1 // SPDX-License-Identifier: BSD-2-Clause
3 Copyright (c) 2014, Matthias Schiffer <mschiffer@universe-factory.net>
11 Image generation tool for the TP-LINK SafeLoader as seen on
12 TP-LINK Pharos devices (CPE210/220/510/520)
28 #include <arpa/inet.h>
30 #include <sys/types.h>
37 #define ALIGN(x,a) ({ typeof(a) __a = (a); (((x) + __a - 1) & ~(__a - 1)); })
40 #define MAX_PARTITIONS 32
42 /** An image partition table entry */
43 struct image_partition_entry
{
49 /** A flash partition table entry */
50 struct flash_partition_entry
{
56 /** Partition trailing padding definitions
57 * Values 0x00 to 0xff are reserved to indicate the padding value
58 * Values from 0x100 are reserved to indicate other behaviour */
59 enum partition_trail_value
{
62 PART_TRAIL_MAX
= 0xff,
63 PART_TRAIL_NONE
= 0x100
66 /** Firmware layout description */
70 const char *support_list
;
71 enum partition_trail_value part_trail
;
73 uint32_t soft_ver_compat_level
;
74 struct flash_partition_entry partitions
[MAX_PARTITIONS
+1];
75 const char *first_sysupgrade_partition
;
76 const char *last_sysupgrade_partition
;
79 struct __attribute__((__packed__
)) meta_header
{
84 /** The content of the soft-version structure */
85 struct __attribute__((__packed__
)) soft_version
{
87 uint8_t version_major
;
88 uint8_t version_minor
;
89 uint8_t version_patch
;
95 uint32_t compat_level
;
99 static const uint8_t jffs2_eof_mark
[4] = {0xde, 0xad, 0xc0, 0xde};
103 Salt for the MD5 hash
105 Fortunately, TP-LINK seems to use the same salt for most devices which use
106 the new image format.
108 static const uint8_t md5_salt
[16] = {
109 0x7a, 0x2b, 0x15, 0xed,
110 0x9b, 0x98, 0x59, 0x6d,
111 0xe5, 0x04, 0xab, 0x44,
112 0xac, 0x2a, 0x9f, 0x4e,
116 /** Firmware layout table */
117 static struct device_info boards
[] = {
118 /** Firmware layout for the CPE210/220 V1 */
121 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
124 "CPE210(TP-LINK|UN|N300-2):1.0\r\n"
125 "CPE210(TP-LINK|UN|N300-2):1.1\r\n"
126 "CPE210(TP-LINK|US|N300-2):1.1\r\n"
127 "CPE210(TP-LINK|EU|N300-2):1.1\r\n"
128 "CPE220(TP-LINK|UN|N300-2):1.1\r\n"
129 "CPE220(TP-LINK|US|N300-2):1.1\r\n"
130 "CPE220(TP-LINK|EU|N300-2):1.1\r\n",
135 {"fs-uboot", 0x00000, 0x20000},
136 {"partition-table", 0x20000, 0x02000},
137 {"default-mac", 0x30000, 0x00020},
138 {"product-info", 0x31100, 0x00100},
139 {"signature", 0x32000, 0x00400},
140 {"firmware", 0x40000, 0x770000},
141 {"soft-version", 0x7b0000, 0x00100},
142 {"support-list", 0x7b1000, 0x00400},
143 {"user-config", 0x7c0000, 0x10000},
144 {"default-config", 0x7d0000, 0x10000},
145 {"log", 0x7e0000, 0x10000},
146 {"radio", 0x7f0000, 0x10000},
150 .first_sysupgrade_partition
= "os-image",
151 .last_sysupgrade_partition
= "support-list",
154 /** Firmware layout for the CPE210 V2 */
157 .vendor
= "CPE210(TP-LINK|UN|N300-2|00000000):2.0\r\n",
160 "CPE210(TP-LINK|EU|N300-2|00000000):2.0\r\n"
161 "CPE210(TP-LINK|EU|N300-2|45550000):2.0\r\n"
162 "CPE210(TP-LINK|EU|N300-2|55530000):2.0\r\n"
163 "CPE210(TP-LINK|UN|N300-2|00000000):2.0\r\n"
164 "CPE210(TP-LINK|UN|N300-2|45550000):2.0\r\n"
165 "CPE210(TP-LINK|UN|N300-2|55530000):2.0\r\n"
166 "CPE210(TP-LINK|US|N300-2|55530000):2.0\r\n"
167 "CPE210(TP-LINK|UN|N300-2):2.0\r\n"
168 "CPE210(TP-LINK|EU|N300-2):2.0\r\n"
169 "CPE210(TP-LINK|US|N300-2):2.0\r\n",
174 {"fs-uboot", 0x00000, 0x20000},
175 {"partition-table", 0x20000, 0x02000},
176 {"default-mac", 0x30000, 0x00020},
177 {"product-info", 0x31100, 0x00100},
178 {"device-info", 0x31400, 0x00400},
179 {"signature", 0x32000, 0x00400},
180 {"device-id", 0x33000, 0x00100},
181 {"firmware", 0x40000, 0x770000},
182 {"soft-version", 0x7b0000, 0x00100},
183 {"support-list", 0x7b1000, 0x01000},
184 {"user-config", 0x7c0000, 0x10000},
185 {"default-config", 0x7d0000, 0x10000},
186 {"log", 0x7e0000, 0x10000},
187 {"radio", 0x7f0000, 0x10000},
191 .first_sysupgrade_partition
= "os-image",
192 .last_sysupgrade_partition
= "support-list",
195 /** Firmware layout for the CPE210 V3 */
198 .vendor
= "CPE210(TP-LINK|UN|N300-2|00000000):3.0\r\n",
201 "CPE210(TP-LINK|EU|N300-2|45550000):3.0\r\n"
202 "CPE210(TP-LINK|UN|N300-2|00000000):3.0\r\n"
203 "CPE210(TP-LINK|US|N300-2|55530000):3.0\r\n"
204 "CPE210(TP-LINK|UN|N300-2):3.0\r\n"
205 "CPE210(TP-LINK|EU|N300-2):3.0\r\n"
206 "CPE210(TP-LINK|EU|N300-2|45550000):3.1\r\n"
207 "CPE210(TP-LINK|UN|N300-2|00000000):3.1\r\n"
208 "CPE210(TP-LINK|US|N300-2|55530000):3.1\r\n"
209 "CPE210(TP-LINK|EU|N300-2|45550000):3.20\r\n"
210 "CPE210(TP-LINK|UN|N300-2|00000000):3.20\r\n"
211 "CPE210(TP-LINK|US|N300-2|55530000):3.20\r\n",
216 {"fs-uboot", 0x00000, 0x20000},
217 {"partition-table", 0x20000, 0x01000},
218 {"default-mac", 0x30000, 0x00020},
219 {"product-info", 0x31100, 0x00100},
220 {"device-info", 0x31400, 0x00400},
221 {"signature", 0x32000, 0x00400},
222 {"device-id", 0x33000, 0x00100},
223 {"firmware", 0x40000, 0x770000},
224 {"soft-version", 0x7b0000, 0x00100},
225 {"support-list", 0x7b1000, 0x01000},
226 {"user-config", 0x7c0000, 0x10000},
227 {"default-config", 0x7d0000, 0x10000},
228 {"log", 0x7e0000, 0x10000},
229 {"radio", 0x7f0000, 0x10000},
233 .first_sysupgrade_partition
= "os-image",
234 .last_sysupgrade_partition
= "support-list",
237 /** Firmware layout for the CPE220 V2 */
240 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
243 "CPE220(TP-LINK|EU|N300-2|00000000):2.0\r\n"
244 "CPE220(TP-LINK|EU|N300-2|45550000):2.0\r\n"
245 "CPE220(TP-LINK|EU|N300-2|55530000):2.0\r\n"
246 "CPE220(TP-LINK|UN|N300-2|00000000):2.0\r\n"
247 "CPE220(TP-LINK|UN|N300-2|45550000):2.0\r\n"
248 "CPE220(TP-LINK|UN|N300-2|55530000):2.0\r\n"
249 "CPE220(TP-LINK|US|N300-2|55530000):2.0\r\n"
250 "CPE220(TP-LINK|UN|N300-2):2.0\r\n"
251 "CPE220(TP-LINK|EU|N300-2):2.0\r\n"
252 "CPE220(TP-LINK|US|N300-2):2.0\r\n",
257 {"fs-uboot", 0x00000, 0x20000},
258 {"partition-table", 0x20000, 0x02000},
259 {"default-mac", 0x30000, 0x00020},
260 {"product-info", 0x31100, 0x00100},
261 {"signature", 0x32000, 0x00400},
262 {"firmware", 0x40000, 0x770000},
263 {"soft-version", 0x7b0000, 0x00100},
264 {"support-list", 0x7b1000, 0x00400},
265 {"user-config", 0x7c0000, 0x10000},
266 {"default-config", 0x7d0000, 0x10000},
267 {"log", 0x7e0000, 0x10000},
268 {"radio", 0x7f0000, 0x10000},
272 .first_sysupgrade_partition
= "os-image",
273 .last_sysupgrade_partition
= "support-list",
276 /** Firmware layout for the CPE220 V3 */
279 .vendor
= "CPE220(TP-LINK|UN|N300-2|00000000):3.0\r\n",
282 "CPE220(TP-LINK|EU|N300-2|00000000):3.0\r\n"
283 "CPE220(TP-LINK|EU|N300-2|45550000):3.0\r\n"
284 "CPE220(TP-LINK|EU|N300-2|55530000):3.0\r\n"
285 "CPE220(TP-LINK|UN|N300-2|00000000):3.0\r\n"
286 "CPE220(TP-LINK|UN|N300-2|45550000):3.0\r\n"
287 "CPE220(TP-LINK|UN|N300-2|55530000):3.0\r\n"
288 "CPE220(TP-LINK|US|N300-2|55530000):3.0\r\n"
289 "CPE220(TP-LINK|UN|N300-2):3.0\r\n"
290 "CPE220(TP-LINK|EU|N300-2):3.0\r\n"
291 "CPE220(TP-LINK|US|N300-2):3.0\r\n",
296 {"fs-uboot", 0x00000, 0x20000},
297 {"partition-table", 0x20000, 0x02000},
298 {"default-mac", 0x30000, 0x00020},
299 {"product-info", 0x31100, 0x00100},
300 {"device-info", 0x31400, 0x00400},
301 {"signature", 0x32000, 0x00400},
302 {"device-id", 0x33000, 0x00100},
303 {"firmware", 0x40000, 0x770000},
304 {"soft-version", 0x7b0000, 0x00100},
305 {"support-list", 0x7b1000, 0x01000},
306 {"user-config", 0x7c0000, 0x10000},
307 {"default-config", 0x7d0000, 0x10000},
308 {"log", 0x7e0000, 0x10000},
309 {"radio", 0x7f0000, 0x10000},
313 .first_sysupgrade_partition
= "os-image",
314 .last_sysupgrade_partition
= "support-list",
317 /** Firmware layout for the CPE510/520 V1 */
320 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
323 "CPE510(TP-LINK|UN|N300-5):1.0\r\n"
324 "CPE510(TP-LINK|UN|N300-5):1.1\r\n"
325 "CPE510(TP-LINK|UN|N300-5):1.1\r\n"
326 "CPE510(TP-LINK|US|N300-5):1.1\r\n"
327 "CPE510(TP-LINK|EU|N300-5):1.1\r\n"
328 "CPE520(TP-LINK|UN|N300-5):1.1\r\n"
329 "CPE520(TP-LINK|US|N300-5):1.1\r\n"
330 "CPE520(TP-LINK|EU|N300-5):1.1\r\n",
335 {"fs-uboot", 0x00000, 0x20000},
336 {"partition-table", 0x20000, 0x02000},
337 {"default-mac", 0x30000, 0x00020},
338 {"product-info", 0x31100, 0x00100},
339 {"signature", 0x32000, 0x00400},
340 {"firmware", 0x40000, 0x770000},
341 {"soft-version", 0x7b0000, 0x00100},
342 {"support-list", 0x7b1000, 0x00400},
343 {"user-config", 0x7c0000, 0x10000},
344 {"default-config", 0x7d0000, 0x10000},
345 {"log", 0x7e0000, 0x10000},
346 {"radio", 0x7f0000, 0x10000},
350 .first_sysupgrade_partition
= "os-image",
351 .last_sysupgrade_partition
= "support-list",
354 /** Firmware layout for the CPE510 V2 */
357 .vendor
= "CPE510(TP-LINK|UN|N300-5):2.0\r\n",
360 "CPE510(TP-LINK|EU|N300-5|00000000):2.0\r\n"
361 "CPE510(TP-LINK|EU|N300-5|45550000):2.0\r\n"
362 "CPE510(TP-LINK|EU|N300-5|55530000):2.0\r\n"
363 "CPE510(TP-LINK|UN|N300-5|00000000):2.0\r\n"
364 "CPE510(TP-LINK|UN|N300-5|45550000):2.0\r\n"
365 "CPE510(TP-LINK|UN|N300-5|55530000):2.0\r\n"
366 "CPE510(TP-LINK|US|N300-5|00000000):2.0\r\n"
367 "CPE510(TP-LINK|US|N300-5|45550000):2.0\r\n"
368 "CPE510(TP-LINK|US|N300-5|55530000):2.0\r\n"
369 "CPE510(TP-LINK|UN|N300-5):2.0\r\n"
370 "CPE510(TP-LINK|EU|N300-5):2.0\r\n"
371 "CPE510(TP-LINK|US|N300-5):2.0\r\n",
376 {"fs-uboot", 0x00000, 0x20000},
377 {"partition-table", 0x20000, 0x02000},
378 {"default-mac", 0x30000, 0x00020},
379 {"product-info", 0x31100, 0x00100},
380 {"signature", 0x32000, 0x00400},
381 {"firmware", 0x40000, 0x770000},
382 {"soft-version", 0x7b0000, 0x00100},
383 {"support-list", 0x7b1000, 0x00400},
384 {"user-config", 0x7c0000, 0x10000},
385 {"default-config", 0x7d0000, 0x10000},
386 {"log", 0x7e0000, 0x10000},
387 {"radio", 0x7f0000, 0x10000},
391 .first_sysupgrade_partition
= "os-image",
392 .last_sysupgrade_partition
= "support-list",
395 /** Firmware layout for the CPE510 V3 */
398 .vendor
= "CPE510(TP-LINK|UN|N300-5):3.0\r\n",
401 "CPE510(TP-LINK|EU|N300-5|00000000):3.0\r\n"
402 "CPE510(TP-LINK|EU|N300-5|45550000):3.0\r\n"
403 "CPE510(TP-LINK|EU|N300-5|55530000):3.0\r\n"
404 "CPE510(TP-LINK|UN|N300-5|00000000):3.0\r\n"
405 "CPE510(TP-LINK|UN|N300-5|45550000):3.0\r\n"
406 "CPE510(TP-LINK|UN|N300-5|55530000):3.0\r\n"
407 "CPE510(TP-LINK|US|N300-5|00000000):3.0\r\n"
408 "CPE510(TP-LINK|US|N300-5|45550000):3.0\r\n"
409 "CPE510(TP-LINK|US|N300-5|55530000):3.0\r\n"
410 "CPE510(TP-LINK|UN|N300-5):3.0\r\n"
411 "CPE510(TP-LINK|EU|N300-5):3.0\r\n"
412 "CPE510(TP-LINK|US|N300-5):3.0\r\n"
413 "CPE510(TP-LINK|UN|N300-5|00000000):3.20\r\n"
414 "CPE510(TP-LINK|US|N300-5|55530000):3.20\r\n"
415 "CPE510(TP-LINK|EU|N300-5|45550000):3.20\r\n",
420 {"fs-uboot", 0x00000, 0x20000},
421 {"partition-table", 0x20000, 0x02000},
422 {"default-mac", 0x30000, 0x00020},
423 {"product-info", 0x31100, 0x00100},
424 {"signature", 0x32000, 0x00400},
425 {"firmware", 0x40000, 0x770000},
426 {"soft-version", 0x7b0000, 0x00100},
427 {"support-list", 0x7b1000, 0x00400},
428 {"user-config", 0x7c0000, 0x10000},
429 {"default-config", 0x7d0000, 0x10000},
430 {"log", 0x7e0000, 0x10000},
431 {"radio", 0x7f0000, 0x10000},
435 .first_sysupgrade_partition
= "os-image",
436 .last_sysupgrade_partition
= "support-list",
439 /** Firmware layout for the CPE610V1 */
442 .vendor
= "CPE610(TP-LINK|UN|N300-5|00000000):1.0\r\n",
445 "CPE610(TP-LINK|EU|N300-5|00000000):1.0\r\n"
446 "CPE610(TP-LINK|EU|N300-5|45550000):1.0\r\n"
447 "CPE610(TP-LINK|EU|N300-5|55530000):1.0\r\n"
448 "CPE610(TP-LINK|UN|N300-5|00000000):1.0\r\n"
449 "CPE610(TP-LINK|UN|N300-5|45550000):1.0\r\n"
450 "CPE610(TP-LINK|UN|N300-5|55530000):1.0\r\n"
451 "CPE610(TP-LINK|US|N300-5|55530000):1.0\r\n"
452 "CPE610(TP-LINK|UN|N300-5):1.0\r\n"
453 "CPE610(TP-LINK|EU|N300-5):1.0\r\n"
454 "CPE610(TP-LINK|US|N300-5):1.0\r\n",
459 {"fs-uboot", 0x00000, 0x20000},
460 {"partition-table", 0x20000, 0x02000},
461 {"default-mac", 0x30000, 0x00020},
462 {"product-info", 0x31100, 0x00100},
463 {"signature", 0x32000, 0x00400},
464 {"firmware", 0x40000, 0x770000},
465 {"soft-version", 0x7b0000, 0x00100},
466 {"support-list", 0x7b1000, 0x00400},
467 {"user-config", 0x7c0000, 0x10000},
468 {"default-config", 0x7d0000, 0x10000},
469 {"log", 0x7e0000, 0x10000},
470 {"radio", 0x7f0000, 0x10000},
474 .first_sysupgrade_partition
= "os-image",
475 .last_sysupgrade_partition
= "support-list",
478 /** Firmware layout for the CPE610V2 */
481 .vendor
= "CPE610(TP-LINK|UN|N300-5|00000000):2.0\r\n",
484 "CPE610(TP-LINK|EU|N300-5|00000000):2.0\r\n"
485 "CPE610(TP-LINK|EU|N300-5|45550000):2.0\r\n"
486 "CPE610(TP-LINK|EU|N300-5|55530000):2.0\r\n"
487 "CPE610(TP-LINK|UN|N300-5|00000000):2.0\r\n"
488 "CPE610(TP-LINK|UN|N300-5|45550000):2.0\r\n"
489 "CPE610(TP-LINK|UN|N300-5|55530000):2.0\r\n"
490 "CPE610(TP-LINK|US|N300-5|55530000):2.0\r\n"
491 "CPE610(TP-LINK|UN|N300-5):2.0\r\n"
492 "CPE610(TP-LINK|EU|N300-5):2.0\r\n"
493 "CPE610(TP-LINK|US|N300-5):2.0\r\n",
498 {"fs-uboot", 0x00000, 0x20000},
499 {"partition-table", 0x20000, 0x02000},
500 {"default-mac", 0x30000, 0x00020},
501 {"product-info", 0x31100, 0x00100},
502 {"signature", 0x32000, 0x00400},
503 {"firmware", 0x40000, 0x770000},
504 {"soft-version", 0x7b0000, 0x00100},
505 {"support-list", 0x7b1000, 0x00400},
506 {"user-config", 0x7c0000, 0x10000},
507 {"default-config", 0x7d0000, 0x10000},
508 {"log", 0x7e0000, 0x10000},
509 {"radio", 0x7f0000, 0x10000},
513 .first_sysupgrade_partition
= "os-image",
514 .last_sysupgrade_partition
= "support-list",
519 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
522 "WBS210(TP-LINK|UN|N300-2):1.20\r\n"
523 "WBS210(TP-LINK|US|N300-2):1.20\r\n"
524 "WBS210(TP-LINK|EU|N300-2):1.20\r\n",
529 {"fs-uboot", 0x00000, 0x20000},
530 {"partition-table", 0x20000, 0x02000},
531 {"default-mac", 0x30000, 0x00020},
532 {"product-info", 0x31100, 0x00100},
533 {"signature", 0x32000, 0x00400},
534 {"firmware", 0x40000, 0x770000},
535 {"soft-version", 0x7b0000, 0x00100},
536 {"support-list", 0x7b1000, 0x00400},
537 {"user-config", 0x7c0000, 0x10000},
538 {"default-config", 0x7d0000, 0x10000},
539 {"log", 0x7e0000, 0x10000},
540 {"radio", 0x7f0000, 0x10000},
544 .first_sysupgrade_partition
= "os-image",
545 .last_sysupgrade_partition
= "support-list",
550 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
553 "WBS210(TP-LINK|UN|N300-2|00000000):2.0\r\n"
554 "WBS210(TP-LINK|US|N300-2|55530000):2.0\r\n"
555 "WBS210(TP-LINK|EU|N300-2|45550000):2.0\r\n",
560 {"fs-uboot", 0x00000, 0x20000},
561 {"partition-table", 0x20000, 0x02000},
562 {"default-mac", 0x30000, 0x00020},
563 {"product-info", 0x31100, 0x00100},
564 {"signature", 0x32000, 0x00400},
565 {"firmware", 0x40000, 0x770000},
566 {"soft-version", 0x7b0000, 0x00100},
567 {"support-list", 0x7b1000, 0x00400},
568 {"user-config", 0x7c0000, 0x10000},
569 {"default-config", 0x7d0000, 0x10000},
570 {"log", 0x7e0000, 0x10000},
571 {"radio", 0x7f0000, 0x10000},
575 .first_sysupgrade_partition
= "os-image",
576 .last_sysupgrade_partition
= "support-list",
581 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
584 "WBS510(TP-LINK|UN|N300-5):1.20\r\n"
585 "WBS510(TP-LINK|US|N300-5):1.20\r\n"
586 "WBS510(TP-LINK|EU|N300-5):1.20\r\n"
587 "WBS510(TP-LINK|CA|N300-5):1.20\r\n",
592 {"fs-uboot", 0x00000, 0x20000},
593 {"partition-table", 0x20000, 0x02000},
594 {"default-mac", 0x30000, 0x00020},
595 {"product-info", 0x31100, 0x00100},
596 {"signature", 0x32000, 0x00400},
597 {"firmware", 0x40000, 0x770000},
598 {"soft-version", 0x7b0000, 0x00100},
599 {"support-list", 0x7b1000, 0x00400},
600 {"user-config", 0x7c0000, 0x10000},
601 {"default-config", 0x7d0000, 0x10000},
602 {"log", 0x7e0000, 0x10000},
603 {"radio", 0x7f0000, 0x10000},
607 .first_sysupgrade_partition
= "os-image",
608 .last_sysupgrade_partition
= "support-list",
613 .vendor
= "CPE510(TP-LINK|UN|N300-5):1.0\r\n",
616 "WBS510(TP-LINK|UN|N300-5|00000000):2.0\r\n"
617 "WBS510(TP-LINK|US|N300-5|55530000):2.0\r\n"
618 "WBS510(TP-LINK|EU|N300-5|45550000):2.0\r\n"
619 "WBS510(TP-LINK|CA|N300-5|43410000):2.0\r\n",
624 {"fs-uboot", 0x00000, 0x20000},
625 {"partition-table", 0x20000, 0x02000},
626 {"default-mac", 0x30000, 0x00020},
627 {"product-info", 0x31100, 0x00100},
628 {"signature", 0x32000, 0x00400},
629 {"firmware", 0x40000, 0x770000},
630 {"soft-version", 0x7b0000, 0x00100},
631 {"support-list", 0x7b1000, 0x00400},
632 {"user-config", 0x7c0000, 0x10000},
633 {"default-config", 0x7d0000, 0x10000},
634 {"log", 0x7e0000, 0x10000},
635 {"radio", 0x7f0000, 0x10000},
639 .first_sysupgrade_partition
= "os-image",
640 .last_sysupgrade_partition
= "support-list",
643 /** Firmware layout for the AD7200 */
649 "{product_name:AD7200,product_ver:1.0.0,special_id:00000000}\r\n",
654 {"SBL1", 0x00000, 0x20000},
655 {"MIBIB", 0x20000, 0x20000},
656 {"SBL2", 0x40000, 0x20000},
657 {"SBL3", 0x60000, 0x30000},
658 {"DDRCONFIG", 0x90000, 0x10000},
659 {"SSD", 0xa0000, 0x10000},
660 {"TZ", 0xb0000, 0x30000},
661 {"RPM", 0xe0000, 0x20000},
662 {"fs-uboot", 0x100000, 0x70000},
663 {"uboot-env", 0x170000, 0x40000},
664 {"radio", 0x1b0000, 0x40000},
665 {"os-image", 0x1f0000, 0x400000},
666 {"file-system", 0x5f0000, 0x1900000},
667 {"default-mac", 0x1ef0000, 0x00200},
668 {"pin", 0x1ef0200, 0x00200},
669 {"device-id", 0x1ef0400, 0x00200},
670 {"product-info", 0x1ef0600, 0x0fa00},
671 {"partition-table", 0x1f00000, 0x10000},
672 {"soft-version", 0x1f10000, 0x10000},
673 {"support-list", 0x1f20000, 0x10000},
674 {"profile", 0x1f30000, 0x10000},
675 {"default-config", 0x1f40000, 0x10000},
676 {"user-config", 0x1f50000, 0x40000},
677 {"qos-db", 0x1f90000, 0x40000},
678 {"usb-config", 0x1fd0000, 0x10000},
679 {"log", 0x1fe0000, 0x20000},
683 .first_sysupgrade_partition
= "os-image",
684 .last_sysupgrade_partition
= "file-system"
687 /** Firmware layout for the C2600 */
693 "{product_name:Archer C2600,product_ver:1.0.0,special_id:00000000}\r\n",
698 We use a bigger os-image partition than the stock images (and thus
699 smaller file-system), as our kernel doesn't fit in the stock firmware's
700 2 MB os-image since kernel 4.14.
703 {"SBL1", 0x00000, 0x20000},
704 {"MIBIB", 0x20000, 0x20000},
705 {"SBL2", 0x40000, 0x20000},
706 {"SBL3", 0x60000, 0x30000},
707 {"DDRCONFIG", 0x90000, 0x10000},
708 {"SSD", 0xa0000, 0x10000},
709 {"TZ", 0xb0000, 0x30000},
710 {"RPM", 0xe0000, 0x20000},
711 {"fs-uboot", 0x100000, 0x70000},
712 {"uboot-env", 0x170000, 0x40000},
713 {"radio", 0x1b0000, 0x40000},
714 {"os-image", 0x1f0000, 0x400000}, /* Stock: base 0x1f0000 size 0x200000 */
715 {"file-system", 0x5f0000, 0x1900000}, /* Stock: base 0x3f0000 size 0x1b00000 */
716 {"default-mac", 0x1ef0000, 0x00200},
717 {"pin", 0x1ef0200, 0x00200},
718 {"product-info", 0x1ef0400, 0x0fc00},
719 {"partition-table", 0x1f00000, 0x10000},
720 {"soft-version", 0x1f10000, 0x10000},
721 {"support-list", 0x1f20000, 0x10000},
722 {"profile", 0x1f30000, 0x10000},
723 {"default-config", 0x1f40000, 0x10000},
724 {"user-config", 0x1f50000, 0x40000},
725 {"qos-db", 0x1f90000, 0x40000},
726 {"usb-config", 0x1fd0000, 0x10000},
727 {"log", 0x1fe0000, 0x20000},
731 .first_sysupgrade_partition
= "os-image",
732 .last_sysupgrade_partition
= "file-system"
735 /** Firmware layout for the A7-V5 */
737 .id
= "ARCHER-A7-V5",
740 "{product_name:Archer A7,product_ver:5.0.0,special_id:45550000}\n"
741 "{product_name:Archer A7,product_ver:5.0.0,special_id:55530000}\n"
742 "{product_name:Archer A7,product_ver:5.0.0,special_id:43410000}\n"
743 "{product_name:Archer A7,product_ver:5.0.0,special_id:4A500000}\n"
744 "{product_name:Archer A7,product_ver:5.0.0,special_id:54570000}\n"
745 "{product_name:Archer A7,product_ver:5.0.0,special_id:52550000}\n",
747 .soft_ver
= "soft_ver:1.0.0\n",
749 /* We're using a dynamic kernel/rootfs split here */
751 {"factory-boot", 0x00000, 0x20000},
752 {"fs-uboot", 0x20000, 0x20000},
753 {"firmware", 0x40000, 0xec0000}, /* Stock: name os-image base 0x40000 size 0x120000 */
754 /* Stock: name file-system base 0x160000 size 0xda0000 */
755 {"default-mac", 0xf40000, 0x00200},
756 {"pin", 0xf40200, 0x00200},
757 {"device-id", 0xf40400, 0x00100},
758 {"product-info", 0xf40500, 0x0fb00},
759 {"soft-version", 0xf50000, 0x00100},
760 {"extra-para", 0xf51000, 0x01000},
761 {"support-list", 0xf52000, 0x0a000},
762 {"profile", 0xf5c000, 0x04000},
763 {"default-config", 0xf60000, 0x10000},
764 {"user-config", 0xf70000, 0x40000},
765 {"certificate", 0xfb0000, 0x10000},
766 {"partition-table", 0xfc0000, 0x10000},
767 {"log", 0xfd0000, 0x20000},
768 {"radio", 0xff0000, 0x10000},
772 .first_sysupgrade_partition
= "os-image",
773 .last_sysupgrade_partition
= "file-system",
776 /** Firmware layout for the C2v3 */
778 .id
= "ARCHER-C2-V3",
781 "{product_name:ArcherC2,product_ver:3.0.0,special_id:00000000}\n"
782 "{product_name:ArcherC2,product_ver:3.0.0,special_id:55530000}\n"
783 "{product_name:ArcherC2,product_ver:3.0.0,special_id:45550000}\n",
785 .soft_ver
= "soft_ver:3.0.1\n",
787 /** We're using a dynamic kernel/rootfs split here */
790 {"factory-boot", 0x00000, 0x20000},
791 {"fs-uboot", 0x20000, 0x10000},
792 {"firmware", 0x30000, 0x7a0000},
793 {"user-config", 0x7d0000, 0x04000},
794 {"default-mac", 0x7e0000, 0x00100},
795 {"device-id", 0x7e0100, 0x00100},
796 {"extra-para", 0x7e0200, 0x00100},
797 {"pin", 0x7e0300, 0x00100},
798 {"support-list", 0x7e0400, 0x00400},
799 {"soft-version", 0x7e0800, 0x00400},
800 {"product-info", 0x7e0c00, 0x01400},
801 {"partition-table", 0x7e2000, 0x01000},
802 {"profile", 0x7e3000, 0x01000},
803 {"default-config", 0x7e4000, 0x04000},
804 {"merge-config", 0x7ec000, 0x02000},
805 {"qos-db", 0x7ee000, 0x02000},
806 {"radio", 0x7f0000, 0x10000},
810 .first_sysupgrade_partition
= "os-image",
811 .last_sysupgrade_partition
= "file-system",
814 /** Firmware layout for the C25v1 */
816 .id
= "ARCHER-C25-V1",
819 "{product_name:ArcherC25,product_ver:1.0.0,special_id:00000000}\n"
820 "{product_name:ArcherC25,product_ver:1.0.0,special_id:55530000}\n"
821 "{product_name:ArcherC25,product_ver:1.0.0,special_id:45550000}\n",
823 .soft_ver
= "soft_ver:1.0.0\n",
825 /* We're using a dynamic kernel/rootfs split here */
827 {"factory-boot", 0x00000, 0x20000},
828 {"fs-uboot", 0x20000, 0x10000},
829 {"firmware", 0x30000, 0x7a0000}, /* Stock: name os-image base 0x30000 size 0x100000 */
830 /* Stock: name file-system base 0x130000 size 0x6a0000 */
831 {"user-config", 0x7d0000, 0x04000},
832 {"default-mac", 0x7e0000, 0x00100},
833 {"device-id", 0x7e0100, 0x00100},
834 {"extra-para", 0x7e0200, 0x00100},
835 {"pin", 0x7e0300, 0x00100},
836 {"support-list", 0x7e0400, 0x00400},
837 {"soft-version", 0x7e0800, 0x00400},
838 {"product-info", 0x7e0c00, 0x01400},
839 {"partition-table", 0x7e2000, 0x01000},
840 {"profile", 0x7e3000, 0x01000},
841 {"default-config", 0x7e4000, 0x04000},
842 {"merge-config", 0x7ec000, 0x02000},
843 {"qos-db", 0x7ee000, 0x02000},
844 {"radio", 0x7f0000, 0x10000},
848 .first_sysupgrade_partition
= "os-image",
849 .last_sysupgrade_partition
= "file-system",
852 /** Firmware layout for the C58v1 */
854 .id
= "ARCHER-C58-V1",
858 "{product_name:Archer C58,product_ver:1.0.0,special_id:00000000}\r\n"
859 "{product_name:Archer C58,product_ver:1.0.0,special_id:45550000}\r\n"
860 "{product_name:Archer C58,product_ver:1.0.0,special_id:55530000}\r\n",
862 .soft_ver
= "soft_ver:1.0.0\n",
865 {"fs-uboot", 0x00000, 0x10000},
866 {"default-mac", 0x10000, 0x00200},
867 {"pin", 0x10200, 0x00200},
868 {"product-info", 0x10400, 0x00100},
869 {"partition-table", 0x10500, 0x00800},
870 {"soft-version", 0x11300, 0x00200},
871 {"support-list", 0x11500, 0x00100},
872 {"device-id", 0x11600, 0x00100},
873 {"profile", 0x11700, 0x03900},
874 {"default-config", 0x15000, 0x04000},
875 {"user-config", 0x19000, 0x04000},
876 {"firmware", 0x20000, 0x7c8000},
877 {"certyficate", 0x7e8000, 0x08000},
878 {"radio", 0x7f0000, 0x10000},
882 .first_sysupgrade_partition
= "os-image",
883 .last_sysupgrade_partition
= "file-system",
886 /** Firmware layout for the C59v1 */
888 .id
= "ARCHER-C59-V1",
892 "{product_name:Archer C59,product_ver:1.0.0,special_id:00000000}\r\n"
893 "{product_name:Archer C59,product_ver:1.0.0,special_id:45550000}\r\n"
894 "{product_name:Archer C59,product_ver:1.0.0,special_id:52550000}\r\n"
895 "{product_name:Archer C59,product_ver:1.0.0,special_id:55530000}\r\n",
897 .soft_ver
= "soft_ver:1.0.0\n",
899 /* We're using a dynamic kernel/rootfs split here */
901 {"fs-uboot", 0x00000, 0x10000},
902 {"default-mac", 0x10000, 0x00200},
903 {"pin", 0x10200, 0x00200},
904 {"device-id", 0x10400, 0x00100},
905 {"product-info", 0x10500, 0x0fb00},
906 {"firmware", 0x20000, 0xe30000},
907 {"partition-table", 0xe50000, 0x10000},
908 {"soft-version", 0xe60000, 0x10000},
909 {"support-list", 0xe70000, 0x10000},
910 {"profile", 0xe80000, 0x10000},
911 {"default-config", 0xe90000, 0x10000},
912 {"user-config", 0xea0000, 0x40000},
913 {"usb-config", 0xee0000, 0x10000},
914 {"certificate", 0xef0000, 0x10000},
915 {"qos-db", 0xf00000, 0x40000},
916 {"log", 0xfe0000, 0x10000},
917 {"radio", 0xff0000, 0x10000},
921 .first_sysupgrade_partition
= "os-image",
922 .last_sysupgrade_partition
= "file-system",
925 /** Firmware layout for the C59v2 */
927 .id
= "ARCHER-C59-V2",
931 "{product_name:Archer C59,product_ver:2.0.0,special_id:00000000}\r\n"
932 "{product_name:Archer C59,product_ver:2.0.0,special_id:45550000}\r\n"
933 "{product_name:Archer C59,product_ver:2.0.0,special_id:55530000}\r\n",
935 .soft_ver
= "soft_ver:2.0.0 Build 20161206 rel.7303\n",
937 /** We're using a dynamic kernel/rootfs split here */
939 {"factory-boot", 0x00000, 0x20000},
940 {"fs-uboot", 0x20000, 0x10000},
941 {"default-mac", 0x30000, 0x00200},
942 {"pin", 0x30200, 0x00200},
943 {"device-id", 0x30400, 0x00100},
944 {"product-info", 0x30500, 0x0fb00},
945 {"firmware", 0x40000, 0xe10000},
946 {"partition-table", 0xe50000, 0x10000},
947 {"soft-version", 0xe60000, 0x10000},
948 {"support-list", 0xe70000, 0x10000},
949 {"profile", 0xe80000, 0x10000},
950 {"default-config", 0xe90000, 0x10000},
951 {"user-config", 0xea0000, 0x40000},
952 {"usb-config", 0xee0000, 0x10000},
953 {"certificate", 0xef0000, 0x10000},
954 {"extra-para", 0xf00000, 0x10000},
955 {"qos-db", 0xf10000, 0x30000},
956 {"log", 0xfe0000, 0x10000},
957 {"radio", 0xff0000, 0x10000},
961 .first_sysupgrade_partition
= "os-image",
962 .last_sysupgrade_partition
= "file-system",
965 /** Firmware layout for the Archer C6 v2 (EU/RU/JP) */
967 .id
= "ARCHER-C6-V2",
971 "{product_name:Archer C6,product_ver:2.0.0,special_id:45550000}\r\n"
972 "{product_name:Archer C6,product_ver:2.0.0,special_id:52550000}\r\n"
973 "{product_name:Archer C6,product_ver:2.0.0,special_id:4A500000}\r\n",
975 .soft_ver
= "soft_ver:1.9.1\n",
978 {"fs-uboot", 0x00000, 0x20000},
979 {"default-mac", 0x20000, 0x00200},
980 {"pin", 0x20200, 0x00100},
981 {"product-info", 0x20300, 0x00200},
982 {"device-id", 0x20500, 0x0fb00},
983 {"firmware", 0x30000, 0x7a9400},
984 {"soft-version", 0x7d9400, 0x00100},
985 {"extra-para", 0x7d9500, 0x00100},
986 {"support-list", 0x7d9600, 0x00200},
987 {"profile", 0x7d9800, 0x03000},
988 {"default-config", 0x7dc800, 0x03000},
989 {"partition-table", 0x7df800, 0x00800},
990 {"user-config", 0x7e0000, 0x0c000},
991 {"certificate", 0x7ec000, 0x04000},
992 {"radio", 0x7f0000, 0x10000},
996 .first_sysupgrade_partition
= "os-image",
997 .last_sysupgrade_partition
= "file-system",
1000 /** Firmware layout for the Archer C6 v2 (US) and A6 v2 (US/TW) */
1002 .id
= "ARCHER-C6-V2-US",
1006 "{product_name:Archer A6,product_ver:2.0.0,special_id:55530000}\n"
1007 "{product_name:Archer A6,product_ver:2.0.0,special_id:54570000}\n"
1008 "{product_name:Archer C6,product_ver:2.0.0,special_id:55530000}\n",
1010 .soft_ver
= "soft_ver:1.9.1\n",
1013 {"factory-boot", 0x00000, 0x20000},
1014 {"default-mac", 0x20000, 0x00200},
1015 {"pin", 0x20200, 0x00100},
1016 {"product-info", 0x20300, 0x00200},
1017 {"device-id", 0x20500, 0x0fb00},
1018 {"fs-uboot", 0x30000, 0x20000},
1019 {"firmware", 0x50000, 0xf89400},
1020 {"soft-version", 0xfd9400, 0x00100},
1021 {"extra-para", 0xfd9500, 0x00100},
1022 {"support-list", 0xfd9600, 0x00200},
1023 {"profile", 0xfd9800, 0x03000},
1024 {"default-config", 0xfdc800, 0x03000},
1025 {"partition-table", 0xfdf800, 0x00800},
1026 {"user-config", 0xfe0000, 0x0c000},
1027 {"certificate", 0xfec000, 0x04000},
1028 {"radio", 0xff0000, 0x10000},
1031 .first_sysupgrade_partition
= "os-image",
1032 .last_sysupgrade_partition
= "file-system",
1034 /** Firmware layout for the Archer C6 v3 */
1036 .id
= "ARCHER-C6-V3",
1040 "{product_name:Archer C6,product_ver:3.20,special_id:55530000}"
1041 "{product_name:Archer C6,product_ver:3.20,special_id:45550000}"
1042 "{product_name:Archer C6,product_ver:3.20,special_id:52550000}"
1043 "{product_name:Archer C6,product_ver:3.20,special_id:4A500000}"
1044 "{product_name:Archer C6,product_ver:3.20,special_id:4B520000}",
1046 .soft_ver
= "soft_ver:1.0.9\n",
1049 {"fs-uboot", 0x00000, 0x40000},
1050 {"firmware", 0x40000, 0xf60000},
1051 {"default-mac", 0xfa0000, 0x00200},
1052 {"pin", 0xfa0200, 0x00100},
1053 {"device-id", 0xfa0300, 0x00100},
1054 {"product-info", 0xfa0400, 0x0fc00},
1055 {"default-config", 0xfb0000, 0x08000},
1056 {"ap-def-config", 0xfb8000, 0x08000},
1057 {"user-config", 0xfc0000, 0x0a000},
1058 {"ag-config", 0xfca000, 0x04000},
1059 {"certificate", 0xfce000, 0x02000},
1060 {"ap-config", 0xfd0000, 0x06000},
1061 {"router-config", 0xfd6000, 0x06000},
1062 {"favicon", 0xfdc000, 0x02000},
1063 {"logo", 0xfde000, 0x02000},
1064 {"partition-table", 0xfe0000, 0x00800},
1065 {"soft-version", 0xfe0800, 0x00100},
1066 {"support-list", 0xfe0900, 0x00200},
1067 {"profile", 0xfe0b00, 0x03000},
1068 {"extra-para", 0xfe3b00, 0x00100},
1069 {"radio", 0xff0000, 0x10000},
1072 .first_sysupgrade_partition
= "os-image",
1073 .last_sysupgrade_partition
= "file-system",
1075 /** Firmware layout for the Archer A6 v3 */
1077 .id
= "ARCHER-A6-V3",
1081 "{product_name:Archer A6,product_ver:3.0.0,special_id:43410000}\n"
1082 "{product_name:Archer A6,product_ver:3.0.0,special_id:55530000}\n"
1083 "{product_name:Archer A6,product_ver:3.0.0,special_id:54570000}\n",
1085 .soft_ver
= "soft_ver:1.0.5\n",
1088 {"fs-uboot", 0x00000, 0x40000},
1089 {"firmware", 0x40000, 0xf60000},
1090 {"default-mac", 0xfa0000, 0x00200},
1091 {"pin", 0xfa0200, 0x00100},
1092 {"device-id", 0xfa0300, 0x00100},
1093 {"product-info", 0xfa0400, 0x0fc00},
1094 {"default-config", 0xfb0000, 0x08000},
1095 {"ap-def-config", 0xfb8000, 0x08000},
1096 {"user-config", 0xfc0000, 0x0a000},
1097 {"ag-config", 0xfca000, 0x04000},
1098 {"certificate", 0xfce000, 0x02000},
1099 {"ap-config", 0xfd0000, 0x06000},
1100 {"router-config", 0xfd6000, 0x06000},
1101 {"favicon", 0xfdc000, 0x02000},
1102 {"logo", 0xfde000, 0x02000},
1103 {"partition-table", 0xfe0000, 0x00800},
1104 {"soft-version", 0xfe0800, 0x00100},
1105 {"support-list", 0xfe0900, 0x00200},
1106 {"profile", 0xfe0b00, 0x03000},
1107 {"extra-para", 0xfe3b00, 0x00100},
1108 {"radio", 0xff0000, 0x10000},
1111 .first_sysupgrade_partition
= "os-image",
1112 .last_sysupgrade_partition
= "file-system",
1114 /** Firmware layout for the Archer C6U v1 */
1116 .id
= "ARCHER-C6U-V1",
1120 "{product_name:Archer C6U,product_ver:1.0.0,special_id:45550000}\n",
1122 .soft_ver
= "soft_ver:1.0.2\n",
1125 {"fs-uboot", 0x00000, 0x40000},
1126 {"firmware", 0x40000, 0xf60000},
1127 {"default-mac", 0xfa0000, 0x00200},
1128 {"pin", 0xfa0200, 0x00100},
1129 {"device-id", 0xfa0300, 0x00100},
1130 {"product-info", 0xfa0400, 0x0fc00},
1131 {"default-config", 0xfb0000, 0x08000},
1132 {"ap-def-config", 0xfb8000, 0x08000},
1133 {"user-config", 0xfc0000, 0x0c000},
1134 {"certificate", 0xfcc000, 0x04000},
1135 {"ap-config", 0xfd0000, 0x08000},
1136 {"router-config", 0xfd8000, 0x08000},
1137 {"partition-table", 0xfe0000, 0x00800},
1138 {"soft-version", 0xfe0800, 0x00100},
1139 {"support-list", 0xfe0900, 0x00200},
1140 {"profile", 0xfe0b00, 0x03000},
1141 {"extra-para", 0xfe3b00, 0x00100},
1142 {"radio", 0xff0000, 0x10000},
1145 .first_sysupgrade_partition
= "os-image",
1146 .last_sysupgrade_partition
= "file-system",
1148 /** Firmware layout for the C60v1 */
1150 .id
= "ARCHER-C60-V1",
1154 "{product_name:Archer C60,product_ver:1.0.0,special_id:00000000}\r\n"
1155 "{product_name:Archer C60,product_ver:1.0.0,special_id:45550000}\r\n"
1156 "{product_name:Archer C60,product_ver:1.0.0,special_id:55530000}\r\n",
1158 .soft_ver
= "soft_ver:1.0.0\n",
1161 {"fs-uboot", 0x00000, 0x10000},
1162 {"default-mac", 0x10000, 0x00200},
1163 {"pin", 0x10200, 0x00200},
1164 {"product-info", 0x10400, 0x00100},
1165 {"partition-table", 0x10500, 0x00800},
1166 {"soft-version", 0x11300, 0x00200},
1167 {"support-list", 0x11500, 0x00100},
1168 {"device-id", 0x11600, 0x00100},
1169 {"profile", 0x11700, 0x03900},
1170 {"default-config", 0x15000, 0x04000},
1171 {"user-config", 0x19000, 0x04000},
1172 {"firmware", 0x20000, 0x7c8000},
1173 {"certyficate", 0x7e8000, 0x08000},
1174 {"radio", 0x7f0000, 0x10000},
1178 .first_sysupgrade_partition
= "os-image",
1179 .last_sysupgrade_partition
= "file-system",
1182 /** Firmware layout for the C60v2 */
1184 .id
= "ARCHER-C60-V2",
1188 "{product_name:Archer C60,product_ver:2.0.0,special_id:42520000}\r\n"
1189 "{product_name:Archer C60,product_ver:2.0.0,special_id:45550000}\r\n"
1190 "{product_name:Archer C60,product_ver:2.0.0,special_id:55530000}\r\n",
1192 .soft_ver
= "soft_ver:2.0.0\n",
1195 {"factory-boot", 0x00000, 0x1fb00},
1196 {"default-mac", 0x1fb00, 0x00200},
1197 {"pin", 0x1fd00, 0x00100},
1198 {"product-info", 0x1fe00, 0x00100},
1199 {"device-id", 0x1ff00, 0x00100},
1200 {"fs-uboot", 0x20000, 0x10000},
1201 {"firmware", 0x30000, 0x7a0000},
1202 {"soft-version", 0x7d9500, 0x00100},
1203 {"support-list", 0x7d9600, 0x00100},
1204 {"extra-para", 0x7d9700, 0x00100},
1205 {"profile", 0x7d9800, 0x03000},
1206 {"default-config", 0x7dc800, 0x03000},
1207 {"partition-table", 0x7df800, 0x00800},
1208 {"user-config", 0x7e0000, 0x0c000},
1209 {"certificate", 0x7ec000, 0x04000},
1210 {"radio", 0x7f0000, 0x10000},
1214 .first_sysupgrade_partition
= "os-image",
1215 .last_sysupgrade_partition
= "file-system",
1218 /** Firmware layout for the C60v3 */
1220 .id
= "ARCHER-C60-V3",
1224 "{product_name:Archer C60,product_ver:3.0.0,special_id:42520000}\r\n"
1225 "{product_name:Archer C60,product_ver:3.0.0,special_id:45550000}\r\n"
1226 "{product_name:Archer C60,product_ver:3.0.0,special_id:55530000}\r\n",
1228 .soft_ver
= "soft_ver:3.0.0\n",
1231 {"factory-boot", 0x00000, 0x1fb00},
1232 {"default-mac", 0x1fb00, 0x00200},
1233 {"pin", 0x1fd00, 0x00100},
1234 {"product-info", 0x1fe00, 0x00100},
1235 {"device-id", 0x1ff00, 0x00100},
1236 {"fs-uboot", 0x20000, 0x10000},
1237 {"firmware", 0x30000, 0x7a0000},
1238 {"soft-version", 0x7d9500, 0x00100},
1239 {"support-list", 0x7d9600, 0x00100},
1240 {"extra-para", 0x7d9700, 0x00100},
1241 {"profile", 0x7d9800, 0x03000},
1242 {"default-config", 0x7dc800, 0x03000},
1243 {"partition-table", 0x7df800, 0x00800},
1244 {"user-config", 0x7e0000, 0x0c000},
1245 {"certificate", 0x7ec000, 0x04000},
1246 {"radio", 0x7f0000, 0x10000},
1250 .first_sysupgrade_partition
= "os-image",
1251 .last_sysupgrade_partition
= "file-system",
1254 /** Firmware layout for the C5 */
1256 .id
= "ARCHER-C5-V2",
1260 "{product_name:ArcherC5,product_ver:2.0.0,special_id:00000000}\r\n"
1261 "{product_name:ArcherC5,product_ver:2.0.0,special_id:55530000}\r\n"
1262 "{product_name:ArcherC5,product_ver:2.0.0,special_id:4A500000}\r\n", /* JP version */
1267 {"fs-uboot", 0x00000, 0x40000},
1268 {"os-image", 0x40000, 0x200000},
1269 {"file-system", 0x240000, 0xc00000},
1270 {"default-mac", 0xe40000, 0x00200},
1271 {"pin", 0xe40200, 0x00200},
1272 {"product-info", 0xe40400, 0x00200},
1273 {"partition-table", 0xe50000, 0x10000},
1274 {"soft-version", 0xe60000, 0x00200},
1275 {"support-list", 0xe61000, 0x0f000},
1276 {"profile", 0xe70000, 0x10000},
1277 {"default-config", 0xe80000, 0x10000},
1278 {"user-config", 0xe90000, 0x50000},
1279 {"log", 0xee0000, 0x100000},
1280 {"radio_bk", 0xfe0000, 0x10000},
1281 {"radio", 0xff0000, 0x10000},
1285 .first_sysupgrade_partition
= "os-image",
1286 .last_sysupgrade_partition
= "file-system"
1289 /** Firmware layout for the C7 */
1291 .id
= "ARCHER-C7-V4",
1294 "{product_name:Archer C7,product_ver:4.0.0,special_id:00000000}\n"
1295 "{product_name:Archer C7,product_ver:4.0.0,special_id:41550000}\n"
1296 "{product_name:Archer C7,product_ver:4.0.0,special_id:45550000}\n"
1297 "{product_name:Archer C7,product_ver:4.0.0,special_id:4B520000}\n"
1298 "{product_name:Archer C7,product_ver:4.0.0,special_id:42520000}\n"
1299 "{product_name:Archer C7,product_ver:4.0.0,special_id:4A500000}\n"
1300 "{product_name:Archer C7,product_ver:4.0.0,special_id:52550000}\n"
1301 "{product_name:Archer C7,product_ver:4.0.0,special_id:54570000}\n"
1302 "{product_name:Archer C7,product_ver:4.0.0,special_id:55530000}\n"
1303 "{product_name:Archer C7,product_ver:4.0.0,special_id:43410000}\n",
1305 .soft_ver
= "soft_ver:1.0.0\n",
1307 /* We're using a dynamic kernel/rootfs split here */
1309 {"factory-boot", 0x00000, 0x20000},
1310 {"fs-uboot", 0x20000, 0x20000},
1311 {"firmware", 0x40000, 0xEC0000}, /* Stock: name os-image base 0x40000 size 0x120000 */
1312 /* Stock: name file-system base 0x160000 size 0xda0000 */
1313 {"default-mac", 0xf00000, 0x00200},
1314 {"pin", 0xf00200, 0x00200},
1315 {"device-id", 0xf00400, 0x00100},
1316 {"product-info", 0xf00500, 0x0fb00},
1317 {"soft-version", 0xf10000, 0x00100},
1318 {"extra-para", 0xf11000, 0x01000},
1319 {"support-list", 0xf12000, 0x0a000},
1320 {"profile", 0xf1c000, 0x04000},
1321 {"default-config", 0xf20000, 0x10000},
1322 {"user-config", 0xf30000, 0x40000},
1323 {"qos-db", 0xf70000, 0x40000},
1324 {"certificate", 0xfb0000, 0x10000},
1325 {"partition-table", 0xfc0000, 0x10000},
1326 {"log", 0xfd0000, 0x20000},
1327 {"radio", 0xff0000, 0x10000},
1331 .first_sysupgrade_partition
= "os-image",
1332 .last_sysupgrade_partition
= "file-system",
1335 /** Firmware layout for the C7 v5*/
1337 .id
= "ARCHER-C7-V5",
1340 "{product_name:Archer C7,product_ver:5.0.0,special_id:00000000}\n"
1341 "{product_name:Archer C7,product_ver:5.0.0,special_id:45550000}\n"
1342 "{product_name:Archer C7,product_ver:5.0.0,special_id:55530000}\n"
1343 "{product_name:Archer C7,product_ver:5.0.0,special_id:43410000}\n"
1344 "{product_name:Archer C7,product_ver:5.0.0,special_id:4A500000}\n"
1345 "{product_name:Archer C7,product_ver:5.0.0,special_id:54570000}\n"
1346 "{product_name:Archer C7,product_ver:5.0.0,special_id:52550000}\n"
1347 "{product_name:Archer C7,product_ver:5.0.0,special_id:4B520000}\n",
1350 .soft_ver
= "soft_ver:7.0.0\n",
1352 /* We're using a dynamic kernel/rootfs split here */
1354 {"factory-boot", 0x00000, 0x20000},
1355 {"fs-uboot", 0x20000, 0x20000},
1356 {"partition-table", 0x40000, 0x10000},
1357 {"radio", 0x50000, 0x10000},
1358 {"default-mac", 0x60000, 0x00200},
1359 {"pin", 0x60200, 0x00200},
1360 {"device-id", 0x60400, 0x00100},
1361 {"product-info", 0x60500, 0x0fb00},
1362 {"soft-version", 0x70000, 0x01000},
1363 {"extra-para", 0x71000, 0x01000},
1364 {"support-list", 0x72000, 0x0a000},
1365 {"profile", 0x7c000, 0x04000},
1366 {"user-config", 0x80000, 0x40000},
1369 {"firmware", 0xc0000, 0xf00000}, /* Stock: name os-image base 0xc0000 size 0x120000 */
1370 /* Stock: name file-system base 0x1e0000 size 0xde0000 */
1372 {"log", 0xfc0000, 0x20000},
1373 {"certificate", 0xfe0000, 0x10000},
1374 {"default-config", 0xff0000, 0x10000},
1379 .first_sysupgrade_partition
= "os-image",
1380 .last_sysupgrade_partition
= "file-system",
1383 /** Firmware layout for the C9 */
1389 "{product_name:ArcherC9,"
1390 "product_ver:1.0.0,"
1391 "special_id:00000000}\n",
1396 {"fs-uboot", 0x00000, 0x40000},
1397 {"os-image", 0x40000, 0x200000},
1398 {"file-system", 0x240000, 0xc00000},
1399 {"default-mac", 0xe40000, 0x00200},
1400 {"pin", 0xe40200, 0x00200},
1401 {"product-info", 0xe40400, 0x00200},
1402 {"partition-table", 0xe50000, 0x10000},
1403 {"soft-version", 0xe60000, 0x00200},
1404 {"support-list", 0xe61000, 0x0f000},
1405 {"profile", 0xe70000, 0x10000},
1406 {"default-config", 0xe80000, 0x10000},
1407 {"user-config", 0xe90000, 0x50000},
1408 {"log", 0xee0000, 0x100000},
1409 {"radio_bk", 0xfe0000, 0x10000},
1410 {"radio", 0xff0000, 0x10000},
1414 .first_sysupgrade_partition
= "os-image",
1415 .last_sysupgrade_partition
= "file-system"
1418 /** Firmware layout for the EAP120 */
1421 .vendor
= "EAP120(TP-LINK|UN|N300-2):1.0\r\n",
1424 "EAP120(TP-LINK|UN|N300-2):1.0\r\n",
1429 {"fs-uboot", 0x00000, 0x20000},
1430 {"partition-table", 0x20000, 0x02000},
1431 {"default-mac", 0x30000, 0x00020},
1432 {"support-list", 0x31000, 0x00100},
1433 {"product-info", 0x31100, 0x00100},
1434 {"soft-version", 0x32000, 0x00100},
1435 {"os-image", 0x40000, 0x180000},
1436 {"file-system", 0x1c0000, 0x600000},
1437 {"user-config", 0x7c0000, 0x10000},
1438 {"backup-config", 0x7d0000, 0x10000},
1439 {"log", 0x7e0000, 0x10000},
1440 {"radio", 0x7f0000, 0x10000},
1444 .first_sysupgrade_partition
= "os-image",
1445 .last_sysupgrade_partition
= "file-system"
1448 /** Firmware layout for the EAP225-Outdoor v1 */
1450 .id
= "EAP225-OUTDOOR-V1",
1453 "EAP225-Outdoor(TP-Link|UN|AC1200-D):1.0\r\n",
1454 .part_trail
= PART_TRAIL_NONE
,
1456 .soft_ver_compat_level
= 1,
1459 {"fs-uboot", 0x00000, 0x20000},
1460 {"partition-table", 0x20000, 0x02000},
1461 {"default-mac", 0x30000, 0x01000},
1462 {"support-list", 0x31000, 0x00100},
1463 {"product-info", 0x31100, 0x00400},
1464 {"soft-version", 0x32000, 0x00100},
1465 {"firmware", 0x40000, 0xd80000},
1466 {"user-config", 0xdc0000, 0x30000},
1467 {"mutil-log", 0xf30000, 0x80000},
1468 {"oops", 0xfb0000, 0x40000},
1469 {"radio", 0xff0000, 0x10000},
1473 .first_sysupgrade_partition
= "os-image",
1474 .last_sysupgrade_partition
= "file-system"
1477 /** Firmware layout for the EAP225 v3 */
1482 "EAP225(TP-Link|UN|AC1350-D):3.0\r\n",
1483 .part_trail
= PART_TRAIL_NONE
,
1485 .soft_ver_compat_level
= 1,
1488 {"fs-uboot", 0x00000, 0x20000},
1489 {"partition-table", 0x20000, 0x02000},
1490 {"default-mac", 0x30000, 0x01000},
1491 {"support-list", 0x31000, 0x00100},
1492 {"product-info", 0x31100, 0x00400},
1493 {"soft-version", 0x32000, 0x00100},
1494 {"firmware", 0x40000, 0xd80000},
1495 {"user-config", 0xdc0000, 0x30000},
1496 {"mutil-log", 0xf30000, 0x80000},
1497 {"oops", 0xfb0000, 0x40000},
1498 {"radio", 0xff0000, 0x10000},
1502 .first_sysupgrade_partition
= "os-image",
1503 .last_sysupgrade_partition
= "file-system"
1506 /** Firmware layout for the EAP225-Wall v2 */
1508 .id
= "EAP225-WALL-V2",
1511 "EAP225-Wall(TP-Link|UN|AC1200-D):2.0\r\n",
1512 .part_trail
= PART_TRAIL_NONE
,
1514 .soft_ver_compat_level
= 1,
1517 {"fs-uboot", 0x00000, 0x20000},
1518 {"partition-table", 0x20000, 0x02000},
1519 {"default-mac", 0x30000, 0x01000},
1520 {"support-list", 0x31000, 0x00100},
1521 {"product-info", 0x31100, 0x00400},
1522 {"soft-version", 0x32000, 0x00100},
1523 {"firmware", 0x40000, 0xd80000},
1524 {"user-config", 0xdc0000, 0x30000},
1525 {"mutil-log", 0xf30000, 0x80000},
1526 {"oops", 0xfb0000, 0x40000},
1527 {"radio", 0xff0000, 0x10000},
1531 .first_sysupgrade_partition
= "os-image",
1532 .last_sysupgrade_partition
= "file-system"
1535 /** Firmware layout for the EAP235-Wall v1 */
1537 .id
= "EAP235-WALL-V1",
1540 "EAP235-Wall(TP-Link|UN|AC1200-D):1.0\r\n",
1541 .part_trail
= PART_TRAIL_NONE
,
1543 .soft_ver_compat_level
= 1,
1546 {"fs-uboot", 0x00000, 0x80000},
1547 {"partition-table", 0x80000, 0x02000},
1548 {"default-mac", 0x90000, 0x01000},
1549 {"support-list", 0x91000, 0x00100},
1550 {"product-info", 0x91100, 0x00400},
1551 {"soft-version", 0x92000, 0x00100},
1552 {"firmware", 0xa0000, 0xd20000},
1553 {"user-config", 0xdc0000, 0x30000},
1554 {"mutil-log", 0xf30000, 0x80000},
1555 {"oops", 0xfb0000, 0x40000},
1556 {"radio", 0xff0000, 0x10000},
1560 .first_sysupgrade_partition
= "os-image",
1561 .last_sysupgrade_partition
= "file-system"
1564 /** Firmware layout for the EAP245 v1 */
1569 "EAP245(TP-LINK|UN|AC1750-D):1.0\r\n",
1570 .part_trail
= PART_TRAIL_NONE
,
1574 {"fs-uboot", 0x00000, 0x20000},
1575 {"partition-table", 0x20000, 0x02000},
1576 {"default-mac", 0x30000, 0x01000},
1577 {"support-list", 0x31000, 0x00100},
1578 {"product-info", 0x31100, 0x00400},
1579 {"soft-version", 0x32000, 0x00100},
1580 {"firmware", 0x40000, 0xd80000},
1581 {"user-config", 0xdc0000, 0x30000},
1582 {"radio", 0xff0000, 0x10000},
1586 .first_sysupgrade_partition
= "os-image",
1587 .last_sysupgrade_partition
= "file-system"
1590 /** Firmware layout for the EAP245 v3 */
1595 "EAP245(TP-Link|UN|AC1750-D):3.0\r\n",
1596 .part_trail
= PART_TRAIL_NONE
,
1598 .soft_ver_compat_level
= 1,
1600 /** Firmware partition with dynamic kernel/rootfs split */
1602 {"factroy-boot", 0x00000, 0x40000},
1603 {"fs-uboot", 0x40000, 0x40000},
1604 {"partition-table", 0x80000, 0x10000},
1605 {"default-mac", 0x90000, 0x01000},
1606 {"support-list", 0x91000, 0x00100},
1607 {"product-info", 0x91100, 0x00400},
1608 {"soft-version", 0x92000, 0x00100},
1609 {"radio", 0xa0000, 0x10000},
1610 {"extra-para", 0xb0000, 0x10000},
1611 {"firmware", 0xc0000, 0xe40000},
1612 {"config", 0xf00000, 0x30000},
1613 {"mutil-log", 0xf30000, 0x80000},
1614 {"oops", 0xfb0000, 0x40000},
1618 .first_sysupgrade_partition
= "os-image",
1619 .last_sysupgrade_partition
= "file-system"
1622 /** Firmware layout for the TL-WA850RE v2 */
1624 .id
= "TLWA850REV2",
1628 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:55530000}\n"
1629 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:00000000}\n"
1630 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:55534100}\n"
1631 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:45550000}\n"
1632 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:4B520000}\n"
1633 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:42520000}\n"
1634 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:4A500000}\n"
1635 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:43410000}\n"
1636 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:41550000}\n"
1637 "{product_name:TL-WA850RE,product_ver:2.0.0,special_id:52550000}\n",
1642 576KB were moved from file-system to os-image
1643 in comparison to the stock image
1646 {"fs-uboot", 0x00000, 0x20000},
1647 {"firmware", 0x20000, 0x390000},
1648 {"partition-table", 0x3b0000, 0x02000},
1649 {"default-mac", 0x3c0000, 0x00020},
1650 {"pin", 0x3c0100, 0x00020},
1651 {"product-info", 0x3c1000, 0x01000},
1652 {"soft-version", 0x3c2000, 0x00100},
1653 {"support-list", 0x3c3000, 0x01000},
1654 {"profile", 0x3c4000, 0x08000},
1655 {"user-config", 0x3d0000, 0x10000},
1656 {"default-config", 0x3e0000, 0x10000},
1657 {"radio", 0x3f0000, 0x10000},
1661 .first_sysupgrade_partition
= "os-image",
1662 .last_sysupgrade_partition
= "file-system"
1665 /** Firmware layout for the TL-WA855RE v1 */
1667 .id
= "TLWA855REV1",
1671 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:00000000}\n"
1672 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:55530000}\n"
1673 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:45550000}\n"
1674 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:4B520000}\n"
1675 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:42520000}\n"
1676 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:4A500000}\n"
1677 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:43410000}\n"
1678 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:41550000}\n"
1679 "{product_name:TL-WA855RE,product_ver:1.0.0,special_id:52550000}\n",
1684 {"fs-uboot", 0x00000, 0x20000},
1685 {"os-image", 0x20000, 0x150000},
1686 {"file-system", 0x170000, 0x240000},
1687 {"partition-table", 0x3b0000, 0x02000},
1688 {"default-mac", 0x3c0000, 0x00020},
1689 {"pin", 0x3c0100, 0x00020},
1690 {"product-info", 0x3c1000, 0x01000},
1691 {"soft-version", 0x3c2000, 0x00100},
1692 {"support-list", 0x3c3000, 0x01000},
1693 {"profile", 0x3c4000, 0x08000},
1694 {"user-config", 0x3d0000, 0x10000},
1695 {"default-config", 0x3e0000, 0x10000},
1696 {"radio", 0x3f0000, 0x10000},
1700 .first_sysupgrade_partition
= "os-image",
1701 .last_sysupgrade_partition
= "file-system"
1704 /** Firmware layout for the TL-WPA8630P v2 (EU)*/
1706 .id
= "TL-WPA8630P-V2.0-EU",
1710 "{product_name:TL-WPA8630P,product_ver:2.0.0,special_id:45550000}\n",
1715 {"factory-uboot", 0x00000, 0x20000},
1716 {"fs-uboot", 0x20000, 0x20000},
1717 {"firmware", 0x40000, 0x5e0000},
1718 {"partition-table", 0x620000, 0x02000},
1719 {"default-mac", 0x630000, 0x00020},
1720 {"pin", 0x630100, 0x00020},
1721 {"device-id", 0x630200, 0x00030},
1722 {"product-info", 0x631100, 0x01000},
1723 {"extra-para", 0x632100, 0x01000},
1724 {"soft-version", 0x640000, 0x01000},
1725 {"support-list", 0x641000, 0x01000},
1726 {"profile", 0x642000, 0x08000},
1727 {"user-config", 0x650000, 0x10000},
1728 {"default-config", 0x660000, 0x10000},
1729 {"default-nvm", 0x670000, 0xc0000},
1730 {"default-pib", 0x730000, 0x40000},
1731 {"radio", 0x7f0000, 0x10000},
1735 .first_sysupgrade_partition
= "os-image",
1736 .last_sysupgrade_partition
= "file-system"
1739 /** Firmware layout for the TL-WPA8630P v2 (INT)*/
1741 .id
= "TL-WPA8630P-V2-INT",
1745 "{product_name:TL-WPA8630P,product_ver:2.0.0,special_id:41550000}\n"
1746 "{product_name:TL-WPA8630P,product_ver:2.0.0,special_id:44450000}\n"
1747 "{product_name:TL-WPA8630P,product_ver:2.1.0,special_id:41550000}\n",
1752 {"factory-uboot", 0x00000, 0x20000},
1753 {"fs-uboot", 0x20000, 0x20000},
1754 {"firmware", 0x40000, 0x5e0000},
1755 {"partition-table", 0x620000, 0x02000},
1756 {"extra-para", 0x632100, 0x01000},
1757 {"soft-version", 0x640000, 0x01000},
1758 {"support-list", 0x641000, 0x01000},
1759 {"profile", 0x642000, 0x08000},
1760 {"user-config", 0x650000, 0x10000},
1761 {"default-config", 0x660000, 0x10000},
1762 {"default-nvm", 0x670000, 0xc0000},
1763 {"default-pib", 0x730000, 0x40000},
1764 {"default-mac", 0x7e0000, 0x00020},
1765 {"pin", 0x7e0100, 0x00020},
1766 {"device-id", 0x7e0200, 0x00030},
1767 {"product-info", 0x7e1100, 0x01000},
1768 {"radio", 0x7f0000, 0x10000},
1772 .first_sysupgrade_partition
= "os-image",
1773 .last_sysupgrade_partition
= "file-system"
1776 /** Firmware layout for the TL-WPA8630P v2.1 (EU)*/
1778 .id
= "TL-WPA8630P-V2.1-EU",
1782 "{product_name:TL-WPA8630P,product_ver:2.1.0,special_id:45550000}\n",
1787 {"factory-uboot", 0x00000, 0x20000},
1788 {"fs-uboot", 0x20000, 0x20000},
1789 {"firmware", 0x40000, 0x5e0000},
1790 {"extra-para", 0x680000, 0x01000},
1791 {"product-info", 0x690000, 0x01000},
1792 {"partition-table", 0x6a0000, 0x02000},
1793 {"soft-version", 0x6b0000, 0x01000},
1794 {"support-list", 0x6b1000, 0x01000},
1795 {"profile", 0x6b2000, 0x08000},
1796 {"user-config", 0x6c0000, 0x10000},
1797 {"default-config", 0x6d0000, 0x10000},
1798 {"default-nvm", 0x6e0000, 0xc0000},
1799 {"default-pib", 0x7a0000, 0x40000},
1800 {"default-mac", 0x7e0000, 0x00020},
1801 {"pin", 0x7e0100, 0x00020},
1802 {"device-id", 0x7e0200, 0x00030},
1803 {"radio", 0x7f0000, 0x10000},
1807 .first_sysupgrade_partition
= "os-image",
1808 .last_sysupgrade_partition
= "file-system"
1811 /** Firmware layout for the TL-WR1043 v5 */
1813 .id
= "TLWR1043NV5",
1817 "{product_name:TL-WR1043N,product_ver:5.0.0,special_id:45550000}\n"
1818 "{product_name:TL-WR1043N,product_ver:5.0.0,special_id:55530000}\n",
1820 .soft_ver
= "soft_ver:1.0.0\n",
1822 {"factory-boot", 0x00000, 0x20000},
1823 {"fs-uboot", 0x20000, 0x20000},
1824 {"firmware", 0x40000, 0xec0000},
1825 {"default-mac", 0xf00000, 0x00200},
1826 {"pin", 0xf00200, 0x00200},
1827 {"device-id", 0xf00400, 0x00100},
1828 {"product-info", 0xf00500, 0x0fb00},
1829 {"soft-version", 0xf10000, 0x01000},
1830 {"extra-para", 0xf11000, 0x01000},
1831 {"support-list", 0xf12000, 0x0a000},
1832 {"profile", 0xf1c000, 0x04000},
1833 {"default-config", 0xf20000, 0x10000},
1834 {"user-config", 0xf30000, 0x40000},
1835 {"qos-db", 0xf70000, 0x40000},
1836 {"certificate", 0xfb0000, 0x10000},
1837 {"partition-table", 0xfc0000, 0x10000},
1838 {"log", 0xfd0000, 0x20000},
1839 {"radio", 0xff0000, 0x10000},
1842 .first_sysupgrade_partition
= "os-image",
1843 .last_sysupgrade_partition
= "file-system"
1846 /** Firmware layout for the TL-WR1043 v4 */
1848 .id
= "TLWR1043NDV4",
1852 "{product_name:TL-WR1043ND,product_ver:4.0.0,special_id:45550000}\n",
1856 /* We're using a dynamic kernel/rootfs split here */
1858 {"fs-uboot", 0x00000, 0x20000},
1859 {"firmware", 0x20000, 0xf30000},
1860 {"default-mac", 0xf50000, 0x00200},
1861 {"pin", 0xf50200, 0x00200},
1862 {"product-info", 0xf50400, 0x0fc00},
1863 {"soft-version", 0xf60000, 0x0b000},
1864 {"support-list", 0xf6b000, 0x04000},
1865 {"profile", 0xf70000, 0x04000},
1866 {"default-config", 0xf74000, 0x0b000},
1867 {"user-config", 0xf80000, 0x40000},
1868 {"partition-table", 0xfc0000, 0x10000},
1869 {"log", 0xfd0000, 0x20000},
1870 {"radio", 0xff0000, 0x10000},
1874 .first_sysupgrade_partition
= "os-image",
1875 .last_sysupgrade_partition
= "file-system"
1878 /** Firmware layout for the TL-WR902AC v1 */
1880 .id
= "TL-WR902AC-V1",
1884 "{product_name:TL-WR902AC,product_ver:1.0.0,special_id:45550000}\n"
1885 "{product_name:TL-WR902AC,product_ver:1.0.0,special_id:55530000}\n",
1890 384KB were moved from file-system to os-image
1891 in comparison to the stock image
1894 {"fs-uboot", 0x00000, 0x20000},
1895 {"firmware", 0x20000, 0x730000},
1896 {"default-mac", 0x750000, 0x00200},
1897 {"pin", 0x750200, 0x00200},
1898 {"product-info", 0x750400, 0x0fc00},
1899 {"soft-version", 0x760000, 0x0b000},
1900 {"support-list", 0x76b000, 0x04000},
1901 {"profile", 0x770000, 0x04000},
1902 {"default-config", 0x774000, 0x0b000},
1903 {"user-config", 0x780000, 0x40000},
1904 {"partition-table", 0x7c0000, 0x10000},
1905 {"log", 0x7d0000, 0x20000},
1906 {"radio", 0x7f0000, 0x10000},
1910 .first_sysupgrade_partition
= "os-image",
1911 .last_sysupgrade_partition
= "file-system",
1914 /** Firmware layout for the TL-WR941HP v1 */
1916 .id
= "TL-WR941HP-V1",
1920 "{product_name:TL-WR941HP,product_ver:1.0.0,special_id:00000000}\n",
1925 {"fs-uboot", 0x00000, 0x20000},
1926 {"firmware", 0x20000, 0x730000},
1927 {"default-mac", 0x750000, 0x00200},
1928 {"pin", 0x750200, 0x00200},
1929 {"product-info", 0x750400, 0x0fc00},
1930 {"soft-version", 0x760000, 0x0b000},
1931 {"support-list", 0x76b000, 0x04000},
1932 {"profile", 0x770000, 0x04000},
1933 {"default-config", 0x774000, 0x0b000},
1934 {"user-config", 0x780000, 0x40000},
1935 {"partition-table", 0x7c0000, 0x10000},
1936 {"log", 0x7d0000, 0x20000},
1937 {"radio", 0x7f0000, 0x10000},
1941 .first_sysupgrade_partition
= "os-image",
1942 .last_sysupgrade_partition
= "file-system",
1945 /** Firmware layout for the TL-WR942N V1 */
1951 "{product_name:TL-WR942N,product_ver:1.0.0,special_id:00000000}\r\n"
1952 "{product_name:TL-WR942N,product_ver:1.0.0,special_id:52550000}\r\n",
1957 {"fs-uboot", 0x00000, 0x20000},
1958 {"firmware", 0x20000, 0xe20000},
1959 {"default-mac", 0xe40000, 0x00200},
1960 {"pin", 0xe40200, 0x00200},
1961 {"product-info", 0xe40400, 0x0fc00},
1962 {"partition-table", 0xe50000, 0x10000},
1963 {"soft-version", 0xe60000, 0x10000},
1964 {"support-list", 0xe70000, 0x10000},
1965 {"profile", 0xe80000, 0x10000},
1966 {"default-config", 0xe90000, 0x10000},
1967 {"user-config", 0xea0000, 0x40000},
1968 {"qos-db", 0xee0000, 0x40000},
1969 {"certificate", 0xf20000, 0x10000},
1970 {"usb-config", 0xfb0000, 0x10000},
1971 {"log", 0xfc0000, 0x20000},
1972 {"radio-bk", 0xfe0000, 0x10000},
1973 {"radio", 0xff0000, 0x10000},
1977 .first_sysupgrade_partition
= "os-image",
1978 .last_sysupgrade_partition
= "file-system",
1981 /** Firmware layout for the RE200 v2 */
1987 "{product_name:RE200,product_ver:2.0.0,special_id:00000000}\n"
1988 "{product_name:RE200,product_ver:2.0.0,special_id:41520000}\n"
1989 "{product_name:RE200,product_ver:2.0.0,special_id:41550000}\n"
1990 "{product_name:RE200,product_ver:2.0.0,special_id:42520000}\n"
1991 "{product_name:RE200,product_ver:2.0.0,special_id:43410000}\n"
1992 "{product_name:RE200,product_ver:2.0.0,special_id:45530000}\n"
1993 "{product_name:RE200,product_ver:2.0.0,special_id:45550000}\n"
1994 "{product_name:RE200,product_ver:2.0.0,special_id:49440000}\n"
1995 "{product_name:RE200,product_ver:2.0.0,special_id:4a500000}\n"
1996 "{product_name:RE200,product_ver:2.0.0,special_id:4b520000}\n"
1997 "{product_name:RE200,product_ver:2.0.0,special_id:52550000}\n"
1998 "{product_name:RE200,product_ver:2.0.0,special_id:54570000}\n"
1999 "{product_name:RE200,product_ver:2.0.0,special_id:55530000}\n",
2004 {"fs-uboot", 0x00000, 0x20000},
2005 {"firmware", 0x20000, 0x7a0000},
2006 {"partition-table", 0x7c0000, 0x02000},
2007 {"default-mac", 0x7c2000, 0x00020},
2008 {"pin", 0x7c2100, 0x00020},
2009 {"product-info", 0x7c3100, 0x01000},
2010 {"soft-version", 0x7c4200, 0x01000},
2011 {"support-list", 0x7c5200, 0x01000},
2012 {"profile", 0x7c6200, 0x08000},
2013 {"config-info", 0x7ce200, 0x00400},
2014 {"user-config", 0x7d0000, 0x10000},
2015 {"default-config", 0x7e0000, 0x10000},
2016 {"radio", 0x7f0000, 0x10000},
2020 .first_sysupgrade_partition
= "os-image",
2021 .last_sysupgrade_partition
= "file-system"
2024 /** Firmware layout for the RE200 v3 */
2030 "{product_name:RE200,product_ver:3.0.0,special_id:00000000}\n"
2031 "{product_name:RE200,product_ver:3.0.0,special_id:41520000}\n"
2032 "{product_name:RE200,product_ver:3.0.0,special_id:41550000}\n"
2033 "{product_name:RE200,product_ver:3.0.0,special_id:42520000}\n"
2034 "{product_name:RE200,product_ver:3.0.0,special_id:43410000}\n"
2035 "{product_name:RE200,product_ver:3.0.0,special_id:45470000}\n"
2036 "{product_name:RE200,product_ver:3.0.0,special_id:45530000}\n"
2037 "{product_name:RE200,product_ver:3.0.0,special_id:45550000}\n"
2038 "{product_name:RE200,product_ver:3.0.0,special_id:49440000}\n"
2039 "{product_name:RE200,product_ver:3.0.0,special_id:4A500000}\n"
2040 "{product_name:RE200,product_ver:3.0.0,special_id:4B520000}\n"
2041 "{product_name:RE200,product_ver:3.0.0,special_id:52550000}\n"
2042 "{product_name:RE200,product_ver:3.0.0,special_id:54570000}\n"
2043 "{product_name:RE200,product_ver:3.0.0,special_id:55530000}\n",
2048 {"fs-uboot", 0x00000, 0x20000},
2049 {"firmware", 0x20000, 0x7a0000},
2050 {"partition-table", 0x7c0000, 0x02000},
2051 {"default-mac", 0x7c2000, 0x00020},
2052 {"pin", 0x7c2100, 0x00020},
2053 {"product-info", 0x7c3100, 0x01000},
2054 {"soft-version", 0x7c4200, 0x01000},
2055 {"support-list", 0x7c5200, 0x01000},
2056 {"profile", 0x7c6200, 0x08000},
2057 {"config-info", 0x7ce200, 0x00400},
2058 {"user-config", 0x7d0000, 0x10000},
2059 {"default-config", 0x7e0000, 0x10000},
2060 {"radio", 0x7f0000, 0x10000},
2064 .first_sysupgrade_partition
= "os-image",
2065 .last_sysupgrade_partition
= "file-system"
2068 /** Firmware layout for the RE200 v4 */
2074 "{product_name:RE200,product_ver:4.0.0,special_id:00000000}\n"
2075 "{product_name:RE200,product_ver:4.0.0,special_id:45550000}\n"
2076 "{product_name:RE200,product_ver:4.0.0,special_id:4A500000}\n"
2077 "{product_name:RE200,product_ver:4.0.0,special_id:4B520000}\n"
2078 "{product_name:RE200,product_ver:4.0.0,special_id:43410000}\n"
2079 "{product_name:RE200,product_ver:4.0.0,special_id:41550000}\n"
2080 "{product_name:RE200,product_ver:4.0.0,special_id:42520000}\n"
2081 "{product_name:RE200,product_ver:4.0.0,special_id:55530000}\n"
2082 "{product_name:RE200,product_ver:4.0.0,special_id:41520000}\n"
2083 "{product_name:RE200,product_ver:4.0.0,special_id:52550000}\n"
2084 "{product_name:RE200,product_ver:4.0.0,special_id:54570000}\n"
2085 "{product_name:RE200,product_ver:4.0.0,special_id:45530000}\n"
2086 "{product_name:RE200,product_ver:4.0.0,special_id:49440000}\n"
2087 "{product_name:RE200,product_ver:4.0.0,special_id:45470000}\n",
2089 .soft_ver
= "soft_ver:1.1.0\n",
2092 {"fs-uboot", 0x00000, 0x20000},
2093 {"firmware", 0x20000, 0x7a0000},
2094 {"partition-table", 0x7c0000, 0x02000},
2095 {"default-mac", 0x7c2000, 0x00020},
2096 {"pin", 0x7c2100, 0x00020},
2097 {"product-info", 0x7c3100, 0x01000},
2098 {"soft-version", 0x7c4200, 0x01000},
2099 {"support-list", 0x7c5200, 0x01000},
2100 {"profile", 0x7c6200, 0x08000},
2101 {"config-info", 0x7ce200, 0x00400},
2102 {"user-config", 0x7d0000, 0x10000},
2103 {"default-config", 0x7e0000, 0x10000},
2104 {"radio", 0x7f0000, 0x10000},
2108 .first_sysupgrade_partition
= "os-image",
2109 .last_sysupgrade_partition
= "file-system"
2112 /** Firmware layout for the RE220 v2 */
2118 "{product_name:RE220,product_ver:2.0.0,special_id:00000000}\n"
2119 "{product_name:RE220,product_ver:2.0.0,special_id:41520000}\n"
2120 "{product_name:RE220,product_ver:2.0.0,special_id:41550000}\n"
2121 "{product_name:RE220,product_ver:2.0.0,special_id:42520000}\n"
2122 "{product_name:RE220,product_ver:2.0.0,special_id:43410000}\n"
2123 "{product_name:RE220,product_ver:2.0.0,special_id:45530000}\n"
2124 "{product_name:RE220,product_ver:2.0.0,special_id:45550000}\n"
2125 "{product_name:RE220,product_ver:2.0.0,special_id:49440000}\n"
2126 "{product_name:RE220,product_ver:2.0.0,special_id:4a500000}\n"
2127 "{product_name:RE220,product_ver:2.0.0,special_id:4b520000}\n"
2128 "{product_name:RE220,product_ver:2.0.0,special_id:52550000}\n"
2129 "{product_name:RE220,product_ver:2.0.0,special_id:54570000}\n"
2130 "{product_name:RE220,product_ver:2.0.0,special_id:55530000}\n",
2135 {"fs-uboot", 0x00000, 0x20000},
2136 {"firmware", 0x20000, 0x7a0000},
2137 {"partition-table", 0x7c0000, 0x02000},
2138 {"default-mac", 0x7c2000, 0x00020},
2139 {"pin", 0x7c2100, 0x00020},
2140 {"product-info", 0x7c3100, 0x01000},
2141 {"soft-version", 0x7c4200, 0x01000},
2142 {"support-list", 0x7c5200, 0x01000},
2143 {"profile", 0x7c6200, 0x08000},
2144 {"config-info", 0x7ce200, 0x00400},
2145 {"user-config", 0x7d0000, 0x10000},
2146 {"default-config", 0x7e0000, 0x10000},
2147 {"radio", 0x7f0000, 0x10000},
2151 .first_sysupgrade_partition
= "os-image",
2152 .last_sysupgrade_partition
= "file-system"
2155 /** Firmware layout for the RE305 v1 */
2161 "{product_name:RE305,product_ver:1.0.0,special_id:45550000}\n"
2162 "{product_name:RE305,product_ver:1.0.0,special_id:55530000}\n"
2163 "{product_name:RE305,product_ver:1.0.0,special_id:4a500000}\n"
2164 "{product_name:RE305,product_ver:1.0.0,special_id:42520000}\n"
2165 "{product_name:RE305,product_ver:1.0.0,special_id:4b520000}\n"
2166 "{product_name:RE305,product_ver:1.0.0,special_id:41550000}\n"
2167 "{product_name:RE305,product_ver:1.0.0,special_id:43410000}\n",
2172 {"fs-uboot", 0x00000, 0x20000},
2173 {"firmware", 0x20000, 0x5e0000},
2174 {"partition-table", 0x600000, 0x02000},
2175 {"default-mac", 0x610000, 0x00020},
2176 {"pin", 0x610100, 0x00020},
2177 {"product-info", 0x611100, 0x01000},
2178 {"soft-version", 0x620000, 0x01000},
2179 {"support-list", 0x621000, 0x01000},
2180 {"profile", 0x622000, 0x08000},
2181 {"user-config", 0x630000, 0x10000},
2182 {"default-config", 0x640000, 0x10000},
2183 {"radio", 0x7f0000, 0x10000},
2187 .first_sysupgrade_partition
= "os-image",
2188 .last_sysupgrade_partition
= "file-system"
2191 /** Firmware layout for the RE350 v1 */
2197 "{product_name:RE350,product_ver:1.0.0,special_id:45550000}\n"
2198 "{product_name:RE350,product_ver:1.0.0,special_id:00000000}\n"
2199 "{product_name:RE350,product_ver:1.0.0,special_id:41550000}\n"
2200 "{product_name:RE350,product_ver:1.0.0,special_id:55530000}\n"
2201 "{product_name:RE350,product_ver:1.0.0,special_id:43410000}\n"
2202 "{product_name:RE350,product_ver:1.0.0,special_id:4b520000}\n"
2203 "{product_name:RE350,product_ver:1.0.0,special_id:4a500000}\n",
2207 /** We're using a dynamic kernel/rootfs split here */
2209 {"fs-uboot", 0x00000, 0x20000},
2210 {"firmware", 0x20000, 0x5e0000},
2211 {"partition-table", 0x600000, 0x02000},
2212 {"default-mac", 0x610000, 0x00020},
2213 {"pin", 0x610100, 0x00020},
2214 {"product-info", 0x611100, 0x01000},
2215 {"soft-version", 0x620000, 0x01000},
2216 {"support-list", 0x621000, 0x01000},
2217 {"profile", 0x622000, 0x08000},
2218 {"user-config", 0x630000, 0x10000},
2219 {"default-config", 0x640000, 0x10000},
2220 {"radio", 0x7f0000, 0x10000},
2224 .first_sysupgrade_partition
= "os-image",
2225 .last_sysupgrade_partition
= "file-system"
2228 /** Firmware layout for the RE350K v1 */
2234 "{product_name:RE350K,product_ver:1.0.0,special_id:00000000,product_region:US}\n",
2238 /** We're using a dynamic kernel/rootfs split here */
2240 {"fs-uboot", 0x00000, 0x20000},
2241 {"firmware", 0x20000, 0xd70000},
2242 {"partition-table", 0xd90000, 0x02000},
2243 {"default-mac", 0xda0000, 0x00020},
2244 {"pin", 0xda0100, 0x00020},
2245 {"product-info", 0xda1100, 0x01000},
2246 {"soft-version", 0xdb0000, 0x01000},
2247 {"support-list", 0xdb1000, 0x01000},
2248 {"profile", 0xdb2000, 0x08000},
2249 {"user-config", 0xdc0000, 0x10000},
2250 {"default-config", 0xdd0000, 0x10000},
2251 {"device-id", 0xde0000, 0x00108},
2252 {"radio", 0xff0000, 0x10000},
2256 .first_sysupgrade_partition
= "os-image",
2257 .last_sysupgrade_partition
= "file-system"
2260 /** Firmware layout for the RE355 */
2266 "{product_name:RE355,product_ver:1.0.0,special_id:00000000}\r\n"
2267 "{product_name:RE355,product_ver:1.0.0,special_id:55530000}\r\n"
2268 "{product_name:RE355,product_ver:1.0.0,special_id:45550000}\r\n"
2269 "{product_name:RE355,product_ver:1.0.0,special_id:4A500000}\r\n"
2270 "{product_name:RE355,product_ver:1.0.0,special_id:43410000}\r\n"
2271 "{product_name:RE355,product_ver:1.0.0,special_id:41550000}\r\n"
2272 "{product_name:RE355,product_ver:1.0.0,special_id:4B520000}\r\n"
2273 "{product_name:RE355,product_ver:1.0.0,special_id:55534100}\r\n",
2277 /* We're using a dynamic kernel/rootfs split here */
2279 {"fs-uboot", 0x00000, 0x20000},
2280 {"firmware", 0x20000, 0x5e0000},
2281 {"partition-table", 0x600000, 0x02000},
2282 {"default-mac", 0x610000, 0x00020},
2283 {"pin", 0x610100, 0x00020},
2284 {"product-info", 0x611100, 0x01000},
2285 {"soft-version", 0x620000, 0x01000},
2286 {"support-list", 0x621000, 0x01000},
2287 {"profile", 0x622000, 0x08000},
2288 {"user-config", 0x630000, 0x10000},
2289 {"default-config", 0x640000, 0x10000},
2290 {"radio", 0x7f0000, 0x10000},
2294 .first_sysupgrade_partition
= "os-image",
2295 .last_sysupgrade_partition
= "file-system"
2298 /** Firmware layout for the RE450 */
2304 "{product_name:RE450,product_ver:1.0.0,special_id:00000000}\r\n"
2305 "{product_name:RE450,product_ver:1.0.0,special_id:55530000}\r\n"
2306 "{product_name:RE450,product_ver:1.0.0,special_id:45550000}\r\n"
2307 "{product_name:RE450,product_ver:1.0.0,special_id:4A500000}\r\n"
2308 "{product_name:RE450,product_ver:1.0.0,special_id:43410000}\r\n"
2309 "{product_name:RE450,product_ver:1.0.0,special_id:41550000}\r\n"
2310 "{product_name:RE450,product_ver:1.0.0,special_id:4B520000}\r\n"
2311 "{product_name:RE450,product_ver:1.0.0,special_id:55534100}\r\n",
2315 /** We're using a dynamic kernel/rootfs split here */
2317 {"fs-uboot", 0x00000, 0x20000},
2318 {"firmware", 0x20000, 0x5e0000},
2319 {"partition-table", 0x600000, 0x02000},
2320 {"default-mac", 0x610000, 0x00020},
2321 {"pin", 0x610100, 0x00020},
2322 {"product-info", 0x611100, 0x01000},
2323 {"soft-version", 0x620000, 0x01000},
2324 {"support-list", 0x621000, 0x01000},
2325 {"profile", 0x622000, 0x08000},
2326 {"user-config", 0x630000, 0x10000},
2327 {"default-config", 0x640000, 0x10000},
2328 {"radio", 0x7f0000, 0x10000},
2332 .first_sysupgrade_partition
= "os-image",
2333 .last_sysupgrade_partition
= "file-system"
2336 /** Firmware layout for the RE450 v2 */
2342 "{product_name:RE450,product_ver:2.0.0,special_id:00000000}\r\n"
2343 "{product_name:RE450,product_ver:2.0.0,special_id:55530000}\r\n"
2344 "{product_name:RE450,product_ver:2.0.0,special_id:45550000}\r\n"
2345 "{product_name:RE450,product_ver:2.0.0,special_id:4A500000}\r\n"
2346 "{product_name:RE450,product_ver:2.0.0,special_id:43410000}\r\n"
2347 "{product_name:RE450,product_ver:2.0.0,special_id:41550000}\r\n"
2348 "{product_name:RE450,product_ver:2.0.0,special_id:41530000}\r\n"
2349 "{product_name:RE450,product_ver:2.0.0,special_id:4B520000}\r\n"
2350 "{product_name:RE450,product_ver:2.0.0,special_id:42520000}\r\n",
2354 /* We're using a dynamic kernel/rootfs split here */
2356 {"fs-uboot", 0x00000, 0x20000},
2357 {"firmware", 0x20000, 0x5e0000},
2358 {"partition-table", 0x600000, 0x02000},
2359 {"default-mac", 0x610000, 0x00020},
2360 {"pin", 0x610100, 0x00020},
2361 {"product-info", 0x611100, 0x01000},
2362 {"soft-version", 0x620000, 0x01000},
2363 {"support-list", 0x621000, 0x01000},
2364 {"profile", 0x622000, 0x08000},
2365 {"user-config", 0x630000, 0x10000},
2366 {"default-config", 0x640000, 0x10000},
2367 {"radio", 0x7f0000, 0x10000},
2371 .first_sysupgrade_partition
= "os-image",
2372 .last_sysupgrade_partition
= "file-system"
2375 /** Firmware layout for the RE450 v3 */
2381 "{product_name:RE450,product_ver:3.0.0,special_id:00000000}\r\n"
2382 "{product_name:RE450,product_ver:3.0.0,special_id:55530000}\r\n"
2383 "{product_name:RE450,product_ver:3.0.0,special_id:45550000}\r\n"
2384 "{product_name:RE450,product_ver:3.0.0,special_id:4A500000}\r\n"
2385 "{product_name:RE450,product_ver:3.0.0,special_id:43410000}\r\n"
2386 "{product_name:RE450,product_ver:3.0.0,special_id:41550000}\r\n"
2387 "{product_name:RE450,product_ver:3.0.0,special_id:41530000}\r\n"
2388 "{product_name:RE450,product_ver:3.0.0,special_id:4B520000}\r\n"
2389 "{product_name:RE450,product_ver:3.0.0,special_id:42520000}\r\n",
2393 /* We're using a dynamic kernel/rootfs split here */
2395 {"fs-uboot", 0x00000, 0x20000},
2396 {"default-mac", 0x20000, 0x00020},
2397 {"pin", 0x20020, 0x00020},
2398 {"product-info", 0x21000, 0x01000},
2399 {"partition-table", 0x22000, 0x02000},
2400 {"soft-version", 0x24000, 0x01000},
2401 {"support-list", 0x25000, 0x01000},
2402 {"profile", 0x26000, 0x08000},
2403 {"user-config", 0x2e000, 0x10000},
2404 {"default-config", 0x3e000, 0x10000},
2405 {"config-info", 0x4e000, 0x00400},
2406 {"firmware", 0x50000, 0x7a0000},
2407 {"radio", 0x7f0000, 0x10000},
2411 .first_sysupgrade_partition
= "os-image",
2412 .last_sysupgrade_partition
= "file-system"
2415 /** Firmware layout for the RE455 v1 */
2421 "{product_name:RE455,product_ver:1.0.0,special_id:00000000}\r\n"
2422 "{product_name:RE455,product_ver:1.0.0,special_id:55530000}\r\n"
2423 "{product_name:RE455,product_ver:1.0.0,special_id:45550000}\r\n"
2424 "{product_name:RE455,product_ver:1.0.0,special_id:4A500000}\r\n"
2425 "{product_name:RE455,product_ver:1.0.0,special_id:43410000}\r\n"
2426 "{product_name:RE455,product_ver:1.0.0,special_id:41550000}\r\n"
2427 "{product_name:RE455,product_ver:1.0.0,special_id:41530000}\r\n"
2428 "{product_name:RE455,product_ver:1.0.0,special_id:4B520000}\r\n"
2429 "{product_name:RE455,product_ver:1.0.0,special_id:42520000}\r\n",
2433 /* We're using a dynamic kernel/rootfs split here */
2435 {"fs-uboot", 0x00000, 0x20000},
2436 {"default-mac", 0x20000, 0x00020},
2437 {"pin", 0x20020, 0x00020},
2438 {"product-info", 0x21000, 0x01000},
2439 {"partition-table", 0x22000, 0x02000},
2440 {"soft-version", 0x24000, 0x01000},
2441 {"support-list", 0x25000, 0x01000},
2442 {"profile", 0x26000, 0x08000},
2443 {"user-config", 0x2e000, 0x10000},
2444 {"default-config", 0x3e000, 0x10000},
2445 {"config-info", 0x4e000, 0x00400},
2446 {"firmware", 0x50000, 0x7a0000},
2447 {"radio", 0x7f0000, 0x10000},
2451 .first_sysupgrade_partition
= "os-image",
2452 .last_sysupgrade_partition
= "file-system"
2455 /** Firmware layout for the RE500 */
2461 "{product_name:RE500,product_ver:1.0.0,special_id:00000000}\r\n"
2462 "{product_name:RE500,product_ver:1.0.0,special_id:55530000}\r\n"
2463 "{product_name:RE500,product_ver:1.0.0,special_id:45550000}\r\n"
2464 "{product_name:RE500,product_ver:1.0.0,special_id:4A500000}\r\n"
2465 "{product_name:RE500,product_ver:1.0.0,special_id:43410000}\r\n"
2466 "{product_name:RE500,product_ver:1.0.0,special_id:41550000}\r\n"
2467 "{product_name:RE500,product_ver:1.0.0,special_id:41530000}\r\n",
2471 /* We're using a dynamic kernel/rootfs split here */
2473 {"fs-uboot", 0x00000, 0x20000},
2474 {"firmware", 0x20000, 0xde0000},
2475 {"partition-table", 0xe00000, 0x02000},
2476 {"default-mac", 0xe10000, 0x00020},
2477 {"pin", 0xe10100, 0x00020},
2478 {"product-info", 0xe11100, 0x01000},
2479 {"soft-version", 0xe20000, 0x01000},
2480 {"support-list", 0xe21000, 0x01000},
2481 {"profile", 0xe22000, 0x08000},
2482 {"user-config", 0xe30000, 0x10000},
2483 {"default-config", 0xe40000, 0x10000},
2484 {"radio", 0xff0000, 0x10000},
2488 .first_sysupgrade_partition
= "os-image",
2489 .last_sysupgrade_partition
= "file-system"
2492 /** Firmware layout for the RE650 */
2498 "{product_name:RE650,product_ver:1.0.0,special_id:00000000}\r\n"
2499 "{product_name:RE650,product_ver:1.0.0,special_id:55530000}\r\n"
2500 "{product_name:RE650,product_ver:1.0.0,special_id:45550000}\r\n"
2501 "{product_name:RE650,product_ver:1.0.0,special_id:4A500000}\r\n"
2502 "{product_name:RE650,product_ver:1.0.0,special_id:43410000}\r\n"
2503 "{product_name:RE650,product_ver:1.0.0,special_id:41550000}\r\n"
2504 "{product_name:RE650,product_ver:1.0.0,special_id:41530000}\r\n",
2508 /* We're using a dynamic kernel/rootfs split here */
2510 {"fs-uboot", 0x00000, 0x20000},
2511 {"firmware", 0x20000, 0xde0000},
2512 {"partition-table", 0xe00000, 0x02000},
2513 {"default-mac", 0xe10000, 0x00020},
2514 {"pin", 0xe10100, 0x00020},
2515 {"product-info", 0xe11100, 0x01000},
2516 {"soft-version", 0xe20000, 0x01000},
2517 {"support-list", 0xe21000, 0x01000},
2518 {"profile", 0xe22000, 0x08000},
2519 {"user-config", 0xe30000, 0x10000},
2520 {"default-config", 0xe40000, 0x10000},
2521 {"radio", 0xff0000, 0x10000},
2525 .first_sysupgrade_partition
= "os-image",
2526 .last_sysupgrade_partition
= "file-system"
2532 #define error(_ret, _errno, _str, ...) \
2534 fprintf(stderr, _str ": %s\n", ## __VA_ARGS__, \
2535 strerror(_errno)); \
2541 /** Stores a uint32 as big endian */
2542 static inline void put32(uint8_t *buf
, uint32_t val
) {
2549 static inline bool meta_partition_should_pad(enum partition_trail_value pv
)
2551 return (pv
>= 0) && (pv
<= PART_TRAIL_MAX
);
2554 /** Allocate a padded meta partition with a correctly initialised header
2555 * If the `data` pointer is NULL, then the required space is only allocated,
2556 * otherwise `data_len` bytes will be copied from `data` into the partition
2558 static struct image_partition_entry
init_meta_partition_entry(
2559 const char *name
, const void *data
, uint32_t data_len
,
2560 enum partition_trail_value pad_value
)
2562 uint32_t total_len
= sizeof(struct meta_header
) + data_len
;
2563 if (meta_partition_should_pad(pad_value
))
2566 struct image_partition_entry entry
= {
2569 .data
= malloc(total_len
)
2572 error(1, errno
, "failed to allocate meta partition entry");
2574 struct meta_header
*header
= (struct meta_header
*)entry
.data
;
2575 header
->length
= htonl(data_len
);
2579 memcpy(entry
.data
+sizeof(*header
), data
, data_len
);
2581 if (meta_partition_should_pad(pad_value
))
2582 entry
.data
[total_len
- 1] = (uint8_t) pad_value
;
2587 /** Allocates a new image partition */
2588 static struct image_partition_entry
alloc_image_partition(const char *name
, size_t len
) {
2589 struct image_partition_entry entry
= {name
, len
, malloc(len
)};
2591 error(1, errno
, "malloc");
2596 /** Frees an image partition */
2597 static void free_image_partition(struct image_partition_entry entry
) {
2601 static time_t source_date_epoch
= -1;
2602 static void set_source_date_epoch() {
2603 char *env
= getenv("SOURCE_DATE_EPOCH");
2607 source_date_epoch
= strtoull(env
, &endptr
, 10);
2608 if (errno
|| (endptr
&& *endptr
!= '\0')) {
2609 fprintf(stderr
, "Invalid SOURCE_DATE_EPOCH");
2615 /** Generates the partition-table partition */
2616 static struct image_partition_entry
make_partition_table(const struct flash_partition_entry
*p
) {
2617 struct image_partition_entry entry
= alloc_image_partition("partition-table", 0x800);
2619 char *s
= (char *)entry
.data
, *end
= (char *)(s
+entry
.size
);
2627 for (i
= 0; p
[i
].name
; i
++) {
2629 size_t w
= snprintf(s
, len
, "partition %s base 0x%05x size 0x%05x\n", p
[i
].name
, p
[i
].base
, p
[i
].size
);
2632 error(1, 0, "flash partition table overflow?");
2639 memset(s
, 0xff, end
-s
);
2645 /** Generates a binary-coded decimal representation of an integer in the range [0, 99] */
2646 static inline uint8_t bcd(uint8_t v
) {
2647 return 0x10 * (v
/10) + v
%10;
2651 /** Generates the soft-version partition */
2652 static struct image_partition_entry
make_soft_version(
2653 const struct device_info
*info
, uint32_t rev
)
2655 /** If an info string is provided, use this instead of
2656 * the structured data, and include the null-termination */
2657 if (info
->soft_ver
) {
2658 uint32_t len
= strlen(info
->soft_ver
) + 1;
2659 return init_meta_partition_entry("soft-version",
2660 info
->soft_ver
, len
, info
->part_trail
);
2665 if (source_date_epoch
!= -1)
2666 t
= source_date_epoch
;
2667 else if (time(&t
) == (time_t)(-1))
2668 error(1, errno
, "time");
2670 struct tm
*tm
= gmtime(&t
);
2672 struct soft_version s
= {
2679 .year_hi
= bcd((1900+tm
->tm_year
)/100),
2680 .year_lo
= bcd(tm
->tm_year
%100),
2681 .month
= bcd(tm
->tm_mon
+1),
2682 .day
= bcd(tm
->tm_mday
),
2684 .compat_level
= htonl(info
->soft_ver_compat_level
)
2687 if (info
->soft_ver_compat_level
== 0)
2688 return init_meta_partition_entry("soft-version", &s
,
2689 (uint8_t *)(&s
.compat_level
) - (uint8_t *)(&s
),
2692 return init_meta_partition_entry("soft-version", &s
,
2693 sizeof(s
), info
->part_trail
);
2696 /** Generates the support-list partition */
2697 static struct image_partition_entry
make_support_list(
2698 const struct device_info
*info
)
2700 uint32_t len
= strlen(info
->support_list
);
2701 return init_meta_partition_entry("support-list", info
->support_list
,
2702 len
, info
->part_trail
);
2705 /** Partition with extra-para data */
2706 static struct image_partition_entry
make_extra_para(
2707 const struct device_info
*info
, const uint8_t *extra_para
, size_t len
)
2709 return init_meta_partition_entry("extra-para", extra_para
, len
,
2713 /** Creates a new image partition with an arbitrary name from a file */
2714 static struct image_partition_entry
read_file(const char *part_name
, const char *filename
, bool add_jffs2_eof
, struct flash_partition_entry
*file_system_partition
) {
2715 struct stat statbuf
;
2717 if (stat(filename
, &statbuf
) < 0)
2718 error(1, errno
, "unable to stat file `%s'", filename
);
2720 size_t len
= statbuf
.st_size
;
2722 if (add_jffs2_eof
) {
2723 if (file_system_partition
)
2724 len
= ALIGN(len
+ file_system_partition
->base
, 0x10000) + sizeof(jffs2_eof_mark
) - file_system_partition
->base
;
2726 len
= ALIGN(len
, 0x10000) + sizeof(jffs2_eof_mark
);
2729 struct image_partition_entry entry
= alloc_image_partition(part_name
, len
);
2731 FILE *file
= fopen(filename
, "rb");
2733 error(1, errno
, "unable to open file `%s'", filename
);
2735 if (fread(entry
.data
, statbuf
.st_size
, 1, file
) != 1)
2736 error(1, errno
, "unable to read file `%s'", filename
);
2738 if (add_jffs2_eof
) {
2739 uint8_t *eof
= entry
.data
+ statbuf
.st_size
, *end
= entry
.data
+entry
.size
;
2741 memset(eof
, 0xff, end
- eof
- sizeof(jffs2_eof_mark
));
2742 memcpy(end
- sizeof(jffs2_eof_mark
), jffs2_eof_mark
, sizeof(jffs2_eof_mark
));
2751 Copies a list of image partitions into an image buffer and generates the image partition table while doing so
2753 Example image partition table:
2755 fwup-ptn partition-table base 0x00800 size 0x00800
2756 fwup-ptn os-image base 0x01000 size 0x113b45
2757 fwup-ptn file-system base 0x114b45 size 0x1d0004
2758 fwup-ptn support-list base 0x2e4b49 size 0x000d1
2760 Each line of the partition table is terminated with the bytes 09 0d 0a ("\t\r\n"),
2761 the end of the partition table is marked with a zero byte.
2763 The firmware image must contain at least the partition-table and support-list partitions
2764 to be accepted. There aren't any alignment constraints for the image partitions.
2766 The partition-table partition contains the actual flash layout; partitions
2767 from the image partition table are mapped to the corresponding flash partitions during
2768 the firmware upgrade. The support-list partition contains a list of devices supported by
2771 The base offsets in the firmware partition table are relative to the end
2772 of the vendor information block, so the partition-table partition will
2773 actually start at offset 0x1814 of the image.
2775 I think partition-table must be the first partition in the firmware image.
2777 static void put_partitions(uint8_t *buffer
, const struct flash_partition_entry
*flash_parts
, const struct image_partition_entry
*parts
) {
2779 char *image_pt
= (char *)buffer
, *end
= image_pt
+ 0x800;
2781 size_t base
= 0x800;
2782 for (i
= 0; parts
[i
].name
; i
++) {
2783 for (j
= 0; flash_parts
[j
].name
; j
++) {
2784 if (!strcmp(flash_parts
[j
].name
, parts
[i
].name
)) {
2785 if (parts
[i
].size
> flash_parts
[j
].size
)
2786 error(1, 0, "%s partition too big (more than %u bytes)", flash_parts
[j
].name
, (unsigned)flash_parts
[j
].size
);
2791 assert(flash_parts
[j
].name
);
2793 memcpy(buffer
+ base
, parts
[i
].data
, parts
[i
].size
);
2795 size_t len
= end
-image_pt
;
2796 size_t w
= snprintf(image_pt
, len
, "fwup-ptn %s base 0x%05x size 0x%05x\t\r\n", parts
[i
].name
, (unsigned)base
, (unsigned)parts
[i
].size
);
2799 error(1, 0, "image partition table overflow?");
2803 base
+= parts
[i
].size
;
2807 /** Generates and writes the image MD5 checksum */
2808 static void put_md5(uint8_t *md5
, uint8_t *buffer
, unsigned int len
) {
2812 MD5_Update(&ctx
, md5_salt
, (unsigned int)sizeof(md5_salt
));
2813 MD5_Update(&ctx
, buffer
, len
);
2814 MD5_Final(md5
, &ctx
);
2819 Generates the firmware image in factory format
2825 0000-0003 Image size (4 bytes, big endian)
2826 0004-0013 MD5 hash (hash of a 16 byte salt and the image data starting with byte 0x14)
2827 0014-0017 Vendor information length (without padding) (4 bytes, big endian)
2828 0018-1013 Vendor information (4092 bytes, padded with 0xff; there seem to be older
2829 (VxWorks-based) TP-LINK devices which use a smaller vendor information block)
2830 1014-1813 Image partition table (2048 bytes, padded with 0xff)
2831 1814-xxxx Firmware partitions
2833 static void * generate_factory_image(struct device_info
*info
, const struct image_partition_entry
*parts
, size_t *len
) {
2837 for (i
= 0; parts
[i
].name
; i
++)
2838 *len
+= parts
[i
].size
;
2840 uint8_t *image
= malloc(*len
);
2842 error(1, errno
, "malloc");
2844 memset(image
, 0xff, *len
);
2848 size_t vendor_len
= strlen(info
->vendor
);
2849 put32(image
+0x14, vendor_len
);
2850 memcpy(image
+0x18, info
->vendor
, vendor_len
);
2853 put_partitions(image
+ 0x1014, info
->partitions
, parts
);
2854 put_md5(image
+0x04, image
+0x14, *len
-0x14);
2860 Generates the firmware image in sysupgrade format
2862 This makes some assumptions about the provided flash and image partition tables and
2863 should be generalized when TP-LINK starts building its safeloader into hardware with
2864 different flash layouts.
2866 static void * generate_sysupgrade_image(struct device_info
*info
, const struct image_partition_entry
*image_parts
, size_t *len
) {
2868 size_t flash_first_partition_index
= 0;
2869 size_t flash_last_partition_index
= 0;
2870 const struct flash_partition_entry
*flash_first_partition
= NULL
;
2871 const struct flash_partition_entry
*flash_last_partition
= NULL
;
2872 const struct image_partition_entry
*image_last_partition
= NULL
;
2874 /** Find first and last partitions */
2875 for (i
= 0; info
->partitions
[i
].name
; i
++) {
2876 if (!strcmp(info
->partitions
[i
].name
, info
->first_sysupgrade_partition
)) {
2877 flash_first_partition
= &info
->partitions
[i
];
2878 flash_first_partition_index
= i
;
2879 } else if (!strcmp(info
->partitions
[i
].name
, info
->last_sysupgrade_partition
)) {
2880 flash_last_partition
= &info
->partitions
[i
];
2881 flash_last_partition_index
= i
;
2885 assert(flash_first_partition
&& flash_last_partition
);
2886 assert(flash_first_partition_index
< flash_last_partition_index
);
2888 /** Find last partition from image to calculate needed size */
2889 for (i
= 0; image_parts
[i
].name
; i
++) {
2890 if (!strcmp(image_parts
[i
].name
, info
->last_sysupgrade_partition
)) {
2891 image_last_partition
= &image_parts
[i
];
2896 assert(image_last_partition
);
2898 *len
= flash_last_partition
->base
- flash_first_partition
->base
+ image_last_partition
->size
;
2900 uint8_t *image
= malloc(*len
);
2902 error(1, errno
, "malloc");
2904 memset(image
, 0xff, *len
);
2906 for (i
= flash_first_partition_index
; i
<= flash_last_partition_index
; i
++) {
2907 for (j
= 0; image_parts
[j
].name
; j
++) {
2908 if (!strcmp(info
->partitions
[i
].name
, image_parts
[j
].name
)) {
2909 if (image_parts
[j
].size
> info
->partitions
[i
].size
)
2910 error(1, 0, "%s partition too big (more than %u bytes)", info
->partitions
[i
].name
, (unsigned)info
->partitions
[i
].size
);
2911 memcpy(image
+ info
->partitions
[i
].base
- flash_first_partition
->base
, image_parts
[j
].data
, image_parts
[j
].size
);
2915 assert(image_parts
[j
].name
);
2922 /** Generates an image according to a given layout and writes it to a file */
2923 static void build_image(const char *output
,
2924 const char *kernel_image
,
2925 const char *rootfs_image
,
2929 struct device_info
*info
) {
2933 struct image_partition_entry parts
[7] = {};
2935 struct flash_partition_entry
*firmware_partition
= NULL
;
2936 struct flash_partition_entry
*os_image_partition
= NULL
;
2937 struct flash_partition_entry
*file_system_partition
= NULL
;
2938 size_t firmware_partition_index
= 0;
2940 for (i
= 0; info
->partitions
[i
].name
; i
++) {
2941 if (!strcmp(info
->partitions
[i
].name
, "firmware"))
2943 firmware_partition
= &info
->partitions
[i
];
2944 firmware_partition_index
= i
;
2948 if (firmware_partition
)
2950 os_image_partition
= &info
->partitions
[firmware_partition_index
];
2951 file_system_partition
= &info
->partitions
[firmware_partition_index
+ 1];
2954 if (stat(kernel_image
, &kernel
) < 0)
2955 error(1, errno
, "unable to stat file `%s'", kernel_image
);
2957 if (kernel
.st_size
> firmware_partition
->size
)
2958 error(1, 0, "kernel overflowed firmware partition\n");
2960 for (i
= MAX_PARTITIONS
-1; i
>= firmware_partition_index
+ 1; i
--)
2961 info
->partitions
[i
+1] = info
->partitions
[i
];
2963 file_system_partition
->name
= "file-system";
2964 file_system_partition
->base
= firmware_partition
->base
+ kernel
.st_size
;
2966 /* Align partition start to erase blocks for factory images only */
2968 file_system_partition
->base
= ALIGN(firmware_partition
->base
+ kernel
.st_size
, 0x10000);
2970 file_system_partition
->size
= firmware_partition
->size
- file_system_partition
->base
;
2972 os_image_partition
->name
= "os-image";
2973 os_image_partition
->size
= kernel
.st_size
;
2976 parts
[0] = make_partition_table(info
->partitions
);
2977 parts
[1] = make_soft_version(info
, rev
);
2978 parts
[2] = make_support_list(info
);
2979 parts
[3] = read_file("os-image", kernel_image
, false, NULL
);
2980 parts
[4] = read_file("file-system", rootfs_image
, add_jffs2_eof
, file_system_partition
);
2982 /* Some devices need the extra-para partition to accept the firmware */
2983 if (strcasecmp(info
->id
, "ARCHER-A6-V3") == 0 ||
2984 strcasecmp(info
->id
, "ARCHER-A7-V5") == 0 ||
2985 strcasecmp(info
->id
, "ARCHER-C2-V3") == 0 ||
2986 strcasecmp(info
->id
, "ARCHER-C7-V4") == 0 ||
2987 strcasecmp(info
->id
, "ARCHER-C7-V5") == 0 ||
2988 strcasecmp(info
->id
, "ARCHER-C25-V1") == 0 ||
2989 strcasecmp(info
->id
, "ARCHER-C59-V2") == 0 ||
2990 strcasecmp(info
->id
, "ARCHER-C60-V2") == 0 ||
2991 strcasecmp(info
->id
, "ARCHER-C60-V3") == 0 ||
2992 strcasecmp(info
->id
, "ARCHER-C6U-V1") == 0 ||
2993 strcasecmp(info
->id
, "ARCHER-C6-V3") == 0 ||
2994 strcasecmp(info
->id
, "TLWR1043NV5") == 0) {
2995 const uint8_t extra_para
[2] = {0x01, 0x00};
2996 parts
[5] = make_extra_para(info
, extra_para
,
2997 sizeof(extra_para
));
2998 } else if (strcasecmp(info
->id
, "ARCHER-C6-V2") == 0) {
2999 const uint8_t extra_para
[2] = {0x00, 0x01};
3000 parts
[5] = make_extra_para(info
, extra_para
,
3001 sizeof(extra_para
));
3002 } else if (strcasecmp(info
->id
, "ARCHER-C6-V2-US") == 0 ||
3003 strcasecmp(info
->id
, "EAP245-V3") == 0) {
3004 const uint8_t extra_para
[2] = {0x01, 0x01};
3005 parts
[5] = make_extra_para(info
, extra_para
,
3006 sizeof(extra_para
));
3012 image
= generate_sysupgrade_image(info
, parts
, &len
);
3014 image
= generate_factory_image(info
, parts
, &len
);
3016 FILE *file
= fopen(output
, "wb");
3018 error(1, errno
, "unable to open output file");
3020 if (fwrite(image
, len
, 1, file
) != 1)
3021 error(1, 0, "unable to write output file");
3027 for (i
= 0; parts
[i
].name
; i
++)
3028 free_image_partition(parts
[i
]);
3032 static void usage(const char *argv0
) {
3034 "Usage: %s [OPTIONS...]\n"
3037 " -h show this help\n"
3039 "Info about an image:\n"
3040 " -i <file> input file to read from\n"
3041 "Create a new image:\n"
3042 " -B <board> create image for the board specified with <board>\n"
3043 " -k <file> read kernel image from the file <file>\n"
3044 " -r <file> read rootfs image from the file <file>\n"
3045 " -o <file> write output to the file <file>\n"
3046 " -V <rev> sets the revision number to <rev>\n"
3047 " -j add jffs2 end-of-filesystem markers\n"
3048 " -S create sysupgrade instead of factory image\n"
3049 "Extract an old image:\n"
3050 " -x <file> extract all oem firmware partition\n"
3051 " -d <dir> destination to extract the firmware partition\n"
3052 " -z <file> convert an oem firmware into a sysupgade file. Use -o for output file\n",
3058 static struct device_info
*find_board(const char *id
)
3060 struct device_info
*board
= NULL
;
3062 for (board
= boards
; board
->id
!= NULL
; board
++)
3063 if (strcasecmp(id
, board
->id
) == 0)
3069 static int add_flash_partition(
3070 struct flash_partition_entry
*part_list
,
3077 /* check if the list has a free entry */
3078 for (ptr
= 0; ptr
< max_entries
; ptr
++, part_list
++) {
3079 if (part_list
->name
== NULL
&&
3080 part_list
->base
== 0 &&
3081 part_list
->size
== 0)
3085 if (ptr
== max_entries
) {
3086 error(1, 0, "No free flash part entry available.");
3089 part_list
->name
= calloc(1, strlen(name
) + 1);
3090 if (!part_list
->name
) {
3091 error(1, 0, "Unable to allocate memory");
3094 memcpy((char *)part_list
->name
, name
, strlen(name
));
3095 part_list
->base
= base
;
3096 part_list
->size
= size
;
3101 /** read the partition table into struct flash_partition_entry */
3102 static int read_partition_table(
3103 FILE *file
, long offset
,
3104 struct flash_partition_entry
*entries
, size_t max_entries
,
3109 const char *parthdr
= NULL
;
3110 const char *fwuphdr
= "fwup-ptn";
3111 const char *flashhdr
= "partition";
3113 /* TODO: search for the partition table */
3123 error(1, 0, "Invalid partition table");
3126 if (fseek(file
, offset
, SEEK_SET
) < 0)
3127 error(1, errno
, "Can not seek in the firmware");
3129 if (fread(buf
, 2048, 1, file
) != 1)
3130 error(1, errno
, "Can not read fwup-ptn from the firmware");
3134 /* look for the partition header */
3135 if (memcmp(buf
, parthdr
, strlen(parthdr
)) != 0) {
3136 fprintf(stderr
, "DEBUG: can not find fwuphdr\n");
3141 end
= buf
+ sizeof(buf
);
3142 while ((ptr
+ strlen(parthdr
)) < end
&&
3143 memcmp(ptr
, parthdr
, strlen(parthdr
)) == 0) {
3147 char name
[32] = { 0 };
3149 unsigned long base
= 0;
3150 unsigned long size
= 0;
3152 end_part
= memchr(ptr
, '\n', (end
- ptr
));
3153 if (end_part
== NULL
) {
3154 /* in theory this should never happen, because a partition always ends with 0x09, 0x0D, 0x0A */
3158 for (int i
= 0; i
<= 4; i
++) {
3159 if (end_part
<= ptr
)
3162 end_element
= memchr(ptr
, 0x20, (end_part
- ptr
));
3163 if (end_element
== NULL
) {
3164 error(1, errno
, "Ignoring the rest of the partition entries.");
3169 /* partition header */
3171 ptr
= end_element
+ 1;
3175 name_len
= (end_element
- ptr
) > 31 ? 31 : (end_element
- ptr
);
3176 strncpy(name
, ptr
, name_len
);
3177 name
[name_len
] = '\0';
3178 ptr
= end_element
+ 1;
3183 ptr
= end_element
+ 1;
3188 base
= strtoul(ptr
, NULL
, 16);
3189 ptr
= end_element
+ 1;
3194 ptr
= end_element
+ 1;
3195 /* actual size. The last element doesn't have a sepeartor */
3196 size
= strtoul(ptr
, NULL
, 16);
3197 /* the part ends with 0x09, 0x0d, 0x0a */
3199 add_flash_partition(entries
, max_entries
, name
, base
, size
);
3208 static void write_partition(
3210 size_t firmware_offset
,
3211 struct flash_partition_entry
*entry
,
3217 fseek(input_file
, entry
->base
+ firmware_offset
, SEEK_SET
);
3219 for (offset
= 0; sizeof(buf
) + offset
<= entry
->size
; offset
+= sizeof(buf
)) {
3220 if (fread(buf
, sizeof(buf
), 1, input_file
) != 1)
3221 error(1, errno
, "Can not read partition from input_file");
3223 if (fwrite(buf
, sizeof(buf
), 1, output_file
) != 1)
3224 error(1, errno
, "Can not write partition to output_file");
3226 /* write last chunk smaller than buffer */
3227 if (offset
< entry
->size
) {
3228 offset
= entry
->size
- offset
;
3229 if (fread(buf
, offset
, 1, input_file
) != 1)
3230 error(1, errno
, "Can not read partition from input_file");
3231 if (fwrite(buf
, offset
, 1, output_file
) != 1)
3232 error(1, errno
, "Can not write partition to output_file");
3236 static int extract_firmware_partition(FILE *input_file
, size_t firmware_offset
, struct flash_partition_entry
*entry
, const char *output_directory
)
3239 char output
[PATH_MAX
];
3241 snprintf(output
, PATH_MAX
, "%s/%s", output_directory
, entry
->name
);
3242 output_file
= fopen(output
, "wb+");
3243 if (output_file
== NULL
) {
3244 error(1, errno
, "Can not open output file %s", output
);
3247 write_partition(input_file
, firmware_offset
, entry
, output_file
);
3249 fclose(output_file
);
3254 /** extract all partitions from the firmware file */
3255 static int extract_firmware(const char *input
, const char *output_directory
)
3257 struct flash_partition_entry entries
[16] = { 0 };
3258 size_t max_entries
= 16;
3259 size_t firmware_offset
= 0x1014;
3262 struct stat statbuf
;
3264 /* check input file */
3265 if (stat(input
, &statbuf
)) {
3266 error(1, errno
, "Can not read input firmware %s", input
);
3269 /* check if output directory exists */
3270 if (stat(output_directory
, &statbuf
)) {
3271 error(1, errno
, "Failed to stat output directory %s", output_directory
);
3274 if ((statbuf
.st_mode
& S_IFMT
) != S_IFDIR
) {
3275 error(1, errno
, "Given output directory is not a directory %s", output_directory
);
3278 input_file
= fopen(input
, "rb");
3280 if (read_partition_table(input_file
, firmware_offset
, entries
, 16, 0) != 0) {
3281 error(1, 0, "Error can not read the partition table (fwup-ptn)");
3284 for (size_t i
= 0; i
< max_entries
; i
++) {
3285 if (entries
[i
].name
== NULL
&&
3286 entries
[i
].base
== 0 &&
3287 entries
[i
].size
== 0)
3290 extract_firmware_partition(input_file
, firmware_offset
, &entries
[i
], output_directory
);
3296 static struct flash_partition_entry
*find_partition(
3297 struct flash_partition_entry
*entries
, size_t max_entries
,
3298 const char *name
, const char *error_msg
)
3300 for (size_t i
= 0; i
< max_entries
; i
++, entries
++) {
3301 if (strcmp(entries
->name
, name
) == 0)
3306 error(1, 0, "%s", error_msg
);
3312 static int firmware_info(const char *input
)
3314 struct flash_partition_entry pointers
[MAX_PARTITIONS
] = { };
3315 struct flash_partition_entry
*e
;
3319 fp
= fopen(input
, "r");
3321 if (read_partition_table(fp
, 0x1014, pointers
, MAX_PARTITIONS
, 0)) {
3322 error(1, 0, "Error can not read the partition table (fwup-ptn)");
3325 printf("Firmware image partitions:\n");
3326 printf("%-8s %-8s %s\n", "base", "size", "name");
3327 for (i
= 0; i
< MAX_PARTITIONS
; i
++) {
3330 if (!e
->name
&& !e
->base
&& !e
->size
)
3333 printf("%08x %08x %s\n", e
->base
, e
->size
, e
->name
? e
->name
: "");
3336 e
= find_partition(pointers
, MAX_PARTITIONS
, "soft-version", NULL
);
3338 size_t data_len
= e
->size
- sizeof(struct meta_header
);
3339 char *buf
= malloc(data_len
);
3340 struct soft_version
*s
;
3345 error(1, errno
, "Failed to alloc buffer");
3347 if (fseek(fp
, 0x1014 + e
->base
+ sizeof(struct meta_header
), SEEK_SET
))
3348 error(1, errno
, "Can not seek in the firmware");
3350 if (fread(buf
, data_len
, 1, fp
) != 1)
3351 error(1, errno
, "Can not read fwup-ptn data from the firmware");
3353 /* Check for string ignoring padding character */
3355 for (i
= 0; i
< data_len
- 1; i
++) {
3356 if (!isascii(buf
[i
])) {
3362 printf("\n[Software version]\n");
3364 fwrite(buf
, data_len
, 1, stdout
);
3366 } else if (data_len
>= offsetof(struct soft_version
, rev
)) {
3367 s
= (struct soft_version
*)buf
;
3369 printf("Version: %d.%d.%d\n", s
->version_major
, s
->version_minor
, s
->version_patch
);
3370 printf("Date: %02x%02x-%02x-%02x\n", s
->year_hi
, s
->year_lo
, s
->month
, s
->day
);
3372 printf("Failed to parse data\n");
3378 e
= find_partition(pointers
, MAX_PARTITIONS
, "support-list", NULL
);
3384 if (fseek(fp
, 0x1014 + e
->base
+ sizeof(struct meta_header
), SEEK_SET
))
3385 error(1, errno
, "Can not seek in the firmware");
3387 printf("\n[Support list]\n");
3388 for (length
= e
->size
- sizeof(struct meta_header
); length
; length
-= bytes
) {
3389 bytes
= fread(buf
, 1, length
> sizeof(buf
) ? sizeof(buf
) : length
, fp
);
3391 error(1, errno
, "Can not read fwup-ptn data from the firmware");
3397 e
= find_partition(pointers
, MAX_PARTITIONS
, "partition-table", NULL
);
3399 struct flash_partition_entry parts
[MAX_PARTITIONS
] = { };
3401 if (read_partition_table(fp
, 0x1014 + e
->base
+ 4, parts
, MAX_PARTITIONS
, 1)) {
3402 error(1, 0, "Error can not read the partition table (partition)");
3405 printf("\n[Partition table]\n");
3406 printf("%-8s %-8s %s\n", "base", "size", "name");
3407 for (i
= 0; i
< MAX_PARTITIONS
; i
++) {
3410 if (!e
->name
&& !e
->base
&& !e
->size
)
3413 printf("%08x %08x %s\n", e
->base
, e
->size
, e
->name
? e
->name
: "");
3422 static void write_ff(FILE *output_file
, size_t size
)
3427 memset(buf
, 0xff, sizeof(buf
));
3429 for (offset
= 0; offset
+ sizeof(buf
) < size
; offset
+= sizeof(buf
)) {
3430 if (fwrite(buf
, sizeof(buf
), 1, output_file
) != 1)
3431 error(1, errno
, "Can not write 0xff to output_file");
3434 /* write last chunk smaller than buffer */
3435 if (offset
< size
) {
3436 offset
= size
- offset
;
3437 if (fwrite(buf
, offset
, 1, output_file
) != 1)
3438 error(1, errno
, "Can not write partition to output_file");
3442 static void convert_firmware(const char *input
, const char *output
)
3444 struct flash_partition_entry fwup
[MAX_PARTITIONS
] = { 0 };
3445 struct flash_partition_entry flash
[MAX_PARTITIONS
] = { 0 };
3446 struct flash_partition_entry
*fwup_os_image
= NULL
, *fwup_file_system
= NULL
;
3447 struct flash_partition_entry
*flash_os_image
= NULL
, *flash_file_system
= NULL
;
3448 struct flash_partition_entry
*fwup_partition_table
= NULL
;
3449 size_t firmware_offset
= 0x1014;
3450 FILE *input_file
, *output_file
;
3452 struct stat statbuf
;
3454 /* check input file */
3455 if (stat(input
, &statbuf
)) {
3456 error(1, errno
, "Can not read input firmware %s", input
);
3459 input_file
= fopen(input
, "rb");
3461 error(1, 0, "Can not open input firmware %s", input
);
3463 output_file
= fopen(output
, "wb");
3465 error(1, 0, "Can not open output firmware %s", output
);
3467 if (read_partition_table(input_file
, firmware_offset
, fwup
, MAX_PARTITIONS
, 0) != 0) {
3468 error(1, 0, "Error can not read the partition table (fwup-ptn)");
3471 fwup_os_image
= find_partition(fwup
, MAX_PARTITIONS
,
3472 "os-image", "Error can not find os-image partition (fwup)");
3473 fwup_file_system
= find_partition(fwup
, MAX_PARTITIONS
,
3474 "file-system", "Error can not find file-system partition (fwup)");
3475 fwup_partition_table
= find_partition(fwup
, MAX_PARTITIONS
,
3476 "partition-table", "Error can not find partition-table partition");
3478 /* the flash partition table has a 0x00000004 magic haeder */
3479 if (read_partition_table(input_file
, firmware_offset
+ fwup_partition_table
->base
+ 4, flash
, MAX_PARTITIONS
, 1) != 0)
3480 error(1, 0, "Error can not read the partition table (flash)");
3482 flash_os_image
= find_partition(flash
, MAX_PARTITIONS
,
3483 "os-image", "Error can not find os-image partition (flash)");
3484 flash_file_system
= find_partition(flash
, MAX_PARTITIONS
,
3485 "file-system", "Error can not find file-system partition (flash)");
3487 /* write os_image to 0x0 */
3488 write_partition(input_file
, firmware_offset
, fwup_os_image
, output_file
);
3489 write_ff(output_file
, flash_os_image
->size
- fwup_os_image
->size
);
3491 /* write file-system behind os_image */
3492 fseek(output_file
, flash_file_system
->base
- flash_os_image
->base
, SEEK_SET
);
3493 write_partition(input_file
, firmware_offset
, fwup_file_system
, output_file
);
3494 write_ff(output_file
, flash_file_system
->size
- fwup_file_system
->size
);
3496 fclose(output_file
);
3500 int main(int argc
, char *argv
[]) {
3501 const char *info_image
= NULL
, *board
= NULL
, *kernel_image
= NULL
, *rootfs_image
= NULL
, *output
= NULL
;
3502 const char *extract_image
= NULL
, *output_directory
= NULL
, *convert_image
= NULL
;
3503 bool add_jffs2_eof
= false, sysupgrade
= false;
3505 struct device_info
*info
;
3506 set_source_date_epoch();
3511 c
= getopt(argc
, argv
, "i:B:k:r:o:V:jSh:x:d:z:");
3517 info_image
= optarg
;
3525 kernel_image
= optarg
;
3529 rootfs_image
= optarg
;
3537 sscanf(optarg
, "r%u", &rev
);
3541 add_jffs2_eof
= true;
3553 output_directory
= optarg
;
3557 extract_image
= optarg
;
3561 convert_image
= optarg
;
3571 firmware_info(info_image
);
3572 } else if (extract_image
|| output_directory
) {
3574 error(1, 0, "No factory/oem image given via -x <file>. Output directory is only valid with -x");
3575 if (!output_directory
)
3576 error(1, 0, "Can not extract an image without output directory. Use -d <dir>");
3577 extract_firmware(extract_image
, output_directory
);
3578 } else if (convert_image
) {
3580 error(1, 0, "Can not convert a factory/oem image into sysupgrade image without output file. Use -o <file>");
3581 convert_firmware(convert_image
, output
);
3584 error(1, 0, "no board has been specified");
3586 error(1, 0, "no kernel image has been specified");
3588 error(1, 0, "no rootfs image has been specified");
3590 error(1, 0, "no output filename has been specified");
3592 info
= find_board(board
);
3595 error(1, 0, "unsupported board %s", board
);
3597 build_image(output
, kernel_image
, rootfs_image
, rev
, add_jffs2_eof
, sysupgrade
, info
);