<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace V5 Site Server v5.13.594-SNAPSHOT-1 (http://www.squarespace.com) on Wed, 16 Sep 2026 10:11:58 GMT--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>Journal</title><link>http://rosincore.squarespace.com/journal/</link><description></description><lastBuildDate>Fri, 09 Sep 2011 01:05:31 +0000</lastBuildDate><copyright></copyright><language>en-US</language><generator>Squarespace V5 Site Server v5.13.594-SNAPSHOT-1 (http://www.squarespace.com)</generator><item><title>LeapPad Explorer Reversing</title><dc:creator>nirvous</dc:creator><pubDate>Sat, 03 Sep 2011 00:47:17 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2011/9/2/leappad-explorer-reversing.html</link><guid isPermaLink="false">401811:4380550:12714110</guid><description><![CDATA[<p><span class="full-image-block ssNonEditable"><img style="width: 400px;" src="http://rosincore.squarespace.com/storage/LP-nirv.png?__SQUARESPACE_CACHEVERSION=1315016666725" alt="" /></span>One drawback of all of my recent work and travel is less time for other pursuits. Case in point: It has been a long, long time since I did any serious hacking. And like any habit, after a while, the &lsquo;jones&rsquo; gets to be too much to bear.</p>
<p>Last night I succumbed.</p>
<p>I found out from the good people on irc (freenode #Didj) that our friends at LeapFrog have released a 3<sup>rd</sup> generation of Linux-based handheld toys powered by the now-venerable ARM926EJ-S-based <a href="http://elinux.org/LeapFrog_Pollux_Platform">LF1000</a> CPU (aka Pollux):&nbsp; The new device, a tablet handheld called <a href="http://elinux.org/LeapPad_Explorer">LeapPad Explorer</a> (code name Madrid) has a 5-inch LCD, a built-in camera, boots off of eMMC connected to the SD controller (instead of NAND Flash as in prior devices) and adds an accelerometer to the mix. The mini tablet form-factor makes this an interesting candidate for alternate uses. (Portable o-scope or logic analyzer? G-force meter? True-to-scale tall-screen arcade emu handheld?)</p>
<p>Curiosity got the better of me and before I knew it I was in my local big-box retailer shelling out hard-earned dinero for fresh pristine hardware, ripe for reversing.</p>
<p>A night&rsquo;s work ensued, including sweeps with a continuity checker, a little de-soldering, some conformal coating stripper to soften the epoxy around the CPU and, finally, some hot-and-heavy action with a heatgun to reflow and remove the CPU. (The epoxy made chip-removal less than optimal, so some of the BGA balls didnt make it, but at least we can follow the traces.)</p>
<p><span class="full-image-block ssNonEditable"><img src="http://rosincore.squarespace.com/storage/BGAempty.png?__SQUARESPACE_CACHEVERSION=1315014302502" alt="" /></span></p>
<p>&nbsp;</p>
<p>What we've found thus far:</p>
<p>UART Serial on the cartridge socket. UART is on the same pins as on previous LF1000 devices, which <a href="https://sites.google.com/site/claudeschwarz/didjhacking2">claude first documented</a> on Didj way back when; so Moogle's <a href="http://jertechonline.com/">DJHI breakouts</a>&nbsp;<span style="text-decoration: line-through;">will </span><span style="text-decoration: line-through;">probably</span> work fine. (<span style="text-decoration: line-through;">I haven&rsquo;t tested this yet</span>) Edit: If at first the device doesn't boot with DJHI inserted, &nbsp;simply re-seat the DJHI and try again.</p>
<p>UART Serial on J5 &ndash; <a href="http://rosincore.squarespace.com/storage/LP-UART.png">VCC, Rx, Tx, Gnd</a>&nbsp; - this looks to be similar to the J5 on the Leapster Explorer.</p>
<p>JTAG &ndash; <a href="http://rosincore.squarespace.com/storage/LP-JTAG.png">nicely labeled, right there on the silkscreen</a> &ndash; and a big shoutout and props to the LeapFrog engineer(s) responsible for labeling the pads. Thank you. Your spot in heaven is assured. :)&nbsp;</p>
<p>TVOut &ndash; <a href="http://rosincore.squarespace.com/storage/LP-TVOut.png">TP125</a> is linked to good ol&rsquo; BGA grid square A2. Having gotten <a class="offsite-link-inline" href="http://hackaday.com/2010/06/30/didj-composite-video-out/" target="_blank">composite video working on&nbsp;Didj</a> and <a href="http://rosincore.com/journal/2010/8/25/leapster-explorer-jumbotronlx.html">Leapster Explorer</a> devices I have a soft spot in my heart for this test pad. (Traced, but not tested, stay tuned...)</p>
<p>USB - The pin header, J34, to which the camera was attached, is USB Device. Pins 2 and 3 on J34 are D+ and D-. Pin 4 is GND and Pin 5 (square) is VCC.&nbsp;</p>
<p>Here are the mainboard scans for the <a href="http://rosincore.squarespace.com/storage/LeapPad%20Explorer%20-%20Teardown%20-%20LeapPad%20Explorer%20-%20Mainboard%20-%20Front.jpg">front</a> and <a href="http://rosincore.squarespace.com/storage/LeapPad%20Explorer%20-%20Teardown%20-%20LeapPad%20Explorer%20-%20Mainboard%20-%20Rear.jpg">rear</a>&nbsp;(and the <a href="http://rosincore.squarespace.com/storage/LP-Rear-desoldered1-PS.jpg">rear following removal of the CPU and cartridge socket</a>).</p>
<p>Enjoy!</p>
<p><a rel="license" href="http://creativecommons.org/licenses/by-sa/3.0/"><img style="border-width: 0;" src="http://i.creativecommons.org/l/by-sa/3.0/88x31.png" alt="Creative Commons License" /></a><br />Images/content licensed under a <a rel="license" href="http://creativecommons.org/licenses/by-sa/3.0/">Creative Commons Attribution-ShareAlike 3.0 Unported License</a>.</p>
<p>n-</p>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-12714110.xml</wfw:commentRss></item><item><title>Augen eGo (Pollux) Linux shell and SD Card support</title><dc:creator>nirvous</dc:creator><pubDate>Sat, 13 Nov 2010 06:45:41 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2010/11/13/augen-ego-pollux-linux-shell-and-sd-card-support.html</link><guid isPermaLink="false">401811:4380550:9456601</guid><description><![CDATA[<p>Managed to get to a Linux shell prompt by UART booting a zimage based on the Leapster Explorer kernel source and an initramfs containing a custom rootfs and modules that support SD/MMC cards.</p>
<p>The kernel module setup needs more refinement...</p>
<pre>LF1000 # go 1800000
## Starting application at 0x01800000 ...
Uncompressing Linux............................................................................................................................................... done, booting the kernel.
Linux version 2.6.31-leapfrog (mgold@mgold-garage) (gcc version 4.4.3 (GCC) ) #40 Sat Nov 13 01:16:54 EST 2010
CPU: ARM926EJ-S [41069265] revision 5 (ARMv5TEJ), cr=00053177
CPU: VIVT data cache, VIVT instruction cache
Machine: ARM-LF1000
Warning: bad configuration page, trying to continue
Memory policy: ECC disabled, Data cache writeback
lf1000_oscvco_set.50  changing pll 0, old=0x00250001, new=0x00496300
PLL0=532.500000 MHz   
lf1000_oscvco_set.50  changing pll 1, old=0x00348E01, new=0x0024C402
PLL1=147.000 MHz   Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 27940
Kernel command line: init=/bin/busybox console=ttyS0,115200 mem=110M
PID hash table entries: 512 (order: 9, 2048 bytes)
Dentry cache hash table entries: 16384 (order: 4, 65536 bytes)
Inode-cache hash table entries: 8192 (order: 3, 32768 bytes)
Memory: 110MB = 110MB total
Memory: 106780KB available (2684K code, 314K data, 1608K init, 0K highmem)
NR_IRQS:42
TIM0=  4.593 MHz   TIM1=  4.593 MHz   TIM2=  4.593 MHz   TIM3=  4.593 MHz   TIM4=  4.593 MHz   
console [ttyS0] enabled
Calibrating delay loop (skipped) preset value.. 1065.00 BogoMIPS (lpj=5325000)
Mount-cache hash table entries: 512
CPU: Testing write buffer coherency: ok
NET: Registered protocol family 16
bio: create slab  at 0
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
NET: Registered protocol family 2
IP route cache hash table entries: 1024 (order: 0, 4096 bytes)
TCP established hash table entries: 4096 (order: 3, 32768 bytes)
TCP bind hash table entries: 4096 (order: 2, 16384 bytes)
TCP: Hash tables configured (established 4096 bind 4096)
TCP reno registered
NET: Registered protocol family 1
arch/arm/mach-lf1000/gpio_main.c.check_for_touchscreen:1346 X2 == high, no touchscreen
Reading Board ID =  0
msgmni has been set to 208
alg: No test for stdrng (krng)
io scheduler noop registered
io scheduler deadline registered (default)
Serial: 8250/16550 driver $Revision: 1.90 $ 4 ports, IRQ sharing disabled
serial8250: ttyS0 at MMIO 0x0 (irq = 10) is a 8250
serial8250: ttyS1 at MMIO 0x0 (irq = 34) is a 8250
serial8250: ttyS2 at MMIO 0x0 (irq = 35) is a 8250
serial8250: ttyS3 at MMIO 0x0 (irq = 36) is a 8250
brd: module loaded
loop: module loaded
ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
usb_hcd_lf1000_probe
hcd-&gt;regs: xc706e000
before ohci_hcd_init()
after ohci_hcd_init()
lf1000-ohci lf1000-ohci: LF1000 OHCI
lf1000-ohci lf1000-ohci: new USB bus registered, assigned bus number 1
lf1000-ohci lf1000-ohci: irq 28, io mem 0xc000d000
ohci-&gt;regs: xc706e000
&amp;ohci-&gt;regs-&gt;control: xc706e004
ioread32(&amp;ohci-&gt;regs-&gt;control): 0x0
after hcd-&gt;driver-&gt;start
usb usb1: configuration #1 chosen from 1 choice
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 2 ports detected
usb_add_hcd() returns 0
after usb_add_hcd()
usb_hcd_lf1000_probe returns
IRQ 31/lf1000-rtc: IRQF_DISABLED is not guaranteed on shared IRQs
lf1000-rtc lf1000-rtc: rtc core: registered lf1000-rtc as rtc0
LF1000 Real Time Clock driver.
i2c /dev entries driver
Software Watchdog Timer: 0.07 initialized. soft_noboot=0 soft_margin=60 sec (nowayout= 0)
setAudioRate: expected rate 32000Hz, actual: 32001Hz
*** MLC mlc_fb_addr=00000000 size=00000000 fb[0]=00000000 ***
lf1000-dpc driver
dpc: DPC not enabled, do config+enable
dpc: PWM clock rate is 9800000
input: LF1000 USB as /class/input/input0
lf1000_power_probe.647
input: Power Button as /class/input/input1
usb 1-1: new full speed USB device using lf1000-ohci and address 2
lf1000_power_probe.717 initial battery reading is :9575
input: LF1000 Keyboard as /class/input/input2
resource BUTTON_VOLUMEUP (16) port is undefined (-1)
resource BUTTON_VOLUMEUP (16) pin is undefined (-1)
resource BUTTON_VOLUMEDOWN (17) port is undefined (-1)
resource BUTTON_VOLUMEDOWN (17) pin is undefined (-1)
dm9000 Ethernet Driver, V1.31
Advanced Linux Sound Architecture Driver Version 1.0.20.
ALSA device list:
  No soundcards found.
TCP cubic registered
NET: Registered protocol family 17
lf1000-rtc lf1000-rtc: setting system clock to 1974-11-13 01:19:20 UTC (153537560)
Freeing init memory: 1608K
usb 1-1: device descriptor read/64, error -62
#
# Executing /init
#
sh: can't access tty; job control turned off
/ # usb 1-1: device descriptor read/64, error -62
usb 1-1: new full speed USB device using lf1000-ohci and address 3
usb 1-1: device descriptor read/64, error -62
usb 1-1: device descriptor read/64, error -62
usb 1-1: new full speed USB device using lf1000-ohci and address 4
usb 1-1: device not accepting address 4, error -62
usb 1-1: new full speed USB device using lf1000-ohci and address 5
usb 1-1: device not accepting address 5, error -62
hub 1-0:1.0: unable to enumerate USB device on port 1

/ # cat /proc/meminfo
MemTotal:         108540 kB
MemFree:          100960 kB
Buffers:               0 kB
Cached:             5016 kB
SwapCached:            0 kB
Active:              744 kB
Inactive:           4520 kB
Active(anon):        248 kB
Inactive(anon):        0 kB
Active(file):        496 kB
Inactive(file):     4520 kB
Unevictable:           0 kB
Mlocked:               0 kB
SwapTotal:             0 kB
SwapFree:              0 kB
Dirty:                 0 kB
Writeback:             0 kB
AnonPages:           272 kB
Mapped:              444 kB
Slab:               1788 kB
SReclaimable:        456 kB
SUnreclaim:         1332 kB
PageTables:           48 kB
NFS_Unstable:          0 kB
Bounce:                0 kB
WritebackTmp:          0 kB
CommitLimit:       54268 kB
Committed_AS:        640 kB
VmallocTotal:     278528 kB
VmallocUsed:       18592 kB
VmallocChunk:     246780 kB
/ # ls
bin         init        linuxrc     proc        usr
dev         lib         lost+found  sbin
etc         libold      mnt         sys
/ # modprobe lf1000_mmc
lf1000_mmc: Unknown symbol mmc_request_done
lf1000_mmc: Unknown symbol mmc_remove_host
lf1000_mmc: Unknown symbol mmc_alloc_host
lf1000_mmc: Unknown symbol mmc_add_host
lf1000_mmc: Unknown symbol mmc_free_host
# XXX: checking for SDIO...
lf1000-sdio lf1000-sdio: response timeout
lf1000-sdio lf1000-sdio: response timeout
lf1000-sdio lf1000-sdio: response timeout
lf1000-sdio lf1000-sdio: response timeout
XXX: checking for SD...
XXX: SD...
mmc0: host does not support reading read-only switch. assuming write-enable.
mmc0: new SD card at address 0001
/ # modprobe mmc_block
mmcblk0: mmc0:0001 00000 1.89 GiB 
 mmcblk0: p1
/ # mount /dev/mmcblk0p1 /mnt
/ # ls /mnt
initrd~1.gz         zImage-46M-WORKING  zimage~1
initrd~1.gz         zImage.NAND-LX      zimage~1
initrd~1.gz         zimage~1            zimage~1
trash-~1            zimage~1            zimage~2
zImage              zimage~1
/ # 
</pre>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-9456601.xml</wfw:commentRss></item><item><title>Augen eGo OE-A732 TV-Out pads!</title><dc:creator>nirvous</dc:creator><pubDate>Tue, 09 Nov 2010 06:25:31 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2010/11/9/augen-ego-oe-a732-tv-out-pads.html</link><guid isPermaLink="false">401811:4380550:9419574</guid><description><![CDATA[<p>In addition to the JTAG pads, a couple of very promising pads for composite TV-Out! These pads link to Pollux BGA ball A2 (composite video...)</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://rosincore.squarespace.com/storage/Tvout-Back1.png?__SQUARESPACE_CACHEVERSION=1289284612378" alt="" /></span></span>&nbsp;</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://rosincore.squarespace.com/storage/Tvout2-back.png?__SQUARESPACE_CACHEVERSION=1289284643103" alt="" /></span></span></p>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-9419574.xml</wfw:commentRss></item><item><title>Augen eGo OE-A732 JTAG pads</title><dc:creator>nirvous</dc:creator><pubDate>Tue, 09 Nov 2010 06:19:53 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2010/11/9/augen-ego-oe-a732-jtag-pads.html</link><guid isPermaLink="false">401811:4380550:9419558</guid><description><![CDATA[<p>Found JTAG pads on the Augen eGo (matching the Pollux BGA grid map).</p>
<p>On front:</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://rosincore.squarespace.com/storage/JTAG-FRONT.png?__SQUARESPACE_CACHEVERSION=1289283773078" alt="" /></span></span></p>
<p>On back:</p>
<p><span class="full-image-block ssNonEditable"><span class="full-image-block ssNonEditable"><span><img src="http://rosincore.squarespace.com/storage/JTAG-BACK.png?__SQUARESPACE_CACHEVERSION=1289283737543" alt="" /></span></span><br /></span></p>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-9419558.xml</wfw:commentRss></item><item><title>Leapster Explorer: JumbotronLX!</title><dc:creator>nirvous</dc:creator><pubDate>Thu, 26 Aug 2010 01:55:06 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2010/8/25/leapster-explorer-jumbotronlx.html</link><guid isPermaLink="false">401811:4380550:8678856</guid><description><![CDATA[<p><span class="full-image-block ssNonEditable"><span><img style="width: 470px;" src="http://rosincore.squarespace.com/storage/101_0674a.JPG?__SQUARESPACE_CACHEVERSION=1282789105408" alt="" /></span></span></p>
<p>The Leapster Explorer, a Linux-based children's handheld, is the follow-on product&nbsp;to the Didj. The Explorer runs the same ARM9-based SoC as its predecessor - one of our first tasks would be to uncover the Explorer's hidden TV-out mechanism.</p>
<p>I managed to overvolt my first Explorer by sending 5v into the USB host pins just days after I bought it. So, I purchased a second unit and dedicated the dead unit to 'science'. After desoldering the mainboard, I was able to trace from BGA grid A2 (Video) to the test pad TP30 '-Right'.</p>
<p><span class="full-image-block ssNonEditable"><span><img style="width: 300px;" src="http://rosincore.squarespace.com/storage/LX-TVout-Trace.jpg?__SQUARESPACE_CACHEVERSION=1282788518131" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>On my second Explorer, I soldered a short length of wire to TP30 and another to ground (cart socket), connected the ends to a composite connector, and modded the case.</p>
<p><span class="full-image-block ssNonEditable"><span><img style="width: 300px;" src="http://rosincore.squarespace.com/storage/101_0649.JPG?__SQUARESPACE_CACHEVERSION=1282789609034" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>I then used a 75 Ohm resistor as a filter - a simplified variant of the filter originally used in the&nbsp;<a href="http://rosincore.squarespace.com/journal/2010/6/29/didjumbotron.html">Didj TV Out hack</a>&nbsp;(no capacitors needed) -&nbsp;hooked up the oscilloscope, and got a good video waveform:</p>
<p><span class="full-image-block ssNonEditable"><span><img style="width: 300px;" src="http://rosincore.squarespace.com/storage/good_LX_waveform.png?__SQUARESPACE_CACHEVERSION=1282788541936" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>And a decent picture on my little test monitor.</p>
<p><span class="full-image-block ssNonEditable"><span><img style="width: 300px;" src="http://rosincore.squarespace.com/storage/101_0656.JPG?__SQUARESPACE_CACHEVERSION=1282788578745" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>The GBA emulator we <a href="http://rosincore.squarespace.com/journal/2010/8/11/didjemulator.html">recently ported</a> works fine on the TV too - that first picture at the top of this post is from Castlevania...</p>
<p>Updated <a href="http://elinux.org/Didj_and_Leapster_Explorer_TV_Out">TV-out steps covering Didj and Leapster Explorer</a> are on our <a href="http://elinux.org/Leapster_Explorer">wiki</a>&nbsp;(full mainboard scans too!)</p>
<p>Thanks and greetz to everyone on #Didj (irc.freenode.org)!</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-8678856.xml</wfw:commentRss></item><item><title>DIDJemulator!</title><dc:creator>nirvous</dc:creator><pubDate>Wed, 11 Aug 2010 17:11:31 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2010/8/11/didjemulator.html</link><guid isPermaLink="false">401811:4380550:8527282</guid><description><![CDATA[<div><span class="full-image-block ssNonEditable"><span><img style="width: 450px;" src="http://rosincore.squarespace.com/storage/Didj_gpSP.JPG?__SQUARESPACE_CACHEVERSION=1281549185810" alt="" /></span></span></div>
<div><strong>Its here!</strong>&nbsp;</div>
<p>Something to cheer about if you were having second thoughts about those 3 Didj handhelds you bought on Woot a couple of months back. At long last, we have successfully ported an emulator (Exophase's gpSP&nbsp;GBA emulator - specifically, notaz's GP2X Wiz version) to both the Leapster Explorer and the Didj.</p>
<p>Source code, documentation and Leapster Explorer binaries are available on <a href="http://github.com/nirvous/gpsp_lf1000">Github</a>.&nbsp;</p>
<p>For Didj, due to memory constraints, please follow&nbsp;<a href="http://elinux.org/Didj_gpSP_GBA_Emulator">these instructions</a>.</p>
<p>Thanks to Exophase and notaz for their superb work as well as to the great group on #Didj (freenode) - including GrizzlyAdams, PhilKll, zucchini, NullMoogleCable, Claude and many others...</p>
<p>&nbsp;<object width="290" height="180"><param name="movie" value="http://www.youtube.com/v/xYtrimSqZ3o&hl=en_US&fs=1&rel=0&border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/xYtrimSqZ3o&hl=en_US&fs=1&rel=0&border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="290" height="160"></embed></object></p>
<p>&nbsp;</p>
<div></div>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-8527282.xml</wfw:commentRss></item><item><title>DIDJumbotron!</title><dc:creator>nirvous</dc:creator><pubDate>Tue, 29 Jun 2010 22:51:19 +0000</pubDate><link>http://rosincore.squarespace.com/journal/2010/6/29/didjumbotron.html</link><guid isPermaLink="false">401811:4380550:8135801</guid><description><![CDATA[<p><span class="full-image-block ssNonEditable"><span><img style="width: 500px;" src="http://rosincore.squarespace.com/storage/plasma.JPG?__SQUARESPACE_CACHEVERSION=1277873289608" alt="" /></span></span></p>
<p>Easily bored? <a href="http://rosincore.squarespace.com/journal#videos">Skip to the videos</a>.</p>
<p>I've been experimenting with the Didj handheld these past months, really diving into the world of embedded development. The Didj is a handheld game from Leapfrog targeted at 5-10 year old children. Among the many interesting things about the Didj: The device runs Linux, and some time after the device was launched, kernel sources were made available. Powering the Didj is the LF1000, a variant of the ARM9-based MagicEyes Pollux 3520F application processor. That same part also powers the new Leapster Explorer and other handheld games like the GPH Wiz, the forthcoming GPH Caanoo handheld demonstrated at E3 recently, as well as other devices including GPS navigators, HD radios, netbooks, thin clients, etc.</p>
<p>There's a really great group of people working together to discover and map the nuances of this device. Among the interesting things we are exploring is the built-in Composite Video output capability native to the Pollux CPU. Other Pollux handhelds (the Wiz) have exposed TV-out capability to users. &nbsp;In our research (which you can see here:&nbsp;<a class="offsite-link-inline" href="http://elinux.org/Didj" target="_blank">http://elinux.org/Didj</a>) we discovered that&nbsp;the Didj seems to possess TV-out capability, but it was not exposed to the general user by the manufacturer.</p>
<p>More specifically, in teardowns we've done, we noticed a test pad (TP6) close to where we knew the CVBS(Composite) output was located on the CPU BGA map. We suspected it to be our Composite Video out. Later, in a more detailed teardown which included desoldering the CPU to access the traces underneath, we confirmed that TP6 was indeed the connection needed for composite video.</p>
<p><span class="thumbnail-image-block ssNonEditable"><span><a href="javascript:showFullImage('/display/ShowImage?imageUrl=%2Fstorage%2FBga-closeup-TP6.jpg%3F__SQUARESPACE_CACHEVERSION%3D1277853929486',1024,956);"><img src="http://rosincore.squarespace.com/storage/thumbnails/4380549-7535373-thumbnail.jpg?__SQUARESPACE_CACHEVERSION=1277853929488" alt="" /></a></span></span></p>
<p>&nbsp;</p>
<p>The remaining challenge was to figure out a way to make this test pad work.</p>
<p>As it happened, I was curious about how Linux graphics drivers worked, and wanted to teach myself how to build a graphics driver of my own. The Video Out problem seemed like a good way to dive in, so&nbsp;I spent lots of time looking at the kernel source code learning how it all worked together. (There really isn't a better way to learn.  I highly recommend just reading lots of code.).</p>
<p>It turns out that the drivers that ship with the Didj kernel sources have compiler pre-processor directives that can enable a 'Dual Display' mode, which pokes the appropriate CPU registers, and enables a framebuffer to be shared between the internal and external display. So the first thing I did was to fire up my cross compiler and build a new kernel with the appropriate directive (CONFIG_LF1000_DPC_DUAL_DISPLAY=y)  just to see if it would boot. Upon transferring it via the Pollux UART boot mechanism using my trusty <a class="offsite-link-inline" href="http://jertechonline.com/" target="_blank">DJHI breakout</a>, it booted up just fine. But since I had no connection yet, I could not verify if it worked.</p>
<p>With that, I figured that all that was needed to get this working was to physically access TP6, solder wire to it and to ground, and then connect the wire to a composite jack on the side of the device.</p>
<p>It wasn't that simple.</p>
<p>To begin with, I managed to fry the TP6 pad on my Didj. (Free advice: If your soldering iron has a temperature adjustment, set it properly. I did not pay attention to the fact that my iron was set waaay too hot, and the pad lifted right up.)</p>
<p>I ordered another device on eBay. It was a long 7 day wait. Once I got it, I opened it up, soldered IDE strands to TP6 and to ground (the cartridge socket), brought the connection out to an RCA jack on the side of the device, (I sacrificed one of the battery carriers) and then closed everything up.</p>
<p><br /><span class="thumbnail-image-block ssNonEditable"><span><a href="javascript:showFullImage('/display/ShowImage?imageUrl=%2Fstorage%2Fcomposite1.jpg%3F__SQUARESPACE_CACHEVERSION%3D1277860219694',768,1024);"><img src="http://rosincore.squarespace.com/storage/thumbnails/4380549-7536671-thumbnail.jpg?__SQUARESPACE_CACHEVERSION=1277860219695" alt="" /></a></span></span></p>
<p>I connected the RCA jack to my oscilloscope, booted up the Dual-display kernel, and...</p>
<p>...nothing. Or maybe it was something.</p>
<p>I expected a nice video waveform but instead I got a solid 3.6V. It looked like this:</p>
<p>&nbsp;</p>
<p><span class="thumbnail-image-block ssNonEditable"><span><a href="javascript:showFullImage('/display/ShowImage?imageUrl=%2Fstorage%2FNoJoy1.png%3F__SQUARESPACE_CACHEVERSION%3D1277854715121',697,880);"><img src="http://rosincore.squarespace.com/storage/thumbnails/4380549-7535487-thumbnail.jpg?__SQUARESPACE_CACHEVERSION=1277854715122" alt="" /></a></span></span></p>
<p>&nbsp;</p>
<p>I thought perhaps that the dual-display kernel wasn't working for some reason. So I took about a week of nightime work write my own user-space 'driver' to manually poke the appropriate registers on the CPU to enable dual-display. Looking at the kernel sources, it turns out there are a ton of registers to poke. And they need to be done in order.</p>
<p>Once I had my own test code ready, I threw that onto the device and ran it.</p>
<p>And I got the same 3.6V. (But at least I could, in theory, toggle the dual-display on and off).</p>
<p>At that point I sought out the advice of my fellow Didj hackers on freenode (#Didj).  PhilKll, Claude,  and GrizzlyAdams all suggested that some kind of filter circuit might be needed in order to work with what now looked to be a current-based Digital-to-Analog converter embedded in the Pollux CPU.</p>
<p>We figured a 75 Ohm resistor pulling TP6 to ground, and a 330pF cap in parallel would do the trick. &nbsp;I didn't have those specific parts, so I used parts I could scrounge up from my parts bin and from my local store (2x33 Ohm and 1x10 Ohm in series, and 2x100pF caps in parallel , plus the RCA connectors)</p>
<p>Here's what things looked like on the breadboard. (I've posted a schematic below the picture. As you can see on the breadboard, its pretty&nbsp;straightforward)&nbsp;</p>
<p>&nbsp;</p>
<p><span class="thumbnail-image-block ssNonEditable"><span><a href="javascript:showFullImage('/display/ShowImage?imageUrl=%2Fstorage%2Ftvout_breadboard.JPG%3F__SQUARESPACE_CACHEVERSION%3D1277857161321',768,1024);"><img src="http://rosincore.squarespace.com/storage/thumbnails/4380549-7535534-thumbnail.jpg?__SQUARESPACE_CACHEVERSION=1277857161322" alt="" /></a></span></span></p>
<p>&nbsp;<span class="thumbnail-image-block ssNonEditable"><span><a href="javascript:showFullImage('/display/ShowImage?imageUrl=%2Fstorage%2Fschematic.png%3F__SQUARESPACE_CACHEVERSION%3D1277874346768',159,618);"><img src="http://rosincore.squarespace.com/storage/thumbnails/4380549-7539353-thumbnail.jpg?__SQUARESPACE_CACHEVERSION=1277874346772" alt="" /></a></span></span></p>
<p>And with that, I connected what is basically a crude low-pass filter to my Didj and to the TV,and then booted the dual-display kernel.</p>
<p>&nbsp;</p>
<p><a name="videos">The results are here:</a></p>
<p>&nbsp;<object width="290" height="180"><param name="movie" value="http://www.youtube.com/v/NB4fvC6ph7Y&hl=en_US&fs=1&rel=0&border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/NB4fvC6ph7Y&hl=en_US&fs=1&rel=0&border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="290" height="160"></embed></object></p>
<p>&nbsp;It also works in color.</p>
<p><object width="290" height="180"><param name="movie" value="http://www.youtube.com/v/1Shss6s3UTc&hl=en_US&fs=1&rel=0&border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/1Shss6s3UTc&hl=en_US&fs=1&rel=0&border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="290" height="180"></embed></object></p>
<p>&nbsp;</p>
<p>For those of you who want to get started quickly, <a href="http://rosincore.squarespace.com/storage/zImage">I've uploaded a dual-display enabled kernel zImage</a> that you can place onto a microSD card which can be booted with our Lightning-Boot 1.4 boot loader.</p>
<p>I'll post dual-display how-to instructions to the <a class="offsite-link-inline" href="http://elinux.org/Didj" target="_blank">wiki</a> shortly.</p>
<p>Many many thanks to the folks on #Didj  (freenode) whose pioneering work enabled me to get this hack working, including Claude, GrizzlyAdams, jburks, losinggeneration,  NullMoogleCable, PhilKll, and many many more...</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://rosincore.squarespace.com/journal/rss-comments-entry-8135801.xml</wfw:commentRss></item></channel></rss>