Many on-line references are just plain wrong about this device. Pinout was wrong, information about the JTAG was wrong. Information about memory architecture was wrong. No clarification about what the buttons was complete.
This page comes as a hopeful clarifications to many missing or wrong information on the web on how to unbrick this device.
DD-WRT has many places where some one can get the wrong idea of how to upgrade this device. Some problems:
In the next sections I will describe what I tried and if you want to do yourself, you probably would like to try these things in this order. They more or less increase in complexity but also in possibility to success!
I just must have to say that it did nothing.
After doing this I tried all the recovery methods: Pinging: nothing, TFTP recover: nothing, UART: nothing back, JTAG: not successful, several SPI ICs flashings: didn't matter.
Info : JTAG tap: bcm4706.cpu tap/device found: 0x000c317f (mfg: 0x0bf (Broadcom), part: 0x00c3, ver: 0x0)
but this was possible only in irlen 32, what is apparently know as the Broadcom JTAG TAP controller and not the EJTAG MIPS Core space. Which is the real processor.
NAND and SPI flash shorting
- The last resort. And everybody said it should work. But, there is a problem: you need a donor image. I couldn't find a donor image for exactl this device available on the web. The most similar one I found was for an Asus_RT-N66U-B1 also with a broadcom BCM4706 SoC device. The network devices were different. And this could be a problem. Later after many trials I asked with private messages directly to particular people on the dd-wrt forum and one nice Adrian answered. He sent me an image of the CFE for the exact same device. Just with one detail. For privacy and security concerns he sent me the file with the MAC addresses and other details edited. Which I totally understand. The problem: the checksums. - One of the first things I did was to get the SPI IC detected. The detection was not stable. But I was able to make a backup like this of my SPI IC. This I discovered possibly had reading corruption. - Later I discovered that reading twice from the SPI IC gave different results. Reason: noise on the lines, solution: 0.1uF capacitor between Vcc and GND on the IC breakout board I used and increase the SPI programming speed. Lowering speeds actually increased errors! I found a nice behavior at 10kHz SPI reading and writing. I tested this by reading multiple times from the IC and comparing md5sums between reads. Must consistently read fine! Then I did a complete erase before doing the final write. And then after writing another reading and comparing to the original file. But unfortunately I discover this problem after I had programmed the IC once. I only had a backup from when I still had data corruption during reading. Fortunately, this backup binary was not corrupted enought to case a Checksum error on the first NVRAM space. (this I guessed later) - During my searchs and in this case with the assistance of AI search assist I was able to get to some ideas of how to calculate the CRC. AI made a lot of wrong assumptions, hallucinated a lot of times, incorrectly extrapolate a lot. It gave different answers for almost the same questions in different days. Until it finally helped me find the correct answer together with my own hex editing examination tools, the three different CFE files I had and the different behaviors I was getting.
The device has an empty pair or tiny pads near the RX pin. One pad connects to RX and the other to Vcc. One could put a pull-up resistor there. I did and it didn't change anything. I later removed it. Now that the device is unbricked, TX and RX work without anything on these pads. Don't solder anything: it is not necessary!
0x000000 -> 0x0003FF: CFE initialization code (very important to be not corrupted) 0x000400 -> 0x000A07: NVRAM_1: First factory NVRAM space (mostly sure) 0x050000 -> 0x0570E7: NVRAM_2: First main NVRAM space (guess) 0x070000 -> 0x077FFF: NVRAM_3: Second factory NVRAM space (guess) 0x078000 -> 0x078687: NVRAM_4: Second main NVRAM space (guess)
one NVRAM layout
0x0000 32bits: MAGIC Key: FLSH 0x0004 32bits: Length: length of whole NVRAM block 0x0005 1byte: Checksum (calculated from 0x0006 till the section end) 0x0006 1byte: version: 0x01 0x0007 2bytes: Flags: 0x0000 0x0008 -> end of section: Data Data: key=value ending with \00 Data section ends with \00\00
CFE> show devices Device Name Description ------------------- --------------------------------------------------------- uart0 NS16550 UART at 0x18000300 uart1 NS16550 UART at 0x18000400 flash0 ST Serial flash size 512KB flash0.boot ST Serial flash offset 00000000 size 256KB flash0.trx ST Serial flash offset 00040000 size 1KB flash0.os ST Serial flash offset 0004001C size 224KB flash0.nvram ST Serial flash offset 00078000 size 32KB flash1.boot ST Serial flash offset 00000000 size 256KB flash1.trx ST Serial flash offset 00040000 size 224KB flash1.nvram ST Serial flash offset 00078000 size 32KB nflash0.trx Samsung NAND flash offset 00000000 size 1KB nflash0.os Samsung NAND flash offset 0000001C size 131072KB nflash1.trx Samsung NAND flash offset 00000000 size 121856KB nflash1.brcmnand Samsung NAND flash offset 07700000 size 9216KB eth0 Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller *** command status = 0
CFE> show clocks Current clocks: 600/300/150/25 Mhz. CFE> show pci PCI bus 0 slot 0/0: vendor 0x14e4 product 0x0800 (flash memory, rev 0x01) PCI bus 0 slot 1/0: vendor 0x14e4 product 0x4715 (ethernet network, rev 0x01) PCI bus 0 slot 4/0: vendor 0x14e4 product 0x471a (USB serial bus, interface 0x10, rev 0x0) PCI bus 0 slot 4/1: vendor 0x14e4 product 0x471a (USB serial bus, interface 0x20, rev 0x0) PCI bus 0 slot 5/0: vendor 0x14e4 product 0x0820 (PCI bridge, rev 0x01) PCI bus 0 slot 6/0: vendor 0x14e4 product 0x0820 (PCI bridge, rev 0x01) PCI bus 0 slot 7/0: vendor 0x14e4 product 0x052e (undefined subclass 0xff, interface 0xff) PCI bus 0 slot 8/0: vendor 0x14e4 product 0x080e (RAM memory, rev 0x01) PCI bus 0 slot 9/0: vendor 0x14e4 product 0x0534 (undefined subclass 0xff, interface 0xff) *** command status = 0 CFE> show memory Range Start Range End Range Size Description ------------ ------------ -------------- -------------------- 000000000000-000006FFFFFF (000007000000) DRAM (available) 000007165000-000007FFFFFF (000000E9B000) DRAM (available) CFE> nvram getall DEF-p_wireless_eth1_11a-crypto=aes DEF-p_wireless_eth2_11bg-crypto=aes boardrev=0x1204 et0macaddr=10-6F-3F-16-17-76 4331_cckbw20ul2gpo=0x3333 boot_wait=off watchdog=3000 et0mdcport=0 43a2_mcsbw805glpo=0x00000000 hw_rev=0 reset_gpio=5 pmon_ver=CFE 6.30.15-1.04 vlan2ports=0 8 43a2_mcsbw805ghpo=0x11111111 gpio4=robo_reset sromrev=8 boardtype=0xf52e 43a2_mcsbw405glpo=0x00000000 4331_cckbw202gpo=0x3333 lan_netmask=255.255.255.0 43a2_mcsbw405ghpo=0x33333333 nvram_version=1.00 region=US vlan2hwname=et0 pmon_date=Tue Apr 24 09:04:01 JST 2012 DEF-p_wireless_eth1_11a-authmode=psk xtalfreq=25000 boardflags2=0x0 DEF-p_wireless_eth1_11a-wpapsk=u3h5nykr5a4nj wait_time=3 DEF-p_wireless_eth2_11bg-wpapsk=u3h5nykr5a4nj melco_id=RD_BB11119 wl_dmatxctl=0x24c0040 43a2_maxp5ga0=40,100,100,66 43a2_maxp5ga1=40,100,100,66 43a2_maxp5ga2=40,100,100,66 wl_dmarxctl=0x24c0000 4331_mcsbw20ul2gpo=0x11111111 clkfreq=600,300,150 lan_ipaddr=192.168.11.1 vlan1hwname=et0 DEF-p_wireless_eth2_11bg-authmode=psk sdram_config=0x0105 vlan1ports=1 2 3 4 8* boardflags=0x110 wandevs=vlan2 DEF-p_wireless_eth1_11a-authmode_ex=wpa2-psk sdram_refresh=0x0000 sdram_ncdl=0x00000000 4331_mcs32po=0x0002 pincode=62456838 product=WZR-D1800H DEF-p_wireless_eth2_11bg-authmode_ex=wpa2-psk 43a2_mcsbw205glpo=0x00000000 et0phyaddr=30 wl_pcie_mrrs=128 landevs=vlan1 wl0 wl1 4331_maxp2ga0=52 4331_maxp2ga1=52 4331_maxp2ga2=52 43a2_mcsbw205ghpo=0x00000000 4331_legofdmbw20ul2gpo=0x11111111 43a2_mcsbw1605glpo=0x00000000 sdram_init=0x0000 43a2_mcsbw1605ghpo=0x00000000 4331_legofdmbw202gpo=0x11111111 4331_mcsbw402gpo=0x88888888 custom_id=0 boardnum=00 4331_mcsbw202gpo=0x11111111 bootflags=1 size: 1668 bytes (31100 left)
No idea. I didn't have to get to this
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324862
Real hndcrc8 table: https://github.com/spotify/linux/blob/master/drivers/staging/brcm80211/util/bcmutils.c#L570 https://git.wut.ee/qi-hardware/openwrt-xburst/src/commit/843274aa37f00bacea2b88c03525c8d6564a54c7/package/nvram/src/crc.c https://github.com/GetOcean/ocean-os-drivers/blob/45785ee9d212973039d1e993043873bc81922106/ap6210.drivers/bcmutils.c#L1369 https://github.com/Coool/Broadcom-CFE/blob/cb59f58fdfdd849430cb59258f960b4da7ebef69/cfe/main/bcmnvram.c#L231
HndCRC8 used: https://git.wut.ee/qi-hardware/openwrt-xburst/src/commit/843274aa37f00bacea2b88c03525c8d6564a54c7/package/nvram/src/nvram.c
NVRAMCRCSTART_POSITION: https://git.wut.ee/qi-hardware/openwrt-xburst/src/commit/843274aa37f00bacea2b88c03525c8d6564a54c7/package/nvram/src/nvram.h
General Info: https://deviwiki.com/wiki/Buffalo_WZR-D1800H https://wiki.dd-wrt.com/wiki/Buffalo_WZR-D1800H
dd-wrt downloads:
dd-wrt recommended downloads (according to webpage): Danger!!! Warning!!!. This was probably the reason I bricked my device. The webupgrade points to a bin file, and the factory flash points to a trx. It is the other way around! https://dd-wrt.com/support/router-database/?model=WZR-D1800H%20(AC1750)_-