My attempts to jump to Canon firmware failed on both 760D and 80D.
sourceAlso tried to:
- identify the main firmware start address from the string "/_term" (tested on 7D2 in QEMU and on 60D; should work on all DIGIC 4/5 models)
- jump to 0xFFFF0000 (hivecs reset interrupt, tested on 60D, probably works on all DIGIC 4/5 models)
- jump to MEM(0xFC000000) (reset address for EOS M3 and M10)
All attempts resulted in black screen and camera locked up.
Please let me know once you are ready for the hardware mod linked above.