Offsets are what scripts/package.sh
writes, checked against the 0.1.2 release images.
| Offset | Content |
|---|---|
0x000000 |
GPT (from binaries/rk3576_spi_nor_gpt.img) |
0x008000 |
idblock: DDR init + U-Boot SPL, about 190 KB |
0x060000 |
FIT: BL31, EDK2, DTB. May grow up to 0xFC0000. |
0xFC0000 |
UEFI variable store, 64 KB |
0xFD0000 |
FTW working block, 64 KB |
0xFE0000 |
FTW spare block, 64 KB |
The three NV regions ship in the erased state (all 0xFF). Zeros there read
as a corrupt store rather than an empty one, and variables never initialise.
| Offset | Content |
|---|---|
0x008000 (sector 64) |
idblock: DDR init + U-Boot SPL |
0x800000 (sector 16384) |
FIT: BL31, EDK2, DTB |
0x1600000 |
UEFI variable store, 3 × 64 KB, erased state |
CM5IO-emmc.img is the same bytes with a protective MBR and a primary GPT in
front. See FLASHING.md.
| Image | Load address | What |
|---|---|---|
atf-1 |
0x3fe70000 |
BL31, PMU SRAM segment |
atf-2 |
0x40040000 |
BL31 main code; the configuration’s entry point |
atf-3 |
0x4005d000 |
BL31 coherent data |
edk2 |
0x40800000 |
EDK2 as BL33. Must match TF-A’s BL33_BASE. |
fdt |
— | The DTB the SPL uses |
RK3576’s DRAM starts at 0x40000000, so every load address except the PMU
SRAM segment sits just above that base. The FIT is built with external data
(mkimage -E -B 0x1000): a 4 KB header followed by the payloads. The ITS is
generated by
scripts/lib/gen_fit_its.py.
BootROM
└─ idblock (DDR init, then SPL)
└─ SPL loads the FIT
├─ BL31 → 0x40040000, EL3
└─ EDK2 → 0x40800000, EL2 (BL33)
└─ UEFI front page / boot manager