Meraki MS220-8P

From Leo's Notes
This page was last edited on 16 January 2019, at 22:52.

Meraki MS220-8P is a gigabit PoE switch by Cisco Meraki. Meraki switches are managed through Meraki's dashboard that resides on their servers and requires a license for the switch to function. This switch was given for free as part of a promotion by Meraki with a 3 year license.

License

The switch appears to function as a normal switch when it cannot contact the cloud servers. I am unsure if this is the case because my license has not expired yet -- though it still routes traffic as a normal switch even after a factory reset.


Hardware

The MS220-8P switch has:

  • Vitesse VSC7424XJG-02 SOC, MIPS 24KEc family
  • 128MB DDR2-800 RAM
  • 16MB Flash - initial booting?
  • 128MB Flash - OS, configs?

It also features 2 PSUs, one outputs 12V for the main board, and another 56V 2.6A unit for PoE. The switch will still boot when the PoE power supply is disconnected from mains voltage.

CPU & Memory

As noted by iHell in the new forum post, the CPU is a Vitesse VSC7424XJG-02 (Not sure if mine is the same as I do not want to take the heatsink off). The SOC according to the running kernel uses the MIPS 24KEc processor.

Memory is provided by a single K4T1G084QJ-BCE7 DDR2-800 5-5-5 SDRAM chip which has a capacity of 128MB.


Storage

There is a 16MB flash and a 128MB NAND flash on board. Both are marked with an orange marker near pin 1.

The NAND flash shows up on the boot log with 9 MTD partitions.

[    5.586000] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xf1
[    5.593000] nand: Micron MT29F1G08ABADAWP
[    5.597000] nand: 128MiB, SLC, page size: 2048, OOB size: 64
[    5.609000] Scanning device for bad blocks
[    6.483000] m25p80 spi0.1: found mx25l12805d, expected m25p80
[    6.489000] m25p80 spi0.1: mx25l12805d (16384 Kbytes)
[    6.494000] 9 cmdlinepart partitions found on MTD device m25p80
[    6.500000] Creating 9 MTD partitions on "m25p80":
[    6.505000] 0x000000000000-0x000000040000 : "loader1"
[    6.665000] 0x000000040000-0x000000400000 : "boot1"
[    6.675000] 0x000000400000-0x000000440000 : "loader2"
[    6.722000] 0x000000440000-0x000000800000 : "boot2"
[    6.740000] 0x000000800000-0x000000880000 : "rsvd"
[    6.818000] 0x000000880000-0x000000e80000 : "bootubi"
[    6.942000] 0x000000e80000-0x000000ec0000 : "conf"
[    6.950000] 0x000000ec0000-0x000000fc0000 : "stackconf"
[    7.112000] 0x000000fc0000-0x000001000000 : "syslog"


Dumping Flash Data

The 16-Pin SOP for the MX25L12845E chip is as follows:

  1. NC/SIO3
  2. VCC
  3. NC
  4. PO2 - parallel data out/in, can be NC in serial mode
  5. PO1
  6. PO0
  7. CS# - chip select
  8. SO/SIO1/PO7 - Serial data output for 1x IO
  9. WP#/SIO2 - Write protection, connect to GND
  10. GND
  11. PO3
  12. PO4
  13. PO5
  14. PO6
  15. SI/SIO0 - Serial data input for 1x IO
  16. SCLK - clock input

To read the chip using flashrom, we can use 1x serial IO by connecting Vcc = 3.3v, Gnd, CS#, SCLK, SI, SO, and WP# = Gnd. That is, we should only need to connect to pins 2, 7, 8, 9, 10, 15, 16. The PO0-PO6 pins can be NC.

Refer to the Raspberry Pi pinout at https://i.stack.imgur.com/eLPtx.png.

The Raspberry Pi should have this in /boot/config.txt:

device_tree_param=spi=on

The /dev/spidev0.0 device should exist, and flashrom should function with this command.

[root@alarmpi alarm]# flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=1000
flashrom v1.0 on Linux 4.14.92-1-ARCH (armv7l)
flashrom is free software, get the source code at https://flashrom.org

Using clock_gettime for delay loops (clk_id: 1, resolution: 1ns).
Found Macronix flash chip "MX25L12805D" (16384 kB, SPI) on linux_spi.
Found Macronix flash chip "MX25L12835F/MX25L12845E/MX25L12865E" (16384 kB, SPI) on linux_spi.
Multiple flash chip definitions match the detected chip(s): "MX25L12805D", "MX25L12835F/MX25L12845E/MX25L12865E"
Please specify which chip definition to use with the -c <chipname> option.

Dump the data using -r filename.

[root@alarmpi alarm]# flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=1000 -c "MX25L12835F/MX25L12845E/MX25L12865E"
flashrom v1.0 on Linux 4.14.92-1-ARCH (armv7l)
flashrom is free software, get the source code at https://flashrom.org

Using clock_gettime for delay loops (clk_id: 1, resolution: 1ns).
Found Macronix flash chip "MX25L12835F/MX25L12845E/MX25L12865E" (16384 kB, SPI) on linux_spi.
No operations were specified.
[root@alarmpi alarm]# flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=300 -c "MX25L12835F/MX25L12845E/MX25L12865E" -r dump7.dat
flashrom v1.0 on Linux 4.14.92-1-ARCH (armv7l)
flashrom is free software, get the source code at https://flashrom.org

Using clock_gettime for delay loops (clk_id: 1, resolution: 1ns).
Found Macronix flash chip "MX25L12835F/MX25L12845E/MX25L12865E" (16384 kB, SPI) on linux_spi.
Reading flash... done.

The dumped 16MB flash content shares the same layout printed in the boot log by the kernel.

# loader1          262144      256        0.25MB
# boot1            3932160     3840       3MB
# loader2          262144      256        0.25MB
# boot2            3932160     3840       3MB
# rsvd             524288      512        0.5MB
# bootubi          6291456     6144       6MB
# conf             262144      256        0.25MB
# stackconf        1048576     1024       1MB
# syslog           262144      256        0.25MB

Things of note:

  • loader1 and loader2 contains the boot code that brings the board up. Both partitions contain identical data.
  • boot1 and boot2 contains the linux kernel. Both partitions also contain identical data.
  • bootubi is the largest partition but only contains UBI headers every 0x1000 bytes.
  • conf contains just these values:
    #@(#)VtssConfig
    MAC=00:18:0a:02:03:04
    BOARDID=123456
    
  • rsvd, stackconf, and syslog partitions are completely filled with 0xFFs (ie. zero filled)

Perhaps loader1+boot1 and loader2+boot2 contain the same data in case they intend to do firmware+kernel updates that can be reverted if needed?

There is no reference to the 3.18.57-meraki-elemental kernel that gets executed in the second stage of the boot process, which I am assuming is stored on the 1GB Flash.

Split the files out using dd:

$ dd if=dump.dat of=loader1    bs=1 skip=$((0x0))      count=262144
$ dd if=dump.dat of=boot1      bs=1 skip=$((0x40000))  count=3932160
$ dd if=dump.dat of=loader2    bs=1 skip=$((0x400000)) count=262144
$ dd if=dump.dat of=boot2      bs=1 skip=$((0x440000)) count=3932160
$ dd if=dump.dat of=rsvd       bs=1 skip=$((0x800000)) count=524288
$ dd if=dump.dat of=bootubi    bs=1 skip=$((0x880000)) count=6291456
$ dd if=dump.dat of=conf       bs=1 skip=$((0xe80000)) count=262144
$ dd if=dump.dat of=stackconf  bs=1 skip=$((0xec0000)) count=1048576
$ dd if=dump.dat of=syslog     bs=1 skip=$((0xfc0000)) count=262144

The kernel in boot1 and boot2 contains a xz archive at the end which you can obtain with dd if=boot1 of=boot-data.xz bs=1 skip=$((0x339604)) count=349124. There is data after the end of the archive that starts with C4 53 05 00 E8 ... 7C F9 84 24 00 00 .. 00 of 2104 bytes in length followed by all FFs signifying empty flash blocks. You can extract all the data after this xz archive with dd if=boot1 of=boot1-patched-post bs=1 skip=$((0x38e9c8)). I'm not sure what this data is. The data before the archive is the kernel plus some other embedded files which you can extract with dd if=boot1 of=boot1-patched-pre bs=1 count=$((0x339604)).

The xz archive contains a cpio archive with some sort of initrd. You can extract the contents of this file with cat boot-data.xz | xz -d | cpio -i

The filesystem contains empty directories as well as two static binaries bootsh and kexec. The bootsh binary will mount the 1GB flash and then attempt to run the kernel from there. It does have the ability to read for a 'magic key' press to boot into a shell (which is disabled in this binary, as it doesn't work) as well as check if the device is in manufacture mode or RMA mode (I assume some string in the conf partition?).

The init file is symlinked to the bootsh binary which will cause it to get executed after the kernel is initialized. Getting root should just be a matter of tinkering with this binary so that it drops us into a shell.

Rooting the Switch

Since bootsh mounts and then launches the kernel image stored on the 1GB flash without any option of hitting a magic key (as the decompiled binary suggests as a possibility), I need a way to make the kernel give me a shell so that I can mount and read the 1GB flash without actually booting into it.

Examining the Boot Image

Digging through how the loader actually works from the released Meraki source code, the loader does a CRC check on the payload before attempting to run the loaded image in memory. If the CRC check fails, it will attempt to load the next partition (by jumping to the next hard-coded memory block containing the SPIM header, see below) and try again. The loader code that does this is written in assembly and can be viewed at meraki-firmware/linux-2.6.32/arch/mips/vcoreiii/loader/head.S.

When the CRC check fails, you will know when the boot log shows the loader running again:

LinuxLoader built Nov 12 2014 18:01:50
init_pll ok
init_spi ok
init_memctl ok
wait_memctl ok
Training DRAM ok
init_irq ok
init_dram_uncached ok
init_icache ok
init_dcache ok
enable_caches ok
init_board ok
Low level initialization complete, exiting boot mode
LinuxLoader built Nov 12 2014 18:01:50
init_pll ok
init_spi ok
init_irq ok
init_dram_uncached ok
init_icache ok
init_dcache ok
enable_caches ok
init_board ok
Low level initialization complete, exiting boot mode

The boot images (that is, the entire data from the boot1 and boot2 mtd partitions) must be of size 3932160 bytes and contains the following bits of data:

  1. The LOADER_MAGIC is 0x4d495053, which from the data file is 53 50 49 4d and is ASCII for SPIM.
  2. 32bit word is the kernel address
  3. 32bit word is the length of data
  4. 32bit word is the entry point
  5. 32bit word is the CRC.
  6. 32bit reserved 1
  7. 32bit reserved 2
  8. 32bit reserved 3
  9. ... data begins ...

The CRC that is calculated is basically the entire image minus the CRC code (0'd out in the code).

  • magic, load address, length of data, entrypoint
  • 32bit CRC (zeroed)
  • 3x 32bit words (reserved 1, reserved 2, reserved 3)
  • Then over all data, up to the length specified in #3 above.


Modifying The Boot Image

The data after the boot image headers mentioned in the previous section contains the kernel and whatever else that's embedded into the kernel including a ramdisk. The ramdisk from the stock kernel is located after byte 0x339604.

To help facilitate modifying this ramdisk to do my bidding, I will split the data portion into 3 parts: The 'pre' ramdisk portion, the ramdisk portion, and the 'post' ramdisk portion. Pre-portion can be generated with dd if=boot1 of=boot1-patched-pre bs=1 count=$((0x339604)) and the post-portion with dd if=boot1 of=boot1-patched-post bs=1 skip=$((0x38e9c8)).

To make changes to the boot file:

  1. Extract the boot data using cat ../boot-data.xz | xz -d | cpio -i
  2. Make your changes to the ramdisk
  3. Recreate the cpio find . | cpio -o -c > ../modified.cpio
  4. Recompress cat modified.cpio | xz -c9 --check=crc32 > modified.xz
  5. If image is smaller, pad with 0's for the difference cat modified.xz zeros.bin > modified.xz
  6. If image is larger, append post data, then adjust data lengths after payload and at the start of the boot file
  7. Reassemble boot file cat boot1-patched-pre modified.xz boot1-patched-post > boot1-patched
  8. Zero out CRC code
  9. Calculate the CRC code php ../crc32.php boot1-patched
  10. Write new CRC code
  11. Reassemble the entire image cat loader1 boot1-patched loader2 boot2 rsvd bootubi conf stackconf syslog > dump-patched.dat
  12. Copy the dump-patched.dat file to raspberry pi
  13. Flash it flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=600 -c "MX25L12835F/MX25L12845E/MX25L12865E" -w dump-patched.dat.


My Failed Attempts

Since I don't have a 32bit MIPS crosscompiler and being the lazy guy I am, I tried the simplest approach which was to patch the bootsh binary so that it calls a shell instead of kexec which is on the ramdisk. I am assuming that the bootsh file mounts the filesystems on the empty directories in the ramdisk.

I hex-edited kexec -f %s --reuse-cmdline to /bin/sh with a bunch of nulls after and tried booting. This did not work as the boot process continued on to the second kernel, implying that the kexec call still got made.

I hex-edited all reference to kexec to /sh with /sh symlinked to /bin/sh but that too did not work. It just tries over and over with this error:

[    3.633000] execl failed: 2
[    3.638000] kexec died
[    3.640000] Calling kexec for /dev/mtdblock/part1 failed!
[    3.647000] execl failed: 2
[    3.651000] kexec died
[    3.654000] Calling kexec for /dev/mtdblock/part2 failed!

Since I removed the kexec binary and replaced all kexec strings to /sh that is symlinked to /bin/sh, having the boot process fail in this manner implies that either the /kexec or the /sh binary is being called. Both of which are symlinked to /bin/sh which suggests that /bin isn't mounted.

I believe the only way forward now is to get a cross-compiler and compile a small shell which would give me control over mounting the 1GB flash.

Other Issues

When building the ramdisk, you need to compress with -C crc32 or else you will get this:

[    0.106000] mkp_lg: Input was encoded with settings that are not supported by this XZ decoder
[    0.106000] Kernel panic - not syncing: Input was encoded with settings that are not supported by this XZ decoder
[    0.106000] Rebooting in 5 seconds..LinuxLoader built Nov 12 2014 18:01:50

The first search result returned this post which suggested compressing the archive using xz -C crc32 -z -c init > init.xz.


If you misalign the embedded ramdisk, the kernel won't be able to mount it and you will see this:

[    2.544000] devtmpfs: error mounting -2
[    2.548000] Warning: unable to open an initial console.
[    2.555000] VFS: Cannot open root device "(null)" or unknown-block(0,0): error -2
[    2.563000] Please append a correct "root=" boot option; here are the available partitions:
[    2.571000] 1f00          131072 mtdblock0  (driver?)
[    2.576000] 1f01             256 mtdblock1  (driver?)
[    2.582000] 1f02            3840 mtdblock2  (driver?)
[    2.587000] 1f03             256 mtdblock3  (driver?)
[    2.592000] 1f04            3840 mtdblock4  (driver?)
[    2.597000] 1f05             512 mtdblock5  (driver?)
[    2.602000] 1f06            6144 mtdblock6  (driver?)
[    2.607000] 1f07             256 mtdblock7  (driver?)
[    2.613000] 1f08            1024 mtdblock8  (driver?)
[    2.618000] 1f09             256 mtdblock9  (driver?)
[    2.623000] 1f0a             126 mtdblock10  (driver?)
[    2.628000] 1f0b             536 mtdblock11  (driver?)
[    2.633000] 1f0c           20538 mtdblock12  (driver?)
[    2.639000] 1f0d           20538 mtdblock13  (driver?)
[    2.644000] 1f0e            8316 mtdblock14  (driver?)
[    2.649000] 1f0f            2095 mtdblock15  (driver?)
[    2.654000] 1f10            2632 mtdblock16  (driver?)
[    2.660000] 1f11            2242 mtdblock17  (driver?)
[    2.665000] 1f12            2223 mtdblock18  (driver?)
[    2.670000] 1f13            2671 mtdblock19  (driver?)
[    2.675000] 1f14            2681 mtdblock20  (driver?)
[    2.681000] 1f15            2674 mtdblock21  (driver?)
[    2.686000] mkp_lg: VFS: Unable to mount root fs on unknown-block(0,0)
[    2.686000] Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)
[    2.686000] Rebooting in 5 seconds..


Other Attempts

The smallest shell I can find is the busybox 1.20 version at 1.5MB. This will cause the archive to be larger than the original which will screw with how the archive gets loaded if I just dump the data in. The data immediately after the archive is also a concern since I have no clue what it is or what it does. My obervation is that immediately after the end of the archive data, there is a 32bit word containing the length of the archive data, followed by some data, padded by 00's to the next 16byte. So, I swapped the archive data out with the larger version with busybox, rewrote the 32bit word to the new length, updated the data length at the start of the boot image as well as the CRC32 code and tried booting it. No go, with the following error:

[    0.106000] mkp_lg: compression method <<▒i=▒▒R;▒,▒C▒8▒C▒\▒C▒x▒C▒▒▒C▒ not configu
[    0.106000] Kernel panic - not syncing: compression method <<▒i=▒▒R;▒,▒C▒8▒C▒\▒C▒x▒C▒▒▒C▒ not configu
[    0.106000] Rebooting in 5 seconds..LinuxLoader built Nov 12 2014 18:01:50

Boot

Jumper 4 (J4) has the pinouts from left to right (from the center of the board): Vcc, Tx, Rx, Gnd. It is a serial port at 115200 baud. Vcc from this pin is approximately 3.2v which is lower than the 3.3 from my USB serial adapter, so I only connected ground, Tx to Rx, and Rx to Tx on the board.

When power is applied to the board, the system boots. The output from it booting is given below.

LinuxLoader built Nov 12 2014 18:01:50
init_pll ok
init_spi ok
init_memctl ok
wait_memctl ok
Training DRAM ok
init_irq ok
init_dram_uncached ok
init_icache ok
init_dcache ok
enable_caches ok
init_board ok
Low level initialization complete, exiting boot mode
[    0.000000] Linux version 3.18.102-meraki-elemental (ssegal@sf201.meraki.com) (gcc version 5.4.0 (GCC) ) #1 Fri Apr 13 11:18:08 PDT 2018
[    0.000000] bootconsole [early0] enabled
[    0.000000] CPU0 revision is: 02019654 (MIPS 24KEc)
[    0.000000] Determined physical RAM map:
[    0.000000]  memory: 00317000 @ 00100000 (usable)
[    0.000000]  memory: 00079000 @ 00417000 (usable after init)
[    0.000000] User-defined physical RAM map:
[    0.000000]  memory: 07ff0000 @ 00000000 (usable)
[    0.000000] Initrd not found or empty - disabling initrd
[    0.000000] Zone ranges:
[    0.000000]   Normal   [mem 0x00000000-0x07feffff]
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x00000000-0x07feffff]
[    0.000000] Initmem setup node 0 [mem 0x00000000-0x07feffff]
[    0.000000] Reserving 0MB of memory at 0MB for crashkernel
[    0.000000] Primary instruction cache 32kB, VIPT, 4-way, linesize 32 bytes.
[    0.000000] Primary data cache 32kB, 4-way, VIPT, cache aliases, linesize 32 bytes
[    0.000000] Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 32496
[    0.000000] Kernel command line:  console=ttyS0,115200 mtdparts=m25p80:0x40000(loader1),0x3c0000(boot1),0x40000(loader2),0x3c0000(boot2),0x80000(rsvd),0x600000(bootubi),0x40000(conf),0x100000(stackconf),0x40000(syslog) ubi.mtd=bootubi ubi.mtd=gen_nand.0 mem=134152192
[    0.000000] PID hash table entries: 512 (order: -1, 2048 bytes)
[    0.000000] Dentry cache hash table entries: 16384 (order: 4, 65536 bytes)
[    0.000000] Inode-cache hash table entries: 8192 (order: 3, 32768 bytes)
[    0.000000] Writing ErrCtl register=8005040c
[    0.000000] Readback ErrCtl register=8005040c
[    0.000000] Cache parity protection enabled
[    0.000000] Memory: 125064K/131008K available (2655K kernel code, 135K rwdata, 364K rodata, 484K init, 101K bss, 5944K reserved, 0K cma-reserved)
[    0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
[    0.000000] NR_IRQS:66
[    0.000000] sched_clock: 32 bits at 1kHz, resolution 1000000ns, wraps every 2147483648000000ns
[    0.001000] Calibrating delay loop... 276.99 BogoMIPS (lpj=138496)
[    0.012000] pid_max: default: 32768 minimum: 301
[    0.013000] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
[    0.014000] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
[    0.020000] devtmpfs: initialized
[    0.023000] NET: Registered protocol family 16
[    0.049000] Switched to clocksource MIPS
[    0.059000] NET: Registered protocol family 2
[    0.066000] TCP established hash table entries: 1024 (order: 0, 4096 bytes)
[    0.073000] TCP bind hash table entries: 1024 (order: 0, 4096 bytes)
[    0.079000] TCP: Hash tables configured (established 1024 bind 1024)
[    0.085000] TCP: reno registered
[    0.089000] UDP hash table entries: 256 (order: 0, 4096 bytes)
[    0.095000] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes)
[    0.101000] NET: Registered protocol family 1
[    0.644000] VCORE-III Watchdog Timer enabled (30 seconds).  Prev boot was not caused by WDT reset.
[    0.654000] futex hash table entries: 256 (order: -1, 3072 bytes)
[    0.676000] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.682000] msgmni has been set to 244
[    0.717000] io scheduler noop registered
[    0.721000] io scheduler deadline registered (default)
[    0.727000] Serial: 8250/16550 driver, 1 ports, IRQ sharing disabled
[    0.735000] console [ttyS0] disabled
[    0.739000] serial8250.0: ttyS0 at MMIO 0x70100000 (irq = 14, base_baud = 13020833) is a 16550A
[    0.747000] console [ttyS0] enabled
[    0.747000] console [ttyS0] enabled
[    0.754000] bootconsole [early0] disabled
[    0.754000] bootconsole [early0] disabled
[    0.765000] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xf1
[    0.772000] nand: Micron MT29F1G08ABADAWP
[    0.776000] nand: 128MiB, SLC, page size: 2048, OOB size: 64
[    0.787000] Scanning device for bad blocks
[    0.904000] m25p80 spi0.1: found mx25l12805d, expected m25p80
[    0.910000] m25p80 spi0.1: mx25l12805d (16384 Kbytes)
[    0.915000] 9 cmdlinepart partitions found on MTD device m25p80
[    0.921000] Creating 9 MTD partitions on "m25p80":
[    0.926000] 0x000000000000-0x000000040000 : "loader1"
[    0.935000] 0x000000040000-0x000000400000 : "boot1"
[    0.943000] 0x000000400000-0x000000440000 : "loader2"
[    0.955000] 0x000000440000-0x000000800000 : "boot2"
[    0.962000] 0x000000800000-0x000000880000 : "rsvd"
[    0.974000] 0x000000880000-0x000000e80000 : "bootubi"
[    0.981000] 0x000000e80000-0x000000ec0000 : "conf"
[    0.992000] 0x000000ec0000-0x000000fc0000 : "stackconf"
[    1.001000] 0x000000fc0000-0x000001000000 : "syslog"
[    1.012000] i2c /dev entries driver
[    1.017000] TCP: cubic registered
[    1.020000] NET: Registered protocol family 17
[    1.025000] 8021q: 802.1Q VLAN Support v1.8
[    1.029000] Meraki MS220-8 board detected
[    1.034000] i2c-gpio i2c-gpio.1: using pins 6 (SDA) and 5 (SCL)
[    1.054000] UBI: attaching mtd6 to ubi0
[    2.061000] UBI: scanning is finished
[    2.102000] UBI: attached mtd6 (name "bootubi", size 6 MiB) to ubi0
[    2.109000] UBI: PEB size: 4096 bytes (4 KiB), LEB size: 3968 bytes
[    2.115000] UBI: min./max. I/O unit sizes: 1/256, sub-page size 1
[    2.121000] UBI: VID header offset: 64 (aligned 64), data offset: 128
[    2.128000] UBI: good PEBs: 1536, bad PEBs: 0, corrupted PEBs: 0
[    2.134000] UBI: user volume: 0, internal volumes: 1, max. volumes count: 23
[    2.141000] UBI: max/mean erase counter: 2/1, WL threshold: 4096, image sequence number: 4249467862
[    2.150000] UBI: available PEBs: 1532, total reserved PEBs: 4, PEBs reserved for bad PEB handling: 0
[    2.159000] UBI: background thread "ubi_bgt0d" started, PID 222
[    2.165000] UBI: attaching mtd0 to ubi1
[    2.895000] UBI: scanning is finished
[    2.932000] UBI: attached mtd0 (name "gen_nand.0", size 128 MiB) to ubi1
[    2.939000] UBI: PEB size: 131072 bytes (128 KiB), LEB size: 129024 bytes
[    2.946000] UBI: min./max. I/O unit sizes: 2048/2048, sub-page size 512
[    2.952000] UBI: VID header offset: 512 (aligned 512), data offset: 2048
[    2.959000] UBI: good PEBs: 1024, bad PEBs: 0, corrupted PEBs: 0
[    2.965000] UBI: user volume: 12, internal volumes: 1, max. volumes count: 128
[    2.972000] UBI: max/mean erase counter: 1536/683, WL threshold: 4096, image sequence number: 1363641321
[    2.982000] UBI: available PEBs: 462, total reserved PEBs: 562, PEBs reserved for bad PEB handling: 20
[    2.991000] UBI: background thread "ubi_bgt1d" started, PID 228
[    3.062000] devtmpfs: mounted
[    3.075000] Freeing unused kernel memory: 484K
[    3.083000] random: init urandom read with 43 bits of entropy available
[    3.091000] Made it into bootsh: Apr 13 2018 11:17:18
[    3.096000] bootsh build T-201804131017-Gcbd29c59-ssegal
[    3.248000] UBIFS: background thread "ubifs_bgt1_4" started, PID 313
[    3.302000] UBIFS: recovery needed
[    3.681000] UBIFS: recovery completed
[    3.685000] UBIFS: mounted UBI device 1, volume 4, name "storage"
[    3.691000] UBIFS: LEB size: 129024 bytes (126 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes
[    3.700000] UBIFS: FS size: 7354368 bytes (7 MiB, 57 LEBs), journal size 1032193 bytes (0 MiB, 6 LEBs)
[    3.710000] UBIFS: reserved for root: 347364 bytes (339 KiB)
[    3.715000] UBIFS: media format: w4/r0 (latest is w4/r0), UUID 2EA2ACA1-07FA-472B-BC2D-F0F2DB4314D3, small LPT model
In manufacturing: FALSE
In rma mode: FALSE
[    8.624000] random: nonblocking pool is initialized
[   12.126000] kexec: Starting new kernel
[   12.130000] Will call new kernel at 0047a4f0
[   12.130000] Bye ...
[    0.000000] Linux version 3.18.57-meraki-elemental (jenkins@dal247.meraki.com) (gcc version 5.4.0 (GCC) ) #2 Fri Aug 24 13:22:04 PDT 2018
[    0.000000] bootconsole [early0] enabled
[    0.000000] CPU0 revision is: 02019654 (MIPS 24KEc)
[    0.000000] Determined physical RAM map:
[    0.000000]  memory: 0046d000 @ 00100000 (usable)
[    0.000000]  memory: 00cb3000 @ 0056d000 (usable after init)
[    0.000000] User-defined physical RAM map:
[    0.000000]  memory: 07ff0000 @ 00000000 (usable)
[    0.000000] Initrd not found or empty - disabling initrd
[    0.000000] Zone ranges:
[    0.000000]   Normal   [mem 0x00000000-0x07feffff]
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x00000000-0x07feffff]
[    0.000000] Initmem setup node 0 [mem 0x00000000-0x07feffff]
[    0.000000] Reserving 0MB of memory at 0MB for crashkernel
[    0.000000] Primary instruction cache 32kB, VIPT, 4-way, linesize 32 bytes.
[    0.000000] Primary data cache 32kB, 4-way, VIPT, cache aliases, linesize 32 bytes
[    0.000000] Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 32496
[    0.000000] Kernel command line:  console=ttyS0,115200 mtdparts=m25p80:0x40000(loader1),0x3c0000(boot1),0x40000(loader2),0x3c0000(boot2),0x80000(rsvd),0x600000(bootubi),0x40000(conf),0x100000(stackconf),0x40000(syslog) ubi.mtd=bootubi ubi.mtd=gen_nand.0 mem=0x7FF0000 ramoops.mem_address=0x7FF0000 ramoops.mem_size=0x10000 ramoops.block_size=0x10000
[    0.000000] PID hash table entries: 512 (order: -1, 2048 bytes)
[    0.000000] Dentry cache hash table entries: 16384 (order: 4, 65536 bytes)
[    0.000000] Inode-cache hash table entries: 8192 (order: 3, 32768 bytes)
[    0.000000] Writing ErrCtl register=8005040c
[    0.000000] Readback ErrCtl register=8005040c
[    0.000000] Cache parity protection enabled
[    0.000000] Memory: 111160K/131008K available (3592K kernel code, 195K rwdata, 736K rodata, 13004K init, 119K bss, 19848K reserved)
[    0.000000] SLUB: HWalign=32, Order=0-3, MinObjects=0, CPUs=1, Nodes=1
[    0.000000] NR_IRQS:66
[    0.000000] sched_clock: 32 bits at 1kHz, resolution 1000000ns, wraps every 2147483648000000ns
[    0.002000] Calibrating delay loop... 276.99 BogoMIPS (lpj=138496)
[    0.013000] pid_max: default: 32768 minimum: 301
[    0.014000] Mount-cache hash table entries: 1024 (order: 0, 4096 bytes)
[    0.015000] Mountpoint-cache hash table entries: 1024 (order: 0, 4096 bytes)
[    0.018000] ftrace: allocating 12018 entries in 24 pages
[    0.045000] Performance counters: mips/24K PMU enabled, 2 32-bit counters available to each CPU, irq -1 (share with timer interrupt)
[    0.052000] devtmpfs: initialized
[    0.058000] NET: Registered protocol family 16
[    0.059000] ramoops: using module parameters
[    0.060000] pstore: Registered ramoops as persistent store backend
[    0.061000] ramoops: attached 0x10000@0x7ff0000, ecc: 0/0
[    0.123000] Switched to clocksource MIPS
[    0.163000] NET: Registered protocol family 2
[    0.170000] TCP established hash table entries: 1024 (order: 0, 4096 bytes)
[    0.177000] TCP bind hash table entries: 1024 (order: 0, 4096 bytes)
[    0.183000] TCP: Hash tables configured (established 1024 bind 1024)
[    0.190000] TCP: reno registered
[    0.193000] UDP hash table entries: 256 (order: 0, 4096 bytes)
[    0.199000] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes)
[    0.206000] NET: Registered protocol family 1
[    4.456000] VCORE-III Watchdog Timer enabled (30 seconds).  Prev boot was not caused by WDT reset.
[    4.467000] futex hash table entries: 256 (order: -1, 3072 bytes)
[    4.499000] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    4.505000] msgmni has been set to 217
[    5.276000] io scheduler noop registered
[    5.280000] io scheduler deadline registered (default)
[    5.433000] Serial: 8250/16550 driver, 1 ports, IRQ sharing disabled
[    5.466000] console [ttyS0] disabled
[    5.470000] serial8250.0: ttyS0 at MMIO 0x70100000 (irq = 14, base_baud = 13020833) is a 16550A
[    5.479000] console [ttyS0] enabled
[    5.479000] console [ttyS0] enabled
[    5.486000] bootconsole [early0] disabled
[    5.486000] bootconsole [early0] disabled
[    5.586000] nand: device found, Manufacturer ID: 0x2c, Chip ID: 0xf1
[    5.593000] nand: Micron MT29F1G08ABADAWP
[    5.597000] nand: 128MiB, SLC, page size: 2048, OOB size: 64
[    5.609000] Scanning device for bad blocks
[    6.483000] m25p80 spi0.1: found mx25l12805d, expected m25p80
[    6.489000] m25p80 spi0.1: mx25l12805d (16384 Kbytes)
[    6.494000] 9 cmdlinepart partitions found on MTD device m25p80
[    6.500000] Creating 9 MTD partitions on "m25p80":
[    6.505000] 0x000000000000-0x000000040000 : "loader1"
[    6.665000] 0x000000040000-0x000000400000 : "boot1"
[    6.675000] 0x000000400000-0x000000440000 : "loader2"
[    6.722000] 0x000000440000-0x000000800000 : "boot2"
[    6.740000] 0x000000800000-0x000000880000 : "rsvd"
[    6.818000] 0x000000880000-0x000000e80000 : "bootubi"
[    6.942000] 0x000000e80000-0x000000ec0000 : "conf"
[    6.950000] 0x000000ec0000-0x000000fc0000 : "stackconf"
[    7.112000] 0x000000fc0000-0x000001000000 : "syslog"
[    7.143000] tun: Universal TUN/TAP device driver, 1.6
[    7.148000] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
[    7.392000] i2c /dev entries driver
[    7.398000] TCP: cubic registered
[    7.402000] Initializing XFRM netlink socket
[    7.409000] NET: Registered protocol family 10
[    7.429000] NET: Registered protocol family 17
[    7.434000] NET: Registered protocol family 15
[    7.438000] 8021q: 802.1Q VLAN Support v1.8
[    7.443000] Meraki MS220-8 board detected
[    7.506000] i2c-gpio i2c-gpio.1: using pins 6 (SDA) and 5 (SCL)
[    7.614000] UBI: attaching mtd6 to ubi0
[    8.462000] random: nonblocking pool is initialized
[    9.373000] UBI: scanning is finished
[    9.418000] UBI: attached mtd6 (name "bootubi", size 6 MiB) to ubi0
[    9.424000] UBI: PEB size: 4096 bytes (4 KiB), LEB size: 3968 bytes
[    9.431000] UBI: min./max. I/O unit sizes: 1/256, sub-page size 1
[    9.437000] UBI: VID header offset: 64 (aligned 64), data offset: 128
[    9.443000] UBI: good PEBs: 1536, bad PEBs: 0, corrupted PEBs: 0
[    9.450000] UBI: user volume: 0, internal volumes: 1, max. volumes count: 23
[    9.457000] UBI: max/mean erase counter: 2/1, WL threshold: 4096, image sequence number: 4249467862
[    9.466000] UBI: available PEBs: 1532, total reserved PEBs: 4, PEBs reserved for bad PEB handling: 0
[    9.477000] UBI: background thread "ubi_bgt0d" started, PID 414
[    9.500000] UBI: attaching mtd0 to ubi1
[   10.247000] UBI: scanning is finished
[   10.291000] UBI: attached mtd0 (name "gen_nand.0", size 128 MiB) to ubi1
[   10.298000] UBI: PEB size: 131072 bytes (128 KiB), LEB size: 129024 bytes
[   10.304000] UBI: min./max. I/O unit sizes: 2048/2048, sub-page size 512
[   10.311000] UBI: VID header offset: 512 (aligned 512), data offset: 2048
[   10.318000] UBI: good PEBs: 1024, bad PEBs: 0, corrupted PEBs: 0
[   10.324000] UBI: user volume: 12, internal volumes: 1, max. volumes count: 128
[   10.331000] UBI: max/mean erase counter: 1536/683, WL threshold: 4096, image sequence number: 1363641321
[   10.341000] UBI: available PEBs: 462, total reserved PEBs: 562, PEBs reserved for bad PEB handling: 20
[   10.350000] UBI: background thread "ubi_bgt1d" started, PID 418
[   11.514000] devtmpfs: mounted
[   11.736000] Freeing unused kernel memory: 13004K (8056d000 - 81220000)
[   12.041000] Made it into bootsh: Aug 24 2018 13:15:33
[   12.047000] bootsh build switch-10-201808241214-G0a4ba17b-rel-owner
[   12.203000] UBIFS: background thread "ubifs_bgt1_4" started, PID 564
[   12.296000] UBIFS: recovery needed
[   12.599000] UBIFS: recovery completed
[   12.603000] UBIFS: mounted UBI device 1, volume 4, name "storage"
[   12.610000] UBIFS: LEB size: 129024 bytes (126 KiB), min./max. I/O unit sizes: 2048 bytes/2048 bytes
[   12.619000] UBIFS: FS size: 7354368 bytes (7 MiB, 57 LEBs), journal size 1032193 bytes (0 MiB, 6 LEBs)
[   12.628000] UBIFS: reserved for root: 347364 bytes (339 KiB)
[   12.634000] UBIFS: media format: w4/r0 (latest is w4/r0), UUID 2EA2ACA1-07FA-472B-BC2D-F0F2DB4314D3, small LPT model
In manufacturing: FALSE
In rma mode: FALSE
init started: BusyBox v1.25.1 (2018-08-24 12:51:28 PDT)
WARNING! THIS CONSOLE IS LOGGED! UNAUTHORIZED ACCESS FORBIDDEN!
<Meraki> [   13.674000] sysctl: error: 'kernel.softlockup_panic' is an unknown key
[   13.682000] sysctl: error: 'kernel.watchdog_thresh' is an unknown key
[   13.926000] sh: write error: Device or resource busy
[   14.039000] vtss_core: module license '(c) Vitesse Semiconductor Inc.' taints kernel.
[   14.047000] Disabling lock debugging due to kernel taint
[   14.647000] switch: 'Meraki MS220-8' board detected
[   15.621000] sysctl -w vm.panic_on_oom=2
[   15.648000] vm.panic_on_oom = 2
[   16.204000] click: starting router thread pid 744 (8081d000)
[   17.055000] Single synchronous check for reset
[   17.363000]
[   17.400000] boot 32 build switch-10-201808241214-G0a4ba17b-rel-owner board elemental mac 0C:8D:DB:7E:D7:76
[   17.436000] Module: vtss_core  .text=0xc1411000 .data=0xc14a90b0 .bss=0xc14a9320
[   17.436000] Module: proclikefs  .text=0xc007c000 .data= .bss=0xc007d040
[   17.436000] Module: merakiclick  .text=0xc182c000 .data=0xc197c800 .bss=0xc197ca80
[   17.436000] Module: elts_meraki  .text=0xc1f59000 .data=0xc224faa0 .bss=0xc22513d0
[   17.436000] Module: vc_click  .text=0xc23ba000 .data=0xc23ebfa0 .bss=0xc23ec130
[   17.598000] ls -1 /sys/fs/pstore/dmesg-ramoops-* 2>/dev/null
[   17.630000] /usr/bin/check_bootreason: reading file : No such file or directory
[   20.435000] !!!!! {/usr/bin/switch_brain} opening /click/switch_port_table/dump_stack_info_and_reset_stack_change failed: No such file or directory
[   22.515000] chatter: from_sw0 :: FromVitesse: initializing fdma
[   23.743000] chatter: dhcp_tracker :: DHCPTracker: skipping undersized restore buffer (buf size: 0)
[   25.112000] !!!!! {/usr/bin/switch_brain} failed writing /click/switch_port_table/set_port_storm_control  errno 2 len 211 data: "PORT 1, ENABLED true\nPORT 2, ENABLED ..."
[   26.079000] chatter: big_acl :: BigACL: skipping undersized restore buffer (buf size: 0)
<Meraki> ^CWARNING! THIS CONSOLE IS LOGGED! UNAUTHORIZED ACCESS FORBIDDEN!

Hitting Ctrl+c will show the <Meraki> prompt but the prompt does not accept any commands.

See Also

Source

Open source code can be found at:

OpenWRT