2 * Copyright 2011 Drew Fisher <drew.m.fisher@gmail.com>. All rights reserved.
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in the
13 * documentation and/or other materials provided with the distribution.
15 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ''AS IS'' AND
16 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18 * ARE DISCLAIMED. IN NO EVENT SHALL DREW FISHER OR CONTRIBUTORS BE LIABLE
19 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27 * The views and conclusions contained in the software and documentation are
28 * those of the authors and should not be interpreted as representing official
29 * policies, either expressed or implied, of Drew Fisher.
38 static libusb_device_handle *dev;
56 #define LOG(...) printf(__VA_ARGS__)
57 #define fn_le32(x) (x)
58 // TODO: support architectures that aren't little-endian
60 static void dump_bl_cmd(bootloader_command cmd) {
62 for(i = 0; i < 24; i++)
63 LOG("%02X ", ((unsigned char*)(&cmd))[i]);
67 static int get_first_reply(void) {
68 unsigned char buffer[512];
71 res = libusb_bulk_transfer(dev, 0x81, buffer, 512, &transferred, 0);
73 LOG("Error reading first reply: %d\ttransferred: %d (expected %d)\n", res, transferred, 0x60);
76 LOG("Reading first reply: ");
78 for(i = 0; i < transferred; ++i) {
79 LOG("%02X ", buffer[i]);
85 static int get_reply(void) {
86 unsigned char dump[512];
87 status_code buffer = ((status_code*)dump)[0];
90 res = libusb_bulk_transfer(dev, 0x81, (unsigned char*)&buffer, 512, &transferred, 0);
91 if(res != 0 || transferred != sizeof(status_code)) {
92 LOG("Error reading reply: %d\ttransferred: %d (expected %lu)\n", res, transferred, sizeof(status_code));
95 if(fn_le32(buffer.magic) != 0x0a6fe000) {
96 LOG("Error reading reply: invalid magic %08X\n",buffer.magic);
99 if(fn_le32(buffer.seq) != seq) {
100 LOG("Error reading reply: non-matching sequence number %08X (expected %08X)\n", buffer.seq, seq);
103 if(fn_le32(buffer.status) != 0) {
104 LOG("Notice reading reply: last uint32_t was nonzero: %d\n", buffer.status);
107 LOG("Reading reply: ");
109 for(i = 0; i < transferred; ++i) {
110 LOG("%02X ", ((unsigned char*)(&buffer))[i]);
117 int main(int argc, char** argv) {
118 char* filename = "firmware.bin";
122 FILE* fw = fopen(filename, "r");
124 fprintf(stderr, "Failed to open %s: error %d", filename, errno);
129 libusb_set_debug(0,3);
130 dev = libusb_open_device_with_vid_pid(NULL, 0x045e, 0x02ad);
133 printf("Couldn't open device.\n");
137 libusb_set_configuration(dev, 1);
138 libusb_claim_interface(dev, 0);
142 bootloader_command cmd;
143 cmd.magic = fn_le32(0x06022009);
144 cmd.seq = fn_le32(seq);
145 cmd.bytes = fn_le32(0x60);
146 cmd.cmd = fn_le32(0);
147 cmd.write_addr = fn_le32(0x15);
148 cmd.unk = fn_le32(0);
150 LOG("About to send: ");
155 res = libusb_bulk_transfer(dev, 1, (unsigned char*)&cmd, sizeof(cmd), &transferred, 0);
156 if(res != 0 || transferred != sizeof(cmd)) {
157 LOG("Error: res: %d\ttransferred: %d (expected %lu)\n",res, transferred, sizeof(cmd));
160 res = get_first_reply(); // This first one doesn't have the usual magic bytes at the beginning, and is 96 bytes long - much longer than the usual 12-byte replies.
161 res = get_reply(); // I'm not sure why we do this twice here, but maybe it'll make sense later.
164 uint32_t addr = 0x00080000;
165 unsigned char page[0x4000];
168 read = fread(page, 1, 0x4000, fw);
173 cmd.seq = fn_le32(seq);
174 cmd.bytes = fn_le32(read);
175 cmd.cmd = fn_le32(0x03);
176 cmd.write_addr = fn_le32(addr);
177 LOG("About to send: ");
180 res = libusb_bulk_transfer(dev, 1, (unsigned char*)&cmd, sizeof(cmd), &transferred, 0);
181 if(res != 0 || transferred != sizeof(cmd)) {
182 LOG("Error: res: %d\ttransferred: %d (expected %lu)\n",res, transferred, sizeof(cmd));
186 while(bytes_sent < read) {
187 int to_send = (read - bytes_sent > 512 ? 512 : read - bytes_sent);
188 res = libusb_bulk_transfer(dev, 1, &page[bytes_sent], to_send, &transferred, 0);
189 if(res != 0 || transferred != to_send) {
190 LOG("Error: res: %d\ttransferred: %d (expected %d)\n",res, transferred, to_send);
193 bytes_sent += to_send;
197 addr += (uint32_t)read;
201 cmd.seq = fn_le32(seq);
202 cmd.bytes = fn_le32(0);
203 cmd.cmd = fn_le32(0x04);
204 cmd.write_addr = fn_le32(0x00080030);
206 res = libusb_bulk_transfer(dev, 1, (unsigned char*)&cmd, sizeof(cmd), &transferred, 0);
207 if(res != 0 || transferred != sizeof(cmd)) {
208 LOG("Error: res: %d\ttransferred: %d (expected %lu)\n", res, transferred, sizeof(cmd));
213 // Now the device reenumerates.