1 (edytowany przez smereka 2023-05-19 08:14:05)

Temat: Telekom Speed Home WLAN 40823475

Wpadł w moje ręce ów sprzęt. Jako, że kupiłem go za grosze, naprawiłem i sobie testuje to pomyślałem, że podzielę się podstawowymi informacjami. Może kogoś zainteresuje.

https://i.ibb.co/0mn2wZp/20230209-142239.jpg
https://i.ibb.co/3TRRX0F/tyl.png
https://i.ibb.co/GCWpLKG/20230209-141845.jpg
https://i.ibb.co/wwbfHQz/20230209-141831.jpg
https://i.ibb.co/p1VvqF5/20230209-141807.jpg





To coś jest na broadcomie na ax4800 a przynajmniej tak gdzieś wyczytałem u producenta. Całkiem fajnie działa. Zasięg troszkę słabszy niż xiaomi ax3600. Urządzenie uszykuje adres po dhcp ale samo nie stanowi bramy do uprzedzeń do niego podłączonych. Nie ma opcji zmienić nic oprócz nazwy wifi, kanału i hasła. Ja testowałem we współpracy z zyxelem nr7101 i kartę plusa więc te 150 co mogłem uzyskać to tyle na 5GHz było.

Jak go wyrwałem za kilkanaście złotych i w mojej ocenie to tak z 50zł jest wart jak na sprzęt z ax jako takim wink więcej bym nie dał no chyba, że byłoby openwrt a nie ma i nie będzie no bo broadcom.

Wypatroszyłem go na tyle na ile się dało. Czarnych radiatorów nie zrywałem bo po odkręcaniu śrub ciężko szło a nie chciałem go uszkodzić skoro przed chwilą naprawiłem big_smile


Log z konsoli uart:

----
BTRM
V1.1
CACH
CODE
ZBSS
MAIN
OTP?
REF?
REFP
RTF?
RTFP
OTPP
FSBT
NAND
IMG?
IMGL
UHD?
UHDP
RLO?
RLOP
AHD?
ROT?
ROTA
MID?
MIDP
AHDP
SBI?
SBIA
PASS
----

U-Boot SPL 2019.07 (Feb 01 2021 - 20:29:11 +0800)
Strap register: 0x7fffffc2
Board is FLD secure
$SPL: 5.04L.02@314035 $
Apply trim code 0x2 reg 0x8 from otp to LDO controller...
nand flash device id 0xeff10095, total size 128MB
block size 128KB, page size 2048 bytes, spare area 64 bytes
ECC BCH-4
FFinit done
find magic number 0x75456e76 at address 0x40000
blob not found for magic 0xcb00cb sel 0x20000327!
FFinit find magic number 0xcb00cb at address 0x45000
reading blob from 0x45000 offset 0x1c8c len 608
digest sha256 OK
FFinit find magic number 0x64447233 at address 0x22000
reading blob from 0x22000 offset 0xc len 28416
digest sha256 OK
mcb selector 0x20000327 checksum 0x46e802ee safe_mode 0
DDR3-1600 CL11 total 256MB 1 16bits part[s]

DDR test done successfully
FFinit find magic number 0x75456e76 at address 0x40000
FFinit find magic number 0x74506c21 at address 0xc1000
reading blob from 0xc1000 offset 0xc len 135505
digest sha256 OK

U-Boot TPL 2019.07 (Feb 01 2021 - 20:29:07 +0800)
Board is FLD secure
$TPL: 5.04L.02@314035 $
set cpu freq to 1500MHz
IMAGE is NAND
Trying to boot from NAND
nand flash device id 0xeff10095, total size 128MB
block size 128KB, page size 2048 bytes, spare area 64 bytes
ECC BCH-4
image from 1048576 to 133169152
RESET STATUS is 0x80000000
SELECTED Image 2 FIT_VOL_ID is 5
Found FIT format U-Boot
tpl_load_read: sector 7000000, count 2688, buf 07000000
tpl_load_read: sector 7000000, count 3686, buf 07000000
fit read sector 7000000, sectors=13958, dst=00000000, count=117440512, size=0x3686
FIT Header Authentication Successfull!
tpl_load_read: sector 7002b80, count 4014, buf 00004000
## Checking hash(es) for Image atf ... sha256+ OK
tpl_load_read: sector 7006b80, count d8210, buf 01000000
## Checking hash(es) for Image uboot ... sha256+ OK
tpl_load_read: sector 77882c0, count dfdb, buf 010d8200
## Checking hash(es) for Image fdt_SHWL_R0A1 ... sha256+ OK
INFO: Creating //trust
INFO: Creating /trust/antirollback_lvl
INFO: Adding exported item node antirollback_lvl to dtb, size:4
INFO: Creating /trust/brcm_pub_key
INFO: Adding exported item node brcm_pub_key to dtb, size:256


U-Boot 2019.07 (Nov 02 2022 - 10:14:59 +0800), Build: 5.04L.02@348603

Model: Broadcom BCM963178
DRAM:  256 MiB
WPS button wasn't pressed
Take PMC out of reset
waiting for PMC finish booting
PMC rev: 3.2.2.347501 running
pmc_init:PMC using DQM mode
Chip ID: BCM6752_A2
$Uboot: 5.04L.02@348603 $
WDT:   Started with servicing (80s timeout)
NAND:  128 MiB
Loading Environment from BOOT_MAGIC... ENV_BOOT_MAGIC_LOAD
found magic at 40000
good crc
resize from 16384 to 8192
OK
In:    serial@0
Out:   serial@0
Err:   serial@0
Model: Broadcom BCM963178
Board is FLD secure
INFO: Can't find /trust/fit-aes1 node in boot DTB!
Now we are in UBOOT proper
HTTPD: ready for starting
boot_device is NAND
image in NAND from 1048576 to 133169152

device nand0 <brcmnand.0>, # parts = 2
#: name                size            offset          mask_flags
0: loader              0x00100000      0x00000000      0
1: image               0x07e00000      0x00100000      0

active partition: nand0,0 - (loader) 0x00100000 @ 0x00000000

defaults:
mtdids  : nand0=brcmnand.0
mtdparts: brcmnand.0:2097152(loader)
Net:   gpio: pin 30 (gpio 30) value is 0
switch set mdio_base 804805c0
sf2 phy_base 8 phy power on workaround timeout 25000
eth switch found, should have been probed name switch0 driver name brcm,ethsw
Initalizing switch low level hardware
Software Resetting Switch ... Done.
Waiting MAC port Rx/Tx to be enabled by hardware ...Done
Disable Switch All MAC port Rx/Tx
eth0: systemport@0x80490000
ARCADYAN: arc_ov_id not [1/2], skip overwrite img
secboot = 0
Hit any key to stop autoboot:  0
CoreV=917
IMAGE=NAND:1M,127M
MCB=0x20000327
arc_ov_id=0
boardid=SHWL_R0A1
bootcmd=printenv;run once;sdk boot_img
bootdelay=1
env_boot_magic=16384@0x40000,0xa0000
ethact=systemport@0x80490000
ethaddr=8C:19:B5:C0:A5:92
fdtcontroladdr=cd0d0a8
filesize=1cb3000
ipaddr=192.168.1.100
mtddevname=loader
mtddevnum=0
mtdids=nand0=brcmnand.0
mtdparts=brcmnand.0:1048576(loader),132120576@1048576(image)
netmask=255.255.255.0
nummacaddrs=10
once=true
partition=nand0,0
secboot=0
serverip=192.168.1.10
stderr=serial@0
stdin=serial@0
stdout=serial@0

Environment size: 538/8188 bytes
No size specified -> Using max size (8012544)
Read 8012544 bytes from volume bootfs2 to 02000000
FIT Header Authentication Successfull!
Read 4 bytes from volume rootfs2 to 0cd0ce68
ERROR:Unable to add a fixup to FDT
## Loading kernel from FIT Image at 02000000 ...
   Using 'conf_lx_SHWL_R0A1' configuration
   Verifying Hash Integrity ... OK
   Trying 'kernel' kernel subimage
     Description:  4.19 kernel
     Type:         Kernel Image
     Compression:  lzo compressed
     Data Start:   0x020e001c
     Data Size:    5996751 Bytes = 5.7 MiB
     Architecture: ARM
     OS:           Linux
     Load Address: 0x00108000
     Entry Point:  0x00108000
     Hash algo:    sha256
     Hash value:   1aabdfec5d872045a7276d8f56ec12d2a1981c705f74f76bed0ace1dd2e05b29
   Verifying Hash Integrity ... sha256+ OK
## Loading fdt from FIT Image at 02000000 ...
   Using 'conf_lx_SHWL_R0A1' configuration
   Verifying Hash Integrity ... OK
   Trying 'fdt_SHWL_R0A1' fdt subimage
     Description:  dtb
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x027882e4
     Data Size:    57271 Bytes = 55.9 KiB
     Architecture: ARM
     Hash algo:    sha256
     Hash value:   78825977d278ed88e924b281e77a8f762c7bfb9e9e7f93ffb96a78431b725ac2
   Verifying Hash Integrity ... sha256+ OK
   Booting using the fdt blob at 0x27882e4
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 07f72000, end 07ffffb6 ... OK
RSVD: not found enrty for adsl
RSVD: not found enrty for rdp1
RSVD: not found enrty for rdp2
RSVD: not found enrty for bufmem
RSVD: not found enrty for rnrmem
RSVD: Allocated for dhd0    11MB
RSVD: Total 0x00c00000 bytes CMA reserved memory @ 0x0f400000
appending extra boot args to linux boot command line:
   mtdparts=brcmnand.0:1048576(loader),132120576@1048576(image) root=/dev/ubiblock0_6 ubi.mtd=image ubi.block=0,6 rootfstype=squashfs cma=0M

Starting kernel ...

remove sysport
Restore Switch's MAC port Rx/Tx, PBVLAN back.
system port tx wait 0 timeout 1000 p 0 c 0
Booting Linux on physical CPU 0x0
Linux version 4.19.183 (tony_chou@Ritchie06) (gcc version 9.2.0 (Buildroot 2019.11.1)) #1 SMP PREEMPT Wed Nov 2 09:56:06 CST 2022
CPU: ARMv7 Processor [410fc075] revision 5 (ARMv7), cr=10c5387d
CPU: div instructions available: patching division code
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
OF: fdt: Machine model: Broadcom BCM963178
bootconsole [earlycon0] enabled
Memory policy: Data cache writealloc
Reserved memory: created CMA memory pool at 0x0f400000, size 12 MiB
OF: reserved mem: initialized node dt_reserved_cma, compatible id shared-dma-pool
On node 0 totalpages: 65536
  Normal zone: 512 pages used for memmap
  Normal zone: 0 pages reserved
  Normal zone: 65536 pages, LIFO batch:15
psci: probing for conduit method from DT.
psci: PSCIv1.1 detected in firmware.
psci: Using standard PSCI v0.2 function IDs
psci: MIGRATE_INFO_TYPE not supported.
psci: SMC Calling Convention v1.0
random: get_random_bytes called from start_kernel+0x9c/0x490 with crng_init=0
percpu: Embedded 14 pages/cpu s27724 r8192 d21428 u57344
pcpu-alloc: s27724 r8192 d21428 u57344 alloc=14*4096
pcpu-alloc: [0] 0 [0] 1 [0] 2
Built 1 zonelists, mobility grouping on.  Total pages: 65024
Kernel command line: console=ttyAMA0 earlyprintk debug irqaffinity=0 pci=pcie_bus_safe isolcpus=2 rootwait init=/sbin/preinit mtdparts=brcmnand.0:1048576(loader),132120576@1048576(image) root=/dev/ubiblock0_6 ubi.mtd=image ubi.block=0,6 rootfstype=squashfs cma=0M
Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
Memory: 235364K/262144K available (7168K kernel code, 204K rwdata, 1388K rodata, 1024K init, 266K bss, 14492K reserved, 12288K cma-reserved, 0K highmem)
Virtual kernel memory layout:
    vector  : 0xffff0000 - 0xffff1000   (   4 kB)
    fixmap  : 0xffc00000 - 0xfff00000   (3072 kB)
    vmalloc : 0xd0800000 - 0xff800000   ( 752 MB)
    lowmem  : 0xc0000000 - 0xd0000000   ( 256 MB)
    pkmap   : 0xbfe00000 - 0xc0000000   (   2 MB)
    modules : 0xbf000000 - 0xbfe00000   (  14 MB)
      .text : 0x(ptrval) - 0x(ptrval)   (8160 kB)
      .init : 0x(ptrval) - 0x(ptrval)   (1024 kB)
      .data : 0x(ptrval) - 0x(ptrval)   ( 205 kB)
       .bss : 0x(ptrval) - 0x(ptrval)   ( 267 kB)
SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=3, Nodes=1
rcu: Preemptible hierarchical RCU implementation.
        Tasks RCU enabled.
NR_IRQS: 16, nr_irqs: 16, preallocated irqs: 16
arch_timer: cp15 timer(s) running at 50.00MHz (phys).
clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0xb8812736b, max_idle_ns: 440795202655 ns
sched_clock: 56 bits at 50MHz, resolution 20ns, wraps every 4398046511100ns
Switching to timer-based delay loop, resolution 20ns
BRCM Legacy Drivers' Helper, all legacy drivers' IO memories/interrupts should be remapped here
     Remapping interrupts...
             hwirq      virq
               60        20
               61        21
               66        22
              110        23
               69        24
              152        25
              153        26
              154        27
              155        28
              156        29
              157        30
              158        31
              159        32
               76        33
               78        34
               77        35
               79        36
              104        37
              105        38
              106        39
               96        40
               97        41
               98        42
               99        43
              100        44
              101        45
              148        46
              149        47
               71        48
              128        49
     Remapping IO memories...
             phys              virt          size
       0000000080180000  00000000d0840000  00024000
       0000000080400000  00000000d0880000  00090000
       00000000ff800000  00000000d0820000  00013000
       00000000ff85a000  00000000d0808000  00008000
       00000000ffe00000  00000000d0980000  00100000
       00000000ff860000  00000000d0812000  00002000
       0000000083010a00  00000000d0805a00  00000100
       000000008000c000  00000000d0818000  00003fff
       0000000083010000  00000000d0815000  00001000
       0000000083018000  00000000d081d000  00001000
       0000000083020000  00000000d0834000  00001000
       0000000083028000  00000000d0836000  00001000
       0000000083030000  00000000d0838000  00001000
       0000000083038000  00000000d083a000  00001000
       0000000083050000  00000000d083c000  00001000
       0000000083060000  00000000d083e000  00001000
       0000000083068000  00000000d0865000  00001000
       00000000810a0000  00000000d0867000  00001000
       0000000081060000  00000000d086c000  00003000
       00000000ffff0000  00000000d0869000  00001000
       0000000083000000  00000000d0870000  00001000
       000000008306c000  00000000d0872000  00001000
       0000000080490000  00000000d0920000  00010000
       0000000080650000  00000000d0940000  00020000
       0000000080700000  00000000d0b00000  00090000
       0000000080800000  00000000d0878000  00006800
       0000000081100000  00000000d0c00000  00091000
Calibrating delay loop (skipped), value calculated using timer frequency.. 100.00 BogoMIPS (lpj=50000)
pid_max: default: 32768 minimum: 301
Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
CPU: Testing write buffer coherency: ok
Setting up static identity map for 0x200000 - 0x200060
rcu: Hierarchical SRCU implementation.
CCI hardware cache coherency enabled
bootloader version  U-Boot 2019.07 (Nov 02 2022 - 10:14:59 +0800), Build: 5.04L.0


inMemNvramData.szBoardId SHWL_R0A1
smp: Bringing up secondary CPUs ...
smp: Brought up 1 node, 3 CPUs
SMP: Total of 3 processors activated (300.00 BogoMIPS).
CPU: All CPU(s) started in SVC mode.
devtmpfs: initialized
VFP support v0.3: implementor 41 architecture 2 part 30 variant 7 rev 5
clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1911260446275000 ns
futex hash table entries: 1024 (order: 4, 65536 bytes)
pinctrl core: initialized pinctrl subsystem
NET: Registered protocol family 16
DMA: preallocated 256 KiB pool for atomic coherent allocations
cpuidle: using governor ladder
PMC driver initcall
PMC driver scanning DT
pmc match PMC brcm,bca-pmc-3-2
     Remapping PMC IO memories...
             phys              virt          size
     0x0000000080301018 0x00000000d0918018 0x00005080
     0x0000000080320000 0x00000000d0913000 0x00000240
     0x0000000080300400 0x00000000d0915400 0x000005d0
     0x0000000080380000 0x00000000d0931000 0x00001000
pmc_init:PMC using DQM mode
Serial: AMBA PL011 UART driver
bcm_rsvmem plat_rsvmem_cached_device: assigned reserved memory node dt_reserved_cma
bcm_rsvmem plat_rsvmem_uncached_device: assigned reserved memory node dt_reserved_cma
reserved CMA memory dhd0 virt addr cf400000 phys addr 0x0f400000 size 0xb00000 cached=0
bcm-bca-cled-ctrl ff803000.led_ctrl: max supported leds 32[32]
bcm-bca-cled-ctrl ff803000.led_ctrl:  Parallel CLED interface found
bcm-bca-cled-ctrl ff803000.led_ctrl: BCA CLED Controller initialized
bcm-bca-gpio ff800500.gpioc: Setting up BCA GPIO
bca_extintr ff800004.bca_extintr0: Ext_Int_0 HWIrq 152 virq 25
bca_extintr ff800004.bca_extintr0: Ext_Int_1 HWIrq 153 virq 26
bca_extintr ff800004.bca_extintr0: Ext_Int_2 HWIrq 154 virq 27
bca_extintr ff800004.bca_extintr0: Ext_Int_3 HWIrq 155 virq 28
bca_extintr ff800004.bca_extintr0: Ext_Int_4 HWIrq 156 virq 29
bca_extintr ff800004.bca_extintr0: Ext_Int_5 HWIrq 157 virq 30
bca_extintr ff800004.bca_extintr0: Ext_Int_6 HWIrq 158 virq 31
bca_extintr ff800004.bca_extintr0: Ext_Int_7 HWIrq 159 virq 32
bca_extintr ff800004.bca_extintr0: Readed resouce bca_extintr0 start 0xff800004 end 0xff80004b
ff812000.serial: ttyAMA0 at MMIO 0xff812000 (irq = 57, base_baud = 0) is a PL011 rev3
console [ttyAMA0] enabled
bootconsole [earlycon0] disabled


EDIT 19.05.2023 - radio na 2,4GHz też jest w standardzie ax. Podczas wyszukiwanie na telefonie jest znaczek 6 smile