rellla changed the topic of #linux-sunxi to: Allwinner/sunxi /development discussion - did you try looking at our wiki? https://linux-sunxi.org - Don't ask to ask. Just ask and wait! - https://github.com/linux-sunxi/ - Logs at http://irclog.whitequark.org/linux-sunxi - *only registered users can talk*
cmeerw has quit [Ping timeout: 264 seconds]
matthias_bgg has quit [Quit: Leaving]
ChriChri_ has joined #linux-sunxi
ChriChri has quit [Ping timeout: 260 seconds]
ChriChri_ is now known as ChriChri
apritzel has quit [Ping timeout: 264 seconds]
guest33333 has joined #linux-sunxi
guest33333 has left #linux-sunxi [#linux-sunxi]
gaston1980 has quit [Ping timeout: 240 seconds]
KotCzarny has quit [Ping timeout: 240 seconds]
Mangy_Dog has quit [Ping timeout: 246 seconds]
Mangy_Dog has joined #linux-sunxi
TheSeven has quit [Ping timeout: 244 seconds]
TheSeven has joined #linux-sunxi
victhor has quit [Ping timeout: 260 seconds]
shailangsa has quit [Ping timeout: 244 seconds]
shailangsa has joined #linux-sunxi
shailangsa has quit [Ping timeout: 240 seconds]
shailangsa has joined #linux-sunxi
_whitelogger has joined #linux-sunxi
KotCzarny has joined #linux-sunxi
KotCzarny has quit [Ping timeout: 240 seconds]
AneoX has quit [Ping timeout: 260 seconds]
AneoX has joined #linux-sunxi
vagrantc has quit [Quit: leaving]
AneoX has quit [Ping timeout: 265 seconds]
AneoX has joined #linux-sunxi
lurchi_ has joined #linux-sunxi
lurchi__ has quit [Ping timeout: 272 seconds]
Asara has quit [Ping timeout: 258 seconds]
asdf28 has joined #linux-sunxi
KotCzarny has joined #linux-sunxi
_whitelogger has joined #linux-sunxi
rex_victor has joined #linux-sunxi
asdf28 has quit [Ping timeout: 272 seconds]
gsz has joined #linux-sunxi
lvrp16 has quit [Ping timeout: 240 seconds]
ullbeking has quit [Ping timeout: 260 seconds]
aliosa27 has quit [Ping timeout: 260 seconds]
steev has quit [Ping timeout: 264 seconds]
ccaione has quit [Ping timeout: 260 seconds]
pdp7 has quit [Ping timeout: 260 seconds]
arnd has quit [Ping timeout: 264 seconds]
narmstrong has quit [Ping timeout: 260 seconds]
ric96 has quit [Ping timeout: 272 seconds]
warpme_ has quit [Ping timeout: 264 seconds]
Benjojo has quit [Ping timeout: 260 seconds]
jeandet has quit [Ping timeout: 240 seconds]
charco has quit [Ping timeout: 260 seconds]
<bauen1> smaeul: there's a 2nd attack that does not require a valid toc0, only the magic must match
<bauen1> but iirc the quick test you did didn't result in hijacking the pc
<bauen1> so maybe it doesn't work
<bauen1> not being able to enter secure mode from fel is actually kind of what i want lol
<bauen1> i suspected that it wasn't really possible to mess with secure boot without bricking a board
<bauen1> but you've already tried a board with an empty rotpk hash so i just need to try with a valid rotpk
<bauen1> i also suspect that code running on the ar100 is always in secure mode, so maybe that is a possible attack vector
<bauen1> and (if you have an fpga) you could always try to power-glitch the image verification
<bauen1> DMA shouldn't be possible if the (presumably existing) SPC is configured correctly
<bauen1> this is funny, on the one side it would be bad for my use case if we can find a way to enter secure mode, on the other hand i don't fancy bricking my only h64
<bauen1> arm cores also have some form of debug, but i believe that is initially disabled
<bauen1> and iirc there's some code in at least the h3 fel enter code that disables it
<bauen1> but it might be worth a shot
ric96 has joined #linux-sunxi
jeandet has joined #linux-sunxi
arnd has joined #linux-sunxi
<bauen1> the h5 sbrom also copies some informationn related to the rotpk to 0x10000 before entering fel (if it isn't overwritten) so dumping memory even from fel might reveal some helpful information
pdp7 has joined #linux-sunxi
ccaione has joined #linux-sunxi
steev has joined #linux-sunxi
warpme_ has joined #linux-sunxi
charco has joined #linux-sunxi
<bauen1> smaeul: but maybe you can add the brom dump ?
lvrp16 has joined #linux-sunxi
Benjojo has joined #linux-sunxi
narmstrong has joined #linux-sunxi
aliosa27 has joined #linux-sunxi
iamfrankenstein has joined #linux-sunxi
ullbeking has joined #linux-sunxi
<bauen1> also looks like the usb on the pinephone is wired to the usb-otg, makes it a bit hard to "disable" (i.e. burn) fel on the a53
asdf28 has joined #linux-sunxi
steev has quit [Ping timeout: 272 seconds]
steev has joined #linux-sunxi
cmeerw has joined #linux-sunxi
JohnDoe_71Rus has joined #linux-sunxi
lurchi_ is now known as lurchi__
The_Loko has joined #linux-sunxi
rex_victor has quit [Ping timeout: 272 seconds]
karme` has joined #linux-sunxi
karme` has left #linux-sunxi [#linux-sunxi]
Net147_ has quit [Quit: Quit]
Net147 has joined #linux-sunxi
msimpson has joined #linux-sunxi
iamfrankenstein has quit [Quit: iamfrankenstein]
victhor has joined #linux-sunxi
cnxsoft has joined #linux-sunxi
cnxsoft1 has quit [Read error: Connection reset by peer]
lurchi__ is now known as lurchi_
_whitelogger has joined #linux-sunxi
rex_victor has joined #linux-sunxi
apritzel has joined #linux-sunxi
victhor has quit [Quit: Leaving]
gaston1980 has joined #linux-sunxi
jbrown has joined #linux-sunxi
chewitt has quit [Read error: Connection reset by peer]
chewitt has joined #linux-sunxi
apritzel has quit [Ping timeout: 258 seconds]
Asara has joined #linux-sunxi
hanni76 has joined #linux-sunxi
jernej has quit [Quit: Free ZNC ~ Powered by LunarBNC: https://LunarBNC.net]
jernej has joined #linux-sunxi
apritzel has joined #linux-sunxi
lurchi_ is now known as lurchi__
diego71 has quit [Ping timeout: 258 seconds]
AneoX has quit [Ping timeout: 264 seconds]
AneoX has joined #linux-sunxi
lurchi__ is now known as lurchi_
victhor has joined #linux-sunxi
<Ashleee> RE tftpboot -- I can confirm that during the lost packet even ping gets lost
<smaeul> bauen1: which brom dump? H6 NBROM is already posted. I cannot access H6 SBROM because I can only access FEL, and I can't switch BROMs from NS mode
hanni76 has quit [Remote host closed the connection]
<apritzel> smaeul: how do you switch the BROM mappings? Is that documented somewhere? I was under the impression that starting in secure boot mode would leave the SBROM mapped?
<smaeul> apritzel: no, FEL is implemented in NBROM, so entering fell switches between them
nashpa has quit [Ping timeout: 256 seconds]
<apritzel> ah, I see. That explains why FEL reads of the BROM area gave me the same results between normal and secure-fuse-burnt A64
<apritzel> so does reading (and dumping) the BROM from a TOC0 image work?
<smaeul> on A64/H5, it's bit 31 of 0x1c000f0: 0 => SBROM, 1 => NBROM. the bit is ignored and RAZ when secure boot is disabled
nashpa has joined #linux-sunxi
<apritzel> smaeul: nice! thanks!
black_ink_ has quit [Quit: ZNC 1.7.3 - https://znc.in]
black_ink has joined #linux-sunxi
<smaeul> (this is func_000080ac in the H5 SBROM)
<apritzel> smaeul: do you happen to know how this switching works? My guess was that the SoC always boots with the SBROM mapped, then checks the secure fuse and switches to the NSBROM immediately when this is not burnt?
<smaeul> apritzel: yes, reading the SBROM from U-boot works when loaded from TOC0. I have it here: https://github.com/smaeul/sunxi-blobs/tree/master/sun50iw2p1/sbrom
<apritzel> from U-Boot even? So from non-secure world?
<smaeul> right
<smaeul> apritzel: I don't think it loads SBROM at all without the fuse. the BROM toggle bit is ignored, and most of the initial setup logic is duplicated between the two BROMs
yann has quit [Remote host closed the connection]
<apritzel> I see, thanks
gnarface has quit [Quit: Leaving]
victhor has quit [Remote host closed the connection]
netlynx has quit [Quit: Ex-Chat]
lurchi_ is now known as lurchi__
yann has joined #linux-sunxi
tuxillo has quit [Ping timeout: 260 seconds]
tuxillo has joined #linux-sunxi
gsz has quit [Quit: Konversation terminated!]
sunshavi has quit [Read error: Connection reset by peer]
damex has quit [Read error: Connection reset by peer]
AneoX has quit [Ping timeout: 260 seconds]
AneoX has joined #linux-sunxi
damex has joined #linux-sunxi
apritzel has quit [Ping timeout: 256 seconds]
damex_ has joined #linux-sunxi
damex has quit [Ping timeout: 272 seconds]
sunshavi has joined #linux-sunxi
damex_ has quit [Read error: Connection reset by peer]
damex has joined #linux-sunxi
rojiro has quit [Ping timeout: 240 seconds]
rojiro has joined #linux-sunxi
damex_ has joined #linux-sunxi
apritzel has joined #linux-sunxi
damex has quit [Ping timeout: 240 seconds]
xzz53 has quit [Ping timeout: 258 seconds]
xzz53 has joined #linux-sunxi
akaWolf has quit [Ping timeout: 264 seconds]
sunshavi has quit [Read error: Connection reset by peer]
akaWolf has joined #linux-sunxi
parazyd has left #linux-sunxi [#linux-sunxi]
sunshavi has joined #linux-sunxi
sunshavi has quit [Ping timeout: 260 seconds]
victhor has joined #linux-sunxi
JohnDoe_71Rus has quit [Quit: KVIrc 5.0.1 Aria http://www.kvirc.net/]
diego71 has joined #linux-sunxi
lurchi__ is now known as lurchi_
asdf28 has quit [Ping timeout: 268 seconds]
lurchi_ is now known as lurchi__
lurchi__ is now known as lurchi_
cmeerw has quit [Ping timeout: 244 seconds]
lurchi_ is now known as lurchi__
The_Loko has quit [Quit: Leaving]
gnarface has joined #linux-sunxi
mps has quit [Read error: Connection reset by peer]
mps has joined #linux-sunxi
putti_ has joined #linux-sunxi
book` has quit [Ping timeout: 260 seconds]
Putti has quit [Ping timeout: 260 seconds]
book` has joined #linux-sunxi
gendevbot has quit [Ping timeout: 240 seconds]
gediz0x539 has quit [Ping timeout: 240 seconds]
vagrantc has joined #linux-sunxi
luke-jr has quit [Read error: Connection reset by peer]
msimpson has quit [Quit: Leaving]
luke-jr has joined #linux-sunxi
lurchi__ is now known as lurchi_