Bootlog??

From t-hack.com - Hack X300T / X301T

Revision as of 21:51, 18 December 2007 by Mce2222 (Talk | contribs)
(diff) ← Older revision | Current revision (diff) | Newer revision → (diff)
Jump to: navigation, search

This is the bootload of a beta X300T. it does not contain the IPTV Bootloader ! instead it has the YAMON debugger in the flash.

a dump of the flash is available but it does not work on the retail X300T boxes

(I tried, and the boot stops at "zboot failed" which means that the encryption certificate is different)

xosPba serial#02931839ad46b278807556525fc0926c subid 0xc4
xenv cs2 ok
dram0 ok
0xe34111ba/0x00093333
dram1 ok
0xe34111ba/0x00093333
zboot ok
**********************************
SMP863x zboot start ...
Version: 2.0.0-2.7.112.1
Started at 0x91000000.
Configurations (chip revision: 6):
Use 8KB DRAM as stack.
Support XLoad format.
**********************************
Boot from flash (0x48000000) mapped to 0xac000000.
Found XENV block at 0xac000000.
CPU clock frequency: 301.50MHz.
System clock frequency: 201.00MHz.
DRAM0 dunit_cfg/delay0_ctrl (0xe34111ba/0x00093333).
DRAM1 dunit_cfg/delay0_ctrl (0xe34111ba/0x00093333).
Using UART port 0 as console.
Board ID.: "KMM3000"
Chip Revision: 0x8634:0x82 .. Mismatched.
Setting up H/W from XENV block at 0xac000000.
Setting to 0x00000603.
Setting to 0x00000000.
Setting to 0x00000100.
Setting to 0xff28ca00.
Setting to 0x0000c000.
Setting to 0x000001ff.
Setting to 0x00000000.
Setting to 0x0d090800.
Setting to 0x01090008.
Setting to 0x01090008.
Setting to 0x000003fc.
Setting to 0x00110101.
Setting to 0x000003f3.
PB cs config: 0x000c10c0 (use 0x000c10c0)
Enabled Devices: 0x00023efe
BM/IDE PCIHost Ethernet IR FIP I2CM I2CS USB PCIDev1 PCIDev2 PCIDev3 PCIDev4 SCARD
MAC: 00:d0:e0:92:0a:9c
PCI IRQ routing:
IDSEL 1: INTA(#14) INTB(#14) INTC(#14) INTD(#14)
IDSEL 2: INTA(#14) INTB(#14) INTC(#14) INTD(#14)
IDSEL 3: INTA(#14) INTB(#14) INTC(#14) INTD(#14)
IDSEL 4: INTA(#15) INTB(#15) INTC(#15) INTD(#15)
Smartcard pin assignments:
OFF pin = 0
5V pin = 1
CMD pin = 2
Setting up Clean Divider 2 to 96000000Hz.
Setting up Clean Divider 4 to 33333333Hz.
GPIO dir/data = 0x00000000/0x00000000
UART0 GPIO mode/dir/data = 0x6e/0x00/0x00
UART1 GPIO mode/dir/data = 0x6e/0x00/0x00
XENV block processing completed.
Found existing memcfg: DRAM0(0x04000000), DRAM1(0x04000000)
Default boot index: 0
Scanning ROMFS image at 0xac040000 (0x48040000) .. Found.
ROMFS found at 0xac040000, Volume name = YAMON_XRPC
Found 1 file(s) to be processed in ROMFS.
Processing xrpc_xload_yamon_ES4_prod.bin (start: 0xac040090, size: 0x00030bc4)
Checking zboot file signature .. Not found.
Trying xload format .. OK
Checking zboot file signature at 0x13000000 .. OK
Decompressing to 0x91100000 .. OK (458240/0x6fe00).
Load time total 279 msec.
Execute at 0x91100000 ..

**********************************
YAMON ROM Monitor
Revision 02.06-SIGMADESIGNS-01-2.7.112.1
**********************************
Memory: code: 0x11000000-0x11040000, 0x11100000-0x11104000
reserved data: 0x11140000-0x12340000, PCI memory: 0x12340000-0x12740000
Environment variable 'start' exists. After 4 seconds
it will be interpreted as a YAMON command and executed.
Press Ctrl-C (or do BREAK) to bypass this.
Ethernet driver for EM86XX (v1.0)
(MAC 00:d0:e0:92:0a:9c, tx_desc/rx_desc = 16/32)
em86xx_eth::open(em86xx_eth) - Full-duplex mode
em86xx_eth::open(em86xx_eth) - 100 Mbit/s
em86xx_eth ethernet start
ipaddr: 192.168.0.12
subnetmask: 255.255.255.0
gateway: 192.168.0.1
Discover DHCP server ...
Discover DHCP server ...
Discover DHCP server ...
Discover DHCP server ...
DHCP Failed
Error : Illegal syntax
Syntax :
load (uu [-z] ) |
(romfs [-z] []) |
(zbf []) |
[-r] (-b tftp:/// ) |
(tftp:///)
(asc:[//(tty0|tty1)])