Adventures in reverse engineering Broadcom NIC firmware
devever.net
devever.net
If anyone attending 37C3 wants to talk more about this, or anything else, or about open source firmware/owner control in general, don't hesitate to get in touch with me in person or online.
I don't have access to my usual email when traveling for security reasons, so use my travel email: https://www.devever.net/~hl/contact
I'll also set up a DECT phone at the event (4526/HUGO).
Comments and questions welcome!
Registers 0x7d10 (sequence number) and 0x7d38 (TLP data) allow you to send custom PCIe TLPs, which let you do the configuration space writes required to get the other card to talk to it. https://citeseerx.ist.psu.edu/document?repid=rep1&type=pdf&d... (see page 383)
It's quite suprising to see one NIC blinking the LEDs of another, by writing to its registers over the point-to-point PCIe link (I used twisted-pair wire-wrap wire to connect them together).
Here's the code to do it, you run it on the MIPS processor: https://pastebin.com/ZJdaUpRZ
This is enough to load custom firmware on a GPU, and get the two talking together, with network access, by the way!
Also the Intel i210 NIC can do this as well, it has an ARC Tangent-A4 processor in the management engine. Same for the i225, but I believe that one has secure boot to prevent unauthorized firmware from running.
We obviously want 100GbE because frankly why bother with less? So you need to translate https://github.com/corundum/corundum into an ASIC and then produce probably a few (ten) thousand ICs to make it worth it. However, you quite likely can get away with an old node -- the Intel XL710 40GbE chip, for example, is produced on a 28nm node.
So the production will be cheap, the initial ASIC engineering and prototyping is going to cost you a bit. But the (very) hard part is luckily already done.
More broadly (no pun intended), NIC vendors want to work with Linux and the GPL means they have to release the source of a driver to do so. No such legal requirement applies to firmware.
> One example motivating the production of open source firmware for the BCM5719 is that it's the only closed-source firmware blob found in the Talos II, a high-performance POWER9-based system otherwise wholly free of firmware blobs... Once this is delivered, it will be possible to use Raptor's POWER9 systems with purely 100% free, open source firmware. As far as I am aware, there is no other machine in the same performance class which can make such a claim.
Firmware is the new proprietary/FLOSS boundary layer.
Unfortunately (for better or worse) GPLv3 flopped
https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://events19.linuxfoundation.org/wp-content/uploads/2017...
The situation around GPL "condoms" would be the same for both GPLv2 and GPLv3 too, if the firmware can be considered a derivative work then there may still be a GPL violation, but more likely the driver<>firmware interface would be fairly high-level, so all the functionality is in the firmware.