电信中兴B860A救砖研究
使用SecureCRT_Portable工具TTL跑码信息如下:================================================================QA9:A;SVN:74E;POC:17F;STS:0;BOOT:0;INIT:0;READ:0;CHECK:0;PASS:0;
no sdio debug board detected
TE : 1278855
BT : 19:42:05 Jun 26 2019
PMU:rn5t618
DC01 v:1100, 0x: 18 -> 28
DC02 v:1150, 0x: 18 -> 2c
DC03 v:1500, 0x: 38 -> 48
LDO01 v:3300, 0x: 4e -> 60
LDO02 v:1800, 0x: 24 -> 24
LDO03 v:1800, 0x: 30 -> 30
LDO04 v:2850, 0x: 4e -> 4e
LDO05 v:1800, 0x: 24 -> 24
LDO0a v:2700, 0x: 28 -> 28
LDO0b v:900, 0x: 00 -> 00
CPU clock is 792MHz
BOARD type: 0x04
CPU type: M8M2
DDR info: 1GB(auto) @ 792MHz(1T)+Scramb EN
DDR channel: DDR 0 + DDR 1
DDR init use : 14707 us
HHH
Boot From SDIO C
0x0000008d
ucl decompress...pass
0x12345678
Boot from internal device 1st tSD/fSD on SDIO C
TE : 1470317
System Started
U-boot-svn182834(m8_k200_v1@) (Jun 26 2019 - 19:41:49)
clr h-ram
DRAM:1 GiB
relocation Offset is: 2fe90000
show partition table:
part: 0, name : conf, size : 400000
part: 1, name : logo, size : 1000000
part: 2, name : recovery, size : 1400000
part: 3, name : misc, size : 400000
part: 4, name : boot, size : 1400000
part: 5, name : cache, size : 30000000
part: 6, name : system, size : 30000000
part: 7, name : data, size : 79000000
part: 8, name : , size : 0
part: 9, name : , size : 0
part: 10, name : , size : 0
part: 11, name : , size : 0
part: 12, name : , size : 0
part: 13, name : , size : 0
part: 14, name : , size : 0
part: 15, name : , size : 0
aml_card_type=0x200
MMC: add mmc dev_num=0, port=1, if_type=6
add mmc dev_num=1, port=2, if_type=6
SDIO Port B: 0, SDIO Port C: 1
board_type 4
PMU fault status:
reg = 0x1d
LSI version:04, OTP version:0c
PMU type:RN5T618
IR init done!
register usb cfg = 3ff6c228
register usb cfg = 3ff6fb4c
enter emmc boot
Emmckey: Access range is illegal!
SDIO Port C:1, if_type=6, initialized OK!
end of part_table, index 8.
Partition table get from SPL is :
name offset size flag
===================================================================================
0: bootloader 0 400000 0
1: reserved 800000 1000000 0
2: env 1c00000 400000 0
3: conf 2400000 400000 1
4: logo 2c00000 1000000 1
5: recovery 4000000 1400000 1
6: misc 5800000 400000 1
7: boot 6000000 1400000 1
8: cache 7800000 30000000 2
9: system 37c00000 30000000 1
10: data 68000000 79000000 4
mmc read lba=0x4000, blocks=0x1
mmc read lba=0x4001, blocks=0x1
mmc_read_partition_tbl: mmc read partition OK!
eMMC/TSD partition table have been checked OK!
i=0,register --- emmc_key
device_boot_flag=2
EMMC BOOT: not init nand
do not init nand : cause boot_device_flag without nand
MMC BOOT, emmc_env_relocate_spec : env_relocate_spec 74
set_storage_device_flag: store 2
vpu driver detect cpu type: m8m2
vpu clk_level = 7
set vpu clk: 364000000Hz, readback: 364000000Hz(0x700)
mode = 11vic = 31
set HDMI vic: 31
config HPLL
config HPLL done
reconfig packet setting done
dectect realtek sdio wifi, config to sdio controller
Multi dtb tool version: v2 .
Multi dtb detected, support 5 dtbs.
aml_dt soc: m8m2 platform: n200 variant: sdio
dtb 0 soc: m8m2 plat: n200 vari: 1G
dtb 1 soc: m8m2 plat: n200 vari: 2G
dtb 2 soc: m8m2 plat: n200 vari: sdio
dtb 3 soc: m8m2 plat: n200C vari: 1G
dtb 4 soc: m8m2 plat: n200C vari: sdio
Find match dtb: 2
Net: Meson_Ethernet
zteDbg: original preboot=run test_facreset;if itest ${upgrade_step} == 3; then run storeargs; run update; fi; if itest ${upgrade_step} == 1; thensetenv upgrade_step 2; saveenv;fi; hdcp prefetch nand;get_rebootmode; clear_rebootmode; echo reboot_mode=${reboot_mode};if test ${reboot_mode} = suspend_off; then suspend;fi;run storeargs;run irremote_update;run update_key; run switch_bootmode;
zteDbg: current preboot=run test_facreset;if itest ${upgrade_step} == 3; then run storeargs; run update; fi; if itest ${upgrade_step} == 1; thensetenv upgrade_step 2; saveenv;fi; hdcp prefetch nand;get_rebootmode; clear_rebootmode; echo reboot_mode=${reboot_mode};if test ${reboot_mode} = suspend_off; then suspend;fi;run storeargs;run irremote_update;run update_key; run switch_bootmode;
init suspend firmware done. (ret:0)
cvbs trimming.1.v5: 0xa0, 0x0
hdcp init_hdcp_ram...
reboot_mode=charging
key1 = 7b84c43b
key2 = b748ff00
key3 = 6699dd22
key4 = 66994eb1
key5 = 66994db2
key6 = 66994cb3
time_out = 30d40
ir init
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
int the read_key
key = 0
failed
COMControlFlag=> value=, val=0
not found mac in efuse
zte_mac=90:D8:F3:0C:26:C3,ethaddr=90:D8:F3:0C:26:C3
Hit Enter key to stop autoboot -- :1 0
exit abortboot: 0
: ====== Logo_disp ======
ntohl(imgheader.magic) = b3100b05 HEADER_MAGIC = 55667788
Logo_disp ret: 0
COMControlFlag=> value=, val=0
ScreenMode=> value=1, val=1
This is a NDK_MARKET!!!!
not found mac in efuse
do_bootsys to boot NORM
head magic=414e4452
hdcp init_hdcp_ram...
## ANDROID Format IMAGE
## Booting kernel from Legacy Image at 12000000 ...
Image Name: Linux-3.10.33
Image Type: ARM Linux Kernel Image (lzo compressed)
Data Size: 6382439 Bytes = 6.1 MiB
Load Address: 00208000
Entry Point:00208000
Verifying Checksum ... OK
Ramdisk start addr = 0x12617000, len = 0xdd8af
dectect realtek sdio wifi, config to sdio controller
Multi dtb tool version: v2 .
Multi dtb detected, support 5 dtbs.
aml_dt soc: m8m2 platform: n200 variant: sdio
dtb 0 soc: m8m2 plat: n200 vari: 1G
dtb 1 soc: m8m2 plat: n200 vari: 2G
dtb 2 soc: m8m2 plat: n200 vari: sdio
dtb 3 soc: m8m2 plat: n200C vari: 1G
dtb 4 soc: m8m2 plat: n200C vari: sdio
Find match dtb: 2
Flat device tree start addr = 0x12700800, len = 0x5479 magic=0xedfe0dd0
Uncompressing Kernel Image ... OK
uboot time: 3616780 us.
EFUSE machid is not set.
Using machid 0xf81 from environment
From device tree /memory/ node aml_reserved_end property, for relocate ramdisk and fdt, relocate_addr: 0x50e7001
Loading Ramdisk to 05009000, end 050e68af ... OK
Loading Device Tree to 05000000, end 05008478 ... OK
Starting kernel ...
[ 0.147315@0] ram_console: failed to create proc entry
[ 0.818002@3] aml_keys: version 0 can not be init c0b20b28
[ 0.818067@3] aml_keys: version 0 can not be init c0b20b28
[ 0.825817@3] NO BATTERY_PARAMETERS FOUND
[ 0.860766@2] ###check hw reset function is already enabled here
[ 0.984910@3] init: failed t[ 1.872029@3] init: mount none to target failed
[ 1.917622@3] init: mount none to target failed
[ 1.921730@3] init: mount adb to target failed
[ 21.015344@1] fs_mgr: Cannot mount filesystem on /dev/block/system at /system
[ 21.016844@1] init: fs_mgr_mount_all returned an error
[ 21.022201@1] aml_keys: version 0 can not be init c0b20b28
[ 21.027415@1] aml_keys: version 0 can not be init c0b20b28
[ 21.036690@1] init: Unable to open persistent property directory /data/property errno: 2
[ 21.041285@1] init: ----open devices error: No such file or directory
[ 21.047352@1] init: Cannot read : -1.
[ 21.051020@1] init: ----open devices error: No such file or directory
[ 21.057406@1] init: Cannot read : -1.
[ 21.061056@1] init: ----open devices error: No such file or directory
[ 21.067460@1] init: Cannot read : -1.
[ 21.071120@1] init: ----open devices error: No such file or directory
[ 21.077515@1] init: Cannot read : -1.
[ 21.081171@1] init: ----open devices error: No such file or directory
[ 21.087685@1] init: Cannot read : -1.
[ 21.091212@1] init: readfailed
[ 21.096356@1] init: cannot find '/system/bin/sh', disabling 'console'
[ 21.100975@1] init: cannot find '/system/bin/servicemanager', disabling 'servicemanager'
[ 21.109006@1] init: cannot find '/system/bin/vold', disabling 'vold'
[ 21.115321@1] init: cannot find '/system/bin/set_display_mode.sh', disabling 'display'
[ 21.123224@1] init: cannot find '/system/bin/dig', disabling 'dig'
[ 21.129502@1] init: cannot find '/system/bin/netd', disabling 'netd'
[ 21.135685@1] init: cannot find '/system/bin/debuggerd', disabling 'debuggerd'
[ 21.142899@1] init: cannot find '/system/bin/surfaceflinger', disabling 'surfaceflinger'
[ 21.150950@1] init: cannot find '/system/bin/app_process', disabling 'zygote'
[ 21.158054@1] init: cannot find '/system/bin/drmserver', disabling 'drm'
[ 21.164722@1] init: cannot find '/system/bin/configserver', disabling 'configserver'
[ 21.172455@1] init: cannot find '/system/bin/mediaserver', disabling 'media'
[ 21.179479@1] init: cannot find '/system/bin/installd', disabling 'installd'
[ 21.186480@1] init: cannot find '/system/etc/install-recovery.sh', disabling 'flash_recovery'
[ 21.194982@1] init: cannot find '/system/bin/keystore', disabling 'keystore'
[ 21.202013@1] init: cannot find '/system/bin/remotecfg.sh', disabling 'remotecfg'
[ 21.209459@1] init: cannot find '/system/bin/stbcfg', disabling 'stbcfg'
[ 21.216126@1] init: cannot find '/system/bin/pppoe_wrapper', disabling 'pppoe_wrapper'
[ 21.224020@1] init: cannot find '/system/bin/imageserver', disabling 'imageserver'
[ 21.231573@1] init: cannot find '/system/bin/zram_mount.sh', disabling 'zram_mem'
[ 21.239018@1] init: cannot find '/system/bin/basicService', disabling 'basicService'
[ 21.249475@1] aml_keys: version 0 can not be init c0b20b28
[ 21.252182@1] aml_keys: version 0 can not be init c0b20b28
[ 21.258250@1] init: cannot find '/system/bin/sdcard', disabling 'sdcard'
[ 21.264326@1] init: property 'ro.product.manufacturer' doesn't exist while expanding '${ro.product.manufacturer}'
[ 21.274560@1] init: cannot expand '${ro.product.manufacturer}' while writing to '/sys/class/android_usb/android0/iManufacturer'
[ 21.285998@1] init: property 'ro.product.model' doesn't exist while expanding '${ro.product.model}'
[ 21.295028@1] init: cannot expand '${ro.product.model}' while writing to '/sys/class/android_usb/android0/iProduct'
[ 21.305496@1] init: property 'ro.usb.vendor.string' doesn't exist while expanding '${ro.usb.vendor.string}'
[ 21.315121@1] init: cannot expand '${ro.usb.vendor.string}' while writing to '/sys/class/android_usb/android0/f_mass_storage/vendor_string'
[ 21.327614@1] init: property 'ro.usb.product.string' doesn't exist while expanding '${ro.usb.product.string}'
[ 21.337477@1] init: cannot expand '${ro.usb.product.string}' while writing to '/sys/class/android_usb/android0/f_mass_storage/product_string'
[ 21.352038@1] init: property 'sys.powerctl' doesn't exist while expanding '${sys.powerctl}'
[ 21.358478@1] init: powerctl: cannot expand '${sys.powerctl}'
[ 21.364183@1] init: property 'sys.sysctl.extra_free_kbytes' doesn't exist while expanding '${sys.sysctl.extra_free_kbytes}'
[ 21.375282@1] init: cannot expand '${sys.sysctl.extra_free_kbytes}' while writing to '/proc/sys/vm/extra_free_kbytes'
================================================================
================================================================
电信中兴B860A救砖研究
本帖最后由 lj249911023 于 2022-6-12 19:00 编辑================================================================
通电使用 遥控器 不停的按 左键 ,进行卡刷,官方原始固件,也失败,要短接哪个位置,能通电 ,通过双公头USB线让晶晨刷机软件识别到啊。
================================================================
TTL跑码一直卡在下面这个位置不动:
[ 21.364183@1] init: property 'sys.sysctl.extra_free_kbytes' doesn't exist while expanding '${sys.sysctl.extra_free_kbytes}'
[ 21.375282@1] init: cannot expand '${sys.sysctl.extra_free_kbytes}' while writing to '/proc/sys/vm/extra_free_kbytes'
没法让控制台出现“m8m2_n200_v1#”,没法输入命令执行啊?
经过我不断的折腾,花了2天多的时间,终于救砖成功了。呵呵呵
https://www.znds.com/forum.php?mod=viewthread&tid=1218951&page=1&extra=#pid63459438、
https://www.znds.com/tv-1218951-1-1.html 本帖最后由 lj249911023 于 2022-6-12 20:46 编辑
https://www.znds.com/jc/article/6992-1.html
https://www.znds.com/jc/article/21105-1.html
https://www.znds.com/jc/article/16710-1.html
https://www.znds.com/jc/article/9400-1.html
重启机顶盒,此时快速不断的按回车键,待看到:m8m2_n200_v1# 后,输入:
safe
https://www.znds.com/forum.php?mod=viewthread&tid=1112390&mobile=2
电路图
https://www.cnblogs.com/shangdawei/p/4917430.html
中兴B860A四川电信版刷机救砖方法和固件https://www.znds.com/tv-1180804-1-1.html lj249911023 发表于 2022-6-14 22:42
经过我不断的折腾,花了2天多的时间,终于救砖成功了。呵呵呵
https://www.znds.com/forum.php?mod=viewthr ...
能不能帮我看看 我是也是860折腾一年了 是我的心病了 久伴不弃可好 发表于 2022-10-8 22:39
能不能帮我看看 我是也是860折腾一年了 是我的心病了
那完了这盒子 我手里十多个 我得折腾多少年了........ xiexiefenmxiang
页:
[1]