nand: kernel inside the UBIFS rootfs, volumes sized by their images; retire the old NAND layouts - #2537
Conversation
NAND images no longer set aside flash for a kernel. The UBI device now holds two volumes: - rootfs: UBIFS, with the kernel in it as /boot/fitImage (zImage + DTB, each hashed); - rootfs_data: the overlay. external.mk adds the kernel to the UBIFS image's own copy of the target tree, so the NOR squashfs is unchanged. It is one file, never two: the FIT where the board builds one, otherwise the uImage. u-boot-xmedia boots either. ubinize-nand.cfg gives rootfs no vol_size, so the volume is exactly as big as its image, and rootfs_data takes the rest. The hi3516ev200 family (hi3516ev200, hi3516ev300, hi3518ev300) moves to this layout from the retired split one (a uImage in a raw `kernel` partition, UBIFS root beside it). Its nand-fit.its names the DTB as @dtb@, since each model builds its own <model>-demb.dtb; rootfs_script.sh stamps it alongside @soc@. hi3516av100, av200, dv100, cv300 and hi3518ev200 stop building NAND images: none has a bootloader that can install or boot this layout. Their NOR images are unchanged. The NAND package carries rootfs.ubifs, rootfs.ubi for a fresh install, and fitImage as the SoC witness. The only size gate is rootfs.ubi at 24M, the RAM a fresh install stages it in; no volume bounds either image. sysupgrade: - ubifs layout (rootfs volume, no kernel volume, no kernel partition): an upgrade writes the one image and resizes the volumes to it. As PID 1 in the RAM root it copies the settings out of rootfs_data, removes that volume, resizes rootfs to the image, writes it, recreates rootfs_data on what is left and puts the settings back. -k means writing the rootfs, since the kernel is in it. -r -n skips the copy. The room checked is both volumes less the settings, not the old rootfs volume. - The split layout is refused before anything is touched, kernel-only runs included. Without that refusal the MTD path flashcp'd a NOR squashfs through gluebi over the mounted UBIFS volume. - The earlier layout with a separate kernel volume is refused the same way. Both refusals point at the reinstall instructions on openipc.org. - ubiblock cameras are unchanged. The offline harness covers all of it: 253 checks pass. Verified on a hi3516ev300 (W25N01GV NAND, 5 factory bad blocks): - Installed from u-boot-xmedia with the openipc.org commands: tftpboot rootfs.ubi, nand erase 0x100000 0x7f00000, nand write.trimffs. - U-Boot loads /boot/fitImage from UBIFS, the hashes pass, and the kernel mounts root=ubi0:rootfs read-only, the UBIFS overlay read-write. - sysupgrade -r from a local package, with a marker in the overlay: - the first run rewrote rootfs at the same 155 LEBs; the second, with an image 2 MB smaller, shrank it from 155 to 138 LEBs. Growing a volume is covered by the harness only; - rootfs_data was recreated each time on the rest (837 and 854 LEBs); - the marker and the SSH key survived both runs; - the camera rebooted each time and came back booting the FIT. - The same camera, still on the split layout, refused an upgrade: "retired split NAND layout ... nothing was written", exit 1, /proc/mtd unchanged.
The squashfs-over-ubiblock layout keeps its kernel in a sized volume of its own, as the first FIT layout does. It is retired the same way: a run that would write either half is refused before anything is touched, with the reinstall link. -n alone still empties the settings volume. Also gone: the gluebi path an old ubiblock camera took when its inittab had no ::restart: entry, and check_rootfs_format's ubiblock branch, which nothing reaches now. Images on the retired layout still boot; init keeps mounting their overlay. Only upgrades are refused. A NAND camera upgrades from a -nand- package only, which the ultimate builds of the hi3516ev200 and gk7205v500 families ship. Harness: 244 checks pass.
PR Summary by QodoBoot NAND kernels from UBIFS and retire unsafe upgrade layouts
AI Description
Diagram
High-Level Assessment
Files changed (17)
|
Code Review by Qodo
1.
|
Review on #2537. - ubiblock is retired only on the SoCs whose NAND images moved to the kernel-in-rootfs layout: gk7205v500, v510, v530, hi3516ev200, hi3516ev300, hi3518ev300 and hi3516dv200 (nand_layout_moved). SigmaStar and Rockchip NAND images are still ubiblock-shaped, so everywhere else the ubiblock write path stays: the kernel volume is written in place, the rootfs goes through the hand-off, and old-inittab cameras keep the gluebi fallback. - Keeping the settings on an upgrade now has to work before anything changes. If the read-only mount or the copy into RAM fails, the run stops with nothing written, and -n remains the way to upgrade without the settings. The archive's real size, which counts sparse files at full length, is then checked against the room beside the new image before the first volume operation. - --kernel=FILE alone on the ubifs layout is refused: the kernel lives inside rootfs.ubifs and has to come with --rootfs=. Previously the run wrote whatever rootfs was at the default path. A remote -k still becomes a rootfs write. - The split-layout refusal links to the camera's own vendor page, not always hisilicon's. Harness: 257 checks pass. New cases: ubiblock writes on ssc338q, ubiblock refused on gk7205v500 with and without ::restart:, --kernel alone refused, and unreadable settings stopping stage 2 before any volume is touched.
The u-boot-xmedia SoCs (hi3516ev200/ev300/dv200, hi3518ev300, gk7205v500/v510/v530) moved to one NAND layout. It landed in OpenIPC/u-boot-xmedia#11 and #12, OpenIPC/firmware#2537, and OpenIPC/website#392 and #393: ``` 0x000000 boot 768K u-boot-<soc>-nand.bin 0x0C0000 env 256K 0x100000 ubi rest rootfs.ubi.<board>: UBIFS rootfs (kernel inside, /boot/fitImage) + rootfs_data ``` defib still installed the retired split layout on these SoCs and downloaded the retired `-universal` bootloader for them. ## Install (`install --nand`) For these SoCs `install --nand` now: - writes `u-boot-<soc>-nand.bin` into 0..0xc0000; - writes `rootfs.ubi.<board>` with `nand erase.part ubi` and `nand write.trimffs`, then reads it back and CRC-checks it; - runs `env default -a`, restores the MAC, and saves. **Never sent:** `setenv mtdparts`, `mtdids`, `bootcmd`, `bootargs`, or `ubi part`/`create`/`write`. **Kernel and `rootfs-data` stages:** no-ops. The kernel and an empty `rootfs_data` are inside the UBI image. **Erase safety:** - The installer checks that `mtdparts` puts `ubi` at 0x100000 before erasing. - It falls back to `nand erase 0x100000` (to the chip end) where `erase.part` is unavailable. - Other chips keep the split-layout path. ## Bootloader names These seven SoCs resolve per flash type, to `u-boot-<soc>-nor.bin` or `u-boot-<soc>-nand.bin`. - `install` follows `--nand`. `burn` gains `--nand` and defaults to NOR. `restore --flash-type` follows the flash type. - The `-universal` image is never downloaded for them, and a stale cached one doesn't stand in for the new build. - Every other chip is unchanged. ## Web UI - Takes the `-nor` build for these SoCs. - Now cuts the SPL where the compressed payload starts (`detectSplSize`, a port of `HiSiliconStandard._detect_spl_size`). The u-boot-xmedia images put it at 0x4400, while the profile says 0x6000. Sending the profile length writes into SRAM the boot ROM uses for its own state. ## Verified On a hi3516ev300 (W25N01GV, 128 MiB, 5 factory bad blocks), `defib install -c hi3516ev300 --nand --power-cycle` with the NAND package and the u-boot-xmedia master NAND image ran end to end: - burned U-Boot to RAM from the boot ROM; - `U-Boot OK`; - `Erased ubi: 0x100000, 0x7F00000 bytes`; - `Flash verified: E2E60EAA`; - `Restoring factory ethaddr`, `Environment saved`; - rebooted into OpenIPC, which booted `/boot/fitImage` and came up on the network. Separately, `defib burn -c hi3516ev300 -f u-boot-hi3516ev300-nand.bin` loaded the u-boot-xmedia image from the boot ROM; defib found its gzip SPL boundary at 0x4400. ## Tests - pytest: 1020 passed. ruff and mypy clean. - New `tests/test_nand_ubi_install.py`: the exact console sequence, the erase fallback, the missing-`mtdparts` path, refusing a relocated `ubi`, an env-only run, and a NOR install taking `-nor` over a cached `-universal`. - `tests/test_firmware.py` covers names per flash type. - Web tests: 92 pass. The new `detectSplSize` gives 0x4400 on the real hi3516ev300 image. ## Not verified on hardware - The gk7205v5xx and hi3516dv200 paths. - The Web UI recovery with the `-nor` images. - The `erase.part` fallback on a U-Boot without it.
hi3516ev200, hi3516ev300 and hi3518ev300 now boot the bootloader OpenIPC/u-boot-xmedia builds (#11 there). It publishes them per flash type as u-boot-<soc>-nor.bin and u-boot-<soc>-nand.bin, and carries the UBI-only NAND layout the firmware installs (OpenIPC/firmware#2537). openipc.org and defib take those now. The publish job would keep overwriting u-boot-<soc>-universal.bin in the OpenIPC/firmware release with a build nothing should load, so it goes. The build and the QEMU smoke test stay as CI for this tree.
Follows OpenIPC/u-boot-xmedia#11, which boots a NAND kernel from the UBIFS rootfs and is now the bootloader for the hi3516ev200 family.
Layout
external.mkcopies the kernel into the UBIFS image's own copy of the target tree. That is the FIT where the board builds one, otherwise the uImage; always exactly one file. The NOR squashfs is unchanged.ubinize-nand.cfggivesrootfsnovol_size, so the volume is exactly as big as its image, androotfs_datatakes the rest. The only size gate isrootfs.ubiat 24M, the RAM a fresh install stages it in.rootfs.ubifs,rootfs.ubi(fresh install), andfitImageas the SoC witness.Boards
kernelpartition).board/hi3516ev200/nand-fit.itsnames its DTB@DTB@, because each model builds its own<model>-demb.dtb.rootfs_script.shstamps the DTB name along with@SOC@.sysupgrade
New layout (
ubifs). An upgrade writes the one image and resizes the volumes to fit it. Running as PID 1 in the RAM root, it:rootfs_data;rootfsto the image (ubirsvol);rootfs_dataon what is left (ubimkvol -m);Related behaviour:
-kmeans writing the rootfs, since the kernel lives in it.-r -nskips the settings copy.Retired layouts are refused before anything is downloaded or written, with a link to the reinstall instructions. This covers:
-non its own is still allowed. Without the split-layout refusal, sysupgrade wrote a NOR squashfs through gluebi over the mounted UBIFS volume and bricked the camera. Retired cameras still boot; only their upgrades are refused.The offline harness passes 244 checks, including new scenarios for each of these paths.
Verified on a hi3516ev300 (W25N01GV NAND, 5 factory bad blocks)
/proc/mtdunchanged.rootfs.ubiwritten withnand write.trimffs. U-Boot loads/boot/fitImagefrom UBIFS withcrc32+ sha1+ OK, and the kernel bootsroot=ubi0:rootfs.sysupgrade -rfrom a local package, with a marker in the overlay, run twice:rootfsstayed at 155 LEBs.rootfsshrank to 138 LEBs androotfs_datawas recreated on the rest.Not covered on hardware: growing a volume (harness only),
-non this layout (harness only), and the gk7205v500 family on this layout (same code path, built in CI).