Skip to content

Working with PPSTRONG cameras

Lukáš Mojžíš edited this page Feb 24, 2026 · 1 revision

PPSTRONG platform

If you have PPSTRONG based camera, which you can assume from ONVIF or UART, you can use these guidelines to work with it

How to tell you have a PPSTRONG camera?

ONVIF

In ONVIF tool, you will see a firmware update filename starting with ppstrong- and/or other mention of either PPSTRONG or PPS in camera identification section.

UART

Assume you have UART access. How to know your camera is PPSTRONG platform? Place an empty ppsMmcTool.txt into the root of FAT formatted SD card, insert to camera, hold down reset button while powering the camera. Alternatively you may also hold the reset button until the camera restarts itself.

In u-boot log there will be something like this:

reset key pressed!
cmd:fatload mmc 0 0x80600000 ppsMmcTool.txt
reading ppsMmcTool.txt

Getting current boot environment variables

Set ppsMmcTool.txt contents to be:

style=upgrade,,writeAddr=0,,password=nothing,,writeLen=0,,fileName=ppsMmcTool.txt - 0x0;printenv,,

Reboot camera again, holding down the reset button You will get full boot environment variables output, like

reset key pressed!
cmd:fatload mmc 0 0x80600000 ppsMmcTool.txt
reading ppsMmcTool.txt
%d bytes read in %d ms (%.02f KiB/s)
cmdBuf:fatload mmc 0 0x80600000 ppsMmcTool.txt - 0x0;printenv,,
reading env

[...]

baudrate=115200
bootargs=console=/dev/null mem=40M@0x0 rmem=20M@0x2800000 nmem=4M@0x3C00000 init=/linuxrc mtdparts=sfc0_nor:256k(BOOT),2560k(sys),7680k(app),5120k(recove),640k(cfg),64k(enc),64k(sysflg) lpj=11968512 debug_mode=0
bootcmd=sf0 probe;sf0 read 0x80600
bootdelay=2
ethact=Jz4775-9161
ethaddr=00:11:22:56:96:69
filesize=ca
gatewayip=193.169.4.1
ipaddr=193.169.4.151
loads_echo=1
netmask=255.255.255.0
serverip=193.169.4.2
stderr=serial
stdin=serial
stdout=serial

Environment size: 503/4092 bytes
error: Pack header size error!
error: upgrade.bin unpack error!
mmc power off ...

Temporary override of boot environment variables

Set ppsMmcTool.txt contents to be:

style=upgrade,,writeAddr=0,,password=nothing,,writeLen=0,,fileName=ppsMmcTool.txt - 0x7b;env import -t 80600000;printenv,,
bootargs=console=ttyS1,115200n8 mem=40M@0x0 rmem=20M@0x2800000 nmem=4M@0x3C00000 init=/linuxrc mtdparts=sfc0_nor:256k(BOOT),2560k(sys),7680k(app),5120k(recove),640k(cfg),64k(enc),64k(sysflg) lpj=11968512

and any env vars you would like to set

NOTE: Do NOT alter bootcmd unless you know what you are doing! Remove it from the list of vars to be set! Altering it (even to the same value) will very likely trigger a callback that will force removal of decryption key and the camera will no longer boot without knowledge of the factory key. Again, if this happens, it is NOT reversible by reverting bootcmd to the original value nor restoring env defaults and reflash of stock firmware will most likely be necessary.

Boot again.

Env should now be set to the new values. This is change is ephemeral (unless you altered bootcmd).

Permanent override of boot environment variables

If you want to make the change permanent, append ;saveenv to the commands on the first line an adjust the skip offset from 0x7b to hex value of final length of the first line, ie. 0x83:

style=upgrade,,writeAddr=0,,password=nothing,,writeLen=0,,fileName=ppsMmcTool.txt - 0x83;env import -t 80600000;printenv;saveenv,,
bootargs=console=ttyS1,115200n8 mem=40M@0x0 rmem=20M@0x2800000 nmem=4M@0x3C00000 init=/linuxrc mtdparts=sfc0_nor:256k(BOOT),2560k(sys),7680k(app),5120k(recove),640k(cfg),64k(enc),64k(sysflg) lpj=11968512

The camera will now always use the env vars in the file. SDcard may now safely be removed and the changes will be kept, unless firmware changes it again.

Sources

The above builds on top of existing processes discovered by @guino, namely it stems from No programmer, No UART, No problem! but has been repurposed altered for changing the boot environment variables. And it's just a single file.

Other use of the approach

You may run additional u-boot, commands, i.e. help or flash thingino directly from SD card

  1. Wiki Home
  2. About the Project
    1. Contributions
    2. Features
    3. Project Philosophy
    4. Releases
  3. Getting Started
    1. FAQ
    2. Glossary
    3. Hardware Identification
    4. Image Builder
    5. USB Boot Mode
    6. Ingenic USB Cloner
      1. OTG Booting
    7. PPSTRONG
    8. Installation: General
    9. Installation: No Tools Methods
    10. Resources and Links
    11. Support Community
    12. Troubleshooting
    13. UART Connection
    14. Updating Firmware
    15. Unbricking
    16. Web UI
  4. Supported Cameras
    1. Cameras
    2. 360 AP1PA3
    3. AliExpress LTIA‐37FJZ (Vanhua Z55 module)
    4. AOQEE C1
    5. Aosu C5L
    6. Cinnado
      1. Cinnado D1 2K
      2. Cinnado D1 3K
    7. Dekco DC5L
    8. Eufy
      1. Eufy E210 Outdoor Cam
      2. Eufy E220
    9. Galayou/Wansview
      1. Galayou G2
      2. Galayou G7
      3. Wansview W6
      4. Wansview W7/Galayou Y4
    10. Hualai (Wyze/Atom/Neos/Personal)
      1. Dafang Upgrading for Wyze v2
      2. NEOS conversion
      3. Personal Cam Pan and Cam 2
      4. Wyze Cam Pan V1
      5. Wyze Doorbell (V1)
        1. Chime Reverse Engineering
        2. Flashing VDB1 over UART (YMODEM)
        3. MQTT Control and Monitoring
      6. Wyze v2/Neos SmartCam/ATOM Cam 1
      7. Wyze v3
      8. Wyze Accessories
    11. iFlytek XFP301‐M
    12. Jienuo JN-107-AR-E-WIFI
    13. Jooan A6M
    14. LaView L2
    15. LongPlus X07
    16. LSC 3215672
    17. Sannce I21AG
    18. Sonoff Cam‐S2 and B1P
    19. TP-Link Tapo C100/C110/C111
    20. Wuuk Y0510
    21. Xiaomi
      1. Xiaomi Mijia1080p (SXJ02ZM)
      2. Xiaomi MJSXJ03HL
      3. Xiaomi Outdoor Camera AW200 (MJSXJ05HL)
  5. Configuration
    1. Administration
    2. Automation
      1. Configuring camera using runonce.sh script
    3. Cron jobs
    4. General
    5. LED Indicators
    6. Lighting
    7. Media Streaming Endpoints
    8. Network Storage
    9. Networking
      1. DHCP: Timezone
      2. Wireless Networking
      3. USB Direct w CDC (NCM)
      4. USB Ethernet Networking
      5. Remote Access
      6. VPN
        1. Tailscale
        2. Wireguard
        3. Zerotier
      7. Wi-Fi
        1. Self Hosted AP
        2. Tips and Tricks
      8. WWAN (Cellular)
    10. Night Mode
    11. ONVIF
    12. OSD (On-screen Display)
    13. Plugins
      1. Motion Guard
      2. Yandex Disk
    14. SSH Access Keys
    15. Wi-Fi Access
    16. Provisioning
    17. Streamer Bitrate Control
    18. Video Rotation
  6. Integration
    1. Home Assistant
    2. Frigate
    3. Ingenic A1/$15 NVR
    4. LightNVR
    5. Mobile Apps
    6. MQTT Integration
    7. Telegram Bot Integration
    8. Virtual Webcam on Linux
    9. Mainsail (Klipper)
  7. Development
    1. Booting
      1. Boot: MMC SD
      2. Boot: NFS
    2. CH341A Programmer
    3. RTSP Players
    4. Flash Chips
    5. go2rtc
    6. Porting Guide
    7. Ingenic Platform Capability Matrix
    8. Ingenic Image Processor
    9. ISP Reserved Memory (RMEM)
    10. Debugging
    11. Software
      1. Building From Sources
      2. Buildroot
      3. Toolchain
      4. Choice of JSON library
    12. SSL and TLS Web UI in thingino
    13. Tech Info
      1. Hardware
      2. PWM Info
      3. Supported Hardware
      4. T23 GPIOs
      5. T31 GPIOs
    14. U-Boot Cheatsheet
    15. Zeratul/Atlas/Tassadar
    16. Resources

Clone this wiki locally