de_Fuse, a Wii U modchip in development by ShinyQuagsire

tumblr_991e04845ab30223dd16b2d1624b6f4c_b49fe612_500.jpg

The Wii U was truly the black sheep of the main Nintendo consoles, but in terms of homebrew capabilities, it was but a diamond in the rough. While the Wii U is way past its heyday by almost a decade, the homebrew community still continues to thrive and develop great things for the system.

One of these developers, @shinyquagsire23, has made some research and advancements towards creating a modchip for the Wii U, which he titled "de_Fuse". The modchip started when Shiny Quasire started looking at the then unhacked Wii Mini console, in an attempt to glitch boot0 on it, and while getting curious if it could work on Wii U, he found that a similar exploit could be attempted for it, with the only downsides being OTP dumps being impossible due it being all 00s and the driver for boot0 being limited to SDHC cards.

While the necessity of having a modchip for the Wii U is not a must since Wii U already has coldboot exploits and many other things like Aroma that could serve a similar purpose, the main purpose of this modchip is to allow booting a Wii U console straight from the SD card, without having to rely on the Wii U's internal eMMC chip to boot into the console. This due to the recent news about some Wii U consoles bricking entirely due to failures in the eMMC chip, so giving players the option to boot from SD card would be a relief to this delicate issue that plagues the console.

72a7403a2705acdef1d456e392cbcbfc94439cd0.jpg

The rest of the information is highly technical and dives into the eFuses, OTP, boot0, boot1 and SRAM of the console, so those interested in a more in-depth and detailed information regarding the process can read it in Shiny Quagsire's own article about de_Fuse on his webpage.

The modchip is currently in early stages of development, and it currently requires an FPGA of sorts, but it hasn't been standardized in terms of schematics or parts. However, Shiny Quagsire is trying to aim for a $25-$35 dlls range when its finished (or lower), based on RP2040 chip. Those interested and willing to collaborate and help out throughout its development can do so through Shiny Quagsire's GitHub repository for the modchip, where he keeps all of the coding and research for it open source.

:arrow: de_Fuse, the One True Pwn article
:arrow: GitHub Repository
 

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain

SDIO, here's what I've done so far.

WIi U with blinking blue light that i believe has the v1 firmware
I dumped the slc with de_fuse. And I got this:
ECC stats for NAND page 0x143F4: 0 uncorrectable, 1 corrected

I run the slc in nandbinckeck and got this:
bad HMAC for "/sys/title/00050010/10004009/code/fw.img"
If i compare that file with another one from the internet, or from another nand, there are differences.

If i try to write back the slc i get:
Failed to program page: 0x317C0 up to 0x317FF

How can i insert a file into the slc? The tools i've found only work on the mlc.
 
Last edited by gorgyrip,
  • Like
Reactions: zfreeman

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,358
Trophies
0
Age
28
XP
1,523
Country
Germany
Ah I see the real problem is, that that SLC page is bad. So injecting a fixed one won't help, as it can't be flashed back.
If the firmware is really v1 (or do you mean OS v10?) than thats another problem, because I believe the patches required for defuse only work on later firmwares.

We should be able to load an firmware from SD. @Lazr1026 can help us with the details, as he has actually done it.
Then we can see how far we get. If we don't get a IOSU old enough booted with defuse, to work with the outdated system, I would make a stroopwafel plugin to copy the right version fw.img back. The ISFS driver in IOSU should be smart enough to deal with that bad block.

But first we try to get some IOSU (fw.img) booted and see how far we get with that.
Also make sure you have full backup stored somewhere else.


EDIT: can you post the system.xml, /sys/title/00050010/1000400a/code/app.xml and /sys/title/00050010/10004009/code/app.xml from your slc dump?
 
Last edited by SDIO,

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
Ah I see the real problem is, that that SLC page is bad. So injecting a fixed one won't help, as it can't be flashed back.
If the firmware is really v1 (or do you mean OS v10?) than thats another problem, because I believe the patches required for defuse only work on later firmwares.

We should be able to load an firmware from SD. @Lazr1026 can help us with the details, as he has actually done it.
Then we can see how far we get. If we don't get a IOSU old enough booted with defuse, to work with the outdated system, I would make a stroopwafel plugin to copy the right version fw.img back. The ISFS driver in IOSU should be smart enough to deal with that bad block.

But first we try to get some IOSU (fw.img) booted and see how far we get with that.
Also make sure you have full backup stored somewhere else.
yes, the nand pages are bad. can they be skipped? If i remember correctly, the vwii is ok, so i intend to swap the banks. Also do you know if there's a compatible ic?

Yes, 99% sure it's fw1, because it has the very first version of boot1.

Until now i've only checked fw.bin because that was the only file reported by nandbincheck. But now i've check more files from the folder 10004009 and they don't match at all with the ones from v1005 or v1006
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,358
Trophies
0
Age
28
XP
1,523
Country
Germany
Did you see my last edit? You should be able to see the exact version in the app.xml I think.
Get the fw.img from that version and put it as ios_orig.img on the SD. Then you select the `patch and boot ios_orig.img` orig option in minute and see what happens.

Thanks to @Lazr1026 for giving me the details
 
  • Like
Reactions: gorgyrip

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
Did you see my last edit? You should be able to see the exact version in the app.xml I think.
Get the fw.img from that version and put it as ios_orig.img on the SD. Then you select the `patch and boot ios_orig.img` orig option in minute and see what happens.

Thanks to @Lazr1026 for giving me the details
Sorry, I didn't see your edit.
I think I have figured it out. Everything is corrupted. All the xml files look like this:
Óÿ]q7äU«Ñr€-fþ!½í&hf渨ù×&{-+ó{ðM°ðxå¡7›„£×“»$Kô'Ee+\ñßZ‚ÔèOo§Ž4ѵB°hN™¶RfpP¶êÕô€ŽXê”ï:o€cä'À‹q\{'Y[Ý}ݤN·Í’ñõÁÙíÇš±<XàgÃ7wÇHÛ.žÂ
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,358
Trophies
0
Age
28
XP
1,523
Country
Germany
I requested access, but I only will have a look tomorrow.

In the meantime you could still try to boot the iosu from SD. First the matching version and after that the latest from OSv10
 

Valery0p

Well-Known Member
Member
Joined
Jan 16, 2017
Messages
560
Trophies
0
XP
1,646
Country
Italy
I requested access, but I only will have a look tomorrow.

In the meantime you could still try to boot the iosu from SD. First the matching version and after that the latest from OSv10
That might not work, if I remember correctly from a conversation with Shiny, de_fuse patches the fw to read the otp from the SD, since the real one is not available, and the patch is only for 5.5.x

It might still be worth a shot
 
  • Like
Reactions: gorgyrip

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
I requested access, but I only will have a look tomorrow.

In the meantime you could still try to boot the iosu from SD. First the matching version and after that the latest from OSv10
Sorry about that, link updated.
I've tried both version of OS9 and a few of OS10 so far:
ancast: failed to open patch file ios-orig.patch
Failed to load IOS with patches
Press POWER/Q to continue.

EDIT: If I rename ios.patch to ios_orig. patch, de_fuse complains that the firmware is not 5.5 and it does nothing. If I use fw 5.5 it also hangs.
 
Last edited by gorgyrip,
  • Like
Reactions: Valery0p

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,358
Trophies
0
Age
28
XP
1,523
Country
Germany
I have some good news I think, but I am not sure how good exactly.
I was able to extract your SLC with Wii U NAND Extractor and the xml files looked good, no gibberish.

You have OSv9 v1006 and OSv10 v1099 (the first one).

On OSv9 I saw two errors:
Code:
sys/title/00050010/10004009/code/fw.img
sys/title/00050010/10004009/code/nsysccr.rpl

The OSv10 seems to be fine!

But the system.xml still points to OSv9
Code:
<default_os_id type="hexBinary" length="8">0005001010004009</default_os_id>
Could it be that this was a system update that failed?

My suggestion would be to change the system.xml to OSv10 (000500101000400a) and see what happens.


EDIT: where does it hang?
 
  • Like
Reactions: Valery0p

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
I have some good news I think, but I am not sure how good exactly.
I was able to extract your SLC with Wii U NAND Extractor and the xml files looked good, no gibberish.

You have OSv9 v1006 and OSv10 v1099 (the first one).

On OSv9 I saw two errors:
Code:
sys/title/00050010/10004009/code/fw.img
sys/title/00050010/10004009/code/nsysccr.rpl

The OSv10 seems to be fine!

But the system.xml still points to OSv9
Code:
<default_os_id type="hexBinary" length="8">0005001010004009</default_os_id>
Could it be that this was a system update that failed?

My suggestion would be to change the system.xml to OSv10 (000500101000400a) and see what happens.


EDIT: where does it hang?
Phew.. Glad to hear that! Thank you!
The error was on my side. I have a folder with nandextractor + a nand from a working console. Another folder with nandextractor + the nand from the bad console. Even if I was in the folder with the bad nand, it opened the good nand + otp from the bad nand and I didn't noticed :)

But how do I insert system.xml back into the nand?

I attached a pic with defuse hanging. The same happens if i use the fw for 5.5 (just it doesn't complain about not being 5.5)
 

Attachments

  • 20230704_233825.jpg
    20230704_233825.jpg
    311 KB · Views: 22

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
You can use the fileInjector from here: https://github.com/GaryOderNichts/wiiuqt But you have to build it yourself, gary didn't release binarys. I can attach you the linux binary but for Windows you have to see yourself.
Thank you. Sadly, i don't know how to compile it for windows and i don have linux, neither know how to use it.
Post automatically merged:

You can use the fileInjector from here: https://github.com/GaryOderNichts/wiiuqt But you have to build it yourself, gary didn't release binarys. I can attach you the linux binary but for Windows you have to see yourself.
I've just tried it. Now the led stays on, it doesn't blink anymore. Defuse removed and i have no signal on hdmi. I've alos tried component and composite and still no signal.
 
Last edited by gorgyrip,

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,358
Trophies
0
Age
28
XP
1,523
Country
Germany
Can you try defuse again and look at the serial console from the pico? I think on windows you can use putty for that.
 

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
Can you try defuse again and look at the serial console from the pico? I think on windows you can use putty for that.
Yes, i have putty. I assume you mean this:
OS9 v1006 as ios_orig
=====================
ancast: reading 0x77b200 bytes from ios_orig.img
ancast: ...00000000 -> 01000000
ancast: ...00100000 -> 01100000
ancast: ...00200000 -> 01200000
ancast: ...00300000 -> 01300000
ancast: ...00400000 -> 01400000
ancast: ...00500000 -> 01500000
ancast: ...00600000 -> 01600000
ancast: ...00700000 -> 01700000
ancast: done reading
ancast: decrypting ios_orig.img...
ancast: fini
ancast: IOS image might not be 5.5!
GPU clocked at: 544.999877MHz
Unmounting SLC...
Shutting down MLC...
sdhc_bus_power(0x0)
Shutting down SD card...
sdhc_bus_power(0x0)
Shutting down interrupts...
Shutting down caches and MMU...
Vectoring to 0x01000300...
Searching for OTP store in patch...
OTP store at: 000010c4


OS10 v1099 as ios_orig
======================
ancast: reading 0x81e200 bytes from ios_orig.img
ancast: ...00000000 -> 01000000
ancast: ...00100000 -> 01100000
ancast: ...00200000 -> 01200000
ancast: ...00300000 -> 01300000
ancast: ...00400000 -> 01400000
ancast: ...00500000 -> 01500000
ancast: ...00600000 -> 01600000
ancast: ...00700000 -> 01700000
ancast: ...00800000 -> 01800000
ancast: done reading
ancast: decrypting ios_orig.img...
ancast: fini
ancast: IOS image might not be 5.5!
GPU clocked at: 544.999877MHz
Unmounting SLC...
Shutting down MLC...
sdhc_bus_power(0x0)
Shutting down SD card...
sdhc_bus_power(0x0)
Shutting down interrupts...
Shutting down caches and MMU...
Vectoring to 0x01000300...
Searching for OTP store in patch...
OTP store at: 000010c4


when the console is powered on:
===============================
[pico] Changed state: WIIU_STATE_NEEDS_DEFUSE -> WIIU_STATE_DEFUSED
[pico] Changed state: WIIU_STATE_DEFUSED -> WIIU_STATE_MONITORING
02020301CF%10(MEM2MEM0PRSH]]01]]028480efa282d9010210010210]]04f00f[Pico] Switching to text mode...
cafff00fcafaU▒U▒U▒U▒f00fcafeGPU TV addr: 17500001
GPU DRC addr: 00000000
minute loading
minute was loaded from boot1 context!
Initializing exceptions...
Configuring caches and MMU...
MEM: cleaning up
MEM: unprotecting memory
MEM: mapping sections
MEM: enabling caches
MEM: enabling MMU
MEM: configuring heap
MEM: init done
Interrupts initialized
prsh: Header at 10005a54, PRST at 10007ff0, 1 entries (32 capacity):
0: boot_info 0x58 10008000
crypto support initialized
BSP version: 0x25100028
Board type: CF (0x4346)
Board revision: 0xb
DDR props: size=2GiB (0x0800) speed=0x0002 vendor=U! (0x5521)

Initializing SD card...
sdhc: SDHC 1.0, 48 MHz base clock
sdhc_bus_power(0x300000)
sdhc_bus_clock(25000, 0)
sdhc_bus_width(1)
CID: B200FDF773221030303030304D531B00
CID: mid=1b name='SM00000' prv=16.2 psn=0273f7fd mdt=2/2011
CSD: 00800EFFDFDBF6BA835A5B32FF7F0000
taac=127 nsac=255 read_bl_len=10 c_size=3819 c_size_mult=7 card size=2002780160 bytes
sdcard_select: resp=700
sdhc_bus_width(4)
sdhc_bus_clock(25000, 0)
Mounting SD card...
crypto: ~0x07d bytes of OTP loaded; JTAG is disabled (000000e1)
f8 b1 8e c3 fe 26 b9 b1 1a d4 a4 ed d3 b7 a0 31
11 9a 79 f8 eb e4 2a 22 5e 85 93 e4 48 d9 c5 45
73 81 aa f7 24 26 2a 3d 00 1f e4 84 6b 9c fc c0
9a e3 fa 65 6f c3 5e dd dd 8f 1b 75 12 d2 ac d4
65 9d cc 7e fc 72 d6 60 c9 7e 3a d3 bc 56 e7 65
11 3c dd d6 1d 52 84 1e 69 73 b5 1d f5 a2 9a 14
b0 01 32 bd f8 7d 5f e7 31 c4 8c ef 61 19 ec a2
7a 30 79 f8 eb a8 f8 72 53 f9 00 00 00
Console is de_Fused! Loading sdmc:/otp.bin...
minini: Failed to open `sdmc:/minute/minute.ini`!
Initializing MLC...
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc_bus_power(0x40000000)
mlc: powerup failed for card
sdhc: SDHC 1.0, 48 MHz base clock
sdhc_bus_power(0x40300000)
sdhc_bus_clock(400, 0)
sdhc_bus_width(1)
CID: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00
resetting due to error interrupt
timeout dump: error_intr: 0x0 intr: 0x2
mlc: SD_SEND_RCA failed with 116
sdhc_bus_width(1)
sdhc_bus_clock(0, 0)
sdhc_bus_power(0x0)
sdhc_bus_power(0x40300000)
sdhc_bus_clock(400, 0)
sdhc_bus_width(1)
CID: 8FB7B23C005C2058494E59484A019000
CSD: 00408AFFFFFFFFFF03590F32014FD000
sdhc_bus_clock(25000, 0)
mlc_select: resp=740
sdhc_bus_width(4)
mlc: card_type=0xf sec_count=0x3b34000
sdhc_bus_clock(52000, 1)
Mounting SLC...
Showing menu...
Post automatically merged:

I think i've managed to compile fileinjector, but i'm having issues.

C:\debug>fileinjector slc.bin system.xml sys\config
Writing file
NandBin::ItemFromPath -> invalid path
!item "sys\\config"
"Failed to write file"
 
Last edited by gorgyrip,

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
Can you try getting PuTTY output from booting a 5.5.X fw.img as "ios_orig.img"?
I've just tried with OSv10 15848
ancast: reading 0xdfd200 bytes from ios_orig.img
ancast: ...00000000 -> 01000000
ancast: ...00100000 -> 01100000
ancast: ...00200000 -> 01200000
ancast: ...00300000 -> 01300000
ancast: ...00400000 -> 01400000
ancast: ...00500000 -> 01500000
ancast: ...00600000 -> 01600000
ancast: ...00700000 -> 01700000
ancast: ...00800000 -> 01800000
ancast: ...00900000 -> 01900000
ancast: ...00a00000 -> 01a00000
ancast: ...00b00000 -> 01b00000
ancast: ...00c00000 -> 01c00000
ancast: ...00d00000 -> 01d00000
ancast: done reading
ancast: decrypting ios_orig.img...
ancast: fini
ancast: IOS image might not be 5.5!
GPU clocked at: 544.999877MHz
Unmounting SLC...
Shutting down MLC...
sdhc_bus_power(0x0)
Shutting down SD card...
sdhc_bus_power(0x0)
Shutting down interrupts...
Shutting down caches and MMU...
Vectoring to 0x01000300...
Searching for OTP store in patch...
OTP store at: 000010c4
region starting at virtual address 0xffff0000:
size = 0x00010000
paddr = 0xffff0000
domain = 0x00000000
attributes: Kernel-Only, cached
region starting at virtual address 0x08120000:
size = 0x000a0000
paddr = 0x08120000
domain = 0x00000000
attributes: Kernel-Only, cached
region starting at virtual address 0x1d000000:
size = 0x02b00000
paddr = 0x1d000000
domain = 0x00000000
attributes: Read/Write, cached
region starting at virtual address 0x08000000:
size = 0x00100000
paddr = 0x08000000
domain = 0x0000000f
attributes: Read/Write, cached
region starting at virtual address 0x08100000:
size = 0x00020000
paddr = 0x08100000
domain = 0x00000000
attributes: Read/Write, cached
region starting at virtual address 0x00000000:
size = 0x00001000
paddr = 0x00000000
domain = 0x00000000
attributes: Kernel-Only, cached
region starting at virtual address 0x00001000:
size = 0x01fff000
paddr = 0x00001000
domain = 0x00000000
attributes: Read/Write, cached
region starting at virtual address 0x14000000:
size = 0x09000000
paddr = 0x14000000
domain = 0x00000000
attributes: Read/Write, cached
region starting at virtual address 0x28000000:
size = 0xa8000000
paddr = 0x28000000
domain = 0x00000000
attributes: Read/Write, cached
region starting at virtual address 0x28000000:
size = 0xa8000000
paddr = 0x28000000
domain = 0x00000000
attributes: Read/Write, cached
IOS_KERNEL: Built 02/04/21 16:05:36, SRAM Utilization 91%, MEM Utilization 90%.
region starting at virtual address 0x05000000:
size = 0x0005b000
paddr = 0x081c0000
domain = 0x00000001
attributes: Read-Only, cached
region starting at virtual address 0x05060000:
size = 0x00010000
paddr = 0x08220000
domain = 0x00000001
attributes: Read-Only, cached
region starting at virtual address 0x05070000:
size = 0x00004000
paddr = 0x08230000
domain = 0x00000001
attributes: Read/Write, cached
region starting at virtual address 0x05074000:
size = 0x0004c000
paddr = 0x08234000
domain = 0x00000001
attributes: Read/Write, cached
region starting at virtual address 0x04000000:
size = 0x00018000
paddr = 0x08280000
domain = 0x00000003
attributes: Read-Only, cached
region starting at virtual address 0x04020000:
size = 0x00004000
paddr = 0x082a0000
domain = 0x00000003
attributes: Read-Only, cached
region starting at virtual address 0x04024000:
size = 0x00001000
paddr = 0x082a4000
domain = 0x00000003
attributes: Read/Write, cached
region starting at virtual address 0x04025000:
size = 0x0000a000
paddr = 0x082a5000
domain = 0x00000003
attributes: Read/Write, cached
region starting at virtual address 0xe7000000:
size = 0x00001000
paddr = 0x082c0000
domain = 0x00000002
attributes: Read/Write, cached
region starting at virtual address 0x10000000:
size = 0x00100000
paddr = 0x10000000
domain = 0x00000001
attributes: Read/Write, cached
region starting at virtual address 0x10100000:
size = 0x00032000
paddr = 0x10100000
domain = 0x00000004
attributes: Read-Only, cached
region starting at virtual address 0x10140000:
size = 0x00005000
paddr = 0x10140000
domain = 0x00000004
attributes: Read-Only, cached
region starting at virtual address 0x10145000:
size = 0x00001000
paddr = 0x10145000
domain = 0x00000004
attributes: Read/Write, cached
region starting at virtual address 0x10146000:
size = 0x00380000
paddr = 0x10146000
domain = 0x00000004
attributes: Read/Write, cached
region starting at virtual address 0x10700000:
size = 0x000f9000
paddr = 0x10700000
domain = 0x00000005
attributes: Read-Only, cached
region starting at virtual address 0x10800000:
size = 0x00034000
paddr = 0x10800000
domain = 0x00000005
attributes: Read-Only, cached
region starting at virtual address 0x10834000:
size = 0x00001000
paddr = 0x10834000
domain = 0x00000005
attributes: Read/Write, cached
region starting at virtual address 0x10835000:
size = 0x01647000
paddr = 0x10835000
domain = 0x00000005
attributes: Read/Write, cached
region starting at virtual address 0x11f00000:
size = 0x00086000
paddr = 0x11f00000
domain = 0x00000006
attributes: Read-Only, cached
region starting at virtual address 0xd1f00000:
size = 0x00086000
paddr = 0x11f00000
domain = 0x00000006
attributes: Read-Only, un-cached
region starting at virtual address 0x11fc0000:
size = 0x00015000
paddr = 0x11fc0000
domain = 0x00000006
attributes: Read-Only, cached
region starting at virtual address 0xd1fc0000:
size = 0x00015000
paddr = 0x11fc0000
domain = 0x00000006
attributes: Read-Only, un-cached
region starting at virtual address 0x11fd5000:
size = 0x00024000
paddr = 0x11fd5000
domain = 0x00000006
attributes: Read/Write, cached
region starting at virtual address 0xd1fd5000:
size = 0x00024000
paddr = 0x11fd5000
domain = 0x00000006
attributes: Read/Write, un-cached
region starting at virtual address 0x11ff9000:
size = 0x00160000
paddr = 0x11ff9000
domain = 0x00000006
attributes: Read/Write, cached
region starting at virtual address 0xd1ff9000:
size = 0x00160000
paddr = 0x11ff9000
domain = 0x00000006
attributes: Read/Write, un-cached
region starting at virtual address 0x12300000:
size = 0x00132000
paddr = 0x12300000
domain = 0x00000007
attributes: Read-Only, cached
region starting at virtual address 0x12440000:
size = 0x00029000
paddr = 0x12440000
domain = 0x00000007
attributes: Read-Only, cached
region starting at virtual address 0x12469000:
size = 0x00001000
paddr = 0x12469000
domain = 0x00000007
attributes: Read/Write, cached
region starting at virtual address 0x1246a000:
size = 0x0005c000
paddr = 0x1246a000
domain = 0x00000007
attributes: Read/Write, cached
region starting at virtual address 0x124c6000:
size = 0x003c8000
paddr = 0x124c6000
domain = 0x00000007
attributes: Read/Write, cached
region starting at virtual address 0xe0000000:
size = 0x000dc000
paddr = 0x12900000
domain = 0x00000008
attributes: Read-Only, cached
region starting at virtual address 0xe0100000:
size = 0x00021000
paddr = 0x12a00000
domain = 0x00000008
attributes: Read-Only, cached
region starting at virtual address 0xe0121000:
size = 0x00001000
paddr = 0x12a21000
domain = 0x00000008
attributes: Read/Write, cached
region starting at virtual address 0xe0122000:
size = 0x00001000
paddr = 0x12a22000
domain = 0x00000008
attributes: Read/Write, cached
region starting at virtual address 0xe0123000:
size = 0x0013f000
paddr = 0x12a23000
domain = 0x00000008
attributes: Read/Write, cached
region starting at virtual address 0xe1000000:
size = 0x00091000
paddr = 0x12bc0000
domain = 0x00000009
attributes: Read-Only, cached
region starting at virtual address 0xe10c0000:
size = 0x00022000
paddr = 0x12c80000
domain = 0x00000009
attributes: Read-Only, cached
region starting at virtual address 0xe10e2000:
size = 0x00002000
paddr = 0x12ca2000
domain = 0x00000009
attributes: Read/Write, cached
region starting at virtual address 0xe10e4000:
size = 0x00205000
paddr = 0x12ca4000
domain = 0x00000009
attributes: Read/Write, cached
region starting at virtual address 0xe2000000:
size = 0x00266000
paddr = 0x12ec0000
domain = 0x0000000b
attributes: Read-Only, cached
region starting at virtual address 0xe2280000:
size = 0x00049000
paddr = 0x13140000
domain = 0x0000000b
attributes: Read-Only, cached
region starting at virtual address 0xe22c9000:
size = 0x00001000
paddr = 0x13189000
domain = 0x0000000b
attributes: Read/Write, cached
region starting at virtual address 0xe22ca000:
size = 0x00001000
paddr = 0x1318a000
domain = 0x0000000b
attributes: Read/Write, cached
region starting at virtual address 0xe22cb000:
size = 0x003fe000
paddr = 0x1318b000
domain = 0x0000000b
attributes: Read/Write, cached
region starting at virtual address 0xe3000000:
size = 0x0016c000
paddr = 0x13640000
domain = 0x0000000c
attributes: Read-Only, cached
region starting at virtual address 0xe3180000:
size = 0x0002d000
paddr = 0x137c0000
domain = 0x0000000c
attributes: Read-Only, cached
region starting at virtual address 0xe31ad000:
size = 0x00001000
paddr = 0x137ed000
domain = 0x0000000c
attributes: Read/Write, cached
region starting at virtual address 0xe31ae000:
size = 0x00001000
paddr = 0x137ee000
domain = 0x0000000c
attributes: Read/Write, cached
region starting at virtual address 0xe31af000:
size = 0x0014e000
paddr = 0x137ef000
domain = 0x0000000c
attributes: Read/Write, cached
region starting at virtual address 0xe4000000:
size = 0x0001a000
paddr = 0x13a40000
domain = 0x0000000d
attributes: Read-Only, cached
region starting at virtual address 0xe4040000:
size = 0x00006000
paddr = 0x13a80000
domain = 0x0000000d
attributes: Read-Only, cached
region starting at virtual address 0xe4046000:
size = 0x00001000
paddr = 0x13a86000
domain = 0x0000000d
attributes: Read/Write, cached
region starting at virtual address 0xe4047000:
size = 0x00112000
paddr = 0x13a87000
domain = 0x0000000d
attributes: Read/Write, cached
region starting at virtual address 0xe5000000:
size = 0x00010000
paddr = 0x13c00000
domain = 0x0000000a
attributes: Read-Only, cached
region starting at virtual address 0xe5040000:
size = 0x00004000
paddr = 0x13c40000
domain = 0x0000000a
attributes: Read-Only, cached
region starting at virtual address 0xe5044000:
size = 0x00001000
paddr = 0x13c44000
domain = 0x0000000a
attributes: Read/Write, cached
region starting at virtual address 0xe5045000:
size = 0x0002a000
paddr = 0x13c45000
domain = 0x0000000a
attributes: Read/Write, cached
region starting at virtual address 0xe6000000:
size = 0x00011000
paddr = 0x13cc0000
domain = 0x00000002
attributes: Read-Only, cached
region starting at virtual address 0xe6040000:
size = 0x00002000
paddr = 0x13d00000
domain = 0x00000002
attributes: Read-Only, cached
region starting at virtual address 0xe6042000:
size = 0x00005000
paddr = 0x13d02000
domain = 0x00000002
attributes: Read/Write, cached
region starting at virtual address 0xe6047000:
size = 0x00002000
paddr = 0x13d07000
domain = 0x00000002
attributes: Read/Write, cached
region starting at virtual address 0x05100000:
size = 0x00019000
paddr = 0x13d80000
domain = 0x00000001
attributes: Read-Only, cached
region starting at virtual address 0x1fb00000:
size = 0x00300000
paddr = 0x1fb00000
domain = 0x00000007
attributes: Read/Write, cached
region starting at virtual address 0x1fe00000:
size = 0x00015000
paddr = 0x1fe00000
domain = 0x00000001
attributes: Read/Write, cached
region starting at virtual address 0x1fe40000:
size = 0x001c0000
paddr = 0x1fe40000
domain = 0x00000001
attributes: Read/Write, cached
region starting at virtual address 0x20000000:
size = 0x08000000
paddr = 0x20000000
domain = 0x00000005
attributes: Read/Write, cached
region starting at virtual address 0xeff00000:
size = 0x00008000
paddr = 0xfff00000
domain = 0x00000001
attributes: Read/Write, cached
Creating main() thread for IOS-BSP:
priority=125 stackSize=4096 stackPtr=0xe7000000 entry=0xe600f848memPermMask=0x00100000
IOS-BSP: Built 02/04/21 16:02:14, Image Utilization 37%.
Creating main() thread for IOS-MCP:
priority=124 stackSize=8192 stackPtr=0x050ba4a0 entry=0x05056718memPermMask=0x000c0030
Creating main() thread for IOS-CRYPTO:
priority=123 stackSize=4096 stackPtr=0x04028628 entry=0x04015ea4memPermMask=0x000c0030
Creating main() thread for IOS-USB:
priority=107 stackSize=16384 stackPtr=0x104b92c8 entry=0x1012e9e8memPermMask=0x00038600
Creating main() thread for IOS-FS:
priority=85 stackSize=16384 stackPtr=0x1114117c entry=0x107f6830memPermMask=0x001c5870
Creating main() thread for IOS-PAD:
priority=117 stackSize=8192 stackPtr=0x1214ab4c entry=0x11f82d94memPermMask=0x00008180
Creating main() thread for IOS-NET:
priority=80 stackSize=16384 stackPtr=0x12804498 entry=0x123e4174memPermMask=0x00002000
Creating main() thread for IOS-ACP:
priority=50 stackSize=16384 stackPtr=0xe0125390 entry=0xe00d8290memPermMask=0x00000000
Creating main() thread for IOS-NSEC:
priority=50 stackSize=4096 stackPtr=0xe12e71a4 entry=0xe108e930memPermMask=0x00000000
Creating main() thread for IOS-AUXIL:
priority=70 stackSize=16384 stackPtr=0xe506a900 entry=0xe500d720memPermMask=0x00000000
Creating main() thread for IOS-NIM-BOSS:
priority=50 stackSize=16384 stackPtr=0xe22cb000 entry=0xe22602fcmemPermMask=0x00000000
Creating main() thread for IOS-FPD:
priority=50 stackSize=16384 stackPtr=0xe31af000 entry=0xe3166b34memPermMask=0x00000000
Creating main() thread for IOS-TEST:
priority=75 stackSize=8192 stackPtr=0xe415623c entry=0xe40168a4memPermMask=0x00000000
IOS-CRYPTO: Built 02/04/21 16:02:14, Image Utilization 72%.
opening /dev/net/ifmgr/ncl...
CRYPTO Open, clientPid=1 nodeId 00000000 titleId 0000000000000000 perm=0xffffffff
IOSC Initialize -- IOSC library build time 09/27/12 19:28:40
IOS-PAD: Built 02/04/21 16:02:14, Image Utilization 58%.
IOS-USB: Built 02/04/21 16:02:14, Image Utilization 62%.
00:00:00:340: MMC(0): initializing Controller 0, Slot 0 base 0x0D070000
00:00:00:345: MMC(3): initializing Controller 2, Slot 0 base 0x0D100000
00:00:00:351: MMC(4): initializing Controller 3, Slot 0 base 0x0D110000
IOS-NET: Built 02/04/21 16:02:14, Image Utilization 92%.
USB Trace: Activating root hubs @ uptime 0.421 s with options 0x40000.
00:00:00:427: USB Trace: Activating root hubs @ uptime 0.421 s with options 0x40000.
UHS0 Trace: DevFsm(EHCI-0/L0/P0): Creating device, speed=HIGH.
00:00:00:448: UHS0 Trace: DevFsm(EHCI-0/L0/P0): Creating device, speed=HIGH.
UHS0 Trace: DevFsm(OHCI-0:0/L0/P0): Creating device, speed=FULL.
00:00:00:461: UHS0 Trace: DevFsm(OHCI-0:0/L0/P0): Creating device, speed=FULL.
USB Info: UhsServerAddHc 0 OK.
00:00:00:470: USB Info: UhsServerAddHc 0 OK.
UHS0 Trace: DevFsm(EHCI-1/L0/P0): Creating device, speed=HIGH.
00:00:00:487: UHS0 Trace: DevFsm(EHCI-1/L0/P0): Creating device, speed=HIGH.
UHS0 Trace: DevFsm(OHCI-1:0/L0/P0): Creating device, speed=FULL.
00:00:00:500: UHS0 Trace: DevFsm(OHCI-1:0/L0/P0): Creating device, speed=FULL.
USB Info: UhsServerAddHc 1 OK.
00:00:00:509: USB Info: UhsServerAddHc 1 OK.
IOS-TEST: Built 02/04/21 16:02:14, Image Utilization 76%.
TEST Info: localProcessHeap OK.
TEST Info: crossProcessHeap OK.
00:00:00:527: TEST Info: crossProcessHeap OK.
UHS0 Trace: Powering on root hub group 0.
00:00:00:534: UHS0 Trace: Powering on root hub group 0.
IOS-AUXIL: Built 02/04/21 16:02:14, Image Utilization 57%.
AUXIL Info: localProcessHeap OK.
AUXIL Info: crossProcessHeap OK.
00:00:00:549: AUXIL Info: crossProcessHeap OK.
UHS0 Trace: Powering on root hub group 1.
00:00:00:556: UHS0 Trace: Powering on root hub group 1.
00:00:00:561: AHCI_MGR Trace: Turning on drive power.
00:00:00:566: AHCI_MGR Trace: Turning on drive power.
IOS-ACP: Built 00:00:00:575: AHCI_MGR Trace: Initializing phy.
00:00:00:579: AHCI_MGR Trace: Initializing phy.
00:00:00:583: AHCI_DRV Trace: Initiating cold open.
00:00:00:587: AHCI_DRV Trace: Initiating cold open.
00:00:00:591: AHCI_DRV Trace: Resetting HBA.
00:00:00:595: AHCI_DRV Trace: Resetting HBA.
AUXIL Info: Net OK.
00:00:00:602: AUXIL Info: Net OK.
IOS-NSEC: Built 02/04/21 16:02:14, Image UtilIOS-NIM-BOSS: Built 02/04/21 16:02:14, Image Utilization 90%.
IOS-FPD: Built 02/04/21 16:02:14, Image Utilization 74%.
02/04/21 16:02:14, Image Utilization 86%.
ization 96%.
act_main.cpp,Start,17400:00:00:649: AHCI_DRV Trace: HBA Reset OK.
00:00:00:652: AHCI_DRV Trace: HBA Reset OK.
CRYPTO Open, clientPid=5 nodeId 00000000 titleId 00000000100000f1 perm=0xffffffff
00:00:00:760: ISFS: FAT INFO (ch WUP): slot 3 / seq 7557 (Each FAT slot has been updated 118 times in avr)
00:00:00:768: ISFS: fs_fat.c(545)FAT INFO (ch WUP): slot 3 / seq 7557 (Each FAT slot has been updated 118 times in avr)
00:00:00:778: FSA: [uptime 0.778 s]: Attached volume to slc01 (isfs): Capacity 511 MB, 262016 logical blocks of size 2048 B.
00:00:00:873: ISFS: FAT INFO (ch RVL Compat): slot 15 / seq 6753 (Each FAT slot has been updated 422 times in avr)
00:00:00:883: ISFS: fs_fat.c(545)FAT INFO (ch RVL Compat): slot 15 / seq 6753 (Each FAT slot has been updated 422 times in avr)
00:00:00:893: FSA: [uptime 0.893 s]: Attached volume to slccmpt01 (isfs): Capacity 511 MB, 261632 logical blocks of size 2048 B.
00:00:00:909: SCFM:Start init. BUILD_TIME:[16:02:03]
00:00:00:916: SCFM:FSAInit
00:00:00:919: SCFM:AddClient
00:00:00:922: SCFM:scfmMountSlc
00:00:00:924: SCFM:scfmLoad
00:00:00:927: SCFM:Done init.
00:00:00:930: PCFS: Disabled because we are in PROD mode.
00:00:00:935: MCP: booting from NAND
00:00:00:938: MCP: Boot PM flags - PON_COLDBOOT
00:00:00:960: MCP: Cafe OS SDK Version 2.13.01 Build 69088 Branch sdk_2_13
00:00:00:966: MCP: Booting on Espresso (0x0000700100000201), Latte (0x25100028), RTC (0x01)
00:00:00:973: MCP: Platform - boardType(CF), boardRevision(11), devicePresence(0x00000000), sataDevice(3), consoleType(1)
00:00:00:985: ISFS: FAT block entries check start
00:00:00:989: ISFS: fs_ops.c(2215)FAT block entries check start
00:00:00:998: ISFS: FAT block entries check finished.
00:00:01:003: ISFS: fs_ops.c(2292)FAT block entries check finished.
00:00:01:022: FSA: [uptime 1.022 s]: Attached volume to mlc01 (wfs): Capacity 29760 MB, 60948480 logical blocks of size 512 B.
00:00:01:045: FSA: [uptime 1.044 s]: Attached volume to sdcard01 (fat): Capacity 1910 MB, 3911680 logical blocks of size 512 B.
00:00:01:057: FSA: [uptime 1.057 s]: Attached volume to ramdisk01 (raw): Capacity 127 MB, 131070 logical blocks of size 1024 B.
00:00:01:067: MCP: Formatting Device ramdisk to wfs
00:00:01:215: FSA: [uptime 1.215 s]: Attached volume to ramdisk01 (wfs): Capacity 127 MB, 131070 logical blocks of size 1024 B.
00:00:01:225: MCP: Format Complete
00:00:01:349: ISFS: FAT block entries check start
00:00:01:353: ISFS: fs_ops.c(2215)FAT block entries check start
00:00:01:362: ISFS: FAT block entries check finished.
00:00:01:366: ISFS: fs_ops.c(2292)FAT block entries check finished.
00:00:01:483: [ES] checkOwnedTitleUpdateFlags: no delete in progress
00:00:01:489: [ES] checkOwnedTitleUpdateFlags: no import in progress
00:00:01:505: MCP: File loading from ramdisk cache is enabled
00:00:01:518: MCP: Master title 0005001010040200 os 000500101000400a from mlc01 flags 0004
2012-10-11 11:48:43
Cafe OS SDK Version 2.13.01 Build 69088 Branch sdk_2_13
Espresso: 0x0000700100000201
Latte: 0x0000409f
System mode: 0x100000
Boot flags: 0x10000
Security Level: 0x1e
Key Type: 0xfffffffc
Prod Version: 0x5
Serial: 102280812
Model: WUP-101(03)
Prod Area: 0x4
Game Area: 0x4
5GHz Code: 0x18
00:00:01:564: MCP: no valid title list found, rebuilding...
00:00:01:574: MCP: os version 10 NDEBUG (0x000500101000400a)
00:00:01:580: MCP: FSA volume on device /dev/mlc01 (wfs) attached @ uptime 1.580 s.
00:00:01:603: MCP: found master title 5001010040200 on mlc01 at 1.603 s
00:00:01:615: MCP: FSA volume on device /dev/ramdisk01 (wfs) attached @ uptime 1.614 s.
00:00:01:622: MCP: Titles scanned (dev_state 0006) on device /dev/ramdisk01 (wfs) @ uptime 1.622 s.
00:00:01:630: MCP: FSA volume on device /dev/sdcard01 (fat) attached @ uptime 1.630 s.
00:00:01:637: MCP: Titles scanned (dev_state 0006) on device /dev/sdcard01 (fat) @ uptime 1.637 s.
00:00:01:645: MCP: FSA volume on device /dev/slc01 (isfs) attached @ uptime 1.645 s.
00:00:01:652: MCP: FSA volume on device /dev/slccmpt01 (isfs) attached @ uptime 1.652 s.
00:00:01:659: MCP: Titles scanned (dev_state 0006) on device /dev/slccmpt01 (isfs) @ uptime 1.659 s.
00:00:01:864: ISFS: fs_ops.c(3733)Can not change the owner Id of a non-empty file
00:00:01:871: ISFS: fs_ops.c(3733) Can not change the owner Id of a non-empty file
00:00:01:878: ISFS: fs_ops.c(6719)Could not set attribute, rc=-524312
00:00:01:883: ISFS: fs_ops.c(6719) Could not set attribute, rc=-524312
00:00:01:908: MCP: Titles scanned (dev_state 000e) on device /dev/slc01 (isfs) @ uptime 1.908 s.
00:00:02:195: MCP: ECO mode is disabled
00:00:02:198: [+-* DK is ready for console input *-+]
00:00:02:202: MCP: syslog mask is set to 0xffffffff
00:00:02:212: W2C: Does not need W2C-reflection
00:00:02:250: MCP: Titles scanned (dev_state 0004) on device /dev/mlc01 (wfs) @ uptime 2.250 s.
$IOSVersion: OHCI1: 02/04/21 16:01:32 $
UHS1 Trace: DevFsm(EHCI-2/L0/P0): Creating device, speed=HIGH.
00:00:02:635: UHS1 Trace: DevFsm(EHCI-2/L0/P0): Creating device, speed=HIGH.
UHS1 Trace: DevFsm(OHCI-2:0/L0/P0): Creating device, speed=FULL.
00:00:02:648: UHS1 Trace: DevFsm(OHCI-2:0/L0/P0): Creating device, speed=FULL.
00:00:02:654: CCR_MAIN: activating root hub.
CRYPTO Open, clientPid=1 nodeId 00000000 titleId 0000000000000000 perm=0xffffffff
00:00:02:851: MCP: Titles scanned (dev_state 000c) on device /dev/mlc01 (wfs) @ uptime 2.851 s.
00:00:02:860: MCP: Titles scanned (dev_state 0006) on device /dev/mlc01 (wfs) @ uptime 2.860 s.
00:00:02:874: FS_MAIN: UMS Server Created.
AUXIL Info: resumed.
00:00:02:882: AUXIL Info: resumed.
[ACP]INFO:mxmlAcpPortInitialize:81: Create local heap 35 for mxml.
Dongle Host Driver, version 5.91.153.64
IOPOS board:11 asic:21/cafe0050 clk:248625000/1942382
Host Controller version 1.0, Vendor Revision: 0x00
sdstd_start_clock:now, divided clk is: 24000000 Hz
sdstd_client_init:SDHOST3-legacy
High-speed clocking mode disabled.
sdstd_start_clock:now, divided clk is: 24000000 Hz
sd_map_dma: Mapped DMA Buffer 4095bytes @Virt/phys: 0x1280b000/0x1280b000
sd_map_dma: Mapped ADMA2 Descriptor Buffer 4095bytes @Virt/phys: 0x1280c000/0x1280c000
Unknown DMA Descriptor Table Format.
DHD: dongle ram size is set to 245760(orig 245760)
UHS1 Trace: DevFsm(EHCI-2/L1/P1): Creating device, speed=HIGH.
00:00:02:968: UHS1 Trace: DevFsm(EHCI-2/L1/P1): Creating device, speed=HIGH.
UHS1 Trace: DevFsm: There are now a total of 1 connected devices.
00:00:02:979: UHS1 Trace: DevFsm: There are now a total of 1 connected devices.
UHS1 Trace: CltIfFsm(V057e|P0341|IF0): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.027 s.
00:00:03:035: UHS1 Trace: CltIfFsm(V057e|P0341|IF0): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.027 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF1): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.045 s.
00:00:03:053: UHS1 Trace: CltIfFsm(V057e|P0341|IF1): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.045 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF2): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.063 s.
00:00:03:071: UHS1 Trace: CltIfFsm(V057e|P0341|IF2): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.063 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF3): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.080 s.
00:00:03:089: UHS1 Trace: CltIfFsm(V057e|P0341|IF3): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.080 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF4): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.098 s.
00:00:03:107: UHS1 Trace: CltIfFsm(V057e|P0341|IF4): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.098 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF5): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.116 s.
00:00:03:124: UHS1 Trace: CltIfFsm(V057e|P0341|IF5): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.116 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF6): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.134 s.
00:00:03:142: UHS1 Trace: CltIfFsm(V057e|P0341|IF6): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.134 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF7): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.152 s.
00:00:03:160: UHS1 Trace: CltIfFsm(V057e|P0341|IF7): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.152 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF8): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.170 s.
00:00:03:178: UHS1 Trace: CltIfFsm(V057e|P0341|IF8): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.170 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF9): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.187 s.
00:00:03:196: UHS1 Trace: CltIfFsm(V057e|P0341|IF9): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.187 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF10): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.205 s.
00:00:03:214: UHS1 Trace: CltIfFsm(V057e|P0341|IF10): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.205 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF11): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.223 s.
00:00:03:232: UHS1 Trace: CltIfFsm(V057e|P0341|IF11): Device EHCI-2/L1/P1/A01 entering probing state @ uptime 3.223 s.
UHS1 Trace: CltIfFsm(V057e|P0341|IF0): Acquired by client in pid 6.
00:00:03:247: UHS1 Trace: CltIfFsm(V057e|P0341|IF0): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF0): Enable endpoints 0x00080000.
00:00:03:259: UHS1 Trace: CltIfFsm(V057e|P0341|IF0): Enable endpoints 0x00080000.
00:00:03:306: __ccr_hid_attach_add_interface: idx 0 ep 3
UHS1 Trace: CltIfFsm(V057e|P0341|IF1): Acquired by client in pid 6.
00:00:03:316: UHS1 Trace: CltIfFsm(V057e|P0341|IF1): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF1): Enable endpoints 0x00100000.
00:00:03:328: UHS1 Trace: CltIfFsm(V057e|P0341|IF1): Enable endpoints 0x00100000.
00:00:03:375: __ccr_hid_attach_add_interface: idx 1 ep 4
UHS1 Trace: CltIfFsm(V057e|P0341|IF2): Acquired by client in pid 6.
00:00:03:386: UHS1 Trace: CltIfFsm(V057e|P0341|IF2): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF3): Acquired by client in pid 6.
00:00:03:398: UHS1 Trace: CltIfFsm(V057e|P0341|IF3): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF3): Activating bAlternateSetting 0.
00:00:03:410: UHS1 Trace: CltIfFsm(V057e|P0341|IF3): Activating bAlternateSetting 0.
OHCI1 NOT READYUHS1 Trace: CltIfFsm(V057e|P0341|IF4): Acquired by client in pid 6.
00:00:03:425: UHS1 Trace: CltIfFsm(V057e|P0341|IF4): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF5): Acquired by client in pid 6.
00:00:03:437: UHS1 Trace: CltIfFsm(V057e|P0341|IF5): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF5): Activating bAlternateSetting 0.
00:00:03:450: UHS1 Trace: CltIfFsm(V057e|P0341|IF5): Activating bAlternateSetting 0.
: waiting for OUHS1 Trace: CltIfFsm(V057e|P0341|IF7): Acquired by client in pid 6.
00:00:03:464: UHS1 Trace: CltIfFsm(V057e|P0341|IF7): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF7): Enable endpoints 0x08001000.
00:00:03:476: UHS1 Trace: CltIfFsm(V057e|P0341|IF7): Enable endpoints 0x08001000.
UHS1 Trace: CltIfFsm(V057e|P0341|IF8): Acquired by client in pid 6.
00:00:03:489: UHS1 Trace: CltIfFsm(V057e|P0341|IF8): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF9): Acquired by client in pid 6.
00:00:03:501: UHS1 Trace: CltIfFsm(V057e|P0341|IF9): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF9): Activating bAlternateSetting 0.
00:00:03:513: UHS1 Trace: CltIfFsm(V057e|P0341|IF9): Activating bAlternateSetting 0.
hciPath=/dev/usUHS1 Trace: CltIfFsm(V057e|P0341|IF10): Acquired by client in pid 6.
00:00:03:528: UHS1 Trace: CltIfFsm(V057e|P0341|IF10): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF11): Acquired by client in pid 6.
00:00:03:541: UHS1 Trace: CltIfFsm(V057e|P0341|IF11): Acquired by client in pid 6.
UHS1 Trace: CltIfFsm(V057e|P0341|IF11): Activating bAlternateSetting 0.
00:00:03:553: UHS1 Trace: CltIfFsm(V057e|P0341|IF11): Activating bAlternateSetting 0.
b/oh1/57e/305
00:00:03:563: DRH chip revision 00000040
00:00:03:566: DRH firmware version 14080113
00:00:03:570: DRH cdc version 00060800
00:00:03:573: DRH wifi module id a8e502d0
00:00:03:576: DRH SPL id 00001c58
Host Controller version 1.0, VOHCI1: USB device at port 0, vid: 0x057e pid: 0x0305
endor Revision: 0x00
sdstd_start_clock:now, divided clk is: 24000000 Hz
sdstd_client_init:SDHOST3-legacy
High-speed clocking mode disabled.
sdstd_start_clock:now, divided clk is: 24000000 Hz
Chip 43362a2 detected
00:00:03:630: BT: BTA/BTE/STACK now operational
FW(chk):43362a2-roml/sdio-nin-keepalive 5.91.153.64 2013/12/09 03:54:26
dhd_wlfc_init(): successfully disabled bdcv2 tlv signaling, 0
Dongle MAC address = 34:AF:2C:4A:67:67
00:00:03:853: MCP: boot1 version 2.06.08
BOOT1: 0x2068
00:00:03:874: MCP: loaded and parsed 'preload.txt' at '/vol/system/title/00050010/1000400a/code'
CRYPTO Open, clientPid=9 nodeId 00000000 titleId 00000000100000f4 perm=0xffffffff
CRYPTO Open, clientPid=6 nodeId 00000000 titleId 00000000100000f2 perm=0xffffffff
00:00:03:899: MCP: Wake 0 signal
00:00:03:939: NET: Applied interface MTU (wl0:1400 eth0:1400).
[NET] Init: Nin00:00:03:946: DRH using runtime generated WLAN data
00:00:03:951: setting DRH system time to 11:48:45
tendo Wii U
00:00:03:957: sending DRC WOWL wake
USBETH Trace: Created interface 100.
00:00:03:972: USBETH Trace: Created interface 100.
IP address of wl0 : 0.0.0.0
00:00:04:063: WUD_BCMFWCheck ==> chipname 20702A1 build 517 from SERIAL FLASH
BT: 0x205
00:00:04:072: BT: BTRM now Active (WUD Operational)
RM loop: Msg type 7 invalid!
CRYPTO Open, clientPid=12 nodeId 00000000 titleId 00000000100000f7 perm=0xffffffff
00:00:04:160: ACT: Current account is #1.
00:00:04:953: ccr_admin_wowl_wake_drc() returned 0
DRH: 0x1408
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
00:00:06:337: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:06:343: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:06:349: AHCI_DRV Trace: Resetting HBA.
00:00:06:353: AHCI_DRV Trace: Resetting HBA.
00:00:06:407: AHCI_DRV Trace: HBA Reset OK.
00:00:06:411: AHCI_DRV Trace: HBA Reset OK.
[ACP]INFO:ClearApplicationBoxCacheForBoss:6353: ClearApplicationBoxCacheForBoss failed due to result.GetValue() = -1607403008
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
00:00:11:421: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:11:427: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:11:433: AHCI_DRV Trace: Resetting HBA.
00:00:11:437: AHCI_DRV Trace: Resetting HBA.
00:00:11:490: AHCI_DRV Trace: HBA Reset OK.
00:00:11:494: AHCI_DRV Trace: HBA Reset OK.
CRYPTO Open, clientPid=11 nodeId 00000000 titleId 00000000100000f3 perm=0xffffffff
00:00:15:157: [BOSS] BG stress mode is disabled.
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
00:00:16:512: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:16:519: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:16:525: AHCI_DRV Trace: Resetting HBA.
00:00:16:528: AHCI_DRV Trace: Resetting HBA.
00:00:16:582: AHCI_DRV Trace: HBA Reset OK.
00:00:16:586: AHCI_DRV Trace: HBA Reset OK.
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
00:00:21:596: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:21:602: AHCI_DRV Warning: link not ready ready with status 16:-531.
00:00:21:608: AHCI_DRV Error: file ahci_drv_api.c, function ahciDrvOpen, line 265, status 16:-531, info 4(0x00000004)
00:00:21:618: AHCI_DRV Error: file ahci_drv_api.c, function ahciDrvOpen, line 265, status 16:-531, info 4(0x00000004)
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
[NET-NC]: ifOperStatus:0 != oper_state:2 (linkstate:2 ifAdminStatus:0 ipaddr:0x0)
initializing /dev/net/ifmgr/ncl... 00000000 00000000 00000002 00000002
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,358
Trophies
0
Age
28
XP
1,523
Country
Germany
We are getting somewhere.... Does it go further or does it hang?
But it getting so far means we can run stroopwafel and reinstall titles.
Maybe it gets even far enough to run udpih
 

gorgyrip

Well-Known Member
Member
Joined
Aug 28, 2018
Messages
136
Trophies
0
XP
769
Country
Spain
We are getting somewhere.... Does it go further or does it hang?
But it getting so far means we can run stroopwafel and reinstall titles.
Maybe it gets even far enough to run udpih
On the putty it just repeats the last line. On the hdmi it just stops at:
Searching for OTP store in patch...
OTP store at: 000010c4
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • SylverReZ @ SylverReZ:
    @mthrnite, Cheetah Girls, the sequel to Action 52's Cheetah Men.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Pokemon Black I played that one a lot
  • K3Nv2 @ K3Nv2:
    Honestly never messed with Pokémon on ds much
  • mthrnite @ mthrnite:
    I played pokemon once, was bored, never tried again
  • Psionic Roshambo @ Psionic Roshambo:
    Oh Dragon Quest IX
  • K3Nv2 @ K3Nv2:
    Spent like 5 hours on switch one never touched it again
  • Psionic Roshambo @ Psionic Roshambo:
    Sentinel of the stary skies
  • K3Nv2 @ K3Nv2:
    Ds is 20 years old this year
  • Psionic Roshambo @ Psionic Roshambo:
    So MJ no longer wants to play with it?
  • K3Nv2 @ K3Nv2:
    He put it down when the 3ds came out
  • SylverReZ @ SylverReZ:
    @K3Nv2, RIP Felix does great videos on the PS3 yellow-light-of-death.
  • Jayro @ Jayro:
    Eventhough the New 3DS XL is more powerful, I still feel like the DS Lite was a more polished system. It's a real shame that it never got an XL variant keeping the GBA slot. You'd have to go on AliExpress and buy an ML shell to give a DS phat the unofficial "DS Lite" treatment, and that's the best we'll ever get I'm afraid.
    +1
  • Jayro @ Jayro:
    The phat model had amazingly loud speakers tho.
    +1
  • SylverReZ @ SylverReZ:
    @Jayro, I don't see whats so special about the DS ML, its just a DS lite in a phat shell. At least the phat model had louder speakers, whereas the lite has a much better screen.
    +1
  • SylverReZ @ SylverReZ:
    They probably said "Hey, why not we combine the two together and make a 'new' DS to sell".
  • Veho @ Veho:
    It's a DS Lite in a slightly bigger DS Lite shell.
    +1
  • Veho @ Veho:
    It's not a Nintendo / iQue official product, it's a 3rd party custom.
    +1
  • Veho @ Veho:
    Nothing special about it other than it's more comfortable than the Lite
    for people with beefy hands.
    +1
  • Jayro @ Jayro:
    I have yaoi anime hands, very lorge but slender.
  • Jayro @ Jayro:
    I'm Slenderman.
  • Veho @ Veho:
    I have hands.
    Veho @ Veho: +1