Editing Talk:SC EEPROM
Jump to navigation
Jump to search
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then publish the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 4: | Line 4: | ||
Pseudo-code: | Pseudo-code: | ||
< | <source lang="python"> | ||
def check_bootrom_diag_mode(mode, param) | def check_bootrom_diag_mode(mode, param) | ||
diag_mode = get_eeprom_bootrom_diag() | diag_mode = get_eeprom_bootrom_diag() | ||
Line 16: | Line 16: | ||
param = -1 | param = -1 | ||
return 1 | return 1 | ||
</ | </source> | ||
== EEPROM Dumps == | == EEPROM Dumps == | ||
Line 28: | Line 28: | ||
== Bus Pirate stuff == | == Bus Pirate stuff == | ||
http://i.imgur.com/48rbR51.png | |||
(needs more wikifying) | (needs more wikifying) | ||
Line 77: | Line 77: | ||
The format of this region is weird, in mullions have a size of 0x200 but it was reduced to 0x100 for sherwoods<br> | The format of this region is weird, in mullions have a size of 0x200 but it was reduced to 0x100 for sherwoods<br> | ||
In sherwoods it seems to start with 2 bytes (bringup counter), 2 bytes (shutdown counter), 4 bytes (total runtime in seconds), 4 bytes (unknown, but the last 2 bytes are always 0000), then value 0x3CEF0000 (unknown, seems to be static). The rest of the region is filled with FF, some consoles have 2 bytes used at relative offset 0x20 (as example, with value 0x55AA) | In sherwoods it seems to start with 2 bytes (bringup counter), 2 bytes (shutdown counter), 4 bytes (total runtime in seconds), 4 bytes (unknown, but the last 2 bytes are always 0000), then value 0x3CEF0000 (unknown, seems to be static). The rest of the region is filled with FF, some consoles have 2 bytes used at relative offset 0x20 (as example, with value 0x55AA) | ||
= Experimental table = | = Experimental table = | ||
Line 307: | Line 82: | ||
{| class="wikitable sortable" style="line-height:100%; font-size:85%" | {| class="wikitable sortable" style="line-height:100%; font-size:85%" | ||
|+ Round | |+ Round 2 | ||
! colspan="3" | Area !! colspan="4" | [[Syscon_Hardware|<abbr title="Only Mullion syscons have a direct SPI access to the EEPROM>SPI</abbr> / <abbr title="All syscons have a UART access>UART</abbr>]] !! colspan=" | ! colspan="3" | Area !! colspan="4" | [[Syscon_Hardware|<abbr title="Only Mullion syscons have a direct SPI access to the EEPROM>SPI</abbr> / <abbr title="All syscons have a UART access>UART</abbr>]] !! colspan="6" | [[LV2_Functions_and_Syscalls#process_socket_service_syscalls|Syscall 863]] !! class="unsortable" rowspan="3" | Data Name !! class="unsortable" rowspan="3" | Wikitable builder Notes (temporal) | ||
|- | |- | ||
! class="unsortable" rowspan="2" | Name !! class="unsortable" rowspan="2" | Size !! class="unsortable" style="padding:1px" rowspan="2" | [[Template:Syscon_checksums|<Abbr title="Checksum">csum</abbr>]] !! colspan="2" | [[Mullion]] !! style="padding:1px" | [[Sherwood]] !! style="padding:1px" | | ! class="unsortable" rowspan="2" | Name !! class="unsortable" rowspan="2" | Size !! class="unsortable" style="padding:1px" rowspan="2" | [[Template:Syscon_checksums|<Abbr title="Checksum">csum</abbr>]] !! colspan="2" | [[Mullion]] !! style="padding:1px" | [[Sherwood]] !! style="padding:1px" | whitelist !! class="unsortable" style="padding:1px" rowspan="2" | [[SC_Communication#Syscon_Services|Block ID<br>NVS Region]] !! colspan="3" | whitelist !! rowspan="2" | Offset !! class="unsortable" rowspan="2" | Size | ||
|- | |- | ||
! <abbr title="201GB, 202GB">32KB</abbr> !! <abbr title="203GB, 301GB, 302GB, 303GB, 304GB">20KB</abbr> !! [[Syscon_SW_Series|SW]]/[[Syscon_SW2_Series|2]]/[[Syscon_SW3_Series|3]]<small><abbr title="Emulated EEPROM">(emu)</abbr></small> !! class="unsortable" | [[Syscon_Firmware#Command_list|EEP]] | ! <abbr title="201GB, 202GB">32KB</abbr> !! <abbr title="203GB, 301GB, 302GB, 303GB, 304GB">20KB</abbr> !! [[Syscon_SW_Series|SW]]/[[Syscon_SW2_Series|2]]/[[Syscon_SW3_Series|3]]<small><abbr title="Emulated EEPROM">(emu)</abbr></small> !! class="unsortable" | [[Syscon_Firmware#Command_list|EEP]] !! class="unsortable" | lv1/[[Dispatcher_Manager|DM]] !! class="unsortable" | [[Update_Manager|UM]] !! class="unsortable" | [[SC_Manager|SCM]] | ||
|- class="sorttop" | |- class="sorttop" | ||
! colspan=" | ! colspan="15" style="padding:0px" | | ||
|- | |- | ||
! Authenticated Data !! | ! Authenticated Data !! 0x2560 !! {{no}} | ||
| 0x0000 || 0x0000 || ? || {{exploitable}} || {{no}} || {{ | | 0x0000 || 0x0000 || ? || {{exploitable}} || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || || || Data table (0x160+(0x9*0x400)) ? | ||
|- {{cellcolors|#e3e3e3}} | |||
! ? !! 0x150 !! {{no}} | |||
| 0x2560 || 0x2560 || ? || {{exploitable}} || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || || || Filled with FF's ? | |||
|- {{cellcolors|#ddddff}} | |- {{cellcolors|#ddddff}} | ||
! System Info !! | ! System Info !! 0x150 !! {{no}} | ||
| | | 0x26B0 || 0x26B0 || 0x0000~ ? || {{exploitable}} || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || || || This wikitable row needs to be splitted up to 5+ rows | ||
|- {{cellcolors|#ffffcc}} | |- {{cellcolors|#ffffcc}} | ||
! Patch 1 !! 0x400 !! {{No}} | ! Patch 1 !! 0x400 !! {{No}} | ||
| <abbr title="Encrypted">0x2800</abbr> || <abbr title="Encrypted">0x2800</abbr> || <abbr title="The patch, in decrypted format, is stored | | <abbr title="Encrypted">0x2800</abbr> || <abbr title="Encrypted">0x2800</abbr> || <abbr title="The patch, in decrypted format, is stored in FLASH, offset 0x2000, length 0x1000>0x2000<small>(flash)</small></abbr> || {{exploitable}} || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x400 || [[Syscon_Firmware#Syscon_patches|Syscon Firmware Patch]] (top half) || | ||
|- {{cellcolors|lightgrey}} | |- {{cellcolors|lightgrey}} | ||
! - !! 0x300 !! {{No}} | ! - !! 0x300 !! {{No}} | ||
| 0x2C00 || 0x2C00 || 0x0B00 || {{yes}} || {{no}} || {{ | | 0x2C00 || 0x2C00 || 0x0B00 || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x300 || style="text-align:center" | ''not used'' || Filled with FF's | ||
|- | |- | ||
! Industry Area !! 0x100 !! {{no}} | ! Industry Area !! 0x100 !! {{no}} | ||
| 0x2F00 || 0x2F00 || 0x0E00 || {{yes}} || 0x10 | | 0x2F00 || 0x2F00 || 0x0E00 || {{yes}}/UART || 0x10 || {{patchable}} || {{yes}} || {{yes}} || 0x02F00 || || || This wikitable row needs to be splitted up to 20+ rows | ||
|- {{cellcolors|#e3e3e3}} | |- {{cellcolors|#e3e3e3}} | ||
! Customer Service Area !! 0x100 !! {{no}} | ! Customer Service Area !! 0x100 !! {{no}} | ||
| 0x3000 || 0x3000 || 0x0F00 || {{yes}} || 0x20 | | 0x3000 || 0x3000 || 0x0F00 || {{yes}}/UART || 0x20 || {{patchable}} || {{yes}} || {{yes}} || 0x03000 || 0x100 || || Filled with FF's ? | ||
|- | |- | ||
! Platform Config !! 0x100 !! {{yes}} | ! Platform Config !! 0x100 !! {{yes}} | ||
| 0x3100 || 0x3100 || 0x0040~ || {{yes}} || {{no}} || {{ | | 0x3100 || 0x3100 || 0x0040~ || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || || This wikitable row needs to be splitted up to 5+ rows | ||
|- | |- | ||
! Hardware Config !! 0x100 !! {{yes}} | ! Hardware Config !! 0x100 !! {{yes}} | ||
| 0x3200 || 0x3200 || 0x0140~ || {{yes}} || {{no}} || {{ | | 0x3200 || 0x3200 || 0x0140~ || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || || This wikitable row needs to be splitted up to 40+ rows | ||
|- | |- | ||
! Thermal Config !! 0x200<!-- size reduced to 0x1B0 for sherwoods ? --> !! {{yes}} | ! Thermal Config !! 0x200<!-- size reduced to 0x1B0 for sherwoods ? --> !! {{yes}} | ||
| 0x3300 || 0x3300 || 0x0250 | | 0x3300 || 0x3300 || 0x0250~ || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x200 || [[Syscon_Thermal_Configs/structs|Data table]]. See: [[Syscon Thermal Configs]] || | ||
|- | |- | ||
! BE Count !! 0x200<!-- size reduced to 0x100 for sherwoods ? --> !! {{no}} | ! BE Count !! 0x200<!-- size reduced to 0x100 for sherwoods ? --> !! {{no}} | ||
| 0x3500 || 0x3500 || 0x0800 (size 0x100) || {{yes}} || {{no}} || {{ | | 0x3500 || 0x3500 || 0x0800 (size 0x100) || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x200 || Data table || | ||
|- | |- | ||
! Error Log !! 0x100 !! {{no}} | ! Error Log !! 0x100 !! {{no}} | ||
| 0x3700 || 0x3700 || 0x0900 || {{yes}} || {{no}} || {{ | | 0x3700 || 0x3700 || 0x0900 || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || Data table. See: [[Syscon Error Codes]] || | ||
|- {{cellcolors|lightgrey}} | |- {{cellcolors|lightgrey}} | ||
! - !! 0x100 !! {{No}} | ! - !! 0x100 !! {{No}} | ||
| 0x3800 || 0x3800 || N/A ? || {{yes}} || {{no}} || {{ | | 0x3800 || 0x3800 || N/A ? || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || style="text-align:center" | ''not used'' || Filled with FF's | ||
|- | |- | ||
! Board Config/Debug !! 0x100 !! {{yes}} | ! Board Config/Debug !! 0x100 !! {{yes}} | ||
| 0x3900 || 0x3900 || 0x0000~ ? || {{yes}} || {{no}} || {{ | | 0x3900 || 0x3900 || 0x0000~ ? || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || || This wikitable row needs to be splitted up to 15+ rows | ||
|- | |- | ||
! HDMI/DVE Config !! 0x100 !! {{no}} | ! HDMI/DVE Config !! 0x100 !! {{no}} | ||
| 0x3A00 || 0x3A00 || 0x0A00 || {{yes}} || {{no}} || {{ | | 0x3A00 || 0x3A00 || 0x0A00 || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || || This wikitable row needs to be splitted up to 5+ rows | ||
|- {{cellcolors|lightgrey}} | |- {{cellcolors|lightgrey}} | ||
! - !! 0x100 !! {{No}} | ! - !! 0x100 !! {{No}} | ||
| 0x3B00 || 0x3B00 || N/A ? || {{yes}} || {{no}} || {{ | | 0x3B00 || 0x3B00 || N/A ? || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x100 || style="text-align:center" | ''not used'' || Filled with FF's | ||
|- {{cellcolors|lightgrey}} | |- {{cellcolors|lightgrey}} | ||
! Config Ring !! 0x200 !! {{yes}} | ! Config Ring !! 0x200 !! {{yes}} | ||
| 0x3C00 || 0x3C00 || 0x0400 ? || {{yes}} || {{no}} || {{ | | 0x3C00 || 0x3C00 || 0x0400 ? || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x200 || style="text-align:center" | ''not used'' || <abbr title="When filled with 0xFF's the checksum at the last 2 bytes is 0xFF00">Filled with FF's</abbr> | ||
|- {{cellcolors|lightgrey}} | |- {{cellcolors|lightgrey}} | ||
! Debug 2 !! 0x200 !! {{yes}} | ! Debug 2 !! 0x200 !! {{yes}} | ||
| 0x3E00 || 0x3E00 || 0x0600 ? || {{yes}} || {{no}} || {{ | | 0x3E00 || 0x3E00 || 0x0600 ? || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x200 || style="text-align:center" | ''not used'' || <abbr title="When filled with 0xFF's the checksum at the last 2 bytes is 0xFF00">Filled with FF's</abbr> | ||
|- {{cellcolors|#888}} | |- {{cellcolors|#888}} | ||
! - !! 0x3000 !! {{No}} | ! - !! 0x3000 !! {{No}} | ||
| 0x4000 || N/A || N/A || {{yes}} || {{no}} || {{ | | 0x4000 || N/A || N/A || {{yes}}/UART || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0x3000 || style="text-align:center" | ''reserved'' || Filled with FF's | ||
|- {{cellcolors|#e3e3e3}} | |- {{cellcolors|#e3e3e3}} | ||
! System Config ? !! 0x100 !! {{no}} | ! System Config ? !! 0x100 !! {{no}} | ||
| 0x7000 || 0x4000 || 0x1000 || {{yes}} || 0x0 | | 0x7000 || 0x4000 || 0x1000 || {{yes}}/UART || 0x0 || {{patchable}} || {{patchable}} || {{yes}} || 0x48000 || 0x100 || || Filled with FF's ? | ||
|- | |- | ||
! Event Log ? !! 0x100 !! {{no}} | ! System Event Log ? !! 0x100 !! {{no}} | ||
| 0x7100 || 0x4100 || 0x1100 || {{yes}} || 0x1 | | 0x7100 || 0x4100 || 0x1100 || {{yes}}/UART || 0x1 || {{patchable}} || {{patchable}} || {{yes}} || 0x48800 || || Data table (0x10+(0x6*0x28)) || <abbr title="It looks like a data table with a 0x10 header and six entries of 0x28 bytes lenght">Header + Data table ?</abbr> | ||
|- | |- | ||
! Flags and Tokens !! 0x100 !! {{no}} | ! Flags and Tokens !! 0x100 !! {{no}} | ||
| 0x7200 || 0x4200 || 0x1200 || {{yes}} || 0x2 | | 0x7200 || 0x4200 || 0x1200 || {{yes}}/UART || 0x2 || {{patchable}} || <abbr title="Every individual value needs a specific tag">Yes<br>or<br>Patch*</abbr> || {{yes}} || 0x48C00 || || || This wikitable row needs to be splitted up to 50+ rows | ||
|- {{cellcolors|#e3e3e3}} | |- {{cellcolors|#e3e3e3}} | ||
! System Data ? !! 0x100 !! {{no}} | ! System Data ? !! 0x100 !! {{no}} | ||
| 0x7300 || 0x4300 || 0x1300 || {{yes}} || 0x3 | | 0x7300 || 0x4300 || 0x1300 || {{yes}}/UART || 0x3 || {{patchable}} || {{patchable}} || {{yes}} || 0x48D00 || 0x100 || || Filled with FF's ? | ||
|- {{cellcolors|#ffffcc}} | |- {{cellcolors|#ffffcc}} | ||
! Patch 2 !! 0xC00 !! {{No}} | ! Patch 2 !! 0xC00 !! {{No}} | ||
| <abbr title="Encrypted">0x7400</abbr> || <abbr title="Encrypted">0x4400</abbr> || <abbr title="The patch, in decrypted format, is stored | | <abbr title="Encrypted">0x7400</abbr> || <abbr title="Encrypted">0x4400</abbr> || <abbr title="The patch, in decrypted format, is stored in FLASH, offset 0x2000, length 0x1000>0x2000<small>(flash)</small></abbr> || {{exploitable}} || {{no}} || {{patchable}} || {{patchable}} || {{patchable}} || ? || 0xC00 || [[Syscon_Firmware#Syscon_patches|Syscon Firmware Patch]] (bottom half) || | ||
|} | |} |