The Forgetful CPU (Linux on M4)
In November 2024, the author acquired an M4 Mac mini, hoping that it would be compatible with Asahi Linux, the open-source project aimed at bringing Linux support to Apple Silicon devices. However, the M4 SoC presented several challenges, as it was the first generation of Apple Silicon to enforce Secure Page Table Monitor (SPTM), a security feature designed to protect against vulnerabilities in the XNU kernel of macOS.
This new security measure necessitated significant modifications to the Linux boot process, making it a more daunting task for the newcomer.
The M4 SoC's Secure Page Table Monitor (SPTM) required the author to disable strict boot security and use the m1n1 hypervisor to capture MMIO traces, which were instrumental in understanding the interactions between the original macOS drivers and the hardware. Despite these efforts, the Linux boot process on the M4 SoC proved to be more complex than expected, as the hypervisor work required extensive modifications to the m1n1 hypervisor to accommodate the SPTM constraints.
As the author continued to troubleshoot the M4 SoC, they disabled the GXF functionality, which was disabled or locked in raw boot mode on these SoCs. Additionally, the RVBAR (Reset Vector Base Address Register) needed to be modified to ensure the correct starting address for the CPU core. However, the author encountered further difficulties when attempting to enable the UART (Universal Asynchronous Receiver-Transmitter) during the kernel boot process.
Bisecting the Linux boot process revealed that the MMU (Memory Management Unit) initialization was causing the CPU to crash. The author discovered that the UART was accessed using memory-mapped I/O (Memory-Mapped I/O), which caused issues when the MMU was enabled. By adding a 1:1 mapping for the MMIO space, the author managed to restore the UART functionality, allowing the debug_putc assembly routine to print a character and progress further into the boot process.
After successfully booting Linux on the M4 Mac mini, the author encountered another challenge when trying to access the serial console for debugging output. The device tree was missing a serial path, which was easily resolved by adding the necessary configuration. Once the serial console was enabled, the author was able to view register dumps and stack traces from Linux during early crashes, providing valuable insight into the boot process and potential areas for further investigation.
Throughout the process, the author noted that the Asahi kernel had unlocked the SYS_IMP_APL_VM_TMR_FIQ_ENA_EL2 register, which was initially commented out due to its relation to virtualization. With this newfound knowledge, the author was able to successfully boot Linux on the M4 Mac mini and explore the operating system's capabilities on Apple Silicon devices.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- The forgetful CPU (Linux on M4) yuka.dev