diff --git a/dsrom/CBHC/arm_kernel/link.ld b/dsrom/CBHC/arm_kernel/link.ld index c28ba4a..1409c57 100644 --- a/dsrom/CBHC/arm_kernel/link.ld +++ b/dsrom/CBHC/arm_kernel/link.ld @@ -2,17 +2,19 @@ OUTPUT_ARCH(arm) MEMORY { - RAMX (rx) : ORIGIN = 0x08134100, LENGTH = 0x000BF00 + RAMX (rx) : ORIGIN = 0x08135000, LENGTH = 0x000B000 } SECTIONS { .text : ALIGN(0x100) { + __file_start = .; build/crt0.o(.init) *(.text) } .rodata : { *(.rodata*) + __file_end = .; } } diff --git a/dsrom/CBHC/arm_kernel/source/crt0.s b/dsrom/CBHC/arm_kernel/source/crt0.s index ae2a3b1..83d7bb6 100644 --- a/dsrom/CBHC/arm_kernel/source/crt0.s +++ b/dsrom/CBHC/arm_kernel/source/crt0.s @@ -5,8 +5,5 @@ .extern _main .type _main, %function -.extern memset -.type memset, %function - _start: b _main diff --git a/dsrom/CBHC/arm_kernel/source/elf_abi.h b/dsrom/CBHC/arm_kernel/source/elf_abi.h new file mode 100644 index 0000000..4d9c796 --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/elf_abi.h @@ -0,0 +1,591 @@ +/* + * Copyright (c) 1995, 1996, 2001, 2002 + * Erik Theisen. All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * This is the ELF ABI header file + * formerly known as "elf_abi.h". + */ + +#ifndef _ELF_ABI_H +#define _ELF_ABI_H + +/* + * This version doesn't work for 64-bit ABIs - Erik. + */ + +/* + * These typedefs need to be handled better. + */ +typedef unsigned int Elf32_Addr; /* Unsigned program address */ +typedef unsigned int Elf32_Off; /* Unsigned file offset */ +typedef signed int Elf32_Sword; /* Signed large integer */ +typedef unsigned int Elf32_Word; /* Unsigned large integer */ +typedef unsigned short Elf32_Half; /* Unsigned medium integer */ + +/* e_ident[] identification indexes */ +#define EI_MAG0 0 /* file ID */ +#define EI_MAG1 1 /* file ID */ +#define EI_MAG2 2 /* file ID */ +#define EI_MAG3 3 /* file ID */ +#define EI_CLASS 4 /* file class */ +#define EI_DATA 5 /* data encoding */ +#define EI_VERSION 6 /* ELF header version */ +#define EI_OSABI 7 /* OS/ABI specific ELF extensions */ +#define EI_ABIVERSION 8 /* ABI target version */ +#define EI_PAD 9 /* start of pad bytes */ +#define EI_NIDENT 16 /* Size of e_ident[] */ + +/* e_ident[] magic number */ +#define ELFMAG0 0x7f /* e_ident[EI_MAG0] */ +#define ELFMAG1 'E' /* e_ident[EI_MAG1] */ +#define ELFMAG2 'L' /* e_ident[EI_MAG2] */ +#define ELFMAG3 'F' /* e_ident[EI_MAG3] */ +#define ELFMAG "\177ELF" /* magic */ +#define SELFMAG 4 /* size of magic */ + +/* e_ident[] file class */ +#define ELFCLASSNONE 0 /* invalid */ +#define ELFCLASsigned int 1 /* 32-bit objs */ +#define ELFCLASS64 2 /* 64-bit objs */ +#define ELFCLASSNUM 3 /* number of classes */ + +/* e_ident[] data encoding */ +#define ELFDATANONE 0 /* invalid */ +#define ELFDATA2LSB 1 /* Little-Endian */ +#define ELFDATA2MSB 2 /* Big-Endian */ +#define ELFDATANUM 3 /* number of data encode defines */ + +/* e_ident[] OS/ABI specific ELF extensions */ +#define ELFOSABI_NONE 0 /* No extension specified */ +#define ELFOSABI_HPUX 1 /* Hewlett-Packard HP-UX */ +#define ELFOSABI_NETBSD 2 /* NetBSD */ +#define ELFOSABI_LINUX 3 /* Linux */ +#define ELFOSABI_SOLARIS 6 /* Sun Solaris */ +#define ELFOSABI_AIX 7 /* AIX */ +#define ELFOSABI_IRIX 8 /* IRIX */ +#define ELFOSABI_FREEBSD 9 /* FreeBSD */ +#define ELFOSABI_TRU64 10 /* Compaq TRU64 UNIX */ +#define ELFOSABI_MODESTO 11 /* Novell Modesto */ +#define ELFOSABI_OPENBSD 12 /* OpenBSD */ +/* 64-255 Architecture-specific value range */ + +/* e_ident[] ABI Version */ +#define ELFABIVERSION 0 + +/* e_ident */ +#define IS_ELF(ehdr) ((ehdr).e_ident[EI_MAG0] == ELFMAG0 && \ + (ehdr).e_ident[EI_MAG1] == ELFMAG1 && \ + (ehdr).e_ident[EI_MAG2] == ELFMAG2 && \ + (ehdr).e_ident[EI_MAG3] == ELFMAG3) + +/* ELF Header */ +typedef struct elfhdr{ + unsigned char e_ident[EI_NIDENT]; /* ELF Identification */ + Elf32_Half e_type; /* object file type */ + Elf32_Half e_machine; /* machine */ + Elf32_Word e_version; /* object file version */ + Elf32_Addr e_entry; /* virtual entry point */ + Elf32_Off e_phoff; /* program header table offset */ + Elf32_Off e_shoff; /* section header table offset */ + Elf32_Word e_flags; /* processor-specific flags */ + Elf32_Half e_ehsize; /* ELF header size */ + Elf32_Half e_phentsize; /* program header entry size */ + Elf32_Half e_phnum; /* number of program header entries */ + Elf32_Half e_shentsize; /* section header entry size */ + Elf32_Half e_shnum; /* number of section header entries */ + Elf32_Half e_shstrndx; /* section header table's "section + header string table" entry offset */ +} Elf32_Ehdr; + +/* e_type */ +#define ET_NONE 0 /* No file type */ +#define ET_REL 1 /* relocatable file */ +#define ET_EXEC 2 /* executable file */ +#define ET_DYN 3 /* shared object file */ +#define ET_CORE 4 /* core file */ +#define ET_NUM 5 /* number of types */ +#define ET_LOOS 0xfe00 /* reserved range for operating */ +#define ET_HIOS 0xfeff /* system specific e_type */ +#define ET_LOPROC 0xff00 /* reserved range for processor */ +#define ET_HIPROC 0xffff /* specific e_type */ + +/* e_machine */ +#define EM_NONE 0 /* No Machine */ +#define EM_M32 1 /* AT&T WE 32100 */ +#define EM_SPARC 2 /* SPARC */ +#define EM_386 3 /* Intel 80386 */ +#define EM_68K 4 /* Motorola 68000 */ +#define EM_88K 5 /* Motorola 88000 */ +#if 0 +#define EM_486 6 /* RESERVED - was Intel 80486 */ +#endif +#define EM_860 7 /* Intel 80860 */ +#define EM_MIPS 8 /* MIPS R3000 Big-Endian only */ +#define EM_S370 9 /* IBM System/370 Processor */ +#define EM_MIPS_RS4_BE 10 /* MIPS R4000 Big-Endian */ +#if 0 +#define EM_SPARC64 11 /* RESERVED - was SPARC v9 + 64-bit unoffical */ +#endif +/* RESERVED 11-14 for future use */ +#define EM_PARISC 15 /* HPPA */ +/* RESERVED 16 for future use */ +#define EM_VPP500 17 /* Fujitsu VPP500 */ +#define EM_SPARC32PLUS 18 /* Enhanced instruction set SPARC */ +#define EM_960 19 /* Intel 80960 */ +#define EM_PPC 20 /* PowerPC */ +#define EM_PPC64 21 /* 64-bit PowerPC */ +#define EM_S390 22 /* IBM System/390 Processor */ +/* RESERVED 23-35 for future use */ +#define EM_V800 36 /* NEC V800 */ +#define EM_FR20 37 /* Fujitsu FR20 */ +#define EM_RH32 38 /* TRW RH-32 */ +#define EM_RCE 39 /* Motorola RCE */ +#define EM_ARM 40 /* Advanced Risc Machines ARM */ +#define EM_ALPHA 41 /* Digital Alpha */ +#define EM_SH 42 /* Hitachi SH */ +#define EM_SPARCV9 43 /* SPARC Version 9 */ +#define EM_TRICORE 44 /* Siemens TriCore embedded processor */ +#define EM_ARC 45 /* Argonaut RISC Core */ +#define EM_H8_300 46 /* Hitachi H8/300 */ +#define EM_H8_300H 47 /* Hitachi H8/300H */ +#define EM_H8S 48 /* Hitachi H8S */ +#define EM_H8_500 49 /* Hitachi H8/500 */ +#define EM_IA_64 50 /* Intel Merced */ +#define EM_MIPS_X 51 /* Stanford MIPS-X */ +#define EM_COLDFIRE 52 /* Motorola Coldfire */ +#define EM_68HC12 53 /* Motorola M68HC12 */ +#define EM_MMA 54 /* Fujitsu MMA Multimedia Accelerator*/ +#define EM_PCP 55 /* Siemens PCP */ +#define EM_NCPU 56 /* Sony nCPU embeeded RISC */ +#define EM_NDR1 57 /* Denso NDR1 microprocessor */ +#define EM_STARCORE 58 /* Motorola Start*Core processor */ +#define EM_ME16 59 /* Toyota ME16 processor */ +#define EM_ST100 60 /* STMicroelectronic ST100 processor */ +#define EM_TINYJ 61 /* Advanced Logic Corp. Tinyj emb.fam*/ +#define EM_X86_64 62 /* AMD x86-64 */ +#define EM_PDSP 63 /* Sony DSP Processor */ +/* RESERVED 64,65 for future use */ +#define EM_FX66 66 /* Siemens FX66 microcontroller */ +#define EM_ST9PLUS 67 /* STMicroelectronics ST9+ 8/16 mc */ +#define EM_ST7 68 /* STmicroelectronics ST7 8 bit mc */ +#define EM_68HC16 69 /* Motorola MC68HC16 microcontroller */ +#define EM_68HC11 70 /* Motorola MC68HC11 microcontroller */ +#define EM_68HC08 71 /* Motorola MC68HC08 microcontroller */ +#define EM_68HC05 72 /* Motorola MC68HC05 microcontroller */ +#define EM_SVX 73 /* Silicon Graphics SVx */ +#define EM_ST19 74 /* STMicroelectronics ST19 8 bit mc */ +#define EM_VAX 75 /* Digital VAX */ +#define EM_CHRIS 76 /* Axis Communications embedded proc. */ +#define EM_JAVELIN 77 /* Infineon Technologies emb. proc. */ +#define EM_FIREPATH 78 /* Element 14 64-bit DSP Processor */ +#define EM_ZSP 79 /* LSI Logic 16-bit DSP Processor */ +#define EM_MMIX 80 /* Donald Knuth's edu 64-bit proc. */ +#define EM_HUANY 81 /* Harvard University mach-indep objs */ +#define EM_PRISM 82 /* SiTera Prism */ +#define EM_AVR 83 /* Atmel AVR 8-bit microcontroller */ +#define EM_FR30 84 /* Fujitsu FR30 */ +#define EM_D10V 85 /* Mitsubishi DV10V */ +#define EM_D30V 86 /* Mitsubishi DV30V */ +#define EM_V850 87 /* NEC v850 */ +#define EM_M32R 88 /* Mitsubishi M32R */ +#define EM_MN10300 89 /* Matsushita MN10200 */ +#define EM_MN10200 90 /* Matsushita MN10200 */ +#define EM_PJ 91 /* picoJava */ +#define EM_NUM 92 /* number of machine types */ + +/* Version */ +#define EV_NONE 0 /* Invalid */ +#define EV_CURRENT 1 /* Current */ +#define EV_NUM 2 /* number of versions */ + +/* Section Header */ +typedef struct { + Elf32_Word sh_name; /* name - index into section header + string table section */ + Elf32_Word sh_type; /* type */ + Elf32_Word sh_flags; /* flags */ + Elf32_Addr sh_addr; /* address */ + Elf32_Off sh_offset; /* file offset */ + Elf32_Word sh_size; /* section size */ + Elf32_Word sh_link; /* section header table index link */ + Elf32_Word sh_info; /* extra information */ + Elf32_Word sh_addralign; /* address alignment */ + Elf32_Word sh_entsize; /* section entry size */ +} Elf32_Shdr; + +/* Special Section Indexes */ +#define SHN_UNDEF 0 /* undefined */ +#define SHN_LORESERVE 0xff00 /* lower bounds of reserved indexes */ +#define SHN_LOPROC 0xff00 /* reserved range for processor */ +#define SHN_HIPROC 0xff1f /* specific section indexes */ +#define SHN_LOOS 0xff20 /* reserved range for operating */ +#define SHN_HIOS 0xff3f /* specific semantics */ +#define SHN_ABS 0xfff1 /* absolute value */ +#define SHN_COMMON 0xfff2 /* common symbol */ +#define SHN_XINDEX 0xffff /* Index is an extra table */ +#define SHN_HIRESERVE 0xffff /* upper bounds of reserved indexes */ + +/* sh_type */ +#define SHT_NULL 0 /* inactive */ +#define SHT_PROGBITS 1 /* program defined information */ +#define SHT_SYMTAB 2 /* symbol table section */ +#define SHT_STRTAB 3 /* string table section */ +#define SHT_RELA 4 /* relocation section with addends*/ +#define SHT_HASH 5 /* symbol hash table section */ +#define SHT_DYNAMIC 6 /* dynamic section */ +#define SHT_NOTE 7 /* note section */ +#define SHT_NOBITS 8 /* no space section */ +#define SHT_REL 9 /* relation section without addends */ +#define SHT_SHLIB 10 /* reserved - purpose unknown */ +#define SHT_DYNSYM 11 /* dynamic symbol table section */ +#define SHT_INIT_ARRAY 14 /* Array of constructors */ +#define SHT_FINI_ARRAY 15 /* Array of destructors */ +#define SHT_PREINIT_ARRAY 16 /* Array of pre-constructors */ +#define SHT_GROUP 17 /* Section group */ +#define SHT_SYMTAB_SHNDX 18 /* Extended section indeces */ +#define SHT_NUM 19 /* number of section types */ +#define SHT_LOOS 0x60000000 /* Start OS-specific */ +#define SHT_HIOS 0x6fffffff /* End OS-specific */ +#define SHT_LOPROC 0x70000000 /* reserved range for processor */ +#define SHT_HIPROC 0x7fffffff /* specific section header types */ +#define SHT_LOUSER 0x80000000 /* reserved range for application */ +#define SHT_HIUSER 0xffffffff /* specific indexes */ + +/* Section names */ +#define ELF_BSS ".bss" /* uninitialized data */ +#define ELF_COMMENT ".comment" /* version control information */ +#define ELF_DATA ".data" /* initialized data */ +#define ELF_DATA1 ".data1" /* initialized data */ +#define ELF_DEBUG ".debug" /* debug */ +#define ELF_DYNAMIC ".dynamic" /* dynamic linking information */ +#define ELF_DYNSTR ".dynstr" /* dynamic string table */ +#define ELF_DYNSYM ".dynsym" /* dynamic symbol table */ +#define ELF_FINI ".fini" /* termination code */ +#define ELF_FINI_ARRAY ".fini_array" /* Array of destructors */ +#define ELF_GOT ".got" /* global offset table */ +#define ELF_HASH ".hash" /* symbol hash table */ +#define ELF_INIT ".init" /* initialization code */ +#define ELF_INIT_ARRAY ".init_array" /* Array of constuctors */ +#define ELF_INTERP ".interp" /* Pathname of program interpreter */ +#define ELF_LINE ".line" /* Symbolic line numnber information */ +#define ELF_NOTE ".note" /* Contains note section */ +#define ELF_PLT ".plt" /* Procedure linkage table */ +#define ELF_PREINIT_ARRAY ".preinit_array" /* Array of pre-constructors */ +#define ELF_REL_DATA ".rel.data" /* relocation data */ +#define ELF_REL_FINI ".rel.fini" /* relocation termination code */ +#define ELF_REL_INIT ".rel.init" /* relocation initialization code */ +#define ELF_REL_DYN ".rel.dyn" /* relocaltion dynamic link info */ +#define ELF_REL_RODATA ".rel.rodata" /* relocation read-only data */ +#define ELF_REL_TEXT ".rel.text" /* relocation code */ +#define ELF_RODATA ".rodata" /* read-only data */ +#define ELF_RODATA1 ".rodata1" /* read-only data */ +#define ELF_SHSTRTAB ".shstrtab" /* section header string table */ +#define ELF_STRTAB ".strtab" /* string table */ +#define ELF_SYMTAB ".symtab" /* symbol table */ +#define ELF_SYMTAB_SHNDX ".symtab_shndx"/* symbol table section index */ +#define ELF_TBSS ".tbss" /* thread local uninit data */ +#define ELF_TDATA ".tdata" /* thread local init data */ +#define ELF_TDATA1 ".tdata1" /* thread local init data */ +#define ELF_TEXT ".text" /* code */ + +/* Section Attribute Flags - sh_flags */ +#define SHF_WRITE 0x1 /* Writable */ +#define SHF_ALLOC 0x2 /* occupies memory */ +#define SHF_EXECINSTR 0x4 /* executable */ +#define SHF_MERGE 0x10 /* Might be merged */ +#define SHF_STRINGS 0x20 /* Contains NULL terminated strings */ +#define SHF_INFO_LINK 0x40 /* sh_info contains SHT index */ +#define SHF_LINK_ORDER 0x80 /* Preserve order after combining*/ +#define SHF_OS_NONCONFORMING 0x100 /* Non-standard OS specific handling */ +#define SHF_GROUP 0x200 /* Member of section group */ +#define SHF_TLS 0x400 /* Thread local storage */ +#define SHF_MASKOS 0x0ff00000 /* OS specific */ +#define SHF_MASKPROC 0xf0000000 /* reserved bits for processor */ + /* specific section attributes */ + +/* Section Group Flags */ +#define GRP_COMDAT 0x1 /* COMDAT group */ +#define GRP_MASKOS 0x0ff00000 /* Mask OS specific flags */ +#define GRP_MASKPROC 0xf0000000 /* Mask processor specific flags */ + +/* Symbol Table Entry */ +typedef struct elf32_sym { + Elf32_Word st_name; /* name - index into string table */ + Elf32_Addr st_value; /* symbol value */ + Elf32_Word st_size; /* symbol size */ + unsigned char st_info; /* type and binding */ + unsigned char st_other; /* 0 - no defined meaning */ + Elf32_Half st_shndx; /* section header index */ +} Elf32_Sym; + +/* Symbol table index */ +#define STN_UNDEF 0 /* undefined */ + +/* Extract symbol info - st_info */ +#define ELF32_ST_BIND(x) ((x) >> 4) +#define ELF32_ST_TYPE(x) (((unsigned int) x) & 0xf) +#define ELF32_ST_INFO(b,t) (((b) << 4) + ((t) & 0xf)) +#define ELF32_ST_VISIBILITY(x) ((x) & 0x3) + +/* Symbol Binding - ELF32_ST_BIND - st_info */ +#define STB_LOCAL 0 /* Local symbol */ +#define STB_GLOBAL 1 /* Global symbol */ +#define STB_WEAK 2 /* like global - lower precedence */ +#define STB_NUM 3 /* number of symbol bindings */ +#define STB_LOOS 10 /* reserved range for operating */ +#define STB_HIOS 12 /* system specific symbol bindings */ +#define STB_LOPROC 13 /* reserved range for processor */ +#define STB_HIPROC 15 /* specific symbol bindings */ + +/* Symbol type - ELF32_ST_TYPE - st_info */ +#define STT_NOTYPE 0 /* not specified */ +#define STT_OBJECT 1 /* data object */ +#define STT_FUNC 2 /* function */ +#define STT_SECTION 3 /* section */ +#define STT_FILE 4 /* file */ +#define STT_NUM 5 /* number of symbol types */ +#define STT_TLS 6 /* Thread local storage symbol */ +#define STT_LOOS 10 /* reserved range for operating */ +#define STT_HIOS 12 /* system specific symbol types */ +#define STT_LOPROC 13 /* reserved range for processor */ +#define STT_HIPROC 15 /* specific symbol types */ + +/* Symbol visibility - ELF32_ST_VISIBILITY - st_other */ +#define STV_DEFAULT 0 /* Normal visibility rules */ +#define STV_INTERNAL 1 /* Processor specific hidden class */ +#define STV_HIDDEN 2 /* Symbol unavailable in other mods */ +#define STV_PROTECTED 3 /* Not preemptible, not exported */ + + +/* Relocation entry with implicit addend */ +typedef struct +{ + Elf32_Addr r_offset; /* offset of relocation */ + Elf32_Word r_info; /* symbol table index and type */ +} Elf32_Rel; + +/* Relocation entry with explicit addend */ +typedef struct +{ + Elf32_Addr r_offset; /* offset of relocation */ + Elf32_Word r_info; /* symbol table index and type */ + Elf32_Sword r_addend; +} Elf32_Rela; + +/* Extract relocation info - r_info */ +#define ELF32_R_SYM(i) ((i) >> 8) +#define ELF32_R_TYPE(i) ((unsigned char) (i)) +#define ELF32_R_INFO(s,t) (((s) << 8) + (unsigned char)(t)) + +/* Program Header */ +typedef struct { + Elf32_Word p_type; /* segment type */ + Elf32_Off p_offset; /* segment offset */ + Elf32_Addr p_vaddr; /* virtual address of segment */ + Elf32_Addr p_paddr; /* physical address - ignored? */ + Elf32_Word p_filesz; /* number of bytes in file for seg. */ + Elf32_Word p_memsz; /* number of bytes in mem. for seg. */ + Elf32_Word p_flags; /* flags */ + Elf32_Word p_align; /* memory alignment */ +} Elf32_Phdr; + +/* Segment types - p_type */ +#define PT_NULL 0 /* unused */ +#define PT_LOAD 1 /* loadable segment */ +#define PT_DYNAMIC 2 /* dynamic linking section */ +#define PT_INTERP 3 /* the RTLD */ +#define PT_NOTE 4 /* auxiliary information */ +#define PT_SHLIB 5 /* reserved - purpose undefined */ +#define PT_PHDR 6 /* program header */ +#define PT_TLS 7 /* Thread local storage template */ +#define PT_NUM 8 /* Number of segment types */ +#define PT_LOOS 0x60000000 /* reserved range for operating */ +#define PT_HIOS 0x6fffffff /* system specific segment types */ +#define PT_LOPROC 0x70000000 /* reserved range for processor */ +#define PT_HIPROC 0x7fffffff /* specific segment types */ + +/* Segment flags - p_flags */ +#define PF_X 0x1 /* Executable */ +#define PF_W 0x2 /* Writable */ +#define PF_R 0x4 /* Readable */ +#define PF_MASKOS 0x0ff00000 /* OS specific segment flags */ +#define PF_MASKPROC 0xf0000000 /* reserved bits for processor */ + /* specific segment flags */ +/* Dynamic structure */ +typedef struct +{ + Elf32_Sword d_tag; /* controls meaning of d_val */ + union + { + Elf32_Word d_val; /* Multiple meanings - see d_tag */ + Elf32_Addr d_ptr; /* program virtual address */ + } d_un; +} Elf32_Dyn; + +extern Elf32_Dyn _DYNAMIC[]; + +/* Dynamic Array Tags - d_tag */ +#define DT_NULL 0 /* marks end of _DYNAMIC array */ +#define DT_NEEDED 1 /* string table offset of needed lib */ +#define DT_PLTRELSZ 2 /* size of relocation entries in PLT */ +#define DT_PLTGOT 3 /* address PLT/GOT */ +#define DT_HASH 4 /* address of symbol hash table */ +#define DT_STRTAB 5 /* address of string table */ +#define DT_SYMTAB 6 /* address of symbol table */ +#define DT_RELA 7 /* address of relocation table */ +#define DT_RELASZ 8 /* size of relocation table */ +#define DT_RELAENT 9 /* size of relocation entry */ +#define DT_STRSZ 10 /* size of string table */ +#define DT_SYMENT 11 /* size of symbol table entry */ +#define DT_INIT 12 /* address of initialization func. */ +#define DT_FINI 13 /* address of termination function */ +#define DT_SONAME 14 /* string table offset of shared obj */ +#define DT_RPATH 15 /* string table offset of library + search path */ +#define DT_SYMBOLIC 16 /* start sym search in shared obj. */ +#define DT_REL 17 /* address of rel. tbl. w addends */ +#define DT_RELSZ 18 /* size of DT_REL relocation table */ +#define DT_RELENT 19 /* size of DT_REL relocation entry */ +#define DT_PLTREL 20 /* PLT referenced relocation entry */ +#define DT_DEBUG 21 /* bugger */ +#define DT_TEXTREL 22 /* Allow rel. mod. to unwritable seg */ +#define DT_JMPREL 23 /* add. of PLT's relocation entries */ +#define DT_BIND_NOW 24 /* Process relocations of object */ +#define DT_INIT_ARRAY 25 /* Array with addresses of init fct */ +#define DT_FINI_ARRAY 26 /* Array with addresses of fini fct */ +#define DT_INIT_ARRAYSZ 27 /* Size in bytes of DT_INIT_ARRAY */ +#define DT_FINI_ARRAYSZ 28 /* Size in bytes of DT_FINI_ARRAY */ +#define DT_RUNPATH 29 /* Library search path */ +#define DT_FLAGS 30 /* Flags for the object being loaded */ +#define DT_ENCODING 32 /* Start of encoded range */ +#define DT_PREINIT_ARRAY 32 /* Array with addresses of preinit fct*/ +#define DT_PREINIT_ARRAYSZ 33 /* size in bytes of DT_PREINIT_ARRAY */ +#define DT_NUM 34 /* Number used. */ +#define DT_LOOS 0x60000000 /* reserved range for OS */ +#define DT_HIOS 0x6fffffff /* specific dynamic array tags */ +#define DT_LOPROC 0x70000000 /* reserved range for processor */ +#define DT_HIPROC 0x7fffffff /* specific dynamic array tags */ + +/* Dynamic Tag Flags - d_un.d_val */ +#define DF_ORIGIN 0x01 /* Object may use DF_ORIGIN */ +#define DF_SYMBOLIC 0x02 /* Symbol resolutions starts here */ +#define DF_TEXTREL 0x04 /* Object contains text relocations */ +#define DF_BIND_NOW 0x08 /* No lazy binding for this object */ +#define DF_STATIC_TLS 0x10 /* Static thread local storage */ + +/* Standard ELF hashing function */ +unsigned long elf_hash(const unsigned char *name); + +#define ELF_TARG_VER 1 /* The ver for which this code is intended */ + +/* + * XXX - PowerPC defines really don't belong in here, + * but we'll put them in for simplicity. + */ + +/* Values for Elf32/64_Ehdr.e_flags. */ +#define EF_PPC_EMB 0x80000000 /* PowerPC embedded flag */ + +/* Cygnus local bits below */ +#define EF_PPC_RELOCATABLE 0x00010000 /* PowerPC -mrelocatable flag*/ +#define EF_PPC_RELOCATABLE_LIB 0x00008000 /* PowerPC -mrelocatable-lib + flag */ + +/* PowerPC relocations defined by the ABIs */ +#define R_PPC_NONE 0 +#define R_PPC_ADDR32 1 /* 32bit absolute address */ +#define R_PPC_ADDR24 2 /* 26bit address, 2 bits ignored. */ +#define R_PPC_ADDR16 3 /* 16bit absolute address */ +#define R_PPC_ADDR16_LO 4 /* lower 16bit of absolute address */ +#define R_PPC_ADDR16_HI 5 /* high 16bit of absolute address */ +#define R_PPC_ADDR16_HA 6 /* adjusted high 16bit */ +#define R_PPC_ADDR14 7 /* 16bit address, 2 bits ignored */ +#define R_PPC_ADDR14_BRTAKEN 8 +#define R_PPC_ADDR14_BRNTAKEN 9 +#define R_PPC_REL24 10 /* PC relative 26 bit */ +#define R_PPC_REL14 11 /* PC relative 16 bit */ +#define R_PPC_REL14_BRTAKEN 12 +#define R_PPC_REL14_BRNTAKEN 13 +#define R_PPC_GOT16 14 +#define R_PPC_GOT16_LO 15 +#define R_PPC_GOT16_HI 16 +#define R_PPC_GOT16_HA 17 +#define R_PPC_PLTREL24 18 +#define R_PPC_COPY 19 +#define R_PPC_GLOB_DAT 20 +#define R_PPC_JMP_SLOT 21 +#define R_PPC_RELATIVE 22 +#define R_PPC_LOCAL24PC 23 +#define R_PPC_UADDR32 24 +#define R_PPC_UADDR16 25 +#define R_PPC_REL32 26 +#define R_PPC_PLT32 27 +#define R_PPC_PLTREL32 28 +#define R_PPC_PLT16_LO 29 +#define R_PPC_PLT16_HI 30 +#define R_PPC_PLT16_HA 31 +#define R_PPC_SDAREL16 32 +#define R_PPC_SECTOFF 33 +#define R_PPC_SECTOFF_LO 34 +#define R_PPC_SECTOFF_HI 35 +#define R_PPC_SECTOFF_HA 36 +/* Keep this the last entry. */ +#define R_PPC_NUM 37 + +/* The remaining relocs are from the Embedded ELF ABI, and are not + in the SVR4 ELF ABI. */ +#define R_PPC_EMB_NADDR32 101 +#define R_PPC_EMB_NADDR16 102 +#define R_PPC_EMB_NADDR16_LO 103 +#define R_PPC_EMB_NADDR16_HI 104 +#define R_PPC_EMB_NADDR16_HA 105 +#define R_PPC_EMB_SDAI16 106 +#define R_PPC_EMB_SDA2I16 107 +#define R_PPC_EMB_SDA2REL 108 +#define R_PPC_EMB_SDA21 109 /* 16 bit offset in SDA */ +#define R_PPC_EMB_MRKREF 110 +#define R_PPC_EMB_RELSEC16 111 +#define R_PPC_EMB_RELST_LO 112 +#define R_PPC_EMB_RELST_HI 113 +#define R_PPC_EMB_RELST_HA 114 +#define R_PPC_EMB_BIT_FLD 115 +#define R_PPC_EMB_RELSDA 116 /* 16 bit relative offset in SDA */ + +/* Diab tool relocations. */ +#define R_PPC_DIAB_SDA21_LO 180 /* like EMB_SDA21, but lower 16 bit */ +#define R_PPC_DIAB_SDA21_HI 181 /* like EMB_SDA21, but high 16 bit */ +#define R_PPC_DIAB_SDA21_HA 182 /* like EMB_SDA21, adjusted high 16 */ +#define R_PPC_DIAB_RELSDA_LO 183 /* like EMB_RELSDA, but lower 16 bit */ +#define R_PPC_DIAB_RELSDA_HI 184 /* like EMB_RELSDA, but high 16 bit */ +#define R_PPC_DIAB_RELSDA_HA 185 /* like EMB_RELSDA, adjusted high 16 */ + +/* This is a phony reloc to handle any old fashioned TOC16 references + that may still be in object files. */ +#define R_PPC_TOC16 255 + +#endif /* _ELF_H */ diff --git a/dsrom/CBHC/arm_kernel/source/elf_patcher.c b/dsrom/CBHC/arm_kernel/source/elf_patcher.c new file mode 100644 index 0000000..8310964 --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/elf_patcher.c @@ -0,0 +1,110 @@ +/*************************************************************************** + * Copyright (C) 2016 + * by Dimok + * + * This software is provided 'as-is', without any express or implied + * warranty. In no event will the authors be held liable for any + * damages arising from the use of this software. + * + * Permission is granted to anyone to use this software for any + * purpose, including commercial applications, and to alter it and + * redistribute it freely, subject to the following restrictions: + * + * 1. The origin of this software must not be misrepresented; you + * must not claim that you wrote the original software. If you use + * this software in a product, an acknowledgment in the product + * documentation would be appreciated but is not required. + * + * 2. Altered source versions must be plainly marked as such, and + * must not be misrepresented as being the original software. + * + * 3. This notice may not be removed or altered from any source + * distribution. + ***************************************************************************/ +#include "types.h" +#include "elf_abi.h" +#include "utils.h" + +static Elf32_Phdr * get_section(u32 data, u32 vaddr) +{ + Elf32_Ehdr *ehdr = (Elf32_Ehdr *) data; + + if ( !IS_ELF (*ehdr) + || (ehdr->e_type != ET_EXEC) + || (ehdr->e_machine != EM_ARM)) + { + return 0; + } + + Elf32_Phdr *phdr = 0; + + u32 i; + for(i = 0; i < ehdr->e_phnum; i++) + { + phdr = (Elf32_Phdr *) (data + ehdr->e_phoff + ehdr->e_phentsize * i); + + if((vaddr >= phdr[0].p_vaddr) && ((i == ehdr->e_phnum) || (vaddr < phdr[1].p_vaddr))) + { + break; + } + } + return phdr; +} + +void section_write_bss(u32 ios_elf_start, u32 address, u32 size) +{ + Elf32_Phdr *phdr = get_section(ios_elf_start, address); + if(!phdr) + return; + + if((address - phdr->p_vaddr + size) > phdr->p_memsz) + { + phdr->p_memsz = (address - phdr->p_vaddr + size); + } +} + +void section_write(u32 ios_elf_start, u32 address, const void *data, u32 size) +{ + Elf32_Phdr *phdr = get_section(ios_elf_start, address); + if(!phdr) + return; + + u32 *addr = (u32*)(ios_elf_start + address - phdr->p_vaddr + phdr->p_offset); + + if((address - phdr->p_vaddr + size) > phdr->p_filesz) + { + u32 additionalSize = address - phdr->p_vaddr + size - phdr->p_filesz; + + Elf32_Ehdr *ehdr = (Elf32_Ehdr *) ios_elf_start; + Elf32_Phdr * tmpPhdr; + u32 i; + for(i = (ehdr->e_phnum-1); i >= 0; i--) + { + tmpPhdr = (Elf32_Phdr *) (ios_elf_start + ehdr->e_phoff + ehdr->e_phentsize * i); + + if(phdr->p_offset < tmpPhdr->p_offset) + { + reverse_memcpy((u8*)ios_elf_start + tmpPhdr->p_offset + additionalSize, (u8*)ios_elf_start + tmpPhdr->p_offset, tmpPhdr->p_filesz); + tmpPhdr->p_offset += additionalSize; + } + else { + break; + } + } + phdr->p_filesz += additionalSize; + if(phdr->p_memsz < phdr->p_filesz) + { + phdr->p_memsz = phdr->p_filesz; + } + } + + // in most cases only a word is copied to an aligned address so do a short cut for performance + if(size == 4 && !((unsigned int)addr & 3) && !((unsigned int)data & 3)) + { + *(u32*)addr = *(u32*)data; + } + else + { + kernel_memcpy(addr, data, size); + } +} diff --git a/dsrom/CBHC/arm_kernel/source/elf_patcher.h b/dsrom/CBHC/arm_kernel/source/elf_patcher.h new file mode 100644 index 0000000..3033ea8 --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/elf_patcher.h @@ -0,0 +1,58 @@ +/*************************************************************************** + * Copyright (C) 2016 + * by Dimok + * + * This software is provided 'as-is', without any express or implied + * warranty. In no event will the authors be held liable for any + * damages arising from the use of this software. + * + * Permission is granted to anyone to use this software for any + * purpose, including commercial applications, and to alter it and + * redistribute it freely, subject to the following restrictions: + * + * 1. The origin of this software must not be misrepresented; you + * must not claim that you wrote the original software. If you use + * this software in a product, an acknowledgment in the product + * documentation would be appreciated but is not required. + * + * 2. Altered source versions must be plainly marked as such, and + * must not be misrepresented as being the original software. + * + * 3. This notice may not be removed or altered from any source + * distribution. + ***************************************************************************/ +#ifndef _ELF_PATCHER_H +#define _ELF_PATCHER_H + +#include "types.h" + +#define ARM_B(addr, func) (0xEA000000 | ((((u32)(func) - (u32)(addr) - 8) >> 2) & 0x00FFFFFF)) +#define ARM_BL(addr, func) (0xEB000000 | ((((u32)(func) - (u32)(addr) - 8) >> 2) & 0x00FFFFFF)) + +typedef struct +{ + u32 address; + void* data; + u32 size; +} patch_table_t; + +void section_write(u32 ios_elf_start, u32 address, const void *data, u32 size); +void section_write_bss(u32 ios_elf_start, u32 address, u32 size); + +static inline void section_write_word(u32 ios_elf_start, u32 address, u32 word) +{ + section_write(ios_elf_start, address, &word, sizeof(word)); +} + + +static inline void patch_table_entries(u32 ios_elf_start, const patch_table_t * patch_table, u32 patch_count) +{ + u32 i; + for(i = 0; i < patch_count; i++) + { + section_write(ios_elf_start, patch_table[i].address, patch_table[i].data, patch_table[i].size); + } +} + + +#endif diff --git a/dsrom/CBHC/arm_kernel/source/main.c b/dsrom/CBHC/arm_kernel/source/main.c index 783d1a2..7431844 100644 --- a/dsrom/CBHC/arm_kernel/source/main.c +++ b/dsrom/CBHC/arm_kernel/source/main.c @@ -1,8 +1,9 @@ #include "types.h" #include "utils.h" +#include "reload.h" +#include "elf_patcher.h" #include "../../payload/arm_user_bin.h" -#include "../../payload/wupserver_bin.h" - +#include "wupserver.h" static const char repairData_set_fault_behavior[] = { 0xE1,0x2F,0xFF,0x1E,0xE9,0x2D,0x40,0x30,0xE5,0x93,0x20,0x00,0xE1,0xA0,0x40,0x00, 0xE5,0x92,0x30,0x54,0xE1,0xA0,0x50,0x01,0xE3,0x53,0x00,0x01,0x0A,0x00,0x00,0x02, @@ -42,27 +43,13 @@ static const char os_launch_hook[] = { static const char sd_path[] = "/vol/sdcard"; -static unsigned int __attribute__((noinline)) disable_mmu(void) -{ - unsigned int control_register = 0; - asm volatile("MRC p15, 0, %0, c1, c0, 0" : "=r" (control_register)); - asm volatile("MCR p15, 0, %0, c1, c0, 0" : : "r" (control_register & 0xFFFFEFFA)); - return control_register; -} - -static void __attribute__((noinline)) restore_mmu(unsigned int control_register) -{ - asm volatile("MCR p15, 0, %0, c1, c0, 0" : : "r" (control_register)); -} +#define wupserver_phys (0x0510E570 - 0x05100000 + 0x13D80000) int _main() { - int(*disable_interrupts)() = (int(*)())0x0812E778; - int(*enable_interrupts)(int) = (int(*)(int))0x0812E78C; void(*invalidate_icache)() = (void(*)())0x0812DCF0; void(*invalidate_dcache)(unsigned int, unsigned int) = (void(*)())0x08120164; void(*flush_dcache)(unsigned int, unsigned int) = (void(*)())0x08120160; - char* (*kernel_memcpy)(void*, void*, int) = (char*(*)(void*, void*, int))0x08131D04; flush_dcache(0x081200F0, 0x4001); // giving a size >= 0x4000 flushes all cache @@ -76,6 +63,9 @@ int _main() /* Patch kernel_error_handler to BX LR immediately */ *(volatile u32*)0x08129A24 = 0xE12FFF1E; + /* apply IOS ELF launch hook (thanks dimok!) */ + *(volatile u32*)0x0812A120 = ARM_BL(0x0812A120, kernel_launch_ios); + void * pset_fault_behavior = (void*)0x081298BC; kernel_memcpy(pset_fault_behavior, (void*)repairData_set_fault_behavior, sizeof(repairData_set_fault_behavior)); @@ -91,9 +81,8 @@ int _main() // overwrite mcp_d_r code with wupserver *(unsigned int*)(0x0510E56C - 0x05100000 + 0x13D80000) = 0x47700000; //bx lr - void * test = (void*)(0x0510E570 - 0x05100000 + 0x13D80000); - kernel_memcpy(test, (void*)wupserver_bin, sizeof(wupserver_bin)); - invalidate_dcache((u32)test, sizeof(wupserver_bin)); + kernel_memcpy((void*)wupserver_phys, get_wupserver_bin(), get_wupserver_bin_len()); + invalidate_dcache((u32)wupserver_phys, get_wupserver_bin_len()); invalidate_icache(); // replace ioctl 0x62 code with jump to wupserver @@ -157,15 +146,15 @@ int _main() for (i = 0; i < sizeof(os_launch_hook); i++) ((char*)(0x05059938 - 0x05000000 + 0x081C0000))[i] = os_launch_hook[i]; - - // change system.xml to syshax.xml - *(volatile u32*)(0x050600F0 - 0x05060000 + 0x08220000) = 0x79736861; //ysha - *(volatile u32*)(0x050600F4 - 0x05060000 + 0x08220000) = 0x782E786D; //x.xm - - *(volatile u32*)(0x05060114 - 0x05060000 + 0x08220000) = 0x79736861; //ysha - *(volatile u32*)(0x05060118 - 0x05060000 + 0x08220000) = 0x782E786D; //x.xm } + // change system.xml to syshax.xml + *(volatile u32*)(0x050600F0 - 0x05060000 + 0x08220000) = 0x79736861; //ysha + *(volatile u32*)(0x050600F4 - 0x05060000 + 0x08220000) = 0x782E786D; //x.xm + + *(volatile u32*)(0x05060114 - 0x05060000 + 0x08220000) = 0x79736861; //ysha + *(volatile u32*)(0x05060118 - 0x05060000 + 0x08220000) = 0x782E786D; //x.xm + *(volatile u32*)(0x1555500) = 0; /* REENABLE MMU */ diff --git a/dsrom/CBHC/arm_kernel/source/mmu.s b/dsrom/CBHC/arm_kernel/source/mmu.s new file mode 100644 index 0000000..17fab93 --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/mmu.s @@ -0,0 +1,18 @@ +.section ".text" +.arm +.align 4 + +.globl disable_mmu +.type disable_mmu, %function +disable_mmu: + mrc p15, 0, r0, c1, c0, 0 + ldr r1, =#0xFFFFEFFA + and r1, r0, r1 + mcr p15, 0, r1, c1, c0, 0 + bx lr + +.globl restore_mmu +.type restore_mmu, %function +restore_mmu: + mcr p15, 0, r0, c1, c0, 0 + bx lr diff --git a/dsrom/CBHC/arm_kernel/source/reload.c b/dsrom/CBHC/arm_kernel/source/reload.c new file mode 100644 index 0000000..22aa77b --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/reload.c @@ -0,0 +1,86 @@ +//kernel relaunch hook, thanks to dimok +#include "types.h" +#include "utils.h" +#include "reload.h" +#include "elf_patcher.h" +#include "wupserver.h" + +extern char __file_start, __file_end; + +void kernel_launch_ios(u32 launch_address, u32 L, u32 C, u32 H) +{ + void (*kernel_launch_bootrom)(u32 launch_address, u32 L, u32 C, u32 H) = (void*)0x0812A050; + + if(*(u32*)(launch_address - 0x300 + 0x1AC) == 0x00DFD000) + { + int level = disable_interrupts(); + unsigned int control_register = disable_mmu(); + + u32 ios_elf_start = launch_address + 0x804 - 0x300; + + // nop out memcmp hash checks + section_write_word(ios_elf_start, 0x040017E0, 0xE3A00000); // mov r0, #0 + section_write_word(ios_elf_start, 0x040019C4, 0xE3A00000); // mov r0, #0 + section_write_word(ios_elf_start, 0x04001BB0, 0xE3A00000); // mov r0, #0 + section_write_word(ios_elf_start, 0x04001D40, 0xE3A00000); // mov r0, #0 + + // patch OS launch sig check + section_write_word(ios_elf_start, 0x0500A818, 0x20002000); // mov r0, #0; mov r0, #0 + + // patch MCP authentication check + section_write_word(ios_elf_start, 0x05014CAC, 0x20004770); // mov r0, #0; bx lr + + // jump over overwritten MCP debug thread start function + section_write_word(ios_elf_start, 0x0501FEE0, 0x20002000); //mov r0, #0; mov r0, #0 + + // fix 10 minute timeout that crashes MCP after 10 minutes of booting + section_write_word(ios_elf_start, 0x05022474, 0xFFFFFFFF); // NEW_TIMEOUT + + // replace ioctl 0x62 code with jump to wupserver + section_write_word(ios_elf_start, 0x05026BA8, 0x47780000); // bx pc + section_write_word(ios_elf_start, 0x05026BAC, 0xE59F1000); // ldr r1, [pc] + section_write_word(ios_elf_start, 0x05026BB0, 0xE12FFF11); // bx r1 + section_write_word(ios_elf_start, 0x05026BB4, 0x0510E570); // wupserver code + + // patch cert verification + section_write_word(ios_elf_start, 0x05052A90, 0xE3A00000); // mov r0, #0 + section_write_word(ios_elf_start, 0x05052A94, 0xE12FFF1E); // bx lr + + // patch IOSC_VerifyPubkeySign to always succeed + section_write_word(ios_elf_start, 0x05052C44, 0xE3A00000); // mov r0, #0 + section_write_word(ios_elf_start, 0x05052C48, 0xE12FFF1E); // bx lr + + // patch cached cert check + section_write_word(ios_elf_start, 0x05054D6C, 0xE3A00000); // mov r0, 0 + section_write_word(ios_elf_start, 0x05054D70, 0xE12FFF1E); // bx lr + + // change system.xml to syshax.xml + section_write_word(ios_elf_start, 0x050600F0, 0x79736861); //ysha + section_write_word(ios_elf_start, 0x050600F4, 0x782E786D); //x.xm + + section_write_word(ios_elf_start, 0x05060114, 0x79736861); //ysha + section_write_word(ios_elf_start, 0x05060118, 0x782E786D); //x.xm + + // overwrite mcp_d_r code with wupserver + section_write_word(ios_elf_start, 0x0510E56C, 0x47700000); //bx lr + section_write(ios_elf_start, 0x0510E570, get_wupserver_bin(), get_wupserver_bin_len()); + + // apply IOS ELF launch hook (thanks dimok!) + section_write_word(ios_elf_start, 0x0812A120, ARM_BL(0x0812A120, kernel_launch_ios)); + + // Put arm_kernel file back where it is now + section_write(ios_elf_start, (u32)&__file_start, &__file_start, &__file_end - &__file_start); + + // allow any region title launch + section_write_word(ios_elf_start, 0xE0030498, 0xE3A00000); // mov r0, #0 + + // allow custom bootLogoTex and bootMovie.h264 + section_write_word(ios_elf_start, 0xE0030D68, 0xE3A00000); // mov r0, #0 + section_write_word(ios_elf_start, 0xE0030D34, 0xE3A00000); // mov r0, #0 + + restore_mmu(control_register); + enable_interrupts(level); + } + + kernel_launch_bootrom(launch_address, L, C, H); +} diff --git a/dsrom/CBHC/arm_kernel/source/reload.h b/dsrom/CBHC/arm_kernel/source/reload.h new file mode 100644 index 0000000..ef11113 --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/reload.h @@ -0,0 +1,7 @@ + +#ifndef _RELOAD_H_ +#define _RELOAD_H_ + +void kernel_launch_ios(u32 launch_address, u32 L, u32 C, u32 H); + +#endif diff --git a/dsrom/CBHC/arm_kernel/source/utils.c b/dsrom/CBHC/arm_kernel/source/utils.c index f02ae47..8ce65ae 100644 --- a/dsrom/CBHC/arm_kernel/source/utils.c +++ b/dsrom/CBHC/arm_kernel/source/utils.c @@ -1,25 +1,92 @@ +/*************************************************************************** + * Copyright (C) 2016 + * by Dimok + * + * This software is provided 'as-is', without any express or implied + * warranty. In no event will the authors be held liable for any + * damages arising from the use of this software. + * + * Permission is granted to anyone to use this software for any + * purpose, including commercial applications, and to alter it and + * redistribute it freely, subject to the following restrictions: + * + * 1. The origin of this software must not be misrepresented; you + * must not claim that you wrote the original software. If you use + * this software in a product, an acknowledgment in the product + * documentation would be appreciated but is not required. + * + * 2. Altered source versions must be plainly marked as such, and + * must not be misrepresented as being the original software. + * + * 3. This notice may not be removed or altered from any source + * distribution. + ***************************************************************************/ -void* m_memcpy(void *dst, const void *src, unsigned int len) +// this memcpy is optimized for speed and to work with MEM1 32 bit access alignment requirement +void reverse_memcpy(void* dst, const void* src, unsigned int size) { - const unsigned char *src_ptr = (const unsigned char *)src; - unsigned char *dst_ptr = (unsigned char *)dst; + const unsigned char *src_p; + unsigned char *dst_p; - while(len) + if((size >= 4) && !((dst - src) & 3)) { - *dst_ptr++ = *src_ptr++; - --len; - } - return dst; -} + const unsigned int *src_p32; + unsigned int *dst_p32; + unsigned int endDst = ((unsigned int)dst) + size; + unsigned int endRest = endDst & 3; -void* m_memset(void *dst, int val, unsigned int bytes) -{ - unsigned char *dst_ptr = (unsigned char *)dst; - unsigned int i = 0; - while(i < bytes) - { - dst_ptr[i] = val; - ++i; + if(endRest) + { + src_p = ((const unsigned char*)(src + size)) - 1; + dst_p = ((unsigned char*)endDst) - 1; + size -= endRest; + + while(endRest--) + *dst_p-- = *src_p--; + } + + src_p32 = ((const unsigned int*)(src + size)) - 1; + dst_p32 = ((unsigned int*)(dst + size)) - 1; + + unsigned int size32 = size >> 5; + if(size32) + { + size &= 0x1F; + + while(size32--) + { + src_p32 -= 8; + dst_p32 -= 8; + + dst_p32[8] = src_p32[8]; + dst_p32[7] = src_p32[7]; + dst_p32[6] = src_p32[6]; + dst_p32[5] = src_p32[5]; + dst_p32[4] = src_p32[4]; + dst_p32[3] = src_p32[3]; + dst_p32[2] = src_p32[2]; + dst_p32[1] = src_p32[1]; + } + } + + unsigned int size4 = size >> 2; + if(size4) + { + size &= 3; + + while(size4--) + *dst_p32-- = *src_p32--; + } + + dst_p = ((unsigned char*)dst_p32) + 3; + src_p = ((const unsigned char*)src_p32) + 3; } - return dst; + else + { + dst_p = ((unsigned char*)dst) + size - 1; + src_p = ((const unsigned char*)src) + size - 1; + } + + while(size--) + *dst_p-- = *src_p--; } diff --git a/dsrom/CBHC/arm_kernel/source/utils.h b/dsrom/CBHC/arm_kernel/source/utils.h index fd41db2..3d55958 100644 --- a/dsrom/CBHC/arm_kernel/source/utils.h +++ b/dsrom/CBHC/arm_kernel/source/utils.h @@ -1,7 +1,40 @@ -#ifndef _UTILS_H_ -#define _UTILS_H_ +/*************************************************************************** + * Copyright (C) 2016 + * by Dimok + * + * This software is provided 'as-is', without any express or implied + * warranty. In no event will the authors be held liable for any + * damages arising from the use of this software. + * + * Permission is granted to anyone to use this software for any + * purpose, including commercial applications, and to alter it and + * redistribute it freely, subject to the following restrictions: + * + * 1. The origin of this software must not be misrepresented; you + * must not claim that you wrote the original software. If you use + * this software in a product, an acknowledgment in the product + * documentation would be appreciated but is not required. + * + * 2. Altered source versions must be plainly marked as such, and + * must not be misrepresented as being the original software. + * + * 3. This notice may not be removed or altered from any source + * distribution. + ***************************************************************************/ +#ifndef _UTILS_H +#define _UTILS_H -void* m_memcpy(void *dst, const void *src, unsigned int len); -void* m_memset(void *dst, int val, unsigned int len); +#define ALIGN4(x) (((x) + 3) & ~3) + +#define kernel_memcpy ((void * (*)(void*, const void*, int))0x08131D04) +#define kernel_memset ((void *(*)(void*, int, unsigned int))0x08131DA0) +#define kernel_strncpy ((char *(*)(char*, const char*, unsigned int))0x081329B8) +#define disable_interrupts ((int(*)())0x0812E778) +#define enable_interrupts ((int(*)(int))0x0812E78C) +#define kernel_bsp_command_5 ((int (*)(const char*, int offset, const char*, int size, void *buffer))0x0812EC40) + +void reverse_memcpy(void* dest, const void* src, unsigned int size); +unsigned int disable_mmu(void); +void restore_mmu(unsigned int control_register); #endif diff --git a/dsrom/CBHC/arm_kernel/source/wupserver.c b/dsrom/CBHC/arm_kernel/source/wupserver.c new file mode 100644 index 0000000..eb47efa --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/wupserver.c @@ -0,0 +1,11 @@ +#include "../../payload/wupserver_bin.h" + +const unsigned char *get_wupserver_bin() +{ + return wupserver_bin; +} + +unsigned int get_wupserver_bin_len() +{ + return wupserver_bin_len; +} diff --git a/dsrom/CBHC/arm_kernel/source/wupserver.h b/dsrom/CBHC/arm_kernel/source/wupserver.h new file mode 100644 index 0000000..a456229 --- /dev/null +++ b/dsrom/CBHC/arm_kernel/source/wupserver.h @@ -0,0 +1,8 @@ + +#ifndef _WUPSERVER_H_ +#define _WUPSERVER_H_ + +const unsigned char *get_wupserver_bin(); +unsigned int get_wupserver_bin_len(); + +#endif diff --git a/dsrom/CBHC/main.c b/dsrom/CBHC/main.c index ad6a5d6..460b21b 100644 --- a/dsrom/CBHC/main.c +++ b/dsrom/CBHC/main.c @@ -14,7 +14,7 @@ #define SIMPLE_RETURN 0x101014E4 #define SOURCE 0x01E20000 #define IOS_CREATETHREAD 0x1012EABC -#define ARM_CODE_BASE 0x08134100 +#define ARM_CODE_BASE 0x08135000 #define REPLACE_SYSCALL 0x081298BC /* YOUR ARM CODE HERE (starts at ARM_CODE_BASE) */ @@ -38,7 +38,7 @@ static unsigned int getButtonsDown(unsigned int padscore_handle, unsigned int vp #define SD_HBL_PATH "/vol/external01/wiiu/apps/homebrew_launcher/homebrew_launcher.elf" #define SD_MOCHA_PATH "/vol/external01/wiiu/apps/mocha/mocha.elf" -static const char *verChar = "CBHC v1.2 by FIX94"; +static const char *verChar = "CBHC v1.3 by FIX94"; #define DEFAULT_DISABLED 0 #define DEFAULT_SYSMENU 1 @@ -166,14 +166,17 @@ uint32_t __main(void) void(*nn_act_initialize)(void); unsigned char(*nn_act_getslotno)(void); + unsigned char(*nn_act_getdefaultaccount)(void); void(*nn_act_finalize)(void); OSDynLoad_FindExport(act_handle, 0, "Initialize__Q2_2nn3actFv", &nn_act_initialize); OSDynLoad_FindExport(act_handle, 0, "GetSlotNo__Q2_2nn3actFv", &nn_act_getslotno); + OSDynLoad_FindExport(act_handle, 0, "GetDefaultAccount__Q2_2nn3actFv", &nn_act_getdefaultaccount); OSDynLoad_FindExport(act_handle, 0, "Finalize__Q2_2nn3actFv", &nn_act_finalize); FSInit(); nn_act_initialize(); unsigned char slot = nn_act_getslotno(); + unsigned char defaultSlot = nn_act_getdefaultaccount(); SAVEInit(); SAVEInitSaveDir(slot); FSAddClient(pClient, -1); @@ -414,6 +417,8 @@ doIOSUexploit: //for patched menu launch void (*SYSLaunchMenu)(void); OSDynLoad_FindExport(sysapp_handle, 0,"SYSLaunchMenu", &SYSLaunchMenu); + void(*_SYSLaunchMenuWithCheckingAccount)(unsigned char slot); + OSDynLoad_FindExport(sysapp_handle,0,"_SYSLaunchMenuWithCheckingAccount",&_SYSLaunchMenuWithCheckingAccount); int (*IOS_Open)(char *path, unsigned int mode); int (*IOS_Close)(int fd); @@ -444,8 +449,17 @@ doIOSUexploit: } //sysmenu or cfw if(launchmode == LAUNCH_CFW_IMG) + { OSForceFullRelaunch(); - SYSLaunchMenu(); + SYSLaunchMenu(); + } + else + { + if(defaultSlot) //normal menu boot + SYSLaunchMenu(); + else //show mii select + _SYSLaunchMenuWithCheckingAccount(slot); + } OSExitThread(0); return 0; } diff --git a/installer/src/main.c b/installer/src/main.c index cb71b53..b03b94b 100644 --- a/installer/src/main.c +++ b/installer/src/main.c @@ -125,7 +125,7 @@ int availSort(const void *c1, const void *c2) void printhdr_noflip() { #ifdef CB - println_noflip(0,"CBHC v1.2 by FIX94"); + println_noflip(0,"CBHC v1.3 by FIX94"); #else println_noflip(0,"Haxchi v2.3u1 by FIX94"); #endif