The goal of this blog is to help me with the documentation of progress on my quest to install an alternate firmware on the now discontinued Netgear WGR826V.

Showing posts with label firmware. Show all posts
Showing posts with label firmware. Show all posts

Tuesday, March 18, 2008

Partial Success ;-)

I looked into the OpenWRT project to see if they had some guidance or information that could help me with this task. They did have a great deal of information. I decided to try loading an image of a somewhat similar device and to my surplice I was able to boot and use the busybox. A few things do not work (wifi and ethernet for example), but I believe this will be corrected when I start building my own images. Here I have a screen splash of the boot process:


Restarting system.
+starting api entry
Ethernet eth0: MAC address 00:03:47:df:32:a8
IP: 192.168.15.169/255.255.255.0, Gateway: 192.168.15.168
Default server: 192.168.15.168, DNS server IP: 0.0.0.0

RedBoot(tm) bootstrap and debug environment [ROM]
Red Hat certified release, version 1.92p1 - built 14:07:09, Oct 8 2004

Bootloader version 1.1
Platform: Intel Generic Residential Gateway (XScale)
Copyright (C) 2000, 2001, 2002, Red Hat, Inc.

RAM: 0x00000000-0x02000000, 0x0001e5c0-0x01fdd000 available
FLASH: 0x50000000 - 0x51000000, 128 blocks of 0x00020000 bytes each.
RedBoot> fis load linux
RedBoot> exec
Using base address 0x00800000 and length 0x000e8034
Uncompressing Linux................................................................. done, booting the kernel.
Linux version 2.6.21.6 (nbd@ds10) (gcc version 4.1.2) #2 Sun Sep 30 20:44:34 CEST 2007
CPU: XScale-IXP42x Family [690541f1] revision 1 (ARMv5TE), cr=000039ff
Machine: Linksys WRT300N v2
Memory policy: ECC disabled, Data cache writeback
CPU0: D VIVT undefined 5 cache
CPU0: I cache: 32768 bytes, associativity 32, 32 byte lines, 32 sets
CPU0: D cache: 32768 bytes, associativity 32, 32 byte lines, 32 sets
Built 1 zonelists. Total pages: 8128
Kernel command line: root=/dev/mtdblock2 rootfstype=squashfs,jffs2 noinitrd console=ttyS0,115200 init=/etc/preinit
PID hash table entries: 128 (order: 7, 512 bytes)
Dentry cache hash table entries: 4096 (order: 2, 16384 bytes)
Inode-cache hash table entries: 2048 (order: 1, 8192 bytes)
Memory: 32MB = 32MB total
Memory: 30416KB available (1788K code, 167K data, 76K init)
Mount-cache hash table entries: 512
CPU: Testing write buffer coherency: ok
NET: Registered protocol family 16
IXP4xx: Using 16MiB expansion bus window size
PCI: IXP4xx is host
PCI: IXP4xx Using direct access for memory space
PCI: bus0: Fast back to back transfers disabled
dmabounce: registered device 0000:00:01.0 on pci bus
Time: OSTS clocksource has been installed.
NET: Registered protocol family 2
IP route cache hash table entries: 1024 (order: 0, 4096 bytes)
TCP established hash table entries: 1024 (order: 1, 8192 bytes)
TCP bind hash table entries: 1024 (order: 0, 4096 bytes)
TCP: Hash tables configured (established 1024 bind 1024)
TCP reno registered
NetWinder Floating Point Emulator V0.97 (double precision)
squashfs: version 3.0 (2006/03/15) Phillip Lougher
Registering mini_fo version $Id$
JFFS2 version 2.2. (NAND) (C) 2001-2006 Red Hat, Inc.
io scheduler noop registered
io scheduler deadline registered (default)
IXP4xx Watchdog Timer: heartbeat 60 sec
Serial: 8250/16550 driver $Revision: 1.90 $ 2 ports, IRQ sharing disabled
serial8250.0: ttyS0 at MMIO 0xc8001000 (irq = 13) is a XScale
IXP4XX Q Manager 0.2.1 initialized.
IXP4XX NPE driver Version 0.3.0 initialized
ixp4xx_crypto 0.0.1 registered successfully
IXP4XX-Flash.0: Found 1 x16 devices at 0x0 in 16-bit bank
Intel/Sharp Extended Query Table at 0x0031
Using buffer write method
cfi_cmdset_0001: Erase suspend on write enabled
Searching for RedBoot partition table in IXP4XX-Flash.0 at offset 0xfe0000
6 RedBoot partitions found on MTD device IXP4XX-Flash.0
Creating 6 MTD partitions on "IXP4XX-Flash.0":
0x00000000-0x00040000 : "RedBoot"
0x00040000-0x00140000 : "linux"
0x00140000-0x00fa0000 : "rootfs"
0x00240000-0x00fa0000 : "rootfs_data"
0x00fa0000-0x00fc0000 : "unallocated"
0x00fc0000-0x00fc1000 : "RedBoot config"
0x00fe0000-0x01000000 : "FIS directory"
i2c /dev entries driver
nf_conntrack version 0.5.0 (256 buckets, 2048 max)
ip_tables: (C) 2000-2006 Netfilter Core Team
TCP westwood registered
NET: Registered protocol family 1
NET: Registered protocol family 17
802.1Q VLAN Support v1.8 Ben Greear
All bugs added by David S. Miller
XScale DSP coprocessor detected.
ixp4xx_mac driver 0.3.1: eth0 on NPE-B with PHY[-1] initialized
ixp4xx_mac driver 0.3.1: eth1 on NPE-C with PHY[1] initialized
drivers/rtc/hctosys.c: unable to open rtc device (rtc0)
VFS: Mounted root (squashfs filesystem) readonly.
Freeing init memory: 76K
Warning: unable to open an initial console.
- preinit -
switching to jffs2
mini_fo: using base directory: /
mini_fo: using storage directory: /jffs
- init -
init started: BusyBox v1.4.2 (2007-09-29 10:12:09 CEST) multi-call binary

Please press Enter to activate this console. eth0: NPE-B not running
eth0: NPE-B not running
PPP generic driver version 2.4.2
wlan: 0.8.4.2 (svn r2568)
ath_hal: module license 'Proprietary' taints kernel.
ath_hal: 0.9.30.13 (AR5210, AR5211, AR5212, AR5416, RF5111, RF5112, RF2413, RF5413, RF2133, REGOPS_FUNC)
ath_rate_minstrel: Minstrel automatic rate control algorithm 1.2 (svn r2568)
ath_rate_minstrel: look around rate set to 10%
ath_rate_minstrel: EWMA rolloff level set to 75%
ath_rate_minstrel: max segment size in the mrr set to 6000 us
wlan: mac acl policy registered
ath_pci: 0.9.4.5 (svn r2568)



BusyBox v1.4.2 (2007-09-29 10:12:09 CEST) Built-in shell (ash)
Enter 'help' for a list of built-in commands.

_______ ________ __
| |.-----.-----.-----.| | | |.----.| |_
| - || _ | -__| || | | || _|| _|
|_______|| __|_____|__|__||________||__| |____|
|__| W I R E L E S S F R E E D O M
KAMIKAZE (7.09) -----------------------------------
* 10 oz Vodka Shake well with ice and strain
* 10 oz Triple sec mixture into 10 shot glasses.
* 10 oz lime juice Salute!
---------------------------------------------------
root@OpenWrt:/# df -h
Filesystem Size Used Available Use% Mounted on
/dev/mtdblock3 13.4M 648.0k 12.7M 5% /jffs
mini_fo:/jffs 960.0k 960.0k 0 100% /
root@OpenWrt:/# ifconfig
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)

root@OpenWrt:/#
To perform the installation I used this link:
http://wiki.openwrt.org/OpenWrtDocs/Hardware/Gateworks/Avila_GW2348_4
And
http://www.dd-wrt.com/wiki/index.php/Installation#First_time_install

Once I build the perfect image I will put together a step by step upgrade how-to and publish the image, maybe it can be backported in.

Tuesday, March 11, 2008

More backups!!

I had doubts of the integrity of the backups so I decided to re-do them based on the output of fis list. With this I may be able to restore the data in case I would like to revert to the original firmware.



RedBoot> fis list -c
Name FLASH addr Checksum Length Entry point
RedBoot 0x50000000 0x00000000 0x00040000 0x00000000
RedBoot config 0x50FC0000 0x00000000 0x00001000 0x00000000
FIS directory 0x50FE0000 0x00000000 0x00020000 0x00000000
appimg1 0x50040000 0x74FB22F9 0x00760000 0x00000000
appimg2 0x507A0000 0x74FB22F9 0x00760000 0x00000000
igwmisc 0x50F00000 0x6BA0CE01 0x00020000 0x00000000
dhcpdl 0x50F20000 0x6BA0CE01 0x00020000 0x00000000
igwpri 0x50F40000 0x6BA0CE01 0x00020000 0x00000000
igwsec 0x50F60000 0x6BA0CE01 0x00020000 0x00000000
prvcacfg 0x50F80000 0x6BA0CE01 0x00020000 0x00000000
prvauth 0x50FA0000 0x6BA0CE01 0x00020000 0x00000000
RedBoot>

jtag> readmem 0x50000000 0x00040000 RedBoot
address: 0x50000000
length: 0x00040000
reading:
addr: 0x50040000
Done.
jtag> readmem 0x50FC0000 0x00001000 RedBoot_config
address: 0x50FC0000
length: 0x00001000
reading:
addr: 0x50FC1000
Done.
jtag> readmem 0x50FE0000 0x00020000 FIS_directory
address: 0x50FE0000
length: 0x00020000
reading:
addr: 0x51000000
Done.
jtag> readmem 0x50F00000 0x00020000 igwmisc
address: 0x50F00000
length: 0x00020000
reading:
addr: 0x50F20000
Done.
jtag> readmem 0x50F20000 0x00020000 dhcpdl
address: 0x50F20000
length: 0x00020000
reading:
addr: 0x50F40000
Done.
jtag> readmem 0x50F40000 0x00020000 igwpri
address: 0x50F40000
length: 0x00020000
reading:
addr: 0x50F60000
Done.
jtag> readmem 0x50F60000 0x00020000 igwsec
address: 0x50F60000
length: 0x00020000
reading:
addr: 0x50F80000
Done.
jtag> readmem 0x50F80000 0x00020000 prvcacfg
address: 0x50F80000
length: 0x00020000
reading:
addr: 0x50FA0000
Done.
jtag> readmem 0x50FA0000 0x00020000 prvauth
address: 0x50FA0000
length: 0x00020000
reading:
addr: 0x50FC0000
Done.
jtag> readmem 0x50040000 0x00760000 appimg1
address: 0x50040000
length: 0x00760000
reading:
addr: 0x507A0000
Done.
jtag> readmem 0x507A0000 0x00760000 appimg2
address: 0x507A0000
length: 0x00760000
reading:
addr: 0x50F00000
Done.
jtag>
I made them in Big Endian and Little Endian.

Monday, January 28, 2008

Backing up firmware!?

Before deleting or modifying the default image I would like to backup the factory image. This task has turned in to a nightmare. BusyBox has being stripped out off any useful command. I can see the different images on the /dev/mtdblock# devices but that is about it.

I have try many things such as:

-NFS: Some of the scripts do mention NFS, but the kernel does not add NFS support, and there are no modules to load.

-HTTPD: binary httpd is hard coded to read from the specified folder and the file system from where the HTML code is loaded is a cramfs mounted read only.

-BusyBox: There are about 10 commands available to the user and none of them seems to be helpful for this task.

-RedBoot: It can load from tftp some code, but I am new to RedBoot… this could be the solution, but I am still learning, maybe someone can guide me on this?

-JTag: This method looks like it is the most likely to succeed but considering the size of the flash, this could take hours? It will be my last thing to try.

So, for now I am a stock, but hopefully I will figure out or maybe someone can make a suggestion?

Thursday, January 24, 2008

Introduction

The goal of this blog is to help me with the documentation of progress on my quest to install an alternate firmware on the Netgear WGR826V.

Archive