0x9f040000 is image address for.
+f80000 is for flash size (refer OpenWRT article 16MB Flash size)
How about 0x81000000 ? Can you explain this one, please?
Firstly, sorry, but I can't help you with your serial typing issue! I have no idea of what could be wrong there!
Secondly, I’m not a coder or programmer I just followed the videos and substituted the info obtained in PuTTY from my router and it has worked every time! 0x81000000 is the load address in my router.
In PuTTY when you type - tftpboot - then ctrl-C to stop the scroll to take note of the IP address at the line that reads "TFTP from server" below that line there should be a line... "Filename 'XXXXXXXX.img'", then below that there should be a line...
"Load address: XxXXXXXXXX" (in my Archer C7 the “Load address” is - 0x81000000)
Further in the process after you type - erase 0x9f040000 +f80000 (or whatever from your router) it erases the sectors, in the next step you type…
cp.b (plus) "Load Address" (plus) 0x9f040000 (plus) 0xf80000 (or whatever your routers addresses are)
My Archer version 2 exact example --> cp.b 0x81000000 0x9f020000 0xfb0000
But, if you now have Lede installed and working it should be easy to revert back to stock using same TFTP method!
Here is the log for press reset button for 3 sec. checksum bad
Quote:
U-Boot 1.1.4 (Aug 10 2017 - 18:22:29)
ap152 - Dragonfly 1.0
DRAM: 128 MB
Top of RAM usable for U-Boot at: 88000000
Reserving 395k for U-Boot at: 87f9c000
Reserving 16448k for malloc() at: 86f8c000
Reserving 44 Bytes for Board Info at: 86f8bfd4
Reserving 36 Bytes for Global Data at: 86f8bfb0
Reserving 128k for boot params() at: 86f6bfb0
Stack Pointer at: 86f6bf98
Now running in RAM - U-Boot at: 87f9c000
Flash Manuf Id 0xc8, DeviceId0 0x40, DeviceId1 0x18
flash size 16MB, sector count = 256
Flash: 16 MB
Using default environment
In: serial
Out: serial
Err: serial
Net: ath_gmac_enet_initialize...
No valid address in Flash. Using fixed address
ath_gmac_enet_initialize: reset mask:c02200
athr_mgmt_init ::done
Dragonfly ----> S17 PHY *
athrs17_reg_init: complete
SGMII in forced mode
athr_gmac_sgmii_setup SGMII done
: cfg1 0x80000000 cfg2 0x7114
eth0: 00:03:7f:09:0b:ad
eth0 up
eth0
Setting 0x181162c0 to 0x40802100
run command setenv serverip 192.168.0.66;setenv ipaddr 192.168.0.86
run command tftp 0x80060000 ArcherC7v4_tp_recovery.bin
Trying eth0
dup 1 speed 1000
Using eth0 device
TFTP from server 192.168.0.66; our IP address is 192.168.0.86
Filename 'ArcherC7v4_tp_recovery.bin'.
Load address: 0x80060000
Loading: checksum bad
checksum bad
##checksum bad
###############################################################
#################################################################
########################checksum bad
#checksum bad
########################################
########checksum bad
#########################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#########################################Tftp server tranfer fail!
tftpboot firmware failed, now start normally.
factory boot check integer ok.
factory boot load fs uboot len 131072 to addr 0x80010000.
Hit any key to stop autoboot: 0
## Starting application at 0x80010000 ...
U-Boot 1.1.4 (Aug 10 2017 - 18:22:1
ap152 - Dragonfly 1.0
DRAM: 128 MB
Top of RAM usable for U-Boot at: 88000000
Reserving 122k for U-Boot at: 87fe0000
Reserving 16448k for malloc() at: 86fd0000
Reserving 44 Bytes for Board Info at: 86fcffd4
Reserving 36 Bytes for Global Data at: 86fcffb0
Reserving 128k for boot params() at: 86faffb0
Stack Pointer at: 86faff98
Now running in RAM - U-Boot at: 87fe0000
Flash Manuf Id 0xc8, DeviceId0 0x40, DeviceId1 0x18
flash size 16MB, sector count = 256
Flash: 16 MB
Using default environment
In: serial
Out: serial
Err: serial
Net: ath_gmac_enet_initialize...
No valid address in Flash. Using fixed address
ath_gmac_enet_initialize: reset mask:c02200
athr_mgmt_init ::done
Dragonfly ----> S17 PHY *
athrs17_reg_init: complete
SGMII in forced mode
athr_gmac_sgmii_setup SGMII done
: cfg1 0x80000000 cfg2 0x7114
eth0: 00:03:7f:09:0b:ad
eth0 up
eth0
Setting 0x181162c0 to 0x40802100
Hit any key to stop autoboot: 0
## Booting image at 9f040000 ...
Bad Magic Number
ath>
Yeah, I have already check that site but V4 stripped firmware is missing, only have V2.
But
Archer C7 AC1750 v2 use Qualcomm Atheros QCA9558 CPU
Archer C7 AC1750 v4 use Qualcomm Atheros QCA9561 CPU
(Refer to LEDE router database)
I thinks V2 firmware is totally incapable with V4.
---
Uncle Luke wrote:
0x81000000 is the load address in my router.
below that line there should be a line... "Filename 'XXXXXXXX.img'", then below that there should be a line...
"Load address: XxXXXXXXXX" (in my Archer C7 the “Load address” is - 0x81000000)
cp.b (plus) "Load Address" (plus) 0x9f040000 (plus) 0xf80000 (or whatever your routers addresses are)
My Archer version 2 exact example --> cp.b 0x81000000 0x9f020000 0xfb0000
Yeah, that's introduction what I use to recover to LEDE.
That article have give me the right introduction.
Quote:
Flash instruction using TFTP recovery:
1. Set PC to fixed ip address 192.168.0.66
2. Download lede-ar71xx-generic-archer-c7-v4-squashfs-factory.bin
and rename it to ArcherC7v4_tp_recovery.bin
3. Start a tftp server with the file tp_recovery.bin in its root directory
4. Turn off the router
5. Press and hold Reset button
6. Turn on router with the reset button pressed and wait ~15 seconds
7. Release the reset button and after a short time
the firmware should be transferred from the tftp server
8. Wait ~30 second to complete recovery.
Don't forget connect via SSH (username root / no password) to the device and running the following two commands:
Renaming it to ArcherC7v4_tp_recovery.bin and flashing with tftpd32. After that I was able to repeat the process using the original untouched firmware from Tp-link website!