RGH Falcon Booting Xell but not Freeboot

wartog

Full Member
Jun 11, 2010
82
0
Nowhere
hello,

please help

have successfully glitched falcon to boot xell but it dosent boot into freeboot .

Xell boots with in 5 sec
freeboot dosent boot just green led flashing.

using coolrunner rev-A (tried the following timing TX_RGH2_A.xsvf xell boots in 5 sec and TX_RGH2_B.xsvf xell boots in 2 min)
Jrunner to build eec glitch and freeboot(14749 dash)
nandx

below is the xebuild logs
---------------------------------------------------------------
xeBuild v1.02.477
---------------------------------------------------------------
building glitch2 image
data directory overridden from command line to '.\xeBuild\14719\'
per build directory overridden from command line to 'xeBuild\data'
file name overridden from command line to 'K:\xbox\RGH\nand files\jrun\014290584207\nandflash.bin'

------ parsing user ini at '.\xeBuild\data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x14f bytes in memory
loading cpukey.txt from .\xeBuild\data\cpukey.txt
CPU Key set to: 0x6BBB0A6A60AD146D86335E81BE275002
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to: 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)

------ parsing ini at '.\xeBuild\14719\_glitch2.ini' ------
ini version 14719

ini: label [falconbl] found
found (1) 'cba_5772.bin' crc: 0xe3696f7e
found (2) 'cbb_5772.bin' crc: 0xfb5ab9a4
found (3) 'cd_9452.bin' crc: 0x455fa02c
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_14719.bin' crc: 0x31764aae
found (6) 'cg_14719.bin' crc: 0x2b990f2a
ini dictates dual CB for this model

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x79fa8ef9
found (2) 'bootanim.xex' crc: 0x4708ac41
found (3) 'createprofile.xex' crc: 0x17d7eeef
found (4) 'dash.xex' crc: 0xc331818a
found (5) 'deviceselector.xex' crc: 0xce0a6ac4
found (6) 'gamerprofile.xex' crc: 0x3d6fde71
found (7) 'hud.xex' crc: 0xfb9af532
found (8) 'huduiskin.xex' crc: 0x59c8f99e
found (9) 'mfgbootlauncher.xex' crc: 0x30028379
found (10) 'minimediaplayer.xex' crc: 0xea50ae99
found (11) 'nomni.xexp' crc: 0xd1e81135
found (12) 'nomnifwk.xexp' crc: 0x6311da91
found (13) 'nomnifwm.xexp' crc: 0x03b32644
found (14) 'SegoeXbox-Light.xtt' crc: 0x086eb344
found (15) 'signin.xex' crc: 0x09f66fc4
found (16) 'updater.xex' crc: 0x9dc378a8
found (17) 'vk.xex' crc: 0x8ad4198e
found (18) 'xam.xex' crc: 0xc1ee0989
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0x945b7092
found (23) 'ximecore.xex' crc: 0x709614d6
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xa1284e82
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: K:\xbox\RGH\nand files\jrun\014290584207\nandflash.bin


------ Checking .\xeBuild\data\nanddump.bin ------
Loading NAND dump (0x22ee70 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x09 Pairing: 0x82fead
CF slot 1 decrypted ok LDV 0x08 Pairing: 0x82fead
setting LDV from image to 9
setting pairing data from image to 0x82fead
MobileB.dat found at page 0x700, size 2048 (0x800) bytes
MobileC.dat found at page 0x6a0, size 512 (0x200) bytes
MobileD.dat found at page 0x68e0, size 2048 (0x800) bytes
MobileE.dat found at page 0x3120, size 1536 (0x600) bytes
Statistics.settings found at page 0x22edf0, size 31680 (0x1000) bytes
seeking FSRoot...fsroot found at page 0x3de0 raw offset 0x7f9e00
seeking security files...
crl.bin found in sector 0x207 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x204 size 0x7090...verified! Will use if external file not found.
extended.bin found in sector 0x34e size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x202 size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image

------ loading system update container ------
.\xeBuild\14719\su20076000_00000000 found, loading...done!
Read 0xba2000 bytes to memory
checking container integrity...
header seems valid, version 2.0.14719.00
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x6aa10 bytes)
decrypting SUPD\xboxupd.bin\CF_14719.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_14719.bin (0x664aa bytes)...done!

------ Loading bootloaders and required security files ------
reading .\xeBuild\data\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading .\xeBuild\data\kv.bin failed, using kv.bin from nand dump
reading .\xeBuild\14719\cba_5772.bin (0x1ac0 bytes)
reading .\xeBuild\14719\cbb_5772.bin (0x9350 bytes)
reading .\xeBuild\14719\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\xeBuild\data\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_14719.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_14719.bin (0x664aa bytes)
reading .\xeBuild\14719\bin\patches_g2falcon.bin (0x734 bytes)
reading .\xeBuild\data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:22:48:1a:77:3e
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 5
resetKey : LLDX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching patches...
Default patch offset 0x000c0010 not changed
Patching patches for alt power reason
Patches patched!
Patching BLs...Done!

------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3000
SMC checksum: 1d0c613e
known clean SMC found, type: Falcon v3.1(1.06)
patching smc at offset: 0x12a3
SMC hacked successfully
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
encoding cba_5772.bin size 0x1ac0
encoding cbb_5772.bin size 0x9350
CB 5772 seq 0x010800d8 type: 0x01 cseq: 0x08 allow: 0x00d8
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 0000000F00000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
fuseset 02: 0000000F00000000 (allow cseq 8)
encoding cd_9452.bin size 0x5200
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_14719.bin size 0x4560
encoding cg_14719.bin size 0x664b0
encoding patches_g2falcon.bin size 0x404
done!

------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_5772.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_5772.bin at raw offset 0x00009ac0 len 0x9350 (end 0x12e10)
adding cd_9452.bin at raw offset 0x00012e10 len 0x5200 (end 0x18010)
adding ce_1888.bin at raw offset 0x00018010 len 0x56070 (end 0x6e080)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_14719.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_14719.bin at raw offset 0x000b4560 len 0x664b0 (end 0xc0000, rest in fs)
adding patches_g2falcon.bin at raw offset 0x000c0010 len 0x404 (end 0xc0414)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0005aa10 (end: 0x0012aa10)...done!

------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x79fa8ef9 ini: 0x79fa8ef9)
adding as aac.xexp1 at raw offset 0x12aa10 len 0x00014000 (end 0x0013ea10)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x4708ac41 ini: 0x4708ac41)
adding as bootanim.xex at raw offset 0x140000 len 0x00061000 (end 0x001a1000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x17d7eeef ini: 0x17d7eeef)
adding as createprofile.xex at raw offset 0x1a1000 len 0x0000c000 (end 0x001ad000)
extracted SUPD\dash.xex (0x63a000 bytes) (crc32: 0xc331818a ini: 0xc331818a)
adding as dash.xex at raw offset 0x1b0000 len 0x0063a000 (end 0x007ea000)
extracted SUPD\deviceselector.xex (0x9000 bytes) (crc32: 0xce0a6ac4 ini: 0xce0a6ac4)
adding as deviceselector.xex at raw offset 0x7ea000 len 0x00009000 (end 0x007f3000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0x3d6fde71 ini: 0x3d6fde71)
adding as gamerprofile.xex at raw offset 0x7f5000 len 0x0001b000 (end 0x00810000)
extracted SUPD\hud.xex (0x1e000 bytes) (crc32: 0xfb9af532 ini: 0xfb9af532)
adding as hud.xex at raw offset 0x813000 len 0x0001e000 (end 0x00831000)
extracted SUPD\huduiskin.xex (0x13000 bytes) (crc32: 0x59c8f99e ini: 0x59c8f99e)
adding as huduiskin.xex at raw offset 0x832000 len 0x00013000 (end 0x00845000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x30028379 ini: 0x30028379)
adding as mfgbootlauncher.xex at raw offset 0x847000 len 0x00008000 (end 0x0084f000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0xea50ae99 ini: 0xea50ae99)
adding as minimediaplayer.xex at raw offset 0x850000 len 0x0000c000 (end 0x0085c000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0xd1e81135 ini: 0xd1e81135)
adding as nomni.xexp1 at raw offset 0x85c000 len 0x0000c800 (end 0x00868800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x6311da91 ini: 0x6311da91)
adding as nomnifwk.xexp1 at raw offset 0x868800 len 0x00002000 (end 0x0086a800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x03b32644 ini: 0x03b32644)
adding as nomnifwm.xexp1 at raw offset 0x86e000 len 0x00005000 (end 0x00873000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0x086eb344 ini: 0x086eb344)
adding as SegoeXbox-Light.xtt at raw offset 0x875000 len 0x00006000 (end 0x0087b000)
extracted SUPD\signin.xex (0x16000 bytes) (crc32: 0x09f66fc4 ini: 0x09f66fc4)
adding as signin.xex at raw offset 0x87e000 len 0x00016000 (end 0x00894000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0x9dc378a8 ini: 0x9dc378a8)
adding as updater.xex at raw offset 0x896000 len 0x00007000 (end 0x0089d000)
extracted SUPD\vk.xex (0x9000 bytes) (crc32: 0x8ad4198e ini: 0x8ad4198e)
adding as vk.xex at raw offset 0x89f000 len 0x00009000 (end 0x008a8000)
extracted SUPD\xam.xex (0x236000 bytes) (crc32: 0xc1ee0989 ini: 0xc1ee0989)
adding as xam.xex at raw offset 0x8a9000 len 0x00236000 (end 0x00adf000)
reading .\xeBuild\14719\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xae2000 len 0x0011b000 (end 0x00bfd000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xbff000 len 0x00018000 (end 0x00c17000)
reading .\xeBuild\14719\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xc18000 len 0x001a8000 (end 0x00dc0000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0x945b7092 ini: 0x945b7092)
adding as xenonjklatin.xttp1 at raw offset 0xdc0000 len 0x00007000 (end 0x00dc7000)
extracted SUPD\ximecore.xex (0x15000 bytes) (crc32: 0x709614d6 ini: 0x709614d6)
adding as ximecore.xex at raw offset 0xdc7000 len 0x00015000 (end 0x00ddc000)
reading .\xeBuild\14719\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xddd000 len 0x00090000 (end 0x00e6d000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xa1284e82 ini: 0xa1284e82)
adding as ximedic.xexp1 at raw offset 0xe70000 len 0x00002800 (end 0x00e72800)
reading .\xeBuild\14719\..\launch.xex (0xb800 bytes)
adding as launch.xex at raw offset 0xe72800 len 0x0000b800 (end 0x00e7e000)
reading .\xeBuild\14719\..\lhelper.xex (0x6000 bytes)
adding as lhelper.xex at raw offset 0xe7f800 len 0x00006000 (end 0x00e85800)

***** could not read .\xeBuild\14719\..\launch.ini, skipping *****

------ adding 5 security files ------
<- Processing crl.bin ->
reading .\xeBuild\data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe88000 len 0x00000a00 (end 0x00e88a00)

<- Processing dae.bin ->
reading .\xeBuild\data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe8c000 len 0x0000ad30 (end 0x00e96d30)

<- Processing extended.bin ->
reading .\xeBuild\data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe98000 len 0x00004000 (end 0x00e9c000)

<- Processing fcrt.bin ->
fcrt.bin not found and not required by keyvault, skipped

<- Processing secdata.bin ->
reading .\xeBuild\data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe9c000 len 0x00000400 (end 0x00e9c400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from nanddump.bin
adding MobileB.dat as type 0x31 at raw offset 0xea0000 len 0x800 (end 0xea0800)
MobileC.dat found, adding from nanddump.bin
adding MobileC.dat as type 0x32 at raw offset 0xea4000 len 0x200 (end 0xea4200)
MobileD.dat found, adding from nanddump.bin
adding MobileD.dat as type 0x33 at raw offset 0xea8000 len 0x800 (end 0xea8800)
MobileE.dat found, adding from nanddump.bin
adding MobileE.dat as type 0x34 at raw offset 0xeac000 len 0x600 (end 0xeac600)
Statistics.settings found, adding from nanddump.bin
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image...done!
calculating ECD bytes and assembling raw image...done!
writing file 'K:\xbox\RGH\nand files\jrun\014290584207\nandflash.bin' to disk...done!
K:\xbox\RGH\nand files\jrun\014290584207\nandflash.bin written OK

---------------------------------------------------------------
K:\xbox\RGH\nand files\jrun\014290584207\nandflash.bin image built, info:
---------------------------------------------------------------
Console : Falcon
NAND size: 16MiB
Build : Glitch (v2)
Xell : power on console with console eject button
CPU Key : 6BBB0A6A60AD146D86335E81BE275002
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : 1CB2A51CC72F06E0D3C83ADC9B1CA8F0
CF LDV : 9
KV type : type2 (hashed)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
 

wartog

Full Member
Jun 11, 2010
82
0
Nowhere
yes xell is booting from eject button after writing the freeboot but the freeboot image dosent boot up
need to check LDV will getback with that.
 

gamehawk55

VIP Member
Mar 21, 2006
202
33
Canada
www.chaotic-consoles.com
Log file shows that SMC config was NOT patched. I'm assuming that this is essential to having the hacked kernal boot is it not? There is an options.ini file in with the xebuild files within the J-Runner folder. open that file in notepad and find the "patchsmc" option and make sure it reads patchsmc = true and not patchsmc = false.

I just checked mine and it is set to true, and I havent had any problems getting a freeboot image to boot on both falcons and jaspers now although my boot times are horrible at the moment they still boot.

Also make sure you are running the latest version of J-Runner. Latest is v0.2 Beta (272). If you are running the latest then just go change the patchsmc setting to true and it should work for you after that.

Surprised you didnt catch that one Martin:p
 

wartog

Full Member
Jun 11, 2010
82
0
Nowhere
SMC PAtch is True in Options.ini

and LDV value was 8 before and after creating the image its incremented to 9

also i found this in the logs will this be a problem


***** could not read .\xeBuild\14719\..\launch.ini, skipping *****
 

wartog

Full Member
Jun 11, 2010
82
0
Nowhere
team,

tried with the new falcon.XSVF timing file with no improvement.

believe that there is something missing in the freeboot image getting created just as the initial jasper versions.

any help or suggestions will be appriciated
 

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
It's not a timings file issue as XeLL boots.

It's also nothing to do with launch.ini being missing as that's a dashlaunch file.

If your LDV is 8, I'm trying to understand how J-Runner is reporting it as 9. Did you edit anything during the creation of the RGH image?

"setting LDV from image to 9"

Indicates it's taken the value from your NAND image.
 

wartog

Full Member
Jun 11, 2010
82
0
Nowhere
It's not a timings file issue as XeLL boots.

It's also nothing to do with launch.ini being missing as that's a dashlaunch file.

If your LDV is 8, I'm trying to understand how J-Runner is reporting it as 9. Did you edit anything during the creation of the RGH image?

"setting LDV from image to 9"

Indicates it's taken the value from your NAND image.

martin sorry to get you confused attached is the images for nand info for original Nand dump and Freeboot image


original nand dump nand info


Freeboot image Nand info




please let me know if these are proper and what needs to be done to correct them.

is any one able to RGH2 a Falcon??? please share any useful tips
 

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
So your LDV is ok - cool.

If it's booting XeLL but not an RGH image, it might be the wire positioning. Can you take a pic of the top and bottom of the board?