D-Link DAP-2553
The D-Link DAP-2553 is a wireless N dualband gigabit access point w/ PoE.
Currently, the DAP-2553 is NOT supported. The hardware is, quite likely, qualified for Openwrt, but the DAP2553 seems to have it's own special firmware “header”, and at the moment, there is no header calculation tool for the DAP2553. There is a lot of information though, that could help building such a utility, see the dedicated topic on Openwrt forum
Supported Versions
Version/Model | Launch Date | S/N | OpenWrt Version Supported | Model Specific Notes |
---|---|---|---|---|
DAP-2553 A1 | - | - | - |
OEM source code available at: http://tsd.dlink.com.tw/downloads2008list.asp?OS=GPL
Hardware Highlights
SoC | Ram | Flash | Network | USB | Serial | JTag |
---|---|---|---|---|---|---|
Atheros AR9132-BC1E@400MHz | 64MiB | 16MiB | 1 (PoE) | No | Yes | ? |
Manufacturer's site: http://www.dlink.com/us/en/business-solutions/wireless/access-points/access-points/dap-2553-wireless-n600-dual-band-poe-access-point
Flash Layout
D-Link DAP-2553 OEM | |||
---|---|---|---|
partition | start | end | Name |
mtd0 | 0x001700c0 | 0x01000000 | rootfs |
mtd1 | 0x000a0000 | 0x00fc0000 | upgrade |
mtd2 | 0x00060000 | 0x00080000 | rgdb |
mtd3 | 0x00040000 | 0x00060000 | bdcfg |
mtd4 | 0x00080000 | 0x000a0000 | langpack |
mtd5 | 0x00fc0000 | 0x00fe0000 | certificate |
mtd6 | 0x00fe0000 | 0x01000000 | radiocfg |
mtd7 | 0x00000000 | 0x01000000 | flash |
mtd8 | 0x00000000 | 0x00040000 | bootloader |
mtd9 | 0x00040000 | 0x00060000 | boot config |
Hardware
Info
Instruction set | MIPS |
---|---|
Vendor | Atheros |
bootloader | Das U-Boot |
System-On-Chip | Atheros AR9132-BC1E |
CPU @Frq | MIPS 4KEc V4.8 @400MHz |
Flash size | 16 MB |
Flash Chip | Winbond W29GL128CH |
RAM size | 64 MB |
RAM Chip | MT46V32M16-5BF |
Wireless No1 | Atheros AR9106 w/ 3×3 MIMO antennas for 2.4GHz 802.11b/g/n |
switch | Atheros AR8021 |
Modem | none |
USB | No |
Serial | Yes |
JTAG |
Photos
Opening the case
Serial
→ port.serial general information about the serial port, serial port cable, etc.
Serial console can be plugged to JP2: connector lacks, it has to be soldered on the board.
How to connect to the Serial Port of this specific device:
You can easily find it, look for the big diode at the front side of the board, the serial connector sits next to it:
-[DIODE]- . . . . 1 2 3 5
Pin | Signal |
---|---|
1 | TxD |
2 | GND |
3 | VCC |
4 | n/a |
5 | RxD |
The settings are: 115200 bauds, 8 bits, no parity, 1 stop bit (115200 8N1)
You are root, once connected to the serial port.
JTAG
→ port.jtag general information about the JTAG port, JTAG cable, etc.
Jtag pins seems to be located in JP1, but the connector lacks.
How to connect to the JTAG Port of this specific device:
Debricking
OEM bootlog
U-Boot 1.1.4 (May 20 2011 - 16:44:33) ALPHA U-boot v2.00r009 DRAM: sri 64 MB Top of RAM usable for U-Boot at: 84000000 Reserving 227k for U-Boot at: 83fc4000 Reserving 256k for malloc() at: 83f84000 Reserving 44 Bytes for Board Info at: 83f83fd4 Reserving 36 Bytes for Global Data at: 83f83fb0 Reserving 128k for boot params() at: 83f63fb0 Stack Pointer at: 83f63f98 Now running in RAM - U-Boot at: 83fc4000 Name: AMD-SPANSION Flash id: 0x1227E, Size: 16777216 bytes. Flash: 16 MB In: serial Out: serial Err: serial Net: ag7100_enet_initialize... : cfg1 0xf cfg2 0x7114 ATHRF1E: Port 0, Neg Success ATHRF1E: unit 0 phy addr 0 ATHRF1E: reg0 1000 eth0: 00:05:0d:06:01:03 eth0 up eth0 ### main_loop entered: bootdelay=1 ### main_loop: bootcmd="run runtime" press 'q' to stop autoboot: 0 ---------1activeregion:1---------- Protect off BF040000 ... BF05FFFF Un-Protecting sectors 2..2 in bank 1 Un-Protected 1 sectors Erasing Flash...Erase Flash from 0xbf040000 to 0xbf05ffff in Bank # 1 First 0x2 last 0x2 ^H^H^H^H^H 100% Erased 1 sectors Writing to Flash... ^H^H^H^H^H 100% done Protecting sectors 2..2 in bank 1 Protected 1 sectors ---------2activeregion:1---------- env_relocate_dual_config[317] malloced ENV at 83fa4360, size()=4 ----------dual gd->env_valid == 1---------- ---------dual env flash--------- ---------dual env flash 4--------- env_ptr_dual_config->data=83fa4371 env_ptr_dual_config->data=83f84019 ---------after relocate_dual_config 3 activeregion:2---------- env_ptr_dual_config->data=83fa4364 env_ptr_dual_config->data=83f8400c oldval==d &env_data[ENV_SIZE]=83fa8360,env=83fa4364 len=10, env_data=3ffc &env_data[ENV_SIZE]=83fa8360,env=83fa4364 =====env_ptr_dual_config->crc=84ed927a----ENV_SIZE=3ffc====== -------test dual_config CFG_ENV_SECT_SIZE 3------- -------test dual_config CONFIG_INFERNO 4------- =====env_ptr_dual_config->crc=84ed927a----ENV_SIZE=3ffc====== Protect off BFFA0000 ... BFFBFFFF Un-Protecting sectors 125..125 in bank 1 Un-Protected 1 sectors Erasing Flash...Erase Flash from 0xbffa0000 to 0xbffbffff in Bank # 1 First 0x7d last 0x7d ^H^H^H^H^H 100% Erased 1 sectors Writing to Flash... ^H^H^H^H^H 100% done Protecting sectors 125..125 in bank 1 Protected 1 sectors env_ptr_dual_config->data=83fa4371 env_ptr_dual_config->data=83f84019 ---------4activeregion:2---------- ## Booting image at bf0a0000 ... Image Name: 7zip Linux Kernel Created: 1970-01-01 0:00:00 UTC Image Type: MIPS Linux Kernel Image (lzma compressed) Data Size: -1 Bytes = 4096 MB Load Address: 80002000 Entry Point: 80002000 Uncompressing Kernel Image with LZMA ... Check Image ... Image OK! OK No initrd ## Transferring control to Linux (at address 80002000) ... ## Giving linux memsize in bytes, 67108864 Starting kernel ... Linux version 2.6.15--LSDK-7.1.3.63 (release@J10) (gcc version 3.4.4) #2 Wed Sep 25 10:58:25 CST 2013 flash_size passed from bootloader = 16 CPU revision is: 00019374 Determined physical RAM map: memory: 02000000 @ 00000000 (usable) User-defined physical RAM map: memory: 04000000 @ 00000000 (usable) Built 1 zonelists Kernel command line: console=ttyS0,115200 root=/dev/mtdblock0 rw mem=64m Primary instruction cache 64kB, physically tagged, 4-way, linesize 32 bytes. Primary data cache 32kB, 4-way, linesize 32 bytes. Synthesized TLB refill handler (20 instructions). Synthesized TLB load handler fastpath (32 instructions). Synthesized TLB store handler fastpath (32 instructions). Synthesized TLB modify handler fastpath (31 instructions). Cache parity protection disabled PID hash table entries: 512 (order: 9, 8192 bytes) Using 200.000 MHz high precision timer. Dentry cache hash table entries: 16384 (order: 4, 65536 bytes) Inode-cache hash table entries: 8192 (order: 3, 32768 bytes) Memory: 62220k/65536k available (1949k kernel code, 3256k reserved, 402k data, 124k init, 0k highmem) Mount-cache hash table entries: 512 Checking for 'wait' instruction... available. NET: Registered protocol family 16 calling simple_config callback.. SCSI subsystem initialized AR7100 GPIOC major 0 squashfs: version 3.1 (2006/08/19) Phillip Lougher devfs: 2004-01-31 Richard Gooch (rgooch@atnf.csiro.au) devfs: boot_options: 0x1 Initializing Cryptographic API io scheduler noop registered io scheduler deadline registered Serial: 8250/16550 driver $Revision: #1 $ 1 ports, IRQ sharing disabled serial8250.0: ttyS0 at MMIO 0x0 (irq = 19) is a 16550A RAMDISK driver initialized: 1 RAM disks of 65536K size 1024 blocksize ELBOX CFI physmap flash device: 1000000 at bf000000 FLASH ID: AMD-SPANSION SIZE: (16 MB) AR9100 serial flash !! ar9100-nor0: squashfs filesystem found at offset 0x00170000 Creating 10 MTD partitions on "ar9100-nor0": 0x001700c0-0x01000000 : "rootfs" 0x000a0000-0x00fc0000 : "upgrade" 0x00060000-0x00080000 : "rgdb" 0x00040000-0x00060000 : "bdcfg" 0x00080000-0x000a0000 : "langpack" 0x00fc0000-0x00fe0000 : "certificate" 0x00fe0000-0x01000000 : "radiocfg" 0x00000000-0x01000000 : "flash" 0x00000000-0x00040000 : "bootloader" 0x00040000-0x00060000 : "boot config" FLASH ID: AMD-SPANSION SIZE: (16 MB) u32 classifier NET: Registered protocol family 2 IP route cache hash table entries: 1024 (order: 0, 4096 bytes) TCP established hash table entries: 4096 (order: 2, 16384 bytes) TCP bind hash table entries: 4096 (order: 2, 16384 bytes) TCP: Hash tables configured (established 4096 bind 4096) TCP reno registered arp_tables: (C) 2002 David S. Miller TCP bic registered NET: Registered protocol family 1 NET: Registered protocol family 17 Bridge firewalling registered 802.1Q VLAN Support v1.8 Ben Greear <greearb@candelatech.com> All bugs added by David S. Miller <davem@redhat.com> ar7100wdt_init: Registering WDT success VFS: Mounted root (squashfs filesystem) readonly. Mounted devfs on /dev Freeing unused kernel memory: 124k freed init started: BusyBox v1.00 (2013.09.25-02:40+0000) multi-call binary Starting pid 14, console /dev/tts/0: '/etc/init.d/rcS' [/etc/init.d/S03config.sh] Mounting proc and var ... Inserting modules ... Inserting Rebootm ... Using /lib/modules/rebootm.ko Rebootm loading ... Inserting atheros ethernet ... Using /lib/modules/ag7100_mod.ko Inserting gpio ... Using /lib/modules/gpio.ko GPIO driver initialized. done. Start xmldb ... [/etc/scripts/misc/profile.sh] get ... [/etc/scripts/misc/defnodes.sh] ... [/etc/defnodes/S10setext.sh] ... PHP [/etc/defnodes/S11setnodes.php] ... PHP [/etc/defnodes/S12features.php] ... PHP [/etc/defnodes/S13flashspeed.php] ... PHP [/etc/defnodes/S20setnodes.php] ... SQUASHFS error: Can't find a SQUASHFS superblock on mtdblock4 mount: Mounting /dev/mtdblock/4 on /www/locale/alt failed: Invalid argument PHP [/etc/defnodes/S40brand.php] ...
LEDE bootlog
U-Boot 1.1.4 (Oct 2 2008 - 10:12:56) ALPHA U-boot v1.00r007 DRAM: sri 64 MB Top of RAM usable for U-Boot at: 84000000 Reserving 221k for U-Boot at: 83fc8000 Reserving 256k for malloc() at: 83f88000 Reserving 44 Bytes for Board Info at: 83f87fd4 Reserving 36 Bytes for Global Data at: 83f87fb0 Reserving 128k for boot params() at: 83f67fb0 Stack Pointer at: 83f67f98 Now running in RAM - U-Boot at: 83fc8000 Name: AMD-SPANSION Flash id: 0x1227E, Size: 16777216 bytes. Flash: 16 MB *** Warning - bad CRC, using default environment In: serial Out: serial Err: serial Net: ag7100_enet_initialize... : cfg1 0xf cfg2 0x7114 ATHRF1E: Port 0, Neg Success ATHRF1E: unit 0 phy addr 0 ATHRF1E: reg0 1000 eth0: 00:05:0d:06:01:03 eth0 up eth0 ### main_loop entered: bootdelay=1 ### main_loop: bootcmd="run runtime" press 'q' to stop autoboot: 0 Emergency web server start... Trying eth0 dup 1 speed 1000 Press 'q' to quit ar7100> tftpboot 0x81000000 lede-ar71xx-generic-dap-2335-a1-initramfs-kernel.bin Trying eth0 Using eth0 device TFTP from server 192.168.0.90; our IP address is 192.168.0.50 Filename 'lede-ar71xx-generic-dap-2553-a1-initramfs-kernel.bin'. Load address: 0x81000000 Loadingdone Bytes transferred = 6097280 (5d0980 hex) ar7100> bootm 0x81000000 ## Booting image at 81000000 ... Image Name: 7zip Linux Kernel Created: 1970-01-01 0:00:00 UTC Image Type: MIPS Linux Kernel Image (lzma compressed) Data Size: -1 Bytes = 4096 MB Load Address: 80002000 Entry Point: 80002000 Uncompressing Kernel Image with LZMA ... Check Image ... Image OK! OK No initrd ## Transferring control to Linux (at address 80002000) ... ## Giving linux memsize in bytes, 67108864 Starting kernel ... [ 0.000000] Linux version 4.4.15 (ignisf@clarity) (gcc version 5.4.0 (LEDE GCC 5.4.0 r1267) ) #0 Tue Aug 16 12:56:53 UTC 2016 [ 0.000000] bootconsole [early0] enabled [ 0.000000] CPU0 revision is: 00019374 (MIPS 24Kc) [ 0.000000] SoC: Atheros AR9132 rev 2 [ 0.000000] Determined physical RAM map: [ 0.000000] memory: 04000000 @ 00000000 (usable) [ 0.000000] Initrd not found or empty - disabling initrd [ 0.000000] No valid device tree found, continuing without [ 0.000000] Zone ranges: [ 0.000000] Normal [mem 0x0000000000000000-0x0000000003ffffff] [ 0.000000] Movable zone start for each node [ 0.000000] Early memory node ranges [ 0.000000] node 0: [mem 0x0000000000000000-0x0000000003ffffff] [ 0.000000] Initmem setup node 0 [mem 0x0000000000000000-0x0000000003ffffff] [ 0.000000] Primary instruction cache 64kB, VIPT, 4-way, linesize 32 bytes. [ 0.000000] Primary data cache 32kB, 4-way, VIPT, cache aliases, linesize 32 bytes [ 0.000000] Built 1 zonelists in Zone order, mobility grouping on. Total pages: 16256 [ 0.000000] Kernel command line: board=DAP-2553-A1 mtdparts=spi0.0:256k(bootloader)ro,128k(bdcfg)ro,128k(rgdb)ro,128k(langpack)ro,15488k(firmware),128k(certificate)ro,128k(radiocfg)ro console=ttyS0,115200 rootfstype=squashfs,jffs2 noinitrd [ 0.000000] PID hash table entries: 256 (order: -2, 1024 bytes) [ 0.000000] Dentry cache hash table entries: 8192 (order: 3, 32768 bytes) [ 0.000000] Inode-cache hash table entries: 4096 (order: 2, 16384 bytes) [ 0.000000] Writing ErrCtl register=00000000 [ 0.000000] Readback ErrCtl register=00000000 [ 0.000000] Memory: 55560K/65536K available (2940K kernel code, 148K rwdata, 748K rodata, 4924K init, 198K bss, 9976K reserved, 0K cma-reserved) [ 0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1 [ 0.000000] NR_IRQS:51 [ 0.000000] Clocks: CPU:400.000MHz, DDR:400.000MHz, AHB:200.000MHz, Ref:5.000MHz [ 0.000000] clocksource: MIPS: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 9556302233 ns [ 0.000013] sched_clock: 32 bits at 200MHz, resolution 5ns, wraps every 10737418237ns [ 0.007873] Calibrating delay loop... 265.42 BogoMIPS (lpj=1327104) [ 0.090597] pid_max: default: 32768 minimum: 301 [ 0.095365] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes) [ 0.101973] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes) [ 0.112337] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns [ 0.123047] NET: Registered protocol family 16 [ 0.129264] MIPS: machine is D-Link DAP-2553 rev. A1 [ 0.406185] clocksource: Switched to clocksource MIPS [ 0.412905] NET: Registered protocol family 2 [ 0.418397] TCP established hash table entries: 1024 (order: 0, 4096 bytes) [ 0.425372] TCP bind hash table entries: 1024 (order: 0, 4096 bytes) [ 0.431783] TCP: Hash tables configured (established 1024 bind 1024) [ 0.438272] UDP hash table entries: 256 (order: 0, 4096 bytes) [ 0.444115] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes) [ 0.450742] NET: Registered protocol family 1 [ 9.167140] futex hash table entries: 256 (order: -1, 3072 bytes) [ 9.173367] Crashlog allocated RAM at address 0x3f00000 [ 9.195763] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 9.201656] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc. [ 9.214681] io scheduler noop registered [ 9.218677] io scheduler deadline registered (default) [ 9.224070] Serial: 8250/16550 driver, 1 ports, IRQ sharing disabled [ 9.231018] console [ttyS0] disabled [ 9.254624] serial8250.0: ttyS0 at MMIO 0x18020000 (irq = 11, base_baud = 12500000) is a 16550A [ 9.263331] console [ttyS0] enabled [ 9.263331] console [ttyS0] enabled [ 9.270360] bootconsole [early0] disabled [ 9.270360] bootconsole [early0] disabled [ 9.282353] m25p80 spi0.0: unrecognized JEDEC id bytes: 00, 0, 0 [ 9.300391] libphy: ag71xx_mdio: probed [ 9.617641] ag71xx ag71xx.0: connected to PHY at ag71xx-mdio.0:00 [uid=004dd04e, driver=Generic PHY] [ 9.627817] eth0: Atheros AG71xx at 0xb9000000, irq 4, mode:RGMII [ 9.636645] NET: Registered protocol family 10 [ 9.645706] NET: Registered protocol family 17 [ 9.650350] bridge: automatic filtering via arp/ip/ip6tables has been deprecated. Update your scripts to load br_netfilter if you need this. [ 9.663207] 8021q: 802.1Q VLAN Support v1.8 [ 9.700598] Freeing unused kernel memory: 4924K (80421000 - 808f0000) [ 9.721243] init: Console is alive [ 9.724940] init: - watchdog - [ 9.749758] init: - preinit - [ 9.953527] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready Press the [f] key and hit [enter] to enter failsafe mode Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level [ 11.616701] eth0: link up (1000Mbps/Full duplex) [ 11.621374] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 13.128665] eth0: link down [ 13.144345] procd: - early - [ 13.147455] procd: - watchdog - [ 13.680206] procd: - ubus - [ 13.691761] random: ubusd urandom read with 21 bits of entropy available [ 13.735703] procd: - init - Please press Enter to activate this console. [ 13.925476] Loading modules backported from Linux version wt-2016-06-20-0-gbc17424 [ 13.933163] Backport generated by backports.git backports-20160216-7-g5735958 [ 14.035658] PPP generic driver version 2.4.2 [ 14.042920] NET: Registered protocol family 24 [ 14.153916] ieee80211 phy0: Atheros AR9100 MAC/BB Rev:7 AR5133 RF Rev:a2 mem=0xb80c0000, irq=2 BusyBox v1.24.2 () built-in shell (ash) _________ / /\ _ ___ ___ ___ / LE / \ | | | __| \| __| / DE / \ | |__| _|| |) | _| /________/ LE \ |____|___|___/|___| lede-project.org \ \ DE / \ LE \ / ----------------------------------------------------------- \ DE \ / Reboot (HEAD, r1351+1) \________\/ ----------------------------------------------------------- root@lede:/#
Notes
Source code for this board is available from d-link. Their GPL-site seems to be http://tsd.dlink.com.tw/downloads2008list.asp?OS=GPL, at firmware available from https://dlink-gpl.s3.amazonaws.com/GPL1400207/DAP2553_GPL130.tar.gz (v1.30) and https://dlink-gpl.s3.amazonaws.com/GPL1300038/DAP-2553_A1_GPL_1.26.tar.gz (v1.26).
The machine runs “U-Boot 1.1.4 (May 20 2011 - 16:44:33)”, with the following memory layout:
64 MB
Top of RAM usable for U-Boot at: 84000000
Reserving 227k for U-Boot at: 83fc4000
Reserving 256k for malloc() at: 83f84000
Reserving 44 Bytes for Board Info at: 83f83fd4
Reserving 36 Bytes for Global Data at: 83f83fb0
Reserving 128k for boot params() at: 83f63fb0
Stack Pointer at: 83f63f98
After booting, (and pressing q) it says:
press 'q' to stop autoboot: 0
Emergency web server start...
Trying eth0
eth0 link down
FAIL
Press 'q' to quit
You can now access the “emergency web server” at 192.168.0.50. Uploading the default D-link firmware works. Download ftp://ftp.dlink.eu/Products/dap/dap-2553/driver_software/DAP-2553_fw_revALL_1-30-rc055_all_en_20131108.zip and unpack, and send the “.bin” file to your dap-2553 to unbrick it. It tells us:
TCP:Can't alloc pktbuf
TCP:Can't alloc pktbuf
TCP:Can't alloc pktbuf
[... many, many times], then:
Control flag in image header: 0x00000001
Control flag in boot config: 0x00000001
Upload file OK!
(ENV) begin addr=0xbf0a0000,end=0xbf53ffff
Erase Flash from 0xbf0a0000 to 0xbf53ffff in Bank # 1 First 0x5 last 0x29
100%
Erased 37 sectors
100%
write image into flash...OK,dest addr=0xbf0a0000
If you press q instead, you get a u-boot menu, that has the following functions:
autoscr - run script from memory
? - alias for 'help'
base - print or set address offset
bdinfo - print Board Info structure
boot - boot default, i.e., run 'bootcmd'
bootd - boot default, i.e., run 'bootcmd'
bootelf - Boot from an ELF image in memory
bootm - boot application image from memory
bootp - boot image via network using BootP/TFTP protocol
bootvx - Boot vxWorks from an ELF image
cmp - memory compare
coninfo - print console devices and information
cp - memory copy
crc32 - checksum calculation
echo - echo args to console
erase - erase FLASH memory
flinfo - print FLASH memory information
go - start application at address 'addr'
help - print online help
iminfo - print header information for application image
imls - list all images found in flash
itest - return true/false on integer compare
loadb - load binary file over serial line (kermit mode)
loads - load S-Record file over serial line
loady - load binary file over serial line (ymodem mode)
loop - infinite loop on address range
md - memory display
mii - MII utility commands
mm - memory modify (auto-incrementing)
mtest - simple RAM test
mw - memory write (fill)
nfs - boot image via network using NFS protocol
nm - memory modify (constant address)
ping - send ICMP ECHO_REQUEST to network host
printenv- print environment variables
protect - enable or disable FLASH write protection
rarpboot- boot image via network using RARP/TFTP protocol
reset - Perform RESET of the CPU
run - run commands in an environment variable
saveenv - save environment variables to persistent storage
setenv - set environment variables
sleep - delay execution for some time
tftpboot- boot image via network using TFTP protocol
version - print monitor version
Command bdinfo tells:
boot_params = 0x83F63FB0
memstart = 0x80000000
memsize = 0x04000000
flashstart = 0xBF000000
flashsize = 0x01000000
flashoffset = 0x000279AC
ethaddr = 00:05:0D:06:01:03
ip_addr = 192.168.0.50
baudrate = 115200 bps
Command printenv tells:
loadstart=0x80002000
runtimeloadstart=0x80002000
bootstart=0xbf000000
bootsize=0x40000
bootend=0xBF03FFFF
runtimestart=0xBF0A0000
runtimesize=0x00F20000
runtimeend=0xBFFBFFFF
envstart=0xBF040000
envend=0xBF05FFFF
bootargs=console=ttyS0,115200
bootcmd=run runtime
bootdelay=1
baudrate=115200
signature=wapnd03_dkbs_dap2553
ethaddr=00:05:0D:06:01:03
ipaddr=192.168.0.50
serverip=192.168.0.90
update_bootloader=protect off $(bootstart) $(bootend);erase $(bootstart) $(boot)
update_runtime=protect off $(runtimestart) $(runtimeend);erase $(runtimestart) )
clean_env=protect off $(envstart) $(envend); erase $(envstart) $(envend);protec)
runtime=bootm $(runtimestart) $(runtimeloadstart)
ctlcode=1
activeregion=1
stdin=serial
stdout=serial
stderr=serial
ethact=eth0
Environment size: 894/16380 bytes
After booting, /proc/mtd is:
dev: size erasesize name
mtd0: 00e8ff40 00020000 “rootfs”
mtd1: 00f20000 00020000 “upgrade”
mtd2: 00020000 00020000 “rgdb”
mtd3: 00020000 00020000 “bdcfg”
mtd4: 00020000 00020000 “langpack”
mtd5: 00020000 00020000 “certificate”
mtd6: 00020000 00020000 “radiocfg”
mtd7: 01000000 00020000 “flash”
mtd8: 00040000 00020000 “bootloader”
mtd9: 00020000 00020000 “boot config”
Or, from the kernel boot log:
0x001700c0-0x01000000 : “rootfs”
0x000a0000-0x00fc0000 : “upgrade”
0x00060000-0x00080000 : “rgdb”
0x00040000-0x00060000 : “bdcfg”
0x00080000-0x000a0000 : “langpack”
0x00fc0000-0x00fe0000 : “certificate”
0x00fe0000-0x01000000 : “radiocfg”
0x00000000-0x01000000 : “flash”
0x00000000-0x00040000 : “bootloader”
0x00040000-0x00060000 : “boot config”