OpenWrt support for Vodafone Gigacube (B157)

:frowning: I know it's desperate but are you sure that atf variable persisted?

I think so.

IPQ807x# printenv
atf=1
baudrate=115200
bootargs=console=ttyMSM0,115200n8
bootcmd=bootipq
bootdelay=1
ethact=eth0
ethaddr=00:03:7f:xx:xx:xx
fdt_high=0x4A400000
fdtcontroladdr=4a970820
flash_type=2
ipaddr=192.168.10.10
machid=8010008
netmask=255.255.255.0
serverip=192.168.10.1
soc_version_major=2
soc_version_minor=0
stderr=serial@78B3000
stdin=serial@78B3000
stdout=serial@78B3000

No, from my boot log, i dont see any issue at all.

BTW, i found the correct patch for the modem cold boot issue: https://lore.kernel.org/all/20250227-pcie-global-irq-v1-17-2b70a7819d1e@linaro.org/.

Now the modem is detected properly!

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.12.47 (vinhthai@vinhthai-virtual-machine) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r35371-1fb621d6d8) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP PREEMPT Sun Sep 28 04:54:14 2025
[    0.000000] Machine model: TCL LINKHUB HH500V
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable memory@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] OF: reserved mem: 0x0000000051100000..0x00000000511fffff (1024 KiB) nomap non-reusable ramoops@51100000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000511fffff]
[    0.000000]   node   0: [mem 0x0000000051200000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] psci: OSI mode supported.
[    0.000000] psci: [Firmware Bug]: failed to set PC mode: -1
[    0.000000] percpu: Embedded 20 pages/cpu s43736 r8192 d29992 u81920
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 ubi.mtd=rootfs root=mtd:ubi_rootfs rootfstype=squashfs rootwait root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 262144
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Preemptible hierarchical RCU implementation.
[    0.000000]  Trampoline variant of Tasks RCU enabled.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] RCU Tasks: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000000] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000125] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000138] pid_max: default: 32768 minimum: 301
[    0.005267] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005281] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.010439] rcu: Hierarchical SRCU implementation.
[    0.010449] rcu:     Max phase no-delay instances is 1000.
[    0.010737] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level
[    0.011154] smp: Bringing up secondary CPUs ...
[    0.011818] Detected VIPT I-cache on CPU1
[    0.011933] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012704] Detected VIPT I-cache on CPU2
[    0.012783] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.013498] Detected VIPT I-cache on CPU3
[    0.013571] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013657] smp: Brought up 1 node, 4 CPUs
[    0.013666] SMP: Total of 4 processors activated.
[    0.013670] CPU: All CPU(s) started at EL1
[    0.013674] CPU features: detected: 32-bit EL0 Support
[    0.013679] CPU features: detected: CRC32 instructions
[    0.013720] alternatives: applying system-wide alternatives
[    0.013910] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.014177] Memory: 880588K/1048576K available (8832K kernel code, 904K rwdata, 2884K rodata, 960K init, 288K bss, 164516K reserved, 0K cma-reserved)
[    0.025423] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.025448] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.025550] 29248 pages in range for non-PLT usage
[    0.025555] 520768 pages in range for PLT usage
[    0.027671] pinctrl core: initialized pinctrl subsystem
[    0.030163] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.030762] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.030803] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.030840] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.031243] thermal_sys: Registered thermal governor 'step_wise'
[    0.031308] cpuidle: using governor menu
[    0.031541] ASID allocator initialised with 65536 entries
[    0.040638] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.040665] /soc@0/phy@8e000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.040752] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@8e000
[    0.040766] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.041851] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.041996] /soc@0/phy@8e000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.044352] /soc@0/phy@8e000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.044440] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.044795] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@8e000
[    0.044865] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.095320] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.118201] SCSI subsystem initialized
[    0.118429] usbcore: registered new interface driver usbfs
[    0.118471] usbcore: registered new interface driver hub
[    0.118528] usbcore: registered new device driver usb
[    0.118813] qcom_scm: convention: smc arm 64
[    0.120824] clocksource: Switched to clocksource arch_sys_counter
[    0.124567] NET: Registered PF_INET protocol family
[    0.124710] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.127076] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.127100] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.127116] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.127201] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.127477] TCP: Hash tables configured (established 8192 bind 8192)
[    0.127967] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.128139] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.128177] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.128631] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.128672] PCI: CLS 0 bytes, default 64
[    0.130506] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.131284] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.131291] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.141214] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.141381] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.142646] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.142797] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.144428] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.144604] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.144649] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.144823] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.145104] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.145233] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.145277] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.145459] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.148442] gpio-export modem: 3 gpio(s) exported
[    0.150273] qcom-pcie 20000000.pcie: host bridge /soc@0/pcie@20000000 ranges:
[    0.150331] qcom-pcie 20000000.pcie:       IO 0x0020200000..0x002020ffff -> 0x0000000000
[    0.150358] qcom-pcie 20000000.pcie:      MEM 0x0020220000..0x002fffffff -> 0x0020220000
[    0.156799] Serial: 8250/16550 driver, 2 ports, IRQ sharing disabled
[    0.157920] msm_serial 78b1000.serial: msm_serial: detected port #1
[    0.158031] msm_serial 78b1000.serial: uartclk = 19200000
[    0.158429] 78b1000.serial: ttyMSM1 at MMIO 0x78b1000 (irq = 20, base_baud = 1200000) is a MSM
[    0.159005] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.159077] msm_serial 78b3000.serial: uartclk = 3686400
[    0.159461] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 21, base_baud = 230400) is a MSM
[    0.159500] msm_serial: console setup on port #0
[    0.159551] printk: legacy console [ttyMSM0] enabled
[    0.252973] qcom-pcie 20000000.pcie: iATU: unroll T, 8 ob, 8 ib, align 4K, limit 1024G
[    0.261193] msm_serial: driver initialized
[    1.172388] loop: module loaded
[    1.173813] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.174350] nand: Micron MT29F2G08ABBGAH4
[    1.181116] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.185191] 4 fixed-partitions partitions found on MTD device qcom_nand.0
[    1.192339] Creating 4 MTD partitions on "qcom_nand.0":
[    1.199261] 0x000000000000-0x000007000000 : "rootfs_1"
[    1.270868] qcom-pcie 20000000.pcie: Phy link never came up
[    1.271425] qcom-pcie 20000000.pcie: PCI host bridge to bus 0000:00
[    1.275270] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.281541] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
[    1.287067] pci_bus 0000:00: root bus resource [mem 0x20220000-0x2fffffff]
[    1.293356] pci 0000:00:00.0: [17cb:1002] type 01 class 0x060400 PCIe Root Port
[    1.300103] pci 0000:00:00.0: BAR 0 [mem 0x00000000-0x00000fff]
[    1.307314] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.313215] pci 0000:00:00.0:   bridge window [io  0x0000-0x0fff]
[    1.318404] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff]
[    1.324671] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff 64bit pref]
[    1.331507] pci 0000:00:00.0: PME# supported from D0 D3hot D3cold
[    1.343743] pci 0000:00:00.0: BAR 0 [mem 0x20220000-0x20220fff]: assigned
[    1.345235] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.352029] pci_bus 0000:00: resource 4 [io  0x0000-0xffff]
[    1.357031] pci_bus 0000:00: resource 5 [mem 0x20220000-0x2fffffff]
[    1.365942] pcieport 0000:00:00.0: PME: Signaling with IRQ 33
[    1.369165] pcieport 0000:00:00.0: AER: enabled with IRQ 33
[    1.386800] 0x000007000000-0x000007800000 : "0:WIFIFW"
[    1.393511] 0x000007800000-0x00000e800000 : "rootfs"
[    1.480533] mtd: setting mtd2 (rootfs) as root device
[    1.480844] mtdsplit: no squashfs found in "rootfs"
[    1.484582] 0x00000e800000-0x00000f000000 : "0:WIFIFW_1"
[    1.499740] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.500601] spi-nor spi0.0: found mx25u25635f, expected n25q128a11
[    1.506163] 19 fixed-partitions partitions found on MTD device spi0.0
[    1.511888] Creating 19 MTD partitions on "spi0.0":
[    1.518368] 0x000000000000-0x000000050000 : "0:SBL1"
[    1.523577] 0x000000050000-0x000000060000 : "0:MIBIB"
[    1.528723] 0x000000060000-0x000000080000 : "0:BOOTCONFIG"
[    1.533659] 0x000000080000-0x0000000a0000 : "0:BOOTCONFIG1"
[    1.539001] 0x0000000a0000-0x000000220000 : "0:QSEE"
[    1.544536] 0x000000220000-0x0000003a0000 : "0:QSEE_1"
[    1.549708] 0x0000003a0000-0x0000003b0000 : "0:DEVCFG"
[    1.554661] 0x0000003b0000-0x0000003c0000 : "0:DEVCFG_1"
[    1.559746] 0x0000003c0000-0x0000003d0000 : "0:APDP"
[    1.565309] 0x0000003d0000-0x0000003e0000 : "0:APDP_1"
[    1.570196] 0x0000003e0000-0x000000420000 : "0:RPM"
[    1.575212] 0x000000420000-0x000000460000 : "0:RPM_1"
[    1.579927] 0x000000460000-0x000000470000 : "0:CDT"
[    1.585163] 0x000000470000-0x000000480000 : "0:CDT_1"
[    1.589803] 0x000000480000-0x000000490000 : "0:APPSBLENV"
[    1.595097] 0x000000490000-0x000000530000 : "0:APPSBL"
[    1.600383] 0x000000530000-0x0000005d0000 : "0:APPSBL_1"
[    1.605455] 0x0000005d0000-0x000000630000 : "0:ART"
[    1.611025] 0x000000630000-0x0000006b0000 : "0:ETHPHYFW"
[    1.623768] spmi_pmic_arb 200f000.spmi: PMIC arbiter version v2 (0x20010000)
[    1.652773] i2c_dev: i2c /dev entries driver
[    1.661841] sdhci: Secure Digital Host Controller Interface driver
[    1.661886] sdhci: Copyright(c) Pierre Ossman
[    1.666922] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.673754] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.681056] NET: Registered PF_INET6 protocol family
[    1.683901] Segment Routing with IPv6
[    1.687975] In-situ OAM (IOAM) with IPv6
[    1.691655] NET: Registered PF_PACKET protocol family
[    1.695670] l2tp_core: L2TP core driver, V2.0
[    1.700429] l2tp_netlink: L2TP netlink interface
[    1.704827] 8021q: 802.1Q VLAN Support v1.8
[    1.746364] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.746703] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.752556] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.759113] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.766918] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.774766] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.783414] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 712000 uV
[    1.790346] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 840000 uV
[    1.800347] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 904000 uV
[    1.810148] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop= 992000 uV
[    1.820005] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 721, quot_offset[ 7]=   0
[    1.829767] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 957, quot_offset[ 7]= 235
[    1.840617] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1060, quot_offset[ 7]= 100
[    1.851557] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1211, quot_offset[ 7]= 150
[    1.862758] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.867504] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.882309] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.891171] ubi0: attaching mtd2
[    2.149400] pci 0000:01:00.0: [17cb:0306] type 00 class 0xff0000 PCIe Endpoint
[    2.149587] pci 0000:01:00.0: BAR 0 [mem 0x00000000-0x00000fff 64bit]
[    2.155604] pci 0000:01:00.0: BAR 2 [mem 0x00000000-0x00000fff 64bit]
[    2.162612] pci 0000:01:00.0: PME# supported from D0 D3hot D3cold
[    2.168623] pci 0000:01:00.0: 7.876 Gb/s available PCIe bandwidth, limited by 8.0 GT/s PCIe x1 link at 0000:00:00.0 (capable of 31.506 Gb/s with 16.0 GT/s PCIe x2 link)
[    2.175086] pcieport 0000:00:00.0: bridge window [mem 0x20300000-0x203fffff]: assigned
[    2.189673] pci 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[    2.197430] pci 0000:01:00.0: BAR 2 [mem 0x20301000-0x20301fff 64bit]: assigned
[    2.451443] ubi0: scanning is finished
[    2.511343] ubi0: attached mtd2 (name "rootfs", size 112 MiB)
[    2.511527] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
[    2.516145] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
[    2.522884] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
[    2.529788] ubi0: good PEBs: 896, bad PEBs: 0, corrupted PEBs: 0
[    2.536547] ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128
[    2.542840] ubi0: max/mean erase counter: 61/30, WL threshold: 4096, image sequence number: 2146408881
[    2.549830] ubi0: available PEBs: 0, total reserved PEBs: 896, PEBs reserved for bad PEB handling: 40
[    2.559187] ubi0: background thread "ubi_bgt0d" started, PID 697
[    2.560045] block ubiblock0_1: created from ubi0:1(rootfs)
[    2.574860] clk: Disabling unused▒[    2.586590] VFS: Mounted root (squashfs filesystem) readonly on device 254:0.
[    2.586911] Freeing unused kernel memory: 960K
[    2.592787] Run /sbin/init as init process
[    2.745644] init: Console is alive
[    2.745786] init: - watchdog -
[    2.930865] random: crng init done
[    3.366671] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    3.448923] gpio_button_hotplug: loading out-of-tree module taints kernel.
[    3.513101] ssdk_dt_parse_interrupt[942]:INFO:intr-gpio does not exist
[    4.540880] regi_init[2525]:INFO:Initializing HPPE Done!!
[    4.541019] regi_init[2574]:INFO:qca-ssdk module init succeeded!
[    4.547463] EDMA ver 1 hw init
[    4.551601] EDMA HW Reset completed succesfully
[    4.554241] Num rings - TxDesc:1 (23-23) TxCmpl:1 (7-7)
[    4.558635] RxDesc:1 (15-15) RxFill:1 (7-7)
[    4.564356] GMAC4(ffffff800340c940) Invalid MAC@ - using 7a:ee:d0:42:3e:9e
[    4.751714] Qualcomm QCA8075 90000.mdio-1:03: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:03, irq=POLL)
[    4.752673] GMAC6(ffffff800340e940) Invalid MAC@ - using 8a:e8:3f:5b:f6:f6
[    4.823191] Qualcomm QCA8081 90000.mdio-1:10: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:10, irq=POLL)
[    4.824015] **********************************************************
[    4.832114] * NSS Data Plane driver
[    4.838589] **********************************************************
[    4.862540] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    4.862601] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 1
[    4.867062] xhci-hcd xhci-hcd.1.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    4.874558] xhci-hcd xhci-hcd.1.auto: irq 57, io mem 0x08a00000
[    4.884251] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    4.889767] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 2
[    4.895414] xhci-hcd xhci-hcd.1.auto: Host supports USB 3.0 SuperSpeed
[    4.903271] hub 1-0:1.0: USB hub found
[    4.909477] hub 1-0:1.0: 1 port detected
[    4.913404] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM.
[    4.917516] hub 2-0:1.0: USB hub found
[    4.925362] hub 2-0:1.0: 1 port detected
[    4.929213] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    4.933007] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 3
[    4.938406] xhci-hcd xhci-hcd.2.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    4.946083] xhci-hcd xhci-hcd.2.auto: irq 58, io mem 0x08c00000
[    4.955347] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    4.961123] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 4
[    4.966676] xhci-hcd xhci-hcd.2.auto: Host supports USB 3.0 SuperSpeed
[    4.974507] hub 3-0:1.0: USB hub found
[    4.980836] hub 3-0:1.0: 1 port detected
[    4.984743] usb usb4: We don't know the algorithms for LPM for this host, disabling LPM.
[    4.988842] hub 4-0:1.0: USB hub found
[    4.996715] hub 4-0:1.0: 1 port detected
[    5.003305] usbcore: registered new interface driver usb-storage
[    5.005261] usbcore: registered new interface driver uas
[    5.010541] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    5.025793] init: - preinit -
Cannot parse config file '/etc/fw_env.config': No such file or directory
Failed to find NVMEM device
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level

i notice that your OEM version using NAND chip only not NOR + NAND chip, so the earse size 00020000 is actually NAND partition, for my device flash layout is difirent:

root@HH500V:/# cat /proc/mtd
dev:    size   erasesize  name
mtd0: 00050000 00010000 "0:SBL1"
mtd1: 00010000 00010000 "0:MIBIB"
mtd2: 00020000 00010000 "0:BOOTCONFIG"
mtd3: 00020000 00010000 "0:BOOTCONFIG1"
mtd4: 00180000 00010000 "0:QSEE"
mtd5: 00180000 00010000 "0:QSEE_1"
mtd6: 00010000 00010000 "0:DEVCFG"
mtd7: 00010000 00010000 "0:DEVCFG_1"
mtd8: 00010000 00010000 "0:APDP"
mtd9: 00010000 00010000 "0:APDP_1"
mtd10: 00040000 00010000 "0:RPM"
mtd11: 00040000 00010000 "0:RPM_1"
mtd12: 00010000 00010000 "0:CDT"
mtd13: 00010000 00010000 "0:CDT_1"
mtd14: 00010000 00010000 "0:APPSBLENV"
mtd15: 000a0000 00010000 "0:APPSBL"
mtd16: 000a0000 00010000 "0:APPSBL_1"
mtd17: 00060000 00010000 "0:ART"
mtd18: 00080000 00010000 "0:ETHPHYFW"
mtd19: 07000000 00020000 "rootfs"
mtd20: 00800000 00020000 "0:WIFIFW"
mtd21: 07000000 00020000 "rootfs_1"
mtd22: 00800000 00020000 "0:WIFIFW_1"
mtd23: 00592000 0001f000 "kernel"
mtd24: 01bda000 0001f000 "ubi_rootfs"
mtd25: 045c0000 0001f000 "rootfs_data"
mtd26: 0022e000 0001f000 "wifi_fw"

I'm out of ideas. Strings dump of u-boot doesn't list atf and it clearly doesn't work. Perhaps it's possible to change bootcmd to load kernel from nand and then boot it with bootm, but then the partitions would not work unless they are hard coded.

Changing bootcmd works:

bootcmd=setenv serverip 192.168.1.1; sleep 2; dhcp hh500v.img; bootm

But I don’t see how to load an image from flash in u-boot:

IPQ807x# help
?       - alias for 'help'
aq_load_fw- LOAD aq-fw-binary
aq_phy_restart- Restart Aquantia phy
base    - print or set address offset
bdinfo  - print Board Info structure
bootipq - bootipq from flash device
bootm   - boot application image from memory
bootp   - boot image via network using BOOTP/TFTP protocol
bootz   - boot Linux zImage image from memory
canary  - test stack canary
chpart  - change active partition
cmp     - memory compare
cp      - memory copy
crc32   - checksum calculation
dcache  - enable or disable data cache
dhcp    - boot image via network using DHCP/TFTP protocol
dm      - Driver model low level access
echo    - echo args to console
env     - environment handling commands
erase   - erase FLASH memory
exectzt - execute TZT

exit    - exit script
false   - do nothing, unsuccessfully
fdt     - flattened device tree utility commands
flash   - flash part_name
        flash part_name load_addr file_size

flasherase- flerase part_name

flinfo  - print FLASH memory information
fuseipq - fuse QFPROM registers from memory

go      - start application at address 'addr'
help    - print command description/usage
i2c     - I2C sub-system
icache  - enable or disable instruction cache
imxtract- extract a part of a multi-image
ipq_mdio- IPQ mdio utility commands
is_sec_boot_enabled- check secure boot fuse is enabled or not

itest   - return true/false on integer compare
loop    - infinite loop on address range
md      - memory display
mii     - MII utility commands
mm      - memory modify (auto-incrementing address)
mmc     - MMC sub system
mmcinfo - display MMC info
mtdparts- define flash/nand partitions
mtest   - simple RAM read/write test
mw      - memory write (fill)
nand    - NAND sub-system
nboot   - boot from NAND device
nm      - memory modify (constant address)
pci     - list and access PCI Configuration Space
ping    - send ICMP ECHO_REQUEST to network host
printenv- print environment variables
protect - enable or disable FLASH write protection
reset   - Perform RESET of the CPU
run     - run commands in an environment variable
runmulticore- Enable and schedule secondary cores
saveenv - save environment variables to persistent storage
secure_authenticate- authenticate the signed image

setenv  - set environment variables
sf      - SPI flash sub-system
showvar - print local hushshell variables
sleep   - delay execution for some time
smeminfo- print SMEM FLASH information
source  - run script from memory
test    - minimal test like /bin/sh
tftpboot- boot image via network using TFTP protocol
tftpput - TFTP put command, for uploading files to a server
true    - do nothing, successfully
uart    - UART sub-system
ubi     - ubi commands
usb     - USB sub-system
usbboot - boot from USB device
version - print monitor, compiler and linker version

Tried it ?

I can’t test it myself now but it should be possible with nand and/or ubi commands.

@frollic bootipq is the standard boot command that validates the secure boot, so it doesn’t work.

I did:

setenv mtdids nand0=nand0
setenv mtdparts mtdparts=nand0:16512k(initial),101m(rootfs)
ubi part rootfs
ubi read 44000000 kernel
setenv mtdids
setenv mtdparts
bootm

And I’ve got something:

## Loading kernel from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.12.48
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x440000e8
     Data Size:    5705330 Bytes = 5.4 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41000000
     Entry Point:  0x41000000
     Hash algo:    crc32
     Hash value:   6f2c0317
     Hash algo:    sha1
     Hash value:   5682b1654b0afc197d7ef355ba658901e3d3d661
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt tcl_linkhub-hh500v device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x445710a0
     Data Size:    45450 Bytes = 44.4 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   4fd83207
     Hash algo:    sha1
     Hash value:   0f552e97f7ad8c792a79c04c094b3254042822ef
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x445710a0
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3f1000, end 4a3ff189 ... OK
mtdids not defined, no default present
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.12.48 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r31182-b5f9e00617) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP Fri Sep 26 18:23:22 2025
[    0.000000] Machine model: TCL LINKHUB HH500V
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable nss@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000510fffff]
[    0.000000]   node   0: [mem 0x0000000051100000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 20 pages/cpu s43288 r8192 d30440 u81920
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 262144
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000000] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000127] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000140] pid_max: default: 32768 minimum: 301
[    0.005209] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005223] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.010171] rcu: Hierarchical SRCU implementation.
[    0.010181] rcu:     Max phase no-delay instances is 1000.
[    0.010479] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level
[    0.010881] smp: Bringing up secondary CPUs ...
[    0.011541] Detected VIPT I-cache on CPU1
[    0.011652] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012399] Detected VIPT I-cache on CPU2
[    0.012475] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.013154] Detected VIPT I-cache on CPU3
[    0.013226] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013309] smp: Brought up 1 node, 4 CPUs
[    0.013318] SMP: Total of 4 processors activated.
[    0.013322] CPU: All CPU(s) started at EL1
[    0.013326] CPU features: detected: 32-bit EL0 Support
[    0.013331] CPU features: detected: CRC32 instructions
[    0.013379] alternatives: applying system-wide alternatives
[    0.013576] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.013836] Memory: 881328K/1048576K available (9088K kernel code, 908K rwdata, 2928K rodata, 960K init, 304K bss, 163776K reserved, 0K cma-reserved)
[    0.023027] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.023053] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.023154] 29168 pages in range for non-PLT usage
[    0.023158] 520688 pages in range for PLT usage
[    0.025322] pinctrl core: initialized pinctrl subsystem
[    0.029744] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.030298] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.030336] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.030370] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.030759] thermal_sys: Registered thermal governor 'step_wise'
[    0.030821] cpuidle: using governor menu
[    0.031028] ASID allocator initialised with 65536 entries
[    0.038758] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.038839] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.039749] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.041818] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.042117] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.092456] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.114842] SCSI subsystem initialized
[    0.115059] usbcore: registered new interface driver usbfs
[    0.115099] usbcore: registered new interface driver hub
[    0.115147] usbcore: registered new device driver usb
[    0.115435] qcom_scm: convention: smc arm 64
[    0.117196] clocksource: Switched to clocksource arch_sys_counter
[    0.121135] NET: Registered PF_INET protocol family
[    0.121275] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.124135] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.124161] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.124176] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.124261] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.124534] TCP: Hash tables configured (established 8192 bind 8192)
[    0.125014] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.125187] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125238] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.125587] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.125626] PCI: CLS 0 bytes, default 64
[    0.127476] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.128217] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.128224] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.130967] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 248)
[    0.136190] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.136338] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.137632] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.137802] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.139365] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.139497] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.139537] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.139703] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.139901] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.140042] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.140081] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.140218] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.142659] gpio-export modem: 3 gpio(s) exported
[    0.144263] qcom-pcie 20000000.pcie: host bridge /soc@0/pcie@20000000 ranges:
[    0.144322] qcom-pcie 20000000.pcie:       IO 0x0020200000..0x002020ffff -> 0x0000000000
[    0.144348] qcom-pcie 20000000.pcie:      MEM 0x0020220000..0x002fffffff -> 0x0020220000
[    0.150016] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.153694] msm_serial 78b1000.serial: msm_serial: detected port #1
[    0.153784] msm_serial 78b1000.serial: uartclk = 19200000
[    0.154152] 78b1000.serial: ttyMSM1 at MMIO 0x78b1000 (irq = 20, base_baud = 1200000) is a MSM
[    0.154579] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.154645] msm_serial 78b3000.serial: uartclk = 3686400
[    0.154983] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 21, base_baud = 230400) is a MSM
[    0.155017] msm_serial: console setup on port #0
[    0.155053] printk: legacy console [ttyMSM0] enabled
[    0.258754] qcom-pcie 20000000.pcie: iATU: unroll T, 8 ob, 8 ib, align 4K, limit 1024G
[    0.264699] msm_serial: driver initialized
[    0.477200] qcom-pcie 20000000.pcie: PCIe Gen.3 x1 link up
[    1.090086] qcom-pcie 20000000.pcie: PCI host bridge to bus 0000:00
[    1.095119] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.101290] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
[    1.106832] pci_bus 0000:00: root bus resource [mem 0x20220000-0x2fffffff]
[    1.113098] pci 0000:00:00.0: [17cb:1002] type 01 class 0x060400 PCIe Root Port
[    1.119879] pci 0000:00:00.0: BAR 0 [mem 0x00000000-0x00000fff]
[    1.127062] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.132971] pci 0000:00:00.0:   bridge window [io  0x0000-0x0fff]
[    1.138185] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff]
[    1.144423] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff 64bit pref]
[    1.151251] pci 0000:00:00.0: PME# supported from D0 D3hot D3cold
[    1.162485] pci 0000:01:00.0: [17cb:0306] type 00 class 0xff0000 PCIe Endpoint
[    1.165076] pci 0000:01:00.0: BAR 0 [mem 0x00000000-0x00000fff 64bit]
[    1.172184] pci 0000:01:00.0: BAR 2 [mem 0x00000000-0x00000fff 64bit]
[    1.179185] pci 0000:01:00.0: PME# supported from D0 D3hot D3cold
[    1.185193] pci 0000:01:00.0: 7.876 Gb/s available PCIe bandwidth, limited by 8.0 GT/s PCIe x1 link at 0000:00:00.0 (capable of 31.506 Gb/s with 16.0 GT/s PCIe x2 link)
[    1.191712] pci 0000:00:00.0: bridge window [mem 0x20300000-0x203fffff]: assigned
[    1.206243] pci 0000:00:00.0: BAR 0 [mem 0x20220000-0x20220fff]: assigned
[    1.213621] pci 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[    1.220427] pci 0000:01:00.0: BAR 2 [mem 0x20301000-0x20301fff 64bit]: assigned
[    1.227546] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.234782] pci 0000:00:00.0:   bridge window [mem 0x20300000-0x203fffff]
[    1.240006] pci_bus 0000:00: resource 4 [io  0x0000-0xffff]
[    1.246934] pci_bus 0000:00: resource 5 [mem 0x20220000-0x2fffffff]
[    1.252328] pci_bus 0000:01: resource 1 [mem 0x20300000-0x203fffff]
[    1.261155] pcieport 0000:00:00.0: PME: Signaling with IRQ 23
[    1.265148] pcieport 0000:00:00.0: AER: enabled with IRQ 23
[    1.269507] loop: module loaded
[    1.277601] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.279227] nand: Micron MT29F2G08ABBGAH4
[    1.285818] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.292153] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.298511] spi-nor spi0.0: unrecognized JEDEC id bytes: 00 00 00 00 00 00
[    1.304990] spmi_pmic_arb 200f000.spmi: PMIC arbiter version v2 (0x20010000)
[    1.348826] i2c_dev: i2c /dev entries driver
[    1.350040] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.356723] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.369920] sdhci: Secure Digital Host Controller Interface driver
[    1.369966] sdhci: Copyright(c) Pierre Ossman
[    1.375001] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.381481] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.388961] NET: Registered PF_INET6 protocol family
[    1.392136] Segment Routing with IPv6
[    1.396054] In-situ OAM (IOAM) with IPv6
[    1.399707] NET: Registered PF_PACKET protocol family
[    1.403604] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.408830] 8021q: 802.1Q VLAN Support v1.8
[    1.453214] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.453539] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.459392] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.465944] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.473642] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.481138] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.490279] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 712000 uV
[    1.497223] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 848000 uV
[    1.507214] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 912000 uV
[    1.516987] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop=1024000 uV
[    1.526878] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 657, quot_offset[ 7]=   0
[    1.536636] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 909, quot_offset[ 7]= 250
[    1.547483] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1013, quot_offset[ 7]= 100
[    1.558420] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1201, quot_offset[ 7]= 185
[    1.569563] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.573730] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.587035] nand: Micron MT29F2G08ABBGAH4
[    1.593468] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.597698] 23 qcomsmem partitions found on MTD device qcom_nand.0
[    1.604828] Creating 23 MTD partitions on "qcom_nand.0":
[    1.611094] 0x000000000000-0x000000100000 : "0:sbl1"
[    1.617912] 0x000000100000-0x000000200000 : "0:mibib"
[    1.622662] 0x000000200000-0x000000280000 : "0:bootconfig"
[    1.627273] 0x000000280000-0x000000300000 : "0:bootconfig1"
[    1.632610] 0x000000300000-0x000000600000 : "0:qsee"
[    1.640103] 0x000000600000-0x000000900000 : "0:qsee_1"
[    1.645271] 0x000000900000-0x000000980000 : "0:devcfg"
[    1.648288] 0x000000980000-0x000000a00000 : "0:devcfg_1"
[    1.653382] 0x000000a00000-0x000000a80000 : "0:apdp"
[    1.658915] 0x000000a80000-0x000000b00000 : "0:apdp_1"
[    1.663797] 0x000000b00000-0x000000b80000 : "0:rpm"
[    1.668770] 0x000000b80000-0x000000c00000 : "0:rpm_1"
[    1.673534] 0x000000c00000-0x000000c80000 : "0:cdt"
[    1.678766] 0x000000c80000-0x000000d00000 : "0:cdt_1"
[    1.683417] 0x000000d00000-0x000000d80000 : "0:appsblenv"
[    1.688654] 0x000000d80000-0x000000e80000 : "0:appsbl"
[    1.694438] 0x000000e80000-0x000000f80000 : "0:appsbl_1"
[    1.699480] 0x000000f80000-0x000001020000 : "0:art"
[    1.704631] 0x000001020000-0x000007520000 : "rootfs"
[    1.786669] mtd: setting mtd18 (rootfs) as root device
[    1.786960] mtdsplit: no squashfs found in "rootfs"
[    1.790762] 0x000007520000-0x000007e20000 : "0:wififw"
[    1.802868] 0x000007e20000-0x00000e320000 : "rootfs_1"
[    1.881316] 0x00000e320000-0x00000ec20000 : "0:wififw_1"
[    1.888786] 0x00000ec20000-0x00000eca0000 : "0:ethphyfw"
[    1.899560] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.901689] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.909666] clk: Disabling unused[    1.919840] /dev/root: Can't open blockdev
[    1.919868] VFS: Cannot open root device "/dev/ubiblock0_1" or unknown-block(0,0): error -6
[    1.922825] Please append a correct "root=" boot option; here are the available partitions:
[    1.931094] 1f00            1024 mtdblock0
[    1.931099]  (driver?)
[    1.943563] 1f01            1024 mtdblock1
[    1.943566]  (driver?)
[    1.950077] 1f02             512 mtdblock2
[    1.950080]  (driver?)
[    1.956583] 1f03             512 mtdblock3
[    1.956586]  (driver?)
[    1.963093] 1f04            3072 mtdblock4
[    1.963095]  (driver?)
[    1.969611] 1f05            3072 mtdblock5
[    1.969614]  (driver?)
[    1.976114] 1f06             512 mtdblock6
[    1.976117]  (driver?)
[    1.982625] 1f07             512 mtdblock7
[    1.982628]  (driver?)
[    1.989138] 1f08             512 mtdblock8
[    1.989141]  (driver?)
[    1.995646] 1f09             512 mtdblock9
[    1.995649]  (driver?)
[    2.002156] 1f0a             512 mtdblock10
[    2.002159]  (driver?)
[    2.009021] 1f0b             512 mtdblock11
[    2.009024]  (driver?)
[    2.015610] 1f0c             512 mtdblock12
[    2.015613]  (driver?)
[    2.022208] 1f0d             512 mtdblock13
[    2.022211]  (driver?)
[    2.028810] 1f0e             512 mtdblock14
[    2.028813]  (driver?)
[    2.035403] 1f0f            1024 mtdblock15
[    2.035406]  (driver?)
[    2.041999] 1f10            1024 mtdblock16
[    2.042002]  (driver?)
[    2.048599] 1f11             640 mtdblock17
[    2.048602]  (driver?)
[    2.055193] 1f12          103424 mtdblock18
[    2.055196]  (driver?)
[    2.061791] 1f13            9216 mtdblock19
[    2.061794]  (driver?)
[    2.068393] 1f14          103424 mtdblock20
[    2.068396]  (driver?)
[    2.074985] 1f15            9216 mtdblock21
[    2.074988]  (driver?)
[    2.081587] 1f16             512 mtdblock22
[    2.081590]  (driver?)
[    2.088185] List of all bdev filesystems:
[    2.090352]  squashfs
[    2.090354]
[    2.096684] Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)
[    2.098262] CPU: 3 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.48 #0
[    2.106329] Hardware name: TCL LINKHUB HH500V (DT)
[    2.112837] Call trace:
[    2.117693]  dump_backtrace.part.0+0xbc/0xc8
[    2.120041]  show_stack+0x18/0x24
[    2.124551]  dump_stack_lvl+0x5c/0x7c
[    2.127765]  dump_stack+0x18/0x24
[    2.131409]  panic+0x12c/0x308
[    2.134707]  mount_root_generic+0x1f4/0x2b0
[    2.137661]  mount_root+0x1c0/0x1e0
[    2.141739]  prepare_namespace+0x1d8/0x21c
[    2.145213]  kernel_init_freeable+0x27c/0x298
[    2.149381]  kernel_init+0x20/0x120
[    2.153806]  ret_from_fork+0x10/0x20
[    2.157105] SMP: stopping secondary CPUs
[    2.160930] Kernel Offset: disabled
[    2.164829] CPU features: 0x00,00000000,00000000,0200400b
[    2.168045] Memory Limit: none
[    2.173599] Rebooting in 1 seconds..

The main problem here is that in this flow u-boot is not patching the device tree. This results with two issues as far as I can tell.

First the command line is missing several arguments ubi.mtd=rootfs rootfstype=squashfs rootwait.

It should be easy to work around this one by adding them to boootargs env variable.

The second issue that the partitions are not populated by u-boot, which u-boot does using uppercase partition names. Because the partition table is empty, kernel then probes it using qcomsmem driver and ends up with a lowercase partition table:

[    1.597698] 23 qcomsmem partitions found on MTD device qcom_nand.0
[    1.604828] Creating 23 MTD partitions on "qcom_nand.0":
[    1.611094] 0x000000000000-0x000000100000 : "0:sbl1"
[    1.617912] 0x000000100000-0x000000200000 : "0:mibib"

This will in turn cause the OpenWrt scripts to fail when looking up mac addresses, wifi calibration, and fw_printenv. Theoretically this can also be done using command line, but then you have to manually take care about primary rootfs rotation, and perhaps some other things beyond my current knowledge. Based on your dmesg it could look something like this:

setenv bootargs "console=ttyMSM0,115200n8 ubi.mtd=rootfs rootfstype=squashfs rootwait \
mtdparts=nand0:1m(SBL1),1m(MIBIB),512k(BOOTCONFIG),512k(BOOTCONFIG1),3m(QSEE),3m(QSEE_1),512k(DEVCFG),512k(DEVCFG_1),512k(APDP),512k(APDP_1),512k(RPM),512k(RPM_1),512k(CDT),512k(CDT_1),512k(APPSBLENV),1m(APPSBL),1m(APPSBL_1),640k(ART),65280k(rootfs_1),7168k(WIFIFW),106880k(rootfs),8192k(WIFIFW_1),512k(ETHPHYFW)"

I modified directly the variables in u-boot so we don’t need to fiddle so much with the command line:

setenv mtdids nand0=nand0
setenv mtdparts mtdparts=nand0:1m(SBL1),1m(MIBIB),512k(BOOTCONFIG),512k(BOOTCONFIG1),3m(QSEE),3m(QSEE_1),512k(DEVCFG),512k(DEVCFG_1),512k(APDP),512k(APDP_1),512k(RPM),512k(RPM_1),512k(CDT),512k(CDT_1),512k(APPSBLENV),1m(APPSBL),1m(APPSBL_1),640k(ART),101m(rootfs),9m(WIFIFW),101m(rootfs_1),9m(WIFIFW_1),512k(ETHPHYFW)"
ubi part rootfs
ubi read 44000000 kernel
setenv bootargs "console=ttyMSM0,115200n8 ubi.mtd=rootfs rootfstype=squashfs rootwait"
bootm

It looks good:

## Loading kernel from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.12.48
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x440000e8
     Data Size:    5705330 Bytes = 5.4 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41000000
     Entry Point:  0x41000000
     Hash algo:    crc32
     Hash value:   6f2c0317
     Hash algo:    sha1
     Hash value:   5682b1654b0afc197d7ef355ba658901e3d3d661
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
   Using 'config@hk09' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt tcl_linkhub-hh500v device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x445710a0
     Data Size:    45450 Bytes = 44.4 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   4fd83207
     Hash algo:    sha1
     Hash value:   0f552e97f7ad8c792a79c04c094b3254042822ef
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x445710a0
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3f1000, end 4a3ff189 ... OK
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.12.48 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 14.3.0 r31182-b5f9e00617) 14.3.0, GNU ld (GNU Binutils) 2.44) #0 SMP Fri Sep 26 18:23:22 2025
[    0.000000] Machine model: TCL LINKHUB HH500V
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable nss@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000510fffff]
[    0.000000]   node   0: [mem 0x0000000051100000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 20 pages/cpu s43288 r8192 d30440 u81920
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 ubi.mtd=rootfs rootfstype=squashfs rootwait root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 262144
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=4.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000000] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000130] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000143] pid_max: default: 32768 minimum: 301
[    0.005201] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005215] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.010172] rcu: Hierarchical SRCU implementation.
[    0.010182] rcu:     Max phase no-delay instances is 1000.
[    0.010479] Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level
[    0.010885] smp: Bringing up secondary CPUs ...
[    0.011544] Detected VIPT I-cache on CPU1
[    0.011655] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012404] Detected VIPT I-cache on CPU2
[    0.012481] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.013164] Detected VIPT I-cache on CPU3
[    0.013236] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013319] smp: Brought up 1 node, 4 CPUs
[    0.013327] SMP: Total of 4 processors activated.
[    0.013332] CPU: All CPU(s) started at EL1
[    0.013336] CPU features: detected: 32-bit EL0 Support
[    0.013341] CPU features: detected: CRC32 instructions
[    0.013387] alternatives: applying system-wide alternatives
[    0.013588] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.013845] Memory: 881312K/1048576K available (9088K kernel code, 908K rwdata, 2928K rodata, 960K init, 304K bss, 163792K reserved, 0K cma-reserved)
[    0.023458] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.023484] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.023583] 29168 pages in range for non-PLT usage
[    0.023588] 520688 pages in range for PLT usage
[    0.025745] pinctrl core: initialized pinctrl subsystem
[    0.030225] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.030773] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.030811] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.030845] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.031223] thermal_sys: Registered thermal governor 'step_wise'
[    0.031285] cpuidle: using governor menu
[    0.031515] ASID allocator initialised with 65536 entries
[    0.039514] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.039594] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.040568] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.042872] /soc@0/phy@84000: Fixed dependency cycle(s) with /soc@0/clock-controller@1800000
[    0.043172] /soc@0/clock-controller@1800000: Fixed dependency cycle(s) with /soc@0/phy@84000
[    0.093278] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.115743] SCSI subsystem initialized
[    0.115959] usbcore: registered new interface driver usbfs
[    0.115999] usbcore: registered new interface driver hub
[    0.116046] usbcore: registered new device driver usb
[    0.116341] qcom_scm: convention: smc arm 64
[    0.118148] clocksource: Switched to clocksource arch_sys_counter
[    0.122036] NET: Registered PF_INET protocol family
[    0.122198] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.125110] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.125138] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.125153] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.125238] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.125512] TCP: Hash tables configured (established 8192 bind 8192)
[    0.125990] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.126162] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.126201] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.126527] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.126566] PCI: CLS 0 bytes, default 64
[    0.128298] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.129043] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.129049] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.131848] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 248)
[    0.137218] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.137379] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.138666] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.138794] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.140356] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.140533] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.140574] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.140751] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.140941] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.141063] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.141103] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.141269] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.143890] gpio-export modem: 3 gpio(s) exported
[    0.145569] qcom-pcie 20000000.pcie: host bridge /soc@0/pcie@20000000 ranges:
[    0.145625] qcom-pcie 20000000.pcie:       IO 0x0020200000..0x002020ffff -> 0x0000000000
[    0.145651] qcom-pcie 20000000.pcie:      MEM 0x0020220000..0x002fffffff -> 0x0020220000
[    0.151347] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.155045] msm_serial 78b1000.serial: msm_serial: detected port #1
[    0.155148] msm_serial 78b1000.serial: uartclk = 19200000
[    0.155505] 78b1000.serial: ttyMSM1 at MMIO 0x78b1000 (irq = 20, base_baud = 1200000) is a MSM
[    0.155936] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.156002] msm_serial 78b3000.serial: uartclk = 3686400
[    0.156336] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 21, base_baud = 230400) is a MSM
[    0.156372] msm_serial: console setup on port #0
[    0.156408] printk: legacy console [ttyMSM0] enabled
[    0.259698] qcom-pcie 20000000.pcie: iATU: unroll T, 8 ob, 8 ib, align 4K, limit 1024G
[    0.266066] msm_serial: driver initialized
[    1.095762] loop: module loaded
[    1.097173] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xaa
[    1.097855] nand: Micron MT29F2G08ABBGAH4
[    1.104637] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    1.108791] 23 fixed-partitions partitions found on MTD device qcom_nand.0
[    1.115825] Creating 23 MTD partitions on "qcom_nand.0":
[    1.123170] 0x000000000000-0x000000100000 : "0:SBL1"
[    1.129829] 0x000000100000-0x000000200000 : "0:MIBIB"
[    1.134482] 0x000000200000-0x000000280000 : "0:BOOTCONFIG"
[    1.138992] 0x000000280000-0x000000300000 : "0:BOOTCONFIG1"
[    1.144314] 0x000000300000-0x000000600000 : "0:QSEE"
[    1.151746] 0x000000600000-0x000000900000 : "0:QSEE_1"
[    1.156875] 0x000000900000-0x000000980000 : "0:DEVCFG"
[    1.159970] 0x000000980000-0x000000a00000 : "0:DEVCFG_1"
[    1.165053] 0x000000a00000-0x000000a80000 : "0:APDP"
[    1.170622] 0x000000a80000-0x000000b00000 : "0:APDP_1"
[    1.175464] 0x000000b00000-0x000000b80000 : "0:RPM"
[    1.180455] 0x000000b80000-0x000000c00000 : "0:RPM_1"
[    1.185198] 0x000000c00000-0x000000c80000 : "0:CDT"
[    1.190481] 0x000000c80000-0x000000d00000 : "0:CDT_1"
[    1.195089] 0x000000d00000-0x000000d80000 : "0:APPSBLENV"
[    1.200371] 0x000000d80000-0x000000e80000 : "0:APPSBL"
[    1.206116] 0x000000e80000-0x000000f80000 : "0:APPSBL_1"
[    1.211154] 0x000000f80000-0x000001020000 : "0:ART"
[    1.216295] 0x000001020000-0x000007520000 : "rootfs"
[    1.299134] mtd: setting mtd18 (rootfs) as root device
[    1.299438] mtdsplit: no squashfs found in "rootfs"
[    1.303180] 0x000007520000-0x000007e20000 : "0:WIFIFW"
[    1.315385] 0x000007e20000-0x00000e320000 : "rootfs_1"
[    1.348166] qcom-pcie 20000000.pcie: Phy link never came up
[    1.348614] qcom-pcie 20000000.pcie: PCI host bridge to bus 0000:00
[    1.352553] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.358833] pci_bus 0000:00: root bus resource [io  0x0000-0xffff]
[    1.364351] pci_bus 0000:00: root bus resource [mem 0x20220000-0x2fffffff]
[    1.370631] pci 0000:00:00.0: [17cb:1002] type 01 class 0x060400 PCIe Root Port
[    1.377387] pci 0000:00:00.0: BAR 0 [mem 0x00000000-0x00000fff]
[    1.384599] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.390491] pci 0000:00:00.0:   bridge window [io  0x0000-0x0fff]
[    1.394683] 0x00000e320000-0x00000ec20000 : "0:WIFIFW_1"
[    1.395688] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff]
[    1.407326] pci 0000:00:00.0:   bridge window [mem 0x00000000-0x000fffff 64bit pref]
[    1.409506] 0x00000ec20000-0x00000eca0000 : "0:ETHPHYFW"
[    1.414082] pci 0000:00:00.0: PME# supported from D0 D3hot D3cold
[    1.431268] pci 0000:00:00.0: BAR 0 [mem 0x20220000-0x20220fff]: assigned
[    1.433115] pci 0000:00:00.0: PCI bridge to [bus 01-ff]
[    1.433336] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.439899] pci_bus 0000:00: resource 4 [io  0x0000-0xffff]
[    1.445813] spi-nor spi0.0: unrecognized JEDEC id bytes: 00 00 00 00 00 00
[    1.452208] pci_bus 0000:00: resource 5 [mem 0x20220000-0x2fffffff]
[    1.457990] spmi_pmic_arb 200f000.spmi: PMIC arbiter version v2 (0x20010000)
[    1.467049] pcieport 0000:00:00.0: PME: Signaling with IRQ 24
[    1.478335] pcieport 0000:00:00.0: AER: enabled with IRQ 24
[    1.499766] i2c_dev: i2c /dev entries driver
[    1.500994] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.507655] aw9523-pinctrl 0-005b: No cache defaults, reading back from HW
[    1.521222] sdhci: Secure Digital Host Controller Interface driver
[    1.521266] sdhci: Copyright(c) Pierre Ossman
[    1.526302] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.533003] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.540273] NET: Registered PF_INET6 protocol family
[    1.543340] Segment Routing with IPv6
[    1.547356] In-situ OAM (IOAM) with IPv6
[    1.551012] NET: Registered PF_PACKET protocol family
[    1.554888] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.560055] 8021q: 802.1Q VLAN Support v1.8
[    1.605002] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.605371] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.611161] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.617732] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.625404] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.632907] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.642043] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 712000 uV
[    1.649001] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 848000 uV
[    1.658982] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 912000 uV
[    1.668784] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop=1024000 uV
[    1.678644] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 657, quot_offset[ 7]=   0
[    1.688404] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 909, quot_offset[ 7]= 250
[    1.699254] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1013, quot_offset[ 7]= 100
[    1.710193] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1201, quot_offset[ 7]= 185
[    1.721333] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.725810] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.741054] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.749764] ubi0: attaching mtd18
[    2.205058] ubi0: scanning is finished
[    2.268644] ubi0: attached mtd18 (name "rootfs", size 101 MiB)
[    2.268683] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
[    2.273378] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
[    2.280260] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
[    2.287093] ubi0: good PEBs: 808, bad PEBs: 0, corrupted PEBs: 0
[    2.293869] ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128
[    2.300124] ubi0: max/mean erase counter: 18682/17109, WL threshold: 4096, image sequence number: 1940344520
[    2.307150] ubi0: available PEBs: 0, total reserved PEBs: 808, PEBs reserved for bad PEB handling: 40
[    2.317148] ubi0: background thread "ubi_bgt0d" started, PID 746
[    2.317808] block ubiblock0_1: created from ubi0:1(rootfs)
[    2.332424] clk: Disabling unused▒[    2.344330] VFS: Mounted root (squashfs filesystem) readonly on device 254:0.
[    2.344633] Freeing unused kernel memory: 960K
[    2.350516] Run /sbin/init as init process
[    2.490951] init: Console is alive
[    2.491065] init: - watchdog -
[    2.858168] random: crng init done
[    2.889554] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    2.934710] gpio_button_hotplug: loading out-of-tree module taints kernel.
[    3.007200] ssdk_dt_parse_interrupt[942]:INFO:intr-gpio does not exist
[    4.028202] regi_init[2525]:INFO:Initializing HPPE Done!!
[    4.028323] regi_init[2574]:INFO:qca-ssdk module init succeeded!
[    4.034751] EDMA ver 1 hw init
[    4.038916] EDMA HW Reset completed succesfully
[    4.041565] Num rings - TxDesc:1 (23-23) TxCmpl:1 (7-7)
[    4.045958] RxDesc:1 (15-15) RxFill:1 (7-7)
[    4.051600] GMAC4(ffffff800385a980) Invalid MAC@ - using 2e:3f:a2:60:e7:0e
[    4.239009] Qualcomm QCA8075 90000.mdio-1:03: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:03, irq=POLL)
[    4.239911] GMAC6(ffffff8003859980) Invalid MAC@ - using 46:12:9e:bd:51:2c
[    4.310381] Qualcomm QCA8081 90000.mdio-1:10: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:10, irq=POLL)
[    4.311223] **********************************************************
[    4.319303] * NSS Data Plane driver
[    4.325779] **********************************************************
[    4.345666] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    4.345718] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 1
[    4.350232] xhci-hcd xhci-hcd.1.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    4.357644] xhci-hcd xhci-hcd.1.auto: irq 48, io mem 0x08a00000
[    4.367099] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    4.372891] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 2
[    4.378449] xhci-hcd xhci-hcd.1.auto: Host supports USB 3.0 SuperSpeed
[    4.386359] hub 1-0:1.0: USB hub found
[    4.392739] hub 1-0:1.0: 1 port detected
[    4.396521] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM.
[    4.400648] hub 2-0:1.0: USB hub found
[    4.408489] hub 2-0:1.0: 1 port detected
[    4.412321] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    4.416119] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 3
[    4.421552] xhci-hcd xhci-hcd.2.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000808002000010
[    4.429008] xhci-hcd xhci-hcd.2.auto: irq 49, io mem 0x08c00000
[    4.438461] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    4.444240] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 4
[    4.449804] xhci-hcd xhci-hcd.2.auto: Host supports USB 3.0 SuperSpeed
[    4.457651] hub 3-0:1.0: USB hub found
[    4.463963] hub 3-0:1.0: 1 port detected
[    4.467862] usb usb4: We don't know the algorithms for LPM for this host, disabling LPM.
[    4.472183] hub 4-0:1.0: USB hub found
[    4.479845] hub 4-0:1.0: 1 port detected
[    4.486450] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    4.488118] init: - preinit -
[    4.849539] mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.
[    4.859436] mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.
Cannot parse config file '/etc/fw_env.config': No such file or directory
Failed to find NVMEM device
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
[    8.248554] nss-dp 3a001600.dp4 lan: PHY Link up speed: 1000
[    9.336110] UBIFS (ubi0:2): default file-system created
[    9.336623] UBIFS (ubi0:2): Mounting in unauthenticated mode
[    9.340293] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" started, PID 1029
[    9.386937] UBIFS (ubi0:2): UBIFS: mounted UBI device 0, volume 2, name "rootfs_data"
[    9.386979] UBIFS (ubi0:2): LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes
[    9.393776] UBIFS (ubi0:2): FS size: 77963264 bytes (74 MiB, 614 LEBs), max 624 LEBs, journal size 3936256 bytes (3 MiB, 31 LEBs)
[    9.403666] UBIFS (ubi0:2): reserved for root: 3682397 bytes (3596 KiB)
[    9.415293] UBIFS (ubi0:2): media format: w5/r0 (latest is w5/r0), UUID 105DDFEC-7D54-4253-A890-D2EC88D5FD6B, small LPT model
[    9.423086] mount_root: overlay filesystem has not been fully initialized yet
[    9.433455] mount_root: switching to ubifs overlay
[    9.442361] overlayfs: null uuid detected in lower fs '/', falling back to xino=off,index=off,nfs_export=off.
[    9.449134] urandom-seed: Seed file not found (/etc/urandom.seed)
[    9.499686] nss-dp 3a001600.dp4 lan: PHY Link is down
[    9.504332] procd: - early -
[    9.504442] procd: - watchdog -
[   10.048018] procd: - watchdog -
[   10.048271] procd: - ubus -
[   10.202387] procd: - init -
Please press Enter to activate this console.
[   10.465477] kmodloader: loading kernel modules from /etc/modules.d/*
[   10.562511] Loading modules backported from Linux version v6.16-0-g038d61fd6422
[   10.562557] Backport generated by backports.git v6.1.145-1-47-g6194bf852a3e
[   10.578750] urngd: v1.0.2 started.
[   10.582975] NET: Registered PF_QIPCRTR protocol family
[   10.687828] PPP generic driver version 2.4.2
[   10.688904] NET: Registered PF_PPPOX protocol family
[   10.693127] wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information.
[   10.696128] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
[   10.732043] ath11k c000000.wifi: ipq8074 hw2.0
[   10.732080] ath11k c000000.wifi: FW memory mode: 0
[   10.766796] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   10.767141] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   11.741531] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   11.785489] ath11k c000000.wifi: qmi fail to get qcom,m3-dump-addr, ignore m3 dump mem req
[   11.792958] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   11.792995] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   11.868238] mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.
[   11.893390] mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.
[   12.418153] usb 3-1: new high-speed USB device number 2 using xhci-hcd
[   17.005564] remoteproc remoteproc0: stopped remote processor cd00000.q6v5_wcss
[   17.005610] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   17.011771] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   17.361816] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   17.364844] kmodloader: done loading kernel modules from /etc/modules.d/*
[   17.408515] ath11k c000000.wifi: qmi fail to get qcom,m3-dump-addr, ignore m3 dump mem req
[   17.415966] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   17.416005] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   17.715002] ath11k c000000.wifi: htt event 48 not handled
[   18.558102] mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.
[   18.566603] mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.
[   19.804263] pci 0000:01:00.0: [17cb:0306] type 00 class 0xff0000 PCIe Endpoint
[   19.804399] pci 0000:01:00.0: BAR 0 [mem 0x00000000-0x00000fff 64bit]
[   19.810595] pci 0000:01:00.0: BAR 2 [mem 0x00000000-0x00000fff 64bit]
[   19.817419] pci 0000:01:00.0: PME# supported from D0 D3hot D3cold
[   19.823546] pci 0000:01:00.0: 7.876 Gb/s available PCIe bandwidth, limited by 8.0 GT/s PCIe x1 link at 0000:00:00.0 (capable of 31.506 Gb/s with 16.0 GT/s PCIe x2 link)
[   19.830037] pcieport 0000:00:00.0: bridge window [mem 0x20300000-0x203fffff]: assigned
[   19.844553] pci 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   19.852309] pci 0000:01:00.0: BAR 2 [mem 0x20301000-0x20301fff 64bit]: assigned
[   19.859579] mhi-pci-generic 0000:01:00.0: MHI PCI device found: foxconn-sdx55
[   19.866740] mhi-pci-generic 0000:01:00.0: BAR 0 [mem 0x20300000-0x20300fff 64bit]: assigned
[   19.874088] mhi-pci-generic 0000:01:00.0: enabling device (0000 -> 0002)
[   19.883530] mhi mhi0: Requested to power ON
[   19.889207] mhi mhi0: Power on setup success
[   20.128198] wwan wwan0: port wwan0qcdm0 attached
[   20.128476] wwan wwan0: port wwan0mbim0 attached
[   20.132251] wwan wwan0: port wwan0at0 attached
[   25.119136] br-lan: port 1(lan) entered blocking state
[   25.119182] br-lan: port 1(lan) entered disabled state
[   25.123220] nss-dp 3a001600.dp4 lan: entered allmulticast mode
[   25.128552] nss-dp 3a001600.dp4 lan: entered promiscuous mode

Looks good indeed :slight_smile:

The only new thing I see is:

mtdblock: MTD device '0:ART' is NAND, please consider using UBI block devices instead.

But seeing that this partition is not UBI and has data stored at certain offsets I think it's safe to ignore. Googling around (including this forum) says the same. You can mark it ro but the warning will still be there.

Probably should be safer to keep it as ro.

This set of commands in u-boot (plus a saveenv) will set up the right vars so it boots OpenWrt.

setenv mtdids nand0=nand0
setenv mtdparts mtdparts=nand0:1m(SBL1),1m(MIBIB),512k(BOOTCONFIG),512k(BOOTCONFIG1),3m(QSEE),3m(QSEE_1),512k(DEVCFG),512k(DEVCFG_1),512k(APDP),512k(APDP_1),512k(RPM),512k(RPM_1),512k(CDT),512k(CDT_1),512k(APPSBLENV),1m(APPSBL),1m(APPSBL_1),640k(ART)ro,101m(rootfs),9m(WIFIFW),101m(rootfs_1),9m(WIFIFW_1),512k(ETHPHYFW)
setenv bootargs "console=ttyMSM0,115200n8 ubi.mtd=rootfs rootfstype=squashfs rootwait"
setenv bootcmd "ubi part rootfs;ubi read 44000000 kernel;bootm"

WiFi and 5G work fine, but fw_printenv doesn’t work

Warning: Bad CRC, using default environment

I haven’t tried to set the right ones and save them, to see if the CRC has any impact in u-boot.

I see the problem. Your APPSBLENV (NAND):

mtd14: 00080000 00020000 "0:APPSBLENV"

My APPSBLENV (NOR)

mtd18: 00010000 00010000 "0:APPSBLENV"

I have hardcoded the values for NOR, so I need to add some logic there.

Can you please check /etc/fw_env.config in OEM firmware just so that I make sure I'm doing it right?

/dev/mtd14 0x0 0x40000 0x00020000 2

Thanks. I've made the changes and uploaded new images to the last filebin.

I think with the current u-boot setup that you have tftpboot initramfs should actually work just fine. That said, you can also test sysupgrade, but don't forget -s to keep flashing the same partition and leave OEM as a backup (if so desired ofc).

sysupgrade worked perfectly fine and now fw_printenv works fine too.

In principle, changing u-boot variables and flashing factory.bin from ssh should allow to install OpenWrt now without a serial connection, right?

Yes, but we would have to be very careful in this case. Without serial, one typo = brick. Also, OEM could be running from 1st or 2nd root, so one would need to account for this in mtdparts. And again, when sysupgrading the partitions would change when not using -s. So one would have to modify mtdparts manually each time they want to switch root. Unless this gets scripted very well :slight_smile:

It would also be good to figure out a way to check if secure boot fuse has been blown from OEM. I think dumpimage -c was passing for me but I'm not so sure any longer.

Please, from HH500V webgui, I downloaded configure.bin (HH500V_VDFGR_V2.0.0B20, Greece) but after running the script and restored it, still does not allow connecting as root from ssh, says “connection refused”, am I doing something wrong or need anything else for having root ssh access to router interface? My kneed is to make changes on current settings so that can modify DNS and if possible other hidden options. Also if there is an OpenWRT modified to work with my router, PLEASE let me have it, tired with all those “locks” from Vodafone. Note that my router works with other ISP than Vodafone, I have a SIM from Cosmote ISP, and it works very good. Thank you for all these posts, I learned a lot for my router that support from Vodafone or TCL is very ….short!!!