- 逆向:Ghidra/IDA 全量反编译 CoreSDKLib.dll/ThermalSDK.dll/libthermalSDK.so/ libcoresdk.so(ARM64)/libmagcore.so,导出 analysis/ida/export/ - 解码官方渲染管线:DDT 校准表加载->快门端点选择->Q12 插值->ref(4x type1 帧 均值)->NUC 查表->盲元补偿->窗口->LUT1024 重建->2x 升采样->调色板 - 逐像素验证:NUC+盲元 0/19200、插值 0 误差、2x 0/76800、窗口一致 - demo3 v5:完整复刻官方管线(含 DDT 解析、FFC 状态机、快门温度驱动), 修复 load_ddt 表错位导致的零像素问题 - 鬼影根因分析写入 analysis/reverse_20260813_full.md - 心跳/恢复机制:analysis/session_state.md + tools/resume_rev.ps1 - 新增 tsdk_pair3 增强采集工具;历史工具归档 csdk/tools/legacy/; 根目录抓帧残留删除,历史文档归档 analysis/history/ - csdk/README.md 完整使用文档;.gitignore/.gitattributes 补 LFS 规则
99 lines
3.6 KiB
C
99 lines
3.6 KiB
C
/* Verify the exact frame layout: print lengths and markers of the two
|
|
* bulk reads (header read + data read), and the tail bytes. */
|
|
#include <stdio.h>
|
|
#include <stdint.h>
|
|
#include <string.h>
|
|
#include <windows.h>
|
|
#include <libusb.h>
|
|
|
|
static libusb_context *g_ctx;
|
|
static libusb_device_handle *g_h;
|
|
|
|
static int sendcmd(unsigned magic, unsigned param, int len) {
|
|
unsigned char cmd[8] = {0};
|
|
cmd[0] = (unsigned char)(magic);
|
|
cmd[1] = (unsigned char)(magic >> 8);
|
|
cmd[2] = (unsigned char)(magic >> 16);
|
|
cmd[3] = (unsigned char)(magic >> 24);
|
|
if (len >= 8) {
|
|
cmd[4] = (unsigned char)(param);
|
|
cmd[5] = (unsigned char)(param >> 8);
|
|
cmd[6] = (unsigned char)(param >> 16);
|
|
cmd[7] = (unsigned char)(param >> 24);
|
|
}
|
|
int xfer = 0;
|
|
if (libusb_bulk_transfer(g_h, 0x03, cmd, len, &xfer, 2000)) return -1;
|
|
unsigned char resp[0x1000];
|
|
if (libusb_bulk_transfer(g_h, 0x82, resp, sizeof(resp), &xfer, 2000)) return -1;
|
|
return 0;
|
|
}
|
|
|
|
int main(void) {
|
|
if (libusb_init(&g_ctx)) return 1;
|
|
libusb_device **list = NULL;
|
|
ssize_t cnt = libusb_get_device_list(g_ctx, &list);
|
|
for (ssize_t i = 0; i < cnt && !g_h; ++i) {
|
|
struct libusb_device_descriptor d;
|
|
libusb_get_device_descriptor(list[i], &d);
|
|
if (d.idVendor == 0x833c) libusb_open(list[i], &g_h);
|
|
}
|
|
libusb_free_device_list(list, 1);
|
|
if (!g_h) { printf("no device\n"); return 1; }
|
|
libusb_set_configuration(g_h, 2);
|
|
libusb_set_configuration(g_h, 1);
|
|
libusb_claim_interface(g_h, 0);
|
|
sendcmd(0x6bb6b66b, 0, 4);
|
|
sendcmd(0x6bb6b66c, 0, 4);
|
|
sendcmd(0x6bb6b66f, 0, 4);
|
|
sendcmd(0x6bb6b672, 0, 8);
|
|
Sleep(100);
|
|
sendcmd(0x6bb6b672, 0, 8);
|
|
Sleep(300);
|
|
sendcmd(0x6bb6b673, 0, 4);
|
|
Sleep(700);
|
|
|
|
unsigned char hdr[64];
|
|
unsigned char buf[40000];
|
|
unsigned prev = 0xffffffff;
|
|
int frames = 0;
|
|
int ffc_done = 0;
|
|
|
|
while (frames < 6) {
|
|
int xfer = 0;
|
|
int rc = libusb_bulk_transfer(g_h, 0x81, hdr, sizeof(hdr), &xfer, 500);
|
|
if (rc || xfer < 28) { printf("hdr rc=%d xfer=%d\n", rc, xfer); Sleep(10); continue; }
|
|
printf("HDR read: xfer=%d marker=%02x %02x %02x %02x\n",
|
|
xfer, hdr[0], hdr[1], hdr[2], hdr[3]);
|
|
unsigned c = (unsigned)hdr[4] | ((unsigned)hdr[5] << 8) |
|
|
((unsigned)hdr[6] << 16) | ((unsigned)hdr[7] << 24);
|
|
if (c == prev) { printf(" dup frame %u\n", c); continue; }
|
|
prev = c;
|
|
xfer = 0;
|
|
rc = libusb_bulk_transfer(g_h, 0x81, buf, sizeof(buf), &xfer, 500);
|
|
printf("DATA read: rc=%d xfer=%d\n", rc, xfer);
|
|
if (xfer >= 8) {
|
|
printf(" first8: %02x %02x %02x %02x %02x %02x %02x %02x\n",
|
|
buf[0], buf[1], buf[2], buf[3], buf[4], buf[5], buf[6], buf[7]);
|
|
printf(" last8 : %02x %02x %02x %02x %02x %02x %02x %02x\n",
|
|
buf[xfer-8], buf[xfer-7], buf[xfer-6], buf[xfer-5],
|
|
buf[xfer-4], buf[xfer-3], buf[xfer-2], buf[xfer-1]);
|
|
}
|
|
frames++;
|
|
if (!ffc_done && frames == 2) { sendcmd(0x6bb6b672, 1, 8); ffc_done = 1; Sleep(200); }
|
|
/* also print type */
|
|
printf(" type=%u (from hdr[12])\n", (unsigned)hdr[12]);
|
|
/* search for 1b b1 b1 1c in the data buffer */
|
|
int found = -1;
|
|
for (int i = 0; i + 4 <= xfer; ++i)
|
|
if (buf[i]==0x1b && buf[i+1]==0xb1 && buf[i+2]==0xb1 && buf[i+3]==0x1c) { found = i; break; }
|
|
printf(" trailer 1bb1b11c found at offset %d\n", found);
|
|
}
|
|
Sleep(300);
|
|
libusb_clear_halt(g_h, 0x03);
|
|
libusb_clear_halt(g_h, 0x82);
|
|
sendcmd(0x6bb6b674, 0, 4);
|
|
libusb_close(g_h);
|
|
libusb_exit(g_ctx);
|
|
return 0;
|
|
}
|