I have a NVR8-7400 and I needed to replace one camera and could not find a Swan camera but I did find the Reolink RLC-410 camera that kinda worked . I was able to use Reolink software to connect to my NVR and manage it so I figured they use the same hardware. Then I found out that RLN8-410 firmware will load on the NVR87400. And then the "find out moment" I was able to see the Reolink camera but not the other seven Swann cameras "crap". The Reolink NVR firmware would not connect to the Swann cameras password error and there is no where to change it
. So I fixed one but broke 7. I tried to revert to the Swann firmware and it just says invalid file. I need to revert to the Swann firmware hopefully.
I opened the unit to see if I could flash the unit via the serial console. I found this post that helped poking-the-swann-nvr-7400. So here is where im stuck unpacking the firmware from the pak file and writing it to the using sf and tftp.
NVR U-Boot serial log
NVR Boot Log

I opened the unit to see if I could flash the unit via the serial console. I found this post that helped poking-the-swann-nvr-7400. So here is where im stuck unpacking the firmware from the pak file and writing it to the using sf and tftp.
NVR U-Boot serial log
Code:
U-Boot 2010.06 (Sep 24 2014 - 15:02:05)
NAND: Check nand flash controller v504. found
Special NAND id table Version 1.36
Nand ID: 0x01 0xF1 0x80 0x1D 0x01 0xF1 0x80 0x1D
Block:128KB Page:2KB Chip:128MB*1 OOB:64B ECC:4bits/512Byte
128 MiB
Check spi flash controller v350... Found
Can't find a valid spi flash chip.
Can't find a valid spi flash chip.
*** Warning - bad CRC or NAND, using default environment
In: serial
Out: serial
Err: serial
Hit any key to stop autoboot: 1 0
hisilicon # ? help
? - alias for 'help'
base - print or set address offset
bootm - boot application image from memory
bootp - boot image via network using BOOTP/TFTP protocol
cmp - memory compare
cp - memory copy
crc32 - checksum calculation
ddr - ddr training function
decjpg - jpgd - decode jpeg picture.
ext2load- load binary file from a Ext2 filesystem
ext2ls - list files in a directory (default /)
fatinfo - print information about filesystem
fatload - load binary file from a dos filesystem
fatls - list files in a directory (default /)
getinfo - print hardware information
go - start application at address 'addr'
help - print command description/usage
loadb - load binary file over serial line (kermit mode)
loady - load binary file over serial line (ymodem mode)
loop - infinite loop on address range
md - memory display
mii - MII utility commands
mm - memory modify (auto-incrementing address)
mtest - simple RAM read/write test
mw - memory write (fill)
nand - NAND sub-system
nboot - boot from NAND device
nm - memory modify (constant address)
ping - send ICMP ECHO_REQUEST to network host
printenv- print environment variables
rarpboot- boot image via network using RARP/TFTP protocol
reset - Perform RESET of the CPU
saveenv - save environment variables to persistent storage
setenv - set environment variables
setvobg - setvobg - set vo backgroud color.
- setvobg [dev color]
sf - SPI flash sub-system
startgx - startgx - open graphics layer.
- startgx [layer addr stride x y w h]
startvo - startvo - open interface of vo device.
- startvo [dev type sync]
stopgx - stopgx - close graphics layer.
- stopgx [layer]
stopvo - stopvo - close interface of vo device.
- stopvo [dev]
tftp - tftp - download or upload image via network using TFTP protocol
usb - USB sub-system
usbboot - boot from USB device
version - print monitor version
hisilicon #
hisilicon #
hisilicon #
hisilicon #
hisilicon #
hisilicon # printenv
jpeg_addr=0x82000000
jpeg_size=0x40000
vobuf=0x8a227000
bootargs=mem=160M console=ttyAMA0,115200 root=/dev/mtdblock4 rootfstype=cramfs mtdparts=hinand:512K(uboot1),1920K(uboot2),128K(bootargs),4352K(kernel),12288K(fs),32768K(app),8192K(para),2048K(logo),11264K(ipc_img),128M@0(wholeflash),1024K@73472K(uid_img)
bootcmd=nand read 0x82000000 0x3ac0000 0x40000;setvobg 0 0;decjpg;startvo 0 36 14;startgx 0 0x8a227000 1 1 1 1 1;nand read 0x82000000 0x280000 0x380000;bootm 0x82000000
bootdelay=1
baudrate=115200
ethaddr=00:00:23:34:45:66
ipaddr=192.168.1.10
serverip=192.168.1.2
netmask=255.255.254.0
bootfile="uImage"
stdin=serial
stdout=serial
stderr=serial
verify=n
ver=U-Boot 2010.06 (Sep 24 2014 - 15:02:05)
Environment size: 712/131068 bytes
hisilicon #
NVR Boot Log
Code:
U-Boot 2010.06 (Sep 24 2014 - 15:02:05)
NAND: Check nand flash controller v504. found
Special NAND id table Version 1.36
Nand ID: 0x01 0xF1 0x80 0x1D 0x01 0xF1 0x80 0x1D
Block:128KB Page:2KB Chip:128MB*1 OOB:64B ECC:4bits/512Byte
128 MiB
Check spi flash controller v350... Found
Can't find a valid spi flash chip.
Can't find a valid spi flash chip.
*** Warning - bad CRC or NAND, using default environment
In: serial
Out: serial
Err: serial
Hit any key to stop autoboot: 1 0
NAND read: device 0 offset 0x3ac0000, size 0x40000
262144 bytes read: OK
dev 0 set background color!
jpeg decoding ...
<<addr=0x82000000, size=0x40000, vobuf=0x8a227000>>
mmu_enable
<<imgwidth=684, imgheight=456, linebytes=1376>>
decode success!!!!
decode jpeg!
dev 0 opened!
graphic layer 0 opened!
NAND read: device 0 offset 0x280000, size 0x380000
3670016 bytes read: OK
## Booting kernel from Legacy Image at 82000000 ...
Image Name: Linux-3.4.35_hi3535
Image Type: ARM Linux Kernel Image (uncompressed)
Data Size: 2358664 Bytes = 2.2 MiB
Load Address: 80008000
Entry Point: 80008000
Loading Kernel Image ... OK
OK
Starting kernel ...
Uncompressing Linux... done, booting the kernel.
Booting Linux on physical CPU 0
Linux version 3.4.35_hi3535 (mdq@baichuan) (gcc version 4.4.1 (Hisilicon_v100(gcc4.4-290+uclibc_0.9.32.1+eabi+linuxpthread)) ) #6 SMP Wed Jun 24 11:30:14 CST 2015
CPU: ARMv7 Processor [414fc091] revision 1 (ARMv7), cr=10c53c7d
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
Machine: hi3535
Truncating memory at 0x80000000 to fit in 32-bit physical address space
Memory policy: ECC disabled, Data cache writealloc
PERCPU: Embedded 7 pages/cpu @c0752000 s5888 r8192 d14592 u32768
Built 1 zonelists in Zone order, mobility grouping on. Total pages: 40640
Kernel command line: mem=160M console=ttyAMA0,115200 root=/dev/mtdblock4 rootfstype=cramfs mtdparts=hinand:512K(uboot1),1920K(uboot2),128K(bootargs),4352K(kernel),12288K(fs),32768K(app),8192K(para),2048K(logo),11264K(ipc_img),128M@0(wholeflash),1024K@73472K(uid_img)
PID hash table entries: 1024 (order: 0, 4096 bytes)
Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
Memory: 160MB = 160MB total
Memory: 156072k/156072k available, 7768k reserved, 0K highmem
Virtual kernel memory layout:
vector : 0xffff0000 - 0xffff1000 ( 4 kB)
fixmap : 0xfff00000 - 0xfffe0000 ( 896 kB)
vmalloc : 0xca800000 - 0xff000000 ( 840 MB)
lowmem : 0xc0000000 - 0xca000000 ( 160 MB)
pkmap : 0xbfe00000 - 0xc0000000 ( 2 MB)
modules : 0xbf000000 - 0xbfe00000 ( 14 MB)
.text : 0xc0008000 - 0xc0591000 (5668 kB)
.init : 0xc0591000 - 0xc05bd700 ( 178 kB)
.data : 0xc05be000 - 0xc05ed420 ( 190 kB)
.bss : 0xc05ed444 - 0xc060ebdc ( 134 kB)
SLUB: Genslabs=11, HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
Hierarchical RCU implementation.
NR_IRQS:128
sched_clock: 32 bits at 62MHz, resolution 16ns, wraps every 68719ms
Console: colour dummy device 80x30
Calibrating delay loop... 1987.37 BogoMIPS (lpj=9936896)
pid_max: default: 32768 minimum: 301
Mount-cache hash table entries: 512
Initializing cgroup subsys freezer
CPU: Testing write buffer coherency: ok
CPU0: thread -1, cpu 0, socket 0, mpidr 80000000
hw perfevents: enabled with ARMv7 Cortex-A9 PMU driver, 7 counters available
Setting up static identity map for 0x804601c0 - 0x804601f4
L310 cache controller enabled
l2x0: 16 ways, CACHE_ID 0x410000c9, AUX_CTRL 0x72430001, Cache size: 262144 B
CPU1: Booted secondary processor
CPU1: thread -1, cpu 1, socket 0, mpidr 80000001
Brought up 2 CPUs
SMP: Total of 2 processors activated (3981.31 BogoMIPS).
NET: Registered protocol family 16
hw-breakpoint: found 5 (+1 reserved) breakpoint and 1 watchpoint registers.
hw-breakpoint: maximum watchpoint size is 4 bytes.
Serial: AMBA PL011 UART driver
uart:0: ttyAMA0 at MMIO 0x20080000 (irq = 40) is a PL011 rev2
console [ttyAMA0] enabled
uart:1: ttyAMA1 at MMIO 0x20090000 (irq = 41) is a PL011 rev2
uart:2: ttyAMA2 at MMIO 0x200a0000 (irq = 42) is a PL011 rev2
bio: create slab <bio-0> at 0
SCSI subsystem initialized
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
Switching to clocksource timer0
cfg80211: Calling CRDA to update world regulatory domain
NET: Registered protocol family 2
IP route cache hash table entries: 2048 (order: 1, 8192 bytes)
TCP established hash table entries: 8192 (order: 4, 65536 bytes)
TCP bind hash table entries: 8192 (order: 4, 65536 bytes)
TCP: Hash tables configured (established 8192 bind 8192)
TCP: reno registered
UDP hash table entries: 128 (order: 0, 4096 bytes)
UDP-Lite hash table entries: 128 (order: 0, 4096 bytes)
NET: Registered protocol family 1
RPC: Registered named UNIX socket transport module.
RPC: Registered udp transport module.
RPC: Registered tcp transport module.
RPC: Registered tcp NFSv4.1 backchannel transport module.
VFS: Disk quotas dquot_6.5.2
Dquot-cache hash table entries: 1024 (order 0, 4096 bytes)
squashfs: version 4.0 (2009/01/31) Phillip Lougher
NTFS driver 2.1.30 [Flags: R/W].
jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
fuse init (API version 7.18)
msgmni has been set to 304
Block layer SCSI generic (bsg) driver version 0.4 loaded (major 254)
io scheduler noop registered
io scheduler deadline registered (default)
io scheduler cfq registered
brd: module loaded
loop: module loaded
ahci: SSS flag set, parallel bus scan disabled
ahci ahci.0: AHCI 0001.0300 32 slots 3 ports 6 Gbps 0x7 impl platform mode
ahci ahci.0: flags: ncq sntf stag pm led clo only pmp fbs slum part ccc sxs boh
scsi0 : ahci_platform
scsi1 : ahci_platform
scsi2 : ahci_platform
ata1: SATA max UDMA/133 mmio [mem 0x12010000-0x1201ffff] port 0x100 irq 63
ata2: SATA max UDMA/133 mmio [mem 0x12010000-0x1201ffff] port 0x180 irq 63
ata3: SATA max UDMA/133 mmio [mem 0x12010000-0x1201ffff] port 0x200 irq 63
Spi id table Version 1.22
Found Nand Flash Controller V504.
Nand ID: 0x01 0xF1 0x80 0x1D 0x01 0xF1 0x80 0x1D
Nand: AMD NAND 128MiB 3,3V 8-bit
Nand(Hardware): Block:128KB Page:2KB OOB:64B ECC:4bits/512Byte Chip:128MB*1
11 cmdlinepart partitions found on MTD device hinand
11 cmdlinepart partitions found on MTD device hinand
Creating 11 MTD partitions on "hinand":
0x000000000000-0x000000080000 : "uboot1"
0x000000080000-0x000000260000 : "uboot2"
0x000000260000-0x000000280000 : "bootargs"
0x000000280000-0x0000006c0000 : "kernel"
0x0000006c0000-0x0000012c0000 : "fs"
0x0000012c0000-0x0000032c0000 : "app"
0x0000032c0000-0x000003ac0000 : "para"
0x000003ac0000-0x000003cc0000 : "logo"
0x000003cc0000-0x0000047c0000 : "ipc_img"
0x000000000000-0x000008000000 : "wholeflash"
0x0000047c0000-0x0000048c0000 : "uid_img"
PPP generic driver version 2.4.2
PPP Deflate Compression module registered
PPP MPPE Compression module registered
NET: Registered protocol family 24
ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
hiusb-ehci hiusb-ehci.0: HIUSB EHCI
hiusb-ehci hiusb-ehci.0: new USB bus registered, assigned bus number 1
hiusb-ehci hiusb-ehci.0: irq 54, io mem 0x10040000
hiusb-ehci hiusb-ehci.0: USB 0.0 started, EHCI 1.00
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 2 ports detected
ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
hiusb-ohci hiusb-ohci.0: HIUSB OHCI
hiusb-ohci hiusb-ohci.0: new USB bus registered, assigned bus number 2
hiusb-ohci hiusb-ohci.0: irq 53, io mem 0x10030000
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 2 ports detected
xhci-hcd hiusb3.0: xHCI Host Controller
xhci-hcd hiusb3.0: new USB bus registered, assigned bus number 3
xhci-hcd hiusb3.0: irq 64, io mem 0x12000000
hub 3-0:1.0: USB hub found
hub 3-0:1.0: 1 port detected
xhci-hcd hiusb3.0: xHCI Host Controller
xhci-hcd hiusb3.0: new USB bus registered, assigned bus number 4
hub 4-0:1.0: USB hub found
hub 4-0:1.0: 1 port detected
usbcore: registered new interface driver cdc_acm
cdc_acm: USB Abstract Control Model driver for USB modems and ISDN adapters
usbcore: registered new interface driver cdc_wdm
Initializing USB Mass Storage driver...
usbcore: registered new interface driver usb-storage
USB Mass Storage support registered.
usbcore: registered new interface driver usbserial
usbserial: USB Serial Driver core
usbcore: registered new interface driver option
USB Serial support registered for GSM modem (1-port)
mousedev: PS/2 mouse device common for all mice
usbcore: registered new interface driver usbhid
usbhid: USB HID core driver
TCP: cubic registered
Initializing XFRM netlink socket
NET: Registered protocol family 17
NET: Registered protocol family 15
lib80211: common routines for IEEE802.11 drivers
Registering the dns_resolver key type
registered taskstats version 1
usb 2-2: new low-speed USB device number 2 using hiusb-ohci
input: USB OPTICAL MOUSE as /devices/platform/hiusb-ohci.0/usb2/2-2/2-2:1.0/input/input0
generic-usb 0003:2188:0AE1.0001: input: USB HID v1.11 Mouse [USB OPTICAL MOUSE ] on usb-hiusb-ohci-2/input0
ata1: softreset failed (1st FIS failed)
ata1: SATA link up 3.0 Gbps (SStatus 123 SControl 300)
ata1.00: ATA-9: ST2000VX003-1HH164, CV11, max UDMA/133
ata1.00: 3907029168 sectors, multi 0: LBA48 NCQ (depth 31/32)
ata1.00: configured for UDMA/133
scsi 0:0:0:0: Direct-Access ATA ST2000VX003-1HH1 CV11 PQ: 0 ANSI: 5
sd 0:0:0:0: [sda] 3907029168 512-byte logical blocks: (2.00 TB/1.81 TiB)
sd 0:0:0:0: [sda] 4096-byte physical blocks
sd 0:0:0:0: Attached scsi generic sg0 type 0
sd 0:0:0:0: [sda] Write Protect is off
sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
sda: sda1 sda2 sda3
sd 0:0:0:0: [sda] Attached SCSI disk
ata2: SATA link down (SStatus 0 SControl 300)
ata3: SATA link down (SStatus 0 SControl 300)
cramfs_fill_nand blocks is 96
VFS: Mounted root (cramfs filesystem) readonly on device 31:4.
Freeing init memory: 176K
_ _ _ _ _ _ _ _ _ _ _ _
\ _ _ _ _ _ ___
/ /__/ \ |_/
/ __ / - _ ___
/ / / / / /
_ _ _ _/ / / \_/ \_ ______
___________\___\__________________
[RCS]: /etc/init.d/S00devs
[RCS]: /etc/init.d/S01udev
udevd (640): /proc/640/oom_adj is deprecated, please use /proc/640/oom_score_adj instead.
[RCS]: /etc/init.d/S80network
[RCS]: /etc/init.d/S81toe
[RCS]: /etc/init.d/S90StartSuvr
usb is not ready for autoexec
loop: exports duplicate symbol loop_register_transfer (owned by kernel)
insmod: can't insert '/boot/loop.ko': invalid module format
kjournald starting. Commit interval 5 seconds
EXT3-fs (sda1): using internal journal
EXT3-fs (sda1): recovery complete
EXT3-fs (sda1): mounted filesystem with ordered data mode
app img on hd is missing
force umount img path:/mnt/img
cramfs_fill_nand blocks is 256
load app.img success on mtd
yaffs: dev is 32505862 name is "mtdblock6" rw
yaffs: passed flags ""
rmmod: can't unload 'hi3535_adec': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_aenc': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_ao': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_ai': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_aio': unknown symbol in module, or unknown parameter
rmmod: can't unload 'acodec': unknown symbol in module, or unknown parameter
rmmod: can't unload 'sil9024': unknown symbol in module, or unknown parameter
rmmod: can't unload 'gpioi2c': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hifb': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_region': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_ive': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_vda': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_vpss': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_vou': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_jpegd': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_hdmi': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_vfmw': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_vdec': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_jpege': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_rc': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_h264e': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_chnl': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_venc': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_vgs': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_tde': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_sys': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hi3535_base': unknown symbol in module, or unknown parameter
rmmod: can't unload 'mmz': unknown symbol in module, or unknown parameter
rmmod: can't unload 'hiuser': unknown symbol in module, or unknown parameter
Hisilicon Media Memory Zone Manager
hi3535_base: module license 'Proprietary' taints kernel.
Disabling lock debugging due to kernel taint
Hisilicon UMAP device driver interface: v3.00
load sys.ko for Hi3535...OK!
Load tde.ko ...OK!
load vgs.ko for Hi3535...OK!
load venc.ko for Hi3535...OK!
load chnl.ko for Hi3535...OK!
load h264e.ko for Hi3535...OK!
load rc.ko for Hi3535...OK!
load jpege.ko for Hi3535...OK!
load vou.ko ....OK!
load vpss.ko ....OK!
load vda.ko ....OK!
load region.ko ....OK!
load vdec.ko ....OK
load vhd firmware.ko OK
load hdmi.ko ....OK!
Load hi3535_jpegd.ko success. (SDK_VERSION:[jpeg6bv1.0] Build Time:[Jul 8 2014, 09:15:50])
gpio init ok ...
Hisilicon Watchdog Timer: 0.01 initialized. default_margin=60 sec (nowayout= 1, nodeamon= 1)
acodec inited!
Auto login as root ...
Jan 1 00:00:26 login[1030]: root login on 'ttyS000'
Last edited: