+#include <sys/stat.h>
+#include <sys/types.h>
+#include <limits.h>
+#include <fcntl.h>
#include <stdio.h>
+#include <stdlib.h>
+#include <strings.h>
+#include <string.h>
+#include <unistd.h>
+#include <errno.h>
+#include <libgen.h>
+#include "rsb-crc.h"
#include "rsb-lz.h"
/* TODO: IMPLEMET THIS! */
* 59b80: 46335053 undefined
*/
+void fn_59788(const char *fname)
+{
+ fprintf(stderr,"%s: error extracting...\n", fname);
+ exit(1);
+}
+
+struct s_59b78 {
+ unsigned char *start; /* 0 */
+ unsigned char *stop; /* 4 */
+ unsigned char y; /* 8 */
+ unsigned char x; /* 9 */
+};
+
+unsigned char fn_597c8(struct s_59b78 *r6_data)
+{
+ unsigned char *r0;
+ unsigned char *r1;
+ unsigned char r5;
+
+ r5 = 0;
+
+ r0 = r6_data->start;
+ r1 = r6_data->stop;
+
+ if (r1 < r0)
+ fn_59788(__func__);
+
+ r5 = *r0;
+ r0++;
+ r6_data->start = r0;
+
+ return r5;
+}
+
+unsigned int fn_59848(struct s_59b78 *r6_data)
+{
+ unsigned char r1;
+ unsigned char r2;
+ unsigned int r5;
+
+ r1 = r6_data->y;
+ if (r1 == 0x80) {
+ r6_data->x = fn_597c8(r6_data);
+ }
+ r1 = r6_data->y;
+ r2 = r6_data->x;
+ r1 = r1 & r2;
+ r5 = r1 & 0xff;
+
+ r1 = r6_data->y;
+ r1 = r1 >> 1;
+ r6_data->y = r1;
+ if (r1 == 0) {
+ r1 = 0x80;
+ r6_data->y = r1;
+ }
+
+ if (r5 == 0)
+ return 0;
+
+ return 1;
+}
+
+unsigned int fn_598b4(struct s_59b78 *r11_data, unsigned int r10_arg2)
+{
+ unsigned int r1;
+ unsigned int r2;
+ unsigned int r6;
+ unsigned int r7;
+
+ r1 = r10_arg2 - 1;
+ r6 = 1 << r1;
+
+ r7 = 0;
+ while (r6 != 0) {
+ r1 = r11_data->y;
+ if (r1 == 0x80) {
+ r1 = fn_597c8(r11_data);
+ r11_data->x = r1;
+ }
+ r1 = r11_data->y;
+ r2 = r11_data->x;
+ r1 = r1 & r2;
+ if (r1 != 0)
+ r7 = r7 | r6;
+
+ r6 = r6 >> 1;
+
+ r2 = r11_data->y;
+ r2 = r2 >> 1;
+ r11_data->y = r2;
+
+ r1 = r11_data->y;
+ if(r1 == 0) {
+ r11_data->y = 0x80;
+ }
+ }
+
+ return r7;
+}
+
+void fn_5980c(unsigned int arg1, unsigned int mem[])
+{
+ unsigned char *r1;
+ unsigned char *r2;
+
+ r1 = (unsigned char*)mem[0];
+ r2 = (unsigned char*)mem[1];
+
+ if (r1 > r2) {
+ printf("r1: 0x%08x, r2: 0x%08x\n", (unsigned int)r1, (unsigned int)r2);
+ fn_59788(__func__);
+ }
+
+ *r1 = arg1 & 0xff;
+
+ r1++;
+ mem[0] = (unsigned int)r1;
+}
+
+void fn_5993c(struct s_59b78 *r10_data, unsigned int r13_mem[])
+{
+ unsigned int r5;
+ unsigned int r2;
+ unsigned char r4;
+ unsigned int r6;
+ unsigned int r7;
+ unsigned int r11;
+ unsigned char arr_59b64[2048];
+
+ r5 = 1;
+
+ while (1) {
+ while (1) {
+ r2 = fn_59848(r10_data);
+ if (r2 == 0)
+ break;
+
+ r2 = fn_598b4(r10_data, 8) & 0xff;
+ r4 = r2;
+
+ fn_5980c(r4, r13_mem);
+ arr_59b64[r5] = r4 & 0xff;
+ r2 = r5 + 1;
+ r2 = r2 << 22;
+ r2 = r2 >> 22;
+ r5 = r2;
+ }
+
+ r11 = fn_598b4(r10_data, 0x0a);
+ if(r11 == 0)
+ return;
+
+ r2 = fn_598b4(r10_data, 0x04);
+ r7 = r2 + 1;
+ r6 = 0;
+ while (r6 <= r7) {
+ r2 = r6 + r11;
+ r2 = r2 << 22;
+ r2 = r2 >> 22;
+ r4 = arr_59b64[r2];
+ fn_5980c(r4, r13_mem);
+ arr_59b64[r5] = r4;
+ r2 = r5 + 1;
+ r2 = r2 << 22;
+ r2 = r2 >> 22;
+ r5 = r2;
+ r6++;
+ }
+ }
+}
+
+unsigned int crc_check_59684(unsigned char *arg1, unsigned int arg2, unsigned int magic)
+{
+ unsigned int r3;
+ unsigned int r4;
+ unsigned int r5;
+
+#if 0
+ if (r0 < 0xc0000000)
+ return 1;
+#endif
+
+ /* ??? */
+ r4 = *((unsigned int*)arg1 + 0x20);
+ r5 = *((unsigned int*)arg1 + 0x24);
+
+ printf("magic: 0x%08x <-> 0x%08x\n", r5, magic);
+ if (r5 != magic)
+ return 2;
+
+ if (arg2 >= r4)
+ r5 = 0;
+ else
+ return 3;
+
+ r5 = ~rsb_crc(~0x00, arg1, r4);
+ r3 = *((unsigned int*)(arg1 + r4));
+ printf("Checksums: 0x%02x <-> 0x%02x\n", r5, r3);
+
+ if (r3 == r5)
+ return 0;
+
+ return 4;
+}
+
+void mkdir_p(char *dir)
+{
+ char *copy, *parent;
+
+ if ((dir == NULL) || (!strcmp(dir, ".")))
+ return;
+
+ if ((copy = strdup(dir)) == NULL) {
+ perror("strdup");
+ exit(1);
+ }
+ parent = dirname(copy);
+ mkdir_p(parent);
+
+ errno = 0;
+ if (mkdir(dir, 0755) == -1) {
+ if (errno != EEXIST) {
+ fprintf(stderr, "%s: ", dir);
+ perror("mkdir");
+ exit(1);
+ }
+ }
+ free(copy);
+}
+
+void write_file(char *fname, unsigned char *buf, int len)
+{
+ char filename[PATH_MAX];
+ char *filename_c, *dirn;
+ int fd;
+ int remaining;
+ int ret;
+
+ strcpy(filename, "extracted/");
+ strcat(filename, fname);
+
+ if ((filename_c = strdup(filename)) == NULL) {
+ perror("strdup");
+ exit(1);
+ }
+ dirn = dirname(filename_c);
+ mkdir_p(dirn);
+ free(filename_c);
+
+ if ((fd = open(filename, O_WRONLY|O_CREAT, 0644)) == -1) {
+ fprintf(stderr, "%s: ", filename);
+ perror("open");
+ exit(1);
+ }
+
+ remaining = len;
+
+ while(remaining) {
+ ret = write(fd, buf + (len - remaining), remaining);
+ if (ret < 0) {
+ perror("write");
+ exit(1);
+ }
+ remaining -= ret;
+ }
+
+ printf(", %s written.\n", filename);
+
+ close(fd);
+}
+
+void extract_lz_file(unsigned char *buf, unsigned char *name)
+{
+ unsigned char *r3;
+ unsigned int r5;
+ unsigned char *r7 = NULL; /* Arg1, mem start */
+ unsigned char *r10 = NULL; /* Arg2, mem end */
+ unsigned char *r11 = buf; /* Arg3 */
+ struct s_59b78 struct1;
+ unsigned int arr_59b7c[1024];
+
+ if (*((unsigned int*)r11) != LZ_MAGIC)
+ fn_59788(__func__);
+
+ r3 = r11 + 4;
+ r5 = *((unsigned int*)r3);
+ printf(", length: %d", r5);
+
+ if ((r7 = malloc(r5)) == NULL) {
+ perror("malloc");
+ exit(1);
+ }
+ r10 = r7 + r5;
+ bzero(r7, r5);
+
+ r3 = r7 + r5;
+ if (r3 > r10)
+ fn_59788(__func__);
+
+ struct1.start = r11 + 8;
+ struct1.stop = r5 + r11;
+ struct1.x = 0;
+ struct1.y = 0x80;
+
+ arr_59b7c[0] = (unsigned int)r7;
+ arr_59b7c[1] = (unsigned int)(r5 + r7);
+
+ fn_5993c(&struct1, arr_59b7c);
+
+#if 0
+ /* This seems to still be completely broken */
+ r3 = r7 + 0x20;
+ r5 = *((unsigned int*)r3);
+
+ if ((ret = crc_check_59684(r7, r5, 0x46335053)) != 0) {
+ printf("crc_check return: %d\n", ret);
+ fn_59788(__func__);
+ }
+#endif
+
+ write_file((char*)name, r7, r5);
+
+ free(r7);
+}
+
void search_lz_sections(unsigned char *fw, int len)
{
int i;
for(i = 0; i < len - 4; i++) {
if (*((unsigned int*)(fw+i)) == LZ_MAGIC) {
j = fw + i - 1;
- if (*j != 0x00)
- continue;
printf("0x%02x: ", i);
j--;
while (j > fw) {
+ if (!strncmp("SP3", (char*)j, 3)) {
+ unsigned char fname[5];
+
+ bzero(fname, sizeof(fname));
+ memcpy(fname, j, 4);
+ printf("Firmware found: %s", fname);
+ extract_lz_file(fw + i, fname);
+ break;
+ }
if (*j == 0x00) {
+ if ((*(j+1) != '/')) {
+ printf("ignoring...\n");
+ break;
+ }
printf("%s", j+1);
+ extract_lz_file(fw + i, j+1);
break;
}
j--;
}
- printf("\n");
}
}
}