« All posts

Booting Linux on Apple's M4: SPTM, Locked Registers and WFI Bugs

Deep dive into booting Linux on Apple's M4 chip: SPTM hardening, register debugging, and a WFI erratum that breaks ARM64 spec compliance.

A developer documents the process of getting Linux running on an Apple M4 Mac mini, detailing why this generation is far harder to bring up than M1-M3 machines. The M4 mandates SPTM (Secure Page Table Monitor), which breaks the hypervisor-based MMIO tracing technique Asahi Linux previously relied on to reverse-engineer macOS driver behavior.

The writeup walks through debugging a silent boot failure using raw println-style debugging via a hand-rolled debug_putc routine, eventually tracing the crash to missing MMU identity mappings for MMIO space, a missing stdout-path device tree entry, and a locked implementation-specific register (SYS_IMP_APL_VM_TMR_FIQ_ENA_EL2) that had to be bypassed.

The hardest problem was a WFI instruction erratum: on M4, WFI zeroes CPU registers in a way that violates the ARM64 architecture spec, unlike previous Apple Silicon generations where this behavior could be toggled. The current workaround replaces WFI/WFIT with NOPs, while upstream Linux maintainers, including Will Deacon, are discussing a proper bootarg-based fix. The post is a useful case study in low-level kernel bring-up and reverse engineering on locked-down silicon.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work