Hacking Bricked EZFlash cart.

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania
Hello everyone! It seems that I've bricked the FPGA somehow during kernel update (which actually didn't happen at all since the update process was not even started - there was a message that something wrong with my sd card).

After that I couldn't enter the update menu at all. Actually, the EZOS even doesn't boot. My GBA just shows own boot logo and that's it. Maybe my sd card has corrupted the contents of the FPGA or NOR... or SPI flash on the back side. I've started checking the SPI, but I can't find its original image anywhere.

I was able to create a dump from SPI, but it would be nice to have at least the checksum of the contents to verify the image is correct. And, it also would be really nice to have the pinout for the jtag interface on the board (don't want to de-solder the FPGA to check which points are connected even though I can)... I assume it goes directly to FPGA, since NOR should be connected to FPGA directly...
So any help is appreciated. Thanks.
 
Last edited by k0walski,

mrgone

old man
Member
GBAtemp Patron
Joined
Nov 6, 2002
Messages
1,332
Trophies
3
Age
46
Location
close to the oktoberfest
XP
2,909
Country
Germany
Hello everyone! It seems that I've bricked the FPGA somehow during kernel update (which actually didn't happen at all since the update process was not even started - there was a message that something wrong with my sd card).

After that I couldn't enter the update menu at all. Actually, the EZOS even doesn't boot. My GBA just shows own boot logo and that's it. Maybe my sd card has corrupted the contents of the FPGA or NOR... or SPI flash on the back side. I've started checking the SPI, but I can't find its original image anywhere.

I was able to create a dump from SPI, but it would be nice to have at least the checksum of the contents to verify the image is correct. And, it also would be really nice to have the pinout for the jtag interface on the board (don't want to de-solder the FPGA to check which points are connected even though I can)... I assume it goes directly to FPGA, since NOR should be connected to FPGA directly...
So any help will be appreciated. Thanks.
you should make a new thread,
not resurrecting a 2 years old thread with a different content
 
  • Like
Reactions: k0walski

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania
you should make a new thread,
not resurrecting a 2 years old thread with a different content
Thank you very much for moving this post to the new thread. My 24h thread creation timeout should expire in half an hour I guess...
 

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania

DrunkenMonk

Well-Known Member
Member
Joined
Sep 30, 2007
Messages
523
Trophies
1
Age
31
XP
1,751
Country
United Kingdom
Yes, I've prepared sd-card earlier. Unfortunately the cart itself doesn't boot into the recovery mode at all. All I can see is Nintendo logo screen.

P.S. - or maybe there are other key combinations to enter recovery mode?
If you can dump the spi flash in it's current state then contact ez flash and give them the dump, they should be able to create a recovery dump for you that you can restore, that's what I ended up having to do after I encountered corruption from the pre-release test firmware before
 

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania
If you can dump the spi flash in it's current state then contact ez flash and give them the dump, they should be able to create a recovery dump for you that you can restore, that's what I ended up having to do after I encountered corruption from the pre-release test firmware before
That might work. But to whom should I send the dump?

Just small info... My current investigation lead me to the following:
SPI flash (on the back side of the board) has two entries, one at offset 0x10000, another - at 0x50000. Both entries have same size, but their checksums don't match. I assume it should be some kind of a boot loader used by FPGA... but FPGA itself doesn't seem to be working at all. I was able to boot the cart only two times... As a matter of fact, I've just ordered EZ Flash Omega DE.... (to have at least one working)...
 

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania
I do not recommend that users do the repair themselves, contacting the dealer for warranty is the fastest and best solution.
Well, I completely agree (in general). But in my case, I know what I'm doing and I know how do the bit-bang instead of h/w SPI protocol, how to compile an application for Z80 CPU using SDCC toolchain, Yocto and other stuff including PCB prototyping, flashing controllers etc...
That's why I'm kindly asking for the images for FPGA (restore contents, I won't ask for the source, of course), on-board JTAG pinout (wouldn't like to do guess work)... Ideally, verify the checksums for SPI flash on the back side... Because I've never seen the behavior I described before...
Of course if you can help. If it's not for sharing - that's ok, I understand, no problem.
Thanks!
 
  • Like
Reactions: The Real Jdbye

EZ-Flash2

Official EZ-FLASH Stuff
Member
Joined
Jul 16, 2003
Messages
1,109
Trophies
3
XP
3,492
Country
China
Well, I completely agree (in general). But in my case, I know what I'm doing and I know how do the bit-bang instead of h/w SPI protocol, how to compile an application for Z80 CPU using SDCC toolchain, Yocto and other stuff including PCB prototyping, flashing controllers etc...
That's why I'm kindly asking for the images for FPGA (restore contents, I won't ask for the source, of course), on-board JTAG pinout (wouldn't like to do guess work)... Ideally, verify the checksums for SPI flash on the back side... Because I've never seen the behavior I described before...
Of course if you can help. If it's not for sharing - that's ok, I understand, no problem.
Thanks!


Sorry, we can't provide FPGA data, anyone with this data will be able to clone card in large quantities, so contacting dealer is indeed a good way.
 
  • Like
Reactions: k0walski

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania
Sorry, we can't provide FPGA data, anyone with this data will be able to clone card in large quantities, so contacting dealer is indeed a good way.
I understand. It might have happened that I've bought one of these clones... That's probably why I'm getting such strange behavior. I'll try to contact the seller.
Thanks anyway!
 

k0walski

Well-Known Member
OP
Newcomer
Joined
Aug 10, 2021
Messages
88
Trophies
1
XP
741
Country
Lithuania
So, as a follow-up to this topic... I've got another cart. This time it's EZ Flash Omega DE. Which works perfectly. I've updated it (was a bit scary after I bricked the first one) successfully. So, I assume the first one wasn't original or, probably, faulty by-default. Anyway, now Omega DE works like a charm!
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://store.steampowered.com/bundle/34203/Tomb_Raider_Definitive_Survivor_Trilogy/ mmm