From: Alastair D'Silva <alastair@d-silva.org>
To: linux-sunxi@lists.linux.dev
Subject: [TF-A / sunxi] Allwinner A733 (sun60iw2) TF-A Support & Validation on Orange Pi 4 Pro
Date: Tue, 06 Oct 2026 23:22:05 +1100 [thread overview]
Message-ID: <c8d7c508075e081219a0ed9ec8650aebade205db.camel@d-silva.org> (raw)
Hi Andre, Jernej,
I have been working on upstream support for the Allwinner A733 (sun60iw2)
SoC using the Xunlong Orange Pi 4 Pro as my test vehicle.
Building on top of Jernej's in-flight A523/A733 groundwork (specifically
commit 5bc9605cb "feat(allwinner): add A733 support"), I have developed
and verified a clean 6-commit series that completes BL31 enablement for
the A733 without requiring vendor out-of-tree SMC hacks.
Summary of What Was Implemented:
1. Disable SCPI in Favor of Native PSCI:
Explicitly sets SUNXI_PSCI_USE_SCPI := 0 in sun60i_a733/platform.mk to
avoid compiling unused SCPI driver dependencies.
2. Generalize SUNXI_BL31_IN_DRAM and Relocate A733 BL31:
Because U-Boot SPL on this SoC is ~136 KB due to embedded LPDDR5 PMU
firmware, SRAM headroom is insufficient for BL31. I generalized
SUNXI_BL31_IN_DRAM to allow platform override of BL31_BASE and
BL31_LIMIT (placing A733 BL31 in DRAM at 0x48000000), dynamically
named the reserved-memory DT node (tf-a@%lx), and added
common/fdt_wrappers.c to allwinner-common.mk for SUNXI_AMEND_DTB builds.
3. Dedicated 4KB Per-Core Stack for DRAM BL31:
Enlarged PLATFORM_STACK_SIZE to 4KB per core when SUNXI_BL31_IN_DRAM is
enabled.
4. Cortex-A76 Silicon Errata Workarounds:
Enabled applicable Cortex-A76 errata workarounds in platform.mk for
the performance cores.
5. Security Controller Un-gating:
Configured the Security Permission Controller (SPC) decode ports and
bypass register, CCU CPU interconnect clocks and resets, DMAC0
security gate, and dual IOMMU auto-bypass in sunxi_security_setup().
This eliminates the need for vendor SMC fastcall backdoors
(0xC000FF05 / 0xC000FF06) when running normal-world drivers.
6. Per-Core Security Re-arm on PSCI CPU_ON:
Added sunxi_security_setup_core(core) to re-configure only the waking
core's SPC decode port in sunxi_pwr_domain_on_finish(), avoiding full
SoC peripheral security re-initialization on hotplug.
Validation on Physical Hardware:
I verified this series on actual Orange Pi 4 Pro hardware across the
entire software stack:
- 8-Core SMP Boot: Clean bring-up of 2x Cortex-A76 + 6x Cortex-A55 under
Linux 7.x with dual-cluster cpufreq.
- PSCI Dynamic CPU Hotplug: Verified cycling secondary cores 1–7 offline
and back online under load.
- PSCI System Reset: Clean reboot via PSCI SYSTEM_RESET.
- Hardware Qualification: Passed full automated qualification testing
across all SoC peripherals un-gated by BL31, including PCIe Gen3 (NVMe),
Display Engine 3.5 DRM, GMAC, SD card IDMAC, Crypto Engine V5 (HWRNG),
NPU, THS, and PMIC.
Related Repositories & Test Environment:
For reproducibility or inspection of how this integrates end-to-end,
the corresponding branches are available here:
- TF-A (sun60i_a733):
https://github.com/InfernoEmbedded/arm-trusted-firmware/commits/sun60i_a733
- U-Boot (v2026.07 rebase with 100% open-source SPL & freestanding C PMU
firmware, completely replacing vendor boot0 blobs):
https://github.com/InfernoEmbedded/u-boot/commits/feature/sunxi-a733-orangepi4pro
- Linux Kernel (7.x edge with A733 DT and driver support):
https://github.com/InfernoEmbedded/linux/commits/feature/sunxi-a733-orangepi4pro
Upstream Coordination:
The TF-A commits are prepared with Gerrit Change-Id headers.
Jernej, Andre:
How would you prefer to coordinate this for review.trustedfirmware.org?
- Should I submit these 6 commits to Gerrit as dependent changes on top
of your A523/A733 branch?
- Or would you prefer to squash/fold these fixes directly into the base
A733 submission before pushing?
I am happy to follow whichever approach works best for you.
Cheers,
--
Alastair D'Silva
--
Alastair D'Silva
0493 18 5566
next reply other threads:[~2026-10-06 12:22 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 12:22 Alastair D'Silva [this message]
[not found] <d30ac7e4f380c2b9d446ae128ef9f4e4aaa2326a.camel@d-silva.org>
[not found] ` <whzyZ-3mTjSNFzcz-TbNtw@gmail.com>
2026-10-06 20:52 ` [TF-A / sunxi] Allwinner A733 (sun60iw2) TF-A Support & Validation on Orange Pi 4 Pro Alastair D'Silva
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c8d7c508075e081219a0ed9ec8650aebade205db.camel@d-silva.org \
--to=alastair@d-silva.org \
--cc=linux-sunxi@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox