User Tools

Site Tools


toh:sercomm:ad1018

Sercomm AD1018

Supported Versions

  • Supported since r5531-e12c72b (only SPI flash mod).
  • As with all Broadcom-based units, internal ADSL is not supported.
  • NAND flash not supported

Since NAND flash chips aren't still supported, we need to solder an SPI flash chip to the board with a new bootloader. Only after the MOD we can install OpenWrt. The NAND flash chip will remain untouched with the original firmware

Hardware Highlights

ModelVersionSoCCPU MHzFlash MBRAM MBWLAN HardwareWLAN2.4WLAN5.0100M portsGbit portsModemUSB
AD1018Broadcom BCM6328320128NAND128Broadcom BCM43217b/g/n-4-ADSL2+Mod

Installation

Other downloads:

Hardware MOD
SPI NOR MOD AD1018-spimod-lede.zip stuff for installing LEDE/openwrt for the first time using the SPI flash mod
CFE-RAM AD1018-CFE_RAM.zip CFE RAM version with SPI and NAND flash support. Useful for making a NAND flash backup or writing to NAND flash, see NAND flash programmer. Special thanks to antares for this CFE mod

Install OpenWrt (generic explanation)

SPI flash MOD installation

Hardware modding for soldering a new SPI flash chip (> 8 MB) required. Access to the serial port on the router with an UART adapter (3.3V) also required.

  1. Solder a new flash chip to the test points as shown in the picture

    don't desolder R228 yet

  2. Run the LEDE RAM firmware using the CFE serial console
    r 192.168.1.7:ad1018-lede-ram.elf
    (192.168.1.7 is an static IP on your computer and ad1018-lede-ram.elf is into the TFTP server's directory)

  3. Now with LEDE RAM firmware running, flash the new CFE into the SPI flash chip. In the LEDE command line execute:
    mtd write CFE-AD1018-CUSTOM-SPI.bin cfe

  4. Flash the LEDE firmware into the SPI flash chip
    mtd write ad1018-lede-r4696.bin linux

  5. Power off the router, and remove the R228 resistor

  6. Done

Recommended SPI flash chips, they're cheap and should work with the custom bootloader:

  • Winbond W25Q64: 8 MB (tested)
  • Winbond W25Q128: 16 MB (tested)
  • Winbond W25Q256: 32 MB

OEM firmware

OEM firmware highlights:

  • Support for ADSL2+
  • Support for VoIP over the WAN port. It can reinject the voice through the ADSL port.
  • One ethernet port can be configured as WAN (FIBRE port).
  • No support for wifi WEP encryption
  • WDS cannot be configured via web interface, but can be enabled via command line. Only working without encryption.

For configuring the device there are three users in the Vodafone-ES stock firmware:

User Default password Notes
vodafone vodafone Limited access
admin VF-ESad1018 Full access (root) for configuration
support ? Full access (root). Only works when accessing through the WAN port
OEM firmware
OEM VFES_2.0.08 AD1018-firmware_OEM-VFES_2008.img Original firmware from Vodafone ISP
OEM VFES_3.0.11 AD1018-firmware_OEM-VFES_3011-telnetd.img Original firmware from Vodafone ISP, telnetd (port 2323) added
MOD VFES_3.0.11 AD1018-firmware_MOD-VFES_3011.img Custom build from Sercomm GPL sourcecode
OEM source code AD1018_3011_20170822.tgz Sercomm GPL sourcecode, some bits may be missing

NAND flash chip specs

ID code : 92f18095 Manufacturer : EON Device : NAND 128MiB 3,3V 8-bit Die/Package : 1 Cell type : 2 Level Cell Simultaneously programmed paged : 1 Interleave between multiple chips: False Write cache : True Page size : 2048 bytes (2 K) Spare area size : 16 bytes / 512 byte Block size : 131072 bytes (128 K) Block count : 1024 Organization : X16 Serial access time : 25 ns OOB size : 64 bytes

OEM NAND flash layout

Partition Offsets Block Name description
mtd0 0x0000000-0x0020000 0 “cferom” rom bootloader
mtd1 0x0020000-0x00c0000 1 “mmap” ram bootloader 1
mtd2 0x00c0000-0x0200000 5 “cferam1” ram bootloader 2
mtd3 0x0200000-0x0340000 16 “cferam2”
mtd4 0x0340000-0x03e0000 26 “serial”
mtd5 0x03e0000-0x0520000 31 “protect”
mtd6 0x0520000-0x2320000 41 “rootfs” Linux root (jffs2)
mtd12 0x2320000-0x3720000 281 “kfs1_lib” Linux root libraries (jffs2)
mtd7 0x3720000-0x5520000 441 “rootfs_inactive” Linux root backup (jffs2)
mtd13 0x5520000-0x6920000 681 “kfs2_lib” Linux root backup libraries (jffs2)
mtd8 0x6920000-0x6a60000 841 “bootflag1”
mtd9 0x6a60000-0x6ba0000 851 “bootflag2”
mtd10 0x6ba0000-0x6e20000 861 “xml_cfg”
mtd11 0x6e20000-0x70a0000 881 “app_dat”

Specific Configuration

Interfaces

The default network configuration is:

Interface Name Description Default configuration
br-lan LAN & WiFi 192.168.1.1/24
eth0 LAN ports (0 to 3) bridged
wlan0 WiFi bridged (disabled)

Hardware

Info

Instruction set MIPS
Vendor Broadcom
bootloader CFE
Board ID 96328avngr
System-On-Chip Broadcom BCM6328 3KFBG
CPU @Frq BMIPS4350 V7.5 @320 MHz
Flash-Chip F59L1G81A-25T / TSOP48 NAND
Flash size 128 MiB
RAM-Chip EtronTech EM68C16CWQE-25H / DDR2-800
RAM size 128 MiB
Wireless BCM43217 802.11b/g/n (onboard)
Ethernet Internal BRCM6328 Switch, 4x 100M + ADSL2+
USB 1x 2.0 mod
FXS VoIP Silicon Labs Si32177-FM1
PSU 12V DC 1.5A / I.T.E MU18-R120150-C5
Serial Yes
JTAG Yes

Photos

Casing

Board

Wifi

BCM43217 802.11b/g/n onboard wifi, 2x non-detachable external antennas.

No physical EEPROM at the board, nor partition reserverd for this data at the flash chip. In theory, in the original firmware, the EEPROM is taken from the file /etc/wlan/bcm43227_map.bin

In OpenWrt the kmod-b43 driver should be used, therefore N mode isn't available. kmod-bcmsmac could support N mode but isn't still supported for the BCM43217 wifi.

JTAG

port.jtag general information about the JTAG port, JTAG cable, etc.

TP17 = TCK TP16 = TMS TP15 = TDO TP14 = TDI TP13 = TRST

Serial

port.serial general information about the serial port, serial port cable, etc.

How to connect to the Serial Port of this specific device:

Only connect TX, RX, and GND.

baud rate: 115200

SPI

Serial Peripheral Interface

The SPI interface is near the VoIP chip. An additional Slave Select is at the bottom of the board.

GPIOs

GPIO pin description, location
0 LED internet red
1 LED internet green
2 NAND
3 NAND
4 NAND
5 NAND
6 74HC164 serial_led_data
7 74HC164 serial_led_clk
8 NAND
9 NAND
10 NAND
11 NAND
12 NAND
13 NAND
14 NAND
15 NAND
16 NAND
17 LED ephy0_spd_led
18 R228, NAND/SPI boot strap
19
20
21 NAND
22 NAND
23 RV135, Si3277 INT# (pin 9) → ext IRQ0
24 BUTTON wps
25 BUTTON wifi
26 LED ephy1_act_led
27 LED ephy2_act_led
28 LED ephy3_act_led
29 RV131, Si32177 RST# (pin 20)
30 Relay (Omron G6S-2-Y 3VDC)
31 BUTTON reset

FXS / VoIP

The board is equiped with a Si32177 FXS chip. Connected via SPI to the BCM6328 SoC, using the chip select 2:

Si32177 BCM6328
SDI SPI MOSI
SDO SPI MISO
SCLK SPI CLK
CS# SPI SS2#
INT# GPIO23, EXT_IRQ0
RST# GPIO29

It seems there are drivers available from Dragino2 board (but using SPI-GPIO bitbanging) → https://github.com/villagetelco/vt-fxs-packages/tree/master/dragino2-si3217x

Hardware mods

→ as a beginner, you really should inform yourself about soldering in general and then obtain some practical experience!

NAND flash programmer

Once you have properly working the SPI flash chip as described in Installation, it's possible to use the router as a NAND flash programmer. You need to desolder the original NAND flash chip and solder a TSOP48 socket wired to the naked NAND pads. See pics

Download the CFE RAM version with support for both SPI/NAND flash chips

AD1018-CFE_RAM.zip

Break into the CFE's from the SPI command line, and run the RAM version over a TFTP server installed in your computer

r 192.168.1.7:cfe6328_ram

now you can dump or write the NAND flash, use the help from the command line to see detailed commands

Example:

  • Backup:
    1. Make sure the TFTP server on your computer will accept uploading files from the AD1018 device
    2. In our cfe6328_ram execute
      dumpspare 192.168.1.7:dumpspare.bin
      dumpflash 192.168.1.7:dumpnand.bin
  • Restore the backup
    1. Put dumpspare.bin and dumpnand.bin files into a TFTP server in your PC
    2. Erase the NAND chip, at the cfe6328_ram execute
      eraseflash
    3. Write dumpnand.bin:
      writeflash 192.168.1.7:dumpnand.bin 0
    4. Write the OOB area:
      writespare 192.168.1.7:dumpspare.bin
    5. Done. This a session of restoring a backup

      CFE> eraseflash Do you really want to erase the NAND flash? (y/n):y ......................................................................................................................................................... ......................................................................................................................................................... ......................................................................................................................................................... ......................................................................................................................................................... ......................................................................................................................................................... ......................................................................................................................................................... .......................................................................................................... *** command status = 0 CFE> writeflash 192.168.1.7:dumpnand.bin arg0: 192.168.1.7:dumpnand.bin, arg1: (null), Block: 0 Reading FILE... .......................................................................................................................................................... .......................................................................................................................................................... .......................................................................................................................................................... .......................................................................................................................................................... .......................................................................................................................................................... .......................................................................................................................................................... ...................................................................................................- last block - . 134217728 Bytes writen in blocks 0 to 1023 *** command status = 0 CFE> writespare 192.168.1.7:dumpspare.bin Reading FILE... - last block - 4194304 bytes read from 192.168.1.7:dumpspare.bin 4194304 bytes written to NAND (spare area) *** command status = 0 CFE>


Credits to antares

USB mod

The board is ready to support an USB host port. We only need to solder a few components

  • F1: 0 ohm resistor
  • R166: 0 ohm resistor
  • R15, R13: 0 ~ 120 ohm resistor. Recommended: 22 ohm
  • Optional: C163, C155, C125, C118: ceramic capacitors with high capacity.

Bootlogs

OEM Bootlog

HELO CPUI L1CI DRAM ---- PHYS ZQDN 300H PHYE DINT LSYN USYN MSYN LMBE RACE PASS ---- ZBSS CODE DATA L12F MAIN RO08 SUN2 find flag find flag SUN6 000 000 000 000 RAM1 NAN3 RFS0 NAN5 CFE version 1.0.38-114.185 for BCM96328 (32bit,SP,BE) Build Date: 2013��� 08�.. 21�.� �..�..��. 11:42:59 CST (root@localhost) Copyright (C) 2000-2011 Broadcom Corporation. NAND flash device: name , id 0x92f1 block 128KB size 131072KB Chip ID: BCM6328B0, MIPS: 320MHz, DDR: 320MHz, Bus: 160MHz Main Thread: TP0 Memory Test Passed Total Memory: 134217728 bytes (128MB) Boot Address: 0xb8000000 find flag begin read flash map Board IP address : 192.168.1.1:ffffff00 Host IP address : 192.168.1.100 Gateway IP address : Run from flash/host (f/h) : f Default host run file name : vmlinux Default host flash file name : bcm963xx_fs_kernel Boot delay (0-9 seconds) : 1 Board Id (0-10) : 96328avngr Number of MAC Addresses (1-32) : 16 Base MAC Address : d4:21:22:89:e4:e4 PSI Size (1-64) KBytes : 24 Enable Backup PSI [0|1] : 0 System Log Size (0-256) KBytes : 0 Auxillary File System Size Percent: 0 Main Thread Number [0|1] : 0 Voice Board Configuration (0-7) : SI32176 SC_DEBUG: Nand Partition Table Magic Found at 20000. *** Press any key to stop auto run (1 seconds) *** Auto run second count down: 1 Port 1 link UP 0 *************************************************** Sercomm Boot Version 1.1.3.0 *************************************************** Entering Firmware : Everything is OK. begin check sum safe value is 255 check sum ok Booting from First image (0xb8520000) ... Decompression OK! Entry at 0x80310230 Closing network. Disabling Switch ports. Flushing Receive Buffers... 1 buffers found. Closing DMA Channels. Starting program at 0x80310230 Linux version 2.6.30 (sharon@localhost.localdomain) (gcc version 4.4.2 (Buildroot 2010.02-git) ) #1 Fri Nov 22 17:23:33 CST 2013 BCM Flash API. Flash device is not found. 96328avngr prom init CPU revision is: 0002a075 (Broadcom4350) DSL SDRAM reserved: 0x100000 Determined physical RAM map: memory: 07f00000 @ 00000000 (usable) Zone PFN ranges: DMA 0x00000000 -> 0x00001000 Normal 0x00001000 -> 0x00007f00 Movable zone start PFN for each node early_node_map[1] active PFN ranges 0: 0x00000000 -> 0x00007f00 On node 0 totalpages: 32512 free_area_init_node: node 0, pgdat 803e5200, node_mem_map 81000000 DMA zone: 32 pages used for memmap DMA zone: 0 pages reserved DMA zone: 4064 pages, LIFO batch:0 Normal zone: 222 pages used for memmap Normal zone: 28194 pages, LIFO batch:7 Built 1 zonelists in Zone order, mobility grouping on. Total pages: 32258 Kernel command line: root=mtd:rootfs rw rootfstype=jffs2 console=ttyS0,115200 wait instruction: enabled Primary instruction cache 32kB, VIPT, 4-way, linesize 16 bytes. Primary data cache 32kB, 2-way, VIPT, cache aliases, linesize 16 bytes NR_IRQS:128 PID hash table entries: 512 (order: 9, 2048 bytes) console [ttyS0] enabled Dentry cache hash table entries: 16384 (order: 4, 65536 bytes) Inode-cache hash table entries: 8192 (order: 3, 32768 bytes) Allocating memory for DSP module core and initialization code Allocated DSP module memory - CORE=0x0 SIZE=0, INIT=0x0 SIZE=0 Memory: 124300k/130048k available (3099k kernel code, 5568k reserved, 830k data, 136k init, 0k highmem) Calibrating delay loop... 319.48 BogoMIPS (lpj=159744) Mount-cache hash table entries: 512 --Kernel Config-- SMP=0 PREEMPT=0 DEBUG_SPINLOCK=0 DEBUG_MUTEXES=0 Broadcom Logger v0.1 Nov 22 2013 17:13:38 net_namespace: 816 bytes NET: Registered protocol family 16 Total Flash size: 0K with -1 sectors registering PCI controller with io_map_base unset registering PCI controller with io_map_base unset bio: create slab <bio-0> at 0 SCSI subsystem initialized usbcore: registered new interface driver usbfs usbcore: registered new interface driver hub usbcore: registered new device driver usb pci 0000:00:09.0: reg 10 32bit mmio: [0x10002600-0x100026ff] pci 0000:00:0a.0: reg 10 32bit mmio: [0x10002500-0x100025ff] pci 0000:01:00.0: PME# supported from D0 D3hot pci 0000:01:00.0: PME# disabled pci 0000:02:00.0: reg 10 64bit mmio: [0x000000-0x007fff] pci 0000:02:00.0: supports D1 D2 pci 0000:01:00.0: PCI bridge, secondary bus 0000:02 pci 0000:01:00.0: IO window: disabled pci 0000:01:00.0: MEM window: 0xa0000000-0xa00fffff pci 0000:01:00.0: PREFETCH window: disabled PCI: Enabling device 0000:01:00.0 (0000 -> 0002) PCI: Setting latency timer of device 0000:01:00.0 to 64 BLOG v3.0 Initialized BLOG Rule v1.0 Initialized Broadcom IQoS v0.1 Nov 22 2013 17:21:33 initialized NET: Registered protocol family 8 NET: Registered protocol family 20 NET: Registered protocol family 2 IP route cache hash table entries: 1024 (order: 0, 4096 bytes) TCP established hash table entries: 4096 (order: 3, 32768 bytes) TCP bind hash table entries: 4096 (order: 2, 16384 bytes) TCP: Hash tables configured (established 4096 bind 4096) TCP reno registered NET: Registered protocol family 1 NTFS driver 2.1.29 [Flags: R/W]. JFFS2 version 2.2. (NAND) �� 2001-2006 Red Hat, Inc. fuse init (API version 7.11) msgmni has been set to 243 io scheduler noop registered (default) pcieport-driver 0000:01:00.0: device [14e4:6328] has invalid IRQ; check vendor BIOS PCI: Setting latency timer of device 0000:01:00.0 to 64 Driver 'sd' needs updating - please use bus_type methods PPP generic driver version 2.4.2 PPP Deflate Compression module registered PPP BSD Compression module registered NET: Registered protocol family 24 bcm963xx_mtd driver v2.0 Failed to read image tag from flash Broadcom DSL NAND controller (BrcmNand Controller) -->brcmnand_scan: CS=0, numchips=1, csi=0 mtd->oobsize=0, mtd->eccOobSize=0 NAND_CS_NAND_XOR=00000000 Disabling XOR on CS#0 brcmnand_scan: Calling brcmnand_probe for CS=0 B4: NandSelect=40000001, nandConfig=15142200, chipSelect=0 brcmnand_read_id: CS0: dev_id=92f18095 After: NandSelect=40000001, nandConfig=15142200 DevId 92f18095 may not be supported. Will use config info Block size=00020000, erase shift=17 NAND Config: Reg=15142200, chipSize=128 MB, blockSize=128K, erase_shift=11 busWidth=1, pageSize=2048B, page_shift=11, page_mask=000007ff timing1 not adjusted: 5363444f timing2 not adjusted: 00000fc6 BrcmNAND mfg 0 0 UNSUPPORTED NAND CHIP 128MB on CS0 Found NAND on CS0: ACC=f3000000, cfg=15142200, flashId=92f18095, tim1=5363444f, tim2=00000fc6 BrcmNAND version = 0x0202 128MB @00000000 B4: NandSelect=40000001, nandConfig=15142200, chipSelect=0 brcmnand_read_id: CS0: dev_id=92f18095 After: NandSelect=40000001, nandConfig=15142200 Found NAND flash on Chip Select 0, chipSize=128MB, usable size=128MB, base=0 brcmnand_scan: Done brcmnand_probe brcmnand_scan: B4 nand_select = 40000001 brcmnand_scan: After nand_select = 40000001 brcmnand_scan 10 200 CS=0, chip->ctrl->CS[0]=0 200 chip->ecclevel=15, acc=f3000000 page_shift=11, bbt_erase_shift=17, chip_shift=27, phys_erase_shift=17 brcmnand_scan 220 Brcm NAND controller version = 2.2 NAND flash size 128MB @18000000 brcmnand_scan 230 brcmnand_scan 40, mtd->oobsize=64, chip->ecclayout=00000000 brcmnand_scan 42, mtd->oobsize=64, chip->ecclevel=15, isMLC=0, chip->cellinfo=0 ECC layout=brcmnand_oob_bch4_4k brcmnand_scan: mtd->oobsize=64 brcmnand_scan: oobavail=50, eccsize=512, writesize=2048 brcmnand_scan, eccsize=512, writesize=2048, eccsteps=4, ecclevel=15, eccbytes=3 300 CS=0, chip->ctrl->CS[0]=0 500 chip=879a7980, CS=0, chip->ctrl->CS[0]=0 -->brcmnand_default_bbt brcmnand_default_bbt: bbt_td = bbt_main_descr Bad block table Bbt0 found at page 0000ffc0, version 0x01 for chip on CS0 Bad block table 1tbB found at page 0000ff80, version 0x01 for chip on CS0 brcmnand_scan 99 ==> sc_setup_mtd_partitions [sc_setup_mtd_partitions] try read a page at offset = 0x20000 [sc_setup_mtd_partitions] read page OK at offset = 0x20000 mmap flag found on oft = 0x20000 [sc_setup_mtd_partitions] try read a page at offset = 0x20800 [sc_setup_mtd_partitions] read page OK at offset = 0x20800 =====> sc_set_running_rootfs bootflags 1 = eRcOmM.000bootflags 2 = eRcOmM.000set booting from kfs 1 <===== sc_set_running_rootfs <== sc_setup_mtd_partitions Creating 14 MTD partitions on "brcmnand.0": 0x000000000000-0x000000020000 : "cferom" 0x0000000c0000-0x000000200000 : "mmap" 0x000000200000-0x000000340000 : "cferam1" 0x000000020000-0x0000000c0000 : "cferam2" 0x000000340000-0x0000003e0000 : "serial" 0x0000003e0000-0x000000520000 : "protect" 0x000000520000-0x000002320000 : "rootfs" 0x000003720000-0x000005520000 : "rootfs_inactive" 0x000006920000-0x000006a60000 : "bootflag1" 0x000006a60000-0x000006ba0000 : "bootflag2" 0x000006ba0000-0x000006e20000 : "xml_cfg" 0x000006e20000-0x0000070a0000 : "app_dat" 0x000002320000-0x000003720000 : "kfs1_lib" 0x000005520000-0x000006920000 : "kfs2_lib" ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver PCI: Enabling device 0000:00:0a.0 (0000 -> 0002) PCI: Setting latency timer of device 0000:00:0a.0 to 64 ehci_hcd 0000:00:0a.0: EHCI Host Controller ehci_hcd 0000:00:0a.0: new USB bus registered, assigned bus number 1 ehci_hcd 0000:00:0a.0: Enabling legacy PCI PM ehci_hcd 0000:00:0a.0: irq 50, io mem 0x10002500 ehci_hcd 0000:00:0a.0: USB f.f started, EHCI 1.00 usb usb1: configuration #1 chosen from 1 choice hub 1-0:1.0: USB hub found hub 1-0:1.0: 1 port detected ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver PCI: Enabling device 0000:00:09.0 (0000 -> 0002) PCI: Setting latency timer of device 0000:00:09.0 to 64 ohci_hcd 0000:00:09.0: OHCI Host Controller ohci_hcd 0000:00:09.0: new USB bus registered, assigned bus number 2 ohci_hcd 0000:00:09.0: irq 49, io mem 0x10002600 usb usb2: configuration #1 chosen from 1 choice hub 2-0:1.0: USB hub found hub 2-0:1.0: 1 port detected usbcore: registered new interface driver usblp Initializing USB Mass Storage driver... usbcore: registered new interface driver usb-storage USB Mass Storage support registered. brcmboard: brcm_board_init entry SES: Button Interrupt 0x1 is enabled sesBtn_mapIntr: is_sesBtn_irq_shared=0, sesBtn_irq=1 Serial: BCM63XX driver $Revision: 3.00 $ ttyS0 at MMIO 0xb0000100 (irq = 36) is a BCM63XX ttyS1 at MMIO 0xb0000120 (irq = 47) is a BCM63XX bcmPktDmaBds_init: Broadcom Packet DMA BDs initialized bcmxtmrt: Broadcom BCM6328B0 ATM/PTM Network Device v0.3 Nov 22 2013 17:20:25 GACT probability NOT on Mirror/redirect action on u32 classifier input device check on Actions configured Netfilter messages via NETLINK v0.30. nf_conntrack version 0.5.0 (2032 buckets, 8128 max) nf_nat_pt: no ports specified ip_tables: (C) 2000-2006 Netfilter Core Team TCP cubic registered Initializing XFRM netlink socket NET: Registered protocol family 17 NET: Registered protocol family 15 Ebtables v2.0 registered ebt_time registered ebt_ftos registered ebt_wmm_mark registered 802.1Q VLAN Support v1.8 Ben Greear <greearb@candelatech.com> All bugs added by David S. Miller <davem@redhat.com> Empty flash at 0x01a1084c ends at 0x01a11000 Empty flash at 0x01a12218 ends at 0x01a12800 Empty flash at 0x01a13b64 ends at 0x01a14000 VFS: Mounted root (jffs2 filesystem) on device 31:6. Freeing unused kernel memory: 136k freed init started: BusyBox v1.15.3 () starting pid 241, tty '': '/etc/rcS' Empty flash at 0x00041598 ends at 0x00041800 Empty flash at 0x00047178 ends at 0x00047800 Empty flash at 0x0004d178 ends at 0x0004d800 Empty flash at 0x00053178 ends at 0x00053800 Empty flash at 0x00104b40 ends at 0x00105000 JFFS2 notice: (269) check_node_data: wrong data CRC in data node at 0x000589c4: read 0xba0378ce, calculated 0x4d0e34a9. JFFS2 notice: (269) check_node_data: wrong data CRC in data node at 0x000529c4: read 0xba0378ce, calculated 0x4d0e34a9. bcm_ingqos: module license 'Proprietary' taints kernel. Broadcom Ingress QoS Module Char Driver v0.1 Nov 22 2013 17:19:48 Registered<243> Broadcom Ingress QoS ver 0.1 initialized JFFS2 notice: (269) check_node_data: wrong data CRC in data node at 0x0004c9c4: read 0xba0378ce, calculated 0x4d0e34a9. pktflow: module license 'Proprietary' taints kernel. NBUFF v1.0 Initialized Initialized fcache state Broadcom Packet Flow Cache Char Driver v2.2 Nov 22 2013 17:19:48 Registered<242> Created Proc FS /procfs/fcache Broadcom Packet Flow Cache registered with netdev chain Broadcom Packet Flow Cache learning via BLOG enabled. Constructed Broadcom Packet Flow Cache v2.2 Nov 22 2013 17:19:48 JFFS2 notice: (269) check_node_data: wrong data CRC in data node at 0x000469c4: read 0xba0378ce, calculated 0x4d0e34a9. bcmxtmcfg: module license 'Proprietary' taints kernel. JFFS2 notice: (269) check_node_data: wrong data CRC in data node at 0x00040df8: read 0x80a95ec1, calculated 0xac95fdaa. bcmxtmcfg: bcmxtmcfg_init entry adsldd: module license 'Proprietary' taints kernel. adsl: adsl_init entry Broadcom BCM6328B0 Ethernet Network Device v0.1 Nov 22 2013 17:20:14 ETH Init: Ch:0 - 200 tx BDs at 0xa7a90000 ETH Init: Ch:0 - 600 rx BDs at 0xa70f8000 dgasp: kerSysRegisterDyingGaspHandler: bcmsw registered eth0: MAC Address: D4:21:22:89:E4:E4 eth1: MAC Address: D4:21:22:89:E4:E4 eth2: MAC Address: D4:21:22:89:E4:E4 eth3: MAC Address: D4:21:22:89:E4:E4 bcmarl: module license 'Proprietary' taints kernel. [NTC arl] arlEnable : Enabled ARL binding to Flow Cache Broadcom Address Resolution Logic Processor (ARL) Char Driver v0.1 Nov 22 2013 17:17:22 Registered <245> bcmvlan: module license 'Proprietary' taints kernel. Broadcom 802.1Q VLAN Interface, v0.1 pwrmngtd: module license 'Proprietary' taints kernel. endpointdd: module license 'Proprietary' taints kernel. Endpoint: endpoint_init entry Endpoint: endpoint_init COMPLETED Success Success Success Success Success sc_drv: module license 'Sercomm' taints kernel. Note: Loading 6300 MDK (default) driver for 6328 chip Switch MDK: num_switches = 1 Switch MDK: unit = 0; phy_pbmp = 0xf; config_pbmp = 0xf Switch MDK link poll thread: unit=0; phypbmp=0xf Host MIPS Clock divider pwrsaving is enabled DDR Self Refresh pwrsaving is enabled AD1018_SERCOMM_VFES_2008 [LAN] LAN3 Link UP 100 mbps full duplex eth1 (switch port: 1) Link UP 100 mbps full duplex message received before monitor task is initialized kerSysSendtoMonitorTask ap_name=syslogd, action=start ap_name=coredump, action=start ap_name=dnrd, action=start ap_name=phy, action=start ap_name=lanip, action=start ap_name=firewall, action=start ap_name=telnetd, action=start ap_name=httpd, action=start ap_name=redirect, action=start socket: Address family not supported by protocol ap_name=dnrd, action=start ap_name=networkmap, action=start ap_name=srt, action=restart ap_name=rp, action=start ap_name=ntp, action=start ap_name=wlan, action=start ap_name=ingress_qos, action=start ap_name=ingress_classify, action=start ap_name=qos, action=start ap_name=qos_cls, action=start Success Success ap_name=qos_remark, action=start Setting SSID: "WLAN_87" ap_name=cpm, action=start ap_name=wanip, action=stop /bin/wlctl: Unsupported ap_name=redirect, action=start ap_name=dnrd, action=start ap_name=wanip, action=stop ap_name=igd_upnp, action=start ap_name=dnsr, action=start invalid option in file /tmp/miniupnpd.0.conf line 5 : lan_netmask=255.255.255.0 invalid option in file /tmp/miniupnpd.0.conf line 9 : upc=Vodafone Entry Level Router invalid option in file /tmp/miniupnpd.0.conf line 10 : sn=E1408AQS113081 invalid option in file /tmp/miniupnpd.0.conf line 11 : nat=1 invalid option in file /tmp/miniupnpd.0.conf line 23 : wan_type=ppp ap_name=cron, action=start ap_name=snmp, action=start 7200 sec killall: wps_det: no process killed starting pid 1250, tty '': '/sbin/getty ttyS0 115200' ad1018 login:


OpenWrt Bootlog

HELO CPUI L1CI DRAM ---- PHYS ZQDN PHYE DINT LSYN USYN MSYN LMBE PASS ---- ZBSS CODE DATA L12F MAIN CFE version 2.0.3 for BCM63XX (32bit,SP,BE) Build Date: Fri Aug 18 14:21:52 CEST 2017 (dani@tool) Copyright (C) 2000-2009 Broadcom Corporation. HS Serial flash device: name ID_W25X64, id 0xef17 size 8192KB Total Flash size: 8192K with 2048 sectors Chip ID: BCM6328B0, MIPS: 320MHz, DDR: 320MHz, Bus: 160MHz Main Thread: TP0 Memory Test Passed Total Memory: 134217728 bytes (128MB) Boot Address: 0xb8000000 Board IP address : 192.168.1.1:ffffff00 Host IP address : 192.168.1.100 Gateway IP address : Run from flash/host (f/h) : f Default host run file name : vmlinux Default host flash file name : bcm963xx_fs_kernel Boot delay (0-9 seconds) : 1 Board Id (0-3) : 96328avngr Number of MAC Addresses (1-32) : 10 Base MAC Address : 00:11:22:33:44:55 PSI Size (1-64) KBytes : 24 Enable Backup PSI [0|1] : 0 System Log Size (0-256) KBytes : 0 Main Thread Number [0|1] : 0 Voice Board Configuration (0-11) : *** Press any key to stop auto run (1 seconds) *** Auto run second count down: 0 Booting from only image (0xb8010000) ... Code Address: 0x80A00000, Entry Address: 0x80a00000 LZMA: Prossible old LZMA format, trying to decompress.. Decompression OK! Entry at 0x80a00000 Closing network. Disabling Switch ports. Flushing Receive Buffers... 0 buffers found. Closing DMA Channels. Starting program at 0x80a00000 [ 0.000000] Linux version 4.4.79 (dani@tool) (gcc version 5.4.0 (LEDE GCC 5.4.0 r4696-df3295f) ) #0 Sat Aug 12 10:28:44 2017 [ 0.000000] Detected Broadcom 0x6328 CPU revision b0 [ 0.000000] CPU frequency is 320 MHz [ 0.000000] 128MB of RAM installed [ 0.000000] board_bcm963xx: Boot address 0xb8000000 [ 0.000000] board_bcm963xx: CFE version: 1.0.37-106.24 [ 0.000000] bootconsole [early0] enabled [ 0.000000] CPU0 revision is: 0002a075 (Broadcom BMIPS4350) [ 0.000000] board: board name: 96328avngr [ 0.000000] MIPS: machine is Sercomm AD1018 [ 0.000000] Determined physical RAM map: [ 0.000000] memory: 08000000 @ 00000000 (usable) [ 0.000000] Initrd not found or empty - disabling initrd [ 0.000000] Zone ranges: [ 0.000000] Normal [mem 0x0000000000000000-0x0000000007ffffff] [ 0.000000] Movable zone start for each node [ 0.000000] Early memory node ranges [ 0.000000] node 0: [mem 0x0000000000000000-0x0000000007ffffff] [ 0.000000] Initmem setup node 0 [mem 0x0000000000000000-0x0000000007ffffff] [ 0.000000] Primary instruction cache 32kB, VIPT, 4-way, linesize 16 bytes. [ 0.000000] Primary data cache 32kB, 2-way, VIPT, cache aliases, linesize 16 bytes [ 0.000000] Built 1 zonelists in Zone order, mobility grouping on. Total pages: 32512 [ 0.000000] Kernel command line: root=/dev/mtdblock2 rootfstype=squashfs,jffs2 noinitrd console=ttyS0,115200 [ 0.000000] PID hash table entries: 512 (order: -1, 2048 bytes) [ 0.000000] Dentry cache hash table entries: 16384 (order: 4, 65536 bytes) [ 0.000000] Inode-cache hash table entries: 8192 (order: 3, 32768 bytes) [ 0.000000] Memory: 124292K/131072K available (3103K kernel code, 154K rwdata, 788K rodata, 1260K init, 197K bss, 6780K reserved, 0K cma) [ 0.000000] SLUB: HWalign=16, Order=0-3, MinObjects=0, CPUs=1, Nodes=1 [ 0.000000] NR_IRQS:256 [ 0.000000] clocksource: MIPS: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 11945377789 ns [ 0.000018] sched_clock: 32 bits at 160MHz, resolution 6ns, wraps every 13421772796ns [ 0.008097] Calibrating delay loop... 319.74 BogoMIPS (lpj=639488) [ 0.046774] pid_max: default: 32768 minimum: 301 [ 0.051827] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes) [ 0.058632] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes) [ 0.075524] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns [ 0.085611] futex hash table entries: 256 (order: -1, 3072 bytes) [ 0.092218] pinctrl core: initialized pinctrl subsystem [ 0.099337] NET: Registered protocol family 16 [ 0.349434] registering PCI controller with io_map_base unset [ 0.374569] PCI host bridge to bus 0000:00 [ 0.378837] pci_bus 0000:00: root bus resource [mem 0x10f00000-0x10ffffff] [ 0.385906] pci_bus 0000:00: root bus resource [??? 0x00000000 flags 0x0] [ 0.392888] pci_bus 0000:00: root bus resource [??? 0x00000000 flags 0x0] [ 0.399874] pci_bus 0000:00: No busn resource found for root bus, will use [bus 00-ff] [ 0.408748] pci 0000:00:00.0: bridge configuration invalid ([bus 00-00]), reconfiguring [ 0.418279] pci 0000:00:00.0: BAR 8: assigned [mem 0x10f00000-0x10ffffff] [ 0.425315] pci 0000:01:00.0: BAR 0: assigned [mem 0x10f00000-0x10f07fff 64bit] [ 0.432851] pci 0000:00:00.0: PCI bridge to [bus 01] [ 0.437948] pci 0000:00:00.0: bridge window [mem 0x10f00000-0x10ffffff] [ 0.446648] clocksource: Switched to clocksource MIPS [ 0.455727] NET: Registered protocol family 2 [ 0.462098] TCP established hash table entries: 1024 (order: 0, 4096 bytes) [ 0.469395] TCP bind hash table entries: 1024 (order: 0, 4096 bytes) [ 0.475993] TCP: Hash tables configured (established 1024 bind 1024) [ 0.483024] UDP hash table entries: 256 (order: 0, 4096 bytes) [ 0.489112] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes) [ 0.496147] NET: Registered protocol family 1 [ 0.512647] Crashlog allocated RAM at address 0x3f00000 [ 0.554931] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 0.560958] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc. [ 0.577718] io scheduler noop registered [ 0.581801] io scheduler deadline registered (default) [ 0.588395] bcm6328-pinctrl 10000080.pin-controller: registered at mmio b0000080 [ 0.597841] PCI: Enabling device 0000:00:00.0 (0000 -> 0002) [ 0.604678] bcm63xx_uart.0: ttyS0 at MMIO 0xb0000100 (irq = 36, base_baud = 1562500) is a bcm63xx_uart [ 0.614343] console [ttyS0] enabled [ 0.614343] console [ttyS0] enabled [ 0.621503] bootconsole [early0] disabled [ 0.621503] bootconsole [early0] disabled [ 0.643012] m25p80 spi1.0: s25fl064k (8192 Kbytes) [ 0.648489] bcm63xxpart: CFE boot tag found with version 6 and board type 96328avngr [ 0.656570] bcm63xxpart: Partition 0 is CFE offset 0 and length 10000 [ 0.663217] bcm63xxpart: Partition 1 is kernel offset 10100 and length 14728c [ 0.670539] bcm63xxpart: Partition 2 is rootfs offset 15738c and length 698c74 [ 0.677977] bcm63xxpart: Partition 3 is nvram offset 7f0000 and length 10000 [ 0.685232] bcm63xxpart: Partition 4 is linux offset 10000 and length 7e0000 [ 0.692488] 5 bcm63xxpart partitions found on MTD device spi1.0 [ 0.698578] Creating 5 MTD partitions on "spi1.0": [ 0.703526] 0x000000000000-0x000000010000 : "CFE" [ 0.711611] 0x000000010100-0x00000015738c : "kernel" [ 0.720400] 0x00000015738c-0x0000007f0000 : "rootfs" [ 0.729183] mtd: device 2 (rootfs) set to be root filesystem [ 0.735932] 1 squashfs-split partitions found on MTD device rootfs [ 0.742333] 0x0000003b0000-0x0000007f0000 : "rootfs_data" [ 0.750920] 0x0000007f0000-0x000000800000 : "nvram" [ 0.759651] 0x000000010000-0x0000007f0000 : "linux" [ 0.808016] b53_common: found switch: BCM63xx, rev 0 [ 0.813740] bcm63xx-wdt bcm63xx-wdt: started, timer margin: 30 sec [ 0.824047] PCI: Enabling device 0000:01:00.0 (0000 -> 0002) [ 0.829957] bcma: bus0: Found chip with id 43217, rev 0x01 and package 0x09 [ 0.837197] bcma: bus0: Core 0 found: ChipCommon (manuf 0x4BF, id 0x800, rev 0x27, class 0x0) [ 0.846026] bcma: bus0: Core 1 found: IEEE 802.11 (manuf 0x4BF, id 0x812, rev 0x1E, class 0x0) [ 0.854950] bcma: bus0: Core 2 found: PCIe (manuf 0x4BF, id 0x820, rev 0x14, class 0x0) [ 0.877004] bcma: bus0: Bus registered [ 0.884047] NET: Registered protocol family 10 [ 0.895366] NET: Registered protocol family 17 [ 0.900122] bridge: automatic filtering via arp/ip/ip6tables has been deprecated. Update your scripts to load br_netfilter if you need t. [ 0.913155] 8021q: 802.1Q VLAN Support v1.8 [ 0.929287] VFS: Mounted root (squashfs filesystem) readonly on device 31:2. [ 0.953695] Freeing unused kernel memory: 1260K (80405000 - 80540000) [ 2.803375] init: Console is alive [ 2.807251] init: - watchdog - [ 4.340367] kmodloader: loading kernel modules from /etc/modules-boot.d/* [ 4.498618] usbcore: registered new interface driver usbfs [ 4.504584] usbcore: registered new interface driver hub [ 4.510280] usbcore: registered new device driver usb [ 4.530875] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver [ 4.540791] ehci-platform: EHCI generic platform driver [ 4.646704] ehci-platform ehci-platform: EHCI Host Controller [ 4.652703] ehci-platform ehci-platform: new USB bus registered, assigned bus number 1 [ 4.661230] ehci-platform ehci-platform: irq 50, io mem 0xb0002500 [ 4.678698] ehci-platform ehci-platform: USB 2.0 started, EHCI 1.00, overcurrent ignored [ 4.689005] hub 1-0:1.0: USB hub found [ 4.693530] hub 1-0:1.0: 1 port detected [ 4.705470] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver [ 4.714888] ohci-platform: OHCI generic platform driver [ 4.720553] ohci-platform ohci-platform: Generic Platform OHCI controller [ 4.727632] ohci-platform ohci-platform: new USB bus registered, assigned bus number 2 [ 4.735956] ohci-platform ohci-platform: irq 49, io mem 0xb0002600 [ 4.800724] hub 2-0:1.0: USB hub found [ 4.805357] hub 2-0:1.0: 1 port detected [ 4.811151] kmodloader: done loading kernel modules from /etc/modules-boot.d/* [ 4.829239] init: - preinit - [ 6.301787] random: jshn: uninitialized urandom read (4 bytes read, 122 bits of entropy available) [ 6.541675] random: jshn: uninitialized urandom read (4 bytes read, 123 bits of entropy available) [ 6.781565] random: jshn: uninitialized urandom read (4 bytes read, 124 bits of entropy available) [ 6.876570] random: jshn: uninitialized urandom read (4 bytes read, 124 bits of entropy available) [ 7.009481] random: jshn: uninitialized urandom read (4 bytes read, 125 bits of entropy available) [ 7.176428] random: nonblocking pool is initialized [ 7.567052] bcm63xx_enetsw bcm63xx_enetsw.0: link UP on LAN3, 100Mbps, full-duplex Press the [f] key and hit [enter] to enter failsafe mode Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level [ 10.141272] jffs2: notice: (359) jffs2_build_xattr_subsystem: complete building xattr subsystem, 0 of xdatum (0 unchecked, 0 orphan) and. [ 10.161341] mount_root: switching to jffs2 overlay [ 10.210925] urandom-seed: Seeding with /etc/urandom.seed [ 10.458491] procd: - early - [ 10.461668] procd: - watchdog - [ 11.202354] procd: - watchdog - [ 11.206090] procd: - ubus - [ 11.491034] procd: - init - Please press Enter to activate this console. [ 12.245029] kmodloader: loading kernel modules from /etc/modules.d/* [ 12.380204] ip6_tables: (C) 2000-2006 Netfilter Core Team [ 12.413432] Loading modules backported from Linux version wt-2017-01-31-0-ge882dff19e7f [ 12.421716] Backport generated by backports.git backports-20160324-13-g24da7d3c [ 12.435705] ip_tables: (C) 2000-2006 Netfilter Core Team [ 12.461186] nf_conntrack version 0.5.0 (1961 buckets, 7844 max) [ 12.568698] xt_time: kernel timezone is -0000 [ 12.724369] PPP generic driver version 2.4.2 [ 12.734097] NET: Registered protocol family 24 [ 12.784918] b43-phy0: Broadcom 43217 WLAN found (core revision 30) [ 12.792210] b43-phy0: Found PHY: Analog 9, Type 4 (N), Revision 17 [ 12.798608] b43-phy0: Found Radio: Manuf 0x17F, ID 0x2057, Revision 14, Version 0 [ 12.807260] Broadcom 43xx driver loaded [ Features: PNL ] [ 12.964342] kmodloader: done loading kernel modules from /etc/modules.d/* [ 26.263810] bcm63xx_enetsw bcm63xx_enetsw.0: link UP on LAN3, 100Mbps, full-duplex [ 26.292015] device eth0.1 entered promiscuous mode [ 26.296975] device eth0 entered promiscuous mode [ 26.316996] br-lan: port 1(eth0.1) entered forwarding state [ 26.322820] br-lan: port 1(eth0.1) entered forwarding state [ 28.326665] br-lan: port 1(eth0.1) entered forwarding state BusyBox v1.26.2 () built-in shell (ash) _________ / /\ _ ___ ___ ___ / LE / \ | | | __| \| __| / DE / \ | |__| _|| |) | _| /________/ LE \ |____|___|___/|___| lede-project.org \ \ DE / \ LE \ / ----------------------------------------------------------- \ DE \ / Reboot (SNAPSHOT, r4696+1-df3295f) \________\/ ----------------------------------------------------------- === WARNING! ====]���������������j There is no root password defined on this device! Use the "passwd" command to set up a new password in order to prevent unauthorized SSH logins. -------------------------------------------------- root@LEDE:/#


Tags

toh/sercomm/ad1018.txt · Last modified: 2018/11/18 09:53 by danitool