sorry for delay, i still work with bootrom disassembling:)
Very nice, you have done exactly what I thought was the way to hack the PMA. I´ll have some look at the bootrom code, too, perhaps I find out something about the checksum routine.
BTW: there is an ARM disassembler that seems to be quite good. It is called "komodo" or "kmd" and was written by a guy from the University of Manchester (I mention that because I spend a year there... with whom I had a chat. You can download it from his web-site <http://www.cs.man.ac.uk/~brejc8/kmd/>
And all this when I had almost given up about the idea of having a real open source operating system running on the PMA...
