niceboygithub / AqaraM1SM2fw

Aqara Gateway M1S (ZHWG15LM) , P3(KTBL12LM), H1(QBCZWG11LM), M2 (ZHWG12LM) Firmwares
168 stars 30 forks source link

Stuck at "Downloading the flasher." #30

Closed wr closed 2 years ago

wr commented 2 years ago

Have an M2 hub (stock firmware) and trying to flash 3.3.9_0013.0616_modified.bin using aqaragateway.exe

It shows a progress bar for "Downloading the flasher" (and TX lights up on the TTY USB) but once the progress bar fills up it hangs.

Do NOT power up your gateway.
IF it is already power up, remove power cable!

Generating padded firmware, please wait...!
Please power up gateway!
If your gateway is powered up, disconnect usb cable and reconnect it.
Downloading the flasher.
omgseb commented 2 years ago

+1, same issue here. US M2 hub, stuck at "downloading the flasher".

niceboygithub commented 2 years ago

I did not have US M2 hub to try. Right now, it only support CN M2 hub.

Nismonx commented 2 years ago

same issue with rootfs_3.4.0_0004.0616_modified.bin on EU model

Nismonx commented 2 years ago

log from putty after manual restart:

uart ok strap:0x412b8ae2 enable spi-nand ROM ver:v1.21, sig:866c151, time:2016.11.04-11:26+0800, CPU(400 MHz), DDR2(533 M Hz)

No recognized ID, rdid=0x00a1e47f init IP fail(0xffffffff) init ddr ok img sig ok chksum ok load img ok s-boot sec sig ok decrypt img jump 0xa0000000

SPI Nand ID=0000a1e4 SPI Nand die chipsize=0x08000000 byte SPI Nand dienum=1, SPI Nand blocksize=0x00020000 byte, SPI Nand pagesize=0x00000800 byte, SPI Nand oobsize=0x00000040 byte, [rtkn_scan_bbt, line 1812], RBA=51, this->RBA_PERCENT = 5,block_v2r_num=1024 [rtkn_scan_bbt, line 1822] block_v2r_num 00000400

INFO: Stored BBT in Die 0: block=8 , block_status_p1=0x000000bb load bbt v2r table:0 page:512 rtk_scan_v2r_bbt have created v2r bbt table:0 on block 8, just loads it !! check v2r bbt table:0 OK [rtk_nand_scan_bbt, line 393] mem_page_num=1 bbt_page 704 INFO: Stored BBT in Die 0: block=11 , block_status_p1=0x000000bb load bbt table:0 page:704 [rtk_nand_scan_bbt] have created bbt table:0 on block 11, just loads it !! check bbt table:0 OK [dump_BBT] Nand BBT Content Congratulation!! No BBs in this Nand. Realtek Crypto Engine v0.1 =>CPU Wake-up interrupt happen! GISR=09000084

---Realtek RTL8197F boot code at 2021.05.13-10:48+0800 v3.4T-pre2.2 (993MHz) Info: Load boot_info success! == RTL8197 Aqara Gateway bootloader == boot_info: ver:0 kernel: newest:1, curr:1 rootfs: newest:1, curr:1 kernel[0]: sum:0x8062, size:2233412, fail:0 [1]: sum:0x8016, size:2233412, fail:0 rootfs[0]: sum:0xf2be, size:9719876, fail:0 [1]: sum:0xee7c, size:9723972, fail:0 root_sum_check: off watchdog_time: 0 boot_version: 1.0.0_0001 boot_magic: 0000917c priv mode Info: loading kernel 1 ... size 2233412 Info: checking kernel 1 ... Success! Info: loading rootfs 1 ... Done Info: checking rootfs 1 ... Info: checking rootfs 1 ... rootfs check Success Info: select rootfs 1 cmdline:root=/dev/mtdblock7 console=ttyS0,38400 Info: booting... Jump to image start=0x80a00000... decompressing kernel: Uncompressing Linux... done, booting the kernel. done decompressing kernel. start address: 0x804e4f10 [ 0.000000] Linux version 3.10.90 (liaozhaobao@compilex64-ipg) (gcc version 4.9.4 20151028 (prerelease) (Realtek MSDK-4.9.4p1 Build 2648) ) #42 Fri Mar 25 11:28:14 CST 2022 [ 0.000000] bootconsole [early0] enabled [ 0.000000] CPU revision is: 00019385 (MIPS 24Kc) [ 0.000000] Determined physical RAM map: [ 0.000000] memory: 04000000 @ 00000000 (usable) [ 0.000000] Zone ranges: [ 0.000000] Normal [mem 0x00000000-0x03ffffff] [ 0.000000] Movable zone start for each node [ 0.000000] Early memory node ranges [ 0.000000] node 0: [mem 0x00000000-0x03ffffff] [ 0.000000] Primary instruction cache 64kB, VIPT, 4-way, linesize 32 bytes. [ 0.000000] Primary data cache 32kB, 4-way, PIPT, no aliases, linesize 32 bytes [ 0.000000] Built 1 zonelists in Zone order, mobility grouping off. Total pages: 4088 [ 0.000000] Kernel command line: root=/dev/mtdblock7 console=ttyS0,38400 [ 0.000000] PID hash table entries: 256 (order: -4, 1024 bytes) [ 0.000000] Dentry cache hash table entries: 8192 (order: 1, 32768 bytes) [ 0.000000] Inode-cache hash table entries: 4096 (order: 0, 16384 bytes) [ 0.000000] Writing ErrCtl register=0005e008 [ 0.000000] Readback ErrCtl register=0005e008 [ 0.000000] Memory: 57488k/65536k available (5043k kernel code, 8048k reserved, 1243k data, 240k init, 0k highmem) [ 0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1 [ 0.000000] NR_IRQS:192 [ 0.000000] Realtek GPIO IRQ init [ 0.000000] Calibrating delay loop... 660.68 BogoMIPS (lpj=3303424) [ 0.070000] pid_max: default: 32768 minimum: 301 [ 0.080000] Mount-cache hash table entries: 2048 [ 0.090000] NET: Registered protocol family 16 [ 0.100000] <<<<>>>> [ 0.120000] Do MDIO_RESET [ 0.150000] 40MHz [ 0.510000] PCIE -> Cannot LinkUP [ 0.520000] INFO: initializing USB devices ... [ 0.570000] enable port 0 two port enable [ 0.730000] patch new usb phy para for 40M OSC [ 1.270000] Realtek GPIO controller driver init [ 1.280000] INFO: initializing i2c devices ... [ 1.290000] INFO: registering sheipa spi device [ 1.310000] bio: create slab at 0 [ 1.320000] SCSI subsystem initialized [ 1.330000] INFO: sheipa spi driver register [ 1.340000] INFO: sheipa spi probe [ 1.350000] usbcore: registered new interface driver usbfs [ 1.360000] usbcore: registered new interface driver hub [ 1.370000] usbcore: registered new device driver usb [ 1.380000] Advanced Linux Sound Architecture Driver Initialized. [ 1.390000] cfg80211: Calling CRDA to update world regulatory domain [ 1.400000] Switching to clocksource MIPS [ 1.410000] NET: Registered protocol family 2 [ 1.420000] TCP established hash table entries: 2048 (order: 0, 16384 bytes) [ 1.440000] TCP bind hash table entries: 2048 (order: -1, 8192 bytes) [ 1.460000] TCP: Hash tables configured (established 2048 bind 2048) [ 1.480000] TCP: reno registered [ 1.490000] UDP hash table entries: 1024 (order: 0, 16384 bytes) [ 1.510000] UDP-Lite hash table entries: 1024 (order: 0, 16384 bytes) [ 1.530000] NET: Registered protocol family 1 [ 1.550000] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 1.570000] exFAT: Version 1.2.9 [ 1.580000] NTFS driver 2.1.30 [Flags: R/O]. [ 1.590000] msgmni has been set to 112 [ 1.610000] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 254) [ 1.630000] io scheduler noop registered (default) [ 1.640000] pwm_probe [ 1.770000] Serial: 8250/16550 driver, 3 ports, IRQ sharing disabled [ 1.800000] console [ttyS0] enabled, bootconsole disabled7) is a 16550A [ 1.800000] console [ttyS0] enabled, bootconsole disabled [ 1.840000] serial8250: ttyS1 at MMIO 0x18147400 (irq = 5) is a 16550A [ 1.860000] serial8250: ttyS2 at MMIO 0x18147800 (irq = 47) is a 16550A [ 1.880000] Realtek GPIO Driver for Flash Reload Default [ 1.900000] id_chain value=a1e47f9f [ 1.910000] id_chain value=a1e47f9f [ 1.920000] NAND device: Manufacturer ID: 0xa1, Chip ID: 0xe4 (Unknown FM_RDID_FM25S01A 1G SPI NAND), 128MiB, page size: 2048, OOB size: 64 [ 1.950000] [rtkn_scan_bbt, line 1812], RBA=51, this->RBA_PERCENT = 5,block_v2r_num=1024 [ 1.980000] [rtkn_scan_bbt, line 1822] block_v2r_num 400

[ 2.030000] INFO: Stored BBT in Die 0: block=8 , block_status_p1=0xbb [ 2.040000] load bbt v2r table:0 page:512 rtk_scan_v2r_bbt have created v2r bbt table:0 on block 8, just loads it !! check v2r bbt table:0 OK [rtk_nand_scan_bbt, line 393] mem_page_num=1 bbt_page 704 [ 2.110000] INFO: Stored BBT in Die 0: block=11 , block_status_p1=0xbb [ 2.130000] load bbt table:0 page:704 [rtk_nand_scan_bbt] have created bbt table:0 on block 11, just loads it !! check bbt table:0 OK [dump_BBT] Nand BBT Content [ 2.170000] Congratulation!! No BBs in this Nand. [ 2.190000] 9 rtkxxpart partitions found on MTD device rtk_nand [ 2.210000] Creating 9 MTD partitions on "rtk_nand": [ 2.220000] 0x000000000000-0x0000000a0000 : "bootloader" [ 2.240000] 0x0000000a0000-0x0000000e0000 : "boot_info" [ 2.260000] 0x0000000e0000-0x000000120000 : "factory" [ 2.270000] 0x000000120000-0x000000200000 : "bbt" [ 2.290000] 0x000000200000-0x000000500000 : "linux_1" [ 2.300000] 0x000000500000-0x000001500000 : "rootfs_1" [ 2.320000] 0x000001500000-0x000001800000 : "linux_2" [ 2.340000] 0x000001800000-0x000002800000 : "rootfs_2" [ 2.350000] 0x000002800000-0x000007320000 : "data" [ 2.370000] Realtek WLAN driver - version 1.7 (2015-10-30)(SVN:Unversioned directory) [ 2.390000] Adaptivity function - version 9.3.4 [ 2.410000] Device Name = RTKWiFi0 [ 2.420000] VIF_NUM=9 [ 2.430000] MACHAL_version_init [ 2.440000] RFE TYPE =0 [ 2.450000] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver [ 2.460000] rtl819x-ehci rtl819x-ehci: Realtek rtl819x On-Chip EHCI Host Controller [ 2.490000] rtl819x-ehci rtl819x-ehci: new USB bus registered, assigned bus number 1 [ 2.540000] rtl819x-ehci rtl819x-ehci: irq 21, io mem 0x18021000 [ 2.570000] rtl819x-ehci rtl819x-ehci: USB 2.0 started, EHCI 1.00 [ 2.580000] hub 1-0:1.0: USB hub found [ 2.600000] hub 1-0:1.0: 2 ports detected [ 2.610000] usbcore: registered new interface driver usb-storage [ 2.630000] lumi_btn_probe reset btn=7 [ 2.640000] input: lumi_key as /devices/virtual/input/input0 [ 2.660000] i2c /dev entries driver [ 2.670000] usbcore: registered new interface driver usbhid [ 2.690000] usbhid: USB HID core driver [ 2.700000] soc-audio soc-audio: ASoC: machine rtl819xd_rt5680 should use snd_soc_register_card() [ 2.730000] soc-audio soc-audio: snd-soc-dummy-dai <-> rtl819x-iis mapping ok [ 2.750000] TCP: cubic registered [ 2.760000] NET: Registered protocol family 10 [ 2.780000] sit: IPv6 over IPv4 tunneling driver [ 2.790000] NET: Registered protocol family 17 [ 2.800000] Key type dns_resolver registered [ 2.820000] [ 2.820000] Probing RTL819X NIC-kenel stack size order[0]... [ 3.510000] eth0 added. vid=9 Member port 0x110... [ 3.530000] eth1 added. vid=8 Member port 0x0... [ 3.550000] ALSA device list: [ 3.560000] #0: rtl819xd_rt5680 [ 3.570000] VFS: Mounted root (squashfs filesystem) readonly on device 31:7. [ 3.600000] Freeing unused kernel memory: 240K (80624000 - 80660000) init started: BusyBox v1.22.1 (2021-05-12 15:41:14 CST) Try attaching UBI(0,0) on MTD8 and mounting in [/data]. [ 4.510000] UBI: attaching mtd8 to ubi0 [ 6.400000] UBI: scanning is finished [ 6.440000] UBI warning: print_rsvd_warning: cannot reserve enough PEBs for bad PEB handling, reserved 18, need 20 [ 6.480000] UBI: attached mtd8 (name "data", size 75 MiB) to ubi0 [ 6.490000] UBI: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes [ 6.510000] UBI: min./max. I/O unit sizes: 2048/2048, sub-page size 2048 [ 6.530000] UBI: VID header offset: 2048 (aligned 2048), data offset: 4096 [ 6.550000] UBI: good PEBs: 601, bad PEBs: 0, corrupted PEBs: 0 [ 6.570000] UBI: user volume: 1, internal volumes: 1, max. volumes count: 128 [ 6.590000] UBI: max/mean erase counter: 48/15, WL threshold: 4096, image sequence number: 737251932 [ 6.620000] UBI: available PEBs: 0, total reserved PEBs: 601, PEBs reserved for bad PEB handling: 18 [ 6.660000] UBI: background thread "ubi_bgt0d" started, PID 883 UBI device number 0, total 601 LEBs (76312576 bytes, 72.8 MiB), available 0 LEBs (0 bytes), LEB size 126976 bytes (124.0 KiB) [ 6.900000] UBIFS: parse sync [ 7.010000] UBIFS: background thread "ubifs_bgt0_0" started, PID 891 [ 7.120000] UBIFS: recovery needed [ 7.710000] UBIFS: recovery completed [ 7.730000] UBIFS: mounted UBI device 0, volume 0, name "app" [ 7.740000] UBIFS: LEB size: 126976 bytes (124 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes [ 7.770000] UBIFS: FS size: 69709824 bytes (66 MiB, 549 LEBs), journal size 9023488 bytes (8 MiB, 72 LEBs) [ 7.800000] UBIFS: reserved for root: 0 bytes (0 KiB) [ 7.810000] UBIFS: media format: w4/r0 (latest is w4/r0), UUID 3F9D6A6F-1428-41C3-9434-74CB792DDB47, small LPT model Mount UBIFS successfully! [ 7.980000] WlanSupportAbility = 0x3 [ 7.990000] [ODM_software_init] [ 7.990000] [97F] Bonding Type 97FS, PKG1 [ 7.990000] [97F] RFE type 0 PHY paratemters: DEFAULT [ 7.990000] clock 40MHz [ 7.990000] load efuse ok [ 7.990000] rom_progress: 0x200006f [ 7.990000] rom_progress: 0x400006f [ 8.060000] [GetHwReg88XX][PHY_REG_PG_8197Fmp_Type0] size [ 8.080000] [GetHwReg88XX][PHY_REG_PG_8197Fmp_Type0] [ 8.300000] [GetHwReg88XX][rtl8197Ffw] [ 8.310000] [GetHwReg88XX][rtl8197Ffw size] [ 8.760000] [97F] Default BB Swing=30 fw_manager.sh revision: 2 pre-revision: 2

hostname: Aqara-Hub-M2-00EC type: lumi.gateway.iragl7, model: AH_M2_BLE Jan 1 00:00:09 mDNSResponder: mDNSResponder (Engineering Build) (May 12 2021 15:43:36) starting Jan 1 00:00:09 mDNSResponder: Unable to parse DNS server list. Unicast DNS-SD unavailable Jan 1 00:00:09 mDNSResponder: mDNSPlatformSourceAddrForDest: connect 1.1.1.1 failed errno 128 (Network is unreachable) Jan 1 00:00:09 mDNSResponder: WARNING: mdnsd continuing as root because user "nobody" does not exist [ 9.660000] store_tty0_enable buf=disable [ 9.660000] , count=8 [ 14.710000] genirq: Flags mismatch irq 79. 00000083 (gpiolib) vs. 00000082 (wps btn) [ 16.370000] WlanSupportAbility = 0x3 [ 16.390000] [ODM_software_init] [ 16.390000] [97F] Bonding Type 97FS, PKG1 [ 16.390000] [97F] RFE type 0 PHY paratemters: DEFAULT [ 16.390000] clock 40MHz [ 16.390000] load efuse ok [ 16.390000] rom_progress: 0x200006f [ 16.390000] rom_progress: 0x400006f [ 16.460000] [GetHwReg88XX][PHY_REG_PG_8197Fmp_Type0] size [ 16.480000] [GetHwReg88XX][PHY_REG_PG_8197Fmp_Type0] [ 16.690000] [GetHwReg88XX][rtl8197Ffw] [ 16.700000] [GetHwReg88XX][rtl8197Ffw size] [ 17.150000] [97F] Default BB Swing=30

Nismonx commented 2 years ago

I've hooked up a virtual com splitter to capture this:

strap:0x412b8ae2 enable spi-nand ROM ver:v1.21, sig:866c151, time:2016.11.04-11:26+0800, CPU(400 MHz), DDR2(533 M Hz) console

uuuuu Unknown cmd dbgmsg 3 dbg level:0x00000003 ri 0 1 1 load efuse ok rom:0x0200006d 0xb8000780: 0x00028e8f 0xb8000784: 0x00000000 0xb8000788: 0x00000000 0xb800078c: 0x00000000 0xb8000790: 0x00000000 0xb8000794: 0x00000000 0xb8000798: 0x00000000 0xb800079c: 0x00000000 0xb80007a0: 0x00000000 0xb80007a4: 0x00000000 0xb80007a8: 0xb139f925 0xb80007ac: 0x773c16bf 0xb80007b0: 0x2c83da67 0xb80007b4: 0x380c40c6 0xb80007b8: 0x2e00a4dd 0xb80007bc: 0xd27fbd02 0xb80007c0: 0x3ee4c655 0xb80007c4: 0x0f2b545c 0xb80007c8: 0xdc3d6617 0xb80007cc: 0x4a473292 0xb80007d0: 0x00000000 0xb80007d4: 0x00000000 0xb80007d8: 0xb537693b 0xb80007dc: 0x02706064 0xb80007e0: 0xb0feac56 0xb80007e4: 0x8c86b3c3 0xb80007e8: 0x171a3a85 0xb80007ec: 0xd106623c 0xb80007f0: 0x02000103 0xb80007f4: 0x9cb63a2f 0xb80007f8: 0x00000005 0xb80007fc: 0x00000000 loc:0x00000220,offset:0x00000044,word_enb:0x0000000e loc:0x00000220,init_dev:0x00000002 0x220 02 00 00 00 00 00 00 00 read eFuse 0x005 byte ctr: 0x00 ctr2: 0x00 ctr3: 0x00 ctr4: 0x00 exec sram: 0x00000000 boot adr: 0x00000000 img off: 0x00000000 dev: 0x00000002 hp adr: 0x00000000 hp len: 0x00000000 er st adr: 0x00000000 rom:0x0400006d ss_init_rxi310 ms_ctrl_0_map=0xb8142000 bond:0x0000000a MCM 64/32MB dram_init_clk_frequency ,ddr_freq=1066 (Mbps), 533 (MHZ) mck_ck=7, 1112 dev_map=0xb8142000 dram_info=0x9fe03e08 dfi_rate=2,dram_period=3752 SDR D1 dram_info-> dev-> device_type=2 ,cr_twr=3 DDR2 dram_info-> dev-> device_type=2 DDR2 dram_info-> mode_reg-> bst_len=0 SDR dq_width=2 SDR page=3 SDR dram_info-> dev-> bank =1 cr_bst_len =0 SDR dfi_rate=2 SDR dq_width=2 ddr_type =2 SDR cas_rd /(dfi_rate)=3 SDR cas_wr /(dfi_rate) =3 SDR dev_map-> dcr =0x00000222 SDR dev_map-> iocr=0x00204000 dev_map-> emr1=0x00000040 dev_map-> mr=0x00000672 SDR dev_map-> drr=0x0912be35 SDR dev_map-> tpr0=0x000066c4 SDR dev_map-> tpr1=0x002a9104 SDR dev_map-> tpr2=0x00000042 DRAM init disable DRAM init enable DRAM init is done , jump to DRAM enable DRAM ODT SDR init done dev_map=0xb8142000 Enter dram_auto_size_detect_rxi310, page_size = 3, bank_size = 1 DDR2 dram_info-> mode_reg-> bst_len=0 Detect page_size = 2KB (3) Detect bank_size = 4 banks(0x00000001) Detect dram size = 64MB (0x04000000) dram_init.c dram_K_turn_on_odt dram test start dram_addr_rot test rotate 0 0xa0400100 passed rotate 4 0xa0400100 passed rotate 8 0xa0400100 passed rotate 12 0xa0400100 passed rotate 16 0xa0400100 passed rotate 20 0xa0400100 passed rotate 24 0xa0400100 passed rotate 28 0xa0400100 passed dram_addr_rot done start dram_com_addr_rot test ~rotate 0 0xa0400100 passed ~rotate 4 0xa0400100 passed ~rotate 8 0xa0400100 passed ~rotate 12 0xa0400100 passed ~rotate 16 0xa0400100 passed ~rotate 20 0xa0400100 passed ~rotate 24 0xa0400100 passed ~rotate 28 0xa0400100 passed dram_com_addr_rot done start dram_byte_access test pattern[0](0x01234567) 0xa0400100 pass pattern[1](0xfedcba98) 0xa0400100 pass pattern[2](0xa5a5a5a5) 0xa0400100 pass pattern[3](0x5a5a5a5a) 0xa0400100 pass pattern[4](0x5a5aa5a5) 0xa0400100 pass pattern[5](0xa5a55a5a) 0xa0400100 pass dram_byte_access done start dram_half_word_access test pattern[0](0x01234567) 0xa0400100 pass pattern[1](0xfedcba98) 0xa0400100 pass pattern[2](0xa5a5a5a5) 0xa0400100 pass pattern[3](0x5a5a5a5a) 0xa0400100 pass pattern[4](0x5a5aa5a5) 0xa0400100 pass pattern[5](0xa5a55a5a) 0xa0400100 pass dram_half_word_access done start dram_walking_of_1 test pattern[0](0x00000001) 0xa0400100 passed pattern[1](0x00000002) 0xa0400100 passed pattern[2](0x00000004) 0xa0400100 passed pattern[3](0x00000008) 0xa0400100 passed pattern[4](0x00000010) 0xa0400100 passed pattern[5](0x00000020) 0xa0400100 passed pattern[6](0x00000040) 0xa0400100 passed pattern[7](0x00000080) 0xa0400100 passed pattern[8](0x00000100) 0xa0400100 passed pattern[9](0x00000200) 0xa0400100 passed pattern[10](0x00000400) 0xa0400100 passed pattern[11](0x00000800) 0xa0400100 passed pattern[12](0x00001000) 0xa0400100 passed pattern[13](0x00002000) 0xa0400100 passed pattern[14](0x00004000) 0xa0400100 passed pattern[15](0x00008000) 0xa0400100 passed pattern[16](0x00010000) 0xa0400100 passed pattern[17](0x00020000) 0xa0400100 passed pattern[18](0x00040000) 0xa0400100 passed pattern[19](0x00080000) 0xa0400100 passed pattern[20](0x00100000) 0xa0400100 passed pattern[21](0x00200000) 0xa0400100 passed pattern[22](0x00400000) 0xa0400100 passed pattern[23](0x00800000) 0xa0400100 passed pattern[24](0x01000000) 0xa0400100 passed pattern[25](0x02000000) 0xa0400100 passed pattern[26](0x04000000) 0xa0400100 passed pattern[27](0x08000000) 0xa0400100 passed pattern[28](0x10000000) 0xa0400100 passed pattern[29](0x20000000) 0xa0400100 passed pattern[30](0x40000000) 0xa0400100 passed pattern[31](0x80000000) 0xa0400100 passed dram_walking_of_1 done start dram_walking_of_0 test pattern[0](0xfffffffe) 0xa0400100 passed pattern[1](0xfffffffd) 0xa0400100 passed pattern[2](0xfffffffb) 0xa0400100 passed pattern[3](0xfffffff7) 0xa0400100 passed pattern[4](0xffffffef) 0xa0400100 passed pattern[5](0xffffffdf) 0xa0400100 passed pattern[6](0xffffffbf) 0xa0400100 passed pattern[7](0xffffff7f) 0xa0400100 passed pattern[8](0xfffffeff) 0xa0400100 passed pattern[9](0xfffffdff) 0xa0400100 passed pattern[10](0xfffffbff) 0xa0400100 passed pattern[11](0xfffff7ff) 0xa0400100 passed pattern[12](0xffffefff) 0xa0400100 passed pattern[13](0xffffdfff) 0xa0400100 passed pattern[14](0xffffbfff) 0xa0400100 passed pattern[15](0xffff7fff) 0xa0400100 passed pattern[16](0xfffeffff) 0xa0400100 passed pattern[17](0xfffdffff) 0xa0400100 passed pattern[18](0xfffbffff) 0xa0400100 passed pattern[19](0xfff7ffff) 0xa0400100 passed pattern[20](0xffefffff) 0xa0400100 passed pattern[21](0xffdfffff) 0xa0400100 passed pattern[22](0xffbfffff) 0xa0400100 passed pattern[23](0xff7fffff) 0xa0400100 passed pattern[24](0xfeffffff) 0xa0400100 passed pattern[25](0xfdffffff) 0xa0400100 passed pattern[26](0xfbffffff) 0xa0400100 passed pattern[27](0xf7ffffff) 0xa0400100 passed pattern[28](0xefffffff) 0xa0400100 passed pattern[29](0xdfffffff) 0xa0400100 passed pattern[30](0xbfffffff) 0xa0400100 passed pattern[31](0x7fffffff) 0xa0400100 passed dram_walking_of_0 done start memcpy_test test memcpy 0 0xa0400100 passed memcpy 4 0xa0400100 passed memcpy 8 0xa0400100 passed memcpy 12 0xa0400100 passed memcpy 16 0xa0400100 passed memcpy 20 0xa0400100 passed memcpy 24 0xa0400100 passed memcpy 28 0xa0400100 passed memcpy_test done init ddr ok rom:0x0800006d xmrx 0xa0000000 recv ok len:0x0001ce80 j a0000000 Jump to 0xA0000000 ۼ▒%▒m$)▒<)4z▒)▒▒▒6▒▒;y▒▒((▒▒▒Xഖ,▒▒▒(l▒ۼ▒%▒m$)▒<+4z▒)▒▒ then when "downloading the flasher" bar is done, nothing happens and get the above artefact. this is as far I can log things.
niceboygithub commented 2 years ago

do not flash customize fw to EU version. The fw of EU version is signed. If you flash customized fw to gateway, it will become brick.

Nismonx commented 2 years ago

@niceboygithub, thanks for the heads up. I genuinely thought it would be fine.