You are not logged in.

#1 Today 06:03:31

Wonderfulyeah
Member
Registered: 2021-02-22
Posts: 11

[HELP] ThinkPad X1 Yoga Gen 3 — RGB camera firmware lost (Sunplus SPCA

# [HELP] ThinkPad X1 Yoga Gen 3 — RGB camera firmware lost (Sunplus SPCA208x, stuck in 1bcf:0b13 ROM mode). Need a read-only flash dump from a healthy unit

## TL;DR

If your ThinkPad's **RGB camera works** and it's the Sunplus module
(**FRU 01HW040** family — X1 Yoga Gen 3 / X1 Carbon 6th / X280 / X380 Yoga /
L380 / L390 Yoga / L480 / P1), please run a **strictly read-only** dump
script on any Linux live USB and send me the resulting `donor-dump.bin`:

```bash
sudo python3 donor-dump-probe.py        # https://github.com/wonderfulyeah/sunplus-camera-rescue
```

You do **not** need to know your camera's USB ID — the script discovers it.
It cannot write to the camera (the flash-write controls are hard-blocked in
code) and it reads every dump twice, keeping results only if both passes
match. A replacement module for these models costs ~$20, so the risk to a
donor is essentially zero, but the dump would save me the same cost and a
lot of e-waste.

## The situation

My X1 Yoga Gen 3 (Type 20LE) has the dual-sensor camera bar (FRU 01HW040 —
RGB + IR). Forensic reads over the vendor UVC extension-unit protocol
(confirmed against fwupd's `sunplus-camera` plugin) established:

- The bar carries **two independent controllers, each with its own 64 KiB
  SPI flash**:
  - IR: SPCA2093B → healthy, enumerates as `5986:211a`, fw version 5465
    (restored with Lenovo's official *Integrated IR Camera Firmware Update
    Utility*, ds505129).
  - RGB: SPCA2087-family → **bricked**, stuck in the mask-ROM state
    `1bcf:0b13` "SPCA2087 PC Camera".
- The RGB controller's flash currently contains a mis-flashed copy of the
  **IR** image (byte-for-byte `sf.bin` from the IR package except one flag
  byte), i.e. **the original RGB firmware is gone** from the chip.
- Lenovo never published an RGB firmware for this generation. I checked:
  Lenovo support channels (chat bot loop, China support → "no download,
  use a repair center"), the Microsoft Update Catalog, LVFS/fwupd metadata
  (all 850 components, text + GUID search), driver packs (the Sunplus INFs
  don't even list this module). Nothing.
- The camera's healthy USB identity was never recorded on my install
  (X1 Yoga Gen 3 units came with either a Chicony RGB camera — the
  `04f2:b61e` on ArchWiki — or this Sunplus one), so I can't even screen
  donors by ID. The probe script handles that automatically.

## What I'm asking

Run this on any machine with a **working** RGB camera on the 01HW040-family
module (Linux live USB is fine, no OS changes):

```bash
git clone https://github.com/wonderfulyeah/sunplus-camera-rescue
cd sunplus-camera-rescue
python3 donor-dump-probe.py --check    # inventory only, no camera I/O yet
sudo python3 donor-dump-probe.py       # read-only probe + dump
```

Then send me `donor-dump.bin` and the `lsusb -nn` line of your machine
(either directly or via the GitHub repo). Units with the Chicony RGB
variant (`04f2:b61e`) will simply fail validation ("no Sunplus firmware
header") — nothing breaks, you just can't donate. Only Sunplus-variant
machines produce a valid image.

## Why this is safe for donors

- The only USB transfers the script can emit are the vendor's flash-read
  pair (`SET_CUR sel 0x0E` seek + `GET_CUR sel 0x16` 64-byte read) on
  extension unit 4 — the same pair the vendor flasher uses to *verify*
  programming, and the same pair fwupd's official plugin uses.
- Flash-write controls (selectors 9/10/11/12) and register writes (2/3)
  are hard-blocked before any ioctl; a coding mistake raises instead of
  transmitting.
- Target allowlists skip all known IR cameras and all known ROM states.
- The dump contains only the camera controller's firmware/calibration
  blob — a webcam flash holds no user data.

## If you can't run the script

Boosting this thread helps. Also useful: if you own a bricked
`1bcf:0b13` camera yourself, `brick-forensics-0b13.py` (same repo,
read-only) reads your module's flash so we can compare damage patterns.

---

*Once I receive a validated dump I'll flash it back over the same UVC
interface (write path per the fwupd plugin: selectors 9/10/11/12 + XOR
checksum + verify) and document the whole procedure in the repo, so the
next person with a bricked 01HW040 RGB camera can self-serve.*

---

<!-- ---------------------------------------------------------------- -->

## Short version (for replying inside existing threads)

> Looking for a read-only 64 KiB firmware dump from a **healthy** Sunplus
> RGB camera (FRU 01HW040 family: X1 Yoga Gen 3 / X1C6 / X280 / X380 /
> L380 / L390 / P1) to recover a bricked X1Y3 camera stuck in ROM mode
> (`1bcf:0b13`). One command on a live USB:
> `sudo python3 donor-dump-probe.py` from
> https://github.com/wonderfulyeah/sunplus-camera-rescue — strictly
> read-only (write selectors hard-blocked), double-read verified, no
> disassembly. Send back `donor-dump.bin` + your `lsusb -nn` line. Thanks!

Offline

Board footer

Powered by FluxBB