<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emu on PSP Blog+ &#187; Hack</title>
	<atom:link href="http://emuonpsp.net/blog/?cat=11&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://emuonpsp.net/blog</link>
	<description>Playstation関連の情報全般を扱うページです</description>
	<lastBuildDate>Sat, 07 Mar 2015 11:05:04 +0000</lastBuildDate>
	<language>ja</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.2.38</generator>
	<item>
		<title>■FON 2601Eの内部シリアルポートと接続してみる</title>
		<link>http://emuonpsp.net/blog/?p=101</link>
		<comments>http://emuonpsp.net/blog/?p=101#comments</comments>
		<pubDate>Sat, 07 Mar 2015 11:04:39 +0000</pubDate>
		<dc:creator><![CDATA[Emu on PSP]]></dc:creator>
				<category><![CDATA[Hack]]></category>

		<guid isPermaLink="false">http://emuonpsp.net/blog/?p=101</guid>
		<description><![CDATA[とりあえず見てみたので、ログに残しておき...]]></description>
				<content:encoded><![CDATA[<p><a href="http://emuonpsp.net/blog/wp-content/uploads/2015/03/DSC_0086.jpg"><img src="http://emuonpsp.net/blog/wp-content/uploads/2015/03/DSC_0086-300x169.jpg" alt="DSC_0086" width="300" height="169" class="alignnone size-medium wp-image-102" /></a><br />
とりあえず見てみたので、ログに残しておきます。<br />
自分チェック用。</p>
<p>FXC-U-Boot 3.6.0.0_v01_20130805</p>
<p>Board: Ralink APSoC DRAM:  128 MB<br />
relocate_code Pointer at: 87fac000<br />
enable ephy clock&#8230;done. rf reg 29 = 5<br />
SSC disabled.<br />
spi_wait_nsec: 29<br />
spi device id: c2 20 18 c2 20 (2018c220)<br />
find flash: MX25L12805D<br />
raspi_read: from:30000 len:1000<br />
raspi_read: from:30000 len:1000<br />
============================================<br />
Ralink UBoot Version: 4.1.1.0<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
ASIC 7620_MP (Port5<->Phy)<br />
DRAM component: 1024 Mbits DDR, width 16<br />
DRAM bus: 16 bit<br />
Total memory: 128 MBytes<br />
Flash component: SPI Flash<br />
Date:Oct 14 2013  Time:21:23:03<br />
============================================<br />
icache: sets:512, ways:4, linesz:32 ,total:65536<br />
dcache: sets:256, ways:4, linesz:32 ,total:32768</p>
<p> ##### The CPU freq = 580 MHZ ####<br />
 estimate memory size =128 Mbytes<br />
PHY 4 Reg 27 = 35<br />
PHY 4 Reg 27 = 31<br />
PHY 5 Reg 27 = ffff<br />
PHY 5 Reg 27 = fffb<br />
### Tom ====== RTL8211E Phy2&#8212;time3<br />
raspi_read: from:50000 len:60</p>
<p>=================================================<br />
Check image validation:<br />
Image1 Header Magic Number &#8211;> OK<br />
Image1 Header Checksum &#8211;> OK<br />
Image1 Data Checksum &#8211;> raspi_read: from:50060 len:5303d0<br />
OK<br />
=================================================</p>
<p>Please choose the operation:<br />
   1: Load system code to SDRAM via TFTP.<br />
   2: Load system code then write to Flash via TFTP.<br />
   3: Boot system code via Flash (default).<br />
   4: Entr boot command line interface.<br />
   7: Load Boot Loader code then write to Flash via Serial.<br />
   9: Load Boot Loader code then write to Flash via TFTP.<br />
 0</p>
<p>3: System Boot system code via Flash.</p>
<p>3: System Boot system code via Flash at addr=0xbc050000<br />
## Booting image at bc050000 &#8230;<br />
raspi_read: from:30000 len:10000<br />
Erasing SPI Flash&#8230;<br />
raspi_erase: offs:30000 len:10000<br />
.<br />
Writing to SPI Flash&#8230;<br />
raspi_write: to:30000 len:10000<br />
.<br />
done<br />
raspi_read: from:50000 len:60<br />
   Image Name:   j18h130.00.v07050.20131113.foxconn<br />
   Image Type:   MIPS Linux Kernel Image (lzma compressed)<br />
   Data Size:    5440464 Bytes =  5.2 MB<br />
   Load Address: 80000000<br />
   Entry Point:  8000c310<br />
raspi_read: from:50060 len:5303d0<br />
   Verifying Checksum &#8230; OK<br />
   Uncompressing Kernel Image &#8230; OK<br />
No initrd<br />
## Transferring control to Linux (at address 8000c310) &#8230;<br />
## Giving linux memsize in MB, 128</p>
<p>Starting kernel &#8230;</p>
<p>LINUX started&#8230;</p>
<p> THIS IS ASIC<br />
Linux version 2.6.36 (tom@localhost.localdomain) (gcc version 3.4.2) #867 Wed Nov 13 10:55:17 CST 2013</p>
<p> The CPU feqenuce set to 580 MHz</p>
<p> MIPS CPU sleep mode enabled.<br />
 PCIE: bypass PCIe DLL.<br />
 PCIE: Elastic buffer control: Addr:0x68 -> 0xB4<br />
 disable all power about PCIe<br />
CPU revision is: 00019650 (MIPS 24Kc)<br />
Determined physical RAM map:<br />
 memory: 08000000 @ 00000000 (usable)<br />
Initrd not found or empty &#8211; disabling initrd<br />
Zone PFN ranges:<br />
  Normal   0x00000000 -> 0x00008000<br />
Movable zone start PFN for each node<br />
early_node_map[1] active PFN ranges<br />
    0: 0x00000000 -> 0x00008000<br />
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 32512<br />
Kernel command line: console=ttyS1,57600n8 root=/dev/ram0 console=ttyS0<br />
PID hash table entries: 512 (order: -1, 2048 bytes)<br />
Dentry cache hash table entries: 16384 (order: 4, 65536 bytes)<br />
Inode-cache hash table entries: 8192 (order: 3, 32768 bytes)<br />
Primary instruction cache 64kB, VIPT, 4-way, linesize 32 bytes.<br />
Primary data cache 32kB, 4-way, PIPT, no aliases, linesize 32 bytes<br />
Writing ErrCtl register=0004546b<br />
Readback ErrCtl register=0004546b<br />
Memory: 121972k/131072k available (2858k kernel code, 9100k reserved, 678k data, 4208k init, 0k highmem)<br />
NR_IRQS:128<br />
MTK/Ralink System Tick Counter init&#8230; cd:8035def8, m:214748, s:32<br />
console [ttyS1] enabled<br />
Calibrating delay loop&#8230; 386.04 BogoMIPS (lpj=772096)<br />
pid_max: default: 32768 minimum: 301<br />
Mount-cache hash table entries: 512<br />
NET: Registered protocol family 16<br />
RALINK_GPIOMODE = 1a301d<br />
RALINK_GPIOMODE = 18301d<br />
PPLL_CFG1=0xe64000<br />
MT7620 PPLL lock<br />
PPLL_DRV =0x80080504<br />
start PCIe register access<br />
RALINK_PCI_PCICFG_ADDR = 1000f0</p>
<p>*************** MT7620 PCIe RC mode *************<br />
bio: create slab <bio-0> at 0<br />
vgaarb: loaded<br />
SCSI subsystem initialized<br />
usbcore: registered new interface driver usbfs<br />
usbcore: registered new interface driver hub<br />
usbcore: registered new device driver usb<br />
pci 0000:00:00.0: BAR 14: assigned [mem 0x20000000-0x200fffff]<br />
pci 0000:00:00.0: BAR 15: assigned [mem 0x20100000-0x201fffff pref]<br />
pci 0000:00:00.0: BAR 1: assigned [mem 0x20200000-0x2020ffff]<br />
pci 0000:00:00.0: BAR 1: set to [mem 0x20200000-0x2020ffff] (PCI address [0x20200000-0x2020ffff]<br />
pci 0000:01:00.0: BAR 0: assigned [mem 0x20000000-0x200fffff 64bit]<br />
pci 0000:01:00.0: BAR 0: set to [mem 0x20000000-0x200fffff 64bit] (PCI address [0x20000000-0x200fffff]<br />
pci 0000:01:00.0: BAR 6: assigned [mem 0x20100000-0x2010ffff pref]<br />
pci 0000:00:00.0: PCI bridge to [bus 01-01]<br />
pci 0000:00:00.0:   bridge window [io  disabled]<br />
pci 0000:00:00.0:   bridge window [mem 0x20000000-0x200fffff]<br />
pci 0000:00:00.0:   bridge window [mem 0x20100000-0x201fffff pref]<br />
BAR0 at slot 0 = 0<br />
bus=0x0, slot = 0x0<br />
res[0]->start = 0<br />
res[0]->end = 0<br />
res[1]->start = 20200000<br />
res[1]->end = 2020ffff<br />
res[2]->start = 0<br />
res[2]->end = 0<br />
res[3]->start = 0<br />
res[3]->end = 0<br />
res[4]->start = 0<br />
res[4]->end = 0<br />
res[5]->start = 0<br />
res[5]->end = 0<br />
bus=0x1, slot = 0x0<br />
res[0]->start = 20000000<br />
res[0]->end = 200fffff<br />
res[1]->start = 0<br />
res[1]->end = 0<br />
res[2]->start = 0<br />
res[2]->end = 0<br />
res[3]->start = 0<br />
res[3]->end = 0<br />
res[4]->start = 0<br />
res[4]->end = 0<br />
res[5]->start = 0<br />
res[5]->end = 0<br />
Switching to clocksource Ralink external timer<br />
NET: Registered protocol family 2<br />
IP route cache hash table entries: 1024 (order: 0, 4096 bytes)<br />
TCP established hash table entries: 4096 (order: 3, 32768 bytes)<br />
TCP bind hash table entries: 4096 (order: 2, 16384 bytes)<br />
TCP: Hash tables configured (established 4096 bind 4096)<br />
TCP reno registered<br />
UDP hash table entries: 256 (order: 0, 4096 bytes)<br />
UDP-Lite hash table entries: 256 (order: 0, 4096 bytes)<br />
NET: Registered protocol family 1<br />
Load Ralink Timer0 Module<br />
Load Ralink Timer1 Module<br />
RT3xxx EHCI/OHCI init.<br />
fuse init (API version 7.15)<br />
Block layer SCSI generic (bsg) driver version 0.4 loaded (major 254)<br />
io scheduler noop registered (default)<br />
pci-stub: invalid id string &#8220;&#8221;<br />
###[FXC] change gpio2 polarity to maintains status.<br />
Ralink gpio driver initialized<br />
Serial: 8250/16550 driver, 2 ports, IRQ sharing disabled<br />
serial8250: ttyS0 at MMIO 0x10000500 (irq = 37) is a 16550A<br />
serial8250: ttyS1 at MMIO 0x10000c00 (irq = 12) is a 16550A<br />
brd: module loaded<br />
deice id : c2 20 18 c2 20 (2018c220)<br />
MX25L12805D(c2 2018c220) (16384 Kbytes)<br />
mtd .name = raspi, .size = 0x01000000 (0M) .erasesize = 0x00000010 (0K) .numeraseregions = 65536<br />
Creating 7 MTD partitions on &#8220;raspi&#8221;:<br />
0x000000000000-0x000001000000 : &#8220;ALL&#8221;<br />
0x000000000000-0x000000030000 : &#8220;Bootloader&#8221;<br />
0x000000030000-0x000000040000 : &#8220;Config&#8221;<br />
0x000000040000-0x000000050000 : &#8220;Factory&#8221;<br />
0x000000050000-0x000000fe0000 : &#8220;Kernel&#8221;<br />
0x000000fe0000-0x000000ff0000 : &#8220;Config_Bak&#8221;<br />
0x000000ff0000-0x000001000000 : &#8220;Radconfig_Bak&#8221;<br />
rdm_major = 253<br />
SMACCR1 &#8212; : 0x000018aa<br />
SMACCR0 &#8212; : 0x45135e89<br />
Ralink APSoC Ethernet Driver Initilization. v3.0  256 rx/tx descriptors allocated, mtu = 1500!<br />
SMACCR1 &#8212; : 0x000018aa<br />
SMACCR0 &#8212; : 0x45135e89<br />
PROC INIT OK!<br />
PPP generic driver version 2.4.2<br />
PPP MPPE Compression module registered<br />
NET: Registered protocol family 24<br />
PPTP driver version 0.8.5<br />
ehci_hcd: USB 2.0 &#8216;Enhanced&#8217; Host Controller (EHCI) Driver<br />
rt3xxx-ehci rt3xxx-ehci: Ralink EHCI Host Controller<br />
rt3xxx-ehci rt3xxx-ehci: new USB bus registered, assigned bus number 1<br />
rt3xxx-ehci rt3xxx-ehci: irq 18, io mem 0x101c0000<br />
rt3xxx-ehci rt3xxx-ehci: USB 0.0 started, EHCI 1.00<br />
hub 1-0:1.0: USB hub found<br />
hub 1-0:1.0: 1 port detected<br />
ohci_hcd: USB 1.1 &#8216;Open&#8217; Host Controller (OHCI) Driver<br />
rt3xxx-ohci rt3xxx-ohci: RT3xxx OHCI Controller<br />
rt3xxx-ohci rt3xxx-ohci: new USB bus registered, assigned bus number 2<br />
rt3xxx-ohci rt3xxx-ohci: irq 18, io mem 0x101c1000<br />
hub 2-0:1.0: USB hub found<br />
hub 2-0:1.0: 1 port detected<br />
Netfilter messages via NETLINK v0.30.<br />
nf_conntrack version 0.5.0 (1905 buckets, 7620 max)<br />
ctnetlink v0.93: registering with nfnetlink.<br />
NF_TPROXY: Transparent proxy support initialized, version 4.1.0<br />
NF_TPROXY: Copyright (c) 2006-2007 BalaBit IT Ltd.<br />
IPVS: Registered protocols ()<br />
IPVS: Connection hash table configured (size=4096, memory=32Kbytes)<br />
IPVS: ipvs loaded.<br />
GRE over IPv4 demultiplexor driver<br />
gre: can&#8217;t add protocol<br />
ip_tables: (C) 2000-2006 Netfilter Core Team, Type=Restricted Cone<br />
ipt_CLUSTERIP: ClusterIP Version 0.8 loaded successfully<br />
TCP cubic registered<br />
NET: Registered protocol family 10<br />
NET: Registered protocol family 17<br />
L2TP core driver, V2.0<br />
802.1Q VLAN Support v1.8 Ben Greear <greearb@candelatech.com><br />
All bugs added by David S. Miller <davem@redhat.com><br />
Freeing unused kernel memory: 4208k freed<br />
init started: BusyBox v1.12.1 Algorithmics/MIPS FPU Emulator v1.5<br />
(2013-11-13 10:34:55 CST)<br />
startingdevpts: called with bogus options<br />
 pid 32, tty &#8221;: &#8216;/etc_ro/rcS&#8217;<br />
mount: mounting none on /proc/bus/usb failed: No such file or directory<br />
Welcome to<br />
    _______  _______  ___     __  ____   _  _   ___<br />
    |  ___  \|   __  ||   |   |__||    \ | || | /  /<br />
    | |___| ||  |__| ||   |__  __ |     \| || |/  /<br />
    |   _   /|   _   ||      ||  || |\     ||     \<br />
    |__| \__\|__| |__||______||__||_| \____||_|\___\</p>
<p>                     =System Architecture Department=</p>
<p>Tue Oct  1 00:00:00 UTC 2013<br />
mii_mgr -s -p 0 -r 0 -v 3900<br />
starting pid 41, tty &#8216;/dev/ttyS1&#8242;: &#8216;/bin/login&#8217;<br />
Set: phy[0].reg[0] = 3900<br />
FON login:<br />
 [waitNvram] goahead: nvram_daemon is ok&#8230;<br />
old version is&#8211;>:07050<br />
###FXC:yes find the file<br />
###FXC:yes get the Version<br />
new version is &#8212;>:07050<br />
        [FXC] do nothing, no new version update.<br />
###FXC:nvram_deamon&#8211;> SSID1_2G&#038;5G has already been right value.<br />
###FXC:the fon feature are all same<br />
fxc-load-fon-value.sh<br />
killall -9 udhcpc<br />
killall: udhcpc: no process killed<br />
killall -9 hotspotd &#038;&#038; nvram_set 2860 FonStatus 0<br />
killall: hotspotd: no process killed<br />
internet.sh<br />
Set: phy[4].reg[0] = 1940<br />
run START here&#8211;>genDevNode<br />
run END here&#8211;>genDevNode<br />
Password for &#8216;FON2601E&#8217; changed<br />
rmmod: ralink_wdt: No such file or directory<br />
rmmod: cls: No such file or directory<br />
rmmod: hw_nat: No such file or directory<br />
rmmod: raeth: No such file or directory<br />
insmod: bridge.ko: module not found<br />
insmod: mii.ko: module not found<br />
insmod: raeth.ko: module not found</p>
<p>##### disable 1st wireless interface #####</p>
<p>##### disable 2nd wireless interface #####<br />
rmmod: rt2860v2_ap_net: No such file or directory<br />
rmmod: rt2860v2_ap: No such file or directory<br />
rmmod: rt2860v2_ap_util: No such file or directory<br />
rmmod: rlt_wifi: No such file or directory<br />
insmod: rt2860v2_ap_util.ko: module not found</p>
<p>=== pAd = c05a2000, size = 806064 ===</p>
<p><-- RTMPAllocTxRxRingMemory, Status=0
<-- RTMPAllocAdapterBlock, Status=0
insmod: rt2860v2_ap_net.ko: module not found


=== pAd = c0b02000, size = 1335176 ===

<-- RTMPAllocTxRxRingMemory, Status=0
<-- RTMPAllocAdapterBlock, Status=0
device_id =0x7662
==>rlt_wlan_chip_onoff(): OnOff:1, Reset= 1, pAd->WlanFunCtrl:0x0, Reg-WlanFunCtrl=0x20a<br />
RtmpChipOpsEepromHook::e2p_type=0, inf_Type=5<br />
RtmpEepromGetDefault::e2p_dafault=2<br />
NVM is FLASH mode<br />
build time =<br />
20130809220650a<br />
rom patch for E3 IC</p>
<p>platform =<br />
ALPS<br />
hw/sw version =</p>
<p>patch version =</p>
<p>FW Version:0.0.00 Build:1<br />
Build Time:201309042057____<br />
fw for E3 IC<br />
RX[0] DESC a6017000 size = 4096<br />
RX[1] DESC a6028000 size = 4096<br />
cfg_mode=14<br />
cfg_mode=14<br />
wmode_band_equal(): Band Not Equal!<br />
1. Phy Mode = 49<br />
Country Region from e2p = ffff<br />
2. Phy Mode = 49<br />
3. Phy Mode = 49<br />
andes_pci_fw_init<br />
0x1300 = 00073200<br />
AntCfgInit: primary/secondary ant 0/1<br />
andes_load_cr:cr_type(2)<br />
ChipStructAssign(): MT76x2 hook !<br />
MCS Set = ff ff 00 00 01<br />
TX0 power compensation = 0x38<br />
TX1 power compensation = 0x38<br />
mt76x2_switch_channel(): Switch to Ch#36(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#40(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#44(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#48(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#52(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#56(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#60(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#64(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#100(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#104(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#108(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#112(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#116(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#120(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#124(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#128(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#132(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#136(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_switch_channel(): Switch to Ch#140(2T2R), BBP_BW=0, bbp_ch_idx=0)<br />
mt76x2_bbp_adjust():rf_bw=2, ext_ch=1, PrimCh=52, HT-CentCh=54, VHT-CentCh=58<br />
mt76x2_switch_channel(): Switch to Ch#58(2T2R), BBP_BW=2, bbp_ch_idx=0)<br />
APStartUp(): AP Set CentralFreq at 58(Prim=52, HT-CentCh=54, VHT-CentCh=58, BBP_BW=2)<br />
mt76x2_calibration():RDMode  is in Silent State, do not calibration.<br />
lala: Rx_PE_Mask=0xff<br />
Main bssid = 18:aa:45:13:5e:90<br />
mt76x2_reinit_agc_gain:original agc_vga0 = 0x5c, agc_vga1 = 0x5c<br />
mt76x2_reinit_agc_gain:updated agc_vga0 = 0x5c, agc_vga1 = 0x5c<br />
<==== rt28xx_init, Status=0
RTMPDrvOpen(1):Check if PDMA is idle!
RTMPDrvOpen(2):Check if PDMA is idle!
RX DESC a6376000  size = 2048
1. Phy Mode = 9
2. Phy Mode = 9
3. Phy Mode = 9
AntCfgInit: primary/secondary ant 0/1
Current Temperature from BBP_R49=0xfffffff1
MCS Set = ff ff 00 00 01
Main bssid = 18:aa:45:13:5e:98
<==== rt28xx_init, Status=0
0x1300 = 00064380
ifconfig: ioctl 0x8913 failed: No such device
brctl: bridge br0: No such device or address
ifconfig: ioctl 0x8913 failed: No such device
brctl: bridge br1: No such device or address
Raeth v3.0 (Tasklet,SkbRecycle)

phy_tx_ring = 0x05a5c000, tx_ring = 0xa5a5c000

phy_rx_ring0 = 0x05a5d000, rx_ring0 = 0xa5a5d000
Reg 27 = fffbReg 27 = 31#####Tom debug:Set auto polling phy address just P4=4
RTL8211 GE1 phy_id0
RTL8211 GE1 phy_id1

###Tom debug: RTL phy_id0=ffff,EXT_RTL8211_PHY_ID0=1c

###Tom debug: RTL phy_id1=ffff,EXT_RTL8211_PHY_ID1=c915
###Tom debug: can't match the RTL8211 PHY ID.
#####Tom debug:Set auto polling phy address just P4=4
RTL8211 GE2 phy_id0
RTL8211 GE2 phy_id1

###Tom debug: RTL phy_id0=1c,EXT_RTL8211_PHY_ID0=1c

###Tom debug: RTL phy_id1=c915,EXT_RTL8211_PHY_ID1=c915
###Tom debug:match the RTL8211 PHY ID.

#####RTL8211 GE2 as WAN port
Before - RALINK_ETH_SW_BASE+0x7014 = e0000c
After - RALINK_ETH_SW_BASE+0x7014 = e00004
Before - RALINK_ETH_SW_BASE+0x701C = 700000c
After - RALINK_ETH_SW_BASE+0x701C = 7000004
SMACCR1 -- : 0x000018aa
SMACCR0 -- : 0x45135e89
CDMA_CSG_CFG = 81000000
GDMA1_FWD_CFG = 21710000
vconfig: ioctl error for rem: No such device
vconfig: ioctl error for rem: No such device
vconfig: ioctl error for rem: No such device
vconfig: ioctl error for rem: No such device
vconfig: ioctl error for rem: No such device
rmmod: 8021q: No such file or directory
insmod: 8021q.ko: module not found
device eth2 entered promiscuous mode
##### FXC config Ralink ESW vlan partition (LLLLW) #####
###[FXC]debug:now is GateWay mode, run config-vlan.sh 3 12345 for private &#038; public
switch reg write offset=2004, value=ff0003
switch reg write offset=2104, value=ff0003
switch reg write offset=2204, value=ff0003
switch reg write offset=2304, value=ff0003
switch reg write offset=2404, value=ff0003
switch reg write offset=2504, value=ff0003
switch reg write offset=2010, value=810000c0
switch reg write offset=2110, value=810000c0
switch reg write offset=2210, value=810000c0
switch reg write offset=2310, value=810000c0
switch reg write offset=2410, value=810000c0
switch reg write offset=2510, value=810000c0
switch reg write offset=2610, value=81000000
switch reg write offset=2710, value=81000000
switch reg write offset=2604, value=20ff0003
switch reg write offset=2704, value=20ff0003
Special Tag Enabled
switch reg write offset=2610, value=81000020
portmap format error, should be of length 7
portmap format error, should be of length 7
portmap format error, should be of length 7
portmap format error, should be of length 7
portmap format error, should be of length 7
portmap format error, should be of length 7
portmap format error, should be of length 7
12345
switch reg write offset=2014, value=10001
switch reg write offset=2114, value=10002
switch reg write offset=2214, value=10003
switch reg write offset=2314, value=10004
switch reg write offset=2414, value=10005
switch reg write offset=2514, value=10006
REG_ESW_WT_MAC_ATC is 0x7ff0002
done.
disable IPv6
device ra0 entered promiscuous mode

##### enable 1nd private wireless interface #####
device eth2.1 entered promiscuous mode
device eth2.2 entered promiscuous mode
device eth2.3 entered promiscuous mode
device ra1 entered promiscuous mode

##### enable 1nd public wireless interface #####
device rai0 entered promiscuous mode

##### enable 2nd private wireless interface #####
device rai1 entered promiscuous mode

##### enable 2nd public wireless interface #####
device rai2 entered promiscuous mode
Enlarge min_free_kbytes....
T = 76921, W= 141 detected by ch 0
killall: udhcpc: no process killed
killall: pppd: no process killed
DFS Channel changed 52 to 120
mt76x2_bbp_adjust():rf_bw=2, ext_ch=3, PrimCh=120, HT-CentCh=118, VHT-CentCh=122
mt76x2_switch_channel(): Switch to Ch#122(2T2R), BBP_BW=2, bbp_ch_idx=1)
APStartUp(): AP Set CentralFreq at 122(Prim=120, HT-CentCh=118, VHT-CentCh=122, BBP_BW=2)
mt76x2_calibration():RDMode  is in Silent State, do not calibration.
lala: Rx_PE_Mask=0xff
udhcpc (v1.12.1) started
br0: port 3(rai0) entering learning state
br0: port 3(rai0) entering learning state
br0: port 2(eth2.1) entering learning state
br0: port 2(eth2.1) entering learning state
br0: port 1(ra0) entering learning state
br0: port 1(ra0) entering learning state
br0: port 3(rai0) entering forwarding state
br0: port 2(eth2.1) entering forwarding state
br0: port 1(ra0) entering forwarding state
br1: port 1(eth2.2) entering learning state
br1: port 1(eth2.2) entering learning state
ifconfig br1 192.168.182.1 netmask 255.255.255.0
br2: port 1(eth2.3) entering learning state
br2: port 1(eth2.3) entering learning state
ifconfig br2 192.168.183.1 netmask 255.255.255.0
killall: udhcpd: no process killed
run free public dhcp server
run eap public dhcp server
ifconfig: ioctl 0x8913 failed: No such device
rm: cannot remove '/etc/radvd.conf': No such file or directory
insmod: hw_nat.ko: module not found
ADDRCONF(NETDEV_UP): ifb0: link is not ready
ADDRCONF(NETDEV_UP): ifb1: link is not ready
ADDRCONF(NETDEV_UP): rai1: link is not ready
ADDRCONF(NETDEV_UP): rai2: link is not ready
ADDRCONF(NETDEV_UP): apclii0: link is not ready
ADDRCONF(NETDEV_UP): ra1: link is not ready
ADDRCONF(NETDEV_UP): apcli0: link is not ready
killall rt2860apd 1>/dev/null 2>&#038;1<br />
killall rtinicapd 1>/dev/null 2>&#038;1<br />
rtinicapd&#038;<br />
iptables -F -t filter 1>/dev/null 2>&#038;1<br />
Ralink DOT1X daemon, version = &#8216;2.6.0.0&#8217;<br />
iptables -D FORWARD -j macipport_filter 1>/dev/null 2>&#038;1<br />
iptables -F macipport_filter 1>/dev/null 2>&#038;1<br />
iptables -D FORWARD -j web_filter  1>/dev/null 2>&#038;1<br />
iptables -F web_filter  1>/dev/null 2>&#038;1<br />
iptables -D FORWARD -j malicious_filter 1>/dev/null 2>&#038;1<br />
iptables -F malicious_filter  1>/dev/null 2>&#038;1<br />
iptables -D INPUT -j malicious_input_filter 1>/dev/null 2>&#038;1<br />
iptables -F malicious_input_filter  1>/dev/null 2>&#038;1<br />
iptables -P INPUT ACCEPT<br />
iptables -P OUTPUT ACCEPT<br />
iptables -P FORWARD ACCEPT<br />
iptables -t filter -N web_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -N macipport_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -N malicious_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -N synflood_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -N malicious_input_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -N synflood_input_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -A FORWARD -j web_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -A FORWARD -j macipport_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -A FORWARD -j malicious_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -A malicious_filter -p tcp &#8211;syn -j synflood_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -A INPUT -j malicious_input_filter 1>/dev/null 2>&#038;1<br />
iptables -t filter -A malicious_input_filter -p tcp &#8211;syn -j synflood_input_filter 1>/dev/null 2>&#038;1<br />
iptables -A FORWARD -p tcp &#8211;tcp-flags SYN,RST SYN -j TCPMSS &#8211;clamp-mss-to-pmtu 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br1  -d 192.168.182.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br1  -d 192.168.182.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br2  -d 192.168.183.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br2  -d 192.168.183.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br1  -d 192.168.10.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br1  -d 192.168.10.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br2  -d 192.168.10.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br2  -d 192.168.10.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br1  -d 192.168.183.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br1  -d 192.168.183.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br2  -d 192.168.182.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br2  -d 192.168.182.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br0  -d 192.168.182.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br0  -d 192.168.182.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p tcp -i br0  -d 192.168.183.1/24 -j REJECT &#8211;reject-with tcp-reset 1>/dev/null 2>&#038;1<br />
iptables -A INPUT -p udp -i br0  -d 192.168.183.1/24 -j REJECT &#8211;reject-with icmp-port-unreachable 1>/dev/null 2>&#038;1<br />
iptables -A malicious_input_filter -i eth2.5 -p tcp &#8211;dport 80 -j REJECT &#8211;reject-with tcp-reset<br />
iptables -A malicious_input_filter -i eth2.5 -p udp &#8211;dport 80 -j REJECT &#8211;reject-with icmp-port-unreachable<br />
iptables -A malicious_input_filter -p tcp -i eth2.5 &#8211;dport 53 -j REJECT &#8211;reject-with tcp-reset<br />
iptables -A malicious_input_filter -p udp -i eth2.5 &#8211;dport 53 -j REJECT &#8211;reject-with icmp-port-unreachable<br />
iptables -A malicious_input_filter -p icmp -i eth2.5 &#8211;icmp-type timestamp-request -j DROP<br />
/bin/super_dmz -f<br />
ifconfig br1 192.168.182.1 netmask 255.255.255.0<br />
ifconfig br2 192.168.183.1 netmask 255.255.255.0<br />
Wizard Debug:lease fail time 1<br />
br1: port 1(eth2.2) entering forwarding state<br />
br2: port 1(eth2.3) entering forwarding state<br />
killall: udhcpd: no process killed<br />
run free public dhcp server<br />
run eap public dhcp server<br />
sh: arptables: not found<br />
superdmz:Can&#8217;t get WAN gateway<br />
iptables -t nat -D PREROUTING -j port_forward 1>/dev/null 2>&#038;1<br />
iptables -t nat -F port_forward  1>/dev/null 2>&#038;1; iptables -t nat -X port_forward  1>/dev/null 2>&#038;1<br />
iptables -t nat -D PREROUTING -j DMZ 1>/dev/null 2>&#038;1<br />
iptables -t nat -F DMZ 1>/dev/null 2>&#038;1; iptables -t nat -X DMZ  1>/dev/null 2>&#038;1<br />
cat /proc/sys/net/netfilter/nf_conntrack_udp_timeout > /var/.udpbackup<br />
echo 0 > /proc/sys/net/netfilter/nf_conntrack_udp_timeout<br />
cat /var/.udpbackup > /proc/sys/net/netfilter/nf_conntrack_udp_timeout; rm -f /var/.udpbackup<br />
cat /proc/sys/net/netfilter/nf_conntrack_tcp_timeout_established > /var/.tcpbackup<br />
echo 0 > /proc/sys/net/netfilter/nf_conntrack_tcp_timeout_established<br />
cat /var/.tcpbackup > /proc/sys/net/netfilter/nf_conntrack_tcp_timeout_established; rm -f /var/.tcpbackup<br />
iptables -t nat -N port_forward 1>/dev/null 2>&#038;1; iptables -t nat -I PREROUTING 1 -j port_forward 1>/dev/null 2>&#038;1<br />
iptables -t nat -N DMZ 1>/dev/null 2>&#038;1; iptables -t nat -I PREROUTING 2 -j DMZ 1>/dev/null 2>&#038;1<br />
ntp.sh<br />
ddns.sh<br />
iwpriv ra0 set WscConfMode=0 1>/dev/null 2>&#038;1<br />
iwpriv rai0 set WscConfMode=7<br />
route add -host 239.255.255.250 dev br0 1>/dev/null 2>&#038;1<br />
killall -q klogd<br />
killall -q syslogd<br />
syslogd -C8 1>/dev/null 2>&#038;1<br />
klogd 1>/dev/null 2>&#038;1<br />
killall -q zebra<br />
killall -q ripd<br />
echo 1 > /proc/sys/net/ipv6/conf/all/disable_ipv6<br />
mii_mgr -s -p 4 -r 0 -v 1140<br />
Set: phy[4].reg[0] = 1140<br />
webs: Listening for HTTP requests at address 192.168.10.1<br />
###FXC:telnet status is locked.<br />
mii_mgr -s -p 0 -r 0 -v 3100<br />
Set: phy[0].reg[0] = 3100</p>
<p>process &#8216;/bin/login&#8217; (pid 41) exited. Scheduling for restart.<br />
starting pid 8247, tty &#8216;/dev/ttyS1&#8242;: &#8216;/bin/login&#8217;<br />
FON login: Wizard Debug:lease fail time 2<br />
mt76x2_calibration(channel = 122)<br />
Wizard Debug:lease fail time 3<br />
Wizard Debug:lease fail time >= 3,Try to discover PPPoE Server now&#8230;&#8230;<br />
killall: pppd: no process killed<br />
Plugin /etc_ro/ppp/plugins/rp-pppoe.so loaded.<br />
RP-PPPoE plugin version 3.8p compiled against pppd 2.4.5</p>
<p>process &#8216;/bin/login&#8217; (pid 8247) exited. Scheduling for restart.<br />
starting pid 8395, tty &#8216;/dev/ttyS1&#8242;: &#8216;/bin/login&#8217;<br />
FON login:</p>
]]></content:encoded>
			<wfw:commentRss>http://emuonpsp.net/blog/?feed=rss2&#038;p=101</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>■PS VitaのNative Hackを使った最初の自作ソフトが公開?</title>
		<link>http://emuonpsp.net/blog/?p=72</link>
		<comments>http://emuonpsp.net/blog/?p=72#comments</comments>
		<pubDate>Mon, 08 Dec 2014 14:32:20 +0000</pubDate>
		<dc:creator><![CDATA[Emu on PSP]]></dc:creator>
				<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[PS Vita]]></category>

		<guid isPermaLink="false">http://emuonpsp.net/blog/?p=72</guid>
		<description><![CDATA[PS VitaのHackが進んでいる今日...]]></description>
				<content:encoded><![CDATA[<p><iframe src="//www.youtube.com/embed/BBBUWIef3rQ" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></p>
<p>PS VitaのHackが進んでいる今日このごろですが、今まではブラウザ経由でのmoduleファイルダンプなどが中心で、主に開発者向けという感じでした。</p>
<p>今回Brian Balling氏が公開した動画はそのexploitを利用して、PS Vitaで初の自作ソフトを動作させるというもので、その動作が確認できます。内容としては、SceNet関数とsceMotionGetState関数を利用して■を動かしたときにPS Vitaから出力されるデータ(傾きセンサーからのデータ)をPCに送信しているようです。</p>
<p>厳密に言うと自作ソフトでは無いとは思いますが、こういったことがこれまでの積み重ねなのでしょうね。これからどのようになるか、期待です。</p>
]]></content:encoded>
			<wfw:commentRss>http://emuonpsp.net/blog/?feed=rss2&#038;p=72</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
