base path changed to C:\Users\CptKlink\Desktop\R-JTAG\J-Runner\xeBuild---- { Image Build Mode } ----
building jtag image
<enter> key on completion suppressed
data directory overridden from command line to '16747\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\CptKlink\Desktop\R-JTAG\J-Runner\007556582707\updflash.bin'
------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0x18BCXXXXXXXXXX2FE2FBCD0DDAF3A3F2 (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to : 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to : 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)
------ parsing ini at '16747\_jtag.ini' ------
ini version 16747
ini: label [falconbl] found
found (1) 'cb_5770.bin' crc: 0x3279f0d5
found (2) 'cd_5770.bin' crc: 0xd04e8927
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2530f8ce
found (6) 'cb_5771.bin' crc: 0x859140f0
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_16747.bin' crc: 0x94a4ef68
found (9) 'cg_16747.bin' crc: 0x88e1e9b9
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x12d353e9
found (2) 'bootanim.xex' crc: 0x151b0618
found (3) 'createprofile.xex' crc: 0x32ceed5a
found (4) 'dash.xex' crc: 0x4103a319
found (5) 'deviceselector.xex' crc: 0xfe497738
found (6) 'gamerprofile.xex' crc: 0xef9022d5
found (7) 'hud.xex' crc: 0xc0e76e31
found (8) 'huduiskin.xex' crc: 0x155495d3
found (9) 'mfgbootlauncher.xex' crc: 0xdecbab8e
found (10) 'minimediaplayer.xex' crc: 0x2892b8d5
found (11) 'nomni.xexp' crc: 0xdcef767a
found (12) 'nomnifwk.xexp' crc: 0x0d14c998
found (13) 'nomnifwm.xexp' crc: 0xdc46bb6e
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0xcbfce61f
found (16) 'updater.xex' crc: 0xafef5cf0
found (17) 'vk.xex' crc: 0xf2caff49
found (18) 'xam.xex' crc: 0x79f6eabf
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x4c2f6bd1
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x34c9b084
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: C:\Users\CptKlink\Desktop\R-JTAG\J-Runner\007556582707\updflash.bin
1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed
------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
***** WARNING: nanddump.bin has a bad LBA at block 0x37e (raw offset 0xe67c00), block LBA ignored
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x09 Pairing: 0x57890f
CF slot 1 decrypted ok LDV 0x0a Pairing: 0x57890f
setting LDV from image to 10
setting pairing data from image to 0x57890f
pairing set to: 57 89 0f
MobileB.dat found at block 0xe8, page 0x4 (page 0x1d04), size 2048 (0x800) bytes
MobileC.dat found at block 0x186, page 0x0 (page 0x30c0), size 512 (0x200) bytes
MobileD.dat found at block 0x152, page 0xc (page 0x2a4c), size 2048 (0x800) bytes
MobileE.dat found at block 0x3a6, page 0x0 (page 0x74c0), size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at block 0x3d9, page 0x0 (page 0x7b20) raw offset 0x7b20
seeking security files...
crl.bin found in sector 0x3bf size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x358 size 0xde60...verified! Will use if external file not found.
extended.bin found in sector 0x3bd size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x3c2 size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image
------ loading system update container ------
16747\su20076000_00000000 found, loading...done!
Read 0xb35000 bytes to memory
checking integrity...
header seems valid, version 2.0.16747.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)...done!
------ Loading bootloaders and required security files ------
could not read 16747\bin\payload.bin, using built in payload (0x200 bytes)
reading data\SMC.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cb_5770.bin (0x8e40 bytes)
loaded cb_5770.bin, could not check signature rsa key not present!
reading .\common\cd_5770.bin (0x56c0 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\common\cf_4532.bin (0x44c0 bytes)
reading .\common\cg_4532.bin (0x2ef40 bytes)
extracted SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)
could not read 16747\bin\freeboot.bin, using built in core (0xd40 bytes)
reading 16747\bin\patches_falcon.bin (0xa0c bytes)
reading data\xell-2f.bin (0x40000 bytes)
reading .\common\cb_5771.bin (0x9340 bytes)
loaded cb_5771.bin, could not check signature rsa key not present!
reading .\common\cd_8453.bin (0x5780 bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:4a:76:3b
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 1
resetKey : YYXY
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cb_5770.bin, 1BL RSA key not present!
could not check signature of cb_5771.bin, 1BL RSA key not present!
done!
------ Patching boot reasons and options into flash header ------
Patching header for xell power reason
------ Encrypting and finalizing bootloaders ------
Fuse CPU Key set to: 0x18BCXXXXXXXXXX2FE2FBCD0DDAF3A3F2
Fuse CF LDV set to : 0xFFFFFFFFFF0000000000000000000000
encoding payload.bin size 0x200 (JTAG)
patching payload.bin to load size 0xd40 (0x350 reps)
encoding SMC.bin size 0x3000 (JTAG)
SMC checksum: a6ee8b80
unknown SMC found, type: Jasper v4.1(2.03)
jtag hack found in SMC binary!
******* WARNING: could not patch SMC reset limit!
encoding kv.bin size 0x4000 (JTAG)
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cb_5770.bin size 0x8e40 (JTAG)
CB 5770 seq 0x01050018 type: 0x01 cseq: 0x05 allow: 0x0018
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 0000F00000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
encoding cd_5770.bin size 0x56c0 (JTAG)
encoding ce_1888.bin size 0x56070 (JTAG)
encoding cf_4532.bin size 0x44c0 (JTAG)
encoding cg_4532.bin size 0x2ef40 (JTAG)
encoding cf_16747.bin size 0x4560 (JTAG)
encoding cg_16747.bin size 0x75ab0 (JTAG)
encoding freeboot.bin size 0xd40 (JTAG)
patching freeboot.bin with with kernel version string '16747'
Boot options set:
- console DVD eject button is being used to start xell
- alternate xell button disabled
encoding patches_falcon.bin size 0xa10 (JTAG)
encoding fuses.bin size 0x60 (JTAG)
encoding xell-2f.bin size 0x40000 (JTAG)
encoding cb_5771.bin size 0x9340 (JTAG)
CB 5771 seq 0x01070058 type: 0x01 cseq: 0x07 allow: 0x0058
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
CBENC pairing set to: 57 89 0f
encoding cd_8453.bin size 0x5780 (JTAG)
Virtual Fuses set to:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000
fuseset 03: 18BCAF8008B8492F
fuseset 04: 18BCAF8008B8492F
fuseset 05: E2FBCD0DDAF3A3F2
fuseset 06: E2FBCD0DDAF3A3F2
fuseset 07: FFFFFFFFFF000000
fuseset 08: 0000000000000000
fuseset 09: 0000000000000000
fuseset 10: 0000000000000000
fuseset 11: 0000000000000000
done!
------ Adding bootloaders to flash image ------
adding payload.bin at raw offset 0x00000200 len 0x200 (end 0x400)
adding SMC.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cb_5770.bin at raw offset 0x00008000 len 0x8e40 (end 0x10e40)
adding cd_5770.bin at raw offset 0x00010e40 len 0x56c0 (end 0x16500)
adding ce_1888.bin at raw offset 0x00016500 len 0x56070 (end 0x6c570)
adding cf_4532.bin at raw offset 0x00070000 len 0x44c0 (end 0x744c0)
adding cg_4532.bin at raw offset 0x000744c0 len 0x2ef40 (end 0x80000, rest in fs)
adding cf_16747.bin at raw offset 0x00080000 len 0x4560 (end 0x84560)
adding cg_16747.bin at raw offset 0x00084560 len 0x75ab0 (end 0x90000, rest in fs)
adding freeboot.bin at raw offset 0x00090000 len 0xd40 (end 0x90d40)
adding patches_falcon.bin at raw offset 0x00091000 len 0xa10 (end 0x91a10)
adding fuses.bin at raw offset 0x00095000 len 0x60 (end 0x95060)
adding xell-2f.bin at raw offset 0x00095060 len 0x40000 (end 0xd5060)
adding cb_5771.bin at raw offset 0x000d5060 len 0x9340 (end 0xde3a0)
adding cd_8453.bin at raw offset 0x000de3a0 len 0x5780 (end 0xe3b20)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xe4000 len 0x00023400 (end: 0x00107400)...done!
Writing target CG patch slot overflow data to sysupdate.xexp2
at raw offset 0xe4000 len 0x0006a010 (end: 0x0014e010)...done!
------ adding 25 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x12d353e9 ini: 0x12d353e9)
adding as aac.xexp2 at raw offset 0x172010 len 0x00014000 (end 0x00186010)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x151b0618 ini: 0x151b0618)
adding as bootanim.xex at raw offset 0x188000 len 0x00061000 (end 0x001e9000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x32ceed5a ini: 0x32ceed5a)
adding as createprofile.xex at raw offset 0x1e9000 len 0x0000c000 (end 0x001f5000)
extracted SUPD\dash.xex (0x598000 bytes) (crc32: 0x4103a319 ini: 0x4103a319)
adding as dash.xex at raw offset 0x1f8000 len 0x00598000 (end 0x00790000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0xfe497738 ini: 0xfe497738)
adding as deviceselector.xex at raw offset 0x790000 len 0x0000a000 (end 0x0079a000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xef9022d5 ini: 0xef9022d5)
adding as gamerprofile.xex at raw offset 0x79a000 len 0x0001b000 (end 0x007b5000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xc0e76e31 ini: 0xc0e76e31)
adding as hud.xex at raw offset 0x7b7000 len 0x0001d000 (end 0x007d4000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x155495d3 ini: 0x155495d3)
adding as huduiskin.xex at raw offset 0x7d5000 len 0x00014000 (end 0x007e9000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xdecbab8e ini: 0xdecbab8e)
adding as mfgbootlauncher.xex at raw offset 0x7ec000 len 0x00008000 (end 0x007f4000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x2892b8d5 ini: 0x2892b8d5)
adding as minimediaplayer.xex at raw offset 0x7f4000 len 0x0000c000 (end 0x00800000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0xdcef767a ini: 0xdcef767a)
adding as nomni.xexp2 at raw offset 0x800000 len 0x0000c800 (end 0x0080c800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x0d14c998 ini: 0x0d14c998)
adding as nomnifwk.xexp2 at raw offset 0x80c800 len 0x00002000 (end 0x0080e800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0xdc46bb6e ini: 0xdc46bb6e)
adding as nomnifwm.xexp2 at raw offset 0x812000 len 0x00005000 (end 0x00817000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x819000 len 0x00006000 (end 0x0081f000)
extracted SUPD\signin.xex (0x19000 bytes) (crc32: 0xcbfce61f ini: 0xcbfce61f)
adding as signin.xex at raw offset 0x822000 len 0x00019000 (end 0x0083b000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xafef5cf0 ini: 0xafef5cf0)
adding as updater.xex at raw offset 0x83d000 len 0x00007000 (end 0x00844000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xf2caff49 ini: 0xf2caff49)
adding as vk.xex at raw offset 0x847000 len 0x0000b000 (end 0x00852000)
extracted SUPD\xam.xex (0x253000 bytes) (crc32: 0x79f6eabf ini: 0x79f6eabf)
adding as xam.xex at raw offset 0x853000 len 0x00253000 (end 0x00aa6000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xaa7000 len 0x0011b000 (end 0x00bc2000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp2 at raw offset 0xbc3000 len 0x00018000 (end 0x00bdb000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbdc000 len 0x001a8000 (end 0x00d84000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp2 at raw offset 0xd84000 len 0x00007000 (end 0x00d8b000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x4c2f6bd1 ini: 0x4c2f6bd1)
adding as ximecore.xex at raw offset 0xd8b000 len 0x00017000 (end 0x00da2000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xda3000 len 0x00090000 (end 0x00e33000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0x34c9b084 ini: 0x34c9b084)
adding as ximedic.xexp2 at raw offset 0xe34000 len 0x00002800 (end 0x00e36800)
------ adding 4 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe38000 len 0x00000a00 (end 0x00e38a00)
<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe3c000 len 0x0000ad30 (end 0x00e46d30)
<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe48000 len 0x00004000 (end 0x00e4c000)
<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe4c000 len 0x00000400 (end 0x00e4c400)
------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe50000 len 0x800 (end 0xe50800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe54000 len 0x200 (end 0xe54200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe58000 len 0x800 (end 0xe58800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe5c000 len 0x800 (end 0xe5c800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)
------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe60000 len 0x4000 (end 0xe64000)...done!
calculating ECD bytes and assembling raw image...done!
done remapping!
------ writing image to disk ------
writing file 'C:\Users\CptKlink\Desktop\R-JTAG\J-Runner\007556582707\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\CptKlink\Desktop\R-JTAG\J-Runner\007556582707\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.16747.0
Console : Falcon
NAND size : 16MiB
Build : JTAG
Xell : power on console with console eject button
Serial : 007556582707
ConsoleId : 016658243151
MoboSerial: 8578473212938267
Mfg Date : 06/29/2008
CPU Key : 18BCXXXXXXXXXX2FE2FBCD0DDAF3A3F2
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : 6094FAA01805B14E6E8347299D2FFE52
CF LDV : 10
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------