Re: [PATCH v5 3/8] clk: sunxi-ng: a733: Add PRCM CCU

From: Norman Herms

Date: Sat Oct 03 2026 - 13:10:14 EST


Hi Junhui, ChenYu,

> > The three bus dividers are secure by default, and either need to be toggled
> > to non-secure by the bootloader, or (I'm guessing) the system is running
> > without secure boot and the secure access bit isn't in effect.
> >
> > Please add a comment about this.
>
> Okay, I will add a comment explaining this.

A data point for that comment, measured since my last reply. For the
registers behind a security switch, ChenYu's guess holds on our boards.
Two test BL31s, each clearing a switch again after
sunxi_security_setup(), then reads and writes from U-Boot at
non-secure EL2:

- PRCM_SEC_SWITCH_REG bit 0 cleared (0x07010290 reads 0x6): r-ahb
reads 0x03000000 and r-apb1 0x04000000, the values EL3 reads, and a
write to r-apb0 (0 -> 1 -> 0) sticks.

- CCMU_SEC_SWITCH_REG cleared to 0 (PLL, BUS and MBUS secure): PLL_PERI0,
AHB, APB0, APB1, TRACE, the AHB and MBUS master gating, NSI and MBUS
read the values EL3 reads. Writes to PLL_NPU pattern 0 and to TRACE
stick, and U-Boot's own write to the MBUS gate enable register
(0x4 -> 0x804) sticks.

So on these non-fused parts (SID + 0xA0 = 0) the switch bits do not
gate non-secure access, as the UM notes on these registers say for
non-security mode. With secure boot enabled, the bootloader has to set
them; we cannot test that.

That narrows what I wrote earlier about secure filtering without the
fuse: on our boards it applies to the registers the UM marks as fixed
secure (S_TWD_BGR_REG), to CCMU_SEC_SWITCH_REG itself and to the SPC
status words, not to the registers behind a switch. We tested a sample
of each switch group, not every register.

One board, AI agents (Claude) on my board as before, so a report, not
a Tested-by.

Thanks,
Norman