Files
Dejvino 1eb6ba6b9f Review must-fix: LICENSE, dangling ref, obsolete markers
- LICENSE (MIT, own work) + README license section
- FINDINGS.md per-version notes point into docs/firmware/
- checksum brute-forcers marked superseded (code + tool docs)
2026-09-30 22:52:21 +02:00

68 lines
3.1 KiB
Markdown

# Lofi-12 XT custom firmware research
> **Disclaimer:** everything here is for educational and entertainment purposes
> only. Modifying firmware can brick your device, void your warranty, or worse.
> Use at your own risk — the authors take no responsibility for damaged units,
> lost projects, or voided warranties.
Reverse engineering + modding toolkit for the **Sonicware Lofi-12 XT**
(TI TMS320C6748: ARM9 + C674x DSP). Status: **SD-update checksum solved 3/3** —
custom `.bin` images can be forged and flashed with the stock updater, no
hardware mods needed.
## Layout
| Path | What |
|---|---|
| `FINDINGS.md` | Device knowledge library (hardware, flash map, formats, checksum, updater) |
| `RE-PROCESS.md` | How it was done: dumping, Ghidra lab, C6000 notes, cracking playbook |
| `rev-diff.md` | v1.1.156 → v1.2.179 → v1.5.205 firmware diff |
| `tweakability-report.md` | What mods are feasible, risk ladder |
| `tools/` | Stdlib-only Python: parse/pack/patch/verify SD images |
| `analysis/` | Function mapping, checksum solver + prover |
| `ghidra/` | Ghidra helpers (vtable CSV, section mapper, headless PyGhidra drivers) |
| `docs/` | `hardware.md`, `bootloader.md`, `firmware-update.md`,
`flash-dumping.md`, `firmware/v1.5.205.md`, own board photos |
| `docs/photos/` | Board + flash-chip photos (own work) |
| `docs/captures/` | Saleae Logic captures (`.sr`) |
## Quickstart (Level-0 mod)
You supply the stock `.bin` (official updates:
https://sonicware.jp/pages/downloads — see test vectors below) as `stock.bin`:
```bash
python3 tools/lofi_unpack.py stock.bin unpack/
python3 tools/lofi_pack.py unpack/ rebuilt.bin # must be byte-identical: cmp stock.bin rebuilt.bin
python3 tools/lofi_patch_string.py stock.bin mod.bin Threshold ThresholX
python3 tools/prove_checksum.py mod.bin # must print MATCH
```
Copy `mod.bin` to SD root as `Lofi-12 XT.bin`, hold PAD while powering on,
watch `SYSTEM UPDATE` on the OLED. Keep a stock SD for revert.
## Test vectors (verify your stock files first)
| Version | Size | SHA-256 | Entry | Sect |
|---|---|---|---|---|
| v1.1.156 | 1,595,605 | `617c3efe…1908ac5` (`617c3efea92399b0e3ed40890dd67a75013b0132059fa713076cae68a1908ac5`) | `C26C4820` | 7 |
| v1.2.179 | 1,606,197 | `30ea9eeb…616a212` (`30ea9eeb58cfeb2cddc68f1b15f65f2586d6956df27009eb9045ca78b616a212`) | `C26CA4C0` | 6 |
| v1.5.205 | 1,707,049 | `a8bffa65…198026` (`a8bffa65919c0a2d4ff2ce77d16301551af4d2964497b8804deed49ce4198026`) | `C2CD1AA0` | 7 |
`python3 tools/prove_checksum.py` must print `MATCH` for every stock image
(checksums `F58AF539 / DFF0D8C2 / B17C0857`).
## Safety + legal
- Mods here touch only the SYSTEM image on SD. The updater lives in separate SPI
flash, so a bad image fails safe back to `SYSTEM UPDATE`. Still: no guarantees,
flash at your own risk, keep the stock revert SD.
- **No vendor binaries or flash dumps are shipped in this repo** (Sonicware IP).
Bring your own `.bin` from an official update ZIP; distribute mods as scripts,
never as full images.
## License
MIT — see `LICENSE`. Covers the code, docs, and photos in this repo (own work
only); no vendor binaries are shipped.