Future Intel Systems to Be Even Less Friendly for Open-Source Firmware
phoronix.com
phoronix.com
That's a much more serious problem -- potentially even worse than the Intel ME since the ME can't possibly intercept every single memory access without the user noticing the slowdown.
Does the programmable processor itself enforce that signature?
Is there a way to modify the keyring for that verification?
No.
You might be able to use the on-die cache as RAM (most bootloaders do this), but that's less than 128MB. For the amount that these things cost nobody is going to want to use them with that little memory.
To the extent that open source is tolerated at all by OEMs, it will be behind someone's sandbox, whether that be some sort of virtual machine or proprietary baseband firmware that runs as super, super root. Eventually, proprietary firmware will verify and attest that the software you run, from power on to end user application code, is authorized and approved, or the machine will refuse to run it. The CPU will shut off after 30s if it cannot find a vendor-signed, approved boot firmware. All for "security reasons", of course; whose security is not specified.
Today if you want to run entirely open source including firmware, your best shot is a prohibitively expensive workstation with a POWER CPU. That's what all of "general purpose computing" will look like soon; only possible with extremely expensive, boutique equipment. Eventually the profit margins on boutique hardware will crumble and no one without a large corporate or government account will be able to get their hands on hardware uncontrolled by someone's proprietary firmware or OS. That's just the economics of the situation.
So yeah, just buy a Mac. Apple may be a multitrillion dollar company, but a) they own very nearly EVERY piece of IP inside that Mac, and when they say "jump", the supply chain asks "how high", meaning that unlike other OEMs, Apple is beholden to NO ONE; b) they are the only OEM that comes remotely close to giving a shit about you, the end user. It's hard to overstate what a miraculous company Apple truly is.
My hope is for frame.work, pine64 and others to get to a point where risc-v or ppc models would be offered.
I have more hours delivering stuff into production using Solaris, HP-UX and Aix, than GNU/Linux.
In fact, had Microsoft been serious with their POSIX subsystem for Windows NT, I most likely wouldn't have bothered with Linux during the university, which for a big part of our lectures was still using DG/UX.
The success of macOS and Microsoft's WSL endeavors prove that most people only care to have some kind of POSIX support, regardless of the actual kernel.
If there is a riscv64 server/workstation out there that I can buy, today, I would love to order one.
They're the "closest", but not remotely close.
AFAICT all the SiFive products that are available to purchase and have workstation-ish amounts of RAM require boot blobs. I would be happy to be wrong about this.
https://forums.sifive.com/t/remaining-agency-issues-to-be-so...
Apparently there was a very limited run of dev boards for which no blobs are needed, and then they promptly discontinued that product and replaced it with a (confusingly-similarly-named) blobbified product that you can pre-order via mouser (listed as "backordered, no ETA"). This product is already marked EOL which is not encouraging.
https://drewdevault.com/2022/01/15/2022-01-15-The-RISC-V-exp...
That board's firmware is not open-source at all. See the link in my previous comment.
> Zero idea what blobs this requires.
You've stumbled into the wrong thread, my friend. This thread is about open-source firmware. The stuff you're hyping does not deliver that.
I am definitely not hyping anything, least of all SiFive.
This subthread started with the need for RISC-V workstations, I simply pointed out the closest thing to one of those. Of course I didn't mention the firmware situation, which was a mistake, but I also didn't know about the situation.
And in a way I suppose it makes some sense, very few (laymen) care about open firmware.
But this is another bleak piece of reality being nailed down the into the open source coffin.
Hahaha, my sides are splitting! Hahaha!
And the future is open-source firmware.
The catch (of the day)? Strong trademark protection and certification to be included in the global supply chain.
Print that out and trace it on your ass Mr. Stallman.
Hahaha. I'm sad.