I've attached 2x .pspec files I created for MPC555 (BA 1472k black oak) and MPC565 (BF/FG 1024k spanish oak).
These are just copies of the ppc 32bit big endian with memory blocks defined, which makes it quicker and easier to open and analyze new files.
These need to go into the ghidra install directory > Ghidra > Processors > PowerPC > data > languages folder.
You'll also need to edit the "ppc.ldefs" file in the same directory, and add them in there as well:
Code: Select all
<language processor="PowerPC"
endian="big"
size="32"
variant="MPC555"
version="1.6"
slafile="ppc_32_be.sla"
processorspec="ppc_32_mpc555.pspec"
manualindexfile="../manuals/PowerPC.idx"
id="PowerPC:BE:32:MPC555">
<description>NXP MPC555 32-bit big endian</description>
<compiler name="default" spec="ppc_32_be.cspec" id="default"/>
<external_name tool="gnu" name="powerpc:MPC5XX"/>
<external_name tool="IDA-PRO" name="ppc"/>
<external_name tool="DWARF.register.mapping.file" name="ppc.dwarf"/>
<external_name tool="qemu" name="qemu-ppc"/>
<external_name tool="qemu_system" name="qemu-system-ppc"/>
</language>
<language processor="PowerPC"
endian="big"
size="32"
variant="MPC565"
version="1.6"
slafile="ppc_32_be.sla"
processorspec="ppc_32_mpc565.pspec"
manualindexfile="../manuals/PowerPC.idx"
id="PowerPC:BE:32:MPC565">
<description>NXP MPC565 32-bit big endian</description>
<compiler name="default" spec="ppc_32_be.cspec" id="default"/>
<external_name tool="gnu" name="powerpc:MPC5XX"/>
<external_name tool="IDA-PRO" name="ppc"/>
<external_name tool="DWARF.register.mapping.file" name="ppc.dwarf"/>
<external_name tool="qemu" name="qemu-ppc"/>
<external_name tool="qemu_system" name="qemu-system-ppc"/>
</language>Once you've imported the binary, don't analyze the file yet. The first step is to find and set the r2/r13 TOC/SDA registers.
They're very easy to find:
- go to (press "G") address 10000. This is the start of the actual strategy contents. Everything before this is the bootloader and cannot be written over OBD.
- hit "D" to disassemble. You should see 4 instructions which are loading an address into the CTR register and branching to it.
- double click the branch instruction to follow it. About a dozen lines down you will see the r2/r13 register initialization, eg:
Code: Select all
00018e84 3c 40 00 0e lis r2,0xe
00018e88 38 42 76 a0 addi r2,r2,0x76a0 R2 = "0xE0000+0x76A0" = E76A0
00018e8c 3d a0 00 40 lis r13,0x40
00018e90 39 ad f0 00 subi r13,r13,0x1000 R13 = "0x40000-0x1000" = 0x3FF000
Set r2 and r13 to the values you found.
From there you're pretty much setup and ready to go.
Once thing I am not completely sure about is the memory layout for 1472k black oak (I've mainly been playing with spanish).
All the datasheets I can find indicate MPC555 has 448k of flash memory, obviously these have 1mb more. You'll find my pspec file above doesn't account for this.
You'll also see them referencing RAM addresses outside / above where the datasheet indicates RAM is.
Maybe someone else knows exactly how memory regions should be configured for 1472k black oak?