2023年5月14日 星期日

露天賣家也會遇詐騙 -- 露天要求簽金流保障協議

 詳情請參考網友整理的 https://www.dcard.tw/f/mood/p/240515319

以下說明我的遭遇

私訊說要買的東西,然後無法下標,傳圖給我


說是他剛問了客服,說賣家的賣場沒有更新金流服務,要我去 https://rutenKF112.tw 處理。

說明要簽署的東西

然後,我就留下姓名手機,就有專員和我服務。半夜 11點多,還這麼熱心服務,真是熱心。我同時上露天找相關認證,都沒有。那就等他打電話來吧。

真的接到電話了,可是口音真重,我聽得模模糊糊的,還要我確定一堆東西。火大不賣了,我要早點睡,明天自己打電話問銀行比較快。

順手 Google "露天更新金流服務 詐騙",馬上就找到有人分享被騙的經驗。


2023年5月13日 星期六

阿米洛68鍵盤 -- firmware 修改

 鍵盤型號是 Miya68 Pro,PCB 型號是 Miya69-V2.2 (A)。MCU 上的文字是 HSAK3201 ARM。經過一翻努力追蹤,確定 MCU 是 Holtek 出的 HT32F1654。flash 內容是鎖住的,使用 eLink32Pro.exe 對 flash 執行 mass erase 操作後,就可以讀出晶片的資訊了。

在 PCB 上焊一個 4pin 的小接頭,pin 腳的間距是 1.24mm,所以要在原來的兩個孔之間再鑽一個小洞。只接了三條線,e-Link32 lite 和鍵盤各自用自己的電源。

使用 OpenOCD 讀取晶片的資訊。

設定檔 dap-tst.cfg 如下。因為使用 Ubuntu 的 openocd 套件,沒有HT32F1654 的資訊,先用 stm32f1x 的設定來讀資料。若要寫入資料,則需加入  HT32F1654 的資訊。

# openocd -f /app/dap-tst.cfg
adapter driver cmsis-dap
adapter speed 1000
transport select swd

source [find target/stm32f1x.cfg]

執行 openocd 的訊息如下。

# openocd -f /app/dap-tst.cfg
Open On-Chip Debugger 0.11.0
Licensed under GNU GPL v2
For bug reports, read
	http://openocd.org/doc/doxygen/bugs.html
Info : Listening on port 6666 for tcl connections
Info : Listening on port 4444 for telnet connections
Info : CMSIS-DAP: SWD  Supported
Info : CMSIS-DAP: FW Version = 1.0.35
Info : CMSIS-DAP: Interface Initialised (SWD)
Info : SWCLK/TCK = 0 SWDIO/TMS = 1 TDI = 0 TDO = 0 nTRST = 0 nRESET = 1
Info : CMSIS-DAP: Interface ready
Info : clock speed 1000 kHz
Info : SWD DPIDR 0x2ba01477
Info : stm32f1x.cpu: hardware has 6 breakpoints, 4 watchpoints
Info : starting gdb server for stm32f1x.cpu on 3333
Info : Listening on port 3333 for gdb connections

使用 telnet 連上 port 4444,執行 dap info 得到的資訊如下。假如還沒解鎖,執行 dap info 會回報錯誤。

/# telnet localhost 4444
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
Open On-Chip Debugger
> dap info

AP ID register 0x24770011
	Type is MEM-AP AHB3
MEM-AP BASE 0xe00ff003
	Valid ROM table present
		Component base address 0xe00ff000
		Peripheral ID 0x0000000000
		Designer ASCII code 0x00, <unknown>
		Part is 0x0, Unrecognized 
		Component class is 0x1, ROM table
		MEMTYPE system memory present on bus
	ROMTABLE[0x0] = 0xfff0f003
		Component base address 0xe000e000
		Peripheral ID 0x04002bb000
		Designer is 0x4bb, ARM Ltd
		Part is 0x0, Cortex-M3 SCS (System Control Space)
		Component class is 0xe, Generic IP component
	ROMTABLE[0x4] = 0xfff02003
		Component base address 0xe0001000
		Peripheral ID 0x04002bb002
		Designer is 0x4bb, ARM Ltd
		Part is 0x2, Cortex-M3 DWT (Data Watchpoint and Trace)
		Component class is 0xe, Generic IP component
	ROMTABLE[0x8] = 0xfff03003
		Component base address 0xe0002000
		Peripheral ID 0x04002bb003
		Designer is 0x4bb, ARM Ltd
		Part is 0x3, Cortex-M3 FPB (Flash Patch and Breakpoint)
		Component class is 0xe, Generic IP component
	ROMTABLE[0xc] = 0xfff01003
		Component base address 0xe0000000
		Peripheral ID 0x04002bb001
		Designer is 0x4bb, ARM Ltd
		Part is 0x1, Cortex-M3 ITM (Instrumentation Trace Module)
		Component class is 0xe, Generic IP component
	ROMTABLE[0x10] = 0xfff41003
		Component base address 0xe0040000
		Peripheral ID 0x04002bb923
		Designer is 0x4bb, ARM Ltd
		Part is 0x923, Cortex-M3 TPIU (Trace Port Interface Unit)
		Component class is 0x9, CoreSight component
		Type is 0x11, Trace Sink, Port
	ROMTABLE[0x14] = 0xfff42002
		Component not present
	ROMTABLE[0x18] = 0x0
		End of ROM table

由以上的訊息確定 MCU 的核心是 Cortex-M3。

使用 eLink32Pro.exe  寫入 pok3r-custom/pok3r_re_firmware 的    disassemble/pok3r/builtin/firmware_builtin.bin,連上電腦,顯示的裝置是 

Bus 001 Device 024: ID 04d9:1141 Holtek Semiconductor, Inc. USB-HID Keyboard

到此為止,成功解鎖以及寫入下載的 firmware,接下來就是要建立自己的 QMK 鍵盤,以及加上小紅點 (Trackpoint)。




2023年5月8日 星期一

OpenOCD 反向工程練習

主要的動機是要在鍵盤上加小紅點,想直接用鍵盤上原有的 MCU。目前拆解的鍵盤是阿米洛 68鍵鍵盤 Miya68 Pro,上面的主控是 HSAK3201,只知道是 Holtek 出的 ARM CPU。

參考連結:

先在 pcstore 買了一塊 [HT32F52352 開發套件(帶排針) ESK32-30501S],想先熟悉一下相關的操作和 HT32 系列 CPU 的相關資料。售價 NT$ 657,運費 NT$ 45,總計 NT$ 702。

先用 Holtek 網站下載的軟體在 Win10 下測試,無法透過 e-Link32 lite 連上開發板。只好再上 pcstore 買一塊 [Holtek 32-bit MCU 調試適配器 e-Link32 Pro],售價 NT$ 939 ,運費 NT$ 45,總計 NT$ 984。目前的總投資成本 NT$ 1,686。開始時還是不成功,又上蝦皮買 [USB 邏輯分析儀] 和一些線材,含運費 NT$ 384。總成本 2千多一些,這是為了一支垃圾鍵盤的控制 IC 所花費的成本,就當作練功的學費吧。

下圖是把 e-Link32 lite 拆下,再用杜邦線連目標開發板,電源各自獨立。 

後來,使用排線連接 e-Link 32  和開發板,都順利成功。追查原因才發現,e-Link32 lite 上的 CN3,是它自身的 SWD port,是讓別人來連它的,CN2 才是要連目標 CPU 的接頭。我一直都用 ST-Link 的想法,認為 CN3 是用來連目標 CPU 的。只能怪我在未測試功能正常前,就把 e-Link32 lite 拆下來了。至於多買的,等整個測試 OK 之後。再用網拍賣給其他需要的人吧。

使用 e-Link32 lite 連目標板,有時可以,有時不行,實在很困擾。交叉比對測試後,確認 reset 腳不用接,但 3.3V 的 VDD 腳要接。因為 e-Link32 lite 的 level shift IC 是由目標板供應的。但我的鍵盤只和 4個 PIN,其中一個 PIN 是 reset,3.3V VDD 沒接。最後把 CN3 和 CN2 的 VDD 接起來就 OK 了。

另外,jtag 的接線不能太長,照官方說法,不能超過 6吋,大約 12CM。我在開始把鍵盤 PCB 的 SWD 線接出時,轉接了好幾段線,超過 30公分,讀取資料就變得很不穩定。後來只留下一段接線,約 17CM,超過一些,但使用 1000kHz,還是可以穩定連線。

要進行反向工程,得先學習使用 OpenOCD,[Wrongbaud's Blog] 的文章是很好的入門教材。再參考一些其他的相關資料,建立了 OpenOCD 的 docker,透過 docker 來使用比較方便。

經反覆測試,最終能成功透過 OpenOCD 讀取開發板上的 MCU 的資訊。

自己建的 dap-tst.cfg 檔,如下。

adapter driver cmsis-dap
transport select swd
source [find target/stm32f1x.cfg]

執行 openocd 指令的畫面如下。

# openocd -f dap-tst.cfg 
Open On-Chip Debugger 0.11.0
Licensed under GNU GPL v2
For bug reports, read
        http://openocd.org/doc/doxygen/bugs.html
Info : Listening on port 6666 for tcl connections
Info : Listening on port 4444 for telnet connections
Info : CMSIS-DAP: SWD  Supported
Info : CMSIS-DAP: FW Version = 1.0.35
Info : CMSIS-DAP: Interface Initialised (SWD)
Info : SWCLK/TCK = 0 SWDIO/TMS = 1 TDI = 0 TDO = 0 nTRST = 0 nRESET = 1
Info : CMSIS-DAP: Interface ready
Info : clock speed 1000 kHz
Info : SWD DPIDR 0x0bc11477
Info : stm32f1x.cpu: hardware has 4 breakpoints, 2 watchpoints
Info : starting gdb server for stm32f1x.cpu on 3333
Info : Listening on port 3333 for gdb connections
Info : accepting 'telnet' connection on tcp/4444 
在外部無法透過 telnet 連上,進入同一個 container,則可以順利連上。先下個 dap info 指令,把初步的資訊 dump 出來。
# telnet localhost 4444
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
Open On-Chip Debugger
> init
> dap info
AP ID register 0x04770031
        Type is MEM-AP AHB3
MEM-AP BASE 0xe00ff003
        Valid ROM table present
                Component base address 0xe00ff000
                Peripheral ID 0x04000bb4c0
                Designer is 0x4bb, ARM Ltd
                Part is 0x4c0, Cortex-M0+ ROM (ROM Table)
                Component class is 0x1, ROM table
                MEMTYPE system memory present on bus
        ROMTABLE[0x0] = 0xfff0f003
                Component base address 0xe000e000
                Peripheral ID 0x04000bb008
                Designer is 0x4bb, ARM Ltd
                Part is 0x8, Cortex-M0 SCS (System Control Space)
                Component class is 0xe, Generic IP component
        ROMTABLE[0x4] = 0xfff02003
                Component base address 0xe0001000
                Peripheral ID 0x04000bb00a
                Designer is 0x4bb, ARM Ltd
                Part is 0xa, Cortex-M0 DWT (Data Watchpoint and Trace)
                Component class is 0xe, Generic IP component
        ROMTABLE[0x8] = 0xfff03003
                Component base address 0xe0002000
                Peripheral ID 0x04000bb00b
                Designer is 0x4bb, ARM Ltd
                Part is 0xb, Cortex-M0 BPU (Breakpoint Unit)
                Component class is 0xe, Generic IP component
        ROMTABLE[0xc] = 0x0
                End of ROM table

>  

假如 flash 被 lock 住的話,dap info 的指令會回報錯誤,執行 mass erase 之後,就可以取得 MCU 的資料了。

到這裡,算是成功的一小步,接下來有空再慢慢進一步的研究。


2023年5月7日 星期日

HT32F52352 開發套件(帶排針) ESK32-30501S

在 pcstore 買的,只此一個,被我買了就缺貨了。

ESK32-30501S使用盛群32位元Arm®Cortex®-M0+高性能、低功耗微控制器HT32F52352。

  • 工作頻率最高可達48 MHz
  • 128KB Flash、16KB SRAM
  • 內建多組 TIMER、2 個I2C、2個SPI、2個USART、2個UART、 1個12位元ADC、USB、I2S、EBI 等,可針對許多外部裝置進行試驗和開發原型
  • 採用 64LQFP 封裝
  • 採用 8.000 MHz External Crystal Clock
  • 51個可程式化通用 IO (GPIO) 腳位

相關文件下載: https://www.holtek.com.tw/esk32-30501,以及下載 [使用手冊]。

要安裝 [HT32 Virtual COM Driver],然後 [e-Link32 Pro ICP Tool] 才能抓到 e-Link 32 lite,並且更新 firmware。


2023年5月1日 星期一

阿米洛68鍵盤拆解

這把從淘寶買回來的垃圾鍵盤,價格還不便宜,接近新台幣一千,但好奇它有什麼好的,還是買來看看。這把的型號是 Miya68 Pro,由 Varmilo 和 Ducky 聯名推出。 

完全沒有螺絲,所以不要到處找螺絲,把外表都挖壞了。


這下面沒有螺絲,別挖了。凹痕是灌模的凹孔,這麼貴的東西,會壓成這樣也太不像話了點。鍵盤 PCB 的型號是 Miya69-V2.2 (A)。

要改裝鍵盤,第一個當然是先看是用什麼晶片,好不容易,用 marco 鏡頭照出比較清晰的型號 -- ARM HSAK3201。


Google 結果,很多鍵盤用這顆 MCU,但完全沒有相關資訊。最下面的字註明是 ARM CPU,應是 32bit 的 CPU。最後找到這一條訊息,

Controller: ARM HSAK3201, HOLTEK (via HWInfo)

Holtek,就是盛群。在鍵盤應用介紹的網頁找到一顆 MCU 的編號 HT66FB576。依據其文件說明,這是一個 USB RGB LED Flash MCU。不過在文件中說,這是一個 "8-bit high performance RISC",所以可能不是這一個 IC。另外有 "多彩獨立光USB鍵盤" 的應用指南。等有空再來比對接腳,看是不是這一顆 CPU。後來也確定不是。

在這裡可以找到各類相關的開發指南 https://www.holtek.com.tw/professional/usb-mcu

電路板上有 4顆 24pin 的 IC,編號是 HSAK021,後來比對網上其他鍵盤的拆解說明,應是內建 PWM 的 16bit 恒流 LED driver,如 Macroblock 的 MBI5043,但沒找到 HolTek 出的相關 IC。每個 IC 有 16條 LED 控制輸出,RGB 三種顏色分開控制。不過,我可能會把燈光給廢了吧,不想搞這麼複雜。



然後,在 pcstore 上找到一家 "倍創科技",專賣 Holtek 的開發工具,其中 32-bit MCU 燒錄器e-Writer32 售價為新台幣 2千多元。後來找到比較便宜的開發板,約 6百元。測試失敗,又花了快一千元買一塊 e-Link32 Pro,做交叉比對,最後都能成功連上。

比對 "多彩獨立光USB鍵盤" 應用指南與實際量到的電路矩陣,可說是完全使用其參考電路,這倒是比較方便追蹤,不用另外整理按鍵矩陣。

這鍵盤的固件 (firmware,為了搜尋方便,使用中國用語) 是可以更新的,也許可以在不改電路之下,更改鍵盤功能。參考此文,阿米洛68键双模键盘修改固件调换键位,阿米洛固件更新工具 M32 BootLoader_180724.exe,依命名來看,基本上就是 STM32 的 DFU 寫入程式。後來繼續查下去,確認 M32 BootLoader 是給較舊的鍵盤使用的。Miya68 Pro 的更新程式是把程式和資料包在一個執行檔裡,而且資料可能是加密過的。但是我只要確定使用的 MCU,再改用 QMK,所以不用管它原來的 firmware 長得什麼樣。

且先不要破壞電路,看能不能有什麼辦法確定使用的 MCU。在 Linux 連上後,列出的訊息如下。

[  269.812200] usb 1-8.1.2: new full-speed USB device number 9 using xhci_hcd
[  269.885558] usb 1-8.1.2: device descriptor read/64, error -32
[  270.065558] usb 1-8.1.2: device descriptor read/64, error -32
[  270.245532] usb 1-8.1.2: new full-speed USB device number 10 using xhci_hcd
[  270.336711] usb 1-8.1.2: New USB device found, idVendor=04d9, idProduct=8008, bcdDevice= 2.03
[  270.336726] usb 1-8.1.2: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[  270.336733] usb 1-8.1.2: Product: USB-HID Keyboard
[  270.336738] usb 1-8.1.2: Manufacturer: HOLTEK
[  270.336743] usb 1-8.1.2: SerialNumber: AP0000000003
[  270.352409] input: HOLTEK USB-HID Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.2/1-8.1.2:1.0/0003:04D9:8008.000A/input/input29
[  270.409145] hid-generic 0003:04D9:8008.000A: input,hidraw5: USB HID v1.11 Keyboard [HOLTEK USB-HID Keyboard] on usb-0000:00:14.0-8.1.2/input0
[  270.410300] hid-generic 0003:04D9:8008.000B: hiddev97,hidraw6: USB HID v1.11 Device [HOLTEK USB-HID Keyboard] on usb-0000:00:14.0-8.1.2/input1
[  270.412672] input: HOLTEK USB-HID Keyboard Mouse as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.2/1-8.1.2:1.2/0003:04D9:8008.000C/input/input30
[  270.412910] input: HOLTEK USB-HID Keyboard System Control as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.2/1-8.1.2:1.2/0003:04D9:8008.000C/input/input31
[  270.469110] input: HOLTEK USB-HID Keyboard Consumer Control as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.2/1-8.1.2:1.2/0003:04D9:8008.000C/input/input32
[  270.469257] input: HOLTEK USB-HID Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.2/1-8.1.2:1.2/0003:04D9:8008.000C/input/input33
[  270.469402] input: HOLTEK USB-HID Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.2/1-8.1.2:1.2/0003:04D9:8008.000C/input/input34
[  270.469606] hid-generic 0003:04D9:8008.000C: input,hiddev98,hidraw7: USB HID v1.11 Mouse [HOLTEK USB-HID Keyboard] on usb-0000:00:14.0-8.1.2/input2
[  270.470828] hid-generic 0003:04D9:8008.000D: hiddev99,hidraw8: USB HID v1.11 Device [HOLTEK USB-HID Keyboard] on usb-0000:00:14.0-8.1.2/input3
lsusb 列出的裝置如下。
# lsusb
Bus 001 Device 012: ID 04d9:8008 Holtek Semiconductor, Inc. USB-HID Keyboard

從這些訊息確定是盛群的 IC。

接下來幾天就跑去合歡山看杜鵑花了。出遊期間,腦袋不時會想著該怎麼做。偶爾上綱找一下資料,發現已經有人針對 Holtek 的 MCU 改過 QMK 了,[Quantum Mechanical Keyboard Firmware for POK3R]。繼續追下去,發現要解鎖 MCU 才能用,又找到了陌生的 OpenOCD。接下來就參雜使用 Holtek 的工具和 OpenOCD,試圖確認鍵盤所使用的 MCU。

繞一大圈之後,讀了網上高手的逆向工程教學,有一些基本能力後,開始各種嘗試。

試著使用 HT32 ICP TOOL (V 1.0.39) 來讀取 firmware 的資料,從第一個 target 開始一個一個選,顯示訊息都是 "Target MCU unmatch!"。

直到倒數沒幾個,接近失望之際,BINGO !  選到 HT32F1654,按下 [Read],顯示訊息變成 "Chip is Locked!"。

接下來的工作就會變比較簡單了,有前人的作法可以參考。

HT32F1653, HT32F1654, HT32F1655, HT32F1656 是同一系列的 MCU -- Cortex-M3 32-Bit Standard MCU,差別在於 Flash 和 SRAM 的大小。HT32F1654 的 Flash 是 64KB,SRAM  是 16KB。

最後,這顆 MCU 已停產,盛群網上公告的訊息,"Holtek 正式提出 HT32F1653/HT32F1654 產品終止到期。上述所提產品之最終訂單截止日為2022年9月30日"。所以官網上找不到它的 datasheet,只能在其他地方下載。 





2023年4月30日 星期日

STM32F103 開發板連接 Trackpoint 測試

測試硬體

要改用 STM32F103 開發板來改裝小紅點鍵盤,首先弄個簡單的測試電路來測試連接 trackpoint 的基本功能。小紅點模組不能直接鎖在電路板上,自己用3D印表機打印了一個固定小紅點模組的固定板。


這塊 trackpoint module 經測試可以使用 3.3V 的電源,但是 DAT 及 CLK 的信號線要用 4.7K 的電阻 pull high  至3.3V。

關於 trackpoint 的設定檔參考 handwired/trackpoint 的設定。關於 STM32F103 的設定則是參考 doio/kb16/rev2 的設定。

因為不同的 bootloader 要有不同的設定,為了支援  dfu-util,又重燒 STM32duino-bootloader。直接下載 binary 檔 generic_boot20_pc13.bin 即可,這個檔是指 LED 接在 PC13 的接腳。

設定檔案

首先測試簡單的 busywait 運作模式,確認電路連接正常。

info.json 如下。

{
    "keyboard_name": "Trackpoint Demo",
    "manufacturer": "QMK",
    "url": "",
    "maintainer": "qmk",
    "usb": {
        "vid": "0x1234",
        "pid": "0x5678",
        "device_version": "0.0.1"
    },
    "processor": "atmega32u4",
    "bootloader": "halfkay",
    "layouts": {
        "LAYOUT": {
            "layout": [
                {"x": 0,"y": 0},
                {"x": 1,"y": 0},
                {"x": 2,"y": 0}
            ]
        }
    }
}

主要是指定 USB 相關的資訊,compile 時會讀取。vid 和 pid 應是亂設的,使用 lsusb 看到的資訊如下。

Bus 001 Device 026: ID 1234:5678 Brain Actuated Technologies Trackpoint Demo

rules.mk 如下。內容是抄來的,有些意義不是很了解,但可通過編譯,就留著不管了。

# MCU name
MCU = STM32F103

OPT_DEFS += -DBOOTLOADER_STM32DUINO
MCU_LDSCRIPT = STM32F103xB_stm32duino_bootloader
BOARD = STM32_F103_STM32DUINO

# Bootloader selection
BOOTLOADER = custom

# Build Options
#   change yes to no to disable
#
BOOTMAGIC_ENABLE = yes      # Enable Bootmagic Lite
MOUSEKEY_ENABLE = no        # Mouse keys
EXTRAKEY_ENABLE = yes       # Audio control and System control
CONSOLE_ENABLE = no         # Console for debug
COMMAND_ENABLE = no         # Commands for debug and configuration
NKRO_ENABLE = yes           # Enable N-Key Rollover
BACKLIGHT_ENABLE = no       # Enable keyboard backlight functionality
RGBLIGHT_ENABLE = no        # Enable keyboard RGB underglow
AUDIO_ENABLE = no           # Audio output

# Enter lower-power sleep mode when on the ChibiOS idle thread
OPT_DEFS += -DCORTEX_ENABLE_WFI_IDLE=TRUE

PS2_MOUSE_ENABLE = yes
PS2_ENABLE = yes
PS2_DRIVER = busywait
#PS2_DRIVER = interrupt

先測最簡單的 busywait 運作模式,先把 interrupt 的部分註解掉。

config.h 如下。只設定了三個按鍵,可以測試鍵盤功能。
#pragma once

#define MATRIX_COL_PINS { B3, B4, B5 }
#define MATRIX_ROW_PINS { B0 }

/* COL2ROW or ROW2COL */
#define DIODE_DIRECTION COL2ROW

#define LOCKING_SUPPORT_ENABLE
#define LOCKING_RESYNC_ENABLE

#ifdef PS2_DRIVER_BUSYWAIT
  #define PS2_CLOCK_PIN   B8
  #define PS2_DATA_PIN    B9

  #define PS2_MOUSE_USE_REMOTE_MODE
#endif

#ifdef PS2_DRIVER_INTERRUPT
  #define PS2_CLOCK_PIN B8
  #define PS2_DATA_PIN  B9
#endif

其中會依 rules.mk 設定的運作模式決定引入相關定義。把接腳都設成一樣的 PIN,改變運作棤式,不需要改接線。

stm32test.h 如下。
#pragma once

#include "quantum.h"

#define LAYOUT( \
  K00, K01, K02  \
) { \
  { K00, K01, K02} \
}
stm32test.c 只有一行,如下。
#include "stm32test.h"

編譯

執行下面的指令開始編譯。
qmk compile -kb ajtest/stm32test -km default"
很不幸出現下面的錯誤。
......
platforms/chibios/drivers/ps2/ps2_io.c: In function 'clock_lo':
./keyboards/ajtest/stm32test/config.h:13:27: error: 'B8' undeclared (first use in this function)
   13 |   #define PS2_CLOCK_PIN   B8
      |                           ^~
...........
platforms/chibios/drivers/ps2/ps2_io.c: In function 'data_lo':
./keyboards/ajtest/stm32test/config.h:14:27: error: 'B9' undeclared (first use in this function)
   14 |   #define PS2_DATA_PIN    B9
      |                           ^~
Google 找到答案,platforms/chibios/drivers/ps2/ps2_io.c 要加入一行 include,如下。
#include <stdbool.h>
#include "ps2_io.h"
#include "gpio.h"

// chibiOS headers
#include "ch.h"
#include "hal.h"
可以成功 compile,但在 link 時出錯。
Linking: .build/ajtest_stm32test_default.elf                                                        [ERRORS]
 | 
 | /usr/lib/gcc/arm-none-eabi/10.3.1/../../../arm-none-eabi/bin/ld: .build/obj_ajtest_stm32test_default/ps2_mouse.o: in function `ps2_mouse_task':
 | /home/ajax/qmk_firmware/drivers/ps2/ps2_mouse.c:93: undefined reference to `pbuf_has_data'
 | collect2: error: ld returned 1 exit status
 | 
gmake[1]: *** [builddefs/common_rules.mk:267: .build/ajtest_stm32test_default.elf] Error 1
gmake: *** [Makefile:392: ajtest/stm32test:default] Error 1

在這裡卡了好久,搜尋程式碼,`pbuf_has_data' 只有定義在 drivers/ps2/ps2_interrupt.c 中,而 ps2_busywait.c 中沒有這一個 function。

後來看到 ps2_mouse.c 中呼叫 `pbuf_has_data' 的前面,有作判斷 

"#ifdef PS2_MOUSE_USE_REMOTE_MODE"

意思是使用 remote moe 就不會呼叫此 function。否則使用 stream mode,此模式最好使用 interrupt 運作方式。

在 config.h 加入 "#define PS2_MOUSE_USE_REMOTE_MODE" 後,成功產生 bin 檔。

燒錄

使用 docker 環境,需使用 usb 裝置及 privileged 參數。執行指令如下。

docker run -it --privileged \
    -v /dev/bus/usb:/dev/bus/usb \
    -v `pwd`:/work  \
    qmk-dev bash

可將開發板的 boot0 接到 1,連上電腦,使用 dfu-util 列出裝置。

-----------------------------------
# dfu-util --list
dfu-util 0.11

Found DFU: [1eaf:0003] ver=0201, devnum=8, cfg=1, intf=0, path="1-8.1.1", alt=2, name="STM32duino bootloader v1.0  Upload to Flash 0x8002000", serial="LLM 003"
Found DFU: [1eaf:0003] ver=0201, devnum=8, cfg=1, intf=0, path="1-8.1.1", alt=1, name="STM32duino bootloader v1.0  Upload to Flash 0x8005000", serial="LLM 003"
Found DFU: [1eaf:0003] ver=0201, devnum=8, cfg=1, intf=0, path="1-8.1.1", alt=0, name="STM32duino bootloader v1.0  ERROR. Upload to RAM not supported.", serial="LLM 003"
-----------------------------------

使用下列指令燒入 bin 檔

------------------------------------------
# dfu-util -D ajtest_stm32test_default.bin -a 2
dfu-util 0.11

dfu-util: Warning: Invalid DFU suffix signature
dfu-util: A valid DFU suffix will be required in a future dfu-util release
Opening DFU capable USB device...
Device ID 1eaf:0003
Device DFU version 0110
Claiming USB DFU Interface...
Setting Alternate Interface #2 ...
Determining device status...
DFU state(2) = dfuIDLE, status(0) = No error condition is present
DFU mode device DFU version 0110
Device returned transfer size 1024
Copying data from PC to DFU device
Download [=========================] 100%        23248 bytes
Download done.
DFU state(8) = dfuMANIFEST-WAIT-RESET, status(0) = No error condition is present
Resetting USB to switch back to runtime mode
Done!
------------------------------------------

再把 boot0 跳線回 0,重新接上電腦,使用 dmesg 看到下列訊息

-------------------------------------------------
[  813.021552] usb 1-8.1.1: new full-speed USB device number 11 using xhci_hcd
[  813.113109] usb 1-8.1.1: New USB device found, idVendor=1234, idProduct=5678, bcdDevice= 0.01
[  813.113123] usb 1-8.1.1: New USB device strings: Mfr=1, Product=2, SerialNumber=0
[  813.113130] usb 1-8.1.1: Product: Trackpoint Demo
[  813.113135] usb 1-8.1.1: Manufacturer: QMK
[  813.121950] input: QMK Trackpoint Demo as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.1/1-8.1.1:1.0/0003:1234:5678.000C/input/input33
[  813.178954] hid-generic 0003:1234:5678.000C: input,hidraw0: USB HID v1.11 Keyboard [QMK Trackpoint Demo] on usb-0000:00:14.0-8.1.1/input0
[  813.180015] input: QMK Trackpoint Demo as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.1/1-8.1.1:1.1/0003:1234:5678.000D/input/input34
[  813.180655] hid-generic 0003:1234:5678.000D: input,hidraw1: USB HID v1.11 Mouse [QMK Trackpoint Demo] on usb-0000:00:14.0-8.1.1/input1
[  813.182002] input: QMK Trackpoint Demo System Control as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.1/1-8.1.1:1.2/0003:1234:5678.000E/input/input35
[  813.238550] input: QMK Trackpoint Demo Consumer Control as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.1/1-8.1.1:1.2/0003:1234:5678.000E/input/input36
[  813.238850] input: QMK Trackpoint Demo Keyboard as /devices/pci0000:00/0000:00:14.0/usb1/1-8/1-8.1/1-8.1.1/1-8.1.1:1.2/0003:1234:5678.000E/input/input37
[  813.239723] hid-generic 0003:1234:5678.000E: input,hidraw2: USB HID v1.11 Keyboard [QMK Trackpoint Demo] on usb-0000:00:14.0-8.1.1/input2
-------------------------------------------------

使用鍵盤測試程式,測試鍵盤功能正確。

測試 interrupt 運作模式

接下來測試 interrupt 的運作模式。QMK 中,對於 stm32 並沒有支援 best 的 USART 運作模式,只能退而求其,使用 better 的 interrupt 運作模式。

按照 QMK 的說明,除了設定 rules.mk 和 config.h 的設定值外,還要修改 

platforms/chibios/boards/common/configs/halconf.h

加入 "#define PAL_USE_CALLBACKS   TRUE",為了確保有一定會加上,我是把原來設定為 FALSE 的設定註解掉,把新的設定放在判斷區塊之外。

修改後,執行編譯再次出現錯誤誤。

......
drivers/ps2/ps2_interrupt.c: In function 'ps2_host_init':
./keyboards/ajtest/stm32test/config.h:20:25: error: 'B8' undeclared (first use in this function)
   13 |   #define PS2_CLOCK_PIN   B8
      |                           ^~
...........
drivers/ps2/ps2_interrupt.c: In function 'ps2_host_send':
./keyboards/ajtest/stm32test/config.h:20:25: error: 'B8' undeclared (first use in this function)
   14 |   #define PS2_DATA_PIN    B8
      |                           ^~
在 drivers/ps2/ps2_interrupt.c 加上 include 即可,如下。
#if defined(__AVR__)
#    include <avr/interrupt.h>
#elif defined(PROTOCOL_CHIBIOS) // TODO: or STM32 ?
// chibiOS headers
  #include "gpio.h"
#    include "ch.h"
#    include "hal.h"
#endif                           ^~
編譯成功。燒錄至開發板,測試功能正常。接下來就可以改裝有小紅點功能的鍵盤了。



2023年4月27日 星期四

STM32F103 開發板改裝 stm32-hid-bootloader

 確定可以使用 ST-LINK 燒錄 STM32F103 開發板後,就可以選擇自己喜歡的 bootloader 了。在測試燒錄功能時,照著教學的步驟燒了 STM32duino-bootloader,但其要配合  Arduino IDE 使用。我只想做 QMK 的鍵盤程式,它有自己的開發環境,所以我只要單純的 bootloader,能寫入程式即可。

假如有用 Vial GUI 的話,那使用 vial-kb / vibl 會比較方便。但我才剛起步,鍵盤連個影子都沒,就用 vibl 所參考的,輕薄短小的 bootsector / stm32-hid-bootloader 吧。

和 STM32duino-bootloader 的 bin 檔為 22KB,stm32-hid-bootloader 號稱只有 4KB,真的小很多。

stm32-hid-bootloader 沒有提供編譯好的 bin 檔,所以自己得要有 stm32 的開發環境才行。用 docker 來建立開發環境是比較好的選擇,不會把自己的電腦弄亂。

參考 Beningo 的  USING DOCKER TO SETUP AN STM32 BUILD ENVIRONMENT,建立 Dockerfile 如下

------------------------------
FROM ubuntu:22.10

# Download Linux support tools
RUN apt-get update && \
         apt-get clean && \
         apt-get install -y \
             build-essential \
             wget \
             curl

# Set up a development tools directory
WORKDIR /home/dev
ADD . /home/dev

RUN wget -qO- https://developer.arm.com/-/media/Files/downloads/gnu-rm/10.3-2021.10/gcc-arm-none-eabi-10.3-2021.10-x86_64-linux.tar.bz2 | tar -xj

ENV PATH $PATH:/home/dev/gcc-arm-none-eabi-10.3-2021.10/bin

WORKDIR /home/app
------------------------------

然後執行 "docker build -t gcc-arm ." 建立 image。

補記 -- 其實在 Ubuntu 下可以直接執行 "apt-get install gcc-arm-none-eabi" 安裝 arm 的編譯器。

執行 "docker run --rm -it --privileged -v "$(pwd):/home/app" gcc-arm bash" 即可進入 stm32 的開發環境。

下載 stm32-hid-bootloader 的專案後,它有三個目錄。進入 [bootloader] 目錄,執行 make,即可產生 HIDBOOTLOADER.bin。使用 ST-LINK 燒錄到 STM32F103 開發板。

將 boot0 連上電腦會出現裝置,訊息如下

hid-generic 0003:1209:BABE.0012: hiddev100,hidraw9: USB HID v1.11 Device [www.brunofreitas.com STM32F HID Bootloader] on usb-0000:00:14.0-7.4.3/input0

回到一般的 Linux 下,到 [cli] 目錄下,執行 make,即可產生 hid-flash 的燒錄指令。

在 stm32 的開發環境下,進入 [blinker] 目錄,執行 make,產生 BLINKER.bin。這是一個讓接在 PC13 的 LED 閃爍的簡單小程式,可以自己修改一下,改變閃爍頻率,確認一切正常。

在 Linux 的環境下,將 boot0 跳線到 1,執行燒錄。

----------------------------
$ sudo ../cli/hid-flash BLINKER.bin 
HID-Flash v1.4a - STM32 HID Bootloader Flash Tool
(c) 04/2018 - Bruno Freitas - http://www.brunofreitas.com/
Sending reset pages command...
Flashing firmware...
Ok!
---------------------------- 

再將 boot0 跳線到 0,重新接上電源,即可看到 LED 按照 blinker 的程式在閃爍著。

接下來,就可以開發 OMK 的鍵盤了。至於跳線 pin 會用指撥開關來代替,比較方便。


網誌存檔