[*] Emulating binary name: rt3052esw
[*] Emulator used: qemu-mipsel
[*] Using root directory: /logs/s115_usermode_emulator/firmware/unblob_extracted/firmware_extract/DIR-600_fw_revb5_214b01_ALL_de_20130122/dir600b_v2.14_d1mg.bin_extract/1179788-3612812.squashfs_v4_le_extract (1/1)
[*] Using CPU config: NONE
[*] Emulating binary: /usr/sbin/rt3052esw
[*] Emulating binary ./usr/sbin/rt3052esw with parameter NONE
[*] Emulating binary ./usr/sbin/rt3052esw with parameter -v
Ralink rt3052 switch !
[*] Emulating binary ./usr/sbin/rt3052esw with parameter -V
Ralink rt3052 switch !
[*] Emulating binary ./usr/sbin/rt3052esw with parameter -h
Ralink rt3052 switch !
[*] Emulating binary ./usr/sbin/rt3052esw with parameter -help
Ralink rt3052 switch !
[*] Emulating binary ./usr/sbin/rt3052esw with parameter --help
Ralink rt3052 switch !
[*] Emulating binary ./usr/sbin/rt3052esw with parameter --version
Ralink rt3052 switch !
[*] Emulating binary ./usr/sbin/rt3052esw with parameter version
Ralink rt3052 switch !
Ralink rt3052 switch !
For reproducing the EMBA user-mode emulation mechanism, the following commands could be used as starting point:
- Start EMBA docker container with the firmware directory as log directory:
# EMBA="." FIRMWARE="/home/runner/work/emba/emba/DIR-600_fw_revb5_214b01_ALL_de_20130122.zip" LOG="/absolute/path/to/EMBA/log/directory" docker-compose run emba
- Change your working directory to the root directory of your firmware:
# cd /logs/s115_usermode_emulator/firmware/unblob_extracted/firmware_extract/DIR-600_fw_revb5_214b01_ALL_de_20130122/dir600b_v2.14_d1mg.bin_extract/1179788-3612812.squashfs_v4_le_extract
- Copy the static compiled user-mode emulator to your current working directory
# cp $(which qemu-mipsel) .
- Start the emulation with the following command:
# jchroot . -- ./qemu-mipsel ./usr/sbin/rt3052esw <parameters like -v or --help>
WARNING: EMBA is doing some more magic in the background. Probably it is not that easy, but give it a try.