狮缘雅隐 发表于 2022-8-26 14:14

北京移动魔百和 CM211-1 MC022 原系统固件分享

本帖最后由 狮缘雅隐 于 2022-8-26 22:47 编辑

注意这是盒子的原系统固件
盒子型号是北京移动 CM211-1
板子号是MC022
盒子照片看下面链接
https://www.znds.com/tv-1221967-1-1.html
跑码如下
GXLX2:BL1:3cfee7:42a5ae;FEAT:ADFD318C:0;POC:3;RCY:0;EMMC:0;READ:0;0.0;CHK:0;
TE: 42763

BL2 Built : 13:36:55, Jun 22 2020.
gxl g85d6ad1 - longyong.chen@droid02-sz

Board ID = 4, adc=302
set vcck to 1070 mv
set vddee to 1070 mv
sunniwell 4L/8bit_ddr board
CPU clk: 1200MHz
DDR3
DDR3 chl: Rank0+1 @ 792MHz - FAIL
DDR3 chl: Rank0 @ 792MHz
bist_test rank: 0 29 03 4f 3e 1b 62 27 00 4f 44 20 68 28 02 4e 3f 19 65 2a 02 52       3e 18 64 568   - PASS

Rank0: 2048MB(auto)-2T-11
AddrBus test pass!
-s
Load fip header from eMMC, src: 0x0000c200, des: 0x01400000, size: 0x00004000
New fip structure!
Load bl30 from eMMC, src: 0x00010200, des: 0x013c0000, size: 0x00007600
Load bl301 from eMMC, src: 0x00018200, des: 0x01380000, size: 0x00002200
Load bl31 from eMMC, src: 0x0001c200, des: 0x10100000, size: 0x00019600
Load bl33 from eMMC, src: 0x00038200, des: 0x01000000, size: 0x00069e00
NOTICE:BL3-1: v1.0(debug):361f8a7
NOTICE:BL3-1: Built : 16:43:26, Dec 19 2018
NOTICE:BL31: GXL normal boot!
NOTICE:BL31: BL33 decompress pass

efuse init ops = c5
efuse init hdcp = c, cf9=7
x2_hp_e = 0
bl30: check_permit, count is 1
bl30: check_permit: ok!
chipid: 0 0 3 c c 0 51 b4 a0 a0 0 c5 not ES chip

INFO:    BL3-1: Initializing runtime services
WARNING: No OPTEE provided by BL2 boot loader
ERROR:   Error initializing runtime service opteed_fast
INFO:    BL3-1: Preparing for EL3 exit to normal world
INFO:    BL3-1: Next image address = 0x1000000
INFO:    BL3-1: Next image spsr = 0x3c9


U-Boot 2015.01-g3b799e1-dirty (Apr 17 2021 - 17:49:32)

DRAM:2 GiB
Relocation Offset is: 76eaf000
gpio: pin GPIODV_25 (gpio 44) value is 1
gpio: pin GPIOZ_14 (gpio 73) value is 1
register usb cfg = 0000000077f5c8c0
canvas init
vpu: error: vpu: check dts: FDT_ERR_BADMAGIC, load default parameters
vpu: clk_level = 7
vpu: set clk: 666667000Hz, readback: 666660000Hz(0x300)
vpp: vpp_init
boot_device_flag : 1
Nand PHY Ver:1.01.001.0006 (c) 2013 Amlogic Inc.
init bus_cycle=6, bus_timing=7, system=5.0ns
reset failed
get_chip_type and ret:fffffffe
get_chip_type and ret:fffffffe
chip detect failed and ret:fffffffe
nandphy_init failed and ret=0xfffffff1
MMC:   aml_priv->desc_buf = 0x0000000073e9fbf0
aml_priv->desc_buf = 0x0000000073ea1f10
SDIO Port B: 0, SDIO Port C: 1
emmc/sd response timeout, cmd8, status=0x1ff2800
emmc/sd response timeout, cmd55, status=0x1ff2800
mmc init success
dtb magic 08088b1f
      Amlogic multi-dtb tool
      GZIP format, decompress...
      Multi dtb detected
      unified board, board id = 4
      Multi dtb tool version: v2 .
      Support 16 dtbs.
      aml_dt soc: gxlx2 platform: p291 variant: 2g
      dtb 0 soc: gxl   plat: p211   vari: 1g
      dtb 1 soc: gxl   plat: p211   vari: 512m
      dtb 2 soc: gxl   plat: p215   vari: 1g
      dtb 3 soc: gxlx   plat: p261   vari: 1g
      dtb 4 soc: gxlx   plat: p261   vari: 2g
      dtb 5 soc: gxlx   plat: p261   vari: 2g028
      dtb 6 soc: gxlx   plat: p261   vari: 2g2
      dtb 7 soc: gxlx   plat: p261   vari: 512m
      dtb 8 soc: gxlx   plat: p265   vari: 1g
      dtb 9 soc: gxlx   plat: p265   vari: 2g
      dtb 10 soc: gxlx2   plat: p291   vari: 1g
      dtb 11 soc: gxlx2   plat: p291   vari: 2g
      dtb 12 soc: gxlx2   plat: p291   vari: 2g028
      dtb 13 soc: gxlx2   plat: p291   vari: 512m
      dtb 14 soc: gxlx2   plat: p295   vari: 1g
      dtb 15 soc: gxlx2   plat: p295   vari: 2g
      Find match dtb: 11
start dts,buffer=0000000073ea4740,dt_addr=0000000073ea4740
      Amlogic multi-dtb tool
      Single dtb detected
parts: 14
00:      logo   0000000002000000 1
01:recovery   0000000002000000 1
02:       rsv   0000000000800000 1
03:       tee   0000000000800000 1
04:   crypt   0000000002000000 1
05:      misc   0000000002000000 1
06: instaboot   0000000020000000 1
07:      boot   0000000002000000 1
08:    system   0000000040000000 1
09:   cache   0000000020000000 2
10:    params   0000000004000000 2
11: bootfiles   0000000020000000 2
12:      swdb   0000000001000000 2
13:      data   ffffffffffffffff 4
eMMC/TSD partition table have been checked OK!
check pattern success
mmc env offset: 0x27400000
In:    serial
Out:   serial
Err:   serial
board id is : 4
hpd_state=0
cvbs performance type = 7, table = 1
To run cmd
_verify_dtb_checksum()-924: calc 6d686a2f, store 6d686a2f
_verify_dtb_checksum()-924: calc 6d686a2f, store 6d686a2f
dtb_read()-1046: total valid 2
dtb_read()-1113: do nothing
      Amlogic multi-dtb tool
      GZIP format, decompress...
      Multi dtb detected
      unified board, board id = 4
      Multi dtb tool version: v2 .
      Support 16 dtbs.
      aml_dt soc: gxlx2 platform: p291 variant: 2g
      dtb 0 soc: gxl   plat: p211   vari: 1g
      dtb 1 soc: gxl   plat: p211   vari: 512m
      dtb 2 soc: gxl   plat: p215   vari: 1g
      dtb 3 soc: gxlx   plat: p261   vari: 1g
      dtb 4 soc: gxlx   plat: p261   vari: 2g
      dtb 5 soc: gxlx   plat: p261   vari: 2g028
      dtb 6 soc: gxlx   plat: p261   vari: 2g2
      dtb 7 soc: gxlx   plat: p261   vari: 512m
      dtb 8 soc: gxlx   plat: p265   vari: 1g
      dtb 9 soc: gxlx   plat: p265   vari: 2g
      dtb 10 soc: gxlx2   plat: p291   vari: 1g
      dtb 11 soc: gxlx2   plat: p291   vari: 2g
      dtb 12 soc: gxlx2   plat: p291   vari: 2g028
      dtb 13 soc: gxlx2   plat: p291   vari: 512m
      dtb 14 soc: gxlx2   plat: p295   vari: 1g
      dtb 15 soc: gxlx2   plat: p295   vari: 2g
      Find match dtb: 11
wipe_data=successful
wipe_cache=successful
bmp pixel: 24
load fb addr from dts
fb_addr for logo: 0x3dc00000
load fb addr from dts
fb_addr for logo: 0x3dc00000
addr=0x3dc00000 width=5760, height=2160
upgrade_step=2
amlkey_init() enter!
keynum is 4
: tee size: 0
rebootmode=cold_boot
key1 = 7d82dd22
key2 = 7e81dd22
key3 = 728ddd22
time_out = 7a120
ir init
irkey - irkey key_value1 key_value2 key_value3 time_value

Usage:
irkey
ee_gate_off ...
## Booting Android Image at 0x01080000 ...
reloc_addr =73f24990
copy done
      Amlogic multi-dtb tool
      Single dtb detected
load dtb from 0x1000000 ......
   Uncompressing Kernel Image ... OK
   kernel loaded at 0x01080000, end = 0x020950f0
   Loading Ramdisk to 73da0000, end 73e9c471 ... OK
   Loading Device Tree to 000000000fff3000, end 000000000ffffc7b ... OK
signature:
fdt_instaboot: get header err

Starting kernel ...

uboot time: 2675020 us
[    0.000000@0] Initializing cgroup subsys cpu
[    0.000000@0] Initializing cgroup subsys cpuacct
[    0.000000@0] Linux version 3.14.29-g18c40508-dirty (luqian@T2) (gcc version       4.9.1 20140529 (prerelease) (crosstool-NG linaro-1.13.1-4.9-2014.07 - Linaro GCC       4.9-2014.06) ) #1 SMP PREEMPT Thu Mar 4 14:40:26 CST 2021
[    0.000000@0] CPU: ARMv71 Processor revision 4
[    0.000000@0] bootconsole enabled
get_dvfs_info 0004
INFO:    HDCP22 key read fail!
INFO:    p1d 0
INFO:    pd1 0
: tee size: 0
: tee size: 0
: tee size: 0
: tee size: 0
WARNING: Unimplemented Sip Call: 0x82000036
root@p201_iptv:/ #
下载链接见附件

狮缘雅隐 发表于 2022-8-26 14:18

北京移动魔百和 CM211-1 MC022 原系统固件

本帖最后由 狮缘雅隐 于 2022-8-26 21:41 编辑

盒子固件信息如下
root@p201_iptv:/ # ll /dev/block
brw------- root   root   179,12 2015-01-01 08:00 boot
brw------- root   root   179,15 2015-01-01 08:00 bootfiles
brw------- root   root   179,   1 2015-01-01 08:00 bootloader
brw------- root   root   179,   3 2015-01-01 08:00 cache
brw------- root   root   179,   9 2015-01-01 08:00 crypt
brw------- root   root   179,17 2015-01-01 08:00 data
brw------- root   root   179,   4 2015-01-01 08:00 env
brw------- root   root   179,11 2015-01-01 08:00 instaboot
brw------- root   root   179,   5 2015-01-01 08:00 logo
brw------- root   root       7,   0 2015-01-01 08:00 loop0
brw------- root   root       7,   1 2015-01-01 08:00 loop1
brw------- root   root       7,   2 2015-01-01 08:00 loop2
brw------- root   root       7,   3 2015-01-01 08:00 loop3
brw------- root   root       7,   4 2015-01-01 08:00 loop4
brw------- root   root       7,   5 2015-01-01 08:00 loop5
brw------- root   root       7,   6 2015-01-01 08:00 loop6
brw------- root   root       7,   7 2015-01-01 08:00 loop7
brw------- root   root   179,10 2015-01-01 08:00 misc
brw------- root   root   179,   0 2015-01-01 08:00 mmcblk0
brw------- root   root   179,32 2015-01-01 08:00 mmcblk0boot0
brw------- root   root   179,64 2015-01-01 08:00 mmcblk0boot1
brw------- root   root   179,96 2015-01-01 08:00 mmcblk0rpmb
brw------- root   root   179,14 2015-01-01 08:00 params
drwxr-xr-x root   root            2015-01-01 08:00 platform
brw------- root   root   179,   6 2015-01-01 08:00 recovery
brw------- root   root   179,   2 2015-01-01 08:00 reserved
brw------- root   root   179,   7 2015-01-01 08:00 rsv
brw------- root   root   179,16 2015-01-01 08:00 swdb
brw------- root   root   179,13 2015-01-01 08:00 system
brw------- root   root   179,   8 2015-01-01 08:00 tee
drwxr--r-- root   root            2015-01-01 08:00 vold
brw------- root   root   253,   0 2015-01-01 08:00 zram0
root@p201_iptv:/ # ls
acct
backup
boot
bootfiles
cache
config
d
data
default.prop
dev
etc
file_contexts
fstab.data.amlogic
fstab.other.amlogic
fstab.system.amlogic
init
init.amlogic.board.rc
init.amlogic.rc
init.amlogic.usb.rc
init.amlogic.wifi.rc
init.amlogic.wifibt.unisoc.rc
init.environ.rc
init.mtk.rc
init.rc
init.trace.rc
init.usb.rc
mnt
params
proc
property_contexts
root
sbin
sdcard
seapp_contexts
sepolicy
storage
swap_zram0
swdb
sys
system
tmp
ueventd.amlogic.rc
ueventd.rc
vendor
root@p201_iptv:/ #

不爱耍脾气小孩 发表于 2022-8-26 14:39

狮缘雅隐 发表于 2022-8-26 21:43

备份固件跑码如下
f=/storage/external_storage/sda1/boot.img                                     <
65536+0 records in
65536+0 records out
33554432 bytes transferred in 0.652 secs (51463852 bytes/sec)
s of=/storage/external_storage/sda1/bootfiles.img                           <
1048576+0 records in
1048576+0 records out
536870912 bytes transferred in 64.861 secs (8277253 bytes/sec)
er of=/storage/external_storage/sda1/bootloader.img                           <
8192+0 records in
8192+0 records out
4194304 bytes transferred in 0.100 secs (41943040 bytes/sec)
=/storage/external_storage/sda1/cache.img                                     <
1048576+0 records in
1048576+0 records out
536870912 bytes transferred in 108.108 secs (4966060 bytes/sec)
=/storage/external_storage/sda1/crypt.img                                     <
65536+0 records in
65536+0 records out
33554432 bytes transferred in 0.759 secs (44208737 bytes/sec)
/storage/external_storage/sda1/data.img                                       <
^[A/storage/external_storage/sda1/data.img: write error: File too large
8388608+0 records in
8388607+1 records out
4294967295 bytes transferred in 965.564 secs (4448143 bytes/sec)
/storage/external_storage/sda1/env.img                                        <
16384+0 records in
16384+0 records out
8388608 bytes transferred in 0.195 secs (43018502 bytes/sec)
t of=/storage/external_storage/sda1/instaboot.img                           <
1048576+0 records in
1048576+0 records out
536870912 bytes transferred in 106.170 secs (5056710 bytes/sec)
/storage/external_storage/sda1/logo.img                                       <
65536+0 records in
65536+0 records out
33554432 bytes transferred in 0.717 secs (46798370 bytes/sec)
=/storage/external_storage/sda1/loop0.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop1.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop2.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop3.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop4.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop5.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop6.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
=/storage/external_storage/sda1/loop7.img                                     <
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
/storage/external_storage/sda1/misc.img                                       <
65536+0 records in
65536+0 records out
33554432 bytes transferred in 0.721 secs (46538740 bytes/sec)
of=/storage/external_storage/sda1/mmcblk0.img                                 <
/storage/external_storage/sda1/mmcblk0.img: write error: File too large
8388608+0 records in
8388607+1 records out
4294967295 bytes transferred in 936.216 secs (4587581 bytes/sec)
of=/storage/external_storage/sda1/mmcblk0boot0.img                            <
8192+0 records in
8192+0 records out
4194304 bytes transferred in 0.109 secs (38479853 bytes/sec)
of=/storage/external_storage/sda1/mmcblk0boot1.img                            <
8192+0 records in
8192+0 records out
4194304 bytes transferred in 0.101 secs (41527762 bytes/sec)
f=/storage/external_storage/sda1/mmcblk0rpmb.img                              <
8192+0 records in
8192+0 records out
4194304 bytes transferred in 0.098 secs (42799020 bytes/sec)
orage/external_storage/sda1/params.img                                        <
131072+0 records in
131072+0 records out
67108864 bytes transferred in 1.270 secs (52841625 bytes/sec)
storage/external_storage/sda1/platform.img                                    <
/dev/block/platform: read error: Is a directory
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
/storage/external_storage/sda1/recovery.img                                 <
65536+0 records in
65536+0 records out
33554432 bytes transferred in 0.644 secs (52103155 bytes/sec)
storage/external_storage/sda1/reserved.img                                    <
131072+0 records in
131072+0 records out
67108864 bytes transferred in 1.283 secs (52306207 bytes/sec)
ge/external_storage/sda1/rsv.img                                              <
16384+0 records in
16384+0 records out
8388608 bytes transferred in 0.175 secs (47934902 bytes/sec)
ge/external_storage/sda1/sda.img                                              <
/storage/external_storage/sda1/sda.img: write error: File too large
8388608+0 records in
8388607+1 records out
4294967295 bytes transferred in 1136.847 secs (3777964 bytes/sec)
rage/external_storage/sda1/sda1.img                                           <
/storage/external_storage/sda1/sda1.img: write error: File too large
8388608+0 records in
8388607+1 records out
4294967295 bytes transferred in 1085.282 secs (3957466 bytes/sec)

age/external_storage/sda1/vold.img                                          <
/dev/block/vold: read error: Is a directory
0+0 records in
0+0 records out
0 bytes transferred in 0.001 secs (0 bytes/sec)
1|root@p201_iptv:/ #
age/external_storage/sda1/tee.img                                             <
16384+0 records in
16384+0 records out
8388608 bytes transferred in 0.190 secs (44150568 bytes/sec)
age/external_storage/sda1/swdb.img                                          <
32768+0 records in
32768+0 records out
16777216 bytes transferred in 0.332 secs (50533783 bytes/sec)
orage/external_storage/sda1/system.img                                        <
2097152+0 records in
2097152+0 records out
1073741824 bytes transferred in 210.877 secs (5091792 bytes/sec)
root@p201_iptv:/ #
其中bootloader同时也备份有bin格式

狮缘雅隐 发表于 2022-8-26 22:39

现在刷了一个IPTV的固件
安卓4.42的
下面是新固件跑码信息

狮缘雅隐 发表于 2022-8-27 20:49

我这盒子很是特殊
注意看图片,闪存是nand的,但注意看跑码信息,确实emmc
还有就是这个款机子的芯片是晶晨S905L3-B,而同型号同板号的也有S905L的
所以刷机的时候一定要看清楚
其中3-B刷armbian是没有网的
而S905L是有有线的,但无线似乎不行

ddythink 发表于 2023-1-17 20:53

请教一下,下载的固件解压出来好多个img怎么刷呢?

w77379228 发表于 2023-3-25 13:11

这个恢复是要TTL?

XYUU 发表于 2023-4-1 22:32

本帖最后由 XYUU 于 2023-4-3 18:52 编辑

我的ZXV10 B860AV2.1-A2中兴的盒子刷这个原版固件恢复成功,但IPTV无法使用,因为没法恢复三码。备份固件的时候没用列出EMCC的区块信息,所以不知道swdb这个分区实际在哪个区里,我看了swdb分区里边没有三码信息。另外,楼主这个固件备份的时候没看分区就直接把所有虚拟分区都备份了,然后目标存储空间又不足,导致最关键的备份:of=/storage/external_storage/sda1/mmcblk0.img                                 <
/storage/external_storage/sda1/mmcblk0.img: write error: File too large
8388608+0 records in
8388607+1 records out
4294967295 bytes transferred in 936.216 secs (4587581 bytes/sec)
报错了,没有备份成功。

taory 发表于 2023-5-17 18:27

备份怎么恢复?能讲一下吗?
页: [1] 2
查看完整版本: 北京移动魔百和 CM211-1 MC022 原系统固件分享