Week 4-BN: flash over SWD from the console (no BOOTSEL)

Add the flash.sh / OpenOCD program-over-probe path to Steps 21 and 29: run it
from Binary Ninja's console via subprocess, and note the probe is single-owner
(stop debug-server.sh's OpenOCD first). Verified live: Verified OK, reset, and the
board booted the hacked image.
This commit is contained in:
Kevin Thomas committed 2026-10-03 16:40:28 -04:00
1 parent d9c2922445
commit 86d3dbdb12
2 files changed
+37 -1

No files matched your search

+37 -1
View File
@@ -827,6 +827,35 @@ age: 70
**43 became 70, permanently, with one byte changed and no source code.**
> **Faster: flash over the Debug Probe (no BOOTSEL).** The repo's `flash.sh` writes the raw `.bin` straight into XIP flash over SWD (`program <bin> 0x10000000 verify reset exit`), so you never touch BOOTSEL or a UF2. Run it from the Binary Ninja console:
>
> ```python
> import os, subprocess
> root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename)))
> bin_path = os.path.join(os.path.dirname(bv.file.original_filename), "0x0005_intro-to-variables-h.bin")
> subprocess.run([os.path.join(root, "flash.sh"), bin_path])
> ```
>
> Or the OpenOCD call directly, if you would rather not depend on the script:
>
> ```python
> import os, subprocess
> ocd = os.path.expanduser("~/.pico-sdk/openocd/0.12.0+dev")
> bin_path = os.path.join(os.path.dirname(bv.file.original_filename), "0x0005_intro-to-variables-h.bin")
> subprocess.run([f"{ocd}/openocd", "-s", f"{ocd}/scripts",
> "-f", "interface/cmsis-dap.cfg", "-f", "target/rp2350.cfg",
> "-c", "adapter speed 5000",
> "-c", f"program {bin_path} 0x10000000 verify reset exit"])
> ```
>
> **The Debug Probe is single-owner.** If Binary Ninja is still attached (the `debug-server.sh` OpenOCD is running), the flash cannot grab the probe. Detach in Binary Ninja and stop that OpenOCD first:
>
> ```bash
> pkill -TERM -f openocd
> ```
>
> Success looks like `Programming Finished` -> `Verified OK` -> `Resetting Target`. On Windows, `flash.ps1` works the same way.
---
## Part 5: Dynamic — Break at `main` and Hack Live (Project 2)
@@ -1155,7 +1184,14 @@ python3 ../uf2conv.py 0x0008_uninitialized-variables-h.bin \
Or run the conversion from the Binary Ninja console, exactly as in Step 20 (`os.chdir` to the build dir, then `runpy.run_path("../../uf2conv.py", run_name="__main__")` with `sys.argv` set to the arguments above).
Hold **BOOTSEL**, plug in the Pico 2, drag `hacked.uf2` onto the **`RP2350`** drive.
Hold **BOOTSEL**, plug in the Pico 2, drag `hacked.uf2` onto the **`RP2350`** drive. Or flash the `.bin` over the Debug Probe with SWD — no BOOTSEL — from the console, exactly as in Step 21 (stop any running OpenOCD first):
```python
import os, subprocess
root = os.path.dirname(os.path.dirname(os.path.dirname(bv.file.original_filename)))
bin_path = os.path.join(os.path.dirname(bv.file.original_filename), "0x0008_uninitialized-variables-h.bin")
subprocess.run([os.path.join(root, "flash.sh"), bin_path])
```
### Step 30: Verify
Binary file not shown.