zzj80 发表于 2015-5-15 15:19

正常 天猫魔盒1s+(M10)TTL读取数据 求大神root方法

EEEE I3000000032940xf10011c336B77500EEEE I400000004294_M8_BL1_10221D113B323EEEE I3000000032940xbbbb000026A22525
no sdio debug board detected
TE : 1428474
BT : 12:53:13 Apr 13 2015
DCDC01 set to 1050, register from 0x0018 to 0x0024, addr:0x0036
DCDC02 set to 1150, register from 0x0018 to 0x002c, addr:0x0037
DCDC03 set to 1500, register from 0x0038 to 0x0048, addr:0x0038
LDO01 set to 2900, register from 0x004e to 0x0050, addr:0x004c
LDO02 set to 1800, register from 0x0024 to 0x0024, addr:0x004d
LDO03 set to 1800, register from 0x0030 to 0x0030, addr:0x004e
LDO04 set to 2850, register from 0x004e to 0x004e, addr:0x004f
LDO05 set to 1800, register from 0x0024 to 0x0024, addr:0x0050
LDO0a set to 2700, register from 0x0028 to 0x0028, addr:0x0056
LDO0b set to 900, register from 0x0000 to 0x0000, addr:0x0057

CPU clock is 792MHz

DDR clock is 768MHz with 1T mode

DDR check pass!

DDR init use : 8308 us

HHH
Start load SMP code!
Load SMP code finished!
Boot From SDIO C
0x0000008d
Aml log : M8-RSA-1024
Aml log : TPL secure check pass!
ucl decompress...pass
0x12345678
Boot from internal device 1st SDIO C

TE : 1687615

System Started


U-boot-00000-g2af4709(m8_mango_v1@2af4709b) (Apr 13 2015 - 12:53:02)

clr h-ram
DRAM:1 GiB
relocation Offset is: 2fec8000
show partition table:
part: 0, name :       logo, size : 1000000
part: 1, name :      logo1, size : 1000000
part: 2, name :   recovery, size : 2000000
part: 3, name :       boot, size : 2000000
part: 4, name :   system, size : 32000000
part: 5, name :      cache, size : 28000000
part: 6, name :   databk, size : c800000
part: 7, name :       swap, size : 19000000
part: 8, name :       data, size : end
aml_card_type=0x100
MMC:    add mmc dev_num=0, port=1, if_type=6
add mmc dev_num=1, port=2, if_type=6
SDIO Port B: 0, SDIO Port C: 1
led blue
PMU fault status:
reg = 0x1d
register usb cfg = 3ff73470
register usb cfg = 3ff70208
register usb cfg = 3ff73488
NAND:EMMC BOOT: not init nand
do not init nand : cause boot_device_flag without nand
get_boot_device_flag: init_ret -1
get_boot_device_flag EMMC BOOT:
Emmckey: Access range is illegal!
SDIO Port C:1, if_type=6, initialized OK!
skip cache partition.
Partition table get from SPL is :
      name                        offset            size            flag
===================================================================================
   0: bootloader                         0            400000                  0
   1: reserved                     2400000         4000000                  0
   2: cache                        6400000          28000000                  2
   3: env                         2e400000            800000                  0
   4: logo                        2ec00000         1000000                  1
   5: logo1                     2fc00000         1000000                  1
   6: recovery                  30c00000         2000000                  1
   7: boot                        32c00000         2000000                  1
   8: system                      34c00000          32000000                  1
   9: databk                      66c00000         c800000                  1
10: swap                        73400000          19000000                  1
11: data                        8c400000         145c00000                  4
mmc read lba=0x12000, blocks=0x1
mmc read lba=0x12001, blocks=0x1
mmc_read_partition_tbl: mmc read partition OK!
eMMC/TSD partition table have been checked OK!
i=0,register --- emmc_key
MMC BOOT, emmc_env_relocate_spec : env_relocate_spec 59
set_storage_device_flag: store 2
Unknown command 'm8_mango_1g' - try 'help'
Secure kernel sz 0x835c50
Aml log : M8-RSA-1024
Aml log : Image secure check pass!
      Multi dtb detected, support 2 dtbs.
      soc: "m8", platform: "mang", variant: "1g"
      soc_int: 6d382020, platform_int: 6d616e67, variant_int: 31672020
      0 dtb: soc 6d382020 plat 6d616e67 vari 31672020 "m8_mang_1g"
      1 dtb: soc 6d382020 plat 6d616e67 vari 32672020 "m8_mang_2g"
      Find match dtb: 0
vpu clk_level in dts: 7
set vpu clk: 364300000Hz, readback: 364300000Hz(0x700)
In:    serial
Out:   serial
Err:   serial
Net:   Meson_Ethernet
init suspend firmware done. (ret:0)
cvbs trimming.1.v5: 0xa0, 0x0
enter preboot...
-->reboot_mode:0x0
reboot_mode=charging
enter prepare...
mode = 6vic = 4
reconfig packet setting done
enter switch_bootmode...
reboot_mode charging
Hit Enter key to stop autoboot -- :0
exit abortboot: 0
check_boot_hang, boot_hang="0"
check_boot_hang, no need hang return.
enter storeboot...
Booting...
pos 509 value is 20not config efuse version
aml_keys: version 0 can not be init 3ff7369c
current storer:emmc_key
ERR(v2_common/optimus_download_key.c)L268:failed to query key state, rc 0, keyIsBurned=0
## ANDROID Format IMAGE
## Booting kernel from Legacy Image at 12000000 ...
   Image Name:   Linux-3.10.33
   Image Type:   ARM Linux Kernel Image (lzo compressed)
   Data Size:    6227205 Bytes = 5.9 MiB
   Load Address: 00208000
   Entry Point:00208000
   Verifying Checksum ... OK
    Ramdisk start addr = 0x125f1000, len = 0x239db6
      Multi dtb detected, support 2 dtbs.
      soc: "m8", platform: "mang", variant: "1g"
      soc_int: 6d382020, platform_int: 6d616e67, variant_int: 31672020
      0 dtb: soc 6d382020 plat 6d616e67 vari 31672020 "m8_mang_1g"
      1 dtb: soc 6d382020 plat 6d616e67 vari 32672020 "m8_mang_2g"
      Find match dtb: 0
    Flat device tree start addr = 0x1282b800, len = 0x4c94 magic=0xedfe0dd0
   Uncompressing Kernel Image ... OK
is_check_restored, bootm_mode="boot"
uboot time: 5425118 us.
EFUSE machid is not set.
Using machid 0xf81 from environment
From device tree /memory/ node aml_reserved_end property, for relocate ramdisk and fdt, relocate_addr: 0x5242001
   Loading Ramdisk to 05008000, end 05241db6 ... OK
   Loading Device Tree to 05000000, end 05007c93 ... OK

Starting kernel ...

[    0.000000@0] Global timer: MESON TIMER-F (c0ab0200) initialized
[    0.126558@0] ram_console: failed to create proc entry
[    0.132064@0] /home/jenkins/.jenkins/jobs/workspace/Release-amlogics802-1sp150313-MagicBox1s_Plus-secuser/common/drivers/amlogic/i2c/aml_i2c.c : aml_i2c_init
[    0.141401@0] aml_dvfs_probe, child name:vcck_dvfs
[    0.145784@0] dvfs table of vcck_dvfs is:
[    0.150302@0]    freq,    min_uV,    max_uV
[    0.155142@0]     96000,    825000,    825000
[    0.159996@0]    192000,    825000,    825000
[    0.164857@0]    312000,    825000,    825000
[    0.169704@0]    408000,    825000,    825000
[    0.174565@0]    504000,    825000,    825000
[    0.179413@0]    600000,    850000,    850000
[    0.184272@0]    720000,    850000,    850000
[    0.189121@0]    816000,    875000,    875000
[    0.193981@0] 1008000,    925000,    925000
[    0.198829@0] 1200000,    975000,    975000
[    0.203689@0] 1416000,   1025000,   1025000
[    0.208538@0] 1608000,   1100000,   1100000
[    0.213398@0] 1800000,   1125000,   1125000
[    0.218246@0] 1992000,   1150000,   1150000
[    0.268336@0] aml_dvfs_register_driver, driver rn5t618-dvfs regist success, mask:7, source id:1
[    0.272002@0] ricoh_pmu_probe, 296
[    0.504249@0] start read sedio dts
[    0.718573@0] rn5t618_otg_change, driver is not ready, do it later
[    1.068870@3] aml_rtc_init...
[    1.070813@3] call aml1216_battery_init, ret = 0
[    1.071372@1] ###check hw reset function is already enabled here
[    1.077668@3] call aml1218_battery_init, ret = 0
[    1.083044@1] call rn5t618_battery_probe in
[    1.088057@3] use BSP configed battery parameters
[    1.093407@3] NO BATTERY_PARAMETERS FOUND
[    1.098235@3] rn5t618_otg_work_fun, value:1, is_short:0
[    1.104646@3] set boost en bit, val:33
[    1.142505@3] call rn5t618_battery_probe exit, ret:0
[    1.142581@2] call rn5t618_battery_init, ret = 0
[    2.646858@3] init: mount none to target failed
[    [    2.863507@3] init: mount none to target failed
[    2.863642@3] init: mount none to target failed
[    2.866995@3] init: mount none to target failed
[    2.873440@3] init: mount none to target failed
[    2.884659@3] init: Before e2fsck_main...
[    3.210754@3] init: After e2fsck_main...
[    3.216455@3] init: Before e2fsck_main...
[    3.216626@3] init: After e2fsck_main...
[    3.230739@3] aml_keys: version 0 can not be init c0ad95d8
[    3.397207@1] init: /dev/hw_random not found
[    3.421039@1] init: cannot find '/system/etc/install-recovery.sh', disabling 'flash_recovery'
[    3.427137@1] init: cannot find '/system/bin/ou', disabling 'yunos_ou'
[    3.450020@1] init: property 'ro.usb.vendor.string' doesn't exist while expanding '${ro.usb.vendor.string}'
[    3.454198@1] init: cannot expand '${ro.usb.vendor.string}' while writing to '/sys/class/android_usb/android0/f_mass_storage/vendor_string'
[    3.466750@1] init: property 'ro.usb.product.string' doesn't exist while expanding '${ro.usb.product.string}'
[    3.476693@1] init: cannot expand '${ro.usb.product.string}' while writing to '/sys/class/android_usb/android0/f_mass_storage/product_string'
[    3.491076@1] init: property 'sys.powerctl' doesn't exist while expanding '${sys.powerctl}'
[    3.497917@1] init: powerctl: cannot expand '${sys.powerctl}'
[    3.503430@1] init: property 'sys.sysctl.extra_free_kbytes' doesn't exist while expanding '${sys.sysctl.extra_free_kbytes}'
[    3.514491@1] init: cannot expand '${sys.sysctl.extra_free_kbytes}' while writing to '/proc/sys/vm/extra_free_kbytes'
[    3.525018@1] init: property 'sys.kernel.panic' doesn't exist while expanding '${sys.kernel.panic}'
[    3.534382@1] init: cannot expand '${sys.kernel.panic}' while writing to '/proc/sys/kernel/panic'
[    3.543229@1] android_usb: already disabled
[    3.565162@3] init: data_integrity_guard main!
[    3.565206@3] init: is_support_system_bak sup_sys_bak:0
root@MagicBox1s_Plus:/ # [   18.055171@2] init: no such service 'wififix'
[   18.578680@3] init: data_integrity_guard isBootCompleted:1!
[   69.316274@0] init: sys_prop: permission denied uid:1013name:media.multich.support.info
[   85.120871@0] init: sys_prop: permission denied uid:1013name:media.multich.support.info


bo361583 发表于 2015-5-16 11:43

vpn78 发表于 2015-5-16 11:05
天猫把功夫全花在防root了,各位高手继续研究,我估计要硬改才能root

硬改也可以啊。。操作不要太复杂就行。。。以前搞过xbox自制,很麻烦。

vpn78 发表于 2015-5-16 11:05

天猫把功夫全花在防root了,各位高手继续研究,我估计要硬改才能root

soln 发表于 2015-5-19 12:06

zzj80 发表于 2015-5-18 00:15
备份文件在ubuntu下显示为 回环设备。文件系统显示未知,可能与rec的分区是mtd格式有关
...

1s+真的无法root无法了刷机了吗? 有点后悔买这盒子了~

兰我爱你一辈子 发表于 2015-5-18 07:33

大神厉害,支持你们

zzj80 发表于 2015-5-16 20:26

用dd命令备份recovery是32M。刷网上下载的rec后进入rec显示“启动文件损坏”不过系统能正常进入 。只能刷回备份rec求大神解决方法

zzj80 发表于 2015-5-16 10:27

不知用dd命令能不能成功,比如
备份recovery:
dd if=/dev/block/??? of=/sdcard/recovery.img
还原recovery:
dd if=/sdcard/recovery.img of=/dev/block/???

到不了了 发表于 2015-5-21 13:43

强烈支持楼主ing……

兰我爱你一辈子 发表于 2015-5-20 22:24

顶贴

shanxizt 发表于 2015-5-20 09:21

魔盒群里有人说用刷机精灵能root,连usb口不插电源

zzj80 发表于 2015-5-18 00:15

备份文件在ubuntu下显示为 回环设备。文件系统显示未知,可能与rec的分区是mtd格式有关

zzj80 发表于 2015-5-15 15:23

系统版本为2.4.0 固件版本为2.4.0-RS-20150413.1254

慌慌慌乱u 发表于 2015-5-15 15:24

{znds10}

ゝ.慌 发表于 2015-5-15 15:28

vpn78 发表于 2015-5-15 18:05

应该比较难root,大神应该也会看ttl,求大神出现...

兰我爱你一辈子 发表于 2015-5-15 19:21

求 root. 默认桌面不能啊

zzj80 发表于 2015-5-15 22:58

TTL连接进入后就是root权限,可是始终在flash_image recovery recovery.img时报错

skyarover 发表于 2015-5-16 08:10

zzj80 发表于 2015-5-15 22:58
TTL连接进入后就是root权限,可是始终在flash_image recovery recovery.img时报错

据说天猫设置了禁止读取!

ipcop 发表于 2015-5-16 08:43

我也折腾了很久,就是无法替换recovery 直接升级就过不了固件检测。

zzj80 发表于 2015-5-17 17:45

vpn78 发表于 2015-5-17 16:23
刷入网上下的recovery就显示损坏,刷回备份的就正常,既然能刷入,难道rec版本是突破口?不动求大神。。。 ...

我觉得刷入方式不对,或者备份方法不对。一般rec在10M内,备份出来的32M我想应该是整个rec分区。备份出来的文件在bantu下是磁盘映象,且不能解包。还原是还原整个分区而不是用新的rec直接还原分区

zzj80 发表于 2015-5-17 17:51

现将原机备份出来的rec分区共享出来。备份命令 dd if=/dev/block/recovery of=/storage/external_storage/sda4/recovery22.img

zzj80 发表于 2015-5-17 17:53

255|root@MagicBox1s_Plus:/ # cat /proc/ntd
dev:    size   erasesizename
inand01:    400000   80000 "bootloader"
inand02:   4000000   80000 "reserved"
inand03:28000000   80000 "cache"
inand04:    800000   80000 "env"
inand05:   1000000   80000 "logo"
inand06:   1000000   80000 "logo1"
inand07:   2000000   80000 "recovery"
inand08:   2000000   80000 "boot"
inand09:32000000   80000 "system"
inand10:   c800000   80000 "databk"
inand11:19000000   80000 "swap"
inand12: 145c00000   80000 "data"

zzj80 发表于 2015-5-19 12:52

soln 发表于 2015-5-19 12:06
1s+真的无法root无法了刷机了吗? 有点后悔买这盒子了~

如果知道天猫的防root措施方法,我想大神们很快就能搞定。更新系统都是在盒子里更新。天猫也不提供系统下载。如果有下载,大神们解包后也能很快搞定的吧?!
页: [1] 2 3 4 5 6 7 8
查看完整版本: 正常 天猫魔盒1s+(M10)TTL读取数据 求大神root方法