The fp carries a factory debug shell with 77 commands. A text file on the SD card runs them at boot, and nothing asks for a password. This is all 77, with the firmware's own usage text where a camera could safely be asked for it.
0xC0BAC14C: 77 entries of
{ char name[0x14]; void *handler; }, stride 0x18,
NULL-terminated. The dispatcher FUN_c03d9c20 splits the line on
spaces, matches the first token against that table, and calls the handler.The same 77 commands, reached three different ways:
| route | how | when |
|---|---|---|
| AutoRun | _AutoRun.txt on the SD card, one command per line |
at boot, before most of the camera is up |
| USB shell | fp USB Shell
forwards a line with shl <cmd> |
any time the camera is on |
| UART | the interactive prompt the shell was built for | needs the pads inside the body |
AutoRun is the one that matters, and it is worth being plain about why: there is no permission gate. A file on a memory card runs arbitrary commands from this list at boot. That is the whole basis of everything else on this site — open gate, the gyro logger, the USB shell all ride on it.
Most of the 77 report something. Five of them change something, and those five are the reason the rest of this project is possible:
| command | what it reaches |
|---|---|
mem set [addr] [data] |
Any 32-bit write, anywhere. The handler checks 4-byte alignment
and nothing else — no range check. That covers DRAM, SRAM and the
SoC's peripheral registers at 0x3xxxxxxx. |
i2c w [dev] [reg] [data] |
Writes the I²C bus: the image sensor, the PMIC, anything on it.
i2c list names the devices. |
prom write [id] [src] [size] |
Non-volatile. See the warning below. |
port set [name] high|low |
Drives a named GPIO pin. |
menu [Setter] [value] |
Writes a live camera setting directly — about 65 setters covering ISO, shutter, aperture, drive, AE and AF. |
mem set is the one that changes what is possible. An arbitrary poke
available at boot, with no gate in front of it, is what turns a closed camera into
one you can modify.
Three tiers, and they are genuinely different:
mem get, mem save, dir,
version, the RTOS introspection commands — none of these
change anything. Note that a read of an unmapped address can still
hang the camera, so a scan of a guessed range is not a read-only operation in
practice.
Everything mem set and port set touch is volatile.
A bad write freezes or resets the camera; pulling the battery gets it back. This
is the tier all of this project's products live in.
prom write outlives the batteryThis is the only tier that can leave the camera permanently worse.
prom write alone.
Its size argument is rounded up to a 128 KB boundary
((size + 0x1FFFF) & 0xFFFE0000) — a NAND erase-block —
so writing a handful of bytes rewrites a whole block. And the id
argument is just an index into a device registry whose mapping to physical parts
has not been worked out. Together that means writing an unknown amount to an
unidentified device. Back everything up with prom readfile first, and
prefer not to go there at all.Search matches the command name and the usage text. Handler addresses are Ver.5.02.
mem0xC03FA2A8writes[usage] memory write : mem set [address] [data] memory read start_address : mem get [start address,,] memory read start-end address : mem get [start address,end address,] memory read start-start+size : mem get [start address,,size] memory save start-end address : mem save [path] [start address,end address,] memory save start-start+size : mem save [path] [start address,,size]
memmgr0xC03FA878ERR shl
ddr0xC03DFB40lw last write : ddr lw [address] (Up to 8 can be set) lr last read : ddr lr [address] w write log : ddr w [start_address] [end_address] s stop : ddr s m mem deadbeef : ddr m [XC_MEMTYPE] [tips] Enter the address in hexadecimal. (0x is not required) XZ01 can not log the CPU
dbg0xC03E04D0disp_mess Toggle Display Debug Message write_out_script Writting out some command sequence to test.txt
drcv0xC03DFF50Input error
runtime0xC0407DA0bounds nil1 nil2
status0xC040FE78get status get [param name] : Get specific parameter value get status get [param name] [index] : Get specific array parameter value param list is_recording app_current app_lv_attribute
sys0xC040FA58selfrefresh sys selfrefresh [on/off] selfStopTime sys selfStopTime 600 : [unit = sec / 0 = default setting] selfConfig output selfRefresh Setting
analyzer0xC0410DA8tskmon_start start task monitor. tskmon_stop stop task monitor. tskmon_out output task monitor. tskmon_top output current. set_logger on or off ex) Display results in shell >analyzer tskmon_start [option] >analyzer tskmon_stop shell ex) Save result to media >analyzer tskmon_start [option] >analyzer tskmon_stop \\DBG_TASK.txt ex) Save result to media >analyzer tskmon_start [option] >analyzer tskmon_stop >analyzer tskmon_out \\DBG_TASK.txt ex) How to link analyzer please type >make help start option arg 0 tskCount arg 1 splitCount arg 2 timePreFix arg 3 lineBufSize arg 4 monitor time(ms) arg 5 output file path ex) analyzer tskmon_start 100000 1000 1000000 100 2000 \\DBG_TASK.txt
ts0xC0418388ram (dst) (src) (original size) : RAM to RAM nand (part id (str)) (dst) (work) (comp size) (original size) (offset) : NAND to RAM
tsd0xC0410638threshold set threshold temp Get the temperature
tkos0xC0411FB8tsklist display task list skdump dump task stack : tkos skdump [tsk_id / tsk_name] [data max:unit=byte, option(default=0x200)] stkchk check task stack : tkos stkchk mtx ref mtx : tkos mtx [all] task control tasks minth check interrupt handler : tkos minth on/off/print
port0xC0405E18writesnot runNot run. drives GPIO pins — the usage text below it would have to be asked on a camera that can afford the consequence.
pmctest0xC0405CD8not runNot run. power-management test — the usage text below it would have to be asked on a camera that can afford the consequence.
ppmgr0xC03E7070sync list erase Bulk delete slot slot chk filter display filter list
reboot0xC0405DD8resetsnot runNot run. reboots the camera — the usage text below it would have to be asked on a camera that can afford the consequence.
rebootf0xC0405DF8resetsnot runNot run. forced reboot — the usage text below it would have to be asked on a camera that can afford the consequence.
poff0xC0405D60resetsnot runNot run. powers the camera off — the usage text below it would have to be asked on a camera that can afford the consequence.
pw_save0xC0405FD0resetssleep enter led sleep poff enter power off eco enter eco mode
echo0xC03D99A0No usage text: it takes no arguments, or prints nothing.
comment0xC03D99F0No usage text: it takes no arguments, or prints nothing.
help0xC03E9598shell usage command : [command] [param1] [param2] .... [option] [enter] up / down : history (max = 30 ) command list adc adj ae af analyzer audio battery cam ctrl dbg ddr detect device dfi dir display drcv echo event evf_bri extstrb fl fwup gps gui help i2c imager imu key led lens levelgauge log mem memmgr menu mkdir model movrec optic pic play pmctest poff port ppmgr ptp prom pw_save qr reboot rebootf recstate rec rectmlg runtime sdcard setconfig setting sg3 status strb sys still time touch tkos ts tsd uart ui usb version versioncheck wb # option list loop[integer] repeat command specified times
log0xC03F9C38usage Log [command] [flag] Log Command List act Active log flag inact Inactive log flag expand Expand log size out Output log data mode Change to the mode to output logs in timely modesave Change to the shellmode level Set log level time swich time ms or us toggle_print Toggle logging with printing realtime or without printing clear clear log data info ロガーの設定状況やメモリ確保状況を表示する analyzer ログ分析を併用する。トグルします。 Log FlagList INIT 0 UI 1 RECMGR 2 CAMERAMGR 3 DATAMGR 4 OSIF 5 IMGCTL 6 MOVIE 7 LENS 8 AE 9 MEDIA 10 DISP 11 FILEMGR 12 GUI 13 BATTERY 14 EVENT 15 SIGPRO 16 MENU 17 RAWSIM 18 AWB 19 USB 20 DEVOPE 21 AF 22 RECMGR2 23 PLAY 24 LED 25 PIC 26 OPT 27 ADJ 28 BURST 29 DRAW 30 MEMMGR 31 AUDIO 32 POWER 33 STRB 34 GPS 35
i2c0xC03E9628writesnot runNot run. writes the I2C bus (sensor, PMIC) — the usage text below it would have to be asked on a camera that can afford the consequence.
prom0xC0406690non-volatilenot runNot run. EEPROM — the usage text below it would have to be asked on a camera that can afford the consequence.
device0xC03E2070rc rc <on/off/s1/s2/push/press/up>: rc status mic mic <on/off>: mic status evf evf <on/off/a_in/a_out/d_e/d_l>: evf status strb strb <on/off>: strb status
dfi0xC03E24E8invalid sub command analyze (partition ID) load (partition ID)
detect0xC03E13E8not runNot run. detection engine control — the usage text below it would have to be asked on a camera that can afford the consequence.
model0xC03DF298ERR shl
version0xC03DF218model = w71c1 xc version = V91 rel version = 5.02.0.V91 git hash = 13aa621060efff11aaba9b21ad925005302605cf
versioncheck0xC041FCF8not runNot run. version enforcement — the usage text below it would have to be asked on a camera that can afford the consequence.
setconfig0xC03DF2D0writesnot runNot run. writes configuration — the usage text below it would have to be asked on a camera that can afford the consequence.
setting0xC041E330writesread setting read : Read all parameter value get setting get [param name] : Get specific parameter value get setting get [param name] [index] : Get specific array parameter value set setting set [param name] [param value] : Set specific parameter value set setting set [param name] [index] [param value] : Set specific array parameter value write setting write : Write all parameter value load setting load : load all parameter from FlashValue save setting save : save all parameter from FlashValue readcom setting readcom : Read XC_CommonSaveData and print it readcam CameraSetting read : Read all parameter value writecam CameraSetting write : Write all parameter value param list cam_still_imagesize.h cam_still_imagesize.v cam_movie_imagesize.h cam_movie_imagesize.v cam_frame_rate cam_aspect exp_mode iso iso_high iso_low
fwup0xC03E73B0non-volatilenot runNot run. firmware update path — the usage text below it would have to be asked on a camera that can afford the consequence.
cam0xC03DB748start camera scheduler each stop integer(1st digit) stop camera scheduler each stop integer(1st digit) ls camera scheduler start log le camera scheduler end log
adc0xC03DBA40[usage]
device command : show support device list
input: adc list
device command : read from i2c with device name
input: adc <device name>
input: adc <device name> <interval:dec> <count:dec>
ex1:once) >adc temp_battery
ex2:10 times at 10 ms interval) >adc temp_battery 10 10
<interval> = 5-100 ms, <count> = max 20 times
battery0xC03DEAD8500 < [interval] < 10000 ms exit : PRESS CAMERA KEY or DIAL
imager0xC03F54E8writesnot runNot run. sensor readout and gain state — the usage text below it would have to be asked on a camera that can afford the consequence.
adj0xC03DC1A0writesnot runNot run. adjustment and calibration data — the usage text below it would have to be asked on a camera that can afford the consequence.
optic0xC04037D8set 次に続くオプションに値をセット get 次に続くオプションの値を得る
pic0xC0404E98set (pattern) (0:off, 1:only tag 2(default):reset inputparam (pattern) (0(default):auto, 1:fix tbsd (pattern) (0:off, 1:adjust(default), 2:test, 3:auto, 4:user adjust, 5:get_status distortion (pattern) (0(default):auto, 1:force_off, 2:test_mode aberration (pattern) (0(default):auto, 1:force_off, 2:test_mode shading (pattern) (0(default):auto, 1:force_off, 2:test_mode 3ddnr (pattern) (0(default):auto, 1:force_off, 2:debug_mode, 3:input_mode monofilter (pattern) (param)(0:off(default), 1:off_debug_mode, 2:grayscale, 3:binalization (0<param<15), 4:dither_dot sig_dsccal Dumping out some data in signal process print_cp Printing cDNG playing info print_tag Printing pic_data When writing tags.
wb0xC0420218fp set fullpower(center 1/4) mode cl clear all debug mode dbg wb dbg integer(1st digit) integer(2nd digit) rec_arg change arguments from recmgr to specified value get_kelvin get kelvin and tint (works on only w71c1)
still0xC040F130not runNot run. still capture — the usage text below it would have to be asked on a camera that can afford the consequence.
movrec0xC0403558not runNot run. movie recording control — the usage text below it would have to be asked on a camera that can afford the consequence.
rec0xC04074E8not runNot run. starts and stops recording — the usage text below it would have to be asked on a camera that can afford the consequence.
recstate0xC0407BA8ena Enable RecState disa Disable RecState init Set Initial Value movrecstwai Waiting for Movie Rec Start movsavewai Waiting for Movie storage stillsavewai Waiting for Still storage savewai Waiting for Still/Movie storage
rectmlg0xC04077A0addtimeset LogFile Infomation Get setfilename LogFile Set Name
play0xC04057C8not runNot run. playback control — the usage text below it would have to be asked on a camera that can afford the consequence.
qr0xC0407298test qrcode library test decode_log qrcode decode log dump_yuv dump yuv when qrcode decode dump_y8 dump y8 when qrcode decode play_make qr make [write data] : make qr code and display play_read qr play_read : read qr code from play image lv_read qr lv_read : read qr code from lv
menu0xC0402F98writesnot runNot run. writes live camera settings — the usage text below it would have to be asked on a camera that can afford the consequence.
ae0xC03DC8E8flck flicker test pline disp pline. arg[0] = 0:ACQ, 1:MONIT, arg[1] = 0:Apex, 1:Not Apex exp disp exposure. 0:ACQ, 1:MONIT fix fix exposure settings. ylevel disp current ylevel.
af0xC03DD020print toggle show the log or not dbg af dbg integer(1st digit) integer(2nd digit) msr Measure get af information acquisition.
lens0xC03F8CC0sh (pattern) (0(default):single, 1:burst init down getfedge 0(default):inf, 1:near cnvfpos (dist=1000) cnvfdist (pos=1000) setfpos (pos=1000) getfpos Get focus position setfinf Set focus position to infinity fc (pattern) (0(default):scan, 1:scan ir (pattern) (0(default):test cnvav Conver to valid aperture value setav (av=4096(AVx1024)) [spd(AVx1024/frame)] getav Get aperture value fwup (filename=lensfirm.bin) [-f:force] clrc clear cache print toggle show the log or not mc Attach SigmaMountConverter? isabs is Abs Positioning? ver Get current system version dof Get dof pls getdata Get Lens data emulate Set Emulate read cmd read (ex:lens read 0x151e00 30) tr (on/off) no1 no2 ... no10
levelgauge0xC03F8E98level gauge command check: check level gauge params (ori, yaw, pitch, roll)
imu0xC03EA2F8cmd : 0 gyro adjustment
cmd : 1 gyro output
cpu : 0 use mainarm
1 use subarm
2 use subarm ring buf
device_id : sampling device id(=0,1,2,...)
interval : sampling interval[msec]
count : sampling count
cmd : 2 get gyro offset
strb0xC040F7F0dump eval dump wait
extstrb0xC03E66E0test basic test print toggle show the log or not print_with_eve toggle show the log or not print_state print ext strb state start task start stop task stop flash flash when task runnning toggle Toggle some setting, manual_flash test emmiting manual flash param set get params
fl0xC03E6BB8rename rename [src] [dest] del delete file(currently not working) delDir delete Directory(currently not working) createdmy file create :cinemaDNG deloneimg delete file topFrame delCinemaDng delete file CinemaDNG delall delete All file
led0xC03F60C8 normal
charging
firmup
movrec
format
medinit
stillwr
movwrite
still2
playlock
playmark
playrot
playdel
chargerr
feeding
output led mode list
<no> = 0...n, <level> = 0:low, n:high
ex) >led 0 1
LED no 0 is on
usb0xC0419028not runNot run. switches USB mode — would drop this very channel — the usage text below it would have to be asked on a camera that can afford the consequence.
uart0xC0419548uart <baudrate> : set baudrate (example: uart 115200) uart def : set default baudrate uart force <baudrate> : set baudrate (no check) uart info : print current baudrate
gps0xC03E7BD8set set: re-set gps info(get and set) get_ifd get: get gps ifd info get_pos get: get gps position/orientation clr clr: clear gps info has has: check if gps has valid info
audio0xC03DE338usage audio mic [int or ext] : change to [internal or external] mic audio mic chk : output mic type audio rec start <file path> : start recording (linear PCM format) ex: audio rec start \\test.wav audio rec stop : stop recording audio play media <file path> (sp_vol) : start playing (linear PCM format) ex: audio play \\test.wav 0x38 audio play beep <id> (vol_level) : start playing beep with/without volume(0xAB to 0x00) ex: audio play beep focus 0x00 audio param filter : Set filter params audio param alc : Set ALC params audio codec vol : Set volume audio codec pga : Set PGA volume audio codec micb : Set MICboost volume audio dngpb start <file path> : start playing (linear PCM format) ex: audio play start \\test.wav audio dngpb stop : stop playing
key0xC03F5DC0not runNot run. injects key events — the usage text below it would have to be asked on a camera that can afford the consequence.
touch0xC0412958tap tap [x] [y] dtap dtap [x] [y] drag drag [start x] [start y] [end x] [end y] [point num] th th [threshold type] [value]
ui0xC0419BC8log log <on/off> detect_log detect ui log <on/off> rload load <file name> <bank:0-6> <load sys set:0/1>: load setting bin file rsave save <file name> <title name:16> <icon name:2>: save setting bin file rdump dump qr preview from current buffer rget get recommend setting type rlog rlog <on/off>: recommend load / save log ctrl
gui0xC03E8F98geti geti <name>: get variable (int) getf getf <name>: (float) gets gets <name>: (string) seti seti <name>: set variable (int) setf setf <name>: (float) sets sets <name>: (string) send send <AppSyncReqName> key key <eXC_GuiControlType> <eXC_GuiKeyType> <on_off> lang lang <language_id>: change language 0:ja, 1:en, 2:de_DE, 3:fr_FR, 4:es_ES, 5:it_IT, 6:zh_CN, 7:zh_TW, 8:ko, 9:ru 10:nl_BE, 11:pl, 12:pt_PT, 13:da, 14:sv_SE, 15:nn_NO, 16:fi lang lang mode <0/1>: change language mode scr scr log <0/1>, scr set <screen name> req req log <0/1>: request log mode time time log <0/1>: update/render proc time log mode area area log <0/1>: draw area log mode image image log <0/1>: load image log mode trace trace log <0/1>: trace log mode val val : value function mem get memory information gc gc execution ver get gui version
display0xC03E5510first of all ,set ctrl target monitor and layer : >>monitor
monitor (MonitorNum0-1),(layer0-1)
hdmi (on:1,off:0)
lcd (on:1,off:0)
lcdTune
colorbar (on:1,off:0) (pattern)
zoom (h=640),(v=480),(addr)
hdmi_onoff (on:1,off:0)
hdmi_mask (set mask:1-n, all clr mask:0)
hdmi_mask_str ON/OFF [option]
hdmi_edid setting debug edid
reset reset shellmode config
osd (on:1,off:0) (color ex::0xffff0000 32bitRed)
osdPalette (on:1,off:0) path ex.) \\dump.pal
image (on:1,off:0) (MonitorNum0-1)
osdfile path ex.) \\SAMPLE\\TEST.TIF (layer0-1) (MonitorNum0-1) (h) (v) (offset)
text (message)
faceframe ON : rect{ 0 1 2 3 } , OFF : {}
focusarea (on:1,off:0)
capture path ex.) \\SAMPLE\\dump.xci ,sel : main(1),sub(2),both(3), compress : none(0),RLE(1),LZ4(2)
palette sel : main(1),sub(2),both(3) , isRgb : yuv(0),rgb(1) ,path(for Dump)
peaking (on:1,off:0) (thresh 0~) (normal:0,custom:1)
address (count 0~)
get_out displ
evf_bri0xC03E2F58OK
event0xC03E5A28send send [event] [param] getattr getattr [filter]: output attribute each sub state.
ptp0xC0406C30log ptp log sts_chg send state change command focus_comp send Focus Driving Complete command capt disp capt status cmd send command
sdcard0xC040B4D0slot Second Argument no input =Get Now slot sd0 =Set SdCard ext =Set External storage test test [slot] test2 test2 [slot] [bufsize] (Write,Read,Diff)*offset test3 test3 [slot] [bufsize] [loop num] (Write,Read)*loop test4 test4 [slot] [bufsize] (Write,Read)*offset test5 test5 [slot] [au] [bufsize] [filename] (Write loop, Read loop) test6 test6 [slot] [filecount] (Disk full) test_rw test_rw [slot] [bufsize] (Write,Read,Seek,Discard,Delete)test size size [slot] fnum fnum [slot] sdmode format format [slot] checkinit checkinit [slot] chkop readOnly readOnly [on|off] [path] : Change attributes | readOnly time : Measure time mnt mnt [slot] : Mount umnt umnt [slot] : UnMount
dir0xC03E2980. 2026/08/25 05:41:28 <DIR> .Spotlight-V100 2026/08/25 08:56:00 14116 AutoRun.txt 2026/08/25 23:15:12 <DIR> CINEMA
mkdir0xC03E2D00usage : mkdir [path]
time0xC04112C0set >time set YYYY/MM/DD hh:mm:ss get >time get utc_offset >time utc_offset [+3:00/-5:30...] summer_time >time summer_time [+1:00/+0:00] reset >time reset tickm >time get ticktimer ms ticku >time get ticktimer us tickmstr >time get ticktimer ms Measurement Start tickmstp >time get ticktimer ms Measurement Stop
ctrl0xC040D538mediaOut path ex.) \\SAMPLE\\TEST.TXT mediaOutTest mediaOutのストレステストを行う。mediaOutのエラー切り分け用 mediaIn path ex.) \\TEST.TXT bufferIn listname keyIn id(0~3), keyID(eXC_EventMessage), iskeyOnOff,isKeyDisable, cmd... sleep ms timmem ex.) timmem [memory no] timclr ex.) timclr [memory no] timmemwai ex.) timmemwai [memory no] [wait time(sec)] setmedia paths ex.) \\TEST1.TXT \\TEST2.TXT getmedia errstk Dump Error Stack errlink print Error Link Addr errlog print Error Log save_log print saved log in nand t_assert test assert t_abort test abort t_null test nullfunc call t_zero test zero div
sg30xC040B800not runNot run. undocumented — the usage text below it would have to be asked on a camera that can afford the consequence.
Nothing matches that.
AutoRun fires early, which cuts both ways:
| state | commands |
|---|---|
| ready immediately | anything that is pure CPU and memory: mem,
port, ddr, reboot, the RTOS
introspection. The most useful one, mem set, is in this
group. |
| needs its driver up | i2c, prom, imager,
adj, imu, pic, optic,
play, qr, rec, movrec,
menu. Run too early these no-op, or act on an uninitialised
state. |
The exact init order per subsystem versus the moment AutoRun fires has not been traced command by command. In practice the products here work around it by doing the memory writes at boot and deferring anything driver-shaped until the camera has reached a known state.
prom device-id to physical-part mapping
(FUN_c0041f78 holds the registry). Until that is read out,
prom write has no safe target.i2c list name is the image sensor and which is the PMIC.sg3 is undocumented and was not run; nobody knows what it is.rectmlg only
stores a tag string, so any limit is probably a menu or
setconfig value rather than a command of its own.The command table, the dispatcher and the handler addresses were read out of the
Ver.5.02 image. The usage text was asked from a camera over the USB shell, with a
capture sink pushed onto the shell's own output stack so the firmware's
printf came back over USB instead of going to the UART pads. The
working documents are
SHELL_COMMANDS
and
SHELL_CAPABILITIES,
and this page is generated from the first of them by
tools/gen_shell_page.py.