PS4 PS4 Unable to boot after downgrade

Alph4_XX

Member
Hi, i tried to downgrade my PS4 Pro from 11.02 to 11.00 (my previous version).

Specs:
Model CECH-7016B
NOR Winbond W25Q256FVEF
Syscon A02-COL2 64 pin
NVA-001 motherboard

I actually made some mistakes, like destroying the first little capacitor near the vcc pin of the syscon (mine is a02-col2), destroyed vcc and glitch pin (rebuilded with enameled 0.1mm wires), and making solder bridges between many pins.

So i decided to desolder the syscon with the hot gun at 370-380 celsius (i put some kapton tape near the syscon and under the motherboard). Then i "fixed" the pins, like removing solder bridges, and making many dumps with my Teensy 4.0 with PS4 Syscon Tools 1.6.0 (2.1.0 beta isn't working at all for me, it recognizes chip, goes on debug mode but both dump and write settings does not start at all), and i think they are good.

Then i patched both NOR (slot switch 3) and Syscon (method A) with PS4 Wee Tools 1.0.1 (NOR validated by BwE NOR Validator), validated both with other dumps and resoldered the syscon with soldering iron.
I didn't desolder the NOR, i directly soldered wires to the little solder balls of the NOR

First try, its not working at all:
4,8V is ok (4,6-4,7V with multimeter), no 12V
no sign of life, no beep, nothing...

So i soldered some pins "better":
4,8V ok, no 12V
there is like a shortcircuit, when you connect the power cable, it turns on the orange led like rest mode, you disconnect it and it remains turned on for much time, and i tried to discharge the last capacitor of the vcc pin of the syscon, little spark and turned off.

I tried another time:
4,8V ok, no 12V
BLOD, it turns on, no UART logs, then it turns off after like 2 seconds

and another time:
4,8V ok, 12V ok
like a BLOD, it turns on, 12V turns on, UART logs available, three long beeps, and it turns off

For now i only did modifications to the syscon, and its going better, but it actually does not turn on correctly
These days i'm always putting some heat to every pin of the syscon with soldering iron.
(The syscon is powered by the first smd capacitor, not the nearest one to the vcc pin that i have destroyed)

Here are UART logs:

"secure loader build: Aug 31 2023 05:21:17 (r10690:release_branches/release_11.000) [800MHz] AGESA: GL&MO.BDK W9313 1030 msec [BOOT TIME] SAMU: 856 msec: enter [BOOT TIME] SAMU: 1889 msec: leave AGESA: MontegoBDK_22.0.5.70908 SAMU: W9313 SIE CONFIDENTIAL Copyright (C) 2023 Sony Interactive Entertainment Inc. All Rights Reserved. Copyright (c) 1992-2012 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD is a registered trademark of The FreeBSD Foundation. r206917/release_branches/release_11.000 Aug 31 2023 05:25:56 amd64 mDBG: Kernel Build ID = d970ac656e88d0db CPU: DG1306SML87HY (1594.00-MHz K8-class CPU) Origin = "AuthenticAMD" Id = 0x740f11 Family = 16 Model = 41 Stepping = 1 Features=0x178bfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,MMX,FXSR,SSE,SSE2,HTT> Features2=0x36d8220b<SSE3,PCLMULQDQ,MON,SSSE3,CX16,SSE4.1,SSE4.2,MOVBE,POPCNT,AESNI,XSAVE,AVX,F16C> AMD Features=0x2e500800<SYSCALL,NX,MMX+,FFXSR,Page1GB,RDTSCP,LM> AMD Features2=0xd54837ff<LAHF,CMP,SVM,ExtAPIC,CR8,ABM,SSE4A,MAS,Prefetch,OSVW,IBS,SKINIT,WDT,NodeId,Topology,PerfCtrExtNB,<b26>,<b28>,<b30>,<b31>> TSC: P-state invariant, performance statistics Event timer "LAPIC" quality 400 ACPI APIC Table: <SIE ORBIS > FreeBSD/SMP: Multiprocessor System Detected: 8 CPUs FreeBSD/SMP: 1 package(s) x 8 core(s) cpu0 (BSP): APIC ID: 0 cpu1 (AP): APIC ID: 1 cpu2 (AP): APIC ID: 2 cpu3 (AP): APIC ID: 3 cpu4 (AP): APIC ID: 4 cpu5 (AP): APIC ID: 5 cpu6 (AP): APIC ID: 6 cpu7 (AP): APIC ID: 7 MADT: Could not find APIC for SCI IRQ 9 [REGMGR] 000001 ... Memory mode: 20: GL8 release BigApp memory : 0x0000000170000000 bytes (5888MiB) FMEM (max) : 0x0000000040000000 bytes (1024MiB) MiniApp DMEM : 0x0000000070000000 bytes (1792MiB) (overlaid on BigApp memory) VSH DMEM : 0x0000000028000000 bytes ( 640MiB) Trace memory & Trace DMEM : 0x0000000000000000 bytes ( 0MiB) Vision memory : 0x0000000001000000 bytes ( 16MiB) Reserved memory : 0x0000000000a00000 bytes ( 10MiB) Flexible memory(SYSTEM) : 0x0000000058e64000 bytes (1423MiB) BIOS memory size : 0x00000000011b8000 bytes ( 18MiB) Kernel static size : 0x000000000c5e4000 bytes ( 198MiB) acpi0: <SIE ORBIS> on motherboard cpu0: <ACPI CPU> on acpi0 cpu1: <ACPI CPU> on acpi0 cpu2: <ACPI CPU> on acpi0 cpu3: <ACPI CPU> on acpi0 cpu4: <ACPI CPU> on acpi0 cpu5: <ACPI CPU> on acpi0 cpu6: <ACPI CPU> on acpi0 cpu7: <ACPI CPU> on acpi0 pcib0: <ACPI Host-PCI bridge> on acpi0 pci0: <ACPI PCI bus> on pcib0 pci0: found pcie_glue iommu0: <AMD IOMMU> on pci0 gc0: <Starsha> on pci0 GL B1 D18F5x8C:0x80008002 GC SE0 Redundant CU: 0x10 GC SE1 Redundant CU: 0x10 GC SE2 Redundant CU: 0x10 GC SE3 Redundant CU: 0x10 # GENERAL_PWRMGT:0x00044604 GCK_PLL_CONTROL:0x00400d10 SClkVid:0x45 SClkDpmVid:3 Dpm:3 Vid:0x45 hdac0: <GPU/DEHT Audio Controller> on pci0 apcie0: <Belize PCI Express glue> on pci0 apcie0: Chip revision: 01000200 apcie0: Chip ID0: eca01120 apcie0: Chip ID1: d60aad05 icc0: <Belize ICC> on pci0 hpet_pci0: <Belize High Precision Event Timer> on pci0 Timecounter "HPET" frequency 10000000 Hz quality 950 Event timer "HPET" frequency 10000000 Hz quality 450 Event timer "HPET1" frequency 10000000 Hz quality 450 Event timer "HPET2" frequency 10000000 Hz quality 450 Event timer "HPET3" frequency 10000000 Hz quality 450 sflash0: <Belize Serial Flash I/F> on pci0 sflash0: Winbond(ef) rtc0: <Belize RTC> on pci0 timer_mvl0: <Belize Timer/WDT> on pci0 uart0: <Non-standard ns8250 class UART with FIFOs> on pci0 uart0: uart_bus_attach uart0: console (115200,n,8,1) ahci0: <Orbis Belize sata0 AHCI SATA controller> on pci0 ahci0: Belize SATA PHY init ahci0: Belize SATA PHY Trace length : 4"

other UART logs:

"secure loader build: Aug 31 2023 05:21:17 (r10690:release_branches/release_11.000) [800MHz] AGESA: GL&MO.BDK W9313 1014 msec [BOOT TIME] SAMU: 881 msec: enter [BOOT TIME] SAMU: 1899 msec: leave AGESA: MontegoBDK_22.0.5.70908 SAMU: W9313 SIE CONFIDENTIAL Copyright (C) 2023 Sony Interactive Entertainment Inc. All Rights Reserved. Copyright (c) 1992-2012 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD is a registered trademark of The FreeBSD Foundation. r206917/release_branches/release_11.000 Aug 31 2023 05:25:56 amd64 mDBG: Kernel Build ID = d970ac656e88d0db CPU: DG1306SML87HY (1594.00-MHz K8-class CPU) Origin = "AuthenticAMD" Id = 0x740f11 Family = 16 Model = 41 Stepping = 1 Features=0x178bfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,MMX,FXSR,SSE,SSE2,HTT> Features2=0x36d8220b<SSE3,PCLMULQDQ,MON,SSSE3,CX16,SSE4.1,SSE4.2,MOVBE,POPCNT,AESNI,XSAVE,AVX,F16C> AMD Features=0x2e500800<SYSCALL,NX,MMX+,FFXSR,Page1GB,RDTSCP,LM> AMD Features2=0xd54837ff<LAHF,CMP,SVM,ExtAPIC,CR8,ABM,SSE4A,MAS,Prefetch,OSVW,IBS,SKINIT,WDT,NodeId,Topology,PerfCtrExtNB,<b26>,<b28>,<b30>,<b31>> TSC: P-state invariant, performance statistics Event timer "LAPIC" quality 400 ACPI APIC Table: <SIE ORBIS > FreeBSD/SMP: Multiprocessor System Detected: 8 CPUs FreeBSD/SMP: 1 package(s) x 8 core(s) cpu0 (BSP): APIC ID: 0 cpu1 (AP): APIC ID: 1 cpu2 (AP): APIC ID: 2 cpu3 (AP): APIC ID: 3 cpu4 (AP): APIC ID: 4 cpu5 (AP): APIC ID: 5 cpu6 (AP): APIC ID: 6 cpu7 (AP): APIC ID: 7 MADT: Could not find APIC for SCI IRQ 9 [REGMGR] 000001 ... Memory mode: 20: GL8 release BigApp memory : 0x0000000170000000 bytes (5888MiB) FMEM (max) : 0x0000000040000000 bytes (1024MiB) MiniApp DMEM : 0x0000000070000000 bytes (1792MiB) (overlaid on BigApp memory) VSH DMEM : 0x0000000028000000 bytes ( 640MiB) Trace memory & Trace DMEM : 0x0000000000000000 bytes ( 0MiB) Vision memory : 0x0000000001000000 bytes ( 16MiB) Reserved memory : 0x0000000000a00000 bytes ( 10MiB) Flexible memory(SYSTEM) : 0x0000000058e7c000 bytes (1423MiB) BIOS memory size : 0x00000000011b8000 bytes ( 18MiB) Kernel static size : 0x000000000c5cc000 bytes ( 198MiB) acpi0: <SIE ORBIS> on motherboard cpu0: <ACPI CPU> on acpi0 cpu1: <ACPI CPU> on acpi0 cpu2: <ACPI CPU> on acpi0 cpu"
 
Today i flashed the stock NOR dump with UART flag on:

"secure loader build: Nov 27 2023 05:21:22 (r10695:release_branches/release_11.020) [800MHz]
AGESA: GL&MO.BDK W9313
ERROR: main(3738) checkUpdVersion 0xffffffff != 0x11020000"

fan goes max for like half a second, then three beeps and turns off
i will try to reflash stock syscon dump too
 
Flashed stock syscon dump, UART logs are identical at the first, long logs, just release is 11.020 obviously, always BLOD with three long beeps.

I think i need to use hot gun to the syscon pins and resolder the other SMD capacitor to the VCC pin of the syscon. I have probably soldered badly many pins of the syscon.

PS: No its not the SSD/HDD, and i need to try another psu
 
Finally, it works.

Bought new Renesas R5F100LLAFB chip (64-pin syscon replacement) and some low melt solder (Sn42Bi57Ag1) from Mouser, soldered with hot gun at low fan speed and 350c, flashed Syscon patched dump (debug ON) with Renesas Flash Programmer (to be converted from bin to s28 file) using a simple USB UART FT232RL. In the software, if you use RTS pin like me, you must enable the option "Invert".

(In my case RFP says my chip is on version 3.03, which i think is good for dumping the syscon with SYSGLITCH or PS4 Syscon Tools, and my chip is new)

You need 3.3v or 5v to be connected to both VDD and EVDD, RXD to TOOL0, TXD to TOOL0 with 1n5819 diode with cathode to UART, RTS to RESET with 1n5819 diode with cathode to UART and obviously GND with GND.

After that i recommend to check UART logs then install Recovery OFW (in my case 11.00, its like 1GB, not like stock one which Is like 500MB)
 
Last edited:

Similar threads

Back
Top