Editing Hardware flashing
Jump to navigation
Jump to search
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then publish the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 1: | Line 1: | ||
<div style="float:right">[[File:Progskeet wiring to NANDs COK-002-idone-SAM 1765.jpg|200px|thumb|left|Progskeet wired to NANDs of a COK-002 board (photo:idone)]]<br /> | [[Category:Hardware]] | ||
[[File:PS3_Hardware.JPG|200px|thumb|left|Typical NOR flashing requires 16 Data wires, 23 Address wires and 3-4 control wires to the NOR pads (photo:defyboy)]]</div> | <div style="float:right">[[File:Progskeet wiring to NANDs COK-002-idone-SAM 1765.jpg|200px|thumb|left|Progskeet wired to NANDs of a COK-002 board (photo:idone)]]<br />[[File:PS3_Hardware.JPG|200px|thumb|left|Typical NOR flashing requires 16 Data wires, 23 Address wires and 3-4 control wires to the NOR pads (photo:defyboy)]]</div> | ||
== Hardware Flashers == | == Hardware Flashers == | ||
Both early launch consoles which feature [ | Both early launch consoles which feature [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NAND NAND flash] memory (block devices, that interleave their data unlike [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash]) and later consoles which feature [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash] memory are able to be flashed. | ||
=== Different Flashers === | === Different Flashers === | ||
Line 18: | Line 10: | ||
==== Noraliser ==== | ==== Noraliser ==== | ||
Marcan has made a | Marcan has made a NOR flasher / address sniffer for his PS3 slim by re-purposing a FPGA board ([http://www.xilinx.com/support/documentation/data_sheets/ds312.pdf Xilinx Spartan3E XC3S500E]) made for Wii hacking. noralizer is a git repo that contains the HDL (verilog) and associated host computer tools for flashing/sniffing. There are ~50 signals to solder. | ||
==== NORway ==== | ==== NORway ==== | ||
Work has been underway to brink a low cost AVR ([http://www.atmel.com/dyn/resources/prod_documents/7593S.pdf Atmel 90USB1286]) based NOR flasher that is capable of reading and writing on all consoles by defyboy. This was opensourced and further enhanced, now known as NORway for [[Teensy | Work has been underway to brink a low cost AVR ([http://www.atmel.com/dyn/resources/prod_documents/7593S.pdf Atmel 90USB1286]) based NOR flasher that is capable of reading and writing on all consoles by defyboy. This was opensourced and further enhanced, now known as NORway for [[Teensy 2.0++]] boards. | ||
==== Progskeet ==== | ==== Progskeet ==== | ||
Other people | Other people havent been sitting idle either: uf6667 and <nowiki>****</nowiki> have developed [http://www.progskeet.com/ Progskeet], based on a [http://www.actel.com/documents/PA3_DS.pdf Actel A3P125 MCU] for NAND ánd NOR based consoles (not only PS3, but also useable for Wii and Xbox360). | ||
==== PNM ==== | ==== PNM ==== | ||
Line 31: | Line 22: | ||
==== PIC32MX ==== | ==== PIC32MX ==== | ||
... | |||
==== E3 ==== | ==== E3 ==== | ||
China commercial developped PS3 only 'flasher'. | |||
=== Comparison === | === Comparison === | ||
{| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | {| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | ||
| | |- bgcolor="#cccccc" | ||
! rowspan="3" | Flasher | ! rowspan="3" | Flasher !! colspan="7" | FAT !! colspan="5" | SLIM !! rowspan="3" | Notes | ||
|- | |- | ||
! | ! CECHA<br />CECHB !! CECHC<br />CECHE !! CECHE !! CECHG !! CECHH !! CECHK !! CECHL<br />CECHM<br />CECHP<br />CECHQ !! CECH-20.. !! CECH-21.. !! CECH-25.. !! CECH-25.. !! CECH-30.. | ||
|- | |- | ||
! | ! COK<br />001 !! COK<br />002 !! COK<br />002W !! SEM<br />001 !! DIA<br />001 !! DIA<br />002 !! VER<br />001 !! DYN<br />001 !! SUR<br />001 !! JTP<br />001 !! JSD<br />001 !! KTE<br />001 | ||
|- | |- | ||
| | | Infectus || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{No}} || {{No}} || {{No}} || {{No}} || {{No}} || {{No}} || {{No}} || {{No}} || NAND only | ||
|- | |- | ||
| | | Progskeet || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || Universal NAND + NOR + SPI | ||
|- | |- | ||
| | | Teensy 2.0++ / NORway || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || OpenSource / OpenHardware | ||
|- | |- | ||
| | | PNM || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || OpenSource / OpenHardware | ||
|- | |- | ||
| | | Noraliser || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || Not commercially avail. | ||
|- | |- | ||
| | | PIC32MX || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || OpenSource / OpenHardware | ||
|- | |- | ||
| | | E3 || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || 1 console only | ||
|- | |- | ||
|} | |} | ||
{| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable sortable" style="border:1px solid #999; border-collapse: collapse;" | {| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable sortable" style="border:1px solid #999; border-collapse: collapse;" | ||
| | |- bgcolor="#cccccc" | ||
! Feature !! | ! Feature !! Infectus !! PNM !! progskeet !! Teensy2.0++<br />NORway !! PIC32 !! E3 !! Remarks | ||
|- | |- | ||
| Use CFI || ? | | Use CFI || ? || {{Yes}} || {{Yes}} || {{No}} || ? || ? || Common Flash Memory Interface writing strategies (Progkseet can dump CFI, but doesnt use it directly for writestrategy) | ||
|- | |- | ||
| PS3 NAND Support<br /><small>(see above table)</small> || {{Yes}} || {{No}} || {{Yes}} || {{ | | PS3 NAND Support<br /><small>(see above table)</small> || {{Yes}} || {{No}} || {{Yes}} || {{No}} || {{No}} || {{Yes}} || E3 supports NAND with later 'to be released' edition | ||
|- | |- | ||
| PS3 NOR Support<br /><small>(see above table)</small> || {{No}} || {{Yes}} || {{Yes | | PS3 NOR Support<br /><small>(see above table)</small> || {{No}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || {{Yes}} || | ||
|- | |- | ||
| Solderless || {{No}} || {{No | | Solderless || {{No}} || {{No}} || {{Yes}} || {{No}} || {{No}} || {{Yes}} || Solderless is optional for E3 (but still requires soldering trisate). | ||
NOR/NAND solderless clip for | NOR/NAND solderless clip for Progskeet are already available now. | ||
Announced for PNM near future. | Announced for PNM near future. | ||
|- | |- | ||
| OpenSource || {{No}} || {{Yes | | OpenSource || {{No}} || {{Yes}} || {{No}} || {{Yes}} || {{Yes}} || {{No}} || | ||
|- | |- | ||
| OpenHardware || {{No}} || {{Yes | | OpenHardware || {{No}} || {{Yes}} || {{No}} || {{Yes}} || {{Yes}} || {{No}} || | ||
|- | |- | ||
| Updateable || JTAG || USB | | Updateable || JTAG || USB || JTAG || USB || ISP || microSD || | ||
|- | |- | ||
| Onboard Flash || {{No}} || {{Yes | | Onboard Flash || {{No}} || {{Yes}} || {{No}} || {{No}} || {{No}} || {{Yes}} || Instant-on dual firmware for PNM using a jumper // E3 uses flash on driveboard, not internal | ||
|- | |- | ||
| Dual Boot solution || {{No | | Dual Boot solution || {{No}} || {{Yes}} || {{Yes}} || {{No}} || {{No}} || {{Yes}} || Real quick dualboot requires dual flash (and user to swap the harddrive) | ||
|- | |- | ||
| File Transfer Protocol || USB || X-Modem | | File Transfer Protocol || USB || X-Modem || USB || USB || || || | ||
|- | |- | ||
| Mass Production || {{No}} || {{No | | Mass Production || {{No}} || {{No}} || {{Yes}} || {{No}} || {{No}} || {{Yes}} || PNM V2 might be mass produced | ||
|- | |- | ||
| X360 NAND Support || {{Yes}} || {{No | | X360 NAND Support || {{Yes}} || {{No}} || {{Yes}} || {{No}} || {{No}} || {{No}} || | ||
|- | |- | ||
| Wii NAND Support || {{Yes}} || {{No | | Wii NAND Support || {{Yes}} || {{No}} || {{Yes}} || {{No}} || {{No}} || {{No}} || | ||
|- | |- | ||
|} | |} | ||
Line 107: | Line 89: | ||
{| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | {| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | ||
|- | |- | ||
! style="background-color:red | ! style="background-color:red;" | <span style="background-color:lightred; color:white;">Generic Warning</span> | ||
|- | |- | ||
| <span style="white; color:red | | style="background-color:white;" | <span style="white; color:red; font-size:200%; ">Make sure you have several proper dumps of your flash before even trying writing to it! Use unpacking tools (e.g. Norunpack, Flowrebuilder, Norpatch etc.) and hexeditors (e.g. HxD) and use [[Flash]] page as reference. | ||
* CRC/MD5 is not a method to check your flash (if it is bad, you are only comparing if the other file is equally bad). | * CRC/MD5 is not a method to check your flash (if it is bad, you are only comparing if the other file is equally bad). | ||
* Also make sure you checked the content of the flash, Flowrebuilder, Norunpack only looks for image header and unpacks without warnings and without checking the content. | * Also make sure you checked the content of the flash, Flowrebuilder, Norunpack only looks for image header and unpacks without warnings and without checking the content. | ||
You cannot recover from bad flash without proper dumps (e.g. bricking the console beyond repair).</span> | You cannot recover from bad flash without proper dumps (e.g. bricking the console beyond repair).</span> | ||
Line 120: | Line 100: | ||
== NAND Wiring == | == NAND Wiring == | ||
Flashers for NAND based consoles (CECHA/COK-001, CECHB/COK-001, CECHC/COK-002, CECHD/unreleased, CECHE/COK-002W, CECHF/unreleased, CECHG/SEM-001) are generaly wired directly to the pins of the NAND ('''you cannot use the testpoints!'''), plus ground and Vcc. For NAND pinouts see: [ | Flashers for NAND based consoles (CECHA/COK-001, CECHB/COK-001, CECHC/COK-002, CECHD/unreleased, CECHE/COK-002W, CECHF/unreleased, CECHG/SEM-001) are generaly wired directly to the pins of the NAND ('''you cannot use the testpoints!'''), plus ground and Vcc. For NAND pinouts see: [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NAND Flash (Hardware) #NAND] | ||
There are 2 nands interleaved at the 512byte sectors level, giving a 1024 byte "interleaved sector". pages are 2kb on each nand. | There are 2 nands interleaved at the 512byte sectors level, giving a 1024 byte "interleaved sector". pages are 2kb on each nand. | ||
<div style="float:right">[[File:PS3_DualNand_Retail_ProgSkeet.png|200px|thumb|left|Dual NAND connection to Progskeet diagram, see http://progskeet.com/]]<br />[[File:Infectus-ps3-nand.png|200px|thumb|left|Dual NAND connection to Infectus diagram]]<br />[[File:Nand-360clip-wiiclip-48pin.jpg|200px|thumb|left|NAND 360Clip pinout]]</div> | |||
<div style="height:520px; overflow:auto"> | |||
{| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable sortable" style="border:1px solid #999; border-collapse: collapse;" | |||
|- bgcolor="#cccccc" | |||
! Chip/PIN !! Description !! [http://www.progskeet.com/download.php Progskeet] !! Infectus || 360clip || Description | |||
|- | |||
!colspan="6" | NAND 0 | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/1-6 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
=== | |- | ||
| 0/7 || R/B || 3 / gp13 || A9 || FRB1 || Read/Busy Output | |||
|- | |||
| 0/8 || RE || 98 / gp15 || A15 || RE || Read Enable | |||
|- | |||
| 0/9 || CE || 7 / gp9 || A14 || FCE1 || Chip Enable | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/10+11 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 0/12 || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | +3.3 || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | Vcc (min 2.7V-max 3.6V / typ 3.3V) | |||
|- | |||
| 0/13 || style="color:white; background-color:#333333;" | Vss || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:#333333;" | VSS - Ground | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/14+15 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 0/16 || CLE || 4 / gp12 || A13 || CLE || Command Latch Enable | |||
|- | |||
| 0/17 || ALE || 5 / gp11 || A12 || ALE || Address Latch Enable | |||
|- | |||
| 0/18 || WE || 2 / gp14 || A11 || WE || Write Enable | |||
|- | |||
| 0/19 || WP || 6 / gp10 || A10 || WP || Write Protect | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/20-28 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 0/29 || I/O-0 || 90 / dq8 || A0 || I/O0 || | |||
|- | |||
| 0/30 || I/O-1 || 91 / dq9 || A1 || I/O1 || | |||
|- | |||
| 0/31 || I/O-2 || 92 / dq10 || A2 || I/O2 || | |||
|- | |||
| 0/32 || I/O-3 || 93 / dq11 || A3 || I/O3 || | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/33-35 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 0/36 || style="color:white; background-color:#333333;" | Vss || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:#333333;" | VSS - Ground | |||
|- | |||
| 0/37 || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | +3.3 || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | Vcc (min 2.7V-max 3.6V / typ 3.3V) | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/38-40 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 0/41 || I/O-4 || 94 / dq12 || A4 || I/O4 || | |||
|- | |||
| 0/42 || I/O-5 || 95 / dq13 || A5 || I/O5 || | |||
|- | |||
| 0/43 || I/O-6 || 96 / dq14 || A6 || I/O6 || | |||
|- | |||
| 0/44 || I/O-7 || 97 / dq15 || A7 || I/O7 || | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 0/45-48 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
! Chip/PIN !! Description !! [http://www.progskeet.com/download.php Progskeet] !! Infectus || Description | |||
|- | |||
!colspan="6" | NAND 1 | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/1-6 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 1/7 || R/B || 64 / rdy || U || FRB1 || Read/Busy Output | |||
|- | |||
| 1/8 || RE || 69 / oe || M || RE || Read Enable | |||
|- | |||
| 1/9 || CE || 60 / gp3 || N || FCE1 || Chip Enable | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/10+11 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 1/12 || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | +3.3 || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | Vcc (min 2.7V-max 3.6V / typ 3.3V) | |||
|- | |||
| 1/13 || style="color:white; background-color:#333333;" | Vss || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:#333333;" | VSS - Ground | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/14+15 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 1/16 || CLE || 63 / gp0 || O || CLE || Command Latch Enable | |||
|- | |||
| 1/17 || ALE || 62 / gp1 || P || ALE || Address Latch Enable | |||
|- | |||
| 1/18 || WE || 65 / we || Q || WE || Write Enable | |||
|- | |||
| 1/19 || WP || 61 / gp2 || T || WP || Write Protect | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/20-28 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 1/29 || I/O-0 || 79 / dq0 || D0 || I/O0 || | |||
|- | |||
| 1/30 || I/O-1 || 80 / dq1 || D1 || I/O1 || | |||
|- | |||
| 1/31 || I/O-2 || 81 / dq2 || D2 || I/O2 || | |||
|- | |||
| 1/32 || I/O-3 || 82 / dq3 || D3 || I/O3 || | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/33-35 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 1/36 || style="color:white; background-color:#333333;" | Vss || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:#333333;" | VSS - Ground | |||
|- | |||
| 1/37 || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | +3.3 || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:#CC3333;" | Vcc (min 2.7V-max 3.6V / typ 3.3V) | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/38-40 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
| 1/41 || I/O-4 || 83 / dq4 || D4 || I/O4 || | |||
|- | |||
| 1/42 || I/O-5 || 84 / dq5 || D5 || I/O5 || | |||
|- | |||
| 1/43 || I/O-6 || 85 / dq6 || D6 || I/O6 || | |||
|- | |||
| 1/44 || I/O-7 || 86 / dq7 || D7 || I/O7 || | |||
|- | |||
| style="color:white; background-color:darkgrey;" | 1/45-48 || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | NC || style="color:white; background-color:darkgrey;" | No Connection | |||
|- | |||
!colspan="6" | Board trace | |||
|- | |||
| GND || style="color:white; background-color:#333333;" | Vss || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#333333;" | GND || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#333333;" | VSS - Ground | |||
|- | |||
| +5VDC || style="color:white; background-color:#CC3333;" | Vcc || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#CC3333;" | 5V || style="color:white; background-color:darkgrey;" | not used / not connected || style="color:white; background-color:#CC3333;" | Vcc from TH3401 (CECHA+CECHB/COK-001)<br />Vcc from TH3401 (CECHC+CECHE/COK-002)<br />Vcc from TH3280 (CECHG/SEM-001) | |||
|- | |||
|} | |||
</div> | |||
Remarks: | Remarks: | ||
* | * Progskeet is feeded from NAND 3.3V | ||
* Infectus is feeded from +5V board trace. | * Infectus is feeded from +5V board trace. | ||
* NAND's are feeded in both cases by the console itself. | * NAND's are feeded in both cases by the console itself. | ||
Progskeet Note: Some modification is needed for Progskeet to unbrick: | |||
* desolder R8 from the | * desolder R8 from the Progskeet PCB (to disable the connection from pad R8 to left pad R7) | ||
* left pin of [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] to left lead of R7, middle pin of [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] to right lead of R7 | * left pin of [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] to left lead of R7, middle pin of [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] to right lead of R7 | ||
* Vcc to +3.3 // put [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] in "OFF" (right) postion, power on the ps3, put the [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] in the "ON"/left position, it will be recognized by the PC, NAND is always on now, do everything as usual''. | * Vcc to +3.3 // put [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] in "OFF" (right) postion, power on the ps3, put the [http://www.google.com/search?um=1&hl=nl&safe=off&tbm=isch&sa=1&q=switch+toggle toggle switch] in the "ON"/left position, it will be recognized by the PC, NAND is always on now, do everything as usual''. | ||
Line 188: | Line 258: | ||
* First connect flasher to pc | * First connect flasher to pc | ||
* Use the PS3 to power the NANDs. | * Use the PS3 to power the NANDs. | ||
Progskeet specific: | |||
* On NAND tab, you click NAND 1 and select 'auto' | * On NAND tab, you click NAND 1 and select 'auto' | ||
* On NAND tab, you click NAND 2 and select 'auto' | * On NAND tab, you click NAND 2 and select 'auto' | ||
Line 195: | Line 265: | ||
=== Using NAND flashers === | === Using NAND flashers === | ||
==== | ==== Progskeet ==== | ||
put switch in "OFF" (R7 is open) position so that | put switch in "OFF" (R7 is open) position so that progskeet is not powered. | ||
power on the ps3 and wait for | power on the ps3 and wait for 20-25 seconds, | ||
put the switch in the "ON" (R7 closed) position, so | put the switch in the "ON" (R7 closed) position, so progskeet is powered and will be recognized by the PC. | ||
NAND is always on now, do everything as usual | NAND is always on now, do everything as usual | ||
| | ||
Line 208: | Line 278: | ||
| | ||
That will give you 132MB (138,412,032 bytes) per NAND (dump time ~ 00:02:40 per NAND) | That will give you 132MB (138,412,032 bytes) per NAND (dump time ~ 00:02:40 per NAND) | ||
For normal console operation (e.g. after you dumped, flashed/downgraded it): | For normal console operation (e.g. after you dumped, flashed/downgraded it): | ||
you need switch to "on" (R7 closed) and | you need switch to "on" (R7 closed) and progskeet USB disconnected. | ||
===== downloads ===== | ===== downloads ===== | ||
All '''current''' downloads are available [http://www.progskeet.com/download.php here] / | All '''current''' downloads are available [http://www.progskeet.com/download.php here] | ||
* diagrams - for PS3: see above, but others are available here: [http://www.progskeet.com/downloads/diagrams_110805.rar diagrams_110805.rar] (backup/mirror: [http://www.multiupload.com/NYI9621BF5 diagrams_110805.rar (10.4 MB)]) | |||
* drivers - [http://www.progskeet.com/downloads/drivers_110812.rar drivers_110812.rar] (backup/mirror: [http://www.multiupload.com/67L14ZWUDH drivers_a110812.rar (267.61 KB)]) / [http://www.multiupload.com/O66HT6FN9R drivers_110726.rar (235.62 KB)] | |||
* flasher software - [http://www.progskeet.com/downloads/ProgSkeet_110819.rar ProgSkeet_110819.rar] (backup/mirror: [http://www.multiupload.com/ZH5WHAIWOZ ProgSkeet_110819.rar (32.27 KB)] | |||
==== Infectus ==== | ==== Infectus ==== | ||
Line 233: | Line 298: | ||
==== Needed NAND tools ==== | ==== Needed NAND tools ==== | ||
In case the flasher program doesnt understand dual NAND de/interleaving you'll need : [http:// | In case the flasher program doesnt understand dual NAND de/interleaving you'll need : [http://www.multiupload.com/BOVOI6OA2V FlowRebuilder v.4.2.0.1.rar (379.34 KB)] <!--// old versions [http://www.sendspace.com/file/qhwkm5 FlowRebuilder v.4.1.0.0] / [http://www.multiupload.com/L9QPX7DIY5 FlowRebuilder v.4.1.3.2.exe (459.95 KB)] //--> | ||
=====Flowrebuilder options===== | =====Flowrebuilder options===== | ||
Line 243: | Line 308: | ||
===== Extracted flash content files ===== | ===== Extracted flash content files ===== | ||
<span style="color:red | <span style="background-color:white; color:red;">(make sure they are all there, flowrebuilder will not give warning when it fails!)</span>: | ||
* bootloader_0 | * bootloader_0 | ||
* bootloader_1 | * bootloader_1 | ||
Line 259: | Line 324: | ||
=== Dump NAND from GameOS === | === Dump NAND from GameOS === | ||
[http:// | [http://gitbrew.org/~glevand/ps3/pkgs/dump_flash.pkg dump_flash.pkg] // backup/mirror: | ||
[http:// | [http://www.multiupload.com/Y1G1G7E4J4 dump_flash.pkg (70.48 KB)]<br /> | ||
Make sure USB stick is FAT32 with enough free space (256MB per dump) | Make sure USB stick is FAT32 with enough free space (256MB per dump) | ||
Line 302: | Line 367: | ||
{| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | {| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | ||
|- | |- | ||
! style="background-color:red | ! style="background-color:red;" id="Brick warning" | <span style="background-color:lightred; color:white;">Brick warning - Peek/Poke only</span> | ||
|- | |- | ||
| [[#Brick warning]]<span style="white; color:red | | style="background-color:white;" | [[#Brick warning]]<span style="white; color:red;"> | ||
TCL: http://pastebin.com/Snh4ERQ6 (Don't use, BRICK RISK, see below)<br /> | TCL: http://pastebin.com/Snh4ERQ6 (Don't use, BRICK RISK, see below)<br /> | ||
Line 311: | Line 376: | ||
|- | |- | ||
|} | |} | ||
=== 'NOR' Interface Testpoints on NAND consoles === | === 'NOR' Interface Testpoints on NAND consoles === | ||
Line 320: | Line 381: | ||
=== TriState on NAND consoles === | === TriState on NAND consoles === | ||
using [[Starship2]] to [[ | using [[Starship2]] to southbridge /SB_EBUS_ACK @ SB_MAIN(P30) (numbered 52 in [[:File:SS2_NOR.JPG]]) | ||
* CECHA (COK-001): | * CECHA (COK-001): IC3801:CXD4302GB-T6 pin:C1/ ebus jl:9308 (page 20 of servicemanual) | ||
* CECHC + CECHE (COK-002): | * CECHC + CECHE (COK-002): IC3801:CXD4302GB-T6 pin:C1/ ebus jl:9308 (page 20 of servicemanual) | ||
* CECHG (SEM001): | * CECHG (SEM001): IC3801:CXD9909GB pin:C1/ ebus jl:9308 (page 21 of servicemanual) | ||
== NOR Interface Testpoints == | == NOR Interface Testpoints == | ||
Line 329: | Line 390: | ||
=== Tristate === | === Tristate === | ||
Tristate, or as it is referred to in the service manuals SB_DISABLE exists solely for the purpose of placing the [[South Bridge]] pins into high-impedance ( | Tristate, or as it is referred to in the service manuals SB_DISABLE exists solely for the purpose of placing the [[South Bridge]] pins into high-impedance (the third state) so that we can access the flash without the [[South Bridge]] interfering. | ||
Because the tristate pin is not connected to the [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash] TSOP package, but to the [[South Bridge]] BGA package, this makes tracing the pin quite difficult. One should be able to locate it by having the running you could ground out the unknown pins whilst checking the continuity of a known address or data line against ground. These should enter high-impedance or no-continuity when you ground out SB_DISABLE. | |||
Because the tristate pin is not connected to the [ | |||
=== Connecting NOR pads to flasher === | === Connecting NOR pads to flasher === | ||
<div style="float:right">[[File:Teensy2.0++.jpg|200px|thumb|left|Teensy 2.0 ++ connection diagram for PS3 NOR pads))]]<br /> | |||
[[File:Progskeet.png|200px|thumb|left|Progskeet NAND/NOR flasher board, based on Actel MCU, see http://progskeet.com/)]]<br /> | |||
[[File:Progskeet_v11.jpg|200px|thumb|left|Progskeet 1.1 NAND/NOR flasher board, with ZIF and dual voltage, see http://progskeet.com/)]]<br />[[File:Pnm.jpg|200px|thumb|left|PNM, based on Altera FPGA and 2x NOR sockets]]<br />[[File:360-clip-56.png|200px|thumb|left|NOR TSOP56 ZIF 360clip and solderboard]]</div> | |||
==== [ | {| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable sortable" style="border:1px solid #999; border-collapse: collapse;" | ||
Some modification is needed for | |- bgcolor="#cccccc" | ||
* desolder R8 from the | ! NORpin !! PAD !! [http://www.progskeet.com/download.php Progskeet] !! Teensy2.0++<br />[http://git.dashhacks.com/norway NORway] !! [http://www.ps3devwiki.com/index.php?title=PNM PNM] !! E3 !! NOR56 360clip || Remark | ||
|- | |||
| 31 || A0 || adr0 || F0 || A0 || ''clip'' || FA0 || | |||
|- | |||
| 26 || A1 || adr1 || F1 || A1 || ''clip'' || FA1 || | |||
|- | |||
| 25 || A2 || adr2 || F2 || A2 || ''clip'' || FA2 || | |||
|- | |||
| 24 || A3 || adr3 || F3 || A3 || ''clip'' || FA3 || | |||
|- | |||
| 23 || A4 || adr4 || F4 || A4 || ''clip'' || FA4 || | |||
|- | |||
| 22 || A5 || adr5 || F5 || A5 || ''clip'' || FA5 || | |||
|- | |||
| 21 || A6 || adr6 || F6 || A6 || ''clip'' || FA6 || | |||
|- | |||
| 20 || A7 || adr7 || F7 || A7 || ''clip'' || FA7 || | |||
|- | |||
| 10 || A8 || adr8 || PA0 || A8 || ''clip'' || FA8 || | |||
|- | |||
| 9 || A9 || adr9 || PA1 || A9 || ''clip'' || FA9 || | |||
|- | |||
| 8 || A10 || adr10 || PA2 || A10 || ''clip'' || FA10 || | |||
|- | |||
| 7 || A11 || adr11 || PA3 || A11 || ''clip'' || FA11 || | |||
|- | |||
| 6 || A12 || adr12 || PA4 || A12 || ''clip'' || FA12 || | |||
|- | |||
| 5 || A13 || adr13 || PA5 || A13 || ''clip'' || FA13 || | |||
|- | |||
| 4 || A14 || adr14 || PA6 || A14 || ''clip'' || FA14 || | |||
|- | |||
| 3 || A15 || adr15 || PA7 || A15 || ''clip'' || FA15 || | |||
|- | |||
| 54 || A16 || adr16 || B0 || A16 || ''clip'' || FA16 || | |||
|- | |||
| 19 || A17 || adr17 || B1 || A17 || ''clip'' || FA17 || | |||
|- | |||
| 18 || A18 || adr18 || B2 || A18 || ''clip'' || FA18 || | |||
|- | |||
| 11 || A19 || adr19 || B3 || A19 || ''clip'' || FA19 || | |||
|- | |||
| 12 || A20 || adr20 || B4 || A20 || ''clip'' || FA20 || | |||
|- | |||
| 15 || A21 || adr21 || B5 || A21 || ''clip'' || FA21 || | |||
|- | |||
| 1 || A23 || Not Used || Not Used || Not Used || ''clip'' || FA23 || pin unused for 128mbit and below | |||
|- | |||
| 56 || A24 || Not Used || Not Used || Not Used || ''clip'' || FA24 || pin unused for 256mbit and below | |||
|- | |||
| 2 || A22 || adr22 || B6 || A22 || ''clip'' || FA22 || | |||
|- | |||
| 35 || DQ0 || dq0 || D0 || DQ0 || ''clip'' || AD0 || | |||
|- | |||
| 37 || DQ1 || dq1 || D1 || DQ1 || ''clip'' || AD1 || | |||
|- | |||
| 39 || DQ2 || dq2 || D2 || DQ2 || ''clip'' || AD2 || | |||
|- | |||
| 41 || DQ3 || dq3 || D3 || DQ3 || ''clip'' || AD3 || | |||
|- | |||
| 44 || DQ4 || dq4 || D4 || DQ4 || ''clip'' || AD4 || | |||
|- | |||
| 46 || DQ5 || dq5 || D5 || DQ5 || ''clip'' || AD5 || | |||
|- | |||
| 48 || DQ6 || dq6 || D6 || DQ6 || ''clip'' || AD6 || | |||
|- | |||
| 50 || DQ7 || dq7 || D7 || DQ7 || ''clip'' || AD7 || | |||
|- | |||
| 36 || DQ8 || dq8 || C0 || DQ8 || ''clip'' || AD8 || | |||
|- | |||
| 38 || DQ9 || dq9 || C1 || DQ9 || ''clip'' || AD9 || | |||
|- | |||
| 40 || DQ10 || dq10 || C2 || DQ10 || ''clip'' || AD10 || | |||
|- | |||
| 42 || DQ11 || dq11 || C3 || DQ11 || ''clip'' || AD11 || | |||
|- | |||
| 45 || DQ12 || dq12 || C4 || DQ12 || ''clip'' || AD12 || | |||
|- | |||
| 47 || DQ13 || dq13 || C5 || DQ13 || ''clip'' || AD13 || | |||
|- | |||
| 49 || DQ14 || dq14 || C6 || DQ14 || ''clip'' || AD14 || | |||
|- | |||
| 51 || DQ15 || dq15 || C7 || DQ15 || ''clip'' || AD15 || | |||
|- | |||
| 13 || #WE || we || E5 || NWE || ''clip'' || WE || | |||
|- | |||
| 32 || CE# || gp0 || E0 || NCE || ''clip'' || CE# || | |||
|- | |||
| 14 || RESET || gp1 || E4 || NRESET || ''clip'' || RESET || | |||
|- | |||
| N/A || TRISTATE || gp2 || E7 || GPIO0 || SBE || N/A || | |||
|- | |||
| 16 || WP# || gp3 || Not Used || NWPACC || ''clip'' || WP# || Is tied to Vcc by mobo | |||
|- | |||
| 53 || BYTE# || Not Used || Not used || Not used || ''clip'' || ? || Is tied to Vcc by mobo | |||
|- | |||
| 34 || OE# || oe || E1 || NOE || ''clip'' || OE || | |||
|- | |||
| 17 || RY/BY# || rdy (ánd gp4 for old bitstream) || E6 || RYNBY || ''clip'' || RDY || JTAG updated progskeet can do without the progskeet:gp4 to progskeet:rdy bridge and use the PS3:RY/BY# to progskeet:rdy alone. | |||
|- | |||
| 33, 52 || VSS || GND || GND || GND || ''clip'' || GND || | |||
|- | |||
| 29, 43 || VCC || Not Used || Not used || Not used || ''clip'' || ? || | |||
|- | |||
| 27, 28, 30, 55 || NC || Not Used || Not Used || Not Used || ''clip'' || Not Used || pins unused / Not Connected | |||
|- | |||
|} | |||
==== Progskeet notes ==== | |||
Some modification is needed for Progskeet to unbrick: | |||
* desolder R8 from the Progskeet PCB | |||
* left pin of switch to left lead of R7, middle pin of switch to right lead of R7 | * left pin of switch to left lead of R7, middle pin of switch to right lead of R7 | ||
* Vcc to +3.3 // put switch in "OFF" (right) postion, power on the ps3, put the switch in the "ON"/left position, it will be recognized by the PC, NOR is always on now, do everything as usual''. | * Vcc to +3.3 // put switch in "OFF" (right) postion, power on the ps3, put the switch in the "ON"/left position, it will be recognized by the PC, NOR is always on now, do everything as usual''. | ||
Line 357: | Line 527: | ||
* Turn on console to restore (progress LEDs will light up one by one and blink if successfully). | * Turn on console to restore (progress LEDs will light up one by one and blink if successfully). | ||
* Unplug powercable and set 1:Flash fun down to PS3 Mode and turn on the PS3, if everything went fine, it will now be debricked (remember: in case syscon has 3.56+ hashes, you need prepatched LV1, see downgrader guides).<br /> | * Unplug powercable and set 1:Flash fun down to PS3 Mode and turn on the PS3, if everything went fine, it will now be debricked (remember: in case syscon has 3.56+ hashes, you need prepatched LV1, see downgrader guides).<br /> | ||
[http://www.multiupload.com/3IHN3VZYZG English-E3 FLASHER repair method if console bricked.pdf (424.95 KB)] | |||
=== Speed comparison NOR flashers === | === Speed comparison NOR flashers === | ||
<!--// Tabelised content : Performance Teensy: quoted from NORway documentation: 0:05:11 for a full dump/read (52,68 KB/s), 0:01:35 per sector write or 2:08:19 for a full write (2,12 KB/s). Teensy speed according to other sources: 0:00:45 for a full dump/read (364 KB/s), 0:00:05.351 per sector write or 0:08:19 for a full write (32,83 KB/s). Comparison with | <!--// Tabelised content : Performance Teensy: quoted from NORway documentation: 0:05:11 for a full dump/read (52,68 KB/s), 0:01:35 per sector write or 2:08:19 for a full write (2,12 KB/s). Teensy speed according to other sources: 0:00:45 for a full dump/read (364 KB/s), 0:00:05.351 per sector write or 0:08:19 for a full write (32,83 KB/s). Comparison with Progskeet: 0:00:16 for a full dump/read (~1MB/s), 0:00:00.365 per sector write or 0:00:46.811 for a full write (~300-400KB/s). //--> | ||
{| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | {| border="1" cellspacing="0" cellpadding="5" border="#999" class="wikitable" style="border:1px solid #999; border-collapse: collapse;" | ||
|- bgcolor="#cccccc" | |- bgcolor="#cccccc" | ||
! colspan="9" | Speed comparison NOR flashers | ! colspan="9" | Speed comparison NOR flashers | ||
|- | |- | ||
! !! colspan="2" | | ! !! colspan="2" | Teensy<br />(NORway 0.1) !! colspan="2" | Teensy<br />(NORway 0.3) !! colspan="2" | Progskeet !! colspan="2" | PNM<br />(X-Modem - 460800 baud) | ||
|- | |- | ||
! !! time (h:mm:ss) !! speed (KB/sec) !! time (h:mm:ss) !! speed (KB/sec) !! time (h:mm:ss) !! speed (KB/sec) !! time (h:mm:ss) !! speed (KB/sec) | ! !! time (h:mm:ss) !! speed (KB/sec) !! time (h:mm:ss) !! speed (KB/sec) !! time (h:mm:ss) !! speed (KB/sec) !! time (h:mm:ss) !! speed (KB/sec) | ||
Line 385: | Line 554: | ||
=== Using NOR flashers === | === Using NOR flashers === | ||
==== | ==== Progskeet ==== | ||
1. Unplug the PS3 powercable from the back | 1. Unplug the PS3 powercable from the back | ||
2 | 2. Set the R7 switch to "off" | ||
3. Plug the PS3 powercable back in and Power on the PS3 | |||
5. Wait 10 seconds and set the R7 switch to "on" to power progskeet | |||
5. Wait 10 seconds and set the R7 switch to "on" to power | | ||
dump: | |||
- Spansion S29GL128N90TFIR2 : 128KB sector, 128 sectors | |||
- Spansion S29GL128P90TFIR2 : 128KB sector, 128 sectors | |||
- Samsung K8Q2815UQB-PI4B : 4KB sector, 4096 sectors | |||
- Samsung K8P2716UZC-QI4D : 128KB sector, 128 sectors | |||
- Macronix MX29GL128ELT2I-90G : 128KB sector, 128 sectors | |||
For normal console operation (e.g. after you dumped, flashed/downgraded it): | For normal console operation (e.g. after you dumped, flashed/downgraded it): | ||
you need to | you need switch to "on" (R7 closed) and progskeet USB disconnected. | ||
==== NORway ==== | ==== NORway ==== | ||
Line 445: | Line 610: | ||
=== Dump NOR from GameOS === | === Dump NOR from GameOS === | ||
[http://gitbrew.org/~glevand/ps3/pkgs/dump_flash.pkg dump_flash.pkg] // backup/mirror: [http://www.multiupload.com/Y1G1G7E4J4 dump_flash.pkg (70.48 KB)]<br /> | [http://gitbrew.org/~glevand/ps3/pkgs/dump_flash.pkg dump_flash.pkg] // backup/mirror: [http://www.multiupload.com/Y1G1G7E4J4 dump_flash.pkg (70.48 KB)]<br /> | ||
Make sure USB stick is FAT32 with enough free space (16MB per dump) | Make sure USB stick is FAT32 with enough free space (16MB per dump) | ||
=== Dumping NOR from Linux === | === Dumping NOR from Linux === | ||
Line 452: | Line 616: | ||
== Board Revisions == | == Board Revisions == | ||
=== | |||
These are the earliest revisions of the PS3 | === COK-001, COK-002, COK-002W, SEM-001 === | ||
These are the earliest revisions of the PS3 motherboard (CECHA, CECHB, CECHC, CECHE, CECHG) and contain 2 x Samsung K9F1G08U0A-PIB0 128MB [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NAND NAND Chips] for a total of 256MB. These chips are interleaved which is controlled by a proprietary controller chip codenamed "[[Starship2]]" or SS2. This chip handles the interleaving and presents the [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NAND NAND Chips] to the [[South Bridge]] as a single large coherent flash.<br /> | |||
Wiring: direct to NAND flash or using boardtraces to NANDs - '''don't use the testpoints'''. | Wiring: direct to NAND flash or using boardtraces to NANDs - '''don't use the testpoints'''. | ||
=== | === DIA-001, DIA-002 === | ||
These boards were the first to get the [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash] memory from the middle revisions of the PS3 (CECHH, CECHJ, CECHK). Only a single Spansion S29GL128N90TFIR2 16MB [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash] chip is used and the [[Starship2]] chip has been completely removed. The 128N is JEDEC CFI compliant and organized as 8,388,608 words or 16,777,216 bytes, addressable as 16-bit words (PS3 modus operandi) and 8-bit / 1 byte when the BYTE# signal is logic zero. | |||
''' | '''DIA-002''': the pinout is same as DIA-001, the only difference is that DIA-002 doesnt have a WP# testpoint but since it's connected to VCC its not needed. | ||
=== | === VER-001 === | ||
Used in the last revisions of the fatter model PS3 ( | Used in the last revisions of the fatter model PS3 (CECHL, CECHM, CECHP, CECHQ), again with the single Spansion S29GL128N90TFIR2 16MB [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash] with the exception of some CECHL which used a Samsung K8Q2815UQB-P14B 16MB [http://www.ps3devwiki.com/index.php?title=Flash_%28Hardware%29#NOR NOR flash]. | ||
=== | === DYN-001 === | ||
Used in | Used in CECH-20xx. The progskeet and teensy pinouts match the teensy picture provided on this page even though it states it's the pinout for progskeet. Contains mostly dual-banked Samsung NOR's, some Spansion "P" and some Macronix. | ||
=== | === SUR-001 === | ||
Used in CECH-21xx. Contains mostly Spansion "P" and some Macronix NOR. Some difference in components but the testpoints are the same for SUR-001/JSD-001/JTP-001/KTE-001 | |||
=== JTP-001 === | |||
Used in CECH-210x. Some difference in components but the testpoints are the same for SUR-001/JSD-001/JTP-001/KTE-001 | |||
=== JSD-001 === | |||
This is the pinout originally supplied by Marcan for a CECH-2504A. Some difference in components but the testpoints are the same for SUR-001/JSD-001/JTP-001/KTE-001 | |||
=== KTE-001 === | |||
Used in CECH-30xx. Some difference in components but the testpoints are the same for SUR-001/JSD-001/JTP-001/KTE-001 | |||
== Pinout Gallery == | |||
<Gallery> | <Gallery> | ||
File:SS2_NOR.JPG|Starship2 | File:SS2_NOR.JPG|Starship2 NOR/EBUS Testpoints (NAND board) | ||
File:COK-001-NOR.jpg|COK-001 | File:COK-001-NOR.jpg|COK-001 NOR Testpoints (NAND board - only overlay) | ||
File:COK-001-NOR_1.jpg|COK-001 | File:COK-001-NOR_1.jpg|COK-001 NOR Testpoints (NAND board) | ||
File:SEM-001-NANDs-boardtraces-jestero.jpg|SEM-001 boardtraces (NAND board) | File:SEM-001-NANDs-boardtraces-jestero.jpg|SEM-001 boardtraces (NAND board) | ||
File: | File:DIA-001_NOR.JPG|DIA-001 NOR Testpoints | ||
File:DIA-002_by_DiscoBear.jpg|DIA-002 NOR Testpoints | |||
File: | File:VER-001_NOR-3.3V.JPG|VER-001 NOR Testpoints | ||
File:DYN-001_NOR.JPG|DYN-001 NOR Testpoints | |||
File:Dyn 001-progskeet.jpg|DYN-001 NOR Testpoints with progskeet labeling | |||
File:Jtp jsd kte-progskeet.jpg|JSD-001, JTP-001, KTE-001 NOR Testpoints with progskeet labeling | |||
File:JSD-001_NOR.JPG|JSD-001 NOR Testpoints | |||
File:JSD-001_NOR_-_nor_testpoints.png|JSD-001 Testpoints (orig. marcan/noraliser) | |||
File:JTP-001_-_1-882-481-21-testpoints.jpg|JTP-001 NOR Testpoints (not mapped) | |||
File:JTP-001_-_1-882-481-31.JPG|JTP-001 NOR Testpoints (not mapped) | |||
File:SUR-001_BOTTOM_TESTPOINTS_-NOT_TRACED-.JPG|SUR-001 Nor Testpoints (not mapped yet) | |||
[[File:Example.jpg]] | |||
File:NOR-PINOUT+ZIF-SolderlessPinout.jpg|NOR Flash general pinout + 50pin ZIF pinout (Progskeet)) | |||
File:Ver-001 nor-rev.jpg|VER-001 NOR Testpoints (trisaster.de, missing TRISTATE) | |||
File:Nand-360clip-wiiclip-48pin.jpg| NAND TSOP48 360clip (note: no need to connect R/B2 on ps3's) | File:Nand-360clip-wiiclip-48pin.jpg| NAND TSOP48 360clip (note: no need to connect R/B2 on ps3's) | ||
File: | File:360-clip-56.png| NOR TSOP56 ZIF 360clip and solderboard | ||
</Gallery> | </Gallery> | ||
'''Missing / requested''' : | |||
* COK-001 (NAND) boardtraces | |||
* COK-002 (NAND) boardtraces | |||
* COK-002W (NAND) anypic | |||
* ''SUR-001 (NOR) mapped NOR Testpoints - some difference in components of JSD-001 but the testpoints are the same as JSD-001'' | |||
* ''JTP-001 (NOR) mapped NOR Testpoints - visually the same as JSD-001, confirmed working with JSD-001 layout'' | |||
* KTE-001 (NOR) - mapped NOR Testpoints - visually the same as JSD-001/JTP-001/SUR-001 | |||
== Generic reference == | == Generic reference == | ||
=== Soldering Guide(s) === | === Soldering Guide(s) === | ||
* http://www.circuitrework.com/guides/7-1-1.shtml | * http://www.circuitrework.com/guides/7-1-1.shtml | ||
* http://store.curiousinventor.com/guides/Surface_Mount_Soldering/101 | * http://store.curiousinventor.com/guides/Surface_Mount_Soldering/101 | ||
=== Soldering Irons/Stations === | === Soldering Irons/Stations === | ||
Line 591: | Line 694: | ||
**http://www.amazon.com/Soldering-Station-Iron-Rework-Solder/dp/B004IQLUFG | **http://www.amazon.com/Soldering-Station-Iron-Rework-Solder/dp/B004IQLUFG | ||
**http://www.amazon.com/REWORK-SOLDERING-IRON-STATION-852D/dp/B004ZB9D4O | **http://www.amazon.com/REWORK-SOLDERING-IRON-STATION-852D/dp/B004ZB9D4O | ||
=== Soldering tips === | === Soldering tips === | ||
* Don't use >40W iron (we are not soldering copper pipes!) | * Don't use >40W iron (we are not soldering copper pipes!) | ||
* Don't use leadfree solder | * Don't use leadfree solder | ||
* Don't use silverbased solder | * Don't use silverbased solder | ||
* Don't use high tin alloy (e.g. 90/10: 300'C @ 97Sn 3Pb and 250'C @ 65Sn 35Pb) | * Don't use high tin alloy (e.g. 90/10: 300'C @ 97Sn 3Pb and 250'C @ 65Sn 35Pb) | ||
* Use 60/40 (374'F / 190'C) or 63/37 (364'F / 183'C) both have nice low melting point for PCBs | * Use 60/40 (374'F / 190'C) or 63/37 (364'F / 183'C) both have nice low melting point for PCBs | ||
=== Wire reference === | === Wire reference === | ||
Wire thickness AWG/mm : | |||
18 AWG - 0.0403" / 1.024mm | |||
19 AWG - 0.0359" / 0.912mm | |||
20 AWG - 0.0320" / 0.812mm | |||
21 AWG - 0.0285" / 0.723mm | |||
22 AWG - 0.0253" / 0.644mm | |||
23 AWG - 0.0226" / 0.573mm | |||
24 AWG - 0.0201" / 0.511mm | |||
25 AWG - 0.0179" / 0.455mm | |||
26 AWG - 0.0159" / 0.405mm | |||
27 AWG - 0.0142" / 0.361mm | |||
28 AWG - 0.0126" / 0.321mm | |||
29 AWG - 0.0113" / 0.286mm | |||
30 AWG - 0.0100" / 0.255mm | |||
31 AWG - 0.00893" / 0.227mm | |||
32 AWG - 0.00795" / 0.202mm | |||
33 AWG - 0.00708" / 0.180mm | |||
34 AWG - 0.00631" / 0.160mm | |||
35 AWG - 0.00562" / 0.143mm | |||
36 AWG - 0.00500" / 0.127mm | |||
37 AWG - 0.00445" / 0.113mm | |||
38 AWG - 0.00397" / 0.101mm7 | |||
39 AWG - 0.00353" / 0.0897mm | |||
40 AWG - 0.00314" / 0.0799mm | |||
| |||
PATA/floppy 40-conductor cable - AWG28 (0.0126" / 0.321mm) with 0.0333" pitch +/- 0.002" | PATA/floppy 40-conductor cable - AWG28 (0.0126" / 0.321mm) with 0.0333" pitch +/- 0.002" | ||
PATA/floppy 40-conductor cable - AWG30 (0.0100" / 0.255mm) with 0.0333" pitch +/- 0.002" | PATA/floppy 40-conductor cable - AWG30 (0.0100" / 0.255mm) with 0.0333" pitch +/- 0.002" | ||
Line 743: | Line 749: | ||
SATA : solid 30 AWG - 0.0100" / 0.255mm | SATA : solid 30 AWG - 0.0100" / 0.255mm | ||
For wiring, use 20-26 AWG. 18 can be too stiff while 28 is too fragile. 24-26 AWG works fine in most cases. The Grounds and VCC wires may ofcourse be thicker than the signal wires. Keep wires short (~20cm). | |||
For NOR wiring the solderarea is 10x larger than the solderarea used with NAND (pitch 0.5mm), so for NOR you have much more headroom (and also need!) to use thicker wires (for NAND you most likely want to use 28 AWG and cannot use much thicker) | |||
== Generic unresolved issues == | == Generic unresolved issues == | ||
There is a table made on the talk page to chart dump/flashing issues (and sucesses). See: [ | There is a table made on the talk page to chart dump/flashing issues (and sucesses). See: [http://www.ps3devwiki.com/index.php?title=Talk:Hardware_flashing#Testreport_table Testreport_table] | ||
== | == Progskeet QA/problem solving == | ||
=== Generic advice === | === Generic advice === | ||
==== Updating | ==== Updating Progskeet with Injectus ==== | ||
# connect injectus to | # connect injectus to progskeet with very short wires (see [[:File:Injectus_jtag_pinout.jpg]] [[:File:Injectus-jtag-bottompads.png]]) | ||
# turn r7 off | |||
# power injectus with usb | # power injectus with usb | ||
# power | # power progskeet with its own usb too (do NOT power the progskeet with the injectus!) | ||
# run injectus programmer software | # run injectus programmer software | ||
## click tools | ## click tools | ||
Line 777: | Line 780: | ||
===== Archive of old versions ===== | ===== Archive of old versions ===== | ||
Diagrams: | |||
* [http://www.multiupload.com/5XEX630GN5 diagrams_110803.rar (4.76 MB)]) | |||
* [http://www.multiupload.com/WCWI0XABBU diagrams_110804.rar (9.73 MB)]) | |||
* [http://www.multiupload.com/NYI9621BF5 diagrams_110805.rar (10.4 MB)]) | |||
Driver: | |||
* | * [http://www.multiupload.com/MIGAUSZL16 drivers_110726.rar (235.62 KB)] | ||
* | * [http://www.multiupload.com/H8GVGR9ITL drivers_110812.rar (264.07 KB)]) | ||
* [http://www. | * [http://www.multiupload.com/67L14ZWUDH drivers_a110812.rar (267.61 KB)] | ||
Bitstream: | |||
* [http://www.multiupload.com/CI6EI4J2ZW ProgSkeet_Bitstreams_111106.rar (1.63 MB)] | |||
* | |||
Flasher: | |||
* [http://www.multiupload.com/N88OW4HAK5 ProgSkeet_110803.rar (28.37 KB)] | |||
* [http://www. | * [http://www.multiupload.com/2CC0N1Y3SN ProgSkeet_110807.rar (29.24 KB)] | ||
* [http://www.multiupload.com/VXYTEGEIJP ProgSkeet_110811-A.rar (30.02 KB)] | |||
* [http://www.multiupload.com/70ICZS8DC1 ProgSkeet_110811-B.rar (29.8 KB)] | |||
* [http://www.multiupload.com/ZH5WHAIWOZ ProgSkeet_110819.rar (32.27 KB)] | |||
* [http://www. | |||
* [http://www. | |||
* [http://www. | |||
* [http://www. | |||
*111004/8: | *111004/8: | ||
**[http://www. | **[http://www.multiupload.com/ZOTQNSFZNR WinSkeet40000_111004.zip (5.1 MB)] (libusb) | ||
**[http://www. | **[http://www.multiupload.com/RP3V1UJFO2 YASkeet_20111008.tar.gz (226.95 KB)] | ||
**[http://www. | **[http://www.multiupload.com/YE6B15YHO0 iSkeet_20111008.zip (497.83 KB)] | ||
*111120: | *111120: | ||
**[http://www. | **[http://www.multiupload.com/ORH9JN84QF Winskeet111120.rar (9.07 MB)] (WinUSB) | ||
**[http://www. | **[http://www.multiupload.com/W9QFCEBNOC YASkeet_20111120.tar.gz (229.72 KB)] | ||
**[http://www. | **[http://www.multiupload.com/1A5MPRPUX5 iSkeet_20111120.zip (11.87 MB)] | ||
*111205: | *111205: | ||
**[http://www. | **[http://www.multiupload.com/CIOAIGZUP3 Winskeet111205.rar (4.18 MB)] (WinUSB) | ||
==== No shorts ==== | ==== No shorts ==== | ||
Line 827: | Line 822: | ||
=== Error : incorrect parameter === | === Error : incorrect parameter === | ||
Make sure you selected the correct values for your NOR/NAND device. If there is a preset, use it | Make sure you selected the correct values for your NOR/NAND device. If there is a preset, use it. | ||
If not, e.g. : | If not, e.g. : | ||
Line 845: | Line 839: | ||
* http://www.microsoft.com/download/en/details.aspx?id=5582 | * http://www.microsoft.com/download/en/details.aspx?id=5582 | ||
=== Error/crash on Windows 7 | === Error/crash on Windows 7 === | ||
* Disable Aero (known to crash on Win7 Ultimate) | * Disable Aero (known to crash on Win7 Ultimate) | ||
** set display color to 256 colors will enforce Aero to disable too | ** set display color to 256 colors will enforce Aero to disable too | ||
Line 851: | Line 845: | ||
* Consider disabling UAC (or re-educate it proper) | * Consider disabling UAC (or re-educate it proper) | ||
* Try "Compatibility Mode" (e.g. Windows 2000 or Windows XP SP2) | * Try "Compatibility Mode" (e.g. Windows 2000 or Windows XP SP2) | ||
=== A/B Trick === | === A/B Trick === | ||
The A/B trick is a solution found by DiGiTaLAnGeL to write his Macronix NOR (but can be tried on other NORs as well <small><span style="color:red | The A/B trick is a solution found by DiGiTaLAnGeL to write his Macronix NOR (but can be tried on other NORs as well <small><span style="color:red;">1</span></small>). <br /> | ||
Some Sectors of his flash were "slow to write" and using the normal flashing procedure was resulting in a fail or in a freeze of the | Some Sectors of his flash were "slow to write" and using the normal flashing procedure was resulting in a fail or in a freeze of the ProgSkeet Flasher. | ||
'''Needed tools:''' | '''Needed tools:''' | ||
Line 870: | Line 855: | ||
'''Step by step guide:''' | '''Step by step guide:''' | ||
* Shut Down your PS3 if not and be sure that the | * Shut Down your PS3 if not and be sure that the Progskeet's USB Cable is not plugged in. | ||
* Put your R7 Switch in OFF Position. | * Put your R7 Switch in OFF Position. | ||
* Power on your PS3. | * Power on your PS3. | ||
Line 877: | Line 862: | ||
* Open Flasher "A" and flash your file (remember to set up the NOR size/sectors!) | * Open Flasher "A" and flash your file (remember to set up the NOR size/sectors!) | ||
* When it reaches 100% , check C:\Proskeet.log, if you found some sectors failed to write... continue to the next step. | * When it reaches 100% , check C:\Proskeet.log, if you found some sectors failed to write... continue to the next step. | ||
* Without powering off your PS3, unplug | * Without powering off your PS3, unplug Progskeet's USB Cable and Close Flasher "A" | ||
* Open Flasher "B" and replug your USB Cable. | * Open Flasher "B" and replug your USB Cable. | ||
* Flash your file (remember to set up the NOR size/sectors!) | * Flash your file (remember to set up the NOR size/sectors!) | ||
Line 886: | Line 871: | ||
If you still have sectors that have failed to write, start again until they successfully write (Rember to check the Progskeet.log because reaching 100% doesn't mean that the sectors have successfully been written) | If you still have sectors that have failed to write, start again until they successfully write (Rember to check the Progskeet.log because reaching 100% doesn't mean that the sectors have successfully been written) | ||
:<small>note: <span style="color:red | :<small>note: <span style="color:red;">1)</span></small><br /> | ||
::<small><DiGiAnGeL> if you successfully write at least one of the sectors you are having problem with, this trick work for you!<br /><DiGiAnGeL> (some sectors require even 5 minutes of trying before successfully writing them)</small><br /> | ::<small><DiGiAnGeL> if you successfully write at least one of the sectors you are having problem with, this trick work for you!<br /><DiGiAnGeL> (some sectors require even 5 minutes of trying before successfully writing them)</small><br /> | ||
=== Irregular device disappering when reading/writing === | === Irregular device disappering when reading/writing === | ||
<MrGBNC> I've had good dumps but sometimes when I click read | <MrGBNC> I've had good dumps but sometimes when I click read progskeet disappears from the Device Manager | ||
<eussNL> hmm, sounds like voltage drop or usb connection fail | <eussNL> hmm, sounds like voltage drop or usb connection fail | ||
<MrGBNC> and last week was | <MrGBNC> and last week was progskeet no longer recognized by windows | ||
<MrGBNC> unknown device | <MrGBNC> unknown device | ||
<Abkarino> you may have gnd problem | <Abkarino> you may have gnd problem | ||
Line 899: | Line 884: | ||
<Abkarino> i had the same problem before | <Abkarino> i had the same problem before | ||
<Abkarino> but uf6667 and ago told me to remove r4 and try again | <Abkarino> but uf6667 and ago told me to remove r4 and try again | ||
<Abkarino> now | <Abkarino> now ProgSkeet work fine every time i plug it to my PC | ||
<MrGBNC> I've also talked to Ago, he said that the resistance between GND and VCC is too small for my | <MrGBNC> I've also talked to Ago, he said that the resistance between GND and VCC is too small for my progskeet | ||
<Ago> well, you had voltage drops | <Ago> well, you had voltage drops | ||
<Ago> and a cap might be bad | <Ago> and a cap might be bad | ||
<MrGBNC> that is why I try to exchange/warranty. I also couldn´t read a socket´ed NAND, only 30 in dump ;) | <MrGBNC> that is why I try to exchange/warranty. I also couldn´t read a socket´ed NAND, only 30 in dump ;) | ||