Hello all!
After the Kodak Reels tinkering I got back to my other digitizing device: a Reflecta DigitDia Evolution magazine slide scanner. It works fine, but I've never been fully happy with the image quality: visible JPEG artifacts and a soft "watercolor" look. It turns out to be the same Novatek family as the Kodak Reels, so I started digging. Sharing what I have so far.
1. Hardware
I read the 8 MB chip in-circuit with an SOIC-8 test clip + a Raspberry Pi 2 + flashrom (scanner unplugged; the Pi's 3.3 V powers the chip):
The loader recognises several files on the card. Its board-init code renames the generic Novatek names, so on this scanner they are:
Thanks to everyone who has been tinkering with the Kodak Reels devices — the knowledge from there transferred surprisingly well!
Attaching a few pictures of the board and from the flash dumping process.
After the Kodak Reels tinkering I got back to my other digitizing device: a Reflecta DigitDia Evolution magazine slide scanner. It works fine, but I've never been fully happy with the image quality: visible JPEG artifacts and a soft "watercolor" look. It turns out to be the same Novatek family as the Kodak Reels, so I started digging. Sharing what I have so far.
1. Hardware
- Main board
AFS61N_MAIN_V1.0 (2021.09.19) - SoC Novatek NT96660BG-H (MIPS, same family as the Kodak Reels' NT96658)
- Flash Winbond 25Q64JVSIQ: 8 MB SPI NOR, the wide 208-mil SOIC-8 package
- RAM: NANYA DDR3, 2 Gbit
- Unpopulated GND / TX / RX UART pads (flat SMD pads, not tried yet), plus empty speaker/mic footprints (the board looks like a cut-down camera design)
- Three slide-position sensor connectors (POSITION_A/B/C), stepper motor, LED light board
- Sensor: 16 MP. The "16M" menu setting is the native 4920×3280. "24M" (6000×4000) is upscaled from it.
I read the 8 MB chip in-circuit with an SOIC-8 test clip + a Raspberry Pi 2 + flashrom (scanner unplugged; the Pi's 3.3 V powers the chip):
- Wiring (flash pin → Pi header pin): 1 CS → 24, 2 DO → 21, 3 WP → not connected, 4 GND → 25, 5 DI → 19, 6 CLK → 23, 7 HOLD → 17 (3.3 V), 8 VCC → 1 (3.3 V)
flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=500 -c W25Q64JV-.Q -r dump.bin.
0x000000: bootloader (its body is compressed at0xB1Cand runs at0x8FF09000)0x008000: main firmware, BCL1 FullComp: 3.4 MB → 22.6 MB, load address0x80000000(uITRON + eCos)- A second, older-looking compressed block further up, with a bad checksum. I think it's leftover data, but I haven't confirmed that.
- Compression is the LZ77 from the "Basic Compression Library" (BCL1, algorithm 9). The checksums work with Tobi@s' ntkcalc. bfc4ntk -c refuses this 22.6 MB image (size limit), so I had to write my own compressor.
- Loader rules: back-references <= 99 999 bytes, no overlapping copies, and the file size must be a multiple of 4, or the loader hangs.
The loader recognises several files on the card. Its board-init code renames the generic Novatek names, so on this scanner they are:
FWFS601T.BIN: load the firmware from the card into RAM and run it. Remove the file and power-cycle, and you're back to stock firmware. This makes testing almost risk-free.FWFS601A.BIN= flash the firmware,LDFS601A.BIN= flash the bootloader — don't put these on a card unless you know exactly what you're doing!- The loader reads FAT32, no exFAT.
- Stock photos are Q95, 4:2:2. The bigger visual issue is strong noise reduction, which makes even small block steps visible. Chroma blocking is the worst artifact.
- Still capture (
ImgCap_EncBS0x80344874): if the finished JPEG doesn't fit its buffer, the firmware re-encodes 5 points lower (95 → 90 → …). The buffer is whatever is left in the capture memory pool: about 6 MB at 24M and ~4.5 MB at 16M. Detailed slides drop to Q90. - Encoder: standard IJG quality formula (
0x801C1D40); Q100 = all-ones tables. The capture parameter table is at0x815938C0(quality is entry 0, plus the rate-control targets 4/5/6 MiB, which are unused by default).
Thanks to everyone who has been tinkering with the Kodak Reels devices — the knowledge from there transferred surprisingly well!
Attaching a few pictures of the board and from the flash dumping process.