Add the flash.sh / OpenOCD program-over-probe path to Steps 21 and 29: run it
from Binary Ninja's console via subprocess, and note the probe is single-owner
(stop debug-server.sh's OpenOCD first). Verified live: Verified OK, reset, and the
board booted the hacked image.
Read the loadable segment (seg.start + seg.data_length) instead of hardcoding the
range or calling os.path.getsize, and document converting the .bin to UF2 from
Binary Ninja's own Python console (chdir + runpy). Verified: the dump is byte-exact
except the patches, and uf2conv yields a valid UF2 (magic/family/blocks OK).
The console's CWD is read-only, so open('...bin','wb') fails with OSError
Errno 30. Write next to the loaded file via bv.file.original_filename, and read
the image range (0x10000000 + 0x3bbc / 0x3d34) instead of the whole mapped view.
The Python shortcut failed with SyntaxError: unknown type name 'stdio_driver_t'
then 'va_list' then 'uint'. set_user_type re-parses each signature as C, so the
Pico SDK types (uint, va_list, stdio_driver_t, uart_inst_t, gpio_function_t) must
be defined first. Add the sdk parse/define block to both snippets and correct the
stale 'undefined named types are fine' note.
Replace the wrong 'double-click the value' instruction with
dbg.set_reg_value('r1', 0x46) / dbg.set_reg_value('r0', 0x20080000);
right-click + E kept as the alternative. Drop the 'turns orange' claim.
- Step 16: Y is the primary resolution key (Change Type sets name+type); N is
rename-only; explicit how-to and worked examples use G then Y
- Step 4: add exact DWARF signatures to both symbol tables
- Python shortcut now sets names AND types (bv.get_function_at(...).set_user_type)
- Step 26: worked examples use G then Y
- Step 16: G/N/Y key table and worked examples (main, stdio_init_all, uart_init,
__wrap_printf); note BN shows int32_t where Ghidra shows int
- Step 26: worked check + pointer to Step 16
- troubleshooting: macOS serial capture needs raw termios at 115200
- Step 13/14/25 and tables: use Debugger -> Add Hardware Breakpoint... (HE),
warn that F2 Toggle Breakpoint is a software breakpoint and never installs on
read-only flash
- new troubleshooting entry: r1 reverts to 0x2b (core running because the
breakpoint is not installed; registers widget is a per-stop snapshot)
- Step 13 rewritten: set/move breakpoints in the GUI, not the command port
- Steps 14/14b/25/25b: breakpoints via the GUI (command port only for the
RAM string write, which BN cannot do)
- Step 22/23: adapter corrected GDB RSP -> GDB MI
- cheat sheet, GUI-actions and OpenOCD tables: GUI-first, command port as fallback
- troubleshooting: real GDB MI causes (pre-existing breakpoint, gdb path, LLDB);
stops reported as Breakpoint not SingleStep