3.1 KiB
How Filogic (MT7981/MT7986) WiFi boots — the four images and three cores
All claims cited to Linux source (mt76 driver unless noted) or to observed
blob content (docs/findings.md, dataset/history.jsonl). Inference is
marked INFERENCE.
The cast
The WiFi subsystem of a Filogic SoC contains three processor cores plus a masked boot ROM, programmed by the kernel driver at probe time:
| Image | Runs on | Role |
|---|---|---|
mt79xx_rom_patch.bin |
patch RAM over boot ROM behavior | small fixup applied before main firmware (evidence: mt76_connac2_load_patch(); patch strings sys_patch_common_mcu.c) |
mt79xx_wm.bin |
WM core ("neptune") | main MAC/PHY firmware: TX/RX control, rate adaptation, MU (MURU) scheduling, calibration, power/thermal (INFERENCE from strings: RA_PARAM_*, MURU_*, DPD Pparam … Do Cal, LPTPO/EVMTPO) |
mt79xx_wa.bin |
WA core | offload/queue-management firmware (INFERENCE: separate load target in driver; distinct ILM/DLM addresses 0x10200000/0x10300000) |
mt79xx_wo*.bin |
WED offload core | packet DMA between WiFi and ethernet; FreeRTOS v10.0/NDS32 (string evidence). Loaded NOT by mt76 but by the ethernet WED driver: drivers/net/ethernet/mediatek/mtk_wed_mcu.c |
WM/WA/WO firmware is NDS32LE (docs/format.md §ISA).
Load sequence (mt7915e driver, SoC/PCIe)
Cited: mt7915/mcu.c: mt7915_mcu_init() →
mt7915_load_firmware(); helpers in mt76_connac_mcu.c.
- Driver acquires the patch semaphore
(
mt76_connac_mcu_get_patch_sem(), MCU PATCH_SEM_CONTROL message). - Patch download:
mt76_connac2_load_patch()parses the BE patch container, busmaster-writes each section to itsaddr(observed0x00900000patch RAM), resets the MCU, waits forFW_STATE_RDYhandshake. - Patch semaphore released; WM container loaded
(
mt76_connac2_load_ram→mt76_connac2_send_ram): regions streamed in table order to theiraddrdestinations. - WA container loaded the same way, then the driver polls for
firmware-ready (
mt7915_mcu_fw_log,fw_ownhandshake inmt76_connac_mcu.c). - On SoCs with WED,
mtk_wed(ethernet driver) separately loads WO firmware for the offload core (cited:mtk_wed_mcu.c).
No signature verification exists anywhere on this path: the loader computes
nothing cryptographic, and the optional per-region encryption
(FW_FEATURE_SET_ENCRYPT) is unset in every observed revision — so blobs on
this platform are freely replaceable at the OS level
(INFERENCE from absence + plaintext; hardware-empirical confirmation is a
planned P2 milestone).
Download destinations (observed, mt7981 WM)
| Address family | feature_set | observed in |
|---|---|---|
0x0041xxxx, 0x0023xxxx |
0x00 | data-ish regions |
0x0220xxxx–0x0233xxxx |
0x00 / 0x20 | code+data (region 0 carries OVERRIDE_ADDR) |
0xe003xxxx–0xe009xxxx |
0x00 | large code regions |
0xf000xxxx–0xf009xxxx |
0x80 (bit7, undefined upstream — U1) | consistently flagged |
Meaning of these bus ranges beyond "download destinations": not yet
established (see PLAN open items; will be mapped in P1 RE against
mt7915/regs.h).