summaryrefslogtreecommitdiff
path: root/arch/arm64/kernel/exceptions.c
diff options
context:
space:
mode:
authorBradley Morgan <brads@mainlining.org>2026-10-03 20:02:29 +0000
committerBradley Morgan <brads@mainlining.org>2026-10-03 21:37:00 +0000
commit9dbdb15abf8ffb9dbdd972d6bbbcea9a3591e2a3 (patch)
tree0fc03f69c4ca60b3306afc7d3a7c86c1fee8437b /arch/arm64/kernel/exceptions.c
tashaboot: arm64 bootloader
A small arm64 bootloader. No board code, no device tree porting, the architecture manual is the whole story: exception vectors in the fixed 16 slot layout (Table D1-7), ESR_ELx decoded by exception class (D1-2172), EL entry and eret chains per the programmers model (D1-2146), cache maintenance by set/way over the CLIDR_EL1 levels, semihosting for console and file io per DUI 0203, and the A64 boot protocol from Documentation/arch/arm64/booting.rst. The loader boots a stock mainline Image end to end on the qemu virt machine. Boot receipt with 7.3-rc3 (42MB Image): tashaboot 0.1 loaded 43450368 bytes at 40200000, entry 40200000 jumping [ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x411fd070] [ 0.000000] Linux version 7.3.0-rc3 [ 0.000000] Machine model: linux,dummy-virt [ 0.000000] earlycon: pl11 MMIO32:0x0000000009000000 ... ---[ end Kernel panic - not syncing: VFS: Unable to mount root fs ]--- The panic is the expected end state, no root filesystem is handed over yet. The boot chain, state per stage, start to payload: +-----------+-----+--------------+----------------------------------+ | stage | EL | state | work | +-----------+-----+--------------+----------------------------------+ | firmware | any | MMU maybe on | x0 = dtb, jump in | +-----------+-----+--------------+----------------------------------+ | tashaboot | 3-2 | | SCR_EL3.NS = 1, eret to EL2 | +-----------+-----+--------------+----------------------------------+ | | 2 | virt scrub | HCR/CNTHCTL/CPTR/HSTR, CNTFRQ, | | | | | VBAR_EL2, MMU off, tlbi alle2 | +-----------+-----+--------------+----------------------------------+ | | 2 | | load Image over semihosting, | | | | | validate header, place per | | | | | booting.rst | +-----------+-----+--------------+----------------------------------+ | | 2 | caches clean | flush dcache, inval icache, | | | | | args ride x20/x21, regs last | +-----------+-----+--------------+----------------------------------+ | payload | 2 | fresh start | x0 = dtb, x1-x3 = 0, DAIF | | | | | masked, br to image entry | +-----------+-----+--------------+----------------------------------+ Two handoff bugs the kernel caught, both AAPCS clobbers in the final jump. Cache maintenance was called after the register setup, x0-x18 are caller saved, so tb_flush_dcache_all() wiped the dtb pointer and the kernel spun in setup_machine_fdt() with an invalid device tree blob. The flush helpers also clobbered x1 (u-boot's void call convention left mov x1, x0 in cache.S) which handed the kernel a wild x0. The arguments ride in x20/x21 across the cache calls now, callee saved, and the register setup is the last thing before the branch. What is missing on purpose: no SMP bringup (secondary cores park), no PSCI, no initrd or root filesystem handoff, single serial console. Those come next. Signed-off-by: Bradley Morgan <brads@mainlining.org>
Diffstat (limited to 'arch/arm64/kernel/exceptions.c')
-rw-r--r--arch/arm64/kernel/exceptions.c67
1 files changed, 67 insertions, 0 deletions
diff --git a/arch/arm64/kernel/exceptions.c b/arch/arm64/kernel/exceptions.c
new file mode 100644
index 0000000..7b40690
--- /dev/null
+++ b/arch/arm64/kernel/exceptions.c
@@ -0,0 +1,67 @@
+/* SPDX-License-Identifier: GPL-2.0+ */
+/*
+ * exceptions.c - report an abort through the console before parking,
+ * so a firmware handoff bug says why it died instead of hanging quiet.
+ * ESR/FAR decode follows armv8 DDI 0487, the EC and ISS fields.
+ *
+ * Copyright (C) 2026 Bradley Morgan <brads@mainlining.org>
+ */
+
+#include <stdint.h>
+#include <debug.h>
+
+struct exc_frame {
+ uint64_t esr;
+ uint64_t far;
+ uint64_t lr;
+};
+
+/*
+ * exception class from ESR, bits 31:26. the classes a bootloader can
+ * actually hit with any frequency.
+ */
+static const char *exc_class_str(uint64_t esr)
+{
+ switch (esr >> 26) {
+ case 0x04: return "data abort, lower EL";
+ case 0x05: return "data abort, same EL";
+ case 0x25: return "data abort, same EL";
+ case 0x08: return "stack pointer misaligned";
+ case 0x11: return "instruction abort, same EL";
+ case 0x16: return "SError";
+ case 0x1a: return "unhandled exception";
+ case 0x22: return "pc alignment fault";
+ case 0x24: return "unknown trap";
+ case 0x26: return "same EL exception return";
+ default: return "unknown EC";
+ }
+}
+
+/*
+ * far is only meaningful for the abort and alignment classes, note it
+ * for those and skip it otherwise so the report does not mislead.
+ */
+static int exc_far_valid(uint64_t esr)
+{
+ switch (esr >> 26) {
+ case 0x04:
+ case 0x05:
+ case 0x25:
+ case 0x11:
+ case 0x22:
+ return 1;
+ default:
+ return 0;
+ }
+}
+
+void exc_report(uint64_t esr, uint64_t far, uint64_t lr)
+{
+ dprintf(CRITICAL, "tashaboot: exception %s\n", exc_class_str(esr));
+ dprintf(CRITICAL, "esr %016llx lr %016llx\n",
+ (unsigned long long)esr, (unsigned long long)lr);
+ if (exc_far_valid(esr))
+ dprintf(CRITICAL, "far %016llx\n", (unsigned long long)far);
+
+ /* nothing recovers from an abort here, park after reporting */
+}