Older TP-Link firmwares used not to have a TFTP server onboard, no idea if that applies to the VR2600 as well. If you're still on stock, it might be a good idea to update to the most recent TP-Link firmware (bootloader gets replaced as well).
This is what I'm running (latest available in Australia). I tried upgrading to the VR2600v version and the EU version but it will not accept them.
Firmware Version:1.5.0 0.8.0 v0050.0 Build 170425 Rel.35576n Hardware Version:Archer VR2600 v1 00000000
Anyway, I am fine opening it and using the serial method. Got the screws out but not sure how to pop the top off without breaking it
You can also try to listen on the network interface with wireshark to obtain the needed ip address and file name of the tftp request...
Don't filter only on tftp packages... If I remember it correctly, there are some arp "who has ip" requests before any tftp happen.
It would be best to connect only your device to the listening ethernet port.
How long do I need to hold the button before it interrupts the boot?
Another question: does the case come apart where the silver meets the bottom black part or in the gap?
Never mind I got it. Just stick a screw driver in the gap and twist (after removing the scews from the feet in the bottom). It comes off very easily.
Well guys, it was nice knowing you
I got a bit too quick on the keyboard and accidentally erased the bootloader. Getting nothing from serial
(IPQ) # tftpboot 0x44000000 sysupgrade.bin
Mac1 unit failed
Using eth1 device
TFTP from server 10.42.21.200; our IP address is 10.42.21.50
Filename 'sysupgrade.bin'.
Load address: 0x44000000
Loading: #################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#####################
done
Bytes transferred = 6029502 (5c00be hex)
(IPQ) # sf erase 0x320000 0xc60000
(IPQ) # sf write 0x44000000 0x3200000 0x5c00be
(IPQ) # reset
note that 0x3200000 should have been 0x320000
Anything I can do with just a serial cable to recover or do I need a flash programmer? Anyone have a full dump of the default flash?
Tried the other serial port and looks like we have CFE!
CPUI
L1CI
HELO
CPUI
L1CI
4.1601-1.0.38-116.15
DRAM
----
PHYS
STRF
400H
PHYE
DDR2
SIZ4
SIZ3
SIZ2
SIZ1
DINT
USYN
LSYN
MFAS
LMBE
RACE
PASS
----
ZBSS
CODE
DATA
L12F
MAIN
Base: 4.16_01
CFE version 1.0.38-116.15 for BCM963268 (32bit,SP,BE)
Build Date: Tue Jul 1 16:50:33 HKT 2014 (swd@localhost.localdomain)
Copyright (C) 2000-2013 Broadcom Corporation.
Chip ID: BCM63168D0, MIPS: 400MHz, DDR: 400MHz, Bus: 200MHz
Main Thread: TP0
Memory Test Passed
Total Memory: 67108864 bytes (64MB)
Boot Address: 0xb8000000
HS Serial flash device: ID_W25X64, id 0xef17 sector 4KB size 8192KB
Flash not used for Auxillary File System
Board IP address : 192.168.1.1:ffffff00
Host IP address : 192.168.1.100
Gateway IP address :
Run from flash/host/tftp (f/h/c) : f
Default host run file name : vmlinux
Default host flash file name : bcm963xx_fs_kernel
Boot delay (0-9 seconds) : 1
Default host ramdisk file name :
Default ramdisk store address :
Board Id (0-30) : 963168TP
Number of MAC Addresses (1-32) : 11
Base MAC Address : 02:10:18:01:00:01
PSI Size (1-64) KBytes : 24
Enable Backup PSI [0|1] : 0
System Log Size (0-256) KBytes : 0
Auxillary File System Size Percent: 0
Main Thread Number [0|1] : 0
Voice Board Configuration (0-0) :
*** Press any key to stop auto run (1 seconds) ***
Auto run second count down: 1
web info: Waiting for connection on socket 0.
CFE> help
Available commands:
phy Set memory or registers.
dbg_uart uart 1 test
tp_mtest Test memory all we can.
mtest Test memory.
sm Set memory or registers.
dm Dump memory or registers.
db Dump bytes.
dh Dump half-words.
dw Dump words.
w Write the whole image start from beginning of the flash
e Erase [n]vram or [a]ll flash except bootrom
ws Write whole image (priviously loaded by kermit) to flash .
r Run program from flash image or from host depend on [f/h] fg
p Print boot line and board parameter info
c Change booline parameters
f Write image to the flash
i Erase persistent storage data
a Change board AFE ID
b Change board parameters
reset Reset the board
pmdio Pseudo MDIO access for external switches.
spi Legacy SPI access of external switch.
force override chipid check for images.
help Obtain help for CFE commands
For more information about a command, enter 'help command-name'
*** command status = 0
CFE>
Tried the other serial port and looks like we have CFE!
CPUI
L1CI
HELO
CPUI
L1CI
4.1601-1.0.38-116.15
DRAM
----
PHYS
STRF
400H
PHYE
DDR2
SIZ4
SIZ3
SIZ2
SIZ1
DINT
USYN
LSYN
MFAS
LMBE
RACE
PASS
----
ZBSS
CODE
DATA
L12F
MAIN
Base: 4.16_01
CFE version 1.0.38-116.15 for BCM963268 (32bit,SP,BE)
Build Date: Tue Jul 1 16:50:33 HKT 2014 (swd@localhost.localdomain)
Copyright (C) 2000-2013 Broadcom Corporation.
Chip ID: BCM63168D0, MIPS: 400MHz, DDR: 400MHz, Bus: 200MHz
Main Thread: TP0
Memory Test Passed
Total Memory: 67108864 bytes (64MB)
Boot Address: 0xb8000000
HS Serial flash device: ID_W25X64, id 0xef17 sector 4KB size 8192KB
Flash not used for Auxillary File System
Board IP address : 192.168.1.1:ffffff00
Host IP address : 192.168.1.100
Gateway IP address :
Run from flash/host/tftp (f/h/c) : f
Default host run file name : vmlinux
Default host flash file name : bcm963xx_fs_kernel
Boot delay (0-9 seconds) : 1
Default host ramdisk file name :
Default ramdisk store address :
Board Id (0-30) : 963168TP
Number of MAC Addresses (1-32) : 11
Base MAC Address : 02:10:18:01:00:01
PSI Size (1-64) KBytes : 24
Enable Backup PSI [0|1] : 0
System Log Size (0-256) KBytes : 0
Auxillary File System Size Percent: 0
Main Thread Number [0|1] : 0
Voice Board Configuration (0-0) :
*** Press any key to stop auto run (1 seconds) ***
Auto run second count down: 1
web info: Waiting for connection on socket 0.
CFE> help
Available commands:
phy Set memory or registers.
dbg_uart uart 1 test
tp_mtest Test memory all we can.
mtest Test memory.
sm Set memory or registers.
dm Dump memory or registers.
db Dump bytes.
dh Dump half-words.
dw Dump words.
w Write the whole image start from beginning of the flash
e Erase [n]vram or [a]ll flash except bootrom
ws Write whole image (priviously loaded by kermit) to flash .
r Run program from flash image or from host depend on [f/h] fg
p Print boot line and board parameter info
c Change booline parameters
f Write image to the flash
i Erase persistent storage data
a Change board AFE ID
b Change board parameters
reset Reset the board
pmdio Pseudo MDIO access for external switches.
spi Legacy SPI access of external switch.
force override chipid check for images.
help Obtain help for CFE commands
For more information about a command, enter 'help command-name'
*** command status = 0
CFE>
Is this another system? It boots and has a login of admin/admin
Base: 4.16_01
CFE version 1.0.38-116.15 for BCM963268 (32bit,SP,BE)
Build Date: Tue Jul 1 16:50:33 HKT 2014 (swd@localhost.localdomain)
Copyright (C) 2000-2013 Broadcom Corporation.
Chip ID: BCM63168D0, MIPS: 400MHz, DDR: 400MHz, Bus: 200MHz
Main Thread: TP0
Memory Test Passed
Total Memory: 67108864 bytes (64MB)
Boot Address: 0xb8000000
HS Serial flash device: ID_W25X64, id 0xef17 sector 4KB size 8192KB
Flash not used for Auxillary File System
Board IP address : 192.168.1.1:ffffff00
Host IP address : 192.168.1.100
Gateway IP address :
Run from flash/host/tftp (f/h/c) : f
Default host run file name : vmlinux
Default host flash file name : bcm963xx_fs_kernel
Boot delay (0-9 seconds) : 1
Default host ramdisk file name :
Default ramdisk store address :
Board Id (0-30) : 963168TP
Number of MAC Addresses (1-32) : 11
Base MAC Address : 02:10:18:01:00:01
PSI Size (1-64) KBytes : 24
Enable Backup PSI [0|1] : 0
System Log Size (0-256) KBytes : 0
Auxillary File System Size Percent: 0
Main Thread Number [0|1] : 0
Voice Board Configuration (0-0) :
*** Press any key to stop auto run (1 seconds) ***
Auto run second count down: 0
Booting from only image (0xb8010000) ...
Code Address: 0x80010000, Entry Address: 0x802dd410
Decompression OK!
Entry at 0x802dd410
Starting program at 0x802dd410
Linux version 3.4.11-rt19 (ustcdirty@ustcdirty) (gcc version 4.6.2 (Buildroot 27
HS Serial flash device: ID_W25X64, id 0xef17 sector 4KB size 8192KB
963168TP prom init
CPU revision is: 0002a080 (Broadcom BMIPS4350)
DSL SDRAM reserved: 0x132000
Determined physical RAM map:
memory: 03ece000 @ 00000000 (usable)
Zone PFN ranges:
DMA 0x00000000 -> 0x00001000
Normal 0x00001000 -> 0x00003ece
Movable zone start PFN for each node
Early memory PFN ranges
0: 0x00000000 -> 0x00003ece
On node 0 totalpages: 16078
free_area_init_node: node 0, pgdat 803a52f0, node_mem_map 81000000
DMA zone: 32 pages used for memmap
DMA zone: 0 pages reserved
DMA zone: 4064 pages, LIFO batch:0
Normal zone: 94 pages used for memmap
Normal zone: 11888 pages, LIFO batch:1
PERCPU: Embedded 7 pages/cpu @81083000 s5088 r8192 d15392 u32768
pcpu-alloc: s5088 r8192 d15392 u32768 alloc=8*4096
pcpu-alloc: [0] 0 [0] 1
Built 1 zonelists in Zone order, mobility grouping on. Total pages: 15952
Kernel command line: ro noinitrd irqaffinity=0
PID hash table entries: 256 (order: -2, 1024 bytes)
Dentry cache hash table entries: 8192 (order: 3, 32768 bytes)
Inode-cache hash table entries: 4096 (order: 2, 16384 bytes)
Primary instruction cache 64kB, VIPT, 4-way, linesize 16 bytes.
Primary data cache 32kB, 2-way, VIPT, cache aliases, linesize 16 bytes
Memory: 59532k/64312k available (2919k kernel code, 4780k reserved, 751k data, )
Preemptible hierarchical RCU implementation.
NR_IRQS:128
console [ttyS0] enabled
Calibrating delay loop... 397.31 BogoMIPS (lpj=198656)
pid_max: default: 32768 minimum: 301
Mount-cache hash table entries: 512
--Kernel Config--
SMP=1
PREEMPT=1
DEBUG_SPINLOCK=0
DEBUG_MUTEXES=0
Broadcom Logger v0.1 Apr 14 2017 16:58:40
CPU revision is: 0002a080 (Broadcom BMIPS4350)
Primary instruction cache 64kB, VIPT, 4-way, linesize 16 bytes.
Primary data cache 32kB, 2-way, VIPT, cache aliases, linesize 16 bytes
Brought up 2 CPUs
NET: Registered protocol family 16
Flash not used for Auxillary File System
Internal 1P2 VREG will be shutdown if unused...Used, leave it on (00008435-0000)
registering PCI controller with io_map_base unset
registering PCI controller with io_map_base unset
bio: create slab <bio-0> at 0
PCI host bridge to bus 0000:00
pci_bus 0000:00: root bus resource [mem 0xa0f00000-0xa0ffffff]
pci_bus 0000:00: root bus resource [io 0xa2000000-0xa200ffff]
pci 0000:00:00.0: [14e4:435f] type 00 class 0x028000
pci 0000:00:00.0: reg 10: [mem 0x10004000-0x10005fff]
PCI host bridge to bus 0000:01
pci_bus 0000:01: root bus resource [mem 0x11000000-0x11efffff]
pci_bus 0000:01: root bus resource [??? 0x00000000 flags 0x0]
pci 0000:01:00.0: [14e4:6326] type 01 class 0x060400
pci 0000:01:00.0: PME# supported from D0 D3hot
pci 0000:01:00.0: PCI bridge to [bus 02-02]
bcmhs_spi bcmhs_spi.1: master is unqueued, this is deprecated
bcmleg_spi bcmleg_spi.0: master is unqueued, this is deprecated
skbFreeTask created successfully
BLOG v3.0 Initialized
BLOG Rule v1.0 Initialized
Broadcom IQoS v0.1 Apr 14 2017 17:01:25 initialized
Broadcom GBPM v0.1 Apr 14 2017 17:01:26 initialized
NET: Registered protocol family 8
NET: Registered protocol family 20
Switching to clocksource MIPS
NET: Registered protocol family 2
IP route cache hash table entries: 1024 (order: 0, 4096 bytes)
TCP established hash table entries: 2048 (order: 2, 16384 bytes)
TCP bind hash table entries: 2048 (order: 2, 16384 bytes)
TCP: Hash tables configured (established 2048 bind 2048)
TCP: reno registered
UDP hash table entries: 128 (order: 0, 4096 bytes)
UDP-Lite hash table entries: 128 (order: 0, 4096 bytes)
NET: Registered protocol family 1
PCI: CLS 64 bytes, default 16
bcm_tstamp initialized, (hpt_freq=200000000 2us_div=200 2ns_mult=5 2ns_shift=0)
squashfs: version 4.0 (2009/01/31) Phillip Lougher
jffs2: version 2.2. (NAND) ?© 2001-2006 Red Hat, Inc.
msgmni has been set to 116
io scheduler noop registered (default)
bcm963xx_mtd driver
File system address: 0xb8010100
Registered device mtd:rootfs dev0 Address=0xb8010100 Size=2830336
PPP generic driver version 2.4.2
PPP BSD Compression module registered
PPP Deflate Compression module registered
NET: Registered protocol family 24
brcmboard: brcm_board_init entry
SES: Button Interrupt 0x1 is enabled
DYING GASP IRQ initialized
Serial: BCM63XX driver $Revision: 3.00 $
Magic SysRq with Auxilliary trigger char enabled (type ^ h for list of supporte)
ttyS0 at MMIO 0xb0000180 (irq = 13) is a BCM63XX
ttyS1 at MMIO 0xb00001a0 (irq = 42) is a BCM63XX
Total # RxBds=1448
bcmPktDmaBds_init: Broadcom Packet DMA BDs initialized
bcmPktDma_init: Broadcom Packet DMA Library initialized
TCP: cubic registered
Initializing XFRM netlink socket
NET: Registered protocol family 17
NET: Registered protocol family 15
8021q: 802.1Q VLAN Support v1.8
VFS: Mounted root (squashfs filesystem) readonly on device 31:0.
Freeing unused kernel memory: 192k freed
init started: BusyBox v1.17.2 (2017-04-14 17:04:25 CST)
starting pid 167, tty '': '/bin/sh -l -c "bcm_boot_launcher start"'
Mounting filesystems...
Configuring system...
Loading drivers and kernel modules...
chipinfo: module license 'proprietary' taints kernel.
Disabling lock debugging due to kernel taint
brcmchipinfo: brcm_chipinfo_init entry
bcmxtmrt: Broadcom BCM3168D0 ATM/PTM Network Device v0.6 Apr 14 2017 17:00:41
Broadcom Ingress QoS Module Char Driver v0.1 Apr 14 2017 17:00:14 Registered<2>
Broadcom Ingress QoS ver 0.1 initialized
BPM: tot_mem_size=67108864B (64MB), buf_mem_size <15%> =10066320B (9MB), num of6
Broadcom BPM Module Char Driver v0.1 Apr 14 2017 17:00:02 Registered<244>
NBUFF v1.0 Initialized
Initialized fcache state
Broadcom Packet Flow Cache Char Driver v2.2 Apr 14 2017 17:00:14 Registered<24>
Created Proc FS /procfs/fcache
Broadcom Packet Flow Cache registered with netdev chain
Broadcom Packet Flow Cache learning via BLOG enabled.
[FHW] pktDbgLvl[0xc011f6e0]=0
[FHW] fhw_construct:
Initialized Fcache HW accelerator layer state
flwStatsThread created
Constructed Broadcom Packet Flow Cache v2.2 Apr 14 2017 17:00:14
chipId 0x631680D0
Broadcom Forwarding Assist Processor (FAP) Char Driver v0.1 Apr 14 2017 17:00:0>
Enabling SMISBUS PHYS_FAP_BASE[0] is 0x10c01000
FAP Soft Reset Done
4ke Reset Done
Enabling SMISBUS PHYS_FAP_BASE[1] is 0x10c01000
FAP Soft Reset Done
4ke Reset Done
FAP Debug values at 0xa241fc00 0xa249fc00
fapGso_LoopBkThread created successfully
Allocated FAP0 SWQ_HOST2FAP_GSO_LOOPBACK_Q mem=a3924000 : 16384 bytes
Allocated FAP0 SWQ_FAP2HOST_GSO_LOOPBACK_Q mem=a395c000 : 16384 bytes
GSO LOOPBACK Cached HOST2FAP Q INFO:
Swq =b0825e40 qStart=a3924000 qEnd=a3928000 msgSize=4 dqm=18 fapId=0
GSO LOOPBACK Cached FAP2HOST Q INFO:
Swq =b0825e20 qStart=a395c000 qEnd=a3960000 msgSize=2 dqm=19 fapId=0
Allocated FAP0 TM SDRAM Queue Storage (a242dc90) : 390144 bytes @ a2500000
Allocated FAP1 TM SDRAM Queue Storage (a24adc90) : 390144 bytes @ a2580000
[NTC fapProto] fapReset : Reset FAP Protocol layer
Broadcom Packet Flow Cache HW acceleration enabled.
[FAP0] DSPRAM : stack <0x80000000><1536>, global <0x80000600><4272>, free <2384>
[FAP1] DSPRAM : stack <0x80000000><1536>, global <0x80000600><4272>, free <2384>
[FAP0] PSM : addr<0x80002000>, used <24160>, free <416>, total <24576>
[FAP1] PSM : addr<0x80002000>, used <24160>, free <416>, total <24576>
[FAP0] DQM : availableMemory 14660 bytes, nextByteAddress 0xE000489C
[FAP1] DQM : availableMemory 14660 bytes, nextByteAddress 0xE000489C
[FAP0] Initializing FAP4KE GSO LOOPBACK on fapIdx=0 ...
[FAP1] FAP BPM Initialized.
[FAP0] SWQ: HOST2FAP_GSO_LOOPBACK
[FAP0] >>>>------------------
[FAP0] swq =80007e40 msgSize =4 words , maxDepth=1024
[FAP0] qStart =a3924000 qEnd=a3928000
[FAP0] rdPtr =a3924000 wrPtr=a3924000 count=0
[FAP0] processed =0 dropped =0
[FAP0] Associated DQM=18 dir HOST2FAP
[FAP0] ------------------<<<<
[FAP0] SWQ: FAP2HOST_GSO_LOOPBACK
[FAP0] >>>>------------------
[FAP0] swq =80007e20 msgSize =2 words , maxDepth=2048
[FAP0] qStart =a395c000 qEnd=a3960000
[FAP0] rdPtr =a395c000 wrPtr=a395c000 count=0
[FAP0] processed =0 dropped =0
[FAP0] Associated DQM=19 dir FAP2HOST
[FAP0] ------------------<<<<
[FAP0] FAP4KE GSO LOOPBACK Init Done...
[FAP0] FAP BPM Initialized.
fapDrv_construct: FAP0: pManagedMemory=b0820650. wastage 8 bytes
fapDrv_construct: FAP1: pManagedMemory=b0a20650. wastage 8 bytes
bcmPktDma_bind: FAP Driver binding successfull
[FAP0] FAP TM: ON
[FAP1] FAP TM: ON
bcmxtmcfg: bcmxtmcfg_init entry
adsl: adsl_init entry
Broadcom BCM63168D0 Ethernet Network Device v0.1 Apr 14 2017 17:00:28
Broadcom GMAC Char Driver v0.1 Apr 14 2017 17:00:38 Registered<249>
Broadcom GMAC Driver v0.1 Apr 14 2017 17:00:38 Initialized
fapDrv_psmAlloc: fapIdx=1, size: 4800, offset=b0a20650 bytes remaining 7000
ETH Init: Ch:0 - 200 tx BDs at 0xb0a20650
fapDrv_psmAlloc: fapIdx=0, size: 4800, offset=b0820650 bytes remaining 7000
ETH Init: Ch:1 - 200 tx BDs at 0xb0820650
fapDrv_psmAlloc: wastage 8 bytes
fapDrv_psmAlloc: fapIdx=0, size: 4808, offset=b0821910 bytes remaining 2184
ETH Init: Ch:0 - 600 rx BDs at 0xb0821910
[FAP0] enetRxChannel 0
fapDrv_psmAlloc: wastage 8 bytes
fapDrv_psmAlloc: fapIdx=1, size: 4808, offset=b0a21910 bytes remaining 2184
ETH Init: Ch:1 - 600 rx BDs at 0xb0a21910
[FAP1] enetRxChannel 1
dgasp: kerSysRegisterDyingGaspHandler: bcmsw registered
eth0: <Int sw port: 0> <Logical : 00> PHY_ID <0x00000001 : 0x01> MAC : 02:10:181
eth1: <Int sw port: 1> <Logical : 01> PHY_ID <0x00000002 : 0x02> MAC : 02:10:181
eth2: <Int sw port: 2> <Logical : 02> PHY_ID <0x00000003 : 0x03> MAC : 02:10:181
eth3: <Int sw port: 3> <Logical : 03> PHY_ID <0x00000004 : 0x04> MAC : 02:10:181
eth4: <Int sw port: 4> <Logical : 04> PHY_ID <0x02000018 : 0x18> MAC : 02:10:181
eth5: <Int sw port: 6> <Logical : 06> PHY_ID <0x02000019 : 0x19> MAC : 02:10:181
Ethernet Auto Power Down and Sleep: Enabled
Energy Efficient Ethernet: Enabled
eth4 Link UP 1000 mbps full duplex
eth5 Link UP 1000 mbps full duplex
NComm TMS V6.80 Kernel Module loaded.
[NTC arl] arlEnable : Enabled ARL binding to FAP
Broadcom Address Resolution Logic Processor (ARL) Char Driver v0.1 Apr 14 2017 >
Broadcom 802.1Q VLAN Interface, v0.1
PCIe: No device found - Powering down
Saving kernel bootup messages for dumpsysinfo...
Starting CMS smd...
===== Release Version 4.16L.01 (build timestamp 170417_1108) =====
Initializing CMS MDM in Hybrid98+181 mode
Host MIPS Clock divider pwrsaving is enabled
DDR Self Refresh pwrsaving is enabled
Adaptive Voltage Scaling is now enabled
BcmPwrMngtEnableAvs: AVS_START, 0x8391c4d8
sh: ebtables: not found
sh: ebtables: not found
sh: ebtables: not found
sh: ebtables: not found
device eth4 entered promiscuous mode
br0: port 1(eth4) entered forwarding state
br0: port 1(eth4) entered forwarding state
sh: ebtables: not found
sh: ebtables: not found
monitor task is initialized pid= 334
starting pid 419, tty '': '-/bin/sh -l -c consoled'
device eth4 left promiscuous mode
br0: port 1(eth4) entered disabled state
BCM963268 Broadband Router
Success
oal_6332.c#dslStatusCheckHandler: dslStatusCheckHandler start.
Login: root
Password:
Login incorrect. Try again.
Login: admin
Password:
> help
?
help
logout
exit
quit
reboot
adsl
xdslctl
xtm
brctl
cat
virtualserver
df
loglevel
logdest
dumpcfg
dumpmdm
dumpeid
mdm
meminfo
kill
dumpsysinfo
exitOnIdle
syslog
echo
ifconfig
ping
ps
pwd
sysinfo
tftp
arp
defaultgateway
dhcpserver
dns
lan
lanhosts
passwd
ppp
restoredefault
route
save
swversion
uptime
cfgupdate
swupdate
wan
>
dumpsysinfo - this looks like a completely different system (DSL subsystem?) for a BCM963268 Broadband Router. What is going on here? It looks like it has network interfaces and everything.
Full dump at https://pastebin.com/MsKRdEu8
> dumpsysinfo
###DumpSysInfo: First dump system information
======Version Info======
######kernel version######
Linux version 3.4.11-rt19 (ustcdirty@ustcdirty) (gcc version 4.6.2 (Buildroot 27
######xdsl version######
/bin/xdslctl version 1.2
/bin/xdslctl: devCtl_adslGetVersion error
ADSL PHY: Unknown version -
======System Info======
######/proc/uptime######
190.40 372.50
######/proc/cpuinfo######
system type : 963168TP
processor : 0
cpu model : Broadcom BMIPS4350 V8.0
BogoMIPS : 397.31
wait instruction : yes
microsecond timers : yes
tlb_entries : 32
extra interrupt vector : no
hardware watchpoint : no
ASEs implemented :
shadow register sets : 1
kscratch registers : 0
core : 0
VCED exceptions : not available
VCEI exceptions : not available
processor : 1
cpu model : Broadcom BMIPS4350 V8.0
BogoMIPS : 403.45
wait instruction : yes
microsecond timers : yes
tlb_entries : 32
extra interrupt vector : no
hardware watchpoint : no
ASEs implemented :
shadow register sets : 1
kscratch registers : 0
core : 0
VCED exceptions : not available
VCEI exceptions : not available
######/proc/brcm/kernel_config######
CONFIG_SMP=1
CONFIG_PREEMPT=1
CONFIG_DEBUG_SPINLOCK=0
CONFIG_DEBUG_MUTEXES=0
######/proc/interrupts######
CPU0 CPU1
0: 9232 2419 BCM63xx IPI
7: 190047 190323 BCM63xx timer
13: 0 202 BCM63xx_no_unmask serial
21: 0 0 BCM63xx_no_unmask brcm_21
22: 0 0 BCM63xx_no_unmask brcm_22
32: 235 0 BCM63xx_no_unmask fap0
33: 217 0 BCM63xx_no_unmask fap1
39: 0 0 BCM63xx_no_unmask brcm_39
52: 0 0 BCM63xx_no_unmask brcm_52
53: 0 0 BCM63xx_no_unmask brcm_53
91: 0 0 BCM63xx_no_unmask brcm_91
ERR: 0
######/proc/meminfo######
MemTotal: 59724 kB
MemFree: 31828 kB
Buffers: 1536 kB
Cached: 5292 kB
SwapCached: 0 kB
Active: 2436 kB
Inactive: 5580 kB
Active(anon): 1172 kB
Inactive(anon): 0 kB
Active(file): 1264 kB
Inactive(file): 5580 kB
Unevictable: 0 kB
Mlocked: 0 kB
SwapTotal: 0 kB
SwapFree: 0 kB
Dirty: 0 kB
Writeback: 0 kB
AnonPages: 1216 kB
Mapped: 1704 kB
Shmem: 0 kB
Slab: 17328 kB
SReclaimable: 340 kB
SUnreclaim: 16988 kB
KernelStack: 640 kB
PageTables: 184 kB
NFS_Unstable: 0 kB
Bounce: 0 kB
WritebackTmp: 0 kB
CommitLimit: 29860 kB
Committed_AS: 3312 kB
VmallocTotal: 1032116 kB
VmallocUsed: 2128 kB
VmallocChunk: 1027124 kB
######/proc/iomem######
00000000-03ecdfff : System RAM
00010000-002e9cff : Kernel code
002e9d00-003a5cdf : Kernel data
11000000-11efffff : bcm63xx pcie memory space
a0f00000-a0ffffff : bcm63xx pci memory space
######/proc/slabinfo######
slabinfo - version: 2.1
# name <active_objs> <num_objs> <objsize> <objperslab> <pagesperslab>
bcmVlan_blogRule_id 0 0 8 339 1 : tunables 120 60 8 : 0
bcmVlan_flowPath 0 0 16 203 1 : tunables 120 60 8 : sl0
bcmVlan_flowDev 0 0 16 203 1 : tunables 120 60 8 : sl0
bcmvlan_tableEntry 0 0 416 9 1 : tunables 54 27 8 : s0
bcmvlan_realDev 0 0 464 8 1 : tunables 54 27 8 : sl0
bcmvlan_vlanDev 0 0 24 145 1 : tunables 120 60 8 : sl0
bcm_EnetSkbCache 0 0 256 15 1 : tunables 120 60 8 : sl0
fapMcast_flowCache 0 0 48 78 1 : tunables 120 60 8 : s0
fap1_4ke_cache 1 1 524288 1 128 : tunables 1 1 0 : sl0
fap0_4ke_cache 1 1 524288 1 128 : tunables 1 1 0 : sl0
bcm_XtmSkbCache 0 0 256 15 1 : tunables 120 60 8 : sl0
ubifs_inode_slab 0 0 416 9 1 : tunables 54 27 8 : sl0
bridge_fdb_cache 0 0 48 78 1 : tunables 120 60 8 : sl0
flow_cache 0 0 88 44 1 : tunables 120 60 8 : sl0
ubi_wl_entry_slab 0 0 24 145 1 : tunables 120 60 8 : sl0
jffs2_inode_cache 0 0 24 145 1 : tunables 120 60 8 : sl0
jffs2_node_frag 0 0 24 145 1 : tunables 120 60 8 : sl0
jffs2_refblock 0 0 248 16 1 : tunables 120 60 8 : sl0
jffs2_tmp_dnode 0 0 32 113 1 : tunables 120 60 8 : sl0
jffs2_raw_inode 0 0 80 48 1 : tunables 120 60 8 : sl0
jffs2_raw_dirent 0 0 48 78 1 : tunables 120 60 8 : sl0
jffs2_full_dnode 0 0 16 203 1 : tunables 120 60 8 : sl0
jffs2_i 0 0 368 10 1 : tunables 54 27 8 : sl0
squashfs_inode_cache 130 130 384 10 1 : tunables 54 27 8 :0
inotify_event_private_data 0 0 16 203 1 : tunables 120 60 0
inotify_inode_mark 0 0 80 48 1 : tunables 120 60 8 : s0
dio 0 0 336 11 1 : tunables 54 27 8 : sl0
fasync_cache 0 0 32 113 1 : tunables 120 60 8 : sl0
posix_timers_cache 0 0 112 35 1 : tunables 120 60 8 : s0
uid_cache 0 0 48 78 1 : tunables 120 60 8 : sl0
UNIX 7 16 496 8 1 : tunables 54 27 8 : sl0
ip_mrt_cache 0 0 96 40 1 : tunables 120 60 8 : sl0
UDP-Lite 0 0 560 7 1 : tunables 54 27 8 : sl0
tcp_bind_bucket 3 113 32 113 1 : tunables 120 60 8 : sl0
inet_peer_cache 0 0 160 24 1 : tunables 120 60 8 : sl0
secpath_cache 0 0 32 113 1 : tunables 120 60 8 : sl0
xfrm_dst_cache 0 0 256 15 1 : tunables 120 60 8 : sl0
ip_fib_trie 3 113 32 113 1 : tunables 120 60 8 : sl0
.
biangbiangmian, did you manage to fix your VR2600? I have done something similar to you and incorrectly flashed my VR2600. It looks like need to reflash mine also. Did you manage to find a full oem dump?
Thanks
Al
No, I am still in need of a full dump
I have a VR2600V on the way, so I can provide you with a dump next week.
BTW, you can recover the bootloader by flashing it using external SPI programmer like CH341A.
You can find the binary in GPL, or compile it from source.
Yes, btw I have a SPI programmer
Ok, Will upload mine then.
You completely wiped your flash or just bootloader?
Thanks! I definitely erased the bootloader, and whatever else in the process of erasing whatever was between these two memory addresses
So basically you deleted almost everything.
Ok, will upload a full dump
Hey, any luck getting the full dump?