This is interesting stuff !
I have tried to dissasemble the firmware but never succeeded in mounting the resulting cramfs. Never figured out if the problem was related to xip-linear
patches I needed, or the image being bad.
What did you do to mount the cramfs ?
And how would the pdaxrom work ? Changeroot from qtopia, killing qpe and starting X ? Or hacking the image so qpe does not start at all ?
I'd be very interested in helping, but must say I have no experience using arm (dis)assembler or kernel coding.
BTW, are you using the latest (1.14-2) firmware for the kernel ? Or do you use 1.13-2 which, I believe, is more stable ?