UV_K5_playground quan sheng AFSK messenger with T9 typing support spectrum analyser
 
 
 
 
 
 
Go to file
Piotr Lewandowski 1a0502d2a4 [skip ci] spectrum png 2023-07-06 20:30:12 +02:00
.github/workflows yml-upd 2023-07-05 20:38:46 +02:00
.vscode [skip ci] pong game 2023-07-04 01:38:00 +02:00
docs [skip ci] spectrum png 2023-07-06 20:30:12 +02:00
libs fix for spectrum scanner, added possibility to switch center freq and peak printing 2023-07-06 20:25:23 +02:00
openocd_scripts
src fix for spectrum scanner, added possibility to switch center freq and peak printing 2023-07-06 20:25:23 +02:00
toolchain
tools
.gitignore
.gitmodules
CMakeLists.txt [rssi_printer] Make RSSI chart "solid" 2023-07-02 03:10:23 +02:00
README.md [skip ci] spectrum png 2023-07-06 20:30:12 +02:00

README.md

UV_K5_playground

src/spectrum auto release build

rssi printer
Spectrum scanner. It prints a spectrum graph that covers +/- 1 MHz from the center frequency. Prints center frequency, and frequency with highest amplitude.

Please, consider paying tribute to the two fallen Quashengs that were bricked during the development process. Their sacrifice played a crucial role in shaping this project. To show your appreciation and support for our ongoing work, you can make a donation.

src/rssi_sbar auto release build

rssi printer
sbar with calibrated S steps

src/rssi_printer auto release build

rssi printer
mod for printing rx signal level (RSSI) in numerical format, also includes small signal level chart.

uploading to radio

src/pong auto release build

rssi printer
this is useless

flash masking and memory layout

Chinese mcu DP32G030 has feature called flash masking, here is how it works: original_memory layout

libs/k5_uv_system (par_runner)

The idea is to run this firmware 'parallel' with the original Quencheng firmware. This can be achieved by relocating the original vector table to the end of the original firmware, and placing a new vector table at the beginning, with entities pointing to the par_runner functions that wrap the original firmware handlers.
Every interrupt is first processed by the par_runner handlers, which can perform tasks like responding to a button press(todo), before invoking the original firmware handler

flash memory layout

When building the "par_runner" target automaticly "bootloader" target will be build memory layout building par_runner target will result in following outputs:

  • par_runner.bin / .hex - right part of image, can be used to generate encrypted firmware compatible with orginal Quescheng update tool
  • bootloader.bin - stripped bootloader from orginal firmware
  • par_runner_with_bootloader.bin - complete firmware image

To change the original firmware that will be wrapped and placed into the original firmware section, replace ./original_fw/original_fw.bin or set the variable CMakeLists.txt set(ORGINAL_FW_BIN orginal_fw.bin) in ./orginal_fw/CMakeLists.txt and rebuild par_runner

build system installation

currently tested on windows, requred:

  • arm-none-eabi-gcc
  • python (i have newest version)
  • cmake
  • ninja
  • open-ocd

All folders with executables of the above programs should be added to the PATH environment variable.

for debugging:

  • vs code
    • Cortex-Debug plugin
    • CMake plugin

building

via terminal

$ mkdir build $ cd build $ cmake ../ -G Ninja $ ninja par_runner outputs ./build/src/par_runner/par_runner.bin / hex / elf

uploading

$ ninja par_runner_flash

via VS Code

Select the par_runner build target in the bottom bar and press build.

uploading

Enter the 'Run & Debug' tab, select 'kwaczek DBG', and press run.

  • currently firmare that is wrapped by par_runner comes from Tunas1337 mod k5_26_encrypted_18to1300MHz.bin UV-K5-Modded-Firmwares
  • crypting/encrypting/modding py tools amnemonic repo

Warning

I'm not responsible for radios bricked by this trojan xD