Jtag pinout mips-BCM7538(STB Kaon)
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
Jtag pinout mips-BCM7358(STB Kaon)
Hallo to all,
i have a kaon stb with bcm7358 mips chip
i want to make jtag (i need a flash dump)but i am not sure is a jtag pinout on the pcb?
i try it on the 2 places
left corner labeled J2 with 5 pins
and in the middle labeled J7 with 4 pins
but no connection
i looked for a detailled datasheet for this processor but had not any luck to find something what would help me.
i know jtag needs 14 pins normally or it must be a ejtag connection (like wrt54 router) because of mips processor?
I am a newbie in this things, but willing to learn , hope someone can take a look on the pic maybe is the jtag pinout somewhere else.
If no jtag pinout then desoldering the flash chip(spansion nand) is the only option to get the flash dump?
thank you very much and sorry for my bad english
@admin: thank you for the activation.
i have a kaon stb with bcm7358 mips chip
i want to make jtag (i need a flash dump)but i am not sure is a jtag pinout on the pcb?
i try it on the 2 places
left corner labeled J2 with 5 pins
and in the middle labeled J7 with 4 pins
but no connection
i looked for a detailled datasheet for this processor but had not any luck to find something what would help me.
i know jtag needs 14 pins normally or it must be a ejtag connection (like wrt54 router) because of mips processor?
I am a newbie in this things, but willing to learn , hope someone can take a look on the pic maybe is the jtag pinout somewhere else.
If no jtag pinout then desoldering the flash chip(spansion nand) is the only option to get the flash dump?
thank you very much and sorry for my bad english
@admin: thank you for the activation.
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
1.
ESMT
AD22653
C-A8G
1326
http://www.elitemicropower.com/upload/AD22653.pdf
it seems this is a audio chip
2.
THS7374
2BK g4
AETS
http://www.alldatasheet.com/datasheet-p ... 4IPWR.html
this is an video buffer chip for scart i think
The pinout J7 is maybe interesting?
ESMT
AD22653
C-A8G
1326
http://www.elitemicropower.com/upload/AD22653.pdf
it seems this is a audio chip
2.
THS7374
2BK g4
AETS
http://www.alldatasheet.com/datasheet-p ... 4IPWR.html
this is an video buffer chip for scart i think
The pinout J7 is maybe interesting?
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
it is a Kaon CO 1300 HDjommega wrote:the j7 show like uart connection:
tx rx vcc gnd
ok. if this 4 point is for uart conection its simple to flash this device with CFE commands.
wich model of kaon stb you have ????
it is branded for a croatian Sat Provider VIP TV on 16e.
if i understood you right with a uart connection(if j7 is uart) i can flash.
what is with a flash dump?
i can use usbjtag device must coonnect only the 4 points then?
or i need something like this
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
In the time i am waiting for the usb uart adapter,
I have measured the voltage on the J7 pinout-
i have 3 pins with 3.3v and 1 pin 0v
the pin with 0v should be gnd
but how to find out which pin is tx, rx and vcc?
On booting i dont see any voltage fluctuations on pins with 3.3v that could be an sign for activity.
If i connect the wrong pin to the adapter i can fry the adapter or the stb yes? (stb vcc to uart adapter vcc)
I have measured the voltage on the J7 pinout-
i have 3 pins with 3.3v and 1 pin 0v
the pin with 0v should be gnd
but how to find out which pin is tx, rx and vcc?
On booting i dont see any voltage fluctuations on pins with 3.3v that could be an sign for activity.
If i connect the wrong pin to the adapter i can fry the adapter or the stb yes? (stb vcc to uart adapter vcc)
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
BBS pinout is
1 is 3v3
2 is BSC_SCL
3 is BCS_SDA
4 is GND
right?
but which adapter to connect?
usbjtag would be ok?
or i need something like this
http://www.ebay.com/itm/EZ-USB-FX2LP-Cypress-CY7C68013A-USB2-0-Developement-Core-Board-module-/271016849175?pt=LH_DefaultDomain_0&hash=item3f19dcef17
1 is 3v3
2 is BSC_SCL
3 is BCS_SDA
4 is GND
right?
but which adapter to connect?
usbjtag would be ok?
or i need something like this
http://www.ebay.com/itm/EZ-USB-FX2LP-Cypress-CY7C68013A-USB2-0-Developement-Core-Board-module-/271016849175?pt=LH_DefaultDomain_0&hash=item3f19dcef17
-
- Junior Member
- Posts: 105
- Joined: Tue Mar 31, 2009 10:25 am
yes for bbs use this tool...offlinemodus wrote:BBS pinout is
1 is 3v3
2 is BSC_SCL
3 is BCS_SDA
4 is GND
right?
but which adapter to connect?
usbjtag would be ok?
or i need something like this
http://www.ebay.com/itm/EZ-USB-FX2LP-Cypress-CY7C68013A-USB2-0-Developement-Core-Board-module-/271016849175?pt=LH_DefaultDomain_0&hash=item3f19dcef17
but you need after broadband studio and plugins for bcm7538 for flash.
-
- Junior Member
- Posts: 10
- Joined: Wed Jan 15, 2014 12:31 am
-
- Junior Member
- Posts: 13
- Joined: Thu Jan 23, 2014 4:49 pm
bcm7358
Hi friend
i have only seen your post today
J7 pin pinout should be
pin1 = RX
Pin2 = TX
Pin3 = GND
Pin4 = 3.3v
this is correct diagram on my BCM7358 receiver i have from different sat provider.
The only issue is that most likely the CFE> will be blocked by provider , like mine did.
i tried via putty using serial com and with hiperterminal i cannot use CFE> commands as it is blocked.
most luck will be either JTAG or with BBS
i have received my bbs tool so i will make some more tests during this week
for JTAG should be 14pin in motherboard, otherwise provider is either using bbs to burn image, or using TFTPD32 to burn via ftp flash..
with putty only letter O from my keyboard made box go to standby and power up mode, no other command or letter in keyboard worked..
this is my motherboard from other provider
https://imageshack.com/i/0a33wzj
we have 2 UART but only one working the other no connection at all
1 bbs
1 EJTAG 14 pin
with USBjtagnt i didn´t have success in connecting yet as it cannot detect device ID only 00000 sometimes ffffff or 80000 or 800fff
someone gave me a hint that it could be using on pin13 or pin14 a vcc 3.3v but loking at diagram looks like i have 2 resistors missing not shure if they are used .
https://imageshack.com/i/1qnpi2p
and this is jtag the ones with red cross are missing in board this resistors one from PIN11 EJTAG and one from pin13 maybe this is why i am not getting JTAG DEVICE ID also??
http://imageshack.com/a/img853/97/1e7v.png
Unless there is a secret way of entering CFE> mode on this MIPS receiver i have... i could execute any command on it.
By the way here is a log with putty ssh
Just for the sake of it the CFE tried it alot of times pressing CTRL -C whilst booting receivers in order to enter CFE and it does not work so i guess its blocked
i have only seen your post today
J7 pin pinout should be
pin1 = RX
Pin2 = TX
Pin3 = GND
Pin4 = 3.3v
this is correct diagram on my BCM7358 receiver i have from different sat provider.
The only issue is that most likely the CFE> will be blocked by provider , like mine did.
i tried via putty using serial com and with hiperterminal i cannot use CFE> commands as it is blocked.
most luck will be either JTAG or with BBS
i have received my bbs tool so i will make some more tests during this week
for JTAG should be 14pin in motherboard, otherwise provider is either using bbs to burn image, or using TFTPD32 to burn via ftp flash..
with putty only letter O from my keyboard made box go to standby and power up mode, no other command or letter in keyboard worked..
this is my motherboard from other provider
https://imageshack.com/i/0a33wzj
we have 2 UART but only one working the other no connection at all
1 bbs
1 EJTAG 14 pin
with USBjtagnt i didn´t have success in connecting yet as it cannot detect device ID only 00000 sometimes ffffff or 80000 or 800fff
someone gave me a hint that it could be using on pin13 or pin14 a vcc 3.3v but loking at diagram looks like i have 2 resistors missing not shure if they are used .
https://imageshack.com/i/1qnpi2p
and this is jtag the ones with red cross are missing in board this resistors one from PIN11 EJTAG and one from pin13 maybe this is why i am not getting JTAG DEVICE ID also??
http://imageshack.com/a/img853/97/1e7v.png
Unless there is a secret way of entering CFE> mode on this MIPS receiver i have... i could execute any command on it.
By the way here is a log with putty ssh
Technicolor - DSTxxxxxx - Launcher v1.10 prod
starting pid 190, tty '': '/etc/init.d/rcS'
Mounting virtual filesystems
/etc/init.d/rcS: line 6: mkdir: command not found
mount: mounting none on /proc/bus/usb failed: No such file or directory
mount: mounting debugfs on /proc/sys/debug failed: No such device
/etc/init.d/rcS: line 12: mkdir: command not found
mount: mounting devpts on /dev/pts failed: No such file or directory
Starting mdev
* WARNING: THIS STB CONTAINS GPLv3 SOFTWARE
* GPLv3 programs must be removed in order to enable security.
* See: http://www.gnu.org/licenses/gpl-faq.html#Tivoization
insmod: can't insert 'change_uid.ko': No such file or directory
NFLL_IOC_OTPSTATUS value [1] ret [0]
/home/DSTXXXXXX/SW3.0/BCM_HD/nexus/../magnum/syslib/hdcplib/7358/bhdcplib_hdcpke
ys.c BHDCPlib_GetKeySet 140: Have gotten HDCP key from flash
#STATION ** OSC Notify: o_station_control_init line: 3631
****************appstore init 1************
#APPSTOR DUMP >>>
#APPSTOR dumping 1 entries from generaion 0
#APPSTOR entry 0: 1/1 'TeleIDEA'/'iguide' 1
#APPSTOR tok=32770 size=1994388, ve=20, exp=ffffffff, auth=ffffffff, l
im=ffffffff
#APPSTOR <<< DUMP
#TRACE BEGIN:
DSTXXXXXX;
DSTXXX;00;
Macronix/MX25L3255DXCI-10G#
Macronix/MT29F1G08AB
AEAH4;
31730921861000ÿÿ;
D2F201309218616;
37060580;
182092180205;;;;;;;
SWV3.0;Iguide;
0.00;0.00;;;;;
00000000;
8B849374;
2B5FA5E4;
6B510EB6CA000000;;;
4432C800C46C;;;;
00001C07;;;;3c#TRACE END
Calling CAO_Pre_Init()
***************************Calling CAO_Pre_Init() *****************************
***************************After CAO_Pre_Init() *****************************
[ext_sfs.c(0009)] ############################ ext_sfs_init_2 ##################
###########
[ext_msm.c(0099)] ############################ ext_msm_init_2 ##################
####
@@ start MSM init 2
** o_msm_register_medium_verifier ok!
#SECURE:WARNING: / is not permanent
gdbo raw port not initialized
#INTPRT[RESET] starting
[o_xyman_client_register] success: client = 1ce0850.
#INTPRT[RESET] init
(HON_Tuner_Init,2296): pipeId:[2] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[6] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[7] TunerIndex 0
### can't find SVL ID 10 - o_svl_retrieve_by_id() returns 4, handle = 0, state =
5
(HON_Tuner_Init,2296): pipeId:[4] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[5] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[9] TunerIndex 0
@@@
[SECRE]
NP version <EMB.HD.3.69> built on <Fri Jun 7 15:39:10 2013>
with CORE version <CO22057>
@@@ [SECRE] manufacturer = Tech_DSTXXX
@@@ [SECRE] manufacturer_version = SWV3.0
@@@ [SECRE] opentv_version = CO22Q57A
***************************Calling CAO_Init *****************************
CAO Version: 2.022
CAO Date: Wed 10 Oct 2012 23:03
CAO Build Date: Oct 19 2012 09:04:06
CAO Version String: R-AOXAF-ABPAR
CAO Debug: Off
ca_scal_init> serverThread:event=1,cardState=0
ca_scal_init> serverThread:event=3,cardState=1
ca_scal_init> serverThread:event=0,cardState=1
***************************After CAO_Init *****************************
ca_scal_init> serverThread:event=1,cardState=3
*************************** DVL Initialized successfully ***********************
****
Before dropping the privilege : Running with UID 0 (effective 0)
GID 0 (effective 0)
After dropping the privilege : Running with UID 1000 (effective 1000)
GID 1000 (effective 1000)
!ctl_omm_init_3>>>
#OMM: omm_evt_mgr_init called
OMMDL: download_app_handler_init
[np_net_control_usvl_init] Updating User List... NO!
HDMI: resolution: 1280x720, frequency: 60, aspect ratio: 1
HDMI: resolution: 1280x720, frequency: 60, aspect ratio: 1
HDMI: found incompatable HD format: frequency: 60, aspect ratio: 1, horizontal p
ixels: 1280
HDMI: vertical pixelsl: 720, interlaced: 1
!ctl_si_tune_start>>>
!ctl_si_tune_do>>> -1 0
actual direct size: direct_segment_size() = 25165824, direct_segment_ptr=0x6
04d8cc0
far_segments_number()=0
total user heap size : 0
far_size_inquire()=0
!DSM INIT 0 0
!DSM INIT 0 0
!DSM INIT ret -1 -1
!DSM INIT 0 0
!DSM INIT 0 0
!hack bad usb msd
(HON_Video_P_DataReadyCallback,555) Decoder mute state changed from [unmute] to
[mute]! for 0
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
!second try 0
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
cc_turn_on_off:0 1
cc_monitor_main: Close Captioning Monitor Starting ...
[hddstate.c(0641)] ############################## ext_ptm_init_3 ###############
#######
[hddstate.c(0444)] o_fs_register_client return 0
[hddstate.c(0449)] system_timer_new(USB_TIMER_TAG) success!
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
[o_xyman_client_register] success: client = 1ca2560.
!ctl_omm_ready>>>
(HON_Video_P_DataReadyCallback,555) Decoder mute state changed from [mute] to ! for 0
#INTPRT[READY] unexpected message, ignored
#INTPRT[READY] unexpected message, ignored
(HON_Tuner_DoScan_priv,1529): NOTIFY_DEMOD_LOCK_FAILED
!demod state: 6 4 4 4
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:4 Freq: Before 17903616 After 1
1130000
!DEMOD demodulator type 6
!ctl_si_tune_do>>> 0 45
!ctl_si_tune_do: ts 1.3 256 11130 29892 0x0700 0x00000213
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:4 Freq: Before 17903616 After 1
1130000
[msvlmgr_config_control_storage] returns 1
!ctl_si_tune_stop>>>
=================== SVL update 260 ....
[np_store_svl] calling s_store_msvl ...
[s_store_msvl] MSVL_STORE_REQUEST returned 0
Unlocking MSVL with SQnC name MSVL_QRY_NAME
CTL_BOOTUP_WAIT_TIMER_TAG
ctl_launch_iguide_app>>> reason 0 arg "1" ""
#AEE app 33 state NON_EXISTANT->NEW
#AEE app_instance_set_property(21, STATUS(INT) 0x1(4))
#AEE app_instance_set_property(21, TOKEN(INT) 0xfffb(2))
#AEE app_instance_set_property(21, AEE(INT) 0x1(4))
#AEE-OCODE unhandled AEE command 5.0 21, 0, 0
#INTPRT[READY] IN_FLASH_APP
***************** app scheduled to run ********************
app name = iguide
producer = TeleIDEA
prodid = 1
applid = 1
***********************************************************
!isdbt_refresh_eit>>>
#AEE app_instance_set_property(21, 0x122(BINARY) *0x5a2f7468(56)
#AEE-OCODE unhandled AEE command 7.0 21, 122, 0
#AEE app_instance_set_property(21, 0x122(BINARY) *0x5a2f7468(56)
ctl_check_persistent_popup: not persistent popup to display
#AEE-OCODE unhandled AEE command 7.0 21, 122, 0
#INTPRT[RUNNING] running:0xfffffffb
Stack Boundaries [0x5fed8ccc-0x5fedace0] (size=0x00002000)
Data Boundaries [0x5fedacf4-0x6004cd44] (size=0x00172050)
Bss Boundaries [0x6004cd44-0x6009485c] (size=0x00047b18)
---------- Manufacturer info -----
OpenTV version : CO22Q57ATech_DSTXXX
Manufacturer : Tech_DSTXXX
Manufacturer version: SWV3.0
----------------------------------
----------------------------------------------------------------
(c) TeleIDEA BV, Eindhoven, The Netherlands
iGuide PVR for Embratel, version: 1.24.4, build: 20
OpenTV version: 20
Build date: Jul 18 2013 12:11:02
----------------------------------------------------------------
Heap available: 4472728
Heap biggest: 4472724
Stack start: 0x5fedac60
[IGUIDE-20][00:00:23.878_01/01] INFO: manufacturer: 'Tech_DSTXXX'
GMT time: 01-01-1970 00:00:23
Local time: 01-01-1970 00:00:23
O_time_daylight_change() FAILED
[IGUIDE-20][00:00:23.888_01/01] INFO: OpenTV version:
Just for the sake of it the CFE tried it alot of times pressing CTRL -C whilst booting receivers in order to enter CFE and it does not work so i guess its blocked
Who is online
Users browsing this forum: No registered users and 8 guests