peabody
In case anyone is interested, attached is bootflg2.zip, which contains bootflg2.fir - my reworking of the bootflag.fir file. This version checks for the presence of firmware v1.0.3, and also checks the initial status of the boot flag area, before proceeding with the process of modifying the boot flag. There's a ReadMe.txt included with more detail. Oh, and it does actually zero out those two buffers instead of pretending to. Commented C code is included.
This does work on my camera, but I make no other promises. The new file still depends on the two subroutines called by the original, and we still don't know anything about them. So I think some risk remains.
I would appreciate any comments or suggestions from anyone who wants to review the C code. I don't really know much about C, but did confirm that the object code does what I wanted - see bootflg2.asm.
Otm
@peabody
Thank you for your effort and sharing your investigations. I don't belive you would find a way - so i'm very surprised.
Both of my 350d worked with the 'old' modifikation - so there's no need to try yours. But i hope you will go on and maybe improve the whole functionality of the hacked firmware.
peabody
I've just started using the latest krazyklaus version - 20101011 - and have a couple dumb questions that I can't find answers to in the thread.
After you bring up the INFO screen, you can no longer exit that screen by pressing INFO again. Is there an approved exit method, or just whatever works?
In INFO, on the second line in place of what used to be the AEB scale, there's now a scale that goes from minus 1 2/3 to + 2 1/3, and the indicator is on +1/3. It appears this no longer has anything to do with AEB, but I can't find anything that's currently set at +1/3, or any setting that changes the indicator. What is this scale?
Thanks
crazyklaus
the scale is a bug, it doesn't ever change, I have no idea what causes it.
half press the shutter button to exit any camera menu, with or without the hack.
curunir
I just read this whole topic and could not really find a solution to the problem I have.
Recently I modded my 350D by removing its IR filter, so I can start using it for infrared photography. However, since this IR filter is now missing, the autofocus does no longer work correctly, which is kind of logical.
However, I would like to install a custom firmware and modify this firmware myself by changing the way the camera focuses. Does anybody have a clue how I can do this?
Also, I looked at the source code and could only find the code that adds the extra functions to the camera. I could not find the actual piece of code where the focusing is done.
Could anybody here help me out and give me some pointers?
crazyklaus
when you do the hack, you change only some bits in the firmware, allowing the camera to boot code from the cf memory card. the rest of the hack is contained in the file autoexec.bin. it's loaded and executed when the camera boots. it only contains the additional code, as you said.
for what you want to do, you need to change the actual firmware (where we only change the boot flag). that's much more dangerous because you can easily destroy your camera.
I have seen instructions on the internet to remove the IR filter that account for the difference in auto focusing and try to preserve the af function. I don't know if this helps you, (I don't know the specifics) but maybe you can find some info that tells you what you can do on the hardware part.
a1ex
You may try to find the amount of misfocus correction; after the camera focused, you call a routine which rotates manually the focus motor. I don't know if this can be done on the 350D; only know that Magic Lantern implemented rack focus, which also rotates the focus motor.
Since you don't have any feedback, don't expect very good results, but I think it will be better than it's now.
For a (much easier) hardware solution, see here:
http://www.astrosurf.org/buil/autofocus/adjust.htm . Don't know if the amount of correction is enough for IR, though.
curunir
Okay, so changing the actual firmware is a dangerous job, I understand that. Is what a1ex says do-able? Is there a way to create my own routine that actually drives the focus motor? Can this routine then be bound to one single button, like let's say the star button which I hardly use? So no menu interventions?
Also, I've seen the link you gave me. But I read that this method only rotates it, where I actually want to bridge the gap that removing the hot mirror has created, which is physically impossible (I mounted the sensor in the camera myself 😉). Do you think this will actually fix it? Then maybe I should just try this!
stonerain
fisrt, I must thank all you guys. and I have a suggestion that the hack function should be actived only in "M" mode.
I don't know if it's possible. but I think it's very helpful for me.
peabody
There have been several people who bricked their 350Ds by running the bootflag modifier program with the wrong firmware installed. As I understand it, they can no longer access any CF card, which means there's no way to reverse whatever damage was done - even if you could figure out what to do - because you can't get back in.
I just wondered if anyone has had experience with sending such a camera in to Canon for repair. In theory all the camera needs is to have the firmware and flags memory and such be completely re-flashed to the original factory state. If that's possible, it shouldn't really be an expensive repair because you wouldn't even need to disassemble the camera.
They might be able to get back in through the USB connector. Or, if you take the battery out and look down into the well, there are two 8-pad connectors at the bottom that don't have anything to do with the battery. Maybe that's some kind of factory access that could be used if CF isn't working.
Well, I know it wouldn't make a lot of sense to spend big repair money on a 350D, but it seems like it might be worth it to at least send it in with an explanation, and ask for a repair quote before they actually do the work.
What do you think?
reboot81
Ive got a 350D with batterygrip, FW 1.03. 32k shutter count. And I have managed to 'brick' mine a couple of times.
I used the camera with the custom firmware, perhaps taken 100 shots with it trying out all the functions.
A week or two after I went out on a boat trip and the camera died after 5 shots. I tried everything, removing the batteries, lens, battery grip, CF-card, and the tiny CR2016 battery. Dead.
Six days later i assembled the whole thing and voila! Red light on, blue light on -all ok.
Two shots later. Dead. This time I left the camera switch ON (displays were dead). 30min later I returned to pack down the camera - it was HOT. Sure I could hold it in my hand, but this was to hottest camera I've held. This time it took three weeks before it 'woke up' again. (This time I had the the tiny CR2016 battery removed.)
Sorry for the long post, but my conclusions are: If 'bricked', remove ALL batteries. Then wait. At least a week. Then reassemble and try. Dont give up, it might take a week or two before the camera is completely drained of power.
And REMOVE THE BATTERIES when not in use. (Fire hazard?)
Q: Why does this happen?
peabody
That sounds really strange. Does this happen with any CF card you might use? Or if you put in a normal non-bootable card with no autoexec.bin file on it, does the camera behave normally and stay cool?
Does the heatup happen when not using the battery grip?
reyalp
reboot81
Ive got a 350D with batterygrip, FW 1.03. 32k shutter count. And I have managed to 'brick' mine a couple of times.
I used the camera with the custom firmware, perhaps taken 100 shots with it trying out all the functions.
A week or two after I went out on a boat trip and the camera died after 5 shots. I tried everything, removing the batteries, lens, battery grip, CF-card, and the tiny CR2016 battery. Dead.
Six days later i assembled the whole thing and voila! Red light on, blue light on -all ok.
Two shots later. Dead. This time I left the camera switch ON (displays were dead). 30min later I returned to pack down the camera - it was HOT. Sure I could hold it in my hand, but this was to hottest camera I've held. This time it took three weeks before it 'woke up' again. (This time I had the the tiny CR2016 battery removed.)
Sorry for the long post, but my conclusions are: If 'bricked', remove ALL batteries. Then wait. At least a week. Then reassemble and try. Dont give up, it might take a week or two before the camera is completely drained of power.
And REMOVE THE BATTERIES when not in use. (Fire hazard?)
Q: Why does this happen?
I would take a wild guess that this is some kind of intermittent electrical/mechanical failure in the camera unrelated to the hack.
Draf
cyrustam
You can build your own hack
1. Download gcc346.zip
http://www.filefactory.com/file/b00a572/n/gcc346.zip
Hi, I use the firmware from the quote.
I want to reassign some of the hotkeys.
spot metering, I can not find this option in main.c
how to assign buttons metering + print = spot metering.
petition asking for my english.
2. Extract it to c:\
3. cd c:\gcc346\myproject\350d_all_in_infov2_fastcwb\
4. build.bat
5. Copy the AUTOEXEC.BIN to your CF Card
you can edit the source code before you run "build.bat"
Hi, I use the firmware from the quote.
I want to reassign some of the hotkeys.
spot metering, I can not find this option in main.c
how to assign buttons metering + print = spot metering.
sorry for my english.
deweb
When updating from firmware 1.0.3 to scanled.fir, the blue LED does not come up at all. I kept the camera at "CF card containing firmware is required to update" screen for 10+min with no blue LED comming up. I checked blue LED is working on PickBridge printing. Have reset all the camera settings to default. Any idea? My camera is Rebel XT (USA ver).
Thank you in advance.
peabody
If you're absolutely sure your camera has firmware v1.0.3, then you may be one of a small number of people who can't get scanled.fir to work even with the right firmware. In earlier posts to this thread we discussed some serious shortcomings with scanled.fir, and I posted a new version called bootflg2.fir:
https://chdk.setepontos.com/d/4202/343
But I think the first thing you should do is see if scanled succeeded in changing the boot flag even though the blue light never came on. Go through the process of making a CF card bootable, put one of the autoexec.bin files in the boot directory, and see if the camera runs it. If it does, then I think you are where you want to be.
If not, then you might want to try my bootflg2.fir. That version works on my XT, and it does check for the presence on 1.0.3 before doing anything. I believe it is a better, safer boot flag modifier, but since I'm the author, I may be biased. In any case, there are no guarantees with any of these programs, so you take your chances.
deweb
Thank you for your quick response peabody.
Using bootflg2.fir produces only one blue LED flash. I am stock. Any other idea?
peabody
No, I'm afraid I don't have any more suggestions. Bootflg2 first checks for v1.0.3 firmware, and makes sure the initial state of the bootflag block is as expected. Apparently that was successful because you got the first blue flash.
But then it calls the subroutine in firmware that's supposed to transfer the boot flag block to ram, and then checks to be sure that was done correctly. If it was, it will blink blue again, but if not you should get a solid red light. Since you get neither of these, I have to assume it's not even coming back into bootflg2 from the subroutine.
I don't know why that is happening. It may be that there are different versions of the 350D hardware, and that the mystery subroutines originally used in scanled.fir without explanation aren't at the same place in all versions. That would make sense if that part of the firmware isn't updated by new versions from Canon - it may be part of the boot code that never changes.
I wish I knew how to dump a range of memory to a file on the CF card. Then I could include a test to see if that routine is where it's supposed to be, and contains what it should. Or, just include the right subroutine in the program in the first place. Maybe someone could suggest how to do that dump.
Anyway, if your camera still works, that's the main thing. If it does, I wouldn't do anymore attempts at this. That has ended badly for some.
primeone
Hey guys,
I'd like to thank everyone who's contributed to this. I just installed it on my 350D and it runs fine.
I used bootflg2 to enable the camera to book from CF (
http://chdk.setepontos.com/index.php?action=dlattach;topic=4202.0;attach=4318) and 350D-20101011.zip on theCF card (
http://download562.mediafire.com/egtxq18xo4ig/uiw46q26dq9ddmm/350D-20101011.zip)
No problems at all.
Just one question - how do I get the Timelapse option to work? I set the timelapse I want, but how do I start taking pictures?
--Edit
Found the answer here :
https://chdk.setepontos.com/d/4202/254
I had to set the "set" button to something other than "normal" in Custom Function 1
Next question - where can I get a copy of gcc346.zip so that I can try out my own modifications? All the links I've found on this thread are dead and I'd rather not try a different compiler version that the tried-and-true one.
Thanks,
Robert
peabody
I found a copy of gcc346.zip here:
http://rapidlibrary.com/index.php?q=350d
But I think after extracting the zip you will need to move your 20101011 folder into the myproject folder and compile from there.
Glad the boot flag thing worked for you.