Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ep-unity

A browser tool for flashing firmware files to Teenage Engineering's EP-133 k.o. II and EP-40 riddim. It assists with rewriting the four SKU bytes in a .tfw header so a device will accept an image built for its peer. Flashes over WebMIDI, and backs up and restores your projects and samples as well.

Written up here: My K.O. II boots as a riddim now. It took four bytes.
Video demo of result: youtube.com/watch?v=_iU3sdBdjdo

Unsupported, and it can brick your device. Teenage Engineering asked that I share this: cross-flashing is unsupported. EP units ship different NOR flash types and densities, and the risks associated with this could include data loss, a brick, and a voided warranty. Everything here was tested on one legacy 64 MiB EP-133. That's a really small sample size - sharing because it is of technical interest. I take no responsibility for broken units.

What it does

Panel
1 · firmware image Drop any TE032 .tfw. Links out to TE's firmware list - you download, this parses it.
2 · SKU rewrite Live before/after of the four header bytes that change, at offsets 15–18.
3 · flash WebMIDI DFU behind three risk acknowledgements, with a post-flash watcher that diagnoses RDY / err sound / ERR SYSTEM_MODEL and tells you how to recover.
4 · backup Projects and samples off the device into a .pak, over WebMIDI FILE. Do this first.
5 · factory projects Thin a factory .pak down to just the samples its pads reference, with a free-space check that blocks a restore that won't fit.
A play 10s demo button in the device bar that plays something different depending on which firmware is running.

It never contacts teenage.engineering

Every link to TE is one you choose to click. No firmware or factory content is mirrored in this repository.

Requirements

WebMIDI with sysex, which today means a Chromium browser: Chrome or Edge on desktop, or Chrome on Android over USB-C — handy at a bench with no laptop.

Running it

node web/serve.mjs        # http://localhost:8766/
node --test web/lib/*.test.js

serve.mjs is a plain static file server and makes no outbound requests.

Things I learned when it seemed like it'd gone wrong

  • Screen stuck on RDY - the image was rejected after transfer. Not a brick; MIDI and DFU still work. Flash a stock same-family .tfw from the bootloader.
  • ERR SoUnD spam - the user filesystem, not the firmware. Power off, hold SHIFT+ERASE, power on to format the sound store, then flash, then restore.
  • ERR SYSTEM_MODEL - the restore didn't fit. Check free space first.

A clean DFU log is not necessarily indicative of a successful flash: PERFORM returning 0 means the bytes arrived, not that the bootloader accepted them.

Command line

python3 tools/tfw.py info ep-40_firmware_2_5_1.tfw
python3 tools/tfw.py rewrite-sku ep-40_firmware_2_5_1.tfw --sku TE032AS001 -o out.tfw
python3 tools/tfw_mcuboot.py info ep-133_firmware_2_5_1.tfw

Firmware files are not included — point these at images you downloaded from TE.

Research notes

Doc Topic
blob-cryptanalysis.md MCUboot / ECIES: why the app payload stays opaque
trailer-static-analysis.md LittleFS trailer reverse engineering
nor-flash-variance.md What TE said about NOR types and densities
decrypt-oracle.md Why the MIDI crypto oracle went nowhere
supertone-feasibility.md What porting Supertone would actually require
swd-dump-path.md The physical dump route
midi-stress-checklist.md Notes, CC and clock stress run against a cross-flashed unit

Prior art

The community work this builds on. None of it is a firmware flasher; all of it was useful: ep133-krate and ep133-ppak for Packed7 and protocol documentation, ep133-export-to-daw, and wmealing's KO2-SYSEX plus his bring-up capture notes.

Disclosure

The client-side SKU gate was reported privately to Teenage Engineering before any of this was public. Their response — the NOR density warning at the top of this file — is quoted in the write-up rather than buried in a footnote.

Not affiliated with Teenage Engineering. Not recommending you do this.

This tool was written in part with AI.

About

Browser tool for Teenage Engineering EP-133 / EP-40: SKU header rewrite, WebMIDI DFU, project + sample backup. Unsupported; can brick your device.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages