Dahua IPC unbricking / recovery over serial UART and TFTP

erdilmen

n3wb
Joined
Feb 27, 2023
Messages
7
Reaction score
0
Location
Cyprus
nvt@na51090: setenv serverpip 192.168.31.141
serverpip=192.168.31.141
nvt@na51090: setenv ipaddr 192.168.31.201
ipaddr=192.168.31.201
nvt@na51090: setenv gateway 192.168.31.1
gateway=192.168.31.1
nvt@na51090: printenv
Unknown command 'printenv' - try 'help'
nvt@na51090: print env
Unknown command 'print' - try 'help'
nvt@na51090: saveenv
Saving Environment to NAND... Erasing NAND...
Erasing at 0x320000 -- 100% complete.
Writing to NAND... OK
Erasing at 0x340000 -- 100% complete.
Erasing at 0x3c0000 -- 100% complete.
OK
nvt@na51090: run da
Using eth0 device
TFTP from server 192.168.31.141; our IP address is 192.168.31.201
Filename 'u-boot.bin.img'.
timeout_count up to 10
Load address: 0x7800000
Loading: T T T T T T T T T T
Retry count exceeded; starting again
connect frondboard!
 

erdilmen

n3wb
Joined
Feb 27, 2023
Messages
7
Reaction score
0
Location
Cyprus
my pc ands server ip 192.168.31.141
default gateway is 192.168.31.1
im defining xvr as 192.168.31.201
xvr connected router via cable
laptop connected same router via wifi
 

Erik2b1

n3wb
Joined
Apr 22, 2019
Messages
15
Reaction score
0
Location
holland
I have a SD22404T-GN that is not accessible. With wireshark i see that it's advertising on the network but the easy Tftp solution is not working.

I have ordered a usb ttl dongle so i can try the uart solution.

1 part of the instructions is not clear for me.
do i need to connect all pins to the camera? so VCC, GND, TX, RX or only RX and TX?
 

Erik2b1

n3wb
Joined
Apr 22, 2019
Messages
15
Reaction score
0
Location
holland
Thanks, Will do that.

As soon as the adapter is in i will give it a go again (no luck with a RPi, but that could be a linux noob thing ;-) )
 

qubit

n3wb
Joined
Aug 16, 2022
Messages
1
Reaction score
0
Location
Estonia
Please help,
three SD22404T-GN cameras suddenly stopped working, looks like they stuck in boot loop.
I connected CP210X dongle and tried to restore firmware, but it does not allow me to stop the autoboot and im not able to type anything.
any suggestions. tnx


U-Boot 2010.06-svn5213 (Apr 04 2018 - 09:21:28)
I2C: ready
DRAM: 198 MiB
gBootLogPtr:00b80008.
NAND: 128 MiB
amb_nand_read_oob read page:49152 err
partition file version 2
rootfstype squashfs root /dev/mtdblock8
fail to load bootargsParametersV22.txt
fail to load bootargsParametersV21.txt
fail to init bootargsParametersV2
TEXT_BASE:01000000
Net: Detected MACID:38:af:29:35:8c:33
PHY:0x001cc816,addr:0x00
s3l phy RTL8201 init

partition file version 2
rootfstype squashfs root /dev/mtdblock8
Using ambarella mac device
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending throu gh gateway 192.168.1.1
Download Filename 'upgrade_info_7db780a713a4.txt'.
Download to address: 0x5000000
Downloading: *
Retry count exceeded; starting again
SD Product try auto upgrade times.
SD try times:1
Using ambarella mac device
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending throu gh gateway 192.168.1.1
Download Filename 'upgrade_info_7db780a713a4.txt'.
Download to address: 0x5000000
Downloading: *
Retry count exceeded; starting again
string value is 0
AUF_getValidLine, the end of file
Failed to get a Line;Crc check error!
PreProcess data error!
Init error!
Using ambarella mac device
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending throu gh gateway 192.168.1.1
Download Filename 'failed.txt'.
Download to address: 0x2000000
Downloading: *
Retry count exceeded; starting again
Support backupVer:255
state:ff,err_count:04

NAND read: device 0 offset 0x60000, size 0x00010000
65536 bytes read: OK
## Booting kernel from Legacy Image at 02000000 ...
Image Name: Linux-3.10.73
Created: 2018-04-04 0:27:13 UTC
Image Type: ARM Linux Kernel Image (uncompressed)
Data Size: 1636644 Bytes = 1.6 MiB
Load Address: 00208000
Entry Point: 00208000
Verifying Checksum ... OK
Loading Kernel Image ...OK
OK
partition file version 2
rootfstype squashfs root /dev/mtdblock8
fail to load bootargsParameters.txt
fail to load bootargsParameters.txt file
get bootargs info failed
cmdLine console=ttyS0,115200 mem=150M root=/dev/mtdblock8 rootfstype=squashfs in it=/linuxrc
crashflasg:1, logmagic:54410011.

Starting kernel ...

backupbst magic err

managed to flash it with UART USB , its not rebooting any more and im able to access the web interface now.

firmware used : DH_SD-Mao-Rhea_Eng_P_Stream3_IVS_V2.622.0000000.7.R.180404.bin

this error still present in PuTTY, but camera is working
fail to load bootargsParameters.txt
fail to load bootargsParameters.txt file
get bootargs info failed
cmdLine console=ttyS0,115200 mem=150M root=/dev/mtdblock8 rootfstype=squashfs in it=/linuxrc
crashflasg:1, logmagic:54410011.

Starting kernel ...

backupbst magic err
 
Last edited:

boxy

n3wb
Joined
Oct 3, 2023
Messages
1
Reaction score
0
Location
asd
U-Boot 2010.06-svn2134 (May 26 2014 - 16:15:03)
DRAM: 256 MiB
Check spi flash controller v350... Found
Spi(cs1) ID: 0xEF 0x40 0x18 0x00 0x00 0x00
reset/hold pin now is RESET
Spi(cs1): Block:64KB Chip:16MB Name:"W25Q128B"
boot from spi
partition file version 2
rootfstype squashfs root /dev/mtdblock7
In: serial
Out: serial
Err: serial
TEXT_BASE:81000000
Hisilicon ETH net controler
MAC: 14-07-08-09-81-F5
UP_PORT : phy status change : LINK=UP : DUPLEX=FULL : SPEED=100M
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending throu gh gateway 192.168.1.1
Download Filename 'upgrade_info_7db780a713a4.txt'.
Download to address: 0x84000000
Downloading: *
Retry count exceeded; starting again
Fail to get info file!
Init error!
Hisilicon ETH net controler
miiphy_register: non unique device name '0:1'
miiphy_register: non unique device name '0:2'
MAC: 14-07-08-09-81-F5
UP_PORT : phy status change : LINK=DOWN : DUPLEX=FULL : SPEED=100M
UP_PORT : phy status change : LINK=UP : DUPLEX=FULL : SPEED=100M
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending through gateway 192.168.1.1
Download Filename 'failed.txt'.
Download to address: 0x82000000
Downloading: *
Retry count exceeded; starting again
SPI probe: 16384 KiB hi_sfc at 0:0 is now current device
## Booting kernel from Legacy Image at 82000000 ...
Image Name: Linux-3.0.8
Image Type: ARM Linux Kernel Image (uncompressed)
Data Size: 1337924 Bytes = 1.3 MiB
Load Address: 80008000
Entry Point: 80008000
Loading Kernel Image ...OK
OK
partition file version 2
rootfstype squashfs root /dev/mtdblock7
cmdLine mem=85M console=ttyS0,115200 root=/dev/mtdblock7 rootfstype=squashfs
crashflasg:1, logmagic:54410011.

Starting kernel ...
Uncompressing Linux... done, booting the kernel.


U-Boot 2010.06-svn2134 (May 26 2014 - 16:15:03)
DRAM: 256 MiB
Check spi flash controller v350... Found
Spi(cs1) ID: 0xEF 0x40 0x18 0x00 0x00 0x00
reset/hold pin now is RESET
Spi(cs1): Block:64KB Chip:16MB Name:"W25Q128B"
boot from spi
partition file version 2
rootfstype squashfs root /dev/mtdblock7
In: serial
Out: serial
Err: serial
TEXT_BASE:81000000
Hisilicon ETH net controler
MAC: 14-07-08-09-81-F5
UP_PORT : phy status change : LINK=DOWN : DUPLEX=FULL : SPEED=100M
UP_PORT : phy status change : LINK=UP : DUPLEX=FULL : SPEED=100M
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending through gateway 192.168.1.1
Download Filename 'upgrade_info_7db780a713a4.txt'.
Download to address: 0x84000000
Downloading: #################################################
done
Bytes transferred = 202 (ca hex)
Hisilicon ETH net controler
miiphy_register: non unique device name '0:1'
miiphy_register: non unique device name '0:2'
MAC: 14-07-08-09-81-F5
UP_PORT : phy status change : LINK=DOWN : DUPLEX=FULL : SPEED=100M
UP_PORT : phy status change : LINK=UP : DUPLEX=FULL : SPEED=100M
TFTP from server 192.168.254.254; our IP address is 192.168.1.108; sending through gateway 192.168.1.1
Download Filename 'romfs-x.squashfs.img'.
Download to address: 0x82000000
Downloading: #################################################
done
Bytes transferred = 737344 (b4040 hex)

## Checking Image at 82000000 ...
Legacy image found
Image Name: romfs
Image Type: ARM Linux Standalone Program (gzip compressed)
Data Size: 737280 Bytes = 720 KiB
Load Address: 00500000
Entry Point: 006a0000
Verifying Checksum ... OK
Programing start at: 0x00500000
SPI probe: 16384 KiB hi_sfc at 0:0 is now current device
write : 100%
done


The camera does this again and again.

i took the eeprom out and flashed it with a programmer out of good camera still its doing this loop
 

CChr

n3wb
Joined
Nov 23, 2016
Messages
3
Reaction score
0
I've done a Firmware Update to my
Dahua IPC-HUM8230P
I don't know if I took the the right firmware I'm not sure,

Since I've updatet I coudn't do any changes in the configuration.
The Cam does a reboot then.
It does also a reboot every 5 to 10 minutes.
So far I've confiigures a serial connection with a ft232rl usb to seriel conector and aftr many tries I got a connection.
I changed ip address and run a tftp server and could load files down but I got this message
Code:
>run dr
Using ambarella mac device
Download Filename 'romfs-x.squashfs.img'.
Downloading: #################################################################
         #################################################################
         #################################################################
         ###############################################################
  ## file size: 0 Bytes,        times: 3s,      speed: 358.4 KiB/s
done
Bytes transferred = 1310784 (140040 hex)
[ERR0002:]The img header be changed!
I've googeled the message and found this:
Dahua IPC EASY unbricking / recovery over TFTP
I think the problem is that the new firmware installed a new bootloader that doesn't allow firmwaredowngrades.
Please tell me how do I et the older firmware to my cam
To anyone that get the error message "[ERR0002:]The img header be changed!" the problem is that you have to flash first the kernel.img otherwise the camera will ignore anything you put in the commands.txt

Here is my commands.txt for the IPC-HDBW5231E-Z

"tftp 0x82000000 kernel.img; flwrite tftp 0x82000000 romfs-x.squashfs.img; flwrite tftp 0x82000000 web-x.squashfs.img; flwrite tftp 0x82000000 .FLASHING_DONE_STOP_TFTP_NOW sleep 5"
the latest files you need are inside the fw zip file with name DH_IPC-HX5X3X-Rhea_MultiLang_PN_Stream3_V2.800.0000029.0.R.221220.zip
 

timoxa

n3wb
Joined
Jan 28, 2024
Messages
1
Reaction score
0
Location
sa
good day! I have a dh-ipc-hdw2231 camera.
I connected to it but I can't download the firmware. the commands described at the beginning are not suitable, and the output of "printenv" has a different appearance

SigmaStar # printenv
printenv
baudrate=115200
bootargs=mem=130840K console=ttyS0,115200 LX_MEM=0x7fc6000 mma_heap=mma_heap_name0,miu=0,sz=0x4000000 rootfstype=ramfs mtdparts=nand0:1536K(boot),512K(tech),5120K(kernel),16384K(app),-(config) hw_type=2011
bootcmd=nand read 0x22000000 0x200000 0x500000; bootm 0x22000000; setenv bootargs $(bootargs) bkp=1; nand read 0x22000000 0x700000 0x500000; bootm 0x22000000
bootdelay=0
ethact=sstar_emac
ethaddr=00:30:1b:ba:02:db
gatewayip=192.168.2.1
ipaddr=192.168.2.2
netmask=255.255.255.0
preboot=gpio output 12 1;gpio output 13 1;gpio output 52 0;gpio output 6 1;gpio output 7 1;gpio output 6 0; ; fwupdate mmc 0:1 firmware.bin --enable-legacy-fw --with-props
serverip=192.168.2.1
stderr=serial
stdin=serial
stdout=serial
usb_folder=images

Environment size: 782/131068 bytes
SigmaStar #
baudrate=115200
bootargs=mem=130840K console=ttyS0,115200 LX_MEM=0x7fc6000 mma_heap=mma_heap_name0,miu=0,sz=0x4000000 rootfstype=ramfs mtdparts=nand0:1536K(boot),512K(tech),5120K(kernel),16384K(app),-(config) hw_type=2011
bootcmd=nand read 0x22000000 0x200000 0x500000; bootm 0x22000000; setenv bootargs $(bootargs) bkp=1; nand read 0x22000000 0x700000 0x500000; bootm 0x22000000
bootdelay=0
ethact=sstar_emac
ethaddr=00:30:1b:ba:02:db
gatewayip=192.168.2.1
ipaddr=192.168.2.2
netmask=255.255.255.0
preboot=gpio output 12 1;gpio output 13 1;gpio output 52 0;gpio output 6 1;gpio output 7 1;gpio output 6 0; ; fwupdate mmc 0:1 firmware.bin --enable-legacy-fw --with-props
serverip=192.168.2.1
stderr=serial
stdin=serial
stdout=serial
usb_folder=images

SigmaStar # version
version

U-Boot 2015.01 (May 25 2021 - 15:27:57)
arm-linux-gnueabihf-gcc (GNU Toolchain for the A-profile Architecture 8.2-2018-08 (arm-rel-8.23)) 8.2.1 20180802
GNU ld (GNU Toolchain for the A-profile Architecture 8.2-2018-08 (arm-rel-8.23)) 2.30.0.20180625
SigmaStar #

U-Boot 2015.01 (May 25 2021 - 15:27:57)
arm-linux-gnueabihf-gcc (GNU Toolchain for the A-profile Architecture 8.2-2018-08 (arm-rel-8.23)) 8.2.1 20180802
GNU ld (GNU Toolchain for the A-profile Architecture 8.2-2018-08 (arm-rel-8.23)) 2.30.0.20180625
SigmaStar #
 

javierfer

n3wb
Joined
May 24, 2017
Messages
21
Reaction score
1
Hello everyone, maybe someone could shed some light on my problem. I have a Dahua SD49225T-HN-S2 PTZ camera that stopped working from one day to the next, has entered a reboot loop and has returned to the factory IP 192.168.1.108 Unfortunately I can't fix it through TFTP It keeps rebooting and the connection cannot be established. I want to find the UART port of the camera but I can't find it. I've only found these single pins that seem to be the UART port but I can't get them to connect since nothing appears on the monitor when the power is connected to the camera Is there a way to activate the UART port?
 

Attachments

javierfer

n3wb
Joined
May 24, 2017
Messages
21
Reaction score
1
on usb adapter i conected tx with rx (on camera), rx on usb adapter with tx(on camera) gnd usb to gnd camera, vcc 3.3v usb to vcc 3.3v on camera.
Once you conected all that ( before there is two white conector 4(whires) to disable ptz check on camera boot (so it doesn`t start spinning and disabling your conection usb to camera)..
I will post later those pictures where those conectors are...

when you disconect pin to disable ptz movement conect rx,tx,gnd,vcc3.3v to usb adapter, open putty baud rate 115200, flow control to none. Putty window will open and then conect the camera to power supply - turn it on...

you will se uboot loader then press and hold * (on keyboard)....

All of this is fine for me, but there is no network connection from camera to my computer...i conected camera directly to my computer or switch. There is always a same problem no conection...

Should i connect camera with poe+ network switch and hope there will be a network conection on my computer
I have a Dahua SD49225T-HN ptz camera that stopped working overnight. I want to find the UART port and I see in your photographs that it is similar to the pins on your camera, but when I connect the ubs-ttl to it, nothing appears on it. monitor. My question is, what voltages do the Rx and TX pins of your camera have?
 

VdjHouse

n3wb
Joined
Apr 11, 2018
Messages
3
Reaction score
0
I have a SD1A203T-GN that went unresponsive and is stuck in the boot cycle. I have set up the tftp server and the camera will connect to it and it seems like the files transfer and flash? I tried with the multiple commands with no success.


tftp 0x2000000 romfs-x.squashfs.img; flwrite
tftp 0x2000000 kernel.img; flwrite
tftp 0x2000000 user-x.squashfs.img; flwrite
tftp 0x2000000 web-x.squashfs.img; flwrite
tftp 0x2000000 pd-x.squashfs.img; flwrite
tftp 0x2000000 custom-x.squashfs.img; flwrite
tftp 0x2000000 partition-x.cramfs.img; flwrite
tftp 0x2000000 .FLASHING_DONE_STOP_TFTP_NOW


I also tried with the run up command since one of the firmware's had the update.img file.



I think the camera was on version DH_SD-Mao-Rhea_MultiLang_PN_Stream3_IVS_V2.800.0000000.4.R.191105

I have attached the output from the console any help would be greatly appreciated.

Ncat: Version 7.40 ( Ncat - Netcat for the 21st Century )
Ncat: Listening on 192.168.254.254:5002
gBootLogPtr:00b80008.
NAND: 128 MiB
amb_nand_read_oob read page:49152 err
partition file version 2
rootfstype squashfs root /dev/mtdblock8
fail to load bootargsParametersV22.txt
fail to load bootargsParametersV21.txt
fail to init bootargsParametersV2
TEXT_BASE:01000000
Net: PHY:0x001cc816,addr:0x00
s3l phy RTL8201 init
partition file version 2
rootfstype squashfs root /dev/mtdblock8
Using ambarella mac device
Download Filename 'upgrade_info_7db780a713a4.txt'.Downloading: 100%
## file size: 78 Bytes, times: 0s, speed: 10.7 KiB/s
done
Bytes transferred = 78 (4e hex)
Using ambarella mac device
Download Filename 'update.img'.Downloading: ICMP Host Redirect to 192.168.1.29 ICMP Host Redirect to 192.168.1.29 100%

## file size: 28.4 MiB, times: 41s, speed: 701.2 KiB/s
done
Bytes transferred = 29770253 (1c6420d hex)
←[0;32mskip check secure Image!
←[0mErasing update flag partition.
partition file version 2
rootfstype squashfs root /dev/mtdblock8
partition file version 2
rootfstype squashfs root /dev/mtdblock8

## Checking Image at 02000040 ...
Legacy image found
Image Name: romfs
Created: 2021-07-05 12:17:56 UTC
Image Type: ARM Linux Kernel Image (uncompressed)
Data Size: 1458176 Bytes = 1.4 MiB
Load Address: 01200000
Entry Point: 01600000
Verifying Checksum ... OK
Programing start at: 0x01200000 for romfs
write : 100%
done
crc from program is :9aec38f4, crc from flash is :9aec38f4

## Checking Image at 02164080 ...
Legacy image found
Image Name: user
Created: 2021-07-05 12:18:19 UTC
Image Type: ARM Linux Standalone Program (uncompressed)
Data Size: 19464192 Bytes = 18.6 MiB
Load Address: 01e00000
Entry Point: 03a80000
Verifying Checksum ... OK
Programing start at: 0x01e00000 for user
write : 100%
done
crc from program is :562712ad, crc from flash is :562712ad

## Checking Image at 033f40c0 ...
Legacy image found
Image Name: web
Created: 2021-07-05 12:18:00 UTC
Image Type: ARM Linux Standalone Program (uncompressed)
Data Size: 5799936 Bytes = 5.5 MiB
Load Address: 01600000
Entry Point: 01e00000
Verifying Checksum ... OK
Programing start at: 0x01600000 for web
write : 100%
done
crc from program is :6e52a74f, crc from flash is :6e52a74f

## Checking Image at 0397c100 ...
Legacy image found
Image Name: pd
Created: 2021-07-05 12:18:34 UTC
Image Type: ARM Linux Standalone Program (uncompressed)
Data Size: 65536 Bytes = 64 KiB
Load Address: 00940000
Entry Point: 00c80000
Verifying Checksum ... OK
Programing start at: 0x00940000 for pd
write : 100%
done
crc from program is :74c6d22a, crc from flash is :74c6d22a

## Checking Image at 0398c140 ...
Legacy image found
Image Name: custom
Created: 2021-07-05 12:18:37 UTC
Image Type: ARM Linux Standalone Program (uncompressed)
Data Size: 1249280 Bytes = 1.2 MiB
Load Address: 00600000
Entry Point: 00940000
Verifying Checksum ... OK
Programing start at: 0x00600000 for custom
write : 100%
done
crc from program is :b8f86cd4, crc from flash is :b8f86cd4

## Checking Image at 03abd180 ...
Legacy image found
Image Name: partition
Created: 2021-07-05 12:17:54 UTC
Image Type: ARM Linux Standalone Program (uncompressed)
Data Size: 4096 Bytes = 4 KiB
Load Address: 00500000
Entry Point: 00600000
Verifying Checksum ... OK
Programing start at: 0x00500000 for partition
write : 100%
done
crc from program is :edc1d69a, crc from flash is :edc1d69a

## Checking Image at 03abe1c0 ...
Legacy image found
Image Name: kernel
Created: 2021-07-05 12:17:54 UTC
Image Type: ARM Linux Firmware (uncompressed)
Data Size: 1725328 Bytes = 1.6 MiB
Load Address: 00c80000
Entry Point: 01200000
Verifying Checksum ... OK
Programing start at: 0x00c80000 for kernel
write : 100%
done
crc from program is :5771ec83, crc from flash is :5771ec83

## Checking Image at 03c63590 ...
Legacy image found
Image Name: CmdScript
Created: 2021-07-05 12:18:39 UTC
Image Type: ARM Linux Standalone Program (uncompressed)
Data Size: 901 Bytes = 901 Bytes
Load Address: c0000000
Entry Point: c0001400
Verifying Checksum ... OK
exce update config script start!
set da 'tftp 0x2000000 dhboot.bin.img; flwrite; tftp dhboot-min.bin.img;nand protect off;flwrite;nand protect on'
set dr 'tftp 0x2000000 romfs-x.squashfs.img; flwrite'
set dk 'tftp 0x2000000 kernel.img; flwrite'
set du 'tftp 0x2000000 user-x.squashfs.img; flwrite'
set dw 'tftp 0x2000000 web-x.squashfs.img; flwrite'
set ds 'tftp 0x2000000 dsp-x.squashfs.img; flwrite'
set dc 'tftp 0x2000000 custom-x.squashfs.img; flwrite'
set dt 'tftp 0x2000000 data-x.squashfs.img; flwrite'
set df 'tftp 0x2000000 fpga.img; flwrite'
set up 'tftp 0x2000000 update.img; flwrite'
set tk 'tftp 0x200100 hawthorn.dts.dtb;tftp 0x2000000 uImage;bootm 0x2000000'
set bootcmd 'nand read 0x200100 0x60000 0x10000;kload 0x2000000; bootm 0x2000000'
setenv bootargs "console=ttyS0,115200 mem=150M root=/dev/mtdblock8 rootfstype=squashfs init=/linuxrc"
save
Saving Environment to NAND...
Erasing Nand...
Erasing at 0x360000 -- 100% complete.
Writing to Nand...
backupbst magic err
done
exce update config script complete!
partition file version 2
rootfstype squashfs root /dev/mtdblock8
partition file version 2
rootfstype squashfs root /dev/mtdblock8
partition file version 2
rootfstype squashfs root /dev/mtdblock8
fail to load bootargsParametersV22.txt
fail to load bootargsParametersV21.txt
WARNING: Fail to update bootargs!!!
partition file version 2
rootfstype squashfs root /dev/mtdblock8
fail to load bootargsParameters.txt
fail to load bootargsParameters.txt file
get bootargs info failed
cmdLine console=ttyS0,115200 mem=150M root=/dev/mtdblock8 rootfstype=squashfs init=/linuxrc
 

votinh69

n3wb
Joined
Jun 11, 2024
Messages
1
Reaction score
0
Location
Vietnam
My IMOU only show this:
Code:
ROM:   Use nor flash.
ROM:    Init cipher.
ROM:    215
Is it dead? :embarrassed:
 

shahram437

n3wb
Joined
Dec 9, 2022
Messages
14
Reaction score
0
Location
Iran
Hi have a good day
I have serial port connection and eliminate bootargs to have only linux boot,l want to search directories. But:
1-the date and time reset to 1970-1-1 and time to 0
2-it starts auto commands ...cpu is alive
3-after 3 minutes reboots again!
So I can't type and search anything!
How could I stop this?
 

shahram437

n3wb
Joined
Dec 9, 2022
Messages
14
Reaction score
0
Location
Iran
Bootrom start
Boot Media: SPI_NAND
Decrypt auxiliary code ...OK
Entry boot auxiliary code

Auxiliary code - v1.00
DDR code - V1.1.2 20160205
Build: Apr 19 2016 - 20:18:19

Reg Version: v1.5.1\
Reg Time: 2017/04/10 14:34:20
Reg Name: hi3798cv2dmd_hi3798cv200_DDR3-1866_1GB_16bitx2_4layers.reg

Boot auxiliary code success
Bootrom success


System startup


Relocate Boot

Jump to C code


Compressed-boot v1.0.0
Uncompress.....................Ok


System startup


Relocate Boot

Jump to C code


Fastboot 3.3.0-svn2968 (jenkins@centos235) (Jan 19 2018 - 13:54:56)

Fastboot: Version 3.3.0
Build Date: Jan 19 2018, 13:55:27
CPU: Hi3798Cv200
Boot Media: SPI-NAND
DDR Size: 1GB

Found flash memory controller hifmc100.
Nand ID: 0xEF 0xAA 0x21 0x00 0x00 0x00 0x00 0x00
maxclk:70M
Nand: WINBOND W25N01GV
Nand(HW-Auto): Block:128KB Page:2KB OOB:64B ECC:4bit/512 Chip:128MB*1
Boot Env on NAND
Env Offset: 0x00300000
Env Size: 0x00020000
Env Range: 0x00100000


SDK Version: HiSTBLinuxV100R005C00SPC031_20160601

logo........... Logo_Main!
--LT8612_Reset Success! Reset Count:0.
BMP_GetPixelFmt : 32
Cnfigure For SATA
CFG_COMBPHY: 0x1010
start_armboot LINE 599 0x1063
Hit any key to stop autoboot: 0
higmac_init(969): Get PhyId 0x1cc816
higmac_net_adjust_link(679): port_mode 0x9f
ETH1: PHY(phyaddr=0, rmii) link UP: DUPLEX=FULL : SPEED=100M
MAC: 38-AF-29-8C-43-C3
NET_autoLipDetect timeout
ETH1: PHY(phyaddr=0, rmii) link UP: DUPLEX=FULL : SPEED=100M
MAC: 38-AF-29-8C-43-C3
TFTP from server 192.168.1.10; our IP address is 192.168.1.108
Download Filename 'ID_4F06138PAZD3539.txt'.
Download to address: 0x1000000
Downloading: T T T
Retry count exceeded; starting again

NAND read: device 0 offset 0x500000, size 0x500000
5242880 bytes read: OK
## Booting kernel from Legacy Image at 01000000 ...
Image Name: Linux-3.18.24_hi3798cv2x
Image Type: ARM Linux Kernel Image (uncompressed)
Data Size: 4969806 Bytes = 4.7 MiB
Load Address: 02000000
Entry Point: 02000000
Verifying Checksum ... OK
Loading Kernel Image from 0x16777280 to 0x33554432 ... OK
OK
ATAGS [0x00000100 - 0x000003D0], 720Bytes

Starting kernel ...


[ 0.000000] Booting Linux on physical CPU 0x0
[ 0.000000] Linux version 3.18.24_hi3798cv2x (jenkins@centos235) (gcc version 4.9.2 20140904 (prerelease) (gcc-4.9.2 + eglibc-2.19 (Build by czyong) Mon Mar 9 14:14:50 CST 2015) ) #1 SMP Fri Jan 19 13:52:56 CST 2018, svn:8109
[ 0.000000] CPU: ARMv7 Processor [410fd034] revision 4 (ARMv7), cr=10c5383d
[ 0.000000] CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
[ 0.000000] Machine model: Hisilicon
[ 0.000000] cma: Reserved 52 MiB at 0x3bc00000
[ 0.000000] cma: Reserved 4 MiB at 0x3fc00000
[ 0.000000] Memory policy: Data cache writealloc
[ 0.000000] DT missing boot CPU MPIDR[23:0], fall back to default cpu_logical_map
[ 0.000000] PERCPU: Embedded 10 pages/cpu @df3c2000 s10944 r8192 d21824 u40960
[ 0.000000] Built 1 zonelists in Zone order, mobility grouping on. Total pages: 261128
[ 0.000000] Kernel command line: mem=1G console=ttyAMA0,115200 root=/dev/mtdblock3 rootfstype=squashfs rootwait mtdparts=hinand:3M(boot),2M(env),10M(kernel),54M(rootfs),10M(web),2M(custom),3M(logo),6M(logs),10M(config),8M(extend1),12M(backup),8M(extend2) mmz=ddr,0,0,50M vmalloc=500M single dh_keyboard=0 load_modules=1
[ 0.000000] ==>start:"=0 load_modules=1" use_console:1
[ 0.000000] log_buf_len individual max cpu contribution: 4096 bytes
[ 0.000000] log_buf_len total cpu_extra contributions: 12288 bytes
[ 0.000000] log_buf_len min size: 16384 bytes
[ 0.000000] log_buf_len: 32768 bytes
[ 0.000000] early log buf free: 14132(86%)
[ 0.000000] PID hash table entries: 2048 (order: 1, 8192 bytes)
[ 0.000000] Dentry cache hash table entries: 65536 (order: 6, 262144 bytes)
[ 0.000000] Inode-cache hash table entries: 32768 (order: 5, 131072 bytes)
[ 0.000000] Memory: 966456K/1048576K available (7256K kernel code, 424K rwdata, 2144K rodata, 450K init, 391K bss, 82120K reserved, 465808K highmem)
[ 0.000000] Virtual kernel memory layout:
[ 0.000000] vector : 0xffff0000 - 0xffff1000 ( 4 kB)
[ 0.000000] fixmap : 0xffc00000 - 0xfff00000 (3072 kB)
[ 0.000000] vmalloc : 0xe0000000 - 0xff000000 ( 496 MB)
[ 0.000000] lowmem : 0xc0000000 - 0xdfc00000 ( 508 MB)
[ 0.000000] pkmap : 0xbfe00000 - 0xc0000000 ( 2 MB)
[ 0.000000] modules : 0xbf000000 - 0xbfe00000 ( 14 MB)
[ 0.000000] .text : 0xc0008000 - 0xc0936528 (9402 kB)
[ 0.000000] .init : 0xc0937000 - 0xc09a7ac0 ( 451 kB)
[ 0.000000] .data : 0xc09a8000 - 0xc0a120e4 ( 425 kB)
[ 0.000000] .bss : 0xc0a120e4 - 0xc0a73edc ( 392 kB)
[ 0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[ 0.000000] Hierarchical RCU implementation.
[ 0.000000] NR_IRQS:352
[ 0.000000] Architected cp15 timer(s) running at 24.00MHz (phys).
[ 0.000003] sched_clock: 56 bits at 24MHz, resolution 41ns, wraps every 2863311519744ns
[ 0.000010] Switching to timer-based delay loop, resolution 41ns
[ 0.000089] sched_clock: 32 bits at 24MHz, resolution 41ns, wraps every 178956969942ns
[ 0.000216] Console: colour dummy device 80x30
[ 0.000228] Calibrating delay loop (skipped), value calculated using timer frequency.. 48.00 BogoMIPS (lpj=96000)
[ 0.000236] pid_max: default: 32768 minimum: 301
[ 0.000301] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
[ 0.000306] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
[ 0.000577] CPU: Testing write buffer coherency: ok
[ 0.000594] ftrace: allocating 23669 entries in 70 pages
[ 0.021311] 1970-1-1 0:0:0 CPU is alive
[ 0.021357] CPU0: thread -1, cpu 0, socket 0, mpidr 80000000
[ 0.021401] Setting up static identity map for 0x6938b8 - 0x693910
[ 0.022786] CPU: hi3798cv200
[ 0.023160] CPU1: thread -1, cpu 1, socket 0, mpidr 80000001
[ 0.023496] CPU2: thread -1, cpu 2, socket 0, mpidr 80000002
[ 0.023824] CPU3: thread -1, cpu 3, socket 0, mpidr 80000003
[ 0.023849] Brought up 4 CPUs
[ 0.023856] SMP: Total of 4 processors activated (192.00 BogoMIPS).
[ 0.023860] CPU: All CPU(s) started in SVC mode.
[ 0.026399] VFP support v0.3: implementor 41 architecture 3 part 40 variant 3 rev 4
[ 0.027052] regulator-dummy: no parameters
[ 0.028460] NET: Registered protocol family 16
[ 0.028737] DMA: preallocated 256 KiB pool for atomic coherent allocations
[ 0.032443] hw-breakpoint: found 5 (+1 reserved) breakpoint and 4 watchpoint registers.
[ 0.032451] hw-breakpoint: maximum watchpoint size is 8 bytes.
[ 0.032467] Serial: AMBA PL011 UART driver
[ 0.032529] f8b00000.uart: ttyAMA0 at MMIO 0xf8b00000 (irq = 81, base_baud = 0) is a PL011 rev2
[ 0.446714] console [ttyAMA0] enabled
[ 0.450527] f8b02000.uart: ttyAMA1 at MMIO 0xf8b02000 (irq = 83, base_baud = 0) is a PL011 rev2
[ 0.475946] hisilicon-pcie: probe of f9860000.pcie failed with error -1
[ 0.482717] vgaarb: loaded
[ 0.485578] SCSI subsystem initialized
[ 0.489569] usbcore: registered new interface driver usbfs
[ 0.495083] usbcore: registered new interface driver hub
[ 0.500420] usbcore: registered new device driver usb
[ 0.505548] media: Linux media interface: v0.10
[ 0.510103] Linux video capture interface: v2.00
[ 0.515158] hisi_iommu_ptable_addr:phy 0x1e000000 size:0x400000
[ 0.521335] hisi_iommu_err_rdaddr :phy 0x1ef56800 size:0x200
[ 0.527247] hisi_iommu_err_wraddr :phy 0x1ef56a00 size:0x200
[ 0.533270] in hisi_iommu_domain_init start
[ 0.538645] in hisi_iommu_domain_init end
[ 0.542840] Advanced Linux Sound Architecture Driver Initialized.
[ 0.549518] Switched to clocksource arch_sys_counter
[ 0.566810] NET: Registered protocol family 2
[ 0.571504] TCP established hash table entries: 4096 (order: 2, 16384 bytes)
[ [ 1.503523] f9c40000.himciv200.SD: eMMC/MMC/SD Device NOT detected!
[ 1.541972] usbcore: registered new interface driver usbhid
[ 1.547541] usbhid: USB HID core driver
[ 1.555020] hiahci-phy: registered new sata phy driver
[ 1.560490] vdd-gpu: 650 <--> 1150 mV at 880 mV
[ 1.565298] usbcore: registered new interface driver snd-usb-audio
[ 1.571630] oprofile: hardware counters not available
[ 1.576681] oprofile: using timer interrupt.
[ 1.580977] Netfilter messages via NETLINK v0.30.
[ 1.585684] nfnl_acct: registering with nfnetlink.
[ 1.590604] ip_tables: (C) 2000-2006 Netfilter Core Team
[ 1.595927] arp_tables: (C) 2002 David S. Miller
[ 1.600554] TCP: cubic registered
[ 1.604266] NET: Registered protocol family 10
[ 1.609136] NET: Registered protocol family 17
[ 1.613723] Registering SWP/SWPB emulation handler
[ 1.619071] open /SigFilePartition error
[ 1.721674] ahci f9900000.hiahci: SSS flag set, parallel bus scan disabled
[ 1.728558] ahci f9900000.hiahci: AHCI 0001.0300 32 slots 1 ports 6 Gbps 0x1 impl platform mode
[ 1.737254] ahci f9900000.hiahci: flags: ncq sntf stag pm led clo only pmp fbs slum part ccc sxs boh
[ 1.746926] scsi host0: ahci_platform
[ 1.750758] ata1: SATA max UDMA/133 mmio [mem 0xf9900000-0xf9900fff] port 0x100 irq 102
[ 1.765568] libphy: higmac_mii_bus: probed
[ 1.769724] libphy: get_phy_device phyid 0x1cc816
[ 1.775086] Higmac dma_sg_phy: 0x3fc7a000
[ 1.780022] ALSA device list:
[ 1.782988] No soundcards found.
[ 2.077529] ata1: SATA link down (SStatus 0 SControl 320)
[ 2.084158] VFS: Mounted root (squashfs filesystem) readonly on device 31:3.
[ 2.091416] Freeing unused kernel memory: 448K (c0937000 - c09a7000)


BusyBox v1.18.4 (2018-01-19 14:11:32 CST) built-in shell (ash)
Revision: 29708
Enter 'help' for a list of built-in commands.

~ # [ 10.269526] 1970-1-1 0:0:10 CPU is alive
[ 20.273520] 1970-1-1 0:0:20 CPU is alive
[ 30.277520] 1970-1-1 0:0:30 CPU is alive
[ 40.281520] 1970-1-1 0:0:40 CPU is alive
[ 50.285520] 1970-1-1 0:0:50 CPU is alive
[ 60.289521] 1970-1-1 0:1:0 CPU is alive
[ 70.293520] 1970-1-1 0:1:10 CPU is alive
[ 80.297520] 1970-1-1 0:1:20 CPU is alive
[ 90.301520] 1970-1-1 0:1:30 CPU is alive
[ 100.305520] 1970-1-1 0:1:40 CPU is alive
[ 110.309520] 1970-1-1 0:1:50 CPU is alive
[ 113.713520] creat /var/tmp/envState error
[ 120.313520] 1970-1-1 0:2:0 CPU is alive
[ 130.317520] 1970-1-1 0:2:10 CPU is alive
[ 140.321520] 1970-1-1 0:2:20 CPU is alive
[ 150.325520] 1970-1-1 0:2:30 CPU is alive
[ 160.329520] 1970-1-1 0:2:40 CPU is alive

Bootrom start
Boot Media: SPI_NAND
Decrypt auxiliary code ...OK
Entry boot auxiliary code

Auxiliary code - v1.00
DDR code - V1.1.2 20160205
Build: Apr 19 2016 - 20:18:19

Reg Version: v1.5.1\
Reg Time: 2017/04/10 14:34:20
Reg Name: hi3798cv2dmd_hi3798cv200_DDR3-1866_1GB_16bitx2_4layers.reg

Boot auxiliary code success
Bootrom success


System startup


Relocate Boot

Jump to C code


Compressed-boot v1.0.0
Uncompress.....................Ok


System startup


Relocate Boot

Jump to C code


Fastboot 3.3.0-svn2968 (jenkins@centos235) (Jan 19 2018 - 13:54:56)

Fastboot: Version 3.3.0
Build Date: Jan 19 2018, 13:55:27
CPU: Hi3798Cv200
Boot Media: SPI-NAND
DDR Size: 1GB

Found flash memory controller hifmc100.
Nand ID: 0xEF 0xAA 0x21 0x00 0x00 0x00 0x00 0x00
maxclk:70M
Nand: WINBOND W25N01GV
Nand(HW-Auto): Block:128KB Page:2KB OOB:64B ECC:4bit/512 Chip:128MB*1
Boot Env on NAND
Env Offset: 0x00300000
Env Size: 0x00020000
Env Range: 0x00100000


SDK Version: HiSTBLinuxV100R005C00SPC031_20160601

logo........... Logo_Main!
-
 

iTuneDVR

Pulling my weight
Joined
Aug 23, 2014
Messages
867
Reaction score
155
Location
Россия
Stop u-boot.
printenv
Looks like appauto = 0
So, shell without loading modules is normal & watchdog work correct.
 

shahram437

n3wb
Joined
Dec 9, 2022
Messages
14
Reaction score
0
Location
Iran
Stop u-boot.
printenv
Looks like appauto = 0
So, shell without loading modules is normal & watchdog work correct.
Thank you very much, I'll try it.
But what about this string? It's repeating every 10 seconds:
"some numbers...date time cpu is alive"
How can I stop it?
Thanks
 

shahram437

n3wb
Joined
Dec 9, 2022
Messages
14
Reaction score
0
Location
Iran
Thank you for uou
Stop u-boot.
printenv
Looks like appauto = 0
So, shell without loading modules is normal & watchdog work correct.
Hi, I tried it, changed appauto=0, but nothing changed and it boots every 3 minuts again!
 
Top