135 lines
6.5 KiB
Markdown
135 lines
6.5 KiB
Markdown
# Package, Image, Netbridge, and Firmware Notes
|
|
|
|
## Scope
|
|
|
|
This page records first-pass static work for the non-main-game targets listed in `next-analysis-targets.md`.
|
|
|
|
Generated artifacts:
|
|
|
|
- `analysis/static-triage/game-image-bin.binwalk.txt`
|
|
- `analysis/static-triage/spike-menu-image-bin.binwalk.txt`
|
|
- `analysis/static-triage/game-image-bin.strings-head.txt`
|
|
- `analysis/static-triage/spike-menu-image-bin.strings-head.txt`
|
|
- `analysis/static-triage/netbridge.strings`
|
|
- `analysis/static-triage/netbridge.objdump-p.txt`
|
|
- `analysis/static-triage/node-firmware-ranges.md`
|
|
- `analysis/static-triage/pokemon_pro_0_83_0_sidx.strings`
|
|
- `analysis/static-triage/pokemon_pro_0_83_0_sidx.head.hex`
|
|
- `analysis/static-triage/sidx-path-summary.txt`
|
|
- `analysis/static-triage/key-artifact-sha256.txt`
|
|
|
|
## `image.bin` Files
|
|
|
|
Targets:
|
|
|
|
- `/games/pokemon_pro/image.bin`
|
|
- `/games/pokemon_pro/spike3/spike_menu/image.bin`
|
|
|
|
Hashes:
|
|
|
|
- `/games/pokemon_pro/image.bin`: `2f1a958c1f859c339c716e53cc9ee752412373c486ea2a1bfd116eefce4617a3`
|
|
- `/games/pokemon_pro/spike3/spike_menu/image.bin`: `a7df00dbbfb75838fd19d57ada30f4247d2ef1bc4b357ca0a64ab60f3a679af0`
|
|
|
|
Both files start with the same 0xb0-byte-looking binary header shape. First 8 bytes are `b0 00 00 00 00 00 00 00`. The game image has early little-endian values including `0x1be18`, `0x1bdf8`, `0x18fd0`, and `0x18c70`; the spike-menu image has corresponding smaller values including `0x3d00`, `0x3ce0`, `0xef8`, and `0xb98`.
|
|
|
|
`binwalk` results:
|
|
|
|
- `/games/pokemon_pro/image.bin` reported copyright strings at `0x1ca6c` and `0x1ddee`, plus a likely false-positive `JBOOT STAG` signature at `0xd36e9d6`.
|
|
- `/games/pokemon_pro/spike3/spike_menu/image.bin` reported copyright strings at `0x4954` and `0x5cd6`.
|
|
|
|
The first strings in both images are Stern EULA text. This is consistent with a Radium/runtime serialized image rather than a normal media archive. The `.sidx` path table below strongly links these images to Radium asset trees under `assets/lcd/demand_loaded/` and `assets/lcd/auto_loaded/`.
|
|
|
|
## Update Index `.sidx`
|
|
|
|
Target:
|
|
|
|
- `/games/spk/index/pokemon_pro-0_83_0.sidx`
|
|
|
|
SHA-256:
|
|
|
|
- `caf06531ca1b969b6d727d76af7ace8931277dbdb6584ecb5a238f427fe0a76a`
|
|
|
|
`strings -a -t x` over the `.sidx` file found 686 package paths. Examples:
|
|
|
|
- `0x40`: `pokemon_pro/spike3/netbridge/rp2040.cfg`
|
|
- `0x68`: `pokemon_pro/spike3/netbridge/spike3-swd.cfg`
|
|
- `0x94`: `pokemon_pro/spike3/netbridge/netbridge.elf`
|
|
- `0xbf`: `pokemon_pro/spike3/netbridge/version.txt`
|
|
- `0xe8`: `pokemon_pro/spike3/powerdist/powerdist_ext.hex`
|
|
- `0x117`: `pokemon_pro/spike3/powerdist/version.txt`
|
|
- `0x140`: `pokemon_pro/spike3/spike_menu/game`
|
|
- `0x163`: `pokemon_pro/spike3/spike_menu/image.bin`
|
|
- `0x18b`: `pokemon_pro/spike3/spike_menu/assets/lcd/demand_loaded/.../scene.radium`
|
|
- `0x1232`: `pokemon_pro/spike3/spike_menu/assets/nuk/fonts/Hack-Regular.ttf`
|
|
|
|
The final path entries include game Radium assets such as:
|
|
|
|
- `pokemon_pro/assets/lcd/auto_loaded/60ed7e5036b8ce09d35a3e101ea6fc1380b37d97/scene.assets/2.asset/247.asset`
|
|
- `pokemon_pro/assets/lcd/auto_loaded/60ed7e5036b8ce09d35a3e101ea6fc1380b37d97/scene.radium`
|
|
- `pokemon_pro/assets/lcd/auto_loaded/856d8afd38e1c753b3536bccebf3b4c925a4fc6e/scene.radium`
|
|
|
|
Inference: the `.sidx` file is a package/content index for the installed `.spk` payload. It enumerates files, but this pass did not fully reverse record headers, hashes, or size fields.
|
|
|
|
## Netbridge
|
|
|
|
Target:
|
|
|
|
- `/games/pokemon_pro/spike3/netbridge/netbridge.elf`
|
|
|
|
Confirmed facts:
|
|
|
|
- SHA-256: `05b7f7c329da79fb24078df69c8401c7a47be5c8a855b73fb937e052bce28d85`
|
|
- ELF: 32-bit little-endian ARM, statically linked, debug info present, not stripped.
|
|
- Program headers map executable code at `0x10000000`, initialized data at `0x200000c0`, and RAM regions at `0x20000000` and `0x20040000`.
|
|
|
|
Strings/function names from `netbridge.elf`:
|
|
|
|
- `uart_node.c`
|
|
- `UART_NodeRxIrq`
|
|
- `UART_NodeTxIrq`
|
|
- `UART_NodeGetMessageBlock`
|
|
- `NODE_Init`
|
|
- `NODEBUS_Poll`
|
|
- `NODEUART_Write`
|
|
- `NODEUART_WritePoll`
|
|
- `NODEUART_WriteAddress`
|
|
- `NODE_SendBreak`
|
|
- `WS2812_NodeSetLED`
|
|
|
|
This confirms netbridge is directly related to nodebus UART communication and WS2812 LED-node operations.
|
|
|
|
OpenOCD configs already documented in `applications-and-services.md`:
|
|
|
|
- `spike3-swd.cfg` maps SWCLK to Raspberry Pi GPIO 11 and SWDIO to GPIO 10.
|
|
- `rp2040.cfg` is present for RP2040 target handling.
|
|
|
|
Deeper Ghidra-backed netbridge protocol notes and the host-side emulator scaffold are now documented in `netbridge-re.md`.
|
|
|
|
## Node Firmware
|
|
|
|
The 17 top-level node firmware HEX files under `/games/pokemon_pro` are Intel HEX style data payloads. All parsed data ranges begin at `0x1000`, consistent with Cortex-M images that leave a bootloader or vector-reserved area below that address.
|
|
|
|
Parsed ranges:
|
|
|
|
| Path | Records | Data bytes | Min addr | Max addr |
|
|
| --- | ---: | ---: | ---: | ---: |
|
|
| `/games/pokemon_pro/coil4_lednode-LPC1313-1_33_0.hex` | 1541 | 24576 | `0x1000` | `0x6fff` |
|
|
| `/games/pokemon_pro/coil4node-LPC1112_101-1_33_0.hex` | 772 | 12288 | `0x1000` | `0x3fff` |
|
|
| `/games/pokemon_pro/coil4node-LPC1112_201-1_33_0.hex` | 772 | 12288 | `0x1000` | `0x3fff` |
|
|
| `/games/pokemon_pro/coil4node-LPC1313-1_33_0.hex` | 1541 | 24576 | `0x1000` | `0x6fff` |
|
|
| `/games/pokemon_pro/hdmi_ws2812node-LPC1313-1_33_0.hex` | 900 | 14336 | `0x1000` | `0x47ff` |
|
|
| `/games/pokemon_pro/hdminode-LPC1313-1_33_0.hex` | 836 | 13312 | `0x1000` | `0x43ff` |
|
|
| `/games/pokemon_pro/lcdnode-LPC1113_302-1_33_0.hex` | 1093 | 17408 | `0x1000` | `0x53ff` |
|
|
| `/games/pokemon_pro/magsensornode-LPC812-1_33_0.hex` | 772 | 12288 | `0x1000` | `0x3fff` |
|
|
| `/games/pokemon_pro/node4-LPC1124_303-1_33_0.hex` | 900 | 14336 | `0x1000` | `0x47ff` |
|
|
| `/games/pokemon_pro/node4-LPC812-1_33_0.hex` | 772 | 12288 | `0x1000` | `0x3fff` |
|
|
| `/games/pokemon_pro/pinnode-LPC1112_101-1_33_0.hex` | 772 | 12288 | `0x1000` | `0x3fff` |
|
|
| `/games/pokemon_pro/pinnode-LPC1112_201-1_33_0.hex` | 772 | 12288 | `0x1000` | `0x3fff` |
|
|
| `/games/pokemon_pro/pinnode-LPC1313-1_33_0.hex` | 1606 | 25600 | `0x1000` | `0x73ff` |
|
|
| `/games/pokemon_pro/tmc2590node-LPC1313-1_33_0.hex` | 836 | 13312 | `0x1000` | `0x43ff` |
|
|
| `/games/pokemon_pro/tmc5041node-LPC1313-1_33_0.hex` | 964 | 15360 | `0x1000` | `0x4bff` |
|
|
| `/games/pokemon_pro/ws2812node-LPC1313-1_33_0.hex` | 900 | 14336 | `0x1000` | `0x47ff` |
|
|
| `/games/pokemon_pro/ws2812pinnode-LPC1313-1_33_0.hex` | 1157 | 18432 | `0x1000` | `0x57ff` |
|
|
|
|
`/games/pokemon_pro/spike3/powerdist/powerdist_ext.hex` is present in the `.sidx` package index and remains a separate follow-up target for power-distribution firmware parsing.
|