// 0x120 - 0x127 = stage3j (0x2401F031200)

// 0x130 - 0x137 = lv1_peek64(34)
// 0x140 - 0x14f = lv1_poke64(35)
// 0x150 - 0x17b = lv1_exec(36)

// 0x180 - 0x187 = lv1_peek32(37)
// 0x190 - 0x19f = lv1_poke32(38)

// 0x210 - 0x217 = stage5j (0x2401F031400)
// 0x220 - 0x227 = stage6j (0x2401F031700)
// 0x230 - 0x237 = isDisableMyappldr (set to 1 by cobra)
// 0x240 - 0x247 = qcfw marker (0x11223344aabbccdd)

// 0x1000000 = lv2 (ofw)
// 0x8000000 = lv2 (cfw) / otheros

// Stagex:
// 0xA00 - 0xBFF = Stagex_Context_s
// 0xD000000 = sc_puts_buffer

// Stage1:
// 0xE000000 = stage_sp
// 0xC000000 = temp lv0FileAddress

// Stage2:
// 0xA000000 = tmpEa (HDDKeyDumper)
// 0xE000000 = stage_sp
// 0xC000000 = temp lv1FileAddress

// Stage3:
// 0xB000000 = temp lv2DiffFileAddress

// Stage4:
// 0xC000000 = temp lv2FileAddress
// 0xB000000 = temp lv2ElfFileAddress
// 0xA000000 = temp decryptBuf

// Stage5:

// Stage6: