And then we jump to a function that's called RCM prot handle message, where it's jumping to the code or it's responding with the version information that you requested and so on.
And this struct contains all the important things that the RCM code needs to know to verify that message, the signature of that message, and what it's supposed to do.
You already have kernel code execution due to some other hack, and you can just set this PMC scratch register and reboot, and then the ROM sees this and just goes into the RCM path.
由于其他些 hack,您已经执行了内核代,您只需设置此 PMC 暂存寄存器并重新启动,然后 ROM 会看到它并进入 RCM 路径。