OpenWrt support for ZBT-Z800AX - IPQ8072A - WiFi6 - 5G Modem (RM520N-GL)

did u means u successfully flash the new openwrt or the backup to back to oem firmware? because i try to flash the new openwrt ubi file. the error is same as yours i think.

PCI1 is not defined in the device tree
In: serial@78B3000
Out: serial@78B3000
Err: serial@78B3000
machid: 8010008
MMC Device 0 not found
eth5 MAC Address from ART is not valid
Hit any key to stop autoboot: 0
ubi0: attaching mtd2
UBI init error 22

Net: MAC0 addr:f8:5e:3c:4d:17:58
PHY ID1: 0x4d
PHY ID2: 0xd0b1
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
eth0

Net: MAC0 addr:f8:5e:3c:4d:17:58
EDMA ver 1 hw init
Num rings - TxDesc:1 (0-0) TxCmpl:1 (7-7)
RxDesc:1 (15-15) RxFill:1 (7-7)
ipq807x_edma_alloc_rings: successfull
ipq807x_edma_setup_ring_resources: successfull
ipq807x_edma_configure_rings: successfull
ipq807x_edma_hw_init: successfull
, eth0
Warning: eth0 MAC addresses don't match:
Address in SROM is f8:5e:3c:4d:17:58
Address in environment is f8:5e:3c:4d:17:59

If you have the oem image, then you can use the uboot command I posted earlier to burn image into the mtd nand flash, and the router should come up.
If you want to burn openwrt built image, then you will have to change uboot env variables as described in https://openwrt.org/toh/dynalink/dl-wrx36. But those instructions are for dl-wrx36, not specifically for z800ax. For one thing, the dl-wrx36 only has nand flash, yet the z800ax has both nor flash and nand flash. So the rootfs offset is different.

can u share the uboot command. i already try still not booting

Hello there!

I found that It's now support officially.
https://openwrt.org/toh/hwdata/zbt/zbt_zbt-z800ax

Can someone please confirm, if it's successfully installed and working fine or not?

Yes it’s working.
But don’t forget its a snapshot…

I have been building openwrt 6.1.71 for z800ax router w/o problem. Recently I start to build openwrt 6.6.69 with the official z800ax support. The itb image can be tftpboot and bootm ok. But when I tried to burn ubi image into the nand partition rootfs_1. The ubi image can be booted up. However, after the boot finished, the whole root directory is empty. That is not good. Has anyone tried openwrt with kernel 6.6.59 for oz800ax?

From the boot log, I found the following error message:
[ 0.928246] nand: device found, Manufacturer ID: 0xc2, Chip ID: 0xaa
[ 0.928763] nand: Macronix MX30UF2G28AD
[ 0.935419] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[ 0.938960] qcom-nandc 79b0000.nand-controller: Opcode not supported: 238
[ 0.946586] Block protection check failed
[ 0.953924] 4 fixed-partitions partitions found on MTD device qcom_nand.0
[ 0.957523] Creating 4 MTD partitions on "qcom_nand.0":
[ 0.964266] 0x000000000000-0x000007800000 : "rootfs"
[ 1.061760] mtd: setting mtd0 (rootfs) as root device
[ 1.062060] mtdsplit: no squashfs found in "rootfs"
[ 1.065828] 0x000007800000-0x000008000000 : "0:wififw"
[ 1.077305] 0x000008000000-0x00000f800000 : "rootfs_1"
[ 1.171603] 0x00000f800000-0x000010000000 : "0:wififw_1"
[ 1.180994] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[ 1.181928] spi-nor spi0.0: mx25u6435f (8192 Kbytes)
[ 1.187473] 19 fixed-partitions partitions found on MTD device spi0.0


Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1-00163
S - IMAGE_VARIANT_STRING=HAABANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002e1
B -       203 - PBL, Start
B -      2738 - bootable_media_detect_entry, Start
B -      2886 - bootable_media_detect_success, Start
B -      2890 - elf_loader_entry, Start
B -     11482 - auth_hash_seg_entry, Start
B -     11722 - auth_hash_seg_exit, Start
B -    253279 - elf_segs_hash_verify_entry, Start
B -    313962 - PBL, End
B -    486902 - SBL1, Start
B -    564402 - GCC [RstStat:0x10, RstDbg:0x600000] WDog Stat : 0x4
B -    574101 - pm_device_init, Start
B -    754112 - PM_SET_VAL:Skip
D -    178150 - pm_device_init, Delta
B -    756552 - pm_driver_init, Start
D -      5368 - pm_driver_init, Delta
B -    762896 - clock_init, Start
D -      2135 - clock_init, Delta
B -    766831 - boot_flash_init, Start
D -      3782 - boot_flash_init, Delta
B -    774395 - boot_config_data_table_init, Start
D -      1006 - boot_config_data_table_init, Delta - (575 Bytes)
B -    784399 - Boot Setting :  0x00000618
B -    788120 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:8
B -    795043 - sbl1_ddr_set_params, Start
B -    798856 - CPR configuration: 0x30c
B -    802333 - cpr_init, Start
B -    805108 - Rail:0 Mode: 5 Voltage: 800000
B -    810324 - CL CPR settled at 752000mV
B -    813130 - Rail:1 Mode: 5 Voltage: 880000
B -    817308 - Rail:1 Mode: 7 Voltage: 920000
D -     16531 - cpr_init, Delta
B -    824201 - Pre_DDR_clock_init, Start
B -    828227 - Pre_DDR_clock_init, End
B -    831521 - DDR Type : PCDDR4
B -    838201 - do ddr sanity test, Start
D -      1037 - do ddr sanity test, Delta
B -    842013 - DDR: Start of HAL DDR Boot Training
B -    846741 - DDR: End of HAL DDR Boot Training
B -    852414 - DDR: Checksum to be stored on flash is -464732340
B -    862845 - Image Load, Start
D -    334280 - QSEE Image Loaded, Delta - (1371968 Bytes)
B -   1197216 - Image Load, Start
D -        61 - SEC Image Loaded, Delta - (0 Bytes)
B -   1204902 - Image Load, Start
D -      9760 - DEVCFG Image Loaded, Delta - (26088 Bytes)
B -   1214723 - Image Load, Start
D -     25986 - RPM Image Loaded, Delta - (86660 Bytes)
B -   1240801 - Image Load, Start
D -    133986 - APPSBL Image Loaded, Delta - (546630 Bytes)
B -   1374940 - QSEE Execution, Start
D -        91 - QSEE Execution, Delta
B -   1380735 - USB D+ check, Start
D -         0 - USB D+ check, Delta
B -   1387140 - SBL1, End
D -    902525 - SBL1, Delta
S - Flash Throughput, 4427 KB/s  (2032593 Bytes,  459112 us)
S - DDR Frequency, 600 MHz
S - Core 0 Frequency, 1651 MHz


U-Boot 2016.01 (Mar 23 2021 - 11:02:46 +0800)

DRAM:  smem ram ptable found: ver: 1 len: 4
1 GiB
NAND:  Could not find nand_gpio in dts, using defaults
ONFI device found
ID = 1190aac2
Vendor = c2
Device = aa
qpic_nand: changing oobsize to 80 from 128 bytes
SPI_ADDR_LEN=3
SF: Detected MX25U6435F with page size 256 Bytes, erase size 64 KiB, total 8 MiB
ipq_spi: page_size: 0x100, sector_size: 0x10000, size: 0x800000
264 MiB
MMC:   sdhci: Node Not found, skipping initialization

PCI1 is not defined in the device tree
In:    serial@78B3000
Out:   serial@78B3000
Err:   serial@78B3000
machid: 8010008
MMC Device 0 not found
eth5 MAC Address from ART is not valid
Hit any key to stop autoboot:  5  4  3  2  1  0 
ubi0: attaching mtd2
ubi0: scanning is finished
ubi0: attached mtd2 (name "mtd=1", size 120 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 960, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 29/15, WL threshold: 4096, image sequence number: 1202525907
ubi0: available PEBs: 0, total reserved PEBs: 960, PEBs reserved for bad PEB handling: 40
Read 0 bytes from volume kernel to 44000000
No size specified -> Using max size (5459968)
## Loading kernel from FIT Image at 44000000 ...
   Using 'config@rt5010w-d350-rev0' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-6.6.59
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x440000e8
     Data Size:    5331376 Bytes = 5.1 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x41000000
     Entry Point:  0x41000000
     Hash algo:    crc32
     Hash value:   16d3857c
     Hash algo:    sha1
     Hash value:   2fd1ce6a6155e0f69b2fc26fdc9a17cf67950fa6
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
   Using 'config@rt5010w-d350-rev0' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt zbtlink_zbt-z800ax device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x44515bdc
     Data Size:    46509 Bytes = 45.4 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   3c258a33
     Hash algo:    sha1
     Hash value:   6c871318b2d02404e029da7f1d5ae4c3ab1e4bc7
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x44515bdc
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4a3f1000, end 4a3ff5ac ... OK
fdt-fixup: unable to find compatible node
invalid mtd device 'spi0.0'
Could not find PCI in device tree
Using machid 0x8010008 from environment

Starting kernel ...

Jumping to AARCH64 kernel via monitor
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 6.6.59 (lu@lu-OptiPlex-9020M) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 13.3.0 r28012-31f1dabb4b) 13.3.0, GNU ld (GNU Binutils) 2.42) #0 SMP Mon Nov  4 22:40:38 2024
[    0.000000] Machine model: Zbtlink ZBT-Z800AX
[    0.000000] OF: reserved mem: 0x0000000040000000..0x0000000040ffffff (16384 KiB) nomap non-reusable nss@40000000
[    0.000000] OF: reserved mem: 0x000000004a400000..0x000000004a5fffff (2048 KiB) nomap non-reusable tzapp@4a400000
[    0.000000] OF: reserved mem: 0x000000004a600000..0x000000004a9fffff (4096 KiB) nomap non-reusable bootloader@4a600000
[    0.000000] OF: reserved mem: 0x000000004aa00000..0x000000004aafffff (1024 KiB) nomap non-reusable sbl@4aa00000
[    0.000000] OF: reserved mem: 0x000000004ab00000..0x000000004abfffff (1024 KiB) nomap non-reusable smem@4ab00000
[    0.000000] OF: reserved mem: 0x000000004ac00000..0x000000004affffff (4096 KiB) nomap non-reusable memory@4ac00000
[    0.000000] OF: reserved mem: 0x000000004b000000..0x0000000050efffff (97280 KiB) nomap non-reusable wcnss@4b000000
[    0.000000] OF: reserved mem: 0x0000000050f00000..0x0000000050ffffff (1024 KiB) nomap non-reusable q6_etr_dump@50f00000
[    0.000000] OF: reserved mem: 0x0000000051000000..0x00000000510fffff (1024 KiB) nomap non-reusable m3_dump@51000000
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000040ffffff]
[    0.000000]   node   0: [mem 0x0000000041000000-0x000000004a3fffff]
[    0.000000]   node   0: [mem 0x000000004a400000-0x00000000510fffff]
[    0.000000]   node   0: [mem 0x0000000051100000-0x000000007fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000007fffffff]
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv1.0 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: MIGRATE_INFO_TYPE not supported.
[    0.000000] psci: SMC Calling Convention v1.0
[    0.000000] percpu: Embedded 18 pages/cpu s35624 r8192 d29912 u73728
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] alternatives: applying boot alternatives
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 ubi.mtd=rootfs_1 rootfstype=squashfs rootwait root=/dev/ubiblock0_1
[    0.000000] Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes, linear)
[    0.000000] Inode-cache hash table entries: 65536 (order: 7, 524288 bytes, linear)
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 258048
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] software IO TLB: SWIOTLB bounce buffer size adjusted to 1MB
[    0.000000] software IO TLB: area num 4.
[    0.000000] software IO TLB: mapped [mem 0x000000007eb00000-0x000000007ec00000] (1MB)
[    0.000000] Memory: 885452K/1048576K available (8384K kernel code, 914K rwdata, 2524K rodata, 1536K init, 277K bss, 163124K reserved, 0K cma-reserved)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000] 	Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] Root IRQ handler: gic_handle_irq
[    0.000000] GICv2m: range[mem 0x0b00a000-0x0b00affc], SPI[448:479]
[    0.000000] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[    0.000000] arch_timer: cp15 and mmio timer(s) running at 19.20MHz (virt/virt).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x46d987e47, max_idle_ns: 440795202767 ns
[    0.000000] sched_clock: 56 bits at 19MHz, resolution 52ns, wraps every 4398046511078ns
[    0.000113] Calibrating delay loop (skipped), value calculated using timer frequency.. 38.40 BogoMIPS (lpj=192000)
[    0.000127] pid_max: default: 32768 minimum: 301
[    0.005225] Mount-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.005239] Mountpoint-cache hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.009569] RCU Tasks Trace: Setting shift to 2 and lim to 1 rcu_task_cb_adjust=1.
[    0.009803] rcu: Hierarchical SRCU implementation.
[    0.009807] rcu: 	Max phase no-delay instances is 1000.
[    0.010734] smp: Bringing up secondary CPUs ...
[    0.011417] Detected VIPT I-cache on CPU1
[    0.011519] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.012211] Detected VIPT I-cache on CPU2
[    0.012281] CPU2: Booted secondary processor 0x0000000002 [0x410fd034]
[    0.012956] Detected VIPT I-cache on CPU3
[    0.013021] CPU3: Booted secondary processor 0x0000000003 [0x410fd034]
[    0.013092] smp: Brought up 1 node, 4 CPUs
[    0.013100] SMP: Total of 4 processors activated.
[    0.013106] CPU features: detected: 32-bit EL0 Support
[    0.013111] CPU features: detected: CRC32 instructions
[    0.013179] CPU features: emulated: Privileged Access Never (PAN) using TTBR0_EL1 switching
[    0.013186] CPU: All CPU(s) started at EL1
[    0.013189] alternatives: applying system-wide alternatives
[    0.023685] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.023712] futex hash table entries: 1024 (order: 4, 65536 bytes, linear)
[    0.025460] pinctrl core: initialized pinctrl subsystem
[    0.027553] NET: Registered PF_NETLINK/PF_ROUTE protocol family
[    0.028115] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.028159] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.028194] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.028608] thermal_sys: Registered thermal governor 'step_wise'
[    0.028667] cpuidle: using governor menu
[    0.028861] ASID allocator initialised with 65536 entries
[    0.055207] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    0.057620] Modules: 29328 pages in range for non-PLT usage
[    0.057629] Modules: 520848 pages in range for PLT usage
[    0.062551] SCSI subsystem initialized
[    0.062749] usbcore: registered new interface driver usbfs
[    0.062784] usbcore: registered new interface driver hub
[    0.062847] usbcore: registered new device driver usb
[    0.063263] qcom_scm: convention: smc arm 64
[    0.064973] clocksource: Switched to clocksource arch_sys_counter
[    0.068725] NET: Registered PF_INET protocol family
[    0.068896] IP idents hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.071469] tcp_listen_portaddr_hash hash table entries: 512 (order: 1, 8192 bytes, linear)
[    0.071494] Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear)
[    0.071509] TCP established hash table entries: 8192 (order: 4, 65536 bytes, linear)
[    0.071636] TCP bind hash table entries: 8192 (order: 6, 262144 bytes, linear)
[    0.071916] TCP: Hash tables configured (established 8192 bind 8192)
[    0.072438] MPTCP token hash table entries: 1024 (order: 2, 24576 bytes, linear)
[    0.072621] UDP hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.072671] UDP-Lite hash table entries: 512 (order: 2, 16384 bytes, linear)
[    0.073106] NET: Registered PF_UNIX/PF_LOCAL protocol family
[    0.073145] PCI: CLS 0 bytes, default 64
[    0.074800] workingset: timestamp_bits=46 max_order=18 bucket_order=0
[    0.075467] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.075476] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.081845] qcom-qmp-usb-phy 58000.phy: supply vdda-phy not found, using dummy regulator
[    0.082019] qcom-qmp-usb-phy 58000.phy: supply vdda-pll not found, using dummy regulator
[    0.082926] qcom-qmp-usb-phy 78000.phy: supply vdda-phy not found, using dummy regulator
[    0.083058] qcom-qmp-usb-phy 78000.phy: supply vdda-pll not found, using dummy regulator
[    0.084199] qcom-qusb2-phy 59000.phy: supply vdd not found, using dummy regulator
[    0.084360] qcom-qusb2-phy 59000.phy: supply vdda-pll not found, using dummy regulator
[    0.084403] qcom-qusb2-phy 59000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.084580] qcom-qusb2-phy 59000.phy: Registered Qcom-QUSB2 phy
[    0.084812] qcom-qusb2-phy 79000.phy: supply vdd not found, using dummy regulator
[    0.084930] qcom-qusb2-phy 79000.phy: supply vdda-pll not found, using dummy regulator
[    0.085050] qcom-qusb2-phy 79000.phy: supply vdda-phy-dpdm not found, using dummy regulator
[    0.085228] qcom-qusb2-phy 79000.phy: Registered Qcom-QUSB2 phy
[    0.087102] gpio-export gpio-export: 1 gpio(s) exported
[    0.093957] Serial: 8250/16550 driver, 2 ports, IRQ sharing disabled
[    0.094988] msm_serial 78b3000.serial: msm_serial: detected port #0
[    0.095044] msm_serial 78b3000.serial: uartclk = 3686400
[    0.095392] 78b3000.serial: ttyMSM0 at MMIO 0x78b3000 (irq = 20, base_baud = 230400) is a MSM
[    0.095427] msm_serial: console setup on port #0
[    0.095470] printk: console [ttyMSM0] enabled
[    0.917393] msm_serial: driver initialized
[    0.926804] loop: module loaded
[    0.928246] nand: device found, Manufacturer ID: 0xc2, Chip ID: 0xaa
[    0.928763] nand: Macronix MX30UF2G28AD
[    0.935419] nand: 256 MiB, SLC, erase size: 128 KiB, page size: 2048, OOB size: 128
[    0.938960] qcom-nandc 79b0000.nand-controller: Opcode not supported: 238
[    0.946586] Block protection check failed
[    0.953924] 4 fixed-partitions partitions found on MTD device qcom_nand.0
[    0.957523] Creating 4 MTD partitions on "qcom_nand.0":
[    0.964266] 0x000000000000-0x000007800000 : "rootfs"
[    1.061760] mtd: setting mtd0 (rootfs) as root device
[    1.062060] mtdsplit: no squashfs found in "rootfs"
[    1.065828] 0x000007800000-0x000008000000 : "0:wififw"
[    1.077305] 0x000008000000-0x00000f800000 : "rootfs_1"
[    1.171603] 0x00000f800000-0x000010000000 : "0:wififw_1"
[    1.180994] spi_qup 78b5000.spi: IN:block:16, fifo:64, OUT:block:16, fifo:64
[    1.181928] spi-nor spi0.0: mx25u6435f (8192 Kbytes)
[    1.187473] 19 fixed-partitions partitions found on MTD device spi0.0
[    1.192077] Creating 19 MTD partitions on "spi0.0":
[    1.198426] 0x000000000000-0x000000050000 : "0:sbl1"
[    1.203721] 0x000000050000-0x000000060000 : "0:mibib"
[    1.208819] 0x000000060000-0x000000080000 : "0:bootconfig"
[    1.213691] 0x000000080000-0x0000000a0000 : "0:bootconfig1"
[    1.219122] 0x0000000a0000-0x000000220000 : "0:qsee"
[    1.224557] 0x000000220000-0x0000003a0000 : "0:qsee_1"
[    1.229802] 0x0000003a0000-0x0000003b0000 : "0:devcfg"
[    1.234746] 0x0000003b0000-0x0000003c0000 : "0:devcfg_1"
[    1.239909] 0x0000003c0000-0x0000003d0000 : "0:apdp"
[    1.245341] 0x0000003d0000-0x0000003e0000 : "0:apdp_1"
[    1.250285] 0x0000003e0000-0x000000420000 : "0:rpm"
[    1.255282] 0x000000420000-0x000000460000 : "0:rpm_1"
[    1.260003] 0x000000460000-0x000000470000 : "0:cdt"
[    1.265269] 0x000000470000-0x000000480000 : "0:cdt_1"
[    1.269870] 0x000000480000-0x000000490000 : "0:appsblenv"
[    1.275141] 0x000000490000-0x000000530000 : "0:appsbl"
[    1.280532] 0x000000530000-0x0000005d0000 : "0:appsbl_1"
[    1.285854] 0x0000005d0000-0x000000610000 : "0:art"
[    1.291023] 0x000000610000-0x000000690000 : "0:ethphyfw"
[    1.303109] spmi spmi-0: PMIC arbiter version v2 (0x20010000)
[    1.323258] i2c_dev: i2c /dev entries driver
[    1.330014] sdhci: Secure Digital Host Controller Interface driver
[    1.330057] sdhci: Copyright(c) Pierre Ossman
[    1.335117] sdhci-pltfm: SDHCI platform and OF driver helper
[    1.341449] remoteproc remoteproc0: releasing cd00000.q6v5_wcss
[    1.348857] NET: Registered PF_INET6 protocol family
[    1.352236] Segment Routing with IPv6
[    1.356171] In-situ OAM (IOAM) with IPv6
[    1.359727] NET: Registered PF_PACKET protocol family
[    1.363786] 8021q: 802.1Q VLAN Support v1.8
[    1.401030] qcom,cpr4-apss-regulator b018000.cpr4-ctrl: CPR valid fuse count: 4
[    1.401361] cpr4_ipq807x_apss_read_fuse_data: apc_corner: speed bin = 0
[    1.407203] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR fusing revision = 1
[    1.413757] cpr4_ipq807x_apss_read_fuse_data: apc_corner: CPR misc fuse value = 0
[    1.421439] cpr4_ipq807x_apss_read_fuse_data: apc_corner: Voltage boost fuse config = 0 boost = disable
[    1.428947] cpr3_mem_acc_init: apc: not using memory accelerator regulator
[    1.438095] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      SVS: open-loop= 720000 uV
[    1.445036] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused      NOM: open-loop= 840000 uV
[    1.455021] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused    TURBO: open-loop= 904000 uV
[    1.464801] cpr4_ipq807x_apss_calculate_open_loop_voltages: apc_corner: fused   STURBO: open-loop=1000000 uV
[    1.474689] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      SVS: quot[ 7]= 724, quot_offset[ 7]=   0
[    1.484448] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused      NOM: quot[ 7]= 941, quot_offset[ 7]= 215
[    1.495297] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused    TURBO: quot[ 7]=1043, quot_offset[ 7]= 100
[    1.506232] cpr4_ipq807x_apss_calculate_target_quotients: apc_corner: fused   STURBO: quot[ 7]=1205, quot_offset[ 7]= 160
[    1.517372] cpr3_regulator_init_ctrl: apc: Default CPR mode = closed-loop
[    1.520712] cpufreq: cpufreq_online: CPU0: Running at unlisted initial frequency: 800000 KHz, changing to: 1017600 KHz
[    1.536634] remoteproc remoteproc0: cd00000.q6v5_wcss is available
[    1.545831] ubi0: attaching mtd2
[    2.091148] ubi0: scanning is finished
[    2.097422] ubi0: attached mtd2 (name "rootfs_1", size 120 MiB)
[    2.097463] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
[    2.102158] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
[    2.109127] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
[    2.115962] ubi0: good PEBs: 960, bad PEBs: 0, corrupted PEBs: 0
[    2.122728] ubi0: user volume: 3, internal volumes: 1, max. volumes count: 128
[    2.128986] ubi0: max/mean erase counter: 29/15, WL threshold: 4096, image sequence number: 1202525907
[    2.136026] ubi0: available PEBs: 0, total reserved PEBs: 960, PEBs reserved for bad PEB handling: 40
[    2.145316] ubi0: background thread "ubi_bgt0d" started, PID 646
[    2.146056] block ubiblock0_1: created from ubi0:1(rooĂ´[    2.169577] VFS: Mounted root (squashfs filesystem) readonly on device 254:0.
[    2.170214] Freeing unused kernel memory: 1536K
[    2.175856] Run /sbin/init as init process
[    2.305009] random: crng init done
[    2.330572] init: Console is alive
[    2.330712] init: - watchdog -
[    2.813589] kmodloader: loading kernel modules from /etc/modules-boot.d/*
[    2.840512] gpio_button_hotplug: loading out-of-tree module taints kernel.
[    2.872771] ssdk_dt_parse_interrupt[941]:INFO:intr-gpio does not exist
[    3.291134] regi_init[2525]:INFO:Initializing HPPE Done!!
[    3.291263] regi_init[2574]:INFO:qca-ssdk module init succeeded!
[    3.297647] EDMA ver 1 hw init
[    3.301816] EDMA HW Reset completed succesfully
[    3.304491] Num rings - TxDesc:1 (23-23) TxCmpl:1 (7-7)
[    3.308906] RxDesc:1 (15-15) RxFill:1 (7-7)
[    3.314449] dp1: ppe offload disabled: 0 for macid 1
[    3.318280] dp1: Switch attached to macid 1 status: 0
[    3.515762] Qualcomm QCA8075 90000.mdio-1:00: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:00, irq=POLL)
[    3.516625] dp2: ppe offload disabled: 0 for macid 2
[    3.524656] dp2: Switch attached to macid 2 status: 0
[    3.615315] Qualcomm QCA8075 90000.mdio-1:01: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:01, irq=POLL)
[    3.616189] dp3: ppe offload disabled: 0 for macid 3
[    3.624209] dp3: Switch attached to macid 3 status: 0
[    3.705339] Qualcomm QCA8075 90000.mdio-1:02: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:02, irq=POLL)
[    3.706195] dp4: ppe offload disabled: 0 for macid 4
[    3.714231] dp4: Switch attached to macid 4 status: 0
[    3.795333] Qualcomm QCA8075 90000.mdio-1:03: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:03, irq=POLL)
[    3.796184] dp5: ppe offload disabled: 0 for macid 5
[    3.804222] dp5: Switch attached to macid 5 status: 0
[    3.885342] Qualcomm QCA8075 90000.mdio-1:04: attached PHY driver (mii_bus:phy_addr=90000.mdio-1:04, irq=POLL)
[    3.886161] **********************************************************
[    3.894237] * NSS Data Plane driver
[    3.900769] **********************************************************
[    3.921505] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.921552] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 1
[    3.926042] xhci-hcd xhci-hcd.1.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000008002000010
[    3.933480] xhci-hcd xhci-hcd.1.auto: irq 39, io mem 0x08a00000
[    3.942929] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller
[    3.948726] xhci-hcd xhci-hcd.1.auto: new USB bus registered, assigned bus number 2
[    3.954280] xhci-hcd xhci-hcd.1.auto: Host supports USB 3.0 SuperSpeed
[    3.962251] hub 1-0:1.0: USB hub found
[    3.968450] hub 1-0:1.0: 1 port detected
[    3.972419] usb usb2: We don't know the algorithms for LPM for this host, disabling LPM.
[    3.976723] hub 2-0:1.0: USB hub found
[    3.984323] hub 2-0:1.0: 1 port detected
[    3.988252] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    3.991953] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 3
[    3.997438] xhci-hcd xhci-hcd.2.auto: hcc params 0x0220fe65 hci version 0x110 quirks 0x0000008002000010
[    4.004838] xhci-hcd xhci-hcd.2.auto: irq 40, io mem 0x08c00000
[    4.014270] xhci-hcd xhci-hcd.2.auto: xHCI Host Controller
[    4.020078] xhci-hcd xhci-hcd.2.auto: new USB bus registered, assigned bus number 4
[    4.025637] xhci-hcd xhci-hcd.2.auto: Host supports USB 3.0 SuperSpeed
[    4.033628] hub 3-0:1.0: USB hub found
[    4.039822] hub 3-0:1.0: 1 port detected
[    4.043846] usb usb4: We don't know the algorithms for LPM for this host, disabling LPM.
[    4.047968] hub 4-0:1.0: USB hub found
[    4.055692] hub 4-0:1.0: 1 port detected
[    4.061915] kmodloader: done loading kernel modules from /etc/modules-boot.d/*
[    4.069551] init: - preinit -
Cannot parse config file '/etc/fw_env.config': No such file or directory
Failed to find NVMEM device
Press the [f] key and hit [enter] to enter failsafe mode
Press the [1], [2], [3] or [4] key and hit [enter] to select the debug level
[    7.685146] nss-dp 3a001000.dp1 lan1: PHY Link up speed: 1000
[    8.796300] UBIFS (ubi0:2): Mounting in unauthenticated mode
[    8.796408] UBIFS (ubi0:2): background thread "ubifs_bgt0_2" started, PID 933
[    8.826987] UBIFS (ubi0:2): recovery needed
[    8.914871] UBIFS (ubi0:2): recovery completed
[    8.915002] UBIFS (ubi0:2): UBIFS: mounted UBI device 0, volume 2, name "rootfs_data"
[    8.918215] UBIFS (ubi0:2): LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes
[    8.926129] UBIFS (ubi0:2): FS size: 102342656 bytes (97 MiB, 806 LEBs), max 817 LEBs, journal size 5079040 bytes (4 MiB, 40 LEBs)
[    8.936025] UBIFS (ubi0:2): reserved for root: 4833895 bytes (4720 KiB)
[    8.947647] UBIFS (ubi0:2): media format: w5/r0 (latest is w5/r0), UUID 296B8C0F-2B1E-4DD2-B805-E673B97CBC6C, small LPT model
[    8.957332] mount_root: switching to ubifs overlay
[    8.969552] overlayfs: null uuid detected in lower fs '/', falling back to xino=off,index=off,nfs_export=off.
[    8.974849] urandom-seed: Seeding with /etc/urandom.seed
[    9.022930] nss-dp 3a001000.dp1 lan1: PHY Link is down
[    9.027634] procd: - early -
[    9.027740] procd: - watchdog -
[    9.572475] procd: - watchdog -
[    9.573119] procd: - ubus -
[    9.726202] procd: - init -
Please press Enter to activate this console.
[    9.937317] kmodloader: loading kernel modules from /etc/modules.d/*
[   10.027552] Loading modules backported from Linux version v6.11.2-0-g7aa21fec187b
[   10.027593] Backport generated by backports.git v6.1.110-1-32-gc61f71fe0942
[   10.038543] NET: Registered PF_QIPCRTR protocol family
[   10.094743] urngd: v1.0.2 started.
[   10.100720] PPP generic driver version 2.4.2
[   10.101597] NET: Registered PF_PPPOX protocol family
[   10.112094] ath11k c000000.wifi: ipq8074 hw2.0
[   10.112127] ath11k c000000.wifi: FW memory mode: 0
[   10.141533] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   10.141846] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   11.176966] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   11.220964] ath11k c000000.wifi: qmi ignore invalid mem req type 3
[   11.228410] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   11.228446] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   16.356751] remoteproc remoteproc0: stopped remote processor cd00000.q6v5_wcss
[   16.356798] remoteproc remoteproc0: powering up cd00000.q6v5_wcss
[   16.363124] remoteproc remoteproc0: Booting fw image IPQ8074/q6_fw.mdt, size 668
[   16.713500] remoteproc remoteproc0: remote processor cd00000.q6v5_wcss is now up
[   16.716248] kmodloader: done loading kernel modules from /etc/modules.d/*
[   16.757352] ath11k c000000.wifi: qmi ignore invalid mem req type 3
[   16.764837] ath11k c000000.wifi: chip_id 0x0 chip_family 0x0 board_id 0xff soc_id 0xffffffff
[   16.764884] ath11k c000000.wifi: fw_version 0x290b84a5 fw_build_timestamp 2024-09-23 11:32 fw_build_id WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
[   17.063766] ath11k c000000.wifi: htt event 48 not handled
[   18.831351] br-lan: port 1(lan1) entered blocking state
[   18.831400] br-lan: port 1(lan1) entered disabled state
[   18.835484] nss-dp 3a001000.dp1 lan1: entered allmulticast mode
[   18.840810] nss-dp 3a001000.dp1 lan1: entered promiscuous mode
[   18.853362] br-lan: port 2(lan2) entered blocking state
[   18.853404] br-lan: port 2(lan2) entered disabled state
[   18.857640] nss-dp 3a001200.dp2 lan2: entered allmulticast mode
[   18.862977] nss-dp 3a001200.dp2 lan2: entered promiscuous mode
[   18.872067] br-lan: port 3(lan3) entered blocking state
[   18.874549] br-lan: port 3(lan3) entered disabled state
[   18.879787] nss-dp 3a001400.dp3 lan3: entered allmulticast mode
[   18.885169] nss-dp 3a001400.dp3 lan3: entered promiscuous mode
[   18.895389] br-lan: port 4(lan4) entered blocking state
[   18.896688] br-lan: port 4(lan4) entered disabled state
[   18.901844] nss-dp 3a001600.dp4 lan4: entered allmulticast mode
[   18.907335] nss-dp 3a001600.dp4 lan4: entered promiscuous mode
[   21.925137] nss-dp 3a001000.dp1 lan1: PHY Link up speed: 1000
[   21.925199] br-lan: port 1(lan1) entered blocking state
[   21.929878] br-lan: port 1(lan1) entered forwarding state
[   32.485019] l11: disabling



BusyBox v1.36.1 (2024-11-04 22:40:38 UTC) built-in shell (ash)

  _______                     ________        __
 |       |.-----.-----.-----.|  |  |  |.----.|  |_
 |   -   ||  _  |  -__|     ||  |  |  ||   _||   _|
 |_______||   __|_____|__|__||________||__|  |____|
          |__| W I R E L E S S   F R E E D O M
 -----------------------------------------------------
 OpenWrt SNAPSHOT, r28012-31f1dabb4b
 -----------------------------------------------------
=== WARNING! =====================================
There is no root password defined on this device!
Use the "passwd" command to set up a new password
in order to prevent unauthorized SSH logins.
--------------------------------------------------
root@OpenWrt:~# ls
root@OpenWrt:~# uname -a
Linux OpenWrt 6.6.59 #0 SMP Mon Nov  4 22:40:38 2024 aarch64 GNU/Linux
root@OpenWrt:~# root@OpenWrt:~# 

After some more investigation, I found the openwty 6.6.59 does NOT have the root directory empty folder problem.
The only issue was that when we booted openwrt kernel 6.1.71, the default path is "/". But when we booted the kenel 6.6.59, the default path is "/root". In any case, when I do "ls -l /", it does show the correct content of "/" directory.