--- title: BDY‑G18‑Pro Armbian Builder – Deployment Guide type: curated permalink: main/projects/d0abaf3f-da04-4dd4-a228-bacf68f44e8f/curated/development/bdy-g18-pro-armbian-builder-deployment-guide stable_id: 818f5e7c-bf74-4bb0-9bb0-187f7243cf18 scope: project project_id: d0abaf3f-da04-4dd4-a228-bacf68f44e8f workspace_type: development usage_profile_id: null preference_context: development document_type: deployment revision: 1 source_memory_ids: [] source_checkpoint_ids: [] source_file_ids: [] source_git_commit: 36234e0082845515a053c10ee552ce35a03415f0 source_git_commits: - 36234e0082845515a053c10ee552ce35a03415f0 source_agent_sync_ids: [] model_connection: Sub2API model_name: git-restore source_count: 125 source_revisions: memory:11052d10-1adf-4d39-800a-08f9ae708758: '1' memory:b70c1a22-6834-4e59-936c-1945b04273b7: '1' memory:340af5e9-b3e5-423a-9971-b370992738ce: '1' memory:bea4a5ba-4685-4869-a02e-f0f1c7f733ea: '1' memory:d5cbbc04-5929-4583-90b4-bd6c8295db25: '1' memory:7cf6c014-d2fa-4f99-9ed9-c070b108d3c7: '1' source_dispositions: processed: 78 unchanged: 0 unsupported: 47 skipped: 0 cited_source_ids: - memory:11052d10-1adf-4d39-800a-08f9ae708758 - memory:b70c1a22-6834-4e59-936c-1945b04273b7 - memory:340af5e9-b3e5-423a-9971-b370992738ce - memory:bea4a5ba-4685-4869-a02e-f0f1c7f733ea - memory:d5cbbc04-5929-4583-90b4-bd6c8295db25 - memory:7cf6c014-d2fa-4f99-9ed9-c070b108d3c7 - git:tools/driver/DriverAssitant_v5.14/Driver/x64/win10/rockusb.inf - git:tools/rkdevtool/revision.txt - git:tools/loader/WHICH-LOADER.txt - git:tools/driver/DriverAssitant_v5.14/Readme.txt - git:tools/driver/DriverAssitant_v5.14/revison.log job_cited_source_ids: [] conflicts: [] supersedes: [] preferences: [] source_cursor: 0 source_hash: 5fe39ad3a37421f812566dd39f89d4c28fc6078c8d39031dff10eb6eb8d72e00 prompt_version: 2026-08-12.3 schema_version: '3' curation_job_id: null created_at: '2026-08-08T10:02:39.887705+00:00' updated_at: '2026-09-23T15:03:47.337332+00:00' tags: - deployment - flash - loader - kernel - dtb - docker - security - documentation restored_from_commit: 6a6a895eafcca6052e81a14fca103a42635dd1c2 --- # BDY‑G18 Pro Armbian Builder – Deployment Overview **Workspace**: `BDYG18ProArmbianBuilder` (type **development**) **Scope**: Reproducible creation of a flash‑able Armbian image for the BDY‑G18‑Pro RK3568 router and reliable programming of the device via the Rockchip **RKDevTool** utility. --- ## 1. Project Goal & Target Image - **Goal**: Produce a reproducible, flash‑able Armbian image (Community DIY 13.3 Debian Trixie) with kernel 6.18.x (current build 6.18.40). - **Preferred image**: *stock* – uses the vendor‑verified boot chain (U‑Boot SPL/U‑Boot on SPI‑NOR) with a minimal Armbian rootfs. - **Self‑built mode** is available for auditability. > Sources: `c650c1e4-18ee-44ad-af42-b7632fbdcf5c`, `dd496c6d-1619-457d-86a9-da57f5b866d7`, `aa3057ab-54c5-4ffc-ba85-c2f2396ee60c` --- ## 2. Repository Layout & Build Infrastructure | Directory | Purpose | |----------|---------| | `arm64‑custom/` | Build scripts (`build_g18pro.py`, `build_g18pro.ps1`). | | `evidence/` | Collected logs, DTB files, kernel configs. | | `outputs/armbian-g18pro/` | Final artefacts – compressed image, SHA‑256 manifest, verification report, build log. | | `armbian‑g18pro‑cache` (Docker volume) | Persistent cache (~19 GB) for U‑Boot, kernel, rootfs, ccache. | > Sources: `adb3722a-51e7-4ec5-88cc-a95dc399a7a1`, `Batch 2/16` The **Docker image** used is `ghcr.io/armbian/docker-armbian-build:armbian-ubuntu-noble-latest`. The orchestrator is a Python script plus a PowerShell wrapper that works on Windows PowerShell **or** Linux Bash. > Sources: `adb3722a-51e7-4ec5-88cc-a95dc399a7a1` --- ## 3. Flash Procedure (RKDevTool) 1. **Verify target storage** – select **EMMC** (not SPI‑NOR) in the *Read Flash Info* dialog. 2. Use **RKDevTool V3.37+** (the latest revision listed in the change log). 3. Load the **preferred loader** `rk356x_spl_loader_v1.25.114.bin` (SHA‑256 `d7db6f39…9bba`). 4. **Download Boot** – copies the loader to DDR (RAM) only; no persistent write. 5. *(Optional)* **Switch Storage** if the board has multiple media (UFS, SPI‑NOR). 6. **Burn Loader** – writes the ID‑Block (SPL) to the selected storage. 7. **Flash partitions** – address 0x00000000, force‑address‑write enabled, load the compressed `.img.xz` (≈ 2.12 GiB). 8. After flashing, run `systemctl reboot` (the `syscon‑reboot‑mode` DTB node forces a clean reboot). 9. Verify with `rkdevtool verify` or compare the SHA‑256 manifest against the image file. > Sources: `6`, `7`, `16` (loader 1), `818f5e7c-bf74-4bb0-9bb0-187f7243cf18` ### 3.1 Loader Provenance | Loader | SHA‑256 | Size | Build date | Remarks | |--------|----------|------|------------|---------| | `rk356x_spl_loader_v1.25.114.bin` | `d7db6f39…9bba` | 481 KB | 2026‑01‑09 | Clean upstream copy – **primary** choice. | | `rk356x_spl_loader_v1.21.113.bin` | `589f1a70…8f8b` | 475 KB | – | 8‑byte timestamp/CRC delta – secondary fallback. | | `rk3568_MiniLoaderAll.bin` | `512211c9…3315d2` | 481 KB | – | 10‑byte delta – tertiary fallback. | > Sources: `16` entries 1‑3 --- ## 4. Kernel & System Configuration - **Kernel**: Linux 6.18.40‑current‑rockchip64 (Armbian 26.05.0). - **DTB**: `rk3568‑bdy‑g18‑pro.dtb` (stock) with the following key patches applied: - `syscon‑reboot‑mode` node (clean reboots). - `snps,tso` removed (TSO disabled). - GMAC0 reset‑storm disabled. - **Root‑flags**: `rw,errors=remount-ro` aligned in both `armbianEnv.txt` and `extlinux.conf`. - **Networking**: TCP congestion control set to **Cubic**; TSO/GSO disabled. - **Docker**: Cache volume retained, cgroup options added via `armbianEnv.txt`. > Sources: `aa3057ab-54c5-4ffc-ba85-c2f2396ee60c`, `ff34c6eb-6bba-41e5-9e43-ff80941fa823`, `evidence/live-system/as-shipped-snapshot.txt`, `evidence/live-system/tso-fix-verification-2026-07-31.txt`, `evidence/vendor-backup/vendor-armbianEnv.txt`, `evidence/vendor-backup/vendor-extlinux.conf` --- ## 5. Key Decisions & Rationale | # | Decision | Rationale | |---|----------|-----------| | 1 | Keep **stock U‑Boot** (no custom SPL compile). | Simplifies firmware supply‑chain; stock boot chain is verified. | | 2 | Remove original `emergency‑reboot.shutdown` hook (now redundant). | The new emergency‑restart script (`sysrq‑b`) already guarantees clean reboots. | | 3 | Add `syscon‑reboot‑mode` DTB node and enable it. | Fixes power‑off hang; clean reboot works without manual power‑cycle. | | 4 | Disable hardware TSO (`snps,tso`). | Eliminates massive retransmission storms; network throughput ↑ to 29.6 Mbps. | | 5 | Set TCP congestion to **Cubic** via sysctl. | Improves TCP performance on the router. | | 6 | Enforce SHA‑256 verification of flashed images. | Prevents accidental NOR overwrite (Failure A on 2026‑07‑25). | | 7 | Strip proxy variables inside Docker; optional `G18PRO_PROXY`. | Avoids proxy leakage into container builds. | | 8 | Force LF line endings via `.gitattributes`; disable `core.autocrlf`. | Prevents CRLF corruption in containers. | | 9 | Compress final image with `xz` and record SHA‑256. | Size savings and reproducibility. | |10| Use **Vaultwarden** for credential storage – repository stores only entry **name** and **purpose**. | Secrets never appear in VCS. | |11| AI / Git integration disabled by default. | Keeps builds deterministic. | |12| Shallow Git clones, pin `RKBIN_GIT_COMMIT=ce50c0d1`. | Faster, reproducible builds. | > Sources: `aa3057ab-54c5-4ffc-ba85-c2f2396ee60c`, `ff34c6eb-6bba-41e5-9e43-ff80941fa823`, `bf88c265-4749-4c50-85bc-4bae25298cd5`, `adb3722a-51e7-4ec5-88cc-a95dc399a7a1`, `Batch 2/16`, `105b328f-4bda-4641-90a7-7282ef156316` --- ## 6. Open / Ongoing Deployment Tasks | # | Task | Status | |---|------|--------| | 1 | Verify tiny‑SPI SPL can read > 8 MiB from SPI‑NOR. | Unresolved – needs measurement. | | 2 | Add missing interrupt‑controller node for RTL8367S in DTB. | Open. | | 3 | Validate PCIe BAR allocation (`pci=realloc`). | Planned. | | 4 | Pin `RKBIN_GIT_COMMIT` permanently (currently `ce50c0d1`). | Open. | | 5 | Test `selfbuilt‑ums` mode (USB‑mass‑storage) for field diagnostics. | Open. | | 6 | Implement post‑flash verification watchdog script. | Open. | | 7 | Keep `rockusb.inf` catalog signed (`rockusb.cat`). | Unresolved – required for driver signing enforcement. | > Sources: `aa3057ab-54c5-4ffc-ba85-c2f2396ee60c`, `evidence/emmc-reset-evaluation.txt`, `evidence/live-system/tso-diagnosis-2026-07-31.txt`, `13`, `14`, `15` --- ## 7. Preferences (Scenario‑Level) - **Language**: Chinese (documentation). - **Primary host**: Windows (PowerShell) with Bash support. - **Design philosophy**: KISS & YAGNI; shallow clones; LF line endings; Docker cache retained. - **Secrets**: Vaultwarden only. - **AI/Git integration**: Disabled unless explicitly enabled. > Sources: `ff34c6eb-6bba-41e5-9e43-ff80941fa823`, `bf88c265-4749-4c50-85bc-4bae25298cd5`, `105b328f-4bda-4641-90a7-7282ef156316`, `3f91189b-11a1-45bb-8357-4f413dc1609d` --- ## 8. Tags `deployment, flash, loader, kernel, dtb, docker, security, documentation`