<?xml-stylesheet href="/rss.xsl" type="text/xsl"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>iank.org</title><link>https://iank.org/</link><description>Recent content on iank.org</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><copyright>2014-2024 iank.org</copyright><lastBuildDate>Sat, 08 Jan 2022 04:44:49 +0000</lastBuildDate><atom:link href="https://iank.org/index.xml" rel="self" type="application/rss+xml"/><item><title>FROGSBORO: SAM9X60 SiP Embedded Linux</title><link>https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/</link><pubDate>Sat, 08 Jan 2022 04:44:49 +0000</pubDate><guid>https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/</guid><description>iank.org https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/ -&lt;p>Another custom embedded Linux board. I recently did a free evaluation of Altium Designer and built this as a way to try it out. The design is based on the SAM9X60 SiP and has a USB device port, two USB host ports, a microSD card, and a low profile 40-pin expansion connector (following the Raspberry Pi pinout) which breaks out GPIOs and various other peripherals. It&amp;rsquo;s called FROGSBORO, which I guess is a moderate improvement over &lt;a href="https://iank.org/posts/catfood-custom-imx6ull-board">CATFOOD&lt;/a>.&lt;/p>
&lt;p>Design files: &lt;a href="https://iank.org/media/frogsboro_schematic_v1.0.2.pdf">Schematic (pdf)&lt;/a>, &lt;a href="https://iank.org/media/frogsboro_bom_v1.0.2.pdf">BOM (pdf)&lt;/a>, &lt;a href="https://iank.org/media/frogsboro_gbr_v1.0.2.zip">Gerbers (zip)&lt;/a>&lt;/p>
&lt;p>&lt;strong>Update 2022-04-17&lt;/strong>: Added a section on the stencil alignment fixture.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_top_complete.jpg" alt="The board measures 67mm by 21mm, has a mini USB-B connector sticking out over one end and two vertical USB-A connectors on the other." width="600" height="319">
&lt;figcaption>
Completed PCB, top view.&lt;/figcaption>
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_bottom_complete_side.jpg" alt="There is a microSD card connector on one end and a 40-pin low-profile board-to-board connector nearby." width="600" height="293">
&lt;figcaption>
Completed PCB, bottom view.&lt;/figcaption>
&lt;/figure>
&lt;h2 id="layout">Layout&lt;/h2>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_layout.png" alt="A screenshot of some of the gerber layers superimposed upon each other." width="600" height="236">
&lt;/figure>
&lt;p>I used a six layer stackup from a low-cost fab. It measures 67mm by 21mm. A MIC2800 PMIC provides the three necessary voltage rails. An oscillator and a crystal provide the core clocks, there&amp;rsquo;s a DDR voltage reference, and the various connectors have ESD protection. (This is the first spin of the board; the 1.0.2 version number reflects some back and forth with the fab). The total cost for PCBs, stencils, and components was around $200.&lt;/p>
&lt;h2 id="assembly">Assembly&lt;/h2>
&lt;h3 id="stencil-alignment-fixture">Stencil Alignment Fixture&lt;/h3>
&lt;p>I&amp;rsquo;m experimenting with a new alignment fixture for applying paste. In the past I&amp;rsquo;ve used scrap PCBs to frame the board and a masking tape hinge on one edge of the stencil &lt;a href="https://www.youtube.com/watch?v=uXvXwzQf1gU">(Video from JLCPCB&lt;/a>, &lt;a href="https://www.sparkfun.com/tutorials/58">Tutorial from Sparkfun&lt;/a>). This has worked well enough for me. It takes some time to line everything up and tape it down, but once set up it&amp;rsquo;s surprisingly repeatable. It&amp;rsquo;s stressful to set up for just a few boards though, and double-sided assembly is a pain since the setup needs to be elevated to apply paste to the second side.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_blank.jpg" alt="Two blank PCBs side-by-side. The PCBs have rails on either side that are attached by thin tabs. The tabs have mouse bites drilled into them and can be broken away." width="600" height="566">
&lt;figcaption>
The bare PCBs (top and bottom), with the breakaway rails still attached.&lt;/figcaption>
&lt;/figure>
&lt;p>On this board I added breakaway rails with mouse bites&lt;sup id="fnref:1">&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref">1&lt;/a>&lt;/sup>. The rails each contain two stencil alignment holes, which are just a non-plated through hole and a corresponding footprint on the paste layer. Since it&amp;rsquo;s not typical&lt;sup id="fnref:2">&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref">2&lt;/a>&lt;/sup> to have paste over holes I included a note to the fab to clarify that this was intentional. I then milled a fixture from a block of common pine.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_stencil_fixture_crosssection.png" alt="Top: Stencil alignment fixture, milled from a block of pine. It has a recess for the board, cavities for components, and alignment holes. Inset left: Stencil alignment cross section in CAD program, showing the board (w/ top side components already assembled) sitting flush with the surface of the stencil fixture. Inset right: Screenshot of toolpaths from CAM program." width="600" height="313">
&lt;figcaption>
Stencil alignment figure&lt;/figcaption>
&lt;/figure>
&lt;p>The board sits in a recess so that the surface is flush with the wood, the stencil can sit on top of both, and gauge pins are used to fix everything in place. There is also a cavity to allow clearance for the top side components when applying paste to the bottom side.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_fixture_paste_application.jpg" alt="Top: Stencil alignment fixture with board, stencil, and gauge pins inserted. Paste has been wiped across the stencil. Bottom: Stencil and gauge pins have been removed, revealing the board sitting in the fixture with paste applied." width="600" height="567">
&lt;figcaption>
Paste application&lt;/figcaption>
&lt;/figure>
&lt;p>There&amp;rsquo;s obviously a different sort of setup time involved in the CAD/CAM and milling the fixture. In the end though it was pleasant to use, the alignment felt solid, and the resulting paste application was crisp and consistent. I won&amp;rsquo;t use this for every board, but for double-sided boards and/or boards with small feature sizes it&amp;rsquo;s a nice tool to have.&lt;/p>
&lt;h3 id="component-placement-and-reflow">Component Placement and Reflow&lt;/h3>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_top_ics_placed.jpg" alt="The PCB clamped onto a preheater, with some integrated circuits placed." width="600" height="450">
&lt;figcaption>
IC placement&lt;/figcaption>
&lt;/figure>
&lt;p>Once paste was applied I used my normal method for assembly. I use my preheater (turned off) to clamp the board while I place components..&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_top_reflowed.jpg" alt="The board (top view) with all of the top components placed and reflowed." width="600" height="388">
&lt;figcaption>
Top after reflow&lt;/figcaption>
&lt;/figure>
&lt;p>&amp;hellip; and then reflow with the preheater around &amp;ldquo;300°C&amp;rdquo;&lt;sup id="fnref:3">&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref">3&lt;/a>&lt;/sup> and very low flow rate hot air at 350°C.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/frogsboro_bottom_reflowed.jpg" alt="The board (bottom view) with all of the bottom components placed and reflowed." width="600" height="361">
&lt;figcaption>
Bottom after reflow&lt;/figcaption>
&lt;/figure>
&lt;p>For the bottom side, I keep the preheater lower (&amp;ldquo;100°C&amp;rdquo;) and use the same hot air settings. Through hole parts are the final step. They need thermal relief as I don&amp;rsquo;t have the board preheated when soldering these.&lt;/p>
&lt;h2 id="software">Software&lt;/h2>
&lt;p>&lt;img src="https://iank.org/media/frogsboro_console.png" alt="A screenshot of a terminal running minicom. It&amp;rsquo;s showing a serial console to the FROGSBORO board, and the output of uname -a and /proc/cpuinfo" title="FROGSBORO serial console">&lt;/p>
&lt;p>I didn&amp;rsquo;t have to do much here. I was able to boot &lt;a href="https://www.linux4sam.org/bin/view/Linux4SAM/Sam9x60EKMainPage#Demo_archives">a demo image form the sam9x60-ek evaluation kit&lt;/a>. I used linux4sam-buildroot-sam9x60ek-headless-2021.10.img. The device tree should ideally be modified to remove peripherals that aren&amp;rsquo;t present (e.g., Ethernet), but leaving it as-is doesn&amp;rsquo;t cause a problem.&lt;/p>
&lt;p>I used an FTDI cable to access the UART for first boot. I then modified the inittab to load &lt;a href="https://www.kernel.org/doc/Documentation/usb/gadget_serial.txt">g_serial&lt;/a> and start getty on ttyGS0. This lets me use the SAM9X60 USB device port, which is also powering the device, as a serial console.&lt;/p>
&lt;p>&lt;strong>Update 2022-11-10&lt;/strong>: I&amp;rsquo;ve since built a &lt;a href="https://github.com/iank/meta-frogsboro">yocto layer&lt;/a> for this board. See &lt;a href="https://github.com/iank/frogsboro-firmware">frogsboro-firmware&lt;/a>&lt;/p>
&lt;h2 id="thoughts">Thoughts&lt;/h2>
&lt;ul>
&lt;li>This was my first six layer board. The extra routing layers were nice, but in this case less useful than they could be. At this budget I&amp;rsquo;m stuck with (relatively large) through vias meaning some areas can quickly become Swiss cheese on every layer.&lt;/li>
&lt;li>I like this PMIC. Absolutely happy to use one part to provide all of the voltage rails when I can get away with it.&lt;/li>
&lt;li>The fab I use has a coarse silkscreen print resolution. This isn&amp;rsquo;t the first board where I&amp;rsquo;ve had to delete some reference designators to make others fit. But the resulting silkscreen is still crowded to the point of ambiguity. I may start leaving designators off for most passives by default and only including the ones that I think may be frequently referenced.&lt;/li>
&lt;li>In the future it would be better to place the mouse bites recessed back from the board edge so that the broken-off pieces don&amp;rsquo;t protrude.&lt;/li>
&lt;/ul>
&lt;div class="footnotes" role="doc-endnotes">
&lt;hr>
&lt;ol>
&lt;li id="fn:1">
&lt;p>I used 0.5mm diameter non-plated holes, with 0.75mm from center to center and 0.5mm clearance from the outside hole edges to board edge. There is no copper on any layer on the rails.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;li id="fn:2">
&lt;p>Aside from &lt;a href="https://www.airborn.com/resources/connector-encyclopedia/paste-in-hole">paste-in-hole&lt;/a>, which I think is still fairly uncommon.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;li id="fn:3">
&lt;p>This and other temperature settings I&amp;rsquo;ll mention for this preheater only loosely correspond to the actual temperature the board reaches. It&amp;rsquo;s an IR heating element an inch or so underneath the board and the control system, such as it is, controls the element temperature, not a temperature probe on the board.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;/ol>
&lt;/div>
- https://iank.org/posts/frogsboro-embedded-linux-board-sam9x60-sip/ - 2014-2024 iank.org</description></item><item><title>A Custom i.MX6ULL Board</title><link>https://iank.org/posts/catfood-custom-imx6ull-board/</link><pubDate>Tue, 28 Dec 2021 02:25:16 +0000</pubDate><guid>https://iank.org/posts/catfood-custom-imx6ull-board/</guid><description>iank.org https://iank.org/posts/catfood-custom-imx6ull-board/ -&lt;p>As a vehicle for learning OrCAD, I built a custom embedded Linux board using NXP&amp;rsquo;s i.MX6ULL processor. The board is called CATFOOD (I was more excited to get started than I was to come up with a name). It has the i.MX6, DDR3, NAND flash, an Ethernet PHY, and an SD card. It presents a serial console over the USB-C connector, which also supplies power.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/catfood-custom-imx6ull-board/catfood_layout.png" alt="CATFOOD layout screenshot" width="600" height="600">
&lt;figcaption>
Layout&lt;/figcaption>
&lt;/figure>
&lt;p>This was my first embedded Linux design, as well as my first design incorporating DDR or Ethernet. The design is heavily based on NXP&amp;rsquo;s reference implementation. I also used Seeed Studio&amp;rsquo;s i.MX6 module as a reference (it is itself a stripped-down version of the NXP design).&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/catfood-custom-imx6ull-board/catfood_paste.jpg" alt="Half-populated CATFOOD" width="600" height="450">
&lt;figcaption>
A half-populated PCB.&lt;/figcaption>
&lt;/figure>
&lt;p>I had the 4-layer board and a stencil manufactured using a low-cost PCB prototyping service and assembled it at home.&lt;/p>
&lt;h2 id="issuesbring-up">Issues/Bring-up&lt;/h2>
&lt;h3 id="ddr">DDR&lt;/h3>
&lt;p>There was at first an issue booting. I traced this down to a problem with the DDR by interrogating the device over the built-in USB bootloader. See &lt;a href="https://github.com/boundarydevices/imx_usb_loader">https://github.com/boundarydevices/imx_usb_loader&lt;/a> as well as NXP&amp;rsquo;s DDR calibration tool. After checking the DDR voltage reference and a few clock termination passives I reflowed the memory chip, which solved the issue. If I had to guess (and I do, because I don&amp;rsquo;t have an X-ray machine), I didn&amp;rsquo;t get enough heat on that part the first time I reflowed it.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/catfood-custom-imx6ull-board/catfood_assembled.jpg" alt="Assembled PCB" width="600" height="427">
&lt;figcaption>
Assembled PCB&lt;/figcaption>
&lt;/figure>
&lt;h3 id="ethernet">Ethernet&lt;/h3>
&lt;p>There were a few driver problems with the Ethernet. This particular part (LAN8700) was my most significant deviation from the reference schematic so it&amp;rsquo;s no surprise that the board init and device tree needed some modifications.&lt;/p>
&lt;ul>
&lt;li>I needed to have u-boot reset the PHY (using the reset GPIO) early in the board initialization. I also set up the ENET clock (provided by the i.MX6 to the LAN8700) in the board init.&lt;/li>
&lt;li>The reference device tree has two ENET modules, with the (shared) MDIO bus configured in the second. This is usually fine even when only one is used, but the part I used has the second ENET module disabled via fuse&lt;sup id="fnref:1">&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref">1&lt;/a>&lt;/sup>.&lt;/li>
&lt;li>I removed the tempmon node in the device tree. It doesn&amp;rsquo;t exist in my part and so Linux kept attempting to do deferred probes of this device. I&amp;rsquo;m still not clear on why, but the first attempted tempmon probe after Linux initializes the PHY would cause a hang.&lt;/li>
&lt;/ul>
&lt;p>Finally, I &lt;a href="https://www.hellion.org.uk/cgi-bin/randmac.pl?scope=local&amp;amp;type=unicast">generated&lt;/a> a valid (unicast, locally-administered) MAC address and burned it into the fuses using u-boot:&lt;/p>
&lt;pre tabindex="0">&lt;code># This programs ENET1 MAC address: F6:07:37:F1:EC:7a
fuse prog 4 3 0xf607
fuse prog 4 2 0x37f1ec7a
&lt;/code>&lt;/pre>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/catfood-custom-imx6ull-board/catfood_ping.jpg" alt="Photo of a monitor with a running CATFOOD in the foreground. The monitor shows a working ping to iank.org" width="600" height="800">
&lt;figcaption>
Working Ethernet&lt;/figcaption>
&lt;/figure>
&lt;h2 id="lessons-learned">Lessons Learned&lt;/h2>
&lt;p>I&amp;rsquo;m happy with the way this came out. It incorporated a lot of new elements for me and they all ended up working. Some disorganized thoughts:&lt;/p>
&lt;ul>
&lt;li>I&amp;rsquo;m stressing the limits of my usual paste stencil alignment method (scrap boards and masking tape). Next time I&amp;rsquo;m going to try putting some alignment holes in the board and stencil.&lt;/li>
&lt;li>The reference design includes a large number of pull-up/down resistors for configuring bootstrap pins. I kept these on my board, knowing they were unnecessary but maybe useful. After learning a bit about the platform I shouldn&amp;rsquo;t need to include them again. All that&amp;rsquo;s needed is access to a couple of the BOOT_MODE pins, combined with the default behavior and the built-in USB loader.&lt;/li>
&lt;li>There&amp;rsquo;s some other elements of NXP&amp;rsquo;s design, mostly around power and reset, that I think I understand well enough now to simplify or drop.&lt;/li>
&lt;li>This was the first time I did stencil paste application / hot air reflow on both sides of the board, and I was worried about either having components fall off or not preheating the board/ground planes enough and having tombstoning. I set my preheater to &amp;ldquo;100C&amp;rdquo; and didn&amp;rsquo;t have any issues.&lt;/li>
&lt;li>When placing small passives I should give them a little tap (into the paste) and use a wide nozzle from relatively far to prevent parts from blowing away.&lt;/li>
&lt;li>I designed a 3d-printed enclosure, which I don&amp;rsquo;t typically do. I need to pay more attention to connector stickout past the board edge.&lt;/li>
&lt;/ul>
&lt;div class="footnotes" role="doc-endnotes">
&lt;hr>
&lt;ol>
&lt;li id="fn:1">
&lt;p>Both ENET modules have instances of the MDIO registers, and it normally doesn&amp;rsquo;t matter which ENET is used to access the bus. But with ENET2 fused, accessing the MDIO registers from that module hung the device.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;/ol>
&lt;/div>
- https://iank.org/posts/catfood-custom-imx6ull-board/ - 2014-2024 iank.org</description></item><item><title>Cyclone IV-based Julia Set Explorer</title><link>https://iank.org/posts/cyclone-iv-julia-set-explorer/</link><pubDate>Mon, 27 Dec 2021 01:09:54 +0000</pubDate><guid>https://iank.org/posts/cyclone-iv-julia-set-explorer/</guid><description>iank.org https://iank.org/posts/cyclone-iv-julia-set-explorer/ -&lt;p>A custom Cyclone IV board interfaces with TFT LCD panel, capacitive touch controller, SDR SDRAM. The FPGA superimposes a Julia set on the Mandelbrot set. Touching the screen chooses the set point z0.&lt;/p>
&lt;p>Check out &lt;a href="http://www.malinc.se/m/JuliaSets.php">Malin Christersson&amp;rsquo;s julia set visualizations here&lt;/a>. This is basically an implementation of the first demo on that page. One thing that should be clear is that there&amp;rsquo;s no need for an FPGA to do this; it&amp;rsquo;s in fact exactly the wrong approach. This project was a solution in search of a problem: I started with a Cyclone II and an LCD with no application in mind and it evolved from there. I got to use it as a vehicle to learn about FPGAs, verilog, and push my PCB layout and assembly capabilities.&lt;/p>
&lt;p>All of the design files can be found on github at &lt;a href="https://github.com/iank/julia_lcd">https://github.com/iank/julia_lcd&lt;/a>.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/cyclone-iv-julia-set-explorer/julia_finished.jpg" alt="Julia finished assembly" width="600" height="800">
&lt;figcaption>
The final assembly&lt;/figcaption>
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/cyclone-iv-julia-set-explorer/julia_example.jpg" alt="Julia example image" width="600" height="450">
&lt;figcaption>
An example Julia set&lt;/figcaption>
&lt;/figure>
&lt;h2 id="hardware">Hardware&lt;/h2>
&lt;p>The final evolution of the hardware is a Cyclone IV FPGA, an external SDRAM, and a Silicon Labs EFM8 microcontroller used to configure the FPGA from a SPI flash. The LCD module contains a capacitive touch controller, broken out on the second, smaller, flex cable.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/cyclone-iv-julia-set-explorer/julia_v2.1.1.0-Board.png" alt="A screenshot of KiCAD showing the PCB layout. The top and bottom layers are visible, along with the silkscreens and some other borders/layout markings." width="600" height="455">
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/cyclone-iv-julia-set-explorer/julia_v2.1.1.0_3DTop.png" alt="A 3D render of the Julia PCB." width="600" height="435">
&lt;/figure>
&lt;h2 id="verilog">Verilog&lt;/h2>
&lt;p>The FPGA&amp;rsquo;s internal blockrams are not large enough to contain an entire frame, hence the external memory. Lines are loaded from memory during the blanking interval before they are needed. Otherwise when the memory bus is not in use the fractal can be computed. First the Mandelbrot set is computed as a binary image and the Julia set is overlaid upon it.&lt;/p>
&lt;p>An i2c master is also implemented. This controls the touch screen. Upon receipt of a touchscreen interrupt, the coordinate is queried and this is used to set the z0 point for the Julia set.&lt;/p>
&lt;h2 id="lessons-learned">Lessons learned&lt;/h2>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/cyclone-iv-julia-set-explorer/julia_debugging.jpg" alt="A picture of the board with a debug board attached to an altera programmer. There&amp;#39;s also a USB logic analyzer connected to some hands-free probes, which are probing the touchscreen connector." width="600" height="450">
&lt;/figure>
&lt;p>I&amp;rsquo;d never used an FPGA before this project. I spent a lot of time iterating on the Verilog here, and I learned a lot about what I could and could not do (as well as the memory bandwidth / LUTs I&amp;rsquo;d need to do it). This was also the first time I assembled a BGA part at home.&lt;/p>
&lt;p>Using a separate debug/programming board was handy. In one spin I had tried using a board-to-board connector for this, which turned out to not be tenable without mechanical support. The IPC cable pictured above was easier to assemble and didn&amp;rsquo;t really take up more space.&lt;/p>
&lt;p>FPGA debugging in-system is hard. Taking the time to set up simulation models/fixtures was worth it every time. First I wrote a mock LCD module that would output frames as png files during the simulation. That made clear some timing/alignment issues that just weren&amp;rsquo;t visible otherwise. Then I adapted a memory model from Micron for the specific part I used, which helped debug some memory issues.&lt;/p>
- https://iank.org/posts/cyclone-iv-julia-set-explorer/ - 2014-2024 iank.org</description></item><item><title>Using radare2 to make a simple binary patch</title><link>https://iank.org/posts/using-radare2-to-make-a-simple-binary-patch/</link><pubDate>Fri, 27 Dec 2019 14:30:00 +0000</pubDate><guid>https://iank.org/posts/using-radare2-to-make-a-simple-binary-patch/</guid><description>iank.org https://iank.org/posts/using-radare2-to-make-a-simple-binary-patch/ -&lt;p>My partner found a game on her computer that she probably downloaded a decade ago, and we wanted to tweak the behaviour.&lt;/p>
&lt;p>In case it&amp;rsquo;s not clear, the following is outrageous and the right way to do this would have been to edit the freely-available C++ source code and rebuild the game, either on my partner&amp;rsquo;s Macbook or cross-compiled from my Linux laptop. But I didn&amp;rsquo;t want to interrupt her. And while the build system for this game is actually fairly straightforward, I have 36 megabytes free on my aging Chromebook. No room for an OS X toolchain. In the end, I think this saved everyone precious block-clicking time and it was certainly more fun.&lt;/p>
&lt;p>The first step was to identify the game, which seemed like the product of an SDK tutorial or a tech demo. In fact it was the &amp;ldquo;blocks&amp;rdquo; test app for &lt;a href="https://www.fltk.org/doc-1.3/examples.html#examples_blocks">FLTK&lt;/a>. The &lt;a href="https://github.com/fltk/fltk/blob/release-1.1.10/test/blocks.cxx">source code&lt;/a> is straightforward and short, and the change we wanted to make was in the level up progression. Each level adds a new level of complexity and also speeds the game up; we wanted to keep adding complexity without speeding up the game.&lt;/p>
&lt;p>Here is the relevant function:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-c++" data-lang="c++">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">void&lt;/span> BlockWindow&lt;span style="color:#f92672">::&lt;/span>up_level() {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> interval_ &lt;span style="color:#f92672">*=&lt;/span> &lt;span style="color:#ae81ff">0.95&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> opened_columns_ &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#ae81ff">0&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (num_colors_ &lt;span style="color:#f92672">&amp;lt;&lt;/span> &lt;span style="color:#ae81ff">7&lt;/span>) num_colors_ &lt;span style="color:#f92672">++&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> level_ &lt;span style="color:#f92672">++&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> sprintf(title_, &lt;span style="color:#e6db74">&amp;#34;Level: %d&amp;#34;&lt;/span>, level_);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> title_y_ &lt;span style="color:#f92672">=&lt;/span> h();
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> Fl&lt;span style="color:#f92672">::&lt;/span>repeat_timeout(interval_, (Fl_Timeout_Handler)timeout_cb, (&lt;span style="color:#66d9ef">void&lt;/span> &lt;span style="color:#f92672">*&lt;/span>)&lt;span style="color:#66d9ef">this&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>All we need to do is delete the code that changes &lt;code>interval_&lt;/code> or change the &lt;code>0.95&lt;/code> constant to &lt;code>1&lt;/code>. It&amp;rsquo;s been a while since I&amp;rsquo;ve had access to IDA Pro, so it&amp;rsquo;s time for me to learn a new tool, &lt;a href="https://rada.re/">radare2&lt;/a>.&lt;/p>
&lt;p>So, we open the binary, analyze it, and list functions:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-txt" data-lang="txt">&lt;span style="display:flex;">&lt;span>ian@chrx:~/Downloads/blocks.app/Contents/MacOS$ radare2 blocks
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>[0x100004af0]&amp;gt; aaa
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>[0x100004af0]&amp;gt; afl
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x100005df6 627 8 fcn.100005df6
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x100009a6c 19 1 fcn.100009a6c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x10000606a 139 3 sym.__ZN11BlockWindow8up_levelEv
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x100005750 337 3 sym.__ZN11BlockWindow5clickEii
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x100005796 14 15 fcn.10000579a
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x1000057a4 253 12 fcn.1000057a4
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>...
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Great. It&amp;rsquo;s not stripped. With some searching, we find the symbol we&amp;rsquo;re looking for. &lt;code>BlockWindow::up_level&lt;/code> has become &lt;code>__ZN11BlockWindow8up_levelEv&lt;/code> due to &lt;a href="https://en.wikipedia.org/wiki/Name_mangling#C++">C++ name mangling&lt;/a>. We can seek to it and print the disassembly:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-txt" data-lang="txt">&lt;span style="display:flex;">&lt;span>[0x100004af0]&amp;gt; s sym.__ZN11BlockWindow8up_levelEv
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>[0x10000606a]&amp;gt; pdf
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; CODE (CALL) XREF from 0x100005f50 (fcn.1000058c0)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; CODE (CALL) XREF from 0x1000054e6 (fcn.1000050dc)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> ; BlockWindow::up_level()
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>/ (fcn) sym.__ZN11BlockWindow8up_levelEv 139
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000606a 55 push rbp
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000606b 4889e5 mov rbp, rsp
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000606e 53 push rbx
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000606f 50 push rax
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006070 4889fb mov rbx, rdi
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006073 f30f5a83100. cvtss2sd xmm0, [rbx+0xb10]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000607b f20f59050d1. mulsd xmm0, [rip+0x4180d]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006083 f20f5ac0 cvtsd2ss xmm0, xmm0
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006087 f30f1183100. movss [rbx+0xb10], xmm0
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000608f c7831c0b000. mov dword [rbx+0xb1c], 0x0
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006099 8b83180b0000 mov eax, [rbx+0xb18]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000609f 83f806 cmp eax, 0x6
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ,=&amp;lt; 0x1000060a2 7f08 jg 0x1000060ac
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| | 0x1000060a4 ffc0 inc eax
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| | 0x1000060a6 8983180b0000 mov [rbx+0xb18], eax
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| `-&amp;gt; 0x1000060ac 8b93140b0000 mov edx, [rbx+0xb14]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060b2 ffc2 inc edx
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060b4 8993140b0000 mov [rbx+0xb14], edx
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060ba 488dbb300b0. lea rdi, [rbx+0xb30]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; CODE (CALL) XREF from 0x100009a7d (fcn.100009a7d)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; DATA XREF from 0x100009a7d (fcn.100009a7d)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060c1 488d35b5390. lea rsi, [rip+0x439b5] ; 0x100009a7d
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060c8 31c0 xor eax, eax
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060ca e87f0b0400 call sym.imp.sprintf
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| sym.imp.sprintf(unk, unk, unk)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060cf 8b432c mov eax, [rbx+0x2c]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060d2 8983300c0000 mov [rbx+0xc30], eax
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060d8 f30f5a83100. cvtss2sd xmm0, [rbx+0xb10]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; CODE (CALL) XREF from 0x1000150dc (fcn.1000150dc)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; CODE (CALL) XREF from 0x100015159 (fcn.100015159)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; CODE (CALL) XREF from 0x100015117 (fcn.100015117)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| ; DATA XREF from 0x1000150dc (fcn.1000150dc)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060e0 488d3df5eff. lea rdi, [rip-0x100b] ; 0x1000150dc
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060e7 4889de mov rsi, rbx
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060ea 4883c408 add rsp, 0x8
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060ee 5b pop rbx
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x1000060ef 5d pop rbp
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>\ 0x1000060f0 e94f1e0000 jmp sym.__ZN2Fl14repeat_timeoutEdPFvPvES0_
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>These are the lines in question. They&amp;rsquo;re relatively easy to pick out since we&amp;rsquo;re interested in a floating point operation:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-txt" data-lang="txt">&lt;span style="display:flex;">&lt;span>| 0x100006073 f30f5a83100. cvtss2sd xmm0, [rbx+0xb10]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x10000607b f20f59050d1. mulsd xmm0, [rip+0x4180d]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006083 f20f5ac0 cvtsd2ss xmm0, xmm0
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>| 0x100006087 f30f1183100. movss [rbx+0xb10], xmm0
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Remember, we&amp;rsquo;re looking for assembly code corresponding to &lt;code>interval_ *= 0.95&lt;/code>. This fits. We:&lt;/p>
&lt;ul>
&lt;li>load &lt;code>interval_&lt;/code> (from the address &lt;code>rbx+0xb10&lt;/code>)&lt;/li>
&lt;li>multiply by a constant (at &lt;code>rip+0x4180d&lt;/code>)&lt;/li>
&lt;li>and store the result back in &lt;code>rbx+0xb10&lt;/code>&lt;/li>
&lt;/ul>
&lt;p>To make sure, we can check the value of the constant in &lt;code>[rip+0x4180d]&lt;/code>. It should be &lt;code>0.95&lt;/code>. We know it&amp;rsquo;s an argument to mulsd, so we&amp;rsquo;re looking for a &lt;a href="https://en.wikipedia.org/wiki/Double-precision_floating-point_format#IEEE_754_double-precision_binary_floating-point_format:_binary64">double&lt;/a>. Recall &lt;code>rip&lt;/code> points to the next instruction to be executed, so:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-txt" data-lang="txt">&lt;span style="display:flex;">&lt;span>[0x10000606a]&amp;gt; pf q @ 0x100006083+0x4180d
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>0x100047890 = (qword) 0x3fee666666666666
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>And indeed, if we &lt;a href="https://binaryconvert.com/result_double.html?hexadecimal=3FEE666666666666">convert it to decimal&lt;/a>, we get &lt;code>0.9499999...&lt;/code>.&lt;/p>
&lt;p>Now all we need to do is find this code in the binary and &lt;a href="https://www.felixcloutier.com/x86/nop">NOP&lt;/a> it out. It&amp;rsquo;s easy enough to search for the corresponding machine code in a hex editor since radare&amp;rsquo;s disassembler has provided it alongside the assembly, and replace that section with &lt;code>0x90&lt;/code>s.&lt;/p>
&lt;p>Radare2 is a cool tool, though, and there&amp;rsquo;s ways to do the patching entirely within the tool. &lt;a href="https://monosource.gitbooks.io/radare2-explorations/content/tut1/tut1_-_simple_patch.html">This tutorial&lt;/a> has an example.&lt;/p>
- https://iank.org/posts/using-radare2-to-make-a-simple-binary-patch/ - 2014-2024 iank.org</description></item><item><title>Mul-T-Lock Interactive Picked</title><link>https://iank.org/posts/mul-t-lock-interactive-picked/</link><pubDate>Thu, 21 Mar 2019 19:59:00 +0000</pubDate><guid>https://iank.org/posts/mul-t-lock-interactive-picked/</guid><description>iank.org https://iank.org/posts/mul-t-lock-interactive-picked/ -
&lt;figure class="image">
&lt;img src="https://iank.org/posts/mul-t-lock-interactive-picked/multlock_picked.jpg" alt="Photo of a Mul-T-Lock Interactive in a vise with a tension wrench hanging out of the keyway. The keyway has been rotated, showing that it has been picked." width="600" height="450">
&lt;/figure>
&lt;p>The other day I picked a &lt;a href="http://www.lockwiki.com/index.php/Mul-T-Lock_Interactive">Mul-T-Lock Interactive&lt;/a> key-in-knob cylinder that a locksmith gave me from his scrap bucket. That feels like an accomplishment to me, hence this otherwise empty post. This morning I repeated the process on video, which took about half an hour.&lt;/p>
&lt;p>I have one thought to contribute: the interactive element intimidated me when I first learned about it, but I realize now it is mostly a key control feature as it does not substantially impact picking (vs a Mul-T-Lock classic).&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/mul-t-lock-interactive-picked/multlock_guts.jpg" alt="Photo of a disassembled Mul-T-Lock Interactive." width="600" height="450">
&lt;/figure>
- https://iank.org/posts/mul-t-lock-interactive-picked/ - 2014-2024 iank.org</description></item><item><title>"I PRESSED CAPS LOCK ONCE IN 1989 AND I NEVER LOOKED BACK"</title><link>https://iank.org/posts/i-pressed-caps-lock-once-in-1989/</link><pubDate>Mon, 29 Dec 2014 19:05:00 +0000</pubDate><guid>https://iank.org/posts/i-pressed-caps-lock-once-in-1989/</guid><description>iank.org https://iank.org/posts/i-pressed-caps-lock-once-in-1989/ -&lt;p>It&amp;rsquo;s a widely reported phenomenon that the most popular or well-received thing a person creates is rarely the thing they are most proud of. Sometimes they grow to resent its overshadowing their more challenging or interesting output. Radiohead reportedly hates &lt;em>Creep&lt;/em>.&lt;/p>
&lt;p>&lt;a href="http://www.ursulavernon.com/">Ursula Vernon&lt;/a> is a Hugo award-winning writer and illustrator, but when I was a teen I went to a book signing to get her autograph on &lt;a href="http://ursulav.deviantart.com/art/The-Biting-Pear-of-Salamanca-29677500">this picture of a pear&lt;/a>, which you&amp;rsquo;ll recognize if you grew up on the internet at a certain time.&lt;/p>
&lt;h3 id="my-pear-is-an-irc-robot-called-loudbot">My pear is an IRC robot called LOUDBOT&lt;/h3>
&lt;p>LOUDBOT was born at least five years ago. I was mourning the disappearance of an internet friend, who I&amp;rsquo;ll call R. We&amp;rsquo;d spend entire days engaged in friendly but vitriolic arguments about his particular brand of stoner socialism or i-can&amp;rsquo;t-even-remember-what, until he vanished, as internet people do.&lt;/p>
&lt;p>Like &amp;ldquo;real&amp;rdquo; people you lose touch for a variety of reasons, benign or tragic, and often you never know. It&amp;rsquo;s cliché but true to remember that there is aways attrition and that change can&amp;rsquo;t and shouldn&amp;rsquo;t be avoided. I&amp;rsquo;ve got to experience the relationships I have now and form new ones, while acknowledging the people who exist only in the past.&lt;/p>
&lt;p>I processed R.&amp;rsquo;s disappearance in my own way by writing a robot to replace him. The bot went through my logs collecting every all-caps thing this guy had ever shouted at us, and when a user yelled it would yell back some mock-furious decontextualized incoherent epiphany or insult, like &amp;ldquo;IDEAS FLOW FREE WHEN TIME IS INCORRECT!&amp;rdquo;&lt;/p>
&lt;h3 id="loudbot-got-bigger-than-me">LOUDBOT got bigger than me&lt;/h3>
&lt;p>It was a simple Perl script, one hundred lines at most, and eventually I generalized it to repeat things that anyone had shouted in the presence of the robot. Anything shouted in all caps would be met with a random all-caps reply.&lt;/p>
&lt;p>I started a &lt;a href="https://twitter.com/LOUDBOT">twitter account for the robot&lt;/a>. Anyone on IRC could tell LOUDBOT to tweet the last thing it shouted. It &lt;a href="loudbot_capscop.png">got into fights&lt;/a> with other twitter bots&lt;sup id="fnref:1">&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref">1&lt;/a>&lt;/sup>. It &lt;a href="loudbot_intel.png">#engaged&lt;/a> with &lt;a href="loudbot_twc.png">#brands&lt;/a>. While never particularly popular (it hovers at about 900 followers), it grew beyond my tiny corner of the internet. I had a surreal moment when I met someone in &amp;ldquo;real life&amp;rdquo; who followed LOUDBOT on twitter before she knew me.&lt;/p>
&lt;p>The Perl script was written and re-written, overengineered, factored, and re-overengineered. It was a vehicle for me to play with NoSQL at the height of that movement (some versions were &lt;a href="https://www.youtube.com/watch?v=b2F-DItXtZs">web-scale&lt;/a>). It&amp;rsquo;s integrated with my distributed swarm of self-managing IRC robots. Now it&amp;rsquo;s over 1500 lines of asynchronous message-passing highly-available &lt;a href="http://www.erlang.org/doc/design_principles/users_guide.html">OTP&lt;/a> Erlang and Perl. I&amp;rsquo;ve forgotten everything there is to know about the code, but the nature of Erlang is that the thing has kept running for the last two years with no real maintenance or input from me. I call it &amp;ldquo;telecom-scale.&amp;rdquo;&lt;/p>
&lt;h3 id="sometimes-its-kind-of-the-worst">Sometimes it&amp;rsquo;s kind of the worst&lt;/h3>
&lt;p>Some of the quotes are stolen from other sources. There are political opinions and tasteless jokes. It is foul-mouthed and occasionally racist and awful. I&amp;rsquo;ll delete the worst of it when I see it (as will others; anyone has this power), but the &amp;ldquo;loud database&amp;rdquo; is a product of the input of the users, and the users are &lt;a href="http://www.penny-arcade.com/comic/2004/03/19">from the internet&lt;/a>.&lt;/p>
&lt;p>But it sometimes reflects the creative humour of the nerds I enjoy spending time with, and the random responses are occasionally brilliant.&lt;/p>
&lt;blockquote>
&lt;p>&amp;lt; HighBit&amp;gt; THERE IS NOTHING MORE DANGEROUS THAN A HIGH-POWERED POLITICIAN ARMED WITH A TWITTER&lt;br>
&amp;lt; LOUDBOT_&amp;gt; THE INTERNET ISN’T PRIVATE? OH SHIT.&lt;/p>
&lt;/blockquote>
&lt;blockquote>
&lt;p>&amp;lt; HighBit&amp;gt; I ONLY EAT DRY FOOD FROM A BAG&lt;br>
&amp;lt; LOUDBOT&amp;gt; YOU HAVE THE POWER TO CHANGE THAT&lt;/p>
&lt;/blockquote>
&lt;p>There is a small but devoted following. They spawned a mock religion. Some people insist it&amp;rsquo;s sentient, maybe &lt;a href="http://en.wikipedia.org/wiki/Skynet_%28Terminator%29">Skynet&lt;/a>, or that I have developed a secret algorithm for keeping LOUDBOT &amp;ldquo;on-topic&amp;rdquo;. It&amp;rsquo;s just a random select from a &lt;a href="http://www.sqlite.org/">SQLite&lt;/a> database.&lt;/p>
&lt;blockquote>
&lt;p>&amp;lt; LOUDBOT&amp;gt; IsharaComix: BACONIZED RESISTENCE&lt;br>
&amp;lt; IsharaComix&amp;gt; YOU SPELLED RESISTANCE WRONG&lt;br>
&amp;lt; LOUDBOT&amp;gt; I REQUIRE EPIC RUBY DRMAA&lt;br>
&amp;lt; IsharaComix&amp;gt; YOU SPELLED DRAMA WRONG&lt;br>
&amp;lt; LOUDBOT&amp;gt; EVERYTHING MUST BE IN ALL CAPS ALL THE TIME OR ELSE NO ONE WILL LOSTEN TO YOU&lt;br>
&amp;lt; IsharaComix&amp;gt; YOU SPELLED LISTEN WRONG GOD LOUDBOT YOURE BAD AT THIS&lt;br>
&amp;lt; LOUDBOT&amp;gt; THIS UNCHECKED AGRESSION WILL NOT STAND&lt;/p>
&lt;/blockquote>
&lt;p>Over time, people grew accustomed to LOUDBOT&amp;rsquo;s presence and the nature of their interactions with it changed. They didn&amp;rsquo;t so much shout at each other anymore, they shouted for the robot to hear, record, and repeat later. The database grew to over 70,000 lines. This was different, and not what I had imagined it would become, but users and systems evolve as they interact with each other. That&amp;rsquo;s neither right nor wrong, it&amp;rsquo;s true and inevitable and interesting.&lt;/p>
&lt;h3 id="like-the-person-it-was-initially-created-to-replace-robots-vanish-too">Like the person it was initially created to replace, robots vanish too.&lt;/h3>
&lt;p>Our relationships with robots and systems, like people, are temporary. Trying to hang on to the way things were at the height of a friendship is impossible at best. It&amp;rsquo;s been fun, but this system is stagnant, we&amp;rsquo;ve grown apart, and we&amp;rsquo;re on to the getting-together-for-an-awkward-lunch-once-a-year phase of this friendship.&lt;/p>
&lt;p>LOUDBOT isn&amp;rsquo;t my &lt;a href="http://en.wikipedia.org/wiki/Creep_%28Radiohead_song%29">&lt;em>Creep&lt;/em>&lt;/a>, but it&amp;rsquo;s time to shut it off. I&amp;rsquo;ll always have this ridiculous &lt;a href="loudbot_wordcloud.png">word cloud&lt;/a>. Thanks, Internet.&lt;/p>
&lt;blockquote>
&lt;p>-!- Nate has joined ##church-of-loudbot&lt;br>
&amp;lt; Nate&amp;gt; wow it really exists&amp;hellip;&lt;br>
-!- Nate was kicked by CAPSBOT [I CAN&amp;rsquo;T HEAR YOU, SOLDIER]&lt;br>
&amp;lt; HighBit&amp;gt; CURRENT STATUS: GOING TO CHURCH&lt;/p>
&lt;/blockquote>
&lt;div class="footnotes" role="doc-endnotes">
&lt;hr>
&lt;ol>
&lt;li id="fn:1">
&lt;p>I&amp;rsquo;m told the creator of @CapsCop &lt;a href="http://twitter.com/natefanaro/status/7789580746">secretly loves @LOUDBOT&lt;/a>&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;/ol>
&lt;/div>
- https://iank.org/posts/i-pressed-caps-lock-once-in-1989/ - 2014-2024 iank.org</description></item><item><title>Your Food is Always Outside of You</title><link>https://iank.org/posts/your-food-is-always-outside-of-you/</link><pubDate>Wed, 05 Nov 2014 22:09:08 +0000</pubDate><guid>https://iank.org/posts/your-food-is-always-outside-of-you/</guid><description>iank.org https://iank.org/posts/your-food-is-always-outside-of-you/ -
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;">
&lt;iframe src="https://www.youtube.com/embed/OyTIqWk-O3E" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" allowfullscreen title="YouTube Video">&lt;/iframe>
&lt;/div>
&lt;p>Yesterday I gave a talk at the &lt;a href="http://lug.ncsu.edu/">NCSU Linux Users&amp;rsquo; Group&lt;/a> and I&amp;rsquo;ve posted the slides and a video here. Not captured in the audio was, after the talk, an impromptu lecture about Hilbert&amp;rsquo;s infinite hotel and then Jim Witschey came up to talk about the expectation of the Poisson distribution. So it was a good time!&lt;/p>
&lt;p>&lt;a href="https://iank.org/media/ncsulug_fa14.pdf">Slides (PDF)&lt;/a>&lt;/p>
&lt;p>Here&amp;rsquo;s the original abstract of the talk:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-txt" data-lang="txt">&lt;span style="display:flex;">&lt;span>YOUR FOOD IS ALWAYS OUTSIDE OF YOU
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>(Some Ideas About Space But Definitely Not Time)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ABSTRACT:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>I&amp;#39;m going to, in an accessible way, cover some mathematical and physical ideas
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>that I think are important or at least pretty cool. I want to talk about why
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>orbits work, what happens in 5-D, why the World Series is slightly better than
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>a coin toss, databases are broken forever, truth itself is wrong, and what
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>happens if an infinite number of buses roll up at your house. Or some subset of
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>that.
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>I&amp;#39;ll cover three or four discrete topics, so don&amp;#39;t worry if you get lost;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>you&amp;#39;ll be following along again in a few slides. Any equations will be
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>supplementary only- you won&amp;#39;t have to understand them to get the general idea.
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>Here&amp;#39;s what loudbot has to say:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&amp;lt; LOUDBOT&amp;gt; ik: GIVEN YOUR PAST PERFORMANCE THIS MAY QUALIFY AS A MIRACLE
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>- https://iank.org/posts/your-food-is-always-outside-of-you/ - 2014-2024 iank.org</description></item><item><title>A True Random Number Generator</title><link>https://iank.org/posts/a-true-random-number-generator/</link><pubDate>Fri, 06 Jun 2014 22:09:08 +0000</pubDate><guid>https://iank.org/posts/a-true-random-number-generator/</guid><description>iank.org https://iank.org/posts/a-true-random-number-generator/ -&lt;p>This page describes the implementation of (Yet Another) avalanche noise hardware random number generator. This is a device which has been implemented many times [e.g. &lt;a href="http://robseward.com/itp/adv_tech/random_generator/">Rob Seward&lt;/a>, &lt;a href="http://www.cryogenius.com/hardware/isarng/">Aaron Logue&lt;/a>], including some commercial offerings [e.g. &lt;a href="http://www.entropykey.co.uk/">Entropy Key&lt;/a>, &lt;a href="http://ubld.it/products/truerng-hardware-random-number-generator/">TrueRNG&lt;/a>]. This project does not do anything better than existing work, but I learned a lot.&lt;/p>
&lt;h2 id="theory">Theory&lt;/h2>
&lt;p>This True Random Number Generator (TRNG) is based on avalanche breakdown noise in a &lt;a href="http://en.wikipedia.org/wiki/P%E2%80%93n_junction">PN junction&lt;/a>. A PN junction is a semiconductor structure which forms a diode, allowing (ideally) electric current to flow in only one direction. Electric fields internal to the structure support a potential gradient allowing current to flow easily in one direction but creating a potential barrier for electrons driven in the reverse direction.&lt;/p>
&lt;p>If strongly reverse-biased, however, electrons which overcome that potential barrier can have sufficient energy to cause &lt;strong>impact ionization&lt;/strong>, leading to a multiplication effect&lt;sup id="fnref:1">&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref">1&lt;/a>&lt;/sup>. An energetic electron impacting a silicon atom in the lattice can knock another electron out of the valence band (forming another electron-hole pair). In the presence of a strong reverse-biased electric field (needed to initiate this process in the first place), the liberated electron will accelerate and the process can continue, creating something like a sustained chain reaction.&lt;/p>
&lt;p>Laying aside quantum effects and considering electrons in our PN junction to act as a Newtonian gas, avalanche breakdown is formally a &lt;a href="http://en.wikipedia.org/wiki/Chaos_theory">chaotic&lt;/a> process: It depends upon strongly nonlinear interactions between a large number of elements and exhibits topological mixing (the charge carriers mix throughout the structure and effects are not localized). Chaos means that this system, even if theoretically deterministic (I believe it is not), is highly sensitive to a tremendously large and unknowable set of initial conditions, rendering it unpredictable.&lt;/p>
&lt;h2 id="prototype">Prototype&lt;/h2>
&lt;p>The prototype is based upon a design by &lt;a href="http://web.jfet.org/hw-rng.html">Will Ware&lt;/a>. The physical random source is a reverse-biased PN junction (actually two terminals of a &lt;a href="http://en.wikipedia.org/wiki/Bipolar_junction_transistor">bipolar junction transistor&lt;/a>). Part of a transistor is used, rather than a diode, because diodes are typically designed with either very high breakdown voltage (as in the case of rectifying diodes) or low breakdown voltages but with minimal avalanche noise (e.g. zener diodes which are meant to be used in breakdown). A schematic is shown below.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_proto_sch.png" alt="TRNG prototype schematic" width="600" height="347">
&lt;figcaption>
TRNG prototype schematic&lt;/figcaption>
&lt;/figure>
&lt;p>&lt;br>
The PN junction formed by the base and emitter of T1 is reverse-biased by an 18V source (realized by two 9V batteries). The collector is left floating. The output is amplified by common-emitter amplifier T3 and coupled through C1 to another common-emitter stage (T2).&lt;/p>
&lt;p>I constructed this prototype on perfboard and sampled the output using the ADC on-board an &lt;a href="http://arduino.cc/en/Main/arduinoBoardUno">Arduino Uno&lt;/a>. After correcting the output &lt;a href="http://en.wikipedia.org/wiki/Probability_distribution">distribution&lt;/a> using &lt;a href="http://en.wikipedia.org/wiki/Hardware_random_number_generator#Software_whitening">Von Neumann&amp;rsquo;s algorithm&lt;/a>, the effective data rate was around 1000 random bits per second, and the device passed the &lt;a href="http://stat.fsu.edu/pub/diehard/">diehard&lt;/a> suite of statistical tests.&lt;/p>
&lt;p>With a working prototype, I set out to create an integrated PCB, increase the data rate, and replace the Arduino with a USB interface.&lt;/p>
&lt;h2 id="iteration-1-pcb-1-power-supply">Iteration 1: PCB 1, power supply&lt;/h2>
&lt;p>The first iteration adds an 18V supply based on the Texas Instruments TPS61040 DC/DC boost converter designed for LCD and LED display lighting applications. The &lt;a href="http://www.ti.com/lit/ds/slvs413f/slvs413f.pdf">datasheet&lt;/a> contains a reference design (Figure 16, pg. 14) for an 18V output from a 5V supply. This eliminates the 9V batteries and allows the design to be powered from USB.&lt;/p>
&lt;p>A PCB was created (using the free version of &lt;a href="http://www.cadsoftusa.com/">EAGLE&lt;/a>) containing the power supply, physics package, and amplifiers. I used 0603 passives and replaced the through-hole 2N3904 transistor from the prototype with the MMBT3904, a surface-mounted equivalent.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng1_sch.png" alt="Schematic for PCB 1" width="600" height="451">
&lt;figcaption>
Schematic for PCB 1&lt;/figcaption>
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng1_brd.png" alt="Board layout for PCB 1" width="600" height="433">
&lt;figcaption>
Board layout for PCB 1&lt;/figcaption>
&lt;/figure>
&lt;p>The PCB was manufactured by &lt;a href="https://www.seeedstudio.com/service/">Seeed Studio Fusion&lt;/a>, a low-cost PCB service. It was assembled and tested with the Arduino.&lt;/p>
&lt;h2 id="iteration-2-pcb-2-adc-and-lpc1343">Iteration 2: PCB 2, ADC and LPC1343&lt;/h2>
&lt;p>Next, I needed a faster interface. After some research I chose to use the &lt;a href="http://www.nxp.com/documents/data_sheet/LPC1311_13_42_43.pdf">LPC1343&lt;/a>, a 32-bit ARM Cortex-M3 microprocessor which has a native USB interface and runs at up to 72 MHz. Olimex offers a &lt;a href="https://www.olimex.com/Products/ARM/NXP/LPC-P1343/">LPC1343 dev board&lt;/a> with published schematics. Using the LPC1343&amp;rsquo;s on-board ADC, I was able to get about a 40x speedup over the Arduino.&lt;/p>
&lt;p>I adapted reference USB mass storage code for the LPC1343 and created a virtual mass storage interface for the device (this is not ideal). When inserted, the TRNG enumerates as a mass storage device (e.g. a USB thumbdrive) of arbitrary capacity. It would appear to, e.g. Linux, as a block device. Writes do nothing and return success. Reads return blocks of random data sampled from the noise circuit.&lt;/p>
&lt;p>Next, I found the &lt;a href="http://www.intersil.com/content/intersil/en/products/data-converters/high-speed-a-d-converters/a-d-converters/HI5767.html">Intersil HI5767/2CBZ&lt;/a>, a fast (up to 20 megasamples per second) dedicated 10-bit ADC in a &lt;a href="http://en.wikipedia.org/wiki/Small_Outline_Integrated_Circuit">SOIC-28&lt;/a> package. Driving the ADC at the LPC1343&amp;rsquo;s clock frequency (12 MHz) led to an overall speedup of 400x vs the prototype.&lt;/p>
&lt;p>I created a SSOIC-28 breakout board using a &lt;a href="http://www.adafruit.com/products/1208">PCB from Adafruit&lt;/a> and built a test circuit for the ADC on perfboard (pictured below), following a reference schematic in the &lt;a href="http://www.intersil.com/content/dam/Intersil/documents/hi57/hi5767.pdf">HI5767 datasheet&lt;/a> (Figure 19, pg. 13).&lt;/p>
&lt;p>The HI5767 has an input dynamic range of no more than 1Vp-p, and I found that removing the second amplifier from the amplifier chain in my physics package reduced the output to within this level. I was able to hack the PCB (pictured below) to achieve this, saving me considerable time.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_adc_test.png" alt="ADC test rig" width="600" height="257">
&lt;figcaption>
ADC test rig&lt;/figcaption>
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_pcb1_hack.png" alt="PCB 1 hack" width="600" height="204">
&lt;figcaption>
PCB 1 hack&lt;/figcaption>
&lt;/figure>
&lt;p>The test setup, shown below, consists of the Arduino Uno (now providing only a 5V power supply!), the LPC1343 (providing a USB interface), The physics package PCB #1 from above (hacked for 1V output), and my ADC test circuit. It is a mess.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_mess1.png" alt="Messy test setup" width="600" height="448">
&lt;figcaption>
Messy test setup&lt;/figcaption>
&lt;/figure>
&lt;h2 id="iteration-3-integration">Iteration 3: Integration&lt;/h2>
&lt;p>Finally, I created a single integrated PCB. I attempted to follow some basic rules of mixed-signal design (single sided PCB with large ground pour on reverse, isolating analog and digital circuitry, short clock traces, etc) to avoid contaminating the analog noise source with radiated &lt;a href="http://mathworld.wolfram.com/FourierSeriesSquareWave.html">high-frequency components&lt;/a> of the clock or digital outputs. It seems ironic to take measures to protect a noise signal from interference, but we must avoid introducing predictable patterns.&lt;/p>
&lt;p>The final schematic, board layout, and images of the completed device are shown below. The final device, after moving the whitening logic to firmware (for completeness sake, but at a significant speed expense), achieved 9 kB/sec random data.&lt;/p>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_final_sch.png" alt="Final schematic" width="600" height="243">
&lt;figcaption>
Final schematic&lt;/figcaption>
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_final_brd.png" alt="Final PCB layout" width="600" height="313">
&lt;figcaption>
Final PCB layout&lt;/figcaption>
&lt;/figure>
&lt;figure class="image">
&lt;img src="https://iank.org/posts/a-true-random-number-generator/trng_final_assembled2.png" alt="Final assembly" width="600" height="313">
&lt;figcaption>
Final assembly&lt;/figcaption>
&lt;/figure>
&lt;h2 id="conclusion">Conclusion&lt;/h2>
&lt;p>This design, like many others in its class (including some commercial offerings) is flawed and should not be used by anyone. It is not a differential design and is easily influenced by external fields. Unlike some commercial products, it has no &lt;a href="http://www.entropykey.co.uk/tech/">tampering detection&lt;/a> or countermeasures, leaving it vulnerable to manipulation.&lt;/p>
&lt;p>I am done iterating and there are loose ends I do not intend to clean up. In particular, the USB mass storage class is a strange way to interface this device.&lt;/p>
&lt;h2 id="linksmisc">Links/misc&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>&lt;a href="https://iank.org/media/2014-07-18_dieharder_test.txt">Test output&lt;/a>&lt;/strong> from the &lt;a href="http://www.phy.duke.edu/~rgb/General/dieharder.php">dieharder test suite&lt;/a>&lt;/li>
&lt;li>While not explicitly referenced, I found these links interesting or useful
&lt;ul>
&lt;li>&lt;a href="http://holdenc.altervista.org/avalanche/">http://holdenc.altervista.org/avalanche/&lt;/a>&lt;/li>
&lt;li>&lt;a href="https://code.google.com/p/avr-hardware-random-number-generation/wiki/AvalancheNoise">https://code.google.com/p/avr-hardware-random-number-generation/wiki/AvalancheNoise&lt;/a>&lt;/li>
&lt;li>&lt;a href="http://www.random.org/analysis/">http://www.random.org/analysis/&lt;/a>&lt;/li>
&lt;li>&lt;a href="http://www.cs.berkeley.edu/~daw/papers/ddj-netscape.html">http://www.cs.berkeley.edu/~daw/papers/ddj-netscape.html&lt;/a>&lt;/li>
&lt;li>&lt;a href="http://gamesbyemail.com/News/DiceOMatic">http://gamesbyemail.com/News/DiceOMatic&lt;/a>&lt;/li>
&lt;li>&lt;a href="http://boallen.com/random-numbers.html">http://boallen.com/random-numbers.html&lt;/a>&lt;/li>
&lt;/ul>
&lt;/li>
&lt;/ul>
&lt;div class="footnotes" role="doc-endnotes">
&lt;hr>
&lt;ol>
&lt;li id="fn:1">
&lt;p>McIntyre, R. J. &amp;ldquo;Multiplication noise in uniform avalanche diodes.&amp;rdquo; Electron Devices, IEEE Transactions on 13.1 (1966): 164-168.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;/ol>
&lt;/div>
- https://iank.org/posts/a-true-random-number-generator/ - 2014-2024 iank.org</description></item></channel></rss>