diff options
| author | Bradley Morgan <brads@mainlining.org> | 2026-10-04 05:04:50 +0000 |
|---|---|---|
| committer | Bradley Morgan <brads@mainlining.org> | 2026-10-04 05:04:50 +0000 |
| commit | 0567dd7e947d10a237405e4a9d965c57dd6b473e (patch) | |
| tree | 38cda1ba14e6e15730a2f0f32b48bd8d20bb284e /tools | |
| parent | be4565f1fe3de7e16a48688ab8da39c433f0fee3 (diff) | |
tashaboot: serror resets, secondary release scrub, gic group truth
An SError while the loader runs means the machine is already
broken, handing the kernel a cpu that lost is worse than
stopping. The handler reports the syndrome then drives the
same reset domain PSCI SYSTEM_RESET does, with a park as the
fallback when the reset request is ignored.
Secondaries leave the pen in the manual's boot state now,
interrupts masked, and CNTVOFF_EL2 zeroed at EL2 so every PE
reads the same virtual counter. A loader cannot repair a per
cpu counter offset below EL2, and the kernel has no way to
repair it at all, whatever ran before could have left one.
The gic group registers are deliberately untouched. The
writes looked like firmware duty, but the group routing is
the secure world's: a non-secure loader's IGROUPR writes are
dropped on hardware implementing the security extension, and
on the emulator here they accept the write and the timer per
cpu interrupts stop reaching the kernel, the tick dies and
the boot hangs past the console handoff. Group config belongs
to the EL3 monitor, this loader runs without one, the comment
says so at the register level.
receipt: gic 8000000 off, smp brought up 1 node 4 cpus, run
/init, busybox shell, two consecutive boots, the pen scrub
exercised in the qemu spin table path.
Diffstat (limited to 'tools')
0 files changed, 0 insertions, 0 deletions
