---+!! !SigmaTel STMP3xxx %TOC% --- ---++ Introduction The !SigmaTel STMP3xxx series is a somewhat popular System-on-a-Chip solution for portable audio players. They include CPU, on chip RAM and ROM, I/O to external storage devices, display, and buttons, USB interface, ADC and DAC, headphone amplifier, and a battery management interface. The major !SigmaTel STMP3xxx series can be devided into the STMP34xx, STMP35xx, and STMP36xx series. The STMP35xx series is backward pin and firmware compatible with STMP3410. The STMP36xx series is based on a different CPU. --- ---++ STMP3400 * Samsung YP-55 > STMP3400 - [[http://www.anythingbutipod.com/forum/showthread.php?t=32690][Firmware updates]] * Rio Nitrus > STMP3400 * Rio Sport S30s/S35s > !STMP3411L * iAudio4 > STMP3400 * Philips Rush SA230 > !STMP3411L - [[http://www.p4c.philips.com/cgi-bin/dcbint/cpindex.pl?scy=DE&slg=ENG&sct=FLASH_AUDIO_PLAYERS_SU&cat=MP3_PLAYERS_CA&grp=PORTABLE_ENTERTAINMENT_GR&ctn=SA230/00C&mid=Link_Software&hlt=Link_Software][Firmware updater]] --- ---++ STMP3500 * MPMan CS157 > STMP3504 * iPod Shuffle > STMP3550 - IpodShuffle * iAudio i5, G2, G3, U2, F1 > STMP3520 * Cenix CMP-M5 > STMP3507 * Creative !MuVo >STMP3520 - [[http://localize-it.narod.ru/errors.htm][Useful page]], [[http://localize-it.narod.ru/download.htm][Firmware archive]] * Creative Zen Nano >STMP3520 * Creative Zen Stone > STMP3550 * Dyne Tuny 11 (AKA Trekstor i.Beat p!nk ) > !STMP35XX * Jingwah Digital JWM62 > STMP3505 - [[http://www.semicon.blue-nut.com/resources/mp3_jwd62/mp3_jwd62.html][Teardown]] * Philips SA 177+ SA1100 +SA1300s + SA1200 > !STMP35XX * Philips !GoGear SA 31XX + 41XX + 51XX > !STMP35XX - PhilipsGoGear3100Port * Samsung YP-53 +YP-T6 > !STMP35XX - [[http://www.anythingbutipod.com/forum/showthread.php?t=32690][Firmware updates]] * Samsung YP-U1 +YP-F1 > STMP3550 - [[http://www.anythingbutipod.com/forum/showthread.php?t=32690][Firmware updates]] * Samsung YP-U2 +YP-F2 > STMP3550 - [[http://www.anythingbutipod.com/forum/showthread.php?t=32690][Firmware updates]] * !RioForge , Rio Carbon > !STMP35XX * !SanDisk Sansa e130/e140 > !STMP35XX - [[http://www.sandisk.com/Retail/Default.aspx?CatID=1295][Firmware updater]] * Packard Bell Vibe 360 > !STMP35XX * Rover Aria M1 (MSI Megaplayer 533) > !STMP35XX - [[http://184.108.40.206/translate_c?hl=en&sl=ru&tl=en&u=http://home.tula.net/nickit/rover.htm&usg=ALkJrhhijO8JN0iOaMXqfeFmuKVU6wyWqw][An attempt by some Russians to write custom code for it]] * iBead 400 (AKA Trekstor i.Beat organix) + iBead 600 (AKA Trekstor i.Beat sweez) >STMP3520 - TrekStorIBeatOrganixFM * Median Mcody MX300, MX700 > STMP3520 * Median Mcody M20, M22, M25 > STMP3507 * Median Mcody M30 (AKA Trekstor i.Beat Blaxx ) > STMP3507 * Meizu X2, E2 (AKA Emgeton E2 Cult) > STMP3520 * Mobiblu DAH-1500i > STMP3520 - MobibluPort * Gigabeat P > !STMP35XX - [[http://www.gigabeat.net/mobileav/audio/soft/inf_gbP_fw3020.htm][Firmware updater]] [[http://www.rockbox.org/twiki/pub/Main/DataSheets/stmp35xx-ds-1-03.pdf][Data sheet]]<br /> [[http://www.sigmatel.com/products/portable/audio/stmp3500.aspx][Product Briefing]]<br /> [[http://www.rockbox.org/twiki/pub/Main/HardwareSchematics/stmp3500_reference_sch_revb.pdf][STMP35XX Reference Schematics]] ---+++ Motorola DSP56004 The STMP3400/500 specifications state that the embedded DSP chip is "DSP56004-compatible", however, it is unclear whether additional instructions have been introduced. Porting Rockbox to an architecture whose smallest addressable unit is 24 bits with inadequate compilers is going to be painful at best. Luckily, information on the chip series is very easy to come by -- more than enough to write or port a new compiler. For more information, see MotorolaDSP56k. --- ---++ STMP3600 Features: * The main core seems to be an !ARM962EJ-S running at ~200Mhz. * Sigmatel provides a SDK to their customers, probably with example code. * Probably, the Media engine provides hardware accelerated video processing? Devices using this chipset: * Samsung YP-Z5 > STMP 3650 - SamsungZ5 * Creative Zen V / Zen V Plus > !STMP36xx - CreativeZenV * Trekstor Vibez > STMP3650 - [[http://www.trekstor.de/en/products/detail_mp3.php?pid=66&page=6][Firmware update]] * IXINg (Technonia) TM-S4 + IXINg Duo > STMP3650 * Siren IV Edge > !STMP36XX * Maxfield G-Flash NG > !STMP36XX - http://www.maxfield.de/index.php?id=16&tx_maxproductslist_pi1[pro_uid]=131&L=0 (Product page with firmware downloads) * Maxfield Max-Ivy > !STMP3660 * RAmos RM-650 > STMP3650 * Sandisk Sansa Express > STMP3630 - SansaExpress * Yuraku Yur.Beat Fusion Stream > !STMP36XX - [[http://www.yuraku.de/downloads/manuals/YurBeatFusionStream%20manual.pdf][Manual]]. They actually used the Wi-Fi capabilities of the chip. * Matsui !MAT140MR > STMP3630 - [[http://forums.cnet.com/5208-7595_102-0.html?forumID=71&threadID=266906&messageID=2600315][Reference]] * Memorex MMP9008 (8gb Video Player) * Baylis EPMX72 Revolution > STMP3638 [[https://www.dropbox.com/s/i5q5dg16kl93pre/linuxbsp-stmp36xx-kernel-20060601-375.tar.gz][STMP36xx Linux BSP]]<br /> [[http://www.sigmatel.com/products/portable/audio/stmp3600.aspx][Product Briefing]] ([[http://www.sigmatel.com/documents/3600-ProductBrief.pdf][PDF]]) [[http://zoobab.wikidot.com/local--files/stmp36xx/stmp36xx-Datasheet-1-02_050306.pdf][external link: STMP36XX Datasheet (PDF)]] [[%ATTACHURL%/stmp36xx-Datasheet-1-02_050306.pdf][stmp36xx-Datasheet-1-02_050306.pdf]] See STMP37xxChips --- ---++ STMP3700 Note: Sigmatel has been bought by Freescale in 2008 and SoCs older than STMP3700 are now discontinued. Features: * The main core seems to be an !ARM962EJ-S running at ~300Mhz. * The (normal) Media engine is absent (compared to STMP36xx), but there's a DCP (which does Color-Space Conversion) and a Media engine 2006. Devices using this chipset: * Creative ZEN > STMP3760 - CreativeZEN * RAmos V7 > STMP 3710 * Teclast X19 > STMP 3710 (@206MHz) * AOC V9 > STMP 3710 (@206MHz) * Sansa Fuze+ > STMP3780 - SansaFuzePlus * Creative ZEN X-Fi > STMP3770 - CreativeZENXFi * Creative ZEN X-Fi2 > STMP3780 - CreativeZENXFi2 * Creative ZEN Style M300 > STMP3770 - CreativeZENStyleM300 * Creative ZEN X-Fi3 > STMP3780 - CreativeZENXFi3 * Creative ZEN X-Fi Style > STMP3780 * Creative ZEN Mozaic > STMP3700 * Kenwood MG-G708 > STMP3770(?) + WM8912G * Kenwood MG-G608 > STMP3770(?) + WM8904(?) * Kenwood MG-G508 > STMP3770 * Kenwood MG-F5xx (F504\F508\F516) > STMP3770 * Kenwood MG-E50x (E502\E504) > STMP3770 * Samsung YP-Q2 > STMP3750 * Samsung YP-S1 > STMP3770 * Samsung YP-U5 > STMP3770 * Samsung YP-U6 > STMP3770 * iRiver E30 > STMP3770 * iRiver E40 > STMP3770 * iRiver E50 > STMP3770 [[http://www.freescale.com/webapp/sps/site/prod_summary.jsp?code=STMP3700][Product Briefing]] ([[http://www.freescale.com/files/32bit/doc/fact_sheet/STMP3700FS.pdf?fpsp=1&WT_TYPE=Fact%20Sheets&WT_VENDOR=FREESCALE&WT_FILE_FORMAT=pdf&WT_ASSET=Documentation][PDF]])%BR% [[http://www.freescale.com/files/32bit/doc/white_paper/BPMPSTMP3700WP.pdf?fpsp=1&WT_TYPE=White%20Papers&WT_VENDOR=FREESCALE&WT_FILE_FORMAT=pdf&WT_ASSET=Documentation][White paper]]%BR% [[http://www.freescale.com/files/32bit/doc/support_info/STMPFAMCOMPTBL.pdf][STMP37xx family comparison table]] See STMP37xxChips --- ---++ Firmware !SigmaTel is offering an SDK for these series of chips for $12,000. The SDK includes full source code to a reference implementation MP3 player. It is unclear how many MP3 player firmwares are directly based on this SDK, but there is evidence of similarity. For example, the SDK includes implementations of MP3 and WMV decoders, which most STMP3-powered players exclusively support. The document "Customizing Flash Players Using !SigmaTel SDK 2.4xx" is available [[http://www.rockbox.org/twiki/pub/Main/DataSheets/Customizing_Flash_Players_Using_SigmaTel_SDK2.4.XX.pdf][here]]. [[http://www.epc.com.cn/meeting/resource/2007consumer/pdf/SigmaTel.pdf][This document]] contains a brief outline of the SDK versioning. ---+++ STMP3400 - SDK v? The firmware updater of the Philips Rush SA230 player includes an unencrypted/unsigned binary firmware image; additionally, the updater boots off of USB before writing any flash, making this a safe environment for hacking and testing on real hardware. * booty.s * dcc.s * resource.bin * stmpsys.s * usbmsc.s ---+++ STMP3500 - SDK v2.4 - v3.2 * bootmanager.sb - This file is a Loader, which code will determine if USB device is connected and load the appropriate Firmware into RAM. It is not loaded during recovery mode. After bootmanager.sb loads the Firmware into RAM it jumps to the reset vector. All code that is loaded by bootmanager.sb, must have a valid reset vector in order to startup. If not, Firmware update could be successful in terms of proper installation process and its integrity, but device will not work. * usbmsc.sb - This file is loaded by bootmanager.sb when device is connected at startup. This file contains only the software that interfaces to the native USB Mass Storage drivers on the OS. The usbmsc.sb firmware uses SCSI commands. It operates at the device sector level and does not contain a file system or have any knowledge about files being transferred. * resource.bin - This file contains all code/data overlays, bitmaps used in user’s interface (e.g. shown on display) and fonts, which are stored in bitmap format as well. Resources loaded into RAM as needed during player operation by !SysLoadResource (system code contained in stmpsys.sb). * stmpsys.sb - The file is loaded by bootmanager.sb when USB device is not connected at startup. This is actually the player itself, as it contains all system code used by the player. System code is considered to be all functions resident in static memory (not overlays). When USB device is connected during player operation, the device is reset and bootmanager.sb loads usbmsc.sb from flash if USB is still connected when bootmanager.sb executes. * hostlink.sb - Reportedly, the purpose of this is to change the device from a USB Host to a Host Link, in an attempt to block users from sharing files over USB OTG connections. See [[http://translate.google.com/translate?hl=en&sl=zh-CN&u=http://www.imp3.net/article/article.php%3Farticleid%3D8209&sa=X&oi=translate&resnum=7&ct=result&prev=/search%3Fq%3Dhostlink.sb%26start%3D10%26hl%3Den%26safe%3Doff%26sa%3DN][here]]. The next file, hostsrc.bin, is presumably related to this. * hostsrc.bin * updater.sb *Note:* Much of the above info was taken from [[http://localize-it.narod.ru/firmware.htm][here]]. The ROM of the STMP3500 contains code to recover the player if no valid firmware is installed on the device (this is also used to initially flash the products in manufacturing). In order to do this, the player must be restarted in recovery mode while connected through USB to a computer with the recovery driver installed (!StMp3Rec.sys). The ROM will then connect to the driver and load the file usbmsc.sb off of the computer and onto the player. From there, the player will restart running only usbmsc.sb. The player will subsequently be recognized as a mass storage device, and all of the remaining firmware files (resource.bin, etc...) can be loaded using stupdaterapp.exe. To make a long story short, it's impossible to brick your stmp35xx device unless you physically break it. Note: To start player in recovery mode, press the reset button while holding the play button. Let go of reset, but continue holding play for at least 5 seconds. Your computer will then make that "something's been connected" sound, and if the recovery driver is installed, usbmsc.sb will automatically be loaded onto the player (provided it can be found in its respective directory on the computer). ---+++ STMP3600 - SDK v4.xx * bootmanager.sb * hostlink.rsc * hostlink.sb * player.rsc * player.sb * stmfgmsc.sb * updater.sb ---+++ Creative ZEN Series Creative used their own firmware format for the ZEN series. Information about the Creative ZEN Vision:M is available at [[CreativeZVMPort]]. --- ---++ Recovery Mode There seems to be a standardized recovery mode in these chips. The =StMp3Rec.sys= file is a "Recovery Player Class Device" driver and will connect the player by it's chip name. --- ---++ Links * [[http://www.mympxplayer.org/sigmatel-recovery-guide-updated-vt8150.html][Sigmatel recovery guide]] * [[http://www.mympxplayer.org/here-df195.html][Sigmatel firmware extractor]] * [[http://www.htelephones.co.uk/repair/sigmatel/sigmatel.htm][A strange guide and software for the MAT140MR]] * [[http://www.oasissemi.com/documents/Q22007GuideC.pdf][An interesting doc comparing the capabilities of 3500/3600]] ---
14 May 2010 - 17:03
ore topic actions
r57 - 20 Mar 2014 - 11:04:25 -
Copyright © by the contributing authors.