Files
2026-09-30 22:48:06 +02:00

79 lines
3.7 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# SPI flash dumping (CH341a)
Required once: backs up the bootloader/app (`IC300`) and factory data (`IC301`)
before any modding, and produced the dumps every finding here rests on. Dumps
stay local — never commit or publish them (vendor IP; `.gitignore` blocks
`*.bin`). Involved enough to deserve its own page; checklist version in
`RE-PROCESS.md` §1.
## 0. What you need
- Black CH341a Mini Programmer (v1612-class flow below; others similar),
SOIC-8 clip, multimeter, a Linux host with `flashrom`.
- Target: core module, `IC300` (boot+app) + `IC301` (data), both `MX25L12833F`.
## 1. Identify the chips
Factory stickers cover the markings — peel carefully, photograph first.
Confirm SOIC-8 pin 1 (dot/dimple, lower-left on both packages below) and probe
`VCC`/`GND` powered on (`VCC` = 3.3 V on this board). The exact part name
matters for `flashrom -c`.
![IC300 + IC301, stickers removed — both MX25L12833F](photos/ic300-ic301-closeup.jpg)
## 2. Fix the programmer voltage (do not skip)
The black board's 3.3/5 V jumper only switches ZIF `VCC`. The CH341A chip itself
stays on 5 V USB, so `CS/MOSI/CLK` idle at ~5 V even in the 3.3 V position —
out of spec for 2.7–3.6 V flash (degrades/kills). Verify: plug in empty, meter
`GND → CS/MOSI/CLK`. If ~5 V, either do the 3.3 V mod (feed CH341 `VCC` pin 28
from the `AMS1117` 3.3 V output) or use a level-shifter adapter board. Re-meter:
all signals ~3.3 V before touching the device.
## 3. Select SPI mode
Two personalities: `1a86:5523` + `ttyUSB0` = UART mode (useless here),
`1a86:5512` = SPI mode (`flashrom` needs this). Move the P/SPI jumper, replug,
confirm with `dmesg` (`New USB device found, idVendor=1a86, idProduct=5512`).
## 4. Permissions and containers
- `Couldn't open device … errno=13` = permissions. Test with `sudo`; make it
permanent with a udev rule for `1a86:5512` (`MODE="0666"`) +
`udevadm control --reload-rules && udevadm trigger`.
- `sudo` inside distrobox/toolbox is **not** host root for USB. Run on the host:
`distrobox-host-exec sudo flashrom …` (or `flatpak-spawn --host …`); podman /
docker need `--privileged -v /dev/bus/usb:/dev/bus/usb`.
## 5. Dump (read-only)
1. Device fully unpowered. Hold the SoC in reset if clipping in-circuit (avoids
bus contention with the C6748 driving SPI); `WP`/`HOLD` pulled high.
2. Seat the SOIC-8 clip on pin 1 → pin 1. A slipped clip shorts rails — reseat,
don't force.
3. Per chip, read **twice** to scratch files, then keep the verified copy as
the canonical dump:
`flashrom -p ch341a_spi -c <exact-chip-name> -r ic300_a.bin` (then `_b`).
4. `sha256sum ic300_*.bin; cmp ic300_a.bin ic300_b.bin` — must be identical;
expect exactly 16,777,216 B per MX25L12833F. Third read on any mismatch.
Then save one verified copy as `ic300.bin` (`ic301.bin` for the other chip).
Canonical names everywhere: `ic300.bin` / `ic301.bin`.
5. Never `-w`/`-E` (write/erase) during backup. Writing is only for recovery
with a verified dump in hand.
## 6. Sanity-check the dumps
- IC300 starts `54 49 50 41` (`TIPA` = AIS `0x41504954`), entropy ~6.9.
- IC301 starts `AILS`, pattern names in clear, `RIFF/WAVE`s from `0x8007E0`.
- `onlySD == 0` string-set test vs the running firmware version
(see `RE-PROCESS.md` §2) confirms which release is flashed.
## Troubleshooting
| Symptom | Cause → fix |
|---|---|
| `1a86:5523`, `ttyUSB0` | UART mode → move mode jumper, replug |
| `Couldn't open … errno=13` (even with sudo in container) | USB not passed through → run on host (§4) |
| `FF…`/`00…` reads, JEDEC ID unknown | Clip seating / wrong `-c` name / chip still powered by board → reseat, hold reset, re-probe `VCC` |
| Signals meter ~5 V | Unmodded black CH341a → §2 before retrying |