Post Reply Subscribe to Thread Email Thread

Hardware root/JTAG pinout

17th May 2014, 12:08 AM   |  #21  
OP Junior Member
Thanks Meter: 6
 
16 posts
Join Date:Joined: Sep 2010
Quote:
Originally Posted by jcase

I spent a bit trying today, I never could get a response from RTCK at all

Ignore it, RTCK is not always available and JTAG works without it as long as your clock is within acceptable range. I used 1000khz-3000khz. Don't know if clock is configurable in riffbox that I believe you use. Also, does riffbox support 1.8v levels?
17th May 2014, 12:54 AM   |  #22  
jcase's Avatar
Forum Moderator / Senior Recognized Developer - Taco Vendor
Flag Sequim WA
Thanks Meter: 9,718
 
4,289 posts
Join Date:Joined: Feb 2010
Donate to Me
More
Quote:
Originally Posted by Determined

Ignore it, RTCK is not always available and JTAG works without it as long as your clock is within acceptable range. I used 1000khz-3000khz. Don't know if clock is configurable in riffbox that I believe you use. Also, does riffbox support 1.8v levels?

Clock is configurable, I believe it does 1.8 but I'm not home now so can't verify

Sent from my HTC One_M8 using XDA Premium 4 mobile app
17th May 2014, 07:29 PM   |  #23  
Member
Thanks Meter: 15
 
59 posts
Join Date:Joined: Feb 2011
Hi!

One noob question, if you can develop a root method or a way to flash the device using jtag, what kind of device will be necessary to do it?

something like this? http://dangerousprototypes.com/docs/Bus_Blaster

thanks!
10th June 2014, 04:34 PM   |  #24  
Member
Thanks Meter: 15
 
59 posts
Join Date:Joined: Feb 2011
Any advances with JTAG?

thanks!
4th July 2014, 08:50 AM   |  #25  
Junior Member
Thanks Meter: 1
 
1 posts
Join Date:Joined: Apr 2011
Quote:
Originally Posted by Determined

Connecting to JTAG with OpenOCD needs a few changes in the cortex_a.c source to enable support for Cortex-A15. If you actually make those changes and play with debug registers, you will discover that DBGEN and SPIDEN signals/fuses are disabled, so debug mode is not accessible.

I have not yet tried flashing.

that's not true, i currently play with openocd, flyswatter2 and ifc6410 (another apq8064 box) and i discovered, that problem is how openocd handles writing to crtlstat register. seems openocd implements dap ver. 0 way, but not dap ver. 1 and dap ver. 2 ways. i'm currently diving to arm coresight documentation and openocd code.
The Following User Says Thank You to cz172638 For This Useful Post: [ View ]
4th July 2014, 03:57 PM   |  #26  
Member
Thanks Meter: 15
 
59 posts
Join Date:Joined: Feb 2011
Quote:
Originally Posted by cz172638

that's not true, i currently play with openocd, flyswatter2 and ifc6410 (another apq8064 box) and i discovered, that problem is how openocd handles writing to crtlstat register. seems openocd implements dap ver. 0 way, but not dap ver. 1 and dap ver. 2 ways. i'm currently diving to arm coresight documentation and openocd code.

Good to know that somebody is working in JTAG solution for AFTV box. Let us know your findings!

Thanks!
Yesterday, 09:19 PM   |  #27  
Junior Member
Thanks Meter: 1
 
7 posts
Join Date:Joined: Apr 2012
Long time ago since last post?
Hi there folks,

is there any progress in finding a reliable jtag connection, i. e. with a busblaster to root it?
Found http://forum.xda-developers.com/fire...-chip-t2885344 which is of core a little bit risky in doing it because of http://forum.xda-developers.com/fire...8#post55673788

I know I can solder but I dont have the other required hardware especially the emmc-adapter to make the connection with the flash chip on the board.
I do have a busblaster and I did some JTAG on a pogoplug. It worked well with OpenOCD.
So know I just want to know if somebody is working on it because it would be a pleasure to me to get a rooted FireTV.

Post Reply Subscribe to Thread
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes