From: "Veysi Özgün" <veysiiozgun@gmail.com>
To: Hilda Wu <hildawu@realtek.com>
Cc: linux-bluetooth@vger.kernel.org, deniz <denizgu@protonmail.ch>,
Ping-Ke Shih <pkshih@realtek.com>, Timlee <timlee@realtek.com>,
Zong-Zhe Yang <kevin_yang@realtek.com>,
Max Chou <max.chou@realtek.com>,
alex_lu@realsil.com.cn, zoey_zhou@realsil.com.cn,
kevinchen@realtek.com, Blc Dragon <fenix78563@gmail.com>
Subject: Re: rtl_bt: RTL8852BU rom_version 3 has no matching in rtl8852bu_fw.bin
Date: Sat, 26 Sep 2026 16:52:19 +0300 [thread overview]
Message-ID: <20260926135219.13925-1-veysiiozgun@gmail.com> (raw)
In-Reply-To: <6027f64b0658478a91f0cadd4a6b051d@realtek.com>
Hi Hilda, all,
Thanks for confirming that eco 4 firmware is planned. I have the same
controller (0bda:b853, rom_version 3) and got it working with the patch
from the Windows driver. Along the way I found something that may matter
for the Linux release: for this ROM revision, the Windows driver sends an
extra vendor command before each patch segment. The current btrtl
download path never sends it.
Hardware / software
-------------------
Machine : Lenovo LOQ 15ARP10E (83S0)
BT : 0bda:b853, hci_rev 0x000b, lmp_subver 0x8852, rom_version 3
Wi-Fi : RTL8852BE (rtw89_8852be), works fine
Kernel : 7.1.5 (Kali), BlueZ 5.87
Windows : Realtek driver 18.4032.0.3008 (rtkbtfilter.inf),
patch file rtl8852bd_mp_chip_new.dat
What Windows sends (USBPcap capture of a radio off/on cycle)
------------------------------------------------------------
HCI_Read_Local_Version
for each of the 3 segments:
0xfc62 plen 9: 21 | le32 0x801200cc | le32 <segment addr> -> status 0
0xfc20 fragments of 252 bytes, index 1..0x7f then wraps to 1,
index restarts at 1 for every segment,
no 0x80 flag at the end of a segment
then one 0xfc20 with index 0x80 and no data -> status 0
segment addr size
0x8010f720 61552
0x8010e990 568
0x801084e0 2900
Afterwards Read_Local_Version returns hci_rev 0x3c91 and lmp_subver 0x950e.
The fragments are byte-identical to the payload of each BTNIC003 entry
(chip_id 0x14, eco 4). In each entry, the two addresses are at +0x3df and
+0x3e7, the payload length is at +0x400, and the payload starts at +0x408.
The first segment has the same layout as the eco 1/2 subsections in
rtl8852bu_fw.bin (code starts with f8630f62 and ends with the 07072db1
trailer).
What does NOT work
------------------
1. Adding the eco 4 payload as an extra RTBTCore subsection and loading it
through the existing v2 path (without 0xfc62). The controller stops
responding in the middle of the download ("command 0xfc20 tx timeout",
"download fw command failed (-110)"). After that, even 0xfc61 times out
and usbcore keeps resetting the device. Only a full power-off recovers it.
2. Loading the patch from userspace (libusb) with the Windows sequence
before btusb binds. The patch itself is accepted (lmp_subver becomes
0x950e), but then btrtl_initialize() finds no ic_info for 0x950e, sets
drop_fw, sends 0xfc66 and the controller goes back to ROM.
What works
----------
I added a small path to btrtl_setup_rtl8723b() for
8852A-id / hci_rev 0xb / USB / rom_version 3. It uses request_firmware() on
the BTNIC003 file and replays the sequence above. With it, the controller
comes up with its real BD_ADDR, registers with mgmt and scans normally.
This is only a proof of concept and not meant for merging (it parses the
vendor Windows file). I'm happy to share the diff and the pcapng if they
help.
Question
--------
Will the upcoming eco 4 firmware work with the existing RTBTCore download
path, or does this ROM revision also need 0xfc62 (or similar) on the
driver side? Either way, I can test pre-release firmware or driver patches
on this hardware.
Thanks,
Veysi Özgün
next prev parent reply other threads:[~2026-09-26 13:52 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-02 12:31 rtl_bt: RTL8852BU rom_version 3 has no matching in rtl8852bu_fw.bin deniz
2026-08-14 11:13 ` Hilda Wu
2026-09-26 13:52 ` Veysi Özgün [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-08-19 13:07 Blc Dragon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926135219.13925-1-veysiiozgun@gmail.com \
--to=veysiiozgun@gmail.com \
--cc=alex_lu@realsil.com.cn \
--cc=denizgu@protonmail.ch \
--cc=fenix78563@gmail.com \
--cc=hildawu@realtek.com \
--cc=kevin_yang@realtek.com \
--cc=kevinchen@realtek.com \
--cc=linux-bluetooth@vger.kernel.org \
--cc=max.chou@realtek.com \
--cc=pkshih@realtek.com \
--cc=timlee@realtek.com \
--cc=zoey_zhou@realsil.com.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox