X-Git-Url: https://git.zerfleddert.de/cgi-bin/gitweb.cgi/rsbs2/blobdiff_plain/0fcfb8f327f693fd691592cd04cc403d553f0924..9eb4b3c68c23622076943399ae2c8d298eb32799:/rsb-lz.c diff --git a/rsb-lz.c b/rsb-lz.c index 64a1a47..b624265 100644 --- a/rsb-lz.c +++ b/rsb-lz.c @@ -1,6 +1,115 @@ +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include "rsb-crc.h" +#include "rsb-lz.h" + /* TODO: IMPLEMET THIS! */ /* Probably very broken lzw implementation by Agilent: * + * 59508: e3a00078 mov r0, #120 ; 0x78 + * 5950c: ee010f10 mcr 15, 0, r0, cr1, cr0, {0} + * 59510: e3a00000 mov r0, #0 ; 0x0 + * 59514: ee070f15 mcr 15, 0, r0, cr7, cr5, {0} + * 59518: ee070f16 mcr 15, 0, r0, cr7, cr6, {0} + * 5951c: ee020f30 mcr 15, 0, r0, cr2, cr0, {1} + * 59520: ee020f10 mcr 15, 0, r0, cr2, cr0, {0} + * 59524: ee030f10 mcr 15, 0, r0, cr3, cr0, {0} + * 59528: ee050f70 mcr 15, 0, r0, cr5, cr0, {3} + * 5952c: ee050f50 mcr 15, 0, r0, cr5, cr0, {2} + * 59530: ee050f30 mcr 15, 0, r0, cr5, cr0, {1} + * 59534: ee050f10 mcr 15, 0, r0, cr5, cr0, {0} + * 59538: e3a00016 mov r0, #22 ; 0x16 + * 5953c: ee060f10 mcr 15, 0, r0, cr6, cr0, {0} + * 59540: ee060f11 mcr 15, 0, r0, cr6, cr1, {0} + * 59544: ee060f12 mcr 15, 0, r0, cr6, cr2, {0} + * 59548: ee060f13 mcr 15, 0, r0, cr6, cr3, {0} + * 5954c: ee060f14 mcr 15, 0, r0, cr6, cr4, {0} + * 59550: ee060f15 mcr 15, 0, r0, cr6, cr5, {0} + * 59554: ee060f16 mcr 15, 0, r0, cr6, cr6, {0} + * 59558: ee060f17 mcr 15, 0, r0, cr6, cr7, {0} + * 5955c: e1a0f00e mov r15, r14 + * 59560: e3a01000 mov r1, #0 ; 0x0 + * 59564: ee071f15 mcr 15, 0, r1, cr7, cr5, {0} + * 59568: ee071f16 mcr 15, 0, r1, cr7, cr6, {0} + * 5956c: e3800078 orr r0, r0, #120 ; 0x78 + * 59570: ee010f10 mcr 15, 0, r0, cr1, cr0, {0} + * 59574: e1a0f00e mov r15, r14 + * 59578: e92d00f0 push {r4, r5, r6, r7} + * 5957c: e3500007 cmp r0, #7 ; 0x7 + * 59580: 8a00003c bhi 0x59678 + * 59584: e3e04ef0 mvn r4, #3840 ; 0xf00 + * 59588: e22440ff eor r4, r4, #255 ; 0xff + * 5958c: e1d14004 bics r4, r1, r4 + * 59590: 1a000038 bne 0x59678 + * 59594: e3a0403f mov r4, #63 ; 0x3f + * 59598: e1d24004 bics r4, r2, r4 + * 5959c: 1a000035 bne 0x59678 + * 595a0: e3a06001 mov r6, #1 ; 0x1 + * 595a4: e1a04423 lsr r4, r3, #8 + * 595a8: e2044001 and r4, r4, #1 ; 0x1 + * 595ac: ee125f30 mrc 15, 0, r5, cr2, cr0, {1} + * 595b0: e1c55016 bic r5, r5, r6, lsl r0 + * 595b4: e1855014 orr r5, r5, r4, lsl r0 + * 595b8: ee025f30 mcr 15, 0, r5, cr2, cr0, {1} + * 595bc: e1a044a3 lsr r4, r3, #9 + * 595c0: e2044001 and r4, r4, #1 ; 0x1 + * 595c4: ee125f10 mrc 15, 0, r5, cr2, cr0, {0} + * 595c8: e1c55016 bic r5, r5, r6, lsl r0 + * 595cc: e1855014 orr r5, r5, r4, lsl r0 + * 595d0: ee025f10 mcr 15, 0, r5, cr2, cr0, {0} + * 595d4: e1a04523 lsr r4, r3, #10 + * 595d8: e2044001 and r4, r4, #1 ; 0x1 + * 595dc: ee135f10 mrc 15, 0, r5, cr3, cr0, {0} + * 595e0: e1c55016 bic r5, r5, r6, lsl r0 + * 595e4: e1855014 orr r5, r5, r4, lsl r0 + * 595e8: ee035f10 mcr 15, 0, r5, cr3, cr0, {0} + * 595ec: e3a0600f mov r6, #15 ; 0xf + * 595f0: e3a07004 mov r7, #4 ; 0x4 + * 595f4: e0070790 mul r7, r0, r7 + * 595f8: e0034006 and r4, r3, r6 + * 595fc: ee155f70 mrc 15, 0, r5, cr5, cr0, {3} + * 59600: e1c55716 bic r5, r5, r6, lsl r7 + * 59604: e1855714 orr r5, r5, r4, lsl r7 + * 59608: ee055f70 mcr 15, 0, r5, cr5, cr0, {3} + * 5960c: e1a04223 lsr r4, r3, #4 + * 59610: e0044006 and r4, r4, r6 + * 59614: ee155f50 mrc 15, 0, r5, cr5, cr0, {2} + * 59618: e1c55716 bic r5, r5, r6, lsl r7 + * 5961c: e1855714 orr r5, r5, r4, lsl r7 + * 59620: ee055f50 mcr 15, 0, r5, cr5, cr0, {2} + * 59624: e1814002 orr r4, r1, r2 + * 59628: e08ff180 add r15, r15, r0, lsl #3 + * 5962c: e1a00000 nop (mov r0,r0) + * 59630: ee064f10 mcr 15, 0, r4, cr6, cr0, {0} + * 59634: ea00000c b 0x5966c + * 59638: ee064f11 mcr 15, 0, r4, cr6, cr1, {0} + * 5963c: ea00000a b 0x5966c + * 59640: ee064f12 mcr 15, 0, r4, cr6, cr2, {0} + * 59644: ea000008 b 0x5966c + * 59648: ee064f13 mcr 15, 0, r4, cr6, cr3, {0} + * 5964c: ea000006 b 0x5966c + * 59650: ee064f14 mcr 15, 0, r4, cr6, cr4, {0} + * 59654: ea000004 b 0x5966c + * 59658: ee064f15 mcr 15, 0, r4, cr6, cr5, {0} + * 5965c: ea000002 b 0x5966c + * 59660: ee064f16 mcr 15, 0, r4, cr6, cr6, {0} + * 59664: ea000000 b 0x5966c + * 59668: ee064f17 mcr 15, 0, r4, cr6, cr7, {0} + * 5966c: e3a00000 mov r0, #0 ; 0x0 + * 59670: e8bd00f0 pop {r4, r5, r6, r7} + * 59674: e1a0f00e mov r15, r14 + * 59678: e3e00000 mvn r0, #0 ; 0x0 + * 5967c: e8bd00f0 pop {r4, r5, r6, r7} + * 59680: e1a0f00e mov r15, r14 * 59684: e92d43f8 push {r3, r4, r5, r6, r7, r8, r9, r14} * 59688: eb000000 bl 0x59690 * 5968c: e8bd83f8 pop {r3, r4, r5, r6, r7, r8, r9, r15} @@ -322,3 +431,364 @@ * 59b7c: 14000410 strne r0, [r0], #-1040 * 59b80: 46335053 undefined */ + +void fn_59788(const char *fname) +{ + fprintf(stderr,"%s: error extracting...\n", fname); + exit(1); +} + +struct s_59b78 { + unsigned char *start; /* 0 */ + unsigned char *stop; /* 4 */ + unsigned char y; /* 8 */ + unsigned char x; /* 9 */ +}; + +unsigned char fn_597c8(struct s_59b78 *r6_data) +{ + unsigned char *r0; + unsigned char *r1; + unsigned char r5; + + r5 = 0; + + r0 = r6_data->start; + r1 = r6_data->stop; + + if (r1 < r0) + fn_59788(__func__); + + r5 = *r0; + r0++; + r6_data->start = r0; + + return r5; +} + +unsigned int fn_59848(struct s_59b78 *r6_data) +{ + unsigned char r1; + unsigned char r2; + unsigned int r5; + + r1 = r6_data->y; + if (r1 == 0x80) { + r6_data->x = fn_597c8(r6_data); + } + r1 = r6_data->y; + r2 = r6_data->x; + r1 = r1 & r2; + r5 = r1 & 0xff; + + r1 = r6_data->y; + r1 = r1 >> 1; + r6_data->y = r1; + if (r1 == 0) { + r1 = 0x80; + r6_data->y = r1; + } + + if (r5 == 0) + return 0; + + return 1; +} + +unsigned int fn_598b4(struct s_59b78 *r11_data, unsigned int r10_arg2) +{ + unsigned int r1; + unsigned int r2; + unsigned int r6; + unsigned int r7; + + r1 = r10_arg2 - 1; + r6 = 1 << r1; + + r7 = 0; + while (r6 != 0) { + r1 = r11_data->y; + if (r1 == 0x80) { + r1 = fn_597c8(r11_data); + r11_data->x = r1; + } + r1 = r11_data->y; + r2 = r11_data->x; + r1 = r1 & r2; + if (r1 != 0) + r7 = r7 | r6; + + r6 = r6 >> 1; + + r2 = r11_data->y; + r2 = r2 >> 1; + r11_data->y = r2; + + r1 = r11_data->y; + if(r1 == 0) { + r11_data->y = 0x80; + } + } + + return r7; +} + +void fn_5980c(unsigned int arg1, unsigned int mem[]) +{ + unsigned char *r1; + unsigned char *r2; + + r1 = (unsigned char*)mem[0]; + r2 = (unsigned char*)mem[1]; + + if (r1 > r2) { + printf("r1: 0x%08x, r2: 0x%08x\n", (unsigned int)r1, (unsigned int)r2); + fn_59788(__func__); + } + + *r1 = arg1 & 0xff; + + r1++; + mem[0] = (unsigned int)r1; +} + +void fn_5993c(struct s_59b78 *r10_data, unsigned int r13_mem[]) +{ + unsigned int r5; + unsigned int r2; + unsigned char r4; + unsigned int r6; + unsigned int r7; + unsigned int r11; + unsigned char arr_59b64[2048]; + + r5 = 1; + + while (1) { + while (1) { + r2 = fn_59848(r10_data); + if (r2 == 0) + break; + + r2 = fn_598b4(r10_data, 8) & 0xff; + r4 = r2; + + fn_5980c(r4, r13_mem); + arr_59b64[r5] = r4 & 0xff; + r2 = r5 + 1; + r2 = r2 << 22; + r2 = r2 >> 22; + r5 = r2; + } + + r11 = fn_598b4(r10_data, 0x0a); + if(r11 == 0) + return; + + r2 = fn_598b4(r10_data, 0x04); + r7 = r2 + 1; + r6 = 0; + while (r6 <= r7) { + r2 = r6 + r11; + r2 = r2 << 22; + r2 = r2 >> 22; + r4 = arr_59b64[r2]; + fn_5980c(r4, r13_mem); + arr_59b64[r5] = r4; + r2 = r5 + 1; + r2 = r2 << 22; + r2 = r2 >> 22; + r5 = r2; + r6++; + } + } +} + +unsigned int crc_check_59684(unsigned char *arg1, unsigned int arg2, unsigned int magic) +{ + unsigned int r3; + unsigned int r4; + unsigned int r5; + +#if 0 + if (r0 < 0xc0000000) + return 1; +#endif + + /* ??? */ + r4 = *((unsigned int*)arg1 + 0x20); + r5 = *((unsigned int*)arg1 + 0x24); + + printf("magic: 0x%08x <-> 0x%08x\n", r5, magic); + if (r5 != magic) + return 2; + + if (arg2 >= r4) + r5 = 0; + else + return 3; + + r5 = ~rsb_crc(~0x00, arg1, r4); + r3 = *((unsigned int*)(arg1 + r4)); + printf("Checksums: 0x%02x <-> 0x%02x\n", r5, r3); + + if (r3 == r5) + return 0; + + return 4; +} + +void mkdir_p(char *dir) +{ + char *copy, *parent; + + if ((dir == NULL) || (!strcmp(dir, "."))) + return; + + if ((copy = strdup(dir)) == NULL) { + perror("strdup"); + exit(1); + } + parent = dirname(copy); + mkdir_p(parent); + + errno = 0; + if (mkdir(dir, 0755) == -1) { + if (errno != EEXIST) { + fprintf(stderr, "%s: ", dir); + perror("mkdir"); + exit(1); + } + } + free(copy); +} + +void write_file(char *fname, unsigned char *buf, int len) +{ + char filename[PATH_MAX]; + char *filename_c, *dirn; + int fd; + int remaining; + int ret; + + strcpy(filename, "extracted/"); + strcat(filename, fname); + + if ((filename_c = strdup(filename)) == NULL) { + perror("strdup"); + exit(1); + } + dirn = dirname(filename_c); + mkdir_p(dirn); + free(filename_c); + + if ((fd = open(filename, O_WRONLY|O_CREAT, 0644)) == -1) { + fprintf(stderr, "%s: ", filename); + perror("open"); + exit(1); + } + + remaining = len; + + while(remaining) { + ret = write(fd, buf + (len - remaining), remaining); + if (ret < 0) { + perror("write"); + exit(1); + } + remaining -= ret; + } + + printf(", %s written.\n", filename); + + close(fd); +} + +void extract_lz_file(unsigned char *buf, unsigned char *name) +{ + unsigned char *r3; + unsigned int r5; + unsigned char *r7 = NULL; /* Arg1, mem start */ + unsigned char *r10 = NULL; /* Arg2, mem end */ + unsigned char *r11 = buf; /* Arg3 */ + struct s_59b78 struct1; + unsigned int arr_59b7c[1024]; + + if (*((unsigned int*)r11) != LZ_MAGIC) + fn_59788(__func__); + + r3 = r11 + 4; + r5 = *((unsigned int*)r3); + printf(", length: %d", r5); + + if ((r7 = malloc(r5)) == NULL) { + perror("malloc"); + exit(1); + } + r10 = r7 + r5; + bzero(r7, r5); + + r3 = r7 + r5; + if (r3 > r10) + fn_59788(__func__); + + struct1.start = r11 + 8; + struct1.stop = r5 + r11; + struct1.x = 0; + struct1.y = 0x80; + + arr_59b7c[0] = (unsigned int)r7; + arr_59b7c[1] = (unsigned int)(r5 + r7); + + fn_5993c(&struct1, arr_59b7c); + +#if 0 + /* This seems to still be completely broken */ + r3 = r7 + 0x20; + r5 = *((unsigned int*)r3); + + if ((ret = crc_check_59684(r7, r5, 0x46335053)) != 0) { + printf("crc_check return: %d\n", ret); + fn_59788(__func__); + } +#endif + + write_file((char*)name, r7, r5); + + free(r7); +} + +void search_lz_sections(unsigned char *fw, int len) +{ + int i; + unsigned char *j; + + for(i = 0; i < len - 4; i++) { + if (*((unsigned int*)(fw+i)) == LZ_MAGIC) { + j = fw + i - 1; + printf("0x%02x: ", i); + j--; + while (j > fw) { + if (!strncmp("SP3", (char*)j, 3)) { + unsigned char fname[5]; + + bzero(fname, sizeof(fname)); + memcpy(fname, j, 4); + printf("Firmware found: %s", fname); + extract_lz_file(fw + i, fname); + break; + } + if (*j == 0x00) { + if ((*(j+1) != '/')) { + printf("ignoring...\n"); + break; + } + printf("%s", j+1); + extract_lz_file(fw + i, j+1); + break; + } + j--; + } + } + } +}