Linux bluetooth development
 help / color / mirror / Atom feed
From: "Veysi Özgün" <veysiiozgun@gmail.com>
To: Hilda Wu <hildawu@realtek.com>
Cc: linux-bluetooth@vger.kernel.org, deniz <denizgu@protonmail.ch>,
	Ping-Ke Shih <pkshih@realtek.com>, Timlee <timlee@realtek.com>,
	Zong-Zhe Yang <kevin_yang@realtek.com>,
	Max Chou <max.chou@realtek.com>,
	alex_lu@realsil.com.cn, zoey_zhou@realsil.com.cn,
	kevinchen@realtek.com, Blc Dragon <fenix78563@gmail.com>
Subject: Re: rtl_bt: RTL8852BU rom_version 3 has no matching in rtl8852bu_fw.bin
Date: Sat, 26 Sep 2026 16:52:19 +0300	[thread overview]
Message-ID: <20260926135219.13925-1-veysiiozgun@gmail.com> (raw)
In-Reply-To: <6027f64b0658478a91f0cadd4a6b051d@realtek.com>

Hi Hilda, all,

Thanks for confirming that eco 4 firmware is planned. I have the same
controller (0bda:b853, rom_version 3) and got it working with the patch
from the Windows driver. Along the way I found something that may matter
for the Linux release: for this ROM revision, the Windows driver sends an
extra vendor command before each patch segment. The current btrtl
download path never sends it.

Hardware / software
-------------------
  Machine   : Lenovo LOQ 15ARP10E (83S0)
  BT        : 0bda:b853, hci_rev 0x000b, lmp_subver 0x8852, rom_version 3
  Wi-Fi     : RTL8852BE (rtw89_8852be), works fine
  Kernel    : 7.1.5 (Kali), BlueZ 5.87
  Windows   : Realtek driver 18.4032.0.3008 (rtkbtfilter.inf),
              patch file rtl8852bd_mp_chip_new.dat

What Windows sends (USBPcap capture of a radio off/on cycle)
------------------------------------------------------------
  HCI_Read_Local_Version
  for each of the 3 segments:
    0xfc62 plen 9: 21 | le32 0x801200cc | le32 <segment addr>  -> status 0
    0xfc20 fragments of 252 bytes, index 1..0x7f then wraps to 1,
      index restarts at 1 for every segment,
      no 0x80 flag at the end of a segment
  then one 0xfc20 with index 0x80 and no data -> status 0

  segment addr    size
  0x8010f720      61552
  0x8010e990        568
  0x801084e0       2900

Afterwards Read_Local_Version returns hci_rev 0x3c91 and lmp_subver 0x950e.

The fragments are byte-identical to the payload of each BTNIC003 entry
(chip_id 0x14, eco 4). In each entry, the two addresses are at +0x3df and
+0x3e7, the payload length is at +0x400, and the payload starts at +0x408.
The first segment has the same layout as the eco 1/2 subsections in
rtl8852bu_fw.bin (code starts with f8630f62 and ends with the 07072db1
trailer).

What does NOT work
------------------
1. Adding the eco 4 payload as an extra RTBTCore subsection and loading it
   through the existing v2 path (without 0xfc62). The controller stops
   responding in the middle of the download ("command 0xfc20 tx timeout",
   "download fw command failed (-110)"). After that, even 0xfc61 times out
   and usbcore keeps resetting the device. Only a full power-off recovers it.

2. Loading the patch from userspace (libusb) with the Windows sequence
   before btusb binds. The patch itself is accepted (lmp_subver becomes
   0x950e), but then btrtl_initialize() finds no ic_info for 0x950e, sets
   drop_fw, sends 0xfc66 and the controller goes back to ROM.

What works
----------
I added a small path to btrtl_setup_rtl8723b() for
8852A-id / hci_rev 0xb / USB / rom_version 3. It uses request_firmware() on
the BTNIC003 file and replays the sequence above. With it, the controller
comes up with its real BD_ADDR, registers with mgmt and scans normally.
This is only a proof of concept and not meant for merging (it parses the
vendor Windows file). I'm happy to share the diff and the pcapng if they
help.

Question
--------
Will the upcoming eco 4 firmware work with the existing RTBTCore download
path, or does this ROM revision also need 0xfc62 (or similar) on the
driver side? Either way, I can test pre-release firmware or driver patches
on this hardware.

Thanks,
Veysi Özgün

  reply	other threads:[~2026-09-26 13:52 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-02 12:31 rtl_bt: RTL8852BU rom_version 3 has no matching in rtl8852bu_fw.bin deniz
2026-08-14 11:13 ` Hilda Wu
2026-09-26 13:52   ` Veysi Özgün [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-08-19 13:07 Blc Dragon

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260926135219.13925-1-veysiiozgun@gmail.com \
    --to=veysiiozgun@gmail.com \
    --cc=alex_lu@realsil.com.cn \
    --cc=denizgu@protonmail.ch \
    --cc=fenix78563@gmail.com \
    --cc=hildawu@realtek.com \
    --cc=kevin_yang@realtek.com \
    --cc=kevinchen@realtek.com \
    --cc=linux-bluetooth@vger.kernel.org \
    --cc=max.chou@realtek.com \
    --cc=pkshih@realtek.com \
    --cc=timlee@realtek.com \
    --cc=zoey_zhou@realsil.com.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox