I've got this packaged from an upstream git commit sufficient to replace atf-allwinner; it even reliably powers off on the pinebook!
https://salsa.debian.org/debian/arm-trusted-firmware It's currently only building the sun50i_a64 target, since that's the one I've tested on pinebook and pine64+, but there are a few more upstream supports that might be possible to enable, if someone could test them. Hoping to upload soon... live well, vagrant
signature.asc
Description: PGP signature