About dejan hack:
It was bit diffrent.
FPGA was attached as a slave (it didn't generated own clock - only captured data at AD0,AD1,ADx, on rising/falling flash clock edges generated by CPU) and when pattern was matched, put ADx high/low.
So x ns job. Here need to FULL capture 2 lines for SO long time.
And remember: in dejan hack target CPU needs to be WORKING (because it patched return jump from PA call on-the-fly), so it needed to execute rest part of code (re-create pm-308,etc..)..
Here we don't need have system running - that's why we can deal with eMMC directly. |