roleoroleo / yi-hack-MStar

Custom firmware for Yi 1080p camera based on MStar platform
GNU General Public License v3.0
830 stars 110 forks source link

4FUS #23

Closed enrysan0 closed 4 years ago

enrysan0 commented 4 years ago

Hi,

Do you plan to port this hack to 4FUS (FW:4.2.0.0H_201909041620)? It is the Amazon version claimed as YI Camera 1080p version 3 (in Europe). Here is an image of the camera disassembled: https://media.discordapp.net/attachments/531894543759441935/635156208332046336/Yi_Home_1080p_v.3_4FUS.jpg?width=1082&height=596

Thanks

roleoroleo commented 4 years ago

I don't know this camera. If you want, I could check if it's the same platform. But you have to dump a log as described here: https://github.com/roleoroleo/yi-hack-6FUS_4.5.0/issues/10

enrysan0 commented 4 years ago

Thanks for the answer roleoroleo. I don't have a "rs232/usb adapter" at the moment. However as soon as i have a bit of time I'll try to dump the log.

enrysan0 commented 4 years ago

Here is the dump:

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2019.11.09 10:35:21 =~=~=~=~=~=~=~=~=~=~=~=
渇¸‡
IPL gd156225
D-01.

HW Reset
64MB

BIST0_0001-OK

[SDMMC] NO SD!
[NOR]
offset:00010000

size:7fc8 chks:5551a134 ok

IPL_CUST gbf16da4

MXP found at 0x00020000

[SDMMC] NO SD!
  decomp_size=0x00041314

-----------------------U-Boot 2015.01 (Apr 28 2018 - 17:08:00)-----------------------

Version: I3ge2accce
DEVINFO: 313E
[WDT] Enalbe WATCHDOG 60s
       Watchdog enabled
I2C:   ready
DRAM:  64 MiB
WARNING: Caches not enabled
MMC:   MStar SD/MMC: 0
nor_flash_mxp allocated success!!
MXIC REMS: 0xC2,0x17
Flash is detected (0x0509, 0xC2, 0x20, 0x18)
SF: Detected nor0 with total size 16 MiB
MXP found at mxp_offset[1]=0x00020000, size=0x1000
env_offset=0x4F000 env_size=0x1000
MXIC REMS: 0xC2,0x17
Flash is detected (0x0509, 0xC2, 0x20, 0x18)
SF: Detected nor0 with total size 16 MiB
In:    serial
Out:   serial
Err:   serial
Net:   No ethernet found.

+++++++++++++++++++   check one.bin    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 one.bin 
_[sdmmc_0] Card Detect Fail! 
** Bad device mmc 0 **
    one.bin Not exist(fatsize err) 

+++++++++++++++++++   check one_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 one_y25 
_[sdmmc_0] Card Detect Fail! 
** Bad device mmc 0 **
    one_y25 Not exist(fatsize err) 

+++++++++++++++++++   check uboot_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 uboot_y25 
_[sdmmc_0] Card Detect Fail! 
** Bad device mmc 0 **
    uboot_y25 Not exist(fatsize err) 

+++++++++++++++++++   check kernel_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 kernel_y25 
_[sdmmc_0] Card Detect Fail! 
** Bad device mmc 0 **
    kernel_y25 Not exist(fatsize err) 

+++++++++++++++++++   check sys_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 sys_y25 
_[sdmmc_0] Card Detect Fail! 
** Bad device mmc 0 **
    sys_y25 Not exist(fatsize err) 

+++++++++++++++++++   check home_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 home_y25 
_[sdmmc_0] Card Detect Fail! 
** Bad device mmc 0 **
    home_y25 Not exist(fatsize err) 
[NetUpgrade] ts_1st=0x163
No ethernet found.
[NetUpgrade] ==== NetLoop(NETUPGRADE) return fail ====!
net_upgrade - do net update from the specified file that is in tftpserver

Usage:
net_upgrade     -  

MXIC REMS: 0xC2,0x17
Flash is detected (0x0509, 0xC2, 0x20, 0x18)
SF: Detected nor0 with total size 16 MiB
SF: 2162688 bytes @ 0x50000 Read: OK
##  Booting kernel from Legacy Image at 21000000 ...
   Image Name:   MVX2##I3ge2accceKL_LX318####[BR:
   Image Type:   ARM Linux Kernel Image (lzma compressed)
   Data Size:    1457444 Bytes = 1.4 MiB
   Load Address: 20008000
   Entry Point:  20008000
   Verifying Checksum ... OK
   Uncompressing Kernel Image ... 
[XZ] !!!reserved 0x21000000 length=0x 1000000 for xz!!
   XZ: uncompressed size=0x3ce1e0, ret=7
OK
ERR: Can't find KIMG header and initrd address, 0x00000000
atags:0x20000000

Starting kernel ...

Booting Linux on physical CPU 0x0
Linux version 3.18.30 (zhengqianbin@ubuntu) (gcc version 4.8.3 20140401 (prerelease) (crosstool-NG linaro-1.13.1-4.8-2014.04 - Linaro GCC 4.8-2014.04) ) #2 PREEMPT Sat Apr 28 17:11:02 HKT 2018
CPU: ARMv7 Processor [410fc075] revision 5 (ARMv7), cr=10c53c7d
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
early_atags_to_fdt() success
Machine model: INFINITY3 MSC000A-S03A-64M
Reserved memory: created CMA memory pool at 0x22a00000, size 22 MiB
Reserved memory: initialized node cma0, compatible id shared-dma-pool
Memory policy: Data cache writeback
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 16256
Kernel command line: console=ttyS0,115200n8r androidboot.console=ttyS0 root=/dev/mtdblock2 rw rootfstype=jffs2 noinitrd init=/init
PID hash table entries: 256 (order: -2, 1024 bytes)
Dentry cache hash table entries: 8192 (order: 3, 32768 bytes)
Inode-cache hash table entries: 4096 (order: 2, 16384 bytes)
Memory: 38176K/65536K available (2646K kernel code, 224K rwdata, 904K rodata, 120K init, 117K bss, 27360K reserved)
Virtual kernel memory layout:
    vector  : 0xffff0000 - 0xffff1000   (   4 kB)
    fixmap  : 0xffc00000 - 0xffe00000   (2048 kB)
    vmalloc : 0xc4800000 - 0xff000000   ( 936 MB)
    lowmem  : 0xc0000000 - 0xc4000000   (  64 MB)
    modules : 0xbf000000 - 0xc0000000   (  16 MB)
      .text : 0xc0008000 - 0xc037fb20   (3551 kB)
      .init : 0xc0380000 - 0xc039e000   ( 120 kB)
      .data : 0xc039e000 - 0xc03d61e0   ( 225 kB)
       .bss : 0xc03d61e0 - 0xc03f36b0   ( 118 kB)
SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
Preemptible hierarchical RCU implementation.
    Dump stacks of tasks blocking RCU-preempt GP.
NR_IRQS:16 nr_irqs:16 16
Find CLK_cpupll_clk, hook ms_cpuclk_ops
[ms_cpuclk_init] get dvfs gpio  vid_1
Architected cp15 timer(s) running at 6.00MHz (virt).
sched_clock: 56 bits at 6MHz, resolution 166ns, wraps every 2863311527936ns
Switching to timer-based delay loop, resolution 166ns
console [ttyS0] enabled
Calibrating delay loop (skipped), value calculated using timer frequency.. 12.00 BogoMIPS (lpj=60000)
pid_max: default: 4096 minimum: 301
Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
CPU: Testing write buffer coherency: ok
Setting up static identity map for 0x20281a40 - 0x20281a74
VFP support v0.3: implementor 41 architecture 2 part 30 variant 7 rev 5
NET: Registered protocol family 16
DMA: preallocated 256 KiB pool for atomic coherent allocations

Version : MVX2##I3ge2accceKL_LX318####[BR:y25_prj]#XVM

GPIO: probe end
MSYS:  INIT DONE. TICK=0x01659AA8
Advanced Linux Sound Architecture Driver Initialized.
Switched to clocksource arch_sys_counter
NET: Registered protocol family 2
TCP established hash table entries: 1024 (order: 0, 4096 bytes)
TCP bind hash table entries: 1024 (order: 2, 20480 bytes)
TCP: Hash tables configured (established 1024 bind 1024)
TCP: reno registered
UDP hash table entries: 128 (order: 0, 6144 bytes)
UDP-Lite hash table entries: 128 (order: 0, 6144 bytes)
NET: Registered protocol family 1
futex hash table entries: 16 (order: -4, 448 bytes)
jffs2: version 2.2. © 2001-2006 Red Hat, Inc.
msgmni has been set to 118
io scheduler noop registered
io scheduler deadline registered (default)
i2c /dev entries driver
[ms_uart_probe] uart port 0 use MUX_PM_UART
1f221000.uart0: ttyS0 at MMIO 0x0 (irq = 98, base_baud = 10750000) is a unknown
[ms_uart_probe] uart port 1 use MUX_UART1
1f221200.uart1: ttyS1 at MMIO 0x0 (irq = 99, base_baud = 10750000) is a unknown
URDMA rx_buf=0xC2A42000(phy:0x22A42000) tx_buf=0xC2A43000(phy:0x22A43000) size=0x1000
[ms_uart_probe] uart port 2 use MUX_UART0
1f220400.uart2: ttyS2 at MMIO 0x0 (irq = 112, base_baud = 10750000) is a unknown
infinity-audio soc:sound: ASoC: CODEC DAI infinity-codec-dai-main not registered
platform soc:sound: Driver infinity-audio requests probe deferral
infinity-audio infinity-codec: ASoC: CODEC DAI infinity-codec-dai-main not registered
platform infinity-codec: Driver infinity-audio requests probe deferral
netif_napi_add() called with weight 128 on device eth%d
MSYS: DMEM request: [EMAC_BUFF]:0x00002000
[EMAC]Init EMAC success! (add delay in reset)
[HVSP]u32Dropmode on/n
[VIP]gu32CMDQmode off/nMSYS: DMEM request: [VIP_CMDQ]:0x00004000
[SCL] SCL init success
mload_size = 35040
mload_virt_addr = c2a50000
mload_dma_addr = 0x22a50000
MSYS: DMEM request: [ISP_base]:0x0001B120
ShareData_Meminfo phyaddr:0x2224da00, viraddr:0xc224da00, len:0x38
AE Base: virt=0xC2A60000 size=0xB400
AWB Base: virt=0xC2A6B400 size=0x8700
AF Base: virt=0xC2A73B00 size=0xF0
HISTO Base: virt=0xC2A73BF0 size=0x2F0
MOT Base: virt=0xC2A73EE0 size=0x6E40
RGBIR Base: virt=0xC2A7AD20 size=0x400
[ISP] register driver success
[CSI] register driver successms_rtc 1f002400.rtc: rtc core: registered 1f002400.rtc as rtc0
[ms_rtc_probe]: rtc setup, frequency=12000000
[SAR] infinity_sar_probe 
MSYS: DMEM request: [BDMA_FSP_WBUFF]:0x00000100
[Ser flash] phys=0x22a46000, virt=0xc2a46000, bus=0x02a46000
[FSP] MXIC REMS: 0xC2,0x17
[FSP] Flash is detected (0x0509, 0xC2, 0x20, 0x18) ver1.1
[FSP] 1-1-2 DUAL_FAST_READ MODE
mtd .name = NOR_FLASH, .size = 0x01000000 (16MiB)
 .erasesize = 0x00010000 .numeraseregions = 0
MXP_PARTS!!
MXP found at mxp_offset[1]=0x00020000, size=0x1000
Creating 6 MTD partitions on "NOR_FLASH":
0x000000000000-0x000000050000 : "BOOT"
0x000000050000-0x0000001d0000 : "KERNEL"
0x0000001d0000-0x0000003b0000 : "ROOTFS"
0x0000003b0000-0x000000fe0000 : "HOME"
0x000000fe0000-0x000000ff0000 : "vd1"
0x000000ff0000-0x000001000000 : "conf"
[ms_cpufreq_init] cpu current clk=796917760
ms_pwm->pad_ctrl[0]=69
ms_pwm->pad_ctrl[1]=17
ms_pwm->pad_ctrl[2]=255
ms_pwm->pad_ctrl[3]=255
ms_pwm->pad_ctrl[4]=53
ms_pwm->pad_ctrl[5]=255
ms_pwm->pad_ctrl[6]=255
ms_pwm->pad_ctrl[7]=56
mstar-i3pwm 1f003400.pwm: probe successful
TCP: cubic registered
NET: Registered protocol family 17
MSYS: DMEM request: [pcmC0D0p]:0x00018000
MSYS: DMEM request: [pcmC0D0c]:0x00014000
infinity-audio soc:sound: infinity-codec-dai-main <-> infinity-cpu-dai mapping ok
ms_rtc 1f002400.rtc: setting system clock to 1970-01-01 00:00:00 UTC (0)
ALSA device list:
  #0: infinity_snd_machine
VFS: Mounted root (jffs2 filesystem) on device 31:2.
Freeing unused kernel memory: 120K (c0380000 - c039e000)
init: SERVICE: ueventd
init: SERVICE: rcs
[FB]Set 68
[DRVHVSP]Drv_HVSP_SetFbManageConfig(645):8000 
DNRR OFF
[FB]Set 57
[DRVHVSP]Drv_HVSP_SetFbManageConfig(645):100 
UNLOCK
[JPE, JpeProbe] set base=0xfd264000 irq=93, nClockRate=288000000
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
ehci_hcd: unknown parameter 'force_host' ignored
ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mstar_ehc_init version:20150512
Mstar-ehci-2 H.W init
Titania3_series_start_ehc start
enable USB function
[USB] config miu select [1] [ef] [ef] ][ef]
[USB] enable miu lower bound address subtraction
[USB] worring.... no platform_data
hcd->rsrc_start:0xfd286400
BC disable 
[USB] soc:Mstar-ehci-2 irq --> 119
soc:Mstar-ehci-2 soc:Mstar-ehci-2: EHCI Host Controller
soc:Mstar-ehci-2 soc:Mstar-ehci-2: new USB bus registered, assigned bus number 1
soc:Mstar-ehci-2 soc:Mstar-ehci-2: irq 119, io mem 0xfd286400
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 1 port detected
Mstar-ehci-1 H.W init
CHIP_FUNCTION SET. ID=4, param=1
Can't get power-enable-pad from DTS, set default GPIO(1)
[mstar_usb_vbus_control] Enable USB VBUS GPIO(81)
Titania3_series_start_ehc start
enable USB function
[USB] config miu select [1] [ef] [ef] ][ef]
[USB] enable miu lower bound address subtraction
[USB] worring.... no platform_data
hcd->rsrc_start:0xfd284800
BC disable 
[USB] soc:Mstar-ehci-1 irq --> 95
soc:Mstar-ehci-1 soc:Mstar-ehci-1: EHCI Host Controller
soc:Mstar-ehci-1 soc:Mstar-ehci-1: new USB bus registered, assigned bus number 2
soc:Mstar-ehci-1 soc:Mstar-ehci-1: irq 95, io mem 0xfd284800
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 1 port detected
>> [sdmmc] ms_sdmmc Driver Initializing... 
>> [sdmmc] ms_sdmmc_probe 
==20150512==> hub_port_init 1 #0
Plug in USB Port1
>> [sdmmc_0] Int CDZ use Ext GPIO IRQ: (151)
>> [sdmmc_0] Probe Platform Devices...(Ret:0) 
>> [sdmmc_0] Get CD => (0)
[Mstar GPIO] gpio(16) to irq(-1)
[USB] ERR, after reset no PE: port status 0xa
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #1
Plug in USB Port1
[USB] device has gone before bus reset
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #2
Plug in USB Port1
[USB] device has gone before bus reset
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #3
Plug in USB Port1
[USB] device has gone before bus reset
hub_port_disable: 1  hub->err: 0 
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #0
Plug in USB Port1
usb 2-1: new high-speed USB device number 6 using soc:Mstar-ehci-1
cryptodev: driver aesdmadev loaded.
MSYS: DMEM request: [AESDMA_ENG]:0x00001000
MSYS: DMEM request: [AESDMA_ENG1]:0x00001000
infinity_aes soc:aesdma: MSTAR AES engine enabled.
MSYS: DMEM request: [VSPL-I0P0B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P0B1]:0x0005A000
MSYS: DMEM request: [VSPL-I0P2B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P2B1]:0x0005A000
MSYS: DMEM request: [MS-00]:0x00357000
MSYS: DMEM request: [MS-01]:0x00357000
MSYS: DMEM request: [VENC-32]:0x000FF000
MSYS: DMEM request: [S0:VENCDMOUT]:0x0000A800
MSYS: DMEM request: [S0:VENCDMP0]:0x0007F800
MSYS: DMEM request: [S0:VENCDMP1]:0x0007F800
MSYS: DMEM request: [VSPL-I0P1B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P1B1]:0x0005A000
MSYS: DMEM request: [VENC-48]:0x00025800
MSYS: DMEM request: [S1:VENCDMOUT]:0x00005600
MSYS: DMEM request: [S1:VENCDMP0]:0x00056400
MSYS: DMEM request: [S1:VENCDMP1]:0x00056400
MSYS: DMEM request: [VENC-49]:0x00025800
MSYS: DMEM request: [S2:VENCDMOUT]:0x00005600
MSYS: DMEM request: [S2:VENCDMP0]:0x00056400
MSYS: DMEM request: [S2:VENCDMP1]:0x00056400
MSYS: DMEM request: [VSPL-I0P3B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P3B1]:0x0005A000
MSYS: DMEM request: [VENC-50]:0x00025800
MSYS: DMEM request: [S3:VENCDMOUT]:0x00005600
MSYS: DMEM request: [S3:VENCDMP0]:0x00056400
MSYS: DMEM request: [S3:VENCDMP1]:0x00056400
MSYS: DMEM request: [VENC-51]:0x00025800
MSYS: fix_dmem enabled
hue, spi0_dev = 0xc23db000 
init.sh (46): drop_caches: 3
cfg80211: Calling CRDA to update world regulatory domain
mtprealloc: module license 'unspecified' taints kernel.
Disabling lock debugging due to kernel taint
==>[0]:PreBuff:0xc1e2c000, DmaAddr:0x21e2c000
==>[1]:PreBuff:0xc1e3c000, DmaAddr:0x21e3c000
==>[2]:PreBuff:0xc23e4000, DmaAddr:0x223e4000
==>[3]:PreBuff:0xc23e8000, DmaAddr:0x223e8000
==>[4]:PreBuff:0xc23ec000, DmaAddr:0x223ec000
==>[5]:PreBuff:0xc23f0000, DmaAddr:0x223f0000
==>[6]:PreBuff:0xc23f4000, DmaAddr:0x223f4000
==>[7]:PreBuff:0xc23f8000, DmaAddr:0x223f8000
==>[8]:PreBuff:0xc23fc000, DmaAddr:0x223fc000
==>[9]:PreBuff:0xc1e40000, DmaAddr:0x21e40000
==>[10]:PreBuff:0xc1e44000, DmaAddr:0x21e44000
==>[11]:PreBuff:0xc1e48000, DmaAddr:0x21e48000
==>[12]:PreBuff:0xc1e4c000, DmaAddr:0x21e4c000
==>[13]:PreBuff:0xc1e50000, DmaAddr:0x21e50000
==>[14]:PreBuff:0xc1e54000, DmaAddr:0x21e54000
==>[15]:PreBuff:0xc1e58000, DmaAddr:0x21e58000
==>[16]:PreBuff:0xc1e5c000, DmaAddr:0x21e5c000
==>[17]:PreBuff:0xc1e60000, DmaAddr:0x21e60000
==>[18]:PreBuff:0xc1e64000, DmaAddr:0x21e64000
==>[19]:PreBuff:0xc1e68000, DmaAddr:0x21e68000
==>[20]:PreBuff:0xc1e6c000, DmaAddr:0x21e6c000
==>[21]:PreBuff:0xc1e70000, DmaAddr:0x21e70000
==>[22]:PreBuff:0xc1e74000, DmaAddr:0x21e74000
==>[23]:PreBuff:0xc1e78000, DmaAddr:0x21e78000
==>[24]:PreBuff:0xc1e7c000, DmaAddr:0x21e7c000
==>[25]:PreBuff:0xc1e80000, DmaAddr:0x21e80000
==>[26]:PreBuff:0xc1e84000, DmaAddr:0x21e84000
==>[27]:PreBuff:0xc1e88000, DmaAddr:0x21e88000
==>[28]:PreBuff:0xc1e8c000, DmaAddr:0x21e8c000
==>[29]:PreBuff:0xc1e90000, DmaAddr:0x21e90000
==>[30]:PreBuff:0xc1e94000, DmaAddr:0x21e94000
==>[31]:PreBuff:0xc1e98000, DmaAddr:0x21e98000
==>[32]:PreBuff:0xc1e9c000, DmaAddr:0x21e9c000
==>[33]:PreBuff:0xc1ea0000, DmaAddr:0x21ea0000
==>[34]:PreBuff:0xc1ea4000, DmaAddr:0x21ea4000
==>[35]:PreBuff:0xc1ea8000, DmaAddr:0x21ea8000
==>[36]:PreBuff:0xc1eac000, DmaAddr:0x21eac000
==>[37]:PreBuff:0xc1eb0000, DmaAddr:0x21eb0000
==>[38]:PreBuff:0xc1eb4000, DmaAddr:0x21eb4000
==>[39]:PreBuff:0xc1eb8000, DmaAddr:0x21eb8000
==>[40]:PreBuff:0xc1ebc000, DmaAddr:0x21ebc000
==>[41]:PreBuff:0xc1ec0000, DmaAddr:0x21ec0000
==>[42]:PreBuff:0xc1ec4000, DmaAddr:0x21ec4000
==>[43]:PreBuff:0xc1ec8000, DmaAddr:0x21ec8000
==>[44]:PreBuff:0xc1ecc000, DmaAddr:0x21ecc000
==>[45]:PreBuff:0xc1ed0000, DmaAddr:0x21ed0000
==>[46]:PreBuff:0xc1ed4000, DmaAddr:0x21ed4000
==>[47]:PreBuff:0xc1ed8000, DmaAddr:0x21ed8000
==>[48]:PreBuff:0xc1edc000, DmaAddr:0x21edc000
==>[49]:PreBuff:0xc1ee0000, DmaAddr:0x21ee0000
==>[50]:PreBuff:0xc1ee4000, DmaAddr:0x21ee4000
==>[51]:PreBuff:0xc1ee8000, DmaAddr:0x21ee8000
==>[52]:PreBuff:0xc1eec000, DmaAddr:0x21eec000
==>[53]:PreBuff:0xc1ef0000, DmaAddr:0x21ef0000
==>[54]:PreBuff:0xc1ef4000, DmaAddr:0x21ef4000
==>[55]:PreBuff:0xc1ef8000, DmaAddr:0x21ef8000
==>[56]:PreBuff:0xc1efc000, DmaAddr:0x21efc000
==>[57]:PreBuff:0xc1f00000, DmaAddr:0x21f00000
==>[58]:PreBuff:0xc1f04000, DmaAddr:0x21f04000
==>[59]:PreBuff:0xc1f08000, DmaAddr:0x21f08000
==>[60]:PreBuff:0xc1f0c000, DmaAddr:0x21f0c000
==>[61]:PreBuff:0xc1f10000, DmaAddr:0x21f10000
==>[62]:PreBuff:0xc1f14000, DmaAddr:0x21f14000
==>[63]:PreBuff:0xc1f18000, DmaAddr:0x21f18000
==>[64]:PreBuff:0xc1f1c000, DmaAddr:0x21f1c000
==>[65]:PreBuff:0xc1f20000, DmaAddr:0x21f20000
==>[66]:PreBuff:0xc1f24000, DmaAddr:0x21f24000
==>[67]:PreBuff:0xc1f28000, DmaAddr:0x21f28000
==>[68]:PreBuff:0xc1f2c000, DmaAddr:0x21f2c000
==>[69]:PreBuff:0xc1f30000, DmaAddr:0x21f30000
==>[70]:PreBuff:0xc2349000, DmaAddr:0x22349000
==>[71]:PreBuff:0xc234b000, DmaAddr:0x2234b000
==>[72]:PreBuff:0xc1f38000, DmaAddr:0x21f38000
==>[73]:PreBuff:0xc1f40000, DmaAddr:0x21f40000
==>[74]:PreBuff:0xc1f48000, DmaAddr:0x21f48000
==>[75]:PreBuff:0xc1f50000, DmaAddr:0x21f50000
==>[76]:PreBuff:0xc1f58000, DmaAddr:0x21f58000
==>[77]:PreBuff:0xc1f60000, DmaAddr:0x21f60000
==>[78]:PreBuff:0xc1f68000, DmaAddr:0x21f68000
==>[79]:PreBuff:0xc1f70000, DmaAddr:0x21f70000
==>[80]:PreBuff:0xc231bc00, DmaAddr:0x2231bc00
install prealloc ok
rtusb init rt2870 --->

=== pAd = c4a50000, size = 863344 ===

allocate tx ringidx 0 
RTMPQMemAddr[0]
allocate tx ringidx 1 
RTMPQMemAddr[1]
allocate tx ringidx 2 
RTMPQMemAddr[2]
allocate tx ringidx 3 
RTMPQMemAddr[3]
allocate tx ringidx 4 
RTMPQMemAddr[4]
allocate tx ringidx 5 
RTMPQMemAddr[5]
allocate tx ringidx 6 
RTMPQMemAddr[6]
allocate tx ringidx 7 
RTMPQMemAddr[7]
allocate tx ringidx 8 
RTMPQMemAddr[8]
allocate tx ringidx 9 
RTMPQMemAddr[9]
allocate tx ringidx 10 
RTMPQMemAddr[10]
allocate tx ringidx 11 
RTMPQMemAddr[11]
allocate tx ringidx 12 
RTMPQMemAddr[12]
allocate tx ringidx 13 
RTMPQMemAddr[13]
allocate tx ringidx 0 
RTMPQMemAddr[14]
allocate tx ringidx 1 
RTMPQMemAddr[15]
allocate tx ringidx 2 
RTMPQMemAddr[16]
allocate tx ringidx 3 
RTMPQMemAddr[17]
allocate tx ringidx 4 
RTMPQMemAddr[18]
allocate tx ringidx 5 
RTMPQMemAddr[19]
allocate tx ringidx 6 
RTMPQMemAddr[20]
allocate tx ringidx 7 
RTMPQMemAddr[21]
allocate tx ringidx 8 
RTMPQMemAddr[22]
allocate tx ringidx 9 
RTMPQMemAddr[23]
allocate tx ringidx 10 
RTMPQMemAddr[24]
allocate tx ringidx 11 
RTMPQMemAddr[25]
allocate tx ringidx 12 
RTMPQMemAddr[26]
allocate tx ringidx 13 
RTMPQMemAddr[27]
allocate tx ringidx 0 
RTMPQMemAddr[28]
allocate tx ringidx 1 
RTMPQMemAddr[29]
allocate tx ringidx 2 
RTMPQMemAddr[30]
allocate tx ringidx 3 
RTMPQMemAddr[31]
allocate tx ringidx 4 
RTMPQMemAddr[32]
allocate tx ringidx 5 
RTMPQMemAddr[33]
allocate tx ringidx 6 
RTMPQMemAddr[34]
allocate tx ringidx 7 
RTMPQMemAddr[35]
allocate tx ringidx 8 
RTMPQMemAddr[36]
allocate tx ringidx 9 
RTMPQMemAddr[37]
allocate tx ringidx 10 
RTMPQMemAddr[38]
allocate tx ringidx 11 
RTMPQMemAddr[39]
allocate tx ringidx 12 
RTMPQMemAddr[40]
allocate tx ringidx 13 
RTMPQMemAddr[41]
allocate tx ringidx 0 
RTMPQMemAddr[42]
allocate tx ringidx 1 
RTMPQMemAddr[43]
allocate tx ringidx 2 
RTMPQMemAddr[44]
allocate tx ringidx 3 
RTMPQMemAddr[45]
allocate tx ringidx 4 
RTMPQMemAddr[46]
allocate tx ringidx 5 
RTMPQMemAddr[47]
allocate tx ringidx 6 
RTMPQMemAddr[48]
allocate tx ringidx 7 
RTMPQMemAddr[49]
allocate tx ringidx 8 
RTMPQMemAddr[50]
allocate tx ringidx 9 
RTMPQMemAddr[51]
allocate tx ringidx 10 
RTMPQMemAddr[52]
allocate tx ringidx 11 
RTMPQMemAddr[53]
allocate tx ringidx 12 
RTMPQMemAddr[54]
allocate tx ringidx 13 
RTMPQMemAddr[55]
RTMPQMemAddr[70]
RTMPQMemAddr[71]
RTMPQMemAddr[72]
RTMPQMemAddr[73]
RTMPQMemAddr[74]
RTMPQMemAddr[75]
RTMPQMemAddr[76]
RTMPQMemAddr[77]
RTMPQMemAddr[78]
RTMPQMemAddr[79]
RTMPQMemAddr[80]
<-- RTMPAllocTxRxRingMemory, Status=0
<-- RTMPAllocAdapterBlock, Status=0
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x8
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x4
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x5
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x6
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x7
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x9
STA Driver version-JEDI.MP1.mt7601u.v1.5.1_20171130_STAONLY
==>WaitForAsicReady MAC_CSR0=0x76010500
==>WaitForAsicReady MAC_CSR0=0x76010500
NVM is EFUSE
Endpoint(8) is for In-band Command
Endpoint(4) is for WMM0 AC0
Endpoint(5) is for WMM0 AC1
Endpoint(6) is for WMM0 AC2
Endpoint(7) is for WMM0 AC3
Endpoint(9) is for WMM1 AC0
Endpoint(84) is for Data-In
Endpoint(85) is for Command Rsp
80211> RFICType = 3
NumOfChan ===> 58
80211> Number of channel = 0x44
80211> Number of rate = 12
80211> CurTxPower = 0 dBm
80211> TxStream = 0
crda> requlation requestion by core: 00
80211> CFG80211_Register
usbcore: registered new interface driver rt2870
================> UP : RTMP_SEM_EVENT_WAIT(STA)
1. LDO_CTR0(6c) = a64799, PMU_OCLEVEL c
2. LDO_CTR0(6c) = a6478d, PMU_OCLEVEL 6
==>WaitForAsicReady MAC_CSR0=0x76010500
FW Version:0.1.00 Build:7640
Build Time:201301040941____
ILM Length = 44276(bytes)
DLM Length = 0(bytes)
Loading FW....
########DBG(Change PMU LEVEL)
RTMP_TimerListAdd: add timer obj c4ace63c!
RTMP_TimerListAdd: add timer obj c4ace66c!
RTMP_TimerListAdd: add timer obj c4ace69c!
RTMP_TimerListAdd: add timer obj c4ace60c!
RTMP_TimerListAdd: add timer obj c4ace57c!
RTMP_TimerListAdd: add timer obj c4ace5ac!
RTMP_TimerListAdd: add timer obj c4a62fb4!
RTMP_TimerListAdd: add timer obj c4a52700!
RTMP_TimerListAdd: add timer obj c4a52734!
RTMP_TimerListAdd: add timer obj c4a63054!
RTMP_TimerListAdd: add timer obj c4a62f54!
RTMP_TimerListAdd: add timer obj c4a63024!
==>WaitForAsicReady MAC_CSR0=0x76010500
cfg_mode=9
wmode_band_equal(): Band Equal!
Key1Str is Invalid key length(0) or Type(0)
Key2Str is Invalid key length(0) or Type(0)
Key3Str is Invalid key length(0) or Type(0)
Key4Str is Invalid key length(0) or Type(0)
###### Force at HT20 (BW_20) mode !!! ########
1. Phy Mode = 14
2. Phy Mode = 14
NVM is Efuse and its size =1d[1e0-1fc] 
ERROR!!! MT7601 E2PROM: WRONG VERSION 0xd, should be 9
3. Phy Mode = 14
AntCfgInit: primary/secondary ant 0/1
---> InitFrequencyCalibration
InitFrequencyCalibrationMode:Unknow mode = 3
InitFrequencyCalibration: frequency offset in the EEPROM = 120(0x78)
<--- InitFrequencyCalibration
RTMPSetPhyMode: channel is out of range, use first channel=1 
MCS Set = ff 00 00 00 01
<==== STA : rt28xx_init, Status=0
80211> re-init bands...
80211> RFICType = 1
NumOfChan ===> 14
80211> Number of channel = 0x44
80211> Number of rate = 12
80211> CurTxPower = 0 dBm
80211> TxStream = 1
0x1300 = 00064300
RTMPDrvOpen(1):Check if PDMA is idle!
RTMPDrvOpen(2):Check if PDMA is idle!
<================ UP : RTMP_SEM_EVENT_UP(STA)
[gpio] Set PAD_SR_IO12 as GPIO(controlled by ISP bank)
hue, get pwm(1) 
[PWN] mstar_pwm_config duty_ns=0, period_ns=100000
reg=0x1F003490 clk=12000000, period=0x78
reg=0x1F003488 clk=12000000, u32Duty=0x0
[PWM] mstar_pwm_enable
[PWM] mstar_pwm_disable
[Mstar GPIO] gpio(83) to irq(166)
hue, gpio_isr 
[CPLD_PERIPH] timer init ok.
timer resolution:10 MHZ
[CPLD_PERIPH] CPLD_PERIPH module inited 
[PWN] mstar_pwm_config duty_ns=0, period_ns=100000
reg=0x1F003490 clk=12000000, period=0x78
reg=0x1F003488 clk=12000000, u32Duty=0x0

[PID_LIST] pid_list_init ok, [ ver=Apr 28 2018, 17:10:59 ] 
MSYS: DMEM request: [ISP_MLOAD]:0x000088E0
MSYS: DMEM request: [DLC_MEM]:0x00000400
[DRVSCLDMA] Double Buffer Status :0
[HVSP1] Size must be align 16, Vsize=1080, Pitch=1920
[HVSP1] Buffer is single, Vsize=1080, Pitch=1920
MSYS: DMEM request: [SCL_MCNR_YC]:0x003FC000
MSYS: DMEM request: [SCL_MCNR_M]:0x000FF000
[HVSP1]: MCNR YC: Phy:239a0000  Vir:c39a0000
[HVSP1]: MCNR CIIR: Phy:0  Vir:0
[HVSP1]: MCNR M: Phy:23da0000  Vir:c3da0000
MSYS: DMEM request: [VSPL-I0P0B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P0B0, phys=0x22AC0000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P0B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P0B1, phys=0x22B20000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P2B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P2B0, phys=0x22B80000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P2B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P2B1, phys=0x22BE0000, length=0x0005A000
MSB2@v1.1-01:r&d analysis.
MSYS: DMEM request: [MS-00]:0x00357000
MSYS: DMEM kept entry found: name=MS-00, phys=0x22C40000, length=0x00357000
MSYS: DMEM request: [MS-01]:0x00357000
MSYS: DMEM kept entry found: name=MS-01, phys=0x22FA0000, length=0x00357000
MSYS: DMEM request: [VENC-32]:0x000FF000
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM kept entry found: name=VENC-32, phys=0x23300000, length=0x000FF000
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM request: [S0:VENCDMOUT]:0x00006400
MSYS: DMEM kept entry found: name=S0:VENCDMOUT, phys=0x23400000, length=0x0000A800
MSB2@v1.1-01:r&d analysis.
MSYS: DMEM request: [VSPL-I0P1B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P1B0, phys=0x23510000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P1B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P1B1, phys=0x23570000, length=0x0005A000
MSYS: DMEM request: [VENC-48]:0x00025800
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM request: [S1:VENCDMOUT]:0x00005600
MSYS: DMEM kept entry found: name=VENC-48, phys=0x235D0000, length=0x00025800
MSYS: DMEM kept entry found: name=S1:VENCDMOUT, phys=0x22A98000, length=0x00005600
MSYS: DMEM request: [S1:VENCDMP0]:0x00056400
MSYS: DMEM kept entry found: name=S1:VENCDMP0, phys=0x23600000, length=0x00056400
MSYS: DMEM request: [S1:VENCDMP1]:0x00056400
MSYS: DMEM kept entry found: name=S1:VENCDMP1, phys=0x23660000, length=0x00056400
MSB2@v1.1-01:r&d analysis.
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM request: [VENC-49]:0x00025800
MSYS: DMEM kept entry found: name=VENC-49, phys=0x236C0000, length=0x00025800
MSYS: DMEM request: [S2:VENCDMOUT]:0x00005600
MSYS: DMEM kept entry found: name=S2:VENCDMOUT, phys=0x22AB8000, length=0x00005600
MSYS: DMEM request: [S2:VENCDMP0]:0x00056400
MSYS: DMEM kept entry found: name=S2:VENCDMP0, phys=0x236F0000, length=0x00056400
MSYS: DMEM request: [S2:VENCDMP1]:0x00056400
MSYS: DMEM kept entry found: name=S2:VENCDMP1, phys=0x23750000, length=0x00056400
MSB2@v1.1-01:r&d analysis.
MSYS: DMEM request: [VSPL-I0P3B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P3B0, phys=0x237B0000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P3B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P3B1, phys=0x23810000, length=0x0005A000
MSYS: DMEM request: [VENC-50]:0x00025800
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM request: [S3:VENCDMOUT]:0x00005600
MSYS: DMEM kept entry found: name=S3:VENCDMOUT, phys=0x22F98000, length=0x00005600
MSYS: DMEM kept entry found: name=VENC-50, phys=0x23870000, length=0x00025800
MSYS: DMEM request: [S3:VENCDMP0]:0x00056400
MSYS: DMEM kept entry found: name=S3:VENCDMP0, phys=0x238A0000, length=0x00056400
MSYS: DMEM request: [S3:VENCDMP1]:0x00056400
MSYS: DMEM kept entry found: name=S3:VENCDMP1, phys=0x23900000, length=0x00056400
MSYS: DMEM request: [VENC-51]:0x00025800
MSYS: DMEM kept entry found: name=VENC-51, phys=0x23960000, length=0x00025800
MT7601_ChipSwitchChannel: SwitchChannel#1(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#2(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#3(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#4(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#5(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#6(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#7(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#8(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#9(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#10(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#11(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#12(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#13(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#1(RF=15, 1T)
80211> cfg80211_scan_done
#####check WPS IE
ConnInfo.bWpsConnection ===> Not WPS IE
80211> Connect bssid e0:3f:49:25:6f:f8
MT7601_ChipSwitchChannel: SwitchChannel#9(RF=15, 1T)
PeerBeaconAtJoinAction(): HT-CtrlChannel=9, CentralChannel=>9
PeerBeaconAtJoinAction(): Set CentralChannel=9
MT7601_ChipSwitchChannel: SwitchChannel#9(RF=15, 1T)
random: wpa_supplicant urandom read with 58 bits of entropy available
Rcv Wcid(1) AddBAReq
Start Seq = 00000002
RTMP_TimerListAdd: add timer obj c4b1dafc!
RTMP_TimerListAdd: add timer obj c4b1badc!
RTMP_TimerListAdd: add timer obj c4b1bb1c!
RTMP_TimerListAdd: add timer obj c4b1bb5c!
hue, cpld_ioctl() cmd(6) invalid !!! 
hue, cpld_ioctl() cmd(6) invalid !!! 
enrysan0 commented 4 years ago

Here is another dump with a fat32 SdCard inserted:

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2019.11.09 11:00:39 =~=~=~=~=~=~=~=~=~=~=~=
‡‡¸Ä‡采‡é‡
IPL gd156225
D-01.

HW Reset
64MB

BIST0_0001-OK

offset:00010000

size:7fc8 chks:5551a134 ok

IPL_CUST gbf16da4

MXP found at 0x00020000

  decomp_size=0x00041314

-----------------------U-Boot 2015.01 (Apr 28 2018 - 17:08:00)-----------------------

Version: I3ge2accce
DEVINFO: 313E
[WDT] Enalbe WATCHDOG 60s
       Watchdog enabled
I2C:   ready
DRAM:  64 MiB
WARNING: Caches not enabled
MMC:   MStar SD/MMC: 0
nor_flash_mxp allocated success!!
MXIC REMS: 0xC2,0x17
Flash is detected (0x0509, 0xC2, 0x20, 0x18)
SF: Detected nor0 with total size 16 MiB
MXP found at mxp_offset[1]=0x00020000, size=0x1000
env_offset=0x4F000 env_size=0x1000
MXIC REMS: 0xC2,0x17
Flash is detected (0x0509, 0xC2, 0x20, 0x18)
SF: Detected nor0 with total size 16 MiB
In:    serial
Out:   serial
Err:   serial
Net:   No ethernet found.

+++++++++++++++++++   check one.bin    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 one.bin 
    one.bin Not exist(fatsize err) 

+++++++++++++++++++   check one_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 one_y25 
    one_y25 Not exist(fatsize err) 

+++++++++++++++++++   check uboot_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 uboot_y25 
    uboot_y25 Not exist(fatsize err) 

+++++++++++++++++++   check kernel_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 kernel_y25 
    kernel_y25 Not exist(fatsize err) 

+++++++++++++++++++   check sys_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 sys_y25 
    sys_y25 Not exist(fatsize err) 

+++++++++++++++++++   check home_y25    +++++++++++++++++++ 
------>setenv filesize 0 
------>fatsize mmc 0 home_y25 
    home_y25 Not exist(fatsize err) 
[NetUpgrade] ts_1st=0x1b6
No ethernet found.
[NetUpgrade] ==== NetLoop(NETUPGRADE) return fail ====!
net_upgrade - do net update from the specified file that is in tftpserver

Usage:
net_upgrade     -  

MXIC REMS: 0xC2,0x17
Flash is detected (0x0509, 0xC2, 0x20, 0x18)
SF: Detected nor0 with total size 16 MiB
SF: 2162688 bytes @ 0x50000 Read: OK
##  Booting kernel from Legacy Image at 21000000 ...
   Image Name:   MVX2##I3ge2accceKL_LX318####[BR:
   Image Type:   ARM Linux Kernel Image (lzma compressed)
   Data Size:    1457444 Bytes = 1.4 MiB
   Load Address: 20008000
   Entry Point:  20008000
   Verifying Checksum ... OK
   Uncompressing Kernel Image ... 
[XZ] !!!reserved 0x21000000 length=0x 1000000 for xz!!
   XZ: uncompressed size=0x3ce1e0, ret=7
OK
ERR: Can't find KIMG header and initrd address, 0x00000000
atags:0x20000000

Starting kernel ...

Booting Linux on physical CPU 0x0
Linux version 3.18.30 (zhengqianbin@ubuntu) (gcc version 4.8.3 20140401 (prerelease) (crosstool-NG linaro-1.13.1-4.8-2014.04 - Linaro GCC 4.8-2014.04) ) #2 PREEMPT Sat Apr 28 17:11:02 HKT 2018
CPU: ARMv7 Processor [410fc075] revision 5 (ARMv7), cr=10c53c7d
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
early_atags_to_fdt() success
Machine model: INFINITY3 MSC000A-S03A-64M
Reserved memory: created CMA memory pool at 0x22a00000, size 22 MiB
Reserved memory: initialized node cma0, compatible id shared-dma-pool
Memory policy: Data cache writeback
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 16256
Kernel command line: console=ttyS0,115200n8r androidboot.console=ttyS0 root=/dev/mtdblock2 rw rootfstype=jffs2 noinitrd init=/init
PID hash table entries: 256 (order: -2, 1024 bytes)
Dentry cache hash table entries: 8192 (order: 3, 32768 bytes)
Inode-cache hash table entries: 4096 (order: 2, 16384 bytes)
Memory: 38176K/65536K available (2646K kernel code, 224K rwdata, 904K rodata, 120K init, 117K bss, 27360K reserved)
Virtual kernel memory layout:
    vector  : 0xffff0000 - 0xffff1000   (   4 kB)
    fixmap  : 0xffc00000 - 0xffe00000   (2048 kB)
    vmalloc : 0xc4800000 - 0xff000000   ( 936 MB)
    lowmem  : 0xc0000000 - 0xc4000000   (  64 MB)
    modules : 0xbf000000 - 0xc0000000   (  16 MB)
      .text : 0xc0008000 - 0xc037fb20   (3551 kB)
      .init : 0xc0380000 - 0xc039e000   ( 120 kB)
      .data : 0xc039e000 - 0xc03d61e0   ( 225 kB)
       .bss : 0xc03d61e0 - 0xc03f36b0   ( 118 kB)
SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
Preemptible hierarchical RCU implementation.
    Dump stacks of tasks blocking RCU-preempt GP.
NR_IRQS:16 nr_irqs:16 16
Find CLK_cpupll_clk, hook ms_cpuclk_ops
[ms_cpuclk_init] get dvfs gpio  vid_1
Architected cp15 timer(s) running at 6.00MHz (virt).
sched_clock: 56 bits at 6MHz, resolution 166ns, wraps every 2863311527936ns
Switching to timer-based delay loop, resolution 166ns
console [ttyS0] enabled
Calibrating delay loop (skipped), value calculated using timer frequency.. 12.00 BogoMIPS (lpj=60000)
pid_max: default: 4096 minimum: 301
Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
CPU: Testing write buffer coherency: ok
Setting up static identity map for 0x20281a40 - 0x20281a74
VFP support v0.3: implementor 41 architecture 2 part 30 variant 7 rev 5
NET: Registered protocol family 16
DMA: preallocated 256 KiB pool for atomic coherent allocations

Version : MVX2##I3ge2accceKL_LX318####[BR:y25_prj]#XVM

GPIO: probe end
MSYS:  INIT DONE. TICK=0x0174E4AD
Advanced Linux Sound Architecture Driver Initialized.
Switched to clocksource arch_sys_counter
NET: Registered protocol family 2
TCP established hash table entries: 1024 (order: 0, 4096 bytes)
TCP bind hash table entries: 1024 (order: 2, 20480 bytes)
TCP: Hash tables configured (established 1024 bind 1024)
TCP: reno registered
UDP hash table entries: 128 (order: 0, 6144 bytes)
UDP-Lite hash table entries: 128 (order: 0, 6144 bytes)
NET: Registered protocol family 1
futex hash table entries: 16 (order: -4, 448 bytes)
jffs2: version 2.2. © 2001-2006 Red Hat, Inc.
msgmni has been set to 118
io scheduler noop registered
io scheduler deadline registered (default)
i2c /dev entries driver
[ms_uart_probe] uart port 0 use MUX_PM_UART
1f221000.uart0: ttyS0 at MMIO 0x0 (irq = 98, base_baud = 10750000) is a unknown
[ms_uart_probe] uart port 1 use MUX_UART1
1f221200.uart1: ttyS1 at MMIO 0x0 (irq = 99, base_baud = 10750000) is a unknown
URDMA rx_buf=0xC2A42000(phy:0x22A42000) tx_buf=0xC2A43000(phy:0x22A43000) size=0x1000
[ms_uart_probe] uart port 2 use MUX_UART0
1f220400.uart2: ttyS2 at MMIO 0x0 (irq = 112, base_baud = 10750000) is a unknown
infinity-audio soc:sound: ASoC: CODEC DAI infinity-codec-dai-main not registered
platform soc:sound: Driver infinity-audio requests probe deferral
infinity-audio infinity-codec: ASoC: CODEC DAI infinity-codec-dai-main not registered
platform infinity-codec: Driver infinity-audio requests probe deferral
netif_napi_add() called with weight 128 on device eth%d
MSYS: DMEM request: [EMAC_BUFF]:0x00002000
[EMAC]Init EMAC success! (add delay in reset)
[HVSP]u32Dropmode on/n
[VIP]gu32CMDQmode off/nMSYS: DMEM request: [VIP_CMDQ]:0x00004000
[SCL] SCL init success
mload_size = 35040
mload_virt_addr = c2a50000
mload_dma_addr = 0x22a50000
MSYS: DMEM request: [ISP_base]:0x0001B120
ShareData_Meminfo phyaddr:0x2224da00, viraddr:0xc224da00, len:0x38
AE Base: virt=0xC2A60000 size=0xB400
AWB Base: virt=0xC2A6B400 size=0x8700
AF Base: virt=0xC2A73B00 size=0xF0
HISTO Base: virt=0xC2A73BF0 size=0x2F0
MOT Base: virt=0xC2A73EE0 size=0x6E40
RGBIR Base: virt=0xC2A7AD20 size=0x400
[ISP] register driver success
[CSI] register driver successms_rtc 1f002400.rtc: rtc core: registered 1f002400.rtc as rtc0
[ms_rtc_probe]: rtc setup, frequency=12000000
[SAR] infinity_sar_probe 
MSYS: DMEM request: [BDMA_FSP_WBUFF]:0x00000100
[Ser flash] phys=0x22a46000, virt=0xc2a46000, bus=0x02a46000
[FSP] MXIC REMS: 0xC2,0x17
[FSP] Flash is detected (0x0509, 0xC2, 0x20, 0x18) ver1.1
[FSP] 1-1-2 DUAL_FAST_READ MODE
mtd .name = NOR_FLASH, .size = 0x01000000 (16MiB)
 .erasesize = 0x00010000 .numeraseregions = 0
MXP_PARTS!!
MXP found at mxp_offset[1]=0x00020000, size=0x1000
Creating 6 MTD partitions on "NOR_FLASH":
0x000000000000-0x000000050000 : "BOOT"
0x000000050000-0x0000001d0000 : "KERNEL"
0x0000001d0000-0x0000003b0000 : "ROOTFS"
0x0000003b0000-0x000000fe0000 : "HOME"
0x000000fe0000-0x000000ff0000 : "vd1"
0x000000ff0000-0x000001000000 : "conf"
[ms_cpufreq_init] cpu current clk=796917760
ms_pwm->pad_ctrl[0]=69
ms_pwm->pad_ctrl[1]=17
ms_pwm->pad_ctrl[2]=255
ms_pwm->pad_ctrl[3]=255
ms_pwm->pad_ctrl[4]=53
ms_pwm->pad_ctrl[5]=255
ms_pwm->pad_ctrl[6]=255
ms_pwm->pad_ctrl[7]=56
mstar-i3pwm 1f003400.pwm: probe successful
TCP: cubic registered
NET: Registered protocol family 17
MSYS: DMEM request: [pcmC0D0p]:0x00018000
MSYS: DMEM request: [pcmC0D0c]:0x00014000
infinity-audio soc:sound: infinity-codec-dai-main <-> infinity-cpu-dai mapping ok
ms_rtc 1f002400.rtc: setting system clock to 1970-01-01 00:00:00 UTC (0)
ALSA device list:
  #0: infinity_snd_machine
VFS: Mounted root (jffs2 filesystem) on device 31:2.
Freeing unused kernel memory: 120K (c0380000 - c039e000)
init: SERVICE: ueventd
init: SERVICE: rcs
[FB]Set 68
[DRVHVSP]Drv_HVSP_SetFbManageConfig(645):8000 
DNRR OFF
[FB]Set 57
[DRVHVSP]Drv_HVSP_SetFbManageConfig(645):100 
UNLOCK
[JPE, JpeProbe] set base=0xfd264000 irq=93, nClockRate=288000000
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
ehci_hcd: unknown parameter 'force_host' ignored
ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mstar_ehc_init version:20150512
Mstar-ehci-2 H.W init
Titania3_series_start_ehc start
enable USB function
[USB] config miu select [1] [ef] [ef] ][ef]
[USB] enable miu lower bound address subtraction
[USB] worring.... no platform_data
hcd->rsrc_start:0xfd286400
BC disable 
[USB] soc:Mstar-ehci-2 irq --> 119
soc:Mstar-ehci-2 soc:Mstar-ehci-2: EHCI Host Controller
soc:Mstar-ehci-2 soc:Mstar-ehci-2: new USB bus registered, assigned bus number 1
soc:Mstar-ehci-2 soc:Mstar-ehci-2: irq 119, io mem 0xfd286400
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 1 port detected
Mstar-ehci-1 H.W init
CHIP_FUNCTION SET. ID=4, param=1
Can't get power-enable-pad from DTS, set default GPIO(1)
[mstar_usb_vbus_control] Enable USB VBUS GPIO(81)
Titania3_series_start_ehc start
enable USB function
[USB] config miu select [1] [ef] [ef] ][ef]
[USB] enable miu lower bound address subtraction
[USB] worring.... no platform_data
hcd->rsrc_start:0xfd284800
BC disable 
[USB] soc:Mstar-ehci-1 irq --> 95
soc:Mstar-ehci-1 soc:Mstar-ehci-1: EHCI Host Controller
soc:Mstar-ehci-1 soc:Mstar-ehci-1: new USB bus registered, assigned bus number 2
soc:Mstar-ehci-1 soc:Mstar-ehci-1: irq 95, io mem 0xfd284800
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 1 port detected
>> [sdmmc] ms_sdmmc Driver Initializing... 
>> [sdmmc] ms_sdmmc_probe 
==20150512==> hub_port_init 1 #0
Plug in USB Port1
>> [sdmmc_0] Int CDZ use Ext GPIO IRQ: (151)
>> [sdmmc_0] Probe Platform Devices...(Ret:0) 
>> [sdmmc_0] Get CD => (1)
[Mstar GPIO] gpio(16) to irq(-1)
>> [sdmmc_0] Set IOS => Clk=48000000 (Real=48000000)
mmc0: new high speed SDHC card at address 0001
mmcblk0: mmc0:0001 SD16G 29.5 GiB 
 mmcblk0: p1
[USB] ERR, after reset no PE: port status 0xa
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #1
Plug in USB Port1
[USB] device has gone before bus reset
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #2
Plug in USB Port1
[USB] device has gone before bus reset
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #3
Plug in USB Port1
[USB] device has gone before bus reset
hub_port_disable: 1  hub->err: 0 
hub_port_disable: 1  hub->err: 0 
==20150512==> hub_port_init 1 #0
Plug in USB Port1
usb 2-1: new high-speed USB device number 6 using soc:Mstar-ehci-1
cryptodev: driver aesdmadev loaded.
MSYS: DMEM request: [AESDMA_ENG]:0x00001000
MSYS: DMEM request: [AESDMA_ENG1]:0x00001000
infinity_aes soc:aesdma: MSTAR AES engine enabled.
MSYS: DMEM request: [VSPL-I0P0B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P0B1]:0x0005A000
MSYS: DMEM request: [VSPL-I0P2B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P2B1]:0x0005A000
MSYS: DMEM request: [MS-00]:0x00357000
MSYS: DMEM request: [MS-01]:0x00357000
MSYS: DMEM request: [VENC-32]:0x000FF000
MSYS: DMEM request: [S0:VENCDMOUT]:0x0000A800
MSYS: DMEM request: [S0:VENCDMP0]:0x0007F800
MSYS: DMEM request: [S0:VENCDMP1]:0x0007F800
MSYS: DMEM request: [VSPL-I0P1B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P1B1]:0x0005A000
MSYS: DMEM request: [VENC-48]:0x00025800
MSYS: DMEM request: [S1:VENCDMOUT]:0x00005600
MSYS: DMEM request: [S1:VENCDMP0]:0x00056400
MSYS: DMEM request: [S1:VENCDMP1]:0x00056400
MSYS: DMEM request: [VENC-49]:0x00025800
MSYS: DMEM request: [S2:VENCDMOUT]:0x00005600
MSYS: DMEM request: [S2:VENCDMP0]:0x00056400
MSYS: DMEM request: [S2:VENCDMP1]:0x00056400
MSYS: DMEM request: [VSPL-I0P3B0]:0x0005A000
MSYS: DMEM request: [VSPL-I0P3B1]:0x0005A000
MSYS: DMEM request: [VENC-50]:0x00025800
MSYS: DMEM request: [S3:VENCDMOUT]:0x00005600
MSYS: DMEM request: [S3:VENCDMP0]:0x00056400
MSYS: DMEM request: [S3:VENCDMP1]:0x00056400
MSYS: DMEM request: [VENC-51]:0x00025800
MSYS: fix_dmem enabled
hue, spi0_dev = 0xc238a800 
init.sh (46): drop_caches: 3
cfg80211: Calling CRDA to update world regulatory domain
mtprealloc: module license 'unspecified' taints kernel.
Disabling lock debugging due to kernel taint
==>[0]:PreBuff:0xc23d8000, DmaAddr:0x223d8000
==>[1]:PreBuff:0xc23d4000, DmaAddr:0x223d4000
==>[2]:PreBuff:0xc1bc4000, DmaAddr:0x21bc4000
==>[3]:PreBuff:0xc1e28000, DmaAddr:0x21e28000
==>[4]:PreBuff:0xc1e2c000, DmaAddr:0x21e2c000
==>[5]:PreBuff:0xc23c8000, DmaAddr:0x223c8000
==>[6]:PreBuff:0xc23cc000, DmaAddr:0x223cc000
==>[7]:PreBuff:0xc1e08000, DmaAddr:0x21e08000
==>[8]:PreBuff:0xc1e0c000, DmaAddr:0x21e0c000
==>[9]:PreBuff:0xc1e10000, DmaAddr:0x21e10000
==>[10]:PreBuff:0xc1e14000, DmaAddr:0x21e14000
==>[11]:PreBuff:0xc1e18000, DmaAddr:0x21e18000
==>[12]:PreBuff:0xc1e1c000, DmaAddr:0x21e1c000
==>[13]:PreBuff:0xc1be0000, DmaAddr:0x21be0000
==>[14]:PreBuff:0xc1be4000, DmaAddr:0x21be4000
==>[15]:PreBuff:0xc1be8000, DmaAddr:0x21be8000
==>[16]:PreBuff:0xc1bec000, DmaAddr:0x21bec000
==>[17]:PreBuff:0xc1bf0000, DmaAddr:0x21bf0000
==>[18]:PreBuff:0xc1bf4000, DmaAddr:0x21bf4000
==>[19]:PreBuff:0xc1bf8000, DmaAddr:0x21bf8000
==>[20]:PreBuff:0xc1bfc000, DmaAddr:0x21bfc000
==>[21]:PreBuff:0xc1e40000, DmaAddr:0x21e40000
==>[22]:PreBuff:0xc1e44000, DmaAddr:0x21e44000
==>[23]:PreBuff:0xc1e48000, DmaAddr:0x21e48000
==>[24]:PreBuff:0xc1e4c000, DmaAddr:0x21e4c000
==>[25]:PreBuff:0xc1e50000, DmaAddr:0x21e50000
==>[26]:PreBuff:0xc1e54000, DmaAddr:0x21e54000
==>[27]:PreBuff:0xc1e58000, DmaAddr:0x21e58000
==>[28]:PreBuff:0xc1e5c000, DmaAddr:0x21e5c000
==>[29]:PreBuff:0xc1e60000, DmaAddr:0x21e60000
==>[30]:PreBuff:0xc1e64000, DmaAddr:0x21e64000
==>[31]:PreBuff:0xc1e68000, DmaAddr:0x21e68000
==>[32]:PreBuff:0xc1e6c000, DmaAddr:0x21e6c000
==>[33]:PreBuff:0xc1e70000, DmaAddr:0x21e70000
==>[34]:PreBuff:0xc1e74000, DmaAddr:0x21e74000
==>[35]:PreBuff:0xc1e78000, DmaAddr:0x21e78000
==>[36]:PreBuff:0xc1e7c000, DmaAddr:0x21e7c000
==>[37]:PreBuff:0xc1b80000, DmaAddr:0x21b80000
==>[38]:PreBuff:0xc1b84000, DmaAddr:0x21b84000
==>[39]:PreBuff:0xc1b88000, DmaAddr:0x21b88000
==>[40]:PreBuff:0xc1b8c000, DmaAddr:0x21b8c000
==>[41]:PreBuff:0xc1b90000, DmaAddr:0x21b90000
==>[42]:PreBuff:0xc1b94000, DmaAddr:0x21b94000
==>[43]:PreBuff:0xc1b98000, DmaAddr:0x21b98000
==>[44]:PreBuff:0xc1b9c000, DmaAddr:0x21b9c000
==>[45]:PreBuff:0xc1ba0000, DmaAddr:0x21ba0000
==>[46]:PreBuff:0xc1ba4000, DmaAddr:0x21ba4000
==>[47]:PreBuff:0xc1ba8000, DmaAddr:0x21ba8000
==>[48]:PreBuff:0xc1bac000, DmaAddr:0x21bac000
==>[49]:PreBuff:0xc1bb0000, DmaAddr:0x21bb0000
==>[50]:PreBuff:0xc1bb4000, DmaAddr:0x21bb4000
==>[51]:PreBuff:0xc1bb8000, DmaAddr:0x21bb8000
==>[52]:PreBuff:0xc1bbc000, DmaAddr:0x21bbc000
==>[53]:PreBuff:0xc1e80000, DmaAddr:0x21e80000
==>[54]:PreBuff:0xc1e84000, DmaAddr:0x21e84000
==>[55]:PreBuff:0xc1e88000, DmaAddr:0x21e88000
==>[56]:PreBuff:0xc1e8c000, DmaAddr:0x21e8c000
==>[57]:PreBuff:0xc1e90000, DmaAddr:0x21e90000
==>[58]:PreBuff:0xc1e94000, DmaAddr:0x21e94000
==>[59]:PreBuff:0xc1e98000, DmaAddr:0x21e98000
==>[60]:PreBuff:0xc1e9c000, DmaAddr:0x21e9c000
==>[61]:PreBuff:0xc1ea0000, DmaAddr:0x21ea0000
==>[62]:PreBuff:0xc1ea4000, DmaAddr:0x21ea4000
==>[63]:PreBuff:0xc1ea8000, DmaAddr:0x21ea8000
==>[64]:PreBuff:0xc1eac000, DmaAddr:0x21eac000
==>[65]:PreBuff:0xc1eb0000, DmaAddr:0x21eb0000
==>[66]:PreBuff:0xc1eb4000, DmaAddr:0x21eb4000
==>[67]:PreBuff:0xc1eb8000, DmaAddr:0x21eb8000
==>[68]:PreBuff:0xc1ebc000, DmaAddr:0x21ebc000
==>[69]:PreBuff:0xc1ec0000, DmaAddr:0x21ec0000
==>[70]:PreBuff:0xc2350000, DmaAddr:0x22350000
==>[71]:PreBuff:0xc2352000, DmaAddr:0x22352000
==>[72]:PreBuff:0xc1ec8000, DmaAddr:0x21ec8000
==>[73]:PreBuff:0xc1ed0000, DmaAddr:0x21ed0000
==>[74]:PreBuff:0xc1ed8000, DmaAddr:0x21ed8000
==>[75]:PreBuff:0xc1ee0000, DmaAddr:0x21ee0000
==>[76]:PreBuff:0xc1ee8000, DmaAddr:0x21ee8000
==>[77]:PreBuff:0xc1ef0000, DmaAddr:0x21ef0000
==>[78]:PreBuff:0xc1ef8000, DmaAddr:0x21ef8000
==>[79]:PreBuff:0xc1b00000, DmaAddr:0x21b00000
==>[80]:PreBuff:0xc1e00800, DmaAddr:0x21e00800
install prealloc ok
rtusb init rt2870 --->

=== pAd = c4a52000, size = 863344 ===

allocate tx ringidx 0 
RTMPQMemAddr[0]
allocate tx ringidx 1 
RTMPQMemAddr[1]
allocate tx ringidx 2 
RTMPQMemAddr[2]
allocate tx ringidx 3 
RTMPQMemAddr[3]
allocate tx ringidx 4 
RTMPQMemAddr[4]
allocate tx ringidx 5 
RTMPQMemAddr[5]
allocate tx ringidx 6 
RTMPQMemAddr[6]
allocate tx ringidx 7 
RTMPQMemAddr[7]
allocate tx ringidx 8 
RTMPQMemAddr[8]
allocate tx ringidx 9 
RTMPQMemAddr[9]
allocate tx ringidx 10 
RTMPQMemAddr[10]
allocate tx ringidx 11 
RTMPQMemAddr[11]
allocate tx ringidx 12 
RTMPQMemAddr[12]
allocate tx ringidx 13 
RTMPQMemAddr[13]
allocate tx ringidx 0 
RTMPQMemAddr[14]
allocate tx ringidx 1 
RTMPQMemAddr[15]
allocate tx ringidx 2 
RTMPQMemAddr[16]
allocate tx ringidx 3 
RTMPQMemAddr[17]
allocate tx ringidx 4 
RTMPQMemAddr[18]
allocate tx ringidx 5 
RTMPQMemAddr[19]
allocate tx ringidx 6 
RTMPQMemAddr[20]
allocate tx ringidx 7 
RTMPQMemAddr[21]
allocate tx ringidx 8 
RTMPQMemAddr[22]
allocate tx ringidx 9 
RTMPQMemAddr[23]
allocate tx ringidx 10 
RTMPQMemAddr[24]
allocate tx ringidx 11 
RTMPQMemAddr[25]
allocate tx ringidx 12 
RTMPQMemAddr[26]
allocate tx ringidx 13 
RTMPQMemAddr[27]
allocate tx ringidx 0 
RTMPQMemAddr[28]
allocate tx ringidx 1 
RTMPQMemAddr[29]
allocate tx ringidx 2 
RTMPQMemAddr[30]
allocate tx ringidx 3 
RTMPQMemAddr[31]
allocate tx ringidx 4 
RTMPQMemAddr[32]
allocate tx ringidx 5 
RTMPQMemAddr[33]
allocate tx ringidx 6 
RTMPQMemAddr[34]
allocate tx ringidx 7 
RTMPQMemAddr[35]
allocate tx ringidx 8 
RTMPQMemAddr[36]
allocate tx ringidx 9 
RTMPQMemAddr[37]
allocate tx ringidx 10 
RTMPQMemAddr[38]
allocate tx ringidx 11 
RTMPQMemAddr[39]
allocate tx ringidx 12 
RTMPQMemAddr[40]
allocate tx ringidx 13 
RTMPQMemAddr[41]
allocate tx ringidx 0 
RTMPQMemAddr[42]
allocate tx ringidx 1 
RTMPQMemAddr[43]
allocate tx ringidx 2 
RTMPQMemAddr[44]
allocate tx ringidx 3 
RTMPQMemAddr[45]
allocate tx ringidx 4 
RTMPQMemAddr[46]
allocate tx ringidx 5 
RTMPQMemAddr[47]
allocate tx ringidx 6 
RTMPQMemAddr[48]
allocate tx ringidx 7 
RTMPQMemAddr[49]
allocate tx ringidx 8 
RTMPQMemAddr[50]
allocate tx ringidx 9 
RTMPQMemAddr[51]
allocate tx ringidx 10 
RTMPQMemAddr[52]
allocate tx ringidx 11 
RTMPQMemAddr[53]
allocate tx ringidx 12 
RTMPQMemAddr[54]
allocate tx ringidx 13 
RTMPQMemAddr[55]
RTMPQMemAddr[70]
RTMPQMemAddr[71]
RTMPQMemAddr[72]
RTMPQMemAddr[73]
RTMPQMemAddr[74]
RTMPQMemAddr[75]
RTMPQMemAddr[76]
RTMPQMemAddr[77]
RTMPQMemAddr[78]
RTMPQMemAddr[79]
RTMPQMemAddr[80]
<-- RTMPAllocTxRxRingMemory, Status=0
<-- RTMPAllocAdapterBlock, Status=0
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x8
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x4
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x5
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x6
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x7
RTMP_COM_IoctlHandle():pAd->BulkOutEpAddr=0x9
STA Driver version-JEDI.MP1.mt7601u.v1.5.1_20171130_STAONLY
==>WaitForAsicReady MAC_CSR0=0x76010500
==>WaitForAsicReady MAC_CSR0=0x76010500
NVM is EFUSE
Endpoint(8) is for In-band Command
Endpoint(4) is for WMM0 AC0
Endpoint(5) is for WMM0 AC1
Endpoint(6) is for WMM0 AC2
Endpoint(7) is for WMM0 AC3
Endpoint(9) is for WMM1 AC0
Endpoint(84) is for Data-In
Endpoint(85) is for Command Rsp
80211> RFICType = 3
NumOfChan ===> 58
80211> Number of channel = 0x44
80211> Number of rate = 12
80211> CurTxPower = 0 dBm
80211> TxStream = 0
crda> requlation requestion by core: 00
80211> CFG80211_Register
usbcore: registered new interface driver rt2870
================> UP : RTMP_SEM_EVENT_WAIT(STA)
1. LDO_CTR0(6c) = a64799, PMU_OCLEVEL c
2. LDO_CTR0(6c) = a6478d, PMU_OCLEVEL 6
==>WaitForAsicReady MAC_CSR0=0x76010500
FW Version:0.1.00 Build:7640
Build Time:201301040941____
ILM Length = 44276(bytes)
DLM Length = 0(bytes)
Loading FW....
########DBG(Change PMU LEVEL)
RTMP_TimerListAdd: add timer obj c4ad063c!
RTMP_TimerListAdd: add timer obj c4ad066c!
RTMP_TimerListAdd: add timer obj c4ad069c!
RTMP_TimerListAdd: add timer obj c4ad060c!
RTMP_TimerListAdd: add timer obj c4ad057c!
RTMP_TimerListAdd: add timer obj c4ad05ac!
RTMP_TimerListAdd: add timer obj c4a64fb4!
RTMP_TimerListAdd: add timer obj c4a54700!
RTMP_TimerListAdd: add timer obj c4a54734!
RTMP_TimerListAdd: add timer obj c4a65054!
RTMP_TimerListAdd: add timer obj c4a64f54!
RTMP_TimerListAdd: add timer obj c4a65024!
==>WaitForAsicReady MAC_CSR0=0x76010500
cfg_mode=9
wmode_band_equal(): Band Equal!
Key1Str is Invalid key length(0) or Type(0)
Key2Str is Invalid key length(0) or Type(0)
Key3Str is Invalid key length(0) or Type(0)
Key4Str is Invalid key length(0) or Type(0)
###### Force at HT20 (BW_20) mode !!! ########
1. Phy Mode = 14
2. Phy Mode = 14
NVM is Efuse and its size =1d[1e0-1fc] 
ERROR!!! MT7601 E2PROM: WRONG VERSION 0xd, should be 9
3. Phy Mode = 14
AntCfgInit: primary/secondary ant 0/1
---> InitFrequencyCalibration
InitFrequencyCalibrationMode:Unknow mode = 3
InitFrequencyCalibration: frequency offset in the EEPROM = 120(0x78)
<--- InitFrequencyCalibration
RTMPSetPhyMode: channel is out of range, use first channel=1 
MCS Set = ff 00 00 00 01
<==== STA : rt28xx_init, Status=0
80211> re-init bands...
80211> RFICType = 1
NumOfChan ===> 14
80211> Number of channel = 0x44
80211> Number of rate = 12
80211> CurTxPower = 0 dBm
80211> TxStream = 1
0x1300 = 00064300
RTMPDrvOpen(1):Check if PDMA is idle!
RTMPDrvOpen(2):Check if PDMA is idle!
<================ UP : RTMP_SEM_EVENT_UP(STA)
[gpio] Set PAD_SR_IO12 as GPIO(controlled by ISP bank)
hue, get pwm(1) 
[PWN] mstar_pwm_config duty_ns=0, period_ns=100000
reg=0x1F003490 clk=12000000, period=0x78
reg=0x1F003488 clk=12000000, u32Duty=0x0
[PWM] mstar_pwm_enable
[PWM] mstar_pwm_disable
[Mstar GPIO] gpio(83) to irq(166)
hue, gpio_isr 
[CPLD_PERIPH] timer init ok.
timer resolution:10 MHZ
[CPLD_PERIPH] CPLD_PERIPH module inited 
[PWN] mstar_pwm_config duty_ns=0, period_ns=100000
reg=0x1F003490 clk=12000000, period=0x78
reg=0x1F003488 clk=12000000, u32Duty=0x0

[PID_LIST] pid_list_init ok, [ ver=Apr 28 2018, 17:10:59 ] 
MSYS: DMEM request: [ISP_MLOAD]:0x000088E0
MSYS: DMEM request: [DLC_MEM]:0x00000400
[DRVSCLDMA] Double Buffer Status :0
[HVSP1] Size must be align 16, Vsize=1080, Pitch=1920
[HVSP1] Buffer is single, Vsize=1080, Pitch=1920
MSYS: DMEM request: [SCL_MCNR_YC]:0x003FC000
MSYS: DMEM request: [SCL_MCNR_M]:0x000FF000
[HVSP1]: MCNR YC: Phy:239a0000  Vir:c39a0000
[HVSP1]: MCNR CIIR: Phy:0  Vir:0
[HVSP1]: MCNR M: Phy:23da0000  Vir:c3da0000
MSYS: DMEM request: [VSPL-I0P0B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P0B0, phys=0x22AC0000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P0B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P0B1, phys=0x22B20000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P2B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P2B0, phys=0x22B80000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P2B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P2B1, phys=0x22BE0000, length=0x0005A000
MSB2@v1.1-01:r&d analysis.
MSYS: DMEM request: [MS-00]:0x00357000
MSYS: DMEM kept entry found: name=MS-00, phys=0x22C40000, length=0x00357000
MSYS: DMEM request: [MS-01]:0x00357000
MSYS: DMEM kept entry found: name=MS-01, phys=0x22FA0000, length=0x00357000
MSYS: DMEM request: [VENC-32]:0x000FF000
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM kept entry found: name=VENC-32, phys=0x23300000, length=0x000FF000
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM request: [S0:VENCDMOUT]:0x00006400
MSYS: DMEM kept entry found: name=S0:VENCDMOUT, phys=0x23400000, length=0x0000A800
MSB2@v1.1-01:r&d analysis.
MSYS: DMEM request: [VSPL-I0P1B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P1B0, phys=0x23510000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P1B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P1B1, phys=0x23570000, length=0x0005A000
MSYS: DMEM request: [VENC-48]:0x00025800
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM kept entry found: name=VENC-48, phys=0x235D0000, length=0x00025800
MSYS: DMEM request: [S1:VENCDMOUT]:0x00005600
MSYS: DMEM kept entry found: name=S1:VENCDMOUT, phys=0x22A98000, length=0x00005600
MSYS: DMEM request: [S1:VENCDMP0]:0x00056400
MSYS: DMEM kept entry found: name=S1:VENCDMP0, phys=0x23600000, length=0x00056400
MSYS: DMEM request: [S1:VENCDMP1]:0x00056400
MSYS: DMEM kept entry found: name=S1:VENCDMP1, phys=0x23660000, length=0x00056400
MSB2@v1.1-01:r&d analysis.
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM request: [VENC-49]:0x00025800
MSYS: DMEM kept entry found: name=VENC-49, phys=0x236C0000, length=0x00025800
MSYS: DMEM request: [S2:VENCDMOUT]:0x00005600
MSYS: DMEM kept entry found: name=S2:VENCDMOUT, phys=0x22AB8000, length=0x00005600
MSYS: DMEM request: [S2:VENCDMP0]:0x00056400
MSYS: DMEM kept entry found: name=S2:VENCDMP0, phys=0x236F0000, length=0x00056400
MSYS: DMEM request: [S2:VENCDMP1]:0x00056400
MSYS: DMEM kept entry found: name=S2:VENCDMP1, phys=0x23750000, length=0x00056400
MSB2@v1.1-01:r&d analysis.
MSYS: DMEM request: [VSPL-I0P3B0]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P3B0, phys=0x237B0000, length=0x0005A000
MSYS: DMEM request: [VSPL-I0P3B1]:0x0005A000
MSYS: DMEM kept entry found: name=VSPL-I0P3B1, phys=0x23810000, length=0x0005A000
MSYS: DMEM request: [VENC-50]:0x00025800
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
mrqc_set_rqcf - skip set RQCT_CFG_SEQ
MSYS: DMEM kept entry found: name=VENC-50, phys=0x23870000, length=0x00025800
MSYS: DMEM request: [S3:VENCDMOUT]:0x00005600
MSYS: DMEM kept entry found: name=S3:VENCDMOUT, phys=0x22F98000, length=0x00005600
MSYS: DMEM request: [S3:VENCDMP0]:0x00056400
MSYS: DMEM kept entry found: name=S3:VENCDMP0, phys=0x238A0000, length=0x00056400
MSYS: DMEM request: [S3:VENCDMP1]:0x00056400
MSYS: DMEM kept entry found: name=S3:VENCDMP1, phys=0x23900000, length=0x00056400
MSYS: DMEM request: [VENC-51]:0x00025800
MSYS: DMEM kept entry found: name=VENC-51, phys=0x23960000, length=0x00025800
MT7601_ChipSwitchChannel: SwitchChannel#1(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#2(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#3(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#4(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#5(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#6(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#7(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#8(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#9(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#10(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#11(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#12(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#13(RF=15, 1T)
MT7601_ChipSwitchChannel: SwitchChannel#1(RF=15, 1T)
80211> cfg80211_scan_done
#####check WPS IE
ConnInfo.bWpsConnection ===> Not WPS IE
80211> Connect bssid e0:3f:49:25:6f:f8
MT7601_ChipSwitchChannel: SwitchChannel#9(RF=15, 1T)
PeerBeaconAtJoinAction(): HT-CtrlChannel=9, CentralChannel=>9
PeerBeaconAtJoinAction(): Set CentralChannel=9
MT7601_ChipSwitchChannel: SwitchChannel#9(RF=15, 1T)
random: wpa_supplicant urandom read with 68 bits of entropy available
RTMP_TimerListAdd: add timer obj c4b1dadc!
Rcv Wcid(1) AddBAReq
Start Seq = 00000004
RTMP_TimerListAdd: add timer obj c4b1fafc!
RTMP_TimerListAdd: add timer obj c4b1db1c!
RTMP_TimerListAdd: add timer obj c4b1db5c!
roleoroleo commented 4 years ago

The system is similar but not enough. You can't use the hack currently released.

Now you should dump the rootfs and the home partitions.

rado0x54 commented 4 years ago

Hey @enrysan0 and @roleoroleo,

I'll use this thread before opening a new one because my camera firmware is exactly the same as mentioned in this thread. More specifically:

  1. I own a Yi Home Camera v3 (1080p) bought in the US
  2. It's labelled as 9FUS
  3. Current Firmware is 4.2.0.0F_201905241332 (but want's to upgrade to 4.2.0.0H_201909041620)
  4. The current release (9FUS 4.5.0 is not working for me)

I'd like to support this thread and dump log output + partitions, but I'm not finding any pins/pads labelled rx/tx/gnd (on either side). @enrysan0 I also don't see any on the image you provided. Would you be able to give me a hint on how you connected your serial adapter?

Update: I think the correct pins are described here: https://github.com/TheCrypt0/yi-hack-v4/issues/49#issuecomment-540715090 So I'll report back as soon as I have more info.

Thanks!

camonice commented 4 years ago

The system is similar but not enough. You can't use the hack currently released.

Now you should dump the rootfs and the home partitions.

I am following up this topic as I also have a 4FCN camera. No solution for it as far as I am aware of.

Regards, Camonice

Rocket200 commented 4 years ago

4FUS will be support soon?

roleoroleo commented 4 years ago

Probably this one: https://drive.google.com/open?id=1WwBl0n8LZpLjYdB6ZKpmh81_BBngR7LE works with 4FUS 4.2.0 but I can't guarantee it. It would be better if you dumped a backup before trying it. If you can.

camonice commented 4 years ago

Probably this one: https://drive.google.com/open?id=1WwBl0n8LZpLjYdB6ZKpmh81_BBngR7LE works with 4FUS 4.2.0 but I can't guarantee it. It would be better if you dumped a backup before trying it. If you can.

I have tried this on my 4FCN camera. It does not flash. Maybe because my firmware is newer? I cannot confirm this easily as I can not pair the camera with my phone...outside China. What about changing the file names to y203c?

roleoroleo commented 4 years ago

I will send you a 4FCN version tomorrow. Don't rename the files.

camonice commented 4 years ago

I will send you a 4FCN version tomorrow. Don't rename the files.

@roleoroleo Excellent. Thank you!

roleoroleo commented 4 years ago

Try this for 4FCN: https://drive.google.com/open?id=1YtGf1XkmTZbcl_hbOlM_xbwElNQdiG-h

roleoroleo commented 4 years ago

If it works (both 4FUS and 4FCN) i will make a new release.

enrysan0 commented 4 years ago

Hi roleoroleo, thanks for the help. I don't know how to dump the firmware. If you can suggest me a guide or how to I'll try to dump it. Are there my personal information (wifi password, Yi account and password) in the dump?

roleoroleo commented 4 years ago

See here: https://github.com/roleoroleo/yi-hack-6FUS_4.5.0/issues/10

For personal info it depends... Remove /etc/back.bin before the dump if you want to be sure.

camonice commented 4 years ago

Try this for 4FCN: https://drive.google.com/open?id=1YtGf1XkmTZbcl_hbOlM_xbwElNQdiG-h

Hi roleoroleo, my 4FCN camera still does not flash. I think it might be due to the firmware version. It was bought recently.

roleoroleo commented 4 years ago

What is the name of the file that u-boot looks for? y25? y203c? ...

camonice commented 4 years ago

What is the name of the file that u-boot looks for? y25? y203c? ...

Sorry I don’t know how to check this. I searched and found that one other user used the name of rootfs_y23 and home_y23 and managed to flash a 4FCN camera...with the wrong firmware in that case:(

roleoroleo commented 4 years ago

y23 at the moment is not supported. To support it I need a dump.

camonice commented 4 years ago

y23 at the moment is not supported. To support it I need a dump.

How can I make a dump for you without breaking the camera?

Also I found myself and other people who use Yi-Hack-V4 need to reboot frequently. My outdoor camera often turns off or the proxychain stops working without a reboot:(

Your version seems to have no such issues!

roleoroleo commented 4 years ago

My version is only for MStar platforn. If you are using v4, your camera is not a MStar.

camonice commented 4 years ago

My version is only for MStar platforn. If you are using v4, your camera is not a MStar.

I have one outdoor 6CCN, a few Yi home 1080p - 6FCN, 6FUS, 4FCN. So I am a test bed for different firmwares:)

Rocket200 commented 4 years ago

Probably this one: https://drive.google.com/open?id=1WwBl0n8LZpLjYdB6ZKpmh81_BBngR7LE works with 4FUS 4.2.0 but I can't guarantee it. It would be better if you dumped a backup before trying it. If you can.

I can not make a backup sorry. I not try to flash it now ,I won't be sure it work . but i check the Firmware on my 4FUS. My 4FUS have Firmware 4.5.0.0C_201910080934 (I not make a Firmware update)

maybe i can dump a log from it https://www.youtube.com/watch?v=fBjKTfWN4TI

roleoroleo commented 4 years ago

I can not make a backup sorry. I not try to flash it now ,I won't be sure it work . but i check the Firmware on my 4FUS. My 4FUS have Firmware 4.5.0.0C_201910080934 (I not make a Firmware update)

maybe i can dump a log from it https://www.youtube.com/watch?v=fBjKTfWN4TI

You can dump a log and make a backup with the same method. Your 4FUS should be a y203, based on firmware version.

Rocket200 commented 4 years ago

the Firmware from gdrive work with it? or i need to wait for a update? i can not dump (Not find USB-TTL)

roleoroleo commented 4 years ago

The y203c works.

Rocket200 commented 4 years ago

I not have a backup from my Cam i open the cam and i not find PINS for USB-TTL IMG_8155 what Firmware I can try to Flash? (on the picture u see y203c)

I can Flash the same Firmware (yi_home_1080p_BFUS_450_0.2.0) for my 4FUS Model ? this FW "yi_home_1080p_BFUS_450_0.2.0" works with my BFUS Model.

or u mean I can try this one "y203c_0.2.2.tgz" ?

roleoroleo commented 4 years ago

All the files with y203c suffix should work. Try 0.2.2.

Rocket200 commented 4 years ago

Thank you ! it works I try the 0.2.2 from gdrive here and it works can I check or try something with the 4FUS - FW 4.5 - yi-hack 0.2.2 ?

I have a second 4FUS I flash the same 0.2.2 or one from the 0.2 releases ?

roleoroleo commented 4 years ago

Use 0.2.2.

Rocket200 commented 4 years ago

can I use a new 0.2.2 for my BFUS Cams? I like the new settings in 0.2.2 (bevor Reboot now Maintenance)

roleoroleo commented 4 years ago

Yes you can use it. Wait for my official release.

camonice commented 4 years ago

Yes you can use it. Wait for my official release.

I opened the back of my 4FCN camera and took a photo. Is the chip the right one? I also checked the front of the board, and it says "Y25....2018/01/28". Am I safe to use the release 0.2.2? Does it include the proxychain? Many thanks!

roleoroleo commented 4 years ago

I think you can use 0 2 2 but I never tried it on your model. Wait for official release.

borodiliz commented 4 years ago

Tested v0.2.2 on a 4FUS Firmware 4.5.0.0C_201910080934. It works like a charm!

roleoroleo commented 4 years ago

home or dome?

borodiliz commented 4 years ago

home or dome?

Product Name: Yi 1080p Home Camera Model: YYS.2016 QC Pass date: 2019.11 Recently purchased at amazon.es

roleoroleo commented 4 years ago

Did you use y203c files?

borodiliz commented 4 years ago

Did you use y203c files?

Yes, y203c files extracted from 0.2.2 release

simox83971 commented 4 years ago

I tryed on Yi Home Camera 3 (4FUS), but it does not work... Is there something wrong or not supported yet?

roleoroleo commented 4 years ago

Which firmware version do you have ?

enrysan0 commented 4 years ago

Same problem here. I tried to use "y203c_0.2.2" version but didn't work: the camera simply booted as normal. My firmware is 4.2.0.0H_201909041620. (edit: last version available)

(@roleoroleo regarding the dump of the firmware i didn't understand the information in the link so i gave up)

roleoroleo commented 4 years ago

I think you have to use y25_0.2.2. Regarding the dump I could help you if you want.

enrysan0 commented 4 years ago

Probably this one: https://drive.google.com/open?id=1WwBl0n8LZpLjYdB6ZKpmh81_BBngR7LE works with 4FUS 4.2.0 but I can't guarantee it. It would be better if you dumped a backup before trying it. If you can.

I tried this but not lucky.. The Cam is cycling trhought solid led yellow to blinking blue led to solid yellow. Is there any procedure to follow before I totally brick the cam? Thanks

enrysan0 commented 4 years ago

This is the log i found in the SD Card:

[
][1/1/0:6:44:934]: dispatch.c(main-5243) hw_type(2)
[
][1/1/0:6:47:490]: rmm.c(msg_proc-4523) pid[193][
][1/1/0:6:47:578]: dispatch.c(main-5303) open_ptz fail[
][1/1/0:6:47:712]: dispatch.c(get_config-1223) got sn(XXXXXXXXXXXXXXXXXXXXXX)[
][1/1/0:6:47:713]: dispatch.c(get_config-1224) got pwd(XXXXXXXXXXXXXXXXXXXXXX)[
][1/1/0:6:47:713]: dispatch.c(get_config-1225) got ssid(XXXXXXXXXXXXXXXXXXXXXX)[
][1/1/0:6:47:713]: dispatch.c(get_config-1226) got tnp_init_string(MMFBJPLDIEEPKPHOOIFEPNEHHDCJFMGOHJENKLIHIJBKDABIPMIIAONIPBCLBOKOPIKPDKPFNJDPAIDKBE)[
][1/1/0:6:47:748]: dispatch.c(choose_server-650) in choose_server, region_id = 17, api_server = https://api.us.xiaoyi.com, log_server = http://log.us.xiaoyi.com, sname = familymonitor-y25, dlproto = mius
[
][1/1/0:6:47:749]: dispatch.c(choose_server-650) in choose_server, region_id = 16, api_server = https://api.eu.xiaoyi.com, log_server = http://log.eu.xiaoyi.com, sname = familymonitor-y25, dlproto = mieu
[
][1/1/0:6:47:758]: dispatch.c(main-5385) init ok, cost time(2822 ms)[
][1/1/0:6:48:528]: rmm.c(init_font-972) font:/home/base/iso8859-1-24x48.bin
[
][1/1/0:6:48:590]: rmm.c(init_font-984) filesize=36864
[
][1/1/0:6:48:590]: rmm.c(init_font-1004) init font /home/base/iso8859-1-24x48.bin ptr size(4)[
][1/1/0:6:48:591]: rmm.c(init_font-972) font:/home/base/iso8859-1-8x16.bin
[
][1/1/0:6:48:591]: rmm.c(init_font-984) filesize=4096
[
][1/1/0:6:48:591]: rmm.c(init_font-1004) init font /home/base/iso8859-1-8x16.bin ptr size(4)[
][1/1/0:6:48:799]: dispatch.c(do_monitor_wifi-1668) wifi disconnected, now reconnect wifi
[
][1/1/0:6:49:609]: rmm.c(rmm_init_isp-1480) pSensorID =8757 S C 2 2
[
][1/1/0:6:51:117]: rmm.c(send_start_recorde_msg-3957) msg snd success[
][1/1/0:6:51:118]: rmm.c(motion_proc-5155) send start recorde detect 
[
][1/1/0:6:51:517]: rmm.c(send_start_recorde_msg-3957) msg snd success[
][1/1/0:6:51:517]: rmm.c(motion_proc-5155) send start recorde detect 
[
][1/1/0:6:51:951]: cloud.c(sys_init-5517) open share mem ok
[
][1/1/0:6:52:204]: oss.c(main-2957) oss stream = ./oss_lapse, venc chn = 0x2000[
][1/1/0:6:52:317]: oss.c(main-2976) fshare_open ok[
][1/1/0:6:52:317]: oss.c(main-2957) oss stream = ./oss_fast, venc chn = 0x1000[
][1/1/0:6:52:473]: oss.c(main-2976) fshare_open ok[
][1/1/0:6:52:474]: oss.c(main-2957) oss stream = ./oss, venc chn = 0x400[
][1/1/0:6:52:649]: oss.c(main-2976) fshare_open ok[
][1/1/0:6:52:703]: p2p_tnp.c(main-6653) fshare_open ok[
][1/1/0:6:52:806]: p2p_tnp.c(p2p_set_tnp_init_status-2112) p2p_set_tnp_init_status 1 send_msg ok!
[
][1/1/0:6:52:911]: watch_process.c(get_watch_info-116) check_interval=10
[
][1/1/0:6:53:104]: watch_process.c(get_watch_info-134) process=dispatch;cmd=cd /home/app;./dispatch &;
[
][1/1/0:6:53:104]: watch_process.c(get_watch_info-134) process=cloud;cmd=cd /home/app;./cloud &;
[
][1/1/0:6:53:104]: watch_process.c(get_watch_info-134) process=rmm;cmd=reboot;
[
][1/1/0:6:53:104]: watch_process.c(get_watch_info-134) process=p2p_tnp;cmd=cd /home/app;./p2p_tnp &;
[
][1/1/0:6:53:104]: watch_process.c(get_watch_info-134) process=mp4record;cmd=cd /home/app;./mp4record &;
[
][1/1/0:6:53:104]: watch_process.c(get_watch_info-134) process=arp_test;cmd=cd /home/app;./arp_test &;
[
][1/1/0:6:53:105]: watch_process.c(get_watch_info-134) process=oss;cmd=cd /home/app;./oss &;
[
][1/1/0:6:53:105]: watch_process.c(get_watch_info-134) process=oss_fast;cmd=cd /home/app;./oss_fast &;
[
][1/1/0:6:53:105]: watch_process.c(get_watch_info-134) process=oss_lapse;cmd=cd /home/app;./oss_lapse &;
[
][12/1/15:56:48:97]: dispatch.c(p_worker-3292) DISPATCH_SET_DEFAULT_TIME 1575215808[
][12/1/15:56:48:194]: mp4record.c(main-1198) init_finish(1), start_with_reset(0)[
][12/1/15:56:48:264]: mp4record.c(main-1200) mp4 mode start init_finish[
][12/1/15:56:48:265]: mp4record.c(main-1206) fshare_open ok[
][12/1/15:56:53:420]: rmm.c(send_start_recorde_msg-3957) msg snd success[
][12/1/15:56:53:531]: rmm.c(motion_proc-5155) send start recorde detect 
[
][12/1/15:56:53:774]: rmm.c(send_start_recorde_msg-3957) msg snd success[
][12/1/15:56:53:774]: rmm.c(motion_proc-5155) send start recorde detect 
[
][12/1/15:56:54:400]: dispatch.c(do_monitor_wifi-1610) wpa may crashed, now reset
[
][12/1/15:56:54:514]: dispatch.c(do_monitor_wifi-1615) no usb dev
roleoroleo commented 4 years ago

The log doesn't show nothing strange.

We have to restore the original fw. If you have another cam of the same model we can dump it. Or we could find another user.

enrysan0 commented 4 years ago

so is this normal?

[12/1/15:56:54:400]: dispatch.c(do_monitor_wifi-1610) wpa may crashed, now reset
[
][12/1/15:56:54:514]: dispatch.c(do_monitor_wifi-1615) no usb dev

Unfortunally I own only one YI Home v3 4FUS. I hope some other user could help me..

roleoroleo commented 4 years ago

Try to re-pair the app. Or a reset.

enrysan0 commented 4 years ago

I tried a reset using the small pin-hole behind the camera. Put the camera side to the router, followed the normal procedure with scanning of the qr code. At the end the camera always say "waiting for connect" as it couldn't see/connect to the wifi.

The log i found in the SDCard card contain a lot of crashes Cloud/p2p/wpa:

[
][1/1/0:0:9:685]: dispatch.c(main-5243) hw_type(2)
[
][1/1/0:0:12:236]: rmm.c(msg_proc-4523) pid[193][
][1/1/0:0:12:331]: dispatch.c(main-5303) open_ptz fail[
][1/1/0:0:12:518]: dispatch.c(get_config-1223) got sn(XXXXXX_REMOVED_XXXXXXXX)[
][1/1/0:0:12:518]: dispatch.c(get_config-1224) got pwd()[
][1/1/0:0:12:518]: dispatch.c(get_config-1225) got ssid()[
][1/1/0:0:12:518]: dispatch.c(get_config-1226) got tnp_init_string()[
][1/1/0:0:12:518]: dispatch.c(get_config-1234) reset because no wifi config[
][1/1/0:0:12:518]: dispatch.c(send_saveconfig_msg-426) send_saveconfig_msg msg snd success[
][1/1/0:0:12:518]: dispatch.c(get_config-1281) get_config save conf
[
][1/1/0:0:12:518]: dispatch.c(choose_server-650) in choose_server, region_id = 17, api_server = https://api.us.xiaoyi.com, log_server = http://log.us.xiaoyi.com, sname = familymonitor-y25, dlproto = mius
[
][1/1/0:0:12:518]: dispatch.c(choose_server-650) in choose_server, region_id = 16, api_server = https://api.eu.xiaoyi.com, log_server = http://log.eu.xiaoyi.com, sname = familymonitor-y25, dlproto = mieu
[
][1/1/0:0:12:528]: dispatch.c(main-5385) init ok, cost time(2840 ms)[
][1/1/0:0:12:528]: dispatch.c(save_config-1024) got pwd()()[
][1/1/0:0:12:529]: dispatch.c(save_config-1025) got ssid()()[
][1/1/0:0:12:529]: dispatch.c(save_config-1026) config save finish 1[
][1/1/0:0:12:829]: dispatch.c(p_worker-3204) save_config[
][1/1/0:0:13:274]: rmm.c(init_font-972) font:/home/base/iso8859-1-24x48.bin
[
][1/1/0:0:13:360]: rmm.c(init_font-984) filesize=36864
[
][1/1/0:0:13:360]: rmm.c(init_font-1004) init font /home/base/iso8859-1-24x48.bin ptr size(4)[
][1/1/0:0:13:360]: rmm.c(init_font-972) font:/home/base/iso8859-1-8x16.bin
[
][1/1/0:0:13:360]: rmm.c(init_font-984) filesize=4096
[
][1/1/0:0:13:360]: rmm.c(init_font-1004) init font /home/base/iso8859-1-8x16.bin ptr size(4)[
][1/19/6:41:36:97]: dispatch.c(p_worker-3292) DISPATCH_SET_DEFAULT_TIME 1453185696[
][1/19/6:41:36:790]: rmm.c(rmm_init_isp-1480) pSensorID =8757 S C 2 2
[
][1/19/6:41:38:773]: cloud.c(sys_init-5517) open share mem ok
[
][1/19/6:41:39:3]: oss.c(main-2957) oss stream = ./oss_fast, venc chn = 0x1000[
][1/19/6:41:39:138]: oss.c(main-2976) fshare_open ok[
][1/19/6:41:39:138]: oss.c(main-2957) oss stream = ./oss, venc chn = 0x400[
][1/19/6:41:39:255]: oss.c(main-2957) oss stream = ./oss_lapse, venc chn = 0x2000[
][1/19/6:41:39:371]: oss.c(main-2976) fshare_open ok[
][1/19/6:41:39:371]: oss.c(main-2976) fshare_open ok[
][1/19/6:41:39:456]: p2p_tnp.c(main-6653) fshare_open ok[
][1/19/6:41:39:540]: p2p_tnp.c(p2p_set_tnp_init_status-2112) p2p_set_tnp_init_status 1 send_msg ok!
[
][1/19/6:41:39:818]: watch_process.c(get_watch_info-116) check_interval=10
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=dispatch;cmd=cd /home/app;./dispatch &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=cloud;cmd=cd /home/app;./cloud &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=rmm;cmd=reboot;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=p2p_tnp;cmd=cd /home/app;./p2p_tnp &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=mp4record;cmd=cd /home/app;./mp4record &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=arp_test;cmd=cd /home/app;./arp_test &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=oss;cmd=cd /home/app;./oss &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=oss_fast;cmd=cd /home/app;./oss_fast &;
[
][1/19/6:41:39:903]: watch_process.c(get_watch_info-134) process=oss_lapse;cmd=cd /home/app;./oss_lapse &;
[
][1/19/6:41:39:903]: dispatch.c(do_mq_process-5058) invalid msg 0x1002
[
][1/19/6:41:40:11]: rmm.c(send_wait_msg-619) msg snd success[
][1/19/6:41:41:818]: rmm.c(msg_proc-4563) got RMM_SPEAK_WAIT[
][1/19/6:41:49:820]: watch_process.c(check_watch_info-171) arp_test crashed![
][1/19/6:41:52:320]: rmm.c(zbar_proc-4407) decoded QR-Code symbol "XXXXXX_REMOVED_XXXXXXXX"
[
][1/19/6:41:52:431]: rmm.c(trans_info-441) trans_json info=b=XXXXXX_REMOVED_XXXXXXXX
[
][1/19/6:41:52:432]: rmm.c(trans_info-513) trans_json result=XXXXXX_REMOVED_XXXXXXXX
[
][1/19/6:41:52:432]: rmm.c(trans_info-441) trans_json info=b=XXXXXX_REMOVED_XXXXXXXX
[
][1/19/6:41:52:432]: rmm.c(trans_info-513) trans_json result=XXXXXX_REMOVED_XXXXXXXX
[
][1/19/6:41:52:432]: rmm.c(trans_info-441) trans_json info=b=XXXXXX_REMOVED_XXXXXXXX
[
][1/19/6:41:52:432]: rmm.c(trans_info-513) trans_json result=XXXXXX_REMOVED_XXXXXXXX
[
][1/19/6:41:52:432]: rmm.c(zbar_proc-4430) rmm got /tmp/got_wpa ssid(XXXXXX_REMOVED_XXXXXXXX) pwd(XXXXXX_REMOVED_XXXXXXXX) bind(XXXXXX_REMOVED_XXXXXXXX)
[
][1/19/6:41:52:432]: dispatch.c(do_mq_process-5058) invalid msg 0x1005
[
][1/19/6:41:52:509]: rmm.c(send_scanok_msg-646) msg snd success[
][1/19/6:41:52:562]: dispatch.c(choose_server-650) in choose_server, region_id = 16, api_server = https://api.eu.xiaoyi.com, log_server = http://log.eu.xiaoyi.com, sname = familymonitor-y25, dlproto = mieu
[
][1/19/6:41:52:627]: rmm.c(send_wifi_conf_msg-676) msg snd success[
][1/19/6:41:52:713]: dispatch.c(do_mq_process-3413) got pwd(XXXXXX_REMOVED_XXXXXXXX)[
][1/19/6:41:52:844]: dispatch.c(send_connectting_msg-138) msg snd success[
][1/19/6:41:52:845]: dispatch.c(do_mq_process-5058) invalid msg 0x1004
[
][1/19/6:41:52:845]: dispatch.c(do_monitor_wifi-1668) wifi disconnected, now reconnect wifi
[
][1/19/6:41:54:694]: rmm.c(msg_proc-4648) got RMM_SPEAK_SCAN_OK[
][1/19/6:41:56:656]: rmm.c(msg_proc-4583) got RMM_SPEAK_CONNECTTING[
][1/19/6:41:59:839]: watch_process.c(check_watch_info-171) cloud crashed![
][1/19/6:41:59:892]: watch_process.c(check_watch_info-171) p2p_tnp crashed![
][1/19/6:42:1:852]: dispatch.c(do_monitor_wifi-1610) wpa may crashed, now reset
[
][1/19/6:42:1:944]: dispatch.c(do_monitor_wifi-1615) no usb dev