Cudy WR3000S v1

The Cudy WR3000S is a Wifi6 Router with 1x WAN and 4x LAN Gigabit Ports built around 64-bit Cortex-A53 SoC (Filogic 820 1.3GHz dual-core processor). It has a small form factor and 4 antennas.

As of Nov 2025: a new variant of WR3000S v1 (serial number date code 2543 or later, see below) was shipped with a new flash chip ESMT F50L1G41LC. This new variant is ONLY supported in version 24.10.5 or later. See PR #20962 for more information. If you are installing the latest version, OpenWrt itself is of no concern anymore, but a new-flash unit also needs the current Cudy-signed image (as of September 2026, the 20251119 build, see below). According to Cudy's notice on its Transition Firmware download page (linked below), the older Cudy-signed images will not boot on it, and stock 2.3.x or older must not be installed on it. The notice says newer stock releases will refuse that downgrade, but units can ship with older stock firmware (a 2026-built unit came with 2.4.6, built in May 2025), so do not rely on the refusal.

Reading the date code: Cudy's notice explains that “2543” in the serial number means 2025, week 43. Cudy uses two serial number formats. On serials starting with S000 (as on 2026-built units), characters 9 to 12 read as YYWW: for example S000xxxx2611xxxxx was built in 2026, week 11. Older labels have serials starting with WR3000S (see the Bottom photo under Photos); there the YYWW should follow the model name, as on WR3000H serials (WR3000H2543...), but this was not checked on a WR3000S. Both positions are inferred from a few units; Cudy does not document them. If in doubt, treat the unit as a new-flash unit. The OpenWrt boot log does not tell the two chips apart: the kernel prints only “ESMT SPI NAND was found”, without the LB/LC suffix. The stock firmware's serial boot log does name the part (see the OEM bootlog below: “Flash Model: F50L1G41LB, ID: C801”). According to the kernel patch that added the LC, it reports manufacturer ID 0x8C where the LB reports 0xC8, so the “SPI_NAND Detected ID” line that BL2 prints on the serial console should also differ (not verified on an LC unit).

Additional information can be found in this OpenWrt Forum thread and Cudy Transition Firmware download page.

Starting with 25.12.4 a ubootmod version is proposed. This mod unlocks the extra memory available, allowing using more packages and advanced features. It is not necessary for basic use of the router, and should only be considered for advanced users. Furthermore, returning to default setup requires a serial link and advanced skills. Information on how to install in the original commit.

Download the Cudy-signed OpenWrt image from the Cudy website https://drive.google.com/drive/folders/1BKVarlwlNxf7uJUtRhuMGUqeCa5KpMnj?usp=sharing

In the Drive folder take WR3000S 1.0.zip and unzip it: upload the .bin file inside, not the .zip. As of September 2026 the file is cudy_wr3000s-v1-sysupgrade_20251119.bin (14,945,872 bytes, MD5 403e276f74fd29917fd4260294d1a137). This build also supports the new F50L1G41LC flash, and once flashed it identifies as “OpenWrt 23.05-SNAPSHOT-CUDY”. The WR3000H, WR3000P and WR3000S files of that date have exactly the same size and names that differ by one letter, so check the MD5 before flashing. Comments of August 2026 on Cudy's Transition Firmware download page (linked in the info box above) report “File is invalid” when uploading an S intermediate. One was on a 2026-built unit, and the file's MD5 was not given. Another poster quoted this MD5 and later reported that the same Drive file was accepted on a retry. Cudy support's advice was to upload the unzipped .bin and, if the router is part of a Cudy mesh, to reset it to factory defaults and power off the other mesh units first. On a 2026-built unit with stock firmware 2.4.6, the unzipped .bin was accepted without problems.

Download the sysupgrade image from https://firmware-selector.openwrt.org/?target=mediatek%2Ffilogic&id=cudy_wr3000s-v1. DO NOT confuse it with the ubootmod version, unless you are planning to install it.

Power on the router, and proceed to basic setup with Cudy GUI start wizard: set as a Wireless router, enter your timezone, set WAN to DHCP.

Note: stock firmware 2.4.6 has no default admin password; its first page asks you to create one. Completing the wizard and connecting the WAN port may not be needed: on one 2026-built unit (stock 2.4.6), setting the admin password with no WAN cable attached was enough, the upload option was labeled Local Update, and its confirmation screen showed the MD5 of the uploaded file, so you can check it there. Cudy's release notes for stock 2.3.4 say the setup wizard turns automatic upgrade on by default, so if you run the wizard with WAN connected, consider turning it off.

Installation can be done easily with two steps. There will be no wifi available after first step, so be sure to use a wired client (LAN).

  1. Open Cudy GUI at http://192.168.10.1/ Go to Advanced Settings, Firmware. Flash the Cudy-signed OpenWrt image. Wait for the device to reboot.
  2. Open the custom OpenWrt LuCI at http://192.168.1.1/ Go to System/Backup flash firmware and flash the official OpenWrt sysupgrade image (or a custom image). DO NOT keep settings. Wait for the device to reboot.

The best time to back up the per-unit Factory and bdinfo partitions is before step 2, while the Cudy-signed image is running (see Flash Layout). The Cudy-signed image also runs SSH at 192.168.1.1 (user root, no password), so step 2 can also be done from the command line: copy the official sysupgrade image to /tmp on the router, for example with scp -O openwrt-25.12.5-mediatek-filogic-cudy_wr3000s-v1-squashfs-sysupgrade.bin root@192.168.1.1:/tmp/ (-O forces the legacy scp protocol; OpenSSH 9 and newer otherwise use SFTP, which a default OpenWrt image does not serve), then run sysupgrade -n /tmp/openwrt-25.12.5-mediatek-filogic-cudy_wr3000s-v1-squashfs-sysupgrade.bin (-n means settings are not kept). Both the copy and the sysupgrade -n step worked on a 2026-built unit.

The initial commit also describes an installation using a serial link, and an initramfs file.

root@WR3000S:~# cat /proc/mtd
dev:    size   erasesize  name
mtd0: 00100000 00020000 "BL2"
mtd1: 00080000 00020000 "u-boot-env"
mtd2: 00200000 00020000 "Factory"
mtd3: 00040000 00020000 "bdinfo"
mtd4: 00200000 00020000 "FIP"
mtd5: 04000000 00020000 "ubi"

The same layout was read on a 2026-built unit, both on the Cudy-signed image and on OpenWrt 25.12.5:

Partition Offset Size Contents
BL2 0x000000 1 MiB first-stage bootloader (Cudy's)
u-boot-env 0x100000 512 KiB U-Boot environment (found empty)
Factory 0x180000 2 MiB Wi-Fi calibration data (MT7981 EEPROM; OpenWrt uses the first 4 KiB), unique per unit
bdinfo 0x380000 256 KiB board data; the label (base) MAC address is at offset 0xde00, unique per unit
FIP 0x3c0000 2 MiB BL31 + U-Boot (Cudy's)
ubi 0x5c0000 64 MiB UBI: OpenWrt kernel, root filesystem (squashfs) and overlay

The flash is a 128 MiB SPI-NAND with NMBM bad-block management; the last 64 blocks (from block 960, offset 0x7800000) hold the NMBM tables and spare blocks. OpenWrt marks every partition except ubi read-only. With this layout, OpenWrt 25.12.5 creates a 48 MiB rootfs_data (UBIFS) volume for the overlay; the free space df reports is lower.

Back up Factory and bdinfo before you go further. Both are unique to each unit, neither is in any download, and a reset does not restore them. A normal sysupgrade only rewrites ubi, but a later mistake (wrong image, bootloader work, serial recovery) can cost the unit its Wi-Fi calibration and MAC addresses. From a Linux PC (or Git Bash on Windows; in Windows PowerShell 5.1, > corrupts binary output), while the Cudy-signed image or OpenWrt is running:

ssh root@192.168.1.1 'cat /dev/mtd2' > Factory.bin
ssh root@192.168.1.1 'cat /dev/mtd3' > bdinfo.bin
ssh root@192.168.1.1 'sha256sum /dev/mtd2 /dev/mtd3'
sha256sum Factory.bin bdinfo.bin

The hashes of each pair must match. Before a ubootmod conversion, save BL2 (mtd0), u-boot-env (mtd1) and FIP (mtd4) the same way; they are needed to go back to the Cudy layout.

Initial commit informations

1. Connect to the serial port as described in the “Hardware” section.

2. Power on the device + press reset pin. Keep pressing reset pin to enter the U-Boot shell.

3. Download the OpenWrt initramfs image. Place it on an TFTP server connected to the Cudy LAN ports. Make sure the server is reachable at 192.168.1.88. Rename the image to “cudy3000s.bin”.

4. Download and boot the OpenWrt initramfs image.

 $ tftpboot 0x46000000 cudy3000s.bin; bootm 0x46000000

5. Transfer the OpenWrt sysupgrade image to the device using scp. Install with sysupgrade.

Upgrading can be done with the usual methods : SSH from command line, or within LuCI.

If it's a soft brick (bad configuration, incorrect package selection, etc.) you can:

  • Reset the router pressing the “reset” button for 10 seconds after boot. This deletes all router configuration and you can start with a clean install on minutes.
  • Entering failsafe mode, where you can fix the problem manually.

More info: generic.debrick

If you need to fix a firmware problem (for example, a bad build) then trying with reset or failsafe doesn't work: it isn't possible to unbrick OpenWrt directly. The Cudy bootloader will start a TFTP client for OEM recovery using the Reset button, but this only accepts OEM firmware. So you need to reinstall OEM Firmware using the TFTP method, then reinstall vanilla OpenWrt afterwards.

Information on Cudy website : https://www.cudy.com/blogs/faq/how-to-recovery-the-cudy-router-from-openwrt-firmware-to-cudy-official-firmware

Additional notes:

  • Reset button timing, from /etc/rc.button/reset in OpenWrt 25.12.5: a press shorter than 1 s reboots the router, and releasing the button after 5 s or more runs the factory reset. Holding it for 10 s, as described above, therefore works.
  • Cudy's TFTP recovery is part of Cudy's own bootloader (BL2/FIP), so it is not available after a ubootmod conversion; OpenWrt's U-Boot then provides its own TFTP recovery instead (see Bootloader mods).
  • For new-flash units (serial date code 2543 or later), use a recent stock image for the recovery. Cudy's notice on its Transition Firmware download page warns against stock 2.3.x or older on these units, while stock 2.4.6 and 2.5.30, the latest as of September 2026 (files starting with WR3000S-R59-, from Cudy's download center), list both the old F50L1G41LB and the new F50L1G41LC flash chip in their drivers. (The TFTP recovery was not tested on a WR3000S.)

→ Basic configuration After flashing, proceed with this.
Set up your Internet connection, configure wireless, etc. The WR3000S has no USB port.

The default network configuration (OpenWrt 25.12.5) is:

Interface Name Description Default configuration
br-lan LAN bridge of lan1 to lan4; Wi-Fi joins it when enabled interface lan: static 192.168.1.1/24
lan1, lan2, lan3, lan4 LAN ports 1 to 4 (DSA ports of the MT7531 switch) members of br-lan
wan WAN port (DSA port of the MT7531 switch) interface wan: DHCP client; interface wan6: DHCPv6 client
eth0 SoC Ethernet, internal 2.5 Gb/s link to the switch (DSA conduit) no address
radio0 2.4 GHz Wi-Fi (platform/soc/18000000.wifi), 802.11ax up to 40 MHz channel 1, HE20, SSID OpenWrt, no encryption, disabled
radio1 5 GHz Wi-Fi (platform/soc/18000000.wifi+1), 802.11ax up to 160 MHz channel 36, HE80, SSID OpenWrt, no encryption, disabled

MAC addresses are derived from the label MAC, which is stored in bdinfo: eth0, br-lan and lan1-lan4 use the label MAC, wan uses label MAC + 1, the 2.4 GHz radio uses the label MAC, and the 5 GHz radio uses label MAC + 1 with the locally administered bit set (for example, a first octet of D4 becomes D6). The stock Cudy firmware derives its 5 GHz address differently, so the 5 GHz MAC changes after installing OpenWrt.

The five Ethernet ports are ports of the MediaTek MT7531 switch, driven by DSA. Each port is its own network device, named as printed on the case, and VLANs are set up with bridge VLAN filtering on br-lan rather than with eth0.N interfaces (see the DSA mini tutorial).

Port Switch port Network device (DSA)
Internet (WAN) 0 wan
LAN 1 1 lan1
LAN 2 2 lan2
LAN 3 3 lan3
LAN 4 4 lan4
internal CPU port 6 eth0 (conduit, fixed 2.5 Gb/s 2500base-x link)

All five front ports are 10/100/1000 Mb/s. The WAN port is 1 GbE, unlike the 2.5 GbE WAN of the WR3000H: on a 2026-built unit every port, WAN included, linked at 1 Gb/s against a 2.5 GbE-capable adapter. The 2500base-x entry in the device tree is the internal link between the switch and the SoC, not a front port. The network device names match the port labels (confirmed by moving a cable from port to port). Seen from the back, left to right: power, then reset (pinhole, above) and WPS (button, below), then LAN 4, LAN 3, LAN 2, LAN 1, WAN.

→ hardware.button on howto use and configure the hardware button(s). Here, we merely name the buttons, so we can use them in the above Howto.

The Cudy WR3000S has the following buttons:

BUTTON Event
Reset (pinhole, rear) reset
WPS (rear) wps

There is no power button (the WR3000H and WR3000P have one). Both buttons are gpio-keys, active low: Reset is KEY_RESTART on GPIO 1 and WPS is KEY_WPS_BUTTON on GPIO 0. Both generate their events on OpenWrt 25.12.5.

Front LED legend

The front panel has 10 lamps. Five are GPIO LEDs controlled by OpenWrt (table below); each was switched on by itself from /sys/class/leds to confirm that it matches its panel label. The WAN and LAN1-LAN4 lamps are driven by the MT7531 switch, not by GPIO: they do not appear in /sys/class/leds, so OpenWrt has no LED settings for them. On one unit running OpenWrt 25.12.5 with the OEM bootloader, they lit on link without any configuration (blinking on traffic was not checked).

Panel label LED name (/sys/class/leds) GPIO Default trigger
System white:status 10 none; OpenWrt uses it as the boot, failsafe, upgrade and running indicator
Internet white:wan-online 11 none, so this lamp stays off
WPS white:wps 9 none
2.4G white:wlan-2ghz 6 phy0tpt (Wi-Fi activity)
5G white:wlan-5ghz 7 phy1tpt (Wi-Fi activity)
WAN none (switch hardware) - none (lights on link, in hardware)
LAN1-LAN4 none (switch hardware) - none (lights on link, in hardware)

All five GPIO LEDs are active low. Wi-Fi is disabled by default, so the 2.4G and 5G lamps stay dark until a radio is enabled. The Internet lamp has no default trigger and no board default in OpenWrt. To make it follow the WAN port, add a trigger under System → LED Configuration in LuCI: LED white:wan-online, trigger netdev, device wan, mode link. Tested on one unit (2026 build): the lamp lit while the WAN port had link and went dark when it lost link. link means a physical link on the WAN port, not a working Internet connection. The same from the command line:

uci set system.internet_led=led
uci set system.internet_led.name='Internet'
uci set system.internet_led.sysfs='white:wan-online'
uci set system.internet_led.trigger='netdev'
uci set system.internet_led.dev='wan'
uci set system.internet_led.mode='link'
uci commit system
/etc/init.d/led restart

mt76-phy0 and mt76-phy1 also appear in /sys/class/leds; the Wi-Fi driver registers them, and they are not among the device-tree LEDs above.

Issue #18338 (“Cudy WR3000S - Missing leds”) describes a switch-register workaround for the switch-driven port lamps (on the WR3000S that includes WAN, which is a port of the MT7531 switch), and an earlier forum post describes a LAN LED tweak. Whether either is still needed on current releases, or after a ubootmod conversion (OpenWrt's own bootloader), was not checked.

Top:

Bottom:

Back:

Rear panel, port and button labels:
Rear panel: power, reset above WPS, LAN4 to LAN1, WAN

Underside label (per-unit values redacted: SSID suffix, Wi-Fi password, MAC, serial number and their barcodes):
Underside label, per-unit values redacted

What the label shows (per-unit values are redacted in the photo; the formats are documented here):

  • Power: 12 V DC, 1 A (the WR3000H and WR3000P use 1.5 A)
  • On the unit checked, the default SSIDs were Cudy-XXXX and Cudy-XXXX-5G, where XXXX is the last four hex digits of the label MAC, and the Wi-Fi password was an 8-digit number.
  • MAC: the unit checked uses the prefix D4:0D:AB. The label MAC is the base address, see Network interfaces.
  • Serial number: encodes the build year and week (YYWW); where to read it depends on the serial number format, see Installation.
  • FCC ID 2APRGWR3000SE, IC 28108-WR3000SE on the 2026 unit checked. That FCC ID is one certification covering both the WR3000S and the WR3000E, granted 2025-03-18; in it Cudy declares the two electrically identical, with the same board layout, differing only in the case, the antennas and how the board is mounted (FCC ID 2APRGWR3000SE). Older labels, as in the Bottom photo above, read FCC ID 2APRGWR3000S and IC 28108-WR3000S; the FCC database has no grant under that ID.

→ Warranty

There is one screw located under the label. It must be removed in order to open the case. Unfortunately, this cannot be done without damaging the adhesive sticker.

There are 10 clips around the sides of the router. Carefully release them one by one. Each clip can be pushed from the side, and they are visible through the ventilation grille.

Main PCB:

Serial connection parameters
for Cudy WR3000S v1
115200, 8N1, 3.3V

Serial pins labeled on the bottom of the PCB, labelling is on the top of the PCB under the heatsink. Unless you have a reason to do so, do not connect the VCC/3.3V pin, only ground, TX, and RX are usually needed.

→ port.jtag general information about the JTAG port, JTAG cable, etc.

How to connect to the JTAG Port of this specific device:
Insert photo of PCB with markings for JTAG port

→ bootloader

OpenWrt also builds a cudy_wr3000s-v1-ubootmod profile (model “Cudy WR3000S v1 (OpenWrt U-Boot layout)”, available since 25.12.4, see the alert box under Installation). It replaces Cudy's BL2 and FIP with OpenWrt's own and enlarges the ubi partition from 64 MiB to about 122 MiB (0x7a40000 bytes), which gives more flash space for packages. The 25.12.5 release has four files for it, whose names start with openwrt-25.12.5-mediatek-filogic-cudy_wr3000s-v1 and end in -ubootmod-preloader.bin, -ubootmod-bl31-uboot.fip, -ubootmod-initramfs-recovery.itb and -ubootmod-squashfs-sysupgrade.itb. After the conversion, Cudy's TFTP recovery (see Debricking) is no longer available, so back up BL2, u-boot-env and FIP first (see Flash Layout). OpenWrt's U-Boot has its own TFTP recovery instead: it loads openwrt-mediatek-filogic-cudy_wr3000s-v1-ubootmod-initramfs-recovery.itb (the release file, renamed without its 25.12.5- part) from a TFTP server at 192.168.1.254 and boots it (see the original commit linked under Installation), but it cannot restore the Cudy layout by itself. For a normal install, use squashfs-sysupgrade.bin instead. (Details from the OpenWrt source and the 25.12.5 release files; the conversion was not tested.)

None so far.

F0: 102B 0000 FA: 1040 0000 FA: 1040 0000 [0200] F9: 0000 0000 V0: 0000 0000 [0001] 00: 0000 0000 BP: 2400 0041 [0000] G0: 1190 0000 EC: 0000 0000 [1000] T0: 0000 024F [010F] Jump to BL NOTICE: BL2: v2.7(release):6284467549-dirty NOTICE: BL2: Built : 02:34:12, May 15 2025 NOTICE: WDT: disabled NOTICE: EMI: Using DDR3 settings dump toprgu registers data: 1001c000 | 00000000 0000ffe0 00000000 00000000 1001c010 | 00000fff 00000000 00f00000 00000000 1001c020 | 00000000 00000000 00000000 00000000 1001c030 | 003c0003 003c0003 00000000 00000000 1001c040 | 00000000 00000000 00000000 00000000 1001c050 | 00000000 00000000 00000000 00000000 1001c060 | 00000000 00000000 00000000 00000000 1001c070 | 00000000 00000000 00000000 00000000 1001c080 | 00000000 00000000 00000000 00000000 dump drm registers data: 1001d000 | 00000000 00000000 00000000 00000000 1001d010 | 00000000 00000000 00000000 00000000 1001d020 | 00000000 00000000 00000000 00000000 1001d030 | 00a083f1 000003ff 00100000 00000000 1001d040 | 00000000 00000000 00020303 000000ff 1001d050 | 00000000 00000000 00000000 00000000 1001d060 | 00000002 00000000 00000000 00000000 drm: 500 = 0x8 [DDR Reserve] ddr reserve mode not be enabled yet DDR RESERVE Success 0 [EMI] ComboMCP not ready, using default setting BYTE_swap:0 BYTE_swap:0 Window Sum 508, worse bit 4, min window 60 Window Sum 520, worse bit 15, min window 60 Window Sum 330, worse bit 1, min window 40 Window Sum 318, worse bit 9, min window 38 Window Sum 346, worse bit 0, min window 42 Window Sum 334, worse bit 14, min window 38 Window Sum 350, worse bit 1, min window 42 Window Sum 344, worse bit 8, min window 42 Window Sum 358, worse bit 0, min window 44 Window Sum 354, worse bit 9, min window 42 Window Sum 368, worse bit 1, min window 44 Window Sum 358, worse bit 14, min window 42 Window Sum 378, worse bit 3, min window 46 Window Sum 372, worse bit 9, min window 44 Window Sum 386, worse bit 0, min window 48 Window Sum 380, worse bit 9, min window 44 Window Sum 392, worse bit 8, min window 48 Window Sum 402, worse bit 3, min window 48 Window Sum 396, worse bit 8, min window 48 NOTICE: EMI: Detected DRAM size: 256MB NOTICE: EMI: complex R/W mem test passed NOTICE: CPU: MT7981 (1300MHz) NOTICE: SPI_NAND parses attributes from parameter page. NOTICE: SPI_NAND Detected ID 0xc8 NOTICE: Page size 2048, Block size 131072, size 134217728 NOTICE: Initializing NMBM ... NOTICE: Signature found at block 1023 [0x07fe0000] NOTICE: First info table with writecount 0 found in block 960 NOTICE: Second info table with writecount 0 found in block 963 NOTICE: NMBM has been successfully attached in read-only mode NOTICE: BL2: Booting BL31 NOTICE: BL31: v2.7(release):6284467549-dirty NOTICE: BL31: Built : 02:34:12, May 15 2025 NOTICE: Hello BL31!!! U-Boot 2022.07-rc3 (May 15 2025 - 02:34:12 +0000), Build: jenkins-mtk_mt7981_router_master-50 CPU: MediaTek MT7981 Model: mt7981-rfb DRAM: 256 MiB Core: 45 devices, 20 uclasses, devicetree: embed Initializing NMBM ... spi-nand: spi_nand spi_nand@0: GigaDevice SPI NAND was found. spi-nand: spi_nand spi_nand@0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64 Could not find a valid device for nmbm0 Signature found at block 1023 [0x07fe0000] First info table with writecount 0 found in block 960 Second info table with writecount 0 found in block 963 NMBM has been successfully attached Loading Environment from MTD... *** Warning - bad CRC, using default environment In: serial@11002000 Out: serial@11002000 Err: serial@11002000 Net: Warning: ethernet@15100000 (eth0) using random MAC address - 2a:90:c3:3b:f0:6a eth0: ethernet@15100000 ubi0: attaching mtd7 ubi0: scanning is finished ubi0: attached mtd7 (name "ubi", size 64 MiB) ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048 ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096 ubi0: good PEBs: 512, bad PEBs: 0, corrupted PEBs: 0 ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128 ubi0: max/mean erase counter: 2/0, WL threshold: 4096, image sequence number: 1747276452 ubi0: available PEBs: 0, total reserved PEBs: 512, PEBs reserved for bad PEB handling: 19 Reading from volume 'kernel' to 0x46000000, size 0x0 ... OK ## Loading kernel from FIT Image at 46000000 ... Using 'config-1' configuration Trying 'kernel-1' kernel subimage Description: ARM64 OpenWrt Linux-5.4.246 Type: Kernel Image Compression: lzma compressed Data Start: 0x460000c0 Data Size: 3206321 Bytes = 3.1 MiB Architecture: AArch64 OS: Linux Load Address: 0x48080000 Entry Point: 0x48080000 Hash algo: crc32 Hash value: 15881ca2 Hash algo: sha1 Hash value: b2c90671984ee4cb59045902c275a5763c794522 Verifying Hash Integrity ... crc32+ sha1+ OK ## Loading fdt from FIT Image at 46000000 ... Using 'config-1' configuration Trying 'fdt-1' fdt subimage Description: ARM64 OpenWrt R59 device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x4630eea8 Data Size: 18772 Bytes = 18.3 KiB Architecture: AArch64 Hash algo: crc32 Hash value: 444f88d0 Hash algo: sha1 Hash value: 0348fff54fe1745760745f3fe7edd386e5be2330 Verifying Hash Integrity ... crc32+ sha1+ OK Booting using the fdt blob at 0x4630eea8 Uncompressing Kernel Image Loading Device Tree to 000000004f7f1000, end 000000004f7f8953 ... OK Starting kernel ... [ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034] [ 0.000000] Linux version 5.4.246 (jenkins@release_server) (gcc version 8.4.0 (OpenWrt GCC 8.4.0 2.3.10)) #0 SMP Thu May 15 02:34:12 2025 [ 0.000000] Machine model: MediaTek MT7981 RFB/R59 [ 0.000000] earlycon: uart8250 at MMIO32 0x0000000011002000 (options '') [ 0.000000] printk: bootconsole [uart8250] enabled [ 0.000000] On node 0 totalpages: 64512 [ 0.000000] DMA32 zone: 1024 pages used for memmap [ 0.000000] DMA32 zone: 0 pages reserved [ 0.000000] DMA32 zone: 64512 pages, LIFO batch:15 [ 0.000000] psci: probing for conduit method from DT. [ 0.000000] psci: PSCIv1.1 detected in firmware. [ 0.000000] psci: Using standard PSCI v0.2 function IDs [ 0.000000] psci: MIGRATE_INFO_TYPE not supported. [ 0.000000] psci: SMC Calling Convention v1.0 [ 0.000000] percpu: Embedded 20 pages/cpu s44120 r8192 d29608 u81920 [ 0.000000] pcpu-alloc: s44120 r8192 d29608 u81920 alloc=20*4096 [ 0.000000] pcpu-alloc: [0] 0 [0] 1 [ 0.000000] Detected VIPT I-cache on CPU0 [ 0.000000] CPU features: detected: GIC system register CPU interface [ 0.000000] CPU features: kernel page table isolation disabled by kernel configuration [ 0.000000] Built 1 zonelists, mobility grouping on. Total pages: 63488 [ 0.000000] Kernel command line: console=ttyS0,115200n1 loglevel=8 earlycon=uart8250,mmio32,0x11002000 [ 0.000000] Dentry cache hash table entries: 32768 (order: 6, 262144 bytes, linear) [ 0.000000] Inode-cache hash table entries: 16384 (order: 5, 131072 bytes, linear) [ 0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off [ 0.000000] Memory: 230796K/258048K available (6590K kernel code, 438K rwdata, 1852K rodata, 448K init, 289K bss, 27252K reserved, 0K cma-reserved) [ 0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1 [ 0.000000] rcu: Hierarchical RCU implementation. [ 0.000000] rcu: CONFIG_RCU_FANOUT set to non-default value of 32. [ 0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 25 jiffies. [ 0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0 [ 0.000000] GICv3: GIC: Using split EOI/Deactivate mode [ 0.000000] GICv3: 640 SPIs implemented [ 0.000000] GICv3: 0 Extended SPIs implemented [ 0.000000] GICv3: Distributor has no Range Selector support [ 0.000000] GICv3: 16 PPIs implemented [ 0.000000] GICv3: no VLPI support, no direct LPI support [ 0.000000] GICv3: CPU0: found redistributor 0 region 0:0x000000000c080000 [ 0.000000] arch_timer: cp15 timer(s) running at 13.00MHz (phys). [ 0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x2ff89eacb, max_idle_ns: 440795202429 ns [ 0.000003] sched_clock: 56 bits at 13MHz, resolution 76ns, wraps every 4398046511101ns [ 0.008192] Calibrating delay loop (skipped), value calculated using timer frequency.. 26.00 BogoMIPS (lpj=52000) [ 0.018512] pid_max: default: 32768 minimum: 301 [ 0.023233] Mount-cache hash table entries: 512 (order: 0, 4096 bytes, linear) [ 0.030494] Mountpoint-cache hash table entries: 512 (order: 0, 4096 bytes, linear) [ 0.039061] ASID allocator initialised with 65536 entries [ 0.044564] rcu: Hierarchical SRCU implementation. [ 0.049686] smp: Bringing up secondary CPUs ... [ 0.054559] Detected VIPT I-cache on CPU1 [ 0.054578] GICv3: CPU1: found redistributor 1 region 0:0x000000000c0a0000 [ 0.054599] CPU1: Booted secondary processor 0x0000000001 [0x410fd034] [ 0.054661] smp: Brought up 1 node, 2 CPUs [ 0.076274] SMP: Total of 2 processors activated. [ 0.081000] CPU features: detected: 32-bit EL0 Support [ 0.086161] CPU features: detected: CRC32 instructions [ 0.091428] CPU: All CPU(s) started at EL2 [ 0.095549] alternatives: patching kernel code [ 0.102349] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns [ 0.112159] futex hash table entries: 512 (order: 3, 32768 bytes, linear) [ 0.119061] pinctrl core: initialized pinctrl subsystem [ 0.124954] NET: Registered protocol family 16 [ 0.129635] DMA: preallocated 256 KiB pool for atomic allocations [ 0.151428] SCSI subsystem initialized [ 0.155366] libata version 3.00 loaded. [ 0.159464] usbcore: registered new interface driver usbfs [ 0.165042] usbcore: registered new interface driver hub [ 0.170418] usbcore: registered new device driver usb [ 0.176387] rbus 18000000.wbsys: PCI host bridge to bus 0000:00 [ 0.182353] pci_bus 0000:00: root bus resource [mem 0x18000000-0x18ffffff] [ 0.189265] pci_bus 0000:00: root bus resource [bus 00-ff] [ 0.194777] pci_bus 0000:00: scanning bus [ 0.198816] pci 0000:00:00.0: [14c3:7981] type 00 class 0x000280 [ 0.204861] pci 0000:00:00.0: reg 0x10: [mem 0x18000000-0x1800000f 64bit] [ 0.211685] pci 0000:00:00.0: reg 0x18: [mem 0x00000000-0x0000000f] [ 0.217984] pci 0000:00:00.0: reg 0x1c: [mem 0x00000000-0x0000000f] [ 0.224284] pci 0000:00:00.0: reg 0x20: [mem 0x00000000-0x0000000f] [ 0.230582] pci 0000:00:00.0: reg 0x24: [mem 0x00000000-0x0000000f] [ 0.237721] pci_bus 0000:00: fixups for bus [ 0.241933] pci_bus 0000:00: bus scan returning with max=00 [ 0.248297] clocksource: Switched to clocksource arch_sys_counter [ 0.255060] thermal_sys: Registered thermal governor 'fair_share' [ 0.255063] thermal_sys: Registered thermal governor 'bang_bang' [ 0.261207] thermal_sys: Registered thermal governor 'step_wise' [ 0.267244] thermal_sys: Registered thermal governor 'user_space' [ 0.273279] thermal_sys: Registered thermal governor 'power_allocator' [ 0.279641] NET: Registered protocol family 2 [ 0.290672] IP idents hash table entries: 4096 (order: 3, 32768 bytes, linear) [ 0.298391] tcp_listen_portaddr_hash hash table entries: 256 (order: 0, 4096 bytes, linear) [ 0.306883] TCP established hash table entries: 2048 (order: 2, 16384 bytes, linear) [ 0.314684] TCP bind hash table entries: 2048 (order: 3, 32768 bytes, linear) [ 0.321877] TCP: Hash tables configured (established 2048 bind 2048) [ 0.328327] UDP hash table entries: 256 (order: 1, 8192 bytes, linear) [ 0.334898] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes, linear) [ 0.341995] NET: Registered protocol family 1 [ 0.346396] PCI: CLS 0 bytes, default 64 [ 0.351138] workingset: timestamp_bits=46 max_order=16 bucket_order=0 [ 0.360505] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 0.366388] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc. [ 0.389243] phy phy-usb-phy@11e10000.1: type_sw - reg 0x218, index 0 [ 0.406213] Serial: 8250/16550 driver, 3 ports, IRQ sharing disabled [ 0.413304] printk: console [ttyS0] disabled [ 0.437716] 11002000.serial: ttyS0 at MMIO 0x11002000 (irq = 12, base_baud = 2500000) is a ST16650V2 [ 0.446926] printk: console [ttyS0] enabled [ 0.446926] printk: console [ttyS0] enabled [ 0.455284] printk: bootconsole [uart8250] disabled [ 0.455284] printk: bootconsole [uart8250] disabled [ 0.465575] cacheinfo: Unable to detect cache hierarchy for CPU 0 [ 0.473973] loop: module loaded [ 0.477973] mt7981-pinctrl 11d00000.pinctrl: pin_config_set op failed for pin 19 [ 0.485375] mtk-spi 1100a000.spi: Error applying setting, reverse things back [ 0.492978] spi-nand spi0.0: Failed to calibrate SPI-NAND (err = -22) [ 0.499521] spi-nand spi0.0: GigaDevice SPI NAND was found. Flash Model: F50L1G41LB, ID: C801 [ 0.508063] spi-nand spi0.0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64 [ 0.518519] usbcore: registered new interface driver r8152 [ 0.524072] usbcore: registered new interface driver ax88179_178a [ 0.530287] xhci-mtk 11200000.xhci: 11200000.xhci supply vbus not found, using dummy regulator [ 0.538924] xhci-mtk 11200000.xhci: 11200000.xhci supply vusb33 not found, using dummy regulator [ 0.547813] phy phy-usb-phy@11e10000.0: try to get sw efuse [ 0.553387] phy phy-usb-phy@11e10000.1: try to get sw efuse [ 0.558951] phy phy-usb-phy@11e10000.1: try to get sw efuse+ [ 0.564624] phy phy-usb-phy@11e10000.1: u3 efuse - intr 2a, rx_imp 11, tx_imp 10 [ 0.572049] phy_efuse_set set efuse, tx_imp 10, rx_imp 11 intr 2a [ 0.578231] xhci-mtk 11200000.xhci: xHCI Host Controller [ 0.583617] xhci-mtk 11200000.xhci: new USB bus registered, assigned bus number 1 [ 0.594118] xhci-mtk 11200000.xhci: hcc params 0x01403f99 hci version 0x110 quirks 0x0000000000210010 [ 0.603362] xhci-mtk 11200000.xhci: irq 89, io mem 0x11200000 [ 0.609187] xhci-mtk 11200000.xhci: xHCI Host Controller [ 0.614498] xhci-mtk 11200000.xhci: new USB bus registered, assigned bus number 2 [ 0.621976] xhci-mtk 11200000.xhci: Host supports USB 3.2 Enhanced SuperSpeed [ 0.629464] hub 1-0:1.0: USB hub found [ 0.633261] hub 1-0:1.0: 1 port detected [ 0.637467] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM. [ 0.645893] hub 2-0:1.0: USB hub found [ 0.649671] hub 2-0:1.0: 1 port detected [ 0.654046] usbcore: registered new interface driver uas [ 0.659434] usbcore: registered new interface driver usb-storage [ 0.665547] i2c /dev entries driver [ 0.669929] mtk-wdt 1001c000.watchdog: Watchdog enabled (timeout=31 sec, nowayout=0) [ 0.677925] device-mapper: ioctl: 4.41.0-ioctl (2019-09-16) initialised: dm-devel@redhat.com [ 0.688240] NET: Registered protocol family 10 [ 0.693268] Segment Routing with IPv6 [ 0.696990] NET: Registered protocol family 17 [ 0.701475] Bridge firewalling registered [ 0.705479] 8021q: 802.1Q VLAN Support v1.8 [ 0.718464] nmbm nmbm_spim_nand: Signature found at block 1023 [0x07fe0000] [ 0.726306] nmbm nmbm_spim_nand: First info table with writecount 0 found in block 960 [ 0.736794] nmbm nmbm_spim_nand: Second info table with writecount 0 found in block 963 [ 0.744815] nmbm nmbm_spim_nand: NMBM has been successfully attached [ 0.751431] 6 fixed-partitions partitions found on MTD device nmbm_spim_nand [ 0.758501] Creating 6 MTD partitions on "nmbm_spim_nand": [ 0.763983] 0x000000000000-0x000000100000 : "BL2" [ 0.769215] 0x000000100000-0x000000180000 : "u-boot-env" [ 0.775014] 0x000000180000-0x000000380000 : "Factory" [ 0.780586] 0x000000380000-0x0000003c0000 : "bdinfo" [ 0.786038] 0x0000003c0000-0x0000005c0000 : "FIP" [ 0.791230] 0x0000005c0000-0x0000045c0000 : "ubi" [ 0.797024] [mtk_hw_init] reset_lock:0, force:0 [ 0.801584] [mtk_hw_init] execute fe cold reset [ 0.817120] mtk_soc_eth 15100000.ethernet: MDC is running on 2500000 Hz [ 0.844592] mtk_soc_eth 15100000.ethernet eth0: mediatek frame engine at 0xffffffc011880000, irq 79 [ 0.854282] mtk_soc_eth 15100000.ethernet eth1: mediatek frame engine at 0xffffffc011880000, irq 79 [ 0.863340] (unnamed net_device) (dummy): netif_napi_add() called with weight 256 [ 1.440334] mt753x gsw@0: LAN/WAN VLAN setting=wllll [ 1.445569] mt753x gsw@0: Switch is MediaTek MT7531AE rev 1 [ 1.455330] mt753x gsw@0: HWSTRAP=0xff XTAL=25MHz [ 5.101432] mt753x gsw@0: >>>>>>>>>>>>>>>>>>>>>>>>>>>>> START CALIBRATION: [ 5.109412] mt753x gsw@0: -------- gephy-calbration (port:0) -------- [ 5.124614] CALDLY = 40 [ 5.176730] 0x1e-e0 = 2828 [ 5.181128] 0x1f-115 = 5 [ 5.183648] GE Rext AnaCal Done! (8)(0x28) [ 5.243174] GE R50 AnaCal Done! (9) (0x34)(0xb4) [ 5.293549] GE R50 AnaCal Done! (8) (0x35)(0xb5) [ 5.339370] GE R50 AnaCal Done! (7) (0x37)(0xb7) [ 5.394302] GE R50 AnaCal Done! (9) (0x34)(0xb4) [ 5.402065] GE 1e_174(0xb4b5), 1e_175(0xb7b4) [ 5.466662] GE Tx offset AnaCal Done! (pair-0)(8)(0x27) 0x1e_172=0x2720 [ 5.518859] GE Tx offset AnaCal Done! (pair-1)(8)(0x27) 0x1e_172=0x2727 [ 5.561948] GE Tx offset AnaCal Done! (pair-2)(6)(0x25) 0x1e_173=0x2520 [ 5.591370] GE Tx offset AnaCal Done! (pair-3)(3)(0x22) 0x1e_173=0x2522 [ 5.653514] GE Tx amp AnaCal Done! (pair-0)(1e_12 = 0x5c17) [ 5.690287] GE Tx amp AnaCal Done! (pair-1)(1e_17 = 0x1919) [ 5.724847] GE Tx amp AnaCal Done! (pair-2)(1e_19 = 0x1820) [ 5.776392] GE Tx amp AnaCal Done! (pair-3)(1e_21 = 0x1c24) [ 5.823102] PORT 0 RX_DC_OFFSET [ 5.835768] before pairA output = d [ 5.841036] after pairA output = 1 [ 5.846132] before pairB output = 1d [ 5.851482] after pairB output = fe [ 5.856664] before pairC output = e [ 5.861922] after pairC output = fe [ 5.867105] before pairD output = 1e [ 5.872455] after pairD output = 0 [ 5.876100] mt753x gsw@0: -------- gephy-calbration (port:1) -------- [ 5.891302] CALDLY = 40 [ 5.948869] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 6.003883] GE R50 AnaCal Done! (9) (0x34)(0xb4) [ 6.054262] GE R50 AnaCal Done! (8) (0x35)(0xb5) [ 6.109193] GE R50 AnaCal Done! (9) (0x34)(0xb4) [ 6.116957] GE 1e_174(0xb2b4), 1e_175(0xb5b4) [ 6.158778] GE Tx offset AnaCal Done! (pair-0)(3)(0x22) 0x1e_172=0x2220 [ 6.201865] GE Tx offset AnaCal Done! (pair-1)(6)(0x25) 0x1e_172=0x2225 [ 6.226733] GE Tx offset AnaCal Done! (pair-2)(2)(0x21) 0x1e_173=0x2120 [ 6.251600] GE Tx offset AnaCal Done! (pair-3)(2)(0x21) 0x1e_173=0x2121 [ 6.319402] GE Tx amp AnaCal Done! (pair-0)(1e_12 = 0x6419) [ 6.356178] GE Tx amp AnaCal Done! (pair-1)(1e_17 = 0x1a1a) [ 6.396402] GE Tx amp AnaCal Done! (pair-2)(1e_19 = 0x141c) [ 6.453615] GE Tx amp AnaCal Done! (pair-3)(1e_21 = 0x1d25) [ 6.500323] PORT 1 RX_DC_OFFSET [ 6.512986] before pairA output = 1c [ 6.518335] after pairA output = ff [ 6.523517] before pairB output = e [ 6.528779] after pairB output = 1 [ 6.533869] before pairC output = e [ 6.539132] after pairC output = ff [ 6.544316] before pairD output = e [ 6.549574] after pairD output = ff [ 6.553310] mt753x gsw@0: -------- gephy-calbration (port:2) -------- [ 6.568515] CALDLY = 40 [ 6.626078] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 6.685654] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 6.745225] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 6.800238] GE R50 AnaCal Done! (9) (0x34)(0xb4) [ 6.808002] GE 1e_174(0xb2b2), 1e_175(0xb2b4) [ 6.872604] GE Tx offset AnaCal Done! (pair-0)(8)(0x27) 0x1e_172=0x2720 [ 6.906580] GE Tx offset AnaCal Done! (pair-1)(4)(0x23) 0x1e_172=0x2723 [ 6.931449] GE Tx offset AnaCal Done! (pair-2)(2)(0x21) 0x1e_173=0x2120 [ 6.951762] GE Tx offset AnaCal Done! (pair-3)(1)(0x1) 0x1e_173=0x2101 [ 7.030801] GE Tx amp AnaCal Done! (pair-0)(1e_12 = 0x701c) [ 7.095891] GE Tx amp AnaCal Done! (pair-1)(1e_17 = 0x1e1e) [ 7.153104] GE Tx amp AnaCal Done! (pair-2)(1e_19 = 0x1e26) [ 7.232960] GE Tx amp AnaCal Done! (pair-3)(1e_21 = 0x2129) [ 7.279670] PORT 2 RX_DC_OFFSET [ 7.292341] before pairA output = f [ 7.297602] after pairA output = ff [ 7.302785] before pairB output = d [ 7.308047] after pairB output = 0 [ 7.313142] before pairC output = 1d [ 7.318490] after pairC output = 0 [ 7.323585] before pairD output = 1e [ 7.328934] after pairD output = ff [ 7.332671] mt753x gsw@0: -------- gephy-calbration (port:3) -------- [ 7.347873] CALDLY = 40 [ 7.409994] GE R50 AnaCal Done! (11) (0x31)(0xb1) [ 7.469568] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 7.529140] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 7.588713] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 7.596564] GE 1e_174(0xb1b2), 1e_175(0xb2b2) [ 7.647497] GE Tx offset AnaCal Done! (pair-0)(5)(0x24) 0x1e_172=0x2420 [ 7.681473] GE Tx offset AnaCal Done! (pair-1)(4)(0x23) 0x1e_172=0x2423 [ 7.724561] GE Tx offset AnaCal Done! (pair-2)(6)(0x25) 0x1e_173=0x2520 [ 7.758537] GE Tx offset AnaCal Done! (pair-3)(4)(0x23) 0x1e_173=0x2523 [ 7.820682] GE Tx amp AnaCal Done! (pair-0)(1e_12 = 0x5c17) [ 7.880102] GE Tx amp AnaCal Done! (pair-1)(1e_17 = 0x1e1e) [ 7.948639] GE Tx amp AnaCal Done! (pair-2)(1e_19 = 0x2028) [ 7.988861] GE Tx amp AnaCal Done! (pair-3)(1e_21 = 0x1b23) [ 8.035567] PORT 3 RX_DC_OFFSET [ 8.048234] before pairA output = e [ 8.053497] after pairA output = 0 [ 8.058593] before pairB output = 1e [ 8.063941] after pairB output = fe [ 8.069124] before pairC output = e [ 8.074387] after pairC output = 0 [ 8.079481] before pairD output = 1c [ 8.084831] after pairD output = fe [ 8.088567] mt753x gsw@0: -------- gephy-calbration (port:4) -------- [ 8.103768] CALDLY = 40 [ 8.161337] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 8.220911] GE R50 AnaCal Done! (10) (0x32)(0xb2) [ 8.275931] GE R50 AnaCal Done! (9) (0x34)(0xb4) [ 8.339968] GE R50 AnaCal Done! (11) (0x31)(0xb1) [ 8.347820] GE 1e_174(0xb2b2), 1e_175(0xb4b1) [ 8.385088] GE Tx offset AnaCal Done! (pair-0)(2)(0x21) 0x1e_172=0x2120 [ 8.423622] GE Tx offset AnaCal Done! (pair-1)(5)(0x24) 0x1e_172=0x2124 [ 8.462152] GE Tx offset AnaCal Done! (pair-2)(5)(0x24) 0x1e_173=0x2420 [ 8.509793] GE Tx offset AnaCal Done! (pair-3)(7)(0x26) 0x1e_173=0x2426 [ 8.571932] GE Tx amp AnaCal Done! (pair-0)(1e_12 = 0x6419) [ 8.608711] GE Tx amp AnaCal Done! (pair-1)(1e_17 = 0x1515) [ 8.643270] GE Tx amp AnaCal Done! (pair-2)(1e_19 = 0x1a22) [ 8.700477] GE Tx amp AnaCal Done! (pair-3)(1e_21 = 0x121a) [ 8.747187] PORT 4 RX_DC_OFFSET [ 8.759855] before pairA output = 1e [ 8.765205] after pairA output = fe [ 8.770388] before pairB output = e [ 8.775650] after pairB output = 0 [ 8.780745] before pairC output = e [ 8.786003] after pairC output = 0 [ 8.791099] before pairD output = 1d [ 8.796447] after pairD output = 0 [ 8.804879] UBI: auto-attach mtd6 [ 8.808193] ubi0: attaching mtd6 [ 9.016427] ubi0: scanning is finished [ 9.025278] ubi0: attached mtd6 (name "ubi", size 64 MiB) [ 9.030681] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes [ 9.037551] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048 [ 9.044329] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096 [ 9.051278] ubi0: good PEBs: 512, bad PEBs: 0, corrupted PEBs: 0 [ 9.057275] ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128 [ 9.064486] ubi0: max/mean erase counter: 2/0, WL threshold: 4096, image sequence number: 1747276452 [ 9.073604] ubi0: available PEBs: 0, total reserved PEBs: 512, PEBs reserved for bad PEB handling: 19 [ 9.082819] ubi0: background thread "ubi_bgt0d" started, PID 681 [ 9.089378] block ubiblock0_1: created from ubi0:1(rootfs) [ 9.094884] ubiblock: device ubiblock0_1 (rootfs) set to be root filesystem [ 9.101839] hctosys: unable to open rtc device (rtc0) [ 9.110638] VFS: Mounted root (squashfs filesystem) readonly on device 253:0. [ 9.117986] Freeing unused kernel memory: 448K [ 9.132341] Run /sbin/init as init process [ 9.358963] init: Console is alive [ 9.362497] init: - watchdog - [ 9.812710] kmodloader: loading kernel modules from /etc/modules-boot.d/* [ 9.836828] conninfra@(mtk_conninfra_drv_init:644) Before platform_driver_register [ 9.844509] Get Index(0-TOP_MISC_BASE) phy_addr(0x11d10000) vir_addr=(0xffffffc010a8f000) size=(0x1000) [ 9.853897] Get Index(1-TOPRGU_BASE) phy_addr(0x1001c000) vir_addr=(0xffffffc010a91000) size=(0x1000) [ 9.863104] Get Index(2-GPIO_BASE) phy_addr(0x11d00000) vir_addr=(0xffffffc010a9d000) size=(0x1000) [ 9.872138] Get Index(3-IOCFG_TR_BASE) phy_addr(0x11f00000) vir_addr=(0xffffffc010a9f000) size=(0x1000) [ 9.881519] Get Index(4-IOCFG_TL_BASE) phy_addr(0x11f10000) vir_addr=(0xffffffc010aa1000) size=(0x1000) [ 9.890902] Get Index(5-INFRACFG_AO_BASE) phy_addr(0x10003000) vir_addr=(0xffffffc010aa3000) size=(0x1000) [ 9.900545] Get Index(6-CONN_INFRA_CFG_BASE) phy_addr(0x18001000) vir_addr=(0xffffffc010aa5000) size=(0x1000) [ 9.910446] Get Index(7-CONN_INFRA_SYSRAM_BASE) phy_addr(0x18050000) vir_addr=(0xffffffc010aad000) size=(0x1000) [ 9.920607] Get Index(8-CONN_INFRA_CLKGEN_ON_TOP_BASE) phy_addr(0x18009000) vir_addr=(0xffffffc010ab5000) size=(0x1000) [ 9.931375] Get Index(9-CONN_HOST_CSR_TOP_BASE) phy_addr(0x18060000) vir_addr=(0xffffffc010afe000) size=(0x1000) [ 9.941536] Get Index(10-CONN_INFRA_BUS_CR_BASE) phy_addr(0x1800e000) vir_addr=(0xffffffc010b00000) size=(0x1000) [ 9.951784] Get Index(11-CONN_INFRA_RGU_BASE) phy_addr(0x18000000) vir_addr=(0xffffffc010b02000) size=(0x1000) [ 9.961771] Get Index(12-CONN_WT_SLP_CTL_REG_BASE) phy_addr(0x18005000) vir_addr=(0xffffffc010b04000) size=(0x1000) [ 9.972193] Get Index(13-INST2_CONN_WT_SLP_CTL_REG_BASE) phy_addr(0x18085000) vir_addr=(0xffffffc010b06000) size=(0x1000) [ 9.983135] Get Index(14-CONN_RF_SPI_MST_REG_BASE) phy_addr(0x18004000) vir_addr=(0xffffffc010b08000) size=(0x1000) [ 9.993559] Get Index(15-INST2_CONN_RF_SPI_MST_REG_BASE) phy_addr(0x18084000) vir_addr=(0xffffffc010b0a000) size=(0x1000) [ 10.004503] Get Index(16-CONN_SEMAPHORE_BASE) phy_addr(0x18070000) vir_addr=(0xffffffc010b20000) size=(0x10000) [ 10.014577] Get Index(17-CONN_AFE_CTL_BASE) phy_addr(0x18003000) vir_addr=(0xffffffc010b0c000) size=(0x1000) [ 10.024391] Get Index(18-CONN_AFE_CTL_2ND_BASE) phy_addr(0x18083000) vir_addr=(0xffffffc010b0e000) size=(0x1000) [ 10.034553] Get Index(19-WF_TOP_SLPPROT_ON_BASE) phy_addr(0x184c0000) vir_addr=(0xffffffc010b40000) size=(0x10000) [ 10.044888] Get Index(20-WF_TOP_CFG_BASE) phy_addr(0x184b0000) vir_addr=(0xffffffc010b10000) size=(0x1000) [ 10.054529] Get Index(21-WF_MCU_CONFIG_LS_BASE) phy_addr(0x184f0000) vir_addr=(0xffffffc010b12000) size=(0x1000) [ 10.064690] Get Index(22-WF_MCU_BUS_CR_BASE) phy_addr(0x18400000) vir_addr=(0xffffffc010b14000) size=(0x1000) [ 10.074592] Get Index(23-WF_MCUSYS_INFRA_BUS_FULL_U_DEBUG_CTRL_AO_BASE) phy_addr(0x18500000) vir_addr=(0xffffffc010b1d000) size=(0x1000) [ 10.086836] Get Index(24-WF_TOP_CFG_ON_BASE) phy_addr(0x184c0000) vir_addr=(0xffffffc010b60000) size=(0x10000) [ 10.096825] conninfra@(consys_plt_hw_init:162) adie_cfg_type = 1, one_adie_dbdc = 1 [ 10.104475] [emi_mng_init] gConEmiPhyBase = [0x47c80000] size = [0x100000] fw size = [0x100000] ops=[(____ptrval____)] [ 10.115257] conninfra@(mtk_conninfra_drv_init:650) After platform_driver_register [ 10.123109] ConnInfra Dev: init (0) [ 10.128041] conninfra@(_consys_polling_chipid_int:306) Read CONNSYS HW IP version successfully! (0x02090000) [ 10.137881] conninfra@(connsys_d_die_cfg:377) D-die efuse: 0x00000000 [ 10.145352] conninfra@(_connsys_a_die_cfg_7976:932) adie_idx[0], A-die CHIP ID = 0x7976, HW Version = 0x8a10 [ 10.156171] conninfra@(consys_spi_write_nolock:513) addr=0x0a00, val=0xffffffff [ 10.164473] conninfra@(consys_spi_write_nolock:513) addr=0x04ac, val=0x0000001c [ 10.172808] conninfra@(consys_spi_write_nolock:513) addr=0x0144, val=0x00000002 [ 10.182117] conninfra@(consys_spi_write_nolock:513) addr=0x0148, val=0x00000000 [ 10.191425] conninfra@(consys_spi_write_nolock:513) addr=0x0148, val=0x43a60000 [ 10.204763] conninfra@(connsys_a_die_efuse_read_nolock:749) efuse = [0x00000001, 0x00c40000, 0x008700b3, 0x00000000] [ 10.216274] conninfra@(consys_spi_write_nolock:513) addr=0x0144, val=0x00000002 [ 10.225582] conninfra@(consys_spi_write_nolock:513) addr=0x0148, val=0x23a6003a [ 10.234891] conninfra@(consys_spi_write_nolock:513) addr=0x0148, val=0x63a7003a [ 10.248229] conninfra@(connsys_a_die_efuse_read_nolock:749) efuse = [0x00000001, 0x00c40000, 0x008700b3, 0x00000000] [ 10.259739] conninfra@(consys_spi_write_nolock:513) addr=0x0144, val=0x00000002 [ 10.269048] conninfra@(consys_spi_write_nolock:513) addr=0x0148, val=0x23a7003a [ 10.278357] conninfra@(consys_spi_write_nolock:513) addr=0x0148, val=0x63ac003a [ 10.291695] conninfra@(connsys_a_die_efuse_read_nolock:749) efuse = [0x00000001, 0x00c40000, 0x008700b3, 0x00000000] [ 10.303206] conninfra@(consys_spi_write_nolock:513) addr=0x0038, val=0x4a563b00 [ 10.311507] conninfra@(consys_spi_write_nolock:513) addr=0x065c, val=0x1d59080f [ 10.319808] conninfra@(consys_spi_write_nolock:513) addr=0x0664, val=0x34c00fe0 [ 10.328111] conninfra@(consys_spi_write_nolock:513) addr=0x0070, val=0x88888005 [ 10.337370] conninfra@(consys_spi_write_nolock:513) addr=0x0070, val=0x00000005 [ 10.345605] conninfra@(_consys_polling_chipid_int:306) Read CONNSYS HW IP version successfully! (0x02090000) [ 10.355416] conninfra@(_consys_hw_conninfra_wakeup:470) conninfra_wakeup refcnt=[0]->[1] wakeup!! [ 10.364278] conninfra@(_consys_hw_conninfra_sleep:490) conninfra_sleep refcnt=[1]->[0] sleep!! [ 10.372876] conninfra@(opfunc_power_on_internal:241) [Conninfra Pwr On] BT=[0] FM=[0] GPS=[0] WF=[0] CONNINFRA=[1] [ 10.387060] mediatek_soc_hnat 15100000.hnat: wan = eth1 [ 10.392322] mediatek_soc_hnat 15100000.hnat: lan = eth0 [ 10.397549] mediatek_soc_hnat 15100000.hnat: lan2 = eth2 [ 10.402853] mediatek_soc_hnat 15100000.hnat: ppd = eth0 [ 10.408075] mediatek_soc_hnat 15100000.hnat: gmac num = 2 [ 10.413467] mediatek_soc_hnat 15100000.hnat: ppe num = 1 [ 10.419194] mediatek_soc_hnat 15100000.hnat: PPE0 entry number = 8192 [ 10.435961] mediatek_soc_hnat 15100000.hnat: PPE0 hwnat start [ 10.441754] hnat roaming work enable [ 10.448264] warp_module_init(): module init and register callback for warp [ 10.455171] create warp_ctrl ok!!! [ 10.458609] wed_get_slot_map(): assign slot_id:0 for entry: 0! [ 10.464448] wed_get_slot_map(): assign slot_id:1 for entry: 1! [ 10.470758] kmodloader: done loading kernel modules from /etc/modules-boot.d/* [ 10.483080] init: - preinit - [ 10.636308] random: crng init done [ 10.798444] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode [ 10.806883] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 10.876774] UBIFS (ubi0:2): Mounting in unauthenticated mode [ 10.882500] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" started, PID 747 [ 10.907570] UBIFS (ubi0:2): recovery needed [ 11.002889] UBIFS (ubi0:2): recovery completed [ 11.007418] UBIFS (ubi0:2): UBIFS: mounted UBI device 0, volume 2, name "rootfs_data" [ 11.015247] UBIFS (ubi0:2): LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes [ 11.025161] UBIFS (ubi0:2): FS size: 44314624 bytes (42 MiB, 349 LEBs), journal size 2158592 bytes (2 MiB, 17 LEBs) [ 11.035586] UBIFS (ubi0:2): reserved for root: 2093089 bytes (2044 KiB) [ 11.042209] UBIFS (ubi0:2): media format: w5/r0 (latest is w5/r0), UUID 0F0FCE3D-0E47-4C9D-A237-6D0973F9218E, small LPT model [ 11.058279] mount_root: switching to ubifs overlay [ 11.068980] urandom-seed: Seeding with /etc/urandom.seed [ 11.531030] procd: - early - [ 11.533975] procd: - watchdog - [ 12.081781] procd: - watchdog - [ 12.086839] procd: - ubus - [ 12.108623] mt753x gsw@0: Port 2 Link is Up - 1Gbps/Full [ 12.114043] gmac: port2 linkup [ 12.141800] procd: - init - [ 12.522233] urngd: v1.0.2 started. [ 12.533818] kmodloader: loading kernel modules from /etc/modules.d/* [ 12.557577] NET: Registered protocol family 15 [ 12.563297] Initializing XFRM netlink socket [ 12.570001] tun: Universal TUN/TAP device driver, 1.6 [ 12.589474] l2tp_core: L2TP core driver, V2.0 [ 12.595420] l2tp_netlink: L2TP netlink interface [ 12.601159] nat46: module (version 362640b41ae52b732d9e9729e61ac555492442a3) loaded. [ 12.610300] gre: GRE over IPv4 demultiplexor driver [ 12.616876] ip_gre: GRE over IPv4 tunneling driver [ 12.647028] ipv6_pass_through: module license 'Proprietary' taints kernel. [ 12.653958] Disabling lock debugging due to kernel taint [ 13.777547] conninfra@(conninfra_pwr_on:120) [conninfra_pwr_on] drv=[3] [ 13.785115] conninfra@(_consys_polling_chipid_int:306) Read CONNSYS HW IP version successfully! (0x02090000) [ 13.802970] Adie Type: 0x7976 [ 13.802971] SKU Type: 3000 [ 13.806889] conninfra@(opfunc_power_on_internal:241) [Conninfra Pwr On] BT=[0] FM=[0] GPS=[0] WF=[1] CONNINFRA=[1] [ 13.820981] WiFi@C12L1,get_dbg_setting_by_profile() 4480: debug level setting=INDEX0_debug_level not found!! [ 13.830836] WiFi@C12L1,get_dbg_setting_by_profile() 4503: debug option setting=INDEX0_debug_option not found!! [ 13.840882] mt_rbus 0000:00:00.0: runtime IRQ mapping not provided by arch [ 13.854254] mt7981_init()--> [ 13.857151] Use the default iPAiLNA bin image! [ 13.861660] <--mt7981_init() [ 13.864676] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX1 [ 13.871994] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX2 [ 13.879310] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX3 [ 13.886633] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX4 [ 13.893955] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX5 [ 13.901272] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX6 [ 13.908589] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX7 [ 13.915905] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX8 [ 13.923221] WiFi@C12L1,match_index_by_chipname() 758: not find chip name INDEX9 [ 13.930762] mt7981 nlwifi attach OK [ 13.942460] mtk_warp_proxy: module uses symbols from proprietary module mt_wifi, inheriting taint. [ 13.973539] wireguard: WireGuard 1.0.20210219 loaded. See www.wireguard.com for information. [ 13.982028] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved. [ 14.005243] xt_time: kernel timezone is -0000 [ 14.040484] PPP generic driver version 2.4.2 [ 14.045664] PPP MPPE Compression module registered [ 14.051566] NET: Registered protocol family 24 [ 14.057246] PPTP driver version 0.8.5 [ 14.072800] l2tp_ppp: PPPoL2TP kernel driver, V2.0 [ 14.081921] kmodloader: done loading kernel modules from /etc/modules.d/* [ 14.165764] client_get_axi_slot_id(): wrong BUS_TYPE [ 14.170865] warp_cap_support(): chip_id=7981 is in WHNAT support list [ 14.177299] warp_entry_acquire(): bus slot:0, hook to WARP, entry id=0, entry: 00000000ad594b70 [ 14.185983] client_hif_specific_get(): hw->base_phy_addr 0x18000000!! [ 14.192411] client_chip_specific_get(): 0x7981 chip id 0x7981!! [ 14.198412] warp_entry_get_by_pdev(): return entry[0] [ 14.203629] warp_msg_register():warp,pid,1647,id,0,wed_idx,0 [ 14.209293] warp_dev0 15010000.wed: Using 32bit DMA for streaming map [ 14.215732] warp_dev0 15010000.wed: Using 32bit DMA for coherent map [ 14.222102] wed_init(0): res_start = 0x15010000, size = 1000, irq=7,base_addr=0xffffffc010b3d000 [ 14.231237] wed_ring_init(): wed tx ring init result = 0 [ 14.236706] wed_ring_init(): wed rx ring init result = 0 [ 14.248445] create wed ok!!! [ 14.251343] wdma_init(): wdma(0) base_addr=0xffffffc010be6800, base_phy_addr=0x15104800 [ 14.260005] warp_woif_bus_init_hw(): bus:00000000f8077308, txring: 20, pa: 0x000000004687a000, 0x000000004687a000, 24, 28, 3c [ 14.271320] warp_woif_bus_init_hw(): bus:00000000f8077308, rxring: 50, pa: 0x00000000468bc000, 0x00000000468bc000, 54, 58, 6c [ 14.282642] get_region_info(): wed_idx = 0, base_addr = 0x00000000c3667faf, size = 0x40000, res.start = 0x47d80000, shared:0 [ 14.293857] get_region_info(): wed_idx = 0, base_addr = 0x000000002df9531c, size = 0x8000, res.start = 0x151e0000, shared:0 [ 14.305010] get_region_info(): wed_idx = 0, base_addr = 0x00000000cee2e9e3, size = 0x240000, res.start = 0x47dc0000, shared:1 [ 14.316311] get_region_info(): wed_idx = 0, base_addr = 0x0000000043a2c0cb, size = 0x1000, res.start = 0x15194000, shared:0 [ 14.327425] warp_fwdl_mcu_mode(): mcu mode, need fwdl [ 14.371760] ########## WO Firmware ########## [ 14.376154] Chip ID: 0x0000 [ 14.378941] ECO version:0 [ 14.381555] Version: DEV_000000 [ 14.384688] Build date: 20231228201845 [ 14.388428] Total region:3 [ 14.391122] ################################# [ 14.395470] Parsing tailer region 0 [ 14.398955] Target address: 0x151e0000 [ 14.402782] Download size: 22112 [ 14.406116] Parsing tailer region 1 [ 14.409596] Target address: 0x47d80000 [ 14.413421] Download size: 86960 [ 14.416817] Parsing tailer region 2 [ 14.420298] Target address: 0x47dc0000 [ 14.424118] Download size: 2345040 [ 14.429520] warp_fwdl_ready_check_mcu_mode(): waiting for wocpu [ 14.450234] warp_fwdl_ready_check_mcu_mode(): wocpu is ready [ 14.455905] warp_woctrl_init_state(), wo_state: WO_STATE_ENABLE [ 14.461824] wo_proc_init done 00000000ade1a65e [ 14.466348] wo_exep_proc_init done 00000000ade1a65e [ 14.471344] wo_exception_init(0): exp log= 0x0000000048f4a77e, phy_addr= 0x0000000046948000 size= 32768 [ 14.560078] WiFi@C12L1,RTMPWirelessModeCfg() 607: Init: BSS0 PhyMode=78 [ 14.566692] WiFi@C12L1,RTMPWirelessModeCfg() 607: Init: BSS1 PhyMode=78 [ 14.573303] WiFi@C12L1,RTMPWirelessModeCfg() 607: Init: BSS2 PhyMode=78 [ 14.579912] WiFi@C12L1,RTMPWirelessModeCfg() 607: Init: BSS3 PhyMode=177 [ 14.586607] WiFi@C12L1,RTMPWirelessModeCfg() 607: Init: BSS4 PhyMode=177 [ 14.593300] WiFi@C12L1,RTMPWirelessModeCfg() 607: Init: BSS5 PhyMode=177 [ 14.650339] WiFi@C15L1,Set_PMFMFPC_Proc() 1722: [PMF] :: apidx=0, Desired MFPC=1 [ 14.657727] WiFi@C15L1,Set_PMFMFPC_Proc() 1722: [PMF] :: apidx=1, Desired MFPC=1 [ 14.665113] WiFi@C15L1,Set_PMFMFPC_Proc() 1722: [PMF] :: apidx=2, Desired MFPC=1 [ 14.672498] WiFi@C15L1,Set_PMFMFPC_Proc() 1722: [PMF] :: apidx=3, Desired MFPC=1 [ 14.679885] WiFi@C15L1,Set_PMFMFPC_Proc() 1722: [PMF] :: apidx=4, Desired MFPC=1 [ 14.687272] WiFi@C15L1,Set_PMFMFPC_Proc() 1722: [PMF] :: apidx=5, Desired MFPC=1 [ 14.700898] WiFi@C12L1,rtmp_read_ap_client_from_file() 1635: APCLI[0] ApCliMuMimoDlEnable = 0 [ 14.709416] WiFi@C12L1,rtmp_read_ap_client_from_file() 1635: APCLI[1] ApCliMuMimoDlEnable = 0 [ 14.718108] WiFi@C12L1,rtmp_read_ap_client_from_file() 1654: APCLI[0] ApCliMuMimoUlEnable = 0 [ 14.726624] WiFi@C12L1,rtmp_read_ap_client_from_file() 1654: APCLI[1] ApCliMuMimoUlEnable = 0 [ 14.735506] WiFi@C03L1,AndesSendCmdMsg() 754: Could not send in band command due to diablefRTMP_ADAPTER_MCU_SEND_IN_BAND_CMD [ 14.746714] WiFi@C03L1,AndesSendCmdMsg() 754: Could not send in band command due to diablefRTMP_ADAPTER_MCU_SEND_IN_BAND_CMD [ 14.832347] wdma_dma_ctrl(): WDMA_GLO_CFG=50404e70, txrx = 0 [ 14.841381] wdma_dma_ctrl(): WDMA_GLO_CFG=40404e70, txrx = 0 [ 14.855026] warp_tx_ring_init_hw(): configure ring 0 setting [ 14.860693] warp_tx_ring_init_hw(): wed:00000000e89726f6 wifi:000000002b3bd17d: 24420=468f8000,24424=2048,24428=0 [ 14.870940] warp_tx_ring_init_hw(): configure ring 1 setting [ 14.876589] warp_tx_ring_init_hw(): wed:00000000e89726f6 wifi:000000002b3bd17d: 24430=46898000,24434=2048,24438=0 [ 14.886955] set_rrocfg,0 [ 14.912373] wdma_dma_ctrl(): WDMA_GLO_CFG=40404e74, txrx = 3 [ 14.918027] using E1 ROM patch [ 14.921073] using E1 RAM [ 14.923598] current sync CR = 0x1 [ 14.926904] Built date: 20231228201236a [ 14.930824] Platform: ALPS [ 14.933613] HW/SW version: 0x8a108a10 [ 14.937355] Patch version: 0xffffffff [ 14.951430] current sync CR = 0x1 [ 14.954747] Chip ID: 0x14 [ 14.957451] Eco version: 0x00 [ 14.960499] Region number: 0x0b [ 14.963715] Format version: 0x02 [ 14.967024] Format flag: 0x01 [ 14.970073] Ram version: ____000000 [ 14.973644] Built date: 20231228201255 [ 14.977478] Common crc: 0xb19053d0 [ 14.980961] Release info: header tag = 0, total length = 64 [ 14.986612] tag 1, padding length = 1, tag length = 59 [ 14.991825] payload: t-neptune-main-mt7915-1953-MT7981_MP2111_IMP-20231228201156 [ 15.020310] Chip ID: 0x00 [ 15.023015] Eco version: 0x00 [ 15.026068] Region number: 0x03 [ 15.029292] Format version: 0x02 [ 15.032603] Format flag: 0x01 [ 15.035645] Ram version: DEV_000000 [ 15.039217] Built date: 20231228201757 [ 15.043052] Common crc: 0x9d94838d [ 15.046532] Release info: header tag = 0, total length = 0 [ 15.137335] current sync CR = 0x7 [ 15.140680] efuse_probe: efuse = deaddead [ 15.286165] WiFi@C02L1,is_cal_free_ic() 831: [a-die version:1] [ 17.643622] WiFi@C17L1,RTMPReadTxPwrPerRate() 450: (450): Don't Support this now! [ 17.651149] WiFi@C01L1,AntCfgInit() 3165: Not support for HIF_MT yet! [ 17.675653] WiFi@C17L1,tx_pwr_comp_init() 641: NotSupportYet! [ 17.681477] WiFi@C12L1,SCS_init() 880: INIT SCSEnable [0]= 1 [ 17.687148] WiFi@C12L1,SCS_init() 887: INIT SCSEnable [1]= 0 [ 17.693104] WiFi@C14L1,IPMacTable_init() 348: IPMacTable already inited! [ 17.719965] wdma_dma_ctrl(): WDMA_GLO_CFG=50804e75, txrx = 3 [ 17.725912] WiFi@C00L1,set_ack_timeout_mode_byband() 13556: CTS/ACK Timeout Range should between [0xFFFF:0]!! [ 17.735828] WiFi@C00L1,set_datcfg_ack_cts_timeout() 13644: DAT config band(0) cck_timeout Fail! [ 17.744517] WiFi@C00L1,set_ack_timeout_mode_byband() 13556: CTS/ACK Timeout Range should between [0xFFFF:0]!! [ 17.754419] WiFi@C00L1,set_datcfg_ack_cts_timeout() 13655: DAT config band(0) ofdm_timeout Fail! [ 17.763192] WiFi@C00L1,set_ack_timeout_mode_byband() 13556: CTS/ACK Timeout Range should between [0xFFFF:0]!! [ 17.773093] WiFi@C00L1,set_datcfg_ack_cts_timeout() 13666: DAT config band(0) ofdma_timeout Fail! [ 17.781953] WiFi@C00L1,set_ack_timeout_mode_byband() 13556: CTS/ACK Timeout Range should between [0xFFFF:0]!! [ 17.791854] WiFi@C00L1,set_datcfg_ack_cts_timeout() 13644: DAT config band(1) cck_timeout Fail! [ 17.800540] WiFi@C00L1,set_ack_timeout_mode_byband() 13556: CTS/ACK Timeout Range should between [0xFFFF:0]!! [ 17.810441] WiFi@C00L1,set_datcfg_ack_cts_timeout() 13655: DAT config band(1) ofdm_timeout Fail! [ 17.819214] WiFi@C00L1,set_ack_timeout_mode_byband() 13556: CTS/ACK Timeout Range should between [0xFFFF:0]!! [ 17.829114] WiFi@C00L1,set_datcfg_ack_cts_timeout() 13666: DAT config band(1) ofdma_timeout Fail! [ 17.841103] phy_freq_adjust : no prim_ch value for adjust! [ 17.847571] phy_freq_adjust : no prim_ch value for adjust! [ 17.853121] phy_freq_adjust : no prim_ch value for adjust! [ 17.991250] WiFi@C00L1,MtCmdCr4RedSet() 914: MtCmdCr4RedSet: (ret = 0) [ 17.998382] WiFi@C23L1,DfsBuildChannelList() 4093: [RDM]: wdev is not 5G. [ 18.005209] phy_freq_adjust : no prim_ch value for adjust! [ 18.012258] WiFi@C23L1,HcGetBandByChannel() 1238: No hdev parking on channel:0, just return a default band_idx 0! [ 20.757210] WiFi@C23L1,DfsBuildChannelList() 4093: [RDM]: wdev is not 5G. [ 20.842486] WiFi@C00L1,TxCCKStreamCtrl() 20928: set wrong parameters [ 20.859135] PrintSrCmd: [ 20.859135] u1CmdSubId = 1, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 20.859135] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 20.873135] PrintSrCmd: [ 20.873135] u1CmdSubId = 5, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 20.873135] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 20.887121] PrintSrCmd: [ 20.887121] u1CmdSubId = 3, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 20.887121] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 20.901110] PrintSrCmd: [ 20.901110] u1CmdSubId = 23, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 20.901110] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 20.915179] PrintSrCmd: [ 20.915179] u1CmdSubId = 31, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 20.915179] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 20.929250] PrintSrCmd: [ 20.929250] u1CmdSubId = 33, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 20.929250] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 20.943434] mtk_ppe_dev_register_hook : ineterface ra0 register (1) [ 20.945922] [mtf_txpower_all_rate_info] band_idx:0 pwr:46 ChBand:2G ePAGain:0 [ 20.962999] extif_put_dev(ra0) [ 20.966061] mtk_ppe_dev_unregister_hook : ineterface ra0 set null (1) [ 24.903924] mtk_soc_eth 15100000.ethernet eth0: Link is Down [ 24.923025] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode [ 24.938106] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 24.942588] br-lan: port 1(eth0) entered blocking state [ 24.951955] br-lan: port 1(eth0) entered disabled state [ 24.957415] device eth0 entered promiscuous mode [ 24.974208] br-lan: port 1(eth0) entered blocking state [ 24.979464] br-lan: port 1(eth0) entered forwarding state [ 24.995649] mtk_soc_eth 15100000.ethernet eth1: configuring for fixed/2500base-x link mode [ 25.011722] mtk_soc_eth 15100000.ethernet eth1: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 25.020656] IPv6: ADDRCONF(NETDEV_CHANGE): eth1: link becomes ready [ 25.158059] wan-detect: service: [ 25.859029] WiFi@C23L1,DfsBuildChannelList() 4093: [RDM]: wdev is not 5G. [ 25.866024] WiFi@C23L1,DfsBuildChannelList() 4093: [RDM]: wdev is not 5G. [ 25.899917] phy_freq_adjust : no prim_ch value for adjust! [ 25.905782] WiFi@C23L1,HcGetBandByChannel() 1238: No hdev parking on channel:0, just return a default band_idx 0! [ 28.653250] WiFi@C23L1,DfsBuildChannelList() 4093: [RDM]: wdev is not 5G. [ 28.748186] WiFi@C00L1,TxCCKStreamCtrl() 20928: set wrong parameters [ 28.764769] PrintSrCmd: [ 28.764769] u1CmdSubId = 1, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 28.764769] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 28.778778] PrintSrCmd: [ 28.778778] u1CmdSubId = 5, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 28.778778] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 28.792768] PrintSrCmd: [ 28.792768] u1CmdSubId = 3, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 28.792768] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 28.806774] PrintSrCmd: [ 28.806774] u1CmdSubId = 23, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 28.806774] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 28.820860] PrintSrCmd: [ 28.820860] u1CmdSubId = 31, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 28.820860] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 28.834942] PrintSrCmd: [ 28.834942] u1CmdSubId = 33, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 28.834942] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 28.849101] extif_set_dev(ra0) [ 28.852157] [mtf_txpower_all_rate_info] band_idx:0 pwr:46 ChBand:2G ePAGain:0 [ 28.859290] mtk_ppe_dev_register_hook : ineterface ra0 register (1) [ 28.865743] IPv6: ADDRCONF(NETDEV_CHANGE): ra0: link becomes ready [ 29.038962] br-lan: port 2(ra0) entered blocking state [ 29.044136] br-lan: port 2(ra0) entered disabled state [ 29.049461] device ra0 entered promiscuous mode [ 29.054095] br-lan: port 2(ra0) entered blocking state [ 29.059273] br-lan: port 2(ra0) entered forwarding state [ 29.111930] WiFi@C00L1,ApAutoChannelAtBootUp() 521: not 5G A band [ 29.118062] WiFi@C08L1,ap_run_at_boot() 668: ACS is disable !! [ 29.224717] WiFi@C00L1,TxCCKStreamCtrl() 20928: set wrong parameters [ 29.244579] PrintSrCmd: [ 29.244579] u1CmdSubId = 1, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 29.244579] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 29.258682] PrintSrCmd: [ 29.258682] u1CmdSubId = 5, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 29.258682] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 29.272732] PrintSrCmd: [ 29.272732] u1CmdSubId = 3, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 29.272732] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 29.286760] PrintSrCmd: [ 29.286760] u1CmdSubId = 23, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 29.286760] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 29.300886] PrintSrCmd: [ 29.300886] u1CmdSubId = 31, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 29.300886] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 29.315005] PrintSrCmd: [ 29.315005] u1CmdSubId = 33, u1ArgNum = 0, u1DbdcIdx = 0, u1Status = 0 [ 29.315005] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 29.329173] mtk_ppe_dev_register_hook : ra2 is in hwnat blackList, not to register [ 29.336890] [mtf_txpower_all_rate_info] band_idx:0 pwr:46 ChBand:2G ePAGain:0 [ 29.587273] br-lan: port 3(ra2) entered blocking state [ 29.592463] br-lan: port 3(ra2) entered disabled state [ 29.597811] device ra2 entered promiscuous mode [ 29.602473] br-lan: port 3(ra2) entered blocking state [ 29.607655] br-lan: port 3(ra2) entered forwarding state [ 29.702147] SetThermalProtectDutyCfg(): band_idx: 0, level_idx: 0, duty: 100 [ 29.711020] SetThermalProtectDutyCfg(): band_idx: 0, level_idx: 1, duty: 75 [ 29.722701] SetThermalProtectDutyCfg(): band_idx: 0, level_idx: 2, duty: 50 [ 29.736000] SetThermalProtectDutyCfg(): band_idx: 0, level_idx: 3, duty: 10 [ 29.747451] SetThermalProtectEnable(): band_idx: 0, protection_type: 1, trigger_type: 1 [ 29.755508] SetThermalProtectEnable(): trigger_temp: 112, restore_temp: 100, recheck_time: 3 [ 29.768547] SetThermalProtectEnable(): band_idx: 0, protection_type: 2, trigger_type: 1 [ 29.776565] SetThermalProtectEnable(): trigger_temp: 124, restore_temp: 0, recheck_time: 5 [ 29.784981] (Thermal Protect) Radio Notify. [ 29.789180] band_idx: 0, level_idx: 0 [ 30.780520] sh (5469): drop_caches: 3 [ 30.851453] sh (5411): drop_caches: 3 [ 31.206073] phy_freq_adjust : no prim_ch value for adjust! [ 31.211748] phy_freq_adjust : no prim_ch value for adjust! [ 31.217366] phy_freq_adjust : no prim_ch value for adjust! [ 31.222899] phy_freq_adjust : no prim_ch value for adjust! [ 31.228467] phy_freq_adjust : no prim_ch value for adjust! [ 31.234002] phy_freq_adjust : no prim_ch value for adjust! [ 31.289939] phy_freq_adjust : no prim_ch value for adjust! [ 31.295498] phy_freq_adjust : no prim_ch value for adjust! [ 31.313049] phy_freq_adjust : no prim_ch value for adjust! [ 31.338677] 7981@C23L1,HcGetBandByChannel() 1238: No hdev parking on channel:0, just return a default band_idx 0! [ 33.462800] PrintSrCmd: [ 33.462800] u1CmdSubId = 1, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.462800] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.476805] PrintSrCmd: [ 33.476805] u1CmdSubId = 5, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.476805] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.490808] PrintSrCmd: [ 33.490808] u1CmdSubId = 3, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.490808] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.504800] PrintSrCmd: [ 33.504800] u1CmdSubId = 23, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.504800] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.518874] PrintSrCmd: [ 33.518874] u1CmdSubId = 31, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.518874] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.532949] PrintSrCmd: [ 33.532949] u1CmdSubId = 33, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.532949] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.547057] mtk_ppe_dev_register_hook : ineterface rax0 register (2) [ 33.549561] [mtf_txpower_all_rate_info] band_idx:1 pwr:46 ChBand:5G ePAGain:0 [ 33.717062] br-lan: port 4(rax0) entered blocking state [ 33.722323] br-lan: port 4(rax0) entered disabled state [ 33.727774] device rax0 entered promiscuous mode [ 33.732510] br-lan: port 4(rax0) entered blocking state [ 33.737758] br-lan: port 4(rax0) entered forwarding state [ 33.811262] 7981@C00L1,ApAutoChannelAtBootUp() 515: zero-wait DFS is not enabled [ 33.818684] 7981@C08L1,ap_run_at_boot() 668: ACS is disable !! [ 33.917766] PrintSrCmd: [ 33.917766] u1CmdSubId = 1, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.917766] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.931773] PrintSrCmd: [ 33.931773] u1CmdSubId = 5, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.931773] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.945763] PrintSrCmd: [ 33.945763] u1CmdSubId = 3, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.945763] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.959768] PrintSrCmd: [ 33.959768] u1CmdSubId = 23, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.959768] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.973850] PrintSrCmd: [ 33.973850] u1CmdSubId = 31, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.973850] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 33.987931] PrintSrCmd: [ 33.987931] u1CmdSubId = 33, u1ArgNum = 0, u1DbdcIdx = 1, u1Status = 0 [ 33.987931] u1DropTaIdx = 0, u1StaIdx = 0, u4Value = 0 [ 34.002070] mtk_ppe_dev_register_hook : rax2 is in hwnat blackList, not to register [ 34.009821] [mtf_txpower_all_rate_info] band_idx:1 pwr:46 ChBand:5G ePAGain:0 [ 34.171001] br-lan: port 5(rax2) entered blocking state [ 34.176257] br-lan: port 5(rax2) entered disabled state [ 34.181716] device rax2 entered promiscuous mode [ 34.186426] br-lan: port 5(rax2) entered blocking state [ 34.191672] br-lan: port 5(rax2) entered forwarding state [ 34.267453] SetThermalProtectDutyCfg(): band_idx: 1, level_idx: 0, duty: 90 [ 34.277504] SetThermalProtectDutyCfg(): band_idx: 1, level_idx: 1, duty: 65 [ 34.293101] SetThermalProtectDutyCfg(): band_idx: 1, level_idx: 2, duty: 40 [ 34.309361] SetThermalProtectDutyCfg(): band_idx: 1, level_idx: 3, duty: 10 [ 34.318828] SetThermalProtectEnable(): band_idx: 1, protection_type: 1, trigger_type: 1 [ 34.326846] SetThermalProtectEnable(): trigger_temp: 112, restore_temp: 100, recheck_time: 3 [ 34.339219] SetThermalProtectEnable(): band_idx: 1, protection_type: 2, trigger_type: 1 [ 34.347256] SetThermalProtectEnable(): trigger_temp: 124, restore_temp: 0, recheck_time: 5 [ 34.355650] (Thermal Protect) Radio Notify. [ 34.359863] band_idx: 1, level_idx: 0 [ 48.913992] SCAN DONE, Reset FSM/CNTL IDLE. [ 53.146055] SCAN DONE, Reset FSM/CNTL IDLE.


F0: 102B 0000 FA: 1040 0000 FA: 1040 0000 [0200] F9: 0000 0000 V0: 0000 0000 [0001] 00: 0000 0000 BP: 2400 0041 [0000] G0: 1190 0000 EC: 0000 0000 [1000] T0: 0000 024F [010F] Jump to BL NOTICE: BL2: v2.7(release):6284467549-dirty NOTICE: BL2: Built : 02:34:12, May 15 2025 NOTICE: WDT: disabled NOTICE: EMI: Using DDR3 settings dump toprgu registers data: 1001c000 | 00000000 0000ffe0 00000000 00000000 1001c010 | 00000fff 00000000 00f00000 00000000 1001c020 | 00000000 00000000 00000000 00000000 1001c030 | 003c0003 003c0003 00000000 00000000 1001c040 | 00000000 00000000 00000000 00000000 1001c050 | 00000000 00000000 00000000 00000000 1001c060 | 00000000 00000000 00000000 00000000 1001c070 | 00000000 00000000 00000000 00000000 1001c080 | 00000000 00000000 00000000 00000000 dump drm registers data: 1001d000 | 00000000 00000000 00000000 00000000 1001d010 | 00000000 00000000 00000000 00000000 1001d020 | 00000000 00000000 00000000 00000000 1001d030 | 00a083f1 000003ff 00100000 00000000 1001d040 | 00000000 00000000 00020303 000000ff 1001d050 | 00000000 00000000 00000000 00000000 1001d060 | 00000002 00000000 00000000 00000000 drm: 500 = 0x8 [DDR Reserve] ddr reserve mode not be enabled yet DDR RESERVE Success 0 [EMI] ComboMCP not ready, using default setting BYTE_swap:0 BYTE_swap:0 Window Sum 512, worse bit 0, min window 64 Window Sum 520, worse bit 15, min window 60 Window Sum 324, worse bit 0, min window 40 Window Sum 316, worse bit 9, min window 38 Window Sum 340, worse bit 6, min window 40 Window Sum 326, worse bit 9, min window 38 Window Sum 346, worse bit 1, min window 42 Window Sum 332, worse bit 9, min window 40 Window Sum 348, worse bit 6, min window 42 Window Sum 352, worse bit 9, min window 42 Window Sum 366, worse bit 1, min window 44 Window Sum 360, worse bit 9, min window 44 Window Sum 376, worse bit 2, min window 46 Window Sum 366, worse bit 9, min window 44 Window Sum 380, worse bit 3, min window 46 Window Sum 374, worse bit 9, min window 44 Window Sum 388, worse bit 6, min window 46 Window Sum 388, worse bit 14, min window 46 Window Sum 392, worse bit 2, min window 48 Window Sum 396, worse bit 8, min window 48 NOTICE: EMI: Detected DRAM size: 256MB NOTICE: EMI: complex R/W mem test passed NOTICE: CPU: MT7981 (1300MHz) NOTICE: SPI_NAND parses attributes from parameter page. NOTICE: SPI_NAND Detected ID 0xc8 NOTICE: Page size 2048, Block size 131072, size 134217728 NOTICE: Initializing NMBM ... NOTICE: Signature found at block 1023 [0x07fe0000] NOTICE: First info table with writecount 0 found in block 960 NOTICE: Second info table with writecount 0 found in block 963 NOTICE: NMBM has been successfully attached in read-only mode NOTICE: BL2: Booting BL31 NOTICE: BL31: v2.7(release):6284467549-dirty NOTICE: BL31: Built : 02:34:12, May 15 2025 NOTICE: Hello BL31!!! U-Boot 2022.07-rc3 (May 15 2025 - 02:34:12 +0000), Build: jenkins-mtk_mt7981_router_master-50 CPU: MediaTek MT7981 Model: mt7981-rfb DRAM: 256 MiB Core: 45 devices, 20 uclasses, devicetree: embed Initializing NMBM ... spi-nand: spi_nand spi_nand@0: GigaDevice SPI NAND was found. spi-nand: spi_nand spi_nand@0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64 Could not find a valid device for nmbm0 Signature found at block 1023 [0x07fe0000] First info table with writecount 0 found in block 960 Second info table with writecount 0 found in block 963 NMBM has been successfully attached Loading Environment from MTD... *** Warning - bad CRC, using default environment In: serial@11002000 Out: serial@11002000 Err: serial@11002000 Net: Warning: ethernet@15100000 (eth0) using random MAC address - 0e:6d:b8:cb:1f:26 eth0: ethernet@15100000 ubi0: attaching mtd7 ubi0: scanning is finished ubi0: attached mtd7 (name "ubi", size 64 MiB) ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048 ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096 ubi0: good PEBs: 512, bad PEBs: 0, corrupted PEBs: 0 ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128 ubi0: max/mean erase counter: 3/2, WL threshold: 4096, image sequence number: 1032550036 ubi0: available PEBs: 2, total reserved PEBs: 510, PEBs reserved for bad PEB handling: 19 Reading from volume 'kernel' to 0x46000000, size 0x0 ... OK ## Loading kernel from FIT Image at 46000000 ... Using 'config-1' configuration Trying 'kernel-1' kernel subimage Description: ARM64 OpenWrt Linux-6.6.93 Type: Kernel Image Compression: lzma compressed Data Start: 0x460000e8 Data Size: 4127807 Bytes = 3.9 MiB Architecture: AArch64 OS: Linux Load Address: 0x48000000 Entry Point: 0x48000000 Hash algo: crc32 Hash value: f17cd8d8 Hash algo: sha1 Hash value: 28d883d1cf8eb1a7a5f7c11b5646312b32fe9c15 Verifying Hash Integrity ... crc32+ sha1+ OK ## Loading fdt from FIT Image at 46000000 ... Using 'config-1' configuration Trying 'fdt-1' fdt subimage Description: ARM64 OpenWrt cudy_wr3000s-v1 device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x463efe68 Data Size: 23071 Bytes = 22.5 KiB Architecture: AArch64 Hash algo: crc32 Hash value: 9b3173f5 Hash algo: sha1 Hash value: 034a8b41c6f6f59d2713c335b60ba4d4c32b0ab2 Verifying Hash Integrity ... crc32+ sha1+ OK Booting using the fdt blob at 0x463efe68 Uncompressing Kernel Image Loading Device Tree to 000000004f7f0000, end 000000004f7f8a1e ... OK Starting kernel ... [ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034] [ 0.000000] Linux version 6.6.93 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 13.3.0 r28739-d9340319c6) 13.3.0, GNU ld (GNU Binutils) 2.42) #0 SMP Mon Jun 23 20:40:36 2025 [ 0.000000] Machine model: Cudy WR3000S v1 [ 0.000000] OF: reserved mem: 0x0000000042ff0000..0x0000000042ffffff (64 KiB) map non-reusable ramoops@42ff0000 [ 0.000000] OF: reserved mem: 0x0000000043000000..0x000000004302ffff (192 KiB) nomap non-reusable secmon@43000000 [ 0.000000] OF: reserved mem: 0x0000000047c80000..0x0000000047d7ffff (1024 KiB) nomap non-reusable wmcpu-reserved@47c80000 [ 0.000000] OF: reserved mem: 0x0000000047d80000..0x0000000047dbffff (256 KiB) nomap non-reusable wo-emi@47d80000 [ 0.000000] OF: reserved mem: 0x0000000047dc0000..0x0000000047ffffff (2304 KiB) nomap non-reusable wo-data@47dc0000 [ 0.000000] Zone ranges: [ 0.000000] DMA [mem 0x0000000040000000-0x000000004fffffff] [ 0.000000] DMA32 empty [ 0.000000] Normal empty [ 0.000000] Movable zone start for each node [ 0.000000] Early memory node ranges [ 0.000000] node 0: [mem 0x0000000040000000-0x0000000042ffffff] [ 0.000000] node 0: [mem 0x0000000043000000-0x000000004302ffff] [ 0.000000] node 0: [mem 0x0000000043030000-0x0000000047c7ffff] [ 0.000000] node 0: [mem 0x0000000047c80000-0x0000000047ffffff] [ 0.000000] node 0: [mem 0x0000000048000000-0x000000004fffffff] [ 0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000004fffffff] [ 0.000000] psci: probing for conduit method from DT. [ 0.000000] psci: PSCIv1.1 detected in firmware. [ 0.000000] psci: Using standard PSCI v0.2 function IDs [ 0.000000] psci: MIGRATE_INFO_TYPE not supported. [ 0.000000] psci: SMC Calling Convention v1.2 [ 0.000000] percpu: Embedded 18 pages/cpu s35624 r8192 d29912 u73728 [ 0.000000] pcpu-alloc: s35624 r8192 d29912 u73728 alloc=18*4096 [ 0.000000] pcpu-alloc: [0] 0 [0] 1 [ 0.000000] Detected VIPT I-cache on CPU0 [ 0.000000] CPU features: detected: GIC system register CPU interface [ 0.000000] CPU features: kernel page table isolation disabled by kernel configuration [ 0.000000] alternatives: applying boot alternatives [ 0.000000] Kernel command line: [ 0.000000] Dentry cache hash table entries: 32768 (order: 6, 262144 bytes, linear) [ 0.000000] Inode-cache hash table entries: 16384 (order: 5, 131072 bytes, linear) [ 0.000000] Built 1 zonelists, mobility grouping on. Total pages: 64512 [ 0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off [ 0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 0MB [ 0.000000] software IO TLB: area num 2. [ 0.000000] software IO TLB: SWIOTLB bounce buffer size roundup to 0MB [ 0.000000] software IO TLB: mapped [mem 0x000000004fe47000-0x000000004fec7000] (0MB) [ 0.000000] Memory: 239884K/262144K available (9024K kernel code, 1000K rwdata, 1672K rodata, 448K init, 307K bss, 22260K reserved, 0K cma-reserved) [ 0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1 [ 0.000000] rcu: Hierarchical RCU implementation. [ 0.000000] rcu: RCU restricting CPUs from NR_CPUS=4 to nr_cpu_ids=2. [ 0.000000] Tracing variant of Tasks RCU enabled. [ 0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies. [ 0.000000] rcu: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=2 [ 0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0 [ 0.000000] GICv3: GIC: Using split EOI/Deactivate mode [ 0.000000] GICv3: 640 SPIs implemented [ 0.000000] GICv3: 0 Extended SPIs implemented [ 0.000000] Root IRQ handler: 0xffffffc080010080 [ 0.000000] GICv3: GICv3 features: 16 PPIs [ 0.000000] GICv3: CPU0: found redistributor 0 region 0:0x000000000c080000 [ 0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention. [ 0.000000] arch_timer: cp15 timer(s) running at 13.00MHz (phys). [ 0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x2ff89eacb, max_idle_ns: 440795202429 ns [ 0.000000] sched_clock: 56 bits at 13MHz, resolution 76ns, wraps every 4398046511101ns [ 0.000075] Calibrating delay loop (skipped), value calculated using timer frequency.. 26.00 BogoMIPS (lpj=130000) [ 0.000083] pid_max: default: 32768 minimum: 301 [ 0.003088] Mount-cache hash table entries: 512 (order: 0, 4096 bytes, linear) [ 0.003095] Mountpoint-cache hash table entries: 512 (order: 0, 4096 bytes, linear) [ 0.005309] cacheinfo: Unable to detect cache hierarchy for CPU 0 [ 0.005842] RCU Tasks Trace: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. [ 0.005982] rcu: Hierarchical SRCU implementation. [ 0.005985] rcu: Max phase no-delay instances is 1000. [ 0.006380] smp: Bringing up secondary CPUs ... [ 0.006740] Detected VIPT I-cache on CPU1 [ 0.006782] GICv3: CPU1: found redistributor 1 region 0:0x000000000c0a0000 [ 0.006810] CPU1: Booted secondary processor 0x0000000001 [0x410fd034] [ 0.006877] smp: Brought up 1 node, 2 CPUs [ 0.006882] SMP: Total of 2 processors activated. [ 0.006886] CPU features: detected: 32-bit EL0 Support [ 0.006889] CPU features: detected: CRC32 instructions [ 0.006920] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching [ 0.006924] CPU: All CPU(s) started at EL2 [ 0.006925] alternatives: applying system-wide alternatives [ 0.010511] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns [ 0.010528] futex hash table entries: 512 (order: 3, 32768 bytes, linear) [ 0.011808] pinctrl core: initialized pinctrl subsystem [ 0.012937] NET: Registered PF_NETLINK/PF_ROUTE protocol family [ 0.013257] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations [ 0.013280] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations [ 0.013301] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations [ 0.013671] thermal_sys: Registered thermal governor 'fair_share' [ 0.013675] thermal_sys: Registered thermal governor 'bang_bang' [ 0.013677] thermal_sys: Registered thermal governor 'step_wise' [ 0.013680] thermal_sys: Registered thermal governor 'user_space' [ 0.013725] ASID allocator initialised with 65536 entries [ 0.014625] pstore: Using crash dump compression: deflate [ 0.014630] pstore: Registered ramoops as persistent store backend [ 0.014632] ramoops: using 0x10000@0x42ff0000, ecc: 0 [ 0.016051] /soc/interrupt-controller@c000000: Fixed dependency cycle(s) with /soc/interrupt-controller@c000000 [ 0.021380] Modules: 29616 pages in range for non-PLT usage [ 0.021389] Modules: 521136 pages in range for PLT usage [ 0.022354] cryptd: max_cpu_qlen set to 1000 [ 0.023419] SCSI subsystem initialized [ 0.023629] libata version 3.00 loaded. [ 0.025241] clocksource: Switched to clocksource arch_sys_counter [ 0.027486] NET: Registered PF_INET protocol family [ 0.027592] IP idents hash table entries: 4096 (order: 3, 32768 bytes, linear) [ 0.028857] tcp_listen_portaddr_hash hash table entries: 256 (order: 0, 4096 bytes, linear) [ 0.028871] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear) [ 0.028879] TCP established hash table entries: 2048 (order: 2, 16384 bytes, linear) [ 0.028897] TCP bind hash table entries: 2048 (order: 4, 65536 bytes, linear) [ 0.028945] TCP: Hash tables configured (established 2048 bind 2048) [ 0.029268] MPTCP token hash table entries: 256 (order: 0, 6144 bytes, linear) [ 0.029372] UDP hash table entries: 256 (order: 1, 8192 bytes, linear) [ 0.029388] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes, linear) [ 0.029583] NET: Registered PF_UNIX/PF_LOCAL protocol family [ 0.029606] PCI: CLS 0 bytes, default 64 [ 0.031249] workingset: timestamp_bits=46 max_order=16 bucket_order=0 [ 0.036244] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 0.036252] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc. [ 0.092483] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251) [ 0.102733] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled [ 0.106332] printk: console [ttyS0] disabled [ 0.126703] 11002000.serial: ttyS0 at MMIO 0x11002000 (irq = 72, base_baud = 2500000) is a ST16650V2 [ 0.126743] printk: console [ttyS0] enabled [ 0.889445] loop: module loaded [ 0.896072] spi-nand spi0.0: calibration result: 0x3 [ 0.901121] spi-nand spi0.0: ESMT SPI NAND was found. [ 0.906178] spi-nand spi0.0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64 [ 0.914631] Signature found at block 1023 [0x07fe0000] [ 0.919786] NMBM management region starts at block 960 [0x07800000] [ 0.927007] First info table with writecount 0 found in block 960 [ 0.935901] Second info table with writecount 0 found in block 963 [ 0.942085] NMBM has been successfully attached [ 0.946947] 6 fixed-partitions partitions found on MTD device spi0.0 [ 0.953532] Creating 6 MTD partitions on "spi0.0": [ 0.958359] 0x000000000000-0x000000100000 : "BL2" [ 0.964119] 0x000000100000-0x000000180000 : "u-boot-env" [ 0.970176] 0x000000180000-0x000000380000 : "Factory" [ 0.976896] 0x000000380000-0x0000003c0000 : "bdinfo" [ 0.982689] 0x0000003c0000-0x0000005c0000 : "FIP" [ 0.988943] 0x0000005c0000-0x0000045c0000 : "ubi" [ 1.023750] ubi0: default fastmap pool size: 25 [ 1.028302] ubi0: default fastmap WL pool size: 12 [ 1.033085] ubi0: attaching mtd5 [ 1.250899] ubi0: scanning is finished [ 1.260403] ubi0: attached mtd5 (name "ubi", size 64 MiB) [ 1.265825] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes [ 1.272690] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048 [ 1.279472] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096 [ 1.286423] ubi0: good PEBs: 512, bad PEBs: 0, corrupted PEBs: 0 [ 1.292416] ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128 [ 1.299627] ubi0: max/mean erase counter: 3/2, WL threshold: 4096, image sequence number: 1032550036 [ 1.308747] ubi0: available PEBs: 0, total reserved PEBs: 512, PEBs reserved for bad PEB handling: 19 [ 1.317963] ubi0: background thread "ubi_bgt0d" started, PID 250 [ 1.324629] block ubiblock0_1: created from ubi0:1(rootfs) [ 1.330159] ubiblock: device ubiblock0_1 (rootfs) set to be root filesystem [ 1.482425] mtk_soc_eth 15100000.ethernet eth0: mediatek frame engine at 0xffffffc081780000, irq 75 [ 1.492153] i2c_dev: i2c /dev entries driver [ 1.498186] mtk-wdt 1001c000.watchdog: Watchdog enabled (timeout=31 sec, nowayout=0) [ 1.507321] NET: Registered PF_INET6 protocol family [ 1.513251] Segment Routing with IPv6 [ 1.516963] In-situ OAM (IOAM) with IPv6 [ 1.520923] NET: Registered PF_PACKET protocol family [ 1.526025] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this. [ 1.539171] 8021q: 802.1Q VLAN Support v1.8 [ 1.646753] mt7530-mdio mdio-bus:1f: configuring for fixed/2500base-x link mode [ 1.655484] mt7530-mdio mdio-bus:1f: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 1.666662] mt7530-mdio mdio-bus:1f wan (uninitialized): PHY [mt7530-0:00] driver [MediaTek MT7531 PHY] (irq=79) [ 1.688821] mt7530-mdio mdio-bus:1f lan1 (uninitialized): PHY [mt7530-0:01] driver [MediaTek MT7531 PHY] (irq=80) [ 1.710893] mt7530-mdio mdio-bus:1f lan2 (uninitialized): PHY [mt7530-0:02] driver [MediaTek MT7531 PHY] (irq=81) [ 1.732938] mt7530-mdio mdio-bus:1f lan3 (uninitialized): PHY [mt7530-0:03] driver [MediaTek MT7531 PHY] (irq=82) [ 1.754977] mt7530-mdio mdio-bus:1f lan4 (uninitialized): PHY [mt7530-0:04] driver [MediaTek MT7531 PHY] (irq=83) [ 1.766264] mtk_soc_eth 15100000.ethernet eth0: entered promiscuous mode [ 1.773007] DSA: tree 0 setup [ 1.776318] clk: Disabling unused clocks [ 1.785570] VFS: Mounted root (squashfs filesystem) readonly on device 254:0. [ 1.792879] Freeing unused kernel memory: 448K [ 1.797391] Run /sbin/init as init process [ 1.801476] with arguments: [ 1.804430] /sbin/init [ 1.807136] with environment: [ 1.810264] HOME=/ [ 1.812611] TERM=linux [ 1.996167] init: Console is alive [ 1.999699] init: - watchdog - [ 2.369340] kmodloader: loading kernel modules from /etc/modules-boot.d/* [ 2.388852] gpio_button_hotplug: loading out-of-tree module taints kernel. [ 2.398665] kmodloader: done loading kernel modules from /etc/modules-boot.d/* [ 2.416662] init: - preinit - [ 2.733647] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode [ 2.742141] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 2.765864] mt7530-mdio mdio-bus:1f lan1: configuring for phy/gmii link mode Press the [f] key and hit [enter] to enter failsafe mode Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level [ 5.855279] random: crng init done [ 6.975303] UBIFS (ubi0:2): Mounting in unauthenticated mode [ 6.981054] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" started, PID 744 [ 7.013938] UBIFS (ubi0:2): recovery needed [ 7.116353] UBIFS (ubi0:2): recovery completed [ 7.120845] UBIFS (ubi0:2): UBIFS: mounted UBI device 0, volume 2, name "rootfs_data" [ 7.128678] UBIFS (ubi0:2): LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes [ 7.138586] UBIFS (ubi0:2): FS size: 47996928 bytes (45 MiB, 378 LEBs), max 388 LEBs, journal size 2412544 bytes (2 MiB, 19 LEBs) [ 7.150227] UBIFS (ubi0:2): reserved for root: 2267013 bytes (2213 KiB) [ 7.156832] UBIFS (ubi0:2): media format: w5/r0 (latest is w5/r0), UUID 2687C4C0-7E3E-4F03-A0F5-5BE64E30D977, small LPT model [ 7.171004] mount_root: switching to ubifs overlay [ 7.180701] overlayfs: null uuid detected in lower fs '/', falling back to xino=off,index=off,nfs_export=off. [ 7.195121] urandom-seed: Seeding with /etc/urandom.seed [ 7.258822] procd: - early - [ 7.261766] procd: - watchdog - [ 7.830837] procd: - watchdog - [ 7.843076] procd: - ubus - [ 7.997237] procd: - init - Please press Enter to activate this console. [ 8.308024] kmodloader: loading kernel modules from /etc/modules.d/* [ 8.338672] crypto-safexcel 10320000.crypto: EIP97:230(0,1,4,4)-HIA:270(0,5,5),PE:150/433(alg:7fcdfc00)/0/0/0 [ 8.361747] Loading modules backported from Linux version v6.12.6-0-ge9d65b48ce1a [ 8.369336] Backport generated by backports.git v6.1.110-1-35-g410656ef04d2 [ 8.505423] urngd: v1.0.2 started. [ 8.764329] mt798x-wmac 18000000.wifi: HW/SW Version: 0x8a108a10, Build Time: 20240823161240a [ 8.764329] [ 8.965602] mt798x-wmac 18000000.wifi: WM Firmware Version: ____000000, Build Time: 20240823161304 [ 9.059822] mt798x-wmac 18000000.wifi: WA Firmware Version: DEV_000000, Build Time: 20240823161841 [ 9.157583] mt798x-wmac 18000000.wifi: registering led 'mt76-phy0' [ 9.267231] mt798x-wmac 18000000.wifi: registering led 'mt76-phy1' [ 9.346945] mtdblock: MTD device 'bdinfo' is NAND, please consider using UBI block devices instead. [ 9.385010] batman_adv: B.A.T.M.A.N. advanced 2024.3-openwrt-6 (compatibility version 15) loaded [ 9.395905] kmodloader: done loading kernel modules from /etc/modules.d/* [ 9.635935] mtdblock: MTD device 'bdinfo' is NAND, please consider using UBI block devices instead. [ 12.742686] mtk_soc_eth 15100000.ethernet eth0: Link is Down [ 12.774472] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode [ 12.786877] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 12.794125] mt7530-mdio mdio-bus:1f lan1: configuring for phy/gmii link mode [ 12.803693] br-lan: port 1(lan1) entered blocking state [ 12.808969] br-lan: port 1(lan1) entered disabled state [ 12.814220] mt7530-mdio mdio-bus:1f lan1: entered allmulticast mode [ 12.820534] mtk_soc_eth 15100000.ethernet eth0: entered allmulticast mode [ 12.831517] mt7530-mdio mdio-bus:1f lan1: entered promiscuous mode [ 12.857452] mt7530-mdio mdio-bus:1f lan2: configuring for phy/gmii link mode [ 12.868351] br-lan: port 2(lan2) entered blocking state [ 12.873584] br-lan: port 2(lan2) entered disabled state [ 12.878871] mt7530-mdio mdio-bus:1f lan2: entered allmulticast mode [ 12.888279] mt7530-mdio mdio-bus:1f lan2: entered promiscuous mode [ 12.908616] mt7530-mdio mdio-bus:1f lan3: configuring for phy/gmii link mode [ 12.920379] br-lan: port 3(lan3) entered blocking state [ 12.925673] br-lan: port 3(lan3) entered disabled state [ 12.930944] mt7530-mdio mdio-bus:1f lan3: entered allmulticast mode [ 12.940344] mt7530-mdio mdio-bus:1f lan3: entered promiscuous mode [ 12.961161] mt7530-mdio mdio-bus:1f lan4: configuring for phy/gmii link mode [ 12.973638] br-lan: port 4(lan4) entered blocking state [ 12.978911] br-lan: port 4(lan4) entered disabled state [ 12.984167] mt7530-mdio mdio-bus:1f lan4: entered allmulticast mode [ 12.994532] mt7530-mdio mdio-bus:1f lan4: entered promiscuous mode [ 13.015000] mt7530-mdio mdio-bus:1f wan: configuring for phy/gmii link mode [ 16.605521] mt7530-mdio mdio-bus:1f lan2: Link is Up - 1Gbps/Full - flow control rx/tx [ 16.605548] br-lan: port 2(lan2) entered blocking state [ 16.618659] br-lan: port 2(lan2) entered forwarding state BusyBox v1.36.1 (2025-09-21 23:22:49 UTC) built-in shell (ash) _______ ________ __ | |.-----.-----.-----.| | | |.----.| |_ | - || _ | -__| || | | || _|| _| |_______|| __|_____|__|__||________||__| |____| |__| W I R E L E S S F R E E D O M ----------------------------------------------------- OpenWrt 24.10.2, r28739-d9340319c6 ----------------------------------------------------- === WARNING! ===================================== There is no root password defined on this device! Use the "passwd" command to set up a new password in order to prevent unauthorized SSH logins. -------------------------------------------------- root@OpenWrt:~#

OpenWrt 25.12.5 (r33051-f5dae5ece4, kernel 6.12.94) on a 2026-built unit with the OEM flash layout. Kernel log only (dmesg over SSH, so there is no BL2 or U-Boot output); the UBI image sequence number and the UBIFS UUID are masked.

[ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034] [ 0.000000] Linux version 6.12.94 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r33051-f5dae5ece4) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP Mon Jun 29 12:59:20 2026 [ 0.000000] Machine model: Cudy WR3000S v1 [ 0.000000] OF: reserved mem: 0x0000000042ff0000..0x0000000042ffffff (64 KiB) map non-reusable ramoops@42ff0000 [ 0.000000] OF: reserved mem: 0x0000000043000000..0x000000004302ffff (192 KiB) nomap non-reusable secmon@43000000 [ 0.000000] OF: reserved mem: 0x0000000047c80000..0x0000000047d7ffff (1024 KiB) nomap non-reusable wmcpu-reserved@47c80000 [ 0.000000] OF: reserved mem: 0x0000000047d80000..0x0000000047dbffff (256 KiB) nomap non-reusable wo-emi@47d80000 [ 0.000000] OF: reserved mem: 0x0000000047dc0000..0x0000000047ffffff (2304 KiB) nomap non-reusable wo-data@47dc0000 [ 0.000000] Zone ranges: [ 0.000000] DMA [mem 0x0000000040000000-0x000000004fffffff] [ 0.000000] DMA32 empty [ 0.000000] Normal empty [ 0.000000] Movable zone start for each node [ 0.000000] Early memory node ranges [ 0.000000] node 0: [mem 0x0000000040000000-0x0000000042ffffff] [ 0.000000] node 0: [mem 0x0000000043000000-0x000000004302ffff] [ 0.000000] node 0: [mem 0x0000000043030000-0x0000000047c7ffff] [ 0.000000] node 0: [mem 0x0000000047c80000-0x0000000047ffffff] [ 0.000000] node 0: [mem 0x0000000048000000-0x000000004fffffff] [ 0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000004fffffff] [ 0.000000] psci: probing for conduit method from DT. [ 0.000000] psci: PSCIv1.1 detected in firmware. [ 0.000000] psci: Using standard PSCI v0.2 function IDs [ 0.000000] psci: MIGRATE_INFO_TYPE not supported. [ 0.000000] psci: SMC Calling Convention v1.2 [ 0.000000] percpu: Embedded 20 pages/cpu s42648 r8192 d31080 u81920 [ 0.000000] pcpu-alloc: s42648 r8192 d31080 u81920 alloc=20*4096 [ 0.000000] pcpu-alloc: [0] 0 [0] 1 [ 0.000000] Detected VIPT I-cache on CPU0 [ 0.000000] CPU features: detected: GIC system register CPU interface [ 0.000000] CPU features: kernel page table isolation disabled by kernel configuration [ 0.000000] alternatives: applying boot alternatives [ 0.000000] Kernel command line: [ 0.000000] Dentry cache hash table entries: 32768 (order: 6, 262144 bytes, linear) [ 0.000000] Inode-cache hash table entries: 16384 (order: 5, 131072 bytes, linear) [ 0.000000] Built 1 zonelists, mobility grouping on. Total pages: 65536 [ 0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off [ 0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 0MB [ 0.000000] software IO TLB: area num 2. [ 0.000000] software IO TLB: SWIOTLB bounce buffer size roundup to 0MB [ 0.000000] software IO TLB: mapped [mem 0x000000004fe4a000-0x000000004feca000] (0MB) [ 0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1 [ 0.000000] rcu: Hierarchical RCU implementation. [ 0.000000] rcu: RCU restricting CPUs from NR_CPUS=4 to nr_cpu_ids=2. [ 0.000000] Tracing variant of Tasks RCU enabled. [ 0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies. [ 0.000000] rcu: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=2 [ 0.000000] RCU Tasks Trace: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. [ 0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0 [ 0.000000] GICv3: GIC: Using split EOI/Deactivate mode [ 0.000000] GICv3: 640 SPIs implemented [ 0.000000] GICv3: 0 Extended SPIs implemented [ 0.000000] Root IRQ handler: 0xffffffc080010080 [ 0.000000] GICv3: GICv3 features: 16 PPIs [ 0.000000] GICv3: GICD_CTRL.DS=0, SCR_EL3.FIQ=0 [ 0.000000] GICv3: CPU0: found redistributor 0 region 0:0x000000000c080000 [ 0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention. [ 0.000000] arch_timer: cp15 timer(s) running at 13.00MHz (phys). [ 0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x2ff89eacb, max_idle_ns: 440795202429 ns [ 0.000000] sched_clock: 56 bits at 13MHz, resolution 76ns, wraps every 4398046511101ns [ 0.000075] Calibrating delay loop (skipped), value calculated using timer frequency.. 26.00 BogoMIPS (lpj=130000) [ 0.000083] pid_max: default: 32768 minimum: 301 [ 0.002998] Mount-cache hash table entries: 512 (order: 0, 4096 bytes, linear) [ 0.003006] Mountpoint-cache hash table entries: 512 (order: 0, 4096 bytes, linear) [ 0.005094] cacheinfo: Unable to detect cache hierarchy for CPU 0 [ 0.005886] rcu: Hierarchical SRCU implementation. [ 0.005893] rcu: Max phase no-delay instances is 1000. [ 0.006093] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level [ 0.006311] smp: Bringing up secondary CPUs ... [ 0.006673] Detected VIPT I-cache on CPU1 [ 0.006718] GICv3: CPU1: found redistributor 1 region 0:0x000000000c0a0000 [ 0.006746] CPU1: Booted secondary processor 0x0000000001 [0x410fd034] [ 0.006825] smp: Brought up 1 node, 2 CPUs [ 0.006830] SMP: Total of 2 processors activated. [ 0.006833] CPU: All CPU(s) started at EL2 [ 0.006836] CPU features: detected: 32-bit EL0 Support [ 0.006839] CPU features: detected: CRC32 instructions [ 0.006864] alternatives: applying system-wide alternatives [ 0.006989] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching [ 0.007112] Memory: 237412K/262144K available (9536K kernel code, 992K rwdata, 1832K rodata, 512K init, 316K bss, 23088K reserved, 0K cma-reserved) [ 0.010110] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns [ 0.010126] futex hash table entries: 512 (order: 3, 32768 bytes, linear) [ 0.010183] 29424 pages in range for non-PLT usage [ 0.010186] 520944 pages in range for PLT usage [ 0.011680] pinctrl core: initialized pinctrl subsystem [ 0.014037] NET: Registered PF_NETLINK/PF_ROUTE protocol family [ 0.014332] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations [ 0.014359] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations [ 0.014380] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations [ 0.014772] thermal_sys: Registered thermal governor 'fair_share' [ 0.014776] thermal_sys: Registered thermal governor 'bang_bang' [ 0.014779] thermal_sys: Registered thermal governor 'step_wise' [ 0.014781] thermal_sys: Registered thermal governor 'user_space' [ 0.014829] ASID allocator initialised with 65536 entries [ 0.015716] pstore: Using crash dump compression: deflate [ 0.015721] pstore: Registered ramoops as persistent store backend [ 0.015723] ramoops: using 0x10000@0x42ff0000, ecc: 0 [ 0.017189] /soc/interrupt-controller@c000000: Fixed dependency cycle(s) with /soc/interrupt-controller@c000000 [ 0.033500] cryptd: max_cpu_qlen set to 1000 [ 0.034969] SCSI subsystem initialized [ 0.035107] libata version 3.00 loaded. [ 0.036747] clocksource: Switched to clocksource arch_sys_counter [ 0.038981] NET: Registered PF_INET protocol family [ 0.039081] IP idents hash table entries: 4096 (order: 3, 32768 bytes, linear) [ 0.040390] tcp_listen_portaddr_hash hash table entries: 256 (order: 0, 4096 bytes, linear) [ 0.040406] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear) [ 0.040418] TCP established hash table entries: 2048 (order: 2, 16384 bytes, linear) [ 0.040436] TCP bind hash table entries: 2048 (order: 4, 65536 bytes, linear) [ 0.040484] TCP: Hash tables configured (established 2048 bind 2048) [ 0.040678] MPTCP token hash table entries: 256 (order: 1, 6144 bytes, linear) [ 0.040777] UDP hash table entries: 256 (order: 1, 8192 bytes, linear) [ 0.040794] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes, linear) [ 0.040990] NET: Registered PF_UNIX/PF_LOCAL protocol family [ 0.041014] PCI: CLS 0 bytes, default 64 [ 0.042249] workingset: timestamp_bits=46 max_order=16 bucket_order=0 [ 0.047342] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 0.047348] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc. [ 0.103454] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251) [ 0.114081] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled [ 0.117589] printk: legacy console [ttyS0] disabled [ 0.137959] 11002000.serial: ttyS0 at MMIO 0x11002000 (irq = 72, base_baud = 2500000) is a ST16650V2 [ 0.138001] printk: legacy console [ttyS0] enabled [ 0.908719] random: crng init done [ 0.914337] loop: module loaded [ 0.920894] spi-nand spi0.0: calibration result: 0x3 [ 0.925945] spi-nand spi0.0: ESMT SPI NAND was found. [ 0.931018] spi-nand spi0.0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64 [ 0.939574] Signature found at block 1023 [0x07fe0000] [ 0.944709] NMBM management region starts at block 960 [0x07800000] [ 0.951823] First info table with writecount 0 found in block 960 [ 0.960264] Second info table with writecount 0 found in block 963 [ 0.966442] NMBM has been successfully attached [ 0.971175] 6 fixed-partitions partitions found on MTD device spi0.0 [ 0.977790] Creating 6 MTD partitions on "spi0.0": [ 0.982579] 0x000000000000-0x000000100000 : "BL2" [ 0.988248] 0x000000100000-0x000000180000 : "u-boot-env" [ 0.994281] 0x000000180000-0x000000380000 : "Factory" [ 1.000957] 0x000000380000-0x0000003c0000 : "bdinfo" [ 1.006675] 0x0000003c0000-0x0000005c0000 : "FIP" [ 1.012824] 0x0000005c0000-0x0000045c0000 : "ubi" [ 1.047355] ubi0: default fastmap pool size: 25 [ 1.051887] ubi0: default fastmap WL pool size: 12 [ 1.056666] ubi0: attaching mtd5 [ 1.272322] ubi0: scanning is finished [ 1.280679] ubi0: attached mtd5 (name "ubi", size 64 MiB) [ 1.286082] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes [ 1.292963] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048 [ 1.299745] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096 [ 1.306693] ubi0: good PEBs: 512, bad PEBs: 0, corrupted PEBs: 0 [ 1.312691] ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128 [ 1.319904] ubi0: max/mean erase counter: 3/2, WL threshold: 4096, image sequence number: xxxxxxxxxx [ 1.329025] ubi0: available PEBs: 0, total reserved PEBs: 512, PEBs reserved for bad PEB handling: 19 [ 1.338245] ubi0: background thread "ubi_bgt0d" started, PID 269 [ 1.338917] block ubiblock0_1: created from ubi0:1(rootfs) [ 1.349734] ubiblock: device ubiblock0_1 (rootfs) set to be root filesystem [ 1.494160] mtk_soc_eth 15100000.ethernet eth0: mediatek frame engine at 0xffffffc081a00000, irq 75 [ 1.504055] i2c_dev: i2c /dev entries driver [ 1.510021] mtk-wdt 1001c000.watchdog: Watchdog enabled (timeout=31 sec, nowayout=0) [ 1.518795] NET: Registered PF_INET6 protocol family [ 1.524505] Segment Routing with IPv6 [ 1.528216] In-situ OAM (IOAM) with IPv6 [ 1.532174] NET: Registered PF_PACKET protocol family [ 1.537277] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this. [ 1.550478] 8021q: 802.1Q VLAN Support v1.8 [ 1.632719] mt7530-mdio mdio-bus:1f: configuring for fixed/2500base-x link mode [ 1.641463] mt7530-mdio mdio-bus:1f: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 1.651534] mt7530-mdio mdio-bus:1f wan (uninitialized): PHY [mt7530-0:00] driver [MediaTek MT7531 PHY] (irq=79) [ 1.672601] mt7530-mdio mdio-bus:1f lan1 (uninitialized): PHY [mt7530-0:01] driver [MediaTek MT7531 PHY] (irq=80) [ 1.693584] mt7530-mdio mdio-bus:1f lan2 (uninitialized): PHY [mt7530-0:02] driver [MediaTek MT7531 PHY] (irq=81) [ 1.714530] mt7530-mdio mdio-bus:1f lan3 (uninitialized): PHY [mt7530-0:03] driver [MediaTek MT7531 PHY] (irq=82) [ 1.735436] mt7530-mdio mdio-bus:1f lan4 (uninitialized): PHY [mt7530-0:04] driver [MediaTek MT7531 PHY] (irq=83) [ 1.746640] mtk_soc_eth 15100000.ethernet eth0: entered promiscuous mode [ 1.753389] DSA: tree 0 setup [ 1.756642] clk: Disabling unused clocks [ 1.760842] PM: genpd: Disabling unused power domains [ 1.770460] VFS: Mounted root (squashfs filesystem) readonly on device 254:0. [ 1.777819] Freeing unused kernel memory: 512K [ 1.782312] Run /sbin/init as init process [ 1.786396] with arguments: [ 1.789371] /sbin/init [ 1.792067] with environment: [ 1.795196] HOME=/ [ 1.797549] TERM=linux [ 2.016384] init: Console is alive [ 2.019961] init: - watchdog - [ 2.358733] kmodloader: loading kernel modules from /etc/modules-boot.d/* [ 2.385906] gpio_button_hotplug: loading out-of-tree module taints kernel. [ 2.401158] kmodloader: done loading kernel modules from /etc/modules-boot.d/* [ 2.418877] init: - preinit - [ 2.778557] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode [ 2.787130] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 2.817398] mt7530-mdio mdio-bus:1f lan1: configuring for phy/gmii link mode [ 7.048826] UBIFS (ubi0:2): default file-system created [ 7.054414] UBIFS (ubi0:2): Mounting in unauthenticated mode [ 7.060268] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" started, PID 759 [ 7.102093] UBIFS (ubi0:2): UBIFS: mounted UBI device 0, volume 2, name "rootfs_data" [ 7.109945] UBIFS (ubi0:2): LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes [ 7.119861] UBIFS (ubi0:2): FS size: 51044352 bytes (48 MiB, 402 LEBs), max 412 LEBs, journal size 2539520 bytes (2 MiB, 20 LEBs) [ 7.131505] UBIFS (ubi0:2): reserved for root: 2410950 bytes (2354 KiB) [ 7.138113] UBIFS (ubi0:2): media format: w5/r0 (latest is w5/r0), UUID xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx, small LPT model [ 7.150738] mount_root: overlay filesystem has not been fully initialized yet [ 7.158153] mount_root: switching to ubifs overlay [ 7.165156] overlayfs: null uuid detected in lower fs '/', falling back to xino=off,index=off,nfs_export=off. [ 7.176992] urandom-seed: Seed file not found (/etc/urandom.seed) [ 7.899409] procd: - early - [ 7.902412] procd: - watchdog - [ 8.463866] procd: - watchdog - [ 8.467450] procd: - ubus - [ 8.621214] procd: - init - [ 9.123460] urngd: v1.0.2 started. [ 9.346583] kmodloader: loading kernel modules from /etc/modules.d/* [ 9.384959] crypto-safexcel 10320000.crypto: EIP97:230(0,1,4,4)-HIA:270(0,5,5),PE:150/433(alg:7fcdfc00)/0/0/0 [ 9.400898] Loading modules backported from Linux version v6.18.26-0-g1fe060681 [ 9.408237] Backport generated by backports.git 6ecbb44 [ 9.791542] mt798x-wmac 18000000.wifi: HW/SW Version: 0x8a108a10, Build Time: 20240823161240a [ 9.966690] mt798x-wmac 18000000.wifi: WM Firmware Version: ____000000, Build Time: 20240823161304 [ 10.060734] mt798x-wmac 18000000.wifi: WA Firmware Version: DEV_000000, Build Time: 20240823161841 [ 10.157907] mt798x-wmac 18000000.wifi: registering led 'mt76-phy0' [ 10.248265] mt798x-wmac 18000000.wifi: registering led 'mt76-phy1' [ 10.330148] PPP generic driver version 2.4.2 [ 10.335418] NET: Registered PF_PPPOX protocol family [ 10.344064] kmodloader: done loading kernel modules from /etc/modules.d/* [ 10.395181] mtdblock: MTD device 'bdinfo' is NAND, please consider using UBI block devices instead. [ 10.579243] mtdblock: MTD device 'bdinfo' is NAND, please consider using UBI block devices instead. [ 15.201833] mtk_soc_eth 15100000.ethernet eth0: Link is Down [ 15.247145] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode [ 15.262548] mt7530-mdio mdio-bus:1f lan1: configuring for phy/gmii link mode [ 15.267150] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx [ 15.270872] br-lan: port 1(lan1) entered blocking state [ 15.283437] br-lan: port 1(lan1) entered disabled state [ 15.288750] mt7530-mdio mdio-bus:1f lan1: entered allmulticast mode [ 15.295021] mtk_soc_eth 15100000.ethernet eth0: entered allmulticast mode [ 15.304714] mt7530-mdio mdio-bus:1f lan1: entered promiscuous mode [ 15.326255] mt7530-mdio mdio-bus:1f lan2: configuring for phy/gmii link mode [ 15.337776] br-lan: port 2(lan2) entered blocking state [ 15.343003] br-lan: port 2(lan2) entered disabled state [ 15.348294] mt7530-mdio mdio-bus:1f lan2: entered allmulticast mode [ 15.356283] mt7530-mdio mdio-bus:1f lan2: entered promiscuous mode [ 15.371231] mt7530-mdio mdio-bus:1f lan3: configuring for phy/gmii link mode [ 15.382366] br-lan: port 3(lan3) entered blocking state [ 15.387648] br-lan: port 3(lan3) entered disabled state [ 15.392893] mt7530-mdio mdio-bus:1f lan3: entered allmulticast mode [ 15.401586] mt7530-mdio mdio-bus:1f lan3: entered promiscuous mode [ 15.438573] mt7530-mdio mdio-bus:1f lan4: configuring for phy/gmii link mode [ 15.454894] br-lan: port 4(lan4) entered blocking state [ 15.460165] br-lan: port 4(lan4) entered disabled state [ 15.465415] mt7530-mdio mdio-bus:1f lan4: entered allmulticast mode [ 15.474691] mt7530-mdio mdio-bus:1f lan4: entered promiscuous mode [ 15.503050] mt7530-mdio mdio-bus:1f wan: configuring for phy/gmii link mode [ 18.626109] mt7530-mdio mdio-bus:1f lan4: Link is Up - 1Gbps/Full - flow control rx/tx [ 18.626135] br-lan: port 4(lan4) entered blocking state [ 18.639259] br-lan: port 4(lan4) entered forwarding state

  • Tested on one 2026-built unit (September 2026): stock 2.4.6 → Cudy-signed 20251119 image → OpenWrt 25.12.5 (r33051-f5dae5ece4, kernel 6.12.94) → sysupgrade -n to a custom image built from main (commit 6727587d24, kernel 6.18.52), which booted; all on the OEM flash layout. On 25.12.5 the LEDs, buttons and all five Ethernet ports were checked, and both radios found nearby networks in a scan using the unit's own calibration data (AP mode was not tested).
  • Cudy's board code for the WR3000S is R59, and its stock image files start with WR3000S-R59- (the WR3000H is R63, the WR3000P is R57). Stock 2.4.6 and 2.5.30 are based on OpenWrt 21.02-SNAPSHOT with Linux 5.4.246.
  • The WR3000E is the same board as the WR3000S in a different case: Cudy's FCC filing for 2APRGWR3000SE covers both and declares them electrically identical, with the same board layout, differing only in the case, the antennas and how the board is mounted. This matches the WR3000E support commit, which describes the same board layout.
  • Last modified: 2026/09/23 15:10
  • by ivanthegeek