From 35ba2ca37fbde70d695516f3e9c0bf4e6af8691e Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Tue, 10 Mar 2026 11:44:13 +0100 Subject: [PATCH] board/aarch64: add dedicated RPi 400 product configuration The Raspberry Pi 400 shares hardware with the RPi 4B but differs in one important way: it has an internal keyboard and mouse connected through a VIA Labs USB hub on the VL805 xHCI controller. Break the symlink to raspberrypi,4-model-b and maintain a dedicated product directory. Factory config changes from the 4B default: - USB1/USB2/USB3 all unlocked: USB2 carries the internal keyboard hub and USB3 the superspeed companion; all are unlocked as this is a desktop device - DHCP vendor-class corrected to "Raspberry Pi 400" Also add interface-quirks.json for the eth0 PHY detach behaviour and the smsc95xx broken flow-control quirk (inherited from the 4B config but now explicit), and remove the spurious bootable flag from the primary and secondary rootfs partitions in genimage.cfg.in. Signed-off-by: Joachim Wiberg --- .../aarch64/raspberrypi-rpi64/genimage.cfg.in | 8 +- .../raspberrypi,400/etc/factory-config.cfg | 312 ++++++++++++++++++ .../etc/product/interface-quirks.json | 10 + 3 files changed, 325 insertions(+), 5 deletions(-) create mode 100644 board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/factory-config.cfg create mode 100644 board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/product/interface-quirks.json diff --git a/board/aarch64/raspberrypi-rpi64/genimage.cfg.in b/board/aarch64/raspberrypi-rpi64/genimage.cfg.in index 8e7b356e..88d7a580 100644 --- a/board/aarch64/raspberrypi-rpi64/genimage.cfg.in +++ b/board/aarch64/raspberrypi-rpi64/genimage.cfg.in @@ -43,8 +43,8 @@ image #INFIX_ID##VERSION#-rpi64-sdcard.img { partition boot { partition-type = 0xc - bootable = "true" image = "boot.vfat" + bootable = "true" } partition aux { @@ -54,16 +54,14 @@ image #INFIX_ID##VERSION#-rpi64-sdcard.img { partition primary { partition-type-uuid = linux - bootable = "true" - size = 250M image = "rootfs.squashfs" + size = 250M } partition secondary { partition-type-uuid = linux - bootable = "true" - size = 250M image = "rootfs.squashfs" + size = 250M } partition cfg { diff --git a/board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/factory-config.cfg b/board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/factory-config.cfg new file mode 100644 index 00000000..94c61bf2 --- /dev/null +++ b/board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/factory-config.cfg @@ -0,0 +1,312 @@ +{ + "ieee802-dot1ab-lldp:lldp": { + "infix-lldp:enabled": true + }, + "ietf-hardware:hardware": { + "component": [ + { + "name": "USB1", + "class": "infix-hardware:usb", + "state": { + "admin-state": "unlocked" + } + }, + { + "name": "USB2", + "class": "infix-hardware:usb", + "state": { + "admin-state": "unlocked" + } + }, + { + "name": "USB3", + "class": "infix-hardware:usb", + "state": { + "admin-state": "unlocked" + } + }, + { + "name": "radio0", + "class": "infix-hardware:wifi", + "infix-hardware:wifi-radio": { + "country-code": "00" + } + } + ] + }, + "ietf-interfaces:interfaces": { + "interface": [ + { + "name": "lo", + "type": "infix-if-type:loopback", + "ietf-ip:ipv4": { + "address": [ + { + "ip": "127.0.0.1", + "prefix-length": 8 + } + ] + }, + "ietf-ip:ipv6": { + "address": [ + { + "ip": "::1", + "prefix-length": 128 + } + ] + } + }, + { + "name": "eth0", + "type": "infix-if-type:ethernet", + "ietf-ip:ipv6": {}, + "ietf-ip:ipv4": { + "infix-dhcp-client:dhcp": { + "option": [ + { + "id": "netmask" + }, + { + "id": "broadcast" + }, + { + "id": "router" + }, + { + "id": "domain" + }, + { + "id": "hostname" + }, + { + "id": "dns-server" + }, + { + "id": "ntp-server" + }, + { + "id": "vendor-class", + "value": "Raspberry Pi 400" + } + ] + } + } + }, + { + "name": "wifi0", + "type": "infix-if-type:wifi", + "infix-interfaces:wifi": { + "radio": "radio0" + } + } + ] + }, + "ietf-keystore:keystore": { + "asymmetric-keys": { + "asymmetric-key": [ + { + "name": "genkey", + "public-key-format": "infix-crypto-types:ssh-public-key-format", + "public-key": "", + "private-key-format": "infix-crypto-types:rsa-private-key-format", + "cleartext-private-key": "", + "certificates": {} + } + ] + } + }, + "ietf-netconf-acm:nacm": { + "enable-nacm": true, + "read-default": "permit", + "write-default": "permit", + "exec-default": "permit", + "groups": { + "group": [ + { + "name": "admin", + "user-name": [ + "admin" + ] + }, + { + "name": "operator", + "user-name": [] + }, + { + "name": "guest", + "user-name": [] + } + ] + }, + "rule-list": [ + { + "name": "admin-acl", + "group": [ + "admin" + ], + "rule": [ + { + "name": "permit-all", + "module-name": "*", + "access-operations": "*", + "action": "permit", + "comment": "Allow 'admin' group complete access to all operations and data." + } + ] + }, + { + "name": "operator-acl", + "group": [ + "operator" + ], + "rule": [ + { + "name": "permit-system-rpcs", + "module-name": "ietf-system", + "rpc-name": "*", + "access-operations": "exec", + "action": "permit", + "comment": "Operators can reboot, shutdown, and set system time." + } + ] + }, + { + "name": "guest-acl", + "group": [ + "guest" + ], + "rule": [ + { + "name": "deny-all-write+exec", + "module-name": "*", + "access-operations": "create update delete exec", + "action": "deny", + "comment": "Guests cannot change anything or exec rpcs." + } + ] + }, + { + "name": "default-deny-all", + "group": [ + "*" + ], + "rule": [ + { + "name": "deny-password-access", + "path": "/ietf-system:system/authentication/user/password", + "access-operations": "*", + "action": "deny", + "comment": "No user except admins can access password hashes." + }, + { + "name": "deny-keystore-access", + "module-name": "ietf-keystore", + "access-operations": "*", + "action": "deny", + "comment": "No user except admins can access cryptographic keys." + }, + { + "name": "deny-truststore-access", + "module-name": "ietf-truststore", + "access-operations": "*", + "action": "deny", + "comment": "No user except admins can access trust store." + } + ] + } + ] + }, + "ietf-netconf-server:netconf-server": { + "listen": { + "endpoints": { + "endpoint": [ + { + "name": "default-ssh", + "ssh": { + "tcp-server-parameters": { + "local-bind": [ + { + "local-address": "::" + } + ] + }, + "ssh-server-parameters": { + "server-identity": { + "host-key": [ + { + "name": "default-key", + "public-key": { + "central-keystore-reference": "genkey" + } + } + ] + } + } + } + } + ] + } + } + }, + "ietf-system:system": { + "hostname": "rpi-%m", + "ntp": { + "enabled": true, + "server": [ + { + "name": "ntp.org", + "udp": { + "address": "pool.ntp.org" + }, + "iburst": true + } + ] + }, + "authentication": { + "user": [ + { + "name": "admin", + "password": "$factory$", + "infix-system:shell": "bash" + } + ] + }, + "infix-system:motd-banner": "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCBPUyDigJQgSW1tdXRhYmxlLkZyaWVuZGx5LlNlY3VyZQp8LS4gdiAuLXwgaHR0cHM6Ly9rZXJuZWxraXQub3JnCictJy0tLSctJwo=" + }, + "infix-meta:meta": { + "version": "1.7" + }, + "infix-services:mdns": { + "enabled": true + }, + "infix-services:web": { + "enabled": true, + "console": { + "enabled": true + }, + "netbrowse": { + "enabled": true + }, + "restconf": { + "enabled": true + } + }, + "infix-services:ssh": { + "enabled": true, + "hostkey": [ + "genkey" + ], + "listen": [ + { + "name": "ipv4", + "address": "0.0.0.0", + "port": 22 + }, + { + "name": "ipv6", + "address": "::", + "port": 22 + } + ] + } +} diff --git a/board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/product/interface-quirks.json b/board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/product/interface-quirks.json new file mode 100644 index 00000000..26be2da0 --- /dev/null +++ b/board/aarch64/raspberrypi-rpi64/rootfs/usr/share/product/raspberrypi,400/etc/product/interface-quirks.json @@ -0,0 +1,10 @@ +{ + "eth0": { + "comment": "Primary Ethernet controller, native on BCM2711, and smsc95xx on BCM2837", + "phy-detached-when-down": true + }, + "@ethtool:driver=smsc95xx": { + "comment": "BCM2837 smsc95xx driver does not support disabling flow control", + "broken-flow-control": true + } +}