12 ms·
Introduction to Apple Silicon
- randyrand 4y ago> You do have to click through Apple's EULA in order to use the machines at all. Someone does. You can walk up to a Mac at a friends house and use it without accepting any EULA. The machine doesn't physically check who accepted the EULA. You can do everything without ever accepting a EULA yourself.
- macintux 4y agoThe overview document makes for an interesting read. Definitely worth referencing next time someone on HN or elsewhere claims Apple's trying to lock down their computers to running macOS only. https://github.com/AsahiLinux/docs/wiki/Introduction-to-Apple-Silicon https://github.com/AsahiLinux/docs/wiki/Introduction-to-Appl...
- reaperducer 4y agoImportant bit: Apple gives users explicit permission to run their own OS in their EULA.
- jaimex2 4y agoIts not like it would matter if they didn't. It's your hardware.
- ChuckNorris89 4y agoTell that to Nintendo.
- Forgeties79 4y agoIt’s baffling how outright hostile Nintendo sometimes can be to its most devoted fans. And it’s not even new - they’ve gotten away with it since the moment they stepped into video games.
- MBCook 4y agoIt’s not baffling at all. That’s what kept them alive. In Japan the Famicom was open, and it got flooded with junk like the Atari 2600 did. This threatened the same problems as Atari ran into. The Famicom Disk System relied on a strange copyright check on the physical disks to make them harder to pirate. It worked better than nothing, but not perfectly. The NES came out after the disk system but before the first mapper chips (which Nintendo controlled tightly for a few years) in 1985. By that time they had been through the problems in Japan and seeing what happened in America with the Atari crash Nintendo, rightly, knew they couldn’t let it happen again in America. They needed to show their console wouldn’t be full of complete trash, so they used the lockout chip to ensure all publishers had to through them. It’s a big part of why they were successful and able to reinvigorate the US market. It worked until the chip was cracked later in the console’s lifecycle. But by then the threat passed, the NES was safely ensconced. They’ve never forgotten that lesson. (No comment on fans)
- musictubes 4y agoAll the best games for the 2600 were by third parties. There were very few good Atari games and none of them came close to the quality of the best third party games. Pretty sure it was Atari's own horrible ET game that sank them, not other companies.
- philistine 4y agoPretty sure doesn’t cut it. You’re wrong. It wasn’t as easy as OP make it out to be, that the glut of third-party games killed the 2600, but it wasn’t Atari’s own games who cratered the price of a 2600 title and took the whole console market down.
- Forgeties79 4y agoE.T. was just one more line item on a massive list of reasons for why the video game industry imploded on itself with Atari standing pretty much dead center of the blast zone.
- Forgeties79 4y ago
- est31 4y agoOn a technical level, you can't install third party OSs without accepting the EULA first. Whether such acceptance has legal meaning, I don't know, and it probably depends on jurisdiction.
- sgjohnson 4y ago> On a technical level, you can't install third party OSs without accepting the EULA first. You absolutely can (no EULA when booting into recovery partition), and I’m also fairly sure that acceptance would be legally void, as it only applies to the software. The hardware you own, it’s not licensed to you. And thanks to the first sale doctrine, there’s nothing stopping someone from starting to sell M1/M2 MacBooks running Asahi commercially.
- est31 4y agoI base this upon what I read in OP. From OP: > You do have to click through Apple's EULA in order to use the machines at all. > Owner control is asserted on first boot (you become machine owner by going through the macOS setup flow and creating the first admin user). > The SEP maintains a database of machine owner users. The first such user is created when the user goes through the macOS boot flow on first startup from a factory-fresh state (or after a full DFU wipe). Subsequent machine owners can only be created by authenticating with an existing owner's credentials. > Permissive Security allows for ~all security features to be disabled, and third-party kernels to be installed. No phoning home is required. Downgrading to Permissive Security requires booting in 1TR paired to the specific OS involved, and authenticating using machine owner credentials. It seems to me that you can boot into the recovery partition but in order to be able to boot Linux, you need to authenticate using machine owner credentials, which you only get if you go through setup of the OS, for which you need to accept the EULA. However, on the good news front, OP also writes that no internet access is required for any of these steps.
- owow123 4y ago"On a technical level..." Sorry, what? Does buying a device from Apple contractually oblige me to turn on the phone and agree to the EULA on "first run"? What about second hand markets? What if I was smart / tooled up enough to replace the Iphone flash storage with my own OS (without running "first run")? At what "technical level" would what your saying make any sense? Because it seems far more like a "contractual condition of purchase" (I appear to have made that term up) issue vs a "technical" issue to me.
- userbinator 4y agoIndeed, the fact that it even has to do so is the important bit, and reflects the attitude of such companies (and to a certain extent, the government) today.
- VogonPoetry 4y agoBooting Apple Silicon has strong cryptographic protections for all of the boot components. An alternate view on the EULA is that it is a legal statement that nobody can get into trouble with any DCMA stupidity if they want to boot their own OS. Contrast this with the Playstation 2 debacle, where you were only allowed to boot Sony's Official Linux. Which they then attempted to disable / withdraw when it was used to attack other parts of the Playstation copy protection system. Apple has also provided a way for ARM Linux VMs to use Rosetta2 for Intel binaries. So they are clearly aware of the wants, needs and usefulness of running other OSs. The cynical might say this was only done to support some internal project that uses Docker, but why put in the effort to make it available to everyone? The current situation does not preclude providing assistance in the future - Apple still hasn't finished replacing all of the Intel products.
- amelius 4y agoYeah but they don't provide the documentation to reliably run said OS, so good luck with that.
- Teknoman117 4y agoThere is a huge difference between not physically locking people out of running custom software and legitimately being able to claim you support other operating systems. Requiring that a community exist that is willing to spend many years of collective time reverse engineering your products when you could have just released documentation is still a massive middle finger to everyone. The problem with these 100% vertically integrated stacks is that every hardware release could be completely different and it'll take years to catch up with just that release. In the intervening time more hardware generations were released - It's been 18 months since the M1 release. Asahi doesn't have 3D acceleration, video encode/decode acceleration, or support for many of the things that make Apple Silicon any good (i.e. the fixed function / low power consumption hardware for the majority of user tasks). At this rate it's going to be years before it's "done" and we already have a successor generation of hardware. I'll leave you with a quote from the Asahi docs > Development for an undocumented platform is a treadmill of work. Every new feature requires reverse engineering the relevant hardware, writing drivers, testing those drivers, then getting them upstreamed. Even after a driver is upstreamed, maintenance and optimisation is sometimes required, for example if Apple introduce a breaking change to any firmware we are required to interface with. For developers the work is never really done It's the same reason we don't have third-party images for most Android phones that are anything beyond tweaks of existing Android images.
- iseanstevens 4y agoIt’s been 18 months on an entirely new platform and a small team of (BRILLIANT) people did such a good job discovering and porting to undocumented hardware that it worked on the M2 hardware essentially before it started shipping. I don’t think Apple is trying to get in their way. Also… developing for documented hardware is also an endless treadmill of work as it evolves/new products are released. It just has much less uncertainty. I 100% agree it would be awesome if Apple released full documentation. Broadcom too. Probably others. (All IMHO)
- Teknoman117 4y ago> small team of (BRILLIANT) people I wasn't trying to take anything away from them at all. It's astounding what they're accomplishing but the fact that it's necessary for this situation to exist at all is what I'm mainly commenting about.
- dang 4y agoDiscussed (a bit) here: AsahiLinux's Introduction to Apple Silicon - https://news.ycombinator.com/item?id=30699794 https://news.ycombinator.com/item?id=30699794 - March 2022 (5 comments) Edit: I think it makes sense for us to change the URL from https://github.com/AsahiLinux/docs/wiki/Apple-Silicon-Subsystems https://github.com/AsahiLinux/docs/wiki/Apple-Silicon-Subsys... to this. Lists of other pages tend not to make good HN submissions—as HN itself is already a list of pages, it's too much indirection. It's better to submit the most interesting element of the list. If there's a more interesting page than the overview one, we can change the above URL again.
- flyinghamster 4y agoI'm a lot less worried about Apple closing off alternate operating systems than I am about not being able to replace the SSD when it inevitably dies. I'd dearly love a Mac Studio, but not if it's guaranteed to become an expensive paperweight for lack of serviceability. I routinely keep computers 10+ years, and unless Apple's SSD can last that long without babying it to a ridiculous degree, it's a non-starter. As someone who grew up with an Apple II+, this "no user serviceable parts inside" mentality has infuriated me about Apple since 1984, so this is nothing new. I've long wanted to love Apple products, but that footgun just has to come out. But I'll give Apple a great deal of credit that they have (even if unofficially) helped rather than hindered the Asahi project. Make a Mac that uses off-the-shelf SSDs at the very least (RAM is a second rant), and I'd be in "shut up and take my money" mode.
- OleksiiA 4y agoSome kind of workaround for this might be an external bootable SSD, with 40 Gbp/s theoretical bandwidth there should be no limitation from that side at least. Just create a bootable SSD before this machine's SSD dies
- philistine 4y agoArm Macs require the internal hard drive to boot. It loads its booting sequence from the drive, even if it is set to default to an external drive for its OS.
- pram 4y agoThe Studio actually has removable NAND cards though, like the Mac Pro.
- flyinghamster 4y agoThat's good to hear, at least, and it made me look deeper. It's not your standard SSD, but it is replaceable, with caveats. In particular, don't expect your SSD to boot in someone else's Mac unless you wipe it. Still, this a much more palatable proposition than soldered-in storage. Just be sure you get the RAM you need, because there's no upgrading it. https://arstechnica.com/gadgets/2022/03/explaining-the-mac-studios-removable-ssds-and-why-you-cant-just-swap-them-out/ https://arstechnica.com/gadgets/2022/03/explaining-the-mac-s...
- bitwize 4y agoApple is playing coy. Their stance is probably something like "Macs are designed to run macOS... but yeah, this is our general purpose computer line and we can't afford the PR hit we'd get by locking them down. Yet."
- macintux 4y agoWere that their attitude they’d be doing less to make it possible today.
- eyelidlessness 4y agoThis is bonkers paranoid. Don’t ask me, reference the article linked above by one of the most prominent Linux distros on aarch64 Macs. The author is clearly qualified when clearly stating that the stance is not this nefarious.
- musictubes 4y agoYou can't have a good development machine that is locked down. As long as Apple wants people to write software they will have to have at least one open platform.
- School-Cotton 4y agoThat’s just not true. Tons of people use a Mac as a software development machine and virtually zero of them install a non-macOS operating system. All it has to do is run Docker and people will continue developing Linux software on it. That said I don’t think Apple is planning on locking down macs, simply because they have never done so (at least not in the modern era), whereas they have always done so with i-devices. Sure there’s always a chance they could change one practice or the other but there’s no good reason to believe they will.
- philistine 4y agoNot only a PR hit. We now have legislation that will force Apple to open up their iPhone. Your cynical take that Apple is waiting to do it is a mistake; they’re losing control of the iPhone as we speak because they locked it down too much.
- novok 4y agoThis is pretty impressive and a great improvement over the current x86 status quo as far as freedom and security goes. All that is left is a way to stop the phone home when you need to do a DFU restore if you set up the 'restore server' first as an owner when you first set up the device. I think corporations and other large organizations would find that end to end assurance useful. Also would be part of removing the dependence from apple to do activation locks and MDM for corps and nerds who want full ownership over their devices. Or some sort of offline DFU restore mode for people who need the ability to do airgapped / isolated updates and wipes. But I also see how that can be leveraged in bad ways by some governments and thieves, so looking at the system balance they chose where a very small lynchpin moment requires phone home is and understandable compromise, even though I don't agree with it fully.. I wonder if the phone home could be done behind VPNs and such, or does it block that?
- webmobdev 4y agoWe should all be grateful for the time and passion the Asahi Linux (AL) team of hackers have invested in documenting (ugh, the most boring job!) and reverse-engineering the Apple Silicon Macs to port Linux to it. If you do plan to buy an Apple Silcon Mac M1 / M2 though, I'd suggest you rather hold off that and instead donate some money to the Asahi Linux team here - https://asahilinux.org/support/ https://asahilinux.org/support/ instead. Despite the progress made by the AL team, the simple fact remains that these Apple Mac M1/M2 platforms can only run crippled versions of other OS, and macOS still remains the only usable OS on it. More donations to the AL team can fix this faster, and not buying these Macs will also put pressure on Apple to further delay locking down these systems more and / or (one can dream!) even force them to release more hardware literature to provide bare minimum support for alternate OS development. Donating even a small sum to AL would be money well spent compared to giving your money to a trillion dollar company that isn't bothered to support system developers. Note that the opaque and closed nature of the Apple Silicon platform (unlike AMD / Intel or other ARM CPUs that support a plethora of OSes and allow their development) hugely constrain our consumer rights, right to repair and computing freedom. > Definitely worth referencing next time someone on HN or elsewhere claims Apple's trying to lock down their computers to running macOS only. I do say this often here vocally that with Apple Silicon Apple does plan to lock down the Mac platform in the future. The key point though is that it will happen only once the Apple Silicon Mac platforms reach a critical level of adoption. Technically, it is trivial now for them to lock the bootloader and completely lock down every mac with a firmware update. But commercially it is not yet a viable move for them as the backlash to such a move would generate a lot of bad PR that would hurt the sale and adoption of the ARM Macs. Apple learnt that lesson when they introduced the Mac Minis with soldered RAM and SSDs - it was the worse selling Mac Mini model, and they were forced to step back, slowdown and reintroduce another model with removable RAMs. The pattern of how Apple has been increasingly locking down the Mac platform is evident: 1. The first few Intel Mac Minis allowed you some level of customisation of both the hardware (change RAM or HDD / SSD) and software (install other full featured OS). 2. Then came the Mac Minis with soldered RAM and SSD. You could no longer customise the hardware. Software was still customisable and you could still install other OSes. (Recall that Apple even offered free drivers for another OS, i.e. Windows). 3. The current generation of M1 Mini now doesn't allow you to customise both the hardware (everything is soldered) and the software. Technically you can install other OSes, but the reality is that currently only crippled versions of Linux and xBSD is available and practically the only full-featured OS that can run on it is still macOS. With the Apple Silicon ARM chips in the Mac, Apple is now only ONE step away from locking the bootloaders of Apple Silicon Macs any time to make it a completely closed platform like the iPhones / iPads. It has been evident that Apple has been planning this for years. It's the old - https://en.wikipedia.org/wiki/Boiling_frog https://en.wikipedia.org/wiki/Boiling_frog - trick to lull its users into not realising how their rights are slowly being encroached, while Apple marketing comes up with new ways to sell you the idea that locking down the system is for your own good. These are very clear indicators of how Apple has been working slowly to lockdown the Mac platform like their ios platforms. The reason for this is simple - BigTech are increasingly moving towards selling everything as a service. Services - https://news.ycombinator.com/item?id=32269915 https://news.ycombinator.com/item?id=32269915 - are more profitable because it means they create recurring income (even after the device is sold) which means more profits. And Apple's successful business model for this, that earns them billions of dollars, is the closed-platform modelof the iPhones / iPads (which ofcourse, are also powered by the same Apple Silicon but with locked bootloaders). Such closed system also help in planned obsolescence that increase sale.
- GeekyBear 4y ago> Definitely worth referencing next time someone on HN or elsewhere claims Apple's trying to lock down their computers to running macOS only. The Asahai Linux lead Has addressed this directly today. >Okay, it's been over a year, and it's time to end the nonsense speculation. I have heard from several Apple employees that: 1. The boot method we use is for 3rd-party OSes, and Apple only use it to test that it works, because 2. It is policy that it works. Apple didn't "leave the door open" for 3rd party OSes. Apple explicitly engineered 3rd party OS support in, and it is a hard policy requirement that it continue to work. Publicly documented feature; Openly improved over time; Multiple employees confirm it's for us, not for Apple; Multiple employees confirm it's staying by policy. https://twitter.com/marcan42/status/1554395176025849856 https://twitter.com/marcan42/status/1554395176025849856
- marcodiego 4y agoHow does it compare in terms of "philosophical freedom" compared to intel IME? Does it need many binary blobs?
- Jtsummers 4y ago> This puts them somewhere between x86 PCs and a libre-first system like the Talos II in terms of freedom to replace firmware and boot components; while a number of blobs are required in order to boot the system, none of those have the ability to take over the OS or compromise it post-boot (unlike, say, Intel ME and AMD PSP on recent systems, or the DMA-capable chips on the LPC bus running opaque blobs that exist on even old ThinkPads). https://github.com/AsahiLinux/docs/wiki/Introduction-to-Apple-Silicon#Firmware-Overview https://github.com/AsahiLinux/docs/wiki/Introduction-to-Appl... - list of firmware blobs
- als0 4y agoCompared to the iME, not much, since at least the secure enclave subsystem won't run any non-Apple code. The scary difference about the iME is that it is directly connected to the network.
- vetinari 4y agoIntel ME is not connected to the network. Intel AMT (vPro) is. You have to pay extra to get it, and there are extra conditions to be fulfilled (LAN or Wifi must be Intel). The difference wrt. Apple Silicon is, that AS firmware blobs run on separate chips and 1) cannot access the main memory freely; they are gated behind IOMMU and 2) there's no SMM equivalent for any of them, so the main CPU time cannot be stolen by firmware.
- dapids 4y ago100% this
- duskwuff 4y agoEh, I'd say the differences go deeper than that. Secure Enclave doesn't appear to have any special access to other resources on the system (like memory), it's initialized by the operating system, not by pre-boot firmware, and the rest of the system works perfectly fine if you leave the SEP uninitialized.
- iasay 4y agoI wonder if anyone at Apple is working on this secretly.
- tasty_freeze 4y agoI sure hope not, as it would compromise all the legitimate reverse engineering being done on it.
- uoaei 4y ago"Compromise"? "Legitimate"?
- soneil 4y ago"clean room" reverse engineering really benefits from the room being clean. I'm not sure how much this applies to Asahi's efforts, but if you're working on reactos or wine, having been exposed to microsoft's source makes you tainted. So to bulk out the grandparent's claim - I'd really like if there was an internal effort that was sanctioned on a "keep our name out of it" grounds.
- uoaei 4y agoBut why would that be a concern? Why isn't Apple's involvement welcomed for the expertise, rather than maligned for some arbitrary notion of "cleanliness" in the process?
- MBCook 4y agoIf Apple was open about it and willing to license stuff as necessary, it would be fine. But they’re not. We know that because they aren’t doing it. So if an Apple employee were to contribute anything it would be some sort of license violation and taint the kernel’s licensing and the (legal) safety of the project. To the degree Apple is involved in this, it can’t be more than “benevolent neglect” of allowing this to happen and setting things up in such a way that it’s possible in the first place. They are never going to answer questions or give any source code.
- Daishiman 4y agoComing in as an Apple skeptic, I’m fairly impressed in the balance Apple has done between user security and device openness. This definitely sounds like a well designed architecture.
- gzer0 4y agoHow does one even begin to start learning about this subject? This is quite fascinating, I've always wanted to learn about OSes, the underlying mechanisms... all of that. The sheer depth of knowledge and technical-know how is truly incredible. I find it hard to even begin, there's so many resources out there.
- Cyberdog 4y agoSome college CS departments have courses in OS development. If that's not an option, I'd start with a textbook like Operating Systems: Design & Implementation, aka the Minix book, since it documents the development of the Minix operating system. https://wiki.minix3.org/doku.php?id=www:documentation:start https://wiki.minix3.org/doku.php?id=www:documentation:start
- saagarjha 4y agoGenerally you’d look to learn about OS design and reverse engineering.
- dento 4y agoFor a hands-on introduction, writing a minimal kernel in Rust, see https://os.phil-opp.com/ https://os.phil-opp.com/
- matheusmoreira 4y agoThe OSDev wiki is nice. https://wiki.osdev.org/ https://wiki.osdev.org/
- AceJohnny2 4y agoWhat is the source for the "Design Goals for AS Macs"? Has Apple or their engineers advertised these? Certainly the "Open to other OSes" goal seems to contradict much of their trend from the past few years. (and the very same page later goes on to say "...as long as they behave like macOS")
- neon_electro 4y ago"Apple's approach to third-party OSes is essentially "have fun". We do not have any expectations of direct support, documentation, or additional development effort from them, nor do we expect them to attempt to hinder third-party OSes in any deliberate way. They have explicitly developed the ability to securely run third-party OSes and bootloaders on these machines, and left the rest to us." Under the list at https://github.com/AsahiLinux/docs/wiki/Introduction-to-Apple-Silicon#design-goals https://github.com/AsahiLinux/docs/wiki/Introduction-to-Appl...
- AceJohnny2 4y agoThat still sounds like an assumption from the community. Perhaps the "third party OSes and bootloaders" is just a side-effect of Apple's own development requirements. On the other hand: "Apple gives users explicit permission to run their own OS in their EULA." I guess I haven't read their EULA!
- smoldesu 4y agoIt's definitely a bit of a reach. Apple has always given users explicit permission to run their own OS, as far as I understand it. Bootcamp has existed for years, and before that there was nothing stopping you from putting Linux on a Macbook (besides the loathesome touch bar). The closest Apple has come to acknowledging third-party OSes on Apple Silicon was their statement that Microsoft is welcome to try porting Windows to it, if they want. I think Asahi sideliners (and Apple fans at large) are quick to attribute mysterious coincidences as benevolence, but I reckon they're making the same mistake that happened when they trusted Microsoft as bedfellows with the open source community. Apple is not your friend, they just make more money if it seems that way.
- GeekyBear 4y agoThe other Apple Silicon tidbit today from Linus Torvalds in his Linux 5.19 release notes: >On a personal note, the most interesting part here is that I did the release (and am writing this) on an arm64 laptop. It's something I've been waiting for for a _loong_ time, and it's finally reality, thanks to the Asahi team. We've had arm64 hardware around running Linux for a long time, but none of it has really been usable as a development platform until now. Not that I've used it for any real work, I literally have only been doing test builds and boots and now the actual release tagging. But I'm trying to make sure that the next time I travel, I can travel with this as a laptop and finally dogfooding the arm64 side too. https://lore.kernel.org/lkml/CAHk-=wgrz5BBk=rCz7W28Fj_o02s0Xi0OEQ3H1uQgOdFvHgx0w@mail.gmail.com/T/#u https://lore.kernel.org/lkml/CAHk-=wgrz5BBk=rCz7W28Fj_o02s0X...
- deleted 4y ago[deleted]
- jshzglr 4y agoWhy is everyone so incredibly cynical. Is it possible Apple did this because they thought it made "business sense". The same reason they do anything else.
- classified 4y agoYears of observation and experience. What makes business sense to Apple (or anyone) is not always in the user's best interest.
- jshzglr 4y agoAccording to who? You don’t have perfect information to know the reasons.
- Sakos 4y agoA lot of things make business sense that aren't good for users/customers or people in general. It making good business sense isn't sufficient reason to judge it as good or justified.
- bitL 4y agoIs there any value in Asahi Linux given GPU won't be likely supported for the next 10+ years (based on how long it took for regular Linux to get decent Nvidia and Radeon open source drivers and those didn't rely on any crypto chips)? It seems like a nice toy project without much value.
- _8j50 4y agoYou can still boot the os and browse the internet right? Seems viable as a dev laptop.