IOMMU integration is important too

This commit is contained in:
Daniel Micay 2019-07-18 07:31:06 -04:00
parent 44cf9578ac
commit f5e2d53c9b

View File

@ -124,11 +124,14 @@
potential targets. In addition to support for installing other operating systems, potential targets. In addition to support for installing other operating systems,
standard hardware-based security features like the hardware-backed keystores, verified standard hardware-based security features like the hardware-backed keystores, verified
boot, attestation and various hardware-based exploit mitigations need to be available. boot, attestation and various hardware-based exploit mitigations need to be available.
Devices with support for alternative operating systems as an afterthought will not be Devices also need to have decent integration of IOMMUs for isolating components such
considered. Devices need to have proper ongoing support for their firmware and as the GPU, radios (NFC, Wi-Fi, Bluetooth, Cellular), media decode / encode, image
software specific to the hardware like drivers in order to provide proper full processor, etc. as if the hardware / firmware support is missing or broken, there's
security updates too. Devices that are end-of-life and no longer receiving these not much that the OS can do to provide an alternative. Devices with support for
updates will not be supported.</p> alternative operating systems as an afterthought will not be considered. Devices need
to have proper ongoing support for their firmware and software specific to the
hardware like drivers in order to provide proper full security updates too. Devices
that are end-of-life and no longer receiving these updates will not be supported.</p>
<p>In order to support a device, the appropriate resources also need to be available <p>In order to support a device, the appropriate resources also need to be available
and dedicated towards it. Releases for each supported device need to be robust and and dedicated towards it. Releases for each supported device need to be robust and
stable, with all standard functionality working properly and testing for each of the stable, with all standard functionality working properly and testing for each of the