kur4o wrote: Mon Jul 08, 2024 4:03 pm
04colyZQ8 wrote: Mon Jul 08, 2024 2:27 pm
6D 40 F0 36 80 00 0E 00 0B 82 B5 7F 48 01 25 FF 70 05 BD 7F 08 00 00 41 05 B6
is this correct checksum is 05 B6 ??
and oe is the length of code? see bellow
B5 7F 48 01 25 FF 70 05 BD 7F 08 00 00 41
You got that correct, now it is time to test on bcm.
No dice I’m 99% sure my arm assembly code is perfect unless you cannot jump from ram to main flash for functions. Was interesting had to use a 32 bit pointer and bx instruction that I never used I typically would use bl for jump to function but that is only -+ 32mb and because we are running from ram which is along ways from the main flash bl doesn’t work!
Anyway the checksum I’m confident with now. But still not sure weather this is supposed to run in 4x instead of 1x
I was using a universal patcher master script with j-console to send the same code the factory uses .. unlock ae etc.. now when I send my mode 36 I get a neg message or no message?
Send 6d 40 f0 36 80……..
Get 6d f0 40 36 18 22 //bad
Should be 74, 73 of 78 if I recall
If I have the utility file to send my kernel and run it in the “program ..” it shows correct 74, 73, or 78 response!
I think this is because the utility file is going from 1x to 4x mode.
How can I do this with script in universal master?
Tried:
Mode:4x
That didn’t work.
I have noticed typically 6d instead of 6c is 4x.
Otherwise I need to hack the utility file to send 36 80, I tried for hours putting 80 where zeros where and never got if to work. So even though it’s giving good response codes on that app it doesn’t matter since I can’t do 36 80 only 36 00