Re: [PATCH v5 0/8] clk: sunxi-ng: Add support for Allwinner A733 CCU and PRCM
From: Norman Herms
Date: Sat Oct 03 2026 - 09:51:47 EST
Hi ChenYu,
> And presumably things work now because the secure/non-secure access bit
> isn't in effect right now because you aren't using secure boot?
Yes, on our side. One data point from a single board type, Radxa Cubie
A7S, two boards. The measurements and this summary were done by AI
agents (Claude) working on my boards, so please read it as a report,
not as a Tested-by.
- Secure boot is not enabled on these boards: SID + 0xA0 (0x030060A0,
SID_SECURE_MODE in the vendor boot0 sources; the UM does not describe
the SID) reads 0 on both. The notes under PRCM_SEC_SWITCH_REG (UM
V1.00 4.2.5.26) say these registers are always non-secure when the
system is in non-security mode.
- The vendor BL31 blob in Radxa's u-boot package (v2.5) opens the
switches at boot: PRCM_SEC_SWITCH_REG |= 0x7, then 0x7 to
CCMU_SEC_SWITCH_REG at 0x02003F00. TF-A's sunxi_security_setup()
does the same for the H6/H616.
- On the A733, CCMU_SEC_SWITCH_REG is at CCU + 0x1F00 (UM 4.1.6.278),
not 0x0F00 as on the H6/H616; here 0x0F00 is SPI0_CLK_REG (UM
4.1.6.160). The A733 TF-A port at github.com/dlan17/trusted-firmware-a
(branch A733, f4c0b0dba, the commit Radxa's package pins) still uses
0x0F00. On one of our boards the 0x7 ended up in SPI0_CLK_REG until
we moved it to 0x1F00.
- TWD: UM 4.2.5.9 marks S_TWD_BGR_REG as fixed secure. We have not
measured it.
Boot chain on these boards: vendor boot0 (DRAM init), U-Boot SPL and
U-Boot from Radxa's A733 tree with a few board patches, TF-A
lts-v2.12.15 with the A733 port above plus our fixes.
Thanks,
Norman