Index: tt-loader/2nd/Makefile
===================================================================
--- tt-loader/2nd/Makefile	(revision 11)
+++ tt-loader/2nd/Makefile	(revision 12)
@@ -11,5 +11,5 @@
 
 S_SRCS = start.S
-C_SRCS = main.c usb.c
+C_SRCS = main.c usb.c crc32.c
 SRCS = $(S_SRCS) $(C_SRCS)
 
Index: tt-loader/2nd/config.h
===================================================================
--- tt-loader/2nd/config.h	(revision 11)
+++ tt-loader/2nd/config.h	(revision 12)
@@ -26,6 +26,14 @@
 #define _CONFIG_H_
 
-// Default address in SRAM
+// Default Linux commandline
+#define KERNEL_CMDLINE "mem=64M console=ttyS0,115200 noinitrd root=/dev/mtdblock_bbs5"
+
+// Default address in SRAM & RAM
+#define RAM_SIZE				0x04000000	// 64M
+#define CFG_BASESDRAM			0x10000000
 #define CFG_LOADADDR			0x20000400
+#define CFG_PARAMADDR			CFG_BASESDRAM+0x100
+#define INITRD_LOAD_ADDR		0x00800000
+#define INITRD_SIZE				0x00000000
 
 // Address to find jtag id, to check on which target we are running
Index: tt-loader/2nd/crc32.c
===================================================================
--- tt-loader/2nd/crc32.c	(revision 12)
+++ tt-loader/2nd/crc32.c	(revision 12)
@@ -0,0 +1,116 @@
+/*
+ * This file is derived from the one provided with u-boot. Check
+ * u-boot to find related files.
+ */
+
+/*
+ * This file is derived from crc32.c from the zlib-1.1.3 distribution
+ * by Jean-loup Gailly and Mark Adler.
+ */
+
+/* crc32.c -- compute the CRC-32 of a data stream
+ * Copyright (C) 1995-1998 Mark Adler
+ * For conditions of distribution and use, see copyright notice in zlib.h
+ */
+
+#include "types.h"
+
+/* ========================================================================
+ * Table of CRC-32's of all single-byte values (made by make_crc_table)
+ */
+static const u32 crc_table[256] = {
+  0x00000000L, 0x77073096L, 0xee0e612cL, 0x990951baL, 0x076dc419L,
+  0x706af48fL, 0xe963a535L, 0x9e6495a3L, 0x0edb8832L, 0x79dcb8a4L,
+  0xe0d5e91eL, 0x97d2d988L, 0x09b64c2bL, 0x7eb17cbdL, 0xe7b82d07L,
+  0x90bf1d91L, 0x1db71064L, 0x6ab020f2L, 0xf3b97148L, 0x84be41deL,
+  0x1adad47dL, 0x6ddde4ebL, 0xf4d4b551L, 0x83d385c7L, 0x136c9856L,
+  0x646ba8c0L, 0xfd62f97aL, 0x8a65c9ecL, 0x14015c4fL, 0x63066cd9L,
+  0xfa0f3d63L, 0x8d080df5L, 0x3b6e20c8L, 0x4c69105eL, 0xd56041e4L,
+  0xa2677172L, 0x3c03e4d1L, 0x4b04d447L, 0xd20d85fdL, 0xa50ab56bL,
+  0x35b5a8faL, 0x42b2986cL, 0xdbbbc9d6L, 0xacbcf940L, 0x32d86ce3L,
+  0x45df5c75L, 0xdcd60dcfL, 0xabd13d59L, 0x26d930acL, 0x51de003aL,
+  0xc8d75180L, 0xbfd06116L, 0x21b4f4b5L, 0x56b3c423L, 0xcfba9599L,
+  0xb8bda50fL, 0x2802b89eL, 0x5f058808L, 0xc60cd9b2L, 0xb10be924L,
+  0x2f6f7c87L, 0x58684c11L, 0xc1611dabL, 0xb6662d3dL, 0x76dc4190L,
+  0x01db7106L, 0x98d220bcL, 0xefd5102aL, 0x71b18589L, 0x06b6b51fL,
+  0x9fbfe4a5L, 0xe8b8d433L, 0x7807c9a2L, 0x0f00f934L, 0x9609a88eL,
+  0xe10e9818L, 0x7f6a0dbbL, 0x086d3d2dL, 0x91646c97L, 0xe6635c01L,
+  0x6b6b51f4L, 0x1c6c6162L, 0x856530d8L, 0xf262004eL, 0x6c0695edL,
+  0x1b01a57bL, 0x8208f4c1L, 0xf50fc457L, 0x65b0d9c6L, 0x12b7e950L,
+  0x8bbeb8eaL, 0xfcb9887cL, 0x62dd1ddfL, 0x15da2d49L, 0x8cd37cf3L,
+  0xfbd44c65L, 0x4db26158L, 0x3ab551ceL, 0xa3bc0074L, 0xd4bb30e2L,
+  0x4adfa541L, 0x3dd895d7L, 0xa4d1c46dL, 0xd3d6f4fbL, 0x4369e96aL,
+  0x346ed9fcL, 0xad678846L, 0xda60b8d0L, 0x44042d73L, 0x33031de5L,
+  0xaa0a4c5fL, 0xdd0d7cc9L, 0x5005713cL, 0x270241aaL, 0xbe0b1010L,
+  0xc90c2086L, 0x5768b525L, 0x206f85b3L, 0xb966d409L, 0xce61e49fL,
+  0x5edef90eL, 0x29d9c998L, 0xb0d09822L, 0xc7d7a8b4L, 0x59b33d17L,
+  0x2eb40d81L, 0xb7bd5c3bL, 0xc0ba6cadL, 0xedb88320L, 0x9abfb3b6L,
+  0x03b6e20cL, 0x74b1d29aL, 0xead54739L, 0x9dd277afL, 0x04db2615L,
+  0x73dc1683L, 0xe3630b12L, 0x94643b84L, 0x0d6d6a3eL, 0x7a6a5aa8L,
+  0xe40ecf0bL, 0x9309ff9dL, 0x0a00ae27L, 0x7d079eb1L, 0xf00f9344L,
+  0x8708a3d2L, 0x1e01f268L, 0x6906c2feL, 0xf762575dL, 0x806567cbL,
+  0x196c3671L, 0x6e6b06e7L, 0xfed41b76L, 0x89d32be0L, 0x10da7a5aL,
+  0x67dd4accL, 0xf9b9df6fL, 0x8ebeeff9L, 0x17b7be43L, 0x60b08ed5L,
+  0xd6d6a3e8L, 0xa1d1937eL, 0x38d8c2c4L, 0x4fdff252L, 0xd1bb67f1L,
+  0xa6bc5767L, 0x3fb506ddL, 0x48b2364bL, 0xd80d2bdaL, 0xaf0a1b4cL,
+  0x36034af6L, 0x41047a60L, 0xdf60efc3L, 0xa867df55L, 0x316e8eefL,
+  0x4669be79L, 0xcb61b38cL, 0xbc66831aL, 0x256fd2a0L, 0x5268e236L,
+  0xcc0c7795L, 0xbb0b4703L, 0x220216b9L, 0x5505262fL, 0xc5ba3bbeL,
+  0xb2bd0b28L, 0x2bb45a92L, 0x5cb36a04L, 0xc2d7ffa7L, 0xb5d0cf31L,
+  0x2cd99e8bL, 0x5bdeae1dL, 0x9b64c2b0L, 0xec63f226L, 0x756aa39cL,
+  0x026d930aL, 0x9c0906a9L, 0xeb0e363fL, 0x72076785L, 0x05005713L,
+  0x95bf4a82L, 0xe2b87a14L, 0x7bb12baeL, 0x0cb61b38L, 0x92d28e9bL,
+  0xe5d5be0dL, 0x7cdcefb7L, 0x0bdbdf21L, 0x86d3d2d4L, 0xf1d4e242L,
+  0x68ddb3f8L, 0x1fda836eL, 0x81be16cdL, 0xf6b9265bL, 0x6fb077e1L,
+  0x18b74777L, 0x88085ae6L, 0xff0f6a70L, 0x66063bcaL, 0x11010b5cL,
+  0x8f659effL, 0xf862ae69L, 0x616bffd3L, 0x166ccf45L, 0xa00ae278L,
+  0xd70dd2eeL, 0x4e048354L, 0x3903b3c2L, 0xa7672661L, 0xd06016f7L,
+  0x4969474dL, 0x3e6e77dbL, 0xaed16a4aL, 0xd9d65adcL, 0x40df0b66L,
+  0x37d83bf0L, 0xa9bcae53L, 0xdebb9ec5L, 0x47b2cf7fL, 0x30b5ffe9L,
+  0xbdbdf21cL, 0xcabac28aL, 0x53b39330L, 0x24b4a3a6L, 0xbad03605L,
+  0xcdd70693L, 0x54de5729L, 0x23d967bfL, 0xb3667a2eL, 0xc4614ab8L,
+  0x5d681b02L, 0x2a6f2b94L, 0xb40bbe37L, 0xc30c8ea1L, 0x5a05df1bL,
+  0x2d02ef8dL
+};
+
+static u32 cbsize = 0 ;
+static u32 cbtotal = 0 ;
+#define CB_BLOCK_SIZE 1024*1024
+
+/* ========================================================================= */
+#define DO1(buf) crc = crc_table[((int)crc ^ (*buf++)) & 0xff] ^ (crc >> 8);
+#define DO2(buf)  DO1(buf); DO1(buf);
+#define DO4(buf)  DO2(buf); DO2(buf);
+#define DO8(buf)  DO4(buf); DO4(buf);
+
+/* ========================================================================= */
+u32 crc32( u32 crc, char* buf, u32 len, crc_cb_fnc_t* cb)
+{
+	// Check to handle callback
+	if (cb)
+	{
+		cbsize = 0 ;
+		cbtotal = len ;
+	}
+	
+    crc = crc ^ 0xffffffffL;
+    while (len >= 8)
+    {
+    	DO8(buf);
+    	len -= 8;
+	 	if (cb)
+		{
+	  		cbsize += 8 ;
+			if (cbsize >= CB_BLOCK_SIZE)
+			{
+				(cb)( cbtotal-len, cbtotal, crc );
+				cbsize = 0 ;
+			}
+		}
+	}	
+    
+    if (len) do {
+      DO1(buf);
+    } while (--len);
+    return crc ^ 0xffffffffL;
+}
Index: tt-loader/2nd/main.c
===================================================================
--- tt-loader/2nd/main.c	(revision 11)
+++ tt-loader/2nd/main.c	(revision 12)
@@ -4,4 +4,8 @@
  * Copyright (C) 2008 Guillaume Bougard <gbougard@pkg.fr>
  * Copyright (C) 2005 Luis Recuerda <lrec@helios.homeip.net>
+ *
+ * ARM kernel loader. Adapt from qemu-neo1973
+ * Copyright (c) 2006-2007 CodeSourcery.
+ * Written by Paul Brook
  *
  * This program is free software; you can redistribute it and/or
@@ -24,14 +28,16 @@
 #include "usb.h"
 
-#define _LSR_   ((volatile u8 *) 0xfffb0014)
-#define _THR_   ((volatile u8 *) 0xfffb0000)
-#define _RHR_   ((volatile u8 *) 0xfffb0000)
-
-#define MEM_READ_SIZE	32
+extern u32 crc32( u32 crc, char* buf, u32 len, crc_cb_fnc_t* cb);
+
+/*
+ * Length of memory dump done by 2nd.bin, must be a multiple of DUMP_LINE_SIZE from host main.c
+ * Must also be sufficient to output lines of text, let's say 128 bytes
+ */
+#define MEM_READ_SIZE	128*32
+#define CHUNK_SIZE		8192
 
 static char *usb_hdr = "TIS" ;
-static char usb_outbuffer[64];
-
-// limited strcpy
+static char usb_outbuffer[MEM_READ_SIZE+4];
+
 static u32 strcpy ( char *dest, char *src )
 {
@@ -39,5 +45,5 @@
 	char *tmp = dest, *s = src;
 	
-	while ( ++count < 256 && *s != '\0' )
+	while ( ++count < MEM_READ_SIZE && *s != '\0' )
 		*tmp++ = *s++ ;
 	
@@ -45,4 +51,16 @@
 	
 	return count ;
+}
+
+static u32 strlen ( char *src )
+{
+	u32 len = 0 ;
+	
+	while ( *src != '\0' ) {
+		src++ ;
+		len ++ ;
+	}
+	
+	return len ;
 }
 
@@ -56,70 +74,4 @@
 	
 	return count ;
-}
-
-static void bsend (char ch)
-{
-	while (!((*_LSR_) & 0x20));
-	*_THR_= ch;
-}
-
-static inline int check_serial (void) { return (*_LSR_) & 0x01; }
-
-static char brecv (void)
-{
-	while (!((*_LSR_) & 0x01));
-	return *_RHR_;
-}
-
-char crecv (void)
-{
-	return brecv ();
-}
-
-void csend (char ch)
-{
-	if (ch == '\n')
-		bsend ('\r');
-	bsend (ch);
-}
-
-void tsend (const char *text)
-{
-	while (*text)
-		csend (*text++);
-}
-
-void xsend (unsigned value)
-{
-	if (value < 10)
-		bsend (value + '0');
-	else
-		bsend (value + ('A'-10));
-}
-
-void x8send (u8 value)
-{
-	xsend (value >> 4);
-	xsend (value & 0xf);
-}
-
-void x16send (u16 value)
-{
-	int	i;
-	for (i= 0; i < 4; ++i)
-	{
-		xsend (value >> 12);
-		value<<= 4;
-	}
-}
-
-void x32send (u32 value)
-{
-	int	i;
-	for (i= 0; i < 8; ++i)
-	{
-		xsend (value >> 28);
-		value<<= 4;
-	}
 }
 
@@ -181,7 +133,90 @@
 }
 
+// stl_raw is qemu related
+#define stl_raw(x,v) *(u32 *)(x) = v
+static void set_kernel_args(u32 ram_size, int initrd_size, const char *kernel_cmdline, u32 ram_start)
+{
+    u32 *p;
+	
+	// Set pointer to kernel params
+    p = (u32 *)(CFG_PARAMADDR);
+	
+    /* ATAG_CORE */
+    stl_raw(p++, 5);
+    stl_raw(p++, 0x54410001);
+    stl_raw(p++, 0); // 0 = ro ; 1= rw
+    stl_raw(p++, 0x1000); // Page size
+    stl_raw(p++, 0); // root device overrided by cmdline
+    /* ATAG_MEM */
+    stl_raw(p++, 4);
+    stl_raw(p++, 0x54410002);
+    stl_raw(p++, ram_size);
+    stl_raw(p++, ram_start);
+    if (initrd_size) {
+        /* ATAG_INITRD2 */
+        stl_raw(p++, 4);
+        stl_raw(p++, 0x54420005);
+        stl_raw(p++, ram_start + INITRD_LOAD_ADDR);
+        stl_raw(p++, initrd_size);
+    }
+    if (kernel_cmdline && *kernel_cmdline) {
+        /* ATAG_CMDLINE */
+        int cmdline_size;
+
+        cmdline_size = strlen((char *)kernel_cmdline);
+        memcpy ((char *)p + 2, (char *)kernel_cmdline, cmdline_size + 1);
+        cmdline_size = (cmdline_size >> 2) + 1;
+        stl_raw(p++, cmdline_size + 2);
+        stl_raw(p++, 0x54410009);
+        p += cmdline_size;
+    }
+    /* ATAG_END */
+    stl_raw(p++, 0);
+    stl_raw(p++, 0);
+}
+
+#define C1_DC		(1<<2)		/* dcache off/on */
+#define C1_IC		(1<<12)		/* icache off/on */
+
+void cleanup_before_linux (void)
+{
+	/*
+	 * this function is called just before we call linux
+	 * it prepares the processor for linux
+	 *
+	 * we turn off caches etc ...
+	 */
+
+	unsigned long i;
+
+	/* turn off I/D-cache */
+	asm ("mrc p15, 0, %0, c1, c0, 0":"=r" (i));
+	i &= ~(C1_DC | C1_IC);
+	asm ("mcr p15, 0, %0, c1, c0, 0": :"r" (i));
+
+	/* flush I/D-cache */
+	i = 0;
+	asm ("mcr p15, 0, %0, c7, c7, 0": :"r" (i));
+}
+
+void usb_crc32_pos( u32 pos, u32 total, u32 crc )
+{
+	u32 len = strcpy(usb_outbuffer,usb_hdr);
+	usb_outbuffer[len-1] = 'x' ;
+	(*(u32 *)(usb_outbuffer+len)) = pos ;
+	len += sizeof(u32);
+	(*(u32 *)(usb_outbuffer+len)) = total ;
+	len += sizeof(u32);
+	(*(u32 *)(usb_outbuffer+len)) = crc ;
+	len += sizeof(u32);
+	usb_send ( usb_outbuffer, len );
+	while (!usb_sent ());
+}
+
 u32 _main (void)
 {	
+	u32 params = CFG_PARAMADDR ;
 	u32 address = CFG_LOADADDR ;
+	u32 crc = 0 ;
 	usb_msg ('m', "In omap plateform");
 	
@@ -205,5 +240,5 @@
 		u32 total, cmd, index = 0 ;
 		
-		u8 usb_inbuffer[64];
+		u8 usb_inbuffer[CHUNK_SIZE];
 		usb_recv (usb_inbuffer, sizeof (usb_inbuffer));
 		while (!usb_rcvd ());
@@ -239,4 +274,52 @@
 			
 		} else
+		if ((char)cmd == 'C') // set crc32 value for next download
+		{
+			crc = *(u32 *) &usb_inbuffer[index];
+			usb_code ('i', crc);
+			
+		} else
+		if ((char)cmd == 'm') // Download size from memory
+		{
+			total= *(u32 *) &usb_inbuffer[index];
+			u32 size = 0;
+			
+			usb_code ('I', total);
+			
+			// Check crc32 if it has been set
+			if (total && crc)
+			{
+				crc_cb_fnc_t* cb = NULL ;
+				if (total>1024*1024)
+					cb = &usb_crc32_pos ;
+				u32 foundcrc = crc32(0, (char *)address,total,cb) ;
+				usb_code ('C', foundcrc);
+				// Skip download on crc match
+				if (foundcrc == crc)
+					total = 0 ;
+			}
+			
+			if (total == 0)
+				usb_blk ('D', (char *)address, 0);
+			
+			while (size < total)
+			{
+				u32 bs = MEM_READ_SIZE ;
+				if ( total - size < MEM_READ_SIZE)
+					bs = total - size ;
+				usb_blk ('D', (char *)address, bs);
+				address += bs ;
+				size += bs ;
+			}
+			
+			// reset crc for next download anyway
+			crc = 0 ;
+			
+		} else
+		if ((char)cmd == 'e') // End, just loop
+		{
+			usb_reset();
+			
+		} else
 		if ((char)cmd == 'f') // load file ACK
 		{
@@ -256,7 +339,28 @@
 			
 		} else
+		if ((char)cmd == 'p') // do a poke on address
+		{
+			u32 size = memcpy( (char *) address, (char *) &usb_inbuffer[index], 4);
+			address += size ;
+			usb_code ('i', address );
+			
+		} else
+		if ((char)cmd == 'P') // do a peek on address
+		{
+			usb_code ('i', *(u32 *) address );
+			address += 4 ;
+			
+		} else
 		if ((char)cmd == 'c') // call command
 		{
-			index = ((u32_fnc_t *)address)();
+			__asm__ __volatile__ (
+						"mov r0, #0	;"
+						"mov r1, #0	;"
+						"mov r2, #0	;"
+						"ldr r3, %1	;"
+						"blx r3		;"
+						"mov %0, r0	;"
+						: "=r"(index) : "m"(address) : "r0", "r1", "r2", "r3"
+						);
 			usb_code ('i', index);
 			
@@ -265,7 +369,42 @@
 		{
 			usb_code ('b', address );
-			// Just return the address where is store the branch to do
-			u32 bootaddress = (u32) &address ; // Convert/cast address just to avoid gcc warning
-			return bootaddress ;
+			usb_reset();
+			__asm__ __volatile__ (
+						"ldr r0, %0	;"
+						"mov pc, r0	;"
+						: : "m"(address)
+						);
+			
+		} else
+		if ((char)cmd == 'k') // boot kernel command
+		{
+			int machid =  * (int *) &usb_inbuffer[index];
+			usb_code ('I', machid);
+			set_kernel_args( RAM_SIZE, INITRD_SIZE, KERNEL_CMDLINE, CFG_BASESDRAM );
+			usb_code ('b', address );
+			usb_reset();
+			cleanup_before_linux();
+			__asm__ __volatile__ (
+						"mov r0, #0	;"
+						"ldr r1, %0	;"
+						"ldr r2, %1	;"
+						"mov r3, #0	;"
+						"mov r4, #0	;"
+						"ldr r5, %2	;"
+						"mov pc, r5	;"
+						: : "m" (machid), "m"(params), "m"(address)
+						);
+		} else
+		if ((char)cmd == 'S') // Stack command
+		{
+			__asm__ __volatile__ (
+						"ldr fp, %0	;"
+						"sub fp, #4 ;"
+						"mov sp, fp	;"
+						"sub sp, #256 ;"
+						: : "m"(address)
+						);
+			usb_code ('i', address);
+			
 		}
 	}
Index: tt-loader/2nd/start.S
===================================================================
--- tt-loader/2nd/start.S	(revision 11)
+++ tt-loader/2nd/start.S	(revision 12)
@@ -102,6 +102,4 @@
 	.extern _main
 	bl _main
-	ldr pc, [r0]			// Branch to content of mem returned as boot command
-
 
 WSPR_VAL1:
Index: tt-loader/2nd/types.h
===================================================================
--- tt-loader/2nd/types.h	(revision 11)
+++ tt-loader/2nd/types.h	(revision 12)
@@ -32,4 +32,5 @@
 typedef u32 (u32_fnc_t) (void);
 typedef void (init_fnc_t) (void);
+typedef void (crc_cb_fnc_t) (u32,u32,u32);
 
 #endif
Index: tt-loader/2nd/usb.c
===================================================================
--- tt-loader/2nd/usb.c	(revision 11)
+++ tt-loader/2nd/usb.c	(revision 12)
@@ -261,2 +261,8 @@
 	return result;
 }
+
+void usb_reset()
+{
+	USBS_SYSCON1 &= ~_PULLUP_EN ;
+	USBS_SYSCON1 |= _PULLUP_EN ;
+}
Index: tt-loader/2nd/usb.h
===================================================================
--- tt-loader/2nd/usb.h	(revision 11)
+++ tt-loader/2nd/usb.h	(revision 12)
@@ -31,5 +31,5 @@
 int usb_rcvd (void);
 
-void usb_debug (void);
+void usb_reset (void);
 
 #endif
Index: tt-loader/Makefile
===================================================================
--- tt-loader/Makefile	(revision 11)
+++ tt-loader/Makefile	(revision 12)
@@ -5,5 +5,5 @@
 LDFLAGS = -g $(LIBS)
 APP_NAME = tt-loader
-APP_VERSION = 0.1
+APP_VERSION = 0.2
 
 # Adapt this to your system
@@ -11,5 +11,8 @@
 DIS_ADDR ?= 0
 
-OBJS = main.o
+# You can overide the name of the extracted MTD partition to get the kernel
+KERNEL_MTD ?= mtd4
+
+OBJS = main.o crc32.o
 
 all: $(APP_NAME)
@@ -36,3 +39,7 @@
 	rm -f $(@F).elf
 
+# Extract kernel from mtd4 nand partition extraction
+kernel.bin: $(KERNEL_MTD)
+	./kernel-extract.sh $^ $@
+
 .PHONY: all clean 2nd
Index: tt-loader/commands.txt
===================================================================
--- tt-loader/commands.txt	(revision 11)
+++ tt-loader/commands.txt	(revision 12)
@@ -1,14 +1,456 @@
-//////// X-LOAD
-// Load x-load in the phone
+/////////////////////////////////////////////////////////////////// READNAND
+# -----------------------------------------
+# Init phone RAM
 a 0x20010000
-// Check README to generate x-load.bin
 f x-load.bin
-
-// Boot with x-load
-a 0x20010c00
-b
-
+// Call a sub from x-load.bin: TT BoardInit (should only work with TT)
+a 0x20010da4
+c
+
+# -----------------------------------------
+# Upload FlashWriteNAND.bin program
+a 0x10000000
+f FlashWriteNAND.bin
+
+# -----------------------------------------
+# ------------------X-LOAD-----------------
+# -----------------------------------------
+# Setup read command for x-load.bin
+a 0x1000ffec
+p 0x00000003
+p 0x10010000
+p 0x00000000
+p 0x00004000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-x-load.bin
+C 0
+
+# -----------------------------------------
+# Download phone memory into local buffer
+a 0x10010000
+m 16
+
+# -----------------------------------------
+# Save the local buffer into a file
+D
+
+# -----------------------------------------
+# ------------------U-BOOT-----------------
+# -----------------------------------------
+# Setup read command for u-boot.bin
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x00004000
+p 0x00030000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-u-boot.bin
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 192
+D
+
+# -----------------------------------------
+# ------------------UNUSED-----------------
+# -----------------------------------------
+# Setup read command for u-boot-params.bin
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x00034000
+p 0x00020000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-u-boot-params.bin
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 128
+D
+
+# -----------------------------------------
+# ------------------SPLASH-----------------
+# -----------------------------------------
+# Setup read command for splash.bin
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x00054000
+p 0x0002c000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-splash.bin
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 176
+D
+
+# -----------------------------------------
+# ------------------KERNEL-----------------
+# -----------------------------------------
+# Setup read command for uImage.bin
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x00080000
+p 0x00100000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-uImage.bin
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 1024
+D
+
+# -----------------------------------------
+# ------------------ROOTFS-----------------
+# -----------------------------------------
+# Setup read command for rootfs.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x00180000
+p 0x00590000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-rootfs.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 5696
+D
+
+# -----------------------------------------
+# ------------------E28-FS-----------------
+# -----------------------------------------
+# Setup read command for e28fs.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x00710000
+p 0x01200000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-e28fs.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 18432
+D
+
+# -----------------------------------------
+# ------------------RSC-FS-----------------
+# -----------------------------------------
+# Setup read command for resource.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x01910000
+p 0x00500000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-resource.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 5120
+D
+
+# -----------------------------------------
+# ------------------USERFS-----------------
+# -----------------------------------------
+# Setup read command for user_jffs2.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x01e10000
+p 0x00dc0000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-user_jffs2.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 14080
+D
+
+# -----------------------------------------
+# -----------------RESERVE-----------------
+# -----------------------------------------
+# Setup read command for reserve.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x02bd0000
+p 0x01200000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-reserve.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 18432
+D
+
+# -----------------------------------------
+# ------------------PART1------------------
+# -----------------------------------------
+# Setup read command for part1.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x03dd0000
+p 0x00008000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-part1.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 32
+D
+
+# -----------------------------------------
+# ------------------PART2------------------
+# -----------------------------------------
+# Setup read command for part2.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x03dd8000
+p 0x00008000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-part2.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 32
+D
+
+# -----------------------------------------
+# ------------------GSMFS------------------
+# -----------------------------------------
+# Setup read command for gsmfs.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x03de0000
+p 0x00020000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-gsmfs.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 128
+D
+
+# -----------------------------------------
+# -----------------GSMCODE-----------------
+# -----------------------------------------
+# Setup read command for gsm_code.raw
+a 0x1000ffec
+p 0x00000000
+p 0x10010000
+p 0x03e00000
+p 0x00200000
+p 0x00000000
+
+// Just peek to control command is set as expected
+a 0x1000ffec
+P;P;P;P;P
+
+# -----------------------------------------
+# Call FlashWriteNAND program
+a 0x10000000
+c
+
+# -----------------------------------------
+# Setup file to be updated
+F /lib/firmware/tt-gsm_code.raw
+C 0
+
+# -----------------------------------------
+# Download firmware to local file
+a 0x10010000
+m 2048
+D
+
+# -----------------------------------------
 end
-/////////////////////////////////////////////////////////////////// X-LOAD END
+/////////////////////////////////////////////////////////////////// READNAND END
 
 /////////////////////////////////////////////////////////////////// U-BOOT
@@ -23,10 +465,63 @@
 
 // Load another program to a new address, check README to generate u-boot.bin
+a 0x11080000
+f u-boot.usb
+
+a 0x10000000
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 1ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 2ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 3ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 4ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 5ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 6ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 7ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 8ko
+
+a 0x1103F800
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 1ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 2ko
+
+// dump depuis _bss_start
+//a 0x11098160
+a 0x1029f300
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 1ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 2ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 3ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 4ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 5ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 6ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 7ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 8ko
+
+// dump zone malloc
+a 0x11060800
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 1ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 2ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 3ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 4ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 5ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 6ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 7ko
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 8ko
+
+// Send u-boot start address and boot there
+a 0x11080000
+b
+
+end
+/////////////////////////////////////////////////////////////////// U-BOOT END
+
+/////////////////////////////////////////////////////////////////// U-BOOT
+# Booting TT with hosted u-boot
+a 0x20010000
+f x-load.bin
+
+// Call a sub from x-load.bin: TT BoardInit (should only work with TT)
+a 0x20010da4
+c
+
+// Load u-boot.bin
 a 0x10280000
 f u-boot.bin
-
-// Send an address and dump the content to check upload has been done
-a 0x10299a50
-M;M;M;M;M;M;M;M
 
 // Send u-boot start address and boot there
@@ -37,25 +532,24 @@
 /////////////////////////////////////////////////////////////////// U-BOOT END
 
+/////////////////////////////////////////////////////////////////// X-LOAD
+# Booting TT with hosted x-load
+// Load x-load in the phone
+a 0x20010000
+// Check README to generate x-load.bin
+f x-load.bin
+
+// Boot with x-load
+a 0x20010c00
+b
+
+end
+/////////////////////////////////////////////////////////////////// X-LOAD END
+
 /////////////////////////////////////////////////////////////////// DUMP MEM
 // Send an address
 a 0x20000000
 
-// Dump 8kB from that address
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 512 octets
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 1ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 2ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 3ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 4ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 5ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 6ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 7ko
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 
-M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M // 8ko
+// Dump from that address
+M;M;M;M;M;M;M;M;M;M;M;M;M;M;M;M
 
 end
Index: tt-loader/crc32.c
===================================================================
--- tt-loader/crc32.c	(revision 12)
+++ tt-loader/crc32.c	(revision 12)
@@ -0,0 +1,93 @@
+/*
+ * This file is derived from the one provided with u-boot. Check
+ * u-boot to find related files.
+ */
+
+/*
+ * This file is derived from crc32.c from the zlib-1.1.3 distribution
+ * by Jean-loup Gailly and Mark Adler.
+ */
+
+/* crc32.c -- compute the CRC-32 of a data stream
+ * Copyright (C) 1995-1998 Mark Adler
+ * For conditions of distribution and use, see copyright notice in zlib.h
+ */
+
+/* ========================================================================
+ * Table of CRC-32's of all single-byte values (made by make_crc_table)
+ */
+static const unsigned long crc_table[256] = {
+  0x00000000L, 0x77073096L, 0xee0e612cL, 0x990951baL, 0x076dc419L,
+  0x706af48fL, 0xe963a535L, 0x9e6495a3L, 0x0edb8832L, 0x79dcb8a4L,
+  0xe0d5e91eL, 0x97d2d988L, 0x09b64c2bL, 0x7eb17cbdL, 0xe7b82d07L,
+  0x90bf1d91L, 0x1db71064L, 0x6ab020f2L, 0xf3b97148L, 0x84be41deL,
+  0x1adad47dL, 0x6ddde4ebL, 0xf4d4b551L, 0x83d385c7L, 0x136c9856L,
+  0x646ba8c0L, 0xfd62f97aL, 0x8a65c9ecL, 0x14015c4fL, 0x63066cd9L,
+  0xfa0f3d63L, 0x8d080df5L, 0x3b6e20c8L, 0x4c69105eL, 0xd56041e4L,
+  0xa2677172L, 0x3c03e4d1L, 0x4b04d447L, 0xd20d85fdL, 0xa50ab56bL,
+  0x35b5a8faL, 0x42b2986cL, 0xdbbbc9d6L, 0xacbcf940L, 0x32d86ce3L,
+  0x45df5c75L, 0xdcd60dcfL, 0xabd13d59L, 0x26d930acL, 0x51de003aL,
+  0xc8d75180L, 0xbfd06116L, 0x21b4f4b5L, 0x56b3c423L, 0xcfba9599L,
+  0xb8bda50fL, 0x2802b89eL, 0x5f058808L, 0xc60cd9b2L, 0xb10be924L,
+  0x2f6f7c87L, 0x58684c11L, 0xc1611dabL, 0xb6662d3dL, 0x76dc4190L,
+  0x01db7106L, 0x98d220bcL, 0xefd5102aL, 0x71b18589L, 0x06b6b51fL,
+  0x9fbfe4a5L, 0xe8b8d433L, 0x7807c9a2L, 0x0f00f934L, 0x9609a88eL,
+  0xe10e9818L, 0x7f6a0dbbL, 0x086d3d2dL, 0x91646c97L, 0xe6635c01L,
+  0x6b6b51f4L, 0x1c6c6162L, 0x856530d8L, 0xf262004eL, 0x6c0695edL,
+  0x1b01a57bL, 0x8208f4c1L, 0xf50fc457L, 0x65b0d9c6L, 0x12b7e950L,
+  0x8bbeb8eaL, 0xfcb9887cL, 0x62dd1ddfL, 0x15da2d49L, 0x8cd37cf3L,
+  0xfbd44c65L, 0x4db26158L, 0x3ab551ceL, 0xa3bc0074L, 0xd4bb30e2L,
+  0x4adfa541L, 0x3dd895d7L, 0xa4d1c46dL, 0xd3d6f4fbL, 0x4369e96aL,
+  0x346ed9fcL, 0xad678846L, 0xda60b8d0L, 0x44042d73L, 0x33031de5L,
+  0xaa0a4c5fL, 0xdd0d7cc9L, 0x5005713cL, 0x270241aaL, 0xbe0b1010L,
+  0xc90c2086L, 0x5768b525L, 0x206f85b3L, 0xb966d409L, 0xce61e49fL,
+  0x5edef90eL, 0x29d9c998L, 0xb0d09822L, 0xc7d7a8b4L, 0x59b33d17L,
+  0x2eb40d81L, 0xb7bd5c3bL, 0xc0ba6cadL, 0xedb88320L, 0x9abfb3b6L,
+  0x03b6e20cL, 0x74b1d29aL, 0xead54739L, 0x9dd277afL, 0x04db2615L,
+  0x73dc1683L, 0xe3630b12L, 0x94643b84L, 0x0d6d6a3eL, 0x7a6a5aa8L,
+  0xe40ecf0bL, 0x9309ff9dL, 0x0a00ae27L, 0x7d079eb1L, 0xf00f9344L,
+  0x8708a3d2L, 0x1e01f268L, 0x6906c2feL, 0xf762575dL, 0x806567cbL,
+  0x196c3671L, 0x6e6b06e7L, 0xfed41b76L, 0x89d32be0L, 0x10da7a5aL,
+  0x67dd4accL, 0xf9b9df6fL, 0x8ebeeff9L, 0x17b7be43L, 0x60b08ed5L,
+  0xd6d6a3e8L, 0xa1d1937eL, 0x38d8c2c4L, 0x4fdff252L, 0xd1bb67f1L,
+  0xa6bc5767L, 0x3fb506ddL, 0x48b2364bL, 0xd80d2bdaL, 0xaf0a1b4cL,
+  0x36034af6L, 0x41047a60L, 0xdf60efc3L, 0xa867df55L, 0x316e8eefL,
+  0x4669be79L, 0xcb61b38cL, 0xbc66831aL, 0x256fd2a0L, 0x5268e236L,
+  0xcc0c7795L, 0xbb0b4703L, 0x220216b9L, 0x5505262fL, 0xc5ba3bbeL,
+  0xb2bd0b28L, 0x2bb45a92L, 0x5cb36a04L, 0xc2d7ffa7L, 0xb5d0cf31L,
+  0x2cd99e8bL, 0x5bdeae1dL, 0x9b64c2b0L, 0xec63f226L, 0x756aa39cL,
+  0x026d930aL, 0x9c0906a9L, 0xeb0e363fL, 0x72076785L, 0x05005713L,
+  0x95bf4a82L, 0xe2b87a14L, 0x7bb12baeL, 0x0cb61b38L, 0x92d28e9bL,
+  0xe5d5be0dL, 0x7cdcefb7L, 0x0bdbdf21L, 0x86d3d2d4L, 0xf1d4e242L,
+  0x68ddb3f8L, 0x1fda836eL, 0x81be16cdL, 0xf6b9265bL, 0x6fb077e1L,
+  0x18b74777L, 0x88085ae6L, 0xff0f6a70L, 0x66063bcaL, 0x11010b5cL,
+  0x8f659effL, 0xf862ae69L, 0x616bffd3L, 0x166ccf45L, 0xa00ae278L,
+  0xd70dd2eeL, 0x4e048354L, 0x3903b3c2L, 0xa7672661L, 0xd06016f7L,
+  0x4969474dL, 0x3e6e77dbL, 0xaed16a4aL, 0xd9d65adcL, 0x40df0b66L,
+  0x37d83bf0L, 0xa9bcae53L, 0xdebb9ec5L, 0x47b2cf7fL, 0x30b5ffe9L,
+  0xbdbdf21cL, 0xcabac28aL, 0x53b39330L, 0x24b4a3a6L, 0xbad03605L,
+  0xcdd70693L, 0x54de5729L, 0x23d967bfL, 0xb3667a2eL, 0xc4614ab8L,
+  0x5d681b02L, 0x2a6f2b94L, 0xb40bbe37L, 0xc30c8ea1L, 0x5a05df1bL,
+  0x2d02ef8dL
+};
+
+/* ========================================================================= */
+#define DO1(buf) crc = crc_table[((int)crc ^ (*buf++)) & 0xff] ^ (crc >> 8);
+#define DO2(buf)  DO1(buf); DO1(buf);
+#define DO4(buf)  DO2(buf); DO2(buf);
+#define DO8(buf)  DO4(buf); DO4(buf);
+
+/* ========================================================================= */
+unsigned long crc32( unsigned long crc, char* buf, unsigned int len)
+{
+    crc = crc ^ 0xffffffffL;
+    while (len >= 8)
+    {
+      DO8(buf);
+      len -= 8;
+    }
+    if (len) do {
+      DO1(buf);
+    } while (--len);
+    return crc ^ 0xffffffffL;
+}
Index: tt-loader/kernel-extract.sh
===================================================================
--- tt-loader/kernel-extract.sh	(revision 12)
+++ tt-loader/kernel-extract.sh	(revision 12)
@@ -0,0 +1,107 @@
+#! /bin/sh
+#
+# copyright - PKG.fr - 2008
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2 of the License, or
+# (at your option) any later version.
+# 
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU Library General Public License for more details.
+# 
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin Street, Fifth Floor Boston, MA 02110-1301,  USA
+
+echo
+echo "kernel extract v0.1"
+echo
+
+if [ ! -s "$1" ]; then
+	echo "You must provide the extracted MTD file as first argument"
+	exit 1
+fi
+
+MTD="$1"
+BIN="$2"
+
+# Update BIN to default if not set
+: ${BIN:=uImage.bin}
+
+function get_int () {
+	Hex="0x"
+	let i=0 offset=$1
+	while (( i < 4 ))
+	do
+		Chr=$( dd if="$MTD" bs=1 count=1 skip=$((offset+i)) 2>/dev/null )
+		Chr=$( printf '%d' "'$Chr" )
+		#echo $Chr 1>&2
+		(( Chr < 0 )) && let Chr+=256
+		Hex="$Hex$( printf '%02lX' $Chr )"
+		#echo $Hex 1>&2
+		let i++
+	done
+	echo "$Hex"
+}
+
+function get_str () {
+	Str=""
+	let Ascii=1 offset=$1
+	while (( Ascii > 0 ))
+	do
+		Chr=$( dd if="$MTD" bs=1 count=1 skip=$((offset)) 2>/dev/null )
+		Ascii=$( printf '%d' "'$Chr" )
+		(( Ascii > 31 && Ascii < 127 )) && Str="$Str$Chr"
+		(( ++offset >= 0x40 )) && break
+	done
+	echo "$Str"
+}
+
+# uImage.bin header used by u-boot
+MAGIC=$(get_int 0)
+HCRC=$(get_int 4)
+TIME=$(get_int 8)
+SIZE=$(get_int 12)
+ADDR=$(get_int 16)
+ADDS=$(get_int 20)
+DCRC=$(get_int 24)
+ARCH=$(get_int 28)
+VERS=$(get_str 32)
+
+printf "Magic=%s HCRC=%d Timestamp=%d DCRC=%d Arch=%s\n\n" $MAGIC $HCRC $TIME $DCRC $ARCH
+printf "Kernel size = %d\nKernel should be loaded at %s address, entry point is %s\n" $SIZE $ADDR $ADDS
+echo "Linux version: $VERS"
+echo
+
+if [ "$MAGIC" != "0x27051956" ]; then
+	echo "Error: Found wrong magic value at offset 0" 1>&2
+	exit 4
+fi
+
+TEST=$(get_int $(($INT1+0x40)) )
+(( TEST )) && echo "Warning: bytes after the kernel are not null"
+
+if (( SIZE > 4096000 )); then
+	echo "The kernel size seems too high, can't process"
+	exit 2
+fi
+
+# Keeping header to get uImage.bin
+let SIZE+=64
+
+# Copy kernel with dd using 4 bytes block size to have minimum performance
+dd if=$MTD of=$BIN bs=4 count=$((SIZE/4))
+
+echo
+CTRL=$( wc -c "$BIN" | cut -d ' ' -f 1 )
+if [ "$CTRL" -eq "$((SIZE+64))" ]; then
+	echo "Kernel extracted to '$BIN'"
+	echo
+else
+	echo "Kernel extraction failed ($CTRL!=$((SIZE)))"
+	echo
+	exit 3
+fi
Index: tt-loader/main.c
===================================================================
--- tt-loader/main.c	(revision 11)
+++ tt-loader/main.c	(revision 12)
@@ -33,4 +33,6 @@
 #include <errno.h>
 
+extern unsigned long crc32( unsigned long crc, char* buf, unsigned int len);
+
 /*
  * Here Vendor/Product detected for the target device
@@ -43,23 +45,29 @@
 
 /*
- * Length of memory dump done by 2nd.bin
+ * Length of memory dump lines
  */
-#define MEM_READ_SIZE		32
+#define DUMP_LINE_SIZE		32
 
 struct mem_file {
 	void *content ;
 	int size ;
+	char *filename ;
 };
 
+/*
+ * MAX_SIZE is the maximum size of the 2nd.bin program
+ */
 #define	MAX_SIZE	65536
+#define CHUNK_SIZE	8192
 static char	buffer[MAX_SIZE + 128];
 static int	buffsize = 0;
-static struct mem_file cmdfile = { NULL, 0 };
+static struct mem_file cmdfile = { NULL, 0, NULL };
 static double btime ;
 static double ticks ;
 
 #define log1(X)		fprintf(stderr, "%9.3f: "X,((double)times(NULL)-btime)/ticks)
-#define log2(X,Y) 	fprintf(stderr, "%9.3f: "X,((double)times(NULL)-btime)/ticks,Y)
-#define log3(X,Y,Z)	fprintf(stderr, "%9.3f: "X,((double)times(NULL)-btime)/ticks,Y,Z)
+#define log2(X,Y) 	fprintf(stderr, "%9.3f: "X,((double)times(NULL)-btime)/ticks,(Y))
+#define log3(X,Y,Z)	fprintf(stderr, "%9.3f: "X,((double)times(NULL)-btime)/ticks,(Y),(Z))
+#define log4(W,X,Y,Z)	fprintf(stderr, "%9.3f: "W,((double)times(NULL)-btime)/ticks,(X),(Y),(Z))
 
 #if __BYTE_ORDER == __LITTLE_ENDIAN
@@ -71,5 +79,5 @@
 #endif
 
-static inline unsigned do_div (unsigned v, unsigned d)
+static inline unsigned roundup (unsigned v, unsigned d)
 {
 	v+= --d;
@@ -92,5 +100,4 @@
 {
 	int	res, len = 5 ;
-	char buffer[64];
 	
 	buffer[0]= 'T';
@@ -101,4 +108,6 @@
 	if (src!=NULL)
 		len += stringcopy (&buffer[4], src, 60);
+	else
+		len = 4 ;
 	buffer[63]= '\0' ; // truncate anyway
 	
@@ -106,5 +115,5 @@
 	if (res < len)
 	{
-		fprintf (stderr, "Error in usb_bulk_write during send_char: %d/4\n", res);
+		log2("Error in usb_bulk_write during send_char: %d/4\n", res);
 		return 0;
 	}
@@ -113,18 +122,17 @@
 }
 
-static int send_binsize (usb_dev_handle *handle, int sz)
+static int send_binsize (usb_dev_handle *handle, int size)
 {
 	int	res;
-	char	buffer[8];
 	buffer[0]= 'T';
 	buffer[1]= 'I';
 	buffer[2]= 'S';
 	buffer[3]= 's';
-	*(u_int32_t *) &buffer[4]= cpu_to_le32 ((sz>4096)?4096:sz);
+	*(u_int32_t *) &buffer[4]= cpu_to_le32 ( size < CHUNK_SIZE ? size : CHUNK_SIZE );
 	
 	res= usb_bulk_write (handle, OUT_EP, buffer, 8, 1000);
 	if (res < 8)
 	{
-		fprintf (stderr, "Error in usb_bulk_write during send_binsize: %d/8\n", res);
+		log2("Error in usb_bulk_write during send_binsize: %d/8\n", res);
 		return 0;
 	}
@@ -133,18 +141,17 @@
 }
 
-static int send_address (usb_dev_handle *handle, int addr)
+static int send_word (usb_dev_handle *handle, const char req, int word)
 {
 	int	res;
-	char	buffer[8];
 	buffer[0]= 'T';
 	buffer[1]= 'I';
 	buffer[2]= 'S';
-	buffer[3]= 'a';
-	*(u_int32_t *) &buffer[4]= cpu_to_le32 (addr);
+	buffer[3]= req;
+	*(u_int32_t *) &buffer[4]= cpu_to_le32 (word);
 	
 	res= usb_bulk_write (handle, OUT_EP, buffer, 8, 1000);
 	if (res < 8)
 	{
-		fprintf (stderr, "Error in usb_bulk_write: %d/8\n", res);
+		log2("Error in usb_bulk_write: %d/8\n", res);
 		return 0;
 	}
@@ -153,12 +160,31 @@
 }
 
-static struct mem_file readfile( const char *filename )
+static int send_poke (usb_dev_handle *handle, int poke)
 {
-	struct mem_file toread = { NULL, 0 };
+	int	res;
+	buffer[0]= 'T';
+	buffer[1]= 'I';
+	buffer[2]= 'S';
+	buffer[3]= 'p';
+	*(u_int32_t *) &buffer[4]= cpu_to_le32 (poke);
+	
+	res= usb_bulk_write (handle, OUT_EP, buffer, 8, 1000);
+	if (res < 8)
+	{
+		log2("Error in usb_bulk_write: %d/8\n", res);
+		return 0;
+	}
+	
+	return 1;
+}
+
+static struct mem_file readfile( char *filename )
+{
+	struct mem_file toread = { NULL, 0, NULL };
 	int fd= open (filename, O_RDONLY);
 	
 	if (fd < 0)
 	{
-		fprintf (stderr, "Error opening %s file\n", filename);
+		log3("Error opening %s file (err=%d)\n", filename, errno);
 		return toread;
 	}
@@ -167,13 +193,13 @@
 	if (toread.size < 0  ||  lseek (fd, 0, SEEK_SET) < 0)
 	{
-		fprintf (stderr, "Error with lseek other %s file\n", filename);
+		log3("Error with lseek other %s file (err=%d)\n", filename, errno);
 		close (fd);
 		return toread;
 	}
 	
-	toread.content= malloc (do_div (toread.size, 4));
+	toread.content= malloc (roundup (toread.size, 4));
 	if (toread.content == NULL)
 	{
-		fprintf (stderr, "Out of memory requesting %d bytes\n", toread.size);
+		log2("Out of memory requesting %d bytes\n", toread.size);
 		close (fd);
 		return toread;
@@ -182,5 +208,5 @@
 	if ((toread.size= read (fd, toread.content, toread.size)) < 0)
 	{
-		fprintf (stderr, "Error reading %s file\n", filename);
+		log3("Error reading %s file (err=%d)\n", filename, errno);
 		close (fd);
 		return toread;
@@ -190,4 +216,26 @@
 	
 	return toread ;
+}
+
+static int savefile( char *filename, struct mem_file buffer )
+{
+	int fd= creat (filename, S_IRUSR|S_IWUSR|S_IRGRP|S_IWGRP|S_IROTH );
+	
+	if (fd < 0)
+	{
+		log3("Error opening %s file for writing (err=%d)\n", filename, errno);
+		return 1;
+	}
+	
+	if (buffer.size != write (fd, buffer.content, buffer.size))
+	{
+		log3("Error writing %s file (err=%d)\n", filename, errno);
+		close (fd);
+		return 1;
+	}
+	
+	close (fd);
+	
+	return 0 ;
 }
 
@@ -218,7 +266,6 @@
 	else
 	{
-		char	inbuff[256];
-		int	insize= usb_bulk_read (handle, IN_EP,
-			inbuff, sizeof (inbuff), 5000);
+		char inbuff[MAX_SIZE + 128];
+		int	insize= usb_bulk_read (handle, IN_EP, inbuff, sizeof (inbuff), 1000);
 		
 		if (insize < 48)
@@ -235,13 +282,14 @@
 			while (size > 0)
 			{
-				int	outsize= usb_bulk_write (handle, OUT_EP, p, 64, 5000);
-				if (outsize < 64)
+				int chunksize = size < CHUNK_SIZE ? size : CHUNK_SIZE ;
+				int	outsize = usb_bulk_write (handle, OUT_EP, p, chunksize, 1000);
+				if (outsize < chunksize)
 				{
-					log2("Error in usb_bulk_write: %d/64\n", outsize);
+					log3("Error in usb_bulk_write: %d/%d\n", outsize,chunksize);
 					break;
 				}
 
-				p+= 64;
-				size-= 64;
+				p+= chunksize;
+				size-= chunksize;
 			}
 			
@@ -249,13 +297,12 @@
 			{
 				log2("Sent %d bytes to OMAP\n",buffsize);
-				usb_bulk_write (handle, OUT_EP, buffer, 0, 1000);
 				
 				p= NULL;
 				size= 0;
 				
-				int	res=1, sz= 0, loop= 1, cmd=0 ;
+				int	res=1, sz= 0, loop= 1, cmd=0, ftag=0, finfo=0, fline=0 ;
 				int vendor, device, info ;
 				char *cmdp = cmdfile.content ;
-				struct mem_file current = { NULL, 0 };
+				struct mem_file current = { NULL, 0, NULL };
 				
 				err = 1 ; // Set error by default
@@ -265,5 +312,5 @@
 					if (loop<0) loop++ ; // Avoid infinite loop
 					
-					if (res>0)
+					if (res>0 || ftag)
 						res= usb_bulk_read (handle, IN_EP,
 							inbuff, sizeof (inbuff), 5000);
@@ -275,4 +322,61 @@
 					}
 					
+					if (ftag)
+					{
+						switch (ftag)
+						{
+							case 0xaaaa0001:
+								// A string should be in the buffer with length still set in finfo
+								if ( res != finfo)
+								{
+									log3("Error waiting string from flasher program: length = %d vs %d expected\n", res, finfo);
+									break ;
+								}
+								// Fix the string just in case
+								inbuff[res] = '\0' ;
+								if (fline)
+									fprintf(stderr, "%s",inbuff);
+								else
+									log2("Flasher: %s", inbuff);
+								if ( inbuff[res-1] == '\n' )
+									fline = 0 ;
+								else
+									fline ++ ;
+								break ;
+							case 0xaaaa0002:
+								finfo = le32_to_cpu (*(u_int32_t *) inbuff);
+								break ;
+							case 0xaaaa0003:
+								finfo = le32_to_cpu (*(u_int32_t *) inbuff);
+								log2("Flasher: NAND read = 0x%08X\n", finfo);
+								break ;
+							case 0xaaaa0004:
+								finfo = le32_to_cpu (*(u_int32_t *) inbuff);
+								log2("Flasher: NAND size = 0x%08X\n", finfo);
+								break ;
+							case 0xaaaa0005:
+								finfo = le32_to_cpu (*(u_int32_t *) inbuff);
+								log2("Flasher: Error code = %d\n", finfo);
+								err = - finfo ; // Will quit on error
+								break ;
+							case 0xaaaa0006:
+								finfo = le32_to_cpu (*(u_int32_t *) inbuff);
+								log2("Flasher: NAND remain = 0x%08X\n", finfo);
+								break ;
+						}
+						ftag = 0 ;
+						continue ;
+					}
+					
+					if (err<0)
+					{
+						err = -err ; // Keep err as positive number
+						if (send_cmd (handle,'e',NULL))
+							log1("Asking stop\n");
+						else
+							log1("Can't ask to stop\n");
+						break ; // Leave loop
+					}
+
 					if (res >= 4)
 					{
@@ -305,5 +409,5 @@
 								sz= le32_to_cpu (*(u_int32_t *) &inbuff[4]);
 								//log2("OMAP read %d\n", sz); 					// DEBUG
-								res= usb_bulk_write (handle, OUT_EP, p, sz, 5000);
+								res= usb_bulk_write (handle, OUT_EP, p, sz, 1000);
 								if (res < sz)
 								{
@@ -318,7 +422,19 @@
 								break;
 								
+							case 'x':
+								info = le32_to_cpu (*(u_int32_t *) &inbuff[4]);
+								u_int32_t len = le32_to_cpu (*(u_int32_t *) &inbuff[8]);
+								u_int32_t crc = le32_to_cpu (*(u_int32_t *) &inbuff[12]);
+								log4("OMAP crc32 computing: pos 0x%08x/0x%08x, current crc32 0x%08X\n",info,len,crc);
+								break;
+								
 							case 'A':
 								info = le32_to_cpu (*(u_int32_t *) &inbuff[4]);
 								log2("OMAP address info: 0x%08X\n", info);
+								break;
+								
+							case 'C':
+								info = le32_to_cpu (*(u_int32_t *) &inbuff[4]);
+								log2("OMAP crc32 found: 0x%08X\n", info);
 								break;
 								
@@ -343,19 +459,62 @@
 								break;
 								
+							case 'D':
+								if (!current.content)
+								{
+									log1("Can't dump memory without buffer\n");
+									loop = 0 ;
+									break ;
+								}
+								res -= 4 ;
+								if (res < 1)
+								{
+									log2("Received empty memory dump (res=%d)\n",res);
+									// reset buffer size anyway
+									current.size = 0 ;
+									res = 0 ; // Target is waiting a new command
+									
+								} else {
+									if (res > size)
+									{
+										log2("Can't dump %d bytes as buffer is full\n",res);
+										loop = 0 ;
+										break ;
+									}
+									memcpy(p,&inbuff[4],res);
+									p += res ;
+									size -= res ;
+								}
+								if ( size == 0 )
+								{
+									log2("%d bytes dumped to buffer\n",current.size);
+									res = 0 ; // Target is waiting a new command
+								}
+								break;
+								
 							case 'M':
-								loop=3 ;
-								log2("0x%08X | ",info);
-								while (++loop<36)
-									fprintf (stderr,"%02hhX", inbuff[loop]);
-								loop=3 ;
-								fprintf (stderr, " |");
-								while (++loop<36)
-									if ((int)inbuff[loop]>=0x20 && (int)inbuff[loop]<0x7f)
-										fprintf (stderr,"%c", inbuff[loop]);
-									else
-										fprintf (stderr,".");
-								fprintf (stderr,"|\n");
+								sz = 0 ;
+								res -= 4 ;
+								while (sz<res)
+								{
+									log2("0x%08X | ",info);
+									
+									loop=0 ;
+									while (++loop<=DUMP_LINE_SIZE)
+										fprintf (stderr,"%02hhX", inbuff[3+sz+loop]);
+									fprintf (stderr, " |");
+									
+									loop=0 ;
+									while (++loop<=DUMP_LINE_SIZE)
+										if ((int)inbuff[3+sz+loop]>=0x20 && (int)inbuff[3+sz+loop]<0x7f)
+											fprintf (stderr,"%c", inbuff[3+sz+loop]);
+										else
+											fprintf (stderr,".");
+									
+									fprintf (stderr,"|\n");
+									
+									info += DUMP_LINE_SIZE;
+									sz += DUMP_LINE_SIZE;
+								}
 								res = 0 ; // Target is waiting a new command
-								info += 32 ;
 								break;
 								
@@ -369,5 +528,5 @@
 								info = le32_to_cpu (*(u_int32_t *) &inbuff[4]);
 								log2("OMAP is booting at address: 0x%08X\n", info);
-								res = 0 ; // Target is waiting a new command
+								loop = err = res = 0 ; // Quit now
 								break;
 
@@ -376,8 +535,31 @@
 								break;
 							}
-						} else {
-							// Fix the string just in case
-							inbuff[res] = '\0' ;
-							log2("Got: %s\n", inbuff);
+						} else
+						{
+							info = le32_to_cpu (*(u_int32_t *) inbuff);
+							switch (info)
+							{
+								case 0xaaaa0001:
+								case 0xaaaa0002:
+								case 0xaaaa0003:
+								case 0xaaaa0004:
+								case 0xaaaa0005:
+								case 0xaaaa0006:
+									ftag = info ;
+									break ;
+								case 0xff555580:
+									log1("Flasher: Command finished\n");
+									break ;
+								default:
+									// Fix the string just in case
+									inbuff[res] = '\0' ;
+									// Strip final EOL in the string
+									if ( inbuff[res-1] == '\n' )
+										inbuff[res-1] = '\0' ;
+									if (res==4)
+										log3("Got: %s (0x%08X)\n", inbuff, info);
+									else
+										log2("Got: %s\n", inbuff);
+							}
 						}
 					}
@@ -397,4 +579,66 @@
 							switch (cmdp[cmd])
 							{
+							case 'D': // Save downloaded memory to a file still specified
+								if (current.filename == NULL)
+								{
+									log1("Can't save without a file specified with 'F' command\n");
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								if (current.content == NULL)
+								{
+									log2("Can't save without download buffer to file '%s'\n",current.filename);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								if (current.size==0)
+									log2("Nothing to save, file %s is still up to date\n",current.filename);
+								else if (savefile(current.filename, current)==0)
+								{
+									info = crc32(0,current.content,current.size);
+									log3("Downloaded memory saved to file %s with CRC32=0x%08X\n",current.filename,info);
+								} else
+								{
+									log2("Can't save downloaded memory saved to file %s\n",current.filename);
+									// Just quit on error
+									loop = 0 ;
+								}
+								// Release memory
+								free((void *)current.content);
+								free((void *)current.filename);
+								current.content = NULL ;
+								current.filename = NULL ;
+								res -- ;
+								break;
+							case 'd': // Save downloaded memory to a file
+								cmd += 2 ;
+								if (cmd >= cmdfile.size || cmdp[cmd] == '\0')
+								{
+									log1("Bad 'd' format in command download\n");
+									break ;
+								}
+								if (current.content == NULL)
+								{
+									log2("Can't save without download buffer to file '%s'\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								if (current.size==0)
+									log2("Nothing to save, file %s is still up to date\n",&cmdp[cmd]);
+								else if (savefile(&cmdp[cmd], current)==0)
+								{
+									info = crc32(0,current.content,current.size);
+									log3("Downloaded memory saved to file %s with CRC32=0x%08X\n",&cmdp[cmd],info);
+								} else
+								{
+									log2("Can't save downloaded memory saved to file %s\n",&cmdp[cmd]);
+									// Just quit on error
+									loop = 0 ;
+								}
+								// Release memory
+								free((void *)current.content);
+								current.content = NULL ;
+								res -- ;
+								break;
 							case 'f': // Put a file to be uploaded in a memory buffer
 								cmd += 2 ;
@@ -407,9 +651,10 @@
 								if (current.content != NULL)
 									free((void *)current.content);
-								current = readfile((const char *)&cmdp[cmd]);
+								current = readfile(&cmdp[cmd]);
 								if (current.content == NULL)
 								{
 									log2("Can't read file '%s'\n",&cmdp[cmd]);
 									loop = 0 ; // Just quit on error
+									break ;
 								}
 								p = current.content ;
@@ -425,4 +670,67 @@
 								}
 								break;
+							case 'F': // Set a filename that would be loaded to check crc and saved
+								cmd += 2 ;
+								if (cmd >= cmdfile.size || cmdp[cmd] == '\0')
+								{
+									log1("Bad 'F' format in command file\n");
+									break ;
+								}
+								// Free previously used memory buffer
+								if (current.filename != NULL)
+									free((void *)current.filename);
+								info = strlen(&cmdp[cmd]);
+								if (info == 0)
+								{
+									log2("Can't read filename '%s' length\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								current.filename = malloc (++info);
+								if (current.filename == NULL)
+								{
+									log2("Out of memory requesting %d bytes\n", info);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								if (info!=stringcopy(current.filename,&cmdp[cmd],info))
+								{
+									log2("Can't read filename '%s'\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								// still read next command
+								res -- ;
+								break;
+							case 'C': // Get a CRC32 and send it to target
+								cmd += 2 ;
+								if (sscanf((const char *)&cmdp[cmd], "%i", &info) != 1)
+								{
+									log2("Can't read crc32 '%s'\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								// compute the current CRC32 if a file is referenced and exists
+								if (!info && current.filename != NULL)
+								{
+									struct mem_file loader = readfile(current.filename);
+									if (loader.content == NULL)
+									{
+										log2("Can't read file '%s', will be initialized with target\n",current.filename);
+									} else
+									{
+										log3("Checking CRC32 of %d bytes from %s file\n",loader.size,current.filename);
+										info = crc32(0,loader.content,loader.size);
+										free(loader.content);
+									}
+								}
+								if (send_word (handle, 'C', info))
+									log2("Sending crc32 0x%02X\n", info);
+								else
+								{
+									log2("Can't send crc32 0x%02X\n", info);
+									loop = 0 ; // Just quit on error
+								}
+								break;
 							case 'a': // Get an address and send it to target
 								cmd += 2 ;
@@ -431,6 +739,7 @@
 									log2("Can't read address '%s'\n",&cmdp[cmd]);
 									loop = 0 ; // Just quit on error
-								}
-								if (send_address (handle, info))
+									break ;
+								}
+								if (send_word (handle, 'a', info))
 									log2("Sending address 0x%02X\n", info);
 								else
@@ -440,8 +749,53 @@
 								}
 								break;
+							case 'm': // Get a size in kB and ask a memory download
+								cmd += 2 ;
+								if (sscanf((const char *)&cmdp[cmd], "%i", &info) != 1)
+								{
+									log2("Can't read size '%s'\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								// size unit is kbytes
+								size = info * 1024 ;
+								// Free previously used memory buffer
+								if (current.content != NULL)
+									free((void *)current.content);
+								current.size = size ;
+								p = malloc (roundup (size, 4));
+								if ( p == NULL)
+								{
+									log2("Out of memory requesting %d bytes\n", roundup (size, 4));
+									loop=0 ;
+									break ;
+								}
+								current.content = p ;
+								if (!(send_word (handle,'m',size)))
+								{
+									log2("Can't ask to download %d bytes from memory\n",size);
+									loop = 0 ; // Just quit on error
+								} else
+									log2("Allocated %d kBytes to download memory\n",info);
+								break;
 							case 'M': // Ask memory dump
 								if (!(send_cmd (handle,'M',NULL)))
 								{
 									log1("Can't ask to read memory\n");
+									loop = 0 ; // Just quit on error
+								}
+								break;
+							case 'P': // Ask a peek onto the address
+								if (!(send_cmd (handle,'P',NULL)))
+								{
+									log1("Can't ask to peek memory\n");
+									loop = 0 ; // Just quit on error
+								}
+								break;
+							case 'S': // Ask to change stack to the last given address
+								if (send_cmd (handle,'S',NULL))
+									log1("Asking stack relocate\n");
+								else
+								{
+									log1("Can't ask to relocate stack\n");
 									loop = 0 ; // Just quit on error
 								}
@@ -457,7 +811,11 @@
 								break;
 							case 'b': // Boot the target by just branching to the last given address
-								if (send_cmd (handle,'b',NULL))
+								if (send_cmd (handle,'b',NULL)) {
 									log1("Asking boot\n");
-								else
+									// Quit now witout error set
+									loop = err = -10 ;
+									cmd = cmdfile.size ;
+									res = 1 ;
+								} else
 								{
 									log1("Can't ask to boot\n");
@@ -467,4 +825,8 @@
 							case 'e': // End of commands
 								log1("Commands read and sent\n");
+								if (send_cmd (handle,'e',NULL))
+									log1("Asking stop\n");
+								else
+									log1("Can't ask to stop\n");
 								// Quit now witout error set
 								loop = err = 0 ;
@@ -472,5 +834,43 @@
 								res = 1 ;
 								break ;
+							case 'k': // Boot a linux kernel to the last given address
+								cmd += 2 ;
+								if (sscanf((const char *)&cmdp[cmd], "%i", &info) != 1)
+								{
+									log2("Can't read mach id '%s'\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								if (send_word (handle,'k', info)) {
+									log1("Asking kernel to boot\n");
+									// Quit now witout error set
+									loop = err = -10 ;
+									cmd = cmdfile.size ;
+									res = 1 ;
+								} else
+								{
+									log1("Can't ask to boot a kernel\n");
+									loop = 0 ; // Just quit on error
+								}
+								break;
+							case 'p': // poke
+								cmd += 2 ;
+								if (sscanf((const char *)&cmdp[cmd], "%i", &info) != 1)
+								{
+									log2("Can't read value to poke '%s'\n",&cmdp[cmd]);
+									loop = 0 ; // Just quit on error
+									break ;
+								}
+								if (send_poke (handle, info))
+									log2("Sending poke 0x%08X\n", info);
+								else
+								{
+									log2("Can't send poke 0x%08X\n", info);
+									loop = 0 ; // Just quit on error
+								}
+								break;
 							case '#':
+								cmd += 2 ;
+								log2("%s\n", &cmdp[cmd]);
 							case '/':
 								// skip comments
@@ -490,4 +890,9 @@
 					}
 				}
+				// Free used memory buffer
+				if (current.content != NULL)
+					free((void *)current.content);
+				if (current.filename != NULL)
+					free((void *)current.filename);
 			}
 		}
@@ -495,7 +900,9 @@
 	
 	if (err>=0) {
+		log1("Releasing usb interface\n");
 		err = usb_release_interface (handle, 0);
 		if (err < 0)
 			log2("Error in usb_release_interface (%d)\n",err);
+		log1("Released usb interface\n");
 	}
 	
@@ -551,5 +958,5 @@
 	}
 	
-	size= do_div (size, 4);
+	size= roundup (size, 4);
 	
 	p[0x21]= cpu_to_le32 (size - 0x40);
@@ -562,5 +969,5 @@
 	p[0x12]= cpu_to_le32 (size);
 	
-	buffsize= 128 + do_div (size, 4);
+	buffsize= 128 + roundup (size, 4);
 	
 	cmdfile = readfile(argv[ARG_CMDFILE]);
@@ -575,4 +982,13 @@
 			if (cmdbuffer[i] == '\n' || cmdbuffer[i] == '\r' || cmdbuffer[i] == ';')
 				cmdbuffer[i] = '\0' ;
+			// Skip comment line
+			if (cmdbuffer[i] == '/') {
+				while ( i++ < cmdfile.size ) {
+					if (cmdbuffer[i] == '\n' || cmdbuffer[i] == '\r') {
+						i-- ;
+						break ;
+					}
+				}
+			}
 		} while ( i++ < cmdfile.size );
 	}
