[coreboot] [RFC] Netbook Support
r.marek at assembler.cz
Sun Jan 4 12:36:45 CET 2009
-----BEGIN PGP SIGNED MESSAGE-----
> do end up needed to did deeper and you can't get any info from the
> manufacturer then EnE is your best bet for reverse engineering.
I have taken a BIOS from Mini A110 (q1d25i.rom). The Quanta IL1 reference design
seems to use ENE3310 controller. The q1d25i.rom was examined. The EC code is on
0xFFF00000 length is 64KB. The file is called HOLE0.ROM inside BIOS.
The ENE KB3310 seems to be similar to ENE KB3920, which datasheet I found via
I have taken IDA and did the LST file. It has 8051 inside. Yesterday I spoke
with Bari and got the s51 emulator from (SVN:
I fixed the serial port issue, and now the firmware runs inside emulator:
wake at z,ACOut
It prints 't' every second or so.
It seems that a flash can be flashed even unsoldered via serial interface of EC.
(some other pins must be pulled low)
Here is a EC schematics from reference design.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
-----END PGP SIGNATURE-----
More information about the coreboot