Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
268 changes: 268 additions & 0 deletions default/firmware/apple/brcmfmac43602-pcie.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,268 @@
# NVRAM for the Broadcom BCM43602 (PCI 14e4:43ba/43bb/43bc) in 2015-2017 Apple
# Macs, extracted from Apple's Windows/Boot Camp driver package and surfaced via
# kernel bug 193121, where it is attached as
# https://bugzilla.kernel.org/attachment.cgi?id=285753. linux-firmware ships
# only the .bin for this part, so without this file the firmware's country
# detection never completes: scans come back 2.4GHz-only at crippled power and
# the WPA four-way handshake times out.
#
# ccode=0/regrev=1 bypass that broken country detection by pinning the "world"
# regulatory domain instead of asking the AP. The values below are otherwise the
# board's own calibration data; do not edit them.
#
# Lines starting with # are comments to humans only; the brcmfmac NVRAM parser
# ignores them.
#
# macaddr= below is the firmware's built-in fallback default (00:90:4c is the Epigram/Broadcom OUI, not a real
# device MAC); the install leaf and migration always substitute the machine's live MAC or strip the line, so it is never used verbatim.
boardrev=0x1101

sromrev=11
boardtype=0x073e
vendid=0x14e4
devid=0x43ba

macaddr=00:90:4c:0d:f4:3e

ccode=0
regrev=1


# Board flags:
# X BFL_BTCOEXIST = 0x00000001 This board implements Bluetooth coexistence
# BFL_EXTLNA = 0x00001000 This board has an external LNA (2G)
# BFL_FEM_BT = 0x00400000 This board has shared antenna w/ BT
# X BFL_PALDO = 0x02000000 Power topology uses PALDO ? - CHECK
# BFL_EXTLNA_5GHz = 0x10000000 Board has an external LNA in 5GHz band
boardflags=0x02000001

# Board flags 2:
# BFL2_BT_SHARE_ANT0 = 0x00800000 share core0 antenna with BT
# X BFL2_LNA1BYPFORTR2G = 0x40000000 acphy, enable lna1 bypass for 2G clip lo
# X BFL2_LNA1BYPFORTR5G = 0x80000000 acphy, enable lna1 bypass for 5G clip lo
# X BFL2_SPUR_WAR = 0x00000200 Board has a WAR for clock-harmonic spurs
# BFL2_2G_SPUR_WAR = 0x00002000 Board has a WAR to reduce and avoid clock-harmonic spurs in 2G band
boardflags2=0xC0000000

# Board flags 3:
# X BFL3_RCAL_WAR = 0x00000008 acphy rcal war active on this board (mainly for 4335a0)
# X BFL3_FEMTBL_FROM_NVRAM = 0x00000100 acphy, femctrl table is read from nvram
boardflags3=0x40000108

#btc_mode=0

#### added rx de-sense

btcdyn_flags=0x7
# Media profile
btcdyn_profile_type=0x2
btcdyn_dflt_dsns_level=0
btcdyn_low_dsns_level=0
btcdyn_mid_dsns_level=21
btcdyn_high_dsns_level=22
btcdyn_default_btc_mode=4
# --- number of rows in the array vars below ---
btcdyn_msw_rows=1
btcdyn_dsns_rows=1
# --- mode switch data rows (max is 4) ---
btcdyn_msw_row0=1,-16,-95,-100
# --- desense switching data rows (max is 4) ---
btcdyn_dsns_row0=4,-16,-63,-95

#### end of rx de-sense


xtalfreq=40000
otpimagesize=484
nocrc=1
muxenab=0x1
btc_params82=0x60



########################################################
# RF Control Definitions

antswitch=0
rxchain=3
txchain=3
aa2g=3
aa5g=3
femctrl=10

# antenna gain per core g-band
agbg0=2
agbg1=2

# antenna gain per core a-band
aga0=2
aga1=2

# RFSWCTRL 2G and 5G iLNA
# WL_TX, WL_RX, WL_RX_ATTN, BT_TX_RX, WL_MASK
swctrlmap_2g=0x04010401,0x08080808,0x04010401,0x00000000,0x000000ff
swctrlmap_5g=0x08080808,0x04010401,0x08080808,0x00000000,0x000000ff

swctrlmapext_2g=0x00000000,0x00000000,0x00000000,0x000000,0x003
swctrlmapext_5g=0x00000000,0x00000000,0x00000000,0x000000,0x003
########################################################

# Bypass offsetting PAPD_EPS_TABLE_PER_TX_INDEX feature
epsdelta2g0=0,-1,0,0,0,0,0,0
epsdelta2g1=0,-1,0,0,0,0,0,0

########################################################
# Rx gain and RSSI parameters
#
# Default so do not set:
# rxgaincal_rssical=0
# rssi_cal_rev=0
# rxgains[25]gtrisoa[01]
# rxgains[25]g[mh]trelnabypa[01]=0

# BW20,BW40
rssicorrnorm_c0=4,4
rssicorrnorm_c1=4,4

# subband5gver=4 =>
# BW20,BW40,BW80 <5250|<5500|<5745|>=5745
# <70m| <100| <149|>=149
rssicorrnorm5g_c0=1,2,3,1,2,3,1,2,3,1,2,3
rssicorrnorm5g_c1=1,2,3,1,2,3,1,2,3,1,2,3

########################################################


########################################################
# 20 MHz in 40 MHz Power Offsets and Duplicate Modes
# 2G and 5G bands

sb20in40hrpo=0x0
sb20in40lrpo=0x0

dot11agduphrpo=0x0
dot11agduplrpo=0x0
########################################################


########################################################
# PAPD parameters
fastpapdgainctrl=0

########################################################
# 2G TSSI / PA Parameters

tworangetssi2g=1
tssipos2g=1
extpagain2g=2
pdgain2g=2

# 2G Max Power
maxp2ga0=74
maxp2ga1=74

# 2G PA Parameters
# Order is A1,B0,B1
#pa2ga0=-125,6514,-739 used for p113 and p115
#pa2ga1=-141,6391,-738 used for p113 and p115
#pa2ga0=-169,6473,-759
#pa2ga1=-174,6462,-759
pa2ga0=-162,6368,-735
pa2ga1=-170,6349,-742



# 2G Power Offsets
cckbw202gpo=0x0000
cckbw20ul2gpo=0x0000
mcsbw202gpo=0x99644422
mcsbw402gpo=0x99644422
dot11agofdmhrbw202gpo=0x6666
ofdmlrbw202gpo=0x0022

########################################################

#AvVmid_c0=2,140,2,145,2,145,2,145,2,145
#AvVmid_c1=2,140,2,145,2,145,2,145,2,145
#AvVmid_c2=0,0,0,0,0,0,0,0,0,0

# AvVmid 2GHz and 5GHz LabNotebook 43569A2_012 data from pcieir
AvVmid_c0=2,140,2,125,2,125,2,135,2,135
AvVmid_c1=2,140,3,100,3,100,3,100,3,100
AvVmid_c2=0,0,0,0,0,0,0,0,0,0

########################################################
# 5G TSSI / PA Parameters

tworangetssi5g=0
tssipos5g=1
extpagain5g=2
subband5gver=0x4
pdgain5g=2

# 5G Max Powers
maxp5ga0=74,74,74,74
maxp5ga1=74,74,74,74

# 5G PA Parameters initial
#pa5ga0=152,5462,658,150,5547,663,150,5950,697,170,5782,688
#pa5ga1=177,5661,685,178,5712,691,166,6161,725,195,5811,706

# 5G PA Parameters *** from LabNotebook 43569A0_099 TSSI opt for 8::18:
#pa5ga0=-181,5835,-709,-183,5842,-712,-186,5832,-710,-187,5744,-703
#pa5ga1=-198,5767,-710,-190,5915,-721,-185,6067,-732,-186,6024,-731

# Updated with LabNotebook 43569A2_012
pa5ga0=-194,5833,-713,-186,6042,-730,-181,5927,-714,-197,5562,-687
pa5ga1=-186,6139,-737,-196,5988,-726,-203,5852,-713,-204,5836,-713



# 5G Power Offsets
mcsbw205glpo=0x88766663
mcsbw405glpo=0x88666663
mcsbw805glpo=0xbb666665
mcsbw205gmpo=0xd8666663
mcsbw405gmpo=0x88666663
mcsbw805gmpo=0xcc666665
mcsbw205ghpo=0xdc666663
mcsbw405ghpo=0xaa666663
mcsbw805ghpo=0xdd666665
mcslr5glpo=0x0000
mcslr5gmpo=0x0000
mcslr5ghpo=0x0000
sb20in40hrpo=0x0
sb20in80and160hr5glpo=0x0
sb40and80hr5glpo=0x0
sb20in80and160hr5gmpo=0x0
sb40and80hr5gmpo=0x0
sb20in80and160hr5ghpo=0x0
sb40and80hr5ghpo=0x0
sb20in40lrpo=0x0
sb20in80and160lr5glpo=0x0
sb40and80lr5glpo=0x0
sb20in80and160lr5gmpo=0x0
sb40and80lr5gmpo=0x0
sb20in80and160lr5ghpo=0x0
sb40and80lr5ghpo=0x0

pdoffset40ma0=0x0000
pdoffset80ma0=0x0000
pdoffset40ma1=0x0000
pdoffset80ma1=0x0000

########################################################


########################################################
# Temperature Values

tempthresh=120
tempoffset=255
rawtempsense=0x1ff

phycal_tempdelta=255
temps_period=15
temps_hysteresis=15

########################################################
1 change: 1 addition & 0 deletions install/hardware/all.sh
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ run_logged "$OMARCHY_INSTALL/hardware/apple/fix-spi-keyboard.sh"
run_logged "$OMARCHY_INSTALL/hardware/apple/fix-suspend-nvme.sh"
run_logged "$OMARCHY_INSTALL/hardware/apple/fix-t2.sh"
run_logged "$OMARCHY_INSTALL/hardware/apple/fix-brcmfmac-supplicant.sh"
run_logged "$OMARCHY_INSTALL/hardware/apple/fix-brcmfmac-nvram.sh"

run_logged "$OMARCHY_INSTALL/hardware/lenovo/fix-yoga-pro7-bass-speakers.sh"

Expand Down
56 changes: 56 additions & 0 deletions install/hardware/apple/fix-brcmfmac-nvram.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# 2015-2017 Apple Macs ship the Broadcom BCM43602, which brcmfmac drives. The
# linux-firmware package provides only the .bin for this part and no NVRAM, and
# without one the firmware's country-code detection never completes (kernel bug
# 193121): scans come back 2.4GHz-only at a fraction of the real signal, and
# the WPA four-way handshake times out, which NetworkManager reports as a
# rejected password. Shipping the board's NVRAM with ccode=0/regrev=1 pins the
# "world" regulatory domain around the broken detection and lets the handshake
# complete. This pairs with fix-brcmfmac-supplicant.sh, which fixes a different
# firmware defect on the same machines; neither replaces the other.
#
# The gate is deliberately narrower than the supplicant quirk's: the NVRAM
# holds this board's calibration data, so it only applies to the BCM43602
# family -- 14e4:43ba/43bb/43bc, the IDs brcmfmac's brcm_hw_ids.h lists for
# BCM43602 and its single-band variants. BCM4360 (14e4:43a0) runs the
# out-of-tree wl driver, which never reads brcmfmac NVRAM, and is excluded.
#
# A file already at the destination wins: user-placed or shipped by a future
# linux-firmware, both outrank this copy, and the skip is silent because it is
# the common case on reruns.
#
# The asset lives under default/, a sibling of the install tree, so it resolves
# from $OMARCHY_PATH (exported by the install entry point and always present at
# runtime) rather than from $OMARCHY_INSTALL, which points at install/ itself.
dest=/usr/lib/firmware/brcm/brcmfmac43602-pcie.txt
sys_vendor="$(cat /sys/class/dmi/id/sys_vendor 2>/dev/null || true)"

if [[ ! -e $dest ]] && [[ $sys_vendor == Apple* ]] &&
lspci -nn | grep -E "14e4:(43ba|43bb|43bc)" >/dev/null; then
echo "Detected a Mac with BCM43602 Wi-Fi; installing its missing NVRAM"

# The NVRAM's macaddr= line carries the donor board's address, so substitute
# this NIC's own, found under the matching PCI device. lspci -D prints the
# domain form /sys uses. awk reads the whole stream instead of exiting on the
# first match, so the pipe stays safe under pipefail (#6608).
bdf="$(lspci -Dnn | awk '/14e4:(43ba|43bb|43bc)/ { if (!found) { print $1; found=1 } }')"
mac=""
if [[ -n $bdf ]]; then
net_addrs=(/sys/bus/pci/devices/"$bdf"/net/*/address)
mac="$(cat "${net_addrs[0]}" 2>/dev/null || true)"
fi

work="$(mktemp)"
if [[ -n $mac ]]; then
sed "s/^macaddr=.*/macaddr=$mac/" \
"$OMARCHY_PATH/default/firmware/apple/brcmfmac43602-pcie.txt" >"$work"
else
# No MAC discoverable: drop the line entirely and let the firmware fall
# back to the OTP address, which is how these NICs already run with no
# NVRAM at all.
sed '/^macaddr=/d' \
"$OMARCHY_PATH/default/firmware/apple/brcmfmac43602-pcie.txt" >"$work"
fi

install -Dm644 "$work" "$dest"
rm -f "$work"
fi
51 changes: 51 additions & 0 deletions migrations/1786961462.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
echo "Install the missing NVRAM for Broadcom BCM43602 Wi-Fi on Apple Macs"

# The install-time leaf only reaches machines set up after it shipped, so an
# existing install on a 2015-2017 Mac still has no NVRAM for its BCM43602:
# 2.4GHz-only scans, crippled signal, and WPA handshakes that time out. See
# install/hardware/apple/fix-brcmfmac-nvram.sh for the failure this fixes and
# for why the gate is limited to 14e4:43ba/43bb/43bc.
dmi_vendor="${OMARCHY_BRCMFMAC_NVRAM_DMI_VENDOR:-/sys/class/dmi/id/sys_vendor}"
pci_devices="${OMARCHY_BRCMFMAC_NVRAM_PCI_DEVICES:-/sys/bus/pci/devices}"
dest="${OMARCHY_BRCMFMAC_NVRAM_DEST:-/usr/lib/firmware/brcm/brcmfmac43602-pcie.txt}"
src="${OMARCHY_BRCMFMAC_NVRAM_SRC:-$OMARCHY_PATH/default/firmware/apple/brcmfmac43602-pcie.txt}"

sys_vendor="$(cat "$dmi_vendor" 2>/dev/null || true)"

if ! [[ $sys_vendor == Apple* ]] ||
! lspci -nn | grep -E "14e4:(43ba|43bb|43bc)" >/dev/null; then
exit 0
fi

# A file already there wins: user-placed or package-shipped, both outrank this
# copy. The same check keeps the migration idempotent for the next user on a
# machine already repaired.
if [[ -e $dest ]]; then
exit 0
fi

# Substitute the NIC's live MAC for the donor board's placeholder, the same way
# the install-time leaf does. awk reads the whole lspci stream instead of
# exiting on the first match, so the pipe stays safe under pipefail (#6608).
bdf="$(lspci -Dnn | awk '/14e4:(43ba|43bb|43bc)/ { if (!found) { print $1; found=1 } }')"
mac=""
if [[ -n $bdf ]]; then
net_addrs=("$pci_devices/$bdf"/net/*/address)
mac="$(cat "${net_addrs[0]}" 2>/dev/null || true)"
fi

work="$(mktemp)"
if [[ -n $mac ]]; then
sed "s/^macaddr=.*/macaddr=$mac/" "$src" >"$work"
else
# No MAC discoverable: drop the line and let the firmware use the OTP
# address, which is how these NICs already run with no NVRAM at all.
sed '/^macaddr=/d' "$src" >"$work"
fi

sudo install -Dm644 "$work" "$dest"
rm -f "$work"

# brcmfmac reads the NVRAM when the module loads. Reloading it here would drop
# the user's live Wi-Fi connection, possibly the one carrying this update.
omarchy-state set reboot-required
Loading