Bricked R8000

6 posts / 0 new
Last post
mike_l
mike_l's picture
Bricked R8000

Hey All,

New hear hoping someone has the answer.

Flashed initial tomato to stock firmware on my netgear R8000.

Then upgraded to latest Arm-137 AIO . RIght after that stuck in boot loop.

Tried multiple resets does no luck.

Started continuous ping.. After 15seconds I get 4 pings from router and then nothing.

Hook up my usb-ttl. Can see boot sequence but cant break boot with Ctrl+C .

Tried many times and nothing. Tried with flow control on and off.

Do I have a new door stop?

Or does anyone know a way around this?

 

Thanks guys

microchip
microchip's picture
I'm sorry but I have a hard

I'm sorry but I have a hard time following what you're saying. Can you explain in proper English, please? The flashing process is a very delicate procedure so we need to know the exact steps done, preferably in proper English

mike_l
mike_l's picture
Thanks for replying microchip

Thanks for replying microchip.

I have an R8000 that when powered on has amber power light.

If I set a constant ping to it, I will get a total of 4 TTL=100 back but thats it.

I have tried tftp an image file to it via windows, and I have also tried using usb-ttl adapter.

When using the serial connection I see the boot sequence, I keep hitting CTRL-C but never get the CFE prompt.

Is there any other process anyone knows about to de-brick?

mike_l
mike_l's picture
Below is also the out put

Below is also the out put when connected to serial.

I have been hammering ctrl-c from instant it turns on until reboot with no luck getting the CFE prompt.

 

 

 

Decompressing...done
Digital core power voltage set to 1.0V

SHMOO VER 1.13

PKID07DC06011801080000000000001A103F01000000

S300001D3
000013C0

RDLYW0 00000004

RDENW0 00000034

RDQSW0

    0000000000111111111122222222223333333333444444444455555555556666
    0123456789012345678901234567890123456789012345678901234567890123
 00 ---------+++++++++++++++++++++++X+++++++++++++++++++++++--------
 01 --------------++++++++++++++++++++++X+++++++++++++++++++++------
 02 ---------+++++++++++++++++++++++X+++++++++++++++++++++++--------
 03 --------+++++++++++++++++++++++X++++++++++++++++++++++----------
 04 ----++++++++++++++++++++++X++++++++++++++++++++++---------------
 05 ----------+++++++++++++++++++++++X+++++++++++++++++++++++-------
 06 ------++++++++++++++++++++++X+++++++++++++++++++++--------------
 07 ------------++++++++++++++++++++++X++++++++++++++++++++++-------
 08 ------++++++++++++++++++++++X++++++++++++++++++++++-------------
 09 -----------++++++++++++++++++++++++X++++++++++++++++++++++++----
 10 -------+++++++++++++++++++++++X++++++++++++++++++++++-----------
 11 -------------+++++++++++++++++++++++X++++++++++++++++++++++-----
 12 -----+++++++++++++++++++++++X+++++++++++++++++++++++------------
 13 ------------++++++++++++++++++++++X++++++++++++++++++++++-------
 14 --------+++++++++++++++++++++++X+++++++++++++++++++++++---------
 15 ------------+++++++++++++++++++++++X++++++++++++++++++++++------

PW0

    0000000000111111111122222222223333333333444444444455555555556666
    0123456789012345678901234567890123456789012345678901234567890123
 00 ++++++++++++++++++++++++++++X+++++++++++++++++++++++++++--------
 01 ---+++++++++++++++++++++++++++X+++++++++++++++++++++++++++------
 02 ++++++++++++++++++++++++++++X+++++++++++++++++++++++++++--------
 03 +++++++++++++++++++++++++++X++++++++++++++++++++++++++----------
 04 ++++++++++++++++++++++++X++++++++++++++++++++++++---------------
 05 ++++++++++++++++++++++++++++X++++++++++++++++++++++++++++-------
 06 +++++++++++++++++++++++++X++++++++++++++++++++++++--------------
 07 --+++++++++++++++++++++++++++X+++++++++++++++++++++++++++-------
 08 +++++++++++++++++++++++++++X++++++++++++++++++++++++++----------
 09 ----++++++++++++++++++++++++++++X++++++++++++++++++++++++++++---
 10 +++++++++++++++++++++++++++X+++++++++++++++++++++++++++---------
 11 ----++++++++++++++++++++++++++++X++++++++++++++++++++++++++++---
 12 +++++++++++++++++++++++++++X++++++++++++++++++++++++++----------
 13 -----++++++++++++++++++++++++++X++++++++++++++++++++++++++------
 14 ++++++++++++++++++++++++++++X++++++++++++++++++++++++++++-------
 15 ---++++++++++++++++++++++++++++X+++++++++++++++++++++++++++-----

NW0

    0000000000111111111122222222223333333333444444444455555555556666
    0123456789012345678901234567890123456789012345678901234567890123
 00 --------++++++++++++++++++++++++X+++++++++++++++++++++++--------
 01 -------------++++++++++++++++++++++++X+++++++++++++++++++++++---
 02 ----------+++++++++++++++++++++++X+++++++++++++++++++++++-------
 03 --------+++++++++++++++++++++++X+++++++++++++++++++++++---------
 04 ----+++++++++++++++++++++++X+++++++++++++++++++++++-------------
 05 ----------++++++++++++++++++++++++X++++++++++++++++++++++++-----
 06 ------++++++++++++++++++++++X++++++++++++++++++++++-------------
 07 ------------++++++++++++++++++++++++X++++++++++++++++++++++++---
 08 ------++++++++++++++++++++++X+++++++++++++++++++++--------------
 09 -----------++++++++++++++++++++++++X++++++++++++++++++++++++----
 10 -------+++++++++++++++++++++++X++++++++++++++++++++++-----------
 11 -------------+++++++++++++++++++++++X++++++++++++++++++++++-----
 12 -----++++++++++++++++++++++++X+++++++++++++++++++++++-----------
 13 ------------++++++++++++++++++++++X++++++++++++++++++++++-------
 14 --------+++++++++++++++++++++++X+++++++++++++++++++++++---------
 15 -----------+++++++++++++++++++++++X+++++++++++++++++++++++------

WRDQW0

    0000000000111111111122222222223333333333444444444455555555556666
    0123456789012345678901234567890123456789012345678901234567890123
 00 +++++++++++++++++++++++X+++++++++++++++++++++++--------++++++++-
 01 ++++++++++++++++++++++++X++++++++++++++++++++++++-------+++++++-
 02 +++++++++++++++++++++++X+++++++++++++++++++++++-------+++++++++-
 03 +++++++++++++++++++++++X++++++++++++++++++++++--------+++++++++-
 04 +++++++++++++++++++++X++++++++++++++++++++-----------++++++++++-
 05 ++++++++++++++++++++++++X+++++++++++++++++++++++-------++++++++-
 06 +++++++++++++++++++++X+++++++++++++++++++++----------++++++++++-
 07 ++++++++++++++++++++++++X+++++++++++++++++++++++-------++++++++-
 08 +++++++++++++++++++++++X++++++++++++++++++++++---------++++++++-
 09 -+++++++++++++++++++++++X+++++++++++++++++++++++-----------++++-
 10 +++++++++++++++++++++++X+++++++++++++++++++++++---------+++++++-
 11 ---++++++++++++++++++++++X++++++++++++++++++++++-------------++-
 12 ++++++++++++++++++++++++X+++++++++++++++++++++++-------++++++++-
 13 --+++++++++++++++++++++++X+++++++++++++++++++++++-----------+++-
 14 ++++++++++++++++++++++++X+++++++++++++++++++++++---------++++++-
 15 --+++++++++++++++++++++++X++++++++++++++++++++++------------+++-

WRDMW0 00000022
WRDMW0 00000024

ADDR

    0000000000111111111122222222223333333333444444444455555555556666
    0123456789012345678901234567890123456789012345678901234567890123
 00 +++++++++++++++++++S+++++++++++X++++++++++++++++++++++++++++++++

Decompressing...done

CFE for Foxconn Router R8000 version: v1.0.8
Build Date: Fri May 30 15:03:06 CST 2014
Init Arena
Init Devs.
Boot up from NAND flash...
Bootcode Boot partition size = 524288(0x80000)
DDR Clock: 800 MHz
Info: DDR frequency set from clkfreq=1000,*800*
et2: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller 7.14.43.2 (r474543)
CPU type 0x0: 1000MHz
Tot mem: 262144 KBytes

Device eth0:  hwaddr E8-FC-AF-F9-69-A8, ipaddr 192.168.1.1, mask 255.255.255.0
        gateway not set, nameserver not set
Checking crc...Loader:raw Filesys:raw Dev:nflash0.os File: Options:(null)
Loading: .... 4304128 bytes read
Entry at 0x00008000
Closing network.
Starting program at 0x00008000
console [ttyS0] enabled, bootconsole disabled
serial8250.0: ttyS1 at MMIO 0x18000400 (irq = 117) is a 16550
brd: module loaded
loop: module loaded
pflash: found no supported devices
bcmsflash: found no supported devices
Boot partition size = 524288(0x80000)
lookup_nflash_rootfs_offset: offset = 0x200000
nflash: squash filesystem with lzma found at block 29
Creating 5 MTD partitions on "nflash":
0x000000000000-0x000000080000 : "boot"
0x000000080000-0x000000200000 : "nvram"
0x000000200000-0x000004200000 : "linux"
0x0000003b4d28-0x000004000000 : "rootfs"
0x000002200000-0x000002240000 : "board_data"
PPP generic driver version 2.4.2
PPP MPPE Compression module registered
NET: Registered protocol family 24
PPTP driver version 0.8.5
=== PPTP init ===
u32 classifier
    Actions configured
Netfilter messages via NETLINK v0.30.
nf_conntrack version 0.5.0 (3989 buckets, 15956 max)
ctnetlink v0.93: registering with nfnetlink.
xt_time: kernel timezone is -0000
ip_tables: (C) 2000-2006 Netfilter Core Team
TCP cubic registered
NET: Registered protocol family 10
ip6_tables: (C) 2000-2006 Netfilter Core Team
NET: Registered protocol family 17
L2TP core driver, V2.0
PPPoL2TP kernel driver, V2.0
802.1Q VLAN Support v1.8 Ben Greear <[email protected]>
All bugs added by David S. Miller <[email protected]>
Registering the dns_resolver key type
Northstar brcmnand NAND Flash Controller driver, Version 0.1 (c) Broadcom Inc. 2012
NAND device: Manufacturer ID: 0x01, Chip ID: 0xf1 (AMD NAND 128MiB 3,3V 8-bit)
Spare area=64 eccbytes 56, ecc bytes located at:
 2 3 4 5 6 7 8 9 10 11 12 13 14 15 18 19 20 21 22 23 24 25 26 27 28 29 30 31 34 35 36 37 38 39 40 41 42 43 44 45 46 47 50 51 52 53 54 55 56 57 58 59 60 61 62 63
Available 7 bytes at (off,len):
(1,1) (16,2) (32,2) (48,2) (0,0) (0,0) (0,0) (0,0)
Scanning device for bad blocks
Options: NO_AUTOINCR,NO_READRDY,BBT_SCAN2NDPAGE,
Creating 1 MTD partitions on "brcmnand":
0x000004000000-0x000008000000 : "brcmnand"
VFS: Mounted root (squashfs filesystem) readonly on device 31:3.
devtmpfs: mounted
Freeing init memory: 216K

Hit ENTER for console...

ctf: module license 'Proprietary' taints kernel.
Disabling lock debugging due to kernel taint
et_module_init: passivemode set to 0x0
et_module_init: txworkq set to 0x0
et_module_init: et_txq_thresh set to 0x400
et_module_init: et_rxlazy_timeout set to 0x3e8
et_module_init: et_rxlazy_framecnt set to 0x20
fwd0: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller 7.14.43.40 (r527781)
fwd1: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller 7.14.43.40 (r527781)
eth0: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller 7.14.43.40 (r527781)
dhd_module_init in
dhd_queue_budget = 256
dhd_sta_threshold = 2048
no wifi platform data, skip
PCI_PROBE:  bus 1, slot 0,vendor 14E4, device AA52(good PCI location)
PCI: Enabling device 0001:01:00.0 (0140 -> 0142)
DHD: dongle ram size is set to 983040(orig 983040) at 0x180000
dhd_attach(): thread:dhd_watchdog_thread:2f6 started
dhd_deferred_work_init: work queue initialized
Dongle Host Driver, version 1.194.33 (r526004)
Compiled in drivers/net/wireless/bcmdhd on Jun 17 2015 at 11:27:36
Register interface [eth1]  MAC: 00:90:4c:11:22:33

dhdpcie_download_code_array: Download, Upload and compare succeeded (43602a1-roml/pcie-ag-splitrx-fdap-mbss-mfp-wl11k-wl11u-txbf-pktctx-amsdutx-ampduretry-chkd2hdma-proptxstatus, 2015.06.17.111523, 2015/06/17 11:15:23).
dhdpcie_bus_write_vars: Download, Upload and compare of NVRAM succeeded.
dhdpcie_readshared: address (0xfe1a01e5) of pciedev_shared invalid
Waited 5006383 usec, dongle is not ready
dhd_bus_init :Shared area read failed
dhd_bus_start, dhd_bus_init failed -1
dhdpcie_init: dhd_bud_start() failed
dhdpcie_readshared: address (0xfe1a01e5) of pciedev_shared invalid
Waited 5006383 usec, dongle is not ready
Enforcing kernel panic
Unable to handle kernel NULL pointer dereference at virtual address 00000000
pgd = c0004000
[00000000] *pgd=00000000
Internal error: Oops: 817 [#1] PREEMPT SMP
last sysfs file: /sys/kernel/uevent_seqnum
module:  dhd     bf02e000        799274
module:  et      bf01b000        48925
module:  igs     bf013000        11927
module:  emf     bf00a000        15169
module:  ctf     bf000000        16424
Modules linked in: dhd(+) et(P) igs(P) emf(P) ctf(P)
CPU: 1    Tainted: P             (2.6.36.4brcmarm #3)
PC is at dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd]
LR is at dhdpcie_bus_process_mailbox_intr+0x17c/0x1e8 [dhd]
pc : [<bf041440>]    lr : [<bf041460>]    psr: 20000113
sp : cf83ded0  ip : c044aee4  fp : 00000000
r10: c003c1d4  r9 : c0450f20  r8 : c0455cd8
r7 : bf05cd00  r6 : 00000000  r5 : 00000100  r4 : cf9d3000
r3 : 00000000  r2 : cf83c000  r1 : 60000113  r0 : 00000019
Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment kernel
Control: 10c53c7d  Table: 8fb8004a  DAC: 00000017
Process swapper (pid: 0, stack limit = 0xcf83c270)
Stack: (0xcf83ded0 to 0xcf83e000)
dec0:                                     00000000 cf9d3000 00000000 b83ef180
dee0: cf83c000 cf9d3000 00000100 00000000 cf83c000 bf051d08 00000100 bf05cd00
df00: ce680000 ce683898 00000000 bf03324c ce683894 c006955c c0069450 00000001
df20: c0400058 cf83c000 00000103 c003c148 c0400040 c0450f20 00000001 c03c1330
df40: d0810000 c0057c94 00000006 0000000a 00000008 cf83c000 c0455cd8 c003c9d0
df60: cf83c000 00000000 cf83c000 0000001f 00000000 c0069d00 000000a3 c03c0ec0
df80: ffffffff f0100100 000000a3 00000002 00000001 c03c09e8 00000002 cf922d00
dfa0: cf83dfe0 00000000 cf83c000 c04230a8 c040ab80 c0423214 80000000 413fc090
dfc0: 0000001f 00000000 00000000 cf83dfe0 c003fbe4 c003fbe8 60000013 ffffffff
dfe0: c003fbc4 c003fd88 8f84806a 0000001f 10c03c7d 80008148 ed57ffef ffffffff
[<bf041440>] (PC is at dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd])
[<bf041440>] (dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd]) from [<bf051d08>] (dhd_bus_dpc+0xc8/0x150 [dhd])
unwind: Index not found bf051d08
Code: e5973000 e3130001 1a000006 e3a03000 (e5833000)
---[ end trace 42161ca811e67e97 ]---
Kernel panic - not syncing: Fatal exception in interrupt
[<c0044ff8>] (unwind_backtrace+0x0/0xf8) from [<c02f979c>] (panic+0x7c/0x1a8)
[<c02f979c>] (panic+0x7c/0x1a8) from [<c00426f8>] (die+0x1ac/0x1dc)
[<c00426f8>] (die+0x1ac/0x1dc) from [<c0046390>] (__do_kernel_fault+0x6c/0x8c)
[<c0046390>] (__do_kernel_fault+0x6c/0x8c) from [<c0046500>] (do_page_fault+0x150/0x1ec)
[<c0046500>] (do_page_fault+0x150/0x1ec) from [<c003e3a4>] (do_DataAbort+0x30/0x9c)
[<c003e3a4>] (do_DataAbort+0x30/0x9c) from [<c03c098c>] (__dabt_svc+0x4c/0x60)
Exception stack(0xcf83de88 to 0xcf83ded0)
de80:                   00000019 60000113 cf83c000 00000000 cf9d3000 00000100
dea0: 00000000 bf05cd00 c0455cd8 c0450f20 c003c1d4 00000000 c044aee4 cf83ded0
dec0: bf041460 bf041440 20000113 ffffffff
[<c03c098c>] (__dabt_svc+0x4c/0x60) from [<bf041440>] (dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd])
[<bf041440>] (dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd]) from [<bf051d08>] (dhd_bus_dpc+0xc8/0x150 [dhd])
unwind: Index not found bf051d08
CPU0: stopping
Rebooting in 3 seconds..[<c0044ff8>] (unwind_backtrace+0x0/0xf8) from [<c003e334>] (do_IPI+0x114/0x154)
[<c003e334>] (do_IPI+0x114/0x154) from [<c03c09e8>] (__irq_svc+0x48/0xe8)
Exception stack(0xc03fff78 to 0xc03fffc0)
ff60:                                                       c8207020 cf9e3600
ff80: c03fffc0 00000000 c03fe000 c04230a8 c040ab80 c040ab78 80000000 413fc090
ffa0: 0000001f 00000000 00000000 c03fffc0 c003fbe4 c003fbe8 60000013 ffffffff
[<c03c09e8>] (__irq_svc+0x48/0xe8) from [<c003fbe8>] (default_idle+0x24/0x28)
[<c003fbe8>] (default_idle+0x24/0x28) from [<c003fd88>] (cpu_idle+0x70/0xa4)
[<c003fd88>] (cpu_idle+0x70/0xa4) from [<c0008e8c>] (start_kernel+0x3cc/0x42c)
[<c0008e8c>] (start_kernel+0x3cc/0x42c) from [<80008148>] (0x80008148)

noyze
noyze's picture
Just a shot in the dark, but

Just a shot in the dark, but have you tried pressing "enter"?

" devtmpfs: mounted

Freeing init memory: 216K

Hit ENTER for console...

ctf: module license 'Proprietary' taints kernel.
Disabling lock debugging due to kernel taint "

oasizfyre
oasizfyre's picture
lol ^

lol ^