //SEQ + + // // pkt_log = tx_pkt_pyld_hdr; + // // pkt_log = pkt_log << 2; + // // if (tx_pkt_pyld_hdr == 0x11a && (pcx_btclk & 0xff) == 0) + // // pkt_log = pkt_log | 0x40000; + // //} + // ////ACL Inject packet + // //else if(!injected) { + // // pkt_hdr_status = 0x40000; + // // pkt_hdr_status |= 0x0; //LT_ADDR + // // pkt_hdr_status |= 0x3 << 3; //Type + // // pkt_hdr_status |= 0x1 << 7; //Flow + // // pkt_hdr_status |= 0x1 << 8; //ARQN + // // pkt_hdr_status |= 0x1 << 9; //SEQ + // // pkt_hdr_status |= 0xf00; //HEC + // // pkt_log = 0x1f << 2 | 0x40000; //payload_hdr + // // injected = 1; + // //} else { + // // injected --; + // //} + //} + + + print_var(pkt_hdr_status); + print_var(pkt_log); + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Interrupt + //if(rtx_dma_ctl == 1 && (pcx_btclk & 3) == 0b01) { + int len; + //if((pcx_btclk & 3) == 0b01) { + if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b01 ) || + ( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b11 ) ){ + print("Rx Done\n"); + sr_status = 0x1c8; + phy_status = 0x1; + + //len = (pkt_log >> 5) & 0x1f; + len = (pkt_log >> 5) & 0x3ff; + len = 128; + print_var(len); + + if (rtx_dma_ctl != 3 && dmaActiveRxBuffer) { + if (read(acl_fd, dmaActiveRxBuffer+4, len) < 1) exit(1); + print_var(dmaActiveRxBuffer); + //for (unsigned char i=0; i < 240; i++) dmaActiveRxBuffer[i] = i; + print("pcktdata (DMA): "); + hexdump(dmaActiveRxBuffer, len); + print("\n"); + } + else { + print("pcktdata: "); + read(acl_fd, 0x370000, len); + hexdump(0x370000, len); + print("\n"); + } + + bluetoothCoreInt_C(); + contextswitch(); + } +} + +/* +void acl_over_tcp() { + if (acl_fd == -1) return; + + if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b10 ) || + ( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b00 ) ){ + + print("Tx Done\n"); + sr_status = 0x1d8; + phy_status = 0x4; + bluetoothCoreInt_C(); + contextswitch(); + + print("TxDone: "); + hexdump(&tx_pkt_info, 4); + print(" | "); + hexdump(&tx_pkt_pyld_hdr, 2); + print("\n"); + } + + //Rx Hdr Int + if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b00 ) || + ( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b10 ) ){ + print("Rx Hdr Done\n"); + sr_status = 0x1c8; + phy_status = 0x3; + + if ( read(acl_fd, &pkt_hdr_status, 2) == 0) exit(1); + read(acl_fd, &pkt_log, 2); + pkt_hdr_status |= 0x40000; + pkt_log |= 0x40000; + + if (rtx_dma_ctl == 1) { + sr_status = 0x1d8; + phy_status = 0x2; + + } + + print_var(pkt_hdr_status); + print_var(pkt_log); + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Interrupt + //if(rtx_dma_ctl == 1 && (pcx_btclk & 3) == 0b01) { + int len; + //if((pcx_btclk & 3) == 0b01) { + if (( acl_role == ACL_ROLE_SLAVE && (pcx_btclk & 3) == 0b01 ) || + ( acl_role == ACL_ROLE_MASTER && (pcx_btclk & 3) == 0b11 ) ){ + print("Rx Done\n"); + sr_status = 0x1c8; + phy_status = 0x1; + + //len = (pkt_log >> 5) & 0x1f; + len = (pkt_log >> 5) & 0x3ff; + len = 128; + + if (rtx_dma_ctl != 3 && dmaActiveRxBuffer) { + if (read(0, dmaActiveRxBuffer, len) < 1) exit(1); + print_var(dmaActiveRxBuffer); + //for (unsigned char i=0; i < 240; i++) dmaActiveRxBuffer[i] = i; + print("pcktdata: "); + hexdump(dmaActiveRxBuffer, len); + print("\n"); + } + else { + print("pcktdata: "); + read(0, 0x370000, len); + hexdump(0x370000, len); + print("\n"); + } + + bluetoothCoreInt_C(); + contextswitch(); + } +} +*/ diff --git a/projects/CYW20819A1/emulation/bcs/inq.h b/projects/CYW20819A1/emulation/bcs/inq.h new file mode 100644 index 0000000..98e2514 --- /dev/null +++ b/projects/CYW20819A1/emulation/bcs/inq.h @@ -0,0 +1,98 @@ +int inq_fd = 0; + +int timeout = 10; +void inquiry() { + if (inq_fd == -1) return; + + //hci_tx_fd = -1; + //hci_rx_fd = -1; + //xmit_state_emu("gen/inq.exe"); + //if (timeout-- < 0) exit(0); + + + if ((pcx_btclk & 3) == 0b10){ + print("Tx Done\n"); + sr_status = 0x1d8; + phy_status = 0x4; + bluetoothCoreInt_C(); + contextswitch(); + } + + if ((pcx_btclk & 3) == 0b00){ + print("Rx Hdr Done\n"); + sr_status = 0x1c8; + phy_status = 0x3; + + read(0, &pkt_hdr_status, 2); + read(0, &pkt_log, 2); + pkt_hdr_status |= 0x40000; + pkt_log |= 0x40000; + + //Eir inject test FHS + /* + if (pcx_btclk & 0x8 == 0) { + sr_status = 0x1d8; + phy_status = 0x2; + + pkt_hdr_status = 0x40000; + pkt_hdr_status |= 0x0; //LT_ADDR + pkt_hdr_status |= 0x2 << 3; //Type + pkt_hdr_status |= 0x1 << 7; //Flow + pkt_hdr_status |= 0x1 << 8; //ARQN + pkt_hdr_status |= 0x1 << 9; //SEQ + pkt_hdr_status |= 0xf00; //HEC + pkt_log = 0xd336 | 0x40000; //payload_hdr + } + //Eir inject Eir + if (pcx_btclk & 0x8) { + sr_status = 0x1d8; + phy_status = 0x2; + + pkt_hdr_status = 0x40000; + pkt_hdr_status |= 0x0; //LT_ADDR + pkt_hdr_status |= 0xa << 3; //Type + pkt_hdr_status |= 0x1 << 7; //Flow + pkt_hdr_status |= 0x1 << 8; //ARQN + pkt_hdr_status |= 0x1 << 9; //SEQ + pkt_hdr_status |= 0xf00; //HEC + pkt_log = 0xf5c2 | 0x40000; //payload_hdr + } + /**/ + + print_var(pkt_hdr_status); + print_var(pkt_log); + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Interrupt + if((pcx_btclk & 3) == 0b01) { + print("Rx Done\n"); + sr_status = 0x1c8; + phy_status = 0x1; + + if (rtx_dma_ctl != 3 && dmaActiveRxBuffer) { + if (read(0, dmaActiveRxBuffer, 240) < 1) exit(1); + print_var(dmaActiveRxBuffer); + for (unsigned char i=0; i < 240; i++) dmaActiveRxBuffer[i] = i; + print("pcktdata: "); + hexdump(dmaActiveRxBuffer, 240); + print("\n"); + } + else { + print("pcktdata: "); + read(0, 0x370000, 16); + hexdump(0x370000, 16); + print("\n"); + //char fhs[] = "\x70\x21\xc9\x74\xaf\x83\xc0\x6c\xff\x5a\x48\x8d\x5a"; + //memcpy(0x370000, fhs, sizeof(fhs)); + //read(0, 0x370000 + 9, 2); //some bt addr part + //read(0, 0x370000 + sizeof(fhs), 240); + //hexdump(0x370000, 240); + } + + bluetoothCoreInt_C(); + contextswitch(); + } + +} diff --git a/projects/CYW20819A1/emulation/bcs/le.h b/projects/CYW20819A1/emulation/bcs/le.h new file mode 100644 index 0000000..3270159 --- /dev/null +++ b/projects/CYW20819A1/emulation/bcs/le.h @@ -0,0 +1,136 @@ +int le_fd = 0; + +int wib_rx_status; +int wib_pkt_log; + +void adv() { + if (le_fd == -1) return; + + if ((pcx_btclk & 3) == 0b10){ + print("Tx Done\n"); + sr_status = 0x1d8; + phy_status = 0x4; + bluetoothCoreInt_C(); + contextswitch(); + + /* + print("TxDone: "); + hexdump(&tx_pkt_info, 4); + print(" | "); + hexdump(&tx_pkt_pyld_hdr, 2); + print("\n"); + */ + } + + //Rx Hdr Int + if ((pcx_btclk & 3) == 0b00){ + print("Rx Hdr Done\n"); + sr_status = 0x1c8; + phy_status = 0x3; + + read(le_fd, &wib_rx_status, 4); + read(le_fd, &wib_pkt_log, 4); + + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Interrupt + if((pcx_btclk & 3) == 0b01) { + print("Rx Done\n"); + sr_status = 0x1c8; + phy_status = 0x1; + + read(le_fd, 0x370c00, 32); + + + bluetoothCoreInt_C(); + contextswitch(); + } +} + +void le_scan() { + if ((pcx_btclk & 3) == 0b10){ + print("Tx Done\n"); + sr_status = 0x1d8; + phy_status = 0x4; + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Hdr Int + if ((pcx_btclk & 3) == 0b00){ + print("Rx Hdr Done\n"); + sr_status = 0x1c8; + phy_status = 0x3; + + read(le_fd, &wib_rx_status, 4); + read(le_fd, &wib_pkt_log, 4); + + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Interrupt + if((pcx_btclk & 3) == 0b01) { + print("Rx Done\n"); + sr_status = 0x1c8; + phy_status = 0x1; + + print_var(wib_rx_status) + print_var(wib_pkt_log) + read(le_fd, 0x370c00, 256); + + bluetoothCoreInt_C(); + contextswitch(); + } +} + +//#include +void le_conn() { + //xmit_state_emu("gen/xmited_le"); + //hci_rx_fd = -1; + //hci_tx_fd = -1; + + if ((pcx_btclk & 3) == 0b10){ + print("Tx Done\n"); + sr_status = 0x1d8; + phy_status = 0x4; + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Hdr Int + if ((pcx_btclk & 3) == 0b00){ + print("Rx Hdr Done\n"); + sr_status = 0x1c8; + phy_status = 0x3; + + wib_rx_status = 0; + read(le_fd, &wib_rx_status, 4); + read(le_fd, &wib_pkt_log, 4); + + //LE heap BoF fix + //wib_rx_status &= 0xffff; + //if (wib_rx_status >= 0xfc00) wib_rx_status = 0xfc00 | (wib_rx_status & 0xff); + //wib_rx_status |= wib_rx_status << 16; + + bluetoothCoreInt_C(); + contextswitch(); + } + + //Rx Interrupt + if((pcx_btclk & 3) == 0b01) { + print("Rx Done\n"); + sr_status = 0x1c8; + phy_status = 0x1; + + print_var(wib_rx_status) + print_var(wib_pkt_log) + read(le_fd, rtx_rx_buffer, 256); + //for (int i=0; i < 0x100; i++) ((char *)0x370c00)[i] = (char)(i&0xff); + + bluetoothCoreInt_C(); + contextswitch(); + } +} diff --git a/projects/CYW20819A1/emulation/bcs/page.h b/projects/CYW20819A1/emulation/bcs/page.h new file mode 100644 index 0000000..05818bb --- /dev/null +++ b/projects/CYW20819A1/emulation/bcs/page.h @@ -0,0 +1,68 @@ +int page_fd = 0; + +int page_idx = 0; + + +/* + Accept any connection attempt +*/ +void page() { + //if (acl_fd == 0 || acl_fd == -1) acl_fd = tcp_connect(127,0,0,1,31338); + + switch(page_idx) { + case 0: + if ( (pcx_btclk & 3) != 0b10) page_idx = page_idx - 1 % 4; + + case 1: + pkt_hdr_status = 0x04e98d; //TODO are these function callbacks? + pkt_log = 0x2404e878; + phy_status = 1; + sr_status = 0xcb3a; + break; + case 2: + pkt_hdr_status = 0x0438f2; //TODO + pkt_log = 0x24040225; + phy_status = 0x1; + sr_status = 0xc99a; + break; + case 3: + pkt_hdr_status = 0x04e0b5; //TODO + pkt_log = 0x2404303e; + phy_status = 5; + sr_status = 0x227f; + + acl_role = ACL_ROLE_MASTER; + break; + } + page_idx = page_idx + 1 % 4; + + bluetoothCoreInt_C(); + contextswitch(); + + return; +} + +void pagescan() { + //bcs_info(); + if (page_fd == -1) return; + //if (acl_fd == 0 || acl_fd == -1) acl_fd = tcp_connect(127,0,0,1,31337); + acl_role = ACL_ROLE_SLAVE; + + read(page_fd, 0x370000, 16); + read(page_fd, &sr_status, 2); + read(page_fd, &phy_status, 2); + read(page_fd, &pkt_hdr_status, 2); + read(page_fd, &pkt_log, 2); + pkt_hdr_status |= 0x40000; + pkt_log |= 0x40000; + + print_var(pkt_hdr_status); + print_var(pkt_log); + print_var(phy_status); + print_var(sr_status); + bluetoothCoreInt_C(); + contextswitch(); + + return; +} + diff --git a/projects/CYW20819A1/emulation/common.h b/projects/CYW20819A1/emulation/common.h new file mode 100644 index 0000000..e028852 --- /dev/null +++ b/projects/CYW20819A1/emulation/common.h @@ -0,0 +1,155 @@ +#ifndef _COMMON_H +#define _COMMON_H +void cont(); + +#define EMULATED + +//utils +int ret1() { return 1; } +int ret0() { return 0; } +void die() { print_caller(); print(" die();\n"); exit(-1);} +void clean_exit() { exit(0);} + +#include +#include "fwdefs.h" +#include +#include "hci.h" +#include "lm.h" +#include "timer.h" +#include "dynamic_memory.h" + +#include + +/* +Hook for Peripheral UART +*/ +void puart_write_hook(char c) { + print("\033[;34m"); + write(2, &c, 1); + print("\033[;00m"); +} + + +/* +Queu +*/ + +//probably mpaf timer/event +struct queue_entry { + void *next; + int maybe_flags; + void *sometimes_callback; + void *callback_arg; + char unknwn[]; +} *queue_entry; + +void msgqueue_Put_hook(struct saved_regs *regs, void *arg) { + void *queue = (void *)regs->r0; + struct queue_entry *item = (void *)regs->r1; + print_caller(); + print(" msgqueue_Put_hook("); + print_ptr(queue); + print(", "); + print_ptr(item); + print(");\n"); + print(" ");print_var(item->maybe_flags) + print(" ");print_var(item->sometimes_callback) + print(" ");print_var(item->callback_arg) + print(" "); hexdump(item, 32); +} + +/* +This +*/ +//TODO get thread list +void print_thrd_bcmbt(uint32_t thrd) { + switch (thrd) { + case 0x249e58: + print("bttransport"); + break; + + case 0x20beb4: + print("lm"); + break; + + case 0x20a578: + print("idle"); + break; + + case 0x20a1fc: + print("mpaf") + break; + + default: + print_ptr(_tx_thread_current_ptr); + } +} + + +/* + global code patching +*/ + +#define idle_loop (*(uint32_t*)0x024de64) //TODO + +uint32_t _tx_v7m_get_and_disable_int(); +void _tx_v7m_set_int(uint32_t); +uint32_t _tx_v7m_get_int(); + + +void synch_GetXSPRExceptionNum(); +void osapi_interruptContext(); +void btclk_AdvanceNatClk_clkpclk(); + +void patch_code() { + //ThreadX basics + patch_return(_tx_v7m_get_and_disable_int); + patch_return(_tx_v7m_set_int); + patch_return(_tx_v7m_get_int); + patch_jump(_tx_thread_system_return, _tx_thread_system_return_hook); + + patch_return(osapi_interruptContext); + //patch_jump(osapi_interruptContext, _tx_thread_system_return); + //patch_return(osapi_interruptContext); + + //Functions, we do not support + patch_return(0xa43ee); //synch_GetXSPRExceptionNum //TODO + patch_return(0x20ffb2); //get_and_disable_int 2nd ed?! //TODO + patch_return(btclk_DelayXus); + patch_return(btclk_Wait4PclkChange); + patch_return(btclk_AdvanceNatClk_clkpclkHWWA); + patch_return(btclk_AdvanceNatClk_clkpclk); + + //Show thread names + print_thrd = print_thrd_bcmbt; + + //Relplace return from interrupt addr with exit + if(idle_loop == 0xfffffffd) + idle_loop = clean_exit; + + //Watchdog HW Reset + patch_jump(&wdog_generate_hw_reset, &die); + //Enable Peripheral UART + patch_jump(&puart_write, &puart_write_hook); + //Trace dbfw Assert Fatals + trace(dbfw_assert_fatal, 1, false); + + //Disable NV RAM + patch_return(wiced_hal_read_nvram); + trace(wiced_hal_read_nvram, 4, true); + patch_return(wiced_hal_write_nvram); + trace(wiced_hal_write_nvram, 4, true); + + //Enable Osapi Timers + add_timer_hooks(); + + hci_install_hooks(); + + add_lm_hooks(); + + + //add heap sanitizer + init_dynamic_memory_sanitizer(); +} + +#endif diff --git a/projects/CYW20819A1/emulation/dynamic_memory.h b/projects/CYW20819A1/emulation/dynamic_memory.h new file mode 100644 index 0000000..ca5de5a --- /dev/null +++ b/projects/CYW20819A1/emulation/dynamic_memory.h @@ -0,0 +1,72 @@ +#ifndef DYNAMIC_MEMORY_H +#define DYNAMIC_MEMORY_H + + +#include "common.h" +#include + + +//void *memcpy_r(void *dest, const void *src, size_t n); +void *utils_memcpy8(void *dest, const void *src, size_t n); +void *sfi_memcpy(void *dest, const void *src, size_t n); +void *utils_memcpy10(void *dest, const void *src, size_t n); +void *utils_memcpy8_postinc(void *dest, const void *src, size_t n); +void *__aeabi_memcpy(void *dest, const void *src, size_t n); +void *utils_memcpy3dword(void *dest, const void *src, size_t n); +void *__rt_memcpy_w(void *dest, const void *src, size_t n); +void *__aeabi_memcpy8(void *dest, const void *src, size_t n); +void *__aeabi_memcpy4(void *dest, const void *src, size_t n); +void *__ARM_common_memcpy4_5(void *dest, const void *src, size_t n); +void *__ARM_common_memcpy4_10(void *dest, const void *src, size_t n); +void *mpaf_memcpy(void *dest, const void *src, size_t n); +void *memcpy(void *dest, const void *src, size_t n); +void *_memcpy_lastbytes(void *dest, const void *src, size_t n); +void *_memcpy_lastbytes_aligned(void *dest, const void *src, size_t n); +void *__rt_memcpy(void *dest, const void *src, size_t n); + +void *__rt_memmove_w(void *dest, const void *src, size_t n); +void *memmove(void *dest, const void *src, size_t n); +void *__memmove_aligned(void *dest, const void *src, size_t n); +void *mpaf_memmove(void *dest, const void *src, size_t n); +void *__rt_memmove(void *dest, const void *src, size_t n); +void *__memmove_lastfew(void *dest, const void *src, size_t n); +void *__memmove_aligned(void *dest, const void *src, size_t n); +void *__aeabi_memmove8(void *dest, const void *src, size_t n); +void *__aeabi_memmove4(void *dest, const void *src, size_t n); +void *__aeabi_memmove(void *dest, const void *src, size_t n); +void *__memmove_lastfew_aligned(void *dest, const void *src, size_t n); + +void *memset(void *dest, int c, size_t n); +void *_memset(void *dest, const size_t n, int c); + + + + +void init_dynamic_memory_sanitizer() { + //clear_heap(); + + dynamic_memory_check_free_list(1); + + dynamic_memory_sanitize_trace_function(dynamic_memory_Release, 1, false); + dynamic_memory_sanitize_trace_function(dynamic_memory_AllocatePrivate, 3, false); + + //dynamic_memory_sanitize_trace_function(memcpy_r, 3, false); + dynamic_memory_sanitize_trace_function(utils_memcpy8, 3, false); + dynamic_memory_sanitize_trace_function(sfi_memcpy, 3, false); + dynamic_memory_sanitize_trace_function(utils_memcpy10, 3, false); + dynamic_memory_sanitize_trace_function(utils_memcpy8_postinc, 3, false); + dynamic_memory_sanitize_trace_function(__aeabi_memcpy, 3, false); + dynamic_memory_sanitize_trace_function(utils_memcpy3dword, 3, false); + dynamic_memory_sanitize_trace_function(__rt_memcpy_w, 3, false); + dynamic_memory_sanitize_trace_function(__aeabi_memcpy8, 3, false); + dynamic_memory_sanitize_trace_function(__aeabi_memcpy4, 3, false); + dynamic_memory_sanitize_trace_function(__ARM_common_memcpy4_5, 3, false); + dynamic_memory_sanitize_trace_function(__ARM_common_memcpy4_10, 3, false); + dynamic_memory_sanitize_trace_function(mpaf_memcpy, 3, false); + dynamic_memory_sanitize_trace_function(memcpy, 3, false); + dynamic_memory_sanitize_trace_function(_memcpy_lastbytes, 3, false); + dynamic_memory_sanitize_trace_function(_memcpy_lastbytes_aligned, 3, false); + dynamic_memory_sanitize_trace_function(__rt_memcpy, 3, false); +} + +#endif diff --git a/projects/CYW20819A1/emulation/execute.c b/projects/CYW20819A1/emulation/execute.c new file mode 100644 index 0000000..fd66c33 --- /dev/null +++ b/projects/CYW20819A1/emulation/execute.c @@ -0,0 +1,19 @@ +#include +#include +#include +#include "common.h" +#include "queue.h" + + +#include +#include + +void do_exit() { + exit(0); +} + +void _start() { + patch_code(); + idle_loop = do_exit; + cont(); +} diff --git a/projects/CYW20819A1/emulation/fwdefs.h b/projects/CYW20819A1/emulation/fwdefs.h new file mode 100644 index 0000000..2e0a753 --- /dev/null +++ b/projects/CYW20819A1/emulation/fwdefs.h @@ -0,0 +1,439 @@ +#ifndef FWDEFS_H +#define FWDEFS_H + + +#ifdef EMULATED + typedef uint16_t wiced_result_t; +#endif + +/* +NVRAM +*/ +uint16_t wiced_hal_read_nvram( uint16_t vs_id, uint16_t data_length, uint8_t* p_data, wiced_result_t * p_status); +uint16_t wiced_hal_write_nvram( uint16_t vs_id, uint16_t data_length, uint8_t* p_data, wiced_result_t * p_status); +void wiced_hal_delete_nvram( uint16_t vs_id, wiced_result_t * p_status); + +void _send_acl_segment(int s, char *buff, int len); + +/* +Queue +*/ + +void *msgqueue_GetNonblock(void *queue); +void *msgqueue_Get(void *queue); +//called by msgqueue_Get after queue event +void *msgqueue_PrivateGet(void *queue, int x); + +void msgqueue_Put(void *queue, void *item); +void msgqueue_PutInFront(void *queue, void *item); + +void *osapi_getQueueItem(void *queue); +void osapi_sendQueueItem(void *queue, void *item); +void osapi_sendQueueItemToFront(void *queue, void *item); + +void *osapi_getQueueItem_tx(void *queue); +void osapi_sendQueueItem_tx(void *queue); +void osapi_sendQueueItemToFront_tx(void *queue, void *item); + +void *_tx_queue_receive(void *tx_queue, void *item); +void _tx_queue_send(void *tx_queue, void *item); +void _tx_queue_front_send(void *tx_queue, void *item); +void _tx_event_flags_set(void *event_group, int a, int b); +void _tx_thread_system_resume(void *); + +/* +slist +*/ +void *slist_get(void *slist); +void *slist_tail(void *slist); +void *slist_front(void *slist); + +void *slist_del_front(void *slist); +void *slist_del(void *slist); //XXX item? + +void slist_add_after( void* slist, void *item); +void slist_add_front( void* slist, void *item); +void slist_add_tail( void* slist, void *item); +void slist_add_before( void* slist, void *item); + + +/* +Utils +*/ +int rand(); +int rbg_rand(int); + +/* +Uart +*/ +extern int sr_ptu_status_adr4; + +void puart_write(char c); +void *btuartcommon_SendHCICommandBackToTransportThread(int); +//For some reason, this always send 0x19 before any hci packet +void uart_SendSynchHeaderBeforeAsynch(void *some_struct, char *data, int len, int x); +// thrd=0x249e58 lr=0x019265 uart_SendAsynch(0x249f70, 0x249e00, 0x01, 0x2117c8) +void uart_SendAsynch(void *uart_struct, char *data, int len, int x); +void uart_SendSynch(void *uart_struct, char *data, int len); +void btuarth4_getpti(); +void uart_SetAndCheckReceiveAFF(); +void uart_SetAndCheckTransmitAEF(); +void btuarth4_InitiateTransmit_help(); +void bttransport_SendMsgToThread(); +void btu_hcif_hardware_error_evt(); +void uart_RunTransmitStateMachine(void*); +void btuarth4_RunTxStateMachines(int, int, int, int); + +void bthci_lm_thread_SendMessageToThread(void *msg); +void bthci_event_SendConnectionRequestEvent(); + +/* +Interrupt Vectors +*/ +void interruptvector_PTU(); //uart +void interruptvector_DMA_DONE(); +void interruptvector_WAKEUP(); +void interruptvector_TIMER1_DONE(); +void interruptvector_TIMER2_DONE(); + + +extern int g_ptu_ISR; +extern int g_uart_DriverState; +void *uart_ReceiveSynch(); +void *uart_ReceiveAsynch(); +void *uart_ReceiveAsynchTerminate(); +void btuarth4_getpti(); +void btuarth4_RunRxStateMachines(); +void btuarth4_HandleRXFullMsgDone(); +void uart_RunReceiveStateMachine(); +void uart_SetupForRXDMA(void *); +void bttransport_Main(void *driver_state); + +void dma_StartTransfer(); +void dma_RequestTransfer(int); + +int mpaf_hci_EventFilter(void *); +extern int mpaf_flags; +extern int mpaf_suppress_hci_rx_to_host; +void mpaf_thread_PostMsgToHandler(void *, void *); + + +void *uart_TransmitDMADoneInterrupt(); +void *uart_ReceiveDMADoneInterrupt(); +void *uart_DirectWrite(); +void *uart_DirectRead(); + +/* + Hardware +*/ +extern int pkt_hdr_status; //Rx +extern int pkt_log; + +extern int tx_pkt_info; +extern int tx_pkt_pyld_hdr; //maybe acl header, length + 3 bits + + +extern int pc_acscd_lo; //Piconet Access Code +extern int pc_acscd_hi; + +extern int dc_fhout; +extern int dc_ind_d_ptr; + +/* +Exception +*/ +void wdog_generate_hw_reset(); +void dbfw_assert_fatal(); + +/* +Os +*/ + +struct thread_dvdn { + uint32_t magic; + uint32_t x1; + uint32_t sp; +}; + +extern struct thread_dvdn g_pmu_idle_IdleThread; + +extern int g_bthci_lm_thread_Thread; + +void _tx_thread_system_suspend(); +void _tx_thread_system_return(void); +void _tx_thread_suspend(void); +int osapi_waitEvent(void *dvdn, int mask, int x); +void interrupt_DisableInterrupts(); +void interrupt_EnableInterrupts(); + +/* +Timer +*/ +struct osapi_timer { + void *next; + void *callback; + int maybe_type; + int i2; + void *mpaf_exec_timer_arg; + int i3; + uint32_t time_offset_low; + uint32_t time_offset_high; + int i6; + int i7; + char unknwn[]; +}; + +void osapi_activateTimer(void *timer, uint32_t time_us); +void osapi_getTimerRemain(void *timer); +void *g_pmu_private_IdleMsgQueue; +void mpaf_osapi_timerCb(void *timer); +uint32_t clock_SystemTimeMicroseconds32(); +uint32_t clock_SystemTimeMicroseconds64(); +uint32_t clock_SystemTimeMicroseconds32_nolock(); +uint32_t clock_SystemTimeMicroseconds64_nolock(); +void clock_serviceTimers(); +void clock_ResetTimer2(); + +extern struct osapi_timer *lm_osTimer; +uint32_t timer1value; //current system time + +/* +Connection +*/ +int createConnection(); +void lm_HandleLmpBBAck(); +void lm_HandleLmpReceivedPdu(int *i); +void lm_HandleLmpHostConnReqNotAccepted(); +void lm_HandleLmpHostConnReqAccepted(); +void *ber_startBerPerTest(char *); +void *rm_getConnFromBdAddress(char *); +void rm_setLocalBdAddr(char *); + +/* +LM +*/ + +extern int lm_curCmd; +extern int lm_curCmdPayload; //XXX custom symbol + +void lm_sendCmd(void *event); +void lm_sendCmdWithId(void *event); +void lm_handleCmd(); +void lm_handleHciResetWithAclLinks(); +int rm_getBBConnectedACLUsage(); +void lm_LmpBBAcked(void *); //called if sent packet is acked + +/* +bpl +*/ +void bpl_lcu_Cmd(int, int); +void bpl_lcu_setPHY(int, int, int, int); +int lb; + +/* +LMP +*/ +extern int diag_sendLmpPktFlag; +void *rm_getACLConnPtr(int i); +void *rm_getDHMAclPtr(int i); +void *rm_allocateACLConnPtr(int i); +void *rm_allocateLTCH(int i); +void lm_LmpReceived(void *acl_conn, void *lmp_msg); +int DHM_LMPTx(int id, void *buff); +int DHM_TxDataAvail(); +void DHM_releaseTxLmpList(int, int, int, int); +void *DHM_GetBasebandTxData(int, int); +void *DHM_GetBasebandRxBuffer(int, int); +void *DHM_BasebandRx(int, int, int); +void DHM_ACLAckRcvd(int); +void DHM_SetAclTxPktAckRcvd(int); +int DHM_isTxLmpListEmpty(void *adhm_acl); +void *DHM_getFrontTxLmp(void *adhm_acl); +void _dhmSlotCbFunc(void *x); + +/* +ACL Task +*/ +void _aclTaskSetupTxBuffer(); +void _aclTaskLcuCmd(); +void _aclTaskRxHeaderDone(); +void _aclTaskRxDone(); +void _aclTaskTxDone(); +void _aclTaskFsmSetup(); +void _aclTaskQosSlotIntCB(); +void _aclTaskProcessRxPacket(); +void _aclTaskSwitch(); + +/* +Inquiry +*/ +void _inqTaskRxHeaderDone(int); +void _inqTaskRxDone(int); +void eir_handleTx(int); +void eir_handleRx(int); +void bcs_inqScanPauseNonBlock(); +void bcs_inqScanPause(); +void _inqTaskFsmDone(int, int); +void _inqTaskFsmSetup(int, int); +void eir_eirInqFHS(int); +void lm_sendInqFHS(int); +void lm_handleInqFHS(int); +void eir_getReceivedEIR(int, int); +void bthci_event_SendInquiryResultEvent(int); +void lc_handleInqResult(int); +void bcs_utilExtractFhsInfo(int); +void inqfilter_isBdAddrRegistered(int, int); +void inqfilter_registerBdAddr(int, int); +extern int eir_fhs; + +/* +Page +*/ +void _pageTaskFsmDone(); +void _pageScanTaskFsmDone(); +void bcs_newConnTaskCreate(); +void bcs_pageScanTaskCreate(); + +/* +LE +*/ +void _advTaskRxDone(); +void _scanTaskRxDone(); +void bcsulp_passRxPktUp(); +void bcsulp_procRxPayload(int, int); +void bcsulp_progTxBuffer(int); +void bcsulp_getPktLength(int, int); +void bcsulp_fillTxBuffer(int dst, int src, int len); +void bcsulp_setupRxBuffer(); +void bcsulp_returnRxBuffer(void); +void *mmulp_allocACLUp(int ); +void *mmulp_allocACLDown(int ); +int mmulp_freeLEABuffer(void *); +void *dhmulp_getRxBuffer(int); +void dhmulp_returnRxBuffer(void *); +void _connTaskLcuCmd_addin(); +void _connTaskLcuCmd(); +void _connTaskSlotInt(); +void _connTaskRxDone(); +void _connTaskRxHeaderDone(); + +/* +LCP +*/ +extern void diag_logLcpPkt(int, int); + + +/* +clk +*/ +int btclk_GetSysClk_slot(void *); +int btclk_GetSysClk_clk(void *); + +/* +bcs +*/ +extern int bcsProfilingData; +extern int pcx_btclk; +extern int dc_nbtc_clk; //ca 1 unit pre 312us +extern int dc_x_clk; //ca 1 unit pre 312us +extern uint32_t *tb; //current task +extern int taskTimerList; +extern int slotCbEntryList; +extern int btProgIntStatus; +extern int taskTransientStateList; +extern int taskActiveList; +extern int taskReadyList; +extern void *taskEventGroup; +extern int phy_status; +extern int sr_status; +extern int sr_status_shadow; +extern int phy_status_shadow; +extern char rm_deviceInfo[]; +extern char rm_deviceLocalName[]; +void bcs_isrSlot11Int(); +void bcs_isrSlot01Int(); +void bcs_utilBbRxPktHdrCheck(int, int); +void bcs_dmaRxEnableEir(int, int); +void bcs_dmaTxEnableEir(int, int); +void bcs_dmaRxEnable(int, int); +void bcs_dmaTxEnable(int, int); +void *bcs_dmaRxDisable(int, int); +void bcs_dmaBlockEnable(); +void bcs_dmaIsTransferComplete(); +void *bcs_dmaGetRxBuffer(); +void bcs_dmaRxBufferRecycle(void *); +void _dmaReqSend(); +void bcs_SlotCbFunctions(); +extern int dmacinttcclr; +extern int rtx_dma_ctl; +extern int dmacinttcstat; +extern int g_dma_ActiveChannels; + +int bcs_taskGetTaskType(int); +void bcs_aclTaskCreate(); +extern int bcs_isrEnableProfiling; +void BtIntDone(); +extern int bcsDataToCrunch; +void pmu_idle_Main(); +void *pmu_idle_MsgHandlersPoll(); +void dbfw_proc_in_idle(); +void bluetoothCoreInt_C(); + +void *bcs_isrRxDoneInt(); +void *bcs_isrTxDoneInt(); +void *bcs_timeline_CrunchData(); +void *bcs_isrRxHeaderDoneInt(); +void bcs_isrFsmDoneInt(); + +void bcs_kernelSlotCbFunctions(); +void bcs_kernelRxDone(); +void bcs_kernelRxHeaderDone(); +void bcs_kernelTimerTick(); +void bcs_kernelBlock(); +void bcs_kernelFsmSetup(); +void bcs_kernelBtProgIntEnable(); + +void bcs_taskUnblock(int); +void bcs_SlotCbFunctions(); +void *bcs_dmaGetRxBuffer(); +int btclk_DelayXus(int us); +void bcs_utilBbRxPyldHdr(); + +void btclk_Wait4PclkChange(int, int); +void btclk_AdvanceNatClk_clkpclkHWWA(); +void intctl_ClrPendingInt(); +void *dhmulp_getTxBuffer(); +void dhmulp_LcpTx(); + +void bluerf_Wr(void *addr, int val); +int bluerf_Rd(void *addr); + +void eir_handleTx(int); +void _afhPipelineRssiScanTaskSlotInt(); + +/* +paging +*/ +void bcs_pageTaskCreate(); +void lc_pageStart(int); + +extern int dc_n_pg; +extern int dc_pg_to; +extern int dc_pg_respto; + + +/* +HCI +*/ +void bthci_processingHCIReset(); +void bthci_processingHCIResetFlag(); +void bthci_lm_thread_Reset(); +void bthci_acl_Reset(); +void bthci_event_AttemptToEnqueueEventToTransport(); +void bthci_event_SendCommandCompleteEventWithStatus(); +void bthci_cmd_lc_HandleCreate_Connection(); +void bthci_cmd_lc_HandleDisconnect(char *); + +void bt_Reset(); + +#endif diff --git a/projects/CYW20819A1/emulation/hci.h b/projects/CYW20819A1/emulation/hci.h new file mode 100644 index 0000000..034abf4 --- /dev/null +++ b/projects/CYW20819A1/emulation/hci.h @@ -0,0 +1,209 @@ +#ifndef HCI_H +#define HCI_H + + +#include "common.h" + + +int hci_tx_fd = -1; +int hci_rx_fd = -1; +int hci_dump_raw_enable = 0; //we wait until the first hci cmd before dumping events + +/* +Sending hci Events +*/ + +void uart_SendSynch_hook(void *some_struct, char *data, int len) { + print("\033[;32mHCI Event (Synch)"); + hexdump(data,len); + print("\033[;00m"); + + return; //XXX called in send header before ... + if (hci_tx_fd != -1 && hci_dump_raw_enable) { + write(hci_tx_fd, data, len); + } +} + +void uart_SendAsynch_hook(struct saved_regs *regs, void *arg) { + uint32_t size = *(uint32_t*) regs->sp; + print("\033[;32mHCI Event (Asynch)"); + hexdump(regs->r1, regs->r2); //header aka type + hexdump(regs->r3, size); //hci packet + print("\033[;00m\n"); + + //dump raw packets + if (hci_tx_fd != -1 && hci_dump_raw_enable) { + write(hci_tx_fd, regs->r1, regs->r2); + write(hci_tx_fd, regs->r3, size); + } +} + +void uart_DirectWrite_hook(char *data, int len) { + return; //not needed + print("\033[;32mHCI Event (Direct Write)"); + hexdump(data, len); + print("\033[;00m\n"); + + return; + if (hci_tx_fd != -1 && hci_dump_raw_enable) { + write(hci_tx_fd, data, len); + } +} + + +//0x249f70 = g_uart_DriverState +//print_var(*(char*)(0x249e58+429)); //rx state + + + +/* +Reading HCI packets +*/ + +/* +This is called in the interrupt handler to complete a Asynch read +*/ + +void uart_DirectRead_hook(char *data, int len) { + int ret; + print("\033[;32mHCI Direct Read "); + for (ret = -1; ret < 0; ret = read(hci_rx_fd, data, len)); + hexdump(data, len); + print("\033[;00m\n"); + + hci_dump_raw_enable = 1; + if (ret == 0) exit(1); //no more to read, exit + return ret; +} + +/* +This method tries to receive directly from the uart and loops forever, as there are no data to read +Therefore, wee hook it +*/ +int uart_ReceiveSynch_hook(void *uart_struct, char *data, int len) { + print("\033[;32mHCI ReceiveSynch "); + int ret; + for (ret = -1; ret < 0; ret = read(hci_rx_fd, data, len)); + hexdump(data, len); + print("\033[;00m\n"); + + hci_dump_raw_enable = 1; + return 8; +} + +/* +Some debug stuff, deprecated +*/ /* +void dump_rx_state(){ + print_var(*(int*)(0x249e58+429)); + print_var(g_uart_DriverState); + print_var(g_ptu_ISR); + print_var(*(int*)(0x360084)); + print_var(*(int*)(0x3600a8)); + print_var(*(int*)(0x3600cc)); + print_var(*(int*)(0x3382d8)); + print_var(*(char*)(0x249f70+13)); + print_var(*(char*)(0x249f70+14)); + // *(int*)(0x360084) = 0x0a; +} */ + + +/* +If the firmware goes to an idle state, we execute the interrupt +and notify the firmware for new HCI data +*/ +void hci_rx_poll(int timeout_ms) { + if (hci_rx_fd == -1) return; + struct pollfd ufds; + int ret = 0; + + //setup poll for hci rx fd + ufds.fd = hci_rx_fd; + ufds.events = POLLIN; + ret = poll(&ufds, 1, timeout_ms); + + //No Data Available + if (ret <= 0) return; + + //classical receive + sr_ptu_status_adr4 |= 0x04; //set register to data available + interruptvector_PTU(); + + //the UART interface seems to have a DMA like receive + char state = *(char *)(0x249f70 + 0xd); //rx_machine state //TODO + print_var(state); + if (state == 6) { + void *data_ptr = *(void **)(0x249f70 + 0x10); //rx_data_ptr //TODO + uint32_t len = *(uint32_t *)(0x249f70 + 0x14); //rx_len //TODO + int ret; + print_var(data_ptr); + print_var(len); + print("\033[;32mRx DMA "); + for (ret = -1; ret < 0; ret = read(hci_rx_fd, data_ptr, len)); + *(uint32_t*)(0x249f70 + 0x3c) = ret; //TODO + hexdump(data_ptr, len); + print("\033[;00m\n"); + print_var(*(uint32_t*)(0x249f70 + 0x3c)); //TODO + //interruptvector_DMA_DONE(); //XXX this is the actual interrupt handler called invoking uart_ReceiveDMADoneInterrupt + uart_ReceiveDMADoneInterrupt(0x249f70); //Invoking isr directly //TODO + } + +} + +void hci_attach() { + //open ptmx + int ptmx = ptmx_open(); + char *pts_name = ptmx_name(ptmx); + print("Pts:"); + puts(pts_name); + print("\n"); + ptmx_btattach(ptmx); + + hci_tx_fd = ptmx; + hci_rx_fd = ptmx; + + //wait for Data + struct pollfd ufds; + ufds.fd = ptmx; + ufds.events = POLLIN; + while (poll(&ufds, 1, 100) <= 0); + +} + + + +void hci_install_hooks() { + //trace uart + trace(btuartcommon_SendHCICommandBackToTransportThread, 2, true); + + //hci uart tx + patch_jump(&uart_DirectWrite, &uart_DirectWrite_hook); //not required + patch_jump(&uart_SendSynch, &uart_SendSynch_hook); //notr required + //ret0 is needed to notify the state machine, that the data has been sent immediately + add_hook(uart_SendAsynch, &uart_SendAsynch_hook, ret0, NULL); //XXX Working + + //hci uart rx + patch_jump(&mpaf_hci_EventFilter, &ret0); //we dont want any hci events to be droped + patch_jump(&uart_SetAndCheckReceiveAFF, &ret0); //there is never data available on uart + patch_jump(&uart_DirectRead, &uart_DirectRead_hook); + patch_jump(&uart_ReceiveSynch, &uart_ReceiveSynch_hook); + + trace(uart_ReceiveAsynch, 3, true); + trace(uart_DirectRead, 3, true); + trace(uart_SendSynchHeaderBeforeAsynch, 4, false); + trace(uart_SendAsynch, 4, true); + trace(uart_SendSynch, 4, false); + trace(uart_DirectWrite, 2, true); + + + trace(btuarth4_RunTxStateMachines, 4, true); + trace(bttransport_SendMsgToThread,2,false); + trace(btu_hcif_hardware_error_evt,2,false); + trace(mpaf_thread_PostMsgToHandler, 1, false); + trace(bthci_lm_thread_SendMessageToThread, 1, false); + trace(uart_SetupForRXDMA, 1, false); +} + + + +#endif diff --git a/projects/CYW20819A1/emulation/lm.h b/projects/CYW20819A1/emulation/lm.h new file mode 100644 index 0000000..4fbbd09 --- /dev/null +++ b/projects/CYW20819A1/emulation/lm.h @@ -0,0 +1,98 @@ +#include + +#ifndef __LM_H +#define __LM_H + + +struct lm_cmd { + short type; + short maybe_subtype; + void *arg; +}; + +struct lcp_pckt { + uint32_t unknwn0; //0x00 + uint32_t unknwn1; //0x4 + uint32_t unknwn2; //0x8 + unsigned char len; //0xd + unsigned char unknwn3; //0xc + uint16_t unknwn4; //0xe + char data[]; +}; + +void lm_hook(struct saved_regs *regs, void *arg) { + struct lm_cmd *lm_cmd = regs->r0; + struct lcp_pckt *lcp; + + //rssi report + if (lm_cmd->type == 0xc) return; + + //inthexdump(regs->r0, 8); + print("lr = "); + print_ptr(regs->lr); + print(" lm_sendCmd("); + print_ptr(lm_cmd->type); + print(" | "); + print_ptr(lm_cmd->maybe_subtype); + print(" | "); + print_ptr(lm_cmd->arg); + print(");\n"); + + //lmulp_handleRxLcp + if (lm_cmd->type == 0xe) { + lcp = lm_cmd->arg; + print("LCP: "); + hexdump(lm_cmd->arg, 16); //hdr + hexdump(lcp->data, lcp->len); + } +} + + +void lmp_rx_hook(struct saved_regs *regs, void *arg) { + print("lr = "); + print_ptr(regs->lr); + print(" lm_LmpReceived("); + print_ptr(regs->r0); + print(", "); + hexdump(regs->r1, 4); + print(" | "); + hexdump(regs->r1 + 4, 24); + print(");\n"); +} + +void lmp_tx_hook(struct saved_regs *regs, void *arg) { + print("lr = "); + print_ptr(regs->lr); + print(" DHM_LMPTx("); + print_ptr(regs->r0); + print(", "); + hexdump(regs->r1, 12); + print(" | "); + hexdump(regs->r1 +12, 19); + print(");\n"); +} + + + + +void add_lm_hooks() { + add_hook(lm_sendCmd, lm_hook, NULL, NULL); + add_hook(lm_LmpReceived, lmp_rx_hook, NULL, NULL); + add_hook(DHM_LMPTx, lmp_tx_hook, NULL, NULL); + + trace(lm_LmpBBAcked, 2, false); + trace(lm_HandleLmpBBAck, 2, false); + trace(lm_sendCmdWithId, 1, false); + trace(lm_LmpReceived, 2 ,false); + trace(lm_HandleLmpReceivedPdu, 1, false); + trace(rm_allocateACLConnPtr, 1, true); + trace(rm_allocateLTCH, 1, true); + trace(DHM_LMPTx, 2, false); + trace(DHM_GetBasebandTxData, 2, true); + trace(DHM_BasebandRx, 3, true); + trace(lc_pageStart, 1, false); + + bcs_add_hooks(); +} + +#endif diff --git a/projects/CYW20819A1/emulation/queue.h b/projects/CYW20819A1/emulation/queue.h new file mode 100644 index 0000000..44a9439 --- /dev/null +++ b/projects/CYW20819A1/emulation/queue.h @@ -0,0 +1,142 @@ +#include + +struct queue_access { + uint32_t thread; + uint32_t queue; + uint32_t lr; +}; + + +struct queue_access queue_read[1024]; +int queue_read_n = 0; +void queue_read_access(struct saved_regs *regs, void *arg) { + for (int i = 0; i < queue_read_n; i++) + if ( queue_read[i].thread == _tx_thread_current_ptr && + queue_read[i].queue == regs->r0 && + queue_read[i].lr == regs->lr ) return; + + //add access + queue_read[queue_read_n].thread = _tx_thread_current_ptr; + queue_read[queue_read_n].queue = regs->r0; + queue_read[queue_read_n].lr = regs->lr; + queue_read_n ++; + + //dump + print("queue read thread="); + print_ptr(_tx_thread_current_ptr); + print(" queue="); + print_ptr(regs->r0); + print(" lr="); + print_ptr(regs->lr); + print("\n"); +} + +struct queue_access queue_write[1024]; +int queue_write_n = 0; +void queue_write_access(struct saved_regs *regs, void *arg) { + for (int i = 0; i < queue_write_n; i++) + if ( queue_write[i].thread == _tx_thread_current_ptr && + queue_write[i].queue == regs->r0 && + queue_write[i].lr == regs->lr ) return; + + //add access + queue_write[queue_write_n].thread = _tx_thread_current_ptr; + queue_write[queue_write_n].queue = regs->r0; + queue_write[queue_write_n].lr = regs->lr; + queue_write_n ++; + + //dump + print("queue write thread="); + print_ptr(_tx_thread_current_ptr); + print(" queue="); + print_ptr(regs->r0); + print(" lr="); + print_ptr(regs->lr); + print("\n"); +} + +struct queue_access slist_read[1024]; +int slist_read_n = 0; +void slist_read_access(struct saved_regs *regs, void *arg) { + for (int i = 0; i < slist_read_n; i++) + if ( slist_read[i].thread == _tx_thread_current_ptr && + slist_read[i].queue == regs->r0 && + slist_read[i].lr == regs->lr ) return; + + //add access + slist_read[slist_read_n].thread = _tx_thread_current_ptr; + slist_read[slist_read_n].queue = regs->r0; + slist_read[slist_read_n].lr = regs->lr; + slist_read_n ++; + + //dump + print("slist read thread="); + print_ptr(_tx_thread_current_ptr); + print(" slist="); + print_ptr(regs->r0); + print(" lr="); + print_ptr(regs->lr); + print("\n"); +} + +struct queue_access slist_write[1024]; +int slist_write_n = 0; +void slist_write_access(struct saved_regs *regs, void *arg) { + for (int i = 0; i < slist_write_n; i++) + if ( slist_write[i].thread == _tx_thread_current_ptr && + slist_write[i].queue == regs->r1 && + slist_write[i].lr == regs->lr ) return; + + //add access + slist_write[slist_write_n].thread = _tx_thread_current_ptr; + slist_write[slist_write_n].queue = regs->r1; + slist_write[slist_write_n].lr = regs->lr; + slist_write_n ++; + + //dump + print("slist write thread="); + print_ptr(_tx_thread_current_ptr); + print(" slist="); + print_ptr(regs->r1); + print(" lr="); + print_ptr(regs->lr); + print("\n"); +} + +void queue_add_hooks() { + trace(msgqueue_Put, 2, false); + trace(msgqueue_PutInFront, 2, false); + trace(msgqueue_Get, 1, true); + trace(msgqueue_GetNonblock, 1, true); + + add_hook(&msgqueue_Get, &queue_read_access, NULL, NULL); + add_hook(&msgqueue_PrivateGet, &queue_read_access, NULL, NULL); + add_hook(&msgqueue_GetNonblock, &queue_read_access, NULL, NULL); + add_hook(msgqueue_PrivateGet, queue_read_access, NULL, NULL); + + + add_hook(&msgqueue_Put, &queue_write_access, NULL, NULL); + add_hook(&msgqueue_PutInFront, &queue_write_access, NULL, NULL); + + add_hook(osapi_sendQueueItem, &queue_read_access, NULL, NULL); + add_hook(osapi_getQueueItem, &queue_write_access, NULL, NULL); + add_hook(osapi_sendQueueItemToFront, &queue_write_access, NULL, NULL); + + add_hook(osapi_getQueueItem_tx, &queue_read_access, NULL, NULL); + add_hook(osapi_sendQueueItem_tx, &queue_write_access, NULL, NULL); + add_hook(osapi_sendQueueItemToFront_tx, &queue_write_access, NULL, NULL); + + add_hook(_tx_queue_receive, &queue_read_access, NULL, NULL); + add_hook(_tx_queue_send, &queue_write_access, NULL, NULL); + add_hook(_tx_queue_front_send, &queue_write_access, NULL, NULL); + + + //add_hook(&slist_get, &slist_read_access, NULL, NULL); //Too short + misaligned + //add_hook(&slist_tail, &slist_read_access, NULL, NULL); // Function too short + add_hook(&slist_front, &slist_read_access, NULL, NULL); + + add_hook(&slist_add_after, &slist_write_access, NULL, NULL); + add_hook(&slist_add_front, &slist_write_access, NULL, NULL); + add_hook(&slist_add_tail, &slist_write_access, NULL, NULL); + add_hook(&slist_add_before, &slist_write_access, NULL, NULL); +} diff --git a/projects/CYW20819A1/emulation/timer.h b/projects/CYW20819A1/emulation/timer.h new file mode 100644 index 0000000..99940b1 --- /dev/null +++ b/projects/CYW20819A1/emulation/timer.h @@ -0,0 +1,64 @@ +#ifndef TIMER_H +#define TIMER_H +#include "bcs.h" + +//dump osapi timers +void show_timers() { + return; + struct osapi_timer *timer = lm_osTimer; + print("-------------------------\n"); + while (timer) { + print_var(timer); + print_var(timer->next); + print_var(timer->callback); + print_var(timer->maybe_type); + print_var(timer->i2); + print_var(timer->mpaf_exec_timer_arg); + print_var(timer->i3); + print_var(timer->time_offset_low); + print_var(timer->time_offset_high); + print_var(timer->i6); + print_var(timer->i7); + timer = timer->next; + print("-------------------------\n"); + } + //bcs_info(); +} + +//hwo many us to wait unti next timer +uint32_t next_timer_timestamp_us() { + struct osapi_timer *timer = lm_osTimer; + uint32_t current_time = clock_SystemTimeMicroseconds32_nolock(); + int32_t next_timer = lm_osTimer->time_offset_low - current_time; + //print_var(current_time); + //print_var(lm_osTimer->time_offset_low); + //print_var(next_timer); + return next_timer; +} + + +void check_and_handle_timers(uint32_t elapsed_time_us) { + timer1value -= elapsed_time_us; + if (next_timer_timestamp_us() < timer1value) return; + print("\033[;31mTimer 2\033[;00m\n"); + show_timers(); + interruptvector_TIMER2_DONE(); + print("\033[;31mTimer 2 Done\033[;00m\n"); +} + + +void add_timer_hooks() { + trace(osapi_activateTimer, 2, false); + trace(osapi_getTimerRemain, 1, true); + trace(mpaf_osapi_timerCb, 1, false); + //trace(clock_SystemTimeMicroseconds32, 1, false); + //trace(clock_SystemTimeMicroseconds64, 1, true); + //trace(clock_SystemTimeMicroseconds32_nolock, 1, false); + //trace(clock_SystemTimeMicroseconds64_nolock, 1, true); + trace(clock_serviceTimers,2 ,false); + trace(mpaf_thread_PostMsgToHandler, 2, false); + //trace(bcs_kernelTimerTick, 0 , false); + trace(bcs_taskUnblock, 1, false); +} + +#endif diff --git a/projects/CYW20819A1/gen/segments.ld b/projects/CYW20819A1/gen/segments.ld index 33c8465..d52dee1 100644 --- a/projects/CYW20819A1/gen/segments.ld +++ b/projects/CYW20819A1/gen/segments.ld @@ -7,7 +7,7 @@ MEMORY { Segment_0x440000 (rwx) : ORIGIN = 0x440000, LENGTH = 0x4000 Segment_0x338000 (rwx) : ORIGIN = 0x338000, LENGTH = 0x8000 Segment_0x650000 (rwx) : ORIGIN = 0x650000, LENGTH = 0x1000 - Segment_0x326000 (rwx) : ORIGIN = 0x326000, LENGTH = 0xa000 + Segment_0x450000 (rwx) : ORIGIN = 0x450000, LENGTH = 0x4000 Segment_0x341000 (rwx) : ORIGIN = 0x341000, LENGTH = 0x1000 Segment_0xe0000000 (rwx) : ORIGIN = 0xe0000000, LENGTH = 0x100000 Segment_0x430000 (rwx) : ORIGIN = 0x430000, LENGTH = 0x4000 @@ -16,7 +16,7 @@ MEMORY { Segment_0x370000 (rwx) : ORIGIN = 0x370000, LENGTH = 0x10000 Segment_0x500000 (rwx) : ORIGIN = 0x500000, LENGTH = 0x41000 Segment_0x350000 (rwx) : ORIGIN = 0x350000, LENGTH = 0x18000 - Segment_0x450000 (rwx) : ORIGIN = 0x450000, LENGTH = 0x4000 + Segment_0x326000 (rwx) : ORIGIN = 0x326000, LENGTH = 0xa000 Segment_0x640000 (rwx) : ORIGIN = 0x640000, LENGTH = 0x800 Segment_0x0 (rwx) : ORIGIN = 0x0, LENGTH = 0x280000 Segment_0x390000 (rwx) : ORIGIN = 0x390000, LENGTH = 0x8000 @@ -29,7 +29,7 @@ SECTIONS { .Segment_0x440000 0x440000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x440000.segment.o} > Segment_0x440000 .Segment_0x338000 0x338000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x338000.segment.o} > Segment_0x338000 .Segment_0x650000 0x650000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x650000.segment.o} > Segment_0x650000 - .Segment_0x326000 0x326000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x326000.segment.o} > Segment_0x326000 + .Segment_0x450000 0x450000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x450000.segment.o} > Segment_0x450000 .Segment_0x341000 0x341000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x341000.segment.o} > Segment_0x341000 .Segment_0xe0000000 0xe0000000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0xe0000000.segment.o} > Segment_0xe0000000 .Segment_0x430000 0x430000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x430000.segment.o} > Segment_0x430000 @@ -38,7 +38,7 @@ SECTIONS { .Segment_0x370000 0x370000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x370000.segment.o} > Segment_0x370000 .Segment_0x500000 0x500000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x500000.segment.o} > Segment_0x500000 .Segment_0x350000 0x350000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x350000.segment.o} > Segment_0x350000 - .Segment_0x450000 0x450000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x450000.segment.o} > Segment_0x450000 + .Segment_0x326000 0x326000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x326000.segment.o} > Segment_0x326000 .Segment_0x640000 0x640000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x640000.segment.o} > Segment_0x640000 .Segment_0x0 0x0:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x0.segment.o} > Segment_0x0 .Segment_0x390000 0x390000:{ gen/internalBlue_11.07.2019_13.52.37/Segment_0x390000.segment.o} > Segment_0x390000 diff --git a/projects/CYW20819A1/gen/symbols.ld b/projects/CYW20819A1/gen/symbols.ld index 46649f9..42e3575 100644 --- a/projects/CYW20819A1/gen/symbols.ld +++ b/projects/CYW20819A1/gen/symbols.ld @@ -6,6 +6,7 @@ gatt_find_bg_dev = 0x67a75; a2dp_findConn = 0x51c33; sdp_server_handle_client_req = 0xa2fb; lite_host_proc_start_req = 0xad3a7; +pcx2_pbtclk = 0x318238; wiced_bt_avrc_msg_req = 0xd292d; ulp_advContentFilter = 0xa99e9; wiced_rtos_create_thread = 0xd33c9; @@ -4996,6 +4997,7 @@ wiced_audio_suspend = 0x468b3; SAM_SWITCH_INSTANT = 0x206828; afh_okToResumeConnection = 0x3f379; base64_encode = 0xd978b; +pcx2_btclk = 0x31823c; puart_checkTxdPortPin = 0xbfeaf; lrm_FindOffsetWithMethod = 0x6e54f; slopeRxMon_lsb = 0x200e9a; @@ -5050,6 +5052,7 @@ bcsulp_mr4p_updateRssiRangeInfo = 0x64343; bcs_taskGetActivateSlot = 0x79dcf; lm_handleHciExitSniffMode = 0xb8427; bleconn_orig_secur_start = 0x36ff9; +wiced_attach_sink_hci_channel = 0x5832d; bcsDataIdx = 0x201f1c; avct_ccb_dealloc = 0xcec83; bthci_cmd_cbb_HandleSet_Reserved_Lt_Addr = 0x149b7; @@ -5817,6 +5820,7 @@ pb_field_iter_begin = 0xc8931; bcs_afhHssiTaskDelete = 0x4be77; pwm_setInversion = 0xc19db; DHM_GetBBPktInfoPtr = 0x8741f; +sr_ptu_status_adr4 = 0x360084; bthci_cmd_lc_HandleMaster_Link_Key = 0x2ec1d; g_chipspecific_config_Table = 0xe57e0; btm_ble_read_remote_features_complete = 0x35c9b; @@ -5922,6 +5926,7 @@ ulp_advFilterCheckLocName = 0xa9a7d; wiced_bt_ble_get_available_tx_buffers = 0xd32f5; lechan2_setChanInitChan2Bit = 0x969d1; BTMUtil_SetPktHwRegs = 0xb15b5; +tx_pkt_info = 0x318acc; avdt_scb_chk_snd_pkt = 0xd16f9; rm_getMasterPiconetCountAllSecureConnections = 0x76089; avrc_proc_far_msg = 0xcb7dd; @@ -6032,6 +6037,7 @@ DHM_ProcLmpQueueAfterMss = 0x16fc9; gatt_sr_get_attr_ptr = 0x582af; bleconn_start_conn_with_peer = 0x36ee9; bthci_cmd_vs_HandleWrite_RAM = 0xa0169; +rtx_dma_ctl = 0x314018; spiffy_exchangeData = 0x9ed5f; g_mws_type6_subframe_mask = 0x206a10; PORT_ParNegInd = 0x262f1; @@ -6107,6 +6113,7 @@ ape_g = 0xbac41; lmulp_handleRxLcpVSFeatureRsp = 0x9a307; wiced_bt_mesh_create_event_ptr = 0x205ebc; port_rfc_send_tx_data = 0x26631; +phy_status = 0x314004; avrc_bld_set_addr_player_cmd = 0xcc5fb; _printf_x = 0xe5733; _sniffTaskLcuSoftReset = 0x84357; @@ -6937,6 +6944,7 @@ GATTC_ConfigureMTU = 0x4fb6d; bt_config_RegisterGroup = 0x1c4b9; ef_system_power_mode_notification_callback_patch = 0x272c7f; pb_decode_varint = 0xc8b51; +dc_x_clk = 0x3186ac; rmulp_multiAdvReset = 0x7c2c3; wiced_rtos_init_mutex = 0xd344f; wiced_audio_set_sinwave = 0x51181; @@ -7256,6 +7264,7 @@ bthci_event_vs_Sam_SendLocalSlotmapDiagnosticData = 0x1342f; pmu_PeriodicTimerLeft = 0x2139f; spiPortConfig = 0x2065a4; lmulp_sendStartEncryptionReq = 0x9a7b5; +sr_status = 0x31400c; mpaf_tran_ResumeHost = 0x94487; LeAudioOffloadingSetting = 0x2074dc; btm_ble_set_ext_adv_params = 0x4905b; @@ -7373,7 +7382,7 @@ wiced_rtos_push_to_queue = 0xd34c5; ape_isDebugPublicKey = 0xbaee3; _micro_bcsEstimateSdsSbTime = 0x7e1f1; btu_hcif_connection_request_evt = 0x22989; -wiced_attach_sink_hci_channel = 0x5832d; +pcx_btclk = 0x31822c; last_bt_sig_type_7_byte = 0x20696d; wiced_bt_dev_get_security_state = 0x82dc5; pcm2_down = 0x9aae9; @@ -8575,6 +8584,7 @@ bthci_cmd_status_HandleRead_Rssi = 0x14c27; vadBurstCount = 0x2067d0; btm_ble_periodic_advertising_terminate_sync = 0x493d3; lculp_handleResolvingReport = 0x8c137; +dc_nbtc_clk = 0x318088; bcsTaskWakeupTaskSwitchPclk = 0x205d84; ConvertLmpOffsetToRealOffset = 0xbeeb5; lculp_advGetType = 0xac87f; @@ -8778,6 +8788,7 @@ lower_transport_layer_handle_ptr = 0x205ea8; bthci_cmd_vs_SetupRSSLocalCommands = 0xa1941; lm_sam_SendLmpSamDefineMap = 0x98b25; bthci_cmd_vs_SleepForeverMode = 0x9fc45; +pkt_log = 0x318b2c; quad_enableInterrupt = 0x4aab; rom_newConnTaskCallback = 0xf75bc; friend_has_nid_ptr = 0x205e94; @@ -9684,6 +9695,7 @@ KeyscanInt_C = 0x9b997; bcs_pmuWaitForBtClock = 0x76b57; rss_le2m_flush_num = 0x207575; _connTaskTxDone = 0x72769; +rtx_mem_start1 = 0x370400; _antTaskCheckScheduleLate = 0x20105; inqScanTask_iac = 0x202238; lmulp_cbTerminateINDAcked = 0xbd909; @@ -10153,6 +10165,7 @@ bcsulp_connTaskSlaveActive = 0x72c9d; btm_ble_deq_resolving_pending = 0x2b29d; SBC_Decoder_Update_PLC = 0x89645; lculp_advSetMinInterval = 0xac85d; +pkt_hdr_status = 0x318b28; gatt_send_error_rsp = 0x674d3; bthci_cmd_status_HandleWrite_Remote_Amp_assoc = 0x14db7; g_lrmHIDBlockInfo = 0x20ec84; @@ -10673,6 +10686,7 @@ _afhRssiScanTaskDelete = 0x4c24b; bbPorInq_accCode = 0x200d90; _lm_sam_InitializeSlotmapsForESam = 0x98699; avdt_ccb_hdl_start_cmd = 0xd2451; +tx_pkt_pyld_hdr = 0x318ad0; COEX_BLE_3_2_T1_TIME_CONN_FIRST_TXN = 0x2068a3; bcs_aclInit = 0x187d5; mcsTaskCallback = 0x206a68; @@ -12178,6 +12192,7 @@ ulp_brcmFilter_delListItem = 0xa9e33; apipe_unMuteFunc = 0x5400d; _printf_string = 0xc3609; scanRssiThresholdDeviceListSize = 0x206cce; +rtx_rx_buffer = 0x370c00; sdpu_build_attrib_entry = 0xa6f9; iqcal_mainReplace = 0x207178; smp_sl_wait_app_rsp_table = 0xe7c68; diff --git a/projects/CYW20819A1/patch/xmit_state.c b/projects/CYW20819A1/patch/xmit_state.c index ed502cd..6e696ad 100644 --- a/projects/CYW20819A1/patch/xmit_state.c +++ b/projects/CYW20819A1/patch/xmit_state.c @@ -107,19 +107,8 @@ void xmit_memory(struct saved_regs *regs, int cont) { Found Map 0x23dc1900 - 0x23dc2000 Found Map 0x23dc3400 - 0x23dc4a00 Found Map 0x23dc4e00 - 0x23dc5700 - - TODO i think it was running until 0x41.... without further results - TODO restarted it at 0x40000000 and it didn't find something */ - //Those segments seem not to be relevant - //hci_xmit_segment(0x20000000, 0x20250000); - //hci_xmit_segment(0x20270000, 0x20284000); - //hci_xmit_segment(0x20500000, 0x20600000); - //hci_xmit_segment(0x22000000, 0x24000000); - //hci_xmit_segment(0x40000000, 0x40004000); //base_ToRam_alias_adr - //hci_xmit_segment(0x42000000, 0x42080000); //base_ToRam_bit_band_adr - hci_xmit_segment(0xe0000000, 0xe0100000); //ppb //Notify Done diff --git a/projects/CYW20819A1/project.json b/projects/CYW20819A1/project.json index 70b587d..7ef15ff 100644 --- a/projects/CYW20819A1/project.json +++ b/projects/CYW20819A1/project.json @@ -6278,7 +6278,9 @@ "dbfw_warning_flag": 2120552, "dbguart_read": 160315, "dcSmplCtlDefault": 2107796, + "dc_nbtc_clk": 3244168, "dc_ptu_uart_lsr": 3540004, + "dc_x_clk": 3245740, "deactivate_threadX_tick_timer": 48673, "debugPrintMissed": 2127324, "debuguart_Enable": 160265, @@ -10063,6 +10065,9 @@ "pcm_scoLinkUp": 525691, "pcmfifo_getRxDataSize": 552155, "pcmfifo_getTxDataSize": 552217, + "pcx2_btclk": 3244604, + "pcx2_pbtclk": 3244600, + "pcx_btclk": 3244588, "pcx_reg_backup": 2129040, "pds_PreSleepControlSettingsHW": 565249, "pds_RestoreControlSettingsHW": 565317, @@ -10072,6 +10077,7 @@ "pds_pre_sleep_data": 2119560, "peripheralUart_HandleTxEvent": 785897, "permute": 804093, + "phy_status": 3227652, "phy_status_shadow": 2104364, "pic_config_Group": 2109844, "pic_config_HandleDynReloTable": 2558065, @@ -10108,6 +10114,8 @@ "pktErrIns": 2105176, "pktTypeOffsets": 1013560, "pktTypeSlotCount": 1011244, + "pkt_hdr_status": 3246888, + "pkt_log": 3246892, "plcApuFilter": 2125984, "plcConfig": 2125957, "plcHandleRxData": 370627, @@ -10961,6 +10969,9 @@ "rtc_sec2RtcTime": 54607, "rtc_setRTCTime": 54563, "rtc_setReferenceTime": 54545, + "rtx_dma_ctl": 3227672, + "rtx_mem_start1": 3605504, + "rtx_rx_buffer": 3607552, "rxCordicBaseHi_adr_save": 2115660, "rxCordicBaseLo_adr_save": 2115656, "rxHeaderDoneDelayTime": 2126906, @@ -11636,6 +11647,8 @@ "spiffyd_txHalfWord": 567563, "spiffyd_txWord": 567585, "split_proxy_ptr": 2121480, + "sr_ptu_status_adr4": 3539076, + "sr_status": 3227660, "sr_status_shadow": 2104368, "srand": 939641, "ssl_mac_md5": 897981, @@ -11824,6 +11837,8 @@ "tssical_wrPadgc": 796703, "txDirectModFreqAdj1_reg": 2123372, "tx_application_define": 4297, + "tx_pkt_info": 3246796, + "tx_pkt_pyld_hdr": 3246800, "txnCollisionTbl": 996728, "u16toHexStr": 519933, "u32toHexStr": 519955,