Upstream Linux support available for Qualcomm Snapdragon 8 Gen 3 Mobile Platform
linaro.org
linaro.org
Also those blobs are often targeted at specific kernel versions, so in 2 years when the upstream vendors stop releasing updated blobs, then it no longer becomes possible to upgrade the kernel, making it very very hard to keep last gen devices secure.
This exact problem is why I was forced to admit there is no secure path to use Android today, and a big reason why I gave up on smartphones entirely.
This is not necessary: my Librem 5 doesn't rely on blobs in kernel and runs FSF-endorsed GNU/Linux, PureOS.
Pixels Pro have now... 7 or 8 years support.
[1]: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd...
Librem 5 has very dated hardware that barely runs. It has only Cortex A53 cores @ 1.5 GHz that were released in 2012. You will see it even lag in Purism's videos.
Modern Android phones have better OS, hardware security, battery life and will be useful for longer and cheaper.
Librem 5 now costs 1000 USD, the same price that Google Pixel 8 Pro costs which also has guaranteed 7 years of OS support. Will you want to use Librem 5 in 7 years?
Also let's not forget how Purism took forever to ship the devices and was declining refunds from people that didn't even get sent the device and waited way over a year.
Oh and there are Android phones that can run on mainline kernels.
Yes: Librem 5 is a full desktop, with my full control, "Thinkpad T400 in mobile". It will always run latest Linux and all desktop apps. I can use it as a full desktop connected to keyboard/screen. On the other hand, Android is not a general purpose computer, which only runs what Google allows you to run.
You should try SXMo if you want to see how smoothly Librem 5 and even Pinephone can work if the software is optimized.
> You can't update the firmware at all and you are still running it.
Is there even theoretically an attack vector here?
Yes, Purism has been having problems with refunds. It doesn't affect security or freedom of they devices. Don't buy from them if you will want a refund.
I believe POWER9 is the only modern option that doesn't use blobs? Of course that doesn't remove the possibility of hardware backdoors (nothing does, except maybe an electron microscope and a lot of free time), but that's a higher bar.
Is there open source microcode, at this point? I can't find anything that suggests there is.
On long obsolete AMD K8 CPUs, there was some work on reverse engineering the microcode back in 2017:
Not sure if the Broadcom GbE NICs they use require firmware. It would seem odd to me that they'd go so far as to include an open FPGA[0] for board management and system bringup to avoid closed firmware blobs, only to then rely on a network interface with firmware requirement.
[0] https://www.crowdsupply.com/raptor-computing-systems/talos-s...
Is this true for the blobs in the Snapdragon 8 Gen 3 Mobile Platform?
> How do I run AOSP using Mainline?
> One might think it is quite hard to run AOSP with mainline on such a new platform, but in reality, not at all! Thanks to the long term effort of Linaro and Google engineers making it possible to run AOSP with vanilla Linux releases. Thanks to Amit Pundir for providing a helping hand to get AOSP on this platform.
> To generate an AOSP image for the Snapdragon 8 Gen 3 Qualcomm Reference Device using the current set of patches available on the mailing list, use the following instructions, which are derived from here https://source.android.com/docs/setup/build/devices with some small changes.
Windows supports virtualization on the 8 Gen 3 only because they use a custom setup to load a signed binary blob ("applet") into the EL2 hypervisor, whose signature it is is hardcoded to accept, and that blob/applet then can be used by Windows as a kind of shim into EL2-land to spawn VMs, etc. But Qualcomm's hypervisor is always present and enforcing its security policy.
In practice every single modern system is running tons of binary firmware blobs, it's mostly where you draw the line on functionality and isolation of components (security, integrity, availability.) Here, Qualcomm does intentionally reduce some functionality, which is pretty bad when you consider that the UEFI spec for ARM mandates EL2 handover, I think, and they just ignore it.
Probably execution level 2.
1: https://developer.arm.com/documentation/102412/0103/Privileg...
This is a problem we should be loud critics of. Proprietary firmware hurts us all, and practically benefits no one.
Wake up, Neo. The Matrix has you...
These computers are no longer simple cores with simple devices. If you want that go buy a DOS machine from the 1980's, or a arm7TDMI.
The problem though is that companies invest in all this firmware, and become convinced that DIMM training, signal integrity/phy training, and algorithms which estimate the cooling capacity and thermal mass of the attached heatsink, or any of a hundred other things are somehow competitive advantages and deserve to be locked up behind closed doors rather than opensource. In some cases they are right, but that shouldn't keep them from publishing reference firmware sources and register documentation.
So, really people complaining about proprietary firmware are sorta missing the point. Complain about the lack of documentation to create your own firmware, not that the company thinks they have a competitive advantage in that firmware.
And also admit that what one needs is hardware/firmware abstractions that allow big kernels like linux to communicate with all the little cores in the machine working on specific tasks, be that NVMe for disks, AT command sets for modems, or ACPI for power management.
Not as good as being able to sign it yourself, but way better than not having the source.
It also prevents an attacker from hacking the hardware in a way that would persist after a full reinstall of the OS.
1. https://github.com/FanX-Tek/rk3588-TRM-and-Datasheet/tree/ma...
https://gitlab.collabora.com/hardware-enablement/rockchip-35...
I wish the rk3588 was blobless, sadly not.
Nice little widgets, crazy faster than a pi4.
> In practice every single modern system is running tons of binary firmware blobs
This one does not: https://www.amazon.com/ASUS-C100PA-DB02-10-1-inch-Chromebook...The SoC's boot ROM is 32K, fully inspectable, does not linger once the OS is booted. Every other software component is built from source and you can replicate it
(I use a usb-to-ethernet dongle and the wifi card is disabled, but you are right in theory)
Although "modern" is debatable.
If I had a dollar for every 8051 that turned out to be inside a chip I designed around...
1. Half of the EL3 and EL2 code is so old, it has to jump between aarch32 and aarch64 multiple times during the boot process.
2. The silicon is full of errors. There are also major security vulnerabilities due to Qualcomm doing their own slightly modified version of everything.
3. Not even their biggest customers (e.g. Samsung) is given the source code for the magical blobs used during boot.
4. Given these issues, the EL2 code is basically there to hold things together. It will never go away and they will never show you what it contains
A viable Linux ARM laptop would be cool, especially if it promised high performance and long battery life!
But it would certainly be great to see more variety, and with a standard (ie: UEFI based) install process.
I would already be rocking an X13s if the Linux support was there.
I swear, the MBP running Linux would be an unstoppable development environment - at least as far as ultrabooks go.
With the developments in Proton, FEX (x86 translation), and usability improvements in desktop linux (Gnome 4x and KDE); I'd go as far to say a MBP running Linux with full hardware support would be the best gaming and general purpose ultrabook on the market.
For now I am testing Asahi but daily driving MacOS.
I've been daily driving my pinebook pro since 2020.
Its not actually upstream, is it?
SOS then?
I agree: it's not at all clear from the title, it sounds as if it's truly "upstream."
But patches based on an upstream tree (as opposed to any forks intended for Android) are pretty useful IMO. They're not accepted/landed but you can use them now and I'd wager good money that they'll continue rebasing them until they land, so you should expect to be able to use them for the foreseeable future.
It's still a nice progress though.
And yet laptop manufacturers seem hellbent on insisting 4GB is still acceptable to ship at all, and even still market 8GB machines to professionals. Folks, "professional software" like Slack takes hundreds of MB of RAM to even render the splash screen these days, it should be nearly criminal to ship a consumer device with less than 16GB now (alternatively, we should be taxing software companies for the negative externalities their waste produces, but that's a messy political fight)
Maybe the problem is slack (and every other program hogging your RAM). Just because we can doesn't mean we should. I get that some workloads need RAM but consumers and not even every professional needs it. There are still jobs where you mainly work with an e-mail client, normal sized documents and a browser.
Blame bad developers for developing terrible software, not the companies providing cheap computing for the masses. There can even be an environmental argument against it. I don't even bother downloading the Slack app, I use it on the web for work, but I refuse to install it. Not going to happen, why would I? You shouldn't either.
> it should be nearly criminal to ship a consumer device with less than 16GB now
I assume you were just being hyperbole because now you're talking strictly professional devices. You can and should give your expertise when non techies have opinions, one could even argue it's in our job description. You seem to have just caved and buy more RAM. I took the other more painful route, scrapped every electron app, learned vim, and am very vocal about the issues at $DAY_JOB. If more people did the same would we be in this situation today?
If you're compiling huge programs I get the need for ridiculous amounts of RAM, but consumers should absolutely be fine with 8GB, many even with 4GB. I work in VMs with 4GB daily and it's no problem using my normal stack, a few terminals, a browser window with a couple of tabs. It doesn't break a sweat so it's difficult to relate.
I'm not a big fan of any SoCs which have soldered-on RAM or storage, but I find it an odd point to argue that I'm supporting Apple's ecosystem overall when all I did was buy their hardware on sale. Their App Store is by far their biggest money-maker.
How is that an odd argument? Voting with your wallet suddenly doesn't count because shiny?
To get GNU/Linux going without proper hardware support I can do it myself, no need to pay extra.
But you can at least try to be honest and not spread fud.
What FUD, when the Framework themselves admit none of the provided Linux distributions support 100% of the hardware features they are selling?
We already had white brands doing the same 20 years ago during the dot-com wave.
Eventually tinkering becomes tiresome.
Which means you get exactly what was advertised. Try the other two companies in my list.
https://www.reddit.com/r/System76/s/dohrbjShW6
Great experience for Apple like prices. /s
Also: Please don't post shallow dismissals, especially of other people's work.
Sure, you can go the purist route if you want. But it is not either or, few things in life are.
Funny way of putting "I am stupefied people pay actual, real world money for a laptop with soldered on storage".
And I have talked about storage.
Anyone have a picture of how likely/soon we can reach a future where mobile devices get kernel upgrades in the mainstream market?
I hear graphics drivers are getting pretty isolated now so is it even possible without open graphics?