Need a copy content of full-flash about uap-ac-m

As you noted, the bootloader is easily cut out of the factory release bin.

The uboot-env is this:

00000000  5c c3 d6 11 62 6f 6f 74  61 72 67 73 3d 63 6f 6e  |\...bootargs=con|
00000010  73 6f 6c 65 3d 74 74 79  30 20 70 61 6e 69 63 3d  |sole=tty0 panic=|
00000020  33 00 62 6f 6f 74 63 6d  64 3d 72 75 6e 20 75 62  |3.bootcmd=run ub|
00000030  6e 74 61 70 70 69 6e 69  74 3b 20 67 6f 20 24 75  |ntappinit; go $u|
00000040  62 6e 74 61 64 64 72 20  75 62 6e 74 62 6f 6f 74  |bntaddr ubntboot|
00000050  3b 62 6f 6f 74 6d 20 24  66 6c 61 73 68 5f 62 6f  |;bootm $flash_bo|
00000060  6f 74 5f 61 64 64 72 00  62 6f 6f 74 64 65 6c 61  |ot_addr.bootdela|
00000070  79 3d 32 00 62 61 75 64  72 61 74 65 3d 31 31 35  |y=2.baudrate=115|
00000080  32 30 30 00 65 74 68 61  64 64 72 3d 30 78 30 30  |200.ethaddr=0x00|
00000090  3a 30 78 61 61 3a 30 78  62 62 3a 30 78 63 63 3a  |:0xaa:0xbb:0xcc:|
000000a0  30 78 64 64 3a 30 78 65  65 00 69 70 61 64 64 72  |0xdd:0xee.ipaddr|
000000b0  3d 31 39 32 2e 31 36 38  2e 31 2e 32 30 00 73 65  |=192.168.1.20.se|
000000c0  72 76 65 72 69 70 3d 31  39 32 2e 31 36 38 2e 31  |rverip=192.168.1|
000000d0  2e 32 35 34 00 75 62 6e  74 61 70 70 69 6e 69 74  |.254.ubntappinit|
000000e0  3d 67 6f 20 24 7b 75 62  6e 74 61 64 64 72 7d 20  |=go ${ubntaddr} |
000000f0  75 61 70 70 69 6e 69 74  3b 67 6f 20 24 7b 75 62  |uappinit;go ${ub|
00000100  6e 74 61 64 64 72 7d 20  75 72 65 73 65 74 5f 62  |ntaddr} ureset_b|
00000110  75 74 74 6f 6e 3b 75 72  65 73 63 75 65 3b 67 6f  |utton;urescue;go|
00000120  20 24 7b 75 62 6e 74 61  64 64 72 7d 20 75 77 72  | ${ubntaddr} uwr|
00000130  69 74 65 00 6d 74 64 70  61 72 74 73 3d 6d 74 64  |ite.mtdparts=mtd|
00000140  70 61 72 74 73 3d 61 74  68 2d 6e 6f 72 30 3a 33  |parts=ath-nor0:3|
00000150  38 34 6b 28 75 2d 62 6f  6f 74 29 2c 36 34 6b 28  |84k(u-boot),64k(|
00000160  75 2d 62 6f 6f 74 2d 65  6e 76 29 2c 37 37 34 34  |u-boot-env),7744|
00000170  6b 28 6b 65 72 6e 65 6c  30 29 2c 37 37 34 34 6b  |k(kernel0),7744k|
00000180  28 6b 65 72 6e 65 6c 31  29 2c 31 32 38 6b 28 62  |(kernel1),128k(b|
00000190  73 29 2c 32 35 36 6b 28  63 66 67 29 2c 36 34 6b  |s),256k(cfg),64k|
000001a0  28 45 45 50 52 4f 4d 29  00 00 00 00 00 00 00 00  |(EEPROM)........|
000001b0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
*
00010000

or the above first 512 bytes of mtd1 (u-boot-env) in base64, the rest of the 64k space is zeros:

XMPWEWJvb3RhcmdzPWNvbnNvbGU9dHR5MCBwYW5pYz0zAGJvb3RjbWQ9cnVuIHVibnRhcHBpbml0
OyBnbyAkdWJudGFkZHIgdWJudGJvb3Q7Ym9vdG0gJGZsYXNoX2Jvb3RfYWRkcgBib290ZGVsYXk9
MgBiYXVkcmF0ZT0xMTUyMDAAZXRoYWRkcj0weDAwOjB4YWE6MHhiYjoweGNjOjB4ZGQ6MHhlZQBp
cGFkZHI9MTkyLjE2OC4xLjIwAHNlcnZlcmlwPTE5Mi4xNjguMS4yNTQAdWJudGFwcGluaXQ9Z28g
JHt1Ym50YWRkcn0gdWFwcGluaXQ7Z28gJHt1Ym50YWRkcn0gdXJlc2V0X2J1dHRvbjt1cmVzY3Vl
O2dvICR7dWJudGFkZHJ9IHV3cml0ZQBtdGRwYXJ0cz1tdGRwYXJ0cz1hdGgtbm9yMDozODRrKHUt
Ym9vdCksNjRrKHUtYm9vdC1lbnYpLDc3NDRrKGtlcm5lbDApLDc3NDRrKGtlcm5lbDEpLDEyOGso
YnMpLDI1NmsoY2ZnKSw2NGsoRUVQUk9NKQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=

The bs partition (mtd7) is this:

00000000 00 00 00 00 a3 4d e8 2b 00 00 00 00 00 00 00 00 |.....M.+........| 00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 00020000
or in base64

AAAAAKNN6CsAAAAAAAAAAA==

I don't know what the significance of the 4 bytes are or if they are unit specific. The known use of the bs partition is if the first byte is 0x80 instead of 0, the second firmware partition will be booted.

On my unit the 'cfg' partition is blank (all 0xFF). It would only be used by stock firmware in any case.

And the eeprom is unit specific you must use the data that was loaded at the factory for proper radio operation.