Jtag pinout mips-BCM7538(STB Kaon)

JTAG on Dish Receivers.
Post Reply
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Jtag pinout mips-BCM7358(STB Kaon)

Post by offlinemodus »

Hallo to all,

i have a kaon stb with bcm7358 mips chip
i want to make jtag (i need a flash dump)but i am not sure is a jtag pinout on the pcb?

i try it on the 2 places

left corner labeled J2 with 5 pins
and in the middle labeled J7 with 4 pins

but no connection
i looked for a detailled datasheet for this processor but had not any luck to find something what would help me.
i know jtag needs 14 pins normally or it must be a ejtag connection (like wrt54 router) because of mips processor?
I am a newbie in this things, but willing to learn :rolleyes:, hope someone can take a look on the pic maybe is the jtag pinout somewhere else.

If no jtag pinout then desoldering the flash chip(spansion nand) is the only option to get the flash dump?

thank you very much and sorry for my bad english :)

@admin: thank you for the activation.

Image
PAPAUKA
Junior Member
Posts: 105
Joined: Tue Mar 31, 2009 10:25 am

Post by PAPAUKA »

the "J7" look like UART connection TX, RX, GND, VCC...

YOU HAVE IMAGE OF BACK OF THIS BOARD ???
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

hi,

thank you for your answer

here the pic of other side
Image
PAPAUKA
Junior Member
Posts: 105
Joined: Tue Mar 31, 2009 10:25 am

Post by PAPAUKA »

you can tell me the reference of this 2 chip "1 and 2" in image
Image
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

1.
ESMT
AD22653
C-A8G
1326

http://www.elitemicropower.com/upload/AD22653.pdf
it seems this is a audio chip

2.
THS7374
2BK g4
AETS

http://www.alldatasheet.com/datasheet-p ... 4IPWR.html

this is an video buffer chip for scart i think

The pinout J7 is maybe interesting?
Image
Image
Image
PAPAUKA
Junior Member
Posts: 105
Joined: Tue Mar 31, 2009 10:25 am

Post by PAPAUKA »

the j7 show like uart connection:
tx rx vcc gnd


ok. if this 4 point is for uart conection its simple to flash this device with CFE commands.

wich model of kaon stb you have ????
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

jommega wrote:the j7 show like uart connection:
tx rx vcc gnd


ok. if this 4 point is for uart conection its simple to flash this device with CFE commands.

wich model of kaon stb you have ????
it is a Kaon CO 1300 HD

it is branded for a croatian Sat Provider VIP TV on 16e.

if i understood you right with a uart connection(if j7 is uart) i can flash.
what is with a flash dump?

i can use usbjtag device must coonnect only the 4 points then?
or i need something like this

Image
PAPAUKA
Junior Member
Posts: 105
Joined: Tue Mar 31, 2009 10:25 am

Yes

Post by PAPAUKA »

YES USE THIS
Image
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

thank you vm.

i try it and give the feedback here.
cheers
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

In the time i am waiting for the usb uart adapter,
I have measured the voltage on the J7 pinout-

i have 3 pins with 3.3v and 1 pin 0v

the pin with 0v should be gnd

but how to find out which pin is tx, rx and vcc?

On booting i dont see any voltage fluctuations on pins with 3.3v that could be an sign for activity.

If i connect the wrong pin to the adapter i can fry the adapter or the stb yes? (stb vcc to uart adapter vcc)
merkin
Junior Member
Posts: 246
Joined: Thu Jun 28, 2007 8:49 pm

Post by merkin »

This looks like BBS/I2C pins.
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

BBS pinout is

1 is 3v3
2 is BSC_SCL
3 is BCS_SDA
4 is GND

right?

but which adapter to connect?
usbjtag would be ok?

or i need something like this
http://www.ebay.com/itm/EZ-USB-FX2LP-Cypress-CY7C68013A-USB2-0-Developement-Core-Board-module-/271016849175?pt=LH_DefaultDomain_0&hash=item3f19dcef17
PAPAUKA
Junior Member
Posts: 105
Joined: Tue Mar 31, 2009 10:25 am

Post by PAPAUKA »

offlinemodus wrote:BBS pinout is

1 is 3v3
2 is BSC_SCL
3 is BCS_SDA
4 is GND

right?

but which adapter to connect?
usbjtag would be ok?

or i need something like this
http://www.ebay.com/itm/EZ-USB-FX2LP-Cypress-CY7C68013A-USB2-0-Developement-Core-Board-module-/271016849175?pt=LH_DefaultDomain_0&hash=item3f19dcef17
yes for bbs use this tool...

but you need after broadband studio and plugins for bcm7538 for flash.
offlinemodus
Junior Member
Posts: 10
Joined: Wed Jan 15, 2014 12:31 am

Post by offlinemodus »

i have ordered the adapter
downloaded broadband studio
but the file bcm97358.msi that i need for the boot/flash nowhere to find.
i think i must surrender :(


anyway thank you very much
n01kn0ws
Junior Member
Posts: 13
Joined: Thu Jan 23, 2014 4:49 pm

bcm7358

Post by n01kn0ws »

Hi friend

i have only seen your post today



J7 pin pinout should be



pin1 = RX
Pin2 = TX
Pin3 = GND
Pin4 = 3.3v


this is correct diagram on my BCM7358 receiver i have from different sat provider.

The only issue is that most likely the CFE> will be blocked by provider , like mine did.

i tried via putty using serial com and with hiperterminal i cannot use CFE> commands as it is blocked.:confused:

most luck will be either JTAG or with BBS

i have received my bbs tool so i will make some more tests during this week

for JTAG should be 14pin in motherboard, otherwise provider is either using bbs to burn image, or using TFTPD32 to burn via ftp flash..


with putty only letter O from my keyboard made box go to standby and power up mode, no other command or letter in keyboard worked..


this is my motherboard from other provider

https://imageshack.com/i/0a33wzj


we have 2 UART but only one working the other no connection at all

1 bbs

1 EJTAG 14 pin


with USBjtagnt i didn´t have success in connecting yet as it cannot detect device ID only 00000 sometimes ffffff or 80000 or 800fff

someone gave me a hint that it could be using on pin13 or pin14 a vcc 3.3v but loking at diagram looks like i have 2 resistors missing not shure if they are used .

https://imageshack.com/i/1qnpi2p


and this is jtag the ones with red cross are missing in board this resistors one from PIN11 EJTAG and one from pin13 maybe this is why i am not getting JTAG DEVICE ID also??

http://imageshack.com/a/img853/97/1e7v.png




Unless there is a secret way of entering CFE> mode on this MIPS receiver i have... i could execute any command on it.



By the way here is a log with putty ssh
Technicolor - DSTxxxxxx - Launcher v1.10 prod

starting pid 190, tty '': '/etc/init.d/rcS'
Mounting virtual filesystems
/etc/init.d/rcS: line 6: mkdir: command not found
mount: mounting none on /proc/bus/usb failed: No such file or directory
mount: mounting debugfs on /proc/sys/debug failed: No such device
/etc/init.d/rcS: line 12: mkdir: command not found
mount: mounting devpts on /dev/pts failed: No such file or directory
Starting mdev
* WARNING: THIS STB CONTAINS GPLv3 SOFTWARE
* GPLv3 programs must be removed in order to enable security.
* See: http://www.gnu.org/licenses/gpl-faq.html#Tivoization
insmod: can't insert 'change_uid.ko': No such file or directory

NFLL_IOC_OTPSTATUS value [1] ret [0]
/home/DSTXXXXXX/SW3.0/BCM_HD/nexus/../magnum/syslib/hdcplib/7358/bhdcplib_hdcpke
ys.c BHDCPlib_GetKeySet 140: Have gotten HDCP key from flash
#STATION ** OSC Notify: o_station_control_init line: 3631
****************appstore init 1************

#APPSTOR DUMP >>>
#APPSTOR dumping 1 entries from generaion 0
#APPSTOR entry 0: 1/1 'TeleIDEA'/'iguide' 1
#APPSTOR tok=32770 size=1994388, ve=20, exp=ffffffff, auth=ffffffff, l
im=ffffffff
#APPSTOR <<< DUMP

#TRACE BEGIN:
DSTXXXXXX;
DSTXXX;00;
Macronix/MX25L3255DXCI-10G#
Macronix/MT29F1G08AB
AEAH4;
31730921861000ÿÿ;
D2F201309218616;
37060580;
182092180205;;;;;;;
SWV3.0;Iguide;
0.00;0.00;;;;;
00000000;
8B849374;
2B5FA5E4;
6B510EB6CA000000;;;
4432C800C46C;;;;
00001C07;;;;3c#TRACE END

Calling CAO_Pre_Init()


***************************Calling CAO_Pre_Init() *****************************




***************************After CAO_Pre_Init() *****************************

[ext_sfs.c(0009)] ############################ ext_sfs_init_2 ##################
###########
[ext_msm.c(0099)] ############################ ext_msm_init_2 ##################
####
@@ start MSM init 2
** o_msm_register_medium_verifier ok!
#SECURE:WARNING: / is not permanent
gdbo raw port not initialized
#INTPRT[RESET] starting
[o_xyman_client_register] success: client = 1ce0850.
#INTPRT[RESET] init
(HON_Tuner_Init,2296): pipeId:[2] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[6] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[7] TunerIndex 0
### can't find SVL ID 10 - o_svl_retrieve_by_id() returns 4, handle = 0, state =
5
(HON_Tuner_Init,2296): pipeId:[4] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[5] TunerIndex 0
(HON_Tuner_Init,2296): pipeId:[9] TunerIndex 0
@@@
[SECRE]
NP version <EMB.HD.3.69> built on <Fri Jun 7 15:39:10 2013>
with CORE version <CO22057>

@@@ [SECRE] manufacturer = Tech_DSTXXX
@@@ [SECRE] manufacturer_version = SWV3.0
@@@ [SECRE] opentv_version = CO22Q57A


***************************Calling CAO_Init *****************************


CAO Version: 2.022
CAO Date: Wed 10 Oct 2012 23:03
CAO Build Date: Oct 19 2012 09:04:06
CAO Version String: R-AOXAF-ABPAR
CAO Debug: Off

ca_scal_init> serverThread:event=1,cardState=0
ca_scal_init> serverThread:event=3,cardState=1
ca_scal_init> serverThread:event=0,cardState=1


***************************After CAO_Init *****************************

ca_scal_init> serverThread:event=1,cardState=3
*************************** DVL Initialized successfully ***********************
****

Before dropping the privilege : Running with UID 0 (effective 0)
GID 0 (effective 0)

After dropping the privilege : Running with UID 1000 (effective 1000)
GID 1000 (effective 1000)
!ctl_omm_init_3>>>
#OMM: omm_evt_mgr_init called
OMMDL: download_app_handler_init
[np_net_control_usvl_init] Updating User List... NO!
HDMI: resolution: 1280x720, frequency: 60, aspect ratio: 1
HDMI: resolution: 1280x720, frequency: 60, aspect ratio: 1
HDMI: found incompatable HD format: frequency: 60, aspect ratio: 1, horizontal p
ixels: 1280
HDMI: vertical pixelsl: 720, interlaced: 1
!ctl_si_tune_start>>>
!ctl_si_tune_do>>> -1 0
actual direct size: direct_segment_size() = 25165824, direct_segment_ptr=0x6
04d8cc0
far_segments_number()=0
total user heap size : 0
far_size_inquire()=0
!DSM INIT 0 0
!DSM INIT 0 0
!DSM INIT ret -1 -1
!DSM INIT 0 0
!DSM INIT 0 0
!hack bad usb msd
(HON_Video_P_DataReadyCallback,555) Decoder mute state changed from [unmute] to
[mute]! for 0
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
!second try 0
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
cc_turn_on_off:0 1
cc_monitor_main: Close Captioning Monitor Starting ...
[hddstate.c(0641)] ############################## ext_ptm_init_3 ###############
#######
[hddstate.c(0444)] o_fs_register_client return 0
[hddstate.c(0449)] system_timer_new(USB_TIMER_TAG) success!
*************NEXUS_VideoDecoder_Flush isHung=1 stcChannelWantsFlush=0 isCdbFull=
0 displayMode=1*********
[o_xyman_client_register] success: client = 1ca2560.
!ctl_omm_ready>>>
(HON_Video_P_DataReadyCallback,555) Decoder mute state changed from [mute] to ! for 0
#INTPRT[READY] unexpected message, ignored
#INTPRT[READY] unexpected message, ignored
(HON_Tuner_DoScan_priv,1529): NOTIFY_DEMOD_LOCK_FAILED
!demod state: 6 4 4 4
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:4 Freq: Before 17903616 After 1
1130000
!DEMOD demodulator type 6
!ctl_si_tune_do>>> 0 45
!ctl_si_tune_do: ts 1.3 256 11130 29892 0x0700 0x00000213
(HON_Tuner_Connect,2502): Tune (SAT) pipeId:4 Freq: Before 17903616 After 1
1130000
[msvlmgr_config_control_storage] returns 1
!ctl_si_tune_stop>>>
=================== SVL update 260 ....
[np_store_svl] calling s_store_msvl ...
[s_store_msvl] MSVL_STORE_REQUEST returned 0
Unlocking MSVL with SQnC name MSVL_QRY_NAME
CTL_BOOTUP_WAIT_TIMER_TAG
ctl_launch_iguide_app>>> reason 0 arg "1" ""
#AEE app 33 state NON_EXISTANT->NEW
#AEE app_instance_set_property(21, STATUS(INT) 0x1(4))
#AEE app_instance_set_property(21, TOKEN(INT) 0xfffb(2))
#AEE app_instance_set_property(21, AEE(INT) 0x1(4))
#AEE-OCODE unhandled AEE command 5.0 21, 0, 0
#INTPRT[READY] IN_FLASH_APP


***************** app scheduled to run ********************

app name = iguide
producer = TeleIDEA
prodid = 1
applid = 1

***********************************************************

!isdbt_refresh_eit>>>
#AEE app_instance_set_property(21, 0x122(BINARY) *0x5a2f7468(56)
#AEE-OCODE unhandled AEE command 7.0 21, 122, 0
#AEE app_instance_set_property(21, 0x122(BINARY) *0x5a2f7468(56)
ctl_check_persistent_popup: not persistent popup to display
#AEE-OCODE unhandled AEE command 7.0 21, 122, 0
#INTPRT[RUNNING] running:0xfffffffb
Stack Boundaries [0x5fed8ccc-0x5fedace0] (size=0x00002000)
Data Boundaries [0x5fedacf4-0x6004cd44] (size=0x00172050)
Bss Boundaries [0x6004cd44-0x6009485c] (size=0x00047b18)
---------- Manufacturer info -----
OpenTV version : CO22Q57ATech_DSTXXX
Manufacturer : Tech_DSTXXX
Manufacturer version: SWV3.0
----------------------------------
----------------------------------------------------------------
(c) TeleIDEA BV, Eindhoven, The Netherlands
iGuide PVR for Embratel, version: 1.24.4, build: 20
OpenTV version: 20
Build date: Jul 18 2013 12:11:02
----------------------------------------------------------------
Heap available: 4472728
Heap biggest: 4472724
Stack start: 0x5fedac60
[IGUIDE-20][00:00:23.878_01/01] INFO: manufacturer: 'Tech_DSTXXX'
GMT time: 01-01-1970 00:00:23
Local time: 01-01-1970 00:00:23
O_time_daylight_change() FAILED
[IGUIDE-20][00:00:23.888_01/01] INFO: OpenTV version:



Just for the sake of it the CFE tried it alot of times pressing CTRL -C whilst booting receivers in order to enter CFE and it does not work so i guess its blocked
Post Reply

Who is online

Users browsing this forum: No registered users and 8 guests