Watchguard AP327X || Arista O-105E Support

Hi and thanks in advance for your time.

I have a Watchguard AP327X Datasheet and it licence is expired internally is the same as the Arista O-105E Datasheet
OpenWrt dosnt support it yet bit it does support the GL-S1300 Hardware Data That is the same procesor but with a diferentet flash size. Im on the way to trying to upload it but i cant acces the U-Boot, I have open the AP and sucsefuly connected the serial port i have attach bellow the serial output. I found the SERIAL FLASH MEMORY Winbond 25Q256JVFQ Datasheet and try to short pins 7 and 8 as this has work in the past with other AP but it dint work.

Do you have any sugestion on how to Acces this U-Boot so i can flash it with the awesome OpenWrt?

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.1.1-00118
S - IMAGE_VARIANT_STRING=DAABANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x00000021
S - Reset status Config, 0x00000000
S - Core 0 Frequency, 0 MHz
B -       261 - PBL, Start
B -      1338 - bootable_media_detect_entry, Start
B -      1678 - bootable_media_detect_success, Start
B -      1692 - elf_loader_entry, Start
B -      5069 - auth_hash_seg_entry, Start
B -      7211 - auth_hash_seg_exit, Start
B -    577090 - elf_segs_hash_verify_entry, Start
B -    694537 - PBL, End
B -    694561 - SBL1, Start
B -    785632 - pm_device_init, Start
D -         7 - pm_device_init, Delta
B -    787078 - boot_flash_init, Start
D -     52830 - boot_flash_init, Delta
B -    844046 - boot_config_data_table_init, Start
D -      3833 - boot_config_data_table_init, Delta - (419 Bytes)
B -    851255 - clock_init, Start
D -      7586 - clock_init, Delta
B -    863315 - CDT version:2,Platform ID:8,Major ID:1,Minor ID:0,Subtype:1
B -    866729 - sbl1_ddr_set_params, Start
B -    871827 - cpr_init, Start
D -         2 - cpr_init, Delta
B -    876210 - Pre_DDR_clock_init, Start
D -         4 - Pre_DDR_clock_init, Delta
D -     13177 - sbl1_ddr_set_params, Delta
B -    889531 - pm_driver_init, Start
D -         2 - pm_driver_init, Delta
B -    960879 - sbl1_wait_for_ddr_training, Start
D -        27 - sbl1_wait_for_ddr_training, Delta
B -    977201 - Image Load, Start
D -    152038 - QSEE Image Loaded, Delta - (297240 Bytes)
B -   1129673 - Image Load, Start
D -      1447 - SEC Image Loaded, Delta - (2048 Bytes)
B -   1140011 - Image Load, Start
D -    202003 - APPSBL Image Loaded, Delta - (412592 Bytes)
B -   1342412 - QSEE Execution, Start
D -        60 - QSEE Execution, Delta
B -   1348629 - SBL1, End
D -    656178 - SBL1, Delta
S - Flash Throughput, 2004 KB/s  (712299 Bytes,  355274 us)
S - DDR Frequency, 672 MHz


U-Boot 2012.07-00007-gb67340d4-dirty [local,local] (May 20 2019 - 13:53:18)

WP9333 U-Boot v0.0.4 (May 20 2019 - 13:53:24)

smem ram ptable found: ver: 1 len: 3
DRAM:  512 MiB
machid : 0x8010001
NAND:  ID = 9580f12c
Vendor = 2c
Device = f1
ONFI device found
SF: Detected W25Q256 with page size 64 KiB, total 32 MiB
ipq_spi: page_size: 0x100, sector_size: 0x10000, size: 0x2000000
160 MiB
In:    serial
Out:   serial
Err:   serial
machid: 8010001
flash_type: 0
Net:   MAC0 addr:0:90:7f:13:5:df
PHY ID1: 0x4d
PHY ID2: 0xd0b1
ipq40xx_ess_sw_init done
eth0
GPIO settings
SF: Detected W25Q256 with page size 64 KiB, total 32 MiB

## Checking Image at 84000000 ...
   FIT image found
   FIT description: ARM OpenWrt FIT (Flattened Image Tree)
    Image 0 (kernel@1)
     Description:  ARM OpenWrt Linux-3.14
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x840000e0
     Data Size:    3218192 Bytes = 3.1 MiB
     Architecture: ARM
     OS:           Linux
     Load Address: 0x80208000
     Entry Point:  0x80208000
     Hash algo:    crc32
     Hash value:   6fb836f9
     Hash algo:    sha1
     Hash value:   f2068860f73a0dea09f3a9781e2bdaed79b632fd
    Image 1 (fdt@1)
     Description:  ARM OpenWrt qcom-ipq40xx-ap.dk04.1-c1 device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x84311d34
     Data Size:    37442 Bytes = 36.6 KiB
     Architecture: ARM
     Hash algo:    crc32
     Hash value:   271fc801
     Hash algo:    sha1
     Hash value:   2280d5e275a571004ba105b870d9df8d6ae07aaa
    Default Configuration: 'config@1'
    Configuration 0 (config@1)
     Description:  OpenWrt
     Kernel:       kernel@1
     FDT:          fdt@1
## Checking hash(es) for FIT Image at 84000000 ...
   Hash(es) for Image 0 (kernel@1): crc32+ sha1+
   Hash(es) for Image 1 (fdt@1): crc32+ sha1+
Saving Environment to NAND...
Erasing Nand...
Erasing at 0x160000 -- 100% complete.
Writing to Nand... done
## Booting kernel from FIT Image at 84000000 ...
   Using 'config@1' configuration
   Trying 'kernel@1' kernel subimage
     Description:  ARM OpenWrt Linux-3.14
     Type:         Kernel Image
     Compression:  gzip compressed
     Data Start:   0x840000e0
     Data Size:    3218192 Bytes = 3.1 MiB
     Architecture: ARM
     OS:           Linux
     Load Address: 0x80208000
     Entry Point:  0x80208000
     Hash algo:    crc32
     Hash value:   6fb836f9
     Hash algo:    sha1
     Hash value:   f2068860f73a0dea09f3a9781e2bdaed79b632fd
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Flattened Device Tree from FIT Image at 84000000
   Using 'config@1' configuration
   Trying 'fdt@1' FDT blob subimage
     Description:  ARM OpenWrt qcom-ipq40xx-ap.dk04.1-c1 device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x84311d34
     Data Size:    37442 Bytes = 36.6 KiB
     Architecture: ARM
     Hash algo:    crc32
     Hash value:   271fc801
     Hash algo:    sha1
     Hash value:   2280d5e275a571004ba105b870d9df8d6ae07aaa
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x84311d34
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 86ff3000, end 86fff241 ... OK
Using machid 0x8010001 from environment

Starting kernel ...

[    0.000000] Booting Linux on physical CPU 0x0
[    0.000000] CPU: ARMv7 Processor [410fc075] revision 5 (ARMv7), cr=10c5387d
[    0.000000] CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
[    0.000000] Machine model: Qualcomm Technologies, Inc. IPQ40xx/AP-DK04.1-C1
[    0.000000] Memory policy: Data cache writealloc
[    0.000000] PERCPU: Embedded 8 pages/cpu @dfbc7000 s8256 r8192 d16320 u32768
[    0.000000] Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 125952
[    0.000000] Kernel command line: console=ttyMSM0,115200n8 ubi.mtd=rootfs root=mtd:ubi_rootfs rootfstype=squashfs rootwait pri=0 clk_ignore_unused
[    0.000000] PID hash table entries: 2048 (order: 1, 8192 bytes)
[    0.000000] Dentry cache hash table entries: 65536 (order: 6, 262144 bytes)
[    0.000000] Inode-cache hash table entries: 32768 (order: 5, 131072 bytes)
[    0.000000] Memory: 496000K/507904K available (4396K kernel code, 390K rwdata, 1520K rodata, 184K init, 624K bss, 11904K reserved, 0K highmem)
[    0.000000] Virtual kernel memory layout:
[    0.000000]     vector  : 0xffff0000 - 0xffff1000   (   4 kB)
[    0.000000]     fixmap  : 0xfff00000 - 0xfffe0000   ( 896 kB)
[    0.000000]     vmalloc : 0xe0800000 - 0xff000000   ( 488 MB)
[    0.000000]     lowmem  : 0xc0000000 - 0xe0000000   ( 512 MB)
[    0.000000]     pkmap   : 0xbfe00000 - 0xc0000000   (   2 MB)
[    0.000000]     modules : 0xbf000000 - 0xbfe00000   (  14 MB)
[    0.000000]       .text : 0xc0208000 - 0xc07cf530   (5918 kB)
[    0.000000]       .init : 0xc07d0000 - 0xc07fe040   ( 185 kB)
[    0.000000]       .data : 0xc0800000 - 0xc0861b44   ( 391 kB)
[    0.000000]        .bss : 0xc0861b44 - 0xc08fdbb0   ( 625 kB)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=4, Nodes=1
[    0.000000] Preemptible hierarchical RCU implementation.
[    0.000000] NR_IRQS:16 nr_irqs:16 16
[    0.000000] Architected cp15 timer(s) running at 48.00MHz (virt).
[    0.000011] sched_clock: 56 bits at 48MHz, resolution 20ns, wraps every 2863311552512ns
[    0.000020] Switching to timer-based delay loop
[    0.000329] Calibrating delay loop (skipped), value calculated using timer frequency.. 96.00 BogoMIPS (lpj=480000)
[    0.000348] pid_max: default: 32768 minimum: 301
[    0.000629] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
[    0.000642] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
[    0.012312] CPU: Testing write buffer coherency: ok
[    0.012672] CPU0: thread -1, cpu 0, socket 0, mpidr 80000000
[    0.012745] Setting up static identity map for 0x80213078 - 0x802130d0
[    0.090629] CPU1: Booted secondary processor
[    0.090675] CPU1: thread -1, cpu 1, socket 0, mpidr 80000001
[    0.110624] CPU2: Booted secondary processor
[    0.110660] CPU2: thread -1, cpu 2, socket 0, mpidr 80000002
[    0.130662] CPU3: Booted secondary processor
[    0.130699] CPU3: thread -1, cpu 3, socket 0, mpidr 80000003
[    0.130840] Brought up 4 CPUs
[    0.130880] SMP: Total of 4 processors activated (384.00 BogoMIPS).
[    0.130888] CPU: All CPU(s) started in SVC mode.
[    0.141324] VFP support v0.3: implementor 41 architecture 2 part 30 variant 7 rev 5
[    0.141699] pinctrl core: initialized pinctrl subsystem
[    0.142132] regulator-dummy: no parameters
[    0.142822] NET: Registered protocol family 16
[    0.144396] DMA: preallocated 2048 KiB pool for atomic coherent allocations
[    0.144951] cpuidle: using governor ladder
[    0.144963] cpuidle: using governor menu
[    0.154951] hw-breakpoint: Debug register access (0xee003e17) caused undefined instruction on CPU 2
[    0.154960] hw-breakpoint: Debug register access (0xee003e17) caused undefined instruction on CPU 3
[    0.154967] hw-breakpoint: Debug register access (0xee003e17) caused undefined instruction on CPU 1
[    0.154971] hw-breakpoint: CPU 3 failed to disable vector catch
[    0.155004] hw-breakpoint: Debug register access (0xee003e17) caused undefined instruction on CPU 0
[    0.155090]
[    0.155090] Version Rollback Feature Disabled
[    0.158532] i2c-msm-v2 78b7000.i2c: probing driver i2c-msm-v2
[    0.160004] sps:sps is ready.
[    0.165048] bio: create slab <bio-0> at 0
[    0.166837] SD0 VccQ: 1800 <--> 3000 mV
[    0.167342] SCSI subsystem initialized
[    0.167933] msm_bus_fabric_init_driver
[    0.168106] msm_bus_device 580000.ad-hoc-bus: Util-fact is missing, default to 100
[    0.168122] msm_bus_device 580000.ad-hoc-bus: Vrail-comp is missing, default to 100
[    0.168141] msm_bus_device 580000.ad-hoc-bus: Failed to get bus clk for bus4096 ctx1
[    0.168184] msm_bus_device 580000.ad-hoc-bus: Util-fact is missing, default to 100
[    0.168199] msm_bus_device 580000.ad-hoc-bus: Vrail-comp is missing, default to 100
[    0.168215] msm_bus_device 580000.ad-hoc-bus: Failed to get bus clk for bus1024 ctx1
[    0.194554] Bluetooth: Core ver 2.18
[    0.194627] NET: Registered protocol family 31
[    0.194637] Bluetooth: HCI device and connection manager initialized
[    0.194656] Bluetooth: HCI socket layer initialized
[    0.194672] Bluetooth: L2CAP socket layer initialized
[    0.194740] Bluetooth: SCO socket layer initialized
[    0.194941] 80000.qcom,pcie supply vreg-3.3 not found, using dummy regulator
[    0.195006] 80000.qcom,pcie supply vreg-1.8 not found, using dummy regulator
[    0.195065] 80000.qcom,pcie supply vreg-0.9 not found, using dummy regulator
[    0.195119] 80000.qcom,pcie supply gdsc-vdd not found, using dummy regulator
[    0.290480] msm_pcie_enable: msm_pcie_enable: PCIe: trigger the reset of endpoint of RC0.
[    0.300470] msm_pcie_enable: msm_pcie_enable: PCIe RC0 PHY is ready!
[    0.320470] msm_pcie_enable: msm_pcie_enable: PCIe: Release the reset of endpoint of RC0.
[    0.460609] msm_pcie_enable: msm_pcie_enable: RC0:No. 1:LTSSM_STATE:0x0
[    0.500660] msm_pcie_enable: msm_pcie_enable: RC0:No. 2:LTSSM_STATE:0x0
[    0.540711] msm_pcie_enable: msm_pcie_enable: RC0:No. 3:LTSSM_STATE:0x0
[    0.580761] msm_pcie_enable: msm_pcie_enable: RC0:No. 4:LTSSM_STATE:0x0
[    0.620812] msm_pcie_enable: msm_pcie_enable: RC0:No. 5:LTSSM_STATE:0x0
[    0.660862] msm_pcie_enable: msm_pcie_enable: PCIe: trigger the reset of endpoint of RC0.
[    0.660876] msm_pcie_enable: msm_pcie_enable: PCIe RC0 link initialization failed
[    0.660904] msm_pcie_enumerate: msm_pcie_enumerate: PCIe: failed to enable RC0.
[    0.660915] msm_pcie_probe: msm_pcie_probe: PCIe: RC0 is not enabled during bootup; it will be enumerated upon WAKE signal.
[    0.660926] msm_pcie_probe: msm_pcie_probe: PCIe: Driver probe failed for RC0:-1
[    0.661354] msm_pcie: probe of 80000.qcom,pcie failed with error -1
[    0.661608] Switched to clocksource arch_sys_counter
[    0.663539] NET: Registered protocol family 2
[    0.664890] TCP established hash table entries: 4096 (order: 2, 16384 bytes)
[    0.664963] TCP bind hash table entries: 4096 (order: 3, 32768 bytes)
[    0.665052] TCP: Hash tables configured (established 4096 bind 4096)
[    0.665107] TCP: reno registered
[    0.665122] UDP hash table entries: 256 (order: 1, 8192 bytes)
[    0.665155] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes)
[    0.665505] NET: Registered protocol family 1
[    0.666783] hw perfevents: enabled with ARMv7 Cortex-A7 PMU driver, 5 counters available
[    0.668212] futex hash table entries: 1024 (order: 4, 65536 bytes)
[    0.676114] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.676132] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.677033] msgmni has been set to 968
[    0.678722] Key type asymmetric registered
[    0.678738] Asymmetric key parser 'x509' registered
[    0.678776] io scheduler noop registered
[    0.678788] io scheduler deadline registered (default)
[    0.679561] MDSS QPIC HW Base phy_Address=0x7980000 virt=0xe0f80000
[    0.679583] mdss_qpic_pinctrl_init: cannot get default pinstate
[    0.679592] mdss_qpic_pinctrl_init: cannot get sleep pinstate
[    0.679668] mdss_qpic_panel_io_init: reset gpio not specified
[    0.679677] mdss_qpic_panel_io_init: cs gpio not specified
[    0.679685] mdss_qpic_panel_io_init: ad8 gpio not specified
[    0.679693] mdss_qpic_panel_io_init: te gpio not specified
[    0.679703] mdss_qpic_panel_io_init: bl gpio not specified
[    0.679720] 7980000.qcom,msm_qpic supply vdd not found, using dummy regulator
[    0.679792] 7980000.qcom,msm_qpic supply avdd not found, using dummy regulator
[    0.679840] msm_bus_cl_get_pdata failed
[    0.680127] mdss_qpic_panel_probe: Panel Name = qpic lcd panel
[    0.682937] mdss_fb_register: FrameBuffer[0] 800x480 registered successfully!
[    0.683604] tcsr 194b000.tcsr: setting usb hs phy mode select = e700e7
[    0.683670] tcsr 1953000.ess_tcsr: setting ess interface select = 0
[    0.683742] tcsr 1949000.tcsr: setting wifi_glb_cfg = 41000000
[    0.683800] tcsr 1957000.tcsr: setting wifi_noc_memtype_m0_m2 = 2222222
[    0.684517] Serial: 8250/16550 driver, 2 ports, IRQ sharing disabled
[    0.685611] msm_serial_hsl_probe: detected port #0 (ttyMSM0)
[    0.685652] msm_serial_hsl_probe: Bus scaling is disabled
[    0.685814] 78af000.serial: ttyMSM0 at MMIO 0x78af000 (irq = 139, base_baud = 115200) is a MSM
[    0.685895] msm_hsl_console_setup: console setup on port #0
[    1.508238] console [ttyMSM0] enabled
[    1.512370] msm_serial_hsl_probe: detected port #1 (ttyMSM1)
[    1.517545] msm_serial_hsl_probe: Bus scaling is disabled
[    1.523078] 78b0000.serial: ttyMSM1 at MMIO 0x78b0000 (irq = 140, base_baud = 115200) is a MSM
[    1.532034] msm_serial_hsl_init: driver initialized
[    1.536795] msm_serial_hs module loaded
[    1.540535] qca_serial_hs module loaded
[    1.546003] sps: BAM device 0x07984000 is not registered yet.
[    1.550726] sps:BAM 0x07984000 is registered.
[    1.554930] msm_nand_bam_init: msm_nand_bam_init: BAM device registered: bam_handle 0xdeaeee00
[    1.563808] sps:BAM 0x07984000 (va:0xe0a60000) enabled: ver:0x19, number of pipes:7
[    1.571511] msm_nand_version_check: nand_major:1, nand_minor:4, qpic_major:1, qpic_minor:4
[    1.579915] msm_nand_flash_onfi_probe: Found an ONFI compliant device MT29F1G08ABAEAWP    ,
[    1.587894] msm_nand_scan: NAND Id: 0x9580f12c Buswidth: 8Bits Density: 128 MByte
[    1.595351] msm_nand_scan: pagesize: 2048 Erasesize: 131072 oobsize: 64 (in Bytes)
[    1.602899] msm_nand_scan: BCH ECC: 4 Bit
[    1.606890] msm_nand_scan: CFG0: 0x2a0408c0,      CFG1: 0x0804745c
[    1.606890]             RAWCFG0: 0x280420c0,   RAWCFG1: 0x0005045d
[    1.606890]           ECCBUFCFG: 0x00000203, ECCBCHCFG: 0x42040700
[    1.606890]      BAD BLOCK BYTE: 0x000001d1
[    1.629575] 2 ofpart partitions found on MTD device 7980000.qcom,nand
[    1.635975] Creating 2 MTD partitions on "7980000.qcom,nand":
[    1.641706] 0x000000000000-0x000004000000 : "rootfs"
[    1.730166] mtd: device 0 (rootfs) set to be root filesystem
[    1.735346] mtdsplit: no squashfs found in "rootfs"
[    1.740148] mtdsplit: no squashfs found in "7980000.qcom,nand"
[    1.745496] 0x000004000000-0x000008000000 : "rootfs2"
[    1.833962] msm_nand_probe: NANDc phys addr 0x7980000, BAM phys addr 0x7984000, BAM IRQ 133
[    1.841281] msm_nand_probe: Allocated DMA buffer at virt_addr 0xe0a7b000, phys_addr 0x9ecfc000
[    1.850715] sps: BAM device 0x07884000 is not registered yet.
[    1.855644] sps:BAM 0x07884000 is registered.
[    1.860830] sps:BAM 0x07884000 (va:0xe0fc0000) enabled: ver:0x19, number of pipes:12
[    1.868011] m25p80 spi0.0: found w25q256, expected n25q128a11
[    1.873665] m25p80 spi0.0: w25q256 (32768 Kbytes)
[    1.878183] 14 ofpart partitions found on MTD device spi0.0
[    1.883700] Creating 14 MTD partitions on "spi0.0":
[    1.888546] 0x000000000000-0x000000040000 : "0:SBL1"
[    1.894682] 0x000000040000-0x000000060000 : "0:MIBIB"
[    1.899818] 0x000000060000-0x0000000c0000 : "0:QSEE"
[    1.904897] 0x0000000c0000-0x0000000d0000 : "0:CDT"
[    1.909865] 0x0000000d0000-0x0000000e0000 : "0:DDRPARAMS"
[    1.915385] 0x0000000e0000-0x000000160000 : "0:APPSBL"
[    1.920624] 0x000000160000-0x000000170000 : "0:APPSBLENV"
[    1.926050] 0x000000170000-0x000000180000 : "0:ART"
[    1.930921] 0x000000180000-0x000000680000 : "0:HLOS"
[    1.935956] 0x000000680000-0x000000b80000 : "0:HLOS1"
[    1.941040] 0x000000b80000-0x000000f80000 : "0:UCONFIG"
[    1.946357] 0x000000f80000-0x000000f90000 : "PANIC"
[    1.951332] 0x000000f90000-0x000000fa0000 : "RESERVED:0"
[    1.956808] 0x000000fa0000-0x000002000000 : "RESERVED:1"
[    1.973656] libphy: ipq40xx_mdio: probed
[    1.980190] ipq40xx-mdio 90000.mdio: ipq40xx-mdio driver was registered
[    1.985873] i2c /dev entries driver
[    1.990303]
[    1.990303] qcom_wdt_scm_fill_log_dump_tlv:  paddr 80864c30 pbytes_addr 80869c40 panic_magic_no 80843a88
[    2.000909] Bluetooth: HCI UART driver ver 2.2
[    2.004677] Bluetooth: HCI H4 protocol initialized
[    2.009428] Bluetooth: HCI BCSP protocol initialized
[    2.016356] TCP: cubic registered
[    2.019307] NET: Registered protocol family 10
[    2.024240] NET: Registered protocol family 17
[    2.027752] Bridge firewalling registered
[    2.031802] Bluetooth: RFCOMM TTY layer initialized
[    2.036532] Bluetooth: RFCOMM socket layer initialized
[    2.041705] Bluetooth: RFCOMM ver 1.11
[    2.045373] Bluetooth: BNEP (Ethernet Emulation) ver 1.3
[    2.050657] Bluetooth: BNEP filters: protocol multicast
[    2.055906] Bluetooth: BNEP socket layer initialized
[    2.060814] Bluetooth: HIDP (Human Interface Emulation) ver 1.2
[    2.066743] Bluetooth: HIDP socket layer initialized
[    2.071679] 8021q: 802.1Q VLAN Support v1.8
[    2.075975] Registering SWP/SWPB emulation handler
[    2.081785] SD0 VccQ: disabling
[    2.083897] regulator-dummy: disabling
[    2.088054] UBI: attaching mtd0 to ubi0
[    2.690394] UBI: scanning is finished
[    2.706306] UBI: attached mtd0 (name "rootfs", size 64 MiB) to ubi0
[    2.711542] UBI: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
[    2.718346] UBI: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
[    2.725013] UBI: VID header offset: 2048 (aligned 2048), data offset: 4096
[    2.731869] UBI: good PEBs: 512, bad PEBs: 0, corrupted PEBs: 0
[    2.737758] UBI: user volume: 2, internal volumes: 1, max. volumes count: 128
[    2.744888] UBI: max/mean erase counter: 8/4, WL threshold: 4096, image sequence number: 184696233
[    2.753831] UBI: available PEBs: 0, total reserved PEBs: 512, PEBs reserved for bad PEB handling: 20
[    2.762967] UBI: background thread "ubi_bgt0d" started, PID 71
[    2.764894] drivers/rtc/hctosys.c: unable to open rtc device (rtc0)
[    2.768369] clk: Not disabling unused clocks
[    2.785149] VFS: Mounted root (squashfs filesystem) readonly on device 31:16.
[    2.791531] Freeing unused kernel memory: 184K (c07d0000 - c07fe000)
/etc/preinit PREINIT=
/etc/preinit PREINIT=1
preinit 2
Inside fs_init []
mount: mounting proc on /proc failed: Device or resource busy
mount: mounting sysfs on /sys failed: Device or resource busy
[    5.455179] random: readlink: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.468657] random: cut: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.482196] random: cut: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.494630] random: basename: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.506741] random: mknod: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.518704] random: readlink: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.532389] random: cut: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.545920] random: cut: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.558281] random: basename: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    5.570361] random: mknod: uninitialized urandom read (4 bytes read, 36 bits of entropy available)
[    6.731686] UBIFS: background thread "ubifs_bgt0_1" started, PID 829
[    6.791274] UBIFS: recovery needed
[    7.251636] UBIFS: recovery completed
[    7.254361] UBIFS: mounted UBI device 0, volume 1, name "ubi_rootfs_data"
[    7.261044] UBIFS: LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes
[    7.270181] UBIFS: FS size: 41775104 bytes (39 MiB, 329 LEBs), journal size 2031616 bytes (1 MiB, 16 LEBs)
[    7.279808] UBIFS: reserved for root: 1973141 bytes (1926 KiB)
[    7.285627] UBIFS: media format: w4/r0 (latest is w4/r0), UUID 5BA6FE39-0BE8-44F0-8423-EB30CDFE1157, small LPT model
[    7.436341] procd: - early -
[    7.438352] procd: - watchdog -
[    7.441437] procd: - watchdog -
[    7.444799] procd: - ubus -
[    7.606776] procd: - init -

 (none) armv7l #1 SMP PREEMPT Wed Nov 6 13:37:26 UTC 2019 (none)
(none) login: [    8.605181] jffs2: notice: (903) jffs2_build_xattr_subsystem: complete building xattr subsystem, 0 of xdatum (0 unchecked, 0 orphan) and 0 of xref (0 dead, 0 orphan) found.
FIPS mode:  [OFF]

 (none) armv7l #1 SMP PREEMPT Wed Nov 6 13:37:26 UTC 2019 (none)

After more troubleshooting I have manage to access U-Boot !!!! my question now is how to upload the firmware, I have work before with the instructions bellow but im worry if the diferen memory size is going to afect. should i change the command " tftpboot 0x81000000 <openwrt_initramfs-kernel_image_name>"?

Installation
1. Prepare TFTP server with OpenWrt initramfs-kernel image.
2. Connect to one of LAN ports.
3. Connect to serial port.
4. Power on the device and when prompted to stop autoboot, hit any key.
5. Adjust "ipaddr" and "serverip" addresses in U-Boot environment, use
   'setenv' to do that, then run following commands:
    tftpboot 0x81000000 <openwrt_initramfs-kernel_image_name>
    bootm 0x81000000
6. Wait about 1 minute for OpenWrt to boot.

the way i manage to acces U-boot is by shorting Reset and GND one second after power up.
image

do not short pins on the flash chip, this is very risky and foolish

can you please give us the FCC ID, so we can see what the board looks like

Here are the pictures the flash chip is the one under the white cable with a yellow dot (by de manufacture)
Imgur
Imgur
Imgur

show the uboot environment with printenv

it is possible that you have trouble accessing uboot because bootdelay = 0

try holding a key like enter instead of shorting pins on flash

Here is the printenv I've try with holding enter and other keys and nothing. Thanks four your time.

ba0=console=ttyMSM0,115200n8 ubi.mtd=rootfs root=mtd:ubi_rootfs rootfstype=squashfs
ba1=console=ttyMSM0,115200n8 ubi.mtd=rootfs2 root=mtd:ubi_rootfs rootfstype=squashfs
baudrate=115200
bootargs=console=ttyMSM0,115200n8 ubi.mtd=rootfs root=mtd:ubi_rootfs rootfstype=squashfs
bootcmd=run ubootscript
bootdelay=2
bootkernel=if test ${pri} != ${last_pri}; then if test ${pri} = 0; then setenv bootargs ${ba0}; else setenv bootargs ${ba1}; fi; setenv last_pri ${pri}; saveenv; fi; bootipq;
check_retries_dothings=if test ${rp} = 0; then setenv sr 0; run switch_pri_and_reset; else run dec_retries; saveenv; run bootkernel; fi;
dec_retries=if test ${rp} = 3; then setenv rp 2; elif test ${rp} = 2; then setenv rp 1; else setenv rp 0; fi;
ethact=eth0
fdt_high=0x87000000
flash_type=0
ipaddr=192.168.1.11
kernel=0x180000
kernel_size=0x500000
last_pri=0
machid=8010001
mtdids=nand1=nand1
mtdparts=mtdparts=nand1:
pri=0
ps=0
restore_config=0
rp=1
sr=1
stderr=serial
stdin=serial
stdout=serial
switch_pri_and_reset=if test ${pri} = 0; then setenv pri 1; else setenv pri 0; fi; setenv ps 1; saveenv; reset;
ubootscript=if test ${pri} = 0; then setenv kernel 0x180000; else setenv kernel 0x680000; fi; sf probe; sf read 0x84000000 ${kernel} ${kernel_size}; iminfo; if test $? = 0; then if test ${sr} = 0; then setenv sr 1; setenv rp 3; saveenv;run bootkernel; else run check_retries_dothings; fi; else run switch_pri_and_reset; fi;

Environment size: 1478/65532 bytes
(IPQ40xx) #

Here are some more pictures with detail on the chips.
Imgur
Imgur

it looks like kernel and rootfs uses NAND
(you labeled in picture as "Memory ?")

can you access shell after it boots?

kernel log?

This is what i got after the boot.

[config]$ help
-----------------------------------------
Help for Sensor Config Shell Commands
-----------------------------------------
Get Commands:
get mode                : Displays the mode in which the device is currently configured
get time                : Displays Device Time
get ip config           : Displays IP information
get serial num          : Displays Board Number
get version             : Displays Version and Build information of all components
get link aggregation   : Displays Link Aggregation information
get acct delay info             : Displays client MACs and corresponding seconds remaining for their accounting stop to be sent
get visible client info: Displays Visible Client information
get vlan gateway mapping : Displays VLAN and Gateway Mapping
get interface           : Displays Network Interface speed and mode
get presence notification parameters        : Displays presence notification feature parameters
get ap                  : Displays all currently visible APs
get log                 : Displays log information as it is created
get rf                  : Displays if RF monitoring for Sensor is ON or OFF
get status              : Displays current running status of all components
get server discovery    : Displays Server discovery/setting information
get vlan config         : Displays vlan information (set info and dynamic info)
get vlan id             : Displays vlan IDs seen by ND
get vlan status         : Displays vlan status information
get proxy server        : Displays proxy server information
get network status      : Displays running status of network profiles
get vlan vni mapping    : Displays vlan to vni mapping for ssid profiles
get network vlan status : Displays IP setting of vlans on remote end point
get vlan connectivity   : Performs ping on particular vlan other than communication vlan
get client logs         : Get client connections logs as it happens
get log config          : Displays the configuration of the logger
get power source                : Displays source of power
get model               : Displays model of the Sensor
get ap status           : Displays wireless profiles and associated clients.
get client role info    : Displays clients role information.
get antenna             : Displays antenna configuration (Internal/ External)
get wired trace   : Performs packet capture on ethernet interface (eth0) upto file size 5MB
get route               : Displays IP routing table entries
get registration key    : Displays device's registration information
get device config       : Gets the device configuration.
get auto tpc config             : Displays current Auto TPC configuration.
get admctl stats                : Displays admission control related statistics.
 feature.pc logs                : Get recent logs (last 5 cycles) for acs or tpc--More--
-----------------------------------------

Set Commands:
set erase               : Sets the erase character to ^H
set interface           : Sets Network Interface speed and mode.
set ip config           : Runs through the current VLAN and IP config wizard
set vlan config         : Sets multiple VLAN monitoring to ON or OFF
set server discovery    : Sets Server discovery information
set proxy server                : Sets proxy server information
set mode                : Sets the mode to Sensor,Network Detector or Sentry
set ipv6 config    : Sets IPv6 network settings.
 to authenticate andssphrase            : Sets the passphrase used by the sensor--More--
                                          communicate with the server
henticate and ion key                   : Sets the key used by the sensor to aut--More--
                                          communicate with the server
ult valuenication key default           : Sets the communication key to its defa--More--
me interval and server ip addressers            : Sets the rssi threshold and ti--More--
set local mode          : Sets the device in Local CLI mode
set server mode : Sets the device in Remote Management mode
-----------------------------------------

Other Commands:
exit                    : Exits the Sensor config shell session
help                    : Displays help for all commands
help set                : Displays help for 'set' commands
help get                : Displays help for 'get' commands
help other              : Displays help for 'other' commands
passwd                  : Changes the config shell password
ping6                   : Ping a IPv6 host Usage: ping6 <ipv6_address/host_name>
ing 192.168.1.246       : Ping a host. Usage: ping <ip_address/host_name> e.g. p--More--
top                     : Displays the CPU and memory status
reboot                  : Reboots the Sensor
restart                 : Restarts the Sensor application
reset factory           : Resets Sensor to 'out of the box' status
upgrade                 : Upgrades the Sensor manually from a given IP address
presence notification enable    : Enable the presence notification feature
presence notification disable   : Disable the presence notification feature
sigma enable    : Enable the sigma certification feature
sigma disable   : Disable the sigma certification feature
bangradar   : Simulates radar detected event
2 command of sigma  : Send QOS MAP SET to station mac address given in ap_set_hs--More--
-----------------------------------------
[config]$ get log config
Default log level : 4

No specific log level is set for the any of the features. They
will use the default log level applicable at the time of logging.

[config]$