What's new

Solved Got a little problem i need help with

  • Thread starter Mr_Viking
  • Start date
  • Views 387
Mr_Viking

Mr_Viking

Enthusiast
Programmer
Messages
467
Reaction score
75
So im Rghing a trinity dumped nand 4 times they all match wrote .ecc booted into xell got cpu key created freeboot image turned it on booted into xell it flashed the freeboot image but when i turned it back on (with any button) it only boots into xell! and i cant seem to get it to boot to dash any ideas guys i don't have the j-runner log for reading/writing nand/.ecc but i can start again if needed.

Xebuild log:
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
base path changed to C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\J-Runner v3 (5) Core Pack\xeBuild
---- { Image Build Mode } ----
building glitch2 image
<enter> key on completion suppressed
data directory overridden from command line to '17489\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin'

------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1a0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0x************************* (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0x*************************
1BL Key set to : 0x************************* sum: 0x983 (expects: 0x983)
xex Key set to : 0x************************* sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)

------ parsing ini at '17489\_glitch2.ini' ------
ini version 17489

ini: label [trinitybl] found
found (1) 'cba_9188.bin' crc: 0x5a76752d
found (2) 'cbb_9188.bin' crc: 0xfebb1074
found (3) 'cd_9452.bin' crc: 0x455fa02
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_17489.bin' crc: 0x26c9baed
found (6) 'cg_17489.bin' crc: 0xa9c9815e
ini dictates dual CB for this model

[rawpatch] label not found in ini

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x40d5adce
found (2) 'bootanim.xex' crc: 0x85238a78
found (3) 'createprofile.xex' crc: 0x034acd79
found (4) 'dash.xex' crc: 0xdb4717cf
found (5) 'deviceselector.xex' crc: 0x1eb402b9
found (6) 'gamerprofile.xex' crc: 0xf4e4902e
found (7) 'hud.xex' crc: 0xb1485b31
found (8) 'huduiskin.xex' crc: 0x5fb2d289
found (9) 'mfgbootlauncher.xex' crc: 0xe9d4483a
found (10) 'minimediaplayer.xex' crc: 0x61f6c912
found (11) 'nomni.xexp' crc: 0x3ec9f846
found (12) 'nomnifwk.xexp' crc: 0x96bf4907
found (13) 'nomnifwm.xexp' crc: 0x772eb1df
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x68541d87
found (16) 'updater.xex' crc: 0xd63a84d9
found (17) 'vk.xex' crc: 0x81700712
found (18) 'xam.xex' crc: 0xa5741001
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x86cbabf6
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xbee64013
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin

1BL RSA pub key (1BL_pub.bin) not available, signature checks will not be performed
PIRS RSA pub key (PIRS_pub.bin) not available, signature checks will not be performed
MASTER RSA pub key (MAST_pub.bin) not available, signature checks will not be performed

------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses big block controller
parsing dump into user and spare...
bad block at 0x17a (raw offset 0x617400), block ignored
bad block at 0x22f (raw offset 0x901e00), block ignored
copying nanddump data from block 0x3fe to block 0x22f for file extraction integrity
block 0x22f was remapped to block 0x3fe at remap instance 1
copying nanddump data from block 0x3ff to block 0x17a for file extraction integrity
block 0x17a was remapped to block 0x3ff at remap instance 0
done!
cleaning up stray remaps
done!
--remap summary--
0: source: 0x017a dest: 0x03ff
1: source: 0x022f dest: 0x03fe
-----------------
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x11 Pairing: 0x699686
CF slot 1 decrypted ok LDV 0x12 Pairing: 0x699686
setting LDV from image to 18
setting pairing data from image to 0x699686
pairing set to: 69 96 86
Scanning for mobile data and fsroot...Mobiles found:
fsroot version 288 found at offset 0x003c0000 len 0x4000 page 0x00001e00
mobileB.dat version 2525 found at offset 0x003be000 len 0x0800 page 0x00001df0
mobileC.dat version 01 found at offset 0x002b0a00 len 0x0200 page 0x00001585
mobileD.dat version 01 found at offset 0x001d6000 len 0x0800 page 0x00000eb0
mobileE.dat version 370 found at offset 0x00491800 len 0x0800 page 0x0000248c
extracting MobileB.dat from page 0x1df0 (offset 0x3be000), size 2048 (0x800) bytes
extracting MobileC.dat from page 0x1585 (offset 0x2b0a00), size 512 (0x200) bytes
extracting MobileD.dat from page 0xeb0 (offset 0x1d6000), size 2048 (0x800) bytes
extracting MobileE.dat from page 0x248c (offset 0x491800), size 2048 (0x800) bytes
Statistics.settings found at offset 0xf78000, size 4096 (0x1000) bytes
seeking security files...
crl.bin found in sector 0x151 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x14c size 0xde60...verified! Will use if external file not found.
extended.bin found in sector 0x1ef size 0x4000...verified! Will use if external file not found.
fcrt.bin found in sector 0x362 size 0x4000...pub key to verify signature is not available, skipping!
verified! Will use if external file not found.
secdata.bin found in sector 0x14a size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image

------ loading system update container ------
17489\su20076000_00000000 found, loading...done!
Read 0xb50000 bytes to memory
checking integrity...
header seems valid, version 2.0.17489.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7ce00 bytes)
decrypting SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)...done!

------ Loading bootloaders and required security files ------
reading data\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cba_9188.bin (0x1ac0 bytes)
loaded cba_9188.bin, could not check signature rsa key not present!
reading .\common\cbb_9188.bin (0x7800 bytes)
reading .\common\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading data\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)
reading 17489\bin\patches_g2trinity.bin (0x91c bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 82øC Gpu: 78øC Edram: 76øC
Max temps : Cpu: 89øC Gpu: 82øC Edram: 82øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : *************************
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : DDUX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_9188.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching BLs...Done!

------ Patching boot reasons and options into flash header ------
Patching header for xell power reason

------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3000
SMC checksum: f9c96639
known clean SMC found, type: Trinity v5.1(3.01)
patching SMC reset limit at offset: 0x13b3
SMC reset limit patched successfully!
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cba_9188.bin size 0x1ac0
encoding cbb_9188.bin size 0x7800
CB 9188 seq 0x03010001 type: 0x03 cseq: 0x01 allow: 0x0001
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0FF0F0 (retail slim)
fuseset 02: F000000000000000 (sequence)
fuseset 02: F000000000000000 (allow cseq 1)
**dual CB flag detected!**
encoding cd_9452.bin size 0x5290
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_17489.bin size 0x4560
encoding cg_17489.bin size 0x788a0
encoding patches_g2trinity.bin size 0x550
done!

------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_9188.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_9188.bin at raw offset 0x00009ac0 len 0x7800 (end 0x112c0)
adding cd_9452.bin at raw offset 0x000112c0 len 0x5290 (end 0x16550)
adding ce_1888.bin at raw offset 0x00016550 len 0x56070 (end 0x6c5c0)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_17489.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_17489.bin at raw offset 0x000b4560 len 0x788a0 (end 0xc0000, rest in fs)
adding patches_g2trinity.bin at raw offset 0x000c0010 len 0x550 (end 0xc0560)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0006ce00 (end: 0x0013ce00)...done!

------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x40d5adce ini: 0x40d5adce)
adding as aac.xexp1 at raw offset 0x13ce00 len 0x00014000 (end 0x00150e00)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x85238a78 ini: 0x85238a78)
adding as bootanim.xex at raw offset 0x154000 len 0x00061000 (end 0x001b5000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x034acd79 ini: 0x034acd79)
adding as createprofile.xex at raw offset 0x1b5000 len 0x0000c000 (end 0x001c1000)
extracted SUPD\dash.xex (0x5b0000 bytes) (crc32: 0xdb4717cf ini: 0xdb4717cf)
adding as dash.xex at raw offset 0x1c4000 len 0x005b0000 (end 0x00774000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0x1eb402b9 ini: 0x1eb402b9)
adding as deviceselector.xex at raw offset 0x774000 len 0x0000a000 (end 0x0077e000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xf4e4902e ini: 0xf4e4902e)
adding as gamerprofile.xex at raw offset 0x77e000 len 0x0001b000 (end 0x00799000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xb1485b31 ini: 0xb1485b31)
adding as hud.xex at raw offset 0x79b000 len 0x0001d000 (end 0x007b8000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x5fb2d289 ini: 0x5fb2d289)
adding as huduiskin.xex at raw offset 0x7b9000 len 0x00014000 (end 0x007cd000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xe9d4483a ini: 0xe9d4483a)
adding as mfgbootlauncher.xex at raw offset 0x7d0000 len 0x00008000 (end 0x007d8000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x61f6c912 ini: 0x61f6c912)
adding as minimediaplayer.xex at raw offset 0x7d8000 len 0x0000c000 (end 0x007e4000)
extracted SUPD\nomni.xexp (0xf000 bytes) (crc32: 0x3ec9f846 ini: 0x3ec9f846)
adding as nomni.xexp1 at raw offset 0x7e4000 len 0x0000f000 (end 0x007f3000)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x96bf4907 ini: 0x96bf4907)
adding as nomnifwk.xexp1 at raw offset 0x7f3000 len 0x00002000 (end 0x007f5000)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x772eb1df ini: 0x772eb1df)
adding as nomnifwm.xexp1 at raw offset 0x7f6000 len 0x00005000 (end 0x007fb000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x7fd000 len 0x00006000 (end 0x00803000)
extracted SUPD\signin.xex (0x1a000 bytes) (crc32: 0x68541d87 ini: 0x68541d87)
adding as signin.xex at raw offset 0x806000 len 0x0001a000 (end 0x00820000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xd63a84d9 ini: 0xd63a84d9)
adding as updater.xex at raw offset 0x822000 len 0x00007000 (end 0x00829000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0x81700712 ini: 0x81700712)
adding as vk.xex at raw offset 0x82b000 len 0x0000b000 (end 0x00836000)
extracted SUPD\xam.xex (0x251000 bytes) (crc32: 0xa5741001 ini: 0xa5741001)
adding as xam.xex at raw offset 0x837000 len 0x00251000 (end 0x00a88000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xa89000 len 0x0011b000 (end 0x00ba4000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xba7000 len 0x00018000 (end 0x00bbf000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbc0000 len 0x001a8000 (end 0x00d68000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp1 at raw offset 0xd68000 len 0x00007000 (end 0x00d6f000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x86cbabf6 ini: 0x86cbabf6)
adding as ximecore.xex at raw offset 0xd6f000 len 0x00017000 (end 0x00d86000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xd87000 len 0x00090000 (end 0x00e17000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xbee64013 ini: 0xbee64013)
adding as ximedic.xexp1 at raw offset 0xe18000 len 0x00002800 (end 0x00e1a800)
reading 17489\..\launch.xex (0xb800 bytes)
adding as launch.xex at raw offset 0xe1a800 len 0x0000b800 (end 0x00e26000)
reading 17489\..\lhelper.xex (0x4800 bytes)
adding as lhelper.xex at raw offset 0xe27800 len 0x00004800 (end 0x00e2c000)
reading 17489\..\launch.ini (0x1a4 bytes)
adding as launch.ini at raw offset 0xe2c800 len 0x000001a4 (end 0x00e2c9a4)

------ adding 5 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe34000 len 0x00000a00 (end 0x00e34a00)

<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe38000 len 0x0000ad30 (end 0x00e42d30)

<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe44000 len 0x00004000 (end 0x00e48000)

<- Processing fcrt.bin ->
could not read fcrt.bin, using data from previous parse...
adding as fcrt.bin at raw offset 0xe48000 len 0x00004000 (end 0x00e4c000)

<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe4c000 len 0x00000400 (end 0x00e4c400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe50000 len 0x800 (end 0xe50800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe54000 len 0x200 (end 0xe54200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe58000 len 0x800 (end 0xe58800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe5c000 len 0x800 (end 0xe5c800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ cleaning up image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe60000 len 0x4000 (end 0xe64000)...done!

------ finalizing image ------
fixing up big block controller on small block NAND LBA numbers...done!
calculating ECD bytes and assembling raw image...done!
remapping 2 blocks
copying 0x4200 bytes of LBA 0x17a to block 0x3ff...zero fill origin...done!
copying 0x4200 bytes of LBA 0x22f to block 0x3fe...zero fill origin...done!
done remapping!

------ writing image to disk ------
writing file 'C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.17489.0
Console : Trinity
NAND size : 16MiB
Build : Glitch (v2)
Xell : power on console with console eject button
Serial : *************************
ConsoleId : *************************
MoboSerial: *************************
Mfg Date : 04/21/2011
CPU Key : *************************
1BL Key : *************************
DVD Key : *************************
CF LDV : 18
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------


My soldering:
20151102_233513.jpg


20151102_233541.jpg
 
Last edited:
HuskerHeaven

HuskerHeaven

when I took his glass of champagne...
Retired
Messages
8,251
Reaction score
3,368
So im Rghing a trinity dumped nand 4 times they all match wrote .ecc booted into xell got cpu key created freeboot image turned it on booted into xell it flashed the freeboot image but when i turned it back on (with any button) it only boots into xell! and i cant seem to get it to boot to dash any ideas guys i don't have the j-runner log for reading/writing nand/.ecc but i can start again if needed.

Xebuild log:
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
base path changed to C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\J-Runner v3 (5) Core Pack\xeBuild
---- { Image Build Mode } ----
building glitch2 image
<enter> key on completion suppressed
data directory overridden from command line to '17489\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin'

------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1a0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0x************************* (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0x*************************
1BL Key set to : 0x************************* sum: 0x983 (expects: 0x983)
xex Key set to : 0x************************* sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)

------ parsing ini at '17489\_glitch2.ini' ------
ini version 17489

ini: label [trinitybl] found
found (1) 'cba_9188.bin' crc: 0x5a76752d
found (2) 'cbb_9188.bin' crc: 0xfebb1074
found (3) 'cd_9452.bin' crc: 0x455fa02
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_17489.bin' crc: 0x26c9baed
found (6) 'cg_17489.bin' crc: 0xa9c9815e
ini dictates dual CB for this model

[rawpatch] label not found in ini

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x40d5adce
found (2) 'bootanim.xex' crc: 0x85238a78
found (3) 'createprofile.xex' crc: 0x034acd79
found (4) 'dash.xex' crc: 0xdb4717cf
found (5) 'deviceselector.xex' crc: 0x1eb402b9
found (6) 'gamerprofile.xex' crc: 0xf4e4902e
found (7) 'hud.xex' crc: 0xb1485b31
found (8) 'huduiskin.xex' crc: 0x5fb2d289
found (9) 'mfgbootlauncher.xex' crc: 0xe9d4483a
found (10) 'minimediaplayer.xex' crc: 0x61f6c912
found (11) 'nomni.xexp' crc: 0x3ec9f846
found (12) 'nomnifwk.xexp' crc: 0x96bf4907
found (13) 'nomnifwm.xexp' crc: 0x772eb1df
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x68541d87
found (16) 'updater.xex' crc: 0xd63a84d9
found (17) 'vk.xex' crc: 0x81700712
found (18) 'xam.xex' crc: 0xa5741001
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x86cbabf6
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xbee64013
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin

1BL RSA pub key (1BL_pub.bin) not available, signature checks will not be performed
PIRS RSA pub key (PIRS_pub.bin) not available, signature checks will not be performed
MASTER RSA pub key (MAST_pub.bin) not available, signature checks will not be performed

------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses big block controller
parsing dump into user and spare...
bad block at 0x17a (raw offset 0x617400), block ignored
bad block at 0x22f (raw offset 0x901e00), block ignored
copying nanddump data from block 0x3fe to block 0x22f for file extraction integrity
block 0x22f was remapped to block 0x3fe at remap instance 1
copying nanddump data from block 0x3ff to block 0x17a for file extraction integrity
block 0x17a was remapped to block 0x3ff at remap instance 0
done!
cleaning up stray remaps
done!
--remap summary--
0: source: 0x017a dest: 0x03ff
1: source: 0x022f dest: 0x03fe
-----------------
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x11 Pairing: 0x699686
CF slot 1 decrypted ok LDV 0x12 Pairing: 0x699686
setting LDV from image to 18
setting pairing data from image to 0x699686
pairing set to: 69 96 86
Scanning for mobile data and fsroot...Mobiles found:
fsroot version 288 found at offset 0x003c0000 len 0x4000 page 0x00001e00
mobileB.dat version 2525 found at offset 0x003be000 len 0x0800 page 0x00001df0
mobileC.dat version 01 found at offset 0x002b0a00 len 0x0200 page 0x00001585
mobileD.dat version 01 found at offset 0x001d6000 len 0x0800 page 0x00000eb0
mobileE.dat version 370 found at offset 0x00491800 len 0x0800 page 0x0000248c
extracting MobileB.dat from page 0x1df0 (offset 0x3be000), size 2048 (0x800) bytes
extracting MobileC.dat from page 0x1585 (offset 0x2b0a00), size 512 (0x200) bytes
extracting MobileD.dat from page 0xeb0 (offset 0x1d6000), size 2048 (0x800) bytes
extracting MobileE.dat from page 0x248c (offset 0x491800), size 2048 (0x800) bytes
Statistics.settings found at offset 0xf78000, size 4096 (0x1000) bytes
seeking security files...
crl.bin found in sector 0x151 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x14c size 0xde60...verified! Will use if external file not found.
extended.bin found in sector 0x1ef size 0x4000...verified! Will use if external file not found.
fcrt.bin found in sector 0x362 size 0x4000...pub key to verify signature is not available, skipping!
verified! Will use if external file not found.
secdata.bin found in sector 0x14a size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image

------ loading system update container ------
17489\su20076000_00000000 found, loading...done!
Read 0xb50000 bytes to memory
checking integrity...
header seems valid, version 2.0.17489.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7ce00 bytes)
decrypting SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)...done!

------ Loading bootloaders and required security files ------
reading data\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cba_9188.bin (0x1ac0 bytes)
loaded cba_9188.bin, could not check signature rsa key not present!
reading .\common\cbb_9188.bin (0x7800 bytes)
reading .\common\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading data\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)
reading 17489\bin\patches_g2trinity.bin (0x91c bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 82øC Gpu: 78øC Edram: 76øC
Max temps : Cpu: 89øC Gpu: 82øC Edram: 82øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : *************************
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : DDUX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_9188.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching BLs...Done!

------ Patching boot reasons and options into flash header ------
Patching header for xell power reason

------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3000
SMC checksum: f9c96639
known clean SMC found, type: Trinity v5.1(3.01)
patching SMC reset limit at offset: 0x13b3
SMC reset limit patched successfully!
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cba_9188.bin size 0x1ac0
encoding cbb_9188.bin size 0x7800
CB 9188 seq 0x03010001 type: 0x03 cseq: 0x01 allow: 0x0001
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0FF0F0 (retail slim)
fuseset 02: F000000000000000 (sequence)
fuseset 02: F000000000000000 (allow cseq 1)
**dual CB flag detected!**
encoding cd_9452.bin size 0x5290
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_17489.bin size 0x4560
encoding cg_17489.bin size 0x788a0
encoding patches_g2trinity.bin size 0x550
done!

------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_9188.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_9188.bin at raw offset 0x00009ac0 len 0x7800 (end 0x112c0)
adding cd_9452.bin at raw offset 0x000112c0 len 0x5290 (end 0x16550)
adding ce_1888.bin at raw offset 0x00016550 len 0x56070 (end 0x6c5c0)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_17489.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_17489.bin at raw offset 0x000b4560 len 0x788a0 (end 0xc0000, rest in fs)
adding patches_g2trinity.bin at raw offset 0x000c0010 len 0x550 (end 0xc0560)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0006ce00 (end: 0x0013ce00)...done!

------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x40d5adce ini: 0x40d5adce)
adding as aac.xexp1 at raw offset 0x13ce00 len 0x00014000 (end 0x00150e00)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x85238a78 ini: 0x85238a78)
adding as bootanim.xex at raw offset 0x154000 len 0x00061000 (end 0x001b5000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x034acd79 ini: 0x034acd79)
adding as createprofile.xex at raw offset 0x1b5000 len 0x0000c000 (end 0x001c1000)
extracted SUPD\dash.xex (0x5b0000 bytes) (crc32: 0xdb4717cf ini: 0xdb4717cf)
adding as dash.xex at raw offset 0x1c4000 len 0x005b0000 (end 0x00774000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0x1eb402b9 ini: 0x1eb402b9)
adding as deviceselector.xex at raw offset 0x774000 len 0x0000a000 (end 0x0077e000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xf4e4902e ini: 0xf4e4902e)
adding as gamerprofile.xex at raw offset 0x77e000 len 0x0001b000 (end 0x00799000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xb1485b31 ini: 0xb1485b31)
adding as hud.xex at raw offset 0x79b000 len 0x0001d000 (end 0x007b8000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x5fb2d289 ini: 0x5fb2d289)
adding as huduiskin.xex at raw offset 0x7b9000 len 0x00014000 (end 0x007cd000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xe9d4483a ini: 0xe9d4483a)
adding as mfgbootlauncher.xex at raw offset 0x7d0000 len 0x00008000 (end 0x007d8000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x61f6c912 ini: 0x61f6c912)
adding as minimediaplayer.xex at raw offset 0x7d8000 len 0x0000c000 (end 0x007e4000)
extracted SUPD\nomni.xexp (0xf000 bytes) (crc32: 0x3ec9f846 ini: 0x3ec9f846)
adding as nomni.xexp1 at raw offset 0x7e4000 len 0x0000f000 (end 0x007f3000)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x96bf4907 ini: 0x96bf4907)
adding as nomnifwk.xexp1 at raw offset 0x7f3000 len 0x00002000 (end 0x007f5000)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x772eb1df ini: 0x772eb1df)
adding as nomnifwm.xexp1 at raw offset 0x7f6000 len 0x00005000 (end 0x007fb000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x7fd000 len 0x00006000 (end 0x00803000)
extracted SUPD\signin.xex (0x1a000 bytes) (crc32: 0x68541d87 ini: 0x68541d87)
adding as signin.xex at raw offset 0x806000 len 0x0001a000 (end 0x00820000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xd63a84d9 ini: 0xd63a84d9)
adding as updater.xex at raw offset 0x822000 len 0x00007000 (end 0x00829000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0x81700712 ini: 0x81700712)
adding as vk.xex at raw offset 0x82b000 len 0x0000b000 (end 0x00836000)
extracted SUPD\xam.xex (0x251000 bytes) (crc32: 0xa5741001 ini: 0xa5741001)
adding as xam.xex at raw offset 0x837000 len 0x00251000 (end 0x00a88000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xa89000 len 0x0011b000 (end 0x00ba4000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xba7000 len 0x00018000 (end 0x00bbf000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbc0000 len 0x001a8000 (end 0x00d68000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp1 at raw offset 0xd68000 len 0x00007000 (end 0x00d6f000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x86cbabf6 ini: 0x86cbabf6)
adding as ximecore.xex at raw offset 0xd6f000 len 0x00017000 (end 0x00d86000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xd87000 len 0x00090000 (end 0x00e17000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xbee64013 ini: 0xbee64013)
adding as ximedic.xexp1 at raw offset 0xe18000 len 0x00002800 (end 0x00e1a800)
reading 17489\..\launch.xex (0xb800 bytes)
adding as launch.xex at raw offset 0xe1a800 len 0x0000b800 (end 0x00e26000)
reading 17489\..\lhelper.xex (0x4800 bytes)
adding as lhelper.xex at raw offset 0xe27800 len 0x00004800 (end 0x00e2c000)
reading 17489\..\launch.ini (0x1a4 bytes)
adding as launch.ini at raw offset 0xe2c800 len 0x000001a4 (end 0x00e2c9a4)

------ adding 5 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe34000 len 0x00000a00 (end 0x00e34a00)

<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe38000 len 0x0000ad30 (end 0x00e42d30)

<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe44000 len 0x00004000 (end 0x00e48000)

<- Processing fcrt.bin ->
could not read fcrt.bin, using data from previous parse...
adding as fcrt.bin at raw offset 0xe48000 len 0x00004000 (end 0x00e4c000)

<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe4c000 len 0x00000400 (end 0x00e4c400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe50000 len 0x800 (end 0xe50800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe54000 len 0x200 (end 0xe54200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe58000 len 0x800 (end 0xe58800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe5c000 len 0x800 (end 0xe5c800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ cleaning up image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe60000 len 0x4000 (end 0xe64000)...done!

------ finalizing image ------
fixing up big block controller on small block NAND LBA numbers...done!
calculating ECD bytes and assembling raw image...done!
remapping 2 blocks
copying 0x4200 bytes of LBA 0x17a to block 0x3ff...zero fill origin...done!
copying 0x4200 bytes of LBA 0x22f to block 0x3fe...zero fill origin...done!
done remapping!

------ writing image to disk ------
writing file 'C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.17489.0
Console : Trinity
NAND size : 16MiB
Build : Glitch (v2)
Xell : power on console with console eject button
Serial : *************************
ConsoleId : *************************
MoboSerial: *************************
Mfg Date : 04/21/2011
CPU Key : *************************
1BL Key : *************************
DVD Key : *************************
CF LDV : 18
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------


My soldering:
20151102_233513.jpg


20151102_233541.jpg
So it's booting to xell when you hit eject or the main power button? If it's eject, it's because freeboot and xell are completely different when booting. Xell will always boot faster then freeboot. You need to play with wire lengths for freeboot. Would be better off with a Ace or CR4. If it's booting xell when you hit the main power button, re-write your freeboot image.
 
Mr_Viking

Mr_Viking

Enthusiast
Programmer
Messages
467
Reaction score
75
So it's booting to xell when you hit eject or the main power button? If it's eject, it's because freeboot and xell are completely different when booting. Xell will always boot faster then freeboot. You need to play with wire lengths for freeboot. Would be better off with a Ace or CR4. If it's booting xell when you hit the main power button, re-write your freeboot image.
Its for a friend i did suggest the CR4 but they said to use the rev c for now, yes it boots xell with the power button and i have wrote the freeboot image god knows how many times and it just boots xell.

It does have 2 bad blocks which are -

• Bad Block ID @ 0x17A [Offset: 0x617400]
• Bad Block ID @ 0x22F [Offset: 0x901E00]
• Bad Block ID @ 0x17A Found @ 0x3FF[Offset: 0x107BE00]
• Bad Block ID @ 0x22F Found @ 0x3FE[Offset: 0x1077C00]

I used fusion to apply the updflash.bin and remap the blocks it goes to boot the dash now but it freezes just before the xbox logo animation ends.

J-Runner log:
Initializing updflash.bin..
Trinity
Nand Initialization Finished
Initializing updflash.bin..
Trinity
Nand Initialization Finished
Version: 10
Flash Config: 0x00023010
Writing Nand
updflash.bin
Error: 202 writing block 230
Starting remapping process
Remapping Block 230 @ 3FF
Done!
in 3:38 min:confused:ec
 
Last edited:
Mr_Viking

Mr_Viking

Enthusiast
Programmer
Messages
467
Reaction score
75
I have fix the issue now with a clean donor nand.
 
RedEyedJesus

RedEyedJesus

✯UK Console Seller/Old Timer/Legend✯
Messages
1,527
Reaction score
432
So im Rghing a trinity dumped nand 4 times they all match wrote .ecc booted into xell got cpu key created freeboot image turned it on booted into xell it flashed the freeboot image but when i turned it back on (with any button) it only boots into xell! and i cant seem to get it to boot to dash any ideas guys i don't have the j-runner log for reading/writing nand/.ecc but i can start again if needed.

Xebuild log:
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
base path changed to C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\J-Runner v3 (5) Core Pack\xeBuild
---- { Image Build Mode } ----
building glitch2 image
<enter> key on completion suppressed
data directory overridden from command line to '17489\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin'

------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1a0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0x************************* (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0x*************************
1BL Key set to : 0x************************* sum: 0x983 (expects: 0x983)
xex Key set to : 0x************************* sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)

------ parsing ini at '17489\_glitch2.ini' ------
ini version 17489

ini: label [trinitybl] found
found (1) 'cba_9188.bin' crc: 0x5a76752d
found (2) 'cbb_9188.bin' crc: 0xfebb1074
found (3) 'cd_9452.bin' crc: 0x455fa02
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_17489.bin' crc: 0x26c9baed
found (6) 'cg_17489.bin' crc: 0xa9c9815e
ini dictates dual CB for this model

[rawpatch] label not found in ini

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x40d5adce
found (2) 'bootanim.xex' crc: 0x85238a78
found (3) 'createprofile.xex' crc: 0x034acd79
found (4) 'dash.xex' crc: 0xdb4717cf
found (5) 'deviceselector.xex' crc: 0x1eb402b9
found (6) 'gamerprofile.xex' crc: 0xf4e4902e
found (7) 'hud.xex' crc: 0xb1485b31
found (8) 'huduiskin.xex' crc: 0x5fb2d289
found (9) 'mfgbootlauncher.xex' crc: 0xe9d4483a
found (10) 'minimediaplayer.xex' crc: 0x61f6c912
found (11) 'nomni.xexp' crc: 0x3ec9f846
found (12) 'nomnifwk.xexp' crc: 0x96bf4907
found (13) 'nomnifwm.xexp' crc: 0x772eb1df
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x68541d87
found (16) 'updater.xex' crc: 0xd63a84d9
found (17) 'vk.xex' crc: 0x81700712
found (18) 'xam.xex' crc: 0xa5741001
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x86cbabf6
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xbee64013
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin

1BL RSA pub key (1BL_pub.bin) not available, signature checks will not be performed
PIRS RSA pub key (PIRS_pub.bin) not available, signature checks will not be performed
MASTER RSA pub key (MAST_pub.bin) not available, signature checks will not be performed

------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses big block controller
parsing dump into user and spare...
bad block at 0x17a (raw offset 0x617400), block ignored
bad block at 0x22f (raw offset 0x901e00), block ignored
copying nanddump data from block 0x3fe to block 0x22f for file extraction integrity
block 0x22f was remapped to block 0x3fe at remap instance 1
copying nanddump data from block 0x3ff to block 0x17a for file extraction integrity
block 0x17a was remapped to block 0x3ff at remap instance 0
done!
cleaning up stray remaps
done!
--remap summary--
0: source: 0x017a dest: 0x03ff
1: source: 0x022f dest: 0x03fe
-----------------
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x11 Pairing: 0x699686
CF slot 1 decrypted ok LDV 0x12 Pairing: 0x699686
setting LDV from image to 18
setting pairing data from image to 0x699686
pairing set to: 69 96 86
Scanning for mobile data and fsroot...Mobiles found:
fsroot version 288 found at offset 0x003c0000 len 0x4000 page 0x00001e00
mobileB.dat version 2525 found at offset 0x003be000 len 0x0800 page 0x00001df0
mobileC.dat version 01 found at offset 0x002b0a00 len 0x0200 page 0x00001585
mobileD.dat version 01 found at offset 0x001d6000 len 0x0800 page 0x00000eb0
mobileE.dat version 370 found at offset 0x00491800 len 0x0800 page 0x0000248c
extracting MobileB.dat from page 0x1df0 (offset 0x3be000), size 2048 (0x800) bytes
extracting MobileC.dat from page 0x1585 (offset 0x2b0a00), size 512 (0x200) bytes
extracting MobileD.dat from page 0xeb0 (offset 0x1d6000), size 2048 (0x800) bytes
extracting MobileE.dat from page 0x248c (offset 0x491800), size 2048 (0x800) bytes
Statistics.settings found at offset 0xf78000, size 4096 (0x1000) bytes
seeking security files...
crl.bin found in sector 0x151 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x14c size 0xde60...verified! Will use if external file not found.
extended.bin found in sector 0x1ef size 0x4000...verified! Will use if external file not found.
fcrt.bin found in sector 0x362 size 0x4000...pub key to verify signature is not available, skipping!
verified! Will use if external file not found.
secdata.bin found in sector 0x14a size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image

------ loading system update container ------
17489\su20076000_00000000 found, loading...done!
Read 0xb50000 bytes to memory
checking integrity...
header seems valid, version 2.0.17489.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7ce00 bytes)
decrypting SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)...done!

------ Loading bootloaders and required security files ------
reading data\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cba_9188.bin (0x1ac0 bytes)
loaded cba_9188.bin, could not check signature rsa key not present!
reading .\common\cbb_9188.bin (0x7800 bytes)
reading .\common\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading data\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)
reading 17489\bin\patches_g2trinity.bin (0x91c bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 82øC Gpu: 78øC Edram: 76øC
Max temps : Cpu: 89øC Gpu: 82øC Edram: 82øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : *************************
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : DDUX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_9188.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching BLs...Done!

------ Patching boot reasons and options into flash header ------
Patching header for xell power reason

------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3000
SMC checksum: f9c96639
known clean SMC found, type: Trinity v5.1(3.01)
patching SMC reset limit at offset: 0x13b3
SMC reset limit patched successfully!
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cba_9188.bin size 0x1ac0
encoding cbb_9188.bin size 0x7800
CB 9188 seq 0x03010001 type: 0x03 cseq: 0x01 allow: 0x0001
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0FF0F0 (retail slim)
fuseset 02: F000000000000000 (sequence)
fuseset 02: F000000000000000 (allow cseq 1)
**dual CB flag detected!**
encoding cd_9452.bin size 0x5290
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_17489.bin size 0x4560
encoding cg_17489.bin size 0x788a0
encoding patches_g2trinity.bin size 0x550
done!

------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_9188.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_9188.bin at raw offset 0x00009ac0 len 0x7800 (end 0x112c0)
adding cd_9452.bin at raw offset 0x000112c0 len 0x5290 (end 0x16550)
adding ce_1888.bin at raw offset 0x00016550 len 0x56070 (end 0x6c5c0)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_17489.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_17489.bin at raw offset 0x000b4560 len 0x788a0 (end 0xc0000, rest in fs)
adding patches_g2trinity.bin at raw offset 0x000c0010 len 0x550 (end 0xc0560)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0006ce00 (end: 0x0013ce00)...done!

------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x40d5adce ini: 0x40d5adce)
adding as aac.xexp1 at raw offset 0x13ce00 len 0x00014000 (end 0x00150e00)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x85238a78 ini: 0x85238a78)
adding as bootanim.xex at raw offset 0x154000 len 0x00061000 (end 0x001b5000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x034acd79 ini: 0x034acd79)
adding as createprofile.xex at raw offset 0x1b5000 len 0x0000c000 (end 0x001c1000)
extracted SUPD\dash.xex (0x5b0000 bytes) (crc32: 0xdb4717cf ini: 0xdb4717cf)
adding as dash.xex at raw offset 0x1c4000 len 0x005b0000 (end 0x00774000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0x1eb402b9 ini: 0x1eb402b9)
adding as deviceselector.xex at raw offset 0x774000 len 0x0000a000 (end 0x0077e000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xf4e4902e ini: 0xf4e4902e)
adding as gamerprofile.xex at raw offset 0x77e000 len 0x0001b000 (end 0x00799000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xb1485b31 ini: 0xb1485b31)
adding as hud.xex at raw offset 0x79b000 len 0x0001d000 (end 0x007b8000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x5fb2d289 ini: 0x5fb2d289)
adding as huduiskin.xex at raw offset 0x7b9000 len 0x00014000 (end 0x007cd000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xe9d4483a ini: 0xe9d4483a)
adding as mfgbootlauncher.xex at raw offset 0x7d0000 len 0x00008000 (end 0x007d8000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x61f6c912 ini: 0x61f6c912)
adding as minimediaplayer.xex at raw offset 0x7d8000 len 0x0000c000 (end 0x007e4000)
extracted SUPD\nomni.xexp (0xf000 bytes) (crc32: 0x3ec9f846 ini: 0x3ec9f846)
adding as nomni.xexp1 at raw offset 0x7e4000 len 0x0000f000 (end 0x007f3000)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x96bf4907 ini: 0x96bf4907)
adding as nomnifwk.xexp1 at raw offset 0x7f3000 len 0x00002000 (end 0x007f5000)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x772eb1df ini: 0x772eb1df)
adding as nomnifwm.xexp1 at raw offset 0x7f6000 len 0x00005000 (end 0x007fb000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x7fd000 len 0x00006000 (end 0x00803000)
extracted SUPD\signin.xex (0x1a000 bytes) (crc32: 0x68541d87 ini: 0x68541d87)
adding as signin.xex at raw offset 0x806000 len 0x0001a000 (end 0x00820000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xd63a84d9 ini: 0xd63a84d9)
adding as updater.xex at raw offset 0x822000 len 0x00007000 (end 0x00829000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0x81700712 ini: 0x81700712)
adding as vk.xex at raw offset 0x82b000 len 0x0000b000 (end 0x00836000)
extracted SUPD\xam.xex (0x251000 bytes) (crc32: 0xa5741001 ini: 0xa5741001)
adding as xam.xex at raw offset 0x837000 len 0x00251000 (end 0x00a88000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xa89000 len 0x0011b000 (end 0x00ba4000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xba7000 len 0x00018000 (end 0x00bbf000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbc0000 len 0x001a8000 (end 0x00d68000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp1 at raw offset 0xd68000 len 0x00007000 (end 0x00d6f000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x86cbabf6 ini: 0x86cbabf6)
adding as ximecore.xex at raw offset 0xd6f000 len 0x00017000 (end 0x00d86000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xd87000 len 0x00090000 (end 0x00e17000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xbee64013 ini: 0xbee64013)
adding as ximedic.xexp1 at raw offset 0xe18000 len 0x00002800 (end 0x00e1a800)
reading 17489\..\launch.xex (0xb800 bytes)
adding as launch.xex at raw offset 0xe1a800 len 0x0000b800 (end 0x00e26000)
reading 17489\..\lhelper.xex (0x4800 bytes)
adding as lhelper.xex at raw offset 0xe27800 len 0x00004800 (end 0x00e2c000)
reading 17489\..\launch.ini (0x1a4 bytes)
adding as launch.ini at raw offset 0xe2c800 len 0x000001a4 (end 0x00e2c9a4)

------ adding 5 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe34000 len 0x00000a00 (end 0x00e34a00)

<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe38000 len 0x0000ad30 (end 0x00e42d30)

<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe44000 len 0x00004000 (end 0x00e48000)

<- Processing fcrt.bin ->
could not read fcrt.bin, using data from previous parse...
adding as fcrt.bin at raw offset 0xe48000 len 0x00004000 (end 0x00e4c000)

<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe4c000 len 0x00000400 (end 0x00e4c400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe50000 len 0x800 (end 0xe50800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe54000 len 0x200 (end 0xe54200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe58000 len 0x800 (end 0xe58800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe5c000 len 0x800 (end 0xe5c800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ cleaning up image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe60000 len 0x4000 (end 0xe64000)...done!

------ finalizing image ------
fixing up big block controller on small block NAND LBA numbers...done!
calculating ECD bytes and assembling raw image...done!
remapping 2 blocks
copying 0x4200 bytes of LBA 0x17a to block 0x3ff...zero fill origin...done!
copying 0x4200 bytes of LBA 0x22f to block 0x3fe...zero fill origin...done!
done remapping!

------ writing image to disk ------
writing file 'C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\reece\Desktop\J-Runner v3 (5) Core Pack\040704611708\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.17489.0
Console : Trinity
NAND size : 16MiB
Build : Glitch (v2)
Xell : power on console with console eject button
Serial : *************************
ConsoleId : *************************
MoboSerial: *************************
Mfg Date : 04/21/2011
CPU Key : *************************
1BL Key : *************************
DVD Key : *************************
CF LDV : 18
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------


My soldering:
20151102_233513.jpg


20151102_233541.jpg

Is this RGH1.2? What programmer are you using?
 
Mr_Viking

Mr_Viking

Enthusiast
Programmer
Messages
467
Reaction score
75
There was no need for a donor nand, sometimes consoles have bad blocks can be normal.

I tried everything I could think off to fix them but j runner couldn't remap them and using a clean donor nand fixed the console.

The bad blocks were freezing the console on the xbox logo boot animation screen, I'm guessing it was them because the clean nand works fine.

Is this RGH1.2? What programmer are you using?

It's RGH 2 and I'm using the j-programmer v2.

The console is all glitched and working now guys.
 
Top Bottom