diff --git a/WEEK04/WEEK04-BN.md b/WEEK04/WEEK04-BN.md index 03ac42f..86c1a33 100644 --- a/WEEK04/WEEK04-BN.md +++ b/WEEK04/WEEK04-BN.md @@ -827,6 +827,35 @@ age: 70 **43 became 70, permanently, with one byte changed and no source code.** +> **Faster: flash over the Debug Probe (no BOOTSEL).** The repo's `flash.sh` writes the raw `.bin` straight into XIP flash over SWD (`program 0x10000000 verify reset exit`), so you never touch BOOTSEL or a UF2. Run it from the Binary Ninja console: +> +> ```python +> import os, subprocess +> root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) +> bin_path = os.path.join(os.path.dirname(bv.file.original_filename), "0x0005_intro-to-variables-h.bin") +> subprocess.run([os.path.join(root, "flash.sh"), bin_path]) +> ``` +> +> Or the OpenOCD call directly, if you would rather not depend on the script: +> +> ```python +> import os, subprocess +> ocd = os.path.expanduser("~/.pico-sdk/openocd/0.12.0+dev") +> bin_path = os.path.join(os.path.dirname(bv.file.original_filename), "0x0005_intro-to-variables-h.bin") +> subprocess.run([f"{ocd}/openocd", "-s", f"{ocd}/scripts", +> "-f", "interface/cmsis-dap.cfg", "-f", "target/rp2350.cfg", +> "-c", "adapter speed 5000", +> "-c", f"program {bin_path} 0x10000000 verify reset exit"]) +> ``` +> +> **The Debug Probe is single-owner.** If Binary Ninja is still attached (the `debug-server.sh` OpenOCD is running), the flash cannot grab the probe. Detach in Binary Ninja and stop that OpenOCD first: +> +> ```bash +> pkill -TERM -f openocd +> ``` +> +> Success looks like `Programming Finished` -> `Verified OK` -> `Resetting Target`. On Windows, `flash.ps1` works the same way. + --- ## Part 5: Dynamic — Break at `main` and Hack Live (Project 2) @@ -1155,7 +1184,14 @@ python3 ../uf2conv.py 0x0008_uninitialized-variables-h.bin \ Or run the conversion from the Binary Ninja console, exactly as in Step 20 (`os.chdir` to the build dir, then `runpy.run_path("../../uf2conv.py", run_name="__main__")` with `sys.argv` set to the arguments above). -Hold **BOOTSEL**, plug in the Pico 2, drag `hacked.uf2` onto the **`RP2350`** drive. +Hold **BOOTSEL**, plug in the Pico 2, drag `hacked.uf2` onto the **`RP2350`** drive. Or flash the `.bin` over the Debug Probe with SWD — no BOOTSEL — from the console, exactly as in Step 21 (stop any running OpenOCD first): + +```python +import os, subprocess +root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename))) +bin_path = os.path.join(os.path.dirname(bv.file.original_filename), "0x0008_uninitialized-variables-h.bin") +subprocess.run([os.path.join(root, "flash.sh"), bin_path]) +``` ### Step 30: Verify diff --git a/WEEK04/WEEK04-BN.pdf b/WEEK04/WEEK04-BN.pdf index f869ade..8f5d1c7 100644 Binary files a/WEEK04/WEEK04-BN.pdf and b/WEEK04/WEEK04-BN.pdf differ