Move the iriver-specific functions for detecting flashed
Rockbox/OF images into system-iriver.c and remove the
HAVE_FLASHED_ROCKBOX define which is now redundant (all
targets using system-iriver.c enable it).
Copyright attribution on the new system-iriver.h header
is a best guess from Git history.
Change-Id: If1933f881a63fd517162ab9ca8f4a3007b997739
Only Coldfire targets have ever implemented this. Gate it
behind CPU_COLDFIRE so the stub functions won't be needed
in other targets.
Change-Id: I507952c40a04d813a40296142a6eba1df24b0a68
Some files were not using the standard header with the
Rockbox logo. Add this and move any technical notes into
a separate comment.
Change-Id: Idaac932cd56154c7b785ba0e6c0231a21878f786
CLEAR_FEATURE(ENDPOINT_HALT) must reset the selected non-control endpoint data toggle as well as removing STALL. Set the corresponding ARC toggle-reset bit when clearing the halt, including when the endpoint is already unstalled. EP0 keeps its SETUP-controlled toggle handling.
The register-stub test checks IN/OUT independently and verifies that EP0 does not receive a non-control toggle reset.
Change-Id: I18bce488ec250336512bfda4db6ff369d21d9180
If RESET and IOC/SOF are reported together, the old interrupt order can refill audio or report completions from descriptors invalidated by the reset. Handle RESET first and return without dispatching those stale events. Disable SOF refill and stop the batch ring when resetting the controller.
The register-stub regression exercises simultaneous RESET, IOC and SOF and checks that no old completion or refill is dispatched.
Change-Id: Iac98df59aea30dfee155302f7ad31c6ba9902975
Modern rockbox builds are just larger than 1MB on the Sansa Fuze/Fuzev2,
which exceeds the reserved space to load the firmware.
The other AMS targets are a little under 1MB, so their time is likely
to come soon. Bump the buffer to 2MB so we never have to worry about
this again.
Change-Id: Ie6bf998596f5e55f5cc8e576a2a22639344306a4
A contributor's check archive matches the row exactly and passes
test_crash clean. test_ftl disagrees with the oracle on two logical
pages in one block - a second, distinct false positive from the
A5D5D589 x2 case: a closed data block addressed purely by position,
with one stale leftover page. Confirmed against the decode notes
(_FTLRestore's "closed blocks -> map" step) and documented in
test_ftl.c alongside the existing false positive.
Testing evidence: utils/ipodnano3g/RESULTS.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Ib24d2df18e2b0e60e000ee6ea43bef9c214f7f72
A contributor's check archive matches the row exactly and passes both
host tests clean: test_ftl agrees with the oracle on all 3,964,928
sectors, test_crash survives 100 power cuts with 0 sectors wrong.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: I7c651c94332e0a04686ce8855a274735ae39546c
Four check archives (B614D5EC x2, A5D5D589 x2, A5D5D589 x4, 3E94D589 x2)
all match their table rows and pass test_crash clean. Three pass test_ftl
outright; A5D5D589 x2 disagrees with the oracle on two logical pages,
traced to _FTLRestore's own tie-break between two competing logs
(verified instruction-for-instruction against osos 1.1.3) - Apple's own
firmware would resolve the same medium the same way, so this is not a
defect. test_ftl.c gets a note explaining the false positive for future
archives that hit it.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: If8de0d6b1175981a292c5c45fbc092d5a6e0891a
A contributor's check archive for a 2-chip-enable A5D5D52C unit matches
the row exactly and replays clean against the host FTL suite. The row
moves in with the validated chips on this evidence alone - no on-device
write test has been run.
Testing evidence: utils/ipodnano3g/RESULTS.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Ia9e00c0e880b10785da3ab52bc98dc93e94acfaf
Reject the first out-of-range configuration index and omit class descriptors for drivers whose initialization failed.
Change-Id: I1f74dcceb69f19b52650aa6ae3f38331e320b151
Account only completed data-stage bytes in the CSW residue. Halt the requested data pipe before returning failed status for an unsupported command with a data phase.
Send ATA IDENTIFY from the initialized transfer buffer rather than a stale READ/WRITE buffer pointer, and reject unsupported WRITE BUFFER variants.
Change-Id: I9855f56b3555c2a69724681cb028e57f733dae0e
Fills in the stubs the Nano 3G port was left with, taking each from how
the original firmware drives the same hardware.
Testing evidence: firmware/target/arm/s5l8702/ipodnano3g/TESTING.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Iea5314769502f5941a176600869591756c5e3233
Rockbox only drives NAND parts proven on hardware, and this tree has one
model to prove them on. This is the image that lets an owner of another
Nano 3G supply what validating theirs takes: a bootloader built with
-DNAND_CHECK and run from DFU, which never touches the NOR flash or
writes to the NAND.
Testing evidence: firmware/target/arm/s5l8702/ipodnano3g/TESTING.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: I46328b69f8011337790f35a195de97b5bcf347a5
The Nano 3G keeps everything behind the S5L8702 flash controller and
Apple's FTL ("Whimory"), and nand-nano3g.c was a stub, so the port had
no storage at all. This is the flash driver, the FTL and the wiring that
makes the NAND Rockbox's disk. The three are one change because neither
half is usable without the other: the driver alone cannot see a
filesystem, and the FTL alone has nothing to drive.
Testing evidence: firmware/target/arm/s5l8702/ipodnano3g/TESTING.md.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Change-Id: Ib04a991489ff3a1a63cd55552e4a8d7ec7a5fc8c
Most of the churn here occurs because 'filesize' is one of
the redefined filesystem functions, but some of the structs
used by the native FS code also include a 'filesize' member
variable which gets renamed by the macro in some but not all
source files.
It's easier to rename 'filesize()' to 'ffilesize()' rather
than try to clean up the macro mess or renaming the struct
members.
There is weirdness with root_realpath() which now breaks on
native builds because it was assumed to be unprefixed there.
dir_get_info() was unprefixed everywhere but this just seems
inconsistent; make it follow the FS_PREFIX() convention too.
Change-Id: Ic3700c6234ea45f32679c1a8429d70fdb8f4088a
A target that defines HAVE_STORAGE_READONLY provides storage_readonly(),
and USB mass storage reports such a drive write protected: MODE SENSE
sets the WP bit, and WRITE(10) and WRITE(16) fail with DATA PROTECT /
WRITE PROTECTED before taking data, so a host mounts it read-only
instead of failing each write as a medium error. Only NAND storage wires
it up so far.
The iPod Nano 3G, added in the changes that follow, defines it: its FTL
mounts read-only in the bootloader and after a failed commit, and the
NAND check image is always read-only.
Built for the Nano 3G (bootloader, check image, firmware) without new
warnings. On hardware, Linux and Windows hosts have read the
always-read-only check image over USB; no host write has been made to a
read-only drive.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Idb34def2d588047e5dced9bac1521c00b37dd5e5
pmu_preinit() masked register 0x10 with 0xdb, which clears bits 2 and
5. With bit 2 clear the NAND chip does not answer and nand_init() fails.
Masking with 0xdf clears only bit 5 and leaves bit 2 alone.
Measured on a 4GB Nano 3G. Every build that had worked carried debug
PMU reads, i.e. extra I2C delay, so delay was the confound to rule out
and each mask was tried with and without it:
0xdb, no extra delay dead
0xdb, extra delay dead
0xdf, extra delay reads (3 runs)
0xdf, no extra delay reads
One early 0xdf build without instrumentation failed once (rc=-1). That
has not been explained; the final validation run is the same
configuration and reads correctly.
Reading the register back after pmu_preinit() gives 0xdf. The new mask
keeps bit 2 and "| 0x8" only sets bit 3, so bit 2 is set as the BootROM
left it - the old mask was clearing it. Bit 5 is hidden by the mask, so
what the ROM leaves there is not known.
What bit 2 does is not established. The old comment guessed "bit4 is
related to NAND, LDO_0x15 on/off"; the register does sit among the NAND
supply settings (0x15 reads back the value commented as Vnand), but no
datasheet was consulted, so the new comment states only the observed
effect.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Iee73f876b7b6a5c85e09f8bf1c5ac174a49409e0
The S5L8702 has two flash memory controllers; the BootROM uses the first
at 0x38a00000 and addresses the second at +0x400. FMC_BASE was defined
for the S5L8700 and S5L8701 only.
Also add the registers Apple's NANDReadPage (BootROM 0x20009910) uses
that are not in the existing S5L8700 set, and three FMCSTAT bits. Their
real names are unknown, so they are named for what they were observed to
do and the comments say which are inferred rather than measured.
No functional change: this header only adds definitions.
AI provenance: developed with Claude Opus 5 (Anthropic), used through
Claude Code. The model wrote most of the code and this message under
Andrew Rice's direction. Any hardware testing described above was
carried out by Andrew Rice, who is responsible for this change.
Change-Id: Ib8c808128abc9a117cb811fe1fe47bffa4ec0abe
The generic USB core calls usb_drv_set_address() after starting the
zero-length status stage for SET_ADDRESS. On an iPod Video 5.5G connected
to a V-MODA VAMP VERZA, applying the address at that point causes the
accessory to reset the USB bus and enumeration does not continue.
Keep the generic USB core unchanged. In the ARC driver, capture a standard
device SET_ADDRESS request when its setup packet arrives and defer writing
REG_DEVICEADDR until the successful zero-length EP0 IN status transfer
completes. Clear any pending address on a new setup packet or USB bus reset.
With this driver-specific change the VAMP completes enumeration, iAP
authentication, 44.1 kHz digital-audio negotiation, and audio playback.
Tested on real hardware:
- Apple iPod Video 5.5G
- V-MODA VAMP VERZA over 30-pin USB
- 44.1 kHz digital audio playback
Development provenance:
The debugging process and patch preparation were performed with assistance
from OpenAI ChatGPT (GPT-5.6 Sol). I built and tested the firmware on the
hardware and verified the final behavior.
Change-Id: Ic9392d211dccda568fd42b06cb2b8853d4b8e893
Add S5L8702 VPU-B initialization, reset, bitstream input, frame output,
and cache maintenance to the iPod 6G target. Advertise it with
HAVE_HW_H264 and append a capability-gated decoder interface to the
plugin API.
Keep MP4 parsing, AAC decode and mixer output, A/V synchronization,
playback controls, resume state, and presentation in the multi-file
h264_player plugin. The target layer exposes decoder operations only.
Accept non-fragmented MP4/M4V containing Constrained Baseline H.264
through level 3.0, up to 640x480 at 30 fps, with optional AAC-LC audio.
Validate codec configuration and all sample-table relationships before
activating the hardware.
Read MP4 tables in bulk, boost the CPU while preparing them, and report
staged loading progress so long movies do not appear to hang during
startup.
Register the viewer and document its format limits and controls. The
libm4a compatibility fixes needed by video-first containers remain in
the preceding standalone change.
Tested on an iPod Classic 6G through an isolated Rolo nightly runtime:
H.264/AAC playback and M4V startup succeeded. Normal and
isolated-runtime iPod 6G builds also complete, and git diff --check is
clean.
Change-Id: I1e96c65c7d0b4231a94f602f8052f1b26d6e4a80
Add NTSC composite output for the iPod Classic 6G/7G using the
S5L8702 video processor, mixer, and encoder. Reconstruct the setup used
by the original firmware and mirror the 320x240 LCD in a centered
648x432 viewport.
Expose the driver through HAVE_COMPOSITE_VIDEO_OUT and a
target-neutral videoout interface. Keep the S5L8702 MMIO layout and
register definitions with the other SoC definitions in s5l87xx.h.
Convert LCD updates from RGB565 to planar YUV420. MPEG playback copies
decoded YUV420 planes directly, avoiding an RGB round trip. Hold output
clocks and CPU boost only while the memory-backed layer is active, and
restore them on disable or power-off.
Defer dock identification out of the serial tick because the accessory
resistor ADC path sleeps. Auto detection recognizes the measured Philips
DCP750/37 resistor range; manual mode can qualify other attached docks.
Leave interrupts enabled during the encoder's 10 ms reset wait so PCM
DMA can service linked-buffer completions when a dock is inserted during
audio playback. Keep reset assertion, reset release, all SVID register
writes, and pipeline start atomic so the composite setup cannot
interleave.
Hardware tested on an iPod Classic 6G/7G with a Philips DCP750/37 for
correct colors and geometry, stable UI mirroring, and full-screen MPEG
playback.
Change-Id: I669f2477d5cc707b48f7d24384c713d874a80e3f
The reason 16/24-bit on the DAC does not work is that this
configures the I2S frame length, and the X1000's AIC uses
a hardcoded 64-bit frame length regardless of the bit depth
selected at the AIC input side. The AIC will pad the lower
bits of the 32-bit output sample with zeros.
Change-Id: I48c9893ca358248a63f24e3f75149da988943953
Pure file move, in preparation for a second Ingenic SoC.
dma, gpio, i2c, installer, kernel, nand and the SPL NAND backend
move from target/mips/ingenic_x1000/ to target/mips/ingenic/
Drivers that cannot move as whole files, because part of each is
genuinely X1000-specific, are left alone for now: msc, uart, sfc, the
debug menu and the OST helpers in system-x1000.c.
Verified as a no-op: built at target 246 --type=b before and after from
the same source path, bootloader.bin is byte-identical, and every moved
file's object has the same instruction stream under its new name.
Builds clean with no warnings for targets 246, 260 and 247, both
--type=n and --type=b.
Change-Id: I9f67c23384df49b8c4554d695b772bcd54a4e32f
Co-Authored-By: Claude Opus 5
sdmmc_host looks only at the transport status the controller returns,
and passes NULL for the response of every data transfer, so nothing ever
reads R1. A card does not signal a rejected command by failing the
transfer: it answers normally and simply does not commit the data. A
write refused for a write-protect violation, an address error or an
internal ECC failure is therefore reported to the filesystem as a
success.
Add sdmmc_host_submit_cmd_r1(), which fails a command whose response
carries any bit in SD_R1_CARD_ERROR, and use it for SET_BLOCKLEN and the
read or write itself. Those responses were already being received and
discarded, so this costs no extra bus traffic.
The R1 of the transfer command is returned before the data moves, so it
cannot report a failure which happened during the transfer. Whatever
ends the transfer has to be checked too: CMD12 where it terminates a
multiblock transfer, and CMD13 (SEND_STATUS) where CMD23 was used and
there is no closing command. Without the CMD13 an error is reported only
on the next transfer, against the wrong sector.
A CMD12-terminated read which ends on the last block of the card will
have tried to read past the end, and the SD spec (4.3.3, "Block Read")
requires the resulting OUT_OF_RANGE to be ignored. It is masked out for
exactly that case.
Only valid for R1 and R1b. A controller cannot apply the check itself
because it is told the response length rather than its format, and R3,
R6 and R7 are also 48-bit responses carrying unrelated bits in the same
positions.
Affects any target building sdmmc_host.
Exercised on X1600 hardware over 8 GiB of sequential reads with no
errors; the error path itself was not observed to trigger. Not run on
X1000 hardware.
Change-Id: I4a80dd29385d3eb4f256bc745a84f96e7054bbf8
Co-Authored-By: Claude Opus 5
This commit does the following changes to the 3ds port:
- Rename the target from ctru to 3ds.
- Rename all files and functions with the ctru naming convention to 3ds.
- Created a new file and folder structure that will better integrate future console ports that share the same codebase.
- Fixed a buffer overflow bug in pcm code.
Change-Id: I17c6f86df64eb99dd2b653485d70832ff46b2ba8
Replace the dead infinite loop in power_off() with sim_do_exit()
which properly shuts down kernel, timer, mcuhwc, and cfgu services
before calling exit(0). Remove the stale sys_poweroff() declaration
in system-ctru.h; the generic implementation in powermgmt.c handles
SYS_POWEROFF broadcasting.
Change-Id: I247c4de482c66c3a060d0b88b7e2239ecec189c5
Restore paths_init() to create /3ds/.rockbox and the config
directory tree at startup, so Rockbox works without manual SD
card setup.
Edited by Vencislav Atanasov: Use the ROCKBOX_DIR macro instead of hardcoding the paths.
Change-Id: I33ab8e588cdca58285d50e9e5698a8071b381cf4
Some 512G Samsung cards (and possibly other cards) seem to
have problems with repeated single block read commands and
sometimes just time out without ever sending the data. The
card response is received OK and reports no errors but no
data is received.
The problem also occurs if a multiple block read is used to
transfer a single block but doesn't seem to occur when more
than one block is transferred.
Less commonly, timeouts can occur on write commands but it
is not clear if that happens only after a timed out read.
Adding a delay of a few tens of milliseconds before each
read/write single block command appears to prevent this.
Change-Id: I5a02b71f59cc02832acaf30e5f900a3ee8804e76
Remove all SD protocol handling and all target specific code
like GPIO/interrupt handling and clock parent setup. This can
now be handled from sdmmc_host_target_init() for each target.
Now only the clock frequency is managed by the MSC driver.
To make this code easier to factor out later, it's confined
to helper functions that do not access the driver state.
One small change is that MSCxDIV output is now clamped to a
minimum of 50MHz to avoid unnecessary frequency changes. The
MSC_CLKRT divider can still divide 50MHz down to 400 KHz so
there is no downside to this.
Auto-CMD12 is now unused. Using it would make error handling
more difficult for sdmmc_host since the controller does not
expose response data for the auto-CMD12.
Explicit CMD12 was not handled correctly in the old version
of the driver because the busy signal was ignored for R1b
responses if there was no associated data transfer. This is
now fixed by waiting for the PRG_DONE interrupt instead of
END_CMD_RES for non-data transfer R1b type commands.
Since existing X1000 targets are all very similar they use
a shared implementation in sdmmc-x1000-common.c for clock
setup and card detection. New targets can either use this
or create a separate file if they are different enough to
warrant one.
Change-Id: I35396637325d7c06a10151bb6aee64cabdc7b682
The ipod4g target has already had UDMA 2 disabled
(see commits 7d78503 and d118f47) due to reported
instabilities. The iPod color, using stock hardware,
appears to be affected too.
Change-Id: I9aea2efce3026938f719da4e5372b233ff6234cf
Route bass and treble adjustments through Rockbox's DSP pipeline
using biquad filters, making the Bass/Treble sliders in Sound
Settings functional rather than no-ops.
💘 Generated with Crush
Assisted-by: Crush:deepseek-v4-pro
Change-Id: I5d168aaa233fe450defaea03d6657732abd2ec47
Map the circle pad to directional buttons, giving an alternative
input method to the D-pad. Uses a deadzone of 64 to prevent
unintended movement from minor stick drift.
💘 Generated with Crush
Assisted-by: Crush:deepseek-v4-pro
Edited by Vencislav Atanasov: Fixed KEY_SELECT handling.
Change-Id: I34bf7127688423fca209e199d9535e032ad8b753
On large touchscreens the software keyboard can now run in "point mode". Keys are laid out finger-sized and tapped directly instead of being navigated with a cursor. Targets opt in with HAVE_KBD_POINT_MODE.
Key size is derived from LCD_DPI so a key is about 5mm across whatever the panel density, falling back to a fixed size where DPI is unknown.
A phone-style default layout in the UI font, across three flip pages of eight lines. Page two is page one shifted (i.e caps). Page three completes Latin-1 and adds additional accented letters common to the other European locales.
Space is drawn as an icon, since the UI font has no glyph for it.
Change-Id: Ibe2e305b3c22b1f9152358cf3864b9445b67b463
Co-Author: Claude Opus 4.8
According to commit 7327d9fb6c ("Implement set block count
(CMD23) for x1000 target") some cards may experience data
corruption with certain controllers when CMD12 is used to
terminate multiblock writes. Using set block count (CMD23)
is reported to fix this issue.
Following the approach in that patch, use the SCR register
to probe support for CMD23, but disable use at runtime if
CMD23 generates an illegal command error.
Change-Id: I3ee1e48939b79b848fbda12c6737f2f974f47fa0
The SCR register is needed for detecting if the card
supports certain commands like SET_BLOCK_COUNT.
Change-Id: I48cbf8fff497b71fb831ba546a462b27bb30851f
Because DMA is still running until CMD12 is issued the second
cache discard must occur after CMD12, otherwise the cache may
contain a stale copy of data. While the buffer is garbage at
this point it's probably not a good idea to leave the buffer
in a weird state where the cache doesn't match what's in RAM.
Change-Id: I7caf91d17631c92686ef0ad6f148e6c1d1bcbfa0