hn.today

Reverse Engineering of the M-VAVE FM-1 Pocket Synthesizer Firmware

github.com57 points36 comments
Screenshot of Reverse Engineering of the M-VAVE FM-1 Pocket Synthesizer Firmware

A focused reverse‑engineering project that reconstructs the firmware, boot chain, and update protocol for the M‑VAVE FM‑1 pocket synthesizer. It identifies the platform as a JieLi AC791N/WL82 SoC with a pi32v2 CPU and XIP flash mapped at 0x02000000, and characterizes the synth engine as a six‑operator FM core derived from Dexed/msfa. Work includes a hardware and memory architecture overview, static disassembly and function classification (two independent V13 analysis pipelines), a detailed trace of the device OTA loader and finish gate, captured USB‑MIDI framing and session flow, and a decompiled Windows updater state machine. The embedded JL‑BR22 string is flagged as library nomenclature rather than reliable chip ID. No replacement firmware or custom image builders are included on the main line; an experimental branch preserves earlier custom firmware work.

Practical artifacts and tooling are provided to reproduce analysis: Ghidra scripts, extraction and classification pipelines, firmware images, and a Linux USB‑MIDI client with offline tests. The safety verdict is explicit: the update protocol is not a demonstrated recovery mechanism - single‑bank flash has no confirmed ROM recovery, rollback, or safe interrupted‑write behavior, and a debug‑surface audit found no factory recovery entry. The repository documents external references, checked‑in third‑party utilities (jl‑misctools, jl‑uboot‑tool), and pointers to the AC791N/WL82 SDK used for corroboration.

Read on github.com36 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.