Arcadyan AW1000 Kernel problem

I encountered an Error Kernel because of a problem when installing Sysupgrade on the AW1000 modem ... Whatever I did especially through Serial and USB flash, Couldn't fix it. any suggestion except these:

  1. enable tftpd and initramfs.bin on it 2. turning on with interrupting Boot loader (ESC) , 3. then executed (tftpboot initramfs.bin bootm)

<Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset), D - Delta, S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00158
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B - 201 - PBL, Start
B - 2735 - bootable_media_detect_entry, Start
B - 3446 - bootable_media_detect_success, Start
B - 3451 - elf_loader_entry, Start
B - 7619 - auth_hash_seg_entry, Start
B - 7864 - auth_hash_seg_exit, Start
B - 69628 - elf_segs_hash_verify_entry, Start
B - 132471 - PBL, End
B - 144326 - SBL1, Start
B - 196877 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B - 203435 - pm_device_init, Start
B - 326228 - PM_SET_VAL:Skip
D - 122305 - pm_device_init, Delta
B - 328637 - pm_driver_init, Start
D - 5337 - pm_driver_init, Delta
B - 334951 - clock_init, Start
D - 2135 - clock_init, Delta
B - 338977 - boot_flash_init, Start
D - 16531 - boot_flash_init, Delta
B - 359290 - boot_config_data_table_init, Start
D - 4026 - boot_config_data_table_init, Delta - (575 Bytes)
B - 366671 - Boot Setting : 0x00000618
B - 370788 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B - 377590 - sbl1_ddr_set_params, Start
B - 381402 - CPR configuration: 0x30c
B - 384879 - cpr_init, Start
B - 387655 - Rail:0 Mode: 5 Voltage: 792000
B - 392870 - CL CPR settled at 744000mV
B - 395707 - Rail:1 Mode: 5 Voltage: 880000
B - 399885 - Rail:1 Mode: 7 Voltage: 896000
D - 16531 - cpr_init, Delta
B - 406748 - Pre_DDR_clock_init, Start
B - 410774 - Pre_DDR_clock_init, End
B - 414068 - DDR Type : PCDDR3
B - 419832 - do ddr sanity test, Start
D - 1067 - do ddr sanity test, Delta
B - 424590 - DDR: Start of HAL DDR Boot Training
B - 429318 - DDR: End of HAL DDR Boot Training
B - 434991 - DDR: Checksum to be stored on flash is 1789927307
B - 445422 - Image Load, Start
D - 215909 - QSEE Image Loaded, Delta - (1376448 Bytes)
B - 661423 - Image Load, Start
D - 61 - SEC Image Loaded, Delta - (0 Bytes)
B - 669109 - Image Load, Start
D - 12017 - DEVCFG Image Loaded, Delta - (26008 Bytes)
B - 681217 - Image Load, Start
D - 23028 - RPM Image Loaded, Delta - (86584 Bytes)
B - 704336 - Image Load, Start
D - 88694 - APPSBL Image Loaded, Delta - (563504 Bytes)
B - 793122 - QSEE Execution, Start
D - 61 - QSEE Execution, Delta
B - 798917 - USB D+ check, Start
D - 0 - USB D+ check, Delta
B - 805322 - SBL1, End
D - 663314 - SBL1, Delta
S - Flash Throughput, 6903 KB/s (2053791 Bytes, 297489 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz

U-Boot 2016.01 (Mar 19 2021 - 12:06:59 +0800)

DRAM: smem ram ptable found: ver: 1 len: 4
1 GiB
NAND: Could not find nand_gpio in dts, using defaults
Not an ONFI device
ONFI probe failed
ID = 2691a398
Vendor = 98
Device = a3
qpic_nand: changing oobsize to 160 from 256 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
1024 MiB
MMC: sdhci: Node Not found, skipping initialization

PCI0 is not defined in the device tree
PCI1 is not defined in the device tree
In: serial@78B3000
Out: serial@78B3000
Err: serial@78B3000
machid: 8010008
MMC Device 0 not found
[arc_board_setting]
[serial_register_init]
Hit any key to stop autoboot: 0

Net: MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd0b1
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0
IPQ807x# ftpboot initramfs.bin
Unknown command 'ftpboot' - try 'help'
IPQ807x# bootm
Wrong Image Format for bootm command
ERROR: can't get kernel image!
IPQ807x# tftpboot initramfs.bin
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.bin'.
Load address: 0x44000000
Loading: *>

:backhand_index_pointing_up: It stuck here with that command....

and with (setenv serverip 192.168.1.10
setenv ipaddr 192.168.1.1
tftpboot initramfs.bin
bootm)

it goes like....

<Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset), D - Delta, S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00158
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B - 201 - PBL, Start
B - 2736 - bootable_media_detect_entry, Start
B - 3448 - bootable_media_detect_success, Start
B - 3453 - elf_loader_entry, Start
B - 7629 - auth_hash_seg_entry, Start
B - 7874 - auth_hash_seg_exit, Start
B - 69754 - elf_segs_hash_verify_entry, Start
B - 132594 - PBL, End
B - 144448 - SBL1, Start
B - 196694 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B - 203191 - pm_device_init, Start
B - 326350 - PM_SET_VAL:Skip
D - 122671 - pm_device_init, Delta
B - 328759 - pm_driver_init, Start
D - 5368 - pm_driver_init, Delta
B - 335134 - clock_init, Start
D - 2104 - clock_init, Delta
B - 339129 - boot_flash_init, Start
D - 16531 - boot_flash_init, Delta
B - 359351 - boot_config_data_table_init, Start
D - 3995 - boot_config_data_table_init, Delta - (575 Bytes)
B - 366732 - Boot Setting : 0x00000618
B - 370849 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B - 377651 - sbl1_ddr_set_params, Start
B - 381463 - CPR configuration: 0x30c
B - 384940 - cpr_init, Start
B - 387716 - Rail:0 Mode: 5 Voltage: 792000
B - 392931 - CL CPR settled at 744000mV
B - 395737 - Rail:1 Mode: 5 Voltage: 880000
B - 399946 - Rail:1 Mode: 7 Voltage: 896000
D - 16531 - cpr_init, Delta
B - 406809 - Pre_DDR_clock_init, Start
B - 410835 - Pre_DDR_clock_init, End
B - 414129 - DDR Type : PCDDR3
B - 419893 - do ddr sanity test, Start
D - 1037 - do ddr sanity test, Delta
B - 424651 - DDR: Start of HAL DDR Boot Training
B - 429379 - DDR: End of HAL DDR Boot Training
B - 435052 - DDR: Checksum to be stored on flash is 1789927307
B - 445483 - Image Load, Start
D - 216001 - QSEE Image Loaded, Delta - (1376448 Bytes)
B - 661575 - Image Load, Start
D - 61 - SEC Image Loaded, Delta - (0 Bytes)
B - 669261 - Image Load, Start
D - 12017 - DEVCFG Image Loaded, Delta - (26008 Bytes)
B - 681370 - Image Load, Start
D - 23027 - RPM Image Loaded, Delta - (86584 Bytes)
B - 704489 - Image Load, Start
D - 88694 - APPSBL Image Loaded, Delta - (563504 Bytes)
B - 793305 - QSEE Execution, Start
D - 61 - QSEE Execution, Delta
B - 799100 - USB D+ check, Start
D - 30 - USB D+ check, Delta
B - 805505 - SBL1, End
D - 663344 - SBL1, Delta
S - Flash Throughput, 6902 KB/s (2053791 Bytes, 297550 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz

U-Boot 2016.01 (Mar 19 2021 - 12:06:59 +0800)

DRAM: smem ram ptable found: ver: 1 len: 4
1 GiB
NAND: Could not find nand_gpio in dts, using defaults
Not an ONFI device
ONFI probe failed
ID = 2691a398
Vendor = 98
Device = a3
qpic_nand: changing oobsize to 160 from 256 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
1024 MiB
MMC: sdhci: Node Not found, skipping initialization

PCI0 is not defined in the device tree
PCI1 is not defined in the device tree
In: serial@78B3000
Out: serial@78B3000
Err: serial@78B3000
machid: 8010008
MMC Device 0 not found
[arc_board_setting]
[serial_register_init]
Hit any key to stop autoboot: 0

Net: MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd0b1
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.bin
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.bin'.
Load address: 0x44000000
Loading: #
Got TFTP_DATA: TFTP remote port: changes from 69 to 51656
################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################
1.8 MiB/s
done
Bytes transferred = 13893632 (d40000 hex)
ipq807x_eth_halt: done
IPQ807x# >

Follow your own post ?

Use </> button when you paste cli output.

what's with you man! you already knw that won't help… as you can see I’m here after all! like you said before “only if you manage to boot the initramfs, from USB or TFTP”

that didn't work for me….

hey by the way u meant using </> like …

<setenv serverip 192.168.1.10
setenv ipaddr 192.168.1.1
tftpboot factory.ubi
bootm>

or

setenv serverip 192.168.1.10
setenv ipaddr 192.168.1.1
tftpboot factory.ubi
bootm

or

<setenv serverip 192.168.1.10> <setenv ipaddr 192.168.1.1>

None of this commands work for me , but curious, it start installing without </> :

setenv serverip 192.168.1.10
setenv ipaddr 192.168.1.1
tftpboot factory.ubi
bootm

Then one in the middle.

yeah, it worke like always…. but :backhand_index_pointing_down:

IPQ807x# <setenv serverip 192.168.1.10> <setenv ipaddr 192.168.1.1>
Unknown command '<setenv' - try 'help'
IPQ807x# <setenv serverip 192.168.1.10> <setenv ipaddr 192.168.1.1>
Unknown command '<setenv' - try 'help'
IPQ807x# <serverip192.168.1.10> <setenv ipaddr 192.168.1.1> <tftpboot faUnknown command '<setenv' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x#
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x#
IPQ807x# tftpboot factory.ubi
ipq807x_eth_halt: done
eth0 PHY0 Down Speed :10 Half duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 up Speed :1000 Full duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'factory.ubi'.
Load address: 0x44000000
Loading: #
Got TFTP_DATA: TFTP remote port: changes from 69 to 56149

1.4 MiB/s
done
Bytes transferred = 22806528 (15c0000 hex)
ipq807x_eth_halt: done
IPQ807x#

But after restarting the modem, as if … nothing has changed...

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset), D - Delta, S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00158
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B - 201 - PBL, Start
B - 2736 - bootable_media_detect_entry, Start
B - 3449 - bootable_media_detect_success, Start
B - 3453 - elf_loader_entry, Start
B - 7632 - auth_hash_seg_entry, Start
B - 7877 - auth_hash_seg_exit, Start
B - 69808 - elf_segs_hash_verify_entry, Start
B - 132647 - PBL, End
B - 144417 - SBL1, Start
B - 196237 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B - 202703 - pm_device_init, Start
B - 325587 - PM_SET_VAL:Skip
D - 122457 - pm_device_init, Delta
B - 327997 - pm_driver_init, Start
D - 5368 - pm_driver_init, Delta
B - 334371 - clock_init, Start
D - 2104 - clock_init, Delta
B - 338367 - boot_flash_init, Start
D - 16531 - boot_flash_init, Delta
B - 358588 - boot_config_data_table_init, Start
D - 4026 - boot_config_data_table_init, Delta - (575 Bytes)
B - 365969 - Boot Setting : 0x00000618
B - 370087 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B - 376888 - sbl1_ddr_set_params, Start
B - 380701 - CPR configuration: 0x30c
B - 384178 - cpr_init, Start
B - 386953 - Rail:0 Mode: 5 Voltage: 792000
B - 392169 - CL CPR settled at 744000mV
B - 394975 - Rail:1 Mode: 5 Voltage: 880000
B - 399153 - Rail:1 Mode: 7 Voltage: 896000
D - 16531 - cpr_init, Delta
B - 406046 - Pre_DDR_clock_init, Start
B - 410072 - Pre_DDR_clock_init, End
B - 413366 - DDR Type : PCDDR3
B - 419100 - do ddr sanity test, Start
D - 1067 - do ddr sanity test, Delta
B - 423950 - DDR: Start of HAL DDR Boot Training
B - 428586 - DDR: End of HAL DDR Boot Training
B - 434350 - DDR: Checksum to be stored on flash is 1789927307
B - 444690 - Image Load, Start
D - 215940 - QSEE Image Loaded, Delta - (1376448 Bytes)
B - 660721 - Image Load, Start
D - 61 - SEC Image Loaded, Delta - (0 Bytes)
B - 668407 - Image Load, Start
D - 12017 - DEVCFG Image Loaded, Delta - (26008 Bytes)
B - 680485 - Image Load, Start
D - 23028 - RPM Image Loaded, Delta - (86584 Bytes)
B - 703604 - Image Load, Start
D - 88694 - APPSBL Image Loaded, Delta - (563504 Bytes)
B - 792420 - QSEE Execution, Start
D - 61 - QSEE Execution, Delta
B - 798246 - USB D+ check, Start
D - 0 - USB D+ check, Delta
B - 804620 - SBL1, End
D - 662521 - SBL1, Delta
S - Flash Throughput, 6902 KB/s (2053791 Bytes, 297549 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz

U-Boot 2016.01 (Mar 19 2021 - 12:06:59 +0800)

DRAM: smem ram ptable found: ver: 1 len: 4
1 GiB
NAND: Could not find nand_gpio in dts, using defaults
Not an ONFI device
ONFI probe failed
ID = 2691a398
Vendor = 98
Device = a3
qpic_nand: changing oobsize to 160 from 256 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
1024 MiB
MMC: sdhci: Node Not found, skipping initialization

PCI0 is not defined in the device tree
PCI1 is not defined in the device tree
In: serial@78B3000
Out: serial@78B3000
Err: serial@78B3000
machid: 8010008
MMC Device 0 not found
[arc_board_setting]
[serial_register_init]
[CheckResetToDefaultButton(277)] reset button is pressed
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 1
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 2
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 3
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 4
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 5
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 6
[CheckResetToDefaultButton(293)] nResetButtonPressed:1, nCurrentWaitTime: 7
[CheckResetToDefaultButton(293)] nResetButtonPressed:0, nCurrentWaitTime: 8
Hit any key to stop autoboot: 0
starting USB...
USB0: Register 2000140 NbrPorts 2
Starting the controller
USB XHCI 1.10
scanning bus 0 for devices... 1 USB Device(s) found
USB1: Register 2000140 NbrPorts 2
Starting the controller
USB XHCI 1.10
scanning bus 1 for devices... 1 USB Device(s) found
** Bad device usb 0 **
[do_boot_unsignedimg(887)] debug:0
setenv - set environment variables

Net: MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd0b1
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0

Net: MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
, eth0
IPQ807x#

Nothing is supposed to change, yet.
Plus, you never ran bootm.

Try help in U-Boot to understand what you're actually doing.

You don't have a modem, you have a router with a built in modem.
I hope you restarted the router.

When pasting the serial output, feel free to omit 99% of the ### from when the image is transferred.

but I copied the commands like this….

setenv serverip 192.168.1.10
setenv ipaddr 192.168.1.1
tftpboot factory.ubi
bootm

and as you can see bootm is in it…

so, it’s possible to reset the router instead of built in modem? or …. u just want me to use router instead of modem in comments!

IPQ807x# help
? - alias for 'help'
aq_load_fw- LOAD aq-fw-binary
aq_phy_restart- Restart Aquantia phy
arc_fuseipq- arcadyan fuse QFPROM registers from memory

arc_manuf- arcadyan manufacturing board data utility

base - print or set address offset
bdinfo - print Board Info structure
bootipq - bootipq from flash device
bootm - boot application image from memory
bootp - boot image via network using BOOTP/TFTP protocol
bootz - boot Linux zImage image from memory
canary - test stack canary
chpart - change active partition
cmp - memory compare
cp - memory copy
crc32 - checksum calculation
dcache - enable or disable data cache
dhcp - boot image via network using DHCP/TFTP protocol
dm - Driver model low level access
echo - echo args to console
env - environment handling commands
erase - erase FLASH memory
exectzt - execute TZT

exit - exit script
false - do nothing, unsuccessfully
fdt - flattened device tree utility commands
flash - flash part_name
flash part_name load_addr file_size

flasherase- flerase part_name

flinfo - print FLASH memory information
fuseipq - fuse QFPROM registers from memory

go - start application at address 'addr'
help - print command description/usage
i2c - I2C sub-system
icache - enable or disable instruction cache
imxtract- extract a part of a multi-image
ipq_mdio- IPQ mdio utility commands
is_sec_boot_enabled- check secure boot fuse is enabled or not

itest - return true/false on integer compare
loop - infinite loop on address range
md - memory display
mii - MII utility commands
mm - memory modify (auto-incrementing address)
mmc - MMC sub system
mmcinfo - display MMC info
mtdparts- define flash/nand partitions
mtest - simple RAM read/write test
mw - memory write (fill)
nand - NAND sub-system
nboot - boot from NAND device
nm - memory modify (constant address)
pci - list and access PCI Configuration Space
ping - send ICMP ECHO_REQUEST to network host
printenv- print environment variables
protect - enable or disable FLASH write protection
reset - Perform RESET of the CPU
run - run commands in an environment variable
runmulticore- Enable and schedule secondary cores
saveenv - save environment variables to persistent storage
secure_authenticate- authenticate the signed image

setenv - set environment variables
sf - SPI flash sub-system
showvar - print local hushshell variables
sleep - delay execution for some time
smeminfo- print SMEM FLASH information
source - run script from memory
test - minimal test like /bin/sh
tftpboot- boot image via network using TFTP protocol
tftpput - TFTP put command, for uploading files to a server
true - do nothing, successfully
uart - UART sub-system
ubi - ubi commands
usb - USB sub-system
usbboot - boot from USB device
version - print monitor, compiler and linker version

The help command was for you, not us.

Try

tftpboot 0x86000000 factory.ubi
bootm

use the </> button when you paste cli/serial output

I also assume factory.ubi actually is an initramfs.

you sure about the address cause it says:


Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00158
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B -       201 - PBL, Start
B -      2736 - bootable_media_detect_entry, Start
B -      3449 - bootable_media_detect_success, Start
B -      3453 - elf_loader_entry, Start
B -      7632 - auth_hash_seg_entry, Start
B -      7877 - auth_hash_seg_exit, Start
B -     69779 - elf_segs_hash_verify_entry, Start
B -    132619 - PBL, End
B -    147955 - SBL1, Start
B -    201788 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B -    208498 - pm_device_init, Start
B -    332236 - PM_SET_VAL:Skip
D -    123159 - pm_device_init, Delta
B -    334646 - pm_driver_init, Start
D -      5368 - pm_driver_init, Delta
B -    341020 - clock_init, Start
D -      2104 - clock_init, Delta
B -    345016 - boot_flash_init, Start
D -     16531 - boot_flash_init, Delta
B -    365237 - boot_config_data_table_init, Start
D -      3995 - boot_config_data_table_init, Delta - (575 Bytes)
B -    372618 - Boot Setting :  0x00000618
B -    376736 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B -    383537 - sbl1_ddr_set_params, Start
B -    387350 - CPR configuration: 0x30c
B -    390827 - cpr_init, Start
B -    393602 - Rail:0 Mode: 5 Voltage: 792000
B -    398818 - CL CPR settled at 744000mV
B -    401624 - Rail:1 Mode: 5 Voltage: 880000
B -    405802 - Rail:1 Mode: 7 Voltage: 896000
D -     16531 - cpr_init, Delta
B -    412695 - Pre_DDR_clock_init, Start
B -    416721 - Pre_DDR_clock_init, End
B -    420015 - DDR Type : PCDDR3
B -    425749 - do ddr sanity test, Start
D -      1067 - do ddr sanity test, Delta
B -    430507 - DDR: Start of HAL DDR Boot Training
B -    435265 - DDR: End of HAL DDR Boot Training
B -    440938 - DDR: Checksum to be stored on flash is 1789927307
B -    451339 - Image Load, Start
D -    216031 - QSEE Image Loaded, Delta - (1376448 Bytes)
B -    667462 - Image Load, Start
D -        61 - SEC Image Loaded, Delta - (0 Bytes)
B -    675148 - Image Load, Start
D -     12017 - DEVCFG Image Loaded, Delta - (26008 Bytes)
B -    687256 - Image Load, Start
D -     23028 - RPM Image Loaded, Delta - (86584 Bytes)
B -    710345 - Image Load, Start
D -     88694 - APPSBL Image Loaded, Delta - (563504 Bytes)
B -    799191 - QSEE Execution, Start
D -        61 - QSEE Execution, Delta
B -    804986 - USB D+ check, Start
D -         0 - USB D+ check, Delta
B -    811391 - SBL1, End
D -    665724 - SBL1, Delta
S - Flash Throughput, 6905 KB/s  (2053791 Bytes,  297397 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz


U-Boot 2016.01 (Mar 19 2021 - 12:06:59 +0800)

DRAM:  smem ram ptable found: ver: 1 len: 4
1 GiB
NAND:  Could not find nand_gpio in dts, using defaults
Not an ONFI device
ONFI probe failed
ID = 2691a398
Vendor = 98
Device = a3
qpic_nand: changing oobsize to 160 from 256 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
1024 MiB
MMC:   sdhci: Node Not found, skipping initialization

PCI0 is not defined in the device tree
PCI1 is not defined in the device tree
In:    serial@78B3000
Out:   serial@78B3000
Err:   serial@78B3000
machid: 8010008
MMC Device 0 not found
[arc_board_setting]
[serial_register_init]
Hit any key to stop autoboot:  0

Net:   MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd0b1
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0
IPQ807x# tftpboot 0x86000000 initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done

I just copied the…

tftpboot 0x86000000 initramfs.itb

bootm

I'm not, trial and error.

But if you served the wrong file over tftp, retry without the mem address.

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset), D - Delta, S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00158
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B - 201 - PBL, Start
B - 2736 - bootable_media_detect_entry, Start
B - 3449 - bootable_media_detect_success, Start
B - 3453 - elf_loader_entry, Start
B - 7632 - auth_hash_seg_entry, Start
B - 7877 - auth_hash_seg_exit, Start
B - 69779 - elf_segs_hash_verify_entry, Start
B - 132619 - PBL, End
B - 147955 - SBL1, Start
B - 201788 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B - 208498 - pm_device_init, Start
B - 332236 - PM_SET_VAL:Skip
D - 123159 - pm_device_init, Delta
B - 334646 - pm_driver_init, Start
D - 5368 - pm_driver_init, Delta
B - 341020 - clock_init, Start
D - 2104 - clock_init, Delta
B - 345016 - boot_flash_init, Start
D - 16531 - boot_flash_init, Delta
B - 365237 - boot_config_data_table_init, Start
D - 3995 - boot_config_data_table_init, Delta - (575 Bytes)
B - 372618 - Boot Setting : 0x00000618
B - 376736 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B - 383537 - sbl1_ddr_set_params, Start
B - 387350 - CPR configuration: 0x30c
B - 390827 - cpr_init, Start
B - 393602 - Rail:0 Mode: 5 Voltage: 792000
B - 398818 - CL CPR settled at 744000mV
B - 401624 - Rail:1 Mode: 5 Voltage: 880000
B - 405802 - Rail:1 Mode: 7 Voltage: 896000
D - 16531 - cpr_init, Delta
B - 412695 - Pre_DDR_clock_init, Start
B - 416721 - Pre_DDR_clock_init, End
B - 420015 - DDR Type : PCDDR3
B - 425749 - do ddr sanity test, Start
D - 1067 - do ddr sanity test, Delta
B - 430507 - DDR: Start of HAL DDR Boot Training
B - 435265 - DDR: End of HAL DDR Boot Training
B - 440938 - DDR: Checksum to be stored on flash is 1789927307
B - 451339 - Image Load, Start
D - 216031 - QSEE Image Loaded, Delta - (1376448 Bytes)
B - 667462 - Image Load, Start
D - 61 - SEC Image Loaded, Delta - (0 Bytes)
B - 675148 - Image Load, Start
D - 12017 - DEVCFG Image Loaded, Delta - (26008 Bytes)
B - 687256 - Image Load, Start
D - 23028 - RPM Image Loaded, Delta - (86584 Bytes)
B - 710345 - Image Load, Start
D - 88694 - APPSBL Image Loaded, Delta - (563504 Bytes)
B - 799191 - QSEE Execution, Start
D - 61 - QSEE Execution, Delta
B - 804986 - USB D+ check, Start
D - 0 - USB D+ check, Delta
B - 811391 - SBL1, End
D - 665724 - SBL1, Delta
S - Flash Throughput, 6905 KB/s (2053791 Bytes, 297397 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz

U-Boot 2016.01 (Mar 19 2021 - 12:06:59 +0800)

DRAM: smem ram ptable found: ver: 1 len: 4
1 GiB
NAND: Could not find nand_gpio in dts, using defaults
Not an ONFI device
ONFI probe failed
ID = 2691a398
Vendor = 98
Device = a3
qpic_nand: changing oobsize to 160 from 256 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
1024 MiB
MMC: sdhci: Node Not found, skipping initialization

PCI0 is not defined in the device tree
PCI1 is not defined in the device tree
In: serial@78B3000
Out: serial@78B3000
Err: serial@78B3000
machid: 8010008
MMC Device 0 not found
[arc_board_setting]
[serial_register_init]
Hit any key to stop autoboot: 0

Net: MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd0b1
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0
IPQ807x# tftpboot 0x86000000 initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# tftpboot 0x86000000 initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# tftpboot 0x86000000 initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# tftpboot 0x86000000 initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# tftpboot 0x86000000 initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.2; our IP address is 192.168.1.254
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x#
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.itb
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.itb'.
Load address: 0x86000000

Error specified load address not allowed
ipq807x_eth_halt: done
IPQ807x# ootm
Unknown command 'ootm' - try 'help'
IPQ807x# reset
resetting ...

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset), D - Delta, S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00158
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B - 201 - PBL, Start
B - 2736 - bootable_media_detect_entry, Start
B - 3448 - bootable_media_detect_success, Start
B - 3452 - elf_loader_entry, Start
B - 7629 - auth_hash_seg_entry, Start
B - 7874 - auth_hash_seg_exit, Start
B - 69765 - elf_segs_hash_verify_entry, Start
B - 132605 - PBL, End
B - 222619 - SBL1, Start
B - 302651 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B - 312625 - pm_device_init, Start
B - 496021 - PM_SET_VAL:Skip
D - 181414 - pm_device_init, Delta
B - 498431 - pm_driver_init, Start
D - 5368 - pm_driver_init, Delta
B - 504805 - clock_init, Start
D - 2104 - clock_init, Delta
B - 508801 - boot_flash_init, Start
D - 16531 - boot_flash_init, Delta
B - 529022 - boot_config_data_table_init, Start
D - 4026 - boot_config_data_table_init, Delta - (575 Bytes)
B - 536403 - Boot Setting : 0x00000618
B - 540521 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B - 547322 - sbl1_ddr_set_params, Start
B - 551135 - CPR configuration: 0x30c
B - 554612 - cpr_init, Start
B - 557387 - Rail:0 Mode: 5 Voltage: 792000
B - 562603 - CL CPR settled at 744000mV
B - 565409 - Rail:1 Mode: 5 Voltage: 880000
B - 569618 - Rail:1 Mode: 7 Voltage: 896000
D - 16531 - cpr_init, Delta
B - 576480 - Pre_DDR_clock_init, Start
B - 580506 - Pre_DDR_clock_init, End
B - 583800 - DDR Type : PCDDR3
B - 589534 - do ddr sanity test, Start
D - 1037 - do ddr sanity test, Delta
B - 594384 - DDR: Start of HAL DDR Boot Training
B - 599020 - DDR: End of HAL DDR Boot Training
B - 604784 - DDR: Checksum to be stored on flash is 1789927307
B - 615124 - Image Load, Start
D - 215940 - QSEE Image Loaded, Delta - (1376448 Bytes)
B - 831155 - Image Load, Start
D - 61 - SEC Image Loaded, Delta - (0 Bytes)
B - 838841 - Image Load, Start
D - 12017 - DEVCFG Image Loaded, Delta - (26008 Bytes)
B - 850950 - Image Load, Start
D - 23027 - RPM Image Loaded, Delta - (86584 Bytes)
B - 874069 - Image Load, Start
D - 88663 - APPSBL Image Loaded, Delta - (563504 Bytes)
B - 962885 - QSEE Execution, Start
D - 91 - QSEE Execution, Delta
B - 968680 - USB D+ check, Start
D - 0 - USB D+ check, Delta
B - 975085 - SBL1, End
D - 754753 - SBL1, Delta
S - Flash Throughput, 6903 KB/s (2053791 Bytes, 297488 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz

U-Boot 2016.01 (Mar 19 2021 - 12:06:59 +0800)

DRAM: smem ram ptable found: ver: 1 len: 4
1 GiB
NAND: Could not find nand_gpio in dts, using defaults
Not an ONFI device
ONFI probe failed
ID = 2691a398
Vendor = 98
Device = a3
qpic_nand: changing oobsize to 160 from 256 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
1024 MiB
MMC: sdhci: Node Not found, skipping initialization

PCI0 is not defined in the device tree
PCI1 is not defined in the device tree
In: serial@78B3000
Out: serial@78B3000
Err: serial@78B3000
machid: 8010008
MMC Device 0 not found
[arc_board_setting]
[serial_register_init]
Hit any key to stop autoboot: 0

Net: MAC0 addr:ec:6c:9a:b7:f4:68
PHY ID1: 0x4d
PHY ID2: 0xd0b1
PHY ID1: 0x4d
PHY ID2: 0xd101
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0
IPQ807x# setenv serverip 192.168.1.10
IPQ807x# setenv ipaddr 192.168.1.1
IPQ807x# tftpboot initramfs.ubi
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'initramfs.ubi'.
Load address: 0x44000000
Loading: #
Got TFTP_DATA: TFTP remote port: changes from 69 to 50522
######
1.5 MiB/s
done
Bytes transferred = 22806528 (15c0000 hex)
ipq807x_eth_halt: done
IPQ807x# tftpboot 0x44000000 factory.ubi
ipq807x_eth_halt: done
eth0 PHY0 up Speed :1000 Full duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 Down Speed :10 Half duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
eth0 PHY5 Down Speed :10 Half duplex
ipq807x_eth_init: done
Using eth0 device
TFTP from server 192.168.1.10; our IP address is 192.168.1.1
Filename 'factory.ubi'.
Load address: 0x44000000
Loading: #
Got TFTP_DATA: TFTP remote port: changes from 69 to 55587
#####
1.6 MiB/s
done
Bytes transferred = 22806528 (15c0000 hex)
ipq807x_eth_halt: done
IPQ807x#

Is usb boot enabled on your router?

I really don't remember whether I’d activated it or no t ... how should I find out?

but when I connect a USB to the router with the appropriate Initramfs, it shows the following error ...

setenv bootusb 'usb start && usbboot 0x44000000 0 && bootm 0x44000000'
setenv bootcmd 'run bootusb; bootipq'
saveenv

and then

IPQ807x# setenv bootusb 'usb start && usbboot 0x44000000 0 && bootm 0x44000000'
IPQ807x# setenv bootcmd 'run bootusb; bootipq'
IPQ807x# saveenv
Saving Environment to NAND...
Erasing NAND...
Erasing at 0xd40000 -- 100% complete.
Writing to NAND... OK

IPQ807x# usb startstarting USB...USB0:   Register 2000140 NbrPorts 2Starting the controllerUSB XHCI 1.10scanning bus 0 for devices... cannot reset port 1!?2 USB Device(s) foundUSB1:   Register 2000140 NbrPorts 2Starting the controllerUSB XHCI 1.10scanning bus 1 for devices... 1 USB Device(s) foundIPQ807x# usbboot 0x44000000 0
Loading from usb device 0, partition 1: Name: usbda1  Type: U-Boot** Unknown image typeIPQ807x# bootm 0x44000000Wrong Image Format for bootm commandERROR: can't get kernel image!IPQ807x#

Initramfs-uImage.itb link is:

I also test it with factory.ubi and sysupgrade.bin…

IPQ807x# usb startIPQ807x# usbboot 0x44000000 0
Loading from usb device 0, partition 1: Name: usbda1  Type: U-Boot** Unknown image typeIPQ807x# bootm 0x44000000Wrong Image Format for bootm commandERROR: can't get kernel image!

should be a way ....

IPQ807x# usb start
IPQ807x# usbboot 0x44000000 0
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
WARN halted endpoint
** Can't read partition table on 0:0 **
** Invalid partition 1 **
IPQ807x# bootm 0x44000000
Wrong Image Format for bootm command
ERROR: can't get kernel image!

Factory or sysupgrade images will not work. Only the kernel image will work.

https://downloads.openwrt.org/releases/24.10.3/targets/qualcommax/ipq807x/openwrt-24.10.3-qualcommax-ipq807x-arcadyan_aw1000-initramfs-uImage.itb

This will work.

Doing this once is enough. This will enable USB boot. The router will check USB devices for compatible kernel images and boot from them

Since you already have UART connected, you can also check this guide for expanding device storage. USB boot steps are available under the recovery options

Hey bro, I really can’t thank you enough, the router finally booted after a few months ... :smiley: :folded_hands:

can you please give me a link for latest stable firmware, thanks again