RGH RGH 2.0 - Help - 5773 Falcon doesn't boot to hacked dash, Xell is okay

SuperFury

Noob Account
Dec 15, 2010
7
3
Germany
I have a problem with my RGH 2.0 Setup on my v3.0 Falcon

ECC boots well, if flashed alone, xell boots from Hacked Image as well, but the hacked dash itself does not boot.

To me it seems software related or is the technical-side of booting xell and booting a Hacked Dash different ?

To me it seems that the Coolrunner receives a kind of signal to stop glitching when the glitch is done. When receiving this signal it stops blinking green.
It seems to some kind of glitch the Hacked Dash but hangs in continuing the usually following boot process.

My most important question is atm, if everything is wired correctly. Is it 100% sure, that if I can boot xell, that the Coolrunner Setup and Wiring is okay ?

If you start your ECC-Xell, is the behaviour of the Coolrunner (blinking times, blinking strengh and sound of the fans) after glitching ECC-Xell compareable to the behaviour when you try to boot your hacked Image ?

Heres the log:
---------------------------------------------------------------
xeBuild v1.01.421
---------------------------------------------------------------
<enter> key on completion suppressed
building glitch image
per build directory overridden from command line to '..\nand'
Using PATCHSMC option
data directory overridden from command line to '14719'
CPU key overridden from command line, not looking for cpukey.txt
CPU Key set to: 0xA1FA448D3EDBC6DB4056A9764364D340
file name overridden from command line to '..\salida\nandflash.bin'

------ parsing user ini at '.\..\nand\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x13c bytes in memory
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to: 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)

------ parsing ini at '.\14719\_glitch.ini' ------
ini version 14719

ini: label [falconbl] found
found (1) 'cba_5772.bin' crc: 0xe3696f7e
found (2) 'cbb_5772.bin' crc: 0xfb5ab9a4
found (3) 'cd_9452.bin' crc: 0x455fa02c
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_14719.bin' crc: 0x31764aae
found (6) 'cg_14719.bin' crc: 0x2b990f2a
ini dictates dual CB for this model

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x79fa8ef9
found (2) 'bootanim.xex' crc: 0x4708ac41
found (3) 'createprofile.xex' crc: 0x17d7eeef
found (4) 'dash.xex' crc: 0xc331818a
found (5) 'deviceselector.xex' crc: 0xce0a6ac4
found (6) 'gamerprofile.xex' crc: 0x3d6fde71
found (7) 'hud.xex' crc: 0xfb9af532
found (8) 'huduiskin.xex' crc: 0x59c8f99e
found (9) 'mfgbootlauncher.xex' crc: 0x30028379
found (10) 'minimediaplayer.xex' crc: 0xea50ae99
found (11) 'nomni.xexp' crc: 0xd1e81135
found (12) 'nomnifwk.xexp' crc: 0x6311da91
found (13) 'nomnifwm.xexp' crc: 0x03b32644
found (14) 'SegoeXbox-Light.xtt' crc: 0x086eb344
found (15) 'signin.xex' crc: 0x09f66fc4
found (16) 'updater.xex' crc: 0x9dc378a8
found (17) 'vk.xex' crc: 0x8ad4198e
found (18) 'xam.xex' crc: 0xc1ee0989
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0x945b7092
found (23) 'ximecore.xex' crc: 0x709614d6
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xa1284e82
found (26) 'launch.xex' crc: 0x00000000
found (27) 'lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: ..\salida\nandflash.bin


------ Checking .\..\nand\nanddump.bin ------
Loading NAND dump (0x22ee70 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x0d Pairing: 0x7b530a
CF slot 1 decrypted ok LDV 0x0c Pairing: 0x7b530a
setting LDV from image to 13
setting pairing data from image to 0x7b530a
MobileB.dat found at page 0xfc0, size 2048 (0x800) bytes
MobileC.dat found at page 0x3b80, size 512 (0x200) bytes
MobileD.dat found at page 0x7080, size 2048 (0x800) bytes
MobileE.dat found at page 0x3a00, size 2048 (0x800) bytes
seeking security files...fsroot found at page 0xee0 raw offset 0x1eae00
crl.bin found in sector 0xa1 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x9c size 0xd9c0...verified! Will use if external file not found.
extended.bin found in sector 0x1a4 size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x76 size 0x400...verified! Will use if external file not found.
Writing initial header to flash image

------ Loading bootloaders and required security files ------
reading .\..\nand\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading .\..\nand\kv.bin failed, using kv.bin from nand dump
reading .\14719\cba_5772.bin (0x1ac0 bytes)
reading .\14719\cbb_5772.bin (0x9350 bytes)
reading .\14719\cd_9452.bin (0x4f20 bytes)
reading .\14719\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\..\nand\xell-gggggg.bin (0x40000 bytes)
reading .\14719\cf_14719.bin (0x4560 bytes)
reading .\14719\cg_14719.bin (0x664aa b pad 0x664b0 b)
reading .\14719\bin\patches_fat.bin (0x720 bytes)
reading .\..\nand\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:81:b2:f5
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : AALU
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching patches...
Default patch offset 0x000c0010 not changed
Patching patches for alt power reason
Patches patched!
Patching BLs...Done!

------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3000
SMC checksum: 1d0c613e
known clean SMC found, type: Falcon v3.1(1.06)
patching smc at offset: 0x12a3
SMC hacked successfully
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
encoding cba_5772.bin size 0x1ac0
encoding cbb_5772.bin size 0x9350
CB 5772 seq 0x010800d8 type: 0x01 cseq: 0x08 allow: 0x00d8
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 0000000F00000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
fuseset 02: 0000000F00000000 (allow cseq 8)
encoding cd_9452.bin size 0x5200
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_14719.bin size 0x4560
encoding cg_14719.bin size 0x664b0
encoding patches_fat.bin size 0x3f0
done!

------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_5772.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_5772.bin at raw offset 0x00009ac0 len 0x9350 (end 0x12e10)
adding cd_9452.bin at raw offset 0x00012e10 len 0x5200 (end 0x18010)
adding ce_1888.bin at raw offset 0x00018010 len 0x56070 (end 0x6e080)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_14719.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_14719.bin at raw offset 0x000b4560 len 0x664b0 (end 0xc0000, rest in fs)
adding patches_fat.bin at raw offset 0x000c0010 len 0x3f0 (end 0xc0400)
Fixing up FS table...done!
Writing CG patch slot overflow data to sysupdate.xexp1 at raw offset 0xd0000...done!

------ adding 28 firmware files ------
reading .\14719\aac.xexp (0x14000 bytes) (crc32: 0x79fa8ef9 ini: 0x79fa8ef9)
adding as aac.xexp1 at raw offset 0x12aa10 len 0x00014000 (end 0x0013ea10)
reading .\14719\bootanim.xex (0x61000 bytes) (crc32: 0x4708ac41 ini: 0x4708ac41)
adding as bootanim.xex at raw offset 0x140000 len 0x00061000 (end 0x001a1000)
reading .\14719\createprofile.xex (0xc000 bytes) (crc32: 0x17d7eeef ini: 0x17d7eeef)
adding as createprofile.xex at raw offset 0x1a1000 len 0x0000c000 (end 0x001ad000)
reading .\14719\dash.xex (0x63a000 bytes) (crc32: 0xc331818a ini: 0xc331818a)
adding as dash.xex at raw offset 0x1b0000 len 0x0063a000 (end 0x007ea000)
reading .\14719\deviceselector.xex (0x9000 bytes) (crc32: 0xce0a6ac4 ini: 0xce0a6ac4)
adding as deviceselector.xex at raw offset 0x7ea000 len 0x00009000 (end 0x007f3000)
reading .\14719\gamerprofile.xex (0x1b000 bytes) (crc32: 0x3d6fde71 ini: 0x3d6fde71)
adding as gamerprofile.xex at raw offset 0x7f5000 len 0x0001b000 (end 0x00810000)
reading .\14719\hud.xex (0x1e000 bytes) (crc32: 0xfb9af532 ini: 0xfb9af532)
adding as hud.xex at raw offset 0x813000 len 0x0001e000 (end 0x00831000)
reading .\14719\huduiskin.xex (0x13000 bytes) (crc32: 0x59c8f99e ini: 0x59c8f99e)
adding as huduiskin.xex at raw offset 0x832000 len 0x00013000 (end 0x00845000)
reading .\14719\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x30028379 ini: 0x30028379)
adding as mfgbootlauncher.xex at raw offset 0x847000 len 0x00008000 (end 0x0084f000)
reading .\14719\minimediaplayer.xex (0xc000 bytes) (crc32: 0xea50ae99 ini: 0xea50ae99)
adding as minimediaplayer.xex at raw offset 0x850000 len 0x0000c000 (end 0x0085c000)
reading .\14719\nomni.xexp (0xc800 bytes) (crc32: 0xd1e81135 ini: 0xd1e81135)
adding as nomni.xexp1 at raw offset 0x85c000 len 0x0000c800 (end 0x00868800)
reading .\14719\nomnifwk.xexp (0x2000 bytes) (crc32: 0x6311da91 ini: 0x6311da91)
adding as nomnifwk.xexp1 at raw offset 0x868800 len 0x00002000 (end 0x0086a800)
reading .\14719\nomnifwm.xexp (0x5000 bytes) (crc32: 0x03b32644 ini: 0x03b32644)
adding as nomnifwm.xexp1 at raw offset 0x86e000 len 0x00005000 (end 0x00873000)
reading .\14719\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0x086eb344 ini: 0x086eb344)
adding as SegoeXbox-Light.xtt at raw offset 0x875000 len 0x00006000 (end 0x0087b000)
reading .\14719\signin.xex (0x16000 bytes) (crc32: 0x09f66fc4 ini: 0x09f66fc4)
adding as signin.xex at raw offset 0x87e000 len 0x00016000 (end 0x00894000)
reading .\14719\updater.xex (0x7000 bytes) (crc32: 0x9dc378a8 ini: 0x9dc378a8)
adding as updater.xex at raw offset 0x896000 len 0x00007000 (end 0x0089d000)
reading .\14719\vk.xex (0x9000 bytes) (crc32: 0x8ad4198e ini: 0x8ad4198e)
adding as vk.xex at raw offset 0x89f000 len 0x00009000 (end 0x008a8000)
reading .\14719\xam.xex (0x236000 bytes) (crc32: 0xc1ee0989 ini: 0xc1ee0989)
adding as xam.xex at raw offset 0x8a9000 len 0x00236000 (end 0x00adf000)
reading .\14719\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xae2000 len 0x0011b000 (end 0x00bfd000)
reading .\14719\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xbff000 len 0x00018000 (end 0x00c17000)
reading .\14719\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xc18000 len 0x001a8000 (end 0x00dc0000)
reading .\14719\xenonjklatin.xttp (0x7000 bytes) (crc32: 0x945b7092 ini: 0x945b7092)
adding as xenonjklatin.xttp1 at raw offset 0xdc0000 len 0x00007000 (end 0x00dc7000)
reading .\14719\ximecore.xex (0x15000 bytes) (crc32: 0x709614d6 ini: 0x709614d6)
adding as ximecore.xex at raw offset 0xdc7000 len 0x00015000 (end 0x00ddc000)
reading .\14719\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xddd000 len 0x00090000 (end 0x00e6d000)
reading .\14719\ximedic.xexp (0x2800 bytes) (crc32: 0xa1284e82 ini: 0xa1284e82)
adding as ximedic.xexp1 at raw offset 0xe70000 len 0x00002800 (end 0x00e72800)
reading .\14719\launch.xex (0xb000 bytes)
adding as launch.xex at raw offset 0xe72800 len 0x0000b000 (end 0x00e7d800)
reading .\14719\lhelper.xex (0x6000 bytes)
adding as lhelper.xex at raw offset 0xe7f000 len 0x00006000 (end 0x00e85000)
reading .\14719\..\launch.ini (0x2d0 bytes)
adding as launch.ini at raw offset 0xe86000 len 0x000002d0 (end 0x00e862d0)

------ adding 4 security files ------
<- Processing crl.bin ->
reading .\..\nand\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe8c000 len 0x00000a00 (end 0x00e8ca00)

<- Processing dae.bin ->
reading .\..\nand\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe90000 len 0x0000ad30 (end 0x00e9ad30)

<- Processing extended.bin ->
reading .\..\nand\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe9c000 len 0x00004000 (end 0x00ea0000)

<- Processing secdata.bin ->
reading .\..\nand\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xea0000 len 0x00000400 (end 0x00ea0400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from nanddump.bin
adding MobileB.dat as type 0x31 at raw offset 0xea4000 len 0x800 (end 0xea4800)
MobileC.dat found, adding from nanddump.bin
adding MobileC.dat as type 0x32 at raw offset 0xea8000 len 0x200 (end 0xea8200)
MobileD.dat found, adding from nanddump.bin
adding MobileD.dat as type 0x33 at raw offset 0xeac000 len 0x800 (end 0xeac800)
MobileE.dat found, adding from nanddump.bin
adding MobileE.dat as type 0x34 at raw offset 0xeb0000 len 0x800 (end 0xeb0800)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image...done!
calculating ECD bytes and assembling raw image...done!
writing file '..\salida\nandflash.bin' to disk...done!
..\salida\nandflash.bin written OK

---------------------------------------------------------------
..\salida\nandflash.bin image built, info:
---------------------------------------------------------------
Console : Falcon
NAND size: 16MiB
Build : Glitch
Xell : power on console with console eject button
CPU Key : ********************************
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : ********************************
CF LDV : 13
KV type : type2 (hashed)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
 
Last edited:

SuperFury

Noob Account
Dec 15, 2010
7
3
Germany
Thank you for your fast answer - Can you confirm that the wiring and cable-lenght and perhaps the used jed-File are correct when xell is booting fine ?

Or are there any wires for dashlaunching only, not required by ECC-Xell ?
 

gamehawk55

VIP Member
Mar 21, 2006
202
33
Canada
www.chaotic-consoles.com
I just did my falcon 5773 last night and it boots xell and the dash. Although the boot times are rather bad at the moment. Usually between 2-3 minutes. Although sometimes I can get it to boot within 15 seconds. I used jrunner to do everything and flashed the coolrunner with the C option. I found that the main culprit for boot times is the CPU_rst wire. I found that wiring to the cpu_rst point on the topside of the board worked best but still have a lot of trial and error to do with the routing and length of that wire. Also the resistor used plays a part too. Some people have had reports that using a 11-16ohm resistor worked for them while others have said that they achieved instant boots using no resistor at all in conjunction with RG59 75ohm coax cable cut to 11inches. If you are hell bent on getting your rgh 2 working now then be prepared to spend countless hours doing A LOT of trial and error with wire types and lengths. Resistor types and strengths. And also testing all different kinds of wirings with all 4 rgh2 timing files. Either that or wait for the TRUE finished rgh2 code to come out and then you we will probably not be having so many issues lol. I'm just hoping we don't have to wait until the demon and coolrunner 2 come out before they release the finished rgh2 hack since it does seem to work fine on existing hardware, just requires a lot of tweaking atm.
 
  • Like
Reactions: Heronimoh

Heronimoh

Full Member
Feb 6, 2011
39
0
SPAIN
I just did my falcon 5773 last night and it boots xell and the dash. Although the boot times are rather bad at the moment. Usually between 2-3 minutes. Although sometimes I can get it to boot within 15 seconds. I used jrunner to do everything and flashed the coolrunner with the C option. I found that the main culprit for boot times is the CPU_rst wire. I found that wiring to the cpu_rst point on the topside of the board worked best but still have a lot of trial and error to do with the routing and length of that wire. Also the resistor used plays a part too. Some people have had reports that using a 11-16ohm resistor worked for them while others have said that they achieved instant boots using no resistor at all in conjunction with RG59 75ohm coax cable cut to 11inches. If you are hell bent on getting your rgh 2 working now then be prepared to spend countless hours doing A LOT of trial and error with wire types and lengths. Resistor types and strengths. And also testing all different kinds of wirings with all 4 rgh2 timing files. Either that or wait for the TRUE finished rgh2 code to come out and then you we will probably not be having so many issues lol. I'm just hoping we don't have to wait until the demon and coolrunner 2 come out before they release the finished rgh2 hack since it does seem to work fine on existing hardware, just requires a lot of tweaking atm.
2 or 3 minutes? :frown:
Probably is true that the resistor value and the kind of the wire has the secret to boot fast.
I have a 50 ohms wire for wifi.
I have to test it.