Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Two-cell addresses truncate unsafely on 32-bit builds, and the central loader-level initrd regression lacks direct coverage.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Adds support for booting kernel-only FIT images without kernel load/entry addresses or an embedded device tree.
Changes:
- Adds configurable FIT kernel relocation and 64-bit address handling.
- Defers initrd fixups until the final DTB is selected.
- Adds Versal high-DDR configuration, documentation, CI, and tests.
| File | Description |
|---|---|
src/fdt.c |
Adds kernel relocation helper and diagnostics. |
src/update_ram.c |
Adds DTB fallback and deferred initrd fixup. |
src/update_disk.c |
Defers initrd fixup and improves address logging. |
src/boot_aarch64.c |
Prints full-width boot addresses. |
include/fdt.h |
Declares the kernel-loading API. |
include/target.h.in |
Exposes the kernel load address. |
Makefile |
Generates the new target setting. |
options.mk |
Defines the kernel relocation option. |
tools/config.mk |
Persists the new configuration variable. |
tools/unit-tests/Makefile |
Enables ramdisk testing. |
tools/unit-tests/unit-fit-gzip.c |
Tests relocation and initrd helpers. |
tools/unit-tests/unit-fdt.c |
Tests two-cell FIT addresses. |
tools/unit-tests/unit-update-disk-fit.c |
Adds the kernel loader stub. |
docs/Targets.md |
Documents supported FIT layouts. |
config/examples/versal_vmk180.config |
Documents optional relocation settings. |
config/examples/versal_vmk180_highddr.config |
Adds a high-DDR Versal example. |
.github/workflows/test-configs.yml |
Builds the new example in CI. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
dgarske
force-pushed
the
versal_fit_noload
branch
from
October 1, 2026 20:45
25ba400 to
37579ca
Compare
dgarske
force-pushed
the
versal_fit_noload
branch
from
October 1, 2026 22:09
37579ca to
4035401
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
Found working through a Versal customer image: a Flattened Image Tree (FIT) built without
load/entryon the kernel node and with nofdtsub-image at all.Fixes two problems and adds a new configuration option:
1. A FIT with no
fdtsub-image entered Linux with a null device treesrc/update_ram.creached its raw-DTB path -hal_get_dts_address(), elseWOLFBOOT_DTS_BOOT_ADDRESSout of flash - only in theelseof the FIT branch, so it ran only when the payload was not a FIT at all. A kernel-only FIT parses, finds nofdtnode, leavesdts_addrNULL, anddo_boot()hands that to the kernel inx0. The raw path is now entered whenever no device tree came out of the FIT, matching whatsrc/update_disk.calready did. A FITfdtnode that fails validation now logs the fallback instead of taking it silently, since it substitutes a different device tree than the FIT names.2. The initrd fixup ran before the device tree was chosen
fit_load_ramdisk()was called inside the FIT branch, with a context opened only on a DTB the FIT itself supplied. When the device tree comes from the boot firmware instead, the ramdisk loaded but/chosen/linux,initrd-startand-endwere never written, so the kernel saw no initrd. Both loaders now defer the fixup until the device tree source is settled.New option
WOLFBOOT_LOAD_KERNEL_ADDRESSstages the FIT kernel at a configured address, overriding the FIT'sload/entry. It mirrors the existingWOLFBOOT_LOAD_RAMDISK_ADDRESSandWOLFBOOT_LOAD_FPGA_ADDRESS, and0- the default - honors the FIT, so no existing target changes behavior. It is what makes such a FIT bootable without editing it: a gzip kernel with noloadhas nowhere to decompress to and fails closed.config/examples/versal_vmk180_highddr.configis a worked configuration for a DDR aperture at0x400_0000_0000, with a CI build job.docs/Targets.mdcovers both FIT shapes, including the two-cellload/entryan ITS needs above 4 GB and the bootargs consequence of a device tree that sits outside the signature.Hardware / test status
Validated end-to-end on a Versal VMK180 (Platform Cable USB II, QSPI payload): a FIT whose kernel node declares no
load/entry, whose ramdisk node declares noload, and which carries nofdtsub-image, with the device tree supplied by the BIF's{ type=raw, load=0x1000, file=system-default.dtb }partition. Read back out of DDR: an arm64Image(MZ, andARM\x64at offset 0x38) at the configured kernel address, and a live/chosencarryinglinux,initrd-start/-endspanning exactly the ramdisk, in the BIF-supplied tree rather than a FIT one.Also covered by unit tests for the override, for the initrd fixup applied to a device tree the FIT did not supply, and for two-cell address decoding. Build-verified across the Xilinx, NXP, PolarFire and Raspberry Pi targets that share these loaders.