This narrative recounts booting Linux on an Apple M4 Mac mini, detailing reverse-engineering steps and the main blockers. The M4 mandates SPTM, which prevents straightforward MMIO tracing with the m1n1 hypervisor, so m1n1 was installed via macOS recovery and a serial console used to inspect boots. Initial hurdles included disabled GXF and a locked RVBAR that required skipping certain initializations/writes; missing stdout-path hid early printk output until an earlycon serial setting and a 1:1 MMIO mapping in the initial page tables exposed UART output. A write to the virtualization-related implementation register SYS_IMP_APL_VM_TMR_FIQ_ENA_EL2 also crashed the kernel until newer iBoot versions unlocked it.
Bringing up secondary cores exposed a WFI (wait-for-interrupt) erratum: the M4 either zeroed registers on WFI or had the chicken-bit removed, violating ARM behavior and causing crashes. A pragmatic workaround replaced WFI/WFIT with NOPs to boot all cores, and a cleaner upstream solution was created by adding a kernel boot argument to disable WFI idle, letting m1n1 supply that argument on affected bare-metal machines. Those fixes have been merged into mainline Linux and m1n1. Reverse engineering of peripherals (GPU, display, camera) continues using improved hypervisor tracing, with most changes submitted upstream and donations requested to fund the work.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.