mtk-wifi-fw/docs/boot.md

59 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# How Filogic (MT7981/MT7986) WiFi boots — the four images and three cores
All claims cited to Linux source (mt76 driver unless noted) or to observed
blob content (`docs/findings.md`, `dataset/history.jsonl`). Inference is
marked INFERENCE.
## The cast
The WiFi subsystem of a Filogic SoC contains three processor cores plus a
masked boot ROM, programmed by the kernel driver at probe time:
| Image | Runs on | Role |
|---|---|---|
| `mt79xx_rom_patch.bin` | patch RAM over boot ROM behavior | small fixup applied before main firmware (evidence: `mt76_connac2_load_patch()`; patch strings `sys_patch_common_mcu.c`) |
| `mt79xx_wm.bin` | WM core ("neptune") | main MAC/PHY firmware: TX/RX control, rate adaptation, MU (MURU) scheduling, calibration, power/thermal (INFERENCE from strings: `RA_PARAM_*`, `MURU_*`, `DPD Pparam … Do Cal`, `LPTPO`/`EVMTPO`) |
| `mt79xx_wa.bin` | WA core | offload/queue-management firmware (INFERENCE: separate load target in driver; distinct ILM/DLM addresses `0x10200000`/`0x10300000`) |
| `mt79xx_wo*.bin` | WED offload core | packet DMA between WiFi and ethernet; FreeRTOS v10.0/NDS32 (string evidence). Loaded NOT by mt76 but by the ethernet WED driver: `drivers/net/ethernet/mediatek/mtk_wed_mcu.c` |
WM/WA/WO firmware is NDS32LE (`docs/format.md` §ISA).
## Load sequence (mt7915e driver, SoC/PCIe)
Cited: `mt7915/mcu.c: mt7915_mcu_init()` →
`mt7915_load_firmware()`; helpers in `mt76_connac_mcu.c`.
1. Driver acquires the patch semaphore
(`mt76_connac_mcu_get_patch_sem()`, MCU PATCH_SEM_CONTROL message).
2. Patch download: `mt76_connac2_load_patch()` parses the BE patch
container, busmaster-writes each section to its `addr` (observed
`0x00900000` patch RAM), resets the MCU, waits for `FW_STATE_RDY`
handshake.
3. Patch semaphore released; WM container loaded
(`mt76_connac2_load_ram` → `mt76_connac2_send_ram`): regions streamed in
table order to their `addr` destinations.
4. WA container loaded the same way, then the driver polls for
firmware-ready (`mt7915_mcu_fw_log`, `fw_own` handshake in
`mt76_connac_mcu.c`).
5. On SoCs with WED, `mtk_wed` (ethernet driver) separately loads WO
firmware for the offload core (cited: `mtk_wed_mcu.c`).
No signature verification exists anywhere on this path: the loader computes
nothing cryptographic, and the optional per-region encryption
(`FW_FEATURE_SET_ENCRYPT`) is unset in every observed revision — so blobs on
this platform are freely replaceable at the OS level
(INFERENCE from absence + plaintext; hardware-empirical confirmation is a
planned P2 milestone).
## Download destinations (observed, mt7981 WM)
| Address family | feature_set | observed in |
|---|---|---|
| `0x0041xxxx`, `0x0023xxxx` | 0x00 | data-ish regions |
| `0x0220xxxx–0x0233xxxx` | 0x00 / 0x20 | code+data (region 0 carries OVERRIDE_ADDR) |
| `0xe003xxxx–0xe009xxxx` | 0x00 | large code regions |
| `0xf000xxxx–0xf009xxxx` | **0x80 (bit7, undefined upstream — U1)** | consistently flagged |
Meaning of these bus ranges beyond "download destinations": not yet
established (see PLAN open items; will be mapped in P1 RE against
`mt7915/regs.h`).