XMMBoot » History » Version 88
Denis 'GNUtoo' Carikli, 03/28/2020 02:47 AM
1 | 1 | Denis 'GNUtoo' Carikli | h1. XMMBoot |
---|---|---|---|
2 | |||
3 | 59 | Denis 'GNUtoo' Carikli | {{toc}} |
4 | |||
5 | 1 | Denis 'GNUtoo' Carikli | h2. Introduction |
6 | |||
7 | For both libsamsung-ipc and the Linux driver it's interesting to understand better the boot of the modem in order to come with good names for the abstraction. |
||
8 | |||
9 | 58 | Denis 'GNUtoo' Carikli | h2. Abstraction |
10 | |||
11 | * hci_power -> link_power |
||
12 | |||
13 | 63 | Denis 'GNUtoo' Carikli | TODO: |
14 | * Find the difference between power_on and boot_power_on |
||
15 | ** Look at the GPIOs and understand what they do |
||
16 | ** Just read the code that use the GPIOs |
||
17 | ** Diff both procedures |
||
18 | 67 | Denis 'GNUtoo' Carikli | * Look which device has which XMM626X |
19 | * Add XMM6210 devices too |
||
20 | 63 | Denis 'GNUtoo' Carikli | |
21 | 16 | Denis 'GNUtoo' Carikli | h2. GPIOs |
22 | |||
23 | 55 | Denis 'GNUtoo' Carikli | h3. Devices GPIOs assignement and drivers |
24 | 47 | Denis 'GNUtoo' Carikli | |
25 | 79 | Denis 'GNUtoo' Carikli | |_\4. Hardware |_\2. Linux |_\1. libsamsung-ipc | |
26 | |_. Variant |_. SOC |_. Modem |_. Link |_. GPIO usage |_. GPIO assignement |_. device driver name | |
||
27 | | Galaxy Tab: |
||
28 | 81 | Denis 'GNUtoo' Carikli | GT-P1000 | Exynos 3310 | | RAM | | | aries | |
29 | 77 | Denis 'GNUtoo' Carikli | | Galaxy S: |
30 | 79 | Denis 'GNUtoo' Carikli | GT-I91000 | Exynos 3110 | | RAM | | | aries | |
31 | 1 | Denis 'GNUtoo' Carikli | | Nexus S: |
32 | GT-I9020 |
||
33 | GT-I9020A |
||
34 | 79 | Denis 'GNUtoo' Carikli | GT-I9023 | Exynos 3110 | | RAM | | | crespo | |
35 | 74 | Denis 'GNUtoo' Carikli | | Galaxy SII: |
36 | 79 | Denis 'GNUtoo' Carikli | GT-I9100 | Exynos 4410 | XMM6260 | HSIC | "CONFIG_UMTS_MODEM_XMM6260=y":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9100_defconfig#n1321 | | galaxys2 | |
37 | 74 | Denis 'GNUtoo' Carikli | | Galaxy Nexus: |
38 | 79 | Denis 'GNUtoo' Carikli | GT-I9250 | OMAP 4460 | | MIPI | | | maguro | |
39 | 74 | Denis 'GNUtoo' Carikli | | Galaxy SIII: |
40 | 49 | Denis 'GNUtoo' Carikli | GT-I9300 | Exynos 4412 | XMM6262 | HSIC | "CONFIG_UMTS_MODEM_XMM6262=y":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9300_defconfig#n1350 |
41 | 1 | Denis 'GNUtoo' Carikli | "Makefile":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/drivers/misc/modem_if/Makefile#n10 |
42 | "modem_modemctl_device_xmm6262.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/drivers/misc/modem_if/modem_modemctl_device_xmm6262.c | "CONFIG_SEC_MODEM_M0=y":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9300_defconfig#n541 |
||
43 | "Makefile":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/Makefile#n320 |
||
44 | 50 | Denis 'GNUtoo' Carikli | "board-m0-modems.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/board-m0-modems.c |
45 | 1 | Denis 'GNUtoo' Carikli | "CONFIG_MACH_M0=y":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9300_defconfig#n455 |
46 | "gpio-midas.h":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/include/mach/gpio-midas.h#n28 |
||
47 | 79 | Denis 'GNUtoo' Carikli | "gpio-rev00-m0.h":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/include/mach/gpio-rev00-m0.h | i9300 | |
48 | 74 | Denis 'GNUtoo' Carikli | | Galaxy Note 8.0 GSM: |
49 | 79 | Denis 'GNUtoo' Carikli | GT-N5100 | Exynos 4412 | | HSIC | | | n5100 | |
50 | 74 | Denis 'GNUtoo' Carikli | | Galaxy Note II: |
51 | 79 | Denis 'GNUtoo' Carikli | GT-N7100 | Exynos 4412 | XMM6262 | HSIC | "CONFIG_UMTS_MODEM_XMM6262=y":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_n7100_defconfig#n1356 | | n7100 | |
52 | 74 | Denis 'GNUtoo' Carikli | | Galaxy Tab 2: |
53 | GT-P3100 |
||
54 | 79 | Denis 'GNUtoo' Carikli | GT-P5100 | OMAP 4430 | | MIPI | | | piranah | |
55 | 55 | Denis 'GNUtoo' Carikli | |
56 | h3. GPIOs usage |
||
57 | |||
58 | 65 | Denis 'GNUtoo' Carikli | TODO: make sure to mention what applies to what device |
59 | * Start with I9300. Assume I9300 if device is not mentioned. Mention device when not I9300 |
||
60 | * Add more devices and mention them |
||
61 | |||
62 | 55 | Denis 'GNUtoo' Carikli | |_. gpio platform data name |_. present |_. absent |_. Implementation |_. comments | |
63 | | gpio_cp_on | | | | powers on the modem? in which state (PMIC?, CPU?) |
||
64 | * On GT-I9100 it's connected to the ON1 modem pin and ON2 is not connected. | |
||
65 | | gpio_cp_reset | | | | Resets the modem CPU? PMIC?: |
||
66 | * "''check the reset timming with C2C connection''":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/drivers/misc/modem_if/modem_modemctl_device_xmm6262.c#n106 : Here C2C probably means chip to chip |
||
67 | Can also read the modem CPU? and/or PMIC? reset state? |
||
68 | * "Reads from the GPIO and ''CP not ready, Active State low'' comment":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/board-m0-modems.c#n287 | |
||
69 | | gpio_reset_req_n | | | | |
||
70 | | gpio_pda_active | | | | Tell the modem if the SOC CPUs are sleeping/active or not? |
||
71 | * "PDA == Application processor":https://android.stackexchange.com/questions/176515/what-do-the-terms-bl-ap-cp-and-csc-mean-in-odin |
||
72 | * "''PDA_ACTIVE, let cp know AP sleep'' comment in status gc1-gpio.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/gc1-gpio.c#n213 |
||
73 | * "PDA_ACTIVE set to 0 right after cpu_pm_enter()":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/cpuidle-exynos4.c#n701 |
||
74 | * "PDA_ACTIVE set to 1 right before cpu_pm_exit()":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/cpuidle-exynos4.c#n796 |
||
75 | * GPIO direction is output on AP side and input on BP side, which is also confirmed by the "pinout table in XDA":https://forum.xda-developers.com/galaxy-s2/help/how-to-talk-to-modem-commands-t1471241/page4 | |
||
76 | 88 | Denis 'GNUtoo' Carikli | | gpio_phone_active | | | | Seem the modem counterpart of gpio_pda_active: |
77 | * See "umts_link_reconnect in board-m0-modems.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/board-m0-modems.c#n341 | |
||
78 | 76 | Denis 'GNUtoo' Carikli | | gpio_cp_dump_int | | | | | |
79 | 55 | Denis 'GNUtoo' Carikli | | gpio_flm_uart_sel |\2. Only used for the Galaxy Nexus in libsamsung-ipc | | Modem download mode ? | |
80 | 76 | Denis 'GNUtoo' Carikli | | gpio_cp_warm_reset | | | | | |
81 | 55 | Denis 'GNUtoo' Carikli | | gpio_revers_bias_clear | | | | | |
82 | | gpio_revers_bias_restore | | | | | |
||
83 | | gpio_sim_detect | | | | Detect SIM card presence ? | |
||
84 | 47 | Denis 'GNUtoo' Carikli | |
85 | 53 | Denis 'GNUtoo' Carikli | h3. Libsamsung-ipc |
86 | 52 | Denis 'GNUtoo' Carikli | |
87 | 1 | Denis 'GNUtoo' Carikli | |/2. ioctl / function |\6. Devices | |
88 | 54 | Denis 'GNUtoo' Carikli | | GT-I9250 (maguro) | GT-I9100 | GT-I9300 | GT-N5100 | GT-N7100 | GT-P3100 / GT-P5100 (piranah) | |
89 | 52 | Denis 'GNUtoo' Carikli | | open, close, read, write |
90 | 1 | Denis 'GNUtoo' Carikli | fmt/rfs |
91 | gprs |
||
92 | 54 | Denis 'GNUtoo' Carikli | power |\6. Yes | |
93 | 52 | Denis 'GNUtoo' Carikli | | boot_power |
94 | 54 | Denis 'GNUtoo' Carikli | status_online_wait | Yes |\5. No | |
95 | 1 | Denis 'GNUtoo' Carikli | | hci_power |
96 | 52 | Denis 'GNUtoo' Carikli | link_control_enable |
97 | link_control_active |
||
98 | link_control_wait |
||
99 | 54 | Denis 'GNUtoo' Carikli | link_get_hostwake_wait | No |\4. Yes | No | |
100 | 52 | Denis 'GNUtoo' Carikli | |
101 | 66 | Denis 'GNUtoo' Carikli | TODO: |
102 | * Don't use abbreviated function names |
||
103 | |||
104 | 56 | Denis 'GNUtoo' Carikli | h3. libsamsung-ipc <-> kernel functions <-> gpios |
105 | 10 | Denis 'GNUtoo' Carikli | |
106 | 56 | Denis 'GNUtoo' Carikli | |_. libsamsung-ipc |_\3. Kernel | |
107 | 57 | Denis 'GNUtoo' Carikli | |_. Function using the ioctl |_. ioctl name |_. function pointer name |_. GPIO used | |
108 | | xmm626_kernel_smdk4412_power | IOCTL_MODEM_ON |
||
109 | IOCTL_MODEM_OFF | modem_on |
||
110 | modem_off | gpio_cp_on |
||
111 | gpio_cp_reset |
||
112 | gpio_reset_req_n |
||
113 | gpio_pda_active | |
||
114 | 56 | Denis 'GNUtoo' Carikli | | | | | gpio_phone_active | |
115 | | | | | gpio_cp_dump_int | |
||
116 | 36 | Denis 'GNUtoo' Carikli | | xmm626_kernel_smdk4412_boot_power | IOCTL_MODEM_BOOT_ON |
117 | 1 | Denis 'GNUtoo' Carikli | IOCTL_MODEM_BOOT_OFF | modem_boot_on |
118 | 56 | Denis 'GNUtoo' Carikli | modem_boot_off | gpio_flm_uart_sel | |
119 | | | | | gpio_cp_warm_reset | |
||
120 | | | | | gpio_revers_bias_clear | |
||
121 | | | | | gpio_revers_bias_restore | |
||
122 | | | | | gpio_sim_detect | |
||
123 | 44 | Denis 'GNUtoo' Carikli | |
124 | h3. Glossary |
||
125 | |||
126 | 72 | Denis 'GNUtoo' Carikli | Terms for the modem CPU: |
127 | 61 | Denis 'GNUtoo' Carikli | * BP: Baseband processor |
128 | * CP: Cellular? processor |
||
129 | 60 | Denis 'GNUtoo' Carikli | |
130 | 72 | Denis 'GNUtoo' Carikli | Term for the CPU of the system on a chip running Replicant: |
131 | 60 | Denis 'GNUtoo' Carikli | * AP: Application processor |
132 | 1 | Denis 'GNUtoo' Carikli | |
133 | 62 | Denis 'GNUtoo' Carikli | TODO: move in its own page and point to it |
134 | |||
135 | 16 | Denis 'GNUtoo' Carikli | h3. SIM card presence detection |
136 | 7 | Denis 'GNUtoo' Carikli | |
137 | Do we really want to check the SIM card presence? |
||
138 | |||
139 | Would it be possible not to for privacy reasons? |
||
140 | |||
141 | Example: |
||
142 | * Boot a modem with a SIM |
||
143 | * Take away the SIM card |
||
144 | 1 | Denis 'GNUtoo' Carikli | * Go to a protest with only the SIM card and a phone with no data on it to be able to call if necessary. |
145 | 7 | Denis 'GNUtoo' Carikli | |
146 | 16 | Denis 'GNUtoo' Carikli | h3. TODO |
147 | 1 | Denis 'GNUtoo' Carikli | |
148 | * check gpio_flm_uart_sel in smdk4412 kernel too |
||
149 | 16 | Denis 'GNUtoo' Carikli | |
150 | 82 | Denis 'GNUtoo' Carikli | h2. Potential privacy and security issues |
151 | |||
152 | 83 | Denis 'GNUtoo' Carikli | h3. gpio_pda_active |
153 | |||
154 | From "cpuidle-exynos4.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/cpuidle-exynos4.c#n701 we have things like that: |
||
155 | <pre> |
||
156 | cpu_pm_enter(); |
||
157 | |||
158 | #if defined(CONFIG_INTERNAL_MODEM_IF) || defined(CONFIG_SAMSUNG_PHONE_TTY) |
||
159 | gpio_set_value(GPIO_PDA_ACTIVE, 0); |
||
160 | #endif |
||
161 | |||
162 | if (log_en) |
||
163 | pr_debug("+++lpa\n") |
||
164 | </pre> |
||
165 | |||
166 | and: |
||
167 | <pre> |
||
168 | if (log_en) |
||
169 | pr_debug("---lpa\n"); |
||
170 | #if defined(CONFIG_INTERNAL_MODEM_IF) || defined(CONFIG_SAMSUNG_PHONE_TTY) |
||
171 | gpio_set_value(GPIO_PDA_ACTIVE, 1); |
||
172 | #endif |
||
173 | |||
174 | cpu_pm_exit(); |
||
175 | </pre> |
||
176 | 84 | Denis 'GNUtoo' Carikli | |
177 | 83 | Denis 'GNUtoo' Carikli | Does it means that we are telling the modem about each time we go in suspend to RAM? |
178 | 84 | Denis 'GNUtoo' Carikli | |
179 | 85 | Denis 'GNUtoo' Carikli | Devices affected or not affected: |
180 | |||
181 | 84 | Denis 'GNUtoo' Carikli | |_. Device |_. Config | |
182 | | GT-I9300 | "# CONFIG_INTERNAL_MODEM_IF is not set":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9300_defconfig#n1373 |
||
183 | "# CONFIG_SAMSUNG_PHONE_TTY is not set":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9300_defconfig#n3039 | |
||
184 | 83 | Denis 'GNUtoo' Carikli | |
185 | 82 | Denis 'GNUtoo' Carikli | h3. gpio_phone_active |
186 | |||
187 | From "ehci-s5p.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/drivers/usb/host/ehci-s5p.c#n129 we have things like that: |
||
188 | <pre> |
||
189 | #if defined(CONFIG_UMTS_MODEM_XMM6262) |
||
190 | if (pdata->get_cp_active_state && !pdata->get_cp_active_state()) { |
||
191 | s5p_ehci_port_control(pdev, CP_PORT, 0); |
||
192 | pr_err("mif: force port%d off by cp reset\n", CP_PORT); |
||
193 | } |
||
194 | #endif |
||
195 | </pre> |
||
196 | 86 | Denis 'GNUtoo' Carikli | |
197 | 82 | Denis 'GNUtoo' Carikli | Does it allows the modem to trigger a re-enumeration of the HSIC bus? |
198 | 86 | Denis 'GNUtoo' Carikli | |
199 | Devices affected or not affected: |
||
200 | |||
201 | |_. Device |_. Config | |
||
202 | 87 | Denis 'GNUtoo' Carikli | | GT-I9300 | "CONFIG_UMTS_MODEM_XMM6262=y":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/configs/lineageos_i9300_defconfig#n1350 |
203 | ".gpio_phone_active = GPIO_PHONE_ACTIVE":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/arch/arm/mach-exynos/board-m0-modems.c#n241 | |
||
204 | 82 | Denis 'GNUtoo' Carikli | |
205 | 16 | Denis 'GNUtoo' Carikli | h2. Modem partitions |
206 | |||
207 | 30 | Denis 'GNUtoo' Carikli | h3. GT-I9300, GT-N7100 |
208 | 3 | Denis 'GNUtoo' Carikli | |
209 | 19 | Denis 'GNUtoo' Carikli | |_. Location |_. Name |_. Content | |
210 | 71 | Denis 'GNUtoo' Carikli | | [ 0x0 -> 0xfff ] | ? | Partition table ? | |
211 | | [ 0x1000 -> 0xefff ] | PSIRAM | First stage bootloader ? | |
||
212 | 31 | Denis 'GNUtoo' Carikli | | [ 0xF000 -> 0x27fff ] | EBL | Second stage bootloader ? | |
213 | 29 | Denis 'GNUtoo' Carikli | | [ 0x28000 -> 0x9ff7ff ] | MAIN | ? | |
214 | 28 | Denis 'GNUtoo' Carikli | | [ 0x9ff800 -> 0x9fffff ] | SECPACK | ? | |
215 | 70 | Denis 'GNUtoo' Carikli | | [ 0xa00000 -> 0xbfffff ] | NV | nvdata default values? |
216 | TODO: find the place in libsamsung-ipc source mentioning that | |
||
217 | 1 | Denis 'GNUtoo' Carikli | |
218 | 31 | Denis 'GNUtoo' Carikli | References for the table: |
219 | * https://git.replicant.us/replicant/external_libsamsung-ipc/tree/samsung-ipc/devices/i9300/i9300.h?id=9ff9785a7f48e32f107ca7fb2e298b1320ad4cbc |
||
220 | * https://git.replicant.us/replicant/external_libsamsung-ipc/tree/samsung-ipc/devices/n7100/n7100.h?id=9ff9785a7f48e32f107ca7fb2e298b1320ad4cbc |
||
221 | * Verified on GT-I9300 and GT-N7100 modem partition table |
||
222 | 23 | Denis 'GNUtoo' Carikli | |
223 | 32 | Denis 'GNUtoo' Carikli | h4. GT-I9300 and GT-N7100 modem partition table dump |
224 | 23 | Denis 'GNUtoo' Carikli | |
225 | 68 | Denis 'GNUtoo' Carikli | TODO: |
226 | * Send patch for the "modem-partition-tool#n33":https://git.replicant.us/contrib/GNUtoo/hardware_replicant_libsamsung-ipc/tree/tools/modem-image-tool.c?h=patches-todo/modem-partition-tool#n33 |
||
227 | * Make sure that we know the device from the command line |
||
228 | * Understand the field depths along the way when supporting more devices |
||
229 | * Document all other devices that don't have this partition table |
||
230 | * Find the name of this partition table |
||
231 | |||
232 | 23 | Denis 'GNUtoo' Carikli | <pre> |
233 | 24 | Denis 'GNUtoo' Carikli | $ hexdump -C RADIO.img |
234 | 00000000 50 53 49 52 41 4d 00 00 00 00 00 00 00 10 00 00 |PSIRAM..........| |
||
235 | 00000010 00 00 00 00 00 e0 00 00 00 00 00 00 00 00 00 00 |................| |
||
236 | 00000020 45 42 4c 00 00 00 00 00 00 00 00 00 00 f0 00 00 |EBL.............| |
||
237 | 00000030 00 00 00 60 00 90 01 00 00 00 00 00 00 00 00 00 |...`............| |
||
238 | 00000040 4d 41 49 4e 00 00 00 00 00 00 00 00 00 80 02 00 |MAIN............| |
||
239 | 00000050 00 00 30 60 00 78 9d 00 00 00 00 00 00 00 00 00 |..0`.x..........| |
||
240 | 00000060 53 45 43 50 41 43 4b 00 00 00 00 00 00 f8 9f 00 |SECPACK.........| |
||
241 | 00000070 00 00 00 00 00 08 00 00 00 00 00 00 00 00 00 00 |................| |
||
242 | 00000080 4e 56 00 00 00 00 00 00 00 00 00 00 00 00 a0 00 |NV..............| |
||
243 | 00000090 00 00 e8 60 00 00 20 00 00 00 00 00 00 00 00 00 |...`.. .........| |
||
244 | 000000a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| |
||
245 | * |
||
246 | [...] |
||
247 | 1 | Denis 'GNUtoo' Carikli | </pre> |
248 | 32 | Denis 'GNUtoo' Carikli | |
249 | h3. Devices without a partition table or with a different one |
||
250 | |||
251 | 69 | Denis 'GNUtoo' Carikli | * GT-I9100, GT-I9250, GT-N7000, GT-P3100 |
252 | * Probably GT-P5100 as well, as it's similar to GT-P3100 |
||
253 | * All the devices with Qualcomm modems (GT-I9305, GT-N7105) |
||
254 | |||
255 | Unknown: |
||
256 | * Galaxy Note 8.0 |
||
257 | 17 | Denis 'GNUtoo' Carikli | |
258 | 1 | Denis 'GNUtoo' Carikli | h2. Links |
259 | |||
260 | 45 | Denis 'GNUtoo' Carikli | * "modem_modemctl_device_xmm6262.c":https://git.replicant.us/replicant/kernel_samsung_smdk4412/tree/drivers/misc/modem_if/modem_modemctl_device_xmm6262.c |
261 | 1 | Denis 'GNUtoo' Carikli | * https://forum.xda-developers.com/galaxy-s2/help/how-to-talk-to-modem-commands-t1471241/page4 |
262 | 45 | Denis 'GNUtoo' Carikli | * http://www.arteris.com/blog/bid/59433/Interchip-Connectivity-HSIC-UniPro-HSI-C2C-LLI-oh-my |
263 | 64 | Denis 'GNUtoo' Carikli | ** TODO: move this link somewhere where it's more useful |