mirror of
https://github.com/logicog/RTLPlayground.git
synced 2026-08-30 14:52:51 +08:00
Update Readme
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
# Understanding the image using ghidra
|
||||
Start ghidra, load file starting from offset 0x0002 into
|
||||
memory starting at 0x0000. The lengthe is 0x10000. Select generic 8051, big
|
||||
endian.
|
||||
|
||||
After loading, the boot vector is at 0x0000, which will jump to 0x0100 for
|
||||
the boot routine.
|
||||
|
||||
The firmware uses only bank 1 of the RTL837x since it is quite short.
|
||||
Otherwise the firmware would be organized as follows
|
||||
```
|
||||
--------------------------- 0x0000 ---------------------------------
|
||||
Boot-Vector
|
||||
ISRs
|
||||
Common Code
|
||||
Trampoline for inter-bank calls
|
||||
Inter-bank calls, calling trampoline, one for each callable function
|
||||
|
||||
----- Bank 1 0x4000 ------ ---- Bank 2 0x4000 ----- -------- .....
|
||||
Overlay 1 Overlay 2 Overlay n
|
||||
|
||||
--------- 0xffff --------- -------- 0xffff -------- -------- 0xffff
|
||||
```
|
||||
The RTL837x firmware images are organized as follows:
|
||||
The first 2 bytes of the image give the size of the prefetched data at the
|
||||
start of the CPU power up. The default is 0x4000 (bytes: 0x00 0x40), which
|
||||
means that the entire shared area of the code memory in all banks,
|
||||
0x4000 bytes is read immediately into the code RAM.
|
||||
|
||||
Common code starts at
|
||||
0x0002 in the image and has length 0x3ffd, the first bank starts at 0x4000
|
||||
in the image, is mapped to 0x4000 and has length 0xc000. The second bank
|
||||
starts at 0x10000, is mapped to 0x4000 and has length 0xc000. The third
|
||||
bank would start at 0x1c000 and would again be mapped to 0x4000.
|
||||
There are about 30 banks in use for managed switches, unmanaged ones use
|
||||
2-3, while the hardware would allow to use 0x3f banks, i.e. up to 4 MB of
|
||||
flash.
|
||||
|
||||
The current image uses Common BANK0 and the first BANK1 via sdccs __banked
|
||||
function keyword and custom banking trampoline code for the RTL837x in
|
||||
assembler.
|
||||
@@ -0,0 +1,58 @@
|
||||
#RTL8272/3 features
|
||||
|
||||
The following hardware features of the RTL8372/3 is supported:
|
||||
- Clock generation, including different divider settings
|
||||
- Interrupt control for timer, serial, external irqs 0, 1
|
||||
- Serial console via SFRs
|
||||
- Flash operations via SFRs
|
||||
- Bank switching via SFRs
|
||||
- Access to Switch registers via SFRs
|
||||
- LED setup
|
||||
- Reset
|
||||
- Some switch settings such as MAC configuration
|
||||
- GPIO to detect SFP module insert/removal/RX-LOS (depending on device/module support)
|
||||
- I2C to read SFP EEPROM on 1 and 2 SFP slot devices
|
||||
- NIC setup
|
||||
- L2 learning table access, L2 table flushing
|
||||
- VLAN setup/configuration
|
||||
- Port mirroring
|
||||
- Access to PHYs via MDIO (clause 45 via SFR):
|
||||
- Internal PHYs of RTL8372 and RTL8373
|
||||
- RTL8221 (1x2.5GBit port on devices with 5 ports)
|
||||
- RTL8224 (4x2.5GBit ports on devices with 8 ports)
|
||||
- SerDes settings of SoC via SFR:
|
||||
- Configure SFPs with 10Gbit/2.5Gbit/1Gbit (Ethernet and Fiber SFP(+) tested)
|
||||
- RTL8221, RTL8224
|
||||
- NIC TX and RX of packets via SFRs
|
||||
- send and receive Ethernet frames via SFRs and Switch registers
|
||||
- RTL-tags and VLAN ingress-tag decoding for CPU-port
|
||||
|
||||
Ethernet frame RX IRQ via IRQ1 is conceptually understood, but not activated. RX is
|
||||
currently done via polling, which allows ping-times of <10ms.
|
||||
|
||||
The RTL8372/3 have 256 bytes of internal RAM (INTMEM) accessible through MOV
|
||||
instructions, which are used for the stack and important globals. Some of
|
||||
these are bit-adressable, e.g. for storing global flags.
|
||||
|
||||
Additionally, 64kB of extended RAM (XMEM) is built in, which is accessed
|
||||
through the MOVX instruction. It is used for global variables, for most
|
||||
of the function argument passing that is not done using the 8 registers
|
||||
R0-R7 or registers A/B, and for local variables (which requires extremely
|
||||
careful planning). The flash memory is transparently accessible for code
|
||||
being executed and can be used to store configuration. Access is done through
|
||||
the MOVC instruction, possibly setting the bank register before and
|
||||
resetting it to access the entire 4MB space. Code is prefetched from flash
|
||||
and cached in a small RAM automatically by the HW.
|
||||
|
||||
The peripherial functions are accessed through 2 different mechanisms:
|
||||
- Special Function Registers (SFRs, 0x80-0xff) for banking, timers, UART, access to
|
||||
switch registers, MDIO, SPI (flash) and NIC transfers. Some SFRs are not
|
||||
used for HW purposes and can be used as RAM. Some SFRs are bit-adressable,
|
||||
allowing for very tight event wait loops (a single 2-byte instruction).
|
||||
- 0x10000 switch registers, which appear to be very similar to the registers
|
||||
of the RTL838x, for which source code and datasheets are available. This
|
||||
controls clock dividers, GPIO/LEDs and general switch functionality.
|
||||
|
||||
The playground image shows access to the different types of memory using the
|
||||
SDCC compiler. Any support of Linux or e.g. Zephyr would require porting gcc.
|
||||
There are FreeRTOS ports to 8051 processors using sdcc, however.
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 83 KiB |
@@ -0,0 +1,25 @@
|
||||
# Supported Hardware
|
||||
The following devices have been tested and are fully working:
|
||||
- Horaco ZX_SG4T2
|
||||
- keepLINK kp-9000-6hx-x2 (RTL8372: 4x 2.5GBit + 2x 10GBit SFP+)
|
||||
- keepLINK KP-9000-6XHML-X2, same as above, but Managed
|
||||
- keepLINK kp-9000-6hx-x (RTL8372 + RTL8221B 2.5GBit PHY: 5 x 2.5GBit + 1x 10GBit SFP+)
|
||||
- keepLINK kp-9000-9xh-x-eu (1 x RTL8373 + RTL8224: 8x 2.5GBit + 1x 10GBit SFP+)
|
||||
- Lianguo LG-SWTGW218AS (RTL8373 + RTL8224 PHY: 8x 2.5GBit + 1x 10GBit SFP+)
|
||||
- No-Name ZX-SWTGW215AS, managed version of kp-9000-6hx-x, ordered on
|
||||
AliExpress as keepLINK 5+1 port managed
|
||||
|
||||
Other device based on RTL8272/3 that may work are described here: [Up-N-Atoms 2.5 GBit RTL Switch hacking guide]
|
||||
(https://github.com/up-n-atom/SWTG118AS)
|
||||
|
||||
Many of the RTL8272/3 devices come in versions with PoE support. The RTLPlayground usually also
|
||||
works on these, however, no support for configuring PoE is provided, simply because these
|
||||
devices usually just provide PoE on all ports without further configuration possibilitites.
|
||||
|
||||
The following forum also discusses this type of switches: [ServeTheHome](https://forums.servethehome.com/index.php?threads/horaco-2-5gbe-managed-switch-8-x-2-5gbe-1-10gb-sfp.41571/)
|
||||
|
||||
There are also 16-port unmanaged devices with RTL8272 SoCs, however these devices do not have
|
||||
serial consoles and use 4 independent RTL8272 SoCs. No central control is provided by RTLPlayground,
|
||||
even if it has been successfully demonstrated to install RTLPlayground to individual SoCs.
|
||||
- [GigaPlus GP-S25-1602](https://www.servethehome.com/gigaplus-gp-s25-1602-review-a-cheap-16-port-2-5gbe-and-2-port-10g-switch/)
|
||||
- [Vimin VM S251602P 16 Port 2.5G PoE Switch With 2x 10G SFP+](https://www.servethehome.com/vimin-vm-s251602p-16-port-2-5g-poe-switch-review-cyperf/vimin-vm-s251602p-16-port-2-5g-poe-switch-with-2x-10g-sfp-battery-2/)
|
||||
Reference in New Issue
Block a user