hyr12358 发表于 2023-3-7 21:55

860A-V2.1B线刷[0x10103005]Romcode/初始化DDR/下载数据/读取镜像失败

本帖最后由 hyr12358 于 2023-3-7 21:54 编辑

盒子是北京联通B860A-V2.1-B,刷了论坛这个帖子里https://www.znds.com/tv-1200464-1-1.html的固件。
这个固件刷的时候要求双钩,并且选择覆盖烧录密钥。

刷完正常开机,但是没有root和adb。想更换,线刷发现固件锁死。进度1%,报错。


Romcode/初始化DDR/下载数据/读取镜像失败。

日志如下
--USB_Burning_Tool soft Version: V2.1.6.8
--Windows Version: Microsoft Windows 7, Bit: 64
--Scan usb device
--Aml scan WorldCup Device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8
--DevPath:\\?\pci#ven_8086&dev_27c8&subsys_301b17aa&rev_01#3&11583659&0&e8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&53e33bb&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->Other device
-------->Other device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9
--DevPath:\\?\pci#ven_8086&dev_27c9&subsys_301b17aa&rev_01#3&11583659&0&e9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&328225bd&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->Other device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA
--DevPath:\\?\pci#ven_8086&dev_27ca&subsys_301b17aa&rev_01#3&11583659&0&ea#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&1a33a40c&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB
--DevPath:\\?\pci#ven_8086&dev_27cb&subsys_301b17aa&rev_01#3&11583659&0&eb#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&1d8cb56c&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
--Host: Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC
--DevPath:\\?\pci#ven_8086&dev_27cc&subsys_301b17aa&rev_01#3&11583659&0&ef#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB20#4&4afb4e1&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
--Scan USB host controller complete
--Update data center with HubMap
--Scan end
--User click open button
--Image path E:\BaiduNetdiskDownload\aml_upgrade_package_tianjing_emmc.img
--OpenImg E:\BaiduNetdiskDownload\aml_upgrade_package_tianjing_emmc.img
--check img crc success!
Parse platform.conf
--Parsing burning package
--Load configuration file D:\Program Files (x86)\Amlogic\USB_Burning_Tool\temp
--Parse burning configuration file D:\Program Files (x86)\Amlogic\USB_Burning_Tool\temp\burn_config.xml
--Get burning key
--User click start button
--SetErase
--Enable burning 1
--Scan usb device
--Aml scan WorldCup Device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8
--DevPath:\\?\pci#ven_8086&dev_27c8&subsys_301b17aa&rev_01#3&11583659&0&e8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&53e33bb&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->Other device
-------->Other device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9
--DevPath:\\?\pci#ven_8086&dev_27c9&subsys_301b17aa&rev_01#3&11583659&0&e9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&328225bd&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->Other device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA
--DevPath:\\?\pci#ven_8086&dev_27ca&subsys_301b17aa&rev_01#3&11583659&0&ea#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&1a33a40c&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB
--DevPath:\\?\pci#ven_8086&dev_27cb&subsys_301b17aa&rev_01#3&11583659&0&eb#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&1d8cb56c&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
--Host: Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC
--DevPath:\\?\pci#ven_8086&dev_27cc&subsys_301b17aa&rev_01#3&11583659&0&ef#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB20#4&4afb4e1&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
--Scan USB host controller complete
--Update data center with HubMap
--Scan end
--Catch DBT_DEVICEARRIVAL
--Scan usb device
--Aml scan WorldCup Device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8
--DevPath:\\?\pci#ven_8086&dev_27c8&subsys_301b17aa&rev_01#3&11583659&0&e8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&53e33bb&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->Other device
-------->Other device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9
--DevPath:\\?\pci#ven_8086&dev_27c9&subsys_301b17aa&rev_01#3&11583659&0&e9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&328225bd&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->Other device
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA
--DevPath:\\?\pci#ven_8086&dev_27ca&subsys_301b17aa&rev_01#3&11583659&0&ea#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&1a33a40c&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
--Host: Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB
--DevPath:\\?\pci#ven_8086&dev_27cb&subsys_301b17aa&rev_01#3&11583659&0&eb#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB#4&1d8cb56c&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
--Host: Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC
--DevPath:\\?\pci#ven_8086&dev_27cc&subsys_301b17aa&rev_01#3&11583659&0&ef#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
---->Roothub:USB#ROOT_HUB20#4&4afb4e1&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->\\?\usb#vid_1b8e&pid_c003#5&30fec54f&0&5#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
-------->NoDeviceConnected
-------->NoDeviceConnected
-------->NoDeviceConnected
--Scan USB host controller complete
--Update data center with HubMap
--Insert new hub5
--Update hub5 device data
--Update HUB5-1
--Update device path
--Update HUB5-2
--Update device path
--Update HUB5-3
--Update device path
--Update HUB5-4
--Update device path
--Update HUB5-5 \\?\usb#vid_1b8e&pid_c003#5&30fec54f&0&5#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
--Update device path
--Begin thread for HUB5-5
--Burning thread HUB5-5 start
--Update HUB5-6
--Update device path
--Burning thread HUB5-5 begin run
--Update HUB5-7
--Update device path
--Update HUB5-8
--Update device path
--Add Hub5: \\.\USB#ROOT_HUB20#4&4afb4e1&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} to m_HubDeviceDataVector
--Open device handle \\?\usb#vid_1b8e&pid_c003#5&30fec54f&0&5#{a5dcbf10-6530-11d2-901f-00c04fb951ed}0x000005f8
--Scan end
--CloneImageProxy
--OpenImg E:\BaiduNetdiskDownload\aml_upgrade_package_tianjing_emmc.img
--Connect path=Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC/P0/P4
--Start burning...
--------------ERASE BOOTLOADER------------
--start SendIdentifyCmd
--2-4-0-0
-------------Download DDR.USB-----------
--Download DDR.USB,size: 49152!
--2-4-0-0
--Control write pll reg1 0xd9000000:0x000000b1
--Control write pll reg1 0xd9000000:0x00005183
--Control write pll reg1 0xd9000000:0x000000b1
--Control write pll reg1 0xd9000000:0x00005183
--Write initial succeed
--Upload encrypt at 0xc8100228
--ulValue = 0xbdfd31bc
--File change to DDR_ENC.USB
--Read encrypt value succeed
--DDR_ENC.USB
--DDR_ENC.USB
--Read item data error, code -1
--DDR_ENC.USB
--Romcode/初始化DDR/下载数据/读取镜像失败
--Close device handle 0x000005f8TTL也锁死,无法输入。日志如下
GXLX:BL1:9ac50e:4a8da0;FEAT:BDFD31BC:0;POC:3;RCY:0;EMMC:0;READ:0;0.0;0.0;CHK:0;
TE: 198309

BL2 Built : 14:48:45, Sep 26 2018.
gxl g6d68897 - yao.zhang@droid07

Board ID = 4, adc=304
set vcck to    1120 mv
set vddee to 1000 mv
CPU clk: 1200MHz
DDR3LPower:
DDR3 chl: Rank0+1 @ 912MHz - FAIL
DDR3 chl: Rank0 @ 912MHz
bist_test rank: 0 15 00 2a 2a 13 42 16 00 2c 2c 15 44 19 04 2f 29 11 42 18 03 2e 2a 13 42 702   - PASS

Rank0: 1024MB(auto)-2T-13
AddrBus test pass!
-s
Load fip header from eMMC, src: 0x0000c200, des: 0x01400000, size: 0x00004000
aml log : R2048 check pass!
New fip structure!
Load bl30 from eMMC, src: 0x00010200, des: 0x01700000, size: 0x00007600
aml log : R2048 check pass!
Load bl301 from eMMC, src: 0x00018200, des: 0x01700000, size: 0x00002600
aml log : R2048 check pass!
Load bl31 from eMMC, src: 0x0001c200, des: 0x01700000, size: 0x00019600
aml log : R2048 check pass!
Load bl33 from eMMC, src: 0x00038200, des: 0x01700000, size: 0x00080600
aml log : R2048 check pass!
NOTICE:BL3-1: v1.0(debug):f10670a
NOTICE:BL3-1: Built : 16:48:58, Nov 14 2018
NOTICE:BL31: GXL secure boot!
NOTICE:BL31: BL33 decompress pass


efuse init ops = c1


efuse init hdcp = c, cf9=7


bl30: check_permit, count is 1


bl30: check_permit: ok!


chipid: 0 0 7 1c c 0 f2 b3 a0 a0 0 c1 not ES chip



INFO:    BL3-1: Initializing runtime services
WARNING: No OPTEE provided by BL2 boot loader
ERROR:   Error initializing runtime service opteed_fast
INFO:    BL3-1: Preparing for EL3 exit to normal world
INFO:    BL3-1: Next image address = 0x1000000
INFO:    BL3-1: Next image spsr = 0x3c9


U-Boot 2015.01-g49ae8bc-dirty (Dec 15 2018 - 12:19:02)

DRAM:1 GiB
reboot_mode=cold_boot
aml log : R2048 check pass!

: tee size: 0


set osd_size 720p
bootmode:NORM
aml log : R2048 check pass!
aml log : R2048 check pass!
aml log : R2048 check pass!
OK
uboot time: 3955697 us
[    0.000000@0][    0/swapp] Initializing cgroup subsys cpu
[    0.000000@0][    0/swapp] Initializing cgroup subsys cpuacct
[    0.000000@0][    0/swapp] CPU: ARMv71 Processor revision 4
[    0.000000@0][    0/swapp] no prop version_code
[    0.000000@0][    0/swapp] bootconsole enabled
get_dvfs_info 0004
[    0.695712@0][    1/swapp] Initramfs unpacking failed: junk in compressed archive
INFO:    HDCP22 key read fail!
INFO:    p1d 0
INFO:    pd1 0
[    盵BL31]: tee size: 0
: tee size: 0
: tee size: 0
: tee size: 0
WARNING: Unimplemented Sip Call: 0x82000036
root@p200_2G:/ # 这里无法输入任何中断指令
[    9.584708@2][ 5960/Threa] monitor: received netlink message:ztebw ok
[    9.585503@2][ 5960/Threa] monitor:reply再往下无任何TTL输出了。
貌似是有固件锁,需要降级。
开机按遥控左键可以进uboot,但是没有卡刷包。

求大神指导刷机方法或降级包。

Terminator-zx 发表于 2024-1-12 10:18

有解决的吗?发下教程

被风吹过的夏天 发表于 2023-3-7 22:38

废了,固件加密,处理器已经熔断了

01z8z0 发表于 2023-8-1 21:15

可以启动tf卡的meson1.dtb 然后刷rec twrp就OK

有教程吗?

这名儿不错 发表于 2023-7-1 13:29

aml burn card

hyr12358 发表于 2023-3-9 00:07

虽然能用,但是心里很不安。好比软禁了人,可以与外界交流,就是出不去。不知固件作者加密用意为何,也不明说固件加密。像盒子这些基本不断电不断网的设备,不禁生疑,会不会留了后门,刷完变为矿机。

hyr12358 发表于 2023-3-9 00:07

虽然能用,但是心里很不安。好比软禁了人,可以与外界交流,就是出不去。不知固件作者加密用意为何,也不明说固件加密。像盒子这些基本不断电不断网的设备,不禁生疑,会不会留了后门,刷完变为矿机。

这名儿不错 发表于 2023-7-1 13:28

可以启动tf卡的meson1.dtb 然后刷rec twrp就OK

这名儿不错 发表于 2023-7-1 13:29

aml burn car

01z8z0 发表于 2023-8-1 21:12


aml burn card
有详细教程吗?

杰斯丁 发表于 2023-12-2 11:35

这名儿不错 发表于 2023-7-1 13:28
可以启动tf卡的meson1.dtb 然后刷rec twrp就OK

大哥有教程吗?
页: [1] 2
查看完整版本: 860A-V2.1B线刷[0x10103005]Romcode/初始化DDR/下载数据/读取镜像失败