From 871e4d1551ac8c5be4339e4a3129c45014e613b5 Mon Sep 17 00:00:00 2001 From: Bradley Morgan Date: Sun, 4 Oct 2026 01:44:02 +0000 Subject: tashaboot: devicetree relocate and grow, real chosen properties Firmware edits the devicetree it hands the kernel: new properties cannot go into a packed fdt in place, the blob moves to scratch first and the blocks grow there. The insert moves the strings block up by the prop size, opens the prop slot before /chosen's end token, the new name lands at the strings end, and all four header fields track the geometry, totalsize, off_dt_ strings, size_dt_strings and size_dt_struct. The last one bounds the token walk in libfdt and a stale value there reads as BADSTRUCTURE, the kernel parsed no memory node and panicked on page table allocation before the first print. The strings block length comes from the size_dt_strings header field, not totalsize minus off_dt_strings, qemu's tree carries a hole after the strings block and the subtraction drags it along as tree. The initrd start and end land in /chosen as real properties now, the initrd= bootargs shortcut is gone. receipt: smp brought up 1 node 4 cpus, run /init, userspace, busybox shell, the initrd mounted from the chosen cells. --- common/dtb_reloc.c | 69 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) create mode 100644 common/dtb_reloc.c (limited to 'common/dtb_reloc.c') diff --git a/common/dtb_reloc.c b/common/dtb_reloc.c new file mode 100644 index 0000000..c3e0fe5 --- /dev/null +++ b/common/dtb_reloc.c @@ -0,0 +1,69 @@ +/* + * dtb_reloc.c - grow the devicetree the way libfdt does, in a + * buffer with room to spare. firmware cannot edit a packed fdt + * in place, new properties shift everything behind them, so the + * blob is copied into scratch verbatim, the free space after + * totalsize is the room the insert code shifts into, then the + * walkers patch the copy and the kernel gets its address. + * + * The layout follows the devicetree specification: header, + * struct block, strings block, free space. The rebuild copies + * header, struct, strings, fixes the offsets in the new header, + * and leaves the gap between struct and strings as the room new + * properties will consume. + * + * Copyright (C) 2026 Bradley Morgan + */ + +#include +#include +#include +#include + +#define FDT_BEGIN_NODE 1 +#define FDT_END_NODE 2 +#define FDT_PROP 3 +#define FDT_NOP 4 +#define FDT_END 9 + +static uint32_t be32(const void *p) +{ + const uint8_t *b = p; + + return ((uint32_t)b[0] << 24) | ((uint32_t)b[1] << 16) | + ((uint32_t)b[2] << 8) | (uint32_t)b[3]; +} + +/* + * copy the blob into the scratch, grow bytes of headroom after + * the end. returns the new blob address or 0 on a short buffer. + */ +uintptr_t tb_dtb_relocate(uintptr_t dtb, void *scratch, size_t scratch_size, + size_t grow) +{ + uint8_t *in = (uint8_t *)dtb; + uint8_t *out = scratch; + uint32_t totalsize; + + if (be32(in) != 0xd00dfeed) + return 0; + + totalsize = be32(in + 4); + + if (scratch_size < (size_t)totalsize + grow) + return 0; + + /* + * verbatim copy, byte for byte. the grow room is the free + * scratch after totalsize, the insert code shifts the + * strings block into it. an interior gap between the + * struct and strings blocks only invites the walkers to + * count it as tree. + */ + for (uint32_t i = 0; i < totalsize; i++) + out[i] = in[i]; + + (void)grow; + + return (uintptr_t)out; +} -- cgit v1.2.3