Cracking the firmware of HiBy's linux devices
Tip
If you just want to see instructions on how to install custom firmware onto your device: here's the guide)
This repo is for:
- Tools to unpack/repack hiby os firmwares
- Documentation on the structure of the firmware
- Documentation on the device (datasheets, ISA, etc.)
- Other tools and information helpful for creating custom firmwares
Note
This project is part of the hiby-modding organization. Also see:
- hiby-r3proii-custom-firmware by noisetta — complementary firmware modding project that adds Arabic text rendering support and documents the proprietary OTA firmware format.
Tip
How Can I Help❓: If you want to help with this project, whether you're a developer or not, look at HOW_CAN_I_HELP.md.
Tip
To talk with the community whether you're a developer or not, you can join the HiBy OS Modding discord: https://discord.gg/mSEuafxPH
I host the discord, and it has the same scope as this project (current HiBy OS devices)
The discord link will expire every once in a while. If you want to join but the link is expired, you can make an issue in this repo, or contact me in whatever other way to inform me.
- The goal of this project is to make it possible to modify the HiBy OS firmware to add custom functionality.
- For now, this project also only focuses on the HiBy OS firmware used by the generation including the R1, R3 II 2025, R3 Pro II, and Tempotec V1. These devices all use the
.uptfirmware format and have an Ingenic X1600E CPU.- Older devices such as the R3 Pro and the R3 Pro Saber used a different format. see hiby-firmware-tools by SuperTaiyaki on GitHub for that older type of firmware
For equivalent functionality on Windows, please see docs/WIN_INSTALL.md.
This repo is applicable to any HiBy OS device that uses the .upt firmware type. However, each device has it's own stock firmware and slightly different hardware.
We have collected documentation and created firmware unpacking/repacking scripts for the following devices:
- HiBy R1
- HiBy R3Pro II
- Hiby R3II 2025
- general upt firmware unpacking script (no helper)
- Can unpack any
.uptfirmware
- Can unpack any
- general upt firmware repacking script (no helper)
- Can repack any unpacked
.uptfirmware
- Can repack any unpacked
- Unpacking and repacking helper scripts. Called
unpack-helper.shandrepack-helper.shexist in theunpacking_and_repackingdirectory for the relevant device.- Base firmwares are already provided
- No configuring needed, just run the script and select what you want
- This helper (automatic) script has only been written for devices that we've collected documentation and firmware for already, so we don't have it for every supported device yet. Feel free to contribute those for new devices.
- this README
- project TODO
- firmware file system structure
- R3ProII
- specs
- output modes
- qemu readme
- QEMU functionality is very experimental, we haven't gotten very far into making it work
- R1
- specs
- qemu readme
- QEMU functionality is very experimental, we haven't gotten very far into making it work
- Third Party
- Curated
- HiBy User Manuals
- Ingenic x1600e (SOC)
- Components
- Halley 6 (Ingenic x1600 development board)
- Sources
- Ingenic Docs Git
- Ingenic Public FTP Server
- URL:
ftp://ftp.ingenic.com.cn - Username:
ingenic_public - Password:
BFdg2f9B12
- URL:
- Curated
Tip
For more specific and detailed instructions, look at UNPACKING.md and REPACKING.md.
- Depending on your device, enter either the
r1directory or ther3proiidirectory - if you want to unpack a firmware not in this repo already, add it in the
firmware/customdirectory - enter the
unpacking_and_repackingdirectory for your device - to unpack your firmware use the
unpack-helper.shscript and choose the firmware you want to unpack- The linux root filesystem of the firmware will be extracted into a folder
- to repack your firmware, just run the
repack-helper.shscript
Note
- You might need to create the
firmware/customdirectory if it doesn't exist - I've made it so that the unpacking and repacking scripts no longer need sudo in order to run