U-Boot: Difference between revisions

From freemyipod
Jump to navigation Jump to search
No edit summary
bootrom dumping
 
(2 intermediate revisions by the same user not shown)
Line 1: Line 1:
== U-Boot Port ==
== U-Boot Port ==


We've been working on an experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]. It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.
We've been working on an experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]], [[Nano 6G]] and [[Nano 7G]]. It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.


The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an [[IMG1]] and sending it to [[WTF]]. This is what [[wInd3x]] does. This way, U-Boot does not have to do any of the 'annoying' early boot stuff like bringing up DRAM.
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an [[IMG1]] and sending it to [[WTF]]. This is what [[wInd3x]] does. This way, U-Boot does not have to do any of the 'annoying' early boot stuff like bringing up DRAM.
Line 15: Line 15:
  $ make apple_n46_defconfig # iPod nano (3rd generation)
  $ make apple_n46_defconfig # iPod nano (3rd generation)
  $ make apple_n33_defconfig # iPod nano (5th generation)
  $ make apple_n33_defconfig # iPod nano (5th generation)
$ make apple_n20_defconfig # iPod nano (6th generation)
  $ make apple_n31_defconfig # iPod nano (7th generation)
  $ make apple_n31_defconfig # iPod nano (7th generation)


Line 51: Line 52:
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.


==== [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] ====
==== [[Nano 3G]], [[Nano 5G]], [[Nano 6G]] and [[Nano 7G]] ====


Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:
Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:
Line 60: Line 61:


The command may fail the first time, retry one or two times before asking for help.
The command may fail the first time, retry one or two times before asking for help.
=== Verifying if U-boot is running ===
After executing the exploit, check if U-boot started successfully. It should expose a DFU interface that provides 2 altsettings: firmware (0) and bootrom (1). The first can be used to boot the next firmware (U-boot, Linux, Rockbox, etc.), the second one can be used to dump the device's bootrom for further inspection.
$ dfu-util --device 05ac:8007 --list


=== Pushing an image to U-boot ===
=== Pushing an image to U-boot ===


When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:
You can send an U-Boot compatible image to the firmware endpoint of U-boot using dfu-util:


  $ dfu-util --device 05ac:8007 --download foo
  $ dfu-util --device 05ac:8007 --alt firmware --download foo
  $ dfu-util --device 05ac:8007 --detach
  $ dfu-util --device 05ac:8007 --detach


Line 71: Line 78:


Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).
=== Dumping the BootROM ===
You can dump the bootrom from the device using dfu-util. It can be used for reverse-engineering and debugging.
$ dfu-util --device 05ac:8007 --alt bootrom --upload bootrom.bin
The bootrom of the S5L87xx SoCs is 50 KiB (0xc800 bytes). It is unencrypted and contains ARM executable code. It is read-only, hence the -ROM suffix.


== Work in progress==
== Work in progress==


You can run the [[Nano 5G]] image on a [[Nano 4G]] and it seems to be working at first glance.
You can run the [[Nano 5G]] image on a [[Nano 4G]] and it seems to be working at first glance.
You can run the [[Nano 5G]] image on a [[Nano 6G]], but if you don't stop the countdown before auto-booting, it gets stuck since the timer which is used to measure how much a second takes is not initialized properly. You can flood the UART console with key presses just while U-boot is printing the messages to skip the auto-boot prompt entiery and get dropped into a U-boot console.


Your mileage may vary. Patches welcome.
Your mileage may vary. Patches welcome.
Line 131: Line 144:
DRAM:  64 MiB
DRAM:  64 MiB
LCD:  Type 38b3 (0)
LCD:  Type 38b3 (0)
Core:  8 devices, 7 uclasses, devicetree: separate
MMC: 
Loading Environment from nowhere... OK
In:    uart@3cc00000
Out:  uart@3cc00000
Err:  uart@3cc00000
Net:  No ethernet found.
Hit any key to stop autoboot:  0
</pre>
=== [[Nano 6G]] ===
<pre>
<debug_uart>
U-Boot 2025.07-rc4-g5a3badf00973 (Aug 09 2026 - 17:57:17 +0300)
CPU:  Samsung S5L8723 (ARM1176JZF-S)
Model: Apple iPod nano (6th generation)
DRAM:  64 MiB
Core:  8 devices, 7 uclasses, devicetree: separate
Core:  8 devices, 7 uclasses, devicetree: separate
MMC:   
MMC:   

Latest revision as of 22:06, 9 August 2026

U-Boot Port

We've been working on an experimental U-Boot port for the iPod nano (2nd generation), iPod nano (3rd generation), iPod nano (5th generation), iPod nano (6th generation) and iPod nano (7th generation). It can be started using wInd3x and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.

The current port expects to be loaded in place of retailOS, eg. by packaging it into an IMG1 and sending it to WTF. This is what wInd3x does. This way, U-Boot does not have to do any of the 'annoying' early boot stuff like bringing up DRAM.

Getting the source

$ git clone git@github.com:freemyipod/u-boot.git
$ cd u-boot

Configuring

$ make apple_n36_defconfig # iPod nano (2nd generation)
$ make apple_n46_defconfig # iPod nano (3rd generation)
$ make apple_n33_defconfig # iPod nano (5th generation)
$ make apple_n20_defconfig # iPod nano (6th generation)
$ make apple_n31_defconfig # iPod nano (7th generation)

Building

You'll need GCC for ARM (for bare metal targets, not for Linux targets), OpenSSL and GnuTLS.

On Linux distros that use apt, these can be installed using the following command.

# apt install gcc-arm-none-eabi libssl-dev gnutls-dev

Then, build the U-boot binary.

$ make CROSS_COMPILE=arm-none-eabi- u-boot.bin

On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:

HOSTCFLAGS="-I/opt/homebrew/Cellar/openssl@3/3.6.1/include" HOSTLDFLAGS="-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib"

substituting your OpenSSL version/path as needed.

Running

If you have a 30-pin breakout cable with the UART pins connected to your computer (for iPod nano (6th generation) and older), or a Alex/DCSD cable (for iPod nano (7th generation)), you can see and interact with U-boot's console. Launch a serial client like picocom before running U-boot. Here is an example command line.

$ picocom --quiet --baud 115200 --imap lfcrlf /dev/ttyUSB0 # or whatever the correct port is

Make sure your user is in the dialout group or similar, so you can access serial ports.

If you have a regular cable, skip this command. USB DFU interface will still be accessible.

Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:

$ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod

Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.

Connect your iPod in DFU Mode and use wInd3x to start U-Boot:

$ ./wInd3x cfw run u-boot.bin

Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).

The command may fail the first time, retry one or two times before asking for help.

Verifying if U-boot is running

After executing the exploit, check if U-boot started successfully. It should expose a DFU interface that provides 2 altsettings: firmware (0) and bootrom (1). The first can be used to boot the next firmware (U-boot, Linux, Rockbox, etc.), the second one can be used to dump the device's bootrom for further inspection.

$ dfu-util --device 05ac:8007 --list

Pushing an image to U-boot

You can send an U-Boot compatible image to the firmware endpoint of U-boot using dfu-util:

$ dfu-util --device 05ac:8007 --alt firmware --download foo
$ dfu-util --device 05ac:8007 --detach

Note the --detach command: this is needed to get U-Boot to exit DFU mode and actually execute the image.

Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).

Dumping the BootROM

You can dump the bootrom from the device using dfu-util. It can be used for reverse-engineering and debugging.

$ dfu-util --device 05ac:8007 --alt bootrom --upload bootrom.bin

The bootrom of the S5L87xx SoCs is 50 KiB (0xc800 bytes). It is unencrypted and contains ARM executable code. It is read-only, hence the -ROM suffix.

Work in progress

You can run the iPod nano (5th generation) image on a iPod nano (4th generation) and it seems to be working at first glance.

Your mileage may vary. Patches welcome.

U-boot logs

<debug_uart>


U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:02 +0300)

CPU:   Samsung S5L8701 (ARM940T)
Model: Apple iPod nano (2nd generation)
DRAM:  32 MiB
Core:  8 devices, 7 uclasses, devicetree: separate
MMC:   
Loading Environment from nowhere... OK
In:    uart@3cc00000
Out:   uart@3cc00000
Err:   uart@3cc00000
Net:   No ethernet found.
Hit any key to stop autoboot:  0 
<debug_uart>


U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:14 +0300)

CPU:   Samsung S5L8702 (ARM926EJ-S)
Model: Apple iPod nano (3rd generation)
DRAM:  32 MiB
LCD:   Type 38b3 (0)
Core:  8 devices, 7 uclasses, devicetree: separate
MMC:   
Loading Environment from nowhere... OK
In:    uart@3cc00000
Out:   uart@3cc00000
Err:   uart@3cc00000
Net:   No ethernet found.
Hit any key to stop autoboot:  0 
<debug_uart>


U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:25 +0300)

CPU:   Samsung S5L8730 (ARM1176JZF-S)
Model: Apple iPod nano (5th generation)
DRAM:  64 MiB
LCD:   Type 38b3 (0)
Core:  8 devices, 7 uclasses, devicetree: separate
MMC:   
Loading Environment from nowhere... OK
In:    uart@3cc00000
Out:   uart@3cc00000
Err:   uart@3cc00000
Net:   No ethernet found.
Hit any key to stop autoboot:  0 
<debug_uart>


U-Boot 2025.07-rc4-g5a3badf00973 (Aug 09 2026 - 17:57:17 +0300)

CPU:   Samsung S5L8723 (ARM1176JZF-S)
Model: Apple iPod nano (6th generation)
DRAM:  64 MiB
Core:  8 devices, 7 uclasses, devicetree: separate
MMC:   
Loading Environment from nowhere... OK
In:    uart@3cc00000
Out:   uart@3cc00000
Err:   uart@3cc00000
Net:   No ethernet found.
Hit any key to stop autoboot:  0 
<debug_uart>


U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:39 +0300)

CPU:   Samsung S5L8740 (ARM Cortex A5)
Model: Apple iPod nano (7th generation)
DRAM:  64 MiB
Core:  10 devices, 7 uclasses, devicetree: separate
MMC:   
Loading Environment from nowhere... OK
In:    uart@3dd00000
Out:   uart@3dd00000
Err:   uart@3dd00000
Net:   No ethernet found.
Hit any key to stop autoboot:  0