Gast
#3748458
Hallo, I cannot find an infocastserver for kreatel. Where can i get it. I have a vip 1960 Gerard Brinkman
|
Anzeige
|
Motorola Vip19x0 (Big brother of Vip1710)
Gast
#3748458
Hallo, I cannot find an infocastserver for kreatel. Where can i get it. I have a vip 1960 Gerard Brinkman Made a new image, no portal address included. It can be set with:
AndrejkaB A. schrieb: > Hi, > > Earlier Blagus asking about JTAG-ing to STMC. > Here are interesting link to czech forum, device is different, but > processor is the same. > > http://forum.ican3800.zajsoft.net/viewtopic.php?f=... > > BR > Andrej As I said, I already use STMC and everything is set up properly. I can connect to all my ST boards except this VIP1003 (and I didn't test 1963 yet).
Gast
#3782508
Hei I have a "Motorola VIP1910-9" Can any one give me an Step By Step list to change the firmware, A have an Raspberry pi or an Windows pc to work from. I want to be able to stream video from my NAS. Hello Martin,
I have problem when I use ajax (jquery) to change content of div
everything works fine except closing socket. After ajax call there is
one socket CLOSE_WAIT and it hangs. In few days number of those unclosed
socket reach 1023 and webkit crash with error too many open files. When
I try portal from PC (chrome browser) sockets are automaticly closed
after 5s. In portal I use this jquery setting
jQuery.ajaxSetup({async:false,cache: false,timeout:5000,crossDomain:
true});
Have you same problem or you doesnt use jquery?
stb example:
/ # netstat -an |grep CLOSE_WAIT
tcp 1 0 10.1.99.67:55115 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:37826 173.194.65.104:443
CLOSE_WAIT
tcp 1 0 10.1.99.67:33034 173.194.116.239:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:36506 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:37824 173.194.65.104:443
CLOSE_WAIT
tcp 1 0 10.1.99.67:55114 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:36518 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:52913 173.194.116.249:443
CLOSE_WAIT
Hi Johny, I'm sorry but I don't use Jquery. Greetz
Gast
#3790218
Gerard here is the infocast server and other tools https://www.mirrorcreator.com/files/HASHBZQG/motorola_tools_0.rar_links
Gast
#3807640
Hi All. Im new at this. I have a VIP 1903 from Comhem Sweden. My question is, if it possible to activate the two USB ports on it and if its possible to get the rest of the codes to display the menu options like 7532, 2357, I have read all that I can find but so far no luck. Im trying to use it on my network and on a secondary Tv. Also looking for a pinout on how to add a hdd. I have checked and it seems like the 1903 and the 1963 using the same board. thanks in advance Jonny // Sweden As far as I know that are the only codes, there are no more options to set. The usb can only be activated by other software but comhem uses a unknown key to sign the software so the software found here can't be used. (I also have a comhem 1903C box) I don't think you can convert a 1903 to a 1963. Doesn't have comhem a 1963? Maybe you can find one cheap on an auction site. Question for you, can you capture the boot image of the comhem box? I like to get mine running again. Greetz from Holland.
Gast
#3807744
Hi Martin. Hmm Ok. I got this box replaced. Comhem started to Use Tivo. Its odd that it seems impossible to do a factory reset and install firmware that Motorola use. Or is it so that just this VIP boxes is only used as OEM like comhem or Telia (Sweden) ? As far as I know it uses linux like sw. So it would be possible to just reflash it. I can try to capture the boot image but frankly I have no clue how to do that. Capture the software can only be done if the box is in active use by comhem. !! If not don't erase it because once erased you can't get software on it. !! The box is running linux but accept only software/ firmware which is signed with a key. Motorola gave the providers, like comhem, telia, comx, kpn the option to use default (developer) keys or custom keys. Comhem & Comx choice to use their own keys. I've tried every version of software I could find but none are accepted by the Comhem (and Comx) box I have.
Gast
#3808070
Ok I see. Well Im connected to Comhem network and I have erased it ones but due to the facked that Im on Comhem network it updated and downloaded new software. So if you like to send me how-to on getting the image out of it I can try. I going to try to talke to Comhem about it maby I can get hold of a tech that can help me but im not to sure ;-)
Gast
#3808110
Hi Martin. I just talked to a really nice person on Comhem support. He couldent help me right away but going to take contact to the tech department for Comhem in Stockholm and ask them. He going to mail me with info. Hope we can solv this with the sw on the boxes :-) Some info to get the images. Find the server address, should be listed in the IP menu -> Metadata Default is 224.2.2.2:22222 Download the file Infocast2Tools.v1.3.zip and compile it. Connect the pc to the iptv port of the modem. Hopefully you get an ip. If not you can try to clone the mac address of the motorola. (this is better because maybe Comhem's loadbalancer uses the mac to send you to the right server) Start the client software. ./client 224.2.2.2 22222 1 This shows what the multicast server has to offer. With ./client 224.2.2.2 22222 2 it saves the files it get -> this is what is needed. This can take a long time! For more info you can also connect me directly.
Gast
#3808162
Ok Ill try. Whats the best. Try to do this in Linux or Windows. I have Linux mint on a test computer and Windows 7 om this one I write to you on. I havent used Linux for a long time befor I started this. Doesn't matter, the tools should compile on both platforms. But I think compile and fake mac address is easier on linux.
Gast
#3808308
Oki then.. Comhem dont use a specific IPTV port on the modem. Using cable modem and its connected to one of the 4 ports on that one. Then its connected to the wall for standard TV. Comhem using Netgear CG3100 as cablemodem. So I have a problem to figure this out. Is it possible to connect Motorola direct to the computer ?? The files we want are send from comhem not from the motorola. Looks like they put the boxes in a Vlan, so with mac spoofing your pc should be in the iptv vlan and the tools should capture the files.
Gast
#3808344
Hmm Getting error Error creating the socket<>: can not assign requested address Did you get an IP address? And are you root (linux) or Administrator (windows)
Gast
#3808373
No I tryed arp -a as well but cant see it in the network. I have the MAC and going to try to clone it. hopefully i can figure this out.
Gast
#3812385
sudo root
nano /etc/network/interfaces
#############
auto eth0
iface eth0 inet dhcp
hwaddress ether 01:02:03:04:05:06
############
ctrl+o
enter
reboot
replace 01:02..etc with the mac address of the Motorola.
If no IP after that try this:
Insert into /etc/network/interfaces:
clientid motorola_vip_1903 //probably, you need Wireshark to find out
If no IP after that try this:
You probably need to tweak the dhcp client also
Again Wireshark will tell you the Vendor Specific Options.
Insert those and you probably will get an IP.
Let me know
Gast
#3814356
Hi I tried this tool too. I use windows version but I have to use switch with mirrored port and repeatly boot STB. When I try it only with pc I have no luck. When I disconnect STB multicast stop. There was some live check or heartbeat from STB. Maybe it helps you. Hi. Regarding VIP1003 JTAG I asked about earlier - it turns out that STi7105 has JTAG lock feature, which Motorola uses. So there's no JTAG for VIP1003, unfortunately. However, STi7109 doesn't seem to have such protection, and I have VIP1910 and VIP1963 so I'll test it on them.
Gast
#3844618
hi you have someone IIP kreatv-option-ca-verimatrix or kreatv-extra-iip-package-ericsson_mu_4.3.IAP30.3.tgz it is never to be found. Thanks
Gast
#3844734
Ales give me some contact to you.
Gast
#3844756
Johny my email is ales-hruby@email.cz
Gast
#3845129
How can you play channel with verimatrix? I have verimatrix.iip, configured .ini, but when I try to play channel, nothing happens. It doesn't even ask on verimatrix server, like I need to force it to get license. Do I miss something?
Gast
#3869672
Hi, I have new stb VIP 1103 and I am looking for image for it. Can anybody help? thx The 19x3 image must work, it is the same platform/ hardware.
Gast
#3881868
It doesnt work. I tried every image which I have. VIP 1003 boot fine but VIP 1103 doesnt. It has new splash screen too with progress bar. It from arris but it doesnt matter because I have motorola 1003 and arris 1003 and they use same image.
Gast
#3889132
Hei i have a "Motorola VIP1910-9" and a "Motorola VIP1903C" How can i make thes work like a Media center? My real Wish is to make the "Motorola VIP1903C" work as a recive and viewer and let the "Motorola VIP1910-9" all the recived data like DVB-C, VCR and USB-HDD. But i will start to make it work as simple Media center. Can some one pleace help me. Hi there Any ideas as to why my VIP 1903 (C?) keeps rebooting after installing a custom firmware, when I alter the HTTP settings to fetch a new firmware from my local server? It's downloading the file "kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin" - installs it, saves it .. then it reboots, and downloads it once again. Keeps doing this until I remove the HTTP settings and let it download the firmware from my TV provider. Thanks I've had the same problem with my Comhem box. Looks like they use an other encryption key. If you have an Comhem box, I'm interested in the provider image. My Comhem box is just a paperweight right now. @Ivan if you can find the SDK with the dlna & dvb-c module you can make an image and connect the boxes just like you want. Greetz Martin Martin V. schrieb: > > @Ivan if you can find the SDK with the dlna & dvb-c module you can make > an image and connect the boxes just like you want. > Does anyone have a link to the starter kit sdk? None of the links in this thread seem to work anymore :-( Alternatively, does anyone have an unencrypted, generic image? I'd just like to dig around the files to get a sense of everything.
Gast
#4045040
The Arcadyan can be hacked by using a timing attack on the cfe memory. I have no idea when or what I did. I just stuck a paperclip onto the reset pins and by resetting the device and poking on the right moment it dumped me into cfe. Problem is I can not get out of it. But you can load your own firmware with it. Oh, anf ofcourse they are violating the GPL. Just to let you know.
Gast
#4066336
Hello, I try to setup SCART on vip1003 to svideo output. I want to use component cable because if I connect stb to 4k TV and after turn off and turn on stb crash down. But i see output only in booting, after apply defaultVideoSetting i got NO SIGNAL only. I have EMEA version of 1003. Could anybody help me with that?
Gast
#4072755
Hello Try set kernel and slash protocols to 323. as some later say "A string with the splash protocol-order to use when downloading the splash image." 1 = BootCast 2 = TFTP 3 = Local Storage (if available) 4 = SAP (Session Announcement Protocol) 5 = DVD/CD (if available) 6 = HTTP (available from version 3.03) 323 try fist local store if has image load it, if dont have is try load tftp. If you trying use http try use protocols 363 etc. tftp-server/client=http://tftpd32.jounin.net/tftpd32_download.html I looked motorola vip 1903 specs and found that has advanced boot chip 32mb and NAND512mb so if power go off is have boot image there. Order is bootloader(32mb)[projected]->nand(512mb)[slow]->ram(2gb)[fast] RAM(1gbx2chips)(flash2) NAND(512mb)(flash) df output Filesystem 1K-blocks Used Available Use% Mounted on tmpfs 116788 20 116768 0% /old_root none 64940 48 64892 0% /old_root/dynamic /dev/rootdisk0 16512 16512 0 100% /old_root/static unionfs 64940 48 64892 0% / none 64940 28 64912 0% /tmp /dev/mtdblock0 512 256 256 50% /flash /dev/mtdblock2 65536 18016 47520 27% /flash2 mount output rootfs on / type rootfs (rw) tmpfs on /old_root type tmpfs (rw) none on /old_root/proc type proc (rw) none on /old_root/dynamic type tmpfs (rw) /dev/rootdisk0 on /old_root/static type squashfs (ro) unionfs on / type unionfs (rw,noatime,dirs=/old_root/dynamic=rw:/old_root/static=ro) none on /sys type sysfs (rw) none on /proc type proc (rw) none on /tmp type tmpfs (rw) none on /dev/pts type devpts (rw) /dev/mtdblock0 on /flash type jffs2 (rw,nodev,noexec,noatime) /dev/mtdblock2 on /flash2 type yaffs (rw,nodev,noexec,noatime) BusyBox v1.13.3 () multi-call binary Copyright (C) 1998-2008 Erik Andersen, Rob Landley, Denys Vlasenko and others. Licensed under GPLv2. See source distribution for full notice. Usage: busybox [function] [arguments]... or: function [arguments]... BusyBox is a multi-call binary that combines many common Unix utilities into a single executable. Most people will create a link to busybox for each function they wish to use and BusyBox will act like whatever it was invoked as! Currently defined functions: [, [[, ash, awk, basename, brctl, bunzip2, bzcat, cat, chgrp, chmod, chown, chroot, clear, cp, cut, date, dd, df, dirname, dmesg, du, echo, egrep, env, expr, false, fdisk, fgrep, find, freeramdisk, ftpget, ftpput, grep, gunzip, gzip, halt, head, hostname, id, ifconfig, init, insmod, ip, ipaddr, iplink, iproute, kill, killall, ln, losetup, ls, lsmod, md5sum, mdev, mkdir, mkfifo, mknod, mkswap, mktemp, modprobe, more, mount, mv, netstat, nslookup, pidof, ping, poweroff, printf, ps, pwd, reboot, renice, reset, rm, rmdir, rmmod, route, sed, sh, sleep, sort, strings, swapoff, swapon, sync, tail, tar, telnet, telnetd, test, tftp, time, top, touch, tr, traceroute, true, udhcpc, umount, uniq, uptime, usleep, vi, watchdog, wc, wget, which, xargs, yes, zcat, zcip Installed with "kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin" used tftp. dmesg dont work so need use logclient to ip-address.VLC client working fine if has address installed and http-server on advanced settings. so i have questions: 1.can some complete build with ext2/3/4 ??? 2.can put PortalURL to set variable easer contorl ?? exsample "<PortalURL>http://192.168.3.15/portal/webkit</PortalURL>" to "<PortalURL>http://${PORTAL_URL)/portal/webkit</PortalURL>" export PORTAL_URL=192.168.3.15 3.can some write ir-codes for 1903 control is hard bind all ??? cd etc rm irmap.conf echo " PROTOCOL=kreatvir,ID=38 # KPN #codes found in irmaps_def 89,2 #1 105,3 #2 121,4 #3 28,5 #4 44,6 #5 60,7 #6 76,8 #7 92,9 #8 108,10 #9 29,0 #0 #inside ring 88,105 #left 104,106 #right 72,108 #down 56,103 #up 107,129 #mute 9,116 #power #fix this #outside ring 40,105 #left 24,106 #right 9,108 #down 127,103 #up 75,63 #red 63,64 #green 120,65 #yellow 31,66 #blue 43,67,29 #text 39,60,56 #rec 15,63 #OK select,play,pause 91,218 #back 73,88 #menu 124,59 #info 25,210 #tv 77,11 #vol + 61,12 #vol - #fix this ">>irmap.conf init-irdriver irmap.conf 4.can install ohter linux version example dsl,puppy,freenas ??? 5.can install router firmwares tomato,dd-wrt ???
Gast
#4072791
VLC-client enable as webportal: View->Add interface->web Now digibox need connect to PC-program VLC-client(webportal) Is as http://localhost:8080/ more info as https://wiki.videolan.org/Control_VLC_via_a_browser/
Gast
#4072849
To help with ir-codes need load ir-map and read codes with read-irdriver then control works with webprotal. PROTOCOL=kreatvir,ID=38 # KPN version with 1903 use #codes found in irmaps_def
Gast
#4072881
To change hard way url is open: vi /usr/applications/ekioh.conf and change frist line: application.homepage: http://192.168.3.15/ to application.homepage: http://ip-address:8080/ And save file as ctrl+":" and :wq kill ekioh pid with find ps and automatic digibox make new ekioh new settings working and VLC-client open with mobile-control have fun lolz.
Gast
#4072926
claude schrieb: > To change hard way url is open: > vi /usr/applications/ekioh.cfg > and change frist line: > application.homepage: http://192.168.3.15/ to > application.homepage: http://ip-address:8080/ > And save file as ctrl+":" and :wq > kill ekioh pid with find ps and automatic digibox make new ekioh new > settings working and VLC-client open with mobile-control have fun lolz.
Gast
#4072929
To change hard way url is open: vi /usr/applications/ekioh.cfg and change frist line: application.homepage: http://192.168.3.15/portal/webkit to application.homepage: http://ip-address:8080/ And save file as ctrl+":" and :wq kill ekioh pid with find ps and automatic digibox make new ekioh new settings working and VLC-client open with mobile-control have fun lolz.
Gast
#4072932
claude schrieb: > claude schrieb: >> To change hard way url is open: >> vi /usr/applications/ekioh.cfg >> and change frist line: >> application.homepage: http://192.168.3.15/portal/webkit to >> application.homepage: http://ip-address:8080/ >> And save file as ctrl+":" and :wq >> kill ekioh pid with find ps and automatic digibox make new ekioh new >> settings working and VLC-client open with mobile-control have fun lolz.
Gast
#4072947
white screen means with log: webkit_portal.sh(521) Note: OPENING URL == http://192.168.3.15/ portal/webkit So if digibox not find portal page so be white screen so put VLC client or http-server up and put it to /usr/applications/ekioh.cfg and last kill ekioh pid Done some working on a KPN VIP19x3, KPN pushed a newer bootloader which won't work with my software. They also stripped Http & Bootcast. The settings menu has gone and the box has the same bootloader as a 1853.
when sending "option KreaTV.kernel-protocol" with dhcpd you can't send : 1 = BootCast 5 = DVD/CD 6 = HTTP (available from version 3.03) You'll get an error
Now wait for my Jtag to get here. Greetz Martin
Gast
#4081502
Hi Martin V try lower bootloader if support it. firmware:http://www.mikrocontroller.net/attachment/164081/kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin TFTP-server:http://tftpd32.jounin.net/tftpd32_download.html Download firmware and TFTP and put firmware inside TFTP folder and run TFTP-server. Go settings in TFTP-server and setup: [x]TFTP Server [ ]TFTP Client [ ]SNTP server [ ]Syslog Server [x]DHCP Server [ ]DNS Server And go digibox 19x3 when is go up press menu and press factor code: 2357(Ip settings) 7532(advanced menu)Go here kernel protocol:323 slash protocol:323 set TFTP-server your PC-address. Digibox settings follow settings DHCP->TFTP->GET file->"kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin" My setup pc(rj-45)->router<-digibox(rj-45) My internet connection is Router->modem-router(NDIS)->internet My TFTP-server log Viewer: Rcvd DHCP Discover Msg for IP 0.0.0.0, Mac 00:02:9B:8B:0F:92 [06/04 21:49:22.137] Client requested address 0.0.0.0 [06/04 21:49:22.140] DHCP: proposed address 192.168.2.45 [06/04 21:49:22.140] 6832 Request 2 not processed [06/04 21:49:22.142] Rcvd DHCP Rqst Msg for IP 0.0.0.0, Mac 00:02:9B:8B:0F:92 [06/04 21:49:22.142] Previously allocated address 192.168.2.45 acked [06/04 21:49:22.143] 6832 Request 2 not processed [06/04 21:49:22.144] Connection received from 192.168.2.45 on port 49696 [06/04 21:49:22.600] Read request for file <kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin>. Mode octet [06/04 21:49:22.601] OACK: <blksize=512,tsize=18082314,timeout=5,> [06/04 21:49:22.601] Using local port 64819 [06/04 21:49:22.601] <kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin>: sent 35318 blks, 18082314 bytes in 15 s. 0 blk resent [06/04 21:49:37.692] Logclient.exe:http://www.mikrocontroller.net/attachment/175928/http_example.rar inside has logclient run it, dmesg dont work so you need run logclient. putty:http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html can run digibox 19x3 and give commands for it. Digibox ipaddress easyly get in TFTP-server logviewer because settings is to set connect frist pc. when you get digibox white screen then digibox running kreatv-bi-vdr-version but is need webportal install to pc. Now next reboot digibox load kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin inside flash[NAND512mb].
Gast
#4081539
Webportal change need give command inside digibox 19x3: vi /usr/applications/ekioh.cfg frist line: application.homepage: http://192.168.3.15/portal/webkit to application.homepage: http://pc-address:8080/ :w saves the current file without quitting http://www.cs.rit.edu/~cslab/vi.html vi-commands ps and find [ekioh pid-number] kill [ekioh pid-number] Automatic digibox make new ekioh and new settings working. New webportal is geted form pc-address, if there has http-portal-server running or vlc-client with add interface->web. Guess who wrote most of the stuff in this topic ;) Problem is KPN changed the bootloader and removed a lott of stuff. Menu isn't there anymore and it looks like the key is changed so the firmware isn't accepted from the tftp server. Greetz Martin
Gast
#4081591
TFTP-server inside settings has boot file need set as: Tftppd Settings: boot file:kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin Now press ok then DHCP-server give that boot file that digibox load it. Tryed load multiple Firmwars this way but no success, because bootloader has security key so boot file need has secured boot file. TFPT-server:http://www.ethernut.de/en/eboot/ settings Build own Firmware:http://sourceforge.net/projects/vip19x0.arris/files/ST40/KreaTV%204.4/kreatv-kit-oss_4.4-st40.tgz 350mb[source codes] Need linux operation system build firmware. Readme: "This distribution covers the VIP19x0, VIP19x3 and VIP1003 series set-top boxes, hereby referred to as VIP1900. To get the corresponding description for VIP1903 or VIP1003, just replace the text "1900" with "1903" in all places below. VIP1900 STB's are only available in secure versions. Secure versions will only boot signed software images. The resulting kernel/boot images signed with the keys supplied with this distribution (located in dist/config/keys) will boot on a development kit secure VIP1900."
Gast
#4081646
Ok Martin But check your boot file frist error with: "utils_getSystemImageHeader: Wrong magic number 1434553" that means no secured boot file cant boot. Normaly digibox go protocols what kernel has but your settings has Kernel Protocol Order: 2 and Splash Protocol Order: 2 1 = BootCast 2 = TFTP 3 = Local Storage (if available) But what is TFTP:"192.168.3.210" ip-address your pc ? And "End of list describing boot protocol order reached" so no more protocols to follow try use secured boot file in tftp-server what you have there settings installed. TFTP:192.168.3.210 if that is not your pc you can change your pc-address to same as what digibox setting has. Then install TFTP-server and settings right and try reboot digibox. Remove software inside digibox, before download firmware your digibox. kreatv-kit-oss_4.4-st40\bootimage\tools\build_flash_secure_boot_image 350lines with encryption with file so can secure boot file that digibox bootloader check security keys. Simply build_flash_secure_boot_image has header check each boot file that is right magic number exsample my file: kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin frist line 53 45 43 01 80 00 02 13 E3 AB 84 FD 3A 8B EA 91 Try use diffrent versions bootfiles right getting digibox booted when white screen is coming.
Gast
#4092669
Hi Martin, still looking for dlna? I found image kreatv-bi-eval_4.3.IAP30.3_st40_vip19x3.bin and there isnt set telnet password. If you boot it up you can copy out extracted iip. Log to stb via telnet use: cd / tar czf dlna.tar.gz / ftpput -u <username> -p <password> <server address> dlna.tar.gz dlna.tar.gz extract archive to sdk directory/extra/dlna now open file with your image in bi directory kreatv-rootdisk-XXXXXXXXXXX_4.3.IAP30.3_st40_vip19x3.tgz and copy file from /etc/processlist.xml to directory extra/dlna/ edit this file and add line below before </SysmanConfig>: <Program name="dlnamediacontroller" run="/usr/bin/start_dlna.sh" starttime="30"/> now add this to your image config: kreatv-tool-include-file:/usr/bin/start_dlna.sh=../extra/dlna/usr/bin/st art_dlna.sh,/usr/bin/dlnamediacontroller=../extra/dlna/usr/bin/dlnamedia controller,/usr/browser/plugins/libtoi-dlnaplugin.so=../extra/dlna/usr/b rowser/plugins/libtoi-dlnaplugin.so,/usr/lib/libdlnacommon.so=../extra/d lna/usr/lib/libdlnacommon.so,/usr/lib/libdlnacommon-1.2.so.1=../extra/dl na/usr/lib/libdlnacommon-1.2.so.1,/usr/lib/libdlnacommon-1.2.so.1.0.2=.. /extra/dlna/usr/lib/libdlnacommon-1.2.so.1.0.2,/usr/lib/libdlna.so=../ex tra/dlna/usr/lib/libdlna.so,/usr/lib/libdlna-1.2.so.1=../extra/dlna/usr/ lib/libdlna-1.2.so.1,/usr/lib/libdlna-1.2.so.1.0.2=../extra/dlna/usr/lib /libdlna-1.2.so.1.0.2,/usr/lib/libplatform-1.2.so.1=../extra/dlna/usr/li b/libplatform-1.2.so.1,/usr/lib/libplatform.so=../extra/dlna/usr/lib/lib platform.so,/usr/lib/libplatform-1.2.so.1.0.2=../extra/dlna/usr/lib/libp latform-1.2.so.1.0.2,/usr/lib/streamer/libdlnasourceelement.so=../extra/ dlna/usr/lib/streamer/libdlnasourceelement.so,/etc/processlist.xml=../ex tra/dlna/processlist.xml now build image and use dlna plugin logclient example: 833 13:20:33.760 webkit_portal.sh(550) Note: Registering plugin for application/motorola-teletext-plugin 835 13:20:33.848 webkit_portal.sh(550) Note: Registering plugin for application/x-motorola-toi-dlna 837 13:20:34.228 webkit_portal.sh(550) Note: Registering plugin for application/x-motorola-toi add <embed type="application/x-motorola-toi-dlna" hidden="true" /> to your index and start using it :) Thnx. I'll make an IIP out of it when I've got the time. DLNA files extracted from image Anyone any luck with 19x3 and a jtag? Can't connect :(
Gast
#4144087
Dump from working Arcadyan_HMB2260 with possible key in debug Same (middleware) software. It's based on Broadcom Nexus. Ow, it runs a upnp server on some port beyond 40000 If you want the menu (html with javascript, plain, not encrypted), let me know. It seems more hackable.
########## Break by Mac // Whoops? Is this a hex to asci screwed up version of the key? Or is the encrypted key in plain ascii form? Any thoughts? ########## End Break
########## Break by Mac // Is this a hex to asci screwed up version of the signature? Or is the encrypted signature in plain ascii form? Any thoughts? ########## End break by Mac
#######################
I will dump the serial output from a working VIP 1963 tomorrow. Arcadyan is a total other platform, don't think it uses kreatv. The Arris is more the same because it uses the kreatv firmware even when it is an other hardware platform. Be carefull putting an old 1963 on an active KPN line, it might get the new firmware.
Gast
#4144191
Hi Martin, they(KPN/XS4ALL) stopped using kreatv last year..it's all Broadcom Nexus middleware from now. Thats why they changed bootloaders. (nexus../magnum/portinginterface) Do a Google on that) Every firmware has the same debug. Take a look at this. Factory resetted vip 1963 from boot 'till download and start. No prob. This one still active. Don't mind the obfuscated dhcp output. It's an configuration behind a router. (long succesfull story) All else is original. [code] [ 352.407070] <vqec-event>Received SIGKILL - terminating input loop [ 353.463277] Restarting system. System memory: 512 MB Using Slot 2 Unpacking Image ...Done Linux version 2.6.23.17_stm23_0121 (mcart@mcart) (gcc version 4.2.4 (snapshot) (STMicroelectronics Special 20090602) [build Oct 28 2009]) #1 PREEMPT Tue Jun 25 16:16:46 CEST 2013 Booting machvec: vip19x3 Reserve 10240 KiB for STAVMEM (0 KiB for graphics) @ 0x4f600000 - 0x4fffffff Motorola VIP19x3 board initialisation STx7105 version 3.x Kernel command line: console=ttyAS0,115200 mtdparts=Onboard_Flash:0x00080000@0x00380000(FFS),0x00380000@0x0(Raw) bootdevice=nor bootfiles=raw systemmemsize=524288 rbl=2 rbl_mode=1 rbl_version=2.12 dbl=2 Kernel has NOT DVR version 5 support size is 4096 Kernel has NOT DVB support bpa2: partition 'bigphysarea' created at 0x4ab00000, size 16384 kB (0x01000000 B) intc: missing unique irq mask for irq 18 (vect 0x0440) intc: missing unique irq mask for irq 19 (vect 0x0460) Using tmu for system timer Using 25.000 MHz high precision timer. console [ttyAS0] enabled Dentry cache hash table entries: 65536 (order: 6, 262144 bytes) Inode-cache hash table entries: 32768 (order: 5, 131072 bytes) Memory: 490624k/524288k available (1245k kernel code, 446k data, 80k init) SH4 450.00 BogoMIPS PRESET (lpj=225000) NET: Registered protocol family 16 Generic PHY: Registered new driver DMA: Registering DMA API. Time: SuperH clocksource has been installed. NET: Registered protocol family 2 IP route cache hash table entries: 16384 (order: 4, 65536 bytes) TCP established hash table entries: 65536 (order: 7, 524288 bytes) TCP bind hash table entries: 65536 (order: 6, 262144 bytes) TCP: Hash tables configured (established 65536 bind 65536) TCP reno registered Unpacking initramfs... Overmounted tmpfs INITRAMFS: Compressed (LZMA) image found done Freeing initrd memory: 579k freed JFFS2 version 2.2. © 2001-2006 Red Hat, Inc. io scheduler noop registered io scheduler anticipatory registered (default) Kboxdev: registered device with major 120 STMicroelectronics ASC driver initialized stasc.0: ttyAS0 at MMIO 0xfd031000 (irq = 122) is a stasc stasc.1: ttyAS1 at MMIO 0xfd032000 (irq = 121) is a stasc Marvell 88E3015: Registered new driver GMAC - user ID: 0x10, Synopsys ID: 0x33 No valid MAC address yet; it will be set from the console later. eth0 - (dev. name: stmmaceth - id: 0, IRQ #134 IO base addr: 0xfd110000) STMMAC MII Bus: probed eth0: PHY ID 01410e20 at 0 IRQ 246 (0:00) active VIP19xx onboard flash device Onboard_Flash: Found 1 x16 devices at 0x0 in 16-bit bank Using word write for ST M28WXX0 FLASH cfi_cmdset_0001: Erase suspend on write enabled 2 cmdlinepart partitions found on MTD device Onboard_Flash Creating 2 MTD partitions on "Onboard_Flash": 0x00380000-0x00400000 : "FFS" 0x00000000-0x00380000 : "Raw" i2c /dev entries driver i2c_st40_pio: ST40 PIO based I2C Driver i2c_st40_pio: allocated pin (2,2) for scl (0x801ccb50) i2c_st40_pio: allocated pin (2,3) for sda (0x801ccb6c) i2c_st40_pio: allocated pin (3,6) for scl (0x801cccd4) i2c_st40_pio: allocated pin (3,7) for sda (0x801cccf0) Software Watchdog Timer: 0.07 initialized. soft_noboot=0 soft_margin=60 sec (nowayout= 1) DMA: Registering fdma_dmac.0 handler (16 channels). platform fdma_dmac.0: SLIM hw 0.0, FDMA fw 6.1 DMA: Registering fdma_dmac.1 handler (16 channels). platform fdma_dmac.1: SLIM hw 0.0, FDMA fw 6.1 stm_rng hardware driver 1.0 configured TCP cubic registered NET: Registered protocol family 17 Freeing unused kernel memorINIT STARTED 00:00:01 01.01.2000 src/main.c 116 DBG > CHILD: New child process with PID: 227 SERVER STARTED 00:00:01 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:01 01.01.2000 src/main.c 130 DBG > PARENT: parent PID: 1, child PID: 227 00:00:01 01.01.2000 src/main.c 116 DBG > CHILD: New child process with PID: 228 00:00:01 01.01.2000 src/main.c 925 DBG > ------------ 00:00:01 01.01.2000 src/main.c 926 DBG > --- Init --- 00:00:01 01.01.2000 src/main.c 927 DBG > ------------ 00:00:01 01.01.2000 src/main.c 929 DBG > ---- DBL 2.0.2stmcore-display: using HDMI hotplug stmcore-display: STi7105 display: probed device probe found 2 display pipelines ---- 00:00:01 01.01.2000 src/mrequesting frm: 'component.fw', c1507af4/8aab9dc8 ain.c 130 DBG > PARENT: parent PID: 1, child PID: 228 00:00:01 01.frm 'component.fw' successfully loaded 01.2000 src/main.c 149 DBG > _waitForChildProcessExit(): Waiting for child process with PID: 228 stmfb: fb0 parameters = "720x576-32@50:8m:0:PAL:YUV:RGB" 00:00:01 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 [DBG: 486]: hdmi_enable_link(): m->mode: 6d [DBG: 487]: hdmi_enable_link(): m->ActiveAreaHeight: 576 [DBG: 488]: hdmi_enable_link(): m->ActiveAreaWidth: 720 [DBG: 489]: hdmi_enable_link(): m->ActiveAreaXStart: 132 [DBG: 490]: hdmi_enable_link(): m->FrameRate: 50000 [DBG: 491]: hdmi_enable_link(): m->FullVBIHeight: 44 [DBG: 492]: hdmi_enable_link(): m->OutputStandards: -2147483136 [DBG: 494]: hdmi_enable_link(): m->ScanType: 1d [DBG: 495]: hdmi_enable_link(): m->0denominator: 15 [DBG: 496]: fb: fb1 parameters = "720x576-32@50i:4m:0:PAL:CVBS" stmhdmi_enable_link(): m->0numerator: 16 [DBG: 497]: hdmi_enable_link(): m->1denominator: 45 [DBG: 498]: hdmi_enable_link(): m->1numerator: 64 [DBG: 500]: hdmi_enable_link(): m->HDMIVideoCodes: 17 [DBG: 501]: hdmi_enable_link(): m->HDMIVideoCodes: 18 00:00:01 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 NAND device: Manufacturer ID: 0x20, Chip ID: 0x76 (ST Micro NAND 64MiB 3,3V 8-bit) Creating 1 MTD partitions on "stm-nand-flex.1": 0x00000000-0x04000000 : "NAND home" frontpanel: controller is mounted 00:00:01 01.01.2000 os/ipc/shm.c 184 DBGfrontpanel: LED character display board with 10 button/9 LED support > _shmOpen: Waiting for SHM file /shmSegment1 frontpanel: display version: 1 input: Front Buttons as /class/input/input0 00:00:01 01.01.2000 19xx/board.c 142 WARNING > _getBasicFlashLayout(): Flash partition layout for device: stm-nand-flex.1 not found 00:00:01 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:01 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:01 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 184 DBG > _shmOpen: Waiting for SHM file /shmSegment1 00:00:02 01.01.2000 os/ipc/shm.c 55 DBG > _shmCreate(): Unable to open shared memory, try to create new segment! (No such file or directory) 00:00:02 01.01.2000 os/ipc/shm.c 100 DBG > _shmCreate(): Shared memory segment created with address: 0x29e1c000, size: 71303168B, fd: 5 00:00:02 01.01.2000 os/ipc/shm.c 211 DBG > os_ipc_shm_initialize(): base segment data: address: 0x29e1c000, size: 71303168 00:00:02 01.01.2000 os/ipc/shm.c 179 DBG > _shmOpen: SHM file created by master process 00:00:02 01.01.2000 os/ipc/shm.c 100 DBG > _shmCreate(): Shared memory segment created with address: 0x2961c000, size: 71303168B, fd: 3 00:00:02 01.01.2000 os/ipc/shm.c 211 DBG > os_ipc_shm_initialize(): base segment data: address: 0x2961c000, size: 71303168 00:00:02 01.01.2000 src/dhcp.c 110 DBG > server_dhcp_initialize(): CALL 00:00:02 01.01.2000 src/ipc.c 77 ERROR > _msqSysVOpen(): Unable to open message queue with key: 0x00000101 (No such file or directory) 00:00:02 01.01.2000 src/ipc.c 269 ERROR > ipc_open(): Unable to open message queue, maybe not exist, try to create it for key: 0x101 00:00:02 01.01.2000 src/ipc.c 77 ERROR > _msqSysVOpen(): Unable to open message queue with key: 0x00000100 (No such file or directory) 00:00:02 01.01.2000 src/ipc.c 269 ERROR > ipc_open(): Unable to open message queue, maybe not exist, try to create it for key: 0x100 00:00:02 01.01.2000 src/main.c 956 DBG > main(): seed for random number generator 2607323087 00:00:02 01.01.2000 /utils/ini.c 86 ERROR > osd_utils_ini_parse: No such file or directory 00:00:02 01.01.2000 src/osd.c 334 ERROR > _loadCustomTranslation(): Error parsing i18n file (1st pass) 00:00:02 01.01.2000 src/osd.c 767 ERROR > osd_open(): _loadCustomTranslation() => 2097157 - assuming default translation 00:00:02 01.01.2000 /utils/ini.c 86 ERROR > osd_utils_ini_parse: No such file or directory 00:00:02 01.01.2000 /utils/pam.c 387 ERROR > osd_utils_pam_get: empty file name 00:00:02 01.01.2000 /utils/pam.c 387 ERROR > osd_utils_pam_get: empty file name 00:00:02 01.01.2000 /utils/pam.c 387 ERROR > osd_utils_pam_get: empty file name 00:00:03 01.01.2000 /utils/pam.c 387 ERROR > osd_utils_pam_get: empty file name 00:00:03 01.01.2000 pplication.c 1542 DBG > app_initialize() 00:00:03 01.01.2000 src/boot.c 1509 DBG > boot_initialize: CALL 00:00:03 01.01.2000 src/dhcp.c 16 DBG > dhcp_initialize(): PROXY CALL 00:00:03 01.01.2000 src/softup.c 660 DBG > softup_initialize: CALL 00:00:03 01.01.2000 src/mmddf.c 528 DBG > mmddf_initialize() 00:00:03 01.01.2000 src/mmddf.c 88 DBG > _notifyTask(): START 00:00:03 01.01.2000 pplication.c 65 ERROR > app_loadErrorMappings(): unable to open mapping file (No such file or directory) 00:00:03 01.01.2000 src/main.c 1006 DBG > main(): Error mappings loading failed. Falling back to default. 00:00:03 01.01.2000 pplication.c 266 DBG > _displayProgress(1, 1) PHY: 0:00 - Link is Up100/Full00:00:06 01.01.2000 src/main.c 1043 DBG > main(): sleeping 1300 ms before network attachment 00:00:07 01.01.2000 src/dhcp.c 34 DBG > dhcp_setup(): PROXY CALL 00:00:07 01.01.2000 src/main.c 232 DBG > SERVER: Received command IPC_COMMAND_TYPE_DHCP 00:00:07 01.01.2000 src/dhcp.c 139 DBG > server_dhcp_handleCommand(): CALL 00:00:07 01.01.2000 src/dhcp.c 845 DBG > dhcp_setup: CALL 00:00:07 01.01.2000 src/dhcp.c 899 DBG > CALL for interface: eth0 00:00:07 01.01.2000 src/dhcp.c 184 DBG > entering 2 listen mode 00:00:07 01.01.2000 src/dhcp.c 158 DBG > _getNetworkInterfaceLinkState(): Link state: 1 debug, Sending discover... 00:00:07 01.01.2000 src/dhcp.c 1113 DBG > dhcp_setup(): Current timeout (INIT_SELECTING): 3256 00:00:07 01.01.2000 src/dhcp.c 158 DBG > _getNetworkInterfaceLinkState(): Link state: 1 00:00:07 01.01.2000 src/dhcp.c 158 DBG > _getNetworkInterfaceLinkState(): Link state: 1 debug, Sending select for (obfuscated)... 00:00:07 01.01.2000 src/dhcp.c 1159 DBG > dhcp_setup(): Current timeout (RENEW_REQUESTED, REQUESTING): 4569 00:00:07 01.01.2000 src/dhcp.c 158 DBG > _getNetworkInterfaceLinkState(): Link state: 1 00:00:07 01.01.2000 src/dhcp.c 1329 DBG > dhcp_setup(): Lease of (obfuscated) obtained, lease time 86400 00:00:07 01.01.2000 src/dhcp.c 444 DBG > _fillDhcpParameters() 00:00:07 01.01.2000 src/dhcp.c 610 DBG > _get_vendor_option(): get_option() returned no data 00:00:07 01.01.2000 src/dhcp.c 230 DBG > _displayDhcpOptions() 00:00:07 01.01.2000 src/dhcp.c 232 DBG > Ip Address : (obfuscated) 00:00:07 01.01.2000 src/dhcp.c 233 DBG > TFTP Server Address : (obfuscated) 00:00:07 01.01.2000 src/dhcp.c 234 DBG > Subnet mask : 255.255.255.0 00:00:07 01.01.2000 src/dhcp.c 235 DBG > Broadcast address : (obfuscated) 00:00:07 01.01.2000 src/dhcp.c 236 DBG > Filename : ÿ 00:00:07 01.01.2000 src/dhcp.c 237 DBG > Boot Filename : (not working) 00:00:07 01.01.2000 src/dhcp.c 238 DBG > DHCP Server Address : (obfuscated)) 00:00:07 01.01.2000 src/dhcp.c 239 DBG > Default gateway : (obfuscated) 00:00:07 01.01.2000 src/dhcp.c 240 DBG > Routers : 00:00:07 01.01.2000 src/dhcp.c 245 DBG > (obfuscated) 00:00:07 01.01.2000 src/dhcp.c 248 DBG > DNS servers : 00:00:07 01.01.2000 src/dhcp.c 253 DBG > (obfuscated) 00:00:07 01.01.2000 src/dhcp.c 256 DBG > Root Path : 00:00:07 01.01.2000 src/dhcp.c 257 DBG > TFTP Kernel filename : 00:00:07 01.01.2000 src/dhcp.c 262 DBG > TFTP server pool : 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 00:00:07 01.01.2000 src/dhcp.c 263 DBG > TFTP pool atempts : 0 00:00:07 01.01.2000 src/dhcp.c 264 DBG > TFTP node atempts : 0 00:00:07 01.01.2000 src/dhcp.c 265 DBG > TFTP block size : 0 00:00:07 01.01.2000 src/dhcp.c 266 DBG > TFTP read request timeout : 0 00:00:07 01.01.2000 src/dhcp.c 267 DBG > TFTP splash filename : 00:00:07 01.01.2000 src/dhcp.c 268 DBG > TFTP timeout : 0 00:00:07 01.01.2000 src/dhcp.c 269 DBG > SAP address : 00:00:07 01.01.2000 src/dhcp.c 270 DBG > SAP attemps : 0 00:00:07 01.01.2000 src/dhcp.c 271 DBG > SAP timeout : 0 00:00:07 01.01.2000 src/dhcp.c 272 DBG > Bootcast address : 00:00:07 01.01.2000 src/dhcp.c 273 DBG > Bootcast attemps : 0 00:00:07 01.01.2000 src/dhcp.c 274 DBG > Bootcast timeout : 0 00:00:07 01.01.2000 src/dhcp.c 275 DBG > Swap server : 0.0.0.0 00:00:07 01.01.2000 src/dhcp.c 276 DBG > Kernel Protocol Order: 00:00:07 01.01.2000 src/dhcp.c 284 DBG > Splash Protocol Order: 00:00:07 01.01.2000 src/dhcp.c 184 DBG > entering 0 listen mode 00:00:07 01.01.2000 src/dhcp.c 785 DBG > dhcp_clean() 00:00:07 01.01.2000 src/dhcp.c 162 DBG > dhcp_setup(): RET 00:00:07 01.01.2000 src/main.c 1064 DBG > Obtained network configuration from DHCP! 00:00:07 01.01.2000 src/main.c 1104 DBG > main: No kernel protocol order is supplied, assuming defaults 00:00:07 01.01.2000 src/main.c 1212 DBG > Added DNS: (obfuscated) 00:00:07 01.01.2000 src/main.c 1242 DBG > Current IGMP version: 0 00:00:07 01.01.2000 src/main.c 1251 DBG > IGMP version forced to 2 00:00:07 01.01.2000 pplication.c 266 DBG > _displayProgress(1, 0) 00:00:07 01.01.2000 src/main.c 1323 DBG > Trying to get SAP location from file /mnt/ffs/SAPaddress 00:00:07 01.01.2000 rc/sysinfo.c 391 ERROR > sysinfo_getSapSetup: Unable to open file /mnt/ffs/SAPaddress 00:00:07 01.01.2000 src/main.c 1329 ERROR > sysinfo_getSapSetup() => 513 00:00:07 01.01.2000 src/main.c 1366 DBG > Trying to get SAP location from DHCP option 67 00:00:07 01.01.2000 src/utils.c 965 DBG > _parseSapAddress(): prefix is different than 'SAP' 00:00:07 01.01.2000 src/main.c 1372 ERROR > Unable to get SAP location from kreatv-bi vdr.config_4.3.IAP30.3_st40_vip19x3.bin 00:00:07 01.01.2000 src/main.c 1377 DBG > Trying to get SAP location from DHCP filename header option 00:00:07 01.01.2000 src/utils.c 950 DBG > _parseSapAddress(): address shorter that 15 characters no space for 'SAP/x/0.0.0.0:0' 00:00:07 01.01.2000 src/main.c 1383 ERROR > Unable to get SAP location from ÿ 00:00:07 01.01.2000 src/main.c 1424 DBG > SAP location hasn't been specified - fallback to hardcoded 00:00:07 01.01.2000 src/utils.c 965 DBG > _parseSapAddress(): prefix is different than 'SAP' 00:00:07 01.01.2000 src/main.c 1434 DBG > Assuming default sap.stb.itvonline.nl as SAP domain name Id: 2 Response: 1 Opcode: 0 Authoritative: 0 Truncation: 0 Recursion desired: 1 Recursion available: 1 Response code: 0 Questions: 1 Answers: 1 NS resource records: 2 Additional res. records: 2 00:00:07 01.01.2000 rc/sysinfo.c 157 ERROR > _readFile(): file open error 00:00:07 01.01.2000 rc/sysinfo.c 198 ERROR > _readFile() => 513 00:00:07 01.01.2000 src/main.c 1493 DBG > Unable to get data from configuration file: assuming that system update is necessary 00:00:07 01.01.2000 pplication.c 266 DBG > _displayProgress(2, 2) 00:00:07 01.01.2000 src/main.c 1521 DBG > Target DBL version is not set - skipping DBL update 00:00:07 01.01.2000 src/main.c 1753 DBG > Attempting to install default system version: vip1963 00:00:07 01.01.2000 pplication.c 266 DBG > _displayProgress(2, 1) 00:00:07 01.01.2000 src/softup.c 848 DBG > softup_system_download: CALL system version: vip1963 00:00:07 01.01.2000 src/softup.c 333 DBG > softup_mmddf_download: CALL 00:00:07 01.01.2000 src/main.c 419 DBG > _dblCallback(): DBL_CALLBACK_EVENT_SYSTEM_DOWNLOAD_ATTEMPT_START 00:00:07 01.01.2000 src/mmddf.c 583 DBG > mmddf_mmf_open: CALL 00:00:07 01.01.2000 src/mmddf.c 611 DBG > mmddf_mmf_open: socket descriptor: 8, address: 0x060203e0 00:00:07 01.01.2000 src/mmddf.c 628 DBG > mmddf_mmf_open: added IP membership to SAP 00:00:07 01.01.2000 src/mmddf.c 815 DBG > mmddf_mmf_getSessionDescription() 00:00:07 01.01.2000 /utils/sdp.c 39 DBG > sdp_descriptionInit() 00:00:08 01.01.2000 src/mmddf.c 911 DBG > mmddf_mmf_getSessionDescription(): received bytes: 395 00:00:08 01.01.2000 src/mmddf.c 930 DBG > mmddf_mmf_getSessionDescription(): first packet received - set timeout to SAP timeout 00:00:08 01.01.2000 src/mmddf.c 956 DBG > ---cut 00:04:44 01.01.2000 src/main.c 493 DBG > _dblCallback(): SYSTEM_FLASH_END 00:04:44 01.01.2000 src/softup.c 1227 DBG > softup_system_free(): CALL 00:04:45 01.01.2000 pplication.c 266 DBG > _displayProgress(3, 1) 00:04:45 01.01.2000 src/boot.c 1542 DBG > boot_boot: CALL 00:04:45 01.01.2000 src/boot.c 1009 DBG > _nandBoot(): CALL NAND device: Manufacturer ID: 0x20, Chip ID: 0x76 (ST Micro NAND 64MiB 3,3V 8-bit) Creating 1 MTD partitions on "stm-nand-flex.1": 0x00000000-0x04000000 : "flash" 00:04:45 01.01.2000 src/boot.c 1034 DBG > _nandBoot(): Read image header from: /dev/mtd2 00:04:45 01.01.2000 src/main.c 521 DBG > _dblCallback(): BOOT_READ_HEADER 00:04:45 01.01.2000 src/utils.c 197 DBG > utils_getSystemImageHeader: version = 3 00:04:45 01.01.2000 src/utils.c 214 DBG > utils_getSystemImageHeader: have version >= 3 - reading force disabling splash 00:04:45 01.01.2000 src/utils.c 118 DBG > Image header: 00:04:45 01.01.2000 src/utils.c 119 DBG > Magic number: 0x3143414b 00:04:45 01.01.2000 src/utils.c 120 DBG > Header version: 0x3 00:04:45 01.01.2000 src/utils.c 121 DBG > Header size: 0x229 (553) 00:04:45 01.01.2000 src/utils.c 122 DBG > Force disabling splash: 0x0 00:04:45 01.01.2000 src/utils.c 123 DBG > Encryption type: 0x1 00:04:45 01.01.2000 src/utils.c 124 DBG > Encryption key size: 0x100 (256) 00:04:45 01.01.2000 src/utils.c 125 DBG > Encryption key: °›s¼qS4ÒZà“¦:pÍŽêp€¿ÎÅRyoYG:1 pR nÚ}Ù´vÕ$8ƒ1Š&íŸUÞÀǨ!ýºæÃc-½O;´§ö’½IQæ;ǾÓ9óyçu<:í^¢/YˆÛQ£ðt:PÍSoèë[Ñ Ï¸‡²"©2Vp àcøF#Áfæ6«+`ëd B8o® «üû36[ÌêÜÛú½†g\« 00:04:45 01.01.2000 src/utils.c 126 DBG > Kernel size: 0x1ad2f0 00:04:45 01.01.2000 src/utils.c 127 DBG > Kernel compression type: 0x2 00:04:45 01.01.2000 src/utils.c 128 DBG > Kernel load address: 0x80700000 00:04:45 01.01.2000 src/utils.c 129 DBG > Kernel entry point address: 0x80701000 00:04:45 01.01.2000 src/utils.c 130 DBG > Kernel signature length: 0x100 (256) 00:04:45 01.01.2000 src/utils.c 131 DBG > Kernel signature: >Âmž³×:;œ j£–„ZO‘™Ñý 00:04:45 01.01.2000 src/utils.c 132 DBG > Rootfs offset: 0x310000 00:04:45 01.01.2000 src/utils.c 133 DBG > Rootfs size: 0x2e04010 00:04:45 01.01.2000 src/utils.c 134 DBG > Rootfs filesystem type: 0x6 PuTTY00:04:45 01.01.2000 src/main.c 525 DBG > _dblCallback(): BOOT_VERIFY_KERNEL 00:04:45 01.01.2000 src/utils.c 872 DBG > utils_verifyKernel() 00:04:49 01.01.2000 src/boot.c 1129 DBG > _nandBoot(): Decrypted kernel size: 1757926 (encrypted size: 1757936) 00:04:49 01.01.2000 src/main.c 529 DBG > _dblCallback(): BOOT_DECOMPRESS_KERNEL 00:04:49 01.01.2000 src/boot.c 1149 DBG > _nandBoot(): Decompressed kernel size: 3381112 00:04:51 01.01.2000 src/main.c 533 DBG > _dblCallback(): BOOT_LOAD_KERNEL 00:04:51 01.01.2000 src/boot.c 215 DBG > _createKernelCommandLine: CALL 00:04:51 01.01.2000 src/boot.c 273 DBG > ntp servers count 0 00:04:51 01.01.2000 src/boot.c 359 DBG > _createKernelCommandLine(): Creating mtdparts parameter! 00:04:51 01.01.2000 src/boot.c 185 DBG > _getDeviceNumberFromDevicePath(): Found number: 4 00:04:51 01.01.2000 src/boot.c 185 DBG > _getDeviceNumberFromDevicePath(): Found number: 4 00:04:51 01.01.2000 src/boot.c 499 DBG > _createKernelCommandLine():UBI mtd device number: 4 00:04:51 01.01.2000 src/boot.c 565 DBG > _createKernelCommandLine: RET 00:04:51 01.01.2000 src/boot.c 1176 DBG > _nandBoot(): Booting kernel from flash with cmdline: console=ttyAS0,115200 mtdparts="Onboard_Flash:0x80000@0x380000(FFS),0x380000@0x0(Raw);stm-nand -flex.1:0x4000000@0x0(system),0x310000@0x0(kernel),0x3cf0000@0x310000(ro otfs)" bootdevice=nor bootfiles=raw systemmemsize=524288 rbl=2 rbl_mode=1 rbl_version=2.12 dbl=2 cdv=2.0.2 ip:(obfuscated)::(obfuscated):255.255.255.0 nwhwconf=device:eth0,hwaddr:00:02:9b:68:97:cf serverid=(obfuscated) root=ubi0:rootfs rw rootfstype=ubifs ubi.mtd=4, length: 427 00:04:51 01.01.2000 src/main.c 537 DBG > _dblCallback(): BOOT_RUN_KERNEL 00:04:51 01.01.2000 pplication.c 266 DBG > _displayProgress(3, 2) Starting new kernel kexec information segment[0]: 0x80700000 - 0x80a3a000 (0x0033a000) start : 0x80701000 [ 0.000000] Linux version 2.6.23.17-stm23-0123 (buildbot@dccbuilder-2) (gcc version 4.2.1 20070719 (experimental) (STMicroelectronics Special) [build Mar 31 2015]) #1 PREEMPT Tue Mar 31 20:21:32 CEST 2015 [ 0.000000] Booting machvec: vip19x3 [ 0.000000] Reserve 115712 KiB for STAVMEM (0 KiB for graphics) [ 0.000000] STx7105 version 3.x [ 0.000000] Kernel command line: console=ttyAS0,115200 mtdparts="Onboard_Flash:0x80000@0x380000(FFS),0x380000@0x0(Raw);stm-nand -flex.1:0x4000000@0x0(system),0x310000@0x0(kernel),0x3cf0000@0x310000(ro otfs)" bootdevice=nor bootfiles=raw systemmemsize=524288 rbl=2 rbl_mode=1 rbl_version=2.12 dbl=2 cdv=2.0.2 ip=(obfuscated)::(obfuscated):255.255.255.0 nwhwconf=device:eth0,hwaddr:00:02:9b:68:97:cf serverid=(obfuscated) root=ubi0:rootfs rw rootfstype=ubifs ubi.mtd=4 [ 0.000000] Kernel has NOT DVR version 5 [ 0.000000] Kernel has NOT DVB support [ 0.000000] bpa2: partition 'bigphysarea' created at 0x40e6b000, size 16384 kB (0x01000000 B) [ 0.000000] Using tmu for system timer [ 0.000047] Using 25.000 MHz high precision timer. [ 0.000238] console [ttyAS0] enabled [ 0.002784] Dentry cache hash table entries: 65536 (order: 6, 262144 bytes) [ 0.006385] Inode-cache hash table entries: 32768 (order: 5, 131072 bytes) [ 0.030527] Memory: 376960k/524288k available (2254k kernel code, 695k data, 344k init) [ 0.031533] SH4 450.00 BogoMIPS PRESET (lpj=225000) [ 0.037191] NET: Registered protocol family 16 [ 0.051276] Pre-powerdown KEYSCAN [ 0.052044] Powered down KEYSCAN! [ 0.063586] Generic PHY: Registered new driver [ 0.065869] SCSI subsystem initialized [ 0.072000] Time: SuperH clocksource has been installed. [ 0.076577] NET: Registered protocol family 2 [ 0.087190] IP route cache hash table entries: 16384 (order: 4, 65536 bytes) [ 0.089572] TCP established hash table entries: 65536 (order: 7, 524288 bytes) [ 0.095896] TCP bind hash table entries: 65536 (order: 6, 262144 bytes) [ 0.098676] TCP: Hash tables configured (established 65536 bind 65536) [ 0.099017] TCP reno registered [ 0.173825] platform_add_pm_devices: [ 0.180839] squashfs: version 3.4 (2008/08/26) Phillip Lougher [ 0.181133] Registering unionfs 2.5.1 (for 2.6.23.17) [ 0.182480] JFFS2 version 2.2. (NAND) © 2001-2006 Red Hat, Inc. [ 0.183623] JFS: nTxBlock = 2945, nTxLock = 23565 [ 0.190154] yaffs Mar 31 2015 20:21:26 Installing. [ 0.191350] io scheduler noop registered [ 0.192025] io scheduler anticipatory registered (default) [ 0.221487] stm_hwrandom stm_hwrandom: STM Random Number Generator ver. 0.1 [ 0.222126] Kboxdev: registered device with major 120 [ 0.223060] STMicroelectronics ASC driver initialized [ 0.224422] stasc.0: ttyAS0 at MMIO 0xfd031000 (irq = 122) is a stasc [ 0.226084] stasc.1: ttyAS1 at MMIO 0xfd032000 (irq = 121) is a stasc [ 0.231285] loop: loaded (max 8 devices) [ 0.233157] Marvell 88E3015: Registered new driver [ 0.235435] GMAC - user ID: 0x10, Synopsys ID: 0x33 [ 0.237304] eth0 - (dev. name: stmmaceth - id: 0, IRQ #134 [ 0.237319] IO base addr: 0xfd110000) [ 0.241170] STMMAC MII Bus: probed [ 0.242037] eth0: PHY ID 01410e20 at 0 IRQ 246 (0:00) active [ 0.246176] scsi0 : sata_stm [ 0.248224] ata1: SATA max UDMA/133 cmd 0xfe209000 ctl 0xfe209820 bmdma 0x00000000 irq 72 [ 0.552035] ata1: SATA link down (SStatus 0 SControl 300) [ 0.554968] VIP19xx onboard NOR flash device [ 0.555211] Onboard_Flash: Found 1 x16 devices at 0x0 in 16-bit bank [ 0.556089] Using word write for ST M28WXX0 FLASH [ 0.557015] cfi_cmdset_0001: Erase suspend on write enabled [ 0.558093] 2 cmdlinepart partitions found on MTD device Onboard_Flash [ 0.559019] Creating 2 MTD partitions on "Onboard_Flash": [ 0.560034] 0x00380000-0x00400000 : "FFS" [ 0.562803] 0x00000000-0x00380000 : "Raw" [ 0.564839] No NAND device found!!! [ 0.565073] No NAND device found!!! [ 0.567218] NAND device: Manufacturer ID: 0x20, Chip ID: 0x76 (ST Micro NAND 64MiB 3,3V 8-bit) [ 0.569320] 3 cmdlinepart partitions found on MTD device stm-nand-flex.1 [ 0.570035] Creating 3 MTD partitions on "stm-nand-flex.1": [ 0.571024] 0x00000000-0x04000000 : "system" [ 0.574653] 0x00000000-0x00310000 : "kernel" [ 0.576636] 0x00310000-0x04000000 : "rootfs" [ 0.580399] UBI: attaching mtd4 to ubi0 [ 0.581032] UBI: physical eraseblock size: 16384 bytes (16 KiB) [ 0.582047] UBI: logical eraseblock size: 15872 bytes [ 0.583016] UBI: smallest flash I/O unit: 512 [ 0.584013] UBI: sub-page size: 256 [ 0.585015] UBI: VID header offset: 256 (aligned 256) [ 0.586020] UBI: data offset: 512 [ 1.069105] UBI: volume 1 ("homedir") re-sized from 13 to 923 LEBs [ 1.074498] UBI: attached mtd4 to ubi0 [ 1.075027] UBI: MTD device name: "rootfs" [ 1.076054] UBI: MTD device size: 60 MiB [ 1.077016] UBI: number of good PEBs: 3895 [ 1.078013] UBI: number of bad PEBs: 5 [ 1.079013] UBI: max. allowed volumes: 92 [ 1.080019] UBI: wear-leveling threshold: 4096 [ 1.081016] UBI: number of internal volumes: 1 [ 1.082031] UBI: number of user volumes: 2 [ 1.083013] UBI: available PEBs: 0 [ 1.084011] UBI: total number of reserved PEBs: 3895 [ 1.085017] UBI: number of PEBs reserved for bad PEB handling: 38 [ 1.086012] UBI: max/mean erase counter: 0/0 [ 1.087027] UBI: background thread "ubi_bgt0d" started, PID 244 [ 1.093014] i8042.c: i8042 controller self test timeout. [ 1.094747] mice: PS/2 mouse device common for all mice [ 1.096368] i2c /dev entries driver [ 1.101390] Software Watchdog Timer: 0.07 initialized. soft_noboot=0 soft_margin=60 sec (nowayout= 1) [ 1.102568] stm_rng hardware driver 1.0 configured [ 1.105374] stlpc device driver registered [ 1.106758] ip_tables: (C) 2000-2006 Netfilter Core Team [ 1.107122] TCP cubic registered [ 1.108072] NET: Registered protocol family 1 [ 1.109036] NET: Registered protocol family 17 [ 1.111664] st40 cpu frequency registered [ 1.112133] sh4 suspend support registered [ 1.625524] stmmac_timer: TMU2 Timer ON (freq 256Hz) [ 2.644318] IP-Config: Complete: [ 2.645016] device=eth0ddr=(obfuscated)ask=255.255.255.0w=(obfuscated), [ 2.649011] host=(obfuscated), domain=, nis-domain=(none), [ 2.650015] bootserver=255.255.255.255ootserver=255.255.255.255ootpath=[ 2.653026] Freeing unused kernel memorù[ 2.699342] UBIFS: mounted UBI device 0, volume 1, name "homedir" [ 2.700027] UBIFS: file system size: 10951680 bytes (10695 KiB, 10 MiB, 690 LEBs) [ 2.701019] UBIFS: journal size: 165888 bytes (162 KiB, 0 MiB, 11 LEBs) [ 2.702020] UBIFS: media format: 4 (latest is 4) [ 2.703014] UBIFS: default compressor: lzo [ 2.704014] UBIFS: reserved for root: 0 bytes (0 KiB) [ 3.400174] PHY: 0:00 - Link is Up100/Full init started: BusyBox v1.22.1 (2015-03-31 19:05:47 CEST) starting pid 269, tty '': '/etc/rc.sysinit' Please wait: booting... mknod: /dev/ptmx: File exists mount: mounting shm on /dev/shm failed: No such file or directory ip: RTNETLINK answers: Operation not supported starting pid 306, tty '': '/etc/init.d/init_hal.sh start' [ 5.184424] sttbx_early_core: module license 'ST Microelectronics' taints kernel. [ 5.474284] Load module stos_core [?] by init_hal (pid 311) [ 5.528973] Load module stsys_ioctl [253] by init_hal (pid 311) [ 5.662401] ehci_hcd: Unknown symbol usb_free_urb [ 5.664501] ehci_hcd: Unknown symbol usb_hub_tt_clear_buffer [ 5.665635] ehci_hcd: Unknown symbol usb_hcd_resume_root_hub [ 5.694413] ehci_hcd: Unknown symbol usb_calc_bus_time [ 5.722427] ehci_hcd: Unknown symbol ehci_cf_port_reset_rwsem [ 5.724553] ehci_hcd: Unknown symbol usb_put_hcd [ 5.726164] ehci_hcd: Unknown symbol usb_get_urb [ 5.744686] ehci_hcd: Unknown symbol usb_hcd_giveback_urb [ 5.746344] ehci_hcd: Unknown symbol usb_hcd_poll_rh_status [ 5.747639] ehci_hcd: Unknown symbol usb_create_hcd [ 5.748678] ehci_hcd: Unknown symbol usb_remove_hcd [ 5.766707] ehci_hcd: Unknown symbol usb_add_hcd [ 5.768618] ehci_hcd: Unknown symbol usb_root_hub_lost_power Error while inserting module ehci-hcd.ko [ 5.792058] ohci_hcd: Unknown symbol usb_hcd_resume_root_hub [ 5.807755] ohci_hcd: Unknown symbol usb_disabled [ 5.810232] ohci_hcd: Unknown symbol usb_calc_bus_time [ 5.812639] ohci_hcd: Unknown symbol usb_put_hcd [ 5.834366] ohci_hcd: Unknown symbol usb_hcd_giveback_urb [ 5.835682] ohci_hcd: Unknown symbol usb_hcd_poll_rh_status [ 5.837529] ohci_hcd: Unknown symbol usb_create_hcd [ 5.839408] ohci_hcd: Unknown symbol usb_remove_hcd [ 5.861777] ohci_hcd: Unknown symbol usb_add_hcd [ 5.863700] ohci_hcd: Unknown symbol usb_root_hub_lost_power Error while inserting module ohci-hcd.ko [ 5.869820] hcd_stm: Unknown symbol stm_ohci_hcd_register [ 5.871892] hcd_stm: Unknown symbol stm_ohci_hcd_unregister [ 5.875818] hcd_stm: Unknown symbol stm_ehci_hcd_unregister [ 5.890656] hcd_stm: Unknown symbol stm_ehci_hcd_register Error while inserting module hcd-stm.ko [ 6.871054] LXLOAD(audio1) : LX loaded => Base=0x40400000 - Last=0x4056a434 - Size=1483828 [ 7.349776] LXLOAD(video1) : LX loaded => Base=0x40000000 - Last=0x40152b24 - Size=1387300 [ 7.376114] frontpanel: controller is mounted [ 7.448194] frontpanel: LED character display board with 10 button/9 LED support [ 7.489504] frontpanel: display version: 1 [ 7.536076] input: Unspecified device as /class/input/input0 WARNING! /dev/front_panel not found! Cannot open /dev/front_panel [ 9.198534] Load module stevt_core [?] by init_hal (pid 311) [ 9.200054] Load module stcommon_core [?] by init_hal (pid 311) [ 9.202077] Load module sttbx_core [?] by init_hal (pid 311) [ 9.203088] Load module stclock_core [253] by init_hal (pid 311) [ 9.205585] Load module stclkrv_core [?] by init_hal (pid 311) [ 9.206033] Load module stpower_core [252] by init_hal (pid 311) [ 9.207091] Load module stfdma_core [251] by init_hal (pid 311) [ 9.210633] Load module stmerge_core [?] by init_hal (pid 311) [ 9.211050] Load module stavmem_core [?] by init_hal (pid 311) [ 9.223534] Load module stbuffer_core [?] by init_hal (pid 311) [ 9.224052] Load module stinject_core [?] by init_hal (pid 311) [ 9.225020] Load module stpio_core [?] by init_hal (pid 311) [ 9.226018] Load module stdenc_core [?] by init_hal (pid 311) [ 9.227016] Load module stlayer_core [?] by init_hal (pid 311) [ 9.228016] Load module stvout_core [?] by init_hal (pid 311) [ 9.229016] Load module stvtg_core [?] by init_hal (pid 311) [ 9.230016] Load module stvid_core [?] by init_hal (pid 311) [ 9.231016] Load module stvin_core [?] by init_hal (pid 311) [ 9.232016] Load module stos_core [?] by init_hal (pid 311) [ 9.233028] Load module stvmix_core [?] by init_hal (pid 311) [ 9.234019] Load module stgxobj_core [?] by init_hal (pid 311) [ 9.235025] Load module staudlx_core [249] by init_hal (pid 311) [ 9.237145] Load module stcc_core [?] by init_hal (pid 311) [ 9.238021] Load module stttx_core [?] by init_hal (pid 311) [ 9.239094] Load module stvbi_core [?] by init_hal (pid 311) [ 9.240021] Load module stblit_core [?] by init_hal (pid 311) [ 9.241065] Load module stsmart_core [246] by init_hal (pid 311) [ 9.243043] Load module stnet_core [?] by init_hal (pid 311) [ 9.244036] Load module stpti4_core [?] by init_hal (pid 311) [ 10.005512] Load module stevt_ioctl [245] by init_hal (pid 311) [ 10.006077] Load module stcommon_ioctl [244] by init_hal (pid 311) [ 10.007037] Load module sttbx_ioctl [243] by init_hal (pid 311) [ 10.008027] Load module stclkrv_ioctl [242] by init_hal (pid 311) [ 10.009025] Load module stpower_ioctl [241] by init_hal (pid 311) [ 10.010166] Load module stfdma_ioctl [240] by init_hal (pid 311) [ 10.011088] Load module stmerge_ioctl [238] by init_hal (pid 311) [ 10.012036] Load module stavmem_ioctl [237] by init_hal (pid 311) [ 10.013038] Load module stbuffer_ioctl [236] by init_hal (pid 311) [ 10.014034] Load module stinject_ioctl [235] by init_hal (pid 311) [ 10.015296] Load module stspi_ioctl [233] by init_hal (pid 311) [ 10.016054] Load module stpio_ioctl [232] by init_hal (pid 311) [ 10.017042] Load module stdenc_ioctl [229] by init_hal (pid 311) [ 10.018050] Load module stlayer_ioctl [228] by init_hal (pid 311) [ 10.019067] Load module stvout_ioctl [227] by init_hal (pid 311) [ 10.020047] Load module stvtg_ioctl [226] by init_hal (pid 311) [ 10.021061] Load module stvid_ioctl [225] by init_hal (pid 311) [ 10.022047] Load module stvin_ioctl [224] by init_hal (pid 311) [ 10.023055] Load module stvmix_ioctl [223] by init_hal (pid 311) [ 10.024047] Load module stgxobj_ioctl [222] by init_hal (pid 311) [ 10.025067] Load module stcc_ioctl [220] by init_hal (pid 311) [ 10.026045] Load module stttx_ioctl [219] by init_hal (pid 311) [ 10.027032] Load module stvbi_ioctl [218] by init_hal (pid 311) [ 10.028042] Load module stblit_ioctl [217] by init_hal (pid 311) [ 10.029240] Load module stsys_ioctl [211] by init_hal (pid 311) [ 10.030086] Load module stnet_ioctl [210] by init_hal (pid 311) [ 10.031051] Load module stpti4_ioctl [209] by init_hal (pid 311) [ 10.125072] Module stapler_core (rev: STAPLER-REL_1.7.0) loaded by (pid -257) [ 10.166279] Load module sttkdma_core by (pid -257) [ 10.176630] Load module sttkdma_ioctl by (pid -257) [ 10.237287] input: IR Remote as /class/input/input1 [ 10.260744] lirc lirc: : probe found data for platform device lirc [ 10.261060] lirc lirc: ioremapped register block at 0xfd018000 [ 10.262018] lirc lirc: ioremapped to 0xfd018000 [ 10.263025] lirc lirc: Bound to irq 125. [ 10.264175] lirc lirc: Registered IR-Wakeup device. [ 10.265096] Registered IR-Wakeup driver. starting pid 442, tty '': '/etc/init.d/load_vqe.sh start' [ 11.010663] <vqec-dev>Registered vqec device with major-id 207 starting pid 449, tty '': '/etc/init.d/udploggerd.sh start' starting pid 455, tty '': '/etc/init.d/player.sh start' starting pid 472, tty '': '/etc/init.d/update-dbl-bootscreen.sh start' Missing /etc/nsn/dbl-bootscreen.version DBL bootscreens updated! starting pid 475, tty '': '/etc/init.d/rbl-upgrade.sh start' can't run '/etc/init.d/rbl-upgrade.sh': No such file or directory starting pid 476, tty '': '/etc/init.d/dropbear start' starting pid 477, tty '': '/etc/init.d/sda.sh start' starting pid 479, tty '': '/etc/init.d/openntpd start' starting pid 482, tty '': '/etc/init.d/appman.sh start' starting pid 486, tty '': '/etc/init.d/syslog start' starting pid 489, tty '': '/etc/init.d/rmnologin start' starting pid 491, tty '': '/usr/local/bin/databases_integrity_checker.sh start' grep: /etc/nsn/system.properties: No such file or directory Starting syslogd/klogd: Starting openntpd Creating Dropbear SSH server RSA host key. done Starting ntpd (-f /etc/nsn-static/ntpd.conf) Generating key, this may take a while... Public key portion is: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDSqNdppCnpqC/b/EJRG6B8fbqmoTuI5q2UxULJFvwR 1CPRlPMjJtlSH68af4Fy+QvKhzik1v8e+VKThBrM3Li/ZtCmgzBtv0vRLAta0YYArSsskfox Haxk4D8f8j/uOSoETZO80/KUA1RCbAzVmP97ETeWAjqBnxiMvPJieaWet3g/Wl85wdzS/2UP Kl1oInIxGJXkg+wkpeAFw0+AbVevElBYPn+aAUTdIOjTLZal8nIAIIji4LCyl1Cjs8OLjj+P lqEGm3oSxGL1Hv7GqD5SrA8qMYxogAuPke8isw4BmsP/jXTKI7FOf8QHIHXHCwjQXKPqBthl m/MOP50vEn3f root@stb Fingerprint: md5 ab:22:15:82:86:fa:7a:b7:5d:e1:44:96:f9:b0:61:a9 Starting Dropbear SSH server: dropbear. [ 149.902735] <VQE_UTILS-6-VQE_MP_TLV_INFO> MP_TLV related info message (detail: MP - Decoded TSRAP TLV data, tlv proc=7, TS pkts generated=14) [code]
Gast
#4144201
You might like this attachment
Gast
#4145446
Maybe we can also use this manual to the STI7105 ? Hello, is it possible to get image for Arris VIP1003 in which remote works. I have tried few of these and they work but remote does not function? I have a lot of these devices and would like to use them in my iptv if i can find correct image for them. You can contact me on email info[at]meganet[dot]ba. Is this thread dead? Nope. Search for the SDK and you can make your own images. Or post the remote code so someone with the SDK can make you an image. I already downloaded SDK, compile it successfully. Im not so familiar with all this things, and im stuck in how to make .bin file? If you can help me with this it would be really good. Thank you in advance. Anyone can help me with this? :)
Gast
#4187795
Hi Martin, I have Set-top box motorola vip1003(Sonera). Set-top box flashing on tftp absolutely normal, but after flashing - error 4, after reboot Set-top box - error 3.... I understand the problem is bootkast id? @Martin Regarding your question about 19x3 and JTAG. I was able to connect to 1963 and dump full 32MB NOR, and even write it back to STB and it's still alive. BL version is 2.xx (I'm not sure which one). I can send you the dump if you want it. Can you please send me the EMEA SDK kit which keeps disappearing from the internet? My mail is reg.blagus[gmail] How did you connect? I can't connect to the 1963 or 1903 I used FTDI's FT2232HQ Mini Module (FT4232H is fine too) and official STMC toolset. You also need STburner which you have to modify so it can recognize 1963's NOR. I had that copy of STburner somewhere, compiled for 1963, I'll try to find it and send it to you, together with 2.xx bootloader dump I made. As far as I can remember, NOR also contains some default configuration, XML files, MAC and serial and there might be some keys (in XML files), but I'm not sure. That's the least thing I can do as a thanks for your mail.
Gast
#4232635
Hi Martin, "option KreaTV.kernel-protocol" for boot order. What option number is that?
Gast
#4232704
Hi Mac, I think you mean for: 1 = BootCast 2 = TFTP 3 = Local Storage (if available) 4 = SAP (Session Announcement Protocol) 5 = DVD/CD (if available) 6 = HTTP (available from version 3.03) I used as 323 kernel/slash
Gast
#4232721
Hi all, Kernel setup: 1.run logclient.exe 192.168.2.200 2.run putty -telnet 192.168.2.200 3.vi /usr/applications/ekioh/ekioh.cfg 4.add line application.homepage:http://192.168.2.131 5.killall ekioh that is right order.
Gast
#4232785
Hi Claude, not really what I meant. I meant which DHCP option since our boxes have a new bootloader which cannot be programmed by hand. I saw that Martin had this in his debug: 00:00:08 01.01.2000 src/dhcp.c 276 DBG > Kernel Protocol Order: 00:00:08 01.01.2000 src/dhcp.c 280 DBG > 2 So I assume he knows what DHCP option that is.
Gast
#4232845
Hi Mac, That be nice have new bootloader im using old version but loading. kreatv-bi-eval_4.3.IAP30.3_st40_vip19x3.bin(new)FW kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin(old)FW It old bootloader has public key hide. I have little problem with New-FW ekioh settings dont stay after reboot setting are cone. Tryed "toish is SetObject config.ekioh.application.homepageurl http://192.168.2.131/index.html permanent" but is dont read them. Puted /flash/securestroage is flash parition as NAND. Now i need put script but init dont have them. old version that toish command worked fine so. i stay new one or old one heh.
Gast
#4232859
Old bootloader working 5 green balls meaning while loading FW 1.1 ball loading FW TFTP/bootloader/http 1.1 small ball loading FW 2.1ball extract FW to flash 2.2 small ball flashing FW 3 ball check is FW unic to keys 4 ball load FW to RAM 5 ball run FW Wrong version FW crash in 3 ball sector Does anyone have a dump of a KPN branded box with the new bootloader? I'd like to figure out if we can get custom code running. Alternatively, any VIP19xx/18xx dump would be welcome, I currently have none. I'm also still looking for the SDK. Email is username AT gmx com Thanks!
Gast
#4233187
/#toish
Usage: toish [<component>|<component alias>] <operation> [arguments...]
Environment variables used:
NAMESERVICE_ADDRESS The address of the name service, this has
precedence
NS_ADDRESS_FILENAME A file from which the name service address can be
read
Defaults to /tmp/nameservice_address
Available components and operations:
applicationservice, as:
Activate <application id>
Activate application <application id>
ActivateWithUri <application id> <uri> <mime type>
Activate application and load uri with it
RegisterApplication <property file path>
Register new application
Kill <application id>
Kill application <application id>
LoadUri <uri> [MIME type] [whitelist]
Load the URI <uri>; the MIME type is guessed if not specified
If "whitelist" is appended, the uri is added
to the portal whitelist (as volatile)
Info
Get info on registered applications
informationservice, is:
GetObject <object name> | all
Returns object value ("all" is for all objects)
GetObjectNames [<adapter> | all]
Returns the names of all objects provided by <adapter> or by all
adapters (default) in alphabetical order.
SetObject <object name> <value> [volatile | permanent]
Set the object, default storage type is volatile
SetObjectFromFile <object name> <file> [volatile | permanent]
Set the object, default storage type is volatile
UnsetObject <object name> [volatile | permanent]
Remove object, default storage type is volatile
platformservice, platform, ps:
RebootNow
Perform a controlled reboot, with components being shut down
properly.
RebootAtNextStandby
Reboot the platform the next time the system goes to standby state.
SetStandbyMode [ true | false | 0 | 1 ]
Deprecated. Same as SetStandby.
SetStandby [ true | false | 0 | 1 ]
Enter or leave standby.
True corresponds to standby, while false corresponds to normal
operation.
uriloaderservice, uriloader, uri:
LoadUri <uri> [MIME type]
Deprecated; use "applicationservice LoadUri" instead
videooutputservice, videooutput, vos:
SetDefaultVideoMode [ HD | SD ] [ disable | 480i | 576i | 576p | 720p
| 1080p |
1080i ]
Sets the default video mode for an output, i.e. the video mode to
use if no
adaptive rules have been set.
SetVideoSafeMode
Sets the video outputs in safe mode configuration.
SetScartMode [CVBS | YC | RGB]
Sets scart output mode.
Found command that reboot remember settings with
toish is setobject cfg.portal.whitelisturls "
<PortalURLs>
<PortalURL>http://192.168.2.131</PortalURL>
<PortalURL>http://192.168.2.131/index.html</PortalURL>
</PortalURLs>
" permanent
Now all working great.
log1.log has old loader log-file reboot to startup
Thanks for all!
@Mac from the SDK I set it to tftp from dhcp but I think the key is wrong so it won't work with the newer bootloader.
Gast
#4234293
Hi Martin, thanxx for the dhcp options! You also included the numbers so I could put them directly in dnsmasq. The reason that your (or any, even official) old FW isn't working anymore is because the new bootloader expects a new encryption. KAC1 (According to the header)
Gast
#4254426
hi claude please can you help me on 1853? regards
Gast
#4256430
Can someone re-upload the sdk? The 4shared link is dead... Here are the instructions on using JTAG to dump/write NOR flash on VIP1963. You need: FT2232HQ or FT4232HQ mini module (or another 2232/4232 breakout board). Wire and setup everything according to the instructions in this PDF: http://www.avi-plus.com/repair-tips-forum/miscellaneous-software/others/st40-stb71xx-jtag-interfacing/page-2.html#658 (post #658) (On Windows, grab official FTDI drivers and add modified VID/PID. Linux will do the magic itself.) Install latest ST40 Tools and STMC2 from here: http://ftp.stlinux.com/pub/tools/products/ If you're on Windows 8/10, set compatibility options to Win7+Run as Admin. If you're on Linux, you'll also need to add tools dir and libs to PATH and do some magic regarding the targetpacks location - I can't remember what exactly, so I'll come back to it in a later post - but error messages will lead you in the right direction. Download this: http://www.mediafire.com/download/gz430oxs3fah6q8/STBurner_vip1963.7z Inside you'll find 4mib.bin - first 4MiB dump of my Motorola VIP-1963. I have to play more with block sizes and add some debug output to make it read all 32MiB instead of looping on first 4, but the essential part - RedBoot and Linux image - are there. Serial and MAC is spoofed. If you're brave enough, edit them to match your STB and try writing it - worst case scenario is that you'll end up with non-bootable STB until you (or me) figure out actual block size values for STBurner which will read/write the dump correctly. Executable is flasher.out, which is sent to the device with sh4xrun utility. Targetpack for 1963 is mb448 (I used non-"se", 29-bit version). Example commands are in run.bat file. Linux and Windows syntax is the same. -r option is for reading, -p option is for writing. If you need more help with setting up STLinux and STBurner, read this: http://blagus.info/stlinux-env-setup-part1/ I bought a KPN VIP 1960 from a thrift shop here in holland. It looks absolutely unused and has even older firmware than the unit Martin V. opened this thread with. RBL 1.7, Firmware 2.20
The kernel is compiled a few months earlier than Martin V.'s 1960 unit. I was expecting no problem booting from his images. However I get this error message:
I tried every image I could find, including the evaluation images from motorola. Same error message every time! Any help is appreciated! Strange, all the 19x0 boxes I've had so far can be used. Only none KPN boxes I couldn't use because they use an other key. I was finally able to install the images by switching from bootcast to tftp. Absolutely no idea why the bootcast download did not work. It worked fine to install the splash image, so the server was set-up correctly as far I know. I lost some time figuring out how to specify the filename for the tftp download, as my box did not use the name specified in the advanced settings menu. It did for the splash filename, but not for the bootimage. You need to specify the name in dhcp option 67. May be it only uses the data from the advanced menu with static ip. I did not test that (yet).
Gast
#4333774
http://www.multiupfile.com/f/67c031c4 here kreatv-kit-starter-kit-emea_4.3.iap30.3_i386.tgz Regards Hi everybody I am new here and I am looking for 4shared files that had been removed So does anyone still have: kreatv-doc-sdk-user-manual_4.3.IAP30.3.tgz and kreatv-extra-iip-package-ericsson_mu_4.3.IAP30.3.tgz Thanks for Anwsering and Best Regards PS: I is there any difrence between Starter Kit and SDK if someone can send me SDK (beacuse I only have starter kit so far) it would be great Thanks for Anwsering and Best Regards
Gast
#4443134
Hi sab Sorry belate message, but im using version 1903 version. Ohter version i don't know how they working is take some time lookout, how they working. Is there software(OS) or bios(FW) replaisment ? Bios need open box and use UART(3-4pins) and use Console(COM1). Software can replaise with right version each boxes as unic security key. So wrong version don't boot but finding right verison need ask ohter people find same version with right Software(OS). Look luck finding ----------------------------------------------------------------------- Source codes can build with VIP19X0/VIP19X3/VIP1003/VIP1853 set-tops http://sourceforge.net/projects/vip19x0.arris/files/ST40/KreaTV%204.6%20-%204.9/ 1.Download file 2.Config settings right version. (./configure) 2.2 read more information inside README file with notepad 3.Build it(make) 4.Then is ready right version with security code and OS. Uploaded with how build with OS with security key script. http://www.multiupfile.com/f/acb9316e Found inside kreatv-kit-oss_4.4-st40.tar Key finding is diffrent story how find it. but that good find Blagus B dump 4mb(NAND) they meybe has right security key. Claude Software engineering
Gast
#4443138
kreatv-kit-oss_4.4-st40.tar was http://sourceforge.net/projects/vip19x0.arris/files/ST40/KreaTV%204.4/ Claude
Gast
#4443155
ok i meybe find it.
---------------------------------------------------------
check_3pp_license(file has information how build it)
----------------------------------------------------
file=3PPLICENSE
elif [ -f $FILENAME ]; then
sha1=$(sha1sum $FILENAME | cut -f 1 -d ' ')
---------------------------------------------------------
3PPLICENSE(key code)
----------------------------------------------------
NAME=STLinux
VERSION=stm23_A27
LICENSE=GPLv2
TARGET=vip19x[03]
FILENAME=stlinux23-STAPI-kernel-sh4-2.6.23.17_stm23_A27-123.noarch.rpm
SHA1=d81112551394a0b0e19e69d0ecea0eab48d14d1f
END_HEADER
END_ATTRIBUTION
------------------------------------------------------------
GPLv2(key)[18kb]
--------------------------------------------
GNU GENERAL PUBLIC LICENSE
etc.
etc.
etc.
use the GNU Lesser General
Public License instead of this License.
----------------------------------------------
So GPLv2 need encode with OS header then is working right.
http://www.gnu.org/licenses/old-licenses/gpl-2.0.html#SEC1
there has too that GPLv2(key)(file)
claude
Gast
#4928333
Hello,
did someone finally make something of latest sdk available on
sourceforge. I was able to make image with 4.3 starter kit for my
vip1003, but with latest sdk I can't do anything. Since 4.3 is quite
old, ekioh/webkit on it is unusable. I saw that there are available
images with newer software, like this here:
<?xml version="1.0"?>
<!DOCTYPE StbConfig SYSTEM "stbconfig.dtd">
<StbConfig>
<BootParams>
<KernelUrl>http://82.199.133.52/static/bootimage/v9.9/kreatv-bi-vip1003.config_4.9.case954144.devdrop2_v9.9_vip1003_st40_vip10x3.bin</KernelUrl>
<KernelVersion>4.9.case954144.devdrop2_v9.9_vip1003</KernelVersion>
<SplashUrl>http://82.199.133.52/static/bootimage/v9.9/splash_vip1003.bin</SplashUrl>
<SplashVersion>3.2</SplashVersion>
</BootParams>
</StbConfig>
Anyone know how to extract this image?
Flash it to a box and hopefully it has telnet so you can get in.
Gast
#4939392
Nope, it doesn't have telnet enabled. I've spend few days looking for some solutions, but seems only jtag is solution, if I found correct pin-out and then somehow unpack firmware. I know that update firmware is encrypted, but don't know is flash encrypted. Basically, I just want newer version of webkit browser from image. The image mentioned above has 536 version, but this one from starter kit is 532, which is way too old.
Gast
#4988749
Igor you have to use script from: Beitrag "Re: Pollin MOTOROLA VIP1710" but you need key for VIP1003 and you will need find right start position to decrypt from. After decryption you use binwalk to check result. If binwalk find something, use parameter -e to extract it. Good luck
Gast
#4988876
Hi there, I have VIP1853 but not remote control. Please give me solution to enter in secret menu and delete original firmware. I use sound files to set my Samsung TV (and unlock hidden menu). May sombody digitalize menu, digits arrows, OK and Exit (I think that's enough) to use with smartphone and 2 infrared leds Hey all, A Little help here please (hope this topic isn't closed). I'm working with a Motorola VIP 1903. I want to make a client to tvheadend witch may be possible. BUT first things first. The bootload image(s). I'm was not able to get bootcast server to work. So I went ahead and tried the tftp boot. My tftp bootserver (and webserver, dhcp server) is on a synology ds 1815+ NAS server which can do tftp and pxe boot. PXE boot works fine on pc boots. So I thought I just put bootimage in tftp root and pointed boot file to the .bin boot file downloaded from this site. Then I set the boot protocol on Motorola box to 313 (Local, tftp, local). Tried with these: kreatv-bi-eval_4.3.IAP30.3_st40_vip19x3.bin kreatv-bi-test.config_4.3.IAP30.3_st40_vip19x3.bin kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin No luck. Then I thought of giving the box it's own static ip. No luck Then I tried booting from webserver (.bin file in root folder) With static or dynamic ip (and bootprotocol set to 363). Still no luck I think there is some kind of information that I have missed. When setop box is booting the first two balls goes green. By the third ball there comes this error message: An error occur updating the software....... Question is what didn't I do right? I hope someone can help me. This project could really turn into something big. Problem might be the wrong keys in the image. Try to log what the 1903 does during boot. Look for logclient in this thread. Greetz
Gast
#5026028
Hi again, I found remote control like this https://www.google.bg/imgres?imgurl=https%3A%2F%2Fstatic.kpn.com%2Fspecials%2Fafstandsbedieningtool%2Fafstandsbediening-kort.png&imgrefurl=https%3A%2F%2Fwww.kpn.com%2Fservice%2Ftelevisie%2Finstalleren%2Fafstandsbediening%2Finstellen.htm&docid=b0JEP3haMTJjFM&tbnid=4J34tqU_CoC2lM%3A&vet=10ahUKEwjfra-z_pbUAhWElxoKHQ2-A2AQMwg0KBEwEQ..i&w=640&h=360&client=firefox-b&bih=859&biw=1851&q=motorola%20vip1853%20kpn%20remote%20control&ved=0ahUKEwjfra-z_pbUAhWElxoKHQ2-A2AQMwg0KBEwEQ&iact=mrc&uact=8 but when box booting nothing happend when I push menu button. On 19x3 with new boot loader is the problem same or simply my remote control not for vip1853.
Gast
#5257649
Hello Martin et al, With the expertise about Vip19x0 found in this thread, I hope this is a good place to ask this question: I have a Motorola VIP1920-9C Conax/ComHem box, so it seems locked to only be used with ComHem, but I wonder if there is any way to use its onboard DVB-C to view the free, non-ComHem cable channels available where I live now? From reading this thread, my guess is that the answer is that this box is totally locked down and that there is no known way around this, but I thought I'd ask anyway. Maybe things have changed in the last year or so? Anyway - great thread! Take care, everybody! Hi, I've also a Comhem cable box with remote (and even keyboard I think) Worked fine on Dutch Cable with Comhem software for FTA channels, untill I started to try and replace the software which didn't work because of missing keys. Greetz
Gast
#5415703
My box successfully boots kreatv-bi-test.config_4.3.IAP30.3_st40_vip19x3.bin (and kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin) from above. Which AES key I can use to decrypt those images with decrypt.c (Beitrag "Re: Pollin MOTOROLA VIP1710")? Can I use the same key to decrypt the original firmware of my box? I think files are created from SDK with default developer keys. So if you find SDK you'll find the keys.
Gast
#5416718
I found kreatv-kit-starter-kit-emea_4.3.IAP30.3.zip, but the keys are in "KreaTV format" with SEC header and I understand that the keys themselves are encrypted. At least using last 32 bytes of the 41-byte file as an AES key did not work. Since I can boot kreatv-bi-test.config_4.3.IAP30.3_st40_vip19x3.bin, I can of course telnet to the box and read the flash, but I don't know how to interpret the comment in decrypt.c: "Seems to come from section at 0x1cf700 in NOR. More work needs to be done to figure out how it is decrypted." I tried to use 32 bytes from position 0x1cf700 of the NOR flash as the key, but that did not work. Then I checked all sections starting with "SEC", but none of them looked like an AES key. The comment in decrypt.c seems to imply that the key itself is encrypted. Yet http://www.duff.dk/zaptor/ writes that "the key for decryption is piece of cake to extract"??? Thanks for any hints!
Gast
#5850956
Hello, someone knows how to decrypt biss in 4.4. The server streams mpegts which is encrypted with biss. Can anyone suggest? I want to access Firmware setting menu for Arris VIP4302 STB. But I don't know the four digit code to access the advance menu. I am trying 7532 but it does not work. So, it might not be for this model. Does any one now this code? Thanks Antwort schreibenBitte melde dich an, um einen Beitrag zu schreiben. |
Anzeige
|