Wednesday, February 9, 2011

Dfu-util - Device Firmware Upgrade Utilities

Official website: http://dfu-util.gnumonks.org
Repository: http://git.openezx.org/dfu-util.git

$ aptitude show dfu-util
Package: dfu-util
New: yes
State: not installed
Version: 0.3-1
Priority: extra
Section: electronics
Maintainer: Uwe Hermann
Uncompressed Size: 81.9 k
Depends: libc6 (>= 2.0), libusb-0.1-4 (>= 2:0.1.12)
Description: Device firmware update (DFU 1.0) USB programmer
dfu-util is a program that implements the host (PC) side of the USB DFU 1.0 (Universal Serial Bus Device Firmware Upgrade) protocol.

Note: At this point only DFU version 1.0 is supported!

In the OpenMoko project (for example), this program is used to communicate with the specially enhanced bootloader u-boot, which implements the DFU device
side.
Homepage: http://dfu-util.gnumonks.org/

$ sudo aptitude install dfu-util

$ dpkg -L dfu-util
/.
/usr
/usr/bin
/usr/bin/dfu-util
/usr/share
/usr/share/doc
/usr/share/doc/dfu-util
/usr/share/doc/dfu-util/copyright
/usr/share/doc/dfu-util/TODO
/usr/share/doc/dfu-util/README
/usr/share/doc/dfu-util/changelog.gz
/usr/share/doc/dfu-util/changelog.Debian.gz
/usr/share/man
/usr/share/man/man1
/usr/share/man/man1/dfu-util.1.gz

USB Device Firmware Upgrade (DFU)

Universal Serial Bus Device Class Specification for Device Firmware Upgrade [PDF]

Page 16 :

Firmware images for specific devices are, by definition, vendor specific. It is therefore required that target addresses, record sizes, and all other information relative to supporting an upgrade are encapsulated within the firmware image file. It is the responsibility of the device manufacturer and the firmware developer to ensure that their devices can consume these encapsulated data. With the exception of the DFU file suffix, the content of the firmware image file is irrelevant to the host. The host simply slices the firmware image file into N pieces and sends them to the device by means of control-write operations on the default control endpoint.

Page 38 :

Any file to be downloaded must contain a DFU suffix. The purpose of the DFU suffix is to allow the operating system in general, and the DFU operator interface application in particular, to have a-priori knowledge of whether a firmware download is likely to complete correctly. In other words, these bytes allow the host software to detect and prevent attempts to download incompatible firmware.

...

In no case is the DFU suffix ever sent to the device. The host application verifies that the bytes occupying the ucDfuSignature field contain the specified values, and that the CRC over the file matches the dwCRC field. If these two criteria are passed, then the host can presume that the firmware upgrade file is intact. The host application then uses the DFU suffix data to perform appropriate validation and screening. During the Transfer phase, the contents of the file are sent, excluding the DFU suffix data.

Tuesday, February 8, 2011

Pure Siesta Flow #4

$ du -b Siesta_Flow_v1.6.dfu
3906160 Siesta_Flow_v1.6.dfu

$ du -b Siesta_Flow_v2.6.dfu
3906160 Siesta_Flow_v2.6.dfu

$ hd -s $((3906160-256)) Siesta_Flow_v1.6.dfu > end-1.6.txt
$ hd -s $((3906160-256)) Siesta_Flow_v2.6.dfu > end-2.6.txt

$ diff -s end-1.6.txt end-2.6.txt
3c3
< 003b9a60 00 00 41 01 9a 14 00 01 55 46 44 10 66 fb 84 a7 |..A.....UFD.fû.§|
---
> 003b9a60 00 00 58 01 9a 14 00 01 55 46 44 10 43 03 d9 42 |..X.....UFD.C.ÙB|

Pure Siesta Flow #3

$ hd -n 256 Siesta_Flow_v1.6.dfu > start-1.6.txt
$ hd -n 256 Siesta_Flow_v2.6.dfu > start-2.6.txt

$ diff -s start-1.6.txt start-2.6.txt
Files start-1.6.txt and start-2.6.txt are identical

$ cat start-1.6.txt
00000000 4e 56 53 31 80 10 00 00 80 0f 04 00 00 00 00 00 |NVS1............|
00000010 4c 44 52 53 00 20 04 00 a0 45 02 00 00 00 00 00 |LDRS. .. E......|
00000020 4c 44 4c 4b 20 66 06 00 e0 23 00 00 00 00 00 00 |LDLK f..à#......|
00000030 4c 44 4c 5a c0 8a 06 00 de 0a 08 00 00 00 00 00 |LDLZÀ...Þ.......|
00000040 4c 4b 47 5a 30 97 0e 00 73 08 0a 00 00 00 00 00 |LKGZ0...s.......|
00000050 53 51 46 53 10 a1 18 00 00 10 27 00 00 00 00 00 |SQFS.¡....'.....|
00000060 46 52 45 45 10 b1 3f 00 f0 4e 02 00 00 00 00 00 |FREE.±?.ðN......|
00000070 ff ff ff ff 00 00 00 00 00 00 00 00 80 00 67 e7 |ÿÿÿÿ..........gç|
00000080 05 00 10 00 00 6c 0c 00 90 68 0c 00 6e 01 19 e0 |.....l...h..n..à|
00000090 05 80 6e 01 02 00 00 00 bc 00 00 02 01 00 00 00 |..n.....Œ.......|
000000a0 02 00 00 00 28 80 02 02 02 00 00 00 02 00 00 00 |....(...........|
000000b0 0c 80 02 02 d9 ce 00 00 02 00 00 00 64 00 00 02 |....ÙÎ......d...|
000000c0 16 44 03 00 00 00 00 00 c8 00 00 00 02 00 00 00 |.D......È.......|
000000d0 64 00 00 02 16 44 04 00 00 00 00 00 c8 00 00 00 |d....D......È...|
000000e0 02 00 00 00 64 00 00 02 16 44 04 80 02 00 00 00 |....d....D......|
000000f0 10 80 02 02 92 33 06 00 02 00 00 00 14 80 02 02 |.....3..........|
00000100

Pure Siesta Flow #2

$ strace -e trace=open wine ./Siesta_Flow_v1.6.exe
...
open("/home/fwhacking/.wine/dosdevices/c:/windows/temp/pft303.tmp", O_RDONLY|O_LARGEFILE|O_DIRECTORY) = 16
...

$ cp /home/fwhacking/.wine/dosdevices/c:/windows/temp/pft303.tmp/Siesta_Flow_v1.6.dfu /home/fwhacking/siesta_flow/

$ strace -e trace=open wine ./Siesta_Flow_v2.6.exe
...
open("/home/fwhacking/.wine/dosdevices/c:/windows/temp/pft2e7.tmp", O_RDONLY|O_LARGEFILE|O_DIRECTORY) = 15
...

$ cp /home/fwhacking/.wine/dosdevices/c\:/windows/temp/pft2e7.tmp/Siesta_Flow_v2.6.dfu /home/fwhacking/siesta_flow/

Pure Siesta Flow #1



Tuesday, February 1, 2011

Sagem RM50 #12

Interesting strings from:

$ strings rootfs1/lib/modules/2.6.28.9/kernel/drivers/net/wireless/kona/kona.ko

DSPG 802.11 Wireless LAN Driver 1.7n BYPASS RELEASE 4649037
DSPG 802.11abg

author=DSP GROUP,Inc.
description=DSPG WIFI Driver
license=GPL
vermagic=2.6.28.9 preempt mod_unload ARMv5

/home/jyoung/scm/kona-wnc-workaround/SME/Sme.c
/home/jyoung/scm/kona-wnc-workaround/SME/SmeOutput.c
/home/jyoung/scm/kona-wnc-workaround/include/DescUtils.h
/home/jyoung/scm/kona-wnc-workaround/Utils/DescUtils.c
/home/jyoung/scm/kona-wnc-workaround/HAL/HalUtils.c
/home/jyoung/scm/kona-wnc-workaround/LWE/LWE_handlers.c
/home/jyoung/scm/kona-wnc-workaround/Scheduler/scheduler.c
/home/jyoung/scm/kona-wnc-workaround/Decap/Decap.c

DSP Group http://www.dspg.com

http://www.dspg.com/GetFile.ashx?FilePath=/upload/Downloads/&FileName=file_188.pdf
Integrated circuits used in products by leading global brands including: [...] Sagem [...]