Samsung YP-R0 Port Page
This port is intended to make rockbox work as an "hybrid" application, that runs on linux, but must control lot's of HW parameters by itself >
- CPU - ARM IMX37_Apollo (532MHz ARM1176JZF?-S core)
- Linux Kernel 2.6.24-2.4.2 - base (Opensource tools available : http://opensource.samsung.com/ punch in "YP-R0" in search bar!)
- Firmware Encrypted 4 Parts: MBoot,Linux,RootFS,Sysdata each encrypted and output from MounEncrypt? >> into R0.ROM, MD5 Checksum created before Encryption -> now makes sense when installing new Firmware -> Checking needs time to decrypt, decompress, split and then check md5
- Player uses Whimory FTL (according to WhimoryFTL it may be version 2.2.1)
- Uses ALSA (so for audio data management we exploit it, for audio volume control we need to make as3543 work.)
- 64 MB of RAM -> about 32 free after kernel is loaded -> plenty of space for RB
- CPU frequencies (200 MHz - 400 MHz - 532 MHz easily selectable using kernel's cpufreq)
- AS3543 audio codec
- SI4709 radio device
- SC900776 "minivet device" -> controls accessories/usb/recovery mode(to be used with non-public samsung tools)
- Partitions mounted: /mnt/media0 -> 4/8/16 GB user storage; /mnt/media1 -> about 64 mb, to store settings and modded sysdata; /mnt/mmc -> mount point for SD card
- Other interesting block devices -> /dev/stl1, contains region code, RTC time diff, and other things. Should be even usable for most of the space (lot isn't used by R0 application)
- IMX37 has both VPU and IPU, for decoding and manipulating videos and images respectively.
For other informations, just wait I'll copy from my piratenpad page (lots of info)
The current code can be found on Flyspray. It's basically very stable and ready for an initial commit: http://www.rockbox.org/tracker/task/12348
To compile, you need a complete arm-linux gcc toolchain. You can build it using rockboxdev.sh (takes a looong time, since glibc needs to be build as well).
|| Standard Linux framebuffer device. ~1200 FPS fullscreen
|| Works fine so far. Explore the possibility of LCD sleep during backlight off to save power
|| Keymap needs some love, but is largely OK. Multiple keypresses through GPIO module are working fine.
|| Playback seems to work rather flawlessy audio-driver wise (using standard alsalib). Volume handling is seperately implemented since alsalib doesnt offer this. For this we directly communicate with the as3543 audio codec. The same driver that SansaAMS uses is used, through ascodec API.
| FM Radio
|| FM Radio is supported using a custom kernel module. RDS is not yet implemented.
| Power Management
|| Charging, voltage readout and charger status are working. We save power by using the ondemand cpu governor the Linux kernel provides. Runtime is about 25 hrs. Space for improvements?
|| We provide a early/safe USB mode in the patched firmware so the OF isn't needed. However there's no USB cable detection in Rockbox yet. Also, doing USB from within Rockbox is desirable to avoid reboots. Special care is needed to close open files before we make a connection, since the USB device cannot be exposed with open handles.
|| Storage handled by Linux. However, we need to mount the sdcard ourself (TODO)
|| All plugins should work and have a keymap. But some actually don't.
(Right-click, View Image for a more detailed resolution)
You can find here a nice tutorial: http://www.anythingbutipod.com/forum/showthread.php?t=64397
[thanks to lebellium]
) you can find the RockBox
porting thread and the modded firmware.
[If that's spam/issue, just remove the link even without saying me that
This player is based on linux. So, let's have a quick look at what is done at startup. When you turn the device on, MBoot (the bootloader) pushes some raw data to the screen: the Samsung logo. This can be easily found in the mboot binary. It's raw data. Then, linux kernel is loaded with the following parameters
noinitrd console=ttymxc0 root=/dev/bml2 rw rootfstype=cramfs
As you can see, ttymxc0 is the UART console (on IMX37) and /dev/bml2 is the block device that contains the cramfs (with all linux stuff + OF application executable and libs)
Once kernel is loaded, some Samsung modules are loaded, such as keypad handler and so on, and then application is launch.
MBoot has another important task: if R0.ROM is copied in the nand (precisely /dev/stl3 mounted as /mnt/media0), then the update process is started.
It consists in a firmware checking stage (where CRC's are checked; lebellium told me if that fails device is anyway bricked because R0.ROM is not deleted :S) and then the real flashing.
I still don't know how this flashing works but basically is a raw copy from the decrypted rom data to the storages.
Firmware is composed by:
- MBoot: bootloader, manages startup + device update and launches kernel
- zImage: compressed (or as I tested, also uncompressed) kernel image
- cramfs-fsl: image of a normal cramfs filesystem. Easy to unpack and repack through linux.
- SysData: contains resources stuff for OF application. It is mounted at /mnt/media1/Sysdata. If you extract it using a tool developed by user, you are able to see the content, modify it and repack it once again. Through safe mode of my modded firmware you can copy this content directly to media1/sysdata editing it in this folder. New resources will load instead of the "flashed" one
Software related interesting facts
Samsung uses a filesystem layer: RFS. Documentation is public available, source not but I found them on a chinese site hehe link: http://dl.dropbox.com/u/38710278/904147731rfs_fs.zip
Link about RFS used by the player: http://www.samsung.com/global/business/semiconductor/products/flash/downloads/RFS_130_Porting_Guide.pdf
Setting cpu to 200 MHz, using default application you will hear scratches while playing WITH backlight off. Interesting is that, if you set the backlight to stay on and you create a script that manages it instead of the OF app, you will not hear these scratches, thus:
- There is a low power mode somewhere
- Screen sleep produces that
Original software is full of bugs everywhere
Basically without Samsung tools there is nothing to do.
I could do a usb sniffing while flashing the firmware, but I have no clue how to do it and moreover I use to flash it through VirtualBox?
'ed windows xp as my host machine has linux.
(to be completed with information about original tool + using freescale tool + necessary samsung files + cable with resistor)
TODOs and ideas
- Power management: we have AS3543 codec and battery voltage is read through it's ADC device. So should be quite easy to use the already written driver for other devices...
- Full charge is done at about 4.200 V w. cable inserted
- Full charge is done at about 4.150 V w/o cable inserted
- OF shuts down at 3.450 volts
- Radio: RDS is still to be implemented.
- USB: easy to make a connection using kernel tools. Easy to detect if cable is inserted or not (using minird program from a script, implementing them throug ioctls in rockbox, /dev/minivet, source for it are available in kernel). Also if only charger cable is inserted is easy to understand. Basically reading a particular register of this device (0xa) , you get a numeric value that identifies if a charger, usb cable, etc is connected
- SD CARD: implement a way of controlling SD card mount/unmount, considering caching (hot swap)
- using Samsung Opensource Tools, able to create new R0.ROM BOTH encryption and decryption are working
- stuck on Bootloader: MBoot.bin is needed which gives me troubles to integrate a different bootloader
- drivers for Player should all be there
- Final Problem: Bootloader - best would be to reverse engineer Encryption to get the original content of R0.ROM (v1.10) and work with this version as its most stable. Opensource Kit from Samsung ships with YP-R1 ROM which differs from R0
- I was able to decrypt firmware again its basically XOR, thanks to JeanLouis? which was restated at http://anythingbutipod.com/forum/showthread.php?t=54481&page=2 -> Next Step is to poke around until I am able to share rootfs and all other partions with USB (is done in the modded firmware - "Safe Mode")
- RootFS? partion is now mountable unfortunately not what I expected but still something to look into
- SysData.bin: there is a packer/unpacker. Cmd line version is both linux/windows. GUI version is unfortunately only for windowds, but that's not an issue, as we can mod it on the fly using "Safe Mode"
- MBoot.bin looks promising in Hexeditor
- it should be possible to abuse Mboot.bin to boot rockbox, I will compile with the hardware i already know, create a zImage as well es cramfs which is mandetory if we use regular firmware check and build a new firmware cloaked as Samsungs Firmware this means loss of original firmware
- Some plugins, especially after sdl removal, crash.
Copyright © by the contributing authors.