394b677c8f
Reverts the 0x8000/0xC000 change from162dbf7, which was WRONG and actively broke transmission. The W5100S datasheet pseudo-code quotes 0x8000 (TX) / 0xC000 (RX) for the memory blocks, but the PARALLEL/indirect (IDM) interface only decodes a 15-bit offset. Bench-proven with an address-aliasing probe: writing distinct values to each candidate base and reading them back showed 0xC000 and 0x4000 are the SAME cell (0xC000 & 0x7FFF == 0x4000) while 0x6000 holds its own value. Consequence of the bad base: every payload byte written to 0x9800+i aliased down onto 0x0000+i, landing on SHAR (0x09-0x0E) and SIPR (0x0F-0x12) and overwriting them with the payload. The chip then transmitted frames with a garbage source MAC/IP, which the peer NIC drops without counting -- the "SEND_OK but rx_packets=0" symptom, and the bogus SIPR0 readback (0x50 was literally payload byte 15, 'P'). The NETLCKR unlock from9c4bc7ais a genuine W5100S requirement and stays. Also: - w5100_udptest.py: self-contained configure+send+readback probe (and the address-aliasing probe that found this), reports over UART. - scripts/build-flash.sh: sweep N seeds and flash the best (capture timing is seed-dependent, so the sweep is mandatory). - scripts/uart-console.py: interactive UART console, plus --send/--read one-shot modes for scripting. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>