Compare commits

...

14 commits
v0.1.0 ... main

Author SHA1 Message Date
9ee127de90 CSI port: SmartRG/MTK CSI patch (Bo Jiao, MTK) rebased onto mt76 eb567bc7 (24.10.5 pin) — 4 rejects hand-merged (enum 0xc2 coexists with SPR_SET_PARAM; Makefile/vendor.h anchors); build via filogic SDK
Some checks failed
ci / test (push) Has been cancelled
ci / track (push) Has been cancelled
2026-08-22 00:08:54 +04:00
67503f2606 Stage 0 complete: walking human detected via RSSI (spread 3->12dB, ~3dB body shadow); windowed analyzer
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 23:57:17 +04:00
47a32ad369 Stage 0: RSSI motion logger (station-dump poll, sparkline, CSV) + still-room baseline (-52dBm ±1 @18.6Hz)
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 23:50:42 +04:00
b2e47dfd56 docs: CSI-project-stages — staged sensing roadmap (RSSI rehearsal → patched-driver CSI → deterministic DSP → firmware upgrades → deterministic SOTA)
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 23:44:24 +04:00
a3e8ca9a55 docs: capability directions — what full firmware access buys (sense/identify/encrypt/reach) and the RE targeting consequence
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 22:42:28 +04:00
c86d9516f2 P1-C: 2024→2026 handler-level changelog — WM id surface identical (169/169, arrays stable); WA handled ids 29→30 with core migration (+BSS_INFO/EDCA, -CHANNEL_SWITCH/WTBL); corrected shift-vs-rewrite framing
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 19:00:48 +04:00
6eb5a53182 P1-C: U4 resolved — WM dispatch = runtime registration list (parser 0xe00412e6, arrays in r5); scan_registrations.py; 130 ABI-named WM handlers + 29 WA; Ghidra labels applied (400 fns); findings F9
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 18:58:57 +04:00
42349632fe Findings: U4 registry entry (WM dispatch mechanism unknown); registry ordering
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 18:53:56 +04:00
1a1c75ae1d P1-B/C: WM survey — 555K instr/4,422 funcs; negative dispatch-table result recorded (U4); GP/tooling scripts; findings F8
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 18:53:30 +04:00
f215c88155 Findings F7: WA MCU_EXT_CMD dispatch table (65-entry @0x10201304), ABI-verified handler alignments, structural scan method
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 18:46:42 +04:00
4042aeda6c P1-C: WA dispatch table located (65-entry MCU_EXT_CMD @0x10201304, ~30 ABI-named handlers); scan_tables.py structural method; ForceDisasmPost; findings F7
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-21 18:45:47 +04:00
b9c46bc11d P1-B: WA survey — 120 funcs/450 strings; WA role identified (EXT_CMD handlers: STAREC/BSS/DevInfo updates, PKTLOSS accounting); overview script fixed (string type filter)
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-20 21:53:39 +04:00
eba408d0c3 P1-B: Ghidra/PyGhidra toolchain scripts; patch blob structure + first decompilation findings (F5): ROM replacement table, assert anchors, N9/CCIF/mailbox evidence
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-20 21:51:36 +04:00
069a26019f Hosting resolved: self-hosted Forgejo at zachery.lol/code/zacheryasc/mtk-wifi-fw
Some checks are pending
ci / test (push) Waiting to run
ci / track (push) Waiting to run
2026-08-20 21:32:42 +04:00
30 changed files with 5384 additions and 4 deletions

6
.gitignore vendored
View file

@ -12,3 +12,9 @@ __pycache__/
*.rep
*.gpr
*.id*
ghidra-proj/
firmware-build/
sdk/
openwrt/
mt76/

16
PLAN.md
View file

@ -107,11 +107,19 @@ router-dependent.
~95% changed, new RA/DPD/thermal strings), docs (format/boot), CI
(push + weekly track), v0.1.0 tagged. Announcement drafted, not posted —
hosting decision still open.
- 2026-08-20 (P1-B started): Ghidra 12.1.3 + JDK21 + PyGhidra pipeline
working (venv at ~/data/tools). Patch blob reversed to structure level:
10-entry ROM function replacement table + 49 NDS32 functions decompiling
cleanly, assert anchors (2 source files w/ line numbers), N9 core name
confirmed, CCIF/mailbox/WDT host-comm hooks mapped (findings F5).
Full decomp kept out of repo (blob-derived); notes only. WA import
running.
## Open items
- Repo name + hosting (GitHub reach vs Codeberg/self-hosted Forgejo;
mirroring makes this non-blocking).
- Repo name + hosting: RESOLVED — mtk-wifi-fw at
https://zachery.lol/code/zacheryasc/mtk-wifi-fw (self-hosted Forgejo 9,
public, pushed 2026-08-20 with v0.1.0). GitHub mirror optional later.
Forgejo Actions may pick up .github/workflows if a runner is registered
(ci-token exists on docean — unverified).
- Router access path (needed from M3/dynamic phase).
- Fork decision (audit vs authoring ladder mix) — after boot/boundary map.
- WO container format (from `mtk_wed_mcu.c`, different loader) — M2-ish.

View file

View file

View file

@ -0,0 +1,422 @@
# 9-entry {id,fn} array @ 0x02231ba8 (r5_t0_a02229800.bin)
0x02231ba8 id=0x00 fn=0xf009707c
0x02231bb0 id=0x09 fn=0xf00963a6
0x02231bb8 id=0x0a fn=0xf0096430
0x02231bc0 id=0x0e fn=0xf0096846
0x02231bc8 id=0x0d fn=0xe0040280
0x02231bd0 id=0x0f fn=0xf0096b72
0x02231bd8 id=0x01 fn=0xe00795c8
0x02231be0 id=0x03 fn=0xe00799a8
0x02231be8 id=0x04 fn=0xe0067480
# 29-entry {id,fn} array @ 0x02231bf8 (r5_t0_a02229800.bin)
0x02231bf8 id=0x06 fn=0xf00969ca
0x02231c00 id=0x0b fn=0xe004649e
0x02231c08 id=0x0c fn=0xf0096150
0x02231c10 id=0x10 fn=0xf009606e
0x02231c18 id=0x11 fn=0xf00961a4
0x02231c20 id=0x12 fn=0xe0098294
0x02231c28 id=0x14 fn=0xe00660b0
0x02231c30 id=0x24 fn=0xf00961f8
0x02231c38 id=0x18 fn=0xf0096000
0x02231c40 id=0x00 fn=0xe003fae4
0x02231c48 id=0x01 fn=0xe003fbe8
0x02231c50 id=0x02 fn=0xe003fc4c
0x02231c58 id=0x03 fn=0xe003fcb0
0x02231c60 id=0x04 fn=0xe003fd14
0x02231c68 id=0x05 fn=0xe003fd78
0x02231c70 id=0x06 fn=0xe003fda4
0x02231c78 id=0x07 fn=0xe003fdda
0x02231c80 id=0x08 fn=0xe003ff5c
0x02231c88 id=0x09 fn=0xe0040000
0x02231c90 id=0x0a fn=0xe0040056
0x02231c98 id=0x0c fn=0xe003face
0x02231ca0 id=0x0d fn=0xe0040082
0x02231ca8 id=0x0e fn=0xe003fae0
0x02231cb0 id=0x0f fn=0xe00400ae
0x02231cb8 id=0x10 fn=0xe00401b8
0x02231cc0 id=0x11 fn=0xe003fe5e
0x02231cc8 id=0x13 fn=0xe00401e4
0x02231cd0 id=0x12 fn=0xe00401f6
0x02231cd8 id=0x15 fn=0xe0040254
# 38-entry {id,fn} array @ 0x02231ea8 (r5_t0_a02229800.bin)
0x02231ea8 id=0x07 fn=0xe0040914
0x02231eb0 id=0x25 fn=0xf0097174
0x02231eb8 id=0x26 fn=0xe0092848
0x02231ec0 id=0x2a fn=0xe00928c6
0x02231ec8 id=0xbf fn=0xe009277c
0x02231ed0 id=0x13 fn=0xe0042006
0x02231ed8 id=0x27 fn=0xe005e710
0x02231ee0 id=0x28 fn=0xe0060b5e
0x02231ee8 id=0x47 fn=0xe005f636
0x02231ef0 id=0x48 fn=0xe005f796
0x02231ef8 id=0x93 fn=0xe005f5ae
0x02231f00 id=0x32 fn=0xe00402fa
0x02231f08 id=0x49 fn=0xe003ee7e
0x02231f10 id=0xa6 fn=0xe005db74
0x02231f18 id=0xae fn=0xe005f706
0x02231f20 id=0x95 fn=0xe004297c
0x02231f28 id=0x81 fn=0xe005d480
0x02231f30 id=0x57 fn=0xe0042558
0x02231f38 id=0x9c fn=0xe0043588
0x02231f40 id=0x94 fn=0xe0040de4
0x02231f48 id=0x02 fn=0xe007fade
0x02231f50 id=0xb7 fn=0xe0042f70
0x02231f58 id=0xc4 fn=0xe0043248
0x02231f60 id=0x98 fn=0xe0061e48
0x02231f68 id=0x42 fn=0xe005f5ec
0x02231f70 id=0x50 fn=0xe0047c90
0x02231f78 id=0x5a fn=0xe004166c
0x02231f80 id=0x3c fn=0xe00414ec
0x02231f88 id=0x1e fn=0xe00663b2
0x02231f90 id=0x36 fn=0xe0062e16
0x02231f98 id=0x38 fn=0xe00640fe
0x02231fa0 id=0x37 fn=0xe0062b62
0x02231fa8 id=0x4b fn=0xe0062bfe
0x02231fb0 id=0x4a fn=0xe0062eae
0x02231fb8 id=0x67 fn=0xe0064714
0x02231fc0 id=0x68 fn=0xe0063182
0x02231fc8 id=0x6b fn=0xe00645da
0x02231fd0 id=0x01 fn=0xe0090b8a
# 31-entry {id,fn} array @ 0x02231fe0 (r5_t0_a02229800.bin)
0x02231fe0 id=0x04 fn=0xe008a8ae
0x02231fe8 id=0x08 fn=0xe0080680
0x02231ff0 id=0x4e fn=0xe0080680
0x02231ff8 id=0x4f fn=0xe00897a0
0x02232000 id=0x19 fn=0xe00918a0
0x02232008 id=0x1f fn=0xe007d684
0x02232010 id=0x21 fn=0xe00804ac
0x02232018 id=0x9b fn=0xe007ee5e
0x02232020 id=0xbe fn=0xe007ef44
0x02232028 id=0x24 fn=0xe00407aa
0x02232030 id=0x2c fn=0xe008bf86
0x02232038 id=0x30 fn=0xe007a9b2
0x02232040 id=0x79 fn=0xe0080b88
0x02232048 id=0x17 fn=0xe0042d38
0x02232050 id=0x82 fn=0xe0082128
0x02232058 id=0x3d fn=0xe008a938
0x02232060 id=0x3e fn=0xe0081686
0x02232068 id=0x9f fn=0xe0045f3c
0x02232070 id=0x87 fn=0x0221cf98
0x02232078 id=0x3a fn=0xe007ce40
0x02232080 id=0xa3 fn=0xe007cb80
0x02232088 id=0xc5 fn=0xe007cd20
0x02232090 id=0x9d fn=0xe007c0c0
0x02232098 id=0xb2 fn=0xe007c138
0x022320a0 id=0x46 fn=0xe004174a
0x022320a8 id=0x44 fn=0xe0048392
0x022320b0 id=0x43 fn=0xe004197c
0x022320b8 id=0x23 fn=0xe008bca8
0x022320c0 id=0x56 fn=0xe006cf68
0x022320c8 id=0x58 fn=0xe008cf2a
0x022320d0 id=0xa1 fn=0xe00419c6
# 24-entry {id,fn} array @ 0x022320e0 (r5_t0_a02229800.bin)
0x022320e0 id=0xad fn=0xe00779ac
0x022320e8 id=0xb5 fn=0xe0077e68
0x022320f0 id=0x73 fn=0xe0040778
0x022320f8 id=0x9a fn=0xe0080024
0x02232100 id=0xab fn=0xe008a67c
0x02232108 id=0xac fn=0xe008a6ce
0x02232110 id=0xa8 fn=0xe0083ede
0x02232118 id=0xa4 fn=0xe008aadc
0x02232120 id=0xb3 fn=0xe008ae7c
0x02232128 id=0xb6 fn=0xe0078664
0x02232130 id=0xb8 fn=0xe0048010
0x02232138 id=0xb9 fn=0xe007944c
0x02232140 id=0xba fn=0xe00814f0
0x02232148 id=0xc8 fn=0xe00419fc
0x02232150 id=0x7a fn=0xe0041a42
0x02232158 id=0x7b fn=0xe00417d0
0x02232160 id=0x7c fn=0xe0041854
0x02232168 id=0xc6 fn=0xe00418ae
0x02232170 id=0xc7 fn=0xe0041702
0x02232178 id=0xc0 fn=0xe007ebc0
0x02232180 id=0xc2 fn=0xe00482e4
0x02232188 id=0xd5 fn=0xe005dde4
0x02232190 id=0x0f fn=0xe0046e14
0x02232198 id=0x5b fn=0xe0081550
# 43-entry {id,fn} array @ 0x022324ec (r5_t0_a02229800.bin)
0x022324ec id=0x01 fn=0xe0045a7e
0x022324f4 id=0x06 fn=0xe0043b36
0x022324fc id=0x0b fn=0xe0043c6c
0x02232504 id=0x14 fn=0xe00452b6
0x0223250c id=0x15 fn=0xe0043990
0x02232514 id=0x0c fn=0xe0043884
0x0223251c id=0x0d fn=0xe0043ba0
0x02232524 id=0x0e fn=0xe0044aec
0x0223252c id=0x0f fn=0xe0043dc2
0x02232534 id=0x10 fn=0xe0044092
0x0223253c id=0x11 fn=0xe0045950
0x02232544 id=0x12 fn=0xe0044b00
0x0223254c id=0x13 fn=0xe0043c06
0x02232554 id=0x33 fn=0xe0043e1a
0x0223255c id=0x18 fn=0xe00440ac
0x02232564 id=0x19 fn=0xe0043a7a
0x0223256c id=0x1a fn=0xe00441ac
0x02232574 id=0x1b fn=0xe00441c8
0x0223257c id=0x50 fn=0xe00439a0
0x02232584 id=0x51 fn=0xe004552a
0x0223258c id=0x64 fn=0xe004432a
0x02232594 id=0x65 fn=0xe0043e58
0x0223259c id=0x66 fn=0xe0043b1c
0x022325a4 id=0x67 fn=0xe0043cbe
0x022325ac id=0x68 fn=0xe0043ec2
0x022325b4 id=0x69 fn=0xe0043a00
0x022325bc id=0x6a fn=0xe0043a1a
0x022325c4 id=0xc8 fn=0xe0044292
0x022325cc id=0xc9 fn=0xe00442c0
0x022325d4 id=0xca fn=0xe0043a42
0x022325dc id=0xcb fn=0xe0044b10
0x022325e4 id=0xcc fn=0xe0043a64
0x022325ec id=0xcd fn=0xe0043aa6
0x022325f4 id=0xd2 fn=0xe0043f1a
0x022325fc id=0xd3 fn=0xe0043f4a
0x02232604 id=0xd0 fn=0xe0043f8c
0x0223260c id=0xd1 fn=0xe0043fbc
0x02232614 id=0x96 fn=0xe0043abc
0x0223261c id=0x97 fn=0xe00441ee
0x02232624 id=0xd4 fn=0xe0043fec
0x0223262c id=0xfe fn=0xe0044bde
0x02232634 id=0xce fn=0xe0043d32
0x0223263c id=0xcf fn=0xe0043aca
# 8-entry {id,fn} array @ 0x0223670c (r5_t0_a02229800.bin)
0x0223670c id=0x00 fn=0xe0077a2c
0x02236714 id=0x01 fn=0xe0077a5c
0x0223671c id=0x02 fn=0xe007758c
0x02236724 id=0x03 fn=0xe007747c
0x0223672c id=0x04 fn=0xe0077aa2
0x02236734 id=0x05 fn=0xe00776a8
0x0223673c id=0x06 fn=0xe0077478
0x02236744 id=0x07 fn=0xe00776b6
# 92-entry {id,fn} array @ 0x02236bf0 (r5_t0_a02229800.bin)
0x02236bf0 id=0x01 fn=0xe0083c88
0x02236bf8 id=0x02 fn=0xe00844f2
0x02236c00 id=0x03 fn=0xe00838c6
0x02236c08 id=0x04 fn=0xe008453c
0x02236c10 id=0x05 fn=0xe0083aa0
0x02236c18 id=0x06 fn=0xe008461a
0x02236c20 id=0x07 fn=0xe0083d1e
0x02236c28 id=0x08 fn=0xe0084666
0x02236c30 id=0x09 fn=0xe0083d62
0x02236c38 id=0x0a fn=0xe00846b2
0x02236c40 id=0x0b fn=0xe00838dc
0x02236c48 id=0x0c fn=0xe0084586
0x02236c50 id=0x0d fn=0xe00838f2
0x02236c58 id=0x0e fn=0xe00845d0
0x02236c60 id=0x0f fn=0xe0083908
0x02236c68 id=0x10 fn=0xe00846fe
0x02236c70 id=0x11 fn=0xe008391a
0x02236c78 id=0x12 fn=0xe0084748
0x02236c80 id=0x13 fn=0xe008392c
0x02236c88 id=0x14 fn=0xe0084792
0x02236c90 id=0x15 fn=0xe008393e
0x02236c98 id=0x16 fn=0xe00847dc
0x02236ca0 id=0x17 fn=0xe0083950
0x02236ca8 id=0x18 fn=0xe0084826
0x02236cb0 id=0x19 fn=0xe0083962
0x02236cb8 id=0x1a fn=0xe008486e
0x02236cc0 id=0x1b fn=0xe0083974
0x02236cc8 id=0x1c fn=0xe00848b8
0x02236cd0 id=0x1d fn=0xe0083986
0x02236cd8 id=0x1e fn=0xe0084902
0x02236ce0 id=0x1f fn=0xe0083998
0x02236ce8 id=0x20 fn=0xe008494c
0x02236cf0 id=0x21 fn=0xe00839aa
0x02236cf8 id=0x22 fn=0xe0084996
0x02236d00 id=0x23 fn=0xe00839c2
0x02236d08 id=0x24 fn=0xe00849e2
0x02236d10 id=0x25 fn=0xe00839da
0x02236d18 id=0x26 fn=0xe0084a2e
0x02236d20 id=0x27 fn=0xe00839f2
0x02236d28 id=0x28 fn=0xe0084a7a
0x02236d30 id=0x29 fn=0xe0083db0
0x02236d38 id=0x2a fn=0xe0084ac6
0x02236d40 id=0x2b fn=0xe0083d8e
0x02236d48 id=0x2c fn=0xe0084b12
0x02236d50 id=0x2d fn=0xe0083a20
0x02236d58 id=0x2e fn=0xe0084b5e
0x02236d60 id=0x31 fn=0xe0083a38
0x02236d68 id=0x32 fn=0xe0084baa
0x02236d70 id=0x33 fn=0xe0083a50
0x02236d78 id=0x34 fn=0xe0084bf6
0x02236d80 id=0x80 fn=0xe0083ddc
0x02236d88 id=0x81 fn=0xe0084d06
0x02236d90 id=0x82 fn=0xe0083ccc
0x02236d98 id=0x83 fn=0xe0084c42
0x02236da0 id=0x84 fn=0xe0084cae
0x02236da8 id=0x85 fn=0xe008385c
0x02236db0 id=0x86 fn=0xe0083884
0x02236db8 id=0x87 fn=0xe0083b6a
0x02236dc0 id=0x88 fn=0xe0083fc2
0x02236dc8 id=0x89 fn=0xe0083cec
0x02236dd0 id=0x8a fn=0xe0084d5a
0x02236dd8 id=0xc0 fn=0xe0083b10
0x02236de0 id=0xc1 fn=0xe00840cc
0x02236de8 id=0xc2 fn=0xe0083b24
0x02236df0 id=0xc3 fn=0xe0084112
0x02236df8 id=0xc4 fn=0xe0083ba0
0x02236e00 id=0xc5 fn=0xe00841a0
0x02236e08 id=0xc6 fn=0xe0083bb4
0x02236e10 id=0xc7 fn=0xe00841e6
0x02236e18 id=0xc8 fn=0xe0083bc8
0x02236e20 id=0xc9 fn=0xe008422c
0x02236e28 id=0xca fn=0xe0083bdc
0x02236e30 id=0xcb fn=0xe0084272
0x02236e38 id=0xcc fn=0xe0083bf0
0x02236e40 id=0xcd fn=0xe00842b8
0x02236e48 id=0xce fn=0xe0083f4e
0x02236e50 id=0xcf fn=0xe00842fe
0x02236e58 id=0xd0 fn=0xe0083c1a
0x02236e60 id=0xd1 fn=0xe0084394
0x02236e68 id=0xd2 fn=0xe0083c04
0x02236e70 id=0xd3 fn=0xe0083aec
0x02236e78 id=0xd4 fn=0xe0084158
0x02236e80 id=0xd5 fn=0xe0083c2e
0x02236e88 id=0xd6 fn=0xe00843da
0x02236e90 id=0xd7 fn=0xe0083c42
0x02236e98 id=0xd8 fn=0xe0084420
0x02236ea0 id=0xd9 fn=0xe0083c56
0x02236ea8 id=0xda fn=0xe0084466
0x02236eb0 id=0xdb fn=0xe00844ac
0x02236eb8 id=0xdc fn=0xe0083c6a
0x02236ec0 id=0xdd fn=0xe0084346
0x02236ec8 id=0xea fn=0xe0083a6a
# 10-entry {id,fn} array @ 0x0223833c (r5_t0_a02229800.bin)
0x0223833c id=0x00 fn=0xe008f91e
0x02238344 id=0x01 fn=0xe008f068
0x0223834c id=0x02 fn=0xe008f080
0x02238354 id=0x03 fn=0xe008f098
0x0223835c id=0x04 fn=0xe008f18e
0x02238364 id=0x05 fn=0xe008f1ba
0x0223836c id=0x06 fn=0xe008f1d8
0x02238374 id=0x07 fn=0xe008ee6c
0x0223837c id=0x08 fn=0xe008f164
0x02238384 id=0x0b fn=0xe008e3e0
# 9-entry {id,fn} array @ 0x02238534 (r5_t0_a02229800.bin)
0x02238534 id=0x00 fn=0xe0091a16
0x0223853c id=0x01 fn=0xe0091a8c
0x02238544 id=0x02 fn=0xe0091aec
0x0223854c id=0x03 fn=0xe0091ee8
0x02238554 id=0x04 fn=0xe009227c
0x0223855c id=0x05 fn=0xe0091ba2
0x02238564 id=0x00 fn=0xe00918f6
0x0223856c id=0x01 fn=0xe00929b0
0x02238574 id=0x02 fn=0xe0091c4e
# 10-entry {id,fn} array @ 0x0223858c (r5_t0_a02229800.bin)
0x0223858c id=0x07 fn=0xe0091cd8
0x02238594 id=0x0a fn=0xe0079520
0x0223859c id=0x0b fn=0xe0091d64
0x022385a4 id=0x0c fn=0xe0091d96
0x022385ac id=0x0d fn=0xe0091de0
0x022385b4 id=0x0e fn=0xe0092690
0x022385bc id=0x0f fn=0xe00924a0
0x022385c4 id=0x10 fn=0xe0092568
0x022385cc id=0x11 fn=0xe003f5d4
0x022385d4 id=0x1b fn=0xe00925d4
# 49-entry {id,fn} array @ 0x02238a5c (r5_t0_a02229800.bin)
0x02238a5c id=0x00 fn=0xe00af53c
0x02238a64 id=0x01 fn=0xe00af544
0x02238a6c id=0x02 fn=0xe00af54c
0x02238a74 id=0x03 fn=0xe00af554
0x02238a7c id=0x00 fn=0xe00af578
0x02238a84 id=0x01 fn=0xe00af55c
0x02238a8c id=0x02 fn=0xe00af568
0x02238a94 id=0x03 fn=0xe00af574
0x02238a9c id=0x04 fn=0xe00af580
0x02238aa4 id=0x05 fn=0xe00af58c
0x02238aac id=0x06 fn=0xe00af598
0x02238ab4 id=0x07 fn=0xe00af5a8
0x02238abc id=0x11 fn=0xe00af5b8
0x02238ac4 id=0x13 fn=0xe00af5c4
0x02238acc id=0x16 fn=0xe00af5d0
0x02238ad4 id=0x17 fn=0xe00af5e0
0x02238adc id=0x00 fn=0xe00af5f0
0x02238ae4 id=0x01 fn=0xe00af604
0x02238aec id=0x02 fn=0xe00af61c
0x02238af4 id=0x03 fn=0xe00af630
0x02238afc id=0x04 fn=0xe00af644
0x02238b04 id=0x05 fn=0xe00af658
0x02238b0c id=0x06 fn=0xe00af670
0x02238b14 id=0x07 fn=0xe00af604
0x02238b1c id=0x08 fn=0xe00af5f0
0x02238b24 id=0x09 fn=0xe00af670
0x02238b2c id=0x0a fn=0xe00af604
0x02238b34 id=0x0b fn=0xe00af604
0x02238b3c id=0x00 fn=0xe00af684
0x02238b44 id=0x01 fn=0xe00af690
0x02238b4c id=0x02 fn=0xe00af69c
0x02238b54 id=0x03 fn=0xe00af6b0
0x02238b5c id=0x0d fn=0xe00af6b8
0x02238b64 id=0x0e fn=0xe00af6c0
0x02238b6c id=0x0f fn=0xe00af6c8
0x02238b74 id=0x10 fn=0xe00af6d0
0x02238b7c id=0x00 fn=0xe00af6d4
0x02238b84 id=0x01 fn=0xe00a68d0
0x02238b8c id=0x02 fn=0xe00af6d0
0x02238b94 id=0x03 fn=0xe00af6e4
0x02238b9c id=0x04 fn=0xe00a6988
0x02238ba4 id=0x05 fn=0xe00af6e8
0x02238bac id=0x06 fn=0xe00af6ec
0x02238bb4 id=0x07 fn=0xe00af6fc
0x02238bbc id=0x08 fn=0xe00af704
0x02238bc4 id=0x09 fn=0xe00af714
0x02238bcc id=0x0a fn=0xe00af71c
0x02238bd4 id=0x0b fn=0xe00af728
0x02238bdc id=0x0c fn=0xe00af734
# 33-entry {id,fn} array @ 0x02238e44 (r5_t0_a02229800.bin)
0x02238e44 id=0x00 fn=0xe003e66e
0x02238e4c id=0x01 fn=0xe003e696
0x02238e54 id=0x16 fn=0xe003c370
0x02238e5c id=0x17 fn=0xe003c370
0x02238e64 id=0x18 fn=0xe003c370
0x02238e6c id=0x19 fn=0xe003c370
0x02238e74 id=0x28 fn=0xe003c63e
0x02238e7c id=0x2b fn=0xe003c63e
0x02238e84 id=0x00 fn=0xe003c3aa
0x02238e8c id=0x29 fn=0xe003c3ac
0x02238e94 id=0x1a fn=0xe003c028
0x02238e9c id=0x1b fn=0xe003c028
0x02238ea4 id=0x1c fn=0xe003c028
0x02238eac id=0x1d fn=0xe003c028
0x02238eb4 id=0x12 fn=0xe003c34c
0x02238ebc id=0x13 fn=0xe003c34c
0x02238ec4 id=0x14 fn=0xe003c34c
0x02238ecc id=0x15 fn=0xe003c34c
0x02238ed4 id=0x06 fn=0xe003c012
0x02238edc id=0x07 fn=0xe003c012
0x02238ee4 id=0x08 fn=0xe003c012
0x02238eec id=0x09 fn=0xe003c012
0x02238ef4 id=0x0a fn=0xe003c012
0x02238efc id=0x0b fn=0xe003c012
0x02238f04 id=0x0c fn=0xe003c012
0x02238f0c id=0x0d fn=0xe003c012
0x02238f14 id=0x2e fn=0xe003e624
0x02238f1c id=0x2f fn=0xe003e624
0x02238f24 id=0x01 fn=0xe003e586
0x02238f2c id=0x02 fn=0xe003e586
0x02238f34 id=0x03 fn=0xe003e586
0x02238f3c id=0x04 fn=0xe003e586
0x02238f44 id=0x23 fn=0xe003c38c
# 9-entry {id,fn} array @ 0x02238f74 (r5_t0_a02229800.bin)
0x02238f74 id=0xef fn=0xe0041460
0x02238f7c id=0xed fn=0xe00412e6
0x02238f84 id=0x04 fn=0xe0040680
0x02238f8c id=0x02 fn=0xe0042ebe
0x02238f94 id=0x8d fn=0xe004276c
0x02238f9c id=0x10 fn=0xe0043330
0x02238fa4 id=0x4b fn=0xe00433fa
0x02238fac id=0x7d fn=0xe004375c
0x02238fb4 id=0xfc fn=0xe00437a4
# 13-entry {id,fn} array @ 0x02238ffc (r5_t0_a02229800.bin)
0x02238ffc id=0x06 fn=0xf009b6d6
0x02239004 id=0x07 fn=0xf009b6d6
0x0223900c id=0x08 fn=0xf009b6d6
0x02239014 id=0x09 fn=0xf009b6d6
0x0223901c id=0x0a fn=0xf009b6d6
0x02239024 id=0x0b fn=0xf009b6d6
0x0223902c id=0x0c fn=0xf009b6d6
0x02239034 id=0x0d fn=0xf009b6d6
0x0223903c id=0x0e fn=0xf009b6d6
0x02239044 id=0x0f fn=0xf009b6d6
0x0223904c id=0x10 fn=0xe006946e
0x02239054 id=0x11 fn=0xe003d7b4
0x0223905c id=0x12 fn=0xe00471f6

View file

@ -0,0 +1,423 @@
# 9-entry {id,fn} array @ 0x02231ba8 (r5_t0_a02229800.bin)
0x02231ba8 id=0x00 fn=0xf009707c
0x02231bb0 id=0x09 fn=0xf00963a6
0x02231bb8 id=0x0a fn=0xf0096430
0x02231bc0 id=0x0e fn=0xf0096846
0x02231bc8 id=0x0d fn=0xe00402a8
0x02231bd0 id=0x0f fn=0xf0096b72
0x02231bd8 id=0x01 fn=0xe0079c14
0x02231be0 id=0x03 fn=0xe0079ff4
0x02231be8 id=0x04 fn=0xe00676e8
# 29-entry {id,fn} array @ 0x02231bf8 (r5_t0_a02229800.bin)
0x02231bf8 id=0x06 fn=0xf00969ca
0x02231c00 id=0x0b fn=0xe0046512
0x02231c08 id=0x0c fn=0xf0096150
0x02231c10 id=0x10 fn=0xf009606e
0x02231c18 id=0x11 fn=0xf00961a4
0x02231c20 id=0x12 fn=0xe009a3e8
0x02231c28 id=0x14 fn=0xe0066318
0x02231c30 id=0x24 fn=0xf00961f8
0x02231c38 id=0x18 fn=0xf0096000
0x02231c40 id=0x00 fn=0xe003fb0c
0x02231c48 id=0x01 fn=0xe003fc10
0x02231c50 id=0x02 fn=0xe003fc74
0x02231c58 id=0x03 fn=0xe003fcd8
0x02231c60 id=0x04 fn=0xe003fd3c
0x02231c68 id=0x05 fn=0xe003fda0
0x02231c70 id=0x06 fn=0xe003fdcc
0x02231c78 id=0x07 fn=0xe003fe02
0x02231c80 id=0x08 fn=0xe003ff84
0x02231c88 id=0x09 fn=0xe0040028
0x02231c90 id=0x0a fn=0xe004007e
0x02231c98 id=0x0c fn=0xe003faf6
0x02231ca0 id=0x0d fn=0xe00400aa
0x02231ca8 id=0x0e fn=0xe003fb08
0x02231cb0 id=0x0f fn=0xe00400d6
0x02231cb8 id=0x10 fn=0xe00401e0
0x02231cc0 id=0x11 fn=0xe003fe86
0x02231cc8 id=0x13 fn=0xe004020c
0x02231cd0 id=0x12 fn=0xe004021e
0x02231cd8 id=0x15 fn=0xe004027c
# 38-entry {id,fn} array @ 0x02231ea8 (r5_t0_a02229800.bin)
0x02231ea8 id=0x07 fn=0xe004093c
0x02231eb0 id=0x25 fn=0xf0097174
0x02231eb8 id=0x26 fn=0xe0094930
0x02231ec0 id=0x2a fn=0xe00949ae
0x02231ec8 id=0xbf fn=0xe0094864
0x02231ed0 id=0x13 fn=0xe0042032
0x02231ed8 id=0x27 fn=0xe005e8bc
0x02231ee0 id=0x28 fn=0xe0060daa
0x02231ee8 id=0x47 fn=0xe005f83c
0x02231ef0 id=0x48 fn=0xe005f99c
0x02231ef8 id=0x93 fn=0xe005f7b4
0x02231f00 id=0x32 fn=0xe0040322
0x02231f08 id=0x49 fn=0xe003ee82
0x02231f10 id=0xa6 fn=0xe005dd20
0x02231f18 id=0xae fn=0xe005f90c
0x02231f20 id=0x95 fn=0xe00429a8
0x02231f28 id=0x81 fn=0xe005d62c
0x02231f30 id=0x57 fn=0xe0042584
0x02231f38 id=0x9c fn=0xe00435b4
0x02231f40 id=0x94 fn=0xe0040e0c
0x02231f48 id=0x02 fn=0xe008020e
0x02231f50 id=0xb7 fn=0xe0042f9c
0x02231f58 id=0xc4 fn=0xe0043274
0x02231f60 id=0x98 fn=0xe00620b0
0x02231f68 id=0x42 fn=0xe005f7f2
0x02231f70 id=0x50 fn=0xe0047d3c
0x02231f78 id=0x5a fn=0xe0041694
0x02231f80 id=0x3c fn=0xe0041514
0x02231f88 id=0x1e fn=0xe006661a
0x02231f90 id=0x36 fn=0xe006307e
0x02231f98 id=0x38 fn=0xe0064366
0x02231fa0 id=0x37 fn=0xe0062dca
0x02231fa8 id=0x4b fn=0xe0062e66
0x02231fb0 id=0x4a fn=0xe0063116
0x02231fb8 id=0x67 fn=0xe006497c
0x02231fc0 id=0x68 fn=0xe00633ea
0x02231fc8 id=0x6b fn=0xe0064842
0x02231fd0 id=0x01 fn=0xe0092c72
# 31-entry {id,fn} array @ 0x02231fe0 (r5_t0_a02229800.bin)
0x02231fe0 id=0x04 fn=0xe008c8b6
0x02231fe8 id=0x08 fn=0xe0080db0
0x02231ff0 id=0x4e fn=0xe0080db0
0x02231ff8 id=0x4f fn=0xe008b7a8
0x02232000 id=0x19 fn=0xe0093988
0x02232008 id=0x1f fn=0xe007ddbc
0x02232010 id=0x21 fn=0xe0080bdc
0x02232018 id=0x9b fn=0xe007f596
0x02232020 id=0xbe fn=0xe007f67c
0x02232028 id=0x24 fn=0xe00407d2
0x02232030 id=0x2c fn=0xe008df8e
0x02232038 id=0x30 fn=0xe007b07c
0x02232040 id=0x79 fn=0xe00813ec
0x02232048 id=0x17 fn=0xe0042d64
0x02232050 id=0x82 fn=0xe0084130
0x02232058 id=0x3d fn=0xe008c940
0x02232060 id=0x3e fn=0xe0081eea
0x02232068 id=0x9f fn=0xe0045f68
0x02232070 id=0x87 fn=0x0221d3b8
0x02232078 id=0x3a fn=0xe007d504
0x02232080 id=0xa3 fn=0xe007d244
0x02232088 id=0xc5 fn=0xe007d3e4
0x02232090 id=0x9d fn=0xe007c78c
0x02232098 id=0xb2 fn=0xe007c804
0x022320a0 id=0x46 fn=0xe0041772
0x022320a8 id=0x44 fn=0xe004843e
0x022320b0 id=0x43 fn=0xe00419a4
0x022320b8 id=0x23 fn=0xe008dcb0
0x022320c0 id=0x56 fn=0xe006d236
0x022320c8 id=0x58 fn=0xe008ef32
0x022320d0 id=0xa1 fn=0xe00419ee
# 25-entry {id,fn} array @ 0x022320e0 (r5_t0_a02229800.bin)
0x022320e0 id=0xad fn=0xe0077dec
0x022320e8 id=0xb5 fn=0xe00782f0
0x022320f0 id=0x73 fn=0xe00407a0
0x022320f8 id=0x9a fn=0xe0080754
0x02232100 id=0xab fn=0xe008c684
0x02232108 id=0xac fn=0xe008c6d6
0x02232110 id=0xa8 fn=0xe0085ee6
0x02232118 id=0xa4 fn=0xe008cae4
0x02232120 id=0xb3 fn=0xe008ce84
0x02232128 id=0xb6 fn=0xe0078c98
0x02232130 id=0xb8 fn=0xe00480bc
0x02232138 id=0xb9 fn=0xe0079a98
0x02232140 id=0xba fn=0xe0081d54
0x02232148 id=0xc8 fn=0xe0041a24
0x02232150 id=0x7a fn=0xe0041a6a
0x02232158 id=0x7b fn=0xe00417f8
0x02232160 id=0x7c fn=0xe004187c
0x02232168 id=0xc6 fn=0xe00418d6
0x02232170 id=0xc7 fn=0xe004172a
0x02232178 id=0xc0 fn=0xe007f2f8
0x02232180 id=0xc2 fn=0xe0048390
0x02232188 id=0xd5 fn=0xe005df90
0x02232190 id=0x0f fn=0xe0046ec0
0x02232198 id=0x5b fn=0xe0081db4
0x022321a0 id=0xc9 fn=0xe0083658
# 43-entry {id,fn} array @ 0x022324f4 (r5_t0_a02229800.bin)
0x022324f4 id=0x01 fn=0xe0045aaa
0x022324fc id=0x06 fn=0xe0043b62
0x02232504 id=0x0b fn=0xe0043c98
0x0223250c id=0x14 fn=0xe00452e2
0x02232514 id=0x15 fn=0xe00439bc
0x0223251c id=0x0c fn=0xe00438b0
0x02232524 id=0x0d fn=0xe0043bcc
0x0223252c id=0x0e fn=0xe0044b18
0x02232534 id=0x0f fn=0xe0043dee
0x0223253c id=0x10 fn=0xe00440be
0x02232544 id=0x11 fn=0xe004597c
0x0223254c id=0x12 fn=0xe0044b2c
0x02232554 id=0x13 fn=0xe0043c32
0x0223255c id=0x33 fn=0xe0043e46
0x02232564 id=0x18 fn=0xe00440d8
0x0223256c id=0x19 fn=0xe0043aa6
0x02232574 id=0x1a fn=0xe00441d8
0x0223257c id=0x1b fn=0xe00441f4
0x02232584 id=0x50 fn=0xe00439cc
0x0223258c id=0x51 fn=0xe0045556
0x02232594 id=0x64 fn=0xe0044356
0x0223259c id=0x65 fn=0xe0043e84
0x022325a4 id=0x66 fn=0xe0043b48
0x022325ac id=0x67 fn=0xe0043cea
0x022325b4 id=0x68 fn=0xe0043eee
0x022325bc id=0x69 fn=0xe0043a2c
0x022325c4 id=0x6a fn=0xe0043a46
0x022325cc id=0xc8 fn=0xe00442be
0x022325d4 id=0xc9 fn=0xe00442ec
0x022325dc id=0xca fn=0xe0043a6e
0x022325e4 id=0xcb fn=0xe0044b3c
0x022325ec id=0xcc fn=0xe0043a90
0x022325f4 id=0xcd fn=0xe0043ad2
0x022325fc id=0xd2 fn=0xe0043f46
0x02232604 id=0xd3 fn=0xe0043f76
0x0223260c id=0xd0 fn=0xe0043fb8
0x02232614 id=0xd1 fn=0xe0043fe8
0x0223261c id=0x96 fn=0xe0043ae8
0x02232624 id=0x97 fn=0xe004421a
0x0223262c id=0xd4 fn=0xe0044018
0x02232634 id=0xfe fn=0xe0044c0a
0x0223263c id=0xce fn=0xe0043d5e
0x02232644 id=0xcf fn=0xe0043af6
# 8-entry {id,fn} array @ 0x02236720 (r5_t0_a02229800.bin)
0x02236720 id=0x00 fn=0xe0077e6c
0x02236728 id=0x01 fn=0xe0077e9c
0x02236730 id=0x02 fn=0xe0077988
0x02236738 id=0x03 fn=0xe007786c
0x02236740 id=0x04 fn=0xe0077ee2
0x02236748 id=0x05 fn=0xe0077aa4
0x02236750 id=0x06 fn=0xe0077868
0x02236758 id=0x07 fn=0xe0077ab2
# 92-entry {id,fn} array @ 0x02236d10 (r5_t0_a02229800.bin)
0x02236d10 id=0x01 fn=0xe0085c90
0x02236d18 id=0x02 fn=0xe00864fa
0x02236d20 id=0x03 fn=0xe00858ce
0x02236d28 id=0x04 fn=0xe0086544
0x02236d30 id=0x05 fn=0xe0085aa8
0x02236d38 id=0x06 fn=0xe0086622
0x02236d40 id=0x07 fn=0xe0085d26
0x02236d48 id=0x08 fn=0xe008666e
0x02236d50 id=0x09 fn=0xe0085d6a
0x02236d58 id=0x0a fn=0xe00866ba
0x02236d60 id=0x0b fn=0xe00858e4
0x02236d68 id=0x0c fn=0xe008658e
0x02236d70 id=0x0d fn=0xe00858fa
0x02236d78 id=0x0e fn=0xe00865d8
0x02236d80 id=0x0f fn=0xe0085910
0x02236d88 id=0x10 fn=0xe0086706
0x02236d90 id=0x11 fn=0xe0085922
0x02236d98 id=0x12 fn=0xe0086750
0x02236da0 id=0x13 fn=0xe0085934
0x02236da8 id=0x14 fn=0xe008679a
0x02236db0 id=0x15 fn=0xe0085946
0x02236db8 id=0x16 fn=0xe00867e4
0x02236dc0 id=0x17 fn=0xe0085958
0x02236dc8 id=0x18 fn=0xe008682e
0x02236dd0 id=0x19 fn=0xe008596a
0x02236dd8 id=0x1a fn=0xe0086876
0x02236de0 id=0x1b fn=0xe008597c
0x02236de8 id=0x1c fn=0xe00868c0
0x02236df0 id=0x1d fn=0xe008598e
0x02236df8 id=0x1e fn=0xe008690a
0x02236e00 id=0x1f fn=0xe00859a0
0x02236e08 id=0x20 fn=0xe0086954
0x02236e10 id=0x21 fn=0xe00859b2
0x02236e18 id=0x22 fn=0xe008699e
0x02236e20 id=0x23 fn=0xe00859ca
0x02236e28 id=0x24 fn=0xe00869ea
0x02236e30 id=0x25 fn=0xe00859e2
0x02236e38 id=0x26 fn=0xe0086a36
0x02236e40 id=0x27 fn=0xe00859fa
0x02236e48 id=0x28 fn=0xe0086a82
0x02236e50 id=0x29 fn=0xe0085db8
0x02236e58 id=0x2a fn=0xe0086ace
0x02236e60 id=0x2b fn=0xe0085d96
0x02236e68 id=0x2c fn=0xe0086b1a
0x02236e70 id=0x2d fn=0xe0085a28
0x02236e78 id=0x2e fn=0xe0086b66
0x02236e80 id=0x31 fn=0xe0085a40
0x02236e88 id=0x32 fn=0xe0086bb2
0x02236e90 id=0x33 fn=0xe0085a58
0x02236e98 id=0x34 fn=0xe0086bfe
0x02236ea0 id=0x80 fn=0xe0085de4
0x02236ea8 id=0x81 fn=0xe0086d0e
0x02236eb0 id=0x82 fn=0xe0085cd4
0x02236eb8 id=0x83 fn=0xe0086c4a
0x02236ec0 id=0x84 fn=0xe0086cb6
0x02236ec8 id=0x85 fn=0xe0085864
0x02236ed0 id=0x86 fn=0xe008588c
0x02236ed8 id=0x87 fn=0xe0085b72
0x02236ee0 id=0x88 fn=0xe0085fca
0x02236ee8 id=0x89 fn=0xe0085cf4
0x02236ef0 id=0x8a fn=0xe0086d62
0x02236ef8 id=0xc0 fn=0xe0085b18
0x02236f00 id=0xc1 fn=0xe00860d4
0x02236f08 id=0xc2 fn=0xe0085b2c
0x02236f10 id=0xc3 fn=0xe008611a
0x02236f18 id=0xc4 fn=0xe0085ba8
0x02236f20 id=0xc5 fn=0xe00861a8
0x02236f28 id=0xc6 fn=0xe0085bbc
0x02236f30 id=0xc7 fn=0xe00861ee
0x02236f38 id=0xc8 fn=0xe0085bd0
0x02236f40 id=0xc9 fn=0xe0086234
0x02236f48 id=0xca fn=0xe0085be4
0x02236f50 id=0xcb fn=0xe008627a
0x02236f58 id=0xcc fn=0xe0085bf8
0x02236f60 id=0xcd fn=0xe00862c0
0x02236f68 id=0xce fn=0xe0085f56
0x02236f70 id=0xcf fn=0xe0086306
0x02236f78 id=0xd0 fn=0xe0085c22
0x02236f80 id=0xd1 fn=0xe008639c
0x02236f88 id=0xd2 fn=0xe0085c0c
0x02236f90 id=0xd3 fn=0xe0085af4
0x02236f98 id=0xd4 fn=0xe0086160
0x02236fa0 id=0xd5 fn=0xe0085c36
0x02236fa8 id=0xd6 fn=0xe00863e2
0x02236fb0 id=0xd7 fn=0xe0085c4a
0x02236fb8 id=0xd8 fn=0xe0086428
0x02236fc0 id=0xd9 fn=0xe0085c5e
0x02236fc8 id=0xda fn=0xe008646e
0x02236fd0 id=0xdb fn=0xe00864b4
0x02236fd8 id=0xdc fn=0xe0085c72
0x02236fe0 id=0xdd fn=0xe008634e
0x02236fe8 id=0xea fn=0xe0085a72
# 10-entry {id,fn} array @ 0x0223845c (r5_t0_a02229800.bin)
0x0223845c id=0x00 fn=0xe00919f8
0x02238464 id=0x01 fn=0xe00910a8
0x0223846c id=0x02 fn=0xe00910c0
0x02238474 id=0x03 fn=0xe00910d8
0x0223847c id=0x04 fn=0xe00911ce
0x02238484 id=0x05 fn=0xe00911fa
0x0223848c id=0x06 fn=0xe0091218
0x02238494 id=0x07 fn=0xe0090eae
0x0223849c id=0x08 fn=0xe00911a4
0x022384a4 id=0x0b fn=0xe0090416
# 9-entry {id,fn} array @ 0x02238654 (r5_t0_a02229800.bin)
0x02238654 id=0x00 fn=0xe0093afe
0x0223865c id=0x01 fn=0xe0093b74
0x02238664 id=0x02 fn=0xe0093bd4
0x0223866c id=0x03 fn=0xe0093fd0
0x02238674 id=0x04 fn=0xe0094364
0x0223867c id=0x05 fn=0xe0093c8a
0x02238684 id=0x00 fn=0xe00939de
0x0223868c id=0x01 fn=0xe0094a98
0x02238694 id=0x02 fn=0xe0093d36
# 10-entry {id,fn} array @ 0x022386ac (r5_t0_a02229800.bin)
0x022386ac id=0x07 fn=0xe0093dc0
0x022386b4 id=0x0a fn=0xe0079b6c
0x022386bc id=0x0b fn=0xe0093e4c
0x022386c4 id=0x0c fn=0xe0093e7e
0x022386cc id=0x0d fn=0xe0093ec8
0x022386d4 id=0x0e fn=0xe0094778
0x022386dc id=0x0f fn=0xe0094588
0x022386e4 id=0x10 fn=0xe0094650
0x022386ec id=0x11 fn=0xe003f5dc
0x022386f4 id=0x1b fn=0xe00946bc
# 49-entry {id,fn} array @ 0x02238b7c (r5_t0_a02229800.bin)
0x02238b7c id=0x00 fn=0xe00afca0
0x02238b84 id=0x01 fn=0xe00afca8
0x02238b8c id=0x02 fn=0xe00afcb0
0x02238b94 id=0x03 fn=0xe00afcb8
0x02238b9c id=0x00 fn=0xe00afcdc
0x02238ba4 id=0x01 fn=0xe00afcc0
0x02238bac id=0x02 fn=0xe00afccc
0x02238bb4 id=0x03 fn=0xe00afcd8
0x02238bbc id=0x04 fn=0xe00afce4
0x02238bc4 id=0x05 fn=0xe00afcf0
0x02238bcc id=0x06 fn=0xe00afcfc
0x02238bd4 id=0x07 fn=0xe00afd0c
0x02238bdc id=0x11 fn=0xe00afd1c
0x02238be4 id=0x13 fn=0xe00afd28
0x02238bec id=0x16 fn=0xe00afd34
0x02238bf4 id=0x17 fn=0xe00afd44
0x02238bfc id=0x00 fn=0xe00afd54
0x02238c04 id=0x01 fn=0xe00afd68
0x02238c0c id=0x02 fn=0xe00afd80
0x02238c14 id=0x03 fn=0xe00afd94
0x02238c1c id=0x04 fn=0xe00afda8
0x02238c24 id=0x05 fn=0xe00afdbc
0x02238c2c id=0x06 fn=0xe00afdd4
0x02238c34 id=0x07 fn=0xe00afd68
0x02238c3c id=0x08 fn=0xe00afd54
0x02238c44 id=0x09 fn=0xe00afdd4
0x02238c4c id=0x0a fn=0xe00afd68
0x02238c54 id=0x0b fn=0xe00afd68
0x02238c5c id=0x00 fn=0xe00afde8
0x02238c64 id=0x01 fn=0xe00afdf4
0x02238c6c id=0x02 fn=0xe00afe00
0x02238c74 id=0x03 fn=0xe00afe14
0x02238c7c id=0x0d fn=0xe00afe1c
0x02238c84 id=0x0e fn=0xe00afe24
0x02238c8c id=0x0f fn=0xe00afe2c
0x02238c94 id=0x10 fn=0xe00afe34
0x02238c9c id=0x00 fn=0xe00afe38
0x02238ca4 id=0x01 fn=0xe00a6904
0x02238cac id=0x02 fn=0xe00afe34
0x02238cb4 id=0x03 fn=0xe00afe48
0x02238cbc id=0x04 fn=0xe00a69bc
0x02238cc4 id=0x05 fn=0xe00afe4c
0x02238ccc id=0x06 fn=0xe00afe50
0x02238cd4 id=0x07 fn=0xe00afe60
0x02238cdc id=0x08 fn=0xe00afe68
0x02238ce4 id=0x09 fn=0xe00afe78
0x02238cec id=0x0a fn=0xe00afe80
0x02238cf4 id=0x0b fn=0xe00afe8c
0x02238cfc id=0x0c fn=0xe00afe98
# 33-entry {id,fn} array @ 0x02238f64 (r5_t0_a02229800.bin)
0x02238f64 id=0x00 fn=0xe003e672
0x02238f6c id=0x01 fn=0xe003e69a
0x02238f74 id=0x16 fn=0xe003c374
0x02238f7c id=0x17 fn=0xe003c374
0x02238f84 id=0x18 fn=0xe003c374
0x02238f8c id=0x19 fn=0xe003c374
0x02238f94 id=0x28 fn=0xe003c642
0x02238f9c id=0x2b fn=0xe003c642
0x02238fa4 id=0x00 fn=0xe003c3ae
0x02238fac id=0x29 fn=0xe003c3b0
0x02238fb4 id=0x1a fn=0xe003c02c
0x02238fbc id=0x1b fn=0xe003c02c
0x02238fc4 id=0x1c fn=0xe003c02c
0x02238fcc id=0x1d fn=0xe003c02c
0x02238fd4 id=0x12 fn=0xe003c350
0x02238fdc id=0x13 fn=0xe003c350
0x02238fe4 id=0x14 fn=0xe003c350
0x02238fec id=0x15 fn=0xe003c350
0x02238ff4 id=0x06 fn=0xe003c016
0x02238ffc id=0x07 fn=0xe003c016
0x02239004 id=0x08 fn=0xe003c016
0x0223900c id=0x09 fn=0xe003c016
0x02239014 id=0x0a fn=0xe003c016
0x0223901c id=0x0b fn=0xe003c016
0x02239024 id=0x0c fn=0xe003c016
0x0223902c id=0x0d fn=0xe003c016
0x02239034 id=0x2e fn=0xe003e628
0x0223903c id=0x2f fn=0xe003e628
0x02239044 id=0x01 fn=0xe003e58a
0x0223904c id=0x02 fn=0xe003e58a
0x02239054 id=0x03 fn=0xe003e58a
0x0223905c id=0x04 fn=0xe003e58a
0x02239064 id=0x23 fn=0xe003c390
# 9-entry {id,fn} array @ 0x02239094 (r5_t0_a02229800.bin)
0x02239094 id=0xef fn=0xe0041488
0x0223909c id=0xed fn=0xe004130e
0x022390a4 id=0x04 fn=0xe00406a8
0x022390ac id=0x02 fn=0xe0042eea
0x022390b4 id=0x8d fn=0xe0042798
0x022390bc id=0x10 fn=0xe004335c
0x022390c4 id=0x4b fn=0xe0043426
0x022390cc id=0x7d fn=0xe0043788
0x022390d4 id=0xfc fn=0xe00437d0
# 13-entry {id,fn} array @ 0x0223911c (r5_t0_a02229800.bin)
0x0223911c id=0x06 fn=0xf009b6d6
0x02239124 id=0x07 fn=0xf009b6d6
0x0223912c id=0x08 fn=0xf009b6d6
0x02239134 id=0x09 fn=0xf009b6d6
0x0223913c id=0x0a fn=0xf009b6d6
0x02239144 id=0x0b fn=0xf009b6d6
0x0223914c id=0x0c fn=0xf009b6d6
0x02239154 id=0x0d fn=0xf009b6d6
0x0223915c id=0x0e fn=0xf009b6d6
0x02239164 id=0x0f fn=0xf009b6d6
0x0223916c id=0x10 fn=0xe00696d6
0x02239174 id=0x11 fn=0xe003d7b8
0x0223917c id=0x12 fn=0xe00472a2

187
dataset/stage0_baseline.csv Normal file
View file

@ -0,0 +1,187 @@
iso_time,monotonic_s,dbm
2026-08-21T23:50:20.262,0.0,-53
2026-08-21T23:50:20.321,0.056,-53
2026-08-21T23:50:20.375,0.114,-53
2026-08-21T23:50:20.430,0.168,-53
2026-08-21T23:50:20.484,0.222,-53
2026-08-21T23:50:20.538,0.277,-53
2026-08-21T23:50:20.591,0.331,-53
2026-08-21T23:50:20.650,0.385,-53
2026-08-21T23:50:20.704,0.443,-53
2026-08-21T23:50:20.762,0.498,-53
2026-08-21T23:50:20.817,0.555,-53
2026-08-21T23:50:20.884,0.613,-53
2026-08-21T23:50:20.942,0.676,-53
2026-08-21T23:50:20.999,0.734,-53
2026-08-21T23:50:21.053,0.791,-52
2026-08-21T23:50:21.106,0.845,-52
2026-08-21T23:50:21.159,0.898,-53
2026-08-21T23:50:21.213,0.952,-52
2026-08-21T23:50:21.268,1.006,-53
2026-08-21T23:50:21.321,1.06,-52
2026-08-21T23:50:21.375,1.114,-52
2026-08-21T23:50:21.428,1.167,-52
2026-08-21T23:50:21.481,1.221,-53
2026-08-21T23:50:21.535,1.274,-53
2026-08-21T23:50:21.590,1.328,-53
2026-08-21T23:50:21.644,1.382,-53
2026-08-21T23:50:21.697,1.436,-53
2026-08-21T23:50:21.756,1.493,-53
2026-08-21T23:50:21.809,1.548,-53
2026-08-21T23:50:21.864,1.602,-53
2026-08-21T23:50:21.917,1.656,-53
2026-08-21T23:50:21.971,1.71,-53
2026-08-21T23:50:22.024,1.764,-52
2026-08-21T23:50:22.080,1.818,-53
2026-08-21T23:50:22.134,1.873,-53
2026-08-21T23:50:22.188,1.927,-53
2026-08-21T23:50:22.242,1.981,-53
2026-08-21T23:50:22.297,2.034,-53
2026-08-21T23:50:22.350,2.089,-53
2026-08-21T23:50:22.403,2.142,-53
2026-08-21T23:50:22.456,2.196,-53
2026-08-21T23:50:22.511,2.249,-53
2026-08-21T23:50:22.564,2.304,-53
2026-08-21T23:50:22.618,2.357,-53
2026-08-21T23:50:22.672,2.41,-53
2026-08-21T23:50:22.726,2.464,-53
2026-08-21T23:50:22.779,2.518,-53
2026-08-21T23:50:22.833,2.572,-53
2026-08-21T23:50:22.887,2.626,-53
2026-08-21T23:50:22.940,2.679,-53
2026-08-21T23:50:22.993,2.732,-53
2026-08-21T23:50:23.046,2.786,-53
2026-08-21T23:50:23.100,2.838,-53
2026-08-21T23:50:23.154,2.892,-53
2026-08-21T23:50:23.207,2.946,-53
2026-08-21T23:50:23.261,3.0,-53
2026-08-21T23:50:23.315,3.054,-53
2026-08-21T23:50:23.368,3.108,-53
2026-08-21T23:50:23.421,3.161,-52
2026-08-21T23:50:23.475,3.214,-52
2026-08-21T23:50:23.530,3.269,-52
2026-08-21T23:50:23.584,3.323,-52
2026-08-21T23:50:23.638,3.377,-52
2026-08-21T23:50:23.692,3.431,-52
2026-08-21T23:50:23.747,3.485,-53
2026-08-21T23:50:23.801,3.54,-53
2026-08-21T23:50:23.854,3.593,-53
2026-08-21T23:50:23.909,3.647,-53
2026-08-21T23:50:23.969,3.705,-53
2026-08-21T23:50:24.024,3.762,-52
2026-08-21T23:50:24.078,3.816,-52
2026-08-21T23:50:24.132,3.871,-52
2026-08-21T23:50:24.186,3.925,-52
2026-08-21T23:50:24.239,3.978,-52
2026-08-21T23:50:24.292,4.031,-52
2026-08-21T23:50:24.346,4.085,-52
2026-08-21T23:50:24.401,4.139,-52
2026-08-21T23:50:24.454,4.193,-52
2026-08-21T23:50:24.507,4.246,-53
2026-08-21T23:50:24.561,4.3,-53
2026-08-21T23:50:24.615,4.353,-53
2026-08-21T23:50:24.671,4.408,-53
2026-08-21T23:50:24.726,4.463,-53
2026-08-21T23:50:24.780,4.518,-53
2026-08-21T23:50:24.833,4.572,-52
2026-08-21T23:50:24.890,4.625,-52
2026-08-21T23:50:24.944,4.682,-52
2026-08-21T23:50:24.998,4.736,-52
2026-08-21T23:50:25.051,4.791,-52
2026-08-21T23:50:25.104,4.844,-52
2026-08-21T23:50:25.158,4.897,-52
2026-08-21T23:50:25.211,4.95,-52
2026-08-21T23:50:25.264,5.004,-52
2026-08-21T23:50:25.317,5.057,-52
2026-08-21T23:50:25.370,5.11,-53
2026-08-21T23:50:25.423,5.163,-53
2026-08-21T23:50:25.476,5.216,-53
2026-08-21T23:50:25.530,5.269,-53
2026-08-21T23:50:25.583,5.322,-52
2026-08-21T23:50:25.636,5.375,-52
2026-08-21T23:50:25.688,5.428,-53
2026-08-21T23:50:25.741,5.481,-53
2026-08-21T23:50:25.794,5.533,-53
2026-08-21T23:50:25.847,5.586,-53
2026-08-21T23:50:25.900,5.639,-53
2026-08-21T23:50:25.953,5.692,-53
2026-08-21T23:50:26.005,5.745,-53
2026-08-21T23:50:26.059,5.798,-53
2026-08-21T23:50:26.111,5.851,-53
2026-08-21T23:50:26.164,5.904,-53
2026-08-21T23:50:26.216,5.956,-53
2026-08-21T23:50:26.269,6.009,-52
2026-08-21T23:50:26.321,6.061,-52
2026-08-21T23:50:26.374,6.114,-52
2026-08-21T23:50:26.426,6.167,-52
2026-08-21T23:50:26.479,6.219,-52
2026-08-21T23:50:26.532,6.271,-53
2026-08-21T23:50:26.584,6.324,-53
2026-08-21T23:50:26.637,6.377,-53
2026-08-21T23:50:26.690,6.429,-52
2026-08-21T23:50:26.743,6.483,-52
2026-08-21T23:50:26.796,6.535,-52
2026-08-21T23:50:26.848,6.588,-53
2026-08-21T23:50:26.901,6.641,-53
2026-08-21T23:50:26.955,6.694,-53
2026-08-21T23:50:27.008,6.747,-52
2026-08-21T23:50:27.063,6.8,-53
2026-08-21T23:50:27.115,6.855,-53
2026-08-21T23:50:27.168,6.908,-52
2026-08-21T23:50:27.221,6.961,-52
2026-08-21T23:50:27.273,7.013,-52
2026-08-21T23:50:27.326,7.066,-52
2026-08-21T23:50:27.379,7.119,-53
2026-08-21T23:50:27.432,7.171,-53
2026-08-21T23:50:27.485,7.224,-52
2026-08-21T23:50:27.538,7.277,-53
2026-08-21T23:50:27.590,7.33,-53
2026-08-21T23:50:27.646,7.384,-52
2026-08-21T23:50:27.699,7.439,-53
2026-08-21T23:50:27.752,7.491,-52
2026-08-21T23:50:27.811,7.545,-52
2026-08-21T23:50:27.866,7.604,-52
2026-08-21T23:50:27.921,7.658,-52
2026-08-21T23:50:27.974,7.713,-52
2026-08-21T23:50:28.027,7.767,-51
2026-08-21T23:50:28.080,7.82,-51
2026-08-21T23:50:28.134,7.872,-52
2026-08-21T23:50:28.187,7.926,-53
2026-08-21T23:50:28.241,7.98,-52
2026-08-21T23:50:28.294,8.033,-51
2026-08-21T23:50:28.351,8.089,-51
2026-08-21T23:50:28.411,8.145,-51
2026-08-21T23:50:28.466,8.205,-51
2026-08-21T23:50:28.519,8.258,-51
2026-08-21T23:50:28.573,8.312,-52
2026-08-21T23:50:28.628,8.366,-52
2026-08-21T23:50:28.682,8.421,-53
2026-08-21T23:50:28.736,8.475,-52
2026-08-21T23:50:28.791,8.528,-52
2026-08-21T23:50:28.845,8.583,-52
2026-08-21T23:50:28.898,8.638,-52
2026-08-21T23:50:28.952,8.691,-52
2026-08-21T23:50:29.005,8.744,-52
2026-08-21T23:50:29.058,8.797,-52
2026-08-21T23:50:29.112,8.851,-52
2026-08-21T23:50:29.166,8.905,-52
2026-08-21T23:50:29.219,8.958,-52
2026-08-21T23:50:29.272,9.011,-52
2026-08-21T23:50:29.324,9.064,-52
2026-08-21T23:50:29.376,9.117,-52
2026-08-21T23:50:29.434,9.173,-52
2026-08-21T23:50:29.486,9.226,-52
2026-08-21T23:50:29.538,9.278,-52
2026-08-21T23:50:29.591,9.33,-52
2026-08-21T23:50:29.643,9.383,-52
2026-08-21T23:50:29.697,9.436,-52
2026-08-21T23:50:29.750,9.489,-52
2026-08-21T23:50:29.803,9.542,-52
2026-08-21T23:50:29.855,9.595,-52
2026-08-21T23:50:29.908,9.648,-52
2026-08-21T23:50:29.961,9.7,-52
2026-08-21T23:50:30.013,9.753,-51
2026-08-21T23:50:30.067,9.806,-51
2026-08-21T23:50:30.120,9.86,-51
2026-08-21T23:50:30.173,9.913,-51
2026-08-21T23:50:30.226,9.966,-51
1 iso_time monotonic_s dbm
2 2026-08-21T23:50:20.262 0.0 -53
3 2026-08-21T23:50:20.321 0.056 -53
4 2026-08-21T23:50:20.375 0.114 -53
5 2026-08-21T23:50:20.430 0.168 -53
6 2026-08-21T23:50:20.484 0.222 -53
7 2026-08-21T23:50:20.538 0.277 -53
8 2026-08-21T23:50:20.591 0.331 -53
9 2026-08-21T23:50:20.650 0.385 -53
10 2026-08-21T23:50:20.704 0.443 -53
11 2026-08-21T23:50:20.762 0.498 -53
12 2026-08-21T23:50:20.817 0.555 -53
13 2026-08-21T23:50:20.884 0.613 -53
14 2026-08-21T23:50:20.942 0.676 -53
15 2026-08-21T23:50:20.999 0.734 -53
16 2026-08-21T23:50:21.053 0.791 -52
17 2026-08-21T23:50:21.106 0.845 -52
18 2026-08-21T23:50:21.159 0.898 -53
19 2026-08-21T23:50:21.213 0.952 -52
20 2026-08-21T23:50:21.268 1.006 -53
21 2026-08-21T23:50:21.321 1.06 -52
22 2026-08-21T23:50:21.375 1.114 -52
23 2026-08-21T23:50:21.428 1.167 -52
24 2026-08-21T23:50:21.481 1.221 -53
25 2026-08-21T23:50:21.535 1.274 -53
26 2026-08-21T23:50:21.590 1.328 -53
27 2026-08-21T23:50:21.644 1.382 -53
28 2026-08-21T23:50:21.697 1.436 -53
29 2026-08-21T23:50:21.756 1.493 -53
30 2026-08-21T23:50:21.809 1.548 -53
31 2026-08-21T23:50:21.864 1.602 -53
32 2026-08-21T23:50:21.917 1.656 -53
33 2026-08-21T23:50:21.971 1.71 -53
34 2026-08-21T23:50:22.024 1.764 -52
35 2026-08-21T23:50:22.080 1.818 -53
36 2026-08-21T23:50:22.134 1.873 -53
37 2026-08-21T23:50:22.188 1.927 -53
38 2026-08-21T23:50:22.242 1.981 -53
39 2026-08-21T23:50:22.297 2.034 -53
40 2026-08-21T23:50:22.350 2.089 -53
41 2026-08-21T23:50:22.403 2.142 -53
42 2026-08-21T23:50:22.456 2.196 -53
43 2026-08-21T23:50:22.511 2.249 -53
44 2026-08-21T23:50:22.564 2.304 -53
45 2026-08-21T23:50:22.618 2.357 -53
46 2026-08-21T23:50:22.672 2.41 -53
47 2026-08-21T23:50:22.726 2.464 -53
48 2026-08-21T23:50:22.779 2.518 -53
49 2026-08-21T23:50:22.833 2.572 -53
50 2026-08-21T23:50:22.887 2.626 -53
51 2026-08-21T23:50:22.940 2.679 -53
52 2026-08-21T23:50:22.993 2.732 -53
53 2026-08-21T23:50:23.046 2.786 -53
54 2026-08-21T23:50:23.100 2.838 -53
55 2026-08-21T23:50:23.154 2.892 -53
56 2026-08-21T23:50:23.207 2.946 -53
57 2026-08-21T23:50:23.261 3.0 -53
58 2026-08-21T23:50:23.315 3.054 -53
59 2026-08-21T23:50:23.368 3.108 -53
60 2026-08-21T23:50:23.421 3.161 -52
61 2026-08-21T23:50:23.475 3.214 -52
62 2026-08-21T23:50:23.530 3.269 -52
63 2026-08-21T23:50:23.584 3.323 -52
64 2026-08-21T23:50:23.638 3.377 -52
65 2026-08-21T23:50:23.692 3.431 -52
66 2026-08-21T23:50:23.747 3.485 -53
67 2026-08-21T23:50:23.801 3.54 -53
68 2026-08-21T23:50:23.854 3.593 -53
69 2026-08-21T23:50:23.909 3.647 -53
70 2026-08-21T23:50:23.969 3.705 -53
71 2026-08-21T23:50:24.024 3.762 -52
72 2026-08-21T23:50:24.078 3.816 -52
73 2026-08-21T23:50:24.132 3.871 -52
74 2026-08-21T23:50:24.186 3.925 -52
75 2026-08-21T23:50:24.239 3.978 -52
76 2026-08-21T23:50:24.292 4.031 -52
77 2026-08-21T23:50:24.346 4.085 -52
78 2026-08-21T23:50:24.401 4.139 -52
79 2026-08-21T23:50:24.454 4.193 -52
80 2026-08-21T23:50:24.507 4.246 -53
81 2026-08-21T23:50:24.561 4.3 -53
82 2026-08-21T23:50:24.615 4.353 -53
83 2026-08-21T23:50:24.671 4.408 -53
84 2026-08-21T23:50:24.726 4.463 -53
85 2026-08-21T23:50:24.780 4.518 -53
86 2026-08-21T23:50:24.833 4.572 -52
87 2026-08-21T23:50:24.890 4.625 -52
88 2026-08-21T23:50:24.944 4.682 -52
89 2026-08-21T23:50:24.998 4.736 -52
90 2026-08-21T23:50:25.051 4.791 -52
91 2026-08-21T23:50:25.104 4.844 -52
92 2026-08-21T23:50:25.158 4.897 -52
93 2026-08-21T23:50:25.211 4.95 -52
94 2026-08-21T23:50:25.264 5.004 -52
95 2026-08-21T23:50:25.317 5.057 -52
96 2026-08-21T23:50:25.370 5.11 -53
97 2026-08-21T23:50:25.423 5.163 -53
98 2026-08-21T23:50:25.476 5.216 -53
99 2026-08-21T23:50:25.530 5.269 -53
100 2026-08-21T23:50:25.583 5.322 -52
101 2026-08-21T23:50:25.636 5.375 -52
102 2026-08-21T23:50:25.688 5.428 -53
103 2026-08-21T23:50:25.741 5.481 -53
104 2026-08-21T23:50:25.794 5.533 -53
105 2026-08-21T23:50:25.847 5.586 -53
106 2026-08-21T23:50:25.900 5.639 -53
107 2026-08-21T23:50:25.953 5.692 -53
108 2026-08-21T23:50:26.005 5.745 -53
109 2026-08-21T23:50:26.059 5.798 -53
110 2026-08-21T23:50:26.111 5.851 -53
111 2026-08-21T23:50:26.164 5.904 -53
112 2026-08-21T23:50:26.216 5.956 -53
113 2026-08-21T23:50:26.269 6.009 -52
114 2026-08-21T23:50:26.321 6.061 -52
115 2026-08-21T23:50:26.374 6.114 -52
116 2026-08-21T23:50:26.426 6.167 -52
117 2026-08-21T23:50:26.479 6.219 -52
118 2026-08-21T23:50:26.532 6.271 -53
119 2026-08-21T23:50:26.584 6.324 -53
120 2026-08-21T23:50:26.637 6.377 -53
121 2026-08-21T23:50:26.690 6.429 -52
122 2026-08-21T23:50:26.743 6.483 -52
123 2026-08-21T23:50:26.796 6.535 -52
124 2026-08-21T23:50:26.848 6.588 -53
125 2026-08-21T23:50:26.901 6.641 -53
126 2026-08-21T23:50:26.955 6.694 -53
127 2026-08-21T23:50:27.008 6.747 -52
128 2026-08-21T23:50:27.063 6.8 -53
129 2026-08-21T23:50:27.115 6.855 -53
130 2026-08-21T23:50:27.168 6.908 -52
131 2026-08-21T23:50:27.221 6.961 -52
132 2026-08-21T23:50:27.273 7.013 -52
133 2026-08-21T23:50:27.326 7.066 -52
134 2026-08-21T23:50:27.379 7.119 -53
135 2026-08-21T23:50:27.432 7.171 -53
136 2026-08-21T23:50:27.485 7.224 -52
137 2026-08-21T23:50:27.538 7.277 -53
138 2026-08-21T23:50:27.590 7.33 -53
139 2026-08-21T23:50:27.646 7.384 -52
140 2026-08-21T23:50:27.699 7.439 -53
141 2026-08-21T23:50:27.752 7.491 -52
142 2026-08-21T23:50:27.811 7.545 -52
143 2026-08-21T23:50:27.866 7.604 -52
144 2026-08-21T23:50:27.921 7.658 -52
145 2026-08-21T23:50:27.974 7.713 -52
146 2026-08-21T23:50:28.027 7.767 -51
147 2026-08-21T23:50:28.080 7.82 -51
148 2026-08-21T23:50:28.134 7.872 -52
149 2026-08-21T23:50:28.187 7.926 -53
150 2026-08-21T23:50:28.241 7.98 -52
151 2026-08-21T23:50:28.294 8.033 -51
152 2026-08-21T23:50:28.351 8.089 -51
153 2026-08-21T23:50:28.411 8.145 -51
154 2026-08-21T23:50:28.466 8.205 -51
155 2026-08-21T23:50:28.519 8.258 -51
156 2026-08-21T23:50:28.573 8.312 -52
157 2026-08-21T23:50:28.628 8.366 -52
158 2026-08-21T23:50:28.682 8.421 -53
159 2026-08-21T23:50:28.736 8.475 -52
160 2026-08-21T23:50:28.791 8.528 -52
161 2026-08-21T23:50:28.845 8.583 -52
162 2026-08-21T23:50:28.898 8.638 -52
163 2026-08-21T23:50:28.952 8.691 -52
164 2026-08-21T23:50:29.005 8.744 -52
165 2026-08-21T23:50:29.058 8.797 -52
166 2026-08-21T23:50:29.112 8.851 -52
167 2026-08-21T23:50:29.166 8.905 -52
168 2026-08-21T23:50:29.219 8.958 -52
169 2026-08-21T23:50:29.272 9.011 -52
170 2026-08-21T23:50:29.324 9.064 -52
171 2026-08-21T23:50:29.376 9.117 -52
172 2026-08-21T23:50:29.434 9.173 -52
173 2026-08-21T23:50:29.486 9.226 -52
174 2026-08-21T23:50:29.538 9.278 -52
175 2026-08-21T23:50:29.591 9.33 -52
176 2026-08-21T23:50:29.643 9.383 -52
177 2026-08-21T23:50:29.697 9.436 -52
178 2026-08-21T23:50:29.750 9.489 -52
179 2026-08-21T23:50:29.803 9.542 -52
180 2026-08-21T23:50:29.855 9.595 -52
181 2026-08-21T23:50:29.908 9.648 -52
182 2026-08-21T23:50:29.961 9.7 -52
183 2026-08-21T23:50:30.013 9.753 -51
184 2026-08-21T23:50:30.067 9.806 -51
185 2026-08-21T23:50:30.120 9.86 -51
186 2026-08-21T23:50:30.173 9.913 -51
187 2026-08-21T23:50:30.226 9.966 -51

1605
dataset/stage0_walk1.csv Normal file

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,29 @@
0x10201308 id=0x01 fn=0x10201bd0 MCU_EXT_CMD_EFUSE_ACCESS
0x1020130c id=0x02 fn=0x10201b90 MCU_EXT_CMD_DEV_INFO_UPDATE
0x10201310 id=0x03 fn=0x10201ba4 (MTK-internal id)
0x10201314 id=0x04 fn=0x10201b78 MCU_EXT_CMD_RF_TEST
0x10201320 id=0x07 fn=0x10201934 MCU_EXT_CMD_PM_STATE_CTRL
0x10201324 id=0x08 fn=0x10201910 MCU_EXT_CMD_CHANNEL_SWITCH
0x10201330 id=0x0b fn=0x1020164c (MTK-internal id)
0x1020133c id=0x0e fn=0x10201614 (MTK-internal id)
0x10201340 id=0x0f fn=0x102015f0 (MTK-internal id)
0x10201344 id=0x10 fn=0x102015c4 (MTK-internal id)
0x10201348 id=0x11 fn=0x102015a0 MCU_EXT_CMD_SET_TX_POWER_CTRL
0x1020134c id=0x12 fn=0x102018fc (MTK-internal id)
0x10201350 id=0x13 fn=0x102016fc MCU_EXT_CMD_FW_LOG_2_HOST
0x10201354 id=0x14 fn=0x102016bc (MTK-internal id)
0x10201358 id=0x15 fn=0x10201688 (MTK-internal id)
0x1020135c id=0x16 fn=0x1020158c (MTK-internal id)
0x10201360 id=0x17 fn=0x10201580 (MTK-internal id)
0x10201364 id=0x18 fn=0x1020155c (MTK-internal id)
0x10201368 id=0x19 fn=0x10201530 (MTK-internal id)
0x1020138c id=0x22 fn=0x102014fc (MTK-internal id)
0x10201390 id=0x23 fn=0x1020143c MCU_EXT_CMD_THERMAL_PROT
0x102013a4 id=0x28 fn=0x10201408 (MTK-internal id)
0x102013a8 id=0x29 fn=0x10201944 (MTK-internal id)
0x102013ac id=0x2a fn=0x102014e4 (MTK-internal id)
0x102013b0 id=0x2b fn=0x10201520 (MTK-internal id)
0x102013b4 id=0x2c fn=0x10201634 MCU_EXT_CMD_THERMAL_CTRL
0x102013c8 id=0x31 fn=0x10201668 (MTK-internal id)
0x102013cc id=0x32 fn=0x10201674 MCU_EXT_CMD_WTBL_UPDATE
0x10201404 id=0x40 fn=0x10201950 (MTK-internal id)

View file

@ -0,0 +1,422 @@
# 9-entry {id,fn} array @ 0x02231ba8 (r5_t0_a02229800.bin)
0x02231ba8 id=0x00 fn=0xf009707c (MTK-internal id)
0x02231bb0 id=0x09 fn=0xf00963a6 (MTK-internal id)
0x02231bb8 id=0x0a fn=0xf0096430 (MTK-internal id)
0x02231bc0 id=0x0e fn=0xf0096846 (MTK-internal id)
0x02231bc8 id=0x0d fn=0xe0040280 (MTK-internal id)
0x02231bd0 id=0x0f fn=0xf0096b72 (MTK-internal id)
0x02231bd8 id=0x01 fn=0xe00795c8 MCU_EXT_CMD_EFUSE_ACCESS
0x02231be0 id=0x03 fn=0xe00799a8 (MTK-internal id)
0x02231be8 id=0x04 fn=0xe0067480 MCU_EXT_CMD_RF_TEST
# 29-entry {id,fn} array @ 0x02231bf8 (r5_t0_a02229800.bin)
0x02231bf8 id=0x06 fn=0xf00969ca (MTK-internal id)
0x02231c00 id=0x0b fn=0xe004649e (MTK-internal id)
0x02231c08 id=0x0c fn=0xf0096150 (MTK-internal id)
0x02231c10 id=0x10 fn=0xf009606e (MTK-internal id)
0x02231c18 id=0x11 fn=0xf00961a4 MCU_EXT_CMD_SET_TX_POWER_CTRL
0x02231c20 id=0x12 fn=0xe0098294 (MTK-internal id)
0x02231c28 id=0x14 fn=0xe00660b0 (MTK-internal id)
0x02231c30 id=0x24 fn=0xf00961f8 (MTK-internal id)
0x02231c38 id=0x18 fn=0xf0096000 (MTK-internal id)
0x02231c40 id=0x00 fn=0xe003fae4 (MTK-internal id)
0x02231c48 id=0x01 fn=0xe003fbe8 MCU_EXT_CMD_EFUSE_ACCESS
0x02231c50 id=0x02 fn=0xe003fc4c MCU_EXT_CMD_DEV_INFO_UPDATE
0x02231c58 id=0x03 fn=0xe003fcb0 (MTK-internal id)
0x02231c60 id=0x04 fn=0xe003fd14 MCU_EXT_CMD_RF_TEST
0x02231c68 id=0x05 fn=0xe003fd78 MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x02231c70 id=0x06 fn=0xe003fda4 (MTK-internal id)
0x02231c78 id=0x07 fn=0xe003fdda MCU_EXT_CMD_PM_STATE_CTRL
0x02231c80 id=0x08 fn=0xe003ff5c MCU_EXT_CMD_CHANNEL_SWITCH
0x02231c88 id=0x09 fn=0xe0040000 (MTK-internal id)
0x02231c90 id=0x0a fn=0xe0040056 (MTK-internal id)
0x02231c98 id=0x0c fn=0xe003face (MTK-internal id)
0x02231ca0 id=0x0d fn=0xe0040082 (MTK-internal id)
0x02231ca8 id=0x0e fn=0xe003fae0 (MTK-internal id)
0x02231cb0 id=0x0f fn=0xe00400ae (MTK-internal id)
0x02231cb8 id=0x10 fn=0xe00401b8 (MTK-internal id)
0x02231cc0 id=0x11 fn=0xe003fe5e MCU_EXT_CMD_SET_TX_POWER_CTRL
0x02231cc8 id=0x13 fn=0xe00401e4 MCU_EXT_CMD_FW_LOG_2_HOST
0x02231cd0 id=0x12 fn=0xe00401f6 (MTK-internal id)
0x02231cd8 id=0x15 fn=0xe0040254 (MTK-internal id)
# 38-entry {id,fn} array @ 0x02231ea8 (r5_t0_a02229800.bin)
0x02231ea8 id=0x07 fn=0xe0040914 MCU_EXT_CMD_PM_STATE_CTRL
0x02231eb0 id=0x25 fn=0xf0097174 MCU_EXT_CMD_STA_REC_UPDATE
0x02231eb8 id=0x26 fn=0xe0092848 MCU_EXT_CMD_BSS_INFO_UPDATE
0x02231ec0 id=0x2a fn=0xe00928c6 (MTK-internal id)
0x02231ec8 id=0xbf fn=0xe009277c (MTK-internal id)
0x02231ed0 id=0x13 fn=0xe0042006 MCU_EXT_CMD_FW_LOG_2_HOST
0x02231ed8 id=0x27 fn=0xe005e710 MCU_EXT_CMD_EDCA_UPDATE
0x02231ee0 id=0x28 fn=0xe0060b5e (MTK-internal id)
0x02231ee8 id=0x47 fn=0xe005f636 MCU_EXT_CMD_RX_HDR_TRANS
0x02231ef0 id=0x48 fn=0xe005f796 MCU_EXT_CMD_MUAR_UPDATE
0x02231ef8 id=0x93 fn=0xe005f5ae (MTK-internal id)
0x02231f00 id=0x32 fn=0xe00402fa MCU_EXT_CMD_WTBL_UPDATE
0x02231f08 id=0x49 fn=0xe003ee7e MCU_EXT_CMD_BCN_OFFLOAD
0x02231f10 id=0xa6 fn=0xe005db74 (MTK-internal id)
0x02231f18 id=0xae fn=0xe005f706 (MTK-internal id)
0x02231f20 id=0x95 fn=0xe004297c MCU_EXT_CMD_FW_DBG_CTRL
0x02231f28 id=0x81 fn=0xe005d480 MCU_EXT_CMD_SET_SER_TRIGGER
0x02231f30 id=0x57 fn=0xe0042558 (MTK-internal id)
0x02231f38 id=0x9c fn=0xe0043588 (MTK-internal id)
0x02231f40 id=0x94 fn=0xe0040de4 MCU_EXT_CMD_TWT_AGRT_UPDATE
0x02231f48 id=0x02 fn=0xe007fade MCU_EXT_CMD_DEV_INFO_UPDATE
0x02231f50 id=0xb7 fn=0xe0042f70 (MTK-internal id)
0x02231f58 id=0xc4 fn=0xe0043248 (MTK-internal id)
0x02231f60 id=0x98 fn=0xe0061e48 (MTK-internal id)
0x02231f68 id=0x42 fn=0xe005f5ec (MTK-internal id)
0x02231f70 id=0x50 fn=0xe0047c90 (MTK-internal id)
0x02231f78 id=0x5a fn=0xe004166c MCU_EXT_CMD_GET_MIB_INFO
0x02231f80 id=0x3c fn=0xe00414ec (MTK-internal id)
0x02231f88 id=0x1e fn=0xe00663b2 MCU_EXT_CMD_TXBF_ACTION
0x02231f90 id=0x36 fn=0xe0062e16 MCU_EXT_CMD_SET_DRR_CTRL
0x02231f98 id=0x38 fn=0xe00640fe (MTK-internal id)
0x02231fa0 id=0x37 fn=0xe0062b62 (MTK-internal id)
0x02231fa8 id=0x4b fn=0xe0062bfe (MTK-internal id)
0x02231fb0 id=0x4a fn=0xe0062eae MCU_EXT_CMD_RX_AIRTIME_CTRL
0x02231fb8 id=0x67 fn=0xe0064714 MCU_EXT_CMD_CAL_CACHE
0x02231fc0 id=0x68 fn=0xe0063182 MCU_EXT_CMD_RED_ENABLE
0x02231fc8 id=0x6b fn=0xe00645da (MTK-internal id)
0x02231fd0 id=0x01 fn=0xe0090b8a MCU_EXT_CMD_EFUSE_ACCESS
# 31-entry {id,fn} array @ 0x02231fe0 (r5_t0_a02229800.bin)
0x02231fe0 id=0x04 fn=0xe008a8ae MCU_EXT_CMD_RF_TEST
0x02231fe8 id=0x08 fn=0xe0080680 MCU_EXT_CMD_CHANNEL_SWITCH
0x02231ff0 id=0x4e fn=0xe0080680 MCU_EXT_CMD_SET_RX_PATH
0x02231ff8 id=0x4f fn=0xe00897a0 MCU_EXT_CMD_EFUSE_FREE_BLOCK
0x02232000 id=0x19 fn=0xe00918a0 (MTK-internal id)
0x02232008 id=0x1f fn=0xe007d684 (MTK-internal id)
0x02232010 id=0x21 fn=0xe00804ac MCU_EXT_CMD_EFUSE_BUFFER_MODE
0x02232018 id=0x9b fn=0xe007ee5e (MTK-internal id)
0x02232020 id=0xbe fn=0xe007ef44 (MTK-internal id)
0x02232028 id=0x24 fn=0xe00407aa (MTK-internal id)
0x02232030 id=0x2c fn=0xe008bf86 MCU_EXT_CMD_THERMAL_CTRL
0x02232038 id=0x30 fn=0xe007a9b2 (MTK-internal id)
0x02232040 id=0x79 fn=0xe0080b88 (MTK-internal id)
0x02232048 id=0x17 fn=0xe0042d38 (MTK-internal id)
0x02232050 id=0x82 fn=0xe0082128 (MTK-internal id)
0x02232058 id=0x3d fn=0xe008a938 MCU_EXT_CMD_ATE_CTRL
0x02232060 id=0x3e fn=0xe0081686 MCU_EXT_CMD_PROTECT_CTRL
0x02232068 id=0x9f fn=0xe0045f3c MCU_EXT_CMD_MURU_CTRL
0x02232070 id=0x87 fn=0x0221cf98 (MTK-internal id)
0x02232078 id=0x3a fn=0xe007ce40 MCU_EXT_CMD_SET_RDD_CTRL
0x02232080 id=0xa3 fn=0xe007cb80 (MTK-internal id)
0x02232088 id=0xc5 fn=0xe007cd20 (MTK-internal id)
0x02232090 id=0x9d fn=0xe007c0c0 MCU_EXT_CMD_SET_RDD_TH
0x02232098 id=0xb2 fn=0xe007c138 (MTK-internal id)
0x022320a0 id=0x46 fn=0xe004174a MCU_EXT_CMD_MAC_INIT_CTRL
0x022320a8 id=0x44 fn=0xe0048392 (MTK-internal id)
0x022320b0 id=0x43 fn=0xe004197c (MTK-internal id)
0x022320b8 id=0x23 fn=0xe008bca8 MCU_EXT_CMD_THERMAL_PROT
0x022320c0 id=0x56 fn=0xe006cf68 (MTK-internal id)
0x022320c8 id=0x58 fn=0xe008cf2a MCU_EXT_CMD_TX_POWER_FEATURE_CTRL
0x022320d0 id=0xa1 fn=0xe00419c6 (MTK-internal id)
# 24-entry {id,fn} array @ 0x022320e0 (r5_t0_a02229800.bin)
0x022320e0 id=0xad fn=0xe00779ac MCU_EXT_CMD_PHY_STAT_INFO
0x022320e8 id=0xb5 fn=0xe0077e68 (MTK-internal id)
0x022320f0 id=0x73 fn=0xe0040778 (MTK-internal id)
0x022320f8 id=0x9a fn=0xe0080024 MCU_EXT_CMD_OFFCH_SCAN_CTRL
0x02232100 id=0xab fn=0xe008a67c MCU_EXT_CMD_GROUP_PRE_CAL_INFO
0x02232108 id=0xac fn=0xe008a6ce MCU_EXT_CMD_DPD_PRE_CAL_INFO
0x02232110 id=0xa8 fn=0xe0083ede MCU_EXT_CMD_SET_SPR
0x02232118 id=0xa4 fn=0xe008aadc (MTK-internal id)
0x02232120 id=0xb3 fn=0xe008ae7c (MTK-internal id)
0x02232128 id=0xb6 fn=0xe0078664 (MTK-internal id)
0x02232130 id=0xb8 fn=0xe0048010 (MTK-internal id)
0x02232138 id=0xb9 fn=0xe007944c (MTK-internal id)
0x02232140 id=0xba fn=0xe00814f0 (MTK-internal id)
0x02232148 id=0xc8 fn=0xe00419fc (MTK-internal id)
0x02232150 id=0x7a fn=0xe0041a42 (MTK-internal id)
0x02232158 id=0x7b fn=0xe00417d0 (MTK-internal id)
0x02232160 id=0x7c fn=0xe0041854 MCU_EXT_CMD_SET_RADAR_TH
0x02232168 id=0xc6 fn=0xe00418ae (MTK-internal id)
0x02232170 id=0xc7 fn=0xe0041702 (MTK-internal id)
0x02232178 id=0xc0 fn=0xe007ebc0 (MTK-internal id)
0x02232180 id=0xc2 fn=0xe00482e4 (MTK-internal id)
0x02232188 id=0xd5 fn=0xe005dde4 (MTK-internal id)
0x02232190 id=0x0f fn=0xe0046e14 (MTK-internal id)
0x02232198 id=0x5b fn=0xe0081550 (MTK-internal id)
# 43-entry {id,fn} array @ 0x022324ec (r5_t0_a02229800.bin)
0x022324ec id=0x01 fn=0xe0045a7e MCU_EXT_CMD_EFUSE_ACCESS
0x022324f4 id=0x06 fn=0xe0043b36 (MTK-internal id)
0x022324fc id=0x0b fn=0xe0043c6c (MTK-internal id)
0x02232504 id=0x14 fn=0xe00452b6 (MTK-internal id)
0x0223250c id=0x15 fn=0xe0043990 (MTK-internal id)
0x02232514 id=0x0c fn=0xe0043884 (MTK-internal id)
0x0223251c id=0x0d fn=0xe0043ba0 (MTK-internal id)
0x02232524 id=0x0e fn=0xe0044aec (MTK-internal id)
0x0223252c id=0x0f fn=0xe0043dc2 (MTK-internal id)
0x02232534 id=0x10 fn=0xe0044092 (MTK-internal id)
0x0223253c id=0x11 fn=0xe0045950 MCU_EXT_CMD_SET_TX_POWER_CTRL
0x02232544 id=0x12 fn=0xe0044b00 (MTK-internal id)
0x0223254c id=0x13 fn=0xe0043c06 MCU_EXT_CMD_FW_LOG_2_HOST
0x02232554 id=0x33 fn=0xe0043e1a (MTK-internal id)
0x0223255c id=0x18 fn=0xe00440ac (MTK-internal id)
0x02232564 id=0x19 fn=0xe0043a7a (MTK-internal id)
0x0223256c id=0x1a fn=0xe00441ac (MTK-internal id)
0x02232574 id=0x1b fn=0xe00441c8 (MTK-internal id)
0x0223257c id=0x50 fn=0xe00439a0 (MTK-internal id)
0x02232584 id=0x51 fn=0xe004552a (MTK-internal id)
0x0223258c id=0x64 fn=0xe004432a (MTK-internal id)
0x02232594 id=0x65 fn=0xe0043e58 (MTK-internal id)
0x0223259c id=0x66 fn=0xe0043b1c (MTK-internal id)
0x022325a4 id=0x67 fn=0xe0043cbe MCU_EXT_CMD_CAL_CACHE
0x022325ac id=0x68 fn=0xe0043ec2 MCU_EXT_CMD_RED_ENABLE
0x022325b4 id=0x69 fn=0xe0043a00 (MTK-internal id)
0x022325bc id=0x6a fn=0xe0043a1a (MTK-internal id)
0x022325c4 id=0xc8 fn=0xe0044292 (MTK-internal id)
0x022325cc id=0xc9 fn=0xe00442c0 (MTK-internal id)
0x022325d4 id=0xca fn=0xe0043a42 (MTK-internal id)
0x022325dc id=0xcb fn=0xe0044b10 (MTK-internal id)
0x022325e4 id=0xcc fn=0xe0043a64 (MTK-internal id)
0x022325ec id=0xcd fn=0xe0043aa6 (MTK-internal id)
0x022325f4 id=0xd2 fn=0xe0043f1a (MTK-internal id)
0x022325fc id=0xd3 fn=0xe0043f4a (MTK-internal id)
0x02232604 id=0xd0 fn=0xe0043f8c (MTK-internal id)
0x0223260c id=0xd1 fn=0xe0043fbc (MTK-internal id)
0x02232614 id=0x96 fn=0xe0043abc (MTK-internal id)
0x0223261c id=0x97 fn=0xe00441ee (MTK-internal id)
0x02232624 id=0xd4 fn=0xe0043fec (MTK-internal id)
0x0223262c id=0xfe fn=0xe0044bde (MTK-internal id)
0x02232634 id=0xce fn=0xe0043d32 (MTK-internal id)
0x0223263c id=0xcf fn=0xe0043aca (MTK-internal id)
# 8-entry {id,fn} array @ 0x0223670c (r5_t0_a02229800.bin)
0x0223670c id=0x00 fn=0xe0077a2c (MTK-internal id)
0x02236714 id=0x01 fn=0xe0077a5c MCU_EXT_CMD_EFUSE_ACCESS
0x0223671c id=0x02 fn=0xe007758c MCU_EXT_CMD_DEV_INFO_UPDATE
0x02236724 id=0x03 fn=0xe007747c (MTK-internal id)
0x0223672c id=0x04 fn=0xe0077aa2 MCU_EXT_CMD_RF_TEST
0x02236734 id=0x05 fn=0xe00776a8 MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x0223673c id=0x06 fn=0xe0077478 (MTK-internal id)
0x02236744 id=0x07 fn=0xe00776b6 MCU_EXT_CMD_PM_STATE_CTRL
# 92-entry {id,fn} array @ 0x02236bf0 (r5_t0_a02229800.bin)
0x02236bf0 id=0x01 fn=0xe0083c88 MCU_EXT_CMD_EFUSE_ACCESS
0x02236bf8 id=0x02 fn=0xe00844f2 MCU_EXT_CMD_DEV_INFO_UPDATE
0x02236c00 id=0x03 fn=0xe00838c6 (MTK-internal id)
0x02236c08 id=0x04 fn=0xe008453c MCU_EXT_CMD_RF_TEST
0x02236c10 id=0x05 fn=0xe0083aa0 MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x02236c18 id=0x06 fn=0xe008461a (MTK-internal id)
0x02236c20 id=0x07 fn=0xe0083d1e MCU_EXT_CMD_PM_STATE_CTRL
0x02236c28 id=0x08 fn=0xe0084666 MCU_EXT_CMD_CHANNEL_SWITCH
0x02236c30 id=0x09 fn=0xe0083d62 (MTK-internal id)
0x02236c38 id=0x0a fn=0xe00846b2 (MTK-internal id)
0x02236c40 id=0x0b fn=0xe00838dc (MTK-internal id)
0x02236c48 id=0x0c fn=0xe0084586 (MTK-internal id)
0x02236c50 id=0x0d fn=0xe00838f2 (MTK-internal id)
0x02236c58 id=0x0e fn=0xe00845d0 (MTK-internal id)
0x02236c60 id=0x0f fn=0xe0083908 (MTK-internal id)
0x02236c68 id=0x10 fn=0xe00846fe (MTK-internal id)
0x02236c70 id=0x11 fn=0xe008391a MCU_EXT_CMD_SET_TX_POWER_CTRL
0x02236c78 id=0x12 fn=0xe0084748 (MTK-internal id)
0x02236c80 id=0x13 fn=0xe008392c MCU_EXT_CMD_FW_LOG_2_HOST
0x02236c88 id=0x14 fn=0xe0084792 (MTK-internal id)
0x02236c90 id=0x15 fn=0xe008393e (MTK-internal id)
0x02236c98 id=0x16 fn=0xe00847dc (MTK-internal id)
0x02236ca0 id=0x17 fn=0xe0083950 (MTK-internal id)
0x02236ca8 id=0x18 fn=0xe0084826 (MTK-internal id)
0x02236cb0 id=0x19 fn=0xe0083962 (MTK-internal id)
0x02236cb8 id=0x1a fn=0xe008486e (MTK-internal id)
0x02236cc0 id=0x1b fn=0xe0083974 (MTK-internal id)
0x02236cc8 id=0x1c fn=0xe00848b8 (MTK-internal id)
0x02236cd0 id=0x1d fn=0xe0083986 (MTK-internal id)
0x02236cd8 id=0x1e fn=0xe0084902 MCU_EXT_CMD_TXBF_ACTION
0x02236ce0 id=0x1f fn=0xe0083998 (MTK-internal id)
0x02236ce8 id=0x20 fn=0xe008494c (MTK-internal id)
0x02236cf0 id=0x21 fn=0xe00839aa MCU_EXT_CMD_EFUSE_BUFFER_MODE
0x02236cf8 id=0x22 fn=0xe0084996 (MTK-internal id)
0x02236d00 id=0x23 fn=0xe00839c2 MCU_EXT_CMD_THERMAL_PROT
0x02236d08 id=0x24 fn=0xe00849e2 (MTK-internal id)
0x02236d10 id=0x25 fn=0xe00839da MCU_EXT_CMD_STA_REC_UPDATE
0x02236d18 id=0x26 fn=0xe0084a2e MCU_EXT_CMD_BSS_INFO_UPDATE
0x02236d20 id=0x27 fn=0xe00839f2 MCU_EXT_CMD_EDCA_UPDATE
0x02236d28 id=0x28 fn=0xe0084a7a (MTK-internal id)
0x02236d30 id=0x29 fn=0xe0083db0 (MTK-internal id)
0x02236d38 id=0x2a fn=0xe0084ac6 (MTK-internal id)
0x02236d40 id=0x2b fn=0xe0083d8e (MTK-internal id)
0x02236d48 id=0x2c fn=0xe0084b12 MCU_EXT_CMD_THERMAL_CTRL
0x02236d50 id=0x2d fn=0xe0083a20 (MTK-internal id)
0x02236d58 id=0x2e fn=0xe0084b5e (MTK-internal id)
0x02236d60 id=0x31 fn=0xe0083a38 (MTK-internal id)
0x02236d68 id=0x32 fn=0xe0084baa MCU_EXT_CMD_WTBL_UPDATE
0x02236d70 id=0x33 fn=0xe0083a50 (MTK-internal id)
0x02236d78 id=0x34 fn=0xe0084bf6 (MTK-internal id)
0x02236d80 id=0x80 fn=0xe0083ddc MCU_EXT_CMD_MWDS_SUPPORT
0x02236d88 id=0x81 fn=0xe0084d06 MCU_EXT_CMD_SET_SER_TRIGGER
0x02236d90 id=0x82 fn=0xe0083ccc (MTK-internal id)
0x02236d98 id=0x83 fn=0xe0084c42 (MTK-internal id)
0x02236da0 id=0x84 fn=0xe0084cae (MTK-internal id)
0x02236da8 id=0x85 fn=0xe008385c (MTK-internal id)
0x02236db0 id=0x86 fn=0xe0083884 (MTK-internal id)
0x02236db8 id=0x87 fn=0xe0083b6a (MTK-internal id)
0x02236dc0 id=0x88 fn=0xe0083fc2 (MTK-internal id)
0x02236dc8 id=0x89 fn=0xe0083cec (MTK-internal id)
0x02236dd0 id=0x8a fn=0xe0084d5a (MTK-internal id)
0x02236dd8 id=0xc0 fn=0xe0083b10 (MTK-internal id)
0x02236de0 id=0xc1 fn=0xe00840cc (MTK-internal id)
0x02236de8 id=0xc2 fn=0xe0083b24 (MTK-internal id)
0x02236df0 id=0xc3 fn=0xe0084112 (MTK-internal id)
0x02236df8 id=0xc4 fn=0xe0083ba0 (MTK-internal id)
0x02236e00 id=0xc5 fn=0xe00841a0 (MTK-internal id)
0x02236e08 id=0xc6 fn=0xe0083bb4 (MTK-internal id)
0x02236e10 id=0xc7 fn=0xe00841e6 (MTK-internal id)
0x02236e18 id=0xc8 fn=0xe0083bc8 (MTK-internal id)
0x02236e20 id=0xc9 fn=0xe008422c (MTK-internal id)
0x02236e28 id=0xca fn=0xe0083bdc (MTK-internal id)
0x02236e30 id=0xcb fn=0xe0084272 (MTK-internal id)
0x02236e38 id=0xcc fn=0xe0083bf0 (MTK-internal id)
0x02236e40 id=0xcd fn=0xe00842b8 (MTK-internal id)
0x02236e48 id=0xce fn=0xe0083f4e (MTK-internal id)
0x02236e50 id=0xcf fn=0xe00842fe (MTK-internal id)
0x02236e58 id=0xd0 fn=0xe0083c1a (MTK-internal id)
0x02236e60 id=0xd1 fn=0xe0084394 (MTK-internal id)
0x02236e68 id=0xd2 fn=0xe0083c04 (MTK-internal id)
0x02236e70 id=0xd3 fn=0xe0083aec (MTK-internal id)
0x02236e78 id=0xd4 fn=0xe0084158 (MTK-internal id)
0x02236e80 id=0xd5 fn=0xe0083c2e (MTK-internal id)
0x02236e88 id=0xd6 fn=0xe00843da (MTK-internal id)
0x02236e90 id=0xd7 fn=0xe0083c42 (MTK-internal id)
0x02236e98 id=0xd8 fn=0xe0084420 (MTK-internal id)
0x02236ea0 id=0xd9 fn=0xe0083c56 (MTK-internal id)
0x02236ea8 id=0xda fn=0xe0084466 (MTK-internal id)
0x02236eb0 id=0xdb fn=0xe00844ac (MTK-internal id)
0x02236eb8 id=0xdc fn=0xe0083c6a (MTK-internal id)
0x02236ec0 id=0xdd fn=0xe0084346 (MTK-internal id)
0x02236ec8 id=0xea fn=0xe0083a6a (MTK-internal id)
# 10-entry {id,fn} array @ 0x0223833c (r5_t0_a02229800.bin)
0x0223833c id=0x00 fn=0xe008f91e (MTK-internal id)
0x02238344 id=0x01 fn=0xe008f068 MCU_EXT_CMD_EFUSE_ACCESS
0x0223834c id=0x02 fn=0xe008f080 MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238354 id=0x03 fn=0xe008f098 (MTK-internal id)
0x0223835c id=0x04 fn=0xe008f18e MCU_EXT_CMD_RF_TEST
0x02238364 id=0x05 fn=0xe008f1ba MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x0223836c id=0x06 fn=0xe008f1d8 (MTK-internal id)
0x02238374 id=0x07 fn=0xe008ee6c MCU_EXT_CMD_PM_STATE_CTRL
0x0223837c id=0x08 fn=0xe008f164 MCU_EXT_CMD_CHANNEL_SWITCH
0x02238384 id=0x0b fn=0xe008e3e0 (MTK-internal id)
# 9-entry {id,fn} array @ 0x02238534 (r5_t0_a02229800.bin)
0x02238534 id=0x00 fn=0xe0091a16 (MTK-internal id)
0x0223853c id=0x01 fn=0xe0091a8c MCU_EXT_CMD_EFUSE_ACCESS
0x02238544 id=0x02 fn=0xe0091aec MCU_EXT_CMD_DEV_INFO_UPDATE
0x0223854c id=0x03 fn=0xe0091ee8 (MTK-internal id)
0x02238554 id=0x04 fn=0xe009227c MCU_EXT_CMD_RF_TEST
0x0223855c id=0x05 fn=0xe0091ba2 MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x02238564 id=0x00 fn=0xe00918f6 (MTK-internal id)
0x0223856c id=0x01 fn=0xe00929b0 MCU_EXT_CMD_EFUSE_ACCESS
0x02238574 id=0x02 fn=0xe0091c4e MCU_EXT_CMD_DEV_INFO_UPDATE
# 10-entry {id,fn} array @ 0x0223858c (r5_t0_a02229800.bin)
0x0223858c id=0x07 fn=0xe0091cd8 MCU_EXT_CMD_PM_STATE_CTRL
0x02238594 id=0x0a fn=0xe0079520 (MTK-internal id)
0x0223859c id=0x0b fn=0xe0091d64 (MTK-internal id)
0x022385a4 id=0x0c fn=0xe0091d96 (MTK-internal id)
0x022385ac id=0x0d fn=0xe0091de0 (MTK-internal id)
0x022385b4 id=0x0e fn=0xe0092690 (MTK-internal id)
0x022385bc id=0x0f fn=0xe00924a0 (MTK-internal id)
0x022385c4 id=0x10 fn=0xe0092568 (MTK-internal id)
0x022385cc id=0x11 fn=0xe003f5d4 MCU_EXT_CMD_SET_TX_POWER_CTRL
0x022385d4 id=0x1b fn=0xe00925d4 (MTK-internal id)
# 49-entry {id,fn} array @ 0x02238a5c (r5_t0_a02229800.bin)
0x02238a5c id=0x00 fn=0xe00af53c (MTK-internal id)
0x02238a64 id=0x01 fn=0xe00af544 MCU_EXT_CMD_EFUSE_ACCESS
0x02238a6c id=0x02 fn=0xe00af54c MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238a74 id=0x03 fn=0xe00af554 (MTK-internal id)
0x02238a7c id=0x00 fn=0xe00af578 (MTK-internal id)
0x02238a84 id=0x01 fn=0xe00af55c MCU_EXT_CMD_EFUSE_ACCESS
0x02238a8c id=0x02 fn=0xe00af568 MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238a94 id=0x03 fn=0xe00af574 (MTK-internal id)
0x02238a9c id=0x04 fn=0xe00af580 MCU_EXT_CMD_RF_TEST
0x02238aa4 id=0x05 fn=0xe00af58c MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x02238aac id=0x06 fn=0xe00af598 (MTK-internal id)
0x02238ab4 id=0x07 fn=0xe00af5a8 MCU_EXT_CMD_PM_STATE_CTRL
0x02238abc id=0x11 fn=0xe00af5b8 MCU_EXT_CMD_SET_TX_POWER_CTRL
0x02238ac4 id=0x13 fn=0xe00af5c4 MCU_EXT_CMD_FW_LOG_2_HOST
0x02238acc id=0x16 fn=0xe00af5d0 (MTK-internal id)
0x02238ad4 id=0x17 fn=0xe00af5e0 (MTK-internal id)
0x02238adc id=0x00 fn=0xe00af5f0 (MTK-internal id)
0x02238ae4 id=0x01 fn=0xe00af604 MCU_EXT_CMD_EFUSE_ACCESS
0x02238aec id=0x02 fn=0xe00af61c MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238af4 id=0x03 fn=0xe00af630 (MTK-internal id)
0x02238afc id=0x04 fn=0xe00af644 MCU_EXT_CMD_RF_TEST
0x02238b04 id=0x05 fn=0xe00af658 MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x02238b0c id=0x06 fn=0xe00af670 (MTK-internal id)
0x02238b14 id=0x07 fn=0xe00af604 MCU_EXT_CMD_PM_STATE_CTRL
0x02238b1c id=0x08 fn=0xe00af5f0 MCU_EXT_CMD_CHANNEL_SWITCH
0x02238b24 id=0x09 fn=0xe00af670 (MTK-internal id)
0x02238b2c id=0x0a fn=0xe00af604 (MTK-internal id)
0x02238b34 id=0x0b fn=0xe00af604 (MTK-internal id)
0x02238b3c id=0x00 fn=0xe00af684 (MTK-internal id)
0x02238b44 id=0x01 fn=0xe00af690 MCU_EXT_CMD_EFUSE_ACCESS
0x02238b4c id=0x02 fn=0xe00af69c MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238b54 id=0x03 fn=0xe00af6b0 (MTK-internal id)
0x02238b5c id=0x0d fn=0xe00af6b8 (MTK-internal id)
0x02238b64 id=0x0e fn=0xe00af6c0 (MTK-internal id)
0x02238b6c id=0x0f fn=0xe00af6c8 (MTK-internal id)
0x02238b74 id=0x10 fn=0xe00af6d0 (MTK-internal id)
0x02238b7c id=0x00 fn=0xe00af6d4 (MTK-internal id)
0x02238b84 id=0x01 fn=0xe00a68d0 MCU_EXT_CMD_EFUSE_ACCESS
0x02238b8c id=0x02 fn=0xe00af6d0 MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238b94 id=0x03 fn=0xe00af6e4 (MTK-internal id)
0x02238b9c id=0x04 fn=0xe00a6988 MCU_EXT_CMD_RF_TEST
0x02238ba4 id=0x05 fn=0xe00af6e8 MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL
0x02238bac id=0x06 fn=0xe00af6ec (MTK-internal id)
0x02238bb4 id=0x07 fn=0xe00af6fc MCU_EXT_CMD_PM_STATE_CTRL
0x02238bbc id=0x08 fn=0xe00af704 MCU_EXT_CMD_CHANNEL_SWITCH
0x02238bc4 id=0x09 fn=0xe00af714 (MTK-internal id)
0x02238bcc id=0x0a fn=0xe00af71c (MTK-internal id)
0x02238bd4 id=0x0b fn=0xe00af728 (MTK-internal id)
0x02238bdc id=0x0c fn=0xe00af734 (MTK-internal id)
# 33-entry {id,fn} array @ 0x02238e44 (r5_t0_a02229800.bin)
0x02238e44 id=0x00 fn=0xe003e66e (MTK-internal id)
0x02238e4c id=0x01 fn=0xe003e696 MCU_EXT_CMD_EFUSE_ACCESS
0x02238e54 id=0x16 fn=0xe003c370 (MTK-internal id)
0x02238e5c id=0x17 fn=0xe003c370 (MTK-internal id)
0x02238e64 id=0x18 fn=0xe003c370 (MTK-internal id)
0x02238e6c id=0x19 fn=0xe003c370 (MTK-internal id)
0x02238e74 id=0x28 fn=0xe003c63e (MTK-internal id)
0x02238e7c id=0x2b fn=0xe003c63e (MTK-internal id)
0x02238e84 id=0x00 fn=0xe003c3aa (MTK-internal id)
0x02238e8c id=0x29 fn=0xe003c3ac (MTK-internal id)
0x02238e94 id=0x1a fn=0xe003c028 (MTK-internal id)
0x02238e9c id=0x1b fn=0xe003c028 (MTK-internal id)
0x02238ea4 id=0x1c fn=0xe003c028 (MTK-internal id)
0x02238eac id=0x1d fn=0xe003c028 (MTK-internal id)
0x02238eb4 id=0x12 fn=0xe003c34c (MTK-internal id)
0x02238ebc id=0x13 fn=0xe003c34c MCU_EXT_CMD_FW_LOG_2_HOST
0x02238ec4 id=0x14 fn=0xe003c34c (MTK-internal id)
0x02238ecc id=0x15 fn=0xe003c34c (MTK-internal id)
0x02238ed4 id=0x06 fn=0xe003c012 (MTK-internal id)
0x02238edc id=0x07 fn=0xe003c012 MCU_EXT_CMD_PM_STATE_CTRL
0x02238ee4 id=0x08 fn=0xe003c012 MCU_EXT_CMD_CHANNEL_SWITCH
0x02238eec id=0x09 fn=0xe003c012 (MTK-internal id)
0x02238ef4 id=0x0a fn=0xe003c012 (MTK-internal id)
0x02238efc id=0x0b fn=0xe003c012 (MTK-internal id)
0x02238f04 id=0x0c fn=0xe003c012 (MTK-internal id)
0x02238f0c id=0x0d fn=0xe003c012 (MTK-internal id)
0x02238f14 id=0x2e fn=0xe003e624 (MTK-internal id)
0x02238f1c id=0x2f fn=0xe003e624 (MTK-internal id)
0x02238f24 id=0x01 fn=0xe003e586 MCU_EXT_CMD_EFUSE_ACCESS
0x02238f2c id=0x02 fn=0xe003e586 MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238f34 id=0x03 fn=0xe003e586 (MTK-internal id)
0x02238f3c id=0x04 fn=0xe003e586 MCU_EXT_CMD_RF_TEST
0x02238f44 id=0x23 fn=0xe003c38c MCU_EXT_CMD_THERMAL_PROT
# 9-entry {id,fn} array @ 0x02238f74 (r5_t0_a02229800.bin)
0x02238f74 id=0xef fn=0xe0041460 (MTK-internal id)
0x02238f7c id=0xed fn=0xe00412e6 (MTK-internal id)
0x02238f84 id=0x04 fn=0xe0040680 MCU_EXT_CMD_RF_TEST
0x02238f8c id=0x02 fn=0xe0042ebe MCU_EXT_CMD_DEV_INFO_UPDATE
0x02238f94 id=0x8d fn=0xe004276c (MTK-internal id)
0x02238f9c id=0x10 fn=0xe0043330 (MTK-internal id)
0x02238fa4 id=0x4b fn=0xe00433fa (MTK-internal id)
0x02238fac id=0x7d fn=0xe004375c MCU_EXT_CMD_SET_RDD_PATTERN
0x02238fb4 id=0xfc fn=0xe00437a4 (MTK-internal id)
# 13-entry {id,fn} array @ 0x02238ffc (r5_t0_a02229800.bin)
0x02238ffc id=0x06 fn=0xf009b6d6 (MTK-internal id)
0x02239004 id=0x07 fn=0xf009b6d6 MCU_EXT_CMD_PM_STATE_CTRL
0x0223900c id=0x08 fn=0xf009b6d6 MCU_EXT_CMD_CHANNEL_SWITCH
0x02239014 id=0x09 fn=0xf009b6d6 (MTK-internal id)
0x0223901c id=0x0a fn=0xf009b6d6 (MTK-internal id)
0x02239024 id=0x0b fn=0xf009b6d6 (MTK-internal id)
0x0223902c id=0x0c fn=0xf009b6d6 (MTK-internal id)
0x02239034 id=0x0d fn=0xf009b6d6 (MTK-internal id)
0x0223903c id=0x0e fn=0xf009b6d6 (MTK-internal id)
0x02239044 id=0x0f fn=0xf009b6d6 (MTK-internal id)
0x0223904c id=0x10 fn=0xe006946e (MTK-internal id)
0x02239054 id=0x11 fn=0xe003d7b4 MCU_EXT_CMD_SET_TX_POWER_CTRL
0x0223905c id=0x12 fn=0xe00471f6 (MTK-internal id)

View file

@ -0,0 +1,422 @@
# 9-entry {id,fn} array @ 0x02231ba8 (r5_t0_a02229800.bin)
0x02231ba8 id=0x00 fn=0xf009707c
0x02231bb0 id=0x09 fn=0xf00963a6
0x02231bb8 id=0x0a fn=0xf0096430
0x02231bc0 id=0x0e fn=0xf0096846
0x02231bc8 id=0x0d fn=0xe0040280
0x02231bd0 id=0x0f fn=0xf0096b72
0x02231bd8 id=0x01 fn=0xe00795c8
0x02231be0 id=0x03 fn=0xe00799a8
0x02231be8 id=0x04 fn=0xe0067480
# 29-entry {id,fn} array @ 0x02231bf8 (r5_t0_a02229800.bin)
0x02231bf8 id=0x06 fn=0xf00969ca
0x02231c00 id=0x0b fn=0xe004649e
0x02231c08 id=0x0c fn=0xf0096150
0x02231c10 id=0x10 fn=0xf009606e
0x02231c18 id=0x11 fn=0xf00961a4
0x02231c20 id=0x12 fn=0xe0098294
0x02231c28 id=0x14 fn=0xe00660b0
0x02231c30 id=0x24 fn=0xf00961f8
0x02231c38 id=0x18 fn=0xf0096000
0x02231c40 id=0x00 fn=0xe003fae4
0x02231c48 id=0x01 fn=0xe003fbe8
0x02231c50 id=0x02 fn=0xe003fc4c
0x02231c58 id=0x03 fn=0xe003fcb0
0x02231c60 id=0x04 fn=0xe003fd14
0x02231c68 id=0x05 fn=0xe003fd78
0x02231c70 id=0x06 fn=0xe003fda4
0x02231c78 id=0x07 fn=0xe003fdda
0x02231c80 id=0x08 fn=0xe003ff5c
0x02231c88 id=0x09 fn=0xe0040000
0x02231c90 id=0x0a fn=0xe0040056
0x02231c98 id=0x0c fn=0xe003face
0x02231ca0 id=0x0d fn=0xe0040082
0x02231ca8 id=0x0e fn=0xe003fae0
0x02231cb0 id=0x0f fn=0xe00400ae
0x02231cb8 id=0x10 fn=0xe00401b8
0x02231cc0 id=0x11 fn=0xe003fe5e
0x02231cc8 id=0x13 fn=0xe00401e4
0x02231cd0 id=0x12 fn=0xe00401f6
0x02231cd8 id=0x15 fn=0xe0040254
# 38-entry {id,fn} array @ 0x02231ea8 (r5_t0_a02229800.bin)
0x02231ea8 id=0x07 fn=0xe0040914
0x02231eb0 id=0x25 fn=0xf0097174
0x02231eb8 id=0x26 fn=0xe0092848
0x02231ec0 id=0x2a fn=0xe00928c6
0x02231ec8 id=0xbf fn=0xe009277c
0x02231ed0 id=0x13 fn=0xe0042006
0x02231ed8 id=0x27 fn=0xe005e710
0x02231ee0 id=0x28 fn=0xe0060b5e
0x02231ee8 id=0x47 fn=0xe005f636
0x02231ef0 id=0x48 fn=0xe005f796
0x02231ef8 id=0x93 fn=0xe005f5ae
0x02231f00 id=0x32 fn=0xe00402fa
0x02231f08 id=0x49 fn=0xe003ee7e
0x02231f10 id=0xa6 fn=0xe005db74
0x02231f18 id=0xae fn=0xe005f706
0x02231f20 id=0x95 fn=0xe004297c
0x02231f28 id=0x81 fn=0xe005d480
0x02231f30 id=0x57 fn=0xe0042558
0x02231f38 id=0x9c fn=0xe0043588
0x02231f40 id=0x94 fn=0xe0040de4
0x02231f48 id=0x02 fn=0xe007fade
0x02231f50 id=0xb7 fn=0xe0042f70
0x02231f58 id=0xc4 fn=0xe0043248
0x02231f60 id=0x98 fn=0xe0061e48
0x02231f68 id=0x42 fn=0xe005f5ec
0x02231f70 id=0x50 fn=0xe0047c90
0x02231f78 id=0x5a fn=0xe004166c
0x02231f80 id=0x3c fn=0xe00414ec
0x02231f88 id=0x1e fn=0xe00663b2
0x02231f90 id=0x36 fn=0xe0062e16
0x02231f98 id=0x38 fn=0xe00640fe
0x02231fa0 id=0x37 fn=0xe0062b62
0x02231fa8 id=0x4b fn=0xe0062bfe
0x02231fb0 id=0x4a fn=0xe0062eae
0x02231fb8 id=0x67 fn=0xe0064714
0x02231fc0 id=0x68 fn=0xe0063182
0x02231fc8 id=0x6b fn=0xe00645da
0x02231fd0 id=0x01 fn=0xe0090b8a
# 31-entry {id,fn} array @ 0x02231fe0 (r5_t0_a02229800.bin)
0x02231fe0 id=0x04 fn=0xe008a8ae
0x02231fe8 id=0x08 fn=0xe0080680
0x02231ff0 id=0x4e fn=0xe0080680
0x02231ff8 id=0x4f fn=0xe00897a0
0x02232000 id=0x19 fn=0xe00918a0
0x02232008 id=0x1f fn=0xe007d684
0x02232010 id=0x21 fn=0xe00804ac
0x02232018 id=0x9b fn=0xe007ee5e
0x02232020 id=0xbe fn=0xe007ef44
0x02232028 id=0x24 fn=0xe00407aa
0x02232030 id=0x2c fn=0xe008bf86
0x02232038 id=0x30 fn=0xe007a9b2
0x02232040 id=0x79 fn=0xe0080b88
0x02232048 id=0x17 fn=0xe0042d38
0x02232050 id=0x82 fn=0xe0082128
0x02232058 id=0x3d fn=0xe008a938
0x02232060 id=0x3e fn=0xe0081686
0x02232068 id=0x9f fn=0xe0045f3c
0x02232070 id=0x87 fn=0x0221cf98
0x02232078 id=0x3a fn=0xe007ce40
0x02232080 id=0xa3 fn=0xe007cb80
0x02232088 id=0xc5 fn=0xe007cd20
0x02232090 id=0x9d fn=0xe007c0c0
0x02232098 id=0xb2 fn=0xe007c138
0x022320a0 id=0x46 fn=0xe004174a
0x022320a8 id=0x44 fn=0xe0048392
0x022320b0 id=0x43 fn=0xe004197c
0x022320b8 id=0x23 fn=0xe008bca8
0x022320c0 id=0x56 fn=0xe006cf68
0x022320c8 id=0x58 fn=0xe008cf2a
0x022320d0 id=0xa1 fn=0xe00419c6
# 24-entry {id,fn} array @ 0x022320e0 (r5_t0_a02229800.bin)
0x022320e0 id=0xad fn=0xe00779ac
0x022320e8 id=0xb5 fn=0xe0077e68
0x022320f0 id=0x73 fn=0xe0040778
0x022320f8 id=0x9a fn=0xe0080024
0x02232100 id=0xab fn=0xe008a67c
0x02232108 id=0xac fn=0xe008a6ce
0x02232110 id=0xa8 fn=0xe0083ede
0x02232118 id=0xa4 fn=0xe008aadc
0x02232120 id=0xb3 fn=0xe008ae7c
0x02232128 id=0xb6 fn=0xe0078664
0x02232130 id=0xb8 fn=0xe0048010
0x02232138 id=0xb9 fn=0xe007944c
0x02232140 id=0xba fn=0xe00814f0
0x02232148 id=0xc8 fn=0xe00419fc
0x02232150 id=0x7a fn=0xe0041a42
0x02232158 id=0x7b fn=0xe00417d0
0x02232160 id=0x7c fn=0xe0041854
0x02232168 id=0xc6 fn=0xe00418ae
0x02232170 id=0xc7 fn=0xe0041702
0x02232178 id=0xc0 fn=0xe007ebc0
0x02232180 id=0xc2 fn=0xe00482e4
0x02232188 id=0xd5 fn=0xe005dde4
0x02232190 id=0x0f fn=0xe0046e14
0x02232198 id=0x5b fn=0xe0081550
# 43-entry {id,fn} array @ 0x022324ec (r5_t0_a02229800.bin)
0x022324ec id=0x01 fn=0xe0045a7e
0x022324f4 id=0x06 fn=0xe0043b36
0x022324fc id=0x0b fn=0xe0043c6c
0x02232504 id=0x14 fn=0xe00452b6
0x0223250c id=0x15 fn=0xe0043990
0x02232514 id=0x0c fn=0xe0043884
0x0223251c id=0x0d fn=0xe0043ba0
0x02232524 id=0x0e fn=0xe0044aec
0x0223252c id=0x0f fn=0xe0043dc2
0x02232534 id=0x10 fn=0xe0044092
0x0223253c id=0x11 fn=0xe0045950
0x02232544 id=0x12 fn=0xe0044b00
0x0223254c id=0x13 fn=0xe0043c06
0x02232554 id=0x33 fn=0xe0043e1a
0x0223255c id=0x18 fn=0xe00440ac
0x02232564 id=0x19 fn=0xe0043a7a
0x0223256c id=0x1a fn=0xe00441ac
0x02232574 id=0x1b fn=0xe00441c8
0x0223257c id=0x50 fn=0xe00439a0
0x02232584 id=0x51 fn=0xe004552a
0x0223258c id=0x64 fn=0xe004432a
0x02232594 id=0x65 fn=0xe0043e58
0x0223259c id=0x66 fn=0xe0043b1c
0x022325a4 id=0x67 fn=0xe0043cbe
0x022325ac id=0x68 fn=0xe0043ec2
0x022325b4 id=0x69 fn=0xe0043a00
0x022325bc id=0x6a fn=0xe0043a1a
0x022325c4 id=0xc8 fn=0xe0044292
0x022325cc id=0xc9 fn=0xe00442c0
0x022325d4 id=0xca fn=0xe0043a42
0x022325dc id=0xcb fn=0xe0044b10
0x022325e4 id=0xcc fn=0xe0043a64
0x022325ec id=0xcd fn=0xe0043aa6
0x022325f4 id=0xd2 fn=0xe0043f1a
0x022325fc id=0xd3 fn=0xe0043f4a
0x02232604 id=0xd0 fn=0xe0043f8c
0x0223260c id=0xd1 fn=0xe0043fbc
0x02232614 id=0x96 fn=0xe0043abc
0x0223261c id=0x97 fn=0xe00441ee
0x02232624 id=0xd4 fn=0xe0043fec
0x0223262c id=0xfe fn=0xe0044bde
0x02232634 id=0xce fn=0xe0043d32
0x0223263c id=0xcf fn=0xe0043aca
# 8-entry {id,fn} array @ 0x0223670c (r5_t0_a02229800.bin)
0x0223670c id=0x00 fn=0xe0077a2c
0x02236714 id=0x01 fn=0xe0077a5c
0x0223671c id=0x02 fn=0xe007758c
0x02236724 id=0x03 fn=0xe007747c
0x0223672c id=0x04 fn=0xe0077aa2
0x02236734 id=0x05 fn=0xe00776a8
0x0223673c id=0x06 fn=0xe0077478
0x02236744 id=0x07 fn=0xe00776b6
# 92-entry {id,fn} array @ 0x02236bf0 (r5_t0_a02229800.bin)
0x02236bf0 id=0x01 fn=0xe0083c88
0x02236bf8 id=0x02 fn=0xe00844f2
0x02236c00 id=0x03 fn=0xe00838c6
0x02236c08 id=0x04 fn=0xe008453c
0x02236c10 id=0x05 fn=0xe0083aa0
0x02236c18 id=0x06 fn=0xe008461a
0x02236c20 id=0x07 fn=0xe0083d1e
0x02236c28 id=0x08 fn=0xe0084666
0x02236c30 id=0x09 fn=0xe0083d62
0x02236c38 id=0x0a fn=0xe00846b2
0x02236c40 id=0x0b fn=0xe00838dc
0x02236c48 id=0x0c fn=0xe0084586
0x02236c50 id=0x0d fn=0xe00838f2
0x02236c58 id=0x0e fn=0xe00845d0
0x02236c60 id=0x0f fn=0xe0083908
0x02236c68 id=0x10 fn=0xe00846fe
0x02236c70 id=0x11 fn=0xe008391a
0x02236c78 id=0x12 fn=0xe0084748
0x02236c80 id=0x13 fn=0xe008392c
0x02236c88 id=0x14 fn=0xe0084792
0x02236c90 id=0x15 fn=0xe008393e
0x02236c98 id=0x16 fn=0xe00847dc
0x02236ca0 id=0x17 fn=0xe0083950
0x02236ca8 id=0x18 fn=0xe0084826
0x02236cb0 id=0x19 fn=0xe0083962
0x02236cb8 id=0x1a fn=0xe008486e
0x02236cc0 id=0x1b fn=0xe0083974
0x02236cc8 id=0x1c fn=0xe00848b8
0x02236cd0 id=0x1d fn=0xe0083986
0x02236cd8 id=0x1e fn=0xe0084902
0x02236ce0 id=0x1f fn=0xe0083998
0x02236ce8 id=0x20 fn=0xe008494c
0x02236cf0 id=0x21 fn=0xe00839aa
0x02236cf8 id=0x22 fn=0xe0084996
0x02236d00 id=0x23 fn=0xe00839c2
0x02236d08 id=0x24 fn=0xe00849e2
0x02236d10 id=0x25 fn=0xe00839da
0x02236d18 id=0x26 fn=0xe0084a2e
0x02236d20 id=0x27 fn=0xe00839f2
0x02236d28 id=0x28 fn=0xe0084a7a
0x02236d30 id=0x29 fn=0xe0083db0
0x02236d38 id=0x2a fn=0xe0084ac6
0x02236d40 id=0x2b fn=0xe0083d8e
0x02236d48 id=0x2c fn=0xe0084b12
0x02236d50 id=0x2d fn=0xe0083a20
0x02236d58 id=0x2e fn=0xe0084b5e
0x02236d60 id=0x31 fn=0xe0083a38
0x02236d68 id=0x32 fn=0xe0084baa
0x02236d70 id=0x33 fn=0xe0083a50
0x02236d78 id=0x34 fn=0xe0084bf6
0x02236d80 id=0x80 fn=0xe0083ddc
0x02236d88 id=0x81 fn=0xe0084d06
0x02236d90 id=0x82 fn=0xe0083ccc
0x02236d98 id=0x83 fn=0xe0084c42
0x02236da0 id=0x84 fn=0xe0084cae
0x02236da8 id=0x85 fn=0xe008385c
0x02236db0 id=0x86 fn=0xe0083884
0x02236db8 id=0x87 fn=0xe0083b6a
0x02236dc0 id=0x88 fn=0xe0083fc2
0x02236dc8 id=0x89 fn=0xe0083cec
0x02236dd0 id=0x8a fn=0xe0084d5a
0x02236dd8 id=0xc0 fn=0xe0083b10
0x02236de0 id=0xc1 fn=0xe00840cc
0x02236de8 id=0xc2 fn=0xe0083b24
0x02236df0 id=0xc3 fn=0xe0084112
0x02236df8 id=0xc4 fn=0xe0083ba0
0x02236e00 id=0xc5 fn=0xe00841a0
0x02236e08 id=0xc6 fn=0xe0083bb4
0x02236e10 id=0xc7 fn=0xe00841e6
0x02236e18 id=0xc8 fn=0xe0083bc8
0x02236e20 id=0xc9 fn=0xe008422c
0x02236e28 id=0xca fn=0xe0083bdc
0x02236e30 id=0xcb fn=0xe0084272
0x02236e38 id=0xcc fn=0xe0083bf0
0x02236e40 id=0xcd fn=0xe00842b8
0x02236e48 id=0xce fn=0xe0083f4e
0x02236e50 id=0xcf fn=0xe00842fe
0x02236e58 id=0xd0 fn=0xe0083c1a
0x02236e60 id=0xd1 fn=0xe0084394
0x02236e68 id=0xd2 fn=0xe0083c04
0x02236e70 id=0xd3 fn=0xe0083aec
0x02236e78 id=0xd4 fn=0xe0084158
0x02236e80 id=0xd5 fn=0xe0083c2e
0x02236e88 id=0xd6 fn=0xe00843da
0x02236e90 id=0xd7 fn=0xe0083c42
0x02236e98 id=0xd8 fn=0xe0084420
0x02236ea0 id=0xd9 fn=0xe0083c56
0x02236ea8 id=0xda fn=0xe0084466
0x02236eb0 id=0xdb fn=0xe00844ac
0x02236eb8 id=0xdc fn=0xe0083c6a
0x02236ec0 id=0xdd fn=0xe0084346
0x02236ec8 id=0xea fn=0xe0083a6a
# 10-entry {id,fn} array @ 0x0223833c (r5_t0_a02229800.bin)
0x0223833c id=0x00 fn=0xe008f91e
0x02238344 id=0x01 fn=0xe008f068
0x0223834c id=0x02 fn=0xe008f080
0x02238354 id=0x03 fn=0xe008f098
0x0223835c id=0x04 fn=0xe008f18e
0x02238364 id=0x05 fn=0xe008f1ba
0x0223836c id=0x06 fn=0xe008f1d8
0x02238374 id=0x07 fn=0xe008ee6c
0x0223837c id=0x08 fn=0xe008f164
0x02238384 id=0x0b fn=0xe008e3e0
# 9-entry {id,fn} array @ 0x02238534 (r5_t0_a02229800.bin)
0x02238534 id=0x00 fn=0xe0091a16
0x0223853c id=0x01 fn=0xe0091a8c
0x02238544 id=0x02 fn=0xe0091aec
0x0223854c id=0x03 fn=0xe0091ee8
0x02238554 id=0x04 fn=0xe009227c
0x0223855c id=0x05 fn=0xe0091ba2
0x02238564 id=0x00 fn=0xe00918f6
0x0223856c id=0x01 fn=0xe00929b0
0x02238574 id=0x02 fn=0xe0091c4e
# 10-entry {id,fn} array @ 0x0223858c (r5_t0_a02229800.bin)
0x0223858c id=0x07 fn=0xe0091cd8
0x02238594 id=0x0a fn=0xe0079520
0x0223859c id=0x0b fn=0xe0091d64
0x022385a4 id=0x0c fn=0xe0091d96
0x022385ac id=0x0d fn=0xe0091de0
0x022385b4 id=0x0e fn=0xe0092690
0x022385bc id=0x0f fn=0xe00924a0
0x022385c4 id=0x10 fn=0xe0092568
0x022385cc id=0x11 fn=0xe003f5d4
0x022385d4 id=0x1b fn=0xe00925d4
# 49-entry {id,fn} array @ 0x02238a5c (r5_t0_a02229800.bin)
0x02238a5c id=0x00 fn=0xe00af53c
0x02238a64 id=0x01 fn=0xe00af544
0x02238a6c id=0x02 fn=0xe00af54c
0x02238a74 id=0x03 fn=0xe00af554
0x02238a7c id=0x00 fn=0xe00af578
0x02238a84 id=0x01 fn=0xe00af55c
0x02238a8c id=0x02 fn=0xe00af568
0x02238a94 id=0x03 fn=0xe00af574
0x02238a9c id=0x04 fn=0xe00af580
0x02238aa4 id=0x05 fn=0xe00af58c
0x02238aac id=0x06 fn=0xe00af598
0x02238ab4 id=0x07 fn=0xe00af5a8
0x02238abc id=0x11 fn=0xe00af5b8
0x02238ac4 id=0x13 fn=0xe00af5c4
0x02238acc id=0x16 fn=0xe00af5d0
0x02238ad4 id=0x17 fn=0xe00af5e0
0x02238adc id=0x00 fn=0xe00af5f0
0x02238ae4 id=0x01 fn=0xe00af604
0x02238aec id=0x02 fn=0xe00af61c
0x02238af4 id=0x03 fn=0xe00af630
0x02238afc id=0x04 fn=0xe00af644
0x02238b04 id=0x05 fn=0xe00af658
0x02238b0c id=0x06 fn=0xe00af670
0x02238b14 id=0x07 fn=0xe00af604
0x02238b1c id=0x08 fn=0xe00af5f0
0x02238b24 id=0x09 fn=0xe00af670
0x02238b2c id=0x0a fn=0xe00af604
0x02238b34 id=0x0b fn=0xe00af604
0x02238b3c id=0x00 fn=0xe00af684
0x02238b44 id=0x01 fn=0xe00af690
0x02238b4c id=0x02 fn=0xe00af69c
0x02238b54 id=0x03 fn=0xe00af6b0
0x02238b5c id=0x0d fn=0xe00af6b8
0x02238b64 id=0x0e fn=0xe00af6c0
0x02238b6c id=0x0f fn=0xe00af6c8
0x02238b74 id=0x10 fn=0xe00af6d0
0x02238b7c id=0x00 fn=0xe00af6d4
0x02238b84 id=0x01 fn=0xe00a68d0
0x02238b8c id=0x02 fn=0xe00af6d0
0x02238b94 id=0x03 fn=0xe00af6e4
0x02238b9c id=0x04 fn=0xe00a6988
0x02238ba4 id=0x05 fn=0xe00af6e8
0x02238bac id=0x06 fn=0xe00af6ec
0x02238bb4 id=0x07 fn=0xe00af6fc
0x02238bbc id=0x08 fn=0xe00af704
0x02238bc4 id=0x09 fn=0xe00af714
0x02238bcc id=0x0a fn=0xe00af71c
0x02238bd4 id=0x0b fn=0xe00af728
0x02238bdc id=0x0c fn=0xe00af734
# 33-entry {id,fn} array @ 0x02238e44 (r5_t0_a02229800.bin)
0x02238e44 id=0x00 fn=0xe003e66e
0x02238e4c id=0x01 fn=0xe003e696
0x02238e54 id=0x16 fn=0xe003c370
0x02238e5c id=0x17 fn=0xe003c370
0x02238e64 id=0x18 fn=0xe003c370
0x02238e6c id=0x19 fn=0xe003c370
0x02238e74 id=0x28 fn=0xe003c63e
0x02238e7c id=0x2b fn=0xe003c63e
0x02238e84 id=0x00 fn=0xe003c3aa
0x02238e8c id=0x29 fn=0xe003c3ac
0x02238e94 id=0x1a fn=0xe003c028
0x02238e9c id=0x1b fn=0xe003c028
0x02238ea4 id=0x1c fn=0xe003c028
0x02238eac id=0x1d fn=0xe003c028
0x02238eb4 id=0x12 fn=0xe003c34c
0x02238ebc id=0x13 fn=0xe003c34c
0x02238ec4 id=0x14 fn=0xe003c34c
0x02238ecc id=0x15 fn=0xe003c34c
0x02238ed4 id=0x06 fn=0xe003c012
0x02238edc id=0x07 fn=0xe003c012
0x02238ee4 id=0x08 fn=0xe003c012
0x02238eec id=0x09 fn=0xe003c012
0x02238ef4 id=0x0a fn=0xe003c012
0x02238efc id=0x0b fn=0xe003c012
0x02238f04 id=0x0c fn=0xe003c012
0x02238f0c id=0x0d fn=0xe003c012
0x02238f14 id=0x2e fn=0xe003e624
0x02238f1c id=0x2f fn=0xe003e624
0x02238f24 id=0x01 fn=0xe003e586
0x02238f2c id=0x02 fn=0xe003e586
0x02238f34 id=0x03 fn=0xe003e586
0x02238f3c id=0x04 fn=0xe003e586
0x02238f44 id=0x23 fn=0xe003c38c
# 9-entry {id,fn} array @ 0x02238f74 (r5_t0_a02229800.bin)
0x02238f74 id=0xef fn=0xe0041460
0x02238f7c id=0xed fn=0xe00412e6
0x02238f84 id=0x04 fn=0xe0040680
0x02238f8c id=0x02 fn=0xe0042ebe
0x02238f94 id=0x8d fn=0xe004276c
0x02238f9c id=0x10 fn=0xe0043330
0x02238fa4 id=0x4b fn=0xe00433fa
0x02238fac id=0x7d fn=0xe004375c
0x02238fb4 id=0xfc fn=0xe00437a4
# 13-entry {id,fn} array @ 0x02238ffc (r5_t0_a02229800.bin)
0x02238ffc id=0x06 fn=0xf009b6d6
0x02239004 id=0x07 fn=0xf009b6d6
0x0223900c id=0x08 fn=0xf009b6d6
0x02239014 id=0x09 fn=0xf009b6d6
0x0223901c id=0x0a fn=0xf009b6d6
0x02239024 id=0x0b fn=0xf009b6d6
0x0223902c id=0x0c fn=0xf009b6d6
0x02239034 id=0x0d fn=0xf009b6d6
0x0223903c id=0x0e fn=0xf009b6d6
0x02239044 id=0x0f fn=0xf009b6d6
0x0223904c id=0x10 fn=0xe006946e
0x02239054 id=0x11 fn=0xe003d7b4
0x0223905c id=0x12 fn=0xe00471f6

View file

@ -0,0 +1,87 @@
# CSI sensing project stages
Ladder of increasing difficulty for WiFi sensing on hardware we own
(MT3000 router, Android phones, AX211 laptop — no purchases required).
Every rung ends in something visible or verifiable. Deterministic signal
processing throughout; ML appears only as classifiers labeling measured
features — no image synthesis, no "guessed" renderings (project rule).
Context: docs/directions.md (capability directions), docs/findings.md
(firmware facts). Key enabler already established: the stock MT7981
firmware registers CSI command handlers (0xc2/0xc3/0xc4 — F9 data), and
MediaTek authored a driver-side CSI patch (2022, never mainlined).
## Stage 0 — pipeline rehearsal, zero firmware work (tonight)
Laptop + phone only. Data is coarse (RSSI: one strength number per
packet), but the tooling built here is reused by every later stage.
- 0.1 RSSI motion logger: phone streams UDP (iperf), laptop logs signal
strength at high rate into Python.
- 0.2 Dashboard: streaming line plot + waterfall renderer.
Done when: waving at the phone visibly moves the plot; crossing the room
leaves a streak.
## Stage 1 — first real CSI (router powered again)
- 1.1 Router online; pull its exact firmware blobs; diff against
linux-firmware copies (ground truth).
- 1.2 Port MediaTek's 2022 CSI patch to the router's OpenWrt mt76;
rebuild, flash (U-Boot recovery available).
- 1.3 Verify firmware answers: 0xc2 CSI events flowing (RE says the
handlers exist — prove live).
- 1.4 Collector: netlink → Python → live CSI heatmap (the barcode),
phone as talker.
Done when: empty-room barcode sits still; walking through breaks it.
## Stage 2 — clean physics, deterministic DSP
- 2.1 Phase cleaning (conjugate-multiply across packets).
- 2.2 Live Doppler spectrogram (speed-labeled streaks).
- 2.3 Breathing extraction: bandpass 0.1–0.6 Hz; verify breaths/min
against a stopwatch.
- 2.4 Distance slices: tone-axis transform; verify at marked positions
(2 m / 4 m / 6 m) against the ~2 m resolution budget.
- 2.5 Event detectors: entry/exit, travel direction, two-person counting
(thresholds, no guessing).
Done when: views match physical reality checkable with tape measure and
stopwatch.
## Stage 3 — firmware upgrades (the RE project pays off)
- 3.1 Crank measurement rate: dedicated sounding traffic instead of
borrowed network traffic.
- 3.2 CSI on every frame + ambient/monitor capture, not just the
associated client.
- 3.3 Channel hopping across the 5 GHz band: synthesize ~555 MHz →
~10-inch distance slices. Verify at marked positions.
- 3.4 Dual-band simultaneous capture (2.4 + 5 GHz).
Done when: slice resolution measurably improves; the firmware's rate
ceiling is documented and its patch location known.
## Stage 4 — state of the art, deterministic only
- 4.1 Full range-Doppler radar screen (live, both transforms).
- 4.2 Gesture vocabulary: ~6 dynamic hand signs classified from measured
Doppler streak shapes (small classifier on measured features; per-user
training; honest accuracy reporting).
- 4.3 Transmitter voiceprinting: classify devices by RF signature; detect
a MAC-spoofed clone.
- 4.4 Through-wall characterization: detection reliability vs distance
through a known wall.
- 4.5 Optional (later hardware): second capture node → floor-plan
overlay; SAR rail for outline imaging.
Out of scope per project rule: skeleton/pose renderings, point clouds,
any network-invented pixels.
## Gates
- Physical: router must be powered (unblocks Stage 1).
- Long grind: Stage 3 firmware work — same RE as the main project, now
with concrete purpose; benefits from the dispatch/handler maps already
built.

77
docs/directions.md Normal file
View file

@ -0,0 +1,77 @@
# What full firmware access buys: capability directions
Why this project exists, in plain terms. The radio's sound stays WiFi-shaped
(fixed silicon), but everything about how the radio *behaves* — measures,
steers, times, chooses — is firmware, and we're writing the manual for it.
These are the directions that manual unlocks, ordered by what they take
rather than what they politely yield.
## Sense — the router as an instrument
- **Motion through walls.** WiFi passes through drywall; people don't. The
router hears the difference: presence, counting, tracking in rooms it
can't see into.
- **Fine enough to see breathing.** Chest-scale motion measurably shifts the
signal. Firmware-grade measurement = continuous presence at that scale —
sleep monitoring, "is grandma moving today."
- **A camera made of radio.** Several boxes on different sides of a space,
each reading signal fade through it; combined, a live occupancy map. No
lens, no light, works through smoke and dark (radio tomography — nobody
sells it).
- **Perimeter radar.** The AP illuminates; moving reflectors — drones,
vehicles, people — return Doppler fingerprints. Private motion-sensing
perimeter from commodity WiFi.
- **Indoor GPS.** Timing accurate enough to place devices (and reflecting
people) within a room.
## Identify — physics as a lie detector
- **Evil-twin detection that works.** A rogue AP clones name and MAC, but
not its transmitter's RF voiceprint (manufacturing imperfections no
software fakes). Detect forgery by physics, not by trusting packets.
- **Countersurveillance.** Always-on full-spectrum ear: every nearby
transmitter fingerprinted, logged, flagged when a new voice appears.
Bug-sweeping as a background service.
- **Spectrum observatory.** Who transmits, when, how strong, from where,
at what signal quality — the whole radio neighborhood, instrumented.
## Encrypt — physics as an uncopyable key
- **Keys from thin air.** Two radios that talked measured a channel
slightly different from what any third radio sees; that difference is
shared secret material. Two of our devices derive encryption keys from
the fading of the air between them, in real time. The eavesdropper two
meters away reads a different channel and gets different bits
(information-theoretic key agreement — real research field, needs exactly
the low-level channel control we're building).
- **Aim silence at the snooper.** Antenna steering puts full signal on our
client and a deliberate null — a cone of near-silence — exactly where the
eavesdropper sits.
- **Vanishing links.** Per-frame frequency hopping + power control: the
link looks like background noise unless you know the dance. Hard to
intercept, hard to jam.
## Reach — the far end of the menu
- **Farthest link this silicon can legally make.** Slowest mode, full
calibrated power, narrowest channel, dish antennas — multi-km
experimental links on commodity hardware. Same trade LoRa makes (speed
for distance), less of it on offer.
- **Per-device brute optimization.** Stock firmware is conservative for a
million strangers; ours knows its clients and pushes each to its true
physical limit every transmission.
## Hard walls (unchanged)
Waveform is fixed (no arbitrary signals, no chirps); the receiver locks
only on WiFi preambles; power ceilings are regulatory; sensing items are
research-grade — but researchers are starving for exactly the measurement
control this platform can have.
## RE targeting consequence
Sensing, fingerprinting, channel-keys, and null-steering all consume the
same primitive: **rich per-packet channel measurement** (CSI/RX-vector
capture and control). That makes the RX measurement path — how the firmware
collects and reports channel state — the highest-value first reverse
engineering target beyond the dispatch layer already mapped.

View file

@ -70,6 +70,123 @@ Section counts: mt7915 patch = 2 sections, all others = 1; section `type`
constant `0x30002` on every observed section (loader downloads all sections
regardless; field semantics otherwise unobserved).
## F5 — mt7981_rom_patch internal structure (first disassembly, 2026-08-20)
The 9.7KB patch section (downloaded to 0x00900000) is a boot-ROM function
replacement table + code + strings, little-endian NDS32:
| offset | content |
|---|---|
| 0x000 | `0x000003ff`, 0 |
| 0x008 | 10 LE pointers into boot ROM (`0x00801xxx–0x0082bxxx`) |
| 0x108 | 10 LE pointers into patch RAM (`0x009002xx–0x009012xx`) — replacements |
| ~0x1e0 | NDS32 code (Ghidra: 49 functions + entry marker) |
| 0x901000+ | string table |
Decompilation is viable end-to-end (Ghidra 12 `NDS32:LE:32`, official
module; our ELF imports directly — deferred acceptance check now PASSED).
Evidence: `ghidra-proj/patch_decomp.txt` (unpublished, blob-derived).
Verified observations:
- Assert anchors: `patch/wf/wm/sys_patch_mcu.c` (lines 0x426, 0x5de...),
`common/sys_patch_common_mcu.c` (0x20f, 0x248...) via ROM `func_0x008004b8`.
- 20+ distinct direct calls into boot ROM (`func_0x0080xxxx`) + GP-relative
indirect calls (`unaff_gp - 0x116xx`) — ROM provides the runtime library.
- Named-entry strings: `MCU_Patch_init`, `ENTRY_wsysMboxSendMsg`,
`ENTRY_wsysMboxRcvAllMsg` (mailbox IPC), `From_CCIF__host_cpu_sw_interrupt`
(CCIF = host↔MCU channel), `WDT_to_Host` / `WDT_to_N9` (confirms the MCU
core is called N9), `Patch_dic_handler_extend`, `WF_Lt_Sec_handler`.
- Diagnostics suite strings: `AXI_Bus_monitor_detect`, `APB_AHB_bus_timeout`,
`IDLM_monitor`, `CPU_UTLZ_CNT_*` (utilization counters),
`cache_miss_ratio`, register-dump prints (`0x8800_0430` etc.).
- `FUN_009002a6`: bus-register writer — LE dword writes to offsets
0x110/0x114/0x118/0x11c on bus 5, RMW `| 0x400000c0`, busy-poll bit
`0x40000000`. `FUN_0090044e`: bounded delay loop via ROM timer reads
(`func_0x00801e20`/`func_0x00801e16`).
Interpretation (labelled): the patch extends boot ROM with host-comm hooks
(CCIF interrupt, mailboxes, watchdog-to-host) and bus diagnostics, plus
download-plumbing register programming — the glue the ROM needs before
WM/WA firmware arrives.
## F6 — mt7981_wa survey (2026-08-20)
Ghidra project `wa` imported + analyzed: 120 functions, 450 strings.
Strings self-identify WA's role — host command handling and TX bookkeeping
(`MCU_EXT_CMD` protocol), matching the driver's separate WA MCU queue:
- `cmdEventParserCmd` with `ucCID` printing; `EXT_CMD_ID_STAREC_UPDATE`,
`DevInfo Update Command`, `BssInfo Update Command` (own-MAC/BSS record
management), `staRec with invalid wandidx` (station records)
- Per-STA loss accounting: `PKTLOSS[%d]times/cnt[tot_tx,drop_tx,seq]`,
`lost seq`, `dup seq`, `dlycnt/maxdly`, plus `[proto,port,src_ip,dest_ip]`
flow dump formatting
Next: match `MCU_EXT_CMD_*` enum ids (mt76 headers) to `cmdEventParserCmd`
dispatch — the ABI anchor map (P1-C/D).
## F7 — WA EXT_CMD dispatch table located (2026-08-20)
Method: string xrefs fail on this code (GP-relative data addressing;
decompiler shows `unaff_gp + imm`) — dispatch found structurally instead:
`tools/scan_tables.py` scans for consecutive LE pointers into ILM
(0x10200000–0x10233370).
- **65-entry table @ ILM+0x1304 (vaddr 0x10201304)** = `MCU_EXT_CMD`
dispatch, indexed by command id. Two default stubs: 0x10200278
(unhandled) / 0x10200270 (reserved). Verified alignments with mt76 enum:
[0x07] PM_STATE_CTRL→0x10201934, [0x08] CHANNEL_SWITCH→0x10201910,
[0x11] SET_TX_POWER_CTRL→0x1020164c, [0x25] STA_REC_UPDATE→0x10201530,
[0x26] BSS_INFO_UPDATE→0x1020155c, [0x2a] DEV_INFO_UPDATE→0x102015c4,
[0x32] WTBL_UPDATE→0x10201688, [0x49] BCN_OFFLOAD→0x10201674.
- ~30 non-default handlers → immediately nameable; ~15 non-default entries
at ids beyond mt76's public enum (MTK-internal commands — discovery list).
- Additional tables: 36-entry @ILM+0x330 (sparse; likely basic
MCU_CMD/mailbox dispatch), 16-entry @ILM+0x8248.
- Coverage prerequisite: forced linear disassembly (`ForceDisasmPost.py`)
28,540 → 125,621 instructions — default analysis leaves most firmware
code undisassembled (no entry graph reaches it).
Next: same scan on WM; handler-by-handler decompile + naming pass.
## F8 — mt7981_wm survey (2026-08-20)
Ghidra project `wm`: forced disassembly to **555,385 instructions / 4,422
functions** (import-time analysis alone: 226K/4,355).
- ~~Code model claim: "only 27 GP-relative refs"~~ CORRECTED in F9: WM is
GP-relative; the operand-object scan undercounted (missed memory-operand
forms). GP value still unsolved, but the dispatcher's GP-relative
constants identified the registration array structurally.
- Structural scan found no *absolute-pointer* dispatch table — resolved in
F9: dispatch is a runtime registration list, and the static registration
arrays use GP-reachable data in region r5.
- Regions: code 0xe003b000 (398KB) + 0xe009c400 (473KB mixed);
data 0x0231dc00 (205KB), 0x0041xxxx pair; 0xf0xxxxxx block (feat 0x80)
still uncharacterized (U1).
## F9 — WM dispatch solved: runtime registration list (2026-08-20, U4 resolved)
WM's command parser found via string xref (`EXT_CMD_ID:0x%02x, SEQ:%u...`
@0xe00a64b0 → **FUN_0xe00412e6**): walks a handler registration array
`{u8 cmd_id; code* handler}` (stride 8) at `gp+0x1b6a0`, count at
`gp+0x227bc`; match → `handler(msg)`; miss → `Not_handled_ucExtenCID`.
A top-level class array (r5 @0x02238f74) maps class 0xed → this parser.
Region r5 (0x02229800) holds the *static* registration arrays:
**15 arrays / 407 `{id,fn}` entries** (`tools/scan_registrations.py` →
`dataset/wm_registrations.txt`). Enum join names **130 handlers** from
mt76's ABI (`dataset/wm_handlers_named.txt`) — e.g. 0x08
CHANNEL_SWITCH→0xe003ff5c, 0x25 STA_REC_UPDATE, 0x32 WTBL→0xe00402fa,
0x81 SER_TRIGGER→0xe005d480, 0x94 TWT→0xe0040de4, 0x9f
MURU_CTRL→0xe0045f3c; 277 entries carry MTK-internal ids beyond the public
enum (discovery list).
Labels applied (`LabelHandlers.py`): WM **371 functions** (115 created +
256 renamed), WA **29** (from F7's table). r5 additionally carries 192
function-name strings (`wsysWfdmaCmdHandle`, `muruExtCmdSetMuruStatistic`,
...) — `__FUNCTION__`-style assert anchors for the next naming pass.
## Unknowns registry
- **U1 — `feature_set` bit 7 (0x80):** observed only on WM regions at
@ -81,6 +198,9 @@ regardless; field semantics otherwise unobserved).
bytes before/around the string (F2) are uninterpreted.
- **U3 — WO container:** `mt7981_wo.bin` uses the mtk_wed loader
(`mtk_wed_mcu.c`), a different format; not yet parsed.
- **U4 — WM command dispatch mechanism: RESOLVED (F9)** — runtime
registration list at gp+0x1b6a0; static arrays in region r5; parser
0xe00412e6.
## Related verified facts

View file

@ -0,0 +1,46 @@
# mt7981 firmware 2024-08 → 2026-05: handler-level changelog
Method: {id,fn} registration arrays (F9) for WM; dense dispatch table @0x10201304 (F7) for WA. Id-level diff — robust to code relayout (2026 build shifted all code addresses; ~95% of region 0xe003b000 differs byte-wise).
## WM (main firmware)
- Command id surface: **identical** — 169 ids present in both builds, 0 added, 0 removed.
- Registration arrays: 4 of 15 arrays sit at the same address with the same count; array @0x022320e0 grew (24, 25)
- Per-handler code comparison deferred: requires function matching across the relayout (string-anchor matching is the planned method). The byte-diff headline (region 0xe003b000 ~95% changed) is dominated by shift, not rewrite — do not read it as a near-total rewrite.
## WA (offload core)
- Handled ids: 29 → 30, with **migration**: 14 newly handled, 13 dropped.
- Newly handled in 2026:
- `+ 0x00 (internal id)`
- `+ 0x05 ID_RADIO_ON_OFF_CTRL`
- `+ 0x06 (internal id)`
- `+ 0x09 (internal id)`
- `+ 0x0c (internal id)`
- `+ 0x0d (internal id)`
- `+ 0x20 (internal id)`
- `+ 0x21 EFUSE_BUFFER_MODE`
- `+ 0x26 BSS_INFO_UPDATE`
- `+ 0x27 EDCA_UPDATE`
- `+ 0x2f (internal id)`
- `+ 0x30 (internal id)`
- `+ 0x3e PROTECT_CTRL`
- `+ 0x3f (internal id)`
- No longer handled in 2026:
- `- 0x03 (internal id)`
- `- 0x04 RF_TEST`
- `- 0x07 PM_STATE_CTRL`
- `- 0x08 CHANNEL_SWITCH`
- `- 0x0b (internal id)`
- `- 0x18 (internal id)`
- `- 0x19 (internal id)`
- `- 0x22 (internal id)`
- `- 0x23 THERMAL_PROT`
- `- 0x2b (internal id)`
- `- 0x2c THERMAL_CTRL`
- `- 0x31 (internal id)`
- `- 0x32 WTBL_UPDATE`
Semantic read (labelled interpretation): responsibility for several commands moved between cores — e.g. WA dropped CHANNEL_SWITCH / WTBL_UPDATE / THERMAL_* handling while gaining BSS_INFO / EDCA / EFUSE_BUFFER_MODE — consistent with MTK rebalancing WM/WA workloads across builds. Verification (decompile the specific handlers) is follow-up work.
Cross-reference: byte/string-level diffs in `mt7981_wm-20240823-vs-20260515.md`.

View file

@ -0,0 +1,31 @@
# Ghidra headless post-script: dump function/string/block overview.
# Run via PyGhidra launcher (see PLAN.md tooling notes).
#@category Analysis
fm = currentProgram.getFunctionManager()
listing = currentProgram.getListing()
print('=== FUNCTIONS ===')
n = 0
for f in fm.getFunctions(True):
print('%s %s' % (f.getEntryPoint(), f.getName()))
n += 1
print('total functions: %d' % n)
print('=== STRINGS (>=6 chars) ===')
ns = 0
for d in listing.getDefinedData(True):
dt = d.getDataType().getName().lower()
if 'char' in dt or 'unicode' in dt or 'string' in dt:
v = d.getValue()
if v is not None and len(str(v)) >= 6:
print('%s %r' % (d.getAddress(), str(v)[:120]))
ns += 1
print('total strings: %d' % ns)
print('=== MEMORY BLOCKS ===')
for b in currentProgram.getMemory().getBlocks():
print('%s %s %s r%s w%s x%s' % (b.getName(), b.getStart(), b.getSize(),
'1' if b.isRead() else '0',
'1' if b.isWrite() else '0',
'1' if b.isExecute() else '0'))

View file

@ -0,0 +1,28 @@
# Headless post-script: find instructions that write the GP register and
# report candidate GP base values. Once GP is known, set it as register
# context and re-run analysis so GP-relative data references resolve.
# Run via pyghidra ghidra_launch ... -postScript FindGPInit.py
#@category Analysis
listing = currentProgram.getListing()
reg = currentProgram.getLanguage().getRegisters()
gp_regs = [r for r in reg if r.getName().lower() in ('gp', 'r26', 'r11')]
print('GP candidates: %s' % [r.getName() for r in gp_regs])
it = listing.getInstructions(True)
hits = 0
while it.hasNext() and hits < 80:
ins = it.next()
n = ins.getNumOperands()
for i in range(n):
try:
ops = ins.getOpObjects(i)
except Exception: # noqa: BLE001
continue
for o in ops:
if hasattr(o, 'getName') and o in gp_regs:
# operand 0 = destination on NDS32 ALU forms
if i == 0:
print('%s %s' % (ins.getAddress(), ins))
hits += 1
print('total gp-writes shown: %d' % hits)

View file

@ -0,0 +1,39 @@
# Headless post-script: force-disassemble all executable blocks and
# re-run auto-analysis. Run with:
# analyzeHeadless <proj_dir> <proj> -process <prog> -noanalysis \
# -scriptPath tools/ghidra_scripts -postScript ForceDisasmPost.py
#@category Analysis
from ghidra.app.cmd.disassemble import DisassembleCommand
from ghidra.app.plugin.core.analysis import AutoAnalysisManager
from ghidra.program.model.address import AddressSet
listing = currentProgram.getListing()
mem = currentProgram.getMemory()
monitor.setMessage('collecting executable blocks')
total = AddressSet()
for b in mem.getBlocks():
if b.isExecute() and 'elf' not in b.getName():
total.addRange(b.getStart(), b.getEnd())
before_ins = listing.getNumInstructions()
before_fun = currentProgram.getFunctionManager().getFunctionCount()
print('ForceDisasm before: %d instructions, %d functions'
% (before_ins, before_fun))
cmd = DisassembleCommand(total, total, False)
tx = currentProgram.startTransaction('force disasm')
try:
ok = cmd.applyTo(currentProgram, monitor)
finally:
currentProgram.endTransaction(tx, True)
print('ForceDisasm disasm apply: %s' % ok)
mgr = AutoAnalysisManager.getAnalysisManager(currentProgram)
mgr.reAnalyzeAll(None)
mgr.startAnalysis(monitor)
print('ForceDisasm after: %d instructions, %d functions'
% (listing.getNumInstructions(),
currentProgram.getFunctionManager().getFunctionCount()))

View file

@ -0,0 +1,37 @@
# Headless post-script: collect all GP-relative references (addr, imm).
# Dump as CSV lines "GPREF,<insn_addr>,<imm>" for offline base inference.
#@category Analysis
listing = currentProgram.getListing()
lang = currentProgram.getLanguage()
gp = None
for r in lang.getRegisters():
if r.getName().lower() == 'gp':
gp = r
break
print('gp register: %s' % (gp.getName() if gp else None))
from ghidra.program.model.scalar import Scalar # noqa: E402
it = listing.getInstructions(True)
n = 0
while it.hasNext():
ins = it.next()
uses_gp = False
for i in range(ins.getNumOperands()):
for o in ins.getOpObjects(i):
if o == gp:
uses_gp = True
if not uses_gp:
continue
imm = None
for i in range(ins.getNumOperands()):
for o in ins.getOpObjects(i):
if isinstance(o, Scalar):
imm = o.getSignedValue()
break
if imm is not None:
break
print('GPREF,%s,%s' % (ins.getAddress(), imm if imm is not None else ''))
n += 1
print('total gp-refs: %d' % n)

View file

@ -0,0 +1,46 @@
# Headless post-script: label command handlers from a named-handler map.
# Reads files listed in env MTK_HANDLER_MAPS (colon-separated), lines like:
# 0x02231eb0 id=0x25 fn=0xf0097174 MCU_EXT_CMD_STA_REC_UPDATE
# Creates a function at each fn address (if missing) and renames it
# cmdHdlr_<id02x>_<ENUMNAME>.
#@category Analysis
import os
import re
from ghidra.program.model.symbol import SourceType
from ghidra.app.cmd.function import CreateFunctionCmd
from ghidra.app.cmd.label import RenameLabelCmd
maps = os.environ.get('MTK_HANDLER_MAPS', '')
fm = currentProgram.getFunctionManager()
created = renamed = skipped = 0
pat = re.compile(r'id=(0x[0-9a-f]+) fn=(0x[0-9a-f]+) (MCU_[A-Z0-9_]+|\(MTK-internal id\))')
for path in maps.split(':'):
if not path:
continue
print('map file: %s' % path)
for ln in open(path):
m = pat.search(ln)
if not m:
continue
cid, fns, nm = int(m.group(1), 16), m.group(2), m.group(3)
name = 'cmdHdlr_%02x_%s' % (cid, nm.strip('()').replace('-internal id', 'internal'))
addr = currentProgram.getAddressFactory().getAddress(fns)
f = fm.getFunctionAt(addr)
tx = currentProgram.startTransaction('label')
try:
if f is None:
f = createFunction(addr, name)
if f is not None:
created += 1
else:
skipped += 1
print(' ! could not create %s at %s' % (name, fns))
else:
f.setName(name, SourceType.USER_DEFINED)
renamed += 1
print(' %s -> %s' % (fns, name))
finally:
currentProgram.endTransaction(tx, True)
print('label summary: created=%d renamed=%d skipped=%d' % (created, renamed, skipped))

View file

@ -0,0 +1,63 @@
#!/usr/bin/env python3
"""Dump disassembly + decompilation for functions of an imported program.
Plain PyGhidra API (venv with pyghidra). Usage:
GHIDRA_INSTALL_DIR=... venv/bin/python tools/ghidra_scripts/dump_decomp.py \
<elf> <project_dir> <project_name> [entry_only|all|0xADDR ...]
"""
import sys
import pyghidra
pyghidra.start()
from ghidra.app.decompiler import DecompInterface # noqa: E402
from ghidra.util.task import ConsoleTaskMonitor # noqa: E402
elf, proj_dir, proj_name = sys.argv[1], sys.argv[2], sys.argv[3]
mode = sys.argv[4] if len(sys.argv) > 4 else 'entry_only'
with pyghidra.program_context(pyghidra.open_project(
__import__('os').path.abspath(proj_dir), proj_name),
'/' + __import__('os').path.basename(elf)) as prog:
fm = prog.getFunctionManager()
def addr(a):
return prog.getAddressFactory().getAddress(hex(a) if isinstance(a, int) else a)
dec = DecompInterface()
dec.openProgram(prog)
all_funcs = list(fm.getFunctions(True))
by_ep = {int('%x' % f.getEntryPoint().getOffset(), 16): f
for f in all_funcs}
targets = []
if mode == 'entry_only':
targets = all_funcs[:1]
elif mode == 'all':
targets = all_funcs
else:
for s in sys.argv[4:]:
targets.append(by_ep.get(int(s, 16)))
targets = [t for t in targets if t is not None]
# entry listing: first 40 instructions
ent = fm.getFunctions(True).next()
listing = prog.getListing()
it = listing.getInstructions(ent.getEntryPoint(), True)
print('=== ENTRY LISTING %s ===' % ent.getEntryPoint())
for i in range(40):
x = it.next()
if x is None:
break
print('%s %s' % (x.getAddress(), x))
for f in targets:
if f is None:
continue
r = dec.decompileFunction(f, 60, ConsoleTaskMonitor())
print('\n=== %s %s ===' % (f.getEntryPoint(), f.getName()))
if r.decompileCompleted():
print(r.getDecompiledFunction().getC())
else:
print('// decompile failed:', r.getErrorMessage())

View file

@ -0,0 +1,46 @@
#!/usr/bin/env python3
"""Find strings matching a regex and decompile their referencing functions.
Usage: dump-like launcher args: <elf> <proj_dir> <proj_name> <regex> [max_funcs]
"""
import re
import sys
import pyghidra
pyghidra.start()
from ghidra.app.decompiler import DecompInterface # noqa: E402
from ghidra.util.task import ConsoleTaskMonitor # noqa: E402
elf, proj_dir, proj_name, pat = sys.argv[1:5]
maxf = int(sys.argv[5]) if len(sys.argv) > 5 else 3
with pyghidra.program_context(pyghidra.open_project(
__import__('os').path.abspath(proj_dir), proj_name),
'/' + __import__('os').path.basename(elf)) as prog:
listing = prog.getListing()
fm = prog.getFunctionManager()
rm = prog.getReferenceManager()
rx = re.compile(pat)
dec = DecompInterface()
dec.openProgram(prog)
seen = set()
for d in listing.getDefinedData(True):
dt = d.getDataType().getName().lower()
if 'string' not in dt and 'char' not in dt:
continue
v = d.getValue()
if v is None or not rx.search(str(v)):
continue
print('STRING %s %r' % (d.getAddress(), str(v)[:100]))
for ref in rm.getReferencesTo(d.getAddress()):
f = fm.getFunctionContaining(ref.getFromAddress())
if f is None or f.getEntryPoint() in seen:
continue
seen.add(f.getEntryPoint())
print(' <- %s %s' % (f.getEntryPoint(), f.getName()))
if len(seen) <= maxf:
r = dec.decompileFunction(f, 90, ConsoleTaskMonitor())
if r.decompileCompleted():
print(r.getDecompiledFunction().getC()[:6000])

View file

@ -0,0 +1,50 @@
#!/usr/bin/env python3
"""Force-disassemble every executable block, then re-analyze.
Firmware images have no entry graph into most code, so default analysis
leaves large undisassembled regions (no xrefs to their strings).
Usage: <proj_dir> <proj_name> <program_path_in_project>
"""
import os
import sys
import pyghidra
pyghidra.start()
from ghidra.app.cmd.disassemble import DisassembleCommand # noqa: E402
from ghidra.app.plugin.core.analysis import AutoAnalysisManager # noqa: E402
from ghidra.program.model.address import AddressSet # noqa: E402
from ghidra.util.task import ConsoleTaskMonitor # noqa: E402
proj_dir, proj_name, prog_path = sys.argv[1], sys.argv[2], sys.argv[3]
monitor = ConsoleTaskMonitor()
proj = pyghidra.open_project(os.path.abspath(proj_dir), proj_name)
with pyghidra.program_context(proj, prog_path) as prog:
mem = prog.getMemory()
listing = prog.getListing()
total = AddressSet()
for b in mem.getBlocks():
if b.isExecute() and 'elf' not in b.getName():
total.addRange(b.getStart(), b.getEnd())
before_ins = listing.getNumInstructions()
before_fun = prog.getFunctionManager().getFunctionCount()
print('before: %d instructions, %d functions'
% (before_ins, before_fun))
cmd = DisassembleCommand(total, total, False)
with pyghidra.transaction(prog, 'force disasm'):
ok = cmd.applyTo(prog, monitor)
print('disasm apply:', ok)
from ghidra.app.script import GhidraScriptUtil
from ghidra.program.flatapi import FlatProgramAPI
GhidraScriptUtil.acquireBundleHostReference()
try:
FlatProgramAPI(prog).analyzeAll(prog)
finally:
GhidraScriptUtil.releaseBundleHostReference()
print('after: %d instructions, %d functions'
% (listing.getNumInstructions(),
prog.getFunctionManager().getFunctionCount()))
proj.close()

View file

@ -0,0 +1,896 @@
diff --git a/mt76_connac_mcu.h b/mt76_connac_mcu.h
index 8d59cf43..574838f1 100644
--- a/mt76_connac_mcu.h
+++ b/mt76_connac_mcu.h
@@ -1046,6 +1046,7 @@ enum {
MCU_EXT_EVENT_BCC_NOTIFY = 0x75,
MCU_EXT_EVENT_WF_RF_PIN_CTRL = 0x9a,
MCU_EXT_EVENT_MURU_CTRL = 0x9f,
+ MCU_EXT_EVENT_CSI_REPORT = 0xc2,
};
/* unified event table */
@@ -1262,6 +1263,7 @@ enum {
MCU_EXT_CMD_DPD_PRE_CAL_INFO = 0xac,
MCU_EXT_CMD_PHY_STAT_INFO = 0xad,
MCU_EXT_CMD_WF_RF_PIN_CTRL = 0xbd,
+ MCU_EXT_CMD_CSI_CTRL = 0xc2,
};
enum {
diff --git a/mt7915/Makefile b/mt7915/Makefile
index 6b0058ca..ad936178 100644
--- a/mt7915/Makefile
+++ b/mt7915/Makefile
@@ -1,10 +1,10 @@
# SPDX-License-Identifier: BSD-3-Clause-Clear
-EXTRA_CFLAGS += -DCONFIG_MT76_LEDS
+ccflags-y += -DCONFIG_MT76_LEDS -DCONFIG_MTK_VENDOR
obj-$(CONFIG_MT7915E) += mt7915e.o
mt7915e-y := pci.o init.o dma.o eeprom.o main.o mcu.o mac.o \
- debugfs.o mmio.o
+ debugfs.o mmio.o vendor.o
mt7915e-$(CONFIG_NL80211_TESTMODE) += testmode.o
mt7915e-$(CONFIG_MT798X_WMAC) += soc.o
diff --git a/mt7915/init.c b/mt7915/init.c
index 2da6ea91..56e722e1 100644
--- a/mt7915/init.c
+++ b/mt7915/init.c
@@ -719,6 +719,12 @@ mt7915_register_ext_phy(struct mt7915_dev *dev, struct mt7915_phy *phy)
/* init wiphy according to mphy and phy */
mt7915_init_wiphy(phy);
+#ifdef CONFIG_MTK_VENDOR
+ INIT_LIST_HEAD(&phy->csi.csi_list);
+ spin_lock_init(&phy->csi.csi_lock);
+ mt7915_vendor_register(phy);
+#endif
+
ret = mt76_register_phy(mphy, true, mt76_rates,
ARRAY_SIZE(mt76_rates));
if (ret)
@@ -1196,6 +1202,25 @@ void mt7915_set_stream_he_caps(struct mt7915_phy *phy)
}
}
+#ifdef CONFIG_MTK_VENDOR
+static int mt7915_unregister_features(struct mt7915_phy *phy)
+{
+ struct csi_data *c, *tmp_c;
+
+ spin_lock_bh(&phy->csi.csi_lock);
+ phy->csi.enable = 0;
+
+ list_for_each_entry_safe(c, tmp_c, &phy->csi.csi_list, node) {
+ list_del(&c->node);
+ kfree(c);
+ }
+ spin_unlock_bh(&phy->csi.csi_lock);
+
+
+ return 0;
+}
+#endif
+
static void mt7915_unregister_ext_phy(struct mt7915_dev *dev)
{
struct mt7915_phy *phy = mt7915_ext_phy(dev);
@@ -1204,6 +1229,10 @@ static void mt7915_unregister_ext_phy(struct mt7915_dev *dev)
if (!phy)
return;
+#ifdef CONFIG_MTK_VENDOR
+ mt7915_unregister_features(phy);
+#endif
+
mt7915_unregister_thermal(phy);
mt76_unregister_phy(mphy);
ieee80211_free_hw(mphy->hw);
@@ -1216,6 +1245,10 @@ static void mt7915_stop_hardware(struct mt7915_dev *dev)
mt7915_dma_cleanup(dev);
tasklet_disable(&dev->mt76.irq_tasklet);
+#ifdef CONFIG_MTK_VENDOR
+ mt7915_unregister_features(&dev->phy);
+#endif
+
if (is_mt798x(&dev->mt76))
mt7986_wmac_disable(dev);
}
@@ -1254,6 +1287,12 @@ int mt7915_register_device(struct mt7915_dev *dev)
dev->mt76.test_ops = &mt7915_testmode_ops;
#endif
+#ifdef CONFIG_MTK_VENDOR
+ INIT_LIST_HEAD(&dev->phy.csi.csi_list);
+ spin_lock_init(&dev->phy.csi.csi_lock);
+ mt7915_vendor_register(&dev->phy);
+#endif
+
ret = mt76_register_device(&dev->mt76, true, mt76_rates,
ARRAY_SIZE(mt76_rates));
if (ret)
diff --git a/mt7915/mcu.c b/mt7915/mcu.c
index 40364eea..9d00b7be 100644
--- a/mt7915/mcu.c
+++ b/mt7915/mcu.c
@@ -39,6 +39,10 @@ static bool sr_scene_detect = true;
module_param(sr_scene_detect, bool, 0644);
MODULE_PARM_DESC(sr_scene_detect, "Enable firmware scene detection algorithm");
+#ifdef CONFIG_MTK_VENDOR
+static int mt7915_mcu_report_csi(struct mt7915_dev *dev, struct sk_buff *skb);
+#endif
+
static u8
mt7915_mcu_get_sta_nss(u16 mcs_map)
{
@@ -421,6 +425,11 @@ mt7915_mcu_rx_ext_event(struct mt7915_dev *dev, struct sk_buff *skb)
case MCU_EXT_EVENT_FW_LOG_2_HOST:
mt7915_mcu_rx_log_message(dev, skb);
break;
+#ifdef CONFIG_MTK_VENDOR
+ case MCU_EXT_EVENT_CSI_REPORT:
+ mt7915_mcu_report_csi(dev, skb);
+ break;
+#endif
case MCU_EXT_EVENT_BCC_NOTIFY:
mt7915_mcu_rx_bcc_notify(dev, skb);
break;
@@ -4139,3 +4148,106 @@ int mt7915_mcu_rf_regval(struct mt7915_dev *dev, u32 regidx, u32 *val, bool set)
return 0;
}
+
+#ifdef CONFIG_MTK_VENDOR
+int mt7915_mcu_set_csi(struct mt7915_phy *phy, u8 mode,
+ u8 cfg, u8 v1, u32 v2, u8 *mac_addr)
+{
+ struct mt7915_dev *dev = phy->dev;
+ struct mt7915_mcu_csi req = {
+ .band = phy != &dev->phy,
+ .mode = mode,
+ .cfg = cfg,
+ .v1 = v1,
+ .v2 = cpu_to_le32(v2),
+ };
+
+ if (is_valid_ether_addr(mac_addr))
+ ether_addr_copy(req.mac_addr, mac_addr);
+
+ return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD(CSI_CTRL), &req,
+ sizeof(req), false);
+}
+
+static int
+mt7915_mcu_report_csi(struct mt7915_dev *dev, struct sk_buff *skb)
+{
+ struct mt76_connac2_mcu_rxd *rxd = (struct mt76_connac2_mcu_rxd *)skb->data;
+ struct mt7915_phy *phy = &dev->phy;
+ struct mt7915_mcu_csi_report *cr;
+ struct csi_data *csi;
+ int len, i;
+
+ skb_pull(skb, sizeof(struct mt76_connac2_mcu_rxd));
+
+ len = le16_to_cpu(rxd->len) - sizeof(struct mt76_connac2_mcu_rxd) + 24;
+ if (len < sizeof(*cr))
+ return -EINVAL;
+
+ cr = (struct mt7915_mcu_csi_report *)skb->data;
+
+ if (phy->csi.interval &&
+ le32_to_cpu(cr->ts) < phy->csi.last_record + phy->csi.interval)
+ return 0;
+
+ csi = kzalloc(sizeof(*csi), GFP_KERNEL);
+ if (!csi)
+ return -ENOMEM;
+
+#define SET_CSI_DATA(_field) csi->_field = le32_to_cpu(cr->_field)
+ SET_CSI_DATA(ch_bw);
+ SET_CSI_DATA(rssi);
+ SET_CSI_DATA(snr);
+ SET_CSI_DATA(data_num);
+ SET_CSI_DATA(data_bw);
+ SET_CSI_DATA(pri_ch_idx);
+ SET_CSI_DATA(info);
+ SET_CSI_DATA(rx_mode);
+ SET_CSI_DATA(h_idx);
+ SET_CSI_DATA(ts);
+
+ SET_CSI_DATA(band);
+ if (csi->band && !phy->mt76->band_idx)
+ phy = mt7915_ext_phy(dev);
+#undef SET_CSI_DATA
+
+ for (i = 0; i < csi->data_num; i++) {
+ csi->data_i[i] = le16_to_cpu(cr->data_i[i]);
+ csi->data_q[i] = le16_to_cpu(cr->data_q[i]);
+ }
+
+ memcpy(csi->ta, cr->ta, ETH_ALEN);
+ csi->tx_idx = le32_get_bits(cr->trx_idx, GENMASK(31, 16));
+ csi->rx_idx = le32_get_bits(cr->trx_idx, GENMASK(15, 0));
+
+ INIT_LIST_HEAD(&csi->node);
+ spin_lock_bh(&phy->csi.csi_lock);
+
+ if (!phy->csi.enable) {
+ kfree(csi);
+ spin_unlock_bh(&phy->csi.csi_lock);
+ return 0;
+ }
+
+ list_add_tail(&csi->node, &phy->csi.csi_list);
+ phy->csi.count++;
+
+ if (phy->csi.count > CSI_MAX_BUF_NUM) {
+ struct csi_data *old;
+
+ old = list_first_entry(&phy->csi.csi_list,
+ struct csi_data, node);
+
+ list_del(&old->node);
+ kfree(old);
+ phy->csi.count--;
+ }
+
+ if (csi->h_idx & BIT(15)) /* last chain */
+ phy->csi.last_record = csi->ts;
+ spin_unlock_bh(&phy->csi.csi_lock);
+
+ return 0;
+}
+#endif
+
diff --git a/mt7915/mcu.h b/mt7915/mcu.h
index 3be105bc..c3c906fc 100644
--- a/mt7915/mcu.h
+++ b/mt7915/mcu.h
@@ -522,4 +522,82 @@ enum {
sizeof(struct bss_info_bmc_rate) +\
sizeof(struct bss_info_ext_bss))
+
+#ifdef CONFIG_MTK_VENDOR
+struct mt7915_mcu_csi {
+ u8 band;
+ u8 mode;
+ u8 cfg;
+ u8 v1;
+ __le32 v2;
+ u8 mac_addr[ETH_ALEN];
+ u8 _rsv[34];
+} __packed;
+
+struct csi_tlv {
+ __le32 tag;
+ __le32 len;
+} __packed;
+
+#define CSI_MAX_COUNT 256
+#define CSI_MAX_BUF_NUM 3000
+
+struct mt7915_mcu_csi_report {
+ struct csi_tlv _t0;
+ __le32 ver;
+ struct csi_tlv _t1;
+ __le32 ch_bw;
+ struct csi_tlv _t2;
+ __le32 rssi;
+ struct csi_tlv _t3;
+ __le32 snr;
+ struct csi_tlv _t4;
+ __le32 band;
+ struct csi_tlv _t5;
+ __le32 data_num;
+ struct csi_tlv _t6;
+ __le16 data_i[CSI_MAX_COUNT];
+ struct csi_tlv _t7;
+ __le16 data_q[CSI_MAX_COUNT];
+ struct csi_tlv _t8;
+ __le32 data_bw;
+ struct csi_tlv _t9;
+ __le32 pri_ch_idx;
+ struct csi_tlv _t10;
+ u8 ta[8];
+ struct csi_tlv _t11;
+ __le32 info;
+ struct csi_tlv _t12;
+ __le32 rx_mode;
+ struct csi_tlv _t17;
+ __le32 h_idx;
+ struct csi_tlv _t18;
+ __le32 trx_idx;
+ struct csi_tlv _t19;
+ __le32 ts;
+} __packed;
+
+struct csi_data {
+ u8 ch_bw;
+ u16 data_num;
+ s16 data_i[CSI_MAX_COUNT];
+ s16 data_q[CSI_MAX_COUNT];
+ u8 band;
+ s8 rssi;
+ u8 snr;
+ u32 ts;
+ u8 data_bw;
+ u8 pri_ch_idx;
+ u8 ta[ETH_ALEN];
+ u32 info;
+ u8 rx_mode;
+ u32 h_idx;
+ u16 tx_idx;
+ u16 rx_idx;
+
+ struct list_head node;
+};
+#endif
+
+
#endif
diff --git a/mt7915/mt7915.h b/mt7915/mt7915.h
index 7d98a42d..071600c2 100644
--- a/mt7915/mt7915.h
+++ b/mt7915/mt7915.h
@@ -240,6 +240,20 @@ struct mt7915_phy {
u8 spe_idx;
} test;
#endif
+
+#ifdef CONFIG_MTK_VENDOR
+ struct {
+ struct list_head csi_list;
+ spinlock_t csi_lock;
+ u32 count;
+ bool mask;
+ bool reorder;
+ bool enable;
+
+ u32 interval;
+ u32 last_record;
+ } csi;
+#endif
};
struct mt7915_dev {
@@ -628,4 +642,10 @@ void mt7915_sta_add_debugfs(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
int mt7915_mmio_wed_init(struct mt7915_dev *dev, void *pdev_ptr,
bool pci, int *irq);
+#ifdef CONFIG_MTK_VENDOR
+void mt7915_vendor_register(struct mt7915_phy *phy);
+int mt7915_mcu_set_csi(struct mt7915_phy *phy, u8 mode,
+ u8 cfg, u8 v1, u32 v2, u8 *mac_addr);
+#endif
+
#endif
diff --git a/mt7915/vendor.c b/mt7915/vendor.c
new file mode 100644
index 00000000..98fd9c2d
--- /dev/null
+++ b/mt7915/vendor.c
@@ -0,0 +1,452 @@
+// SPDX-License-Identifier: ISC
+/*
+ * Copyright (C) 2020, MediaTek Inc. All rights reserved.
+ */
+
+#include <net/netlink.h>
+
+#include "mt7915.h"
+#include "mcu.h"
+#include "vendor.h"
+
+static const struct nla_policy
+csi_ctrl_policy[NUM_MTK_VENDOR_ATTRS_CSI_CTRL] = {
+ [MTK_VENDOR_ATTR_CSI_CTRL_CFG] = {.type = NLA_NESTED },
+ [MTK_VENDOR_ATTR_CSI_CTRL_CFG_MODE] = { .type = NLA_U8 },
+ [MTK_VENDOR_ATTR_CSI_CTRL_CFG_TYPE] = { .type = NLA_U8 },
+ [MTK_VENDOR_ATTR_CSI_CTRL_CFG_VAL1] = { .type = NLA_U8 },
+ [MTK_VENDOR_ATTR_CSI_CTRL_CFG_VAL2] = { .type = NLA_U8 },
+ [MTK_VENDOR_ATTR_CSI_CTRL_MAC_ADDR] = { .type = NLA_NESTED },
+ [MTK_VENDOR_ATTR_CSI_CTRL_INTERVAL] = { .type = NLA_U32 },
+ [MTK_VENDOR_ATTR_CSI_CTRL_DUMP_NUM] = { .type = NLA_U16 },
+ [MTK_VENDOR_ATTR_CSI_CTRL_DATA] = { .type = NLA_NESTED },
+};
+
+struct csi_null_tone {
+ u8 start;
+ u8 end;
+};
+
+struct csi_reorder{
+ u8 dest;
+ u8 start;
+ u8 end;
+};
+
+struct csi_mask {
+ struct csi_null_tone null[10];
+ u8 pilot[8];
+ struct csi_reorder ro[3];
+};
+
+static const struct csi_mask csi_mask_groups[] = {
+ /* OFDM */
+ { .null = { { 0 }, { 27, 37 } },
+ .ro = { {0, 0, 63} },
+ },
+ { .null = { { 0, 69 }, { 96 }, { 123, 127 } },
+ .ro = { { 0, 96 }, { 38, 70, 95 }, { 1, 97, 122 } },
+ },
+ { .null = { { 0, 5 }, { 32 }, { 59, 127 } },
+ .ro = { { 0, 32 }, { 38, 6, 31 }, { 1, 33, 58 } },
+ },
+ { .null = { { 0, 5 }, { 32 }, { 59, 69 }, { 96 }, { 123, 127 } },
+ .ro = { { 0, 0, 127 } },
+ },
+ { .null = { { 0, 133 }, { 160 }, { 187, 255 } },
+ .ro = { { 0, 160 }, { 1, 161, 186 }, { 38, 134, 159 } },
+ },
+ { .null = { { 0, 197 }, { 224 }, { 251, 255 } },
+ .ro = { { 0, 224 }, { 1, 225, 250 }, { 38, 198, 223 } },
+ },
+ { .null = { { 0, 5 }, { 32 }, { 59, 255 } },
+ .ro = { { 0, 32 }, { 1, 33, 58 }, { 38, 6, 31 } },
+ },
+ { .null = { { 0, 69 }, { 96 }, { 123, 255 } },
+ .ro = { { 0, 96 }, { 1, 97, 122 }, { 38, 70, 95 } },
+ },
+ { .null = { { 0, 133 }, { 160 }, { 187, 197 }, { 224 }, { 251, 255 } },
+ .ro = { { 0, 192 }, { 2, 198, 250 }, { 74, 134, 186 } },
+ },
+ { .null = { { 0, 5 }, { 32 }, { 59, 69 }, { 96 }, { 123, 255 } },
+ .ro = { { 0, 64 }, { 2, 70, 122 }, { 74, 6, 58 } },
+ },
+ { .null = { { 0, 5 }, { 32 }, { 59, 69 }, { 96 }, { 123, 133 },
+ { 160 }, { 187, 197 }, { 224 }, { 251, 255 } },
+ .ro = { { 0, 0, 255 } },
+ },
+
+ /* HT/VHT */
+ { .null = { { 0 }, { 29, 35 } },
+ .pilot = { 7, 21, 43, 57 },
+ .ro = { { 0, 0, 63 } },
+ },
+ { .null = { { 0, 67 }, { 96 }, { 125, 127 } },
+ .pilot = { 75, 89, 103, 117 },
+ .ro = { { 0, 96 }, { 36, 68, 95 }, { 1, 97, 124 } },
+ },
+ { .null = { { 0, 3 }, { 32 }, { 61, 127 } },
+ .pilot = { 11, 25, 39, 53 },
+ .ro = { { 0, 32 }, { 36, 4, 31 }, { 1, 33, 60 } },
+ },
+ { .null = { { 0, 1 }, { 59, 69 }, { 127 } },
+ .pilot = { 11, 25, 53, 75, 103, 117 },
+ .ro = { { 0, 0, 127 } },
+ },
+ { .null = { { 0, 131 }, { 160 }, { 189, 255 } },
+ .pilot = { 139, 153, 167, 181 },
+ .ro = { { 0, 160 }, { 1, 161, 188 }, { 36, 132, 159 } },
+ },
+ { .null = { { 0, 195 }, { 224 }, { 253 }, { 255 } },
+ .pilot = { 203, 217, 231, 245 },
+ .ro = { { 0, 224 }, { 1, 225, 252 }, { 36, 196, 223 } },
+ },
+ { .null = { { 0, 3 }, { 32 }, { 61, 255 } },
+ .pilot = { 11, 25, 39, 53 },
+ .ro = { { 0, 32 }, { 1, 33, 60 }, { 36, 4, 31 } },
+ },
+ { .null = { { 0, 67 }, { 96 }, { 125, 255 } },
+ .pilot = { 75, 89, 103, 117 },
+ .ro = { { 0, 96 }, { 1, 97, 124 }, { 36, 68, 95 } },
+ },
+ { .null = { { 0, 133 }, { 191, 193 }, { 251, 255 } },
+ .pilot = { 139, 167, 181, 203, 217, 245 },
+ .ro = { { 0, 192 }, { 2, 194, 250 }, { 70, 134, 190 } },
+ },
+ { .null = { { 0, 5 }, { 63, 65 }, { 123, 127 } },
+ .pilot = { 11, 39, 53, 75, 89, 117 },
+ .ro = { { 0, 64 }, { 2, 66, 122 }, { 70, 6, 62 } },
+ },
+ { .null = { { 0, 1 }, { 123, 133 }, { 255 } },
+ .pilot = { 11, 39, 75, 103, 153, 181, 217, 245 },
+ .ro = { { 0, 0, 255 } },
+ },
+
+ /* HE */
+ { .null = { { 0 }, { 31, 33 } },
+ .pilot = { 12, 29, 35, 52 },
+ .ro = { { 0, 0, 63 } },
+ },
+ { .null = { { 30, 34 }, { 96 } },
+ .pilot = { 4, 21, 43, 60, 70, 87, 105, 122 },
+ .ro = { { 0, 96 }, { 34, 66, 95 }, { 1, 97, 126 } },
+ },
+ { .null = { { 32 }, { 94, 98 } },
+ .pilot = { 6, 23, 41, 58, 68, 85, 107, 124 },
+ .ro = { { 0, 32 }, { 34, 2, 31 }, { 1, 31, 62 } },
+ },
+ { .null = { { 0 }, { 62, 66 } },
+ .pilot = { 9, 26, 36, 53, 75, 92, 102, 119 },
+ .ro = { { 0, 0, 127 } },
+ },
+ { .null = { { 30, 34 }, { 160 } },
+ .pilot = { 4, 21, 43, 60, 137, 154, 166, 183 },
+ .ro = { { 0, 160 }, { 1, 161, 190 }, { 34, 130, 159 } },
+ },
+ { .null = { { 94, 98 }, { 224 } },
+ .pilot = { 68, 85, 107, 124, 201, 218, 230, 247 },
+ .ro = { { 0, 224 }, { 1, 225, 254 }, { 34, 194, 223 } },
+ },
+ { .null = { { 32 }, { 158, 162 } },
+ .pilot = { 9, 26, 38, 55, 132, 149, 171, 188 },
+ .ro = { { 0, 32 }, { 1, 33, 62 }, { 34, 2, 31 } },
+ },
+ { .null = { { 96 }, { 222, 226 } },
+ .pilot = { 73, 90, 102, 119, 196, 213, 235, 252 },
+ .ro = { { 0, 96 }, { 1, 97, 126 }, { 34, 66, 95 } },
+ },
+ { .null = { { 62, 66 }, { 192 } },
+ .pilot = { 36, 53, 75, 92, 169, 186, 198, 215 },
+ .ro = { { 0, 192 }, { 1, 193, 253 }, { 67, 131, 191 } },
+ },
+ { .null = { { 64 }, { 190, 194 } },
+ .pilot = { 41, 58, 70, 87, 164, 181, 203, 220 },
+ .ro = { { 0, 64 }, { 1, 65, 125 }, { 67, 3, 63 } },
+ },
+ { .null = { { 0 }, { 126, 130 } },
+ .pilot = { 6, 23, 100, 117, 139, 156, 233, 250 },
+ .ro = { { 0, 0, 255 } },
+ },
+};
+
+static inline u8 csi_group_idx(u8 mode, u8 ch_bw, u8 data_bw, u8 pri_ch_idx)
+{
+ if (ch_bw < 2 || data_bw < 1)
+ return mode * 11 + ch_bw * ch_bw + pri_ch_idx;
+ else
+ return mode * 11 + ch_bw * ch_bw + (data_bw + 1) * 2 + pri_ch_idx;
+}
+
+static int mt7915_vendor_csi_ctrl(struct wiphy *wiphy,
+ struct wireless_dev *wdev,
+ const void *data,
+ int data_len)
+{
+ struct ieee80211_hw *hw = wiphy_to_ieee80211_hw(wiphy);
+ struct mt7915_phy *phy = mt7915_hw_phy(hw);
+ struct nlattr *tb[NUM_MTK_VENDOR_ATTRS_CSI_CTRL];
+ int err;
+
+ err = nla_parse(tb, MTK_VENDOR_ATTR_CSI_CTRL_MAX, data, data_len,
+ csi_ctrl_policy, NULL);
+ if (err)
+ return err;
+
+ if (tb[MTK_VENDOR_ATTR_CSI_CTRL_CFG]) {
+ u8 mode = 0, type = 0, v1 = 0, v2 = 0;
+ u8 mac_addr[ETH_ALEN] = {};
+ struct nlattr *cur;
+ int rem;
+
+ nla_for_each_nested(cur, tb[MTK_VENDOR_ATTR_CSI_CTRL_CFG], rem) {
+ switch(nla_type(cur)) {
+ case MTK_VENDOR_ATTR_CSI_CTRL_CFG_MODE:
+ mode = nla_get_u8(cur);
+ break;
+ case MTK_VENDOR_ATTR_CSI_CTRL_CFG_TYPE:
+ type = nla_get_u8(cur);
+ break;
+ case MTK_VENDOR_ATTR_CSI_CTRL_CFG_VAL1:
+ v1 = nla_get_u8(cur);
+ break;
+ case MTK_VENDOR_ATTR_CSI_CTRL_CFG_VAL2:
+ v2 = nla_get_u8(cur);
+ break;
+ default:
+ return -EINVAL;
+ };
+ }
+
+ if (tb[MTK_VENDOR_ATTR_CSI_CTRL_MAC_ADDR]) {
+ int idx = 0;
+
+ nla_for_each_nested(cur, tb[MTK_VENDOR_ATTR_CSI_CTRL_MAC_ADDR], rem) {
+ mac_addr[idx++] = nla_get_u8(cur);
+ }
+ }
+
+ mt7915_mcu_set_csi(phy, mode, type, v1, v2, mac_addr);
+
+ spin_lock_bh(&phy->csi.csi_lock);
+
+ phy->csi.enable = !!mode;
+
+ if (mode == 2 && type == 5) {
+ if (v1 >= 1)
+ phy->csi.mask = 1;
+ if (v1 == 2)
+ phy->csi.reorder = 1;
+ }
+
+ /* clean up old csi stats */
+ if ((mode == 0 || mode == 2) && !list_empty(&phy->csi.csi_list)) {
+ struct csi_data *c, *tmp_c;
+
+ list_for_each_entry_safe(c, tmp_c, &phy->csi.csi_list,
+ node) {
+ list_del(&c->node);
+ kfree(c);
+ phy->csi.count--;
+ }
+ } else if (mode == 1) {
+ phy->csi.last_record = 0;
+ }
+
+ spin_unlock_bh(&phy->csi.csi_lock);
+ }
+
+ if (tb[MTK_VENDOR_ATTR_CSI_CTRL_INTERVAL])
+ phy->csi.interval = nla_get_u32(tb[MTK_VENDOR_ATTR_CSI_CTRL_INTERVAL]);
+
+ return 0;
+}
+
+static void
+mt7915_vendor_csi_tone_mask(struct mt7915_phy *phy, struct csi_data *csi)
+{
+ static const u8 mode_map[] = {
+ [MT_PHY_TYPE_OFDM] = 0,
+ [MT_PHY_TYPE_HT] = 1,
+ [MT_PHY_TYPE_VHT] = 1,
+ [MT_PHY_TYPE_HE_SU] = 2,
+ };
+ const struct csi_mask *cmask;
+ int i;
+
+ if (csi->rx_mode == MT_PHY_TYPE_CCK || !phy->csi.mask)
+ return;
+
+ if (csi->data_bw == IEEE80211_STA_RX_BW_40)
+ csi->pri_ch_idx /= 2;
+
+ cmask = &csi_mask_groups[csi_group_idx(mode_map[csi->rx_mode],
+ csi->ch_bw,
+ csi->data_bw,
+ csi->pri_ch_idx)];
+
+ for (i = 0; i < 10; i++) {
+ const struct csi_null_tone *ntone = &cmask->null[i];
+ u8 start = ntone->start;
+ u8 end = ntone->end;
+ int j;
+
+ if (!start && !end && i > 0)
+ break;
+
+ if (!end)
+ end = start;
+
+ for (j = start; j <= end; j++) {
+ csi->data_i[j] = 0;
+ csi->data_q[j] = 0;
+ }
+ }
+
+ for (i = 0; i < 8; i++) {
+ u8 pilot = cmask->pilot[i];
+
+ if (!pilot)
+ break;
+
+ csi->data_i[pilot] = 0;
+ csi->data_q[pilot] = 0;
+ }
+
+ if (!phy->csi.reorder)
+ return;
+
+ for (i = 0; i < 3; i++) {
+ const struct csi_reorder *ro = &cmask->ro[i];
+ u8 dest = ro->dest;
+ u8 start = ro->start;
+ u8 end = ro->end;
+
+ if (!dest && !start && !end)
+ break;
+
+ if (dest == start)
+ continue;
+
+ if (end) {
+ memmove(&csi->data_i[dest], &csi->data_i[start],
+ end - start + 1);
+ memmove(&csi->data_q[dest], &csi->data_q[start],
+ end - start + 1);
+ } else {
+ csi->data_i[dest] = csi->data_i[start];
+ csi->data_q[dest] = csi->data_q[start];
+ }
+ }
+}
+
+static int
+mt7915_vendor_csi_ctrl_dump(struct wiphy *wiphy, struct wireless_dev *wdev,
+ struct sk_buff *skb, const void *data, int data_len,
+ unsigned long *storage)
+{
+#define RESERVED_SET BIT(31)
+ struct ieee80211_hw *hw = wiphy_to_ieee80211_hw(wiphy);
+ struct mt7915_phy *phy = mt7915_hw_phy(hw);
+ struct nlattr *tb[NUM_MTK_VENDOR_ATTRS_CSI_CTRL];
+ int err = 0;
+
+ if (*storage & RESERVED_SET) {
+ if ((*storage & GENMASK(15, 0)) == 0)
+ return -ENOENT;
+ (*storage)--;
+ }
+
+ if (data) {
+ err = nla_parse(tb, MTK_VENDOR_ATTR_CSI_CTRL_MAX, data, data_len,
+ csi_ctrl_policy, NULL);
+ if (err)
+ return err;
+ }
+
+ if (!(*storage & RESERVED_SET) && tb[MTK_VENDOR_ATTR_CSI_CTRL_DUMP_NUM]) {
+ *storage = nla_get_u16(tb[MTK_VENDOR_ATTR_CSI_CTRL_DUMP_NUM]);
+ *storage |= RESERVED_SET;
+ }
+
+ spin_lock_bh(&phy->csi.csi_lock);
+
+ if (!list_empty(&phy->csi.csi_list)) {
+ struct csi_data *csi;
+ void *a, *b;
+ int i;
+
+ csi = list_first_entry(&phy->csi.csi_list, struct csi_data, node);
+
+ mt7915_vendor_csi_tone_mask(phy, csi);
+
+ a = nla_nest_start(skb, MTK_VENDOR_ATTR_CSI_CTRL_DATA);
+
+ if (nla_put_u8(skb, MTK_VENDOR_ATTR_CSI_DATA_VER, 1) ||
+ nla_put_u8(skb, MTK_VENDOR_ATTR_CSI_DATA_RSSI, csi->rssi) ||
+ nla_put_u8(skb, MTK_VENDOR_ATTR_CSI_DATA_SNR, csi->snr) ||
+ nla_put_u8(skb, MTK_VENDOR_ATTR_CSI_DATA_BW, csi->data_bw) ||
+ nla_put_u8(skb, MTK_VENDOR_ATTR_CSI_DATA_CH_IDX, csi->pri_ch_idx) ||
+ nla_put_u8(skb, MTK_VENDOR_ATTR_CSI_DATA_MODE, csi->rx_mode))
+ goto out;
+
+ if (nla_put_u16(skb, MTK_VENDOR_ATTR_CSI_DATA_TX_ANT, csi->tx_idx) ||
+ nla_put_u16(skb, MTK_VENDOR_ATTR_CSI_DATA_RX_ANT, csi->rx_idx))
+ goto out;
+
+ if (nla_put_u32(skb, MTK_VENDOR_ATTR_CSI_DATA_INFO, csi->info) ||
+ nla_put_u32(skb, MTK_VENDOR_ATTR_CSI_DATA_H_IDX, csi->h_idx) ||
+ nla_put_u32(skb, MTK_VENDOR_ATTR_CSI_DATA_TS, csi->ts))
+ goto out;
+
+ b = nla_nest_start(skb, MTK_VENDOR_ATTR_CSI_DATA_TA);
+ for (i = 0; i < ARRAY_SIZE(csi->ta); i++)
+ if (nla_put_u8(skb, i, csi->ta[i]))
+ goto out;
+ nla_nest_end(skb, b);
+
+ b = nla_nest_start(skb, MTK_VENDOR_ATTR_CSI_DATA_I);
+ for (i = 0; i < ARRAY_SIZE(csi->data_i); i++)
+ if (nla_put_u16(skb, i, csi->data_i[i]))
+ goto out;
+ nla_nest_end(skb, b);
+
+ b = nla_nest_start(skb, MTK_VENDOR_ATTR_CSI_DATA_Q);
+ for (i = 0; i < ARRAY_SIZE(csi->data_q); i++)
+ if (nla_put_u16(skb, i, csi->data_q[i]))
+ goto out;
+ nla_nest_end(skb, b);
+
+ nla_nest_end(skb, a);
+
+ list_del(&csi->node);
+ kfree(csi);
+ phy->csi.count--;
+
+ err = phy->csi.count;
+ }
+out:
+ spin_unlock_bh(&phy->csi.csi_lock);
+
+ return err;
+}
+
+static const struct wiphy_vendor_command mt7915_vendor_commands[] = {
+ {
+ .info = {
+ .vendor_id = MTK_NL80211_VENDOR_ID,
+ .subcmd = MTK_NL80211_VENDOR_SUBCMD_CSI_CTRL,
+ },
+ .flags = WIPHY_VENDOR_CMD_NEED_NETDEV |
+ WIPHY_VENDOR_CMD_NEED_RUNNING,
+ .doit = mt7915_vendor_csi_ctrl,
+ .dumpit = mt7915_vendor_csi_ctrl_dump,
+ .policy = csi_ctrl_policy,
+ .maxattr = MTK_VENDOR_ATTR_CSI_CTRL_MAX,
+ }
+};
+
+void mt7915_vendor_register(struct mt7915_phy *phy)
+{
+ phy->mt76->hw->wiphy->vendor_commands = mt7915_vendor_commands;
+ phy->mt76->hw->wiphy->n_vendor_commands = ARRAY_SIZE(mt7915_vendor_commands);
+}
diff --git a/mt7915/vendor.h b/mt7915/vendor.h
new file mode 100644
index 00000000..9d3db2a7
--- /dev/null
+++ b/mt7915/vendor.h
@@ -0,0 +1,60 @@
+#ifndef __MT7915_VENDOR_H
+#define __MT7915_VENDOR_H
+
+#define MTK_NL80211_VENDOR_ID 0x0ce7
+
+enum mtk_nl80211_vendor_subcmds {
+ MTK_NL80211_VENDOR_SUBCMD_CSI_CTRL = 0xc2,
+};
+
+enum mtk_vendor_attr_csi_ctrl {
+ MTK_VENDOR_ATTR_CSI_CTRL_UNSPEC,
+
+ MTK_VENDOR_ATTR_CSI_CTRL_CFG,
+ MTK_VENDOR_ATTR_CSI_CTRL_CFG_MODE,
+ MTK_VENDOR_ATTR_CSI_CTRL_CFG_TYPE,
+ MTK_VENDOR_ATTR_CSI_CTRL_CFG_VAL1,
+ MTK_VENDOR_ATTR_CSI_CTRL_CFG_VAL2,
+ MTK_VENDOR_ATTR_CSI_CTRL_MAC_ADDR,
+ MTK_VENDOR_ATTR_CSI_CTRL_INTERVAL,
+
+ MTK_VENDOR_ATTR_CSI_CTRL_DUMP_NUM,
+
+ MTK_VENDOR_ATTR_CSI_CTRL_DATA,
+
+ /* keep last */
+ NUM_MTK_VENDOR_ATTRS_CSI_CTRL,
+ MTK_VENDOR_ATTR_CSI_CTRL_MAX =
+ NUM_MTK_VENDOR_ATTRS_CSI_CTRL - 1
+};
+
+enum mtk_vendor_attr_csi_data {
+ MTK_VENDOR_ATTR_CSI_DATA_UNSPEC,
+ MTK_VENDOR_ATTR_CSI_DATA_PAD,
+
+ MTK_VENDOR_ATTR_CSI_DATA_VER,
+ MTK_VENDOR_ATTR_CSI_DATA_TS,
+ MTK_VENDOR_ATTR_CSI_DATA_RSSI,
+ MTK_VENDOR_ATTR_CSI_DATA_SNR,
+ MTK_VENDOR_ATTR_CSI_DATA_BW,
+ MTK_VENDOR_ATTR_CSI_DATA_CH_IDX,
+ MTK_VENDOR_ATTR_CSI_DATA_TA,
+ MTK_VENDOR_ATTR_CSI_DATA_I,
+ MTK_VENDOR_ATTR_CSI_DATA_Q,
+ MTK_VENDOR_ATTR_CSI_DATA_INFO,
+ MTK_VENDOR_ATTR_CSI_DATA_RSVD1,
+ MTK_VENDOR_ATTR_CSI_DATA_RSVD2,
+ MTK_VENDOR_ATTR_CSI_DATA_RSVD3,
+ MTK_VENDOR_ATTR_CSI_DATA_RSVD4,
+ MTK_VENDOR_ATTR_CSI_DATA_TX_ANT,
+ MTK_VENDOR_ATTR_CSI_DATA_RX_ANT,
+ MTK_VENDOR_ATTR_CSI_DATA_MODE,
+ MTK_VENDOR_ATTR_CSI_DATA_H_IDX,
+
+ /* keep last */
+ NUM_MTK_VENDOR_ATTRS_CSI_DATA,
+ MTK_VENDOR_ATTR_CSI_DATA_MAX =
+ NUM_MTK_VENDOR_ATTRS_CSI_DATA - 1
+};
+
+#endif

View file

@ -0,0 +1,54 @@
# MCU_EXT_CMD_* ids from mt76_connac_mcu.h (torvalds master)
# Same enum serves WM and WA: MCU_WA_EXT_CMD(t) = MCU_EXT_CMD(t) | WA-routing bit.
enum {
MCU_EXT_CMD_EFUSE_ACCESS = 0x01,
MCU_EXT_CMD_RF_REG_ACCESS = 0x02,
MCU_EXT_CMD_RF_TEST = 0x04,
MCU_EXT_CMD_ID_RADIO_ON_OFF_CTRL = 0x05,
MCU_EXT_CMD_PM_STATE_CTRL = 0x07,
MCU_EXT_CMD_CHANNEL_SWITCH = 0x08,
MCU_EXT_CMD_SET_TX_POWER_CTRL = 0x11,
MCU_EXT_CMD_FW_LOG_2_HOST = 0x13,
MCU_EXT_CMD_TXBF_ACTION = 0x1e,
MCU_EXT_CMD_EFUSE_BUFFER_MODE = 0x21,
MCU_EXT_CMD_THERMAL_PROT = 0x23,
MCU_EXT_CMD_STA_REC_UPDATE = 0x25,
MCU_EXT_CMD_BSS_INFO_UPDATE = 0x26,
MCU_EXT_CMD_EDCA_UPDATE = 0x27,
MCU_EXT_CMD_DEV_INFO_UPDATE = 0x2A,
MCU_EXT_CMD_THERMAL_CTRL = 0x2c,
MCU_EXT_CMD_WTBL_UPDATE = 0x32,
MCU_EXT_CMD_SET_DRR_CTRL = 0x36,
MCU_EXT_CMD_SET_RDD_CTRL = 0x3a,
MCU_EXT_CMD_ATE_CTRL = 0x3d,
MCU_EXT_CMD_PROTECT_CTRL = 0x3e,
MCU_EXT_CMD_DBDC_CTRL = 0x45,
MCU_EXT_CMD_MAC_INIT_CTRL = 0x46,
MCU_EXT_CMD_RX_HDR_TRANS = 0x47,
MCU_EXT_CMD_MUAR_UPDATE = 0x48,
MCU_EXT_CMD_BCN_OFFLOAD = 0x49,
MCU_EXT_CMD_RX_AIRTIME_CTRL = 0x4a,
MCU_EXT_CMD_SET_RX_PATH = 0x4e,
MCU_EXT_CMD_EFUSE_FREE_BLOCK = 0x4f,
MCU_EXT_CMD_TX_POWER_FEATURE_CTRL = 0x58,
MCU_EXT_CMD_RXDCOC_CAL = 0x59,
MCU_EXT_CMD_GET_MIB_INFO = 0x5a,
MCU_EXT_CMD_TXDPD_CAL = 0x60,
MCU_EXT_CMD_CAL_CACHE = 0x67,
MCU_EXT_CMD_RED_ENABLE = 0x68,
MCU_EXT_CMD_CP_SUPPORT = 0x75,
MCU_EXT_CMD_SET_RADAR_TH = 0x7c,
MCU_EXT_CMD_SET_RDD_PATTERN = 0x7d,
MCU_EXT_CMD_MWDS_SUPPORT = 0x80,
MCU_EXT_CMD_SET_SER_TRIGGER = 0x81,
MCU_EXT_CMD_TWT_AGRT_UPDATE = 0x94,
MCU_EXT_CMD_FW_DBG_CTRL = 0x95,
MCU_EXT_CMD_OFFCH_SCAN_CTRL = 0x9a,
MCU_EXT_CMD_SET_RDD_TH = 0x9d,
MCU_EXT_CMD_MURU_CTRL = 0x9f,
MCU_EXT_CMD_SET_SPR = 0xa8,
MCU_EXT_CMD_GROUP_PRE_CAL_INFO = 0xab,
MCU_EXT_CMD_DPD_PRE_CAL_INFO = 0xac,
MCU_EXT_CMD_PHY_STAT_INFO = 0xad,
MCU_EXT_CMD_WF_RF_PIN_CTRL = 0xbd,
};

View file

53
tools/scan_registrations.py Executable file
View file

@ -0,0 +1,53 @@
#!/usr/bin/env python3
"""Scan MediaTek Connac2 firmware regions for {id, fn*} registration arrays.
WM registers command handlers as sparse {u8 cmd_id, code*} arrays (see
findings F9: dispatcher walks gp+0x1b6a0, stride 8). This tool finds every
such array across a blob's regions — the recoverable handler map.
Usage: scan_registrations.py <blob-stem-dir> [min_run] > out.txt
(blob-stem-dir = extracted/mt7981_wm; scans all rN region files)
"""
import struct
import sys
from pathlib import Path
def code_p(w, ranges):
return any(lo <= w < hi for lo, hi in ranges)
def scan(f: Path, ranges, min_run):
d = f.read_bytes()
base = int(f.name.split('_a')[1][:8], 16)
n = len(d) // 4
ws = struct.unpack_from('<%dI' % n, d)
out = []
i = 0
while i < n - 1:
j, run = i, 0
while j < n - 1 and ws[j] < 0x100 and code_p(ws[j + 1], ranges):
run += 1
j += 2
if run >= min_run:
out.append((base + i * 4, run, ws[i:j]))
i = j + 2 if run else i + 1
return out
def main():
stem = Path(sys.argv[1])
min_run = int(sys.argv[2]) if len(sys.argv) > 2 else 8
ranges = []
for f in sorted(stem.glob('r*.bin')):
base = int(f.name.split('_a')[1][:8], 16)
ranges.append((base, base + f.stat().st_size))
for f in sorted(stem.glob('r*.bin')):
for addr, run, ws in scan(f, ranges, min_run):
print('# %d-entry {id,fn} array @ 0x%08x (%s)' % (run, addr, f.name))
for k in range(run):
print('0x%08x id=0x%02x fn=0x%08x' % (addr + k * 8, ws[2 * k], ws[2 * k + 1]))
if __name__ == '__main__':
main()

59
tools/scan_tables.py Executable file
View file

@ -0,0 +1,59 @@
#!/usr/bin/env python3
"""Scan firmware regions for consecutive function-pointer tables.
Finds runs of >= min_run consecutive little-endian dwords that all fall in a
given code range — the shape of MCU command-handler dispatch tables.
Usage: scan_tables.py <region.bin> <code_lo> <code_hi> [min_run] [tolerance]
tolerance = max absolute non-code dwords allowed inside a run (0/NULL counted).
"""
import struct
import sys
from pathlib import Path
path = Path(sys.argv[1])
lo, hi = int(sys.argv[2], 0), int(sys.argv[3], 0)
min_run = int(sys.argv[4]) if len(sys.argv) > 4 else 8
tol = int(sys.argv[5]) if len(sys.argv) > 5 else 0
d = path.read_bytes()
base = 0
# If the region file corresponds to a load address, pass that as lo bound
# via argv; region offsets here are file offsets, so also print file offset.
words = struct.unpack_from('<%dI' % (len(d) // 4), d)
run_start = None
run = []
tables = []
def flush(end):
global run, run_start
code = sum(1 for w in run if lo <= w < hi)
if len(run) >= min_run and code >= min_run:
tables.append((run_start, end, len(run), code))
run = []
run_start = None
for i, w in enumerate(words):
ok = lo <= w < hi or w == 0
if ok:
if run_start is None:
run_start = i * 4
run.append(w)
else:
if run_start is not None and tol:
run.append(w) # tolerate, next check trims
if sum(1 for x in run[-3:] if not (lo <= x < hi or x == 0)) >= 2:
flush(i * 4)
else:
flush(i * 4)
for t in tables:
start_off, end_off, n, code = t
print('table @ file+0x%x..0x%x (%d words, %d code ptrs)'
% (start_off, end_off, n, code))
vals = words[start_off // 4:end_off // 4]
for j, w in enumerate(vals[:64]):
mark = '' if lo <= w < hi else ('(0)' if w == 0 else '(?)')
print(' [%2d] 0x%08x %s' % (j, w, mark))

26
tools/stage0/analyze.py Executable file
View file

@ -0,0 +1,26 @@
#!/usr/bin/env python3
"""Windowed stats over an RSSI capture CSV (stage 0)."""
import csv
import sys
path = sys.argv[1] if len(sys.argv) > 1 else 'dataset/stage0_walk1.csv'
win = int(sys.argv[2]) if len(sys.argv) > 2 else 10
rows = []
for r in csv.reader(open(path)):
if len(r) == 3 and r[2] != 'dbm':
rows.append((float(r[1]), int(r[2])))
if not rows:
sys.exit('no data rows')
print(f'{path}: {len(rows)} samples, span {rows[-1][0]:.0f}s')
print(' window mean spread std')
for w in range(0, int(rows[-1][0]) + 1, win):
v = [d for t, d in rows if w <= t < w + win]
if not v:
continue
m = sum(v) / len(v)
sd = (sum((x - m) ** 2 for x in v) / len(v)) ** 0.5
sp = max(v) - min(v)
print(f'{w:3d}-{w + win:3d}s {m:6.1f} {sp:5d} {sd:5.2f} '
+ '#' * int(max(1, sp)))

98
tools/stage0/rssi_logger.py Executable file
View file

@ -0,0 +1,98 @@
#!/usr/bin/env python3
"""Stage 0 RSSI motion logger (CSI-project-stages.md §0.1).
Polls the AP's signal strength as fast as `iw` allows and logs
timestamp,dbm to CSV. Bodies moving through the laptop<->AP path wobble
the reading; a still room is a flat line. Busy link (iperf traffic) =
fresh readings.
Usage: rssi_logger.py [-i wlan0] [-o out.csv] [-d seconds] [--plot]
"""
import argparse
import csv
import datetime
import subprocess
import time
from pathlib import Path
SPARK = ' ▁▂▃▄▅▆▇█'
def poll(iface):
out = subprocess.run(['iw', 'dev', iface, 'station', 'dump'],
capture_output=True, text=True).stdout
for ln in out.splitlines():
s = ln.strip()
if s.startswith('signal:'):
return int(s.split()[1])
return None
def sparkline(vals):
if not vals:
return ''
lo, hi = min(vals), max(vals)
span = max(1, hi - lo)
return ''.join(SPARK[min(8, 1 + 8 * (v - lo) // span)] for v in vals)
def main():
ap = argparse.ArgumentParser()
ap.add_argument('-i', '--iface', default='wlan0')
ap.add_argument('-o', '--out', default=None)
ap.add_argument('-d', '--duration', type=float, default=0,
help='seconds; 0 = run forever')
ap.add_argument('--plot', action='store_true')
args = ap.parse_args()
sink = None
if args.out:
Path(args.out).parent.mkdir(parents=True, exist_ok=True)
sink = open(args.out, 'w', newline='')
w = csv.writer(sink)
w.writerow(['iso_time', 'monotonic_s', 'dbm'])
vals, t0, last_line = [], time.monotonic(), time.monotonic()
n = 0
try:
while True:
t = time.monotonic()
if args.duration and t - t0 > args.duration:
break
dbm = poll(args.iface)
if dbm is not None:
n += 1
vals.append(dbm)
if sink:
w.writerow([datetime.datetime.now().isoformat(
timespec='milliseconds'), round(t - t0, 3), dbm])
if t - last_line >= 1.0:
win = vals[-40:]
spread = (max(win) - min(win)) if win else 0
mean = sum(win) / len(win) if win else 0
print(f'\r{sparkline(win[-40:]):<42s} '
f'now={dbm} mean={mean:.1f} spread={spread}',
end='', flush=True)
last_line = t
time.sleep(0.05)
except KeyboardInterrupt:
pass
finally:
if sink:
sink.close()
print(f'\nsamples={n} rate={n / max(0.001, time.monotonic() - t0):.1f}/s '
f'min={min(vals)} max={max(vals)}')
if args.plot and vals:
try:
import matplotlib.pyplot as plt
plt.plot(vals)
plt.xlabel('sample')
plt.ylabel('dBm')
plt.title('RSSI')
plt.show()
except ImportError:
print('matplotlib not installed; CSV saved instead')
if __name__ == '__main__':
main()