nandtool.py -> Read, extract, compare, and verify the main bootchain of two nand images
patchreader.py -> Parse freeBOOT patches.bin into a nandtool-readable text file
fstool.py -> Read, validate, list, and extract a NAND FlashFS
splitbb.py -> Split 2048+64 BB pages into 4x 512+16 SB pages
stripspare.py -> Strip the 16 bytes of spare data from each page
set_smcconf_0.py -> Set SMC config addr in NAND header to 0
set_size_0.py -> Set Size addr in NAND header to 0
frankenstein.py -> Splice A's SMC, KV and encrypted boot chain (including CF/CG continuation blocks) into B. Uses A's component addresses and layout fields; retains B's other header fields, filesystem, config and spare metadata. Regenerates changed-page ECC without re-encrypting bootloaders.
python3 frankenstein.py xebuild.bin gxbuild.bin -o frankenstein.binThe standard retail 1BL key is built in; --secret-1bl overrides it for CF table inspection. No CPU key is required. --format-a / --format-b can select raw, page (512+16), or chunked (2048+64), with automatic detection by default. The output retains B's physical format. Existing output files are rejected.
This is a diagnostic splice, not a filesystem rebuild: A's continuation blocks overwrite B at those addresses without updating B's filesystem allocation map. Bad blocks intersecting copied regions are rejected; resolve remapping before using the script. It copies only component-related header fields at 0x08..0x0F, 0x60..0x73, and 0x78..0x7F; B's NAND pairing/flags, copyright, reserved bytes and SMC-config pointer remain intact.
Tests: python3 -m unittest discover -s tests -v