- The main binary in *.app/Contents/MacOS/ was not signed using the "hardened runtime" option.
- The ipodpatcher and sansapatcher binaries in RockboxUtility.app/Contents/bin/ were not signed at all.
The produced .dmg images are now suitable for notarization so the app inside can be installed and started with no security warnings.
They are not notarized yet, as this takes a significant amount of time, but it can be done manually using:
xcrun notarytool submit build-qt/RockboxUtility.dmg --keychain-profile <your-profile> --wait
xcrun stapler staple build-qt/RockboxUtility.dmg
Only ARM macOS is supported at the moment.
Co-authored-by: ChatGPT-5.6 Luna
Change-Id: Id88d7da18f541f9f503172f5dcb5b17d64e0602e
Adds the platform file, modelled on the Nano 2G's and the iPod
Classic's, and corrects the supported-versions text shared by the Nano
manuals, which said Rockbox does not run on the third generation.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Ie6290d67ae113086cb8a63c825eb9db9544c1d49
Fills in the stubs the Nano 3G port was left with, taking each from how
the original firmware drives the same hardware.
Testing evidence: firmware/target/arm/s5l8702/ipodnano3g/TESTING.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Iea5314769502f5941a176600869591756c5e3233
Rockbox only drives NAND parts proven on hardware, and this tree has one
model to prove them on. This is the image that lets an owner of another
Nano 3G supply what validating theirs takes: a bootloader built with
-DNAND_CHECK and run from DFU, which never touches the NOR flash or
writes to the NAND.
Testing evidence: firmware/target/arm/s5l8702/ipodnano3g/TESTING.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: I46328b69f8011337790f35a195de97b5bcf347a5
Several symbols were missing these annotations so the compiler wasn't
handling thumb interworking correctly.
Should resolve tone control crashes seen on clipv1 and our handful of
other 2MB armv5 targets that we build (mostly) in thumb mode.
Change-Id: If8c533a5f10b6592a2d2bec519f2c4d6539d7a66
When we request a thumb build on a non-thumb-only target, we hand
compilation to a script that tries to build everything as thumb, falling
back to non-thumb arm mode if the thumb build fails. In order for
this to work, the compiler flag -mthumb-interwork is required.
Move this definition out of the thumb-cc script, and into the configure
script (ie along with the other target-specific definitions)
Change-Id: Idc1f8caa088dbbf710b169b272de61cc0b7c9ca6
The Nano 3G keeps everything behind the S5L8702 flash controller and
Apple's FTL ("Whimory"), and nand-nano3g.c was a stub, so the port had
no storage at all. This is the flash driver, the FTL and the wiring that
makes the NAND Rockbox's disk. The three are one change because neither
half is usable without the other: the driver alone cannot see a
filesystem, and the FTL alone has nothing to drive.
Testing evidence: firmware/target/arm/s5l8702/ipodnano3g/TESTING.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Ib04a991489ff3a1a63cd55552e4a8d7ec7a5fc8c
The DX50 keymap already defines button_context_yesno, but
target_get_context_mapping() did not select it for
CONTEXT_YESNOSCREEN. As a result, physical buttons could not
operate dialogs such as "Playlist finished. Play again?".
Add the missing context mapping.
Tested on iBasso DX50 hardware: Play and Previous accept Yes;
Next and Power cancel.
Change-Id: I9f6078b45a48047a662aad5f231d0adac9a42d5d
Most of the churn here occurs because 'filesize' is one of
the redefined filesystem functions, but some of the structs
used by the native FS code also include a 'filesize' member
variable which gets renamed by the macro in some but not all
source files.
It's easier to rename 'filesize()' to 'ffilesize()' rather
than try to clean up the macro mess or renaming the struct
members.
There is weirdness with root_realpath() which now breaks on
native builds because it was assumed to be unprefixed there.
dir_get_info() was unprefixed everywhere but this just seems
inconsistent; make it follow the FS_PREFIX() convention too.
Change-Id: Ic3700c6234ea45f32679c1a8429d70fdb8f4088a
A target that defines HAVE_STORAGE_READONLY provides storage_readonly(),
and USB mass storage reports such a drive write protected: MODE SENSE
sets the WP bit, and WRITE(10) and WRITE(16) fail with DATA PROTECT /
WRITE PROTECTED before taking data, so a host mounts it read-only
instead of failing each write as a medium error. Only NAND storage wires
it up so far.
The iPod Nano 3G, added in the changes that follow, defines it: its FTL
mounts read-only in the bootloader and after a failed commit, and the
NAND check image is always read-only.
Built for the Nano 3G (bootloader, check image, firmware) without new
warnings. On hardware, Linux and Windows hosts have read the
always-read-only check image over USB; no host write has been made to a
read-only drive.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Idb34def2d588047e5dced9bac1521c00b37dd5e5
libusb_control_transfer returns <0 for errors,
0 is success without any bytes, read and ret >0
is the amount if bytes read.
Tested command: sudo ./usbboot --vid 0xa108 --pid 0x1000 --cpuinfo
Before:
Can't get CPU info: 8
After:
CPU info: X1000_v1
Change-Id: Ied6d430406239ea4f99e7c83274d99ae4c555899
Add the HiBy R1 and X1600 USB boot path, sharing the boot-package reader
with X1000. Load the returning USB stage separately from the flash SPL,
check its DDR result, then upload and run the second-stage bootloader.
Built on macOS; error paths checked with mocked USB transfers.
Change-Id: I501c1ffdb9e3d5f0c76a379ec6d229ec579bf100
pmu_preinit() masked register 0x10 with 0xdb, which clears bits 2 and
5. With bit 2 clear the NAND chip does not answer and nand_init() fails.
Masking with 0xdf clears only bit 5 and leaves bit 2 alone.
Measured on a 4GB Nano 3G. Every build that had worked carried debug
PMU reads, i.e. extra I2C delay, so delay was the confound to rule out
and each mask was tried with and without it:
0xdb, no extra delay dead
0xdb, extra delay dead
0xdf, extra delay reads (3 runs)
0xdf, no extra delay reads
One early 0xdf build without instrumentation failed once (rc=-1). That
has not been explained; the final validation run is the same
configuration and reads correctly.
Reading the register back after pmu_preinit() gives 0xdf. The new mask
keeps bit 2 and "| 0x8" only sets bit 3, so bit 2 is set as the BootROM
left it - the old mask was clearing it. Bit 5 is hidden by the mask, so
what the ROM leaves there is not known.
What bit 2 does is not established. The old comment guessed "bit4 is
related to NAND, LDO_0x15 on/off"; the register does sit among the NAND
supply settings (0x15 reads back the value commented as Vnand), but no
datasheet was consulted, so the new comment states only the observed
effect.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Iee73f876b7b6a5c85e09f8bf1c5ac174a49409e0
The S5L8702 has two flash memory controllers; the BootROM uses the first
at 0x38a00000 and addresses the second at +0x400. FMC_BASE was defined
for the S5L8700 and S5L8701 only.
Also add the registers Apple's NANDReadPage (BootROM 0x20009910) uses
that are not in the existing S5L8700 set, and three FMCSTAT bits. Their
real names are unknown, so they are named for what they were observed to
do and the comments say which are inferred rather than measured.
No functional change: this header only adds definitions.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Ib8c808128abc9a117cb811fe1fe47bffa4ec0abe
Database still opened an empty list when the config failed to parse. This results in the Device being complete unresponsive and needs a hard-reboot.
This shows a file-not-found splash instead and return to the previous menu.
Change-Id: Ifbb6998c46a4685eae486cffd89833f93a172713
Apple fitted at least five makers' NAND to the Nano 3G, in eighteen
chip and chip-enable combinations. Rockbox's Nano 3G NAND support can
only be enabled for writing on a chip that has been validated on
hardware, and so far one has. This gives owners of the others a way to
send what validation needs without installing anything.
nano3g-check.dfu runs from DFU mode (mks5lboot --dfusend). It reads the
chip ids on every chip enable, matches Apple's chip table, tries a
read-only mount, and shows a short summary. It then serves the raw NAND
over USB as a write-protected disk: sector 0 a text report, then 16-byte
spare records for every page, then page data. Nothing is written to the
iPod's NAND or NOR.
nandcheck.py collect finds that disk on Linux, macOS or Windows and
writes a few-MB archive: the report, every page's spare metadata and
read result, and every page that is not user data or erased (the FTL
and VFL control structures and Apple's bad-block records). It includes
no file contents and not the serial number. The README lists the chips,
how to tell which one an iPod has, and the procedure.
The image is the Nano 3G bootloader built with -DNAND_CHECK from the
Nano 3G NAND driver work, which is not merged yet.
Tested on a 4GB Nano 3G (Hynix A514D3AD x4): sent with mks5lboot
--dfusend, the disk appears within seconds, and collect reads it in 7
minutes with no ECC failures or timeouts. The archive mounts in the
driver's host FTL tests with every sector resolving to its newest copy.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Id790997768ee79451b7adeb5e9764dc8054faf4c
Registers the Nano 3G (platform ipodnano3g, model number 117, "nn3g"
header) so mks5lboot can build DFU installers and uninstallers for it,
adds its original bootloader to the dualboot code, and lists the
platform in the usage text and the README.
The target has to be named ipodnano3g rather than nano3g: the dualboot
Makefile derives the source directory and the piezo driver's file name
from it.
The per-target OF hash table is the substantive change. identify_fw()
decrypts the IM3 header's data_sign with the hardware UKEY and looks it
up in of_sha[], and anything not listed is taken to be a Rockbox
bootloader. The table held only iPod Classic firmware, so on a Nano 3G
the installer took Apple's own bootloader for a Rockbox one and gave up,
and the uninstaller would have refused to restore it. Both bail out
before writing, so nothing is damaged, but neither can work. The table
is now per target, and lists the bootloader of every Nano 3G firmware
release, 1.0.1 to 1.1.3.
The decrypted data_sign is the first 16 bytes of the SHA-1 of the
plaintext bootloader, so it is the same on every unit. Each release's
updater image (aupd, GID-encrypted, in the ipsw) carries that bootloader,
0x1f800 bytes, at the start of a NOR image. The aupd of each release was
decrypted on a Nano 3G with the hardware GID key and hashed on the host.
For 1.1.3 the result matches the data_sign read from a 4GB unit (model
MA978) whose NOR had never been written to, and the bootloader in its
aupd is byte-identical to the decrypted copy the installer relocated on
that unit. 1.1.2 and 1.1.3 ship the same bootloader.
dualboot.c is generated, and only the Nano 3G arrays are added. The iPod
Classic arrays are left byte-for-byte as they were: rebuilding them with
a different compiler changes their bytes, which would ship an untested
installer to Classic users for no reason.
The dualboot Makefile did not build from the current tree for any
target, which the committed blobs, older than both problems, had hidden.
config.h needs autoconf.h, which tools/configure generates per target,
so each target now takes a CONFIGDIR_<target> pointing at a configured
bootloader build for it, e.g.
make CONFIGDIR_ipod6g=../../../build-ipod6g-bl \
CONFIGDIR_ipodnano3g=../../../build-nano3g-bl
And the linker script is preprocessed with __ASSEMBLER__ defined, under
which config.h now emits the ldmpc/ldrpc assembler macros that ld
rejects; the sed that cleans it now also drops .macro, .endm and .syntax
lines and the macro bodies. Before these fixes the iPod Classic build
failed first on the missing autoconf.h and then with a linker syntax
error; with them it builds both blobs.
Tested on that unit, with s5l8702pwnage delivering the images through
Apple's DFU, and again with mks5lboot's own --bl-inst and --bl-uninst:
the installer put Rockbox in NOR, the unit then booted
Rockbox, and holding MENU booted Apple's firmware from the relocated
original bootloader; the uninstaller restored it and the unit booted
Apple's firmware again. Those images carried a table holding only the
1.1.3 entry. The Nano 3G blobs in dualboot.c were then rebuilt with the
Makefile for the full table - with the one-entry table the rebuild was
byte-identical to what the tested images carried - and mks5lboot
--bl-inst with them installed Rockbox on the same unit, which booted
Rockbox and, holding MENU, Apple's firmware. The uninstaller built with
the full table has not been run, and no firmware other than 1.1.3 has
been installed to or uninstalled from on hardware. For the iPod Classic,
the uninstaller DFU this builds is byte-identical to the one built
before this change.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: I4b2fa692ac4110192ccbde0f1790b0ae2d1c73f5
backlight_on_button_hold / remote_backlight_on_button_hold
were never added to the Plugin API nor backlight_use_settings() helper
Change-Id: I75999af76f98244a870ab86564e591c8a900e66c
The generic USB core calls usb_drv_set_address() after starting the
zero-length status stage for SET_ADDRESS. On an iPod Video 5.5G connected
to a V-MODA VAMP VERZA, applying the address at that point causes the
accessory to reset the USB bus and enumeration does not continue.
Keep the generic USB core unchanged. In the ARC driver, capture a standard
device SET_ADDRESS request when its setup packet arrives and defer writing
REG_DEVICEADDR until the successful zero-length EP0 IN status transfer
completes. Clear any pending address on a new setup packet or USB bus reset.
With this driver-specific change the VAMP completes enumeration, iAP
authentication, 44.1 kHz digital-audio negotiation, and audio playback.
Tested on real hardware:
- Apple iPod Video 5.5G
- V-MODA VAMP VERZA over 30-pin USB
- 44.1 kHz digital audio playback
Development provenance:
The debugging process and patch preparation were performed with assistance
from OpenAI ChatGPT (GPT-5.6 Sol). I built and tested the firmware on the
hardware and verified the final behavior.
Change-Id: Ic9392d211dccda568fd42b06cb2b8853d4b8e893
Add S5L8702 VPU-B initialization, reset, bitstream input, frame output,
and cache maintenance to the iPod 6G target. Advertise it with
HAVE_HW_H264 and append a capability-gated decoder interface to the
plugin API.
Keep MP4 parsing, AAC decode and mixer output, A/V synchronization,
playback controls, resume state, and presentation in the multi-file
h264_player plugin. The target layer exposes decoder operations only.
Accept non-fragmented MP4/M4V containing Constrained Baseline H.264
through level 3.0, up to 640x480 at 30 fps, with optional AAC-LC audio.
Validate codec configuration and all sample-table relationships before
activating the hardware.
Read MP4 tables in bulk, boost the CPU while preparing them, and report
staged loading progress so long movies do not appear to hang during
startup.
Register the viewer and document its format limits and controls. The
libm4a compatibility fixes needed by video-first containers remain in
the preceding standalone change.
Tested on an iPod Classic 6G through an isolated Rolo nightly runtime:
H.264/AAC playback and M4V startup succeeded. Normal and
isolated-runtime iPod 6G builds also complete, and git diff --check is
clean.
Change-Id: I1e96c65c7d0b4231a94f602f8052f1b26d6e4a80
This was added in commit 8ff2c81bd to prevent a custom
root menu UI from flashing on screen in some themes
when returning from a plugin. Because the display isn't
updated in this scenario anymore, the workaround can be
safely eliminated.
Change-Id: Ie46b0921cfdad6e45a31661a5d451dc2717171d6
Top, bottom, and right icons were displayed too far to
the left. Apparently a long-standing issue.
Icon width is 7, so subtract 7/2 = 3 pixels, instead
of 4, from calculated center, and only 7 pixels, instead
of 8, from the right vp edge.
Change-Id: I8440a4fef4778a66d56117a05b3fe4c36ac8dadd
Remove trailing whitespace from int settings, so
that right-aligned or centered values look correct
in Quickscreen for settings such as Brightness.
Change-Id: I006cf3c3e8b30be2246e7370f26e0428fa47e54b
Size the reduced stco lookup with ceiling division. The table stores
chunk entries 0, divider, 2 * divider, and so on, so floor division
allocated one entry too few whenever the original count had a
remainder.
Treat a valid media-information atom whose first child is not smhd as
a non-audio track and skip the remainder. Continue scanning subsequent
tracks so AAC decoding works when an MP4 places its video track before
the audio track, while still rejecting malformed atom sizes and
malformed sound headers.
Keep these container fixes independent of the H.264 player and target
driver so they can be reviewed and applied to libm4a on their own.
Build-tested as part of the normal and isolated-runtime iPod 6G
configurations and hardware-tested with AAC audio in M4V playback.
Change-Id: I8c711525932f54ecbdad982c7f7ddc9490c5668d
Add some hardcoded flick gestures in the list UI:
Top -> open quickscreen
Left -> go back
Right -> go to the WPS
The WPS also gets a set of hardcoded flick shortcuts:
Top -> open quickscreen
Left -> go to file / database browser
Right -> view playlist
Bottom -> context menu
These are enabled by default in pointing mode but can
be disabled using the "Touchscreen Flick Shortcuts"
option.
Change-Id: Ib30a338ebb9662cd136985da6d34ed5b041e4077
Add Off, Auto, and On choices under the LCD settings menu for targets
with HAVE_COMPOSITE_VIDEO_OUT. Off is the default and leaves accessory
ADC, video registers, framebuffer conversion, output clocks, and CPU
boost untouched.
Auto enables output only for the qualified Philips dock signature. On
still requires a physically present, fully identified dock and permits
other detected composite accessories.
Document the menu behavior and the corresponding configuration-file
values in the iPod Classic manual.
Hardware tested on an iPod Classic 6G/7G with a Philips DCP750/37.
Change-Id: I649149daa331a95aa31110e1f2260a4a00ba789a
Add NTSC composite output for the iPod Classic 6G/7G using the
S5L8702 video processor, mixer, and encoder. Reconstruct the setup used
by the original firmware and mirror the 320x240 LCD in a centered
648x432 viewport.
Expose the driver through HAVE_COMPOSITE_VIDEO_OUT and a
target-neutral videoout interface. Keep the S5L8702 MMIO layout and
register definitions with the other SoC definitions in s5l87xx.h.
Convert LCD updates from RGB565 to planar YUV420. MPEG playback copies
decoded YUV420 planes directly, avoiding an RGB round trip. Hold output
clocks and CPU boost only while the memory-backed layer is active, and
restore them on disable or power-off.
Defer dock identification out of the serial tick because the accessory
resistor ADC path sleeps. Auto detection recognizes the measured Philips
DCP750/37 resistor range; manual mode can qualify other attached docks.
Leave interrupts enabled during the encoder's 10 ms reset wait so PCM
DMA can service linked-buffer completions when a dock is inserted during
audio playback. Keep reset assertion, reset release, all SVID register
writes, and pipeline start atomic so the composite setup cannot
interleave.
Hardware tested on an iPod Classic 6G/7G with a Philips DCP750/37 for
correct colors and geometry, stable UI mirroring, and full-screen MPEG
playback.
Change-Id: I669f2477d5cc707b48f7d24384c713d874a80e3f
Listen to GUI_EVENT_NEED_UI_UPDATE events and redraw, so
screen doesn't disappear if a theme draws over the UI vp.
Occurs in situations when the SBS is redrawn after waking
the screen, or when the song changes.
Change-Id: I062e802959ab9d34d8c04b7f82da6b87efb5d739
Reduces GNU complexity score from 7 to 2.
Use separate inline functions that group setting
- x-position and width for left and right text viewport
- y-position and height for all text viewports
- position/dimensions for icons viewport
Change-Id: I14f4eee1f4d6fefa9acbf4a37970a535e77990b1
importing discards duplicate entries based on context + action code
however you may want multiple entries to map to the same action
and you can't do it within the same context
instead only consider an entry as a duplicate if they have the same
context, actioncode, button, and prebutton
Change-Id: I5aba3459505987ba37e26758aec62f02fcf8165a
The parent vp wasn't set before checking the string size,
so, in certain scenarios, the size was calculated using a
different font than the one configured for the UI viewport.
Change-Id: I66bb2e496598811f6169a118de5cb83b451fa292
I intended to remove this in commit a8f8aa40b9 ("lastfm_scrobbler:
fetch rbversion from plugin API") but apparently forgot to do so,
so the scrobbler plugin was still rebuilding itself when RBVERSION
changes. Removing the header fixes that.
Change-Id: I6740d72ad35f5037a6a4a7580559a6c980b3225b
Eliminate special case for transition to the Shortcuts menu.
The SBS refresh doesn't cause a screen update anymore, and
has negligible cost, so do it regardless.
Reverts the changes to quickscreen.c introduced in commit
dfd9c10 ("Eliminate skin updates in between activities")
+ simplify quickscreen_draw_item (no effect on behavior)
Change-Id: I3fca976de554c720cb69a41566fd0d0a7e6ea92d
Fixes possible crash in case of pathological
UI vp dimensions, when attempting to clear a
QS item's vp.
E.g. https://github.com/federicoplg/musicOS
(commit c5e8570) configures a 1x1 UI viewport
at x=319 y=239, resulting in left/right item
viewports that have negative width or height.
Minor additional simplifications with no
effect on behavior:
- Combine actions requiring cleanup in a setup function.
Put it below the existing cleanup function
- Rename quick_screen_quick to quickscreen_show, and
quickscreen_run to quickscreen_main
- Iterate over items using FOR_QS_ITEMS macro
- Remove quickscreen_draw_item's int_value
- quickscreen_update: immediately continue if qs skinned
- Remove some obsolete #includes
Change-Id: I49aea3be837b861bdcd5132e84fef858df72327b
The "View RAM info" debug screen reports the host system's memory. It
calls sysinfo(2) and reads /proc/meminfo, but it is guarded only by
HIBY_LINUX.
That breaks the win32 simulator for all seven HIBY_LINUX targets -
agptekrocker, aigoerosq, hibyr1, hibyr3proii, hidizsap80max, xduoox20
and xduoox3ii - because HIBY_LINUX is still defined when the simulator
is cross-compiled for Windows, and mingw has no <sys/sysinfo.h>:
apps/debug_menu.c:146:10: fatal error: sys/sysinfo.h: No such file or directory
Exclude simulators at all three sites - the include, the function and
the menu entry - matching the !defined(SIMULATOR) guards already used
elsewhere in this file. On a simulator the screen reports the developer
machine's memory rather than the simulated device's, so it does not
belong there on any host.
Verified by building agptekrocker three ways: as a Windows simulator,
which now succeeds; as a Linux simulator, which still succeeds; and for
the device itself with arm-rockbox-linux-gnueabi, which still succeeds
and keeps the screen.
Provenance, per the AI disclosure requirement in docs/CONTRIBUTING: this
change was drafted with Claude Code (Anthropic Claude Opus 5) at my
direction. Patch set 3 adopts Solomon Peachy's review suggestion to key
the guard off SIMULATOR rather than __linux__.
Change-Id: If8a09da82d22118924a3375e05739dcd5640e11d