← Firmware research

The firmware shell

The fp carries a factory debug shell with 77 commands. A text file on the SD card runs them at boot, and nothing asks for a password. This is all 77, with the firmware's own usage text where a camera could safely be asked for it.

Where it is
A table at 0xC0BAC14C: 77 entries of { char name[0x14]; void *handler; }, stride 0x18, NULL-terminated. The dispatcher FUN_c03d9c20 splits the line on spaces, matches the first token against that table, and calls the handler.
Where the text came from
Every usage block below was printed by the camera itself over the USB shell. It is the firmware's own help, not a reconstruction, which is why the formatting and the typos are uneven.
What was not run
21 commands could reboot the camera, write non-volatile storage, drive hardware, change live settings, or drop the USB channel carrying the question. They are listed with what they are and why they were skipped.

Three ways in

The same 77 commands, reached three different ways:

routehowwhen
AutoRun _AutoRun.txt on the SD card, one command per line at boot, before most of the camera is up
USB shell fp USB Shell forwards a line with shl <cmd> any time the camera is on
UART the interactive prompt the shell was built for needs the pads inside the body

AutoRun is the one that matters, and it is worth being plain about why: there is no permission gate. A file on a memory card runs arbitrary commands from this list at boot. That is the whole basis of everything else on this site — open gate, the gyro logger, the USB shell all ride on it.

The write primitives

Most of the 77 report something. Five of them change something, and those five are the reason the rest of this project is possible:

commandwhat it reaches
mem set [addr] [data] Any 32-bit write, anywhere. The handler checks 4-byte alignment and nothing else — no range check. That covers DRAM, SRAM and the SoC's peripheral registers at 0x3xxxxxxx.
i2c w [dev] [reg] [data] Writes the I²C bus: the image sensor, the PMIC, anything on it. i2c list names the devices.
prom write [id] [src] [size] Non-volatile. See the warning below.
port set [name] high|low Drives a named GPIO pin.
menu [Setter] [value] Writes a live camera setting directly — about 65 setters covering ISO, shutter, aperture, drive, AE and AF.

mem set is the one that changes what is possible. An arbitrary poke available at boot, with no gate in front of it, is what turns a closed camera into one you can modify.

Safety

Three tiers, and they are genuinely different:

  1. Reading is safe

    mem get, mem save, dir, version, the RTOS introspection commands — none of these change anything. Note that a read of an unmapped address can still hang the camera, so a scan of a guessed range is not a read-only operation in practice.

  2. A RAM or register poke is, at worst, a reboot

    Everything mem set and port set touch is volatile. A bad write freezes or resets the camera; pulling the battery gets it back. This is the tier all of this project's products live in.

  3. prom write outlives the battery

    This is the only tier that can leave the camera permanently worse.

Two specific reasons to leave prom write alone. Its size argument is rounded up to a 128 KB boundary ((size + 0x1FFFF) & 0xFFFE0000) — a NAND erase-block — so writing a handful of bytes rewrites a whole block. And the id argument is just an index into a device registry whose mapping to physical parts has not been worked out. Together that means writing an unknown amount to an unidentified device. Back everything up with prom readfile first, and prefer not to go there at all.

All 77 commands

Search matches the command name and the usage text. Handler addresses are Ver.5.02.

77 of 77

Memory, CPU and RTOS 23

mem0xC03FA2A8writes
[usage]
  memory write                  : mem set [address] [data] 
  memory read start_address     : mem get [start address,,] 
  memory read start-end address : mem get [start address,end address,] 
  memory read start-start+size  : mem get [start address,,size] 
  memory save start-end address : mem save [path] [start address,end address,] 
  memory save start-start+size  : mem save [path] [start address,,size]
memmgr0xC03FA878
ERR shl
ddr0xC03DFB40
lw         last write : ddr lw [address] (Up to 8 can be set)
  lr         last read  : ddr lr [address]
  w          write log  : ddr w [start_address] [end_address]
  s          stop       : ddr s
  m          mem deadbeef : ddr m [XC_MEMTYPE] 
[tips]  
  Enter the address in hexadecimal. (0x is not required)
  XZ01 can not log the CPU
dbg0xC03E04D0
disp_mess  Toggle Display Debug Message
  write_out_script Writting out some command sequence to test.txt
drcv0xC03DFF50
Input error
runtime0xC0407DA0
bounds     
  nil1       
  nil2
status0xC040FE78
get        status get [param name]                        : Get specific parameter value
  get        status get [param name] [index]                : Get specific array parameter value
param list 
  is_recording
  app_current
  app_lv_attribute
sys0xC040FA58
selfrefresh sys selfrefresh [on/off]
  selfStopTime sys selfStopTime 600 : [unit = sec / 0 = default setting]
  selfConfig output selfRefresh Setting
analyzer0xC0410DA8
tskmon_start  start task monitor.
  tskmon_stop  stop task monitor.
  tskmon_out  output task monitor.
  tskmon_top  output current.
  set_logger on or off
ex) Display results in shell 
 >analyzer tskmon_start [option]
 >analyzer tskmon_stop shell
ex) Save result to media 
 >analyzer tskmon_start [option]
 >analyzer tskmon_stop \\DBG_TASK.txt 
ex) Save result to media 
 >analyzer tskmon_start [option]
 >analyzer tskmon_stop 
 >analyzer tskmon_out \\DBG_TASK.txt 
ex) How to link analyzer 
please type >make help
  start option 
  arg 0 tskCount
  arg 1 splitCount
  arg 2 timePreFix
  arg 3 lineBufSize
  arg 4 monitor time(ms)
  arg 5 output file path
ex) analyzer tskmon_start 100000 1000 1000000 100 2000 \\DBG_TASK.txt
ts0xC0418388
ram        (dst) (src) (original size)                                       : RAM to RAM
  nand       (part id (str)) (dst) (work) (comp size) (original size) (offset) : NAND to RAM
tsd0xC0410638
threshold  set threshold 
  temp       Get the temperature
tkos0xC0411FB8
tsklist    display task list
  skdump     dump task stack : tkos skdump [tsk_id / tsk_name] [data max:unit=byte, option(default=0x200)]
  stkchk     check task stack : tkos stkchk
  mtx        ref mtx : tkos mtx [all]
  task       control tasks
  minth      check interrupt handler : tkos minth on/off/print
port0xC0405E18writesnot run

Not run. drives GPIO pins — the usage text below it would have to be asked on a camera that can afford the consequence.

pmctest0xC0405CD8not run

Not run. power-management test — the usage text below it would have to be asked on a camera that can afford the consequence.

ppmgr0xC03E7070
sync        
  list        
  erase      Bulk delete
  slot       slot chk
  filter     display filter list
reboot0xC0405DD8resetsnot run

Not run. reboots the camera — the usage text below it would have to be asked on a camera that can afford the consequence.

rebootf0xC0405DF8resetsnot run

Not run. forced reboot — the usage text below it would have to be asked on a camera that can afford the consequence.

poff0xC0405D60resetsnot run

Not run. powers the camera off — the usage text below it would have to be asked on a camera that can afford the consequence.

pw_save0xC0405FD0resets
sleep      enter led sleep
  poff       enter power off
  eco        enter eco mode
echo0xC03D99A0

No usage text: it takes no arguments, or prints nothing.

comment0xC03D99F0

No usage text: it takes no arguments, or prints nothing.

help0xC03E9598
shell usage 
 command   : [command] [param1]  [param2] .... [option] [enter]
 up / down : history (max = 30 ) 
command list 
  adc
  adj
  ae
  af
  analyzer
  audio
  battery
  cam
  ctrl
  dbg
  ddr
  detect
  device
  dfi
  dir
  display
  drcv
  echo
  event
  evf_bri
  extstrb
  fl
  fwup
  gps
  gui
  help
  i2c
  imager
  imu
  key
  led
  lens
  levelgauge
  log
  mem
  memmgr
  menu
  mkdir
  model
  movrec
  optic
  pic
  play
  pmctest
  poff
  port
  ppmgr
  ptp
  prom
  pw_save
  qr
  reboot
  rebootf
  recstate
  rec
  rectmlg
  runtime
  sdcard
  setconfig
  setting
  sg3
  status
  strb
  sys
  still
  time
  touch
  tkos
  ts
  tsd
  uart
  ui
  usb
  version
  versioncheck
  wb
  #
option list 
  loop[integer]  repeat command specified times
log0xC03F9C38
usage 
 Log [command] [flag] 
Log Command List 
  act        Active log flag
  inact      Inactive log flag
  expand     Expand log size
  out        Output log data
  mode       Change to the mode to output logs in timely
  modesave   Change to the shellmode 
  level      Set log level
  time       swich time ms or us
  toggle_print Toggle logging with printing realtime or without printing
  clear      clear log data
  info       ロガーの設定状況やメモリ確保状況を表示する
  analyzer   ログ分析を併用する。トグルします。
Log FlagList 
  INIT  0 
  UI  1 
  RECMGR  2 
  CAMERAMGR  3 
  DATAMGR  4 
  OSIF  5 
  IMGCTL  6 
  MOVIE  7 
  LENS  8 
  AE  9 
  MEDIA  10 
  DISP  11 
  FILEMGR  12 
  GUI  13 
  BATTERY  14 
  EVENT  15 
  SIGPRO  16 
  MENU  17 
  RAWSIM  18 
  AWB  19 
  USB  20 
  DEVOPE  21 
  AF  22 
  RECMGR2  23 
  PLAY  24 
  LED  25 
  PIC  26 
  OPT  27 
  ADJ  28 
  BURST  29 
  DRAW  30 
  MEMMGR  31 
  AUDIO  32 
  POWER  33 
  STRB  34 
  GPS  35

Bus, device and firmware 14

i2c0xC03E9628writesnot run

Not run. writes the I2C bus (sensor, PMIC) — the usage text below it would have to be asked on a camera that can afford the consequence.

prom0xC0406690non-volatilenot run

Not run. EEPROM — the usage text below it would have to be asked on a camera that can afford the consequence.

device0xC03E2070
rc         rc <on/off/s1/s2/push/press/up>: rc status
  mic        mic <on/off>: mic status
  evf        evf <on/off/a_in/a_out/d_e/d_l>: evf status
  strb       strb <on/off>: strb status
dfi0xC03E24E8
invalid sub command
  analyze    (partition ID)
  load       (partition ID)
detect0xC03E13E8not run

Not run. detection engine control — the usage text below it would have to be asked on a camera that can afford the consequence.

model0xC03DF298
ERR shl
version0xC03DF218
model       = w71c1 
xc version  = V91 
rel version = 5.02.0.V91  
git hash    = 13aa621060efff11aaba9b21ad925005302605cf
versioncheck0xC041FCF8not run

Not run. version enforcement — the usage text below it would have to be asked on a camera that can afford the consequence.

setconfig0xC03DF2D0writesnot run

Not run. writes configuration — the usage text below it would have to be asked on a camera that can afford the consequence.

setting0xC041E330writes
read       setting read          : Read all parameter value
  get        setting get [param name]                        : Get specific parameter value
  get        setting get [param name] [index]                : Get specific array parameter value
  set        setting set [param name] [param value]          : Set specific parameter value
  set        setting set [param name] [index] [param value]  : Set specific array parameter value
  write      setting write        : Write all parameter value
  load       setting load          : load all parameter from FlashValue
  save       setting save          : save all parameter from FlashValue
  readcom    setting readcom       : Read XC_CommonSaveData and print it
  readcam    CameraSetting read    : Read all parameter value
  writecam   CameraSetting write  : Write all parameter value
param list 
  cam_still_imagesize.h
  cam_still_imagesize.v
  cam_movie_imagesize.h
  cam_movie_imagesize.v
  cam_frame_rate
  cam_aspect
  exp_mode
  iso
  iso_high
  iso_low
fwup0xC03E73B0non-volatilenot run

Not run. firmware update path — the usage text below it would have to be asked on a camera that can afford the consequence.

cam0xC03DB748
start      camera scheduler each stop integer(1st digit)
  stop       camera scheduler each stop integer(1st digit)
  ls         camera scheduler start log
  le         camera scheduler end log
adc0xC03DBA40
[usage]
  device command : show support device list 
    input: adc list 
  device command : read from i2c with device name 
    input: adc <device name> 
    input: adc <device name> <interval:dec> <count:dec>
  ex1:once) >adc temp_battery 
  ex2:10 times at 10 ms interval) >adc temp_battery 10 10 
  <interval> = 5-100 ms, <count> = max 20 times
battery0xC03DEAD8
        500 < [interval] < 10000 ms 
exit : PRESS CAMERA KEY or DIAL

Imaging, ISP and recording 12

imager0xC03F54E8writesnot run

Not run. sensor readout and gain state — the usage text below it would have to be asked on a camera that can afford the consequence.

adj0xC03DC1A0writesnot run

Not run. adjustment and calibration data — the usage text below it would have to be asked on a camera that can afford the consequence.

optic0xC04037D8
set        次に続くオプションに値をセット
  get        次に続くオプションの値を得る
pic0xC0404E98
set        (pattern) (0:off, 1:only tag 2(default):reset
  inputparam (pattern) (0(default):auto, 1:fix
  tbsd       (pattern) (0:off, 1:adjust(default), 2:test, 3:auto, 4:user adjust, 5:get_status
  distortion (pattern) (0(default):auto, 1:force_off, 2:test_mode
  aberration (pattern) (0(default):auto, 1:force_off, 2:test_mode
  shading    (pattern) (0(default):auto, 1:force_off, 2:test_mode
  3ddnr      (pattern) (0(default):auto, 1:force_off, 2:debug_mode, 3:input_mode
  monofilter (pattern) (param)(0:off(default), 1:off_debug_mode, 2:grayscale, 3:binalization (0<param<15), 4:dither_dot
  sig_dsccal Dumping out some data in signal process
  print_cp   Printing cDNG playing info
  print_tag  Printing pic_data When writing tags.
wb0xC0420218
fp         set fullpower(center 1/4) mode
  cl         clear all debug mode
  dbg        wb dbg integer(1st digit) integer(2nd digit)
  rec_arg    change arguments from recmgr to specified value
  get_kelvin get kelvin and tint (works on only w71c1)
still0xC040F130not run

Not run. still capture — the usage text below it would have to be asked on a camera that can afford the consequence.

movrec0xC0403558not run

Not run. movie recording control — the usage text below it would have to be asked on a camera that can afford the consequence.

rec0xC04074E8not run

Not run. starts and stops recording — the usage text below it would have to be asked on a camera that can afford the consequence.

recstate0xC0407BA8
ena        Enable RecState
  disa       Disable RecState
  init       Set Initial Value
  movrecstwai Waiting for Movie Rec Start
  movsavewai Waiting for Movie storage
  stillsavewai Waiting for Still storage
  savewai    Waiting for Still/Movie storage
rectmlg0xC04077A0
addtimeset  LogFile Infomation Get
  setfilename LogFile Set Name
play0xC04057C8not run

Not run. playback control — the usage text below it would have to be asked on a camera that can afford the consequence.

qr0xC0407298
test       qrcode library test
  decode_log qrcode decode log
  dump_yuv   dump yuv when qrcode decode
  dump_y8    dump y8 when qrcode decode
  play_make  qr make [write data] : make qr code and display
  play_read  qr play_read         : read qr code from play image
  lv_read    qr lv_read           : read qr code from lv

Exposure, AF and lens 6

menu0xC0402F98writesnot run

Not run. writes live camera settings — the usage text below it would have to be asked on a camera that can afford the consequence.

ae0xC03DC8E8
flck       flicker test
  pline      disp pline. arg[0] = 0:ACQ, 1:MONIT, arg[1] = 0:Apex, 1:Not Apex
  exp        disp exposure. 0:ACQ, 1:MONIT
  fix        fix exposure settings.
  ylevel     disp current ylevel.
af0xC03DD020
print      toggle show the log or not
  dbg        af dbg integer(1st digit) integer(2nd digit)
  msr        Measure
  get        af information acquisition.
lens0xC03F8CC0
sh         (pattern) (0(default):single, 1:burst
  init       
  down       
  getfedge   0(default):inf, 1:near
  cnvfpos    (dist=1000)
  cnvfdist   (pos=1000)
  setfpos    (pos=1000)
  getfpos    Get focus position
  setfinf    Set focus position to infinity
  fc         (pattern) (0(default):scan, 1:scan
  ir         (pattern) (0(default):test
  cnvav      Conver to valid aperture value
  setav      (av=4096(AVx1024)) [spd(AVx1024/frame)]
  getav      Get aperture value
  fwup       (filename=lensfirm.bin) [-f:force]
  clrc       clear cache
  print      toggle show the log or not
  mc         Attach SigmaMountConverter?
  isabs      is Abs Positioning?
  ver        Get current system version
  dof        Get dof pls
  getdata    Get Lens data
  emulate    Set Emulate
  read       cmd read (ex:lens read 0x151e00 30)
  tr         (on/off) no1 no2 ... no10
levelgauge0xC03F8E98
level gauge command
  check:   check level gauge params (ori, yaw, pitch, roll)
imu0xC03EA2F8
cmd : 0 gyro adjustment
cmd : 1 gyro output
     cpu : 0 use mainarm
           1 use subarm
           2 use subarm ring buf
     device_id : sampling device id(=0,1,2,...)
     interval : sampling interval[msec]
     count : sampling count
cmd : 2 get gyro offset

I/O, UI and storage 22

strb0xC040F7F0
dump       eval dump
  wait
extstrb0xC03E66E0
test       basic test
  print      toggle show the log or not
  print_with_eve toggle show the log or not
  print_state print ext strb state
  start      task start
  stop       task stop
  flash      flash when task runnning
  toggle     Toggle some setting,
  manual_flash test emmiting manual flash
  param      set get params
fl0xC03E6BB8
rename     rename [src] [dest]
  del        delete file(currently not working)
  delDir     delete Directory(currently not working)
  createdmy  file create :cinemaDNG
  deloneimg  delete file topFrame
  delCinemaDng delete file CinemaDNG
  delall     delete All file
led0xC03F60C8
    normal
    charging
    firmup
    movrec
    format
    medinit
    stillwr
    movwrite
    still2
    playlock
    playmark
    playrot
    playdel
    chargerr
    feeding
    output led mode list 
    <no> = 0...n, <level> = 0:low, n:high 
    ex) >led 0 1 
         LED no 0 is on
usb0xC0419028not run

Not run. switches USB mode — would drop this very channel — the usage text below it would have to be asked on a camera that can afford the consequence.

uart0xC0419548
uart <baudrate>       : set baudrate (example: uart 115200)
uart def              : set default baudrate
uart force <baudrate> : set baudrate (no check)
uart info             : print current baudrate
gps0xC03E7BD8
set        set: re-set gps info(get and set)
  get_ifd    get: get gps ifd info
  get_pos    get: get gps position/orientation
  clr        clr: clear gps info
  has        has: check if gps has valid info
audio0xC03DE338
usage 
   audio mic [int or ext]      : change to [internal or external] mic 
   audio mic chk               : output mic type 
   audio rec start <file path> : start recording (linear PCM format) ex: audio rec start \\test.wav
   audio rec stop              : stop recording 
   audio play media <file path> (sp_vol) : start playing (linear PCM format) ex: audio play \\test.wav 0x38
   audio play beep <id> (vol_level) : start playing beep with/without volume(0xAB to 0x00) ex: audio play beep focus 0x00
   audio param filter           : Set filter params
   audio param alc             : Set ALC params 
   audio codec vol             : Set volume 
   audio codec pga             : Set PGA volume 
   audio codec micb            : Set MICboost volume 
   audio dngpb start <file path> : start playing (linear PCM format) ex: audio play start \\test.wav
   audio dngpb stop              : stop playing
key0xC03F5DC0not run

Not run. injects key events — the usage text below it would have to be asked on a camera that can afford the consequence.

touch0xC0412958
tap        tap [x] [y]
  dtap       dtap [x] [y]
  drag       drag [start x] [start y] [end x] [end y] [point num]
  th         th [threshold type] [value]
ui0xC0419BC8
log        log <on/off>
  detect_log detect ui log <on/off>
  rload      load <file name> <bank:0-6> <load sys set:0/1>: load setting bin file
  rsave      save <file name> <title name:16> <icon name:2>: save setting bin file
  rdump      dump qr preview from current buffer
  rget       get recommend setting type
  rlog       rlog <on/off>: recommend load / save log ctrl
gui0xC03E8F98
geti       geti <name>: get variable (int)
  getf       getf <name>: (float)
  gets       gets <name>: (string)
  seti       seti <name>: set variable (int)
  setf       setf <name>: (float)
  sets       sets <name>: (string)
  send       send <AppSyncReqName>
  key        key <eXC_GuiControlType> <eXC_GuiKeyType> <on_off>
  lang       lang <language_id>: change language
 0:ja, 1:en, 2:de_DE, 3:fr_FR, 4:es_ES, 5:it_IT, 6:zh_CN, 7:zh_TW, 8:ko, 9:ru 
 10:nl_BE, 11:pl, 12:pt_PT, 13:da, 14:sv_SE, 15:nn_NO, 16:fi
  lang       lang mode <0/1>: change language mode 
  scr        scr log <0/1>, scr set <screen name>
  req        req log <0/1>: request log mode
  time       time log <0/1>: update/render proc time log mode
  area       area log <0/1>: draw area log mode
  image      image log <0/1>: load image log mode
  trace      trace log <0/1>: trace log mode
  val        val : value function
  mem        get memory information
  gc         gc execution
  ver        get gui version
display0xC03E5510
first of all ,set ctrl target monitor and layer : >>monitor 
  monitor    (MonitorNum0-1),(layer0-1)
  hdmi       (on:1,off:0)
  lcd        (on:1,off:0)
  lcdTune    
  colorbar   (on:1,off:0) (pattern)
  zoom       (h=640),(v=480),(addr)
  hdmi_onoff (on:1,off:0)
  hdmi_mask  (set mask:1-n, all clr mask:0)
  hdmi_mask_str ON/OFF [option]
  hdmi_edid  setting debug edid
  reset      reset shellmode config
  osd        (on:1,off:0) (color ex::0xffff0000 32bitRed) 
  osdPalette (on:1,off:0) path ex.) \\dump.pal 
  image      (on:1,off:0) (MonitorNum0-1)
  osdfile    path ex.) \\SAMPLE\\TEST.TIF (layer0-1) (MonitorNum0-1) (h) (v) (offset)
  text       (message)
  faceframe  ON : rect{ 0 1 2 3 } , OFF : {}
  focusarea  (on:1,off:0)
  capture    path ex.) \\SAMPLE\\dump.xci ,sel : main(1),sub(2),both(3), compress : none(0),RLE(1),LZ4(2)
  palette    sel : main(1),sub(2),both(3) , isRgb : yuv(0),rgb(1) ,path(for Dump) 
  peaking    (on:1,off:0) (thresh 0~) (normal:0,custom:1)
  address    (count 0~)
  get_out    displ
evf_bri0xC03E2F58
OK
event0xC03E5A28
send       send [event] [param]
  getattr    getattr [filter]: output attribute each sub state.
ptp0xC0406C30
log        ptp log
  sts_chg    send state change command
  focus_comp send Focus Driving Complete command
  capt       disp capt status
  cmd        send command
sdcard0xC040B4D0
slot       Second Argument
   no input =Get Now slot
   sd0      =Set SdCard
   ext      =Set External storage
  test       test [slot]
  test2      test2 [slot] [bufsize]                  (Write,Read,Diff)*offset
  test3      test3 [slot] [bufsize] [loop num]       (Write,Read)*loop
  test4      test4 [slot] [bufsize]                  (Write,Read)*offset
  test5      test5 [slot] [au] [bufsize] [filename]  (Write loop, Read loop)
  test6      test6 [slot] [filecount]                (Disk full)
  test_rw    test_rw [slot] [bufsize]                (Write,Read,Seek,Discard,Delete)test
  size       size [slot]
  fnum       fnum [slot]
  sdmode     
  format     format [slot]
  checkinit  checkinit [slot]
  chkop      
  readOnly   readOnly [on|off] [path] : Change attributes | readOnly time : Measure time
  mnt        mnt [slot]  : Mount
  umnt       umnt [slot] : UnMount
dir0xC03E2980
.
2026/08/25  05:41:28 <DIR>                .Spotlight-V100
2026/08/25  08:56:00                14116 AutoRun.txt
2026/08/25  23:15:12 <DIR>                CINEMA
mkdir0xC03E2D00
usage : mkdir [path]
time0xC04112C0
set        >time set YYYY/MM/DD hh:mm:ss
  get        >time get
  utc_offset >time utc_offset [+3:00/-5:30...]
  summer_time >time summer_time [+1:00/+0:00]
  reset      >time reset
  tickm      >time get ticktimer ms
  ticku      >time get ticktimer us
  tickmstr   >time get ticktimer ms Measurement Start
  tickmstp   >time get ticktimer ms Measurement Stop
ctrl0xC040D538
mediaOut   path ex.) \\SAMPLE\\TEST.TXT
  mediaOutTest mediaOutのストレステストを行う。mediaOutのエラー切り分け用 
  mediaIn    path ex.) \\TEST.TXT
  bufferIn   listname
  keyIn      id(0~3), keyID(eXC_EventMessage), iskeyOnOff,isKeyDisable, cmd...
  sleep      ms
  timmem     ex.) timmem [memory no]
  timclr     ex.) timclr [memory no]
  timmemwai  ex.) timmemwai [memory no] [wait time(sec)]
  setmedia   paths ex.) \\TEST1.TXT \\TEST2.TXT
  getmedia   
  errstk     Dump Error Stack
  errlink    print Error Link Addr
  errlog     print Error Log
  save_log   print saved log in nand
  t_assert   test assert
  t_abort    test abort
  t_null     test nullfunc call
  t_zero     test zero div
sg30xC040B800not run

Not run. undocumented — the usage text below it would have to be asked on a camera that can afford the consequence.

Nothing matches that.

What is available at boot

AutoRun fires early, which cuts both ways:

statecommands
ready immediately anything that is pure CPU and memory: mem, port, ddr, reboot, the RTOS introspection. The most useful one, mem set, is in this group.
needs its driver up i2c, prom, imager, adj, imu, pic, optic, play, qr, rec, movrec, menu. Run too early these no-op, or act on an uninitialised state.

The exact init order per subsystem versus the moment AutoRun fires has not been traced command by command. In practice the products here work around it by doing the memory writes at boot and deferring anything driver-shaped until the camera has reached a known state.

Still open

Sources

The command table, the dispatcher and the handler addresses were read out of the Ver.5.02 image. The usage text was asked from a camera over the USB shell, with a capture sink pushed onto the shell's own output stack so the firmware's printf came back over USB instead of going to the UART pads. The working documents are SHELL_COMMANDS and SHELL_CAPABILITIES, and this page is generated from the first of them by tools/gen_shell_page.py.