Skip to content

G Pro X Superlight (0xc094): profile dump, reports format 4 not 7 #159

Description

@Alon-W

Hey, saw the comment on the 0xc094 guard in onboard-profiles.ts asking for a dump from this exact PID, so here's one from my Superlight.

The interesting part is that mine doesn't report format 7 like the comment assumes. It reports format 4, so it's on the base v1 layout, not the Superlight 2 one. Could be a firmware difference with the #46 mouse, no idea. Mine's on main app MPM25.01_B0018.

Setup: PRO X Wireless on a Lightspeed receiver (046d:c547, device index 1), macOS 15, Chrome. Bootloader is BL125.00_B0013, and the main app entry from 0x0003 ends in 01 40 93 fe 92 43 6c, so the 4093 wpid is in there.

getOnboardProfilesInfo:

01 04 01 05 01 05 10 00 ff 0a 04 00

That's format 4, 5 profiles, 1 OOB, 16 sectors of 255 bytes. Onboard mode is on.

Profile sector 1 (active), before I touched anything in OpenMouse. CRC checks out:

00: 01 00 00 20 03 00 00 00 00 00 00 00 00 ff ff ff
10: ff 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff
20: 80 01 00 01 80 01 00 02 80 01 00 04 80 01 00 08
30: 80 01 00 10 ff ff ff ff ff ff ff ff ff ff ff ff
40-c0: ff ...
d0: 00 00 00 00 00 00 1f 40 00 00 00 00 00 00 00 00
e0: 00 1f 40 00 00 00 ff ff ff ff ff ff ff ff ff ff
f0: ff ff ff ff ff ff ff ff ff ff ff ff ff dd 75

Directory (sector 0): 00 01 01 ff 00 02 00 ff 00 03 00 ff 00 04 00 ff 00 05 00 ff ff ff …

Sectors 2–5 are unused and still have the factory stages (400/800/1600/3200/6400, default index 1). CRCs good on all of them.

The v1 DPI table works fine on this mouse. Stages are at 0x03–0x0c, 5 × u16 little-endian, raw DPI, 0 = stage off. Default index at 0x01, shift index at 0x02, both 0-based. Report rate at 0x00 is the interval in ms (01 = 1000 Hz), same as your v1 decode. 0x2201 says 100–25600 in steps of 50. I've written 800, 1600 and 2550 but haven't poked at the limits.

What I tested:

  • Changed DPI on openmouse.app, then diffed all 16 sectors against my dump. Only sector 1 changed: stage 1 at 0x03 went 20 03 → f6 09 (800 → 2550) and the CRC went dd 75 → bb 5f. Valid CRC, and 0x2201 reads 2550.
  • Also wrote the sector myself with a small script (startWrite fn 6, 16-byte writeData fn 7, endWrite fn 8, read back). Rewrote it unchanged, then set stage 1 to 800, then 1600. Read-back matched every time.
  • With 1600 stored, I closed everything on the host and turned the mouse off and on. It came back at 1600, so it's really in flash.

No HID++ errors at all, never saw the 0x05 from #46.

One thing I'm confused about: DEFAULT_FORMAT_CAPABILITIES has dpiStages: null for v1, but the site still wrote stage 1 at 0x03 on my mouse. Is the live site ahead of main, or does DPI go through a different path?

Happy to grab more dumps or test stuff on this mouse if it helps.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions