[PATCH v5 0/8] clk: sunxi-ng: Add support for Allwinner A733 CCU and PRCM

Norman Herms dockseed at proton.me
Sat Oct 3 06:51:18 PDT 2026


Hi ChenYu,

> And presumably things work now because the secure/non-secure access bit
> isn't in effect right now because you aren't using secure boot?

Yes, on our side. One data point from a single board type, Radxa Cubie
A7S, two boards. The measurements and this summary were done by AI
agents (Claude) working on my boards, so please read it as a report,
not as a Tested-by.

- Secure boot is not enabled on these boards: SID + 0xA0 (0x030060A0,
  SID_SECURE_MODE in the vendor boot0 sources; the UM does not describe
  the SID) reads 0 on both. The notes under PRCM_SEC_SWITCH_REG (UM
  V1.00 4.2.5.26) say these registers are always non-secure when the
  system is in non-security mode.

- The vendor BL31 blob in Radxa's u-boot package (v2.5) opens the
  switches at boot: PRCM_SEC_SWITCH_REG |= 0x7, then 0x7 to
  CCMU_SEC_SWITCH_REG at 0x02003F00. TF-A's sunxi_security_setup()
  does the same for the H6/H616.

- On the A733, CCMU_SEC_SWITCH_REG is at CCU + 0x1F00 (UM 4.1.6.278),
  not 0x0F00 as on the H6/H616; here 0x0F00 is SPI0_CLK_REG (UM
  4.1.6.160). The A733 TF-A port at github.com/dlan17/trusted-firmware-a
  (branch A733, f4c0b0dba, the commit Radxa's package pins) still uses
  0x0F00. On one of our boards the 0x7 ended up in SPI0_CLK_REG until
  we moved it to 0x1F00.

- TWD: UM 4.2.5.9 marks S_TWD_BGR_REG as fixed secure. We have not
  measured it.

Boot chain on these boards: vendor boot0 (DRAM init), U-Boot SPL and
U-Boot from Radxa's A733 tree with a few board patches, TF-A
lts-v2.12.15 with the A733 port above plus our fixes.

Thanks,
Norman



More information about the linux-riscv mailing list