Home repair tips forum

PM Notification

You are not logged in.

Welcome, Guest
Username Password: Remember me

Search Forum

Keyword

EJTAG MIPS BCM7358
(1 viewing) (1) Guest
  • Page:
  • 1

TOPIC: EJTAG MIPS BCM7358

EJTAG MIPS BCM7358 7 years, 3 months ago #2190

  • n01knows
  • OFFLINE
  • Junior Boarder
  • Posts: 32
  • Karma: 0
Hi guys

i have recently received a new STB for testing

it uses the BCM7358 CHIP + Macronix MX25L3255DXCI-10G flash and 1GB nand flash macronix MT29F1G08AB
interesting enough this unit supplied by tv provider is running on LINUX OS, and after digging a litle bit i found some tools and sdk for it.

i bought some tools in order to make some flash dumps, but so far i only got success in serial comunication via RS232TTL serial converter, but any interaction via SSH or hiperterminal is blocked, i guess it might be something related to the U-BOOT or the cfe.signed

this motherboard is very tiny, but it comes it 2 UART and 1 EJTAG-ETG

i have bought USBJTAGNT and Cypress EZ Tools but so far no luck with detecting the ID on the USBJTAGNT

i am wondering if anyone else as made testing on the BCM7358 Mips in order to suceed in DUMPING the flash via JTAG

also J2 pinout 4 pins seem to be a BBS pinout

BBS pinout
1 is 3v3
2 is BSC_SCL
3 is BCS_SDA
4 is GND

so i will try to use EZ-CYPRESS tool later to see if i can get any extra information.

Using USBJTAGNT when i press IDCODE it doest not detect any id via JTAG any ideas on what i might be doing wrong?
attached some pics and RS232 log







and some logs of rs232ttl serial converter conection
Technicolor - DST7xxxx - Launcher v1.10 prod

starting pid 190, tty '': '/etc/init.d/rcS'
Mounting virtual filesystems
/etc/init.d/rcS: line 6: mkdir: command not found
mount: mounting none on /proc/bus/usb failed: No such file or directory
mount: mounting debugfs on /proc/sys/debug failed: No such device
/etc/init.d/rcS: line 12: mkdir: command not found
mount: mounting devpts on /dev/pts failed: No such file or directory
Starting mdev
* WARNING: THIS STB CONTAINS GPLv3 SOFTWARE
* GPLv3 programs must be removed in order to enable security.
* See: www.gnu.org/licenses/gpl-faq.html#Tivoization
insmod: can't insert 'change_uid.ko': No such file or directory

NFLL_IOC_OTPSTATUS value [1] ret [0]
/home/DST7xxxxx/SW3.0/BCM_HD/nexus/../magnum/syslib/hdcplib/7358/bhdcplib_hdcpke
ys.c BHDCPlib_GetKeySet 140: Have gotten HDCP key from flash
#STATION ** OSC Notify: o_station_control_init line: 3631
****************appstore init 1************

#APPSTOR DUMP >>>
#APPSTOR dumping 1 entries from generaion 0
#APPSTOR entry 0: 1/1 'TeleIDEA'/'iguide' 1
#APPSTOR tok=32770 size=1994388, ve=20, exp=ffffffff, auth=ffffffff, l
im=ffffffff
#APPSTOR <<< DUMP

#TRACE BEGIN:
DST7xxxxxx;
DST7xx;00;
Macronix/MX25L3255DXCI-10G#
Macronix/MT29F1G08AB
AEAH4;
31730921861000ÿÿ;
D2F201309218616;
37060580;
182092180205;;;;;;;
SWV3.0;Iguide;
0.00;0.00;;;;;
00000000;
8B849374;
2B5FA5E4;
6B510EB6CA000000;;;
4432C800C46C;;;;
00001C07;;;;3c#TRACE END

Calling CAO_Pre_Init()


***************************Calling CAO_Pre_Init() *****************************




***************************After CAO_Pre_Init() *****************************

[ext_sfs.c(0009)] ############################ ext_sfs_init_2 ##################
###########
[ext_msm.c(0099)] ############################ ext_msm_init_2 ##################
####
@@ start MSM init 2
** o_msm_register_medium_verifier ok!
#SECURE:WARNING: / is not permanent
gdbo raw port not initialized
#INTPRT[RESET] starting
[o_xyman_client_register] success: client = 1ce0850.
#INTPRT[RESET] init
(HON_Tuner_Init,2296): pipeId:[2] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[6] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[7] TunerIndex 0
### can't find SVL ID 10 - o_svl_retrieve_by_id() returns 4, handle = 0, state =
5
(HON_Tuner_Init,2296): pipeId:[4] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[5] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[9] TunerIndex 0
@@@
[EMBNP]
NP version <EMB.HD.3.69> built on <Fri Jun 7 15:39:10 2013>
with CORE version <CO22057>

@@@ [EMBNP] manufacturer = Tech_DST7xx
@@@ [EMBNP] manufacturer_version = SWV3.0
@@@ [EMBNP] opentv_version = CO22Q57A


***************************Calling CAO_Init *****************************


CAO Version: 2.022
CAO Date: Wed 10 Oct 2012 23:03
CAO Build Date: Oct 19 2012 09:04:06
CAO Version String: R-AOXAF-ABPAR
CAO Debug: Off

ca_scal_init> serverThread:event=1,cardState=0
ca_scal_init> serverThread:event=3,cardState=1
ca_scal_init> serverThread:event=0,cardState=1


***************************After CAO_Init *****************************

ca_scal_init> serverThread:event=1,cardState=3
*************************** DVL Initialized successfully ***********************
****

Before dropping the privilege : Running with UID 0 (effective 0)
GID 0 (effective 0)

After dropping the privilege : Running with UID 1000 (effective 1000)
GID 1000 (effective 1000)
!ctl_omm_init_3>>>
#OMM: omm_evt_mgr_init called
OMMDL: download_app_handler_init
[np_net_control_usvl_init] Updating User List... NO!
HDMI: resolution: 1280x720, frequency: 60, aspect ratio: 1
HDMI: resolution: 1280x720, frequency: 60, aspect ratio: 1
HDMI: found incompatable HD format: frequency: 60, aspect ratio: 1, horizontal p
ixels: 1280
HDMI: vertical pixelsl: 720, interlaced: 1
!ctl_si_tune_start>>>
!ctl_si_tune_do>>> -1 0
actual direct size: direct_segment_size() = 25165824, direct_segment_ptr=0x6
04d8cc0
far_segments_number()=0
total user heap size : 0
far_size_inquire()=0
!DSM INIT 0 0
!DSM INIT 0 0
!DSM INIT ret -1 -1
!DSM INIT 0 0
!DSM INIT 0 0
!hack bad usb msd
(HON_Video_P_DataReadyCallback,555) Decoder mute state changed from [unmute] to
[mute]! for 0
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
!second try 0
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
cc_turn_on_off:0 1
cc_monitor_main: Close Captioning Monitor Starting ...
[hddstate.c(0641)] ############################## ext_ptm_init_3 ###############
#######
[hddstate.c(0444)] o_fs_register_client return 0
[hddstate.c(0449)] system_timer_new(USB_TIMER_TAG) success!
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
[o_xyman_client_register] success: client = 1ca2560.
!ctl_omm_ready>>>
(HON_Video_P_DataReadyCallback,555) Decoder mute state changed from [mute] to [u
nmute]! for 0
#INTPRT[READY] unexpected message, ignored
#INTPRT[READY] unexpected message, ignored
(HON_Tuner_DoScan_priv,1529): NOTIFY_DEMOD_LOCK_FAILED
!demod state: 6 4 4 4
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:4 Freq: Before 17903616 After 1
1130000
!DEMOD demodulator type 6
!ctl_si_tune_do>>> 0 45
!ctl_si_tune_do: ts 1.3 256 11130 29892 0x0700 0x00000213
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:4 Freq: Before 17903616 After 1
1130000
[msvlmgr_config_control_storage] returns 1
!ctl_si_tune_stop>>>
=================== SVL update 260 ....
[np_store_svl] calling s_store_msvl ...
[s_store_msvl] MSVL_STORE_REQUEST returned 0
Unlocking MSVL with SQnC name MSVL_QRY_NAME
CTL_BOOTUP_WAIT_TIMER_TAG
ctl_launch_iguide_app>>> reason 0 arg "1" ""
#AEE app 33 state NON_EXISTANT->NEW
#AEE app_instance_set_property(21, STATUS(INT) 0x1(4))
#AEE app_instance_set_property(21, TOKEN(INT) 0xfffb(2))
#AEE app_instance_set_property(21, AEE(INT) 0x1(4))
#AEE-OCODE unhandled AEE command 5.0 21, 0, 0
#INTPRT[READY] IN_FLASH_APP


***************** app scheduled to run ********************

app name = iguide
producer = TeleIDEA
prodid = 1
applid = 1

***********************************************************

!isdbt_refresh_eit>>>
#AEE app_instance_set_property(21, 0x122(BINARY) *0x5a2f7468(56)
#AEE-OCODE unhandled AEE command 7.0 21, 122, 0
#AEE app_instance_set_property(21, 0x122(BINARY) *0x5a2f7468(56)
ctl_check_persistent_popup: not persistent popup to display
#AEE-OCODE unhandled AEE command 7.0 21, 122, 0
#INTPRT[RUNNING] running:0xfffffffb
Stack Boundaries [0x5fed8ccc-0x5fedace0] (size=0x00002000)
Data Boundaries [0x5fedacf4-0x6004cd44] (size=0x00172050)
Bss Boundaries [0x6004cd44-0x6009485c] (size=0x00047b18)
---------- Manufacturer info -----
OpenTV version : CO22Q57ATech_DST7xx
Manufacturer : Tech_DST7xx
Manufacturer version: SWV3.0
----------------------------------
----------------------------------------------------------------
(c) TeleIDEA BV, Eindhoven, The Netherlands
iGuide PVR for XXXXXXXXX, version: 1.24.4, build: 20
OpenTV version: 20
Build date: Jul 18 2013 12:11:02
----------------------------------------------------------------
Heap available: 4472728
Heap biggest: 4472724
Stack start: 0x5fedac60
[IGUIDE-20][00:00:23.878_01/01] INFO: manufacturer: 'Tech_DST7xx'
GMT time: 01-01-1970 00:00:23
Local time: 01-01-1970 00:00:23
O_time_daylight_change() FAILED
[IGUIDE-20][00:00:23.888_01/01] INFO: OpenTV version: CO22Q57ATech_DST7xx
[hdop.c(1380)] ** Leave standby - launch iguide - HDD_INFO SQC **
[hdop.c(1486)] cache_notify=255, medium_h=0x0, notify_reason=0
[hdop.c(1495)] ** NotifyIguide with-0x0(NP_RESTART_IGUIDE_NORMAL), status=<>, ca
che_notify=255
[IGUIDE-20][00:00:23.951_01/01] Detected:
[IGUIDE-20][00:00:23.952_01/01] Nr of hdds: 0
[IGUIDE-20][00:00:23.953_01/01] Nr of fat partitions: 0
[IGUIDE-20][00:00:23.955_01/01] Nr of sfs partitions: 0
[IGUIDE-20][00:00:23.955_01/01] Notify reason: 0
[IGUIDE-20][00:00:23.956_01/01] Medium: 0
Chip Revision is: A1
Chip Revision is: A1
[IGUIDE-20][00:00:24.260_01/01] ERROR@3097 CASystem: Could not get product name,
i=0, size=12, status = PARAMETER_INVALID
[IGUIDE-20][00:00:24.261_01/01] ERROR@3097 CASystem: Could not get product name,
i=1, size=12, status = PARAMETER_INVALID
[IGUIDE-20][00:00:24.633_01/01] WARNING, can not open source file '/flash/igfav1
.svl' for copying
[IGUIDE-20][00:00:24.645_01/01] WARNING, can not open source file '/flash/iglock
.svl' for copying
[IGUIDE-20][00:00:24.650_01/01] O_PIPE_CURRENT_PROGRAM_STATUS, connection: , sta
te: 0
[IGUIDE-20][00:00:24.654_01/01] O_PIPE_CURRENT_PROGRAM_STATUS, connection: , sta
te: 0
!PROG ON "rb_display" "service" "1" "3" "21" ""
!prog on after 3pa
!np_ph_resource_array_new>>> rb_display service.1.3.21 service.1.3.21 SVL_ID:10

!PH NEW service.1.3.21 -> sat_tuner_class?SR? usage rb_display#service.1.3.21
!np_ph_resource_get_pipe_name_global>>> sat_tuner_1 broadcast_class display_clas
s
!np_ph_resource_get_pipe_name_global>>> sat_tuner_1 playback_class display_class

!np_ph_resource_get_pipe_name_global>>> sat_tuner_1 broadcast_class display_clas
s
!np_ph_resource_get_pipe_name_global>>> sat_tuner_1 playback_class display_class

!PROG ON "sat1_display" "service" "1" "3" "21" ""
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:2 Freq: Before 17903616 After 1
1130000
[IGUIDE-20][00:00:28.829_01/01] ERROR: System time not set (cable unplugged?)
(HON_Tuner_Disconnect,2829): Received HON_Tuner_Disconnect for pipeId: 5
(HON_Tuner_Disconnect,2880): ISDB-Tb HON_Tuner_Disconnect



Any ideas or options will be welcomed, as i´ve tried reading the Flash model via Universal Programmer, but data i am looking for seems to be either on the nand flash or exra encrypted with new algos, so i am only left to trying a jtag option in order to read some other area´s contents..

thanks in advance

n01kn0ws
Last Edit: 7 years, 3 months ago by n01knows.
The following user(s) said Thank You: aerorockets

Re: EJTAG MIPS BCM7358 7 years, 2 months ago #2227

  • kangaro0
  • OFFLINE
  • Fresh Boarder
  • Posts: 2
  • Karma: 0
hi
have test the volt out on the BBS pinout as many stb with the same cpu are missing some resistance ( 0 ohm ) that connected the sda and csl to the cpu .
waiting yr reply

Re: EJTAG MIPS BCM7358 7 years, 2 months ago #2231

  • n01knows
  • OFFLINE
  • Junior Boarder
  • Posts: 32
  • Karma: 0
dmxjo wrote:
hi
have test the volt out on the BBS pinout as many stb with the same cpu are missing some resistance ( 0 ohm ) that connected the sda and csl to the cpu .
waiting yr reply


It looks like this unit has got all the resistors in place

my nex question would be, can Broadband studio dumpl flash contents or just be used to write flash?

Re: EJTAG MIPS BCM7358 7 years, 2 months ago #2232

  • kangaro0
  • OFFLINE
  • Fresh Boarder
  • Posts: 2
  • Karma: 0
Broadband studio can dump flash contents i'v test it under vu+ duo witch have bcm7335 the problem is that i,v seen only 3 package around the net
its for Bcm97413 Bcm97335 Bcm97325
the else needs adeveloping registered user to download it thats for the uart.
i can help you to enable ejtag for this cpu i know the hardware stuff you only need an interface that support bcm7358 and you flash .
regards

Re: EJTAG MIPS BCM7358 7 years, 2 months ago #2233

  • n01knows
  • OFFLINE
  • Junior Boarder
  • Posts: 32
  • Karma: 0
dmxjo wrote:
Broadband studio can dump flash contents i'v test it under vu+ duo witch have bcm7335 the problem is that i,v seen only 3 package around the net
its for Bcm97413 Bcm97335 Bcm97325
the else needs adeveloping registered user to download it thats for the uart.
i can help you to enable ejtag for this cpu i know the hardware stuff you only need an interface that support bcm7358 and you flash .
regards



Hi PM sent

Re: EJTAG MIPS BCM7358 7 years, 2 months ago #2235

  • Hogan
  • OFFLINE
  • Fresh Boarder
  • Posts: 1
  • Karma: 0
hi there,

i have also a stb with bcm7358.
It is a different layout,details hereBCM7358

i think the pinout J7 could be BBS Pinout
on 3 pins i have 3.3v and one pin is 0v

Anyone have the bcm97358.msi file?

i have the bbs tool
cypress is ordered
need the file also

Re: EJTAG MIPS BCM7358 7 years, 1 month ago #2280

  • emmiko888
  • OFFLINE
  • Fresh Boarder
  • Posts: 3
  • Karma: 0
Hi there I'm looking for some help I'm trying to get a ejtag to be able to copy and reflash modified firmware to a broadcom bcm7335 chip my problem is I do not know ere the ejtag points are and what to use to read it and reflash etc any help would be much appreciated thanks in advance my email address is This e-mail address is being protected from spambots. You need JavaScript enabled to view it

Re: EJTAG MIPS BCM7358 7 years ago #2289

  • wyse
Hi Guys,
Can you help me in bcm97358.msi file?
I also ordered cypress board, now I am looking for right pinouts, later I will attach pics
Thank you in advanced for your help.

Re: EJTAG MIPS BCM7335hi 7 years ago #2309

  • emmiko888
  • OFFLINE
  • Fresh Boarder
  • Posts: 3
  • Karma: 0
Hi there I'm looking for some help I'm trying to connect to drx890x circuit board it has a bcm97335 chip I bought a cypress boards off ebay. But I'm unable to connect there are 4 pins on the drx890 set top box circuit board I think they are bbs but not sure getting a ground , one one pin 2.7v on another and .1 or submit on the other two I'm unable to connect when I run broad band studio 3 select device bcm7335 etc etc I would be very grateful of some expert help I've been trying this for months now and not getting anywhere any help would be much appreciated many thanks in advance please reply to my email address it This e-mail address is being protected from spambots. You need JavaScript enabled to view it

Re: EJTAG MIPS BCM7358 7 years ago #2310

  • emmiko888
  • OFFLINE
  • Fresh Boarder
  • Posts: 3
  • Karma: 0
Hi there I'm looking for some help I'm trying to connect to drx890x circuit board it has a bcm97335 chip I bought a cypress boards off ebay. But I'm unable to connect there are 4 pins on the drx890 set top box circuit board I think they are bbs but not sure getting a ground , one one pin 2.7v on another and .1 or submit on the other two I'm unable to connect when I run broad band studio 3 select device bcm7335 etc etc I would be very grateful of some expert help I've been trying this for months now and not getting anywhere any help would be much appreciated many thanks in advance please reply to my email address it This e-mail address is being protected from spambots. You need JavaScript enabled to view it

Re: EJTAG MIPS BCM7358 6 years, 6 months ago #2383

  • Ayo
  • OFFLINE
  • Fresh Boarder
  • Posts: 3
  • Karma: 0
Hello all,

have you succeded connecting to the bcm7358 board recently?
Have you already found bcm97358.msi?
If not, you can find it here
Last Edit: 6 years, 6 months ago by Ayo.

Re: EJTAG MIPS BCM7358 6 years, 4 months ago #2398

  • n01knows
  • OFFLINE
  • Junior Boarder
  • Posts: 32
  • Karma: 0
kabnaj wrote:
Hello all,

have you succeded connecting to the bcm7358 board recently?
Have you already found bcm97358.msi?
If not, you can find it here



Very important information!!!

BBS3 and cypress board, this only works ok in Unlocked CPU FTA boxes..

TV provider STB bcm boxes are jtag locked with CPU keys ( to unlock this STB from Providers with BCM cpus will be nearly impossible) unless you find a way to glitch cpu like its done on XBOX360 cpu key extraction.....

in CA provider boxes all you can see is CPUID detected on Broadband Studio tool but no flash, or cpu , nand connections , allways locked and give timeout readings because its all protected and locke by provider. So don´t expect it to make any dumps.

Unless your provider left the CPU unlocked which i pretty much doubt it.

Re: EJTAG MIPS BCM7358 5 years, 4 months ago #2478

Hi have you managed to jtag the stb and
any solutions or advices are appricated

Re: EJTAG MIPS BCM7358 5 years, 4 months ago #2480

i want too

Re: EJTAG MIPS BCM7358 5 years, 4 months ago #2481

would you please help me about the hardware stuff if bcm7358 i will try to ejtag it too. thank you very much

Re: EJTAG MIPS BCM7358 3 years ago #2683

  • cobramostar
  • OFFLINE
  • Junior Boarder
  • Posts: 33
  • Karma: 0
@n01knows

have you dump of this firmware
and have any pdf for this CPU with pinout

thanks

Re: EJTAG MIPS BCM7358 2 years, 11 months ago #2701

  • mody
  • OFFLINE
  • Fresh Boarder
  • Posts: 1
  • Karma: 0
now we have datasheet and can dump the flash for this cpu

Re: EJTAG MIPS BCM7358 2 years, 10 months ago #2710

  • Ada
  • OFFLINE
  • Fresh Boarder
  • Posts: 1
  • Karma: 0
now we have datasheet and can dump the flash for this cpu


Where can we get a copy of the datasheet?

Thank you in advance

Re: EJTAG MIPS BCM7358 6 months, 1 week ago #2811

  • cobramostar
  • OFFLINE
  • Junior Boarder
  • Posts: 33
  • Karma: 0
is there a possibility to access cpu 7358
via jtag or bbs is it still impossible

Re: EJTAG MIPS BCM7358 2 months, 1 week ago #2812

  • devloper
  • OFFLINE
  • Fresh Boarder
  • Posts: 14
  • Karma: 1
cobramostar wrote:
is there a possibility to access cpu 7358
via jtag or bbs is it still impossible



is not a big deal for me for bcm7358
  • Page:
  • 1
Time to create page: 2.68 seconds
Sizler icin kurdugumuz sitemizde yabanci diziler ve film arsivi ile birlikte gunluk burc yorumlari son dakika haberler bulunur Dizimag Hayata dair herseyi sizlere gosteriyoruz. Hemen sitemize girip eglencenize bakabilir zamaninizi guzel gecirebilirsiniz.