|
小黄鱼上花190买了块砖,没有超级密码,闲鱼也找不到人查,尝试各种方法,回想以前玩路由器的时候有TTL线刷的方法,于是拆机研究,发现有预留,但是没有针,于是自己焊上,然后用putty也能跑码,然后就没然后了,应该也是限制了,真的要变砖了,有没有大神能研究一下线刷固件降级啊?
下面是读出来的数据
SPI NAND
start read bootloader
secure boot
CBC decrypt OK!
CBC decrypt OK!
verify OK!
Jump
enter bootloader...
pll init, cpu freq=1100
crpm init ok
product_vid == 91,ddrsize == 0x20000000
ddr4 init, rate=2133Mbps
ddr4 init done
Calibration pull UP: 0xa
Calibration pull DOWN: 0x1e
ddr init ok
SPI NAND
ncfg:111013
0,40,b,800
secure uboot
verify OK!
backup header!!
Jump
U-Boot 2016.01-rc3 (May 13 2023 - 13:20:18 +0800)
CPU : ZX279132@A53,1100MHZ
Board: ZTE zx279132evb
I2C: ready
DRAM: 496 MiB
el=3
product_vid = 91
vid=91-G7615
mtk reset,66
boot_ctrl value=====3
bootsel=3
NAND: spifc pin mux config ok!!!
bootsel=3
manuid=c9,52
found flash: SPI NAND HYF2GQ4UAACAE 256MiB 3,3V
HY SPI NAND HYF2GQ4UAACAE 256MiB 3,3V
256 MiB, MLC, erase size: 128 KiB, page size: 2048, OOB size: 64
256 MiB
<nand_read_skip_bad_,1199>!mtdpart=0x1,offset=0x0,mtdpartoffset=0x280000,mtdPartsize=0x80000,length=0x20000
In: serial
Out: serial
Err: serial
Net: No ethernet found.
rx data disable
mdio_miiphy_initialize
addr 0x15600018 before value is 1f0000
addr 0x15600018 after value is 1f0000
addr 0x15600018 after value is 1f01ff
AN1_pll_lock_finish
mode_10g_epon_nsyn_fifo_cfg
top soft reset =0x313
com_pll_lock_ready
rx los =0 rx data in
switch security version start...
sec mode!
### main_loop entered: bootdelay=1
Hit any key to stop autoboot: 0
rx data disable
zboot info init done!
skip bad block...addr=0x1000000
skip bad block...addr=0x4140000
select=0x0
<nand_read_skip_bad_,1199>!mtdpart=0x6,offset=0x0,mtdpartoffset=0x300000,mtdPartsize=0x200000,length=0x1000
tmp=0x00000000, value=0
select=0x0
search=0x2
search->result[0].entry=1700240,offset=240
<nand_read_skip_bad_,1199>!mtdpart=0x2,offset=0x0,mtdpartoffset=0x1700000,mtdPartsize=0x3000000,length=0x28e0000
verify vmlinuz success!!
RSA Verify OK
decry kernel...
start 1700000-4700000
addrstart=1be0000,jffsoffset=4e0000
<nand_read_skip_bad_,1199>!mtdpart=0x0,offset=0x140000,mtdpartoffset=0x0,mtdPartsize=0x280000,length=0x140000
crc check ok : 38146d2b 38146d2b
find flash patch cpy:9ef80000 87c00000 40 2c080
<nand_read_skip_bad_,1199>!mtdpart=0x0,offset=0x0,mtdpartoffset=0x0,mtdPartsize=0x280000,length=0x280000
lseek=0x8c092d80
cmdline=U-Boot V2.0.0P1N22 20230513134504
kernel start step1..images->state:70f
==BOOTM_STATE_START:1
==BOOTM_STATE_FINDOS:2
## Loading kernel from FIT Image at 88000240 ...
Using 'conf@132SG' configuration
Trying 'kernel@A53' kernel subimage
Description: Unify(TODO) Linux kernel for project-131G
Type: Kernel Image
Compression: gzip compressed
Data Start: 0x88000348
Data Size: 5016716 Bytes = 4.8 MiB
Architecture: AArch64
OS: Linux
Load Address: 0x80080000
Entry Point: 0x80080000
Verifying Hash Integrity ... OK
==BOOTM_STATE_FINDOTHER:4
## Loading fdt from FIT Image at 88000240 ...
Using 'conf@132SG' configuration
Trying 'fdt@132SG' fdt subimage
Description: Flattened Device Tree blob for project-132SG
Type: Flat Device Tree
Compression: uncompressed
Data Start: 0x884c90c0
Data Size: 35757 Bytes = 34.9 KiB
Architecture: AArch64
Verifying Hash Integrity ... OK
Booting using the fdt blob at 0x884c90c0
==BOOTM_STATE_LOADOS:8
Uncompressing Kernel Image ... OK
kernel start step6..
Loading Device Tree to 0000000083ff4000, end 0000000083fffba0 ... OK
Starting kernel ...
first spin
first spin
first spin
first spin
CPUID:0 cpunoline 1 nucpus 4 try wake up secondary cpu from rom.
CPUID:1 wake up from rom.
CPUID:2 wake up from rom.
CPUID:3 wake up from rom.
init psci ok!!
cpu 1 power on
cpu 1 has been powered on
cpu 2 power on
cpu 2 has been powered on
cpu 3 power on
cpu 3 has been powered on
|
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有账号?立即注册
×
|