OpenWrt support for Vodafone Gigacube (B157)

Here is the initramfs image finally:

Check whether the script has tcl,hh500v) or tcl,linkhub-hh500v) You may have taken some bits before the rename and the script itself after the rename.

Some errors in the bootlog (MAC, board_detect,…)

IPQ807x# bootm
## Loading kernel from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.12.48
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x440000e8
     Data Size:    15565836 Bytes = 14.8 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41000000
     Entry Point:  0x41000000
     Hash algo:    crc32
     Hash value:   3650119c
     Hash algo:    sha1
     Hash value:   b731561f78ebcd23b875abf6af6f0a9a36fbb445
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt tcl_linkhub-hh500v device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x44ed8638
     Data Size:    45450 Bytes = 44.4 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   4fd83207
     Hash algo:    sha1
     Hash value:   0f552e97f7ad8c792a79c04c094b3254042822ef
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x44ed8638
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3f1000, end 4a3ff189 ... OK
mtdids not defined, no default present
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.12.48 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r31131+18-c8c187f0f0) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP Wed Sep 24 08:22:37 2025
[    0.000000] Machine model: TCL LINKHUB HH500V
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable nss@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000510fffff]
[    0.000000]   node   0: [mem 0x0000000051100000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 20 pages/cpu s43288 r8192 d30440 u81920
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 262144
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000000] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000127] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000139] pid_max: default: 32768 minimum: 301
[    0.005209] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005223] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.010180] rcu: Hierarchical SRCU implementation.
[    0.010189] rcu:     Max phase no-delay instances is 1000.
[    0.010489] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level
[    0.010892] smp: Bringing up secondary CPUs ...
[    0.011551] Detected VIPT I-cache on CPU1
[    0.011662] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012411] Detected VIPT I-cache on CPU2
[    0.012488] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.013170] Detected VIPT I-cache on CPU3
[    0.013243] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013326] smp: Brought up 1 node, 4 CPUs
[    0.013335] SMP: Total of 4 processors activated.
[    0.013340] CPU: All CPU(s) started at EL1
[    0.013343] CPU features: detected: 32-bit EL0 Support
[    0.013348] CPU features: detected: CRC32 instructions
[    0.013394] alternatives: applying system-wide alternatives
[    0.013595] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.013850] Memory: 871664K/1048576K available (9088K kernel code, 908K rwdata, 2928K rodata, 10624K init, 304K bss, 173440K reserved, 0K cma-reserved)
[    0.023035] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.023062] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.023161] 26752 pages in range for non-PLT usage
[    0.023166] 518272 pages in range for PLT usage
[    0.025326] pinctrl core: initialized pinctrl subsystem
[    0.029741] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.030290] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.030330] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.030364] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.030754] thermal_sys: Registered thermal governor 'step_wise'
[    0.030815] cpuidle: using governor menu
[    0.031020] ASID allocator initialised with 65536 entries
[    0.038763] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.038844] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.039751] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.041816] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.042403] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.092430] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.114827] SCSI subsystem initialized
[    0.115043] usbcore: registered new interface driver usbfs
[    0.115083] usbcore: registered new interface driver hub
[    0.115131] usbcore: registered new device driver usb
[    0.115418] qcom_scm: convention: smc arm 64
[    0.117181] clocksource: Switched to clocksource arch_sys_counter
[    0.121123] NET: Registered PF_INET protocol family
[    0.121264] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.124123] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.124147] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.124163] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.124247] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.124519] TCP: Hash tables configured (established 8192 bind 8192)
[    0.124996] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.125169] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125219] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125564] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.125601] PCI: CLS 0 bytes, default 64
[    0.140797] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.141604] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.141614] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.144494] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 248)
[    0.150150] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.150339] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.151666] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.151838] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.153458] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.153595] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.153635] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.153803] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.154030] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.154175] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.154214] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.154360] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.156938] gpio-export modem: 3 gpio(s) exported
[    0.158744] qcom-pcie 20000000.pcie: host bridge /soc@0/pcie@20000000 ranges:
[    0.158806] qcom-pcie 20000000.pcie:       IO 0x0020200000..0x002020ffff -> 0x0000000000
[    0.158832] qcom-pcie 20000000.pcie:      MEM 0x0020220000..0x002fffffff -> 0x0020220000
[    0.164949] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.168946] msm_serial 78b1000.serial: msm_serial: detected port #1
[    0.169061] msm_serial 78b1000.serial: uartclk = 19200000
[    0.169456] 78b1000.serial: ttyMSM1 at MMIO 0x78b1000 (irq = 20, base_baud = 1200000) is a MSM
[    0.169958] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.170033] msm_serial 78b3000.serial: uartclk = 3686400
[    0.170400] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 21, base_baud = 230400) is a MSM
[    0.170438] msm_serial: console setup on port #0
[    0.170475] printk: legacy console [ttyMSM0] enabled
[    0.288799] qcom-pcie 20000000.pcie: iATU: unroll T, 8 ob, 8 ib, align 4K, limit 1024G
[    0.290919] msm_serial: driver initialized
[    1.106611] loop: module loaded
[    1.108099] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.108574] nand: Micron MT29F2G08ABBGAH4
[    1.115166] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.132511] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.133396] spi-nor spi0.0: unrecognized JEDEC id bytes: ff ff ff ff ff ff
[    1.139155] spmi_pmic_arb 200f000.spmi: PMIC arbiter version v2 (0x20010000)
[    1.198955] i2c_dev: i2c /dev entries driver
[    1.200112] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.206859] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.220139] sdhci: Secure Digital Host Controller Interface driver
[    1.220184] sdhci: Copyright(c) Pierre Ossman
[    1.225221] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.231738] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.239236] NET: Registered PF_INET6 protocol family
[    1.242427] Segment Routing with IPv6
[    1.246273] In-situ OAM (IOAM) with IPv6
[    1.249882] NET: Registered PF_PACKET protocol family
[    1.253803] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.258990] 8021q: 802.1Q VLAN Support v1.8
[    1.303001] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.303402] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.309166] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.315730] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.323428] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.330946] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.340061] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 712000 uV
[    1.346984] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 848000 uV
[    1.356990] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 912000 uV
[    1.366805] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop=1024000 uV
[    1.367189] qcom-pcie 20000000.pcie: Phy link never came up
[    1.376662] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 657, quot_offset[ 7]=   0
[    1.386819] qcom-pcie 20000000.pcie: PCI host bridge to bus 0000:00
[    1.391718] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 909, quot_offset[ 7]= 250
[    1.402806] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.402819] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
[    1.408900] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1013, quot_offset[ 7]= 100
[    1.419992] pci_bus 0000:00: root bus resource [mem 0x20220000-0x2fffffff]
[    1.420111] pci 0000:00:00.0: [17cb:1002] type 01 class 0x060400 PCIe Root Port
[    1.425359] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1201, quot_offset[ 7]= 185
[    1.431557] pci 0000:00:00.0: BAR 0 [mem 0x00000000-0x00000fff]
[    1.442782] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.449337] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.449351] pci 0000:00:00.0:   bridge window [io  0x0000-0x0fff]
[    1.485365] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff]
[    1.485393] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.491609] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff 64bit pref]
[    1.498372] nand: Micron MT29F2G08ABBGAH4
[    1.504857] pci 0000:00:00.0: PME# supported from D0 D3hot D3cold
[    1.512518] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.519921] pci 0000:00:00.0: BAR 0 [mem 0x20220000-0x20220fff]: assigned
[    1.529998] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.532854] 23 qcomsmem partitions found on MTD device qcom_nand.0
[    1.536913] pci_bus 0000:00: resource 4 [io  0x0000-0xffff]
[    1.541953] Creating 23 MTD partitions on "qcom_nand.0":
[    1.541962] 0x000000000000-0x000000100000 : "0:sbl1"
[    1.548198] pci_bus 0000:00: resource 5 [mem 0x20220000-0x2fffffff]
[    1.565429] 0x000000100000-0x000000200000 : "0:mibib"
[    1.567153] pcieport 0000:00:00.0: PME: Signaling with IRQ 33
[    1.571447] 0x000000200000-0x000000280000 : "0:bootconfig"
[    1.575688] pcieport 0000:00:00.0: AER: enabled with IRQ 33
[    1.582014] 0x000000280000-0x000000300000 : "0:bootconfig1"
[    1.592896] 0x000000300000-0x000000600000 : "0:qsee"
[    1.600280] 0x000000600000-0x000000900000 : "0:qsee_1"
[    1.605469] 0x000000900000-0x000000980000 : "0:devcfg"
[    1.608481] 0x000000980000-0x000000a00000 : "0:devcfg_1"
[    1.613587] 0x000000a00000-0x000000a80000 : "0:apdp"
[    1.619164] 0x000000a80000-0x000000b00000 : "0:apdp_1"
[    1.623972] 0x000000b00000-0x000000b80000 : "0:rpm"
[    1.628979] 0x000000b80000-0x000000c00000 : "0:rpm_1"
[    1.633701] 0x000000c00000-0x000000c80000 : "0:cdt"
[    1.638973] 0x000000c80000-0x000000d00000 : "0:cdt_1"
[    1.643627] 0x000000d00000-0x000000d80000 : "0:appsblenv"
[    1.648863] 0x000000d80000-0x000000e80000 : "0:appsbl"
[    1.654579] 0x000000e80000-0x000000f80000 : "0:appsbl_1"
[    1.659675] 0x000000f80000-0x000001020000 : "0:art"
[    1.664844] 0x000001020000-0x000007520000 : "rootfs"
[    1.746668] mtd: setting mtd18 (rootfs) as root device
[    1.746959] mtdsplit: no squashfs found in "rootfs"
[    1.750759] 0x000007520000-0x000007e20000 : "0:wififw"
[    1.762878] 0x000007e20000-0x00000e320000 : "rootfs_1"
[    1.841357] 0x00000e320000-0x00000ec20000 : "0:wififw_1"
[    1.848818] 0x00000ec20000-0x00000eca0000 : "0:ethphyfw"
[    1.859576] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.861842] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.869696] clk: Disabling unused▒[    1.882623] Freeing unused kernel memory: 10624K
[    1.882701] Run /init as init process
[    2.059443] init: Console is alive
[    2.059573] init: - watchdog -
[    2.066695] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    2.086489] gpio_button_hotplug: loading out-of-tree module taints kernel.
[    2.100704] ssdk_dt_parse_interrupt[942]:INFO:intr-gpio does not exist
[    3.117255] regi_init[2525]:INFO:Initializing HPPE Done!!
[    3.117379] regi_init[2574]:INFO:qca-ssdk module init succeeded!
[    3.123873] EDMA ver 1 hw init
[    3.127970] EDMA HW Reset completed succesfully
[    3.130620] Num rings - TxDesc:1 (23-23) TxCmpl:1 (7-7)
[    3.135013] RxDesc:1 (15-15) RxFill:1 (7-7)
[    3.140717] GMAC4(ffffff800524d980) Invalid MAC@ - using c6:c0:7b:eb:f0:20
[    3.318023] Qualcomm QCA8075 90000.mdio-1:03: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:03, irq=POLL)
[    3.318972] GMAC6(ffffff8005f58980) Invalid MAC@ - using 76:9c:59:dc:5f:04
[    3.389431] Qualcomm QCA8081 90000.mdio-1:10: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:10, irq=POLL)
[    3.390213] **********************************************************
[    3.398351] * NSS Data Plane driver
[    3.404830] **********************************************************
[    3.425657] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.425707] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 1
[    3.430201] xhci-hcd xhci-hcd.1.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    3.437638] xhci-hcd xhci-hcd.1.auto: irq 48, io mem 0x08a00000
[    3.447071] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.452880] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 2
[    3.458437] xhci-hcd xhci-hcd.1.auto: Host supports USB 3.0 SuperSpeed
[    3.466371] hub 1-0:1.0: USB hub found
[    3.472597] hub 1-0:1.0: 1 port detected
[    3.476510] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.480875] hub 2-0:1.0: USB hub found
[    3.488528] hub 2-0:1.0: 1 port detected
[    3.492334] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.496108] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 3
[    3.501552] xhci-hcd xhci-hcd.2.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    3.509000] xhci-hcd xhci-hcd.2.auto: irq 49, io mem 0x08c00000
[    3.518433] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.524230] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 4
[    3.529802] xhci-hcd xhci-hcd.2.auto: Host supports USB 3.0 SuperSpeed
[    3.537639] hub 3-0:1.0: USB hub found
[    3.543946] hub 3-0:1.0: 1 port detected
[    3.547856] usb usb4: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.551960] hub 4-0:1.0: USB hub found
[    3.560016] hub 4-0:1.0: 1 port detected
[    3.566311] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    3.568769] init: - preinit -
[   12.367172] usb 3-1: new high-speed USB device number 2 using xhci-hcd
[   12.877174] random: crng init done
get_mac_binary: file  not found!
get_mac_binary: file  not found!
/bin/board_detect: line 10: Unsupported: not found
Cannot parse config file '/etc/fw_env.config': No such file or directory
Failed to find NVMEM device
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
[   17.163695] procd: - early -
[   17.163805] procd: - watchdog -
[   17.703974] procd: - watchdog -
[   17.704203] procd: - ubus -
[   17.857522] procd: - init -
Please press Enter to activate this console.
[   17.995166] kmodloader: loading kernel modules from /etc/modules.d/*
[   18.076508] Loading modules backported from Linux version v6.16-0-g038d61fd6422
[   18.076549] Backport generated by backports.git v6.1.145-1-47-g6194bf852a3e
[   18.091359] NET: Registered PF_QIPCRTR protocol family
[   18.128674] PPP generic driver version 2.4.2
[   18.129487] NET: Registered PF_PPPOX protocol family
[   18.133637] wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information.
[   18.136969] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
[   18.144966] urngd: v1.0.2 started.
[   18.156556] ath11k c000000.wifi: ipq8074 hw2.0
[   18.157548] ath11k c000000.wifi: FW memory mode: 0
[   18.179965] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   18.180072] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   18.531527] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   18.575473] ath11k c000000.wifi: qmi fail to get qcom,m3-dump-addr, ignore m3 dump mem req
[   18.582939] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   18.582977] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   18.657962] ath11k c000000.wifi: failed to fetch board data for bus=ahb,qmi-chip-id=0,qmi-board-id=255,variant=TCL-LINKHUB-HH500V from ath11k/IPQ8074/hw2.0/board-2.bin
[   18.658034] ath11k c000000.wifi: failed to fetch board data for bus=ahb,qmi-chip-id=0,qmi-board-id=255 from ath11k/IPQ8074/hw2.0/board-2.bin
[   18.671846] ath11k c000000.wifi: failed to fetch board data for bus=ahb,qmi-chip-id=0,qmi-board-id=255 from ath11k/IPQ8074/hw2.0/board-2.bin
[   18.684629] ath11k c000000.wifi: failed to fetch board.bin from IPQ8074/hw2.0
[   18.697187] ath11k c000000.wifi: qmi failed to fetch board file: -12
[   18.704199] ath11k c000000.wifi: failed to load board data file: -12
[   32.487215] l11: disabling
[   79.847203] ath11k c000000.wifi: Coldboot Calibration timed out
[   79.850279] kmodloader: done loading kernel modules from /etc/modules.d/*
[   81.571177] pci 0000:01:00.0: [17cb:0306] type 00 class 0xff0000 PCIe Endpoint
[   81.571303] pci 0000:01:00.0: BAR 0 [mem 0x00000000-0x00000fff 64bit]
[   81.577393] pci 0000:01:00.0: BAR 2 [mem 0x00000000-0x00000fff 64bit]
[   81.584323] pci 0000:01:00.0: PME# supported from D0 D3hot D3cold
[   81.590413] pci 0000:01:00.0: 7.876 Gb/s available PCIe bandwidth, limited by 8.0 GT/s PCIe x1 link at 0000:00:00.0 (capable of 31.506 Gb/s with 16.0 GT/s PCIe x2 link)
[   81.596860] pcieport 0000:00:00.0: bridge window [mem 0x20300000-0x203fffff]: assigned
[   81.611471] pci 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   81.619199] pci 0000:01:00.0: BAR 2 [mem 0x20301000-0x20301fff 64bit]: assigned
[   81.626477] mhi-pci-generic 0000:01:00.0: MHI PCI device found: foxconn-sdx55
[   81.633662] mhi-pci-generic 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   81.641000] mhi-pci-generic 0000:01:00.0: enabling device (0000 -> 0002)
[   81.650356] mhi mhi0: Requested to power ON
[   81.656049] mhi mhi0: Power on setup success
[   81.723440] wwan wwan0: port wwan0qcdm0 attached
[   81.723699] wwan wwan0: port wwan0mbim0 attached
[   81.727448] wwan wwan0: port wwan0at0 attached

printenv issue:

root@OpenWrt:~# fw_printenv Cannot parse config file '/etc/fw_env.config': No such file or directory 

WiFi doesn’t work, which I guess is expected from an initramfs (art partition).

LEDs work fine.

LAN ports work fine but MACs are wrong. I’m getting c6:c0:7b:… and 76:9c:59:… instead of b4:69:5f:… Maybe because of that, the bridge (br-lan) isn’t built.

It looks like the modem is being detected too, but I’m unable to get a working AT port to test.

Thanks! Found and fixed the bug for board_detect/lan. I remembered now that fw_printenv/macs/wifi won't work in initramfs because of qcomsmem partitions l, but wifi should fail on calibration rather than board file. This is not a bug, I just included the wrong file name in the image, the correct file name is in the corresponding firmware repo.

New image version uploaded to the same bin.

It looks better, now the ethernet ports are properly configured, but it still doesn’t get the right MAC addresses.

IPQ807x# bootm
## Loading kernel from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.12.48
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x440000e8
     Data Size:    15565685 Bytes = 14.8 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41000000
     Entry Point:  0x41000000
     Hash algo:    crc32
     Hash value:   9e9a8b93
     Hash algo:    sha1
     Hash value:   a15445db0882988aece221034d1e8683021dd8bd
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt tcl_linkhub-hh500v device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x44ed85a4
     Data Size:    45450 Bytes = 44.4 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   4fd83207
     Hash algo:    sha1
     Hash value:   0f552e97f7ad8c792a79c04c094b3254042822ef
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x44ed85a4
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3f1000, end 4a3ff189 ... OK
mtdids not defined, no default present
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.12.48 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r31131+18-c8c187f0f0) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP Wed Sep 24 17:53:55 2025
[    0.000000] Machine model: TCL LINKHUB HH500V
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable nss@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000510fffff]
[    0.000000]   node   0: [mem 0x0000000051100000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 20 pages/cpu s43288 r8192 d30440 u81920
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 262144
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000000] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000127] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000140] pid_max: default: 32768 minimum: 301
[    0.005197] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005211] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.010180] rcu: Hierarchical SRCU implementation.
[    0.010191] rcu:     Max phase no-delay instances is 1000.
[    0.010488] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level
[    0.010890] smp: Bringing up secondary CPUs ...
[    0.011552] Detected VIPT I-cache on CPU1
[    0.011666] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012414] Detected VIPT I-cache on CPU2
[    0.012490] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.013176] Detected VIPT I-cache on CPU3
[    0.013247] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013330] smp: Brought up 1 node, 4 CPUs
[    0.013339] SMP: Total of 4 processors activated.
[    0.013343] CPU: All CPU(s) started at EL1
[    0.013347] CPU features: detected: 32-bit EL0 Support
[    0.013352] CPU features: detected: CRC32 instructions
[    0.013397] alternatives: applying system-wide alternatives
[    0.013597] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.013854] Memory: 871664K/1048576K available (9088K kernel code, 908K rwdata, 2928K rodata, 10624K init, 304K bss, 173440K reserved, 0K cma-reserved)
[    0.023031] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.023058] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.023157] 26752 pages in range for non-PLT usage
[    0.023162] 518272 pages in range for PLT usage
[    0.025321] pinctrl core: initialized pinctrl subsystem
[    0.029750] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.030304] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.030344] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.030379] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.030769] thermal_sys: Registered thermal governor 'step_wise'
[    0.030831] cpuidle: using governor menu
[    0.031037] ASID allocator initialised with 65536 entries
[    0.038794] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.038877] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.039786] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.041853] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.042428] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.092501] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.114931] SCSI subsystem initialized
[    0.115146] usbcore: registered new interface driver usbfs
[    0.115186] usbcore: registered new interface driver hub
[    0.115233] usbcore: registered new device driver usb
[    0.115525] qcom_scm: convention: smc arm 64
[    0.117298] clocksource: Switched to clocksource arch_sys_counter
[    0.121170] NET: Registered PF_INET protocol family
[    0.121335] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.124244] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.124272] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.124287] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.124372] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.124646] TCP: Hash tables configured (established 8192 bind 8192)
[    0.125130] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.125303] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125341] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125668] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.125707] PCI: CLS 0 bytes, default 64
[    0.140897] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.141703] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.141712] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.144645] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 248)
[    0.150336] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.150502] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.151840] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.151967] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.153604] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.153781] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.153822] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.153979] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.154195] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.154316] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.154371] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.154574] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.157108] gpio-export modem: 3 gpio(s) exported
[    0.158764] qcom-pcie 20000000.pcie: host bridge /soc@0/pcie@20000000 ranges:
[    0.158823] qcom-pcie 20000000.pcie:       IO 0x0020200000..0x002020ffff -> 0x0000000000
[    0.158850] qcom-pcie 20000000.pcie:      MEM 0x0020220000..0x002fffffff -> 0x0020220000
[    0.164803] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.168865] msm_serial 78b1000.serial: msm_serial: detected port #1
[    0.168964] msm_serial 78b1000.serial: uartclk = 19200000
[    0.169371] 78b1000.serial: ttyMSM1 at MMIO 0x78b1000 (irq = 20, base_baud = 1200000) is a MSM
[    0.169918] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.169994] msm_serial 78b3000.serial: uartclk = 3686400
[    0.170378] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 21, base_baud = 230400) is a MSM
[    0.170422] msm_serial: console setup on port #0
[    0.170459] printk: legacy console [ttyMSM0] enabled
[    0.288896] qcom-pcie 20000000.pcie: iATU: unroll T, 8 ob, 8 ib, align 4K, limit 1024G
[    0.290930] msm_serial: driver initialized
[    1.106641] loop: module loaded
[    1.108099] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.108603] nand: Micron MT29F2G08ABBGAH4
[    1.115193] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.132063] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.133044] spi-nor spi0.0: unrecognized JEDEC id bytes: ff ff ff ff ff ff
[    1.138731] spmi_pmic_arb 200f000.spmi: PMIC arbiter version v2 (0x20010000)
[    1.199001] i2c_dev: i2c /dev entries driver
[    1.200180] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.206902] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.220136] sdhci: Secure Digital Host Controller Interface driver
[    1.220181] sdhci: Copyright(c) Pierre Ossman
[    1.225217] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.231722] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.239179] NET: Registered PF_INET6 protocol family
[    1.242262] Segment Routing with IPv6
[    1.246283] In-situ OAM (IOAM) with IPv6
[    1.249950] NET: Registered PF_PACKET protocol family
[    1.253801] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.258977] 8021q: 802.1Q VLAN Support v1.8
[    1.303442] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.303785] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.309605] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.316171] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.323877] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.331373] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.340503] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 712000 uV
[    1.347459] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 848000 uV
[    1.347459] qcom-pcie 20000000.pcie: Phy link never came up
[    1.347882] qcom-pcie 20000000.pcie: PCI host bridge to bus 0000:00
[    1.357436] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 912000 uV
[    1.367217] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.372530] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop=1024000 uV
[    1.378778] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
[    1.388893] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 657, quot_offset[ 7]=   0
[    1.394127] pci_bus 0000:00: root bus resource [mem 0x20220000-0x2fffffff]
[    1.404125] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 909, quot_offset[ 7]= 250
[    1.410200] pci 0000:00:00.0: [17cb:1002] type 01 class 0x060400 PCIe Root Port
[    1.421144] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1013, quot_offset[ 7]= 100
[    1.427917] pci 0000:00:00.0: BAR 0 [mem 0x00000000-0x00000fff]
[    1.438933] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1201, quot_offset[ 7]= 185
[    1.446049] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.457422] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.462889] pci 0000:00:00.0:   bridge window [io  0x0000-0x0fff]
[    1.478306] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.479030] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff]
[    1.485957] nand: Micron MT29F2G08ABBGAH4
[    1.492058] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff 64bit pref]
[    1.498469] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.505208] pci 0000:00:00.0: PME# supported from D0 D3hot D3cold
[    1.519559] 23 qcomsmem partitions found on MTD device qcom_nand.0
[    1.527875] pci 0000:00:00.0: BAR 0 [mem 0x20220000-0x20220fff]: assigned
[    1.530594] Creating 23 MTD partitions on "qcom_nand.0":
[    1.536660] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.543520] 0x000000000000-0x000000100000 : "0:sbl1"
[    1.548908] pci_bus 0000:00: resource 4 [io  0x0000-0xffff]
[    1.555171] 0x000000100000-0x000000200000 : "0:mibib"
[    1.559057] pci_bus 0000:00: resource 5 [mem 0x20220000-0x2fffffff]
[    1.561648] pcieport 0000:00:00.0: PME: Signaling with IRQ 33
[    1.565590] 0x000000200000-0x000000280000 : "0:bootconfig"
[    1.569923] pcieport 0000:00:00.0: AER: enabled with IRQ 33
[    1.576539] 0x000000280000-0x000000300000 : "0:bootconfig1"
[    1.593345] 0x000000300000-0x000000600000 : "0:qsee"
[    1.600665] 0x000000600000-0x000000900000 : "0:qsee_1"
[    1.605831] 0x000000900000-0x000000980000 : "0:devcfg"
[    1.608982] 0x000000980000-0x000000a00000 : "0:devcfg_1"
[    1.614020] 0x000000a00000-0x000000a80000 : "0:apdp"
[    1.619485] 0x000000a80000-0x000000b00000 : "0:apdp_1"
[    1.624442] 0x000000b00000-0x000000b80000 : "0:rpm"
[    1.629426] 0x000000b80000-0x000000c00000 : "0:rpm_1"
[    1.634157] 0x000000c00000-0x000000c80000 : "0:cdt"
[    1.639427] 0x000000c80000-0x000000d00000 : "0:cdt_1"
[    1.644045] 0x000000d00000-0x000000d80000 : "0:appsblenv"
[    1.649297] 0x000000d80000-0x000000e80000 : "0:appsbl"
[    1.655065] 0x000000e80000-0x000000f80000 : "0:appsbl_1"
[    1.660118] 0x000000f80000-0x000001020000 : "0:art"
[    1.665259] 0x000001020000-0x000007520000 : "rootfs"
[    1.747737] mtd: setting mtd18 (rootfs) as root device
[    1.748032] mtdsplit: no squashfs found in "rootfs"
[    1.751814] 0x000007520000-0x000007e20000 : "0:wififw"
[    1.763982] 0x000007e20000-0x00000e320000 : "rootfs_1"
[    1.843168] 0x00000e320000-0x00000ec20000 : "0:wififw_1"
[    1.850667] 0x00000ec20000-0x00000eca0000 : "0:ethphyfw"
[    1.861430] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.863663] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.871643] clk: Disabling unused▒[    1.884567] Freeing unused kernel memory: 10624K
[    1.884645] Run /init as init process
[    2.067956] init: Console is alive
[    2.068094] init: - watchdog -
[    2.076552] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    2.091710] gpio_button_hotplug: loading out-of-tree module taints kernel.
[    2.103891] ssdk_dt_parse_interrupt[942]:INFO:intr-gpio does not exist
[    3.127340] regi_init[2525]:INFO:Initializing HPPE Done!!
[    3.127469] regi_init[2574]:INFO:qca-ssdk module init succeeded!
[    3.133921] EDMA ver 1 hw init
[    3.138051] EDMA HW Reset completed succesfully
[    3.140704] Num rings - TxDesc:1 (23-23) TxCmpl:1 (7-7)
[    3.145099] RxDesc:1 (15-15) RxFill:1 (7-7)
[    3.150817] GMAC4(ffffff800550c980) Invalid MAC@ - using 96:25:00:74:36:70
[    3.328162] Qualcomm QCA8075 90000.mdio-1:03: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:03, irq=POLL)
[    3.329105] GMAC6(ffffff800550a980) Invalid MAC@ - using 32:30:6d:60:2c:ff
[    3.399535] Qualcomm QCA8081 90000.mdio-1:10: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:10, irq=POLL)
[    3.400398] **********************************************************
[    3.408461] * NSS Data Plane driver
[    3.414935] **********************************************************
[    3.434820] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.434872] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 1
[    3.439383] xhci-hcd xhci-hcd.1.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    3.446805] xhci-hcd xhci-hcd.1.auto: irq 48, io mem 0x08a00000
[    3.456242] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.462043] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 2
[    3.467608] xhci-hcd xhci-hcd.1.auto: Host supports USB 3.0 SuperSpeed
[    3.475542] hub 1-0:1.0: USB hub found
[    3.481857] hub 1-0:1.0: 1 port detected
[    3.485685] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.489827] hub 2-0:1.0: USB hub found
[    3.497748] hub 2-0:1.0: 1 port detected
[    3.501552] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.505273] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 3
[    3.510707] xhci-hcd xhci-hcd.2.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    3.518170] xhci-hcd xhci-hcd.2.auto: irq 49, io mem 0x08c00000
[    3.527603] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.533392] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 4
[    3.538956] xhci-hcd xhci-hcd.2.auto: Host supports USB 3.0 SuperSpeed
[    3.546774] hub 3-0:1.0: USB hub found
[    3.553111] hub 3-0:1.0: 1 port detected
[    3.557024] usb usb4: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.561143] hub 4-0:1.0: USB hub found
[    3.568997] hub 4-0:1.0: 1 port detected
[    3.575577] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    3.585205] init: - preinit -
[   12.417287] usb 3-1: new high-speed USB device number 2 using xhci-hcd
[   12.777287] random: crng init done
get_mac_binary: file  not found!
get_mac_binary: file  not found!
Cannot parse config file '/etc/fw_env.config': No such file or directory
Failed to find NVMEM device
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
[   17.047744] nss-dp 3a001600.dp4 lan: PHY Link up speed: 1000
[   17.054197] nss-dp 3a001600.dp4 lan: PHY Link is down
[   17.057776] procd: - early -
[   17.058311] procd: - watchdog -
[   17.589907] procd: - watchdog -
[   17.590142] procd: - ubus -
[   17.743552] procd: - init -
Please press Enter to activate this console.
[   17.876070] kmodloader: loading kernel modules from /etc/modules.d/*
[   17.960876] Loading modules backported from Linux version v6.16-0-g038d61fd6422
[   17.960916] Backport generated by backports.git v6.1.145-1-47-g6194bf852a3e
[   17.975655] NET: Registered PF_QIPCRTR protocol family
[   18.013536] PPP generic driver version 2.4.2
[   18.014444] NET: Registered PF_PPPOX protocol family
[   18.018558] wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information.
[   18.021833] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
[   18.030702] urngd: v1.0.2 started.
[   18.041436] ath11k c000000.wifi: ipq8074 hw2.0
[   18.042398] ath11k c000000.wifi: FW memory mode: 0
[   18.064613] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   18.064713] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   18.415966] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   18.459961] ath11k c000000.wifi: qmi fail to get qcom,m3-dump-addr, ignore m3 dump mem req
[   18.467429] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   18.467467] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   18.543085] ath11k c000000.wifi: failed to fetch board data for bus=ahb,qmi-chip-id=0,qmi-board-id=255,variant=TCL-LINKHUB-HH500V from ath11k/IPQ8074/hw2.0/board-2.bin
[   18.543154] ath11k c000000.wifi: failed to fetch board data for bus=ahb,qmi-chip-id=0,qmi-board-id=255 from ath11k/IPQ8074/hw2.0/board-2.bin
[   18.556950] ath11k c000000.wifi: failed to fetch board data for bus=ahb,qmi-chip-id=0,qmi-board-id=255 from ath11k/IPQ8074/hw2.0/board-2.bin
[   18.569805] ath11k c000000.wifi: failed to fetch board.bin from IPQ8074/hw2.0
[   18.582310] ath11k c000000.wifi: qmi failed to fetch board file: -12
[   18.589331] ath11k c000000.wifi: failed to load board data file: -12
[   32.487336] l11: disabling
[   79.847309] ath11k c000000.wifi: Coldboot Calibration timed out
[   79.850429] kmodloader: done loading kernel modules from /etc/modules.d/*
[   81.593288] pci 0000:01:00.0: [17cb:0306] type 00 class 0xff0000 PCIe Endpoint
[   81.593416] pci 0000:01:00.0: BAR 0 [mem 0x00000000-0x00000fff 64bit]
[   81.599547] pci 0000:01:00.0: BAR 2 [mem 0x00000000-0x00000fff 64bit]
[   81.606439] pci 0000:01:00.0: PME# supported from D0 D3hot D3cold
[   81.612550] pci 0000:01:00.0: 7.876 Gb/s available PCIe bandwidth, limited by 8.0 GT/s PCIe x1 link at 0000:00:00.0 (capable of 31.506 Gb/s with 16.0 GT/s PCIe x2 link)
[   81.618958] pcieport 0000:00:00.0: bridge window [mem 0x20300000-0x203fffff]: assigned
[   81.633563] pci 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   81.641308] pci 0000:01:00.0: BAR 2 [mem 0x20301000-0x20301fff 64bit]: assigned
[   81.648596] mhi-pci-generic 0000:01:00.0: MHI PCI device found: foxconn-sdx55
[   81.655758] mhi-pci-generic 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   81.663113] mhi-pci-generic 0000:01:00.0: enabling device (0000 -> 0002)
[   81.672417] mhi mhi0: Requested to power ON
[   81.678230] mhi mhi0: Power on setup success
[   81.765990] wwan wwan0: port wwan0qcdm0 attached
[   81.766256] wwan wwan0: port wwan0mbim0 attached
[   81.770014] wwan wwan0: port wwan0at0 attached
[   86.139542] br-lan: port 1(lan) entered blocking state
[   86.139589] br-lan: port 1(lan) entered disabled state
[   86.143626] nss-dp 3a001600.dp4 lan: entered allmulticast mode
[   86.148994] nss-dp 3a001600.dp4 lan: entered promiscuous mode
[   89.288007] nss-dp 3a001600.dp4 lan: PHY Link up speed: 1000
[   89.288072] br-lan: port 1(lan) entered blocking state
[   89.292750] br-lan: port 1(lan) entered forwarding state

the board name seem to be correct, it’s indeed a strange bug.

Macs won't be correct until you boot from flash and wifi calibration either :frowning:
But the wifi firmware needs to load. I've made another clean build, hope it's better now.

Some improvement…

## Loading kernel from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.12.48
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x440000e8
     Data Size:    15569022 Bytes = 14.8 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41000000
     Entry Point:  0x41000000
     Hash algo:    crc32
     Hash value:   f9fa9c35
     Hash algo:    sha1
     Hash value:   f7541363131fd4752b8e827b5fbce68e67d8e02c
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt tcl_linkhub-hh500v device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x44ed92ac
     Data Size:    45450 Bytes = 44.4 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   4fd83207
     Hash algo:    sha1
     Hash value:   0f552e97f7ad8c792a79c04c094b3254042822ef
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x44ed92ac
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3f1000, end 4a3ff189 ... OK
mtdids not defined, no default present
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.12.48 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r31131+18-c8c187f0f0) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP Wed Sep 24 17:53:55 2025
[    0.000000] Machine model: TCL LINKHUB HH500V
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable nss@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000510fffff]
[    0.000000]   node   0: [mem 0x0000000051100000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 20 pages/cpu s43288 r8192 d30440 u81920
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 262144
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000001] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000128] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000141] pid_max: default: 32768 minimum: 301
[    0.005253] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005267] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.010252] rcu: Hierarchical SRCU implementation.
[    0.010263] rcu:     Max phase no-delay instances is 1000.
[    0.010562] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level
[    0.010964] smp: Bringing up secondary CPUs ...
[    0.011627] Detected VIPT I-cache on CPU1
[    0.011738] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012484] Detected VIPT I-cache on CPU2
[    0.012561] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.013245] Detected VIPT I-cache on CPU3
[    0.013318] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013399] smp: Brought up 1 node, 4 CPUs
[    0.013409] SMP: Total of 4 processors activated.
[    0.013413] CPU: All CPU(s) started at EL1
[    0.013417] CPU features: detected: 32-bit EL0 Support
[    0.013422] CPU features: detected: CRC32 instructions
[    0.013471] alternatives: applying system-wide alternatives
[    0.013667] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.013924] Memory: 871664K/1048576K available (9088K kernel code, 908K rwdata, 2928K rodata, 10624K init, 304K bss, 173440K reserved, 0K cma-reserved)
[    0.023139] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.023166] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.023265] 26752 pages in range for non-PLT usage
[    0.023270] 518272 pages in range for PLT usage
[    0.025429] pinctrl core: initialized pinctrl subsystem
[    0.029868] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.030421] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.030460] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.030495] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.030887] thermal_sys: Registered thermal governor 'step_wise'
[    0.030948] cpuidle: using governor menu
[    0.031156] ASID allocator initialised with 65536 entries
[    0.038894] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.038974] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.039883] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.041954] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.042529] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.092764] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.115210] SCSI subsystem initialized
[    0.115428] usbcore: registered new interface driver usbfs
[    0.115468] usbcore: registered new interface driver hub
[    0.115516] usbcore: registered new device driver usb
[    0.115804] qcom_scm: convention: smc arm 64
[    0.117586] clocksource: Switched to clocksource arch_sys_counter
[    0.121456] NET: Registered PF_INET protocol family
[    0.121621] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.124530] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.124559] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.124574] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.124659] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.124937] TCP: Hash tables configured (established 8192 bind 8192)
[    0.125416] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.125588] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125626] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125953] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.125990] PCI: CLS 0 bytes, default 64
[    0.141267] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.142064] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.142075] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.145010] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 248)
[    0.150977] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.151122] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.152444] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.152562] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.154207] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.154387] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.154426] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.154594] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.154803] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.154929] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.154969] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.155157] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.157752] gpio-export modem: 3 gpio(s) exported
[    0.159329] qcom-pcie 20000000.pcie: host bridge /soc@0/pcie@20000000 ranges:
[    0.159404] qcom-pcie 20000000.pcie:       IO 0x0020200000..0x002020ffff -> 0x0000000000
[    0.159432] qcom-pcie 20000000.pcie:      MEM 0x0020220000..0x002fffffff -> 0x0020220000
[    0.165984] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.170071] msm_serial 78b1000.serial: msm_serial: detected port #1
[    0.170175] msm_serial 78b1000.serial: uartclk = 19200000
[    0.170588] 78b1000.serial: ttyMSM1 at MMIO 0x78b1000 (irq = 20, base_baud = 1200000) is a MSM
[    0.171089] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.171166] msm_serial 78b3000.serial: uartclk = 3686400
[    0.171516] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 21, base_baud = 230400) is a MSM
[    0.171560] msm_serial: console setup on port #0
[    0.171598] printk: legacy console [ttyMSM0] enabled
[    0.289186] qcom-pcie 20000000.pcie: iATU: unroll T, 8 ob, 8 ib, align 4K, limit 1024G
[    0.292070] msm_serial: driver initialized
[    1.107741] loop: module loaded
[    1.109125] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.109704] nand: Micron MT29F2G08ABBGAH4
[    1.116295] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.133200] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.134194] spi-nor spi0.0: unrecognized JEDEC id bytes: ff ff ff ff ff ff
[    1.139843] spmi_pmic_arb 200f000.spmi: PMIC arbiter version v2 (0x20010000)
[    1.199284] i2c_dev: i2c /dev entries driver
[    1.200457] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.207202] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.220278] sdhci: Secure Digital Host Controller Interface driver
[    1.220324] sdhci: Copyright(c) Pierre Ossman
[    1.225359] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.231912] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.239409] NET: Registered PF_INET6 protocol family
[    1.242631] Segment Routing with IPv6
[    1.246425] In-situ OAM (IOAM) with IPv6
[    1.250035] NET: Registered PF_PACKET protocol family
[    1.253954] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.259147] 8021q: 802.1Q VLAN Support v1.8
[    1.302965] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.303286] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.309146] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.315694] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.323371] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.330889] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.340008] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 712000 uV
[    1.346947] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 848000 uV
[    1.356939] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 912000 uV
[    1.366747] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop=1024000 uV
[    1.376607] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 657, quot_offset[ 7]=   0
[    1.377591] qcom-pcie 20000000.pcie: Phy link never came up
[    1.386367] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 909, quot_offset[ 7]= 250
[    1.397598] qcom-pcie 20000000.pcie: PCI host bridge to bus 0000:00
[    1.402599] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1013, quot_offset[ 7]= 100
[    1.413711] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.419794] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1201, quot_offset[ 7]= 185
[    1.430894] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
[    1.436485] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.447298] pci_bus 0000:00: root bus resource [mem 0x20220000-0x2fffffff]
[    1.451502] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.453484] pci 0000:00:00.0: [17cb:1002] type 01 class 0x060400 PCIe Root Port
[    1.460321] nand: Micron MT29F2G08ABBGAH4
[    1.467006] pci 0000:00:00.0: BAR 0 [mem 0x00000000-0x00000fff]
[    1.473532] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.480547] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.495346] 23 qcomsmem partitions found on MTD device qcom_nand.0
[    1.498084] pci 0000:00:00.0:   bridge window [io  0x0000-0x0fff]
[    1.503275] Creating 23 MTD partitions on "qcom_nand.0":
[    1.509536] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff]
[    1.515691] 0x000000000000-0x000000100000 : "0:sbl1"
[    1.521086] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff 64bit pref]
[    1.529086] 0x000000100000-0x000000200000 : "0:mibib"
[    1.532862] pci 0000:00:00.0: PME# supported from D0 D3hot D3cold
[    1.541752] 0x000000200000-0x000000280000 : "0:bootconfig"
[    1.548957] pci 0000:00:00.0: BAR 0 [mem 0x20220000-0x20220fff]: assigned
[    1.552465] 0x000000280000-0x000000300000 : "0:bootconfig1"
[    1.556932] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.564613] 0x000000300000-0x000000600000 : "0:qsee"
[    1.569180] pci_bus 0000:00: resource 4 [io  0x0000-0xffff]
[    1.577084] 0x000000600000-0x000000900000 : "0:qsee_1"
[    1.579585] pci_bus 0000:00: resource 5 [mem 0x20220000-0x2fffffff]
[    1.587579] 0x000000900000-0x000000980000 : "0:devcfg"
[    1.592663] pcieport 0000:00:00.0: PME: Signaling with IRQ 33
[    1.597122] 0x000000980000-0x000000a00000 : "0:devcfg_1"
[    1.601794] pcieport 0000:00:00.0: AER: enabled with IRQ 33
[    1.613596] 0x000000a00000-0x000000a80000 : "0:apdp"
[    1.618865] 0x000000a80000-0x000000b00000 : "0:apdp_1"
[    1.623999] 0x000000b00000-0x000000b80000 : "0:rpm"
[    1.628984] 0x000000b80000-0x000000c00000 : "0:rpm_1"
[    1.633697] 0x000000c00000-0x000000c80000 : "0:cdt"
[    1.639102] 0x000000c80000-0x000000d00000 : "0:cdt_1"
[    1.643629] 0x000000d00000-0x000000d80000 : "0:appsblenv"
[    1.648858] 0x000000d80000-0x000000e80000 : "0:appsbl"
[    1.654530] 0x000000e80000-0x000000f80000 : "0:appsbl_1"
[    1.659835] 0x000000f80000-0x000001020000 : "0:art"
[    1.664784] 0x000001020000-0x000007520000 : "rootfs"
[    1.746211] mtd: setting mtd18 (rootfs) as root device
[    1.746508] mtdsplit: no squashfs found in "rootfs"
[    1.750309] 0x000007520000-0x000007e20000 : "0:wififw"
[    1.762467] 0x000007e20000-0x00000e320000 : "rootfs_1"
[    1.841577] 0x00000e320000-0x00000ec20000 : "0:wififw_1"
[    1.849043] 0x00000ec20000-0x00000eca0000 : "0:ethphyfw"
[    1.859814] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.861980] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.869937] clk: Disabling unused▒[    1.883133] Freeing unused kernel memory: 10624K
[    1.883217] Run /init as init process
[    2.067559] init: Console is alive
[    2.067757] init: - watchdog -
[    2.075830] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    2.091068] gpio_button_hotplug: loading out-of-tree module taints kernel.
[    2.103611] ssdk_dt_parse_interrupt[942]:INFO:intr-gpio does not exist
[    3.127650] regi_init[2525]:INFO:Initializing HPPE Done!!
[    3.127775] regi_init[2574]:INFO:qca-ssdk module init succeeded!
[    3.134339] EDMA ver 1 hw init
[    3.138363] EDMA HW Reset completed succesfully
[    3.141011] Num rings - TxDesc:1 (23-23) TxCmpl:1 (7-7)
[    3.145407] RxDesc:1 (15-15) RxFill:1 (7-7)
[    3.151034] GMAC4(ffffff80052ef980) Invalid MAC@ - using 8a:23:4e:16:ec:42
[    3.298436] Qualcomm QCA8075 90000.mdio-1:03: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:03, irq=POLL)
[    3.299480] GMAC6(ffffff80052e8980) Invalid MAC@ - using 0e:59:9b:04:3f:40
[    3.379797] Qualcomm QCA8081 90000.mdio-1:10: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:10, irq=POLL)
[    3.380731] **********************************************************
[    3.388719] * NSS Data Plane driver
[    3.395195] **********************************************************
[    3.417144] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.417197] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 1
[    3.421744] xhci-hcd xhci-hcd.1.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    3.429155] xhci-hcd xhci-hcd.1.auto: irq 48, io mem 0x08a00000
[    3.438621] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.444380] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 2
[    3.449934] xhci-hcd xhci-hcd.1.auto: Host supports USB 3.0 SuperSpeed
[    3.457973] hub 1-0:1.0: USB hub found
[    3.464092] hub 1-0:1.0: 1 port detected
[    3.468490] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.472145] hub 2-0:1.0: USB hub found
[    3.480113] hub 2-0:1.0: 1 port detected
[    3.483927] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.487610] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 3
[    3.493012] xhci-hcd xhci-hcd.2.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    3.500494] xhci-hcd xhci-hcd.2.auto: irq 49, io mem 0x08c00000
[    3.509924] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.515716] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 4
[    3.521284] xhci-hcd xhci-hcd.2.auto: Host supports USB 3.0 SuperSpeed
[    3.529167] hub 3-0:1.0: USB hub found
[    3.535429] hub 3-0:1.0: 1 port detected
[    3.539371] usb usb4: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.543446] hub 4-0:1.0: USB hub found
[    3.551324] hub 4-0:1.0: 1 port detected
[    3.557953] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    3.564947] init: - preinit -
[   12.457578] usb 3-1: new high-speed USB device number 2 using xhci-hcd
[   13.937580] random: crng init done
get_mac_binary: file  not found!
get_mac_binary: file  not found!
Cannot parse config file '/etc/fw_env.config': No such file or directory
Failed to find NVMEM device
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
[   18.177926] nss-dp 3a001600.dp4 lan: PHY Link up speed: 1000
[   18.253617] nss-dp 3a001600.dp4 lan: PHY Link is down
[   18.256976] procd: - early -
[   18.257781] procd: - watchdog -
[   18.787495] procd: - watchdog -
[   18.787748] procd: - ubus -
[   18.941095] procd: - init -
Please press Enter to activate this console.
[   19.075882] kmodloader: loading kernel modules from /etc/modules.d/*
[   19.156478] Loading modules backported from Linux version v6.16-0-g038d61fd6422
[   19.156519] Backport generated by backports.git v6.1.145-1-47-g6194bf852a3e
[   19.171536] NET: Registered PF_QIPCRTR protocol family
[   19.208451] PPP generic driver version 2.4.2
[   19.209201] NET: Registered PF_PPPOX protocol family
[   19.210496] urngd: v1.0.2 started.
[   19.217151] wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information.
[   19.219976] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
[   19.236117] ath11k c000000.wifi: ipq8074 hw2.0
[   19.237400] ath11k c000000.wifi: FW memory mode: 0
[   19.259905] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   19.260022] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   19.611368] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   19.655300] ath11k c000000.wifi: qmi fail to get qcom,m3-dump-addr, ignore m3 dump mem req
[   19.662764] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   19.662803] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   19.749084] ath11k c000000.wifi: qmi failed to load CAL data file:cal-ahb-c000000.wifi.bin
[   19.749166] ath11k c000000.wifi: failed to load board data file: -12
[   32.487624] l11: disabling
[   79.847702] ath11k c000000.wifi: Coldboot Calibration timed out
[   79.850614] kmodloader: done loading kernel modules from /etc/modules.d/*
[   81.594629] pci 0000:01:00.0: [17cb:0306] type 00 class 0xff0000 PCIe Endpoint
[   81.594759] pci 0000:01:00.0: BAR 0 [mem 0x00000000-0x00000fff 64bit]
[   81.600885] pci 0000:01:00.0: BAR 2 [mem 0x00000000-0x00000fff 64bit]
[   81.607829] pci 0000:01:00.0: PME# supported from D0 D3hot D3cold
[   81.613839] pci 0000:01:00.0: 7.876 Gb/s available PCIe bandwidth, limited by 8.0 GT/s PCIe x1 link at 0000:00:00.0 (capable of 31.506 Gb/s with 16.0 GT/s PCIe x2 link)
[   81.620335] pcieport 0000:00:00.0: bridge window [mem 0x20300000-0x203fffff]: assigned
[   81.634899] pci 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   81.642643] pci 0000:01:00.0: BAR 2 [mem 0x20301000-0x20301fff 64bit]: assigned
[   81.649929] mhi-pci-generic 0000:01:00.0: MHI PCI device found: foxconn-sdx55
[   81.657099] mhi-pci-generic 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   81.664446] mhi-pci-generic 0000:01:00.0: enabling device (0000 -> 0002)
[   81.673725] mhi mhi0: Requested to power ON
[   81.679546] mhi mhi0: Power on setup success
[   81.756653] wwan wwan0: port wwan0qcdm0 attached
[   81.756893] wwan wwan0: port wwan0mbim0 attached
[   81.760685] wwan wwan0: port wwan0at0 attached
[   85.709168] br-lan: port 1(lan) entered blocking state
[   85.709213] br-lan: port 1(lan) entered disabled state
[   85.713255] nss-dp 3a001600.dp4 lan: entered allmulticast mode
[   85.718632] nss-dp 3a001600.dp4 lan: entered promiscuous mode
[   88.807942] nss-dp 3a001600.dp4 lan: PHY Link up speed: 1000
[   88.808009] br-lan: port 1(lan) entered blocking state
[   88.812685] br-lan: port 1(lan) entered forwarding state

That's good enough, thanks! WiFi calibration and mac addresses will start working when booting from flash. Thanks @jav I can proceed with the PR now.

I'm having some trouble compiling from your GitHub mkrle. I have all the dependencies correctly installed, I've updated to the latest version of gcc, I've tried numerous distributions, Manjaro, Ubuntu, Debian, and they all give the same error and don't generate the file correctly. Can you send the bin so I can flash it via SSH? The ITB file won't let me flash it unless I force it, and I'm not sure about this since I'd like to avoid having to solder a TTL converter. Finally, thank you all again for the effort you're making. Thank you very much.

Don't force the flash the ITB :slight_smile:

Please be aware that AFAIK flashing has only been tested by myself and if things go wrong you may still need the serial console to recover. With that said, if you still want to try here is the factory.bin that you can flash with sysupgrade -n from OEM ssh:

Well, after backing up all mtd partitions, I gave it a try, but it didn’t work.

sysupgrade -n openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin
is nand image:
Warning: optional section "sb11" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "sbl2" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "u-boot" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "lkboot" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "ddr-ap-hk09" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "ssd" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "tz" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "rpm" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
TZ authentication enabled ...
Kernel extracted from ubi image
[  212.129299] sec_upgrade_auth failed with return=-22
write: Invalid argument
0x17 /tmp/tmp_kernel.bin Image authentication failed
Rebooting the system
Image check 'platform_check_image' failed.

That's great feedback! I am not sure if my OEM OS is different (I can't check it now), but looking at the OS update dumps you shared and the output I see that checkimage executable is failing. Since you have everything backed up, could you try adding "-F" to sysupgrade?

Let’s destroy the whole thing! :slight_smile:

sysupgrade -F -n openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v
-squashfs-factory.bin
is nand image:
Warning: optional section "sb11" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "sbl2" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "u-boot" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "lkboot" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "ddr-ap-hk09" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "ssd" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "tz" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "rpm" missing from "openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
TZ authentication enabled ...
Kernel extracted from ubi image
[ 5061.366694] sec_upgrade_auth failed with return=-22
write: Invalid argument
0x17 /tmp/tmp_kernel.bin Image authentication failed
Rebooting the system
Image check 'platform_check_image' failed but --force given - will update anyway!
Sending TERM to remaining processes ... sleep adb /sbin/sysupgrade: line 114: can't open /proc/10844/cmdline: no such file
grep lua nginx nginx sh: 10750: unknown operand
nginx odhcpd logd logread cnssdaemon rngd miniupnpd miniupnpd[17228]: shutting down MiniUPnPd
dnsmasq ntpclient cat breakpad_report rpcd acfg_tool [ 5061.483637] mhi_reset_data_chan rp ffffff8001bfa080 wp ffffff8001bfa070
[ 5061.483670] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[ 5061.489086] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[ 5061.497064] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[ 5061.505040] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[ 5061.512684] mhi_test_rp_wp chan_name = IP_HW_ADPL rp           (null) wp           (null)
[ 5061.527829] mc_detach: disabled snooping on br-lan2.
[ 5061.528817] mc_detach: disabled snooping on br-lan1.
[ 5061.534851] mhi_reset_data_chan rp ffffff8001bf8000 wp ffffff8001bf8000
[ 5061.538666] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[ 5061.544980] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[ 5061.552948] mhi_test_rp_wp chan_name = QMI0 rp ffffff8001bfa070 wp ffffff8001bfa070
[ 5061.560958] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[ 5061.568578] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[ 5061.576220] mhi_test_rp_wp chan_name = IP_HW_ADPL rp           (null) wp           (null)
[ 5061.590880] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.592176] sig[0] = 0
netifd crond zebra watchquagga[2947]: zebra state -> down : read[ 5061.600326] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.607110] wlan: [8107:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 2 Max_mac_rings 1
[ 5061.611023] wlan: [8107:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 1 Max_mac_rings 1
[ 5061.612101] sig[0] = 0
[ 5061.612127] qcom_mhi_qrtr_send signal pending (qrtr-ns:831)
[ 5061.612128] sig[0] = 0
[ 5061.612160] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612161] sig[0] = 0
[ 5061.612187] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612188] sig[0] = 0
[ 5061.612211] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612213] sig[0] = 0
[ 5061.612439] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612441] sig[0] = 0
[ 5061.612456] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612457] sig[0] = 0
[ 5061.612501] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612502] sig[0] = 0
[ 5061.612526] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612527] sig[0] = 0
[ 5061.612559] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612560] sig[0] = 0
[ 5061.612596] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612597] sig[0] = 0
[ 5061.612623] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612625] sig[0] = 0
[ 5061.612647] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612648] sig[0] = 0
[ 5061.612664] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612666] sig[0] = 0
[ 5061.612693] qcom_mhi_qrtr_send signal pending (main:5093)
[ 5061.612695] sig[0] = 0
[ 5061.737976] wlan: [8107:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 2 Max_mac_rings 1
[ 5061.739761] wlan: [8107:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 1 Max_mac_rings 1
 returned EOF
watchquagga watchquagga[2947]: Terminating on signal
xl2tpd mcsd lua mcastds: Leaving mcsd executive program
netmgrd adb thermald lua rild lua fota lbd qrtr-ns iotd ping /sbin/sysupgrade: line 114: can't open /proc/9593/cmdline: no such file
grep
/usr/bin/iotd[837]: Received signal 15
Sending KILL to remaining processes ... sleep adb grep /sbin/sysupgrade: line 114: can't open /proc/10929/cmdline: no such file
grep adb nslookup /sbin/sysupgrade: line 114: can't open /proc/10947/cmdline: no such file
grep rngd iotd
Switching to ramdisk...
[ 5065.734379] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" stops
Performing system upgrade...
[ 5066.493061] wlan: [2195:I:ANY] Skip bcast de-auth reason code 3, handled in VDEV down
Terminated
@HH500V:/tmp# [ 5066.534815] device ath0 left promiscuous mode
[ 5066.534873] br-lan1: port 2(ath0) entered disabled state
[ 5066.576757] wlan: [2195:I:ANY] Skip bcast de-auth reason code 3, handled in VDEV down
[ 5066.604721] device ath1 left promiscuous mode
[ 5066.604772] br-lan1: port 3(ath1) entered disabled state
[ 5069.494863] reboot: Restarting system

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00163
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B -       201 - PBL, Start
B -      2736 - bootable_media_detect_entry, Start
B -      4201 - bootable_media_detect_success, Start
B -      4206 - elf_loader_entry, Start
B -      6873 - auth_hash_seg_entry, Start
B -     29761 - auth_hash_seg_exit, Start
B -     91734 - elf_segs_hash_verify_entry, Start
B -    154588 - PBL, End
B -    253424 - SBL1, Start
B -    332694 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B -    342576 - pm_device_init, Start
B -    525637 - PM_SET_VAL:Skip
D -    181109 - pm_device_init, Delta
B -    528046 - pm_driver_init, Start
D -      5368 - pm_driver_init, Delta
B -    534421 - clock_init, Start
D -      2104 - clock_init, Delta
B -    538416 - boot_flash_init, Start
D -     12535 - boot_flash_init, Delta
B -    554612 - boot_config_data_table_init, Start
D -      3050 - boot_config_data_table_init, Delta - (575 Bytes)
B -    562115 - Boot Setting :  0x00000618
B -    566019 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B -    572942 - sbl1_ddr_set_params, Start
B -    576755 - CPR configuration: 0x30c
B -    580201 - cpr_init, Start
B -    582977 - Rail:0 Mode: 5 Voltage: 832000
B -    588192 - CL CPR settled at 784000mV
B -    591029 - Rail:1 Mode: 5 Voltage: 896000
B -    595207 - Rail:1 Mode: 7 Voltage: 936000
D -     16531 - cpr_init, Delta
B -    602100 - Pre_DDR_clock_init, Start
B -    606096 - Pre_DDR_clock_init, End
B -    609390 - DDR Type : PCDDR3
B -    615154 - do ddr sanity test, Start
D -      1067 - do ddr sanity test, Delta
B -    619912 - DDR: Start of HAL DDR Boot Training
B -    624640 - DDR: End of HAL DDR Boot Training
B -    630313 - DDR: Checksum to be stored on flash is -854838923
B -    640744 - Image Load, Start
D -    350902 - QSEE Image Loaded, Delta - (1378368 Bytes)
B -    991738 - Image Load, Start
D -        61 - SEC Image Loaded, Delta - (0 Bytes)
B -    999424 - Image Load, Start
D -    138531 - DEVCFG Image Loaded, Delta - (32488 Bytes)
B -   1138046 - Image Load, Start
D -    149755 - RPM Image Loaded, Delta - (93060 Bytes)
B -   1287893 - Image Load, Start
D -    217434 - APPSBL Image Loaded, Delta - (554742 Bytes)
B -   1505480 - QSEE Execution, Start
D -        91 - QSEE Execution, Delta
B -   1511275 - USB D+ check, Start
D -         0 - USB D+ check, Delta
B -   1517680 - SBL1, End
D -   1266543 - SBL1, Delta
S - Flash Throughput, 6736 KB/s  (2059905 Bytes,  305785 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz


U-Boot 2016.01 (Nov 01 2022 - 18:51:28 +0800)

DRAM:  smem ram ptable found: ver: 1 len: 4
1 GiB
NAND:  Could not find nand_gpio in dts, using defaults
ONFI device found
ID = 1590aa2c
Vendor = 2c
Device = aa
qpic_nand: changing oobsize to 80 from 128 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
256 MiB
MMC:   sdhci: Node Not found, skipping initialization

PCI1 is not defined in the device tree
In:    serial@78B3000
Out:   serial@78B3000
Err:   serial@78B3000
machid: 8010008
MMC Device 0 not found
eth0 MAC Address from ART is not valid
eth1 MAC Address from ART is not valid
eth2 MAC Address from ART is not valid
eth3 MAC Address from ART is not valid
eth4 MAC Address from ART is not valid
eth5 MAC Address from ART is not valid
Hit any key to stop autoboot:  0
ubi0: attaching mtd1
ubi0: scanning is finished
ubi0: attached mtd1 (name "mtd=0", size 101 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 808, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 18680/17109, WL threshold: 4096, image sequence number: 1424527628
ubi0: available PEBs: 0, total reserved PEBs: 808, PEBs reserved for bad PEB handling: 40
Read 0 bytes from volume kernel to 44000000
No size specified -> Using max size (6221824)
## Loading kernel from FIT Image at 44000028 ...
   Using 'config@hk09' configuration
   Trying 'kernel@1' kernel subimage
     Description:  ARM64 OpenWrt Linux-4.4.60
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x44000110
     Data Size:    4112776 Bytes = 3.9 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41080000
     Entry Point:  0x41080000
     Hash algo:    crc32
     Hash value:   ad9a313a
     Hash algo:    sha1
     Hash value:   ef36bb43af10c2e6f87809ae3ee1edf3cbd49ae8
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000028 ...
   Using 'config@hk09' configuration
   Trying 'fdt@hk09' fdt subimage
     Description:  ARM64 OpenWrt qcom-ipq807x-hkxx device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x445221d8
     Data Size:    88898 Bytes = 86.8 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   e5c52334
     Hash algo:    sha1
     Hash value:   653fb0282c891edf9ee1c668b60c4a402e01e685
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x445221d8
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3e7000, end 4a3ffb41 ... OK
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor

After a delay here, it booted the secondary OEM image.

There’s something weird in the mtd partitions, as now the erasesize isn’t 0x20000 for some of them:

dev:    size   erasesize  name
mtd0: 00100000 00020000 "0:SBL1"
mtd1: 00100000 00020000 "0:MIBIB"
mtd2: 00080000 00020000 "0:BOOTCONFIG"
mtd3: 00080000 00020000 "0:BOOTCONFIG1"
mtd4: 00300000 00020000 "0:QSEE"
mtd5: 00300000 00020000 "0:QSEE_1"
mtd6: 00080000 00020000 "0:DEVCFG"
mtd7: 00080000 00020000 "0:DEVCFG_1"
mtd8: 00080000 00020000 "0:APDP"
mtd9: 00080000 00020000 "0:APDP_1"
mtd10: 00080000 00020000 "0:RPM"
mtd11: 00080000 00020000 "0:RPM_1"
mtd12: 00080000 00020000 "0:CDT"
mtd13: 00080000 00020000 "0:CDT_1"
mtd14: 00080000 00020000 "0:APPSBLENV"
mtd15: 00100000 00020000 "0:APPSBL"
mtd16: 00100000 00020000 "0:APPSBL_1"
mtd17: 000a0000 00020000 "0:ART"
mtd18: 06500000 00020000 "rootfs"
mtd19: 00900000 00020000 "0:WIFIFW"
mtd20: 06500000 00020000 "rootfs_1"
mtd21: 00900000 00020000 "0:WIFIFW_1"
mtd22: 00080000 00020000 "0:ETHPHYFW"
mtd23: 005ef000 0001f000 "kernel"
mtd24: 01bda000 0001f000 "ubi_rootfs"
mtd25: 03abb000 0001f000 "rootfs_data"
mtd26: 0020f000 0001f000 "wifi_fw"

I'm not sure why the erase is different. If you want you can try to return to the primary image first. I think that even with "-F" the the platform_check_image function is rebooting. Can you try to find dumpimage -c $1 in /lib/upgrade/platform.sh and edit it into dumpimage -V $1? Then the check should pass and it should work without "-F".

Now the whole thing broke…

sysupgrade -n /tmp/openwrt-qualcommax-ipq807x-tcl_link
hub-hh500v-squashfs-factory.bin
is nand image:
is nand image:
Warning: optional section "sb11" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "sbl2" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "u-boot" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "lkboot" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "ddr-ap-hk09" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "ssd" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "tz" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
Warning: optional section "rpm" missing from "/tmp/openwrt-qualcommax-ipq807x-tcl_linkhub-hh500v-squashfs-factory.bin". Continue...
dumpimage version 2016.01
Sending TERM to remaining processes ... lua nginx odhcpd cnssdaemon miniupnpd dnsmasq ntpclient rngd cat breakpad_report logd logread rpcd acfg_tool [  193.874082] mhi_reset_data_chan rp ffffff8001bfa080 wp ffffff8001bfa070
[  193.874115] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[  193.879509] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[  193.887510] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[  193.895486] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[  193.903122] mhi_test_rp_wp chan_name = IP_HW_ADPL rp           (null) wp           (null)
[  193.913919] mc_detach: disabled snooping on br-lan2.
[  193.919671] mc_detach: disabled snooping on br-lan1.
netifd lua crond zebra watchquagga xl2tpd watchquagga[2964]: zebra state -> down : read returned EOF
watchquagga[2964]: Termina[  193.939168] mhi_reset_data_chan rp ffffff8001bf8000 wp ffffff8001bf8000
[  193.939922] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[  193.946558] mhi_test_rp_wp chan_name = LOOPBACK rp           (null) wp           (null)
[  193.954516] mhi_test_rp_wp chan_name = QMI0 rp ffffff8001bfa070 wp ffffff8001bfa070
[  193.962487] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[  193.970135] mhi_test_rp_wp chan_name = QMI1 rp           (null) wp           (null)
[  193.977787] mhi_test_rp_wp chan_name = IP_HW_ADPL rp           (null) wp           (null)
[  193.987964] qcom_mhi_qrtr_send signal pending (main:8656)
[  193.993732] sig[0] = 0
[  193.999244] qcom_mhi_qrtr_send signal pending (main:8656)
[  193.999424] wlan: [8095:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 2 Max_mac_rings 1
[  193.999445] wlan: [8095:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 1 Max_mac_rings 1
[  193.999803] wlan: [8095:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 2 Max_mac_rings 1
[  193.999821] wlan: [8095:I:Monitor Filter] dp_mon_ht2_rx_ring_cfg: 119: srng type 1 Max_mac_rings 1
[  194.033803] sig[0] = 0
[  194.042835] qcom_mhi_qrtr_send signal pending (qrtr-ns:830)
[  194.045294] sig[0] = 0
[  194.050680] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.053135] sig[0] = 0
[  194.058655] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.060832] sig[0] = 0
[  194.066370] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.068557] sig[0] = 0
[  194.074097] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.076561] sig[0] = 0
[  194.081806] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.084009] sig[0] = 0
[  194.089996] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.091772] sig[0] = 0
[  194.097390] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.099459] sig[0] = 0
[  194.105043] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.108179] sig[0] = 0
ting on signal
mcsd ping /sbin/sysupgrade: line 114: can't open /proc/30975/cmdline: no such file
grep mcastds: Leaving mcsd executive program
sleep ping timeout lua netmgrd adb fota thermald lua lua rild lbd qrtr-ns iotd
/usr/bin/iotd[836]: Received signal 15
[  194.312923] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.312947] sig[0] = 0
[  194.317330] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.319548] sig[0] = 0
[  194.325039] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.327273] sig[0] = 0
[  194.332756] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.335012] sig[0] = 0
[  194.340488] qcom_mhi_qrtr_send signal pending (main:8656)
[  194.342724] sig[0] = 0
Sending KILL to remaining processes ... rngd sleep adb grep /sbin/sysupgrade: line 114: can't open /proc/31764/cmdline: no such file
grep adb iotd
Switching to ramdisk...
[  198.063517] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" stops
Performing system upgrade...
[  199.440039] ubi0 error: ubi_detach_mtd_dev: ubi0 reference count 2, destroy anyway
[  199.504931] ubi0: detaching mtd18
[  199.505472] ubi0: mtd18 is detached
ubiformat: mtd20 (nand), size 105906176 bytes (101.0 MiB), 808 eraseblocks of 131072 bytes (128.0 KiB), min. I/O size 2048 bytes
libscan: scanning eraseblock 807 -- 100 % complete
ubiformat: 808 eraseblocks have valid erase counter, mean value is 0
ubiformat: flashing eraseblock 141 -- 100 % complete
ubiformat: formatting eraseblock 807 -- 100 % complete
Flashed ubi
find: /proc/17075: No such file or directory
find: /proc/17076: No such file or directory
Unlocking /dev/mtd2 ...
Erasing /dev/mtd2 ...
0+1 records in
1+0 records out
2048 bytes (2.0KB) copied, 0.000041 seconds, 47.6MB/s

Writing from <stdin> to /dev/mtd2 ...
Unlocking /dev/mtd3 ...
Erasing /dev/mtd3 ...
0+1 records in
1+0 records out
2048 bytes (2.0KB) copied, 0.000041 seconds, 47.6MB/s

Writing from <stdin> to /dev/mtd3 ...
grep: /sys/block/mmcblk*/mmcblk*p*/uevent: No such file or directory
Upgrade completed
Rebooting system...
[  212.890573] reboot: Restarting system

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00163
S - IMAGE_VARIANT_STRING=HAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e5
B -       203 - PBL, Start
B -      2739 - bootable_media_detect_entry, Start
B -      4213 - bootable_media_detect_success, Start
B -      4218 - elf_loader_entry, Start
B -      6879 - auth_hash_seg_entry, Start
B -     29743 - auth_hash_seg_exit, Start
B -     91569 - elf_segs_hash_verify_entry, Start
B -    154423 - PBL, End
B -    245525 - SBL1, Start
B -    322415 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B -    332023 - pm_device_init, Start
B -    509014 - PM_SET_VAL:Skip
D -    175192 - pm_device_init, Delta
B -    511424 - pm_driver_init, Start
D -      5337 - pm_driver_init, Delta
B -    517737 - clock_init, Start
D -      2104 - clock_init, Delta
B -    521733 - boot_flash_init, Start
D -     12566 - boot_flash_init, Delta
B -    538081 - boot_config_data_table_init, Start
D -      3080 - boot_config_data_table_init, Delta - (575 Bytes)
B -    545553 - Boot Setting :  0x00000618
B -    549488 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B -    556411 - sbl1_ddr_set_params, Start
B -    560224 - CPR configuration: 0x30c
B -    563670 - cpr_init, Start
B -    566446 - Rail:0 Mode: 5 Voltage: 832000
B -    571661 - CL CPR settled at 784000mV
B -    574467 - Rail:1 Mode: 5 Voltage: 896000
B -    578646 - Rail:1 Mode: 7 Voltage: 936000
D -     16500 - cpr_init, Delta
B -    585539 - Pre_DDR_clock_init, Start
B -    589534 - Pre_DDR_clock_init, End
B -    592950 - DDR Type : PCDDR3
B -    598593 - do ddr sanity test, Start
D -      1037 - do ddr sanity test, Delta
B -    603442 - DDR: Start of HAL DDR Boot Training
B -    608078 - DDR: End of HAL DDR Boot Training
B -    613751 - DDR: Checksum to be stored on flash is -854838923
B -    624182 - Image Load, Start
D -    350994 - QSEE Image Loaded, Delta - (1378368 Bytes)
B -    975268 - Image Load, Start
D -        61 - SEC Image Loaded, Delta - (0 Bytes)
B -    982954 - Image Load, Start
D -    138561 - DEVCFG Image Loaded, Delta - (32488 Bytes)
B -   1121607 - Image Load, Start
D -    149785 - RPM Image Loaded, Delta - (93060 Bytes)
B -   1271484 - Image Load, Start
D -    217465 - APPSBL Image Loaded, Delta - (554742 Bytes)
B -   1489071 - QSEE Execution, Start
D -        91 - QSEE Execution, Delta
B -   1494866 - USB D+ check, Start
D -         0 - USB D+ check, Delta
B -   1501271 - SBL1, End
D -   1258033 - SBL1, Delta
S - Flash Throughput, 6731 KB/s  (2059905 Bytes,  306031 us)
S - DDR Frequency, 466 MHz
S - Core 0 Frequency, 1651 MHz


U-Boot 2016.01 (Nov 01 2022 - 18:51:28 +0800)

DRAM:  smem ram ptable found: ver: 1 len: 4
1 GiB
NAND:  Could not find nand_gpio in dts, using defaults
ONFI device found
ID = 1590aa2c
Vendor = 2c
Device = aa
qpic_nand: changing oobsize to 80 from 128 bytes
SF: Unsupported flash IDs: manuf ff, jedec ffff, ext_jedec ffff
ipq_spi: SPI Flash not found (bus/cs/speed/mode) = (0/0/48000000/0)
256 MiB
MMC:   sdhci: Node Not found, skipping initialization

PCI1 is not defined in the device tree
In:    serial@78B3000
Out:   serial@78B3000
Err:   serial@78B3000
machid: 8010008
MMC Device 0 not found
eth0 MAC Address from ART is not valid
eth1 MAC Address from ART is not valid
eth2 MAC Address from ART is not valid
eth3 MAC Address from ART is not valid
eth4 MAC Address from ART is not valid
eth5 MAC Address from ART is not valid
Hit any key to stop autoboot:  0
ubi0: attaching mtd1
ubi0: scanning is finished
ubi0: volume 2 ("rootfs_data") re-sized from 9 to 624 LEBs
ubi0: attached mtd1 (name "mtd=0", size 101 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 808, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 3/1, WL threshold: 4096, image sequence number: 304962861
ubi0: available PEBs: 0, total reserved PEBs: 808, PEBs reserved for bad PEB handling: 40
Read 0 bytes from volume kernel to 44000000
No size specified -> Using max size (5840896)
Kernel image authentication failed
BUG: failure at board/qca/arm/common/cmd_bootqca.c:634/do_boot_signedimg()!
BUG!
resetting ...

This means that secure boot is enabled on your box :frowning: Can you try fw_setenv atf 1 from tftpboot and then try the flash boot? I guess the variable can be set directly from u-boot as well.

Tried. Same behavior. If secure boot is enabled, why does it boot the initramfs image?

I guess bootm doesn't do the checks. Do you have is_sec_boot_enabled in u-boot?

@thai020601 did you experience secure boot issues when booting from flash?

:slightly_frowning_face:

IPQ807x# is_sec_boot_enabled
secure boot fuse is enabled