mediatek: add UBI layout for TP-Link BE450
Add an OpenWrt U-Boot ("UBI") layout variant for the TP-Link Archer
BE450. It replaces the vendor bootloader and the stock dual-image
layout with a single large UBI partition, extending the usable flash
to around 95 MiB, and ships a current U-Boot with TFTP recovery.
Hardware
--------
SoC: MediaTek MT7988D (Filogic 880)
Wi-Fi: MediaTek MT7992AV (BE7200, 2.4/5 GHz)
Flash: 128 MiB SPI-NAND
RAM: 512 MiB DDR4
Serial: 115200 8N1, header located next to the heatsink:
heatsink
| |
| |
| | +----+-----+------+-------+ +-----------------+
| | | TX | RX | GND | +3.3V | | power connector |
+---+ +----+-----+------+-------+ +-----------------+
|
Don't connect ----+
MAC addresses
-------------
The label MAC (base) is stored in tp_data/default-mac and is written
into the factory partition at offset 0x4 during installation:
eth0 (LAN): base (factory 0x4)
eth1 (WAN): base + 1
eth2 (LAN): base + 2
Wi-Fi: derived by mt76 from the factory EEPROM (2.4 GHz = base,
5 GHz = base with bit 0x10 set), matching the stock
layout behaviour.
Installation
------------
Requires a serial connection and a TFTP server. The device must be
running the stock-layout OpenWrt (tplink_be450) build.
1. From the running stock-layout OpenWrt, back up the vendor
bootloader and the calibration/MAC data. These cannot be
recovered otherwise:
cat /dev/mtd0 > /tmp/boot.bin
cat /dev/mtd5 > /tmp/tp_data.bin
scp /tmp/boot.bin /tmp/tp_data.bin user@pc:backup/
scp -r /tmp/tp_data user@pc:backup/
Store boot.bin, tp_data.bin and the tp_data file contents
(MT7992_EEPROM.bin, default-mac) somewhere safe.
2. Boot the UBI-layout initramfs. Connect the PC to one of the LAN ports
(LAN1-3) and serve the recovery image from a TFTP server on the PC at
192.168.1.2. Interrupt the vendor U-Boot on the serial console
(Ctrl+C), then:
setenv serverip 192.168.1.2
tftpboot 0x50000000 openwrt-mediatek-filogic-tplink_be450-ubi-initramfs-recovery.itb
bootm 0x50000000
3. Copy the required files to the booted initramfs (192.168.1.1):
scp -O MT7992_EEPROM.bin default-mac \
openwrt-mediatek-filogic-tplink_be450-ubi-bl31-uboot.fip \
openwrt-mediatek-filogic-tplink_be450-ubi-preloader.bin \
openwrt-mediatek-filogic-tplink_be450-ubi-squashfs-sysupgrade.itb \
root@192.168.1.1:/tmp
4. Build the factory image from the EEPROM and MAC data:
cd /tmp
dd if=/dev/zero bs=$((0x100000)) count=1 | tr '\000' '\377' > factory.bin
dd if=MT7992_EEPROM.bin of=factory.bin bs=1 count=$((0x1e00)) conv=notrunc
dd if=default-mac of=factory.bin bs=1 seek=4 conv=notrunc
5. Create the UBI volumes. Warning: this permanently erases the
remaining vendor data, including tp_data - only proceed with the
backups from step 1 stored safely:
ubidetach -p /dev/mtd2
ubiformat /dev/mtd2 -y
ubiattach -p /dev/mtd2
ubimkvol /dev/ubi0 -N fip -t static -s 2MiB
ubiupdatevol /dev/ubi0_0 /tmp/openwrt-mediatek-filogic-tplink_be450-ubi-bl31-uboot.fip
ubimkvol /dev/ubi0 -N ubootenv -s 0x1f000
ubimkvol /dev/ubi0 -N ubootenv2 -s 0x1f000
6. Write the factory data and the BL2 preloader. kmod-mtd-rw is
required to lift the read-only protection of the bl2 partition;
set up internet access first or upload the package manually:
apk update && apk add kmod-mtd-rw
insmod mtd-rw i_want_a_brick=1
mtd erase factory
mtd write /tmp/factory.bin factory
mtd erase bl2
mtd write /tmp/openwrt-mediatek-filogic-tplink_be450-ubi-preloader.bin bl2
7. Flash the system:
sysupgrade -n /tmp/openwrt-mediatek-filogic-tplink_be450-ubi-squashfs-sysupgrade.itb
Revert to stock firmware
------------------------
1. From the UBI-layout OpenWrt, force-flash the stock-layout OpenWrt
(tplink_be450) initramfs image; the board name differs, so
sysupgrade must be forced:
sysupgrade -F -n openwrt-mediatek-filogic-tplink_be450-initramfs-kernel.bin
2. After booting into that initramfs, set up network access, copy
boot.bin and tp_data.bin from the backup to /tmp and restore the
vendor bootloader and data:
apk update && apk add kmod-mtd-rw
insmod mtd-rw i_want_a_brick=1
mtd erase boot
mtd write /tmp/boot.bin boot
mtd erase ubi0
mtd erase ubi1
mtd erase userconfig
mtd erase tp_data
mtd write /tmp/tp_data.bin tp_data
3. Verify the tp_data restore before rebooting - without it the
device has no ethernet:
md5sum /tmp/tp_data.bin
md5sum /dev/mtd5
If the checksums match, reboot. The vendor U-Boot web recovery
comes up on 192.168.1.1; flash the TP-Link stock firmware from
there.
Signed-off-by: Emre Yavuzalp <emreyavuzalp2@gmail.com>
Link: https://github.com/openwrt/openwrt/pull/23211
Signed-off-by: Jonas Jelonek <jelonek.jonas@gmail.com>