Technology3 min read

Reverse Engineering of the M-VAVE FM-1 Pocket Synthesizer Firmware

By · Published by Everything Blog

In short

The M-VAVE FM-1 synthesizer firmware reverse engineering project has identified the target as the JieLi AC791N/WL82 microcontroller with a pi32v2 CPU and XIP flash memory at 0x02000000. The main branch preserves an experimental implementation, while the with-custom-firmware branch contains no replacement firmware or custom image builders. The update protocol captures USB-MIDI framing, session flow, loader behavior, and unresolved gates, and includes static search for consoles, factory modes, test commands, and recovery entry points. The Windows updater analysis decompiled the M-UPGRADE state machine and identity parsing, and offline tests are available. The repository retains two independen…

Key points

  • Reverse engineering and firmware update protocol research for the M-VAVE FM-1 synthesizer…: Reverse engineering and firmware update protocol research for the M-VAVE FM-1 synthesizer has identified the target as the JieLi AC791N/WL82 microcontroller with a pi32v2 CPU, XIP flash memory at 0x02000000, and a Dexed/msfa-derived six-ope
  • The main branch of the repository contains no replacement firmware or custom image builde…: The main branch of the repository contains no replacement firmware or custom image builders, preserving an experimental implementation on the with-custom-firmware branch.
  • The update protocol is not a demonstrated recovery mechanism, and current work has not es…: The update protocol is not a demonstrated recovery mechanism, and current work has not established ROM recovery, rollback, or safe interrupted-write behavior for the single-bank layout.

Reverse engineering and update-protocol research for the M-Vave FM-1

synthesizer. Package, SPL, and SDK provenance identify the target as JieLi

AC791N/WL82 with a pi32v2 CPU, XIP flash at 0x02000000

, and a

Dexed/msfa-derived six-operator FM engine. The embedded JL-BR22

string is

inherited library nomenclature, not reliable SoC identification.

This main

branch intentionally contains no replacement firmware or custom

image builders. The former experimental implementation is preserved on the

with-custom-firmware

branch.

- Architecture overview: mapped hardware, boot chain, memory layout, and major subsystems.

- OTA protocol: captured USB-MIDI framing, session flow, loader behavior, and unresolved gates.

- Safety verdict and open questions: evidence required before treating any update path as recoverable.

- Debug-surface audit: static search for consoles, factory modes, test commands, and recovery entry points.

- Device OTA loader and finish-gate trace: extraction, control flow, flash gates, and terminal handshake.

- Windows updater analysis: decompiled M-UPGRADE state machine and identity parsing.

- Linux protocol client, tool notes, and offline tests.

- analysis/: V13 disassembly, byte-identical reassembly, function databases, classifications, OTA loader analysis, and host updater decompilation.

- docs/: firmware characterization, architecture, subsystem teardowns, function indexes, and OTA findings.

- scripts/: disassembly, extraction, indexing, and classification pipelines.

- tools/: USB-MIDI update-protocol client and offline tests.

- ghidra/scripts/: checked-in pi32v2 headless-analysis scripts.

- firmware-images/: immutable V13 and V14 packages and unpacked inputs.

reference/

: ignored SDKs, Ghidra installations, and upstream source mirrors populated by scripts/setup_reference.sh.- 3rd-party/jl-misctools and 3rd-party/jl-uboot-tool: pinned submodules used for firmware parsing and boot-tool reference.

The repository retains two independently developed V13 analysis pipelines. analysis/README.md explains their roles. analysis/db.json and docs/function-index.md are the current classification outputs; analysis/function_db.json and analysis/master_index.json provide independent cross-validation and provenance.

Run commands from the repository root:

# Low-level disassembly and independent function map

scripts/run_ghidra.sh

python3 scripts/build_funcdb.py

python3 scripts/resolve_strings.py

python3 scripts/match_libs.py

python3 scripts/build_master_index.py

python3 scripts/build_slices.py

# OTA loader extraction, vendor map, and corroborative Ghidra sweep

scripts/analyze_ota_loader.sh

scripts/run_ghidra_loader.sh

# Current enriched classification database and documentation

python3 scripts/build_db.py

scripts/disasm_toolchain_libs.sh

python3 scripts/match_libs.py

python3 scripts/mech_tag.py

python3 scripts/export_shards.py

python3 scripts/aggregate.py

# Offline OTA protocol checks

python3 -m unittest discover -s tools/tests -v

The update protocol is not a demonstrated recovery mechanism. Current work has not established ROM recovery, rollback, or safe interrupted-write behavior for the single-bank layout. The console/factory-mode audit in analysis/device/debug-surfaces.md found no substitute recovery entry. Read TODO_aug2.md before using any update or flash utility.

- USB_KEY | jielie: reverse-engineered notes on invoking JieLi USB boot using a signal on D+/D-, including the key waveform, acknowledgement, timing, and USB bus caveats.

- JL SoC forum thread: long-running Russian community discussion of JieLi SoCs, SDKs, toolchains, programmers, boot activators, and USB/ISP/UART key experiments. Reports are community observations and may apply only to the chip family being discussed.

- SMK-37 Pro community notes: observations about a related M-Vave/JieLi keyboard that may help identify shared packaging, update, and hardware conventions.

- kagaimiq/jl-misctools

(

3rd-party/jl-misctools

, also checked out at../jl-misctools

): utilities for JieLi firmware containers, key files, UI resources, and older formats. - kagaimiq/jl-uboot-tool

(

3rd-party/jl-uboot-tool

): Python tooling for discovering UBOOT devices, loading code into RAM, and reading, writing, or erasing flash. Its support table lists WL82/AC791N as unknown, so it is not an established FM-1 flasher. - Jieli-Tech/fw-AC79_AIoT_SDK

(

../fw-AC79_AIoT_SDK

): official AC791N/WL82 SDK containing peripheral and MaskROM API headers, boot/update configuration, libraries, build tools, and application examples used to identify stock firmware behavior.

Original source: github.com

Technology