Contents Menu Expand Light mode Dark mode Auto light/dark, in light mode Auto light/dark, in dark mode Skip to content
Onyx Boox Note Air5 C
Onyx Boox Note Air5 C

Reference

  • 1. XBL
    • 1.2.1. XBL → ABL hand-off contract (bounded)
    • 1.2.2. The EL3 “Sec” monitor and the EL1 hand-off
    • 1.2.3. Embedded UEFI firmware volume
    • 1.2.4. Platform config (uefiplat.cfg)
    • 1.2.5. Companion image — xbl_config
    • 1.2.6. Platform state partitions: cdt, ddr, uefivarstore
    • 1.2.7. Charger-type detection and the unreachable fedl/LED branch
  • 2. ABL
    • 2.1. ABL overview, key handling, fastboot
    • 2.2. ABL entry point and top-level orchestration
    • 2.3. Kernel/DTB/ramdisk load and the kernel hand-off
    • 2.4. AVB enforcement code path (LoadImageAndAuth / libavb)
    • 2.5. Fastboot handler internals (FastbootLib)
    • 2.6. ABL function map and upstream-source correlation
  • 3. Boot
    • 3.1. Boot chain and exception-level hand-off (PBL → XBL → ABL)
    • 3.2. Secure boot and image signing
    • 3.3. Boot image: kernel, DTB, ramdisk, config
    • 3.4. Recovery ramdisk (recovery environment)
    • 3.5. Physical keys: power, volume, and the boot-mode dispatcher
    • 3.6. Below UEFI — execution state and hardware register surface
    • 3.7. Base kernel device tree (the SoC boot contract)
    • 3.8. USB transport — the DWC3 controller behind every off-device path
    • 3.9. QUP/GENI serial-engine bus map (what is wired where)
    • 3.10. DTBO overlays
  • 4. EDL
    • 4.1. EDL / 9008 entry and the deep-flash cable
    • 4.2. EDL / Firehose interface
    • 4.3. Firehose fuse read and secure-boot confirmation
  • 5. Partition map and checksums
  • 6. TrustZone
    • 6.1. Secure world and coprocessors (TZ, HYP, trustlets)
    • 6.2. Crypto engine (QCE) and hardware RNG
  • 7. SoC platform fabric
    • 7.1. Storage controllers — UFS, ICE, and SDCC
    • 7.2. Pin control — TLMM and the PMIC GPIOs
    • 7.3. Clock tree — GCC, domain CCs, RPMh
    • 7.4. Interconnect — NoC / BCM and the LLCC
    • 7.5. GPU — Adreno A619, the GMU, and the zap shader
    • 7.6. Absent and vestigial hardware (reference-base leftovers)
    • 7.7. PMIC reset timers, charging and reachability
    • 7.8. AOP — the Always-On Processor (RPMh / power back-end)
    • 7.9. IPA — the networking datapath accelerator
    • 7.10. Thermal management (tsens, zones, mitigation)
  • 8. Wireless
    • 8.1. Bluetooth / FM controller firmware (WCN3990 “Cherokee”)
    • 8.2. Bluetooth A2DP sink-latency: a two-bug chain in the HAL path (one confirmed, one inferred)
    • 8.3. Wireless drivers and HAL
  • 9. Sensors
    • 9.1.1. Capacitive touch (Parade pt_core)
    • 9.1.2. Misc sensors (fingerprint, hall, keyboard cover)
    • 9.1.3. Sensor drivers and HAL
  • 10. Display
    • 10.1. Display pipeline — DSI transport to the color e-ink TCON
    • 10.2. Splash partition
    • 10.3. The e-ink software stack (Onyx EPDC)
    • 10.4. E-ink driver internals (register-level, from the kernel)
    • 10.5. The /dev/ebc interface: ioctls, update modes, and the waveform format
    • 10.6. Wacom EMR pen digitizer driver
    • 10.7. Display drivers and HAL
  • 11. Audio
    • 11.1. ADSP and CDSP firmware
    • 11.2. Audio drivers and HAL
  • 12. Android userspace (bridge to the firmware)
    • 12.1. Firmware-blob inventory (the payloads)
    • 12.2. Vendor drivers and HALs
    • 12.3. Security and DRM userspace
    • 12.4. The Onyx/Boox platform layer
    • 12.5. Userspace boot — init, SELinux, A/B updates
    • 12.6. Preinstalled apps (Boox, GMS, AOSP)
    • 12.7. APK sweep: bulk decompile of the remaining 123 system/product apps
    • 12.8. OAT containers: what’s actually AOT-compiled to native code, and where
    • 12.9. Vendor diagnostic, factory-test and provisioning tools in bin/xbin
  • 13. Open questions and limits of analysis
  • 14. Mainline Linux port readiness — per-subsystem status
Back to top
View this page

6. TrustZone¶

The secure world: TrustZone (TZ) and the hypervisor (HYP) images, the QSEE trustlets running under them, and the hardware crypto engine (QCE/ICE/HWKM) that backs keymaster/keystore and storage encryption. Split out into its own section because it’s a genuinely distinct execution environment from the non-secure boot chain and SoC fabric documented elsewhere.

  • 6.1. Secure world and coprocessors (TZ, HYP, trustlets)
  • 6.2. Crypto engine (QCE) and hardware RNG
Next
6.1. Secure world and coprocessors (TZ, HYP, trustlets)
Previous
5. Partition map and checksums
Copyright © RE author + contributors. Licensed under CC BY-SA 4.0 — see LICENSE.
Made with Sphinx and @pradyunsg's Furo