>There are 2 paths for the boot; if the boot is a normal one then it
>jumps to 0xe000 (which *is* writable) with r0=hwrev, r1=ram (MB),

I take it the code which checks for DC-Power and decides to skip the flash loader prompt must be in the protected area, rather than up at 0xe000, Right?

-ml