Changes

2,483 bytes removed ,  01:56, 27 January 2021
Line 8: Line 8:  
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| [[#PDN_SHAREDWRAM_32K_DATA|PDN_SHAREDWRAM_32K_DATA]]<0-7>
+
| [[#CFG11_SHAREDWRAM_32K_CODE|CFG11_SHAREDWRAM_32K_CODE]]<0-7>
 
| 0x10140000
 
| 0x10140000
 
| 1*8
 
| 1*8
Line 14: Line 14:  
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| [[#PDN_SHAREDWRAM_32K_CODE|PDN_SHAREDWRAM_32K_CODE]]<0-7>
+
| [[#CFG11_SHAREDWRAM_32K_DATA|CFG11_SHAREDWRAM_32K_DATA]]<0-7>
 
| 0x10140008
 
| 0x10140008
 
| 1*8
 
| 1*8
 
| Boot11, Process9, [[DSP Services]]
 
| Boot11, Process9, [[DSP Services]]
|-
+
|-style="border-top: double"
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| ?
+
| [[#CFG11_NULLPAGE_CNT|CFG11_NULLPAGE_CNT]]
 
| 0x10140100
 
| 0x10140100
| 2
+
| 4
 
|  
 
|  
 
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| ?
+
| [[#CFG11_FIQ_MASK|CFG11_FIQ_MASK]]
| 0x10140102
  −
| 2
  −
|
  −
|-
  −
| style="background: green" | Yes
  −
| ARM11 interrupt related.
   
| 0x10140104
 
| 0x10140104
 
| 1
 
| 1
Line 38: Line 32:  
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| ?
+
| Debug related bitfield?
 +
Observed: 0b1100(N3DS)/0b0000(O3DS)
 
| 0x10140105
 
| 0x10140105
 
| 1
 
| 1
| Kernel11.
+
|  
 
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| ?
+
| [[#CFG11_CDMA_CNT|CFG_CDMA_CNT]]
| 0x10140108
+
| 0x1014010C
 
| 2
 
| 2
 
| TwlBg
 
| TwlBg
 
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| ?
+
| [[#CFG11_GPUPROT|CFG11_GPUPROT]]
| 0x1014010C
  −
| 2
  −
|
  −
|-
  −
| style="background: green" | Yes
  −
| ?
   
| 0x10140140
 
| 0x10140140
| 2
+
| 4
|  
+
| Kernel11
 
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| [[#PDN_WIFI_CNT|PDN_WIFI_CNT]]
+
| [[#CFG11_WIFICNT|CFG11_WIFICNT]]
 
| 0x10140180
 
| 0x10140180
 
| 1
 
| 1
| TwlBg
+
| TwlBg, [[NWM Services]]
 
|-
 
|-
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| [[#PDN_SPI_CNT|PDN_SPI_CNT]]
+
| [[#CFG11_SPI_CNT|CFG11_SPI_CNT]]
 
| 0x101401C0
 
| 0x101401C0
| 4
+
| 2
 
| [[SPI Services]], TwlBg
 
| [[SPI Services]], TwlBg
|-
+
|-style="border-top: double"
 
| style="background: green" | Yes
 
| style="background: green" | Yes
 
| ?
 
| ?
 
| 0x10140200
 
| 0x10140200
 
| 4
 
| 4
|  
+
|
 
|-style="border-top: double"
 
|-style="border-top: double"
 
| style="background: red" | No
 
| style="background: red" | No
| Clock related?
+
| [[#CFG11_GPU_N3DS_CNT|CFG11_GPU_N3DS_CNT]]
 
| 0x10140400
 
| 0x10140400
 
| 1
 
| 1
| NewProcess11
+
| NewKernel11
 
|-
 
|-
 
| style="background: red" | No
 
| style="background: red" | No
| Clock related?
+
| [[#CFG11_CDMA_PERIPHERALS|CFG11_CDMA_PERIPHERALS]]
 
| 0x10140410
 
| 0x10140410
 
| 4
 
| 4
| NewProcess11
+
| NewKernel11
 
|-
 
|-
 
| style="background: red" | No
 
| style="background: red" | No
| [[#PDN_BOOTROM_OVERLAY_CNT|PDN_BOOTROM_OVERLAY_CNT]]
+
| [[#CFG11_BOOTROM_OVERLAY_CNT|CFG11_BOOTROM_OVERLAY_CNT]]
 
| 0x10140420
 
| 0x10140420
| 4
+
| 1
| NewProcess11
+
| NewKernel11
 
|-
 
|-
 
| style="background: red" | No
 
| style="background: red" | No
| [[#PDN_BOOTROM_OVERLAY_VAL|PDN_BOOTROM_OVERLAY_VAL]]
+
| [[#CFG11_BOOTROM_OVERLAY_VAL|CFG11_BOOTROM_OVERLAY_VAL]]
 
| 0x10140424
 
| 0x10140424
 
| 4
 
| 4
| NewProcess11
+
| NewKernel11
 
|-
 
|-
 
| style="background: red" | No
 
| style="background: red" | No
Line 107: Line 96:  
| 0x10140428
 
| 0x10140428
 
| 4
 
| 4
|  
+
|
 
|-style="border-top: double"
 
|-style="border-top: double"
 
| style="background: green" | Yes
 
| style="background: green" | Yes
| [[#PDN_MPCORE_CFG|PDN_MPCORE_CFG]]
+
| [[#CFG11_SOCINFO|CFG11_SOCINFO]]
 
| 0x10140FFC
 
| 0x10140FFC
| 1
  −
| NewKernel11
  −
|-style="border-top: double"
  −
| style="background: green" | Yes
  −
| PDN_GPU_STATUS?
  −
| 0x10141000
  −
| 4
  −
| Kernel11, TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| PDN_PTM_0
  −
| 0x10141008
  −
| 4
  −
| [[PTM Services]], [[PDN Services]]
  −
|-
  −
| style="background: green" | Yes
  −
| PDN_PTM_1
  −
| 0x1014100C
  −
| 4
  −
| [[PTM Services]], TwlBg, [[PDN Services]]
  −
|-style="border-top: double"
  −
| style="background: green" | Yes
  −
| [[#PDN_TWLMODE_0|PDN_TWLMODE_0]]
  −
| 0x10141100
  −
| 2
  −
| TwlProcess9, TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_TWLMODE_1|PDN_TWLMODE_1]]
  −
| 0x10141104
  −
| 2
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_TWLMODE_2|PDN_TWLMODE_2]]
  −
| 0x10141108
  −
| 2
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
|
  −
| 0x1014110A
  −
| 2
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| PDN_WIFI?
  −
| 0x1014110C
  −
| 1
  −
|
  −
|-
  −
| style="background: green" | Yes
  −
| ?
  −
| 0x10141110
  −
| 2
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| ?
  −
| 0x10141112
  −
| 2
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_CODEC|PDN_CODEC_0]]
  −
| 0x10141114
  −
| 2
  −
| [[CODEC Services]], TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_CODEC|PDN_CODEC_1]]
  −
| 0x10141116
   
| 2
 
| 2
| [[CODEC Services]], TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| ?
  −
| 0x10141118
  −
| 1
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| ?
  −
| 0x10141119
  −
| 1
  −
| TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| ?
  −
| 0x10141120
  −
| 1
  −
| TwlBg
  −
|-
  −
|-style="border-top: double"
  −
| style="background: green" | Yes
  −
| [[#PDN_GPU_CNT|PDN_GPU_CNT]]
  −
| 0x10141200
  −
| 4
  −
| Boot11, Kernel11, [[PDN Services]]
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_GPU_CNT2|PDN_GPU_CNT2]]
  −
| 0x10141204
  −
| 4
   
| Boot11, Kernel11
 
| Boot11, Kernel11
|-
  −
| style="background: green" | Yes
  −
| PDN_GPU_CNT3
  −
| 0x10141210
  −
| 2
  −
| Kernel11, TwlBg
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_CODEC_CNT|PDN_CODEC_CNT]]
  −
| 0x10141220
  −
| 1
  −
| Boot11, TwlBg, [[PDN Services]]
  −
|-
  −
| style="background: green" | Yes
  −
| [[#PDN_CAMERA_CNT|PDN_CAMERA_CNT]]
  −
| 0x10141224
  −
| 1
  −
| [[PDN Services]]
  −
|-
  −
| style="background: green" | Yes
  −
| PDN_DSP_CNT
  −
| 0x10141230
  −
| 1
  −
| Process9, [[PDN Services]]
  −
|-style="border-top: double"
  −
| style="background: red" | No
  −
| [[#PDN_MPCORE_STATUS|PDN_MPCORE_STATUS]]
  −
| 0x10141300
  −
| 2
  −
| NewProcess11
  −
|-
  −
| style="background: red" | No
  −
| [[#PDN_MPCORE_CNT|PDN_MPCORE_CNT]]
  −
| 0x10141304
  −
| 2
  −
| NewProcess11
  −
|-
  −
| style="background: red" | No
  −
| [[#PDN_MPCORE_BOOTCNT<0-3>|PDN_MPCORE_BOOTCNT]]<0-3>
  −
| 0x10141310
  −
| 1*4
  −
| NewProcess11
   
|}
 
|}
   −
== PDN_SHAREDWRAM_32K_DATA ==
+
== CFG11_SHAREDWRAM_32K_CODE ==
 
Used for mapping 32K chunks of shared WRAM for DSP data.
 
Used for mapping 32K chunks of shared WRAM for DSP data.
   Line 269: Line 113:  
|-
 
|-
 
| 0-1
 
| 0-1
| Master (0=ARM9?, 1=ARM11?, 2 or 3=DSP/data)
+
| Master (0=ARM9?, 1=ARM11?, 2 or 3=DSP/code)
 
|-
 
|-
 
| 2-4
 
| 2-4
Line 281: Line 125:  
|}
 
|}
   −
== PDN_SHAREDWRAM_32K_CODE ==
+
== CFG11_SHAREDWRAM_32K_DATA ==
 
Used for mapping 32K chunks of shared WRAM for DSP data.
 
Used for mapping 32K chunks of shared WRAM for DSP data.
   Line 289: Line 133:  
|-
 
|-
 
| 0-1
 
| 0-1
| Master (0=ARM9?, 1=ARM11?, 2 or 3=DSP/code)
+
| Master (0=ARM9?, 1=ARM11?, 2 or 3=DSP/data)
 
|-
 
|-
 
| 2-4
 
| 2-4
Line 301: Line 145:  
|}
 
|}
   −
== PDN_SPI_CNT ==
+
== CFG11_NULLPAGE_CNT ==
 
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
 
!  Bit
 
!  Bit
Line 307: Line 151:  
|-
 
|-
 
| 0
 
| 0
| Enable [[SPI Registers]] 0x10160000.
+
| Trap all ''data'' accesses to physmem addresses 0x0000 to 0x1000
|-
  −
| 1
  −
| Enable [[SPI Registers]] 0x10142000.
   
|-
 
|-
| 2
+
| 16
| Enable [[SPI Registers]] 0x10143800.
+
| Unknown
 
|}
 
|}
   −
== PDN_BOOTROM_OVERLAY_CNT ==
+
The reset value of this register is 0x10000.
Bit0: Enable bootrom overlay functionality.
+
 
 +
== CFG11_FIQ_MASK ==
 +
Write bit N to mask FIQ interrutps on core N? (judging from what Kernel11 does -- it only ever configures FIQ for core1)
   −
== PDN_BOOTROM_OVERLAY_VAL ==
+
Reset value: 0xF
The 32-bit value to overlay data-reads to bootrom with. See [[#PDN_MPCORE_BOOTCNT|PDN_MPCORE_BOOTCNT]].
     −
== PDN_MPCORE_CFG ==
+
== CFG11_CDMA_CNT ==
Read-only register.
+
Write 1 to enable, to disable.
    
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
Line 330: Line 172:  
|-
 
|-
 
| 0
 
| 0
| Always set to 1 on both Old3DS and New3DS.
+
| Enable Microphone DMA (CDMA 0x00)
 
|-
 
|-
 
| 1
 
| 1
| 3rd ARM11 MPCore available maybe?
+
| Enable NTRCARD DMA on Arm11 side (CDMA 0x01)
 +
|-
 +
| 2-4
 +
| ?
 
|-
 
|-
| 2
+
| 5
| 4th ARM11 MPCore available maybe?
+
| WiFi. Enabled during kernel init since 11.4.
 
|}
 
|}
   −
== PDN_MPCORE_STATUS ==
+
== CFG11_SPI_CNT ==
Read-only register.
+
When the corresponding bit is 0, the bus has to be accessed using the DS SPI registers. Otherwise it has to be accessed using the 3DS SPI registers.
 
   
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
Bits
+
Bit
 
!  Description
 
!  Description
 
|-
 
|-
 
| 0
 
| 0
| Always set to 1 on both Old3DS and New3DS.
+
| Enable [[SPI Registers]] 0x10160800.
 
|-
 
|-
 
| 1
 
| 1
| 3rd ARM11 MPCore powered on maybe?
+
| Enable [[SPI Registers]] 0x10142800.
 
|-
 
|-
 
| 2
 
| 2
| 4th ARM11 MPCore powered on maybe?
+
| Enable [[SPI Registers]] 0x10143800.
 
|}
 
|}
   −
== PDN_MPCORE_CNT ==
+
== CFG11_GPU_N3DS_CNT ==
 
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
Bits
+
Bit
 
!  Description
 
!  Description
 
|-
 
|-
 
| 0
 
| 0
| Power on 3rd ARM11 MPCore maybe?
+
| Enable N3DS mode? (enables access to the extra N3DS FCRAM banks, etc.)
 
|-
 
|-
| 8
+
| 1
| Power on 4th ARM11 MPCore maybe?
+
| Texture related? (observing texture glitches when disabling this bit)
 
|}
 
|}
   −
== PDN_MPCORE_BOOTCNT<0-3> ==
+
== CFG11_CDMA_PERIPHERALS ==
 
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
Bits
+
Bit
 
!  Description
 
!  Description
 
|-
 
|-
| 0
+
| 0-17
| Enable bootrom instruction overlay. This bit is only writable for core2 and core3.
+
| CDMA Peripheral 0x00-0x11 data request target (0=Old CDMA, 1=New CDMA)
|-
  −
| 1
  −
| Enable bootrom data overlay. This bit is only writable for core2 and core3.
  −
|-
  −
| 4
  −
| Has core booted maybe?
   
|-
 
|-
| 5
+
| 18-31
| Always 1?
+
| Unused
 
|}
 
|}
   −
The normal ARM11 bootrom checks cpuid and hangs if cpuid >= 2. This is a problem when booting the 2 additional New3DS ARM11 MPCores. NewKernel11 solves this by using a hardware feature to overlay the bootrom with a configurable branch to a kernel function. This overlay feature was added with the New3DS.
+
== CFG11_BOOTROM_OVERLAY_CNT ==
 +
Bit0: Enable bootrom overlay functionality.
   −
Bit1 in register above enables a bootrom data-override for physical addresses 0xFFFF0000-0xFFFF1000 and 0x10000-0x11000. All _data reads_ made to those regions now read the 32-bit value provided in [[#PDN_BOOTROM_OVERLAY_VAL|PDN_BOOTROM_OVERLAY_VAL]].
+
== CFG11_BOOTROM_OVERLAY_VAL ==
 +
The 32-bit value to overlay data-reads to bootrom with. See [[PDN Registers#PDN_LGR_CPU_CNT<0-3>|PDN_LGR_CPU_CNT]]<0-3>.
   −
Bit0 enables a bootrom instruction-overlay which means that _instruction reads_ made to the bootrom region are overridden. We have not been able to dump what instructions are actually placed at bootrom by this switch (because reading the area only yields data-reads). Jumping randomly into the 0xFFFF0000-0xFFFF1000 region works fine and jumps to the value provided by the data overlay [[#PDN_BOOTROM_OVERLAY_VAL|PDN_BOOTROM_OVERLAY_VAL]]. Thus we may predict that the entire bootrom region is filled by:
+
== CFG11_SOCINFO ==
ldr pc, [pc]
+
Read-only register. Identifies the maximum mode-switching capabilities of the SoC.
   −
Or equivalent. However, jumping to some high addresses such as 0xFFFF0FF0+ will crash the core. This may be explained by prefetching in the ARM pipeline, and might help us identify what instructions are placed by the instruction-overlay.
+
* CTR: O3DS
 +
* LGR1: N3DS prototype, 4 cores (orginally 2), up to 535MHz, no L2C (see below)
 +
* LGR2: retail N3DS, 4 cores, up to 804MHz, has L2C
   −
==PDN_WIFI_CNT==
+
Kernel code suggests that devices that support LGR1 but not LGR2 only had 2 cores. All cores (the number of which can be read from MPCORE SCU registers) are usable in LGR1 mode.
Bit0: Enable wifi.
     −
==PDN_TWLMODE_0==
+
{| class="wikitable" border="1"
Observed 0x8001 when running under TWL_FIRM, 0 NATIVE_FIRM.
+
!  Bits
 +
!  Description
 +
!  Used by
 +
|-
 +
| 0
 +
| CTR mode (1 on all 3DSes)
 +
| Boot11
 +
|-
 +
| 1
 +
| LGR1 (1 on all N3DSes, orginally 2 cores, and 2x clockrate)
 +
| Kernel11
 +
|-
 +
| 2
 +
| LGR2 (1 on all released N3DSes, 4 cores and 3x clockrate)
 +
| Kernel11
 +
|}
   −
The very last 3DS-mode register poke the [[FIRM|TWL_FIRM]] Process9 does before it gets switched into TWL-mode, is writing 0x8000 to this register. Before writing this register, TWL Process9 waits for the value of this register to become non-zero. The Process9 code for this runs from ITCM, since switching into TWL-mode includes remapping all ARM9 physical memory.
+
==CFG11_GPUPROT==
 +
{| class="wikitable" border="1"
 +
!  Old3DS
 +
!  Bits
 +
!  Description
 +
|-
 +
| style="background: green" | Yes
 +
| 3-0
 +
| Old FCRAM DMA cutoff size, 0 = no protection.
 +
|-
 +
| style="background: red" | No
 +
| 7-4
 +
| New FCRAM DMA cutoff size, 0 = no protection.
 +
|-
 +
| style="background: green" | Yes
 +
| 8
 +
| AXIWRAM protection, 0 = accessible.
 +
|-
 +
| style="background: red" | No
 +
| 10-9
 +
| QTM DMA cutoff size
 +
|-
 +
| style="background: green" | Yes
 +
| 31-11
 +
| Zeroes
 +
|}
   −
Writing 0x8000 to here from the ARM9 with NATIVE_FIRM running doesn't seem to do anything, other reg-pokes likely need done first.
+
For the old FCRAM DMA cutoff, it protects starting from 0x28000000-(0x800000*x) until end of FCRAM. There is no way to protect the first 0x800000-bytes.
   −
==PDN_TWLMODE_1==
+
For the new FCRAM DMA cutoff, it protects starting from 0x30000000-(0x800000*x) until end of FCRAM. When the old FCRAM cutoff is set to non-zero, the first 0x800000-bytes bytes of new FCRAM are protected.
Observed 0x8000 when running under TWL_FIRM, 0 NATIVE_FIRM.
     −
==PDN_GPU_CNT==
+
On New3DS the old+new FCRAM cutoff can be used at the same time, however this isn't done officially.
This one seems to control the LCD/GPU/Backlight.
     −
Bit0: Enable GPU registers at 0x10400000+.
+
For the QTM DMA cutoff, it protects starting from 0x1F400000-(0x100000*x) until end of QTM mem.
Bit16: Turn on LCD backlight.
     −
==PDN_GPU_CNT2==
+
On cold boot this reg is set to 0.
Bit0: Power on GPU?
     −
==PDN_CODEC==
+
When this register is set to value 0, the GPU can access the entire FCRAM, AXIWRAM, and on New3DS all QTM-mem.
The following is the only time the ARM11 CODEC module uses any 0x1EC41XXX registers. In one case CODEC module clears bit1 in register 0x1EC41114, in the other case CODEC module sets bit1 in registers 0x1EC41114 and 0x1EC41116.
     −
==PDN_CODEC_CNT==
+
[[SVC|Initialized]] during kernel boot, and used with [[SVC]] 0x59 which was implemented with [[11.3.0-36|v11.3]].
This is the power register used for the [[PDN_Services|PDN]] CODEC service.
     −
bit0 = unknown, bit1 = turn on/off DSP, rest = always 0.
+
==CFG11_WIFICNT==
 
+
{| class="wikitable" border="1"
==PDN_CAMERA_CNT==
+
!  Old3DS
This is the power register used for the [[PDN_Services|PDN]] camera service.
+
!  Bits
 
+
!  Description
bit0 = unknown, bit1 = turn on/off cameras, rest = always 0.
+
|-
 +
| style="background: green" | Yes
 +
| 0
 +
| Enable wifi subsystem
 +
|}
516

edits