Simplified the structure by moving to the mapping mode 2 from mapping mode 3
This commit is contained in:
@@ -66,7 +66,7 @@ It's a key that you hold to open the BROM serial port. It depends on the vendor.
|
|||||||
|
|
||||||
### How is the tool working without a DA binary?
|
### How is the tool working without a DA binary?
|
||||||
|
|
||||||
Yes, MTreader used a DA in the past, but now it's completely blob-free (and this allowed to move it to the [public domain](./UNLICENSE)) and works via BROM itself. The trick is in using the correct mapping register setting: when we set the 32-bit value at the `0xa0510000` to 3, all the ROM contents (in 32-bit little-endian chunks) are mapped onto `0x10000000` base address by the MT626x chipset itself.
|
Yes, MTreader used a DA in the past, but now it's completely blob-free (and this allowed to move it to the [public domain](./UNLICENSE)) and works via BROM itself. The trick is in using the correct mapping register setting: when we set the 32-bit value at the `0xa0510000` to 2, all the ROM contents (in 32-bit little-endian chunks) are mapped onto zero base address by the MT626x chipset itself.
|
||||||
|
|
||||||
### Where was information collected from?
|
### Where was information collected from?
|
||||||
|
|
||||||
|
|||||||
+2
-3
@@ -65,13 +65,12 @@ class MTreader:
|
|||||||
self.write16(0xa0030000, 0x2200) # disable system watchdog
|
self.write16(0xa0030000, 0x2200) # disable system watchdog
|
||||||
self.write16(0xa0700a28, 0x8000) # enable USB download mode
|
self.write16(0xa0700a28, 0x8000) # enable USB download mode
|
||||||
self.write16(0xa0700a24, 2) # disable battery watchdog
|
self.write16(0xa0700a24, 2) # disable battery watchdog
|
||||||
self.write32(0xa0510000, 3) # enter memory map mode 3
|
self.write32(0xa0510000, 2) # enter memory map mode 2 to map ROM from the start of RAM
|
||||||
# now all flash is mapped as little-endian 32-bit chunks at 0x10000000
|
|
||||||
|
|
||||||
def read_flash(self, outfile, start, size, blk_size=1024):
|
def read_flash(self, outfile, start, size, blk_size=1024):
|
||||||
outf = open(outfile, 'wb')
|
outf = open(outfile, 'wb')
|
||||||
offset = 0
|
offset = 0
|
||||||
addr = 0x10000000 + start
|
addr = start
|
||||||
while size > 0:
|
while size > 0:
|
||||||
rsize = min(size, blk_size)
|
rsize = min(size, blk_size)
|
||||||
chunk = self.read32(addr, rsize>>2, '<')
|
chunk = self.read32(addr, rsize>>2, '<')
|
||||||
|
|||||||
Reference in New Issue
Block a user