U-Boot: Difference between revisions
User890104 (talk | contribs) Add Nano 6G |
User890104 (talk | contribs) bootrom dumping |
||
| (One intermediate revision by the same user not shown) | |||
| Line 61: | Line 61: | ||
The command may fail the first time, retry one or two times before asking for help. | The command may fail the first time, retry one or two times before asking for help. | ||
=== Verifying if U-boot is running === | |||
After executing the exploit, check if U-boot started successfully. It should expose a DFU interface that provides 2 altsettings: firmware (0) and bootrom (1). The first can be used to boot the next firmware (U-boot, Linux, Rockbox, etc.), the second one can be used to dump the device's bootrom for further inspection. | |||
$ dfu-util --device 05ac:8007 --list | |||
=== Pushing an image to U-boot === | === Pushing an image to U-boot === | ||
You can send an U-Boot compatible image to the firmware endpoint of U-boot using dfu-util: | |||
$ dfu-util --device 05ac:8007 --download foo | $ dfu-util --device 05ac:8007 --alt firmware --download foo | ||
$ dfu-util --device 05ac:8007 --detach | $ dfu-util --device 05ac:8007 --detach | ||
| Line 72: | Line 78: | ||
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended). | Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended). | ||
=== Dumping the BootROM === | |||
You can dump the bootrom from the device using dfu-util. It can be used for reverse-engineering and debugging. | |||
$ dfu-util --device 05ac:8007 --alt bootrom --upload bootrom.bin | |||
The bootrom of the S5L87xx SoCs is 50 KiB (0xc800 bytes). It is unencrypted and contains ARM executable code. It is read-only, hence the -ROM suffix. | |||
== Work in progress== | == Work in progress== | ||
Latest revision as of 22:06, 9 August 2026
U-Boot Port
We've been working on an experimental U-Boot port for the iPod nano (2nd generation), iPod nano (3rd generation), iPod nano (5th generation), iPod nano (6th generation) and iPod nano (7th generation). It can be started using wInd3x and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.
The current port expects to be loaded in place of retailOS, eg. by packaging it into an IMG1 and sending it to WTF. This is what wInd3x does. This way, U-Boot does not have to do any of the 'annoying' early boot stuff like bringing up DRAM.
Getting the source
$ git clone git@github.com:freemyipod/u-boot.git $ cd u-boot
Configuring
$ make apple_n36_defconfig # iPod nano (2nd generation) $ make apple_n46_defconfig # iPod nano (3rd generation) $ make apple_n33_defconfig # iPod nano (5th generation) $ make apple_n20_defconfig # iPod nano (6th generation) $ make apple_n31_defconfig # iPod nano (7th generation)
Building
You'll need GCC for ARM (for bare metal targets, not for Linux targets), OpenSSL and GnuTLS.
On Linux distros that use apt, these can be installed using the following command.
# apt install gcc-arm-none-eabi libssl-dev gnutls-dev
Then, build the U-boot binary.
$ make CROSS_COMPILE=arm-none-eabi- u-boot.bin
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:
HOSTCFLAGS="-I/opt/homebrew/Cellar/openssl@3/3.6.1/include" HOSTLDFLAGS="-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib"
substituting your OpenSSL version/path as needed.
Running
If you have a 30-pin breakout cable with the UART pins connected to your computer (for iPod nano (6th generation) and older), or a Alex/DCSD cable (for iPod nano (7th generation)), you can see and interact with U-boot's console. Launch a serial client like picocom before running U-boot. Here is an example command line.
$ picocom --quiet --baud 115200 --imap lfcrlf /dev/ttyUSB0 # or whatever the correct port is
Make sure your user is in the dialout group or similar, so you can access serial ports.
If you have a regular cable, skip this command. USB DFU interface will still be accessible.
Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:
$ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.
iPod nano (3rd generation), iPod nano (5th generation), iPod nano (6th generation) and iPod nano (7th generation)
Connect your iPod in DFU Mode and use wInd3x to start U-Boot:
$ ./wInd3x cfw run u-boot.bin
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).
The command may fail the first time, retry one or two times before asking for help.
Verifying if U-boot is running
After executing the exploit, check if U-boot started successfully. It should expose a DFU interface that provides 2 altsettings: firmware (0) and bootrom (1). The first can be used to boot the next firmware (U-boot, Linux, Rockbox, etc.), the second one can be used to dump the device's bootrom for further inspection.
$ dfu-util --device 05ac:8007 --list
Pushing an image to U-boot
You can send an U-Boot compatible image to the firmware endpoint of U-boot using dfu-util:
$ dfu-util --device 05ac:8007 --alt firmware --download foo $ dfu-util --device 05ac:8007 --detach
Note the --detach command: this is needed to get U-Boot to exit DFU mode and actually execute the image.
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).
Dumping the BootROM
You can dump the bootrom from the device using dfu-util. It can be used for reverse-engineering and debugging.
$ dfu-util --device 05ac:8007 --alt bootrom --upload bootrom.bin
The bootrom of the S5L87xx SoCs is 50 KiB (0xc800 bytes). It is unencrypted and contains ARM executable code. It is read-only, hence the -ROM suffix.
Work in progress
You can run the iPod nano (5th generation) image on a iPod nano (4th generation) and it seems to be working at first glance.
Your mileage may vary. Patches welcome.
U-boot logs
<debug_uart> U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:02 +0300) CPU: Samsung S5L8701 (ARM940T) Model: Apple iPod nano (2nd generation) DRAM: 32 MiB Core: 8 devices, 7 uclasses, devicetree: separate MMC: Loading Environment from nowhere... OK In: uart@3cc00000 Out: uart@3cc00000 Err: uart@3cc00000 Net: No ethernet found. Hit any key to stop autoboot: 0
<debug_uart> U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:14 +0300) CPU: Samsung S5L8702 (ARM926EJ-S) Model: Apple iPod nano (3rd generation) DRAM: 32 MiB LCD: Type 38b3 (0) Core: 8 devices, 7 uclasses, devicetree: separate MMC: Loading Environment from nowhere... OK In: uart@3cc00000 Out: uart@3cc00000 Err: uart@3cc00000 Net: No ethernet found. Hit any key to stop autoboot: 0
<debug_uart> U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:25 +0300) CPU: Samsung S5L8730 (ARM1176JZF-S) Model: Apple iPod nano (5th generation) DRAM: 64 MiB LCD: Type 38b3 (0) Core: 8 devices, 7 uclasses, devicetree: separate MMC: Loading Environment from nowhere... OK In: uart@3cc00000 Out: uart@3cc00000 Err: uart@3cc00000 Net: No ethernet found. Hit any key to stop autoboot: 0
<debug_uart> U-Boot 2025.07-rc4-g5a3badf00973 (Aug 09 2026 - 17:57:17 +0300) CPU: Samsung S5L8723 (ARM1176JZF-S) Model: Apple iPod nano (6th generation) DRAM: 64 MiB Core: 8 devices, 7 uclasses, devicetree: separate MMC: Loading Environment from nowhere... OK In: uart@3cc00000 Out: uart@3cc00000 Err: uart@3cc00000 Net: No ethernet found. Hit any key to stop autoboot: 0
<debug_uart> U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:39 +0300) CPU: Samsung S5L8740 (ARM Cortex A5) Model: Apple iPod nano (7th generation) DRAM: 64 MiB Core: 10 devices, 7 uclasses, devicetree: separate MMC: Loading Environment from nowhere... OK In: uart@3dd00000 Out: uart@3dd00000 Err: uart@3dd00000 Net: No ethernet found. Hit any key to stop autoboot: 0