Reverse Engineering of the M-VAVE FM-1 Pocket Synthesizer Firmware
Assembly
51
32 commits
updated Sep 8, 2026
Reverse engineering and update-protocol research for the M-Vave FM-1
synthesizer. Package, SPL, and SDK provenance identify the target as JieLi
AC791N/WL82 with a pi32v2 CPU, XIP flash at 0x02000000, and a
Dexed/msfa-derived six-operator FM engine. The embedded JL-BR22 string is
inherited library nomenclature, not reliable SoC identification.
This main branch intentionally contains no replacement firmware or custom
image builders. The former experimental implementation is preserved on the
with-custom-firmware
branch.
reference/: ignored SDKs, Ghidra installations, and upstream source mirrors
populated by scripts/setup_reference.sh.The repository retains two independently developed V13 analysis pipelines. analysis/README.md explains their roles. analysis/db.json and docs/function-index.md are the current classification outputs; analysis/function_db.json and analysis/master_index.json provide independent cross-validation and provenance.
Run commands from the repository root:
# Low-level disassembly and independent function map
scripts/run_ghidra.sh
python3 scripts/build_funcdb.py
python3 scripts/resolve_strings.py
python3 scripts/match_libs.py
python3 scripts/build_master_index.py
python3 scripts/build_slices.py
# OTA loader extraction, vendor map, and corroborative Ghidra sweep
scripts/analyze_ota_loader.sh
scripts/run_ghidra_loader.sh
# Current enriched classification database and documentation
python3 scripts/build_db.py
scripts/disasm_toolchain_libs.sh
python3 scripts/match_libs.py
python3 scripts/mech_tag.py
python3 scripts/export_shards.py
python3 scripts/aggregate.py
# Offline OTA protocol checks
python3 -m unittest discover -s tools/tests -v
The update protocol is not a demonstrated recovery mechanism. Current work has not established ROM recovery, rollback, or safe interrupted-write behavior for the single-bank layout. The console/factory-mode audit in analysis/device/debug-surfaces.md found no substitute recovery entry. Read TODO_aug2.md before using any update or flash utility.
3rd-party/jl-misctools, also checked out at ../jl-misctools): utilities
for JieLi firmware containers, key files, UI resources, and older formats.3rd-party/jl-uboot-tool): Python tooling for discovering UBOOT devices,
loading code into RAM, and reading, writing, or erasing flash. Its support
table lists WL82/AC791N as unknown, so it is not an established FM-1 flasher.../fw-AC79_AIoT_SDK): official AC791N/WL82 SDK containing peripheral and
MaskROM API headers, boot/update configuration, libraries, build tools, and
application examples used to identify stock firmware behavior.Reverse Engineering of the M-VAVE FM-1 Pocket Synthesizer Firmware
Assembly
51
32 commits
updated Sep 8, 2026
Reverse engineering and update-protocol research for the M-Vave FM-1
synthesizer. Package, SPL, and SDK provenance identify the target as JieLi
AC791N/WL82 with a pi32v2 CPU, XIP flash at 0x02000000, and a
Dexed/msfa-derived six-operator FM engine. The embedded JL-BR22 string is
inherited library nomenclature, not reliable SoC identification.
This main branch intentionally contains no replacement firmware or custom
image builders. The former experimental implementation is preserved on the
with-custom-firmware
branch.
reference/: ignored SDKs, Ghidra installations, and upstream source mirrors
populated by scripts/setup_reference.sh.The repository retains two independently developed V13 analysis pipelines. analysis/README.md explains their roles. analysis/db.json and docs/function-index.md are the current classification outputs; analysis/function_db.json and analysis/master_index.json provide independent cross-validation and provenance.
Run commands from the repository root:
# Low-level disassembly and independent function map
scripts/run_ghidra.sh
python3 scripts/build_funcdb.py
python3 scripts/resolve_strings.py
python3 scripts/match_libs.py
python3 scripts/build_master_index.py
python3 scripts/build_slices.py
# OTA loader extraction, vendor map, and corroborative Ghidra sweep
scripts/analyze_ota_loader.sh
scripts/run_ghidra_loader.sh
# Current enriched classification database and documentation
python3 scripts/build_db.py
scripts/disasm_toolchain_libs.sh
python3 scripts/match_libs.py
python3 scripts/mech_tag.py
python3 scripts/export_shards.py
python3 scripts/aggregate.py
# Offline OTA protocol checks
python3 -m unittest discover -s tools/tests -v
The update protocol is not a demonstrated recovery mechanism. Current work has not established ROM recovery, rollback, or safe interrupted-write behavior for the single-bank layout. The console/factory-mode audit in analysis/device/debug-surfaces.md found no substitute recovery entry. Read TODO_aug2.md before using any update or flash utility.
3rd-party/jl-misctools, also checked out at ../jl-misctools): utilities
for JieLi firmware containers, key files, UI resources, and older formats.3rd-party/jl-uboot-tool): Python tooling for discovering UBOOT devices,
loading code into RAM, and reading, writing, or erasing flash. Its support
table lists WL82/AC791N as unknown, so it is not an established FM-1 flasher.../fw-AC79_AIoT_SDK): official AC791N/WL82 SDK containing peripheral and
MaskROM API headers, boot/update configuration, libraries, build tools, and
application examples used to identify stock firmware behavior.