Soo, this project started pretty simple. I was working on a DVR and the original goal was to run DOOM on it. I didn’t have much success trying to compile HDAL code for it, but I did manage to edit scripts, modify the Linux filesystem, and even change the boot logo to my own, and I also had sucess initializing hardware by using original Sofia, just run it on the clean linux system and wait for it to crash.

This post is some of the research I did while trying to figure out how this thing actually works.

The beginning

This DVR is based on a Novatek NT98321BG SoC running Linux. I already did a lot of research on the firmware and wrote scripts to unpack and repack it, allowing me to edit the Linux system in a simple folder format.

Quick note: you’ll see the name NA51068 show up later (in the boot log, the SDK, etc). NT98321BG is the market/silkscreen name; NA51068 is Novatek’s internal codename for the same chip. It’s never officially explained anywhere, but it’s probably tied to the licensed ARM core Novatek puts on their SoCs.

The DVR originally runs an application called Sofia. Sofia is basically the main application for the entire device: it handles recording, playback, USB export, settings, display output, and, more importantly for this project, a huge amount of the hardware initialization and control through Novatek’s HDAL stack.

When Linux boots, it runs a shell script at /etc/init.d/rcS. I started by modifying this script and had some success doing simple things such as adding delays and removing or adding commands.

Naturally, I tried to see what hardware was already available.

I tried accessing things like /dev/fb0, which is referenced by the main Sofia application, and /dev/sda, which is the block device used for USB storage.

I couldn’t access fb0 because it didn’t exist, and initially I thought sda didn’t exist either.

That second one was actually just me being an idiot.

I was trying to access /dev/sda as if it were a directory and even tried doing stupid things like calling /dev/sda/script.sh. Of course that wasn’t going to work — it’s a block device, not a filesystem directory.

Once I actually mounted it properly, the USB storage situation made much more sense.

And I only figured that out much later, after I had already solved the UART issue. I was a beginner back then, and I’m still learning some stuff about Linux XD.

The Linux side actually handles the normal hardware reasonably well: USB storage works, the UART support is there, and the basic peripherals behave like you’d expect from a Linux system.

The problem is the interesting stuff.

Video capture, audio input/output, the display pipeline and the framebuffer are where the Novatek-specific stack really takes over.

Those weren’t simply sitting there as normal Linux devices waiting for me to open them.

HDAL

After looking around more, I confirmed that the DVR requires the Novatek software stack to properly initialize the interesting hardware.

The kernel modules do perform real work. They’re not completely fake drivers, and they handle things such as USB-related functionality and UART is built into the kernel. But simply loading the modules doesn’t give me the multimedia hardware I actually care about.

The complicated parts — video capture, audio input/output, display and framebuffer functionality — depend heavily on the Novatek initialization stack.

This is where HDAL — Hardware Device Abstraction Layer enters the picture.

The SDK documentation describes a large software stack around the SoC’s multimedia hardware. When I compared the SDK with Sofia in Ghidra, the function names matched almost perfectly.

The architecture started making more sense:

Linux kernel
    ↓
Novatek kernel modules
    ↓
nvtmem / KDRV / KFLOW
    ↓
HDAL
    ↓
hardware initialization
    ↓
video / audio / display hardware

The kernel provides the foundation, but loading the modules isn’t enough to magically make the multimedia hardware usable.

The vendor software still has to initialize and configure it.

And this is where the architecture gets annoying for reverse engineering.

The boot chain

Boot Chain Image

The SDK documentation made the boot sequence much clearer.

The important parts are the call to /usr/etc/loadmod, which is an sh script that extracts and calls vg_boot.sh to load the kernel modules, followed by module_init, which initializes the Novatek hardware stack through ioctls made by Novatek’s closed-source libraries into /dev/nvtmem.

Once this initialization succeeds, the system can create the interfaces expected by the rest of the software, including the framebuffer.

So the problem wasn’t that the NT98321BG couldn’t provide a framebuffer.

It was that the framebuffer wasn’t there until the vendor initialization process had successfully happened.

The same applies to the more interesting multimedia hardware: loading the kernel modules alone isn’t sufficient. Something still needs to configure the video, audio and display subsystems.

The particularly annoying part is that I couldn’t simply reproduce this initialization myself. The relevant initialization path is tied into Sofia and the proprietary HDAL stack.

Instead of having a convenient standalone hardware initialization program that I could run and then replace, the firmware essentially initializes the hardware as part of getting the DVR application running.

Which is a pretty terrible situation when your goal is to replace the application.

The UART mystery

There was another mystery I spent quite a while chasing:

Why the hell was the UART silent?

U-Boot clearly had ttyS0 configured as the console, and the Linux kernel actually contains the serial support, but I wasn’t getting the expected output.

I initially suspected HDAL, the kernel, or some missing driver.

It wasn’t any of those.

Xiongmai had simply disabled the serial console in the bootloader.

There was a hidden U-Boot environment variable controlling it.

The magic incantation turned out to be:

setenv -f xmuart 0
saveenv
reset

And suddenly:

UART.

This was especially funny because I had spent months, and even set this project aside, looking for some complicated Linux-side explanation. Maybe the drivers weren’t built into the kernel. Maybe they required HDAL. Maybe the lack of UART was somehow another part of the vendor initialization.

Instead, the answer was literally a hidden U-Boot variable. Maybe I could have found that earlier if I took a better look on /boot/zImage.img on Ghidra

The whole thing actually seemed plausible to me at the time. I knew HDAL was doing a lot of hardware initialization, and I had found all this vendor-specific stuff on the SDK, so it seemed entirely reasonable that Novatek/Xiongmai could ship a mostly stock kernel and hide all their magic inside their custom applications.

So at least the UART mystery had a satisfying ending.

The final fight with Sofia

Once I had UART working, I could finally see what the system was actually doing during boot, which made the next phase of reverse engineering much easier.

I spent a lot of time modifying module_init and patching Sofia.

One of the things I wanted to know was where the hardware configuration actually came from.

module_init has a configuration file in the form of a DTB, but Sofia doesn’t work like that, even tho it looks for a configuration file inside /mnt/mtd, it doesn’t exist, turns out Sofia generates the configuration during runtime by reading the hardware info and doing some weird math

So I patched it to dump those configurations.

The patch I ended up using is pretty stupid but effective: at 0x003D0828 I patched a BEQ into a NOP, making Sofia skip an if and go directly into an error-printing path that dumps the configurations it had generated.

This gave me a pretty interesting look at what Sofia was setting up:

DDR  Type   Size       Addr          Name               Shared Pool
 0    028    1352KB   0x0B400000   enc_scl_out
 0    000   16200KB   0x0B552000   disp0_in
 0    107    4080KB   0x0C524000   disp0_fb
 0    001     812KB   0x0C920000   disp1_in
 0    102    1260KB   0x0C9EB000   tmnr_motion
 0    033   14456KB   0x0CB26000   common
 0    024    9788KB   0x0D944000   disp_dec_in
 0    029   12388KB   0x0E2D3000   enc_out
 0    103    4860KB   0x0EEEC000   osg
 0    025   45024KB   0x0F3AB000   disp_dec_out         disp0_cap_out
 0    027   75552KB   0x11FA3000   enc_cap_out
 0    034   17012KB   0x1CDAB000   user_blk
 0    031     200KB   0x1DE48000   au_enc
 0    032      40KB   0x1DE7A000   au_dec

(28)enc_scl_out_ddr0 DDR0(1352KB)
(00)disp0_in_ddr0 DDR0(16200KB)
(01)disp1_in_ddr0 DDR0(812KB)
(33)common_ddr0 DDR0(14456KB)
(24)disp_dec_in_ddr0 DDR0(9788KB)
(29)enc_out_ddr0 DDR0(12388KB)
(103)osg_ddr0 DDR0(4860KB)
(25)disp_dec_out_ddr0 DDR0(45024KB)
(06)disp0_cap_out_ddr0 DDR0(0KB)
(27)enc_cap_out_ddr0 DDR0(75552KB)
(34)user_blk_ddr0 DDR0(17012KB)
(31)au_enc_ddr0 DDR0(200KB)
(32)au_dec_ddr0 DDR0(40KB)

I took this information and tried putting the relevant configuration into the Device Tree used by module_init.

It still broke.

I then tried a different approach: patching Sofia so that it would initialize the hardware and then quit immediately.

The idea was pretty simple:

  1. Let Sofia initialize everything.
  2. Let the hardware become usable.
  3. Make Sofia exit.
  4. Take over the system myself.

That didn’t work either.

Instead, the system produced some completely bizarre error that had very little apparent relationship with what I had changed.

At that point I had to admit that I was probably fighting the architecture itself rather than just one missing configuration value.

Update: I was being dumb, if I did the patch again now maybe it would work, I think the issue was that I was hand-editing raw bytes in IDA (which doesn’t have an ARM assembler) instead of writing actual instructions on Ghidra and letting the tool assemble the encoding. If a patch like that touches anything near a branch, the PC-relative offset needs to be recalculated by hand too — mess that up and the CPU just jumps to garbage with no warning. That would explain the bizarre, seemingly unrelated crash. Should’ve used Ghidra’s patch-instruction feature instead of doing it byte-by-byte.

I’m holding on to this project

I’ve abandoned and come back to this project more times than I can count. In an earlier version of this post, this section said I’d given up and was going to look for a DVR with a HiSilicon chip instead. After more research, though, it turns out HiSilicon has its own proprietary hardware abstraction system too, so switching wouldn’t have actually solved anything. So I’m holding on to this DVR project instead of jumping ship, and I’m almost there.

Files and tools

I’ve put the tools I used during this research on GitHub, including the firmware repacking workspace, the original firmware unpacking/repacking workspace, scripts for compiling code, toolchain, and the patched Sofia binary that I’m not even sure if it works.

GitHub: Repository

I’m also attaching the Sofia patch that dumps the hardware configuration generated at runtime.

The patch works by replacing the BEQ at 0x003D0828 with a NOP, causing Sofia to skip the conditional branch and reach the error-printing path that dumps the generated configuration.

Here are some of the other useful files from the investigation:

Original boot log

The full original boot log, with xmuart set to 0:

NPpT0table1
IO0_26 0

UNZOK!NA51068 05.03.04
CPU1200 DONE
mmc bootstrap
0oad all-in-one fw
Loader Start ...
321_DRAM1_933_4096Gb_DRAM2_0Gb 04/11/2022 13:54:13

SPI NOR MID=00000020,TYPE=00000040,SIZE=00000018=>01000000
SPI NOR
Dual_read
tmp_addr 0x02000000
LdCtrl2 0x00000000
Dual_read
uboot_addr 0x06000000
uboot_size 0x01F80000
Dual_read
core No. 0x00000511
fdt 0x00080000
shm 0x00A00000
p_bininfo->boot.fdt_addr 0x00080000
bl_smp_start
uboot_entry 0x06000000
core2_jump_program 0xFE080500
code2JumpCodelen 0x00000010
core2_entry2_addr 0x1FF80000
core2_entry_program 0xFE080510
code2EntryCodelen 0x000001A4
0xFE0B9000= 0x00000000
reset core2
2acor1await

U-Boot 2016.07 (Apr 11 2022 - 13:54:25 +0800)

CPU:   Novatek NT @ 1200 MHz
DRAM:  512 MiB
Relocation to 0x07d57000, Offset is 0x01d57000 sp at 07a46ed0
ARM CA9 global timer had already been initiated
 CONFIG_MEM_SIZE              =      0x20000000
 CONFIG_NVT_UIMAGE_SIZE       =      0x00a00000
 CONFIG_UBOOT_SDRAM_BASE      =      0x06000000
 CONFIG_UBOOT_SDRAM_SIZE      =      0x01f80000
 CONFIG_LINUX_SDRAM_BASE      =      0x00b00000
 CONFIG_LINUX_SDRAM_SIZE      =      0x05500000
 CONFIG_LINUX_SDRAM_START     =      0x05600000
SPI:   nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
all blocks is unlocked.
SRx val: {[1, 0x20], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601220.
nvt spinor 1-bit mode @ 48000000 Hz
nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
all blocks is unlocked.
SRx val: {[1, 0x20], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601220.
nvt spinor 1-bit mode @ 48000000 Hz
DTS find cpu freq clock 1200MHz
Read power trim = 0x0000000d
cpu 1200 remap_data 54
Set CPU clk 1200MHz
Read power trim = 0x0000000d
ddr 1864 remap_data 30
Net:   na51068_eth_initialize 1.0.3.0
na51068_eth_initialize(2121) nodeoffset < 0
na51068_eth_initialize: path /eth0@fcc00000 not found
<<<<<<<<na51068_eth_initialize: dtb node /eth1@fcd00000 found>>>>>>>
################## eqos_initialize 0xfcd00000 ##################
eth_parse_phy_intf: get IO MEM 0xfcd00000
DTS /eth1@fcd00000 found
LED2 pinmux 0x200046
eth_parse_phy_intf: ref-clk-out 0, phy_clk: 0
eth_parse_phy_intf: pinmux detect emb phy 0x200
@xm_eth_read_phyid(), phy_id: 0x0, phy_ver: 0x1.
val 1
eth1
Warning: eth1 MAC addresses don't match:
Address in SROM is         0a:0b:0c:0d:0e:02
Address in environment is  00:0b:3f:00:00:01

USB0:   USB EHCI 1.00
scanning bus 0 for devices... 1 USB Device(s) found
USB1:   USB EHCI 1.00
scanning bus 1 for devices... 1 USB Device(s) found
0 Storage Device(s) found
usb device not found
but something wrong, please check log shown above

Hit CTRL-C to stop autoboot:  0
NovaWdt_Start nSecs :88
nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
all blocks is unlocked.
SRx val: {[1, 0x20], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601220.
nvt spinor 1-bit mode @ 48000000 Hz
@do_spi_flash_probe() flash->erase_size: 65536, flash->sector_size: 65536
device 0 offset 0xf60000, size 0x20000
SF: 131072 bytes @ 0xf60000 Read: OK
at do_logoload pType: squashfs.
srcAddr 0x4000000, dstAddr 0x4500000
created_inode 0x7a83800
find_squashfs_file: name Close, start_block 0, offset 0, type 1
find_squashfs_file: name Thumbs.db, start_block 0, offset 32, type 2
find_squashfs_file: name VideoBlank, start_block 0, offset 72, type 1
find_squashfs_file: name VideoLock, start_block 0, offset 104, type 1
find_squashfs_file: name VideoLoss, start_block 0, offset 220, type 1
find_squashfs_file: name h264dvr.jpg, start_block 0, offset 252, type 2
read inode: name h264dvr.jpg, sb 0, of 252, type 2
write_file: regular file, blocks 14
len 55953
### FS load complete: 55953 bytes loaded to 0x4500000
jpeg decoding ...
<<imgwidth=800, imgheight=600, linebytes=1600>>
decode success!!!!
decode jpeg success.
LCD300:0 chooses PLL9:297000000 with div=4 (drv:1.1.2)
@do_bootlogo(), g_vin: 1[1:800*600,2:1024*768;3:720P;],g_output: 0x1000[0x1000:720P,0x1001:1080P,0x1002:1024*768],g_infmt: 2[0:YUV422,1:RGB888,2:RGB565,3:ARGB1555], lcd_frame_base[LCD0_ID]: 0x1E800000.
hdmi_if_init, apply new vid:4 setting.
hdmitx_init_phy, clock_rate:74250KHz
Init PHY END
Skip InitDDC
hdmi: audio stream enable.
Bootlogo CVBS ON. g_vin[0] 0,g_output[0] 0
LCD210_1: chooses PLL11:54000 with div=2
LCD300:0 chooses PLL9:297000000 with div=4 (drv:1.1.2)
@do_bootlogo(), g_vin: 1[1:800*600,2:1024*768;3:720P;],g_output: 0x1000[0x1000:720P,0x1001:1080P,0x1002:1024*768],g_infmt: 2[0:YUV422,1:RGB888,2:RGB565,3:ARGB1555], lcd_frame_base[LCD0_ID]: 0x1E800000.
hdmi_if_init, apply new vid:4 setting.
Bootlogo CVBS ON. g_vin[0] 0,g_output[0] 0
LCD210_1: chooses PLL11:54000 with div=2
nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
all blocks is unlocked.
SRx val: {[1, 0x20], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601220.
nvt spinor 1-bit mode @ 48000000 Hz
@do_spi_flash_probe() flash->erase_size: 65536, flash->sector_size: 65536
device 0 offset 0xb0000, size 0x370000
SF: 3604480 bytes @ 0xb0000 Read: OK
aSrcAddr[0]: 0x4000000, dstAddr: 0x5600000, apFileName[0]: boot/uImage.
created_inode 0x7a6aeb0
find_squashfs_file: name Close, start_block 0, offset 0, type 1
find_squashfs_file: name Thumbs.db, start_block 0, offset 32, type 2
find_squashfs_file: name VideoBlank, start_block 0, offset 72, type 1
find_squashfs_file: name VideoLock, start_block 0, offset 104, type 1
find_squashfs_file: name VideoLoss, start_block 0, offset 220, type 1
find_squashfs_file: name h264dvr.jpg, start_block 0, offset 252, type 2
find_squashfs_file: name webLogo, start_block 0, offset 388, type 1
find_squashfs_file fail
### get_squashfs_file Failed, size: 0, filename: boot/uImage, aSrcAddr[0]: 0x4000000!
aSrcAddr[1]: 0xB00000, dstAddr: 0x5600000, apFileName[0]: boot/uImage.
created_inode 0x7a6c050
find_squashfs_file: name bin, start_block 0, offset 2724, type 1
find_squashfs_file: name boot, start_block 0, offset 2828, type 1
read inode: name boot, sb 0, of 2828, type 1
find_squashfs_file: name zImage.img, start_block 0, offset 2756, type 2
find_squashfs_file fail
### get_squashfs_file Failed, size: 0, filename: boot/uImage, aSrcAddr[1]: 0xB00000!
aSrcAddr[0]: 0x4000000, dstAddr: 0x5600000, apFileName[1]: boot/zImage.img.
created_inode 0x7a85850
find_squashfs_file: name Close, start_block 0, offset 0, type 1
find_squashfs_file: name Thumbs.db, start_block 0, offset 32, type 2
find_squashfs_file: name VideoBlank, start_block 0, offset 72, type 1
find_squashfs_file: name VideoLock, start_block 0, offset 104, type 1
find_squashfs_file: name VideoLoss, start_block 0, offset 220, type 1
find_squashfs_file: name h264dvr.jpg, start_block 0, offset 252, type 2
find_squashfs_file: name webLogo, start_block 0, offset 388, type 1
find_squashfs_file fail
### get_squashfs_file Failed, size: 0, filename: boot/zImage.img, aSrcAddr[0]: 0x4000000!
aSrcAddr[1]: 0xB00000, dstAddr: 0x5600000, apFileName[1]: boot/zImage.img.
created_inode 0x7a67720
find_squashfs_file: name bin, start_block 0, offset 2724, type 1
find_squashfs_file: name boot, start_block 0, offset 2828, type 1
read inode: name boot, sb 0, of 2828, type 1
find_squashfs_file: name zImage.img, start_block 0, offset 2756, type 2
read inode: name zImage.img, sb 0, of 2756, type 2
write_file: regular file, blocks 10
len 2477600
### get_squashfs_file OK: loade 2477600 bytes to 0x5600000
uImage is at 5600000, uboot fdt image is at 7a47090
## Booting kernel from Legacy Image at 05600000 ...
   Image Name:   Linux-4.9.118
   Image Type:   ARM Linux Kernel Image (uncompressed)
   Data Size:    2477536 Bytes = 2.4 MiB
   Load Address: 00008000
   Entry Point:  00008000
   Verifying Checksum ... OK
## Flattened Device Tree blob at 07a47090
   Booting using the fdt blob at 0x7a47090
   Loading Kernel Image ... OK
   Loading Device Tree to 07a38000, end 07a42fff ... OK
at xminfo_get() g_nXmBootSysIndex: 0, g_nXmRomfsIndex: 0.
at xminfo_get() aXmInfo: XmUart=0,XmAuto=1,Id=NULL,Mac=00:0b:3f:00:00:01,HwId=NULL,SysIndex=0,RomfsIndex=0,CorruptFlag=0x0,BackupCount=0.
osMemStart: 0x0, osMem: 0xB400000.

Starting kernel ...

ACTLR: 0x00000005
ACTLR: 0x00000045
Disable MMU
Clear MMU
Uboot L2 cache aux val: 0x72430000
Uboot L2 cache prefetch ctrl val: 0x70000000
Uboot L2 cache ctrl val: 0x00000000
Done
Uncompressing Linux... done, booting the kernel.
abceBooting Linux on physical CPU 0x0
Linux version 4.9.118 (ruanyingda@dell) (gcc version 6.5.0 (Buildroot 2019.05.2-00003-g3ccc130) ) #131 SMP Thu Dec 30 16:06:08 CST 2021
CPU: ARMv7 Processor [414fc091] revision 1 (ARMv7), cr=10c5387d
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
OF: fdt:Machine model: Novatek NA51068
Memory policy: Data cache writealloc
percpu: Embedded 13 pages/cpu @8b23a000 s24332 r8192 d20724 u53248
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 45675
Kernel command line: earlyprintk console=ttyS0,115200 init=linuxrc mem=0xb400000 rootwait nprofile_irq_duration=on root=/dev/mtdblock4 rootfstype=squashfs mtdparts=spi_nor.0
PID hash table entries: 1024 (order: 0, 4096 bytes)
Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
Memory: 174968K/184320K available (4790K kernel code, 268K rwdata, 1668K rodata, 268K init, 303K bss, 9352K reserved, 0K cma-reserved)
Virtual kernel memory layout:
    vector  : 0xffff0000 - 0xffff1000   (   4 kB)
    fixmap  : 0xffc00000 - 0xfff00000   (3072 kB)
    vmalloc : 0x8b800000 - 0xff800000   (1856 MB)
    lowmem  : 0x80000000 - 0x8b400000   ( 180 MB)
    modules : 0x7e800000 - 0x80000000   (  24 MB)
      .text : 0x80008000 - 0x804b5cd8   (4792 kB)
      .init : 0x80659000 - 0x8069c000   ( 268 kB)
      .data : 0x8069c000 - 0x806df150   ( 269 kB)
       .bss : 0x806e1000 - 0x8072cf54   ( 304 kB)
SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
Hierarchical RCU implementation.
NR_IRQS:384
L2C-310 enabling early BRESP for Cortex-A9
L2C-310 full line of zeros enabled for Cortex-A9
L2C-310 ID prefetch enabled, offset 1 lines
L2C-310 dynamic clock gating enabled, standby mode enabled
L2C-310 cache controller enabled, 16 ways, 256 kB
L2C-310: CACHE_ID 0x410000c9, AUX_CTRL 0x76430001
APIs of flush/clean all cache are supported
novatek_clock_init
sched_clock: 64 bits at 150MHz, resolution 6ns, wraps every 2199023255551ns
clocksource: arm_global_timer: mask: 0xffffffffffffffff max_cycles: 0x2298375bd0, max_idle_ns: 440795208267 ns
Switching to timer-based delay loop, resolution 6ns
FTTMR010 Driver Version: 1.0.1
clocksource: fttmr010_clksrc: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 159271703898 ns
fttmr010_clock_event_shutdown, shutdown tmr0
Console: colour dummy device 80x30
Calibrating delay loop (skipped), value calculated using timer frequency.. 300.00 BogoMIPS (lpj=1500000)
pid_max: default: 32768 minimum: 301
Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
CPU: Testing write buffer coherency: ok
Setting up static identity map for 0x8240 - 0x8298
Brought up 2 CPUs
SMP: Total of 2 processors activated (600.00 BogoMIPS).
CPU: All CPU(s) started in SVC mode.
devtmpfs: initialized
VFP support v0.3: implementor 41 architecture 3 part 30 variant 9 rev 4
NVTBOOTTS: nvt_bootts_init initial success
NVTBOOTTS: nvt_bootts_proc_init initial success
nvt_jiffies: system HZ: 100, pClk: 12000000
clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
futex hash table entries: 512 (order: 3, 32768 bytes)
pinctrl core: initialized pinctrl subsystem
NET: Registered protocol family 16
DMA: preallocated 256 KiB pool for atomic coherent allocations
cpuidle: using governor menu
nvt_otp_module_init
------------------------------
AXI0=500 AXI1=400 AXI2=350 HCLK=300
CPU=1200 DRAM=1864 DSP=600 CODEC=380
DISP0=297 DISP1=270 DISP2=54 CNN=600
MPLL8(VCAP)=465 SSP=344
------------------------------
SCSI subsystem initialized
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
clocksource: Switched to clocksource arm_global_timer
NET: Registered protocol family 2
TCP established hash table entries: 2048 (order: 1, 8192 bytes)
TCP bind hash table entries: 2048 (order: 2, 16384 bytes)
TCP: Hash tables configured (established 2048 bind 2048)
UDP hash table entries: 256 (order: 1, 8192 bytes)
UDP-Lite hash table entries: 256 (order: 1, 8192 bytes)
NET: Registered protocol family 1
RPC: Registered named UNIX socket transport module.
RPC: Registered udp transport module.
RPC: Registered tcp transport module.
RPC: Registered tcp NFSv4.1 backchannel transport module.
NetWinder Floating Point Emulator V0.97 (double precision)
workingset: timestamp_bits=14 max_order=16 bucket_order=2
squashfs: version 4.0 (2009/01/31) Phillip Lougher
exFAT: Version 1.2.9
jffs2: version 2.2. (NAND) © 2001-2006 Red Hat, Inc.
fuse init (API version 7.26)
io scheduler noop registered
io scheduler deadline registered (default)
io scheduler cfq registered
probe fe400000.gpio OK, at 0xfe700000, version:1.0.4.
probe fe420000.gpio OK, at 0xfe720000, version:1.0.4.
probe fe440000.gpio OK, at 0xfe740000, version:1.0.4.
probe fe640000.gpio OK, at 0xfe940000, version:1.0.4.
ftdmac030 fca00000.dma030: driver probed, irq 19, mapped at fca00000
Serial: 8250/16550 driver, 4 ports, IRQ sharing disabled
console [ttyS0] disabled
fe200000.uart: ttyS0 at MMIO 0xfe200000 (irq = 7, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
console [ttyS0] enabled
fe220000.uart: ttyS1 at MMIO 0xfe220000 (irq = 8, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
fe240000.uart: ttyS2 at MMIO 0xfe240000 (irq = 9, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
fe260000.uart: ttyS3 at MMIO 0xfe260000 (irq = 10, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
[drm] Initialized
brd: module loaded
loop: module loaded
NVT_SATA100_AHCI driver version 1.01.08 (0xF9E00000)(0xFDC00000)
nvt_sata100 f9e00000.sata: AHCI NVT GPIO LED control is enabled. (-1)(-1)(-1)(-1)(-1)
nvt_sata100 f9e00000.sata: forcing PORTS_IMPL to 0x1
nvt_sata100 f9e00000.sata: SSS flag set, parallel bus scan disabled
nvt_sata100 f9e00000.sata: AHCI 0001.0100 32 slots 1 ports 6 Gbps 0x1 impl platform mode
nvt_sata100 f9e00000.sata: flags: ncq sntf stag pm led clo only pmp pio slum part ccc
scsi host0: NVT_SATA100_AHCI
ata1: SATA max UDMA/133 mmio [mem 0xf9e00000-0xf9e00fff] port 0x100 irq 11
NVT_SATA100_AHCI driver version 1.01.08 (0xF9F00000)(0xFDD00000)
nvt_sata100 f9f00000.sata: AHCI NVT GPIO LED control is enabled. (-1)(-1)(-1)(-1)(-1)
nvt_sata100 f9f00000.sata: forcing PORTS_IMPL to 0x1
nvt_sata100 f9f00000.sata: SSS flag set, parallel bus scan disabled
nvt_sata100 f9f00000.sata: AHCI 0001.0100 32 slots 1 ports 6 Gbps 0x1 impl platform mode
nvt_sata100 f9f00000.sata: flags: ncq sntf stag pm led clo only pmp pio slum part ccc
scsi host1: NVT_SATA100_AHCI
ata2: SATA max UDMA/133 mmio [mem 0xf9f00000-0xf9f00fff] port 0x100 irq 12
nand_hw_init: round to 37500000 Hz
id =  0x20 0x40 0x18 0x20
at XmMtd_Test_FlashAccessInfo_init(), flashSizeMB: 0x10.
@nvt_flash_setup(), CONFIG_CLOSE_SPI_NAND_8PIN_4IO = y.
eFlashType: 22.
Flash Name: XM_XM25QH128C{0x204018), 0x1000000.
@XmSpiNor_BlkLockMgr_init(), nTotalBlks: 286.
lk=>6, 0x800000.
SRx val: {[1, 0x38], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601238.
spi020_nor fa900000.nor: mtd .name=spi_nor.0 .size=1000000(16M) .erasesize = 0x10000(64K)
spi020_nor fa900000.nor: 1-bit mode @ 48000000 Hz
mtd: no mtd-id
10 ofpart partitions found on MTD device spi_nor.0
at XMMtd_RegisterProtFreeRgn() index:0,offset:0xf80000,size:0x80000.
at XmMtd_Test_FlashAccessInfo_registerStatBlock(), addr: 0xF80000, startBlock: 248, erasesize: 0x10000.
at XmSpiNor_freeProtFrom() offset:0xF80000, level:6, mtd->size: 0x1000000.
port auto power off 0x8B943000
Creating 10 MTD partitions on "spi_nor.0":
0x000000000000-0x000000010000 : "loader"
0x000000010000-0x000000030000 : "fdt"
0x000000030000-0x000000050000 : "fdt.restore"
0x000000050000-0x0000000b0000 : "boot"
0x0000000b0000-0x000000420000 : "romfs"
0x000000420000-0x000000ba0000 : "usr"
0x000000ba0000-0x000000c10000 : "web"
0x000000c10000-0x000000f60000 : "custom"
0x000000f60000-0x000000f80000 : "logo"
0x000000f80000-0x000001000000 : "mtd"
libphy: Fixed MDIO Bus: probed
nvt_eth_env_probe: IO MEM res start 0xfcd00000
nvt_eth_env_probe: get IO MEM 0x8b9a0000
nvt_eth_env_probe: get pinmux 0x200
nvt_eth_env_probe: pinmux detect emb phy 0x200
DWC_ETH_QOS: Phy detected at ID/ADDR 1
nvt_probe: enter
nvt_probe: get pinmux 0x200
NVT EMB phy route to MAC1
Get remap addr 0x8b973000
libphy: dwc_phy: probed
port auto power off 0x8B94B000
nvt_resume: enter
netif_napi_add() called with weight 128 on device eth%d
Supports TSO, SG and TX COE
Supports RX COE and GRO
Supports Poe Control
PPP generic driver version 2.4.2
PPP BSD Compression module registered
PPP Deflate Compression module registered
PPP MPPE Compression module registered
NET: Registered protocol family 24
usbcore: registered new interface driver zd1201
usbcore: registered new interface driver rndis_wlan
usbcore: registered new interface driver asix
usbcore: registered new interface driver ax88179_178a
usbcore: registered new interface driver cdc_ether
usbcore: registered new interface driver net1080
usbcore: registered new interface driver rndis_host
usbcore: registered new interface driver cdc_subset
usbcore: registered new interface driver zaurus
GobiNet: Quectel_Linux&Android_GobiNet_Driver_V1.6.1
usbcore: registered new interface driver GobiNet
usbcore: registered new interface driver cdc_ncm
ata1: hard resetting link
usbcore: registered new interface driver qmi_wwan
ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
ehci-nvtivot f9100000.u2host: usbhc-nvtivot
ehci-nvtivot f9100000.u2host: new USB bus registered, assigned bus number 1
ehci-nvtivot f9100000.u2host: irq 23, io mem 0xf9100000 mapped 8b975000
ehci-nvtivot f9100000.u2host: USB 2.0 started, EHCI 1.00, overcurrent ignored
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 1 port detected
ehci-nvtivot f9200000.u2host: usbhc-nvtivot
ehci-nvtivot f9200000.u2host: new USB bus registered, assigned bus number 2
ehci-nvtivot f9200000.u2host: irq 27, io mem 0xf9200000 mapped 8b9b3000
ata2: hard resetting link
ehci-nvtivot f9200000.u2host: USB 2.0 started, EHCI 1.00, overcurrent ignored
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 1 port detected
usbcore: registered new interface driver cdc_wdm
usbcore: registered new interface driver usb-storage
usbcore: registered new interface driver usbserial
usbcore: registered new interface driver usbserial_generic
usbserial: USB Serial support registered for generic
usbcore: registered new interface driver option
usbserial: USB Serial support registered for GSM modem (1-port)
usbcore: registered new interface driver qcserial
usbserial: USB Serial support registered for Qualcomm USB modem
usbcore: registered new interface driver usb_serial_simple
usbserial: USB Serial support registered for carelink
usbserial: USB Serial support registered for zio
usbserial: USB Serial support registered for funsoft
usbserial: USB Serial support registered for flashloader
usbserial: USB Serial support registered for google
usbserial: USB Serial support registered for libtransistor
usbserial: USB Serial support registered for vivopay
usbserial: USB Serial support registered for moto_modem
usbserial: USB Serial support registered for motorola_tetra
usbserial: USB Serial support registered for novatel_gps
usbserial: USB Serial support registered for hp4x
usbserial: USB Serial support registered for suunto
usbserial: USB Serial support registered for siemens_mpi
mousedev: PS/2 mouse device common for all mice
nvt_rtc_chk_power: enter
nvt_rtc_chk_power: RTC ready timeout, plz check 32K OSC on PCB
nvt_rtc fe880000.rtc: rtc core: registered nvt_rtc as rtc0
i2c /dev entries driver
NVT I2C0 Driver Version: 1.0.0(hdmi:no) irq 43, mapped at fe600000
NVT I2C1 Driver Version: 1.0.0(hdmi:no) irq 44, mapped at fe620000
NVT I2C2 Driver Version: 1.0.0(hdmi:no) irq 45, mapped at fe640000
NVT I2C3 Driver Version: 1.0.0(hdmi:no) irq 46, mapped at fe660000
NVT I2C4 Driver Version: 1.0.0(hdmi:no) irq 47, mapped at fe680000
NVT I2C5 Driver Version: 1.0.0(hdmi:no) irq 48, mapped at fe6a0000
thermal thermal_zone0: thermal_ctrl 0x0000000b
thermal thermal_zone0: tempature 0x000000f8
xmauto = 1,Will nvt_wdt_start
usbcore: registered new interface driver usbhid
usbhid: USB HID core driver
NET: Registered protocol family 17
ThumbEE CPU extension supported.
Registering SWP/SWPB emulation handler
nvt_rtc fe880000.rtc: hctosys: unable to read the hardware clock
VFS: Mounted root (squashfs filesystem) readonly on device 31:4.
devtmpfs: mounted
Freeing unused kernel memory: 268K
This architecture does not have kernel memory protection.
random: fast init done
Mounting root fs rw ...
mount: can't read '/proc/mounts': No such file or directory
Mounting other filesystems ...
Bringing up interfaces ...
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>at mtdchar_ioctl() <case XMMTD_GETLOCKVERSION> xmVersion:0x1001.
>>=>ibwlan version: 1.0.0 - Complie time Dec  7 2020 20:40:52, wpa-psk
watchdaog is creat???
WatchdogCreate_noLock
flash/flash.c(145) [Flash_getLockVersion]: version:0x1001!
-----------------------------------------------------------kwrap: loading out-of-tree module taints kernel.

        Boot NVR_MODE=0
-------------------------------------nvt_vos: 1.00.005 (Apr 26 2021 10:22:43)
----------------------
NVTMEM: register misc device successfully!
NVTMEM: 0.0.5
log.ko v2.7: Apr 26 2021 10:22:50 (mmap 0x88e00000 size 0x78000 vmalloc 0)

LOG base 0x88d60000(ddr0) size 64K (start pointer 0x7e832014)
PAGE_OFFSET(0x80000000) VMALLOC START(0x8b800000) HZ(100)
ms: module license 'NVT' taints kernel.
ms.ko v2.33 Apr 26 2021 10:22:55
em.ko v2.21 Apr 26 2021 10:22:55
em_user v2.0 Apr 26 2021 10:22:55
Start EM thread 0(em_callback) with nice -20
TVE100: PA = 0xfad00000, VA = 0x8bb4e000, size:0x1000 bytes
Start EM putjob (em_putjob) with nice -20
TVE 100 INIT OK.
HDMI(fd900000.hdmi20): paddr:0xfd900000, vaddr:0x8bb66000, drv version:1.1.17.
hdmi20 driver version:1.1.17

LCD300 platform: Hook NA51068 driver.
lcd300: suspend_state:1

LCD210 platform: Hook NA51068 driver.
LCD200:0: suspend_state:1
HI_CHIP_NT832X addr = 0
HI_CHIP_NT832X =0
i2c_client_init0!!
at24c driver init successful!
 ===============================================================
 ===============================================================
at24c driver init start ...
gpio_i2c_wread_24c16 0x00:d2
gpio_i2c_read_24c16 0x01:d4
FVIDEO driver init start ...
HI_CHIP_HI3521d
HI_CHIP_HI3521d   -1973771744
i2c_client_init0!!
ext0_clk driving 2
fvideo driver init successful!
 ===============================================================
| BM8563: Compiled by zhangyangyang at Apr  1 2021 09:35:11 |
 ===============================================================
HI_CHIP_NT832X addr = 0 I2cAddr = 0xa2
HI_CHIP_NT832X=0
sbcore: registered new interface driver rt2870
31mWdtMonitor.c(64) [app_auto]: Get xmauto Fialed ,xmauto = 1
M2D] version :1.03.22 init done vbase 0x8C806000, pbase 0xFAA00000 0x88681600 36
[0m/var/SifiaIsRun No Run 1/1202.12
ssca_module_init:16 Host#0 Version: 0.2.4
ssca_probe:SSCA ver:0.01.10 initial done1 10:22:55
gs.ko v2.45 Apr 26 2021 10:22:55
GS driver, log: level(0) category(0) bmp width(64)
usr.ko v2.13 Apr 26 2021 10:22:55
vpd.ko v2.67 (gmlib->ioctl v1.14) Apr 26 2021 10:22:55
datain v2.6 (minors 176 : 0x2 + 2) Apr 26 2021 10:22:55
dataout v2.3 (minors 192 : 0x2 + 0) Apr 26 2021 10:22:55
clearwin mode 0 v3.1 Apr 26 2021 10:22:550.1.43.0 built @ Apr 26 2021 10:22:50
[VD]Decoder flow v1.0.15.0, built @ Apr 26 2021 10:22:55
fc400000.nvt_arb 1.02.2 Apr 26 2021 10:22:50
0. resource:0xfc400000 size:0xa00000940 fire_mode = Link-List
1. resource:0xfd600000 size:0xa000on: 0.0.009 Apr 26 2021 10:22:55
IRQ 0. ID26.c(473) [ProtectInfoFile_readCmp]: <01>:pStrBuf:install prealloc ok
DevID Major:249 minor:0dBuf:0xcabde21a00327b63..
Arbiter addr 0xfc400000 0x8c970000e_readCmp]: <01>:if(!strcmp(readBuf, strBuf)):0xcabde21a00327b63..
SEM ID: 0x7ee89480 [FlashProtect_judge]: ProtectInfoFile_readCmp <OK 01>!
ddr_arb_platform_create_resource: exit
nvt_ddr_arb_drv_init: resource doneto Fialed ,xmauto = 1
nvt_irdet_module_init:
nvt_irdet_probe:0. resource:0xfe540000 size:0x1000
nvt_irdet_probe:IRQ 0. ID17
nvt_irdet_probe:DevID Major:248 minor:0
CMD:i2c 0x11011
doing mdev-s
done!!
idx:3
ifconfig: ioctl 0x8913 failed: No such device
ifconfig: SIOCSIFADDR: No such device
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>>>=>ibwlan version: 1.0.0 - Complie time Dec  7 2020 20:40:52, wpa-psk
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>>>=>ibwlan version: 1.0.0 - Complie time Dec  7 2020 20:40:52, wpa-psk
@TimeCheck Will Sleep 30
Dogtest▒▒Complie time Jun 20 2022 20:26:44
pthread_create UsbNet_thrd OK!
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>>>=>ibwlan version: 1.0.0 - Complie time Dec  7 2020 20:40:52, wpa-psk
year: 100, month: 0, day: 1, wday: 0, hour: 0, minute: 0, second: 42
/var/SifiaIsRun No Run 2/120
/var/SifiaIsRun No Run 3/120
random: crng init done
/var/SifiaIsRun No Run 4/120
phydev exist: resume phy
nvt_resume: enter
DWC_ETH_QOS_yinit: assume APB 120 MHz
DWC_ETH_QOS_yinit: apb_clk 120000000 Hz
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>Queue0 Tx fifo size 16384, Rx fifo size 16384
>>=>ibwlan version: 1.0.0 - Complie time Dec  7 2020 20:40:5Disabled JUMBO pkt
2, wpa-psk
Enabled Rx watchdog timer
Enabled TSO
Disabled Rx Split header mode
phydev exist: start phy
atmagic[0]=d2,atmagic[1]=d4, ret[0], cptat24c_fd[4]
/etc/init.d/rcS: line 79: /mnt/custom/extapp.sh: not found
PPPD: Start PPPD deamon, Version 1.0.0 Build Time: May 18 2017 23:08:04
 =============================================================
| PPPD: SVN:11,Compiled by shaoweidong at May 18 2017 23:08:04 |
 =============================================================
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
/var/SifiaIsRun No Run 5/120
CryptoDecrypt,565 or_sel=1
LibCrypto : g_cryptotype = 1, a24
CryptoDecrypt,565 or_sel=1
phydev exist: resume phy
nvt_resume: enter
DWC_ETH_QOS_yinit: assume APB 120 MHz
DWC_ETH_QOS_yinit: apb_clk 120000000 Hz
Queue0 Tx fifo size 16384, Rx fifo size 16384
Disabled JUMBO pkt
Enabled Rx watchdog timer
Enabled TSO
Disabled Rx Split header mode
phydev exist: start phy
nvt_resume: enter


"netinit help" for help

eth0:
<eth0> IP: <192.168.86.18>      <eth0>  netmask: <255.255.255.0>
net/net.c(1668) [NetSetHostIP]: pEthName: eth0, pHostIP: 192.168.86.18, pNetmask: 255.255.255.0.
net/net.c(1122) [SaveEthAttrInFile]: filename: /mnt/mtd/Config/network, buf: HOSTIP = 192.168.86.18
SUBMASK = 255.255.255.0
GATEWAYIP = 192.168.86.1
 <Write01>
net/net.c(1122) [SaveEthAttrInFile]: filename: /mnt/mtd/Config/network, buf: HOSTIP = 192.168.86.18
SUBMASK = 255.255.255.0
GATEWAYIP = 192.168.86.1
 <Write01>
<eth0> Gateway: <192.168.86.1>
eth_device[0].name:eth0
net/net.c(1122) [SaveEthAttrInFile]: filename: /mnt/mtd/Config/network, buf: HOSTIP = 192.168.86.18
SUBMASK = 255.255.255.0
GATEWAYIP = 192.168.86.1
 <Write01>

PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
/var/SifiaIsRun No Run 6/120
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
/var/SifiaIsRun No Run 7/120
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>>>=>ibwlan version: 1.0.0 - Complie time Dec  7 2020 20:40:5at mtdchar_ioctl() <case XMMTD_GETLOCKVERSION> xmVersion:0x1001.
2, wpa-psk
flash/flash.c(145) [Flash_getLockVersion]: version:0x1001!
@SrvDebug: Get Ctrl Fialed, Def: 1.
dvrHelper.c(60) [App_isAutoRun]: Get xmauto Fialed, xmauto = 1, res:-1.
killall: timetest: no process killed
misc/sys.c(1477) [InvokeSystemRunScript]: run shell script fail, script exit code: 1
DDDHelper: Close Dbg Failed: No such file or directory!
dvrHelper version: Jun 20 2022
dvrHelper.c(60) [App_isAutoRun]: Get xmauto Fialed, xmauto = 1, res:-1.
/usr/sbin/SofiaRun.sh is starting ...
LibCrypto : g_cryptotype mem= 1, a24
at mtdchar_ioctl() <case XMMTD_GETLOCKVERSION> xmVersion:0x1001.
i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
/var/SifiaIsRun No Run 8/120Output extra 9 SCL clocks to release device hang!

i2c#1 iaddr:0x88 write failed!!
i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
Output extra 9 SCL clocks to release device hang!
i2c#1 iaddr:0x88 read failed!!
i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
Output extra 9 SCL clocks to release device hang!
i2c#1 iaddr:0x88 write failed!!
i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
Output extra 9 SCL clocks to release device hang!
i2c#1 iaddr:0x88 read failed!!
i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
Output extra 9 SCL clocks to release device hang!
i2c#1 iaddr:0x88 read failed!!
DDR  Type   Size       Addr          Name               Shared Pool
 0    028    1352KB   0x0B400000   enc_scl_out
 0    000   16200KB   0x0B552000   disp0_in
 0    107    4080KB   0x0C524000   disp0_fb
 0    001     812KB   0x0C920000   disp1_in
 0    102    1260KB   0x0C9EB000   tmnr_motion
 0    033   14456KB   0x0CB26000   common
 0    024    9788KB   0x0D944000   disp_dec_in
 0    029   12388KB   0x0E2D3000   enc_out
 0    103    4860KB   0x0EEEC000   osg
 0    025   45024KB   0x0F3AB000   disp_dec_out         disp0_cap_out
 0    027   75552KB   0x11FA3000   enc_cap_out
 0    034   17012KB   0x1CDAB000   user_blk
 0    031     200KB   0x1DE48000   au_enc
 0    032      40KB   0x1DE7A000   au_dec
(28)enc_scl_out_ddr0 DDR0(1352KB)
(00)disp0_in_ddr0 DDR0(16200KB)
(01)disp1_in_ddr0 DDR0(812KB)
(33)common_ddr0 DDR0(14456KB)
(24)disp_dec_in_ddr0 DDR0(9788KB)
(29)enc_out_ddr0 DDR0(12388KB)
(103)osg_ddr0 DDR0(4860KB)
(25)disp_dec_out_ddr0 DDR0(45024KB)
(06)disp0_cap_out_ddr0 DDR0(0KB)
(27)enc_cap_out_ddr0 DDR0(75552KB)
(34)user_blk_ddr0 DDR0(17012KB)
(31)au_enc_ddr0 DDR0(200KB)
(32)au_dec_ddr0 DDR0(40KB)
gm2d_file_mmap:gfx size:0x5000 io_size:0x1000 page_off:0x0 mapping_type:0x0
CryptoDecrypt,565 or_sel=1
SERIES_TYPE = 3
PRODUCTION_MODEL = 0xf0
flash/flash.c(145) [Flash_getLockVersion]: version:0x1001!
osmemsize:b400000 pBootArgs 0xb400000
Jul 28 2022 20:43:21 ==>CaptureGetJsonValue(586): debug assertion failure (0 == access(CONFIG_JSON, F_OK))
Jul 28 2022 20:43:21 ==>CaptureGetCustom(645): debug assertion failure (ret == 0)
**********************************************************************
|                      SYSTEM INFO
|  libcpypto version:           1.0.1 svn 596-chenbo Complie time May 11 2021 20:16:53
|          slave_num:           0
| mast video channel:           8
| mast audio channel:           4
|slave video channel:           0
|slave audio channel:           0
|         alarm mode:           Com in-0 out-0
|        master chip:           0x0010
|   production model:           0x00f0
|        disk number:           0x0002
**********************************************************************
cpu_type:16
Fvideo: SampleChipType_V1,Line 781,~~~~~~~~~~~~~~~~~~~~~~6168C
Fvideo: SampleChipType_V1,Line 812,~~~~~~~~~~~~~~~~~~~~~~G_Pthread_Enable=1
playbackSize 46104576 previewSize 32272384
ddr_usage[0] 12a84000 sys_hdal.size[0] 14c00000
372-GM2D_DRV_LIB_VER:1.03.21
GM2D ID:0x20190903driver_init_device: 372EP0 is inactive
use default HVR config.
================dump_hvrcap()================
                Analog-n4KChn:      0
                Analog-n5MChn:      0
                Analog-n4MChn:  0
                Analog-n3MChn:      0
                Analog-n1080PChn:  0
                Analog-n5M_NChn:        8
                Analog-n4M_NChn:        0
                Analog-n1080NChn:  0
                Analog-n720PChn:   0
                Analog-n960HChn:   0
                Analog-nD1Chn:     0
                Analog-nHD1Chn:    0
                Analog-nCIFChn:    0
                Digital-n4KChn:    0
                Digital-n5MChn:    0
                Digital-n4MChn:    0
                Digital-n3MChn:    0
                Digital-n1080PChn: 0
                Digital-n1080NChn: 0
                Digital-n960PChn:  0
                Digital-n720PChn:  0
                Digital-n960HChn:  0
                Digital-nD1Chn:    0
                Digital-nHD1Chn:   0
                Digital-nCIFChn:   0
                AnalogCap-nPlayChn:   4
                AnalogCap-nDigiTalChn:   0
                DigitalCap-nPlayChn:   4
                DigitalCap-nDigiTalChn:   0
use default HVR config.
================dump_hvrcap()================
                Analog-n4KChn:      0
                Analog-n5MChn:      0
                Analog-n4MChn:  0
                Analog-n3MChn:      0
                Analog-n1080PChn:  0
                Analog-n5M_NChn:        8
                Analog-n4M_NChn:        0
                Analog-n1080NChn:  0
                Analog-n720PChn:   0
                Analog-n960HChn:   0
                Analog-nD1Chn:     0
                Analog-nHD1Chn:    0
                Analog-nCIFChn:    0
                Digital-n4KChn:    0
                Digital-n5MChn:    0
                Digital-n4MChn:    0
                Digital-n3MChn:    0
                Digital-n1080PChn: 0
                Digital-n1080NChn: 0
                Digital-n960PChn:  0
                Digital-n720PChn:  0
                Digital-n960HChn:  0
                Digital-nD1Chn:    0
                Digital-nHD1Chn:   0
                Digital-nCIFChn:   0
                AnalogCap-nPlayChn:   4
                AnalogCap-nDigiTalChn:   0
                DigitalCap-nPlayChn:   4
                DigitalCap-nDigiTalChn:   0
**************************************************
| LIBHICAP: Compiled at Jul 28 2022 20:43:20  SVN:3631
|TOTAL_VI_CHN_NUM                       8
|TOTAL_VENC_CHN_NUM                     16
|VENC_CHN_NUM_HOST_CHIP                 16
|TOTAL_AI_CHN_NUM                       8
|TOTAL_AENC_CHN_NUM                     8
|AENC_CHN_NUM_HOST_CHIP                 8
|HDEC_CHN_NUM                           4
|VDEC_CHN_NUM                           4
|HVR_PLAY_DECODE_NUM                    4
|HVR_DIGITAL_DECODE_NUM                 0
**************************************************
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>>>=>ibwlan version: 1.0.0 - Complie time Apr 10 2021 10:03:57, wpa-psk


Sofia: $Version_fix: R11, $Source svn: 30502, $Include svn: 41183, $Build svn: 41181, Exchange svn: 41170, Build in:Jul 30 2022, 14:38:27, 0
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
misc/sys.c(563) [NT8321_getBoardType]: @ Get 0xfe040004 = 0xd16aaab8
0_15:[0x0]


Infra: $base Dir Trunk, $Source svn: 39231, $Include svn: 2915, $Build in:Mar 17 2022, 10:17:44
CInfra::start()>>>>>>>>>>
CTimerManager::CTimerManager()>>>>>>>>>
CThreadManager::CThreadManager()>>>>>>>>>

libManager.a: $base Dir D_General_Manager_V4.02.0.R11_20130906, $Source svn: 41057, $Include svn: 30262, $Build in:Jun 28 2022, 20:03:41

CConfigManager::start()...
CVerifyConfig::Start()...
CDefaultConfig::Start()...
CConfigManager::getConfig 'NetWork.NetDNS', but default config is not set yet!

===new timezone__180__,old timezone__0___========

CTime::setTimeZone(180):TWD+3:00
onVerifyNetIPFilter() ../../Manager/VerifyConfig.cpp 1306
onVerifyNetDHCP() ../../Manager/VerifyConfig.cpp 1312
onVerifyNetDDNS() ../../Manager/VerifyConfig.cpp 1317
onVerifyNetEmail() ../../Manager/VerifyConfig.cpp 1322
custom config NetWork.RemoteDevice verify failed with ret:20!
GUITheme List:General
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
misc/sys.c(697) [GetBoardHardwareVersion]: @ Get 0xfe040004 = 0xd16aaab8
misc/sys.c(709) [GetBoardHardwareVersion]: @ Get 0_26 = 0x0
ethMac:00:12:42:64:db:f8

==timezone:180==0=

CTime::setTimeZone(180):TWD+3:00
CConfigManager::setConfig(System.TimeZone, )
CConsole::start()...
==>libdvr:SystemTimeToRtcTimeSet called.
watchdog/wdt.c(58) [app_auto]: Get xmauto Fialed ,xmauto = 1
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
PPPD: Open /mnt/mtd/Config/ppp/pppoe-enable file failed!
PPPD: Disable PPPOE!
nvt_irdet_drv_open:0
nvt_irdet_api_write_receiver_test:pinmux is not set
nvt_irdet_api_write_receiver_test:NEC protocol
nvt_irdet_proc_cmd_open:
nvt_irdet_proc_cmd_write:CMD:w ch 8
lk=>2, 0x80000.
lk=>6, 0x800000.
CMagicBox::start()...
ethMac:00:12:42:64:db:f8
--- use v3 SN --- SN:907278faf17e3b8i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001884
cndr3 -- year:2022 rand:0

initOEMinfo-->1674,[Source/MagicBoxi2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
.cpp],m_oemInfo[BURN_OEM_ID]9,m_oemInfo[BURN_OEM_PRODUCT]0,m_oemOutput extra 9 SCL clocks to release device hang!
Info[BURN_OEM_SERIAL]0
pCaps->HasAudioBoard 4
misc/sys.c(i2c#1 iaddr:0x64 write failed!!
405) [SystemGetBoardType]:  ====================================i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
===========================
misc/sys.c(406) [SystemGeti2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
BoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr Output extra 9 SCL clocks to release device hang!
 8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardTypei2c#1 iaddr:0x64 read failed!!
]:  ============================================================i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
===
CurrentTime:1999-12-31 21:00:48
FlashTime:2025-07-22 0i2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
7:14:40
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$CMOS NO PWOER$$$$$$$Output extra 9 SCL clocks to release device hang!
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
RecoverFlash Time:2025-07-22 07:i2c#1 iaddr:0x64 write failed!!
15:05
gmtime :125-6-22, today is weekday 2
time:10:15:5
====i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
========================================================?tm->tm_i2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
year = 25
libdvr SystemTimeToRtcTimeSet
CTime::setCurrentTime Output extra 9 SCL clocks to release device hang!
SystemTimeToRtcTimeSet to 2025-07-22 07:15:05
Log Manager starti2c#1 iaddr:0x64 read failed!!
ing....!

Log.a: $base Dir Trunk, $Source svn: 37523, $Include svn: 2919, $Build in:Jun 16 2020, 10:46:21

=======Shut Down at 2025-7-22 07:14:40 with m_exitState[1]
CDaylight::start()...
m_cloudExAbility:0
watchdaog is creat???
1111111111111i = 0
@CDevAbility::start()>>>>>>>>>>
HasIntelFunc: 1, HasCPCFunc: 0, HasNatFunc: 1, HasSpotFunc: 0, HasBaseFunc: 0, HasEnBaseFunc: 0, HasHVRFunc:0, FrontSwithType:1, system_func.NoHasDeep:1, cpu:43
CConfigManager::getConfig 'Ability.PreHVRCapMode', but default config is not set yet!

Start-->1331,[../../Manager/DevAbility.cpp],m_eNVRSwitchMode[0x00000004],ability_D1[0],m_cpuAbility[20],m_iNumMainStream[0],m_maxD1Num[1]
m_nVTotalChns: 8, m_nVCapChns: 8, m_nVPlayChns: 4, m_nDigDecChns: 0
CConfigManager::getConfig 'fVideo.AudioAcquisitionMode', but default config is not set yet!
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
CConfigManager::setConfig(Ability.DigitalReal, )
CConfigManager::setConfig(NetWork.DigManagerShow, )
CFrontboard::CFrontboard()>>>>
FbdCreateInit Successful /dev/ttyS1
uart/fbd.c(910) [Fbd_NOMCUCreate]: 0xfe040000:0xaa96aaa0
uart/fbd.c(915) [Fbd_NOMCUCreate]: 0xfe040000:0xaa96aaa0
uart/fbd.c(918) [Fbd_NOMCUCreate]: 0xfe040010:0xaa69a
uart/fbd.c(922) [Fbd_NOMCUCreate]: 0xfe040010:0xa0692
uart/fbd.c(333) [UpDateMessage]: UpDateMessage success
uart/fbd.c(425) [UpDateMessage]:
COL_COUNT=5,ROW_COUNT:5,COL_COUNT=5,ROW_COUNT5
CFrontBoardParser::Init()>>>>>>>>>
0xfe040010:[0xa0692]
path = /usr/bin/Squirrel/pad
sProtocolName: General
CFrontBoardParser::Init()>>>>>>>>>
path = /usr/bin/Squirrel/remote
sProtocolName: General


Manager: $Rev: 1008 $, Build in:Jul 30 2022, 14:23:33
CManager::start()>>>>>>>>>>

Launched at Local Time 2025/7/22 07:15:11!
CUserManager::start......
onVerifyNetIPFilter() ../../Manager/VerifyConfig.cpp 1306
CAutoMaintain::Start()...
m_randomDelayMinutes:9
CConfigManager::getConfig 'Network.WebLoginEncrypt', but default config is not set yet!
Debug Tld: remove aMainFile Failed, Err: No such file or directory.
Debug Tld: remove aSecFile Failed, Err: No such file or directory.
misc/env.c(562) [set_do_setenv]: set nrdnx_ver =
misc/env.c(562) [set_do_setenv]: set pslgn_ver =
CPacketManagerImp::CPacketManagerImp()>>>>>>>>>
sm_packetBuf null use self heap memory!
Adjust Page!
Packet usage : 0K / 12287K, 0%

----------------------[07-22 07:15:11]
CCaptureBuffer::Init size = 256 KB
======= pre record buf 256
Fvideo: VideoCreate,Line 1724,=========================================================================
Fvideo: VideoCreate,Line 1725,| LIBFVIDEO: Customer is General
Fvideo: VideoCreate,Line 1726,| LIBFVIDEO: Compiled at GM_ffb: [ver:1.2.1]INIT flcd300 OK.
LCD300(0): PA = 0xfda00000, VA = 0x8c9a0000, size:0x10000 bytes, dfb_size=0
LCD300(0): deskres(3):1024x768(XVGA), output(46):HDMI_1024x768_RGB
hdmi_setting, target is HDMI_1024X768P60.
hdmi_polling_thread is running.
LCD300: Common Driver[Ver: 1.1.20]
hdmi_polling_thread, apply new vid:163 setting.

LCD300(0) registers 1 entities to video graph!
LCD300(0): Driver[Ver: 2.1.24] init ok, Chip Ver[0x20190731, 0x3210310], fb0_fb1_share:0
LCDC300(0) enters IDLE mode.
platform_set_pinmux_videosrc = 0, 0
platform_set_pinmux_videosrc = 0, 3
platform_set_pinmux_videosrc = 0, 10
LCD200:0: Desk resolution is NTSC.
GM_ffb: [ver:0.1.23]INIT flcd200 OK.
LCD200:0: PA = 0xfdb00000, VA = 0x8cb60000, size:0x10000 bytes
LCD200(0): deskres(0):NTSC, output(0):NTSC_SDTV
vdac_setting, target is TV_NTSC.
LCD200:0: Desk resolution is NTSC.
LCD200:0 registers 1 entities to videograph!
LCD200(0): Driver[Ver: 2.0.34] init ok, fb_max_width:720, fb_max_height:480, fb0_fb1_share:0
LCD200:0 chip_state:1
LCD200:0, pmu clock:1
Jun  8 2022 09:15:16
Fvideo: VideoCreate,Line 1727,=========================================================================
Fvideo: VideoCreate,Line 1732,>>>>>>>>>>>>VideoCreate LINE1732  PRODUCTION_MODEL=0xf0
Fvideo: VideoCreate,Line 1741,>>>>>>>>>F_VI_CHN_NUM_HOST_CHIP=8 VI_CHN_NUM_HOST_CHIP=8
Fvideo: VideoCreate,Line 1742,>>>>>>>>>F_AI_CHN_NUM_HOST_CHIP=4 AI_CHN_NUM_HOST_CHIP=4
Fvideo: GetCpuChipType,Line 1603,GetCpuChipType:CPU CHIP TYPE IS NVT98321
Fvideo: fvideo_register,Line 1516,fvideo_register:Register operation to 6168
Fvideo: nvp61xx_get_ad_maxchannel,Line 4028,get max channel num = 8
Fvideo: nvp6158_videoModeInit,Line 5850,Get system captureSize set is  30,NVP6158_OUTMODE=15,CAPTURE_SIZE_5M_N
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[0]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[1]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[2]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[3]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[0]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[1]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[2]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[3]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6168_audio_re_initialize,Line 24618,Audio init!! Audio sampling rate=8000~~~chip_num=0 AudioType = 0
Fvideo: nvp6158_audio_default_set,Line 5358, audio ch =8
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[4]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[5]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[6]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[7]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[4]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[5]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[6]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[7]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6168_audio_re_initialize,Line 24618,Audio init!! Audio sampling rate=8000~~~chip_num=1 AudioType = 0
Fvideo: nvp6158_audio_default_set,Line 5358, audio ch =8
NVP6168/C reset AD channel ad addr=0x60
NVP6168/C reset AD channel ad addr=0x62
>>>>change channel[0] = 0
>>>>change channel[1] = 1
>>>>change channel[2] = 2
>>>>change channel[3] = 3
>>>>change channel[4] = 4
>>>>change channel[5] = 5
>>>>change channel[6] = 6
>>>>change channel[7] = 7
VideoOut SetInit Resolution:1024x768
lcd1 not support to set fb0
lcd1 not support to set fb2


Gdi: $base Dir Trunk, $Source svn: 39831, $Include svn: 2831, $Build in:Aug  9 2021, 20:09:10
CGDI::start()>>>>>>>>

@=================================
kdrv_audioio_open, ssp_used  = 2
kdrv_audioio_open, Use ssp 1 as record route
dsp_init_one [0] version 1.00.14
audio subsystem ver:0.0.3
<AUDIO_DSP> RegFile location is 0x8a564000
<AUDIO_DSP> Check DSP State..., 0x66660000
<AUDIO_DSP> DSP State, 0x66660000
<AUDIO_DSP> DSP Ver is 20200716
<AUDIO_DSP> Reg_table_sz from DSP is 6708, from host is 6708
<AUDIO_DSP> audio_dsp_drv: ddr id:0 pa:9100000 va:89100000 sz:1b800
<AUDIO_DSP> SSP 1 record_ddr_0 addr = 9100000, va: 89100000
<AUDIO_DSP> SSP 1 record_ddr_1 addr = 9102800, va: 89102800
<AUDIO_DSP> SSP 1 record_ddr_2 addr = 9105000, va: 89105000
<AUDIO_DSP> SSP 1 record_ddr_3 addr = 9107800, va: 89107800
<AUDIO_DSP> SSP 1 record_ddr_4 addr = 910a000, va: 8910a000
<AUDIO_DSP> SSP 1 record_ddr_5 addr = 910c800, va: 8910c800
<AUDIO_DSP> SSP 1 record_ddr_6 addr = 910f000, va: 8910f000
<AUDIO_DSP> SSP 1 record_ddr_7 addr = 9111800, va: 89111800
<AUDIO_DSP> SSP 1 play_ddr addr = 0x9114000, va: 89114000
fmem: 0x10 not mapped in pte!
<AUDIO_DSP> audio_dsp_drv: ddr id:0 pa:ffffffff va:10 sz:0
DSP:card1, record total buffer size: 81984, accumulate: 81984 bytes.
DSP:card1, playback total buffer size: 10240, accumulate: 92224 bytes.
DSP:ssp card1(0xfa320000) is probed, capability: 0x3.
<AUDIO_DSP> WAIT DSP TEST
<AUDIO_DSP> DSP is running
dsp_init_done
<AUDIO_DSP>  WAIT DSP REMOVE
<AUDIO_DSP> DSP REMOVE OK
kdrv_audioio_open, ssp_used  = 2
kdrv_audioio_open, Use ssp 1 as record route
dsp_init_one [0] version 1.00.14
audio subsystem ver:0.0.3
<AUDIO_DSP> RegFile location is 0x8a564000
<AUDIO_DSP> Check DSP State..., 0x66660000
<AUDIO_DSP> DSP State, 0x66660000
<AUDIO_DSP> DSP Ver is 20200716
<AUDIO_DSP> Reg_table_sz from DSP is 6708, from host is 6708
<AUDIO_DSP> audio_dsp_drv: ddr id:0 pa:9100000 va:89100000 sz:1b800
<AUDIO_DSP> SSP 1 record_ddr_0 addr = 9100000, va: 89100000
<AUDIO_DSP> SSP 1 record_ddr_1 addr = 9102800, va: 89102800
<AUDIO_DSP> SSP 1 record_ddr_2 addr = 9105000, va: 89105000
<AUDIO_DSP> SSP 1 record_ddr_3 addr = 9107800, va: 89107800
<AUDIO_DSP> SSP 1 record_ddr_4 addr = 910a000, va: 8910a000
<AUDIO_DSP> SSP 1 record_ddr_5 addr = 910c800, va: 8910c800
<AUDIO_DSP> SSP 1 record_ddr_6 addr = 910f000, va: 8910f000
<AUDIO_DSP> SSP 1 record_ddr_7 addr = 9111800, va: 89111800
<AUDIO_DSP> SSP 1 play_ddr addr = 0x9114000, va: 89114000
<AUDIO_DSP> audio_dsp_drv: ddr id:0 pa:a2c0000 va:8a2c0000 sz:14000
<AUDIO_DSP> SSP 6 play_ddr addr = 0xa2c0000, va: 8a2c0000
DSP:card1, record total buffer size: 81984, accumulate: 81984 bytes.
DSP:card1, playback total buffer size: 10240, accumulate: 92224 bytes.
DSP:ssp card1(0xfa320000) is probed, capability: 0x3.
DSP:card6, playback total buffer size: 61440, accumulate: 153664 bytes.
DSP:ssp card6(0xfe4c0000) is probed, capability: 0x2.
<AUDIO_DSP> WAIT DSP TEST
<AUDIO_DSP> DSP is running
dsp_init_done
VIDEODECODER: m_newDataBuf[819] m_netCapBuffer[1638]
enc_out_ddr0 (12388KB):
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0   1625KB (win_size 810KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
  DDR0    222KB (win_size 111KB)
     Total Needs 14784KB (oversize)
Reduce to:reduce_ratio=83
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0   1349KB (win_size 810KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
  DDR0    184KB (win_size 111KB)
     Total Needs 12271KB
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
         @mem = 0x0x744bd000 0x0x744bd000 0x(nil)
         @pitch = 2048
         @width = 1024
         @height = 768
         @foramt = 0
@===================================
CLocales::CLocales()>>>>>>>>>
CFontManager::CFontManager()>>>>>>>>>
CFontManager::CFontManager Open FontGB2312 File Failed!
Language load path:/mnt/custom/data/Strings/Portugal
CConfigManager::getConfig 'General.SupportLang', but default config is not set yet!
GUI Use Theme:default
                PageConfigIOTDevice
                PageConfigIOTScene
                PageConfigBlindDetect
                PageConfigLossDetect
                PageConfigAlarm
                PageAlarmOut
                PageConfigVideoAnalyze
                PageDigitalConfig
                PageDigitStatus
                PageDigitalInfo
                PageCoaxialControlCamera
                PageImageEnhance
                PageXVIUpgrade
                PageCameraImExport
                PageXVIAudioSet
Pic Path:h264dvr.jpg, PicDir:/mnt/logo/*
CBackupManager::CBackupManager()>>>>>>>>>>>>>>>>
CDriverManager::CDriverManager()>>>>>>>>>


Storage: $Rev: 922 $, $Author: liwj $, Build in:Jun 16 2022, 15:02:13


Storage: $base Dir D_General_Storage_V4.02.0.R11_20130906, $Source svn: 40833, $Include svn: 24911, $Build in:Jun 16 2022, 15:02:13
CStorage::start()>>>>>>>>>>
CDriverManager::Start()>>>>>>>>>
ide/ide.c(1020) [ide_init]: MAX_DISK_NUM is 2
 123____ide_num=0, ide_port=2, ide_bad=0, ide_msk=0, file:Source/StorageManagerIn.cpp,line:676

WFS: $base Dir Trunk, $Source svn: 374, $Include svn: 374, $Build in:Jun 16 2022, 15:07:39

wfs_file_sys_init() libWFS_new.a $Rev: 9 $, Build in:Jun 16 2022 15:07:39
disk_num = 0
ide_num:0
ide_port:2
ide_mask:0x0
ide_bad:0x0
cap:
wfs_file_sys_init() end============================

driver basic parameter:
 -------------------------------------------------------------------------------------------------------------------------------------
| dev.part |type|total_clus | temp_off | index_off | dir_off |lock_off |mark_off |face_off | data_off | rev_clus | sec/clus |status|
|----------|----|-----------|----------|-----------|---------|---------|---------|---------|----------|----------|----------|------|
 -------------------------------------------------------------------------------------------------------------------------------------
driver operation parameter:
 -------------------------------------------------------------------------------------------------------------------------
| dev.part | F| S|  curr  |        start1         |         end1          |        start2         |        end2           |
|          |  |  |        |MM-DD HH:MM:SS|  clus  |MM-DD HH:MM:SS|  clus  |MM-DD HH:MM:SS|  clus  |MM-DD HH:MM:SS|  clus  |
|----------|--|--|--------|--------------|--------|--------------|--------|--------------|--------|--------------|--------|
 --------------------------------------------------------------------------------------------------------------------------
driver time chart:
 --------------------------------------------------------------------------
|dev.part | period of time                                                 |
|---------|----------------------------------------------------------------|
 ------------------------------------------------------------------------
driver time sections:
 ------------------------------------------------------------------------
|dev part |start_clus| end_clus |    start_time     |   end_time        |
 ------------------------------------------------------------------------

CMedia::start() $Rev: 972 $>>>>>
vcap_host.nr_of_vi 4
sched set 98, 2
CPacketBuffer::CPacketBuffer size = 1638 KB
CConfigManager::getConfig 'fVideo.VideoSeque', but default config is not set yet!
CConfigManager::getConfig 'Media.DecodeParam', but default config is not set yet!

[clearARPEthName]!
venc osg num:0!
onVerifyAudioInFormat() ../../Manager/VerifyConfig.cpp 1711
onVerifyTour() ../../Manager/VerifyConfig.cpp 1620
1  4
CConfigManager::setConfig(AVEnc.AHDChannelState, )
CSnapManager::start()...
venc osg num:0!
1  4
onVerifyTour() ../../Manager/VerifyConfig.cpp 1620
===>>> VideoSetTVMargin (0, 0, 0, 0)
dwType 0
dwType 0
chn 0 left 0 bottom 256 right 340 top 0
x 0 y 0 w 340 h 256 win.visible 1
chn 1 left 340 bottom 256 right 680 top 0
x 340 y 0 w 340 h 256 win.visible 1
chn 2 left 680 bottom 256 right 1020 top 0
x 680 y 0 w 340 h 256 win.visible 1
chn 3 left 0 bottom 512 right 340 top 256
x 0 y 256 w 340 h 256 win.visible 1
chn 4 left 340 bottom 512 right 680 top 256
x 340 y 256 w 340 h 256 win.visible 1
chn 5 left 680 bottom 512 right 1020 top 256
x 680 y 256 w 340 h 256 win.visible 1
chn 6 left 0 bottom 768 right 340 top 512
x 0 y 512 w 340 h 256 win.visible 1
chn 7 left 340 bottom 768 right 680 top 512
x 340 y 512 w 340 h 256 win.visible 1
CConfigManager::setConfig(AVEnc.Encode, )
channel 0,streamType 0
channel 1,streamType 0
channel 2,streamType 0
channel 3,streamType 0
channel 4,streamType 0
channel 5,streamType 0
channel 6,streamType 0
channel 7,streamType 0
venc osg num:9!
venc osg num:18!
Fvideo: nvp6158_set_color,Line 2345,FmtDef[2]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[3]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[0]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[1]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[6]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[7]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[4]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
Fvideo: nvp6158_set_color,Line 2345,FmtDef[5]=c9101e72 color setting[f5 88 85 04 f8 f8 00 fd 8f]
VIDEOENC: SetToLib >>>>> ch[0] +[1]
VIDEOENC: SetToLib >>>>> ch[1] +[1]
VIDEOENC: SetToLib >>>>> ch[2] +[1]
VIDEOENC: SetToLib >>>>> ch[3] +[1]
VIDEOENC: SetToLib >>>>> ch[4] +[1]
VIDEOENC: SetToLib >>>>> ch[5] +[1]
VIDEOENC: SetToLib >>>>> ch[6] +[1]
VIDEOENC: SetToLib >>>>> ch[7] +[1]
CConfigManager::setConfig(AVEnc.SmartH264V2, )
venc osg num:0!
venc osg num:0!
chn:0   type:0
chn:1   type:0
chn:2   type:0
chn:3   type:0
chn:4   type:0
chn:5   type:0
chn:6   type:0
chn:7   type:0
CRecordManager::start()>>>>>>>>>
AudioSwitch dwChannel=0 dwType=2 pAudioDev->dwchannel 0
Fvideo: nvp6158_set_audiomode,Line 6383,Play_Mode[app_ch=0]:mode=2 G_NVP6168_AudioMode=0
AudioSwitch dwChannel=1 dwType=2 pAudioDev->dwchannel 0
Fvideo: nvp6158_set_audiomode,Line 6383,Play_Mode[app_ch=0]:mode=2 G_NVP6168_AudioMode=0
AudioSwitch dwChannel=2 dwType=2 pAudioDev->dwchannel 1
Fvideo: nvp6158_set_audiomode,Line 6383,Play_Mode[app_ch=0]:mode=2 G_NVP6168_AudioMode=0
AudioSwitch dwChannel=3 dwType=2 pAudioDev->dwchannel 2
Fvideo: nvp6158_set_audiomode,Line 6383,Play_Mode[app_ch=0]:mode=2 G_NVP6168_AudioMode=0
CConfigManager::getConfig 'Detect.HumanDetectionDVR', but default config is not set yet!


Comm: $base Dir D_General_Comm_V4.02.0.R11_20130906, $Source svn: 37471, $Include svn: 38138, $Build in:Dec  3 2020, 19:18:48
name: General
name: General
CFrontBoardProtocol::start()......
KeyMap OK .............
onVerifyComm() ../../Manager/VerifyConfig.cpp 1604
CNutParser::Init()>>>>>>>>>
path = /usr/bin/Squirrel/rs485
CComm::start()>>>>>>>>>
CDevComm::open failed!
onVerifyComm() ../../Manager/VerifyConfig.cpp 1604
CPtz::CPtz()>>>>>>>>>
onVerifyPTZ() ../../Manager/VerifyConfig.cpp 1609
CConfigManager::getConfig 'Uart.PTZTour', but default config is not set yet!
CConfigManager::getConfig 'Uart.PTZPreset', but default config is not set yet!
CConfigManager::getConfig 'Uart.PTZPattern', but default config is not set yet!
onVerifyPTZ() ../../Manager/VerifyConfig.cpp 1609
CPtz::Init()>>>>>>>>>
CRS485::CRS485()>>>>>>>>>
CNutParser::Init()>>>>>>>>>
path = /usr/bin/Squirrel/rs485
CNutParser::Init()>>>>>>>>>
path = /usr/bin/Squirrel/netkeyboard
uart/ptz.c(143) [PtzOpen]: Open Ptz Dev:/dev/ttyS2 Successful
CRS485Protocol start...
onVerifyPTZAlarmProtocol() ../../Manager/VerifyConfig.cpp 1108
CAlarmManager::instance()->start()...
CAlarm::CAlarm()>>>>>>>>>
CAlarm::Start()>>>>>>>>>
CConfigManager::getConfig 'Alarm.IPCAlarm', but default config is not set yet!
------->cpu_use1:0.0, idle:100.0
---->cpu_use:0
**************************************************
| IMP: Compiled at Oct 15 2020 20:59:48
**chnNum 8**************************************
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[INIT]: Open Class File xmnn /usr/ai_mode/pbd_up_gray_8_384X112_inst.xmnn param /usr/ai_mode/pbd_up_gray_8_384X112_inst.param.
[INIT] Alg Malloc Size 535729
CNNINIT INPUT IMAGESIZE:(384,112)
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x19817a8 *pvHandle 0x1984c60 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x19f0958 *pvHandle 0x19f3e10 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x1a536a0 *pvHandle 0x1a56b58 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x1ab6848 *pvHandle 0x1ab9d00 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x1b19a40 *pvHandle 0x1b1cef8 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x1b7cb70 *pvHandle 0x1b80028 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x1bdfdc8 *pvHandle 0x1be3280 OK
[INIT]:LIBXMIA IAtype 700 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 70592
[INIT]: TD Version: DetectTarget_20201012[Oct 15 2020 15:59:22]
[CFG-input]: DetectType 257 eAlgSense 2 DetRect[(0 0) (8191 8191)]
[CFG]: IA_PERIMETER iBoundaryPtsNum 3 eAlarmDirect 0 (0 0) (0 0) (0 0) [CFG]: eSensitivity 2
[CFG]: SetRuleTdConfig OK
[INIT] Alg Malloc Size 60656
[INIT] Alg Malloc Size 49664
[INIT]: Open Class File xmnn /usr/ai_mode/pdfeature_8_inst.xmnn param /usr/ai_mode/pdfeature_8_inst.param.
[INIT] Alg Malloc Size 128545
CNNINIT INPUT IMAGESIZE:(32,64)
[INIT]: iTdMaxNum 6 iDetType 257
[INIT]: PdInit pvHandle 0x1c43048 *pvHandle 0x1c46500 OK
[INIT]:LIBXMIA IAtype 3 Complied at Oct 15 2020 15:59:19 GIT_ID:07bc209
[INIT] Alg Malloc Size 1048576
[INIT]: Platform 2000 IMG 1920x1080 type 18 Alg 1280x720 AlgSense 2 RotateMode 0 Rotate 0 ClearThr 0 FaceMin 910 FaceMax 7280 FaceAngleMode 0[Y 90 R 45 P 45] RecRgn[(0 0) (8191 8191)] FdNum 1 FrNum 0
[INIT] Alg Malloc Size 153600
[CFG]: eAlgSense 2 fThr 0.50
[INIT]: Open Class File xmnn /usr/ai_mode/fd_claire_8_inst.xmnn param /usr/ai_mode/fd_claire_8_inst.param.
[INIT] Alg Malloc Size 705713
onTimerSearchPic-------------------------------------------------
monthNum 2 2025 7
month------------ 0 2025 7
month------------ 1 2025 6
 search finish---------------------  8
[INIT]: FdrInit() OK. Version FACE_DET_REC_20201013 BuildTime Oct 15 2020 15:55:20
g_FaceLibVersion :
IMP_FDR_Onoff channel:0 open 1
IMP_FDR_Onoff channel:1 open 1
IMP_FDR_Onoff channel:2 open 1
IMP_FDR_Onoff channel:3 open 1
IMP_FDR_Onoff channel:4 open 1
IMP_FDR_Onoff channel:5 open 1
IMP_FDR_Onoff channel:6 open 1
IMP_FDR_Onoff channel:7 open 1
CGUI::Start()>>>>>>>>>
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../Main.cpp,2626
tracepoint: ../../Main.cpp,2632
CConfigManager::setConfig(fVideo.GUISet, )
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[Waiting entity: (datain_0_0_128:1)-(audioDecode_0_1_1:1)-
[Warning] apply timeout. ver(Au_Render_3:1) apply(#18)
1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
Pic Path:VideoChannelLoss.jpg, PicDir:/mnt/logo/VideoLoss/*
____ g_Theme.loadImage error  m_bmpWifiSignal[0;]  _____
____ g_Theme.loadImage error  m_bmpWifiSignal[1;]  _____
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
channel:0 dwLVolume:70 dwRVolume:262144 audioType:4 rightVolume:0
Fvideo: nvp6158_set_ad_ao_volume,Line 6300,Volume AO set : appch=0 volume:0xa, ao_gain: 0a offset=0
Fvideo: nvp6158_set_ad_ao_volume,Line 6301,Volume AO set : NVP61XX_AUDIO_FLAG: 1, NVP61XX_AUDIO_VOLUME: 0a
logic chn:8, max:32
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
WIRELESS - WLan_init(2302): ERR: get ifname err!
WIRELESS - WLanClose(2362): wireless close!
WIRELESS - WLanOpen(2404): wireless_init err!
NETSTATE: start CheckNetAbort...
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
@@@@@@@@@@@@@@@@@>>>>>>>>>>>>>>WARNING!!!!!!> Same Table in same row .......
tracepoint: ../../GUI/Pages/PageConfigEvent.cpp,1265

err mainMenu is too many!!!!!!!
m_Rect.Width(528) m_Rect.Height(360)
CConfigManager::setConfig(AVEnc.Encode, )
__LINE__[930], __FILE__[../../GUI/Pages/PageDesktop.cpp],onAppEvent: WindowClick
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 2 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 3 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 0 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 1 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 6 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 7 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 4 ],OUTMODE [ 3 ]
Fvideo: FvideoSetVideoOutputMode,Line 6127,AHD_TVI_MIX 0, channel [ 5 ],OUTMODE [ 3 ]
@ifc_down(), ioctl <SIOCGIFFLAGS> err: No such device(19)
 =================================================================
| LIBWIRELESS: SVN: 474,Compiled by chenwenrong at Apr 10 2021 10:03:54 |
 =================================================================
@ifc_down(), ioctl <SIOCGIFFLAGS> err: No such device(19)
======================================================================
|                     -----------init-------------                  |
======================================================================
WLan_init fun:WLan_init line:2298
WLan_init err!


NetIP: $Rev: 1055 $, $Author: chencb $, Build in:Jul 30 2022, 14:22:27
CNetService::start()>>>>>>>>>>
onVerifyNetEmail() ../../Manager/VerifyConfig.cpp 1322
onVerifyNetDDNS() ../../Manager/VerifyConfig.cpp 1317
SMTPD: >>>>>>>>>>>>>Start


LIBNETSERVICE_SMTP: $Version_fix: NETSTATE: Start(Delay 30s) thread[CheckIPConflict], ThreadID[487]
SIOCGIFADDR failed!
: No such device
DHCPPROTO: DhcpInitCtxt fail! eth name(eth1) not valid!
SIOCGIFADDR failed!
: No such device
DHCPPROTO: DhcpInitCtxt fail! eth name(eth2) not valid!
SIOCGIFADDR failed!
: No such device
DHCPPROTO: DhcpInitCtxt fail! eth name(eth3) not valid!
SIOCGIFADDR failed!
: No such device
DHCPPROTO: DhcpInitCtxt fail! eth name(bond0) not valid!
DHCPC: start...
AUTOSEARCH: m_statusSerialNo[1] m_SerialNo[907278faf17e3b8cndr3]
DHCPC: eth0 is Broken
AUTOSEARCH: Start..m_ExAbility[3d],m_AUTOSEARCHPORT[34569].m_iSock[73]
RTP: CRtspSvrApp start ok
HTTPD: Start Thread[HttpProc], tid[503] pid[372]
HTTPD: create socket[79] success!
HTTPD: Start Thread[task0], tid[504] pid[372]
DECODERMG: Start thread[NetDecoderManager], ThreadID[512]
V0.01, $Svn: XXX, Build in:Jul 30 2022, 14:24:41, 0
FTP: >>>>>>>>>>>>>Start
DDNS: Start ....
open file fail: /mnt/mtd/Config/ppp/pap-secrets, get from cmos
read pppoe info from cmos fail
NTPD: Start OK...
Devtype:0x1
AlarmCenter: Start ....
CRtpApp start ok


LIBWEB: $Version_fix:  V1.0, $Svn: XXX, Build in:Jan 22 2022, 08:51:22, 0
 =======================================================================================
| libweb.a: SVN[167] Author[zhaochanglong] Compiled[Jan 22 2022 08:51:22]
| Port[http(80) tcp(34567) udp(34568)] language[9] webFile[/mnt/web]
 =======================================================================================
szUrl: http://:8080/ocx/Active.exe
UPNP: start ...
ARSP: Start ....


NetIP: $Rev: 1055 $, $Author: chencb $, Build in:Jul 30 2022, 14:20:56
CNetIP::start()>>>>>>>>>>
 ================================================================
| LIB3GNET: SVN:8415388,Compiled by chenwenrong at Jun 20 2020 16:09:59 |
 ================================================================
WritePortInfo begin ==>>
WritePortInfo begin11 ==>>
WritePortInfo len=128
WritePortInfo begin22 ==>>
 =======================================================================================
| libtransport.a: SVN[41069] Author[dingyanan] Compiled[Jul  7 2022 14:54:45]
 =======================================================================================
Transport: CServerIOThread start OK
cfgNetCommon.TCPPort=[34567]
s_DeviceMac=[907278faf17e3b8cndr3]
s_DevInfo.msgID====feffff01
-----------OnEncode----------->
<-----------OnEncode-----------
CNetManager start ok
CLocalSDKManager start ok
s_DeviceMac=[907278faf17e3b8cndr3]
m_DevicePort=[34567]
>>>>>>>>CXmCloud: Start>>>>>>>>
agent_device build time: Sep  8 2021 17:01:57
agent device start success
rps timeout notifyer thread: 515
agent worker thread: 516
try init agent device
try create event base
create event base success
try create master socket
create master socket success
try create master event
create master event success
 CHttpRealplay Start >>>>
gevent add master event success
try create notify event
create_notify_pipe auccess
 CHttpPlayBack Start >>>>
[RpsDebug]create notify event sucess !!!
create notify event success
FrontboardWrite failed[writted:0  errRet:0]!
Threads:
               Name            PID  Prior State
_______________________________________________________
                    Main        372   64  Normal
            TimerManager        384   50  Normal
              SnapAnalog        385   50  Normal
                 Console        386   50  Normal
           DevFrontboard        456   50  Normal
                DevMouse        409   50  Normal
           DriverManager        417   50  Normal
                     GUI        476   50  Normal
                  Backup        415   50  Normal
          CaptureManager        429   98  Normal
       NetDecoderManager        512   50  Normal
         CheckIPConflict        487   50  Normal
              LightWrReg        444   50  Normal
              LightRdReg        443   50  Normal
           RecordManager        455   50  Normal
                  DevPtz        457   50  Normal
                AhdCvs:1        483   50  Normal
            Page_Desktop        475   50  Normal
            ThreadCheack        464   50  Normal
                 FastKey        465   50  Normal
      TimerNetBitrateCal        511   50  Normal
                AhdCvs:0        467   50  Normal
          FacePicManager        460   50  Normal
    Page_*Temp.InputTray        471   50  Normal
   Page_*Temp.OsdOverlay        472   50  Normal
  m_InitRSAKeyIndexTimer        479   50  Normal
                   Page_        473   50  Normal
     Page_CPageDesktopQr        474   50  Normal
            NetIPManager        508   50  Normal
                MacCheck        478   50  Normal
                    ARSP        506   50  Normal
                 RTSPSvr        501   50  Normal
                  RTPAPP        502   50  Normal
                  Pooled        517   50  Normal
        CloudStateReportnvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
year: 125, month: 6, day: 22, wday: 2, hour: 10, minute: 15, second: 27
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
        518   50  Normal
          NetAlarmCenter        500   50  Normal
              TCP_Server        507   50  Normal
                CXmCloud        514   50  Normal
                CUpnpCli        505   50  Normal
              DHCPClient        498   50  Normal
       CAutoSearchDevice        499   50  Normal
                    SMTP        488   50  Normal
                     FTP        489   50  Normal
                LocalSDK        513   50  Normal
                   Alarm        463   50  Normal
Timers: ( 33210 Milli-Seconds Elapsed )
_________________________________________
        TPtzLink       33250 Idel
        NetState       33310 Idel
        hostname       33330 Idel
                       33370 Idel
        SaveTime       33380 Idel
TimerNetBitrateCal       33390 Running
       FlushTime       33400 Idel
     DetectTimer       33430 Idel
        AhdCvs:1       33510 Running
        AhdCvs:0       33510 Running
   TimerChnState       33510 Idel
TimerCheckNetAbort       33670 Idel
                       33750 Idel
        LockUser       33760 Idel
CoaxialControl:1       33770 Idel
                       33810 Idel
   TimerSnapShot       33880 Idel
CoaxialControl:0       34010 Idel
    EventManager       34170 Idel
    StorageAlarm       34210 Idel
          Encode       34260 Idel
    CGIIdleCount       34750 Idel
        NatProbe       34760 Idel
       NetStatus       34810 Idel
     BitrateStat       35740 Idel
       InputIdle       36310 Idel
           Caret       36310 Idel
        WatchDog       43640 Idel
CheckNetStateipv4       44620 Idel
     LogSaveFile       52610 Idel
      CheckAudio       53890 Idel
DiskStateChecker       85640 Idel
   LimitCLiCheck       92860 Idel
    AutoMaintain      118760 Idel
                     3626270 Idel
       SearchPic    86425900 Idel
open file fail: /mnt/mtd/Config/ppp/pap-secrets, get from cmos
read pppoe info from cmos fail
-------->Test GetWay[192.168.86.1].........
MYPING 192.168.86.1(192.168.86.1): 56 bytes data in ICMP packets.
recvfrom Error
FUNCTION:recv_packet    LINE:348
--------------------MYPING statistics-------------------
1 packets transmitted, 0 received , 1 lost


MYPING 192.168.86.1(192.168.86.1): 56 bytes data in ICMP packets.
recvfrom Error
FUNCTION:recv_packet    LINE:348
--------------------MYPING statistics-------------------
1 packets transmitted, 0 received , 1 lost


MYPING 192.168.86.1(192.168.86.1): 56 bytes data in ICMP packets.
recvfrom Error
FUNCTION:recv_packet    LINE:348
--------------------MYPING statistics-------------------
1 packets transmitted, 0 received , 1 lost


MYPING 192.168.86.1(192.168.86.1): 56 bytes data in ICMP packets.
recvfrom Error
FUNCTION:recv_packet    LINE:348
--------------------MYPING statistics-------------------
1 packets transmitted, 0 received , 1 lost


CCaptureManager::OsdAppend system time is flowing backwards!!!!!!!!!!!!!
TPBASE: tp_gethostbyname(182) tp_gethostbyname2 fail!
gethostbyname mac.secu100.net fail
TPBASE: tp_gethostbyname(182) tp_gethostbyname2 fail!
CCloudMediaManager::Start-------->get pub cfg ip failed [pub-cfg.secu100.net]
GetDssconfig===>send
[{ "CfgProtocol" : { "Body" : { "AuthCode" : "907278faf17e3b8cndr3", "OemID" : "General", "OtherInfo" : "V4.03.R11.85100228.12001.132500.0000005", "ProductID" : "AHB8008R-LME-NVT", "SerialNumber" : "907278faf17e3b8cndr3" }, "Header" : { "CSeq" : "1", "MessageType" : "MSG_DSS_CFG_QUERY_REQ", "Version" : "1.0" } } }
]
[GetNatServerIP] default domain: secu100.net
TPBASE: tp_gethostbyname(182) tp_gethostbyname2 fail!
NTPD: NTP servername NTP,host[NTP], port[123]
tracepoint: src/NTP/NtpCli.cpp,101
HTTPClientSendRequest failed
send request error ->[https://pub-cfg.secu100.net:8186]
[GetNatServerIP] get domain ip failed: secu100.net
[GetNatServerIP] resolve backup default domain: aiotsecu.com
[GetNatServerIP] resolve domain ip failed: aiotsecu.com
GetNatServerIP error
TPBASE: tp_gethostbyname(182) tp_gethostbyname2 fail!
GetCssconfig::Start-------->get pub cfg ip failed [pub-cfg.secu100.net]
[GetNatServerIP] default domain: secu100.net
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
year: 125, month: 6, day: 22, wday: 2, hour: 10, minute: 15, second: 57
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken
nvt_irdet_drv_ioctl:Irdet data wait timeout, over 5000 ms!
DHCPC: eth0 is Broken

Modified boot log

The modified firmware removes Sofia, cleans up rcS, and boots directly into a terminal:

NPpT0table1
IO0_26 0

UNZOK!NA51068 05.03.04
CPU1200 DONE
mmc bootstrap
0oad all-in-one fw
Loader Start ...
321_DRAM1_933_4096Gb_DRAM2_0Gb 04/11/2022 13:54:13

SPI NOR MID=00000020,TYPE=00000040,SIZE=00000018=>01000000
SPI NOR
Dual_read
tmp_addr 0x02000000
LdCtrl2 0x00000000
Dual_read
uboot_addr 0x06000000
uboot_size 0x01F80000
Dual_read
core No. 0x00000511
fdt 0x00080000
shm 0x00A00000
p_bininfo->boot.fdt_addr 0x00080000
bl_smp_start
uboot_entry 0x06000000
core2_jump_program 0xFE080500
code2JumpCodelen 0x00000010
core2_entry2_addr 0x1FF80000
core2_entry_program 0xFE080510
code2EntryCodelen 0x000001A4
0xFE0B9000= 0x00000000
reset core2
2acor1await

U-Boot 2016.07 (Apr 11 2022 - 13:54:25 +0800)

CPU:   Novatek NT @ 1200 MHz
DRAM:  512 MiB
Relocation to 0x07d57000, Offset is 0x01d57000 sp at 07a46ed0
ARM CA9 global timer had already been initiated
 CONFIG_MEM_SIZE              =      0x20000000
 CONFIG_NVT_UIMAGE_SIZE       =      0x00a00000
 CONFIG_UBOOT_SDRAM_BASE      =      0x06000000
 CONFIG_UBOOT_SDRAM_SIZE      =      0x01f80000
 CONFIG_LINUX_SDRAM_BASE      =      0x00b00000
 CONFIG_LINUX_SDRAM_SIZE      =      0x05500000
 CONFIG_LINUX_SDRAM_START     =      0x05600000
SPI:   nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
lk=>6, 0x800000.
SRx val: {[1, 0x38], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601238.
nvt spinor 1-bit mode @ 48000000 Hz
nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
lk=>6, 0x800000.
SRx val: {[1, 0x38], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601238.
nvt spinor 1-bit mode @ 48000000 Hz
DTS find cpu freq clock 1200MHz
Read power trim = 0x0000000d
cpu 1200 remap_data 54
Set CPU clk 1200MHz
Read power trim = 0x0000000d
ddr 1864 remap_data 30
Net:   na51068_eth_initialize 1.0.3.0
na51068_eth_initialize(2121) nodeoffset < 0
na51068_eth_initialize: path /eth0@fcc00000 not found
<<<<<<<<na51068_eth_initialize: dtb node /eth1@fcd00000 found>>>>>>>
################## eqos_initialize 0xfcd00000 ##################
eth_parse_phy_intf: get IO MEM 0xfcd00000
DTS /eth1@fcd00000 found
LED2 pinmux 0x200046
eth_parse_phy_intf: ref-clk-out 0, phy_clk: 0
eth_parse_phy_intf: pinmux detect emb phy 0x200
@xm_eth_read_phyid(), phy_id: 0x0, phy_ver: 0x1.
val 1
eth1
Warning: eth1 MAC addresses don't match:
Address in SROM is         0a:0b:0c:0d:0e:02
Address in environment is  00:0b:3f:00:00:01

USB0:   USB EHCI 1.00
scanning bus 0 for devices... 1 USB Device(s) found
USB1:   USB EHCI 1.00
scanning bus 1 for devices... 1 USB Device(s) found
0 Storage Device(s) found
usb device not found
but something wrong, please check log shown above

Hit CTRL-C to stop autoboot:  0
NovaWdt_Start nSecs :88
nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
lk=>6, 0x800000.
SRx val: {[1, 0x38], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601238.
nvt spinor 1-bit mode @ 48000000 Hz
@do_spi_flash_probe() flash->erase_size: 65536, flash->sector_size: 65536
device 0 offset 0xf60000, size 0x20000
SF: 131072 bytes @ 0xf60000 Read: OK
at do_logoload pType: unknow.
at logofsmagic:[1:ff,2:ff,3:ff,4:ff][1:▒,2:▒,3:▒,4:▒]
Will Clear JPEG_BUFFER_SIZE
jpeg decoding ...
addr:07ded324,logoaddr:0x4500000,: 0, 0  0 0
load jpeg err.
[OUTPUT_1280x720]
LCD300:0 chooses PLL9:297000000 with div=4 (drv:1.1.2)
@do_bootlogo(), g_vin: 1[1:800*600,2:1024*768;3:720P;],g_output: 0x1000[0x1000:720P,0x1001:1080P,0x1002:1024*768],g_infmt: 2[0:YUV422,1:RGB888,2:RGB565,3:ARGB1555], lcd_frame_base[LCD0_ID]: 0x1E800000.
hdmi_if_init, apply new vid:4 setting.
hdmitx_init_phy, clock_rate:74250KHz
Init PHY END
Skip InitDDC
hdmi: audio stream enable.
Bootlogo CVBS ON. g_vin[0] 0,g_output[0] 0
LCD210_1: chooses PLL11:54000 with div=2
LCD300:0 chooses PLL9:297000000 with div=4 (drv:1.1.2)
@do_bootlogo(), g_vin: 1[1:800*600,2:1024*768;3:720P;],g_output: 0x1000[0x1000:720P,0x1001:1080P,0x1002:1024*768],g_infmt: 2[0:YUV422,1:RGB888,2:RGB565,3:ARGB1555], lcd_frame_base[LCD0_ID]: 0x1E800000.
hdmi_if_init, apply new vid:4 setting.
Bootlogo CVBS ON. g_vin[0] 0,g_output[0] 0
LCD210_1: chooses PLL11:54000 with div=2
nvt_spinor_reset: spi flash pinmux 0x4
id =  0x20 0x40 0x18 0x20 0x00
eFlashType: 22.
Flash Name: XM25QH128C{0x204018), 0x1000000.
@nvt_spinor_validate_params(), XmSpiNor_ProtMgr_probe(): OK.
STDR128FW with page size 256 Bytes, erase size 64 KiB, total 16 MiB
CONFIG_CLOSE_SPI_8PIN_4IO = y.
lk=>6, 0x800000.
SRx val: {[1, 0x38], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601238.
nvt spinor 1-bit mode @ 48000000 Hz
@do_spi_flash_probe() flash->erase_size: 65536, flash->sector_size: 65536
device 0 offset 0xb0000, size 0x370000
SF: 3604480 bytes @ 0xb0000 Read: OK
aSrcAddr[0]: 0x4000000, dstAddr: 0x5600000, apFileName[0]: boot/uImage.
unknow
read_super_m faile
### get_squashfs_file Failed, size: 0, filename: boot/uImage, aSrcAddr[0]: 0x4000000!
aSrcAddr[1]: 0xB00000, dstAddr: 0x5600000, apFileName[0]: boot/uImage.
created_inode 0x7a83e28
find_squashfs_file: name bin, start_block 0, offset 2492, type 1
find_squashfs_file: name boot, start_block 0, offset 2596, type 1
read inode: name boot, sb 0, of 2596, type 1
find_squashfs_file: name zImage.img, start_block 0, offset 2524, type 2
find_squashfs_file fail
### get_squashfs_file Failed, size: 0, filename: boot/uImage, aSrcAddr[1]: 0xB00000!
aSrcAddr[0]: 0x4000000, dstAddr: 0x5600000, apFileName[1]: boot/zImage.img.
unknow
read_super_m faile
### get_squashfs_file Failed, size: 0, filename: boot/zImage.img, aSrcAddr[0]: 0x4000000!
aSrcAddr[1]: 0xB00000, dstAddr: 0x5600000, apFileName[1]: boot/zImage.img.
created_inode 0x7a6f968
find_squashfs_file: name bin, start_block 0, offset 2492, type 1
find_squashfs_file: name boot, start_block 0, offset 2596, type 1
read inode: name boot, sb 0, of 2596, type 1
find_squashfs_file: name zImage.img, start_block 0, offset 2524, type 2
read inode: name zImage.img, sb 0, of 2524, type 2
write_file: regular file, blocks 10
len 2477600
### get_squashfs_file OK: loade 2477600 bytes to 0x5600000
uImage is at 5600000, uboot fdt image is at 7a47090
## Booting kernel from Legacy Image at 05600000 ...
   Image Name:   Linux-4.9.118
   Image Type:   ARM Linux Kernel Image (uncompressed)
   Data Size:    2477536 Bytes = 2.4 MiB
   Load Address: 00008000
   Entry Point:  00008000
   Verifying Checksum ... OK
## Flattened Device Tree blob at 07a47090
   Booting using the fdt blob at 0x7a47090
   Loading Kernel Image ... OK
   Loading Device Tree to 07a38000, end 07a42fff ... OK
at xminfo_get() g_nXmBootSysIndex: 0, g_nXmRomfsIndex: 0.
at xminfo_get() aXmInfo: XmUart=0,XmAuto=1,Id=NULL,Mac=00:0b:3f:00:00:01,HwId=NULL,SysIndex=0,RomfsIndex=0,CorruptFlag=0x0,BackupCount=0.
osMemStart: 0x0, osMem: 0xB400000.

Starting kernel ...

ACTLR: 0x00000005
ACTLR: 0x00000045
Disable MMU
Clear MMU
Uboot L2 cache aux val: 0x72430000
Uboot L2 cache prefetch ctrl val: 0x70000000
Uboot L2 cache ctrl val: 0x00000000
Done
Uncompressing Linux... done, booting the kernel.
abceBooting Linux on physical CPU 0x0
Linux version 4.9.118 (ruanyingda@dell) (gcc version 6.5.0 (Buildroot 2019.05.2-00003-g3ccc130) ) #131 SMP Thu Dec 30 16:06:08 CST 2021
CPU: ARMv7 Processor [414fc091] revision 1 (ARMv7), cr=10c5387d
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
OF: fdt:Machine model: Novatek NA51068
Memory policy: Data cache writealloc
percpu: Embedded 13 pages/cpu @8b23a000 s24332 r8192 d20724 u53248
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 45675
Kernel command line: earlyprintk console=ttyS0,115200 init=linuxrc mem=0xb400000 rootwait nprofile_irq_duration=on root=/dev/mtdblock4 rootfstype=squashfs mtdparts=spi_nor.0
PID hash table entries: 1024 (order: 0, 4096 bytes)
Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
Memory: 174968K/184320K available (4790K kernel code, 268K rwdata, 1668K rodata, 268K init, 303K bss, 9352K reserved, 0K cma-reserved)
Virtual kernel memory layout:
    vector  : 0xffff0000 - 0xffff1000   (   4 kB)
    fixmap  : 0xffc00000 - 0xfff00000   (3072 kB)
    vmalloc : 0x8b800000 - 0xff800000   (1856 MB)
    lowmem  : 0x80000000 - 0x8b400000   ( 180 MB)
    modules : 0x7e800000 - 0x80000000   (  24 MB)
      .text : 0x80008000 - 0x804b5cd8   (4792 kB)
      .init : 0x80659000 - 0x8069c000   ( 268 kB)
      .data : 0x8069c000 - 0x806df150   ( 269 kB)
       .bss : 0x806e1000 - 0x8072cf54   ( 304 kB)
SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
Hierarchical RCU implementation.
NR_IRQS:384
L2C-310 enabling early BRESP for Cortex-A9
L2C-310 full line of zeros enabled for Cortex-A9
L2C-310 ID prefetch enabled, offset 1 lines
L2C-310 dynamic clock gating enabled, standby mode enabled
L2C-310 cache controller enabled, 16 ways, 256 kB
L2C-310: CACHE_ID 0x410000c9, AUX_CTRL 0x76430001
APIs of flush/clean all cache are supported
novatek_clock_init
sched_clock: 64 bits at 150MHz, resolution 6ns, wraps every 2199023255551ns
clocksource: arm_global_timer: mask: 0xffffffffffffffff max_cycles: 0x2298375bd0, max_idle_ns: 440795208267 ns
Switching to timer-based delay loop, resolution 6ns
FTTMR010 Driver Version: 1.0.1
clocksource: fttmr010_clksrc: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 159271703898 ns
fttmr010_clock_event_shutdown, shutdown tmr0
Console: colour dummy device 80x30
Calibrating delay loop (skipped), value calculated using timer frequency.. 300.00 BogoMIPS (lpj=1500000)
pid_max: default: 32768 minimum: 301
Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
CPU: Testing write buffer coherency: ok
Setting up static identity map for 0x8240 - 0x8298
Brought up 2 CPUs
SMP: Total of 2 processors activated (600.00 BogoMIPS).
CPU: All CPU(s) started in SVC mode.
devtmpfs: initialized
VFP support v0.3: implementor 41 architecture 3 part 30 variant 9 rev 4
NVTBOOTTS: nvt_bootts_init initial success
NVTBOOTTS: nvt_bootts_proc_init initial success
nvt_jiffies: system HZ: 100, pClk: 12000000
clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
futex hash table entries: 512 (order: 3, 32768 bytes)
pinctrl core: initialized pinctrl subsystem
NET: Registered protocol family 16
DMA: preallocated 256 KiB pool for atomic coherent allocations
cpuidle: using governor menu
nvt_otp_module_init
------------------------------
AXI0=500 AXI1=400 AXI2=350 HCLK=300
CPU=1200 DRAM=1864 DSP=600 CODEC=380
DISP0=297 DISP1=270 DISP2=54 CNN=600
MPLL8(VCAP)=465 SSP=344
------------------------------
SCSI subsystem initialized
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
clocksource: Switched to clocksource arm_global_timer
NET: Registered protocol family 2
TCP established hash table entries: 2048 (order: 1, 8192 bytes)
TCP bind hash table entries: 2048 (order: 2, 16384 bytes)
TCP: Hash tables configured (established 2048 bind 2048)
UDP hash table entries: 256 (order: 1, 8192 bytes)
UDP-Lite hash table entries: 256 (order: 1, 8192 bytes)
NET: Registered protocol family 1
RPC: Registered named UNIX socket transport module.
RPC: Registered udp transport module.
RPC: Registered tcp transport module.
RPC: Registered tcp NFSv4.1 backchannel transport module.
NetWinder Floating Point Emulator V0.97 (double precision)
workingset: timestamp_bits=14 max_order=16 bucket_order=2
squashfs: version 4.0 (2009/01/31) Phillip Lougher
exFAT: Version 1.2.9
jffs2: version 2.2. (NAND) © 2001-2006 Red Hat, Inc.
fuse init (API version 7.26)
io scheduler noop registered
io scheduler deadline registered (default)
io scheduler cfq registered
probe fe400000.gpio OK, at 0xfe700000, version:1.0.4.
probe fe420000.gpio OK, at 0xfe720000, version:1.0.4.
probe fe440000.gpio OK, at 0xfe740000, version:1.0.4.
probe fe640000.gpio OK, at 0xfe940000, version:1.0.4.
ftdmac030 fca00000.dma030: driver probed, irq 19, mapped at fca00000
Serial: 8250/16550 driver, 4 ports, IRQ sharing disabled
console [ttyS0] disabled
fe200000.uart: ttyS0 at MMIO 0xfe200000 (irq = 7, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
console [ttyS0] enabled
fe220000.uart: ttyS1 at MMIO 0xfe220000 (irq = 8, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
fe240000.uart: ttyS2 at MMIO 0xfe240000 (irq = 9, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
fe260000.uart: ttyS3 at MMIO 0xfe260000 (irq = 10, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
[drm] Initialized
brd: module loaded
loop: module loaded
NVT_SATA100_AHCI driver version 1.01.08 (0xF9E00000)(0xFDC00000)
nvt_sata100 f9e00000.sata: AHCI NVT GPIO LED control is enabled. (-1)(-1)(-1)(-1)(-1)
nvt_sata100 f9e00000.sata: forcing PORTS_IMPL to 0x1
nvt_sata100 f9e00000.sata: SSS flag set, parallel bus scan disabled
nvt_sata100 f9e00000.sata: AHCI 0001.0100 32 slots 1 ports 6 Gbps 0x1 impl platform mode
nvt_sata100 f9e00000.sata: flags: ncq sntf stag pm led clo only pmp pio slum part ccc
scsi host0: NVT_SATA100_AHCI
ata1: SATA max UDMA/133 mmio [mem 0xf9e00000-0xf9e00fff] port 0x100 irq 11
NVT_SATA100_AHCI driver version 1.01.08 (0xF9F00000)(0xFDD00000)
nvt_sata100 f9f00000.sata: AHCI NVT GPIO LED control is enabled. (-1)(-1)(-1)(-1)(-1)
nvt_sata100 f9f00000.sata: forcing PORTS_IMPL to 0x1
nvt_sata100 f9f00000.sata: SSS flag set, parallel bus scan disabled
nvt_sata100 f9f00000.sata: AHCI 0001.0100 32 slots 1 ports 6 Gbps 0x1 impl platform mode
nvt_sata100 f9f00000.sata: flags: ncq sntf stag pm led clo only pmp pio slum part ccc
scsi host1: NVT_SATA100_AHCI
ata2: SATA max UDMA/133 mmio [mem 0xf9f00000-0xf9f00fff] port 0x100 irq 12
nand_hw_init: round to 37500000 Hz
id =  0x20 0x40 0x18 0x20
at XmMtd_Test_FlashAccessInfo_init(), flashSizeMB: 0x10.
@nvt_flash_setup(), CONFIG_CLOSE_SPI_NAND_8PIN_4IO = y.
eFlashType: 22.
Flash Name: XM_XM25QH128C{0x204018), 0x1000000.
@XmSpiNor_BlkLockMgr_init(), nTotalBlks: 286.
lk=>6, 0x800000.
SRx val: {[1, 0x38], [1, 0x12], [1, 0x60], [0, 0x0]}, SrVal: 0x700000000601238.
spi020_nor fa900000.nor: mtd .name=spi_nor.0 .size=1000000(16M) .erasesize = 0x10000(64K)
spi020_nor fa900000.nor: 1-bit mode @ 48000000 Hz
mtd: no mtd-id
10 ofpart partitions found on MTD device spi_nor.0
at XMMtd_RegisterProtFreeRgn() index:0,offset:0xf80000,size:0x80000.
at XmMtd_Test_FlashAccessInfo_registerStatBlock(), addr: 0xF80000, startBlock: 248, erasesize: 0x10000.
at XmSpiNor_freeProtFrom() offset:0xF80000, level:6, mtd->size: 0x1000000.
port auto power off 0x8B943000
Creating 10 MTD partitions on "spi_nor.0":
0x000000000000-0x000000010000 : "loader"
0x000000010000-0x000000030000 : "fdt"
0x000000030000-0x000000050000 : "fdt.restore"
0x000000050000-0x0000000b0000 : "boot"
0x0000000b0000-0x000000420000 : "romfs"
0x000000420000-0x000000ba0000 : "usr"
0x000000ba0000-0x000000c10000 : "web"
0x000000c10000-0x000000f60000 : "custom"
0x000000f60000-0x000000f80000 : "logo"
0x000000f80000-0x000001000000 : "mtd"
libphy: Fixed MDIO Bus: probed
nvt_eth_env_probe: IO MEM res start 0xfcd00000
nvt_eth_env_probe: get IO MEM 0x8b9a0000
nvt_eth_env_probe: get pinmux 0x200
nvt_eth_env_probe: pinmux detect emb phy 0x200
DWC_ETH_QOS: Phy detected at ID/ADDR 1
nvt_probe: enter
nvt_probe: get pinmux 0x200
NVT EMB phy route to MAC1
Get remap addr 0x8b973000
libphy: dwc_phy: probed
port auto power off 0x8B94B000
nvt_resume: enter
netif_napi_add() called with weight 128 on device eth%d
Supports TSO, SG and TX COE
Supports RX COE and GRO
Supports Poe Control
PPP generic driver version 2.4.2
PPP BSD Compression module registered
PPP Deflate Compression module registered
PPP MPPE Compression module registered
NET: Registered protocol family 24
usbcore: registered new interface driver zd1201
usbcore: registered new interface driver rndis_wlan
usbcore: registered new interface driver asix
usbcore: registered new interface driver ax88179_178a
usbcore: registered new interface driver cdc_ether
usbcore: registered new interface driver net1080
usbcore: registered new interface driver rndis_host
usbcore: registered new interface driver cdc_subset
usbcore: registered new interface driver zaurus
GobiNet: Quectel_Linux&Android_GobiNet_Driver_V1.6.1
usbcore: registered new interface driver GobiNet
usbcore: registered new interface driver cdc_ncm
usbcore: registered new interface driver qmi_wwan
ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
ata1: hard resetting link
ehci-nvtivot f9100000.u2host: usbhc-nvtivot
ehci-nvtivot f9100000.u2host: new USB bus registered, assigned bus number 1
ehci-nvtivot f9100000.u2host: irq 23, io mem 0xf9100000 mapped 8b975000
ehci-nvtivot f9100000.u2host: USB 2.0 started, EHCI 1.00, overcurrent ignored
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 1 port detected
ehci-nvtivot f9200000.u2host: usbhc-nvtivot
ehci-nvtivot f9200000.u2host: new USB bus registered, assigned bus number 2
ehci-nvtivot f9200000.u2host: irq 27, io mem 0xf9200000 mapped 8b9b3000
ata2: hard resetting link
ehci-nvtivot f9200000.u2host: USB 2.0 started, EHCI 1.00, overcurrent ignored
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 1 port detected
usbcore: registered new interface driver cdc_wdm
usbcore: registered new interface driver usb-storage
usbcore: registered new interface driver usbserial
usbcore: registered new interface driver usbserial_generic
usbserial: USB Serial support registered for generic
usbcore: registered new interface driver option
usbserial: USB Serial support registered for GSM modem (1-port)
usbcore: registered new interface driver qcserial
usbserial: USB Serial support registered for Qualcomm USB modem
usbcore: registered new interface driver usb_serial_simple
usbserial: USB Serial support registered for carelink
usbserial: USB Serial support registered for zio
usbserial: USB Serial support registered for funsoft
usbserial: USB Serial support registered for flashloader
usbserial: USB Serial support registered for google
usbserial: USB Serial support registered for libtransistor
usbserial: USB Serial support registered for vivopay
usbserial: USB Serial support registered for moto_modem
usbserial: USB Serial support registered for motorola_tetra
usbserial: USB Serial support registered for novatel_gps
usbserial: USB Serial support registered for hp4x
usbserial: USB Serial support registered for suunto
usbserial: USB Serial support registered for siemens_mpi
mousedev: PS/2 mouse device common for all mice
nvt_rtc_chk_power: enter
nvt_rtc_chk_power: RTC ready timeout, plz check 32K OSC on PCB
nvt_rtc fe880000.rtc: rtc core: registered nvt_rtc as rtc0
i2c /dev entries driver
NVT I2C0 Driver Version: 1.0.0(hdmi:no) irq 43, mapped at fe600000
NVT I2C1 Driver Version: 1.0.0(hdmi:no) irq 44, mapped at fe620000
NVT I2C2 Driver Version: 1.0.0(hdmi:no) irq 45, mapped at fe640000
NVT I2C3 Driver Version: 1.0.0(hdmi:no) irq 46, mapped at fe660000
NVT I2C4 Driver Version: 1.0.0(hdmi:no) irq 47, mapped at fe680000
NVT I2C5 Driver Version: 1.0.0(hdmi:no) irq 48, mapped at fe6a0000
thermal thermal_zone0: thermal_ctrl 0x0000000b
thermal thermal_zone0: tempature 0x000000fb
xmauto = 1,Will nvt_wdt_start
usbcore: registered new interface driver usbhid
usbhid: USB HID core driver
NET: Registered protocol family 17
ThumbEE CPU extension supported.
Registering SWP/SWPB emulation handler
nvt_rtc fe880000.rtc: hctosys: unable to read the hardware clock
VFS: Mounted root (squashfs filesystem) readonly on device 31:4.
devtmpfs: mounted
Freeing unused kernel memory: 268K
This architecture does not have kernel memory protection.
random: fast init done
Hacked by HouseY2K
Mounting root fs rw ...
mount: can't read '/proc/mounts': No such file or directory
Mounting linux VFS
Mounting /usr from /dev/mtdblock5
Enabling hotplug device nodes (mdev)
Bringing up network interface
ifconfig: SIOCSIFADDR: No such device
Loading modules
-----------------------------------------------------------kwrap: loading out-of-tree module taints kernel.

        Boot NVR_MODE=0
-------------------------------------nvt_vos: 1.00.005 (Apr 26 2021 10:22:43)
----------------------
NVTMEM: register misc device successfully!
NVTMEM: 0.0.5
log.ko v2.7: Apr 26 2021 10:22:50 (mmap 0x89000000 size 0x78000 vmalloc 0)

LOG base 0x89760000(ddr0) size 64K (start pointer 0x7e832014)
PAGE_OFFSET(0x80000000) VMALLOC START(0x8b800000) HZ(100)
ms: module license 'NVT' taints kernel.
ms.ko v2.33 Apr 26 2021 10:22:55
em.ko v2.21 Apr 26 2021 10:22:55
em_user v2.0 Apr 26 2021 10:22:55
Start EM thread 0(em_callback) with nice -20
Start EM putjob (em_putjob) with nice -20
TVE100: PA = 0xfad00000, VA = 0x8baf9000, size:0x1000 bytes
TVE 100 INIT OK.
HDMI(fd900000.hdmi20): paddr:0xfd900000, vaddr:0x8bb11000, drv version:1.1.17.
hdmi20 driver version:1.1.17

LCD300 platform: Hook NA51068 driver.
lcd300: suspend_state:1

LCD210 platform: Hook NA51068 driver.
LCD200:0: suspend_state:1
HI_CHIP_NT832X addr = 0
HI_CHIP_NT832X =0
i2c_client_init0!!
at24c driver init successful!
 ===============================================================
 ===============================================================
at24c driver init start ...
gpio_i2c_wread_24c16 0x00:d2
gpio_i2c_read_24c16 0x01:d4
FVIDEO driver init start ...
HI_CHIP_HI3521d
HI_CHIP_HI3521d   -1973783520
i2c_client_init0!!
ext0_clk driving 2
fvideo driver init successful!
 ===============================================================
| BM8563: Compiled by zhangyangyang at Apr  1 2021 09:35:11 |
 ===============================================================
HI_CHIP_NT832X addr = 0 I2cAddr = 0xa2
HI_CHIP_NT832X=0
i2c_client_init0!!
bm8563 driver init start ...
@RTC: BM8563 driver init successful!
[VCAP_INF]: VCAP316 Version: 0.2.12
[VCAP_INF]: VCAP316 Host#0 Version: 0.2.4
kflow_vpe Version: 1.1.19.000 Apr 26 2021 10:22:55
dsp_drv_init done done
kflow_di Version: 1.1.6.000 Apr 26 2021 10:22:55
nvt_jpg_module_init:
kdrv_jpg driver version: 1.00.022
H26X Encoder v0.2.76, built @ Apr 26 2021 10:22:50
[VE]Encoder flow v1.0.18, built @ Apr 26 2021 10:22:55
H26X Decoder IRQ mode PLT:9832X, version 0.1.43.0 built @ Apr 26 2021 10:22:50
[VD]Decoder flow v1.0.15.0, built @ Apr 26 2021 10:22:55
osg_drv:Version: 1.02.2 Apr 26 2021 10:22:50
osg_drv:osg(0, 0) IP version 0x19100940 fire_mode = Link-List
osg_module_initial:kflow_osg Version: 0.0.009 Apr 26 2021 10:22:55
install prealloc ok
rtusb init rt2870 --->
usbcore: registered new interface driver rt2870
[GM2D] version :1.03.22 init done vbase 0x8C7B2000, pbase 0xFAA00000 0x892DAC00 36
ssca_module_init:
ssca_probe:SSCA ver:0.01.10 initial done
gs.ko v2.45 Apr 26 2021 10:22:55
GS driver, log: level(0) category(0) bmp width(64)
usr.ko v2.13 Apr 26 2021 10:22:55
vpd.ko v2.67 (gmlib->ioctl v1.14) Apr 26 2021 10:22:55
datain v2.6 (minors 176 : 0x2 + 2) Apr 26 2021 10:22:55
dataout v2.3 (minors 192 : 0x2 + 0) Apr 26 2021 10:22:55
clearwin mode 0 v3.1 Apr 26 2021 10:22:55

fc400000.nvt_arb
0. resource:0xfc400000 size:0xa000
1. resource:0xfd600000 size:0xa000
IRQ 0. ID26
DevID Major:249 minor:0
Arbiter addr 0xfc400000 0x8c920000
SEM ID: 0x7ee89480
ddr_arb_platform_create_resource: exit
nvt_ddr_arb_drv_init: resource done
nvt_irdet_module_init:
nvt_irdet_probe:0. resource:0xfe540000 size:0x1000
nvt_irdet_probe:IRQ 0. ID17
nvt_irdet_probe:DevID Major:248 minor:0
CMD:i2c 0x11011
doing mdev-s
done!!
idx:3
Disabling watchdog(s)
============================================
  NOVATEK CLEAN BOOT SUCCESSFUL! @housey2k
============================================
Welcome to XM Platform.
/ #

U-Boot environment

The stock U-Boot environment dump:

appCloudExAbility=Yvov7pgKAe4=
appRunningOut3Days=Dm8Hxy71
appSystemLanguage=Portugal
appVideoStandard=NTSC
arch=arm
baudrate=115200
board=nvt-na51068
board_name=nvt-na51068
bootargs=earlyprintk console=ttyS0,115200 init=linuxrc mem=${osmem} rootwait nprofile_irq_duration=on root=/dev/mtdblock4 rootfstype=squashfs mtdparts=spi_nor.0
bootcmd=setenv setargs setenv bootargs ${bootargs};run setargs;run loadlogo;run loadromfs
bootdelay=0
cpu=armv7
da=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 u-boot.bin.img;sf probe 0;flwrite
dc=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 custom-x.cramfs.img;sf probe 0;flwrite
dd=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 mtd-x.jffs2.img;sf probe 0;flwrite
de=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 u-boot.env.img;sf probe 0;flwrite
df=eth_init;mw.b 0x02000000 ff 100000;tftpboot 0x02000000 fdt.bin.img;flwrite
dl=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 logo-x.cramfs.img;sf probe 0;flwrite
dr=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 romfs-x.cramfs.img;sf probe 0;flwrite
du=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 user-x.cramfs.img;sf probe 0;flwrite
dw=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 web-x.cramfs.img;sf probe 0;flwrite
eth1addr=00:0b:3d:10:00:01
ethact=eth1
ethaddr=00:0b:3f:00:00:01
ethprime=eth0
fdt_high=0x04000000
gatewayip=192.168.68.254
hostname=oaalnx
ipaddr=192.168.68.101
ld=eth_init;mw.b 0x02000000 ff 100000;tftpboot 0x02000000 loader.bin.img;flwrite
loadlogo=sf probe 0;sf read 0x04000000 0xF60000 0x20000;logoload 0x04000000;decjpg 0;bootlogo
loadromfs=sf probe 0;sf read 0xB00000 0xB0000 0x370000;squashfsload;nvt_boot
mtdids=nor0=spi_nor.0
mtdparts=mtdparts=spi_nor.0:0x10000@0x0(loader),0x20000@0x10000(fdt),0x20000@0x30000(fdt.restore),0x60000@0x50000(boot),0x370000@0xb0000(romfs),0x780000@0x420000(usr),0x70000@0xba0000(web),0x350000@0xc10000(custom),0x20000@0xf60000(logo),0x80000@0xf80000(mtd)
netmask=255.255.255.0
osmem=0xb400000
serverip=192.168.68.100
soc=nvt-na51068
stderr=serial
stdin=serial
stdout=serial
tk=eth_init;tftpboot 0x02000000 uImage;setenv setargs setenv bootargs ${bootargs};run setargs;nvt_boot 0x02000000
ua=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 upall_verify.img;sf probe 0;flwrite
up=eth_init;mw.b 0x02000000 ff 0x1000000;tftpboot 0x02000000 update.img;sf probe 0;flwrite
vendor=novatek
ver=U-Boot 2016.07 (Apr 11 2022 - 13:54:25 +0800)

Environment size: 2578/65532 bytes

Sofia configuration dump

The configuration dump produced by Sofia:

DDR  Type   Size       Addr          Name               Shared Pool
 0    028    1352KB   0x0B400000   enc_scl_out
/var/SifiaIsRun No Run 9/120 0    000   16200KB   0x0B552000   disp0_in

 0    107    4080KB   0x0C524000   disp0_fb
 0    001     812KB   0x0C920000   disp1_in
 0    102    1260KB   0x0C9EB000   tmnr_motion
 0    033   14456KB   0x0CB26000   common
 0    024    9788KB   0x0D944000   disp_dec_in
 0    029   12388KB   0x0E2D3000   enc_out
 0    103    4860KB   0x0EEEC000   osg
 0    025   45024KB   0x0F3AB000   disp_dec_out         disp0_cap_out
 0    027   75552KB   0x11FA3000   enc_cap_out
 0    034   17012KB   0x1CDAB000   user_blk
 0    031     200KB   0x1DE48000   au_enc
 0    032      40KB   0x1DE7A000   au_dec
(28)enc_scl_out_ddr0 DDR0(1352KB)
(00)disp0_in_ddr0 DDR0(16200KB)
(01)disp1_in_ddr0 DDR0(812KB)
(33)common_ddr0 DDR0(14456KB)
(24)disp_dec_in_ddr0 DDR0(9788KB)
(29)enc_out_ddr0 DDR0(12388KB)
(103)osg_ddr0 DDR0(4860KB)
(25)disp_dec_out_ddr0 DDR0(45024KB)
(06)disp0_cap_out_ddr0 DDR0(0KB)
(27)enc_cap_out_ddr0 DDR0(75552KB)
(34)user_blk_ddr0 DDR0(17012KB)
(31)au_enc_ddr0 DDR0(200KB)
(32)au_dec_ddr0 DDR0(40KB)

My final effort with this thing

The last thing I tried was compiling the full thing with the SDK on Ubuntu 14.04 I used config number 9 on lunch These commands were necessary:

sudo docker run -it   --name nt9832x-ubuntu14   -v "$HOME/NT9832x_SDK/software/board/na51068_linux_sdk:/home/brenno/NT9832x_SDK/software/board/na51068_linux_sdk"   -v /opt/ivot/arm-ca9-linux-uclibcgnueabihf-6.5:/opt/arm-ca9-linux-uclibcgnueabihf-6.5   ubuntu:14.04

# inside the container

apt update
apt upgrade -y
apt install -y build-essential git bc bison flex libssl-dev libncurses-dev \
    squashfs-tools mtd-utils u-boot-tools python3 python3-pip \
    libmpfr6 libmpc3 libgmp-dev
	
cd /home/*/NT9832x_SDK/software/board/na51068_linux_sdk/code/hdal/samples/hdal_product

grep -Rnl --include='Makefile' 'sh install.sh' ./ | xargs sed -i 's/sh install\.sh/bash install.sh/g'

I managed to compile the full system, then I uncompressed output/raw/rootfs.squash.bin.raw into the romfs directory, removed usr from the repack script, and tried flashing, but the vendor u-boot apparently has a bug where partitions after a certain size fail to read and the thing gets stuck in a boot loop Then I tried replacing the BCL1 U-Boot generated by the SDK, and it failed even earlier, it couldn’t load U-Boot, not really explained, so I’m ending this project here

Sleep solves everything

Got the framebuffer to work after running vanilla Sofia on the clean linux, before this I got Claude to make me a Sofia patch that would run only a function called SystemSDKInit, it kinda worked and initialized the hardware and a bunch of stuff popped on /dev, but I didn’t see a framebuffer. After looking around on the SDK docs and IDA I found out we needed to call hd_videoout_set to create the framebuffer. My Claude Free usage ran out so I decided to just run the vanilla Sofia on the clean Linux, I already knew it was gonna crash, but I was surprised when I saw that it went far enough to initialize the hardware, then it ended trying to load a language file, failing, then having a segfault. This is the log for Sofia:

atmagic[0]=d2,atmagic[1]=d4, ret[0], cptat24c_fd[4]
random: crng init done
CryptoDecrypt,565 or_sel=1
LibCrypto : g_cryptotype = 1, a24
LibCrypto : FILE -> crypto.c, LINE -> 992: fopen fail
SERIES_TYPE = 3
PRODUCTION_MODEL = 0xf0
Jul 28 20at mtdchar_ioctl() <case XMMTD_GETLOCKVERSION> xmVersion:0x1001.
22 20:43:21 ==>CaptureSetBasicHVRCap(1274): open file error.
Jul 28 2022 20:43:21 ==>CaptureSetHVRCap2(1185): open file error,fd=-1
Jul 28 2022 20:43:21 ==>Capturat XmMtd_Comm_unlockUser() start: 0xFFFFFFFFFFFFFFFF >= ChipSize: 16777216 <UnLock All>.
eSetHVRCap2(1185): open file error,fd=-1
flash/flasat XmMtd_Comm_unlockUser() start: 0x0, length: 0x1000000.
h.c(145) [Flash_getLockVersion]: version:0x1001!
flashall blocks is unlocked.
/flash.c(380) [getSofiaFileInfo]: stat Error:/usr/bin/Sofia.tar.lzma!flash/flash.c(498) [FlashProtect_judge]: File not exists!
flash/flash.c(431) [ProtectInfoFile_update]: fopen() Failed<1>:/mnt/mtd/Config/FlashProtectInfoFile!
2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
mflash/flash.c(657) [Flash_start]: Disable_Prot OK!
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
osmemsize:b400000 pBootArgs 0xb400000
Jul 28 2022Output extra 9 SCL clocks to release device hang!
 20:43:21 ==>CaptureGetJsonValue(586): debug assertion failure (i2c#1 iaddr:0x88 write failed!!
0 == access(CONFIG_JSON, F_OK))
Jul 28 2022 20:43i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
:21 ==>CaptureGetCustom(645): debug assertion failure (ret == 0)i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)

*******************************************************Output extra 9 SCL clocks to release device hang!
***************
|                      SYSTEM INFO             i2c#1 iaddr:0x88 read failed!!

|  libcpypto version:           1.0.1 svn 596i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
-chenbo Complie time May 11 2021 20:16:53
|          slave_num:i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
                0
| mast video channel:           8
| mast audio channel:           4
|slave Output extra 9 SCL clocks to release device hang!
video channel:          0
|slave audio channel:           0
|         alarm modi2c#1 iaddr:0x88 write failed!!
e:              Com in-0 out-0
|        master chip:           0x0010
|   productioi2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
n model:                0x00f0
|        disk number:           0x0002
***************i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
*******************************************************
cpu_typOutput extra 9 SCL clocks to release device hang!
e:16
i2c#1 iaddr:0x88 read failed!!
i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
i2c i2c-1: ftiic010_tx_msg addr 0x44 data 0x88 fail (-121)
Output extra 9 SCL clocks to release device hang!
i2c#1 iaddr:0x88 read failed!!
Fvideo: SampleChipType_V1,Line 781,~~~~~~~~~~~~~~~~~~~~~~6168C
Fvideo: SampleChipType_V1,Line 812,~~~~~~~~~~~~~~~~~~~~~~G_Pthread_Enable=1
playbackSize 46104576 previewSize 32272384
ddr_usage[0] 12a84000 sys_hdal.size[0] 14c00000DDR  Type   Size       Addr          Name               Shared Pool

 0    028    1352KB   0x0B400000   enc_scl_out
 0    000   16200KB   0x0B552000   disp0_in
 0    107    4080KB   0x0C524000   disp0_fb
 0    001     812KB   0x0C920000   disp1_in
 0    102    1260KB   0x0C9EB000   tmnr_motion
 0    033   14456KB   0x0CB26000   common
 0    024    9788KB   0x0D944000   disp_dec_in
 0    029   12388KB   0x0E2D3000   enc_out
 0    103    4860KB   0x0EEEC000   osg
 0    025   45024KB   0x0F3AB000   disp_dec_out         disp0_cap_out
 0    027   75552KB   0x11FA3000   enc_cap_out
 0    034   17012KB   0x1CDAB000   user_blk
 0    031     200KB   0x1DE48000   au_enc
 0    032      40KB   0x1DE7A000   au_dec
(28)enc_scl_out_ddr0 DDR0(1352KB)
(00)disp0_in_ddr0 DDR0(16200KB)
(01)disp1_in_ddr0 DDR0(812KB)
(33)common_ddr0 DDR0(14456KB)
(24)disp_dec_in_ddr0 DDR0(9788KB)
(29)enc_out_ddr0 DDR0(12388KB)
(103)osg_ddr0 DDR0(4860KB)
(25)disp_dec_out_ddr0 DDR0(45024KB)
(06)disp0_cap_out_ddr0 DDR0(0KB)
(27)enc_cap_out_ddr0 DDR0(75552KB)
(34)user_blk_ddr0 DDR0(17012KB)
(31)au_enc_ddr0 DDR0(200KB)
(32)au_dec_ddr0 DDR0(40KB)
366-GM2D_DRV_LIB_VER:1.03.21gm2d_file_mmap:gfx size:0x5000 io_size:0x1000 page_off:0x0 mapping_type:0x0

GM2D ID:0x20190903driver_init_device: 366EP0 is inactive
use default HVR config.
================dump_hvrcap()================
                Analog-n4KChn:      0
                Analog-n5MChn:      0
                Analog-n4MChn:  0
                Analog-n3MChn:      0
                Analog-n1080PChn:  0
                Analog-n5M_NChn:        8
                Analog-n4M_NChn:        0
                Analog-n1080NChn:  0
                Analog-n720PChn:   0
                Analog-n960HChn:   0
                Analog-nD1Chn:     0
                Analog-nHD1Chn:    0
                Analog-nCIFChn:    0
                Digital-n4KChn:    0
                Digital-n5MChn:    0
                Digital-n4MChn:    0
                Digital-n3MChn:    0
                Digital-n1080PChn: 0
                Digital-n1080NChn: 0
                Digital-n960PChn:  0
                Digital-n720PChn:  0
                Digital-n960HChn:  0
                Digital-nD1Chn:    0
                Digital-nHD1Chn:   0
                Digital-nCIFChn:   0
                AnalogCap-nPlayChn:   4
                AnalogCap-nDigiTalChn:   0
                DigitalCap-nPlayChn:   4
                DigitalCap-nDigiTalChn:   0
use default HVR config.
================dump_hvrcap()================
                Analog-n4KChn:      0
                Analog-n5MChn:      0
                Analog-n4MChn:  0
                Analog-n3MChn:      0
                Analog-n1080PChn:  0
                Analog-n5M_NChn:        8
                Analog-n4M_NChn:        0
                Analog-n1080NChn:  0
                Analog-n720PChn:   0
                Analog-n960HChn:   0
                Analog-nD1Chn:     0
                Analog-nHD1Chn:    0
                Analog-nCIFChn:    0
                Digital-n4KChn:    0
                Digital-n5MChn:    0
                Digital-n4MChn:    0
                Digital-n3MChn:    0
                Digital-n1080PChn: 0
                Digital-n1080NChn: 0
                Digital-n960PChn:  0
                Digital-n720PChn:  0
                Digital-n960HChn:  0
                Digital-nD1Chn:    0
                Digital-nHD1Chn:   0
                Digital-nCIFChn:   0
                AnalogCap-nPlayChn:   4
                AnalogCap-nDigiTalChn:   0
                DigitalCap-nPlayChn:   4
                DigitalCap-nDigiTalChn:   0
**************************************************
| LIBHICAP: Compiled at Jul 28 2022 20:43:20  SVN:3631
|TOTAL_VI_CHN_NUM                       8
|TOTAL_VENC_CHN_NUM                     16
|VENC_CHN_NUM_HOST_CHIP                 16
|TOTAL_AI_CHN_NUM                       8
|TOTAL_AENC_CHN_NUM                     8
|AENC_CHN_NUM_HOST_CHIP                 8
|HDEC_CHN_NUM                           4
|VDEC_CHN_NUM                           4
|HVR_PLAY_DECODE_NUM                    4
|HVR_DIGITAL_DECODE_NUM                 0
**************************************************
misc/sys.c(1909) [XmDvr_System_constructor]: <<<<<<Enter>>>>>=>ibwlan version: 1.0.0 - Complie time Apr 10 2021 10:03:57, wpa-psk


Sofia: $Version_fix: R11, $Source svn: 30502, $Include svn: 41183, $Build svn: 41181, Exchange svn: 41170, Build in:Jul 30 2022, 14:38:27, 0
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
misc/sys.c(563) [NT8321_getBoardType]: @ Get 0xfe040004 = 0xd16aaab8
0_15:[0x0]


Infra: $base Dir Trunk, $Source svn: 39231, $Include svn: 2915, $Build in:Mar 17 2022, 10:17:44
CInfra::start()>>>>>>>>>>
CTimerManager::CTimerManager()>>>>>>>>>
CThreadManager::CThreadManager()>>>>>>>>>

libManager.a: $base Dir D_General_Manager_V4.02.0.R11_20130906, $Source svn: 41057, $Include svn: 30262, $Build in:Jun 28 2022, 20:03:41

!!dir /mnt/mtd/Config create failed
CConfigManager::start()...
CVerifyConfig::Start()...
CDefaultConfig::Start()...

===new timezone__-480__,old timezone__0___========

CTime::setTimeZone(-480):TEI-8:00
onVerifyNetIPFilter() ../../Manager/VerifyConfig.cpp 1306
onVerifyNetDHCP() ../../Manager/VerifyConfig.cpp 1312
onVerifyNetDDNS() ../../Manager/VerifyConfig.cpp 1317
onVerifyNetEmail() ../../Manager/VerifyConfig.cpp 1322
custom config NetWork.RemoteDevice verify failed with ret:20!
GUITheme List:
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
misc/sys.c(697) [GetBoardHardwareVersion]: @ Get 0xfe040004 = 0xd16aaab8
misc/sys.c(709) [GetBoardHardwareVersion]: @ Get 0_26 = 0x0
ethMac:00:55:7b:b5:7d:f7

==timezone:-480==0=

CTime::setTimeZone(-480):TEI-8:00
CConfigManager::setConfig(System.TimeZone, )
CConsole::start()...
CMagicBox::start()...
ethMac:00:55:7b:b5:7d:f7
tracepoint: Source/MagicBox.cpp,1475
Use OEM mac  normal:00124264dbf8  oem:00557bb57df7
--- use v3 SN --- SN:907278faf17e3b8cmec6 -- year:2022 rand:0

initOEMinfo-->1674,[Source/MagicBox.cpp],m_oemInfo[BURN_OEM_ID]9,m_oemInfo[BURN_OEM_PRODUCT]0,m_oemInfo[BURN_OEM_SERIAL]0
pCaps->HasAudioBoard 4
misc/sys.c(405) [SystemGetBoardType]:  ===============================================================
misc/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled by zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
CurrentTime:1970-01-01 08:00:39
FlashTime:2000-00-00 00:00:00
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$CMOS NO PWOER$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
RecoverFlash Time:1999-11-30 00:00:25
Log Manager starting....!

Log.a: $base Dir Trunk, $Source svn: 37523, $Include svn: 2919, $Build in:Jun 16 2020, 10:46:21

=======Shut Down at 2000-0-0 00:00:00 with m_exitState[0]
CDaylight::start()...
m_cloudExAbility:0
watchdaog is creat???
watchdog/wdt.c(58) [app_auto]: Get xmauto Fialed ,xmauto = 1
1111111111111i = 0
i = 1
i = 2
i = 3
i = 4
i = 5
i = 6
i = 7
i = 8
i = 9
i = 10
i = 11
i = 12
i = 13
i = 14
i = 15
i = 16
i = 17
i = 18
i = 19
i = 20
i = 21
i = 22
i = 23
i = 24
i = 25
i = 26
i = 27
i = 28
i = 29
i = 30
i = 31
i = 32
i = 33
i = 34
i = 35
i = 36
i = 37
i = 38
i = 39
i = 40
i = 41
i = 42
i = 43
i = 44
i = 45
i = 46
i = 47
i = 48
i = 49
CMagicBox::Write fail!!
==>libdvr:SystemTimeToRtcTimeSet called.
gmtime :100-0-1, today is weekday 6
time:0:0:44
============================================================?tm->tm_year = 0
libdvr SystemTimeToRtcTimeSet
CTime::setCurrentTime SystemTimeToRtcTimeSet to 2000-01-01 08:00:44
CConfigManager::setConfig(General.Location, )
@CDevAbility::start()>>>>>>>>>>
HasIntelFunc: 1, HasCPCFunc: 0, HasNatFunc: 1, HasSpotFunc: 0, HasBaseFunc: 0, HasEnBaseFunc: 0, HasHVRFunc:0, FrontSwithType:1, system_func.NoHasDeep:1, cpu:43
CConfigManager::getConfig 'Ability.PreHVRCapMode', but default config is not set yet!
CConfigManager::setConfig(Ability.PreHVRCapMode, )
CConfigManager::setConfig(fVideo.VideoSeque, )

Start-->1331,[../../Manager/DevAbility.cpp],m_eNVRSwitchMode[0x00000004],ability_D1[0],m_cpuAbility[20],m_iNumMainStream[0],m_maxD1Num[1]
m_nVTotalChns: 8, m_nVCapChns: 8, m_nVPlayChns: 4, m_nDigDecChns: 0
CConfigManager::getConfig 'fVideo.AudioAcquisinvt_irdet_drv_open:0
tionMode', but default config is not set yet!
pCaps->HasAudioBonvt_irdet_api_write_receiver_test:pinmux is not set
ard 4
misc/sys.c(405) [SystemGetBoardType]:  =============nvt_irdet_api_write_receiver_test:NEC protocol
==================================================
misnvt_irdet_proc_cmd_open:
c/sys.c(406) [SystemGetBoardType]: | LIBDVR: SVN:3750,Compiled bnvt_irdet_proc_cmd_write:CMD:w ch 8
y zhangyangyang at Apr  8 2022 17:13:57 |
misc/sys.c(407) [SystemGetBoardType]:  ===============================================================
CConfigManager::setConfig(Ability.DigitalReal, )
CConfigManager::setConfig(NetWork.DigManagerShow, )
reboot config onVerifyMultiChannel 2520
CConfigManager::setConfig(Detect.MotionDetect, )
CConfigManager::setConfig(Detect.BlindDetect, )
CConfigManager::setConfig(Detect.LossDetect, )
CConfigManager::setConfig(Alarm.LocalAlarm, )
CConfigManager::setConfig(Detect.HumanDetectionDVR, )
CConfigManager::setConfig(Detect.FaceDetection, )
CFrontboard::CFrontboard()>>>>
FbdCreateInit Successful /dev/ttyS1
uart/fbd.c(910) [Fbd_NOMCUCreate]: 0xfe040000:0xaa96aaa0
uart/fbd.c(915) [Fbd_NOMCUCreate]: 0xfe040000:0xaa96aaa0
uart/fbd.c(918) [Fbd_NOMCUCreate]: 0xfe040010:0xaa69a
uart/fbd.c(922) [Fbd_NOMCUCreate]: 0xfe040010:0xa0692
uart/fbd.c(333) [UpDateMessage]: UpDateMessage success
uart/fbd.c(425) [UpDateMessage]:
COL_COUNT=5,ROW_COUNT:5,COL_COUNT=5,ROW_COUNT5
CFrontBoardParser::Init()>>>>>>>>>
0xfe040010:[0xa0692]
sProtocolName: General
CFrontBoardParser::Init()>>>>>>>>>
sProtocolName: General


Manager: $Rev: 1008 $, Build in:Jul 30 2022, 14:23:33
CManager::start()>>>>>>>>>>

Launched at Local Time 2000/1/1 08:00:45!
CUserManager::start......
CUserManager::setDefault() custom config file parsing failed.
write config file failed!
CConfigManager::setConfig(System.ExUserMap, )
onVerifyNetIPFilter() ../../Manager/VerifyConfig.cpp 1306
CAutoMaintain::Start()...
m_randomDelayMinutes:0
CConfigManager::getConfig 'Network.WebLoginEncrypt', but default config is not set yet!
Debug Tld: remove aMainFile Failed, Err: No such file or directory.
Debug Tld: remove aSecFile Failed, Err: No such file or directory.
misc/env.c(562) [set_do_setenv]: set nrdnx_ver =
misc/env.c(562) [set_do_setenv]: set pslgn_ver =
lk=>6, 0x800000.
 Open xml error in CustomAudioParser::Init!
CPacketManagerImp::CPacketManagerImp()>>>>>>>>>
sm_packetBuf null use self heap memory!
Adjust Page!
Packet usage : 0K / 20i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001884
479K, 0%

----------------------[01-01 08:00:46]
CCaptureBuffi2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
er::Init size = 4096 KB
======= pre record buf 4096
Output extra 9 SCL clocks to release device hang!
Fvideo: VideoCreate,Line 1724,==================================i2c#1 iaddr:0x64 write failed!!
=======================================
Fvideo: Vii2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
deoCreate,Line 1725,| LIBFVIDEO: Customer is General
2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
32mFvideo: VideoCreate,Line 1726,| LIBFVIDEO: Compiled at Jun  8Output extra 9 SCL clocks to release device hang!
 2022 09:15:16
Fvideo: VideoCreate,Line 1727,====i2c#1 iaddr:0x64 read failed!!
================================================================i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
=====
Fvideo: VideoCreate,Line 1732,>>>>>>>>>>>>Vii2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
deoCreate LINE1732  PRODUCTION_MODEL=0xf0
Fvideo: Output extra 9 SCL clocks to release device hang!
VideoCreate,Line 1741,>>>>>>>>>F_VI_CHN_NUM_HOST_CHIP=8 VI_CHN_Ni2c#1 iaddr:0x64 write failed!!
UM_HOST_CHIP=8
Fvideo: VideoCreate,Line 1742,>>>>>i2c i2c-1: ftiic010_tx_byte(428) nack! sts=0x01001804
>>>>F_AI_CHN_NUM_HOST_CHIP=4 AI_CHN_NUM_HOST_CHIP=4
2c i2c-1: ftiic010_tx_msg addr 0x32 data 0x64 fail (-121)
2mFvideo: GetCpuChipType,Line 1603,GetCpuChipType:CPU CHIP TYPE Output extra 9 SCL clocks to release device hang!
IS NVT98321
Fvideo: fvideo_register,Line 1516,fvidi2c#1 iaddr:0x64 read failed!!
eo_register:Register operation to 6168
Fvideo: nvp61xx_get_ad_maxchannel,Line 4028,get max channel num = 8
Fvideo: nvp6158_videoModeInit,Line 5850,Get system captureSize set is  30,NVP6158_OUTMODE=15,CAPTURE_SIZE_5M_N
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[0]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[1]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[2]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[3]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[0]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[1]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[2]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[3]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6168_audio_re_initialize,Line 24618,Audio init!! Audio sampling rate=8000~~~chip_num=0 AudioType = 0
Fvideo: nvp6158_audio_default_set,Line 5358, audio ch =8
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[4]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[5]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[6]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[7]=0x0 ed=0x0 69=0x0
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[4]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[5]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[6]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6158_port_format_mode_set,Line 1223,CIF func,video mode[7]=0x201900 ed=0x0 69=0x0
Fvideo: nvp6168_novideo_1080P_set,Line 338,...... 1080P no video set! ......
Fvideo: nvp6168_audio_re_initialize,Line 24618,Audio init!! Audio sampling rate=8000~~~chip_num=1 AudioType = 0
Fvideo: nvp6158_audio_default_set,Line 5358, audio ch =8
NVP6168/C reset AD channel ad addr=0x60
NVP6168/C reset AD channel ad addr=0x62
>>>>change channel[0] = 0
>>>>change channel[1] = 1
>>>>change channel[2] = 2
>>>>change channel[3] = 3
>>>>change channelGM_ffb: [ver:1.2.1]INIT flcd300 OK.
[4] = 4
>>>>change channel[5] = 5
>>>>change channel[6] = 6
>LCD300(0): PA = 0xfda00000, VA = 0x8cae0000, size:0x10000 bytes, dfb_size=0
>>>change channel[7] = 7
LCD300(0): deskres(3):1024x768(XVGA), output(46):HDMI_1024x768_RGB

hdmi_setting, target is HDMI_1024X768P60.
hdmi_polling_thread is running.
LCD300: Common Driver[Ver: 1.1.20]
hdmi_polling_thread, apply new vid:163 setting.
hdmi: hotplug is ON!

LCD300(0) registers 1 entities to video graph!
LCD300(0): Driver[Ver: 2.1.24] init ok, Chip Ver[0x20190731, 0x3210310], fb0_fb1_share:0
LCDC300(0) enters IDLE mode.
hdmitx_init_phy, clock_rate:65000KHz
Init PHY END
hdmi requests irq:51.
hdmi: i2c_new_device OK.
hdmi_i2c_probe done.
hdmi: i2c_add_driver OK.
hdmi_i2c(hdmi_i2c) open done.
hdmitx_init_ddc, ExtBlk:1
platform_set_pinmux_videosrc = 0, 0
platform_set_pinmux_videosrc = 0, 3
platform_set_pinmux_videosrc = 0, 10
HDMI EDID Parsing Results Flag: 0X007F173F, referece hdmitx.h: HDMI EDID flags
LCD300(0), the best EDID resolution is HDMI_1920x1080_RGB(51)
hdmi: audio stream enable.
LCD200:0: Desk resolution is NTSC.
GM_ffb: [ver:0.1.23]INIT flcd200 OK.
LCD200:0: PA = 0xfdb00000, VA = 0x8dae0000, size:0x10000 bytes
LCD200(0): deskres(0):NTSC, output(0):NTSC_SDTV
vdac_setting, target is TV_NTSC.
LCD200:0: Desk resolution is NTSC.
LCD200:0 registers 1 entities to videograph!
LCD200(0): Driver[Ver: 2.0.34] init ok, fb_max_width:720, fb_max_height:480, fb0_fb1_share:0
LCD200:0 chip_state:1
LCD200:0, pmu clock:1
lcd1 not support to set fb0
lcd1 not support to set fb2


Gdi: $base Dir Trunk, $Source svn: 39831, $Include svn: 2831, nvt_irdet_drv_ioctl:Irdet waiting task was killed error!
$Build in:Aug  9 2021, 20:09:10
CGDI::start()>>>>>>>>

@=================================
         @mem = 0x0x73cb6000 0x0x73cb6000 0x(nil)
         @pitch = 2048
         @width = 1024
         @height = 768
         @foramt = 0
@===================================
CLocales::CLocales()>>>>>>>>>
CFontManager::CFontManager()>>>>>>>>>
CFontManager::CFontManager Open FontSmallEn.bin File Failed!
CFontManager::CFontManager Open Font File Failed!
CFontManager::CFontMananvt_irdet_drv_release:0
ger Open FontGB2312 File Failed!
Language load path:/mnt/customwatchdog: watchdog0: watchdog did not stop!
/data/Strings/Portugal
CLocales::setLanguage Load Strings File '/mnt/custom/data/Strings/Portugal' Failed!
CConfigManager::getConfig 'General.SupportLang', but default config is not set yet!
Segmentation fault

Now I am working on identifying all the hardware initialization code on Sofia so I can isolate everything and remove all the DVR code, signifficantly reducing the binary size, but for now I am using the original sofia on my experiments, the next step was to find out how to write to the framebuffer correctly, because naturally I started by trying to write /dev/urandom into /dev/fb0, but I didn’t get a really good result, on a normal linux computer you get a pretty colorful “glitter” screen, but here it was mostly dark with some colored spots, I even tried to get help from AI to figure out what pixel format it was expecting, but I didn’t have success, I even ran find . -type f -name "*.h" -exec grep -n "HD_VIDEO_PXLFMT" {} + on the SDK root so we could try everything that showed up, but nothing worked, until I fed ChatGPT the documentation for hd_videoout and hd_videoout_fb because I’m way too lazy to read XD, then we figured out we needed to use fb1 instead, and for the pixel format, I did reverse engineering of Sofia looking for FMT related strings, with a little bit of looking around, I managed to find the pixel format, I found this specific function by searching for hd_videoout_set on strings and clicking on this one: .rodata:007FBB00 00000037 C hd_videoout_set:HD_VIDEOOUT_PARAM_FB_FMT, fail(0x%lx)\n, that took me to the function set_videoout_fb_fmt

.text:003EAE30 ; int __fastcall set_videoout_fb_fmt(unsigned int, int)
.text:003EAE30 set_videoout_fb_fmt                     ; CODE XREF: sub_3EB3F0+39C↓p
.text:003EAE30                                         ; sub_3EB3F0+7DC↓p
.text:003EAE30
.text:003EAE30 var_28          = -0x28
.text:003EAE30 var_24          = -0x24
.text:003EAE30 var_20          = -0x20
.text:003EAE30 dest            = -0x14
.text:003EAE30 var_10          = -0x10
.text:003EAE30 var_F           = -0xF
.text:003EAE30 var_C           = -0xC
.text:003EAE30 var_8           = -8
.text:003EAE30 var_6           = -6
.text:003EAE30 var_4           = -4
.text:003EAE30
.text:003EAE30                 PUSH            {R4-R6,LR}
.text:003EAE34                 MOV             R2, #0x14 ; n
.text:003EAE38                 SUB             SP, SP, #0x28
.text:003EAE3C                 MOV             R4, R0
.text:003EAE40                 MOV             R5, R1
.text:003EAE44                 MOV             R6, R0,LSR#16
.text:003EAE48                 MOV             R1, #0  ; c
.text:003EAE4C                 ADD             R0, SP, R2 ; s
.text:003EAE50                 BL              memset
.text:003EAE54                 MOV             R3, #0
.text:003EAE58                 ADD             R2, SP, #0x28+var_20
.text:003EAE5C                 MOV             R1, #0xA
.text:003EAE60                 MOV             R0, R4
.text:003EAE64                 STR             R3, [SP,#0x28+var_20]
.text:003EAE68                 STR             R5, [SP,#0x28+var_20+4]
.text:003EAE6C                 BL              hd_videoout_set
.text:003EAE70                 SUBS            R5, R0, #0
.text:003EAE74                 STRNE           R4, [SP,#0x28+var_24]
.text:003EAE78                 MOVWNE          R3, #0x185
.text:003EAE7C                 BNE             loc_3EAEB0
.text:003EAE80                 VLDR            D16, =0x2110155500000001

The novatek SDK headers say HD_VIDEO_PXLFMT_ARGB1555 = 0x21101555 That means we are dealing with ARGB15555 on fb1 Instead of being a typical device with fb0 controlling everything, this DVR has 3 framebuffers per videoout, we have two videoouts on this device that I assume videoout0 is HDMI/VGA and videoout1 is CVBS, but I’m just guessing, I could test tho, and fb2 I guess is reserved, I messed with it but I didn’t observe any change During my tests, with the help of AI I built a little program to debug framebuffers, here is the source for it:

// fb_test.c
//
// Novatek Linux framebuffer test utility
//
// Usage:
//   ./fb_test /dev/fb1 colors
//   ./fb_test /dev/fb1 0xFC00
//   ./fb_test /dev/fb1 bit
//   ./fb_test /dev/fb1 ramp
//
// Designed to test 16-bit framebuffer formats such as ARGB1555.

#include <stdio.h>
#include <stdlib.h>
#include <stdint.h>
#include <string.h>
#include <fcntl.h>
#include <unistd.h>
#include <sys/ioctl.h>
#include <sys/mman.h>
#include <linux/fb.h>

static uint16_t argb1555(
    int a,
    int r,
    int g,
    int b)
{
    uint16_t v = 0;

    if (a)
        v |= 0x8000;

    v |= ((r >> 3) & 0x1F) << 10;
    v |= ((g >> 3) & 0x1F) << 5;
    v |= ((b >> 3) & 0x1F);

    return v;
}

static void fill16(
    uint16_t *fb,
    size_t pixels,
    uint16_t value)
{
    for (size_t i = 0; i < pixels; i++)
        fb[i] = value;
}

static void test_value(
    uint16_t *fb,
    int width,
    int height,
    uint16_t value,
    const char *name)
{
    printf("TEST %-24s 0x%04X\n", name, value);

    fill16(fb, (size_t)width * height, value);

    /*
     * Give the display some time to show it.
     */
    sleep(2);
}

static void colors(
    uint16_t *fb,
    int width,
    int height)
{
    printf("\n=== ARGB1555 COLOR TEST ===\n\n");

    test_value(fb, width, height,
               argb1555(1,255,0,0),
               "ARGB1555 RED");

    test_value(fb, width, height,
               argb1555(1,0,255,0),
               "ARGB1555 GREEN");

    test_value(fb, width, height,
               argb1555(1,0,0,255),
               "ARGB1555 BLUE");

    test_value(fb, width, height,
               argb1555(1,255,255,255),
               "ARGB1555 WHITE");

    test_value(fb, width, height,
               argb1555(1,0,0,0),
               "ARGB1555 BLACK");

    /*
     * Alpha = 0 versions.
     */
    test_value(fb, width, height,
               argb1555(0,255,0,0),
               "A0 RED");

    test_value(fb, width, height,
               argb1555(0,0,255,0),
               "A0 GREEN");

    test_value(fb, width, height,
               argb1555(0,0,0,255),
               "A0 BLUE");

    /*
     * Byte-swapped versions.
     *
     * Useful if the framebuffer memory/display path has
     * unexpected byte ordering.
     */
    test_value(fb, width, height,
               0x00FC,
               "SWAP RED");

    test_value(fb, width, height,
               0xE083,
               "SWAP GREEN");

    test_value(fb, width, height,
               0x1F80,
               "SWAP BLUE");

    test_value(fb, width, height,
               0xFFFF,
               "0xFFFF");

    test_value(fb, width, height,
               0x0000,
               "0x0000");

    /*
     * Useful diagnostic patterns.
     */
    test_value(fb, width, height,
               0x8000,
               "ALPHA ONLY");

    test_value(fb, width, height,
               0x7FFF,
               "RGB MAX A0");

    printf("\nDone.\n");
}

static void bit_test(
    uint16_t *fb,
    int width,
    int height)
{
    printf("\n=== INDIVIDUAL BIT TEST ===\n");
    printf("Each bit is displayed for 2 seconds.\n\n");

    for (int bit = 0; bit < 16; bit++)
    {
        uint16_t value = (uint16_t)(1U << bit);

        printf("BIT %2d -> 0x%04X\n", bit, value);

        fill16(
            fb,
            (size_t)width * height,
            value
        );

        sleep(2);
    }

    printf("\nDone.\n");
}

static void ramp_test(
    uint16_t *fb,
    int width,
    int height)
{
    printf("\n=== BIT RAMP TEST ===\n");

    for (int bit = 0; bit < 16; bit++)
    {
        uint16_t value = (uint16_t)((1U << (bit + 1)) - 1);

        printf("BITS 0..%2d -> 0x%04X\n",
               bit,
               value);

        fill16(
            fb,
            (size_t)width * height,
            value
        );

        sleep(1);
    }

    printf("\nDone.\n");
}

static void exact_value(
    uint16_t *fb,
    int width,
    int height,
    uint16_t value)
{
    printf("Writing exact value 0x%04X\n", value);
    printf("Press Ctrl+C to stop.\n");

    fill16(
        fb,
        (size_t)width * height,
        value
    );

    while (1)
        sleep(1);
}

int main(int argc, char **argv)
{
    if (argc < 3)
    {
        printf(
            "Usage:\n"
            "  %s <fbdev> colors\n"
            "  %s <fbdev> bit\n"
            "  %s <fbdev> ramp\n"
            "  %s <fbdev> 0x1234\n"
            "\n"
            "Examples:\n"
            "  %s /dev/fb1 colors\n"
            "  %s /dev/fb1 bit\n"
            "  %s /dev/fb1 0xFC00\n",
            argv[0], argv[0], argv[0], argv[0],
            argv[0], argv[0], argv[0]);

        return 1;
    }

    const char *device = argv[1];
    const char *mode = argv[2];

    int fd = open(device, O_RDWR);

    if (fd < 0)
    {
        perror("open framebuffer");
        return 1;
    }

    struct fb_fix_screeninfo finfo;
    struct fb_var_screeninfo vinfo;

    memset(&finfo, 0, sizeof(finfo));
    memset(&vinfo, 0, sizeof(vinfo));

    if (ioctl(fd, FBIOGET_FSCREENINFO, &finfo) < 0)
    {
        perror("FBIOGET_FSCREENINFO");
        close(fd);
        return 1;
    }

    if (ioctl(fd, FBIOGET_VSCREENINFO, &vinfo) < 0)
    {
        perror("FBIOGET_VSCREENINFO");
        close(fd);
        return 1;
    }

    printf("\n");
    printf("Framebuffer: %s\n", device);
    printf("Name       : %s\n", finfo.id);
    printf("Resolution : %ux%u\n",
           vinfo.xres,
           vinfo.yres);
    printf("Virtual    : %ux%u\n",
           vinfo.xres_virtual,
           vinfo.yres_virtual);
    printf("BPP        : %u\n",
           vinfo.bits_per_pixel);
    printf("Stride     : %u bytes\n",
           finfo.line_length);

    printf("\nLinux FB format description:\n");
    printf("  Red    : offset=%u length=%u\n",
           vinfo.red.offset,
           vinfo.red.length);
    printf("  Green  : offset=%u length=%u\n",
           vinfo.green.offset,
           vinfo.green.length);
    printf("  Blue   : offset=%u length=%u\n",
           vinfo.blue.offset,
           vinfo.blue.length);
    printf("  Alpha  : offset=%u length=%u\n",
           vinfo.transp.offset,
           vinfo.transp.length);

    printf("\n");

    size_t map_size = finfo.smem_len;

    if (map_size == 0)
    {
        map_size =
            (size_t)finfo.line_length *
            vinfo.yres_virtual;
    }

    void *mapped = mmap(
        NULL,
        map_size,
        PROT_READ | PROT_WRITE,
        MAP_SHARED,
        fd,
        0
    );

    if (mapped == MAP_FAILED)
    {
        perror("mmap");
        close(fd);
        return 1;
    }

    uint16_t *fb = (uint16_t *)mapped;

    if (vinfo.bits_per_pixel != 16)
    {
        printf(
            "WARNING: framebuffer reports %u BPP, "
            "but this program writes 16-bit pixels.\n\n",
            vinfo.bits_per_pixel);
    }

    /*
     * Use stride rather than assuming width*2 when
     * walking individual rows. For the current fb1,
     * this should normally be 2048 for 1024 pixels.
     */
    int width = vinfo.xres;
    int height = vinfo.yres;

    if (!strcmp(mode, "colors"))
    {
        colors(fb, width, height);
    }
    else if (!strcmp(mode, "bit"))
    {
        bit_test(fb, width, height);
    }
    else if (!strcmp(mode, "ramp"))
    {
        ramp_test(fb, width, height);
    }
    else
    {
        char *end;
        unsigned long value =
            strtoul(mode, &end, 0);

        if (*end != '\0' || value > 0xFFFF)
        {
            fprintf(
                stderr,
                "Invalid 16-bit value: %s\n",
                mode);

            munmap(mapped, map_size);
            close(fd);
            return 1;
        }

        exact_value(
            fb,
            width,
            height,
            (uint16_t)value
        );
    }

    munmap(mapped, map_size);
    close(fd);

    return 0;
}

And this was the code for the snake game, generated by ChatGPT:

// snake_fb.c
//
// Snake directly on /dev/fb1
// Pixel format: ARGB1555
//
// Controls:
//   W A S D
//   Arrow keys
//   Q = quit
//   R = restart after game over
//
// Build:
//   gcc -O2 -Wall -o snake_fb snake_fb.c
//
// Run:
//   ./snake_fb /dev/fb1

#include <stdio.h>
#include <stdlib.h>
#include <stdint.h>
#include <stdbool.h>
#include <string.h>
#include <fcntl.h>
#include <unistd.h>
#include <sys/ioctl.h>
#include <sys/mman.h>
#include <linux/fb.h>
#include <termios.h>
#include <time.h>
#include <signal.h>

#define DEFAULT_FB "/dev/fb1"

#define CELL_SIZE 20
#define TICK_MS   100

#define MAX_SNAKE 4096

typedef struct {
    int x;
    int y;
} Point;

static int fb_fd;
static uint8_t *fb_mem;
static size_t fb_size;

static struct fb_var_screeninfo vinfo;
static struct fb_fix_screeninfo finfo;

static int width;
static int height;
static int stride;

static uint16_t *backbuffer;

static Point snake[MAX_SNAKE];
static int snake_len;

static Point food;

static int dx;
static int dy;

static volatile sig_atomic_t running = 1;


/* --------------------------------------------------------- */
/* ARGB1555                                                   */
/* --------------------------------------------------------- */

static uint16_t argb1555(
    int a,
    int r,
    int g,
    int b)
{
    uint16_t v = 0;

    if (a)
        v |= 0x8000;

    v |= ((r >> 3) & 0x1F) << 10;
    v |= ((g >> 3) & 0x1F) << 5;
    v |= ((b >> 3) & 0x1F);

    return v;
}


/* --------------------------------------------------------- */
/* Framebuffer                                                */
/* --------------------------------------------------------- */

static inline void fb_pixel(
    int x,
    int y,
    uint16_t color)
{
    if ((unsigned)x >= (unsigned)width ||
        (unsigned)y >= (unsigned)height)
        return;

    uint16_t *p =
        (uint16_t *)(fb_mem + y * stride + x * 2);

    *p = color;
}


static void fb_clear(uint16_t color)
{
    for (int y = 0; y < height; y++)
    {
        uint16_t *row =
            (uint16_t *)(fb_mem + y * stride);

        for (int x = 0; x < width; x++)
            row[x] = color;
    }
}


/*
 * Backbuffer has no padding.
 *
 * Actual framebuffer may have padding at the end of
 * every line, so present() copies row-by-row using
 * finfo.line_length.
 */
static void present(void)
{
    for (int y = 0; y < height; y++)
    {
        memcpy(
            fb_mem + y * stride,
            backbuffer + y * width,
            width * sizeof(uint16_t)
        );
    }
}


static void fill_rect(
    int x,
    int y,
    int w,
    int h,
    uint16_t color)
{
    if (x < 0)
    {
        w += x;
        x = 0;
    }

    if (y < 0)
    {
        h += y;
        y = 0;
    }

    if (x + w > width)
        w = width - x;

    if (y + h > height)
        h = height - y;

    if (w <= 0 || h <= 0)
        return;

    for (int yy = y; yy < y + h; yy++)
    {
        uint16_t *row =
            backbuffer + yy * width + x;

        for (int xx = 0; xx < w; xx++)
            row[xx] = color;
    }
}


/* --------------------------------------------------------- */
/* Snake                                                      */
/* --------------------------------------------------------- */

static bool snake_at(int x, int y)
{
    for (int i = 0; i < snake_len; i++)
    {
        if (snake[i].x == x &&
            snake[i].y == y)
            return true;
    }

    return false;
}


static void spawn_food(void)
{
    int grid_w = width / CELL_SIZE;
    int grid_h = height / CELL_SIZE;

    do
    {
        food.x = rand() % grid_w;
        food.y = rand() % grid_h;

    } while (snake_at(food.x, food.y));
}


static void reset_game(void)
{
    int grid_w = width / CELL_SIZE;
    int grid_h = height / CELL_SIZE;

    snake_len = 5;

    int cx = grid_w / 2;
    int cy = grid_h / 2;

    for (int i = 0; i < snake_len; i++)
    {
        snake[i].x = cx - i;
        snake[i].y = cy;
    }

    dx = 1;
    dy = 0;

    spawn_food();
}


static bool update_game(void)
{
    Point head = snake[0];

    head.x += dx;
    head.y += dy;

    int grid_w = width / CELL_SIZE;
    int grid_h = height / CELL_SIZE;

    /* Wall collision */

    if (head.x < 0 ||
        head.x >= grid_w ||
        head.y < 0 ||
        head.y >= grid_h)
        return false;


    bool eating =
        head.x == food.x &&
        head.y == food.y;


    /*
     * If we're not eating, the tail disappears this
     * frame. Therefore moving into the old tail position
     * is allowed.
     */
    int collision_len =
        eating ? snake_len : snake_len - 1;

    for (int i = 0; i < collision_len; i++)
    {
        if (snake[i].x == head.x &&
            snake[i].y == head.y)
            return false;
    }


    if (eating)
    {
        if (snake_len < MAX_SNAKE)
            snake_len++;
    }


    for (int i = snake_len - 1; i > 0; i--)
        snake[i] = snake[i - 1];

    snake[0] = head;


    if (eating)
        spawn_food();

    return true;
}


/* --------------------------------------------------------- */
/* Rendering                                                  */
/* --------------------------------------------------------- */

static void draw_game(void)
{
    uint16_t black =
        argb1555(1, 0, 0, 0);

    uint16_t snake_head =
        argb1555(1, 0, 255, 0);

    uint16_t snake_body =
        argb1555(1, 0, 120, 0);

    uint16_t food_color =
        argb1555(1, 255, 0, 0);


    /* Clear */

    for (int i = 0; i < width * height; i++)
        backbuffer[i] = black;


    /* Food */

    fill_rect(
        food.x * CELL_SIZE,
        food.y * CELL_SIZE,
        CELL_SIZE,
        CELL_SIZE,
        food_color
    );


    /* Snake */

    for (int i = snake_len - 1; i >= 0; i--)
    {
        uint16_t color =
            (i == 0)
                ? snake_head
                : snake_body;

        fill_rect(
            snake[i].x * CELL_SIZE,
            snake[i].y * CELL_SIZE,
            CELL_SIZE - 1,
            CELL_SIZE - 1,
            color
        );
    }


    present();
}


/* --------------------------------------------------------- */
/* Terminal                                                   */
/* --------------------------------------------------------- */

static struct termios old_terminal;


static void terminal_restore(void)
{
    tcsetattr(
        STDIN_FILENO,
        TCSANOW,
        &old_terminal
    );
}


static void terminal_setup(void)
{
    struct termios t;

    tcgetattr(
        STDIN_FILENO,
        &old_terminal
    );

    t = old_terminal;

    t.c_lflag &= ~(ICANON | ECHO);

    t.c_cc[VMIN] = 0;
    t.c_cc[VTIME] = 0;

    tcsetattr(
        STDIN_FILENO,
        TCSANOW,
        &t
    );

    atexit(terminal_restore);
}


static void signal_handler(int sig)
{
    (void)sig;
    running = 0;
}


/* --------------------------------------------------------- */
/* Input                                                       */
/* --------------------------------------------------------- */

static void set_direction(int x, int y)
{
    /*
     * Don't allow an immediate 180-degree turn.
     */
    if (x == -dx && y == -dy)
        return;

    dx = x;
    dy = y;
}


static void read_input(void)
{
    unsigned char c;

    while (read(STDIN_FILENO, &c, 1) == 1)
    {
        switch (c)
        {
            case 'w':
            case 'W':
                if (dy != 1)
                    set_direction(0, -1);
                break;

            case 's':
            case 'S':
                if (dy != -1)
                    set_direction(0, 1);
                break;

            case 'a':
            case 'A':
                if (dx != 1)
                    set_direction(-1, 0);
                break;

            case 'd':
            case 'D':
                if (dx != -1)
                    set_direction(1, 0);
                break;

            case 'q':
            case 'Q':
                running = 0;
                break;

            case 0x1B:
            {
                unsigned char seq[2];

                if (read(STDIN_FILENO, &seq[0], 1) != 1)
                    break;

                if (seq[0] != '[')
                    break;

                if (read(STDIN_FILENO, &seq[1], 1) != 1)
                    break;

                switch (seq[1])
                {
                    case 'A':
                        if (dy != 1)
                            set_direction(0, -1);
                        break;

                    case 'B':
                        if (dy != -1)
                            set_direction(0, 1);
                        break;

                    case 'C':
                        if (dx != -1)
                            set_direction(1, 0);
                        break;

                    case 'D':
                        if (dx != 1)
                            set_direction(-1, 0);
                        break;
                }

                break;
            }
        }
    }
}


/* --------------------------------------------------------- */
/* Game over                                                  */
/* --------------------------------------------------------- */

static bool game_over_screen(void)
{
    uint16_t black =
        argb1555(1, 0, 0, 0);

    uint16_t red =
        argb1555(1, 255, 0, 0);

    /*
     * Fill screen red as a very simple game-over
     * indication.
     */
    for (int i = 0; i < width * height; i++)
        backbuffer[i] = red;

    present();

    while (running)
    {
        unsigned char c;

        if (read(STDIN_FILENO, &c, 1) == 1)
        {
            if (c == 'q' || c == 'Q')
            {
                running = 0;
                return false;
            }

            if (c == 'r' || c == 'R')
            {
                reset_game();
                return true;
            }
        }

        usleep(10000);
    }

    (void)black;

    return false;
}


/* --------------------------------------------------------- */
/* Main                                                       */
/* --------------------------------------------------------- */

int main(int argc, char **argv)
{
    const char *device =
        argc >= 2 ? argv[1] : DEFAULT_FB;


    srand((unsigned)time(NULL));


    signal(SIGINT, signal_handler);
    signal(SIGTERM, signal_handler);


    /* Open framebuffer */

    fb_fd = open(device, O_RDWR);

    if (fb_fd < 0)
    {
        perror("open framebuffer");
        return 1;
    }


    /* Get framebuffer information */

    if (ioctl(
            fb_fd,
            FBIOGET_FSCREENINFO,
            &finfo) < 0)
    {
        perror("FBIOGET_FSCREENINFO");
        close(fb_fd);
        return 1;
    }


    if (ioctl(
            fb_fd,
            FBIOGET_VSCREENINFO,
            &vinfo) < 0)
    {
        perror("FBIOGET_VSCREENINFO");
        close(fb_fd);
        return 1;
    }


    width  = vinfo.xres;
    height = vinfo.yres;
    stride = finfo.line_length;


    printf(
        "Framebuffer: %s\n"
        "Name:        %s\n"
        "Resolution:  %dx%d\n"
        "Virtual:     %dx%d\n"
        "BPP:         %u\n"
        "Stride:      %d\n"
        "Format:      R%d G%d B%d A%d\n",
        device,
        finfo.id,
        width,
        height,
        vinfo.xres_virtual,
        vinfo.yres_virtual,
        vinfo.bits_per_pixel,
        stride,
        vinfo.red.offset,
        vinfo.green.offset,
        vinfo.blue.offset,
        vinfo.transp.offset
    );


    if (vinfo.bits_per_pixel != 16)
    {
        fprintf(
            stderr,
            "ERROR: expected 16-bit framebuffer\n"
        );

        close(fb_fd);
        return 1;
    }


    /* Map framebuffer */

    fb_size = finfo.smem_len;

    if (fb_size == 0)
    {
        fb_size =
            (size_t)stride *
            vinfo.yres_virtual;
    }


    fb_mem = mmap(
        NULL,
        fb_size,
        PROT_READ | PROT_WRITE,
        MAP_SHARED,
        fb_fd,
        0
    );


    if (fb_mem == MAP_FAILED)
    {
        perror("mmap");
        close(fb_fd);
        return 1;
    }


    /*
     * RAM framebuffer.
     *
     * This is only width*height*2.
     */
    backbuffer =
        malloc(
            (size_t)width *
            height *
            sizeof(uint16_t)
        );


    if (!backbuffer)
    {
        perror("malloc");

        munmap(
            fb_mem,
            fb_size
        );

        close(fb_fd);
        return 1;
    }


    terminal_setup();


    reset_game();

    fb_clear(
        argb1555(
            1,
            0,
            0,
            0
        )
    );


    printf(
        "Snake running.\n"
        "WASD / arrows = move\n"
        "Q = quit\n"
    );


    while (running)
    {
        read_input();


        if (!update_game())
        {
            if (!game_over_screen())
                break;

            continue;
        }


        draw_game();


        usleep(
            TICK_MS * 1000
        );
    }


    /* Clear framebuffer */

    fb_clear(
        argb1555(
            1,
            0,
            0,
            0
        )
    );


    free(backbuffer);


    munmap(
        fb_mem,
        fb_size
    );


    close(fb_fd);


    return 0;
}

Now knowing how the framebuffer works, I decided to finally get the game running, I got Sofia and the compiled snake on a flash drive, mounted it with mount /dev/sda1 /mnt/usb, and ran the following commands (on a sh file for ease when recording the video):

./Sofia # run original program and wait for it to crash
echo V > /dev/watchdog # Sofia decides to feed the watchdog when it starts
./snake # Start game, grab into fb1

And this is the result that made me really happy:

Addendum or whatever idc

1 - Compiled Linux kernel boot log, compiled for eMMC


Starting kernel ...

ACTLR: 0x00000005
ACTLR: 0x00000045
Disable MMU
Clear MMU
Uboot L2 cache aux val: 0x72430000
Uboot L2 cache prefetch ctrl val: 0x70000000
Uboot L2 cache ctrl val: 0x00000000
Done
Uncompressing Linux... done, booting the kernel.
abceBooting Linux on physical CPU 0x0
Linux version 4.9.118 (brenno@PC-Breno) (gcc version 6.5.0 (Buildroot 2019.05.2) ) #2 SMP Wed Jul 15 20:28:31 -03 2026
CPU: ARMv7 Processor [414fc091] revision 1 (ARMv7), cr=10c5387d
CPU: PIPT / VIPT nonaliasing data cache, VIPT aliasing instruction cache
OF: fdt:Machine model: Novatek NA51068
Memory policy: Data cache writealloc
percpu: Embedded 13 pages/cpu @8b23a000 s24332 r8192 d20724 u53248
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 45675
Kernel command line: earlyprintk console=ttyS0,115200 init=linuxrc mem=0xb400000 rootwait nprofile_irq_duration=on root=/dev/mtdblock4 rootfstype=squashfs mtdparts=spi_nor.0
PID hash table entries: 1024 (order: 0, 4096 bytes)
Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
Memory: 176444K/184320K available (3843K kernel code, 219K rwdata, 1272K rodata, 260K init, 230K bss, 7876K reserved, 0K cma-reserved)
Virtual kernel memory layout:
    vector  : 0xffff0000 - 0xffff1000   (   4 kB)
    fixmap  : 0xffc00000 - 0xfff00000   (3072 kB)
    vmalloc : 0x8b800000 - 0xff800000   (1856 MB)
    lowmem  : 0x80000000 - 0x8b400000   ( 180 MB)
    modules : 0x7e800000 - 0x80000000   (  24 MB)
      .text : 0x80008000 - 0x803c8ed0   (3844 kB)
      .init : 0x80509000 - 0x8054a000   ( 260 kB)
      .data : 0x8054a000 - 0x80580d30   ( 220 kB)
       .bss : 0x80582000 - 0x805bbb08   ( 231 kB)
SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
Hierarchical RCU implementation.
NR_IRQS:384
L2C-310 enabling early BRESP for Cortex-A9
L2C-310 full line of zeros enabled for Cortex-A9
L2C-310 ID prefetch enabled, offset 1 lines
L2C-310 dynamic clock gating enabled, standby mode enabled
L2C-310 cache controller enabled, 16 ways, 256 kB
L2C-310: CACHE_ID 0x410000c9, AUX_CTRL 0x76430001
APIs of flush/clean all cache are supported
novatek_clock_init
sched_clock: 64 bits at 150MHz, resolution 6ns, wraps every 2199023255551ns
clocksource: arm_global_timer: mask: 0xffffffffffffffff max_cycles: 0x2298375bd0, max_idle_ns: 440795208267 ns
Switching to timer-based delay loop, resolution 6ns
FTTMR010 Driver Version: 1.0.1
clocksource: fttmr010_clksrc: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 159271703898 ns
fttmr010_clock_event_shutdown, shutdown tmr0
Console: colour dummy device 80x30
Calibrating delay loop (skipped), value calculated using timer frequency.. 300.00 BogoMIPS (lpj=1500000)
pid_max: default: 32768 minimum: 301
Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
CPU: Testing write buffer coherency: ok
Setting up static identity map for 0x8240 - 0x8298
Brought up 2 CPUs
SMP: Total of 2 processors activated (600.00 BogoMIPS).
CPU: All CPU(s) started in SVC mode.
devtmpfs: initialized
VFP support v0.3: implementor 41 architecture 3 part 30 variant 9 rev 4
NVTBOOTTS: nvt_bootts_init initial success
NVTBOOTTS: nvt_bootts_proc_init initial success
nvt_jiffies: system HZ: 100, pClk: 12000000
clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
futex hash table entries: 512 (order: 3, 32768 bytes)
pinctrl core: initialized pinctrl subsystem
NET: Registered protocol family 16
DMA: preallocated 256 KiB pool for atomic coherent allocations
cpuidle: using governor menu
nvt_otp_module_init
------------------------------
AXI0=500 AXI1=400 AXI2=350 HCLK=300
CPU=1200 DRAM=1864 DSP=600 CODEC=380
DISP0=297 DISP1=270 DISP2=54 CNN=600
MPLL8(VCAP)=465 SSP=344
------------------------------
SCSI subsystem initialized
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
clocksource: Switched to clocksource arm_global_timer
NET: Registered protocol family 2
TCP established hash table entries: 2048 (order: 1, 8192 bytes)
TCP bind hash table entries: 2048 (order: 2, 16384 bytes)
TCP: Hash tables configured (established 2048 bind 2048)
UDP hash table entries: 256 (order: 1, 8192 bytes)
UDP-Lite hash table entries: 256 (order: 1, 8192 bytes)
NET: Registered protocol family 1
NetWinder Floating Point Emulator V0.97 (double precision)
workingset: timestamp_bits=14 max_order=16 bucket_order=2
squashfs: version 4.0 (2009/01/31) Phillip Lougher
jffs2: version 2.2. (NAND) © 2001-2006 Red Hat, Inc.
io scheduler noop registered
io scheduler deadline registered (default)
io scheduler cfq registered
probe fe400000.gpio OK, at 0xfe700000, version:1.0.4.
probe fe420000.gpio OK, at 0xfe720000, version:1.0.4.
probe fe440000.gpio OK, at 0xfe740000, version:1.0.4.
probe fe640000.gpio OK, at 0xfe940000, version:1.0.4.
ftdmac030 fca00000.dma030: driver probed, irq 19, mapped at fca00000
Serial: 8250/16550 driver, 4 ports, IRQ sharing disabled
console [ttyS0] disabled
fe200000.uart: ttyS0 at MMIO 0xfe200000 (irq = 7, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
console [ttyS0] enabled
fe220000.uart: ttyS1 at MMIO 0xfe220000 (irq = 8, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
fe240000.uart: ttyS2 at MMIO 0xfe240000 (irq = 9, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
fe260000.uart: ttyS3 at MMIO 0xfe260000 (irq = 10, base_baud = 3000000) is a 16550A [NVT: hw_flow = 0, rx_trig = 1]
[drm] Initialized
brd: module loaded
loop: module loaded
libphy: Fixed MDIO Bus: probed
nvt_eth_env_probe: IO MEM res start 0xfcd00000
nvt_eth_env_probe: get IO MEM 0x8b940000
nvt_eth_env_probe: get pinmux 0x200
nvt_eth_env_probe: pinmux detect emb phy 0x200
DWC_ETH_QOS: Phy detected at ID/ADDR 1
nvt_probe: enter
nvt_probe: get pinmux 0x200
NVT EMB phy route to MAC1
Get remap addr 0x8b937000
libphy: dwc_phy: probed
nvt_resume: enter
netif_napi_add() called with weight 128 on device eth%d
Supports TSO, SG and TX COE
Supports RX COE and GRO
usbcore: registered new interface driver usb-storage
mousedev: PS/2 mouse device common for all mice
nvt_rtc_chk_power: RTC ready timeout, plz check 32K OSC on PCB
nvt_rtc fe880000.rtc: rtc core: registered nvt_rtc as rtc0
i2c /dev entries driver
NVT I2C0 Driver Version: 1.0.0(hdmi:no) irq 43, mapped at fe600000
NVT I2C1 Driver Version: 1.0.0(hdmi:no) irq 44, mapped at fe620000
NVT I2C2 Driver Version: 1.0.0(hdmi:no) irq 45, mapped at fe640000
NVT I2C3 Driver Version: 1.0.0(hdmi:no) irq 46, mapped at fe660000
NVT I2C4 Driver Version: 1.0.0(hdmi:no) irq 47, mapped at fe680000
NVT I2C5 Driver Version: 1.0.0(hdmi:no) irq 48, mapped at fe6a0000
usbcore: registered new interface driver usbhid
usbhid: USB HID core driver
NET: Registered protocol family 17
ThumbEE CPU extension supported.
Registering SWP/SWPB emulation handler
nvt_rtc fe880000.rtc: hctosys: unable to read the hardware clock
Waiting for root device /dev/mtdblock4...

2 - Compiled Linux kernel boot log, compiled for NOR and worked

It turned into lost media

3 - Flash mod

This mod allows me to reflash the board easily as I modify the firmware, I accomplished this by removing the flash chip from the board, soldering it to a customized breakout board, and soldering a wired header to the board where the flash used to be, this is how it looks:

Flash board

Flash chip

Why Ubuntu 14.04? The SDK expects you to use this as your development environment, so I assume the toolchain was also made in this environment

A smaller writeup more focused on the hardware markings and chip specs is available on the Recessim Wiki.

If you find the original Novatek toolchain, please contact me through E-Mail or Discord:

  • E-Mail: brennomaturino2@gmail.com
  • Discord: @brennomaturino1