Hardware Help me unbrick my Wii U!

  • Thread starter Thread starter The T
  • Start date Start date
  • Views Views 4,553
  • Replies Replies 51

The T

Active Member
Newcomer
Joined
Mar 29, 2016
Messages
33
Reaction score
1
Trophies
0
Age
39
XP
228
Country
United States
Hello, another story of "I took my WiiU out of storage and it's bricked". On launch, it shows the WiiU logo and then is frozen there forever. I picked up a Rasberry Pi, was able to load up recovery_menu, but it doesn't display. I blindly navigated to Dump Syslogs, found a bunch of FSA: ### DATA CORRUPTION ERROR ###, dev:mlc01, err:-1245211, cmd:11, path:(null) errors.

Tried to install/access ISFShax, but I'm also not able to see that. Followed the instructions of dumping the entire contents from the sd folder of isfsh.ax to the root of the SD card. The LED flashes purple, but nothing displays, and navigating blindly doesn't seem to have any effect; the LED just continues to flash purple. I'm at a loss at this point; I'm only mildly technically minded and this is way out of my comfort zone, so would love some advice.

I couldn't figure out how to attach the logs, so I've uploaded them here: https://filebin.net/17x5w2aftsb8qkrj/logs.zip
 
Using latest recovery menu, and rename boot1.img into boot1now.img, place it at the root of your SD, enter recovery menu, do nothing and wait for around 10 seconds, it should load boot1.img automatically.

Follow the ISFShax tutorial for installing.
 
Hi, thanks for the suggestion!

in the isfshax_release on isfsh.ax, there is no "boot1.img", just "boot1now.img". When I have the contents of that entire folder on the root of the sd card, it (seemingly) briefly loads into recovery_menu (nothing is visible on the screen), and then possibly loads into minute, but again nothing is visible. The LED goes from purple solid, to purple flashing at that point. Attempts to navigate blindly have failed. This is where I'm stuck.

(fwiw, yes my TV supports 1080p. I understand that issue but it shouldn't be the cause...)
 
where did you get the recovery menu? should from here:

Recovery menu 0.6

Changelog:


  • Added a new "Load BOOT1 payload" option.
    • Loads a payload from the root of the SD Card named boot1.img and executes it from within boot1.
    • If the file is named boot1now.img it gets loaded automatically when starting the recovery_menu after a 5 second timeout.
    • This allows booting minute_minute.
Some consoles indeed struggle to get recovery menu displayed, but as far as I know, not minute.
 
Are you saying I should replace the recovery_menu in the ISFShax all-in-one download with the standalone version?

I did use the current version of recovery_menu when I dumped the logs, but used the one from the ISFShax download when attempting to run it.

I can give it a try, but I'm not sure how this will help me get past the "I can't see anything" issue.

A question that will help; when it does load into minute, what does the blinking purple indicate. That it is working, or that something went wrong?

Edit: Tried it, doesn't seem to make a difference. Seems like they are the same file, even.

Any other things I could try to boot into, to see if it would somehow help?

Edit2: Something else I've tried is creating a minute.ini, putting it in a folder in the root called minute, with
[boot] autoboot=7 autoboot_timeout=3
And no change, it still just blinks purple. I am of the belief minute itself is not working, possibly; is there something with my system that could prevent it from loading, and if so, is there any other workaround I can try?
 
Last edited by The T,
Purple means UDPIH exploit triggered successfully, blinking purple means it failed to read some files. If you confirm the boot1now.img has correct hash, try a different SD card, format it into FAT32+32K cluster and try again.

Like I said some consoles cannot display recovery menu correctly, but should be able to display minute as long as your HDMI port is good.
 
Sounds good. I have another SD card already on the way (a SanDisk High Endurance that I intended to use for redNAND) so I'll wait till I received that and give it a go.
 
Or you can operate blindly using the boot1.img + 0.6 recovery menu, this version has LED feedback when you pressed a button. You just move to "Load BOOT1 payload" in recovery menu and another Power+ eject will get you into the minute.
 
When exactly does it blink purple? Directly when triggering UDPIH or only after a few seconds after it was already static purple?

Blinking purple is usually a corrupted recovery_menu when it happens directly after triggering the exploit.

The cluster size doesn't matter
 
A few seconds after it was already static purple.

The new SD card is arriving tomorrow, so I'll give it a go then.
Post automatically merged:

Alright, even with a new SD card, formatted to FAT32 file system, allocated unit size 32 kilobytes, it's doing the same thing: purple for a few seconds, then some quick flickering (like it's loading), and then the steady blinking purple.

Is there anything in my logs that might hint at what's wrong? A different version of something I should try? Anything?
 
Last edited by The T,
I can try that again; but the blinking sounds like it's an indication of an error, is it not?

Edit: Yep, no difference. Is there anything else I can try?

UPDATE!!! I've made progress!!

I tried multiple old versions of minute, and this one was the one that ended up working.

I'm now trying to follow this guide, but I'm lost on 2 things.

"Backing up savegames", if this is still a possible thing to do; where do I find the "Dump SLC + MLC option"? If it's in recovery_menu; it seems like my WiiU now boots straight into minute (I think?), instead of recovery_menu. (edit: it's not in recovery_menu) How should I be tackling this?

Next: "Rebuilding the MLC"; It says I need to "copy the otp.bin from the SD card", but I don't have this file. Is this something that I would be getting from backing up savegames?

Also want to ask: at some point I accidentally chose the first option on minute, "Patch (slc) and boot IOS (slc)"; I think it just errored out but I figured I'd bring it up in case that could potentially mess something up.

Thanks a lot for any help going forward. It feels like I'm so close now... 😭
 
Last edited by The T,
You dump the otp and SEEPROM in the backup and restore menu in minute.

I would suggest you then setup redNAND. Once you have redNAND running you can mount the old MLC on the redNAND and then use save mii to backup your saves.

Also I don't think the minute version should make a difference here, it probably was just luck on the try. Use the newest minute from now on.
Post automatically merged:

Btw I took a look at your logs and I don't see MEDIA ERRORS only data corruption on /vol/storage_mlc01/sys/title/0005001b/10042400/content/CafeTw.ttf.
Code:
00:00:04:621: FSA: ### DATA CORRUPTION ERROR ###, dev:mlc01, err:-1245211, cmd:11, path:(null)
00:00:04:621: failed to read file /vol/storage_mlc01/sys/title/0005001b/10042400/content/CafeCn.ttf, err -196635
00;00;04;501: ***LoadShared - WaitLoadComplete(0,8388608) failed with error -196635 on file "CafeCn.ttf".
00:00:05:379: FSA: ### DATA CORRUPTION ERROR ###, dev:mlc01, err:-1245211, cmd:11, path:(null)
00:00:05:380: failed to read file /vol/storage_mlc01/sys/title/0005001b/10042400/content/CafeTw.ttf, err -196635
00:00:05:382: NET: Change admin state (1 -> 2)(iface:0 link:2)
00;00;05;260: ***LoadShared - WaitLoadComplete(0,8229724) failed with error -196635 on file "CafeTw.ttf".

Maybe this isn't a bad eMMC after all and just some logical corruption for some reason.
In the worst case that could be caused by bad dram, in that case you would also get the error on the redNAND. Bad DRAM could also explain why you had so trouble loading minute initially from the recovery.

I suggest you continue with the redNAND setup for now and if that works and you could backup your saves, we can then try to replace the corrupted file on the mlc.
 
Last edited by SDIO,
I super appreciate you taking a look at the logs!!

I can definitely give that a go, I just feel like I'm missing some understanding of the steps.

"You dump the otp and SEEPROM in the backup and restore menu in minute."

What option am I selecting to do this?

Or at this point, in your second post, should I just skip all of it and go straight to setting up redNAND? Do I need to do the "Rebuilding the MLC" part?
 
Like I mentioned, there is no option.

1746471039588.png
 
You ever stare at a problem so long that you miss the obvious thing right in front of you?

Yeah. Thanks.

I'll post an update if I do get it working, but I'll be busy the rest of the day. But I do now have otp.bin and hopefully it'll be smooth sailing. Thanks.

Edit: Well, things got worse all of a sudden. I don't know what changed, but now it won't boot to anything.

I've noticed now when I turn it on, the LED briefly goes orange, and then blue; which it did not do this before. I *thought* previously it was going straight to minute; but after dealing with adding the partition to the SD card, it doesn't; it just continues to go to the Wii U screen, and if I try to do the recovery_menu thing with the Pi it just shuts off again.

Did I mess something up?

Edit2: I took a fresh SD card and launched recovery_menu, and was able to get in. Dumped my logs again. Don't know if this says anything new.

If I don't get any better advice, I'll try both wiping the SD card I was using, and using this new one, and see if I can start over from scratch. 🤷‍♀️
 

Attachments

Last edited by The T,
when it goes orange that means it can't read the fw.img off the sd and then it will go to fallback mode, where it boots the system with just minimal patches. So something is up with your SD or it doesn't make good contact.
 
Alright, finally getting back to this. I did some experimenting with my two SD cards (one a very old one 32 GB SD card, and one the newly purchased SanDisk High Endurance 32 GB microSD in it's included Adapter) and I can launch into minute in the prior, but not the latter, with the same files.

The microSD card has been partitioned by Paragon Partition Manager, but the older one hasn't. Did I possibly do this incorrectly? Fwiw, I was confused by the instructions, "It's recommended to align the Partitions on 64MiB boundaries and use a multiple of 64MiB for the size." I just now looked up that 64 MiB is not 64 MB, so I might be completely misunderstanding this. But I opted to create a partition of 1.28 GB for the FAT32 partition, and then format all the rest as NTFS.

Is it worth me trying the process on the older card? Will I suffer any risks if I get it "working" on the older card, but it's not "high endurance" enough to be a redNAND?
 
Last edited by The T,

Site & Scene News

Popular threads in this forum