TP-LINK TGR1900 (Google OnHub)

From TechInfoDepot
(Redirected from Google OnHub)
Jump to navigationJump to search
abgn+ac (AC1750)
Google OnHub Wireless Router
Wikipedia TP-Link
WikiDevi.wi-cat.ru TP-LINK TGR1900 (Google OnHub)
3rd Party Firmware
dd-wrt Status Unknown
OpenWrt Supported
Tomato any flavor Incompatible
Gargoyle Status Unknown
Platform
BrandModelRev TP-LINK TGR1900 BLU (Google OnHub)
FCC ID TE7TGR1900
IC ID 8853A-TGR1900
Type wireless router
CPU1 checkY Qualcomm IPQ8064
CPU1 Type ARMv7-A Cortex-A15
CPU1 Speed 1.4 GHz ( 2 cores )
Flash1 Chip Micron MTFC4GACAAAM-1MWT
Flash1 Size 4 GiB 4,096 MiB <br />4,294,967,296 B <br />33,554,432 Kib <br />4,194,304 KiB <br />32,768 Mib <br /> (eMMC NAND)
Flash2 Chip Micron N25Q064A
Flash2 Size 8 MiB8,388,608 B <br />65,536 Kib <br />8,192 KiB <br />64 Mib <br />0.00781 GiB <br />
RAM1 Size 1 GiB 1,024 MiB <br />1,073,741,824 B <br />8,388,608 Kib <br />1,048,576 KiB <br />8,192 Mib <br />
RAM1 Chip Micron MT41K256M16HA-125:E x 2
ETH chip1 Qualcomm IPQ8064
Switch Qualcomm Atheros QCA8337
Ethernet Port Count 1-1GbE-WAN
4-1GbE-LAN
Wired Standard IEEE 802.3i/3u/3ab

802dot11 OUI: none specified

Stock bootloader Coreboot
Expansion IF types USB 3.0
USB ports 1
USB Hub Compatible Untested
Power 12 VDC, 3 A
Connector type barrel
Serial Port (UART) yes, (115200 8N1)
JTAG Port no

Flags:
Bluetooth 4.0, ZigBee, Speaker 3W

Additional chips
2.4GHz WLAN Power Amplifier Module;Skyworks;SKY2623L;;3;
2.4GHz 256QAM LNA Module;Skyworks;SKY65971-11;;3;
5GHz WLAN Power Amplifier Module;Skyworks;SKY85405;;3;
5GHz 802.11ac LNA Module;Skyworks;SKY65981-11;;3;
5GHz DPDT switch;Skyworks;SKY13438;;3;
2.4GHz Bluetooth Radio Chip;Atheros;AR3012-BL3D;;1;
SoC Network Co-Processor for ZigBee;Silicon Labs;EM3581;;1;
2.4GHz ZigBee/Smart Front End Module;Skyworks;SKY66109-1;;1;
Programmable 9-output LED Driver;National Semiconductor;LP5523;;1;
Trusted Platform Module;Infineon;SLB9615;;1;

Other
3rd Party Firmware Support OpenWrt • (List | Dev | DLs)
Retail
Availability End of Life
FCC approval date 12 August 2015
(Est.) initial retail price (in USD): $200
ASIN B013ALA9LA
Country of manuf China
Radio 1
Chip1 Qualcomm Atheros QCA9880
Wireless interface OUI none specified
Antenna Connector Type U.FL
MIMO status 3x3:3
Wireless Standard IEEE 802.11b/g/n
802.11n up to 450 Mbps
802.11g up to 54 Mbps
802.11b up to 11 Mbps
WiFi Operating Frequency 2.4 GHz
Radio 2
Chip1 Qualcomm Atheros QCA9880-BR4A
Wireless interface OUI none specified
Antenna Connector Type U.FL
MIMO status 3x3:3
Wireless Standard IEEE 802.11a/n/ac
802.11ac up to 1300 Mbps
802.11n up to 450 Mbps
802.11a up to 54 Mbps
WiFi Operating Frequency 5 GHz
Radio 3
Chip1 Qualcomm Atheros QCA9882
Wireless interface OUI none specified
Antenna Connector Type none specified
MIMO status 1x1:1
Wireless Standard IEEE 802.11a/b/g/n/ac
WiFi Operating Frequency 2.4 or 5 GHz

For a list of all currently documented Qualcomm chipsets with specifications, see Qualcomm.
For a list of all currently documented Qualcomm Atheros (QCA) chipsets with specifications, see Qualcomm Atheros.

For a list of all currently documented TP-LINK devices with specifications, see TP-LINK.

450 Mbps - 3SS 2.4GHz 802.11n (40MHz chan.),
1300 Mbps - 3SS 5GHz 802.11ac (80MHz chan.) = AC1750 class

Overview

"Model: TGR1900(BLU)(US) Ver:1.0", "1520" (05/2015),

"02002" and "CA-F121" is silkscreened on the board.


This device was under short-term confidentiality, but that expired 02/05/2016 ⚠.

Links of Interest

Product page (Google OnHub Router)
Product page (TP-LINK TGR1900 OnHub Router)

Reviews

- Skyworks SE2623L 2.4GHz power amp (x3)
- Skyworks unidentified DPDT switch ("S81") (x3)
- Skyworks SKY65971-11 2.4GHz 256QAM LNA (x3)
- Skyworks SKY85405 5GHz Power amp (x3)
- Skyworks SKY13438 6GHz DPDT switch (x3)
- Skyworks SKY65981-11 5GHz 802.11ac LNA (x3)
  • Monitor: Qualcomm Atheros QCA9882 (1x1 802.11abgn/ac)
  • Bluetooth: Atheros AR3012 Bluetooth 4.0 SoC
  • ZigBee: Silicon Labs EM3581 ZigBee/Thread SoC
- Skyworks SKY66109-11 2.4GHz Front End Module

Teardown

Dual-core (2x Krait 300)
  • Flash: 8MB (SPI) + 4GB (eMMC)
Micron N25Q064A (64Mb SPI flash)
Micron MTFC4GACAAAM (4GB NAND flash)
chip marked "M, 4ZA28JWA57, 7PYG" (4GB eMMC NAND)
chip marked "M, 5DE77D9PXV, PGGL" (4Gb DDR3L SDRAM)
Congestion-sensing radio: Qualcomm Atheros QCA9882 (1x1)
Skyworks SKY2623L - 2.4GHz WLAN Power amplifier
Skyworks SKY85405 - 5GHz WLAN Power amplifier
  • Antenna: Dual band 2.4GHz and 5GHz 12-antenna array
6x 2.4GHz antennas (marked J211, J212, J221, J222, J231, J232)
6x 5GHz antennas (marked J511, J512, J521, J522, J531, J532)
1x congestion-sensing antenna (JS1)
  • Bluetooth: Atheros AR3012-BL3D Bluetooth 4.0 SoC + antenna (JBT1)
Infineon SLB9615 - Trusted Platform Module
  • ZigBee: Silicon Labs EM3581 SoC Network Co-Processor + ant. (JZB1)
Skyworks SKY66109 - 2.4GHz ZigBee/Smart Energy front-end module
  • Switch: Qualcomm Atheros QCA8337 (1x WAN, 1x LAN)
  • USB: 1x USB 3.0 port + Bluetooth 4.0
  • LED: National Semiconductor LP5523 Programmable 9-output LED driver
Ambient light sensor, Speaker 3W

Flashing

Flashing OpenWrt

Target: ipq806x
Subtarget: chromium
Package architecture: arm_cortex-a15_neon-vfpv4
Supported Since Commit
Support started version: 23.05.0
Current supported version: 25.12.5
LAN Hardware: Qualcomm Atheros QCA8337
WLAN Hardware: 2x Qualcomm Atheros QCA9880, Qualcomm Atheros QCA9882
WLAN Comment: QCA9882 is 1x1 for monitoring, not regular use
Installation method(s):
see devicepage
Recovery method(s):
see devicepage
Comment:
Bluetooth 4.0, ZigBee, TPM 1.2, Speaker. 4GB eMMC
git • >>
ipq806x: Initial TP-Link and ASUS OnHub support
TP-Link and ASUS OnHub devices are very similar, sharing many of the
same characteristics and much of their Device Tree. They both run a
version of ChromeOS for their factory firmware, and so installation
instructions look very similar to Google Wifi [1].

Things I've tested, and are working:

 * Ethernet
 * WiFi (2.4 and 5 GHz)
 * LEDs
 * USB
 * eMMC
 * Serial console (if you wire it up yourself)
 * 2x CPU
 * Speaker

== Installation instructions summary ==

1. Flash *-factory.bin to a USB drive (e.g., with `dd`)
2. Insert USB drive, to boot OpenWrt from USB
3. Copy the same *-factory.bin over to device, and flash it to eMMC to
   make OpenWrt permanent

== Developer mode, booting from USB (Step 2) ==

To enter Developer Mode and boot OpenWrt from a USB stick:

1. Unplug power
2. Gain access to the "developer switch" through the bottom of the
   device
3. Hold down the "reset switch" (near the USB port / power plug)
4. Plug power back in
5. The LED on the device should turn white, then blink orange, then
   red. Release the reset switch.
6. Insert USB drive with OpenWrt factory.bin
7. Press the hidden developer switch under the device to boot to USB;
   you should see some activity lights (if you have any) on your USB
   drive
8. Depending on your configuration, the router's LED(s) should come on.
   You're now running OpenWrt off a USB stick.

These instructions are derived from:

https://www.exploitee.rs/index.php/Rooting_The_Google_OnHub#Enabling_%22Developer_Mode%22_on_the_OnHub
https://www.exploitee.rs/index.php/Asus_OnHub#Enabling_%22Developer_Mode%22_on_the_OnHub

~~Finding the developer switch:~~ for TP-Link, the developer switch is
on the bottom of the device, underneath some of the rubber padding and a
screw. For ASUS, remove the entire base, via 4 screws under the rubber
feet. See the Exploitee instructions for more info and photos.

== Making OpenWrt permanent (on eMMC) (Step 3) ==

Once you're running OpenWrt via USB:

1. Connect Ethernet to the LAN port; router's LAN address should be at
   192.168.1.1
2. Connect another system to the router's LAN, and copy the factory.bin
   image over, via SCP and SSH:

     scp -O openwrt-ipq806x-chromium-tplink_onhub-squashfs-factory.bin root@192.168.1.1:
     ssh root@192.168.1.1 -C "dd if=/dev/zero bs=512 seek=7552991 of=/dev/mmcblk0 count=33 && \
     dd if=/root/openwrt-ipq806x-chromium-tplink_onhub-squashfs-factory.bin of=/dev/mmcblk0"
3. Reboot and remove the USB drive.

== Developer mode beep ==

Note that every time you boot the OnHub in developer mode, the device
will play a loud "beep" after a few seconds. This is described in the
Chromium docs [2], and is intended to make it clear that the device is
not running Google software. It is nontrivial to completely disable this
beep, although it's possible to "acknowledge" developer mode (and skip
the beep) by using a USB keyboard to press CTRL+D every time you boot.

[1] https://openwrt.org/toh/google/wifi
[2] https://chromium.googlesource.com/chromiumos/docs/+/HEAD/developer_mode.md

Pictures

User Images