3.0 KiB
Lofi-12 XT custom firmware research
Disclaimer: everything here is for educational and entertainment purposes only. Modifying firmware can brick your device, void your warranty, or worse. Use at your own risk — the authors take no responsibility for damaged units, lost projects, or voided warranties.
Reverse engineering + modding toolkit for the Sonicware Lofi-12 XT
(TI TMS320C6748: ARM9 + C674x DSP). Status: SD-update checksum solved 3/3 —
custom .bin images can be forged and flashed with the stock updater, no
hardware mods needed.
Layout
| Path | What |
|---|---|
FINDINGS.md |
Device knowledge library (hardware, flash map, formats, checksum, updater) |
RE-PROCESS.md |
How it was done: dumping, Ghidra lab, C6000 notes, cracking playbook |
rev-diff.md |
v1.1.156 → v1.2.179 → v1.5.205 firmware diff |
tweakability-report.md |
What mods are feasible, risk ladder |
tools/ |
Stdlib-only Python: parse/pack/patch/verify SD images |
analysis/ |
Function mapping, checksum solver + prover |
ghidra/ |
Ghidra helpers (vtable CSV, section mapper, headless PyGhidra drivers) |
docs/ |
hardware.md, bootloader.md, firmware-update.md, |
flash-dumping.md, firmware/v1.5.205.md, own board photos |
|
docs/photos/ |
Board + flash-chip photos (own work) |
docs/captures/ |
Saleae Logic captures (.sr) |
Quickstart (Level-0 mod)
You supply the stock .bin (official updates:
https://sonicware.jp/pages/downloads — see test vectors below) as stock.bin:
python3 tools/lofi_unpack.py stock.bin unpack/
python3 tools/lofi_pack.py unpack/ rebuilt.bin # must be byte-identical: cmp stock.bin rebuilt.bin
python3 tools/lofi_patch_string.py stock.bin mod.bin Threshold ThresholX
python3 tools/prove_checksum.py mod.bin # must print MATCH
Copy mod.bin to SD root as Lofi-12 XT.bin, hold PAD while powering on,
watch SYSTEM UPDATE on the OLED. Keep a stock SD for revert.
Test vectors (verify your stock files first)
| Version | Size | SHA-256 | Entry | Sect |
|---|---|---|---|---|
| v1.1.156 | 1,595,605 | 617c3efe…1908ac5 (617c3efea92399b0e3ed40890dd67a75013b0132059fa713076cae68a1908ac5) |
C26C4820 |
7 |
| v1.2.179 | 1,606,197 | 30ea9eeb…616a212 (30ea9eeb58cfeb2cddc68f1b15f65f2586d6956df27009eb9045ca78b616a212) |
C26CA4C0 |
6 |
| v1.5.205 | 1,707,049 | a8bffa65…198026 (a8bffa65919c0a2d4ff2ce77d16301551af4d2964497b8804deed49ce4198026) |
C2CD1AA0 |
7 |
python3 tools/prove_checksum.py must print MATCH for every stock image
(checksums F58AF539 / DFF0D8C2 / B17C0857).
Safety + legal
- Mods here touch only the SYSTEM image on SD. The updater lives in separate SPI
flash, so a bad image fails safe back to
SYSTEM UPDATE. Still: no guarantees, flash at your own risk, keep the stock revert SD. - No vendor binaries or flash dumps are shipped in this repo (Sonicware IP).
Bring your own
.binfrom an official update ZIP; distribute mods as scripts, never as full images.