14 ms·
Demystifying the i-Device NVMe NAND
- mi100hael 10y ago> In order to read the NVMe, I therefor developped a PCIe card with a Zero > Insertion Force reader. I brought the JTAG part to 20pin header. The hard > pard in here is the signal integrity of the differential pairs. In order > to do so, I had to use multi layer PCB, and have the impedence match by > knowing the stackup, materials used for prepeg and so on.. Posts like this are very humbling. They serve as a good reminder that no matter how far I've come and how much I've learned, there will always be someone out there who knows vastly more than me like the back of their hand.
- akuma73 10y agoDon't feel too bad. Fully understanding the complete stack of a modern computer system is outside the scope of almost everyone. These things are complicated and we've built abstractions, interfaces and modules to manage the complexity. People specialize in their own fields. I am trained in digital integrated circuit design, but don't ask me to build a file system.
- djsumdog 10y agoExactly. This is super impressive work, but also very specialized. Even for non-EE majors, most IT people could at least understand the basics of what he was doing.
- camboyero1992 10y agoAgreed - we are all so deep in our stacks that we all look like wizards to outsiders.
- alexbeloi 10y agoI bet he plays jazz piano too.
- revelation 10y agoThat's the bread and butter of digital EEs. In fact a digital EE would be very happy if all he had to do was a 4 layer board with a single 70 ball chip :)
- dom0 10y agoThe layout here shouldn't be difficult at all - but the other feats are quite impressive, still :)
- setq 10y agoAll these things are just different worlds. I'm the same when it comes to medicine or tree surgery or a multitude of different things. I have no idea how a security guard even works! On this subject though, I did EE in the past and now software and it's roughly as complicated as throwing some code together after a few years of practice. Except that the design rules, physics and CAD software are perhaps ironically somewhat better defined than what the software industry has managed! Many an EE has looked in awe at the software that we write too.
- StavrosK 10y agoIt's not even that hard, I managed to design a simple PCB after only a few months of tinkering with hardware. It's really not bad, and very fun. I recommend it to everyone.
- TTPrograms 10y agoI enjoy PCB design too - through it results in me spending an inordinate amount of time tweaking trace placement and ground planes for mostly aesthetic purposes :)
- StavrosK 10y agoThat is 90% of the fun :P
- setq 10y agoRecommended too. For one-offs you can entirely forgo the PCB design if you so desire as well and just use the PCB stock and rats nest it. One of my creations: http://imgur.com/mcS79lU http://imgur.com/mcS79lU - fugly but very robust, functional, free of nasty parasitics and from paper to powered up and working is around 20 minutes work.
- dom0 10y ago> I have no idea how a security guard even works! Hm. Can someone shed some light on this?
- pjc50 10y agoThis side of the business is actually pretty straightforward to learn and be guided by your PCB assembly house and design software. Ask the PCB fab for the stackup, punch 90 ohms into the calculator, and get a number in mils for the PCB software. And the dirty secret is that for short runs, testbeds and hacking tools you can often cheat on the controlled impedance a bit to produce abominations like USB-over-FFC and three-ended ethernet cables. Now, hot air rework, that's a serious manual skill that I respect. (I suppose the difference versus learning software development work is that failures are expensive...)
- erichocean 10y ago> Ask the PCB fab for the stackup, punch 90 ohms into the calculator, and get a number in mils for the PCB software. This sounds like gibberish to me. (I know it's not, just that the notion that it's "straightforward to get into" is maybe off the mark.)
- rfrank 10y agoThe stackup is what controls the layers of a bare PCB; signal, power, ground, etc [1]. An engineer at your board supplier is likely involved in determining the stackup with the EE and PCB designer. The stackup and material selection of the bare board is one of the things that controls min/max trace width, proximity, etc. Once you have that info, you can plug it into your CAD tool of choice, for instance in Mentor Xpedition it's CES [2]. Makes things like differential pairs a lot easier. 1. http://blog.optimumdesign.com/hdi-layer-stackups-for-large-dense-pcbs http://blog.optimumdesign.com/hdi-layer-stackups-for-large-d... 2. https://www.mentor.com/pcb/xpedition/constraint-manager/ https://www.mentor.com/pcb/xpedition/constraint-manager/
- jdietrich 10y agoGood SMT rework is 60% flux, 20% isopropyl alcohol, 10% magnification and 10% practice. The trick is surface tension - if the surfaces are properly wetted, surface tension pulls the part into alignment as if by magic. Achieving good wetting is as simple as getting the solderable surfaces spotlessly clean and deoxidized, then using copious amounts of flux. If your preparation is good, the parts almost solder themselves. Fine-pitch BGA rework can be genuinely challenging, but the core skills are remarkably straightforward. A complete novice can rework QFNs and 0603 passives with very little practice if they're taught the correct techniques. I actively prefer working with SMT over through-hole.
- honkhonkpants 10y agoSome big words mixed in there, but if you try your hand at this I think you'd find that making impedance-controlled differential traces on a PCB isn't much of a trick at all. It's a difficult engineering challenge if you intend to mass produce, but it's not a challenge if you intend to make 10 boards and you aren't cost sensitive and you don't care if 9 boards don't work.
- muad 10y agoGeneralists usually feel that way about specialists.
- cushychicken 10y agoI help design PCIe cards and interfaces, and this guy's work is blowing my fucking mind.
- iuuuuu145 10y ago>It looks like to reduce the size needed, the NVMe core uses the host DDR in order to work. Therefor, apple is not strictly following the specification regarding the initialisation. Yikes.
- deleted 10y ago[deleted]
- codebook 10y agoNVMe added feature of HMB (Host Memory Buffer) to use host DDR rather than internal RAM. So, I think this chip used HMB feature.
- drv 10y agoIt's presumably not standard Host Memory Buffer, since the spec says "The controller shall function properly without host memory resources."
- misnome 10y agoIt's not as though they are manufacturing these for anybody else to use.
- djsumdog 10y agoDoesn't surprise me; Apple for not doing anything by standards. When you control all the hardware, I guess it doesn't matter. You can have broken ACPI and driver implementations all over the place. I've started to give up on ARM embedded boards for the same reason. You need to build out images for all the different potential ARM systems if they don't use device trees. There are Intel Atom/AMD Geode Pi/Beagelboard clones that will boot up just like a desktop and you can install most Linux distributions right on them without modification. If ARM ever decides to start selling an architecture spec instead of just a SoC spec, I think it would go a long way at making it a better platform. I'm pretty sure Apple would still ignore it f
- StillBored 10y ago
- kanwisher 10y agoRefreshing to see a deep tech article on HN. I really liked how he debugged the code on the controller
- deleted 10y ago[deleted]
- sounds 10y agoThe gold is at the bottom: The idea here would be to see if it was possible to control the NVMe over jtag in order to ask it to perform a DMA read over the PCIe Bus. In order to do so, the PCI_COMMAND_BUS_MASTER has to be set to 1. We can assume that since the chip is using remote RAM, it is allowed to act as a master over PCIe. Here is a snippet of the probing function of the kernel driver. (code) Our goal here is to force the DMA to happen just by controlling the ARM of the NVMe over JTAG, in order to ask it to dump the region we alloc'd in kernel and see if we get the data out of it. In other words, full root exploit of the phone from the NVMe JTAG pins.
- walterbell 10y agoDoes the phone's ARM CPU have an IOMMU?
- huslage 10y agoYes
- revelation 10y agoThe JTAG angle is unnecessary, and difficult to do in practice with this LGA70 chip face-down soldered onto the logic board. It really means there is a Cortex-A (so lots of brunt) with a firmware update mechanism that has 1) direct access to the application processor RAM and 2) direct access to the plentiful permanent storage.
- huslage 10y agoHe made a board so that he can do JTAG in-line. Not sure how else he could tell the processor to do something.
- AstralStorm 10y agoBy flashing custom unverified firmware, of course.
- nimish 10y agoApple's purchase of Anobit is paying dividends!
- digi_owl 10y agoSometimes i wonder how many companies Apple has bought that now simply exist to make parts of Apple products.
- threeseed 10y agoSomewhere in the vicinity of 20 companies. What's interesting is that about a third of those companies we have yet to see the output of. Expect Apple to get into AR/VR in a big way in 2017/2018.
- SmokyBorbon 10y agoThe grammar and spelling. Holy hell.
- athiercelin 10y agoVery good stuff!
- mmastrac 10y agoHas anyone managed to capture the text of this article? It doesn't appear to be in a Google cache AFAICT.
- arm 10y agohttps://archive.is/FGIiC https://archive.is/FGIiC
- condescendence 10y agoDefinitely one of the cooler and more in depth posts this year, what a great read.
- deleted 10y ago[deleted]