OpenWrt support for Xiaomi AX3000T

Trying to recover fully bricked (aka system halt) router after mostly wiping internal memory. Managed to boot once via mtk_uartboot + TFTP and flashed some openwrt images. Bootloader still bricked, but now I can't even boot via mtk_uartboot, it doesn't asks for TFTP and boots straight into broken system, then hangs:

<6>[    1.716915] FIT: Detected U-Boot 2024.07-OpenWrt-r27494-2e626ae2d2
<6>[    1.723360] FIT: Selected configuration: "config-1" (OpenWrt xiaomi_mi-router-ax3000t-ubootmod)
<6>[    1.732356] FIT:           kernel sub-image 0x00001000..0x005a33dd "kernel-1" (ARM64 OpenWrt Linux-6.6.52) 
<6>[    1.742371] FIT:          flat_dt sub-image 0x005a4000..0x005a9b10 "fdt-1" (ARM64 OpenWrt xiaomi_mi-router-ax3000t-ubootmod device tree blob) 
<6>[    1.827235] mt7530-mdio mdio-bus:1f: configuring for fixed/2500base-x link mode
<6>[    1.836485] mt7530-mdio mdio-bus:1f: Link is Up - 2.5Gbps/Full - flow control rx/tx
<6>[    1.847233] mt7530-mdio mdio-bus:1f wan (uninitialized): PHY [mt7530-0:00] driver [MediaTek MT7531 PHY] (irq=80)
<6>[    1.869666] mt7530-mdio mdio-bus:1f lan2 (uninitialized): PHY [mt7530-0:01] driver [MediaTek MT7531 PHY] (irq=81)
<6>[    1.891961] mt7530-mdio mdio-bus:1f lan3 (uninitialized): PHY [mt7530-0:02] driver [MediaTek MT7531 PHY] (irq=82)
<6>[    1.914208] mt7530-mdio mdio-bus:1f lan4 (uninitialized): PHY [mt7530-0:03] driver [MediaTek MT7531 PHY] (irq=83)
<6>[    1.926037] mtk_soc_eth 15100000.ethernet eth0: entered promiscuous mode
<6>[    1.933041] DSA: tree 0 setup
<6>[    1.936705] clk: Disabling unused clocks
<6>[    1.941354] Waiting for root device /dev/fit0...

Now there is no way to recover it?

UPD: Flashing with reset button falls into TFTP, so fixed for me

After some more experiments (I've flashed my backup files) it bootloops, mtk_uartboot doesn't boot at all (does nothing, just goes into bootloop). Logs:

F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 2400 0041 [0000]
G0: 1190 0000
EC: 0000 0000 [1000]
T0: 0000 024B [010F]
Jump to BL

NOTICE:  BL2: v2.6(release):9548a30134d-dirty
NOTICE:  BL2: Built : 02:27:18, Jan 24 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings

dump toprgu registers data: 
1001c000 | 00000000 0000ffe0 00000000 00000000
1001c010 | 00000fff 00000000 00f00000 00000000
1001c020 | 00000000 00000000 00000000 00000000
1001c030 | 003c0003 003c0003 00000000 00000000
1001c040 | 00000000 00000000 00000000 00000000
1001c050 | 00000000 00000000 00000000 00000000
1001c060 | 00000000 00000000 00000000 00000000
1001c070 | 00000000 00000000 00000000 00000000
1001c080 | 00000000 00000000 00000000 00000000

dump drm registers data: 
1001d000 | 00000000 00000000 00000000 00000000
1001d010 | 00000000 00000000 00000000 00000000
1001d020 | 00000000 00000000 00000000 00000000
1001d030 | 00a003f1 000000ff 00100000 00000000
1001d040 | 00027e71 000200a0 00020303 000000ff
1001d050 | 00000000 00000000 00000000 00000000
1001d060 | 00000002 00000000 00000000 00000000
drm: 500 = 0xc 
[DDR Reserve] ddr reserve mode not be enabled yet
DDR RESERVE Success 0
[EMI] ComboMCP not ready, using default setting
BYTE_swap:0 
BYTE_swap:0 
Window Sum 596, worse bit 2, min window 72
Window Sum 580, worse bit 8, min window 72
Window Sum 528, worse bit 3, min window 64
Window Sum 518, worse bit 11, min window 60
Window Sum 522, worse bit 11, min window 60
Window Sum 534, worse bit 1, min window 66
Window Sum 536, worse bit 8, min window 66
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):9548a30134d-dirty
NOTICE:  BL31: Built : 02:27:18, Jan 24 2024
NOTICE:  Hello BL31!!!

Probably time to buy normal router, flashing this via desoldering chip will cost more than price of this brick

Before declaring defeat, try to go through steps from the UART flash method.

ran automatic script, all 50 + 10 manual tries went into bootloop

I have the latest immortalwrt flashed on my rd03 but have lost Ethernet port access, I have it connected as a client to an existing wireless network therefore it has internet access. How do I install this version with the correct driver for AN8855?

Same problem here.
I've tried a lot of different recent firmware without recovering my ethernet ports.
Also I think that UART recovery method is also impacted: as the ram temporary firmware probably doesn't support ethernet -> no TFTP possible.

I have 2 AX3000T in 1.0.84, on both I'm not able to get ethernet port working after flashing (even with firmwares which should support AN8855).

I have seriously bricked one, so I made a full SPI backup of the other one and restored on the bricked one... Better but it doesn't work:

UART `Hello BL31!!!` boot loop
NOTICE:  BL2: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL2: Built : 01:44:14, May 29 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL31: Built : 01:44:14, May 29 2024
NOTICE:  Hello BL31!!!

F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 2400 0041 [0000]
G0: 1190 0000
EC: 0000 0000 [1000]
T0: 0000 024B [010F]
Jump to BL

NOTICE:  BL2: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL2: Built : 01:44:14, May 29 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL31: Built : 01:44:14, May 29 2024
NOTICE:  Hello BL31!!!

F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 2400 0041 [0000]
G0: 1190 0000
EC: 0000 0000 [1000]
T0: 0000 024B [010F]
Jump to BL

NOTICE:  BL2: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL2: Built : 01:44:14, May 29 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL31: Built : 01:44:14, May 29 2024
NOTICE:  Hello BL31!!!

F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 2400 0041 [0000]
G0: 1190 0000
EC: 0000 0000 [1000]
T0: 0000 024B [010F]
Jump to BL

NOTICE:  BL2: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL2: Built : 01:44:14, May 29 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL31: Built : 01:44:14, May 29 2024
NOTICE:  Hello BL31!!!

Even UART unbrick with mtk_uartboot is crashing too
May be that some parts firmware (like mac, etc...) are checked at boot , which would explain these crashes ?

Some information about my flash recovery:


ch341a programmer (directly on the motherboard at my own risk)


(I choose W25N01GV 3.3v)

If someone is interested by the SPI dump 1.0.84 / AN8855 (the one which is still working), here my file.

3 Likes

Try restoring this uboot instead. Worked for me. Then you can try flashing OpenWRT with it if you want.

Couldn't test it sorry I don't have router with new eth chip. I guess it's because old mtk switch app that doesn't know AN8855. I've updated this app but still can't test. Anyway WiFi should work by default and at least one lan port.
Confirmed by some guy that switch works but some issues with different switch app's commands.

Anyone investigating for USB3_hardware_mod? nothing mentioned in wiki.

How about getting NFC support on owrt?

Has AN8855 support been added in 23.05.5?

No.
Also not support Winbond W25N01KV chip! (official images)

I'm wondering if anyone has even started any development to support the AN8855 at all. :slightly_smiling_face:

It seems like this needs to be integrated into OpenWrt by developers... Motivated developer with RD03 1.0.84 is required.

1 Like

eto pryamo kakoy to pisets(((

1 Like

search in this topic, many:

Hello,
My ax3000t rd03 ex 1.0.47 is bricked.
I explain my problem and tests on other post: AX3000T bicked but no comm on UART

But I don't understand why I don't have any input/output on the UART. My USB TTL cable work well on an other ax3000t.
What is bricked: bootloader, hardware?

Thanks

If the LED is blinking and you have not flashed a custom bootloader, then there is a chance to restore the router according to the recovery instructions using the Xiaomi utility - MIWIFIRepairTool.x86 for Windows.

Hello guys.

I have two RD03 which came with firmware 1.0.47. I've updated both using the downgrade method and because I'm quite a noobie and I read that U-boot could be easier to recover, I changed to OpenWRT U-boot.

I'm currently using the snapshot version r26490-8619d7af67 but I want to go to the stable version.

Could someone guide me through the safest process to do this? As I understand the stable version is not compatible with U-boot and after all, this is not required for the fully functional system, right?

Any tips and help are very appreciated.

thanks.

My Device is stuck in a boot loop, any advice here? It seems to all happen so quickly without being able to do any input



F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 2400 0041 [0000]
G0: 1190 0000
EC: 0000 0000 [1000]
T0: 0000 024B [010F]
Jump to BL

NOTICE:  BL2: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL2: Built : 01:44:14, May 29 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL31: Built : 01:44:14, May 29 2024
NOTICE:  Hello BL31!!!
In:    serial@11002000
Out:   serial@11002000
Err:   serial@11002000
Net:   [miwifi] find switch an8855
eth0: ethernet@15100000

  *** U-Boot Boot Menu ***

     1. Startup system (Default)
     2. Startup firmware0
     3. Startup firmware1
     4. Upgrade firmware
     5. Upgrade ATF BL2
     6. Upgrade ATF FIP
     7. Upgrade single image
     8. Load image
     0. U-Boot console


  Press UP/DOWN to move, ENTER to select, ESC/CTRL+C to quit
detect button reset released!
Reading from 0x0 to 0x4f7fdd7c, size 0x4 ... OK
Boot failure detected on both systems
Reading from 0x0 to 0x4f7fdd7c, size 0x4 ... OK
Saving Environment to MTD... Erasing on MTD device 'nmbm0'... OK
Writing to MTD device 'nmbm0'... OK
OK
Booting System 0, sys1_failed = 2512, sys2_failed = 8
ubi0: attaching mtd9
ubi0: scanning is finished
ubi0: attached mtd9 (name "ubi", size 34 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 272, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 1, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 2/1, WL threshold: 4096, image sequence number: 1340148454
ubi0: available PEBs: 220, total reserved PEBs: 52, PEBs reserved for bad PEB handling: 19
Reading from volume 'kernel' to 0x46000000, size 0x0 ... OK
## Loading kernel from FIT Image at 46000000 ...
   Using 'config-1' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-5.4.255
     Type:         Kernel Image
     Compression:  lzma compressed
     Data Start:   0x46000130
     Data Size:    3617620 Bytes = 3.5 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x48080000
     Entry Point:  0x48080000
     Hash algo:    crc32
     Hash value:   eedc1dbb
     Hash algo:    sha1
     Hash value:   eecb3e1ff519e7ecc402b8479eddc97118f3041f
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 46000000 ...
   Using 'config-1' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt xiaomi_mi-router-ax3000t device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x463735cc
     Data Size:    17546 Bytes = 17.1 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   dcb28c13
     Hash algo:    sha1
     Hash value:   dba35ea891768d4b3ab7a9c805f2342228affec8
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x463735cc
   Uncompressing Kernel Image
   Loading Device Tree to 000000004f7f1000, end 000000004f7f8489 ... OK

Starting kernel ...

[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 5.4.255 (runner@fv-az1756-209) (gcc version 8.4.0 (OpenWrt GCC 8.4.0 r20594-c0c3289b3f)) #0 SMP Wed Sep 18 17:47:10 2024
[    0.000000] Machine model: Xiaomi Mi Router AX3000T
[    0.000000] On node 0 totalpages: 64592
[    0.000000]   DMA32 zone: 1024 pages used for memmap
[    0.000000]   DMA32 zone: 0 pages reserved
[    0.000000]   DMA32 zone: 64592 pages, LIFO batch:15
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.1 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 20 pages/cpu s44056 r8192 d29672 u81920
[    0.000000] pcpu-alloc: s44056 r8192 d29672 u81920 alloc=20*4096
[    0.000000] pcpu-alloc: [0] 0 [0] 1
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] CPU features: detected: GIC system register CPU interface
[    0.000000] CPU features: kernel page table isolation disabled by kernel configuration
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 63568
[    0.000000] Kernel command line: console=ttyS0,115200n1 loglevel=8 swiotlb=512 rootfstype=squashfs firmware=0 mtd=ubi uart_en=1
[    0.000000] Dentry cache hash table entries: 32768 (order: 6, 262144 bytes, linear)
[    0.000000] Inode-cache hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] Memory: 229864K/258368K available (7486K kernel code, 540K rwdata, 2056K rodata, 448K init, 290K bss, 28504K reserved, 0K cma-reserved)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000] rcu:     CONFIG_RCU_FANOUT set to non-default value of 32.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 25 jiffies.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] GICv3: GIC: Using split EOI/Deactivate mode
[    0.000000] GICv3: 640 SPIs implemented
[    0.000000] GICv3: 0 Extended SPIs implemented
[    0.000000] GICv3: Distributor has no Range Selector support
[    0.000000] GICv3: 16 PPIs implemented
[    0.000000] GICv3: no VLPI support, no direct LPI support
[    0.000000] GICv3: CPU0: found redistributor 0 region 0:0x000000000c080000
[    0.000000] arch_timer: cp15 timer(s) running at 13.00MHz (phys).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x2ff89eacb, max_idle_ns: 440795202429 ns
[    0.000003] sched_clock: 56 bits at 13MHz, resolution 76ns, wraps every 4398046511101ns
[    0.000145] Calibrating delay loop (skipped), value calculated using timer frequency.. 26.00 BogoMIPS (lpj=52000)
[    0.000152] pid_max: default: 32768 minimum: 301
[    0.000239] Mount-cache hash table entries: 512 (order: 0, 4096 bytes, linear)
[    0.000245] Mountpoint-cache hash table entries: 512 (order: 0, 4096 bytes, linear)
[    0.001250] ASID allocator initialised with 65536 entries
[    0.001314] rcu: Hierarchical SRCU implementation.
[    0.001631] smp: Bringing up secondary CPUs ...
[    0.001961] Detected VIPT I-cache on CPU1
[    0.001983] GICv3: CPU1: found redistributor 1 region 0:0x000000000c0a0000
[    0.002009] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.002077] smp: Brought up 1 node, 2 CPUs
[    0.002086] SMP: Total of 2 processors activated.
[    0.002091] CPU features: detected: 32-bit EL0 Support
[    0.002095] CPU features: detected: CRC32 instructions
[    0.002204] CPU: All CPU(s) started at EL2
[    0.002215] alternatives: patching kernel code
[    0.004696] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 7645041785100000 ns
[    0.004711] futex hash table entries: 512 (order: 3, 32768 bytes, linear)
[    0.004793] pinctrl core: initialized pinctrl subsystem
[    0.005376] NET: Registered protocol family 16
[    0.005963] DMA: preallocated 256 KiB pool for atomic allocations
[    0.006988] pstore: Registered ramoops as persistent store backend
[    0.006999] ramoops: using 0x10000@0x42ff0000, ecc: 0
[    0.021894] cryptd: max_cpu_qlen set to 1000
[    0.023934] SCSI subsystem initialized
[    0.024207] libata version 3.00 loaded.
[    0.024395] usbcore: registered new interface driver usbfs
[    0.024427] usbcore: registered new interface driver hub
[    0.024460] usbcore: registered new device driver usb
[    0.025352] Bluetooth: Core ver 2.22
[    0.025402] NET: Registered protocol family 31
[    0.025407] Bluetooth: HCI device and connection manager initialized
[    0.025420] Bluetooth: HCI socket layer initialized
[    0.025426] Bluetooth: L2CAP socket layer initialized
[    0.025436] Bluetooth: SCO socket layer initialized
[    0.025711] rbus 18000000.wbsys: PCI host bridge to bus 0000:00
[    0.025727] pci_bus 0000:00: root bus resource [mem 0x18000000-0x18ffffff]
[    0.025734] pci_bus 0000:00: root bus resource [bus 00-ff]
[    0.025740] pci_bus 0000:00: scanning bus
[    0.025759] pci 0000:00:00.0: [14c3:7981] type 00 class 0x000280
[    0.025775] pci 0000:00:00.0: reg 0x10: [mem 0x18000000-0x1800000f 64bit]
[    0.025782] pci 0000:00:00.0: reg 0x18: [mem 0x00000000-0x0000000f]
[    0.025788] pci 0000:00:00.0: reg 0x1c: [mem 0x00000000-0x0000000f]
[    0.025794] pci 0000:00:00.0: reg 0x20: [mem 0x00000000-0x0000000f]
[    0.025801] pci 0000:00:00.0: reg 0x24: [mem 0x00000000-0x0000000f]
[    0.026689] pci_bus 0000:00: fixups for bus
[    0.026698] pci_bus 0000:00: bus scan returning with max=00
[    0.027163] clocksource: Switched to clocksource arch_sys_counter
[    0.027770] thermal_sys: Registered thermal governor 'fair_share'
[    0.027777] thermal_sys: Registered thermal governor 'bang_bang'
[    0.027786] thermal_sys: Registered thermal governor 'step_wise'
[    0.027790] thermal_sys: Registered thermal governor 'user_space'
[    0.027794] thermal_sys: Registered thermal governor 'power_allocator'
[    0.028041] NET: Registered protocol family 2
[    0.028156] IP idents hash table entries: 4096 (order: 3, 32768 bytes, linear)
[    0.028602] tcp_listen_portaddr_hash hash table entries: 256 (order: 0, 4096 bytes, linear)
[    0.028623] TCP established hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.028644] TCP bind hash table entries: 2048 (order: 3, 32768 bytes, linear)
[    0.028675] TCP: Hash tables configured (established 2048 bind 2048)
[    0.028750] UDP hash table entries: 256 (order: 1, 8192 bytes, linear)
[    0.028766] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes, linear)
[    0.028884] NET: Registered protocol family 1
[    0.028917] PCI: CLS 0 bytes, default 64
[    0.029993] workingset: timestamp_bits=46 max_order=16 bucket_order=0
[    0.033038] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.033048] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.045514] NET: Registered protocol family 38
[    0.046083] phy phy-usb-phy@11e10000.1: type_sw - reg 0x218, index 0
[    0.056816] Serial: 8250/16550 driver, 3 ports, IRQ sharing disabled
[    0.057581] printk: console [ttyS0] disabled
[    0.077728] 11002000.serial: ttyS0 at MMIO 0x11002000 (irq = 12, base_baud = 2500000) is a ST16650V2
[    0.732537] printk: console [ttyS0] enabled
[    0.737462] mtk_rng trng@1020f000: registered RNG driver
[    0.737486] random: crng init done
[    0.742955] cacheinfo: Unable to detect cache hierarchy for CPU 0
[    0.754665] loop: module loaded
[    0.758774] mt7981-pinctrl 11d00000.pinctrl: pin_config_set op failed for pin 19
[    0.766177] mtk-spi 1100a000.spi: Error applying setting, reverse things back
[    0.774021] spi-nand spi0.0: Winbond SPI NAND was found.
[    0.779359] spi-nand spi0.0: 128 MiB, block size: 128 KiB, page size: 2048, OOB size: 64
[    0.789488] [mtk_hw_init] reset_lock:0, force:0
[    0.794078] [mtk_hw_init] execute fe cold reset
[    0.809910] mtk_soc_eth 15100000.ethernet: generated random MAC address 0e:4b:ee:ca:f0:e2
[    0.818397] mtk_soc_eth 15100000.ethernet eth0: mediatek frame engine at 0xffffffc011a80000, irq 76
[    0.827481] mtk_soc_eth 15100000.ethernet: generated random MAC address 6e:f0:3d:ae:21:7f
[    0.835963] mtk_soc_eth 15100000.ethernet eth1: mediatek frame engine at 0xffffffc011a80000, irq 76
[    0.845012] (unnamed net_device) (dummy): netif_napi_add() called with weight 256
[    0.852932] usbcore: registered new interface driver uas
[    0.858319] usbcore: registered new interface driver usb-storage
[    0.864436] i2c /dev entries driver
[    0.869439] mtk-wdt 1001c000.watchdog: Watchdog enabled (timeout=31 sec, nowayout=0)
[    0.877460] device-mapper: ioctl: 4.41.0-ioctl (2019-09-16) initialised: dm-devel@redhat.com
[    0.886027] Bluetooth: HCI UART driver ver 2.3
[    0.890560] Bluetooth: HCI UART protocol H4 registered
[    0.895692] Bluetooth: HCI UART protocol BCSP registered
[    0.901092] Bluetooth: HCI UART protocol Broadcom registered
[    0.906772] Bluetooth: HCI UART protocol QCA registered
[    0.912574] crypto-safexcel 10320000.crypto: EIP97:230(0,1,4,4)-HIA:270(0,5,5),PE:150/433(alg:7fcdfc00)/0/0/0
[    0.927865] Initializing XFRM netlink socket
[    0.932536] NET: Registered protocol family 10
[    0.937756] Segment Routing with IPv6
[    0.941545] NET: Registered protocol family 17
[    0.946035] Bridge firewalling registered
[    0.950142] 8021q: 802.1Q VLAN Support v1.8
[    0.955074] pstore: Using crash dump compression: deflate
[    0.969429] nmbm nmbm_spim_nand: Signature found at block 1023 [0x07fe0000]
[    0.977057] nmbm nmbm_spim_nand: First info table with writecount 0 found in block 960
[    0.986862] nmbm nmbm_spim_nand: Second info table with writecount 0 found in block 963
[    0.994863] nmbm nmbm_spim_nand: NMBM has been successfully attached
[    1.001495] 9 fixed-partitions partitions found on MTD device nmbm_spim_nand
[    1.008542] Creating 9 MTD partitions on "nmbm_spim_nand":
[    1.014021] 0x000000000000-0x000000100000 : "BL2"
[    1.019326] 0x000000100000-0x000000140000 : "Nvram"
[    1.024731] 0x000000140000-0x000000180000 : "Bdata"
[    1.030128] 0x000000180000-0x000000380000 : "Factory"
[    1.035704] 0x000000380000-0x000000580000 : "FIP"
[    1.040936] 0x000000580000-0x0000005c0000 : "crash"
[    1.046323] 0x0000005c0000-0x000000600000 : "crash_log"
[    1.052063] 0x000000600000-0x000007600000 : "ubi"
[    1.057490] 0x000007600000-0x000007640000 : "KF"
[    1.635426] mt753x gsw@0: No mt753x switch found
[    1.640075] mt753x: probe of gsw@0 failed with error -22
[    1.645827] UBI: auto-attach mtd8
[    1.649159] ubi0: attaching mtd8
[    1.740867] ubi0 error: ubi_attach: bad image sequence number 1472932408 in PEB 272, expected 1340148454
[    1.750343] Erase counter header dump:
[    1.754085]  magic          0x55424923
[    1.757826]  version        1
[    1.760786]  ec             2
[    1.763746]  vid_hdr_offset 2048
[    1.766960]  data_offset    4096
[    1.770180]  image_seq      1472932408
[    1.773921]  hdr_crc        0x5908d434
[    1.777661] erase counter header hexdump:
[    1.781667] 00000000: 55 42 49 23 01 00 00 00 00 00 00 00 00 00 00 02 00 00 08 00 00 00 10 00 57 cb 2a 38 00 00 00 00  UBI#....................W.*8....
[    1.795215] 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 59 08 d4 34  ............................Y..4
[    1.808793] ubi0 error: ubi_attach_mtd_dev: failed to attach mtd8, error -22
[    1.815862] UBI error: cannot attach mtd8
[    1.819879] hctosys: unable to open rtc device (rtc0)
[    1.825554] /dev/root: Can't open blockdev
[    1.829685] VFS: Cannot open root device "(null)" or unknown-block(0,0): error -6
[    1.837158] Please append a correct "root=" boot option; here are the available partitions:
[    1.845522] 1f00          131072 mtdblock0
[[    1.845523]  (driver?)
[    1.852151] 1f01            1024 mtdblock1
[    1.852152]  (driver?)
[    1.858686] 1f02             256 mtdblock2
[    1.858687]  (driver?)
[    1.865229] 1f03             256 mtdblock3
[    1.865230]  (driver?)
[    1.871771] 1f04            2048 mtdblock4
[    1.871772]  (driver?)
[    1.878305] 1f05            2048 mtdblock5
[    1.878306]  (driver?)
[    1.884847] 1f06             256 mtdblock6
[    1.884848]  (driver?)
[    1.891387] 1f07             256 mtdblock7
[    1.891388]  (driver?)
[    1.897922] 1f08          114688 mtdblock8
[    1.897923]  (driver?)
[    1.904465] 1f09             256 mtdblock9
[    1.904466]  (driver?)
[    1.911000] Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)
    1.825554] /dev/root: Can't

[    1.829685] VFS: Cannot open

[    1.837158] Please append a

[    1.845522] 1f00          13

[[  [    1.931392] SMP: stopping secondary CPUs
  1.845523]  (dr[    1.935658] Kernel Offset: disabled
[    1.940511] CPU features: 0x00002,20002008
[    1.944592] Memory Limit: none
[    1.950364] Rebooting in 1 seconds..

F0: 102B 0000
FA: 1040 0000
FA: 1040 0000 [0200]
F9: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 2400 0041 [0000]
G0: 1190 0000
EC: 0000 0000 [1000]
T0: 0000 024B [010F]
Jump to BL

NOTICE:  BL2: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL2: Built : 01:44:14, May 29 2024
NOTICE:  WDT: disabled
NOTICE:  EMI: Using DDR3 settings
NOTICE:  EMI: Detected DRAM size: 256MB
NOTICE:  EMI: complex R/W mem test passed
NOTICE:  CPU: MT7981 (1300MHz)
NOTICE:  SPI_NAND parses attributes from parameter page.
NOTICE:  SPI_NAND Detected ID 0xef
NOTICE:  Page size 2048, Block size 131072, size 134217728
NOTICE:  Initializing NMBM ...
NOTICE:  Signature found at block 1023 [0x07fe0000]
NOTICE:  First info table with writecount 0 found in block 960
NOTICE:  Second info table with writecount 0 found in block 963
NOTICE:  NMBM has been successfully attached in read-only mode
NOTICE:  BL2: Booting BL31
NOTICE:  BL31: v2.6(release):b18eebc1b35-dirty
NOTICE:  BL31: Built : 01:44:14, May 29 2024
NOTICE:  Hello BL31!!!
In:    serial@11002000
Out:   serial@11002000
Err:   serial@11002000
Net:   [miwifi] find switch an8855
eth0: ethernet@15100000

  *** U-Boot Boot Menu ***

     1. Startup system (Default)
     2. Startup firmware0
     3. Startup firmware1
     4. Upgrade firmware
     5. Upgrade ATF BL2
     6. Upgrade ATF FIP
     7. Upgrade single image
     8. Load image
     0. U-Boot console


  Press UP/DOWN to move, ENTER to select, ESC/CTRL+C to quit
detect button reset released!