General ARM7TDMI Information ARM CPU Overview ARM CPU Register Set ARM CPU Flags & Condition Field (cond) ARM CPU 26bit Memory Interface ARM CPU Exceptions ARM CPU Memory Alignments Further Information ARM Pseudo Instructions and Directives ARM CP15 System Control Coprocessor ARM CPU Instruction Cycle Times ARM CPU Versions ARM CPU Data Sheet |
ARM 32bit Opcodes (ARM Code) ARM Instruction Summary ARM Branch and Branch with Link (B, BL, BX, BLX, SWI, BKPT) ARM Data Processing (ALU) ARM Multiply and Multiply-Accumulate (MUL, MLA) ARM Special ARM9 Instructions (CLZ, QADD/QSUB) ARM PSR Transfer (MRS, MSR) ARM Memory: Single Data Transfer (LDR, STR, PLD) ARM Memory: Halfword, Doubleword, and Signed Data Transfer ARM Memory: Block Data Transfer (LDM, STM) ARM Memory: Single Data Swap (SWP) ARM Coprocessor (MRC/MCR, LDC/STC, CDP, MCRR/MRRC) |
ARM 16bit Opcodes (THUMB Code) When operating in THUMB state, cut-down 16bit opcodes are used. THUMB is supported on T-variants of ARMv4 and up, ie. ARMv4T, ARMv5T, etc. THUMB Instruction Summary THUMB Register Operations (ALU, BX) THUMB Memory Load/Store (LDR/STR) THUMB Memory Addressing (ADD PC/SP) THUMB Memory Multiple Load/Store (PUSH/POP and LDM/STM) THUMB Jumps and Calls |
| GBA Reference |
| GBA Technical Data |
ARM Mode ARM7TDMI 32bit RISC CPU, 16.78MHz, 32bit opcodes (GBA) THUMB Mode ARM7TDMI 32bit RISC CPU, 16.78MHz, 16bit opcodes (GBA) CGB Mode Z80/8080-style 8bit CPU, 4.2MHz or 8.4MHz (CGB compatibility) DMG Mode Z80/8080-style 8bit CPU, 4.2MHz (monochrome gameboy compatib.) |
BIOS ROM 16 KBytes Work RAM 288 KBytes (Fast 32K on-chip, plus Slow 256K on-board) VRAM 96 KBytes OAM 1 KByte (128 OBJs 3x16bit, 32 OBJ-Rotation/Scalings 4x16bit) Palette RAM 1 KByte (256 BG colors, 256 OBJ colors) |
Display 240x160 pixels (2.9 inch TFT color LCD display) BG layers 4 background layers BG types Tile/map based, or Bitmap based BG colors 256 colors, or 16 colors/16 palettes, or 32768 colors OBJ colors 256 colors, or 16 colors/16 palettes OBJ size 12 types (in range 8x8 up to 64x64 dots) OBJs/Screen max. 128 OBJs of any size (up to 64x64 dots each) OBJs/Line max. 128 OBJs of 8x8 dots size (under best circumstances) Priorities OBJ/OBJ: 0-127, OBJ/BG: 0-3, BG/BG: 0-3 Effects Rotation/Scaling, alpha blending, fade-in/out, mosaic, window Backlight GBA SP only (optionally by light on/off toggle button) |
Analogue 4 channel CGB compatible (3x square wave, 1x noise) Digital 2 DMA sound channels Output Built-in speaker (mono), or headphones socket (stereo) |
Gamepad 4 Direction Keys, 6 Buttons |
Serial Port Various transfer modes, 4-Player Link, Single Game Pak play |
GBA Game Pak max. 32MB ROM or flash ROM + max 64K SRAM CGB Game Pak max. 32KB ROM + 8KB SRAM (more memory requires banking) |
Size (mm) GBA: 145x81x25 - GBA SP: 82x82x24 (closed), 155x82x24 (stretch) |
Battery GBA GBA: 2x1.5V DC (AA), Life-time approx. 15 hours Battery SP GBA SP: Built-in rechargeable Lithium ion battery, 3.7V 600mAh External GBA: 3.3V DC 350mA - GBA SP: 5.2V DC 320mA |
---------------------------------------------------------------------------- |
____._____________...___.____
____/ : CARTRIDGE SIO : \____
| L _____________________ LED R |
| | | |
| _||_ | 2.9" TFT SCREEN | (A) |
| |_ _| | 240x160pix 61x40mm | (B) |
| || | NO BACKLIGHT | :::: |
| | | SPEAKR |
| STRT() |_____________________| :::: |
| SLCT() GAME BOY ADVANCE VOLUME |
|____ OFF-ON BATTERY 2xAA PHONES _==_|
\__.##.__________________,,___/
|
_______________________ _ | _____________________ | / / || || / / || 2.9" TFT SCREEN || / / || 240x160pix 61x40mm || / / || WITH BACKLIGHT || / / || || GBA SP SIDE VIEWS / / ||_____________________|| / / | GAME BOY ADVANCE SP | _____________________(_) |_______________________| |. . . . . . . .'.'. _| |_|________|________|_|_| |_CARTRIDGE_:_BATT._:_|_| <-- EXT1/EXT2 |L EXT1 EXT2 R| | (*) LEDSo _____________________ _ (VOL_||_ (A) o |_____________________(_) | |_ _| ,,,,,(B) | |. . . . . . . .'.'. _| | || ;SPK; | |_CARTRIDGE_:_BATT._:_|_| <-- EXT1/EXT2 | ''''' ON # _ _____________________ | SLCT STRT OFF# _____________________(_)_____________________| | CART. () () | |. . . . . . . .'.'. _| |_:___________________:_| |_CARTRIDGE_:_BATT._:_|_| <-- EXT1/EXT2 |
________________SIO_______________
| L __________________ R |
| | GBA-MICRO | |
| _||_ | 2.0" TFT SCREEN | (A)| +
||_ _| |240x160pix 42x28mm| (B) |VOL
| || | BACKLIGHT | | -
| |__________________| ... |
|___________SELECT__START__________|
PWR <--- CARTRIDGE SLOT ---> PHONES
|
_____________________________________
| _____________________ |
| | | |
| | 3" TFT SCREEN | |
| | 256x192pix 61x46mm | |
| | BACKLIGHT | |
| ::::: | Original NDS | ::::: |
| ::::: |_____________________| ::::: |
_| _ ______ _ |_ <-- gap between screens: 22mm
|L|_______| |________| |_| |_______|R| (equivalent to 90 pixels)
|_______ _____________________ _______|
| PWR | | | |SEL STA|
| _ | | 3" TFT SCREEN | | |
| _| |_ | | 256x192pix 61x46mm | | X |
||_ _|| | BACKLIGHT | | Y A |
| |_| | | TOUCH SCREEN | | B |
| | |_____________________| | |
|_______| NintendoDS |_______|
| MIC LEDS |
|_________________________________________|
VOL SLOT2(GBA) MIC/PHONES
|
_____________________________________
| _____________________ |
| | | |
| | 3" TFT SCREEN | |
| ... | 256x192pix 61x46mm | ... |
| ... | BACKLIGHT | ... |
| | NDS-LITE | |
| |_____________________| |
|___ _ _ _ _ _ _ _ _ _ _ _ _ _ _ ____| <-- gap between screens: 23mm
L| _ |_____________MIC____________|LEDS|R
| _ _____________________ |
| _| |_ | | X |
||_ _|| 3" TFT SCREEN | Y A |PWR
| |_| | 256x192pix 61x46mm | B |
| | BACKLIGHT | |
| | TOUCH SCREEN |oSTART |
| |_____________________|oSELECT|
|_____________________________________|
VOL SLOT2(GBA) MIC/PHONES
|
_____________________________________
| _____________________ |
| | | O o | <-- CAM (O) and LED (o)
| | 3.25" TFT SCREEN | | (on backside)
| | 256x192pix 66x50mm | |
| | BACKLIGHT | |
| __ | DSi | __ |
| (__) |_____________________| (__) |
|___ _ _ _ _ _ _ _ _ _ _ _ _ _ _ ____| <-- gap between screens: 23mm
L|LEDS|__________CAM__MIC_________| __ |R (88 pixels)
+ | _ _____________________ |
VOL| _| |_ | | X | <-- SD Card Slot
- ||_ _|| 3.25" TFT SCREEN | Y A |
| |_| | 256x192pix 66x50mm | B |
| | BACKLIGHT | |
| | TOUCH SCREEN |oSTART |
| POWERo|_____________________|oSELECT|
|_____________________________________|
MIC/PHONES
|
As DSi, but bigger case, and bigger 4.2" screens |
_____________________________________
| __________CAM____________ | <-- internal camera
| . | | . | (and two back cameras and LED
|. . .| x.xx" TFT SCREEN |. . .| on backside)
| . | 800x240pix XXxXXmm | . |
| | BACKLIGHT | .|
| | STEREOSCOPIC 3D | || <-- 3D slider
| |_________________________| '|
|___ _ _ _ _ _ _ _ _ _ _ _ _ _ _ ____| <-- gap between screens: XXmm
L| __ |___________________________| __o|R <-- Notify RGB LED (XX pix)
| .-. _____________________ |
VOL| ( ) | | X | <-- wifi LED
| '-' | x.xx" TFT SCREEN | Y A | <-- wifi Button
| _ | 320x240pix XXxXXmm | B |
| _| |_ | BACKLIGHT | |
SD||_ _|| TOUCH SCREEN | |
| |_| |_____________________| |
| SELECT HOME START oPOWER |
|_____________________________________|
PHONES LEDs (power/charge)
|
_________
L____------- -------____R
/ ___ \ / (Y) \Z
/ / O \ | (START) | (X)\ Z = Gameboy Player Menu
| \___/ \_______/ (A) | X or Y = Select button
|\ _ \ / (B) /|
| \___ _| |_ \ / ___ ___/ | optionally X/Y can be
| |\ |_ _| / \ / C \ /| | swapped with L/R (?)
| | \ |_| / \ \___/ / | |
| | \_____/ \_____/ | | analogue sticks = ?
\__/ \__/
|
_______ _______
/ Y \ / X \ Y/B = left bongo rear/front side
| . . . . |_| . . . . | X/A = right bongo rear/front side
| B |R| A | S = start/pause button
|\_______/|_|\_______/| R = microphone (triggers R button)
|\_______/|S|\_______/|
| |_| | (the X/Y inputs can be assigned to
|\_______/| |\_______/| GBA R/L inputs in GBA player setup)
\_______/ \_______/
|
| GBA Memory Map |
00000000-00003FFF BIOS - System ROM (16 KBytes) 00004000-01FFFFFF Not used 02000000-0203FFFF WRAM - On-board Work RAM (256 KBytes) 2 Wait 02040000-02FFFFFF Not used 03000000-03007FFF WRAM - On-chip Work RAM (32 KBytes) 03008000-03FFFFFF Not used 04000000-040003FE I/O Registers 04000400-04FFFFFF Not used |
05000000-050003FF BG/OBJ Palette RAM (1 Kbyte) 05000400-05FFFFFF Not used 06000000-06017FFF VRAM - Video RAM (96 KBytes) 06018000-06FFFFFF Not used 07000000-070003FF OAM - OBJ Attributes (1 Kbyte) 07000400-07FFFFFF Not used |
08000000-09FFFFFF Game Pak ROM/FlashROM (max 32MB) - Wait State 0 0A000000-0BFFFFFF Game Pak ROM/FlashROM (max 32MB) - Wait State 1 0C000000-0DFFFFFF Game Pak ROM/FlashROM (max 32MB) - Wait State 2 0E000000-0E00FFFF Game Pak SRAM (max 64 KBytes) - 8bit Bus width 0E010000-0FFFFFFF Not used |
10000000-FFFFFFFF Not used (upper 4bits of address bus unused) |
Region Bus Read Write Cycles BIOS ROM 32 8/16/32 - 1/1/1 Work RAM 32K 32 8/16/32 8/16/32 1/1/1 I/O 32 8/16/32 8/16/32 1/1/1 OAM 32 8/16/32 16/32 1/1/1 * Work RAM 256K 16 8/16/32 8/16/32 3/3/6 ** Palette RAM 16 8/16/32 16/32 1/1/2 * VRAM 16 8/16/32 16/32 1/1/2 * GamePak ROM 16 8/16/32 - 5/5/8 **/*** GamePak Flash 16 8/16/32 16/32 5/5/8 **/*** GamePak SRAM 8 8 8 5 ** |
* Plus 1 cycle if GBA accesses video memory at the same time. ** Default waitstate settings, see System Control chapter. *** Separate timings for sequential, and non-sequential accesses. One cycle equals approx. 59.59ns (ie. 16.78MHz clock). |
| GBA I/O Map |
4000000h 2 R/W DISPCNT LCD Control 4000002h 2 R/W - Undocumented - Green Swap 4000004h 2 R/W DISPSTAT General LCD Status (STAT,LYC) 4000006h 2 R VCOUNT Vertical Counter (LY) 4000008h 2 R/W BG0CNT BG0 Control 400000Ah 2 R/W BG1CNT BG1 Control 400000Ch 2 R/W BG2CNT BG2 Control 400000Eh 2 R/W BG3CNT BG3 Control 4000010h 2 W BG0HOFS BG0 X-Offset 4000012h 2 W BG0VOFS BG0 Y-Offset 4000014h 2 W BG1HOFS BG1 X-Offset 4000016h 2 W BG1VOFS BG1 Y-Offset 4000018h 2 W BG2HOFS BG2 X-Offset 400001Ah 2 W BG2VOFS BG2 Y-Offset 400001Ch 2 W BG3HOFS BG3 X-Offset 400001Eh 2 W BG3VOFS BG3 Y-Offset 4000020h 2 W BG2PA BG2 Rotation/Scaling Parameter A (dx) 4000022h 2 W BG2PB BG2 Rotation/Scaling Parameter B (dmx) 4000024h 2 W BG2PC BG2 Rotation/Scaling Parameter C (dy) 4000026h 2 W BG2PD BG2 Rotation/Scaling Parameter D (dmy) 4000028h 4 W BG2X BG2 Reference Point X-Coordinate 400002Ch 4 W BG2Y BG2 Reference Point Y-Coordinate 4000030h 2 W BG3PA BG3 Rotation/Scaling Parameter A (dx) 4000032h 2 W BG3PB BG3 Rotation/Scaling Parameter B (dmx) 4000034h 2 W BG3PC BG3 Rotation/Scaling Parameter C (dy) 4000036h 2 W BG3PD BG3 Rotation/Scaling Parameter D (dmy) 4000038h 4 W BG3X BG3 Reference Point X-Coordinate 400003Ch 4 W BG3Y BG3 Reference Point Y-Coordinate 4000040h 2 W WIN0H Window 0 Horizontal Dimensions 4000042h 2 W WIN1H Window 1 Horizontal Dimensions 4000044h 2 W WIN0V Window 0 Vertical Dimensions 4000046h 2 W WIN1V Window 1 Vertical Dimensions 4000048h 2 R/W WININ Inside of Window 0 and 1 400004Ah 2 R/W WINOUT Inside of OBJ Window & Outside of Windows 400004Ch 2 W MOSAIC Mosaic Size 400004Eh - - Not used 4000050h 2 R/W BLDCNT Color Special Effects Selection 4000052h 2 R/W BLDALPHA Alpha Blending Coefficients 4000054h 2 W BLDY Brightness (Fade-In/Out) Coefficient 4000056h - - Not used |
4000060h 2 R/W SOUND1CNT_L Channel 1 Sweep register (NR10) 4000062h 2 R/W SOUND1CNT_H Channel 1 Duty/Length/Envelope (NR11, NR12) 4000064h 2 R/W SOUND1CNT_X Channel 1 Frequency/Control (NR13, NR14) 4000066h - - Not used 4000068h 2 R/W SOUND2CNT_L Channel 2 Duty/Length/Envelope (NR21, NR22) 400006Ah - - Not used 400006Ch 2 R/W SOUND2CNT_H Channel 2 Frequency/Control (NR23, NR24) 400006Eh - - Not used 4000070h 2 R/W SOUND3CNT_L Channel 3 Stop/Wave RAM select (NR30) 4000072h 2 R/W SOUND3CNT_H Channel 3 Length/Volume (NR31, NR32) 4000074h 2 R/W SOUND3CNT_X Channel 3 Frequency/Control (NR33, NR34) 4000076h - - Not used 4000078h 2 R/W SOUND4CNT_L Channel 4 Length/Envelope (NR41, NR42) 400007Ah - - Not used 400007Ch 2 R/W SOUND4CNT_H Channel 4 Frequency/Control (NR43, NR44) 400007Eh - - Not used 4000080h 2 R/W SOUNDCNT_L Control Stereo/Volume/Enable (NR50, NR51) 4000082h 2 R/W SOUNDCNT_H Control Mixing/DMA Control 4000084h 2 R/W SOUNDCNT_X Control Sound on/off (NR52) 4000086h - - Not used 4000088h 2 BIOS SOUNDBIAS Sound PWM Control 400008Ah .. - - Not used 4000090h 2x10h R/W WAVE_RAM Channel 3 Wave Pattern RAM (2 banks!!) 40000A0h 4 W FIFO_A Channel A FIFO, Data 0-3 40000A4h 4 W FIFO_B Channel B FIFO, Data 0-3 40000A8h - - Not used |
40000B0h 4 W DMA0SAD DMA 0 Source Address 40000B4h 4 W DMA0DAD DMA 0 Destination Address 40000B8h 2 W DMA0CNT_L DMA 0 Word Count 40000BAh 2 R/W DMA0CNT_H DMA 0 Control 40000BCh 4 W DMA1SAD DMA 1 Source Address 40000C0h 4 W DMA1DAD DMA 1 Destination Address 40000C4h 2 W DMA1CNT_L DMA 1 Word Count 40000C6h 2 R/W DMA1CNT_H DMA 1 Control 40000C8h 4 W DMA2SAD DMA 2 Source Address 40000CCh 4 W DMA2DAD DMA 2 Destination Address 40000D0h 2 W DMA2CNT_L DMA 2 Word Count 40000D2h 2 R/W DMA2CNT_H DMA 2 Control 40000D4h 4 W DMA3SAD DMA 3 Source Address 40000D8h 4 W DMA3DAD DMA 3 Destination Address 40000DCh 2 W DMA3CNT_L DMA 3 Word Count 40000DEh 2 R/W DMA3CNT_H DMA 3 Control 40000E0h - - Not used |
4000100h 2 R/W TM0CNT_L Timer 0 Counter/Reload 4000102h 2 R/W TM0CNT_H Timer 0 Control 4000104h 2 R/W TM1CNT_L Timer 1 Counter/Reload 4000106h 2 R/W TM1CNT_H Timer 1 Control 4000108h 2 R/W TM2CNT_L Timer 2 Counter/Reload 400010Ah 2 R/W TM2CNT_H Timer 2 Control 400010Ch 2 R/W TM3CNT_L Timer 3 Counter/Reload 400010Eh 2 R/W TM3CNT_H Timer 3 Control 4000110h - - Not used |
4000120h 4 R/W SIODATA32 SIO Data (Normal-32bit Mode; shared with below) 4000120h 2 R/W SIOMULTI0 SIO Data 0 (Parent) (Multi-Player Mode) 4000122h 2 R/W SIOMULTI1 SIO Data 1 (1st Child) (Multi-Player Mode) 4000124h 2 R/W SIOMULTI2 SIO Data 2 (2nd Child) (Multi-Player Mode) 4000126h 2 R/W SIOMULTI3 SIO Data 3 (3rd Child) (Multi-Player Mode) 4000128h 2 R/W SIOCNT SIO Control Register 400012Ah 2 R/W SIOMLT_SEND SIO Data (Local of MultiPlayer; shared below) 400012Ah 2 R/W SIODATA8 SIO Data (Normal-8bit and UART Mode) 400012Ch - - Not used |
4000130h 2 R KEYINPUT Key Status 4000132h 2 R/W KEYCNT Key Interrupt Control |
4000134h 2 R/W RCNT SIO Mode Select/General Purpose Data 4000136h - - IR Ancient - Infrared Register (Prototypes only) 4000138h - - Not used 4000140h 2 R/W JOYCNT SIO JOY Bus Control 4000142h - - Not used 4000150h 4 R/W JOY_RECV SIO JOY Bus Receive Data 4000154h 4 R/W JOY_TRANS SIO JOY Bus Transmit Data 4000158h 2 R/? JOYSTAT SIO JOY Bus Receive Status 400015Ah - - Not used |
4000200h 2 R/W IE Interrupt Enable Register 4000202h 2 R/W IF Interrupt Request Flags / IRQ Acknowledge 4000204h 2 R/W WAITCNT Game Pak Waitstate Control 4000206h - - Not used 4000208h 2 R/W IME Interrupt Master Enable Register 400020Ah - - Not used 4000300h 1 R/W POSTFLG Undocumented - Post Boot Flag 4000301h 1 W HALTCNT Undocumented - Power Down Control 4000302h - - Not used 4000410h ? ? ? Undocumented - Purpose Unknown / Bug ??? 0FFh 4000411h - - Not used 4000800h 4 R/W ? Undocumented - Internal Memory Control (R/W) 4000804h - - Not used 4xx0800h 4 R/W ? Mirrors of 4000800h (repeated each 64K) 4700000h 4 W (3DS) Disable ARM7 bootrom overlay (3DS only) |
| GBA LCD Video Controller |
| LCD I/O Display Control |
Bit Expl. 0-2 BG Mode (0-5=Video Mode 0-5, 6-7=Prohibited) 3 Reserved / CGB Mode (0=GBA, 1=CGB; can be set only by BIOS opcodes) 4 Display Frame Select (0-1=Frame 0-1) (for BG Modes 4,5 only) 5 H-Blank Interval Free (1=Allow access to OAM during H-Blank) 6 OBJ Character VRAM Mapping (0=Two dimensional, 1=One dimensional) 7 Forced Blank (1=Allow FAST access to VRAM,Palette,OAM) 8 Screen Display BG0 (0=Off, 1=On) 9 Screen Display BG1 (0=Off, 1=On) 10 Screen Display BG2 (0=Off, 1=On) 11 Screen Display BG3 (0=Off, 1=On) 12 Screen Display OBJ (0=Off, 1=On) 13 Window 0 Display Flag (0=Off, 1=On) 14 Window 1 Display Flag (0=Off, 1=On) 15 OBJ Window Display Flag (0=Off, 1=On) |
Mode Rot/Scal Layers Size Tiles Colors Features 0 No 0123 256x256..512x515 1024 16/16..256/1 SFMABP 1 Mixed 012- (BG0,BG1 as above Mode 0, BG2 as below Mode 2) 2 Yes --23 128x128..1024x1024 256 256/1 S-MABP 3 Yes --2- 240x160 1 32768 --MABP 4 Yes --2- 240x160 2 256/1 --MABP 5 Yes --2- 160x128 2 32768 --MABP |
Bit Expl. 0 Green Swap (0=Normal, 1=Swap) 1-15 Not used |
| LCD I/O Interrupts and Status |
Bit Expl. 0 V-Blank flag (Read only) (1=VBlank) (set in line 160..226; not 227) 1 H-Blank flag (Read only) (1=HBlank) (toggled in all lines, 0..227) 2 V-Counter flag (Read only) (1=Match) (set in selected line) (R) 3 V-Blank IRQ Enable (1=Enable) (R/W) 4 H-Blank IRQ Enable (1=Enable) (R/W) 5 V-Counter IRQ Enable (1=Enable) (R/W) 6 Not used (0) / DSi: LCD Initialization Ready (0=Busy, 1=Ready) (R) 7 Not used (0) / NDS: MSB of V-Vcount Setting (LYC.Bit8) (0..262)(R/W) 8-15 V-Count Setting (LYC) (0..227) (R/W) |
Bit Expl. 0-7 Current Scanline (LY) (0..227) (R) 8 Not used (0) / NDS: MSB of Current Scanline (LY.Bit8) (0..262) (R) 9-15 Not Used (0) |
| LCD I/O BG Control |
Bit Expl. 0-1 BG Priority (0-3, 0=Highest) 2-3 Character Base Block (0-3, in units of 16 KBytes) (=BG Tile Data) 4-5 Not used (must be zero) (except in NDS mode: MSBs of char base) 6 Mosaic (0=Disable, 1=Enable) 7 Colors/Palettes (0=16/16, 1=256/1) 8-12 Screen Base Block (0-31, in units of 2 KBytes) (=BG Map Data) 13 BG0/BG1: Not used (except in NDS mode: Ext Palette Slot for BG0/BG1) 13 BG2/BG3: Display Area Overflow (0=Transparent, 1=Wraparound) 14-15 Screen Size (0-3) |
Value Text Mode Rotation/Scaling Mode 0 256x256 (2K) 128x128 (256 bytes) 1 512x256 (4K) 256x256 (1K) 2 256x512 (4K) 512x512 (4K) 3 512x512 (8K) 1024x1024 (16K) |
| LCD I/O BG Scrolling |
Bit Expl. 0-8 Offset (0-511) 9-15 Not used |
| LCD I/O BG Rotation/Scaling |
Bit Expl. 0-7 Fractional portion (8 bits) 8-26 Integer portion (19 bits) 27 Sign (1 bit) 28-31 Not used |
Bit Expl. 0-7 Fractional portion (8 bits) 8-14 Integer portion (7 bits) 15 Sign (1 bit) |
Rotation Center X and Y Coordinates (x0,y0) Rotation Angle (alpha) Magnification X and Y Values (xMag,yMag) |
A = Cos (alpha) / xMag ;distance moved in direction x, same line B = Sin (alpha) / xMag ;distance moved in direction x, next line C = Sin (alpha) / yMag ;distance moved in direction y, same line D = Cos (alpha) / yMag ;distance moved in direction y, next line |
x0,y0 Rotation Center x1,y1 Old Position of a pixel (before rotation/scaling) x2,y2 New position of above pixel (after rotation scaling) A,B,C,D BG2PA-BG2PD Parameters (as calculated above) |
x2 = A(x1-x0) + B(y1-y0) + x0 y2 = C(x1-x0) + D(y1-y0) + y0 |
| LCD I/O Window Feature |
Bit Expl. 0-7 X2, Rightmost coordinate of window, plus 1 8-15 X1, Leftmost coordinate of window |
Bit Expl. 0-7 Y2, Bottom-most coordinate of window, plus 1 8-15 Y1, Top-most coordinate of window |
Bit Expl. 0-3 Window 0 BG0-BG3 Enable Bits (0=No Display, 1=Display) 4 Window 0 OBJ Enable Bit (0=No Display, 1=Display) 5 Window 0 Color Special Effect (0=Disable, 1=Enable) 6-7 Not used 8-11 Window 1 BG0-BG3 Enable Bits (0=No Display, 1=Display) 12 Window 1 OBJ Enable Bit (0=No Display, 1=Display) 13 Window 1 Color Special Effect (0=Disable, 1=Enable) 14-15 Not used |
Bit Expl. 0-3 Outside BG0-BG3 Enable Bits (0=No Display, 1=Display) 4 Outside OBJ Enable Bit (0=No Display, 1=Display) 5 Outside Color Special Effect (0=Disable, 1=Enable) 6-7 Not used 8-11 OBJ Window BG0-BG3 Enable Bits (0=No Display, 1=Display) 12 OBJ Window OBJ Enable Bit (0=No Display, 1=Display) 13 OBJ Window Color Special Effect (0=Disable, 1=Enable) 14-15 Not used |
| LCD I/O Mosaic Function |
Bit Expl. 0-3 BG Mosaic H-Size (minus 1) 4-7 BG Mosaic V-Size (minus 1) 8-11 OBJ Mosaic H-Size (minus 1) 12-15 OBJ Mosaic V-Size (minus 1) 16-31 Not used |
| LCD I/O Color Special Effects |
Bit Expl.
0 BG0 1st Target Pixel (Background 0)
1 BG1 1st Target Pixel (Background 1)
2 BG2 1st Target Pixel (Background 2)
3 BG3 1st Target Pixel (Background 3)
4 OBJ 1st Target Pixel (Top-most OBJ pixel)
5 BD 1st Target Pixel (Backdrop)
6-7 Color Special Effect (0-3, see below)
0 = None (Special effects disabled)
1 = Alpha Blending (1st+2nd Target mixed)
2 = Brightness Increase (1st Target becomes whiter)
3 = Brightness Decrease (1st Target becomes blacker)
8 BG0 2nd Target Pixel (Background 0)
9 BG1 2nd Target Pixel (Background 1)
10 BG2 2nd Target Pixel (Background 2)
11 BG3 2nd Target Pixel (Background 3)
12 OBJ 2nd Target Pixel (Top-most OBJ pixel)
13 BD 2nd Target Pixel (Backdrop)
14-15 Not used
|
Bit Expl. 0-4 EVA Coefficient (1st Target) (0..16 = 0/16..16/16, 17..31=16/16) 5-7 Not used 8-12 EVB Coefficient (2nd Target) (0..16 = 0/16..16/16, 17..31=16/16) 13-15 Not used |
I = MIN ( 31, I1st*EVA + I2nd*EVB ) |
Bit Expl. 0-4 EVY Coefficient (Brightness) (0..16 = 0/16..16/16, 17..31=16/16) 5-31 Not used |
I = I1st + (31-I1st)*EVY ;For Brightness Increase I = I1st - (I1st)*EVY ;For Brightness Decrease |
| LCD VRAM Overview |
06000000-0600FFFF 64 KBytes shared for BG Map and Tiles 06010000-06017FFF 32 KBytes OBJ Tiles |
Item Depth Required Memory One Tile 4bit 20h bytes One Tile 8bit 40h bytes 1024 Tiles 4bit 8000h (32K) 1024 Tiles 8bit 10000h (64K) - excluding some bytes for BG map BG Map 32x32 800h (2K) BG Map 64x64 2000h (8K) |
Item Depth Required Memory One Tile 8bit 40h bytes 256 Tiles 8bit 4000h (16K) BG Map 16x16 100h bytes BG Map 128x128 4000h (16K) |
06000000-06013FFF 80 KBytes Frame 0 buffer (only 75K actually used) 06014000-06017FFF 16 KBytes OBJ Tiles |
06000000-06009FFF 40 KBytes Frame 0 buffer (only 37.5K used in Mode 4) 0600A000-06013FFF 40 KBytes Frame 1 buffer (only 37.5K used in Mode 4) 06014000-06017FFF 16 KBytes OBJ Tiles |
| LCD VRAM Character Data |
| LCD VRAM BG Screen Data Format (BG Map) |
Bit Expl.
0-9 Tile Number (0-1023) (a bit less in 256 color mode, because
there'd be otherwise no room for the bg map)
10 Horizontal Flip (0=Normal, 1=Mirrored)
11 Vertical Flip (0=Normal, 1=Mirrored)
12-15 Palette Number (0-15) (Not used in 256 color/1 palette mode)
|
Bit Expl. 0-7 Tile Number (0-255) |
| LCD VRAM Bitmap BG Modes |
Bit Expl. 0-4 Red Intensity (0-31) 5-9 Green Intensity (0-31) 10-14 Blue Intensity (0-31) 15 Not used in GBA Mode (in NDS Mode: Alpha=0=Transparent, Alpha=1=Normal) |
| LCD OBJ - Overview |
1210 (=304*4-6) If "H-Blank Interval Free" bit in DISPCNT register is 0 954 (=240*4-6) If "H-Blank Interval Free" bit in DISPCNT register is 1 |
Cycles per <n> Pixels OBJ Type OBJ Type Screen Pixel Range n*1 cycles Normal OBJs 8..64 pixels 10+n*2 cycles Rotation/Scaling OBJs 8..64 pixels (area clipped) 10+n*2 cycles Rotation/Scaling OBJs 16..128 pixels (double size) |
| LCD OBJ - OAM Attributes |
Bit Expl.
0-7 Y-Coordinate (0-255)
8 Rotation/Scaling Flag (0=Off, 1=On)
When Rotation/Scaling used (Attribute 0, bit 8 set):
9 Double-Size Flag (0=Normal, 1=Double)
When Rotation/Scaling not used (Attribute 0, bit 8 cleared):
9 OBJ Disable (0=Normal, 1=Not displayed)
10-11 OBJ Mode (0=Normal, 1=Semi-Transparent, 2=OBJ Window, 3=Prohibited)
12 OBJ Mosaic (0=Off, 1=On)
13 Colors/Palettes (0=16/16, 1=256/1)
14-15 OBJ Shape (0=Square,1=Horizontal,2=Vertical,3=Prohibited)
|
Bit Expl.
0-8 X-Coordinate (0-511)
When Rotation/Scaling used (Attribute 0, bit 8 set):
9-13 Rotation/Scaling Parameter Selection (0-31)
(Selects one of the 32 Rotation/Scaling Parameters that
can be defined in OAM, for details read next chapter.)
When Rotation/Scaling not used (Attribute 0, bit 8 cleared):
9-11 Not used
12 Horizontal Flip (0=Normal, 1=Mirrored)
13 Vertical Flip (0=Normal, 1=Mirrored)
14-15 OBJ Size (0..3, depends on OBJ Shape, see Attr 0)
Size Square Horizontal Vertical
0 8x8 16x8 8x16
1 16x16 32x8 8x32
2 32x32 32x16 16x32
3 64x64 64x32 32x64
|
Bit Expl. 0-9 Character Name (0-1023=Tile Number) 10-11 Priority relative to BG (0-3; 0=Highest) 12-15 Palette Number (0-15) (Not used in 256 color/1 palette mode) |
OBJ No. 0 with Priority relative to BG=1 ;hi OBJ prio, lo BG prio OBJ No. 1 with Priority relative to BG=0 ;lo OBJ prio, hi BG prio |
| LCD OBJ - OAM Rotation/Scaling Parameters |
1st Group - PA=07000006, PB=0700000E, PC=07000016, PD=0700001E 2nd Group - PA=07000026, PB=0700002E, PC=07000036, PD=0700003E etc. |
| LCD OBJ - VRAM Character (Tile) Mapping |
| LCD Color Palettes |
05000000-050001FF - BG Palette RAM (512 bytes, 256 colors) 05000200-050003FF - OBJ Palette RAM (512 bytes, 256 colors) |
Bit Expl. 0-4 Red Intensity (0-31) 5-9 Green Intensity (0-31) 10-14 Blue Intensity (0-31) 15 Not used |
| LCD Dimensions and Timings |
Visible 240 dots, 57.221 us, 960 cycles - 78% of h-time H-Blanking 68 dots, 16.212 us, 272 cycles - 22% of h-time Total 308 dots, 73.433 us, 1232 cycles - ca. 13.620 kHz |
Visible (*) 160 lines, 11.749 ms, 197120 cycles - 70% of v-time V-Blanking 68 lines, 4.994 ms, 83776 cycles - 30% of v-time Total 228 lines, 16.743 ms, 280896 cycles - ca. 59.737 Hz |
| GBA Sound Controller |
| GBA Sound Channel 1 - Tone & Sweep |
Bit Expl. 0-2 R/W Number of sweep shift (n=0-7) 3 R/W Sweep Frequency Direction (0=Increase, 1=Decrease) 4-6 R/W Sweep Time; units of 7.8ms (0-7, min=7.8ms, max=54.7ms) 7-15 - Not used |
X(t) = X(t-1) +/- X(t-1)/2^n |
Bit Expl. 0-5 W Sound length; units of (64-n)/256s (0-63) 6-7 R/W Wave Pattern Duty (0-3, see below) 8-10 R/W Envelope Step-Time; units of n/64s (1-7, 0=No Envelope) 11 R/W Envelope Direction (0=Decrease, 1=Increase) 12-15 R/W Initial Volume of envelope (1-15, 0=No Sound) |
0: 12.5% ( -_______-_______-_______ ) 1: 25% ( --______--______--______ ) 2: 50% ( ----____----____----____ ) (normal) 3: 75% ( ------__------__------__ ) |
Bit Expl. 0-10 W Frequency; 131072/(2048-n)Hz (0-2047) 11-13 - Not used 14 R/W Length Flag (1=Stop output when length in NR11 expires) 15 W Initial (1=Restart Sound) 16-31 - Not used |
| GBA Sound Channel 2 - Tone |
| GBA Sound Channel 3 - Wave Output |
Bit Expl. 0-4 - Not used 5 R/W Wave RAM Dimension (0=One bank/32 digits, 1=Two banks/64 digits) 6 R/W Wave RAM Bank Number (0-1, see below) 7 R/W Sound Channel 3 Off (0=Stop, 1=Playback) 8-15 - Not used |
Bit Expl. 0-7 W Sound length; units of (256-n)/256s (0-255) 8-12 - Not used. 13-14 R/W Sound Volume (0=Mute/Zero, 1=100%, 2=50%, 3=25%) 15 R/W Force Volume (0=Use above, 1=Force 75% regardless of above) |
Bit Expl. 0-10 W Sample Rate; 2097152/(2048-n) Hz (0-2047) 11-13 - Not used 14 R/W Length Flag (1=Stop output when length in NR31 expires) 15 W Initial (1=Restart Sound) 16-31 - Not used |
Wave RAM, single bank 32 digits Tone Frequency FFFFFFFFFFFFFFFF0000000000000000 65536/(2048-n) Hz FFFFFFFF00000000FFFFFFFF00000000 131072/(2048-n) Hz FFFF0000FFFF0000FFFF0000FFFF0000 262144/(2048-n) Hz FF00FF00FF00FF00FF00FF00FF00FF00 524288/(2048-n) Hz F0F0F0F0F0F0F0F0F0F0F0F0F0F0F0F0 1048576/(2048-n) Hz |
| GBA Sound Channel 4 - Noise |
Bit Expl. 0-5 W Sound length; units of (64-n)/256s (0-63) 6-7 - Not used 8-10 R/W Envelope Step-Time; units of n/64s (1-7, 0=No Envelope) 11 R/W Envelope Direction (0=Decrease, 1=Increase) 12-15 R/W Initial Volume of envelope (1-15, 0=No Sound) 16-31 - Not used |
Bit Expl. 0-2 R/W Dividing Ratio of Frequencies (r) 3 R/W Counter Step/Width (0=15 bits, 1=7 bits) 4-7 R/W Shift Clock Frequency (s) 8-13 - Not used 14 R/W Length Flag (1=Stop output when length in NR41 expires) 15 W Initial (1=Restart Sound) 16-31 - Not used |
7bit: X=X SHR 1, IF carry THEN Out=HIGH, X=X XOR 60h ELSE Out=LOW 15bit: X=X SHR 1, IF carry THEN Out=HIGH, X=X XOR 6000h ELSE Out=LOW |
| GBA Sound Channel A and B - DMA Sound |
If Timer overflows then
Move 8bit data from FIFO to sound circuit.
If FIFO contains only 4 x 32bits (16 bytes) then
Request more data per DMA
Receive 4 x 32bit (16 bytes) per DMA
Endif
Endif
|
| GBA Sound Control Registers |
Bit Expl. 0-2 R/W Sound 1-4 Master Volume RIGHT (0-7) 3 - Not used 4-6 R/W Sound 1-4 Master Volume LEFT (0-7) 7 - Not used 8-11 R/W Sound 1-4 Enable Flags RIGHT (each Bit 8-11, 0=Disable, 1=Enable) 12-15 R/W Sound 1-4 Enable Flags LEFT (each Bit 12-15, 0=Disable, 1=Enable) |
Bit Expl. 0-1 R/W Sound # 1-4 Volume (0=25%, 1=50%, 2=100%, 3=Prohibited) 2 R/W DMA Sound A Volume (0=50%, 1=100%) 3 R/W DMA Sound B Volume (0=50%, 1=100%) 4-7 - Not used 8 R/W DMA Sound A Enable RIGHT (0=Disable, 1=Enable) 9 R/W DMA Sound A Enable LEFT (0=Disable, 1=Enable) 10 R/W DMA Sound A Timer Select (0=Timer 0, 1=Timer 1) 11 W? DMA Sound A Reset FIFO (1=Reset) 12 R/W DMA Sound B Enable RIGHT (0=Disable, 1=Enable) 13 R/W DMA Sound B Enable LEFT (0=Disable, 1=Enable) 14 R/W DMA Sound B Timer Select (0=Timer 0, 1=Timer 1) 15 W? DMA Sound B Reset FIFO (1=Reset) |
Bit Expl. 0 R Sound 1 ON flag (Read Only) 1 R Sound 2 ON flag (Read Only) 2 R Sound 3 ON flag (Read Only) 3 R Sound 4 ON flag (Read Only) 4-6 - Not used 7 R/W PSG/FIFO Master Enable (0=Disable, 1=Enable) (Read/Write) 8-31 - Not used |
Bit Expl. 0 - Not used 1-9 R/W Bias Level (Default=100h, converting signed samples into unsigned) 10-13 - Not used 14-15 R/W Amplitude Resolution/Sampling Cycle (Default=0, see below) 16-31 - Not used |
0 9bit / 32.768kHz (Default, best for DMA channels A,B) 1 8bit / 65.536kHz 2 7bit / 131.072kHz 3 6bit / 262.144kHz (Best for PSG channels 1-4) |
| GBA Comparison of CGB and GBA Sound |
| GBA Timers |
Bit Expl. 0-1 Prescaler Selection (0=F/1, 1=F/64, 2=F/256, 3=F/1024) 2 Count-up Timing (0=Normal, 1=See below) ;Not used in TM0CNT_H 3-5 Not used 6 Timer IRQ Enable (0=Disable, 1=IRQ on Timer overflow) 7 Timer Start/Stop (0=Stop, 1=Operate) 8-15 Not used |
| GBA DMA Transfers |
Bit Expl.
0-4 Not used
5-6 Dest Addr Control (0=Increment,1=Decrement,2=Fixed,3=Increment/Reload)
7-8 Source Adr Control (0=Increment,1=Decrement,2=Fixed,3=Prohibited)
9 DMA Repeat (0=Off, 1=On) (Must be zero if Bit 11 set)
10 DMA Transfer Type (0=16bit, 1=32bit)
11 Game Pak DRQ - DMA3 only - (0=Normal, 1=DRQ <from> Game Pak, DMA3)
12-13 DMA Start Timing (0=Immediately, 1=VBlank, 2=HBlank, 3=Special)
The 'Special' setting (Start Timing=3) depends on the DMA channel:
DMA0=Prohibited, DMA1/DMA2=Sound FIFO, DMA3=Video Capture
14 IRQ upon end of Word Count (0=Disable, 1=Enable)
15 DMA Enable (0=Off, 1=On)
|
2N+2(n-1)S+xI |
| GBA Communication Ports |
| SIO Normal Mode |
Bit Expl. 0-3 Undocumented (current SC,SD,SI,SO state, as for General Purpose mode) 4-8 Not used (Should be 0, bits are read/write-able though) 9-13 Not used (Always 0, read only) 14 Not used (Should be 0, bit is read/write-able though) 15 Must be zero (0) for Normal/Multiplayer/UART modes |
Bit Expl. 0 Shift Clock (SC) (0=External, 1=Internal) 1 Internal Shift Clock (0=256KHz, 1=2MHz) 2 SI State (opponents SO) (0=Low, 1=High/None) --- (Read Only) 3 SO during inactivity (0=Low, 1=High) (applied ONLY when Bit7=0) 4-6 Not used (Read only, always 0 ?) 7 Start Bit (0=Inactive/Ready, 1=Start/Active) 8-11 Not used (R/W, should be 0) 12 Transfer Length (0=8bit, 1=32bit) 13 Must be "0" for Normal Mode 14 IRQ Enable (0=Disable, 1=Want IRQ upon completion) 15 Not used (Read only, always 0) |
(Expl. Old SO=LOW kept output until 1st clock bit received). (Expl. New SO=HIGH is automatically output at transfer completion). |
Step Sender 1st Recipient 2nd Recipient Transfer 1: DATA #0 --> UNDEF --> UNDEF --> Transfer 2: DATA #1 --> DATA #0 --> UNDEF --> Transfer 3: DATA #2 --> DATA #1 --> DATA #0 --> Transfer 4: DATA #3 --> DATA #2 --> DATA #1 --> |
| SIO Multi-Player Mode |
Bit Expl. 0-3 Undocumented (current SC,SD,SI,SO state, as for General Purpose mode) 4-8 Not used (Should be 0, bits are read/write-able though) 9-13 Not used (Always 0, read only) 14 Not used (Should be 0, bit is read/write-able though) 15 Must be zero (0) for Normal/Multiplayer/UART modes |
Bit Expl. 0-1 Baud Rate (0-3: 9600,38400,57600,115200 bps) 2 SI-Terminal (0=Parent, 1=Child) (Read Only) 3 SD-Terminal (0=Bad connection, 1=All GBAs Ready) (Read Only) 4-5 Multi-Player ID (0=Parent, 1-3=1st-3rd child) (Read Only) 6 Multi-Player Error (0=Normal, 1=Error) (Read Only) 7 Start/Busy Bit (0=Inactive, 1=Start/Busy) (Read Only for Slaves) 8-11 Not used (R/W, should be 0) 12 Must be "0" for Multi-Player mode 13 Must be "1" for Multi-Player mode 14 IRQ Enable (0=Disable, 1=Want IRQ upon completion) 15 Not used (Read only, always 0) |
GBAs Bits Delays Timeout 1 18 None Yes 2 36 1 Yes 3 54 2 Yes 4 72 3 None |
| SIO UART Mode |
Bit Expl. 0-3 Undocumented (current SC,SD,SI,SO state, as for General Purpose mode) 4-8 Not used (Should be 0, bits are read/write-able though) 9-13 Not used (Always 0, read only) 14 Not used (Should be 0, bit is read/write-able though) 15 Must be zero (0) for Normal/Multiplayer/UART modes |
Bit Expl. 0-1 Baud Rate (0-3: 9600,38400,57600,115200 bps) 2 CTS Flag (0=Send always/blindly, 1=Send only when SC=LOW) 3 Parity Control (0=Even, 1=Odd) 4 Send Data Flag (0=Not Full, 1=Full) (Read Only) 5 Receive Data Flag (0=Not Empty, 1=Empty) (Read Only) 6 Error Flag (0=No Error, 1=Error) (Read Only) 7 Data Length (0=7bits, 1=8bits) 8 FIFO Enable Flag (0=Disable, 1=Enable) 9 Parity Enable Flag (0=Disable, 1=Enable) 10 Send Enable Flag (0=Disable, 1=Enable) 11 Receive Enable Flag (0=Disable, 1=Enable) 12 Must be "1" for UART mode 13 Must be "1" for UART mode 14 IRQ Enable (0=Disable, 1=IRQ when any Bit 4/5/6 become set) 15 Not used (Read only, always 0) |
| SIO JOY BUS Mode |
Bit Expl. 0-3 Undocumented (current SC,SD,SI,SO state, as for General Purpose mode) 4-8 Not used (Should be 0, bits are read/write-able though) 9-13 Not used (Always 0, read only) 14 Must be "1" for JOY BUS Mode 15 Must be "1" for JOY BUS Mode |
Bit Expl. 0 Device Reset Flag (Command FFh) (Read/Acknowledge) 1 Receive Complete Flag (Command 14h or 15h?) (Read/Acknowledge) 2 Send Complete Flag (Command 15h or 14h?) (Read/Acknowledge) 3-5 Not used 6 IRQ when receiving a Device Reset Command (0=Disable, 1=Enable) 7-31 Not used |
Bit Expl. 0 Not used 1 Receive Status Flag (0=Remote Side is/was receiving) (Read Only?) 2 Not used 3 Send Status Flag (1=Remote Side is/was sending) (Read Only?) 4-5 General Purpose Flag (Not assigned, may be used for whatever purpose) 6-31 Not used |
Receive FFh (Command) Send 00h (GBA Type number LSB) Send 04h (GBA Type number MSB) Send XXh (lower 8bits of JOYSTAT register) |
Receive 00h (Command) Send 00h (GBA Type number LSB) Send 04h (GBA Type number MSB) Send XXh (lower 8bits of JOYSTAT register) |
Receive 15h (Command) Receive XXh (Lower 8bits of JOY_RECV_L) Receive XXh (Upper 8bits of JOY_RECV_L) Receive XXh (Lower 8bits of JOY_RECV_H) Receive XXh (Upper 8bits of JOY_RECV_H) Send XXh (lower 8bits of JOYSTAT register) |
Receive 14h (Command) Send XXh (Lower 8bits of JOY_TRANS_L) Send XXh (Upper 8bits of JOY_TRANS_L) Send XXh (Lower 8bits of JOY_TRANS_H) Send XXh (Upper 8bits of JOY_TRANS_H) Send XXh (lower 8bits of JOYSTAT register) |
| SIO General-Purpose Mode |
Bit Expl. 0 SC Data Bit (0=Low, 1=High) 1 SD Data Bit (0=Low, 1=High) 2 SI Data Bit (0=Low, 1=High) 3 SO Data Bit (0=Low, 1=High) 4 SC Direction (0=Input, 1=Output) 5 SD Direction (0=Input, 1=Output) 6 SI Direction (0=Input, 1=Output, but see below) 7 SO Direction (0=Input, 1=Output) 8 SI Interrupt Enable (0=Disable, 1=Enable) 9-13 Not used 14 Must be "0" for General-Purpose Mode 15 Must be "1" for General-Purpose or JOYBUS Mode |
| SIO Control Registers Summary |
R.15 R.14 S.13 S.12 Mode 0 x 0 0 Normal 8bit 0 x 0 1 Normal 32bit 0 x 1 0 Multiplay 16bit 0 x 1 1 UART (RS232) 1 0 x x General Purpose 1 1 x x JOY BUS |
Bit 0 1 2 3 4 5 6 7 8 9 10 11 Normal Master Rate SI/In SO/Out - - - Start - - - - Multi Baud Baud SI/In SD/In ID# Err Start - - - - UART Baud Baud CTS Parity S R Err Bits FIFO Parity Send Recv |
| GBA Wireless Adapter |
| GBA Wireless Adapter Games |
bit Generations series (Japan only) Boktai 2: Solar Boy Django (Konami) Boktai 3: Sabata's Counterattack Classic NES Series: Donkey Kong Classic NES Series: Dr. Mario Classic NES Series: Ice Climber Classic NES Series: Pac-Man Classic NES Series: Super Mario Bros. Classic NES Series: Xevious Digimon Racing (Bandai) (No Wireless Adapter support in European release) Dragon Ball Z: Buu's Fury (Atari) Famicom Mini Series: #13 Balloon Fight Famicom Mini Series: #12 Clu Clu Land Famicom Mini Series: #16 Dig Dug Famicom Mini Series: #02 Donkey Kong Famicom Mini Series: #15 Dr. Mario Famicom Mini Series: #03 Ice Climber Famicom Mini Series: #18 Makaimura Famicom Mini Series: #08 Mappy Famicom Mini Series: #11 Mario Bros. Famicom Mini Series: #06 Pac-Man Famicom Mini Series: #30 SD Gundam World Scramble Wars Famicom Mini Series: #01 Super Mario Bros. Famicom Mini Series: #21 Super Mario Bros. Famicom Mini Series: #19 Twin Bee Famicom Mini Series: #14 Wrecking Crew Famicom Mini Series: #07 Xevious Hamtaro: Ham-Ham Games (Nintendo) Lord of the Rings: The Third Age, The (EA Games) Mario Golf: Advance Tour (Nintendo) Mario Tennis: Power Tour (Nintendo) Mega Man Battle Network 5: Team Protoman (Capcom) Mega Man Battle Network 5: Team Colonel (Capcom) Mega Man Battle Network 6: Cybeast Falzar Mega Man Battle Network 6: Cybeast Gregar Momotaro Dentetsu G: Make a Gold Deck! (Japan only) Pokemon Emerald (Nintendo) Pokemon FireRed (Nintendo) Pokemon LeafGreen (Nintendo) Sennen Kazoku (Japan only) Shrek SuperSlam Sonic Advance 3 |
| GBA Wireless Adapter Login |
rcnt=8000h ;\ rcnt=80A0h ; rcnt=80A2h ; reset adapter or so wait ; rcnt=80A0h ;/ siocnt=5003h ;\set 32bit normal mode, 2MHz internal clock rcnt=0000h ;/ passes=0, index=0 @@lop: passes=passes+1, if passes>32 then ERROR ;give up (usually only 10 passses) recv.lo=siodata AND FFFFh ;response from adapter recv.hi=siodata/10000h ;adapter's own "NI" data if send.hi<>recv.lo then index=0, goto @@stuck ;<-- fallback to index=0 if (send.lo XOR FFFFh)<>recv.lo then goto @@stuck if (send.hi XOR FFFFh)<>recv.hi then goto @@stuck index=index+1 @@stuck: send.lo=halfword[@@key_string+index*2] send.hi=recv.hi XOR FFFFh siodata=send.lo+(send.hi*10000h) siocnt.bit7=1 ;<-- start transmission if index<4 then goto @@lop ret @@key_string db 'NINTENDO',01h,80h ;10 bytes (5 halfwords; index=0..4) |
GBA ADAPTER
xxxx494E ;\ <--> xxxxxxxx
xxxx494E ; "NI" <--> "NI"/; 494EB6B1 ;\
NOT("NI") /; B6B1494E ;/ <--> \; 494EB6B1 ; NOT("NI")
\; B6B1544E ;\"NT" <--> "NT"/; 544EB6B1 ;/
NOT("NT") /; ABB1544E ;/ <--> \; 544EABB1 ;\NOT("NT")
\; ABB14E45 ;\"EN" <--> "EN"/; 4E45ABB1 ;/
NOT("EN") /; B1BA4E45 ;/ <--> \; 4E45B1BA ;\NOT("EN")
\; B1BA4F44 ;\"DO" <--> "DO"/; 4F44B1BA ;/
NOT("DO") /; B0BB4F44 ;/ <--> \; 4F44B0BB ;\NOT("DO")
\; B0BB8001 ;-fin <--> fin-; 8001B0BB ;/
\ \ \ \
\ LSBs=Own \ LSBs=Inverse of
\ Data.From.Gba \ Prev.Data.From.Gba
\ \
MSBs=Inverse of MSBs=Own
Prev.Data.From.Adapter Data.From.Adapter
|
| GBA Wireless Adapter Commands |
GBA Adapter 9966ppcch 80000000h ;-send command (cc), and num param_words (pp) <param01> 80000000h ;\ <param02> 80000000h ; send "pp" parameter word(s), if any ... ... ;/ 80000000h 9966rraah ;-recv ack (aa=cc+80h), and num response_words (rr) 80000000? <reply01> ;\ 80000000? <reply02> ; recv "rr" response word(s), if any ... ... ;/ |
wait until [4000128h].Bit2=0 ;want SI=0 set [4000128h].Bit3=1 ;set SO=1 wait until [4000128h].Bit2=1 ;want SI=1 set [4000128h].Bit3=0,Bit7=1 ;set SO=0 and start 32bit transfer |
Cmd Para Reply Name 10h - - Hello (send immediately after login) 11h - 1 Good/Bad response to cmd 16h ? 12h 13h - 1 14h 15h 16h 6 - Introduce (send game/user name) 17h 1 - Config (send after Hello) (eg. param=003C0420h or 003C043Ch) 18h 19h 1Ah 1Bh 1Ch - - 1Dh - NN Get Directory? (receive list of game/user names?) 1Eh - NN Get Directory? (receive list of game/user names?) 1Fh 1 - Select Game for Download (send 16bit Game_ID) |
20h - 1 21h - 1 Good/Bad response to cmd 1Fh ? 22h 23h 24h - - 25h ;use EXT clock! 26h - - 27h - - Begin Download ? ;use EXT clock! 28h 29h 2Ah 2Bh 2Ch 2Dh 2Eh 2Fh |
30h 1 - 31h 32h 33h 34h 35h ;use EXT clock! 36h 37h ;use EXT clock! 38h 39h 3Ah 3Bh 3Ch 3Dh - - Bye (return to language select) 3Eh 3Fh |
| GBA Wireless Adapter Component Lists |
U1 32pin Freescale MC13190 (2.4 GHz ISM band transceiver) U2 48pin Freescale CT3000 or CT3001 (depending on adapter version) X3 2pin 9.5MHz crystal |
Sticker on Case:
"GAME BOY advance, WIRELESS ADAPTER"
"Pat.Pend.Made in Philipines, CE0125(!)B"
"MODEL NO./MODELE NO.AGB-015 D-63760 Grossosteim P/AGB-A-WA-EUR-2 E3"
PCB: "19-C046-04, A-7" (top side) and "B-7" and Microchip ",\\" (bottom side)
PCB: white stamp "3104, 94V-0, RU, TW-15"
PCB: black stamp "22FDE"
U1 32pin "Freescale 13190, 4WFQ" (MC13190) (2.4 GHz ISM band transceiver)
U2 48pin "Freescale CT3001, XAC0445" (bottom side)
X3 2pin "D959L4I" (9.5MHz) (top side) (ca. 19 clks per 2us)
|
D1 5pin "D6F, 44" (top side, below X3) U71 6pin ".., () 2" (top side, right of X3, tiny black chip) B71 6pin "[]" (top side, right of X3, small white chip) ANT 2pin on-board copper wings Q? 3pin (top side, above CN1) Q? 3pin (top side, above CN1) D? 2pin "72" (top side, above CN1) D3 2pin "F2" (top side, above CN1) U200 4pin "MSV" (top side, above CN1) U202 5pin "LXKA" (top side, right of CN1) U203 4pin "M6H" (top side, right of CN1) CN1 6pin connector to GBA link port (top side) |
U201 5pin "LXVB" (bottom side, near CN1) U72 4pin "BMs" (bottom side, near ANT, tiny black chip) FL70 ?pin "[] o26" (bottom side, near ANT, bigger white chip) B70 6pin "[]" (bottom side, near ANT, small white chip) |
Sticker on Case: N/A PCB: "19-C046-03, A-1" (top side) and "B-1" and Microchip ",\\" (bottom side) PCB: white stamp "3204, TW-15, RU, 94V-0" PCB: black stamp "23MN" or "23NH" or so (smeared) U1 32pin "Freescale 13190, 4FGD" (top side) U2 48pin "Freescale CT3000, XAB0425" (bottom side) ;CT3000 (not CT3001) X3 2pin "9.5SKSS4GT" (top side) |
D1 5pin "D6F, 31" (top side, below X3) U71 6pin "P3, () 2" (top side, right of X3, tiny black chip) B71 6pin "[]" (top side, right of X3, small white chip) ANT 2pin on-board copper wings Q70 3pin (top side, above CN1) D? 2pin "72" (top side, above CN1) D3 2pin "F2" (top side, above CN1) U200 4pin "MSV" (top side, above CN1) U202 5pin "LXKH" (top side, right of CN1) U203 4pin "M6H" (top side, right of CN1) CN1 6pin connector to GBA link port (top side) |
U201 5pin "LXV2" (bottom side, near CN1) U70 6pin "AAG" (bottom side, near ANT, tiny black chip) FL70 ?pin "[] o26" (bottom side, near ANT, bigger white chip) B70 6pin "[]" (bottom side, near ANT, small white chip) |
Sticker "N/A" vs "Grossosteim P/AGB-A-WA-EUR-2 E3" PCB-markings "19-C046-03, A-1, 3204" vs "19-C046-04, A-7, 3104" U1 "CT3000, XAB0425" vs "CT3001, XAC0445" Transistors One transistor (Q70) vs Two transistors (both nameless) U70/U72 U70 "AAG" (6pin) vs U72 "BMs" (4pin) |
| GBA Infrared Communication |
Bit Expl. 0 Transmission Data (0=LED Off, 1=LED On) 1 READ Enable (0=Disable, 1=Enable) 2 Reception Data (0=None, 1=Signal received) (Read only) 3 AMP Operation (0=Off, 1=On) 4 IRQ Enable Flag (0=Disable, 1=Enable) 5-15 Not used |
| GBA Keypad Input |
Bit Expl. 0 Button A (0=Pressed, 1=Released) 1 Button B (etc.) 2 Select (etc.) 3 Start (etc.) 4 Right (etc.) 5 Left (etc.) 6 Up (etc.) 7 Down (etc.) 8 Button R (etc.) 9 Button L (etc.) 10-15 Not used |
Bit Expl. 0 Button A (0=Ignore, 1=Select) 1 Button B (etc.) 2 Select (etc.) 3 Start (etc.) 4 Right (etc.) 5 Left (etc.) 6 Up (etc.) 7 Down (etc.) 8 Button R (etc.) 9 Button L (etc.) 10-13 Not used 14 Button IRQ Enable (0=Disable, 1=Enable) 15 Button IRQ Condition (0=Logical OR, 1=Logical AND) |
| GBA Interrupt Control |
Bit Expl. 0 Disable all interrupts (0=Disable All, 1=See IE register) 1-31 Not used |
Bit Expl. 0 LCD V-Blank (0=Disable) 1 LCD H-Blank (etc.) 2 LCD V-Counter Match (etc.) 3 Timer 0 Overflow (etc.) 4 Timer 1 Overflow (etc.) 5 Timer 2 Overflow (etc.) 6 Timer 3 Overflow (etc.) 7 Serial Communication (etc.) 8 DMA 0 (etc.) 9 DMA 1 (etc.) 10 DMA 2 (etc.) 11 DMA 3 (etc.) 12 Keypad (etc.) 13 Game Pak (external IRQ source) (etc.) 14-15 Not used |
Bit Expl. 0 LCD V-Blank (1=Request Interrupt) 1 LCD H-Blank (etc.) 2 LCD V-Counter Match (etc.) 3 Timer 0 Overflow (etc.) 4 Timer 1 Overflow (etc.) 5 Timer 2 Overflow (etc.) 6 Timer 3 Overflow (etc.) 7 Serial Communication (etc.) 8 DMA 0 (etc.) 9 DMA 1 (etc.) 10 DMA 2 (etc.) 11 DMA 3 (etc.) 12 Keypad (etc.) 13 Game Pak (external IRQ source) (etc.) 14-15 Not used |
00000018 b 128h ;IRQ vector: jump to actual BIOS handler 00000128 stmfd r13!,r0-r3,r12,r14 ;save registers to SP_irq 0000012C mov r0,4000000h ;ptr+4 to 03FFFFFC (mirror of 03007FFC) 00000130 add r14,r15,0h ;retadr for USER handler $+8=138h 00000134 ldr r15,[r0,-4h] ;jump to [03FFFFFC] USER handler 00000138 ldmfd r13!,r0-r3,r12,r14 ;restore registers from SP_irq 0000013C subs r15,r14,4h ;return from IRQ (PC=LR-4, CPSR=SPSR) |
Addr. Size Expl. 3007FFCh 4 Pointer to user IRQ handler (32bit ARM code) 3007FF8h 2 Interrupt Check Flag (for IntrWait/VBlankIntrWait functions) 3007FF4h 4 Allocated Area 3007FF0h 4 Pointer to Sound Buffer 3007FE0h 16 Allocated Area 3007FA0h 64 Default area for SP_svc Supervisor Stack (4 words/time) 3007F00h 160 Default area for SP_irq Interrupt Stack (6 words/time) |
SP_svc=03007FE0h SP_irq=03007FA0h SP_usr=03007F00h |
| GBA System Control |
Bit Expl. 0-1 SRAM Wait Control (0..3 = 4,3,2,8 cycles) 2-3 Wait State 0 First Access (0..3 = 4,3,2,8 cycles) 4 Wait State 0 Second Access (0..1 = 2,1 cycles) 5-6 Wait State 1 First Access (0..3 = 4,3,2,8 cycles) 7 Wait State 1 Second Access (0..1 = 4,1 cycles; unlike above WS0) 8-9 Wait State 2 First Access (0..3 = 4,3,2,8 cycles) 10 Wait State 2 Second Access (0..1 = 8,1 cycles; unlike above WS0,WS1) 11-12 PHI Terminal Output (0..3 = Disable, 4.19MHz, 8.38MHz, 16.78MHz) 13 Not used 14 Game Pak Prefetch Buffer (Pipe) (0=Disable, 1=Enable) 15 Game Pak Type Flag (Read Only) (0=GBA, 1=CGB) (IN35 signal) 16-31 Not used |
Bit Expl. 0 Undocumented. First Boot Flag (0=First, 1=Further) 1-7 Undocumented. Not used. |
Bit Expl. 0-6 Undocumented. Not used. 7 Undocumented. Power Down Mode (0=Halt, 1=Stop) |
Bit Expl.
0 Disable 32K+256K WRAM (0=Normal, 1=Disable) (when off: empty/prefetch)
From endrift: bit0 swaps 00000000h-01FFFFFFh and 02000000h-03FFFFFFh
in GBA mode (but keeps BIOS protection)
1 Unknown (Read/Write-able)
2 Unknown (Read/Write-able)
3 Disable CGB Bootrom (0=Normal, 1=Disable, start cart at 0000h)
4 Unused (0)
5 Enable 256K WRAM (0=Disable, 1=Normal) (when off: mirror of 32K WRAM)
6-23 Unused (0)
24-27 Wait Control WRAM 256K (0-14 = 15..1 Waitstates, 15=Lockup)
28-31 Unknown (Read/Write-able)
|
| GBA GamePak Prefetch |
1) opcodes with internal cycles (I) which do not change R15, shift/rotate
register-by-register, load opcodes (ldr,ldm,pop,swp), multiply opcodes
2) opcodes that load/store memory (ldr,str,ldm,stm,etc.)
|
"Opcodes in GamePak ROM with Internal Cycles which do not change R15" |
| GBA Cartridges |
| GBA Cartridge Header |
Address Bytes Expl. 000h 4 ROM Entry Point (32bit ARM branch opcode, eg. "B rom_start") 004h 156 Nintendo Logo (compressed bitmap, required!) 0A0h 12 Game Title (uppercase ascii, max 12 characters) 0ACh 4 Game Code (uppercase ascii, 4 characters) 0B0h 2 Maker Code (uppercase ascii, 2 characters) 0B2h 1 Fixed value (must be 96h, required!) 0B3h 1 Main unit code (00h for current GBA models) 0B4h 1 Device type (usually 00h) (bit7=DACS/debug related) 0B5h 7 Reserved Area (should be zero filled) 0BCh 1 Software version (usually 00h) 0BDh 1 Complement check (header checksum, required!) 0BEh 2 Reserved Area (should be zero filled) --- Additional Multiboot Header Entries --- 0C0h 4 RAM Entry Point (32bit ARM branch opcode, eg. "B ram_start") 0C4h 1 Boot mode (init as 00h - BIOS overwrites this value!) 0C5h 1 Slave ID Number (init as 00h - BIOS overwrites this value!) 0C6h 26 Not used (seems to be unused) 0E0h 4 JOYBUS Entry Pt. (32bit ARM branch opcode, eg. "B joy_start") |
U Unique Code (usually "A" or "B" or special meaning) TT Short Title (eg. "PM" for Pac Man) D Destination/Language (usually "J" or "E" or "P" or specific language) |
A Normal game; Older titles (mainly 2001..2003) B Normal game; Newer titles (2003..) C Normal game; Not used yet, but might be used for even newer titles F Famicom/Classic NES Series (software emulated NES games) K Yoshi and Koro Koro Puzzle (acceleration sensor) P e-Reader (dot-code scanner) (or NDS PassMe image when gamecode="PASS") R Warioware Twisted (cartridge with rumble and z-axis gyro sensor) U Boktai 1 and 2 (cartridge with RTC and solar sensor) V Drill Dozer (cartridge with rumble) |
Usually an abbreviation of the game title (eg. "PM" for "Pac Man") (unless that gamecode was already used for another game, then TT is just random) |
J Japan P Europe/Elsewhere F French S Spanish E USA/English D German I Italian |
Value Expl. 01h Joybus mode 02h Normal mode 03h Multiplay mode |
Value Expl. 01h Slave #1 02h Slave #2 03h Slave #3 |
| GBA Cartridge ROM |
| GBA Cart Backup IDs |
EEPROM_Vnnn EEPROM 512 bytes or 8 Kbytes (4Kbit or 64Kbit) SRAM_Vnnn SRAM 32 Kbytes (256Kbit) FLASH_Vnnn FLASH 64 Kbytes (512Kbit) (ID used in older files) FLASH512_Vnnn FLASH 64 Kbytes (512Kbit) (ID used in newer files) FLASH1M_Vnnn FLASH 128 Kbytes (1Mbit) |
| GBA Cart Backup SRAM/FRAM |
| GBA Cart Backup EEPROM |
2 bits "11" (Read Request) n bits eeprom address (MSB first, 6 or 14 bits, depending on EEPROM) 1 bit "0" |
4 bits - ignore these 64 bits - data (conventionally MSB first) |
2 bits "10" (Write Request) n bits eeprom address (MSB first, 6 or 14 bits, depending on EEPROM) 64 bits data (conventionally MSB first) 1 bit "0" |
| GBA Cart Backup Flash ROM |
[E005555h]=AAh, [E002AAAh]=55h, [E005555h]=90h (enter ID mode) dev=[E000001h], man=[E000000h] (get device & manufacturer) [E005555h]=AAh, [E002AAAh]=55h, [E005555h]=F0h (terminate ID mode) |
dat=[E00xxxxh] (read byte from address xxxx) |
[E005555h]=AAh, [E002AAAh]=55h, [E005555h]=80h (erase command) [E005555h]=AAh, [E002AAAh]=55h, [E005555h]=10h (erase entire chip) wait until [E000000h]=FFh (or timeout) |
[E005555h]=AAh, [E002AAAh]=55h, [E005555h]=80h (erase command) [E005555h]=AAh, [E002AAAh]=55h, [E00n000h]=30h (erase sector n) wait until [E00n000h]=FFh (or timeout) |
old=IME, IME=0 (disable interrupts) [E005555h]=AAh, [E002AAAh]=55h, [E005555h]=A0h (erase/write sector command) [E00xxxxh+00h..7Fh]=dat[00h..7Fh] (write 128 bytes) IME=old (restore old IME state) wait until [E00xxxxh+7Fh]=dat[7Fh] (or timeout) |
[E005555h]=AAh, [E002AAAh]=55h, [E005555h]=A0h (write byte command) [E00xxxxh]=dat (write byte to address xxxx) wait until [E00xxxxh]=dat (or timeout) |
[E005555h]=F0h (force end of write/erase command) |
[E005555h]=AAh, [E002AAAh]=55h, [E005555h]=B0h (select bank command) [E000000h]=bnk (write bank number 0..1) |
ID Name Size Sectors AverageTimings Timeouts/ms Waits D4BFh SST 64K 16x4K 20us?,?,? 10, 40, 200 3,2 1CC2h Macronix 64K 16x4K ?,?,? 10,2000,2000 8,3 1B32h Panasonic 64K 16x4K ?,?,? 10, 500, 500 4,2 3D1Fh Atmel 64K 512x128 ?,?,? ...40.., 40 8,8 1362h Sanyo 128K ? ?,?,? ? ? ? ? 09C2h Macronix 128K ? ?,?,? ? ? ? ? |
| GBA Cart Backup DACS |
| GBA Cart I/O Port (GPIO) |
bit0-3 Data Bits 0..3 (0=Low, 1=High) bit4-15 not used (0) |
bit0-3 Direction for Data Port Bits 0..3 (0=In, 1=Out) bit4-15 not used (0) |
bit0 Register 80000C4h..80000C8h Control (0=Write-Only, 1=Read/Write) bit1-15 not used (0) |
GPIO | Boktai | Wario Bit Pin | RTC SOL | GYR RBL -----------+---------+--------- 0 ROM.1 | SCK CLK | RES - 1 ROM.2 | SIO RST | CLK - 2 ROM.21 | CS - | DTA - 3 ROM.22 | - FLG | - MOT -----------+---------+--------- IRQ ROM.43 | IRQ - | - - |
| GBA Cart Real-Time Clock (RTC) |
NDS_________GBA_________GBA/Params___ stat2 control (1-byte) datetime datetime (7-byte) time time (3-byte) stat1 force reset (0-byte) clkadjust force irq (0-byte) alarm1/int1 always FFh (boktai contains code for writing 1-byte to it) alarm2 always FFh (unused) free always FFh (unused) |
Bit Dir Expl. 0 - Not used 1 R/W IRQ duty/hold related? 2 - Not used 3 R/W Per Minute IRQ (30s duty) (0=Disable, 1=Enable) 4 - Not used 5 R/W Unknown? 6 R/W 12/24-hour Mode (0=12h, 1=24h) (usually 1) 7 R Power-Off (auto cleared on read) (0=Normal, 1=Failure, time lost) |
Boktai series ;which/how many titles? P-Letter series ;which/how many titles? Rockman EXE 4.5 Real Operation |
| GBA Cart Solar Sensor |
strh 0001h,[80000c8h] ;-enable R/W mode strh 0007h,[80000c6h] ;-init I/O direction strh 0002h,[80000c4h] ;-reset counter to zero (high=reset) (I/O bit0) strh 0000h,[80000c4h] ;-clear reset (low=normal) mov r0,0 ;-initial level @@lop: strh 0001h,[80000c4h] ;-clock high ;\increase counter (I/O bit1) strh 0000h,[80000c4h] ;-clock low ;/ ldrh r1,[80000c4h] ;-read port (I/O bit3) tst r1,08h ;\ addeq r0,1 ; loop until voltage match (exit with r0=00h..FFh), tsteq r0,100h ; or until failure/timeout (exit with r0=100h) beq @@lop ;/ |
E8h total darkness (including LED light, or daylight on rainy days) Dxh close to a 100 Watt Bulb 5xh reaches max level in boktai's solar gauge 00h close to a tactical nuclear bomb dropped on your city |
| GBA Cart Tilt Sensor |
E008000h (W) Write 55h to start sampling E008100h (W) Write AAh to start sampling E008200h (R) Lower 8 bits of X axis E008300h (R) Upper 4 bits of X axis, and Bit7: ADC Status (0=Busy, 1=Ready) E008400h (R) Lower 8 bits of Y axis E008500h (R) Upper 4 bits of Y axis |
wait until [E008300h].Bit7=1 or until timeout ;wait ready x = ([E008300h] AND 0Fh)*100h + [E008200h] ;get x y = ([E008500h] AND 0Fh)*100h + [E008400h] ;get y [E008000h]=55h, [E008100h]=AAh ;start next conversion |
X ranged between 0x2AF to 0x477, center at 0x392. Huh? Y ranged between 0x2C3 to 0x480, center at 0x3A0. Huh? |
| GBA Cart Gyro Sensor |
GPIO.Bit0 (W) Start Conversion GPIO.Bit1 (W) Serial Clock GPIO.Bit2 (R) Serial Data GPIO.Bit3 (W) Used for Rumble (not gyro related) |
read_gyro: mov r1,8000000h ;-cartridge base address mov r0,01h ;\enable R/W access strh r0,[r1,0c8h] ;/ mov r0,0bh ;\init direction (gpio2=input, others=output) strh r0,[r1,0c6h] ;/ ldrh r2,[r1,0c4h] ;-get current state (for keeping gpio3=rumble) orr r2,3 ;\ strh r2,[r1,0c4h] ;gpio0=1 ; start ADC conversion bic r2,1 ; strh r2,[r1,0c4h] ;gpio0=0 ;/ mov r0,00010000h ;stop-bit ;\ bic r2,2 ; @@lop: ; ldrh r3,[r1,0c4h] ;get gpio2=data ; read 16 bits strh r2,[r1,0c4h] ;gpio1=0=clk=low ; (4 dummy bits, plus 12 data bits) movs r3,r3,lsr 3 ;gpio2 to cy=data ; adcs r0,r0,r0 ;merge data, cy=done; orr r3,r2,2 ;set bit1 and delay ; strh r3,[r1,0c4h] ;gpio1=1=clk=high ; bcc @@lop ;/ bic r0,0f000h ;-strip upper 4 dummy bits (isolate 12bit adc) bx lr |
354h rotated in anti-clockwise direction (shock-speed) 64Dh rotated in anti-clockwise direction (normal fast) 6A3h rotated in anti-clockwise direction (slow) 6C0h no rotation (stopped) 6DAh rotation in clockwise direction (slow) 73Ah rotation in clockwise direction (normal fast) 9E3h rotation in clockwise direction (shock-speed) |
| GBA Cart Rumble |
| GBA Cart e-Reader |
________________ | ShortStrip | |L L| |o Center o| |n Region n| |g g| | may contain | |S pictures, S| |t instructions t| |r etc. r| |i i| |p p| |___ShortStrip___| |
| GBA Cart e-Reader Overview |
| GBA Cart e-Reader I/O Ports |
0 Output to PGA.Pin93 (which seems to be not connected to anything) 1-3 Unknown, read/write-able (not used by e-Reader BIOS) 4-15 Always zero (0) |
0 Always zero (0) 1 Reset Something? (0=Normal, 1=Reset) 2 Unknown, always set (1) 3 Unknown, read/write-able (not used by e-Reader BIOS) 4-7 Always zero (0) 8 Unknown, read/write-able (not used by e-Reader BIOS) 9-15 Always zero (0) |
0-6 Max Brightness (00h..7Fh; 00h=All black, 7Fh=One or more white) 7-15 Always zero |
0-7 Max Darkness (00h..7Fh; 00h=One or more black, 7Fh=All white) 8-15 Always zero |
0-6 Block Intensity Boundaries (0..7Fh; 7Fh=Whole block gets black) 7 Always zero |
0 Serial Data (Low/High) 1 Serial Clock (Low/High) 2 Serial Direction (0=Input, 1=Output) 3 Led/Irq Enable (0=Off, 1=On; Enable LED and Gamepak IRQ) 4 Start Scan (0=Off, 1=Start) (0-to-1 --> Resync line 0) 5 Phi 16MHz Output (0=Off, 1=On; Enable Clock for Camera, and for LED) 6 Power 3V Enable (0=Off, 1=On; Enable 3V Supply for Camera) 7 Not used (always 0) (sometimes 1) (Read only) |
0 Not used (always 0) 1 Scanline Flag (1=Scanline Received, 0=Acknowledge) 2-3 Not used (always 0) 4 Strange Bit (0=Normal, 1=Force Resync/Line0 on certain interval?) 5 LED Anode Voltage (0=3.0V, 1=5.1V; requires E00FFB0h.Bit3+5 to be set) 6 Not used (always 0) 7 Input from PGA.Pin22, always high (not used by e-Reader) (Read Only) |
Port Expl. (e-Reader Setting) 00h Maybe Chip ID (12h) (not used by e-Reader BIOS) (Read Only) 01h (05h) ;-Bit0: 1=auto-repeat scanning? 02h (0Eh) 10h-11h Vertical Scroll (calib_data[30h]+7) 12h-13h Horizontal Scroll (0030h) 14h-15h Vertical Size (00F6h=246) 16h-17h Horizontal Size (0140h=320) 20h-21h H-Blank Duration (00C4h) 22h-23h (0400h) ;-Upper-Blanking in dot-clock units? 25h (var) ;-bit1: 0=enable [57h..5Ah] ? 26h (var) ;\maybe a 16bit value 27h (var) ;/ 28h (00h) 30h Brightness/contrast (calib_data[31h]+/-nn) 31h-33h (014h,014h,014h) 34h Brightness/contrast (02h) 50h-52h 8bit Read/Write (not used by e-Reader BIOS) 53h-55h 2bit Read/Write (not used by e-Reader BIOS) 56h 8bit Read/Write (not used by e-Reader BIOS) 57h-58h 16bit value, used to autodetect/adjust register[30h] (Read Only) 59h-5Ah 16bit value, used to autodetect/adjust register[30h] (Read Only) 80h-FFh Mirrors of 00h..7Fh (not used by e-Reader BIOS) |
Port Expl. (e-Reader Setting) 00h (22h) 01h (50h) 02h-03h Vertical Scroll (calib_data[30h]+28h) 04h-05h Horizontal Scroll (001Eh) 06h-07h Vertical Size (00F6h) ;=246 08h-09h Horizontal Size (0140h) ;=320 0Ah-0Ch (not used by e-Reader BIOS) 0Dh (01h) 0Eh-0Fh (01EAh) ;=245*2 10h-11h (00F5h) ;=245 12h-13h (20h,F0h) ;maybe min/max values? 14h-15h (31h,C0h) ;maybe min/max values? 16h (00h) 17h-18h (77h,77h) 19h-1Ch (30h,30h,30h,30h) 1Dh-20h (80h,80h,80h,80h) 21h-FFh (not used by e-Reader BIOS) |
E00D000 14h ID String ('Card-E Reader 2001',0,0)
E00D014 2 Sector Checksum (NOT(x+x/10000h); x=sum of all other halfwords)
|
E00D016 8x6 [00h] Intensity Boundaries for 8x6 blocks ;see E00FF80h..AFh E00D046 1 [30h] Vertical scroll (0..36h) ;see type1.reg10h/type2.reg02h E00D047 1 [31h] Brightness or contrast ;see type1.reg30h E00D048 2 [32h] LED Duration ;see E00FFB2h..B3h E00D04A 2 [34h] Not used? (0000h) E00D04C 2 [36h] Signed value, related to adjusting the 8x6 blocks E00D04E 4 [38h] Not used? (00000077h) E00D052 4 [3Ch] Camera Type (0=none,1=DV488800,2=Whatever?) |
E00D056 FAAh Not used (zerofilled) (included in above checksum) |
call ereader_power_on call ereader_initialize for z=1 to number_of_frames for y=0 to 245 Wait until E00FFB1h.Bit1 gets set by hardware (can be handled by IRQ) Copy 14h halfwords from DFC0000h to buf+y*28h via DMA3 Reset E00FFB1h.Bit1 by software next y ;(could now check DFC0028h..DFC0086h/DFC0088h for adjusting E00FF00h..2Fh) ;(could now show image on screen, that may require to stop/pause scanning) next z call ereader_power_off Ret |
[4000204h]=5803h ;Init waitstates, and enable Phi 16MHz [DFA0000h].Bit1=1 Wait(10ms) [E00FFB0h]=40h ;Enable Power3V and reset other bits [DFA0000h].Bit1=0 [E00FFB1h]=20h ;Enable Power5V and reset other bits Wait(40ms) [E00FFB1h].Bit4=0 ;...should be already 0 ? [E00FFB0h]=40h+27h ;Phi16MHz=On, SioDtaClkDir=HighHighOut Ret |
[E00FFB0h]=04h ;Power3V=Off, Disable Everything, SioDtaClkDir=LowLowOut [DFA0000h].Bit1=0 ;...should be already 0 [E00FFB1h].Bit5=0 ;Power5V=Off Ret |
IF calib_data[3Ch] AND 03h = 1 THEN init_camera_type1 [E00FFB0h].Bit4=1 ;ScanStart IF calib_data[3Ch] AND 03h = 2 THEN init_camera_type2 Copy calib_data[00h..2Fh] to [E00FF80h+00h..2Fh] ;Intensity Boundaries Copy calib_data[32h..33h] to [E00FFB2h+00h..01h] ;LED Duration LSB,MSB [E00FFB0h].Bit3=1 ;LedIrqOn Ret |
x=MIN(0,calib_data[31h]-0Bh) Set Sio Registers (as shown for Camera Type 1, except below values...) Set Sio Registers [30h]=x [25h]=04h, [26h]=58h, [27h]=6Ch ;(could now detect/adjust <x> based on Sio Registers [57h..5Ah]) Set Sio Registers [30h]=x [25h]=06h, [26h]=E8h, [27h]=6Ch Ret |
Wait(0.5ms) Set Sio Registers (as shown for Camera Type 2) Ret |
Begin Write(A) Write(B) Read(C) Read(D) End Idle PwrOff
Dir ooooooo ooooooo ooooooo iiiiiii iiiiiii ooooooo ooooooo ooooooo
Dta ---____ AAAAAAA BBBBBBB xxxxxCx xxxxxDx ______- ------- _______
Clk ------_ ___---_ ___---_ ___---_ ___---_ ___---- ------- _______
|
Delay: Wait circa 2.5us, Ret SioBegin: SioDta=1, SioDir=Out, SioClk=1, Delay, SioDta=0, Delay, SioClk=0, Ret SioEnd: SioDta=0, SioDir=Out, Delay, SioClk=1, Delay, SioDta=1, Ret SioRead1bit: ;out: databit SioDir=In, Delay, SioClk=1, Delay, databit=SioDta, SioClk=0, Ret SioWrite1bit: ;in: databit SioDta=databit, SioDir=Out, Delay, SioClk=1, Delay, SioClk=0, Ret SioReadByte: ;in: endflag - out: data for i=7 to 0, data.bit<i>=SioRead1bit, next i, SioWrite1bit(endflag), Ret SioWriteByte: ;in: data - out: errorflag for i=7 to 0, Delay(huh/why?), SioWrite1bit(data.bit<i>), next i errorflag=SioRead1bit, SioDir=Out(huh/why?), Ret SioWriteRegisters: ;in: index, len, buffer SioBegin SioWriteByte(22h) ;command (set_index) (and write_data) SioWriteByte(index) ;index for i=0 to len-1 SioWriteByte(buffer[i]) ;write data (and auto-increment index) next SioEnd ret SioReadRegisters: ;in: index, len - out: buffer SioBegin SioWriteByte(22h) ;command (set_index) (without any write_data here) SioWriteByte(index) ;index SioBegin SioWriteByte(23h) ;command (read_data) (using above index) for i=0 to len-1 if i=len-1 then endflag=1 else endflag=0 buffer[i]=SioReadByte(endflag) ;read data (and auto-increment index) next SioEnd Ret |
C000000h-C7FFFFFh ROM (8MB) C800000h-DF7FFFFh Open Bus DF80000h-DF80001h Useless Register (R/W) DF80002h-DF9FFFFh Mirrors of DF80000h-DF80001h DFA0000h-DFA0001h Reset Register (R/W) DFA0002h-DFBFFFFh Mirrors of DFA0000h-DFA0001h DFC0000h-DFC0027h Scanline Data (320 Pixels) (R) DFC0028h-DFC0087h Brightest Pixels of 8x6 Blocks (R) DFC0088h Darkest Pixel of whole Image (R) DFC0089h-DFC00FFh Always zero DFC0100h-DFDFFFFh Mirrors of DFC0000h-DFC00FFh DFE0000h-DFFFFFFh Open Bus E000000h-E00CFFFh FLASH Bank 0 - Data E00D000h-E00DFFFh FLASH Bank 0 - Calibration Data E00E000h-E00EFFFh FLASH Bank 0 - Copy of Calibration Data E00F000h-E00FF7Fh FLASH Bank 0 - Unused region E000000h-E00EFFFh FLASH Bank 1 - Data E00F000h-E00FF7Fh FLASH Bank 1 - Unused region E00FF80h-E00FFAFh Intensity Boundaries for 8x6 Blocks (R/W) E00FFB0h Control Register 0 (R/W) E00FFB1h Control Register 1 (R/W) E00FFB2h-E00FFB3h LED Duration (16bit) (R/W) E00FFB4h-E00FFBFh Always zero E00FFC0h-E00FFFFh Mirror of E00FF80h-E00FFBFh |
Actual Shape Scanned Shape
XXXXX X X
XXXXXXX X X X
XXXXXXXXX X X X XX
XXXXXXXXX X X X XX
XXXXXXX XXXXXXX
XXXXX XXXXX
|
| GBA Cart e-Reader Dotcode Format |
XXX BLOCK 1 XXX BLOCK 2 XXX
XXXXX XXXXX XXXXX
XXXXX X X X X X X X X X X X X XXXXX X X X X X X X X X X X X XXXXX
XXXXX XXXXX XXXXX
XXX HHHHHHHHHHHHHHHHHHHH...... XXX HHHHHHHHHHHHHHHHHHHH...... XXX
.......................... ..........................
...... 3 short lines ..... ..........................
A..................................A..................................A..
A.... 26 long lines ....A........ X = Sync Marks ........A..
A.... (each 34 data dots) ....A........ H = Block Header ........A..
A....(not all lines shown here)....A........ . = Data Bits ........A..
A..................................A........ A = Address Bits ........A..
...... 3 short lines ..... ..........................
...(each 26 data dots).... ..........................
XXX .......................... XXX .......................... XXX
XXXXX XXXXX XXXXX
XXXXX X X X X X X X X X X X X XXXXX X X X X X X X X X X X X XXXXX
XXXXX XXXXX XXXXX
XXX XXX XXX
<ca. 35 blank lines>
___Snip____________________________________________________________________
|
addr[0] = 03FFh
for i = 1 to 53
addr[i] = addr[i-1] xor ((i and (-i)) * 769h)
if (i and 07h)=0 then addr[i] = addr[i] xor (769h)
if (i and 0Fh)=0 then addr[i] = addr[i] xor (769h*2)
if (i and 1Fh)=0 then addr[i] = addr[i] xor (769h*4) xor (769h)
next i
|
00h Unknown (00h)
01h Dotcode type (02h=Short, 03h=Long)
02h Unknown (00h)
03h Address of 1st Block (01h=Short, 19h=Long)
04h Total Fragment Size (40h) ;64 bytes per fragment, of which,
;48 bytes are actual data, the remaining
05h Error-Info Size (10h) ;16 bytes are error-info
06h Unknown (00h)
07h Interleave Value (1Ch=Short, 2Ch=Long)
08h..17h 16 bytes Reed-solomon error correction info for Block Header
|
4bit 00h 01h 02h 03h 04h 05h 06h 07h 08h 09h 0Ah 0Bh 0Ch 0Dh 0Eh 0Fh 5bit 00h 01h 02h 12h 04h 05h 06h 16h 08h 09h 0Ah 14h 0Ch 0Dh 11h 10h |
RAW Offset Content 000h..001h 1st 2 bytes of RAW Header 002h 1st byte of 1st fragment 003h 1st byte of 2nd fragment ... ... 002h+I-1 1st byte of last fragment 002h+I 2nd byte of 1st fragment 003h+I 2nd byte of 2nd fragment ... ... 002h+I*2-1 2nd byte of last fragment ... ... |
| GBA Cart e-Reader Data Format |
Data Header (48 bytes) Main-Title (17 bytes, or 33 bytes) Sub-Title(s) (3+18 bytes, or 33 bytes) (for each strip) (optional) VPK Size (2 byte value, total length of VPK Data in ALL strips) NULL Value (4 bytes, contained ONLY in 1st strip of GBA strips) VPK Data (length as defined in VPK Size entry, see above) |
Data Header (48 bytes) Main-Title (17 bytes, or 33 bytes) Sub-Title(s) (3+18 bytes, or 33 bytes) (for each strip) (optional) VPK Data (continued from previous strip) |
00h-01h Fixed (00h,30h)
02h Fixed (01h) ;01h="Do not calculate Global Checksum" ?
03h Primary Type (see below)
04h-05h Fixed (00h,01h) (don't care)
06h-07h Strip Size (0510h=Short, 0810h=Long Strip) ((I-1)*30h) (MSB,LSB)
08h-0Bh Fixed (00h,00h,10h,12h)
0Ch-0Dh Region/Type (see below)
0Eh Strip Type (02h=Short Strip, 01h=Long Strip) (don't care)
0Fh Fixed (00h) (don't care)
10h-11h Unknown (whatever) (don't care)
12h Fixed (10h) ;10h="Do calculate Data Checksum" ?
13h-14h Data Checksum (see below) (MSB,LSB)
15h-19h Fixed (19h,00h,00h,00h,08h)
1Ah-21h ID String ('NINTENDO')
22h-25h Fixed (00h,22h,00h,09h)
26h-29h Size Info (see below)
2Ah-2Dh Flags (see below)
2Eh Header Checksum (entries [0Ch-0Dh,10h-11h,26h-2Dh] XORed together)
2Fh Global Checksum (see below)
|
0 Card Type (upper bit) (see below) 1 Unknown (usually opposite of Bit0) (don't care) 2-7 Unknown (usually zero) |
0-3 Unknown (don't care) 4-7 Card Type (lower bits) (see below) 8-11 Region/Version (0=Japan/Original, 1=Non-japan, 2=Japan/Plus) 12-15 Unknown (don't care) |
0 Unknown (don't care)
1-4 Strip Number (01h..Number of strips)
5-8 Number of Strips (01h..0Ch) (01h..08h for Japan/Original version)
9-23 Size of all Strips (excluding Headers and Main/Sub-Titles)
(same as "VPK Size", but also including the 2-byte "VPK Size" value,
plus the 4-byte NULL value; if it is present)
24-31 Fixed (02h) (don't care)
|
0 Permission to save (0=Start Immediately, 1=Prompt for FLASH Saving) 1 Sub-Title Flag (0=Yes, 1=None) (Japan/Original: always 0=Yes) 2 Application Type (0=GBA/Z80, 1=NES) (Japan/Original: always 0=Z80) 3-31 Zero (0) (don't care) |
Bit Expl.
0-3 h1, values 1..15 shown as "10..150", value 0 is not displayed
4-6 i3, values 0..7 shown as "A..G,#"
7-13 i2, values 0..98 shown as "01..99" values 99..127 as "A0..C8"
14-18 i1, values 0..31 shown as "A..Z,-,_,{HP},.,{ID?},:"
19-22 Unknown
23 Disable stats (0=Show as "HP: h1 ID: i1-i2-i3", 1=Don't show it)
|
00h --> end-byte 81h,40h --> SPC 81h,43h..97h --> punctuation marks 82h,4Fh..58h --> "0..9" 82h,60h..79h --> "A..Z" 82h,81h..9Ah --> "a..z" |
00 = end-byte
01 = spc
02..0B = 0..9
0C..AF = japanese
B0..B4 = dash, male, female, comma, round-dot
B5..C0 = !"%&~?/+-:.'
C1..DA = A..Z
DB..DF = unused (blank)
E0..E5 = japanese
E6..FF = a..z
N/A = #$()*;<=>@[\]^_`{|}
|
00h..01h Blank Screen (?) 02h..03h Dotcode Application with 17byte-title, with stats, load music A 04h..05h Dotcode Application with 17byte-title, with stats, load music B 06h..07h P-Letter Attacks 08h..09h Construction Escape 0Ah..0Bh Construction Action 0Ch..0Dh Construction Melody Box 0Eh Dotcode Application with 33byte-title, without stats, load music A 0Fh Game specific cards 10h..1Dh P-Letter Viewer 1Eh..1Fh Same as 0Eh and 0Fh (see above) |
| GBA Cart e-Reader Program Code |
IF e-Reader is Non-Japanese, AND [2000008h] is outside of range of 2000000h..20000E3h, AND only if booted from camera (not when booted from FLASH?), THEN [2000008h]=[2000008h]-0001610Ch ELSE [2000008h] kept intact |
Store "B 20000C0h" at 2000000h ;redirect to RAM-entrypoint Zerofill 2000004h..20000BFh ;erase header (for better compression rate) Store 01h,01h at 20000C4h ;indicate RAM boot |
http://problemkaputt.de/everynes.htm |
for i=17h to 0 for j=07h to 0, nmi = nmi shr 1, if carry then nmi = nmi xor 8646h, next j nmi = nmi xor (byte[dmca_data+i] shl 8) next i dmca_data: db 0,0,'DMCA NINTENDO E-READER' |
Bit0-14 Lower bits of Entrypoint (0..7FFFh = Address 8000h..FFFFh) Bit15 Nametable Mode (0=Vertical Mirroring, 1=Horizontal Mirroring) |
(NES limitations, 1 16K program rom + 1-2 8K CHR rom, mapper 0 and 1) ines mapper 1 would be MMC1, rather than CNROM (ines mapper 3)? but, there are more or less NONE games that have 16K PRG ROM + 16K VROM? |
CB [Prefix] E0 RET PO E2 JP PO,nn E4 CALL PO,nn 27 DAA 76 HALT ED [Prefix] E8 RET PE EA JP PE,nn EC CALL PE,nn D3 OUT (n),A DD [IX Prefix] F3 DI 08 EX AF,AF' F4 CALL P,nn DB IN A,(n) FD [IY Prefix] FB EI D9 EXX FC CALL M,nn xx RST 00h..38h |
76 WAIT A frames, D3 WAIT n frames, and C7/CF RST 0/8 used for API calls. |
retry: ld bc,data // ld hl,00c8h ;src/dst lop: ld a,[bc] // inc bc // ld e,a ;lsb ld a,[bc] // inc bc // ld d,a ;msb dw 0bcfh ;aka rst 8 // db 0bh ;[4000000h+hl]=de (DMA registers) inc hl // inc hl // ld a,l cp a,0dch // jr nz,lop mod1 equ $+1 dw 37cfh ;aka rst 8 // db 37h ;bx 3E700F0h ;below executed only on jap/plus... on jap/plus, above 37cfh is hl=[400010Ch] ld a,3Ah // ld [mod1],a ;bx 3E700F0h (3Ah instead 37h) ld hl,1 // ld [mod2],hl // ld [mod3],hl ;base (0200010Ch instead 0201610Ch) jr retry data: mod2 equ $+1 dd loader ;40000C8h dma2sad (loader) ;\ dd 030000F0h ;40000CCh dma2dad (mirrored 3E700F0h) ; relocate loader dd 8000000ah ;40000D0h dma2cnt (copy 0Ah x 16bit) ;/ mod3 equ $+1 dd main ;40000D4h dma3sad (main) ;\prepare main reloc dd 02000000h ;40000D8h dma3dad (2000000h) ;/dma3cnt see loader .align 2 ;alignment for 16bit-halfword org $+201600ch ;jap/plus: adjusted to org $+200000ch loader: mov r0,80000000h ;(dma3cnt, copy 10000h x 16bit) mov r1,04000000h ;i/o base strb r1,[r1,208h] ;ime=0 (better disable ime before moving ram) str r0,[r1,0DCh] ;dma3cnt (relocate to 2000000h) mov r15,2000000h ;start relocated code at 2000000h in ARM state main: ;...insert/append whatever ARM code here... end |
| GBA Cart e-Reader API Functions |
db 76h ;Wait8bit A db D3h,xxh ;Wait8bit xxh db C7h,xxh ;RST0_xxh db CFh,xxh ;RST8_xxh ld r,[00xxh] ;get system values (addresses differ on jap/ori) ld r,[00C2h..C3h] ;GetKeyStateSticky (jap/ori: 9F02h..9F03h) ld r,[00C4h..C5h] ;GetKeyStateRaw (jap/ori: 9F04h..9F05h) ld r,[00C0h..C1h] ;see Exit and ExitRestart ld r,[00D0h..D3h] ;see Mul16bit |
bx [30075FCh] ;ApiVector ;in: r0=func_no,r1,r2,r3,[sp+0],[sp+4],[sp+8]=params bx lr ;Exit ;in: r0 (0=Restart, 2=To_Menu) |
RST0_00h FadeIn, A speed, number of frames (0..x)
RST0_01h FadeOut
RST0_02h BlinkWhite
RST0_03h (?)
RST0_04h (?) blend_func_unk1
RST0_05h (?)
RST0_06h (?)
RST0_07h (?)
RST0_08h (?)
RST0_09h (?) _020264CC_check
RST0_0Ah (?) _020264CC_free
RST0_0Bh N/A (bx 0)
RST0_0Ch N/A (bx 0)
RST0_0Dh N/A (bx 0)
RST0_0Eh N/A (bx 0)
RST0_0Fh N/A (bx 0)
RST0_10h LoadSystemBackground, A number of background (1..101), E bg# (0..3)
RST0_11h SetBackgroundOffset, A=bg# (0..3), DE=X, BC=Y
RST0_12h SetBackgroundAutoScroll
RST0_13h SetBackgroundMirrorToggle
RST0_14h (?)
RST0_15h (?)
RST0_16h (?) write_000000FF_to_02029494_
RST0_17h (?)
RST0_18h (?)
RST0_19h SetBackgroundMode, A=mode (0..2)
RST0_1Ah (?)
RST0_1Bh (?)
RST0_1Ch (?)
RST0_1Dh (?)
RST0_1Eh (?)
RST0_1Fh (?)
RST0_20h LayerShow
RST0_21h LayerHide
RST0_22h (?)
RST0_23h (?)
RST0_24h ... [20264DCh+A*20h+1Ah]=DE, [20264DCh+A*20h+1Ch]=BC
RST0_25h (?)
RST0_26h (?)
RST0_27h (?)
RST0_28h (?)
RST0_29h (?)
RST0_2Ah (?)
RST0_2Bh (?)
RST0_2Ch (?)
RST0_2Dh LoadCustomBackground, A bg# (0..3), DE pointer to struct_background,
max. tile data size = 3000h bytes, max. map data size = 1000h bytes
RST0_2Eh GBA: N/A - Z80: (?)
RST0_2Fh (?)
RST0_30h CreateSystemSprite, - - (what "- -" ???)
RST0_31h SpriteFree, HL sprite handle
RST0_32h SetSpritePos, HL=sprite handle, DE=X, BC=Y
RST0_33h (?) sprite_unk2
RST0_34h SpriteFrameNext
RST0_35h SpriteFramePrev
RST0_36h SetSpriteFrame, HL=sprite handle, E=frame number (0..x)
RST0_37h (?) sprite_unk3
RST0_38h (?) sprite_unk4
RST0_39h SetSpriteAutoMove, HL=sprite handle, DE=X, BC=Y
RST0_3Ah (?) sprite_unk5
RST0_3Bh (?) sprite_unk6
RST0_3Ch SpriteAutoAnimate
RST0_3Dh (?) sprite_unk7
RST0_3Eh SpriteAutoRotateUntilAngle
RST0_3Fh SpriteAutoRotateByAngle
RST0_40h SpriteAutoRotateByTime
RST0_41h (?) sprite_unk8
RST0_42h SetSpriteAutoMoveHorizontal
RST0_43h SetSpriteAutoMoveVertical
RST0_44h (?) sprite_unk9
RST0_45h SpriteDrawOnBackground
RST0_46h SpriteShow, HL=sprite handle
RST0_47h SpriteHide, HL=sprite handle
RST0_48h SpriteMirrorToggle
RST0_49h (?) sprite_unk10
RST0_4Ah (?) sprite_unk11
RST0_4Bh (?) sprite_unk12
RST0_4Ch GetSpritePos
RST0_4Dh CreateCustomSprite
RST0_4Eh (?)
RST0_4Fh (?) sprite_unk14
RST0_50h (?) sprite_unk15
RST0_51h (?) sprite_unk16
RST0_52h (?) sprite_unk17
RST0_53h (?) sprite_unk18
RST0_54h (?)
RST0_55h (?) sprite_unk20
RST0_56h (?)
RST0_57h SpriteMove
RST0_58h (?) sprite_unk22
RST0_59h (?) sprite_unk23
RST0_5Ah (?) sprite_unk24
RST0_5Bh SpriteAutoScaleUntilSize, C=speed (higher value is slower),
HL=sprite handle, DE=size (0100h = normal size,
lower value = larger, higher value = smaller)
RST0_5Ch SpriteAutoScaleBySize
RST0_5Dh SpriteAutoScaleWidthUntilSize
RST0_5Eh SpriteAutoScaleHeightBySize
RST0_5Fh (?)
RST0_60h (?)
RST0_61h (?)
RST0_62h (?)
RST0_63h (?)
RST0_64h hl=[[2024D28h+a*4]+12h]
RST0_65h (?) sprite_unk25
RST0_66h SetSpriteVisible, HL=sprite handle, E=(0=not visible, 1=visible)
RST0_67h (?) sprite_unk26
RST0_68h (?) set_sprite_unk27
RST0_69h (?) get_sprite_unk27
RST0_6Ah (?)
RST0_6Bh (?)
RST0_6Ch (?)
RST0_6Dh (?)
RST0_6Eh hl=[hl+000Ah] ;r0=[r1+0Ah]
RST0_6Fh (?)
RST0_70h (?)
RST0_71h (?)
RST0_72h (?)
RST0_73h (?)
RST0_74h (?)
RST0_75h (?)
RST0_76h (?)
RST0_77h (?)
RST0_78h (?)
RST0_79h (?)
RST0_7Ah (?)
RST0_7Bh (?)
RST0_7Ch (?) _0202FD2C_unk12
RST0_7Dh Wait16bit ;HL=num_frames (16bit variant of Wait8bit opcode/function)
RST0_7Eh SetBackgroundPalette, HL=src_addr, DE=offset, C=num_colors (1..x)
RST0_7Fh GetBackgroundPalette(a,b,c)
RST0_80h SetSpritePalette, HL=src_addr, DE=offset, C=num_colors (1..x)
RST0_81h GetSpritePalette(a,b,c)
RST0_82h ClearPalette
RST0_83h (?) _0202FD2C_unk11
RST0_84h (?)
RST0_85h (?)
RST0_86h (?)
RST0_87h (?) _0202FD2C_unk8
RST0_88h (?) _0202FD2C_unk7
RST0_89h (?)
RST0_8Ah (?) _0202FD2C_unk6
RST0_8Bh (?) _0202FD2C_unk5
RST0_8Ch GBA: N/A - Z80: (?)
RST0_8Dh GBA: N/A - Z80: (?)
RST0_8Eh (?)
RST0_8Fh WindowHide
RST0_90h CreateRegion, H=bg# (0..3), L=palbank# (0..15),
D,E,B,C=x1,y1,cx,cy (in tiles), return: n/a (no$note: n/a ???)
RST0_91h SetRegionColor
RST0_92h ClearRegion
RST0_93h SetPixel
RST0_94h GetPixel
RST0_95h DrawLine
RST0_96h DrawRect
RST0_97h (?) _0202FD2C_unk4
RST0_98h SetTextColor, A=region handle, D=color foreground (0..15),
E=color background (0..15)
RST0_99h DrawText, A=region handle, BC=pointer to text, D=X, E=Y
(non-japan uses ASCII text, but japanese e-reader's use STH ELSE?)
RST0_9Ah SetTextSize
RST0_9Bh (?) RegionUnk7
RST0_9Ch (?) _0202FD2C_unk3
RST0_9Dh (?) _0202FD2C_unk2
RST0_9Eh (?) _0202FD2C_unk1
RST0_9Fh Z80: (?) - GBA: SetBackgroundModeRaw
RST0_A0h (?)
RST0_A1h (?)
RST0_A2h (?) RegionUnk6
RST0_A3h GBA: N/A - Z80: (?)
RST0_A4h GBA: N/A - Z80: (?)
RST0_A5h (?)
RST0_A6h (?)
RST0_A7h (?)
RST0_A8h (?)
RST0_A9h (?)
RST0_AAh (?)
RST0_ABh (?)
RST0_ACh (?)
RST0_ADh (?) RegionUnk5
RST0_AEh [202FD2Ch+122h]=A
RST0_AFh [202FD2Ch+123h]=A
RST0_B0h [202FD2Ch+124h]=A
RST0_B1h (?)
RST0_B2h (?)
RST0_B3h GBA: N/A - Z80: Sqrt ;hl=sqrt(hl)
RST0_B4h GBA: N/A - Z80: ArcTan ;hl=ArcTan2(hl,de)
RST0_B5h Sine ;hl=sin(a)*de
RST0_B6h Cosine ;hl=cos(a)*de
RST0_B7h (?)
RST0_B8h (?)
RST0_B9h N/A (bx 0)
RST0_BAh N/A (bx 0)
RST0_BBh N/A (bx 0)
RST0_BCh N/A (bx 0)
RST0_BDh N/A (bx 0)
RST0_BEh N/A (bx 0)
RST0_BFh N/A (bx 0)
Below Non-Japan and Japan/Plus only (not Japan/Ori)
RST0_C0h GetTextWidth(a,b)
RST0_C1h GetTextWidthEx(a,b,c)
RST0_C2h (?)
RST0_C3h Z80: N/A (bx 0) - GBA: (?)
RST0_C4h (?)
RST0_C5h (?)
RST0_C6h (?)
RST0_C7h (?)
RST0_C8h (?)
RST0_C9h (?)
RST0_CAh (?)
RST0_CBh (?)
RST0_CCh (?)
RST0_CDh N/A (bx lr)
RST0_CEh ;same as RST0_3Bh, but with 16bit mask
RST0_CFh ;same as RST0_3Eh, but with 16bit de
RST0_D0h ;same as RST0_3Fh, but with 16bit de
RST0_D1h ;same as RST0_5Bh, but with 16bit de
RST0_D2h ;same as RST0_5Ch, but with 16bit de
RST0_D3h ;same as RST0_5Dh, but with 16bit de
RST0_D4h ;same as RST0_5Eh, but with 16bit de
RST0_D5h (?)
RST0_D6h (?)
RST0_D7h ;[202FD2Ch+125h]=A
RST0_D8h (?)
RST0_D9h (?)
RST0_DAh (?)
RST0_DBh ;A=[3003E51h]
RST0_DCh ;[3004658h]=01h
RST0_DDh DecompressVPKorNonVPK
RST0_DEh FlashWriteSectorSingle(a,b)
RST0_DFh FlashReadSectorSingle(a,b)
RST0_E0h SoftReset
RST0_E1h GetCartridgeHeader ;[hl+0..BFh]=[8000000h..80000BFh]
RST0_E2h GBA: N/A - Z80: bx hl ;in: hl=addr, af,bc,de,sp=param, out: a
RST0_E3h Z80: N/A (bx 0) - GBA: (?)
RST0_E4h (?)
RST0_E5h (?)
RST0_E6h (?)
RST0_E7h (?)
RST0_E8h (?)
RST0_E9h ;[2029498h]=0000h
RST0_EAh Z80: N/A (bx 0) - GBA: InitMemory(a)
RST0_EBh (?) BL_irq_sio_dma3
RST0_ECh ;hl = [3003E30h]*100h + [3003E34h]
RST0_EDh FlashWriteSectorMulti(a,b,c)
RST0_EEh FlashReadPart(a,b,c)
RST0_EFh ;A=((-([2029416h] xor 1)) OR (+([2029416h] xor 1))) SHR 31
RST0_F0h (?) _unk1
RST0_F1h RandomInit ;in: hl=random_seed
RST0_F2h (?)
Below Japan/Plus only
RST0_F3h (?)
RST0_F4h (?)
RST0_F5h (?)
RST0_F6h (?)
RST0_F7h GBA: N/A - Z80: (?)
Below is undefined/garbage (values as so in Z80 mode)
Jap/Ori: RST0_C0h N/A (bx 0)
Jap/Ori: RST0_C1h..FFh Overlaps RST8 jump list
Non-Jap: RST0_F3h..FFh Overlaps RST8 jump list
Jap/Pls: RST0_F8h..FFh Overlaps RST8 jump list
|
RST8_00h GBA: N/A - Z80: Exit ;[00C0h]=a ;(1=restart, 2=exit) RST8_01h GBA: N/A - Z80: Mul8bit ;hl=a*e RST8_02h GBA: N/A - Z80: Mul16bit ;hl=hl*de, s32[00D0h]=hl*de RST8_03h Div ;hl=hl/de RST8_04h DivRem ;hl=hl mod de RST8_05h PlaySystemSound ;in: hl=sound_number RST8_06h (?) sound_unk1 RST8_07h Random8bit ;a=random(0..FFh) RST8_08h SetSoundVolume RST8_09h BcdTime ;[de+0..5]=hhmmss(hl*bc) RST8_0Ah BcdNumber ;[de+0..4]=BCD(hl), [de+5]=00h RST8_0Bh IoWrite ;[4000000h+hl]=de RST8_0Ch IoRead ;de=[4000000h+hl] RST8_0Dh GBA: N/A - Z80: (?) RST8_0Eh GBA: N/A - Z80: (?) RST8_0Fh GBA: N/A - Z80: (?) RST8_10h GBA: N/A - Z80: (?) RST8_11h DivSigned ;hl=hl/de, signed RST8_12h RandomMax ;a=random(0..a-1) RST8_13h SetSoundSpeed RST8_14h hl=[202FD20h]=[2024CACh] RST8_15h hl=[2024CACh]-[202FD20h] RST8_16h SoundPause RST8_17h SoundResume RST8_18h PlaySystemSoundEx RST8_19h IsSoundPlaying RST8_1Ah (?) RST8_1Bh (?) RST8_1Ch (?) RST8_1Dh GetExitCount ;a=[2032D34h] RST8_1Eh Permille ;hl=de*1000/hl RST8_1Fh GBA: N/A - Z80: ExitRestart;[2032D38h]=a, [00C0h]=0001h ;a=? RST8_20h GBA: N/A - Z80: WaitJoypad ;wait until joypad<>0, set hl=joypad RST8_21h GBA: N/A - Z80: (?) RST8_22h (?) _sound_unk7 RST8_23h (?) _sound_unk8 RST8_24h (?) _sound_unk9 RST8_25h (?) _sound_unk10 RST8_26h Mosaic ;bg<n>cnt.bit6=a.bit<n>, [400004Ch]=de RST8_27h (?) RST8_28h (?) RST8_29h (?) RST8_2Ah (?) get_8bit_from_2030110h RST8_2Bh (?) RST8_2Ch (?) get_16bit_from_2030112h ;jap/ori: hl=[20077B2h] RST8_2Dh (?) get_16bit_from_2030114h ;jap/ori: hl=[20077B4h] RST8_2Eh (?) RST8_2Fh PlayCustomSound(a,b) Below not for Japanese/Original (the renumbered functions can be theoretically used on japanese/original) (but, doing so would blow forwards compatibility with japanese/plus) RST8_30h (ori: none) GBA: N/A - Z80: (?) RST8_31h (ori: none) PlayCustomSoundEx(a,b,c) RST8_32h (ori: RST8_30h) BrightnessHalf ;[4000050h]=00FFh,[4000054h]=0008h RST8_33h (ori: RST8_31h) BrightnessNormal ;[4000050h]=0000h RST8_34h (ori: RST8_32h) N/A (bx lr) RST8_35h (ori: RST8_33h) (?) RST8_36h (ori: RST8_34h) ResetTimer ;[400010Ch]=00000000h, [400010Eh]=A+80h RST8_37h (ori: RST8_35h) GetTimer ;hl=[400010Ch] RST8_38h (ori: none) GBA: N/A - Z80: (?) Below is undefined/reserved/garbage (values as so in Z80 mode) (can be used to tweak jap/ori to start GBA-code from inside of Z80-code) (that, after relocating code to 3000xxxh via DMA via IoWrite function) RST8_39h (ori: RST8_36h) bx 0140014h RST8_3Ah (ori: RST8_37h) bx 3E700F0h RST8_3Bh (ori: RST8_38h) bx 3E70000h+1 RST8_3Ch (ori: RST8_39h) bx 3E703E6h+1 RST8_3Dh (ori: RST8_3Ah) bx 3E703E6h+1 RST8_3Eh (ori: RST8_3Bh) bx 3E703E6h+1 RST8_3Fh (ori: RST8_3Ch) bx 3E703E6h+1 40h-FFh (ori: 3Dh-FFh) bx ... |
RSTX_00h Wait8bit ;for 16bit: RST0_7Dh RSTX_01h GetKeyStateSticky() RSTX_02h GetKeyStateRaw() RSTX_03h (?) RSTX_04h (?) |
| GBA Cart e-Reader VPK Decompression |
collected32bit=80000000h ;initially empty (endflag in bit31)
for i=0 to 3, id[i]=read_bits(8), next i, if id[0..3]<>'vpk0' then error
dest_end=dest+read_bits(32) ;size of decompressed data (of all strips)
method=read_bits(8), if method>1 then error
tree_index=0, load_huffman_tree, disproot=tree_index
tree_index=tree_index+1, load_huffman_tree, lenroot=tree_index
;above stuff is contained only in the first strip. below loop starts at
;current location in first strip, and does then continue in further strips.
decompress_loop:
if read_bits(1)=0 then ;copy one uncompressed data byte,
[dest]=read_bits(8), dest=dest+1 ;does work without huffman trees
else
if disproot=-1 or lenroot=-1 then error ;compression does require trees
disp=read_tree(disproot)
if method=1 ;disp*4 is good for 32bit ARM opcodes
if disp>2 then disp=disp*4-8 else disp=disp+4*read_tree(disproot)-7
len=read_tree(lenroot)
if len=0 or disp<=0 or dest+len-1>dest_end then error ;whoops
for j=1 to len, [dest]=[dest-disp], dest=dest+1, next j
if dest<dest_end then decompress_loop
ret
|
mov data=0
for i=1 to num
shl collected32bit,1 ;move next bit to carry, or set zeroflag if empty
if zeroflag
collected32bit=[src+0]*1000000h+[src+1]*10000h+[src+2]*100h+[src+3]
src=src+4 ;read data in 32bit units, in reversed byte-order
carryflag=1 ;endbit
rcl collected32bit,1 ;move bit31 to carry (and endbit to bit0)
rcl data,1 ;move carry to data
next i
ret(data)
|
i=root_index
while node[i].right<>-1 ;loop until reaching data node
if read_bits(1)=1 then i=node[i].right else i=node[i].left
i=node[i].left ;get number of bits
i=read_bits(i) ;read that number of bits
ret(i) ;return that value
|
stacktop=sp if read_bits(1)=1 then tree_index=-1, ret ;exit (empty) node[tree_index].right=-1 ;indicate data node node[tree_index].left=read_bits(8) ;store data value if read_bits(1)=1 then ret ;exit (only 1 data node at root) push tree_index ;save previous (child) node tree_index=tree_index+1 jmp data_injump load_loop: push tree_index ;save previous (child) node tree_index=tree_index+1 if read_bits(1)=1 then parent_node data_injump: node[tree_index].right=-1 ;indicate data node node[tree_index].left=read_bits(8) ;store data value jmp load_loop parent_node: pop node[tree_index].right ;store 1st child pop node[tree_index].left ;store 2nd child if sp<>stacktop then jmp load_loop if read_bits(1)=0 then error ;end bit (must be 1) ret |
| GBA Cart e-Reader Error Correction |
reverse_byte_order(data,dtalen)
zerofill_error_bytes(data,errlen)
for i=dtalen-1 to errlen ;loop across data portion
z = rev[ data[i] xor data[errlen-1] ] ;
for j=errlen-1 to 0 ;loop across error-info portion
if j=0 then x=00h else x=data[j-1]
if z<>FFh then
y=gg[j], if y<>FFh then
y=y+z, if y>=FFh then y=y-FFh
x=x xor pow[y]
data[j]=x
next j
next i
invert_error_bytes(data,errlen)
reverse_byte_order(data,dtalen)
|
reverse_byte_order(data,dtalen)
invert_error_bytes(data,errlen)
make_rev(data,dtalen)
for i=78h to 78h+errlen-1
x=0, z=0
for j=0 to dtalen-1
y=data[j]
if y<>FFh then
y=y+z, if y>=FFh then y=y-FFh
x=x xor pow[y]
z=z+i, if z>=FFh then z=z-FFh
next j
if x<>0 then error
next i
;(if errors occured, could correct them now)
make_pow(data,dtalen)
invert_error_bytes(data,errlen)
reverse_byte_order(data,dtalen)
|
for i=0 to len-1, data[i]=rev[data[i]], next i |
for i=0 to len-1, data[i]=pow[data[i]], next i |
for i=0 to len-1, data[i]=data[i] xor FFh, next i |
for i=0 to len-1, data[i]=00h, next i |
for i=0 to (len-1)/2, x=data[i], data[i]=data[len-i], data[len-i]=x, next i |
x=01h, pow[FFh]=00h, rev[00h]=FFh
for i=00h to FEh
pow[i]=x, rev[x]=i, x=x*2, if x>=100h then x=x xor 187h
next i
|
gg[0]=pow[78h]
for i=1 to errlen-1
gg[i]=01h
for j=i downto 0
if j=0 then y=00h else y=gg[j-1]
x=gg[j], if x<>00h then
x=rev[x]+78h+i, if x>=FFh then x=x-FFh
y=y xor pow[x]
gg[j]=y
next j
next i
make_rev(gg,errlen)
|
00h,4Bh,EBh,D5h,EFh,4Ch,71h,00h,F4h,00h,71h,4Ch,EFh,D5h,EBh,4Bh |
pow = alpha_to, but generated as shown above rev = index_of, dito b0 = 78h nn = dtalen kk = dtalen-errlen %nn = MOD FFh (for the ereader that isn't MOD dtalen) -1 = FFh |
| GBA Cart e-Reader File Formats |
| GBA Cart Unknown Devices |
| GBA Cart Protections |
| GBA Flashcards |
configure_flashcard(9E2468Ah,9413h) ;unlock flash advance cards turbo=1, send_command(8000000h,90h) ;enter ID mode (both chips, if any) maker=[8000000h], device=[8000000h+2] IF maker=device THEN device=[8000000h+4] ELSE turbo=0 flashcard_read_mode ;exit ID mode search (maker+device*10000h) in device_list total/erase/write_block_size = list_entry SHL turbo |
FOR x=1 to len/erase_block_size send_command(dest,20h) ;erase sector command send_command(dest,D0h) ;confirm erase sector dest=dest+erase_block_size IF wait_busy=okay THEN NEXT x enter_read_mode ;exit erase/status mode |
siz=write_block_size FOR x=1 to len/siz IF siz=2 THEN send_command(dest,10h) ;write halfword command IF siz>2 THEN send_command(dest,E8h) ;write to buffer command IF siz>2 THEN send_command(dest,16-1) ;buffer size 16 halfwords (per chip) FOR y=1 TO siz/2 [dest]=[src], dest=dest+2, src=src+2 ;write data to buffer NEXT y IF siz>2 THEN send_command(dest,D0h) ;confirm write to buffer IF wait_busy=okay THEN NEXT x enter_read_mode ;exit write/status mode |
[adr]=val IF turbo THEN [adr+2]=val |
send_command(8000000h,FFh) ;exit status mode send_command(8000000h,FFh) ;again maybe more stable (as in jeff's source) |
start=time REPEAT stat=[8000000h] XOR 80h IF turbo THEN stat=stat OR ([8000000h+2] XOR 80h) IF (stat AND 7Fh)>0 THEN error IF (stat AND 80h)=0 THEN ready IF time-start>5secs THEN timeout UNTIL ready OR error OR timeout IF error OR timeout THEN send_command(8000000h,50h) ;clear status |
[930ECA8h]=5354h [802468Ah]=1234h, repeated 500 times [800ECA8h]=5354h [802468Ah]=5354h [802468Ah]=5678h, repeated 500 times [930ECA8h]=5354h [802468Ah]=5354h [8ECA800h]=5678h [80268A0h]=1234h [802468Ah]=ABCDh, repeated 500 times [930ECA8h]=5354h [adr]=val |
configure_flashcard(942468Ah,???) |
ID Code Total Erase Write Name -??-00DCh ? ? ? Hudson Cart (???) 00160089h 4M 128K 32 Intel i28F320J3A (Flash Advance) 00170089h 8M 128K 32 Intel i28F640J3A (Flash Advance) 00180089h 16M 128K 32 Intel i28F128J3A (Flash Advance) 00E200B0h ? 64K 2 Sharp LH28F320BJE ? (Nintendo) |
| GBA Cheat Devices |
| GBA Cheat Codes - General Info |
| GBA Cheat Codes - Codebreaker/Xploder |
0000xxxx 000y Enable Code 1 - Game ID 1aaaaaaa 000z Enable Code 2 - Hook Address 2aaaaaaa yyyy [aaaaaaa]=[aaaaaaa] OR yyyy 3aaaaaaa 00yy [aaaaaaa]=yy 4aaaaaaa yyyy [aaaaaaa+0..(cccc-1)*ssss]=yyyy+0..(cccc-1)*ssss iiiicccc ssss parameters for above code 5aaaaaaa cccc [aaaaaaa+0..(cccc-1)]=11,22,33,44,etc. 11223344 5566 parameter bytes 1..6 for above code (example) 77880000 0000 parameter bytes 7..8 for above code (padded with zero) 6aaaaaaa yyyy [aaaaaaa]=[aaaaaaa] AND yyyy 7aaaaaaa yyyy IF [aaaaaaa]=yyyy THEN (next code) 8aaaaaaa yyyy [aaaaaaa]=yyyy 9xyyxxxx xxxx Enable Code 0 - Encrypt all following codes (optional) Aaaaaaaa yyyy IF [aaaaaaa]<>yyyy THEN (next code) Baaaaaaa yyyy IF [aaaaaaa]>yyyy THEN (next code) (signed comparison) Caaaaaaa yyyy IF [aaaaaaa]<yyyy THEN (next code) (signed comparison) D0000020 yyyy IF [joypad] AND yyyy = 0 THEN (next code) Eaaaaaaa yyyy [aaaaaaa]=[aaaaaaa]+yyyy Faaaaaaa yyyy IF [aaaaaaa] AND yyyy THEN (next code) |
crc=FFFFh for i=0 to FFFFh x=byte[i] xor (crc/100h) x=x xor (x/10h) crc=(crc*100h) xor (x*1001h) xor (x*20h) next i |
for i=0 to 2Fh, swaplist[i]=i, next i
randomizer = 1111h xor byte[code+4] ;LSB value
for i=0 to 4Fh
exchange swaplist[random MOD 30h] with swaplist[random MOD 30h]
next i
halfword[seedlist+0] = halfword[code+0] ;LSW address
randomizer = 4EFAD1C3h
for i=0 to byte[code+3]-91h, randomizer=random, next i ;MSB address
word[seedlist+2]=random, halfword[seedlist+6]=random
randomizer = F254h xor byte[code+5] ;MSB value
for i=0 to byte[code+5]-01h, randomizer=random, next i ;MSB value
word[seedlist+8]=random, halfword[seedlist+12]=random
;note: byte[code+2] = don't care
ret
|
randomizer=randomizer*41C64E6Dh+3039h, x=(randomizer SHL 14 AND C0000000h) randomizer=randomizer*41C64E6Dh+3039h, x=(randomizer SHR 1 AND 3FFF8000h)+x randomizer=randomizer*41C64E6Dh+3039h, x=(randomizer SHR 16 AND 00007FFFh)+x return(x) |
for i=2Fh to 0
j=swaplist[i]
bitno1=(i AND 7), index1=xlatlist[i/8]
bitno2=(j AND 7), index2=xlatlist[j/8]
exchange [code+index1].bitno1 with [code+index2].bitno2
next i
word[code+0] = word[code+0] xor word[seedlist+8]
i = (byte[code+3]*1010000h + byte[code+0]*100h + byte[code+5])
i = (halfword[code+1]*10001h) xor (word[seedlist+2]) xor i
i = (byte[seedlist+0]*1010101h) xor (byte[seedlist+1]*1000000h) xor i
j = (byte[code+5] + (byte[code+0] xor byte[code+4])*100h)
j = (byte[seedlist+0]*101h) xor halfword[seedlist+6] xor j
word[code+0] = i, halfword[code+4] = j
|
| GBA Cheat Codes - Gameshark/Action Replay V1/V2 |
0aaaaaaa 000000xx [aaaaaaa]=xx 1aaaaaaa 0000xxxx [aaaaaaa]=xxxx 2aaaaaaa xxxxxxxx [aaaaaaa]=xxxxxxxx 3000cccc xxxxxxxx write xxxxxxxx to (cccc-1) addresses (list in next codes) aaaaaaaa aaaaaaaa parameter for above code, containing two addresses each aaaaaaaa 00000000 last parameter for above, zero-padded if only one address 60aaaaaa y000xxxx [8000000h+aaaaaa*2]=xxxx (ROM Patch) 8a1aaaaa 000000xx IF GS_Button_Down THEN [a0aaaaa]=xx 8a2aaaaa 0000xxxx IF GS_Button_Down THEN [a0aaaaa]=xxxx 80F00000 0000xxxx IF GS_Button_Down THEN slowdown xxxx * ? cycles per hook Daaaaaaa 0000xxxx IF [aaaaaaa]=xxxx THEN (next code) E0zzxxxx 0aaaaaaa IF [aaaaaaa]=xxxx THEN (next 'zz' codes) Faaaaaaa 00000x0y Enable Code - Hook Routine xxxxxxxx 001DC0DE Enable Code - Game Code ID (value at [0ACh] in cartridge) DEADFACE 0000xxyy Change Encryption Seeds |
y=1 - Executes code handler without backing up the LR register. y=2 - Executes code handler and backs up the LR register. y=3 - Replaces a 32-bit pointer used for long-branches. x=0 - Must turn GSA off before loading game. x=1 - Must not do that. |
y=0 wait for the code handler to enable the patch y=1 patch is enabled before the game starts y=2 unknown ? |
FOR I=1 TO 32
A=A + (V*16+S0) XOR (V+I*9E3779B9h) XOR (V/32+S1)
V=V + (A*16+S2) XOR (A+I*9E3779B9h) XOR (A/32+S3)
NEXT I
|
S0=09F4FBBDh S1=9681884Ah S2=352027E9h S3=F3DEE5A7h |
FOR y=0 TO 3
FOR x=0 TO 3
z = T1[(xx+x) AND FFh] + T2[(yy+y) AND FFh]
Sy = Sy*100h + (z AND FFh)
NEXT x
NEXT y
|
| GBA Cheat Codes - Pro Action Replay V3 |
C4aaaaaa 0000yyyy Enable Code - Hook Routine at [8aaaaaa] xxxxxxxx 001DC0DE Enable Code - ID Code [080000AC] DEADFACE 0000xxxx Enable Code - Change Encryption Seeds 00aaaaaa xxxxxxyy [a0aaaaa..a0aaaaa+xxxxxx]=yy 02aaaaaa xxxxyyyy [a0aaaaa..a0aaaaa+xxxx*2]=yyyy 04aaaaaa yyyyyyyy [a0aaaaa]=yyyyyyyy 40aaaaaa xxxxxxyy [ [a0aaaaa] + xxxxxx ]=yy (Indirect) 42aaaaaa xxxxyyyy [ [a0aaaaa] + xxxx*2 ]=yyyy (Indirect) 44aaaaaa yyyyyyyy [ [a0aaaaa] ]=yyyyyyyy (Indirect) 80aaaaaa 000000yy [a0aaaaa]=[a0aaaaa]+yy 82aaaaaa 0000yyyy [a0aaaaa]=[a0aaaaa]+yyyy 84aaaaaa yyyyyyyy [a0aaaaa]=[a0aaaaa]+yyyyyyyy C6aaaaaa 0000yyyy [4aaaaaa]=yyyy (I/O Area) C7aaaaaa yyyyyyyy [4aaaaaa]=yyyyyyyy (I/O Area) iiaaaaaa yyyyyyyy IF [a0aaaaa] <cond> <value> THEN <action> 00000000 60000000 ELSE (?) 00000000 40000000 ENDIF (?) 00000000 0800xx00 AR Slowdown : loops the AR xx times 00000000 00000000 End of the code list 00000000 10aaaaaa 000000zz 00000000 IF AR_BUTTON THEN [a0aaaaa]=zz 00000000 12aaaaaa 0000zzzz 00000000 IF AR_BUTTON THEN [a0aaaaa]=zzzz 00000000 14aaaaaa zzzzzzzz 00000000 IF AR_BUTTON THEN [a0aaaaa]=zzzzzzzz 00000000 18aaaaaa 0000zzzz 00000000 [8000000+aaaaaa*2]=zzzz (ROM Patch 1) 00000000 1Aaaaaaa 0000zzzz 00000000 [8000000+aaaaaa*2]=zzzz (ROM Patch 2) 00000000 1Caaaaaa 0000zzzz 00000000 [8000000+aaaaaa*2]=zzzz (ROM Patch 3) 00000000 1Eaaaaaa 0000zzzz 00000000 [8000000+aaaaaa*2]=zzzz (ROM Patch 4) |
00000000 80aaaaaa 000000yy ssccssss repeat cc times [a0aaaaa]=yy (with yy=yy+ss, a0aaaaa=a0aaaaa+ssss after each step) |
00000000 82aaaaaa 0000yyyy ssccssss repeat cc times [a0aaaaa]=yyyy (with yyyy=yyyy+ss, a0aaaaa=a0aaaaa+ssss*2 after each step) |
00000000 84aaaaaa yyyyyyyy ssccssss repeat cc times [a0aaaaa]=yyyyyyyy (with yyyy=yyyy+ss, a0aaaaa=a0aaaaa+ssss*4 after each step) |
<cond> <value> <action> 08 Equal = 00 8bit zz 00 execute next code 10 Not equal <> 02 16bit zzzz 40 execute next two codes 18 Signed < 04 32bit zzzzzzzz 80 execute all following 20 Signed > 06 (always false) codes until ELSE or ENDIF 28 Unsigned < C0 normal ELSE turn off all codes 30 Unsigned > 38 Logical AND |
For the "Always..." codes: - XXXXXXXX can be any authorised address except 00000000 (eg. use 02000000). - ZZZZZZZZ can be anything. - The "y" in the code data must be in the [1-7] range (which means not 0). typ=y,sub=0,siz=3 Always skip next line. typ=y,sub=1,siz=3 Always skip next 2 lines. typ=y,sub=2,siz=3 Always Stops executing all the codes below. typ=y,sub=3,siz=3 Always turn off all codes. |
adr mask = 003FFFFF n/a mask = 00C00000 ;not used xtr mask = 01000000 ;used only by I/O write, and MSB of Hook siz mask = 06000000 typ mask = 38000000 ;0=normal, other=conditional sub mask = C0000000 |
S0=7AA9648Fh S1=7FAE6994h S2=C0EFAAD5h S3=42712C57h |
| GBA Gameboy Player |
Drill Dozer (supports BOTH handheld-rumble and GBP-rumble?) Mario & Luigi: Superstar Saga Pokemon Pinball: Ruby & Sapphire Shikakui Atama wo Marukusuru Advance: Kokugo Sansu Rika Shakai Shikakui Atama wo Marukusuru Advance: Kanji Keisan Summon Night Craft Sword Monogatari: Hajimari no Ishi Super Mario Advance 4: Super Mario Bros. 3 |
Remudvance (FluBBA) (homebrew) Goomba (FluBBA) (8bit Gameboy Color Emulator for 32bit GBA) (homebrew) and, supposedly in "Tetanus on Drugs" (Tepples) (homebrew) |
Receive Response 0000494E 494EB6B1 xxxx494E 494EB6B1 B6B1494E 544EB6B1 B6B1544E 544EABB1 ABB1544E 4E45ABB1 ABB14E45 4E45B1BA B1BA4E45 4F44B1BA B1BA4F44 4F44B0BB B0BB4F44 8000B0BB B0BB8002 10000010 10000010 20000013 20000013 40000004 30000003 40000004 30000003 40000004 30000003 40000004 30000003 400000yy 30000003 40000004 |
| GBA Backwards Compatibility CGB Mode |
4000000h.bit14 (DISPCNT) - enable BG2 aka CGB screen 4000000h.bit3 (DISPCNT) - prepare switch to CGB mode 4000301h (HALTCNT) - apply switch to CGB mode (and stop ARM forever?) 4000204h.bit15 (WAITCNT) - detect GBA/CGB cart type (and supply voltage) 4000800h.bit3 (UNDOC) - disable CGB bootrom 5000000h.bit0-15 - Palette Backdrop (screen border color) BG2X/BG2Y registers - CGB screen position within GBA screen BLDCNT/BLDY - can be used to tweak better CGB brightness sound BIAS and vol? - sound |
2000000h-200FFFFh.bit0-15 unused ;\ 2010000h-2011FFEh.bit0-7 mapped to C000h-CFFFh ; 2012000h-2013FFEh.bit0-7 mapped to 1:D000h-DFFFh ; GBA Main RAM halfwords 2014000h-2015FFEh.bit0-7 mapped to 2:D000h-DFFFh ; used as 32K CGB WRAM 2016000h-2017FFEh.bit0-7 mapped to 3:D000h-DFFFh ; 2018000h-2019FFEh.bit0-7 mapped to 4:D000h-DFFFh ; 201A000h-201BFFEh.bit0-7 mapped to 5:D000h-DFFFh ; 201C000h-201DFFEh.bit0-7 mapped to 6:D000h-DFFFh ; 201E000h-201FFFEh.bit0-7 mapped to 7:D000h-DFFFh ; 2010001h-201FFFFh.bit8-15 unused (halfword.msbs) ; 2020000h-203FFFFh.bit0-15 unused ;/ 3000000h-3003FFFh.bit0-7 mapped to 0:8000h-8FFFh ;\ 3000000h-3003FFFh.bit8-15 mapped to 0:9000h-9FFFh ; GBA Fast WRAM words 3000000h-3003FFFh.bit16-23 mapped to 1:8000h-8FFFh ; used as 16K CGB VRAM 3000000h-3003FFFh.bit24-31 mapped to 1:9000h-9FFFh ; 3004000h-3007FFFh.bit0-31 unused ;/ |
| GBA Unpredictable Things |
WORD = [$+8] |
LSW = [$+4], MSW = [$+4] |
LSW = [$+4], MSW = [$+6] ;for opcodes at 4-byte aligned locations LSW = [$+2], MSW = [$+4] ;for opcodes at non-4-byte aligned locations |
LSW = [$+4], MSW = OldHI ;for opcodes at 4-byte aligned locations LSW = OldLO, MSW = [$+4] ;for opcodes at non-4-byte aligned locations |
OldLO=[$+2], OldHI=[$+2] |
OldLO=LSW(data), OldHI=MSW(data) Theoretically, this might also change if a DMA transfer occurs. |
| NDS Reference |
| DS Technical Data |
1x ARM946E-S 32bit RISC CPU, 66MHz (NDS9 video) (not used in GBA mode) 1x ARM7TDMI 32bit RISC CPU, 33MHz (NDS7 sound) (16MHz in GBA mode) |
4096KB Main RAM (8192KB in debug version) 96KB WRAM (64K mapped to NDS7, plus 32K mappable to NDS7 or NDS9) 60KB TCM/Cache (TCM: 16K Data, 32K Code) (Cache: 4K Data, 8K Code) 656KB VRAM (allocateable as BG/OBJ/2D/3D/Palette/Texture/WRAM memory) 4KB OAM/PAL (2K OBJ Attribute Memory, 2K Standard Palette RAM) 248KB Internal 3D Memory (104K Polygon RAM, 144K Vertex RAM) ?KB Matrix Stack, 48 scanline cache 8KB Wifi RAM 256KB Firmware FLASH (512KB in iQue variant, with chinese charset) 36KB BIOS ROM (4K NDS9, 16K NDS7, 16K GBA) |
2x LCD screens (each 256x192 pixel, 3 inch, 18bit color depth, backlight) 2x 2D video engines (extended variants of the GBA's video controller) 1x 3D video engine (can be assigned to upper or lower screen) 1x video capture (for effects, or for forwarding 3D to the 2nd 2D engine) |
16 sound channels (16x PCM8/PCM16/IMA-ADPCM, 6x PSG-Wave, 2x PSG-Noise) 2 sound capture units (for echo effects, etc.) Output: Two built-in stereo speakers, and headphones socket Input: One built-in microphone, and microphone socket |
Gamepad 4 Direction Keys, 8 Buttons Touchscreen (on lower LCD screen) |
Wifi IEEE802.11b |
Built-in Real Time Clock Power Managment Device Hardware divide and square root functions CP15 System Control Coprocessor (cache, tcm, pu, bist, etc.) |
NDS Slot (for NDS games) (encrypted 8bit data bus, and serial 1bit bus) GBA Slot (for NDS expansions, or for GBA games) (but not for DMG/CGB games) |
ROM: 16MB, 32MB, or 64MB EEPROM/FLASH/FRAM: 0.5KB, 8KB, 64KB, 256KB, or 512KB |
NDS Cartridge (NDS mode) Firmware FLASH (NDS mode) (eg. by patching firmware via ds-xboo cable) Wifi (NDS mode) GBA Cartridge (GBA mode) (without DMG/CGB support) (without SIO support) |
Built-in rechargeable Lithium ion battery, 3.7V 1000mAh (DS-Lite) External Supply: 5.2V DC |
| DS I/O Maps |
4000000h 4 2D Engine A - DISPCNT - LCD Control (Read/Write) 4000004h 2 2D Engine A+B - DISPSTAT - General LCD Status (Read/Write) 4000006h 2 2D Engine A+B - VCOUNT - Vertical Counter (Read only) 4000008h 50h 2D Engine A (same registers as GBA, some changed bits) 4000060h 2 DISP3DCNT - 3D Display Control Register (R/W) 4000064h 4 DISPCAPCNT - Display Capture Control Register (R/W) 4000068h 4 DISP_MMEM_FIFO - Main Memory Display FIFO (R?/W) 400006Ch 2 2D Engine A - MASTER_BRIGHT - Master Brightness Up/Down |
40000B0h 30h DMA Channel 0..3 40000E0h 10h DMA FILL Registers for Channel 0..3 4000100h 10h Timers 0..3 4000130h 2 KEYINPUT 4000132h 2 KEYCNT |
4000180h 2 IPCSYNC - IPC Synchronize Register (R/W) 4000184h 2 IPCFIFOCNT - IPC Fifo Control Register (R/W) 4000188h 4 IPCFIFOSEND - IPC Send Fifo (W) 40001A0h 2 AUXSPICNT - Gamecard ROM and SPI Control 40001A2h 2 AUXSPIDATA - Gamecard SPI Bus Data/Strobe 40001A4h 4 Gamecard bus timing/control 40001A8h 8 Gamecard bus 8-byte command out 40001B0h 4 Gamecard Encryption Seed 0 Lower 32bit 40001B4h 4 Gamecard Encryption Seed 1 Lower 32bit 40001B8h 2 Gamecard Encryption Seed 0 Upper 7bit (bit7-15 unused) 40001BAh 2 Gamecard Encryption Seed 1 Upper 7bit (bit7-15 unused) |
4000204h 2 EXMEMCNT - External Memory Control (R/W) 4000208h 2 IME - Interrupt Master Enable (R/W) 4000210h 4 IE - Interrupt Enable (R/W) 4000214h 4 IF - Interrupt Request Flags (R/W) 4000240h 1 VRAMCNT_A - VRAM-A (128K) Bank Control (W) 4000241h 1 VRAMCNT_B - VRAM-B (128K) Bank Control (W) 4000242h 1 VRAMCNT_C - VRAM-C (128K) Bank Control (W) 4000243h 1 VRAMCNT_D - VRAM-D (128K) Bank Control (W) 4000244h 1 VRAMCNT_E - VRAM-E (64K) Bank Control (W) 4000245h 1 VRAMCNT_F - VRAM-F (16K) Bank Control (W) 4000246h 1 VRAMCNT_G - VRAM-G (16K) Bank Control (W) 4000247h 1 WRAMCNT - WRAM Bank Control (W) 4000248h 1 VRAMCNT_H - VRAM-H (32K) Bank Control (W) 4000249h 1 VRAMCNT_I - VRAM-I (16K) Bank Control (W) |
4000280h 2 DIVCNT - Division Control (R/W) 4000290h 8 DIV_NUMER - Division Numerator (R/W) 4000298h 8 DIV_DENOM - Division Denominator (R/W) 40002A0h 8 DIV_RESULT - Division Quotient (=Numer/Denom) (R) 40002A8h 8 DIVREM_RESULT - Division Remainder (=Numer MOD Denom) (R) 40002B0h 2 SQRTCNT - Square Root Control (R/W) 40002B4h 4 SQRT_RESULT - Square Root Result (R) 40002B8h 8 SQRT_PARAM - Square Root Parameter Input (R/W) 4000300h 4 POSTFLG - Undoc 4000304h 2 POWCNT1 - Graphics Power Control Register (R/W) |
4000320h..6A3h |
4001000h 4 2D Engine B - DISPCNT - LCD Control (Read/Write) 4001008h 50h 2D Engine B (same registers as GBA, some changed bits) 400106Ch 2 2D Engine B - MASTER_BRIGHT - 16bit - Brightness Up/Down |
40021Axh .. DSi Registers 4004xxxh .. DSi Registers |
4100000h 4 IPCFIFORECV - IPC Receive Fifo (R) 4100010h 4 Gamecard bus 4-byte data in, for manual or dma read (R) (or W) |
4FFF0xxh .. Ensata Emulator Debug Registers 4FFFAxxh .. No$gba Emulator Debug Registers |
27FFD9Ch .. NDS9 Debug Stacktop / Debug Vector (0=None) DTCM+3FF8h 4 NDS9 IRQ Check Bits (hardcoded RAM address) DTCM+3FFCh 4 NDS9 IRQ Handler (hardcoded RAM address) |
27FFFFEh 2 Main Memory Control |
4000004h 2 DISPSTAT 4000006h 2 VCOUNT 40000B0h 30h DMA Channels 0..3 4000100h 10h Timers 0..3 4000120h 4 Debug SIODATA32 4000128h 4 Debug SIOCNT 4000130h 2 KEYINPUT 4000132h 2 KEYCNT 4000134h 2 Debug RCNT 4000136h 2 EXTKEYIN 4000138h 1 RTC Realtime Clock Bus 4000180h 2 IPCSYNC - IPC Synchronize Register (R/W) 4000184h 2 IPCFIFOCNT - IPC Fifo Control Register (R/W) 4000188h 4 IPCFIFOSEND - IPC Send Fifo (W) 40001A0h 2 AUXSPICNT - Gamecard ROM and SPI Control 40001A2h 2 AUXSPIDATA - Gamecard SPI Bus Data/Strobe 40001A4h 4 Gamecard bus timing/control 40001A8h 8 Gamecard bus 8-byte command out 40001B0h 4 Gamecard Encryption Seed 0 Lower 32bit 40001B4h 4 Gamecard Encryption Seed 1 Lower 32bit 40001B8h 2 Gamecard Encryption Seed 0 Upper 7bit (bit7-15 unused) 40001BAh 2 Gamecard Encryption Seed 1 Upper 7bit (bit7-15 unused) 40001C0h 2 SPI bus Control (Firmware, Touchscreen, Powerman) 40001C2h 2 SPI bus Data |
4000204h 2 EXMEMSTAT - External Memory Status 4000206h 2 WIFIWAITCNT 4000208h 4 IME - Interrupt Master Enable (R/W) 4000210h 4 IE - Interrupt Enable (R/W) 4000214h 4 IF - Interrupt Request Flags (R/W) 4000218h - IE2 ;\DSi only (additional ARM7 interrupt sources) 400021Ch - IF2 ;/ 4000240h 1 VRAMSTAT - VRAM-C,D Bank Status (R) 4000241h 1 WRAMSTAT - WRAM Bank Status (R) 4000300h 1 POSTFLG 4000301h 1 HALTCNT (different bits than on GBA) (plus NOP delay) 4000304h 2 POWCNT2 Sound/Wifi Power Control Register (R/W) 4000308h 4 BIOSPROT - Bios-data-read-protection address |
4000400h 100h Sound Channel 0..15 (10h bytes each) 40004x0h 4 SOUNDxCNT - Sound Channel X Control Register (R/W) 40004x4h 4 SOUNDxSAD - Sound Channel X Data Source Register (W) 40004x8h 2 SOUNDxTMR - Sound Channel X Timer Register (W) 40004xAh 2 SOUNDxPNT - Sound Channel X Loopstart Register (W) 40004xCh 4 SOUNDxLEN - Sound Channel X Length Register (W) 4000500h 2 SOUNDCNT - Sound Control Register (R/W) 4000504h 2 SOUNDBIAS - Sound Bias Register (R/W) 4000508h 1 SNDCAP0CNT - Sound Capture 0 Control Register (R/W) 4000509h 1 SNDCAP1CNT - Sound Capture 1 Control Register (R/W) 4000510h 4 SNDCAP0DAD - Sound Capture 0 Destination Address (R/W) 4000514h 2 SNDCAP0LEN - Sound Capture 0 Length (W) 4000518h 4 SNDCAP1DAD - Sound Capture 1 Destination Address (R/W) 400051Ch 2 SNDCAP1LEN - Sound Capture 1 Length (W) |
40021Axh .. DSi Registers 4004xxxh .. DSi Registers 4004700h 2 DSi SNDEXCNT Register ;\mapped even in DS mode 4004C0xh .. DSi GPIO Registers ;/ |
4100000h 4 IPCFIFORECV - IPC Receive Fifo (R) 4100010h 4 Gamecard bus 4-byte data in, for manual or dma read (R) (or W) |
4700000h 4 Disable ARM7 bootrom overlay (W) (3DS only) |
4800000h .. Wifi WS0 Region (32K) (Wifi Ports, and 8K Wifi RAM) 4808000h .. Wifi WS1 Region (32K) (mirror of above, other waitstates) |
380FFC0h 4 DSi7 IRQ IF2 Check Bits (hardcoded RAM address) (DSi only) 380FFDCh .. NDS7 Debug Stacktop / Debug Vector (0=None) 380FFF8h 4 NDS7 IRQ IF Check Bits (hardcoded RAM address) 380FFFCh 4 NDS7 IRQ Handler (hardcoded RAM address) |
| DS Memory Maps |
00000000h Instruction TCM (32KB) (not moveable) (mirror-able to 1000000h) 0xxxx000h Data TCM (16KB) (moveable) 02000000h Main Memory (4MB) 03000000h Shared WRAM (0KB, 16KB, or 32KB can be allocated to ARM9) 04000000h ARM9-I/O Ports 05000000h Standard Palettes (2KB) (Engine A BG/OBJ, Engine B BG/OBJ) 06000000h VRAM - Engine A, BG VRAM (max 512KB) 06200000h VRAM - Engine B, BG VRAM (max 128KB) 06400000h VRAM - Engine A, OBJ VRAM (max 256KB) 06600000h VRAM - Engine B, OBJ VRAM (max 128KB) 06800000h VRAM - "LCDC"-allocated (max 656KB) 07000000h OAM (2KB) (Engine A, Engine B) 08000000h GBA Slot ROM (max 32MB) 0A000000h GBA Slot RAM (max 64KB) FFFF0000h ARM9-BIOS (32KB) (only 3K used) |
00000000h ARM7-BIOS (16KB) 02000000h Main Memory (4MB) 03000000h Shared WRAM (0KB, 16KB, or 32KB can be allocated to ARM7) 03800000h ARM7-WRAM (64KB) 04000000h ARM7-I/O Ports 04800000h Wireless Communications Wait State 0 (8KB RAM at 4804000h) 04808000h Wireless Communications Wait State 1 (I/O Ports at 4808000h) 06000000h VRAM allocated as Work RAM to ARM7 (max 256K) 08000000h GBA Slot ROM (max 32MB) 0A000000h GBA Slot RAM (max 64KB) |
3D Engine Polygon RAM (52KBx2) 3D Engine Vertex RAM (72KBx2) Firmware (256KB) (built-in serial flash memory) GBA-BIOS (16KB) (not used in NDS mode) NDS Slot ROM (serial 8bit-bus, max 4GB with default protocol) NDS Slot FLASH/EEPROM/FRAM (serial 1bit-bus) |
| DS Memory Control |
| DS Memory Control - Cache and TCM |
ITCM 32K, base=00000000h (fixed, not move-able) DTCM 16K, base=moveable (default base=27C0000h) |
Data Cache 4KB, Instruction Cache 8KB 4-way set associative method Cache line 8 words (32 bytes) Read-allocate method (ie. writes are not allocating cache lines) Round-robin and Pseudo-random replacement algorithms selectable Cache Lockdown, Instruction Prefetch, Data Preload Data write-through and write-back modes selectable |
Region Name Address Size Cache WBuf Code Data - Background 00000000h 4GB - - - - 0 I/O and VRAM 04000000h 64MB - - R/W R/W 1 Main Memory 02000000h 4MB On On R/W R/W 2 ARM7-dedicated 027C0000h 256KB - - - - 3 GBA Slot 08000000h 128MB - - - R/W 4 DTCM 027C0000h 16KB - - - R/W 5 ITCM 01000000h 32KB - - R/W R/W 6 BIOS FFFF0000h 32KB On - R R 7 Shared Work 027FF000h 4KB - - - R/W |
| DS Memory Control - Cartridges and Main RAM |
0-1 32-pin GBA Slot SRAM Access Time (0-3 = 10, 8, 6, 18 cycles) 2-3 32-pin GBA Slot ROM 1st Access Time (0-3 = 10, 8, 6, 18 cycles) 4 32-pin GBA Slot ROM 2nd Access Time (0-1 = 6, 4 cycles) 5-6 32-pin GBA Slot PHI-pin out (0-3 = Low, 4.19MHz, 8.38MHz, 16.76MHz) 7 32-pin GBA Slot Access Rights (0=ARM9, 1=ARM7) 8-10 Not used (always zero) 11 17-pin NDS Slot Access Rights (0=ARM9, 1=ARM7) 12 Not used (always zero) 13 NDS:Always set? ;set/tested by DSi bootcode: Main RAM enable, CE2 pin? 14 Main Memory Interface Mode Switch (0=Async/GBA/Reserved, 1=Synchronous) 15 Main Memory Access Priority (0=ARM9 Priority, 1=ARM7 Priority) |
6 clks --> returns "Addr/2" 8 clks --> returns "Addr/2" 10 clks --> returns "Addr/2 OR FE08h" (or similar garbage) 18 clks --> returns "FFFFh" (High-Z) |
| DS Memory Control - WRAM |
0-1 ARM9/ARM7 (0-3 = 32K/0K, 2nd 16K/1st 16K, 1st 16K/2nd 16K, 0K/32K) 2-7 Not used |
| DS Memory Control - VRAM |
0 VRAM C enabled and allocated to NDS7 (0=No, 1=Yes) 1 VRAM D enabled and allocated to NDS7 (0=No, 1=Yes) 2-7 Not used (always zero) |
0-2 VRAM MST ;Bit2 not used by VRAM-A,B,H,I 3-4 VRAM Offset (0-3) ;Offset not used by VRAM-E,H,I 5-6 Not used 7 VRAM Enable (0=Disable, 1=Enable) |
VRAM SIZE MST OFS ARM9, Plain ARM9-CPU Access (so-called LCDC mode) A 128K 0 - 6800000h-681FFFFh B 128K 0 - 6820000h-683FFFFh C 128K 0 - 6840000h-685FFFFh D 128K 0 - 6860000h-687FFFFh E 64K 0 - 6880000h-688FFFFh F 16K 0 - 6890000h-6893FFFh G 16K 0 - 6894000h-6897FFFh H 32K 0 - 6898000h-689FFFFh I 16K 0 - 68A0000h-68A3FFFh VRAM SIZE MST OFS ARM9, 2D Graphics Engine A, BG-VRAM (max 512K) A,B,C,D 128K 1 0..3 6000000h+(20000h*OFS) E 64K 1 - 6000000h F,G 16K 1 0..3 6000000h+(4000h*OFS.0)+(10000h*OFS.1) VRAM SIZE MST OFS ARM9, 2D Graphics Engine A, OBJ-VRAM (max 256K) A,B 128K 2 0..1 6400000h+(20000h*OFS.0) ;(OFS.1 must be zero) E 64K 2 - 6400000h F,G 16K 2 0..3 6400000h+(4000h*OFS.0)+(10000h*OFS.1) VRAM SIZE MST OFS 2D Graphics Engine A, BG Extended Palette E 64K 4 - Slot 0-3 ;only lower 32K used F,G 16K 4 0..1 Slot 0-1 (OFS=0), Slot 2-3 (OFS=1) VRAM SIZE MST OFS 2D Graphics Engine A, OBJ Extended Palette F,G 16K 5 - Slot 0 ;16K each (only lower 8K used) VRAM SIZE MST OFS Texture/Rear-plane Image A,B,C,D 128K 3 0..3 Slot OFS(0-3) ;(Slot2-3: Texture, or Rear-plane) VRAM SIZE MST OFS Texture Palette E 64K 3 - Slots 0-3 ;OFS=don't care F,G 16K 3 0..3 Slot (OFS.0*1)+(OFS.1*4) ;ie. Slot 0, 1, 4, or 5 VRAM SIZE MST OFS ARM9, 2D Graphics Engine B, BG-VRAM (max 128K) C 128K 4 - 6200000h H 32K 1 - 6200000h I 16K 1 - 6208000h VRAM SIZE MST OFS ARM9, 2D Graphics Engine B, OBJ-VRAM (max 128K) D 128K 4 - 6600000h I 16K 2 - 6600000h VRAM SIZE MST OFS 2D Graphics Engine B, BG Extended Palette H 32K 2 - Slot 0-3 VRAM SIZE MST OFS 2D Graphics Engine B, OBJ Extended Palette I 16K 3 - Slot 0 ;(only lower 8K used) VRAM SIZE MST OFS <ARM7>, Plain <ARM7>-CPU Access C,D 128K 2 0..1 6000000h+(20000h*OFS.0) ;OFS.1 must be zero |
5000000h Engine A Standard BG Palette (512 bytes) 5000200h Engine A Standard OBJ Palette (512 bytes) 5000400h Engine B Standard BG Palette (512 bytes) 5000600h Engine B Standard OBJ Palette (512 bytes) 7000000h Engine A OAM (1024 bytes) 7000400h Engine B OAM (1024 bytes) |
| DS Memory Control - BIOS |
Opcodes at... Can read from Expl. 0..[BIOSPROT]-1 0..3FFFh Double-protected (when BIOSPROT is set) [BIOSPROT]..3FFFh [BIOSPROT]..3FFFh Normal-protected (always active) |
05ECh ldrb r3,[r3,12h] ;requires incoming r3=src-12h 05EEh pop r2,r4,r6,r7,r15 ;requires dummy values & THUMB retadr on stack |
| DS Memory Timings |
Bus clock = 33MHz (33.513982 MHz) (1FF61FEh Hertz) NDS7 clock = 33MHz (same as bus clock) NDS9 clock = 66MHz (internally twice bus clock; for cache/tcm) |
NDS7/CODE NDS9/CODE N32 S32 N16 S16 Bus N32 S32 N16 S16 Bus 9 2 8 1 16 9 9 4.5 4.5 16 Main RAM (read) (cache off) 1 1 1 1 32 4 4 2 2 32 WRAM,BIOS,I/O,OAM 2 2 1 1 16 5 5 2.5 2.5 16 VRAM,Palette RAM 16 12 10 6 16 19 19 9.5 9.5 16 GBA ROM (example 10,6 access) - - - - - 0.5 0.5 0.5 0.5 32 TCM, Cache_Hit - - - - - (--Load 8 words--) Cache_Miss |
NDS7/DATA NDS9/DATA N32 S32 N16 S16 Bus N32 S32 N16 S16 Bus 10 2 9 1 16 10 2 9 1 16 Main RAM (read) (cache off) 1 1 1 1 32 4 1 4 1 32 WRAM,BIOS,I/O,OAM 1? 2 1 1 16 5 2 4 1 16 VRAM,Palette RAM 15 12 9 6 16 19 12 13 6 16 GBA ROM (example 10,6 access) 9 10 9 10 8 13 10 13 10 8 GBA RAM (example 10 access) - - - - - 0.5 0.5 0.5 - 32 TCM, Cache_Hit - - - - - (--Load 8 words--) Cache_Miss - - - - - 11 11 11 - 32 Cache_Miss (BIOS) - - - - - 23 23 23 - 16 Cache_Miss (Main RAM) |
S16 and N16 do not exist (because thumb-double-fetching) (see there). S32 becomes N32 (ie. the ARM9 does NOT support fast sequential timing). |
Eg. an ARM9 N32 or S32 to 16bit bus will take: N16 + S16 + 3 waits. Eg. an ARM9 N32 or S32 to 32bit bus will take: N32 + 3 waits. |
Eg. LDRH on 16bit-data-bus is N16+3waits. Eg. LDR on 16bit-data-bus is N16+S16+3waits. Eg. LDM on 16bit-data-bus is N16+(n*2-1)*S16+3waits. |
That is NOT true for LDM (works only for LDR/LDRB/LDRH). That is NOT true for DATA in SAME memory region than CODE. That is NOT true for DATA in ITCM (no matter if CODE is in ITCM). |
| DS Video |
| DS Video Stuff |
0-4 Factor used for 6bit R,G,B Intensities (0-16, values >16 same as 16)
Brightness up: New = Old + (63-Old) * Factor/16
Brightness down: New = Old - Old * Factor/16
5-13 Not used
14-15 Mode (0=Disable, 1=Up, 2=Down, 3=Reserved)
16-31 Not used
|
write new LY values only in range of 202..212 write only while old LY values are in range of 202..212 |
Region______Engine A______________Engine B___________ I/O Ports 4000000h 4001000h Palette 5000000h (1K) 5000400h (1K) BG VRAM 6000000h (max 512K) 6200000h (max 128K) OBJ VRAM 6400000h (max 256K) 6600000h (max 128K) OAM 7000000h (1K) 7000400h (1K) |
Bit0-3 "COMMAND" (?) Bit4-7 "COMMAND2" (?) Bit8-11 "COMMAND3" (?) |
| DS Video BG Modes / Control |
Bit Engine Expl. 0-2 A+B BG Mode 3 A BG0 2D/3D Selection (instead CGB Mode) (0=2D, 1=3D) 4 A+B Tile OBJ Mapping (0=2D; max 32KB, 1=1D; max 32KB..256KB) 5 A+B Bitmap OBJ 2D-Dimension (0=128x512 dots, 1=256x256 dots) 6 A+B Bitmap OBJ Mapping (0=2D; max 128KB, 1=1D; max 128KB..256KB) 7-15 A+B Same as GBA 16-17 A+B Display Mode (Engine A: 0..3, Engine B: 0..1, GBA: Green Swap) 18-19 A VRAM block (0..3=VRAM A..D) (For Capture & above Display Mode=2) 20-21 A+B Tile OBJ 1D-Boundary (see Bit4) 22 A Bitmap OBJ 1D-Boundary (see Bit5-6) 23 A+B OBJ Processing during H-Blank (was located in Bit5 on GBA) 24-26 A Character Base (in 64K steps) (merged with 16K step in BGxCNT) 27-29 A Screen Base (in 64K steps) (merged with 2K step in BGxCNT) 30 A+B BG Extended Palettes (0=Disable, 1=Enable) 31 A+B OBJ Extended Palettes (0=Disable, 1=Enable) |
Mode BG0 BG1 BG2 BG3 0 Text/3D Text Text Text 1 Text/3D Text Text Affine 2 Text/3D Text Affine Affine 3 Text/3D Text Text Extended 4 Text/3D Text Affine Extended 5 Text/3D Text Extended Extended 6 3D - Large - |
BGxCNT.Bit7 BGxCNT.Bit2 Extended Affine Mode Selection 0 CharBaseLsb rot/scal with 16bit bgmap entries (Text+Affine mixup) 1 0 rot/scal 256 color bitmap 1 1 rot/scal direct color bitmap |
0 Display off (screen becomes white) 1 Graphics Display (normal BG and OBJ layers) 2 Engine A only: VRAM Display (Bitmap from block selected in DISPCNT.18-19) 3 Engine A only: Main Memory Display (Bitmap DMA transfer from Main RAM) |
engine A screen base: BGxCNT.bits*2K + DISPCNT.bits*64K engine B screen base: BGxCNT.bits*2K + 0 engine A char base: BGxCNT.bits*16K + DISPCNT.bits*64K engine B char base: BGxCNT.bits*16K + 0 |
bgcnt size text rotscal bitmap large bmp 0 256x256 128x128 128x128 512x1024 1 512x256 256x256 256x256 1024x512 2 256x512 512x512 512x256 - 3 512x512 1024x1024 512x512 - |
for BG0CNT, BG1CNT only: bit13 selects extended palette slot
(BG0: 0=Slot0, 1=Slot2, BG1: 0=Slot1, 1=Slot3)
|
| DS Video OBJs |
Bit4 Bit20-21 Dimension Boundary Total ;Notes 0 x 2D 32 32K ;Same as GBA 2D Mapping 1 0 1D 32 32K ;Same as GBA 1D Mapping 1 1 1D 64 64K 1 2 1D 128 128K 1 3 1D 256 256K ;Engine B: 128K max |
Bit6 Bit5 Bit22 Dimension Boundary Total ;Notes 0 0 x 2D/128 dots 8x8 dots 128K ;Source Bitmap width 128 dots 0 1 x 2D/256 dots 8x8 dots 128K ;Source Bitmap width 256 dots 1 0 0 1D 128 bytes 128K ;Source Width = Target Width 1 0 1 1D 256 bytes 256K ;Engine A only 1 1 x Reserved |
1D_BitmapVramAddress = TileNumber(0..3FFh) * BoundaryValue(128..256) 2D_BitmapVramAddress = (TileNo AND MaskX)*10h + (TileNo AND NOT MaskX)*80h |
| DS Video Extended Palettes |
standard palette --> 16-color tiles (with 16bit bgmap entries) (text)
256-color tiles (with 8bit bgmap entries) (rot/scal)
256-color bitmaps
backdrop-color (color 0)
extended palette --> 256-color tiles (with 16bit bgmap entries)(text,rot/scal)
|
16 colors x 16 palettes --> standard palette memory (=256 colors) 256 colors x 16 palettes --> extended palette memory (=4096 colors) |
| DS Video Capture and Main Memory Display Mode |
0-4 EVA (0..16 = Blending Factor for Source A) 5-7 Not used 8-12 EVB (0..16 = Blending Factor for Source B) 13-15 Not used 16-17 VRAM Write Block (0..3 = VRAM A..D) (VRAM must be allocated to LCDC) 18-19 VRAM Write Offset (0=00000h, 0=08000h, 0=10000h, 0=18000h) 20-21 Capture Size (0=128x128, 1=256x64, 2=256x128, 3=256x192 dots) 22-23 Not used 24 Source A (0=Graphics Screen BG+3D+OBJ, 1=3D Screen) 25 Source B (0=VRAM, 1=Main Memory Display FIFO) 26-27 VRAM Read Offset (0=00000h, 0=08000h, 0=10000h, 0=18000h) 28 Not used 29-30 Capture Source (0=Source A, 1=Source B, 2/3=Sources A+B blended) 31 Capture Enable (0=Disable/Ready, 1=Enable/Busy) |
Dest_Intensity = ( (SrcA_Intensitity * SrcA_Alpha * EVA)
+ (SrcB_Intensitity * SrcB_Alpha * EVB) ) / 16
Dest_Alpha = (SrcA_Alpha AND (EVA>0)) OR (SrcB_Alpha AND EVB>0))
|
- to Screen A (set DISPCNT to Main Memory Display mode), or - to Display Capture unit (set DISPCAPCNT to Main Memory Source). |
| DS Video Display System Block Diagram |
_____________ __________
VRAM A -->| 2D Graphics |--------OBJ->| |
VRAM B -->| Engine A |--------BG3->| Layering |
VRAM C -->| |--------BG2->| and |
VRAM D -->| |--------BG1->| Special |
VRAM E -->| | ___ | Effects |
VRAM F -->| |->|SEL| | | ______
VRAM G -->| - - - - - - | |BG0|-BG0->| |----o--->| |
| 3D Graphics |->|___| |__________| | |Select|
| Engine | | |Video |
|_____________|--------3D----------------. | |Input |
_______ _______ ___ | | | |
| | | |<-----------|SEL|<-' | |and |-->
| | | | _____ |A | | | |
VRAM A <--|Select | |Select | | |<-|___|<----' |Master|
VRAM B <--|Capture|<---|Capture|<--|Blend| ___ |Bright|
VRAM C <--|Dest. | |Source | |_____|<-|SEL|<----. |A |
VRAM D <--| | | | |B | | | |
|_______| |_______|<-----------|___|<-. | | |
_______ | | | |
VRAM A -->|Select | | | | |
VRAM B -->|Display|--------------------------------o------>| |
VRAM C -->|VRAM | | | |
VRAM D -->|_______| _____________ | | |
|Main Memory | | | |
Main ------DMA---->|Display FIFO |------------------o--->|______|
Memory |_____________|
_____________ __________ ______
VRAM C -->| 2D Graphics |--------OBJ->| Layering | | |
VRAM D -->| Engine B |--------BG3->| and | |Master|
VRAM H -->| |--------BG2->| Special |-------->|Bright|-->
VRAM I -->| |--------BG1->| Effects | |B |
|_____________|--------BG0->|__________| |______|
|
| DS Files - 2D Video |
____________________________ Nitro Color Palette _____________________________ |
000h 4 Chunk ID "RLCN" (aka NCLR backwards, Nitro Color Resource) 004h 2 Byte Order (FEFFh) 006h 2 Version (0100h) 008h 4 Total Filesize 00Ch 2 Offset to "TTLP" Chunk, aka Size of "RLCN" Chunk (0010h) 00Eh 2 Total number of following Chunks (1=TTLP) (or 2=TTLP+PMCP ?) |
000h 4 Chunk ID "TTLP" (aka PLTT backwards, Palette data) 004h 4 Chunk Size (eg. 0218h) 008h 4 Reportedly Color Depth (ie. "tile usage info") (3=4bpp, 4=8bpp) 00Ch 4 Zero 010h 4 Palette Data Size in bytes (eg. 200h) (or 200h-N? no, blah!) 014h 4 Offset from TTLP+8 to Palette Data? (always 10h) 018h N*2 Palete Data (16bit colors, 0000h..7FFFh) |
000h 4 Chunk ID "PMCP" (aka PCMP backwards, Palette CMP?) 004h 4 Chunk Size (reportedly always 12h ???) 008h 2 Number of palettes in file (uh?) 00Ah 2 Unused (BEEFh=Bullshit) 00Ch 4 Offset from PMCP+8 to Palette IDs? (always 08h) DATA N*2 "Palette ID numbers for each palette (starting from 0)" |
___________________________ Nitro Character Tiles ____________________________ |
eg. DSi Launcher "rom:\debug\DebugFont.NCGR" -- with SOPC chunk eg. DSi Launcher "rom:\layout\cmn\launcher_d.szs\.." -- without SOPC chunk |
000h 4 Chunk ID "RGCN" (aka NCGR backwards, Nitro Char Graphics Resource) 004h 2 Byte Order (FEFFh) 006h 2 Version (0101h) (unknown if 0100h does also exist?) 008h 4 Total Filesize 00Ch 2 Offset to "RAHC" Chunk, aka Size of "RGCN" Chunk (0010h) 00Eh 2 Total number of following Chunks (1=RAHC, or 2=RAHC+SOPC) |
000h 4 Chunk ID "RAHC" (aka CHAR backwards) 004h 4 Chunk Size (eg. 1420h) 008h 2 Tile Data Size in Kilobytes ;\or both set to FFFFh 00Ah 2 Unknown (always 20h) ;/(when size<>N*1024) 00Ch 4 Color Depth (3=4bpp, 4=8bpp) 010h 2 Zero ;or 10h (when SOPC not exists? kbyte size rounded up?) 012h 2 Zero ;or 20h (when SOPC not exists?) 014h 4 Zero 018h 4 Tile Data Size in Bytes (eg. 1400h) 01Ch 4 Offset from RAHC+8 to Tile Data? ;=always 18h 020h ... Tile Data (eg. 20h-byte zerofilled for 4bpp SPC char?) |
000h 4 Chunk ID "SOPC" (aka CPOS backwards) 004h 4 Chunk Size (10h) 008h 4 Zero 00Ch 2 Same as [00Ah] in RAHC chunk? (always 20h) 00Eh 2 Same as [008h] in RAHC chunk? (size in kilobytes) |
__________________________ Unknown Character Tiles ___________________________ |
NCGR (Nitro Character Graphic Resource) - Graphical Tiles --> see above NBGR (Nitro Basic Graphic Resource) - Graphical Tiles --> what ??? |
___________________________ Nitro BG Maps Screens ____________________________ |
000h 4 Chunk ID "RCSN" (aka NSCR backwards, Nitro Screen Resource) 004h 2 Byte Order (FEFFh) 006h 2 Version (0100h) 008h 4 Total Filesize 00Ch 2 Offset to "NRCS" Chunk, aka Size of "RCSN" Chunk (0010h) 00Eh 2 Total number of following Chunks (1=NRCS) |
000h 4 Chunk ID "NRCS" (aka SCRN backwards, Screen) 004h 4 Chunk Size 008h 4 Screen Width in pixels 00Ah 2 Screen Height in pixels 00Ch 4 Zero 010h 4 Screen Data Size (width/8)*(height/8)*2 014h N*2 Screen Data (16bit BG Map entries, palette+xyflip+tileno) |
____________________________ Nitro OBJ Animations ____________________________ |
000h 4 Chunk ID "RNAN" (aka NANR backwards, Nitro Animation Resource) 004h 2 Byte Order (FEFFh) 006h 2 Version (0100h) 008h 4 Total Filesize 00Ch 2 Offset to "KNBA" Chunk, aka Size of "RNAN" Chunk (0010h) 00Eh 2 Total number of following Chunks (1=KNBA, or 3=KNBA+LBAL+TXEU) |
000h 4 Chunk ID "KNBA" (aka ABNK backwards, Animation Bank) 004h 4 Chunk Size (always padded to 4-byte boundary if LABL chunk follows) 008h 2 Number of 16-byte Animation Blocks ;implies NumLabels in LABL chunk 00Ah 2 Number of 8-byte Frame Blocks 00Ch 4 Offset from KNBA+8 to Animation Blocks ;=18h 010h 4 Offset from KNBA+8 to Frame Blocks ;=[0Ch]+[08h]*10h 014h 4 Offset from KNBA+8 to Frame Data ;=[10h]+[0Ah]*8 018h 8 Zero DATA .. Animation Blocks (16-byte entries) 00h 4 Number of Frames 04h 2 Unknown (0) 06h 2 Unknown Always (1) ;reportedly "always unknown" 08h 4 Unknown (1..2) 0Ch 4 Offset from FrameBlock+0 to First Frame DATA .. Frame Blocks (8-byte entries) 00h 4 Offset from FrameData+0 to whatever? (always 4-byte aligned?) 04h 2 Frame Width ;3Ch or 01..06h ;Time in 60Hz units? num meta's? 06h 2 Unused (usually 0000h, or BEEFh=Bullshit) DATA .. Frame Data (2-byte entries) 00h 2 Unknown 16bit values? (maybe CELL index or whatever??) (CCCCh=?) |
000h 4 Chunk ID "LBAL" (aka LABL backwards, Labels) 004h 4 Chunk Size (not padded to 4-byte size, following TXEU is unaligned) 008h 4*N Offsets from LabelArea+0 to Labels (for each Animation Block) ... .. Label Area (ASCII Strings, terminated by 00h) |
000h 4 Chunk ID "TXEU" (aka UEXT backwards, Whatever Extension or so?) 004h 4 Chunk Size (0Ch) 008h 4 Unknown (usually 0) (reportedly 0 or 1) |
__________________________ Nitro OBJ Metatile Cells __________________________ |
000h 4 Chunk ID "RECN" (aka NCER backwards, Nitro Cell Resource) 004h 2 Byte Order (FEFFh) 006h 2 Version (0100h) 008h 4 Total Filesize 00Ch 2 Offset to "KBEC" Chunk, aka Size of "RECN" Chunk (0010h) 00Eh 2 Total number of following Chunks (1=KBEC, or 3=KBEC+LBAL+TXEU) |
000h 4 Chunk ID "KBEC" (aka CEBK backwards, Cell Bank)
004h 4 Chunk Size (always padded to 4-byte boundary if LABL chunk follows)
008h 2 Number of Metatiles
00Ah 2 Metatiles Entry Size (0=Normal 8 bytes, 1=Extended 16 bytes)
(DSi Launcher ..layout\cmn\launcher_u\.. uses 16-byte size)
00Ch 4 Offset from KBEC+8 to Metatile Table? (18h)
010h 4 Boundary Size (?) (but is ZERO in layout\cmn\launcher_u\)
"Specifies the area in which the image can be drawn,
multiplied by 64, ie. 2 means that the area is 128x128 pixels."
014h 0Ch Zero
020h .. Metatile Table (8 bytes each) (or 16 bytes)
... .. OBJ Attribute Table (6-bytes each)
|
000h 2 Number of OBJs 002h 2 Unknown 004h 4 OBJ Data Offset (from begin of OBJ Attr Table) (008h 2) Unknown (can be 02h,10h,48h,74h) (00Ah 2) Unknown (can be 08h) (00Ch 2) Unknown (can be FFA0h..FFF0h) ;\maybe extra coordinate offsets? (00Eh 2) Unknown (can be FFF0h..FFF9h) ;/ |
starts at Number of Cells * 8 | each cell is made up of 6 bytes) |
____________________________ Nitro Unknown Files ____________________________ |
.NMAR file (with "RAMN" header ID, and "KNBA"+"LBAL" chunks) .NMCR file (with "RCMN" header ID, and "KBCM" chunk) |
OBJ with 16bit x/y (instead 9bit/8bit)? OBJ with fractional x/y-stepping (moving/motion)? OBJ rotation/scaling? BG scroll offsets? BG tile replacement? |
000h 2 Unknown (000xh..007Ah, maybe time or so?) 002h 2 Unknown (signed 16bit?) 004h 2 Unknown (signed 16bit?) 006h 2 Unknown (0x21h, with x=0..8) |
_________________________ Nitro More Unknown Files __________________________ |
000h 4 ID "JNBL" 004h 2 Zero 006h 2 Number of 6-byte entries (01h or more) 008h N*6 Unknown |
000h 4 ID "JNCL" 004h 2 Zero (0000h) 006h 2 Number of 8-byte entries (01h or more) 008h N*8 Unknown (eg. 80h,10h,C0h,20h,00h,00h,00h,00h) |
000h 4 ID "JNLL" 004h 2 Zero (0000h) 006h 2 Number of 16-byte entries (01h or more) 008h N*16 Unknown (eg. 80h,50h,60h,10h,7Ch,29h,FFh,FDh,0Dh,19h,0,0,0,0,0,0) |
000h 4 ID "BNGL" ;this same as file extension (not JNGL) 004h 2 Zero (0000h) 006h 2 Number of ?-byte entries (01h or more) 008h 2 Unknown (can be 02h,04h,06h,0Ah) 00Ah 2 Number of ?-byte other entries maybe (01h or more) ... ... Entries? ... Other Entries? ... Maybe More Other Entries? |
______________________________ .ntft and .ntfp _______________________________ |
______________________________ .wmif and .wmpf _______________________________ |
000h 1Bh ID "Wild Magic Image File 3.00",00h 01Bh 4 Palette Filename Length (eg. 0Dh) 01Fh LEN Palette Filename (eg. "BG_Board.wmpf") ... 4 Texture Format (5=2bpp, 6=4bpp, 7=8bpp) (non-standard numbering) ... 4 Texture Width in pixels ... 4 Texture Height in pixels ... .. Texture data (vertically mirrored, starting with lower line) |
000h 1Dh ID "Wild Magic Palette File 1.00",00h 01Dh 4 Zero? 021h 4 Number of Colors 025h .. Colors, 16bit (0000h..7FFFh) |
_______________________________ .ntf and .xtf ________________________________ |
000h 4 Unknown, ID? (always 0Ch) 004h 4 Unknown, ID? (always 01h) (maybe num textures, aa in .xtf ?) 008h 2 Width in pixels (usually 8 SHL W) 00Ah 2 Height in pixels (usually 8 SHL H) 00Ch 2 Width shift (W) 00Eh 2 Height shift (H) 010h 4? Texture Format (1..7) 014h 4 Bitmap Size (Width*Height*bpp/8) 018h 4 Palette Size (NumColors*2) 01Ch 4 Unknown (0) 020h .. Bitmap Data ... .. Palette Data |
000h 4 Offset to Texture part 004h 4 Number of Whatever (N) ;\ 008h 4 Unknown (0Ch) ; Attributes? 00Ch N*8 Whatever List (CCCC00xxh,Offset) ; ... N*var Whatever Entries ... ;/ ... 4 Unknown (08h) ;\ ... 4 Number of Texture Blocks (1 or more) ; Texture part ... .. Texture Block(s) ;/ Texture Block: 000h 2 Width (usually 8 SHL W) ;\ 002h 2 Height (usually 8 SHL H) ; 004h 2 Width shift (W) ; 006h 2 Height shift (H) ; one or more such blocks 008h 4? Texture Format (1..7) ; 00Ch 4 Bitmap Size (Width*Height*bpp/8) ; (about same as in .ntf files) 010h 4 Palette Size (NumColors*2) ; 014h 4 Unknown (0) ; 018h .. Bitmap Data ; ... .. Palette Data ;/ |
____________________________________ TEX. ____________________________________ |
000h 4 ID ("TEX.")
004h 4 Texture Format (1..7)
008h 4 Width shift (W)
00Ch 4 Height shift (H)
010h 4 Usually zero (or, 1 in menu\planet_a\waterplanet.tex) (color0 ?)
014h 4 Width in pixels (usually 8 SHL W)
018h 4 Height in pixels (usually 8 SHL H, or sometimes less than 8 SHL H)
01Ch 4 Compressed Palette Offset (34h)
020h 4 Compressed Palette Size in bytes
024h 4 Unknown Offset? (usually/always same as [02Ch])
028h 4 Unknown Size? (usually/always 0=None)
02Ch 4 Compressed Bitmap Offset
030h 4 Compressed Bitmap Size in bytes
034h .. Compressed Palette Data
... .. Compressed Bitmap Data
The Compressed Data blocks look as so:
000h 1 Compression Method (00h=Stored/uncompressed, 10h=LZSS/compressed)
001h 3 Uncompressed Size
004h .. Compressed Data
... .. Padding to 4-byte boundary
The bitmap is stored in some files, and compressed in other files.
The palette is usually/always stored.
|
__________________________________ PMB+TTLP __________________________________ |
000h 4 ID (" PMB") (aka BMP backwards)
004h 4 Compressed Bitmap Size in bytes (can be odd, footer is unaligned)
008h .. Compressed Bitmap (LZSS) (10h,size(24bit),compressed data)
.. 2 Bitmap Width (100h)
.. 2 Bitmap Height (C0h)
.. 4 Palette Filename length
... .. Palette Filename ("2d/palette/name", without any trailing zero)
|
000h 4 ID ("TTLP") (aka PLTT backwards)
004h 4 Palette Size in bytes
008h .. Palette (uncompressed, 16bit entries)
|
____________________________________ NTFA ____________________________________ |
000h 4 Maybe Header Size (maybe 1Ch or so?) 004h 8 ID "NTFA0000" 00Ch 2 Color 0 Transparency (0=Solid, Nonzero=Transparent) 00Eh 2 Color Depth (3=4bpp, 4=8bpp) 010h 2 Bitmap Width 012h 2 Bitmap Height 014h 4 Bitmap Offset (maybe 1Ch+NumColors*2 ?) 018h 4 Palette Offset (maybe 1Ch or so?) ... N*2 Palette Data (RGB555) ... .. Bitmap Data |
| DS Files - 3D Video |
type BMD0/BCA0/BTA0/BTX0/BTP0/BMA0 is used by Mariokart DS (2005) type BMD0/BCA0/BTA0 is used by Walk with Me (2008-2009) type BVA0 is used by what... if it was ever used? |
000h 1 Dummy (00h) 001h 1 Number of entries (N) 002h 2 Size of whole Dict (Hdr(8)+Tree(4+X*4)+Data(4+N*siz)+Name(N*10h)) 004h 2 Offset to Tree Section (always 08h) 006h 2 Offset to Data Section (0Ch+X*4) 008h 4 Tree entry 0 (Patricia Tree Root entry) ;\Tree 00Ch X*4 Tree entry 1..X (Patricia Tree and actual Names/Data) ;/ ... 2 Size of each Data entry (siz) (usually 4 or 8) ;\ ... 2 Size of this Data Info Section (4+N*siz) ; Data ... N*siz Data (siz bytes, for each entry) ;/ ... N*10h Name Strings (10h-byte ASCII, zeropadded, for each entry) ;-Names |
000h 1 Patricia Tree First Bit-number (always 7Fh=Last=char[0Fh].bit7) 001h 1 Patricia Tree First entry (1..X) (usually points to rightmost bit) 002h 2 Patricia Tree Unused (zerofilled) |
000h 1 Patricia Tree Bit-number to be tested (0=Bit0 of 1st char) 001h 1 Patricia Tree Next entry when test=0 ;\upon match: Next=Curr 002h 1 Patricia Tree Next entry when test=1 ;/upon error: Next=0 003h 1 Entry number in Data and Name tables (used when Next=Curr entry) |
3D Video Container/Headers have version=1 (except: BMD0 has version=2) BoundingBox seems to have "origin/size" values (not "min/max" values) SHININESS is a 128-byte array, that's definietly not encoded in 4-byte entry Material seems to contain OR-mask and AND-mask values for POLYGON_ATTR ? Material can have further parameters, in the TODO part? MaterialIdxList offsets are relative to Model[008h], not to MaterialIdxList Pivot should use C=B and D=A (not C=A and D=B) for sine/cosine rotations? BasisMatrix description could be simplified, and are the unknown 2bit used? Animations have IDs "J.AC","M.AT", "M.PT", "M.AM" (with "."=00h) Dict's (aka NameList's) contain Patricia Trees for fast lookup (alike 3DS) SRT0 does "Texture Coordinate Animation" (not "Material Animation") SRT0 probably supports texture Scale/Rotate/Translate (not just Translate) TEX0[04h]=Size of TEX0 TEX0[18h]=Padding32bit (is MISSING in .txt, insert this after "block1_off") TEX0[1Eh]=CompressedTextureDictOffs (alias for TEX[0Eh]=TextureDictOffs) Texture[004h] is 11bit width, 11bit height (from TEXIMAGE bits), and bit31=1 NSBMA files do exists (eg. in Mariokart DS), and could/should be described NSBVA files... would be nice to know if they are used by any games? |
| DS Files - 3D Video BMD0 (.NSBMD Model Data) |
000h 4 ID "BMD0" (Basic Model Data) 004h 2 Byte Order (FEFFh) 006h 2 Version (2) (unknown if version 1 did also exist) 008h 4 Total Filesize 00Ch 2 Header size, excluding the Chunk offsets (always 10h) 00Eh 2 Number of chunks (1=MDL0 or 2=MDL0+TEX0) 010h 4 Offset from BMD0 to MDL0 Chunk 014h 4 Offset from BMD0 to TEX0 Chunk (if any) |
000h 4 Chunk ID "MDL0" (Model Block) 004h 4 Chunk Size 008h .. Model Dict (with 32bit offsets from MDL0 to Models) ... .. Models |
000h 4 Size of Model in bytes 004h 4 Offset from Model to RenderCommandList 008h 4 Offset from Model to Material info 00Ch 4 Offset from Model to Dict for Meshes 010h 4 Offset from Model to InvBindMatrices 014h 1 Unknown (00h) 015h 1 Unknown (00h or 01h) 016h 1 Unknown (00h) 017h 1 Number of BoneMatrices 018h 1 Number of Materials 019h 1 Number of Meshes 01Ah 2 Unknown (can be ZERO, or same as Number of BoneMatrices?) 01Ch 4 Scaling Factor for Up Scale command (fixed point, 1.19.12) 020h 4 Scaling Factor for Down Scale command (fixed point, 1.19.12) 024h 2 Number of Vertices 026h 2 Number of Polygons (Triangles+Quads) 028h 2 Number of Triangles 02Ah 2 Number of Quads 02Ch 2 Bounding Box X-Coordinate (fixed point, 1.3.12) ;\ 02Eh 2 Bounding Box Y-Coordinate (fixed point, 1.3.12) ; 030h 2 Bounding Box Z-Coordinate (fixed point, 1.3.12) ; for BOX_TEST 032h 2 Bounding Box X-Size, Width (fixed point, 1.3.12) ; command 034h 2 Bounding Box Y-Size, Height (fixed point, 1.3.12) ; 036h 2 Bounding Box T-Size, Depth (fixed point, 1.3.12) ;/ 038h 4 Unknown (1000h) ;\maybe fixed point value 1.0 ? 03Ch 4 Unknown (1000h) ;/ 040h .. Dict for BoneMatrices (with 32bit offsets from 040h to BoneMatrices) [04h] .. RenderCommandList [08h]+0 2 Offset from [08h] to Dict for Material-to-Texture Pairings ;\ [08h]+2 2 Offset from [08h] to Dict for Material-to-Palette Pairings ; [08h]+4 .. Dict for Materials (with 32bit offsets from [08h] to Materials) ; ... .. Dict for Material-to-Texture Pairings (with 4-byte entries) ; ... .. Dict for Material-to-Palette Pairings (with 4-byte entries) ;/ [0Ch] .. Dict for Meshes (with 32bit offsets from [0Ch] to VertexMeshes) [10h] .. InvBindMatrices (54h-byte each) |
_____________________________ RenderCommandList ______________________________ |
Cmd Params Description 00h 0 Nop (no operation?) 40h 0 Nop (same as above?) 80h 0 Nop (same as above?) 01h 0 End of RenderCommandList 02h 2 Unknown ;reportedly, params: Node ID, Visibility 03h 1 Load Matrix from Stack (param=StackIndex) 04h 1 Bind Material for subsequent Draw command (param=MaterialIndex) 24h 1 Bind Material (same as above?) 44h 1 Bind Material (same as above?) 05h 1 Draw VertexMesh (param=VertexMeshIndex) 06h 3 Multiply Matrix by BoneMatrix (see below) 26h 4 Multiply Matrix by BoneMatrix and Store Matrix to Stack 46h 4 Multiply Matrix by BoneMatrix and Load Matrix from Stack 66h 5 Multiply Matrix by BoneMatrix and Load/Store Matrix from/to Stack 07h 1 Unknown 47h 2? Unknown (as above? but with 2 params?) 08h 1 Unknown 09h var Calculate Skinning Equation (see below) 0Ah - Unused? 0Bh 0 Scale Up (using the scale factor in Model[01Ch]) ;or "BEGIN"? 2Bh 0 Scale Down (using the scale factor in Model[020h]( ;or "END"? 0Ch 2 Unknown 0Dh 2 Unknown 0Eh - Unused? 0Fh - Unused? 1xh - Unused? |
bone_idx = next_param ;index of BoneMatrix ;1st param parent_idx = next_param ;Parent of the Bone ;2nd param unknown = next_param ;? ;3rd param if cmd.bit6 then CurrMatrix = MatrixStack[next_param] ;4th param (if any) CurrMatrix *= BoneMatrices[bone_idx] if cmd.bit5 then MatrixStack[next_param] = CurrMatrix ;Last param (if any) |
CurrMatrix = 0
store_index = next_param ;1st param
num_terms = next_param ;2nd param
loop num_terms times:
term = MatrixStack[next_param] ;local-to-world matrix ;3rd,6th,..
term *= InvBindMatrices[next_param] ;4th,7th,..
term *= next_param / 256 ;weight ;5th,8th,..
CurrMatrix += term
MatrixStack[store_index] = CurrMatrix
|
_______________________________ InvBindMatrix ________________________________ |
000h 30h Position Matrix (3x4, fixed point 1.19.12) (rotate,scale,translate) 030h 24h Vector Matrix (3x3, fixed point 1.19.12) (rotate only, for light) |
_________________________________ VertexMesh _________________________________ |
000h 2 Dummy 002h 2 Unknown (0010h, possibly the size of VertexMesh?) 004h 4 Unknown 008h 4 Offset from VertexMesh to GXFIFO Command List 00Ch 4 Size of GXFIFO Command List in bytes |
00h=NOP, 14h=MTX_RESTORE, 1Bh=MTX_SCALE, 40h=BEGIN_VTXS, 41h=END_VTXS 20h=COLOR, 21h=NORMAL, 22h=TEXCOORD 23h=VTX_16, 24h=VTX_10,25h=VTX_XY, 26h=VTX_XZ, 27h=VTX_YZ, 28h=VTX_DIFF |
_________________________________ Materials __________________________________ |
000h 2 Dummy (0)
002h 2 Size of this Material in bytes (002Ch)
004h 4 Value for DIF_AMB register
008h 4 Value for SPE_EMI register
00Ch 4 Value for POLYGON_ATTR register ;<-- OR value?
010h 4 Mask for POLYGON_ATTR register (1F3FF8FFh) ? ;<-- AND value?
014h 4 Value for TEXIMAGE_PARAMS register (bit16-19 and 30-31, see below)
018h 4 Unknown (FFFFFFFFh)
01Ch 4 Unknown (1FCE0000h)
020h 2 Texture_width
022h 2 Texture_height
024h 4 Unknown (00001000h)
028h 4 Unknown (00001000h)
XXX above is 2Ch-bytes (other source says "Usually 48 bytes" aka 30h-byte)
XXX unknown if above can have optionaly extra entries
XXX reportedly above can optionally contain a texcoord transform matrix?
XXX unknown if above contains 16bit COLOR (eg. for texture-less polygons)
|
0-15 Zero in Model/Material (instead, derived from TEX0) 16 Repeat in S Direction (0=Clamp Texture, 1=Repeat Texture) 17 Repeat in T Direction (0=Clamp Texture, 1=Repeat Texture) 18 Flip in S Direction (0=No, 1=Flip each 2nd Texture; requires Repeat) 19 Flip in T Direction (0=No, 1=Flip each 2nd Texture; requires Repeat) 20-29 Zero in Model (instead, derived from TEX0) 30-31 Texture Coordinates Transformation Mode (0..3) |
000h 2 Offset from Model[008h] (?) to List of 8bit Materials Indices 002h 1 Number of entries in the List of 8bit Materials Indices 003h 1 Dummy (0) |
________________________________ BoneMatrices ________________________________ |
00h 2 Flags
0 Disable Translation (0=Enable, 1=Disable)
1 Disable Rotation (0=Enable, 1=Disable)
2 Disable Scale (0=Enable, 1=Disable)
3 Matrix Type for Rotation (0=3x3 Matrix, 1=Pivot Matrix)
4-7 Rotation Pivot Form ;\
8 Rotation Pivot NegI ; for Pivot Matrix Rotation
9 Rotation Pivot NegC ;
10 Rotation Pivot NegD ;/
11-15 Unused (0)
02h 2 Rotation Matrix m0 (fixed point, 1.3.12) ;-here for alignment reasons
... 4 Translation X (fixed point, 1.19.12) ;\
... 4 Translation Y (fixed point, 1.19.12) ; only if flags.bit0=0
... 4 Translation Z (fixed point, 1.19.12) ;/
... 2 Rotation Matrix m1 (fixed point, 1.3.12) ;\
... 2 Rotation Matrix m2 (fixed point, 1.3.12) ; only if Flags.bit3=0=3x3
... 2 Rotation Matrix m3 (fixed point, 1.3.12) ; and Flags.bit1=0
... 2 Rotation Matrix m4 (fixed point, 1.3.12) ; [ m0 m3 m6 ]
... 2 Rotation Matrix m5 (fixed point, 1.3.12) ; [ m1 m4 m7 ]
... 2 Rotation Matrix m6 (fixed point, 1.3.12) ; [ m2 m5 m8 ]
... 2 Rotation Matrix m7 (fixed point, 1.3.12) ;
... 2 Rotation Matrix m8 (fixed point, 1.3.12) ;/
... 2 Rotation Pivot A (fixed point, 1.3.12) ;\only if Flags.bit3=1=Pivot
... 2 Rotation Pivot B (fixed point, 1.3.12) ;/ (and Flags.bit1=0?)
... 4 Scale X (fixed point, 1.19.12) ;\
... 4 Scale Y (fixed point, 1.19.12) ; only if Flags.bit2=0
... 4 Scale Z (fixed point, 1.19.12) ;/
|
| DS Files - 3D Video BTX0 (.NSBTX Texture Data) |
000h 4 ID "BTX0" (Basic Texture) 004h 2 Byte Order (FEFFh) 006h 2 Version (1) 008h 4 Total Filesize 00Ch 2 Header size, excluding the Chunk offsets (always 10h) 00Eh 2 Number of chunks (1=TEX0) 010h 4 Offset from BTX0 to TEX0 Chunk |
000h 4 Chunk ID "TEX0" (Texture Block) 004h 4 Chunk Size 008h 4 Padding (0) 00Ch 2 Texture Data Size/8 ;\Texture 00Eh 2 Texture Dict Offset (03Ch) ; (Format 1..4 010h 4 Padding (0) ; and 6..7) 014h 4 Texture Data Offset ;/ 018h 4 Padding (0) 01Ch 2 Compressed Texture Data Size/12 (often 0=none) ;\ 01Eh 2 Compressed Texture Dict Offset (03Ch, too) ; Compressed 020h 4 Padding (0) ; Texture 024h 4 Compressed Texture Offset for 4x4-Texel Data ; (Format 5) 028h 4 Compressed Texture Offset for 4x4-Texel Attr ;/ 02Ch 4 Padding (0) 030h 4 Palette Data Size/8 ;\ 034h 4 Palette Dict Offset ; Palette 038h 4 Palette Data Offset ;/ [0Eh] .. Texture Dict (with 8-byte entries, see below) ;\Dict's [34h] .. Palette Dict (with 4-byte entries, see below) ;/ [14h] [0Ch]*8 Texture Data ;\ [24h] [1Ch]*8 Compressed Texture 4x4-Texel Data (2bpp) ; VRAM Data [28h] [1Ch]*4 Compressed Texture 4x4-Texel Attr (1bpp) ; [38h] [30h]*8 Palette Data Section ;/ |
000h 4 Value for TEXIMAGE_PARAM register
0-15 Texture Data (Offset/8, in File Data / VRAM Data)
16-19 Zero in TEX0 (instead, derived from Model's Material)
20-22 Texture S-Size (W) (for W=0..7: Width=(8 SHL W)
23-25 Texture T-Size (H) (for H=0..7: Height=(8 SHL H)
26-28 Texture Format (0..7)
29 Palette Color 0 (0=Displayed, 1=Made Transparent)
30-31 Zero in TEX0 (instead, derived from Model's Material)
004h 4 Width/Height (contains the above 3bit W/H values decoded to 11bit)
0-10 Width in pixels (8 shl W) (8..1024)
11-21 Height in pixels (8 shl H) (8..1024)
22-30 Unknown (0)
31 Unknown (1)
|
000h 2 Value for PLTT_BASE register
0-12 Palette Base (Offset/8, in File Data / VRAM Data)
13-15 Unused (0)
002h 2 Unknown (usually 0, sometimes 1) ;unrelated to number of colors
|
Texture Name: "MS_ttl_1_2" ;\both SAME name Palette Name: "MS_ttl_1_2" ;/ Texture Name: "MS_ttl_3" ;\palette with extra "_pl" suffix (or "_p") Palette Name: "MS_ttl_3_pl" ;/ Texture Name: "MS1_11_2" ;\palette without suffix Palette Name: "MS1_11" ;/ Texture Name: "nr_space3_2" ;\palette without prefix Palette Name: "space3_2" ;/ |
| DS Files - 3D Video BCA0 (.NSBCA Character Skeletal Animation) |
000h 4 ID "BCA0" (Basic Character Animation) 004h 2 Byte Order (FEFFh) 006h 2 Version (1) 008h 4 Total Filesize 00Ch 2 Header size, excluding the Chunk offsets (always 10h) 00Eh 2 Number of chunks (1=JNT0) 010h 4 Offset from BCA0 to JNT0 Chunk |
000h 4 Chunk ID "JNT0" (Joint Block) 004h 4 Chunk Size 008h .. Joint Dict (with 32bit offsets from JNT0 to J.AC) |
000h 4 ID "J",00h,"AC" (nicknamed "J.AC") (Joint Animation Content ?) 004h 2 Number of Frames 006h 2 Number of Tracks (T) 008h 4 Unknown (3) 00Ch 4 Offset from J.AC to PivotMatrices 010h 4 Offset from J.AC to BasisMatrices 014h 2*T Offsets from J.AC to AnimationTrack(s) ... .. Padding to 4-byte boundary (if needed) ... .. AnimationTrack(s) ... .. PivotMatrices (06h-bytes each) ;\used for Rotations ... .. BasisMatrices (0Ah-bytes each) ;/(see "Curve" entries) |
000h 2 Flags (eg. 3028h)
0 No Channel
1-2 No Translation channels ;why 2bit?
3 Translation X is constant
4 Translation Y is constant
5 Translation Z is constant
6-7 No Rotation channel ;why 2bit?
8 Rotation is constant
9-10 No Scale channels ;why 2bit?
11 Scale X is constant
12 Scale Y is constant
13 Scale Z is constant
14-15 Unknown (0) (unused?)
002h 1 Dummy (00h)
003h 1 target_index (the index of the BoneMatrix this track targets?)
... .. Curve, Translation X ;\
... .. Curve, Translation Y ; only if Flags.bit0=0 and Flags.bit1-2=0
... .. Curve, Translation Z ;/
... .. Curve, Rotation ;-only if Flags.bit0=0 and Flags.bit6-7=0
... .. Curve, Scale X ;\
... .. Curve, Scale Y ; only if Flags.bit0=0 and Flags.bit9-10=0
... .. Curve, Scale Z ;/
|
___________________________________ Curves ___________________________________ |
When Constant=1 and Translation X/Y/Z:
000h 4 Translation value (fixed point, 1.19.12)
When Constant=1 and Rotation:
000h 2 Matrix Index/Type (bit0-14=Index, bit15=Type: 0=Basis, 1=Pivot)
002h 2 Unused (padding for alignment, probably)
When Constant=1 and Scaling X/Y/Z:
000h 4 Scaling Value (fixed point, 1.19.12)
004h 4 Unknown (fixed point, 1.19.12)
When Constant=0:
000h 4 Frame Info
bit0-15 Start_frame (start on this frame, step=samplerate)
bit16-27 End_frame (up to excluding this frame)
bit28-29 Width for Scale/Translate (0=32bit, 1=16bit)
bit30-31 Samplerate (0,1,2,3 = Each 1,2,4,8 frames)
004h 4 Offset from J.AC to SampledCurve
|
num_samples=(end_frame-start_frame)/samplerate
When Translation X/Y/Z, and Width=0:
000h 4 Sample (fixed point, 1.19.12)
When Translation X/Y/Z, and Width=1:
000h 2 Sample (fixed point, 1.3.12)
When Rotation:
000h 2 Matrix Index/Type (bit0-14=Index, bit15=Type: 0=Basis, 1=Pivot)
Whan Scaling X/Y/Z, and Width=0:
000h 4 Sample (fixed point, 1.19.12)
004h 4 Unknown (fixed point, 1.19.12)
Whan Scaling X/Y/Z, and Width=1:
000h 2 Sample (fixed point, 1.3.12)
002h 2 Unknown (fixed point, 1.3.12)
|
________________________________ PivotMatrix _________________________________ |
000h 2 Flags (bit0-3=Form, bit4=NegI, bit5=NegC, bit6=NegD, bit7-15=Unused) 002h 2 Value A (fixed point, 1.3.12) ;\usually cos/sin values 003h 2 Value B (fixed point, 1.3.12) ;/ |
[ i 0 0 ] [ 0 a c ] [ 0 a c ]
Form0 = [ 0 a c ] Form1 = [ i 0 0 ] Form2 = [ 0 b d ]
(X) [ 0 b d ] [ 0 b d ] [ i 0 0 ]
|
[ 0 i 0 ] [ a 0 c ] [ a 0 c ]
Form3 = [ a 0 c ] Form4 = [ 0 i 0 ] Form5 = [ b 0 d ]
[ b 0 d ] (Y) [ b 0 d ] [ 0 i 0 ]
|
[ 0 0 i ] [ a c 0 ] [ a c 0 ]
Form6 = [ a c 0 ] Form7 = [ 0 0 i ] Form8 = [ b d 0 ]
[ b d 0 ] [ b d 0 ] (Z) [ 0 0 i ]
|
________________________________ BasisMatrix _________________________________ |
000h 2 bit3-15=a0.bit0-12, and bit0-2=b2.bit9-11 002h 2 bit3-15=a1.bit0-12, and bit0-2=b2.bit6-8 004h 2 bit3-15=a2.bit0-12, and bit0-2=b2.bit3-5 006h 2 bit3-15=b0.bit0-12, and bit0-2=b2.bit0-2 008h 2 bit3-15=b1.bit0-12, and bit0=b2.bit12, and bit1-2=unknown? |
(c0,c1,c2) = (a0,a1,a2) x (b0,b1,b2) ;cross product |
[ a0 b0 c0 ] [ a1 b1 c1 ] [ a2 b2 c2 ] |
| DS Files - 3D Video BTA0 (.NSBTA Texture Coordinate Animation) |
000h 4 ID "BTA0" (Texture Animation) 004h 2 Byte Order (FEFFh) 006h 2 Version (1) 008h 4 Total Filesize 00Ch 2 Header size, excluding the Chunk offsets (always 10h) 00Eh 2 Number of chunks (1=SRT0) 010h 4 Offset from BTA0 to SRT0 Chunk |
000h 4 Chunk ID "SRT0" (maybe short for Scale/Rotate/Translate?) 004h 4 Chunk Size 008h .. Dict (with 32bit offsets from SRT0 to Animations) ... .. Animation(s) |
000h 4 ID "M",00h,"AT" (nicknamed "M.AT") 004h 2 Unknown (can be 3Bh) ;is that Number of Frames? 006h 2 Unknown (can be 0) 008h .. Dict (with 28h-byte Track entries) ... .. Key Frames |
000h 8 Channel 0 - unknown, maybe Scale U ;\ 008h 8 Channel 1 - unknown, maybe Scale V ; maybe scale/rotate? 010h 8 Channel 2 - unknown, maybe Rotate Matrix ;/ 018h 8 Channel 3 - Translation U ;\texture scrolling 020h 8 Channel 4 - Translation V ;/ |
000h 2 Number of Keyframes (can be 3Bh)
002h 2 Flags (1000h, 2000h or 3000h) (maybe loop flags and/or rate?)
004h 4 When Flags=1000h: Offset from "M.AT" to Keyframe(s)
When Flags=2000h: Unknown (10000000h) ;\maybe disable, or fixed
When Flags=3000h: Unknown (1000h or 0) ;/setting for all frames?
|
000h 2 Value (for Translation: fixed point 1.10.5) |
| DS Files - 3D Video BTP0 (.NSBTP Texture Pattern Animation) |
000h 4 ID "BTP0" (Texture Pattern Animation) 004h 2 Byte Order (FEFFh) 006h 2 Version (1) 008h 4 Total Filesize 00Ch 2 Header size, excluding the Chunk offsets (always 10h) 00Eh 2 Number of chunks (1=PAT0) 010h 4 Offset from BTP0 to PAT0 Chunk |
000h 4 Chunk ID "PAT0" (Pattern Block) 004h 4 Chunk Size 008h .. Dict (with 32bit offsets from PAT0 to Pattern Animations) ... .. Pattern Animation(s) |
000h 4 ID "M",00h,"PT" (nicknamed "M.PT") 004h 2 Unknown (can be 08h or 32h) ;rather NOT Number of Frames? 006h 1 Number of Texture Names (Y) 007h 1 Number of Palette Names (Z) 008h 2 Offset from "M.PT" to Texture Names 00Ah 2 Offset from "M.PT" to Palette Names 00Ch .. Dict (with 8-byte Track entries; includes offsets to Key Frames) ... X*4 Key Frames ... Y*10h Texture Names (each 10h-byte ASCII, zeropadded) ... Z*10h Palette Names (each 10h-byte ASCII, zeropadded) |
000h 4 Number of Keyframes 004h 2 Unknown (1000h or 00F5h) (maybe loop flags and/or framerate etc.) 006h 2 Offset from "M.PT" to Keyframe(s) |
000h 2 Frame Number (increasing 0000h..NumKeyFrames-1) 002h 1 Index into Texture Names 003h 1 Index into Palette Names |
| DS Files - 3D Video BMA0 (.NSBMA Material Animation) |
000h 4 ID "BMA0" (Material Animation) 004h 2 Byte Order (FEFFh) 006h 2 Version (1) 008h 4 Total Filesize 00Ch 2 Header size, excluding the Chunk offsets (always 10h) 00Eh 2 Number of chunks (1=MAT0) 010h 4 Offset from BMA0 to MAT0 Chunk |
000h 4 Chunk ID "MAT0" (Material Block) 004h 4 Chunk Size 008h .. Dict (with 32bit offsets from PAT0 to Pattern Animations) ... .. Animation(s) |
000h 4 ID "M",00h,"AM" (nicknamed "M.AM") 004h 2 Unknown (can be 5Ah) ;is that Number of Frames? 006h 2 Unknown (can be 3) 008h .. Dict (with 14h-byte Track entries) ... .. Key Frames |
000h 2 Unknown (40h) Offset from "M.AM" to Keyframes ;\ 002h 1 Unknown (5Ah) Number of Keyframes (5Ah*2=B4h bytes) ; ch0 003h 1 Unknown (0) Flags ;/ 004h 2 Unknown (F4h) Offset from "M.AM" to Keyframes ;\ 006h 1 Unknown (5Ah) Number of Keyframes (5Ah*2=B4h bytes) ; ch1 007h 1 Unknown (0) Flags ;/ 008h 2 Unknown (0) Maybe fixed value for all frames? ;\ 00Ah 1 Unknown (5Ah) Number of Keyframes ; ch2 00Bh 1 Unknown (20h) Flags (20h=Fixed/Disabled?) ;/ 00Ch 2 Unknown (0) Maybe fixed value for all frames? ;\ 00Eh 1 Unknown (5Ah) Number of Keyframes ; ch3 00Fh 1 Unknown (20h) Flags (20h=Fixed/Disabled?) ;/ 010h 2 Unknown (1Fh) Maybe fixed value for all frames? ;\ 012h 1 Unknown (5Ah) Number of Keyframes ; ch4 013h 1 Unknown (20h) Flags (20h=Fixed/Disabled?) ;/ |
000h 2 Unknown |
| DS Files - 3D Video NVA0 (.NSBVA Unknown Vis Animation) |
000h 4 ID "BVA0" (whatever Vis... Animation?) ... .. XXX |
000h 4 Chunk ID "VIS0" (Visibility...?) 004h 4 Chunk Size ... .. Unknown |
| DS 3D Video |
| DS 3D Overview |
| DS 3D I/O Map |
Address Siz Name Expl. Rendering Engine (per Frame settings) 4000060h 2 DISP3DCNT 3D Display Control Register (R/W) 4000320h 1 RDLINES_COUNT Rendered Line Count Register (R) 4000330h 10h EDGE_COLOR Edge Colors 0..7 (W) 4000340h 1 ALPHA_TEST_REF Alpha-Test Comparision Value (W) 4000350h 4 CLEAR_COLOR Clear Color Attribute Register (W) 4000354h 2 CLEAR_DEPTH Clear Depth Register (W) 4000356h 2 CLRIMAGE_OFFSET Rear-plane Bitmap Scroll Offsets (W) 4000358h 4 FOG_COLOR Fog Color (W) 400035Ch 2 FOG_OFFSET Fog Depth Offset (W) 4000360h 20h FOG_TABLE Fog Density Table, 32 entries (W) 4000380h 40h TOON_TABLE Toon Table, 32 colors (W) Geometry Engine (per Polygon/Vertex settings) 4000400h 40h GXFIFO Geometry Command FIFO (W) 4000440h ... ... Geometry Command Ports (see below) 4000600h 4 GXSTAT Geometry Engine Status Register (R and R/W) 4000604h 4 RAM_COUNT Polygon List & Vertex RAM Count Register (R) 4000610h 2 DISP_1DOT_DEPTH 1-Dot Polygon Display Boundary Depth (W) 4000620h 10h POS_RESULT Position Test Results (R) 4000630h 6 VEC_RESULT Vector Test Results (R) 4000640h 40h CLIPMTX_RESULT Read Current Clip Coordinates Matrix (R) 4000680h 24h VECMTX_RESULT Read Current Directional Vector Matrix (R) |
Address Cmd Pa.Cy. N/A 00h - - NOP - No Operation (for padding packed GXFIFO commands) 4000440h 10h 1 1 MTX_MODE - Set Matrix Mode (W) 4000444h 11h - 17 MTX_PUSH - Push Current Matrix on Stack (W) 4000448h 12h 1 36 MTX_POP - Pop Current Matrix from Stack (W) 400044Ch 13h 1 17 MTX_STORE - Store Current Matrix on Stack (W) 4000450h 14h 1 36 MTX_RESTORE - Restore Current Matrix from Stack (W) 4000454h 15h - 19 MTX_IDENTITY - Load Unit Matrix to Current Matrix (W) 4000458h 16h 16 34 MTX_LOAD_4x4 - Load 4x4 Matrix to Current Matrix (W) 400045Ch 17h 12 30 MTX_LOAD_4x3 - Load 4x3 Matrix to Current Matrix (W) 4000460h 18h 16 35* MTX_MULT_4x4 - Multiply Current Matrix by 4x4 Matrix (W) 4000464h 19h 12 31* MTX_MULT_4x3 - Multiply Current Matrix by 4x3 Matrix (W) 4000468h 1Ah 9 28* MTX_MULT_3x3 - Multiply Current Matrix by 3x3 Matrix (W) 400046Ch 1Bh 3 22 MTX_SCALE - Multiply Current Matrix by Scale Matrix (W) 4000470h 1Ch 3 22* MTX_TRANS - Mult. Curr. Matrix by Translation Matrix (W) 4000480h 20h 1 1 COLOR - Directly Set Vertex Color (W) 4000484h 21h 1 9* NORMAL - Set Normal Vector (W) 4000488h 22h 1 1 TEXCOORD - Set Texture Coordinates (W) 400048Ch 23h 2 9 VTX_16 - Set Vertex XYZ Coordinates (W) 4000490h 24h 1 8 VTX_10 - Set Vertex XYZ Coordinates (W) 4000494h 25h 1 8 VTX_XY - Set Vertex XY Coordinates (W) 4000498h 26h 1 8 VTX_XZ - Set Vertex XZ Coordinates (W) 400049Ch 27h 1 8 VTX_YZ - Set Vertex YZ Coordinates (W) 40004A0h 28h 1 8 VTX_DIFF - Set Relative Vertex Coordinates (W) 40004A4h 29h 1 1 POLYGON_ATTR - Set Polygon Attributes (W) 40004A8h 2Ah 1 1 TEXIMAGE_PARAM - Set Texture Parameters (W) 40004ACh 2Bh 1 1 PLTT_BASE - Set Texture Palette Base Address (W) 40004C0h 30h 1 4 DIF_AMB - MaterialColor0 - Diffuse/Ambient Reflect. (W) 40004C4h 31h 1 4 SPE_EMI - MaterialColor1 - Specular Ref. & Emission (W) 40004C8h 32h 1 6 LIGHT_VECTOR - Set Light's Directional Vector (W) 40004CCh 33h 1 1 LIGHT_COLOR - Set Light Color (W) 40004D0h 34h 32 32 SHININESS - Specular Reflection Shininess Table (W) 4000500h 40h 1 1 BEGIN_VTXS - Start of Vertex List (W) 4000504h 41h - 1 END_VTXS - End of Vertex List (W) 4000540h 50h 1 392 SWAP_BUFFERS - Swap Rendering Engine Buffer (W) 4000580h 60h 1 1 VIEWPORT - Set Viewport (W) 40005C0h 70h 3 103 BOX_TEST - Test if Cuboid Sits inside View Volume (W) 40005C4h 71h 2 9 POS_TEST - Set Position Coordinates for Test (W) 40005C8h 72h 1 5 VEC_TEST - Set Directional Vector for Test (W) |
| DS 3D Display Control |
0 Texture Mapping (0=Disable, 1=Enable) 1 PolygonAttr Shading (0=Toon Shading, 1=Highlight Shading) 2 Alpha-Test (0=Disable, 1=Enable) (see ALPHA_TEST_REF) 3 Alpha-Blending (0=Disable, 1=Enable) (see various Alpha values) 4 Anti-Aliasing (0=Disable, 1=Enable) 5 Edge-Marking (0=Disable, 1=Enable) (see EDGE_COLOR) 6 Fog Color/Alpha Mode (0=Alpha and Color, 1=Only Alpha) (see FOG_COLOR) 7 Fog Master Enable (0=Disable, 1=Enable) 8-11 Fog Depth Shift (FOG_STEP=400h shr FOG_SHIFT) (see FOG_OFFSET) 12 Color Buffer RDLINES Underflow (0=None, 1=Underflow/Acknowledge) 13 Polygon/Vertex RAM Overflow (0=None, 1=Overflow/Acknowledge) 14 Rear-Plane Mode (0=Blank, 1=Bitmap) 15-31 Not used |
0 Translucent polygon Y-sorting (0=Auto-sort, 1=Manual-sort)
1 Depth Buffering (0=With Z-value, 1=With W-value)
(mode 1 does not function properly with orthogonal projections)
2-31 Not used
|
0-7 Screen/BG0 Coordinate X1 (0..255) (For Fullscreen: 0=Left-most) 8-15 Screen/BG0 Coordinate Y1 (0..191) (For Fullscreen: 0=Bottom-most) 16-23 Screen/BG0 Coordinate X2 (0..255) (For Fullscreen: 255=Right-most) 24-31 Screen/BG0 Coordinate Y2 (0..191) (For Fullscreen: 191=Top-most) |
0-14 W-Coordinate (Unsigned, 12bit integer, 3bit fractional part) 15-31 Not used (0000h=Closest, 7FFFh=Most Distant) |
0-4 Alpha-Test Comparision Value (0..31) (Draw pixels if Alpha>AlphaRef) 5-31 Not used |
| DS 3D Geometry Commands |
0-7 First Packed Command (or Unpacked Command) 8-15 Second Packed Command (or 00h=None) 16-23 Third Packed Command (or 00h=None) 24-31 Fourth Packed Command (or 00h=None) |
0-31 Parameter data for the previously sent (packed) command(s) |
- command1 (upper 24bit zero) - parameter(s) for command1 (if any) - command2 (upper 24bit zero) - parameter(s) for command2 (if any) - command3 (upper 24bit zero) - parameter(s) for command3 (if any) |
- command1,2,3,4 packed into one 32bit value (all bits used) - parameter(s) for command1 (if any) - parameter(s) for command2 (if any) - parameter(s) for command3 (if any) - parameter(s) for command4 (top-most packed command MUST have parameters) - command5,6 packed into one 32bit value (upper 16bit zero) - parameter(s) for command5 (if any) - parameter(s) for command6 (top-most packed command MUST have parameters) - command7,8,9 packed into one 32bit value (upper 8bit zero) - parameter(s) for command7 (if any) - parameter(s) for command8 (if any) - parameter(s) for command9 (top-most packed command MUST have parameters) |
| DS 3D Matrix Load/Multiply |
0-1 Matrix Mode (0..3)
0 Projection Matrix
1 Position Matrix (aka Modelview Matrix)
2 Position & Vector Simultaneous Set mode (used for Light+VEC_TEST)
3 Texture Matrix (see DS 3D Texture Coordinates chapter)
2-31 Not used
|
MTX_SCALE in Mode 2: uses ONLY Position Matrix MTX_PUSH/POP/STORE/RESTORE in Mode 1: uses BOTH Position AND Vector Matrices |
ClipMatrix = PositionMatrix * ProjectionMatrix |
| DS 3D Matrix Types |
_ 4x4 Matrix _ _ Identity Matrix _ | m[0] m[1] m[2] m[3] | | 1.0 0 0 0 | | m[4] m[5] m[6] m[7] | | 0 1.0 0 0 | | m[8] m[9] m[10] m[11] | | 0 0 1.0 0 | |_m[12] m[13] m[14] m[15]_| |_ 0 0 0 1.0 _| |
_ 4x3 Matrix _ _ Translation Matrix _ | m[0] m[1] m[2] 0 | | 1.0 0 0 0 | | m[3] m[4] m[5] 0 | | 0 1.0 0 0 | | m[6] m[7] m[8] 0 | | 0 0 1.0 0 | |_m[9] m[10] m[11] 1.0 _| |_m[0] m[1] m[2] 1.0 _| |
_ 3x3 Matrix _ _ Scale Matrix _ | m[0] m[1] m[2] 0 | | m[0] 0 0 0 | | m[3] m[4] m[5] 0 | | 0 m[1] 0 0 | | m[6] m[7] m[8] 0 | | 0 0 m[2] 0 | |_ 0 0 0 1.0 _| |_ 0 0 0 1.0 _| |
| DS 3D Matrix Stack |
Matrix Stack________Valid Stack Area____Stack Pointer___________________ Projection Stack 0..0 (1 entry) 0..1 (1bit) (GXSTAT: 1bit) Coordinate Stack 0..30 (31 entries) 0..63 (6bit) (GXSTAT: 5bit only) Directional Stack 0..30 (31 entries) (uses Coordinate Stack Pointer) Texture Stack One..None? 0..1 (1bit) (GXSTAT: N/A) |
MTX_MODE = 0 --> Projection Stack MTX_MODE = 1 or 2 --> BOTH Coordinate AND Directional Stack MTX_MODE = 3 --> Texture Stack |
Parameter Bit0-5: Stack Offset (signed value, -30..+31) (usually +1) Parameter Bit6-31: Not used |
Parameter Bit0-4: Stack Address (0..30) (31 causes overflow in GXSTAT.15) Parameter Bit5-31: Not used |
Parameter Bit0-4: Stack Address (0..30) (31 causes overflow in GXSTAT.15) Parameter Bit5-31: Not used |
| DS 3D Matrix Examples (Projection) |
Perspective Projection Orthogonal Projection
__ __________
top __..--'' | top | |
| view | | view |
Eye ----|--------->| Eye ----|--------->|
|__volume | | volume |
bottom ''--..__| bottom|__________|
near far near far
|
| (2.0)/(r-l) 0 0 0 | | 0 (2.0)/(t-b) 0 0 | | 0 0 (2.0)/(n-f) 0 | | (l+r)/(l-r) (b+t)/(b-t) (n+f)/(n-f) 1.0 | |
| (2*n)/(r-l) 0 0 0 | | 0 (2*n)/(t-b) 0 0 | | (r+l)/(r-l) (t+b)/(t-b) (n+f)/(n-f) -1.0 | | 0 0 (2*n*f)/(n-f) 0 | |
| cos/(asp*sin) 0 0 0 | | 0 cos/sin 0 0 | | 0 0 (n+f)/(n-f) -1.0 | | 0 0 (2*n*f)/(n-f) 0 | |
| DS 3D Matrix Examples (Rotate/Scale/Translate) |
Load(Identity) ;no rotation/scaling used Load(Identity), Mul(Rotate), Mul(Scale) ;rotation/scaling (not so efficient) Load(Rotate), Mul(Scale) ;rotation/scaling (more efficient) |
Around X-Axis Around Y-Axis Around Z-Axis | 1.0 0 0 | | cos 0 sin | | cos sin 0 | | 0 cos sin | | 0 1.0 0 | | -sin cos 0 | | 0 -sin cos | | -sin 0 cos | | 0 0 1.0 | |
| DS 3D Matrix Examples (Maths Basics) |
| c11 c12 c13 c14 | | a11 a12 a13 a14 | | b11 b12 b13 b14 | | c21 c22 c23 c24 | = | a21 a22 a23 a24 | * | b21 b22 b23 b24 | | c31 c32 c33 c34 | | a31 a32 a33 a34 | | b31 b32 b33 b34 | | c41 c42 c43 c44 | | a41 a42 a43 a44 | | b41 b42 b43 b44 | |
cyx = ay1*b1x + ay2*b2x + ay3*b3x + ay4*b4x |
| b11 b12 b13 b14 |
| c11 c12 c13 c14 | = | a11 a12 a13 a14 | * | b21 b22 b23 b24 |
| b31 b32 b33 b34 |
| b41 b42 b43 b44 |
|
cyx = ay1*b1x + ay2*b2x + ay3*b3x + ay4*b4x |
cyx = ayx*n |
cyx = ayx +/- byx |
cyx = ay1*b1x + ay2*b2x + ay3*b3x + ay4*b4x |
| DS 3D Polygon Attributes |
0-3 Light 0..3 Enable Flags (each bit: 0=Disable, 1=Enable) 4-5 Polygon Mode (0=Modulation,1=Decal,2=Toon/Highlight Shading,3=Shadow) 6 Polygon Back Surface (0=Hide, 1=Render) ;Line-segments are always 7 Polygon Front Surface (0=Hide, 1=Render) ;rendered (no front/back) 8-10 Not used 11 Depth-value for Translucent Pixels (0=Keep Old, 1=Set New Depth) 12 Far-plane intersecting polygons (0=Hide, 1=Render/clipped) 13 1-Dot polygons behind DISP_1DOT_DEPTH (0=Hide, 1=Render) 14 Depth Test, Draw Pixels with Depth (0=Less, 1=Equal) (usually 0) 15 Fog Enable (0=Disable, 1=Enable) 16-20 Alpha (0=Wire-Frame, 1..30=Translucent, 31=Solid) 21-23 Not used 24-29 Polygon ID (00h..3Fh, used for translucent, shadow, and edge-marking) 30-31 Not used |
Parameter 1, Bit 0-4 Red Parameter 1, Bit 5-9 Green Parameter 1, Bit 10-14 Blue Parameter 1, Bit 15-31 Not used |
| DS 3D Polygon Definitions by Vertices |
Separate Tri. Triangle Strips Line Segment v0 v2___v4____v6 |\ v3 /|\ |\ /\ v0 v1 | \ /\ v0( | \ | \ / \ ------ |__\ /__\ \|__\|__\/____\ v2 v1 v2 v4 v5 v1 v3 v5 v7 |
Separate Quads Quadliteral Strips Prohibited Quads
v0__v3 v0__v2____v4 v10__ v0__v3 v4
/ \ v4____v7 / \ |\ _____ / /v11 \/ |\
/ \ | \ / \ | |v6 v8| / /\ v5| \
/______\ |_____\ /______\___|_|_____|/ /__\ /___\
v1 v2 v5 v6 v1 v3 v5 v7 v9 v2 v1 v6 v7
|
Parameter 1, Bit 0-1 Primitive Type (0..3, see below) Parameter 1, Bit 2-31 Not used |
0 Separate Triangle(s) ;3*N vertices per N triangles 1 Separate Quadliteral(s) ;4*N vertices per N quads 2 Triangle Strips ;3+(N-1) vertices per N triangles 3 Quadliteral Strips ;4+(N-1)*2 vertices per N quads |
Parameter 1, Bit 0-15 X-Coordinate (signed, with 12bit fractional part) Parameter 1, Bit 16-31 Y-Coordinate (signed, with 12bit fractional part) Parameter 2, Bit 0-15 Z-Coordinate (signed, with 12bit fractional part) Parameter 2, Bit 16-31 Not used |
Parameter 1, Bit 0-9 X-Coordinate (signed, with 6bit fractional part) Parameter 1, Bit 10-19 Y-Coordinate (signed, with 6bit fractional part) Parameter 1, Bit 20-29 Z-Coordinate (signed, with 6bit fractional part) Parameter 1, Bit 30-31 Not used |
Parameter 1, Bit 0-15 X-Coordinate (signed, with 12bit fractional part) Parameter 1, Bit 16-31 Y-Coordinate (signed, with 12bit fractional part) |
Parameter 1, Bit 0-15 X-Coordinate (signed, with 12bit fractional part) Parameter 1, Bit 16-31 Z-Coordinate (signed, with 12bit fractional part) |
Parameter 1, Bit 0-15 Y-Coordinate (signed, with 12bit fractional part) Parameter 1, Bit 16-31 Z-Coordinate (signed, with 12bit fractional part) |
Parameter 1, Bit 0-9 X-Difference (signed, with 9/12bit fractional part) Parameter 1, Bit 10-19 Y-Difference (signed, with 9/12bit fractional part) Parameter 1, Bit 20-29 Z-Difference (signed, with 9/12bit fractional part) Parameter 1, Bit 30-31 Not used |
( xx, yy, zz, ww ) = ( x, y, z, 1.0 ) * ClipMatrix |
screen_x = (xx+ww)*viewport_width / (2*ww) + viewport_x1 screen_y = (yy+ww)*viewport_height / (2*ww) + viewport_y1 |
| DS 3D Polygon Light Parameters |
0-9 Directional Vector's X component (1bit sign + 9bit fractional part) 10-19 Directional Vector's Y component (1bit sign + 9bit fractional part) 20-29 Directional Vector's Z component (1bit sign + 9bit fractional part) 30-31 Light Number (0..3) |
0-4 Red (0..1Fh) ;\light color this will be combined with 5-9 Green (0..1Fh) ; diffuse, specular, and ambient colors 10-14 Blue (0..1Fh) ;/upon execution of the normal command 15-29 Not used 30-31 Light Number (0..3) |
0-4 Diffuse Reflection Red ;\light(s) that directly hits the polygon, 5-9 Diffuse Reflection Green ; ie. max when NormalVector has opposite 10-14 Diffuse Reflection Blue ;/direction of LightVector 15 Set Vertex Color (0=No, 1=Set Diffuse Reflection Color as Vertex Color) 16-20 Ambient Reflection Red ;\light(s) that indirectly hits the polygon, 21-25 Ambient Reflection Green ; ie. assuming that light is reflected by 26-30 Ambient Reflection Blue ;/walls/floor, regardless of LightVector 31 Not used |
0-4 Specular Reflection Red ;\light(s) reflected towards the camera, 5-9 Specular Reflection Green ; ie. max when NormalVector is in middle of 10-14 Specular Reflection Blue ;/LightVector and ViewDirection 15 Specular Reflection Shininess Table (0=Disable, 1=Enable) 16-20 Emission Red ;\light emitted by the polygon itself, 21-25 Emission Green ; ie. regardless of light colors/vectors, 26-30 Emission Blue ;/and no matter if any lights are enabled 31 Not used |
0-7 Shininess 0 (unsigned fixed-point, 0bit integer, 8bit fractional part)
8-15 Shininess 1 ("")
16-23 Shininess 2 ("")
24-31 Shininess 3 ("")
|
0-9 X-Component of Normal Vector (1bit sign + 9bit fractional part) 10-19 Y-Component of Normal Vector (1bit sign + 9bit fractional part) 20-29 Z-Component of Normal Vector (1bit sign + 9bit fractional part) 30-31 Not used |
IF TexCoordTransformMode=2 THEN TexCoord=NormalVector*Matrix (see TexCoord)
NormalVector=NormalVector*DirectionalMatrix
VertexColor = EmissionColor
FOR i=0 to 3
IF PolygonAttrLight[i]=enabled THEN
DiffuseLevel = max(0,-(LightVector[i]*NormalVector))
ShininessLevel = max(0,(-HalfVector[i])*(NormalVector))^2
IF TableEnabled THEN ShininessLevel = ShininessTable[ShininessLevel]
;note: below processed separately for the R,G,B color components...
VertexColor = VertexColor + SpecularColor*LightColor[i]*ShininessLevel
VertexColor = VertexColor + DiffuseColor*LightColor[i]*DiffuseLevel
VertexColor = VertexColor + AmbientColor*LightColor[i]
ENDIF
NEXT i
|
LightVector[i] = (LightVector*DirectionalMatrix) HalfVector[i] = (LightVector[i]+LineOfSightVector)/2 |
LineOfSightVector = (0,0,-1.0) |
Specular Reflection WON'T WORK when the ProjectionMatrix is rotated (!) |
| DS 3D Shadow Polygons |
| DS 3D Texture Attributes |
Parameter 1, Bit 0-15 S-Coordinate (X-Coordinate in Texture Source) Parameter 1, Bit 16-31 T-Coordinate (Y-Coordinate in Texture Source) Both values are 1bit sign + 11bit integer + 4bit fractional part. A value of 1.0 (=1 SHL 4) equals to one Texel. |
0-15 Texture VRAM Offset div 8 (0..FFFFh -> 512K RAM in Slot 0,1,2,3)
(VRAM must be allocated as Texture data, see Memory Control chapter)
16 Repeat in S Direction (0=Clamp Texture, 1=Repeat Texture)
17 Repeat in T Direction (0=Clamp Texture, 1=Repeat Texture)
18 Flip in S Direction (0=No, 1=Flip each 2nd Texture) (requires Repeat)
19 Flip in T Direction (0=No, 1=Flip each 2nd Texture) (requires Repeat)
20-22 Texture S-Size (for N=0..7: Size=(8 SHL N); ie. 8..1024 texels)
23-25 Texture T-Size (for N=0..7: Size=(8 SHL N); ie. 8..1024 texels)
26-28 Texture Format (0..7, see below)
29 Color 0 of 4/16/256-Color Palettes (0=Displayed, 1=Made Transparent)
30-31 Texture Coordinates Transformation Mode (0..3, see below)
|
0 No Texture - 1 A3I5 Translucent Texture 8bpp 2 4-Color Palette Texture 2bpp 3 16-Color Palette Texture 4bpp 4 256-Color Palette Texture 8bpp 5 4x4-Texel Compressed Texture 3bpp 6 A5I3 Translucent Texture 8bpp 7 Direct Texture 16bpp |
0 Do not Transform texture coordinates 1 TexCoord source 2 Normal source 3 Vertex source |
Clamp _____ Repeat Repeat+Flip _____/ /////////// /\/\/\/\/\/ |
0-12 Palette Base Address (div8 or div10h, see below)
(Not used for Texture Format 7: Direct Color Texture)
(0..FFF8h/8 for Texture Format 2: ie. 4-color-palette Texture)
(0..17FF0h/10h for all other Texture formats)
13-31 Not used
|
Bit0-4: Red Bit5-9: Green Bit10-14: Blue Bit15: Not used |
| DS 3D Texture Formats |
Bit0-4: Color Index (0..31) of a 32-color Palette Bit5-7: Alpha (0..7; 0=Transparent, 7=Solid) |
Bit0-2: Color Index (0..7) of a 8-color Palette Bit3-7: Alpha (0..31; 0=Transparent, 31=Solid) |
Bit0-7 Upper 4-Texel row (LSB=first/left-most Texel)
Bit8-15 Next 4-Texel row ("")
Bit16-23 Next 4-Texel row ("")
Bit24-31 Lower 4-Texel row ("")
|
Bit0-13 Palette Offset in 4-byte steps; Addr=(PLTT_BASE*10h)+(Offset*4) Bit14-15 Transparent/Interpolation Mode (0..3, see below) |
slot1_addr = slot0_addr / 2 ;lower 64K of Slot1 assoc to Slot0 slot1_addr = slot2_addr / 2 + 10000h ;upper 64K of Slot1 assoc to Slot2 |
Texel Mode 0 Mode 1 Mode 2 Mode 3 0 Color 0 Color0 Color 0 Color 0 1 Color 1 Color1 Color 1 Color 1 2 Color 2 (Color0+Color1)/2 Color 2 (Color0*5+Color1*3)/8 3 Transparent Transparent Color 3 (Color0*3+Color1*5)/8 |
| DS 3D Texture Coordinates |
( S' T' ) = ( S T ) |
| m[0] m[1] |
( S' T' ) = ( S T 1/16 1/16 ) * | m[4] m[5] |
| m[8] m[9] |
| m[12] m[13] |
|
| m[0] m[1] |
( S' T' ) = ( Nx Ny Nz 1.0 ) * | m[4] m[5] |
| m[8] m[9] |
| S T |
|
| m[0] m[1] |
( S' T' ) = ( Vx Vy Vz 1.0 ) * | m[4] m[5] |
| m[8] m[9] |
| S T |
|
Matrix m[..] 1+19+12 (32bit) Vertex Vx,Vy,Vz 1+3+12 (16bit) Normal Nx,Ny,Nz 1+0+9 (10bit) Constant 1.0 0+1+0 (1bit) Constant 1/16 0+0+4 (4bit) TexCoord S,T 1+11+4 (16bit) Result S',T' 1+11+4 (16bit) <-------- clipped to that size ! |
| DS 3D Texture Blending |
R = ((Rt+1)*(Rv+1)-1)/64 G = ((Gt+1)*(Gv+1)-1)/64 B = ((Bt+1)*(Bv+1)-1)/64 A = ((At+1)*(Av+1)-1)/64 |
R = (Rt*At + Rv*(63-At))/64 ;except, when At=0: R=Rv, when At=31: R=Rt G = (Gt*At + Gv*(63-At))/64 ;except, when At=0: G=Gv, when At=31: G=Gt B = (Bt*At + Bv*(63-At))/64 ;except, when At=0: B=Bv, when At=31: B=Bt A = Av |
R = ((Rt+1)*(Rs+1)-1)/64 ;Rs=ToonTableRed[Rv] G = ((Gt+1)*(Gs+1)-1)/64 ;Gs=ToonTableGreen[Rv] B = ((Bt+1)*(Bs+1)-1)/64 ;Bs=ToonTableBlue[Rv] A = ((At+1)*(Av+1)-1)/64 |
R = ((Rt+1)*(Rs+1)-1)/64+Rs ;truncated to MAX=63 G = ((Gt+1)*(Gs+1)-1)/64+Gs ;truncated to MAX=63 B = ((Bt+1)*(Bs+1)-1)/64+Bs ;truncated to MAX=63 A = ((At+1)*(Av+1)-1)/64 |
| DS 3D Toon, Edge, Fog, Alpha-Blending, Anti-Aliasing |
Bit0-4: Red, Bit5-9: Green, Bit10-14: Blue, Bit15: Not Used |
Bit0-4: Red, Bit5-9: Green, Bit10-14: Blue, Bit15: Not Used |
0-4 Fog Color, Red ;\ 5-9 Fog Color, Green ; used only when DISP3DCNT.Bit6 is zero 10-14 Fog Color, Blue ;/ 15 Not used 16-20 Fog Alpha ;-used no matter of DISP3DCNT.Bit6 21-31 Not used |
0-14 Fog Offset (Unsigned) (0..7FFFh) 15-31 Not used |
FogDepthBoundary[n] = FOG_OFFSET + FOG_STEP*(n+1) ;with n = 0..31 |
0-6 Fog Density (00h..7Fh = None..Full) (usually increasing values) 7 Not used |
FrameBuffer[R] = (FogColor[R]*Density + FrameBuffer[R]*(128-Density)) / 128 FrameBuffer[G] = (FogColor[G]*Density + FrameBuffer[G]*(128-Density)) / 128 FrameBuffer[B] = (FogColor[B]*Density + FrameBuffer[B]*(128-Density)) / 128 FrameBuffer[A] = (FogColor[A]*Density + FrameBuffer[A]*(128-Density)) / 128 |
FrameBuf[R] = (Poly[R]*(Poly[A]+1) + FrameBuf[R]*(31-(Poly[A])) / 32 FrameBuf[G] = (Poly[G]*(Poly[A]+1) + FrameBuf[G]*(31-(Poly[A])) / 32 FrameBuf[B] = (Poly[B]*(Poly[A]+1) + FrameBuf[B]*(31-(Poly[A])) / 32 FrameBuf[A] = max(Poly[A],FrameBuf[A]) |
1) Alpha-Blending is disabled (DISP3DCNT.Bit3=0) 2) The polygon pixel is opaque (Poly[A]=31) 3) The old framebuffer value is totally transparent (FrameBuf[A]=0) |
Opaque polygons (except wire-frames) without Edge-Marking and Anti-Aliasing, and, all polygons with vertical right-edges (except line-segments). Plus, Translucent Polys when Alpha-Blending is disabled in DISP3DCNT.Bit3. |
| DS 3D Status |
0 BoxTest,PositionTest,VectorTest Busy (0=Ready, 1=Busy) 1 BoxTest Result (0=All Outside View, 1=Parts or Fully Inside View) 2-7 Not used 8-12 Position & Vector Matrix Stack Level (0..31) (lower 5bit of 6bit value) 13 Projection Matrix Stack Level (0..1) 14 Matrix Stack Busy (0=No, 1=Yes; Currently executing a Push/Pop command) 15 Matrix Stack Overflow/Underflow Error (0=No, 1=Error/Acknowledge/Reset) 16-24 Number of 40bit-entries in Command FIFO (0..256) (24) Command FIFO Full (MSB of above) (0=No, 1=Yes; Full) 25 Command FIFO Less Than Half Full (0=No, 1=Yes; Less than Half-full) 26 Command FIFO Empty (0=No, 1=Yes; Empty) 27 Geometry Engine Busy (0=No, 1=Yes; Busy; Commands are executing) 28-29 Not used 30-31 Command FIFO IRQ (0=Never, 1=Less than half full, 2=Empty, 3=Reserved) |
0-11 Number of Polygons currently stored in Polygon List RAM (0..2048) 12-15 Not used 16-28 Number of Vertices currently stored in Vertex RAM (0..6144) 13-15 Not used |
0-5 Minimum Number (minus 2) of buffered lines in previous frame (0..46) 6-31 Not used |
| DS 3D Tests |
Parameter 1, Bit 0-15 X-Coordinate Parameter 1, Bit 16-31 Y-Coordinate Parameter 2, Bit 0-15 Z-Coordinate Parameter 2, Bit 16-31 Width (presumably: X-Offset?) Parameter 3, Bit 0-15 Height (presumably: Y-Offset?) Parameter 3, Bit 16-31 Depth (presumably: Z-Offset?) All values are 1bit sign, 3bit integer, 12bit fractional part |
Parameter 1, Bit 0-15 X-Coordinate Parameter 1, Bit 16-31 Y-Coordinate Parameter 2, Bit 0-15 Z-Coordinate Parameter 2, Bit 16-31 Not used All values are 1bit sign, 3bit integer, 12bit fractional part. |
Parameter 1, Bit 0-9 X-Component Parameter 1, Bit 10-19 Y-Component Parameter 1, Bit 20-29 Z-Component Parameter 1, Bit 30-31 Not used All values are 1bit sign, 9bit fractional part. |
| DS 3D Rear-Plane |
--> 2D Layers --> 3D Polygons --> 3D Rear-plane --> 2D Layers --> 2D Backdrop |
0-4 Clear Color, Red 5-9 Clear Color, Green 10-14 Clear Color, Blue 15 Fog (enables Fog to the rear-plane) (doesn't affect Fog of polygons) 16-20 Alpha 21-23 Not used 24-29 Clear Polygon ID (affects edge-marking, at the screen-edges?) 30-31 Not used |
0-14 Clear Depth (0..7FFFh) (usually 7FFFh = most distant) 15 Not used 16-31 See Port 4000356h, CLRIMAGE_OFFSET |
Rear Color Bitmap (located in Texture Slot 2)
0-4 Clear Color, Red
5-9 Clear Color, Green
10-14 Clear Color, Blue
15 Alpha (0=Transparent, 1=Solid) (equivalent to 5bit-alpha 0 and 31)
Rear Depth Bitmap (located in Texture Slot 3)
0-14 Clear Depth, expanded to 24bit as X=(X*200h)+((X+1)/8000h)*1FFh
15 Clear Fog (Initial fog enable value)
|
Bit0-7 X-Offset (0..255; 0=upper row of bitmap) Bit8-14 Y-Offset (0..255; 0=left column of bitmap) |
| DS 3D Final 2D Output |
Brightness up/down with BG0 as 1st Target via EVY (as for 2D) Blending with BG0 as 2nd Target via EVA/EVB (as for 2D) Blending with BG0 as 1st Target via 3D Alpha-values (unlike as for 2D) |
| DS Sound |
| DS Sound Channels 0..15 |
Bit0-6 Volume Mul (0..127=silent..loud) Bit7 Not used (always zero) Bit8-9 Volume Div (0=Normal, 1=Div2, 2=Div4, 3=Div16) Bit10-14 Not used (always zero) Bit15 Hold (0=Normal, 1=Hold last sample after one-shot sound) Bit16-22 Panning (0..127=left..right) (64=half volume on both speakers) Bit23 Not used (always zero) Bit24-26 Wave Duty (0..7) ;HIGH=(N+1)*12.5%, LOW=(7-N)*12.5% (PSG only) Bit27-28 Repeat Mode (0=Manual, 1=Loop Infinite, 2=One-Shot, 3=Prohibited) Bit29-30 Format (0=PCM8, 1=PCM16, 2=IMA-ADPCM, 3=PSG/Noise) Bit31 Start/Status (0=Stop, 1=Start/Busy) |
Bit0-26 Source Address (must be word aligned, bit0-1 are always zero) Bit27-31 Not used |
Bit0-15 Timer Value, Sample frequency, timerval=-(33513982Hz/2)/freq |
Bit0-15 Loop Start, Sample loop start position
(counted in words, ie. N*4 bytes)
|
Bit0-21 Sound length (counted in words, ie. N*4 bytes) Bit22-31 Not used |
| DS Sound Control Registers |
Bit0-6 Master Volume (0..127=silent..loud) Bit7 Not used (always zero) Bit8-9 Left Output from (0=Left Mixer, 1=Ch1, 2=Ch3, 3=Ch1+Ch3) Bit10-11 Right Output from (0=Right Mixer, 1=Ch1, 2=Ch3, 3=Ch1+Ch3) Bit12 Output Ch1 to Mixer (0=Yes, 1=No) (both Left/Right) Bit13 Output Ch3 to Mixer (0=Yes, 1=No) (both Left/Right) Bit14 Not used (always zero) Bit15 Master Enable (0=Disable, 1=Enable) Bit16-31 Not used (always zero) |
Bit0-9 Sound Bias (0..3FFh, usually 200h) Bit10-31 Not used (always zero) |
| DS Sound Capture |
Bit0 Control of Associated Sound Channels (ANDed with Bit7)
SNDCAP0CNT: Output Sound Channel 1 (0=As such, 1=Add to Channel 0)
SNDCAP1CNT: Output Sound Channel 3 (0=As such, 1=Add to Channel 2)
Caution: Addition mode works only if BOTH Bit0 and Bit7 are set.
Bit1 Capture Source Selection
SNDCAP0CNT: Capture 0 Source (0=Left Mixer, 1=Channel 0/Bugged)
SNDCAP1CNT: Capture 1 Source (0=Right Mixer, 1=Channel 2/Bugged)
Bit2 Capture Repeat (0=Loop, 1=One-shot)
Bit3 Capture Format (0=PCM16, 1=PCM8)
Bit4-6 Not used (always zero)
Bit7 Capture Start/Status (0=Stop, 1=Start/Busy)
|
Bit0-26 Destination address (word aligned, bit0-1 are always zero) Bit27-31 Not used (always zero) |
Bit0-15 Buffer length (1..FFFFh words) (ie. N*4 bytes) Bit16-31 Not used |
1) Both Negative Bug - SNDCAPxCNT Bit1=1, Bit0=0 (addition disabled) Capture data is accidently set to -8000h if ch(a) and ch(b) are both <0. Otherwise the correct capture result is returned, ie. plain ch(a) data, not being affected by ch(b) (since addition is disabled). Workaround: Ensure that ch(a) and/or ch(b) are >=0 (or disabled). 2) Overflow Bug - SNDCAPxCNT Bit1=1, Bit0=1 (addition enabled) In this mode, Capture data isn't clipped to MinMax(-8000h,+7FFFh), instead, it is ANDed with FFFFh, so the sign bit is lost if the addition result ch(a)+ch(b) is less/greater than -8000h/+7FFFh. Workaround: Reduce ch(a)/ch(b) volume or data to avoid overflows. |
1) Addition Result for Capture(x) when using capture source=ch(a): Addition is performed always, no matter of SOUNDCNT.Bit12/13. And, no matter of ch(a) enable, result is plain ch(b) if ch(a) is disabled. Result is 16bit (plus fraction) with overflow error (see Capture Bugs). 2) Addition Result for Mixer (towards speakers, and capture source=mixer): Ch(b) is muted if ch(a) is disabled. Ch(b) is muted if ch(b) SOUNDCNT.Bit12/13 is set to "Ch(b) not to mixer". Result is 17bit (plus fraction) without overflow error. |
| DS Sound Block Diagrams |
_____
Ch0.L ------------->| | .------------------------------> to Capture 0
___ | | | ___
Ch1.L ---o->|Sel|-->| | | Ch0..Ch15 | |
| |___| |Left |--o---------------->| |
Ch2.L ---|--------->|Mixer| |Sel| ______ ____
| ___ | | Ch1 | | |Master| |Add |
Ch3.L -o-|->|Sel|-->| | .----------------->| |->|Volume|->|Bias|-> L
| | |___| | | | | | |______| |____|
Ch4.L -|-|--------->| | | Ch3 | |
... -|-|--------->| | | .--------------->| |
Ch15.L-|-|--------->|_____| | | ___ | |
| '------------------o-|->|Add| Ch1+Ch3 | |
'----------------------o->|___|-------->|___|
|
____ _________ ___ ___ ___ |FIFO|-->|Channel 0|-->|Vol|-->|Add|-o->|Pan|--> Ch0.L |____| |_________| |___| |___| | |___|--> Ch0.R ____ _________ ___ ^ | |FIFO|<--|Capture 0|<--|Sel|<----|---' |____| |_ _____ _| |___|<----|-------------- Left Mixer ____ _:Timer:_ ___ _|_ ___ |FIFO|-->|Channel 1|-->|Vol|-->|Sel|--->|Pan|--> Ch1.L |____| |_________| |___| |___| |___|--> Ch1.R |
____ _________ ___ ___ |FIFO|-->|Channel 4|-->|Vol|----------->|Pan|--> Ch4.L |____| |_________| |___| |___|--> Ch4.R |
| DS Sound Notes |
data.vol = data*N/128 pan.left = data*(128-N)/128 pan.right = data*N/128 master.vol = data*N/128/64 |
Step Bits Min Max 0 Incoming PCM16 Data 16.0 -8000h +7FFFh 1 Volume Divider (div 1..16) 16.4 -8000h +7FFFh 2 Volume Factor (mul N/128) 16.11 -8000h +7FFFh 3 Panning (mul N/128) 16.18 -8000h +7FFFh 4 Rounding Down (strip 10bit) 16.8 -8000h +7FFFh 5 Mixer (add channel 0..15) 20.8 -80000h +7FFF0h 6 Master Volume (mul N/128/64) 14.21 -2000h +1FF0h 7 Strip fraction 14.0 -2000h +1FF0h 8 Add Bias (0..3FFh, def=200h) 15.0 -2000h+0 +1FF0h+3FFh 9 Clip (min/max 0h..3FFh) 10.0 0 +3FFh |
0 12.5% "_______-_______-_______-" 1 25.0% "______--______--______--" 2 37.5% "_____---_____---_____---" 3 50.0% "____----____----____----" 4 62.5% "___-----___-----___-----" 5 75.0% "__------__------__------" 6 87.5% "_-------_-------_-------" 7 0.0% "________________________" |
X=X SHR 1, IF carry THEN Out=LOW, X=X XOR 6000h ELSE Out=HIGH |
Bit0-15 Initial PCM16 Value (Pcm16bit = -7FFFh..+7FFF) (not -8000h) Bit16-22 Initial Table Index Value (Index = 0..88) Bit23-31 Not used (zero) |
Diff = ((Data4bit AND 7)*2+1)*AdpcmTable[Index]/8 ;see rounding-error IF (Data4bit AND 8)=0 THEN Pcm16bit = Max(Pcm16bit+Diff,+7FFFh) IF (Data4bit AND 8)=8 THEN Pcm16bit = Min(Pcm16bit-Diff,-7FFFh) Index = MinMax (Index+IndexTable[Data4bit AND 7],0,88) |
Diff = AdpcmTable[Index]/8 IF (data4bit AND 1) THEN Diff = Diff + AdpcmTable[Index]/4 IF (data4bit AND 2) THEN Diff = Diff + AdpcmTable[Index]/2 IF (data4bit AND 4) THEN Diff = Diff + AdpcmTable[Index]/1 |
Max(+7FFFh) leaves -8000h unclipped (can happen if initial PCM16 was -8000h) Min(-7FFFh) clips -8000h to -7FFFh (possibly unlike windows .WAV files?) |
0007h,0008h,0009h,000Ah,000Bh,000Ch,000Dh,000Eh,0010h,0011h,0013h,0015h 0017h,0019h,001Ch,001Fh,0022h,0025h,0029h,002Dh,0032h,0037h,003Ch,0042h 0049h,0050h,0058h,0061h,006Bh,0076h,0082h,008Fh,009Dh,00ADh,00BEh,00D1h 00E6h,00FDh,0117h,0133h,0151h,0173h,0198h,01C1h,01EEh,0220h,0256h,0292h 02D4h,031Ch,036Ch,03C3h,0424h,048Eh,0502h,0583h,0610h,06ABh,0756h,0812h 08E0h,09C3h,0ABDh,0BD0h,0CFFh,0E4Ch,0FBAh,114Ch,1307h,14EEh,1706h,1954h 1BDCh,1EA5h,21B6h,2515h,28CAh,2CDFh,315Bh,364Bh,3BB9h,41B2h,4844h,4F7Eh 5771h,602Fh,69CEh,7462h,7FFFh |
X=000776d2h, FOR I=0 TO 88, Table[I]=X SHR 16, X=X+(X/10), NEXT I Table[3]=000Ah, Table[4]=000Bh, Table[88]=7FFFh, Table[89..127]=0000h |
| DS Files - Sound (SDAT etc.) |
| DS Sound Files - SDAT (Sound Data Archive) |
000h 4 ID "SDAT" ;alike "CSAR" on 3DS 004h 2 Byte Order (FEFFh) 006h 2 Version (0100h) 008h 4 Total Filesize 00Ch 2 Header Size (usually 40h) 00Eh 2 Number of Blocks (usually 4 = SYMB+INFO+FAT+FILE) (or 3=no SYMB) 010h 4+4 SYMB Block (Offset from SDAT+0, Size) ;=0,0 if above is 3=no SYMB 018h 4+4 INFO Block (Offset from SDAT+0, Size) ;\ 020h 4+4 FAT Block (Offset from SDAT+0, Size) ; always present 028h 4+4 FILE Block (Offset from SDAT+0, Size) ;/ 030h 10h Padding to 20h-byte boundary (0) |
_________________________________ SYMB Block _________________________________ |
000h 4 ID "SYMB" 004h 4 SYMB Block Size (rounded up to 4-byte boundary, unlike as in SDAT) 008h 4 File List SSEQ (Offset from SYMB+0) Sequences (songs) 00Ch 4 Folder List SSAR (Offset from SYMB+0) Sequence Archives (fx) 010h 4 File List BANK (Offset from SYMB+0) Banks 014h 4 File List SWAR (Offset from SYMB+0) Wave Archives (samples) 018h 4 File List Player (Offset from SYMB+0) Player (Group-related) 01Ch 4 File List Group (Offset from SYMB+0) Group (SSEQ+SSAR+BANK+SWAR) 020h 4 File List Player2 (Offset from SYMB+0) Player2 (Stream-related) 024h 4 File List STRM (Offset from SYMB+0) Wave Stream 028h 18h Reserved (0) 040h .. File/Folder Lists (see below) .. .. File/Folder Name Strings (ASCII, terminated by 0) .. .. Padding to 4-byte boundary (0) |
000h 4 Number of entries in this list (can be 0=None) 004h N*4 File Name (Offset from SYMB+0) |
000h 4 Number of entries in this list (can be 0=None) 004h N*(4+4) SSAR "Folder Name" and SSEQ "File List" (Offset's from SYMB+0) |
_________________________________ INFO Block _________________________________ |
000h 4 ID "INFO" 004h 4 INFO Block Size (same as in SDAT header) 008h 4 Info List SSEQ (Offset from INFO+0) Sequences (songs) 00Ch 4 Info List SSAR (Offset from INFO+0) Sequence Archives (fx) 010h 4 Info List BANK (Offset from INFO+0) Banks 014h 4 Info List SWAR (Offset from INFO+0) Wave Archives (samples) 018h 4 Info List Player (Offset from INFO+0) Player (Group-related) 01Ch 4 Info List Group (Offset from INFO+0) Group (SSEQ+SSAR+BANK+SWAR) 020h 4 Info List Player2 (Offset from INFO+0) Player2 (Stream-related) 024h 4 Info List STRM (Offset from INFO+0) Wave Stream 028h 18h Reserved (0) .. .. Info Lists (see below) .. .. Info Entries (see below) .. .. Padding to 4-byte boundary (0) |
000h 4 Number of entries in this list (can be 0=None) 004h N*4 Info Entries (Offset from INFO+0) |
000h 2 FAT fileID of SSEQ file ;for accessing this file 002h 2 Unknown 004h 2 bnk ;Associated BANK 006h 1 vol ;Volume 007h 1 cpr 008h 1 ppr 009h 1 ply 00Ah 2 Unknown (0) |
000h 2 FAT fileID of SSAR file 002h 2 unknown |
000h 2 FAT fileID of SBNK file 002h 2 unknown 004h 2 1st SWAR ;\ 006h 2 2nd SWAR ; Associated Wave Archives (FFFFh=Unused entry) 008h 2 3rd SWAR ; 00Ah 2 4th SWAR ;/ |
000h 2 FAT fileID of SWAR file 002h 2 unknown |
000h 1 Unknown 001h 3 Padding 004h 4 Unknown |
000h 4 Number of items in this group 004h N*(4+4) Array (with ID+Index pairs) |
000h 1 nCount ;number of USED entries in below array 001h 16 v[16] ;unknown array (UNUSED entries are set to FFh 011h 7 Reserved (0) |
000h 2 FAT fileID of STRM file ;for accessing the file 002h 2 Unknown 004h 1 vol ;volume 005h 1 pri ;priority? 006h 1 ply ;play? 007h 5 Reserved (0) |
____________________________ FAT and FILE Blocks _____________________________ |
000h 4 ID "FAT " 004h 4 FAT Block Size (same as in SDAT header) (0Ch+N*10h) 008h 4 Number of files 00Ch N*(4+4+8) File Entries (Offset from SDAT+0, Size, Zero) |
000h 4 ID "FILE" 004h 4 FILE Block Size (same as in SDAT header) 008h 4 Number of files (same as in FAT block) 00Ch 4 Reserved (0) 010h .. Files (SSEQ,SSAR,SBNK,SWAR,STRM) (at offsets specified in FAT) |
| DS Sound Files - SSEQ (Sound Sequence) |
000h 4 ID "SSEQ" ;\ 004h 2 Byte Order (FEFFh) ; 006h 2 Version (0100h) ; Main header 008h 4 Total Filesize ; 00Ch 2 Header Size (usually 10h) ; 00Eh 2 Number of Blocks (usually 1 = DATA) ;/ 010h 4 ID "DATA" ;\ 014h 4 Total Filesize, minus 10h ; Sub header 018h 4 Offset to data (from SSEQ+0) (1Ch) ;/ 01Ch .. Arrays of sequence data.. ;- |
cycle variable action 1 0 Add 160 2 160 Add 160 3 320 Subtract 240, process once, add 160 4 240 Subtract 240, process once, add 160 5 160 Add 160 6 320 Subtract 240, process once, add 160 7 240 Subtract 240, process once, add 160 8 160 Add 160 |
ID Parameter Description
00h-7Fh Velocity: 1 byte [0..127]
Duration: Variable Length
NOTE-ON. Duration is expressed in tick.
48 for quartet note.
Usually it is NOT a multiple of 3.
80h Duration: Variable Length
REST. It tells the SSEQ-sequencer to wait for
a certain tick. Usually it is a multiple of 3.
81h Bank & Program Number:
Variable Length
bits[0..7] is the program number,
bits[8..14] is the bank number.
Bank change is seldomly found,
so usually bank 0 is used.
FEh 2 bytes Indicates which tracks are used.
Bit0 for track 0, ... Bit15 for track 15.
If the bit is set, the corresponding track is used.
Indication begin of multitrack. Must be in the
beginning of the first track to work. A series
of event 0x93 follows.
93h 4 bytes 1st byte is track number [0..15]
The other 3 bytes are the relative adress of track data.
Add nDataOffset (usually 0x1C) to find out the absolute address.
SSEQ is similar to MIDI in that track data are
stored one after one track. Unlike mod music.
94h JUMP Address: 3 bytes
(Add nDataOffset (usually 0x1C) to find out the absolute address.)
JUMP. A jump must be backward. So that the
song will loop forever.
95h CALL Address: 3 bytes
(Add nDataOffset (usually 0x1C) to find out the absolute address.)
A0h-BFh See loveemu's sseq2mid for more details.
Some arithmetic operations / comparions.
Affect how SSEQ is to be played.
C0h 1 byte PAN (0..127, middle is 64, uh?)
C1h 1 byte VOLUME (0..127)
C2h 1 byte MASTER VOLUME (0..127)
C3h 1 byte TRANSPOSE (Channel Coarse Tuning) (0..64 = 64..128 in MIDI)
C4h 1 byte PITCH BEND
C5h 1 byte PITCH BEND RANGE
C6h 1 byte TRACK PRIORITY
C7h 1 byte MONO/POLY (0=Poly, 1=Mono)
C8h 1 byte TIE (unknown) (0=Off, 1=On)
C9h 1 byte PORTAMENTO CONTROL
CAh 1 byte MODULATION DEPTH (0=Off, 1=On)
CBh 1 byte MODULATION SPEED
CCh 1 byte MODULATION TYPE (0=Pitch, 1=Volume, 2=Pan)
CDh 1 byte MODULATION RANGE
CEh 1 byte PORTAMENTO ON/OFF
CFh 1 byte PORTAMENTO TIME
D0h 1 byte ATTACK RATE
D1h 1 byte DECAY RATE
D2h 1 byte SUSTAIN RATE
D3h 1 byte RELEASE RATE
D4h 1 byte LOOP START (how many times to be looped)
D5h 1 byte EXPRESSION
D6h 1 byte PRINT VARIABLE (unknown)
E0h 2 byte MODULATION DELAY
E1h 2 byte TEMPO
E3h 2 byte SWEEP PITCH
FCh - LOOP END (for LOOP START)
FDh - RETURN from CALL command
FFh - EOT: End Of Track
|
| DS Sound Files - SSAR (Sound Sequence Archive) |
000h 4 ID "SSAR" ;\ 004h 2 Byte Order (FEFFh) ; 006h 2 Version (0100h) ; Main header 008h 4 Total Filesize ; 00Ch 2 Header Size (usually 10h) ; 00Eh 2 Number of Blocks (usually 1 = DATA) ;/ 010h 4 ID "DATA" ;\ 014h 4 Total Filesize, minus 10h ; 018h 4 Offset to data (from SSAR+0) (20h+N*0Ch) ; Sub header 01Ch 4 Number of records ; 020h N*0Ch Records (12 bytes each) ;/ .. .. data... unknown content? alike SSEQ? ;- |
000h 4 nOffset ;relative offset of the archived SEQ file,
absolute offset = nOffset + SSAR::nDataOffset
004h 2 bnk ;bank
006h 1 vol ;volume
007h 1 cpr ;channel pressure
008h 1 ppr ;polyphonic pressure
009h 1 ply ;play
00Ah 2 reserved (0)
|
data... unknown content? alike SSEQ? |
| DS Sound Files - SBNK (Sound Bank) |
000h 4 ID "SBNK" ;\ 004h 2 Byte Order (FEFFh) ; 006h 2 Version (0100h) ; Main header 008h 4 Total Filesize ; 00Ch 2 Header Size (usually 10h) ; 00Eh 2 Number of Blocks (usually 1 = DATA) ;/ 010h 4 ID "DATA" ;\ 014h 4 Total Filesize, minus 10h ; 018h 20h Reserved (0) (for use at runtime) ; Sub header 038h 4 Number of Instruments (SWAV's) ; 03Ch N*4 Instrument Records (1+2+1 bytes per instr.) ;/ ... .. Instrument Data (depending of above records) ;- |
000h 1 fRecord ;can be either 0, 1..4, 16 or 17 001h 2 nOffset ;absolute offset of the data in file ;uh, misaligned? 003h 1 Reserved (0) |
00h 10 SWAV, SWAR, Note, Attack, Decay, Sustain, Release, Pan |
00h 1 Lower note (0..127) ;eg. 10 ;\notes 10..20 01h 1 Upper note (0..127) ;eg. 20 ;/ 02h+N*12 2 Unknown (usually 0001h) 04h+N*12 10 SWAV, SWAR, Note, Attack, Decay, Sustain, Release, Pan |
00h 1 End of 1st region (0..127) ;eg. 25 = notes 0..25 01h 1 End of 2nd region (0..127) ;eg. 35 = notes 26..35 02h 1 End of 3rd region (0..127) ;eg. 45 = notes 36..45 03h 1 End of 4th region (0..127) ;eg. 55 = notes 46..55 04h 1 End of 5th region (0..127) ;eg. 65 = notes 56..65 05h 1 End of 6th region (0..127) ;eg. 127 = notes 66..last 06h 1 End of 7th region (0..127) ;eg. 0 = none 07h 1 End of 8th region (0..127) ;eg. 0 = none 08h+N*12 2 Unknown (usually 0001h) 08h+N*12 10 SWAV, SWAR, Note, Attack, Decay, Sustain, Release, Pan |
00h 2 SWAV Number the swav used 02h 2 SWAR Mumber the swar used (see Info Block --> "BANK Info Entry") 04h 1 Note Number (0..127) 05h 1 Attack Rate (0..127, 127=fast) 06h 1 Decay Rate (0..127, 127=fast) 07h 1 Sustain Level (0..127, 127=stay at max, no decay) 08h 1 Release Rate (0..127, 127=fast) 09h 1 Pan (0..127, 64=middle) (uh, what=left, what=right?) |
. <-- max level (127)
/ \
/ \
/ '---------. <-- sustain level (0..127)
/ \
/ \
-----'---------------------'-- <-- min level (0)
Attack Decay Sustain Release
|
"The SEQ Player treats 0 as the 100% amplitude value and -92544 (723*128) as the 0% amplitude value. The starting ampltitude is 0% (-92544)." uh? |
"During the attack phase, in each cycle, the SSEQ Player calculates the new amplitude value: amplitude value = attack rate * amplitude value / 255. The attack phase stops when amplitude reaches 0." THAT IS... NON-LINEAR attack? |
"During the decay phase, in each cycle, the SSEQ Player calculates the new amplitude value: amplitude value = amplitude value - decay rate. Note the starting amplitude value is 0. The decay phase stops when amplitude reaches sustain level." THAT IS... LINEAR decay/release? |
| DS Sound Files - SWAR (Sound Wave Archive) |
000h 4 ID "SWAR" ;\ 004h 2 Byte Order (FEFFh) ; 006h 2 Version (0100h) ; Main header 008h 4 Total Filesize (including SWAV's) ; 00Ch 2 Header Size (usually 10h) ; 00Eh 2 Number of Blocks (usually 1 = DATA) ;/ 010h 4 ID "DATA" ;\ 014h 4 Total Filesize, minus 10h ; 018h 20h Reserved (0) (for use at runtime) ; Sub header 038h 4 Number of SWAV sample blocks ; 03Ch N*4 Offsets to Sample blocks (from SWAR+0) ;/ .. .. Sample blocks... starting with Type (0=PCM8, 1=PCM16, 2=IMA-ADPCM) |
| DS Sound Files - SWAV (Sound Wave Data) |
000h 4 ID "SWAV" ;\ 004h 2 Byte Order (FEFFh) ; 006h 2 Version (0100h) ; Main header 008h 4 Total Filesize ; 00Ch 2 Header Size (usually 10h) ; 00Eh 2 Number of Blocks (usually 1 = DATA) ;/ 010h 4 ID "DATA" ;\Sub header 014h 4 Total Filesize, minus 10h ;/ 018h .. Sample block (see below) |
000h 1 WaveType (0=PCM8, 1=PCM16, 2=IMA-ADPCM)
001h 1 Loop flag = TRUE|FALSE ;uh?
002h 2 Sampling Rate
004h 2 Time (ARM7_CLOCK / nSampleRate)
[ARM7_CLOCK: 33.513982MHz/2 = 1.6756991 E +7]
006h 2 Loop Offset, in 4-byte units
008h 4 Sound Length, in 4-byte units (exluding ADPCM header, if any)
00Ch ... Data... (samples) (with 32bit header in case of ADPCM)
|
| DS Sound Files - STRM (Sound Wave Stream) |
000h 4 ID "STRM" ;\
004h 2 Byte Order (FEFFh) ;
006h 2 Version (0100h) ; Main header
008h 4 Total Filesize ;
00Ch 2 Header Size (usually 10h) ;
00Eh 2 Number of Blocks (usually 2 = HEAD+DATA) ;/
010h 4 ID "HEAD" ;\
014h 4 Size of HEAD structure (uh, this is... 50h?) ;
018h 1 Type (0=PCM8, 1=PCM16, 2=IMA-ADPCM) ; Sub header
019h 1 Loop flag (?=TRUE|FALSE) ;uh? ;
01Ah 1 Channels (?=What) ;mono/stereo? ;
01Bh 1 Unknown (always 0) ;
01Ch 2 Sampling Rate (perhaps resampled from original) ;
01Eh 2 Time (1.0 / rate * ARM7_CLOCK / 32) ;
[ARM7_CLOCK: 33.513982MHz/2 = 1.6756991e7] ;
020h 4 Loop Offset (samples) ;
024h 4 Number of Samples ;
028h 4 Wave Data Offset (always 68h) ;
02Ch 4 Number of Blocks (per what?) ;
030h 4 Block Length (per Channel) ;
034h 4 Samples Per Block (per Channel) ;
038h 4 Last Block Length (per Channel) ;
03Ch 4 Samples Per Last Block (per Channel) ;
040h 20h Reserved (always 0) ;/
060h 4 ID "DATA" ;\Data header
064h 4 Data Size (8+N ?) ;/
068h N Wave Data blocks... ;-Sample data
|
| DS Sound Files - HWAS (Multiblock Sound Wave Data) |
000h 4 ID "sawh" (aka "hwas" spelled backwards) 004h 4 Blocksize (2000h in Over the Hedge, 8000h in Guitar Heroes) 008h 4 Samplerate in Hertz (always 19996) 00Ch 4 Number of Channels (always 1=mono) 010h 4 Loop Start Sample (always 0, offset from start of data section) 014h 4 Filesize minus 200h (ie. excluding 200h-byte header) 018h 4 Loop End Sample (end of music, offset from start of data section) 01Ch 1E4h Zerofilled Data Section: 200h .. 1st data block (adpcm_header[4], plus adpcm_data[blocksize]) ... .. 2nd data block (adpcm_header[4], plus adpcm_data[blocksize]) ... .. etc. ... .. Last data block (adpcm_header[4], plus adpcm_data[remaining bytes]) ... .. Padding to 200h-byte boundary |
| DS System and Built-in Peripherals |
| DS DMA Transfers |
0 Start Immediately 1 Start at V-Blank 2 Start at H-Blank (paused during V-Blank) 3 Synchronize to start of display 4 Main memory display 5 DS Cartridge Slot 6 GBA Cartridge Slot 7 Geometry Command FIFO |
0 Start Immediately 1 Start at V-Blank 2 DS Cartridge Slot 3 DMA0/DMA2: Wireless interrupt, DMA1/DMA3: GBA Cartridge Slot |
Bit0-31 Filldata |
| DS Timers |
| DS Interrupts |
0 Disable all interrupts (0=Disable All, 1=See IE register) 1-31 Not used |
0 LCD V-Blank 1 LCD H-Blank 2 LCD V-Counter Match 3 Timer 0 Overflow 4 Timer 1 Overflow 5 Timer 2 Overflow 6 Timer 3 Overflow 7 NDS7 only: SIO/RCNT/RTC (Real Time Clock) 8 DMA 0 9 DMA 1 10 DMA 2 11 DMA 3 12 Keypad 13 GBA-Slot (external IRQ source) / DSi: None such 14 Not used / DSi9: NDS-Slot Card change? 15 Not used / DSi: dito for 2nd NDS-Slot? 16 IPC Sync 17 IPC Send FIFO Empty 18 IPC Recv FIFO Not Empty 19 NDS-Slot Game Card Data Transfer Completion 20 NDS-Slot Game Card IREQ_MC 21 NDS9 only: Geometry Command FIFO 22 NDS7 only: Screens unfolding 23 NDS7 only: SPI bus 24 NDS7 only: Wifi / DSi9: XpertTeak DSP 25 Not used / DSi9: Camera 26 Not used / DSi9: Undoc, IF.26 set on FFh-filling 40021Axh 27 Not used / DSi: Maybe IREQ_MC for 2nd gamecard? 28 Not used / DSi: NewDMA0 29 Not used / DSi: NewDMA1 30 Not used / DSi: NewDMA2 31 Not used / DSi: NewDMA3 ? DSi7: any further new IRQs on ARM7 side... in bit13-15,21,25-26? |
0 DSi7: GPIO18[0] ;\ 1 DSi7: GPIO18[1] ; maybe 1.8V signals? 2 DSi7: GPIO18[2] ;/ 3 DSi7: Unused (0) 4 DSi7: GPIO33[0] unknown (related to "GPIO330" testpoint on mainboard?) 5 DSi7: GPIO33[1] Headphone connect (HP#SP) (static state) 6 DSi7: GPIO33[2] Powerbutton interrupt (short pulse upon key-down) 7 DSi7: GPIO33[3] Sound Enable Output (ie. not a useful irq-input) 8 DSi7: SD/MMC Controller ;-Onboard eMMC and External SD Slot 9 DSi7: SD Slot Data1 pin ;-For SDIO hardware in External SD Slot 10 DSi7: SDIO Controller ;\Atheros Wifi Unit 11 DSi7: SDIO Data1 pin ;/ 12 DSi7: AES interrupt 13 DSi7: I2C interrupt 14 DSi7: Microphone Extended interrupt 15-31 DSi7: Unused (0) |
Bit 0-31 Pointer to IRQ Handler |
Bit 0-31 IRQ Flags (same format as IE/IF registers) |
| DS Maths |
0-1 Division Mode (0-2=See below) (3=Reserved; same as Mode 1) 2-13 Not used 14 Division by zero (0=Okay, 1=Division by zero error; 64bit Denom=0) 15 Busy (0=Ready, 1=Busy) (Execution time see below) 16-31 Not used |
Mode Numer / Denom = Result, Remainder ; Cycles 0 32bit / 32bit = 32bit , 32bit ; 18 clks 1 64bit / 32bit = 64bit , 32bit ; 34 clks 2 64bit / 64bit = 64bit , 64bit ; 34 clks |
DIV0 --> REMAIN=NUMER, RESULT=+/-1 (with sign opposite of NUMER) -MAX/-1 --> RESULT=-MAX (instead +MAX) |
0 Mode (0=32bit input, 1=64bit input) 1-14 Not used 15 Busy (0=Ready, 1=Busy) (Execution time is 13 clks, in either Mode) 16-31 Not used |
| DS Inter Process Communication (IPC) |
Bit Dir Expl. 0-3 R Data input from IPCSYNC Bit8-11 of remote CPU (00h..0Fh) 4-7 - Not used 8-11 R/W Data output to IPCSYNC Bit0-3 of remote CPU (00h..0Fh) 12 - Not used 13 W Send IRQ to remote CPU (0=None, 1=Send IRQ) 14 R/W Enable IRQ from remote CPU (0=Disable, 1=Enable) 15-31 - Not used |
Bit Dir Expl. 0 R Send Fifo Empty Status (0=Not Empty, 1=Empty) 1 R Send Fifo Full Status (0=Not Full, 1=Full) 2 R/W Send Fifo Empty IRQ (0=Disable, 1=Enable) 3 W Send Fifo Clear (0=Nothing, 1=Flush Send Fifo) 4-7 - Not used 8 R Receive Fifo Empty (0=Not Empty, 1=Empty) 9 R Receive Fifo Full (0=Not Full, 1=Full) 10 R/W Receive Fifo Not Empty IRQ (0=Disable, 1=Enable) 11-13 - Not used 14 R/W Error, Read Empty/Send Full (0=No Error, 1=Error/Acknowledge) 15 R/W Enable Send/Receive Fifo (0=Disable, 1=Enable) 16-31 - Not used |
Bit0-31 Send Fifo Data (max 16 words; 64bytes) |
Bit0-31 Receive Fifo Data (max 16 words; 64bytes) |
| DS Keypad |
0 Button X (0=Pressed, 1=Released) 1 Button Y (0=Pressed, 1=Released) 2 Unknown / set 3 DEBUG button (0=Pressed, 1=Released/None such) 4,5 Unknown / set 6 Pen down (0=Pressed, 1=Released/Disabled) (always 0 in DSi mode) 7 Hinge/folded (0=Open, 1=Closed) 8..15 Unknown / zero |
| DS Absent Link Port |
NDS7 4000128h SIOCNT Bit15 "CKUP" New Bit in NORMAL/MULTI/UART mode (R/W) NDS7 4000128h SIOCNT Bit14 "N/A" Removed IRQ Bit in UART mode (?) NDS7 400012Ah SIOCNT_H Bit14 "TFEMP" New Bit (R/W) NDS7 400012Ah SIOCNT_H Bit15 "RFFUL" New Bit (always zero?) NDS7 400012Ch SIOSEL Bit0 "SEL" New Bit (always zero?) NDS7 4000140h JOYCNT Bit7 "MOD" New Bit (R/W) |
NDS9 4000120h SIODATA32 Bit0-31 Data (always zero?) NDS9 4000128h SIOCNT Bit2 "TRECV" New Bit (always zero?) NDS9 4000128h SIOCNT Bit3 "TSEND" New Bit (always zero?) NDS9 400012Ch SIOSEL Bit0 "SEL" New Bit (always zero?) |
| DS Real-Time Clock (RTC) |
Bit Expl. 0 Data I/O (0=Low, 1=High) 1 Clock Out (0=Low, 1=High) 2 Select Out (0=Low, 1=High/Select) 4 Data Direction (0=Read, 1=Write) 5 Clock Direction (should be 1=Write) 6 Select Direction (should be 1=Write) 3,8-11 Unused I/O Lines 7,12-15 Direction for Bit3,8-11 (usually 0) 16-31 Not used |
Init CS=LOW and /SCK=HIGH, and wait at least 1us Switch CS=HIGH, and wait at least 1us Send the Command byte (see bit-transfer below) Send/receive Parameter byte(s) associated with the command (see below) Switch CS to LOW |
Output /SCK=LOW and SIO=databit (when writing), then wait at least 5us Output /SCK=HIGH, wait at least 5us, then read SIO=databit (when reading) In either direction, data is output on (or immediately after) falling edge. |
Command Register
Fwd Rev
0 7 Fixed Code (must be 0)
1 6 Fixed Code (must be 1)
2 5 Fixed Code (must be 1)
3 4 Fixed Code (must be 0, or, DSi only: 1=Extended Command)
4-6 3-1 Command
Fwd Rev Parameter bytes (read/write access)
0 0 1 byte, status register 1
4 1 1 byte, status register 2
2 2 7 bytes, date & time (year,month,day,day_of_week,hh,mm,ss)
6 3 3 bytes, time (hh,mm,ss)
1* 4* 1 byte, int1, frequency duty setting
1* 4* 3 bytes, int1, alarm time 1 (day_of_week, hour, minute)
5 5 3 bytes, int2, alarm time 2 (day_of_week, hour, minute)
3 6 1 byte, clock adjustment register
7 7 1 byte, free register
Extended command (when above "fourth bit" was set, DSi only)
Fwd Rev Parameter bytes (read/write access)
0 0 3 byte, up counter (msw,mid,lsw) (read only)
4 1 1 byte, FOUT register setting 1
2 2 1 byte, FOUT register setting 2
6 3 reserved
1 4 3 bytes, alarm date 1 (year,month,day)
5 5 3 bytes, alarm date 2 (year,month,day)
3 6 reserved
7 7 reserved
7 0 Parameter Read/Write Access (0=Write, 1=Read)
|
Status Register 1
0 W Reset (0=Normal, 1=Reset)
1 R/W 12/24 hour mode (0=12 hour, 1=24 hour)
2-3 R/W General purpose bits
4 R Interrupt 1 Flag (1=Yes) ;auto-cleared on read
5 R Interrupt 2 Flag (1=Yes) ;auto-cleared on read
6 R Power Low Flag (0=Normal, 1=Power is/was low) ;auto-cleared on read
7 R Power Off Flag (0=Normal, 1=Power was off) ;auto-cleared on read
Power off indicates that the battery was removed or fully discharged,
all registers are reset to 00h (or 01h), and must be re-initialized.
Status Register 2
0-3 R/W INT1 Mode/Enable
0000b Disable
0x01b Selected Frequency steady interrupt
0x10b Per-minute edge interrupt
0011b Per-minute steady interrupt 1 (duty 30.0 seconds)
0100b Alarm 1 interrupt
0111b Per-minute steady interrupt 2 (duty 0.0079 seconds)
1xxxb 32kHz output
4-5 R/W General purpose bits
6 R/W INT2 Enable
0b Disable
1b Alarm 2 interrupt
7 R/W Test Mode (0=Normal, 1=Test, don't use) (cleared on Reset)
Clock Adjustment Register (to compensate oscillator inaccuracy)
0-7 R/W Adjustment (00h=Normal, no adjustment)
Free Register
0-7 R/W General purpose bits
|
Year Register
0-7 R/W Year (BCD 00h..99h = 2000..2099)
Month Register
0-4 R/W Month (BCD 01h..12h = January..December)
5-7 - Not used (always zero)
Day Register
0-5 R/W Day (BCD 01h..28h,29h,30h,31h, range depending on month/year)
6-7 - Not used (always zero)
Day of Week Register (septenary counter)
0-2 R/W Day of Week (00h..06h, custom assignment, usually 0=Monday?)
3-7 - Not used (always zero)
|
Hour Register
0-5 R/W Hour (BCD 00h..23h in 24h mode, or 00h..11h in 12h mode)
6 * AM/PM (0=AM before noon, 1=PM after noon)
* 24h mode: AM/PM flag is read only (PM=1 if hour = 12h..23h)
* 12h mode: AM/PM flag is read/write-able
* 12h mode: Observe that 12 o'clock is defined as 00h (not 12h)
7 - Not used (always zero)
Minute Register
0-6 R/W Minute (BCD 00h..59h)
7 - Not used (always zero)
Second Register
0-6 R/W Minute (BCD 00h..59h)
7 - Not used (always zero)
|
Alarm1 and Alarm2 Day of Week Registers (INT1 and INT2 each)
0-2 R/W Day of Week (00h..06h)
3-6 - Not used (always zero)
7 R/W Compare Enable (0=Alarm every day, 1=Alarm only at specified day)
Alarm1 and Alarm2 Hour Registers (INT1 and INT2 each)
0-5 R/W Hour (BCD 00h..23h in 24h mode, or 00h..11h in 12h mode)
6 R/W AM/PM (0=AM, 1=PM) (must be correct even in 24h mode?)
7 R/W Compare Enable (0=Alarm every hour, 1=Alarm only at specified hour)
Alarm1 and Alarm2 Minute Registers (INT1 and INT2 each)
0-6 R/W Minute (BCD 00h..59h)
7 R/W Compare Enable (0=Alarm every min, 1=Alarm only at specified min)
Selected Frequency Steady Interrupt Register (INT1 only) (when Stat2/Bit2=0)
0 R/W Enable 1Hz Frequency (0=Disable, 1=Enable)
1 R/W Enable 2Hz Frequency (0=Disable, 1=Enable)
2 R/W Enable 4Hz Frequency (0=Disable, 1=Enable)
3 R/W Enable 8Hz Frequency (0=Disable, 1=Enable)
4 R/W Enable 16Hz Frequency (0=Disable, 1=Enable)
The signals are ANDed when two or more frequencies are enabled,
ie. the /INT signal gets LOW when either of the signals is LOW.
5-7 R/W General purpose bits
|
Up Counter Msw
0-7 R Up Counter bit16-23 (non-BCD, 00h..FFh)
Up Counter Mid
0-7 R Up Counter bit8-15 (non-BCD, 00h..FFh)
Up Counter Lsw
0-7 R Up Counter bit0-7 (non-BCD, 00h..FFh)
|
Alarm 1 and Alarm 2 Year Register
0-7 R/W Year (BCD 00h..99h = 2000..2099)
Alarm 1 and Alarm 2 Month Register
0-4 R/W Month (BCD 01h..12h = January..December)
5 - Not used (always zero)
6 R/W Year Compare Enable (0=Ignore, 1=Enable)
7 R/W Month Compare Enable (0=Ignore, 1=Enable)
Alarm 1 and Alarm 2 Day Register
0-5 R/W Day (BCD 01h..28h,29h,30h,31h, range depending on month/year)
6 - Not used (always zero)
7 R/W Day Compare Enable (0=Ignore, 1=Enable)
|
FOUT Register Setting 1
0-7 R/W Enable bits (bit0=256Hz, bit1=512Hz, ..., bit7=32768Hz)
FOUT Register Setting 2
0-7 R/W Enable bits (bit0=1Hz, bit1=2Hz, ..., bit7=128Hz)
The above sixteen FOUT signals are ANDed when two or more frequencies are
enabled, ie. the FOUT signal gets LOW when either of the signals is LOW.
|
1 /INT 8 VDD 2 XOUT 7 SIO 3 XIN 6 /SCK 4 GND 5 CS |
| DS Serial Peripheral Interface Bus (SPI) |
0-1 Baudrate (0=4MHz/Firmware, 1=2MHz/Touchscr, 2=1MHz/Powerman., 3=512KHz) 2 DSi: Baudrate MSB (4=8MHz, 5..7=None/0Hz) (when SCFG_EXT7.bit9=1) 2 NDS: Not used (Zero) 3-6 Not used (Zero) 7 Busy Flag (0=Ready, 1=Busy) (presumably Read-only) 8-9 Device Select (0=Powerman., 1=Firmware, 2=Touchscr, 3=Reserved) 10 Transfer Size (0=8bit/Normal, 1=16bit/Bugged) 11 Chipselect Hold (0=Deselect after transfer, 1=Keep selected) 12-13 Not used (Zero) 14 Interrupt Request (0=Disable, 1=Enable) 15 SPI Bus Enable (0=Disable, 1=Enable) |
0-7 Data 8-15 Not used (always zero, even in bugged-16bit mode) |
| DS Touch Screen Controller (TSC) |
0-1 Power Down Mode Select 2 Reference Select (0=Differential, 1=Single-Ended) 3 Conversion Mode (0=12bit, max CLK=2MHz, 1=8bit, max CLK=3MHz) 4-6 Channel Select (0-7, see below) 7 Start Bit (Must be set to access Control Byte) |
0 Temperature 0 (requires calibration, step 2.1mV per 1'C accuracy) 1 Touchscreen Y-Position (somewhat 0B0h..F20h, or FFFh=released) 2 Battery Voltage (not used, connected to GND in NDS, always 000h) 3 Touchscreen Z1-Position (diagonal position for pressure measurement) 4 Touchscreen Z2-Position (diagonal position for pressure measurement) 5 Touchscreen X-Position (somewhat 100h..ED0h, or 000h=released) 6 AUX Input (connected to Microphone in the NDS) 7 Temperature 1 (difference to Temp 0, without calibration, 2'C accuracy) |
Mode /PENIRQ VREF ADC Recommended use 0 Enabled Auto Auto Differential Mode (Touchscreen, Penirq) 1 Disabled Off On Single-Ended Mode (Temperature, Microphone) 2 Enabled On Off Don't use 3 Disabled On On Don't use |
scr.x = (adc.x-adc.x1) * (scr.x2-scr.x1) / (adc.x2-adc.x1) + (scr.x1-1) scr.y = (adc.y-adc.y1) * (scr.y2-scr.y1) / (adc.y2-adc.y1) + (scr.y1-1) |
Rtouch = (Rx_plate*Xpos*(Z2pos/Z1pos-1))/4096 Rtouch = (Rx_plate*Xpos*(4096/Z1pos-1)-Ry_plate*(1-Ypos))/4096 |
touchval = Xpos*(Z2pos/Z1pos-1) |
K = (CAL.TP0-ADC.TP0) * 0.4 + CAL.KELVIN |
K = (ADC.TP1-ADC.TP0) * 8568 / 4096 |
Celsius: C = (K-273.15) Fahrenheit: F = (K-273.15)*9/5+32 Reaumur: R = (K-273.15)*4/5 Rankine: X = (K)*9/5 |
________
VCC 1|o |16 DCLK
X+ 2| |15 /CS
Y+ 3| TSC |14 DIN
X- 4| 2046 |13 BUSY
Y- 5| |12 DOUT
GND 6| |11 /PENIRQ
VBAT 7| |10 IOVDD
AUX 8|________|9 VREF
|
| DS Power Control |
0 Enable Flag for both LCDs (0=Disable) (Prohibited, see notes) 1 2D Graphics Engine A (0=Disable) (Ports 008h-05Fh, Pal 5000000h) 2 3D Rendering Engine (0=Disable) (Ports 320h-3FFh) 3 3D Geometry Engine (0=Disable) (Ports 400h-6FFh) 4-8 Not used 9 2D Graphics Engine B (0=Disable) (Ports 1008h-105Fh, Pal 5000400h) 10-14 Not used 15 Display Swap (0=Send Display A to Lower Screen, 1=To Upper Screen) 16-31 Not used |
Bit Expl. 0 Sound Speakers (0=Disable, 1=Enable) (Initial setting = 1) 1 Wifi (0=Disable, 1=Enable) (Initial setting = 0) 2-31 Not used |
Bit Expl. 0-1 WS0 nonsequential time (0-3 = 10, 8, 6, 18 cycles) ;\4800000h-4807FFFh 2 WS0 sequential time (0-1 = 6, 4 cycles) ;/ (used for RAM) 3-4 WS1 nonsequential time (0-3 = 10, 8, 6, 18 cycles) ;\4808000h-480FFFFh 5 WS1 sequential time (0-1 = 10, 4 cycles) ;/ (used for I/O) 6-15 Not used (zero) |
Bit Expl. 0-5 Not used (zero) 6-7 Power Down Mode (0=No function, 1=Enter GBA Mode, 2=Halt, 3=Sleep) |
Bit Expl. 0 Post Boot Flag (0=Boot in progress, 1=Boot completed) 1 NDS7: Not used (always zero), NDS9: Bit1 is read-writeable 2-7 Not used (always zero) |
| DS Power Management Device |
Index Register
Bit0-6 Register Select (0..3) (0..4 for DS-Lite) (0..7Fh for DSi)
Bit7 Register Direction (0=Write, 1=Read)
Register 0 - Powermanagement Control (R/W)
Bit0 Sound Amplifier Enable (0=Disable, 1=Enable)
(Old-DS: Disabled: Sound is very silent, but still audible)
(DS-Lite: Disabled: Sound is NOT audible)
(DSi in NDS Mode: R/W, but effect is unknown yet)
(DSi in DSi Mode: Not used, Bit0 is always 1)
Bit1 Sound Amplifier Mute (0=Normal, 1=Mute) (Old-DS Only, not DS-Lite)
(Old-DS: Muted: Sound is NOT audible (that works only if Bit0=1)
(DS-Lite: Not used, Bit1 is always zero)
(DSi in NDS Mode: R/W, but effect is unknown yet)
(DSi in DSi Mode: R/W, but effect is unknown yet)
Bit2 Lower Backlight (0=Disable, 1=Enable)
Bit3 Upper Backlight (0=Disable, 1=Enable)
Bit4 Power LED Blink Enable (0=Always ON, 1=Blinking OFF/ON)
Bit5 Power LED Blink Speed (0=Slow, 1=Fast) (only if Blink enabled)
(DSi: Power LED Blinking isn't supported, neither in NDS nor DSi mode)
Bit6 DS System Power (0=Normal, 1=Shut Down)
Bit7 Not used (always 0)
Register 1 - Battery Status (R)
Bit0 Battery Power LED Status (0=Power Good/Green, 1=Power Low/Red)
(DSi: Usually 0, not tested if it changes upon Power=Low)
Bit1-7 Not used
Register 2 - Microphone Amplifier Control (R/W)
Bit0 Amplifier (0=Disable, 1=Enable)
Bit1-7 Not used (always 0)
(DSi in NDS Mode: looks same as NDS, ie. only bit0 is R/W)
(DSi in DSi Mode: Not used, always FFh)
Register 3 - Microphone Amplifier Gain Control (R/W)
Bit0-1 Gain (0..3=Gain 20, 40, 80, 160)
Bit2-7 Not used (always 0)
(DSi in NDS Mode: looks same as NDS, ie. only bit0-1 are R/W)
(DSi in DSi Mode: Not used, always FFh)
Register 4 - DS-Lite and DSi Only - Backlight Levels/Power Source (R/W)
Bit0-1 Backlight Brightness (0..3=Low,Med,High,Max) (R/W)
(when bit2+3 are both set, then reading bit0-1 always returns 3)
Bit2 Force Max Brightness when Bit3=1 (0=No, 1=Yes) (R/W)
Bit3 External Power Present (0=No, 1=Yes) (Read-Only)
Bit4-7 Unknown (Always 4) (Read-Only)
(DSi in NDS Mode: looks same as in DSi mode)
(DSi in DSi Mode: Bit0-1 are R/W, but ignored, bit2-3 are always 0)
Register 10h - DSi Only - Backlight Mirrors & Reset (R/W)
Bit0 Reset (0=No, 1=Reboot DSi) (same/similar as BPTWL reset feature?)
Bit1 Unknown (R/W) (note: whatever it is, it isn't warmboot flag)
Bit2-3 Mirror of Register 0, bit2-3 (backlight enable bits) (R/W)
Bit4-7 Not used (always 0)
Bit5 Not used (always 0) - but DSi bootrom sets that bit on boot error?
(This register works in NDS mode and DSi mode, though it's mainly intended
for NDS mode, eg. DS Download Play uses the Reset bit to return to DSi menu)
(note: writing bit2 seems to affect BOTH bit1 and bit2 in register 0)
Register 1Fh and 20h - DSi Only (?)
DSi bootrom sets register 1Fh and 20h bit0-4 to value 1Fh on boot error,
unknown purpose, seems to have no effect, maybe prototype backlight level?
|
| DS Main Memory Control |
LDRH R0,[27FFFFEh] ;read one value STRH R0,[27FFFFEh] ;write should be same value as above STRH R0,[27FFFFEh] ;write should be same value as above STRH R0,[27FFFFEh] ;write any value STRH R0,[27FFFFEh] ;write any value LDRH R0,[2400000h+CR*2] ;read, address-bits are defining new CR value |
Bit Expl.
0-6 Reserved (Must be 7Fh)
7 Write Control
0=WE Single Clock Pulse Control without Write Suspend Function
1=WE Level Control with Write Suspend Function)
Burst Read/Single Write is not supported at WE Single Clock Mode.
8 Reserved (Must be 1)
9 Valid Clock Edge (0=Falling Edge, 1=Rising Edge)
10 Single Write (0=Burst Read/Burst Write, 1=Burst Read/Single Write)
11 Burst Sequence (0=Reserved, 1=Sequential)
12-14 Read Latency (1=3 clocks, 2=4 clocks, 3=5 clocks, other=Reserved)
15 Mode
0=Synchronous: Burst Read, Burst Write
1=Asynchronous: Page Read, Normal Write
In Mode 1 (Async), only the Partial Size bits are used,
all other bits, CR bits 0..18, must be "1".
16-18 Burst Length (2=8 Words, 3=16Words, 7=Continous, other=Reserved)
19-20 Partial Size (0=1MB, 1=512KB, 2=Reserved, 3=Deep/0 bytes)
|
STRH 2000h,[4000204h] ;EXMEMCNT, enable RAM, async mode LDRH R0,[27FFFFEh] STRH R0,[27FFFFEh] STRH R0,[27FFFFEh] STRH FFDFh,[27FFFFEh] STRH E732h,[27FFFFEh] LDRH R0,[27E57FEh] STRH 6000h,[4000204h] ;EXMEMCNT, enable RAM, normal mode |
| DS Backwards-compatible GBA-Mode |
--- NDS9: --- ZEROFILL VRAM A,B ;init black screen border (or other color/image) POWCNT=8003h ;enable 2D engine A on upper screen (0003h=lower) EXMEMCNT=... ;set Async Main Memory mode (clear bit14) IME=0 ;disable interrupts SWI 06h ;halt with interrupts disabled (lockdown) --- NDS7: --- POWERMAN.REG0=09h ;enable sound amplifier & upper backlight (05h=lower) IME=0 ;disable interrupts wait for VCOUNT=200 ;wait until VBlank SWI 1Fh with R2=40h ;enter GBA mode, by CustomHalt(40h) |
| DS Debug Registers (Emulator/Devkits) |
4FFFA00h..A0Fh R Emulation ID (16 bytes, eg. "no$gba v2.7", padded with 20h) 4FFFA10h W String Out (raw) 4FFFA14h W String Out (with %param's) 4FFFA18h W String Out (with %param's, plus linefeed) 4FFFA1Ch W Char Out (nocash) 4FFFA20h..A27h R Clock Cycles (64bit) 4FFFA28h..A3Fh - N/A |
4000640h (32bit) ;aka CLIPMTX_RESULT (mis-used to invoke detection) 4000006h (16bit) ;aka VCOUNT (mis-used to get detection result) 4FFF010h (32bit) ;use to initialize/unlock/reset something 4FFF000h (8bit) ;debug message character output (used when Ensata detected) |
[4000640h]=2468ACE0h ;CLIPMTX_RESULT (on real hardware it's read-only)
if ([4000006h] AND 1FFh)=10Eh ;VCOUNT (on real hardware it's 000h..106h)
[4FFF010h]=13579BDFh ;\initialize/reset something
[4FFF010h]=FDB97531h ;/
Ensata=true
else
Ensata=false
endif
|
| DS Cartridges, Encryption, Firmware |
| DS Cartridge Header |
Address Bytes Expl.
000h 12 Game Title (Uppercase ASCII, padded with 00h)
00Ch 4 Gamecode (Uppercase ASCII, NTR-<code>) (0=homebrew)
010h 2 Makercode (Uppercase ASCII, eg. "01"=Nintendo) (0=homebrew)
012h 1 Unitcode (00h=NDS, 02h=NDS+DSi, 03h=DSi) (bit1=DSi)
013h 1 Encryption Seed Select (00..07h, usually 00h)
014h 1 Devicecapacity (Chipsize = 128KB SHL nn) (eg. 7 = 16MB)
015h 7 Reserved (zero filled)
01Ch 1 Reserved (zero) (except, used on DSi)
01Dh 1 NDS Region (00h=Normal, 80h=China, 40h=Korea) (other on DSi)
01Eh 1 ROM Version (usually 00h)
01Fh 1 Autostart (Bit2: Skip "Press Button" after Health and Safety)
(Also skips bootmenu, even in Manual mode & even Start pressed)
020h 4 ARM9 rom_offset (4000h and up, align 1000h)
024h 4 ARM9 entry_address (2000000h..23BFE00h)
028h 4 ARM9 ram_address (2000000h..23BFE00h)
02Ch 4 ARM9 size (max 3BFE00h) (3839.5KB)
030h 4 ARM7 rom_offset (8000h and up)
034h 4 ARM7 entry_address (2000000h..23BFE00h, or 37F8000h..3807E00h)
038h 4 ARM7 ram_address (2000000h..23BFE00h, or 37F8000h..3807E00h)
03Ch 4 ARM7 size (max 3BFE00h, or FE00h) (3839.5KB, 63.5KB)
040h 4 File Name Table (FNT) offset
044h 4 File Name Table (FNT) size
048h 4 File Allocation Table (FAT) offset
04Ch 4 File Allocation Table (FAT) size
050h 4 File ARM9 overlay_offset
054h 4 File ARM9 overlay_size
058h 4 File ARM7 overlay_offset
05Ch 4 File ARM7 overlay_size
060h 4 Port 40001A4h setting for normal commands (usually 00586000h)
064h 4 Port 40001A4h setting for KEY1 commands (usually 001808F8h)
068h 4 Icon/Title offset (0=None) (8000h and up)
06Ch 2 Secure Area Checksum, CRC-16 of [[020h]..00007FFFh]
06Eh 2 Secure Area Delay (in 131kHz units) (051Eh=10ms or 0D7Eh=26ms)
070h 4 ARM9 Auto Load List Hook RAM Address (?) ;\endaddr of auto-load
074h 4 ARM7 Auto Load List Hook RAM Address (?) ;/functions
078h 8 Secure Area Disable (by encrypted "NmMdOnly") (usually zero)
080h 4 Total Used ROM size (remaining/unused bytes usually FFh-padded)
084h 4 ROM Header Size (4000h)
088h 4 Unknown, some rom_offset, or zero? (DSi: slightly different)
08Ch 8 Reserved (zero filled; except, [88h..93h] used on DSi)
094h 2 NAND end of ROM area ;\in 20000h-byte units (DSi: 80000h-byte)
096h 2 NAND start of RW area ;/usually both same address (0=None)
098h 18h Reserved (zero filled)
0B0h 10h Reserved (zero filled; or "DoNotZeroFillMem"=unlaunch fastboot)
0C0h 9Ch Nintendo Logo (compressed bitmap, same as in GBA Headers)
15Ch 2 Nintendo Logo Checksum, CRC-16 of [0C0h-15Bh], fixed CF56h
15Eh 2 Header Checksum, CRC-16 of [000h-15Dh]
160h 4 Debug rom_offset (0=none) (8000h and up) ;only if debug
164h 4 Debug size (0=none) (max 3BFE00h) ;version with
168h 4 Debug ram_address (0=none) (2400000h..27BFE00h) ;SIO and 8MB
16Ch 4 Reserved (zero filled) (transferred, and stored, but not used)
170h 90h Reserved (zero filled) (transferred, but not stored in RAM)
200h E00h Reserved (zero filled) (usually not transferred)
|
Delay,Cmd |
Cmd,Delay,Cmd ;for 2x repeat Cmd,Delay,Cmd,Cmd,Cmd,Cmd,Cmd,Cmd,Cmd,Cmd ;for 9x repeat |
U Unique Code (usually "A", "B", "C", or special meaning) TT Short Title (eg. "PM" for Pac Man) D Destination/Language (usually "J" or "E" or "P" or specific language) |
A NDS common games B NDS common games C NDS common games D DSi-exclusive games H DSiWare (system utilities and browser) (eg. HNGP=browser) I NDS and DSi-enhanced games with built-in Infrared port K DSiWare (dsiware games and flipnote) (eg. KGUV=flipnote) N NDS nintendo channel demo's japan (NTR-NTRJ-JPN) T NDS many games U NDS and DSi uncommon extra hardware (eg. NAND, ram, microSD, TV, azimuth) V DSi-enhanced games Y NDS many games |
Usually an abbreviation of the game title (eg. "PM" for "Pac Man") (unless that gamecode was already used for another game, then TT is just random) |
A Asian E English/USA I Italian M Swedish Q Danish U Australian B N/A F French J Japanese N Nor R Russian V EUR+AUS C Chinese G N/A K Korean O Int S Spanish W..Z Europe #3..5 D German H Dutch L USA #2 P Europe T USA+AUS |
| DS Cartridge Secure Area |
Value Expl. "encryObj" raw ID before encryption (raw ROM-image) (encrypted) encrypted ID after encryption (encrypted ROM-image) "encryObj" raw ID after decryption (verified by BIOS boot code) E7FFDEFFh,E7FFDEFFh destroyed ID (overwritten by BIOS after verify) |
000h..007h Secure Area ID (see above) 008h..00Dh Fixed (FFh,DEh,FFh,E7h,FFh,DEh) 00Eh..00Fh CRC16 across following 7E0h bytes, ie. [010h..7FFh] 010h..7FDh Unknown/random values, mixed with some THUMB SWI calls 7FEh..7FFh Fixed (00h,00h) |
| DS Cartridge Icon/Title |
0000h 2 Version (0001h, 0002h, 0003h, or 0103h)
0002h 2 CRC16 across entries 0020h..083Fh (all versions)
0004h 2 CRC16 across entries 0020h..093Fh (Version 0002h and up)
0006h 2 CRC16 across entries 0020h..0A3Fh (Version 0003h and up)
0008h 2 CRC16 across entries 1240h..23BFh (Version 0103h and up)
000Ah 16h Reserved (zero-filled)
0020h 200h Icon Bitmap (32x32 pix) (4x4 tiles, 4bit depth) (4x8 bytes/tile)
0220h 20h Icon Palette (16 colors, 16bit, range 0000h-7FFFh)
(Color 0 is transparent, so the 1st palette entry is ignored)
0240h 100h Title 0 Japanese (128 characters, 16bit Unicode)
0340h 100h Title 1 English ("")
0440h 100h Title 2 French ("")
0540h 100h Title 3 German ("")
0640h 100h Title 4 Italian ("")
0740h 100h Title 5 Spanish ("")
0840h 100h Title 6 Chinese ("") (Version 0002h and up)
0940h 100h Title 7 Korean ("") (Version 0003h and up)
0A40h 800h Zerofilled (probably reserved for Title 8..15)
|
1240h 1000h Icon Animation Bitmap 0..7 (200h bytes each, format as above) 2240h 100h Icon Animation Palette 0..7 (20h bytes each, format as above) 2340h 80h Icon Animation Sequence (16bit tokens) |
0840h 1C0h Unused/padding (FFh-filled) in Version 0001h 0940h C0h Unused/padding (FFh-filled) in Version 0002h 23C0h 40h Unused/padding (FFh-filled) in Version 0103h |
0001h = Original 0002h = With Chinese Title 0003h = With Chinese+Korean Titles 0103h = With Chinese+Korean Titles and animated DSi icon |
15 Flip Vertically (0=No, 1=Yes) 14 Flip Horizontally (0=No, 1=Yes) 13-11 Palette Index (0..7) 10-8 Bitmap Index (0..7) 7-0 Frame Duration (01h..FFh) (in 60Hz units) |
0000h 2 Version (0103h) 0002h 6 Reserved (zero-filled) 0008h 2 CRC16 across entries 0020h..119Fh (with initial value FFFFh) 000Ah 16h Reserved (zero-filled) 0020h 1000h Icon Animation Bitmap 0..7 (200h bytes each) ;\same format as 1020h 100h Icon Animation Palette 0..7 (20h bytes each) ; in Icon/Title 1120h 80h Icon Animation Sequence (16bit tokens) ;/ 11A0h 2E60h Garbage (random values, maybe due to eMMC decryption) |
| DS Cartridge Protocol |
0000000h-0000FFFh Header (unencrypted) 0001000h-0003FFFh Not read-able (zero filled in ROM-images) 0004000h-0007FFFh Secure Area, 16KBytes (first 2Kbytes with extra encryption) 0008000h-... Main Data Area |
XX00000h XX02FFFh DSi Not read-able (XX00000h=first megabyte after NDS area) XX03000h-XX06FFFh DSi ARM9i Secure Area (usually with modcrypt encryption) XX07000h-... DSi Main Data Area |
Command/Params Expl. Cmd Reply Len -- Unencrypted Load -- 9F00000000000000h Dummy (read HIGH-Z bytes) RAW RAW 2000h 0000000000000000h Get Cartridge Header RAW RAW 200h DSi:1000h 00aaaaaaaa000000h Get Cartridge Header (1T-ROM,NAND)RAW RAW 200h 9000000000000000h 1st Get ROM Chip ID RAW RAW 4 A000000000000000h Get 3DS encryption type (3DS) RAW RAW 4 00aaaaaaaa000000h Unencrypted Data (debug ver only) RAW RAW 200h 3Ciiijjjxkkkkkxxh Activate KEY1 Encryption (NDS) RAW RAW 0 3Diiijjjxkkkkkxxh Activate KEY1 Encryption (DSi) RAW RAW 0 3E00000000000000h Activate 16-byte commands (3DS) RAW RAW 0 -- Secure Area Load -- 4llllmmmnnnkkkkkh Activate KEY2 Encryption Mode KEY1 FIX 910h+0 1lllliiijjjkkkkkh 2nd Get ROM Chip ID KEY1 KEY2 910h+4 xxxxxxxxxxxxxxxxh Invalid - Get KEY2 Stream XOR 00h KEY1 KEY2 910h+... 2bbbbiiijjjkkkkkh Get Secure Area Block (4Kbytes) KEY1 KEY2 910h+10A8h 6lllliiijjjkkkkkh Optional KEY2 Disable KEY1 KEY2 910h+? Alllliiijjjkkkkkh Enter Main Data Mode KEY1 KEY2 910h+0 -- Main Data Load -- B7aaaaaaaa000000h Encrypted Data Read KEY2 KEY2 200h B800000000000000h 3rd Get ROM Chip ID KEY2 KEY2 4 xxxxxxxxxxxxxxxxh Invalid - Get KEY2 Stream XOR 00h KEY2 KEY2 ... B500000000000000h Whatever NAND related? (DSi?) KEY2 KEY2 0 D600000000000000h Whatever NAND related? (DSi?) KEY2 KEY2 4 |
aaaaaaaa 32bit ROM address (command B7 can access only 8000h and up) bbbb Secure Area Block number (0004h..0007h for addr 4000h..7000h) x,xx Random, not used in further commands (DSi: always zero) iii,jjj,llll Random, must be SAME value in further commands kkkkk Random, must be INCREMENTED after FURTHER commands mmm,nnn Random, used as KEY2-encryption seed |
____________ Unencrypted Commands (First Part of Boot Procedure) _____________ |
NDS/MROM --> Read 200h bytes from address 000h NDS/1T-ROM --> Read 200h bytes from address 000h NDS/NAND --> Read 200h bytes from address 000h DSi/MROM --> Read 1000h bytes from address 000h DSi/1T-ROM --> Read 8x200h bytes from address 000h,200h,400h,..,E00h DSi/NAND --> Read 8x200h bytes from address 000h,200h,400h,..,E00h |
1st byte - Manufacturer (eg. C2h=Macronix) (roughly based on JEDEC IDs) 2nd byte - Chip size (00h..7Fh: (N+1)Mbytes, F0h..FFh: (100h-N)*256Mbytes?) 3rd byte - Flags (see below) 4th byte - Flags (see below) |
0 Uses Infrared (but via SPI, unrelated to ROM) (also Jam with the Band) 1 Unknown (set in some 3DS carts) 2-6 Zero 7 Unknown (set in Kingdom Hearts - Re-Coded) |
0-2 Zero 3 NAND flag (0=ROM, 1=NAND) 4 3DS Flag (0=NDS/DSi, 1=3DS) 5 Unknown (0=Normal, 1=Support cmd B5h/D6h) 6 DSi flag (0=NDS/3DS, 1=DSi) (but also set in NDS Walk with Me) 7 Cart Protocol Variant (0=old/smaller MROM, 1=new/bigger 1T-ROM or NAND) |
C2h,07h,00h,00h NDS Macronix 8MB ROM (eg. DS Vision, with microSD slot) AEh,0Fh,00h,00h NDS Noname 16MB ROM (eg. Meine Tierarztpraxis) C2h,0Fh,00h,00h NDS Macronix 16MB ROM (eg. Metroid Demo) C2h,1Fh,00h,00h NDS Macronix 32MB ROM (eg. Over the Hedge) C2h,1Fh,00h,40h DSi Macronix 32MB ROM (eg. Art Academy, TWL-VAAV, SystemFlaw) 80h,3Fh,01h,E0h NDS SanDisk 64MB ROM+Infrared (eg. Walk with Me, NTR-IMWP) AEh,3Fh,00h,E0h DSi Noname 64MB ROM (eg. de Blob 2, TWL-VD2V) C2h,3Fh,00h,00h NDS Macronix 64MB ROM (eg. Ultimate Spiderman) C2h,3Fh,00h,40h DSi Macronix 64MB ROM (eg. Crime Lab, NTR-VAOP) 80h,7Fh,00h,80h NDS SanDisk 128MB ROM (DS Zelda, NTR-AZEP-0) 80h,7Fh,01h,E0h ? SanDisk? 128MB ROM+Infrared (P-letter SoulSilver, IPGE) C2h,7Fh,00h,80h NDS Macronix 128MB ROM (eg. Spirit Tracks, NTR-BKIP) C2h,7Fh,00h,C0h DSi Macronix 128MB ROM (eg. Cooking Coach, TWL-VCKE) ECh,7Fh,00h,88h NDS Samsung 128MB NAND (eg. Warioware D.I.Y., NTR-UORE) ECh,7Fh,01h,88h NDS Samsung 128MB NAND (eg. Jam with the Band, NTR-UXBP) ECh,7Fh,00h,E8h DSi Samsung 128MB NAND (eg. Face Training, TWL-USKV) 80h,FFh,80h,E0h NDS SanDisk? 256MB ROM (Kingdom Hearts - Re-Coded, NTR-BK9P) C2h,FFh,01h,C0h DSi Macronix 256MB ROM+Infrared (eg. P-Letter White) C2h,FFh,00h,80h NDS Macronix 256MB ROM (eg. Band Hero, NTR-BGHP) C2h,FEh,01h,C0h DSi Macronix 512MB ROM+Infrared (eg. P-Letter White 2) C2h,FEh,00h,90h 3DS Macronix probably 512MB? ROM (eg. Sims 3) 45h,FAh,00h,90h 3DS SanDisk? maybe... 1GB? ROM (eg. Starfox) C2h,F8h,00h,90h 3DS Macronix maybe... 2GB? ROM (eg. Kid Icarus) C2h,7Fh,00h,90h 3DS Macronix 128MB ROM CTR-P-AENJ MMinna no Ennichi C2h,FFh,00h,90h 3DS Macronix 256MB ROM CTR-P-AFSJ Pro Yakyuu Famista 2011 C2h,FEh,00h,90h 3DS Macronix 512MB ROM CTR-P-AFAJ Real 3D Bass FishingFishOn C2h,FAh,00h,90h 3DS Macronix 1GB ROM CTR-P-ASUJ Hana to Ikimono Rittai Zukan C2h,FAh,02h,90h 3DS Macronix 1GB ROM CTR-P-AGGW Luigis Mansion 2 ASiA CHT C2h,F8h,00h,90h 3DS Macronix 2GB ROM CTR-P-ACFJ Castlevania - Lords of Shadow C2h,F8h,02h,90h 3DS Macronix 2GB ROM CTR-P-AH4J Monster Hunter 4 AEh,FAh,00h,90h 3DS Noname? 1GB ROM CTR-P-AGKJ Gyakuten Saiban 5 AEh,FAh,00h,98h 3DS Noname? 1GB NAND CTR-P-EGDJ Tobidase Doubutsu no Mori 45h,FAh,00h,90h 3DS SanDisk? 1GB ROM CTR-P-AFLJ Fantasy Life 45h,F8h,00h,90h 3DS SanDisk? 2GB ROM CTR-P-AVHJ Senran Kagura Burst - Guren C2h,F0h,00h,90h 3DS Macronix 4GB ROM CTR-P-ABRJ Biohazard Revelations ?,?,?,? NDS ? ? (eg. Japanese TV Tuner, NTR-UNSJ) 00h,00h,00h,00h Cart Reset Busy (Face Training needs 20ms delay after reset) FFh,FFh,FFh,FFh None (no cartridge inserted) |
1) Command 2bbbbiiijjjkkkkkh loads ARM9i secure area (instead of ARM9 area) 2) Command B7aaaaaaaa000000h allows to read the 'whole' cartridge space |
____________ KEY1 Encrypted Commands (2nd Part of Boot procedure) ____________ |
________________ KEY2 Encrypted Commands (Main Data Transfer) ________________ |
___________________________________ Notes ___________________________________ |
1) Chip ID.Bit31=0 Used by older/smaller carts with up to 64MB ROM 2) Chip ID.Bit31=1 Used by newer/bigger carts with 64MB or more ROM |
| DS Cartridge Backup |
Type Total Size Page Size Chip/Example Game/Example EEPROM 0.5K bytes 16 bytes ST M95040-W (eg. Metroid Demo) EEPROM 8K bytes 32 bytes ST M95640-W (eg. Super Mario DS) EEPROM 64K bytes 128 bytes ST M95512-W (eg. Downhill Jam) EEPROM 128K bytes ? bytes ? (eg. Explorers of Sky) FLASH 256K bytes 256 bytes ST M45PE20 (eg. Skateland) FLASH 256K bytes Sanyo LE25FW203T (eg. Mariokart) FLASH 512K bytes 256 bytes ST M25PE40? (eg. which/any games?) FLASH 512K bytes ST 45PE40V6 (eg. DS Zelda, NTR-AZEP-0) FLASH 1024K bytes ST 45PE80V6 (eg. Spirit Tracks, NTR-BKIP) FLASH 8192K bytes MX25L6445EZNI-10G (Art Academy only, TWL-VAAV) FRAM 8K bytes No limit ? (eg. which/any games?) FRAM 32K bytes No limit Ramtron FM25L256? (eg. which/any games?) |
Type Max Writes per Page Data Retention EEPROM 100,000 40 years FLASH 100,000 20 years FRAM No limit 10 years |
06h WREN Write Enable Cmd, no parameters 04h WRDI Write Disable Cmd, no parameters 05h RDSR Read Status Register Cmd, read repeated status value(s) 01h WRSR Write Status Register Cmd, write one-byte value 9Fh RDID Read JEDEC ID (not supported on EEPROM/FLASH, returns FFh-bytes) |
03h RDLO Read from Memory 000h-0FFh Cmd, addr lsb, read byte(s) 0Bh RDHI Read from Memory 100h-1FFh Cmd, addr lsb, read byte(s) 02h WRLO Write to Memory 000h-0FFh Cmd, addr lsb, write 1..MAX byte(s) 0Ah WRHI Write to Memory 100h-1FFh Cmd, addr lsb, write 1..MAX byte(s) |
03h RD Read from Memory Cmd, addr msb,lsb, read byte(s) 02h WR Write to Memory Cmd, addr msb,lsb, write 1..MAX byte(s) |
As above, but with 24bit addr msb,mid,lsb ? |
0 WIP Write in Progress (1=Busy) (Read only) (always 0 for FRAM chips) 1 WEL Write Enable Latch (1=Enable) (Read only, except by WREN,WRDI) 2-3 WP Write Protect (0=None, 1=Upper quarter, 2=Upper Half, 3=All memory) |
4-7 ONEs Not used (all four bits are always set to "1" each) |
4-6 ZERO Not used (all three bits are always set to "0" each) 7 SRWD Status Register Write Disable (0=Normal, 1=Lock) (Only if /W=LOW) |
RDSR RDID Type (bus-width) FFh, FFh,FFh,FFh None (none) F0h, FFh,FFh,FFh EEPROM (with 8+1bit address bus) 00h, FFh,FFh,FFh EEPROM/FRAM (with 16bit address bus) ? ?,?,? EEPROM (with 24bit address bus) 00h, xxh,xxh,xxh FLASH (usually with 24bit address bus) |
Pin Name Expl. 1 /S Chip Select 2 Q Data Out 3 /W Write-Protect (not used in NDS, wired to VCC) 4 VSS Ground 5 D Data In 6 C Clock 7 /HOLD Transfer-pause (not used in NDS, wired to VCC) 8 VCC Supply 2.5 to 5.5V for M95xx0-W |
DS Vision (NDS cart with microSD slot... and maybe ALSO with EEPROM?) NAND carts can store data in a read/write-able portion of the "ROM" chip Typing Adventure does have SPI FLASH (but not directly wired to SPI bus) |
| DS Cartridge NAND |
ECh,7Fh,00h,88h NDS Samsung 128MB NAND (eg. Warioware D.I.Y., NTR-UORE) ECh,7Fh,01h,88h NDS Samsung 128MB NAND (eg. Jam with the Band, NTR-UXBP) ECh,7Fh,00h,E8h DSi Samsung 128MB NAND (eg. Face Training, TWL-USKV) |
00000000h ROM region (one large region) (R) 0xxx0000h RW region (split into several 128KByte blocks) (R/W) 07A00000h Reserved region (R) |
In ROM access mode: 9400000000000000h Len=200h NAND Read ID B2aaaaaaaa000000h Len=0 NAND Select 128Kbyte RW access mode B300000000000000h Len=04h Unknown (returns 00000000h) BB00000000000000h Len=200h Unknown (returns 1X 04 09 20 04, plus zeroes) In RW access mode (on DSi carts, this works ONLY in DSi mode): 81aaaaaaaa000000h Len=200h NAND Write to Write Buffer (must be issued 4x) 8200000000000000h Len=0 NAND Forward Write Buffer to NAND 8400000000000000h Len=0 NAND Discard Write Buffer 8500000000000000h Len=0 NAND Write Enable 8600000000000000h Len=0 Unknown 8700000000000000h Len=0 NAND Write Disable 8B00000000000000h Len=0 NAND Select ROM access mode In either mode: 0B00000000000000h Len=200h Returns cart header[000h..1FFh] 0C00000000000000h Len=200h Returns corrupted cart header[1F8h..3F7h] ?? 58h..5Fh Len=0 Unknown (looks same/similar as in 1T-ROM carts) 60h..68h Len=800h Unknown (looks same/similar as in 1T-ROM carts) B000000000000000h Len=04h Unknown (returns 01010101h) B500000000000000h Len=0 Unknown (looks same/similar as in SanDisk carts) B7aaaaaaaa000000h Len=200h NAND Read from ROM or RW area B800000000000000h Len=04h Read Chip ID D600000000000000h Len=04h NAND Read Status Further command(s) spotted in Face Training disassembly: 8800000000000000h Len=0 Unknown (is in disassembly, but fails on HW?) |
0-1 Unknown (usually zero) 2-3 Unknown (usually zero, but tested by DSi Launcher, not NAND related?) 4 NAND write enable 5 NAND status (0=busy, 1=ready) 6 Unknown (usually zero, but set by DeSmuME) 7 Unknown (possible error flag?) 8-15 Same as bit0-7 16-23 Same as bit0-7 24-31 Same as bit0-7 |
Values in Jam with the Band (nocash dump): 17 04 09 20 04, plus 1FBh zeroes Values in Face Training (nocash dump): 10 04 09 20 04, plus 1FBh zeroes |
Values in Jam with the Band (arisotura dump): 000h EC F1 00 95 40 00 00 00 00 00 00 00 00 00 00 00 ....@........... 010h 00 00 00 00 00 00 00 00 EC 00 9E A1 51 65 34 35 ............Qe45 020h 30 35 30 31 19 19 02 0A 00 00 00 00 00 00 00 00 0501............ 030h FF FF FF .. (1D0h bytes) (why not 00h's ???) ................ Values in Jam with the Band (nocash dump): 000h EC F1 00 95 40 00 00 00 00 00 00 00 00 00 00 00 ....@........... 010h 00 00 00 00 00 00 00 00 EC 00 3B 5A 32 9B 32 30 ..........;Z2.20 020h 35 35 30 30 19 19 02 0A 00 00 00 00 00 00 00 00 5500............ 030h 00 00 00 .. (1D0h bytes) ................ Values in Face Training (nocash dump): 000h EC F1 00 95 40 00 00 00 00 00 00 00 00 00 00 00 ....@........... 010h 00 00 00 00 00 00 00 00 EC 00 5A 36 5C 14 35 35 ..........Z6\.55 020h 32 36 30 36 04 04 08 0A 00 00 00 00 00 00 00 00 2606............ 030h 00 00 00 .. (1D0h bytes) ................ |
Values in Jam with the Band (arisotura dump): 079E0000h FF FF FF .. (1F800h bytes) ................ 079FF800h EC 00 9E A1 51 65 34 35 30 35 30 31 19 19 02 0A ....Qe450501.... 079FF810h 00 00 00 00 6D D6 DA 9B B0 24 22 88 79 3B BF EA ....m....$".y;.. 079FF820h E6 AC 5E FA 69 12 0D 52 5D 5B F5 80 FF FF FF FF ..^.i..R][...... 079FF830h FF FF FF .. (7D0h bytes) ................ Values in Jam with the Band (nocash dump): 079E0000h FF FF FF .. (1F800h bytes) ................ 079FF800h EC 00 3B 5A 32 9B 32 30 35 35 30 30 19 19 02 0A ..;Z2.205500.... 079FF810h 00 00 00 00 DD 58 84 07 F9 72 19 04 96 8C FF 67 .....X...r.....g 079FF820h 7F 66 B9 E5 FD F7 3F 1A AE 60 60 00 FF FF FF FF .f....?..``..... 079FF830h FF FF FF .. (7D0h bytes) ................ |
B2aaaaaaaa000000h - Select 128Kbyte RW access mode (unlesss already) 8500000000000000h - NAND Write Enable 81aaaaaaaa000000h - NAND Write to Write Buffer + Data[200h] 81aaaaaaaa000000h - NAND Write to Write Buffer + Data[200h] 81aaaaaaaa000000h - NAND Write to Write Buffer + Data[200h] 81aaaaaaaa000000h - NAND Write to Write Buffer + Data[200h] 8200000000000000h - NAND Forward Write Buffer to NAND D600000000000000h - NAND Read Status + Data[4] (...repeat reading status until bit5=1=ready...) 8400000000000000h - NAND Discard SRAM write 8B00000000000000h - NAND Select ROM access mode (if desired) |
PCB "DI X-7 C17-01" Chip "SAMSUNG 004, KLC2811ANB-P204, NTR-UORE-0" |
PCB (Unknown) Chip "SAMSUNG 013, KLC2811UOC-P30A, NTR-UXBP-0, WKA069J2" |
PCB "DI X-8 C17-01" U1 "SAMSUNG 031, KLC2811UOC-P309, TWL-USKV-0, WKE114(80?)" (this chip must be slightly different, for DSi mode support) |
| DS Cartridge I/O Ports |
0-1 SPI Baudrate (0=4MHz/Default, 1=2MHz, 2=1MHz, 3=512KHz) 2-5 Not used (always zero) 6 SPI Hold Chipselect (0=Deselect after transfer, 1=Keep selected) 7 SPI Busy (0=Ready, 1=Busy) (presumably Read-only) 8-12 Not used (always zero) 13 NDS Slot Mode (0=Parallel/ROM, 1=Serial/SPI-Backup) 14 Transfer Ready IRQ (0=Disable, 1=Enable) (for ROM, not for AUXSPI) 15 NDS Slot Enable (0=Disable, 1=Enable) (for both ROM and AUXSPI) |
0-7 Data 8-15 Not used (always zero) |
0-12 KEY1 gap1 length (0-1FFFh) (forced min 08F8h by BIOS) (leading gap) 13 KEY2 encrypt data (0=Disable, 1=Enable KEY2 Encryption for Data) 14 "SE" Unknown? (usually same as Bit13) (does NOT affect timing?) 15 KEY2 Apply Seed (0=No change, 1=Apply Encryption Seed) (Write only) 16-21 KEY1 gap2 length (0-3Fh) (forced min 18h by BIOS) (200h-byte gap) 22 KEY2 encrypt cmd (0=Disable, 1=Enable KEY2 Encryption for Commands) 23 Data-Word Status (0=Busy, 1=Ready/DRQ) (Read-only) 24-26 Data Block size (0=None, 1..6=100h SHL (1..6) bytes, 7=4 bytes) 27 Transfer CLK rate (0=6.7MHz=33.51MHz/5, 1=4.2MHz=33.51MHz/8) 28 KEY1 Gap CLKs (0=Hold CLK High during gaps, 1=Output Dummy CLK Pulses) 29 RESB Release Reset (0=Reset, 1=Release) (cannot be cleared once set) 30 Data Direction "WR" (0=Normal/read, 1=Write, for FLASH/NAND carts) 31 Block Start/Status (0=Ready, 1=Start/Busy) (IRQ See 40001A0h/Bit14) |
hdr[60h] hdr[64h] hdr[6Eh] 00586000h 001808F8h 051Eh ;older/faster MROM 00416657h 081808F8h 0D7Eh ;newer/slower 1T-ROM 00416657h 081808F8h 0D7Eh ;newer/slower NAND |
0-7 1st Command Byte (at 40001A8h) (eg. B7h) (MSB) 8-15 2nd Command Byte (at 40001A9h) (eg. addr bit 24-31) 16-23 3rd Command Byte (at 40001AAh) (eg. addr bit 16-23) 24-31 4th Command Byte (at 40001ABh) (eg. addr bit 8-15) (when aligned=even) 32-39 5th Command Byte (at 40001ACh) (eg. addr bit 0-7) (when aligned=00h) 40-47 6th Command Byte (at 40001ADh) (eg. 00h) 48-57 7th Command Byte (at 40001AEh) (eg. 00h) 56-63 8th Command Byte (at 40001AFh) (eg. 00h) (LSB) |
0-7 1st received Data Byte (at 4100010h) 8-15 2nd received Data Byte (at 4100011h) 16-23 3rd received Data Byte (at 4100012h) 24-31 4th received Data Byte (at 4100013h) |
For more info: |
| DS Cartridge NitroROM and NitroARC File Systems |
FNT = cart_hdr[040h] ;\origin as defined in ROM cartridge header FAT = cart_hdr[048h] ;/ IMG = 00000000h ;-origin at begin of ROM |
... ... Optional Header (eg. compression header, or RSA signature) 000h 4 Chunk Name "NARC" (Nitro Archive) ;\ 004h 2 Byte Order (FFFEh) (unlike usually, not FEFFh) ; 006h 2 Version (0100h) ; NARC 008h 4 File Size (from "NARC" ID to end of file) ; Header 00Ch 2 Chunk Size (0010h) ; 00Eh 2 Number of following chunks (0003h) ;/ 010h 4 Chunk Name "BTAF" (File Allocation Table Block) ;\ 014h 4 Chunk Size (including above chunk name) ; File 018h 2 Number of Files ; Allocation 01Ah 2 Reserved (0000h) ; Table 01Ch ... FAT (see below) ;/ ... 4 Chunk Name "BTNF" (File Name Table Block) ;\ ... 4 Chunk Size (including above chunk name) ; File Name ... ... FNT (see below) ; Table ... .. Padding for 4-byte alignment (FFh-filled, if any) ;/ ... 4 Chunk Name "GMIF" (File Image Block) ;\ ... 4 Chunk Size (including above chunk name) ; File Data ... ... IMG (File Data) ;/ |
000h 4 FNT Filename Table Offset (always at 10h) 004h 4 FNT Filename Table Size 008h 4 FAT Allocaton Table Offset (at above Offset+Size+Padding) 00Ch 4 FAT Allocaton Table Size 010h .. FNT Filename Table Data ... .. FAT Allocaton Table Data ... .. IMG File Data |
Addr Size Expl. 00h 4 Start address (originated at IMG base) (0=Unused Entry) 04h 4 End address (Start+Len) (0=Unused Entry) |
Addr Size Expl. 00h 4 Offset to Sub-table (originated at FNT base) 04h 2 ID of first file in Sub-table (0000h..EFFFh) |
06h 2 Total Number of directories (1..4096) |
06h 2 ID of parent directory (F000h..FFFEh) |
Addr Size Expl.
00h 1 Type/Length
01h..7Fh File Entry (Length=1..127, without ID field)
81h..FFh Sub-Directory Entry (Length=1..127, plus ID field)
00h End of Sub-Table
80h Reserved
01h LEN File or Sub-Directory Name, case-sensitive, without any ending
zero, ASCII 20h..7Eh, except for characters \/?"<>*:;|
|
LEN+1 2 Sub-Directory ID (F001h..FFFFh) ;see FNT+(ID AND FFFh)*8 |
Addr Size Expl. 00h 4 Overlay ID 04h 4 RAM Address ;Point at which to load 08h 4 RAM Size ;Amount to load 0Ch 4 BSS Size ;Size of BSS data region 10h 4 Static initialiser start address 14h 4 Static initialiser end address 18h 4 File ID (0000h..EFFFh) 1Ch 4 Reserved (zero) |
| DS Cartridge Unknown Commands |
Title Chip ID Commands... Metroid First Hunt 00000FC2 B7 B8 D8 Meine Tierarztpraxis 00000FAE B7 B8 D8 Meine Tierpension 00000FC2 B7 B8 D8 Nanostray 00000FC2 B7 B8 D8 Over the Hedge 00001FC2 B7 B8 D8 Tony Hawk's Skateland 00003FC2 B7 B8 Tony Hawk's Downhill Jam 00003FC2 B7 B8 Ultimate Spiderman 00003FC2 B7 B8 System Flaw (DSi) 40001FC2 B7 B8 F1 Biggest Loser (DSi) 40001FC2 B7 B8 F1 Cooking Coach (DSi) C0007FC2 58..5F 60..68 B7 B8 Walk with Me E0013F80 69..6C B5 B7 B8 D6 Face Training (DSI NAND) E8007FEC 0x 5x 6x 8x 94 Bx D6 (see NAND chapter) |
______________________________ Command 58h..68h ______________________________ |
______________________________ Command 69h..6Ch ______________________________ |
______________________________ Command B5h/D6h _______________________________ |
if chip_id AND 20000000h
get_nand_status(cmd_D6h)
if (nand_status AND 0Ch)<>0 ;whatever bits
whatever(cmd_B5h) ;whatever command
loop:
get_nand_status(cmd_D6h)
if (nand_status AND 20h)=0 then goto loop ;wait for ready flag
|
________________________________ Command D8h _________________________________ |
________________________________ Command F1h _________________________________ |
0000..0DFF FF-filled 0E00 1E 40 05 5A FF FF 0D 01 32 68 38 7A 23 3F FF FF 0E10 03 0B 00 00 03 09 FF FF FF FF FF FF FF FF FF FF 0E20 1E 40 05 03 0B 00 00 03 09 00 00 FF FF FF FF FF 0E30 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E40 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E50 FF FF FF FF FF 5A FF 5E FF FF FF FF FF FF 5A FF 0E60 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E70 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E80..0FFF FF-filled 1000..3FFF mirrors of 0000-0FFF |
0000..0DFF FF-filled 0E00 11 16 08 5A FF FF 0D 0B 39 7C 40 8E 2A 53 FF FF 0E10 03 0A 07 05 05 04 00 00 07 00 7F FF 00 FF FF FF 0E20 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E30 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E40 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E50 FF FF FF FF FF 5A FF 5E FF FF FF FF FF FF 5A FF 0E60 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E70 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0E80..0FFF FF-filled 1000..3FFF mirrors of 0000-0FFF |
| DS Cartridge PassMe/PassThrough |
Addr Siz Patch 004h 4 E59FF018h ;opcode LDR PC,[027FFE24h] at 27FFE04h 01Fh 1 04h ;set autostart bit 022h 1 01h ;set ARM9 rom offset to nn01nnnnh (above secure area) 024h 4 027FFE04h ;patch ARM9 entry address to endless loop 034h 4 080000C0h ;patch ARM7 entry address in GBA slot 15Eh 2 nnnnh ;adjust header crc16 |
0A0h GBA-style Title ("DSBooter")
0ACh GBA-style Gamecode ("PASS")
0C0h ARM7 Entrypoint (32bit ARM code)
|
| DS Cartridge GBA Slot |
NDS: Normal 32pin slot DS Lite: Short 32pin slot (GBA cards stick out) DSi: N/A (dropped support for GBA carts, and for DS-expansions) |
| DS Cart Rumble Pak |
VCC, GND, /WR, AD1, and IRQ (grounded) |
for i=0 to 0FFFh
if halfword[8000000h+i*2]<>(i and FFFDh) then <not_a_ds_rumble_pak>
next i
|
rumble_state = rumble_state xor 0002h halfword[8000000h]=rumble_state |
| DS Cart Slider with Rumble |
00h Product_ID (R) (03h) 01h Revision_ID (R) (10h=Rev. 1.0) (20h=Used in DS-option-pak) 02h Motion/Status Flags (R) 03h Delta_X (R) (signed 8bit) (automatically reset to 00h after reading) 04h Delta_Y (R) (signed 8bit) (automatically reset to 00h after reading) 05h SQUAL (R) (surface quality) (unsigned 8bit) 06h Average_Pixel (R) (unsigned 6bit, upper 2bit unused) 07h Maximum_Pixel (R) (unsigned 6bit, upper 2bit unused) 08h Reserved 09h Reserved 0Ah Configuration_bits (R/W) 0Bh Reserved 0Ch Data_Out_Lower (R) 0Dh Data_Out_Upper (R) 0Eh Shutter_Lower (R) 0Fh Shutter_Upper (R) 10h Frame_Period_Lower (R/W) 11h Frame_Period_Upper (R/W) |
7 Motion since last report or PD (0=None, 1=Motion occurred) 6 Reserved 5 LED Fault detected (0=No fault, 1=Fault detected) 4 Delta Y Overflow (0=No overflow, 1=Overflow occured) 3 Delta X Overflow (0=No overflow, 1=Overflow occured) 2 Reserved 1 Reserved 0 Resolution in counts per inch (0=400, 1=800) |
7 Reset Power up defaults (W) (0=No, 1=Reset)
6 LED Shutter Mode (0=LED always on, 1=LED only on when shutter is open)
5 Self Test (W) (0=No, 1=Perform all self tests)
4 Resolution in counts per inch (0=400, 1=800)
3 Dump 16x16 Pixel bitmap (0=No, 1=Dump via Data_Out ports)
2 Reserved
1 Reserved
0 Sleep Mode (0=Normal/Sleep after 1 second, 1=Always awake)
_______
|74273 |
/WR -----------------> |CLK | _____
AD1/SIO CLK ---------> |D1 Q1|--------------> CLK |74125|
AD2 power control ---> |D2 Q2|---> ____ | |
AD3/SIO DIR ---------> |D3 Q3|------o-|7400\________|/EN |
AD8 rumble on/off ---> |D? Q?|---> '-|____/ | |
AD0/SIO DTA ----o----> |D5 Q5|----------------------|A Y|--o--DTA
| |_______| |- - -| |
____ '-------------------------------------|Y A|--'
/RD ---|7400\______ ____ | |
/RD ---|____/ |7400\_____________________________|/EN |
A19 _______________|____/ |_____|
|
| DS Cart Expansion RAM |
Opera (8MB RAM) (official RAM expansion for Opera browser) EZ3/4/3-in-1 (8-16MB RAM, plus FLASH, plus rumble) Supercard (32MB) M3 (32MB) G6 (32MB) |
base=9000000h, size=800000h (8MB) unlock=1, lock=0 STRH [8240000h],lock/unlock |
base=8400000h, size=VAR (8MB..16MB) locking/unlocking/detection see below |
base=8000000h, size=1FFFFFEh (32MB minus last two bytes?) unlock=5 (RAM_RW), lock=3 (MEDIA) STRH [9FFFFFEh],A55Ah STRH [9FFFFFEh],A55Ah STRH [9FFFFFEh],lock/unlock STRH [9FFFFFEh],lock/unlock |
base=8000000h, size=2000000h (32MB) unlock=00400006h, lock=00400003h LDRH Rd,[8E00002h] LDRH Rd,[800000Eh] LDRH Rd,[8801FFCh] LDRH Rd,[800104Ah] LDRH Rd,[8800612h] LDRH Rd,[8000000h] LDRH Rd,[8801B66h] LDRH Rd,[8000000h+(lock/unlock)*2] LDRH Rd,[800080Eh] LDRH Rd,[8000000h] LDRH Rd,[80001E4h] LDRH Rd,[80001E4h] LDRH Rd,[8000188h] LDRH Rd,[8000188h] |
base=8000000h, size=2000000h (32MB) unlock=6, lock=3 LDRH Rd,[9000000h] LDRH Rd,[9FFFFE0h] LDRH Rd,[9FFFFECh] LDRH Rd,[9FFFFECh] LDRH Rd,[9FFFFECh] LDRH Rd,[9FFFFFCh] LDRH Rd,[9FFFFFCh] LDRH Rd,[9FFFFFCh] LDRH Rd,[9FFFF4Ah] LDRH Rd,[9FFFF4Ah] LDRH Rd,[9FFFF4Ah] LDRH Rd,[9200000h+(lock/unlock)*2] LDRH Rd,[9FFFFF0h] LDRH Rd,[9FFFFE8h] |
ez_ram_test: ;Based on DSLinux Amadeus' detection
ez_subfunc(9880000h,8000h) ;-SetRompage (OS mode)
ez_subfunc(9C40000h,1500h) ;-OpenNorWrite
[08400000h]=1234h ;\
if [08400000h]=1234h ; test writability at 8400000h
[8000000h]=4321h ; and non-writability at 8000000h
if [8000000h]<>4321h ;
return true ;/
ez_subfunc(9C40000h,D200h) ;CloseNorWrite
ez_subfunc(9880000h,0160h) ;SetRompage (0160h)
ez_subfunc(9C40000h,1500h) ;OpenNorWrite
[8400000h]=1234h ;\
if [8400000h]=1234h ; test writability at 8400000h
return true ;/
return false ;-failed
ez_subfunc(addr,data):
STRH [9FE0000h],D200h
STRH [8000000h],1500h
STRH [8020000h],D200h
STRH [8040000h],1500h
STRH [addr],data
STRH [9FC0000h],1500h
|
| DS Cart Infrared/Pedometers |
H8/300H Series Programming Manual (Hitachi, 257 pages) ;-Opcodes H8/38602R Group Hardware Manual (Renesas, 554 pages) ;-SFR's The addition of H8/38606 Group (Renesas, 6 pages) ;-FLASH/ROM/RAM |
BMA150 Triaxial digital acceleration sensor Data sheet (Bosch, 56 pages) SSD1850 Advance Information (Solomon System, 56 pages) ;-LCD driver http://dmitry.gr/?r=05.Projects&proj=28.%20pokewalker ;-Disassembly/Story http://forums.nesdev.org/viewtopic.php?f=23&t=21140#p265388 ;-Forum |
| DS Cart Infrared Cartridge SPI Commands |
OLD was used in Walk with Me (maybe also Active Health?) NEW was used in the P-Letter game series |
04h,04h Initial dummy in walk with me (bugged read or wrdi?) 00h,cmd,params[...] Savedata access 01h,00h,00h Infrared RX (none, len=0, plus dummy data=0) 01h,len,data[len] Infrared RX (OLD: max 84h bytes, NEW: max B8h bytes) 02h,data[...] Infrared TX (OLD: max 84h bytes, NEW: max B8h bytes) 02h,F2h,data[...] OLD: ignored (refuses to TX data starting with F2h) 03h,msb,lsb,data Memory Write 8bit ;\MOV.B 04h,msb,lsb,data Memory Read 8bit ;/ 05h,msb,lsb,data,data Memory Write 16bit ;\MOV.W (fails on 8bit SFRs?) 06h,msb,lsb,data,data Memory Read 16bit ;/ 07h,00h,num,num,num,... Blah, returns num params from previous spi command 08h..FFh OLD: Ignored (keeps awaiting a SPI command byte) 08h,ver NEW: Returns version (ver=AAh) 09h..FFh OLD: Ignored (returns zeropadding) |
| DS Cart Infrared Cartridge Memory Map |
[0FFD6h].0 Port 3 Data bit0 OUT IrDA PWDOWN (1=disable IrDA RX) [0FFD6h].1 Port 3 Data bit1 IN IrDA RXD ;\via serial IrDA registers [0FFD6h].2 Port 3 Data bit2 OUT IrDA TXD ;/ [0FFDBh].3 Port 8 Data bit3 OUT Savedata chipselect (0=select) (cmd 00h) [0FFDBh].2 Port 8 Data bit2 OUT LED color ;\used in UNUSED functions, [0FFDBh].3 Port 8 Data bit3 OUT LED color ; in OLD ROM only, and [0FFDEh].0 Port B Data bit0 IN Button input ;/conflicting with Savedata IrDA IR Transfers SPI NDS Console (and cmd 00h forwarding to Savedata) |
FB80h 200h undocumented and unused RAM, is R/W in my 38600R (!) FD80h 2 unused ;-unused FD82h 2 ir_callback ;\main callbacks for ir/spi polling FD84h 2 spi_callback ;/ FD86h 2 ir_timestamp ;-last ir access (for timeout)? FD88h 2 spi_timestamp ;-last spi access (for debug or so)? FD8Ah 1 initial_blah ;-initial state of Port 8.bit3 (not really used) FD8Bh 1 ir_rxbuf_wrptr ;-ir_rxbuf_wrptr (for incoming IR data)? FD8Ch 1 ir_rxbuf_rdptr ;-ir_rxbuf_rdptr (for forwarding to spi)? FD8Dh 84h spi_rx_buf ;-spi_rx_buf ;(also ir TX buf) FE11h 84h infrared_rx_buf ;-infrared_rx_buf FE95h 1 spi_index ;-spi_index FE96h 1 ir_tx_index ;-ir_tx_index (from spi buf to TX infrared) FE97h 1 ir_timeout_flag ;-ir_timeout_flag (or packet end or so?) FE98h 2 button_num_changes ;\ FE9Ah 2 button_num_pushes ; used only in FE9Ch 1 button_new_state ; UNUSED functions FE9Dh 1 button_old_state ; FE9Eh 1 button_newly_pushed ; FE9Fh 1 button_offhold ;/ FEA0h E0h stack_area (stacktop at FF80h) |
FB80h 200h undocumented and unused RAM, is R/W in my 38600R (!) FD80h 2 unused ;-unused FD82h 2 ir_callback ;\main callbacks for ir/spi polling FD84h 2 spi_callback ;/ FD86h 2 ir_timestamp ;-last ir access (for timeout)? FD88h 1 ir_rxbuf_wrptr ;-ir_rxbuf_wrptr (for incoming IR data)? FD89h 1 ir_rxbuf_rdptr ;-blah, always set to 0, never used FD8Ah 1 spi_index ;-spi_index FD8Bh 1 ir_tx_index ;-ir_tx_index (from spi buf to TX infrared) FD8Ch B8h spi_rx_buf ;-spi_rx_buf ;(also ir TX buf) FE44h B8h+1 infrared_rx_buf ;-infrared_rx_buf (plus space for appending 00h) FEFDh 1 ir_timeout_flag ;-ir_timeout_flag (or packet end or so?) FEFEh 82h stack_area (stacktop at FF80h) |
| DS Cart Infrared Activity Meter IR Commands |
sum=0, packet[2,3]=00h,00h ;-initial chksum
for i=0 to size-1
if (i and 1)=0 then sum=sum+packet[i]*100h ;\add in big-endian fashion
if (i and 1)=1 then sum=sum+packet[i] ;/
sum=(sum/10000h)+(sum AND FFFFh) ;\final adjust
sum=(sum/10000h)+(sum) ;/
packet[2,3]=sum,sum/100h ;-store in little-endian
|
08,xx,cc,cc,msb,lsb,data[..] CPU Memory Write (len=3Eh max) ;Reply=08 0A,xx,cc,cc,msb,lsb,len CPU Memory Read (len=40h max) ;Reply=0A 0A,xx,cc,cc,FB,9C,len CPU Memory Read FB9Ch with ClrFlag ;Reply=0A 20,xx,cc,cc,msb,lsb,data[..] Serial EEPROM Write (len=3Eh max) ;Reply=20 22,xx,cc,cc,msb,lsb,len Serial EEPROM Read (len=40h max) ;Reply=22 24,00,cc,cc,ss,ss,ss,ss Update Ringbuf_mm ;\ ;Reply=24 24,01,cc,cc,ss,ss,ss,ss Update Ringbuf_hh ; and set ;Reply=24 24,02,cc,cc,ss,ss,ss,ss Update Ringbuf_dd ; 32bit ;Reply=24 24,03,cc,cc,ss,mm,hh Set RTC hh:mm:ss ; seconds ;Reply=24 24,04,cc,cc,ss,ss,ss,ss Raw Set ssssssss ? ;/ ;Reply=24 24,xx,cc,cc,ss,ss,ss,ss Invalid (same as 24,04) ;Reply=24 26,xx,cc,cc Deadlock ;\both same (maybe ;Reply=26 28,xx,cc,cc Deadlock ;/Watchdog/reboot?) ;Reply=26 2A,xx,cc,cc,00,nn Stepback Ringbuf_hh ;\go back nn ;Reply=2A 2A,xx,cc,cc,01,nn Stepback Ringbuf_mm ; entries, ;Reply=2A 2A,xx,cc,cc,02,nn Stepback Ringbuf_dd ;/see [FCDAh] ;Reply=2A 2A,xx,cc,cc,xx,.. Invalid ;Reply=2A 2C,cs,cc,cc Toggle one LED on/off ;Reply=2C F4,xx,cc,cc Disconnect ;Reply=None F6,xx,cc,cc Force "Bad Chksum" reply ;Reply=FC FA,xx,cc,cc Connect ;Reply=F8 FE,... Noise ;\ignored, noise ;Reply=None FF,... Noise ;/ ;Reply=None xx,xx,cc,cc Invalid ;-ignored, invalid cmd ;Reply=None xx,xx,xx,xx Bad Chksum ;Reply=FC |
08,sq,cc,cc Reply to Cmd 08 (CPU Memory Write reply) 0A,sq,cc,cc,data[..] Reply to Cmd 0A (CPU Memory Read reply) 20,sq,cc,cc Reply to Cmd 20 (Serial EEPROM Write reply) 22,sq,cc,cc,data[..] Reply to Cmd 22 (Serial EEPROM Read reply) 26,xx,cc,cc Reply to Cmd 26 and 28 (Deadlock reply) 24,xx,cc,cc Reply to Cmd 24 (Update, or Set RTC time) 2A,xx,cc,cc Reply to Cmd 2A (Stepback, with result at [FCDAh]) 2C,cs,cc,cc Reply to Cmd 2C (LED reply) 80,FF,cc,cc Factory Reset and Hardware Test completed (or failed) F8,00,cc,cc Reply to Cmd FA (Connect reply) FC,xx,cc,cc Reply to Cmd's with Bad Chksum (and Cmd F6) FC Advertising Msg (after pressing button) (single byte) |
cc,cc Checksum (LITTLE-ENDIAN) msb,lsb Memory Address (big-endian) ss,ss,ss,ss Seconds since 2001 (big-endian) ss,mm,hh RTC time HH:MM:SS (BCD) (caution: smashes seconds since 2001) sq Increasing sequence number in Memory Access replies cs LED color/state (c=color red/green, s=state on/off) xx Whatever (don't care?) |
| DS Cart Infrared Activity Meter Memory Map |
[0FFD4h].0 Port 1 Data bit0 IN Factory Test (0=Test, 1=Normal) [0FFD4h].2 Port 1 Data bit2 OUT Set for sum of eight A/D conversions [0FFD6h].0 Port 3 Data bit0 OUT IrDA PWDOWN (1=disable IrDA RX) [0FFD6h].1 Port 3 Data bit1 IN IrDA RXD ;\via serial IrDA registers [0FFD6h].2 Port 3 Data bit2 OUT IrDA TXD ;/ [0FFDBh].2 Port 8 Data bit2 OUT LED color? [0FFDBh].3 Port 8 Data bit3 OUT LED color? [0FFDCh].0 Port 9 Data bit0 OUT SPI EEPROM chipselect (0=select) [0FFDEh].0 Port B Data bit0 IN Button input IrDA IR Transfers SPI SPI 8Kbyte EEPROM A/D Used to read two single-axis sensors (for step counting)? A/D Also used to read sum of eight A/D conversions (for wakeup from sleep)? |
FB80h 1 Button flags (bit7=curr.state, bit6=newly.pressed, bit5=old.state) FB81h 1 ... cleared if memread src was unique_id (and other cases) FB82h 1 ... sys/power mode ? FB83h 1 ... adc_mode, or power_saving? FB84h 1 ... clock change request FB85h 1 ... led_extra_mask (never CLEARED, except on boot, or maybe via IR) FB86h 1 adc_array_index (index in ADC array X/Y, wraps in range 00h..3Fh) FB87h 1 ... entrysize of current data in ringbuf (per newest TAG) or so? FB88h 1 SPI overrun error (probably nonsense, SPI clk can't outrun itself) FB89h 1 Unused FB8Ah 1 num_steps_curr_minute (00h..FCh) (no conflict with tag FDh,FEh,FFh) FB8Bh 1 rtc_event_flags (bit0=minute, bit1=hour, bit2=day, bit3=also.hour) FB8Ch 1 ... timing offhold for various stuff FB8Dh 1 some_shift_amount ;READ via IR FB8Eh 1 Daily goal reached flag (aka LED color) (bit0=reached, bit1=???) FB8Fh 1 ... timing for LED step pulses? FB90h 1 ... timing for LED step pulses? FB91h 1 ... flag for LED step pulse state? FB92h 1 Hour when new day starts (BCD, usually/always 03h) ;READ via IR FB93h 1 ... some flag for inactivity low-power mode ? FB94h 1 LED animation number (1..5, or 0=none) (factory test result) FB95h 1 Unused FB96h 1 New day flag FB97h 1 Fixed LED mask (this is a "fixed" setting from EEPROM) FB98h 1 Compare_ctrl_0 ;\for "Compare Control" HW registers (89h,89h) FB99h 1 Compare_ctrl_1 ;/ FB9Ah 1 New Goal flag (apply [FCF4h] as new goal, starting on next day?) FB9Bh 1 Unused FB9Ch 28h Unique ID ;READ via IR (initally set by NDS via RAM+EEPROM writes?) FBC4h 2 adc_current_x FBC6h 2 adc_current_y FBC8h 80h adc_array_x (40h x 16bit) FC48h 80h adc_array_y (40h x 16bit) FCC8h 2 adc_scale_factor_x ;\scale factors FCCAh 2 adc_scale_factor_y ;/ FCCCh 2 adc_scale_unused_z ;\semi-unused (written, but never read) FCCEh 2 adc_scale_unused_t ;/ FCD0h 2 ringbuf_mm_index (0020h..16A0h) ;READ via IR FCD2h 2 ringbuf_hh_index (16A1h..1C42h) ;READ via IR FBD4h 2 Unused FCD6h 2 ringbuf_dd_index (1C43h..1CDEh) ;READ via IR FCD8h 2 num_steps_curr_hour (16bit step counter for current hour) FCDAh 2 ringbuf_stepback_index (result from cmd_2Ah, to be read by cmd_0Ah) FCDCh 2 adc_inactivity_timer (time since last pedometer step) FCDEh 2 SPI overrun error counter (related to flag at FB88h) FCE0h 2 Unused FCE2h 2 adc_current_sum (sum of eight A/D conversions) FCE4h 4 seconds_counter (seconds since 1st Jan 2001?, initially 0D2B0B80h) FCE8h 4 num_steps_lifelong (lifelong TOTAL steps) FCECh 4 num_steps_today (step counter, for current day) FCF0h 4 Daily_goal (WRITTEN via IR, NDS cart default=3000 decimal) FCF4h 4 new_goal_steps (somewhat reload value for daily goal?) FCF8h 18h Unused FD10h 2 main_callback (main_adc_button_callback, or ir_callback) FD12h 40h ir_tx_data (buffer for Memory & EEPROM reads) FD52h 2 clk_callback (clk_whatever_callback, or 0=none) FD54h 2 ir_callback (ir_active_callback, or ir_dummy_callback) FD56h 2 ir_timestamp_last_byte (for sensing SHORT GAPs, aka end-of-packet) FD58h 2 RX chksum from hdr[2..3] FD5Ah 2 RX chksum from calculation FD5Ch 2 ir_timestamp_last_xfer (for sensing LONG GAPs, aka sleep mode) FD5Eh 1 Unused FD5Fh 1 ir_rx_len FD60h 1 ... semi-unused (set to 00h?) (but never read) FD61h 44h ir_rxtx_buf, hdr[4]+data[40h] FDA5h 1 ir_tx_hdr_len ;\memorized TX len+hdr[4] FDA6h 4 ir_tx_hdr_copy ;/(never actually used) FDAAh 1 bad_chksum_count, give up sending bad_chksum replies after 3 errors FDABh 1 bad_chksum_flag, request reply_FCh (bad_chksum) FDACh 80h ... array (40h x 16bit) ;\ FE2Ch 80h ... array (40h x 16bit) ; analog sine/cosine FEACh 4 ... dword ; stuff for converting FEB0h 4 ... dword ; adc to step counter? FEB4h 1 ... byte ; FEB5h 1 ... byte ;/ FEB6h 2 Incremented in main_adc_button_callback (but not used elsewhere) FEB8h 1 Unused ;\maybe meant to be 4-byte tx hdr, FEB9h 1 TX sequence number ; but only hdr[1] used (as increasing FEBAh 2 Unused ;/seq.no for memory read/write replies) FEBCh 4 ... array (2 x 16bit) FEC0h 4 ... array (2 x 16bit) FEC4h 4 ... array (2 x 16bit) FEC8h 4 ... array (2 x 16bit) FECEh B2h CPU Stack area, initial SP=FF80h |
EEPROM:0000h 9 ID "nintendo",00h (9 bytes) EEPROM:0009h 17h Unused (FFh-filled) EEPROM:0020h 1681h Ringbuf_mm ;steps per MINUTE for 4 days ;(24*60*4-1)*8bit EEPROM:16A1h 5A2h Ringbuf_hh ;steps per HOUR for 30 days ;(24*30+1)*16bit EEPROM:1C43h 9Ch Ringbuf_dd ;steps per DAY for 52 days ;(52)*24bit EEPROM:1CDFh 1 Unused (FFh) (padding ringbuf's to 20h-byte-boundary) EEPROM:1CE0h 200h Unused (FFh-filled) EEPROM:1EE0h 8+1 ADC_scale_values (4x16bit) ;RAM:FCC8h ;\ EEPROM:1EE9h 2+1 ADC sum_limit ;RAM:stack ; these EEPROM EEPROM:1EECh 3 Unused ; settings EEPROM:1EEFh 4+1 Num_steps_lifelong ;RAM:FCE8h ; have 1-byte EEPROM:1EF4h 1+1 Fixed LED Mask ;RAM:FB97h ; checksums EEPROM:1EF6h 2 Unused ; appended, and EEPROM:1EF8h 1+1 Some_shift_amount ;RAM:FB8Dh ; backups at EEPROM:1EFAh 4+1 Daily_goal ;RAM:FCF0h ; 1F40h-1F9Fh EEPROM:1EFFh 4+1 New_goal_steps ;RAM:FCF4h ; EEPROM:1F04h 28h+1 Unique ID ;RAM:FB9Ch ; EEPROM:1F2Dh 13h Unused (00h-filled) ;/ EEPROM:1F40h 60h Backup copies of above data at 1EE0h..1F3Fh ;-backups EEPROM:1FA0h 2 Error code (initially FFFFh) EEPROM:1FA2h 1 Reboot counter (initially 00h or 01h ?) EEPROM:1FA3h 5Dh Unused (FFh-filled) |
00xxh Zero steps for N minutes (N=max FCh) ;\in ringbuf_mm xxh N steps per minute (N=01h..FCh) ;/ xxxxh N steps per hour (N=0000h..FFFFh) ;-in ringbuf_hh xxxxxxh N steps per day (N=000000h..FFFFFFh) ;-in ringbuf_dd FDxxxxxxxxxxh Timestamp, reversed-BCD-digit-order, seconds since 2001 or so? FEh Newest entry marker? FFh Unused entry marker? |
| DS Cart Infrared P-Walker IR Commands |
EEPROM Commands (Cmd 02,04,0C,0E,82) ;\From NDS or Walker Connect Commands (Cmd F8,FA,FC) ;/ Peer Commands (Cmd 10...1C) ;-From Walker Unused Commands (Cmd's with * marking) ;-From Prototype tests? Other Commands (Cmd's other than above) ;-From NDS |
00,hi,..,lzss(..) EEPROM Write [hi00h..hi7Fh] Compressed ;Reply=04 80,hi,..,lzss(..) EEPROM Write [hi80h..hiFFh] Compressed ;Reply=04 02,hi,..,data(..) EEPROM Write [hi00h..hi7Fh] Raw ;Reply=04 82,hi,..,data(..) EEPROM Write [hi80h..hiFFh] Raw ;Reply=04 04,xx,.. EEPROM Write Reply ;SendMoreCmd(s) 06,hi,..,lo,data(nn)* CPU Memory Write [hilo+(0..nn-1)] ;Reply=06 0A,hi,..,lo,data(nn)* EEPROM Write Random Len [hilo+(0..nn-1)] ;Reply=04 0C,xx,..,hi,lo,nn EEPROM Read Request [hilo+(0..nn-1)] ;Reply=0E 0E,xx,..,data(nn) EEPROM Read Reply ;SendMoreCmd(s) 10,xx,..,data(68h) Peer Step 1 Request ;Reply=12 12,xx,..,data(68h) Peer Step 1 Reply ;SendMoreCmd(s) 14,xx,..,data(38h) Peer Step 2 Request ;Reply=16 16,xx,.. Peer Step 2 Reply ;Reply=16 or None 1C,xx,.. Peer Refuse ;Reply=None+Disconnect 20,xx,.. Identity Read Request ;Reply=22 24,xx,.. * Ping Request ;Reply=26 2A,xx,..,none? Unique ID Read Request ;Reply=2A 2C,xx,..,none? * Unique ID Read Request slightly other ;Reply=2A 32,xx,..,data(28h?) * Identity Write Request 1 ;Reply=34 36,xx,.. * Connection Error 1 ;Reply=None 38,xx,.. * Walk Start Silent ;Reply=38 40,xx,..,data(28h?) * Identity Write Request 2 ;Reply=42 44,xx,.. * Connection Error 2 ;Reply=None 4E,xx,.. Walk End Request ;Reply=50 52,xx,..,data(28h?)?? Identity Write Request 3 ;Reply=54 56,xx,.. * Connection Error 3 ;Reply=None 5A,xx,.. Walk Start Nonsilent ;Reply=5A 60,xx,..,data(28h?) * Identity Write Request 4 ;Reply=62 64,xx,.. * Connection Error 4 ;Reply=None 66,xx,.. * Walk End Request OTHER ;Reply=68 9C,xx,.. * Error Whatever ;Reply=9C+Disconnect 9E,xx,.. * Error Weird Participate ;Reply=9E+Disconnect A0,xx,.. * Weird Participate 1 ;Reply=A0 or 9E A2,xx,.. * Weird Participate 2 ;Reply=A2 or 9E A4,xx,.. * Weird Participate 3 ;Reply=A4 or 9E A6,xx,.. * Weird Participate 4 ;Reply=A6 or 9E A8,xx,.. * Weird Participate 5 ;Reply=A8 or 9E AA,xx,.. * Weird Participate 6 ;Reply=AA or 9E AC,xx,.. * Weird Participate 7 ;Reply=AC or 9E AE,xx,.. * Weird Participate 8 ;Reply=AE or 9E B8,xx,.. * Award Stamp Heart ;Reply=D8 BA,xx,.. * Award Stamp Spade ;Reply=DA BC,xx,.. * Award Stamp Diamond ;Reply=DC BE,xx,.. * Award Stamp Club ;Reply=DE C0,xx,.. * Award Special Map ;Reply=C0 C2,xx,.. * Award Event P-Letter ;Reply=C2 C4,xx,.. * Award Event Item ;Reply=C4 C6,xx,.. * Award Event Route ;Reply=C6 D0,xx,.. * Award All Stamps and Special Map ;Reply=C0 D2,xx,.. * Award All Stamps and Event P-Letter ;Reply=C2 D4,xx,.. * Award All Stamps and Event Item ;Reply=C4 D6,xx,.. * Award All Stamps and Event Route ;Reply=C6 D8,xx,.. * Connection Error 5 ;Reply=None F0,xx,..,data(71h) ?? Enroll Data (28h+40h+8+1 bytes) ;Reply=F0 F4,xx,.. * Disconnect ;Reply=None+Disconnect F8,02,.. Connection Reply from Walker ;SendCmd=1002 FA,01,.. Connection Request from NDS ;Reply=F802 FA,02,.. Connection Request from Walker ;Reply=F802 FA,xx,.. Connection Request invalid ;Reply=None+Disconnect FC Connection Beacon from Walker ;SendCmd=FA FE,01,..,data(8) * EEPROM Write [0008h..000Fh] ;Reply=FE xx * Ignored (single byte other than FC) ;Reply=None xx,xx,.. * Invalid Cmd ;Reply=None xx,xx,xxxx * Ignored (wrong 4-byte ID for Cmd 00-F7) ;Reply=None xx,xx,xxxx * Bad Checksum (disconnect if too often) ;Reply=None |
02,hi,..,data(nn) EEPROM Write ... ;Cmd=Peer 82,hi,..,data(nn) EEPROM Write ... ;Cmd=Peer 04,hi,.. EEPROM Write Reply ;Cmd=00/02/0A/80/82 06,hi,.. * CPU Memory Write Reply ;Cmd=06h 0C,02,..,hi,lo,nn EEPROM Read Request ;Peer, EEPROM Read ;Cmd=0Eh 0E,02,..,data(nn) EEPROM Read Reply ;Cmd=0Ch 10,02,..,data(68h) Peer Step 1 Request (after Connect Reply);Cmd=F8h 12,02,..,data(68h) Peer Step 1 Reply ;Cmd=10h 14,02,..,data(38h) Peer Step 2 Request ;Cmd=0Eh 16,02,.. Peer Step 2 Reply ;Cmd=14h/16h 1C,02,.. Peer Refuse ;Cmd=10h/12h 22,02,..,data(68h) Identitiy Read Reply ;Cmd=20h 26,02,.. * Ping Reply ;Cmd=24h 2A,02,..,data(28h) Unique ID Reply ;Cmd=2Ah/2Ch 34,02,.. * Identitiy Write 1 Reply ;Cmd=32h 38,02,.. * Walk Start silent Reply ;Cmd=38h 42,02,.. * Identitiy Write 2 Reply ;Cmd=40h 50,02,.. Walk End Reply ;Cmd=4Eh 54,02,.. ?? Identitiy Write 3 Reply ;Cmd=52h 5A,02,.. Walk Start nonsilent Reply ;Cmd=5Ah 62,02,.. * Identitiy Write 4 Reply ;Cmd=60h 68,02,.. * Walk End OTHER Reply ;Cmd=66h 9C,02,.. * Weird Whatever Reply-to-Reply? ;Cmd=9Ch 9E,02,..,data(11h) * Weird Participated Reply ;Cmd=A0h..AEh 9E,02,.. * Weird Participated Reply-to-Reply? ;Cmd=9Eh A0,02,..,data(11h) * Weird Participated Reply 1 ;Cmd=A0h A2,02,..,data(11h) * Weird Participated Reply 2 ;Cmd=A2h A4,02,..,data(11h) * Weird Participated Reply 3 ;Cmd=A4h A6,02,..,data(11h) * Weird Participated Reply 4 ;Cmd=A6h A8,02,..,data(11h) * Weird Participated Reply 5 ;Cmd=A8h AA,02,..,data(11h) * Weird Participated Reply 6 ;Cmd=AAh AC,02,..,data(11h) * Weird Participated Reply 7 ;Cmd=ACh AE,02,..,data(11h) * Weird Participated Reply 8 ;Cmd=AEh C0,02,.. * Award Special Map Reply ;Cmd=C0h/D0h C2,02,.. * Award Event P-Letter Reply ;Cmd=C2h/D2h C4,02,.. * Award Event Item Reply ;Cmd=C4h/D4h C6,02,.. * Award Event Route Reply ;Cmd=C6h/D6h C8,02,.. * Award Stamp Heart Reply ;Cmd=B8h CA,02,.. * Award Stamp Spade Reply ;Cmd=BAh CC,02,.. * Award Stamp Diamond Reply ;Cmd=BCh CE,02,.. * Award Stamp Club Reply ;Cmd=BEh F0,02,..,data(28h) ?? Enroll Reply ;Cmd=F0h F8,02,.. Connect Reply ;Cmd=FAh FA,02,.. Connect Request from walker ;Cmd=FCh FC Connection Beacon ;Button? FE,02,.. * EEPROM Write [0008h..000Fh] Reply ;Cmd=FEh -?- Checksum Error... has no reply? or maybe sends Beacons? |
.. short for 16bit Checksum at hdr[2..3] and 32bit Session ID at hdr[4..7] xx somewhat don't care (usually 01h=From NDS, or 02h=From Walker) |
SessionID = ConnectRequestRandomID XOR ConnectReplyRandomID. |
| DS Cart Infrared P-Walker Memory Map |
[0FFD4h].0 Port 1 Data bit0 OUT SPI LCD chipselect (0=select) [0FFD4h].1 Port 1 Data bit1 OUT SPI LCD access mode (0=Cmd, 1=Data) [0FFD4h].2 Port 1 Data bit2 OUT SPI EEPROM chipselect (0=select) [0FFD6h].0 Port 3 Data bit0 OUT IrDA PWDOWN (1=disable IrDA RX) [0FFD6h].1 Port 3 Data bit1 IN IrDA RXD ;\via serial IrDA registers [0FFD6h].2 Port 3 Data bit2 OUT IrDA TXD ;/ [0FFDBh].2 Port 8 Data bit2 ? [0FFDBh].3 Port 8 Data bit3 ? [0FFDBh].4 Port 8 Data bit4 OUT A/D related ... whatfor LCD? accel? batt? [0FFDCh].0 Port 9 Data bit0 OUT SPI Accelerometer chipselect (0=select) [0FFDEh].0 Port B Data bit0 IN ? ;\ [0FFDEh].2 Port B Data bit2 IN ? ; maybe buttons [0FFDEh].4 Port B Data bit4 IN ? ;/ [0FFDEh].5 Port B Data bit5 OUT ? Timer W General A/B/C Audio Frequency/Volume IrDA IR Transfers SPI SPI 64Kbyte EEPROM, LCD Cmd/Data, Accelerometer A/D whatfor LCD? accel? batt? |
F780h 60h Misc variables F7E0h 2 main_callback ;<-- F7E2h ECh Misc variables F8CEh 8+80h Infrared RX/TX buffer hdr+data (also misc/heap) F956h 62Ah Temp buffer, free RAM, and stack ;<-- FF80h - Stacktop (end of RAM) |
0772h Send IR packet (F8D6h=src, r0l=len, r0h=hdr[0], r1l=hdr[1]) 08D6h Default callback (when in IR transfer mode) 259Eh Watchdog refresh |
0000h 8 ID "nintendo" (set after initial power-up eeprom init)
0008h 8 ID whatever (set via Cmd F0h and FEh) (never read)
0010h 62h ???
0072h 1 Number of watchdog resets
0073h 0Dh ???
0080h 02h+1 ADC calibration (factory-provided) ;\
0083h 28h+1 Unique ID (set via Cmd F0h) ; with 1-byte
00ACh 40h+1 LCD ConfigCmds (set via Cmd F0h) ; checksums
00EDh 68h+1 Identity Data ("provisioned" at walk start time) ; and backup
0156h 18h+1 Health Data ("provisioned" at walk start time) ; copies at
016Fh 01h+1 Copy Flag (00h=Normal, A5h=copy was interrupted) ; 0180h-027Fh
0171h 0Fh Unused ;/
0180h 100h Backup copies of entries at 0080h-0017Fh
0280h ... Various Bitmaps
8C70h ... Various Garbage, Bitmaps, Items, Team, Route
CE8Ah 2 current watts written to eeprom by cmd 20h before replying
(likely so remote can read them directly). u16 BE
CE8Ch ... Various stuff
CEF0h 1Ch Historic step count per day. u32 each, BE,
[0] is yesterday, [1] is day before, etc...
CF0Ch ... Various stuff
|
__________________ Data Structures (in EEPROM and Packets) ___________________ |
00h 28h Generated by the DS game at pairing time, unique per walker |
00h 4 Unknown (LE, always 1?) ;\written from game packet at walk start 04h 4 Unknown (LE, always 1?) ; ;<-- 0 at walk end ;copied from [0] 08h 2 Unknown (LE, always 7?) ; 0Ah 2 Unknown (LE, always 7?) ;/ ;<-- 0 at walk end ;copied from [8?] 0Ch 2 TrainerTID 0Eh 2 TrainerSID 10h 28h Unique ID 38h 10h EventBitmap (aka bitfield with 128 event flags?) 48h 10h Trainer Name (8 chars, using a custom 16bit charset, non-unicode) 58h 1 Unknown 59h 1 Unknown 5Ah 1 Unknown 5Bh 1 Flags (bit0=PairedToGame, bit1=HasPoke, bit2=PokeJoinedOnAWalk) 5Ch 1 ProtoVer (02h) (written by DS, refuse peer's with other values) 5Dh 1 Unknown 5Eh 1 ProtoSubver (00h) (written by DS, refuse peer's with other values) 5Fh 1 Unknown (02h) (written by DS at walk start) 60h 4 LastSyncTime ;Big Endian ;in WHAT... maybe seconds since WHEN? 64h 4 StepCount ;Big Endian ;since WHEN... today? lifetime? lastsync? |
00h 4 curStepCount (since WHEN?) 04h 2 curWatts 06h 2 Unused 08h 4 Unknown, copied from IdentityData[00h] 0Ch 2 Unknown, copied from IdentityData[08h] 0Eh 2 Species 10h 16h P-Nickname (11 chars) ;\the actual names in bitmap format 26h 10h Trainer Name (8 chars) ;/are stored elsewhere in EEPROM? 36h 1 GenderForm 37h 1 HasSpecialForms (spinda, arceus, unown, etc.) |
00h 1 u8 contrastAndFlags (if 00h/FFh? commands at ROM:BEB8h will be used) 01h 3Fh u8 commands[3fh] (Commands, or FDh,NNh=Delay(NNh), FEh=End of list) |
00h 28h Unique ID ;always written 28h 40h LCD Config Data ;written or verified depending on byte[70h] 68h 8 Whatever ID ;always written to EEPROM:0008h 70h 1 LCD Action (00h=WriteA, 01h=Compare, 03h=WriteB, 02h/04h-FFh=Nop) |
00h 4 u32 lifetimeTotalSteps 04h 4 u32 todaySteps //zeroed at midnight 08h 4 u32 lastSyncTime 0Ch 2 u16 totalDays 0Eh 2 u16 curWatts 10h 2 u16 unk_0 12h 1 u8 unk_1 13h 1 u8 unk_2 14h 3 u8 padding[3] 17h 1 u8 settings (bit0=isOnSpecialRoute, bit1-2=Volume, bit3-6=Contrast) |
| DS Cart Infrared P-Walker Ports LCD Controller |
1st Byte 2nd Byte Description
00h+(0..Fh) - Set Column Address bit0-3 ;\VRAM xloc in 1-pixel units
10h+(0..7) - Set Column Address bit4-6 ;/
18h+(0..7) - Reserved
20h+(0..7) - Set Internal Regulator Resistor Ratio
(0..7 = 2.3, 3.0, 3.7, 4.4, 5.1, 5.8, 6.5, 7.2)
28h+(0..7) - Set Power Control Register
bit2: Internal Voltage Booster (0=Off, 1=On)
bit1: Internal Regulator (0=Off, 1=On)
bit0: Output Op-amp Buffer (0=Off, 1=On)
30h+(0..0Fh) - Reserved
40h 00h-xxh Set Display Start Line (0..127?) (ROW) ("scroll yloc")
41h+(0..2) 00h-xxh Same as above?
44h 00h-xxh Set Display Offset (0..63) (COM0=ROW0..63) (pinout?)
45h+(0..2) 00h-xxh Same as above?
48h 00h-xxh Set Multiplex Ratio (num lines, duty 1/((16..64)+icon))
49h+(0..2) 00h-xxh Same as above?
4Ch 00h-3Fh Set N-line Inversion (0=Off, 1..31=Reduce crosstalk?)
4Ch 20h-FFh Same as above?
4Dh+(0..2) 00h-FFh Same as above?
50h+(0..7) - Set LCD Bias (0..5=1/(4..9), 6=1/9, too)
57h+(0..0Ch) - Reserved
64h+(0..3) - Set DC-DC Converter Factor (0=2x/3x, 1=4x, 2/3=5x)
68h+(0..18h) - Reserved
81h 00h-3Fh Set Contrast (0..3Fh, 3Fh=Darkest)
82h OTP Set VL6 voltage (00h..0Fh = original+Signed4bit(N))
83h OTP OTP Programming?
84h+(0..7) - Reserved
88h 00h-FFh Set White Mode (bit0-3=FrameA, bit4-7=FrameB)
89h 00h-FFh Set White Mode (bit0-3=FrameC, bit4-7=FrameD)
8Ah 00h-FFh Set Light Gray Mode (bit0-3=FrameA, bit4-7=FrameB)
8Bh 00h-FFh Set Light Gray Mode (bit0-3=FrameC, bit4-7=FrameD)
8Ch 00h-FFh Set Dark Gray Mode (bit0-3=FrameA, bit4-7=FrameB)
8Dh 00h-FFh Set Dark Gray Mode (bit0-3=FrameC, bit4-7=FrameD)
8Eh 00h-FFh Set Black Mode (bit0-3=FrameA, bit4-7=FrameB)
8Fh 00h-FFh Set Black Mode (bit0-3=FrameC, bit4-7=FrameD)
Above defines the grayscale palette for color 0-3,
normally all frames should use the same setting.
Color 0 is usually white (set to zero), color 3 is
usually black (set to number of levels selected via
cmd 90h). Color 1 and 2 are usually light/dark gray,
set to desired contrast, which may depend on the LCD.
90h+(0..7) - Set PWM and FRC for gray-scale operation
bit0-1: Levels (0/1=Nine, 2=Twelve, 3=Fifteen Levels)
bit2: Frames (0=Four, 1=Three Frames)
Note: Nintendo uses "9 levels" ranging from "0 to 9"
(maybe level 0 is treated as off, thus not counted)
98h+(0..7) - Reserved
A0h+(0..1) - Set Segment Remap (0=Col00h is SEG0, 1=Col7Fh is SEG0)
Aka xflip mirror?
A2h+(0..1) - Set Icon Enable (0=Disable, 1=Enable)
A4h+(0..1) - Set Entire Display On/Off (0=Show RAM, 1=All Pixels On)
A6h+(0..1) - Set Inverse Display (0=Normal, 1=Inverse On/Off Pixels)
A8h+(0..1) - Set Power Save Mode (0=Standby, 1=Sleep)
AAh - Reserved
ABh - Start Internal Oscillator (needed after reset)
ACh+(0..1) ? Reserved
AEh+(0..1) - Set Display On/Off (0=Off, 1=On)
B0h+(0..0Fh) - Set Page Address (00h..0Fh) ;VRAM yloc in 8-pixel units
C0h+(0,8) - Set COM Output Scan Direction (0=Normal, 8=Remapped)
Remapped: COM[0..(N-1)] becomes COM[(N-1)..0])
Aka yflip mirror?
C1h+(0..6) - Same as above (Normal)
C9h+(0..6) - Same as above (Remapped)
D0h+(0..10h) - Reserved
E1h - Exit Power-save Mode (return from Sleep/Standby modes)
E2h - Software Reset (initialize some internal registers)
E3h - Reserved
E4h - Exit N-line Inversion mode
E5h+(0..2) - Reserved
E8h LEN+DTA Transfer VRAM Display Data (for 3-wire SPI mode only)
(LEN=00h-FFh, followed by LEN+1 data bytes)
E9h+(0..6) - Reserved
F0h+(0..0Fh) .. Test mode commands and Extended features
F0h 00h-03h Ext. Set VL6 Noise reduction (0=Enable, 3=Disable)
F1h 08h-0Fh Ext. Set TC Value per 'C (0=-0.05%, 1=-0.07%, 2..7=?)
F2h 00h-07h Ext. Oscillator Adjustment
(0..7 = -9%, -6%, -3%, +0%, +3%, +6%, +9%, +12%)
F7h 00h-01h Ext. Oscillator Source (0=Internal, 1=External, 2=UNDOC)
F6h 00h-1Fh Ext. Frame Frequency Adjust
bit0-2: FrameFQ (0..7 = 0..7)
bit3-4: Fosc (0-3 = 59kHz, 75kHz, 94kHz, 113kHz)
FBh X2h,X6h Ext. Lock/Unlock Interface (bit2: 0=Unlock, 1=Lock)
|
00h+(xloc) AND 0Fh ;Set Column Address bit0-3 10h+(xloc/10h) ;Set Column Address bit4-6 B0h+(yloc/8) ;Set Page Address (00h..0Ah, other=reserved?) |
1st byte = bitplane 1 ;\color 0..3 are usually white, lgray, dgray, black 2nd byte = bitplane 0 ;/(palette can be changed via cmd 88h-8Fh though) |
3-wire SPI Serial write-only (/CS, CLK, MOSI, with cmd E8h instead D/C pin) 4-wire SPI Serial write-only (/CS, CLK, MOSI, D/C=Data/Cmd) 12-wire 8080 Parallel read/write (/CS, D0-D7, D/C, /RD, /WR) 12-wire 6800 Parallel read/write (/CS, D0-D7, D/C, E, R/W) |
7 BUSY Chip is executing instruction (0=Ready, 1=Busy) 6 ON Display is On/Off (0=Off, 1=On) 5 RES Chip is executing reset (0=Ready, 1=Busy) 4-0 - Fixed Chip ID (08h=SSD1850) |
SSD0852 128x128 would allow double-buffer, but extended commands are wrong
SSD0858 104x65 close, but extended commands are wrong
SSD0859 128x81 could be correct (almost same as SSD1850)
SSD1820 128x65 wrong, lacks palette (command 88h-8Fh)
SSD1820A 128x65 wrong, lacks palette (command 88h-8Fh)
SSD1821 128x81 wrong, lacks palette (command 88h-8Fh)
SSD1850 128x65 could be correct (ysiz is good, but no double-buffering)
SSD1851 128x81 as above, but more lines than needed
SSD1852 128x128 would allow double-buffer, but extended commands are wrong
SSD1854 128x160 wrong, uses 2-byte command B0h,YYh lacks extended commands
(also cmd 18h,20h,4xh,50h,60h-63h,64h,82h,83h,etc. differ)
SSD1858 104x65 close, but lacks many extended commands
SSD1859 128x81 could be correct (almost same as SSD1850)
|
| DS Cart Infrared P-Walker Ports Accelerometer BMA150 |
00h Chip ID (bit7-3=Unused, bit2-0=02h) 01h Version (bit7-4=al_version, bit3-0=ml_version) (undefined values) 02h Acc X Low (bit7-6=DataLsb, bit5-1=Unused, bit0=NewDataFlag) 03h Acc X High (bit7-0=DataMsb) 04h Acc Y Low (bit7-6=DataLsb, bit5-1=Unused, bit0=NewDataFlag) 05h Acc Y High (bit7-0=DataMsb) 06h Acc Z Low (bit7-6=DataLsb, bit5-1=Unused, bit0=NewDataFlag) 07h Acc Z High (bit7-0=DataMsb) 08h Temperature (bit7-0=DataTempMsb) (Lsb not existing, except in Trimming?) 09h Status Flags (see below) 0Ah Control Flags (see below) 0Bh Config Flags (see below) 0Ch LG Threshold (bit7-0) 0Dh LG Duration (bit7-0) 0Eh HG Threshold (bit7-0) 0Fh HG Duration (bit7-0) 10h Any Motion Threshold (bit7-0) 11h Misc Stuff (bit7-6=AnyMotionDur, bit5-3=HG Hyst, bit2-0=LG Hyst) 12h Customer Reserved 1 (bit7-0) 13h Customer Reserved 2 (bit7-0) 14h Range/Bandwidth (bit7-5=Reserved, bit4-3=Range, bit2-0=Bandwidth) 15h Misc Flags (see below) 16h Trimming X Low (bit7-6=OffsetLsb, bit5-0=Gain) 17h Trimming Y Low (bit7-6=OffsetLsb, bit5-0=Gain) 18h Trimming Z Low (bit7-6=OffsetLsb, bit5-0=Gain) 19h Trimming T Low (bit7-6=OffsetLsb, bit5-0=Gain) 1Ah Trimming X High (bit7-0=OffsetMsb) 1Bh Trimming Y High (bit7-0=OffsetMsb) 1Ch Trimming Z High (bit7-0=OffsetMsb) 1Dh Trimming T High (bit7-0=OffsetMsb) 1Eh-22h BST reserved (official blank/green) 23h BST reserved (official blank/white) 24h-2Ah Not used (official gray/dither) 2Bh-3Dh EEPROM Defaults for Registers 0Bh-1Dh 3Eh-42h BST reserved (official blank/orange) 43h-49h Not used (official gray/dither) 4Ah-4Fh Not mentioned (official not here) 50h-7Fh BST reserved (official blank/cyan) |
7 ST Result 6-5 Not used (official piss/dither) 4 Alert Phase 3 LG_latched 2 HG_latched 1 LG_status 0 HG_status |
7 Reserved (official gray/dither) 6 Reset INT 5 Update IMAGE 4 EE_W (uh? maybe eeprom write?) 3 Self Test 1 2 Self Test 0 1 Soft Reset 0 Sleep |
7 Alert 6 Any Motion 5-4 Counter HG 3-2 Counter LG 1 Enable HG 0 Enable LG |
7 SPI4 6 enable_adv_INT 5 new_data_INT 4 latch_INT 3 shadow_dis 2-1 wake_up_pause 0 wake_up |
| DS Cart Infrared Component Lists |
Case "Nintendo, NTR-031. PAT. PEND., IMWPN1J12" PCB "DA A-4 IRU01-10" (two layers) plus "IRL01-01 "(brown extra film layer) U1 32pin "S906748-1, SanDisk, 11014-64B, P0A837.00, 0843, NTR-IMWP-1" (ROM) U2 32pin "38600R, A06V, AH00167, 0832" (CPU, ROM 8Kbyte, RAM 0.5KByte) U3 5pin "?" (OR-gate? flipflop?) (for forwarding SPI /CS to FLASH /CS) U4 8pin "45PE80VG, HPAMZ V5, KOR 833X, ST e3" (SPI FLASH 1024 Kbytes) U1' 7pin "5 S.. 9" IR transceiver (on brown film layer) X1 6pin "737Wv" ;7.37MHz? /FLASH.CS --|""""|-- GND R1,R2,RA1 resistors | U3 |-- /SPI.CS (from NDS) C1,C2,C3,C4,C5,C6 capacitors VDD33 --|____|-- U2.pinxxx |
PCB "DI Y-1 IRC02-01" (two layers, without brown extra film layer) U1 32pin "MXIC..." (ROM) U2 32pin "..." (CPU, ROM 8Kbyte, RAM 0.5KByte) U3 5pin "..." (OR-gate? flipflop?) (for forwarding SPI /CS to FLASH /CS) U4 8pin "..." (SPI FLASH) U5 7pin "..." IR transceiver X1 6pin "..." R1,R2,RA1 resistors C1,C2,C3,C4,C5,C6 capacitors |
Case "Nintendo DS, NTR-027, (C) 2008 Nintendo, NTR-A-HC, Made in Japan" Case "CE ./ VCI, ACN 060 566 083, Nintendo" PCB "NTR-DHC-01" (in water resistant case) Ux 32pin Side-A "38602R, F22V, AH04731, 0834" (CPU, ROM 16Kbyte, RAM 1KByte) U2 8pin Side-B "564X, 48H3, 30" (SPI EEPROM 8Kbyte, ST M95640-W or similar) U3 7pin Side-B "1 S. 9" IR transceiver ?? 2pin Side-A huge smd capacitor shaped thing, maybe analog 1-axis sensor? ?? 2pin Side-A huge smd capacitor shaped thing, maybe analog 1-axis sensor? Ux/Qx Side-A many small chips with 3-6 pins and few markings Xx 3pin Side-A "CB825" ;32.768-kHz or 38.4-kHz Crystal Resonator? Yx 6pin Side-A ":i] 3.68t" ;3.68MHz (115.2kHz*32) C1..C34 Plenty capacitors R1..R28 Plenty resistors BTI 2pin Side-B Battery holder (for CR2032 H, 3V) Button Side-A Push button (communication button) |< 4pin Side-A Two color LED |
Case "?"
PCB "NTR-PHC-01" (with green solder stop & unconventional black text layer)
U1 32pin Side-B "F38606, F04V, AK04052, 0942" (CPU,FLASH 48Kbyte,RAM 2KByte)
U2 4pin Side-A "?"
U3 4pin Side-A "?"
U4 4pin Side-A "M_RA"
U5 7pin Side-B IR transceiver
U6 8pin Side-A "Sxxxx, xxxx" (maybe SPI EEPROM?)
U7 12pin Side-B "043, A939, 021" (accelerometer?) (Bosch BMA150 ?)
U8 5pin Side-A "?"
Q1 6pin Side-A "Z4"
D1 3pin Side-A "?" dual diode or so
X1 3pin Side-B "EAJJ" ;32.768-kHz or 38.4-kHz Crystal Resonator?
Y1 6pin Side-B "3.68" ;3.68MHz (115.2kHz*32)
BZ1 2pin Side-B wires to piezo speaker (aka buzzer)
CN1 14pin Side-A LCD connector 14pin? or 2x14pin? (without backlight)
(with SSD1850 display controller (or similar) inside of LCD screen)
(96x64 2-bit greyscale screen) (reportedly with SPI bus)
BT+/- Side-B Battery contacts for removeable battery (for CR2032, 3V)
C1..C29 Plenty capacitors
R1..R22 Plenty resistors
SW's Side-A Three buttons (left, center, right)
|
PCB "SAMU-01" (with green solder stop & unconventional black text layer) U1 40pin Side-B "R5F101EEA, 1242KE415, SINGAPORE" (RL78 CPU) U2 7pin Side-B "845G2947" IR transceiver, with metal shield U3 16pin Side-B (not installed) U4 16pin Side-A --UNKNOWN MARKING, BAD PHOTO-- maybe accelerometer U5 4pin Side-A --UNKNOWN MARKING, BAD PHOTO-- maybe SPI EEPROM/FLASH U6 4pin Side-A (not installed) U7 7pin Side-B "I357, U231, 094" whatever, in metal shielded case X1 3pin Side-B "EABL" crystal or so BZ1 2pin Side-B wires to piezo speaker (aka buzzer) CN1 14pin Side-A LCD connector 14pin? or 2x14pin? (without backlight) BT+/- Side-B Battery contacts for removeable battery Q1 3pin Side-A Transistor or so D1..D2 Side-A Diodes (3pin each) C1..C29 Plenty capacitors R1..R22 Plenty resistors SW's Side-A Three buttons (left, center, right) |
| H8/386 SFRs |
F020h FLMCR1 FLASH Memory Control 1 F021h FLMCR2 FLASH Memory Control 2 F022h FLPWCR FLASH Memory Power Control F023h EBR1 FLASH Erase Block 1 F02Bh FENR FLASH Memory Enable F067h RTCFLG RTC Interrupt Flag F068h RSECDR RTC Seconds / Free running counter F069h RMINDR RTC Minutes F06Ah RHRDR RTC Hours F06Bh RWKDR RTC Day-of-week F06Ch RTCCR1 RTC Control 1 F06Dh RTCCR2 RTC Control 2 F06Fh RTCCSR RTC Clock Source Select F078h ICCR1 I2C Bus Control 1 F079h ICCR2 I2C Bus Control 2 F07Ah ICMR I2C Bus Mode F07Bh ICIER I2C Bus Interrupt Enable F07Ch ICSR I2C Bus Status F07Dh SAR I2C Slave Address F07Eh ICDRT I2C Bus Transmit Data F07Fh ICDRR I2C Bus Receive Data F085h PFCR System Port Function Control F086h PUCR8 Port 8 Pull-up Control F087h PUCR9 Port 9 Pull-up Control F08Ch PODR9 Port 9 Open-drain Control F0D0h TMB1 Timer B1 Mode F0D1h TC/LB1 Timer B1 Counter (R) / Load (W) F0DCh CMCR0 Compare Control 0 F0DDh CMCR1 Compare Control 1 F0DEh CMDR Compare Data F0E0h SSCRH SPI Synchronous Serial Control H (AccessState3) F0E1h SSCRL SPI Synchronous Serial Control L (AccessState3) F0E2h SSMR SPI Synchronous Serial Mode (AccessState3) F0E3h SSER SPI Synchronous Serial Enable (AccessState3) F0E4h SSSR SPI Synchronous Serial Status (AccessState3) F0E9h SSRDR SPI Synchronous Serial Receive Data (AccessState3) F0EBh SSTDR SPI Synchronous Serial Transmit Data (AccessState3) F0F0h TMRW Timer W Mode F0F1h TCRW Timer W Control F0F2h TIERW Timer W Interrupt Enable F0F3h TSRW Timer W Status F0F4h TIOR0 Timer W I/O control 0 F0F5h TIOR1 Timer W I/O control 1 F0F6h TCNT Timer W Counter (16bit) F0F8h GRA Timer W General A (16bit) F0FAh GRB Timer W General B (16bit) F0FCh GRC Timer W General C (16bit) F0FEh GRD Timer W General D (16bit) |
FF8Ch ECPWCR Async Event Counter PWM Compare (16bit) FF8Eh ECPWDR Async Event Counter PWM Data (16bit) FF91h SPCR IrDA UART Serial 3 Port Control FF92h AEGSR Async Event Input Pin Edge Select FF94h ECCR Async Event Counter Control FF95h ECCSR Async Event Counter Control/Status FF96h ECH Async Event Counter H FF97h ECL Async Event Counter L FF98h SMR3 IrDA UART Serial 3 Mode (AccessState3) FF99h BRR3 IrDA UART Serial 3 Bit Rate (AccessState3) FF9Ah SCR3 IrDA UART Serial 3 Control (AccessState3) FF9Bh TDR3 IrDA UART Serial 3 Transmit Data (AccessState3) FF9Ch SSR3 IrDA UART Serial 3 Status (AccessState3) FF9Dh RDR3 IrDA UART Serial 3 Receive Data (AccessState3) FFA6h SEMR IrDA UART Serial 3 Extended Mode (AccessState3) FFA7h IrCR IrDA Control FFB0h TMWD Timer WD Watchdog Mode FFB1h TCSRWD1 Timer WD Watchdog Control/Status 1 FFB2h TCSRWD2 Timer WD Watchdog Control/Status 2 FFB3h TCWD Timer WD Watchdog Counter FFBCh ADRR A/D Converter Result (16bit) FFBEh AMR A/D Converter Mode FFBFh ADSR A/D Converter Start FFC0h PMR1 Port 1 Mode FFC2h PMR3 Port 3 Mode FFCAh PMRB Port B Mode FFD4h PDR1 Port 1 Data FFD6h PDR3 Port 3 Data FFDBh PDR8 Port 8 Data FFDCh PDR9 Port 9 Data FFDEh PDRB Port B Data FFE0h PUCR1 Port 1 Pull-up Control FFE1h PUCR3 Port 3 Pull-up Control FFE4h PCR1 Port 1 Control FFE6h PCR3 Port 3 Control FFEBh PCR8 Port 8 Control FFECh PCR9 Port 9 Control FFF0h SYSCR1 System Control 1 FFF1h SYSCR2 System Control 2 FFF2h IEGR Interrupt Edge Select FFF3h IENR1 Interrupt Enable 1 FFF4h IENR2 Interrupt Enable 2 FFF5h OSCCR System Oscillator Control FFF6h IRR1 Interrupt Flag 1 FFF7h IRR2 Interrupt Flag 2 FFFAh CKSTPR1 Clock Stop 1 FFFBh CKSTPR2 Clock Stop 2 |
| H8/386 Exception Vectors |
0000h Reset/Watchdog 0002h Reserved 0004h Reserved 0006h Reserved 0008h Reserved 000Ah Reserved 000Ch Reserved 000Eh External NMI interrupt 0010h Trap 0 opcode 0012h Trap 1 opcode 0014h Trap 2 opcode 0016h Trap 3 opcode 0018h Reserved 001Ah CPU Direct transition by executing SLEEP 001Ch Reserved 001Eh Reserved 0020h External IRQ0 interrupt 0022h External IRQ1 interrupt 0024h External IRQAEC interrupt 0026h Reserved 0028h Reserved 002Ah Comparator COMP0 002Ch Comparator COMP1 002Eh RTC per 0.25 seconds (4Hz) ;0.25-second overflow 0030h RTC per 0.5 seconds (2Hz) ;0.5-second overflow 0032h RTC per second (1Hz) ;Second periodic overflow 0034h RTC per minute ;Minute periodic overflow 0036h RTC per hour ;Hour periodic overflow 0038h RTC per day ;Day-of-week periodic overflow 003Ah RTC per week (7 days) ;Week periodic overflow 003Ch RTC Free-running overflow 003Eh WDT overflow (interval timer) 0040h Asynchronous event counter overflow 0042h Timer B1 Overflow 0044h Serial SPI (or IIC2) (aka I2C ?) 0046h Timer W Overflow or Capture/compare A,B,C,D 0048h Reserved 004Ah IrDA UART Serial 3 004Ch A/D Conversion end 004Eh Reserved |
| H8/300H Operands |
R0..R6 32bit General Purpose ;\can be alternately used as R7 (SP) 32bit Stack Pointer ;/8bit/16bit registers (see below) PC 24bit Program Counter CCR 8bit Flags (occupies 16bit when pushed/stored in memory) |
.-----------------------.
| ERx | 32bit (ERx)
|-----------+-----------|
| Ex | Rx | 16bit (Rx)
'-----------+-----+-----|
' RxH | RxL | 8bit (RxB)
'-----'-----'
|
Normal Mode --> 16bit addressing (default) Extended Mode --> 24bit addressing |
Native Nocash @aa:8 [FFaa] Memory at FF00h..FFFFh (upper RAM and SFR's) @aa:16 [nnnn] @aa:24 [nnnnnn] @Erm [Erm] @(d:16,ERm) [ERm+nnnn] @(d:24,ERm) [ERm+nnnnnn] @ERm+ [ERm+] Memory access with post-increment @-ERm [ERm-] Memory access with pre-decrement (implied) [ER6+],[ER5+] Memory block transfer (EEPMOV) |
Native Nocash #nn:8,@aa:8 [FFaa].n RnB,@aa:8 [FFaa].RnB #nn:8,RdB RdB.n RnB,RdB RdB.RnB |
| H8/300H Opcodes |
0..7 8bit Registers R0H..R7H (bit8-15) ;\RxB 8..F 8bit Registers R0L..R7L (bit0-7) ;/ 0..7 16bit Registers R0..R7 (bit0-15) ;\Rx 8..F 16bit Registers E0..E7 (bit16-31) ;/ 0..7 32bit Registers ER0..ER7 (bit0-31) ;-ERx (in normal opcodes) 8..F 32bit Registers ER0..ER7 (bit0-31) ;-ERx (in opcodes marked *m,*s) |
Opcode Native Nocash States IxHUNZVC 0.. --> Misc 0xxx 1.. --> Misc 1xxx 2dnn MOV.B @aa:8,RdB MOV.B RdB,[FFaa] 4 ----nz0- 3snn MOV.B Rs,@aa:8 MOV.B [FFaa],Rs 4 ----nz0- 4cnn --> Jumps (relative 8bit range) 5.. --> Jumps (various) and unsigned mul/div 6.. --> Misx 6xxx 7.. --> Misc 7xxx 8dnn ADD.B #nn:8,RdB ADD.B RdB,nn 2 --h-nzvc 9dnn ADDX #nn:8,RdB ADC.B RdB,nn 2 --h-nzvc Adnn CMP.B #nn:8,RdB CMP.B RdB,nn 2 --h-nzvc Bdnn SUBX #nn:8,RdB SBC.B RdB,nn 2 --h-nzvc Cdnn OR.B #nn:8,RdB OR.B RdB,nn 2 ----nz0- Ddnn XOR.B #nn:8,RdB XOR.B RdB,nn 2 ----nz0- Ednn AND.B #nn:8,RdB AND.B RdB,nn 2 ----nz0- Fdnn MOV.B #nn:8,RdB MOV.B RdB,nn 2 ----nz0- |
0000 NOP NOP 2 -------- 01.. --> Misc 01xx ;Memory Load/Store (32bit ERn) etc. 020d STC.B CCR,RdB MOV.B RdB,CCR 2 -------- 030s LDC.B RsB,CCR MOV.B CCR,RsB 2 xxxxxxxx 04nn ORC #nn:8,CCR OR.B CCR,nn 2 xxxxxxxx 05nn XORC #nn:8,CCR XOR.B CCR,nn 2 xxxxxxxx 06nn ANDC #nn:8,CCR AND.B CCR,nn 2 xxxxxxxx 07nn LDC.B #nn:8,CCR MOV.B CCR,nn 2 xxxxxxxx 08sd ADD.B RsB,RdB ADD.B RdB,RsB 2 --h-nzvc 09sd ADD.W Rs,Rd ADD.W Rd,Rs 2 --h-nzvc 0A.. --> Increment/Add 0B.. --> Increment/Add 0Csd MOV.B RsB,RdB MOV.B RdB,RsB 2 ----nz0- 0Dsd MOV.W Rs,Rd MOV.W Rd,Rs 2 ----nz0- 0Esd ADDX RsB,RdB ADC.B RdB,RsB 2 --h-nzvc 0F0d DAA RdB DAA.B RdB 2 --U-nzUc 0Fsd *s MOV.L ERs,ERd MOV.L ERd,ERs 2 ----nz0- |
010069md MOV.L @ERm,ERd MOV.L ERd,[ERm] 8 ----nz0- 014069m0 LDC.W @ERm,CCR MOV.W CCR,[ERm] 6 xxxxxxxx 010069ms *m MOV.L ERs,@ERm MOV.L [ERm],ERs 8 ----nz0- 014069m0 *m STC.W CCR,@ERm MOV.W [ERm],CCR 6 -------- 01006B0dnnnn MOV.L @aa:16,ERd MOV.L ERd,[nnnn] 10 ----nz0- 01406B00nnnn LDC.W @aa:16,CCR MOV.W CCR,[nnnn] 8 xxxxxxxx 01006B2d00nnnnnn MOV.L @aa:24,ERd MOV.L ERd,[nnnnnn] 12 ----nz0- 01406B2000nnnnnn LDC.W @aa:24,CCR MOV.W CCR,[nnnnnn] 10 xxxxxxxx 01006B8snnnn MOV.L ERs,@aa:16 MOV.L [nnnn],ERs 10 ----nz0- 01406B80nnnn STC.W CCR,@aa:16 MOV.W [nnnn],CCR 8 -------- 01006BAs00nnnnnn MOV.L ERs,@aa:24 MOV.L [nnnnnn],ERs 12 ----nz0- 01406BA000nnnnnn STC.W CCR,@aa:24 MOV.W [nnnnnn],CCR 10 -------- 01006Dmd MOV.L @ERm+,ERd MOV.L ERd,[ERm+] 10 ----nz0- 01406Dm0 LDC.W @ERm+,CCR MOV.W CCR,[ERm+] 8 xxxxxxxx 01006Dms *m MOV.L ERs,@-ERm MOV.L [ERm-],ERs 10 ----nz0- 01406Dm0 *m STC.W CCR,@-ERm MOV.W [ERm-],CCR 8 -------- 01006Fmdnnnn MOV.L @(d:16,ERm),ERd MOV.L ERd,[ERm+nnnn] 10 ----nz0- 01406Fm0nnnn LDC.W @(d:16,ERm),CCR MOV.W CCR,[ERm+nnnn] 8 xxxxxxxx 01006Fmsnnnn *m MOV.L ERs,@(d:16,ERm) MOV.L [ERm+nnnn],ERs 10 ----nz0- 01406Fm0nnnn *m STC.W CCR,@(d:16,ERm) MOV.W [ERm+nnnn],CCR 8 -------- 010078m06B2d00.. MOV.L @(d:24,ERm),ERd MOV.L ERd,[ERm+nnnnnn] 14 ----nz0- 014078m06B2000.. LDC.W @(d:24,ERm),CCR MOV.W CCR,[ERm+nnnnnn] 12 xxxxxxxx 010078m06BAs00..*? MOV.L ERs,@(d:24,ERm) MOV.L [ERm+nnnnnn],ERs 14 ----nz0- 014078m06BA000.. STC.W CCR,@(d:24,ERm) MOV.W [ERm+nnnnnn],CCR 12 -------- 0180 SLEEP HALT 2 -------- 01C050sd MULXS.B RsB,Rd SMUL.B Rd,RsB 16 ----nz-- 01C052sd MULXS.W Rs,ERd SMUL.W ERd,Rs 24 ----nz-- 01D051sd DIVXS.B RsB,Rd SDIV.B Rd,RsB 16 ----nz-- 01D053sd DIVXS.W Rs,ERd SDIV.W ERd,Rs 24 ----nz-- 01F064sd OR.L ERs,ERd OR.L ERd,ERs 4 ----nz0- 01F065sd XOR.L ERs,ERd XOR.L ERd,ERs 4 ----nz0- 01F066sd AND.L E?Rs,ERd AND.L ERd,ERs 4 ----nz0- |
10.. --> Shift/Rotate (shift left) 11.. --> Shift/Rotate (shift right) 12.. --> Shift/Rotate (rotate left) 13.. --> Shift/Rotate (rotate right) 14sd OR.B RsB,RdB OR.B RdB,RsB 2 ----nz0- 15sd XOR.B RsB,RdB XOR.B RdB,RsB 2 ----nz0- 16sd AND.B RsB,RdB AND.B RdB,RsB 2 ----nz0- 17.. --> Not/Neg/Extend 18sd SUB.B RsB,RdB SUB.B RdB,RsB 2 --h-nzvc 19sd SUB.W Rs,Rd SUB.W Rd,Rs 2 --h-nzvc 1A.. --> Decrement/Subtract 1B.. --> Decrement/Subtract 1Csd CMP.B RsB,RdB CMP.B RdB,RsB 2 --h-nzvc 1Dsd CMP.W Rs,Rd CMP.W Rd,Rs 2 --h-nzvc 1Esd SUBX RsB,RdB SBC.B RdB,RsB 2 --h-nzvc 1F0d DAS RdB DAS.B RdB 2 --U-nzU? 1Fsd *s CMP.L ERs,ERd CMP.L ERd,ERs 2 --h-nzvc |
100d SHLL.B RdB SHL.B RdB 2 ----nz0c 101d SHLL.W Rd SHL.W Rd 2 ----nz0c 103d SHLL.L ERd SHL.L ERd 2 ----nz0c 108d SHAL.B RdB SAL.B RdB 2 ----nzvc 109d SHAL.W Rd SAL.W Rd 2 ----nzvc 10Bd SHAL.L ERd SAL.L ERd 2 ----nzvc 110d SHLR.B RdB SHR.B RdB 2 ----0z0c 111d SHLR.W Rd SHR.W Rd 2 ----0z0c 113d SHLR.L ERd SHR.L ERd 2 ----0z0c 118d SHAR.B RdB SAR.B RdB 2 ----nz0c 119d SHAR.W Rd SAR.W Rd 2 ----nz0c 11Bd SHAR.L ERd SAR.L ERd 2 ----nz0c 120d ROTXL.B RdB RCL.B RdB 2 ----nz0c 121d ROTXL.W Rd RCL.W Rd 2 ----nz0c 123d ROTXL.L ERd RCL.L ERd 2 ----nz0c 128d ROTL.B RdB ROL.B RdB 2 ----nz0c 129d ROTL.W Rd ROL.W Rd 2 ----nz0c 12Bd ROTL.L ERd ROL.L ERd 2 ----nz0c 130d ROTXR.B RdB RCR.B RdB 2 ----nz0c 131d ROTXR.W Rd RCR.W Rd 2 ----nz0c 133d ROTXR.L ERd RCR.L ERd 2 ----nz0c 138d ROTR.B RdB ROR.B RdB 2 ----nz0c 139d ROTR.W Rd ROR.W Rd 2 ----nz0c 13Bd ROTR.L ERd ROR.L ERd 2 ----nz0c |
170d NOT.B RdB NOT.B RdB 2 ----nz0- 171d NOT.W Rd NOT.W Rd 2 ----nz0- 173d NOT.L Rd NOT.L ERd 2 ----nz0- 175d EXTU.W Rd UMOV Rd,RdL ;or Ed,EdL? 2 ----0z0- 177d EXTU.L ERd UMOV ERd,Rd 2 ----0z0- 178d NEG.B RdB NEG.B RdB 2 --h-nzvc 179d NEG.W Rd NEG.W Rd 2 --h-nzvc 17Bd NEG.L Rd NEG.L ERd 2 --h-nzvc 17Dd EXTS.W Rd SMOV Rd,RdL ;or Ed,EdL? 2 ----nz0- 17Fd EXTS.L ERd SMOV ERd,Rd 2 ----nz0- |
0A0d INC.B RdB INC.B RdB,1 2 ----nzv- 1A0d DEC.B RdB DEC.B RdB,1 2 ----nzv- 0Asd *s ADD.L E?Rs,ERd ADD.L ERd,ERs 2 --h-nzvc 1Asd *s SUB.L ERs,ERd SUB.L ERd,ERs 2 --h-nzvc 0B0d ADDS #1,ERd INC.S ERd,1 2 -------- 1B0d SUBS #1,ERd DEC.S ERd,1 2 -------- 0B5d INC.W #1,Rd INC.W Rd,1 2 ----nzv- 1B5d DEC.W #1,Rd DEC.W Rd,1 2 ----nzv- 0B7d INC.L #1,ERd INC.L ERd,1 2 ----nzv- 1B7d DEC.L #1,ERd DEC.L ERd,1 2 ----nzv- 0B8d ADDS #2,ERd INC.S ERd,2 2 -------- 1B8d SUBS #2,ERd DEC.S ERd,2 2 -------- 0B9d ADDS #4,ERd INC.S ERd,4 2 -------- 1B9d SUBS #4,ERd DEC.S ERd,4 2 -------- 0BDd INC.W #2,Rd INC.W Rd,2 2 ----nzv- 1BDd DEC.W #2,Rd DEC.W Rd,2 2 ----nzv- 0BFd INC.L #2,ERd INC.L ERd,2 2 ----nzv- 1BFd DEC.L #2,ERd DEC.L ERd,2 2 ----nzv- |
50sd MULXU.B RsB,Rd UMUL.B Rd,RsB 14 ----nz-- 51sd DIVXU.B RsB,Rd UDIV.B Rd,RsB 14 ----nz-- 52sd MULXU.W Rs,ERd UMUL.W ERd,Rs 22 ----nz-- 53sd DIVXU.W Rs,ERd UDIV.W ERd,Rs 22 ----nz-- 5470 RTS RET 8,10 -------- 55nn BSR d:8 CALL $+/-nn 6,8 -------- 5670 RTE RETI 10 xxxxxxxx 57n0 TRAPA #n:2 TRAP 0..3 ;[0010h+n*2] 14 1x------ 58c0nnnn --> Jumps (relative 16bit range) 59s0 JMP @ERs JMP ERs 4 -------- 5Annnnnn JMP @aa:24 JMP nnnnnn 6 -------- 5Baa JMP @@aa:8 JMP [FFaa] 8,10 -------- 5C00nnnn BSR d:16 CALL $+/-nnnn 8,10 -------- 5Ds0 JSR @ERs CALL ERs 6,8 -------- 5Ennnnnn JSR @aa:24 CALL nnnnnn 8,10 -------- 5Faa JSR @@aa:8 CALL [FFaa] 8,12 -------- |
4cnn Bcc d:8 Jcc $+/-nn 4 -------- 58c0nnnn Bcc d:16 Jcc $+/-nnnn 6 -------- |
0 BRA or BT JMP ;always/true 1 BRN or BF - ;never/false 2 BHI JA ;unsigned-above 3 BLS JBE ;unsigned-below-equal 4 BCC or BHS JNC or JAE ;unsigned-above-equal 5 BCS or BLO JC or JB ;unsigned-below 6 BNE JNZ or JNE ;not equal/zero 7 BEQ JZ or JE ;equal/zero 8 BVC JNO ;signed-no overflow 9 BVS JO ;signed-n-overflow A BPL JNS ;signed-n-plus B BMI JS ;signed-n-minus C BGE JGE ;signed-n-greater-eq D BLT JL ;signed-n-less E BGT JG ;signed-n-greater F BLE JLE ;signed-n-less-equal |
60nd BSET RnB,RdB SET RdB.RnB 2 --------
61nd BNOT RnB,RdB NOT RdB.RnB 2 --------
62nd BCLR RnB,RdB CLR RdB.RnB 2 --------
63nd BTST RnB,RdB TST RdB.RnB 2 -----z--
64sd OR.W Rs,Rd OR.W Rd,Rs 2 ----nz0-
65sd XOR.W Rs,Rd XOR.W Rd,Rs 2 ----nz0-
66sd AND.W Rs,Rd AND.W Rd,Rs 2 ----nz0-
67nd *i B{I}ST #nn:8,RdB MOV RdB.n,{not} C 2 --------
68md MOV.B @ERm,RdB MOV.B RdB,[ERm] 4 ----nz0-
68ms *m MOV.B RsB,@ERm MOV.B [ERm],RsB 4 ----nz0-
69md MOV.W @ERm,Rd MOV.W Rd,[ERm] 4 ----nz0-
69ms *m MOV.W Rs,@ERm MOV.W [ERm],Rs 4 ----nz0-
6A0dnnnn MOV.B @aa:16,RdB MOV.B RdB,[aaaa] 6 ----nz0-
6A2d00nnnnnn MOV.B @aa:24,RdB MOV.B RdB,[aaaaaa] 8 ----nz0-
6A4dnnnn MOVFPE @aa:16,RdB MOV.B RdB,[periph:aaaa] * ----nz0-
6A8snnnn MOV.B RsB,@aa:16 MOV.B [aaaa],RsB 6 ----nz0-
6AAs00nnnnnn MOV.B RsB,@aa:24 MOV.B [aaaaaa],RsB 8 ----nz0-
6ACsnnnn MOVTPE RsB,@aa:16 MOV.B [periph:aaaa],RsB * ----nz0-
6B0dnnnn MOV.W @aa:16,Rd MOV.W Rd,[aaaa] 6 ----nz0-
6B2d00nnnnnn MOV.W @aa:24,Rd MOV.W Rd,[aaaaaa] 8 ----nz0-
6B8snnnn MOV.W Rs,@aa:16 MOV.W [aaaa],Rs 6 ----nz0-
6BAs00nnnnnn MOV.W Rs,@aa:24 MOV.W [aaaaaa],Rs 8 ----nz0-
6Cmd MOV.B @ERm+,RdB MOV.B RdB,[ERm+] 6 ----nz0-
6Cms *m MOV.B RsB,@-ERm MOV.B [ERm-],RsB 6 ----nz0-
6Dmd MOV.W @ERm+,RdB MOV.W RdB,[ERm+] 6 ----nz0-
6Dms *m MOV.W RsB,@-ERm MOV.W [ERm-],RsB 6 ----nz0-
6Emdnnnn MOV.B @(d:16,ERm),RdB MOV.B RdB,[ERm+nnnn] 6 ----nz0-
6Emsnnnn *m MOV.B RsB,@(d:16,ERm) MOV.B [ERm+nnnn],RsB 6 ----nz0-
6Fmdnnnn MOV.W @(d:16,ERm),Rd MOV.W Rd,[ERm+nnnn] 6 ----nz0-
6Fmsnnnn *m MOV.W Rs,@(d:16,ERm) MOV.W [ERm+nnnn],Rs 6 ----nz0-
|
70nd BSET #nn:8,RdB SET RdB.n 2 --------
71nd BNOT #nn:8,RdB NOT RdB.n 2 --------
72nd BCLR #nn:8,RdB CLR RdB.n 2 --------
73nd BTST #nn:8,RdB TST RdB.n 2 -----z--
74nd *i B{I}OR #nn:8,RdB OR C,{not} RdB.n 2 -------c
75nd *i B{I}XOR #nn:8,RdB XOR C,{not} RdB.n 2 -------c
76nd *i B{I}AND #nn:8,RdB AND C,{not} RdB.n 2 -------c
77nd *i B{I}LD #nn:8,RdB MOV C,{not} RdB.n 2 -------c
78m06A2d00nnnnnn MOV.B @(d:24,ERm),RdB MOV.B RdB,[ERm+nnnnnn] 10 ----nz0-
78m06AAs00nnnnnn MOV.B RsB,@(d:24,ERm) MOV.B [ERm+nnnnnn],RsB 10 ----nz0-
78m06B2d00nnnnnn MOV.W @(d:24,ERm),Rd MOV.W Rd,[ERm+nnnnnn] 10 ----nz0-
78m06BAs00nnnnnn*? MOV.W Rs,@(d:24,ERm) MOV.W [ERm+nnnnnn],Rs 10 ----nz0-
79.. --> Immediate (16bit)
7A.. --> Immediate (32bit)
7B5C498F EEPMOV.B MOV [ER6+],[ER5+],R4L- 8+4n --------
7BD4598F EEPMOV.W MOV [ER6+],[ER5+],R4- 8+4n --------
7C.. --> Bit Operations (Memory at ERm)
7D.. --> Bit Operations (Memory at ERm)
7E.. --> Bit Operations (Memory at FFaa)
7F.. --> Bit Operations (Memory at FFaa)
|
790dnnnn MOV.W #nnnn:16,Rd MOV.W Rd,nnnn 4 ----nz0- 791dnnnn ADD.W #nnnn:16,Rd ADD.W Rd,nnnn 4 --h-nzvc 792dnnnn CMP.W #nnnn:16,Rd CMP.W Rd,nnnn 4 --h-nzvc 793dnnnn SUB.W #nnnn:16,Rd SUB.W Rd,nnnn 4 --h-nzvc 794dnnnn OR.W #nnnn:16,Rd OR.W Rd,nnnn 4 ----nz0- 795dnnnn XOR.W #nnnn:16,Rd XOR.W Rd,nnnn 4 ----nz0- 796dnnnn AND.W #nnnn:16,Rd AND.W Rd,nnnn 4 ----nz0- 7A0dnnnnnnnn MOV.L #nnnnnnnn:32,E?Rd MOV.L E?Rd,nnnnnnnn 6 ----nz0- 7A1dnnnnnnnn ADD.L #nnnnnnnn:32,ERd ADD.L ERd,nnnnnnnn 6 --h-nzvc 7A2dnnnnnnnn CMP.L #nnnnnnnn:32,ERd CMP.L ERd,nnnnnnnn 6 --h-nzvc 7A3dnnnnnnnn SUB.L #nnnnnnnn:32,ERd SUB.L ERd,nnnnnnnn 6 --h-nzvc 7A4dnnnnnnnn OR.L #nnnnnnnn:32,ERd OR.L ERd,nnnnnnnn 6 ----nz0- 7A5dnnnnnnnn XOR.L #nnnnnnnn:32,ERd XOR.L ERd,nnnnnnnn 6 ----nz0- 7A6dnnnnnnnn AND.L #nnnnnnnn:32,ERd AND.L ERd,nnnnnnnn 6 ----nz0- |
7Cm074n0 *i B{I}OR #nn:8,@ERm OR C,{not} [ERm].n 6 -------c
7Cm075n0 *i B{I}XOR #nn:8,@ERm XOR C,{not} [ERm].n 6 -------c
7Cm076n0 *i B{I}AND #nn:8,@ERm AND C,{not} [ERm].n 6 -------c
7Cm077n0 *i B{I}LD #nn:8,@ERm MOV C,{not} [ERm].n 6 -------c
7Dm060n0 BSET RnB,@ERm SET [ERm].RnB 8 --------
7Dm061n0 BNOT RnB,@ERm NOT [ERm].RnB 8 --------
7Dm062n0 BCLR RnB,@ERm CLR [ERm].RnB 8 --------
7Dm063n0 BTST RnB,@ERm TST [ERm].RnB 8 -----z--
7Dm067n0 *i B{I}ST #nn:8,@ERm MOV [ERm].n,{not} C 8 --------
7Dm070n0 BSET #nn:8,@ERm SET [ERm].n 8 --------
7Dm071n0 BNOT #nn:8,@ERm NOT [ERm].n 8 --------
7Dm072n0 BCLR #nn:8,@ERm CLR [ERm].n 8 --------
7Dm073n0 BTST #nn:8,@ERm TST [ERm].n 8 -----z--
7Eaa74n0 *i B{I}OR #nn:8,@aa:8 OR C,{not} [FFaa].n 6 -------c
7Eaa75n0 *i B{I}XOR #nn:8,@aa:8 XOR C,{not} [FFaa].n 6 -------c
7Eaa76n0 *i B{I}AND #nn:8,@aa:8 AND C,{not} [FFaa].n 6 -------c
7Eaa77n0 *i B{I}LD #nn:8,@aa:8 MOV C,{not} [FFaa].n 6 -------c
7Faa60n0 BSET RnB,@aa:8 SET [FFaa].RnB 8 --------
7Faa61n0 BNOT RnB,@aa:8 NOT [FFaa].RnB 8 --------
7Faa62n0 BCLR RnB,@aa:8 CLR [FFaa].RnB 8 --------
7Faa63n0 BTST RnB,@aa:8 TST [FFaa].RnB 8 -----z--
7Faa67n0 *i B{I}ST #nn:8,@aa:8 MOV [FFaa].n,{not} C 8 --------
7Faa70n0 BSET #nn:8,@aa:8 SET [FFaa].n 8 --------
7Faa71n0 BNOT #nn:8,@aa:8 NOT [FFaa].n 8 --------
7Faa72n0 BCLR #nn:8,@aa:8 CLR [FFaa].n 8 --------
7Faa73n0 BTST #nn:8,@aa:8 TST [FFaa].n 8 -----z--
|
*i optional inverted source operand (when setting bit3 in the "n" digit) *s must have bit3 set in "s" digit *m must have bit3 set in "m" digit *? must have bit3 set-or-not-set (has conflicting info in official specs) E?Rs meant to be ERs (although official specs omit the E in some cases) E?Rd meant to be ERd (although official specs omit the E in some cases) xxxS meant to be Silent, no flags affected (although specs say Sign Extend) xxxX meant to mean Carry, or meant to mean nothing specific in other cases |
6DFn PUSH.W Rn ;MOV.W [ER7-],Rn 6D7n POP.W Rn ;MOV.W Rn,[ER7+] 01006DFn PUSH.L ERn ;MOV.L [ER7-],ERn 01006D7n POP.L ERn ;MOV.L ERn,[ER7+] |
---N/A--- MOV.L @aa:8,ERd MOV.L ERd,[FFaa] - ----nz0- ---N/A--- MOV.L ERs,@aa:8 MOV.L [FFaa],ERs - ----nz0- ---N/A--- MOV.W @aa:8,Rd MOV.W Rd,[FFaa] - ----nz0- ---N/A--- MOV.W Rs,@aa:8 MOV.W [FFaa],Rs - ----nz0- ---N/A--- SUB.B #nn:8,RdB SUB.B RdB,nn - --h-nzvc |
| DS Cart Unknown Extras |
typical Macronix ROM STMicroelectronics M25PE10 SPI FLASH memory, presumably 128K Broadcom BCM2070 Bluetooth controller 26MHz crystal oscillator |
NTR-UNSJ Japanese TV Tuner, with TV receiver NTR-UBRP Nintendo DS Brower, with RAM cart in GBA slot NTR-UAMA DS Vision Starter Kit, with microSD NTR-UEIJ Starry Sky Navigation, with azimuth NTR/TWL-Uxxx NAND carts (see NAND chapter) |
| DS Cart Cheat Action Replay DS |
ABCD-NNNNNNNN Game ID ;ASCII Gamecode [00Ch] and CRC32 across [0..1FFh] 00000000 XXXXXXXX manual hook codes (rarely used) (default is auto hook) 0XXXXXXX YYYYYYYY word[XXXXXXX+offset] = YYYYYYYY 1XXXXXXX 0000YYYY half[XXXXXXX+offset] = YYYY 2XXXXXXX 000000YY byte[XXXXXXX+offset] = YY 3XXXXXXX YYYYYYYY IF YYYYYYYY > word[XXXXXXX] ;unsigned ;\ 4XXXXXXX YYYYYYYY IF YYYYYYYY < word[XXXXXXX] ;unsigned ; for v1.54, 5XXXXXXX YYYYYYYY IF YYYYYYYY = word[XXXXXXX] ; when X=0, 6XXXXXXX YYYYYYYY IF YYYYYYYY <> word[XXXXXXX] ; uses 7XXXXXXX ZZZZYYYY IF YYYY > ((not ZZZZ) AND half[XXXXXXX]) ; [offset] 8XXXXXXX ZZZZYYYY IF YYYY < ((not ZZZZ) AND half[XXXXXXX]) ; instead of 9XXXXXXX ZZZZYYYY IF YYYY = ((not ZZZZ) AND half[XXXXXXX]) ; [XXXXXXX] AXXXXXXX ZZZZYYYY IF YYYY <> ((not ZZZZ) AND half[XXXXXXX]) ;/ BXXXXXXX 00000000 offset = word[XXXXXXX+offset] C0000000 YYYYYYYY FOR loopcount=0 to YYYYYYYY ;execute Y+1 times C4000000 00000000 offset = address of the C4000000 code ;v1.54 C5000000 XXXXYYYY counter=counter+1, IF (counter AND YYYY) = XXXX ;v1.54 C6000000 XXXXXXXX [XXXXXXXX]=offset ;v1.54 D0000000 00000000 ENDIF D1000000 00000000 NEXT loopcount D2000000 00000000 NEXT loopcount, and then FLUSH everything D3000000 XXXXXXXX offset = XXXXXXXX D4000000 XXXXXXXX datareg = datareg + XXXXXXXX D5000000 XXXXXXXX datareg = XXXXXXXX D6000000 XXXXXXXX word[XXXXXXXX+offset]=datareg, offset=offset+4 D7000000 XXXXXXXX half[XXXXXXXX+offset]=datareg, offset=offset+2 D8000000 XXXXXXXX byte[XXXXXXXX+offset]=datareg, offset=offset+1 D9000000 XXXXXXXX datareg = word[XXXXXXXX+offset] DA000000 XXXXXXXX datareg = half[XXXXXXXX+offset] DB000000 XXXXXXXX datareg = byte[XXXXXXXX+offset] ;bugged on pre-v1.54 DC000000 XXXXXXXX offset = offset + XXXXXXXX EXXXXXXX YYYYYYYY Copy YYYYYYYY parameter bytes to [XXXXXXXX+offset...] 44332211 88776655 parameter bytes 1..8 for above code (example) 0000AA99 00000000 parameter bytes 9..10 for above code (padded with 00s) FXXXXXXX YYYYYYYY Copy YYYYYYYY bytes from [offset..] to [XXXXXXX...] |
1st: Address used prior to launching game (eg. 23xxxxxh) 2nd: Address to write the hook at (inside the ARM7 executable) 3rd: Hook final address (huh?) 4th: Hook mode selection (0=auto, 1=mode1, 2=mode2) 5th: Opcode that replaces the hooked one (eg. E51DE004h) 6th: Address to store important stuff (default 23FE000h) 7th: Address to store the code handler (default 23FE074h) 8th: Address to store the code list (default 23FE564h) 9th: Must be 1 (00000001h) |
| DS Cart Cheat Codebreaker DS |
---Initialization--- 0000CR16 GAMECODE Specify Game ID, use Encrypted codes 8000CR16 GAMECODE Specify Game ID, use Unencrypted codes BEEFC0DE XXXXXXXX Change Encryption Keys A0XXXXXX YYYYYYYY Bootup-Hook 1, X=Address, Y=Value A8XXXXXX YYYYYYYY Bootup-Hook 2, X=Address, Y=Value F0XXXXXX TYYYYYYY Code-Hook 1 (T=Type,Y=CheatEngineAddr,X=HookAddr) F8XXXXXX TPPPPPPP Code-Hook 2 (T=Type,X=CheatEngineHookAddr,P=Params) ---General codes--- 00XXXXXX 000000YY [X]=YY 10XXXXXX 0000YYYY [X]=YYYY 20XXXXXX YYYYYYYY [X]=YYYYYYYY 60XXXXXX 000000YY ZZZZZZZZ 00000000 [[X]+Z]=YY 60XXXXXX 0000YYYY ZZZZZZZZ 10000000 [[X]+Z]=YYYY 60XXXXXX YYYYYYYY ZZZZZZZZ 20000000 [[X]+Z]=YYYYYYYY 30XXXXXX 000000YY [X]=[X] + YY 30XXXXXX 0001YYYY [X]=[X] + YYYY 38XXXXXX YYYYYYYY [X]=[X] + YYYYYYYY 70XXXXXX 000000YY [X]=[X] OR YY 70XXXXXX 001000YY [X]=[X] AND YY 70XXXXXX 002000YY [X]=[X] XOR YY 70XXXXXX 0001YYYY [X]=[X] OR YYYY 70XXXXXX 0011YYYY [X]=[X] AND YYYY 70XXXXXX 0021YYYY [X]=[X] XOR YYYY ---Memory fill/copy--- 40XXXXXX 2NUMSTEP 000000YY 000000ZZ byte[X+(0..NUM-1)*STEP*1]=Y+(0..NUM-1)*Z 40XXXXXX 1NUMSTEP 0000YYYY 0000ZZZZ half[X+(0..NUM-1)*STEP*2]=Y+(0..NUM-1)*Z 40XXXXXX 0NUMSTEP YYYYYYYY ZZZZZZZZ word[X+(0..NUM-1)*STEP*4]=Y+(0..NUM-1)*Z 50XXXXXX YYYYYYYY ZZZZZZZZ 00000000 copy Y bytes from [X] to [Z] ---Conditional codes (bugged)--- 60XXXXXX 000000YY ZZZZZZZZ 01c100VV IF [[X]+Z] .. VV THEN [[X]+Z]=YY 60XXXXXX 000000YY ZZZZZZZZ 01c0VVVV IF [[X]+Z] .. VVVV THEN [[X]+Z]=YY 60XXXXXX 0000YYYY ZZZZZZZZ 11c100VV IF [[X]+Z] .. VV THEN [[X]+Z]=YYYY 60XXXXXX 0000YYYY ZZZZZZZZ 11c0VVVV IF [[X]+Z] .. VVVV THEN [[X]+Z]=YYYY 60XXXXXX YYYYYYYY ZZZZZZZZ 21c100VV IF [[X]+Z] .. VV THEN [[X]+Z]=YYYYYYYY 60XXXXXX YYYYYYYY ZZZZZZZZ 21c0VVVV IF [[X]+Z] .. VVVV THEN [[X]+Z]=YYYYYYYY ---Conditional codes (working)--- D0XXXXXX NNc100YY IF [X] .. YY THEN exec max(1,NN) lines D0XXXXXX NNc0YYYY IF [X] .. YYYY THEN exec max(1,NN) lines |
0 IF [mem] = imm THEN ... 4 IF ([mem] AND imm) = 0 THEN ... 1 IF [mem] <> imm THEN ... 5 IF ([mem] AND imm) <> 0 THEN ... 2 IF [mem] < imm THEN ... (unsigned) 6 IF ([mem] AND imm) = imm THEN ... 3 IF [mem] > imm THEN ... (unsigned) 7 IF ([mem] AND imm) <> imm THEN ... |
GAMECODE Cartridge Header[00Ch] (32bit in reversed byte-order) CR16 Cartridge Header[15Eh] (16bit in normal byte-order) XXXXXX 27bit addr (actually 7 digits, XXXXXXX, overlaps 5bit code number) |
for i=4Fh to 00h
y=77628ECFh
if i>13h then y=59E5DC8Ah
if i>27h then y=054A7818h
if i>3Bh then y=B1BF0855h
address = (Key0-value) xor address
value = value - Key1 - (address ror 1Bh)
address = (address xor (value + y)) ror 13h
if (i>13h) then
if (i<=27h) or (i>3Bh) then x=Key2 xor Key1 xor Key0
else x=((Key2 xor Key1) and Key0) xor (Key1 and Key2)
value=value xor (x+y+address)
x = Secure[((i*4+00h) and FCh)+000h]
x = Secure[((i*4+34h) and FCh)+100h] xor x
x = Secure[((i*4+20h) and FCh)+200h] xor x
x = Secure[((i*4+08h) and FCh)+300h] xor x
address = address - (x ror 19h)
next i
|
Secure[0..7FFh] = Copy of the ENCRYPTED 1st 2Kbytes of the game's Secure Area Key0 = 0C2EAB3Eh, Key1 = E2AE295Dh, Key2 = E1ACC3FFh, Key3 = 70D3AF46h scramble_keys |
Key0 = Key0 + (XXXXXXXX ror 1Dh) Key1 = Key1 - (XXXXXXXX ror 05h) Key2 = Key2 xor (Key3 xor Key0) Key3 = Key3 xor (Key2 - Key1) scramble_keys |
for i=0 to FFh
y = byte(xlat_table[i])
Secure[i*4+000h] = (Secure[i*4+000h] xor Secure[y*4]) + Secure[y*4+100h]
Secure[i*4+400h] = (Secure[i*4+400h] xor Secure[y*4]) - Secure[y*4+200h]
next i
for i=0 to 63h
Key0 = Key0 xor (Secure[i*4] + Secure[i*4+190h])
Key1 = Key1 xor (Secure[i*4] + Secure[i*4+320h])
Key2 = Key2 xor (Secure[i*4] + Secure[i*4+4B0h])
Key3 = Key3 xor (Secure[i*4] + Secure[i*4+640h])
next i
Key0 = Key0 - Secure[7D0h]
Key1 = Key1 xor Secure[7E0h]
Key2 = Key2 + Secure[7F0h]
Key3 = Key3 xor Secure[7D0h] xor Secure[7F0h]
|
34h,59h,00h,32h,7Bh,D3h,32h,C9h,9Bh,77h,75h,44h,E0h,73h,46h,06h 0Bh,88h,B3h,3Eh,ACh,F2h,BAh,FBh,2Bh,56h,FEh,7Ah,90h,F7h,8Dh,BCh 8Bh,86h,9Ch,89h,00h,19h,CDh,4Ch,54h,30h,01h,93h,30h,01h,FCh,36h 4Dh,9Fh,FDh,D7h,32h,94h,AEh,BCh,2Bh,61h,DFh,B3h,44h,EAh,8Bh,A3h 2Bh,53h,33h,54h,42h,27h,21h,DFh,A9h,DDh,C0h,35h,58h,EFh,8Bh,33h B4h,D3h,1Bh,C7h,93h,AEh,32h,30h,F1h,CDh,A8h,8Ah,47h,8Ch,70h,0Ch 17h,4Eh,0Eh,A2h,85h,0Dh,6Eh,37h,4Ch,39h,1Fh,44h,98h,26h,D8h,A1h B6h,54h,F3h,AFh,98h,83h,74h,0Eh,13h,6Eh,F4h,F7h,86h,80h,ECh,8Eh EEh,4Ah,05h,A1h,F1h,EAh,B4h,D6h,B8h,65h,8Ah,39h,B3h,59h,11h,20h B6h,BBh,4Dh,88h,68h,24h,12h,9Bh,59h,38h,06h,FAh,15h,1Dh,40h,F0h 01h,77h,57h,F5h,5Dh,76h,E5h,F1h,51h,7Dh,B4h,FAh,7Eh,D6h,32h,4Fh 0Eh,C8h,61h,C1h,EEh,FBh,2Ah,FCh,ABh,EAh,97h,D5h,5Dh,E8h,FAh,2Ch 06h,CCh,86h,D2h,8Ch,10h,D7h,4Ah,CEh,8Fh,EBh,03h,16h,ADh,84h,98h F5h,88h,2Ah,18h,ACh,7Fh,F6h,94h,FBh,3Fh,00h,B6h,32h,A2h,ABh,28h 64h,5Ch,0Fh,C6h,23h,12h,0Ch,D2h,BAh,4Dh,A3h,F2h,C9h,86h,31h,57h 0Eh,F8h,ECh,E1h,A0h,9Ah,3Ch,65h,17h,18h,A0h,81h,D0h,DBh,D5h,AEh |
| DS Cart DLDI Driver |
00h 4 DLDI ID (EDh,A5h,8Dh,BFh) (aka BF8DA5EDh) ;\patching tools will
04h 8 DLDI String (20h,"Chishm",00h) ; refuse any other
0Ch 1 DLDI Version (01h in .dldi, don't care in .nds) ;/values
0Dh 1 Size of .dldi+BSS (rounded up to 1 SHL N bytes) (max 0Fh=32Kbytes)
0Eh 1 Sections to fix/destroy (see FIX_xxx)
0Fh 1 Space in .nds file (1 SHL N) (0Eh..0Fh in .nds, can be 0 in .dldi)
10h 48 ASCII Full Driver Name (max 47 chars, plus zero padding)
40h 4 Address of ALL start (text) ;-base address (BF800000h in .dldi)
44h 4 Address of ALL end (data) ;-for highly-unstable FIX_ALL addr.adjusts
48h 4 Address of GLUE start ;\for semi-stable FIX_GLUE addr.adjusts
4Ch 4 Address of GLUE end ;/ ("Interworking glue" for ARM-vs-THUMB)
50h 4 Address of GOT start ;\for semi-stable FIX_GOT addr.adjusts
54h 4 Address of GOT end ;/ ("Global Offset Table")
58h 4 Address of BSS start ;\for zerofilling "BSS" via FIX_BSS
5Ch 4 Address of BSS end ;/ ("Block Started by Symbol")
60h 4 ASCII Short Driver/Device Name (4 chars, eg. "MYHW" for MyHardware)
64h 4 Flags 2 (see FEATURE_xxx) (usually 13h=GbaSlot, or 23h=NdsSlot)
68h 4 Address of Function startup() ;<-- must be at offset +80h !! ;\
6Ch 4 Address of Function isInserted() ;out: 0=no/fail, 1=yes/okay ; all
70h 4 Address of Function readSectors(sector,numSectors,buf) ; return
74h 4 Address of Function writeSectors(sector,numSectors,buf) ; 0=fail,
78h 4 Address of Function clearStatus() ; 1=okay
7Ch 4 Address of Function shutdown() ;/
80h .. Driver Code (can/must begin with "startup()") ;\max 7F80h
.. .. Glue section (usually a small snippet within above code) ; bytes (when
.. .. GOT section (usually after above code) (pointer table) ; having 32K
.. .. BSS section (usually at end, may exceed .dldi filesize) ; allocated)
.. .. Optional two garbage NOPs at end of default.dldi ;/
|
0 FIX_ALL ;-installer uses highly-unstable guessing in whole dldi file 1 FIX_GLUE ;-installer uses semi-stable address guessing in GLUE area 2 FIX_GOT ;-installer uses semi-stable address guessing in GOT area 3 FIX_BSS ;-installer will zerofill BSS area 4-7 Reserved (0) |
0 FEATURE_MEDIUM_CANREAD 00000001h (usually set) 1 FEATURE_MEDIUM_CANWRITE 00000002h (a few carts can't write) 2-3 Reserved (0) 4 FEATURE_SLOT_GBA 00000010h (need EXMEMCNT bit7 adjusted) 5 FEATURE_SLOT_NDS 00000020h (need EXMEMCNT bit11 adjusted) 6-31 Reserved (0) |
dldi area should be located at a 40h-byte aligned address in ROM image. dldi area should be located in ARM9 (or ARM7) bootcode area. |
dldi[00h..0Bh] must contain DLDI ID word/string dldi[0Fh] must contain allocated size (0Eh=16Kbyte or 0Fh=32Kbyte) dldi[40h..43h] must contain RAM base address of DLDI block and other entries should contain valid dummy strings and dummy functions. |
dldi[0Fh] must be kept as in the old .nds file (not as in .dldi file) |
| DS Cart DLDI Driver - Guessed Address-Adjustments |
| DS Encryption by Gamecode/Idcode (KEY1) |
NDS.ARM7 ROM: 00000030h..00001077h (values 99 D5 20 5F ..) Blowfish/NDS-mode DSi.ARM9 ROM: FFFF99A0h..FFFFA9E7h (values 99 D5 20 5F ..) "" DSi.TCM Copy: 01FFC894h..01FFD8DBh (values 99 D5 20 5F ..) "" DSi.ARM7 ROM: 0000C6D0h..0000D717h (values 59 AA 56 8E ..) Blowfish/DSi-mode DSi.RAM Copy: 03FFC654h..03FFD69Bh (values 59 AA 56 8E ..) "" DSi.Debug: (stored in launcher) (values 69 63 52 05 ..) Blowfish/DSi-debug |
Y=[ptr+0]
X=[ptr+4]
FOR I=0 TO 0Fh (encrypt), or FOR I=11h TO 02h (decrypt)
Z=[keybuf+I*4] XOR X
X=[keybuf+048h+((Z SHR 24) AND FFh)*4]
X=[keybuf+448h+((Z SHR 16) AND FFh)*4] + X
X=[keybuf+848h+((Z SHR 8) AND FFh)*4] XOR X
X=[keybuf+C48h+((Z SHR 0) AND FFh)*4] + X
X=Y XOR X
Y=Z
NEXT I
[ptr+0]=X XOR [keybuf+40h] (encrypt), or [ptr+0]=X XOR [keybuf+4h] (decrypt)
[ptr+4]=Y XOR [keybuf+44h] (encrypt), or [ptr+4]=Y XOR [keybuf+0h] (decrypt)
|
encrypt_64bit(keycode+4)
encrypt_64bit(keycode+0)
[scratch]=0000000000000000h ;S=0 (64bit)
FOR I=0 TO 44h STEP 4 ;xor with reversed byte-order (bswap)
[keybuf+I]=[keybuf+I] XOR bswap_32bit([keycode+(I MOD modulo)])
NEXT I
FOR I=0 TO 1040h STEP 8
encrypt_64bit(scratch) ;encrypt S (64bit) by keybuf
[keybuf+I+0]=[scratch+4] ;write S to keybuf (first upper 32bit)
[keybuf+I+4]=[scratch+0] ;write S to keybuf (then lower 32bit)
NEXT I
|
if key=nds then copy [nds_arm7bios+0030h..1077h] to [keybuf+0..1047h] if key=dsi then copy [dsi_arm7bios+C6D0h..D717h] to [keybuf+0..1047h] [keycode+0]=[idcode] [keycode+4]=[idcode]/2 [keycode+8]=[idcode]*2 IF level>=1 THEN apply_keycode(modulo) ;first apply (always) IF level>=2 THEN apply_keycode(modulo) ;second apply (optional) [keycode+4]=[keycode+4]*2 [keycode+8]=[keycode+8]/2 IF level>=3 THEN apply_keycode(modulo) ;third apply (optional) |
init_keycode(firmware_header+08h,1,0Ch,nds) ;idcode (usually "MACP"), level 1 decrypt_64bit(firmware_header+18h) ;rominfo init_keycode(firmware_header+08h,2,0Ch,nds) ;idcode (usually "MACP"), level 2 decrypt ARM9 and ARM7 bootcode by decrypt_64bit (each 8 bytes) decompress ARM9 and ARM7 bootcode by LZ77 function (swi) calc CRC16 on decrypted/decompressed ARM9 bootcode followed by ARM7 bootcode |
init_keycode(cart_header+0Ch,1,08h,nds) ;gamecode, level 1, modulo 8 decrypt_64bit(cart_header+78h) ;rominfo (secure area disable) init_keycode(cart_header+0Ch,2,08h,nds) ;gamecode, level 2, modulo 8 encrypt_64bit all NDS KEY1 commands (1st command byte in MSB of 64bit value) after loading the secure_area, calculate secure_area crc, then decrypt_64bit(secure_area+0) ;first 8 bytes of secure area init_keycode(cart_header+0Ch,3,08h,nds) ;gamecode, level 3, modulo 8 decrypt_64bit(secure_area+0..7F8h) ;each 8 bytes in first 2K of secure init_keycode(cart_header+0Ch,1,08h,dsi) ;gamecode, level 1, modulo 8 encrypt_64bit all DSi KEY1 commands (1st command byte in MSB of 64bit value) |
| DS Encryption by Random Seed (KEY2) |
Seed0 = 58C56DE0E8h Seed1 = 5C879B9B05h |
Seed0 = (mmmnnn SHL 15)+6000h+Seedbyte Seed1 = 5C879B9B05h |
x = reversed_bit_order(seed0) ;ie. LSB(bit0) exchanged with MSB(bit38), etc. y = reversed_bit_order(seed1) |
x = (((x shr 5)xor(x shr 17)xor(x shr 18)xor(x shr 31)) and 0FFh)+(x shl 8) y = (((y shr 5)xor(y shr 23)xor(y shr 18)xor(y shr 31)) and 0FFh)+(y shl 8) data = (data xor x xor y) and 0FFh |
| DS Firmware Serial Flash Memory |
Chips used as wifi-flash: ID 20h,40h,12h - ST M45PE20 - 256 KBytes (Nintendo DS) (in my old DS) ID 20h,50h,12h - ST M35PE20 - 256 KBytes (Nintendo DS) (in my DS-Lite) ID 20h,80h,13h - ST M25PE40 - 512 KBytes (iQue DS, with chinese charset) ID 20h,40h,11h - ST 45PE10V6 - 128 Kbytes (Nintendo DSi) (in my DSi) ID 20h,58h,0Ch?- 5A32 - 4 Kbytes (Nintendo DSi, newer models) ID ? - 26FV032T - (Nintendo DSi, J27H020) (this has big package) ID ? - 5K32 - (3DS?) ID 62h,62h,0Ch - 32B, 3XH - 4 Kbytes (New3DS) Other similar chips (used in game cartridges): ID 20h,40h,13h - ST 45PE40V6 - 512 KBytes (DS Zelda, NTR-AZEP-0) ID 20h,40h,14h - ST 45PE80V6 - 1024 Kbytes (eg. Spirit Tracks, NTR-BKIP) +ID 62h,11h,00h - Sanyo ? - 512 Kbytes (P-Letter Diamond, ADAE) ID 62h,16h,00h - Sanyo LE25FW203T - 256 KBytes (Mariokart backup) +ID 62h,26h,11h - Sanyo ? - ? Kbytes (3DS: CTR-P-AXXJ) +ID 62h,26h,13h - Sanyo ? - ? Kbytes (3DS: CTR-P-APDJ) ID C2h,22h,11h - Macronix MX25L1021E? 128 Kbytes (eg. 3DS Starfox) ID C2h,22h,13h - Macronix ...? 512 Kbytes (eg. 3DS Kid Icarus, 3DS Sims 3) ID C2h,20h,17h - Macronix MX25L6445EZNI-10G 8192 Kbytes (DSi Art Academy) ID 01h,F0h,00h - Garbage/Infrared on SPI-bus? (eg. P-Letter White) ID 03h,F8h,00h - Garbage/Infrared on SPI-bus? (eg. P-Letter White 2) |
06h WREN Write Enable (No Parameters)
04h WRDI Write Disable (No Parameters)
9Fh RDID Read JEDEC Identification (Read 1..3 ID Bytes)
(Manufacturer, Device Type, Capacity)
05h RDSR Read Status Register (Read Status Register, endless repeated)
Bit7-2 Not used (zero)
Bit1 WEL Write Enable Latch (0=No, 1=Enable)
Bit0 WIP Write/Program/Erase in Progess (0=No, 1=Busy)
03h READ Read Data Bytes (Write 3-Byte-Address, read endless data stream)
0Bh FAST Read Data Bytes at Higher Speed (Write 3-Byte-Address, write 1
dummy-byte, read endless data stream) (max 25Mbit/s)
0Ah PW Page Write (Write 3-Byte-Address, write 1..256 data bytes)
(changing bits to 0 or 1) (reads unchanged data, erases the page,
then writes new & unchanged data) (11ms typ, 25ms max)
02h PP Page Program (Write 3-Byte-Address, write 1..256 data bytes)
(changing bits from 1 to 0) (1.2ms typ, 5ms max)
DBh PE Page Erase 100h bytes (Write 3-Byte-Address) (10ms typ, 20ms max)
D8h SE Sector Erase 10000h bytes (Write 3-Byte-Address) (1s typ, 5s max)
B9h DP Deep Power-down (No Parameters) (consumption 1uA typ, 10uA max)
(3us) (ignores all further instructions, except RDP)
ABh RDP Release from Deep Power-down (No Parameters) (30us)
|
Set Chip Select LOW to invoke the command Transmit the instruction byte Transmit any parameter bytes Transmit/receive any data bytes Set Chip Select HIGH to finish the command |
000000h..0002FFh Writeable only if /WP=HIGH (otherwise writes are ignored) 000300h..01F2FFh Not writeable (FFh-filled, writes are ignored) 01F300h..01FFFFh Writeable 020000h and up Mirrors of 0..01FFFFh (same read/write-ability as above) |
1 D Serial Data In (latched at rising clock edge) _________ 2 C Serial Clock (max 25MHz) /|o | 3 /RES Reset 1 -| | |- 8 4 /S Chip Select (instructions start at falling edge) 2 -| | |- 7 5 /W Write Protect (makes first 256 pages read-only) 3 -| |_________|- 6 6 VCC Supply (2.7V..3.6V typ) (4V max) (DS:VDD3.3) 4 -|/ |- 5 7 VSS Ground |___________| 8 Q Serial Data Out (changes at falling clock edge) |
1 /S Chip Select (instructions start at falling edge) ___________ 2 Q Serial Data Out (changes at falling clock edge) 1 -| o |- 8 3 /W Write Protect (makes first pages read-only) 2 -| |- 7 4 VSS Ground 3 -| |- 6 5 D Serial Data In (latched at rising clock edge) 4 -|___________|- 5 6 C Serial Clock 7 /RES Reset 8 VCC Supply (2.7V..3.6V typ) (DSi: VDD33) |
| DS Firmware Header |
00000h-00029h Firmware Header 0002Ah-001FFh Wifi Settings 00200h-3F9FFh Firmware Code/Data ;-NDS only (not DSi) 00200h-002FEh 00h-filled ;\ 002FFh 80h ; 00300h-1F2FFh FFh-filled (not write-able on 4K chips) ; DSi only (not NDS) 1F300h-1F3FEh FFh-filled (write-able) ; 1F3FFh Whatever Debug/Bootflags ; 1F400h-1F5FFh Wifi Access Point 4 ;\with WPA/WPA2 ; 1F600h-1F7FFh Wifi Access Point 5 ; support ; 1F800h-1F9FFh Wifi Access Point 6 ;/ ;/ 3FA00h-3FAFFh Wifi Access Point 1 ;\ 3FB00h-3FBFFh Wifi Access Point 2 ; Open/WEP only 3FC00h-3FCFFh Wifi Access Point 3 ;/ 3FD00h-3FDFFh Not used 3FE00h-3FEFFh User Settings Area 1 3FF00h-3FFFFh User Settings Area 2 |
Addr Size Expl.
000h 2 part3 romaddr/8 (arm9 gui code) (LZ/huffman compression)
002h 2 part4 romaddr/8 (arm7 wifi code) (LZ/huffman compression)
004h 2 part3/4 CRC16 arm9/7 gui/wifi code
006h 2 part1/2 CRC16 arm9/7 boot code
008h 4 firmware identifier (usually nintendo "MAC",nn) (or nocash "XBOO")
the 4th byte (nn) occassionally changes in different versions
00Ch 2 part1 arm9 boot code romaddr/2^(2+shift1) (LZSS compressed)
00Eh 2 part1 arm9 boot code 2800000h-ramaddr/2^(2+shift2)
010h 2 part2 arm7 boot code romaddr/2^(2+shift3) (LZSS compressed)
012h 2 part2 arm7 boot code 3810000h-ramaddr/2^(2+shift4)
014h 2 shift amounts, bit0-2=shift1, bit3-5=shift2, bit6-8=shift3,
bit9-11=shift4, bit12-15=firmware_chipsize/128K
016h 2 part5 data/gfx romaddr/8 (LZ/huffman compression)
018h 8 Optional KEY1-encrypted "enPngOFF"=Cartridge KEY2 Disable
(feature isn't used in any consoles, instead contains timestamp)
018h 5 Firmware version built timestamp (BCD minute,hour,day,month,year)
01Dh 1 Console type
FFh=Nintendo DS
20h=Nintendo DS-lite
57h=Nintendo DSi (also iQueDSi)
43h=iQueDS
63h=iQueDS-lite
The entry was unused (FFh) in older NDS, ie. replace FFh by 00h)
Bit0 seems to be DSi/iQue related
Bit1 seems to be DSi/iQue related
Bit2 seems to be DSi related
Bit3 zero
Bit4 seems to be DSi related
Bit5 seems to be DS-Lite related
Bit6 indicates presence of "extended" user settings (DSi/iQue)
Bit7 zero
01Eh 2 Unused (FFh-filled)
020h 2 User Settings Offset (div8) (usually last 200h flash bytes)
022h 2 Unknown (7EC0h or 0B51h)
024h 2 Unknown (7E40h or 0DB3h)
026h 2 part5 CRC16 data/gfx
028h 2 unused (FFh-filled)
02Ah-1FFh Wifi Calibration Data (see next chapter)
|
000h 1Dh Zerofilled (bootcode is in new eMMC chip, not on old FLASH chip) 01Dh 6 Same as on DS (header: Console Type and User Settings Offset) 022h 6 Zerofilled (bootcode is in new eMMC chip, not on old FLASH chip) 028h..1FCh Same as on DS (wifi calibration) 1FDh 1 Wifi Board (01h=DWM-W015, 02h=W024, 03h=W028) ;\this was 1FEh 1 Wifi Flash (20h=With access point 4/5/6) ; FFh-filled 1FFh 1 Same as on DS (FFh) ;/on DS 200h FFh Zerofilled ;\ 2FFh 1 Unknown (80h) ; this was 300h 1F000h FFh's (not write-able on 4K chips) ; bootcode 1F300h FFh FFh's (write-able) ;twl-debugger: 00h's ; on DS 1F3FFh 1 FFh ;twl-debugger: 40h ;/ |
| DS Firmware Wifi Calibration Data |
Addr Size Expl.
000h-029h Firmware Header (see previous chapter)
02Ah 2 CRC16 (with initial value 0) of [2Ch..2Ch+config_length-1]
02Ch 2 config_length (usually 0138h, ie. entries 2Ch..163h)
02Eh 1 Unused (00h)
02Fh 1 Version (0=v1..v4, 3=v5, 5=v6..v7,6=W006,15=W015,24=W024,34=N3DS)
030h 6 Unused (00h-filled) (DS-Lite and DSi: FF,FF,FF,FF,FF,00)
036h 6 48bit MAC address (v1-v5: 0009BFxxxxxx, v6-v7: 001656xxxxxx)
03Ch 2 list of enabled channels ANDed with 7FFE (Bit1..14 = Channel 1..14)
(usually 3FFEh, ie. only channel 1..13 enabled)
03Eh 2 Whatever Flags (usually FFFFh)
040h 1 RF Chip Type (NDS: usually 02h) (DS-Lite and DSi/3DS: usually 03h)
041h 1 RF Bits per entry at 0CEh (usually 18h=24bit=3byte) (Bit7=?)
042h 1 RF Number of entries at 0CEh (usually 0Ch)
043h 1 Unknown (usually 01h)
044h 2 Initial Value for [4808146h] ;W_CONFIG_146h
046h 2 Initial Value for [4808148h] ;W_CONFIG_148h
048h 2 Initial Value for [480814Ah] ;W_CONFIG_14Ah
04Ah 2 Initial Value for [480814Ch] ;W_CONFIG_14Ch
04Ch 2 Initial Value for [4808120h] ;W_CONFIG_120h
04Eh 2 Initial Value for [4808122h] ;W_CONFIG_122h
050h 2 Initial Value for [4808154h] ;W_CONFIG_154h
052h 2 Initial Value for [4808144h] ;W_CONFIG_144h
054h 2 Initial Value for [4808130h] ;W_CONFIG_130h
056h 2 Initial Value for [4808132h] ;W_CONFIG_132h
058h 2 Initial Value for [4808140h] ;W_CONFIG_140h ;maybe ACK timeout?
05Ah 2 Initial Value for [4808142h] ;W_CONFIG_142h
05Ch 2 Initial Value for [4808038h] ;W_POWER_TX
05Eh 2 Initial Value for [4808124h] ;W_CONFIG_124h
060h 2 Initial Value for [4808128h] ;W_CONFIG_128h
062h 2 Initial Value for [4808150h] ;W_CONFIG_150h
064h 69h Initial 8bit values for BB[0..68h]
0CDh 1 Unused (00h)
|
0CEh 24h Initial 24bit values for RF[0,4,5,6,7,8,9,0Ah,0Bh,1,2,3] 0F2h 54h Channel 1..14 2x24bit values for RF[5,6] 146h 0Eh Channel 1..14 8bit values for BB[1Eh] (usually somewhat B1h..B7h) 154h 0Eh Channel 1..14 8bit values for RF[9].Bit10..14 (usually 10h-filled) |
--- Type3 values are originated at 0CEh, following addresses depend on: --- 1) number of initial values, found at [042h] ;usually 29h 2) number of BB indices, found at [0CEh+[042h]] ;usually 02h 3) number of RF indices, found at [043h] ;usually 02h --- Below example addresses assume above values to be set to 29h,02h,02h --- 0CEh 29h Initial 8bit values for RF[0..28h] 0F7h 1 Number of BB indices per channel 0F8h 1 1st BB index 0F9h 14 1st BB data for channel 1..14 107h 1 2nd BB index 108h 14 2nd BB data for channel 1..14 116h 1 1st RF index 117h 14 1st RF data for channel 1..14 125h 1 2nd RF index 126h 14 2nd RF data for channel 1..14 134h 46 Unused (FFh-filled) |
162h 1 Unknown (usually 19h..1Ch) 163h 1 Unused (FFh) (Inside CRC16 region, with config_length=138h) 164h 99h Unused (FFh-filled) (Outside CRC16 region, with config_length=138h) 1FDh 1 DSi/3DS Wifi Board (01h=W015, 02h=W024, 03h=W028);\this was 1FEh 1 DSi/3DS Wifi Flash (20h=With access point 4/5/6) ; FFh-filled on DS 1FFh 1 DSi/3DS Same as on DS (FFh) ;/ |
| DS Firmware Wifi Internet Access Points |
Addr Siz Expl.
000h 64 Unknown (usually 00h-filled) (no Proxy supported on NDS)
040h 32 SSID (ASCII name of the access point) (padded with 00h's)
060h 32 SSID for WEP64 on AOSS router (each security level has its own SSID)
080h 16 WEP Key 1 (for type/size, see entry E6h)
090h 16 WEP Key 2 ;\
0A0h 16 WEP Key 3 ; (usually 00h-filled)
0B0h 16 WEP Key 4 ;/
0C0h 4 IP Address (0=Auto/DHCP)
0C4h 4 Gateway (0=Auto/DHCP)
0C8h 4 Primary DNS Server (0=Auto/DHCP)
0CCh 4 Secondary DNS Server (0=Auto/DHCP)
0D0h 1 Subnet Mask (0=Auto/DHCP, 1..1Ch=Leading Ones) (eg. 6 = FC.00.00.00)
0D1h .. Unknown (usually 00h-filled)
0E6h 1 WEP Mode (0=None, 1/2/3=5/13/16 byte hex, 5/6/7=5/13/16 byte ascii)
0E7h 1 Status (00h=Normal, 01h=AOSS, FFh=connection not configured/deleted)
0E8h 1 Zero (not SSID Length, ie. unlike as entry 4,5,6 on DSi)
0E9h 1 Unknown (usually 00h)
0EAh 2 DSi only: MTU (Max transmission unit) (576..1500, usually 1400)
0ECh 3 Unknown (usually 00h-filled)
0EFh 1 bit0/1/2 - connection 1/2/3 (1=Configured, 0=Not configured)
0F0h 6 Nintendo Wifi Connection (WFC) 43bit User ID
(ID=([F0h] AND 07FFFFFFFFFFh)*1000, shown as decimal string
NNNN-NNNN-NNNN-N000) (the upper 5bit of the last byte are
containing additional/unknown nonzero data)
0F6h 8 Unknown (nonzero stuff !?!)
0FEh 2 CRC16 for Entries 000h..0FDh (with initial value 0000h)
|
Addr Siz Expl. 000h 32 Proxy Authentication Username (ASCII string, padded with 00's) 000h 32 Proxy Authentication Password (ASCII string, padded with 00's) 040h 32 SSID (ASCII string, padded with 00's) (see [0E8h] for length) 060h .. Maybe same as NDS 080h 16 WEP Key (zerofilled for WPA) 0xxh .. Maybe same as NDS 0C0h 4 IP Address (0=Auto/DHCP) 0C4h 4 Gateway (0=Auto/DHCP) 0C8h 4 Primary DNS Server (0=Auto/DHCP) 0CCh 4 Secondary DNS Server (0=Auto/DHCP) 0D0h 1 Subnet Mask (0=Auto/DHCP, 1..1Ch=Leading Ones) (eg. 6 = FC.00.00.00) 0D1h .. Unknown (zerofilled) 0E6h 1 WEP (00h=None/WPA/WPA2, 01h/02h/03h/05h/06h/07h=WEP, same as NDS) 0E7h 1 WPA (00h=Normal, 10h=WPA/WPA2, 13h=WPS+WPA/WPA2, FFh=unused/deleted) 0E8h 1 SSID Length in characters (01h..20h, or 00h=unused) 0E9h 1 Unknown (usually 00h) 0EAh 2 MTU Value (Max transmission unit) (576..1500, usually 1400) 0ECh 3 Unknown (usually 00h-filled) 0EFh 1 bit0/1/2 - connection 4/5/6 (1=Configured, 0=Not configured) 0F0h 14 Zerofilled (or maybe ID as on NDS, if any such ID exists for DSi?) 0FEh 2 CRC16 for Entries 000h..0FDh (with initial value 0000h) 100h 32 Precomputed PSK (based on WPA/WPA2 password and SSID) ;\all zero 120h 64 WPA/WPA2 password (ASCII string, padded with 00's) ;/for WEP 160h 33 Zerofilled 181h 1 WPA (0=None/WEP, 4=WPA-TKIP, 5=WPA2-TKIP, 6=WPA-AES, 7=WPA2-AES) 182h 1 Proxy Enable (00h=None, 01h=Yes) 183h 1 Proxy Authentication (00h=None, 01h=Yes) 184h 48 Proxy Name (ASCII string, max 47 chars, padded with 00's) 1B4h 52 Zerofilled 1E8h 2 Proxy Port (16bit) 1EAh 20 Zerofilled 1FEh 2 CRC16 for Entries 100h..1FDh (with initial value 0000h) (0=deleted) |
| DS Firmware User Settings |
Addr Size Expl. 000h 2 Version (5) (Always 5, for all NDS/DSi Firmware versions) 002h 1 Favorite color (0..15) (0=Gray, 1=Brown, etc.) 003h 1 Birthday month (1..12) (Binary, non-BCD) 004h 1 Birthday day (1..31) (Binary, non-BCD) 005h 1 Not used (zero) 006h 20 Nickname string in UTF-16 format 01Ah 2 Nickname length in characters (0..10) 01Ch 52 Message string in UTF-16 format 050h 2 Message length in characters (0..26) 052h 1 Alarm hour (0..23) (Binary, non-BCD) 053h 1 Alarm minute (0..59) (Binary, non-BCD) 054h 2 056h 1 80h=enable alarm (huh?), bit 0..6=enable? 057h 1 Zero (1 byte) 058h 2x2 Touch-screen calibration point (adc.x1,y1) 12bit ADC-position 05Ch 2x1 Touch-screen calibration point (scr.x1,y1) 8bit pixel-position 05Eh 2x2 Touch-screen calibration point (adc.x2,y2) 12bit ADC-position 062h 2x1 Touch-screen calibration point (scr.x2,y2) 8bit pixel-position 064h 2 Language and Flags (see below) 066h 1 Year (2000..2255) (when having entered date in the boot menu) 067h 1 Unknown (usually 00h...08h or 78h..7Fh or so) 068h 4 RTC Offset (difference in seconds when RTC time/date was changed) 06Ch 4 Not used (FFh-filled, sometimes 00h-filled) (=MSBs of above?) |
070h 2 Update counter (used to check latest) (must be 0000h..007Fh) 072h 2 CRC16 of entries 00h..6Fh (70h bytes) 074h 8Ch Not used (FFh-filled) (or extended data, see below) |
074h 1 Unknown (01h) (maybe version?)
075h 1 Extended Language (0..5=Same as Entry 064h, plus 6=Chinese)
(for language 6, entry 064h defaults to english; for compatibility)
(for language 0..5, both entries 064h and 075h have same value)
076h 2 Bitmask for Supported Languages (Bit0..6)
(007Eh for iQue DS, ie. with chinese, but without japanese)
(0042h for iQue DSi, chinese (and english, but only for NDS mode))
(003Eh for DSi/EUR, ie. without chinese, and without japanese)
078h 86h Not used (FFh-filled on iQue DS, 00h-filled on DSi)
0FEh 2 CRC16 of entries 74h..FDh (8Ah bytes)
|
0..2 Language (0=Japanese, 1=English, 2=French, 3=German,
4=Italian, 5=Spanish, 6..7=Reserved) (for Chinese see Entry 075h)
(the language setting also implies time/data format)
3 GBA mode screen selection (0=Upper, 1=Lower)
4-5 Backlight Level (0..3=Low,Med,High,Max) (DS-Lite only)
6 Bootmenu Disable (0=Manual/bootmenu, 1=Autostart Cartridge)
7-8 ?
9 Settings Lost (1=Prompt for User Info, and Language, and Calibration)
10 Settings Okay (0=Prompt for User Info)
11 Settings Okay (0=Prompt for User Info) (Same as Bit10)
12 No function
13 Settings Okay (0=Prompt for User Info, and Language)
14 Settings Okay (0=Prompt for User Info) (Same as Bit10)
15 Settings Okay (0=Prompt for User Info) (Same as Bit10)
|
IF count1=((count0+1) AND 7Fh) THEN area1=newer ELSE area0=newer |
| DS Firmware Extended Settings |
Addr Siz Expl.
00h 8 ID "XbooInfo"
08h 2 CRC16 Value [0Ch..0Ch+Length-1]
0Ah 2 CRC16 Length (from 0Ch and up)
0Ch 1 Version (currently 01h)
0Dh 1 Update Count (newer = (older+1) AND FFh)
0Eh 1 Bootmenu Flags
Bit6 Important Info (0=Disable, 1=Enable)
Bit7 Bootmenu Screen (0=Upper, 1=Lower)
0Fh 1 GBA Border (0=Black, 1=Gray Line)
10h 2 Temperature Calibration TP0 ADC value (x16) (sum of 16 ADC values)
12h 2 Temperature Calibration TP1 ADC value (x16) (sum of 16 ADC values)
14h 2 Temperature Calibration Degrees Kelvin (x100) (0=none)
16h 1 Temperature Flags
Bit0-1 Format (0=Celsius, 1=Fahrenheit, 2=Reaumur, 3=Kelvin)
17h 1 Backlight Intensity (0=0ff .. FFh=Full)
18h 4 Date Century Offset (currently 20, for years 2000..2099)
1Ch 1 Date Month Recovery Value (1..12)
1Dh 1 Date Day Recovery Value (1..31)
1Eh 1 Date Year Recovery Value (0..99)
1Fh 1 Date/Time Flags
Bit0-1 Date Format (0=YYYY-MM-DD, 1=MM-DD-YYYY, 2=DD-MM-YYYY)
Bit2 Friendly Date (0=Raw Numeric, 1=With Day/Month Names)
Bit5 Time DST (0=Hide DST, 1=Show DST=On/Off)
Bit6 Time Seconds (0=Hide Seconds, 1=Show Seconds)
Bit7 Time Format (0=24 hour, 1=12 hour)
20h 1 Date Separator (Ascii, usually Slash, or Dot)
21h 1 Time Separator (Ascii, usually Colon, or Dot)
22h 1 Decimal Separator (Ascii, usually Comma, or Dot)
23h 1 Thousands Separator (Ascii, usually Comma, or Dot)
24h 1 Daylight Saving Time (Nth)
Bit 0-3 Activate on (0..4 = Last,1st,2nd,3rd,4th)
Bit 4-7 Deactivate on (0..4 = Last,1st,2nd,3rd,4th)
25h 1 Daylight Saving Time (Day)
Bit 0-3 Activate on (0..7 = Mon,Tue,Wed,Thu,Fri,Sat,Sun,AnyDay)
Bit 4-7 Deactivate on (0..7 = Mon,Tue,Wed,Thu,Fri,Sat,Sun,AnyDay)
26h 1 Daylight Saving Time (of Month)
Bit 0-3 Activate DST in Month (1..12)
Bit 4-7 Deactivate DST in Month (1..12)
27h 1 Daylight Saving Time (Flags)
Bit 0 Current DST State (0=Off, 1=On)
Bit 1 Adjust DST Enable (0=Disable, 1=Enable)
|
| DS File Formats |
| DS Files - Text Messages (MESG) |
000h 8 ID "MESGbmg1" ;or "GSEM1gmb" in Super Mario 64 DS 008h 4 Total Filesize ;or Filesize+1 in Super Mario 64 DS 00Ch 4 Number of Chunks (2=INF1+DAT1, 3=INF1+DAT1+MID1) 010h 1 Encoding (1=CP1252, 2=UTF-16, 3=Shift-JIS, 4=UTF-8) 011h 15 Padding (0) |
000h 4 Chunk ID "INF1" ;or "1FNI" in Super Mario 64 DS 004h 4 Chunk Size 008h 2 Number of messages (N) 00Ah 2 Size of each INF data in bytes ;or in BITs in Super Mario 64 DS 00Ch 4 "BMG file ID = ID for this BMG file (usually 0)" 010h N*siz Message Info (32bit offset from DAT1+8, and optional attributes) |
000h 4 Offset to the message (after DAT1+8 section header) 004h siz-4 Attributes/flags (if entrysize is bigger than 4 bytes) |
000h 4 Chunk ID "DAT1" ;or "1TAD" in Super Mario 64 DS 004h 4 Chunk Size ;or Size+1 in Super Mario 64 DS 008h .. Message strings (usually UTF-16, depending on Encoding in header) |
0000 End of String (except inside Escape sequences)
000A Linebreak
001A,nn,command,parameters Escape Sequences (nn=length in bytes)
001A,08,00,0000,00xx Set font size (64h=100%=Normal Size)
001A,08,00,0001,00xx Set text color to xx
001A,08,01,0000,24xx Draw Unicode char U+2460..246E ;"(1)"..("15)"
001A,08,01,0000,xxxx Draw Unicode char U+E068..F12B ;custom?
001A,06,02,0000 Draw Name of current player
001A,0A,02,0010,000x,000w Draw Integer from index x with w digits
001A,08,02,0011,00xx Unknown (with xx=0..8)
001A,08,02,0012,0000 Draw Name of a player
001A,08,02,0013,0000 Unknown
001A,08,02,0014,0000 Unknown
001A,08,02,0015,0000 Unknown
001A,0A,02,0016,0000,0000 Unknown
001A,08,02,0017,0000 Unknown
001A,08,02,0020,0000 Draw Name of a Wii friend
001A,08,03,0010,0000 Unknown
001A,0C,04,0000,000x,yyyy,zzzz Unknown (x=0..1, y=0524..14A4, and z=y+1)
0025,00xx,00yy,00zz Escape codes in form of "%xyz" (or similar)
00xx ASCII Characters 20h..7Eh
E0xx Custom button symbols (eg. in DSi Launcher)
|
0D Linebreak? 10..1F Escape codes? xx,xx Unknown (doesn't really look like english Shift-JIS characters) FF End of String |
000h 4 Chunk ID "MID1" 004h 4 Chunk Size 008h 2 Number of messages (same as in INF1 block) 00Ah 2 Unknown (usually 1000h) 00Ch 4 Padding (0) 010h 4*N Message IDs |
| DS Files - Text Manuals |
000h 4 ID "NTLI" 004h 2 Byte Order (FEFFh) 006h 2 Version (can be 0200h) 008h 4 Total Filesize 00Ch 2 Header Size (10h) 00Eh 4 Number of Chunks (usually 1 = mtl1) |
000h 4 Chunk ID "mtl1" 004h 4 Chunk Size 008h 4 Number of supported languages 00Ch 2*N Language IDs (two-letter ASCII spelled backwards) |
000h 4 ID "NTMC" 004h 2 Byte Order (FEFFh) 006h 2 Version (can be 0200h) 008h 4 Total Filesize 00Ch 2 Header Size (10h) 00Eh 4 Number of Chunks (usually 3 = nap1+txp1+mtc1) |
000h 4 Chunk ID "nap1" 004h 4 Chunk Size 008h 4 Number of chapters (aka pages) minus 1? (eg. 18h=19h) 00Ch 4*N Offsets to filenames (from nap+0Ch) ... .. Filenames (ASCII, terminated by 00h) |
000h 4 Chunk ID "txp1" 004h 4 Chunk Size 008h 4 Number of something?? minus 1 (eg. 25h=26h) 00Ch 4*N Offsets to something?? (from txp1+0Ch) ... .. Somewhat corrupt UTF-16 strings (many aborted with char 20xxh) |
000h 4 Chunk ID "mtc1" 004h 4 Chunk Size 008h 4 Number of dunno what (eg. 0Dh=Much more?) 00Ch 2*? 16bit Indices in txp1? (eg. 0000h..0025h) |
000h 4 ID "NTPC" 004h 2 Byte Order (FEFFh) 006h 2 Version (can be 0200h) 008h 4 Total Filesize 00Ch 2 Header Size (10h) 00Eh 4 Number of Chunks (usually 7 = nap1+txp1+pag1+pan1+pas1+txt1+pae1) |
000h 4 Chunk ID "nap1" 004h 4 Chunk Size (10h) 008h 4 Zero (unlike as in NTMC file) 00Ch 4 Unknown (4) |
000h 4 Chunk ID "txp1" 004h 4 Chunk Size 008h 4 Number of something?? minus 1 (eg. 02h=03h) 00Ch 4*N Offsets to something?? (from txp1+0Ch) ... .. UTF-16 strings (Headline, Body, Footer?) |
000h 4 Chunk ID "pag1" 004h 4 Chunk Size (10h) 008h 2? 0000h text color black? 00Ah 2? 0160h link color or so? 00Ch 2? 7FFFh bg color white? 00Eh 2? 0000h |
000h 4 Chunk ID "pan1" 004h 4 Chunk Size (10h) 008h 2? 0000h 00Ah 2? 0000h 00Ch 2? 0100h 00Eh 2? 0160h link color or so? |
000h 4 Chunk ID "pan1" 004h 4 Chunk Size (0Ch) 008h 4? 00000001h |
000h 4 Chunk ID "txt1"
004h 4 Chunk Size
008h 2? 0008h
00Ah 2? 0008h
00Ch 2? 00F0h
00Eh 2? 0150h
010h 2? 0001h
012h 2? 0015h Number of 8-byte entries? start/end line-wrapping list?
014h 2? 000Dh
016h 2? 0010h
018h 4? 00000000h
01Ch 4? 00001CE7h
020h 4? 00000000h
024h 4? 00000000h
028h N*8 Unknown 8-byte entries? (00xxh,0010h,0000h,00yyh)
Or maybe positioning for symbols/images/tables?
|
000h 4 Chunk ID "pae1" 004h 4 Chunk Size (08h) |
000h 2 Bitmap Width in bytes (eg. 0Fh, 10h, 14h, 40h, 60h) 002h 2 Bitmap Height (eg. 12h, 0Eh, 14h, 30h, 47h) 004h 1 Unknown, maybe Texture Format? (always 04h=256-Color?) 005h 1 Unknown, maybe Color0.alpha? (00h or 01h) (often same as [007h]) 006h 2 Number of Palette entries (usually 10h, 80h, or 100h) 008h 8 Zerofilled 010h .. Palette data (with 16bit values in range 0000h..7FFFh) ... .. Bitmap data (seems to be always 8bpp) |
| DS Wireless Communications |
| DS Wifi I/O Map |
Address Dir Name r/w [Init] Description 4808000h R W_ID ---- [1440] Chip ID (1440h=DS, C340h=DS-Lite) 4808004h R/W W_MODE_RST 9fff [0000] Mode/Reset 4808006h R/W W_MODE_WEP --7f [0000] Mode/Wep modes 4808008h R/W W_TXSTATCNT ffff [0000] Beacon Status Request 480800Ah R/W W_X_00Ah ffff [0000] [bit7 - ingore rx duplicates] 4808010h R/W W_IF ackk [0000] Wifi Interrupt Request Flags 4808012h R/W W_IE ffff [0000] Wifi Interrupt Enable 4808018h R/W W_MACADDR_0 ffff [0000] Hardware MAC Address, 1st 2 bytes 480801Ah R/W W_MACADDR_1 ffff [0000] Hardware MAC Address, next 2 bytes 480801Ch R/W W_MACADDR_2 ffff [0000] Hardware MAC Address, last 2 bytes 4808020h R/W W_BSSID_0 ffff [0000] BSSID (first 2 bytes) 4808022h R/W W_BSSID_1 ffff [0000] BSSID (next 2 bytes) 4808024h R/W W_BSSID_2 ffff [0000] BSSID (last 2 bytes) 4808028h R/W W_AID_LOW ---f [0000] usually as lower 4bit of AID value 480802Ah R/W W_AID_FULL -7ff [0000] AID value assigned by a BSS. 480802Ch R/W W_TX_RETRYLIMIT ffff [0707] Tx Retry Limit (set from 00h-FFh) 480802Eh R/W W_INTERNAL ---1 [0000] 4808030h R/W W_RXCNT ff0e [0000] Receive control 4808032h R/W W_WEP_CNT ffff [0000] WEP engine enable 4808034h R? W_INTERNAL 0000 [0000] bit0,1 (see ports 004h,040h,1A0h) |
4808036h R/W W_POWER_US ---3 [0001] 4808038h R/W W_POWER_TX ---7 [0003] 480803Ch R/W W_POWERSTATE -r-2 [0200] 4808040h R/W W_POWERFORCE 8--1 [0000] 4808044h R W_RANDOM 0xxx [0xxx] 4808048h R/W W_POWER_? ---3 [0000] |
4808050h R/W W_RXBUF_BEGIN ffff [4000] 4808052h R/W W_RXBUF_END ffff [4800] 4808054h R W_RXBUF_WRCSR 0rrr [0000] 4808056h R/W W_RXBUF_WR_ADDR -fff [0000] 4808058h R/W W_RXBUF_RD_ADDR 1ffe [0000] 480805Ah R/W W_RXBUF_READCSR -fff [0000] 480805Ch R/W W_RXBUF_COUNT -fff [0000] 4808060h R W_RXBUF_RD_DATA rrrr [xxxx] 4808062h R/W W_RXBUF_GAP 1ffe [0000] 4808064h R/W W_RXBUF_GAPDISP -fff [0000] |
4808068h R/W W_TXBUF_WR_ADDR 1ffe [0000] 480806Ch R/W W_TXBUF_COUNT -fff [0000] 4808070h W W_TXBUF_WR_DATA xxxx [xxxx] 4808074h R/W W_TXBUF_GAP 1ffe [0000] 4808076h R/W W_TXBUF_GAPDISP 0fff [0000] 4808078h W W_INTERNAL mirr [mirr] Read: Mirror of 068h 4808080h R/W W_TXBUF_BEACON ffff [0000] Beacon Transmit Location 4808084h R/W W_TXBUF_TIM --ff [0000] Beacon TIM Index in Frame Body 4808088h R/W W_LISTENCOUNT --ff [0000] Listen Count 480808Ch R/W W_BEACONINT -3ff [0064] Beacon Interval 480808Eh R/W W_LISTENINT --ff [0000] Listen Interval 4808090h R/W W_TXBUF_CMD ffff [0000] Multiplay Command 4808094h R/W W_TXBUF_REPLY1 ffff [0000] Multiplay Next Reply 4808098h R W_TXBUF_REPLY2 0000 [0000] Multiplay Current Reply 480809Ch R/W W_INTERNAL ffff [0050] value 4x00h --> preamble+x*12h us? 48080A0h R/W W_TXBUF_LOC1 ffff [0000] 48080A4h R/W W_TXBUF_LOC2 ffff [0000] 48080A8h R/W W_TXBUF_LOC3 ffff [0000] 48080ACh W W_TXREQ_RESET fixx [0050] 48080AEh W W_TXREQ_SET fixx [0050] 48080B0h R W_TXREQ_READ --1f [0010] 48080B4h W W_TXBUF_RESET 0000 [0000] (used by firmware part4) 48080B6h R W_TXBUSY 0000 [0000] (used by firmware part4) 48080B8h R W_TXSTAT 0000 [0000] 48080BAh ? W_INTERNAL 0000 [0000] 48080BCh R/W W_PREAMBLE ---3 [0001] 48080C0h R/W x W_CMD_TOTALTIME ffff [0000] (used by firmware part4) 48080C4h R/W x W_CMD_REPLYTIME ffff [0000] (used by firmware part4) |
48080C8h ? W_INTERNAL 0000 [0000] 48080D0h R/W W_RXFILTER 1fff [0401] 48080D4h R/W W_CONFIG_0D4h ---3 [0001] 48080D8h R/W W_CONFIG_0D8h -fff [0004] 48080DAh R/W W_RX_LEN_CROP ffff [0602] 48080E0h R/W W_RXFILTER2 ---f [0008] |
48080E8h R/W W_US_COUNTCNT ---1 [0000] Microsecond counter enable 48080EAh R/W W_US_COMPARECNT ---1 [0000] Microsecond compare enable 48080ECh R/W W_CONFIG_0ECh 3f1f [3F03] 48080EEh R/W W_CMD_COUNTCNT ---1 [0001] 48080F0h R/W W_US_COMPARE0 fc-- [FC00] Microsecond compare, bits 0-15 48080F2h R/W W_US_COMPARE1 ffff [FFFF] Microsecond compare, bits 16-31 48080F4h R/W W_US_COMPARE2 ffff [FFFF] Microsecond compare, bits 32-47 48080F6h R/W W_US_COMPARE3 ffff [FFFF] Microsecond compare, bits 48-63 48080F8h R/W W_US_COUNT0 ffff [0000] Microsecond counter, bits 0-15 48080FAh R/W W_US_COUNT1 ffff [0000] Microsecond counter, bits 16-31 48080FCh R/W W_US_COUNT2 ffff [0000] Microsecond counter, bits 32-47 48080FEh R/W W_US_COUNT3 ffff [0000] Microsecond counter, bits 48-63 4808100h ? W_INTERNAL 0000 [0000] 4808102h ? W_INTERNAL 0000 [0000] 4808104h ? W_INTERNAL 0000 [0000] 4808106h ? W_INTERNAL 0000 [0000] 480810Ch R/W W_CONTENTFREE ffff [0000] ... 4808110h R/W W_PRE_BEACON ffff [0000] 4808118h R/W W_CMD_COUNT ffff [0000] 480811Ch R/W W_BEACON_COUNT ffff [0000] reloaded with W_BEACONINT |
4808120h R/W W_CONFIG_120h 81ff [0048] init from firmware[04Ch] 4808122h R/W W_CONFIG_122h ffff [4840] init from firmware[04Eh] 4808124h R/W W_CONFIG_124h ffff [0000] init from firmware[05Eh], or 00C8h 4808126h ? W_INTERNAL fixx [ 0080] 4808128h R/W W_CONFIG_128h ffff [0000] init from firmware[060h], or 07D0h 480812Ah ? W_INTERNAL fixx [1000] lower 12bit same as W_CONFIG_128h 4808130h R/W W_CONFIG_130h -fff [0142] init from firmware[054h] 4808132h R/W W_CONFIG_132h 8fff [8064] init from firmware[056h] 4808134h R/W W_POST_BEACON ffff [FFFF] ... 4808140h R/W W_CONFIG_140h ffff [0000] init from firmware[058h], or xx 4808142h R/W W_CONFIG_142h ffff [2443] init from firmware[05Ah] 4808144h R/W W_CONFIG_144h --ff [0042] init from firmware[052h] 4808146h R/W W_CONFIG_146h --ff [0016] init from firmware[044h] 4808148h R/W W_CONFIG_148h --ff [0016] init from firmware[046h] 480814Ah R/W W_CONFIG_14Ah --ff [0016] init from firmware[048h] 480814Ch R/W W_CONFIG_14Ch ffff [162C] init from firmware[04Ah] 4808150h R/W W_CONFIG_150h ff3f [0204] init from firmware[062h], or 202h 4808154h R/W W_CONFIG_154h 7a7f [0058] init from firmware[050h] |
4808158h W W_BB_CNT mirr [00B5] BB Access Start/Direction/Index 480815Ah W W_BB_WRITE ???? [0000] BB Access data byte to write 480815Ch R W_BB_READ 00rr [00B5] BB Access data byte read 480815Eh R W_BB_BUSY 000r [0000] BB Access Busy flag 4808160h R/W W_BB_MODE 41-- [0100] BB Access Mode 4808168h R/W W_BB_POWER 8--f [800D] BB Access Powerdown |
480816Ah ? W_INTERNAL 0000 [0001] (or 0000h?) 4808170h ? W_INTERNAL 0000 [0000] 4808172h ? W_INTERNAL 0000 [0000] 4808174h ? W_INTERNAL 0000 [0000] 4808176h ? W_INTERNAL 0000 [0000] 4808178h W W_INTERNAL fixx [0800] Read: mirror of 17Ch |
480817Ch R/W W_RF_DATA2 ffff [0800] 480817Eh R/W W_RF_DATA1 ffff [C008] 4808180h R W_RF_BUSY 000r [0000] 4808184h R/W W_RF_CNT 413f [0018] |
4808190h R/W W_INTERNAL ffff [0000] 4808194h R/W W_TX_HDR_CNT ---7 [0000] used by firmware part4 (0 or 6) 4808198h R/W W_INTERNAL ---f [0000] 480819Ch R W_RF_PINS fixx [0004] 48081A0h R/W W_X_1A0h -933 [0000] used by firmware part4 (0 or 823h) 48081A2h R/W W_X_1A2h ---3 [0001] used by firmware part4 48081A4h R/W W_X_1A4h ffff [0000] "Rate used when signal test..." |
48081A8h R W_RXSTAT_INC_IF rrrr [0000] Stats Increment Flags 48081AAh R/W W_RXSTAT_INC_IE ffff [0000] Stats Increment IRQ Enable 48081ACh R W_RXSTAT_OVF_IF rrrr [0000] Stats Half-Overflow Flags 48081AEh R/W W_RXSTAT_OVF_IE ffff [0000] Stats Half-Overflow IRQ Enable 48081B0h R/W W_RXSTAT --ff [0000] 48081B2h R/W W_RXSTAT ffff [0000] RX_LengthRateErrorCount 48081B4h R/W W_RXSTAT rrff [0000] ... firmware uses also MSB ... ? 48081B6h R/W W_RXSTAT ffff [0000] 48081B8h R/W W_RXSTAT --ff [0000] 48081BAh R/W W_RXSTAT --ff [0000] 48081BCh R/W W_RXSTAT ffff [0000] 48081BEh R/W W_RXSTAT ffff [0000] 48081C0h R/W W_TX_ERR_COUNT --ff [0000] TransmitErrorCount 48081C4h R W_RX_COUNT fixx [0000] |
48081D0h R/W W_CMD_STAT ff-- [0000] 48081D2h R/W W_CMD_STAT ffff [0000] 48081D4h R/W W_CMD_STAT ffff [0000] 48081D6h R/W W_CMD_STAT ffff [0000] 48081D8h R/W W_CMD_STAT ffff [0000] 48081DAh R/W W_CMD_STAT ffff [0000] 48081DCh R/W W_CMD_STAT ffff [0000] 48081DEh R/W W_CMD_STAT ffff [0000] |
48081F0h R/W W_INTERNAL ---3 [0000]
4808204h ? W_INTERNAL fixx [0000]
4808208h ? W_INTERNAL fixx [0000]
480820Ch W W_INTERNAL fixx [0050]
4808210h R W_TX_SEQNO fixx [0000]
4808214h R W_RF_STATUS XXXX [0009] (used by firmware part4)
480821Ch W W_IF_SET fbff [0000] Force Interrupt (set bits in W_IF)
4808220h R/W W_RAM_DISABLE ffff [0000] WifiRAM control
4808224h R/W W_INTERNAL ---3 [0003]
4808228h W W_X_228h fixx [0000] (used by firmware part4) (bit3)
4808230h R/W W_INTERNAL --ff [0047]
4808234h R/W W_INTERNAL -eff [0EFF]
4808238h R/W W_INTERNAL ffff [0000] ;rx_seq_no-60h+/-x ;why that?
;other day: fixed value, not seq_no related?
480823Ch ? W_INTERNAL fixx [0000] like W_TXSTAT... ONLY for beacons?
4808244h R/W W_X_244h ffff [0000] (used by firmware part4)
4808248h R/W W_INTERNAL ffff [0000]
480824Ch R W_INTERNAL fixx [0000] ;rx_mac_addr_0 ;\OverTheHedge
480824Eh R W_INTERNAL fixx [0000] ;rx_mac_addr_1 ;/writes FFFFh?
4808250h R W_INTERNAL fixx [0000] ;rx_mac_addr_2
4808254h ? W_CONFIG_254h fixx [0000] (read: FFFFh=DS, EEEEh=DS-Lite)
4808258h ? W_INTERNAL fixx [0000]
480825Ch ? W_INTERNAL fixx [0000]
4808260h ? W_INTERNAL fixx [ 0FEF]
4808264h R W_INTERNAL fixx [0000] ;rx_addr_1 (usually "rxtx_addr-x")
4808268h R W_RXTX_ADDR fixx [0005] ;rxtx_addr
4808270h R W_INTERNAL fixx [0000] ;rx_addr_2 (usually "rx_addr_1-1")
4808274h ? W_INTERNAL fixx [ 0001]
4808278h R/W W_INTERNAL ffff [000F]
480827Ch ? W_INTERNAL fixx [ 000A]
4808290h (R/W) W_X_290h fixx [FFFF] bit 0 = ? (used by firmware part4)
4808298h W W_INTERNAL fixx [0000]
48082A0h R/W W_INTERNAL ffff [0000]
48082A2h R W_INTERNAL XXXX [7FFF] 15bit shift reg (used during tx?)
48082A4h R W_INTERNAL fixx [0000] ;rx_rate_1 not ALWAYS same as 2C4h
48082A8h W W_INTERNAL fixx [0000]
48082ACh ? W_INTERNAL fixx [ 0038]
48082B0h W W_INTERNAL fixx [0000]
48082B4h R/W W_INTERNAL -1-3 [0000]
48082B8h ? W_INTERNAL fixx [0000] ;dsi launcher checks if zero
48082C0h R/W W_INTERNAL ---1 [0000]
48082C4h R W_INTERNAL fixx [000A] ;rx_rate_2 (0Ah,14h = 1,2 Mbit/s)
48082C8h R W_INTERNAL fixx [0000] ;rx_duration/length/rate (or so?)
48082CCh R W_INTERNAL fixx [0000] ;rx_framecontrol; from ieee header
48082D0h DIS W_INTERNAL ;"W_POWERACK" (internal garbage)
;normally DISABLED (unless FORCE)
48082F0h R/W W_INTERNAL ffff [0000]
48082F2h R/W W_INTERNAL ffff [0000]
48082F4h R/W W_INTERNAL ffff [0000]
48082F6h R/W W_INTERNAL ffff [0000]
|
4804000h W_MACMEM RX/TX Buffers (2000h bytes) (excluding below specials) 4805F60h Used for something, not included in the rx circular buffer. 4805F80h W_WEPKEY_0 (32 bytes) 4805FA0h W_WEPKEY_1 (32 bytes) 4805FC0h W_WEPKEY_2 (32 bytes) 4805FE0h W_WEPKEY_3 (32 bytes) |
[480xxxxh]=5A5Ah/A5A5h ;-initial dummy WifiRAM memfill values [4805F70h]=FFFFh ;\ [4805F72h]=FFFFh ; set to FFFFh by software [4805F76h]=FFFFh ; [4805F7Eh]=FFFFh ;/ |
[4805F6Eh]=0F00h (nothing received), or 0F01h (received something) |
[4805F70h]=Received MAC Address (6 bytes, looks same as port 480824Ch) [4805F76h]=xxx0h (increasing value, Sequence Control from packet header) |
[4805F7Eh]=xxx0h (next higher sequence number? ie. [4805F76h]+10h) |
| DS Wifi Control |
0-15 Chip ID (1440h on NDS, C340h on NDS-lite) |
0 Adjust some ports (0/1=see lists below) (R/W)
TX Master Enable for LOC1..3 and Beacon (0=Disable, 1=Enable)
1-12 Unknown (R/W)
13 Reset some ports (0=No change, 1=Reset/see list below) (Write-Only)
14 Reset some ports (0=No change, 1=Reset/see list below) (Write-Only)
15 Unknown (R/W)
|
0-2 Unknown, specify a software mode for wifi operation
(may be related to hardware but a correlation has not yet been found)
3-5 WEP Encryption Key Size:
0=Reserved (acts same as 1)
1=64bit WEP (IV=24bit + KEY=40bit) (aka 3+5 bytes) ;standard/us
2=128bit WEP (IV=24bit + KEY=104bit) (aka 3+13 bytes) ;standard/world
3=152bit WEP (IV=24bit + KEY=128bit) (aka 3+16 bytes) ;uncommon
4=Unknown, mabye 256bit WEP (IV=24bit + KEY=232bit) (aka 3+29 bytes)?
5=Reserved (acts same as 1)
6=Reserved (acts same as 1)
7=Reserved (acts same as 1)
6 Unknown
7-15 Always zero
|
Bit0-3 Multiplay Slave number (1..15, or 0) Bit4-15 Not used |
Bit0-10 Association ID (AID) (1..2007, or zero) Bit11-15 Not used |
0-14 Unknown (usually zero) 15 WEP Engine Enable (0=Disable, 1=Enable) |
0-10 Random 11-15 Not used (zero) |
X = (X AND 1) XOR (X ROL 1) ;(rotation within 11bit range) |
Bit Dir Expl. 0 R/W Unknown (this does NOT affect TX) 1 R/W Preamble (0=Long, 1=Short) (this does NOT affect TX) 2 W Preamble (0=Long, 1=Short) (this does affect TX) (only at 2Mbit/s) 3-15 - Always zero |
Type Carrier Signal SFD Value PLCP Header Data Long 128bit, 1Mbit 16bit, 1Mbit 48bit, 1Mbit N bits, 1Mbit or 2Mbit Short 56bit, 1Mbit 16bit, 1Mbit 48bit, 2Mbit N bits, 2Mbit |
[4808034h]=0002h ;W_INTERNAL [480819Ch]=0046h ;W_RF_PINS [4808214h]=0009h ;W_RF_STATUS [480827Ch]=0005h ;W_INTERNAL [48082A2h]=? ;...unstable? |
[480827Ch]=000Ah ;W_INTERNAL |
[4808056h]=0000h ;W_RXBUF_WR_ADDR [48080C0h]=0000h ;W_CMD_TOTALTIME [48080C4h]=0000h ;W_CMD_REPLYTIME [48081A4h]=0000h ;W_X_1A4h [4808278h]=000Fh ;W_INTERNAL ...Also, following may be affected (results are unstable though)... [48080AEh]=? ;or rather the actual port (which it is an mirror of) [48080BAh]=? ;W_INTERNAL (occassionally unstable) [4808204h]=? ;W_INTERNAL [480825Ch]=? ;W_INTERNAL [4808268h]=? ;W_RXTX_ADDR [4808274h]=? ;W_INTERNAL |
[4808006h]=0000h ;W_MODE_WEP [4808008h]=0000h ;W_TXSTATCNT [480800Ah]=0000h ;W_X_00Ah [4808018h]=0000h ;W_MACADDR_0 [480801Ah]=0000h ;W_MACADDR_1 [480801Ch]=0000h ;W_MACADDR_2 [4808020h]=0000h ;W_BSSID_0 [4808022h]=0000h ;W_BSSID_1 [4808024h]=0000h ;W_BSSID_2 [4808028h]=0000h ;W_AID_LOW [480802Ah]=0000h ;W_AID_FULL [480802Ch]=0707h ;W_TX_RETRYLIMIT [480802Eh]=0000h ;W_INTERNAL [4808050h]=4000h ;W_RXBUF_BEGIN [4808052h]=4800h ;W_RXBUF_END [4808084h]=0000h ;W_TXBUF_TIM [48080BCh]=0001h ;W_PREAMBLE [48080D0h]=0401h ;W_RXFILTER [48080D4h]=0001h ;W_CONFIG_0D4h [48080E0h]=0008h ;W_RXFILTER2 [48080ECh]=3F03h ;W_CONFIG_0ECh [4808194h]=0000h ;W_TX_HDR_CNT [4808198h]=0000h ;W_INTERNAL [48081A2h]=0001h ;W_X_1A2h [4808224h]=0003h ;W_INTERNAL [4808230h]=0047h ;W_INTERNAL |
| DS Wifi Interrupts |
0 Receive Complete (packet received and stored in the RX fifo) 1 Transmit Complete (packet is done being transmitted) (no matter if error) 2 Receive Event Increment (IRQ02, see W_RXSTAT_INC_IE) 3 Transmit Error Increment (IRQ03, see W_TX_ERR_COUNT) 4 Receive Event Half-Overflow (IRQ04, see W_RXSTAT_OVF_IE) 5 Transmit Error Half-Overflow (IRQ05, see W_TX_ERR_COUNT.Bit7) 6 Start Receive (IRQ06, a packet has just started to be received) 7 Start Transmit (IRQ07, a packet has just started to be transmitted) 8 Txbuf Count Expired (IRQ08, see W_TXBUF_COUNT) 9 Rxbuf Count Expired (IRQ09, see W_RXBUF_COUNT) 10 Not used (always zero, even when trying to set it with W_IF_SET) 11 RF Wakeup (IRQ11, see W_POWERSTATE) 12 Multiplay CMD done (or failed) (IRQ12, see W_CMD_COUNT) 13 Post-Beacon Timeslot (IRQ13, see W_POST_BEACON) 14 Beacon Timeslot (IRQ14, see W_BEACON_COUNT/W_US_COMPARE) 15 Pre-Beacon Timeslot (IRQ15, see W_BEACON_COUNT/W_PRE_BEACON) |
0-15 Enable Flags, same bits as W_IF (0=Disable, 1=Enable) |
0-15 Set corresponding bits in W_IF (0=No change, 1=Set Bit) |
Caution Caution Caution Caution Caution That means, when acknowledging IF.Bit24, then NO FURTHER wifi IRQs will be executed whilst and as long as (W_IF AND W_IE) is non-zero. |
| DS Wifi Power-Down Registers |
0 Disable W_US_COUNT and W_BB_ports (0=Enable, 1=Disable) 1 Unknown (usually 0) 2-15 Always zero |
0 Auto Wakeup (1=Leave Idle Mode a while after Pre-Beacon IRQ15) 1 Auto Sleep (0=Enter Idle Mode on Post-Beacon IRQ13) 2 Unknown 3 Unknown (Write-only) (used by firmware) 4-15 Always zero |
0 Unknown (usually 0) (R/W) 1 Request Power Enable (0=No, 1=Yes/queued) (R/W, but not always) 2-7 Always zero 8 Indicates that Bit9 is about the be cleared (Read only) 9 Current power state (0=Enabled, 1=Disabled) (Read only) 10-15 Always zero |
0 New value for W_POWERSTATE.Bit9 (0=Clear/Delayed, 1=Set/Immediately) 1-14 Always zero 15 Apply Bit0 to W_POWERSTATE.Bit9 (0=No, 1=Yes) |
(Doing this is okay. Switches to power down mode. Similar to IRQ13.) [4808034h]=0002h ;W_INTERNAL [480803Ch]=02xxh ;W_POWERSTATE [48080B0h]=0000h ;W_TXREQ_READ [480819Ch]=0046h ;W_RF_PINS [4808214h]=0009h ;W_RF_STATUS (idle) |
(Don't do this. After that sequence, the hardware seems to be messed up) W_POWERSTATE.Bit8 gets set to indicate the pending operation, while pending, changes to W_POWERFORCE aren't applied to W_POWERSTATE, while pending, W_POWERACK becomes Read/Write-able, writing 0000h to W_POWERACK does clear W_POWERSTATE.Bit8, and does apply POWERFORCE.Bit0 to W_POWERSTATE.Bit9 and does deactivate Port W_POWERACK again. |
0 Unknown 1 Unknown 2-15 Always zero |
| DS Wifi Receive Control |
0 Copy W_RXBUF_WR_ADDR to W_RXBUF_WRCSR (aka force RX buf empty) (W) 1-3 Unknown (R/W) 4-6 Always zero 7 Copy W_TXBUF_REPLY1 to W_TXBUF_REPLY2, set W_TXBUF_REPLY1 to 0000h (W) 8-14 Unknown (R/W) 15 Enable Queuing received data to RX FIFO (R/W) |
0 For Broadcasts? (0=Insist on W_BSSID, 1=Accept no matter of W_BSSID)
1 Unknown (usually zero)
2 Unknown (usually zero)
3 Unknown (usually zero)
4 Unknown (usually zero)
5 Unknown (usually zero)
6 Unknown (usually zero)
7 Unknown (0 or 1)
8 Empty Packets (0=Ignore, 1=Accept; with RXHDR[0]=801Fh)
9 Unknown (0 or 1)
10 Unknown (0 or 1) (when set, receives beacons, and maybe others)
11 Unknown (usually zero) ;reportedly "allow toDS" ?
12 Update W_RXBUF_WRCSR after IEEE header (instead after full packets?)
(setting bit12 causes a mess, where new "packets" in RX buf could
either contain RXHDR+IEEE header, or Data corresponding to that
headers, which could be useful only if there's a way to distinguish
between headers and data, and knowing the size of the data blocks).
13-15 Not used (always zero)
|
0000h = Disable receive. FFFFh = Enable receive. 0400h = Receives managment frames (and possibly others, too) |
DA=W_MACADDR is always received DA=Broadcast, and BSSID=W_BSSID is always received DA=Broadcast, and BSSID=other is received only if RXFILTER.bit0=1 |
0 Unknown (0=Receive Data Frames, 1=Ignore Data Frames) (?) 1 Unknown 2 Unknown 3 Unknown (usually set) 4-15 Not used (always zero) |
| DS Wifi Receive Buffer |
0-15 Byte-offset in Wifi Memory (usually 4000h..5FFEh) |
0-11 Halfword Address in RAM 12-15 Always zero |
0-11 Halfword Address in RAM 12-15 Always zero |
0 Always zero 1-12 Halfword Address in RAM for reading via W_RXBUF_RD_DATA 13-15 Always zero |
0-11 Halfword Address in RAM 12-15 Always zero |
0-15 Data |
0 Always zero 1-12 Halfword Address in RAM 13-15 Always zero |
Addr=Addr+2 and 1FFEh ;address increment (by W_RXBUF_RD_DATA read)
if Addr=RXBUF_END then ;normal begin/end wrapping (done before gap wraps)
Addr=RXBUF_BEGIN
if Addr=RXBUF_GAP then ;now gap-wrap (may include further begin/end wrap)
Addr=RXBUF_GAP+RXBUF_GAPDISP*2
if Addr>=RXBUF_END then Addr=Addr+RXBUF_BEGIN-RXBUF_END ;wrap more
|
0-11 Halfword Offset, used with W_RXBUF_GAP (see there) 12-15 Always zero |
0-11 Decremented on reads from W_RXBUF_RD_DATA 12-15 Always zero |
| DS Wifi Receive Statistics |
0-12 Increment Flags (see Port 48081B0h..1BFh) 13-15 Always zero |
0-12 Counter Increment Interrupt Enable (see 48081B0h..1BFh) (1=Enable) 13-15 Unknown (usually zero) |
0-12 Half-Overflow Flags (see Port 48081B0h..1BFh) 13-15 Always zero |
0-12 Half-Overflow Interrupt Enable (see Port 48081B0h..1BFh) (1=Enable) 13-15 Unknown (usually zero) |
Port Dir Bit Expl.
48081B0h R/W 0 W_RXSTAT ?
48081B1h - - Always 0 -
48081B2h R/W 1 W_RXSTAT ? "RX_RateErrorCount"
48081B3h R/W 2 W_RXSTAT Length>2348 error
48081B4h R/W 3 W_RXSTAT RXBUF Full error
48081B5h R 4? W_RXSTAT ? (R) (but seems to exist; used by firmware)
48081B6h R/W 5 W_RXSTAT Length=0 or Wrong FCS Error
48081B7h R/W 6 W_RXSTAT Packet Received Okay
(also increments on W_MACADDR mis-match)
(also increments on internal ACK packets)
(also increments on invalid IEEE type=3)
(also increments TOGETHER with 1BCh and 1BEh)
(not incremented on RXBUF_FULL error)
48081B8h R/W 7 W_RXSTAT ?
48081B9h - - Always 0 -
48081BAh R/W 8 W_RXSTAT ?
48081BBh - - Always 0 -
48081BCh R/W 9 W_RXSTAT WEP Error (when FC.Bit14 is set)
48081BDh R/W 10 W_RXSTAT ?
48081BEh R/W 11 W_RXSTAT (duplicated sequence control)
48081BFh R/W 12 W_RXSTAT ?
|
0-? Receive Okay Count (increments together with ports 48081B4h, 48081B7h) 8-? Receive Error Count (increments together with ports 48081B3h, 48081B6h) |
48081D0h Not used (always zero) 48081D1h..1DFh Client 1..15 Response Error (increments on missing replies) |
| DS Wifi Transmit Control |
0-3 Reset corresponding bits in W_TXREQ_READ (0=No change, 1=Reset) 4-15 Unknown (if any) |
0-3 Set corresponding bits in W_TXREQ_READ (0=No change, 1=Set) 4-15 Unknown (if any) |
0 Send W_TXBUF_LOC1 (1=Transfer, if enabled in W_TXBUF_LOC1.Bit15) 1 Send W_TXBUF_CMD (1=Transfer, if enabled in W_TXBUF_CMD.Bit15) 2 Send W_TXBUF_LOC2 (1=Transfer, if enabled in W_TXBUF_LOC2.Bit15) 3 Send W_TXBUF_LOC3 (1=Transfer, if enabled in W_TXBUF_LOC3.Bit15) 4 Unknown (Beacon?) (always 1, except when cleared via W_POWERFORCE) 5-15 Unknown/Not used |
0 W_TXBUF_LOC1 (1=Requested Transfer busy, or not yet started at all) 1 W_TXBUF_CMD (1=Requested Transfer busy, or not yet started at all) 2 W_TXBUF_LOC2 (1=Requested Transfer busy, or not yet started at all) 3 W_TXBUF_LOC3 (1=Requested Transfer busy, or not yet started at all) 4 W_TXBUF_BEACON (1=Beacon Transfer busy) 5-15 Unknown (if any) |
0 One (or more) Packet has Completed (1=Yes)
(No matter if successful, for that info see Bit1)
(No matter if ALL packets are done, for that info see Bit12-13)
1 Packet Failed (1=Error)
2-7 Unknown/Not used
8-11 Usually 0, ...but firmware is checking for values 03h,08h,0Bh
(gets set to 07h when transferred W_TXBUF_LOC1/2/3 did have Bit12=set)
(gets set to 00h otherwise)
(gets set to 03h after beacons ;if enabled in W_TXSTATCNT.Bit15)
(gets set to 08h after cmd's ;if enabled in W_TXSTATCNT.Bit14)
(gets set to 0Bh after cmd ack's ;if enabled in W_TXSTATCNT.Bit13)
(gets set to 04h after reply's ;if enabled in W_TXSTATCNT.Bit12)
12-13 Packet that updated W_TXSTAT (0=LOC1/BEACON/CMD/REPLY, 1=LOC2, 2=LOC3)
14-15 Unknown/Not used
|
0-11 Unknown (usually zero) (otherwise disables RXing multiplay REPLY's?) 12 Update W_TXSTAT=0401h and trigger IRQ01 after REPLY transmits (1=Yes) 13 Update W_TXSTAT=0B01h and trigger IRQ01 after CMD ACK transmits (1=Yes) 14 Update W_TXSTAT=0800h and trigger IRQ01 after CMD DATA transmits(1=Yes) 15 Update W_TXSTAT=0301h and trigger IRQ01 after BEACON transmits (1=Yes) |
0 IEEE FC.Bit12 and Duration (0=Auto/whatever, 1=Manual/Wifi RAM) 1 IEEE Frame Check Sequence (0=Auto/FCS/CRC32, 1=Manual/Wifi RAM) 2 IEEE Sequence Control (0=Auto/W_TX_SEQNO, 1=Manual/Wifi RAM) 3-15 Always zero |
0-11 Increments on IRQ07 (Transmit Start Interrupt) 12-15 Always zero |
| DS Wifi Transmit Buffers |
0 Always zero 1-12 Halfword Address in RAM for Writes via W_TXBUF_WR_DATA 13-15 Always zero |
0-15 Data to be written to address specified in W_TXBUF_WR_ADDR |
0 Always zero 1-12 Halfword Address 13-15 Always zero |
0-11 Halfword Offset (added to; if equal to W_TXBUF_GAP) 12-15 Always zero |
0-11 Halfword Address of TX Frame Header in RAM
12 For LOC1-3: When set, W_TXSTAT.bit8-10 are set to 07h after transfer
And, when set, the transferred frame-body gets messed up?
For BEACON: Unknown, no effect on W_TXSTAT
For CMD: Unknown, no effect on W_TXSTAT
13 IEEE Sequence Control (0=From W_TX_SEQNO, 1=Value in Wifi RAM)
For BEACON: Unknown (always uses W_TX_SEQNO) (no matter of bit13)
14 Unknown
15 Transfer Request (1=Request/Pending)
|
0 Disable LOC1 (0=No change, 1=Reset W_TXBUF_LOC1.Bit15) 1 Disable CMD (0=No change, 1=Reset W_TXBUF_CMD.Bit15) 2 Disable LOC2 (0=No change, 1=Reset W_TXBUF_LOC2.Bit15) 3 Disable LOC3 (0=No change, 1=Reset W_TXBUF_LOC3.Bit15) 4-5 Unknown/Not used 6 Disable REPLY2 (0=No change, 1=Reset W_TXBUF_REPLY2.Bit15) 7 Disable REPLY1 (0=No change, 1=Reset W_TXBUF_REPLY1.Bit15) 8-15 Unknown/Not used |
0-7 Location of TIM parameters within Beacon Frame Body 8-15 Not used/zero |
0-11 Decremented on writes to W_TXBUF_WR_DATA 12-15 Always zero |
| DS Wifi Transmit Errors |
0-7 Retry Count (usually 07h) 8-15 Unknown (usually 07h) |
0-7 TransmitErrorCount 8-15 Always zero |
| DS Wifi Status |
0 Reportedly "carrier sense" (maybe 1 during RX.DTA?) (usually 0)
1 TX.MAIN (RFU.Pin17) Transmit Data Phase (0=No, 1=Active)
2 Unknown (RFU.Pin3) Seems to be always high (Always 1=high?)
3-5 Not used (Always zero)
6 TX.ON (RFU.Pin14) Transmit Preamble+Data Phase (0=No, 1=Active)
Uhhh, no that seems to be still wrong...
Bit6 is often set, even when not transmitting anything...
7 RX.ON (RFU.Pin15) Receive Mode (0=No, 1=Enable)
8-15 Not used (Always zero)
|
0 RX.BUSY Receiving Preamble or Data (0=Idle or TX Busy, 1=RX Busy) 1 Data Phase (for both RX/TX mode) (0=Idle or Preamble, 1=Data) |
0-3 Current Transmit/Receive State:
0 = Initial value on Power-up (before raising W_MODE_RST.Bit0)
1 = RX Mode enabled (waiting for incoming data)
2 = Switching from RX to TX (takes a few clock cycles)
3 = TX Mode active (sending preamble and data)
4 = Switching from TX to RX (takes a few clock cycles)
5 = Multiplay: CMD was sent, waiting for replies (RF_PINS=0084h) (uh?)
Or rather: CMD was received, preparing reply? (on slave side!)
6 = RX (processing incoming data?)
7 = Switching from RX/REPLY to TX/ACK (between STAT=5 and STAT=8)
8 = Multiplay: Sending REPLY, or CMD-Ack (RF_PINS=0046h)
9 = Idle (upon IRQ13, and upon raising W_MODE_RST.Bit0)
4-15 Always zero?
|
0-11 Halfword address 12-15 Always zero |
| DS Wifi Timers |
0 Counter Enable (0=Disable, 1=Enable) 1-15 Always zero |
0-63 Counter Value in microseconds (incrementing) |
0 Compare Enable (0=Disable, 1=Enable) (IRQ14/IRQ15) 1 Force IRQ14 (0=No, 1=Force Now) (Write-only) 2-15 Always zero |
0 Block Beacon IRQ14 until W_US_COUNT=W_US_COMPARE (0=No, 1=Block) (W) 1-9 Always zero 10-63 Compare Value in milliseconds (aka microseconds/1024) (R/W) |
0-15 Decrementing Millisecond Counter (reloaded with W_BEACONINT upon IRQ14) |
0-15 Decrementing Millisecond Counter (reloaded with FFFFh upon IRQ14) |
0-9 Frequency in milliseconds of beacon transmission 10-15 Always zero |
0-15 Pre-Beacon Time in microseconds (static value, ie. NOT decrementing) |
0-7 Decremented by hardware at IRQ14 events (ie. once every beacon) 8-15 Always zero |
0-7 Listen Interval, counted in beacons (usually 02h) 8-15 Always zero |
0-15 Decrementing microsecond counter |
W_IF.Bit13=1 ;interrupt request |
[4808034h]=0002h ;W_INTERNAL ;(similar to W_POWERFORCE=8001h) [480803Ch]=02xxh ;W_POWERSTATE ;(W_TXREQ_READ.Bit4 is kept intact though) [480819Ch]=0046h ;W_RF_PINS.7=0;disable receive (enter idle mode) (RX.ON=Low) [4808214h]=0009h ;W_RF_STATUS=9;indicate idle mode |
W_BEACON_COUNT=W_BEACONINT ;next IRQ15/IRQ14 (Above is NOT done when IRQ14 was forced via W_US_COMPARECNT.Bit1) |
(Below IS ALSO DONE when IRQ14 was forced via W_US_COMPARECNT.Bit1)
W_IF.Bit14=1
W_POST_BEACON=FFFFh ;about 64 secs (ie. almost never) ;next IRQ13 ("never")
W_TXREQ_READ=W_TXREQ_READ AND FFF2h
if W_TXBUF_BEACON.15 then W_TXBUSY.Bit4=1
if W_LISTENCOUNT=00h then W_LISTENCOUNT=W_LISTENINT
W_LISTENCOUNT=W_LISTENCOUNT-1
|
W_RF_PINS.Bit7=0 ;disable receive (RX.ON=Low) W_RF_STATUS=2 ;indicate switching from RX to TX mode |
W_RF_PINS.Bit6=1 ;transmit preamble start (TX.ON=High) W_RF_STATUS=3 ;indicate TX mode |
W_POST_BEACON = W_POST_BEACON + TagDDhSteppingValue ;next IRQ13 |
W_IF.Bit7=1 ;interrupt request W_RF_PINS.Bit1=1 ;start data transfer (preamble finished now) (TX.MAIN=High) |
[TXBUF...] = W_TX_SEQNO*10h ;auto-adjust IEEE Sequence Control W_TX_SEQNO=W_TX_SEQNO+1 ;increase sequence number |
W_RF_PINS.Bit6=0 ;disable TX (TX.ON=Low) W_RF_STATUS=4 ;indicate switching from TX to RX mode |
W_IF.Bit1=1 ;interrupt request W_RF_PINS.Bit1=0 ;disable TX (TX.MAIN=Low) W_RF_PINS.Bit7=1 ;enable RX (RX.ON=High) W_RF_STATUS=1 ;indicate RX mode |
if W_US_COMPARECNT=1 then W_IF.Bit15=1 |
W_RF_PINS.Bit7=1 ;enable RX (RX.ON=High) ;\gets set like so a good while W_RF_STATUS=1 ;indicate RX mode ;/after IRQ15 (but not immediately) |
IRQ15 Pre-Beacon (beacon will be transferred soon) IRQ14 Beacon (beacon will be transferred very soon) (carrier starts) IRQ07 Tx Start (beacon transfer starts) (if enabled in W_TXBUF_BEACON.15) IRQ01 Tx End (beacon transfer done) (if enabled in W_TXSTATCNT.15) IRQ13 Post-Beacon (beacon transferred) (unless next IRQ14 occurs earlier) |
| DS Wifi Multiplay Master |
0 Enable W_CMD_COUNT (0=Disable, 1=Enable) 1-15 Always Zero |
0-15 Decremented once every 10 microseconds (Stopped at 0000h) |
0-15 Duration per ALL slave response packet(s) in microseconds |
0-15 Duration per SINGLE slave response packet in microseconds |
master_time = (master_bytes*4)+(60h) ;60h = 96 decimal = short preamble slave_time = (slave_bytes*4)+(0D0h..0D2h) all_slave_time = (EAh..F0h)+(slave_time+0Ah)*num_slaves txhdr[2] = slave_bits ;hardware header (*) ieee[2] = all_slave_time ;ieee header (duration/id) body[0] = slave_time ;duration per slave (for multiboot/pictochat) body[2] = slave_bits ;frame body -- required (*) [48080C0h] = all_slave_time ;W_CMD_TOTALTIME [48080C4h] = slave_time ;W_CMD_REPLYTIME duration per slave [4808118h] = (388h+(num_slaves*slave_time)+master_time+32h)/10 ;W_CMD_COUNT [4808090h] = 8000h+master_packet_address ;start transmit ;W_TXBUF_CMD |
After starting transfer via TXREQ and TXBUF_CMD write: TXBUSY=2 (formerly 0) (after TXBUF_CMD write, or sometimes a bit later) After about 50-500 microseconds: ;\ RF_STAT=3 (TXing) (formerly 2) ; RXTX_ADDR=0006h..0008h (TXbuf+0Ch..) (formerly in RXBUF) ; CMD SEQNO+1 ; After TX preamble: ; IF=80h (TX Start, for CMD) ; RXTX_ADDR=0009h..0xxxh (TXbuf..) ; After TX data: ; optional: IF=02h (TX Done, for CMD) (if enabled in TXSTATCNT); optional: TXSTAT=0800h (CMD done) (if enabled in TXSTATCNT); RF_STAT=5 (CMD done, prepare for REPLY) ;/ US=0017h ;\ RXTX_ADDR=rxbuf.. ; After RX preamble: ; IF=40h (RX Start, for REPLY) ; REPLY RXTX_ADDR=rxbuf.. ; (if any) After RX data: ; IF=01h (RX Done, for REPLY) ; WRCSR+18h (for REPLY) ;/ After a dozen microseconds: ;\ RF_STAT=7 ;Switching from REPLY to ACK ; RF_STAT=8 ;TXing ACK (shortly after above STAT=7) ; RXTX_ADDR=0FC0h (special dummy addr during TX ACK) ; After TX preamble: ; ACK IF=80h (TX Start, for ACK) ; After TX data: ; optional: IF=02h (TX Done, for ACK) (if enabled in TXSTATCNT); optional: TXSTAT=0B01h (ACK done) (if enabled in TXSTATCNT); TXBUSY=0000h (formerly 0002h) ; TXBUF_CMD.bit15=0 ; TXHDR_0=0001h (okay) (formerly 0000h) ; TXHDR_2=0000h (no error flags) (formerly 0002h) ; SEQNO+1 ; RF_STAT=1 ;RX awaiting ; IF=1000h (CMD timeslot done) (shortly AFTER above IF=02h) ;/ |
1. MP host sends the CMD frame, as soon as possible. after preamble,
IRQ7 is triggered
2. once the transfer is finished: if bit14 in W_TXSTATCNT is set,
W_TXSTAT is set to 0x0800, and IRQ1 is triggered
somewhere here: set W_RF_STATUS=5, RFPINS=0x0084
3. hardware waits for MP clients' replies, duration is:
16 + ((10 + W_CMD_REPLYTIME) * count_ones(client_mask_from_frame_body))
4. MP host sends the CMD ack. after preamble, IRQ7 is triggered
(this is why you get two IRQ7's from a CMD transfer)
5. during the ack transfer, W_RF_STATUS is 8, and W_RXTXADDR is 0x0FC0
6. once the transfer is finished: if bit13 in W_TXSTATCNT is set,
W_TXSTAT is set to 0x0B01, and IRQ1 is triggered.
7. the TX header of the CMD frame is adjusted: bits in TXheader[02] are
cleared to indicate that the corresponding clients responded
successfully. Nintendo software checks this.
|
| DS Wifi Multiplay Slave |
0-11 Halfword address 12-14 Unknown (the bits can be set, ie. they DO exist) 15 Enable |
At incoming CMD DATA packet: ;\
RF_STATUS=6 ;RX processing incoming stuff ;
After RX preamble: ; CMD
IRQ6 (RX Start, for CMD DATA) ; DATA
After RX data: ;
IRQ0 (RX Done, for CMD DATA) ;
WRCSR=WRCSR+(size of CMD DATA) ;
RF_STATUS=5 ;preparing REPLY ;
if REPLY2.bit15=1 ;
TXHDR[1]=TXHDR[0] ;<-- or sometimes random? ;\adjust TXHDR[0,1] ;
TXHDR[0]=01h ;<-- mark done/discarded ;/for <old> REPLY2 ;
REPLY2=REPLY1, REPLY1=0000h ;-forward new reply ;
if REPLY2.bit15=1 ;
TXHDR[4] incremented (unless already max FFh) ;\adjust TXHDR[4,5] ;
TXHDR[5]=00h ;/for <new> REPLY2 ;
TX_SEQNO incremented ;<-- done here if REPLY2 exists ;/
After some moment (at the AID_LOW slot?): ;\
RF_STATUS=8 ;TX sending REPLY ;
After TX preamble: ; REPLY
IRQ7 (TX Start, for REPLY) ;
After TX data: ;
RF_STATUS=1 ;RX awaiting next packet ;
optional: IRQ1 (TX Done) (only if enabled in TXSTATCNT, and REPLY2.bit15=1)
optional: TXSTAT=0401h (only if enabled in TXSTATCNT) ;
if REPLY2.bit15=0 ;
SEQNO increased ;<-- done here when REPLY2 is empty ;/
After some moment: ;\
RF_STATUS=6 ;RX processing incoming stuff ;
After RX preamble: ; CMD
IRQ6 (RX Start, for CMD ACK) ; ACK
After RX data: ;
IRQ0 (RX Done, for CMD ACK) ;
WRCSR=WRCSR+(size of CMD ACK) ;
RF_STATUS=1 ;RX awaiting next packet ;/
Thereafter, Nintendo's software seems to require a delay (at least
100h microseconds) before receiving the next CMD DATA packet.
|
| DS Wifi Configuration Ports |
W_CONFIG_140h = firmware[058h]+0202h ;1Mbit/s W_CONFIG_140h = firmware[058h]+0202h-6161h ;2Mbit/s with long preamble W_CONFIG_140h = firmware[058h]+0202h-6161h-6060h ;2Mbit/s with short preamble |
0-7 Decrease RX Length by N halfwords for Non-WEP packets (usually 2) 8-15 Decrease RX Length by N halfwords for WEP packets (usually 6) |
| DS Wifi Baseband Chip (BB) |
0-7 Index (00h-68h) 8-11 Not used (should be zero) 12-15 Direction (5=Write BB_WRITE to Chip, 6=Read from Chip to BB_READ) |
0-7 Data to be sent to chip (by following W_BB_CNT transfer) 8-15 Not used (should be zero) |
0-7 Data received from chip (from previous W_BB_CNT transfer) 8-15 Not used (always zero) |
0 Transfer Busy (0=Ready, 1=Busy) 1-15 Always zero |
0-7 Always zero 8 Unknown (usually 1) (no effect no matter what setting?) 9-13 Always zero 14 Unknown (usually 0) (W_BB_READ gets unstable when set) 15 Always zero |
0-3 Disable whatever (usually 0Dh=disable) 4-14 Always zero 15 Disable W_BB_ports (usually 1=Disable) |
Index Num Dir Expl. 00h 1 R always 6Dh (R) (Chip ID) 01h..0Ch 12 R/W 8bit R/W 0Dh..12h 6 - always 00h 13h..15h 3 R/W 8bit R/W 16h..1Ah 5 - always 00h 1Bh..26h 12 R/W 8bit R/W 27h 1 - always 00h 28h..4Ch R/W 8bit R/W 4Dh 1 R always 00h or BFh (depending on other regs) 4Eh..5Ch R/W 8bit R/W 5Dh 1 R always 01h (R) 5Eh..61h - always 00h 62h..63h 2 R/W 8bit R/W 64h 1 R always FFh or 3Fh (depending on other regs) 65h 1 R/W 8bit R/W 66h 1 - always 00h 67h..68h 2 R/W 8bit R/W 69h..FFh - always 00h |
Addr Initial Meaning
01h 0x9E [unsetting/resetting bit 7 initializes/resets the system?]
02h unknown (firmware is messing with this register)
06h unknown (firmware is messing with this register, too)
13h 0x00 CCA operation - criteria for receiving
0=only use Carrier Sense (CS)
1=only use Energy Detection (ED)
2=receive if CS OR ED
3=receive only if CS AND ED
1Eh 0xBB see change channels flowchart (Ext. Gain when RF[09h].bit16=0)
35h 0x1F Energy Detection (ED) criteria
value 0..61 (representing energy levels of -60dBm to -80dBm)
|
| DS Wifi RF Chip |
0-1 Upper 2bit of 18bit data 2-6 Index (00h..1Fh) (firmware uses only 00h..0Bh) 7 Command (0=Write data, 1=Read data) 8-15 Should be zero (not used with 24bit transfer) |
0-3 Command (5=Write data, 6=Read data) 4-15 Should be zero (not used with 20bit transfer) |
0-15 Lower 16bit of 18bit data |
0-7 Data (to be written to chip) (or being received from chip) 8-15 Index (usually 00h..28h) (index 40h..FFh are mirrors of 00h..3Fh) |
0 Transfer Busy (0=Ready, 1=Busy) 1-15 Always zero |
0-5 Transfer length (init from firmware[041h].Bit0-5) 6-7 Always zero 8 Unknown (init from firmware[041h].Bit7) 9-13 Always zero 14 Unknown (usually 0) 15 Always zero |
| DS Wifi RF9008 Registers |
Firmware Index Data (24bit) (4bit) (18bit) 00C007h = 00h + 0C007h ;-also set to 0C008h for power-down 129C03h = 04h + 29C03h 141728h = 05h + 01728h ;\these are also written when changing channels 1AE8BAh = 06h + 2E8BAh ;/ 1D456Fh = 07h + 1456Fh 23FFFAh = 08h + 3FFFAh 241D30h = 09h + 01D30h ;-bit10..14 should be also changed per channel? """"50h = """ + """50h ;firmware v5 and up uses narrower tx filter 280001h = 0Ah + 00001h 2C0000h = 0Bh + 00000h 069C03h = 01h + 29C03h 080022h = 02h + 00022h 0DFF6Fh = 03h + 1FF6Fh |
17-16 Reserved, program to zero (0) 15-14 Reference Divider Value (0=Div2, 1=Div3, 2=Div44, 3=Div1) 3 Sleep Mode Current (0=Normal, 1=Very Low) 2 RF VCO Regulator Enable (0=Disable, 1=Enable) 1 IF VCO Regulator Enable (0=Disable, 1=Enable) 0 IF VGA Regulator Enable (0=Disable, 1=Enable) |
17 IF PLL Enable (0=Disable, 1=Enable) 16 IF PLL KV Calibration Enable (0=Disable, 1=Enable) 15 IF PLL Coarse Tuning Enable (0=Disable, 1=Enable) 14 IF PLL Loop Filter Select (0=Internal, 1=External) 13 IF PLL Charge Pump Leakage Current (0=Minimum value, 1=2*Minimum value) 12 IF PLL Phase Detector Polarity (0=Positive, 1=Negative) 11 IF PLL Auto Calibration Enable (0=Disable, 1=Enable) 10 IF PLL Lock Detect Enable (0=Disable, 1=Enable) 9 IF PLL Prescaler Modulus (0=4/5 Mode, 1=8/9 Mode) 8-4 Reserved, program to zero (0) 3-0 IF VCO Coarse Tuning Voltage (N=Voltage*16/VDD) |
17-16 Reserved, program to zero (0) 15-0 IF PLL divide-by-N value |
17 Reserved, program to zero (0) 16-8 IF VCO KV Calibration, delta N value (signed) ;DeltaF=(DN/Fr) 7-4 IF VCO Coarse Tuning Default Value 3-0 IF VCO KV Calibration Default Value |
17-10 Same as for RF[01h] (but for RF, not for IF) 9 RF PLL Prescaler Modulus (0=8/9 Mode, 1=8/10 Mode) 8-0 Same as for RF[01h] (but for RF, not for IF) |
17-6 RF PLL Divide By N Value 5-0 RF PLL Numerator Value (Bits 23-18) |
17-0 RF PLL Numerator Value (Bits 17-0) |
17-10 Same as for RF[03h] (but for RF, not for IF) ;and, DN=(deltaF/Fr)*256 |
17-13 VCO1 Warm-up Time ;TVCO1=(approximate warm-up time)*(Fr/32) 12-8 VCO1 Tuning Gain Calibration ;TLOCK1=(approximate lock time)*(Fr/128) 7-3 VCO1 Coarse Tune Calibration Reference ;VALUE=(average time)*(Fr/32) 2-0 Lock Detect Resolution (0..7) |
17 Receiver DC Removal Loop (0=Enable DC Removal Loop, 1=Disable) 16 Internal Variable Gain for VGA (0=Disable/External, 1=Enable/Internal) 15 Internal Variable Gain Source (0=From TXVGC Bits, 1=From Power Control) 14-10 Transmit Variable Gain Select (TXVGC) (0..1Fh = High..low gain) 9-7 Receive Baseband Low Pass Filter (0=Wide Bandwidth, 7=Narrow) 6-4 Transmit Baseband Low Pass Filter (0=Wide Bandwidth, 7=Narrow) 3 Mode Switch (0=Single-ended mode, 1=Differential mode) 2 Input Buffer Enable TX (0=Input Buffer Controlled by TXEN, 1=By BBEN) 1 Internal Bias Enable (0=Disable/External, 1=Enable/Internal) 0 TX Baseband Filters Bypass (0=Not Bypassed, 1=Bypassed) |
17-15 Select MID_BIAS Level (1.6V through 2.6V) 14-9 Desired output power at antenna (N*0.5dBm) 8-3 Power Control loop-variation-adjustment Offset (signed, N*0.5dB) 2-0 Desired delay for using a single TX_PE line (N*0.5us) |
17-12 Desired MAX output power when PABIAS=MAX=2.6V (N*0.5dBm) 11-6 Desired MAX output power when PABIAS=MID_BIAS (N*0.5dBm) 5-0 Desired MAX output power when PABIAS=MIN=1.6V (N*0.5dBm) |
17 IF VCO Band Current Compensation (0=Disable, 1=Enable) 16 RF VCO Band Current Compensation (0=Disable, 1=Enable) 15-0 Reserved, program to zero (0) |
Not used. |
17-0 This is a test register for internal use only. |
Not used. |
17-0 Don't care (writing any value resets the chip) |
| DS Wifi Unknown Registers |
0-15 Unknown (usually zero) |
0-1 Unknown 2-3 Always zero 4-5 Unknown 6-7 Always zero 8 Unknown 9-10 Always zero 11 Unknown 12-15 Always zero |
0-1 Unknown. Firmware writes values 03h, 01h, and VAR. 2-15 Always zero |
0-1 Disable WifiRAM (0=Normal, other=locks memory at 4804000h-5FFFh) 2-4 Unknown (0=Normal, other=prevents/affects RX to ram?) 5 Disable Special Log? (0=Normal, 1=Prevent 4805F6Eh..5F77h updates) 6-15 Unknown (0=Normal, other=?) |
0 Unknown (R/W) (if present) 1-15 Not used |
| DS Wifi Unused Registers |
4800000h-4807FFFh Wifi WS0 Region (32K) ;used for RAM at 4804000h 4808000h-4808000h Wifi WS1 Region (32K) ;used for registers at 4808000h 4810000h-4FFFFFFh Not used (00h-filled) |
Wifi-WS0-Region Wifi-WS1-Region Content 4800000h-4800FFFh 4808000h-4808FFFh Registers 4801000h-4801FFFh 4809000h-4809FFFh Registers (mirror) 4802000h-4803FFFh 480A000h-480BFFFh Unused 4804000h-4805FFFh 480C000h-480DFFFh Wifi RAM (8K) 4806000h-4806FFFh 480E000h-480EFFFh Registers (mirror) 4807000h-4807FFFh 480F000h-480FFFFh Registers (mirror) |
2030h, 2044h, 2056h, 2080h, 2090h, 2094h, 2098h, 209Ch, 20A0h, 20A4h, 20A8h, 20AAh, 20B0h, 20B6h, 20BAh, 21C0h, 2208h, 2210h, 2244h, 31D0h, 31D2h, 31D4h, 31D6h, 31D8h, 31DAh, 31DCh, 31DEh. |
Read from (W) Mirrors to (NDS) Or to (NDS-Lite) 070h W_TXBUF_WR_DATA 060h W_RXBUF_RD_DATA 074h W_TXBUF_GAP 078h W_INTERNAL 068h W_TXBUF_WR_ADDR 074h W_TXBUF_GAP 0ACh W_TXREQ_RESET 09Ch W_INTERNAL ? (zero) 0AEh W_TXREQ_SET 09Ch W_INTERNAL ? (zero) 0B4h W_TXBUF_RESET 0B6h W_TXBUSY ? (zero) 158h W_BB_CNT 15Ch W_BB_READ ? (zero) 15Ah W_BB_WRITE ? (zero) ? (zero) 178h W_INTERNAL 17Ch W_RF_DATA2 ? (zero) 20Ch W_INTERNAL 09Ch W_INTERNAL ? (zero) 21Ch W_IF_SET 010h W_IF 010h-OR-05Ch-OR-more? 228h W_X_228h ? (zero) ? (zero) 298h W_INTERNAL 084h W_TXBUF_TIM 084h W_TXBUF_TIM 2A8h W_INTERNAL 238h W_INTERNAL 238h W_INTERNAL 2B0h W_INTERNAL 084h W_TXBUF_TIM 084h W_TXBUF_TIM |
| DS Wifi Initialization |
[4000304h].Bit1 = 1 ;POWCNT2 ;-Enable power to the wifi system W_MACADDR = firmware[036h] ;-Set 48bit Mac address reg[012h] = 0000h ;W_IE ;-Disable interrupts |
reg[036h] = 0000h ;W_POWER_US ;\clear all powerdown bits
delay 8 ms ; (works without that killer-delay ?)
reg[168h] = 0000h ;W_BB_POWER ;/
IF firmware[040h]=02h ;\
temp=BB[01h] ; for wifitype=02h only:
BB[01h]=temp AND 7Fh ; reset BB[01h].Bit7, then restore old BB[01h]
BB[01h]=temp ; (that BB setting enables the RF9008 chip)
ENDIF ;/
delay 30 ms ;-(more killer-delay now getting REALLY slow)
call init_sub_functions ;- same as "Init 16 registers by firmware[..]"
; and "Init RF registers", below.
; this or the other one probably not necessary
|
reg[004h] = 0000h - W_MODE_RST ;set hardware mode reg[008h] = 0000h - W_TXSTATCNT ; reg[00Ah] = 0000h - ? W_X_00Ah ;(related to rx filter) reg[012h] = 0000h - W_IE ;disable interrupts (again) reg[010h] = FFFFh - W_IF ;acknowledge/clear any interrupts reg[254h] = 0000h - W_CONFIG_254h ; reg[0B4h] = FFFFh - W_TXBUF_RESET ;--reset all TXBUF_LOC's reg[080h] = 0000h - W_TXBUF_BEACON ;disable automatic beacon transmission reg[02Ah] = 0000h - W_AID_FULL ;\clear AID reg[028h] = 0000h - W_AID_LOW ;/ reg[0E8h] = 0000h - W_US_COUNTCNT ;disable microsecond counter reg[0EAh] = 0000h - W_US_COMPARECNT ;disable microsecond compare reg[0EEh] = 0001h - W_CMD_COUNTCNT ;(is 0001h on reset anyways) reg[0ECh] = 3F03h - W_CONFIG_0ECh ; reg[1A2h] = 0001h - ? ; reg[1A0h] = 0000h - ? ; reg[110h] = 0800h - W_PRE_BEACON ; reg[0BCh] = 0001h - W_PREAMBLE ;disable short preamble reg[0D4h] = 0003h - W_CONFIG_0D4h ; reg[0D8h] = 0004h - W_CONFIG_0D8h ; reg[0DAh] = 0602h - W_RX_LEN_CROP ; reg[076h] = 0000h - W_TXBUF_GAPDISP ;disable gap/skip (offset=zero) |
reg[146h] = firmware[044h] ;W_CONFIG_146h reg[148h] = firmware[046h] ;W_CONFIG_148h reg[14Ah] = firmware[048h] ;W_CONFIG_14Ah reg[14Ch] = firmware[04Ah] ;W_CONFIG_14Ch reg[120h] = firmware[04Ch] ;W_CONFIG_120h reg[122h] = firmware[04Eh] ;W_CONFIG_122h reg[154h] = firmware[050h] ;W_CONFIG_154h reg[144h] = firmware[052h] ;W_CONFIG_144h reg[130h] = firmware[054h] ;W_CONFIG_130h reg[132h] = firmware[056h] ;W_CONFIG_132h reg[140h] = firmware[058h] ;W_CONFIG_140h reg[142h] = firmware[05Ah] ;W_CONFIG_142h reg[038h] = firmware[05Ch] ;W_POWER_TX reg[124h] = firmware[05Eh] ;W_CONFIG_124h reg[128h] = firmware[060h] ;W_CONFIG_128h reg[150h] = firmware[062h] ;W_CONFIG_150h |
numbits = BYTE firmware[041h] ;usually 18h
numbytes = (numbits+7)/8 ;usually 3
reg[0x184] = (numbits+80h) AND 017Fh -- W_RF_CNT
for i=0 to BYTE firmware[042h]-1 ;number of entries (usually 0Ch) (0..0Bh)
if BYTE firmware[040h]=3
RF[i]=firmware[0CEh+i]
else
RF_Write(numbytes at firmware[0CEh+i*numbytes])
endif
|
(this should be not required, already set by firmware bootcode) reg[160h] = 0100h ;W_BB_MODE BB[0..68h] = firmware[64h+(0..68h)] |
copy 6 bytes from firmware[036h] to mac address at 0x04800018 (why again ?) |
reg[02Ch]=0007h ;W_TX_RETRYLIMIT - XXX needs to be set for every transmit? Set channel (see section on changing channels) Set Mode 2 -- sets bottom 3 bits of W_MODE_WEP to 2 Set Wep Mode / key -- Wep mode is bits 3..5 of W_MODE_WEP BB[13h] = 00h ;CCA operation (use only carrier sense, without ED) BB[35h] = 1Fh ;Energy Detection Threshold (ED) |
reg[032h] = 8000h -- W_WEP_CNT ;Enable WEP processing reg[134h] = FFFFh -- W_POST_BEACON ;reset post-beacon counter to LONG time reg[028h] = 0000h -- W_AID_LOW ;\clear W_AID value, again?! reg[02Ah] = 0000h -- W_AID_FULL ;/ reg[0E8h] = 0001h -- W_US_COUNTCNT ;enable microsecond counter reg[038h] = 0000h -- W_POWER_TX ;disable transmit power save reg[020h] = 0000h -- W_BSSID_0 ;\ reg[022h] = 0000h -- W_BSSID_1 ; clear BSSID reg[024h] = 0000h -- W_BSSID_2 ;/ |
reg[0AEh] = 000Dh -- W_TXREQ_SET ;flush all pending transmits (uh?) |
reg[030h] = 8000h W_RXCNT ;enable RX system (done again below) reg[050h] = 4C00h W_RXBUF_BEGIN ;(example values) reg[052h] = 5F60h W_RXBUF_END ;(length = 4960 bytes) reg[056h] = 0C00h/2 W_RXBUF_WR_ADDR ;fifo begin latch address reg[05Ah] = 0C00h/2 W_RXBUF_READCSR ;fifo end, same as begin at start. reg[062h] = 5F60h-2 W_RXBUF_GAP ;(set gap<end) (zero should work, too) reg[030h] = 8001h W_RXCNT ;enable, and latch new fifo values to hardware |
reg[030h] = 8000h W_RXCNT enable receive (again?)
reg[010h] = FFFFh W_IF clear interrupt flags
reg[012h] = whatever W_IE set enabled interrupts
reg[1AEh] = 1FFFh W_RXSTAT_OVF_IE desired STAT Overflow interrupts
reg[1AAh] = 0000h W_RXSTAT_INC_IE desired STAT Increase interrupts
reg[0D0h] = 0181h W_RXFILTER set to 0x581 when you successfully connect
to an access point and fill W_BSSID with a mac
address for it. (W_RXFILTER) [not sure on the values
for this yet]
reg[0E0h] = 000Bh -- W_RXFILTER2 ;
reg[008h] = 0000h -- ? W_TXSTATCNT ;(again?)
reg[00Ah] = 0000h -- ? W_X_00Ah ;(related to rx filter) (again?)
reg[004h] = 0001h -- W_MODE_RST ;hardware mode
reg[0E8h] = 0001h -- W_US_COUNTCNT ;enable microsecond counter (again?)
reg[0EAh] = 0001h -- W_US_COMPARECNT ;enable microsecond compare
reg[048h] = 0000h -- W_POWER_? ;[disabling a power saving technique]
reg[038h].Bit1 = 0 -- W_POWER_TX ;[this too]
reg[048h] = 0000h -- W_POWER_? ;[umm, it's done again. necessary?]
reg[0AEh] = 0002h -- W_TXREQ_SET ;
reg[03Ch].Bit1 = 1 -- W_POWERSTATE ;queue enable power (RX power, we believe)
reg[0ACh] = FFFFh -- W_TXREQ_RESET;reset LOC1..3
|
| DS Wifi Flowcharts |
(1) Copy the TX Header followed by the 802.11 packet to send anywhere it
will fit in MAC memory (halfword-aligned)
(2) Take the offset from start of MAC memory that you put the packet,
divide it by 2, and or with 0x8000 - store this in one of the
W_TXBUF_LOC registers
(3) Set W_TX_RETRYLIMIT, to allow your packet to be retried until an ack is
received (set it to 7, or something similar)
(4) Store the bit associated with the W_TXBUF_LOC register you used
into W_TXREQ_SET - this will send the packet.
(5) You can then read the result data in W_TXSTAT when the TX is over
(you can tell either by polling or interrupt) to find out how many
retries were used, and if the packet was ACK'd
|
(1) Calculate the length of the new packet (read "received frame length"
which is +8 bytes from the start of the packet) - total frame length
is (12 + received frame length) padded to a multiple of 4 bytes.
(2) Read the data out of the RX FIFO area (keep in mind it's a circular
buffer and you may have to wrap around the end of the buffer)
(3) Set the value of W_RXBUF_READCSR to the location of the next packet
(add the length of the packet, and wrap around if necessary)
|
RF[firmware[F2h+(ch-1)*6]/40000h] = firmware[F2h+(ch-1)*6] AND 3FFFFh RF[firmware[F5h+(ch-1)*6]/40000h] = firmware[F5h+(ch-1)*6] AND 3FFFFh delay a few milliseconds ;huh? IF RF[09h].bit16=0 ;External Gain (default) BB[1Eh]=firmware[146h+(ch-1)] ;set BB.Gain register ELSEIF RF[09h].bit15=0 ;Internal Gain from TXVGC Bits RF[09h].Bit10..14 = (firmware[154h+(ch-1)] AND 1Fh) ;set RF.TXVGC Bits ENDIF |
num_initial_regs = firmware[042h]
addr=0CEh+num_initial_regs
num_bb_writes = firmware[addr]
num_rf_writes = firmware[43h]
addr=addr+1
for i=1 to num_bb_writes
BB[firmware[addr]] = firmware[addr+ch]
addr=addr+15
next i
for i=1 to num_rf_writes
RF[firmware[addr]] = firmware[addr+ch]
addr=addr+15
next i
|
| DS Wifi Hardware Headers |
Addr Siz Expl.
00h 2 Status - In: Don't care - Out: Status (0000h=Failed, 0001h=Okay)
0000h=Retrying? (TXBUF_LOCn)
0001h=Okay (TXBUF_LOCn,TXBUF_BEACON,TXBUF_CMD)
xx01h=Okay (TXBUF_REPLY, with increasing "xx")
0003h=Failed (TXBUF_LOCn)
0005h=Failed (TXBUF_CMD, with errorflags in TXHDR[2])
02h 2 Unknown - In: Don't care
Bit0: Usually zero.
Bit1..15 --------> flags for multiboot slaves number 1..15
(Should be usually zero, except when sending multiplay commands
via W_TXBUF_CMD. In that case, the slave flags should be ALSO
stored in the second halfword of the FRAME BODY. Actually, the
hardware seems to use only that entry (in the BODY), rather than
using this entry (in the hardware header)).
04h 1 Unknown - In: Must be 00h..02h (should be 00h)
00h = use W_TX_SEQNO (if enabled in TXBUF_LOCn)
01h = force NOT to use W_TX_SEQNO (even if it is enabled in LOCn)
02h = seems to behave same as 01h
03h..FFh = results in error: W_TXSTAT.Bit1 gets set (though
header entry[00h] is kept set to 0001h=Okay)
other theory: maybe an 8bit retry count with 00h=first try?
05h 1 Unknown - In: Don't care - Out: Set to 00h
06h 2 Unknown - In: Don't care
08h 1 Transfer Rate (0Ah=1Mbit/s, 14h=2Mbit/s) (other values=1MBit/s, too)
09h 1 Unknown - In: Don't care
0Ah 2 Length of IEEE Frame Header+Body+checksum(s) in bytes
(14bits, upper 2bits are unused/don't care)
|
Addr Siz Expl.
00h 2 Flags
Bit0-3: Frame type/subtype:
00h: managment/any frame (except beacon and invalid subtypes)
01h: managment/beacon frame
05h: control/ps-poll frame
08h: data/any frame (subtype0..7) (ie. except invalid subtypes)
Values 0Ch..0Fh are for Multiplay cmd/reply packets:
0Ch: CMD frame ;FC=0228h=Data, FromDS, Data+CF_Poll
0Dh: CMD ack frame ;FC=0218h=Data, FromDS, Data+CF-Ack
0Eh: REPLY frame (data) ;FC=0118h=Data, ToDS, Data+CF-Ack
0Fh: REPLY frame (empty) ;FC=0158h=Data, ToDS, CF_Ack
0Fh: Also ALL empty packets (raw IEEE header, with 0-byte body)
Bit4: Seems to be always set
Bit5-7: Seems to be always zero
Bit8: Set when FC.Bit10 is set (more fragments)
Bit9: Set when the lower-4bit of Sequence Control are nonzero,
it is also set when FC.Bit10 is set (more fragments)
So, probably, it is set on fragment-mismatch-errors
Bit10-14: Seems to be always zero
Bit15: Set when Frame Header's BSSID value equals W_BSSID register
02h 2 Unknown (0040h=Normal, 0440h=WEP?, or Unchanged for multiplay CMDs?)
04h 2 Unchanged (not updated by hardware, contains old Wifi RAM content)
06h 2 Transfer Rate (N*100kbit/s) (ie. 14h for 2Mbit/s)
08h 2 Length of IEEE Frame Header+Body in bytes (excluding FCS checksum)
0Ah 1 MAX RSSI (bit0=always 1?) ;\Received Signal Strength Indicator
0Bh 1 MIN RSSI ;/
|
arm7_xlat_rssi_r0: ;bit0=unused, bit1=extraflag, bit2-7=unsigned value tst r0,2h ;bit1 mov r0,r0,asr 2h ;div4 (sign bits in bit31-8 are always zero-expanded) addeq r0,r0,19h ;add extra constant... when bit1=0 !!!!!! and r0,r0,0FFh ;blah (max is FFh/4+19h) bx r14 |
| DS Wifi Nintendo Beacons |
TXHDR using 2MBit/s rate 802.11 Management frame header 802.11 Beacon header (Timestamp, BeaconInterval=00xxh, Capability=0021h) Supported rates (Tag=01h, Len=02h, 82h,84h) ;1Mbit/s and 2Mbit/s Distribution Channel (Tag=03h, Len=01h, 0xh) ;channel 1, 7, or 13 TIM vector (Tag=05h, Len=05h, 00h,02h,0,0,0) ;adjusted by hardware Custom extension (Tag=DDh, Len=18h+N, see below) |
00h 4 Nintendo Beacon OUI (00h,09h,BFh,00h) 04h 2 Stepping Offset for 4808134h/W_POST_BEACON (always 000Ah) 06h 2 LCD Video Sync in 15.625Hz units (VCOUNT*7Fh-W_US_COUNT*2)/80h 08h 4 Fixed ID (00400001h) 0Ch 4 Game ID (0040xxxxh) (or 00000857h=Nintendo Zone) 10h 2 Randomly generated Stream code (0000h..FFFFh?) 12h 1 Number of bytes from entry 18h and up (70h for multiboot) (0 if Empty) 13h 1 Beacon Type (1=Multicart/Pictochat, 9=Empty, 0Bh=Multiboot, ?=Zone) 14h 2 CMD data size (01FEh = FFh halfwords) (or 0100h) 16h 2 REPLY data size (0008h = 4 halfwords) |
18h - Nothing, no data |
18h .. Custom data, usually containing the host name, either in 8bit ascii,
or 16bit unicode format. Sometimes taken from Firmware User Settings,
and sometimes from Cartridge Backup Memory.
|
18h 2 Fixed (always 2348h) 1Ah 2 Unknown xxxx 1Ch 1 Chatroom number (00h..03h for Chatroom A..D) 1Dh 1 Number of users already connected (1..16, including master) 1Eh 2 Fixed (always 0004h) |
18h 4 Game ID (0040xxxxh) (same as [0Ch]) (varies from game to game)
1Ch 1 Last Snippet flag (00h=Snippet #0..8, 02h=Snippet #9)
1Dh 1 Session Number (00h=First) (increments when restarting a new upload)
1Eh 1 Number of slaves already connected (0..15, excluding master)
Uh, actually [1Eh] is always 01h, even for 2..3 slaves?
1Fh 1 Snippet number (0..9=Snippet #0..9)
20h 2 Checksum (on entries [22h..87h])
chksum=0, for i=22h to 86h step 2, chksum=chksum+halfword[i], next i,
chksum=FFFFh AND NOT (chksum+chksum/10000h)
22h 1 In Snippet #0..8: Snippet number (0..8, same as [1Fh])
In Snippet #9: Number or players connected (0..16, may include master)
23h 1 Highest Snippet number (09h=Snippet #9)
24h 2 In Snippet #0..8: Snippet Size in bytes (62h for #0..7, 48h for #8)
In Snippet #9: Player Mask (eg. 000Fh=4-Players, including Master)
26h 62h Snippet Data (always 62h bytes, zeropadded if size<62h)
|
18h 70h Encrypted Nintendo Zone Beacon Info (see below) |
000h 32 Icon Palette (same as for ROM Cartridge Icon) 020h 512 Icon Bitmap (same as for ROM Cartridge Icon) 220h 1 Favorite color (00h..0Fh) ;\ 221h 1 Username Length (0..10) ; from firmware user settings 222h 20 Username (max 10 chars UCS-2) ;/ 236h 1 Max number of players (1..16, may include master) 237h 1 Unknown (00h) 238h 96 Game name (48 UCS-2) (same as 1st line of ROM Cartridge Title) 298h 192 Description (96 UCS-2) (same as further lines of ROM Cart Title) 358h 26 Unused (padding 48h-byte Snippet #8 to 62h-byte size) |
000h 2 Slave Mask (eg. 000Eh for three slaves) (initially 0000h, see note) 002h 1 Slave 1 Number*10h+Color (10h+color) ;\ 003h 1 Slave 1 Username Length (0..10) ; Slave 1 (if any) 004h 14h Slave 1 Username (max 10 chars UCS-2) ;/ 018h 1 Slave 2 Number*10h+Color (20h+color) ;\ 019h 1 Slave 2 Username Length (0..10) ; Slave 2 (if any) 01Ah 14h Slave 2 Username (max 10 chars UCS-2) ;/ 01Eh 1 Slave 3 Number*10h+Color (30h+color) ;\ 01Fh 1 Slave 3 Username Length (0..10) ; Slave 3 (if any) 020h 14h Slave 3 Username (max 10 chars UCS-2) ;/ ... |
Host sends beacon(s) Client sends an Authentication Request (AuthSeq=1) ;\Auth Host sends an Authentication Response (AuthSeq=2) ;/ Host sends beacon(s) Client sends an Association Request (with special SSID) ;\Assoc Host sends an Association Response ;/ Host sends beacon(s) and begins sending CMD/Data packets |
SSID for multiboot (20h-byte binary, non-ASCII): 00h 4 Game ID (0040xxxxh) (from Beacon Tag=DDh, entry 0Ch) 04h 2 Stream code (from Beacon Tag=DDh, entry 10h) 06h 1Ah Zerofilled |
00h 32 Access Point SSID (ASCII, zeropadded if shorter than 32 chars)
20h 10 Server ApNum (ASCII, ten digits/chars...?)
2Ah 2 Unknown (0001h)
2Ch 24 Server? Retailer ID string? (eg. "ShopName Country") (purpose=?)
44h 32 Access Point WEP key (0/5/13/16 bytes) or WPA/WPA2 password
64h 1 Unknown (00h for DSi, other values for 3DS)
65h 1 Access Point WEP mode (0=Open, 1/2/3=5/13/16 bytes)
(only on 3DS?: 4=WPA-TKIP, 5=WPA2-TKIP, 6=WPA-AES, 7=WPA2-AES)
66h 2 Flags (0003h)
Bit0: Enable Nintendo Zone content on DS(i)
Bit1: Enable Online Gaming and Friend list
Bit4: Enable Nintendo Zone Viewer on 3DS
Bit7: Block Nintendo eShop
Bit8: Block Internet Browser
68h 4 Unknown (uh, maybe zero?)
6Ch 2 Unknown (0428h)
6Eh 2 CRC16 with initial value 0 across [00h..6Dh] (or optionally 0=NoCrc)
|
Key[0..3] = "!SDW" (aka "WDS!" backwards) Key[4..7] = Last 4 bytes of the 6-byte BSSID from Beacon header |
| DS Wifi Nintendo DS Download Play |
Host sends NameRequests, client(s) send UsernameReply Host sends RSA frame, client(s) send RsaReply Host sends Data (Header/ARM9/ARM7 binaries), client(s) send DataReply Host sends Data, if it's the last packet, client(s) send GotAllReply Host sends Final message, client(s) send FinalReply Client(s) send Deauthentication with Reason=3 and jump to entrypoints |
00h 2 Value for W_CMD_REPLYTIME (0106h) 02h 2 Slave Flags, bit1..15 for slave 1..15 (1=connected) (eg. 0002h) 04h 1 Size in halfwords of Command+Data (ie. [06h..end, excluding footer]) 05h 1 Flags (11h=Normal, 01h=Footerless/Can be ignored, 00h=Deauth'ed?) 06h 1 Command (01h=NameRequest, 03h=RSA, 04h=DataPacket, 05h=Done) For Command 00h (Dummy, NameDone/RsaDone/DataDone): ;\ 07h 5 Unused (zerofilled) ; For Command 01h (NameRequest): ; 07h 5 Unused (zerofilled) ; For Command 02h (Error: Wrong Game Serial): ; 07h 5 Unused (zerofilled) ; Data For Command 03h (RSA): ; 07h E4h RSA Signature Frame (see below) ; EBh 5 Unused (zerofilled) ; For Command 04h (Data Packet): ; 07h 2 Unknown (zero) ; 09h 2 Packet Number (0=Header, 1..N=ARM9, N+1..Last=ARM7) ; 0Bh .. Data (1F8h bytes, or less for Header, or end of ARM7/ARM9) ; xxh 1 Unused (zero) ; For Command 05h (Final): ; 07h 5 Unused (garbage, same as last data command) ; For Command 06h (Unknown): ;normally not used, but ds download play ; 07h .. Unknown ;supports cmd 02h,03h,06h after username ;/ Extra Footer (usually present, unless Flags [05h].bit4=0): ;\ xxh 2 Slave Flags, again? (0002h) ;or 0000h ? ; Footer Note: The footer is usually present in most or all packets ; (Super Mario 64 DS has some dummy packets without footer) ;/ |
00h 1 Size in halfwords (of [02h..end])? (00h=Short, or 04h=Normal) 01h 1 Flags? (00h, 01h, 81h, or 80h) Short Dummy Reply: 02h - Nothing (can occur once or then during username or data transfer) Normal Dummy Reply: 02h 1 Reply Type (00h=Dummy) (can occur before username transfer) 03h 7 Unused (zerofilled) Username Reply: 02h 1 Reply Type (07h=Username) 03h 1 Username snippet number (00h..04h=Snippet #0..4) 04h 6 Snippet 0: Game ID (0040xxxxh), Favorite Color, UsernameLength(0-10) 04h 6 Snippet 1: Username Char[0,1,2] 04h 6 Snippet 2: Username Char[3,4,5] 04h 6 Snippet 3: Username Char[6,7,8] 04h 6 Snippet 4: Username Char[9], 0001h/0002h, C500h/0000h (There can be more (smaller) snippets if Tag=DDh [16h] is smaller than 8) Rsa Reply: 02h 1 Reply Type (08h=RsaReply) 03h 7 Unused (garbage, usually same as Username Snippet #2) Data Reply: 02h 1 Reply Type (09h=DataReply) 03h 2 Next wanted packet number (smallest missing packet number) 05h 2 Number of different packets received (0001h..Total-1) 07h 3 Unused (zerofilled) Got All Reply: 02h 1 Reply Type (0Ah=GotAllReply, no further packets needed) 03h 7 Garbage (old values from last Data Reply) Final Reply: 02h 1 Reply Type (0Bh=FinalReply, confirms the FinalCommand) 03h 7 Garbage (old values from last Data Reply) |
00h 2 Unknown/random? (eg. 0046h or 001Bh) 02h 2 Error Flags (bit1-15=No reply from Slave 1-15, eg. when AID_LOW=0) |
00h 4 ARM9 Entrypoint (usually 20008xxh)
04h 4 ARM7 Entrypoint (usually 2380000h) (or WRAM?)
08h 4 Zerofilled
0Ch 4 Header Destination (temp) (usually 27FFE00h)
10h 4 Header Destination (actual) (usually 27FFE00h)
14h 4 Header Size (160h)
18h 4 Zerofilled
1Ch 4 ARM9 Destination (temp) (usually 2000000h)
20h 4 ARM9 Destination (actual) (usually 2000000h)
24h 4 ARM9 Size
28h 4 Zerofilled
2Ch 4 ARM7 Destination (temp) (usually 22C0000h in Main RAM)
30h 4 ARM7 Destination (actual) (usually 2380000h) (or WRAM?)
34h 4 ARM7 Size
38h 4 Unknown (00000001h)
3Ch 4 Signature ID (61h,63h,01h,00h) (aka "ac", or backwards "ca") ;\
40h 80h Signature RSA (RSA signature in OpenPGP SHA1 format) ;
C0h 4 Signature Seed (same as value used to create RSA signature) ;/
(Nanostray:22AA9FC2h, Hedge:24272349h)
(Eragon:2512EE7Ah, TableHockey:02704DF6h)
C4h 20h Zerofilled (stored together with above in E4h-byte array)
|
00h 14h SHA1 on Header 14h 14h SHA1 on ARM9 bootcode 28h 14h SHA1 on ARM7 bootcode 3Ch 4 Signature Seed (same as the four bytes from [C0h]) |
0000h 160h Repaired Header (address/size/entrypoint for ARM9,ARM7,Icon,RSA) 0160h A0h Zerofilled 0200h 10h ID "DS DOWNLOAD PLAY" (8bit characters) 0210h 10h ID "----------------" (8bit characters) 0220h 160h Original Header (to be uploaded for RSA check) 0380h 10h ID "----------------" (8bit characters) 0390h 10h ID "Nintendo" (16bit characters) 03A0h 10h ID Zerofilled 03B0h 10h ID "----------------" (8bit characters) 03C0h .. Zerofilled |
27FFC40h 2 Boot Indicator (2=Booted from DS Download Play via Wifi) 27FFC42h 2 Beacon Size (0060h, based on Tag=DDh size: "(88h-08h+41h)/2") 27FFC44h 2 Looks like RSSI Signal Strength AND FEh (eg. 12h=Low, 82h=High) 27FFC46h 6 BSSID (master's MAC address) 27FFC4Ch 2 SSID Size? (0020h) 27FFC4Eh 4 SSID Game Serial ID (0040xxxxh) 27FFC52h 2 SSID Random Stream ID (xxxxh) 27FFC54h 1Ah SSID Padding? (zerofilled) 27FFC6Eh 2 Beacon Capabilities (0021h) 27FFC70h 2 Beacon Rates (bit0/1 = 1/2Mbit/s) (0003h) 27FFC72h 2 Beacon Rates (same as above) (0003h) 27FFC74h 2 Beacon Interval (00Cxh..00Dxh) 27FFC76h 2 Beacon TIM ListenInt (0002h) 27FFC78h 2 Beacon Channel (1, 7, or 13) 27FFC7Ah 04h Unknown (zerofilled) 27FFC7Eh 2 Unused? (zero) (not part of 3Ch-bytes at 27FFC42h) |
Game ID Players Title 00400136h 2 Over the Hedge (download contains a 2D minigame) 00400052h 2 Nanostray 00400011h 1-4 Super Mario 64 DS etc. (unknown if/which games support more than 4 players) |
Eragon Lara Croft Tomb Raider Legend Magnetica Metroid Prime Hunters Demo Submarine Tech Demo (and many trailers with non-playable movie clips) |
Allows to download some bootmenu, offering downloading demos/trailers? |
WifiMe - downloader patch for NDS firmware without RSA check? Unlaunch.dsi v2.1 - can patch RSA check in DSi's DS Download Play HaxxStation - uploader patch for Download Station to upload homebrew/hacks? |
100 Classic Books Absolute Chess (Nintendo DSiWare) Absolute Reversi (Nintendo DSiWare) Advance Wars: Dual Strike Age Of Empires: Mythologies America's Test Kitchen: Let's Get Cooking Animaniacs: Lights, Camera, Action! Arkanoid DS Art Academy Atari Greatest Hits Volume 1 Atari Greatest Hits Volume 2 Avatar, The Last Airbender: Into The Inferno Bakugan: Defenders Of The Core Battle Of Giants: Dinosaurs Battle Of Giants: Dragons Battle Of Giants: Mutant Insects Beyblade: Metal Fusion Big Bang Mini Big Brain Academy Bleach: Blade Of Fate, The Bleach: Dark Souls Boing! Docomodake DS Bomberman Bomberman Land Touch! Bomberman Land Touch! 2 Boogie Bookworm (retail version) Brain Age: Train Your Brain In Minutes A Day! Brain Age 2: More Training In Minutes A Day! Brain Assist Brain Voyage Bratz: Forever Diamondz Break 'Em All Burnout Legends Bust-A-Move DS Call Of Duty 4: Modern Warfare Candace Kane's Candy Factory Carnival Games Cars 2 Cars Mater-National Cars Race-O-Rama Cartoon Network Racing Chameleon Cheetah Girls, The: Passport To Stardom Chessmaster: The Art Of Learning Classic Word Games Club Penguin: Elite Penguin Force Club Penguin: Elite Penguin Force - Herbert's Revenge Clubhouse Games Clubhouse Games Express: Card Classics (Nintendo DSiWare) Clubhouse Games Express: Family Favorites (Nintendo DSiWare) Clubhouse Games Express: Strategy Pack (Nintendo DSiWare) Cookie & Cream Cooking Mama Cooking Mama 2: Dinner With Friends Cooking Mama 3: Shop & Chop C.O.R.E. Corvette Evolution GT Cosmo Fighters (Nintendo DSiWare) Crafting Mama Crash Boom Bang! Custom Robo Arena Dairojo! Samurai Defenders (Nintendo DSiWare) Deca Sports DS Diary Girl Diddy Kong Racing DS Dino Master: Dig, Discover, Duel DiRT 2 Disney Fairies: Tinker Bell DK Jungle Climber Dokapon Journey Draglade Dragon Ball Z: Harukanaru Densetsu Dragon Booster Dragon Quest Heroes: Rocket Slime Dreamer: Pop Star Dropcast Eco-Creatures: Save The Forrest Elite Beat Agents Everyday Soccer (Nintendo DSiWare) Ferrari Challenge: Trofeo Pirelli FIFA Soccer 06 FIFA Soccer 08 FIFA Soccer 09 FIFA Soccer 10 FIFA Street 3 FIFA World Cup 06 Final Fantasy Fables: Chocobo Tales Flash Focus: Vision Training In Minutes A Day Foto Frenzy Freedom Wings Fritz Chess Frogger: Helmet Chaos Gardening Mama Gauntlet Geometry Wars: Galaxies Godzilla: Unleashed Double Smash Golden Compass, The GoldenEye: Rogue Agent Grease GRID Gunpey DS Harry Potter And The Deathly Hallows, Part 1 Harry Potter And The Deathly Hallows, Part 2 Harry Potter And The Order Of The Phoenix Harvest Moon: Frantic Farming Hasbro Family Game Night Hearts Spades Euchre (Nintendo DSiWare) Heavy Armor Brigade High School Musical 2: Work This Out! Homie Rollerz Igor: The Game Imagine Babysitters Imagine Ballet Star Imagine Ice Champions Imagine Rock Star Imagine Teacher Intellivision Lives! Ivy The Kiwi? (retail version) Jeopardy Jewel Quest Expeditions Jumble Madness Kirby: Squeak Squad Kirby Super Star Ultra Konami Classics Series: Arcade Hits Labyrinth Learn Science Left Brain Right Brain Left Brain Right Brain 2 Legend Of Zelda, The: Phantom Hourglass Legend Of Zelda, The: Spirit Tracks Legendary Starfy, The LEGO Star Wars II: The Original Trilogy Little League World Series Baseball 2009 L.O.L. Lost In Blue 2 Lost In Blue 3 Lunar Knights Madagascar Madagascar: Escape 2 Africa Madden NFL 08 Madden NFL 09 Magnetica Mario & Sonic At The Olympic Games Mario & Sonic At The Olympic Winter Games Mario Hoops 3-On-3 Mario Kart DS Mario Party DS Mario Vs. Donkey Kong 2: March Of The Minis Marvel Super Hero Squad Math Play Mega Man ZX Advent Meteos Meteos: Disney Magic Metroid Prime Hunters Metroid Prime Pinball Might & Magic: Clash Of Heroes Mini Ninjas MLB Power Pros 2008 Monopoly/Boggle/Yahtzee/Battleship Monster Band Monster Bomber Monster Racers Monsters Vs Aliens MX Vs ATV Reflex My DoItAll My Frogger Toy Trials My Word Coach MySims MySims Agents MySims Kingdom MySims Party MySims Racing MySims SkyHeroes Nacho Libre Namco Museum DS Nanostray Nanostray 2 Need For Speed Carbon: Own The City Need For Speed: Nitro Need For Speed: ProStreet Need For Speed: Undercover Nervous Brickdown NEVES New Carnival Games New International Track & Field New Super Mario Bros. New York Times Crosswords, The Nicktoons: Attack Of The ToyBots Nicktoons: Battle For Volcano Island Ninjatown Over The Hedge PDC World Championship Darts Peggle Dual Shot Personal Trainer: Math Petz Dogz 2 Petz Dogz Fashion Phineas And Ferb Ride Again Phineas And Ferb: Across The 2nd Dimension Picross 3D Picross DS PICTOIMAGE Ping Pals Pirates: Duels On The High Seas Pirates Of The Caribbean: At World's End Planet 51: The Game Planet Puzzle League Plants Vs. Zombies Playmobil Knights Playmobil Pirates Pogo Island Point Blank DS Pokemon Mystery Dungeon: Explorers Of Sky Pokemon Trozei! Polar Bowler Polarium Pony Friends Pony Friends: Mini-Breeds Edition Pony Friends 2 Pop Island (Nintendo DSiWare) Pop Island - Paperfield (Nintendo DSiWare) Power Play Pool Prey The Stars Princess And The Frog, The Princess In Love Prism: Light The Way Pro Evolution Soccer 2008 Professional Fisherman's Tour: Northern Hemisphere Puchi Puchi Virus Puyo POP FEVER Puzzle De Harvest Moon Quest Trio, The QuickSpot Rabbids Go Home Race Driver: Create & Race Rafa Nadal Tennis Ratatouille Rayman Raving Rabbids 2 Rayman Raving Rabbids TV Party Ridge Racer DS Ringling Bros. and Barnum & Bailey Circus Rio Rock Revolution Rollin' Rascals RooGoo Attack! Rub Rabbits Rubik's World SBK: Snowboard Kids Scrabble Sega Casino Sega Superstars Tennis Shaun White Snowboarding Shining Stars: Super Starcade Shrek The Third Simpsons Game, The Skate It Solitaire Overload Sonic Colors Sonic Rush Sonic Rush Adventure Space Bust-A-Move Space Invaders Extreme Space Invaders Extreme 2 SpongeBob's Boating Bash Squishy Tank Star Fox Command Stitch Jam Style Lab: Makeover Super Black Bass Fishing Super Dodgeball Brawlers Super Mario 64 DS Super Monkey Ball: Touch & Roll Super Speed Machines Superman Returns: The Videogame Suzuki Super-Bikes II: Riding Challenge Tamagotchi Connection: Corner Shop Tamagotchi Connection: Corner Shop 2 Tamagotchi Connection: Corner Shop 3 Tank Beat Tetris DS Tetris Party Deluxe ThinkSmart Kids 8+ Thrillville: Off The Rails Tiger Woods PGA Tour 08 Tinker Bell And The Great Fairy Rescue Toon-Doku Top Gun Totally Spies! 2: Undercover Touch Darts Touchmaster 2 Touchmaster 3 Touchmaster: Connect TrackMania DS TrackMania Turbo Trioncube Tropix DS True Swing Golf Ultimate Mortal Kombat Ultimate Puzzle Games: Sudoku Edition USA Today Puzzle Craze Warhammer 40,000: Squad Command Whac-A-Mole Wild West, The Windy X Windham Winning Eleven: Pro Evolution Soccer 2007 WireWay Wizards Of Waverly Place Wordfish WordJong World Championship Games World Championship Poker: Deluxe Series World Cup Of Pool World Of Zoo Worms: Open Warfare Worms: Open Warfare 2 Xiaolin Showdown Yoshi Touch & Go Zendoku Zoo Keeper |
| DS Wifi IEEE802.11 Frames |
10..30 bytes MAC Header 0..2312 bytes Frame Body (in practice, network MTU is circa 1500 bytes max) 4 bytes Frame Check Sequence (FCS) (aka CRC32 on Header+Body) |
Size Content 2 Frame Control Field (FC) 2 Duration/ID 6 Address 1 (6) Address 2 (if any) (6) Address 3 (if any) (2) Sequence Control (if any) (6) Address 4 (if any) |
Bit Expl. 0-1 Protocol Version (0=Current, 1..3=Reserved) 2-3 Type (0=Managment, 1=Control, 2=Data, 3=Reserved) 4-7 Subtype (see next chapters) (meaning depends on above Type) 8 To Distribution System (ToDS) 9 From Distribution System (FromDS) 10 More Fragments 11 Retry 12 Power Managment (0=Active, 1=STA will enter Power-Safe mode after..) 13 More Data 14 Wired Equivalent Privacy (WEP) Encryption (0=No, 1=Yes) 15 Order |
0000h..7FFFh Duration (0-32767)
8000h Fixed value within frames transmitted during the CFP
(CFP=Contention Free Period)
8001h..BFFFh Reserved
C000h Reserved
C001h..C7D7h Association ID (AID) (1..2007) in PS-Poll frames
C7D8h..FFFFh Reserved
|
0 Group Flag (0=Individual Address, 1=Group Address) 1 Local Flag (0=Universally Administered Address, 1=Locally Administered) 2-23 22bit Manufacturer ID (assigned by IEEE) 24-47 24bit Device ID (assigned by the Manufacturer) |
00 09 BF xx xx xx NDS-Consoles (Original NDS with firmware v1-v5) 00 16 56 xx xx xx NDS-Consoles (Newer NDS-Lite with firmware v6 and up) 00 23 CC xx xx xx DSi-Consoles (Original DSi with early mainboard; nocash) 00 24 1E xx xx xx DSi-Consoles (Another DSi; scanlime) 40 F4 07 xx xx xx DSi-Consoles (with DWM-W024; nocash) E0 E7 51 xx xx xx DSi-Consoles (with DWM-W024; nocash/desoldered) CC 9E 00 xx xx xx DSi-Consoles (with J27H020; nocash) 03 09 BF 00 00 00 NDS-Multiboot: host to client (main data flow) 03 09 BF 00 00 10 NDS-Multiboot: client to host (replies) 03 09 BF 00 00 03 NDS-Multiboot: host to client (acknowledges replies) FF FF FF FF FF FF Broadcast to all stations (eg. Beacons) |
Bit Expl. 0-3 Fragment Number (0=First (or only) fragment) 4-15 Sequence Number |
3 bytes Initialization Vector (WEP IV) 1 byte Pad (6bit, all zero), Key ID (2bit) 1..? bytes Data (encrypted data) 4 bytes ICV (encrypted CRC32 across Data) |
| DS Wifi IEEE802.11 Managment Frames (Type=0) |
FC(2), Duration(2), DA(6), SA(6), BSSID(6), Sequence Control(2) |
Subtype Frame Body
0 Association request Capability, ListenInterval, SSID, SuppRates
1 Association response Capability, Status, AID, SuppRates
2 Reassociation request Capability, ListenInterval, CurrAP, SSID, SuppRates
3 Reassociation response Capability, Status, AID, SuppRates
4 Probe request SSID, SuppRates
5 Probe response Same as for Beacon (but without TIM)
8 Beacon Timestamp,BeaconInterval,Capability,SSID,SuppRates,
FH Parameter Set (when using Frequency Hopping),
DS Parameter Set (when using Direct Sequence),
CF Parameter Set (when supporting PCF),
IBSS Parameter Set (when in an IBSS),
TIM (when generated by AP)
9 Announcement traffic indication message (ATIM) Body is "null" (=none?)
A Disassociation ReasonCode
B Authentication AuthAlgorithm, AuthSequence, Status, ChallengeText
C Deauthentication ReasonCode
|
Timestamp: value of the TSFTIMER (see 11.1) of a frame's source. Uh? |
Current AP (Access Point): MAC Address of AP with which station is associated |
Capability Information (see list below) Status code (see list below) (0000h=Successful, other=Error code) Reason code (see list below) (Error code) Association ID (AID) (C000h+1..2007) Authentication Algorithm (0=Open System, 1=Shared Key, 2..FFFFh=Reserved) Authentication Transaction Sequence Number (Open System:1-2, Shared Key:1-4) Beacon Interval (Time between beacons, N*1024 us) Listen Interval (see note below) |
ID LEN Expl.
00h 00h-20h SSID Service Set Identity (LEN=0 for broadcast SSID) (ASCII)
01h 01h-08h Supported rates; each (nn AND 7Fh)*500kbit/s, bit7=flag
02h 05h FH (Frequency Hopping) Parameter Set
DwellTime(16bit), HopSet, HopPattern, HopIndex
03h 01h DS (Distribution System) Parameter Set; Channel (01h..0Eh)
04h 06h CF Parameter Set; Count, Period, MaxDuration, RemainDuration
05h 04h..FEh TIM; Count,Period,Control, 1-251 bytes PartialVirtualBitmap
06h 02h IBSS Parameter Set; ATIM Window length (16bit)
07h-0Fh - Reserved
(07h) .. 802.11d Country
(08h) .. 802.11d Hopping Pattern Params
(09h) .. 802.11d Hopping Pattern Table
(0Ah) .. 802.11d Request
10h 02h..FEh Challenge text; 1-253 bytes Authentication data
(Used only for Shared Key sequence no 2,3)
(none such for Open System)
(none such for Shared key sequence no 1,4)
11h-1Fh - Reserved for challenge text extension
20h-FFh - Reserved
(20h) .. 802.11h Power Constraint
(21h) .. 802.11h Power Capability
(22h) .. 802.11h TPC Request (Transmit Power Control)
(23h) .. 802.11h TPC Report
(24h) .. 802.11h Supported Channels
(25h) .. 802.11h Channel Switch Announcement
(26h) .. 802.11h Measurement Request
(27h) .. 802.11h Measurement Report
(28h) .. 802.11h Quiet
(29h) .. 802.11h IBSS DFS
2Ah .. 802.11g ERP Information (spotted in newer beacons)
30h var 802.11i Reserved but used for WPA2 RSNIE <-- officially
32h .. 802.11g Extended Supported Rates (spotted in newer beacons)
DDh var Reserved but used for WPA RSNIE <-- vendor specific
DDh var Reserved but used by Nintendo for NDS-Multiboot beacons
2Dh .. Unknown (spotted in newer beacons)
2Fh .. Unknown (spotted in newer beacons)
3Dh .. Unknown (spotted in newer beacons)
7Fh .. Unknown (spotted in newer beacons)
|
Bit0 ESS Bit1 IBSS Bit2 CF-Pollable Bit3 CF-Poll Request Bit4 Privacy Bit5 Short Preamble (IEEE802.11b only) Bit6 PBCC (IEEE802.11b only) Bit7 Channel Agility (IEEE802.11b only) Bit5-7 Reserved (0) (original IEEE802.11 specs) Bit8-15 Reserved (0) |
... used to indicate to the AP how often an STA wakes to listen to Beacon management frames. The value of this parameter is the STA's Listen Interval parameter of the MLME-Associate. request primitive and is expressed in units of Beacon Interval. |
00h Reserved
01h Unspecified reason
02h Previous authentication no longer valid
03h Deauthenticated because sending station is leaving (or has left) IBSS
or ESS
04h Disassociated due to inactivity
05h Disassociated because AP is unable to handle all currently associated
stations
06h Class 2 frame received from nonauthenticated station
07h Class 3 frame received from nonassociated station
08h Disassociated because sending station is leaving (or has left) BSS
09h Station requesting (re)association is not authenticated with responding
station
0Ah..FFFFh Reserved
|
00h Successful
01h Unspecified failure
02h..09h Reserved
0Ah Cannot support all requested cap's in the Capability Information field
0Bh Reassociation denied due to inability to confirm that association exists
0Ch Association denied due to reason outside the scope of this standard
0Dh Responding station doesn't support the specified authentication algorithm
0Eh Received an Authentication frame with authentication transaction sequence
number out of expected sequence
0Fh Authentication rejected because of challenge failure
10h Authentication rejected due to timeout waiting for next frame in sequence
11h Association denied because AP is unable to handle additional associated
stations
12h Association denied due to requesting station not supporting all of the
data rates in the BSSBasicRateSet parameter
13h Association denied due to requesting station not supporting
the Short Preamble option (IEEE802.11b only)
14h Association denied due to requesting station not supporting
the PBCC Modulation option (IEEE802.11b only)
15h Association denied due to requesting station not supporting
the Channel Agility option (IEEE802.11b only)
13h-15h Reserved (original IEEE802.11 specs)
16h..FFFFh Reserved
|
| DS Wifi IEEE802.11 Control and Data Frames (Type=1 and 2) |
Subtype Frame Header 0-9 Reserved - - - - A Power Save (PS)-Poll FC AID BSSID TA B Request To Send (RTS) FC Duration RA TA C Clear To Send (CTS) FC Duration RA - D Acknowledgment (ACK) FC Duration RA - E Contention-Free (CF)-End FC Duration RA BSSID F CF-End + CF-Ack FC Duration RA BSSID |
FC, Duration/ID, Address 1, Address 2, Address 3, Sequence Control, Address 4 (only on From DS to DS), Frame Body, FCS. |
Frame Control Address 1 Address 2 Address 3 Address 4 From STA to STA DA SA BSSID - From DS to STA DA BSSID SA - From STA to DS BSSID SA DA - From DS to DS RA TA DA SA |
0 Data 1 Data + CF-Ack 2 Data + CF-Poll 3 Data + CF-Ack + CF-Poll 4 Null function (no data) 5 CF-Ack (no data) 6 CF-Poll (no data) 7 CF-Ack + CF-Poll (no data) 8-F Reserved |
| DS Wifi WPA/WPA2 Handshake Messages (EAPOL) |
00h 2 Version/Type (or Type/Version?) (01 03) 02h 2 Length of [04h..end] (005Fh+LEN) ;BIG-ENDIAN 04h 1 Descriptor Type (FEh=WPA, 02h=WPA2) 05h 2 Key Information (flags, see below) ;BIG-ENDIAN 07h 2 Key Length (0=None, 20h=TKIP, 10h=CCMP, 05h/0Dh=WEP) ;BIG-ENDIAN 09h 8 Key Replay Counter (usually 0 or 1 in first message) ;BIG-ENDIAN 11h 32 Key Nonce (ANonce/SNonce) 31h 16 Key Data IV (RC4 uses IV+KEK) (not used for AES-Key-Wrap) 41h 8 Key RSC (TSC/PN) (whatever, for GTK) ;LITTLE-ENDIAN 49h 8 Reserved (zerofilled) 51h 16 Key MIC on [00h..end] (with MIC initially zerofilled) ;HMAC 61h 2 Key Data Length (LEN) (00 nn) ;BIG-ENDIAN 63h LEN Key Data (can be encrypted in certain messages) |
0-2 Key Descriptor Version (1=WPA/MD5/RC4, 2=WPA2/SHA1/AESkeywrap) 3 Key Type (0=Group, 1=Pairwise) 4-5 Reserved (0) or WPA Group Key Index (1 or 2) (zero for WPA2) 6 Install (0=No, 1=Yes, configure temporal key) 7 Key Ack (0=No, 1=Yes, AP wants a reply; with same Key Replay Counter) 8 Key MIC (0=No, 1=Yes, key frame contains MIC) 9 Secure (0=No, 1=Yes, initial key-exchange complete) 10 Error (0=No, 1=Yes, MIC failure and Request=1) 11 Request (0=No, 1=Yes, request AP to invoke a new handshake) 12 Encrypted(0=No, 1=Yes, Key Data is encrypted; via RC4 or AESkeywrap) 13-15 Reserved (0) |
00h 1 Element ID (for WPA: DDh=RSNIE - for WPA2: 30h=RSNIE, DDh=KDE) 01h 1 Element Length of [02h..end] 02h .. Element Data (OUI's etc.) |
EAPOL Descriptor Type values WPA WPA2 Meaning FEh 02h Indicates if ElementIDs and OUIs are WPA or WPA2 EAPOL Key Information flags/values 0089h 008Ah Handshake #1 ;\ 0109h 010Ah Handshake #2 ; 4-way Handshake 01C9h 13CAh Handshake #3 ; 0109h(again) 030Ah Handshake #4 ;/ 0391h/03A1h 1382h Handshake #5 ;\Group Key Handshake 0311h/0321h 0302h Handshake #6 ;/ EAPOL Key Data Element IDs DDh 30h Element ID for RSNIE (Robust Network Security info) - DDh Element ID for KDE (Key Data Encapsulation) - DDh Element ID for padding (followed by 00h-bytes) RSNIE Prefix OUI's (WPA only): 00-50-F2-01 - Element Vendor OUI for RSNIE RSNIE Group Cipher suite selector OUI's (aka Multicast): 00-50-F2-01 00-0F-AC-01 RSNIE Group Cipher WEP-40 (default for US/NSA) 00-50-F2-02 00-0F-AC-02 RSNIE Group Cipher TKIP (default for WPA) 00-50-F2-04 00-0F-AC-04 RSNIE Group Cipher CCMP (default for WPA2) 00-50-F2-05 00-0F-AC-05 RSNIE Group Cipher WEP-104 (default for WEP) RSNIE Pairwise Cipher suite selector OUI's (aka Unicast): 00-50-F2-00 00-0F-AC-00 RSNIE Pairwise Cipher None (WEP, Group Cipher only) 00-50-F2-02 00-0F-AC-02 RSNIE Pairwise Cipher TKIP (default for WPA) 00-50-F2-04 00-0F-AC-04 RSNIE Pairwise Cipher CCMP (default for WPA2) RSNIE Authentication AKM suite selector OUI's : 00-50-F2-01 00-0F-AC-01 RSNIE Authentication over IEEE 802.1X (radius?) 00-50-F2-02 00-0F-AC-02 RSNIE Authentication over PSK (default/home use) KDE Key Data Encapsulation OUI's (WPA2 only): - 00-0F-AC-01 KDE GTK (followed by 2+N bytes) - 00-0F-AC-02 KDE STAKey (followed by 2+6+N bytes) - 00-0F-AC-03 KDE MAC address (followed by 6 bytes) - 00-0F-AC-04 KDE PMKID (followed by 16 bytes) |
WPA2 RSNIE (Robust Network Security Information Element): 00h 1 Element ID (30h=RSNIE for WPA2) 01h 1 Element Len of [02h..end] (usually 14h) 02h 2 RSNIE Version 1 (01 00) ;WHATEVER-ENDIAN? 04h 4 RSNIE Group Cipher Suite OUI (CCMP) (00 0F AC 04) 08h 2 RSNIE Pairwise Cipher Suite Count (1) (01 00) ;LITTLE-ENDIAN 0Ah 4 RSNIE Pairwise Cipher Suite OUI (CCMP) (00 0F AC 04) 0Eh 2 RSNIE Authentication Count (1) (01 00) ;LITTLE-ENDIAN 10h 4 RSNIE Authentication OUI (PSK) (00 0F AC 02) 14h 2 RSNIE Capabilities (00 00) ;LITTLE-ENDIAN? 16h (2) RSNIE Optional PMKID Count ;\usually none such ;LITTLE-ENDIAN 18h (16)RSNIE Optional PMKID's ;/ WPA RSNIE (Robust Network Security Information Element): 00h 1 Element ID (DDh=Vendor/RSNIE for WPA) 01h 1 Element Len of [02h..end] (usually 16h or 18h) 02h 4 Element Vendor OUI for RSNIE (00 50 F2 01) ;<-- WPA only 06h 2 RSNIE Version value? (1) (01 00) ;WHATEVER-ENDIAN? 08h 4 RSNIE Mcast OUI (TKIP) (00 50 F2 02) 0Ch 2 RSNIE Ucast Count (1) (01 00) ;LITTLE-ENDIAN 0Eh 4 RSNIE Ucast OUI (TKIP) (00 50 F2 02) 12h 2 RSNIE Auth AKM Count (1) (01 00) ;LITTLE-ENDIAN 14h 4 RSNIE Auth AKM OUI (PSK) (00 50 F2 02) 18h (2) RSNIE Capabilities maybe? (00 00) ;LITTLE-ENDIAN? RSN Capabilities flags (usually 0000h) (also spotted: 0C 00): 0 RSN Pre-Auth capabilities 1 RSN No Pairwise capabilities 2-3 RSN PTKSA Replay Counters (0..3 = 1,2,4,16 replay counters) 4-5 RSN GTKSA Replay Counters (0..3 = 1,2,4,16 replay counters) 6 Managment Frame Protection Required 7 Managment Frame Protection Capable 8 Joint Multi-band RSNA 9 PeerKey Enabled 10 SPP A-MSDU Capable 11 SPP A-MSDU Required 12 PBAC 13 Ext Key ID for Unicast 14-15 Reserved (0) |
WPA2 KDE GTK (Key Data Encapsulation for Group Key, in encrypted Key Data): 00h 1 Element ID (DDh=KDE for WPA2) 01h 1 Element Len (16h) 02h 4 KDE OUI GTK (00-0F-AC-01) (occurs in message 3/5) 06h 1 KDE GTK Key ID (01h or 02h) ;bit2: Tx ? 07h 1 KDE GTK Reserved (00h) 08h 16 KDE GTK Key GTK (for Key ID from above byte [06h]) WPA2 KDE PKMID (Key Data Encapsulation for PKMID) (optional, not needed): 00h 1 Element ID (DDh=KDE for WPA2) 01h 1 Element Len (14h) 02h 4 KDE OUI PMKID (00-0F-AC-04) (optionally occurs in message 1) 06h 16 KDE PMKID (useless checksum on PMK, sometimes exposed in message 1) WPA2 KDE Padding (for padding Key Data to Nx8 bytes for AES-Key-wrap): 00h 1 Element ID (DDh=KDE for WPA2) 01h 0-6 Padding (00h) (aka Element Len=00h) WPA GTK (raw Group Key; without Element ID or KDE-style encapsulation): 00h 16 Key GTK (for Key ID from Key Information bit4-5) (in message 5) |
| DS Wifi WPA/WPA2 Keys and MICs |
PSK Preshared Key (based on password and SSID) PMK Pairwise Master Key (same as PSK) PTK Pairwise Transient Key (based on PMK, AA, SPA, ANonce, SNonce) KCK EAPOL Key Confirmation Key (PTK.bit0..127) ;for handshake MIC's KEK EAPOL Key Encryption Key (PTK.bit128..255) ;for handshake Key Data TK Temporal Key (TKIP:PTK.bit256..511, CCMP:PTK.bit256..383) GMK Group Master Key (don't care, used only internally by the access point) GTK Group Transient Key (for multicast/broadcast) (based on GMK, AA, GNonce) |
password ASCII password for the Wifi network SSID ASCII name of access point AA MAC address of access point (BSSID) SPA MAC address of DSi console Anonce Random number from access point (handshake message #1 and #3) Snonce Random number from console (handshake message #2) Gnonce Random number internally used by access point (don't care) |
MIC Message Integrity Code, checksum on EAPOL messages PMKID PMK ID, checksum on PMK and AA, SPA (optional, don't care) |
for i=0 to (dstlen-1)/14
call SHA1HMAC(src,srclen, key,keylen, tmpdst)
tmpsum[0..13] = tmpdst[0..13]
for j=1 to numrounds-1 ;only if numrounds>1
tmpsrc[0..13] = tmpdst[0..13], tmpsrclen=14
call SHA1HMAC(tmpsrc,tmpsrclen, key,keylen, tmpdst)
tmpsum[0..13] = tmpsum[0..13] XOR tmpdst[0..13]
next j
src[srclen-1] = src[srclen-1] + 01h ;increase last byte of src
len=min(14,(dstlen-i*14))
dst[i*14+(0..(len-1))] = tmpsum[0..(len-1)]
next i
src[srclen-1] = src[srclen-1] - (dstlen+13)/14 ;undo increments, if desired
|
key = password, keylen = len(password) ;ASCII string src = ssid + bytes(00h,00h,00h,01h), srclen = len(ssid)+4 ;ASCII string dst = PSK, dstlen = 32, numrounds=4096 call PRF(key,keylen, src,srclen, dst,dstlen, numrounds) PMK=PSK |
src[0..21] = "Pairwise key expansion" src[22] = byte(00h) src[23..28] = min(AA,SPA) ;\MAC addresses (AA=BSSID, SPA=console) src[29..34] = max(AA,SPA) ;/ src[35..66] = min(ANonce,SNonce) ;\nonces from 4-way handshake message 1+2 src[67..98] = max(ANonce,SNonce) ;/ src[99] = byte(00h) srclen = 22+1+6+6+32+32+1 = 100 key=PSK, keylen=32, numrounds=1 dst=PTK, dstlen=64 ;WPA needs dstlen=64 (WPA2 would also work with len=48) call PRF(key,keylen, src,srclen, dst,dstlen, numrounds) KCK = PTK[00h..0Fh] ;-for EAPOL handshake MIC checksums KEK = PTK[10h..1Fh] ;-for EAPOL handshake Key Data decryption TK.key = PTK[20h..2Fh] ;-for data packets TX.tx = PTK[30h..37h] ;\needed for WPA/TKIP only (not WPA2/AES) TX.rx = PTK[38h..3Fh] ;/ TK.keyindex = 0 |
GTK.key = GTK[00h..0Fh] ;-for data packets GTX.tx = GTK[10h..17h] ;\needed for WPA/TKIP only (not WPA2/AES) GTX.rx = GTK[18h..1Fh] ;/ GTK.keyindex = 1 or 2 ;WPA: from EAPOL Key Information bit4-5 GTK.keyindex = 1 or 2 ;WPA2: from EAPOL Key Data KDE entry |
oldmic = EAPOL[51h..60h] EAPOL[51h..60h] = zerofill src=EAPOL, srclen=EAPOL[02h]*100h+EAPOL[03h] key=KCK, keylen=16 if (EAPOL[06h] AND 07h)=1 then call MD5HMAC(src,srclen, key,keylen, dst) if (EAPOL[06h] AND 07h)=2 then call SHA1HMAC(src,srclen, key,keylen, dst) newmic = dst[0..0Fh] ;16-byte MD5 result, or first 16byte of SHA1 result EAPOL[51h..60h] = newmic if newmic <> oldmic then error ;when verifying MIC |
key=PMK, keylen=32 src[0..7] = "PMK Name" src[8..13] = AA ;aka MAC address of access point (BSSID) src[14..19] = SPA ;aka MAC address of console srclen = 8+6+6 = 20 call SHA1HMAC(src,srclen, key,keylen, dst) PMKID = dst[0..0Fh] ;first 16byte of SHA1 result |
src[0..18] = "Group key expansion" src[19] = byte(00h) src[20..25] = AA ;MAC address (AA=BSSID) src[26..57] = GNonce ;whaever random/timer/index src[58] = byte(00h) srclen = 19+1+6+32+1 = 59 key=GMK, keylen=32, numrounds=1 ;whatever random key dst=GTK, dstlen=32 call PRF(key,keylen, src,srclen, dst,dstlen, numrounds) |
| DS Wifi WPA/WPA2 Encryption |
Encrypt/Decrypt WPA/WEP packets --> RC4 (Rivest Cipher 4 aka ARC4) Encrypt/Decrypt WPA EAPOL key data --> RC4 (Rivest Cipher 4 aka ARC4) Encrypt/Decrypt WPA2 EAPOL key data --> AES-Key-Wrap/Unwrap Encrypt/Decrypt WPA2 packets --> AES-CCMP (AES-CTR-with-CBC-MAC) |
RC4(src,dst,len,preskip,key,keylen):
for i=0 to FFh, sbox[i]=i, next i ;-clear sbox
j=0 ;\
for i=0 to FFh ;
j=(j+sbox[i]+key[i mod keylen]) and FFh ; apply key
swap(sbox[i],sbox[j] ;
next i ;/
i=0, j=0
for k=1 to preskip+len
i=(i+1) and FFh, j=(j+sbox[i]) and FFh, swap(sbox[i],sbox[j])
if preskip>0 then preskip=preskip-1
else [dst]=[src] xor sbox[(sbox[i]+sbox[j]) and FFh], dst=dst+1, src=src+1
next k
parameters for WEP/WPA packets (done by hardware):
key=iv(3)+password(5/13), keylen=3+5/13 ;WEP Key=WEP.IV+Password
key=iv(3)+from PTK???, keylen=3+??? ;WPA Key=WEP.IV+???
src=data(n)+icv(4), srclen=n+4 ;src, for WEP
src=data(n)+mic(8)+icv(4), srclen=n+8+4 ;src, for WPA
preskip=0
parameters for WPA EAPOL key data (requires software implementation):
key=EAPOL[31h..40h]+KEK[00h..0Fh], keylen=10h+10h ;Key = EAPOL Key IV + KEK
src=EAPOL+63h, srclen=bigendian(EAPOL[61h]) ;src, for WPA
preskip=100h
parameters for 70h-byte block in Nintendo Zone beacons (by software):
key="!SDW"+LastFourBytesOf(BSSID), keylen=8
src=BeaconTagDDh[18h..87h], srclen=70h
preskip=0
|
AES-Key-Wrap/Unwrap(src,dst,len,key,keylen,mode) (for WPA2 EAPOL Key Data)
if (len and 7)<>0 then error ;must be multiple of 8 ;-verify len
aes_setkey(mode,key,keylen) ;-init key
if mode=ENCRYPT and [src+00h..07h]<>A6A6A6A6A6A6A6A6h then error ;-verify IV
if mode=ENCRYPT then org=dst+8, count=1 ;-for wrap
if mode=DECRYPT then org=dst+len-8, count=((len-8)/8)*6 ;-for unwrap
[dst+0..len-1] = [src+0..len-1] ;copy IV+DATA to dst
[tmp+00h..07h] = [dst+00h..07h] ;read IV from dst+0
for i=1 to 6
ptr=org
for j=1 to (len-8)/8
[tmp+08h..0Fh] = [ptr+00h..07h] ;read DATA from dst+index
if mode=ENCRYPT then aes_crypt_block(ENCRYPT,tmp,tmp) ;encrypt tmp
[tmp+07h]=[tmp+07h] xor count ;adjust byte[7]
if mode=DECRYPT then aes_crypt_block(DECRYPT,tmp,tmp) ;decrypt tmp
[ptr+00h..07h] = [tmp+08h..0Fh] ;writeback DATA to dst+index
if mode=ENCRYPT then ptr=ptr+8, count=count+1
if mode=DECRYPT then ptr=ptr-8, count=count-1
next j
next i
[dst+00h..07h] = [tmp+00h..07h] ;writeback IV to dst+0
if mode=DECRYPT and [dst+00h..07h]<>A6A6A6A6A6A6A6A6h then error ;-verify IV
Parameters for Wrap/Unwrap:
mode=ENCRYPT ;<-- for Wrap (encrypt, used by access points)
mode=DECRYPT ;<-- for Unwrap (decrypt, used by clients)
key=KEK, keylen=10h bytes (128bit)
src=EAPOL+63h, srclen=bigendian(EAPOL[61h])
|
.. MAC Header ;-Normal Header 1 TSC1 ;\ WEPSeed[1]=(TSC1 OR 20h) AND 7Fh 1 WEPSeed[1] ; WEP IV and Flags 1 TSC0 (LSB) ; (Flags: bit0-4=Rsvd, bit5=ExtIV, bit6-7=KeyID) 1 Flags ;/ (bit5: 0=No/WEP, 1=Yes/TKIP) 1 TSC2 ;\ 1 TSC3 ; WPA Extended IV 1 TSC4 ; 1 TSC5 (MSB) ;/ .. Data ;-Normal Data ;\ 8 MIC ;-WPA MIC "Michael" ; encrypted area 4 ICV ;-WEP ICV ;/ 4 FCS ;-Normal FCS |
.. MAC Header ;-Normal Header 1 PN0 (LSB) ;\ 1 PN1 ; CCMP Header (IV and Flags) 1 Rsvd ; (Flags: bit0-4=Rsvd, bit5=ExtIV, bit6-7=KeyID) 1 Flags ; (bit5: 0=No/WEP, 1=Yes/TKIP) 1 PN2 ; 1 PN3 ; 1 PN4 ; 1 PN5 (MSB) ;/ .. Data ;-Normal Data ;\encrypted area 8 MIC ;-CCMP MIC "AES MAC?" ;/ 4 FCS ;-Normal FCS |
6 DA 6 SA 1 Priority (0) (reserved for future) 3 Zero (0) (also reserved for future) .. Data 8 MIC (M0..M7) (aka L0..L3, R0..R3) |
TTAK = Phase1 (TK, TA, TSC) WEP seed = Phase2 (TTAK, TK, TSC) |
| DS Wifi FFC ID |
https://fccid.io/BKE - Nintendo https://fccid.io/EW4 - Mitsumi https://fccid.io/MCL - Hon Hai (Foxconn) |
https://fccid.io/EW4-AGBWA GBA ;\GBA wireless adaptor https://fccid.io/EW4-OXYWA GBA-Micro ;/(not wifi/wlan compatible) https://fccid.io/BKENTR001 NDS (non-remove-able board) https://fccid.io/BKEUSG-001 NDS-Lite (old remove-able board, with MM3155) https://fccid.io/EW4DWMW006 NDS-Lite (new remove-able board, with MM3218) https://fccid.io/BKERVL036 Wii https://fccid.io/EW4DWMW004 Wii (mitsumi) (also W016, and maybe W014 ?) https://fccid.io/MCLJ27H010 Wii (foxconn) (also H003 ?) https://fccid.io/EW4DWMW015 DSi (old wifi board, mitsumi) https://fccid.io/EW4DWMW024 DSi (new wifi board, mitsumi) https://fccid.io/MCLJ27H020 DSi (new wifi board, foxconn) https://fccid.io/EW4DWMW028 3DS (mitsumi) https://fccid.io/MCLJ27H023 3DS (foxconn) https://fccid.io/MCLJ27H02301 2DS (foxconn) (also in 3DS XL) https://fccid.io/BKERED001 New3DS (on mainboard) |
1 MX_SD_CLK 2 GND 3 GND 4 VDD_18 5 SDIO_DATA0 6 VDD_18 7 SDIO_DATA3 8 GND 9 SDIO_DATA1 10 VDD_33 11 SDIO_CMD 12 VDD_33 13 SDIO_DATA2 14 GND 15 JTAG_TDO 16 ATH_TX_H 17 JTAG_TMS 18 SYS_RST_L 19 GND 20 JTAG_TDI 21 CLK32k 22 JTAG_TCK 23 GND 24 JTAG_TRST_L 25 NC(VDD28_TP) 26 SEL_ATH_L 27 SPI_CS2 28 W_B /FLASH_WP 29 BBP_SLEEP 30 SPI_CLK 31 RF_SLEEP 32 SPI_DO MISO 33 RF_SCS 34 SPI_DI MOSI 35 BBP_SCS 36 CCA 37 BB_RF_SDO 38 RXPE 39 BB_RF_SDI 40 TRDATA 41 BB_RF_SCLK 42 GND 43 NC(VDD18_TP) 44 TRCLK 45 GND 46 TRRDY 47 MCLK 48 TXPE 49 GND 50 RESET |
1 GND 16 +3.3V 2 TXPE 17 GND 3 RXPE 18 RF_SCS 4 CCA 19 BBP_SLEEP 5 TRRDY 20 BBP_SCS 6 GND 21 RF_SLEEP 7 TRCLK 22 RESET 8 TRDATA 23 GND 9 GND 24 SPI_CLK 10 BB_RF_SDO 25 SPI_DI MOSI 11 BB_RF_SDI 26 SPI_DO MISO 12 BB_RF_SCLK 27 W_B /FLASH_WP 13 GND 28 SPI_CS2 14 MCLK 29 LD ? 15 GND 30 GND |
1 GND 12 VDD3.3 2 SDIO_DATA_2 13 GND 3 SDIO_DATA_1 14 GPIO_0 4 GND 15 GND 5 SDIO_CLK 16 SDIO_DATA_3 6 GND 17 SDIO_DATA_0 7 GPIO_1 18 GND 8 GND 19 SDIO_CMD 9 N.C.(VDD1.8) 20 GND 10 N.C.(VDD1.8) 21 ANT_A (MAIN) 11 VDD3.3 22 ANT_B (AUX) |
1 MCLK 2 RF_CSRF 3 GND 4 BB_CSBB 5 RXPE 6 BB_RF_SDIN 7 TXPE 8 BB_RF_SDOUT 9 CCA 10 BB_RF_SCK 11 TRDATA 12 GND 13 TRCLK 14 BBP_SLEEP_L 15 TRRDY 16 RF_SLEEP_L 17 TRST_L 18 SEL_ATH_L 19 GND 20 GND 21 SDIO_DATA_0 22 JTAG_TDO 23 SDIO_DATA_1 24 JTAG_TMS 25 SDIO_DATA_2 26 JTAG_TDI 27 SDIO_DATA_3 28 JTAG_TCK 29 GND 30 SPI_CS2 31 SDIO_CLK 32 W_B /FLASH_WP 33 GND 34 SPI_CLK 35 SDIO_CMD 36 SPI_DO MISO 37 UART_TXD 38 SPI_DI MOSI 39 UART_RXD 40 SYS_RST_L 41 GND 42 ATH_TX_H 43 CLK32k 44 RESET 45 GND 46 GND 47 VDD_18 48 VDD_33 49 VDD_18 50 VDD_33 |
| DS Wifi Dslink/Wifiboot Protocol |
PC sends UDP announce message (repeatedly, as broadcast) ;\ console does TCP listen (if it isn't already listening) ; UDP and console sends UDP reply message (repeatedly, to PC) ; listen/accept PC does TCP connect (upon UDP reply) ; console does TCP accept (upon TCP connect) ;/ |
type NDS/DSi 3DS.firm 3DS.3dsx 3DS.gba announce "dsboot" "3dsfirmboot" "3dsboot" "gbaboot" reply "bootds" "bootfirm3ds" "boot3ds" "bootgba" |
PC sends NDS header (170h bytes) ;SMALLER ;\ PC sends Info Block (90h bytes) ;NEW ; console sends 32bit response word (4 bytes) ; PC sends Icon/Title (optional, if response.bit17) ;NEW ; PC sends DSi header (1000h bytes, if response.bit16) ; TCP transfer PC sends ARM7 bootcode ; PC sends ARM9 bootcode ; PC sends ARM7i bootcode (optional, if response.bit16) ; PC sends ARM9i bootcode (optional, if response.bit16) ; PC sends commandline 32bit length (00000000h=none) ; PC sends commandline string (if any) ;/ |
PC sends FIRM header (200h bytes) ;\ PC sends Info Block (90h bytes) ; console sends 32bit response word (4 bytes) ; PC sends Icon/Title (optional, if response.bit17) ; PC sends Logo (optional, if response.bit18) ; TCP transfer PC sends Banner (optional, if response.bit19) ; PC sends FIRM section 0 ; PC sends FIRM section 1 ; PC sends FIRM section 2 ; PC sends FIRM section 3 ; PC sends commandline 32bit length (0=none) ; PC sends commandline string (if any) ;/ |
PC sends GBA Header (C0h bytes) ;\ PC sends Info Block (90h bytes) ; PC sends GBA Footer (360h bytes) ; console sends 32bit response word (4 bytes) ; TCP transfer ;PC sends Icon/Title (optional, if response.bit17) ; ;PC sends Logo (optional, if response.bit18) ; ;PC sends Banner (optional, if response.bit19) ; PC sends GBA ROM-Image ; PC sends commandline 32bit length (0=none) ; PC sends commandline string (if any) ;/ |
0-x Error flags 16 Request DSi header and ARM7i/ARM9i blocks (DSi) 17 Request Icon/Title (NDS/DSi/3DS) 18 Request Logo (3DS) 19 Request Banner (3DS) 20-31 Reserved (0) |
00h 8 Overall ID "BootINFO" (if other: ignore all entries below) 08h 24 Uploader name/version, zeropadded (eg. "nocash wifiboot v2.6") 20h 1 Time Seconds (BCD, 00h..59h) ;\ 21h 1 Time Minutes (BCD, 00h..59h) ; current time (local timezone) 22h 1 Time Hours (BCD, 00h..23h) ; (for updating lost RTC time) 23h 1 Time DayOfWeek (0..6, 0=Monday) ; (or all zeroes = none) 24h 1 Time Day (BCD, 01h..31h) ; 25h 1 Time Month (BCD, 01h..12h) ; 26h 1 Time Year (BCD, 00h..99h) ; 27h 1 Time Century (BCD, 00h..99h) ;/ 28h 4 Icon/Title Size (0=None, 840h/940h/A40h/23C0h=NDS/DSi, 36C0h=3DS) 2Ch 4 Logo Size (0=None, Other=3DS only) 30h 4 Banner Size (0=None, Other=3DS only) 34h 5Ch Reserved (0) |
| DS Xboo |
Console Pin/Names Parallel Port Pin/Names RFU.9 FMW.1 D ---|>|--- DSUB.14 CNTR.14 AutoLF RFU.6 FMW.2 C ---|>|--- DSUB.1 CNTR.1 Strobe RFU.10 FMW.3 /RES ---|>|--- DSUB.16 CNTR.31 Init RFU.7 FMW.4 /S ---|>|--- DSUB.17 CNTR.36 Select RFU.5 FMW.5 /W --. SL1A - - N.C. RFU.28 FMW.6 VCC __| SL1B - - N.C. RFU.2,12 FMW.7 VSS --------- DSUB.18-25 CNTR.19-30 Ground RFU.8 FMW.8 Q --------- DSUB.11 CNTR.11 Busy P00 Joypad-A ---|>|--- DSUB.2 CNTR.2 D0 P01 Joypad-B ---|>|--- DSUB.3 CNTR.3 D1 P02 Joypad-Select ---|>|--- DSUB.4 CNTR.4 D2 P03 Joypad-Start ---|>|--- DSUB.5 CNTR.5 D3 P04 Joypad-Right ---|>|--- DSUB.6 CNTR.6 D4 P05 Joypad-Left ---|>|--- DSUB.7 CNTR.7 D5 P06 Joypad-Up ---|>|--- DSUB.8 CNTR.8 D6 P07 Joypad-Down ---|>|--- DSUB.9 CNTR.9 D7 RTC.1 INT aka SI --------- DSUB.10 CNTR.10 /Ack |
http://problemkaputt.de/nds-pins.gif (GIF-Image, 7.5KBytes) |
| DSi Reference |
| DSi Basic Differences to NDS |
4004020h - SCFG_WL 4004C04h - GPIO_WIFI BPTWL[30h] - Wifi LED related (also needed to enable Atheros Wifi SDIO) |
| DSi I/O Map |
0000000h 64Kbyte ARM7 BIOS (unlike NDS which had only 16KB) 2000000h 16MByte Main RAM (unlike NDS which had only 4MB) 3000000h 800Kbyte Shared RAM (unlike NDS which had only 32KB) 4004000h New DSi I/O Ports 8000000h Fake GBA Slot (32MB+64KB) (FFh-filled; when mapped to current CPU) C000000h Mirror of 16Mbyte Main RAM D000000h Open Bus? in retail version, Extra 16Mbyte MainRAM in debug version FFFF000h 64Kbyte ARM9 BIOS (unlike NDS which had only 4KB) |
4000004h 2 DISPSTAT (new Bit6, LCD Initialization Ready Flag) 4000204h 2 EXMEMCNT (removed Bit0-7, ie. the GBA-slot related bits) 4000210h 4 IE (new interrupt sources, removed GBA-slot IRQ) 4000214h 4 IF (new interrupt sources, removed GBA-slot IRQ) 40021A0h 4 Unknown, nonzero, probably same/silimar as on DSi7 side 40021A4h 4 Unknown, zero, probably same/silimar as on DSi7 side 40021A8h .. 40021Bxh .. 4102010h 4 |
4004000h 2 SCFG_A9ROM DSi - NDS9 - ROM Status (R) [0000h] 4004004h 2 SCFG_CLK DSi - NDS9 - New Block Clock Control (R/W) 4004006h 2 SCFG_RST DSi - NDS9 - New Block Reset (R/W) 4004008h 4 SCFG_EXT9 DSi - NDS9 - Extended Features (R/W) 4004010h 2 SCFG_MC Memory Card Interface Status (16bit) (undocumented) |
4004040h 4 MBK1 WRAM-A Slots for Bank 0,1,2,3 ;\Global ARM7+ARM9 4004044h 4 MBK2 WRAM-B Slots for Bank 0,1,2,3 ; Slot Mapping 4004048h 4 MBK3 WRAM-B Slots for Bank 4,5,6,7 ; (R or R/W, depending 400404Ch 4 MBK4 WRAM-C Slots for Bank 0,1,2,3 ; on MBK9 setting) 4004050h 4 MBK5 WRAM-C Slots for Bank 4,5,6,7 ;/ 4004054h 4 MBK6 WRAM-A Address Range ;\Local ARM9 Side 4004058h 4 MBK7 WRAM-B Address Range ; (R/W) 400405Ch 4 MBK8 WRAM-C Address Range ;/ 4004060h 4 MBK9 WRAM-A/B/C Slot Write Protect (R) |
4004100h 4 NDMAGCNT NewDMA Global Control ;-Control 4004104h 4 NDMA0SAD NewDMA0 Source Address ;\ 4004108h 4 NDMA0DAD NewDMA0 Destination Address ; 400410Ch 4 NDMA0TCNT NewDMA0 Total Length for Repeats ; NewDMA0 4004110h 4 NDMA0WCNT NewDMA0 Logical Block Size ; 4004114h 4 NDMA0BCNT NewDMA0 Block Transfer Timing/Interval ; 4004118h 4 NDMA0FDATA NewDMA0 Fill Data ; 400411Ch 4 NDMA0CNT NewDMA0 Control ;/ 4004120h 4 NDMA1SAD ;\ 4004124h 4 NDMA1DAD ; 4004128h 4 NDMA1TCNT ; NewDMA1 400412Ch 4 NDMA1WCNT ; 4004130h 4 NDMA1BCNT ; 4004134h 4 NDMA1FDATA ; 4004138h 4 NDMA1CNT ;/ 400413Ch 4 NDMA2SAD ;\ 4004140h 4 NDMA2DAD ; 4004144h 4 NDMA2TCNT ; NewDMA2 4004148h 4 NDMA2WCNT ; 400414Ch 4 NDMA2BCNT ; 4004150h 4 NDMA2FDATA ; 4004154h 4 NDMA2CNT ;/ 4004158h 4 NDMA3SAD ;\ 400415Ch 4 NDMA3DAD ; 4004160h 4 NDMA3TCNT ; NewDMA3 4004164h 4 NDMA3WCNT ; 4004168h 4 NDMA3BCNT ; 400416Ch 4 NDMA3FDATA ; 4004170h 4 NDMA3CNT ;/ |
4004200h 2 CAM_MCNT Camera Module Control (16bit) 4004202h 2 CAM_CNT Camera Control (16bit) 4004204h 4 CAM_DAT Camera Data (32bit) 4004210h 4 CAM_SOFS Camera Trimming Starting Position Setting (32bit) 4004214h 4 CAM_EOFS Camera Trimming Ending Position Setting (32bit) |
4004300h 2 DSP_PDATA DSP Transfer Data 4004304h 2 DSP_PADR DSP Transfer Address 4004308h 2 DSP_PCFG DSP Configuration 400430Ch 2 DSP_PSTS DSP Status 4004310h 2 DSP_PSEM DSP ARM9-to-DSP Semaphore (R/W) 4004314h 2 DSP_PMASK DSP DSP-to-ARM9 Semaphore Mask (R/W) 4004318h 2 DSP_PCLEAR DSP DSP-to-ARM9 Semaphore Clear (W) 400431Ch 2 DSP_SEM DSP DSP-to-ARM9 Semaphore Data (R) 4004320h 2 DSP_CMD0 DSP ARM9-to-DSP Command Register 0 (R/W) 4004324h 2 DSP_REP0 DSP DSP-to-ARM9 Reply Register 0 (R) 4004328h 2 DSP_CMD1 DSP ARM9-to-DSP Command Register 1 (R/W) 400432Ch 2 DSP_REP1 DSP DSP-to-ARM9 Reply Register 1 (R) 4004330h 2 DSP_CMD2 DSP ARM9-to-DSP Command Register 2 (R/W) 4004334h 2 DSP_REP2 DSP DSP-to-ARM9 Reply Register 2 (R) 4004340h C0h DSP_mirror Mirrors of above 40h-byte DSP register area |
4000004h 2 DISPSTAT (new Bit6, LCD Initialization Ready Flag) (as DSi9?) 40001C0h 2 SPICNT (new Bit2, for 8MHz transfer clock) 4000204h 2 EXMEMCNT (removed Bit0-7: GBA-slot related bits) (as DSi9?) 4000210h 4 IE (new interrupt sources, removed GBA-slot IRQ) 4000214h 4 IF (new interrupt sources, removed GBA-slot IRQ) 4000218h IE2 (new register with more new interrupt sources) 400021Ch IF2 (new register with more new interrupt sources) |
40021A0h 4 Unknown, nonzero, probably related to below 40021A4h 40021A4h 4 Unknown, related to 40001A4h (Gamecard Bus ROMCTRL) 40021A8h .. 40021Bxh .. 4102010h 4 |
4004000h 1 SCFG_A9ROM used by BIOS and SystemFlaw (bit0,1) 4004001h 1 SCFG_A7ROM used by BIOS and SystemFlaw (bit0,1,2) 4004004h 2 SCFG_CLK7 used by SystemFlaw 4004006h 2 SCFG_JTAG Debugger Control 4004008h 4 SCFG_EXT7 used by SystemFlaw 4004010h 2 SCFG_MC Memory Card Interface Control (R/W) ;\ 4004012h 2 SCFG_CARD_INSERT_DELAY (usually 1988h = 100ms) ; Game Cartridge 4004014h 2 SCFG_CARD_PWROFF_DELAY (usually 264Ch = 150ms) ;/ 4004020h 2 SCFG_WL Wireless Disable ;bit0 = wifi? 4004024h 2 SCFG_OP Debugger Type (R) ;bit0-1 = (0=retail, ?=debug) |
4004040h 4 MBK1 WRAM-A Slots for Bank 0,1,2,3 ;\ 4004044h 4 MBK2 WRAM-B Slots for Bank 0,1,2,3 ; Global ARM7+ARM9 4004048h 4 MBK3 WRAM-B Slots for Bank 4,5,6,7 ; Slot Mapping (R) 400404Ch 4 MBK4 WRAM-C Slots for Bank 0,1,2,3 ; (set on ARM9 side) 4004050h 4 MBK5 WRAM-C Slots for Bank 4,5,6,7 ;/ 4004054h 4 MBK6 WRAM-A Address Range ;\Local ARM7 Side 4004058h 4 MBK7 WRAM-B Address Range ; (R/W) 400405Ch 4 MBK8 WRAM-C Address Range ;/ 4004060h 4 MBK9 WRAM-A/B/C Slot Write Protect (R/W) |
4004100h 74h NewDMA (new DMA, as on ARM9i, see there) |
4004400h 4 AES_CNT (R/W) 4004404h 4 AES_BLKCNT (W) 4004408h 4 AES_WRFIFO (W) 400440Ch 4 AES_RDFIFO (R) 4004420h 16 AES_IV (W) 4004430h 16 AES_MAC (W) 4004440h 48 AES_KEY0 (W) ;used for modcrypt 4004470h 48 AES_KEY1 (W) ;used for ? 40044A0h 48 AES_KEY2 (W) ;used for JPEG signatures 40044D0h 48 AES_KEY3 (W) ;used for eMMC sectors |
4004500h 1 I2C_DATA 4004501h 1 I2C_CNT |
4004600h 2 MIC_CNT Microphone Control 4004604h 4 MIC_DATA Microphone FIFO |
4004700h 2 SNDEXCNT <-- can be read even in DS mode! |
4004800h 2 SD_CMD Command and Response/Data Type 4004802h 2 SD_CARD_PORT_SELECT (SD/MMC:020Fh, SDIO:010Fh) 4004804h 4 SD_CMD_PARAM0-1 Argument (32bit, 2 halfwords) 4004808h 2 SD_STOP_INTERNAL_ACTION 400480Ah 2 SD_DATA16_BLK_COUNT "Transfer Block Count" 400480Ch 16 SD_RESPONSE0-7 (128bit, 8 halfwords) 400481Ch 4 SD_IRQ_STATUS0-1 ;IRQ Status (0=ack, 1=req) 4004820h 4 SD_IRQ_MASK0-1 ;IRQ Disable (0=enable, 1=disable) 4004824h 2 SD_CARD_CLK_CTL Card Clock Control 4004826h 2 SD_DATA16_BLK_LEN Memory Card Transfer Data Length 4004828h 2 SD_CARD_OPTION Memory Card Option Setup (can be C0FFh) 400482Ah 2 Fixed always zero? 400482Ch 4 SD_ERROR_DETAIL_STATUS0-1 Error Detail Status 4004830h 2 SD_DATA16_FIFO Data Port (SD_FIFO?) 4004832h 2 Fixed always zero? ;(TC6371AF:BUF1 Data MSBs?) 4004834h 2 SD_CARD_IRQ_CTL ;(SD_TRANSACTION_CTL) 4004836h 2 SD_CARD_IRQ_STAT ;(SD_CARD_INTERRUPT_CONTROL) 4004838h 2 SD_CARD_IRQ_MASK ;(SDCTL_CLK_AND_WAIT_CTL) 400483Ah 2 Fixed always zero? ;(SDCTL_SDIO_HOST_INFORMATION) 400483Ch 2 Fixed always zero? ;(SDCTL_ERROR_CONTROL) 400483Eh 2 Fixed always zero? ;(TC6387XB: LED_CONTROL) 4004840h 2 Fixed always 003Fh? 4004842h 2 Fixed always 002Ah? 4004844h 6Eh Fixed always zerofilled? 40048B2h 2 Fixed always FFFFh? 40048B4h 6 Fixed always zerofilled? 40048BAh 2 Fixed always 0200h? 40048BCh 1Ch Fixed always zerofilled? 40048D8h 2 SD_DATA_CTL 40048DAh 6 Fixed always zerofilled? 40048E0h 2 SD_SOFT_RESET Software Reset (bit0=SRST=0=reset) 40048E2h 2 Fixed always 0009h? ;(RESERVED2/9, TC6371AF:CORE_REV) 40048E4h 2 Fixed always zero? 40048E6h 2 Fixed always zero? ;(RESERVED3, TC6371AF:BUF_ADR) 40048E8h 2 Fixed always zero? ;(TC6371AF:Resp_Header) 40048EAh 6 Fixed always zerofilled? 40048F0h 2 Fixed always zero? ;(RESERVED10) 40048F2h 2 ? Can be 0003h 40048F4h 2 ? Can be 0770h 40048F6h 2 SD_WRPROTECT_2 (R) ;Write protect for eMMC (RESERVED4) 40048F8h 4 SD_EXT_IRQ_STAT0-1 ;Insert/eject for eMMC (RESERVED5-6) 40048FCh 4 SD_EXT_IRQ_MASK0-1 ;(TC6371AF:Revision) (RESERVED7-8) 4004900h 2 SD_DATA32_IRQ 4004902h 2 Fixed always zero? 4004904h 2 SD_DATA32_BLK_LEN 4004906h 2 Fixed always zero? 4004908h 2 SD_DATA32_BLK_COUNT 400490Ah 2 Fixed always zero? 400490Ch 4 SD_DATA32_FIFO 4004910h F0h Fixed always zerofilled? |
4004A00h 512 SDIO_xxx (same as SD_xxx at 4004800h..40049FFh, see there) 4004A02h 2 SDIO_CARD_PORT_SELECT (slightly different than 4004802h) |
4004C00h 1 GPIO Data In (R) (even in DS mode) 4004C00h 1 GPIO Data Out (W) 4004C01h 1 GPIO Data Direction (R/W) 4004C02h 1 GPIO Interrupt Edge Select (R/W) 4004C03h 1 GPIO Interrupt Enable (R/W) 4004C04h 2 GPIO_WIFI (R/W) |
4004D00h 8 CPU/Console ID Code (64bit) (R) 4004D08h 2 CPU/Console ID Flag (1bit) (R) |
8030200h 2 GBA area, accessed alongsides with SDIO port [4004A30h] (bug?) |
2FFFFFEh 2 Main Memory Control (for 16MByte RAM chip) DFFFFFEh 2 Main Memory Control (extra 16MByte RAM chip in debug version) |
| DSi Control Registers (SCFG) |
0 ARM9 BIOS Upper 32K half of DSi BIOS (0=Enabled, 1=Disabled) 1 ARM9 BIOS for NDS Mode (0=DSi BIOS, 1=NDS BIOS) 2-15 Unused (0) 16-31 Unspecified (0) |
00h DSi ROM mapped at FFFFxxxxh, full 64K enabled (during bootstage 1 only) 01h DSi ROM mapped at FFFFxxxxh, lower 32K only 03h NDS ROM mapped at FFFFxxxxh (internal setting) 00h NDS ROM mapped at FFFFxxxxh (visible setting due to SCFG_EXT9.bit31=0) |
0 ARM9 BIOS Upper 32Kbyte of DSi BIOS (0=Enabled, 1=Disabled) (FFFF8xxxh) 1 ARM9 BIOS for NDS Mode (0=DSi BIOS, 1=NDS BIOS)(FFFF0xxxh) 2-7 Unused (0) 8 ARM7 BIOS Upper 32Kbyte of DSi BIOS (0=Enabled, 1=Disabled) (0008xxxh) 9 ARM7 BIOS for NDS Mode (0=DSi BIOS, 1=NDS BIOS) (0000xxxh) 10 Access to Console ID registers (0=Enabled, 1=Disabled) (4004Dxxh) 11-15 Unused (0) 16 Unknown, used by bootrom, set to 0 (0=Maybe start ARM9 ?) 17-31 Unused (0) |
0 ARM9 CPU Clock (0=NITRO/67.03MHz, 1=TWL/134.06MHz) (TCM/Cache)
1 Teak DSP Block Clock (0=Stop, 1=Run)
2 Camera Interface Clock (0=Stop, 1=Run)
3-6 Unused (0)
7 New Shared RAM Clock (0=Stop, 1=Run) (set via ARM7) (R)
8 Camera External Clock (0=Disable, 1=Enable) ("outputs at 16.76MHz")
9-15 Unused (0)
16-31 See below (Port 4004006h, SCFG_RST)
|
0 SD/MMC Clock (0=Stop, 1=Run) (should be same as SCFG_EXT7.bit18) 1 Unknown/used (0=Stop, 1=Run) (backlight goes off when cleared?) 2 Unknown/used (0=Stop, 1=Run) (unknown effect?) 3-6 Unused (0) 7 New Shared RAM Clock (0=Stop, 1=Run) 8 Touchscreen Clock (0=Stop, 1=Run) (needed for touchscr input) 9-15 Unused (0) 16-31 See below (Port 4004006h, SCFG_JTAG) |
0 Teak DSP Block Reset (0=Apply Reset, 1=Release Reset) 1-15 Unused (0) |
0 ARM7SEL (set when debugger can do ARM7 debugging) 1 CPU JTAG Enable 2-7 Unused (0) 8 DSP JTAG Enable 9-15 Unused (0) |
0 Revised ARM9 DMA Circuit (0=NITRO, 1=Revised) 1 Revised Geometry Circuit (0=NITRO, 1=Revised) 2 Revised Renderer Circuit (0=NITRO, 1=Revised) 3 Revised 2D Engine Circuit (0=NITRO, 1=Revised) 4 Revised Divider Circuit (0=NITRO, 1=Revised) 5-6 Unused (0) 7 Revised Card Interface Circuit (0=NITRO, 1=Revised) 8 Extended ARM9 Interrupts (0=NITRO, 1=Extended) 9-11 Unused (0) 12 Extended LCD Circuit (0=NITRO, 1=Extended) 13 Extended VRAM Access (0=NITRO, 1=Extended) 14-15 Main Memory RAM Limit (0..1=4MB/DS, 2=16MB/DSi, 3=32MB/DSiDebugger) 16 Access to New DMA Controller (0=Disable, 1=Enable) (40041xxh) 17 Access to Camera Interface (0=Disable, 1=Enable) (40042xxh) 18 Access to Teak DSP Block (0=Disable, 1=Enable) (40043xxh) 19-23 Unused (0) 24 Access to 2nd NDS Cart Slot (0=Disable, 1=Enable) (set via ARM7) (R) 25 Access to New Shared WRAM (0=Disable, 1=Enable) (set via ARM7) (R) 26-30 Unused (0) 31 Access to SCFG/MBK registers (0=Disable, 1=Enable) (4004000h-4004063h) |
8307F100h for DSi firmware, DSi cartridges and DSiware 03000000h for NDS cartridges (and DSiware in NDS mode, eg. Pictochat) |
Mode 2000000h-2FFFFFFh C000000h-CFFFFFFh D000000h-DFFFFFFh 4MB (0 or 1) 1st 4MB (+mirrors) Zerofilled Zerofilled 16MB (2) 1st 16MB 1st 16MB (mirror) 1st 16MB (mirror) 32MB (3) 1st 16MB 1st 16MB (mirror) Open bus (or 2nd 16MB) |
0 Revised ARM7 DMA Circuit (0=NITRO, 1=Revised) 1 Revised Sound DMA (0=NITRO, 1=Revised) 2 Revised Sound (0=NITRO, 1=Revised) 3-6 Unused (0) 7 Revised Card Interface Circuit (0=NITRO, 1=Revised) (set via ARM9) (R) 8 Extended ARM7 Interrupts (0=NITRO, 1=Extended) (4000218h) 9 Extended SPI Clock (8MHz) (0=NITRO, 1=Extended) (40001C0h) 10 Extended Sound DMA ? (0=NITRO, 1=Extended) (?) 11 Undocumented/Unknown ?? (0=NITRO, 1=Extended) (?) 12 Extended LCD Circuit (0=NITRO, 1=Extended) (set via ARM9) (R) 13 Extended VRAM Access (0=NITRO, 1=Extended) (set via ARM9) (R) 14-15 Main Memory RAM Limit (0..1=4MB, 2=16MB, 3=32MB) (set via ARM9) (R) 16 Access to New DMA Controller (0=Disable, 1=Enable) (40041xxh) 17 Access to AES Unit (0=Disable, 1=Enable) (40044xxh) 18 Access to SD/MMC registers (0=Disable, 1=Enable) (40048xxh-40049xxh) 19 Access to SDIO Wifi registers (0=Disable, 1=Enable) (4004Axxh-4004Bxxh) 20 Access to Microphone regs (0=Disable, 1=Enable) (40046xxh) 21 Access to SNDEXCNT register (0=Disable, 1=Enable) (40047xxh) 22 Access to I2C registers (0=Disable, 1=Enable) (40045xxh) 23 Access to GPIO registers (0=Disable, 1=Enable) (4004Cxxh) 24 Access to 2nd NDS Cart Slot (0=Disable, 1=Enable) (40021xxh) 25 Access to New Shared WRAM (0=Disable, 1=Enable) (3xxxxxxh) 26-27 Unused (0) 28 Undocumented/Unknown (0=???, 1=Normal) (?) 29-30 Unused (0) 31 Access to SCFG/MBK registers (0=Disable, 1=Enable) (4004000h-4004063h) |
93FFFB06h for DSi Firmware (Bootcode and SysMenu/Launcher) 13FFFB06h for DSiware (eg. SysSettings, Flipnote, PaperPlane) 13FBFB06h for DSi Cartridges (eg. System Flaw) (bit18=0=sdmmc off) 12A03000h for NDS cartridges (and DSiware in NDS mode, eg. Pictochat) |
0 1st NDS Slot Game Cartridge (0=Inserted, 1=Ejected) (R) 1 1st NDS Slot Unknown/Unused (0) 2-3 1st NDS Slot Power State (0=Off, 1=On+Reset, 2=On, 3=RequestOff) (R/W) 4 2nd NDS Slot Game Cartridge (always 1=Ejected) ;\DSi (R) 5 2nd NDS Slot Unknown/Unused (0) ; prototype 6-7 2nd NDS Slot Power State (always 0=Off) ;/relict (R/W) 8-14 Unknown/Undocumented (0) 15 Swap NDS Slots (0=Normal, 1=Swap) (R/W) 16-31 ARM7: See Port 4004012h, ARM9: Unspecified (0) |
0=Power is Off 1=Power On and force Reset (shall be MANUALLY changed to state=2) 2=Power On 3=Request Power Off (will be AUTOMATICALLY changed to state=0) |
wait until state<>3 ;wait if pwr off busy exit if state<>0 AND no_reset_wanted ;exit if already on & no reset wanted wait 1ms, then set state=1 ;pwr on & force reset wait 10ms, then set state=2 ;pwr on normal state ;better: 1ms wait 27ms, then set ROMCTRL=20000000h ;release reset pin ;better: 0ms wait 120ms (or 270ms on 3DS) ;more insane delay? ;better: 1ms/20ms ;note: the last delay (after releasing reset) can be 1ms for most carts, ;except DSi NAND carts do require 20ms (eg. Face Training) ;XXX other day: needs MORE than 20ms (30ms works), temperature related?? |
wait until state<>3 ;wait if pwr off busy exit if state<>2 ;exit if already off set state=3 ;request pwr off exit unless you want to know when below pointless delay has ellapsed wait until state=0 ;default=150ms ;wait until pwr off ;better: skip |
0-15 Delay in 400h cycle units (at 67.027964MHz) ;max FFFFh=ca. 1 second |
0 OFFB, related to Wifi Enable flag from TWLCFGn.dat and HWINFO_S files 1-15 Unknown/unused (0) |
0-1 Debug Hardware Type (0=Retail, other=debug variants) 2-3 Unknown/unused (0) 4 Unknown (maybe used, since it isn't masked & copied to RAM) 5-15 Unknown/unused (0) |
| DSi XpertTeak (DSP) |
| DSi Teak Misc |
TeakLite Architecture Specification Revision 4.41 (DSP Group Inc.) OakDSPCore Technical Manuals for CWDSP1640 or CWDSP167x (LSI Logic) OakDSPCore DSP Subsystem AT75C (Atmel) |
TeakLite II disassembler dll in RVDS (RealView Developer Suite) 4.0 Pro |
searching for "teak" in the "search for chip" box on "www.lauterbach.com" should lead to this file: trace32_ceva-teak_r_2019_02_000108303_win64.zip |
0000h..7FFFh X Space (for RAM, with 1-stage write-buffer) ;min zero 8000h..87FFh Z Space (for Memory-mapped I/O, no write-buffer) ;min zero 8800h..FFFFh Y Space (for RAM, with 1-stage write-buffer)) ;min 1Kword |
NumCycles = max(NumberOfOpcodeWords, NumberOfDataReadsWrites) |
Teak actual CPU clock(s) are... 134.055928MHz (aka 134MHz) <-- for Timer 0, SIO, DMA (no "waitstates") 107.244742MHz (aka 134MHz/1.25) <-- for Timer 1, CPU (with "waitstates") |
| DSi Teak I/O Ports (on ARM9 Side) |
0-15 Data (one stage of the 16-stage Read FIFO) |
0-15 Data (one stage of the 16-stage Write FIFO) |
0-15 Lower 16bit of Address in DSP Memory (in 16bit units) |
MMIO[81BEh] - DMA Select Channel (must be 0 for below DMA 0 regisrers) MMIO[81C2h:0] - DMA Channel 0: Source Address, bit16-31 (R/W) MMIO[81C6h:0] - DMA Channel 0: Destination Address, bit16-31 (R/W) |
0 DSP Reset (0=Release, 1=Reset) ;should be held "1" for 8 DSP clks 1 DSP Transfer Address Auto-Increment (0=Off, 1=On) 2-3 DSP Read Data Length (0=1 word, 1=8 words, 2=16 words, 3=FreeRun) 4 DSP Read Start Flag (mem transfer via Read FIFO) (1=Start) 5 Interrupt Enable Read FIFO Full (0=Off, 1=On) 6 Interrupt Enable Read FIFO Not-Empty (0=Off, 1=On) 7 Interrupt Enable Write FIFO Full (0=Off, 1=On) 8 Interrupt Enable Write FIFO Empty (0=Off, 1=On) 9 Interrupt Enable Reply Register 0 (0=Off, 1=On) 10 Interrupt Enable Reply Register 1 (0=Off, 1=On) 11 Interrupt Enable Reply Register 2 (0=Off, 1=On) 12-15 DSP Memory Transfer (0=DSP/Data, 1=DSP/MMIO, 5=DSP/Code, 7=ARM/AHBM) |
0 Read Transfer Underway Flag (0=No, 1=Yes/From DSP Memory) 1 Write Transfer Underway Flag (0=No, 1=Yes/To DSP Memory) 2 Peripheral Reset Flag (0=No/Ready, 1=Reset/Busy) 3-4 Unused (0) 5 Read FIFO Full Flag (0=No, 1=Yes/Full) 6 Read FIFO Not-Empty Flag (0=No, 1=Yes, ARM9 may read PDATA) 7 Write FIFO Full Flag (0=No, 1=Yes/Full) 8 Write FIFO Empty Flag (0=No, 1=Yes/Empty) 9 Semaphore IRQ Flag (0=None, 1=IRQ) 10 Reply Register 0 Update Flag (0=Was Written by DSP, 1=No) 11 Reply Register 1 Update Flag (0=Was Written by DSP, 1=No) 12 Reply Register 2 Update Flag (0=Was Written by DSP, 1=No) 13 Command Register 0 Read Flag (0=Was Read by DSP, 1=No) 14 Command Register 1 Read Flag (0=Was Read by DSP, 1=No) 15 Command Register 2 Read Flag (0=Was Read by DSP, 1=No) |
0-15 ARM9-to-DSP Semaphore 0..15 Flags (0=Off, 1=On) |
0-15 DSP-to-ARM9 Semaphore 0..15 Interrupt Disable (0=Enable, 1=Disable) |
0-15 DSP-to-ARM9 Semaphore 0..15 Clear (0=No Change, 1=Clear/Ack) |
0-15 DSP-to-ARM9 Semaphore 0..15 Flags (0=Off, 1=On) |
0-15 Command/Data to DSP |
0-15 Reply/Data from DSP |
| DSi Teak MMIO - Register Summary |
8000h..8002h 3300 3300 3300 R Mirror of Port 80D6h |
8004h 0000 0000 87FF R/W JAM Unknown 8006h ? ? ? ?? JAM Unknown/Crash, DANGER (crashes on read) 8008h..800Eh 3300 3300 3300 R Mirror of Port 80D6h |
8010h 0000 0000 0003 R/W GLUE CFG0 8012h 0000 0000 0003 R/W GLUE Unknown 2bit 8014h 0000 0000 FFFF R/W GLUE Unknown 16bit 8016h 0000 0000 0000 R GLUE Unknown (DSi=0000h, New3DS=00BAh) 8018h 0000 0000 BDEF R/W GLUE Whatever Parity/Shuffle 801Ah C902 C902 C902 R GLUE Chip config ID (for xpert_offsets_tbl) 801Ch..801Eh 0003 0003 0003 R Mirror of port 8010h |
8020h 0000 0000 7xDF R/W Timer 0 Control (bit11=DANGER) ;\ 8022h 0000 0000 0000 W Timer 0 Trigger Event/Watchdog ; 8024h 0000 0000 FFFF R/W Timer 0 Reload value, bit0-15 ; Timer 0 8026h 0000 0000 FFFF R/W Timer 0 Reload value, bit16-31 ; 8028h 0000 0000 0000 R Timer 0 Counter value, bit0-15 ; 802Ah 0000 0000 0000 R Timer 0 Counter value, bit16-31 ; 802Ch 0000 0000 FFFF R/W Timer 0 PWM Reload value, bit0-15 ; 802Eh 0000 0000 FFFF R/W Timer 0 PWM Reload value, bit16-31 ;/ 8030h 0200 0200 7xDF R/W Timer 1 Control (bit11=DANGER) ;\ 8032h 0000 0000 0000 W Timer 1 Trigger Event/Watchdog ; 8034h 0000 0000 FFFF R/W Timer 1 Reload value, bit0-15 ; Timer 1 8036h 0000 0000 FFFF R/W Timer 1 Reload value, bit16-31 ; 8038h 0000 0000 0000 R Timer 1 Counter value, bit0-15 ; 803Ah 0000 0000 0000 R Timer 1 Counter value, bit16-31 ; 803Ch 0000 0000 FFFF R/W Timer 1 PWM Reload value, bit0-15 ; 803Eh 0000 0000 FFFF R/W Timer 1 PWM Reload value, bit16-31 ;/ 8040h..804Eh 3300 3300 3300 R Mirror of Port 80D6h |
8050h 7000 0000 F03F R/W SIO Control 8052h 0000 0000 7F7F R/W SIO Clock Divider 8054h 0000 0000 0000 R+W SIO Data (R) and (W) 8056h 0000 0000 0001 R/W SIO Enable 8058h 0000 0000 0000 R SIO Status 805Ah..805Eh F03F F03F F03F R Mirror of port 8050h |
8060h 0105 0105 0105 R OCEM Program Flow Trace Buffer, bit0-15 8061h 0000 0000 0000 R OCEM Program Flow Trace Buffer, bit16-31 8062h FFFF 0000 FFFF R/W OCEM Program Break Address 1, bit0-15 8063h 0F03 0000 0F03 R/W OCEM Program Break Address 1, bit16-31 8064h FFFF 0000 FFFF R/W OCEM Program Break Address 2, bit0-15 8065h 0F03 0000 0F03 R/W OCEM Program Break Address 2, bit16-31 8066h FFFF 0000 FFFF R/W OCEM Program Break Address 3, bit0-15 8067h 0F03 0000 0F03 R/W OCEM Program Break Address 3, bit16-31 8068h 00FF 0000 00FF R/W OCEM Program Break Counter 1 8069h 00FF 0000 00FF R/W OCEM Program Break Counter 2 806Ah 00FF 0000 00FF R/W OCEM Program Break Counter 3 806Bh FFFF 0000 FFFF R/W OCEM Data Break Mask 806Ch FFFF 0000 FFFF R/W OCEM Data Break Address 806Dh 0000 0000 R/W OCEM Breakpoint Enable Flags (DANGER) 806Eh 3001 0000 FFFF R/W OCEM Mode/Indication? 806Fh 0000 0000 BFFF R/W OCEM Breakpoint Status Flags 8070h 0000 0000 0001 R/W OCEM Program Flow Trace Update Disable 8072h 0000 0000 FFFF R/W Unknown 16bit? 8074h C000 C000 C000 R OCEM Boot/Debug Mode 8076h..807Eh 0105 0105 0105 R Mirror of port 8060h |
8080h C00E 0000 FFFF R/W PMU PLL Multiplier 8082h 0001 0000 0001 R/W PMU PLL Power-on config 8084h 8000 R/W PMU PLL Divider/Bypass (DANGER) 8086h 0000 R/W PMU Wake/Shutdown Module(s) 8088h 0000 0000 07BF R/W PMU Recover Module(s) on interrupt 0 808Ah 0000 0000 07BF R/W PMU Recover Module(s) on interrupt 1 808Ch 0000 0000 07BF R/W PMU Recover Module(s) on interrupt 2 808Eh 0000 0000 07BF R/W PMU Recover Module(s) on vectored interrupt 8090h 0000 0000 06BF R/W PMU Recover Module(s) on Timer 0 (no bit8) 8092h 0000 0000 05BF R/W PMU Recover Module(s) on Timer 1 (no bit9) 8094h 0000 0000 07BF R/W PMU Recover Module(s) on NMI 8096h 0000 0000 0002 R/W PMU Recover DMA on external signal (bit1) 8098h 0000 0000 0302 R/W PMU Breakpoint mask module(s) (bit1,8,9 only) 809Ah 0000 0000 0003 R/W PMU Wake/Shutdown BTDMP(s) 809Ch 0000 0000 0003 R/W PMU Recover BTDMP(s) on interrupt 0 809Eh 0000 0000 0003 R/W PMU Recover BTDMP(s) on interrupt 1 80A0h 0000 0000 0003 R/W PMU Recover BTDMP(s) on interrupt 2 80A2h 0000 0000 0003 R/W PMU Recover BTDMP(s) on vectored interrupt 80A4h 0000 0000 0003 R/W PMU Recover BTDMP(s) on Timer 0 80A6h 0000 0000 0003 R/W PMU Recover BTDMP(s) on Timer 1 80A8h 0000 0000 0003 R/W PMU Recover BTDMP(s) on NMI (undoc?) 80AAh 0000 0000 FFFF R/W Unknown 16bit 80ACh 0000 0000 FFFF R/W Unknown 16bit 80AEh 0000 0000 FFFF R/W Unknown 16bit 80B0h..80BEh FFFF FFFF FFFF R Mirror of port 8080h |
80C0h xxxx xxxx xxxx R/W APBP DSP-to-ARM Reply 0 80C2h 4300 4300 4300 R APBP ARM-to-DSP Command 0 80C4h 0000 0000 FFFF R/W APBP DSP-to-ARM Reply 1 80C6h 3123 3123 3123 R APBP ARM-to-DSP Command 1 80C8h 0000 0000 FFFF R/W APBP DSP-to-ARM Reply 2 80CAh 3223 3223 3223 R APBP ARM-to-DSP Command 2 80CCh 0000 0000 FFFF R/W APBP DSP-to-ARM Semaphore Set Flags 80CEh 0000 R/W APBP ARM-to-DSP Semaphore Interrupt Mask 80D0h 0000 W? APBP ARM-to-DSP Semaphore Ack Flags 80D2h AFFE AFFE AFFE R APBP ARM-to-DSP Semaphore Get Flags 80D4h 0000 R/W APBP Control (DANGER: can crash cpu) 80D6h 03C0 03C0 03C0 R APBP DSP-side Status 80D8h 3B00 3B00 3B00 R APBP ARM-side Status (mirror of 400430Ch) 80DAh..80DEh 0000 0000 0000 R Fixed 0000h |
80E0h 0000 0000 0000 R AHBM Status 80E2h+N*6 0000 0000 0FBF R/W AHBM Channel 0..2 Configure Burst/Data 80E4h+N*6 0000 0000 03FF R/W AHBM Channel 0..2 Configure Whatever 80E6h+N*6 0000 0000 00FF R/W AHBM Channel 0..2 Configure DMA 80F4h 0000 0000 FC00 R/W Unknown 6bit? bit10-15 are used 80F6h 0000 0000 0000 R? AHBM Internal FIFO (R) and maybe also (W?) 80F8h 0000 0000 0000 R? Unknown always zero? 80FAh 0000 0000 FFFF R/W Read/write-able(!) mirror of MMIO[80FCh] 80FCh FFFF 0000 FFFF R/W Unknown 16bit? 80FEh 0000 0000 FFFF R/W Unknown 16bit? |
8100h FFFF 0000 FFFF R/W MIU Waitstate Settings, bit0-15 8102h 0FFF 0000 0FFF R/W MIU Waitstate Settings, bit16-31 8104h 0000 0000 FFFF R/W MIU Waitstate Area Z0 8106h 0000 0000 FFFF R/W MIU Waitstate Area Z1 8108h 0000 0000 FFFF R/W MIU Waitstate Area Z2 810Ah 0000 0000 FFFF R/W MIU Waitstate Area Z3 810Ch 0014 0014 0014 R Mirror of port 811Ah 810Eh 0000 0000 FFFF R/W MIU X Page (16bit) (or unused) 8110h 0000 0000 00FF R/W MIU Y Page (8bit) (or unused) 8112h 0000 R/W MIU Z Page (16bit) (or absolute page)(DANGER) 8114h 1E20 R/W MIU X/Y Page Size for Page 0 (or all pages) 8116h 1E20 0100 403F R/W MIU X/Y Page Size for Page 1 (or unused) 8118h 1E20 0100 403F R/W MIU X/Y Page Size for Off-chip (or unused) 811Ah 0014 00x4 R/W MIU Config for Misc stuff (DANGER) 811Ch 0004 0000 007F R/W MIU Config for Program Page and Download Mem 811Eh 8000 R/W MIU Base Address for MMIO Registers (DANGER) 8120h 0000 0000 000F R/W MIU Observability Mode 8122h 0000 0000 007F R/W MIU Pin Config? 8124h..813Eh 0014 0014 0014 R Mirror of port 811Ah |
8140h+N*4 0000 0000 FFFF R/W CRU Entry 0..14 Offset, bit0-15 8142h+N*4 0000 0000 803F R/W CRU Entry 0..14 Offset, bit16-31 817Ch 0000 0000 FFFF R/W CRU Entry 15 Offset, bit0-15 ;\with control 817Eh 0000 0000 C03F R/W CRU Entry 15 Offset, bit16-31 ;/status bits |
8180h 0000 0000 0000 R DMA Internal: Channel Size0 Busy or so? 8182h 0000 0000 0000 R DMA Internal: Channel Size1 Busy or so? 8184h 0001 0000 00FF R/W DMA Channel Start Flags (1=Start/Busy) 8186h 0000 0000 00FF R/W DMA Channel Pause Flags (1=Pause) 8188h 0000 0000 0000 R DMA Channel End Flags for Size0 818Ah 0000 0000 0000 R DMA Channel End Flags for Size1 818Ch 0000 0000 0000 R DMA Channel End Flags for Size2 (all done) 818Eh 3210 0000 7777 R/W DMA Whatever Slot Config, bit0-15 8190h 7654 0000 7777 R/W DMA Whatever Slot Config, bit16-31 8192h 0000 0000 7C03 R/W Unknown, R/W mask 7C03h 8194h 0000 0000 0000 R DMA Internal: contains SRC_ADDR_L after DMA 8196h 0000 0000 0000 R DMA Internal: contains DST_ADDR_L after DMA 8198h..81B4h 0000 0000 0000 R Fixed 0000h 81B6h 0000 0000 FFFF R/W Unknown, 16bit 81B8h 0000 0000 FFFF R/W Unknown, 16bit 81BAh 0000 0000 FFFF R/W Unknown, 16bit 81BCh 0000 0000 FFFF R/W Unknown, 16bit 81BEh 0000 0000 0007 R/W DMA Select Channel (bank for 81C0h-81Exh) 81C0h:0..7 0000 0000 FFFF R/W DMA Channel: Source Address, bit0-15 81C2h:0..7 0000 0000 FFFF R/W DMA Channel: Source Address, bit16-31 81C4h:0..7 0000 0000 FFFF R/W DMA Channel: Destination Address, bit0-15 81C6h:0..7 0000 0000 FFFF R/W DMA Channel: Destination Address, bit16-31 81C8h:0..7 FFFF 0001 FFFF R/W DMA Channel: Size0 (usually total len) 81CAh:0..7 0001 0001 FFFF R/W DMA Channel: Size1 (usually 1) 81CCh:0..7 0001 0001 FFFF R/W DMA Channel: Size2 (usually 1) 81CEh:0..7 0001 0000 FFFF R/W DMA Channel: Source Step0 ;-2,4,2,1 81D0h:0..7 0001 0000 FFFF R/W DMA Channel: Source Step1 ;-4,2,2,1 81D2h:0..7 0001 0000 FFFF R/W DMA Channel: Source Step2 ;-2,4,0,1 81D4h:0..7 0001 0000 FFFF R/W DMA Channel: Destination Step0 ;-4,2,0,1 81D6h:0..7 0001 0000 FFFF R/W DMA Channel: Destination Step1 ;-0,0,0,1 81D8h:0..7 0001 0000 FFFF R/W DMA Channel: Destination Step2 ;-0,0,0,1 81DAh:0..7 F200 0000 F7FF R/W DMA Channel: Memory Area Config 81DCh:0..7 0000 0000 1FF7 R/W DMA Channel: Unknown, usually set to 0300h? 81DEh:0..7 0000 0000 00FF R/W DMA Channel: Start/Stop/Control 81E0h:0..7 0000 0000 0000 R DMA Internal: contains SRC_ADDR_L after DMA 81E2h:0..7 0000 0000 0000 R DMA Internal: contains DST_ADDR_L after DMA 81E4h:0..7 0000 0000 0000 R DMA Internal: contains SRC_ADDR_H after DMA 81E6h:0..7 0000 0000 0000 R DMA Internal: contains DST_ADDR_H after DMA 81E8h..81FEh 0000 0000 0000 R Fixed 0000h |
8200h 4020 4020 4020 R ICU Interrupt Pending Flags (1=Pending) 8202h 0000 0000 0000 W ICU Interrupt Acknowledge (1=Clear) 8204h 0000 0000 FFFF R/W ICU Interrupt Manual Trigger (1=Set) 8206h 0000 0000 FFFF R/W ICU Enable Interrupt as int0 (1=Enable) 8208h 0000 0000 FFFF R/W ICU Enable Interrupt as int1 (1=Enable) 820Ah 0000 0000 FFFF R/W ICU Enable Interrupt as int2 (1=Enable) 820Ch 0000 0000 FFFF R/W ICU Enable Interrupt as vint (1=Enable) 820Eh 2000 0000 FFFF R/W ICU Interrupt Trigger mode (0=Level, 1=Edge) 8210h 2000 0000 FFFF R/W ICU Interrupt Polarity (0=Normal, 1=Invert) 8212h+N*4 0003 0000 8003 R/W ICU Vectored Interrupt 0..15 Addr, bit16-31 8214h+N*4 FC00 0000 FFFF R/W ICU Vectored Interrupt 0..15 Addr, bit0-15 8252h 0000 0000 FFFF R/W ICU Interrupt Master Disable (1=Off/undoc) 8254h 0000 0000 5555 R/W Unknown, R/W mask 5555h 8256h 0000 0000 5555 R/W Unknown, R/W mask 5555h 8258h..827Eh 0000 0000 0000 R Mirror of Port 8200h |
8280h+N*80h 0005 0000 FFFF R/W BTDMP Receive Control ;\ 8282h+N*80h 0000 0000 7FE7 R/W BTDMP Receive Period ; 8284h+N*80h 0000 0000 0FE7 R/W BTDMP Receive Usually 0004h ; 8286h+N*80h 0000 0000 0003 R/W BTDMP Receive Usually 0021h ; RX 8288h+N*80h 1FFF 0000 1FFF R/W BTDMP Receive Usually 0000h ; (microphone) 828Ah+N*80h 0000 0000 0FFF R/W BTDMP Receive Usually 0000h ; 828Ch+N*80h 0000 0000 3FFF R/W BTDMP Receive Usually 0000h ; 828Eh+N*80h 0000 0000 FFFF R/W BTDMP Receive Usually unused ; 8290h+N*80h 0000 0000 FFFF R/W BTDMP Receive Usually unused ; 8292h+... 0000 0000 0000 R Fixed 0000h ; 829Eh+N*80h 0000 0000 8000 R/W BTDMP Receive Enable ;/ 82A0h+N*80h 0005 0000 FFFF R/W BTDMP Transmit Control ;\ 82A2h+N*80h 0000 0000 7FE7 R/W BTDMP Transmit Period ; 82A4h+N*80h 0000 0000 0FE7 R/W BTDMP Transmit Usually 0004h ; 82A6h+N*80h 0000 0000 0003 R/W BTDMP Transmit Usually 0021h ; TX 82A8h+N*80h 1FFF 0000 1FFF R/W BTDMP Transmit Usually 0000h ; (audio out) 82AAh+N*80h 0000 0000 0FFF R/W BTDMP Transmit Usually 0000h ; 82ACh+N*80h 0000 0000 3FFF R/W BTDMP Transmit Usually 0000h ; 82AEh+N*80h 0000 0000 FFFF R/W BTDMP Transmit Usually unused ; 82B0h+N*80h 0000 0000 FFFF R/W BTDMP Transmit Usually unused ; 82B2h+... 0000 0000 0000 R Fixed 0000h ; 82BEh+N*80h 0000 0000 8000 R/W BTDMP Transmit Enable ;/ 82C0h+N*80h 001x 001F 001F R BTDMP Receive FIFO Status ;\ 82C2h+N*80h 0057 005x 0057 R BTDMP Transmit FIFO Status ; 82C4h+N*80h E0A1 FFFF E0A1 R BTDMP Receive FIFO Data ; RX/TX 82C6h+N*80h 0000 0000 0000 W BTDMP Transmit FIFO Data ; 82C8h+N*80h 0000 0000 0003 R/W BTDMP Receive FIFO Control ; 82CAh+N*80h 0000 0000 0003 R/W BTDMP Transmit FIFO Control ;/ 82CCh+... 0000 0000 0000 R Fixed 0000h 8380h..867Eh 03C0 03C0 03C0 R Mirror of Port 80D6h |
8680h..87FEh 03C0 03C0 03C0 R Mirror of Port 80D6h |
(this is called "Host-to-Core JAM protocol" and consists of 11bit values) (not sure if that are MMIO registers, or some 11bit data transfer protocol) 8800h..8807h 0000 0000 0000 R? Fixed 0 (reportedly H2C aka dbg stuff?) |
? JAM GLUE TMR SIO OCEM PMU APBP AHBM MIU CRU DMA ICU AUDIO ?
#0 3333 0000 0010 0020 0050 0060 0080 00A0 3333 00C0 3333 0100 0180 0200 3333
#1 0000 0004 0010 0020 0050 0060 0080 00C0 00E0 0100 0140 0180 0200 0280 0680
#2 3333 0004 0010 3333 3333 0020 0040 3333 3333 0060 3333 3333 0120 3333 3333
|
| DSi Teak MMIO[8000h] - Misc Registers (JAM/GLUE) |
0-10 Unknown (R/W) (0..7FFh=?) 11-14 Unused (0) 15 Unknown (R/W) (0..1=?) |
0 Timer 1 clock source (0=107MHz/Core, 1=Timer0_TOUT) 1 Timer 0 force restart upon Timer 1 output (0=No, 1=Yes) 2-15 Unused (0) |
0-1 Unknown (R/W) (0..3=?) 2-15 Unused (0) |
0-15 Unknown (R/W) (0..FFFFh=?) |
0-15 Unknown (DSi: always 0000h, New3DS: always 00BAh) |
0-3 Value A (R/W) 4 All four bits in Value A XORed together (R) 5-8 Value B (R/W) 9 All four bits in Value B XORed together (R) 10-13 Value C (R/W) 14 All four bits in Value C XORed together (R) 15 Value D (R/W) |
0-15 Fixed, always C902h on DSi and New3DS |
0 Reset (0=No, 1=Yes) 1 Boot (0=No, 1=Yes) 2 Debug (0=No, 1=Yes) 4 URST (user reset) (0=No, 1=Yes) 5 - 6 Internal Program (Load code to on-chip memory) (0=No, 1=Yes) 7-10 - |
0-6 - 7 Continue core's clock after stopped by software (0=No, 1=Yes) 8 Stop (Stop core's clock) (0=No, 1=Yes) 9 NMI (0=No, 1=Yes) 10 Abort (0=No, 1=Yes) |
0-10 Interrupt 0..10 (0=No, 1=Yes) |
0-10 GPI (General Purpose Input) 0..10 (0=Low, 1=High) |
0-4 GPI (General Purpose Input) 11..15 (0=Low, 1=High) 5-8 - 9-10 UI (User Input) 0..1 (0=Low, 1=High) |
0-10 Interrupt external/internal control 0..10 (0=Ext, 1=Int) |
0-10 GPI Enable Control 0..10 (0=Disable, 1=Enable) |
0-4 GPI Enable Control 11..15 (0=Disable, 1=Enable) 5-8 9-10 User Input Enable Control 0..1 (0=Disable, 1=Enable) |
| DSi Teak MMIO[8020h] - Timers (TMR) |
0-1 Time prescaler (0=Div1, 1=Div2, 2=Div4, 3=Div16)
2-4 Count mode
0h: single count Stop at zero
1h: auto restart Wrap from zero to Reload value
2h: free running Wrap from zero to FFFFFFFFh
3h: event count Decrement manually, and stop at zero
4h: watchdog mode 1 Trigger Teak Reset at zero
5h: watchdog mode 2 Trigger Teak NMI at zero
6h: watchdog mode 3 Trigger Unacknowledgeable-Timer-IRQ at zero?
7h: reserved Same as mode 0 (stop at zero)
5 Unused (0)
6 Output signal polarity (0=Normal, 1=Invert/Buggy?)
7 Clear output signal; when bit14-15=0 (0=No change, 1=Clear) (W)
8 Pause the counter (0=Unpause, 1=Pause)
9 Freeze COUNTER_L/H register value (0=Freeze, 1=Update)
Note: Bit8/Bit9 can be forced to always 1 via other Timer's Bit13
10 Restart/Reload the counter (0=No change, 1=Restart) (W)
11 Breakpoint requests enable (0=Disable, 1=Enable) (DANGER/TRAP)
12 Clock source (0=InternalClk=134MHz/107MHz, 1=ExternalClk=None)
13 General Purpose (somehow interact between Timer 0 and 1)
Timer0: Force Timer1.Control.Bit9=1 (0=No, 1=Yes/ForceUpdate)
Timer1: Force Timer0.Control.Bit8=1 (0=No, 1=Yes/ForcePause)
14-15 Clear output signal automatically (0=No, 1/2/3=After 2/4/8 cycles)
|
For Timer 0 (no "waitstates") --> 134.055928MHz For Timer 1 (with "waitstates") --> 107.244742MHz (aka 134.055928MHz/1.25) For Timer 1 (if GLUE_CFG0.bit0) --> Timer0_TOUT (bugs if Timer0_Reload<3) Unknown what "waitstates" refers to, probably not the Z0/Z1/Z2/Z3 waits? |
0 In Event Mode: Decrement Counter (0=No change, 1=Decrement)
In Watchdog Mode: Reload Counter (0=No change, 1=Reload)
1-15 Unused (0)
|
0-31 Start/Reload value for decrementing counter |
0-31 Current (or frozen) decrementing counter value |
0-31 Restart value for PWM counter (uh, maybe PWM duty?) |
| DSi Teak MMIO[8050h] - Serial Port (SIO) |
0 Chip Select Polarity (0=Active High, 1=Active Low) 1 Chip Select Output (0=Disable/Hangs, 1=Enable) (for Master) 2 Master/Slave Clock (0=FromClkDivider, 1=ExternalClk/Hangs) 3 Clock Polarity (0=Idle Low, 1=Idle High) 4 Clock Edge Phase (0=InputOnRising, 1=OutputOnRising) 5 Transfer End Interrupt (0=Enable, 1=Disable/Hangs/NoStatusDone) 6-11 Unused (0) 12-15 Num data bits per transfer (0=Hangs, 1..15=2bit..16bit) |
0-6 Clock Divider 1 (1..7Fh = Div1..Div127) (0=Div1, too) 7 Unused (0) 8-14 Clock Divider 2 (1..7Fh = Div1..Div127) (0=Div1, too) 15 Unused (0) |
0-15 Transfer data (probably using only LSBs when NumBits<16) |
0 Enable SIO operation (0=Disable/Hangs, 1=Enable) 1-15 Unused (0) |
0 Transfer done (0=No, 1=Done, Data can be read now) 1 Overrun error (0=No, 1=New data arrived before reading old data) 2-15 Unused (0) |
| DSi Teak MMIO[8060h] - Debug (OCEM, On-chip Emulation Module) |
0-17 Program Flow Trace Address 18-23 Unused (0) 24-27 Program Flow Trace Page 28-31 Unused (0) |
0-17 Program Break Address 18-23 Unused (0) 24-27 Program Break Page (should be usually 00h) 28-31 Unused (0) |
0-7 Program Address Break Counter (decrements upon PC=break.addr) 8-15 Unused (0) |
0-15 Mask/Address |
0 Data value break point on data write transaction 1 Data value break point on data read transaction 2 Data address break point as a result on data write transaction 3 Data address break point as a result on data read transaction 4 Simultaneous data address and data value match 5 External register write transaction ;\(aka ext0/1/2/3?) 6 External register read transaction ;/ 7 Program Address break 1 count zero 8 Program Address break 2 count zero 9 Program Address break 3 count zero 10 Break on any program jumps instead of executing the next address 11 Break on detection of interrupt service routine 12 Break as a result of program flow trace buffer full 13 Break when returning to the beginning of block repeat loop 14 Break on illegal condition (uh, are that... illegal opcodes?) 15 Single Step |
0 Program Flow Trace Buffer full (0=Not full/OldestIsGarbage, 1=Full) 1-11 Unknown (R/W) 12 MOVD instruction detected (uh, usually 1, even when not using movd?) 13 User reset activated while in break point service routine 14 Boot mode (0=No, 1=Yes) 15 Debug mode (0=No, 1=Yes) |
0 Break caused by Data value match 1 Break caused by Data address match 2 Break caused by Data value and data address match 3 Break caused by User defined register transaction (aka ext0/1/2/3?) 4 Break caused by an external event (aka what?) 5 Break caused by Program address break 1 count zero 6 Break caused by Program address break 2 count zero 7 Break caused by Program address break 3 count zero 8-10 Unknown (R/W) 11 Break caused by Branch break point 12 Break caused by Interrupt break point 13 Break caused by Program Flow Trace Buffer full 14 Break caused by Illegal break point 15 Break caused by Software trap |
0 Disable Program Flow Buffer Updating (0=Enable, 1=Disable) 1-15 Unused (0) |
0-15 Unknown (R/W) |
0-13 Unused? (0) 14 Boot mode (0=No, 1=Yes) 15 Debug mode (0=No, 1=Yes) |
| DSi Teak MMIO[8080h] - PLL and Power (PMU, Power Management Unit) |
0-15 Configuration of the PLL clock multiplication (0..FFFFh=what?) |
0 PLL power-on configuration value for PLL use (0..1=what) 1-15 Unused (0) |
0-6 Clock Divider (0 or 1=Div1) (2..7Fh=Crashes?) 7-14 Unused (0) 15 Bypass PLL (0=Use PLL/Crashes, 1=Bypass; works only if Div1) |
For registers MMIO[8086h..8096h]: 0 Core ;aka cpu? 1 DMA 2 SIO 3 GLUE 4 APBP/HPI 5 AHBM 6 Unused (0) 7 OCEM 8 Timer 0 9 Timer 1 10 JAM 11-15 Unused (0) For registers MMIO[809Ah..80A8h]: 0 BTDMP 0 1 BTDMP 1 2-15 Unused (0) |
0 Unused (0) 1 DMA 2-7 Unused (0) 8 Timer 0 9 Timer 1 10-15 Unused (0) |
| DSi Teak MMIO[80C0h] - Host Port Interface (APBP aka HPI) |
0-15 Command/Reply Data |
0-15 Semaphore Flag 0..15 |
0-1 Unused (0) 2 ARM-side register endianness (0=Normal, 1=Big-Endian/DANGER) 3-7 Unused (0) 8 Interrupt when CMD0 is written by ARM (0=Enable, 1=Disable) 9-11 Unused (0) 12 Interrupt when CMD1 is written by ARM (0=Enable, 1=Disable) 13 Interrupt when CMD2 is written by ARM (0=Enable, 1=Disable) 14-15 Unused (0) |
0-4 Unused? (usually 0) 5 Reply Register 0 Read Flag (0=Was Read by ARM?, 1=No) 6 Reply Register 1 Read Flag (0=Was Read by ARM?, 1=No) 7 Reply Register 2 Read Flag (0=Was Read by ARM?, 1=No) 8 Command Register 0 Update Flag (0=Was Written by ARM?, 1=No) 9 Semaphore IRQ Flag (0=No, 1=[80D2h] AND NOT [80CEh]) 10-11 Unused? (usually 0) 12 Command Register 1 Update Flag (0=Was Written by ARM?, 1=No) 13 Command Register 2 Update Flag (0=Was Written by ARM?, 1=No) 14-15 Unused? (usually 0) |
0 Read Transfer Underway Flag (0=No, 1=Yes/From DSP Memory) 1 Write Transfer Underway Flag (0=No, 1=Yes/To DSP Memory) 2 Peripheral Reset Flag (0=No/Ready, 1=Reset/Busy) 3-4 Unused (0) 5 Read FIFO Full Flag (0=No, 1=Yes/Full) 6 Read FIFO Not-Empty Flag (0=No, 1=Yes, ARM9 may read PDATA) 7 Write FIFO Full Flag (0=No, 1=Yes/Full) 8 Write FIFO Empty Flag (0=No, 1=Yes/Empty) 9 Semaphore IRQ Flag (0=None, 1=IRQ) 10 Reply Register 0 Update Flag (0=Was Written by DSP, 1=No) 11 Reply Register 1 Update Flag (0=Was Written by DSP, 1=No) 12 Reply Register 2 Update Flag (0=Was Written by DSP, 1=No) 13 Command Register 0 Read Flag (0=Was Read by DSP, 1=No) 14 Command Register 1 Read Flag (0=Was Read by DSP, 1=No) 15 Command Register 2 Read Flag (0=Was Read by DSP, 1=No) |
| DSi Teak MMIO[80E0h] - AHBM - Advanced High Performance Bus Master |
02000000h/Main RAM --> works 03000000h/Shared RAM --> works (maybe also New Shared RAM, if any mapped?) 04000000h/ARM9 I/O --> works 05000000h/Palette --> works 06000000h/VRAM --> works 07000000h/OAM --> works 08000000h/GBA SLOT ROM --> works (with dummy FFFFFFFFh values) 0A000000h/GBA SLOT RAM --> works (with dummy FFFFFFFFh values) FFFF0000h/ARM9 BIOS --> works (lower 32K only, upper 32K is zerofilled) DTCM/ITCM --> probably ignored? Any other --> returns zero (but without MMIO[80E0h] error flag) |
20000000h/FCRAM --> works 1FF80000h/AXI --> works 1FF40000h/DSP/DATA --> oddly mirrors to 1FF80000h/AXI Any other --> rejected (and sets MMIO[80E0h].bit4 error flag) |
0-1 Usually/always 0 ? 2 Burst queue not empty (0=Empty, 1=Not-empty) 3 Usually/always 0 ? 4 Busy/stuck/error? (0=Normal, 1=Invalid ARM address) ;3DS only? 5-15 Usually/always 0 ? |
0 Applications set this to 1 if BURST is non-zero, uh? 1-2 Burst type (0=x1, 1=x4, 2=x8, 3=?) 3 Unknown (R/W) (0=Normal, 1=Dunno/NoTransfer?) 4-5 Data type (0=8bit, 1=16bit, 2=32bit, 3=?) 6 Unused (0) 7 Unknown (R/W) (0=Normal, 1=Dunno/TransferHangs/crashes?) 8-11 Unknown (R/W) (0..Fh=?) (usually 0) 12-15 Unused (0) |
0-7 Unknown (R/W) (0..FFh=?) (usually 0) 8 Transfer direction (0=Read external memory, 1=Write external memory) 9 Applications always set this (usually 1=set) (but also works when 0) 10-15 Unused (0) |
0-7 Connect to DMA channel 0..7 (0=No, 1=Connect) 8-15 Unused (0) |
| DSi Teak MMIO[8100h] - Memory Interface Unit (MIU) |
0-3 Number of wait-states for off-chip Z0 block 4-7 Number of wait-states for off-chip Z1 block 8-11 Number of wait-states for off-chip Z2 block 12-15 Number of wait-states for off-chip Z3 block 16-19 Number of wait-states for off-chip Z blocks outside Z0/Z1/Z2/Z3 20-23 Number of wait-states for off-chip X/Y memory transactions 24-27 Number of wait-states for off-chip Program-memory transactions 28-31 Unused (0) |
0-5 Wait-state block Start address in 1K-word units 6-11 Wait-state block End address in 1K-word units 12-15 Wait-state block Page (lower 4bit of page) |
0-15 Memory Page (...base or so, in WHAT-units?) |
0-7 Memory Page (...base or so, in WHAT-units?) 8-15 Unused (0) |
When PGM=0 --> MMIO[8112h] is the "absolute" data memory page When PGM=1 --> MMIO[810Eh/8110h/8112h] are the X/Y/Z pages |
0-5 X memory size (0..3Fh) 6-7 Unused (0) 8-14 Y memory size (1..40h) 15 Unused (0) |
When PGM=0?--> MMIO[8114h,8116h,8118h] used for Page 0, 1, and Off-chip pages When PGM=1?--> MMIO[8114h] used for all pages |
0 Program protection mechanism, uh, what is that? (0=Disable, 1=Enable) 1 Program page for entire program space (from Test pin) (1=offchip) 2 Program page for breakpoint handler (0=Page1/offchip, 1=Page0/onchip) 3 Unknown (R/W) (0..1=?) 4 Core/DMA data use only Z-even address bus (single? PGM=0?) (1=Enable) 5 Unknown (R/W) (0..1=?) 6 Paging mode (PGM) (for X/Y/Z pages) (0=Normal, 1=DANGER) 7-15 Unused (0) |
0 Select Z-space data memory (0=Regular Memory, 1=Download memory) 1 Download mem is/was selected (bit1 can be cleared during Trap only) 2-5 Alternative Program Page for movd/movp opcodes (PDLPAGE) (4bit) 6 Select program page for movd/movp (0=2bit/movpd, 1=4bit/PDLPAGE) 7-15 Unused (0) |
0-9 Unused (0) 10-15 MMIO Base Address (in 400h-word units) |
0 Observability Enable (0=Disable, 1=Enable) 1-3 Observability Mode (0..4=Mode, see below) 4-15 Unused (0) |
00h: Core XZ address/data buses 01h: Core Y address/data buses 02h: Core P address/data buses 03h: DMA DST address/data buses 04h: DMA SRC address/data buses |
0 Z Read Polarity Bit - for DRZON/DRZEN 1 Z Write Polarity Bit - for DWZON/DWZEN 2 Z Strobe Polarity Bit - for ZSTRB 3 X Strobe Polarity Bit - for XSTRB 4 X Select Polarity Bit - for XS 5 Z Select Polarity Bit - for ZS 6 Signal Polarity Bit - for RD_WR 7-15 Unused (0) |
| DSi Teak MMIO[8140h] - Code Replacement Unit (CRU) |
0-17 Program Address (0..3FFFFh) (R/W) 18-21 Program Page (usually 0) (0..Fh) (R/W) 22-30 Unused (0) (except bit25-30 in entry 15) 25-28 Entry 15: Match entry number (0..15=Entry 0..15) (R) 29 Entry 15: Match flag (cleared after read) (0=None, 1=Yes/match) (R) 30 Entry 15: Master enable for all entries (0=Disable, 1=Enable) (R/W) 31 Enable Entry (0=Disable, 1=Enable) (R/W) |
| DSi Teak MMIO[8180h] - Direct Memory Access (DMA) |
_____________________________ DMA Control/Status _____________________________ |
0-7 Channel 0..7 flags 8-15 Unused (0) |
0-7 Channel 0..7 end flags (0=No, 1=End) 8-15 Unused (0) |
0-2 Whatever (0..7) (initially 0 on reset) 4-6 Whatever (0..7) (initially 1 on reset) 8-10 Whatever (0..7) (initially 2 on reset) 12-14 Whatever (0..7) (initially 3 on reset) 16-18 Whatever (0..7) (initially 4 on reset) 20-22 Whatever (0..7) (initially 5 on reset) 24-24 Whatever (0..7) (initially 6 on reset) 28-30 Whatever (0..7) (initially 7 on reset) Bit3,7,11,15,19,23,25,31 are unused (always 0) |
________________________________ DMA Channels ________________________________ |
0-2 Select the channel to be mapped to MMIO[81C0h..81Exh] (0..7) 3-15 Unused (0) |
0-31 Address (within the selected memory area, see MMIO[81DAh]) |
0-15 Length (for each array dimension) (0001h..FFFFh) |
0-15 Step (... in 8bit/16bit/32bit units?) (signed or unsigned?) |
0-3 Source Memory Area (0..0Fh, see below) 4-7 Destination Memory Area (0..0Fh, see below) 8 Unknown? (0=Normal, 1=No Irq, No end, maybe repeat?) 9 Different Memory Areas (0=No/Slow, 1=Yes/Simultaneous Read+Write) 10 Transfer Unit size (0=16bit/Slow, 1=32bit/Fast) 11 Unused (0) 12-13 Unknown? (0..3=?) 12-15 Transfer Speed (0=Slow, 1/2=Medium, 3=Fast) (or burst size?) |
00h DSP/Data memory ;\ 01h DSP/MMIO registers ; 16bit-address units 05h DSP/Code memory (only for DST_SPACE) (untested) ;/ 07h ARM/AHBM external memory (via AHBM registers) ;-8bit-address units |
0-2 Unknown (R/W) (0..07h=?) (usually 0) 3 Unused (0) 4-7 Unknown (R/W) (0..0Fh=?) (usually 0h) 8-9 Unknown (R/W) (0/1/2=Hangs?, 3=Normal) 10-12 Unknown (R/W) (0..07h=?) (usually 0h) 13-15 Unused (0) |
0-2 Interrupt upon Size 0..2 End (0=Disable, 1=Enable) (R/W) 3-5 Never set Size2 End flag? (0=Normal, 1=No end, maybe repeat?) (R/W) 6-7 Unknown (0..3) (R/W) 8-13 Unused? (0) 14-15 Start/Stop Transfer (0=No change, 1=Start, 2=Stop, 3=Same as 1) (W) |
______________________ DMA Unknown/Internal Registers ________________________ |
_________________________________ DMA Notes _________________________________ |
SRC_ADDR = 0 SIZE0 = 3 SIZE1 = 5 SIZE2 = 2 SRC_STEP0 = 2 SRC_STEP1 = 1 SRC_STEP2 = 7 |
<--------------------------size1--------------------------> <--size0--> <--size0--> <--size0--> <--size0--> <--size0--> 0, 2, 4, 5, 7, 9, 10, 12, 14, 15, 17, 19, 20, 22, 24 <-- size2 (1st) 31, 33, 35, 36, 38, 40, 41, 43, 45, 46, 48, 50, 51, 53, 55 <-- size2 (2nd) |
| DSi Teak MMIO[8200h] - Interrupt Control Unit (ICU) |
0-8 No hardware IRQs (but can be used as Software IRQs via Manual Trigger) 9 Timer 1 10 Timer 0 11 BTDMP 0 12 BTDMP 1 13 SIO 14 APBP 15 DMA |
0-17 Address of interrupt handler for vectored interrupt 0..15 18-30 Unused (0) 31 Context switch on vectored interrupt 0..15 (0=Disable, 1=Enable) |
0-15 Master Disable for interrupt 0..15 (0=Normal, 1=Off, don't set pending) |
code:00000h start (from reset or timer watchdog) code:00002h trap_handler (trap/break) (from OCEM or Timers) code:00004h nmi_handler (non-maskable interrupt) (from timer watchdog) code:00006h int0_handler code:0000Eh int1_handler code:00016h int2_handler code:variable vint_handler(s) (with context switch, instead of push/pop?) |
new_state=incoming_hw_signal ;always 0 for interrupt 0..8 if polarity=1 then new_state=new_state xor 1 new_state=new_state OR manual_trigger ;done AFTER above polarity invert new_state=new_state AND NOT master_disable if new_state=1 and old_state=0 then pending=1 old_state=new_state |
| DSi Teak MMIO[8280h] - Audio (Buffered Time Division Multiplexing Port) |
BTDMP 0 is used for Receive (microphone) and Transmit (audio out). BTDMP 1 isn't actually used for anything. |
0-3 Unknown (0..Fh) (usually 0Dh/0Fh) 4-7 Unknown (0..Fh) (usually 00h) 8-11 Enable BTDMP Interrupt when non-zero (0=Off, AnyOther=On?) 12-15 Unknown (0..Fh) (usually 00h) |
0-2 Clock Divider? (0..7) (usually 4) (affects timing when bit13=1) 3-4 Unused (0) 5-12 Clock Divider? (0..FFh) (usually 80h) (affects timing when bit13=1) 13 Clock Select (0=ExternalDSiAudioClk, 1=InternalClkDivider?) 14 Unknown (0..1) (usually 0) 15 Unused (0) |
0-2 Unknown (0..7) (R/W) (R/W) 3-4 Unused? (0) 5-11 Unknown (0..7Fh) (R/W) (R/W) 12-15 Unused? (0) |
0-1 Unknown (0..3) (R/W) (R/W) 2-4 Unused? (0) 5 Unknown/writeonly? (read=0) (code writes 1 here) (W?) 6-15 Unused? (0) |
0-12 Unknown (0..1FFFh) (R/W) (initially=1FFFh on reset) 13-15 Unused (0) |
0-11 Unknown (0..0FFFh) (R/W) 12-15 Unused (0) |
0-13 Unknown (0..3FFFh) (R/W) 14-15 Unused (0) |
0-15 Unknown (0..FFFFh) (R/W) |
0-14 Unused (0) 15 Enable Transfer (0=Off, 1=On, allow Transfer+IRQ's) |
________________________________ BTDMP FIFOs _________________________________ |
0 usually 0 1 If transfer ENABLED usually set, sometimes 0 2 If transfer ENABLED usually set 3 FIFO Full (0=No, 1=Full, 16x16bit words) 4 FIFO Empty (0=No, 1=Empty, 0x16bit words) 5 If transfer ENABLED usually set 6 usually 0 7 For TX: gets set when FIFO contains ONE word? 8-15 usually 0 |
0-15 Signed 16bit audio sample. |
0-1 Unknown (0..3=?) (R/W) 2 Flush FIFO (0=No change, 1=Clear FIFO) (W) 3-15 Unused (0) |
| DSi Teak CPU Registers |
a0e:a0h:a0l (4:16:16 bits) = a0 (36bit) ;TL2: 40bit (8:16:16) a1e:a1h:a1l (4:16:16 bits) = a1 (36bit) ;TL2: 40bit (8:16:16) b0e:b0h:b0l (4:16:16 bits) = b0 (36bit) ;TL2: 40bit (8:16:16) b1e:b1h:b1l (4:16:16 bits) = b1 (36bit) ;TL2: 40bit (8:16:16) |
r0 ;TL ;16bit ;\ r1 ;TL ;16bit ; r2 ;TL ;16bit ; old TL1 registers r3 ;TL ;16bit ; r4 ;TL ;16bit ; r5 ;TL ;16bit ;/ r6 ;TL2 ;16bit ;<-- new TL2 register r7 ;TL ;16bit ;<-- aka rb (with optional immediate, MemR7Imm) |
x0 ;TL ;16bit ;- y0 ;TL ;16bit ;- x1 ;TL2 ;16bit ;- y1 ;TL2 ;16bit ;- p0 ;TL ;33bit! ;\Px ;TL2: 33bit p0e:p0 ? ;TL1: 32bit? p1 ;TL2 ;33bit! ;/ ;TL2: 33bit p1e:p1 ? ;TL1: N/A p0h ;TL ;16bit ; ;<-- aka ph ;<-- called "p0" (aka "p") in "RegisterP0" |
Unsigned = Unsigned * Unsigned ;use shift 0 Unsigned = Unsigned * Signed ;use shift +1 Unsigned = Signed * Signed ;use shift +2 Signed = Unsigned * Unsigned ;use shift -1 Signed = Unsigned * Signed ;use shift 0 Signed = Signed * Signed ;use shift +1 |
pc ;TL ;18bit! ;-program counter (TL2: 18bit, TL1: 16bit) sp ;TL ;16bit ;-stack pointer (decreasing on push/call) sv ;TL ;16bit ;-shift value (negative=right) (for shift-by-register) mixp ;TL ;16bit ;-related to min/max/mind/maxd lc ;TL ;16bit ;-Loop Counter (of block repeat) repc ;TL ;16bit ;-Repeat Counter (for "rep" opcode) dvm ;TL ;16bit ;-Data Value Match (OCEM data breakpoints) (and for trap) |
vtr0 ;TL2 16bit ;\related to vtrshr,vtrmov,vtrclr vtr1 ;TL2 16bit ;/(saved C/C1 carry flags for Viterby decoding) prpage ;TL2 4bit ;-??? (bit0-3 used/dangerous, bit4-15 always 0) |
ext0 ;TL ;16bit ext1 ;TL ;16bit ext2 ;TL ;16bit ext3 ;TL ;16bit |
page ;TL ;8bit "load" st1.bit0-7 (page for MemImm8) ;aka "lpg" ps ;TL ;2bit "load" st1.bit10-11 (product shifter for multiply?) ps01 ;TL2 ;4bit "load" mod0...? (maybe separate "ps" for p0 and p1 ?) movpd ;TL2 ;2bit "load" stt2.bit6-7 (page for reading DATA from ProgMem) modi ;TL ;9bit "load" cfgi.bit7-15 =imm9 modj ;TL ;9bit "load" cfgj.bit7-15 =imm9 stepi ;TL ;7bit "load" cfgi.bit0-6 =imm7 stepj ;TL ;7bit "load" cfgj.bit0-6 =imm7 |
st0 bit0,2-11 ;\control/status (cntx) st1 bit10-11 (and "swap": bit0-7) ; (TL2: probably also SttMod) st2 bit0-7 ;/ a0 <--> b0 manualswap only? ;\accumulators (swap) a1 <--> b1 autoswapped? ;/ r0 <--> r0b ;\ r1 <--> r1b ; r4 <--> r4b ; BankFlags (banke) r7 <--> r7b ;TL2 ; cfgi <--> cfgib ; cfgj <--> cfgjb ;TL2 ;/ Ar,Arp <--> ? ;TL2 ;-? (bankr and/or cntx) |
dmod ;TL ;suffix ;\ dmodi ;TL2 ;suffix ; dmodj ;TL2 ;suffix ; dmodij ;TL2 ;suffix ;/ context;TL ;suffix ;<-- (related to "cntx") eu ;TL ;suffix ;<-- (aka "Axheu", now "Axh,eu") dbrv ;TL2 ;suffix ;\for "bitrev" ebrv ;TL2 ;suffix ;/ s ;TL ;suffix ;\param for "cntx" opcode ;"s" also for opcode 88D1h r ;TL ;suffix ;/ |
TL: x y p ph rb lpg a0heu a1heu TL2: x0 y0 p0 p0h r7 page a0h,eu a1h,eu |
| DSi Teak CPU Control/Status Registers |
Old registers (for TeakLite): st0/st1/st2, and icr New registers (for TeakLiteII): stt0/stt1/stt2, and mod0/mod1/mod2/mod3 |
ZMNVCEL- add, addh, addl, cmp, cmpu, sub, subh, subl, inc, dec, neg ZMNVCEL- maa, maasu, mac, macsu, macus, macuu, msu, sqra, rnd, pacr, movr ZMN-C--- or ZM--C--- addv, cmpv, subv, and ZMN--E-- clr, clrr, copy, divs, swap, not, xor ZMN--0L- lim ZMNVCELR norm ZMN-CE-- rol, ror ZMN-CE-- movs, movsi, shfc, shfi, shl, shl4, shr, shr4 ;for logical shift ZMNVCEL- movs, movsi, shfc, shfi, shl, shl4, shr, shr4 ;for arithmetic shift ZMN--E-- mov, movp, pop ;when dst=ac,bc (whut?) ;\ xxxxxxxx mov, movp, pop ;when dst=st0 ; mov etc. ------L- mov, push ;when src=aXL,aXH,bXL,bXH ; -------- mov, movp, pop, push ;when src/dst neither of above ;/ ZMN--E-- cntx s ;store shadows (new flags for a1) ;\cntx ZMNVCELR cntx r ;restore shadows (old flags) ;/ ZM------ set, rst, chng Z------- tst0, tst1, tstb -M------ max, maxd, min -------R modr -------- mpy, mpyi, mpysu, sqr, exp -------- banke, dint, eint, load, nop, bkrep, rep, break, trap, movd -------- br, brr, call, calla, callr, ret, retd, reti, retid, rets |
__________________________ Old registers (TeakLite) __________________________ |
0 SAT R/W Saturation Mode (0=Off, 1=Saturate "Ax to data") ;mod0.0 1 IE R/W Interrupt Enable (0=Disable, 1=Enable) ;dint/eint ;mod3.7 2 IM0 R/W Interrupt INT0 Mask (0=Disable, 1=Enable if IE=1) ;mod3.8 3 IM1 R/W Interrupt INT1 Mask (0=Disable, 1=Enable if IE=1) ;mod3.9 4 R R/W Flag: rN is Zero ;see Cond nr ;stt1.4 5 L R/W Flag: Limit ;see Cond l ;L=(LM or VL) ;stt0.0+1 6 E R/W Flag: Extension ;see Cond e ;stt0.2 7 C R/W Flag: Carry ;see Cond c ;stt0.3 8 V R/W Flag: Overflow ;see Cond v ;stt0.4 9 N R/W Flag: Normalized ;see Cond nn ;stt0.5 10 M R/W Flag: Minus ;see Cond gt,ge,lt,le ;stt0.6 11 Z R/W Flag: Zero ;see Cond eq,neq,gt,le ;stt0.7 12-15 a0e R/W Accumulator 0 Extension Bits ;a0.32-35 |
0-7 PAGE R/W Data Memory Page (for MemImm8) (see "load page") ;mod1.0-7
8-9 - - Reserved (read: always set) ;-
10-11 PS R/W Product Shifter for P0 (see "load ps")(multiply?) ;mod0.10-11
(0=No Shift, 1=SHR1, 2=SHL1, 3=SHL2)
12-15 a1e R/W Accumulator 1 Extension Bits ;a1.32-35
|
0-3 MDn R/W Enable cfgi.modi modulo for R0..R3 (0=Off, 1=On) ;mod2.0-3 4-5 MDn R/W Enable cfgj.modj modulo for R4..R5 (0=Off, 1=On) ;mod2.4-5 6 IM2 R/W Interrupt INT2 Mask (0=Disable, 1=Enable if IE=1) ;mod3.10 7 S R/W Shift Mode (0=Arithmetic, 1=Logic) ;mod0.7 8 OU0 R/W OUSER0 User Output Pin ;mod0.8 9 OU1 R/W OUSER1 User Output Pin ;mod0.9 10 IU0 R IUSER0 User Input Pin (zero) ;see Cond iu0,niu0 ;stt1.?? 11 IU1 R IUSER1 User Input Pin (zero) ;see Cond iu1 ;stt1.?? 12 - - Reserved (read: always set) ;- 13 IP2 R Interrupt Pending INT2 (0=No, 1=IRQ) ;stt2.2 14 IP0 R Interrupt Pending INT0 (0=No, 1=IRQ) ;stt2.0 15 IP1 R Interrupt Pending INT1 (0=No, 1=IRQ) ;stt2.1 |
0 NMIC R/W NMI Context switching enable (0=Off, 1=On) ;mod3.0 1 IC0 R/W INT0 Context switching enable (0=Off, 1=On) ;mod3.1 2 IC1 R/W INT1 Context switching enable (0=Off, 1=On) ;mod3.2 3 IC2 R/W INT2 Context switching enable (0=Off, 1=On) ;mod3.3 4 LP R InLoop (when inside one or more "bkrep" loops) ;stt2.15 5-7 BCn R Block repeat nest. counter ;see "bkrep" ;stt2.12-14 8-15 - - Reserved (read: always set) ;- |
_________________________ New registers (TeakLiteII) _________________________ |
0 LM R/W Flag: Limit, set if saturation has/had occured ;st0.5 1 VL R/W Flag: LatchedV, set if overflow has/had occurred ;st0.5, too 2 E R/W Flag: Extension ;see Cond e ;st0.6 3 C R/W Flag: Carry ;see Cond c ;st0.7 4 V R/W Flag: Overflow ;see Cond v ;st0.8 5 N R/W Flag: Normalized ;see Cond nn ;st0.9 6 M R/W Flag: Minus ;see Cond gt,ge,lt,le ;st0.10 7 Z R/W Flag: Zero ;see Cond eq,neq,gt,le ;st0.11 8-10 - - Unknown (reads as zero) 11 C1 R/W Flag: Carry1 (2nd carry, for dual-operation opcodes) 12-15 - - Unknown (reads as zero) |
0-3 - - Unknown (reads as zero) 4 R R/W Flag: rN is Zero ;see Cond nr ;st0.4 5-13 - - Unknown (reads as zero) (IU1 and IU0 should be here!) 14 P0E R/W Upper bit of 33bit P0 register ;\shifted-in on ;p0.32 15 P1E R/W Upper bit of 33bit P1 register ;/arith right shifts ;p1.32 |
0 IP0 R Interrupt Pending INT0 (0=No, 1=IRQ) ;st2.14
1 IP1 R Interrupt Pending INT1 (0=No, 1=IRQ) ;st2.15
2 IP2 R Interrupt Pending INT2 (0=No, 1=IRQ) ;st2.13
3 IPV R Interrupt Pending VINT ;-
4-5 - - Unknown (reads as zero) ;-
6-7 PCMhi R/W Program Memory Bank (for ProgMemRn/ProgMemAxl) ("load movpd")
8-11 - - Unknown (reads as zero) ;-
12-14 BCn R Block repeat nest. counter ;see "bkrep" ;icr.5-7
15 LP R InLoop (when inside one or more "bkrep" loops) ;icr.4
|
0 SAT R/W Saturation Mode (0=Off, 1=Saturate "Ax to data"?) ;st0.0
1 SATA R/W Saturation Mode on store (0=Off, 1="(Ax op data) to Ax"?)
2 ? R Unknown (reads as one)
3 - - Unknown (reads as zero)
4 - - Unknown (reads as zero)
5-6 HWM R/W Halfword Multiply ... Modify y0 (and y1?)
0=read y0/y1 directly (full 16bit words)
1=Takes y0>>8 and y1>>8 (logic shift)
2=Takes y0&0xFF and y1&0xFF
3=Takes y0>>8 and y1&&0xFF
7 S R/W Shift Mode (0=Arithmetic, 1=Logic) ;st2.7
8 OU0 R/W OUSER0 User Output Pin ;st2.8
9 OU1 R/W OUSER1 User Output Pin ;st2.9
10-11 PS0 R/W Product Shifter for P0 (see "load ps")(multiply?) ;st1.10-11
12 - - Unknown (reads as zero)
13-14 PS1 R/W Product Shifter for P1 (see "load ps")(multiply?)
15 - - Unknown (reads as zero)
|
0-7 PAGE R/W Data Memory Page (for MemImm8) (see "load page") ;st1.0-7
8-11 - - Unknown (reads as zero)
12 STP16 R/W banke opcode (0=exchange cfgi/cfgj, 1=cfgi/cfgj+stepi0/stepj0)
1=use stepi0/j0 instead of stepi/j for stepping Rn registers
13 CMD R/W Change Modulo mode (0=New TL2 style, 1=TL1 style)
14 EPI R/W Unknown (1=Set R3=0 after any "modr R3" or "access[R3]"?)
15 EPJ R/W Unknown (1=Set R7=0 after any "modr R7" or "access[R7]"?)
|
0-3 MDn R/W Enable cfgi.modi modulo for R0..R3 (0=Off, 1=On) ;st2.0-3 4-5 MDn R/W Enable cfgj.modj modulo for R4..R5 (0=Off, 1=On) ;st2.4-5 6-7 MDn R/W Enable cfgj.modj modulo for R6..R7 (0=Off, 1=On) ;TL2 only 8-11 BRn R/W Step +s for R0..R3 (0=cfgi.stepi, 1=stepi0) 12-15 BRn R/W Step +s for R4..R7 (0=cfgj.stepi, 1=stepj0) |
0 NMIC R/W NMI Context switching enable (0=Off, 1=On) ;icr.0 1 IC0 R/W INT0 Context switching enable (0=Off, 1=On) ;icr.1 2 IC1 R/W INT1 Context switching enable (0=Off, 1=On) ;icr.2 3 IC2 R/W INT2 Context switching enable (0=Off, 1=On) ;icr.3 4 OU2 R/W Unknown (R/W) 5 OU3 R/W Unknown (R/W) 6 OU4 ? ---DANGER BIT--- (1=hangs/crashes when set) 7 IE R/W Interrupt Enable (0=Disable, 1=Enable) ;dint/eint ;st0.1 8 IM0 R/W Interrupt INT0 Mask (0=Disable, 1=Enable if IE=1) ;st0.2 9 IM1 R/W Interrupt INT1 Mask (0=Disable, 1=Enable if IE=1) ;st0.3 10 IM2 R/W Interrupt INT2 Mask (0=Disable, 1=Enable if IE=1) ;st2.6 11 IMV R/W Interrupt VINT Mask (0=Disable, 1=Enable if IE=1?) 12 - - Unknown (reads as zero) 13 CCNTA R/W Unknown (R/W) 14 CPC R/W Stack word order for PC on call/ret (0=Normal, 1=Reversed) 15 CREP R/W Unknown (R/W) |
| DSi Teak CPU Address Config/Step/Modulo |
_______________________________ Address Config _______________________________ |
Unknown which settings affect which opcodes exactly. |
0-2 R/W PM1/PM3 Post Modify Step (0..7 = +0,+1,-1,+s,+2,-2,+2,-2) 3-4 R/W CS1/CS3 Offset (0..3 = +0,+1,-1,-1) 5-7 R/W PM0/PM2 Post Modify Step (0..7 = +0,+1,-1,+s,+2,-2,+2,-2) 8-9 R/W CS0/CS2 Offset (0..3 = +0,+1,-1,-1) 10-12 R/W RN1/RN3 Register (0..7 = R0..R7) 13-15 R/W RN0/RN2 Register (0..7 = R0..R7) |
0-2 R/W PIn Post Modify Step I (0..7 = +0,+1,-1,+s,+2,-2,+2,-2) 3-4 R/W CIn Offset I (0..3 = +0,+1,-1,-1) 5-7 R/W PJn Post Modify Step J (0..7 = +0,+1,-1,+s,+2,-2,+2,-2) 8-9 R/W CJn Offset J (0..3 = +0,+1,-1,-1) 10-11 R/W RIn Register I (0..3 = R0..R3) 12 - - Unused (always zero) 13-14 R/W RJn Register J (0..3 = R4..R7) 15 - - Unused (always zero) |
________________________________ Step/Modulo ________________________________ |
0-6 stepi/stepj (7bit) (see "load stepi/stepj") ;step "Rn+s" ? 7-15 modi/modj (9bit) (see "load modi/modj") |
0-16 stepi0/stepj0 |
| DSi TeakLite II Instruction Set Encoding |
Base Ver Opcode (with parameter bits located at @bitnumber and up)
D4FBh TL add MemImm16@16, Ax@8
A600h TL add MemImm8@0, Ax@8
86C0h TL add Imm16@16, Ax@8
C600h TL add Imm8u@0, Ax@8
D4DBh TL add MemR7Imm16@16, Ax@8
4600h TL add MemR7Imm7s@0, Ax@8
8680h TL add MemRn@0, Ax@8 || Rn@0stepZIDS@3
86A0h TL add RegisterP0@0, Ax@8
D2DAh TL2 add Ab@10, Bx@0
5DF0h TL2 add Bx@1, Ax@0
9070h TL2 add MemR01@8, sv, Abh@2 || sub MemR01@8offsZI@0, sv, Abl@2
|| mov Abl@2, MemR45@8 || R01@8stepII2@0, R45@8stepII2@1
5DB0h TL2 add MemR04@1, sv, Abh@2 || sub MemR04@1offsZI@0, sv, Abl@2
|| R04@1stepII2@0
6F80h TL2 add MemR45@2, MemR01@2, Abh@3
|| add MemR45@2offsZI@1, MemR01@2offsZI@0, Abl@3
|| R01@2stepII2@0, R45@2stepII2@1
6FA0h TL2 add MemR45@2, MemR01@2, Abh@3
|| sub MemR45@2offsZI@1, MemR01@2offsZI@0, Abl@3
|| R01@2stepII2@0, R45@2stepII2@1
5E30h TL2 add MemR45@8, sv, Abh@2 || sub MemR45@8offsZI@1, sv, Abl@2
|| mov Abl@2, MemR01@8 || R01@8stepII2@0, R45@8stepII2@1
5DC0h TL2 add p0, p1, Ab@2
D782h TL2 add p1, Ax@0
5DF8h TL2 add Px@1, Bx@0
D38Bh TL2 add r6, Ax@4
4590h TL2 add3 p0, p1, Ab@2
4592h TL2 add3a p0, p1, Ab@2
4593h TL2 add3aa p0, p1, Ab@2
5DC1h TL2 adda p0, p1, Ab@2
B200h TL addh MemImm8@0, Ax@8
9280h TL addh MemRn@0, Ax@8 || Rn@0stepZIDS@3
92A0h TL addh Register@0, Ax@8
9464h TL2 addh r6, Ax@0
90E0h TL2 addhp MemR0425@2, Px@4, Ax@8 || R0425@2stepII2D2S@0 ;p=ProgMem? Px?
B400h TL addl MemImm8@0, Ax@8
9480h TL addl MemRn@0, Ax@8 || Rn@0stepZIDS@3
94A0h TL addl Register@0, Ax@8
9466h TL2 addl r6, Ax@0
906Ch TL2 addsub p0, p1, Ab@0
49C2h TL2 addsub p1, p0, Ab@4
916Ch TL2 addsuba p0, p1, Ab@0
49C3h TL2 addsuba p1, p0, Ab@4
E700h TL addv Imm16@16, MemImm8@0
86E0h TL addv Imm16@16, MemRn@0 || Rn@0stepZIDS@3
87E0h TL addv Imm16@16, Register@0
47BBh TL2 addv Imm16@16, r6
D4F9h TL and MemImm16@16, Ax@8
A200h TL and MemImm8@0, Ax@8
82C0h TL and Imm16@16, Ax@8
C200h TL and Imm8u@0, Ax@8
D4D9h TL and MemR7Imm16@16, Ax@8
4200h TL and MemR7Imm7s@0, Ax@8
8280h TL and MemRn@0, Ax@8 || Rn@0stepZIDS@3
82A0h TL and RegisterP0@0, Ax@8
6770h TL2 and Ab@2, Ab@0, Ax@12 ;TL2 only
D389h TL2 and r6, Ax@4
4B80h TL banke BankFlags6@0 ;{r0}{,r1}{,r4}{,cfgi}{,r7}{,cfgj}
8CDFh TL2 bankr ;without operand ?
8CDCh TL2 bankr Ar@0
8CD0h TL2 bankr Ar@2, Arp@0
8CD8h TL2 bankr Arp@0
5EB8h TL2 bitrev Rn@0
D7E8h TL2 bitrev Rn@0, dbrv
D7E0h TL2 bitrev Rn@0, ebrv
5C00h TL bkrep NoReverse, Imm8u@0, Address16@16
5D00h TL bkrep NoReverse, Register@0, Address18@16and5
8FDCh TL2 bkrep NoReverse, r6, Address18@16and0
DA9Ch TL2 bkreprst MemR0425@0
5F48h TL2 bkreprst MemSp, Unused2@0
DADCh TL2 bkrepsto MemR0425@0, Unused1@10
9468h TL2 bkrepsto MemSp, Unused3@0
4180h TL br Address18@16and4, Cond@0
D3C0h TL break ;break
5000h TL brr RelAddr7@4, Cond@0
41C0h TL call Address18@16and4, Cond@0
D480h TL calla Axl@8
D381h TL2 calla Ax@4
1000h TL callr RelAddr7@4, Cond@0
9068h TL2 cbs Axh@0, Axh@not0, r0, ge
9168h TL2 cbs Axh@0, Axh@not0, r0, gt
D49Eh TL2 cbs Axh@8, Bxh@5, r0, ge
D49Fh TL2 cbs Axh@8, Bxh@5, r0, gt
D5C0h TL2 cbs MemR01@2, MemR45@2, ge || R01@2stepII2@0, R45@2stepII2@1
D5C8h TL2 cbs MemR01@2, MemR45@2, gt || R01@2stepII2@0, R45@2stepII2@1
E500h TL chng Imm16@16, MemImm8@0
84E0h TL chng Imm16@16, MemRn@0 || Rn@0stepZIDS@3
85E0h TL chng Imm16@16, Register@0
47BAh TL2 chng Imm16@16, r6
0038h TL2 chng Imm16@16, SttMod@0
6760h TL clr Implied ConstZero, Ax@12, Cond@0 ;aX=0
6F60h TL clr Implied ConstZero, Bx@12, Cond@0 ;bX=0
8ED0h TL2 clr Implied ConstZero, Ab@2, Ab@0
5DFEh TL2 clrp p0
5DFFh TL2 clrp p0, p1
5DFDh TL2 clrp p1
67C0h TL clrr Implied Const8000h, Ax@12, Cond@0 ;aX=8000h
6F70h TL2 clrr Implied Const8000h, Bx@12, Cond@0 ;bX=8000h
8DD0h TL2 clrr Implied Const8000h, Ab@2, Ab@0
D4FEh TL cmp MemImm16@16, Ax@8
AC00h TL cmp MemImm8@0, Ax@8
8CC0h TL cmp Imm16@16, Ax@8
CC00h TL cmp Imm8u@0, Ax@8
D4DEh TL cmp MemR7Imm16@16, Ax@8
4C00h TL cmp MemR7Imm7s@0, Ax@8
8C80h TL cmp MemRn@0, Ax@8 || Rn@0stepZIDS@3
8CA0h TL cmp RegisterP0@0, Ax@8
4D8Ch TL2 cmp Ax@1, Bx@0
D483h TL2 cmp b0, b1
D583h TL2 cmp b1, b0
DA9Ah TL2 cmp Bx@10, Ax@0
8B63h TL2 cmp p1, Ax@4
D38Eh TL2 cmp r6, Ax@4
BE00h TL cmpu MemImm8@0, Ax@8
9E80h TL cmpu MemRn@0, Ax@8 || Rn@0stepZIDS@3
9EA0h TL cmpu Register@0, Ax@8
8A63h TL2 cmpu r6, Ax@3
ED00h TL cmpv Imm16@16, MemImm8@0
8CE0h TL cmpv Imm16@16, MemRn@0 || Rn@0stepZIDS@3
8DE0h TL cmpv Imm16@16, Register@0
47BEh TL2 cmpv Imm16@16, r6
D390h TL cntx r ;restore shadows
D380h TL cntx s ;store shadows
67F0h TL copy Implied Ax@not12, Ax@12, Cond@0 ;aX=aY
67E0h TL dec Implied Const1, Ax@12, Cond@0 ;aX=aX-1
43C0h TL dint ;IE=0, interrupt disable
0E00h TL divs MemImm8@0, Ax@8
4380h TL eint ;IE=1, interrupt enable
9460h TL exp Bx@0, Implied sv
9060h TL exp Bx@0, Implied sv, Ax@8
9C40h TL exp MemRn@0, Implied sv || Rn@0stepZIDS@3
9840h TL exp MemRn@0, Implied sv, Ax@8 || Rn@0stepZIDS@3
9040h TL exp RegisterP0@0, Implied sv, Ax@8
9440h TL exp RegisterP0@0, Implied sv
D7C1h TL2 exp r6, Implied sv
D382h TL2 exp r6, Implied sv, Ax@4
67D0h TL inc Implied Const1, Ax@12, Cond@0 ;aX=aX+1
49C0h TL lim a0 ;aka a0,a0
49D0h TL lim a0, a1
49F0h TL lim a1 ;aka a1,a1
49E0h TL lim a1, a0
4D80h TL load Imm2u@0, ps ;st1.bit11-10=imm2
DB80h TL load Imm7s@0, stepi ;cfgi.LSB=imm7
DF80h TL load Imm7s@0, stepj ;cfgj.LSB=imm7
0400h TL load Imm8u@0, page ;st1.LSBs=imm8 ;aka "lpg"
0200h TL load Imm9u@0, modi ;cfgi.MSB=imm9
0A00h TL load Imm9u@0, modj ;cfgj.MSB=imm9
D7D8h TL2 load Imm2u@1, movpd, Unused1@0 ;stt2.bit6.7 (page for ProgMem)
0010h TL2 load Imm4u@0, ps01 ;mod0.bit10-11,13-14 and st1.10-11 ?
D400h TL maa MemR45@2, MemR0123@0, Ax@11
|| R0123@0stepZIDS@3, R45@2stepZIDS@5
8400h TL maa MemRn@0, Imm16@16, Ax@11 || Rn@0stepZIDS@3
8420h TL maa y0, MemRn@0, Ax@11 || Rn@0stepZIDS@3
8440h TL maa y0, Register@0, Ax@11
E400h TL maa y0, MemImm8@0, Ax@11
5EA8h TL2 maa y0, r6, Ax@0
D700h TL maasu MemR45@2, MemR0123@0, Ax@11
|| R0123@0stepZIDS@3, R45@2stepZIDS@5
8700h TL maasu MemRn@0, Imm16@16, Ax@11 || Rn@0stepZIDS@3
8720h TL maasu y0, MemRn@0, Ax@11 || Rn@0stepZIDS@3
8740h TL maasu y0, Register@0, Ax@11
5EAEh TL2 maasu y0, r6, Ax@0
D200h TL mac MemR45@2, MemR0123@0, Ax@11
|| R0123@0stepZIDS@3, R45@2stepZIDS@5
8200h TL mac MemRn@0, Imm16@16, Ax@11 || Rn@0stepZIDS@3
8220h TL mac y0, MemRn@0, Ax@11 || Rn@0stepZIDS@3
8240h TL mac y0, Register@0, Ax@11
E200h TL mac y0, MemImm8@0, Ax@11
5EA4h TL2 mac y0, r6, Ax@0
4D84h TL2 mac y0, x1, Ax@1, Unused1@0
5E28h TL2 mac1 MemR45@2, MemR01@2, Ax@8 || R01@2stepII2@0, R45@2stepII2@1
D600h TL macsu MemR45@2, MemR0123@0, Ax@11
|| R0123@0stepZIDS@3, R45@2stepZIDS@5
8600h TL macsu MemRn@0, Imm16@16, Ax@11 || Rn@0stepZIDS@3
E600h TL macsu y0, MemImm8@0, Ax@11
8620h TL macsu y0, MemRn@0, Ax@11 || Rn@0stepZIDS@3
8640h TL macsu y0, Register@0, Ax@11
5EACh TL2 macsu y0, r6, Ax@0
D300h TL macus MemR45@2, MemR0123@0, Ax@11
|| R0123@0stepZIDS@3, R45@2stepZIDS@5
8300h TL macus MemRn@0, Imm16@16, Ax@11 || Rn@0stepZIDS@3
8320h TL macus y0, MemRn@0, Ax@11 || Rn@0stepZIDS@3
8340h TL macus y0, Register@0, Ax@11
5EA6h TL2 macus y0, r6, Ax@0
D500h TL macuu MemR45@2, MemR0123@0, Ax@11
|| R0123@0stepZIDS@3, R45@2stepZIDS@5
8500h TL macuu MemRn@0, Imm16@16, Ax@11 || Rn@0stepZIDS@3
8520h TL macuu y0, MemRn@0, Ax@11 || Rn@0stepZIDS@3
8540h TL macuu y0, Register@0, Ax@11
5EAAh TL2 macuu y0, r6, Ax@0
8460h TL max NoReverse, Ax@8, Implied Ax@not8, Bogus MemR0, ge,
Implied mixp, Implied r0 || R0stepZIDS@3 ;when aY >= aX
8660h TL max NoReverse, Ax@8, Implied Ax@not8, Bogus MemR0, gt,
Implied mixp, Implied r0 || R0stepZIDS@3 ;when aY > aX
5E21h TL2 max a0h, a1h || max a0l, a1l || vtrshr
5F21h TL2 max a1h, a0h || max a1l, a0l || vtrshr
D784h TL2 max Axh@1, Bxh@0 || max Axl@1, Bxl@0 || vtrshr
4A40h TL2 max Axh@3, Bxh@4 || max Axl@3, Bxl@4 || mov Axl@not3, MemR04@1
|| vtrshr || R04@1stepII2@0
4A44h TL2 max Axh@3, Bxh@4 || max Axl@3, Bxl@4 || mov Axh@not3, MemR04@1
|| vtrshr || R04@1stepII2@0
45A0h TL2 max Axh@4, Bxh@3 || max Axl@4, Bxl@3 || mov Axh@not4, MemR45@2
|| mov Axl@not4, MemR01@2 || vtrshr
|| R01@2stepII2@0, R45@2stepII2@1
D590h TL2 max Axh@6, Bxh@5 || max Axl@6, Bxl@5 || mov Axh@not6, MemR01@2
|| mov Axl@not6, MemR45@2 || vtrshr
|| R01@2stepII2@0, R45@2stepII2@1
4A60h TL2 max Bxh@4, Axh@3 || max Bxl@4, Axl@3 || mov Bxl@not4, MemR04@1
|| vtrshr || R04@1stepII2@0
4A64h TL2 max Bxh@4, Axh@3 || max Bxl@4, Axl@3 || mov Bxh@not4, MemR04@1
|| vtrshr || R04@1stepII2@0
8060h TL maxd NoReverse, Ax@8, MemR0, ge, Implied mixp, Implied r0
|| R0stepZIDS@3 ;when (r0) >= aX
8260h TL maxd NoReverse, Ax@8, MemR0, gt, Implied mixp, Implied r0
|| R0stepZIDS@3 ;when (r0) > aX
8860h TL min NoReverse, Ax@8, Implied Ax@not8, Bogus MemR0, le,
Implied mixp, Implied r0 || R0stepZIDS@3 ;when aY <= aX
8A60h TL min NoReverse, Ax@8, Implied Ax@not8, Bogus MemR0, lt,
Implied mixp, Implied r0 || R0stepZIDS@3 ;when aY < aX
43C2h TL2 min Axh@0, Axh@not0 || min Axl@0, Axl@not0 || vtrshr
D2B8h TL2 min Axh@11, Bxh@10 || min Axl@11, Bxl@10
|| mov Axh@not11, MemR01@2 || mov Axl@not11, MemR45@2
|| vtrshr || R01@2stepII2@0, R45@2stepII2@1
4A00h TL2 min Axh@3, Bxh@4 || min Axl@3, Bxl@4 || mov Axl@not3, MemR04@1
|| vtrshr || R04@1stepII2@0
4A04h TL2 min Axh@3, Bxh@4 || min Axl@3, Bxl@4 || mov Axh@not3, MemR04@1
|| vtrshr || R04@1stepII2@0
45E0h TL2 min Axh@4, Bxh@3 || min Axl@4, Bxl@3 || mov Axh@not4, MemR45@2
|| mov Axl@not4, MemR01@2 || vtrshr
|| R01@2stepII2@0, R45@2stepII2@1
D4BAh TL2 min Axh@8, Bxh@0 || min Axl@8, Bxl@0 || vtrshr
4A20h TL2 min Bxh@4, Axh@3 || min Bxl@4, Axl@3 || mov Bxl@not4, MemR04@1
|| vtrshr || R04@1stepII2@0
4A24h TL2 min Bxh@4, Axh@3 || min Bxl@4, Axl@3 || mov Bxh@not4, MemR04@1
|| vtrshr || R04@1stepII2@0
47A0h TL2 mind NoReverse, Ax@3, MemR0, le, Implied mixp, Implied r0
|| R0stepZIDS@0
47A4h TL2 mind NoReverse, Ax@3, MemR0, lt, Implied mixp, Implied r0
|| R0stepZIDS@0
0080h TL modr MemRn@0stepZIDS@3
00A0h TL modr MemRn@0stepZIDS@3, dmod ;Disable modulo
D294h TL2 modr MemR0123@10stepII2D2S0@0 || modr MemR4567@10stepII2D2S0@5
0D80h TL2 modr MemR0123@5stepII2D2S0@1 || modr MemR4567@5stepII2D2S0@3, dmod
0D81h TL2 modr MemR0123@5stepII2D2S0@1, dmod
|| modr MemR4567@5stepII2D2S0@3, dmod
8464h TL2 modr MemR0123@8stepII2D2S0@0, dmod || modr MemR4567@8stepII2D2S0@3
5DA0h TL2 modr MemRn@0stepD2
5DA8h TL2 modr MemRn@0stepD2, dmod
4990h TL2 modr MemRn@0stepI2
4998h TL2 modr MemRn@0stepI2, dmod
D290h TL mov Ab@10, Ab@5
D298h TL mov Abl@10, dvm
D2D8h TL mov Abl@10, x0
3000h TL mov Ablh@9, MemImm8@0
D4BCh TL mov Axl@8, MemImm16@16
D49Ch TL mov Axl@8, MemR7Imm16@16
DC80h TL mov Axl@8, MemR7Imm7s@0
D4B8h TL mov MemImm16@16, Ax@8
6100h TL mov MemImm8@0, Ab@11
6200h TL mov MemImm8@0, Ablh@10
6500h TL mov MemImm8@0, Axh@12, eu ;aka Axheu
6000h TL mov MemImm8@0, R0123457y0@10
6D00h TL mov MemImm8@0, sv
D491h TL mov dvm, Ab@5
D492h TL mov icr, Ab@5
5E20h TL mov Imm16@16, Bx@8
5E00h TL mov Imm16@16, Register@0
4F80h TL mov Imm5u@0, icr ;uh, but icr is 8bit wide (only 4bit are R/W)?
2500h TL mov Imm8s@0, Axh@12 ;signed!
2900h TL mov Imm8s@0, ext0
2D00h TL mov Imm8s@0, ext1
3900h TL mov Imm8s@0, ext2
3D00h TL mov Imm8s@0, ext3
2300h TL mov Imm8s@0, R0123457y0@10 ;signed!
0500h TL mov Imm8s@0, sv
2100h TL mov Imm8u@0, Axl@12 ;unsigned!
D498h TL mov MemR7Imm16@16, Ax@8
D880h TL mov MemR7Imm7s@0, Ax@8
98C0h TL mov MemRn@0, Bx@8 || Rn@0stepZIDS@3
1C00h TL mov MemRn@0, Register@5 || Rn@0stepZIDS@3
47E0h TL mov MemSp, Register@0
47C0h TL mov mixp, Register@0
2000h TL mov R0123457y0@9, MemImm8@0
4FC0h TL mov Register@0, icr
5E80h TL mov Register@0, mixp
1800h TL mov Register@5, MemRn@0 || Rn@0stepZIDS@3
5EC0h TL mov RegisterP0@0, Bx@5
5800h TL mov RegisterP0@0, Register@5
D490h TL mov repc, Ab@5
7D00h TL mov sv, MemImm8@0
D493h TL mov x0, Ab@5
D49Bh TL2 mov a0h, stepi0
D59Bh TL2 mov a0h, stepj0
4390h TL2 mov a0h, MemR0425@2 || mov y0, MemR0425@2offsZIDZ@0
|| R0425@2stepII2D2S@0
43D0h TL2 mov a1h, MemR0425@2 || mov y0, MemR0425@2offsZIDZ@0
|| R0425@2stepII2D2S@0
8FD4h TL2 mov Ab@0, p0
43A0h TL2 mov Abh@3, MemR01@2 || mov Abl@3, MemR45@2
|| R01@2stepII2@0, R45@2stepII2@1
43E0h TL2 mov Abh@3, MemR45@2 || mov Abl@3, MemR01@2
|| R01@2stepII2@0, R45@2stepII2@1
9D40h TL2 mov Abh@4, MemR04@1 || mov Abh@2, MemR04@1offsZI@0
|| R04@1stepII2@0
9164h TL2 mov Abl@0, prpage
9064h TL2 mov Abl@0, repc
D394h TL2 mov Abl@0, x1
D384h TL2 mov Abl@0, y1
9540h TL2 mov Abl@3, ArArp@0
9C60h TL2 mov Abl@3, SttMod@0
9560h TL2 mov ArArp@0, Abl@3
D488h TL2 mov ArArp@0, MemR04@8 || R04@8stepII2@5
5F50h TL2 mov ArArpSttMod@0, MemR7Imm16@16
886Bh TL2 mov Ax@8, pc
8C60h TL2 mov Axh@4, MemR4567@8 || mov MemR0123@8, Axh@4
|| R0123@8stepII2D2S@0, R4567@8stepII2D2S@2
4800h TL2 mov Axh@6, MemR0123@4 || movr MemR4567@4, Axh@6
|| R0123@4stepII2D2S@0, R4567@4stepII2D2S@2
4900h TL2 mov Axh@6, MemR0123@4 || mov MemR4567@4, Axh@6
|| R0123@4stepII2D2S@0, R4567@4stepII2D2S@2
7F80h TL2 mov Axh@6, MemR4567@4 || movr MemR0123@4, Axh@6
|| R0123@4stepII2D2S@0, R4567@4stepII2D2S@2
8863h TL2 mov Bx@8, pc
0008h TL2 mov Imm16@16, ArArp@0
0023h TL2 mov Imm16@16, r6
0001h TL2 mov Imm16@16, repc
8971h TL2 mov Imm16@16, stepi0
8979h TL2 mov Imm16@16, stepj0
0030h TL2 mov Imm16@16, SttMod@0
5DD0h TL2 mov Imm4u@0, prpage
80C4h TL2 mov MemR01@9, Abh@10 || mov MemR45@9, Abl@10
|| R01@9stepII2@0, R45@9stepII2@8
D292h TL2 mov MemR0425@10_MemR0425@10offsZIDZ@5, Px@0
|| R0425@10stepII2D2S@5
D7D4h TL2 mov MemR04@1, repc || R04@1stepII2@0
5F4Ch TL2 mov MemR04@1, sv || sub3 MemR04@1, p0, p1, b0 || R04@1stepII2@0
D4B4h TL2 mov MemR04@1, sv || sub3rnd MemR04@1, p0, p1, b1 || R04@1stepII2@0
DE9Ch TL2 mov MemR04@1, sv || sub3rnd MemR04@1, p0, p1, b0 || R04@1stepII2@0
4B40h TL2 mov MemR04@3, sv || addsub MemR04@3, p1, p0, Bx@0
|| R04@3stepII2@2
4B42h TL2 mov MemR04@3, sv || addsubrnd MemR04@3, p1, p0, Bx@0
|| R04@3stepII2@2
8062h TL2 mov MemR04@4, ArArp@8 || R04@4stepII2@3
8063h TL2 mov MemR04@4, SttMod@8 || R04@4stepII2@3
9960h TL2 mov MemR04@4, sv || addsub MemR04@4, p1, p0, Bx@2
|| R04@4stepD2S@3 ;<-- ordered p1, p0 here !
99E0h TL2 mov MemR04@4, sv || addsubrnd MemR04@4, p1, p0, Bx@2
|| R04@4stepD2S@3 ;<-- ordered p1, p0 here !
9860h TL2 mov MemR04@4, sv || sub3 MemR04@4, p0, p1, Bx@2
|| R04@4stepD2S@3
98E0h TL2 mov MemR04@4, sv || sub3rnd MemR04@4, p0, p1, Bx@2
|| R04@4stepD2S@3
8873h TL2 mov MemR04@8, sv || sub3 MemR04@8, p0, p1, b1 || R04@8stepII2@3
D4C0h TL2 mov MemR45@5, Abh@2 || mov MemR01@5, Abl@2
|| R01@5stepII2@0, R45@5stepII2@1
4D90h TL2 mov MemR7Imm16@16, ArArpSttMod@0
D2DCh TL2 mov MemR7Imm16@16, repc, Unused2@0, Unused1@10
1B20h TL2 mov MemRn@0, r6 || Rn@0stepZIDS@3 ;override 1800h (mov a1,MemRn@0)
D29Ch TL2 mov MemSp, r6, Unused2@0, Unused1@10
8A73h TL2 mov mixp, Bx@3
4381h TL2 mov mixp, r6
4382h TL2 mov p0h, Bx@0
D3C2h TL2 mov p0h, r6
4B60h TL2 mov p0h, Register@0 ;<-- here "p0h" as source
8FD8h TL2 mov p1, Ab@0
88D0h TL2 mov Px@1, MemR0425@8_MemR0425@8offsZIDZ@2 || R0425@8stepII2D2S@2
88D1h TL2 mov Px@1, MemR0425@8_MemR0425@8offsZIDZ@2,s || R0425@8stepII2D2S@2
D481h TL2 mov r6, Bx@8
1B00h TL2 mov r6, MemRn@0 || Rn@0stepZIDS@3 ;override 1800h (mov a0,MemRn@0)
43C1h TL2 mov r6, mixp
5F00h TL2 mov r6, Register@0
5F60h TL2 mov Register@0, r6
D2D9h TL2 mov repc, Abl@10
D7D0h TL2 mov repc, MemR04@1 || R04@1stepII2@0
D3C8h TL2 mov repc, MemR7Imm16@16, Unused3@0
D482h TL2 mov stepi0, a0h
D582h TL2 mov stepj0, a0h
D2F8h TL2 mov SttMod@0, Abl@10
49C1h TL2 mov x1, Ab@4
D299h TL2 mov y1, Ab@10
5EB0h TL2 mov prpage, Abl@0
49A0h TL2 mov SttMod@0, MemR04@4 || R04@4stepII2@3
4DC0h TL2 mova Ab@4, MemR0425@2_MemR0425@2offsZIDZ@0 || R0425@2stepII2D2S@0
4BC0h TL2 mova MemR0425@2_MemR0425@2offsZIDZ@0, Ab@4 || R0425@2stepII2D2S@0
5F80h TL movd MemR0123@0,ProgMemR45@2 || R0123@0stepZIDS@3, R45@2stepZIDS@5
0040h TL movp ProgMemAxl@5, Register@0
0D40h TL2 movp ProgMemAx@5, Register@0
0600h TL movp ProgMemRn@0, MemR0123@5 || R0123@5stepZIDS@7, Rn@0stepZIDS@3
D499h TL2 movpdw ProgMemAx@8_ProgMemAx@8offsI, pc
8864h TL movr MemR0425@3, Abh@8 || R0425@3stepII2D2S@0 ;op*10000h+8000h
9CE0h TL movr MemRn@0, Ax@8 || Rn@0stepZIDS@3
9CC0h TL movr RegisterP0@0, Ax@8
5DF4h TL2 movr Bx@1, Ax@0
8961h TL2 movr r6, Ax@3
6300h TL movs Implied sv, MemImm8@0, Ab@11
0180h TL movs Implied sv, MemRn@0, Ab@5 || Rn@0stepZIDS@3
0100h TL movs Implied sv, RegisterP0@0, Ab@5
5F42h TL2 movs Implied sv, r6, Ax@0
4080h TL movsi Implied Imm5s@0, R0123457y0@9, Ab@5, Bogus Imm5s@0
D000h TL mpy MemR45@2, MemR0123@0 || R0123@0stepZIDS@3, R45@2stepZIDS@5
8000h TL mpy MemRn@0, Imm16@16 || Rn@0stepZIDS@3
8020h TL mpy y0, MemRn@0 || Rn@0stepZIDS@3
8040h TL mpy y0, Register@0
E000h TL mpy y0, MemImm8@0
5EA0h TL2 mpy y0, r6
CB00h TL2 mpy MemR45@5, MemR01@5 || mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3 p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB01h TL2 mpy MemR45@5, MemR01@5 || mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3 p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB02h TL2 mpy MemR45@5, MemR01@5 || mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB03h TL2 mpy MemR45@5, MemR01@5 || mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB04h TL2 mpy MemR45@5, MemR01@5 || mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3 p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB05h TL2 mpy MemR45@5, MemR01@5 || mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3 p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB06h TL2 mpy MemR45@5, MemR01@5 || mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CB07h TL2 mpy MemR45@5, MemR01@5 || mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
D5E0h TL2 mpy MemR04@1, x1 || mpy y1, x0 || sub3 p0, p1, Ax@3
|| R04@1stepII2@0
D5E4h TL2 mpy MemR04@1, x1 || mpy y1, x0 || add3 p0, p1, Ax@3
|| R04@1stepII2@0
C800h TL2 mpy MemR4567@4, MemR0123@4
|| mpy MemR4567@4offsZIDZ@2, MemR0123@4offsZIDZ@0
|| add3 p0, p1, Ab@6 || R0123@4stepII2D2S@0, R4567@4stepII2D2S@2
C900h TL2 mpy MemR4567@4, MemR0123@4
|| mpy MemR4567@4offsZIDZ@2, MemR0123@4offsZIDZ@0
|| sub3 p0, p1, Ab@6 || R0123@4stepII2D2S@0, R4567@4stepII2D2S@2
80C2h TL2 mpy MemR45@0, MemR01@0 || mpy MemR45@0offsZI@9, MemR01@0offsZI@8
|| add3a p0, p1, Ab@10 || R01@0stepII2@8, R45@0stepII2@9
49C8h TL2 mpy MemR45@2, MemR01@2 || mpy MemR45@2offsZI@1, MemR01@2offsZI@0
|| sub3a p0, p1, Ab@4 || R01@2stepII2@0, R45@2stepII2@1
80C8h TL2 mpy MemR45@2, MemR01@2 || mpy MemR45@2offsZI@1, MemR01@2offsZI@0
|| addsub p0, p1, Ab@10 || R01@2stepII2@0, R45@2stepII2@1
81C8h TL2 mpy MemR45@2, MemR01@2 || mpy MemR45@2offsZI@1, MemR01@2offsZI@0
|| addsuba p0, p1, Ab@10 || R01@2stepII2@0, R45@2stepII2@1
82C8h TL2 mpy MemR45@2, MemR01@2 || mpy MemR45@2offsZI@1, MemR01@2offsZI@0
|| add p0, p1, Ab@10 || R01@2stepII2@0, R45@2stepII2@1
83C8h TL2 mpy MemR45@2, MemR01@2 || mpy MemR45@2offsZI@1, MemR01@2offsZI@0
|| adda p0, p1, Ab@10 || R01@2stepII2@0, R45@2stepII2@1
00C0h TL2 mpy MemR45@3, MemR01@3 || mpy MemR45@3offsZI@2, MemR01@3offsZI@1
|| sub p0, p1, Ab@4 || R01@3stepII2@1, R45@3stepII2@2
00C1h TL2 mpy MemR45@3, MemR01@3 || mpy MemR45@3offsZI@2, MemR01@3offsZI@1
|| suba p0, p1, Ab@4 || R01@3stepII2@1, R45@3stepII2@2
0D20h TL2 mpy MemR45@3, MemR01@3 || mpyus MemR45@3offsZI@2, MemR01@3offsZI@1
|| add3a p0, p1, Ax@0, dmodi || R01@3stepII2@1, R45@3stepII2@2
0D30h TL2 mpy MemR45@3, MemR01@3 || mpyus MemR45@3offsZI@2, MemR01@3offsZI@1
|| add3a p0, p1, Ax@0, dmodj || R01@3stepII2@1, R45@3stepII2@2
4B50h TL2 mpy MemR45@3, MemR01@3 || mpyus MemR45@3offsZI@2, MemR01@3offsZI@1
|| add3a p0, p1, Ax@0, dmodij || R01@3stepII2@1, R45@3stepII2@2
D7A0h TL2 mpy MemR45@3, MemR01@3 || mpy MemR45@3offsZI@2, MemR01@3offsZI@1
|| add3 sv, p0, p1, Ax@4 || R01@3stepII2@1, R45@3stepII2@2
D7A1h TL2 mpy MemR45@3, MemR01@3 || mpy MemR45@3offsZI@2, MemR01@3offsZI@1
|| add3rnd sv, p0, p1, Ax@4 || R01@3stepII2@1, R45@3stepII2@2
9861h TL2 mpy MemR45@4, MemR01@4 || mpy MemR45@4offsZI@3, MemR01@4offsZI@2
|| add3 p0, p1, Ax@8, dmodj || R01@4stepII2@2, R45@4stepII2@3
9862h TL2 mpy MemR45@4, MemR01@4 || mpy MemR45@4offsZI@3, MemR01@4offsZI@2
|| add3 p0, p1, Ax@8, dmodi || R01@4stepII2@2, R45@4stepII2@3
9863h TL2 mpy MemR45@4, MemR01@4 || mpy MemR45@4offsZI@3, MemR01@4offsZI@2
|| add3 p0, p1, Ax@8, dmodij || R01@4stepII2@2, R45@4stepII2@3
98E1h TL2 mpy MemR45@4, MemR01@4 || mpy MemR45@4offsZI@3, MemR01@4offsZI@2
|| add3a p0, p1, Ax@8, dmodj || R01@4stepII2@2, R45@4stepII2@3
98E2h TL2 mpy MemR45@4, MemR01@4 || mpy MemR45@4offsZI@3, MemR01@4offsZI@2
|| add3a p0, p1, Ax@8, dmodi || R01@4stepII2@2, R45@4stepII2@3
98E3h TL2 mpy MemR45@4, MemR01@4 || mpy MemR45@4offsZI@3, MemR01@4offsZI@2
|| add3a p0, p1, Ax@8, dmodij || R01@4stepII2@2, R45@4stepII2@3
4DA0h TL2 mpy y0, MemR04@3 || mpyus y1, MemR04@3offsZI@2
|| sub3 p0, p1, Ax@4 || R04@3stepII2@2
4DA1h TL2 mpy y0, MemR04@3 || mpyus y1, MemR04@3offsZI@2
|| sub3a p0, p1, Ax@4 || R04@3stepII2@2
4DA2h TL2 mpy y0, MemR04@3 || mpyus y1, MemR04@3offsZI@2
|| add3 p0, p1, Ax@4 || R04@3stepII2@2
4DA3h TL2 mpy y0, MemR04@3 || mpyus y1, MemR04@3offsZI@2
|| add3a p0, p1, Ax@4 || R04@3stepII2@2
94E0h TL2 mpy y0, MemR04@4 || mpy y1, MemR04@4offsZI@3
|| sub3 p0, p1, Ax@8 || R04@4stepII2@3
94E2h TL2 mpy y0, MemR04@4 || mpy y1, MemR04@4offsZI@3
|| sub3a p0, p1, Ax@8 || R04@4stepII2@3
94E4h TL2 mpy y0, MemR04@4 || mpy y1, MemR04@4offsZI@3
|| add3 p0, p1, Ax@8 || R04@4stepII2@3
94E6h TL2 mpy y0, MemR04@4 || mpy y1, MemR04@4offsZI@3
|| add3a p0, p1, Ax@8 || R04@4stepII2@3
94E1h TL2 mpy y0, MemR04@4 || mpysu y1, MemR04@4offsZI@3
|| sub3 p0, p1, Ax@8 || R04@4stepII2@3
94E3h TL2 mpy y0, MemR04@4 || mpysu y1, MemR04@4offsZI@3
|| sub3a p0, p1, Ax@8 || R04@4stepII2@3
94E5h TL2 mpy y0, MemR04@4 || mpysu y1, MemR04@4offsZI@3
|| add3 p0, p1, Ax@8 || R04@4stepII2@3
94E7h TL2 mpy y0, MemR04@4 || mpysu y1, MemR04@4offsZI@3
|| add3a p0, p1, Ax@8 || R04@4stepII2@3
8862h TL2 mpy y0, x1 || mpy MemR04@4, x0 || sub3 p0, p1, Ax@8
|| R04@4stepII2@3
8A62h TL2 mpy y0, x1 || mpy MemR04@4, x0 || add3 p0, p1, Ax@8
|| R04@4stepII2@3
4D88h TL2 mpy y0, x1 || mpy y1, x0 || sub p0, p1, Ax@1
5E24h TL2 mpy y0, x1 || mpy y1, x0 || add p0, p1, Ab@0
8061h TL2 mpy y0, x1 || mpy y1, x0 || add3 p0, p1, Ab@8
8071h TL2 mpy y0, x1 || mpy y1, x0 || add3a p0, p1, Ab@8
8461h TL2 mpy y0, x1 || mpy y1, x0 || sub3 p0, p1, Ab@8
8471h TL2 mpy y0, x1 || mpy y1, x0 || sub3a p0, p1, Ab@8
D484h TL2 mpy y0, x1 || mpy y1, x0 || add3aa p0, p1, Ab@0
D49Dh TL2 mpy y0, x1 || mpy y1, x0 || sub p0, p1, Bx@5
D4A0h TL2 mpy y0, x1 || mpy y1, x0 || addsub p0, p1, Ab@0
4FA0h TL2 mpy y0, x1 || mpy y1, x0 || add3 p0, p1, Ab@3
|| mov Axh@6, MemR04@1 || mov Bxh@2, MemR04@1offsZI@0
|| R04@1stepII2@0
5818h TL2 mpy y0, x1 || mpy y1, x0 || addsub sv, p0, p1, Ax@0
|| mov Axh@0, MemR0425@7 || mov Axh@not0, MemR0425@7offsZI@6
|| R0425@7stepII2@6 ;override 5800h+18h (mov a0, Register)
5838h TL2 mpy y0, x1 || mpy y1, x0 || addsubrnd sv, p0, p1, Ax@0
|| mov Axh@0, MemR0425@7 || mov Axh@not0, MemR0425@7offsZI@6
|| R0425@7stepII2@6 ;override 5800h+38h (mov a1, Register)
80D0h TL2 mpy y0, x1 || mpy y1, x0 || addsub sv, p0, p1, Ax@10
|| mov Axh@9, MemR04@3 || mov Bxh@8, MemR04@3offsZI@2
|| R04@3stepII2@2
80D1h TL2 mpy y0, x1 || mpy y1, x0 || addsubrnd sv, p0, p1, Ax@10
|| mov Axh@9, MemR04@3 || mov Bxh@8, MemR04@3offsZI@2
|| R04@3stepII2@2
80D2h TL2 mpy y0, x1 || mpy y1, x0 || add3 sv, p0, p1, Ax@10
|| mov Axh@9, MemR04@3 || mov Bxh@8, MemR04@3offsZI@2
|| R04@3stepII2@2
80D3h TL2 mpy y0, x1 || mpy y1, x0 || add3rnd sv, p0, p1, Ax@10
|| mov Axh@9, MemR04@3 || mov Bxh@8, MemR04@3offsZI@2
|| R04@3stepII2@2
D3A0h TL2 mpy y0, x1 || mpy y1, x0 || addsub p0, p1, Ab@3
|| mov Axh@6, MemR04@1 || mov Bxh@2, MemR04@1offsZI@0
|| R04@1stepII2@0
4D89h TL2 mpy y0, x1 || mpyus y1, x0 || sub p0, p1, Ax@1
5F24h TL2 mpy y0, x1 || mpyus y1, x0 || add p0, p1, Ab@0
8069h TL2 mpy y0, x1 || mpyus y1, x0 || add3 p0, p1, Ab@8
8079h TL2 mpy y0, x1 || mpyus y1, x0 || add3a p0, p1, Ab@8
8469h TL2 mpy y0, x1 || mpyus y1, x0 || sub3 p0, p1, Ab@8
8479h TL2 mpy y0, x1 || mpyus y1, x0 || sub3a p0, p1, Ab@8
D584h TL2 mpy y0, x1 || mpyus y1, x0 || add3aa p0, p1, Ab@0
D59Dh TL2 mpy y0, x1 || mpyus y1, x0 || sub p0, p1, Bx@5
D5A0h TL2 mpy y0, x1 || mpyus y1, x0 || addsub p0, p1, Ab@0
0800h TL mpyi NoReverse, Implied p0, y0, Imm8s@0 ;multiply ;aka "mpys"
D100h TL mpysu MemR45@2, MemR0123@0 || R0123@0stepZIDS@3, R45@2stepZIDS@5
8100h TL mpysu MemRn@0, Imm16@16 || Rn@0stepZIDS@3
8120h TL mpysu y0, MemRn@0 || Rn@0stepZIDS@3
8140h TL mpysu y0, Register@0
CA00h TL2 mpysu MemR45@5, MemR01@5
|| mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA01h TL2 mpysu MemR45@5, MemR01@5
|| mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA02h TL2 mpysu MemR45@5, MemR01@5
|| mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3aa p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA03h TL2 mpysu MemR45@5, MemR01@5
|| mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| sub3aa p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA04h TL2 mpysu MemR45@5, MemR01@5
|| mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA05h TL2 mpysu MemR45@5, MemR01@5
|| mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3a p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA06h TL2 mpysu MemR45@5, MemR01@5
|| mpysu MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3aa p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
CA07h TL2 mpysu MemR45@5, MemR01@5
|| mpyus MemR45@5offsZI@4, MemR01@5offsZI@3
|| add3aa p0, p1, Ab@6 || R01@5stepII2@3, R45@5stepII2@4
5EA2h TL2 mpysu y0, r6
D080h TL msu MemR45@2,MemR0123@0,Ax@8 || R0123@0stepZIDS@3, R45@2stepZIDS@5
90C0h TL msu MemRn@0, Imm16@16, Ax@8 || Rn@0stepZIDS@3 ;multiply, subtract
9080h TL msu y0, MemRn@0, Ax@8 || Rn@0stepZIDS@3
90A0h TL msu y0, Register@0, Ax@8
B000h TL msu y0,MemImm8@0, Ax@8
9462h TL2 msu y0, r6, Ax@0
8264h TL2 msusu y0, MemR0425@3, Ax@8 || R0425@3stepII2D2S@0
6790h TL neg Ax@12, Cond@0 ;aX=0-aX
0000h TL nop
94C0h TL norm Ax@8, Bogus MemRn@0 || Rn@0stepZIDS@3 ;if N=0 (aX=aX*2,rN+/-)
6780h TL not Ax@12, Cond@0 ;aX=not aX
D4F8h TL or MemImm16@16, Ax@8
A000h TL or MemImm8@0, Ax@8
80C0h TL or Imm16@16, Ax@8
C000h TL or Imm8u@0, Ax@8
D4D8h TL or MemR7Imm16@16, Ax@8
4000h TL or MemR7Imm7s@0, Ax@8
8080h TL or MemRn@0, Ax@8 || Rn@0stepZIDS@3
80A0h TL or RegisterP0@0, Ax@8
D291h TL2 or Ab@10, Ax@6, Ax@5
D4A4h TL2 or Ax@8, Bx@1, Ax@0
D3C4h TL2 or b0, Bx@1, Ax@0
D7C4h TL2 or b1, Bx@1, Ax@0
D388h TL2 or r6, Ax@4
67B0h TL pacr Implied Const8000h, Implied p0, Ax@12, Cond@0 ;aX=shfP+8000h
D7C2h TL2 pacr1 Implied Const8000h, Implied p1, Ax@0
5E60h TL pop Register@0
47B4h TL2 pop Abe@0
80C7h TL2 pop ArArpSttMod@8
0006h TL2 pop Bx@5, Unused1@0
D7F4h TL2 pop prpage, Unused2@0
D496h TL2 pop Px@0
0024h TL2 pop r6, Unused1@0
D7F0h TL2 pop repc, Unused2@0
D494h TL2 pop x0
D495h TL2 pop x1
0004h TL2 pop y1, Unused1@0
47B0h TL2 popa Ab@0
5F40h TL push Imm16@16
5E40h TL push Register@0
D7C8h TL2 push Abe@1, Unused1@0
D3D0h TL2 push ArArpSttMod@0
D7FCh TL2 push prpage, Unused2@0
D78Ch TL2 push Px@1, Unused1@0
D4D7h TL2 push r6, Unused1@5
D7F8h TL2 push repc, Unused2@0
D4D4h TL2 push x0, Unused1@5
D4D5h TL2 push x1, Unused1@5
D4D6h TL2 push y1, Unused1@5
4384h TL2 pusha Ax@6, Unused2@0
D788h TL2 pusha Bx@1, Unused1@0
0C00h TL rep Imm8u@0 ;repeat next opcode N+1 times
0D00h TL rep Register@0 ;repeat next opcode N+1 times
0002h TL2 rep r6, Unused1@0
4580h TL ret Cond@0 ;=pop pc
D780h TL retd ;delayed return (after 2 clks)
45C0h TL reti Cond@0 ;Don't context switch
45D0h TL reti Cond@0, context ;Do context switch
D7C0h TL retid ;delayed, from interrupt
D3C3h TL2 retid context
0900h TL rets Imm8u@0 ;ret+dealloc sp (for INCOMING pushed params)
67A0h TL rnd Implied Const8000h, Ax@12, Cond@0 ;aX=aX+8000h
6750h TL rol Implied Const1, Ax@12, Cond@0 ;aX=aX rcl 1 (37bit rotate)
6F50h TL rol Implied Const1, Bx@12, Cond@0 ;bX=bX rcl 1 (37bit rotate)
6740h TL ror Implied Const1, Ax@12, Cond@0 ;aX=aX rcr 1 (37bit rotate)
6F40h TL ror Implied Const1, Bx@12, Cond@0 ;bX=bX rcr 1 (37bit rotate)
E300h TL rst Imm16@16, MemImm8@0
82E0h TL rst Imm16@16, MemRn@0 || Rn@0stepZIDS@3
83E0h TL rst Imm16@16, Register@0
47B9h TL2 rst Imm16@16, r6
4388h TL2 rst Imm16@16, SttMod@0
E100h TL set Imm16@16, MemImm8@0
80E0h TL set Imm16@16, MemRn@0 || Rn@0stepZIDS@3
81E0h TL set Imm16@16, Register@0
47B8h TL2 set Imm16@16, r6
43C8h TL2 set Imm16@16, SttMod@0
D280h TL shfc Implied sv, Ab@10, Ab@5, Cond@0
9240h TL shfi Implied Imm6s@0, Ab@10, Ab@7, Bogus Imm6s@0
6720h TL shl Implied Const1, Ax@12, Cond@0 ;aX=aX*2
6F20h TL shl Implied Const1, Bx@12, Cond@0 ;bX=bX*2
6730h TL shl4 Implied Const4, Ax@12, Cond@0 ;aX=aX*10h
6F30h TL shl4 Implied Const4, Bx@12, Cond@0 ;bX=bX*10h
6700h TL shr Implied Const1, Ax@12, Cond@0 ;aX=aX/2
6F00h TL shr Implied Const1, Bx@12, Cond@0 ;bX=bX/2
6710h TL shr4 Implied Const4, Ax@12, Cond@0 ;aX=aX/10h
6F10h TL shr4 Implied Const4, Bx@12, Cond@0 ;bX=bX/10h
BA00h TL sqr MemImm8@0
9A80h TL sqr MemRn@0 || Rn@0stepZIDS@3
9AA0h TL sqr Register@0
D790h TL2 sqr Abh@2 || sqr Abl@2 || add3 p0, p1, Ab@0
49C4h TL2 sqr Abh@4 || mpysu Abh@4, Abl@4 || add3a p0, p1, Ab@0
4B00h TL2 sqr MemR0425@4 || sqr MemR0425@4offsZIDZ@2 || add3 p0, p1, Ab@0
|| R0425@4stepII2D2S@2
5F41h TL2 sqr r6
BC00h TL sqra MemImm8@0, Ax@8
9C80h TL sqra MemRn@0, Ax@8 || Rn@0stepZIDS@3
9CA0h TL sqra Register@0, Ax@8
9062h TL2 sqra r6, Ax@8, Unused1@0
D4FFh TL sub MemImm16@16, Ax@8
AE00h TL sub MemImm8@0, Ax@8
8EC0h TL sub Imm16@16, Ax@8
CE00h TL sub Imm8u@0, Ax@8
D4DFh TL sub MemR7Imm16@16, Ax@8
4E00h TL sub MemR7Imm7s@0, Ax@8
8E80h TL sub MemRn@0, Ax@8 || Rn@0stepZIDS@3
8EA0h TL sub RegisterP0@0, Ax@8
8A61h TL2 sub Ab@3, Bx@8
8861h TL2 sub Bx@4, Ax@3
8064h TL2 sub MemR01@8, sv, Abh@3 || add MemR01@8offsZI@0, sv, Abl@3
|| mov MemR45@8, sv || R01@8stepII2@0, R45@8stepII2@1
5DE0h TL2 sub MemR04@1, sv, Abh@2 || add MemR04@1offsZI@0, sv, Abl@2
|| R04@1stepII2@0
6FC0h TL2 sub MemR45@2, MemR01@2, Abh@3
|| add MemR45@2offsZI@1, MemR01@2offsZI@0, Abl@3
|| R01@2stepII2@0, R45@2stepII2@1
6FE0h TL2 sub MemR45@2, MemR01@2, Abh@3
|| sub MemR45@2offsZI@1, MemR01@2offsZI@0, Abl@3
|| R01@2stepII2@0, R45@2stepII2@1
5D80h TL2 sub MemR45@2, sv, Abh@3 || add MemR45@2offsZI@1, sv, Abl@3
|| mov MemR01@2, sv || R01@2stepII2@0, R45@2stepII2@1
5DC2h TL2 sub p0, p1, Ab@2
D4B9h TL2 sub p1, Ax@8
8FD0h TL2 sub Px@1, Bx@0
D38Fh TL2 sub r6, Ax@4
80C6h TL2 sub3 p0, p1, Ab@10
82C6h TL2 sub3a p0, p1, Ab@10
83C6h TL2 sub3aa p0, p1, Ab@10
5DC3h TL2 suba p0, p1, Ab@2
B600h TL subh MemImm8@0, Ax@8
9680h TL subh MemRn@0, Ax@8 || Rn@0stepZIDS@3
96A0h TL subh Register@0, Ax@8
5E23h TL2 subh r6, Ax@8
B800h TL subl MemImm8@0, Ax@8
9880h TL subl MemRn@0, Ax@8 || Rn@0stepZIDS@3
98A0h TL subl Register@0, Ax@8
5E22h TL2 subl r6, Ax@8
EF00h TL subv Imm16@16, MemImm8@0
8EE0h TL subv Imm16@16, MemRn@0 || Rn@0stepZIDS@3
8FE0h TL subv Imm16@16, Register@0
47BFh TL2 subv Imm16@16, r6
4980h TL swap SwapTypes4@0
0020h TL trap ;software interrupt
A800h TL tst0 Axl@8, MemImm8@0
8880h TL tst0 Axl@8, MemRn@0 || Rn@0stepZIDS@3
88A0h TL tst0 Axl@8, Register@0
E900h TL tst0 Imm16@16, MemImm8@0
88E0h TL tst0 Imm16@16, MemRn@0 || Rn@0stepZIDS@3
89E0h TL tst0 Imm16@16, Register@0
D38Ch TL2 tst0 Axl@4, r6
47BCh TL2 tst0 Imm16@16, r6
9470h TL2 tst0 Imm16@16, SttMod@0
AA00h TL tst1 Axl@8, MemImm8@0 Implied Not
8A80h TL tst1 Axl@8, MemRn@0 Implied Not || Rn@0stepZIDS@3
8AA0h TL tst1 Axl@8, Register@0 Implied Not
EB00h TL tst1 Imm16@16, MemImm8@0 Implied Not
8AE0h TL tst1 Imm16@16, MemRn@0 Implied Not || Rn@0stepZIDS@3
8BE0h TL tst1 Imm16@16, Register@0 Implied Not
D38Dh TL2 tst1 Axl@4, r6 Implied Not
47BDh TL2 tst1 Imm16@16, r6 Implied Not
9478h TL2 tst1 Imm16@16, SttMod@0 Implied Not
80C1h TL2 tst4b a0l, MemR0425@10 || R0425@10stepII2D2S@8
4780h TL2 tst4b a0l, MemR0425@2, Ax@4 || R0425@2stepII2D2S@0
F000h TL tstb NoReverse, Implied Not MemImm8@0, Imm4bitno@8
9020h TL tstb NoReverse, Implied Not MemRn@0, Imm4bitno@8 || Rn@0stepZIDS@3
9000h TL tstb NoReverse, Implied Not Register@0, Imm4bitno@8
9018h TL2 tstb NoReverse, Implied Not r6, Imm4bitno@8 ;override tstb a0,Imm4
0028h TL2 tstb NoReverse, Implied Not SttMod@0, Imm4bitno@16, Unused12@20
5F45h TL2 vtrclr vtr0 ;vtr0=0 ;for Viterbi decoding...
5F47h TL2 vtrclr vtr0, vtr1 ;vtr0=0, vtr1=0 ;(saved C/C1 carry flags)
5F46h TL2 vtrclr vtr1 ;vtr1=0
D383h TL2 vtrmov Axl@4 ;Axl=(vtr1 and FF00h)+(vtr0/100h)
D29Ah TL2 vtrmov vtr0, Axl@0 ;Axl=vtr0
D69Ah TL2 vtrmov vtr1, Axl@0 ;Axl=vtr1
D781h TL2 vtrshr ;vtr0=vtr0/2+C*8000h, vtr1=vtr1/2+C1*8000h
D4FAh TL xor MemImm16@16, Ax@8
A400h TL xor MemImm8@0, Ax@8
84C0h TL xor Imm16@16, Ax@8
C400h TL xor Imm8u@0, Ax@8
D4DAh TL xor MemR7Imm16@16, Ax@8
4400h TL xor MemR7Imm7s@0, Ax@8
8480h TL xor MemRn@0, Ax@8 || Rn@0stepZIDS@3
84A0h TL xor RegisterP0@0, Ax@8
D38Ah TL2 xor r6, Ax@4
8800h TL undefined Unused5@0, Unused1@8 ;(mpy/mpys without A in bit11)
8820h TL undefined Unused5@0, Unused1@8 ;(mpy/mpys without A in bit11)
8840h TL undefined Unused5@0, Unused1@8 ;(mpy/mpys without A in bit11)
D800h TL undefined Unused7@0, Unused1@8 ;(mpy/mpys without A in bit11)
9B80h TL undefined Unused6@0 ;(sqr without A in bit8)
BB00h TL undefined Unused8@0 ;(sqr without A in bit8)
E800h TL undefined Unused8@0 ;(mpy without A in bit11)
5EA1h TL2 undefined Unused1@1 ;(mpy/mpys without A in bit11)
5DFCh TL2 undefined
8CDEh TL2 undefined
D3C1h TL2 undefined
5EB4h TL2 undefined Unused2@0
|
| DSi TeakLite II Operand Encoding |
name native nocash MemRn (Rn) [Rn] MemSp (sp) [sp] ProgMemRn (Rn) [code:movpd:Rn] ProgMemAxl (Axl) [code:movpd:Axl] ProgMemAx (Ax) [code:Ax] ProgMemAx_.. (Ax),(Ax+) [code:Ax]:[code:Ax+] MemImm8 0xNN [page:NNh] MemImm16 [##0xNNNN] [NNNNh] MemR7Imm7s (r7+#0xNN), (r7+#-NNN) [r7+/-NNh] MemR7Imm16 (r7+##0xNNNN) [r7+NNNNh] |
Address18 0xNNNNN NNNNNh ;for bkrep/br/call Address16 0xNNNN NNNNh ;for bkrep RelAddr7 0xNNNN NNNNh ;for jmp ImmN: #0xNNNN NNNNh ImmNs: #0xNN, #-NNN +/-NNh Imm16: ##0xNNNN NNNNh Imm4bitno: ... 1 shl N ConstZero <implied> 0000h Const1 <implied> 0001h Const4 <implied> 0004h Const8000h <implied> 8000h |
Register: RegisterP0: Ax: Axl: Axh: Px: 00: r0 00: r0 0: a0 0: a0l 0: a0h 0: p0 01: r1 01: r1 1: a1 1: a1l 1: a1h 1: p1 02: r2 02: r2 03: r3 03: r3 Bx: Bxl: Bxh: Ablh: 04: r4 04: r4 0: b0 0: b0l 0: b0h 0: b0l 05: r5 05: r5 1: b1 1: b1l 1: b1h 1: b0h 06: r7 06: r7 2: b1l 07: y0 07: y0 Ab: Abl: Abh: Abe: 3: b1h 08: st0 08: st0 0: b0 0: b0l 0: b0h 0: b0e 4: a0l 09: st1 09: st1 1: b1 1: b1l 1: b1h 1: b1e 5: a0h 0A: st2 0A: st2 2: a0 2: a0l 2: a0h 2: a0e 6: a1l 0B: p0h !! 0B: p0 !! 3: a1 3: a1l 3: a1h 3: a1e 7: a1h 0C: pc 0C: pc 0D: sp 0D: sp Cond: 0E: cfgi 0E: cfgi 0: true ;Always ;always 0F: cfgj 0F: cfgj 1: eq ;Equal to zero ;Z=1 10: b0h 10: b0h 2: neq ;Not equal to zero ;Z=0 11: b1h 11: b1h 3: gt ;Greater than zero ;M=0 and Z=0 12: b0l 12: b0l 4: ge ;Greater or equal to zero ;M=0 13: b1l 13: b1l 5: lt ;Less than zero ;M=1 14: ext0 14: ext0 6: le ;Less or equal to zero ;M=1 or Z=1 15: ext1 15: ext1 7: nn ;Normalize flag is cleared ;N=0 16: ext2 16: ext2 8: c ;Carry flag is set ;C=1 17: ext3 17: ext3 9: v ;Overflow flag is set ;V=1 18: a0 18: a0 A: e ;Extension flag is set ;E=1 19: a1 19: a1 B: l ;Limit flag is set ;L=1 1A: a0l 1A: a0l C: nr ;R flag is cleared ;R=0 1B: a1l 1B: a1l D: niu0 ;Input user pin 0 cleared ;IUSER0=0 1C: a0h 1C: a0h E: iu0 ;Input user pin 0 set ;IUSER0=1 1D: a1h 1D: a1h F: iu1 ;Input user pin 1 set ;IUSER1=1 1E: lc 1E: lc 1F: sv 1F: sv |
R0123457y0: Rn: ArArpSttMod: ArArp: SttMod:
0: r0 0: r0 0: ar0 0: ar0 0: stt0
1: r1 1: r1 1: ar1 1: ar1 1: stt1
2: r2 2: r2 2: arp0 2: arp0 2: stt2
3: r3 3: r3 3: arp1 3: arp1 3: reserved
4: r4 4: r4 4: arp2 4: arp2 4: mod0
5: r5 5: r5 5: arp3 5: arp3 5: mod1
6: r7 ;aka rb 6: r6 ;TL2 only 6: reserved 6: reserved 6: mod2
7: y0 ;aka y 7: r7 ;TL2 only 7: reserved 7: reserved 7: mod3
8: stt0
R01: R04: R45: 9: stt1 Ar: BankFlags:
0: r0 0: r0 0:r4 A: stt2 0: ar0 01h: cfgi
1: r1 1: r4 1:r5 B: reserved 1: ar1 02h: r4
C: mod0 04h: r1
R0123: R0425: R4567: D: mod1 Arp: 08h: r0
0: r0 0: r0 0: r4 E: mod2 0: arp0 10h: r7 ;TL2
1: r1 1: r4 1: r5 F: mod3 1: arp1 20h: cfgj ;TL2
2: r2 2: r2 2: r6 2: arp2
3: r3 3: r5 3: r7 3: arp3
|
SwapTypes: val native nocash ;meaning 0: (a0,b0) a0,b0 ;a0 <--> b0 ;flags(a0) 1: (a0,b1) a0,b1 ;a0 <--> b1 ;flags(a0) 2: (a1,b0) a1,b0 ;a1 <--> b0 ;flags(a1) 3: (a1,b1) a1,b1 ;a1 <--> b1 ;flags(a1) 4: (a0,b0),(a1,b1) a0:a1,b0:b1 ;a0 <--> b0 and a1 <--> b1 ;flags(a0) 5: (a0,b1),(a1,b0) a0:a1,b1:b0 ;a0 <--> b1 and a1 <--> b0 ;flags(a0) 6: (a0,b0,a1) a1,b0,a0 ;a0 --> b0 --> a1 ;flags(a1) 7: (a0,b1,a1) a1,b1,a0 ;a0 --> b1 --> a1 ;flags(a1) 8: (a1,b0,a0) a0,b0,a1 ;a1 --> b0 --> a0 ;flags(a0) 9: (a1,b1,a0) a0,b1,a1 ;a1 --> b1 --> a0 ;flags(a0) A: (b0,a0,b1) b1,a0,b0 ;b0 --> a0 --> b1 ;flags(a0)! B: (b0,a1,b1) b1,a1,b0 ;b0 --> a1 --> b1 ;flags(a1)! C: (b1,a0,b0) b0,a0,b1 ;b1 --> a0 --> b0 ;flags(a0)! D: (b1,a1,b0) b0,a1,b1 ;b1 --> a1 --> b0 ;flags(a1)! E: reserved reserved ;- ;- F: reserved reserved ;- ;- |
offsZI: ;maybe offsAr01 ? 0: '' ;Z (zero) 1: '+' ;I (increment) offsI: 0: '+' ;I (increment) offsZIDZ: ;aka offsAr0123 0: '' ;Z (zero) 1: '+' ;I (increment) 2: '-' ;D (decrement) 3: '' ;Z (zero) stepZIDS: 0: '' ;Z (zero) 1: '+1' ;I (increment) 2: '-1' ;D (decrement) 3: '+s' ;S (add step) ;XXX ? see "stepi" and "stepj" modrstepZIDS: 0: '' ;Z (zero) 1: '+' ;I (increment) 2: '-' ;D (decrement) 3: '+s' ;S (add step) ;XXX ? see "stepi" and "stepj" stepII2D2S: ;aka stepAr0123@ 0: '+1' ;I (increment) 1: '+2' ;I2 (increment twice) 2: '-2' ;D2 (decrement twice) 3: '+s' ;S (add step) ;XXX ? see "stepi" and "stepj" stepD2S: 0: '-2' ;D2 (decrement twice) 1: '+s' ' ;S (add step) ;XXX ? see "stepi" and "stepj" modrstepII2D2S0: 0: '+' ;I (increment) 1: '+2' ;I2 (increment twice) 2: '-2' ;D2 (decrement twice) 3: '+s0' ;S0 (add step0 ?) ;XXX ?? see "stepi0" and "stepj0" stepII2: 0: '+1' ;I (increment) 1: '+2' ;I2 (increment twice) modrstepI2: 0: '+2' ;I2 (increment twice) modrstepD2: 0: '-2' ;D2 (decrement twice) |
| DSi New Shared WRAM (for ARM7, ARM9, DSP) |
Old WRAM-0/1 32Kbytes (2x16K), mappable to ARM7, or ARM9 New WRAM-A 256Kbytes (4x64K), mappable to ARM7, or ARM9 New WRAM-B 256Kbytes (8x32K), mappable to ARM7, ARM9, or DSP-program memory New WRAM-C 256Kbytes (8x32K), mappable to ARM7, ARM9, or DSP-data memory |
____________________________ Slot Write Protect ______________________________ |
0-3 WRAM-A, Port 4004040h-4004043h Write (0=Writeable by ARM9, 1=Read-only) 4-7 Unknown/Unused (0) 8-15 WRAM-B, Port 4004044h-400404Bh Write (0=Writeable by ARM9, 1=Read-only) 16-23 WRAM-C, Port 400404Ch-4004053h Write (0=Writeable by ARM9, 1=Read-only) 24-31 Unknown/Unused (0) ;but, carthdr has nonzero data for it? |
______________________________ Slot Allocation ______________________________ |
0 Master (0=ARM9, 1=ARM7) 1 Not used 2-3 Offset (0..3) (slot 0..3) (LSB of address in 64Kbyte units) 4-6 Not used 7 Enable (0=Disable, 1=Enable) |
0-1 Master (0=ARM9, 1=ARM7, 2 or 3=DSP/code) 2-4 Offset (0..7) (slot 0..7) (LSB of address in 32Kbyte units) 5-6 Not used (0) 7 Enable (0=Disable, 1=Enable) |
0-1 Master (0=ARM9, 1=ARM7, 2 or 3=DSP/data) 2-4 Offset (0..7) (slot 0..7) (LSB of address in 32Kbyte units) 5-6 Not used (0) 7 Enable (0=Disable, 1=Enable) |
______________________________ Address Mapping ______________________________ |
0-3 Not used (0) 4-11 Start Address (3000000h+N*10000h) ;=3000000h..3FF0000h 12-13 Image Size (0 or 1=64KB/Slot0, 2=128KB/Slot0+1+2??, 3=256KB/Slot0..3) 14-19 Not used (0) 20-28 End Address (3000000h+N*10000h-1) ;=2FFFFFFh..4FEFFFFh 29-31 Not used (0) |
0-2 Not used (0) 3-11 Start Address (3000000h+N*8000h) ;=3000000h..3FF8000h 12-13 Image Size (0=32K/Slot0,1=64KB/Slot0-1,2=128KB/Slot0-3,3=256KB/Slot0-7) 14-18 Not used (0) 19-28 End Address (3000000h+N*8000h-1) ;=2FFFFFFh..4FF7FFFh 29-31 Not used (0) |
___________________________________ Notes ___________________________________ |
Slots 0,1,2,3,0,1,2,3,0,1,2,3,0,1,2,3,etc. |
Slots -,-,-,-,-,-,2,3,0,1,2,3,-,-,-,-,etc. |
Slots -,-,-,-,-,-,2,z,0,1,2,z,-,-,-,-,etc. |
New Shared-WRAM-A Highest Priority New Shared-WRAM-B High Priority New Shared-WRAM-C Low Priority Old Shared-WRAM-0/1 Lowest Priority Old ARM7-WRAM Whatever Priority (unknown...) I/O ports 4xxxxxxh Whatever Priority (unknown...) |
Unknown what happens when selecting multiple WRAM blocks to the same slot? |
| DSi New DMA (NDMA) |
0-15 Unused (0) 16-19 Cycle Selection (0=None, 1..15=1..16384 clks) ;1 SHL (N-1) 20-30 Unused (0) 31 DMA Arbitration Mode (0=NDMA0=HighestPriority, 1=RoundRobinPriority) |
0-1 Unused (0) 2-31 DMA Source/Destination Address, in 4-byte steps |
0-27 Total Number of Words to Transfer (1..0FFFFFFFh, or 0=10000000h) 28-31 Unused (0) |
0-23 Number of Words to Transfer (1..00FFFFFFh, or 0=01000000h) 24-31 Unused (0) |
0-15 Interval Timer (1..FFFFh, or 0=Infinite/TillTransferEnd) 16-17 Prescaler (33.514MHz SHR (n*2)) ;0=33MHz, 1=8MHz, 2=2MHz, 3=0.5MHz 18-31 Unused (0) |
0-31 Fill Data (can be used as Fixed Source Data for memfill's) |
0-9 Unused (0) 10-11 Dest Address Update (0=Increment, 1=Decrement, 2=Fixed, 3=Reserved) 12 Dest Address Reload (0=No, 1=Reload at (logical blk?) transfer end) 13-14 Source Address Update (0=Increment, 1=Decrement, 2=Fixed, 3=FillData) 15 Source Address Reload (0=No, 1=Reload at (logical blk?) transfer end) 16-19 Physical Block Size (0..0Fh=1..32768 words, aka (1 SHL n) words) 20-23 Unused (0) 24-28 DMA Startup Mode (00h..1Fh, see ARM7/ARM9 startup lists below) 29 DMA Repeat Mode (0=Repeat until NDMAxTCNT, 1=Repeat infinitely) 30 DMA Interrupt Enable (0=Disable, 1=Enable) 31 DMA Enable/Busy (0=Disable, 1=Enable/Busy) |
00h Timer0 ;\ 01h Timer1 ; new NDMA-specific modes 02h Timer2 ; 03h Timer3 ;/ 04h DS Cartridge Slot 4100010h 05h Reserved (maybe 2nd DS-Cart Slot 4102010h, or GBA slot relict?) 06h V-Blank 07h H-Blank (but not during V-blank) 08h Display Sync (sync to H-blank drawing) ;Uh, what is BLANK-DRAWING ?? 09h Work RAM (what?) (=probably Main memory display, as on NDS) 0Ah Geometry Command FIFO 0Bh Camera ;-new NDMA-specific mode 0Ch..0Fh Reserved 10h..1Fh Start immediately (without repeat) |
00h Timer0 ;\ 01h Timer1 ; new NDMA-specific modes 02h Timer2 ; 03h Timer3 ;/ 04h DS Cartridge Slot 4100010h 05h Reserved? (maybe 2nd DS-Cart Slot 4102010h, or GBA slot relict?) 06h V-Blank 07h NDS-Wifi 08h SD/MMC (SD_DATA32_FIFO) ;\ 09h DSi-Wifi (SDIO_DATA32_FIFO) ; 0Ah AES in (AES_WRFIFO) ; new NDMA-specific modes 0Bh AES out (AES_RDFIFO) ; 0Ch Microphone (MIC_DATA) ;/ 0Dh..0Fh Reserved? 10h..1Fh Start immediately (without repeat) |
| DSi Microphone and SoundExt |
0-1 Data Format (0=MakeStereo, 1=SameAsNormal?, 2=Normal, 3=None) (R/W) 2-3 Sampling Rate (0..3=F/1, F/2, F/3, F/4) (R/W) 4-7 Unused (0) (-) 8 FIFO Empty (0=No, 1=Empty) ;0 words (R) 9 FIFO Half-Full (0=No, 1=Half-Full) ;8 or more words (R) 10 FIFO Full (0=No, 1=Full) ;16 words (R) 11 FIFO Overrun (0=No, 1=Overrun/Stopped) ;more than 16 words (R) 12 Clear FIFO (0=No change, 1=Clear) ;works only if bit15 was 0 (W) 13-14 IRQ Enable (0=Off, 1=Same as 3, 2=When Full, 3=When Half-Full)(R/W) 15 Enable (0=Disable, 1=Enable) (R/W) |
I2S=32.73kHz --> F/1=32.73kHz, F/2=16.36kHz, F/3=10.91kHz, F/4=8.18kHz I2S=47.61kHz --> F/1=47.61kHz, F/2=23.81kHz, F/3=15.87kHz, F/4=11.90kHz |
0-15 Signed 16bit Data, 1st sample ;\16 words FIFO, aka 32 halfwords 16-31 Signed 16bit Data, 2nd sample ;/ |
0-3 NITRO/DSP ratio (valid range is 0 to 8) (R/W) 4-12 Unknown/Unused (0) (0?) 13 Sound/Microphone I2S frequency (0=32.73 kHz, 1=47.61 kHz) (R or R/W) 14 Mute status (does NOT affect mic) (?=Mute WHAT?) (R/W) 15 Enable Microphone (and Sound Output!) (1=Enable) (R/W) |
00h DSP sound 8/8, NITRO sound 0/8 (=DSP sound only) 01h DSP sound 7/8, NITRO sound 1/8 02h DSP sound 6/8, NITRO sound 2/8 03h DSP sound 5/8, NITRO sound 3/8 04h DSP sound 4/8, NITRO sound 4/8 (=half volume for DSP and NITRO each) 05h DSP sound 3/8, NITRO sound 5/8 06h DSP sound 2/8, NITRO sound 6/8 07h DSP sound 1/8, NITRO sound 7/8 08h DSP sound 0/8, NITRO sound 8/8 (=NITRO sound only) 09h..0Fh Reserved |
| DSi Advanced Encryption Standard (AES) |
| DSi AES I/O Ports |
0-4 Write FIFO Count (00h..10h words) (00h=Empty, 10h=Full) (R)
5-9 Read FIFO Count (00h..10h words) (00h=Empty, 10h=Full) (R)
10 Write FIFO Flush (0=No change, 1=Flush) (N/A or W)
11 Read FIFO Flush (0=No change, 1=Flush) (N/A or W)
12-13 Write FIFO DMA Size (0..3 = 16,12,8,4 words) (2=Normal=8) (R or R/W)
14-15 Read FIFO DMA Size (0..3 = 4,8,12,16 words) (1=Normal=8) (R or R/W)
16-18 CCM MAC Size, max(4,(N*2+2)) bytes, usually 7=16 bytes (R or R/W)
19 CCM Pass Associated Data to RDFIFO (0=No/Normal, 1=Yes) (R or R/W)
Bit19=1 is a bit glitchy: The data should theoretically arrive in
RDFIFO immediately after writing 4 words to WRFIFO, but actually,
Bit19=1 seems to cause 4 words held hidden in neither FIFO, until
the first Payload block is written (at that point, the hidden
associated words are suddenly appearing in RDFIFO)
20 CCM MAC Verify Source (0=From AES_WRFIFO, 1=From AES_MAC) (R or R/W)
21 CCM MAC Verify Result (0=Invalid/Busy, 1=Verified/Okay) (R)
22-23 Unknown/Unused (0) (0)
24 Key Select (0=No change, 1=Apply key selected in Bit26-27) (W)
25 Key Schedule Busy (uh, always 0=ready?) (rather sth else busy?) (R)
26-27 Key Slot (0..3=KEY0..KEY3, applied via Bit24) (R or R/W)
28-29 Mode (0=CCM/decrypt, 1=CCM/encrypt, 2=CTR, 3=Same as 2) (R or R/W)
30 Interrupt Enable (0=Disable, 1=Enable IRQ on Transfer End) (R or R/W)
31 Start/Enable (0=Disable/Ready, 1=Enable/Busy) (R/W)
|
0-15 Number of Extra associated data blocks for AES-CCM (unused for AES-CTR) 16-31 Number of Payload data blocks (0..FFFFh = 0..FFFF0h bytes) |
0-31 Data |
For AES-CTR mode: CTR[00h..0Fh] = AES_IV[00h..0Fh]
CBC[00h..0Fh] = not used by AES-CTR mode
For AES-CCM mode: CTR[00h..0Fh] = 00h,00h,00h,AES_IV[00h..0Bh],02h
CBC[00h..0Fh] = x0h,xxh,0xh,AES_IV[00h..0Bh],flg
|
AES-CCM Encryption: MAC is returned in AES_RDFIFO after transfer AES-CCM Decryption, AES_CNT.20=0: MAC written to AES_WRFIFO after transfer AES-CCM Decryption, AES_CNT.20=1: MAC written to AES_MAC before transfer |
Byte 00h-0Fh Normal 128bit Key ;\use either normal key, Byte 10h-1Fh Special 128bit Key_X ; or special key_x/y Byte 20h-2Fh Special 128bit Key_Y ;/ |
Key = ((Key_X XOR Key_Y) + FFFEFB4E295902582A680F5F1A4F3E79h) ROL 42 |
| DSi AES Little-Endian High Level Functions |
aes_setkey(ENCRYPT,key,key_size] ;-init key
[ctr+0..15] = [iv+0..15] ;-init ctr
n=[nc_off]
while len>0 ;code is 100% same for ENCRYPT and DECRYPT ;\
if n=0 ; encrypt
aes_crypt_block(ENCRYPT,ctr,tmp) ; or decrypt
littleendian(ctr)=littleendian(ctr)+1 ;increment counter ; message
[dst] = [src] xor [tmp+n] ;
src=src+1, dst=dst+1, len=len-1, n=(n+1) and 0Fh ;/
[nc_off]=n
|
if mac_len<4 or mac_len>16 or (mac_len and 1)=1 then error ;\limits
if iv_len<7 or iv_len>13 then error ;/
aes_setkey(ENCRYPT,key,key_size] ;-init key
ctr_len = 15-iv_len ;\
[ctr+15]=ctr_len-1 ;bit3..7=zero ;1 byte (ctr_len) ; init ctr
[ctr+(15-iv_len)..14] = [iv+0..(iv_len-1)] ;7..13 bytes (iv) ;
[ctr+0..(14-iv_len)]=littleendian(0) ;8..2 bytes (counter=0) ;/
[cbc+0..15]=littleendian(msg_len) ;-[(iv_len+1)..15]=msg_len ;\
if [cbc+15..15-iv_len]<>0 then error ;msg_len overlaps iv/flags ;
[cbc+(15-iv_len)..14]=[iv+0..iv_len-1] ;-[1..iv_len]=iv/nonce ;
[cbc+15].bit7=0 ;reserved/zero ;\ ; init cbc
[cbc+15].bit6=(xtra_len>0) ; [15]=flags ;
[cbc+15].bit5..3=(mac_len/2-1) ; ;
[cbc+15].bit2..0=(ctr_len-1) ;/ ;
aes_crypt_block(ENCRYPT,cbc,cbc) ;UPDATE_CBC_MAC ;/
if NintendoDSi then ;\
a=0 ;the DSi hardware doesn't support xtra_len encoding at all ;
elseif xtra_len<0FF00h then ;
[cbc+14..15]=[cbc+14..15] xor littleendian(xtra_len), a=2 ; weird
elseif xtra_len<100000000h then ; encoding
[cbc+14..15]=[cbc+14..15] xor littleendian(FFFEh) ; for
[cbc+10..13]=[cbc+10..13] xor littleendian(xtra_len), a=6 ; xtra_len
else ;
[cbc+14..15]=[cbc+14..15] xor littleendian(FFFFh) ;
[cbc+6..13] =[cbc+6..13] xor littleendian(xtra_len), a=10 ;/
while xtra_len>0 ;\scatter
z=min(xtra_len,16-a) ; cbc by
[cbc+16-a-z..(15-a)]=[cbc+16-a-z..(15-a)] xor [xtra+0..(z-1)] ; xtra
aes_crypt_block(ENCRYPT,cbc,cbc) ;UPDATE_CBC_MAC ; (if any)
xtra=xtra+z, xtra_len=xtra_len-z, a=0 ;/
while msg_len>0 ;\
littleendian(ctr)=littleendian(ctr)+1 ;increment counter ;
aes_crypt_block(ENCRYPT,ctr,tmp) ;CTR_CRYPT ;
z=min(msg_len,16) ; encrypt
if mode=ENCRYPT ; or decrypt
[cbc+(16-z)..15] = [cbc+(16-z)..15] xor [src+0..(z-1)] ; message
[dst+0..(z-1)] = [src+0..(z-1)] xor [tmp+(16-z)..15] ; body
if mode=DECRYPT ;
[cbc+(16-z)..15] = [cbc+(16-z)..15] xor [dst+0..(z-1)] ;
aes_crypt_block(ENCRYPT,cbc,cbc) ;UPDATE_CBC_MAC ;
src=src+z, dst=dst+z, msg_len=msg_len-z ;/
[ctr+0..(14-iv_len)]=littleendian(0) ;reset counter=0 ;\
aes_crypt_block(ENCRYPT,ctr,tmp) ;CTR_CRYPT ; message
[cbc+0..15] = [cbc+0..15] xor [tmp+0..15] ; auth code
z=mac_len ; (mac)
IF mode=ENCRYPT then [mac+0..(z-1)] = [cbc+(16-z)..15] ;
IF mode=DECRYPT and [mac+0..(z-1)] <> [cbc+(16-z)..15] then error;/
|
aes_setkey(mode,key,key_size] ;-init key
[cbc+0..15] = [iv+0..15] ;-init cbc
if (len AND 0Fh)>0 then error
while len>0 ;\
if mode=ENCRYPT ;
[dst+0..15] = [src+0..15] xor [cbc+0..15] ;
aes_crypt_block(mode,dst,dst) ; encrypt
[cbc+0..15] = [dst+0..15] ; or decrypt
if mode=DECRYPT ; message
[tmp+0..15] = [src+0..15] ;
aes_crypt_block(mode,src,dst) ;
[dst+0..15] = [dst+0..15] xor [cbc+0..15] ;
[cbc+0..15] = [tmp+0..15] ;
src=src+16, dst=dst+16, len=len-16 ;/
|
aes_setkey(ENCRYPT,key,key_size] ;-init key
[cfb+0..15] = [iv+0..15] ;-init cfb
n=[iv_off]
while len>0 ;\
if n=0 then aes_crypt_block(ENCRYPT,cfb,cfb) ; encrypt
if mode=DECRYPT then c=[src], [dst]=c xor [cfb+n], [cfb+n]=c ; or decrypt
if mode=ENCRYPT then c=[cfb+n] xor [src], [cfb+n]=c, [dst]=c ; message
src=src+1, dst=dst+1, len=len-1, n=(n+1) and 0Fh ;/
[iv_off]=n
|
aes_setkey(ENCRYPT,key,key_size] ;-init key
[cfb+0..15] = [iv+0..15] ;-init cfb
n=[iv_off]
while len>0 ;\
aes_crypt_block(ENCRYPT,cfb,tmp) ;
[cfb+1..15] = [cfb+0..14] ;shift with 8-bit step ; encrypt
if mode=DECRYPT then [cfb+0] = [src+(n xor 0Fh)] ; or decrypt
[dst+(n xor 0Fh)] = [src+(n xor 0Fh)] xor [tmp+15] ;shift-in ; message
if mode=ENCRYPT then [cfb+0] = [dst+(n xor 0Fh)] ;
len=len-1, n=n+1 ;/
[iv_off]=n
|
aes_setkey(mode,key,key_size] ;-init key
if (len AND 0Fh)>0 then error
while len>0 ;\encrypt
aes_crypt_block(mode,src,dst) ; or decrypt
src=src+16, dst=dst+16, len=len-16 ;/message
|
| DSi AES Little-Endian Core Function and Key Schedule |
aes_crypt_block(mode,src,dst):
Y0 = RK[0] xor [src+00h]
Y1 = RK[1] xor [src+04h]
Y2 = RK[2] xor [src+08h]
Y3 = RK[3] xor [src+0Ch]
;below code depending on mode: <---ENCRYPT---> -or- <---DECRYPT--->
for i=1 to nr-1
X0 = RK[i*4+0] xor scatter32(FT,Y1,Y2,Y3,Y0) -or- (RT,Y3,Y2,Y1,Y0)
X1 = RK[i*4+1] xor scatter32(FT,Y2,Y3,Y0,Y1) -or- (RT,Y0,Y3,Y2,Y1)
X2 = RK[i*4+2] xor scatter32(FT,Y3,Y0,Y1,Y2) -or- (RT,Y1,Y0,Y3,Y2)
X3 = RK[i*4+3] xor scatter32(FT,Y0,Y1,Y2,Y3) -or- (RT,Y2,Y1,Y0,Y3)
Y0=X0, Y1=X1, Y2=X2, Y3=X3
[dst+00h] = RK[nr*4+0] xor scatter8(FSb,Y1,Y2,Y3,Y0) -or- (RSb,Y3,Y2,Y1,Y0)
[dst+04h] = RK[nr*4+1] xor scatter8(FSb,Y2,Y3,Y0,Y1) -or- (RSb,Y0,Y3,Y2,Y1)
[dst+08h] = RK[nr*4+2] xor scatter8(FSb,Y3,Y0,Y1,Y2) -or- (RSb,Y1,Y0,Y3,Y2)
[dst+0Ch] = RK[nr*4+3] xor scatter8(FSb,Y0,Y1,Y2,Y3) -or- (RSb,Y2,Y1,Y0,Y3)
|
scatter32(TAB,a,b,c,d): scatter8(TAB,a,b,c,d): w= (TAB[a.bit0..7] ror 24) w.bit0..7 = TAB[a.bit0..7] w=w xor (TAB[b.bit8..15] ror 16) w.bit8..15 = TAB[b.bit8..15] w=w xor (TAB[c.bit16..23] ror 8) w.bit16..23 = TAB[c.bit16..23] w=w xor (TAB[d.bit24..31]) w.bit24..31 = TAB[d.bit24..31] return w return w |
aes_setkey(mode,key,keysize): ;out: RK[0..43/51/59], nr=10/12/14
aes_generate_tables ;<-- unless tables are already initialized
if keysize<>128 and keysize<>192 and keysize<>256 then error ;size in bits
rc=01h, j=0, jj=keysize/32, nr=jj+6 ;jj=4,6,8 ;\
for i=0 to (nr+1)*4-1 ;nr=10,12,14 ; copy 16/24/32-byte key
if i<jj then w=[key+(jj-1-i)*4+0..3] ; to RK[0..3/5/7]
else w=w xor RK[(i-jj) xor 3] ; and, make
RK[i xor 3]=w, j=j+1 ; RK[4/6/8..43/51/59]
if j=jj then ;
w=scatter8(FSb,w,w,w,w) ;
w=(w rol 8) xor (rc shl 24) ;
j=0, rc=rc*2, if rc>0FFh then rc=rc xor 11Bh ;
if j=4 and jj=8 then w=scatter8(FSb,w,w,w,w) ;/
if mode=DECRYPT then
for i=0 to nr/2-1 ;swap entries (except middle one)
for j=0 to 3
w=RK[i*4+j], v=RK[nr*4-i*4+j]
RK[i*4+j]=v, RK[nr*4-i*4+j]=w
for i=4 to nr*4-1 ;modify entries (except RK[0..3] and RK[nr*4+0..3])
w=RK[i], w=scatter8(FSb,w,w,w,w), RK[i]=scatter32(RT,w,w,w,w)
|
| DSi AES Little-Endian Tables and Test Values |
aes_generate_tables:
for i=0 to 0FFh ;compute pow and log tables...
if i=0 then x=01h, else x=x xor x*2, if x>0FFh then x=x xor 11Bh
pow[i]=x, log[x]=i
for i=0 to 0FFh ;generate the forward and reverse S-boxes...
x=pow[0FFh-log[i]]
x=x xor (x rol 1) xor (x rol 2) xor (x rol 3) xor (x rol 4) xor 63h
if i=0 then x=63h
FSb[i]=x, RSb[x]=i
for i=0 to 0FFh ;generate the forward and reverse tables...
x=FSb[i]*2, if x>0FFh then x=x xor 11Bh
FT[i]=(FSb[i]*00010101h) xor (x*01000001h)
w=00000000h, x=RSb[i]
if x<>00h then ;ie. not at i=63h
w=w+pow[(log[x]+log[0Eh]) mod 00FFh]*1000000h
w=w+pow[(log[x]+log[09h]) mod 00FFh]*10000h
w=w+pow[(log[x]+log[0Dh]) mod 00FFh]*100h
w=w+pow[(log[x]+log[0Bh]) mod 00FFh]*1h
RT[i]=w
|
aes_generate_tables_results: pow[00h..FFh] = 01,03,05,0F,11,..,C7,52,F6,01 ;pow ;\needed temporarily log[00h..FFh] = 00,FF,19,01,32,..,C0,F7,70,07 ;log ;/for table creation FSb[00h..FFh] = 63,7C,77,7B,F2,..,B0,54,BB,16 ;Forward S-box RSb[00h..FFh] = 52,09,6A,D5,30,..,55,21,0C,7D ;Reverse S-box FT[00h..FFh] = C66363A5,F87C7C84,..,2C16163A ;Forward Table RT[00h..FFh] = 51F4A750,7E416553,..,D0B85742 ;Reverse Table |
aes_setkey_results: key = "AES-Test-Key-Str-1234567-Abcdefg" ;use only 1st bytes for 128/192bit 128bit ENCRYPT --> RK[0..9..30..43] = 2D534541..2783080F..93AF7DF0..827EE10D 192bit ENCRYPT --> RK[0..9..30..51] = 79654B2D..9708FA95..2529372B..C66C19FA 256bit ENCRYPT --> RK[0..9..30..59] = 3332312D..DF5C92A5..74174E2E..3C8ADAE6 128bit DECRYPT --> RK[0..9..30..43] = AEABCD4D..ECD33F19..8C87B246..7274532D 192bit DECRYPT --> RK[0..9..30..51] = AFA9796F..72A3EFE5..455646C7..37363534 256bit DECRYPT --> RK[0..9..30..59] = 0ED52830..4601F929..415A7D65..67666564 |
aes_crypt_results: [key+0..15] = "AES-Test-Key-Str-1234567-Abcdefg" [iv+0..15] = "Nonce/InitVector" [xtra+0..20] = "Extra-Associated-Data" ;\for CCM iv_len=12, mac_len=16, xtra_len=xx ;/ Unencrypted: [dta+0..113Fh] = "Unencrypted-Data", 190h x "TestPadding" AES-ECB: [dta+0..113Fh] = 20,24,73,88,..,44,A8,D6,A8 ;\ AES-CBC: [dta+0..113Fh] = A4,6F,7A,F2,..,58,C9,02,B4 ; AES-CFB128: [dta+0..113Fh] = 20,C6,DB,35,..,9A,83,7F,DB ; keysize=128 AES-CFB8: [dta+0..113Fh] = 55,C7,75,1C,..,24,6E,A6,D1 ; AES-CTR: [dta+0..113Fh] = 20,C6,DB,35,..,AB,09,0C,75 ; AES-CCM: [dta+0..113Fh] = C8,37,D7,F1,..,7B,EF,FC,12 ; AES-CCM (ori): [mac+0..0Fh] = xx,xx,xx,xx,..,xx,xx,xx,xx ; AES-CCM (DSi): [mac+0..0Fh] = xx,xx,xx,xx,..,xx,xx,xx,xx ;/ AES-ECB: [dta+0..113Fh] = CC,B6,4D,17,..,D3,56,3E,64 ;-keysize=192 AES-ECB: [dta+0..113Fh] = A9,A9,9B,3E,..,8A,C6,13,A1 ;-keysize=256 |
| DSi AES Big-Endian High Level Functions |
aes_setkey(ENCRYPT,key,key_size] ;-init key
[ctr+0..15] = [iv+0..15] ;-init ctr
n=[nc_off]
while len>0 ;code is 100% same for ENCRYPT and DECRYPT ;\
if n=0 ; encrypt
aes_crypt_block(ENCRYPT,ctr,tmp) ; or decrypt
bigendian(ctr)=bigendian(ctr)+1 ;increment counter ; message
[dst] = [src] xor [tmp+n] ;
src=src+1, dst=dst+1, len=len-1, n=(n+1) and 0Fh ;/
[nc_off]=n
|
if mac_len<4 or mac_len>16 or (mac_len and 1)=1 then error ;\limits
if iv_len<7 or iv_len>13 then error ;/
aes_setkey(ENCRYPT,key,key_size] ;-init key
ctr_len = 15-iv_len ;\
[ctr+0]=ctr_len-1 ;bit3..7=zero ;1 byte (ctr_len) ; init ctr
[ctr+1..iv_len] = [iv+0..(iv_len-1)] ;7..13 bytes (iv) ;
[ctr+(iv_len+1)..15]=bigendian(0) ;8..2 bytes (counter=0) ;/
[cbc+0..15]=bigendian(msg_len) ;-[(iv_len+1)..15]=msg_len ;\
if [cbc+0..iv_len]<>0 then error ;errif msg_len overlaps iv/flags;
[cbc+1..iv_len]=[iv+0..iv_len-1] ;-[1..iv_len]=iv (aka nonce) ;
[cbc+0].bit7=0 ;reserved/zero ;\ ; init cbc
[cbc+0].bit6=(xtra_len>0) ; [0]=flags ;
[cbc+0].bit5..3=(mac_len/2-1) ; ;
[cbc+0].bit2..0=(ctr_len-1) ;/ ;
aes_crypt_block(ENCRYPT,cbc,cbc) ;UPDATE_CBC_MAC ;/
if NintendoDSi then ;\
a=0 ;the DSi hardware doesn't support xtra_len encoding at all ;
elseif xtra_len<0FF00h then ;
[cbc+0..1]=[cbc+0..1] xor bigendian(xtra_len), a=2 ; weird
elseif xtra_len<100000000h then ; encoding
[cbc+0..1]=[cbc+0..1] xor bigendian(FFFEh) ; for
[cbc+2..5]=[cbc+2..5] xor bigendian(xtra_len), a=6 ; xtra_len
else ;
[cbc+0..1]=[cbc+0..1] xor bigendian(FFFFh) ;
[cbc+2..9]=[cbc+2..9] xor bigendian(xtra_len), a=10 ;/
while xtra_len>0 ;\scatter
z=min(xtra_len,16-a) ; cbc by
[cbc+a..(a+z-1)]=[cbc+a..(a+z-1)] xor [xtra+0..(z-1)] ; xtra
aes_crypt_block(ENCRYPT,cbc,cbc) ;UPDATE_CBC_MAC ; (if any)
xtra=xtra+z, xtra_len=xtra_len-z, a=0 ;/
while msg_len>0 ;\
bigendian(ctr)=bigendian(ctr)+1 ;increment counter ;
aes_crypt_block(ENCRYPT,ctr,tmp) ;CTR_CRYPT ;
z=min(msg_len,16) ; encrypt
if mode=ENCRYPT ; or decrypt
[cbc+0..(z-1)] = [cbc+0..(z-1)] xor [src+0..(z-1)] ; message
[dst+0..(z-1)] = [src+0..(z-1)] xor [tmp+0..(z-1)] ; body
if mode=DECRYPT ;
[cbc+0..(z-1)] = [cbc+0..(z-1)] xor [dst+0..(z-1)] ;
aes_crypt_block(ENCRYPT,cbc,cbc) ;UPDATE_CBC_MAC ;
src=src+z, dst=dst+z, msg_len=msg_len-z ;/
[ctr+(iv_len+1)..15]=bigendian(0) ;reset counter=0 ;\
aes_crypt_block(ENCRYPT,ctr,tmp) ;CTR_CRYPT ; message
[cbc+0..15] = [cbc+0..15] xor [tmp+0..15] ; auth code
z=mac_len ; (mac)
IF mode=ENCRYPT then [mac+0..(z-1)] = [cbc+0..(z-1)] ;
IF mode=DECRYPT and [mac+0..(z-1)] <> [cbc+0..(z-1)] then error ;/
|
aes_setkey(mode,key,key_size] ;-init key
[cbc+0..15] = [iv+0..15] ;-init cbc
if (len AND 0Fh)>0 then error
while len>0 ;\
if mode=ENCRYPT ;
[dst+0..15] = [src+0..15] xor [cbc+0..15] ;
aes_crypt_block(mode,dst,dst) ; encrypt
[cbc+0..15] = [dst+0..15] ; or decrypt
if mode=DECRYPT ; message
[tmp+0..15] = [src+0..15] ;
aes_crypt_block(mode,src,dst) ;
[dst+0..15] = [dst+0..15] xor [cbc+0..15] ;
[cbc+0..15] = [tmp+0..15] ;
src=src+16, dst=dst+16, len=len-16 ;/
|
aes_setkey(ENCRYPT,key,key_size] ;-init key
[cfb+0..15] = [iv+0..15] ;-init cfb
n=[iv_off]
while len>0 ;\
if n=0 then aes_crypt_block(ENCRYPT,cfb,cfb) ; encrypt
if mode=DECRYPT then c=[src], [dst]=c xor [cfb+n], [cfb+n]=c ; or decrypt
if mode=ENCRYPT then c=[cfb+n] xor [src], [cfb+n]=c, [dst]=c ; message
src=src+1, dst=dst+1, len=len-1, n=(n+1) and 0Fh ;/
[iv_off]=n
|
aes_setkey(ENCRYPT,key,key_size] ;-init key
[cfb+0..15] = [iv+0..15] ;-init cfb
while len>0 ;\
aes_crypt_block(ENCRYPT,cfb,tmp) ;
[cfb+0..14] = [cfb+1..15] ;shift with 8-bit step ; encrypt
if mode=DECRYPT then [cfb+15] = [src] ; or decrypt
[dst] = [src] xor [tmp+0] ;shift-in new 8-bits ; message
if mode=ENCRYPT then [cfb+15] = [dst] ;
src=src+1, dst=dst+1, len=len-1 ;/
|
aes_setkey(mode,key,key_size] ;-init key
if (len AND 0Fh)>0 then error
while len>0 ;\encrypt
aes_crypt_block(mode,src,dst) ; or decrypt
src=src+16, dst=dst+16, len=len-16 ;/message
|
| DSi AES Big-Endian Core Function and Key Schedule |
aes_crypt_block(mode,src,dst):
Y0 = RK[0] xor [src+00h]
Y1 = RK[1] xor [src+04h]
Y2 = RK[2] xor [src+08h]
Y3 = RK[3] xor [src+0Ch]
;below code depending on mode: <---ENCRYPT---> -or- <---DECRYPT--->
for i=1 to nr-1
X0 = RK[i*4+0] xor scatter32(FT,Y0,Y1,Y2,Y3) -or- (RT,Y0,Y3,Y2,Y1)
X1 = RK[i*4+1] xor scatter32(FT,Y1,Y2,Y3,Y0) -or- (RT,Y1,Y0,Y3,Y2)
X2 = RK[i*4+2] xor scatter32(FT,Y2,Y3,Y0,Y1) -or- (RT,Y2,Y1,Y0,Y3)
X3 = RK[i*4+3] xor scatter32(FT,Y3,Y0,Y1,Y2) -or- (RT,Y3,Y2,Y1,Y0)
Y0=X0, Y1=X1, Y2=X2, Y3=X3
[dst+00h] = RK[nr*4+0] xor scatter8(FSb,Y0,Y1,Y2,Y3) -or- (RSb,Y0,Y3,Y2,Y1)
[dst+04h] = RK[nr*4+1] xor scatter8(FSb,Y1,Y2,Y3,Y0) -or- (RSb,Y1,Y0,Y3,Y2)
[dst+08h] = RK[nr*4+2] xor scatter8(FSb,Y2,Y3,Y0,Y1) -or- (RSb,Y2,Y1,Y0,Y3)
[dst+0Ch] = RK[nr*4+3] xor scatter8(FSb,Y3,Y0,Y1,Y2) -or- (RSb,Y3,Y2,Y1,Y0)
|
scatter32(TAB,a,b,c,d): scatter8(TAB,a,b,c,d): w= (TAB[a.bit0..7]) w.bit0..7 = TAB[a.bit0..7] w=w xor (TAB[b.bit8..15] rol 8) w.bit8..15 = TAB[b.bit8..15] w=w xor (TAB[c.bit16..23] rol 16) w.bit16..23 = TAB[c.bit16..23] w=w xor (TAB[d.bit24..31] rol 24) w.bit24..31 = TAB[d.bit24..31] return w return w |
aes_setkey(mode,key,keysize): ;out: RK[0..43/51/59], nr=10/12/14
aes_generate_tables ;<-- unless tables are already initialized
if keysize<>128 and keysize<>192 and keysize<>256 then error ;size in bits
rc=01h, j=0, jj=keysize/32, nr=jj+6 ;jj=4,6,8 ;\
for i=0 to (nr+1)*4-1 ;nr=10,12,14 ; copy 16/24/32-byte key
if i<jj then w=[key+i*4+0..3] ; to RK[0..3/5/7]
else w=w xor RK[i-jj] ; and, make
RK[i]=w, j=j+1 ; RK[4/6/8..43/51/59]
if j=jj then ;
w=scatter8(FSb,w,w,w,w) ;
w=(w ror 8) xor (rc) ;
j=0, rc=rc*2, if rc>0FFh then rc=rc xor 11Bh ;
if j=4 and jj=8 then w=scatter8(FSb,w,w,w,w) ;/
if mode=DECRYPT then
for i=0 to nr/2-1 ;swap entries (except middle one)
for j=0 to 3
w=RK[i*4+j], v=RK[nr*4-i*4+j]
RK[i*4+j]=v, RK[nr*4-i*4+j]=w
for i=4 to nr*4-1 ;modify entries (except RK[0..3] and RK[nr*4+0..3])
w=RK[i], w=scatter8(FSb,w,w,w,w), RK[i]=scatter32(RT,w,w,w,w)
|
| DSi AES Big-Endian Tables and Test Values |
aes_generate_tables:
for i=0 to 0FFh ;compute pow and log tables...
if i=0 then x=01h, else x=x xor x*2, if x>0FFh then x=x xor 11Bh
pow[i]=x, log[x]=i
for i=0 to 0FFh ;generate the forward and reverse S-boxes...
x=pow[0FFh-log[i]]
x=x xor (x rol 1) xor (x rol 2) xor (x rol 3) xor (x rol 4) xor 63h
if i=0 then x=63h
FSb[i]=x, RSb[x]=i
for i=0 to 0FFh ;generate the forward and reverse tables...
x=FSb[i]*2, if x>0FFh then x=x xor 11Bh
FT[i]=(FSb[i]*01010100h) xor (x*01000001h)
w=00000000h, x=RSb[i]
if x<>00h then ;ie. not at i=63h
w=w+pow[(log[x]+log[0Eh]) mod 00FFh]*1h
w=w+pow[(log[x]+log[09h]) mod 00FFh]*100h
w=w+pow[(log[x]+log[0Dh]) mod 00FFh]*10000h
w=w+pow[(log[x]+log[0Bh]) mod 00FFh]*1000000h
RT[i]=w
|
aes_generate_tables_results: pow[00h..FFh] = 01,03,05,0F,11,..,C7,52,F6,01 ;pow ;\needed temporarily log[00h..FFh] = 00,FF,19,01,32,..,C0,F7,70,07 ;log ;/for table creation FSb[00h..FFh] = 63,7C,77,7B,F2,..,B0,54,BB,16 ;Forward S-box RSb[00h..FFh] = 52,09,6A,D5,30,..,55,21,0C,7D ;Reverse S-box FT[00h..FFh] = A56363C6,847C7CF8,..,3A16162C ;Forward Table RT[00h..FFh] = 50A7F451,5365417E,..,4257B8D0 ;Reverse Table |
aes_setkey_results: key = "AES-Test-Key-Str-1234567-Abcdefg" ;use only 1st bytes for 128/192bit 128bit ENCRYPT --> RK[0..9..30..43] = 2D534541..ED0DC6FA..43DAC81C..0F5026BB 192bit ENCRYPT --> RK[0..9..30..51] = 2D534541..4AAB3D82..29CA38D2..CA4DFE3B 256bit ENCRYPT --> RK[0..9..30..59] = 2D534541..1AA51359..CCB886C8..88956C9C 128bit DECRYPT --> RK[0..9..30..43] = F653079B..47DD8A1C..1C2070A7..7274532D 192bit DECRYPT --> RK[0..9..30..51] = 3CEC6AFF..C4F96B6F..AE36B4AE..7274532D 256bit DECRYPT --> RK[0..9..30..59] = DE7ADCD9..8C559ADD..067A387E..7274532D |
aes_crypt_results: [key+0..15] = "AES-Test-Key-Str-1234567-Abcdefg" [iv+0..15] = "Nonce/InitVector" [xtra+0..20] = "Extra-Associated-Data" ;\for CCM iv_len=12, mac_len=16, xtra_len=21 ;/ Unencrypted: [dta+0..113Fh] = "Unencrypted-Data", 190h x "TestPadding" AES-ECB: [dta+0..113Fh] = 5F,BD,04,DB,..,E4,07,F4,B6 ;\ AES-CBC: [dta+0..113Fh] = 0B,BB,53,FA,..,DD,28,6D,AE ; AES-CFB128: [dta+0..113Fh] = F4,75,4F,0E,..,73,B5,D7,E7 ; keysize=128 AES-CFB8: [dta+0..113Fh] = F4,10,6A,83,..,BF,1B,16,3E ; AES-CTR: [dta+0..113Fh] = F4,75,4F,0E,..,04,DF,EB,BA ; AES-CCM: [dta+0..113Fh] = FD,1A,6D,98,..,EE,FD,68,F6 ; AES-CCM (ori): [mac+0..0Fh] = FD,F9,FE,85,..,4F,50,3C,AF ; AES-CCM (DSi): [mac+0..0Fh] = xx,xx,xx,xx,..,xx,xx,xx,xx ;/ AES-ECB: [dta+0..113Fh] = 0E,69,F5,1A,..,9A,5F,7A,9A ;-keysize=192 AES-ECB: [dta+0..113Fh] = C6,FB,68,C1,..,14,89,6C,E0 ;-keysize=256 |
| DSi ES Block Encryption |
FAT16:\sys\dev.kp FAT16:\ticket\000300tt\4ggggggg.tik (tickets) SD Card: .bin files (aka Tad Files) (contains multiple blocks) .twl-*.der files (within the "verdata" NARC file) |
00000h BLKLEN Data Block (AES-CCM encrypted) BLKLEN+00h 10h Data Checksum (AES-CCM MAC value on above Data) BLKLEN+10h 1 Fixed 3Ah (AES-CTR encrypted) BLKLEN+11h 0Ch Nonce (unencrypted) BLKLEN+1Dh 1 BLKLEN.bit16-23 (AES-CTR encrypted) BLKLEN+1Eh 1 BLKLEN.bit8-15 (AES-CTR encrypted) BLKLEN+1Fh 1 BLKLEN.bit0-7 (AES-CTR encrypted) |
IV[00h..0Bh]=[BLKLEN+11h..1Ch] ;Nonce IV[0Ch..0Fh]=Don't care (not used for CCM) |
00000h BLKLEN Data Block (AES-CCM) |
IV[00h..02h]=offset/10h + 1 ;CTR value for desired 16-byte block IV[03h..0Eh]=[BLKLEN+11h..1Ch] ;Nonce for CTR IV[0Fh]=02h ;Indicate 3-byte wide CTR (fixed on DSi) |
IV[00h..02h]=BLKLEN/10h + 1 ;CTR value for last 16-byte block IV[03h..0Eh]=[BLKLEN+11h..1Ch] ;Nonce IV[0Fh]=02h ;Indicate 3-byte wide CTR (fixed on DSi) |
IV[00h]=00h ;Zero IV[01h..0Ch]=[BLKLEN+11h..1Ch] ;Nonce IV[0Dh..0Fh]=00h,00h,00h ;Zero |
BLKLEN+10h 1 Fixed 3Ah (AES-CTR encrypted) BLKLEN+11h 0Ch Nonce (unencrypted) BLKLEN+1Dh 1 BLKLEN.bit16-23 (AES-CTR encrypted) BLKLEN+1Eh 1 BLKLEN.bit8-15 (AES-CTR encrypted) BLKLEN+1Fh 1 BLKLEN.bit0-7 (AES-CTR encrypted) |
BLKLEN+10h 1 Fixed 3Ah (unencrypted) (to be verified) BLKLEN+11h 0Ch Nonce (AES-CTR encrypted) (useless/garbage) BLKLEN+1Dh 1 BLKLEN.bit16-23 (unencrypted) (to be verified) BLKLEN+1Eh 1 BLKLEN.bit8-15 (unencrypted) (to be verified) BLKLEN+1Fh 1 BLKLEN.bit0-7 (unencrypted) (to be verified) |
| DSi Cartridge Header |
012h 1 Unitcode (00h=NDS, 02h=NDS+DSi, 03h=DSi) (bit1=DSi)
01Ch 1 NDS:Reserved, DSi:Flags (03h=Normal, 0Bh=Sys, 0Fh=Debug/Sys)
bit0 Has TWL-Exclusive Region ;MUST be 1 for DSi titles?
bit1 Modcrypted (0=No, 1=Yes, see [220h..22Fh])
bit2 Modcrypt key select (0=Retail, 1=Debug)
bit3 Disable Debug ?
01Dh 1 NDS:Region, DSi:Permit jump (00h=Normal, 01h=System Settings)
bit0 jump (always include title at [2FFD800h..])
bit1 tmpjump (?)
068h 4 Icon/Title offset (same as NDS, but with new extra entries)
080h 4 Total Used ROM size, EXCLUDING DSi area
088h 4 NDS:Unknown, DSi:ARM9 Parameters Table Offset ??? ;base=[028h]
08Ch 4 NDS:Reserved, DSi:ARM7 Parameters Table Offset ??? ;base=[038h]
090h 2 NDS:Reserved, DSi:NTR ROM Region End/80000h ;\usually both same
092h 2 NDS:Reserved, DSi:TWL ROM Region Start/80000h ;/(zero for DSiware)
|
(012h)1 Unitcode (must be 00h for non-DSi carts) (020h)16 Changed ARM9/ARM7 areas (DSi-in-NDS-mode more restricted than NDS) 088h 4 Unknown (B8h,4Bh,00h,00h) (similar as in DSi carts) 1BFh 1 Flags (40h=RSA+TwoHMACs, 60h=RSA+ThreeHMACs) 33Ch 14 HMAC for Icon/Title (only if [1BFh]=60h) ;as Whitelist Phase 3 378h 14 HMAC for 160h-byte header and ARM9+ARM7 areas ;as Whitelist Phase 1 38Ch 14 HMAC for OverlayARM9+NitroFAT (zero if no overlay) ;as Phase 2 F80h 128 RSA signature |
ARM9 2004000h..227FFFFh (siz=27C000h) (for NDS mode: 2000000h and up) ARM7 2380000h..23BFFFFh (siz=40000h) ARM9i 2400000h..267FFFFh (siz=280000h) ARM7i 2E80000h..2F87FFFh (siz=108000h) |
Main 2000000h..2FFC000h (excluding bootstrap at 23FEE00h..23FF000h) WRAM 3000000h..380F000h (excluding bootstrap at 3FFF600h..3FFF800h) |
180h 20 Global MBK1..MBK5 Settings, WRAM Slots
194h 12 Local MBK6..MBK8 Settings, WRAM Areas for ARM9
1A0h 12 Local MBK6..MBK8 Settings, WRAM Areas for ARM7
1ACh 3 Global MBK9 Setting, WRAM Slot Write Protect
1AFh 1 Global WRAMCNT Setting (usually 03h) (FCh/00h in SysMenu/Settings)
1B0h 4 Region flags (bit0=JPN, bit1=USA, bit2=EUR, bit3=AUS, bit4=CHN,
bit5=KOR, bit6-31=Reserved) (FFFFFFFFh=Region Free)
1B4h 4 Access control (AES Key Select)
bit0 Common Client Key ;want 380F000h=3FFC600h+00h "common key"
bit1 AES Slot B ;380F010h=3FFC400h+180h and KEY1=unchanged
bit2 AES Slot C ;380F020h=3FFC400h+190h and KEY2.Y=3FFC400h+1A0h
bit3 SD Card ;want Device I
bit4 NAND Access ;want Device A-H and KEY3=intact
bit5 Game Card Power On ;tested with bit8
bit6 Shared2 File ;used... but WHAT for?
bit7 Sign JPEG For Launcher (AES Slot B);select 1 of 2 jpeg keys?
bit8 Game Card NTR Mode ;tested with bit5
bit9 SSL Client Cert (AES Slot A) ;KEY0=3FFC600h+30h (twl-*.der)
bit10 Sign JPEG For User (AES Slot B) ;\
bit11 Photo Read Access ; seems to be unused
bit12 Photo Write Access ; (and, usually ZERO,
bit13 SD Card Read Access ; even if the stuff is
bit14 SD Card Write Access ; accessed)
bit15 Game Card Save Read Access ; (bit11 set in flipnote)
bit16 Game Card Save Write Access ;/
bit31 Debugger Common Client Key ;want 380F000h=3FFC600h+10h
1B8h 4 ARM7 SCFG_EXT7 setting (bit0,1,2,10,18,31)
1BCh 3 Reserved/flags? (zerofilled)
1BFh 1 Flags (usually 01h) (DSiware Browser: 0Bh)
bit0: TSC Touchscreen/Sound Controller Mode (0=NDS, 1=DSi)
bit1: Require EULA Agreement (see hdr[20Eh] for version)
bit2: Custom Icon (0=No/Normal, 1=Use banner.sav)
bit3: Show Nintendo Wi-Fi Connection icon in Launcher
bit4: Show DS Wireless icon in Launcher
bit5: NDS cart with icon SHA1 (DSi firmware v1.4 and up)
bit6: NDS cart with header RSA (DSi firmware v1.0 and up)
bit7: Developer App
1C0h 4 ARM9i ROM Offset (usually XX03000h, XX=1MB-boundary after NDS area)
1C4h 4 Reserved (zero)
1C8h 4 ARM9i RAM Load address
1CCh 4 ARM9i Size
1D0h 4 ARM7i ROM Offset
1D4h 4 SD/MMC Device List ARM7 RAM Addr; 400h-byte initialized by firmware
1D8h 4 ARM7i RAM Load address
1DCh 4 ARM7i Size
1E0h 4 Digest NTR region offset (usually same as ARM9 rom offs, 0004000h)
1E4h 4 Digest NTR region length
1E8h 4 Digest TWL region offset (usually same as ARM9i rom offs, XX03000h)
1ECh 4 Digest TWL region length
1F0h 4 Digest Sector Hashtable offset ;\SHA1-HMAC's on all sectors
1F4h 4 Digest Sector Hashtable length ;/in above NTR+TWL regions
1F8h 4 Digest Block Hashtable offset ;\SHA1-HMAC's on each N entries
1FCh 4 Digest Block Hashtable length ;/in above Sector Hashtable
200h 4 Digest Sector size (eg. 400h bytes per sector)
204h 4 Digest Block sectorcount (eg. 20h sectors per block)
208h 4 Icon/Title size (usually 23C0h for DSi) (older 840h-byte works too)
20Ch 1 SD/MMC size of "shared2\0000" file in 32Kbyte units? (dsi sound)
20Dh 1 SD/MMC size of "shared2\0001" file in 32Kbyte units?
;or are shared2 sizes rather counted in 16Kbyte cluster units?
20Eh 1 EULA Version (01h) ? ;used when hdr[1BFh].bit1=1 !
20Fh 1 Use Ratings (00h) ? !
210h 4 Total Used ROM size, INCLUDING DSi area (optional, can be 0)
214h 1 SD/MMC size of "shared2\0002" file in 32Kbyte units?
215h 1 SD/MMC size of "shared2\0003" file in 32Kbyte units?
216h 1 SD/MMC size of "shared2\0004" file in 32Kbyte units?
217h 1 SD/MMC size of "shared2\0005" file in 32Kbyte units?
218h 4 ARM9i Parameters Table Offset (84 D0 04 00) ??? ;base=[028h]
21Ch 4 ARM7i Parameters Table Offset (2C 05 00 00) ??? ;base=[038h]
220h 4 Modcrypt area 1 offset ;usually same as ARM9i rom offs (XX03000h)
224h 4 Modcrypt area 1 size ;usually min(4000h,ARM9iSize+Fh AND not Fh)
228h 4 Modcrypt area 2 offset (0=None)
22Ch 4 Modcrypt area 2 size (0=None)
230h 4 Title ID, Emagcode (aka Gamecode spelled backwards)
234h 1 Title ID, Filetype (00h=Cartridge, 04h=DSiware, 05h=System Fun
Tools, [0Fh=Non-executable datafile without cart header],
15h=System Base Tools, 17h=System Menu)
235h 1 Title ID, Zero (00h=Normal)
236h 1 Title ID, Three (03h=DSi) (as opposed to Wii or 3DS)
237h 1 Title ID, Zero (00h=Normal)
238h 4 SD/MMC (DSiware) "public.sav" filesize in bytes (0=none)
23Ch 4 SD/MMC (DSiware) "private.sav" filesize in bytes (0=none)
240h 176 Reserved (zero-filled)
|
2F0h 10h Parental Control Age Ratings (for different countries/areas)
Bit7: Rating exists for local country/area
Bit6: Game is prohibited in local country/area?
Bit5: Unused
Bit4-0: Age rating for local country/area (years)
2F0h 1 CERO (Japan) (0=None/A, 12=B, 15=C, 17=D, 18=Z)
2F1h 1 ESRB (US/Canada) (0=None, 3=EC, 6=E, 10=E10+, 13=T, 17=M)
2F2h 1 Reserved (0=None)
2F3h 1 USK (Germany) (0=None, 6=6+, 12=12+, 16=16+, 18=18+)
2F4h 1 PEGI (Pan-Europe) (0=None, 3=3+, 7=7+, 12=12+, 16=16+, 18=18+)
2F5h 1 Reserved (0=None)
2F6h 1 PEGI (Portugal) (0=None, 4=4+, 6=6+, 12=12+, 16=16+, 18=18+)
2F7h 1 PEGI and BBFC (UK) (0=None, 3, 4=4+/U, 7, 8=8+/PG, 12, 15, 16, 18)
2F8h 1 AGCB (Australia) (0=None/G, 7=PG, 14=M, 15=MA15+, plus 18=R18+?)
2F9h 1 GRB (South Korea) (0=None, 12=12+, 15=15+, 18=18+) (aka "BG"?)
2FAh 6 Reserved (6x) (0=None)
? ? OFLC (NZ) (unknown, exists in DSi System Settings rom:layout\cmn)
N/A? - DEJUS (Brazil) (L, 10, 12, 14, 16, 18)
N/A? - GSRMR (Taiwan) (formerly CSRR) (0,6,12,18) (and GSRMR: 15)
N/A? - PEGI (Finland) (discontinued 2007, shortly before DSi launch)
bit0-4 Rating (0..18)
bit6 Pending
bit7 Enabled
|
300h 20 SHA1-HMAC hash ARM9 (with encrypted secure area) ;[020h,02Ch]
314h 20 SHA1-HMAC hash ARM7 ;[030h,03Ch]
328h 20 SHA1-HMAC hash Digest master ;[1F8h,1FCh]
33Ch 20 SHA1-HMAC hash Icon/Title (also in newer NDS titles) ;[068h,208h]
350h 20 SHA1-HMAC hash ARM9i (decrypted) ;[1C0h,1CCh]
364h 20 SHA1-HMAC hash ARM7i (decrypted) ;[1D0h,1DCh]
378h 20 Reserved (zero-filled) (but used for non-whitelisted NDS titles)
38Ch 20 Reserved (zero-filled) (but used for non-whitelisted NDS titles)
3A0h 20 SHA1-HMAC hash ARM9 (without 16Kbyte secure area) ;[020h,02Ch]
3B4h 2636 Reserved (zero-filled)
E00h 180h Reserved and unchecked region, always zero. Used for passing
arguments in debug environment.
F80h 80h RSA-SHA1 signature across header entries [000h..DFFh]
|
1000h..3FFFh Non-Load area in ROMs... but contains sth in DSiWare files!?! |
No need for NDS backwards compatibility (since DSiware is DSi only) Entry 3A0h can be zero-filled (in LAUNCHER) |
Modcrypt Area 1 IV[0..F]: First 16 bytes of the ARM9 SHA1-HMAC [300h..30Fh] Modcrypt Area 2 IV[0..F]: First 16 bytes of the ARM7 SHA1-HMAC [314h..323h] |
IF header[01Ch].Bit1=0
None (modcrypt disabled)
ELSEIF header[01Ch].Bit2 OR header[1BFh].Bit7 THEN (probably for prototypes)
Debug KEY[0..F]: First 16 bytes of the header [000h..00Fh]
ELSE (commonly used for retail software)
Retail KEY_X[0..7]: Fixed 8-byte ASCII string ("Nintendo")
Retail KEY_X[8..B]: The 4-byte gamecode, forwards [00Ch..00Fh]
Retail KEY_X[C..F]: The 4-byte gamecode, backwards [00Fh..00Ch]
Retail KEY_Y[0..F]: First 16 bytes of the ARM9i SHA1-HMAC [350h..35Fh]
|
| DSi Touchscreen/Sound Controller |
| DSi Touchscreen Access |
0 Direction for following data bytes (0=Write, 1=Read) 1-7 INDEX (00h..7Fh) for following data bytes (auto-increasing) |
TSC[00h]=PAGE ;<-- change page (at INDEX=0) TSC[PAGE:INDEX] ;<-- access registers in select page |
if (TSC[3:09h] AND 40h)<>0 then return(not_pressed) ;ADC Ready Flag if (TSC[3:0Eh] AND 03h)<>0 then return(not_pressed) ;Undocumented Flags? return(pressed) |
touchdata[0..19] = TSC[FCh:01h..14h] ;read page FCh, index(1..20)
rawx=0, rawy=0
for i=0 to 8 step 2
x = touchdata[i+0]*100h+touchdata[i+1]
y = touchdata[i+10]*100h+touchdata[i+11]
if (x or y) and F000h then return(not_pressed)
rawx=rawx+x, rawy=rawy+y
return(rawx/5, rawy/5)
|
0-11 Coordinate (0..FFFh) (usually 000h when not pressed) 12-14 State (0=Pressed, 7=Released) (or sometimes also 1 or 3=Released) 15 State Changed (0=No, 1=Newly pressed/released; cleared after read) |
| DSi Touchscreen/Sound Init Flowcharts |
TSC[3:0Eh]=00h ;Undoc (RMW: bit7=0) TSC[3:02h]=18h ;SAR ADC clk divider, Div8 (12bit mode) (RMW bit34=3, bit7=?) TSC[3:0Fh]=A0h ;Scan Mode Timer TSC[3:0Eh].28h ;Undoc (RNW: bit345=5) TSC[3:0Eh].28h ;Undoc (RMW: bit6=0) TSC[3:03h]=87h ;SAR ADC Control 2 (SelfByPenDown, ScanXY, /PENIRQ) TSC[3:05h].04h ;Stabilization time = 30us (RMW bit012=4) TSC[3:04h].02h ;Sense time = 3us (RMW bit012=2) TSC[3:04h].22h ;Precharge time = 3us (RMW bit456=2) TSC[3:12h].00h ;Debounce Time = 0us (RMW bit012=0) TSC[3:0Eh].A8h ;Undoc (RMW bit7=1) |
TSC[1:2Eh]=03h ;MICBIAS=AVDD TSC[0:51h]=80h ;ADC Digital Mic, on TSC[0:52h]=00h ;ADC Digital Volume Control Fine Adjust, unmute TSC[1:2Fh]=37h ;MIC PGA=27.5dB (or use other value, if desired) |
TSC[0:52h]=80h ;ADC Digital Volume Control Fine Adjust, mute TSC[0:51h]=00h ;ADC Digital Mic, off TSC[1:2Eh]=00h ;MICBIAS=Off |
TSC[0:01h]=01h ;Software Reset TSC[0:39h]=66h ;ADC DC Measurement 1 TSC[1:20h]=16h ;Class-D Speaker Amplifier (RMW:bit4=1) TSC[0:04h]=00h ;Clock-Gen Muxing TSC[0:12h]=81h ;ADC NADC Value TSC[0:13h]=82h ;ADC MADC Value TSC[0:51h]=82h ;ADC Digital Mic TSC[0:51h]=00h ;ADC Digital Mic again TSC[0:04h]=03h ;Clock-Gen Muxing TSC[0:05h]=A1h ;PLL P and R-Values TSC[0:06h]=15h ;PLL J-Value TSC[0:0Bh]=87h ;DAC NDAC Value TSC[0:0Ch]=83h ;DAC MDAC Value TSC[0:12h]=87h ;ADC NADC Value TSC[0:13h]=83h ;ADC MADC Value TSC[3:10h]=88h ;Scan Mode Timer Clock (RMW:bit0-6) TSC[4:08h..0Dh]=7Fh,E1h,80h,1Fh,7Fh,C1h ;some coeff's TSC[0:41h]=08h ;DAC Left Volume Control TSC[0:42h]=08h ;DAC Right Volume Control TSC[0:3Ah]=00h ;GPI3 Pin Control TSC[4:08h..0Dh]=7Fh,E1h,80h,1Fh,7Fh,C1h ;some coeff's ;again? TSC[1:2Fh]=2Bh ;MIC PGA TSC[1:30h]=40h ;P-Terminal Delta-Sigma Mono ADC Channel Fine-Gain Input TSC[1:31h]=40h ;M-Terminal ADC Input Selection TSC[1:32h]=60h ;Input CM Settings TSC[0:74h]=82h ;VOL/MICDET-Pin SAR ADC - Volume Control (RMW) TSC[0:74h]=92h ;VOL/MICDET-Pin SAR ADC - Volume Control (RMW) TSC[0:74h]=D2h ;VOL/MICDET-Pin SAR ADC - Volume Control (RMW) TSC[1:21h]=20h ;HP Output Drivers POP Removal Settings TSC[1:22h]=F0h ;Output Driver PGA Ramp-Down Period Control TSC[0:3Fh]=D4h ;DAC Data-Path Setup (RMW) TSC[1:23h]=44h ;DAC_L and DAC_R Output Mixer Routing TSC[1:1Fh]=D4h ;Headphone Drivers TSC[1:28h]=4Eh ;HPL Driver (Left Headphone) TSC[1:29h]=4Eh ;HPR Driver (Right Headphone) TSC[1:24h]=9Eh ;Analog Volume to HPL (Left Headphone) TSC[1:25h]=9Eh ;Analog Volume to HPR (Right Headphone) TSC[1:20h]=D4h ;Class-D Speaker Amplifier TSC[1:2Ah]=14h ;SPL Driver (Left Speaker) TSC[1:2Bh]=14h ;SPR Driver (Right Speaker) TSC[1:26h]=A7h ;Analog Volume to SPL (Left Speaker) TSC[1:27h]=A7h ;Analog Volume to SPR (Right Speaker) TSC[0:40h]=00h ;DAC Volume Control (should set DSi.GPIO.data.bit7 here, but can be also done elsewhere) TSC[0:3Ah]=60h ;GPI3 Pin Control |
TSC[1:26h]=ACh ;\special setting (when found special gamecode) TSC[1:27h]=ACh ;/ TSC[1:26h]=A7h ;\normal setting (for any other gamecodes) TSC[1:27h]=A7h ;/ TSC[1:2Eh]=03h ;MICBIAS=AVDD TSC[3:03h]=00h ;SAR ADC Control 2 TSC[1:21h]=20h ;HP Output Drivers POP Removal Settings TSC[1:22h]=F0h ;Output Driver PGA Ramp-Down Period Control (70h OR 80h) TSC[1:22h]=70h ;Output Driver PGA Ramp-Down Period Control (bit7=0) TSC[0:52h]=80h ;ADC Digital Volume Control Fine Adjust TSC[0:51h]=00h ;ADC Digital Mic READ[3:02h] (returns 00h) TSC[3:02h].Bit7=1 ;SAR ADC Control 1 (set to 80h) (or 98h?) (RMW) TSC[FFh:05h]=00h ;TSC final enter NDS mode |
| DSi TSC, Register Summary |
7bit index: selected via the first SPI byte, with direction flag in bit0 8bit page: selected by writing to index 00h, ie. to TSC[xxh:00h] |
TSC[xxh:00h] - Page Select Register (00h) |
TSC[0:01h] - Software Reset (00h) TSC[0:02h] - Reserved (xxh) (R) TSC[0:03h] - Overtemperature OT Flag (02h..FFh) (R) TSC[0:04h] - Clock-Gen Muxing (00h) TSC[0:05h] - PLL P and R-Values (11h) TSC[0:06h] - PLL J-Value (04h) TSC[0:07h,08h] - PLL D-Value MSB,LSB (0000h) TSC[0:09h,0Ah] - Reserved (xxh) TSC[0:0Bh] - DAC NDAC Value (01h) TSC[0:0Ch] - DAC MDAC Value (01h) TSC[0:0Dh,0Eh] - DAC DOSR Value MSB,LSB (0080h) TSC[0:0Fh] - DAC IDAC Value (80h) TSC[0:10h] - DAC miniDSP Engine Interpolation (08h) TSC[0:11h] - Reserved (xxh) TSC[0:12h] - ADC NADC Value (01h) TSC[0:13h] - ADC MADC Value (01h) TSC[0:14h] - ADC AOSR Value (80h) TSC[0:15h] - ADC IADC Value (80h) TSC[0:16h] - ADC miniDSP Engine Decimation (04h) TSC[0:17h,18h] - Reserved (xxh) TSC[0:19h] - CLKOUT MUX (00h) TSC[0:1Ah] - CLKOUT Divider M Value (01h) |
TSC[0:1Bh] - Codec Interface Control 1 (00h) (R/W) TSC[0:1Ch] - Data-Slot Offset Programmability (00h) TSC[0:1Dh] - Codec Interface Control 2 (00h) TSC[0:1Eh] - BCLK Divider N Value (01h) TSC[0:1Fh] - Codec Secondary Interface Control 1 (00h) TSC[0:20h] - Codec Secondary Interface Control 2 (00h) TSC[0:21h] - Codec Secondary Interface Control 3 (00h) TSC[0:22h] - I2C Bus Condition (00h) TSC[0:23h] - Reserved (xxh) |
TSC[0:24h] - ADC Flag Register (0xh) (R) TSC[0:25h] - DAC Flag Register (00h) (R) TSC[0:26h] - DAC Flag Register (00h) (R) TSC[0:27h] - Overflow Flags (00h) (R) TSC[0:28h..2Bh] - Reserved (xxh) TSC[0:2Ch] - Interrupt Flags DAC, sticky (00h..30h) (R) TSC[0:2Dh] - Interrupt Flags ADC, sticky (00h..18h) (R) TSC[0:2Eh] - Interrupt Flags DAC, non-sticky? (00h..30h) (R) TSC[0:2Fh] - Interrupt Flags ADC, non-sticky? (00h..18h) (R) TSC[0:30h] - INT1 Control Register (Select INT1 Sources) (00h) TSC[0:31h] - INT2 Control Register (Select INT2 Sources) (00h) TSC[0:32h] - INT1 and INT2 Control Register (00h) |
TSC[0:33h] - GPIO1 In/Out Pin Control (00h..C2h) TSC[0:34h] - GPIO2 In/Out Pin Control (00h..C2h) TSC[0:35h] - SDOUT (OUT Pin) Control (12h) TSC[0:36h] - SDIN (IN Pin) Control (02h or 03h) TSC[0:37h] - MISO (OUT Pin) Control (02h) TSC[0:38h] - SCLK (IN Pin) Control (02h..03h) TSC[0:39h] - GPI1 and GPI2 Pin Control (00h..11h) TSC[0:3Ah] - GPI3 Pin Control (00h..10h) TSC[0:3Bh] - Reserved (xxh) |
TSC[0:3Ch] - DAC Instruction Set (01h) TSC[0:3Dh] - ADC Instruction Set (04h) TSC[0:3Eh] - Programmable Instruction Mode-Control Bits (00h) TSC[0:3Fh] - DAC Data-Path Setup (14h) TSC[0:40h] - DAC Volume Control (0Ch) TSC[0:41h] - DAC Left Volume Control (00h) TSC[0:42h] - DAC Right Volume Control (00h) TSC[0:43h] - Headset Detection (00h..60h) TSC[0:44h] - DRC Control 1 (0Fh) TSC[0:45h] - DRC Control 2 (38h) TSC[0:46h] - DRC Control 3 (00h) TSC[0:47h] - Beep Generator and Left Beep Volume (00h) TSC[0:48h] - Beep Generator and Right Beep Volume (00h) TSC[0:49h,4Ah,4Bh] - Beep Length MSB,MID,LSB (0000EEh) TSC[0:4Ch,4Dh] - Beep Frequency Sin(x) MSB,LSB (10D8h) TSC[0:4Eh,4Fh] - Beep Frequency Cos(x) MSB,LSB (7EE3h) TSC[0:50h] - Reserved (xxh) TSC[0:51h] - ADC Digital Mic (00h) TSC[0:52h] - ADC Digital Volume Control Fine Adjust (80h) TSC[0:53h] - ADC Digital Volume Control Coarse Adjust (00h) TSC[0:54h,55h] - Reserved (xxh) |
TSC[0:56h] - AGC Control 1 (00h) TSC[0:57h] - AGC Control 2 (00h) TSC[0:58h] - AGC Maximum Gain (7Fh, uh that's 7Fh=Reserved?) TSC[0:59h] - AGC Attack Time (00h) TSC[0:5Ah] - AGC Decay Time (00h) TSC[0:5Bh] - AGC Noise Debounce (00h) TSC[0:5Ch] - AGC Signal Debounce (00h) TSC[0:5Dh] - AGC Gain-Applied Reading (xxh) (R) TSC[0:5Eh...65h] - Reserved (xxh) TSC[0:66h] - ADC DC Measurement 1 (00h) TSC[0:67h] - ADC DC Measurement 2 (00h) TSC[0:68h,69h,6Ah] - ADC DC Measurement Output MSB,MID,LSB (R) (000000h) TSC[0:6Bh...73h] - Reserved (xxh) TSC[0:74h] - VOL/MICDET-Pin SAR ADC - Volume Control (00h) TSC[0:75h] - VOL/MICDET-Pin Gain (xxh) (R) TSC[0:76h...7Fh] - Reserved (xxh) |
TSC[1:01h..1Dh] - Reserved (xxh) TSC[1:1Eh] - Headphone and Speaker Amplifier Error Control (00h) TSC[1:1Fh] - Headphone Drivers (04h) TSC[1:20h] - Class-D Speaker Amplifier (06h) TSC[1:21h] - HP Output Drivers POP Removal Settings (3Eh) TSC[1:22h] - Output Driver PGA Ramp-Down Period Control (00h) TSC[1:23h] - DAC_L and DAC_R Output Mixer Routing (00h) TSC[1:24h] - Analog Volume to HPL (Left Headphone) (7Fh) TSC[1:25h] - Analog Volume to HPR (Right Headphone) (7Fh) TSC[1:26h] - Analog Volume to SPL (Left Speaker) (7Fh) TSC[1:27h] - Analog Volume to SPR (Right Speaker) (7Fh) TSC[1:28h] - HPL Driver (Left Headphone) (02h) TSC[1:29h] - HPR Driver (Right Headphone) (02h) TSC[1:2Ah] - SPL Driver (Left Speaker) (00h) TSC[1:2Bh] - SPR Driver (Right Speaker) (00h) TSC[1:2Ch] - HP Driver Control (00h) TSC[1:2Dh] - Reserved (xxh) TSC[1:2Eh] - MICBIAS (00h) TSC[1:2Fh] - MIC PGA (80h) TSC[1:30h] - P-Terminal Delta-Sigma Mono ADC Channel Fine-Gain Input (00h) TSC[1:31h] - M-Terminal ADC Input Selection (00h) TSC[1:32h] - Input CM Settings (00h) TSC[1:33h..FFh] - Reserved (xxh) |
TSC[2:01h..FFh] - Reserved (00h) |
TSC[3:01h] - Reserved (xxh) TSC[3:02h] - SAR ADC Control 1 (00h) TSC[3:03h] - SAR ADC Control 2 (00h) TSC[3:04h] - Precharge and Sense (00h) TSC[3:05h] - Panel Voltage Stabilization (00h) TSC[3:06h] - Voltage Reference (20h) TSC[3:07h,08h] - Reserved (xxh) TSC[3:09h] - Status Bits 1 (40h) (R) TSC[3:0Ah] - Status Bits 2 (00h) (R) TSC[3:0Bh,0Ch] - Reserved (xxh) TSC[3:0Dh] - Buffer Mode (03h) ;DSi: Unused,seems to use TSC[3:0Eh] instead TSC[3:0Eh] - Reserved / Undocumented (read by DSi for Pen Down Test) (0Fh) TSC[3:0Fh] - Scan Mode Timer (40h) TSC[3:10h] - Scan Mode Timer Clock (81h) TSC[3:11h] - SAR ADC Clock (81h) TSC[3:12h] - Debounce Time for Pen-Up Detection (00h) TSC[3:13h] - Auto AUX Measurement Selection (00h) TSC[3:14h] - Touch-Screen Pen Down (00h) TSC[3:15h] - Threshold Check Flags Register (00h) (R) TSC[3:16h,17h] - AUX1 Maximum Value Check MSB,LSB (0000h) TSC[3:18h,19h] - AUX1 Minimum Value Check MSB,LSB (0000h) TSC[3:1Ah,1Bh] - AUX2 Maximum Value Check MSB,LSB (0000h) TSC[3:1Ch,1Dh] - AUX2 Minimum Value Check MSB,LSB (0000h) TSC[3:1Eh,1Fh] - Temperature(TEMP1/TEMP2) Maximum Value Check MSB,LSB (0000h) TSC[3:20h,21h] - Temperature(TEMP1/TEMP2) Minimum Value Check MSB,LSB (0000h) TSC[3:22h...29h] - Reserved (xxh) TSC[3:2Ah,2Bh] - Touchscreen X-Coordinate Data MSB,LSB (0000h) (R) TSC[3:2Ch,2Dh] - Touchscreen Y-Coordinate Data MSB,LSB (0000h) (R) TSC[3:2Eh,2Fh] - Touchscreen Z1-Pressure Register MSB,LSB (0000h) (R) TSC[3:30h,31h] - Touchscreen Z2-Pressure Register MSB,LSB (0000h) (R) TSC[3:32h...35h] - Reserved (xxh) TSC[3:36h,37h] - AUX1 Data MSB,LSB (0000h) (R) TSC[3:38h,39h] - AUX2 Data MSB,LSB (0000h) (R) TSC[3:3Ah,3Bh] - VBAT Data MSB,LSB (0000h) (R) TSC[3:3Ch...41h] - Reserved (xxh) TSC[3:42h,43h] - Temperature TEMP1 Data Register MSB,LSB (0000h) (R) TSC[3:44h,45h] - Temperature TEMP2 Data Register MSB,LSB (0000h) (R) TSC[3:46h...7Fh] - Reserved (xxh) |
TSC[04h..05h:xxh] - ADC Coefficient RAM (126 x 16bit) TSC[06h..07h:xxh] - Reserved (00h) TSC[08h:01h] - DAC Coefficient RAM Control (00h) TSC[08h..0Bh:xxh] - DAC Coefficient RAM, DAC Buffer A (252 x 16bit) TSC[0Ch..0Fh:xxh] - DAC Coefficient RAM, DAC Buffer B (252 x 16bit) TSC[10h..1Fh:xxh] - Reserved (00h) TSC[20h..2Bh:xxh] - ADC DSP Engine Instruction RAM (384 x 24bit) TSC[2Ch..3Fh:xxh] - Reserved (00h) TSC[40h..5Fh:xxh] - DAC DSP Engine Instruction RAM (1024 x 24bit) TSC[60h..FBh:xxh] - Reserved (00h) |
TSC[64h:01h..xxh] - 3DS Config Registers for Sound (and Microphone?) TSC[65h:01h..xxh] - 3DS Config Registers for Sound (and Microphone?) TSC[67h:01h..xxh] - 3DS Config Registers for Touchscreen and Circle Pad TSC[FBh:01h..xxh] - 3DS Buffer Mode Data for Touchscreen and Circle Pad |
TSC[FCh:01h..xxh] - Buffer Mode Data MSB,LSB (xxxxh) (R) TSC[FCh:xxh..7Fh] - Reserved (xxh) |
TSC[FDh:xxh] - Contains some undocumented non-zero values (DSi specific?) TSC[FEh:xxh] - Reserved (00h) TSC[FFh:xxh] - Accessing this page changes operation (DSi specific?) |
| DSi TSC[0:00h..1Ah], Basic PLL and Timing Control |
7-0 Page Select (00h..FEh) (FFh=Undocumented, enter special mode?) |
7-1 Reserved. Write only zeros to these bits. 0 Software Reset (0=No change, 1=Reset) |
7-0 Reserved. Do not write to this register. |
7-2 Reserved. Do not write to these bits. (R) 1 Overtemperature protection flag (0=Alert, 1=Normal) (R) 0 Reserved. Do not write to these bits. (R/W?) |
Old3DS = 16h New3DS XL = 36h |
7-4 Reserved. Write only zeros to these bits. 3-2 Select PLL_CLKIN (0=MCLK, 1=BCLK, 2=GPIO1, 3=SDIN) 1-0 Select CODEC_CLKIN (0=MCLK, 1=BCLK, 2=GPIO1, 3=PLL_CLK) |
7 PLL Enable (0=Power down, 1=Power up) 6-4 PLL Divider P (1..7=Div1..7, or 0=Div8) 3-0 PLL Multiplier R (1..15=Mul1..15, or 0=Mul16) |
7-6 Reserved. Write only zeros to these bits. 5-0 PLL Multiplier J (1..63=Mul1..63, or 0=Reserved) |
15-14 Reserved. Write only zeros to these bits. 13-0 PLL fractional multiplier D-Val (14bit) |
7-0 Reserved. Write only zeros to these bits. |
7 DAC NDAC Divider Enable (0=Power down, 1=Power up) 6-0 DAC NDAC Divider (1..127=Div1..127, or 0=Div128) |
7 DAC MDAC Divider Enable (0=Power down, 1=Power up) 6-0 DAC MDAC Divider (1..127=Div1..127, or 0=Div128) |
15-10 Reserved 9-0 DAC OSR value "DOSR" (1..1023, or 0=1024) |
7-0 Number of instructions for DAC miniDSP engine (IDAC=N*4)
(1..255 = 4..1020 (N*4), or 0=1024)
|
7-4 Reserved. Do not write to these registers. 3-0 Interpolation ratio in DAC miniDSP engine (1..15, or 0=16) |
7-0 Reserved. Do not write to this register. |
7 ADC NADC divider is powered
0: ADC NADC divider is powered down and ADC_DSP_CLK = DAC_DSP_CLK.
1: ADC NADC divider is powered up.
6-0 ADC NADC divider (1..127, or 0=128)
|
7 ADC MADC divider is powered
0: ADC MADC divider is powered down and ADC_MOD_CLK = DAC_MOD_CLK.
1: ADC MADC divider is powered up.
6-0 ADC MADC divider (1..127, or 0=128)
|
7-0 ADC OSR "AOSR" divider (1..255, or 0=256) |
7-0 Number of instruction for ADC miniDSP engine (IADC=N*2)
(1..192 = 2..384 (N*2), or 0,193..255=Reserved)
|
7-4 Reserved 3-0 Decimation ratio in ADC miniDSP engine (1..15, or 0=16) |
7-0 Reserved. Do not write to these registers. |
7-3 Reserved
2-0 CDIV_CLKIN (0=MCLK, 1=BCLK, 2=SDIN, 3=PLL_CLK, 4=DAC_CLK(DSP),
5=DAC_MOD_CLK, 6=ADC_CLK(DSP), 7=ADC_MOD_CLK)
|
7 CLKOUT divider M Enable (0=Powered down, 1=Powered up) 6-0 CLKOUT divider M (1..127, or 0=128) |
| DSi TSC[0:1Bh..23h], Codec Control |
7-6 Codec interface type (0=I2S, 1=DSP, 2=RJF, 3=LJF)
5-4 Codec interface word length (0..3=16,20,24,32 bits)
3 BCLK Direction (0=Input, 1=Output)
2 WCLK Direction (0=Input, 1=Output)
1 Reserved
0 Driving SDOUT to High-Impedance for the Extra BCLK cycle when
data is not being transferred (0=Disabled, 1=Enabled)
|
7-0 Offset (0..255 = 0..255 BCLKs) |
7-6 Reserved 5 SDIN-to-SDOUT loopback (0=Disable, 1=Enable) 4 ADC-to-DAC loopback (0=Disable, 1=Enable) 3 BCLK Invert (0=No, 1=Invert) 2 BCLK and WCLK active even with Codec powered down (0=No, 1=Yes) 1-0 BDIV_CLKIN (0=DAC_CLK, 1=DAC_MOD_CLK, 2=ADC_CLK, 3=ADC_MOD_CLK) |
7 BCLK divider N Enable (0=Powered down, 1=Powered up) 6-0 BCLK divider N (1..127, or 0=128) |
7-5 Secondary BCLK is obtained from ;\(0=GPIO1, 1=SCLK, 2=MISO, 3=SDOUT, 4-2 Secondary WCLK is obtained from ;/ 4=GPIO2, 5=GPI1, 6=GPI2, 7=GPI3) 1-0 Secondary SDIN is obtained from (0=GPIO1, 1=SCLK, 2=GPIO2, 3=GPI1) |
7-5 ADC_WCLK is obtained from (0=GPIO1, 1=SCLK, 2=MISO, 3=Reserved, 4 Reserved 4=GPIO2, 5=GPI1, 6=GPI2, 7=GPI3) 3 Codec/ClockGen BCLK source (0=Primary BCLK, 1=Secondary BCLK) 2 Codec WCLK source (0=Primary WCLK, 1=Secondary WCLK) 1 Codec ADC_WCLK source (0=DAC_WCLK, 1=ADC_WCLK) 0 Codec SDIN source (0=Primary SDIN, 1=Secondary SDIN) |
7 Primary BCLK output (0=Internally generated BCLK, 1=Secondary BCLK) 6 Secondary BCLK output (0=Primary BCLK, 1=Internally generated BCLK) 5-4 Primary WCLK output (0=DAC_fS, 1=ADC_fS, 2=Secondary WCLK, 3=Reserved) 3-2 Secondary WCLK output (0=Primary WCLK, 1=DAC_fS, 2=ADC_fS, 3=Reserved) 1 Primary SDOUT (0=SDOUT from codec, 1=Secondary SDIN) 0 Secondary SDOUT (0=Primary SDIN, 1=SDOUT from codec) |
7-6 Reserved. Write only the reset value to these bits. 5 Accept I2C general-call address (0=No/Ignore, 1=Yes/Accept) 4-0 Reserved. Write only zeros to these bits. |
7-0 Reserved. Write only zeros to these bits. |
| DSi TSC[0:24h..32h], Status and Interrupt Flags |
7 ADC PGA applied gain = programmed gain (0=Differs, 1=Equal) (R) 6 ADC powered (0=Powered down, 1=Powered up) (R) 5 AGC saturated (0=No/inrange, 1=Yes/saturated to max) (R) 4-0 Reserved. Write only zeros to these bits. |
7 Left-channel DAC powered (0=Powered down, 1=Powered up) (R) 6 Reserved. Write only zero to this bit. 5 Left Headphone HPL driver powered (0=Powered down, 1=Powered up) (R) 4 Left-channel class-D driver powered (0=Powered down, 1=Powered up) (R) 3 Right-channel DAC powered (0=Powered down, 1=Powered up) (R) 2 Reserved. Write only zero to this bit. 1 Right Headphone HPR driver powered (0=Powered down, 1=Powered up) (R) 0 Right-channel class-D driver powered (0=Powered down, 1=Powered up) (R) |
7-5 Reserved. Do not write to these bits. 4 Left-channel DAC PGA applied gain=programmed gain (0=Differs, 1=Equal) 3-1 Reserved. Write only zeros to these bits. 0 Right-channel DAC PGA applied gain=programmed gain (0=Differs, 1=Equal) |
7 Left-Channel DAC Overflow Flag (0=None, 1=Overflow) (R) 6 Right-Channel DAC Overflow Flag (0=None, 1=Overflow) (R) 5 DAC Barrel Shifter Output Overflow Flag (0=None, 1=Overflow) (R) 4 Reserved. Write only zeros to these bits. 3 Delta-Sigma Mono ADC Overflow Flag (0=None, 1=Overflow) (R) 2 Reserved. Write only zero to this bit. 1 ADC Barrel Shifter Output Overflow Flag (0=None, 1=Overflow) (R) 0 Reserved. Write only zero to this bit. |
7-0 Reserved. Write only the reset value to these bits. |
7 Short-circuit detected at HPL/left class-D driver (0=No, 1=Yes) 6 Short-circuit detected at HPR/right class-D driver (0=No, 1=Yes) 5 Headset button pressed (0=No, 1=Yes) 4 Headset insertion/removal is detected (0=No, 1=Yes) 3 Left DAC signal power vs signal threshold of DRC (0=Less/Equal,1=Above) 2 Right DAC signal power vs signal threshold of DRC(0=Less/Equal,1=Above) 1 DAC miniDSP Engine Standard Interrupt-Port Output (0=Read 0, 1=Read 1) 0 DAC miniDSP Engine Auxiliary Interrupt-Port Output (0=Read 0, 1=Read 1) |
7 Reserved. Write only zero to this bit.
6 ADC signal power vs noise threshold for AGC (0=Greater, 1=Less)
5 Reserved. Write only zeros to these bits.
4 ADC miniDSP Engine Standard Interrupt Port Output (0=Read 0, 1=Read 1)
3 ADC miniDSP Engine Auxiliary Interrupt Port Output (0=Read 0, 1=Read 1)
2 DC measurement using Delta Sigma Audio ADC
(0=Not available, 1=Not available, too, uh?)
1-0 Reserved. Write only zeros to these bits.
|
7 Short circuit detected at HPL/left class-D driver (0=No, 1=Yes) 6 Short circuit detected at HPR/right class-D driver (0=No, 1=Yes) 5 Headset button pressed (0=No, 1=Yes) 4 Headset removal/insertion detected (0=Removal, 1=Insertion) 3 Left DAC signal power vs signal threshold of DRC (0=Below, 1=Above) 2 Right DAC signal power vs signal threshold of DRC (0=Below, 1=Above) 1 DAC miniDSP Engine Standard Interrupt Port Output (0=Read 0, 1=Read 1) 0 DAC miniDSP Engine Auxiliary Interrupt Port Output (0=Read 0, 1=Read 1) |
7 Reserved
6 Delta-sigma mono ADC signal power vs noise threshold for left AGC
5 Reserved (0=Greater, 1=Less)
4 ADC miniDSP Engine Standard Interrupt Port Output (0=Read 0, 1=Read 1)
3 ADC miniDSP Engine Auxiliary Interrupt Port Output (0=Read 0, 1=Read 1)
2 DC measurement using Delta Sigma Audio ADC
(0=Not available, 1=Not available, too, uh?)
1-0 Reserved. Write only zeros to these bits.
|
7 Headset-insertion detect (0=Off, 1=On) 6 Button-press detect (0=Off, 1=On) 5 DAC DRC signal-power (0=Off, 1=On) 4 ADC AGC noise (0=Off, 1=On) 3 Short-circuit (0=Off, 1=On) 2 Engine-generated (0=Off, 1=On) 1 DC measurement using Delta Sigma Audio ADC data-available (0=Off, 1=On) 0 INT duration (0=Pulse Once, 1=Pulse Repeatedly until Acknowledge) |
7 INT1 upon SAR measurement data-out-of-threshold range (0=Off, 1=Off?) 6 INT1 upon Pen touch/SAR data-available (0=Off, 1=On) 5 INT2 upon SAR measurement data-out-of-threshold range (0=Off, 1=Off?) 4 Reserved 3 Pen touch detected (0=No, 1=Touch) (R) 2 Data available for read (0=No, 1=Available) (R) 1 SAR data out of programmed threshold range (0=No, 1=Out) (R) 0 Reserved. Write only the default value to this bit. (R) |
| DSi TSC[0:33h..3Bh], Pin Control |
7-6 Reserved. Do not write any value other than reset value.
5-2 GPIOx Mode (R/W)
0 = GPIOx disabled (input and output buffers powered down)
1 = GPIOx input mode (as secondary BCLK/WCLK/SDIN input, or
as ADC_WCLK input, Dig_Mic_In or in ClockGen block)
2 = GPIOx input mode (as GPI general-purpose input)
3 = GPIOx output = general-purpose output
4 = GPIOx output = CLKOUT output
5 = GPIOx output = INT1 output
6 = GPIOx output = INT2 output
7 = GPIOx output = ADC_WCLK output for codec interface
8 = GPIOx output = secondary BCLK output for codec interface
9 = GPIOx output = secondary WCLK output for codec interface
10 = GPIOx output = ADC_MOD_CLK output for the digital microphone
11 = GPIOx output = secondary SDOUT for codec interface
12 = GPIOx output = TouchScreen/SAR ADC interrupt (active-low),
13-15 = Reserved as PINTDAV signal
1 GPIOx input buffer value (0 or 1) (R)
0 GPIOx general-purpose output value (0 or 1) (R/W)
|
7-5 Reserved
4 SDOUT bus keeper (0=Enabled, 1=Disabled)
3-1 SDOUT Mode
0 = SDOUT disabled (output buffer powered down)
1 = SDOUT = primary SDOUT output for codec interface
2 = SDOUT = general-purpose output
3 = SDOUT = CLKOUT output
4 = SDOUT = INT1 output
5 = SDOUT = INT2 output
6 = SDOUT = secondary BCLK output for codec interface
7 = SDOUT = secondary WCLK output for codec interface
0 SDOUT general-purpose output value (0 or 1)
|
7-3 Reserved
2-1 SDIN Mode
0 = SDIN disabled (input buffer powered down)
1 = SDIN enabled (as codec SDIN, Dig_Mic_In, or in ClockGen block)
2 = SDIN enabled (as GPI general-purpose input)
3 = Reserved
0 SDIN input-buffer value (0 or 1) (R)
|
7-5 Reserved
4-1 MISO Mode
0 = MISO disabled (output buffer powered down)
1 = MISO = MISO output for SPI interface (or disabled for I2C)
2 = General-purpose output
3 = MISO = CLKOUT output
4 = MISO = INT1 output
5 = MISO = INT2 output
6 = MISO = ADC_WCLK output for codec interface
7 = MISO = ADC_MOD_CLK output for the digital microphone
8 = MISO = secondary SDOUT for codec interface
9 = MISO = secondary BCLK output for codec interface
10 = MISO = secondary WCLK output for codec interface
11-15 = Reserved
0 MISO general-purpose output value (0 or 1)
|
7-3 Reserved
2-1 SCLK Mode
0 = SCLK disabled (input buffer powered down)
1 = SCLK enabled (for the SPI interface)
2 = SCLK enabled (as a GPI general-purpose input)
3 = SCLK enabled (as secondary SDIN/BCLK/WCLK input,
or as ADC_WCLK input, or Dig_Mic_In)
0 SCLK input buffer value (0 or 1) (R)
|
7 Reserved. Write only zero to this bit.
6-5 GPI1 Mode
0 = GPI1 disabled (input buffer powered down)
1 = GPI1 enabled (as secondary SDIN/BCLK/WCLK input, or ADC_WCLK inp)
2 = GPI1 enabled (as a GPI general-purpose input)
3 = Reserved (unlike below GPI2)
4 GPI1 pin value (0 or 1) (R)
3 Reserved. Write only zero to this bit.
2-1 GPI2 Mode
0 = GPI2 disabled (input buffer powered down)
1 = GPI2 enabled (as secondary BCLK/WCLK input, or ADC_WCLK input)
2 = GPI2 enabled (as a GPI general-purpose input)
3 = GPI2 enabled (as an HP_SP input)
0 GPI2 pin value (0 or 1) (R)
|
7 Reserved. Write only zero to this bit.
6-5 GPI3 Mode
0 = GPI3 disabled (input buffer powered down)
1 = GPI3 enabled (as secondary BCLK/WCLK input, or ADC_WCLK input)
2 = GPI3 enabled (as a GPI general purpose input)
3 = Reserved (Undocumented - used by DSi?)
4 GPI3 pin value (0 or 1) (R)
3-0 Reserved. Write only zeros to these bits.
|
7-0 Reserved. Write only zeros to these bits. |
| DSi TSC[0:3Ch..55h], DAC/ADC and Beep |
7-5 Reserved. Write only default value.
4-0 DAC Signal Processing Block
0 = DAC miniDSP is used for signal processing
1..25 = DAC Signal Processing Block PRB_P1 .. PRB_P25
26..31 = Reserved. Do not use.
|
7-5 Reserved. Write only default values.
4-0 ADC Signal Processing Block
0 = ADC miniDSP is used for signal processing
1..3 = Reserved
4..6 = ADC Signal Processing Block PRB_R4 .. PRB_R6
7..9 = Reserved
10..12 = ADC Signal Processing Block PRB_R10 .. PRB_R12
13..15 = Reserved
16..18 = ADC Signal Processing Block PRB_R16 .. PRB_R18
19..31 = Reserved. Do not write these sequences to these bits.
|
7 Reserved 6 ADC miniDSP Engine Auxiliary Control bit A (0 or 1) 5 ADC miniDSP Engine Auxiliary Control bit B (0 or 1) 4 Reset ADC miniDSP instruction counter at start of new frame (0=Yes) 3 Reserved 2 DAC miniDSP Engine Auxiliary Control bit A (0 or 1) 1 DAC miniDSP Engine Auxiliary Control bit B (0 or 1) 0 Reset DAC miniDSP instruction counter at start of new frame (0=Yes) |
7 Left-channel DAC (0=Powered down, 1=Powered up)
6 Right-channel DAC (0=Powered down, 1=Powered up)
5-4 Left-channel DAC data path (0=Off, 1=Left Data, 2=Right Data, 3=Both)
3-2 Right-channel DAC data path (0=Off, 1=Right Data, 2=Left Data, 3=Both)
1-0 DAC channel volume control soft-stepping (0=One step per sample,
1=One step per 2 samples, 2=Disabled, 3=Reserved)
|
7-4 Reserved. Write only zeros to these bits.
3 Left-channel DAC (0=Not muted, 1=Muted)
2 Right-channel DAC (0=Not muted, 1=Muted)
1-0 DAC Mono/Stereo Volume
0: Use Left/Right volume control for Left/Right channels ("stereo")
1: Use Right volume control for Both channels ("mono")
2: Use Left volume control for Both channels ("mono")
3: Same as 0 ("stereo")
|
7-0 Digital gain in 0.5dB units (-127..+48 = -63.5dB..+24dB, Other=Reserved) |
7 Headset detection Enable (0=Disabled, 1=Enabled)
6-5 Headset detection (0=None, 1=Headset, 2=Reserved, 3=Headset+Mic) (R)
4-2 Debounce for Glitch Rejection During Headset Detection
(0..5 = 16ms, 32ms, 64ms, 128ms, 256ms, 512ms, 6..7=Reserved)
(when TSC[3:10h] set to 1MHz)
1-0 Debounce for Glitch Rejection During Headset Button-Press Detection
(0..3 = 0ms, 8ms, 16ms, 32ms) (when TSC[3:10h] set to 1MHz)
|
7 Reserved. Write only the reset value to these bits. 6 DRC for left channel (0=Disabled, 1=Enabled) 5 DRC for right channel (0=Disabled, 1=Enabled) 4-2 DRC threshold (0..7 = -3dB,-6dB,-9dB,-12dB,-15dB,-18dB,-21dB,-24dB) 1-0 DRC hysteresis (0..3 = +0dB,+1dB,+2dB,+3dB) |
7 Reserved. Write only the reset value to these bits.
6-3 DRC Hold Time
0 = DRC Hold Disabled ;-disable
1 = 32 DAC Word Clocks ;\
2 = 64 DAC Word Clocks ;
3 = 128 DAC Word Clocks ;
4 = 256 DAC Word Clocks ; powers of 2
5 = 512 DAC Word Clocks ;
6 = 1024 DAC Word Clocks ;
7 = 2048 DAC Word Clocks ;
8 = 4096 DAC Word Clocks ;
9 = 8192 DAC Word Clocks ;
10 = 16384 DAC Word Clocks ;/
11 = 1*32768 DAC Word Clocks ;\
12 = 2*32768 DAC Word Clocks ;
13 = 3*32768 DAC Word Clocks ; multiples of 32768
14 = 4*32768 DAC Word Clocks ;
15 = 5*32768 DAC Word Clocks ;/
2-0 Reserved. Write only the reset value to these bits.
|
7-4 DRC attack rate, "(4 SHR N) dB per DAC Word Clock"
(0=4dB, 1=2dB, 2=1dB, ..., 15=0.000122dB per DAC Word Clock)
3-0 DRC decay rate, "(1 SHR (N+6)) dB per DAC Word Clock"
(0=0.0156dB, 1=0.00781dB, ..., 15=0.000000476dB per DAC Word Clock)
|
7 Beep Generator Enable (0=Disabled/Duration ended, 1=Enabled/Busy)
(self-clearing based on beep duration)
6 Auto beep generator on pen touch (0=Disabled, 1=Enabled)
(CODEC_CLKIN should be available for this and is
used whenever touch is detected).
5-0 Left-channel beep volume control "(2-N)dB" (0..63 = +2dB .. -61dB)
|
7-6 Beep Mono/Stereo Volume
0: Use Left/Right volume control for Left/Right channels ("stereo")
1: Use Right volume control for Both channels ("mono")
2: Use Left volume control for Both channels ("mono")
3: Same as 0 ("stereo")
5-0 Right-channel beep volume control "(2-N)dB" (0..63 = +2dB .. -61dB)
|
23-0 Number of samples for which beep need to be generated (24bit) |
15-0 Beep Frequency sin/cos values (16bit, each) |
7-0 Reserved. Write only the reset value to these bits. |
7 ADC channel (0=Powered Down, 1=Powered Up)
6 Reserved
5-4 Digital microphone input (0=GPIO1, 1=SCLK, 2=SDIN, 3=GPIO2)
3 Digital microphone for delta-sigma mono ADC channel (0=Off, 1=On)
2 Reserved
1-0 ADC channel volume control soft-stepping (0=One step per sample,
1=One step per 2 samples, 2=Disabled, 3=Reserved)
|
7 ADC channel (0=Not muted, 1=Muted)
6-4 Delta-Sigma Mono ADC Channel Volume Control Fine Gain
(0=0dB, 1=-0.1dB, 2=-0.2dB, 3=-0.3dB, 4=-0.4dB, 5..7=Reserved)
3-0 Reserved. Write only zeros to these bits.
|
7 Reserved
6-0 Delta-Sigma Mono ADC Channel Volume Control Coarse Gain
00h..27h = 0..39 = Reserved
28h..xxh = 40 = -12 dB
29h = 39 = -11.5 dB
... ...
67h = 103 = +19.5 dB
68h = 104 = +20 dB
69h..7Fh = 105..127 = Reserved
|
7-0 Reserved. Write only the reset value to these bits. |
| DSi TSC[0:56h..7Fh], AGC and ADC |
7 AGC (0=Disabled, 1=Enabled)
6-4 AGC target level (0=-5.5dB, 1=-8dB, 2=-10dB, 3=-12dB,
4=-14dB, 5=-17dB, 6=-20dB, 7=-24dB)
3-0 Reserved. Write only zeros to these bits.
|
7-6 AGC hysterysis setting (0=1dB, 1=2dB, 2=4dB, 3=Disable AGC hysterysis)
5-1 AGC noise threshold (and silence detection)
0 = AGC noise/silence detection is disabled.
1 = AGC noise threshold = -30dB
2 = AGC noise threshold = -32dB
3 = AGC noise threshold = -34dB
...
29 = AGC noise threshold = -86dB
30 = AGC noise threshold = -88dB
31 = AGC noise threshold = -90dB
0 Reserved. Write only zero to this bit.
|
7 Reserved. Write only zero to this bit. 6-0 AGC maximum gain in 0.5dB units (0..119=0..+59.5dB, 120..127=Reserved) |
7-3 AGC attack/decay time, (N*2+1)*32/fS (0..31 = 1*32/fS .. 63*32/fS) 2-0 AGC attack/decay time Multiply factor, 1 SHL N (0..7 = 1..128) |
7-5 Reserved. Write only zeros to these bits.
4-0 AGC noise debounce
0..5 = 0/fS, 4/fS, 8/fS, 16/fS, 32/fS, 64/fS ;\powers of 2
6..10 = 128/fS, 256/fS, 512/fS, 1024/fS, 2048/fS ;/
11..14 = 1*4096/fS, 2*4096/fS, 3*4096/fS ;\multiples
14..31 = 4*4096/fS, .., 20*4096/fS, 21*4096/fS ;/of 4096
|
7-4 Reserved. Write only zeros to these bits.
3-0 AGC signal debounce
0..5 = 0/fS, 4/fS, 8/fS, 16/fS, 32/fS, 64/fS ;\powers of 2
6..9 = 128/fS, 256/fS, 512/fS, 1024/fS ;/
10..13 = 1*2048/fS, 2*2048/fS, 3*2048/fS ;\multiples
13..15 = 4*2048/fS, 5*2048/fS, 6*2048/fS ;/of 2048
|
7-0 Gain applied by AGC in 0.5dB units (-24..+119 = -12dB..+59.5dB) (R) |
7-0 Reserved. Do not write to these registers. |
7 DC measurement for mono ADC channel (0=Disabled, 1=Enabled)
6 Reserved. Write only reset value.
5 DC measurement is done based on
0: 1st order sinc filter with averaging of 2^D.
1: 1st order low-pass IIR filter whose coefficients
are calculated based on D value.
4-0 DC Meaurement D setting (1..20 = D=1 .. D=20) (0 or 21..31=Reserved)
|
7 Reserved. Write only reset value.
6 DC measurement data update (0=Enabled, 1=Disabled/allow stable reading)
(Disabled: user can read the last updated data without corruption)
5 For IIR based DC measurement, the measurment value is
0: the instantaneous output of the IIR filter
1: update before periodic clearing of the IIR filter
4-0 IIR based DC measurment, average time setting:
0 Infinite average is used
1 Averaging time is 2^1 ADC modulator clock periods
2 Averaging time is 2^2 ADC modulator clock periods
...
19 Averaging time is 2^19 ADC modulator clock periods
20 Averaging time is 2^20 ADC modulator clock periods
21..31 Reserved. Don't use.
|
23-0 ADC DC Measurement Output (24bit) |
7-0 Reserved. Do not write to these registers. |
7 DAC volume control is controlled by,
0: controlled by control register (7-bit Vol ADC is powered down)
1: controlled by pin (analog volume input)
6 Clock for the 7-bit Vol ADC for pin volume control,
0: Internal on-chip RC oscillator
1: External MCLK
5-4 Hysteresis
0: No hysteresis for volume control ADC output
1: Hysteresis of +/-1 bit
2: Hysteresis of +/-2 bits
3: Reserved. Do not write this sequence to these bits.
3 Reserved. Write only reset value.
2-0 Throughput of the 7-bit Vol ADC for pin volume control,
When Bit6=1 and external MCLK is 12MHz:
(0..7=15.625Hz, 31.25Hz, 62.5Hz, 125Hz, 250Hz, 500Hz, 1000Hz, 2000Hz)
When Bit6=0 (use Internal oscillator):
(0..7=10.68Hz, 21.35Hz, 42.71Hz, 85Hz?, 170Hz, 340Hz, 680Hz, 1370Hz)
|
7 Reserved. Write only zero to this bit.
6-0 Gain applied by pin volume control
0 = +18 dB
1 = +17.5 dB
2 = +17 dB
...
35 = +0.5 dB
36 = 0 dB
37 = -0.5 dB
...
89 = -26.5 dB
90 = -27 dB ;below in 1dB steps instead of 0.5dB steps !
91 = -28 dB
...
125 = -62 dB
126 = -63 dB
127 = Reserved
|
7-0 Reserved. Do not write to these registers. |
| DSi TSC[1:xxh], DAC and ADC Routing, PGA, Power-Controls and MISC Logic |
7-0 Reserved. Do not write to these registers. |
7-2 Reserved 1 Reset HPL/HPR power-up bits upon short-circuit detect (0=Yes, 1=No) 0 Reset SPL/SPR power-up bits upon short-circuit detect (0=Yes, 1=No) |
7 HPL output driver (0=Powered down, 1=Powered up)
6 HPR output driver (0=Powered down, 1=Powered up)
5 Reserved. Write only zero to this bit.
4-3 Output common-mode voltage (0=1.35V, 1=1.5V, 2=1.65V, 3=1.8V)
2 Reserved. Write only 1 to this bit. (!!!)
1 Action when short-circuit protection is enabled/detected,
0=Limit the maximum current to the load.
1=Power down the output driver.
0 Short-circuit detected on the headphone driver (0=No, 1=Yes) (R)
|
7 Left-channel class-D output driver (0=Powered down, 1=Powered up) 6 Right-channel class-D output driver (0=Powered down, 1=Powered up) 5-1 Reserved. Write only the reset value (00011b) to these bits (!!!) 0 Short-circuit is detected on the class-D driver (0=No, 1=Yes) (R) |
7 If power down sequence is activated by device software power down
using TSC[1:2Eh].Bit7 then power down DAC,
0: simultaneously with the HP and SP amplifiers.
1: after HP and SP amplifiers are completely powered down.
(the latter setting is to optimize power-down POP).
6-3 Driver power-on time (at 8.2MHz) (1=15.3us, 2=153us, 3=1.53ms,
4=15.3ms,5=76.2ms, 6=153ms, 7=304ms, 8=610ms, 9=1.22s, 10=3.04s,
11=6.1s, 12..15=Reserved)
2-1 Driver ramp-up step time (8.2MHz) (0=0ms, 1=0.98ms, 2=1.95ms, 3=3.9ms)
0 Weakly driven output common-mode voltage is generated from,
0=resistor divider of the AVDD supply.
1=band-gap reference.
|
7 Reserved. Write only the reset value to this bit. (USED on DSi!)
6-4 Speaker Power-Up Wait Time (at 8.2MHz) (0=0 ms, 1=3.04 ms, 2=7.62 ms,
3=12.2 ms, 4=15.3 ms, 5=19.8 ms, 6=24.4 ms, 7=30.5 ms)
3-0 Reserved. Write only the reset value to these bits.
|
7-6 DAC_L route (0=Nowhere, 1=To L-Mixer, 2=Direct to HPL, 3=Reserved) 5 MIC input routed to the left-channel mixer amplifier (0=No, 1=Yes) 4 AUX1 input routed to the left-channel mixer amplifier (0=No, 1=Yes) 3-2 DAC_R route (0=Nowhere, 1=To R-Mixer, 2=Direct to HPR, 3=Reserved) 1 AUX1 input routed to the right-channel mixer amplifier (0=No, 1=Yes) 0 HPL driver output routed to HPR driver (for differential) (0=No, 1=Yes) |
7 Analog volume control routed to HPx/SPx output driver (0=No, 1=Yes) 6-0 Analog volume control gain (non-linear) (0 dB to -78 dB) |
7 Reserved. Write only zero to this bit.
6-3 HPx driver PGA (0..9 = 0dB..9dB, 10..15=Reserved)
2 HPx driver (0=Muted, 1=Not muted)
1 HPx driver during power down (0=Weakly driven to a common mode,
1=High-impedance)
0 All programmed gains to HPx have been applied (0=Not yet, 1=Yes/all) (R)
|
7-5 Reserved. Write only zeros to these bits. 4-3 SPx class-D driver output stage gain (0=6dB, 1=12dB, 2=18dB, 3=24dB) 2 SPx class-D driver (0=Muted, 1=Not muted) 1 Reserved. Write only zero to this bit. 0 All programmed gains to SPx have been applied (0=Not yet, 1=Yes/all) (R) |
7-5 Debounce time for the headset short-circuit detection
(0..7 = 0us, 8us, 16us, 32us, 64us, 128us, 256us)
(when TSC[3:10h] set to 1MHz)
4-3 DAC Performance (0=Normal, 1=Increased, 2=Reserved, 3=Further Increased)
(increased: by increased current, further: by increased current gain)
2 HPL output driver type (0=Headphone, 1=Lineout)
1 HPR output driver type (0=Headphone, 1=Lineout)
0 Reserved. Write only zero to this bit.
|
7-0 Reserved. Do not write to these registers. |
7 Device software power-down (0=Disabled, 1=PowerDown?-Enabled) 6-4 Reserved. Write only zeros to these bits. 3 Power up programmed MICBIAS (0=Only if Headset inserted, 1=Always) 2 Reserved. Write only zero to this bit. 1-0 MICBIAS output (0=Off, 1=2V, 2=2.5V, 3=AVDD) |
7 MIC PGA (0=Controlled by bits6-0, 1=Force 0dB) 6-0 PGA in 0.5dB units (0..119 = 0..59.5dB, 120..127=Reserved) |
7-6 MIC to MIC PGA feed-forward (0=Off, 1=10kOhm, 2=20kOhm, 3=40kOhm) 5-4 AUX1 to MIC PGA feed-forward (0=Off, 1=10kOhm, 2=20kOhm, 3=40kOhm) 3-2 AUX2 to MIC PGA feed-forward (0=Off, 1=10kOhm, 2=20kOhm, 3=40kOhm) 1-0 Reserved. Write only zeros to these bits. |
7-6 CM to MIC PGA feed-forward (0=Off, 1=10kOhm, 2=20kOhm, 3=40kOhm) 5-4 AUX2 to MIC PGA feed-forward (0=Off, 1=10kOhm, 2=20kOhm, 3=40kOhm) 3-0 Reserved. Write only zeros to these bits. |
7 MIC input (0=Floating, 1=Connected to CM internally)
(when not used for MIC PGA and analog bypass)
6 AUX1 input (0=Floating, 1=Connected to CM internally)
(when not used for MIC PGA and analog bypass)
5 AUX2 input (0=Floating, 1=Connected to CM internally)
(when not used for MIC PGA)
4-1 Reserved. Write only zeros to these bits.
0 All programmed gains to ADC have been applied (0=Not yet, 1=Yes/all) (R)
|
7-0 Reserved. Write only the reset value to these bits. |
| DSi TSC[3:xxh], Touchscreen/SAR Control and TSC[FCh:xxh], Buffer |
7-0 Reserved. Write only the reset value to these bits. |
7 Stop (0=Normal mode, 1=Stop conversion and power down SAR ADC)
6-5 SAR ADC resolution (0=12bit, 1=8bit, 2=10bit, 3=12bit)
4-3 SAR ADC clock divider
0 = Div1 (use for 8bit resolution mode only) (This divider is only
for the conversion clock generation, not for other logic)
1 = Div2 (use for 8bit/10bit resolution mode only)
2 = Div4 (recommended for better performance in 8bit/10bit mode)
3 = Div8 (recommended for better performance in 12bit mode)
(See Figure 5-40, uh?)
2 Filter used for on-chip data averaging (0=Mean, 1=Median) (if enabled)
1-0 On-chip data averaging for mean/median filter
0 = On-chip data averaging disabled
1 = 4-data averaging (mean), or 5-data averaging (median)
2 = 8-data averaging (mean), or 9-data averaging (median)
3 = 16-data averaging (mean), or 15-data averaging (median)
|
7 Conversions controlled,
0 = Host-controlled conversions
1 = Self-controlled conversions for touch screen based on pen touch
6 Reserved. Write only zero to this bit.
5-2 Conversion Mode
0 = No scan
1 = Scan X/Y ;\Even in host-controlled mode ;\until either
2 = Scan X/Y/Z1/Z2 ;/ ; pen is lifted,
3 = Scan X ;\ ; or a stop bit
4 = Scan Y ; Only in self-controlled mode ; TSC[3:02h].Bit7
5 = Scan Z1/Z2 ;/ ;/is sent
6 = VBAT measurement
7 = AUX2 measurement
8 = AUX1 measurement
9 = Auto scan. Sequence used is AUX1, AUX2, VBAT.
Each of these inputs can be enabled or disabled independently
using TSC[3:13h], and with that sequence is modified accordingly.
Scan continues until stop bit TSC[3:02h].Bit7 is sent,
or Bit5-2 of this register are changed.
10 = TEMP1 measurement
11 = Port scan: AUX1, AUX2, VBAT
12 = TEMP2 measurement
13-15 = Reserved. Do not write these sequences to these bits.
1-0 Interrupt pin (GPIO1 or GPIO2 pin)
0 = PEN-interrupt /PENIRQ (active low)
1 = Data-available /DATA_AVA (active low)
2 = PEN-interrupt PENIRQ and Data-available DATA_AVA (active high)
3 = Reserved
|
7 Pen touch detection (0=Enabled, 1=Disabled)
6-4 Precharge time before touch detection
(0..7 = 0.25us, 1us, 3us, 10us, 30us, 100us, 300us, 1000us)
(when TSC[3:11h] set to 8MHz)
3 Reserved. Write only zero to this bit.
2-0 Sense time during touch detection
(0..7 = 1us, 2us, 3us, 10us, 30us, 100us, 300us, 1000us)
(when TSC[3:11h] set to 8MHz)
|
7-6 SAR comparator bias current (0=Normal, 1..3=Increase by 25%, 50%, 100%)
(use Increase to support higher conversion clock)
5 Sample duration (0=Default, 1=Doubled; for higher impedance)
4-3 Reserved. Write only zeroes to these bits.
2-0 Panel voltage stabilization time before conversion
(0..7 = 0.25us, 1us, 3us, 10us, 30us, 100us, 300us, 1000us)
(when TSC[3:11h] set to 8MHz)
|
7 Reference for Non-touch-screen Measurement (0=External, 1=Internal)
6 Internal reference voltage (0=1.25V, 1=2.5V)
5 Internal reference powered (0=Always, 1=Only during conversion)
4 Reserved
3-2 Reference Stabilization Time before Conversion
(0=0us, 1=100us, 2=500us, 3=1ms) (when TSC[3:11h] set to 8MHz)
1 Reserved
0 Battery measurement input (0=VBAT<=VREF, 1=VBAT=BAT)
|
7-0 Reserved. Write only the reset value to these bits. |
7 Pen Touch detected (0=Not detected, 1=Detected) (R) 6 ADC Ready (0=Busy, 1=Ready) (R) 5 New data is available (0=None, 1=Yes) (R) 4 Reserved. Write only the reset value to this bit. 3 New X data is available (0=None, 1=Yes) (R) 2 New Y data is available (0=None, 1=Yes) (R) 1 New Z1 data is available (0=None, 1=Yes) (R) 0 New Z2 data is available (0=None, 1=Yes) (R) |
7 New AUX1 data is available (0=None, 1=Yes) (R) 6 New AUX2 data is available (0=None, 1=Yes) (R) 5 New VBAT data is available (0=None, 1=Yes) (R) 4-2 Reserved. Write only zeros to these bits. 1 New TEMP1 data is available (0=None, 1=Yes) (R) 0 New TEMP2 data is available (0=None, 1=Yes) (R) |
7-0 Reserved. Write only the reset value to these bits. |
7 Buffer Mode Enable (0=Disabled, 1=Enabled)
(when disabled: RDPTR/WRPTR/TGPTR are set to their default values)
6 Buffer Mode Type (0=Countinuos-conversion, 1=Single-shot)
5-3 Trigger level for conversion "(N+1)*8*number of converted data"
0..7 = (8..64)*number of converted data
uh, does "X*number of converted data" mean "after X conversions"?
2 Reserved
1 Buffer Full (0=No, 1=Full; contains 64 unread converted data) (R)
0 Buffer Empty (0=No, 1=Empty; contains 0 unread converted data) (R)
|
7-0 Reserved. Write only the reset value to these bits. |
7 Undoc Enable (0=Disabled, 1=Enabled) (R/W) 6 Undoc Whatever (0=Normal) (R/W) 5-3 Undoc Whatever (5=Normal) (R/W) 2 Undoc Unused (?) 1 Undoc Pendown/DataAvailable? (R?) 0 Undoc Unused (R?) |
7 Programmable delay for Touch-screen measurement (0=Disable, 1=Enable)
6-4 Programmable interval timer delay
(0..7 = 8ms, 1ms, 2ms, 3ms, 4ms, 5ms, 6ms, 7ms)
(when TSC[3:10h] set to 1MHz)
3 Programmable delay for Non-touch-screen auto measurement (1=Enable)
2-0 Programmable interval timer delay (0..7 = 1.12min, 3.36min,
5.59min, 7.83min, 10.01min, 12.30min, 14.54min, 16.78min)
(uh, what is that? minutes? minimum? or what?)
(when TSC[3:10h] set to 1MHz)
|
7 Clock used for Programmable Delay Timer (0=Internal Osc/8, 1=Ext. MCLK)
6-0 MCLK Divider to Generate 1-MHz Clock for the Programmable Delay Timer
(1..127=Div1..127, or 0=Div128)
|
7 Clock used for SAR ADC and TSC FSM (0=Internal Osc/1, 1=External MCLK) 6-0 MCLK Divider for the SAR (min 40ns) (1..127=Div1..127, or 0=Div128) |
7 Interface used for the buffer data reading (0=SPI, 1=I2C)
6 SAR/buffer data update is,
0: held automatically (to avoid simultaneous buffer read and write
operations) based on internal detection logic.
1: held using software control and TSC[3:12h].Bit5.
5 SAR/buffer data update is (only if above Bit6=1),
0: enabled all the time
1: stopped so that user can read the last updated data
without any data corruption.
4-3 Reserved. Write only zeros to these bits.
2-0 Pen-touch removal detection with debounce
(0..7 = 0us, 8us, 16us, 32us, 64us, 128us, 256us, 512us)
(when TSC[3:10h] set to 1MHz)
|
7 Auto AUX1 measurement during auto non-touch screen scan (0=Off, 1=On) 6 Auto AUX2 measurement during auto non-touch screen scan (0=Off, 1=On) 5 Auto VBAT measurement during auto non-touch screen scan (0=Off, 1=On) 4 Auto TEMP measurement during auto non-touch screen scan (0=Off, 1=On) 3 TEMP Measurement (0=Use TEMP1, 1=Use TEMP2) 2 AUX1 Usage (0=Voltage measurement, 1=Resistance measurement) 1 AUX2 Usage (0=Voltage measurement, 1=Resistance measurement) 0 Resistance measurement bias (0=Internal bias, 1=External bias) |
7-3 Reserved
2-0 Debounce Time for Pen-Down Detection
(0..7 = 0us, 64us, 128us, 256us, 512us, 1024us, 2048us, 4096us)
(when TSC[3:10h] set to 1MHz)
|
7-6 Reserved. Write only zeros to these bits. 5 AUX1 Maximum (0=Inrange, 1=Exceeds Limit; Equal/Above MAX) 4 AUX1 Minimum (0=Inrange, 1=Exceeds Limit; Equal/Below MIN) 3 AUX2 Maximum (0=Inrange, 1=Exceeds Limit; Equal/Above MAX) 2 AUX2 Minimum (0=Inrange, 1=Exceeds Limit; Equal/Below MIN) 1 TEMP Maximum (0=Inrange, 1=Exceeds Limit; Equal/Above MAX) 0 TEMP Minimum (0=Inrange, 1=Exceeds Limit; Equal/Below MIN) |
15-13 Reserved
12 Threshold check (0=Disabled, 1=Enabled)
(valid for auto/non-auto scan measurement).
11-0 Threshold code (12bit)
|
15-0 Data... but, seems to be always zero on DSi? |
7-0 Reserved. Write only the reset value to these bits. |
15 Ring-buffer Full (1=All 64 entries are unread) 14 Ring-buffer Empty (1=All 64 entries are read) 13 Reserved (uh?) 12 Data ID (0=X/Z1/BAT/AUX2, 1=Y/Z2/AUX1/TEMP) 11-0 Converted data (12bit), read from "RDPTR" ring-buffer location |
7-0 Reserved. Write only the reset value to these bits. |
| DSi TSC[04h..05h:xxh], ADC Digital Filter Coefficient RAM |
ADC miniDSP ADC FIR Filter Special
Coefficients Coefficients Coefficients
TSC[4:00h] Page Select - -
TSC[4:01h] Reserved - -
TSC[4:02h..07h] C1..C3 - N0,N1,D1 for AGC LPF
(first-order IIR, used
as averager to detect level)
TSC[4:08h..0Dh] C4..C6 - N0,N1,D1 for ADC-programmable
first-order IIR
TSC[4:0Eh..17h] C7..C11 FIR0..FIR4 N0,N1,N2,D1,D2 for ADC Biquad A
TSC[4:18h..21h] C12..C16 FIR5..FIR9 N0,N1,N2,D1,D2 for ADC Biquad B
TSC[4:22h..2Bh] C17..C21 FIR10..FIR14 N0,N1,N2,D1,D2 for ADC Biquad C
TSC[4:2Ch..35h] C22..C26 FIR15..FIR19 N0,N1,N2,D1,D2 for ADC Biquad D
TSC[4:36h..3Fh] C27..C31 FIR20..FIR24 N0,N1,N2,D1,D2 for ADC Biquad E
TSC[4:40h..7Fh] C32..C63 - -
TSC[5:00h] Page Select - -
TSC[5:01h] Reserved - -
TSC[5:02h..7Fh] C65..C127 - -
|
input[n] ---o--MUL(F0)-->ADD-----------------> output[n]
| ^
input[n-1] | ;\
| | ; first order FIR
o--MUL(F1)-->ADD ;/
| ^
input[n-2] | ;\
| | ; second order FIR
o--MUL(F2)-->ADD ;/
: ^
: : ;-further order's
|
input[n] ---o--MUL(N0)-->ADD-------------o---> output[n]
| ^ |
input[n-1] | output[n-1] ;\
| | | ; first order IIR
o--MUL(N1)-->ADD<--MUL(-D1)--o ;/
|
input[n] ---o--MUL(N0)-->ADD-------------o---> output[n]
| ^ |
input[n-1] | output[n-1] ;\
| | | ; first order IIR
o--MUL(N1)-->ADD<--MUL(-D1)--o ;/
| ^ |
input[n-2] | output[n-2] ;\
| | | ; second order IIR
o--MUL(N2)-->ADD<--MUL(-D2)--o ;/
|
| DSi TSC[08h..0Fh:xxh], DAC Digital Filter Coefficient RAM |
7-4 Reserved. Write only the reset value.
3 DAC miniDSP generated flag for toggling MSB of coefficient RAM address
(only used in non-adaptive mode) (R)
2 DAC Adaptive Filtering in DAC miniDSP (0=Disabled, 1=Enabled) (R/W)
1 DAC Adaptive Filter Buffer Control Flag (R)
aka DAC Coefficient Buffers in adaptive filter mode
0: miniDSP accesses Buffer A,
external control interface (=the user?) accesses Buffer B
1: miniDSP accesses Buffer B,
external control interface (=the user?) accesses Buffer A
0 DAC Adaptive Filter Buffer Switch Control (R/W)
0: DAC coefficient buffers will not be switched at next frame boundary
1: DAC coefficient buffers will be switched at next frame boundary
(only if adaptive filtering mode is enabled)
This bit will self-clear on switching.
|
DAC miniDSP Special
(DAC Buffer A) DAC-programmable
Coefficient Coefficient
TSC[8:00h] Page Select -
TSC[8:01h] Control - (see above)
TSC[8:02h..0Bh] C1..C5 N0,N1,N2,D1,D2 for Left Biquad A ;N0=7FFFh
TSC[8:0Ch..15h] C6..C10 N0,N1,N2,D1,D2 for Left Biquad B ;N1,N2,D1,
TSC[8:16h..1Fh] C11..C15 N0,N1,N2,D1,D2 for Left Biquad C ; D2=0
TSC[8:20h..29h] C16..C20 N0,N1,N2,D1,D2 for Left Biquad D
TSC[8:2Ah..33h] C21..C25 N0,N1,N2,D1,D2 for Left Biquad E
TSC[8:34h..3Dh] C26..C30 N0,N1,N2,D1,D2 for Left Biquad F
TSC[8:3Eh..3Fh] C31 -
TSC[8:40h..41h] C32 for 3D PGA for PRB_P23, PRB_P24 and PRB_P25
TSC[8:42h..4Bh] C33..C37 N0,N1,N2,D1,D2 for Right Biquad A
TSC[8:4Ch..55h] C38..C42 N0,N1,N2,D1,D2 for Right Biquad B
TSC[8:56h..5Fh] C43..C47 N0,N1,N2,D1,D2 for Right Biquad C
TSC[8:60h..69h] C48..C52 N0,N1,N2,D1,D2 for Right Biquad D
TSC[8:6Ah..73h] C53..C57 N0,N1,N2,D1,D2 for Right Biquad E
TSC[8:74h..7Dh] C58..C62 N0,N1,N2,D1,D2 for Right Biquad F
TSC[8:7Eh..7Fh] C63 -
TSC[9:00h] Page Select -
TSC[9:01h] Reserved - (do not write to this register)
TSC[9:02h..07h] C65..C67 N0,N1,D1 for Left first-order IIR
TSC[9:08h..0Dh] C68..C70 N0,N1,D1 for Right first-order IIR
TSC[9:0Eh..13h] C71..C73 N0,N1,D1 for DRC first-order high-pass filter
TSC[9:14h..19h] C74..C76 N0,N1,D1 for DRC first-order low-pass filter
TSC[9:1Ah..7Fh] C77..C127 -
TSC[A:00h] Page Select -
TSC[A:01h] Reserved - (do not write to this register)
TSC[A:02h..7Fh] C129..C191 -
TSC[B:00h] Page Select -
TSC[B:01h] Reserved - (do not write to this register)
TSC[B:02h..7Fh] C193..C255 -
|
DAC miniDSP Special
(DAC Buffer A) DAC-programmable
Coefficient Coefficient
TSC[C:02h..0Bh] C1..C5 Unknown ;\
TSC[C:0Ch..15h] C6..C10 Unknown ;
TSC[C:16h..1Fh] C11..C15 Unknown ; maybe Left Biquad A..F
TSC[C:20h..29h] C16..C20 Unknown ; as for Buffer A
TSC[C:2Ah..33h] C21..C25 Unknown ;
TSC[C:34h..3Dh] C26..C30 Unknown ;/
TSC[C:3Eh..3Fh] C31 -
TSC[C:40h..41h] C32 Unknown maybe 3D PGA as for Buffer A
TSC[C:42h..4Bh] C33..C37 Unknown ;\
TSC[C:4Ch..55h] C38..C42 Unknown ;
TSC[C:56h..5Fh] C43..C47 Unknown ; maybe Right Biquad A..F
TSC[C:60h..69h] C48..C52 Unknown ; as for Buffer A
TSC[C:6Ah..73h] C53..C57 Unknown ;
TSC[C:74h..7Dh] C58..C62 Unknown ;/
TSC[C:7Eh..7Fh] C63 -
TSC[D:00h] Page Select -
TSC[D:01h] Reserved - (do not write to this register)
TSC[D:02h..07h] C65..C67 Unknown ;\
TSC[D:08h..0Dh] C68..C70 Unknown ; maybe IIR and DRC
TSC[D:0Eh..13h] C71..C73 Unknown ; as for Buffer A
TSC[D:14h..19h] C74..C76 Unknown ;/
TSC[D:1Ah..7Fh] C77..C127 -
TSC[E:00h] Page Select -
TSC[E:01h] Reserved - (do not write to this register)
TSC[E:02h..7Fh] C129..C191 -
TSC[F:00h] Page Select -
TSC[F:01h] Reserved - (do not write to this register)
TSC[F:02h..7Fh] C193..C255 -
|
| DSi TSC[20h..2Bh:xxh], TSC[40h..5Fh:xxh] ADC/DAC Instruction RAM |
TSC[20h..2Bh:00h] Page Select TSC[20h..2Bh:01h] Reserved TSC[20h:02h...61h] ADC Instructions 0...31 TSC[21h:02h...61h] ADC Instructions 32...63 TSC[22h:02h...61h] ADC Instructions 64...95 TSC[23h:02h...61h] ADC Instructions 96...127 TSC[24h:02h...61h] ADC Instructions 128...159 TSC[25h:02h...61h] ADC Instructions 160...191 TSC[26h:02h...61h] ADC Instructions 192...223 TSC[27h:02h...61h] ADC Instructions 224...255 TSC[28h:02h...61h] ADC Instructions 256...287 TSC[29h:02h...61h] ADC Instructions 288...319 TSC[2Ah:02h...61h] ADC Instructions 320...351 TSC[2Bh:02h...61h] ADC Instructions 352...383 TSC[20h..2Bh:62h..7Fh] Reserved |
TSC[40h..5Fh:00h] Page Select TSC[40h..5Fh:01h] Reserved TSC[40h:02h...61h] DAC Instructions 0...31 TSC[41h:02h...61h] DAC Instructions 32...63 TSC[42h:02h...61h] DAC Instructions 64...95 TSC[43h:02h...61h] DAC Instructions 96...127 TSC[44h:02h...61h] DAC Instructions 128...159 TSC[45h:02h...61h] DAC Instructions 160...191 TSC[46h:02h...61h] DAC Instructions 192...223 TSC[47h:02h...61h] DAC Instructions 224...255 TSC[48h:02h...61h] DAC Instructions 256...287 TSC[49h:02h...61h] DAC Instructions 288...319 TSC[4Ah:02h...61h] DAC Instructions 320...351 TSC[4Bh:02h...61h] DAC Instructions 352...383 TSC[4Ch:02h...61h] DAC Instructions 384...415 TSC[4Dh:02h...61h] DAC Instructions 416...447 TSC[4Eh:02h...61h] DAC Instructions 448...479 TSC[4Fh:02h...61h] DAC Instructions 480...511 TSC[50h:02h...61h] DAC Instructions 512...543 TSC[51h:02h...61h] DAC Instructions 544...575 TSC[52h:02h...61h] DAC Instructions 576...607 TSC[53h:02h...61h] DAC Instructions 608...639 TSC[54h:02h...61h] DAC Instructions 640...671 TSC[55h:02h...61h] DAC Instructions 672...703 TSC[56h:02h...61h] DAC Instructions 704...735 TSC[57h:02h...61h] DAC Instructions 736...767 TSC[58h:02h...61h] DAC Instructions 768...799 TSC[59h:02h...61h] DAC Instructions 800...831 TSC[5Ah:02h...61h] DAC Instructions 832...863 TSC[5Bh:02h...61h] DAC Instructions 864...895 TSC[5Ch:02h...61h] DAC Instructions 896...927 TSC[5Dh:02h...61h] DAC Instructions 928...959 TSC[5Eh:02h...61h] DAC Instructions 960...991 TSC[5Fh:02h...61h] DAC Instructions 992...1023 TSC[40h..5Fh:62h..7Fh] Reserved |
| DSi I2C Bus |
Register Width Description
02h 1 Used for DSi IRQ6 IF flags
uh, IF.Bit6 would be Timer3overflow ?
or, IF2.Bit6 would be PowerButton ?
04h 1 Unknown (bit0 toggled)
|
Device Delay Description 7Ah 0 0 Camera0(internal) ;Aptina MT9V113 (SelfPortrait) 78h 0 1 Camera1(external) ;Aptina MT9V113 (External) A0h 0 2 Camera0 config (Ext) ;\maybe for other manufacturer? E0h 0 3 Camera1 config (Self);/ 4Ah 180h 4 BPTWL Chip (LED/Volume/Powerbutton/Reset) 40h 0 5 Debug? 90h 0 6 Debug? |
82h Power Managment Device (connected to BPTWL chip) 50h I2C bus potentiometer (volume D/A converter) (connected to BPTWL chip) 30h I2C bus unknown write-only, DSiXL omly ? (connected to BPUTL chip) A0h I2C bus EEPROM (connected to Atheros wifi chip) - I2C voltage translator (between ARM CPU and BPTWL chip) |
| DSi I2C I/O Ports |
0-7 Data (or Device, or Register) |
0 Stop (0=No, 1=Stop signal, after last byte)
1 Start (0=No, 1=Start signal, before first byte)
2 Error (0=No, 1=Pause/Flush? after Error, used with/after Stop)
(1=Transfer only selected Start/Stop signal(s), without data?)
(Nintendo seems to use bit2+bit0 to (try to) overcome problems
with the BPTWL chip's quirky Stop handling)
3 Unknown/unused (0)
4 Ack (0=High=Error/LastRead, 1=Low=Okay) ;For DataRead:W, for DataWrite:R
5 Data Direction (0=Write, 1=Read) (note: Ack uses opposite direction)
6 Interrupt Enable (0=Disable, 1=Enable)
7 Start/busy (0=Ready, 1=Start/busy)
|
For Writing: Write Device+0 (with Start condition) ;\ Write Index byte(s) ; write index + data Write Data byte(s) (last byte with Stop condition) ;/ For Reading: Write Device+0 (with Start condition) ;\1st step: write index Write Index byte(s) ;/ Write Device+1 (with Start condition) ;\2nd step: read data Read Data byte(s) (last byte with ACK=0 and Stop) ;/ |
Invoke byte-transfer Do WaitByLoop (needed for the BPTWL device only) Wait for start/busy flag to get zero |
| DSi I2C Signals |
START D7 D6 D5 D4 D3 D2 D1 D0 ACK D7 D6/ .. /D1 D0 ACK STOP
__ ___ ___ ___ ___ ___ ___ ___ ___ ___ __/ /___ ___ ___
SDA |__|___|___|___|___|___|___|___|___|___|___|_/ .. /|___|___|______|
____ _ _ _ _ _ _ _ _ _ _ / / _ _ _ _____
SCL |_| |_| |_| |_| |_| |_| |_| |_| |_| |_| |/ .. / |_| |_| |_| |_|
/ /
<--><------------------------------><--><--------------------><--><-->
Start Device/Direction Byte Ack Index/Data Byte(s) Ack Stop
|
if (send_start) then i2c_start_cond() ;-start (if so) for i=7 downto 0, i2c_write_bit(databyte.bit(i)), next i ;-write 8bit nack = i2c_read_bit() ;-read nack if (send_stop) then i2c_stop_cond() ;-stop (if so) return nack ;return 0 if ack by the slave. ;-return nack |
for i=7 downto 0, databyte.bit(i)=i2c_read_bit(), next i ;-read 8bit
i2c_write_bit(nack) ;-write nack
if (send_stop) then ;\
i2c_write_bit(1) ;NACK (ack=high=Last byte) ; nack (finish)
i2c_stop_cond() ;STOP ;/
else ;\ack (want more)
i2c_write_bit(0) ;ACK (ack=low=More bytes) ;/
return databyte ;-return databyte
|
if (bit) then SDA=HighZ else SDA=Low ;- I2C_delay() ;- SCL=HighZ wait until SCL=High (or timeout) ;-wait (for clock stretching) if (bit=1 and SDA=Low) then arbitration_lost();-errif other HW pulls SDA=low I2C_delay() ;- SCL=Low ;- |
SDA=HighZ ;-let the slave drive data I2C_delay() ;-delay (one half clk) SCL=HighZ wait until SCL=High (or timeout) ;-wait (for clock stretching) bit = SDA ;- I2C_delay() ;-delay (one half clk) SCL=Low ;- return bit ;- |
if (started) then ;if started, do a restart cond
SDA=HighZ ;-set SDA to 1
I2C_delay()
SCL=HighZ
wait until SCL=High (or timeout) ;-wait (for clock stretching)
I2C_delay() ;Repeated start setup time, minimum 4.7us
if (SDA=Low) then arbitration_lost()
SDA=Low ;-
I2C_delay()
SCL=Low
started = true
|
SDA=Low ;- I2C_delay() ;- SCL=HighZ ;- wait until SCL=High (or timeout) ;-wait (for clock stretching) I2C_delay() ;Stop bit setup time, minimum 4us if (SDA=Low) then arbitration_lost() I2C_delay() started = false |
1. No receiver is present on the bus with the transmitted address so there
is no device to respond with an acknowledge.
2. The receiver is unable to receive or transmit because it is performing
some real-time function and is not ready to start communication with the
master.
3. During the transfer, the receiver gets data or commands that it does not
understand.
4. During the transfer, the receiver cannot receive any more data bytes.
5. A master-receiver must signal the end of the transfer to the slave
transmitter.
|
| DSi I2C Device 4Ah (BPTWL chip) |
00h R Version/Speed (usually 33h) (00h..20h=Slow, 21h..FFh=Fast)
01h R ? Unknown, Powerman Status 1 (00h) ;some hw/sw type/version?
02h R ? Unknown, Powerman Status 2 (50h) ;30h=AlternateCamLedHardware?
03h-0Fh - Reserved (5Ah-filled)
10h R Power Button Status (bit0=WasWhat?, bit1=IsDown, bit3=WasDown?)
(bit0/3 are cleared after reading)
11h R/W System Reset (00h=No, 01h=Force Reset, 02h=Prevent Reset?)
12h R/W Power Button Tapping (00h=Auto-Reset, 01h=IRQ) (bit1=WL_RXPE??)
bit0: Enable IRQs (for Power/Vol+/- button, battery low)
bit1: battery boundaries (and 0=disable battery low IRQs)
bit5: initially set (while bptwl chip is booting up?)
bit7: Linear volume button mode
13h-1Fh - Reserved (5Ah-filled)
20h R Battery State (bit0..3=Battery Level, bit7=Charge)
W On 3DS in DSi mode: Write 8=Shutdown, 4=Return to 3DS mode ?
21h R/W Powerman Sleep?, NDS Cartridge related? (07h=normal)
22h-2Fh - Reserved (5Ah-filled)
30h R/W Wifi LED (0/2=Off, 1=On, 3=BlinkOnTraffic) and bit4=SDIO enable
31h R/W Camera LED (00h=Off, 01h=On, 02h=Blink)
32h-3Fh - Reserved (5Ah-filled)
40h R/W Volume Level (00h..1Fh) ;\nonvolatile!
41h R/W Backlight Level (00h..04h) ;/
42h-4Fh - Reserved (5Ah-filled)
50h R/W Unknown Value (DSi-XL only) (output to I2C device 30h)
51h R/W Unknown Trigger (DSi-XL only) (cleared when processed)
50h-5Fh - Reserved (5Ah-filled) (except 50h-51h on DSi XL)
60h R/W Battery Calibration Mode (bit0=1=Calibrate, Stop I2C, Purple LED)
61h R Battery Calibration Flag (01h=Calibrated, E0h/E8h=NotCalibrated)
62h R Battery Calibration Data (xxh=BatteryBias, 50h=NotCalibrated)
63h R/W Force Power LED (0=Automatic, 1=Red, 2=Blue, 3=Purple)
64h-6Fh - Reserved (5Ah-filled)
70h R/W Bootflag (00h=Coldboot, 01h=Warmboot/SkipHealthSafety)
71h R/W ? Unknown (00h) ;\more general-purpose bootflags?
72h-76h R/W ? Unknown (00h-filled) ;/
77h ?/W Firmware Updater (write 4Ah, plus HEX file with delays) (danger!)
78h-7Fh - Reserved (5Ah-filled)
80h R/W Power Button Tap delay (10h) ;\can affect/disable
81h R/W Power Button Hold delay (64h) ;/Power Button Tapping
82h-FFh - Reserved (5Ah-filled)
|
Forced volume (for alerts) (ie. alternately to current "user volume") |
00h R Version/Speed (35h on New3DS) 10h R Power Button Status (only 2 bits?: bit3=WasDown?, bit6=?) 11h R/W Reset (01h=Reset, other=ignored) (read: always 00h) 12h R/W Power Button Tapping (bit0,1,7=?) 20h R Battery State 31h R/W Camera LED (bit0,1) 40h R/W Volume Level 70h R/W Bootflag Other - Unused (FFh) |
Short tap --> reset (warmboot, go to DSi menu, without health and safety) Hold 1 second --> power-off |
Auto-Reset (used for NDS games) IRQ (supposed to be used with Manual-Reset) (used for DSi games) Forced Power-off (for games which fail to handle the IRQ within 5 seconds) |
0x10 1 Power flags. When bit0 is set, arm7 does a system reset.
When bit1 or bit3 are set, arm7 does a shutdown. Bits 0-2
are used for DSi IRQ6 IF flags (uh, rather IF2 maybe?).
0x20 1 Battery flags. When zero the battery is at critical level,
arm7 does a shutdown. Bit7 is set when the battery is
charging. Battery levels in the low 4-bits: battery icon
bars full 0xF, 3 bars 0xB, 2 bars 0x7, one solid red bar
0x3, and one blinking red bar 0x1. When plugging in or
removing recharge cord, this value increases/decreases
between the real battery level and 0xF, thus the battery
level while bit7 is set is useless.
|
DSi: Renesas Electronics "BPTWL, KG07K" ;reg[00h]=33h DSiXL: Renesas Electronics "BP UTL-1, KG08" ;reg[00h]=BBh or B7h 3DS: Renesas Electronics "UC CTR, 041KM73, KG10" ;reg[00h]=? New3DSXL: Renesas Electronics "UC KTR, 423KM01, 'TK14" ;reg[00h]=35h |
| 78K/0 Opcode List |
85/87/AB/AA/AE MOV A, [DE]/[HL]/[HL+B]/[HL+C]/[HL+nn] F0/F4/8E MOV A, [FExx]/[FFxx]/[nnnn] 60/--/62/63/64/65/66/67 MOV A, X/-/C/B/E/D/L/H 70/--/72/73/74/75/76/77 MOV X/-/C/B/E/D/L/H, A A0/A1/A2/A3/A4/A5/A6/A7 MOV X/A/C/B/E/D/L/H, nn 95/97/BB/BA/BE MOV [DE]/[HL]/[HL+B]/[HL+C]/[HL+nn], A F2/F6/9E MOV [FExx]/[FFxx]/[nnnn], A 11/13 MOV [FExx]/[FFxx], nn 30/--/32/33/34/35/36/37 XCH A, X/-/C/B/E/D/L/H 05/07/318B/318A/DE XCH A, [DE]/[HL]/[HL+B]/[HL+C]/[HL+nn] 83/93/CE XCH A, [FExx]/[FFxx]/[nnnn] |
C2/C4/C6/10 MOVW AX, BC/DE/HL/nnnn 89/A9/02 MOVW AX, [FExx]/[FFxx]/[nnnn] D2/D4/D6 MOVW BC/DE/HL, AX 12/14/16 MOVW BC/DE/HL, nnnn 99/B9/03 MOVW [FExx]/[FFxx]/[nnnn], AX EE/FE MOVW [FExx]/[FFxx], nnnn E2/E4/E6 XCHW AX,BC/DE/HL B1/B3/B5/B7/22 PUSH AX/BC/DE/HL/PSW ;PSW=[FF1Eh] (8bit) B0/B2/B4/B6/23 POP AX/BC/DE/HL/PSW ;PSW=[FF1Eh] (8bit) |
6100/6101/6102/6103/6104/6105/6106/6107 ADD X/A/C/B/E/D/L/H, A 6120/6121/6122/6123/6124/6125/6126/6127 ADDC X/A/C/B/E/D/L/H, A 6110/6111/6112/6113/6114/6115/6116/6117 SUB X/A/C/B/E/D/L/H, A 6130/6131/6132/6133/6134/6135/6136/6137 SUBC X/A/C/B/E/D/L/H, A 6140/6141/6142/6143/6144/6145/6146/6147 CMP X/A/C/B/E/D/L/H, A 6150/6151/6152/6153/6154/6155/6156/6157 AND X/A/C/B/E/D/L/H, A 6160/6161/6162/6163/6164/6165/6166/6167 OR X/A/C/B/E/D/L/H, A 6170/6171/6172/6173/6174/6175/6176/6177 XOR X/A/C/B/E/D/L/H, A 6108/----/610A/610B/610C/610D/610E/610F ADD A, X/-/C/B/E/D/L/H 6128/----/612A/612B/612C/612D/612E/612F ADDC A, X/-/C/B/E/D/L/H 6118/----/611A/611B/611C/611D/611E/611F SUB A, X/-/C/B/E/D/L/H 6138/----/613A/613B/613C/613D/613E/613F SUBC A, X/-/C/B/E/D/L/H 6148/----/614A/614B/614C/614D/614E/614F CMP A, X/-/C/B/E/D/L/H 6158/----/615A/615B/615C/615D/615E/615F AND A, X/-/C/B/E/D/L/H 6168/----/616A/616B/616C/616D/616E/616F OR A, X/-/C/B/E/D/L/H 6178/----/617A/617B/617C/617D/617E/617F XOR A, X/-/C/B/E/D/L/H 0D/0F/310B/310A/09/0E/08 ADD A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 2D/2F/312B/312A/29/2E/28 ADDC A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 1D/1F/311B/311A/19/1E/18 SUB A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 3D/3F/313B/313A/39/3E/38 SUBC A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 4D/4F/314B/314A/49/4E/48 CMP A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 5D/5F/315B/315A/59/5E/58 AND A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 6D/6F/316B/316A/69/6E/68 OR A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 7D/7F/317B/317A/79/7E/78 XOR A,nn/[HL]/[HL+B]/[HL+C]/[HL+nn]/[FExx]/[nnnn] 88 ADD [FExx], nn A8 ADDC [FExx], nn 98 SUB [FExx], nn B8 SUBC [FExx], nn C8 CMP [FExx], nn D8 AND [FExx], nn E8 OR [FExx], nn F8 XOR [FExx], nn 40/41/42/43/44/45/46/47/81 INC X/A/C/B/E/D/L/H/[FExx] 50/51/52/53/54/55/56/57/91 DEC X/A/C/B/E/D/L/H/[FExx] |
CA/DA/EA ADDW/SUBW/CMPW AX,nnnn 80/82/84/86 INCW AX/BC/DE/HL 90/92/94/96 DECW AX/BC/DE/HL |
26 ROL A,1 24 ROR A,1 27 ROLC A,1 25 RORC A,1 3180 ROL4 A,[HL] ;12bit A.lsb:[HL],4 ;native: ROL4 [HL] 3190 ROR4 A,[HL] ;12bit A.lsb:[HL],4 ;native: ROR4 [HL] |
3198 JMP AX ;native: BR AX 9B JMP absolute addr ;native: BR FA JMP relative short addr ;native: BR 9A CALL absolute addr ;native: CALL C1+(nn AND 3Eh) CALL [40h..7Eh] ;native: CALLT 0C/1C/2C/3C/4C/5C/6C/7C CALLF 08nn/09nn/0Ann/0Bnn/0Cnn/0Dnn/0Enn/0Fnn |
8D JC aka JB rel ;carry/below ;native: BC AD JZ aka JE rel ;zero/equal ;native: BZ 9D JNC aka JAE rel ;not carry/below ;native: BNC BD JNZ aka JNE rel ;not zero/equal ;native: BNZ 04/8B/8A DJNZ [FExx]/B/C, rel ;decrement+jnz ;native: DBNZ |
3101/3105/3185/310D+n*10 BTCLR [FExx]/[FFxx]/[HL]/A.n, rel 8C/3106/3186/310E+n*10 BT [FExx]/[FFxx]/[HL]/A.n, rel 3103/3107/3187/310F+n*10 BF [FExx]/[FFxx]/[HL]/A.n, rel |
7101/7109/7181/6189+n*10 MOV1 [FExx]/[FFxx]/[HL]/A.n, CY 7104/710C/7184/618C+n*10 MOV1 CY, [FExx]/[FFxx]/[HL]/A.n 7105/710D/7185/618D+n*10 AND1 CY, [FExx]/[FFxx]/[HL]/A.n 7106/710E/7186/618E+n*10 OR1 CY, [FExx]/[FFxx]/[HL]/A.n 7107/710F/7187/618F+n*10 XOR1 CY, [FExx]/[FFxx]/[HL]/A.n 20/0A/710A/7182/618A+n*10 SET1 CY/[FExx]/[FFxx]/[HL]/A.n 21/0B/710B/7183/618B+n*10 CLR1 CY/[FExx]/[FFxx]/[HL]/A.n 01 NOT1 CY |
00 NOP BF/7110/7100 BRK/HALT/STOP AF/9F/8F RET/RETB/RETI 61D0/61D8/61F0/61F8 SEL RB0/1/2/3 3188 MULU AX,A,X ;unsigned AX=A*X ;native: MULU X 3182 DIVUW AX,C ;unsigned AX=AX/C, C=remainder ;X 6180/6190 ADJBA/ADJBS ;decimal BCD adjust A after Add/Sub 7A1E/7B1E EI/DI ;pseudo SET1/CLR1 PSW.7 FA JR addr ;pseudo jmp short relative addr |
| 78K/0 Opcode Map |
00 10 20 30
00 NOP MOVW AX,nnnn SET1 CY XCH A,X
01 NOT1 CY MOV [FExx],nn CLR1 CY <prefix>
02 MOVW AX,[nnnn] MOVW BC,nnnn PUSH PSW ;[FF1Eh] XCH A,C
03 MOVW [nnnn],AX MOV [FFxx],nn POP PSW ;[FF1Eh] XCH A,B
04 DBNZ [FExx],rel MOVW DE,nnnn ROR A,1 XCH A,E
05 XCH A,[DE] <undef> RORC A,1 XCH A,D
06 <undef> MOVW HL,nnnn ROL A,1 XCH A,L
07 XCH A,[HL] <undef> ROLC A,1 XCH A,H
08 ADD A,[nnnn] SUB A,[nnnn] ADDC A,[nnnn] SUBC A,[nnnn]
09 ADD A,[HL+nn] SUB A,[HL+nn] ADDC A,[HL+nn] SUBC A,[HL+nn]
0A SET1 [FExx].0 SET1 [FExx].1 SET1 [FExx].2 SET1 [FExx].3
0B CLR1 [FExx].0 CLR1 [FExx].1 CLR1 [FExx].2 CLR1 [FExx].3
0C CALLF 08nn CALLF 09nn CALLF 0Ann CALLF 0Bnn
0D ADD A,nn SUB A,nn ADDC A,nn SUBC A,nn
0E ADD A,[FExx] SUB A,[FExx] ADDC A,[FExx] SUBC A,[FExx]
0F ADD A,[HL] SUB A,[HL] ADDC A,[HL] SUBC A,[HL]
|
40 50 60 70
40 INC X DEC X MOV A,X MOV X,A
41 INC A DEC A <prefix> <prefix>
42 INC C DEC C MOV A,C MOV C,A
43 INC B DEC B MOV A,B MOV B,A
44 INC E DEC E MOV A,E MOV E,A
45 INC D DEC D MOV A,D MOV D,A
46 INC L DEC L MOV A,L MOV L,A
47 INC H DEC H MOV A,H MOV H,A
48 CMP A,[nnnn] AND A,[nnnn] OR A,[nnnn] XOR A,[nnnn]
49 CMP A,[HL+nn] AND A,[HL+nn] OR A,[HL+nn] XOR A,[HL+nn]
4A SET1 [FExx].4 SET1 [FExx].5 SET1 [FExx].6 SET1 [FExx].7
4B CLR1 [FExx].4 CLR1 [FExx].5 CLR1 [FExx].6 CLR1 [FExx].7
4C CALLF 0Cnn CALLF 0Dnn CALLF 0Enn CALLF 0Fnn
4D CMP A,nn AND A,nn OR A,nn XOR A,nn
4E CMP A,[FExx] AND A,[FExx] OR A,[FExx] XOR A,[FExx]
4F CMP A,[HL] AND A,[HL] OR A,[HL] XOR A,[HL]
|
80 90 A0 B0
80 INCW AX DECW AX MOV X,nn POP AX
81 INC [FExx] DEC [FExx] MOV A,nn PUSH AX
82 INCW BC DECW BC MOV C,nn POP BC
83 XCH A,[FExx] XCH A,[FFxx] MOV B,nn PUSH BC
84 INCW DE DECW DE MOV E,nn POP DE
85 MOV A,[DE] MOV [DE],A MOV D,nn PUSH DE
86 INCW HL DECW HL MOV L,nn POP HL
87 MOV A,[HL] MOV [HL],A MOV H,nn PUSH HL
88 ADD [FExx],nn SUB [FExx],nn ADDC [FExx],nn SUBC [FExx],nn
89 MOVW AX,[FExx] MOVW [FExx],AX MOVW AX,[FFxx] MOVW [FFxx],AX
8A DBNZ C,rel CALL nnnn MOV A,[HL+C] MOV [HL+C],A
8B DBNZ B,rel BR nnnn MOV A,[HL+B] MOV [HL+B],A
8C BT [FExx].0,rel BT [FExx].1,rel BT [FExx].2,rel BT [FExx].3,rel
8D BC rel BNC rel BZ rel BNZ rel
8E MOV A,[nnnn] MOV [nnnn],A MOV A,[HL+nn] MOV [HL+nn],A
8F RETI RETB RET BRK
|
C0 D0 E0 F0
C0 <undef> <undef> <undef> MOV A,[FExx]
C1 CALLT [40] CALLT [50] CALLT [60] CALLT [70]
C2 MOVW AX,BC MOVW BC,AX XCHW AX,BC MOV [FExx],A
C3 CALLT [42] CALLT [52] CALLT [62] CALLT [72]
C4 MOVW AX,DE MOVW DE,AX XCHW AX,DE MOV A,[FFxx]
C5 CALLT [44] CALLT [54] CALLT [64] CALLT [74]
C6 MOVW AX,HL MOVW HL,AX XCHW AX,HL MOV [FFxx],A
C7 CALLT [46] CALLT [56] CALLT [66] CALLT [76]
C8 CMP [FExx],nn AND [FExx],nn OR [FExx],nn XOR [FExx],nn
C9 CALLT [48] CALLT [58] CALLT [68] CALLT [78]
CA ADDW AX,nnnn SUBW AX,nnnn CMPW AX,nnnn BR rel
CB CALLT [4A] CALLT [5A] CALLT [6A] CALLT [7A]
CC BT [FExx].4,rel BT [FExx].5,rel BT [FExx].6,rel BT [FExx].7,rel
CD CALLT [4C] CALLT [5C] CALLT [6C] CALLT [7C]
CE XCH A,[nnnn] XCH A,[HL+nn] MOVW [FExx],nnnn MOVW [FFxx],nnnn
CF CALLT [4E] CALLT [5E] CALLT [6E] CALLT [7E]
|
3100+xxx*10 - 3180+xxx*10 - (unless below ROL/ROR) 3101+bbb*10 BTCLR [FExx].n,rel ;n=0..7 3181+xxx*10 - 3102+xxx*10 - 3182+xxx*10 - (unless below DIV) 3103+bbb*10 BF [FExx].n,rel ;n=0..7 3183+xxx*10 - 3104+xxx*10 - 3184+xxx*10 - 3105+bbb*10 BTCLR [FFxx].n,rel ;n=0..7 3185+bbb*10 BTCLR [HL].n,rel ;n=0..7 3106+bbb*10 BT [FFxx].n,rel ;n=0..7 3186+bbb*10 BT [HL].n,rel ;n=0..7 3107+bbb*10 BF [FFxx].n,rel ;n=0..7 3187+bbb*10 BF [HL].n,rel ;n=0..7 3108+xxx*10 - 3188+xxx*10 - (unless below MUL/BR) 3109+xxx*10 - 3189+xxx*10 - 310A+xxx*10 <see below ADD/SUB/ADDC/SUBC/CMP/AND/OR/XOR) 318A+xxx*10 - (unless below XCH) 310B+xxx*10 <see below ADD/SUB/ADDC/SUBC/CMP/AND/OR/XOR) 318B+xxx*10 - (unless below XCH) 310C+xxx*10 - 318C+xxx*10 - 310D+bbb*10 BTCLR A.n,rel ;n=0..7 318D+xxx*10 - 310E+bbb*10 BT A.n,rel ;n=0..7 318E+xxx*10 - 310F+bbb*10 BF A.n,rel ;n=0..7 318F+xxx*10 - 310A ADD A,[HL+C] 310B ADD A,[HL+B] 311A SUB A,[HL+C] 311B SUB A,[HL+B] 312A ADDC A,[HL+C] 312B ADDC A,[HL+B] 313A SUBC A,[HL+C] 313B SUBC A,[HL+B] 314A CMP A,[HL+C] 314B CMP A,[HL+B] 315A AND A,[HL+C] 315B AND A,[HL+B] 316A OR A,[HL+C] 316B OR A,[HL+B] 317A XOR A,[HL+C] 317B XOR A,[HL+B] 318A XCH A,[HL+C] 318B XCH A,[HL+B] 3180 ROL4 A,[HL] ;rol 12bit A.lsb:[HL],4 ;native: ROL4 [HL] 3190 ROR4 A,[HL] ;ror 12bit A.lsb:[HL],4 ;native: ROR4 [HL] 3182 DIVUW AX,C ;unsigned AX=AX/C, C=remainder ;native: DIVWU C 3188 MULU AX,A,X ;unsigned AX=A*X ;native: MULU X 3198 BR AX |
6100+rrr ADD r,A ;r=X,A,C,B,E,D,L,H 6108+rrr ADD A,r ;r=X,-,C,B,E,D,L,H 6110+rrr SUB r,A ;r=X,A,C,B,E,D,L,H 6118+rrr SUB A,r ;r=X,-,C,B,E,D,L,H 6120+rrr ADDC r,A ;r=X,A,C,B,E,D,L,H 6128+rrr ADDC A,r ;r=X,-,C,B,E,D,L,H 6130+rrr SUBC r,A ;r=X,A,C,B,E,D,L,H 6138+rrr SUBC A,r ;r=X,-,C,B,E,D,L,H 6140+rrr CMP r,A ;r=X,A,C,B,E,D,L,H 6148+rrr CMP A,r ;r=X,-,C,B,E,D,L,H 6150+rrr AND r,A ;r=X,A,C,B,E,D,L,H 6158+rrr AND A,r ;r=X,-,C,B,E,D,L,H 6160+rrr OR r,A ;r=X,A,C,B,E,D,L,H 6168+rrr OR A,r ;r=X,-,C,B,E,D,L,H 6170+rrr XOR r,A ;r=X,A,C,B,E,D,L,H 6178+rrr XOR A,r ;r=X,-,C,B,E,D,L,H 6180+xxx*10 - (unless below ADJ/SEL) 6181+xxx*10 - 6182+xxx*10 - 6183+xxx*10 - 6184+xxx*10 - 6185+xxx*10 - 6186+xxx*10 - 6187+xxx*10 - 6188+xxx*10 - (unless below ADJ/SEL) 6189+bbb*10 MOV1 A.n,CY ;n=0..7 618A+bbb*10 SET1 A.n ;n=0..7 618B+bbb*10 CLR1 A.n ;n=0..7 618C+bbb*10 MOV1 CY,A.n ;n=0..7 618D+bbb*10 AND1 CY,A.n ;n=0..7 618E+bbb*10 OR1 CY,A.n ;n=0..7 618F+bbb*10 XOR1 CY,A.n ;n=0..7 6180 ADJBA ;Decimal BCD adjust A after Addition 6190 ADJBS ;Decimal BCD adjust A after Subtraction 61D0 SEL RB0 61D8 SEL RB1 61F0 SEL RB2 61F8 SEL RB3 |
7100+xxx*10 - (unless below STOP/HALT) 7180+xxx*10 - 7101+bbb*10 MOV1 [FExx].n,CY ;n=0..7 7181+bbb*10 MOV1 [HL].n,CY ;n=0..7 7102+xxx*10 - 7182+bbb*10 SET1 [HL].n ;n=0..7 7103+xxx*10 - 7183+bbb*10 CLR1 [HL].n ;n=0..7 7104+bbb*10 MOV1 CY,[FExx].n ;n=0..7 7184+bbb*10 MOV1 CY,[HL].n ;n=0..7 7105+bbb*10 AND1 CY,[FExx].n ;n=0..7 7185+bbb*10 AND1 CY,[HL].n ;n=0..7 7106+bbb*10 OR1 CY,[FExx].n ;n=0..7 7186+bbb*10 OR1 CY,[HL].n ;n=0..7 7107+bbb*10 XOR1 CY,[FExx].n ;n=0..7 7187+bbb*10 XOR1 CY,[HL].n ;n=0..7 7108+xxx*10 - 7188+xxx*10 - 7109+bbb*10 MOV1 [FFxx].n,CY ;n=0..7 7189+xxx*10 - 710A+bbb*10 SET1 [FFxx].n ;n=0..7 718A+xxx*10 - 710B+bbb*10 CLR1 [FFxx].n ;n=0..7 718B+xxx*10 - 710C+bbb*10 MOV1 CY,[FFxx].n ;n=0..7 718C+xxx*10 - 710D+bbb*10 AND1 CY,[FFxx].n ;n=0..7 718D+xxx*10 - 710E+bbb*10 OR1 CY,[FFxx].n ;n=0..7 718E+xxx*10 - 710F+bbb*10 XOR1 CY,[FFxx].n ;n=0..7 718F+xxx*10 - 7100 STOP 7110 HALT |
| 78K/0 Memory Map and SFRs |
78K0/Kx2 User's Manual: Hardware ;info on I/O Ports 78K0/Kx2 Flash Memory Self Programming ;info on 8100h function 78K0/Kx2 Flash Memory Programming ;info on UART/SPI cable 78K/0 Series Instructions ;info on opcodes 78K0/KB2 One-sheet Manual ;quick reference poster |
0000h..003Fh FLASH ROM Exception Vectors (16bit each)
0040h..007Fh FLASH ROM CALLT Vectors (16bit each)
0080h..0084h FLASH ROM Option Byte Area (5 bytes)
0085h..008Eh FLASH ROM Debug Security Area (10 bytes, if any)
008Fh..07FFh FLASH ROM
0800h..0FFFh FLASH ROM (accessible via CALLF opcodes)
1000h..1FFFh FLASH ROM (can be swapped with 0000h..0FFFh)
2000h..xFFFh FLASH ROM (if any, in larger chips)
8000h..BFFFh FLASH ROM (if any, in larger chips) (bank-switched via BANK)
8000h..9FFFh System ROM area (when mapped, with function handler at 8100h)
A000h..BFFFh System ROM mirror (same as 8000h..9FFFh)
C000h.. System ROM empty (mostly FFh-filled, some FEh-bytes)
E000h..F7FFh Extra RAM (max 6K, if any) (mostly FFh-filled, some F0h-bytes)
F800h..F8FFh Undoc SFR's
F900h..FAFFh Zerofilled
FB00h..FBFFh Unknown (filled with random values) (more RAM?) (unused in DSi)
(FB00h is ONLY mapped when ROM enabled, otherwise FFh-filled)
FC00h..FF1Fh RAM (officially/used area)
FE20h..FEDFh RAM (accessible via short "saddr" opcodes)
FEE0h..FEE7h Register Bank 3 (X,A,C,B,E,D,L,H aka AX,BC,DE,HL)
FEE8h..FEEFh Register Bank 2 (X,A,C,B,E,D,L,H aka AX,BC,DE,HL)
FEF0h..FEF7h Register Bank 1 (X,A,C,B,E,D,L,H aka AX,BC,DE,HL)
FEF8h..FEFFh Register Bank 0 (X,A,C,B,E,D,L,H aka AX,BC,DE,HL)
FF00h..FFFFh Special Function Registers (SFR's)
|
0000h RESET input, POC, LVI, WDT 0002h - 0004h INTLVI 0006h INTP0 0008h INTP1 000Ah INTP2 000Ch INTP3 000Eh INTP4 0010h INTP5 0012h INTSRE6 0014h INTSR6 0016h INTST6 0018h INTCSI10/INTST0 001Ah INTTMH1 001Ch INTTMH0 001Eh INTTM50 0020h INTTM000 0022h INTTM010 0024h INTAD 0026h INTSR0 0028h INTWTI 002Ah INTTM51 002Ch INTKR 002Eh INTWT 0030h INTP6 0032h INTP7 0034h INTIIC0/NTDMU 0036h INTCSI11 0038h INTTM001 003Ah INTTM011 003Ch INTACSI 003Eh BRK |
0080h db 07Eh ;Option Byte: Watchdog Mode
0081h db 000h ;Option Byte: POC Mode (0=1.59V, 1=2.7V)
0082h db 000h ;Option Byte: Reserved (00h)
0083h db 000h ;Option Byte: Reserved (00h)
0084h db 000h ;Option Byte: On-chip Debug Control (0=Off)
;---
0085h db 0CCh ;On-chip debug security ID (0Ah bytes) ...
0086h db 023h
0087h db 0BAh
0088h db 0C3h
0089h db 07Dh
008Ah db 094h
008Bh db 0FEh
008Ch db 073h
008Dh db 0A5h
008Eh db 0E6h
|
7 IE ;Interrupt Enable 6 Z ;Zero Flag 5 RBS1 ;Register Bank Select bit1 4 AC ;Aux Carry Flag 3 RBS0 ;Register Bank Select bit0 2 0 1 ISP ;In-Service Priority Flag 0 CY ;Carry Flag |
Addr Symbol R/W 1BW Reset BCDEF Special Function Register (SFR) FF00h P0 R/W 1B- 00h BCDEF Port 0 FF01h P1 R/W 1B- 00h BCDEF Port 1 FF02h P2 R/W 1B- 00h BCDEF Port 2 FF03h P3 R/W 1B- 00h BCDEF Port 3 FF04h P4 R/W 1B- 00h -CDEF Port 4 FF05h P5 R/W 1B- 00h ---EF Port 5 FF06h P6 R/W 1B- 00h BCDEF Port 6 FF07h P7 R/W 1B- 00h -CDEF Port 7 FF08h ADCR R --W 0000h BCDEF 10-bit A/D conversion result FF09h ADCRH R -B- 00h BCDEF 8-bit A/D conversion result FF0Ah RXB6 R -B- FFh BCDEF Receive buffer 6 FF0Bh TXB6 R/W -B- FFh BCDEF Transmit buffer 6 FF0Ch P12 R/W 1B- 00h BCDEF Port 12 FF0Dh P13 R/W 1B- 00h -cDEF Port 13 (KC2: 48pin only) FF0Eh P14 R/W 1B- 00h -cDEF Port 14 (KC2: 48pin only) FF0Fh SIO10 R -B- 00h BCDEF Serial I/O shift 10 FF10h TM00 R --W 0000h BCDEF 16-bit timer counter 00 FF12h CR000 R/W --W 0000h BCDEF 16-bit timer capture/compare 000 FF14h CR010 R/W --W 0000h BCDEF 16-bit timer capture/compare 010 FF16h TM50 R -B- 00h BCDEF 8-bit timer counter 50 FF17h CR50 R/W -B- 00h BCDEF 8-bit timer compare 50 FF18h CMP00 R/W -B- 00h BCDEF 8-bit timer H compare 00 FF19h CMP10 R/W -B- 00h BCDEF 8-bit timer H compare 10 FF1Ah CMP01 R/W -B- 00h BCDEF 8-bit timer H compare 01 FF1Bh CMP11 R/W -B- 00h BCDEF 8-bit timer H compare 11 FF1Ch SP R/W --W xxxxh BCDEF CPU Stack Pointer ;\undocumented, used FF1Eh PSW R/W 1B- xxh BCDEF CPU Program Status Word;/in pseudo opcodes FF1Fh TM51 R -B- 00h BCDEF 8-bit timer counter 51 FF20h PM0 R/W 1B- FFh BCDEF Port mode 0 FF21h PM1 R/W 1B- FFh BCDEF Port mode 1 FF22h PM2 R/W 1B- FFh BCDEF Port mode 2 FF23h PM3 R/W 1B- FFh BCDEF Port mode 3 FF24h PM4 R/W 1B- FFh -CDEF Port mode 4 FF25h PM5 R/W 1B- FFh ---EF Port mode 5 FF26h PM6 R/W 1B- FFh BCDEF Port mode 6 FF27h PM7 R/W 1B- FFh -CDEF Port mode 7 FF28h ADM R/W 1B- 00h BCDEF A/D converter mode FF29h ADS R/W 1B- 00h BCDEF Analog input channel specification FF2Ch PM12 R/W 1B- FFh BCDEF Port mode 12 FF2Eh PM14 R/W 1B- FFh -cDEF Port mode 14 (KC2: 48pin only) FF2Fh ADPC R/W 1B- 00h BCDEF A/D port configuration FF30h PU0 R/W 1B- 00h BCDEF Pull-up resistor option 0 FF31h PU1 R/W 1B- 00h BCDEF Pull-up resistor option 1 FF33h PU3 R/W 1B- 00h BCDEF Pull-up resistor option 3 FF34h PU4 R/W 1B- 00h -CDEF Pull-up resistor option 4 FF35h PU5 R/W 1B- 00h ---EF Pull-up resistor option 5 FF36h PU6 R/W 1B- 00h ----F Pull-up resistor option 6 FF37h PU7 R/W 1B- 00h -CDEF Pull-up resistor option 7 FF3Ch PU12 R/W 1B- 00h BCDEF Pull-up resistor option 12 FF3Eh PU14 R/W 1B- 00h -cDEF Pull-up resistor option 14 (KC2: 48pin only) FF40h CKS R/W 1B- 00h -cDEF Clock output selection (KC2: 48pin only) FF41h CR51 R/W -B- 00h BCDEF 8-bit timer compare 51 FF43h TMC51 R/W 1B- 00h BCDEF 8-bit timer mode control 51 FF48h EGP R/W 1B- 00h BCDEF External interrupt rising edge enable FF49h EGN R/W 1B- 00h BCDEF External interrupt falling edge enable FF4Ah SIO11 R -B- 00h ---eF Serial I/O shift 11 (KE2: 48KB only) FF4Ch SOTB11 R/W -B- 00h ---eF Transmit buffer 11 (KE2: 48KB only) FF4Fh ISC R/W 1B- 00h BCDEF Input switch control FF50h ASIM6 R/W 1B- 01h BCDEF Async serial interface operation mode 6 FF53h ASIS6 R -B- 00h BCDEF Async serial interface reception err/stat 6 FF55h ASIF6 R -B- 00h BCDEF Async serial interface transmission status 6 FF56h CKSR6 R/W -B- 00h BCDEF Clock selection 6 FF57h BRGC6 R/W -B- FFh BCDEF Baud rate generator control 6 FF58h ASICL6 R/W 1B- 16h BCDEF Async serial interface control 6 FF60h SDR0 R -BW 0000h -cdeF Remainder data 0 bit0.. ;\ FF61h SDR0H R -B- 00h -cdeF Remainder data 0 bit8.. ; FF62h MDA0L R/W -BW 0000h -cdeF Multiply/divide data A0 bit0.. ; KC2-KE2: FF63h MDA0LH R/W -B- 00h -cdeF Multiply/divide data A0 bit8.. ; 48KB only FF64h MDA0H R/W -BW 0000h -cdeF Multiply/divide data A0 bit16.. ; FF65h MDA0HH R/W -B- 00h -cdeF Multiply/divide data A0 bit24.. ; FF66h MDB0 R/W -BW 0000h -cdeF Multiply/divide data B0 bit0.. ; FF67h MDB0H R/W -B- 00h -cdeF Multiply/divide data B0 bit8.. ; FF68h DMUC0 R/W 1B- 00h -cdeF Multiply/divide control 0 ;/ FF69h TMHMD0 R/W 1B- 00h BCDEF 8-bit timer H mode 0 FF6Ah TCL50 R/W 1B- 00h BCDEF Timer clock selection 50 FF6Bh TMC50 R/W 1B- 00h BCDEF 8-bit timer mode control 50 FF6Ch TMHMD1 R/W 1B- 00h BCDEF 8-bit timer H mode 1 FF6Dh TMCYC1 R/W 1B- 00h BCDEF 8-bit timer H carrier control 1 FF6Eh KRM R/W 1B- 00h -CDEF Key return mode FF6Fh WTM R/W 1B- 00h -CDEF Watch timer operation mode FF70h ASIM0 R/W 1B- 01h BCDEF Async serial interface operation mode 0 FF71h BRGC0 R/W -B- 1Fh BCDEF Baud rate generator control 0 FF72h RXB0 R -B- FFh BCDEF Receive buffer 0 FF73h ASIS0 R -B- 00h BCDEF Async serial interface reception err/stat 0 FF74h TXS0 W -B- FFh BCDEF Transmit shift 0 FF80h CSIM10 R/W 1B- 00h BCDEF Serial operation mode 10 FF81h CSIC10 R/W 1B- 00h BCDEF Serial clock selection 10 FF84h SOTB10 R/W -B- 00h BCDEF Transmit buffer 10 FF88h CSIM11 R/W 1B- 00h ---eF Serial operation mode 11 (KE2: 48KB only) FF89h CSIC11 R/W 1B- 00h ---eF Serial clock selection 11 (KE2: 48KB only) FF8Ch TCL51 R/W 1B- 00h BCDEF Timer clock selection 51 FF90h CSIMA0 R/W 1B- 00h ----F Serial operation mode specification 0 FF91h CSIS0 R/W 1B- 00h ----F Serial status 0 FF92h CSIT0 R/W 1B- 00h ----F Serial trigger 0 FF93h BRGCA0 R/W -B- 03h ----F Division value selection 0 FF94h ADTP0 R/W -B- 00h ----F Automatic data transfer address point spec 0 FF95h ADTI0 R/W -B- 00h ----F Automatic data transfer interval spec 0 FF96h SIOA0 R/W -B- 00h ----F Serial I/O shift 0 FF97h ADTC0 R -B- 00h ----F Automatic data transfer address count 0 FF99h WDTE R/W -B- xAh BCDEF Watchdog timer enable (initial=1Ah/9Ah) FF9Fh OSCCTL R/W 1B- 00h BCDEF Clock operation mode select FFA0h RCM R/W 1B- x0h BCDEF Internal oscillation mode FFA1h MCM R/W 1B- 00h BCDEF Main clock mode FFA2h MOC R/W 1B- 80h BCDEF Main OSC control FFA3h OSTC R 1B- 00h BCDEF Oscillation stabilization time counter stat FFA4h OSTS R/W -B- 05h BCDEF Oscillation stabilization time select FFA5h IIC0 R/W -B- 00h BCDEF IIC shift 0 FFA6h IICC0 R/W 1B- 00h BCDEF IIC control 0 FFA7h SVA0 R/W -B- 00h BCDEF Slave address 0 FFA8h IICCL0 R/W 1B- 00h BCDEF IIC clock selection 0 FFA9h IICX0 R/W 1B- 00h BCDEF IIC function expansion 0 FFAAh IICS0 R 1B- 00h BCDEF IIC status 0 FFABh IICF0 R/W 1B- 00h BCDEF IIC flag 0 FFACh RESF R -B- xxh BCDEF Reset control flag FFB0h TM01 R --W 0000h ---eF 16-bit timer counter 01 ;\ FFB2h CR001 R/W --W 0000h ---eF 16-bit timer capture/compare 001 ; FFB4h CR011 R/W --W 0000h ---eF 16-bit timer capture/compare 011 ; KE2: FFB6h TMC01 R/W 1B- 00h ---eF 16-bit timer mode control 01 ; 48KB FFB7h PRM01 R/W 1B- 00h ---eF Prescaler mode 01 ; only) FFB8h CRC01 R/W 1B- 00h ---eF Capture/compare control 01 ; FFB9h TOC01 R/W 1B- 00h ---eF 16-bit timer output control 01 ;/ FFBAh TMC00 R/W 1B- 00h BCDEF 16-bit timer mode control 00 FFBBh PRM00 R/W 1B- 00h BCDEF Prescaler mode 00 FFBCh CRC00 R/W 1B- 00h BCDEF Capture/compare control 00 FFBDh TOC00 R/W 1B- 00h BCDEF 16-bit timer output control 00 FFBEh LVIM R/W 1B- xxh BCDEF Low-voltage detection FFBFh LVIS R/W 1B- xxh BCDEF Low-voltage detection level selection FFC0h PFCMD W? ?B? ? ? Undoc: Flash Protect Command (write A5h) FFC1h - R/W 1B- ? ? Undoc: Flash ... FFC1h ... bits/pulses FSSQ ? FFC2h PFS R ? ? Undoc: Flash Protect Status FFC4h FLPMC R/W 1B? ? ? Undoc: Flash Programming Mode Ctl ;triple write FFC5h - W 1?- ? ? Undoc: Flash ... 0FFC5h ... bits/mode ? FFC6h FLAPH W 1B- ? ? Undoc: Flash addr ptr upper 8bit (bit1=flag) FFC7h - R/W 1?- ? ? Undoc: Flash ... 0FFC7h ... flag bits FFC8h FLAPL W 1BW ? ? Undoc: Flash addr ptr lower 16bit (bit0,1=flag) FFCAh - R/W ?B? ? ? Undoc: Flash ... 0FFCAh ... ;triple write FFCBh FLWE W ?B- ? ? Undoc: Flash write data ECC error correction? FFCCh FLWH W -BW ? ? Undoc: Flash write data upper 16bit ;\4-byte FFCEh FLWL W -BW ? ? Undoc: Flash write data lower 16bit ;/ FFE0h IF0L R/W 1BW 00h BCDEF Interrupt request flag 0L ;\IF0 FFE1h IF0H R/W 1BW 00h BCDEF Interrupt request flag 0H ;/ FFE2h IF1L R/W 1BW 00h BCDEF Interrupt request flag 1L ;\IF1 FFE3h IF1H R/W 1BW 00h BCDEF Interrupt request flag 1H ;/ FFE4h MK0L R/W 1BW FFh BCDEF Interrupt mask flag 0L ;\MK0 FFE5h MK0H R/W 1BW FFh BCDEF Interrupt mask flag 0H ;/ FFE6h MK1L R/W 1BW FFh BCDEF Interrupt mask flag 1L ;\MK1 FFE7h MK1H R/W 1BW FFh BCDEF Interrupt mask flag 1H ;/ FFE8h PR0L R/W 1BW FFh BCDEF Priority specification flag 0L ;\PR0 FFE9h PR0H R/W 1BW FFh BCDEF Priority specification flag 0H ;/ FFEAh PR1L R/W 1BW FFh BCDEF Priority specification flag 1L ;\PR1 FFEBh PR1H R/W 1BW FFh BCDEF Priority specification flag 1H ;/ FFF0h IMS R/W -B- CFh BCDEF Internal memory size switching FFF3h BANK R/W -B- 00h --def Memory bank select (KD2-KF2: min 96KB only) FFF4h IXS R/W -B- 0Ch bcdeF Internal expansion RAM size switching FFF5h - R ?B- ? ? Undoc: chip_id (package type and memory size) FFFBh PCC R/W 1B- 01h BCDEF Processor clock control |
F800h..F0h - --- ? ? Undoc: unknown values, unused by software F8F1h FLrE R -B- ? ? Undoc: Flash read data ECC error correction? F8F2h FLrH R -BW ? ? Undoc: Flash read data upper 16bit ;\4-byte F8F4h FLrL R -BW ? ? Undoc: Flash read data lower 16bit ;/total F8F6h ??? R/W --W ? ? Undoc: Flash ...0F8F6h_word ;-16bit F8F8h - - --- ? ? Undoc: ;(unused by software) F8F9h ??? R/W -B- ? ? Undoc: Flash ...0F8F9h ;- F8FAh - - --- ? ? Undoc: ;(unused by software) F8FBh - - --- ? ? Undoc: ;(unused by software) F8FCh - - --- ? ? Undoc: ;(unused by software) F8FDh - - --- ? ? Undoc: ;(unused by software) F8FEh - - --- ? ? Undoc: ;(unused by software) F8FFh - - --- ? ? Undoc: ;(unused by software) |
1BT = supports Bit/Byte/Word access (1bit/8bit/16bit) BCDEF = supported on KB2/KC2/KD2/KE2/KF2 chip versions |
| DSi Autoload on Warmboot |
2000000h Autoload Parameters for newly loaded title ;<-- optional extra 2000300h Autoload via numeric Title ID ;<-- official method 2000800h Autoload via string "device:\path\filename" ;<-- alternate method 2FFD800h Title List (jump-able titles for use at 2000300h) BPTWL[70h].bit0 Warmboot flag ;<-- required flag BPTWL[11h].bit0 Trigger reset ;<-- trigger reset |
2000000h 8 AutoParam Old Title ID (former title) ;carthdr[230h] 2000008h 1 AutoParam Unknown/Unused 2000009h 1 AutoParam Flags (03h=Stuff is used?) 200000Ah 2 AutoParam Old Maker code ;carthdr[010h] 200000Ch 2 AutoParam Unknown (02ECh) ;\counter/length/indices/whatever? 200000Eh 2 AutoParam Unknown (0000h) ;/ 2000010h 2 AutoParam CRC16 on [000h..2FFh], initial=FFFFh, [010h]=0000h 2000012h 2 AutoParam Unknown/Unused (000Fh = want Internet Settings?) 2000014h 2ECh AutoParam Unknown... some buffer... string maybe? |
2000300h 4 AutoLoad ID ("TLNC")
2000304h 1 AutoLoad Unknown/unused (usually 01h)
2000305h 1 AutoLoad Length of data at 2000308h (01h..18h,for CRC,18h=norm)
2000306h 2 AutoLoad CRC16 of data at 2000308h (with initial value FFFFh)
2000308h 8 AutoLoad Old Title ID (former title) (can be 0=anonymous)
2000310h 8 AutoLoad New Title ID (new title to be started,0=none/launcher)
2000318h 4 AutoLoad Flags (bit0, 1-3, 4, 5,6,7) ;usually 16bit, once 32bit
200031Ch 4 AutoLoad Unused (but part of checksummed area when CRC len=18h)
2000320h E0h AutoLoad Unused (but zerofilled upon erasing autoload area)
|
0 IsValid (somehow enables/disables HealthSafety when TitleID is wrong?) 1-3 Boottype (01h=Cartridge, 02h=Landing, 03h=DSiware) (see below) 4 Unknown 5 Unknown 6 LoadCompl (causes some error when set) (loading completed flag?) 7 Unknown 8-15 Unused 16-31 Unused (usually not accessed at all, with normal 16bit reads) |
01h = Cartridge (with NewTitleID) (with RSA signed header, or Whitelisted)
02h = Landing ("nand:/tmp/jump.app") (with RSA signed DownloadPlay footer)
03h = DSiware (with NewTitleID) (with RSA signed header)
|
2000800h 12 Unlaunch Auto-load ID ("AutoLoadInfo")
200080Ch 2 Unlaunch Length for CRC16 (fixed, must be 3F0h)
200080Eh 2 Unlaunch CRC16 (across 2000810h..2000BFFh, initial value FFFFh)
2000810h 4 Unlaunch Flags
2000814h 2 Unlaunch Upper screen BG color (0..7FFFh)
2000816h 2 Unlaunch Lower screen BG color (0..7FFFh)
2000818h 20h Unlaunch Reserved (zero)
2000838h 208h Unlaunch Device:/Path/Filename.ext (16bit Unicode,end by 0000h)
2000A40h 1C0h Unlaunch Reserved (zero)
|
0 Load the title at 2000838h 1 Use colors 2000814h (use if loaded title is KNOWN to use such colors) 2-31 Reserved (zero) |
"nand:/path/name.ext",0000h File on 1st partition of internal eMMC "sdmc:/path/name.ext",0000h File on 1st partition of external SD/MMC "cart:",0000h ROM cartridge (in NDS cartridge slot) "menu:",0000h Force starting unlaunch filemenu "sett:",0000h Force starting unlaunch options menu "wifi:",0000h Force starting unlaunch wifiboot overlay |
2FFD800h 1 Titles: Number of titles in below lists (max 76h) 2FFD801h 0Fh Titles: Zerofilled 2FFD810h 10h Titles: Pub Flags (1bit each) ;same maker plus public.sav 2FFD820h 10h Titles: Prv Flags (1bit each) ;same maker plus private.sav 2FFD830h 10h Titles: Jmp Flags (1bit each) ;jumpable or current-title 2FFD840h 10h Titles: Mkr Flags (1bit each) ;same maker 2FFD850h 3B0h Titles: Title IDs (8 bytes each) |
[010h].bit0-15 Maker (must match current title for Mkr Flags) [01Dh].bir0 Jump (must be set for Jmp Flags) [230h].bit0-63 Title ID (must be nonzero for being listed) [238h].bit0-31 Public.sav size (must be nonzero for Pub Flags) [23Ch].bit0-31 Private.sav size (must be nonzero for Prv Flags) |
00030015484E42xxh ;System Settings 00030005484E4441h ;DS Download Play 00030005484E4541h ;Pictochat 00030004484E47xxh ;Nintendo DSi Browser (if installed) |
| DSi Aptina Camera Initialization |
AptWr ,0001Ah,00003h ;RESET_AND_MISC_CONTROL (issue reset) ;\reset
AptWr ,0001Ah,00000h ;RESET_AND_MISC_CONTROL (release reset) ;/
AptWr ,00018h,04028h ;STANDBY_CONTROL (wakeup) ;\
AptWr ,0001Eh,00201h ;PAD_SLEW ; wakeup
AptWr ,00016h,042DFh ;CLOCKS_CONTROL ;
AptWaitClr,00018h,04000h ;STANDBY_CONTROL (wait for WakeupDone) ;
AptWaitSet,0301Ah,00004h ;UNDOC_CORE_301A (wait for WakeupDone) ;/
AptWrMcu ,002F0h,00000h ;UNDOC! RAM?
AptWrMcu ,002F2h,00210h ;UNDOC! RAM?
AptWrMcu ,002F4h,0001Ah ;UNDOC! RAM?
AptWrMcu ,02145h,002F4h ;UNDOC! SEQ?
AptWrMcu ,0A134h, 001h ;UNDOC! SEQ?
AptSetMcu ,0A115h, 002h ;SEQ_CAP_MODE (set bit1=video)
AptWrMcu ,02755h,00002h ;MODE_OUTPUT_FORMAT_A (bit5=0=YUV) ;\select
AptWrMcu ,02757h,00002h ;MODE_OUTPUT_FORMAT_B ;/YUV mode
AptWr ,00014h,02145h ;PLL_CONTROL ;\
AptWr ,00010h,00111h ;PLL_DIVIDERS ; match
AptWr ,00012h,00000h ;PLL_P_DIVIDERS ; PLL
AptWr ,00014h,0244Bh ;PLL_CONTROL ; to DSi
AptWr ,00014h,0304Bh ;PLL_CONTROL ; timings
AptWaitSet,00014h,08000h ;PLL_CONTROL (wait for PLL Lock okay) ;
AptClr ,00014h,00001h ;PLL_CONTROL (disable PLL Bypass) ;/
AptWrMcu ,02703h,00100h ;MODE_OUTPUT_WIDTH_A ;\Size A
AptWrMcu ,02705h,000C0h ;MODE_OUTPUT_HEIGHT_A ;/ 256x192
AptWrMcu ,02707h,00280h ;MODE_OUTPUT_WIDTH_B ;\Size B
AptWrMcu ,02709h,001E0h ;MODE_OUTPUT_HEIGHT_B ;/ 640x480
AptWrMcu ,02715h,00001h ;MODE_SENSOR_ROW_SPEED_A ;\
AptWrMcu ,02719h,0001Ah ;MODE_SENSOR_FINE_CORRECTION_A ;
AptWrMcu ,0271Bh,0006Bh ;MODE_SENSOR_FINE_IT_MIN_A ; Sensor A
AptWrMcu ,0271Dh,0006Bh ;MODE_SENSOR_FINE_IT_MAX_MARGIN_A ;
AptWrMcu ,0271Fh,002C0h ;MODE_SENSOR_FRAME_LENGTH_A ;
AptWrMcu ,02721h,0034Bh ;MODE_SENSOR_LINE_LENGTH_PCK_A ;/
AptWrMcu ,0A20Bh, 000h ;AE_MIN_INDEX ;\AE min/max
AptWrMcu ,0A20Ch, 006h ;AE_MAX_INDEX ;/
AptWrMcu ,0272Bh,00001h ;MODE_SENSOR_ROW_SPEED_B ;\
AptWrMcu ,0272Fh,0001Ah ;MODE_SENSOR_FINE_CORRECTION_B ;
AptWrMcu ,02731h,0006Bh ;MODE_SENSOR_FINE_IT_MIN_B ; Sensor B
AptWrMcu ,02733h,0006Bh ;MODE_SENSOR_FINE_IT_MAX_MARGIN_B ;
AptWrMcu ,02735h,002C0h ;MODE_SENSOR_FRAME_LENGTH_B ;
AptWrMcu ,02737h,0034Bh ;MODE_SENSOR_LINE_LENGTH_PCK_B ;/
AptSet ,03210h,00008h ;COLOR_PIPELINE_CONTROL (PGA pixel shading..)
AptWrMcu ,0A208h, 000h ;UNDOC! RESERVED_AE_08
AptWrMcu ,0A24Ch, 020h ;AE_TARGETBUFFERSPEED
AptWrMcu ,0A24Fh, 070h ;AE_BASETARGET
If Device=7Ah ;\
AptWrMcu,02717h,00024h ;MODE_SENSOR_READ_MODE_A ; Read Mode
AptWrMcu,0272Dh,00024h ;MODE_SENSOR_READ_MODE_B ; with x-flip
Else (xflip) ; on internal
AptWrMcu,02717h,00025h ;MODE_SENSOR_READ_MODE_A ; camera
AptWrMcu,0272Dh,00025h ;MODE_SENSOR_READ_MODE_B ;/
If Device=7Ah ;\
AptWrMcu,0A202h, 022h ;AE_WINDOW_POS ;
AptWrMcu,0A203h, 0BBh ;AE_WINDOW_SIZE ;
Else (?) ;
AptWrMcu,0A202h, 000h ;AE_WINDOW_POS ;
AptWrMcu,0A203h, 0FFh ;AE_WINDOW_SIZE ;/
AptSet ,00016h,00020h ;CLOCKS_CONTROL (set bit5=1, reserved)
AptWrMcu ,0A115h, 072h ;SEQ_CAP_MODE (was already manipulated above)
AptWrMcu ,0A11Fh, 001h ;SEQ_PREVIEW_1_AWB ;\
If Device=7Ah ;
AptWr ,0326Ch,00900h ;APERTURE_PARAMETERS ;
AptWrMcu,0AB22h, 001h ;HG_LL_APCORR1 ;
Else (?) ;
AptWr ,0326Ch,01000h ;APERTURE_PARAMETERS ;
AptWrMcu,0AB22h, 002h ;HG_LL_APCORR1 ;/
AptWrMcu ,0A103h, 006h ;SEQ_CMD (06h=RefreshMode)
AptWaitMcuClr,0A103h, 00Fh ;SEQ_CMD (wait above to become ZERO)
AptWrMcu ,0A103h, 005h ;SEQ_CMD (05h=Refresh)
AptWaitMcuClr,0A103h, 00Fh ;SEQ_CMD (wait above to become ZERO)
|
AptClr ,00018h,00001h ;STANDBY_CONTROL (bit0=0=wakeup) ;\ AptWaitClr,00018h,04000h ;STANDBY_CONTROL (wait for WakeupDone) ; Wakeup AptWaitSet,0301Ah,00004h ;UNDOC_CORE_301A (wait for WakeupDone) ;/ AptWr ,03012h,000xxh ;COARSE_INTEGRATION_TIME (Y Time) AptSet ,0001Ah,00200h ;RESET_AND_MISC_CONTROL (Parallel On) ;-Data on |
AptClr ,0001Ah,00200h ;RESET_AND_MISC_CONTROL (Parallel Off) ;-Data off AptSet ,00018h,00001h ;STANDBY_CONTROL (set bit0=1=Standby) ;\ AptWaitSet,00018h,04000h ;STANDBY_CONTROL (wait for StandbyDone) ; Standby AptWaitClr,0301Ah,00004h ;UNDOC_CORE_301A (wait for StandbyDone) ;/ |
| DSi Aptina Camera Registers: SYSCTL (0000h-0051h) |
0000h 2 CHIP_VERSION_REG Model ID (2280h=MT9V113 on DSi/3DS) (R)
0006h .. RESERVED_SYSCTL_06 Reserved
0010h 2 PLL_DIVIDERS PLL Dividers (def=0366h)
0-7 PLL M-Divider value (uh, actually a Multiplier?!)
8-13 PLL N-Divider value
14-15 Unused (0)
Because the input clock frequency is unknown, the sensor starts
up with the PLL disabled. The PLL takes time to power up. During
this time, the behavior of its output clock signal is not
guaranteed. The PLL output frequency is determined by two
constants, M and N, and the input clock frequency.
VCO = Fin * 2 * M / (N+1)
PLL_output_frequency = VCO / (P1+1)
The PLL can generate a master clock signal whose frequency is up
to 85 MHz (input clock from 6 MHz through 54 MHz).
0012h 2 PLL_P_DIVIDERS PLL P Dividers (def=00F5h)
0-3 P1 (00h..0Fh)
4-7 Unspecified
8-11 P3 (00h..0Fh)
12-13 Division ratio of word clock/clockn from bit_clock (0..3)
14 Unused (0)
15 Unspecified
0014h 2 PLL_CONTROL PLL Control (def=21F9h)
0 PLL Bypass
1 PLL Enable
2-3 Reserved (0..3)
4-7 Reserved (0..0Fh)
8 Reset_cntr
9 Reserved
10 Reserved
11 Reserved
12 Reserved
13 Reserved
14 Unused (0)
15 PLL Lock (R)
0016h 2 CLOCKS_CONTROL Clocks Control
0 Reserved
1 Reserved
2 Reserved
3 Reserved
4 Reserved
5 Reserved/UNDOC/USED (manipulated by DSi)
6 Reserved
7 Reserved
8 Reserved
9 clk_clkin_en
11-12 Reserved
13 Reserved
15 Reserved
0018h 2 STANDBY_CONTROL Standby Control and Status (def=4029h)
0 Ship (uh?) (0=Enable various regs, 1=Standby)
1 Reserved
2 Stop MCU
3 en_IRQ
4 Reserved
5 Reserved
6-13 Unused (0)
14 Standby_done (0=WakeupDone, 1=StandbyDone) (R?)
(takes MUCH time?)
15 Reserved (R)
001Ah 2 RESET_AND_MISC_CONTROL Reset and Control (def=0050h) (0-0333h)
0 Reset SOC I2C
1 MIPI_TX_Reset
2 Unused (0)
3 MIPI_TX_en (=Serial Data?)
4 IP_PD_en (=Parallel Data or what?)
5 Reserved
6 Sensor_full_res
7 Unused (0)
8 OE_N_Enable
9 Parallel_enable (=Parallel Data?)
10 Unused (0)
11 Reserved
12-15 Unused (0)
001Ch 2 MCU_BOOT_MODE MCU Boot Mode
0 Reset MCU
1 Reserved
2 Reserved
3 Reserved
4-7 Reserved (0..0Fh)
8-15 Reserved (0..FFh) (R)
001Eh 2 PAD_SLEW Pad Slew Control (def=0400h)
0-2 Parallel Data Output Slew Rate Control (0-7)
3 Unused (0)
4-6 GPIO Slew Rate Control (0-7)
7 Unused (0)
8-10 PCLK aka PXLCLK Slew Rate Control (0-7)
11-15 Unused (0)
0020h .. RESERVED_SYSCTL_20 Reserved
0022h 2 VDD_DIS_COUNTER VDD_DIS_COUNTER (0..FFFFh, def=0438h)
0024h 2 GPI_STATUS GPI_STATUS (0..000Fh) (R)
0026h .. RESERVED_SYSCTL_26 Reserved
0028h 2 EN_VDD_DIS_SOFT EN_VDD_DIS_SOFT (0..0001h, def=0001h)
0050h .. RESERVED_SYSCTL_50 Reserved
|
| DSi Aptina Camera Registers: RX_SS, FUSE, XDMA (0100h-099Fh) |
0100h .. RESERVED_RX_SS_100 Reserved 0102h 2 TEST_PXL_RED Test Pixel Red ;\Default value is 1FFh 0104h 2 TEST_PXL_G1 Test Pixel Green1 ; for Gray Flat Field 0106h 2 TEST_PXL_G2 Test Pixel Green2 ; (0..03FFh, def=01FFh) 0108h 2 TEST_PXL_BLUE Test Pixel Blue ;/ 010Ah .. RESERVED_RX_SS_10A-116 Reserved |
0800h .. RESERVED_FUSE_ROM_800-81E Reserved |
0982h .. RESERVED_XDMA_982 Reserved
098Ch 2 MCU_ADDRESS MCU Address (0000h..FFFFh)
0-7 driver_variable (0..FFh)
8-12 driver_id (0..1Fh) (eg. 3=AWB, 7=MODE, etc.)
13-14 address space (0=Physical/RAM/SFR, 1=Logical/Variables)
15 access_8_bit (0=16bit, 1=8bit; converted to 16bit)
0990h 8x2 MCU_DATA_0-7 MCU Data 0..7 (8 x 16bit)
|
| DSi Aptina Camera Registers: CORE (3000h-31FFh, 38xxh) |
3000h .. RESERVED_CORE_3000 Reserved (same as CHIP_VERSION_REG)
3002h 2 Y_ADDR_START Y1 ;\Image Position/Size ;def=0004h
3004h 2 X_ADDR_START X1 ; (up to including ;def=0004h
3006h 2 Y_ADDR_END Y2 ; X2,Y2) (0-07FFh) ;def=04BBh
3008h 2 X_ADDR_END X2 ;/ ;def=064Bh
300Ah 2 FRAME_LENGTH_LINES Y Total ;\Total X/Y Size with ;def=0512h
300Ch 2 LINE_LENGTH_PCK X Total ;/blanking (0..FFFFh) ;def=0886h
3010h .. RESERVED_CORE_3010 Reserved
3012h 2 COARSE_INTEGRATION_TIME Y Time ;\Integration Time in ;def=0010h
3014h 2 FINE_INTEGRATION_TIME X Time ;/lines/pix (0..FFFFh);def=00F6h
3016h 2 ROW_SPEED Row Speed (def=0111h)
0-2 Pixclk_speed (0..7)
3 Unused (0)
4-6 Reserved
7 Unused (0)
8-10 Reserved
11-15 Unused (0)
3018h .. RESERVED_CORE_3018-3019 Reserved
301Ah UNDOC_CORE_301A Undocumented Status Reg (mask=D7FFh)
0-1 Unspecified
2 Undoc/USED (1=WakeupDone) (opposite of 0018h.bit14)
3-4 Unspecified
5 Whatever "demo_system, version_reg_write, value=1"
6-8 Unspecified
9 Mask_corrupted_frames (alias of 3022h.bit0)
10 Unspecified
11 Unused (0)
12 Unspecified
13 Unused (0)
14 Unspecified
15 Grouped_parameter_hold (alias of 3022h.bit8)
301Ch .. RESERVED_CORE_301C-3020 Reserved
3022h 2 GROUPED_PARAMETER_HOLD_MASK_CORRUPTED_FRAMES
0 Mask_corrupted_frames (alias of Reg 301Ah.bit9)
1-7 Unused (0)
8 Grouped_parameter_hold (alias of Reg 301Ah.bit15)
9-15 Unused (0)
3024h 2 PIXEL_ORDER Pixel Order (mask=0300h, 0..0300h) (R)
3026h .. RESERVED_CORE_3026 Reserved
3028h 2 ANALOGUE_GAIN_CODE_GLOBAL Analog Global ;\
302Ah 2 ANALOGUE_GAIN_CODE_GREENR Analog GreenR ; Analogue Gain Codes
302Ch 2 ANALOGUE_GAIN_CODE_RED Analog Red ; with 3bit fraction
302Eh 2 ANALOGUE_GAIN_CODE_BLUE Analog Blue ; (0..007Fh, def=000Bh)
3030h 2 ANALOGUE_GAIN_CODE_GREENB Analog GreenB ;/
3032h 2 DIGITAL_GAIN_GREENR Digital GreenR ;\Digital Gain with
3034h 2 DIGITAL_GAIN_RED Digital Red ; 8bit dummy-fraction
3036h 2 DIGITAL_GAIN_BLUE Digital Blue ; (bit8-10=Gain, 0..7)
3038h 2 DIGITAL_GAIN_GREENB Digital GreenB ;/(mask=0700h,def=100h)
303Ah .. RESERVED_CORE_303A-3C Reserved
3040h 2 READ_MODE Read Mode (0-DEFFh, def=0024h)
0 horiz_mirror
1 vert_flip
2-4 y_odd_inc (0..7)
5-7 x_odd_inc (0..7)
8 Unused (0)
9 low_power
10 xy_bin_en
11 x_bin_en
12 bin_sum (Enable summing mode for binning)
13 read_mode_y_sumen
14 Reserved
15 Reserved
3044h .. RESERVED_CORE_3044-3048 Reserved
304Ah 2 OTPM_CONTROL One-time Programmable Memory? Control
0 auto_wr_start ;\
1 auto_wr_end (finished) (R) ; automatic write sequence
2 auto_wr_success (okay) (R) ;/
3 unspecified
4 auto_rd_start ;\
5 auto_rd_end (finished) (R) ; automatic read sequence
6 auto_rd_success (okay) (R) ;/
7-15 Unused (0)
3050h .. RESERVED_CORE_3050-3054 Reserved
3056h 2 GREEN1_GAIN Gain Green1 ;\
3058h 2 BLUE_GAIN Gain Blue ; Gain Values
305Ah 2 RED_GAIN Gain Red ; (0..0FFFh,
305Ch 2 GREEN2_GAIN Gain Green2 ; def=022Ch)
0-6 Initial Gain (0..7Fh, with 5bit fraction) ;
7-8 Analog Gain (0..3) (bit8+1)*(bit7+1)*(initial_gain/32)
9-11 Digital Gain (1..7) ;
12-15 Unused (0) ;/
305Eh .. RESERVED_CORE_305E-31DF Reserved
31E0h 2 UNDOC_CORE_31E0 (mask=E003h, 0..8001h, def=0001h) USED!
Used by DSi (set to 0001h) (reportedly "PIX_DEF_ID")
31E2h .. RESERVED_CORE_31E2-31F9 Reserved
31FAh 2 UNDOC_CORE_31FA Whatever (mask=FFFFh, def=CDEFh)
0-4 Unspecified
5-11 Whatever "demo_system, version_reg_read, value=3"
12-15 Unspecified
31FCh .. RESERVED_CORE_305E-31FE Reserved
|
3800h .. RESERVED_CORE_3800-3802 Reserved |
| DSi Aptina Camera Registers: SOC1 (3210h-33FDh) |
3210h 2 COLOR_PIPELINE_CONTROL (mask=05B8h, 0..05B0h, def=01B0h)
3 Enable PGA pixel shading correction
All coefficients and other configuration settings
(including other fields in this register) must be set up
before enabling shading correction.
4 Enable 2D aperture correction
5 Enable color correction
7 Enable gamma correction
8 Decimator (1=Enable scale)
10 Reserved
3216h .. RESERVED_SOC1_3216-321A Reserved
321Ch 2 OFIFO_CONTROL_STATUS Ofifo control status 1 (def=0003h)
0-3 txfifo_bypass
(0=tx_fifo, 1=sensor, 2=sam observe, 3=cpipe format,
4=test walking ones cpipe frequency,
5=test walking ones sensor frequency,
6=RESERVED, 7=test PIXCLK, 8..F=Unspecified)
4-6 Unused (0)
7 sensor_bypass (0=cpipe, 1=sensor)
8 Reserved
9 Reserved
10 Reserved
11 Reserved
12 Reserved (R)
13 Reserved (R)
14 Reserved (R)
15 Reserved (R)
321Eh 2 OFIFO_CONTROL_STATUS_2 Ofifo control status 2 (def=0010h)
0-9 Reserved (0..3FFh)
10 Disable PV output clock during blank (1=disable)
11-15 Reserved (0..1Fh)
3220h .. RESERVED_SOC1_3220 Reserved
3222h 2 LOWER_X_BOUND_ZOOM_WINDOW Lower X ;def=? ;\Zoom Window
3224h 2 UPPER_X_BOUND_ZOOM_WINDOW Upper X ;def=063Fh ; Boundaries
3226h 2 LOWER_Y_BOUND_ZOOM_WINDOW Lower Y ;def=? ; (0..07FFh)
3228h 2 UPPER_Y_BOUND_ZOOM_WINDOW Upper Y ;def=04AFh ;/
322Ah 2 UNDOC_SOC1_322A (mask=0016h, 0..0016h) USED by DSi!
322Ch 2 WEIGHT_HORIZ_DECIMATION Scaling Weight X ;\Scaling Weight X,Y
322Eh 2 WEIGHT_VERTICAL_DECIMATION Scaling Weight Y ;/(0..0FFFh, def=800h)
323Eh 2 UNDOC_SOC1_323E (0..FFFFh, def=1A2Dh) (DSi: C22Ch)
3240h 2 UNDOC_SOC1_3240 (0..FFFFh, def=C814h) (DSi: 6214h)
3242h .. RESERVED_SOC1_3242 Reserved
3244h 2 UNDOC_SOC1_3244 (mask=03FFh, range=0..00FFh?, def=0310)
3254h .. RESERVED_SOC1_3254-326A Reserved
326Ch 2 APERTURE_PARAMETERS Aperture Params (0..7FFFh, def=0A08h)
0-7 2D aperture threshold (knee) (00h-FFh)
8-10 2D aperture gain (0-7)
11-13 2D aperture gain's exponent (0-7)
14 Abs (1=force aperture gain be positive)
15 Unused (0)
326Eh .. RESERVED_SOC1_326E-3276 Reserved
327Ah 2 BLACK_LEVEL_1ST_RED Offset Red ;\Offsets subtracted
327Ch 2 BLACK_LEVEL_1ST_GREEN1 Offset Green1 ; from RGB pixels
327Eh 2 BLACK_LEVEL_1ST_GREEN2 Offset Green2 ; (0000-01FFh/03FFh,
3280h 2 BLACK_LEVEL_1ST_BLUE Offset Blue ;/def=002Ah)
328Eh 2 THRESH_EDGE_DETECT Demosaic Edge Threshold (def=000Ch)
3290h 2 TEST_PATTERN Test Pattern Enable/Width
0-4 Unused (0)
5 en_walk_ones_tp Enable Test Pattern (0=disable, 1=enable)
6 walk_ones_10 Pattern Width (0=8-bit, 1=10-bit)
7-15 Unused (0)
329Eh .. RESERVED_SOC1_329E-32A0 Reserved
32C0h 2 COLOR_CORR_MATRIX_SCALE_14 Exponents C11..C22 (0-7FFFh, def=3923h)
32C2h 2 COLOR_CORR_MATRIX_SCALE_11 Exponents C23..C33 (0-0FFFh, def=0724h)
32C4h 2 COLOR_CORR_MATRIX_1_2 Elements C11=LSB, C12=MSB (def=7DCCh)
32C6h 2 COLOR_CORR_MATRIX_3_4 Elements C13=LSB, C21=MSB (def=2711h)
32C8h 2 COLOR_CORR_MATRIX_5_6 Elements C22=LSB, C23=MSB (def=62E5h)
32CAh 2 COLOR_CORR_MATRIX_7_8 Elements C31=LSB, C32=MSB (def=690Dh)
32CCh 2 COLOR_CORR_MATRIX_9 Element C33=LSB, Signs=MSB (def=2DCDh)
32D4h 2 DIGITAL_GAIN_1_RED Gain for Red channel ;\Digital Gain1
32D6h 2 DIGITAL_GAIN_1_GREEN1 Gain for Green1 channel ; (mul 128,
32D8h 2 DIGITAL_GAIN_1_GREEN2 Gain for Green2 channel ; 0000h..03FFh,
32DAh 2 DIGITAL_GAIN_1_BLUE Gain for Blue channel ;/def=0080h)
32F4h .. RESERVED_SOC1_32F4-332E Reserved
3330h 2 OUTPUT_FORMAT_TEST OUTPUT_FORMAT_TEST (0..0FFFh)
0 Disable Cr channel
1 Disable Y channel
2 Disable Cb channel
3-5 Test ramp output
6 8+2 bypass
7 Reserved
8 Enable Lens Correction Bypass
9 Reserved
10 Reserved
11 Reserved
12-15 Unused (0)
3332h .. RESERVED_SOC1_3332-334A Reserved
337Ch 2 YUV_YCBCR_CONTROL YUV_YCBCR_CONTROL (0..000Fh, def=0006h)
0 Mult_y_uv (normalize Y in 16-235; U and V in 16-240)
1 Coefficient control
2 Add 128 to U and V
3 Clip Y in 16-235; U and V in 16-240
4-15 Unused (0)
337Eh 2 Y_RGB_OFFSET Y_RGB Offset
0-7 Reserved (0..FFh)
8-15 Y offset (0..FFh)
33E6h .. RESERVED_SOC1_33E6-33EE Reserved
33F4h 2 KERNEL_CONFIG Kernel Config (0..01FFh, def=0003h)
0 Defect correction (DC) enable
1 Reserved
2 Reserved
3 Noise reduction (NR) enable
4 Reserved
5 Reserved
6 Reserved
7 Reserved
8 Reserved
33F6h .. RESERVED_SOC1_33F6-33FC Reserved
|
| DSi Aptina Camera Registers: SOC2 (3400h-3729h) |
3400h 2 MIPI_CONTROL MIPI_Control (def=782Eh)
0 MIPI restart enable
1 MIPI standby
2 Continuous MIPI clock
3 Frame boundary sync bit (R)
4 Wait until eof to react to standby
5 Reserved
6-8 MIPI channel number
9 Unused (0) or Reserved (REV3)
10-15 Data Type (1Eh=YUV422_8bit, 20h=RGB444, 21h=RGB555,
22h=RGB565, 2Ah=RAW8, 2Bh=RAW10)
3402h 2 MIPI_STATUS MIPI_Status (def=0011h)
0 MIPI in standby (R)
1-3 Unused (0)
4 MIPI aka MIPICCP idle (R)
5 MIPI ready to receive data (R)
6-8 Unused (0)
9 Reserved (R)
10 Reserved (R)
11 Reserved
12 Reserved
13-15 Unused (0)
3404h 2 CUSTOM_SHORT_PKT MIPI_Custom_Short_Packet (0000h-3F00h)
0-5 Unused (0)
6 frame_cnt_reset (sent in frame start/end short packets)
7 frame_cnt_en (Insert frame counter value in WC field)
8-10 custom_short_packet_data_type
11 custom_short_packet_request
12 custom_short_packet_frame_sync
13 custom_short_packet_reset (R)
14-15 Unused (0)
3408h 2 LINE_BYTE_CNT MIPI line byte count (def=0C80h)
340Ch 2 CUSTOM_SHORT_PKT_WC WC field of a custom short packet
340Eh .. RESERVED_SOC2_340E-341A Reserved
3580h 2 AE_ZONE_X AE Window/Zone X (def=1300h)
0-7: ae_zone_x_start (00h..FFh) (div8) ;for WINDOW
8-15: ae_zone_x_width (00h..FFh) (div8, minus 1) ;for each ZONE
3582h 2 AE_ZONE_Y AE Window/Zone Y (def=0E00h)
0-7: ae_zone_y_start (00h..FFh) (div8) ;for WINDOW
8-15: ae_zone_y_width (00h..FFh) (div8, minus 1) ;for each ZONE
3584h 2 AE_WINDOW_SIZE_LO LSBs ;\Size of each AE zone in pixels
3586h 2 AE_WINDOW_SIZE_HI MSBs ;/(0..0001FFFFh, def=000x4B00h ?)
3588h .. RESERVED_SOC2_3588-35AE Reserved
35B0h UNDOC_SOC2_35B0 (mask=FFFFh, 0..FFFFh, def=05FAh) USED!
35B2h .. RESERVED_SOC2_35B2-3602 Reserved
3604h 20 R_GAMMA_CURVE_KNEES_0-18 Red Gamma Curve Knees 0..18 (1B00h,..)
3618h 20 G_GAMMA_CURVE_KNEES_0-18 Green Gamma Curve Knees 0..18 (1B00h,..)
362Ch 20 B_GAMMA_CURVE_KNEES_0-18 Blue Gamma Curve Knees 0..18 (1B00h,..)
Above 20-byte knees consist of ten 16bit values (Knee0 in LSB)
Due to the 16bit-big-endian format, the byte-order is:
Knee1,Knee0,Knee3,Knee2,...,Knee17,Knee16,UNUSED,Knee18
3640h .. RESERVED_SOC2_3640 Reserved
3642h 2 POLY_ORIGIN_R Center Row (max 07FFh, def=025Ch)
3644h 2 POLY_ORIGIN_C Center Column (max 07FFh, def=0324h)
3646h .. RESERVED_SOC2_3646-364C Reserved
364Eh 5x2 P_GR_P0Q0-4 P0Q for Green1 ;\P0 Coefficients
3658h 5x2 P_RD_P0Q0-4 P0Q for Red ; (5 x float16 each)
3662h 5x2 P_BL_P0Q0-4 P0Q for Blue ; (0010h,... each)
366Ch 5x2 P_GB_P0Q0-4 P0Q for Green2 ;/
3676h 5x2 P_GR_P1Q0-4 P1Q for Green1 ;\
3680h 5x2 P_RD_P1Q0-4 P1Q for Red ; P1 Coefficients
368Ah 5x2 P_BL_P1Q0-4 P1Q for Blue ; (5 x float16 each)
3694h 5x2 P_GB_P1Q0-4 P1Q for Green2 ;/
369Eh 5x2 P_GR_P2Q0-4 P2Q for Green1 ;\
36A8h 5x2 P_RD_P2Q0-4 P2Q for Red ; P2 Coefficients
36B2h 5x2 P_BL_P2Q0-4 P2Q for Blue ; (5 x float16 each)
36BCh 5x2 P_GB_P2Q0-4 P2Q for Green2 ;/
36C6h 5x2 P_GR_P3Q0-4 P3Q for Green1 ;\
36D0h 5x2 P_RD_P3Q0-4 P3Q for Red ; P3 Coefficients
36DAh 5x2 P_BL_P3Q0-4 P3Q for Blue ; (5 x float16 each)
36E4h 5x2 P_GB_P3Q0-4 P3Q for Green2 ;/
36EEh 5x2 P_GR_P4Q0-4 P4Q for Green1 ;\
36F8h 5x2 P_RD_P4Q0-4 P4Q for Red ; P4 Coefficients
3702h 5x2 P_BL_P4Q0-4 P4Q for Blue ; (5 x float16 each)
370Ch 5x2 P_GB_P4Q0-4 P4Q for Green2 ;/
3716h .. RESERVED_SOC2_3716-3278 Reserved
|
| DSi Aptina Camera Variables: RAM/SFR/MON (GPIO/Monitor) (MCU:0000h-20xxh) |
02F0h 2 UNDOC_RAM_02F0 (set to 0000h by DSi games) 02F2h 2 UNDOC_RAM_02F2 (set to 0210h by DSi games) 02F4h 2 UNDOC_RAM_02F4 (set to 001Ah by DSi games) |
1040h .. RESERVED_SFR_1040-1050 Reserved
1060h .. RESERVED_SFR_1060-1066 Reserved (REV3)
1070h 2 GPIO_DATA GPIO Data (0..1E00h)
0-8 Unused (0)
9-12 gpio_3_0_data
13-15 Unused (0)
1072h 2 RESERVED_SFR_1072 Reserved
1074h 2 GPIO_OUTPUT_SET GPIO Set (0..0C00h/1E00h?) (W)
0-8 Unused (0)
9-12 gpio_3_0_output_toggle (uh, toggle or set?)
13-15 Unused (0)
1076h 2 GPIO_OUTPUT_CLEAR GPIO Clear (0..0C00h/1E00h?) (W)
0-8 Unused (0)
9-12 gpio_3_0_output_clear
13-15 Unused (0)
1078h 2 GPIO_DIR GPIO Direction (0..1E00h, def=1E00h)
0-8 Unused (0)
9 gpio_0_dir (0=Output, 1=Input) ;(LSB0 of 10bit Output)
10 gpio_1_dir (0=Output, 1=Input) ;(LSB1 of 10bit Output)
11 gpio_2_dir (0=Output, 1=Input) ;(Flash/Shutter Pulse)
12 gpio_3_dir (0=Output, 1=Input) ;(OE_BAR for Databus)
13-15 Unused (0)
107Ah .. RESERVED_SFR_107A-10FD Reserved
|
2000h 5 RESERVED_MON_00-04 Reserved
2005h 1 MON_CMD Monitor Command (0..FFh)
2006h 2 MON_ARG1 Monitor First Argument (0..FFFFh)
2008h .. RESERVED_MON_08-22 Reserved
2024h 2 MON_PATCH_ID_0 Monitor First Patch (0..FFFFh) (REV1)
0-7 mon_patch_0_version (00h-0Fh)
The version number of the first patch (R)
8-15 mon_patch_0_number (00h-0Fh)
Identifies which patch the first patch is (R)
2024h 1 MON_PATCH_ID_0 (mask=FFh) (R) ;\unlike above (REV3)
2025h 1 MON_PATCH_ID_1 (0..FF) ;/REV1 specs (REV3)
2026h 1 MON_PATCH_ID_2 (0..FF) (REV3)
2027h 1 RESERVED_MON_27 Reserved (REV3)
|
| DSi Aptina Camera Variables: SEQ (Sequencer) (MCU:21xxh) |
2100h .. RESERVED_SEQ_00 Reserved
2102h 1 SEQ_MODE SEQ Mode (enables "drivers") (def=0Fh)
0 Enable AE (ID=2)
1 Enable FD (ID=4)
2 Enable AWB (ID=3)
3 Enable HG (ID=11)
4-7 Unspecified
2103h 1 SEQ_CMD SEQ Cmd (0..FFh, def=01h)
0-7 Cmd (0=Run, 1=Preview, 2=Capture, 3=Standby,
4=Lock, 5=Refresh, 6=Refresh Mode)
2104h 1 SEQ_STATE SEQ State (0..FFh)
0-7 State (0=Run, 1=ToPreview, 2=Enter, 3=Preview
4=Leave, 5=ToCapture, 6=Enter, 7=Capture,
8=Leave, 9=Standby)
2105h .. RESERVED_SEQ_05 Reserved
2106h 1 SEQ_FLASHTYPE Type of flash to be used
0-6 Flash Type (0=None, 1=LED, 2=Xenon, 3=XenonBurst)
7 Set flash to LOCK mode (0=Normal, 1=LOCK mode)
2107h .. RESERVED_SEQ_07-08 Reserved
2109h 1 SEQ_AE_FASTBUFF AE Fast Buff (0..FFh, def=10h)
210Ah 1 SEQ_AE_FASTSTEP AE Fast Step (0..FFh, def=02h)
210Bh 1 SEQ_AWB_CONTBUFF AWB Cont Buff (0..FFh, def=08h)
210Ch 1 SEQ_AWB_CONTSTEP AWB Cont Step (0..FFh, def=02h)
210Dh .. RESERVED_SEQ_0D-10 Reserved
2111h 1 SEQ_OPTIONS SEQ Options (0..FFh, def=08h)
0 Reserved
1 Reserved
2 Reserved
3 seq_crop_win_ae, Use crop window for AE statistics
4 seq_crop_win_awb, Use crop window for AWB statistics
7 Reserved
2112h .. RESERVED_SEQ_12 Reserved
2113h 2 SEQ_FLASH_TH SEQ Flash TH (0..FFFFh)
2115h 1 SEQ_CAP_MODE Capture mode (in Capture state only)
0 Xenon Flash (Still Only)
1 Video
2 Turn Flash off before last frame in capture state
4 Video AE on
5 Video AWB on
6 Video HG on
2116h 1 SEQ_CAP_NUMFRAMES Num still frames captured (0..FFh,def=3)
2117h 1 SEQ_PREVIEW_0_AE Preview 0 AE (PREVIEW ENTER) ;\
0-3 AE (0=Off, 1=Fast, 2=Manual, 3=Continuous, 4=MDR) ;
4-7 Unspecified (0..5) (0..0Fh for PREVIEW_2/3) ; Pre-
2118h 1 SEQ_PREVIEW_0_FD Preview 0 FD (PREVIEW ENTER) ; view
0-7 FD (0=Off, 1=Continuous, 2=Manual) ; 0
2119h 1 SEQ_PREVIEW_0_AWB Preview 0 AWB (PREVIEW ENTER) ;
0-7 AWB (0=Off, 1=On) ; PRE-
211Ah 1 SEQ_PREVIEW_0_HG Preview 0 HG (PREVIEW ENTER) ; VIEW
0-7 HG (0=Off, 1=Fast, 2=Manual, 3=Continuous) ; ENTER
211Bh 1 SEQ_PREVIEW_0_FLASH Flash Config (0..FFh) ;
0-6 Flash (0=Off,1=On,2=Locked,3=AutoEvaluate,7=UserDef) ;
7 Reserved ;
211Ch 1 SEQ_PREVIEW_0_SKIPFRAME Skipframe State Config (def=40h) ;
0-3 Unspecified ;
4 Unspecified (except PREVIEW_2: Reserved) ;
5 Skip_led_on ;
6 Skip_state (0=No skip state, 1=Skip state) ;
7 Turn_off_fen ;/
211Dh 1 SEQ_PREVIEW_1_AE ;\ def=01h
211Eh 1 SEQ_PREVIEW_1_FD ; Preview 1 (PREVIEW) def=01h
211Fh 1 SEQ_PREVIEW_1_AWB ; (same as Preview 0, but def=01h
2120h 1 SEQ_PREVIEW_1_HG ; without AE=MDR, def=01h
2121h 1 SEQ_PREVIEW_1_FLASH ; without HG=Manual/Continous)
2122h 1 SEQ_PREVIEW_1_SKIPFRAME ;/ def=N/A
2123h 1 SEQ_PREVIEW_2_AE ;\
2124h 1 SEQ_PREVIEW_2_FD ; Preview 2 (PREVIEW LEAVE)
2125h 1 SEQ_PREVIEW_2_AWB ; (same as Preview 0, but
2126h 1 SEQ_PREVIEW_2_HG ; without HG=Manual/Continous)
2127h 1 SEQ_PREVIEW_2_FLASH ;
2128h 1 SEQ_PREVIEW_2_SKIPFRAME ;/
2129h 1 SEQ_PREVIEW_3_AE ;\
212Ah 1 SEQ_PREVIEW_3_FD ; Preview 3 (CAPTURE ENTER)
212Bh 1 SEQ_PREVIEW_3_AWB ; (same as Preview 0)
212Ch 1 SEQ_PREVIEW_3_HG ;
212Dh 1 SEQ_PREVIEW_3_FLASH ;
212Eh 1 SEQ_PREVIEW_3_SKIPFRAME ;/
212Fh .. RESERVED_SEQ_2F-33 Reserved
2134h 1 UNDOC_SEQ_34 (0..FFh)
2135h .. RESERVED_SEQ_35-44 Reserved
2145h 2 UNDOC_SEQ_45 (0..FFFFh)
2147h .. RESERVED_SEQ_47-59 Reserved
|
| DSi Aptina Camera Variables: AE (Auto Exposure) (MCU:22xxh) |
2200h .. RESERVED_AE_00 Reserved
2202h 1 AE_WINDOW_POS AE Window Position Y0 and X0
0-3 X0 (in units of 1/16th of frame width) (0..0Fh)
4-7 Y0 (in units of 1/16th of frame height) (0..0Fh)
2203h 1 AE_WINDOW_SIZE AE Window Height and Width (def=FFh)
0-3 Width (units of 1/16th of frame width, minus 1) (0..0Fh)
4-7 Height (units of 1/16th of frame height, minus 1) (0..0Fh)
2204h .. RESERVED_AE_04 Reserved
2206h 1 AE_TARGET AE Target Brightness (0..FFh, def=32h)
2207h 1 AE_GATE AE Sensitivity (0..FFh, def=04h)
2208h .. UNDOC_AE_08 (0..FFh, def=02h)
2209h .. RESERVED_AE_09-0A Reserved
220Bh 1 AE_MIN_INDEX Min (0-FFh)
220Ch 1 AE_MAX_INDEX Max allowed zone number (0-FFh,def=18h)
220Dh 1 AE_MIN_VIRTGAIN Min allowed virtual gain (0-FFh,def=10h)
220Eh 1 AE_MAX_VIRTGAIN Max allowed virtual gain (0-FFh,def=80h)
220Fh .. RESERVED_AE_0F-11 Reserved
2212h 2 AE_MAX_DGAIN_AE1 Max digital gain pre-LC (def=8000h)
2214h .. RESERVED_AE_14-16 Reserved
2217h 1 AE_STATUS AE Status
0 AE_at_limit (1=AE reached limit)
1 R9_changed (1=Need to skip frame)
2 Ready (0=AE not ready, 1=AE ready)
3-7 Unused (0)
2218h 1 AE_CURRENT_Y Last measured luma (0-FFh,def=4Bh) (R)
2219h 2 AE_R12 Curr shutter delay (def=0279h) (R)
221Bh 1 AE_INDEX Curr zone integration time (def=04h) (R)
221Ch 1 AE_VIRTGAIN Curr virtual gain (0-FFh,def=10h) (R)
221Dh .. RESERVED_AE_1D-1E Reserved
221Fh 2 AE_DGAIN_AE1 Current digital gain pre-LC (def=0080h)
2221h .. RESERVED_AE_21 Reserved
2222h 2 AE_R9 Current R9:0 value (0-FFFFh, def=0010h)
2224h .. RESERVED_AE_24-2C Reserved
222Dh 2 AE_R9_STEP Integration time per zone (def=009Dh)
222Fh .. RESERVED_AE_2F-49 Reserved
224Ah 1 AE_TARGETMIN Min value for target (0..FFh, def=32h)
224Bh 1 AE_TARGETMAX Max value for target (0..FFh, def=96h)
224Ch 1 AE_TARGETBUFFERSPEED Target Buffer Speed (0..FFh, def=0Ch)
224Dh .. RESERVED_AE_4D Reserved
224Fh 1 AE_BASETARGET Target Base (0..FFh, def=36h)
2250h .. RESERVED_AE_50-61 Reserved
2262h .. RESERVED_AE_62-64 Reserved (REV3)
|
| DSi Aptina Camera Variables: AWB (Auto White Balance) (MCU:23xxh) |
2300h .. RESERVED_AWB_00 Reserved
2302h 1 AWB_WINDOW_POS AWB Window Position Y0 and X0
0-3 X0 (in units of 1/16th of frame width) (0..0Fh)
4-7 Y0 (in units of 1/16th of frame height) (0..0Fh)
2303h 1 AWB_WINDOW_SIZE AWB Window Size (def=EFh)
0-3 Width (units of 1/16th of frame width, minus 1) (0..0Fh)
4-7 Height (units of 1/16th of frame height, minus 1) (0..0Fh)
2304h .. RESERVED_AWB_04 Reserved
2306h 3x2 AWB_CCM_L_0-2 Left CCM K11,K12,K13 (0180h,FF00h,0080h)
230Ch 3x2 AWB_CCM_L_3-5 Left CCM K21,K22,K23 (FF66h,0180h,FFEEh)
2312h 3x2 AWB_CCM_L_6-8 Left CCM K31,K32,K33 (FFCDh,FECDh,019Ah)
2318h 2 AWB_CCM_L_9 Left CCM Red/Green gain (0020h)
231Ah 2 AWB_CCM_L_10 Left CCM Blue/Green gain (0033h)
231Ch 3x2 AWB_CCM_RL_0-2 DeltaCCM D11,D12,D13 (0100h,FF9Ah,xxxxh)
2322h 3x2 AWB_CCM_RL_3-5 DeltaCCM D21,D22,D23 (004Dh,FFCDh,FFB8h)
2328h 3x2 AWB_CCM_RL_6-8 DeltaCCM D31,D32,D33 (004Dh,0080h,FF66h)
232Eh 2 AWB_CCM_RL_9 DeltaCCM Red/Green gain (0008h)
2330h 2 AWB_CCM_RL_10 DeltaCCM Blue/Green gain (FFF7h)
2332h 3x2 AWB_CCM_0-2 Curr CCM C11,C12,C13 (01BAh,FF5Bh,FFF1h)
2338h 3x2 AWB_CCM_3-5 Curr CCM C21,C22,C23 (FFC7h,01B9h,FF87h)
233Eh 3x2 AWB_CCM_6-8 Curr CCM C31,C32,C33 (FFF9h,FF32h,01DCh)
2344h 2 AWB_CCM_9 Curr CCM Red/Green gain (003Ch)
2346h 2 AWB_CCM_10 Curr CCM Blue/Green gain (002Bh)
2348h 1 AWB_GAIN_BUFFER_SPEED Gain Speed (1-20h, def=08h, 20h=fastest)
2349h 1 AWB_JUMP_DIVISOR Jump Divisor (1-FFh, def=02h, 1=fastest)
234Ah 1 AWB_GAIN_MIN Min AWB Red (def=59h) ;\Digital Gain
234Bh 1 AWB_GAIN_MAX Max allowed Red (def=B6h) ; Min/max
234Ch 1 AWB_GAINMIN_B Min AWB (def=59h) ; (0..FFh)
234Dh 1 AWB_GAINMAX_B Max allowed (def=A6h) ;/
234Eh 1 AWB_GAIN_R Current R digital gain ;\Current Gain
234Fh 1 AWB_GAIN_G Current G digital gain ; (0..FFh,
2350h 1 AWB_GAIN_B Current B digital gain ;/def=80h)
2351h 1 AWB_CCM_POSITION_MIN Min/Left (def=?) ;\(range 0..FFh,
2352h 1 AWB_CCM_POSITION_MAX Max/Right (def=7Fh) ; 00h=incandescent,
2353h 1 AWB_CCM_POSITION Position (def=40h) ;/7Fh=daylight)
2354h 1 AWB_SATURATION Saturation (0..FFh, def=80h, 80h=100%)
2355h 1 AWB_MODE Misc control for AWB (0..FFh)
0 Steady (1=AWB is done)
1 Limits Reached (1=AWB limit is reached)
2 Reserved
3 Reserved
4 Reserved
5 Force_unit_dgains
6 NormCCM_off
2356h 2 AWB_GAINR_BUF Time-buffered R gain (0..FFFFh)
2358h 2 AWB_GAINB_BUF Time-buffered B gain (0..FFFFh)
235Ah .. RESERVED_AWB_5A-5C Reserved
235Dh 1 AWB_STEADY_BGAIN_OUT_MIN (0-FF, def=78h)
235Eh 1 AWB_STEADY_BGAIN_OUT_MAX (0-FF, def=86h)
235Fh 1 AWB_STEADY_BGAIN_IN_MIN (0-FF, def=7Eh)
2360h 1 AWB_STEADY_BGAIN_IN_MAX (0-FF, def=82h)
2361h 2 UNDOC_AWB_61 (0..FFFFh, def=0040h)
2363h 1 AWB_TG_MIN0 True Gray minimum (0..FFh, def=D2h)
2364h 1 AWB_TG_MAX0 True Gray maximum (0..FFh, def=F6h)
2365h 1 AWB_X0 (0-FFh, def=10h)
2366h 1 AWB_KR_L (0-FFh, def=80h)
2367h 1 AWB_KG_L (0-FFh, def=80h)
2368h 1 AWB_KB_L (0-FFh, def=80h)
2369h 1 AWB_KR_R (0-FFh, def=80h)
236Ah 1 AWB_KG_R (0-FFh, def=80h)
236Bh 1 AWB_KB_R (0-FFh, def=80h)
236Ch .. RESERVED_AWB_6C-6E Reserved
|
| DSi Aptina Camera Variables: FD (Anti-Flicker) (MCU:24xxh) |
2400h .. RESERVED_FD_00 Reserved
2402h 1 FD_WINDOW_POSH Window Pos H (0..FFh, def=1Dh)
0-3 Width (in units of 1/16th of frame width, minus 1) (0..0Fh)
4-7 X0 (=position/origin or so?) (0..0Fh)
2403h 1 FD_WINDOW_HEIGHT FlickerMeasurementWindowHeight (def=04h)
0-5 Flicker measurement window height in rows (0..3Fh)
6-7 Unspecified
2404h 1 FD_MODE Flicked Detection switches/indicators
0-3 Reserved (0..0Fh) (R)
4 Debug_mode (0=Disable, 1=Enable single period mode)
5 Curr Flicker State (0=60Hz, 1=50Hz) (R)
6 Curr Settings (0=60Hz, 1=50Hz)
7 Manual Mode (0=Disable, 1=Enable)
2405h .. RESERVED_FD_05-07 Reserved
2408h 1 FD_SEARCH_F1_50 Search F1 50Hz (0..FFh, def=33h)
2409h 1 FD_SEARCH_F2_50 Search F2 50Hz (0..FFh, def=35h)
240Ah 1 FD_SEARCH_F1_60 Search F1 60Hz (0..FFh, def=29h)
240Bh 1 FD_SEARCH_F2_60 Search F2 60Hz (0..FFh, def=2Bh)
240Ch 1 UNDOC_FD_0C (0..FFh)
240Dh 1 FD_STAT_MIN Stat Min (0..FFh, def=03h)
240Eh 1 FD_STAT_MAX Stat Max (0..FFh, def=05h)
240Fh .. RESERVED_FD_0F Reserved
2410h 1 FD_MIN_AMPLITUDE Ignore Signals below Min (0..FFh, def=5)
2411h 2 FD_R9_STEP_F60_A 60HzA (def=0D4h) ;\Minimal Shutter Width
2413h 2 FD_R9_STEP_F50_A 50HzA (def=103h) ; Steps for 60Hz/50H AC
2415h 2 FD_R9_STEP_F60_B 60HzB (def=09Dh) ; in Context A/B
2417h 2 FD_R9_STEP_F50_B 50HzB (def=0B8h) ;/(0..FFFFh)
2419h .. RESERVED_FD_19-7B Reserved
|
| DSi Aptina Camera Variables: MODE (Mode/Context) (MCU:27xxh) |
2700h .. RESERVED_MODE_00-02 Reserved
2703h 2 MODE_OUTPUT_WIDTH_A (CX) (0..FFFFh, def=0320h) ;\Size A
2705h 2 MODE_OUTPUT_HEIGHT_A (CY) (0..FFFFh, def=0258h) ;/
2707h 2 MODE_OUTPUT_WIDTH_B (0..FFFFh, def=0640h) ;\Size B
2709h 2 MODE_OUTPUT_HEIGHT_B (0..FFFFh, def=04B0h) ;/
270Bh 1 MODE_A_MIPI_VC (0..07h) (REV3) ;-Mipi A
270Ch 1 MODE_B_MIPI_VC (0..07h) (REV3) ;-Mipi B
270Dh 2 MODE_SENSOR_ROW_START_A (Y1) (0..FFFFh) ;\
270Fh 2 MODE_SENSOR_COL_START_A (X1) (0..FFFFh) ;
2711h 2 MODE_SENSOR_ROW_END_A (Y2) (0..FFFFh, def=040Dh) ;
2713h 2 MODE_SENSOR_COL_END_A (X2) (0..FFFFh, def=050Dh) ; Sensor
2715h 2 MODE_SENSOR_ROW_SPEED_A (0..0777h, def=0112h) ; A
0-2: pixclk_speed (0..7) ;
1ADC: Pclk = 2 mclks * bits[0:2] ;
2ADC: bits[0:2] ;
4-6: Reserved (0..7) ;
8-10: Reserved (0..7) ;
2717h 2 MODE_SENSOR_READ_MODE_A (0..FFFFh, def=046Ch) ;
0: horiz_mirror ;
1: vert_flip ;
2-4: y_odd_inc (0..7) ;
5-7: x_odd_inc (0..7) ;
9: low_power ;
10: xy_bin_en ;
11: x_bin_en ;
2719h 2 MODE_SENSOR_FINE_CORRECTION_A (0..FFFFh, def=007Bh) ;
271Bh 2 MODE_SENSOR_FINE_IT_MIN_A (0..FFFFh, def=0408h) ;
271Dh 2 MODE_SENSOR_FINE_IT_MAX_MARGIN_A (0..FFFFh, def=00ABh) ;
271Fh 2 MODE_SENSOR_FRAME_LENGTH_A (0..FFFFh, def=0293h) ;
2721h 2 MODE_SENSOR_LINE_LENGTH_PCK_A (0..FFFFh, def=07D0h) ;/
2723h 2 MODE_SENSOR_ROW_START_B (0..FFFFh, def=0004h) ;\
2725h 2 MODE_SENSOR_COL_START_B (0..FFFFh, def=0004h) ; Sensor
2727h 2 MODE_SENSOR_ROW_END_B (0..FFFFh, def=040Bh) ; B
2729h 2 MODE_SENSOR_COL_END_B (0..FFFFh, def=050Bh) ;
272Bh 2 MODE_SENSOR_ROW_SPEED_B (0..0777h, def=0111h) ; (same
272Dh 2 MODE_SENSOR_READ_MODE_B (0..FFFFh, def=0024h) ; as
272Fh 2 MODE_SENSOR_FINE_CORRECTION_B (0..FFFFh, def=00A4h) ; Sensor
2731h 2 MODE_SENSOR_FINE_IT_MIN_B (0..FFFFh, def=0408h) ; A, see
2733h 2 MODE_SENSOR_FINE_IT_MAX_MARGIN_B (0..FFFFh, def=00A4h) ; there)
2735h 2 MODE_SENSOR_FRAME_LENGTH_B (0..FFFFh, def=04EDh) ;
2737h 2 MODE_SENSOR_LINE_LENGTH_PCK_B (0..FFFFh, def=0D06h) ;/
2739h 2 MODE_CROP_X0_A (0..FFFFh) ;\
273Bh 2 MODE_CROP_X1_A (0..FFFFh, def=031Fh) ; Crop A
273Dh 2 MODE_CROP_Y0_A (0..FFFFh) ;
273Fh 2 MODE_CROP_Y1_A (0..FFFFh, def=0257h) ;/
2741h .. RESERVED_MODE_41-45 Reserved
2747h 2 MODE_CROP_X0_B (0..FFFFh) ;\
2749h 2 MODE_CROP_X1_B (0..FFFFh, def=063Fh) ; Crop B
274Bh 2 MODE_CROP_Y0_B (0..FFFFh) ;
274Dh 2 MODE_CROP_Y1_B (0..FFFFh, def=04AFh) ;/
274Fh .. RESERVED_MODE_4F-53 Reserved
2755h 2 MODE_OUTPUT_FORMAT_A Format A (0..FFFFh ;\
2757h 2 MODE_OUTPUT_FORMAT_B Format B (0..FFFFh ;
0 swap_channels (swap Cb/Cr in YUV and R/B in RGB);
1 swap_chrominance_luma ; Format
2 bayer_out (Progressive Bayer) ; A/B
3 monochrome (0..1) ;
4 Reserved ;
5 output_mode (0=YUV, 1=RGB) ;
6-7 RGB Format (0=565, 1=555, 2=444xh, 3:x444h) ;
8 Processed Bayer (0..1) ;
9 Invert out_clk (0..1) (REV3) ;
10-15 Unspecified ;/
2759h 2 MODE_SPEC_EFFECTS_A Effects A (def=6440h) ;\
275Bh 2 MODE_SPEC_EFFECTS_B Effects B (def=6440h) ;
0-2 Selection (1=Mono, 2=Sepia, 3=Negative, ; Effects
4=Solarization, 5=Solarization w/ UV) ; A/B
3-5 Dither_bitwidth ;
6 Dither_luma ;
8-15 Solarization Threshold (0..7 for diff effects) ;/
275Dh 1 MODE_Y_RGB_OFFSET_A Offset A (00h..FFh) ;\Offset
275Eh 1 MODE_Y_RGB_OFFSET_B Offset B (00h..FFh) ;/A/B
275Fh 2 MODE_COMMON_MODE_SETTINGS_BRIGHT_COLOR_KILL ;\
Shadow register for 35A4h in SOC2 ;
0-2 Color kill saturation point (0..7) ; Kill
3-5 Bright color kill gain (0..7) ; Bright
6-8 Bright color kill threshold (0..7) ;
9 Signal_ctrl (1=use luma as min/max value) ;
10 en_kl (1=enable bright color kill) ;
11-15 Unspecified ;/
2761h 2 MODE_COMMON_MODE_SETTINGS_DARK_COLOR_KILL ;\
Shadow register for 35A2h in SOC2 ;
0-2 Dark color kill gain (0..7) ; Kill
3-5 Dark color kill threshold (0..7) ; Dark
6 Signal_ctrl (1=use luma as min/max value) ;
7 en_dark_kl (1=enable dark color kill) ;
8-15 Unspecified ;/
2763h 2 MODE_COMMON_MODE_SETTINGS_FX_SEPIA_SETTINGS ;\
0-7 Sepia constants for Cr (00h..FFh) ; Sepia
8-15 Sepia constants for Cb (00h..FFh) ;/
2765h 1 MODE_COMMON_MODE_SETTINGS_FILTER_MODE ;\
Shadow register for 326Eh in SOC1 ;
0-2 UV Filter mode (0..7) ; Filter
3-4 Y Filter mode (0..3) ;
5 Enable_y_filter (enable y permanently) ;
6 Threshold_switch, switch for adaptive Y filter threshold
7 Off_switch, B/W filter enable switch ;/
2766h 1 MODE_COMMON_MODE_SETTINGS_TEST_MODE Test (00h..FFh)
0-? Test Pattern (0=None?, 1=Flat, 2=Ramp, 3=ColorBars,
4=VertStripes, 5=Noise, 6=HoriStripes)
Output test pattern (instead camera image)
requires "Refresh Command" sent to Sequencer
2767h .. RESERVED_MODE_67-68 Reserved
|
| DSi Aptina Camera Variables: HG (Histogram) (MCU:2Bxxh) |
2B00h .. RESERVED_HG_00-03 Reserved
2B04h 1 HG_MAX_DLEVEL DarkLevel Limit (0..FFh, def=40h)
2B05h .. RESERVED_HG_05 Reserved
2B06h 1 HG_PERCENT Percent? (0..FFh, def=03h)
2B07h .. RESERVED_HG_07 Reserved
2B08h 1 HG_DLEVEL DarkLevel (0..FFh, def=10h)
2B09h .. RESERVED_HG_09-16 Reserved
2B17h 1 HG_AVERAGELUMA Average Luma (0..FFh)
2B18h .. RESERVED_HG_18-1A Reserved
2B1Bh 2 HG_BRIGHTNESSMETRIC Brightness Metric (0..FFFFh)
2B1Dh .. RESERVED_HG_1D Reserved
2B1Fh 1 HG_LLMODE Low Light mode controls (def=C4h)
0-3 Brightness Metric Prescaler (01h..0Fh)
4-5 Unused (0)
6 HG_2d_corr_vs_clusterdc
7 Clusterdc_vs_gains
2B20h 1 HG_LL_SAT1 LL_SAT1 (0..FFh, def=43h)
2B21h 1 UNDOC_HG_21 Whatever (0..FFh, def=10h)
2B22h 1 HG_LL_APCORR1 LL_APCORR1 (0..FFh, def=03h)
2B23h 1 UNDOC_HG_23 Whatever (0..FFh, def=04h)
2B24h 1 HG_LL_SAT2 LL_SAT2 (0..FFh, def=0Ch)
2B25h 1 HG_LL_INTERPTHRESH2 LL_INTERPTHRESH2 (0..FFh, def=23h)
2B26h 1 HG_LL_APCORR2 LL_APCORR2 (0..FFh)
2B27h 1 HG_LL_APTHRESH2 LL_APTHRESH2 (0..FFh, def=04h)
2B28h 2 HG_LL_BRIGHTNESSSTART LL_BRIGHTNESSSTART (0..FFFFh, def=0A8Ch)
2B2Ah 2 HG_LL_BRIGHTNESSSTOP LL_BRIGHTNESSSTOP (0..FFFFh, def=34BCh)
2B2Ch 1 HG_NR_START_R NR_START_R (0..FFh, def=06h)
2B2Dh 1 HG_NR_START_G NR_START_G (0..FFh, def=0Eh)
2B2Eh 1 HG_NR_START_B NR_START_B (0..FFh, def=06h)
2B2Fh 1 HG_NR_START_OL NR_START_OL (0..FFh, def=06h)
2B30h 1 HG_NR_STOP_R NR_STOP_R (0..FFh, def=1Eh)
2B31h 1 HG_NR_STOP_G NR_STOP_G (0..FFh, def=1Eh)
2B32h 1 HG_NR_STOP_B NR_STOP_B (0..FFh, def=1Eh)
2B33h 1 HG_NR_STOP_OL NR_STOP_OL (0..FFh, def=1Eh)
2B34h 1 HG_NR_GAINSTART NR_GAINSTART (0..FFh, def=08h)
2B35h 1 HG_NR_GAINSTOP NR_GAINSTOP (0..FFh, def=80h)
2B36h 1 HG_CLUSTERDC_TH CLUSTERDC_TH (0..FFh, def=1Eh)
2B37h 1 HG_GAMMA_MORPH_CTRL Gamma Morphing Control (0..FFh, def=3)
0-1 Enable Gamma Morph (0=Disable, 1=Use Table A, 2=Use Table B,
3=AutoMorph between Table A and B based on BrightnessMetric)
2-7 Unspecified
2B38h 2 HG_GAMMASTARTMORPH Gamma Start Morph (0..FFFFh, def=0A8Ch)
2B3Ah 2 HG_GAMMASTOPMORPH Gamma Stop Morph (0..FFFFh, def=34BCh)
2B3Ch 19 HG_GAMMA_TABLE_A_0-18 Gamma Table A for normal light condition
Default=xx,1B,2E,4C,78,98,B0,E8,CF,D9,E1,E8,EE,F2,F6,F9,FB,FD,FF
2B4Fh 19 HG_GAMMA_TABLE_B_0-18 Gamma Table B for low light condition
Default=xx,0F,1A,2E,50,6A,80,91,A1,AF,BB,C6,D0,D9,E2,EA,F1,F9,FF
Above 2 tables have normal byte-order (Entry0,Entry1,...,Entry18)
2B62h 2 HG_FTB_START_BM (0..FFFFh, def=7FBCh) (REV3)
2B64h 2 HG_FTB_STOP_BM (0..FFFFh, def=82DCh) (REV3)
2B66h 2 HG_CLUSTER_DC_BM (0..FFFFh, def=4A38h) (REV3)
|
| DSi Alternate Cameras from Unknown Manufacturer |
003h, 1,001h ;<-- bank maybe?
009h, 3,0E2h,002h,002h
004h, 1,010h
004h, 1,0A0h
004h, 2,090h,04Ch
00Dh, 1,0FFh
016h, 1,053h
018h, 3,002h,001h,00Fh
020h, 1,000h
023h, 2,000h,000h
034h, 8,000h,003h,000h,003h,001h,002h,000h,0C2h
03Dh, 4,050h,050h,000h,067h
042h, 1,01Ch
04Ah, 2,043h,0F8h
04Eh, 7,028h,0FCh,000h,024h,014h,008h,008h
056h,13,000h,018h,028h,034h,044h,056h,06Eh,080h,0A4h,0C2h,0D6h,0E8h,0F4h
065h,12,00Fh,038h,008h,000h,01Fh,01Fh,01Fh,01Fh,01Fh,01Fh,01Fh,01Fh
07Ah,17,039h,03Bh,03Ah,036h,03Ch,03Ch,03Ah,03Ch,03Ch,03Ch,03Ah,03Ch,038h
03Ah,031h,03Ah,082h
08Dh,22,08Ah,090h,096h,09Ch,0A4h,0AAh,0B0h,0B6h,0BCh,0C4h,0CAh,0D0h,0D6h
0DCh,0E4h,0EAh,0F0h,0F2h,0F4h,0F6h,0F8h,0FAh
0A9h, 1,02Bh
0ABh, 3,02Eh,000h,050h
0AFh, 1,070h
0B2h, 4,03Ch,068h,049h,070h
0B7h,21,032h,000h,00Eh,0F8h,00Ch,07Ah,040h,000h,000h,010h,044h,064h,052h
012h,001h,0D7h,004h,002h,024h,002h,024h
0D4h, 5,004h,004h,008h,00Ah,010h
016h, 1,0F7h
0DEh, 2,002h,024h
016h, 1,053h
0E1h, 1,034h
0FFh, 1,00Fh
003h, 1,002h ;<-- bank maybe?
005h, 2,06Dh,004h
011h, 4,004h,048h,004h,048h
016h, 2,00Ch,0D8h
019h, 2,00Ch,0D8h
01Eh, 6,002h,024h,070h,000h,001h,06Eh
026h, 7,008h,00Fh,00Fh,006h,0FFh,0FFh,003h
02Eh,19,07Eh,088h,074h,07Eh,008h,010h,080h,008h,084h,078h,001h,003h,00Ah
025h,060h,0B0h,006h,000h,000h
042h, 7,080h,010h,010h,010h,040h,080h,0FFh
04Ah,30,000h,000h,001h,0E5h,001h,0E0h,000h,070h,002h,0F0h,000h,02Eh,001h
0F3h,000h,005h,000h,000h,001h,000h,000h,0C0h,000h,026h,000h,01Ch
000h,0B3h,000h,086h
069h,36,000h,000h,006h,014h,014h,01Fh,000h,000h,000h,000h,000h,01Fh,000h
000h,010h,010h,010h,01Fh,000h,000h,004h,004h,004h,01Fh,000h,000h
000h,000h,000h,01Fh,000h,000h,010h,010h,010h,01Fh
095h, 1,084h
097h,18,002h,000h,0FFh,0FFh,000h,0FFh,0FFh,000h,000h,0FFh,0FFh,000h,0FFh
0FFh,000h,0F8h,014h,010h
0AAh,13,044h,098h,08Ch,09Ch,048h,08Ch,08Ah,09Ch,046h,02Ah,080h,008h,026h
0B8h, 8,02Ah,084h,000h,026h,02Ah,080h,008h,020h
0C1h,10,038h,020h,01Fh,01Dh,034h,020h,01Fh,01Dh,045h,05Dh
0CCh, 2,020h,020h
0D0h, 3,080h,000h,0FFh
003h, 1,000h ;<-- bank maybe?
013h, 2,000h,04Ch
01Dh, 2,000h,04Ch
015h, 2,001h,05Fh
055h, 2,001h,05Eh
031h, 6,006h,068h,00Ch,005h,004h,047h
047h, 2,000h,003h
04Ah, 3,0A0h,000h,003h
04Fh, 2,000h,003h
059h, 2,000h,001h
05Fh, 2,000h,001h
066h, 1,09Eh
06Eh, 2,07Fh,003h
075h, 1,050h
07Ah, 2,000h,001h
07Eh, 1,020h
082h, 1,038h
084h,14,003h,040h,003h,040h,000h,000h,040h,003h,0FFh,002h,008h,020h,018h,006h
093h,11,020h,040h,040h,01Fh,002h,000h,000h,000h,000h,000h,000h
003h, 1,001h ;<-- bank maybe?
00Fh, 1,0C9h ;or, for Device E0h: 00Fh, 1,0C8h
052h, 3,004h,008h,008h ;or, for Device E0h: N/A
003h, 1,002h ;<-- bank maybe?
026h, 1,008h ;or, for Device E0h: 026h, 1,000h
0CCh, 2,0C0h,0C0h ;or, for Device E0h: N/A
0B4h, 1,000h ;or, for Device E0h: N/A
0B6h, 1,026h ;or, for Device E0h: N/A
0B9h, 3,000h,008h,026h ;or, for Device E0h: N/A
0BDh, 1,000h ;or, for Device E0h: N/A
026h, 1,008h ;or, for Device E0h: N/A
003h, 1,001h ;<-- bank maybe?
02Dh, 1,0FFh
004h, 1,020h
|
003h, 1,002h ;<-- bank maybe? 0A7h, 1,014h 003h, 1,001h ;<-- bank maybe? 004h, 1,0A0h 004h, 1,090h 02Dh, 1,000h 004h, 1,098h |
C1h, 8,038h,030h,01Fh,01Fh,02Ch,030h,01Fh,01Fh C1h, 8,038h,030h,01Fh,01Fh,038h,030h,01Fh,01Fh C1h, 8,02Ch,030h,01Fh,01Fh,02Ch,030h,01Fh,01Fh C1h, 8,02Ch,030h,01Fh,01Fh,02Ch,030h,01Fh,01Fh C1h, 8,02Ch,030h,01Fh,01Fh,02Ch,030h,01Fh,01Fh C1h, 8,02Ch,030h,01Fh,01Fh,02Ch,030h,01Fh,01Fh C1h, 8,030h,028h,018h,018h,034h,028h,008h,018h C1h, 8,030h,028h,018h,018h,030h,028h,008h,018h C1h, 8,028h,028h,018h,018h,028h,028h,008h,018h C1h, 8,028h,028h,018h,018h,028h,028h,008h,018h C1h, 8,028h,028h,018h,018h,028h,028h,008h,018h C1h, 8,028h,028h,018h,018h,028h,028h,008h,018h |
| DSi Cameras |
0 Unknown (R or R/W) 1 Unknown (1=Enable?) (R or R/W) 2-4 Unknown (R or R/W) 5 Unknown (1=Enable?) (0=CamI2C fails?) (R or R/W) 6 Unknown (R or R/W) 7 Unknown (gets set automatically?) (R?) 8-15 Unknown/Unused (00h) (0?) |
0-3 Number of DMA scanlines minus 1 (usually 3=Four Scanlines) (R or R/W) 4 Data overrun/underrun error (R) 5 Clear bit4, and flush CAM_DAT till next Camera Vblank? (W) 6-7 Unknown/Unused (0) (0?) 8-9 ? Set to 2 during init, 0 on cameras shutdown (R/W) 10 ? Set to 1 during init, 0 on cameras shutdown (R/W) 11 IRQ Enable (0=Disable, 1=Enable) (R/W) 12 Unknown/Unused (0) (0?) 13 Color Format (0=Direct/YUV422, 1=Convert YUV-to-RGB555) (R or R/W) 14 Trimming Enable (0=Normal/FullPicture, 1=Crop via SOFS/EOFS) (R or R/W) 15 Transfer Enable (0=Disable/AllowConfig, 1=Enable/Transfer) (R/W) |
0-7 First Pixel Luminance (Y) (unsigned, 00h..FFh, FFh=white) 8-15 Both Pixels Blue (Cb aka U) (unsigned, 00h..FFh, 80h=gray) 16-23 Second Pixel Luminance (Y) (unsigned, 00h..FFh, FFh=white) 24-31 Both Pixels Red (Cr aka V) (unsigned, 00h..FFh, 80h=gray) |
0-4 First Pixel Red Intensity (0..31) 5-9 First Pixel Green Intensity (0..31) 10-14 First Pixel Blue Intensity (0..31) 15 First Pixel Alpha (always 1=NonTransparent) 16-20 Second Pixel Red Intensity (0..31) 21-25 Second Pixel Green Intensity (0..31) 26-30 Second Pixel Blue Intensity (0..31) 31 Second Pixel Alpha (always 1=NonTransparent) |
R = Y+(Cr-80h)*1.402 G = Y-(Cr-80h)*0.714)-(Cb-80h)*0.344 B = Y+(Cb-80h)*1.772 |
0 Unused (0) (0) 1-9 X-Offset (0..1FFh) in words (ie. 2-pixel units)? (R or R/W) 10-15 Unused (0) (0) 16-24 Y-Offset (0..1FFh) in scanlines? (R or R/W) 25-31 Unused (0) (0) |
[4004004h]=[4004004h] OR 0004h ;SCFG_CLK, CamInterfaceClock = ON [4004200h]=0000h, delay(1Eh) ;CAM_MCNT, Camera Module Control [4004004h]=[4004004h] OR 0100h, delay(1Eh) ;SCFG_CLK, CamExternal Clock = ON [4004200h]=0022h, delay(2008h) ;CAM_MCNT, Camera Module Control [4004004h]=[4004004h] AND NOT 0100h ;SCFG_CLK, CamExternal Clock = OFF [4004202h]=[4004202h] AND NOT 8000h ;CAM_CNT, allow changing params [4004202h]=[4004202h] OR 0020h ;CAM_CNT, flush data fifo [4004202h]=([4004202h] AND NOT 0300h) OR 0200h [4004202h]=[4004202h] OR 0400h [4004202h]=[4004202h] OR 0800h ;CAM_CNT, irq enable [4004004h]=[4004004h] OR 0100h, delay(14h) ;SCFG_CLK, CamExternal Clock = ON issue "aptina_code_list_init" via I2C bus on ARM7 side [4004004h]=[4004004h] AND NOT 0100h ;SCFG_CLK, CamExternal Clock = OFF [4004004h]=[4004004h] OR 0100h, delay(14h) ;SCFG_CLK, CamExternal Clock = ON issue "aptina_code_list_activate" via I2C bus on ARM7 side [4004202h]=[4004202h] OR 2000h ;CAM_CNT, enable YUV-to-RGB555 [4004202h]=([4004202h] AND NOT 000Fh) OR 0003h [4004202h]=[4004202h] OR 0020h ;CAM_CNT, flush data fifo [4004202h]=[4004202h] OR 8000h ;CAM_CNT, start transfer [4004120h]=04004204h ;NDMA1SAD, source CAM_DTA [4004124h]=0xxxxxxxh ;NDMA1DAD, dest RAM/VRAM [4004128h]=00006000h ;NDMA1TCNT, len for 256x192 total [400412Ch]=00000200h ;NDMA1WCNT, len for 256x4 blocks [4004130h]=00000002h ;NDMA1BCNT, timing interval or so [4004138h]=8B044000h ;NDMA1CNT, start camera DMA |
640*480 VGA (0.3 Megapixel) No zoom and no flash. |
Nintendo DSi Camera System Menu (can take photos, and can display JPG's with "Star" sticker) Flipnote (doesn't directly support camera hardware, but can import JPG's) |
Asphalt 4 : Elite Racing (DSiWare) Brain Challenge (DSiWare) Classic Word Games Cooking Coach Pop SuperStar : Road To Celebrity (DSiWare) Real Football 2009 (DSiWare) WarioWare : Snapped! (DSiWare) iCarly Pokemon Black,White (2010,JP) Castle of Magic (DSiWare) Photo Dojo (DSiWare) System Flaw (mis-uses camera as gyro sensor) |
| DSi SD/MMC Protocol and I/O Ports |
| DSi SD/MMC I/O Ports: Command/Param/Response/Data |
15 undoc Unknown/undoc (read/write-able)
14 undoc Security Cmd? (0=Normal, 1=Whatever/Security?) (sdio?)
13 undoc Data Length (0=Single Block, 1=Multiple Blocks)
12 undoc Data Direction (0=Write, 1=Read)
11 NTDT Data Transfer (0=No data, 1=With data)
10-8 REP2-0 Response Type (0=Auto, 1..2=Unknown/Reserved, 3=None, 4=48bit,
5=48bit+Busy, 6=136bit, 7=48bitOcrWithoutCRC7)
7-6 CMD1-0 Command Type (0=CMD, 1=ACMD, 2..3=unknown, maybe GEN WR/RD?)
5-0 CIX Command Index (0..3Fh, command index)
|
31-0 Parameter value for CMD |
31-0 Response 127-32 Older Responses |
119-0 120bit Response 127-120 Zero (always?) |
.----------. CPU
o--| FIFO16_A |--o o---------------- 4004830h
serial '----------' \ 16bit
SD/MMC ---o o---------o
bus \ .----------. \ .--------. CPU/NDMA
o--| FIFO16_B |--o o---| FIFO32 |--- 400490Ch
'----------' '--------' 32bit
|
15-13 Always zero 12 Unknown (usually 1) (R?) 11-6 Always zero 5 Unknown (read/write-able) (usually 0) (R/W) 4 Unknown (usually 1) (R?) 3-2 Always zero 1 Select 16bit/32bit Data Mode (0=DATA16, 1=DATA32, see 4004900h) (R/W) 0 Always zero |
15-0 Number of Data Blocks for multiple read/write commands (0..FFFFh) |
15-10 Always zero 9-0 Data Block Length in bytes (for DATA16: clipped to max 0200h by hw) |
15-0 Data (Read/Write one block (usually 100h halfwords) upon RXRDY/TXRQ) |
31-0 Data (Read/Write one block (usually 80h words) upon RX32RDY/TX32RQ) |
| DSi SD/MMC I/O Ports: Interrupt/Status |
Bit Stat Mask Function 0 SREP MREP CMDRESPEND (response end) (or R1b: busy end) 1 0 0 Unknown/unused (always 0) 2 SRWA MRWA DATAEND (set after (last) data block end) 3 SCOT MCOT CARD_REMOVE (0=No event, 1=Is/was newly ejected) ;\ 4 SCIN MCIN CARD_INSERT (0=No event, 1=Is/was newly inserted) ; SD 5 undoc 0 SIGSTATE (0=Ejected, 1=Inserted) (SDIO: always 1) ; Slot 6 0 0 Unknown/unused (always 0) ; Sw's 7 undoc 0 WRPROTECT (0=Locked/Ejected, 1=Unlocked/HalfEjected);/ 8 undoc undoc CARD_REMOVE_A (0=No event, 1=High-to-Low occurred) ;\SD 9 undoc undoc CARD_INSERT_A (0=No event, 1=Low-to-High occurred) ; Slot 10 undoc 0 SIGSTATE_A (usually 1=High) ;also as so for SDIO ;/Data3 11 0 0 Unknown/unused (always 0) 12 0 0 Unknown/unused (always 0) 13 0 0 Unknown/unused (always 0) 14 0 0 Unknown/unused (always 0) 15 0 0 Unknown/unused (always 0) 16 SCIX MCIX CMD_IDX_ERR Bad CMD-index in response (RCMDE,SCMDE) 17 SCRC MCRC CRCFAIL CRC response error (WCRCE,RCRCE,SCRCE,CCRCE) 18 SEND MEND STOPBIT_ERR End bit error (WEBER,REBER,SEBER,CEBER) 19 SDTO MDTO DATATIMEOUT Data Timeout (NRCS,NWCS,KBSY) 20 SFOF MFOF RXOVERFLOW HOST tried write full 21 SFUF MFUF TXUNDERRUN HOST tried read empty 22 SCTO MCTO CMDTIMEOUT Response start-bit timeout (NRS,NSR) 23 undoc 0 DATA0_PIN (0=Low, 1=High) (of selected port: eMMC or SD Slot) 24 SBRE MBRE RXRDY (fifo not empty) (request data read) 25 SBWE MBWE TXRQ (datafifoempty?) (request data write) 26 0 0 Unknown/unused (always 0) 27 undoc undoc Unknown/undoc (bit27 is mask-able in IRQ_MASK) 28 0 0 Unknown/unused (always 0) 29 undoc 0 CMD_READY? (inverse of BUSY?) (unlike toshiba ILFSL/IFSMSK) 30 undoc 0 CMD_BUSY (CMD_BUSY=0 shortly before CMD_READY=1?) 31 ILA IMSK Illegal Command Access (old CMD still busy, or wrong NTDT) |
Bit Stat Mask Function 15 undoc undoc SomeIRQ (triggered SOMETIMES on forced CMDTIMEOUT?) 14 undoc undoc SomeIRQ (triggered near DATAEND?) 13-3 0 0 Always zero 2 undoc undoc SomeIRQ (triggered on forced TXUNDERRUN?) 1 undoc undoc SomeIRQ (triggered about once per datablock?) 0 CINT0 CIMSK0 CardIRQ (triggered by /IRQ aka Data1 pin; for SDIO devices) |
15-10 Always zero 9 Enable setting SD_CARD_IRQ_STAT.bit14 and cause nothing special? (R/W) 8 Enable setting SD_CARD_IRQ_STAT.bit15 and cause CMDTIMEOUT? (R/W) 7-3 Always zero 2 Enable setting SD_CARD_IRQ_STAT.bit2 and cause TXUNDERRUN? (R/W) 1 Always zero 0 Enable setting SD_CARD_IRQ_STAT.bit0 (CardIRQ upon Data1=LOW) (R/W) |
Bit Stat Mask Function 0 SCOT MCOT CARD_REMOVE (0=No event, 1=Is/was newly ejected) ;\eMMC 1 SCIN MCIN CARD_INSERT (0=No event, 1=Is/was newly inserted) ; Slot 2 undoc 1 SIGSTATE (MMC: Always 1=Inserted) (SDIO: always 0);/Sw 3 0 RW Unknown (stat always 0, but mask is R/W) ;\maybe another 4 0 RW Unknown (stat always 0, but mask is R/W) ; unimplemented 5 0 1 Unknown (stat always 0, and mask always 1) ;/device? 6 0 RW Unknown (stat always 0, but mask is R/W) ;\maybe yet one 7 0 RW Unknown (stat always 0, but mask is R/W) ; more? 8-15 0 0 Unknown/unused (always 0) ;/ 16 ?? RW Unknown (stat can be 0/1) (R/W? or rather R?) 17 ?? RW Unknown (stat can be 0/1) (R/W? or rather R?) 18 ?? 1 Unknown (1=normal, 0=data/read from card to fifo busy?) (R) 19 0 RW Unknown (stat always 0, but mask is R/W) 20 0 RW Unknown (stat always 0, but mask is R/W) 21 0 1 Unknown (stat always 0, and mask always 1) 22 0 RW Unknown (stat always 0, but mask is R/W) 23 0 RW Unknown (stat always 0, but mask is R/W) 24-31 0 0 Unknown/unused (always 0) |
15-13 Always zero 12 TX32RQ IRQ Enable (0=Disable, 1=Enable) (R/W) 11 RX32RDY IRQ Enable (0=Disable, 1=Enable) (R/W) 10 Clear FIFO32 (0=No change, 1=Force FIFO32 Empty) (W) 9 TX32RQ IRQ Flag (0=IRQ, 1=No) (0=FIFO32 Empty) (R) 8 RX32RDY IRQ Flag (0=No, 1=IRQ) (1=FIFO32 Full) (R) 7-2 Always zero 1 Select 16bit/32bit Data Mode (0=DATA16, 1=DATA32, see 40048D8h) (R/W) 0 Always zero |
31-23 0 Always zero 22 KBSY Timeout for CRC status busy ;\STAT.19 21 NWCS Timeout for CRC status (can occur for Data Write) ; (SDTO) 20 NRCS Timeout for Data start-bit, or for Post Data Busy ;/ 19-18 0 Always zero 17 NRS Response Timeout for auto-issued CMD12 ;\STAT.22 16 NCR Response Timeout for non-auto-issued CMD's ;/(SCTO) 15-14 0 Always zero 13 undoc Unknown/undoc (always 1) ;-Always 1 12 0 Always zero 11 WCRCE CRC error for Write CRC status for a write command ;\ 10 RCRCE CRC error for Read Data ; STAT.17 9 SCRCE CRC error for a Response for auto-issued CMD12 ; (SCRC) 8 CCRCE CRC error for a Response for non-auto-issued CMD's ;/ 5 WEBER End bit error for Write CRC status ;\ 4 REBER End bit error for Read Data ; STAT.18 3 SEBER End bit error for Response for auto-issued CMD12 ; (SEND) 2 CEBER End bit error for Response for non-auto-issued CMD's ;/ 1? SCMDE Bad CMD-index in Response of auto-issued CMD12 ;\STAT.16 0 RCMDE Bad CMD-index in Response of non-auto-issued CMD's ;/(SCIX) |
15-1 Always zero 0 WRPROTECT_2 for onboard eMMC (usually/always 0=Unlocked) (R) |
- first acknowledge IF2.bit8 (must be done before next step) - then check for pending IRQs in IRQ_STATUS and DATA32_IRQ, and process all of them |
| DSi SD/MMC I/O Ports: Control Registers |
15-11 Always zero 10 Unknown (should be set on write) (reads as zero) (1=CardIRQ off!) (W) 9-8 Unknown (Always 2 for SD/4004802h, always 1 for SDIO/4004A02h) (R) 7-4 Always zero 3-1 Unknown (read/write-able) (R/W) 0 Port Select (0=SD Card Slot, 1=Onboard eMMC) (for SDIO: Unknown) (R/W) |
15 undoc Bus Width (0=4bit, 1=1bit) (R/W) 14 undoc Unknown (usually set) (R?) 13-9 0 Always zero 8 undoc Unknown (firmware tries to toggle this after CLK change?) (W?) 7-4 RTO Data start/busy timeout (2000h SHL 0..14, or 15=100h SDCLK's)(R/W) 0-3 TO? SIGSTATE detect delay (400h SHL 0..14, or 15=100h HCLK's) (R/W) |
15-11 Always zero ;unlike Toshiba: no HCLK divider-disable in bit15) 10 Unknown (0=Normal, 1=Unknown, doesn't affect SDCLK output?) (R/W) 9 SDCLK Auto pause (0=Normal, 1=Freeze SDCLK output when inactive) (R/W) 8 SDCLK Pin Enable (0=Force SDCLK=LOW, 1=Output SDCLK=HCLK/n) (R/W) 7-0 HCLK Div (0,1,2,4,8,16,32,64,128 = Div2,4,8,16,32,64,128,256,512) (R/W) |
15-9 Always zero 8 Auto-Stop (1=Automatically send CMD12 after BLK_COUNT blocks) (R/W) 7-1 Always zero 0 Unknown (firmware often clears this bit, but never sets it?) (R/W) |
15-3 Always zero 2 Unknown (always 1) (R?) 1 Unknown (always 1) (though firmware tries to toggle this bit) (R?) 0 SRST Soft Reset (0=Reset, 1=Release) (R/W) |
SD_STOP_INTERNAL_ACTION = 0000h SD_RESPONSE0-7 = zerofilled SD_IRQ_STATUS0-1 = all IRQ flags acknowledged SD_ERROR_DETAIL_STATUS0-1 = all bits cleared (except bit13/always set) SD_CARD_CLK_CTL = bit 8 and 10 cleared SD_CARD_OPTION = 40EEh SD_CARD_IRQ_STAT = 0000h Internal FIFO16 address is reset to first halfword of FIFO_A Reading FIFO16 returns 0000h (but old content reappears when releasing reset) |
| DSi SD/MMC I/O Ports: Unknown/Unused Registers |
15-2 Always zero 1-0 Unknown (0..3) (R/W) |
15-11 Always zero 10-8 Unknown (0..7) (R/W) 7 Always zero 6-4 Unknown (0..7) (R/W) 3-0 Always zero |
400482Ah/4004A2Ah 2 Fixed always zero? 4004832h/4004A32h 2 Fixed always zero? ;(TC6371AF:BUF1 Data MSBs?) 400483Ah/4004A3Ah 2 Fixed always zero? ;(SDCTL_SDIO_HOST_INFORMATION) 400483Ch/4004A3Ch 2 Fixed always zero? ;(SDCTL_ERROR_CONTROL) 400483Eh/4004A3Eh 2 Fixed always zero? ;(TC6387XB: LED_CONTROL) 4004840h/4004A40h 2 Fixed always 003Fh? 4004842h/4004A42h 2 Fixed always 002Ah? 4004844h/4004A44h 6Eh Fixed always zerofilled? 40048B2h/4004AB2h 2 Fixed always FFFFh? 40048B4h/4004AB4h 6 Fixed always zerofilled? 40048BAh/4004ABAh 2 Fixed always 0200h? 40048BCh/4004ABCh 1Ch Fixed always zerofilled? 40048DAh/4004ADAh 6 Fixed always zerofilled? 40048E2h/4004AE2h 2 Fixed always 0009h? ;(RESERVED2/9, TC6371AF:CORE_REV) 40048E4h/4004AE4h 2 Fixed always zero? 40048E6h/4004AE6h 2 Fixed always zero? ;(RESERVED3, TC6371AF:BUF_ADR) 40048E8h/4004AE8h 2 Fixed always zero? ;(TC6371AF:Resp_Header) 40048EAh/4004AEAh 6 Fixed always zerofilled? 40048F0h/4004AF0h 2 Fixed always zero? ;(RESERVED10) 4004902h/4004B02h 2 Fixed always zero? 4004906h/4004B06h 2 Fixed always zero? 400490Ah/4004B0Ah 2 Fixed always zero? 4004910h/4004B10h F0h Fixed always zerofilled? |
| DSi SD/MMC I/O Ports: Misc |
Chip Year Pages Features Toshiba TC6371AF 2000-2002 58 SD/MMC/Smart/PCI (old/basic specs, no SDIO) Toshiba TC6380AF 2001-2002 90 SD/MMC/SDIO/SmartMedia Toshiba TC6387XB 2001-2002 62 SD/MMC/SDIO/SDLED Toshiba TC6391XB 2002 202 SD/MMC/SDIO/SmartMedia/USB/LCD/etc. Toshiba TC6393XB ? ;\unknown features, no datasheet exists (the chips Toshiba T7L66XB ? ;/are mentioned in tmio_mmc.h and tmio_mmc.c source) |
https://github.com/torvalds/linux/tree/master/drivers/mmc/host/ (see files toshsd.* and tmio_mmc.*) (that just as historic references, meanwhile there's better source code around, written specifically for DSi and 3DS hardware) |
| DSi SD/MMC Protocol: Command/Response/Register Summary |
CMD0 sd/mmc spi GO_IDLE_STATE (CMD0 with arg=stuff) (type=bc) CMD0 mmc GO_PRE_IDLE_STATE (CMD0 with arg=F0F0F0F0h) (type=bc) CMD0 mmc BOOT_INITIATION (CMD0 with arg=FFFFFFFAh, type=N/A) CMD1 sd/mmc spi SEND_OP_COND (On SD Cards: SPI only) CMD2 sd/mmc ALL_GET_CID (type=bcr) CMD3 sd GET_RELATIVE_ADDR (type=bcr) CMD3 mmc SET_RELATIVE_ADDR (type=ac) CMD4 sd/mmc SET_DSR (type=bc) CMD5 sd spi Reserved for I/O cards (see "SDIO Card Specification") CMD5 mmc ? SLEEP_AWAKE (type=ac) (MMC only, IO_SEND_OP_COND on SDIO) CMD7 sd/mmc SELECT_DESELECT_CARD (type=ac) ;actually: (type=bcr) CMD8 sd spi SET_IF_COND (type=bcr) CMD8 mmc spi GET_EXT_CSD (type=adtc) CMD9 sd/mmc spi GET_CSD (type=ac) (SPI: type=adtc) CMD10 sd/mmc spi GET_CID (type=ac) (SPI: type=adtc) CMD11 sd VOLTAGE_SWITCH (type=ac) CMD12 sd/mmc spi STOP_TRANSMISSION (type=ac) CMD13 sd/mmc spi GET_STATUS (type=ac) (sends 16bit status in SPI Mode) CMD14 mmc BUSTEST_R (type=adtc) (MMC only, Reserved on SD) CMD19 mmc BUSTEST_W (type=adtc) (MMC only, SET_TUNING_BLOCK on SD) CMD15 sd/mmc GO_INACTIVE_STATE (type=ac) |
CMD16 sd/mmc spi SET_BLOCKLEN (type=ac) CMD17 sd/mmc spi READ_SINGLE_BLOCK (type=adtc) CMD18 sd/mmc spi READ_MULTIPLE_BLOCK (type=adtc) CMD19 sd SET_TUNING_BLOCK (type=adtc) CMD20 sd SPEED_CLASS_CONTROL (type=ac) CMD22 sd Reserved CMD23 sd/mmc-spi SET_BLOCK_COUNT (type=ac) (SPI supported ONLY on MMC?) |
CMD16 sd/mmc spi SET_BLOCKLEN (type=ac) CMD20 sd SPEED_CLASS_CONTROL (type=ac) CMD23 sd/mmc-spi SET_BLOCK_COUNT (type=ac) (SPI supported ONLY on MMC?) CMD24 sd/mmc spi WRITE_BLOCK (type=adtc) CMD25 sd/mmc spi WRITE_MULTIPLE_BLOCK (type=adtc) CMD26 sd/mmc Reserved For Manufacturer (MMC: PROGRAM_CID) CMD27 sd/mmc spi PROGRAM_CSD (type=adtc) |
CMD28 sd/mmc spi SET_WRITE_PROT (type=ac) CMD29 sd/mmc spi CLR_WRITE_PROT (type=ac) CMD30 sd/mmc spi GET_WRITE_PROT (type=adtc) CMD31 - SD: Reserved CMD31 mmc MMC: SEND_WRITE_PROT_TYPE (type=adtc) |
CMD32 sd spi ERASE_WR_BLK_START (type=ac) CMD33 sd spi ERASE_WR_BLK_END (type=ac) CMD32-34 mmc spi Reserved for compatibility with older MMC cards (uh?) CMD35 mmc spi ERASE_GROUP_START (type=ac) CMD36 mmc spi ERASE_GROUP_END (type=ac) CMD37 mmc spi Reserved for compatibility with older MMC cards (uh?) CMD38 sd/mmc spi ERASE (type=ac) CMD39 - Reserved CMD41 - Reserved |
CMD16 sd/mmc spi SET_BLOCKLEN (type=ac) CMD40 sd Defined by DPS Spec (Data Protection System) (type=adtc) CMD42 sd/mmc spi LOCK_UNLOCK (type=adtc) CMD43-47 - Reserved CMD51 - Reserved |
CMD39-40 mmc MMCA Optional Command, currently not supported CMD55-56 mmc MMCA Optional Command, currently not supported CMD55 sd spi APP_CMD (type=ac) ;\also defined for MMC, CMD56 sd spi GEN_CMD (type=adtc) ;/but ONLY in SPI mode !!?? CMD60-63 sd/mmc spi Reserved for manufacturer |
CMD5 sdio spi SDIO: IO_SEND_OP_COND CMD52 sdio spi SDIO: IO_RW_DIRECT CMD53 sdio spi SDIO: IO_RW_EXTENDED CMD54 - SDIO: Reserved CMD39 mmcio MMCIO: FAST_IO (type=ac) CMD40 mmcio MMCIO: GO_IRQ_STATE (type=bcr) |
CMD6 mmc spi SWITCH (type=ac) ;related to EXT_CSD register CMD6 sd spi SWITCH_FUNC (type=adtc) CMD34-37 sd+spi Reserved for Command Systems from CMD6 ;\SPI CMD50,57 sd+spi Reserved for Command Systems from CMD6 ;/ CMD34-35 sd Reserved ;\ CMD36-37 sd Undoc (description field is held blank) ; Non-SPI CMD50,57 sd Undoc (description field is held blank) ;/ |
CMD21 sd Reserved for DPS Specification (Data Protection System) CMD48 sd READ_EXTR_SINGLE (type=adtc) CMD49 sd WRITE_EXTR_SINGLE (type=adtc) CMD58 sd READ_EXTR_MULTI (type=adtc) ;SPI: READ_OCR CMD59 sd WRITE_EXTR_MULTI (type=adtc) ;SPI: CRC_ON_OFF |
CMD11 mmc READ_DAT_UNTIL_STOP (class 1) (type=adtc) CMD20 mmc WRITE_DAT_UNTIL_STOP (class 3) (type=adtc) |
CMD58 sd/mmc+spi READ_OCR ;SPI-only ;SD Mode: READ_EXTR_MULTI CMD59 sd/mmc+spi CRC_ON_OFF ;SPI-only ;SD Mode: WRITE_EXTR_MULTI |
ACMD6 sd SET_BUS_WIDTH (type=ac) ACMD13 sd spi SD_STATUS (type=adtc) (get 512bit SSR) ACMD22 sd spi GET_NUM_WR_BLOCKS (type=adtc) ACMD23 sd spi SET_WR_BLK_ERASE_COUNT (type=ac) ACMD41 sd spi SD_SEND_OP_COND (type=bcr) ;SPI: reduced functionality ACMD42 sd spi SET_CLR_CARD_DETECT (type=ac) ACMD51 sd spi GET_SCR (type=adtc) ACMD1-5 - Reserved ACMD7-12 - Reserved ACMD14-16 sd Reserved for DPS Specification (Data Protection System) ACMD17 - Reserved ACMD18 sd spi Reserved for SD security applications ACMD19-21 - Reserved ACMD24 - Reserved ACMD25 sd spi Reserved for SD security applications ACMD26 sd spi Reserved for SD security applications ACMD27 - Shall not use this command ACMD28 sd Reserved for DPS Specification (Data Protection System) ACMD29 - Reserved ACMD30-35 sd Reserved for Security Specification ACMD36-37 - Reserved ACMD38 sd spi Reserved for SD security applications ACMD39-40 - Reserved ACMD43-49 sd spi Reserved for SD security applications ACMD52-54 sd Reserved for Security Specification ACMD55 - Not exist (equivalent to CMD55) ACMD56-59 sd Reserved for Security Specification ACMD0 - Unknown/Unused/Undocumented ACMD50 - Unknown/Unused/Undocumented ACMD60-63 - Unknown/Unused/Undocumented |
CSR 32bit sd/mmc spi Card Status: command error & state information OCR 32bit sd/mmc spi Operation Conditions Register CID 128bit sd/mmc spi Card Identification CSD 128bit sd/mmc spi Card-Specific Data (CSD Version 1.0 and 2.0) RCA 16bit sd/mmc Relative Card Address (not used in SPI mode) DSR 16bit sd/mmc spi Driver Stage Register (optional) SSR 512bit sd spi SD Card Status Register: Extended status field SCR 64bit sd spi SD Card Configuration Register EXT_CSD 4096bit mmc spi MMC Extended CSD Register (status & config) PWD 128bit sd/mmc spi Password (Card Lock) (max 16 bytes) PWD_LEN 8bit sd/mmc spi Password Length (0..16 max) (0=no password) |
N/A 0bit CMD0, CMD4, CMD15 No response R1 48bit Normal CMDs/ACMDs 32bit CSR Card Status R1b 48bit Busy CMDs/ACMDs 32bit CSR Card Status (and DATA=busy) R2 136bit CMD9 120bit CSD Card-Specific Data R2 136bit CMD2, CMD10 120bit CID Card Identification R3 48bit ACMD41, MMC:CMD1 32bit OCR Register (without crc7) R4 - - Reserved for SDIO R5 - - Reserved for SDIO R6 48bit CMD3 16bit RCA and cut-down 16bit CSR R7 48bit CMD8 32bit Card interface condition |
R1 8bit Normal CMDs/ACMDs 8bit CSR Card Status R1b 8bit Busy CMDs/ACMDs 8bit CSR Card Status (and DATA=busy) R2 16bit CMD13, ACMD13 16bit CSR Card Status R3 40bit CMD58 8bit CSR and 32bit OCR R4 - - Reserved for SDIO R5 - - Reserved for SDIO R6 - - Reserved R7 40bit CMD8 8bit CSR and 32bit Card interface condition ERROR 8bit Only first 8bit sent upon Illegal Command or Command CRC Error |
CMD17,18 R sd/mmc spi READ_SINGLE_BLOCK, READ_MULTIPLE_BLOCK CMD24,25 W sd/mmc spi WRITE_BLOCK, WRITE_MULTIPLE_BLOCK CMD8 R mmc spi GET_EXT_CSD (4096bit) CMD9 R sd/mmc spi GET_CSD (128bit) ;\in SPI Mode only (Non-SPI mode CMD10 R sd/mmc spi GET_CID (128bit) ;/sends that info as CMD response) ACMD13 R sd spi SD_STATUS (512bit SSR register) ACMD22 R sd spi GET_NUM_WR_BLOCKS (32bit counter) ACMD51 R sd spi GET_SCR (64bit SCR register) CMD14,19 R/W mmc BUSTEST_R, BUSTEST_W CMD19 W? sd SET_TUNING_BLOCK (512bit tuning pattern) CMD27 W sd/mmc spi PROGRAM_CSD (128bit CSD register) CMD30 R sd/mmc spi GET_WRITE_PROT (32bit write-protect flags) CMD31 R mmc GET_WRITE_PROT_TYPE (32x2bit write-protect types) CMD42 W sd/mmc spi LOCK_UNLOCK (password header/data) CMD6 ?? sd spi SWITCH_FUNC CMD40 ? sd Defined by DPS Spec (Data Protection System) CMD48,49 R/W sd READ_EXTR_SINGLE, WRITE_EXTR_SINGLE CMD58,59 R/W sd READ_EXTR_MULTI, WRITE_EXTR_MULTI CMD56 R/W sd spi GEN_CMD CMD11 R mmc READ_DAT_UNTIL_STOP (class 1) (type=adtc) CMD20 W mmc WRITE_DAT_UNTIL_STOP (class 3) (type=adtc) xR1b R sd/mmc spi Busy signal for commands with "R1b" response |
Official Name Renamed ALL_SEND_CID ALL_GET_CID SEND_CID GET_CID SEND_CSD GET_CSD SEND_STATUS GET_STATUS SEND_RELATIVE_ADDR GET_RELATIVE_ADDR SEND_SCR GET_SCR SEND_EXT_CSD GET_EXT_CSD SEND_WRITE_PROT GET_WRITE_PROT SEND_WRITE_PROT_TYPE GET_WRITE_PROT_TYPE SEND_NUM_WR_BLOCKS GET_NUM_WR_BLOCKS SEND_IF_COND SET_IF_COND ;-to card SEND_TUNING_BLOCK SET_TUNING_BLOCK ;-to card SEND_OP_COND ... SD_SEND_OP_COND ... |
CMD0 Terminate SD transaction and reset SD-TRAN state.
CMD3 Returns Device ID in the response instead of RCA
CMD4 Illegal
CMD6 Function Group 1 and 3 are not used.
CMD7 Device ID is set to the argument instead of RCA
CMD13 Device operation is up to implementation during data transfer (eg. CTS)
CMD11 Illegal
CMD12 Normally, TLEN (data length) in UHS-II packet is used to stop data
transfer.
CMD12 Should be used to abort an operation when illegal situation occurs.
CMD15 Illegal
CMD19 Illegal
CMD23 Not Affected. TLEN in UHS-II packet is used to specify data length.
CMD55 Not Affected. ACMD is set by APP field in UHS-II packet.
ACMD6 Illegal
ACMD42 Illegal
|
| DSi SD/MMC Protocol: General Commands |
31-0 stuff bits |
31-12 reserved bits 11-8 supply voltage (VHS) 7-0 check pattern |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Command (the 6bit CMD being responded to) ;/ 39-20 Reserved (zero filled) (20bit) ;\2nd..4th byte 19-16 Voltage accepted (see below) (4bit) ;/ 23-8 Echo-back of check pattern (8bit) ;-5th byte 7-1 CRC7 ;\6th byte 0 End Bit (1) ;/ |
39-32 R1 (8bit Card Status, same as in normal SPI command responses) 31-28 Command version (???) (4bit) 27-12 Reserved (0) (16bit) 11-8 Voltage Accepted (see below) (4bit) 7-0 Echo-back of check pattern (8bit) |
0001b = 2.7-3.6V 0010b = Reserved for Low Voltage Range 0100b = Reserved 1000b = Reserved Others = Not Defined |
31-0 reserved bits (0) |
31-0 stuff bits |
31-16 RCA 15-0 reserved bits (0) |
31-1 stuff bits 0 CRC option (0=off, 1=on) |
31-2 stuff bits 1-0 Bus width for Data transfers (0=1bit, 2=4bit, 1/3=reserved). |
31-1 stuff bits 0 set_cd (0=Disconnect, 1=Connect) |
31-16 RCA (SPI Mode: stuff bits) 15-0 stuff bits |
31-1 stuff bits 0 RD/WR Direction (0=Write to Card, 1=Read from Card) |
General purpose data For SDSC, block length is set via SET_BLOCKLEN command. For SDHC/SDXC, block length is fixed to 512 bytes. |
31-0 stuff bits |
test pattern (2bit per DATA line? eg. 8bit pattern in 4bit-mode?) |
| DSi SD/MMC Protocol: Block Read/Write Commands |
31-0 Block length (for Block Read, Block Write, Lock, and GEN_CMD) |
31-28 Speed Class Control (for Block Read, and Block Write commands) 27-0 Reserved (0) |
31-0 Block Count (MMC: only lower 16bit used, upper 16bit=reserved) |
________________________ Block-Oriented READ Commands ________________________ |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: in 512-byte units) |
data |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: in 512-byte units) |
data |
31-0 reserved bits (0) |
64 bytes (512bit) tuning pattern is sent for SDR50 and SDR104. |
_______________________ Block-Oriented WRITE Commands _______________________ |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: in 512-byte units) |
data |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: in 512-byte units) |
data |
31-0 stuff bits |
31-0 Number of the written (without errors) write blocks (32bit) |
31-23 stuff bits 22-0 Number of blocks |
_____________________ Byte-Streaming READ/WRITE Commands _____________________ |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: in 512-byte units) |
data |
| DSi SD/MMC Protocol: Special Extra Commands |
_________________________ Write PROTECTION Commands _________________________ |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: Unsupported) |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: Unsupported) |
31-0 Flags (1=write-protected) (bit0=addressed group, bit1..31=next groups) |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: Unsupported) |
63-0 Flags (1=write-protected) (bit0-1=addressed group, bit2..63=next) |
_______________________________ Erase Commands _______________________________ |
31-0 data address (SDSC: in 1-byte units, SDHC/SDXC: in 512-byte units) |
31-0 data address (MMC: in WHAT units?) |
31-0 stuff bits |
________________________________ I/O Commands ________________________________ |
CMD5 SDIO: IO_SEND_OP_COND CMD52 SDIO: IO_RW_DIRECT CMD53 SDIO: IO_RW_EXTENDED |
__________________________ Switch Function Commands __________________________ |
31 Mode (0=Check function, 1=Switch function) 30-24 reserved (All '0') 23-20 function group 6: Reserved (0h or Fh) 19-16 function group 5: Reserved (0h or Fh) 15-12 function group 4: Power Limit ;SPI Mode: Reserved (0h or Fh) 11-8 function group 3: Drive Strength ;SPI Mode: Reserved (0h or Fh) 7-4 function group 2: Command System 3-0 function group 1: Access Mode |
unknown |
________________________ Function Extension Commands ________________________ |
31 MIO (0=Memory, 1=I/O) 30-27 FNO 26 Reserved (0) 25-9 ADDR 8-0 LEN |
whatever |
31 MIO (0=Memory, 1=I/O) 30-27 FNO 26 MW 25-9 ADDR 8-0 LEN/MASK |
whatever |
31 MIO (0=Memory, 1=I/O) 30-27 FNO 26 BUS (0=512B, 1=32KB) 25-9 ADDR 8-0 BUC |
whatever |
31 MIO (0=Memory, 1=I/O) 30-27 FNO 26 BUS (0=512B, 1=32KB) 25-9 ADDR 8-0 BUC |
whatever |
| DSi SD/MMC Protocol: CSR Register (32bit Card Status Register) |
31-16 RCA (SPI Mode: stuff bits) 15-0 stuff bits |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Command (the 6bit CMD being responded to) ;/ 39-8 CSR Card Status Register (32bit) (see below) ;-2nd..5th byte 7-1 CRC7 ;\6th byte 0 End Bit (1) ;/ |
15-0 CSR Card Status Register (16bit) (see below) ;-1st..2nd byte |
Bit Typ Clr Identifier Meaning
31 ERX C OUT_OF_RANGE (1=Command's argument was out of range)
30 ERX C ADDRESS_ERROR (1=Misaligned address/block len mismatch)
29 ERX C BLOCK_LEN_ERROR (1=Wrong block length, bytelen mismatch)
28 ER C ERASE_SEQ_ERROR (1=Error in erase command sequence)
27 ERX C ERASE_PARAM (1=Wrong erease selection of write-blocks)
26 ERX C WP_VIOLATION (1=Write failed due to write-protection)
25 SX A CARD_IS_LOCKED (1=Card is locked by the host)
24 ERX C LOCK_UNLOCK_FAILED (1=Lock/unlock sequence or password error)
23 ER B COM_CRC_ERROR (1=CRC check of previous command failed)
22 ER B ILLEGAL_COMMAND (1=Command not legal for the card state)
21 ERX C CARD_ECC_FAILED (1=Internal error correction failed)
20 ERX C CC_ERROR (1=Internal card controller error)
19 ERX C ERROR (1=General error, or Unknown error)
18 - - Reserved (eMMC: UNDERRUN)
17 - - Reserved (eMMC: OVERRUN) (eSD: DEFERRED_RESPONSE)
16 ERX C CSD_OVERWRITE (1=read-only CSD section doesn't match card
content, or attempted to reverse the
Copy/WP bits)
15 ERX C WP_ERASE_SKIP (1=partial erase error due to write-protect)
14 SX A CARD_ECC_DISABLED (1=Internal error correction wasn't used)
13 SR C ERASE_RESET (1=Erase sequence was aborted)
12-9 SX B CURRENT_STATE (00h..0Fh=state, see below)
8 SX A READY_FOR_DATA (1=Ready/buffer is empty)
7 EX C SWITCH_ERROR (1=SWITCH command refused, MMC only)
6 - - Reserved/Unspecified (description is left blank)
5 SR C APP_CMD (1=Card will expect ACMD)
4 - - Reserved for SD I/O Card
3 ER C AKE_SEQ_ERROR (1=Authentication Sequence Error)
2 - - Reserved for application specific commands
1-0 - - Reserved for manufacturer test mode
|
These bits indicate the OLD state of card when receiving the command, (ie. if the command does change the state, then the NEW state won't be seen until the NEXT command returns the new updated status bits) 00h = idle 01h = ready 02h = ident 03h = stby 04h = tran ;<-- normal state (when waiting for read/write commands) 05h = data ;data read (CMD8,CMD11,CMD17,CMD18,CMD30,CMD56/R) 06h = rcv ;data write (CMD20?,CMD24,CMD25,CMD26,CMD27,CMD42,CMD56/W) 07h = prg ;erase/wprot (CMD6,CMD28,CMD29,CMD38) 08h = dis 09h = btst ;bus test write (CMD19, MMC only) 0Ah = slp ;sleep (CMD5, MMC only) 0Bh-0Eh = reserved 0Fh = reserved for I/O mode (SDIO-only devices, without SD-memory) N/A = ina ;inactive (CMD15) (card is killed, and can't send status) N/A = irq ;interrupt mode (CMD40, MMC only) N/A = pre ;pre-idle (MMC only) |
E: Error bit. S: Status bit. R: Flag may get set within response of current command. X: Flag may get set within response of NEXT command (with R1 response) |
A: According to the card current state.
B: Always related to the previous command. Reception of a valid command
will clear it (with a delay of one command).
C: Clear by read.
|
FIRST BYTE of all SPI Responses: 7 always 0 ;\ 6 parameter error ; These 8bit are returned in ALL normal 5 address error ; SPI commands (with 8bit "R1" response) 4 erase sequence error ; and, 3 com crc error ; the same 8bits are also returned 2 illegal command ; as FIRST BYTE in SPI commands with 1 erase reset ; longer responses 0 in idle state ;/ SECOND BYTE of SPI "R2" Response: 7 out of range, or csd overwrite ;\ 6 erase param ; 5 wp violation ; These extra 8bits are returned 4 card ecc failed ; as SECOND BYTE in SPI commands 3 CC error ; with 16bit "R2" status response 2 error ; (ie. in CMD13 and ACMD13) 1 wp erase skip, or lock/unlock cmd failed ; 0 Card is locked ;/ |
Bits 31 30 29 28 27 26 25 24 23 22 21 20 19 18 17 16 15 14 13 12-9 8 5 CMD3 x x x x CMD6 x x x x x x x x CMD7 x x x x x x x x x x x x x x x CMD11 x x x x x CMD12 x x x x x x x x x x x CMD13 x x x x x x x x x x x x x x x x CMD16 x x x x x x x x x x x x x x x CMD17 x x x x x x x x x x x x x x x x CMD18 x x x x x x x x x x x x x x x x CMD19 x x x x x x x x x x x x x x x x CMD20 x x x x x x x x x x x x x x x x x x CMD23 x x x x x x x x x x x x x x x x x CMD24 x x x x x x x x x x x x x x x x x x CMD25 x x x x x x x x x x x x x x x x x x CMD26 x x x x x x x x x x x x x x CMD27 x x x x x x x x x x x x x x CMD28 x x x x x x x x x x x x x x x CMD29 x x x x x x x x x x x x x x x CMD30 x x x x x x x x x x x x x x x CMD32 x x x x x x x x x x x x x x x x CMD33 x x x x x x x x x x x x x x x x CMD38 x x x x x x x x x x x x x x x CMD42 x x x x x x x x x x x x x x CMD48 x x x x x x x x x x x x x x x x x x CMD49 x x x x x x x x x x x x x x x x x x CMD55 x x x x x x x x x x x x x x x CMD56 x x x x x x x x x x x x x x x x CMD58 x x x x x x x x x x x x x x x x x x CMD59 x x x x x x x x x x x x x x x x x x ACMD6 x x x x x x x x x x x x x x x x ACMD13 x x x x x x x x x x x x x x x ACMD22 x x x x x x x x x x x x x x x ACMD23 x x x x x x x x x x x x x x x ACMD42 x x x x x x x x x x x x x x x ACMD51 x x x x x x x x x x x x x x x |
| DSi SD/MMC Protocol: SSR Register (512bit SD Status Register) |
31-0 stuff bits |
511-0 SSR Register (512bit) |
Bits Type Clr Identifier
511-510 SR A DAT_BUS_WIDTH (0..3, see below)
509 SR A SECURED_MODE (0=Normal, 1=Secured) (Part 3 Security Specs)
508-502 - - Reserved for Security Functions (Part 3 Security Specs)
501-496 - - Reserved
495-480 SR A SD_CARD_TYPE (0..FFFFh, see below)
479-448 SR A SIZE_OF_PROTECTED_AREA Size of protected area (see below)
447-440 SR A SPEED_CLASS Speed Class of the card (see below)
439-432 SR A PERFORMANCE_MOVE Performance of move indicated by 1 MB/s step
431-428 SR A AU_SIZE Size of AU (see below)
427-424 - - Reserved
423-408 SR A ERASE_SIZE Number of AUs to be erased at a time
407-402 SR A ERASE_TIMEOUT Timeout value for erasing areas
specified by UNIT_OF_ERASE_AU (see below)
401-400 SR A ERASE_OFFSET Fixed offset value added to erase time
399-396 SR A UHS_SPEED_GRADE Speed Grade for UHS mode (see below)
395-392 SR A UHS_AU_SIZE Size of AU for UHS mode (see below)
391-312 - - Reserved
311-0 - - Reserved for manufacturer
|
00h = 1 bit width (default) 01h = reserved 02h = 4 bit width 03h = reserved |
0000h = Regular SD RD/WR Card 0001h = SD ROM Card 0002h = OTP 0004h,0008h,0010h,0020h,0040h,0080h = Reserved for future variations 01xxh..FFxxh = Reserved for Cards that don't comply to Physical Layer Specs |
Protected Area = SIZE_OF_PROTECTED_AREA_* MULT * BLOCK_LEN. SIZE_OF_PROTECTED_AREA is specified by the unit in MULT*BLOCK_LEN. |
Protected Area = SIZE_OF_PROTECTED_AREA SIZE_OF_PROTECTED_AREA is specified by the unit in byte. |
00h Speed Class 0 01h Speed Class 2 02h Speed Class 4 03h Speed Class 6 04h Speed Class 10 05h-FFh Reserved for future/faster classes |
00h Sequential Write 01h 1 [MB/sec] 02h 2 [MB/sec] ... ... FEh 254 [MB/sec] FFh Infinity |
00h Not Defined 01h 16 KB 02h 32 KB 03h 64 KB 04h 128 KB 05h 256 KB 06h 512 KB 07h 1 MB 08h 2 MB 09h 4 MB 0Ah 8 MB 0Bh 12 MB (!) 0Ch 16 MB 0Dh 24 MB (!) 0Eh 32 MB 0Fh 64 MB |
Card Capacity up to 64MB up to 256MB up to 512MB up to 32GB up to 2TB Maximum AU Size 512 KB 1 MB 2 MB 4 MB1 64MB |
0000h Erase Time-out Calculation is not supported. 0001h 1 AU 0002h 2 AU 0003h 3 AU ... ... FFFFh 65535 AU |
00h Erase Time-out Calculation is not supported. 01h 1 [sec] 02h 2 [sec] 03h 3 [sec] ... ... 3Fh 63 [sec] |
00h 0 [sec] 01h 1 [sec] 02h 2 [sec] 03h 3 [sec] |
00h Less than 10MB/sec 01h 10MB/sec and above 02h-0Fh Reserved |
00h Not Defined 01h-06h Not Used 07h 1 MB 08h 2 MB 09h 4 MB 0Ah 8 MB 0Bh 12 MB (!) 0Ch 16 MB 0Dh 24 MB (!) 0Eh 32 MB 0Fh 64 MB |
| DSi SD/MMC Protocol: OCR Register (32bit Operation Conditions Register) |
31-0 OCR without busy (ie. without the power-up busy flag in bit31) |
31 Reserved (0) ;\special case (applies 30 HCS (Host Capacity Support information) ; to SD-cards in SPI-mode 29-0 Reserved (0) ;/only) |
31 reserved bit 30 HCS(OCR[30]) (Host Capacity Support information) 29 reserved for eSD ;\ 28 XPC Max Power Consumption (watts); SPI Mode: Reserved 27-25 reserved bits ; (ie. only bit30 is used for SPI) 24 S18R ; (ie. ACMD41 is SAME as SPI CMD1 ?) 23-0 VDD Voltage Window(OCR[23-0]) ;/ |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Reserved (111111) (instead of Command value) ;/ 39-8 OCR (32bit) ;-2nd..5th byte 7-1 Reserved (111111) (instead of CRC7) ;\6th byte 0 End Bit (1) ;/ |
XPC=0: 0.36W (100mA at 3.6V on VDD1) (max) but speed class is not supported. XPC=1: 0.54W (150mA at 3.6V on VDD1) (max) and speed class is supported. |
31-0 stuff bits |
39-32 R1 (8bit Card Status, same as in normal SPI command responses) 31-0 OCR (32bit) |
31 Card power up status bit (0=Busy, 1=Ready)
30 Card Capacity Status (CCS) (valid only if above Bit31 indicates Ready)
CCS=0 SDSC Card (addressed in 1-byte units) ;MMC max 2GB
CCS=1 SDHC/SDXC card (addressed in 512-byte units) ;MMC > 2GB
29 UHS-II Card Status
28-25 Reserved
24 Switching to 1.8V Accepted (S18A) (Only UHS-I card supports this bit)
23 3.5-3.6 ;\
22 3.4-3.5 ;
21 3.3-3.4 ;
20 3.2-3.3 ;<-- this used by DSi ;
19 3.1-3.2 ; VDD Voltage Window
18 3.0-3.1 ;
17 2.9-3.0 ;
16 2.8-2.9 ;
15 2.7-2.8 ;
14-8 Reserved (MMC: 2.0V .. 2.6V) ; ;<-- uh, probably in opposite order?
7 Reserved for Low Voltage Range ;
6-4 Reserved ;
3-0 Reserved ;/
|
| DSi SD/MMC Protocol: CID Register (128bit Card Identification) |
31-0 stuff bits |
31-16 RCA (SPI Mode: stuff bits) 15-0 stuff bits |
135 Start Bit (0) ;\ 134 Transmission To Host (0) ; 1st byte 133-128 Reserved (111111) (instead of Command value) ;/ 127-8 CID (120bit) (15 bytes) ;\aka 128bit ;-2nd..16th byte 7-1 CRC7 ; when including ;\17th byte 0 End Bit (1) ;/CRC7+EndBit ;/ |
127-0 CID (128bit) ... or 120bit ? |
Bit Siz Field Name 127-120 8 MID Manufacturer ID (binary) ;\assigned by SD-3C, LLC 119-104 16 OID OEM/Application ID (ASCII) ;/ 103-64 40 PNM Product name (ASCII) 63-56 8 PRV Product revision (BCD, 00h-99h) (eg 62h = rev 6.2) 55-24 32 PSN Product serial number (32bit) 23-20 4 - Reserved (zero) 19-8 12 MDT Manufacturing date (yymh) (m=1..12, yy=0..255?; +2000) 7-1 7 CRC CRC7 checksum 0 1 1 Stop bit (always 1) |
Bit Siz Field Name 127-120 8 MID Manufacturer ID (binary) ;\assigned by MMCA 119-104 16 OID OEM/Application ID (binary) ;/ ... or ... 127-120 8 MID Manufacturer ID (binary) ;\assigned by MMCA/JEDEC 119-114 6 - Reserved (0) ; 113-112 2 CBX Device (0=Card, 1=BGA, 2=POP) ; 119-104 8 OID OEM/Application ID (binary) ;/ 103-56 48 PNM Product name (ASCII) 55-48 8 PRV Product revision (BCD, 00h-99h) (eg 62h = rev 6.2) 47-16 32 PSN Product serial number (32bit) 15-8 8 MDT Manufacturing date (myh) (m=1..12, y=0..15; +1997) 7-1 7 CRC CRC7 checksum 0 1 1 Stop bit (always 1) |
MY ss ss ss ss 03 4D 30 30 46 50 41 00 00 15 00 ;DSi Samsung KMAPF0000M-S998 MY ss ss ss ss 32 57 37 31 36 35 4D 00 01 15 00 ;DSi Samsung KLM5617EFW-B301 MY ss ss ss ss 30 36 35 32 43 4D 4D 4E 01 FE 00 ;DSi ST NAND02GAH0LZC5 rev30 MY ss ss ss ss 31 36 35 32 43 4D 4D 4E 01 FE 00 ;DSi ST NAND02GAH0LZC5 rev31 MY ss ss ss ss 03 47 31 30 43 4D 4D 00 01 11 00 ;3DS whatever chiptype? MY ss ss ss ss 07 43 59 31 47 34 4D 00 01 15 00 ;3DS Samsung KLM4G1YE0C-B301 |
| DSi SD/MMC Protocol: CSD Register (128bit Card-Specific Data) |
31-16 RCA (SPI Mode: stuff bits) 15-0 stuff bits |
135 Start Bit (0) ;\ 134 Transmission To Host (0) ; 1st byte 133-128 Reserved (111111) (instead of Command value) ;/ 127-8 CSD (120bit) (15 bytes) ;\aka 128bit ;-2nd..16th byte 7-1 CRC7 ; when including ;\17th byte 0 End Bit (1) ;/CRC7+EndBit ;/ |
127-0 CID (128bit) ... or 120bit ? |
31-0 stuff bits |
128-0 CSD register (whole 128bit) (read-only bits must be unchanged) |
Bit Siz Type Name Field Value 127-126 2 R CSD structure version CSD_STRUCTURE 00b 125-122 4 R MMC: System spec version SPEC_VERS .. 125-122 4 R SD: reserved - 0000b 121-120 2 R reserved - 00b 119-112 8 R data read access-time-1 TAAC xxh 111-104 8 R data read access-time-2 NSAC xxh 103-96 8 R max data transfer rate TRAN_SPEED 32h or 5Ah 95-84 12 R card command classes CCC 01x110110101b 83-80 4 R max read data block len READ_BL_LEN xh 79 1 R partial blocks for read allowed READ_BL_PARTIAL 1b 78 1 R write block misalignment WRITE_BLK_MISALIGN xb 77 1 R read block misalignment READ_BLK_MISALIGN xb 76 1 R DSR implemented DSR_IMP xb 75-74 2 R reserved - 00b 73-70 4 R SDHC/SDXC: reserved - 0000b 69-48 22 R SDHC/SDXC: device size C_SIZE ... 47 1 R SDHC/SDXC: reserved - 0 73-62 12 R MMC/SDSC: device size C_SIZE xxxh 61-59 3 R MMC/SDSC: max read current @VDD min VDD_R_CURR_MIN xxxb 58-56 3 R MMC/SDSC: max read current @VDD max VDD_R_CURR_MAX xxxb 55-53 3 R MMC/SDSC: max write current @VDD min VDD_W_CURR_MIN xxxb 52-50 3 R MMC/SDSC: max write current @VDD max VDD_W_CURR_MAX xxxb 49-47 3 R MMC/SDSC: device size multiplier C_SIZE_MULT xxxb 46-42 5 R MMC: Erase Group Size ERASE_GRP_SIZE .. 41-37 5 R MMC: Erase Group Multiplier ERASE_GRP_MULT .. 36-32 5 R MMC: Write Protect Grp Size WP_GRP_SIZE .. 46 1 R SD: erase single block enable ERASE_BLK_EN xb 45-39 7 R SD: erase sector size SECTOR_SIZE xxxxxxxb 38-32 7 R SD: write protect group size WP_GRP_SIZE xxxxxxxb 31 1 R write protect group enable WP_GRP_ENABLE xb 30-29 2 R MMC: Manufacturer default ECC DEFAULT_ECC .. 30-29 2 R SD: reserved (do not use) - 00b 28-26 3 R write speed factor R2W_FACTOR xxxb 25-22 4 R max write data block len WRITE_BL_LEN xxxxb 21 1 R partial blocks for write allowed WRITE_BL_PARTIAL xb 20-17 4 R reserved - 0000b 16 1 R SD: reserved - 0 16 1 R MMC: Content Protection Applicat. CONTENT_PROP_APP .. 15 1 R/W(1) File format group FILE_FORMAT_GRP xb 15 1 R SDHC/SDXC: reserved (FILE_FORMAT_GRP)0 14 1 R/W(1) copy flag COPY xb 13 1 R/W(1) permanent write protection PERM_WRITE_PROTECT xb 12 1 R/W temporary write protection TMP_WRITE_PROTECT xb 11-10 2 R/W(1) File format FILE_FORMAT xxb 11-10 2 R SDHC/SDXC: reserved (FILE_FORMAT) 00b 9-8 2 R/W MMC: ECC Code ECC .. 9-8 2 R/W SDSC: reserved, R/W - 00b 9-8 2 R SDHC/SDXC: reserved, R - 00b 7-1 7 R/W CRC CRC xxxxxxxb 0 1 - not used, always '1' - 1b |
8 16 24 32 40 48 56 64 72 80 88 96 104112120pad ;<--bit numbers 40 40 96 E9 7F DB F6 DF 01 59 0F 2A 01 26 90 00 ;DSi Samsung KMAPF0000M-S998 40 40 8E FF 03 DB F6 DF 01 59 0F 32 01 27 90 00 ;DSi Samsung KLM5617EFW-B301 00 40 8A E0 BF FF 7F F5 80 59 0F 32 01 2F 90 00 ;DSi ST NAND02GAH0LZC5 rev30 00 40 8A E0 BF FF 7F F5 80 59 0F 32 01 2F 90 00 ;DSi ST NAND02GAH0LZC5 rev31 ? 00 ;3DS whatever chiptype? 40 40 8A E7 FF DB F6 6B 02 5A 0F 32 01 27 D0 00 ;3DS Samsung KLM4G1YE0C-B301 |
bit name KMAPF0000M KLM5617EFW NAND02GAH0LZC5 KLM4G1YE0C 126-127 CSD_STRUCTURE 2=v1.2 2=v1.2 2=v1.2 3=SeeEXT_CSD 112-119 TAAC 26h=1.5ms 27h=15ms 2Fh=20ms 27h=15ms 96-103 TRAN_SPEED 2Ah=20MHz 32h=25MHz 32h=25MHz 32h=25MHz 80-83 READ_BL_LEN 9=512 9=512 9=512 0Ah=1024 79 READ_BL_PARTIAL 0=No(?) 0=No(?) 1=Yes 0=No(?) 62-73 C_SIZE 77Fh=240MB 77Fh=240MB 3D5h=245.5MB 9AFh=1240MB 59-61 VDD_R_CURR_MIN 6=60mA 6=60mA 7=100mA 6=60mA 56-58 VDD_R_CURR_MAX 6=80mA 6=80mA 7=200mA 6=80mA 53-55 VDD_W_CURR_MIN 6=60mA 6=60mA 7=100mA 6=60mA 50-52 VDD_W_CURR_MAX 6=80mA 6=80mA 7=200mA 6=80mA 47-49 C_SIZE_MULT 6=256 6=256 7=512 7=512 42-46 ERASE_GRP_SIZE 1Fh=32x32 00h=1x32 1Fh=32x32 1Fh=32x32 32-36 WP_GRP_SIZE 09h=10 1Fh=32 00h=1 07h=8 26-28 R2W_FACTOR 05h=32x 03h=8x 02h=4x 02h=4x 14 COPY 1=Copy 1=Copy 0=Original 1=Copy |
00h CSD version No. 1.0 MMC Version 1.0 - 1.2 01h CSD version No. 1.1 MMC Version 1.4 - 2.2 02h CSD version No. 1.2 MMC Version 3.1 - 3.2 - 3.31 - 4.0 - 4.1- 4.2 03h Version is coded in the CSD_STRUCTURE byte in the EXT_CSD register |
00h CSD Version 1.0 SDSC (Standard Capacity) 01h CSD Version 2.0 SDHC/SDXC (High Capacity and Extended Capacity) 02h-03h Reserved |
00h MMC System Specification Version 1.0 - 1.2 01h MMC System Specification Version 1.4 02h MMC System Specification Version 2.0 - 2.2 03h MMC System Specification Version 3.1 - 3.2 - 3.31 04h MMC System Specification Version 4.0 - 4.1 - 4.2 05h-0Fh Reserved |
7 Reserved
6-3 Time value
0=reserved, 1=1.0, 2=1.2, 3=1.3, 4=1.5, 5=2.0, 6=2.5, 7=3.0,
8=3.5, 9=4.0, A=4.5, B=5.0, C=5.5, D=6.0, E=7.0, F=8.0
2-0 Time unit
0=1ns, 1=10ns, 2=100ns, 3=1us, 4=10us, 5=100us, 6=1ms, 7=10ms
|
7 Reserved
6-3 Time value
0=reserved, 1=1.0, 2=1.2, 3=1.3, 4=1.5, 5=2.0, 6=2.5, 7=3.0,
8=3.5, 9=4.0, A=4.5, B=5.0, C=5.5, D=6.0, E=7.0, F=8.0
2-0 Transfer rate unit
0=100kbit/s, 1=1Mbit/s, 2=10Mbit/s, 3=100Mbit/s, 4..7=reserved
MMC: same as above, but specified in <Hz> instead of <bits/s>
|
11 Supports Command Class 11 - Function Extension Commands (SD) 10 Supports Command Class 10 - Switch Function Commands (SD) 9 Supports Command Class 9 - I/O Mode Commands (SDIO/MMCIO) 8 Supports Command Class 8 - Application-Specific Commands 7 Supports Command Class 7 - Password Lock Commands 6 Supports Command Class 6 - Block-Oriented Write Protection Commands 5 Supports Command Class 5 - Erase Commands 4 Supports Command Class 4 - Block-Oriented Write Commands 3 Supports Command Class 3 - WRITE_DAT_UNTIL_STOP (MMC) 2 Supports Command Class 2 - Block-Oriented Read Commands 1 Supports Command Class 1 - READ_DAT_UNTIL_STOP (MMC) 0 Supports Command Class 0 - Basic Commands |
3-0 Setting |
00h..08h Reserved 09h Block length 512 Bytes (2^9) 0Ah Block length 1024 Bytes (2^10) 0Bh Block length 2048 Bytes (2^11) 0Ch..0Fh Reserved |
WRITE_BLK_MISALIGN=0 crossing physical block boundaries is invalid WRITE_BLK_MISALIGN=1 crossing physical block boundaries is allowed |
READ_BLK_MISALIGN=0 crossing physical block boundaries is invalid READ_BLK_MISALIGN=1 crossing physical block boundaries is allowed |
DSR_IMP=0 no DSR implemented DSR_IMP=1 DSR implemented |
memory capacity = BLOCKNR * BLOCK_LEN |
BLOCKNR = (C_SIZE+1) * MULT MULT = 2^(C_SIZE_MULT+2) ;(C_SIZE_MULT < 8) BLOCK_LEN = 2^READ_BL_LEN ;(READ_BL_LEN < 12) |
2-0 0=0.5mA, 1=1mA, 2=5mA, 3=10mA, 4=25mA, 5=35mA, 6=60mA, 7=100mA |
2-0 0=1mA, 1=5mA, 2=10mA, 3=25mA, 4=35mA, 5=45mA, 6=80mA, 7=200mA |
2-0 Device Size Factor (0..7 = Factor 4,8,16,32,64,128,256,512) |
Figure 5-1: ERASE_BLK_EN = 0 Example
Physical Block (per CSD)
0 1 2 3 4 5 6
0123456789 0123456789 0123456789 0123456789 0123456789 0123456789 0123456789
<----- Host Erase Address Range ------->
<---------- Erase Area ---------------------------------------------->
<---------- Erase Unit Size ------><------- Erase Unit Size --------->
|
Figure 5-2: ERASE_BLK_EN = 1 Example
Physical Block (per CSD)
0 1 2 3 4 5 6
0123456789 0123456789 0123456789 0123456789 0123456789 0123456789 0123456789
<----- Host Erase Address Range ------->
<----- Erase Area --------------------->
|
size of erasable unit = (ERASE_GRP_SIZE + 1) * (ERASE_GRP_MULT + 1) |
ECC ECC type Maximum number of correctable bits per block 00h None (default) Mone 01h BCH (542,512) 3 02h-03h Reserved - |
2-0 Multiples of read access time (0..5=Mul 1,2,4,8,16,32, 6..7=Reserved) |
3-0 Block Length |
00h..08h Reserved 09h 512 bytes (2^9) 0Ah 1024 Bytes (2^10) 0Bh 2048 Bytes (2^11) 0Ch..0Fh Reserved |
FILE_FORMAT_GRP FILE_FORMAT Type
0 0 Hard disk-like file system with partition table
0 1 DOS FAT (floppy-like) with boot sector only
(no partition table)
0 2 Universal File Format
0 3 Others/Unknown
1 0, 1, 2, 3 Reserved
|
| DSi SD/MMC Protocol: CSD Register (128bit Card-Specific Data) Version 2.0 |
Bit Siz Type Name Field Value 127-126 2 R CSD structure CSD_STRUCTURE 01b 125-120 6 R reserved - 000000b 119-112 8 R data read access-time-1 (TAAC) 0Eh 111-104 8 R data read access-time-2 (NSAC) 00h 103-96 8 R max data transfer rate (TRAN_SPEED) 32h,5Ah,0Bh,2Bh 95-84 12 R card command classes CCC x1x110110101b 83-80 4 R max read data block length (READ_BL_LEN) 9 79 1 R partial blocks for read allowed (READ_BL_PARTIAL) 0 78 1 R write block misalignment (WRITE_BLK_MISALIGN) 0 77 1 R read block misalignment (READ_BLK_MISALIGN) 0 76 1 R DSR implemented DSR_IMP x 75-70 6 R reserved - 000000b 69-48 22 R device size C_SIZE xxxxxxh 47 1 R reserved - 0 46 1 R erase single block enable (ERASE_BLK_EN) 1 45-39 7 R erase sector size (SECTOR_SIZE) 7Fh 38-32 7 R write protect group size (WP_GRP_SIZE) 00h 31 1 R write protect group enable (WP_GRP_ENABLE) 0 30-29 2 R reserved - 00b 28-26 3 R write speed factor (R2W_FACTOR) 010b 25-22 4 R max write data block length (WRITE_BL_LEN) 9 21 1 R partial blocks for write allowed (WRITE_BL_PARTIAL) 0 20-16 5 R reserved - 00000b 15 1 R File format group (FILE_FORMAT_GRP) 0 14 1 R/W(1) copy flag COPY x 13 1 R/W(1) permanent write protection PERM_WRITE_PROTECT x 12 1 R/W temporary write protection TMP_WRITE_PROTECT x 11-10 2 R File format (FILE_FORMAT) 00b 9-8 2 R reserved - 00b 7-1 7 R/W CRC CRC xxh 0 1 - not used, always '1' - 1 |
memory capacity = (C_SIZE+1) * 512KByte |
32h SDSC/SDHC/SDXC in Default Speed mode (25MHz) 5Ah SDSC/SDHC/SDXC in High Speed mode (50MHz) 0Bh SDHC/SDXC in SDR50 or DDR50 mode (100Mbit/sec) 2Bh SDHC/SDXC in SDR104 mode (200Mbit/sec) |
| DSi SD/MMC Protocol: EXT_CSD Register (4096bit Extended CSD Register) (MMC) |
31-0 stuff bits |
4095-0 EXT_CSD Register (4096bit) |
31-26 6bit Reserved (0)
25-24 2bit Access
00h Change Command Set (EXT_CSD[191] = parameter bit2-0)
01h Set bits (EXT_CSD[index] = EXT_CSD[index] OR value)
02h Clr bits (EXT_CSD[index] = EXT_CSD[index] AND NOT value)
03h Write (EXT_CSD[index] = value)
23-16 8bit Index (0..191) ;\used only if "Access=1..3"
15-8 8bit Value (0..255) ;/
7-3 5bit Reserved (0)
2-0 3bit Cmd Set (0..7) ;-used only if "Access=0"
|
Properties Segment Byte Siz Type Name Field 511-505 7 - Reserved(1) - 504 1 R Supported Command Sets S_CMD_SET 503-216 288 - Reserved(1) - 215-212 4 R moviNAND only: Sector Count SEC_COUNT 211 1 - Reserved - 210 1 R Min Write Performance for 8bit @52MHz MIN_PERF_W_8_52 209 1 R Min Read Performance for 8bit @52MHz MIN_PERF_R_8_52 208 1 R Min Write Perf. for 8/4bit @26/52MHz MIN_PERF_W_8_26_4_52 207 1 R Min Read Perf. for 8/4bit @26/52MHz MIN_PERF_R_8_26_4_52 206 1 R Min Write Performance for 4bit @26MHz MIN_PERF_W_4_26 205 1 R Min Read Performance for 4bit @26MHz MIN_PERF_R_4_26 204 1 - Reserved(1) - 203 1 R Power Class for 26MHz @ 3.6V PWR_CL_26_360 202 1 R Power Class for 52MHz @ 3.6V PWR_CL_52_360 201 1 R Power Class for 26MHz @ 1.95V PWR_CL_26_195 200 1 R Power Class for 52MHz @ 1.95V PWR_CL_52_195 199-197 3 - Reserved(1) - 196 1 R Card Type CARD_TYPE 195 1 - Reserved(1) - 194 1 R CSD Structure Version CSD_STRUCTURE 193 1 - Reserved(1) - 192 C0h 1 R Extended CSD Revision EXT_CSD_REV Modes Segment 191 BFh 1 R/W Command Set CMD_SET 190 BEh 1 - Reserved(1) - 189 BDh 1 RO Command Set Revision CMD_SET_REV 188 BCh 1 - Reserved(1) - 187 BBh 1 R/W Power Class POWER_CLASS 186 BAh 1 - Reserved(1) - 185 B9h 1 R/W High Speed Interface Timing HS_TIMING 184 B8h 1 - Reserved(1) - 183 B7h 1 WO Bus Width Mode BUS_WIDTH 182 B6h ? ? 181 B5h 1 - Reserved - 180 B4h 1 RO moviNAND only: Erased Memory Content ERASED_MEM_CONT 180-0 181 - Reserved(a) - |
Bit Command Set 7-5 Reserved 4 moviNAND only: ATA on MMC 3 moviNAND only: SecureMCC 2.0 2 Content Protection SecureMMC 1 SecureMMC 0 Standard MMC |
Value Performance
0x00 For Cards not reaching the 2.4MB/s minimum value
0x08 Class A: 2.4MB/s and is the lowest allowed value for MMCplus and
MMCmobile(16x150kB/s)
0x0A Class B: 3.0MB/s and is the next allowed value (20x150kB/s)
0x0F Class C: 4.5MB/s and is the next allowed value (30x150kB/s)
0x14 Class D: 6.0MB/s and is the next allowed value (40x150kB/s)
0x1E Class E: 9.0MB/s and is the next allowed value (60x150kB/s)
This is also the highest class which any MMCplus or MMCmobile card
is needed to support in low bus category operation mode (26MHz with
4bit data bus).
A MMCplus or MMCmobile card supporting any higher class than this
have to support this class also (in low category bus operation mode).
0x28 Class F: Equals 12.0MB/s and is the next allowed value (80x150kB/s)
0x32 Class G: Equals 15.0MB/s and is the next allowed value (100x150kB/s)
0x3C Class H: Equals 18.0MB/s and is the next allowed value (120x150kB/s)
0x46 Class J: Equals 21.0MB/s and is the next allowed value (140x150kB/s)
This is also the highest class which any MMCplus or MMCmobile card
is needed to support in mid bus category operation mode (26MHz with
8bit data bus or 52MHz with 4bit data bus).
A MMCplus or MMCmobile card supporting any higher class than this
have to support this Class (in mid category bus operation mode) and
Class E also (in low category bus operation mode).
0x50 Class K: Equals 24.0MB/s and is the next allowed value (160x150kB/s)
0x64 Class M: Equals 30.0MB/s and is the next allowed value (200x150kB/s)
0x78 Class O: Equals 36.0MB/s and is the next allowed value (240x150kB/s)
0x8C Class R: Equals 42.0MB/s and is the next allowed value (280x150kB/s)
0xA0 Class T: Equals 48.0MB/s and is the last defined value (320x150kB/s)
|
Voltage Value Max RMS Current Max Peak Current Remarks
3.6V 0 100 mA 200 mA Default current
1 120 mA 220 mA consumption for
2 150 mA 250 mA high voltage cards
3 180 mA 280 mA
4 200 mA 300 mA
5 220 mA 320 mA
6 250 mA 350 mA
7 300 mA 400 mA
8 350 mA 450 mA
9 400 mA 500 mA
10 450 mA 550 mA
11-15 Reserved for future use
1.95V 0 65 mA 130 mA Default current
1 70 mA 140 mA consumption for
2 80 mA 160 mA Dual voltage cards
3 90 mA 180 mA (if any, not moviNAND)
4 100 mA 200 mA
5 120 mA 220 mA
6 140 mA 240 mA
7 160 mA 260 mA
8 180 mA 280 mA
9 200 mA 300 mA
10 250 mA 350 mA
6-15 Reserved for future use
|
- Maximum bus frequency - Maximum operating voltage - Worst case functional operation - Worst case environmental parameters (temperature,...) |
Bit Card Type 7-2 Reserved 1 High Speed MultiMediaCard @ 52MHz 0 High Speed MultiMediaCard @ 26MHz |
CSD_STRUCTURE CSD structure version Valid for System Specification Version 0 CSD version No. 1.0 Version 1.0 - 1.2 1 CSD version No. 1.1 Version 1.4 - 2.2 2 CSD version No. 1.2 Version 3.1-3.2-3.31-4.0-4.1-4.2 3 Reserved for future use 4-255 Reserved for future use |
EXT_CSD_REV Extended CSD Revision 0 Revision 1.0 1 Revision 1.1 2 Revision 1.2 (moviNAND) 3-255 Reserved |
Code MMC Revisions 0 v4.0 1-255 Reserved |
Bits Description 7-4 Reserved 3-0 Card power class code (See Table 5-29) |
Value Bus Mode 0 1 bit data bus (MMC, with old 7pin connector) 1 4 bit data bus (MMCplus, with SD-card-compatible 9pin connector) 2 8 bit data bus (MMCplus, with special 13pin connector) 3-255 Reserved |
Value Erased Memory content 00h Erased memory range shall be '0' 01h Erased memory range shall be '1' 02h-FFh Reserved |
| DSi SD/MMC Protocol: RCA Register (16bit Relative Card Address) |
31-0 stuff bits |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Command (the 6bit CMD being responded to) ;/ 39-24 New published RCA of the card ;-16bit ;-2nd..3th byte 23-22 CSR Card Status, bit 23-22 ;\ ;\ 21 CSR Card Status, bit 19 ; 16bit ; 4nd..5th byte 20-8 CSR Card Status, bit 12-0 ;/ ;/ 7-1 CRC7 ;\6th byte 0 End Bit (1) ;/ |
31-16 RCA 15-0 stuff bits |
31-16 RCA 15-0 stuff bits |
31-16 RCA 15 Sleep/Awake flag (0=Awake/stby, 1=Sleep/slp) 14-0 stuff bits |
CMD0 sd/mmc spi GO_IDLE_STATE (type=bc) CMD2 sd/mmc ALL_GET_CID (type=bcr) CMD3 sd GET_RELATIVE_ADDR (type=bcr) CMD4 sd/mmc SET_DSR (type=bc) CMD7 sd/mmc SELECT_DESELECT_CARD (type=ac) ;actually: (type=bcr) CMD8 sd spi SET_IF_COND (type=bcr) ACMD41 sd spi SD_SEND_OP_COND (type=bcr) ;SPI: reduced functionality |
| DSi SD/MMC Protocol: DSR Register (16bit Driver Stage Register) (Optional) |
31-16 DSR 15-0 stuff bits |
| DSi SD/MMC Protocol: SCR Register (64bit SD Card Configuration Register) |
31-0 stuff bits |
63-0 SCR Register (8bytes, aka 64bit) |
Bit Siz Typ Description Field ;common 63-60 4 R SCR Structure SCR_STRUCTURE ;\00h or 59-56 4 R SD Memory Card - Spec. Version SD_SPEC ;/01h 55 1 R data_status_after erases DATA_STAT_AFTER_ERASE ;\ 54-52 3 R CPRM Security Support SD_SECURITY ; A5h 51-48 4 R DAT Bus widths supported SD_BUS_WIDTHS ;/ 47 1 R Spec. Version 3.00 or higher SD_SPEC3 ;\ 46-43 4 R Extended Security Support EX_SECURITY ; 0000h 42 1 R Spec. Version 4.00 or higher SD_SPEC4 ; 41-36 6 R Reserved - ; 35-32 4 R Command Support bits CMD_SUPPORT ;/ 31-0 32 R reserved for manufacturer usage - ;-var |
SCR_STRUCTURE SCR Structure Version SD Physical Layer Specification Version 00h SCR version 1.0 Version 1.01-4.00 01h..0Fh reserved |
SD_SPEC SD_SPEC3 SD_SPEC4 Physical Layer Specification Version Number
0 0 0 Version 1.0 and 1.01
1 0 0 Version 1.10
2 0 0 Version 2.00
2 1 0 Version 3.0X
2 1 1 Version 4.XX
Others Reserved
|
(1) The card does not support CMD6 (2) The card does not support CMD8 (3) User area capacity shall be up to 2GB |
(1) The card shall support CMD6 (2) The card does not support CMD8 (3) User area capacity shall be up to 2GB |
(1) The card shall support CMD6 (2) The card shall support CMD8 (3) The card shall support CMD42 (4) User area capacity shall be up to 2GB (SDSC) or 32GB (SDHC) (5) Speed Class shall be supported (SDHC) |
(1) The card shall support CMD6
(2) The card shall support CMD8
(3) The card shall support CMD42
(4) User area capacity shall be up to 2GB (SDSC) or 32GB (SDHC)
User area capacity shall be more than or equal to 32GB and up to 2TB (SDXC)
(5) Speed Class shall be supported (SDHC or SDXC)
|
A card supports any of following functions shall satisfy essential conditions of Version 3.00 Card (1) Speed Class supported under the conditions defined in Version 3.00 (2) UHS-I supported card (3) CMD23 supported card |
(1) Same as the essential conditions of Version 3.00 device
(2) Support any of additional functions defined by Version 4.XX:
Followings functions (a) to (c) are defined by Version 4.00.
(a) Support of CMD48 and CMD49
(b) Support of UHS-II mode
(c) Support of DPS (Data Protection System)
Followings functions (d) to (f) are defined by Version 4.10.
(d) Support of CMD58 and CMD59
(e) Support of Power Management Functions
(f) Support of Speed Grade 1 for UHS-II mode
|
00h No Security 01h Not Used 02h SDSC Card (CPRM Security Version 1.01) 03h SDHC Card (CPRM Security Version 2.00) 04h SDXC Card (CPRM Security Version 3.xx) 05h-07h Reserved |
SDSC Card sets this field to 2 (Version 1.01). SDHC Card sets this field to 3 (Version 2.00). SDXC Card sets this field to 4 (Version 3.xx). |
Bit 3 Reserved Bit 2 4 bit (DAT0-3) Bit 1 Reserved Bit 0 1 bit (DAT0) |
00h Extended Security is not supported.
01h..0Fh Extended Security is supported. SCR[44-43] is defined by the
Part A4 Data Protection System Specification. SCR[46-45] is
reserved for future extension.
|
Bit Supported Command Command CCC Remark 35 Extension Register Multi-Block CMD58/59 11 Optional. 34 Extension Register Single Block CMD48/49 11 Optional. 33 Set Block Count CMD23 2,4 Mandatory for UHS104 card 32 Speed Class Control CMD20 2,4 Mandatory for SDXC card |
| DSi SD/MMC Protocol: PWD Register (128bit Password plus 8bit Password len) |
Defined by DPS Spec. |
unknown |
31-0 Reserved bits (0) |
Note: Before using this command, the size of the following data block (ie.
"1st..Nth/Extra" byte) must be set via SET_BLOCKLEN command (CMD16).
1st byte: Flags
Bit7-4 Reserved (0)
Bit3 ERASE Force Erase (1=Erase WHOLE CARD and clear password)
Bit1 LOCK_UNLOCK Lock card (0=Unlock, 1=Lock) (default on power up: Lock)
Bit1 CLR_PWD Clears password (0=no, 1=yes)
Bit0 SET_PWD Set new password (0=no, 1=yes)
2nd byte: PWDS_LEN Length of the Password(s) in bytes ("3rd..Nth" byte)
3rd..Nth byte: Password (old password, if SET_PWD: followed by new password)
Extra byte: Alignment padding (only in DDR50 mode, if above is odd num bytes)
|
| DSi SD/MMC Protocol: State |
Command old state --> idle readyidentstby tran data rcv prg dis ina
DONE Operation Complete ---- ---- ---- ---- ---- tran ---- tran stby ----
class 0
CMD0 GO_IDLE_STATE ok idle idle idle idle idle idle idle idle ----
CMD2 ALL_SEND_CID ---- ident---- ---- ---- ---- ---- ---- ---- ----
CMD3 SEND_RELATIVE_ADDR ---- ---- stby ok ---- ---- ---- ---- ---- ----
CMD4 SET_DSR ---- ---- ---- ok ---- ---- ---- ---- ---- ----
CMD7 SELECT_DESELECT_CARD
card is addressed ---- ---- ---- tran ---- ---- ---- ---- prg ----
card is not addr. ---- ---- ---- ok stby stby ---- dis ---- ----
CMD8 SEND_IF_COND ok ---- ---- ---- ---- ---- ---- ---- ---- ----
CMD9 SEND_CSD ---- ---- ---- ok ---- ---- ---- ---- ---- ----
CMD10 SEND_CID ---- ---- ---- ok ---- ---- ---- ---- ---- ----
CMD11 VOLTAGE_SWITCH ---- ok ---- ---- ---- ---- ---- ---- ---- ----
CMD12 STOP_TRANSMISSION ---- ---- ---- ---- ---- tran prg ---- ---- ----
CMD13 SEND_STATUS ---- ---- ---- ok ok ok ok ok ok ----
CMD15 GO_INACTIVE_STATE ---- ---- ---- ina ina ina ina ina ina ----
class 2
CMD16 SET_BLOCKLEN ---- ---- ---- ---- ok ---- ---- ---- ---- ----
CMD17 READ_SINGLE_BLOCK ---- ---- ---- ---- data ---- ---- ---- ---- ----
CMD18 READ_MULTIPLE_BLOCK ---- ---- ---- ---- data ---- ---- ---- ---- ----
CMD19 SEND_TUNING_BLOCK ---- ---- ---- ---- data ---- ---- ---- ---- ----
CMD20 SPEED_CLASS_CONTROL ---- ---- ---- ---- prg ---- ---- ---- ---- ----
CMD23 ---- ---- ---- ---- ok ---- ---- ---- ---- ----
class 4
CMD16 SET_BLOCKLEN (2)---- ---- ---- ---- ok ---- ---- ---- ---- ----
CMD20 SPEED_CLASS_CONTROL(2)---- ---- ---- ---- prg ---- ---- ---- ---- ----
CMD23 SET_BLOCK_COUNT ---- ---- ---- ---- ok ---- ---- ---- ---- ----
CMD24 WRITE_BLOCK ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
CMD25 WRITE_MULTIPLE_BLOCK ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
CMD27 PROGRAM_CSD ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
class 6
CMD28 SET_WRITE_PROT ---- ---- ---- ---- prg ---- ---- ---- ---- ----
CMD29 CLR_WRITE_PROT ---- ---- ---- ---- prg ---- ---- ---- ---- ----
CMD30 SEND_WRITE_PROT ---- ---- ---- ---- data ---- ---- ---- ---- ----
class 5
CMD32 ERASE_WR_BLK_START ---- ---- ---- ---- ok ---- ---- ---- ---- ----
CMD33 ERASE_WR_BLK_END ---- ---- ---- ---- ok ---- ---- ---- ---- ----
CMD38 ERASE ---- ---- ---- ---- prg ---- ---- ---- ---- ----
class 7
CMD40 Read Block (DPS Spec) ---- ---- ---- ---- data ---- ---- ---- ---- ----
CMD42 LOCK_UNLOCK ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
class 8
CMD55 APP_CMD ok ---- ---- ok ok ok ok ok ok ----
CMD56 GEN_CMD, RD/WR=0 ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
GEN_CMD, RD/WR=1 ---- ---- ---- ---- data ---- ---- ---- ---- ----
ACMD6 SET_BUS_WIDTH ---- ---- ---- ---- ok ---- ---- ---- ---- ----
ACMD13 SD_STATUS ---- ---- ---- ---- data ---- ---- ---- ---- ----
ACMD22 SEND_NUM_WR_BLOCKS ---- ---- ---- ---- data ---- ---- ---- ---- ----
ACMD23 SET_WR_BLK_ERASE_CO. ---- ---- ---- ---- ok ---- ---- ---- ---- ----
ACMD41 SD_SEND_OP_COND
OCR check is OK
and card is not busy ready---- ---- ---- ---- ---- ---- ---- ---- ----
OCR check is OK
and card is busy(2) ok ---- ---- ---- ---- ---- ---- ---- ---- ----
OCR check fails
query mode ina ---- ---- ---- ---- ---- ---- ---- ---- ----
ACMD42 SET_CLR_CARD_DETECT ---- ---- ---- ---- ok ---- ---- ---- ---- ----
ACMD51 SEND_SCR ---- ---- ---- ---- data ---- ---- ---- ---- ----
class 9
class 10 (1)
CMD6 SWITCH_FUNC ---- ---- ---- ---- data ---- ---- ---- ---- ----
class 11
CMD48 READ_EXTR_SINGLE ---- ---- ---- ---- data ---- ---- ---- ---- ----
CMD49 WRITE_EXTR_SINGLE ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
CMD58 READ_EXTR_MULTI ---- ---- ---- ---- data ---- ---- ---- ---- ----
CMD59 WRITE_EXTR_MULTI ---- ---- ---- ---- rcv ---- ---- ---- ---- ----
ACMD14-16 Refer to DPS Specification (class 8)
ACMD28 Refer to DPS Specification (class 8)
ACMD18,25,26,38,
43,44,45,46,47,48,49 Refer to the "Part3 Security Specification" for
information about the SD Security Features (class 8)
CMD52-CMD54 Refer to the "SDIO Card Specification" (class 9)
CMD21 Refer to DPS Specification (class 11)
CMD34-37,50,57 Refer to each command system specification (class 10)
CMD41,CMD43-47 reserved (class 11)
CMD60...CMD63 reserved for manufacturer (class 11)
SPI Mode
CMD1 SEND_OP_COND SPI-only
CMD58 READ_OCR SPI-only
CMD59 CRC_ON_OFF SPI-only
|
- Card executes internal initialization process - When HCS in the argument is set to 0 to SDHC or SDXC Card. |
---- command is treated as illegal command ok command is accepted, and card stays in SAME state xxx command is accepted, and card switches to "xxx" state |
Command old state --> idl rdy idt stb trn dta tst rcv prg dis ina slp irq
Class Independent
ERR CRC error --- --- --- --- --- --- --- --- --- --- --- --- stb
ERR command not supported--- --- --- --- --- --- --- --- --- --- --- --- stb
Class 0
CMD0 (arg=00000000h) ok idl idl idl idl idl idl idl idl idl --- idl stb
GO_IDLE_STATE
CMD0 (arg=F0F0F0F0h) pre pre pre pre pre pre pre pre pre pre --- pre stb
GO_PRE_IDLE_STATE
CMD0 (arg=FFFFFFFAh) initiate alternative boot operation
BOOT_INITIATION
CMD1 SEND_OP_COND
card VDD range ok rdy --- --- --- --- --- --- --- --- --- --- --- stb
card is busy ok --- --- --- --- --- --- --- --- --- --- --- stb
card VDD range bad ina --- --- --- --- --- --- --- --- --- --- --- stb
CMD2 ALL_SEND_CID
card wins bus --- idt --- --- --- --- --- --- --- --- --- --- stb
card loses bus --- ok --- --- --- --- --- --- --- --- --- --- stb
CMD3 SET_RELATIVE_ADDR --- --- stb --- --- --- --- --- --- --- --- --- stb
CMD4 SET_DSR --- --- --- ok --- --- --- --- --- --- --- --- stb
CMD5 SLEEP_AWAKE --- --- --- slp -?- -?- -?- -?- -?- -?- -?- stb stb
CMD6 SWITCH --- --- --- --- prg --- --- --- --- --- --- --- stb
CMD7 SELECT_DESELECT_CARD
card is addressed --- --- --- trn --- --- --- --- --- prg --- --- stb
card is not addr. --- --- --- --- stb stb --- --- dis --- --- --- stb
CMD8 SEND_EXT_CSD --- --- --- --- dta --- --- --- --- --- --- --- stb
CMD9 SEND_CSD --- --- --- ok --- --- --- --- --- --- --- --- stb
CMD10 SEND_CID --- --- --- ok --- --- --- --- --- --- --- --- stb
CMD12 STOP_TRANSMISSION --- --- --- --- --- trn --- prg --- --- --- --- stb
CMD13 SEND_STATUS --- --- --- ok ok ok ok ok ok ok --- --- stb
CMD14 BUSTEST_R --- --- --- --- --- --- trn --- --- --- --- --- stb
CMD15 GO_INACTIVE_STATE --- --- --- ina ina ina ina ina ina ina --- --- stb
CMD19 BUSTEST_W --- --- --- --- tst --- --- --- --- --- --- --- stb
Class 1
CMD11 READ_DAT_UNTIL_STOP --- --- --- --- dta --- --- --- --- --- --- --- stb
Class 2
CMD16 SET_BLOCKLEN --- --- --- --- ok --- --- --- --- --- --- --- stb
CMD17 READ_SINGLE_BLOCK --- --- --- --- dta --- --- --- --- --- --- --- stb
CMD18 READ_MULTIPLE_BLOCK --- --- --- --- dta --- --- --- --- --- --- --- stb
CMD23 SET_BLOCK_COUNT --- --- --- --- ok --- --- --- --- --- --- --- stb
Class 3
CMD20 WRITE_DAT_UNTIL_STOP--- --- --- --- rcv --- --- --- --- --- --- --- stb
Class 4
CMD16 SET_BLOCKLEN see class 2
CMD23 SET_BLOCK_COUNT see class 2
CMD24 WRITE_BLOCK --- --- --- --- rcv --- --- --- rcv1--- --- --- stb
CMD25 WRITE_MULTIPLE_BL. --- --- --- --- rcv --- --- --- rcv2--- --- --- stb
CMD26 PROGRAM_CID --- --- --- --- rcv --- --- --- --- --- --- --- stb
CMD27 PROGRAM_CSD --- --- --- --- rcv --- --- --- --- --- --- --- stb
Class 6
CMD28 SET_WRITE_PROT --- --- --- --- prg --- --- --- --- --- --- --- stb
CMD29 CLR_WRITE_PROT --- --- --- --- prg --- --- --- --- --- --- --- stb
CMD30 SEND_WRITE_PROT --- --- --- --- dta --- --- --- --- --- --- --- stb
CMD31 SEND_WRITE_PROT_TYPE--- --- --- --- dta --- --- --- --- --- --- --- stb
Class 5
CMD35 ERASE_GROUP_START --- --- --- --- ok --- --- --- --- --- --- --- stb
CMD36 ERASE_GROUP_END --- --- --- --- ok --- --- --- --- --- --- --- stb
CMD38 ERASE --- --- --- --- prg --- --- --- --- --- --- --- stb
Class 7
CMD16 SET_BLOCKLEN see class 2
CMD42 LOCK_UNLOCK --- --- --- --- rcv --- --- --- --- --- --- --- stb
Class 8
CMD55 APP_CMD --- --- --- ok ok ok ok ok ok ok --- --- ok
CMD56 GEN_CMD, RD/WR=0 --- --- --- --- rcv --- --- --- --- --- --- --- stb
GEN_CMD, RD/WR=1 --- --- --- --- dta --- --- --- --- --- --- --- stb
Class 9
CMD39 FAST_IO --- --- --- ok --- --- --- --- --- --- --- --- stb
CMD40 GO_IRQ_STATE --- --- --- irq --- --- --- --- --- --- --- --- stb
Class 10-11
CMD41, CMD43..CMD54 Reserved
CMD57..CMD59 Reserved
CMD60..CMD63 Reserved for Manufacturer
SPI Mode
CMD58 READ_OCR SPI-only
CMD59 CRC_ON_OFF SPI-only
|
pre Pre-idle idl idle rdy ready idt ident stb stby trn tran dta data tst btst |
| DSi SD/MMC Protocol: Signals |
__ start bit __ checksum bits (CRC-CCITT)
| |
| <------------data bits-------------> | __ stop bit
| | |
DAT0 0 1st 2nd 3rd 4th 5th 6th 7th ... last crc 1
|
__ start bit __ checksum bits (CRC-CCITT)
| |
| <--data bits--> | __ stop bit
| | |
DAT3 0 1st 5th ... ... crc 1
DAT2 0 2nd 6th ... ... crc 1
DAT1 0 3rd 7th ... ... crc 1
DAT0 0 4th 8th ... last crc 1
|
| DSi SDIO Special SDIO Commands |
31 R/W Flag (0=Read, 1=Write) 30-28 Function Number (3bit) 27 Read-after-write (RAW) Flag (if Bit31=1=Write, and Bit27=1) 26 Stuff (unspecified, should be probably 0, but is 1 on DSi) 25-9 Register Address (17bit) 8 Stuff (unspecified, should be probably 0, but is 1 on DSi) 7-0 Write Data (8bit), or Stuff bits (for read) |
47 Start Bit (0) ;\
46 Transmission To Host (0) ; 1st byte
45-40 Command (the 6bit CMD being responded to) ;/
39-24 Stuff Bits ;-2nd..3rd byte
23-16 Response Flags ;-4th byte
7 COM_CRC_ERROR
6 ILLEGAL_COMMAND
5-4 IO_CURRENT STATE (0=dis, 1=cmd, 2=trn(cmd53), 3=rfu)
3 ERROR
2 RFU (reserved for future use)
1 INVALID_FUNCTION_NUMBER
0 OUT_OF_RANGE
15-8 Read or Write Data (8bit) ;-5th byte
7-1 CRC7 ;\6th byte
0 End Bit (1) ;/
|
8bit modified R1 response
7 start bit (0)
6 parameter error (0=okay, 1=error)
5 RFU (0)
4 function number error (0=okay, 1=error)
3 COM CRC error (0=okay, 1=error)
2 illegal command (0=okay, 1=error)
1 RFU (0)
0 in idle state (0=no, 1=idle)
8bit Read or Write Data
|
31 R/W Flag (0=Read, 1=Write) 30-28 Function Number (3bit) (0=CIA) 27 Block Mode (0=Bytes, 1=Blocks/optional) 26 OP Code (0=Fixed Address, 1=Incrementing Address) 25-9 Register Address (17bit) 8-0 Byte/Block Count (9bit) (1..511) (0=512 Bytes, or 0=Infinite Blocks) |
For Byte Mode: Similar to CMD17/CMD24 (single block) For Block Mode: Similar to CMD18/CMD25 (multiple block) For Block Mode: CMD52:STOP_TRANSMISSION only needed if using "InfiniteBlocks" |
31-25 stuff bits (0) 24 Switching to 1.8V Request (S18R) 23 I/O OCR VDD Voltage Window 3.5V-3.6V 22 I/O OCR VDD Voltage Window 3.4V-3.5V 21 I/O OCR VDD Voltage Window 3.3V-3.4V 20 I/O OCR VDD Voltage Window 3.2V-3.3V 19 I/O OCR VDD Voltage Window 3.1V-3.2V 18 I/O OCR VDD Voltage Window 3.0V-3.1V 17 I/O OCR VDD Voltage Window 2.9V-3.0V 16 I/O OCR VDD Voltage Window 2.8V-2.9V 15 I/O OCR VDD Voltage Window 2.7V-2.8V 14 I/O OCR VDD Voltage Window 2.6V-2.7V 13 I/O OCR VDD Voltage Window 2.5V-2.6V 12 I/O OCR VDD Voltage Window 2.4V-2.5V 11 I/O OCR VDD Voltage Window 2.3V-2.4V 10 I/O OCR VDD Voltage Window 2.2V-2.3V 9 I/O OCR VDD Voltage Window 2.1V-2.2V 8 I/O OCR VDD Voltage Window 2.0V-2.1V 7-4 I/O OCR VDD Voltage Window Reserved 3-0 I/O OCR VDD Voltage Window Reserved |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Reserved (111111) (instead of Command value) ;/ 39 Card is ready to operate after init ;\ 38-36 Number of I/O Functions ; 35 Memory Present ; 2nd byte 34-33 Stuff bits (0) ; 32 Switching to 1.8V Accepted (S18R) (not SPI) ;/ 31-8 I/O OCR (24bit) ;-3rd..5th byte 7-1 Reserved (111111) (instead of CRC7) ;\6th byte 0 End Bit (1) ;/ |
8bit modified R1 Response
7 start bit (0)
6 parameter error (0=okay, 1=error)
5 RFU (0)
4 function number error (0=okay, 1=error)
3 COM CRC error (0=okay, 1=error)
2 illegal command (0=okay, 1=error)
1 RFU (0)
0 in idle state (0=no, 1=idle)
32bit same as SD Response bit39-8 (but without S18R bit)
|
- SCFG_EXT7.bit19 needed for SDIO controller (else 4004Axxh-4004Bxxh disabled) - SCFG_CLK7 seems to be NOT needed for SDIO clock enable (unlike SDMMC) - SCFG_WL.bit0 seems to be wifi-related (but effect is unknown) - GPIO_WIFI.bit8 needed for AR6013G chips (else SDIO Function 1 fails) - BPTWL[30h] needed for LED and SDIO (else SDIO fails badly) - RTC.FOUT pin as configured by firmware (else WMI commands/events fail) |
Command ini stb cmd trn ina
CMD3 SET_RELATIVE_ADDR stb ok --- --- ---
CMD5 IO_SEND_OP_COND ok --- --- --- ---
ocr bad ina --- --- --- ---
CMD7 SELECT_CARD --- cmd ok --- ---
DESELECT_CARD --- ok stb --- ---
CMD15 GO_INACTIVE_STATE ina ina ina --- ---
CMD52 IO_RW_DIRECT --- --- ok (cmd)---
CMD53 IO_RW_EXTENDED --- --- trn --- ---
|
CMD0 GO_IDLE_STATE for entering SPI mode only (but does NOT reset SDIO) CMD8 SEND_IF_COND optional for SDHC/SDXC CMD11 VOLTAGE_SWITCH optional for UHS-I CMD19 SEND_TUNING_BLOCK optional for UHS-I CMD59 CRC_ON_OFF spi-only |
____________________________ I/O Commands for MMC____________________________ |
31-16 RCA 15 Register Write Flag 14-8 Register Address 7-0 Register Data |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Command (the 6bit CMD being responded to) ;/ 39-24 RCA ;-2nd..3rd byte 23 Status (0=Bad, 1=Successful) ;\4th byte 22-16 Register Address ;/ 15-8 Read Register Contents ;-5th byte 7-1 CRC7 ;\6th byte 0 End Bit (1) ;/ |
31-0 Stuff Bits |
47 Start Bit (0) ;\ 46 Transmission To Host (0) ; 1st byte 45-40 Command (the 6bit CMD being responded to) ;/ 39-24 RCA ;-2nd..3rd byte 23-8 Not defined (may be used for IRQ data) ;-4th..5th byte 7-1 CRC7 ;\6th byte 0 End Bit (1) ;/ |
| DSi SDIO Memory and I/O Maps |
0:00000h..000FFh Card Common Control Registers (CCCR) 0:00100h..001FFh Function Basic Registers (FBR) for Function 1 0:00200h..002FFh Function Basic Registers (FBR) for Function 2 0:00300h..003FFh Function Basic Registers (FBR) for Function 3 0:00400h..004FFh Function Basic Registers (FBR) for Function 4 0:00500h..005FFh Function Basic Registers (FBR) for Function 5 0:00600h..006FFh Function Basic Registers (FBR) for Function 6 0:00700h..007FFh Function Basic Registers (FBR) for Function 7 0:00800h..00FFFh Reserved for Future 0:01000h..17FFFh Card Information Structures (Common CIS and Func 1-7 CIS) 0:18000h..1FFFFh Reserved for Future |
n:00000h..1FFFFh Registers (seven 128K spaces, one for each function) |
CSA:00000h..FFFFFh 16Mbyte FAT12/FAT16 (accessed indirectly via "Window") |
0:00000h 2 CCCR: Revision (R) 0:00002h 2 CCCR: I/O Function Enable/Ready (R/W) 0:00004h 2 CCCR: Interrupt Enable/Pending (R/W) 0:00006h 1 CCCR: I/O Abort (W) 0:00007h 1 CCCR: Bus Interface Control (R/W) 0:00008h 1 CCCR: Card Capability 0:00009h 3 CCCR: Common CIS Pointer, Lo/Mid/Hi 0:0000Ch 1 CCCR: Bus Suspend 0:0000Dh 1 CCCR: Function Select (R/W) 0:0000Eh 2 CCCR: Exec/Ready Flags (R) 0:00010h 2 CCCR: CMD53 Block Size for Function 0, Lo/Hi (R/W) 0:00012h 1 CCCR: Power Control 0:00013h 2 CCCR: Bus Speed Select 0:00015h 1 CCCR: Driver Strength 0:00016h 1 CCCR: Interrupt Extension 0:00017h D9h CCCR: Reserved for Future 0:000F0h 10h CCCR: Reserved for Vendors |
0:00n00h 1 FBR(n): Misc 0:00n01h 1 FBR(n): Extended standard SDIO Function interface code 0:00n02h 1 FBR(n): Misc 0:00n02h 7 FBR(n): Reserved for Future 0:00n09h 3 FBR(n): Pointer to Card Information Structure (CIS), Lo/Mid/Hi 0:00n0Ch 3 FBR(n): Code Storage Area (CSA) Address, Lo/Mid/Hi 0:00n0Fh 1 FBR(n): Code Storage Area (CSA) Data "Window" 0:00n10h 2 FBR(n): CMD53 Block Size for Function n, Lo/Hi 0:00n12h EEh FBR(n): Reserved for Future |
| DSi SDIO Common Control Registers (CCCR) |
0-3 CCCR/FBR Format Version (0=v1.00, 1=v1.10, 2=v2.00, 3=v3.00) (R) 4-7 SDIO Spec Version (0=v1.00, 1=v1.10, 2=v1.20, 3=v2.00, 4=v3.00) (R) 8-11 SD Physical Layer Spec (0=v1.01, 1=v1.10, 2=v2.00, 3=v3.0x) (R) 12-15 Reserved for Future (-) |
0 Reserved for Future (-) 1-7 SDIO Function 1..7 Enable Flags (0=Disable, 1=Enable) (R/W) 8 Reserved for Future (-) 9-15 SDIO Function 1..7 Ready Flags (0=Disabled/Busy, 1=Ready) (R) |
0 SDIO Interrupt Master Enable (0=Disable, 1=Enable) (R/W) 1-7 SDIO Function 1..7 Interrupt Enable (0=Disable, 1=Enable) (R/W) 8 Reserved for Future (-) 9-15 SDIO Function 1..7 Interrupt Pending (0=No, 1=IRQ) (R) |
0-2 SDIO Function Number to be Aborted (0=None?, 1..7=Function 1..7) (W)
XXXsee pg 35
3 Reset SDIO Card (0=Normal, 1=Reset) (W)
4-7 Reserved for Future (-)
|
0-1 Bus Width (0=1bit, 1=Reserved, 2=4bit, 3=EmbeddedSDIO/8bit) (R/W) 2 Support 8bit Bus Flag (0=No, 1=Yes/EmbeddedSDIO only) (R) 3-4 Reserved for Future (-) 5 Enable Continous SPI Interrupt (0=Disable, 1=Enable) (R/W) 6 Support Continous SPI Interrupt (0=No, 1=Yes) (R) 7 Card Detect Disable (0=Enable Pull-up on DAT3 pin, 1=Disable) (R/W) |
0 Support Direct Command (CMD52) during Data Transfer (0=No, 1=Yes) (R) 1 Support Multi-Block transfer (CMD53.block mode) (0=No, 1=Yes) (R) 2 Support Read Wait Control (RWC via DAT2 pin) (0=No, 1=Yes) (R) 3 Support Bus Control Suspend/Resume (0=No, 1=Yes) (R) 4 Support Block Gap Interrupt during Multi-Block (0=No, 1=Yes) (R) 5 Enable Block Gap Interrupt during Multi-Block (0=No, 1=Enable) (R/W) 6 Low Speed Card (0=Full-Speed, 1=Low-Speed) (R) 7 Support 4bit Mode for Low-Speed Card (0=No, 1=Yes) (R) |
0-16 Pointer to Card Common Card Information Structure (Common CIS) (R) 17-23 Unspecified (probably reserved) (-) |
0 Bus Status XXX see pg 37 (R) 1 Bus Release Request XXX see pg 38 (R) 2-7 Reserved for Future (-) |
0-3 Select Function (0=CIA, 1..7=Function 1..7, 8=Memory Card) (R/W) 4-6 Reserved for Future (-) 7 Data Flag (more data after resuming) (0=No, 1=Yes) (R) |
0 Command Execution Flag for Memory (=SD/Combo? or CSA?) (R) 1-7 Command Execution Flags for Function 1..7 (0=Busy, 1=Ready) (R) 8 Read/Write Ready Flag for Memory (=SD/Combo? or CSA?) (R) 9-15 Read/Write Ready Flags for Function 1..7 (0=Busy, 1=Ready) (R) |
0-15 CMD53 Block size for Function(0) (0001h..0800h) (0=None) (R/W) |
0 Support Master Power Control (0=No, 1=Yes) (R) 1 Enable Master Power Control (0=No/max 720mW, 1=Yes/allow more) (R/W) 2-7 Reserved for Future (-) |
0 Support High-Speed Mode (SDR25 or higher) (0=No, 1=Yes) (R) 1-3 Bus Speed Select (0=SDR12, 1=SDR25, 2=SDR50, 3=SDR104, 4=DDR50) (R/W) 4-7 Reserved for Future (-) 8 Support UHS-I SDR50 (usable in 1.8V mode only) (0=No, 1=Yes) (R) 9 Support UHS-I SDR104 (usable in 1.8V mode only) (0=No, 1=Yes) (R) 10 Support UHS-I DDR50 (usable in 1.8V mode only) (0=No, 1=Yes) (R) 11-15 Reserved for Future |
0 Support Driver Type A ;\see Physical Layer Specs (0=No, 1=Yes) (R) 1 Support Driver Type C ; version 3.0x for details (0=No, 1=Yes) (R) 2 Support Driver Type D ;/ (0=No, 1=Yes) (R) 3 Reserved for Future (-) 5-4 Driver Type Select (0=Default/B, 1=Type A, 2=Type C, 3=Type D) (R/W) 7-6 Reserved for Future (-) |
0 Support Asynchronous Interrupt in 4bit mode (0=No, 1=Yes) (R) 1 Enable Asynchronous Interrupt in 4bit mode (0=No, 1=Enable) (R/W) 7-2 Reserved for Future (-) |
| DSi SDIO Function Basic Registers (FBR) |
0-3 Standard SDIO Function Interface Code (R) 4-5 Reserved for Future (-) 6 Code Storage Area (CSA) Supported (0=No, 1=Yes) (R) 7 Code Storage Area (CSA) Enable (0=Block reads/writes, 1=Enable) (R/W) 8-15 Extended standard SDIO Function interface code (when bit0-3=0Fh) (R) |
0h:00h = No SDIO standard interface (eg. Atheros Wifi in DSi) 1h:00h = SDIO Standard UART 2h:00h = SDIO Bluetooth Type-A standard interface 3h:00h = SDIO Bluetooth Type-B standard interface 4h:00h = SDIO GPS standard interface 5h:00h = SDIO Camera standard interface 6h:00h = SDIO PHS standard interface 7h:00h = SDIO WLAN interface 8h:00h = Embedded SDIO-ATA standard interface 9h:00h = SDIO Bluetooth Type-A Alternate MAC PHY (AMP) standard interface Ah:00h = Reserved for Future Bh:00h = Reserved for Future Ch:00h = Reserved for Future Dh:00h = Reserved for Future Eh:00h = Reserved for Future Fh:00h..FFh = Reserved for Future |
0 Support Power Selection (0=No, 1=Yes) (R) 1 Enable Power Selection (0=Normal Current, 1=Lower Current) (R/W) 2-3 Reserved for Future (-) 4-7 Power State (R/W) |
0-16 Pointer to Function(n)'s Card Information Structure (Function CIS)(R) 17-23 Unspecified (probably reserved) (-) |
0-23 Pointer to CSA memory (incremented after CSA data read/write) (R/W) |
0-7 Data (to/from auto-incrementing CSA Address) (R for ROM, R/W otherwise) |
0-15 CMD53 Block size for Function(n) (0001h..0800h) (0=None) (R/W) |
| DSi SDIO Card Information Structures (CIS) |
PC Card Standard, Volume 4, Metaformat Specification |
00h CISTPL_code 01h Offset to next tuple (n) (aka size of body) 02h+(0..n-1) Body (n bytes) |
00h = CISTPL_NULL Null Tuple 10h = CISTPL_CHECKSUM Checksum Control 15h = CISTPL_VERS_1 Level 1 Version/Product Information 16h = CISTPL_ALTSTR Alternate Language String 20h = CISTPL_MANFID Manufacturer ID 21h = CISTPL_FUNCID Function ID 22h = CISTPL_FUNCE Function Extensions 80h-8Fh = Vendor specific Vendor specific 91h = CISTPL_SDIO_STD Info for Standard SDIO Functions 92h = CISTPL_SDIO_EXT Reserved for future SDIO stuff FFh = CISTPL_END End-of-chain |
00h Tuple ID (00h) 01h Tuple Size (00h) |
00h Tuple ID (10h) 01h Tuple Size (?) ... Unknown |
00h Tuple ID (15h) 01h Tuple Size (?) ... Unknown |
00h Tuple ID (20h) 01h Tuple Size (at least 4) 02h-03h Manufacturer ID (assigned by JEIDA or PCMCIA) 04h-05h Part Number/Revision (manufacturer specific) |
00h Tuple ID (21h) 01h Tuple Size (2) 02h Card Function Code (0Ch for SDIO) 03h System initialization bit mask (Not used, 00h) |
00h Tuple ID (22h) 01h Tuple Size (..) 02h Type of extended data 03h..xxh Function information |
00h Tuple ID (22h)
01h Tuple Size (04h+2*N)
02h Type of extended data (00h=Type 00h)
03h-04h Max Block Size for Function 0 (0001h or higher)
05h Max Transfer Speed for Function 0-7 (specified as Value*Unit bits/s)
bit0-2: Unit (0=0.1M, 1=1M, 2=10M, 3=100M, 4..7=Reserved)
bit3-6: Value (0=Reserved, 1=1, 2=1.2, 3=1.3, 4=1.5, 5=2, 6=2.5,
7=3, 8=3.5, 9=4, 10=4.5, 11=5, 12=5.5, 13=6, 14=7, 15=8)
bit7: Reserved
06h... N two-byte pairs (TC,CP) for 1..N ;(N=([01h]-4)/2)
|
00h Tuple ID (22h) 01h Tuple Size (2Ah) 02h Type of extended data (01h=Type 01h) 03h Function Info (bit0=WakeUpSupport, bit1..7=Reserved) 04h Standard SDIO Function version (2x4bit maj.min, or 00h=Nonstandard) 05h-08h Card Product Serial Number PSN (32bit) (unique value, or 0=None) 09h-0Ch CSA Size in bytes available for this Function (32bit) 0Dh CSA Property (bit0=WriteProtected/ReadOnly, bit1=NoReformatting) 0Eh-0Fh Max Block Size for this Function (0001h or higher) 10h-13h Operation Condition OCR (same as in ACMD41 for SD Memory devices) 14h-16h 3x8bit Operation Power (Min/Average/Max) (0..254mA, or 255=more) 17h-19h 3x8bit Standby Power (Min/Average/Max) (0..254mA, or 255=more) 1Ah-1Dh 2x16bit Bandwidth (Min/Optimal) (1..65535 KB/sec, or 0=None) 1Eh-1Fh Timeout for Enable-till-Ready in 10ms units (max 655.35 seconds) 20h-23h 2x16bit Operation 3.3V (Average/Max) (1..65535mA, or 0=?) 24h-25h 2x16bit High-Current-Mode 3.3V (Average/Max) (1..65535mA, or 0=?) 28h-2Bh 2x16bit Low-Current-Mode 3.3V (Average/Max) (1..65535mA, or 0=?) |
00h Tuple ID (22h) 01h Tuple Size (02h+N*2) (N=1..15, for up to 15 power states) 02h Type of extended data (02h=Type 02h) 03h Fixed value (00h) 04h..xxh Nx16bit Max consumption in Power State 1..N (0..65535mW) |
00h Tuple ID (91h) 01h Tuple Size (02h..FFh) 02h SDIO STD ID (the 4+8bit Interface Type in FBR, squeezed into 8bits?) 03h SDIO STD Type ;\depends on Interface Type 04h... SDIO STD Data (if any) ;/ |
00h Tuple ID (92h) 01h Tuple Size (?) 02h... Reserved (if any) |
00h Tuple ID (FFh) |
| DSi SD/MMC Filesystem |
| DSi SD/MMC Partition Table (aka Master Boot Record aka MBR) |
0000 00 00 00 00 00 00 00 00 .. .. .. .. 00 00 ;bootcode (zero) 01BE 00 03 18 04 06 0F E0 3B 77 08 00 00 89 6F 06 00 ;1st partition (main) 01CE 00 02 CE 3C 06 0F E0 BE 4D 78 06 00 B3 05 01 00 ;2nd partition (photo) 01DE 00 02 DE BF 01 0F E0 BF 5D 7E 07 00 A3 01 00 00 ;3rd partition (extra) 01EE 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ;4th partition (none) 01FE 55 AA ;mbr id (55h,AAh) |
000h 446 bootcode (zerofilled on DSi) ;-bootcode 1BEh+n*10h 1 status (00h) ;\ 1BFh+n*10h 3 chsFirst ; four 1C2h+n*10h 1 type (00h=unused, 01h=FAT12, 06h=FAT16B) ; partitions 1C3h+n*10h 3 chsLast ; (n=0..3) 1C6h+n*10h 4 lbaFirst ;\logical block addresses/sizes ; 1CAh+n*10h 4 lbaSize ;/counted in 200h-byte sectors ;/ 1FEh 2 mbrsig (55h,AAh) ;-MBR ID |
0-7 Head Bit0-7 (00h..FEh) (or less common, 00h..FFh) 8-13 Sector Bit0-5 (01h..3Fh) 14-15 Cylinder Bit8-9 16-23 Cylinder Bit0-7 (000h..3FFh, with above bit8-7) |
LBA = (Cylinder*32*16) + (Head*32) + (Sector-1) |
http://en.wikipedia.org/wiki/Master_Boot_Record http://en.wikipedia.org/wiki/Partition_type <-- rather meaningless |
| DSi SD/MMC Filesystem (FAT) |
000h 3 80x86 jump opcode (DSi: E9h,00h,00h) 003h 8 ascii disk name (DSi: "TWL ") 00Bh 2 bytes / sector (DSi: 0200h) 00Dh 1 sectors / cluster (DSi: 20h) 00Eh 2 sectors / boot-record (DSi: 0001h) 010h 1 number of FAT-copys (DSi: 02h) 011h 2 entrys / root-directory (DSi: 0200h) 013h 2 sectors / disk (DSi: 0000h) 015h 1 ID (DSi: F8h=HDD) 016h 2 sectors / FAT (DSi: A:0034h, B:0009h) 018h 2 sectors / track (DSi: 0020h) 01Ah 2 heads / disk (DSi: 0010h) 01Ch 2 number of reserved sectors (DSi: None such entry!) 01Ch 4 LBA First "hidden" (DSi: A:00000877h, B:0006784Dh) 020h 4 LBA Size (total sectors)(DSi: A:00066F89h, B:000105B3h) 024h 1 Drive Number (DSi: A:00h, B:01h) 025h 1 Flags (reserved) (DSi: 00h) 026h 1 EBPB Version (DSi: 29h) (that is, DOS 4.0 EBPB) 027h 4 Volume Serial Number (DSi: 12345678h) 02Bh 11 Volume Label (DSi: " ") 036h 8 Filesystem Type (DSi: 00h-filled) 03Eh 448 Bootcode (DSi: 00h-filled) 1FEh 2 Signature (DSi: 55h,AAh) |
011h 2 Must be 0 (number of root entries, is variable-length FAT chain) 016h 2 Must be 0 (sectors per fat, instead use 32bit value at 024h) 024h 4 sectors / FAT (new 32bit value instead of old entry 016h) 028h 2 ExtFlags (related to "active" FAT copy) 02Ah 2 Version of FAT32 filesystem (minor, major) (should be 0.0) 02Ch 4 Cluster number of first Root directory cluster (usually/often 2) 030h 2 Sector number of FSINFO in reserved area (usually 0001h) 032h 2 Sector number of VBR backup copy in reserved area (usually 0006h) 034h 12 Reserved for future ;Should be zerofilled 040h 1 Drive Number ;\ 041h 1 Flags (reserved) ; as old 042h 1 EBPB Version ;Must be 29h (that is, DOS 4.0 EBPB) ; entries 043h 4 Volume Serial Number ; at 024h 047h 11 Volume Label ; 052h 8 Filesystem Type ;Must be "FAT32 " ;/ |
000h 4 Value 41615252h (aka "RRaA") 004h 480 Reserved (should be 0) 1E4h 4 Value 61417272h (aka "rrAa") 1E8h 4 Hint on number of free clusters (or FFFFFFFFh=unknown) 1ECh 4 Hint on first free cluster number (or FFFFFFFFh=unknown) 1F0h 12 Reserved (should be 0) 1FCh 4 Value AA550000h |
(x000)(0)000 unused, free (x000)(0)001 ??? (x000)(0)002... pointer to next cluster in chain (0)002..(F)FEF (xFFF)(F)FF0-6 reserved (no part of chain, not free) (xFFF)(F)FF7 defect cluster, don't use (xFFF)(F)FF8-F last cluster of chain |
00-07 8 Filename (first byte: 00=free entry, 2E=dir, E5=deleted entry)
08-0A 3 Filename extension
0B 1 Fileattribute
bit0 read only
bit1 hidden
bit2 system
bit3 volume label
bit4 subdirectory
bit5 archive-flag
bit6 reserved
bit7 reserved
0C-0D 2 Reserved, or stuff
0E-0F 2 Reserved, or Creation Timestamp
10-11 2 Reserved, or Creation Datestamp
12-13 2 Reserved, or Last Access Datestamp
14-15 2 Reserved, or MSBs of Cluster (for FAT32)
16-17 2 Last Modify Timestamp: HHHHHMMM, MMMSSSSS
18-19 2 Last Modify Datestamp: YYYYYYYM, MMMDDDDD
1A-1B 2 Pointer to first Cluster of file
1C-1F 4 Filesize in bytes (always 0 for directories)
|
00h 1 Sequence Number (bit6: last logical, first physical LFN entry,
bit5: 0, bit4-0: number 01h..14h (1Fh)) (or E5h=deleted entry)
01h 10 Long Filename characters (five UCS-2 characters)
0Bh 1 Attributes (always 0Fh for LFN prefix)
0Ch 1 Type (always 00h)
0Dh 1 Short Filename Checksum
sum=00h, for i=0 to 10, sum = (sum ROR 1) + shortname_char[i], next i
0Eh 12 Long Filename characters (six UCS-2 characters)
1Ah 2 First cluster (always 0000h)
1Ch 4 Long Filename characters (two UCS-2 characters)
|
Entry 1: LFN Prefix (43h) "me.ext", 0000h, 6xFFFFh Entry 2: LFN Prefix (02h) "y long filena" Entry 3: LFN Prefix (01h) "File with ver" Entry 4: Normal 8.3 short filename entry "FILEWI~1.EXT" |
| DSi SD/MMC Internal NAND Layout |
Offset Size Description
00000000h 200h PC-style MBR, encrypted with a per-console key
00000200h 200h Stage 2 Boot Info Block 1 (used)
00000400h 200h Stage 2 Boot Info Block 2 (unused, same as above)
00000600h 200h Stage 2 Boot Info Block 3 (unused, nonsense NAND offsets)
00000800h 26600h Stage 2 ARM9 Bootcode (encrypted with universal key)
00026E00h 27600h Stage 2 ARM7 Bootcode (encrypted with universal key)
0004E400h 400h Stage 2 Footer -- unknown format, but first 10 bytes
are (unencrypted) build number of Stage 2 bootloader
0004E800h B1000h Unused (all 00h)
000FF800h 200h Unused (all 00h) (or No$gba Footer with CID & Console ID)
000FFA00h 400h Diagnostic area. (often contains build date of
device in plaintext) Blank in never-before-booted
DSi. Might be written to during firmware updates.
000FFE00h 200h Unused (all FFh)
00100000h EE00h Unused (all 00h)
0010EE00h CDF1200h 1st partition (205.9Mbyte) (main, encrypted, FAT16)
0CF00000h 9A00h Unused (all 00h)
0CF09A00h 20B6600h 2nd partition (32.7Mbyte) (photo, encrypted, FAT12)
For 240.0MB chips (Samsung KMAPF0000M-S998 or KLM5617EFW-B301):
0EFC0000h BA00h Unused (all 00h)
0EFCBA00h 34600h 3rd partition (0.2Mbyte) (extra, unformatted)
0F000000h - End of 240MByte Address Space
For 245.5MB chips (ST NAND02GAH0LZC5, both rev30 and rev31):
0EFC0000h B600h Unused (all 00h?) (smaller unused area as in 240MB chip)
0EFCB600h 5B4A00h 3rd partition (5.7Mbyte) (extra, unformatted)
0F580000h - End of 245.5MByte Address Space
|
000h 20h Zerofilled 020h 4 ARM9 Bootcode NAND Offset (800h) (Info Block 3: 80400h) 024h 4 ARM9 Bootcode Size actual (26410h) 028h 4 ARM9 Bootcode RAM Address / Entry (37B8000h) 02Ch 4 ARM9 Bootcode Size rounded-up (26600h) 030h 4 ARM7 Bootcode NAND Offset (26E00h) (Info Block 3: A6A00h) 034h 4 ARM7 Bootcode Size actual (27588h) 038h 4 ARM7 Bootcode RAM Address / Entry (37B8000h) 03Ch 4 ARM7 Bootcode Size rounded-up (27600h) 040h BFh Zerofilled 0FFh 1 ARM Loadmode Flags (0Ch) 100h 80h RSA Block (B3,FF,EC,E5,..) (Boot Info Block 3: 5B,E1,7A,9F,..) 180h 14h Global MBK1..MBK5 Slot Settings 194h 0Ch Local MBK6..MBK8 Settings, WRAM Areas for ARM9 1A0h 0Ch Local MBK6..MBK8 Settings, WRAM Areas for ARM7 1ACh 4 Global MBK9 Setting, WRAM Slot Write Protect (FF000000h) 1B0h 50h Zerofilled |
0 ARM9 Loadmode (0=Normal to memory, 1=Special via bit3) 1 ARM7 Loadmode (0=Normal to memory, 1=Special via bit3) 2 Unused, set (usually 1) 3 Special Loadmode (0=LZSS to memory, 1=Transfer via IPC FIFO) 4-7 Unused, cleared (usually 0) |
Pre 0Bh Leading RSA Padding (01,FF,FF,FF,FF,FF,FF,FF,FF,FF,00)
00h 10h AES_Engine Key Y for ARM9/ARM7 Bootcode (EC,07,00,00,...)
10h 14h SHA1 on WifiFlash[00h..27h] and eMMCBootInfo[00h..FFh,180h..1FFh]
3DS: reportedly NAND/MBR[00h..27h] instead of WifiFlash[00h..27h]??
24h 14h SHA1 on decrypted ARM9 Bootcode, with the actual binary size
38h 14h SHA1 on decrypted ARM7 Bootcode, with the actual binary size
4Ch 14h Zerofilled
60h 14h SHA1 on above 60h-byte area at [00h..5Fh] (63,D2,FC,6E,...)
|
RSA_KEY = F1,F5,1A,FF,... ;-from 3DS TWL_FIRM (for RSA Block) IV[0..3] = +size ;\ IV[4..7] = -size ; size rounded up to 200h boundary, ie. IV[8..B] = -size-1 ; from Boot Info Block entries [02Ch,03Ch] IV[C..F] = 00000000h ;/ KEY_X[0..F] = "Nintendo DS",... ;-same as Key X for "Tad Files" KEY_Y[0..F] = EC,07,00,00,... ;-from RSA Block (see above) |
IV[0..F]: SHA1(CID)+Address/10h ;-eMMC Chip ID KEY_X[0..3]: [4004D00h] ;\ KEY_X[4..7]: [4004D00h] XOR 24EE6906h ; CPU/Console ID, for KEY_X[8..B]: [4004D04h] XOR E65B601Dh ; DSi partitions on DSi KEY_X[C..F]: [4004D04h] ;/ KEY_X[0..3]: [4004D00h] ;\CPU/Console ID, for KEY_X[4..B]: "NINTENDO" ; DSi partitions on 3DS KEY_X[C..F]: [4004D04h] ;/ KEY_Y[0..F]: 0AB9DC76h,BD4DC4D3h,202DDD1Dh,E1A00005h ;-Constant |
CID = [2FFD7BCh] = dd,ss,ss,ss,ss,03,4D,30,30,46,50,41,00,00,15,00 SHA1(CID) = SWI_27h(SHA1value,2FFD7BCh,10h) |
"NUS Downloader" allows to download and decrypt system updates "DSi SRL Extract" allows to decrypt DSiware files (when copied to SD card) "TWLTool" decrypt/encrypt eMMC images (firmware downgrading, dsiware-hax) "TWLbf" and "bfCL" bruteforce Console ID or CID (or both) from eMMC images |
| DSi SD/MMC Bootloader |
Stage 1: Load Stage 2 from NAND Boot Sectors (via code in BIOS ROM) Stage 2: Load Stage 3 from NAND Filesystem Stage 3: Contains GUI and allows to boot Cartridges or NAND files |
Initialize the encryption hardware Read the contents of NVRAM Initialize both LCDs Read blocks (but not files) from the NAND flash Perform some variety of integrity check on all data it reads(signature,CRC,?) Display basic hexadecimal error codes Possibly factory-programming the NAND flash? Might also do basic power-on self test of peripherals |
Error Code Description
0000FE00 Error communicating NAND chip (It's missing, CLK shorted, etc.)
0000FEFC Integrity error in first block of Stage 2 (address at 220h)
0000FEFD Integrity error in second block of Stage 2 (address at 230h)
0000FEFE Boot sector integrity error (Sector 200h not valid), or error
in NVRAM contents.
|
00000220 00 08 00 00 10 64 02 00 00 80 7b 03 00 66 02 00 |.....d....{..f..|
00000230 00 6e 02 00 88 75 02 00 00 80 7b 03 00 76 02 00 |.n...u....{..v..|
00000240 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
|
1. The NAND flash is partially re-initialized
2. Sector 0 is read from the NAND. Appears to be (encrypted) DOS-style MBR.
3. The MBR signature and the type of the first partition are verified.
4. Filesystem metadata is read from sectors starting around 0x100000. The
metadata appears to be in FAT format with long filenames.
5. Multiple files are loaded from the filesystem. The exact read addresses
will vary depending on your DSi's firmware version and the state of
its filesystem when you performed the last firmware update. On a brand
new DSi, it appears that the DSi Menu itself is loaded from 0xb20000
after two small metadata files are read from 0xb1c000 and 0x7a0000.
|
Text Description
"Error: 1-2435-8325" Invalid signature or partition type in MBR,
invalid starting LBA.
"Error: 2-2435-8325" Error reading fat/sectors from eMMC
"Error: 3-2435-8325" DSi Menu integrity checks failed
|
| DSi SD/MMC Device List |
000h 54h*11 Device List (max 11 entries) 39Ch 24h Zerofilled 3C0h 40h Name 'nand:/title/000300tt/4ggggggg/content/000000vv.app' + 00h's |
00h 1 Drive Letter ("A".."I")
01h 1 Flags (see below)
02h 1 Access Rights (bit1=Write, bit2=Read)
03h 1 Zero
04h 10h Device Name (eg. "nand" or "dataPub") (zeropadded)
14h 40h Path (eg. "/" or "nand:/shared1") (zeropadded)
|
0 Physical Drive (0=External SD/MMC Slot, 1=Internal eMMC) 1-2 Zero (maybe MSBs of Drive) 3-4 Device Type (0=Physical, 1=Virtual/File, 2=Virtual/Folder, 3=Reserved) 5 Partition (0=1st, 1=2nd) 6 Zero (maybe MSB of Partition) 7 Encrypt? (set for eMMC physical devices; not for virtual, not for SD) |
Letter/Flags Name Path ;Notes 'A',81h,06h,00h 'nand' '/' ;eMMC Cart Partition 1 'B',A1h,06h,00h 'nand2' '/' ;eMMC Cart Partition 2 'C',11h,04h,00h 'content' 'nand:/title/000300tt/4ggggggg/content' 'D',11h,04h,00h 'shared1' 'nand:/shared1' ;TWLCFGn.dat 'E',11h,06h,00h 'shared2' 'nand:/shared2' ;Sound and wrap.bin 'F',31h,06h,00h 'photo' 'nand2:/photo' ;Camera photos/frames 'G',09h,06h,00h 'dataPrv' 'nand:/title/000300tt/4ggggggg/data/private.sav' 'H',09h,06h,00h 'dataPub' 'nand:/title/000300tt/4ggggggg/data/public.sav' 'I',00h,06h,00h 'sdmc' '/' ;SD Cart Partition 1 |
'C',09h,06h,00h 'share' 'nand:/shared2/0000' ;Sound file |
'verdata' for Version Data NARC file 'rom' for executable's NitroROM filesystem 'otherPub' 'otherPrv' |
'nand:/<tmpjump>' --> 'nand:/tmp/jump.app' 'nand:/<sharedFont>' --> 'nand:/sys/TWLFontTable.dat' 'nand:/<verdata>' --> 'nand:/title/0003000f/484e4c%02x/content/%08x.app' 'nand:/<banner>' --> ..... '/data/banner.sav' ':<srl>' --> ..... |
"nand:/../CONTENT/title.tmd" "nand:/../CONTENT/00000002.app" "nand:/../DATA/public.sav" "nand:/../DATA/private.sav" |
"sdmc:/../My Folder Name/Filpnote Studio (EUR.AUS).dsi" "sdmc:/../My Folder Name/Filpnote Studio (EUR.AUS).pub" "sdmc:/../My Folder Name/Filpnote Studio (EUR.AUS).prv" |
"sdmc:/../MYFOLD~1/FLIPN~12.DSI" "sdmc:/../MYFOLD~1/FLIPN~10.PUB" "sdmc:/../MYFOLD~1/FLIPNO~2.PRV" |
| DSi SD/MMC Complete List of SD/MMC Files/Folders |
SYS <DIR> sys LOG <DIR> log PRODUCT LOG 0000023D product.log SYSMENU LOG 00004000 sysmenu.log SHOP LOG 00000020 shop.log HWINFO_S DAT 00004000 HWINFO_S.dat HWINFO_N DAT 00004000 HWINFO_N.dat CERT SYS 00000F40 cert.sys HWID SGN 00000100 HWID.sgn TWLFON~1 DAT 000D2C40 TWLFontTable.dat DEV KP 000001BE dev.kp TITLE <DIR> title 00030017 <DIR> 00030017 (aka System Menu) 484E4150 <DIR> 484e4150 (aka Launcher) DATA <DIR> data PRIVATE SAV 00004000 private.sav CONTENT <DIR> content TITLE TMD 00000208 title.tmd 00000002 APP 0019E400 00000002.app 00030015 <DIR> 00030015 (aka System Base Tools) 484E4250 <DIR> 484e4250 (aka System Settings) DATA <DIR> data CONTENT <DIR> content TITLE TMD 00000208 title.tmd 00000002 APP 00285C00 00000002.app 484E4650 <DIR> 484e4650 (aka Nintendo DSi Shop) DATA <DIR> data PRIVATE SAV 00004000 private.sav EC CFG 00000134 ec.cfg CONTENT <DIR> content 00000004 APP 00526400 00000004.app TITLE TMD 00000208 title.tmd 0003000F <DIR> 0003000f (aka System Data) 484E4341 <DIR> 484e4341 (aka Wifi Firmware) DATA <DIR> data CONTENT <DIR> content TITLE TMD 00000208 title.tmd 00000002 APP 00017E60 00000002.app 484E4841 <DIR> 484e4841 (aka Nintendo DS Cart Whitelist) DATA <DIR> data CONTENT <DIR> content TITLE TMD 00000208 title.tmd 00000001 APP 0004B1D0 00000001.app 484E4C50 <DIR> 484e4c50 (aka Version Data) DATA <DIR> data CONTENT <DIR> content 00000004 APP 00001B50 00000004.app TITLE TMD 00000208 title.tmd 00030005 <DIR> 00030005 (aka System Fun Tools) 484E4441 <DIR> 484e4441 (aka DS Download Play) DATA <DIR> data CONTENT <DIR> content TITLE TMD 00000208 title.tmd 00000001 APP 00069BC0 00000001.app 484E4541 <DIR> 484e4541 (aka Pictochat) DATA <DIR> data CONTENT <DIR> content 00000000 APP 00074FC0 00000000.app TITLE TMD 00000208 title.tmd 484E4950 <DIR> 484e4950 (aka Nintendo DSi Camera) DATA <DIR> data PRIVATE SAV 00080000 private.sav CONTENT <DIR> content TITLE TMD 00000208 title.tmd 00000002 APP 00443C00 00000002.app 484E4A50 <DIR> 484e4a50 (aka Nintendo Zone) DATA <DIR> data PRIVATE SAV 00100000 private.sav CONTENT <DIR> content 00000003 APP 0014D000 00000003.app TITLE TMD 00000208 title.tmd 484E4B50 <DIR> 484e4b50 (aka Nintendo DSi Sound) DATA <DIR> data PRIVATE SAV 00080000 private.sav CONTENT <DIR> content 00000002 APP 00451000 00000002.app TITLE TMD 00000208 title.tmd 00030004 <DIR> 00030004 (aka DSiware) 484E4750 <DIR> 484e4750 (aka Nintendo DSi Browser) DATA <DIR> data PRIVATE SAV 00200000 private.sav CONTENT <DIR> content 00000001 APP 008F1C00 00000001.app TITLE TMD 00000208 title.tmd 4B475556 <DIR> 4b475556 (aka Flipnote Studio) DATA <DIR> data PUBLIC SAV 007F0000 public.sav CONTENT <DIR> content 00000000 APP 00348400 00000000.app TITLE TMD 00000208 title.tmd TICKET <DIR> ticket 00030017 <DIR> 00030017 (aka System Menu) 484E4150 TIK 000002C4 484e4150.tik (aka Launcher) 00030015 <DIR> 00030015 (aka System Base Tools) 484E4250 TIK 000002C4 484e4250.tik (aka System Settings) 484E4650 TIK 000002C4 484e4650.tik (aka Nintendo DSi Shop) 0003000F <DIR> 0003000f (aka System Data) 484E4341 TIK 000002C4 484e4341.tik (aka Wifi Firmware) 484E4841 TIK 000002C4 484e4841.tik (aka Nintendo DS Cart Whitelist) 484E4C50 TIK 000002C4 484e4c50.tik (aka Version Data) 00030005 <DIR> 00030005 (aka System Fun Tools) 484E4441 TIK 000002C4 484e4441.tik (aka DS Download Play) 484E4541 TIK 000002C4 484e4541.tik (aka Pictochat) 484E4950 TIK 000002C4 484e4950.tik (aka Nintendo DSi Camera) 484E4A50 TIK 000002C4 484e4a50.tik (aka Nintendo Zone) 484E4B50 TIK 000002C4 484e4b50.tik (aka Nintendo DSi Sound) 00030004 <DIR> 00030004 (aka DSiware) 484E4750 TIK 000002C4 484e4750.tik (aka Nintendo DSi Browser) 4B414D56 TIK 000002C4 4b414d56.tik (aka Paper Plane) 4B443956 TIK 000002C4 4b443956.tik (aka Dr. Mario) 4B475556 TIK 000002C4 4b475556.tik (aka Flipnote Studio) 4B4D3958 TIK 000002C4 4b4d3958.tik (aka Magic Made Fun: Deep Psyche) SHARED1 <DIR> shared1 TWLCFG0 DAT 00004000 TWLCFG0.dat TWLCFG1 DAT 00004000 TWLCFG1.dat SHARED2 <DIR> shared2 LAUNCHER <DIR> launcher WRAP BIN 00004000 wrap.bin 0000 00200000 0000 IMPORT <DIR> import TMP <DIR> tmp ES <DIR> es WRITE <DIR> write PROGRESS <DIR> progress |
PHOTO <DIR> photo PRIVATE <DIR> private DS <DIR> ds APP <DIR> app 484E494A <DIR> 484E494A (aka Nintendo DSi Camera Stuff) PIT BIN 00001F60 pit.bin DCIM <DIR> DCIM 100NIN02 <DIR> 100NIN02 HNI_0008 JPG 0000AB51 HNI_0008.JPG HNI_0009 JPG 00009A96 HNI_0009.JPG HNI_0010 JPG 0000932B HNI_0010.JPG HNI_0011 JPG 00009CB8 HNI_0011.JPG HNI_0012 JPG 00009CA9 HNI_0012.JPG HNI_0013 JPG 00009A3B HNI_0013.JPG |
PRIVATE <DIR> private DS <DIR> ds TITLE <DIR> title ;\ 484E4750 BIN 9.180K 484E4750.bin (aka Nintendo DSi Browser) ; dsiware 4B475556 BIN 11.510K 4B475556.bin (aka Flipnote Studio) ; games HNB_ LST 2K HNB_.lst (content: "VUGKPGNH") ;/ APP <DIR> app 484E494A <DIR> 484E494A (aka Nintendo DSi Camera Stuff) ;\ PIT BIN 47K pit.bin ; camera DCIM <DIR> DCIM ; frames 100NIN02 <DIR> 100NIN02 ; HNI_0001 JPG 45K HNI_0001.JPG ;-frame/mask ;/ 4B475556 <DIR> 4B475556 (aka Flipnote Studio Stuff) ;\ RECENT10 PLS 4K recent10.pls ; MARK0 PLS 8K mark0.pls ; flipnote MARK1 PLS 8K mark1.pls ; stuff MARK2 PLS 8K mark2.pls ; MARK3 PLS 8K mark3.pls ; 001 <DIR> 001 ; DIRMEMO2 LST 157K dirmemo2.lst ; F08243~1 PPM 467K F08243_0E5E2296197E5_000.ppm ;/ DCIM <DIR> DCIM 101NIN02 <DIR> 101NIN02 ;<-- can be 100NIN02 thru 999NIN02 HNI_0001 JPG 43K HNI_0001.JPG ;\dsi camera photos HNI_0002 JPG 17K HNI_0002.JPG ; (names are numbered differently HNI_0003 JPG 39K HNI_0003.JPG ;/as on eMMC where they came from) |
| DSi SD/MMC Summary of SD/MMC Files/Folders |
000000vv Title Version (lowercase hex32bit) from tmd[1E4h] as carthdr[1Eh] 4ggggggg Title ID Gamecode (hex) as carthdr[230h..233h] 000300tt Title ID Filetype (hex) as carthdr[234h..237h] HNI_nnnn Camera photo/frame files (nnnn = 0001..0100 decimal) nnnNIN02 Camera photo/frame folders (nnn = 100..999 decimal) |
00030000 ROM Cartridges (as so for ROMs, doesn't appear in SD/MMC files) 00030004 DSiware (browser, flipnote, and games) (if any installed) 00030005 System Fun Tools (camera, sound, zone, pictochat, ds download play) 0003000f System Data (non-executable, without carthdr) 00030015 System Base Tools (system settings, dsi shop, 3ds transfer tool) 00030017 System Menu (launcher) |
484e41gg System Menu (Launcher)
484e42gg System Settings
484e4341 Wifi Firmware (non-executable datafile) (all regions)
484e4441 DS Download Play (all regions)
484e4541 Pictochat (all regions) (no update available)
484e46gg Nintendo DSi Shop
484e47gg Nintendo DSi Browser
484e4841 Nintendo DS Cart Whitelist (non-executable datafile) (all regions)
484e49gg Nintendo DSi Camera
484e4agg Nintendo Zone (doesn't exist in Korea)
484e4bgg Nintendo DSi Sound
484e4cgg Version Data (non-executable datafile)
484e4fgg Nintendo 3DS Transfer Tool
484E494A Nintendo DSi Camera Data (uppercase) ("japan") (aka all regions)
4b44474a Dokodemo Wii no Ma (japan only)
4b4755gg Flipnote Studio (doesn't exist in Korea/China)
42383841 DS Internet settings (a new DSi tool on 3DS consoles)
4bgggggg DSiware games... (whatever games you have purchased, if any)
|
FAT16:\ticket\000300tt\4ggggggg.tik (encrypted) ;ticket (708 bytes) FAT16:\title\000300tt\4ggggggg\content\title.tmd ;tmd (520 bytes) FAT16:\title\000300tt\4ggggggg\content\000000vv.app ;executable (decrypted) FAT16:\title\000300tt\4ggggggg\data\public.sav ;size as carthdr[238h] FAT16:\title\000300tt\4ggggggg\data\private.sav ;size as carthdr[23Ch] FAT16:\title\000300tt\4ggggggg\data\ec.cfg ;dsi shop only FAT16:\title\000300tt\4ggggggg\data\banner.sav ;if carthdr[1BFh].bit2=1 |
FAT16:\shared1\TWLCFG0.dat ;16K FAT16:\shared1\TWLCFG1.dat ;16K FAT16:\shared2\launcher\wrap.bin ;16K FAT16:\shared2\0000 ;2048K (sound recorder) FAT16:\sys\log\product.log ;573 bytes FAT16:\sys\log\sysmenu.log ;16K FAT16:\sys\log\shop.log ;32 bytes FAT16:\sys\HWINFO_S.dat ;16K FAT16:\sys\HWINFO_N.dat ;16K FAT16:\sys\cert.sys ;3904 bytes (or 2560 bytes) FAT16:\sys\HWID.sgn ;256 bytes (unknown purpose/content) FAT16:\sys\TWLFontTable.dat ;843.1K (D2C40h bytes) (compressed) FAT16:\sys\dev.kp ;446 bytes (encrypted) FAT16:\import\ ;empty folder FAT16:\progress\ ;empty folder FAT16:\tmp\es\write\ ;empty folder |
FAT12:\photo\DCIM\100NIN02\HNI_nnnn.JPG ;camera photos FAT12:\photo\private\ds\app\484E494A\pit.bin ;camera info FAT12:\photo\private\ds\app\484E494A\DCIM\100NIN02\HNI_nnnn.JPG;camera frames |
SD:\private\ds\title\4GGGGGGG.bin ;executable/data in one file (encrypted) SD:\private\ds\title\HNB_.lst ;list of gamecodes |
SD:\DCIM\nnnNIN02\HNI_nnnn.JPG ;camera photos SD:\private\ds\app\484E494A\pit.bin ;camera info SD:\private\ds\app\484E494A\DCIM\nnnNIN02\HNI_nnnn.JPG ;camera frames |
SD:\private\ds\app\4B4755GG\recent10.pls ;Recently saved path/filenames SD:\private\ds\app\4B4755GG\mark0.pls ;Heart sticker path/filenames SD:\private\ds\app\4B4755GG\mark1.pls ;Crown sticker path/filenames SD:\private\ds\app\4B4755GG\mark2.pls ;Music sticker path/filenames SD:\private\ds\app\4B4755GG\mark3.pls ;Skull sticker path/filenames SD:\private\ds\app\4B4755GG\001\dirmemo2.lst ;List of all files in folder SD:\private\ds\app\4B4755GG\001\XNNNNN_NNNNNNNNNNNNN_NNN.ppm ;normal SD:\private\ds\app\4B4755GG\YYYYMMDD\NNN\XNNNNN_NNNNNNNNNNNNN_NNN.ppm ;backup SD:\private\ds\app\4B4755GG\gif\XNNNNN_NNNNNNNNNNNNN_NNN.gif ;gif |
SD:\...\*.aac SD:\...\*.m4a |
http://nus.cdn.t.shop.nintendowifi.net/ccs/download/000300tt4ggggggg/tmd http://nus.cdn.t.shop.nintendowifi.net/ccs/download/000300tt4ggggggg/cetk http://nus.cdn.t.shop.nintendowifi.net/ccs/download/000300tt4ggggggg/000000vv |
d:\...\TITLES\000300tt4ggggggg\ddd\000000vv ;executable (encrypted) d:\...\TITLES\000300tt4ggggggg\ddd\000000vv.APP ;executable (decrypted) d:\...\TITLES\000300tt4ggggggg\ddd\CETK ;cetk (2468 bytes) d:\...\TITLES\000300tt4ggggggg\ddd\TMD ;tmd (520 bytes) |
| DSi SD/MMC Images |
DSi-#.mmc ;eMMC for machine 1..12 (# = 1..C hex) |
00000000h .. Encrypted eMMC image (usually 240Mbyte for DSi)
0F000000h 16 Footer ID ("DSi eMMC CID/CPU")
0F000010h 16 eMMC CID (dd ss ss ss ss 03 4D 30 30 46 50 41 00 00 15 00)
0F000020h 8 CPU/Console ID (nn n1 nn nn nn nn xn 08)
0F000028h 24 Reserved (zerofilled)
|
DSi-#.sd ;SD Card for machine 1..12 (# = 1..C hex) |
| DSi SD/MMC DSiware Files on Internal eMMC Storage |
KEY_X[00h..03h] = 4E00004Ah ;\ KEY_X[04h..07h] = 4A00004Eh ; same as for Tad KEY_X[08h..0Bh] = Port[4004D00h+4] xor C80C4B72h ; KEY_X[0Ch..0Fh] = Port[4004D00h+0] ;/ KEY_Y[00h..0Fh] = Constant (E5,CC,5A,8B,...) ;from ARM7BIOS |
Data Management (in System Settings), DSi Shop, and 3DS transfer tool |
0000h 14h SHA1 on entries [014h..03Fh]
0014h 14h SHA1 on entries [040h..177h]
0028h 4 ID ("APWR") (aka 'WRAP' with mis-ordered letters)
002Ch 4 Size of entries at [040h..177h] (00000138h, aka 39*8)
0030h 10h Zerofilled
0040h 138h Space for 39 Title IDs (as at cart[230h]) (8x00h=unused entry)
0178h 3E88h Unknown (looks like random/garbage, or encrypted junk)
|
0000h 4 ID ("TSSV")
0004h 4 Zerofilled (used somehow, can be nonzero?)
0008h 2 CRC16 on [000h..0153h], initial value 5356h, assume [008h]=0000h
000Ah 6 Zerofilled
0010h 39x8 Title IDs (gg,gg,gg,gg,tt,00,03,00) (0=NDS CartSlot or Unused)
0148h 8 Zerofilled
0150h 4 Index of NDS CartSlot Entry (0..39)
|
| DSi SD/MMC DSiware Files on External SD Card (.bin aka Tad Files) |
000h 1200 List of 300 gamecodes, spelled backwards (or zero = unused entry) 4B0h 1 Language (0=Jap, 1=Eng, 2=Fre, 3=Ger, 4=Ita, 5=Spa, 6=Chi, 7=Kor?) 4B1h 3 Zero 4B4h 2 CRC16 on entries [000h..4B3h] (with initial value FFFFh) 4B6h 2 Zero |
Offset Size Key Description 000000h 4000h+20h FIX Icon/Title 004020h B4h+20h FIX Header 0040F4h 440h+20h FIX Cert (certificates/hashes) 004554h 208h+20h VAR title.tmd (usually 208h bytes; but could be bigger) 00477Ch size+N*20h VAR 000000vv.app ... 0 ? seven N/A parts (unknown if/when they are used) ... size+N*20h FIX public.sav (if any) ... ? ? banner.sav (if any) |
KEY_X[00h..0Fh] = Constant ("Nintendo DS",...)
KEY_Y[00h..0Fh] = Constant (66,82,32,04,...) ;from ARM7BIOS
since above X/Y are constant, that gives a fixed normal key:
KEY[00h..0Fh] = Constant (3D,A3,EA,33,...) ;as used in "dsi srl extract"
|
KEY_X[00h..03h] = 4E00004Ah ;\ KEY_X[04h..07h] = 4A00004Eh ; same as for dev.kp KEY_X[08h..0Bh] = Port[4004D00h+4] xor C80C4B72h ; KEY_X[0Ch..0Fh] = Port[4004D00h+0] ;/ KEY_Y[00h..0Fh] = Constant (CC,FC,A7,03,...) ;from ARM7BIOS |
0000h 23C0h Icon/Title (usually 23C0h bytes) ;see carthdr[068h,208h] 23C0h 1C40h Zerofilled (padding to get 4000h byte size) |
000h 4 Fixed ID "4ANT" (aka TNA4, spelled backwards)
004h 2 Maker Code, spelled backwards ("10"=Nintendo) ;carthdr[010h]
006h 1 Zero
007h 1 Title version (vv) ;carthdr[01Eh]
008h 6 DSi MAC Address, spelled backwards ;wifi_flash[036h]
00Eh 2 Zero
010h 16 Some console ID from HWINFO_N.dat ;datfile[8Ch..9Bh]
020h 8 Title ID (gg gg gg gg 04 00 03 00) ;carthdr[230h]
028h 4 Size of title.tmd (usually 208h+20h)
02Ch 4 Size of 000000vv.app (size+N*20h) ;carthdr[210h]
030h 4*7 Size of seven N/A parts (0)
04Ch 4 Size of public.sav (size+N*20h) ;carthdr[238h]
050h 4 Size of banner.sav? (usually 0) ;carthdr[1BFh].bit2=1
054h 4*8 List of eight Content IDs in same order as title.tmd
074h 3Eh Reserved section per tmds, uh? (mostly zero, plus garbage?)
0B2h 2 Unknown (zero)
|
000h 20 SHA1 of Icon/Title 014h 20 SHA1 of TNA4 028h 20 SHA1 of title.tmd 03Ch 20 SHA1 of 000000vv.app 040h 20*7 SHA1 of seven N/A parts (unused, can be whatever garbage) 0DCh 20 SHA1 of public.sav 0F0h 20 SHA1 of banner.sav 104h 3Ch ECC signature of [000h..103h] with AP cert 140h 180h AP cert, signed by TW cert 2C0h 180h TW cert, specific to a console (see dev.kp) |
140h 4 Signature Type (00,01,00,02) (ECC, sect233r1, non-RSA) ;\
144h 3Ch Signature Hex numbers... across... below? ; AP cert
180h 40h Signature padding/alignment (zerofilled) ; 180h-byte
1C0h 40h Signature Name "Root-CA..-MS..-TW..-08..", 00h-padded ;
"Root-CA00000001-MS00000008-TWxxxxxxxx-08nnnnnnnnnnn1nn";
200h 4 Key Type (00,00,00,02) (ECC, sect233r1, non-RSA) ;
204h 40h Key Name "AP00030015484e42gg", 00h-padded ;sys.settings ;
244h 4 Key Random/time/type/flags/chksum? ;<-- ZERO here ;
248h 3Ch Key Public ECC Key (point X,Y) (random/per game?) ;
284h 3Ch Key padding/alignment (zerofilled) ;/
2C0h 4 Signature Type (00,01,00,02) (ECC, sect233r1, non-RSA) ;\
2C4h 3Ch Signature Hex numbers... across... below? ; TW cert
300h 40h Signature padding/alignment (zerofilled) ; 180h-byte
340h 40h Signature Name "Root-CA00000001-MS00000008", 00h-padded ; (same as
380h 4 Key Type (00,00,00,02) (ECC, sect233r1, non-RSA) ; dev.kp,
384h 40h Key Name "TWxxxxxxxx-08nnnnnnnnnnn1nn", 00h-padded ; excluding
3C4h 4 Key Random/time/type/flags/chksum? ; private
3C8h 3Ch Key Public ECC Key (point X,Y) ; key)
404h 3Ch Key padding/alignment (zerofilled) ;/
|
| DSi SD/MMC DSiware Files from Nintendo's Server |
Server: "000000vv" (AES-CBC encrypted, raw) eMMC: "000000vv.app" (decrypted, raw) SD Card: "GGGGGGGG.bin" (ES-block encrypted, with extra data) |
KEY[00h..0Fh] = Common Key (AF,1B,F5,16,...) ;from ARM7BIOS IV[00h..07h] = Title ID (00,03,00,tt,gg,gg,gg,gg) ;from tik/cetk[1DCh] IV[08h..0Fh] = Zerofilled ;padding Input: Encrypted Title Key ;from tik/cetk[1BFh] Output: Decrypted Title Key ;for use in next step |
KEY[00h..0Fh] = Decrypted Title Key ;from above step IV[00h..01h] = Usually Zero (or "Index" from tmd?) ;from tmd[1E8h+N*24h] ? IV[02h..0Fh] = Zerofilled ;padding Input: Encrypted file "000000vv" ;from http download Output: Decrypted file "000000vv.app" ;saved on eMMC |
http://nus.cdn.t.shop.nintendowifi.net/ccs/download/00030015484e4250/tmd http://nus.cdn.t.shop.nintendowifi.net/ccs/download/00030015484e4250/cetk http://nus.cdn.t.shop.nintendowifi.net/ccs/download/00030015484e4250/00000002 http://nus.cdn.t.shop.nintendowifi.net/ccs/download/00030015484e4250/00000003 |
| DSi SD/MMC DSiware Tickets and Title metadata |
Server: "cetk" unencrypted, 2468 bytes (2A4h+700h), tik+certificate eMMC: "gggggggg.tik" encrypted, 708 bytes (2A4h+20h), tik+es_block SD Card: N/A N/A, tickets aren't exported to SD card |
000h 4 Signature Type (00h,01h,00h,01h) (100h-byte RSA) 004h 100h Signature RSA-OpenPGP-SHA1 across 140h..2A3h 104h 3Ch Signature padding/alignment (zerofilled) 140h 40h Signature Name "Root-CA00000001-XS00000006", 00h-padded 180h 3Ch ECDH data for one-time installation keys? ;zero for free tik's 1BCh 1 Zero (3DS: Ticket Version=1) 1BDh 1 Zero (3DS: CaCrl Version=0) 1BEh 1 Zero (3DS: SignerCrl Version=0) 1BFh 10h Encrypted AES-CBC Title Key 1CFh 1 Zero 1D0h 8 Ticket ID (00,03,xx,xx,xx,xx,xx,xx) ? 1D8h 4 Console ID (see dev.kp "TWxxxxxxxx", zero for free system updates) 1DCh 8 Title ID (00,03,00,17,"HNAP") ;cart[230h] 1E4h 2 Zero (Wii: mostly FFFFh) 1E6h 2 Title Version (vv,00) (LITTLE-ENDIAN!?) ;NEWEST ;cart[01Eh] 1E8h 4 Zero (Wii: Permitted Titles Mask) 1ECh 4 Zero (Wii: Permit mask) 1F0h 1 Zero (Wii: Allow Title Export using PRNG key, 0=No, 1=Yes) 1F1h 1 Zero (Wii: Common Key Index, 0=Normal, 1=Korea) (DSi: Always 0) 1F2h 2Ah Zero 21Ch 4 Zero (3DS: eShop Account ID?) 220h 1 Zero 221h 1 Unknown (01h) (Wii: Unknown, 00h=Non-VC, 01h=VC=VirtualConsole?) 222h 20h FFh-filled (Wii: Content access permissions, 1 bit per content) 242h 20h 00h-filled (Wii: Content access permissions, 1 bit per content) 262h 2 Zero 264h 4 Zero ;Wii: Time Limit Enable (0=Disable, 1=Enable) 268h 4 Zero ;Wii: Time Limit Seconds (uh, seconds since/till when?) 26Ch 38h Zero ;Wii: Seven more Time Limits (Enable, Seconds) 2A4h 700h Certificates (see below) (only in "cetk", not in ".tik) |
Server: "tmd" unencrypted, 2312 bytes (208h+700h), tmd+certificate Server: "tmd.nn" as above, OLDER tmd versions (nn=0,1,256,257,512,etc) eMMC: "title.tmd" unencrypted, 520 bytes (208h+0), tmd SD Card: "GGGGGGGG.bin" encrypted, huge file, contains .app+tmd+sav files |
000h 4 Signature Type (00h,01h,00h,01h) (100h-byte RSA) 004h 100h Signature RSA-OpenPGP-SHA1 across 140h..207h 104h 3Ch Signature padding/alignment (zerofilled) 140h 40h Signature Name "Root-CA00000001-CP00000007", 00h-padded 180h 1 TMD Version (00h) (unlike 3DS) 181h 1 ca_crl_version (00h) 182h 1 signer_crl_version (00h) 183h 1 Zero (padding/align 4h) 184h 8 System Version (0) 18Ch 8 Title ID (00,03,00,17,"HNAP") ;cart[230h] 194h 4 Title Type (0) 198h 2 Group ID (eg. "01"=Nintendo) ;cart[010h] 19Ah 4 SD/MMC "public.sav" filesize in bytes (0=none) ;cart[238h] 19Eh 4 SD/MMC "private.sav" filesize in bytes (0=none) ;cart[23Ch] 1A2h 4 Zero 1A6h 1 Zero (3DS: SRL Flag) 1A7h 3 Zero 1AAh 10h Parental Control Age Ratings ;cart[2F0h] 1BAh 1Eh Zerofilled 1D8h 4 Access rights (0) 1DCh 2 Title Version (vv,00) (LITTLE-ENDIAN!?) ;NEWEST ;cart[01Eh] 1DEh 2 Number of contents (at 1E4h and up) (usually 00h,01h) 1E0h 2 boot content index (0) 1E2h 2 Zerofilled (padding/align 4h) 1E4h+N*24h 4 Content ID (00,00,00,vv) ;lowercase/hex ;"0000000vv.app" 1E8h+N*24h 2 Content Index (00,00) 1EAh+N*24h 2 Content Type (00,01) ;aka DSi .app 1ECh+N*24h 8 Content Size (00,00,00,00,00,19,E4,00) ;NEWEST ;cart[210h] 1F4h+N*24h 14h Content SHA1 (on decrypted ".app" file);NEWEST 208h+.. 700h Certificates (see below) (only in "tmd", not in ".tmd) |
cert cetk tmd siz content 000h 2A4h 208h 4 Signature Type (00h,01h,00h,01h) ;\ 004h 2A8h 20Ch 100h Signature ; 104h 3A8h 30Ch 3Ch Signature padding/alignment (zerofilled) ; 140h 3E4h 348h 40h Signature Name "Root-CA00000001", 00h-padded ; 300h bytes 180h 424h 388h 4 Key Type (00,00,00,01) (100h-byte RSA) ; 184h 428h 38Ch 40h Key Name "XS00000006", 00h-padded ; 1C4h 468h 3CCh 4 Key Random/time/type/flags/chksum? ; 1C8h 46Ch 3D0h 100h Key Public RSA Key ; 2C8h 56Ch 4D0h 4 Key Public RSA Exponent? (00,01,00,01) ; 2CCh 570h 4D4h 34h Key padding/alignment (zerofilled) ;/ 300h 5A4h 508h 4 Signature Type (00h,01h,00h,00h) ;\ 304h 5A8h 50Ch 200h Signature ; 504h 7A8h 70Ch 3Ch Signature padding/alignment (zerofilled) ; 540h 7E4h 748h 40h Signature Name "Root" (padded with 00h) ; 400h bytes 580h 824h 788h 4 Key Type (00,00,00,01) (100h-byte RSA) ; 584h 828h 78Ch 40h Key Name "CA00000001", 00h-padded ; 5C4h 868h 7CCh 4 Key Random/time/type/flags/chksum? ; 5C8h 86Ch 7D0h 100h Key Public RSA Key ; 6C8h 86Ch 8D0h 4 Key Public RSA Exponent? (00,01,00,01) ; 6CCh 970h 8D4h 34h Key padding/alignment (zerofilled) ;/ |
| DSi SD/MMC Firmware dev.kp and cert.sys Certificate Files |
000h 300h Public RSA Key "XS00000006" signed by "Root-CA00000001" 300h 400h Public RSA Key "CA00000001" signed by "Root" 700h 300h Public RSA Key "CP00000007" signed by "Root-CA00000001" Below NOT in Korea? Or NOT when notyet connected to DSi Shop? A00h 240h Public ECC Key "MS00000008" signed by "Root-CA00000001" C40h 300h Public RSA Key "XS00000003" signed by "Root-CA00000001" |
000h 300h Public RSA Key "CP00000005" signed by "Root-CA00000002" 300h 300h Public RSA Key "XS00000006" signed by "Root-CA00000002" 600h 400h Public RSA Key "CA00000002" signed by "Root" A00h 300h Public RSA Key "CP00000007" signed by "Root-CA00000002" |
000h 4 Signature Type (00,01,00,01) (100h-byte RSA) ;\ 004h 100h Signature RSA-OpenPGP-SHA1 across 140h..2FFh ; 104h 3Ch Signature padding/alignment (zerofilled) ; 140h 40h Signature Name "Root-CA00000001", 00h-padded ; 180h 4 Key Type (00,00,00,01) (100h-byte RSA) ; 184h 40h Key Name "XS00000006", 00h-padded ; 1C4h 4 Key Random/time/type/flags/chksum? ; 1C8h 100h Key Public RSA Key (92,FF,96,40..) ; 2C8h 4 Key Public RSA Exponent? (00,01,00,01) ; 2CCh 34h Key padding/alignment (zerofilled) ;/ 300h 4 Signature Type (00,01,00,00) (200h-byte RSA) (!) ;\ 304h 200h Signature RSA-OpenPGP-SHA1 across 540h..6FFh ; 504h 3Ch Signature padding/alignment (zerofilled) ; 540h 40h Signature Name "Root", 00h-padded ; 580h 4 Key Type (00,00,00,01) (100h-byte RSA) ; 584h 40h Key Name "CA00000001", 00h-padded ; 5C4h 4 Key Random/time/type/flags/chksum? ; 5C8h 100h Key Public RSA Key (B2,79,C9,E2..) ; 6C8h 4 Key Public RSA Exponent? (00,01,00,01) ; 6CCh 34h Key padding/alignment (zerofilled) ;/ 700h 4 Signature Type (00,01,00,00) (100h-byte RSA) ;\ 704h 100h Signature RSA-OpenPGP-SHA1 across 840h..9FFh ; 804h 3Ch Signature padding/alignment (zerofilled) ; 840h 40h Signature Name "Root-CA00000001", 00h-padded ; 880h 4 Key Type (00,00,00,01) (100h-byte RSA) ; 884h 40h Key Name "CP00000007", 00h-padded ; 8C4h 4 Key Random/time/type/flags/chksum? ; 8C8h 100h Key Public RSA Key (93,BC,0D,1F..) ; 9C8h 4 Key Public RSA Exponent? (00,01,00,01) ; 9CCh 34h Key padding/alignment (zerofilled) ;/ Below NOT when notyet connected to DSi Shop: A00h 4 Signature Type (00,01,00,01) (100h-byte RSA) ;\ A04h 100h Signature RSA-OpenPGP-SHA1 across B40h..C3Fh ; B04h 3Ch Signature padding/alignment (zerofilled) ; B40h 40h Signature Name "Root-CA00000001", 00h-padded ; B80h 4 Key Type (00,00,00,02) (ECC, sect233r1, non-RSA) ; B84h 40h Key Name "MS00000008", 00h-padded ; BC4h 4 Key Random/time/type/flags/chksum? ; BC8h 3Ch Key Public ECC Key (point X,Y) (01,93,6D,08..) ; C04h 3Ch Key padding/alignment (zerofilled) ;/ C40h 4 Signature Type (00,01,00,01) (100h-byte RSA) ;\ C44h 100h Signature RSA-OpenPGP-SHA1 across D80h..F3Fh ; D44h 3Ch Signature padding/alignment (zerofilled) ; D80h 40h Signature Name "Root-CA00000001", 00h-padded ; DC0h 4 Key Type (00,00,00,01) (100h-byte RSA) ; DC4h 40h Key Name "XS00000003", 00h-padded ; E04h 4 Key Random/time/type/flags/chksum? ; E08h 100h Key Public RSA Key (AD,07,A9,37..) ; F08h 4 Key Public RSA Exponent? (00,01,00,01) ; F0Ch 34h Key padding/alignment (zerofilled) ;/ |
Root-CA00000001: used for signing the four certificates below
Root-CA00000001-CP00000007: used for signing TMDs ("Content Protection"?)
Root-CA00000001-MS00000008: used for signing per-console ECC keys ("Master"?)
Root-CA00000001-XS00000003: used for signing tickets from the DSiWare Shop
Root-CA00000001-XS00000006: used for signing (common) tickets ("access"?)
|
KEY_X[00h..03h] = 4E00004Ah ;\ KEY_X[04h..07h] = 4A00004Eh ; same as for Tad KEY_X[08h..0Bh] = Port[4004D00h+4] xor C80C4B72h ; KEY_X[0Ch..0Fh] = Port[4004D00h+0] ;/ KEY_Y[00h..0Fh] = Constant (E5,CC,5A,8B,...) ;from ARM7BIOS |
000h 4 Signature Type (00,01,00,02) (ECC, sect233r1, non-RSA) ;\ 004h 3Ch Signature Hex numbers... across... below? ; 040h 40h Signature padding/alignment (zerofilled) ; 080h 40h Signature Name "Root-CA00000001-MS00000008", 00h-padded ; 0C0h 4 Key Type (00,00,00,02) (ECC, sect233r1, non-RSA) ; 0C4h 40h Key Name "TWxxxxxxxx-08nnnnnnnnnnn1nn", 00h-padded ; 104h 4 Key Random/time/type/flags/chksum? ; 108h 3Ch Key Public ECC Key (point X,Y) ;<-- public key ; 144h 3Ch Key padding/alignment (zerofilled) ; 180h 1Eh Key Private ECC Key ;<-- private key ;/ |
"TW" might be for DSi only (ie. it might be different on DSi XL or 3DS?) "xxxxxxxx" is 8-digit lower-case hex number (unknown where from; for .tik) "08nnnnnnnnnnn1nn" is 16-digit lower-case hex number (from Port 4004D00h) |
Signature across rest of block -- type = 0x00010002, ECC 0000000: 00 01 00 02 00 db da 21 3b e1 f1 bf bb 4d dc 1d 0000010: 60 29 da 19 42 1e 66 4f a8 e5 27 a1 d4 ea 46 7d 0000020: 9b b4 00 95 c5 0d e8 fa ef a7 8d e9 bc 54 da c1 0000030: 24 94 0b 7c ad a8 61 d5 05 97 c2 64 38 ad 18 f9 |
0000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Key used to sign this cert (Root-CA00000001-MS00000008) 0000080: 52 6f 6f 74 2d 43 41 30 30 30 30 30 30 30 31 2d Root-CA00000001- 0000090: 4d 53 30 30 30 30 30 30 30 38 00 00 00 00 00 00 MS00000008 00000a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Console ID string 00000c0: 00 00 00 02 54 57 63 37 39 64 63 65 63 39 2d 30 ....TWc79dcec9-0 00000d0: 38 61 32 30 32 38 37 30 31 30 38 34 31 31 38 00 8a2028701084118. 00000e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00000f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Public ECC key (30 bytes, starting at 0x108) 0000100: 00 00 00 00 6f dd de 42 01 e0 34 a3 19 bc a9 af 0000110: 50 fe 8a ac 75 08 07 a9 3a 2c 21 51 93 ae 4a 90 0000120: 6e 62 41 f1 a2 fe 00 00 3d 0a 13 97 da 53 17 98 0000130: 69 38 65 67 ca f4 9c 87 ec 44 b7 eb d0 ec b8 3d 0000140: 23 cf 7a 35 00 00 00 00 00 00 00 00 00 00 00 00 0000150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0000160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0000170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Private per-console ECC key, used for signing files on SD 0000180: 01 12 9d e0 77 82 44 d3 ee 99 ad ce e5 fa fa ed 0000190: c9 ab 8e a1 f9 b5 c8 14 3c 74 74 f8 19 3a |
| DSi SD/MMC Firmware Certificate/Keys (DER) |
DSi Version Data, narc:\NintendoCA-G2.der (unencrypted) DSi Version Data, narc:\.twl-*.der (ES Block encrypted) DSi Browser, rom:\ca\*.ca (unencrypted) DSi is-twl-update, *.der (dev unit public keys) (unencrypted, stringless) DSi Dokodemi, rom:key\pubkey.der (only 162 bytes) (unencrypted, stringless) 3DS browser applet, RomFS:\browser\rootca.pem (ASCII BASE64 .der's) 3DS System Data Archives 1, offline... cave.pem (ASCII BASE64 .der) 3DS Shared Data Archives, Non-Nintendo TLS, *.der (unencrypted) 3DS System Data Archives 1, ClCertA, RomFS:*.bin (AES-CBC encrypted) 3DS Nintendo Zone, RomFS:\certs\*.der (unencrypted) 3DS Nintendo Zone, RomFS:\certs\dev.pem (ASCII BASE64 .der) 3DS Nintendo Zone, RomFS:\certs\client.key (ASCII BASE64 .der) 3DS Miiverse olv applet, RomFS:\browser\cave.pem (ASCII BASE64 .der) 3DS Miiverse olv applet, RomFS:\browser\*.p12 (nested der-inside-der?) |
_________________________ Tag,Length,Value Encoding __________________________ |
bit6-7 class (0=Universal, 1=Application, 2=Context-defined, 3=Private) bit5 form (0=Primitive, 1=Constructed) bit4-0 number (0..1Fh) |
BOOLEAN UNIVERSAL Primitive 00000001 (01h) INTEGER UNIVERSAL Primitive 00000010 (02h) BIT STRING UNIVERSAL Primitive 00000011 (03h) OCTET STRING UNIVERSAL Primitive 00000100 (04h) NULL UNIVERSAL Primitive 00000101 (05h) OBJECT IDENTIFIER UNIVERSAL Primitive 00000110 (06h) UTF8String UNIVERSAL Primitive 00001100 (0Ch) PrintableString UNIVERSAL Primitive 00010011 (13h) TeletexString UNIVERSAL Primitive 00010100 (14h) IA5String UNIVERSAL Primitive 00010110 (16h) Time String (17h) in dsi version data BMPString UNIVERSAL Primitive 00011110 (1Eh) SEQUENCE UNIVERSAL Constructed 00110000 (30h) SEQUENCE OF UNIVERSAL Constructed 00110000 (30h) SET UNIVERSAL Constructed 00110001 (31h) SET OF UNIVERSAL Constructed 00110001 (31h) -unknown- CONTEXT Primitive (80h) ;3ds miiverse .p12 -unknown- CONTEXT Constructed (A0h) ;dsi version (small) -unknown- CONTEXT Constructed (A3h) ;dsi browser (big) |
when bit7=0 --> bit6-0 contain length (0..127 bytes) when bit7=1 --> bit6-0 contain number of following length bytes |
len = Length 0..127 bytes (with len<80h) 81h,len = Length 128..255 bytes (with len>7Fh) 82h,msb,lsb = Length 256..65535 bytes (with msb:len>00FFh) |
___________________________________ Tag's ____________________________________ |
value[0] = flag (00h=False, or FFh=True) |
value[0..(len-1)] = data ;(len)*8 bits (with sign bit in MSB of 1st byte) |
value[0] = number of unused bits in LSB of last byte (0..7) value[1..(len-1)] = data ;(len-1)*8-unused bits |
value[1..(len-1)] = data ;(len-1)*8 bits |
value[0] = 2nd+(1st*40) ;\ value[1] = 3rd ; basic encoding for 7bit values value[2] = 4th ; etc. ;/ |
1.2.3.4.255 --> 2Ah, 03h, 04h, 81h,7Fh 2.999.1234.1.2.3.4 --> 88h,37h, 89h,52h, 01h, 02h, 03h, 04h |
http://oidref.com/ |
value[0..(len-1)] = text string |
"YYMMDDHHMMZ" ;\ "YYMMDDHHMM+HHMM" ; UTC Time without seconds, and optional timezone "YYMMDDHHMM-HHMM" ;/ "YYMMDDHHMMSSZ" ;\ "YYMMDDHHMMSS+HHMM" ; UTC Time with seconds, and optional timezone "YYMMDDHHMMSS-HHMM" ;/ "YYYYMMDDHHMMSSZ" ;\Generalized Time with seconds and century, and "YYYYMMDDHHMMSS.SSSSZ" ;/optional seconds fraction (no trailing zeroes) |
value[0..(len-1)] = contains further Tag,Length,Data values |
_________________________________ OID Values _________________________________ |
0.9.2342.19200300.100.1.* /itu-t/data/pss/ucl/pilot/pilotAttributeType/.. 0.9.2342.19200300.100.1.1 ../userid ;unused 0.9.2342.19200300.100.1.25 ../domainComponent ;unused 1.2.840.113533.7.65.* /iso/member-body/us/nortelnetworks/entrust/nsn-ce/.. 1.2.840.113533.7.65.0 ../0 ;dsi browser equifax_s_ca.ca 1.2.840.113549.1.1.* /iso/member-body/us/rsadsi/pkcs/pkcs-1/.. 1.2.840.113549.1.1.1 ../rsaEncryption 1.2.840.113549.1.1.2 ../rsaEncryptionWithMD2 ;dsi browser rsa.ca 1.2.840.113549.1.1.3 ../rsaEncryptionWithMD4 ;unused 1.2.840.113549.1.1.4 ../rsaEncryptionWithMD5 ;dsi browser thawte.ca 1.2.840.113549.1.1.5 ../rsaEncryptionWithSHA1 1.2.840.113549.1.1.11 ../rsaEncryptionWithSHA256 1.2.840.113549.1.1.12 ../rsaEncryptionWithSHA384 ;unused 1.2.840.113549.1.1.13 ../rsaEncryptionWithSHA512 ;unused 1.2.840.113549.1.1.14 ../rsaEncryptionWithSHA224 ;unused 1.2.840.113549.1.7.* /iso/member-body/us/rsadsi/pkcs/pkcs-7/.. 1.2.840.113549.1.7.1 ../data ;for nested .der? ;3ds miiverse olv applet 1.2.840.113549.1.7.6 ../encryptedData ;"inside" pkcs-7 1.2.840.113549.1.9.* /iso/member-body/us/rsadsi/pkcs/pkcs-9/.. 1.2.840.113549.1.9.1 ../emailAddress 1.2.840.113549.1.9.21 ../localKeyID ;"inside" pkcs-7 1.2.840.113549.1.12.1.* /iso/member-body/us/rsadsi/pkcs/pkcs-12/PbeIds/.. 1.2.840.113549.1.12.1.3 ../pbeWithSHAAnd3-KeyTripleDES-CBC ;\inside pkcs-7 1.2.840.113549.1.12.1.6 ../pbeWithSHAAnd40BitRC2-CBC ;/ 1.2.840.113549.1.12.10.* /iso/member-body/us/rsadsi/pkcs/pkcs-12/Version1/. 1.2.840.113549.1.12.10.1.2 ../BagIds/ShroudedKeyBag ;-inside pkcs-7 1.3.6.1.4.1.311.* /iso/org/dod/internet/prv/enterprise/microsoft/.. 1.3.6.1.4.1.311.20.2 ../20/2/? ;incomplete blurp? ;3ds browser securetrust 1.3.6.1.4.1.311.21.1 ../21.1 ;unknown blurp? ;3ds browser securetrust 1.3.6.1.5.5.7.1.* /iso/org/dod/internet/security/mechanisms/pkix/pe/.. 1.3.6.1.5.5.7.1.12 ../id-pe-logotype ;3ds shared data TLS, CA_8.der 1.3.14.3.2.* /iso/org/oiw/secsig/algorithms/.. 1.3.14.3.2.26 ../hashAlgorithmIdentifier ;3ds miiverse olv applet 2.5.4.* /joint/ds/attributeType/.. 2.5.4.3 ../commonName 2.5.4.4 ../surname 2.5.4.5 ../serialNumber 2.5.4.6 ../countryName 2.5.4.7 ../localityName 2.5.4.8 ../stateOrProvinceName 2.5.4.9 ../streetAddress 2.5.4.10 ../organizationName 2.5.4.11 ../organizationalUnit 2.5.4.12 ../title 2.5.4.42 ../givenName 2.5.29.* /joint/ds/certificateExtension/.. 2.5.29.14 ../subjectKeyIdentifier 2.5.29.15 ../keyUsage 2.5.29.16 ../privateKeyUsagePeriod ;dsi browser equifax_s_ca.ca 2.5.29.17 ../subjectAltName ;3ds browser japnese gov 2.5.29.18 ../issuerAltName ;unused 2.5.29.19 ../basicConstraints 2.5.29.20 ../cRLNumber ;unused 2.5.29.21 ../reasonCode ;unused 2.5.29.22 ../expirationDate ;unused 2.5.29.23 ../instructionCode ;unused 2.5.29.24 ../invalidityDate ;unused 2.5.29.25 ../cRLDistributionPoints ;unused 2.5.29.26 ../issuingDistributionPoint ;unused 2.5.29.27 ../deltaCRLIndicator ;unused 2.5.29.28 ../issuingDistributionPoint ;unused 2.5.29.29 ../certificateIssuer ;unused 2.5.29.30 ../nameConstraints ;unused 2.5.29.31 ../cRLDistributionPoints 2.5.29.32 ../certificatePolicies ;dsi browser swiss_g2.ca 2.5.29.33 ../policyMappings ;unused 2.5.29.34 ../policyConstraints ;unused 2.5.29.35 ../authorityKeyIdentifier 2.5.29.36 ../policyConstraints ;unused 2.5.29.37 ../extKeyUsage ;3ds browser usertrust 2.16.840.1.113730.1.* /joint/country/us/organization/netscape/cert-ext/.. 2.16.840.1.113730.1.1 ../cert-type ;dsi browser tc_c2_ca.ca 2.16.840.1.113730.1.8 ../ca-policy-url ;dsi browser tc_c2_ca.ca 2.16.840.1.113730.1.13 ../comment |
| DSi SD/MMC Firmware Font File |
0000h 80h RSA-SHA1 on entries [0080h..009Fh] (23h,8Bh,F9h,08h,...) 0080h 4 Date? (00h,31h,07h,08h=Normal, 00h,27h,05h,09h=China/Korea) 0084h 1 Number of NFTR resources (NUM) (3=Normal, 9=China/Korea) 0085h 1 Zerofilled 0086h 1 Unknown (0=Normal, 4=China, 5=Korea) 0087h 5 Zerofilled 008Ch 14h SHA1 on below resource headers at [00A0h+(0..NUM*40h-1)] 00A0h+N*40h 20h Resource Name in ASCII, padded with 00h 00C0h+N*40h 4 Compressed Resource Size in .dat file ;\compressed 00C4h+N*40h 4 Compressed Resource Start in .dat file ;/ 00C8h+N*40h 4 Decompressed Resource Size ;-decompressed 00CCh+N*40h 14h SHA1 on Compressed Resource at [Start+0..Size-1] ... .. Compressed Font Resources (with 16-byte alignment padding) |
"TBF1_l.NFTR" ;0 Large 16x21 pixels ;\Normal (blurry: 4 colors used) "TBF1_m.NFTR" ;1 Medium 12x16 pixels ; 2bpp, 7365 characters, Unicode "TBF1_s.NFTR" ;2 Small 10x12 pixels ;/ "TBF1-cn_l.NFTR" ;3 Large 16x21 pixels ;\China (crisp-clear: 2 colors used) "TBF1-cn_m.NFTR" ;4 Medium 12x16 pixels ; 2bpp, 7848 characters, Unicode "TBF1-cn_s.NFTR" ;5 Small 12x13 pixels ;/ "TBF1-kr_l.NFTR" ;6 Large 16x21 pixels ;\Korea (crisp-clear: 2 colors used) "TBF1-kr_m.NFTR" ;7 Medium 12x16 pixels ; 2bpp, 3679 characters, Unicode "TBF1-kr_s.NFTR" ;8 Small 12x12 pixels ;/ |
.. uncompressed area (usually 15h bytes) ... compressed area (decompressed backwards) .. footer: padding (to 4-byte boundary) 3 footer: size of footer+compressed area (offset to compressed.bottom) 1 footer: size of footer (offset to compressed.top) 4 footer: extra DEST size (offset to decompressed.top) .. zeropadding to 10h-byte boundary |
| DS Cartridge Nitro Font Resource Format |
.NFTR Raw uncompressed Nitro Font Resource .ZFTR LZ11-compressed Nitro Font Resource .dat Archive with three LZrev-compressed Nitro Font Resources (used on DSi) |
00h 4 Chunk ID "RTFN" (aka NFTR backwards, Nitro Font Resource) 04h 2 Byte Order (FEFFh) (indicates that above is to be read backwards) 06h 2 Version (0100h..0102h) (usually 0101h or 0102h) 08h 4 Decompressed Resource Size (000A3278h) (including the NFTR header) 0Ch 2 Offset to "FNIF" Chunk, aka Size of "RTFN" Chunk (0010h) 0Eh 2 Total number of following Chunks (0003h+NumCharMaps) (0018h) |
00h 4 Chunk ID "FNIF" (aka FINF backwards, Font Info) 04h 4 Chunk Size (1Ch or 20h) 08h 1 Unknown/unused (zero) 09h xxx 1 Height ;or Height+/-1 0Ah xxx 1 Unknown (usually 00h, or sometimes 1Fh maybe for chr(3Fh)="?") 0Bh 2 Unknown/unused (zero) 0Dh xxx 1 Width ;\or Width+1 0Eh xxx 1 Width_bis (?) ;/ 0Fh 1 Encoding (0=UTF8, 1=Unicode, 2=SJIS, 3=CP1252) (usually 1) 10h 4 Offset to Character Glyph chunk, plus 8 14h 4 Offset to Character Width chunk, plus 8 18h 4 Offset to first Character Map chunk, plus 8 1Ch (1) Tile Height ;\present only 1Dh xxx (1) Max Width or so +/-? ; when above 1Eh (1) Underline location ; Chunk Size = 20h 1Fh (1) Unknown/unused (zero) ;/(version 0102h) |
00h 4 Chunk ID "PLGC" (aka CGLP backwards, Character Glyph) 04h 4 Chunk Size (10h+NumTiles*siz+padding) 08h 1 Tile Width in pixels 09h 1 Tile Height in pixels 0Ah 2 Tile Size in bytes (siz=width*height*bpp+7)/8) 0Ch 1 Underline location 0Dh 1 Max proportional Width including left/right spacing 0Eh 1 Tile Depth (bits per pixel) (usually 1 or 2, sometimes 3) 0Fh 1 Tile Rotation (0=None/normal, other=see below) 10h ... Tile Bitmaps ... ... Padding to 4-byte boundary (zerofilled) |
00h 4 Chunk ID "HDWC" (aka CWDH backwards, Character Width) 04h 4 Chunk Size (10h+NumTiles*3+padding) 08h 2 First Tile Number (should be 0000h) 0Ah 2 Last Tile Number (should be NumTiles-1) 0Ch 4 Unknown/unused (zero) 10h+N*3 1 Left Spacing (to be inserted left of character bitmap) 11h+N*3 1 Width of Character Bitmap (excluding left/right spacing) 12h+N*3 1 Total Width of Character (including left/right spacing) ... ... Padding to 4-byte boundary (zerofilled) |
00h 4 Chunk ID "PAMC" (aka CMAP backwards, Character Map) 04h 4 Chunk Size (14h+...+padding) 08h 2 First Character (eg. 0020h=First ASCII Char) 0Ah 2 Last Character (eg. 007Eh=Last ASCII Char) 0Ch 4 Map Type (0..2, for entry 14h and up, see there) 10h 4 Offset to next Character Map, plus 8 (0=None, no further) |
14h 2 TileNo for First Char (and increasing for further chars) 16h 2 Padding to 4-byte boundary (zerofilled) |
14h+N*2 2 TileNo's for First..Last Char (FFFFh=None; no tile assigned) ... 0/2 Padding to 4-byte boundary (zerofilled) |
14h 2 Number of following Char=Tile groups... 16h+N*4 2 Character Number 18h+N*4 2 Tile Number ... 2 Padding to 4-byte boundary (zerofilled) |
| LZ Decompression Functions |
10,ss,ss,Ss ;ID(10h), Size(Ssssss) ;-LZSS header 11,ss,ss,Ss ;ID(11h), Size(Ssssss) ;-LZ11 header "Yaz0",Ss,ss,ss,ss,0,0,0,0,0,0,0,0 ;-Yaz0 header Ff ;Flags(Ff), each 8 entries ;-Flags (bit7=first) 1N,nn,nP,pp ;Disp(Ppp)+1, Len(Nnnn)+111h ;\ 0N,nP,pp ;Disp(Ppp)+1, Len(Nn)+11h ; LZ11, when flag=1 NP,pp ;Disp(Ppp)+1, Len(N)+1 ;/ 0P,pp,Nn ;Disp(Ppp)+1, Len(Nn)+12h ;\Yaz0, when flag=0 NP,pp ;Disp(Ppp)+1, Len(N)+2 ;/ NP,pp ;Disp(Ppp)+1, Len(N)+3 ;-LZSS, when flag=1 Dd ;Databyte(Dd) ;-When flag other than above |
if src has "LZ77" or "CMPR" prefix then src=src+4 ;skip prefix (if any)
typ=byte[src]
if typ=59h ;YAZ0
errif (bytes[src+0..3]<>"Yaz0") OR (bytes[src+8..15]<>0)
fin=dst+BigEndian(word[src+04h]), src=src+16
else ;LZSS/LZ11
fin=dst+(word[src]/100h), src=src+4
endif
@@collect_more:
flagbits=[src], src=src+1, numflags=8
if typ=59h then flagbits=flagbits XOR 0FFh ;-invert for YAZ0
@@decompress_lop:
if dst>=fin then goto @@decompress_done
if numflags=0 then goto @@collect_more
numflags=numflags-1, flagbits=flagbits*2
if (flagbits AND 100h)=0 then
[dst]=[src], dst=dst+1, src=src+1
else
if typ=10h ;LZ10 aka LZSS (BIOS SWI compatible)
len=3
len=len+[src]/10h, disp=001h+([src] AND 0Fh)*100h+[src+1], src=src+2
elseif typ=11h ;LZ11 (special extended format)
if [src]/10h>1 then len=001h
if [src]/10h<1 then len=011h+([src] AND 0Fh)*10h, src=src+1
if [src]/10h=1 then len=111h+([src] AND 0Fh)*1000h+[src+1]*10h, src=src+2
len=len+[src]/10h, disp=001h+([src] AND 0Fh)*100h+[src+1], src=src+2
elseif typ=59h ;YAZ0 (special extended format)
len=[src]/10h, disp=001h+([src] AND 0Fh)*100h+[src+1], src=src+2
if len=0 then len=[src]+12h, src=src+1, else len=len+02h
endif
for i=1 to len, [dst]=[dst-disp], dst=dst+1, next i
endif
goto @@decompress_lop
@@decompress_done:
ret
|
Extension is ".lz", ".lz77", ".LZ", or extension is preceeded by "_LZ." Less common extensions are ".l", ".lex", ".cmp" (and various others) Bytes[5..10] (after header+flags) contain IDs alike "NARC",FFFEh etc. File starts with "LZ77",10h or "CMPR",10h (both rather uncommon) |
Used for DSi Font (within TWLFontTable.dat) Used for 3DS .code files (within NCCH ExeFS filesystems) Used for files with .blz extension (eg. in DSi Flipnote, DSi Paper Plane) Used for ALZ1+LZrev double compression with .blz extension (eg. DSi Dr Mario) |
dest_size=src_size+[src+src_size-4] ;when dest_size is unknown (for 3DS)
allocate buf(dest_size), copy "src_size" bytes from file to buf
src=buf+src_size ;origin = pointing after footer
dst=src+(word[src-4])-1 ;dst = src plus extra len
fin=src-(word[src-8] AND 00FFFFFFh) ;fin = src minus compressed_len
src=src-(byte[src-5])-1 ;src = src minus footer_len
@@collect_more:
flagbits=[src], src=src-1, numflags=8
@@decompress_lop:
if src<=fin then goto @@decompress_done
if numflags=0 then goto @@collect_more
numflags=numflags-1, flagbits=flagbits*2
if (flagbits AND 100h)=0 then
[dst]=[src], dst=dst-1, src=src-1
else
len=([src]/10h)+3, disp=([src] AND 0Fh)*100h+([src-1])+3, src=src-2
for i=1 to len, [dst]=[dst+disp], dst=dst-1, next i
endif
goto @@decompress_lop
@@decompress_done:
ret
|
DSi Browser (rom:\skin\std_skin.zip) -- corrupted .zip (with 0D,0A appended) DSi Shop (rom:\skin\std_skin.zip) -- intact .zip (unlike above) 3DS Browser applet (RomFS:\browser\page\..\*.zip) |
| LZ Decompression Functions ASH0 |
collected[0]=80000000h ;stream 0 initially empty (endflag in bit31)
collected[1]=80000000h ;stream 1 initially empty (endflag in bit31)
src[0]=source+0 ;stream 0 start
for i=0 to 3, id[i]=read_bits(0,8), next i, if id[0..3]<>'ASH0' then error
dest_end=dest+read_bits(0,32) ;size of decompressed data
src[1]=source+read_bits(0,32) ;stream 1 start
load_huffman_tree(0,9) ;load stream 0 tree (9bit len/data values)
load_huffman_tree(1,11) ;load stream 1 tree (11bit disp values)
decompress_loop:
temp=0, while temp<8000h do temp=tree[0][temp+read_bits(0,1)]
if temp<8100h then
[dest]=temp AND FFh, dest=dest+1 ;store one uncompressed data byte
else
disp=0, while disp<8000h do disp=tree[1][disp+read_bits(1,1)]
len=temp+3-8100h, disp=disp+1-8000h
for j=1 to len, [dest]=[dest-disp], dest=dest+1, next j
if dest<dest_end then decompress_loop
ret
|
data=0
for i=1 to num
shl collected[s],1 ;move next bit to carry, or set zeroflag if empty
if zeroflag
collected[s]=[src[s]]*1000000h+[src[s]+1]*10000h+[src[s]+2]*100h+[src[s]+3]
src[s]=src[s]+4 ;read data in 32bit units, in reversed byte-order
carryflag=1 ;endbit
rcl collected[s],1 ;move bit31 to carry (and endbit to bit0)
rcl data,1 ;move carry to data
next i
ret(data)
|
stacktop=sp tree_index=0 load_lop: if getbits(0,1)=1 push tree_index+1 ;right (bit0=right) ;\ push tree_index ;left ; memorize left/right indices tree_index=tree_index+2 ; and load more goto load_lop ;/ dta=getbits(0,width)+8000h ;get data (bit15=data) resolve_lop: pop idx ;parent index tree[s][idx]=dta ;store data (or child_index) if (idx AND 1)=0 then goto load_lop ;load more (if it was left node) dta=idx-1 ;child_index (to be stored at next parent_index) if stacktop<>sp then goto resolve_lop ret |
tree[0] = about 200h*6 halfwords tree[1] = about 800h*6 halfwords |
| ZIP Decompression |
Local file headers, with file data Central directory, with file headers, and optional signature End of central directory record, with optional comment |
000h 4 local file header signature (04034B50h) ("PK",3,4)
004h 2 version needed to extract (os*256+major*10+minor) (common=14h=v2.0)
006h 2 general purpose bit flag (common=0)
008h 2 compression method (0=stored, 8=deflated, other=rare?)
00Ah 2 last mod file time
00Ch 2 last mod file date
00Eh 4 crc32 of uncompressed file data (zero when size=0)
012h 4 compressed size
016h 4 uncompressed size
01Ah 2 file name length
01Ch 2 extra field length
01Eh .. file name (or "folder/file" name)
... .. extra field
... .. compressed file data
|
000h 4 central file header signature (02014B50h) ("PK",1,2)
004h 2 version made by
006h 2 version needed to extract
008h 2 general purpose bit flag
00Ah 2 compression method (0=stored, 8=deflated, other=rare?)
00Ch 2 last mod file time
00Eh 2 last mod file date
010h 4 crc32 of uncompressed file data
014h 4 compressed size
018h 4 uncompressed size
01Ch 2 file name length
01Eh 2 extra field length
020h 2 file comment length
022h 2 disk number start
024h 2 internal file attributes
026h 4 external file attributes
02Ah 4 offset of local file header (from begin of disk number [022h])
02Eh .. file name (or "folder/file" name)
... .. extra field
... .. file comment (usually ASCII text, if any)
|
000h 4 header signature (05054B50h) ("PK",5,5)
004h 2 size of data
006h .. signature data (variable size, whatever crap)
|
000h 4 end of central dir signature (06054B50h) ("PK",5,6)
004h 2 number of this disk (usually 0000h)
006h 2 number of disk with the start of central directory
008h 2 total number of entries in the central directory on this disk
00Ah 2 total number of entries in the central directory
00Ch 4 size of the central directory
010h 4 offset of start of central directory, on disk number [006h]
014h 2 .ZIP file comment length (can be zero even if comment/junk follows)
016h .. .ZIP file comment (usually ASCII text, if any)
|
http://support.pkware.com/home/pkzip/developer-tools/appnote |
http://pkware.cachefly.net/webdocs/APPNOTE/APPNOTE-6.3.9.TXT ;July 2020 |
| Inflate - Core Functions |
tinf_init() ;init constants (needed to be done only once) tinf_align_src_to_byte_boundary() repeat bfinal=tinf_getbit() ;read final block flag (1 bit) btype=tinf_read_bits(2) ;read block type (2 bits) if btype=0 then tinf_inflate_uncompressed_block() if btype=1 then tinf_build_fixed_trees(), tinf_inflate_compressed_block() if btype=2 then tinf_decode_dynamic_trees(), tinf_inflate_compressed_block() if btype=3 then ERROR ;reserved until bfinal=1 tinf_align_src_to_byte_boundary() ret |
tinf_align_src_to_byte_boundary() len=LittleEndian16bit[src+0] ;get len if LittleEndian16bit[src+2]<>(len XOR FFFFh) then ERROR ;verify inverse len src=src+4 ;skip len values for i=0 to len-1, [dst]=[src], dst=dst+1, src=src+1, next i ;copy block ret |
repeat sym1=tinf_decode_symbol(tinf_len_tree) if sym1<256 [dst]=sym1, dst=dst+1 if sym1>256 len = tinf_read_bits(length_bits[sym1-257])+length_base[sym1-257] sym2 = tinf_decode_symbol(tinf_dist_tree) dist = tinf_read_bits(dist_bits[sym2])+dist_base[sym2] for i=0 to len-1, [dst]=[dst-dist], dst=dst+1, next i until sym1=256 ret |
sum=0, cur=0, len=0 repeat ;get more bits while code value is above sum cur=cur*2 + tinf_getbit() len=len+1 sum=sum+tree.table[len] cur=cur-tree.table[len] until cur<0 return tree.trans[sum+cur] |
val=0 for i=0 to num-1, val=val+(tinf_getbit() shl i), next i return val |
bit=tag AND 01h, tag=tag/2 if tag=00h then tag=[src], src=src+1, bit=tag AND 01h, tag=tag/2+80h return bit |
tag=01h ;empty/end-bit (discard any bits, align src to byte-boundary) ret |
| Inflate - Initialization & Tree Creation |
tinf_build_bits_base(length_bits, length_base, 4, 3) length_bits[28]=0, length_base[28]=258 tinf_build_bits_base(dist_bits, dist_base, 2, 1) ret |
for i=0 to 29 bits[i]=min(0,i-delta)/delta base[i]=base_val base_val=base_val+(1 shl bits[i]) ret |
for i=0 to 6, tinf_len_tree.table[i]=0, next i ;[0..6]=0 ;len tree... tinf_len_tree.table[7,8,9]=24,152,112 ;[7..9]=24,152,112 for i=0 to 23, tinf_len_tree.trans[i+0] =i+256, next i ;[0..23] =256..279 for i=0 to 143, tinf_len_tree.trans[i+24] =i+0, next i ;[24..167] =0..143 for i=0 to 7, tinf_len_tree.trans[i+168]=i+280, next i ;[168..175]=280..287 for i=0 to 111, tinf_len_tree.trans[i+176]=i+144, next i ;[176..287]=144..255 for i=0 to 4, tinf_dist_tree.table[i]=0, next i ;[0..4]=0,0,0,0,0 ;\dist tinf_dist_tree.table[5]=32 ;[5]=32 ; tree for i=0 to 31, tinf_dist_tree.trans[i]=i, next i ;[0..31]=0..31 ;/ ret |
hlit = tinf_read_bits(5)+257 ;get 5 bits HLIT (257-286) hdist = tinf_read_bits(5)+1 ;get 5 bits HDIST (1-32) hclen = tinf_read_bits(4)+4 ;get 4 bits HCLEN (4-19) for i=0 to 18, lengths[i]=0, next i for i=0 to hclen-1 ;read lengths for code length alphabet lengths[clcidx[i]]=tinf_read_bits(3) ;get 3 bits code length (0-7) tinf_build_tree(code_tree, lengths, 19) ;build code length tree for num=0 to hlit+hdist-1 ;decode code lengths for dynamic trees sym = tinf_decode_symbol(code_tree) len=1, val=sym ;default (for sym=0..15) if sym=16 then len=tinf_read_bits(2)+3, val=lengths[num-1] ;3..6 previous if sym=17 then len=tinf_read_bits(3)+3, val=0 ;3..10 zeroes if sym=18 then len=tinf_read_bits(7)+11, val=0 ;11..138 zeroes for i=1 to len, lengths[num]=val, num=num+1, next i tinf_build_tree(tinf_len_tree, 0, hlit) ;\build trees tinf_build_tree(tinf_dist_tree, 0+hlit, hdist) ;/ ret |
for i=0 to 15, tree.table[i]=0, next i ;clear code length count table ;scan symbol lengths, and sum code length counts... for i=0 to num-1, x=lengths[i+first], tree.table[x]=tree.table[x]+1, next i tree.table[0]=0 sum=0 ;compute offset table for distribution sort for i=0 to 15, offs[i]=sum, sum=sum+tree.table[i], next i for i=0 to num-1 ;create code to symbol xlat table (symbols sorted by code) x=lengths[i+first], if x<>0 then tree.trans[offs[x]]=i, offs[x]=offs[x]+1 next i ret |
clcidx[0..18] = 16,17,18,0,8,7,9,6,10,5,11,4,12,3,13,2,14,1,15 ;constants |
typedef struct TINF_TREE: unsigned short table[16] ;table of code length counts unsigned short trans[288] ;code to symbol translation table |
TINF_TREE tinf_len_tree ;length/symbol tree TINF_TREE tinf_dist_tree ;distance tree TINF_TREE code_tree ;temporary tree (for generating the dynamic trees) unsigned char lengths[288+32] ;temporary 288+32 x 8bit ;\for dynamic tree unsigned short offs[16] ;temporary 16 x 16bit ;/creation |
unsigned char length_bits[30] unsigned short length_base[30] unsigned char dist_bits[30] unsigned short dist_base[30] |
| Inflate - Headers and Checksums |
src_start=src, dst_start=dst ;memorize start addresses if (src[0]<>1fh or src[1]<>8Bh) then ERROR ;check id bytes if (src[2]<>08h) then ERROR ;check method is deflate flg=src[3] ;get flag byte if (flg AND 0E0h) then ERROR ;verify reserved bits src=src+10 ;skip base header if (flg AND 04h) then src=src+2+LittleEndian16bit[src] ;skip extra data if (flg AND 08h) then repeat, src=src+1, until [src-1]=00h ;skip file name if (flg AND 10h) then repeat, src=src+1, until [src-1]=00h ;skip file comment hcrc=(tinf_crc32(src_start, src-src_start) & 0000ffffh)) ;calc header crc if (flg AND 02h) then x=LittleEndian16bit[src], src=src+2 ;get header crc if (flg AND 02h) then if x<>hcrc then ERROR ;verify header tinf_uncompress(dst, destLen, src, src_start+sourceLen-src-8) ;----> inflate crc32=LittleEndian32bit[src], src=src+4 ;get crc32 of decompressed data dlen=LittleEndian32bit[src], src=src+4 ;get decompressed length if (dlen<>destLen) then ERROR ;verify dest len if (crc32<>tinf_crc32(dst_start,dlen)) then ERROR ;verify crc32 ret |
src_start=src, dst_start=dst ;memorize start addresses if (src[0]<>1fh or src[1]<>A1h) then ERROR ;check id bytes src=src+2 ;skip header tinf_uncompress(dst, destLen, src, sourceLen-0Ah) ;----> inflate crc32=LittleEndian32bit[src], src=src+4 ;get crc32 of decompressed data dlen=LittleEndian32bit[src], src=src+4 ;get decompressed length if (dlen<>destLen) then ERROR ;verify dest len if (crc32<>tinf_crc32(dst_start,dlen)) then ERROR ;verify crc32 ret |
src_start=src, dst_start=dst ;memorize start addresses hdr=BigEndian16bit[src], src=src+2 ;get header if (hdr MOD 31)<>0 then ERROR ;check header checksum (modulo) if (hdr AND 20h)>0 then ERROR ;check there is no preset dictionary if (hdr AND 0F00h)<>0800h then ERROR ;check method is deflate if (had AND 0F000h)>7000h then ERROR ;check window size is valid tinf_uncompress(dst, destLen, src, sourceLen-6) ;------> inflate chk=BigEndian32bit[src], src=src+4 ;get data checksum if src-src_start<>sourceLen then ERROR ;verify src len if dst-dst_start<>destLen then ERROR ;verify dst len if a32<>tinf_adler32(dst_start,destLen)) then ERROR ;verify data checksum ret |
s1=1, s2=0 while (length>0) k=max(length,5552) ;max length for avoiding 32bit overflow before mod for i=0 to k-1, s1=s1+[src], s2=s2+s1, src=src+1, next i s1=s1 mod 65521, s2=s2 mod 65521, length=length-k return (s2*10000h+s1) |
| PNG Bitmaps |
000h 8 ID (89h,'PNG',0Dh,0Ah,1Ah,0Ah) 008h .. Chunks |
000h 4 Chunk Size (LEN) ;big-endian
004h 4 Chunk ID (4-letter ASCII) ("A..Z" and "a..z")
008h LEN Chunk Data
... 4 Chunk CRC32 on [004h+(0..LEN+3)] ;big-endian
|
1st char Uppercase=Critical (Basic) Lowercase=Ancillary (Optional extras) 2nd char Uppercase=Public (Official) Lowercase=Private (Custom extensions) 3rd char Uppercase=Normal Lowercase=Reserved 4th char Uppercase=Unsafe to copy Lowercase=Safe to copy |
IHDR v1.0 Image header (first chunk) ;\ PLTE v1.0 Palette (if any) ; Critical chunks IDAT v1.0 Image data (can be multiple IDAT chunks!) ; (aka the bitmap data) IEND v1.0 Image trailer (last chunk) ;/ tRNS v1.0 Transparency ;-Transparency cHRM v1.0 Primary chromaticities and white point ;\ gAMA v1.0 Image gamma ; iCCP v1.1 Embedded ICC profile ; Colour space info sBIT v1.0 Significant bits ; sRGB v1.1 Standard RGB colour space ; cICP v3rd Coding-independent code points ;/ bKGD v1.0 Background colour ;\ hIST v1.0 Image histogram ; pHYs v1.0 Physical pixel dimensions ; Miscellaneous info sPLT v1.1 Suggested palette ; eXIf v3rd EXIF chunk (starts with "MM"=byteorder) ;/ tEXt v1.0 Textual data ;\Textual information zTXt v1.0 Compressed textual data ; (aka comments) iTXt v1.2 International textual data ;/ tIME v1.0 Image last-modification time ;-Time stamp acTL v3rd Animation Control Chunk ;\ fcTL v3rd Frame Control Chunk ; Animation (APNG) fdAT v3rd Frame Data Chunk ;/ |
000h 4 Chunk Size (always 0Dh) ;big-endian
004h 4 Chunk ID ("IHDR")
008h 4 Width in pixels (0=invalid) ;big-endian
00Ch 4 Height in pixels (0=invalid) ;big-endian
010h 1 Bits per sample (1,2,4,8,16) (allowed values depend on Color Type)
011h 1 Color Type (0,2,3,4,6)
012h 1 Compression method (always 0=Zlib-Deflate)
013h 1 Filter method (always 0=Adaptive; with subtype per line)
014h 1 Interlace method (0=None, 1=Adam7)
015h 4 Chunk CRC32 on [004h..] ;big-endian
|
Color type (Samples) Bits/sample Bits/pixel 0=Grayscale (I) 1,2,4,8,16 --> 1,2,4,8,16 2=Truecolor (RGB) 8,16 --> 24,48 3=Palette indices (I) 1,2,4,8 --> 1,2,4,8 4=Grayscale with alpha (IA) 8,16 --> 16,32 6=Truecolor with alpha (RGBA) 8,16 --> 32,64 |
000h 4 Chunk Size (LEN=NumColors*3) (3..300h) ;big-endian
004h 4 Chunk ID ("PLTE")
008h LEN Palette Data (three bytes per color, ordered R,G,B)
... 4 Chunk CRC32 on [004h+(0..LEN+3)] ;big-endian
|
000h 4 Chunk Size (LEN) ;big-endian
004h 4 Chunk ID ("IDAT")
008h LEN Zlib-Deflate compressed image data
... 4 Chunk CRC32 on [004h+(0..LEN+3)] ;big-endian
|
000h 4 Chunk Size (0) ;big-endian
004h 4 Chunk ID ("IEND")
008h 4 Chunk CRC32 on [004h..007h] (always AE426082h) ;big-endian
|
_________________ Decompression, Unfiltering, Deinterlacing __________________ |
000h 1 zlib compression method/flags code (usually 78h) 001h 1 Additional flags/check bits (usually 9Ch) (or DAh) 002h .. Compressed data blocks (deflate) ... 4 Adler32 checksum on decompressed data ;big-endian |
decompressed_size = ((width*bpp+7)/8+1)*height |
for pass=1 to num_passes ;for 7-pass interlacing
calc width/height for current pass
for x=1 to (bpp+7)/8 + (width*bpp+7)/8
byte[dst]=00h, dst=dst+1 ;-pad topmost for unfiltering
for y=1 to height
filter = byte[src], src=src+1
for x=1 to (bpp+7)/8
byte[dst]=00h, dst=dst+1 ;-pad leftmost for unfiltering
for x=1 to (width*bpp+7)/8
left = byte[dst-(bpp+7)/8]
upper = byte[dst-bytes_per_scanline]
upperleft = byte[dst-bytes_per_scanline-(bpp+7)/8]
if filter=0 then byte[dst]=byte[src]
if filter=1 then byte[dst]=byte[src]+left
if filter=2 then byte[dst]=byte[src]+upper
if filter=3 then byte[dst]=byte[src]+(left+upper)/2
if filter=4 then
pa=abs(upper-upperleft)
pb=abs(left-upperleft)
pc=abs(left+upper-(upperleft*2))
if pa<=pb AND pa<=pc then byte[dst]=byte[src]+left
elseif pb<=pc then byte[dst]=byte[src]+upper
else byte[dst]=byte[src]+upperleft
if filter>4 then error
src=src+1, dst=dst+1
next x
|