Ant
But this function does not return focal length. It prints value as a string to somewhere like EventShell buffer(0x00051520).
UPD. The mistake was found in the first call. There should be "bl sub_fc43cd97\n"
You don't need to set the thumb bit for BL instruction labels when you write asm code.
Due to the calling convention, a function call destroys the content of registers r0..r3.
I'd try this:
movs r0, #0
push {r4, r5, lr} // modified
bl loc_fc43cd96
mov r4, r0
ldr r0, [r0, #0x24]
movs r1, #0xa0
strb r1, [r0, #0]
movs r1, #0
ldr r0, [r4, #0x24]
strb r1, [r0, #1]
ldr r0, [r4, #0x24]
strb r1, [r0, #2]
movs r1, #3
ldr r0, [r4, #0x20]
str r1, [r0, #0]
mov r0, r4
bl loc_fc2f2c0e
ldr r0, [r4, #0x28]
ldrb r1, [r0, #1]
ldrb r0, [r0, #2]
add.w r0, r0, r1, lsl #8
uxth r5, r0 // modified
// ldr r0, =0xfc43e274 ; *".Focal Length = %ld mm" // -
// bl loc_fc37fd9c // -
mov r0, r4
bl loc_fc43cdf4
// movs r0, #0 // -
mov r0, r5 // +
pop {r4, r5, pc} // modified