{"id":3149,"date":"2012-01-13T19:19:01","date_gmt":"2012-01-14T00:19:01","guid":{"rendered":"https:\/\/example.com\/?postname=chinese-wonder-pun"},"modified":"2012-01-13T19:19:01","modified_gmt":"2012-01-14T00:19:01","slug":"chinese-wonder-pun","status":"publish","type":"post","link":"http:\/\/atomsofttech.com\/blog\/uncategorized\/chinese-wonder-pun\/","title":{"rendered":"Chinese Wonder* (pun)"},"content":{"rendered":"<p><a href=\"http:\/\/atomsoft.wordpress.com\/wp-content\/uploads\/2012\/01\/lap11.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1757\" title=\"LAP1\" src=\"http:\/\/atomsoft.wordpress.com\/wp-content\/uploads\/2012\/01\/lap11.jpg\" alt=\"\" width=\"627\" height=\"470\" srcset=\"http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap11.jpg 800w, http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap11-300x225.jpg 300w, http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap11-768x576.jpg 768w\" sizes=\"auto, (max-width: 627px) 100vw, 627px\" \/><\/a><\/p>\n<p>Ok i have one of those tiny 7 inch laptops which has a ARM and WinCE\/Android running on it..<\/p>\n<p>While this is pretty cool to have i have no use for it. Unless i start learning how to program for android. Which i will not even get into. The cool thing i like about this laptop is the 7in LCD and the fact it has a mouse and keyboard built in. I would love to be able to use this for something other than what it has.<\/p>\n<p>This so called PC uses a WM8505 Processor which in it self is quite hard to find good info on..<\/p>\n<p><a href=\"http:\/\/atomsoft.wordpress.com\/wp-content\/uploads\/2012\/01\/lap21.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1756\" title=\"lap2\" src=\"http:\/\/atomsoft.wordpress.com\/wp-content\/uploads\/2012\/01\/lap21.jpg\" alt=\"\" width=\"627\" height=\"510\" srcset=\"http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap21.jpg 800w, http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap21-300x244.jpg 300w, http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap21-768x625.jpg 768w\" sizes=\"auto, (max-width: 627px) 100vw, 627px\" \/><\/a><\/p>\n<p>Here are some specs on my model:<\/p>\n<p><strong>Max Resolution:<\/strong> 800 x 480 px<br \/>\n<strong> OS Language:<\/strong> English<br \/>\n<strong> Operating System:<\/strong> Windows CE 6.0 or Android<br \/>\n<strong> CPU:<\/strong> ARM-WM8505 or VIA VT8505( ARM926EJ-S)<br \/>\n<strong> Chipset:<\/strong> WM8505<br \/>\n<strong> Memory:<\/strong> 128 MB<br \/>\n<strong> Flash Disk:<\/strong> 2GB Built-in<br \/>\n<strong> External Memory:<\/strong> SD\/MMC card (16GB Max.)<br \/>\n<strong> LAN:<\/strong> RJ45, 10\/100Mbps<br \/>\n<strong> WLAN:<\/strong> 802.11b\/g Wifi \/ Wireless LAN<br \/>\n<strong> Speaker:<\/strong> Internal Speaker x 2<br \/>\n<strong> Touchpad:<\/strong> Yes<br \/>\n<strong> Keyboard:<\/strong> 80-key keyboard<br \/>\n<strong> Ports:<\/strong><br \/>\n2 * USB External<br \/>\n1 * USB Internal<br \/>\n1 * RJ45 LAN<br \/>\n1 * 3.5mm Microphone<br \/>\n1 * 3.5mm Headphone<br \/>\n1 * SD\/MMC card slot<\/p>\n<p>Now for the GOOD the BAD and the UGLY!<\/p>\n<p>The Good&#8230; The main board has a UART port on it and i am able to get valuable information from it. I can even access a terminal on it.<\/p>\n<p><a href=\"http:\/\/atomsoft.wordpress.com\/wp-content\/uploads\/2012\/01\/lap3.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1760\" title=\"lap3\" src=\"http:\/\/atomsoft.wordpress.com\/wp-content\/uploads\/2012\/01\/lap3.jpg\" alt=\"\" width=\"569\" height=\"266\" srcset=\"http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap3.jpg 569w, http:\/\/atomsofttech.com\/blog\/wp-content\/uploads\/2012\/01\/lap3-300x140.jpg 300w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/a><\/p>\n<p>Here is what i get on boot:<\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"638\">\n<pre><strong>WonderMedia Technologies, Inc. W-Load Version : 0.17.00.00 ethaddr............found U-Boot 1.1.4 (Apr\u00a0 1 2010 - 16:26:54) WonderMedia Technologies, Inc. WMT U-Boot Version : 0.12.01.00.14 U-Boot code: 03F80000 -&gt; 03FB9294\u00a0 BSS: -&gt; 040076AC RAM Configuration: Bank #0: 00000000 128 MB boot from spi flash. flash: \u00a0\u00a0\u00a0\u00a0 Bank1: FFF80000 -- FFFFFFFF \u00a0\u00a0\u00a0\u00a0 Bank2: FF780000 -- FFF7FFFF Flash:\u00a0 8.5 MB In:\u00a0\u00a0\u00a0 serial Out:\u00a0\u00a0 serial Err:\u00a0\u00a0 serial ### main_loop entered: bootdelay=1 bootcmd=\"nand read 3c00000 12f00000 100000;logo show;run text1\" CE0: NAND FLASH ID: 0xECD514B6 CE0: NAND FLASH Name: SAMSUNG_K9XXG08UXM (2048 MB) block4095 tag=74624230\u00a0 version =1 block4094 tag=62743142\u00a0 version =1 g_nfinfo[0].id = 0xE, g_nfinfo[1].id = 0xFFFF Read finsih show logo ..... LCD param (setting): 1,30000,8,800,480,48,40,40,3,29,13 PWM param (setting): 0,4,599,599 LCD FrameBuffer = 0x07900000, BMP Address = 0x03C00000 Loading BMP ..... ok no string .... PWM0 input freq = 47916666 Hz, output freq = 19998 Hz PWM0 register setting: scalar = 3, period = 598, duty = 598 \"V1.5.2\" Execute register operation: \u00a0 reg op: 0xD8110064 | 0xC \u00a0 reg op: 0xD811008C | 0xC \u00a0 reg op: 0xD81100B4 &amp; 0xFFFFFFFB \u00a0 reg op: 0xD81100B4 | 0x8 \u00a0 reg op: 0xD8130054 | 0x1 ### main_loop: bootcmd=\"nand read 0 0 300000;bootm 0\" Hit any key to stop autoboot:\u00a0 0 WMT # <\/strong><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>When I type help this is what i get:<\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"638\">\n<pre><strong>WMT # help<\/strong>\n<strong>?\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 - alias for 'help'<\/strong>\n<strong>autoscr - run script from memory<\/strong>\n<strong>base\u00a0\u00a0\u00a0 - print or set address offset<\/strong>\n<strong>bdinfo\u00a0 - print Board Info structure<\/strong>\n<strong>boot\u00a0\u00a0\u00a0 - boot default, i.e., run 'bootcmd'<\/strong>\n<strong>bootd\u00a0\u00a0 - boot default, i.e., run 'bootcmd'<\/strong>\n<strong>bootm\u00a0\u00a0 - boot application image from memory<\/strong>\n<strong>bootp\u00a0\u00a0 - boot image via network using BootP\/TFTP protocol<\/strong>\n<strong>cleanlcd - clean LCD screen<\/strong>\n<strong>cmp\u00a0\u00a0\u00a0\u00a0 - memory compare<\/strong>\n<strong>coninfo - print console devices and information<\/strong>\n<strong>cp\u00a0\u00a0\u00a0\u00a0\u00a0 - memory copy<\/strong>\n<strong>crc32\u00a0\u00a0 - checksum calculation<\/strong>\n<strong>dhcp\u00a0\u00a0\u00a0 - invoke DHCP client to obtain IP\/boot params<\/strong>\n<strong>diskboot- boot from IDE device<\/strong>\n<strong>dmacp\u00a0\u00a0\u00a0\u00a0 - dma memory copy<\/strong>\n<strong>echo\u00a0\u00a0\u00a0 - echo args to console<\/strong>\n<strong>erase\u00a0\u00a0 - erase FLASH memory<\/strong>\n<strong>fatinfo - print information about filesystem<\/strong>\n<strong>fatload - load binary file from a dos filesystem<\/strong>\n<strong>fatls\u00a0\u00a0 - list files in a directory (default \/)<\/strong>\n<strong>fatstore - store binary file to a dos filesystem<\/strong>\n<strong>flinfo\u00a0 - print FLASH memory information<\/strong>\n<strong>go\u00a0\u00a0\u00a0\u00a0\u00a0 - start application at address 'addr'<\/strong>\n<strong>help\u00a0\u00a0\u00a0 - print online help<\/strong>\n<strong>ide\u00a0\u00a0\u00a0\u00a0 - IDE sub-system<\/strong>\n<strong>iminfo\u00a0 - print header information for application image<\/strong>\n<strong>imls\u00a0\u00a0\u00a0 - list all images found in flash<\/strong>\n<strong>itest\u00a0\u00a0 - return true\/false on integer compare<\/strong>\n<strong>lcdinit - initialize LCD<\/strong>\n<strong>loadb\u00a0\u00a0 - load binary file over serial line (kermit mode)<\/strong>\n<strong>loads\u00a0\u00a0 - load S-Record file over serial line<\/strong>\n<strong>show\u00a0\u00a0\u00a0 -<\/strong>\n<strong>loop\u00a0\u00a0\u00a0 - infinite loop on address range<\/strong>\n<strong>md\u00a0\u00a0\u00a0\u00a0\u00a0 - memory display<\/strong>\n<strong>mii\u00a0\u00a0\u00a0\u00a0 - MII utility commands<\/strong>\n<strong>mm\u00a0\u00a0\u00a0\u00a0\u00a0 - memory modify (auto-incrementing)<\/strong>\n<strong>mmcinit - init mmc card<\/strong>\n<strong>mtest\u00a0\u00a0 - simple RAM test<\/strong>\n<strong>mw\u00a0\u00a0\u00a0\u00a0\u00a0 - memory write (fill)<\/strong>\n<strong>nand\u00a0\u00a0\u00a0 - NAND sub-system<\/strong>\n<strong>nfs\u00a0\u00a0\u00a0\u00a0 - boot image via network using NFS protocol<\/strong>\n<strong>nm\u00a0\u00a0\u00a0\u00a0\u00a0 - memory modify (constant address)<\/strong>\n<strong>ping\u00a0\u00a0\u00a0 - send ICMP ECHO_REQUEST to network host<\/strong>\n<strong>printenv- print environment variables<\/strong>\n<strong>protect - enable or disable FLASH write protection<\/strong>\n<strong>randmac - generate a random MAC address and save to \"ethaddr\" environment variable<\/strong>\n<strong>rarpboot- boot image via network using RARP\/TFTP protocol<\/strong>\n<strong>reset\u00a0\u00a0 - Perform RESET of the CPU<\/strong>\n<strong>run\u00a0 \u00a0\u00a0\u00a0- run commands in an environment variable<\/strong>\n<strong>saveenv - save environment variables to persistent storage<\/strong>\n<strong>sdwaitins - wait sd card inserted or removed<\/strong>\n<strong>sdwaitins 0 -- waiting removed<\/strong>\n<strong>sdwaitins 1 -- waiting inserted<\/strong>\n<strong>setenv\u00a0 - set environment variables<\/strong>\n<strong>sleep\u00a0\u00a0 - delay execution for some time<\/strong>\n<strong>textout - show text to the screen<\/strong>\n<strong>textout x y \"str\" color<\/strong>\n<strong>color is 24bit Hex, R[23:16], G[15:8], B[7:0]<\/strong>\n<strong>for example: textout 0 0 \"hello world\" FFFFFF<\/strong>\n<strong>tftpboot- boot image via network using TFTP protocol<\/strong>\n<strong>tmpt\u00a0\u00a0\u00a0\u00a0 - execute Mass Production Tool<\/strong>\n<strong>uploadfile- Transfer the spi flash image to the server.<\/strong>\n<strong>version - print monitor version<\/strong><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>While this maybe cool and usefull it will suck if i can not create my own code.<\/p>\n<p>The BAD&#8230;. Since im mostly interested in the LCD and keyboard and could care less about the processor or anything else i am stuck.<br \/>\nAs you might expect there is no datasheet for either and manually reverse engineering both is beyond me since i dont have the necessary tools.<\/p>\n<p>The Ugly&#8230; Now what i am trying to figure out is how do i get into a U-Boot.bin file to get all the source. This is beyond me as well. The U-Boot.bin file has the bootloader and from what i can see some LCD init stuff and a ton more. To find out what can be expected in the file i used my Linux OS (debian) to search for strings in the file&#8230;<\/p>\n<p>(this is from Cygwin tho easier to copy\/paste)<\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"638\">\n<pre><strong>Jason@Jason-PC ~\/ARM8505\/script<\/strong>\n<strong>$ strings u-boot.bin<\/strong>\n<strong>...<\/strong>\n<strong>U-Boot 1.1.4 (Apr\u00a0 1 2010 - 16:26:54)<\/strong>\n<strong>Bbt01tbB@x}<\/strong>\n<strong>Font 12x22<\/strong>\n<strong>...<\/strong>\n<strong>LCD_ENABLE<\/strong>\n<strong>CxScreen<\/strong>\n<strong>CyScreen<\/strong>\n<strong>LCD_ID<\/strong>\n<strong>LCD panel ID????<\/strong>\n<strong>Un-Support LCD panel ID ( %d )<\/strong>\n<strong>X_LTEXT<\/strong>\n<strong>Y_LTEXT<\/strong>\n<strong>LCDC_FB<\/strong>\n<strong>BMP_ADR<\/strong>\n<strong>LCD FrameBuffer = 0x%08X, BMP Address = 0x%08X<\/strong>\n<strong>....<\/strong>\n<strong>lcdparam<\/strong>\n<strong>LCD param (default): 1,25000,8,800,480,48,40,40,3,29,13<\/strong>\n<strong>LCD param (setting): %s<\/strong>\n<strong>LCD param Error: expected version 1, but get %d<\/strong>\n<strong>LCD param Error: need %d arg count, but get %d<\/strong>\n<strong>So use default LCD param: 1,25000,8,800,480,48,40,40,3,29,13<\/strong>\n<strong>LCD param Error: the string length of extra register opreation length = %d, it is too long, it should be less than %d<\/strong>\n<strong>Not excute extra register operation for LCD<\/strong>\n<strong>.....<\/strong>\n<strong>LCD already initialized<\/strong>\n<strong>Loading BMP .....<\/strong>\n<strong>....<\/strong>\n<strong>LCDC_FB2<\/strong>\n<strong>failed<\/strong>\n<strong>LOGO_STRING<\/strong>\n<strong>no string ....<\/strong>\n<strong>Execute register operation for LCD:<\/strong><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Obviously there is more but i clipped out what wasnt relevant to save scroll space&#8230;<\/p>\n<p>I know know there are quite a few things related to the LCD in there which is something i will need. I ran across a program called binwalk and tried it on the uboot bin file and got:<\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"638\">\n<pre><strong>Scan Time:\u00a0\u00a0\u00a0 Jan 10, 2012 @ 22:04:41<\/strong>\n<strong>Magic File:\u00a0\u00a0 \/usr\/local\/etc\/binwalk\/magic.binwalk<\/strong>\n<strong>Signatures:\u00a0\u00a0 75<\/strong>\n<strong>Target File:\u00a0 u-boot.bin<\/strong>\n<strong>MD5 Checksum: d2c6f4e628ee5594caaccedb95fda7a6<\/strong>\n<strong>\u00a0<\/strong>\n<strong>DECIMAL\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 HEX\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 DESCRIPTION<\/strong>\n<strong>-------------------------------------------------------------------------------------------------------<\/strong>\n<strong>184350\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 0x2D01E\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 LZMA compressed data, properties: 0x01, dictionary size: 8388608 bytes, uncompressed size: 128 bytes<\/strong>\n<strong>185224\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 0x2D388\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 LZMA compressed data, properties: 0x03, dictionary size: 8388608 bytes, uncompressed size: 64 bytes<\/strong>\n<strong>186634\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 0x2D90A\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 LZMA compressed data, properties: 0x01, dictionary size: 8388608 bytes, uncompressed size: 4194432 bytes<\/strong>\n<strong>231695\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 0x3890F\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0 LZMA compressed data, properties: 0xD8, dictionary size: 65011712 bytes, uncompressed size: 1 bytes<\/strong>\n<strong>\u00a0<\/strong><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This leads me to believe that there is something i can extract and decompress &#8230; Look at address 186634 (0x2D90A) the uncompressed size is 4,194,432 bytes.<\/p>\n<p>That is just about 4MB big&#8230; Also since there are strings easily readable in there it also leads me to think that there are most likely normal files i can open. (i hope)<\/p>\n<p>&nbsp;<\/p>\n<p>The Only BIG problem im having is&#8230; getting the data out of the u-boot.bin which is the main goal. I made a simple program to extract data from a file at a specific offset for a specifiv length and output it to a file. All in binary. While it does the job it doesnt work . I think its because i dont know when the archive ends? Or when it starts really.<\/p>\n<p>While the above binwalk gives me a address i doubt its to the actual compressed file. LZMA compressed file have a magic number which usually is something like :<\/p>\n<p>0x5D, 0x00,0x00,0x08 or something similar. I know the 0x5D is correct. But the above binwalk points to the Properties of said location&#8230; like 186634 offset is a 0x01 and not a 0x5D&#8230;<\/p>\n<p>So if anyone knows how to extract this stuff please help me out.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ok i have one of those tiny 7 inch laptops which has a ARM and WinCE\/Android running on it.. While this is pretty cool to have i have no use for it. Unless i start learning how to program for android. Which i will not even get into. The cool thing i like about this [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-3149","post","type-post","status-publish","format-standard","hentry"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/posts\/3149","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/comments?post=3149"}],"version-history":[{"count":0,"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/posts\/3149\/revisions"}],"wp:attachment":[{"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/media?parent=3149"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/categories?post=3149"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/atomsofttech.com\/blog\/wp-json\/wp\/v2\/tags?post=3149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}