Archer A7 v5 bricked? What now?

I was able to install and configure OpenWRT for a TAP-Bridge VPN, but when I tried to change the default IP in Luci, it would not save, and stopped working. I tried using TFTP to install first the TPL stock firmware and then the factory OpenWRT, etc but nothing installs now and there is no response in Tftpd32 or 64 (which worked before) when trying to install firmware. I installed USB->UART interface, (boot sequence shown below) but cannot get to a point which will accept any input. Nothing happens when I press the reset button. I tried to stop autoboot in 2 places and the flag turns from 1 to 0 but nothing else changes. I tried entering 'f' and 'enter' when it asks if I want 'failsafe' but it just proceeds as if nothing was done. Is there anything else, or time to buy a new router?

▒
U-Boot 1.1.4-g14abe3ec-dirty (Aug 10 2018 - 16:06:27)

ap152 - Dragonfly 1.0

DRAM:  128 MB
Top of RAM usable for U-Boot at: 88000000
Reserving 397k for U-Boot at: 87f9c000
Reserving 16448k for malloc() at: 86f8c000
Reserving 44 Bytes for Board Info at: 86f8bfd4
Reserving 36 Bytes for Global Data at: 86f8bfb0
Reserving 128k for boot params() at: 86f6bfb0
Stack Pointer at: 86f6bf98
Now running in RAM - U-Boot at: 87f9c000
Flash Manuf Id 0xef, DeviceId0 0x40, DeviceId1 0x18
flash size 16MB, sector count = 256
Flash: 16 MB
Using default environment

In:    serial
Out:   serial
Err:   serial
Net:   ath_gmac_enet_initialize...
No valid address in Flash. Using fixed address
ath_gmac_enet_initialize: reset mask:c02200
athr_mgmt_init ::done
Dragonfly  ----> S17 PHY *
athrs17_reg_init: complete
SGMII in forced mode
athr_gmac_sgmii_setup SGMII done
: cfg1 0x80000000 cfg2 0x7114
eth0: 00:03:7f:09:0b:ad
eth0 up
eth0
Setting 0x181162c0 to 0x40802100
factory boot check integer ok.

factory boot load fs uboot len 131072 to addr 0x80010000.
Hit any key to stop autoboot:  0
## Starting application at 0x80010000 ...


U-Boot 1.1.4-g7732fa90-dirty (Sep 22 2021 - 22:26:42)

ap152 - Dragonfly 1.0

DRAM:  128 MB
Top of RAM usable for U-Boot at: 88000000
Reserving 125k for U-Boot at: 87fe0000
Reserving 16448k for malloc() at: 86fd0000
Reserving 44 Bytes for Board Info at: 86fcffd4
Reserving 36 Bytes for Global Data at: 86fcffb0
Reserving 128k for boot params() at: 86faffb0
Stack Pointer at: 86faff98
Now running in RAM - U-Boot at: 87fe0000
Flash Manuf Id 0xef, DeviceId0 0x40, DeviceId1 0x18
flash size 16MB, sector count = 256
Flash: 16 MB
Using default environment

In:    serial
Out:   serial
Err:   serial
Net:   ath_gmac_enet_initialize...
No valid address in Flash. Using fixed address
ath_gmac_enet_initialize: reset mask:c02200
athr_mgmt_init ::done
Dragonfly  ----> S17 PHY *
athrs17_reg_init: complete
SGMII in forced mode
athr_gmac_sgmii_setup SGMII done
: cfg1 0x80000000 cfg2 0x7114
eth0: 00:03:7f:09:0b:ad
eth0 up
eth0
Setting 0x181162c0 to 0x40802100
Hit any key to stop autoboot:  0
## Booting image at 9f040000 ...
   Image Name:   MIPS OpenWrt Linux-5.4.188
   Created:      2022-04-16  12:59:34 UTC
   Image Type:   MIPS Linux Kernel Image (lzma compressed)
   Data Size:    2049960 Bytes =  2 MB
   Load Address: 80060000
   Entry Point:  80060000
   Verifying Checksum at 0x9f040040 ...OK
   Uncompressing Kernel Image ... OK
No initrd
## Transferring control to Linux (at address 80060000) ...
## Giving linux memsize in bytes, 134217728

Starting kernel ...

[    0.000000] Linux version 5.4.188 (builder@buildhost) (gcc version 8.4.0 (OpenWrt GCC 8.4.0 r16554-1d4dea6d4f)) #0 Sat Apr 16 12:59:34 2022
[    0.000000] printk: bootconsole [early0] enabled
[    0.000000] CPU0 revision is: 00019750 (MIPS 74Kc)
[    0.000000] MIPS: machine is TP-Link Archer A7 v5
[    0.000000] SoC: Qualcomm Atheros QCA956X ver 1 rev 0
[    0.000000] Initrd not found or empty - disabling initrd
[    0.000000] Primary instruction cache 64kB, VIPT, 4-way, linesize 32 bytes.
[    0.000000] Primary data cache 32kB, 4-way, VIPT, cache aliases, linesize 32 bytes
[    0.000000] Zone ranges:
[    0.000000]   Normal   [mem 0x0000000000000000-0x0000000007ffffff]
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000000000000-0x0000000007ffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000000000000-0x0000000007ffffff]
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 32480
[    0.000000] Kernel command line: console=ttyS0,115200n8 rootfstype=squashfs,jffs2
[    0.000000] Dentry cache hash table entries: 16384 (order: 4, 65536 bytes, linear)
[    0.000000] Inode-cache hash table entries: 8192 (order: 3, 32768 bytes, linear)
[    0.000000] Writing ErrCtl register=00000000
[    0.000000] Readback ErrCtl register=00000000
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] Memory: 122180K/131072K available (5259K kernel code, 192K rwdata, 688K rodata, 1212K init, 205K bss, 8892K reserved, 0K cma-reserved)
[    0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
[    0.000000] NR_IRQS: 51
[    0.000000] random: get_random_bytes called from 0x80661a28 with crng_init=0
[    0.000000] CPU clock: 775.000 MHz
[    0.000000] clocksource: MIPS: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 4932285024 ns
[    0.000006] sched_clock: 32 bits at 387MHz, resolution 2ns, wraps every 5541893118ns
[    0.008225] Calibrating delay loop... 385.02 BogoMIPS (lpj=770048)
[    0.046713] pid_max: default: 32768 minimum: 301
[    0.051716] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes, linear)
[    0.059431] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes, linear)
[    0.071725] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
[    0.082016] futex hash table entries: 256 (order: -1, 3072 bytes, linear)
[    0.089297] pinctrl core: initialized pinctrl subsystem
[    0.097175] NET: Registered protocol family 16
[    0.128365] clocksource: Switched to clocksource MIPS
[    0.134628] thermal_sys: Registered thermal governor 'step_wise'
[    0.134982] NET: Registered protocol family 2
[    0.146092] IP idents hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.154437] tcp_listen_portaddr_hash hash table entries: 512 (order: 0, 4096 bytes, linear)
[    0.163317] TCP established hash table entries: 1024 (order: 0, 4096 bytes, linear)
[    0.171406] TCP bind hash table entries: 1024 (order: 0, 4096 bytes, linear)
[    0.178851] TCP: Hash tables configured (established 1024 bind 1024)
[    0.185678] UDP hash table entries: 256 (order: 0, 4096 bytes, linear)
[    0.192616] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes, linear)
[    0.200260] NET: Registered protocol family 1
[    0.204915] PCI: CLS 0 bytes, default 32
[    0.212661] workingset: timestamp_bits=14 max_order=15 bucket_order=1
[    0.225768] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.231959] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.255247] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251)
[    0.266530] pinctrl-single 1804002c.pinmux: 544 pins, size 68
[    0.273121] gpio-export gpio-export: 1 gpio(s) exported
[    0.279430] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.288287] printk: console [ttyS0] disabled
[    0.292880] 18020000.uart: ttyS0 at MMIO 0x18020000 (irq = 9, base_baud = 1562500) is a 16550A
[    0.301989] printk: console [ttyS0] enabled
[    0.301989] printk: console [ttyS0] enabled
[    0.311047] printk: bootconsole [early0] disabled
[    0.311047] printk: bootconsole [early0] disabled
[    0.339909] spi-nor spi0.0: w25q128 (16384 Kbytes)
[    0.344935] 7 fixed-partitions partitions found on MTD device spi0.0
[    0.351507] Creating 7 MTD partitions on "spi0.0":
[    0.356483] 0x000000000000-0x000000020000 : "factory-uboot"
[    0.363114] 0x000000020000-0x000000040000 : "u-boot"
[    0.369138] 0x000000040000-0x000000f00000 : "firmware"
[    0.377899] 2 uimage-fw partitions found on MTD device firmware
[    0.384053] Creating 2 MTD partitions on "firmware":
[    0.389201] 0x000000000000-0x000000200000 : "kernel"
[    0.395131] 0x000000200000-0x000000ec0000 : "rootfs"
[    0.401123] mtd: device 4 (rootfs) set to be root filesystem
[    0.408769] 1 squashfs-split partitions found on MTD device rootfs
[    0.415207] 0x000000580000-0x000000ec0000 : "rootfs_data"
[    0.421633] 0x000000f40000-0x000000f60000 : "info"
[    0.427460] 0x000000f60000-0x000000fb0000 : "config"
[    0.433477] 0x000000fc0000-0x000000fd0000 : "partition-table"
[    0.440338] 0x000000ff0000-0x000001000000 : "art"
[    1.099802] switch0: Atheros AR8337 rev. 2 switch registered on mdio.0
[    1.148358] random: fast init done
[    1.687852] ag71xx 19000000.eth: connected to PHY at mdio.0:00 [uid=004dd036, driver=Atheros AR8216/AR8236/AR8316]
[    1.699112] eth0: Atheros AG71xx at 0xb9000000, irq 4, mode: sgmii
[    1.705870] i2c /dev entries driver
[    1.712464] NET: Registered protocol family 10
[    1.723235] Segment Routing with IPv6
[    1.727191] NET: Registered protocol family 17
[    1.731866] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.745257] 8021q: 802.1Q VLAN Support v1.8
[    1.750405] PCI host bridge /ahb/pcie-controller@18250000 ranges:
[    1.756773]  MEM 0x0000000012000000..0x0000000013ffffff
[    1.762185]   IO 0x0000000000000000..0x0000000000000000
[    1.767748] PCI host bridge to bus 0000:00
[    1.772020] pci_bus 0000:00: root bus resource [mem 0x12000000-0x13ffffff]
[    1.779124] pci_bus 0000:00: root bus resource [io  0x0000]
[    1.784893] pci_bus 0000:00: root bus resource [??? 0x00000000 flags 0x0]
[    1.791910] pci_bus 0000:00: No busn resource found for root bus, will use [bus 00-ff]
[    1.800133] pci 0000:00:00.0: [168c:003c] type 00 class 0x028000
[    1.806397] pci 0000:00:00.0: reg 0x10: [mem 0x00000000-0x001fffff 64bit]
[    1.813462] pci 0000:00:00.0: reg 0x30: [mem 0x00000000-0x0000ffff pref]
[    1.820457] pci 0000:00:00.0: supports D1 D2
[    1.825857] pci_bus 0000:00: busn_res: [bus 00-ff] end is updated to 00
[    1.832734] pci 0000:00:00.0: BAR 0: assigned [mem 0x12000000-0x121fffff 64bit]
[    1.840309] pci 0000:00:00.0: BAR 6: assigned [mem 0x12200000-0x1220ffff pref]
[    1.849232] hctosys: unable to open rtc device (rtc0)
[    1.860754] VFS: Mounted root (squashfs filesystem) readonly on device 31:4.
[    1.874711] Freeing unused kernel memory: 1212K
[    1.879416] This architecture does not have kernel memory protection.
[    1.886067] Run /sbin/init as init process
[    2.445781] init: Console is alive
[    2.449574] init: - watchdog -
[    3.609272] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    3.654741] usbcore: registered new interface driver usbfs
[    3.660546] usbcore: registered new interface driver hub
[    3.666140] usbcore: registered new device driver usb
[    3.677043] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
[    3.685338] ehci-fsl: Freescale EHCI Host controller driver
[    3.692603] ehci-platform: EHCI generic platform driver
[    3.698295] ehci-platform 1b000000.usb: EHCI Host Controller
[    3.704215] ehci-platform 1b000000.usb: new USB bus registered, assigned bus number 1
[    3.712445] ehci-platform 1b000000.usb: irq 13, io mem 0x1b000000
[    3.732378] ehci-platform 1b000000.usb: USB 2.0 started, EHCI 1.00
[    3.739599] hub 1-0:1.0: USB hub found
[    3.743871] hub 1-0:1.0: 1 port detected
[    3.750645] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    3.759422] init: - preinit -
[    5.125607] random: jshn: uninitialized urandom read (4 bytes read)
[    5.243193] random: jshn: uninitialized urandom read (4 bytes read)
[    5.473330] random: jshn: uninitialized urandom read (4 bytes read)
[    6.766253] eth0: link up (1000Mbps/Full duplex)
[    6.776509] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
[    6.788503] IPv6: ADDRCONF(NETDEV_CHANGE): eth0.1: link becomes ready
[    6.824691] urandom_read: 4 callbacks suppressed
[    6.824698] random: procd: uninitialized urandom read (4 bytes read)
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
[   11.053770] jffs2: notice: (597) jffs2_build_xattr_subsystem: complete building xattr subsystem, 97 of xdatum (43 unchecked, 51 orphan) and 128 of xref (51 dead, 0 orphan) found.
[   11.072933] mount_root: switching to jffs2 overlay
[   11.081608] overlayfs: upper fs does not support tmpfile.
[   11.094834] urandom-seed: Seeding with /etc/urandom.seed
[   11.184001] eth0: link down
[   11.208231] procd: - early -
[   11.211426] procd: - watchdog -
[   11.801711] procd: - watchdog -
[   11.806341] procd: - ubus -
[   11.869664] random: ubusd: uninitialized urandom read (4 bytes read)
[   11.878295] random: ubusd: uninitialized urandom read (4 bytes read)
[   11.890781] procd: - init -
Please press Enter to activate this console.
[   12.811683] kmodloader: loading kernel modules from /etc/modules.d/*
[   12.865104] tun: Universal TUN/TAP device driver, 1.6
[   12.939650] Loading modules backported from Linux version v5.10.110-0-g3238bffaf992
[   12.947622] Backport generated by backports.git v5.10.110-1-0-g1fbde860
[   13.013008] xt_time: kernel timezone is -0000
[   13.164632] urngd: v1.0.2 started.
[   13.244802] PPP generic driver version 2.4.2
[   13.257132] NET: Registered protocol family 24
[   13.335243] ath10k 5.10 driver, optimized for CT firmware, probing pci device: 0x3c.
[   13.361227] ath10k_pci 0000:00:00.0: enabling device (0000 -> 0002)
[   13.367911] ath10k_pci 0000:00:00.0: pci irq legacy oper_irq_mode 1 irq_mode 0 reset_mode 0
[   13.397051] crng init done
[   16.743466] ath10k_pci 0000:00:00.0: qca988x hw2.0 target 0x4100016c chip_id 0x043202ff sub 0000:0000
[   16.753047] ath10k_pci 0000:00:00.0: kconfig debug 0 debugfs 1 tracing 0 dfs 1 testmode 0
[   16.765279] ath10k_pci 0000:00:00.0: firmware ver 10.1-ct-8x-__fW-022-ecad3248 api 2 features wmi-10.x,has-wmi-mgmt-tx,mfp,txstatus-noack,wmi-10.x-CT,ratemask-CT,txrate-CT,get-temp-CT,tx-rc-CT,cust-stats-CT,retry-gt2-CT,txrate2-CT,beacon-cb-CT,wmi-block-ack-CT crc32 3e4cf97f
[   17.189294] ath10k_pci 0000:00:00.0: board_file api 1 bmi_id N/A crc32 bebc7c08
[   18.155300] ath10k_pci 0000:00:00.0: 10.1 wmi init: vdevs: 16  peers: 127  tid: 256
[   18.172097] ath10k_pci 0000:00:00.0: wmi print 'P 128 V 8 T 410'
[   18.178556] ath10k_pci 0000:00:00.0: wmi print 'msdu-desc: 1424  sw-crypt: 0 ct-sta: 0'
[   18.186850] ath10k_pci 0000:00:00.0: wmi print 'alloc rem: 24984 iram: 38672'
[   18.236889] ath10k_pci 0000:00:00.0: htt-ver 2.1 wmi-op 2 htt-op 2 cal file max-sta 128 raw 0 hwcrypto 1
[   18.249786] ath10k_pci 0000:00:00.0: NOTE:  Firmware DBGLOG output disabled in debug_mask: 0x10000000
[   18.456083] ieee80211 phy1: Atheros AR9561 Rev:0 mem=0xb8100000, irq=2
[   18.533479] kmodloader: done loading kernel modules from /etc/modules.d/*
[   32.824554] eth0: link up (1000Mbps/Full duplex)
[   32.850137] br-lan: port 1(eth0.1) entered blocking state
[   32.855768] br-lan: port 1(eth0.1) entered disabled state
[   32.861637] device eth0.1 entered promiscuous mode
[   32.866624] device eth0 entered promiscuous mode
[   32.876440] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
[   32.922424] br-lan: port 1(eth0.1) entered blocking state
[   32.928050] br-lan: port 1(eth0.1) entered forwarding state
[   33.824454] IPv6: ADDRCONF(NETDEV_CHANGE): br-lan: link becomes ready
[   37.904068] br-lan: port 2(tap_vpn) entered blocking state
[   37.909795] br-lan: port 2(tap_vpn) entered disabled state
[   37.915763] device tap_vpn entered promiscuous mode
[   37.921040] br-lan: port 2(tap_vpn) entered blocking state
[   37.926748] br-lan: port 2(tap_vpn) entered forwarding state

TP-Link often cripples serial input, you might need to solder/short something on the PCB to make it work.
read about it at https://openwrt.org/toh/tp-link/archer_a7_v5#serial
same page describes the TFTP recovery using the reset button, I'd try that 1st.

But it looks like the router finished the boot sequence ... ?

Have you tried holding the Reset button down for upto 10 seconds, either immediately, or a few seconds after applying power to the router when the Power LED starts to flash?

1 Like

As bill888 mentioned, your device seems to boot up just fine - and might 'just' be misconfigured, which would be easily solved with a factory reset.

1 Like

@frollic Thanks for the pointer to the wiki. I soldered the jumper and got the serial UART working. Could get a Linux prompt in failsafe mode and tried to flash the openwrt factory firmware but that didn't work. Now I can't get to failsafe mode but still can get to the ath prompt,

Boot sequence below:

U-Boot 1.1.4-g14abe3ec-dirty (Aug 10 2018 - 16:06:27)

ap152 - Dragonfly 1.0

DRAM:  128 MB
Top of RAM usable for U-Boot at: 88000000
Reserving 397k for U-Boot at: 87f9c000
Reserving 16448k for malloc() at: 86f8c000
Reserving 44 Bytes for Board Info at: 86f8bfd4
Reserving 36 Bytes for Global Data at: 86f8bfb0
Reserving 128k for boot params() at: 86f6bfb0
Stack Pointer at: 86f6bf98
Now running in RAM - U-Boot at: 87f9c000
Flash Manuf Id 0xef, DeviceId0 0x40, DeviceId1 0x18
flash size 16MB, sector count = 256
Flash: 16 MB
Using default environment

In:    serial
Out:   serial
Err:   serial
Net:   ath_gmac_enet_initialize...
No valid address in Flash. Using fixed address
ath_gmac_enet_initialize: reset mask:c02200
athr_mgmt_init ::done
Dragonfly  ----> S17 PHY *
athrs17_reg_init: complete
SGMII in forced mode
athr_gmac_sgmii_setup SGMII done
: cfg1 0x80000000 cfg2 0x7114
eth0: 00:03:7f:09:0b:ad
eth0 up
eth0
Setting 0x181162c0 to 0x40802100
factory boot check integer ok.

factory boot load fs uboot len 131072 to addr 0x80010000.
Hit any key to stop autoboot:  0
## Starting application at 0x80010000 ...


U-Boot 1.1.4-g7732fa90-dirty (Sep 22 2021 - 22:26:42)

ap152 - Dragonfly 1.0

DRAM:  128 MB
Top of RAM usable for U-Boot at: 88000000
Reserving 125k for U-Boot at: 87fe0000
Reserving 16448k for malloc() at: 86fd0000
Reserving 44 Bytes for Board Info at: 86fcffd4
Reserving 36 Bytes for Global Data at: 86fcffb0
Reserving 128k for boot params() at: 86faffb0
Stack Pointer at: 86faff98
Now running in RAM - U-Boot at: 87fe0000
Flash Manuf Id 0xef, DeviceId0 0x40, DeviceId1 0x18
flash size 16MB, sector count = 256
Flash: 16 MB
Using default environment

In:    serial
Out:   serial
Err:   serial
Net:   ath_gmac_enet_initialize...
No valid address in Flash. Using fixed address
ath_gmac_enet_initialize: reset mask:c02200
athr_mgmt_init ::done
Dragonfly  ----> S17 PHY *
athrs17_reg_init: complete
SGMII in forced mode
athr_gmac_sgmii_setup SGMII done
: cfg1 0x80000000 cfg2 0x7114
eth0: 00:03:7f:09:0b:ad
eth0 up
eth0
Setting 0x181162c0 to 0x40802100
Hit any key to stop autoboot:  0
## Booting image at 9f040000 ...
Bad Magic Number
ath>

It seems I should have flashed the sysupgrade fw instead of the factory fw.

Any pointers to flashing fw from the ath prompt? Thanks.

Printenv in uboot should give you all the info you need, but it should be the same as in the wiki link.