Glitch is not so complex, its easy to analyze, the most complicated is to communicate with all existing emmc on each switch models (especially samsung emmc is garbage)
Yes yes I know. I know how spacecraft nx work, but on the emmc write function, the offset was controlled by the fpga and was not visible. So I wasn't sure where the payload was written.
But this is an ubuntu only version, I've heard about a working version that boot in HOS but restricted to an specific pico id. Is that the one you try to reverse / bypass or whatever ?
I'm curious to know, on what firmware did you start reverse engineering. I've seen a lot of random firmware drop in this thread, i'm little bit lost but I wan't to try to reverse engineering to.
If you have hekate, you can fix this (not really) by put this line into the "hekate_ipl.ini" : autohosoff=2. This immediately power off the switch when it detect a "woke up from HOS via an RTC alarm". It work for me (in real fact this is not really fix the problem, it just hide it).