-
Notifications
You must be signed in to change notification settings - Fork 83
/
firmware.c
393 lines (344 loc) · 11.5 KB
/
firmware.c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
/*
* ps4-kexec - a kexec() implementation for Orbis OS / FreeBSD
*
* Copyright (C) 2015-2016 shuffle2 <godisgovernment@gmail.com>
* Copyright (C) 2015-2016 Hector Martin "marcan" <marcan@marcan.st>
*
* This code is licensed to you under the 2-clause BSD license. See the LICENSE
* file for more information.
*/
#include "firmware.h"
#include "types.h"
#include "kernel.h"
#include "string.h"
#include "types.h"
#include "crc32.h"
#define DIR 0040755
#define FILE 0100644
struct firmware_header {
u32 size_bytes;
u32 header_size_bytes;
u16 header_version_major;
u16 header_version_minor;
u16 ip_version_major;
u16 ip_version_minor;
u32 ucode_version;
u32 ucode_size_bytes;
u32 ucode_array_offset_bytes;
u32 crc32;
union {
struct {
u32 ucode_feature_version;
u32 jt_offset;
u32 jt_size;
u8 end[];
} gfx1;
struct {
u32 ucode_feature_version;
u32 save_and_restore_offset;
u32 clear_state_descriptor_offset;
u32 avail_scratch_ram_locations;
u32 master_pkt_description_offset;
u8 end[];
} rlc1;
struct {
u32 ucode_feature_version;
u32 ucode_change_version;
u32 jt_offset;
u32 jt_size;
u8 end[];
} sdma1;
u8 raw[0xe0];
};
};
static inline char hex(u8 c)
{
if (c <= 9)
return '0' + c;
return 'a' + c - 10;
}
static void hex8(u8 **p, u32 val)
{
*(*p)++ = hex(val >> 28);
*(*p)++ = hex((val >> 24) & 0xf);
*(*p)++ = hex((val >> 20) & 0xf);
*(*p)++ = hex((val >> 16) & 0xf);
*(*p)++ = hex((val >> 12) & 0xf);
*(*p)++ = hex((val >> 8) & 0xf);
*(*p)++ = hex((val >> 4) & 0xf);
*(*p)++ = hex(val & 0xf);
}
void cpio_hdr(u8 **p, const char *name, u32 mode, size_t size)
{
size_t name_len = strlen(name);
// Pad to 4 byte multiple
while (((uintptr_t)*p) & 0x3)
*(*p)++ = 0;
memcpy(*p, "070701", 6);
*p += 6;
hex8(p, 0); // c_ino
hex8(p, mode); // c_mode
hex8(p, 0); // c_uid
hex8(p, 0); // c_gid
hex8(p, 1); // c_nlink
hex8(p, 0); // c_mtime
hex8(p, size); // c_filesize
hex8(p, 0); // c_maj
hex8(p, 0); // c_min
hex8(p, 0); // c_rmaj
hex8(p, 0); // c_rmin
hex8(p, name_len + 1); // c_namesize
hex8(p, 0); // c_chksum
memcpy(*p, name, name_len);
*p += name_len;
*(*p)++ = 0;
while (((uintptr_t)*p) & 0x3)
*(*p)++ = 0;
}
struct fw_header_t {
u64 size_words;
char *unk_ident;
u64 unk;
void *blob;
u64 unk2;
};
struct fw_info_t {
struct fw_header_t *rlc;
struct fw_header_t *sdma0;
struct fw_header_t *sdma1;
struct fw_header_t *ce;
struct fw_header_t *pfp;
struct fw_header_t *me;
struct fw_header_t *mec1;
struct fw_header_t *mec2;
};
struct fw_expected_sizes_t {
u64 rlc;
u64 sdma0;
u64 sdma1;
u64 ce;
u64 pfp;
u64 me;
u64 mec1;
u64 mec2;
};
static const struct fw_expected_sizes_t liverpool_fw_sizes = {
LVP_FW_RLC_SIZE,
LVP_FW_SDMA_SIZE,
LVP_FW_SDMA1_SIZE,
LVP_FW_CE_SIZE,
LVP_FW_PFP_SIZE,
LVP_FW_ME_SIZE,
LVP_FW_MEC_SIZE,
LVP_FW_MEC2_SIZE
};
static const struct fw_expected_sizes_t gladius_fw_sizes = {
GL_FW_RLC_SIZE,
GL_FW_SDMA_SIZE,
GL_FW_SDMA1_SIZE,
GL_FW_CE_SIZE,
GL_FW_PFP_SIZE,
GL_FW_ME_SIZE,
GL_FW_MEC_SIZE,
GL_FW_MEC2_SIZE
};
int copy_firmware(u8 **p, const char *name, struct fw_header_t *hdr, size_t expected_size)
{
kern.printf("Copying %s firmware\n", name);
if (expected_size != (hdr->size_words * 4)) {
kern.printf("copy_firmware: %s: expected size %d, got %d\n",
name, expected_size, hdr->size_words * 4);
return 0;
}
struct firmware_header *fhdr = (struct firmware_header*)*p;
memset(fhdr, 0, sizeof(*fhdr));
*p += sizeof(*fhdr);
memcpy(*p, hdr->blob, expected_size);
fhdr->size_bytes = expected_size + sizeof(*fhdr);
fhdr->header_size_bytes = offsetof(struct firmware_header, raw);
fhdr->header_version_major = 1;
fhdr->header_version_minor = 0;
fhdr->ucode_version = 0x10;
fhdr->ucode_size_bytes = expected_size;
fhdr->ucode_array_offset_bytes = sizeof(*fhdr);
*p += expected_size;
return 1;
}
int copy_gfx_firmware(u8 **p, const char *name, struct fw_header_t *hdr, size_t expected_size)
{
struct firmware_header *fhdr = (struct firmware_header*)*p;
if (!copy_firmware(p, name, hdr, expected_size))
return 0;
fhdr->ip_version_major = 7;
fhdr->ip_version_minor = 2;
fhdr->header_size_bytes = offsetof(struct firmware_header, gfx1.end);
fhdr->gfx1.ucode_feature_version = 21;
fhdr->gfx1.jt_offset = (expected_size & ~0xfff) >> 2;
fhdr->gfx1.jt_size = (expected_size & 0xfff) >> 2;
fhdr->crc32 = crc32(0, fhdr->raw, sizeof(fhdr->raw) + expected_size);
return 1;
}
int copy_rlc_firmware(u8 **p, const char *name, struct fw_header_t *hdr, size_t expected_size)
{
struct firmware_header *fhdr = (struct firmware_header*)*p;
if (!copy_firmware(p, name, hdr, expected_size))
return 0;
fhdr->ip_version_major = 7;
fhdr->ip_version_minor = 2;
fhdr->header_size_bytes = offsetof(struct firmware_header, rlc1.end);
fhdr->rlc1.ucode_feature_version = 1;
fhdr->rlc1.save_and_restore_offset = 0x90;
fhdr->rlc1.clear_state_descriptor_offset = 0x3d;
fhdr->rlc1.avail_scratch_ram_locations = 0x270; // 0x170 for bonaire, 0x270 for kabini??
fhdr->rlc1.master_pkt_description_offset = 0;
fhdr->crc32 = crc32(0, fhdr->raw, sizeof(fhdr->raw) + expected_size);
return 1;
}
int copy_sdma_firmware(u8 **p, const char *name, struct fw_header_t *hdr, size_t expected_size, int idx)
{
struct firmware_header *fhdr = (struct firmware_header*)*p;
if (!copy_firmware(p, name, hdr, expected_size))
return 0;
fhdr->ip_version_major = 2;
fhdr->ip_version_minor = 1;
fhdr->header_size_bytes = offsetof(struct firmware_header, sdma1.end);
fhdr->sdma1.ucode_feature_version = idx == 0 ? 9 : 0;
fhdr->sdma1.ucode_change_version = 0;
fhdr->sdma1.jt_offset = (expected_size & ~0xfff) >> 2;
fhdr->sdma1.jt_size = (expected_size & 0xfff) >> 2;
fhdr->crc32 = crc32(0, fhdr->raw, sizeof(fhdr->raw) + expected_size);
return 1;
}
static const u32 pfp_nop_handler[] = {
0xdc120000, // mov r4, ctr
0x31144000, // seteq r5, r4, #0x4000
0x95400009, // cbz r5, l0
0xc4200016, // ldw r8, [r0, #0x16]
0xdc030000, // mov ctr, r0
0xcc000049, // stw r0, [r0, #0x49]
0xcc200013, // stw r0, [r8, #0x13]
0xc424007e, // ldw r9, [r0, #0x7e]
0x96400000, // l1: cbz r9, l1
0x7c408001, // mov r2, r1
0x88000000, // btab
0xd440007f, // l0: stm r1, [r0, #0x7f]
0x7c408001, // mov r2, r1
0x88000000, // btab
};
static const u32 ce_nop_handler[] = {
0xdc120000, // mov r4, ctr
0x31144000, // seteq r5, r4, #0x4000
0x95400009, // cbz r5, l0
0xc420000c, // ldw r8, [r0, #0xc]
0xdc030000, // mov ctr, r0
0xcc00002f, // stw r0, [r0, #0x2f]
0xcc200012, // stw r0, [r8, #0x12]
0xc424007e, // ldw r9, [r0, #0x7e]
0x96400000, // l1: cbz r9, l1
0x7c408001, // mov r2, r1
0x88000000, // btab
0xd440007f, // l0: stm r1, [r0, #0x7f]
0x7c408001, // mov r2, r1
0x88000000, // btab
};
static const u32 mec_nop_handler[] = {
0xdc120000, // mov r4, ctr
0x31144000, // seteq r5, r4, #0x4000
0x95400009, // cbz r5, l0
0xc43c000c, // ldw r15, [r0, #0x9]
0xdc030000, // mov ctr, r0
0xcc00002b, // stw r0, [r0, #0x2b]
0xcc3c000d, // stw r0, [r15, #0xd]
0xc424007e, // ldw r9, [r0, #0x7e]
0x96400000, // l1: cbz r9, l1
0x7c408001, // mov r2, r1
0x88000000, // btab
0xd440007f, // l0: stm r1, [r0, #0x7f]
0x7c408001, // mov r2, r1
0x88000000, // btab
};
#define PACKET_TYPE_NOP 0x10
static void patch_fw(void *p, const u32 *handler, int handler_size) {
int size = ((struct firmware_header*)p)->ucode_size_bytes;
int code_size = (size & ~0xfff) / 4;
int nop_start = code_size - 0x10;
u32 *fw = p + sizeof(struct firmware_header);
kern.printf("NOP handler at 0x%x\n", nop_start);
memcpy(&fw[nop_start], handler, handler_size);
// patch the branch table entry
for (int off = code_size; off < size/4; off++) {
if ((fw[off] >> 16) == PACKET_TYPE_NOP) {
fw[off] = (PACKET_TYPE_NOP << 16) | nop_start;
}
}
}
struct fw_info_t *get_fw_info() {
if (kern.gc_get_fw_info) {
return kern.gc_get_fw_info();
} else if (kern.Starsha_UcodeInfo) {
return kern.Starsha_UcodeInfo;
} else {
return NULL;
}
}
const struct fw_expected_sizes_t *get_fw_expected_sizes() {
if (kern.gpu_devid_is_9924 && kern.gpu_devid_is_9924()) {
return &gladius_fw_sizes;
} else {
return &liverpool_fw_sizes;
}
}
ssize_t firmware_extract(void *dest)
{
u8 *p = dest;
// Yeah, this calls it Starsha... Liverpool, Starsha, ThebeJ, whatever.
struct fw_info_t *info = get_fw_info();
if (!info) {
kern.printf("firmware_extract: Could not locate firmware table");
return -1;
}
const struct fw_expected_sizes_t *fw_sizes = get_fw_expected_sizes();
cpio_hdr(&p, "lib", DIR, 0);
cpio_hdr(&p, "lib/firmware", DIR, 0);
cpio_hdr(&p, "lib/firmware/radeon", DIR, 0);
cpio_hdr(&p, "lib/firmware/radeon/liverpool_pfp.bin", FILE, FW_HEADER_SIZE + fw_sizes->pfp);
u8 *pfp = p;
if (!copy_gfx_firmware(&p, "PFP", info->pfp, fw_sizes->pfp))
return -1;
patch_fw(pfp, pfp_nop_handler, sizeof(pfp_nop_handler));
cpio_hdr(&p, "lib/firmware/radeon/liverpool_me.bin", FILE, FW_HEADER_SIZE + fw_sizes->me);
if (!copy_gfx_firmware(&p, "ME", info->me, fw_sizes->me))
return -1;
cpio_hdr(&p, "lib/firmware/radeon/liverpool_ce.bin", FILE, FW_HEADER_SIZE + fw_sizes->ce);
u8 *ce = p;
if (!copy_gfx_firmware(&p, "CE", info->ce, fw_sizes->ce))
return -1;
patch_fw(ce, ce_nop_handler, sizeof(ce_nop_handler));
cpio_hdr(&p, "lib/firmware/radeon/liverpool_mec.bin", FILE, FW_HEADER_SIZE + fw_sizes->mec1);
u8 *mec1 = p;
if (!copy_gfx_firmware(&p, "MEC", info->mec1, fw_sizes->mec1))
return -1;
patch_fw(mec1, mec_nop_handler, sizeof(mec_nop_handler));
cpio_hdr(&p, "lib/firmware/radeon/liverpool_mec2.bin", FILE, FW_HEADER_SIZE + fw_sizes->mec2);
u8 *mec2 = p;
if (!copy_gfx_firmware(&p, "MEC2", info->mec2, fw_sizes->mec2))
return -1;
patch_fw(mec2, mec_nop_handler, sizeof(mec_nop_handler));
cpio_hdr(&p, "lib/firmware/radeon/liverpool_rlc.bin", FILE, FW_HEADER_SIZE + fw_sizes->rlc);
if (!copy_rlc_firmware(&p, "RLC", info->rlc, fw_sizes->rlc))
return -1;
cpio_hdr(&p, "lib/firmware/radeon/liverpool_sdma.bin", FILE, FW_HEADER_SIZE + fw_sizes->sdma0);
if (!copy_sdma_firmware(&p, "SDMA", info->sdma0, fw_sizes->sdma0, 0))
return -1;
cpio_hdr(&p, "TRAILER!!!", FILE, 0);
cpio_hdr(&p, "lib/firmware/radeon/liverpool_sdma1.bin", FILE, FW_HEADER_SIZE + fw_sizes->sdma1);
if (!copy_sdma_firmware(&p, "SDMA1", info->sdma1, fw_sizes->sdma1, 1))
return -1;
cpio_hdr(&p, "TRAILER!!!", FILE, 0);
size_t size = p - (u8*)dest;
if (size > FW_CPIO_SIZE) {
kern.printf("firmware_extract: overflow! %d > %d\n", size, FW_CPIO_SIZE);
return -1;
}
return size;
}