OpenWrt support for Xiaomi AX3000T

Check the kernel logs in luci?

First post updated.

Now remittor's images 24.05.4 support new nand chip Winbond W25N01KV (240822 and newest).

4 Likes

This is idle state , dummy AP , booth radios on , but nothing connected.
Also since it measure on 12V side , losses of power supply are not concidered.

1 Like

Idle:
5W Original Firmware
4.5W Openwrt

Wifi 5Ghz 20dBm Transfer:
330mbit 9W

Using the higher 5Ghz channels UNII-2-Ext: 5470-5725 MHz OpenWRT send with mit 26dBm.
Here with Data transfer 11.5W

1 Like

Hi all. rd23 here, set by alexq guide, but something going bad, now i have u-boot, and accept only load by tftp, then after

ubiformat /dev/mtd8 -y -f /tmp/openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-initramfs-factory.ubi

i see in putty console

Wrong Image Type for bootm command
ERROR -91: can't get kernel image!

and again and again. i tried snapshot, of release, and many others, looks the same.
yea, and ubootmod firmware too. what can i do with these?

And after tftp recovery i can reboot device without tftp, firmware load, but still
readonly

boot

Press UP/DOWN to move, ENTER to select, ESC to quit
No size specified -> Using max size (8380416)
Read 8380416 bytes from volume recovery to 0000000046000000
## Loading kernel from FIT Image at 46000000 ...
   Using 'config-1' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.6.47
     Type:         Kernel Image
     Compression:  lzma compressed
     Data Start:   0x460000e8
     Data Size:    4335940 Bytes = 4.1 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x48000000
     Entry Point:  0x48000000
     Hash algo:    crc32
     Hash value:   477b6fca
     Hash algo:    sha1
     Hash value:   44e385077339d4c172fe0e78be8e6c07e9fbcb7d
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading ramdisk from FIT Image at 46000000 ...
   Using 'config-1' configuration
   Trying 'initrd-1' ramdisk subimage
     Description:  ARM64 OpenWrt xiaomi_mi-router-ax3000t-ubootmod initrd
     Type:         RAMDisk Image
     Compression:  uncompressed
     Data Start:   0x46422b78
     Data Size:    3954860 Bytes = 3.8 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: unavailable
     Entry Point:  unavailable
     Hash algo:    crc32
     Hash value:   e5644c04
     Hash algo:    sha1
     Hash value:   86b355042bf131d0f23f2dc7c0d8d1e0053d19d7
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 46000000 ...
   Using 'config-1' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt xiaomi_mi-router-ax3000t-ubootmod device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x467e8544
     Data Size:    23023 Bytes = 22.5 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   12b3dbff
     Hash algo:    sha1
     Hash value:   946030b9c7488f6da2917989f90f80bbc30c821e
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x467e8544
Working FDT set to 467e8544
   Uncompressing Kernel Image to 48000000
   Loading Ramdisk to 4f435000, end 4f7fa8ac ... OK
   Loading Device Tree to 000000004f42c000, end 000000004f4349ee ... OK
Working FDT set to 4f42c000
Add 'ramoops@42ff0000' node failed: FDT_ERR_EXISTS

Starting kernel ...

<6>[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
<5>[    0.000000] Linux version 6.6.47 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 13.3.0 r27201-1069514978) 13.3.0, GNU ld (GNU Binutils) 2.42) #0 SMP Wed Aug 21 23:20:02 2024
<6>[    0.000000] Machine model: Xiaomi Mi Router AX3000T (OpenWrt U-Boot layout)
<6>[    0.000000] OF: reserved mem: 0x0000000042ff0000..0x0000000042ffffff (64 KiB) map non-reusable ramoops@42ff0000
<6>[    0.000000] OF: reserved mem: 0x0000000043000000..0x000000004302ffff (192 KiB) nomap non-reusable secmon@43000000
<6>[    0.000000] OF: reserved mem: 0x0000000047c80000..0x0000000047d7ffff (1024 KiB) nomap non-reusable wmcpu-reserved@47c80000
<6>[    0.000000] OF: reserved mem: 0x0000000047d80000..0x0000000047dbffff (256 KiB) nomap non-reusable wo-emi@47d80000
<6>[    0.000000] OF: reserved mem: 0x0000000047dc0000..0x0000000047ffffff (2304 KiB) nomap non-reusable wo-data@47dc0000
<6>[    0.000000] Zone ranges:
<6>[    0.000000]   DMA      [mem 0x0000000040000000-0x000000004fffffff]
<6>[    0.000000]   DMA32    empty
<6>[    0.000000]   Normal   empty
<6>[    0.000000] Movable zone start for each node
<6>[    0.000000] Early memory node ranges
<6>[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000042ffffff]
<6>[    0.000000]   node   0: [mem 0x0000000043000000-0x000000004302ffff]
<6>[    0.000000]   node   0: [mem 0x0000000043030000-0x0000000047c7ffff]
<6>[    0.000000]   node   0: [mem 0x0000000047c80000-0x0000000047ffffff]
<6>[    0.000000]   node   0: [mem 0x0000000048000000-0x000000004fffffff]
<6>[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000004fffffff]
<6>[    0.000000] psci: probing for conduit method from DT.
<6>[    0.000000] psci: PSCIv1.1 detected in firmware.
<6>[    0.000000] psci: Using standard PSCI v0.2 function IDs
<6>[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
<6>[    0.000000] psci: SMC Calling Convention v1.4
<6>[    0.000000] percpu: Embedded 18 pages/cpu s35112 r8192 d30424 u73728
<7>[    0.000000] pcpu-alloc: s35112 r8192 d30424 u73728 alloc=18*4096
<7>[    0.000000] pcpu-alloc: [0] 0 [0] 1
<6>[    0.000000] Detected VIPT I-cache on CPU0
<6>[    0.000000] CPU features: detected: GIC system register CPU interface
<6>[    0.000000] CPU features: kernel page table isolation disabled by kernel configuration
<6>[    0.000000] alternatives: applying boot alternatives
<5>[    0.000000] Kernel command line: console=ttyS0,115200n8 console_msg_format=syslog
<6>[    0.000000] Dentry cache hash table entries: 32768 (order: 6, 262144 bytes, linear)
<6>[    0.000000] Inode-cache hash table entries: 16384 (order: 5, 131072 bytes, linear)
<6>[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 64512
<6>[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
<6>[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 0MB
<6>[    0.000000] software IO TLB: area num 2.
<6>[    0.000000] software IO TLB: SWIOTLB bounce buffer size roundup to 0MB
<6>[    0.000000] software IO TLB: mapped [mem 0x000000004fe47000-0x000000004fec7000] (0MB)
<6>[    0.000000] Memory: 235316K/262144K available (8896K kernel code, 904K rwdata, 2592K rodata, 448K init, 304K bss, 26828K reserved, 0K cma-reserved)
<6>[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
<6>[    0.000000] rcu: Hierarchical RCU implementation.
<6>[    0.000000] rcu:  RCU restricting CPUs from NR_CPUS=4 to nr_cpu_ids=2.
<6>[    0.000000]       Tracing variant of Tasks RCU enabled.
<6>[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
<6>[    0.000000] rcu: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=2
<6>[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
<6>[    0.000000] GICv3: GIC: Using split EOI/Deactivate mode
<6>[    0.000000] GICv3: 640 SPIs implemented
<6>[    0.000000] GICv3: 0 Extended SPIs implemented
<6>[    0.000000] Root IRQ handler: gic_handle_irq
<6>[    0.000000] GICv3: GICv3 features: 16 PPIs
<6>[    0.000000] GICv3: CPU0: found redistributor 0 region 0:0x000000000c080000
<6>[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
<6>[    0.000000] arch_timer: cp15 timer(s) running at 13.00MHz (phys).
<6>[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x2ff89eacb, max_idle_ns: 440795202429 ns
<6>[    0.000000] sched_clock: 56 bits at 13MHz, resolution 76ns, wraps every 4398046511101ns
<6>[    0.000076] Calibrating delay loop (skipped), value calculated using timer frequency.. 26.00 BogoMIPS (lpj=130000)
<6>[    0.000084] pid_max: default: 32768 minimum: 301
<6>[    0.002952] Mount-cache hash table entries: 512 (order: 0, 4096 bytes, linear)
<6>[    0.002959] Mountpoint-cache hash table entries: 512 (order: 0, 4096 bytes, linear)
<4>[    0.005119] cacheinfo: Unable to detect cache hierarchy for CPU 0
<6>[    0.005657] RCU Tasks Trace: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1.
<6>[    0.005800] rcu: Hierarchical SRCU implementation.
<6>[    0.005803] rcu:  Max phase no-delay instances is 1000.
<6>[    0.006215] smp: Bringing up secondary CPUs ...
<6>[    0.006587] Detected VIPT I-cache on CPU1
<6>[    0.006633] GICv3: CPU1: found redistributor 1 region 0:0x000000000c0a0000
<6>[    0.006664] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
<6>[    0.006735] smp: Brought up 1 node, 2 CPUs
<6>[    0.006740] SMP: Total of 2 processors activated.
<6>[    0.006744] CPU features: detected: 32-bit EL0 Support
<6>[    0.006747] CPU features: detected: CRC32 instructions
<6>[    0.006779] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
<6>[    0.006783] CPU: All CPU(s) started at EL2
<6>[    0.006784] alternatives: applying system-wide alternatives
<6>[    0.010456] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
<6>[    0.010474] futex hash table entries: 512 (order: 3, 32768 bytes, linear)
<6>[    0.011732] pinctrl core: initialized pinctrl subsystem
<6>[    0.012833] NET: Registered PF_NETLINK/PF_ROUTE protocol family
<6>[    0.013423] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
<6>[    0.013452] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
<6>[    0.013473] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
<6>[    0.013838] thermal_sys: Registered thermal governor 'fair_share'
<6>[    0.013842] thermal_sys: Registered thermal governor 'bang_bang'
<6>[    0.013845] thermal_sys: Registered thermal governor 'step_wise'
<6>[    0.013847] thermal_sys: Registered thermal governor 'user_space'
<6>[    0.013915] ASID allocator initialised with 65536 entries
<6>[    0.014961] pstore: Using crash dump compression: deflate
<6>[    0.014966] pstore: Registered ramoops as persistent store backend
<6>[    0.014969] ramoops: using 0x10000@0x42ff0000, ecc: 0
<6>[    0.021994] Modules: 29440 pages in range for non-PLT usage
<6>[    0.022003] Modules: 520960 pages in range for PLT usage
<6>[    0.022865] cryptd: max_cpu_qlen set to 1000
<5>[    0.024002] SCSI subsystem initialized
<7>[    0.024213] libata version 3.00 loaded.
<6>[    0.025715] clocksource: Switched to clocksource arch_sys_counter
<6>[    0.027989] NET: Registered PF_INET protocol family
<6>[    0.028094] IP idents hash table entries: 4096 (order: 3, 32768 bytes, linear)
<6>[    0.029346] tcp_listen_portaddr_hash hash table entries: 256 (order: 0, 4096 bytes, linear)
<6>[    0.029360] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
<6>[    0.029369] TCP established hash table entries: 2048 (order: 2, 16384 bytes, linear)
<6>[    0.029386] TCP bind hash table entries: 2048 (order: 4, 65536 bytes, linear)
<6>[    0.029439] TCP: Hash tables configured (established 2048 bind 2048)
<6>[    0.029513] UDP hash table entries: 256 (order: 1, 8192 bytes, linear)
<6>[    0.029538] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes, linear)
<6>[    0.029807] NET: Registered PF_UNIX/PF_LOCAL protocol family
<6>[    0.029835] PCI: CLS 0 bytes, default 64
<6>[    0.030037] Unpacking initramfs...
<6>[    0.036621] workingset: timestamp_bits=46 max_order=16 bucket_order=0
<6>[    0.041376] squashfs: version 4.0 (2009/01/31) Phillip Lougher
<6>[    0.041384] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
<6>[    0.074851] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251)
<6>[    0.085615] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
<6>[    0.088707] printk: console [ttyS0] disabled
<6>[    0.109044] 11002000.serial: ttyS0 at MMIO 0x11002000 (irq = 72, base_baud = 2500000) is a ST16650V2
<6>[    0.109085] printk: console [ttyS0] enabled
<6>[    0.893997] loop: module loaded
<6>[    0.900420] spi-nand spi0.0: ESMT SPI NAND was found.
<6>[    0.905773] spi-nand spi0.0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64
<6>[    1.193134] Freeing initrd memory: 3860K
<5>[    1.206989] 9 fixed-partitions partitions found on MTD device spi0.0
<5>[    1.213612] Creating 9 MTD partitions on "spi0.0":
<5>[    1.218668] 0x000000000000-0x000000100000 : "BL2"
<5>[    1.224723] 0x000000100000-0x000000140000 : "Nvram"
<5>[    1.230535] 0x000000140000-0x000000180000 : "Bdata"
<5>[    1.237183] 0x000000180000-0x000000380000 : "Factory"
<5>[    1.244215] 0x000000380000-0x000000580000 : "FIP"
<5>[    1.250661] 0x000000580000-0x0000005c0000 : "crash"
<5>[    1.256426] 0x0000005c0000-0x000000600000 : "crash_log"
<5>[    1.262513] 0x000007600000-0x000007640000 : "KF"
<5>[    1.268055] 0x000000600000-0x000007600000 : "ubi"
<6>[    1.477568] mtk_soc_eth 15100000.ethernet eth0: mediatek frame engine at 0xffffffc081280000, irq 75
<6>[    1.487599] i2c_dev: i2c /dev entries driver
<6>[    1.494687] mtk-wdt 1001c000.watchdog: Watchdog enabled (timeout=31 sec, nowayout=0)
<6>[    1.504041] NET: Registered PF_INET6 protocol family
<6>[    1.510569] Segment Routing with IPv6
<6>[    1.514518] In-situ OAM (IOAM) with IPv6
<6>[    1.518798] NET: Registered PF_PACKET protocol family
<6>[    1.524136] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
<6>[    1.537633] 8021q: 802.1Q VLAN Support v1.8
<6>[    1.659085] mt7530-mdio mdio-bus:1f: configuring for fixed/2500base-x link mode
<6>[    1.668345] mt7530-mdio mdio-bus:1f: Link is Up - 2.5Gbps/Full - flow control rx/tx
<6>[    1.679088] mt7530-mdio mdio-bus:1f wan (uninitialized): PHY [mt7530-0:00] driver [MediaTek MT7531 PHY] (irq=80)
<6>[    1.701542] mt7530-mdio mdio-bus:1f lan2 (uninitialized): PHY [mt7530-0:01] driver [MediaTek MT7531 PHY] (irq=81)
<6>[    1.723834] mt7530-mdio mdio-bus:1f lan3 (uninitialized): PHY [mt7530-0:02] driver [MediaTek MT7531 PHY] (irq=82)
<6>[    1.746195] mt7530-mdio mdio-bus:1f lan4 (uninitialized): PHY [mt7530-0:03] driver [MediaTek MT7531 PHY] (irq=83)
<6>[    1.758046] mtk_soc_eth 15100000.ethernet eth0: entered promiscuous mode
<6>[    1.765052] DSA: tree 0 setup
<5>[    1.768896] UBI: auto-attach mtd8
<5>[    1.772481] ubi0: default fastmap pool size: 40
<5>[    1.777295] ubi0: default fastmap WL pool size: 20
<5>[    1.782334] ubi0: attaching mtd8
<5>[    2.159919] ubi0: scanning is finished
<5>[    2.170331] ubi0: attached mtd8 (name "ubi", size 112 MiB)
<5>[    2.176099] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
<5>[    2.183221] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
<5>[    2.190260] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
<5>[    2.197471] ubi0: good PEBs: 896, bad PEBs: 0, corrupted PEBs: 0
<5>[    2.203725] ubi0: user volume: 6, internal volumes: 1, max. volumes count: 128
<5>[    2.211196] ubi0: max/mean erase counter: 50/26, WL threshold: 4096, image sequence number: 262617550
<5>[    2.220664] ubi0: available PEBs: 0, total reserved PEBs: 896, PEBs reserved for bad PEB handling: 20
<5>[    2.230142] ubi0: background thread "ubi_bgt0d" started, PID 616
<7>[    2.237659] FIT: Selected configuration: "config-1" (OpenWrt xiaomi_mi-router-ax3000t-ubootmod)
<7>[    2.246648] FIT:           kernel sub-image 0x00001000..0x005a4bfa "kernel-1" (ARM64 OpenWrt Linux-6.6.47)
<7>[    2.256673] FIT:          flat_dt sub-image 0x005a5000..0x005aa9ee "fdt-1" (ARM64 OpenWrt xiaomi_mi-router-ax3000t-ubootmod device tree blob)
<7>[    2.269723] FIT:       filesystem sub-image 0x005ab000..0x009b3fff "rootfs-1" (ARM64 OpenWrt xiaomi_mi-router-ax3000t-ubootmod rootfs)
<7>[    2.282150] FIT: selecting configured loadable "rootfs-1" to be root filesystem
<6>[    2.289711]  ubiblock0_4: p1(rootfs-1)
<6>[    2.289936] block ubiblock0_4: created from ubi0:4(fit)
<6>[    2.299552] clk: Disabling unused clocks
<6>[    2.304374] Freeing unused kernel memory: 448K
<6>[    2.309155] Run /init as init process
<7>[    2.313066]   with arguments:
<7>[    2.316294]     /init
<7>[    2.318816]   with environment:
<7>[    2.322204]     HOME=/
<7>[    2.324812]     TERM=linux
<14>[    2.488187] init: Console is alive
<14>[    2.492060] init: - watchdog -
<14>[    2.500195] kmodloader: loading kernel modules from /etc/modules-boot.d/*
<4>[    2.510412] gpio_button_hotplug: loading out-of-tree module taints kernel.
<14>[    2.520526] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
<14>[    2.537473] init: - preinit -
<6>[    2.659698] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode
<6>[    2.668633] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx
<6>[    2.713940] mt7530-mdio mdio-bus:1f lan4: configuring for phy/gmii link mode
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
<5>[    4.884317] random: procd: uninitialized urandom read (4 bytes read)
<14>[    4.886946] procd: - early -
<14>[    4.894327] procd: - watchdog -
<14>[    5.433474] procd: - watchdog -
<14>[    5.437164] procd: - ubus -
<5>[    6.725724] random: crng init done
<14>[    6.731925] procd: - init -
Please press Enter to activate this console.
<14>[    6.923675] kmodloader: loading kernel modules from /etc/modules.d/*
<6>[    6.941055] crypto-safexcel 10320000.crypto: EIP97:230(0,1,4,4)-HIA:270(0,5,5),PE:150/433(alg:7fcdfc00)/0/0/0
<6>[    6.958067] Loading modules backported from Linux version v6.9.9-0-g28fdf4518483
<6>[    6.965740] Backport generated by backports.git v6.1.97-1-29-gf1d24a3683b2
<14>[    7.131437] urngd: v1.0.2 started.
<6>[    7.315881] mt798x-wmac 18000000.wifi: HW/SW Version: 0x8a108a10, Build Time: 20221208201745a
<6>[    7.315881]
<6>[    7.332291] mt798x-wmac 18000000.wifi: WM Firmware Version: ____000000, Build Time: 20221208201806
<6>[    7.374547] mt798x-wmac 18000000.wifi: WA Firmware Version: DEV_000000, Build Time: 20221208202048
<6>[    7.466126] mt798x-wmac 18000000.wifi: registering led 'mt76-phy0'
<6>[    7.507225] mt798x-wmac 18000000.wifi: registering led 'mt76-phy1'
<6>[    9.744986] PPP generic driver version 2.4.2
<6>[    9.750278] NET: Registered PF_PPPOX protocol family
<14>[    9.758242] kmodloader: done loading kernel modules from /etc/modules.d/*
<4>[   10.841971] mtdblock: MTD device 'Bdata' is NAND, please consider using UBI block devices instead.
<6>[   14.560240] mtk_soc_eth 15100000.ethernet eth0: Link is Down
<6>[   14.583081] mtk_soc_eth 15100000.ethernet eth0: configuring for fixed/2500base-x link mode
<6>[   14.591838] mtk_soc_eth 15100000.ethernet eth0: Link is Up - 2.5Gbps/Full - flow control rx/tx
<6>[   14.598409] mt7530-mdio mdio-bus:1f lan2: configuring for phy/gmii link mode
<6>[   15.616933] br-lan: port 1(lan2) entered blocking state
<6>[   15.622427] br-lan: port 1(lan2) entered disabled state
<6>[   15.627950] mt7530-mdio mdio-bus:1f lan2: entered allmulticast mode
<6>[   15.634470] mtk_soc_eth 15100000.ethernet eth0: entered allmulticast mode
<6>[   15.644273] mt7530-mdio mdio-bus:1f lan2: entered promiscuous mode
<6>[   15.663921] mt7530-mdio mdio-bus:1f lan3: configuring for phy/gmii link mode
<6>[   15.672065] br-lan: port 2(lan3) entered blocking state
<6>[   15.677638] br-lan: port 2(lan3) entered disabled state
<6>[   15.683153] mt7530-mdio mdio-bus:1f lan3: entered allmulticast mode
<6>[   15.691538] mt7530-mdio mdio-bus:1f lan3: entered promiscuous mode
<6>[   15.707621] mt7530-mdio mdio-bus:1f lan4: configuring for phy/gmii link mode
<6>[   15.720527] br-lan: port 3(lan4) entered blocking state
<6>[   15.726101] br-lan: port 3(lan4) entered disabled state
<6>[   15.731629] mt7530-mdio mdio-bus:1f lan4: entered allmulticast mode
<6>[   15.740405] mt7530-mdio mdio-bus:1f lan4: entered promiscuous mode
<6>[   15.759006] mt7530-mdio mdio-bus:1f wan: configuring for phy/gmii link mode
<6>[   17.883813] mt7530-mdio mdio-bus:1f wan: Link is Up - 100Mbps/Full - flow control off
<6>[   24.969768] mt7530-mdio mdio-bus:1f wan: Link is Down
<6>[   25.348796] mt7530-mdio mdio-bus:1f lan2: Link is Up - 1Gbps/Full - flow control rx/tx
<6>[   25.982947] br-lan: port 1(lan2) entered blocking state
<6>[   25.988483] br-lan: port 1(lan2) entered forwarding state
<6>[   29.087814] mt7530-mdio mdio-bus:1f wan: Link is Up - 100Mbps/Full - flow control off



BusyBox v1.36.1 (2024-08-21 23:20:02 UTC) built-in shell (ash)

  _______                     ________        __
 |       |.-----.-----.-----.|  |  |  |.----.|  |_
 |   -   ||  _  |  -__|     ||  |  |  ||   _||   _|
 |_______||   __|_____|__|__||________||__|  |____|
          |__| W I R E L E S S   F R E E D O M
 -----------------------------------------------------
 OpenWrt SNAPSHOT, r27201-1069514978
 -----------------------------------------------------

Finally i'm tried guide snapshot
and
after

ubiformat /dev/mtd8 -y -f /tmp/openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-ubootmod-initramfs-factory.ubi

or

ubiformat /dev/mtd8 -y -f /tmp/openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-initramfs-factory.ubi

get

Using ethernet@15100000 device
TFTP from server 192.168.1.254; our IP address is 192.168.1.1
Filename 'openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-ubootmod-initramfs-recovery.itb'.
ERROR: reserving fdt memory region failed (addr=4fc00000 size=100000 flags=4)
Load address: 0x46000000
Loading: T T T T T T T T T T

What you get is the serial log when you start the router? Why do you fall back to tftp boot? No uboot menu?

When i was stuck in initramfs mode i did the uboot 'reset-to-defaults' step, mabe this helps?

Be aware the latest snapshot r27201-1069514978 from firmware selector took so much longer time (63 seconds) booting than before (as I recall less than 30 seconds) that I thought it was bricked and panic for quite a bit.

Hope it calms down a little bit for anyone who has similar experience?

    ( ( ( OpenWrt ) ) )       U-Boot 2024.07-OpenWrt-r27179-2ae5bea856 (Aug 
  1. Run default boot command.
  2. Boot system via TFTP.
  3. Boot production system from NAND.
  4. Boot recovery system from NAND.
  5. Load production system via TFTP then write to NAND.
  6. Load recovery system via TFTP then write to NAND.
  7. Load BL31+U-Boot FIP via TFTP then write to NAND.
  8. Load BL2 preloader via TFTP then write to NAND.
  9. Reboot.
  a. Reset all settings to factory defaults.
  0. Exit

If i choose 3 or 4

Volume fit not found!
Press ENTER to return to menu

Default boot - Boot system via TFTP.

i boot from tftp, then

ubiformat /dev/mtd8 -y -f /tmp/openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-ubootmod-initramfs-factory.ubi

or

ubiformat /dev/mtd8 -y -f /tmp/openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-initramfs-factory.ubi

get

Using ethernet@15100000 device
TFTP from server 192.168.1.254; our IP address is 192.168.1.1
Filename 'openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-ubootmod-initramfs-recovery.itb'.
ERROR: reserving fdt memory region failed (addr=4fc00000 size=100000 flags=4)
Load address: 0x46000000

and over and over

Then your partitions or uboot environment variables are messed up

Tftp should not be the default boot option.

Recover to stock with the vendor recovery tool

I do not save backups of original firmware. Can I revert to the stock configuration?

Hello

Message : Cannot find volume 'kernel'

This is the log

.[?25l.[2J.[1;1H.[1;1H.[2K.[2;1H  *** U-Boot Boot Menu ***.[0K.[3;1H.[2K.[14;1H.[2K.[15;1H  Press UP/DOWN to move, ENTER to select, ESC/CTRL+C to quit.[0K.[16;1H.[2K.[4;1H     .[7m1. Startup system (Default).[0m.[5;1H     2. Startup firmware0.[6;1H     3. Startup firmware1.[7;1H     4. Upgrade firmware.[8;1H     5. Upgrade ATF BL2.[9;1H     6. Upgrade ATF FIP.[10;1H     7. Upgrade single image.[11;1H     8. Load image.[12;1H     0. U-Boot console.[14;1H  Hit any key to stop autoboot:  5 ... 4 ... 3 ... 2 ... 1 ... 0 .[14;1H.[2K.[?25h.[2J.[1;1Hdetect button reset released!
Reading from 0x0 to 0x4f7fdd7c, size 0x4 ... OK
Boot failure detected on both systems
Reading from 0x0 to 0x4f7fdd7c, size 0x4 ... OK
Saving Environment to MTD... Erasing on MTD device 'nmbm0'... OK
Writing to MTD device 'nmbm0'... OK
OK
Booting System 0, sys1_failed = 1323, sys2_failed = 9
ubi0: attaching mtd9
ubi0: scanning is finished
ubi0: attached mtd9 (name "ubi", size 34 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 272, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 0, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 5/3, WL threshold: 4096, image sequence number: 1825635382
ubi0: available PEBs: 249, total reserved PEBs: 23, PEBs reserved for bad PEB handling: 19
Reading from volume 'kernel' to 0x46000000, size 0x0 ... .[93;41m*** Cannot find volume 'kernel' ***.[0m
resetting ...


F0: 102B 0000

FA: 1040 0000

FA: 1040 0000 [0200]

F9: 0000 0000

V0: 0000 0000 [0001]

00: 0000 0000

BP: 2400 0041 [0000]

G0: 1190 0000

EC: 0000 0000 [1000]

T0: 0000 024F [010F]

Jump to BL


NOTICE:  BL2: v2.6(release):e233a3d581-dirty
NOTICE:  BL2: Built : 06:23:27, Jul 30 2023
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings

dump toprgu registers data: 
1001c000 | 00000000 0000ffe0 00000000 00000000
1001c010 | 00000fff 00000000 00f00000 00000000
1001c020 | 00000000 00000000 00000000 00000000
1001c030 | 003c0003 003c0003 00000000 00000000
1001c040 | 00000000 00000000 00000000 00000000
1001c050 | 00000000 00000000 00000000 00000000
1001c060 | 00000000 00000000 00000000 00000000
1001c070 | 00000000 00000000 00000000 00000000
1001c080 | 00000000 00000000 00000000 00000000

dump drm registers data: 
1001d000 | 00000000 00000000 00000000 00000000
1001d010 | 00000000 00000000 00000000 00000000
1001d020 | 00000000 00000000 00000000 00000000
1001d030 | 00a003f1 000000ff 00100000 00000000
1001d040 | 00027e71 000200a0 00020303 000000ff
1001d050 | 00000000 00000000 00000000 00000000
1001d060 | 00000002 00000000 00000000 00000000
drm: 500 = 0xc 
[DDR Reserve] ddr reserve mode not be enabled yet

DDR RESERVE Success 0
[EMI] ComboMCP not ready, using default setting
BYTE_swap:0 
BYTE_swap:0 
Window Sum 608, worse bit 0, min window 76
Window Sum 592, worse bit 9, min window 72
Window Sum 440, worse bit 6, min window 52
Window Sum 388, worse bit 9, min window 46
Window Sum 452, worse bit 0, min window 54
Window Sum 396, worse bit 15, min window 46
Window Sum 454, worse bit 0, min window 56
Window Sum 402, worse bit 8, min window 48
Window Sum 464, worse bit 0, min window 56
Window Sum 404, worse bit 14, min window 48
Window Sum 424, worse bit 11, min window 50
Window Sum 430, worse bit 15, min window 50
Window Sum 434, worse bit 9, min window 52
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xc8
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963

NOTICE:  NMBM has been successfully attached in read-only mode

NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):e233a3d581-dirty
NOTICE:  BL31: Built : 06:23:27, Jul 30 2023
NOTICE:  Hello BL31!!!
In:    serial@11002000
Out:   serial@11002000
Err:   serial@11002000
Net:   eth0: ethernet@15100000

and it's looping.

here is your options, list. I donot know howto use it.

In your logs,
BL2 --- ok
BL31 --- ok
seems then BL3 cannot boot openwrt.

You have to check what BL31 you flashed before, and then TFTP flash a "right version" openwrt fw.

AX3000T has two firmware partitions: what you flashed before.

hi dude
how to recover
im stock on boot
System Halt!

What doesn't it mean "what BL31 you flashed before" ?
where can i fond that information ?

At first i used snapshot version few month ago, and official released at the beginning of the week

I try to follow tutorial

Debricking
→ generic.debrick

Assume that you have installed OpenWrt with stock layout, with original u-boot:

Connect to router via UART
Select Load Image in the u-boot
Set start address to 0x48000000, then set TFTP parameters to load the initramfs-kernel.bin.
Start the loaded kernel, then perform sysupgrade on OpenWrt.
If you have installed OpenWrt with u-boot mode layout, you can still use above UART recovery procedure, but u-boot will also look for a file called openwrt-mediatek-filogic-xiaomi_mi-router-ax3000t-ubootmod-initramfs-recovery.itb in a tftp server at IP address 192.168.1.254

If you provide that file in a tftp server, it'll be automatically loaded and run, so system can be recovered without using a UART connection.

But i have always issue : "TIMEOUT waiting for Ack block #0"

How to Set start address to 0x48000000??

You did not touch the BL31, that means you are in factory partitions. We can see this in the logs.

do you try to select:

and

to check if you could boot the router, monitoring the logs.

or you have to fix the TFTP:

running a Ram image: (https://downloads.openwrt.org/releases/23.05.4/targets/mediatek/filogic/openwrt-23.05.4-mediatek-filogic-xiaomi_mi-router-ax3000t-initramfs-kernel.bin)

then do sysupgrade in luci. Using: (https://downloads.openwrt.org/releases/23.05.4/targets/mediatek/filogic/openwrt-23.05.4-mediatek-filogic-xiaomi_mi-router-ax3000t-squashfs-sysupgrade.bin)

im stock
F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 3903 0041
F3: 1001 0000 [0200]
F3: 1001 0000
F6: 102C 0000
F5: 480A 0031
00: 1005 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 3903 0041
F3: 1001 0000 [0200]
F3: 1001 0000
F6: 102C 0000
01: 102A 0001
02: 1005 0000
BP: 2000 00C0 [0001]
EC: 0000 0000 [1000]
T0: 0000 00ED [010F]
System halt!
and need to write uboot to 0x48 but idont know HOW

You seems deeply dead in the boot, all bootloader is missing.

You have to use an SPI tools to recover the whole flash chip.

Yes i tried both, without any change.

When i try to upload through TFTP :

  • I fix IP adresse of Ethernet Card : 192.168.10.99 for example
  • Router initiate its IP at 192.168.10.1 (automatically set in parameters)
  • Mask : 255.255.255.0
  • File name

It launch command into TFTP64, but i have always error "TIMEOUT waiting for Ack block #0"'

Why ?