summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--Makefile4
-rw-r--r--arch/arm64/kernel/start.S27
-rw-r--r--arch/arm64/lib/gic.c105
-rw-r--r--common/dtb_find.c178
-rw-r--r--common/main.c26
5 files changed, 338 insertions, 2 deletions
diff --git a/Makefile b/Makefile
index 78cad75..6112249 100644
--- a/Makefile
+++ b/Makefile
@@ -23,7 +23,7 @@ OBJS := arch/arm64/kernel/start.o \
arch/arm64/kernel/halt.o \
arch/arm64/kernel/boot.o \
arch/arm64/lib/cache.o \
- arch/arm64/lib/semihosting.o \
+ arch/arm64/lib/semihosting.o arch/arm64/lib/gic.o \
arch/arm64/lib/mmu.o \
arch/arm64/lib/psci.o \
arch/arm64/lib/system.o \
@@ -31,7 +31,7 @@ OBJS := arch/arm64/kernel/start.o \
arch/arm64/lib/timer.o \
common/main.o common/console.o common/image.o common/load.o \
common/mmutest.o common/dtb_patch.o common/dtb_reloc.o \
- common/dtb_grow.o \
+ common/dtb_grow.o common/dtb_find.o \
lib/printf.o lib/itoa.o lib/semihosting.o \
$(patsubst %.c,%.o,$(wildcard lib/string/*.c))
diff --git a/arch/arm64/kernel/start.S b/arch/arm64/kernel/start.S
index 6ee9941..3cf58d2 100644
--- a/arch/arm64/kernel/start.S
+++ b/arch/arm64/kernel/start.S
@@ -222,6 +222,24 @@ park:
wfe
b 1b
2:
+ /* interrupts masked at release, the manual's boot state */
+ msr daifset, #0xf
+ /*
+ * every PE must read the same virtual counter. whatever
+ * ran before this loader could have left a per cpu offset
+ * in the virtual counter view, the kernel has no way to
+ * repair that itself. CNTVOFF_EL2 is writable at EL2 and
+ * the write holds for the EL1 virtual timer the kernel
+ * runs on. below EL2 it is out of reach, the reset value
+ * is the best a lower EL can do.
+ */
+ mrs x4, CurrentEL
+ lsr x4, x4, #2
+ cmp x4, #2
+ b.lt 3f
+ msr cntvoff_el2, xzr
+ isb
+3:
mov x0, xzr /* secondaries enter with x0-x3 zero */
mov x1, xzr
mov x2, xzr
@@ -396,6 +414,15 @@ exc_serr:
mov x1, #0
mov x2, lr
bl exc_report
+ /*
+ * an SError while this loader runs means the machine is
+ * broken. handing the kernel a cpu that already lost is
+ * worse than stopping: report, then drive the reset domain
+ * the same way PSCI SYSTEM_RESET does. the reset call does
+ * not return, the park below is the fallback if a reset
+ * domain ignores the request.
+ */
+ bl tb_system_reset
ldp x29, x30, [sp], #16
b park
diff --git a/arch/arm64/lib/gic.c b/arch/arm64/lib/gic.c
new file mode 100644
index 0000000..647e987
--- /dev/null
+++ b/arch/arm64/lib/gic.c
@@ -0,0 +1,105 @@
+/*
+ * gic.c - the interrupt controller state a bootloader owns. the
+ * kernel programs the gic itself for the running system, but it
+ * trusts the state it inherits: on real hardware the secure
+ * world configures which interrupts are visible to non-secure,
+ * and a bootloader that leaves random enables or secure group
+ * bits set hands the kernel a half-configured distributor that
+ * can fire before the kernel's irqchip driver is up.
+ *
+ * this is the gicv2 sequence from the TRM, the same shape
+ * u-boot leaves the machine in: distributor off, every
+ * interrupt in the non-secure group, all per interrupt enables
+ * cleared, pending state cleared, cpu interfaces off. defined
+ * state, nothing firing, the kernel starts from zero.
+ *
+ * GICv1 shows the same register map minus the security
+ * extension registers, the writes below are harmless there.
+ *
+ * Copyright (C) 2026 Bradley Morgan <brads@mainlining.org>
+ */
+
+#include <string.h>
+#include <stdint.h>
+#include <boot.h>
+#include <reg.h>
+
+/* distributor registers, offsets from the GICD base */
+#define GICD_CTLR 0x000
+#define GICD_TYPER 0x004
+#define GICD_ISENABLER(n) (0x100 + (n) * 4)
+#define GICD_ICENABLER(n) (0x180 + (n) * 4)
+#define GICD_ICPENDR(n) (0x280 + (n) * 4)
+#define GICD_ICACTIVER(n) (0x380 + (n) * 4)
+
+/* cpu interface registers, offsets from the GICC base */
+#define GICC_CTLR 0x000
+#define GICC_PMR 0x004
+
+/* GICD_CTLR bits */
+#define GICD_CTLR_ENABLE_GRP1 (1 << 0)
+#define GICD_CTLR_ENABLE_GRP0 (1 << 1)
+
+/* GICC_CTLR bits */
+#define GICC_CTLR_ENABLE (1 << 0)
+
+#define GICD_TYPER_ITLINES_MASK 0x1f
+
+/*
+ * how many 32-irq lines the distributor carries, TYPER.ITLines
+ * holds count of (irqs / 32) - 1, clamped per the spec because
+ * the field is 5 bits and caps at 1020 irqs.
+ */
+static int gicd_irq_lines(uintptr_t gicd)
+{
+ uint32_t typer = readl(REG32(gicd + GICD_TYPER));
+
+ return ((typer & GICD_TYPER_ITLINES_MASK) + 1);
+}
+
+/*
+ * leave the gic in the defined state the kernel expects. the
+ * addresses come from the devicetree the caller walked, qemu
+ * virt carries a gicv2 at 0x08000000 with the cpu interface at
+ * +0x10000.
+ */
+int tb_gic_init(uintptr_t gicd, uintptr_t gicc)
+{
+ int lines;
+ int n;
+
+ if (!gicd || !gicc)
+ return -1;
+
+ /* the distributor is off while it is reconfigured */
+ writel(0, REG32(gicd + GICD_CTLR));
+ writel(0, REG32(gicc + GICC_CTLR));
+
+ lines = gicd_irq_lines(gicd);
+
+ /*
+ * the group routing is deliberately untouched. the group
+ * registers are the secure world's, a non-secure loader's
+ * writes are dropped on hardware that implements the
+ * security extension, and on emulators that accept them
+ * the timer's per cpu interrupts stop reaching the
+ * kernel. group config belongs to the EL3 monitor, this
+ * loader runs without one.
+ */
+
+ /* no per interrupt enables, nothing pending */
+ for (n = 0; n < lines; n++) {
+ writel(0xffffffff, REG32(gicd + GICD_ICENABLER(n)));
+ writel(0xffffffff, REG32(gicd + GICD_ICPENDR(n)));
+ }
+
+ /*
+ * the cpu interface stays off with the priority mask at
+ * the lowest priority, the kernel raises it when it
+ * brings its own irq handling up. off is the defined
+ * state, the enable is the kernel's decision to make.
+ */
+ writel(0, REG32(gicc + GICC_PMR));
+
+ return 0;
+}
diff --git a/common/dtb_find.c b/common/dtb_find.c
new file mode 100644
index 0000000..29a67f3
--- /dev/null
+++ b/common/dtb_find.c
@@ -0,0 +1,178 @@
+/*
+ * dtb_find.c - locate nodes and read reg by walking the flat
+ * devicetree. the machine tells the firmware where its devices
+ * live, a bootloader that hardcodes the gic address breaks on
+ * the first board with a different map.
+ *
+ * the walk is the standard token scan, FDT_BEGIN_NODE with a
+ * matching name at any depth, then the reg property inside,
+ * the first address/size pair decoded per the parent's cell
+ * counts, which the root carries in #address-cells and
+ * #size-cells.
+ *
+ * Copyright (C) 2026 Bradley Morgan <brads@mainlining.org>
+ */
+
+#include <string.h>
+#include <stdint.h>
+#include <boot.h>
+
+#define FDT_BEGIN_NODE 1
+#define FDT_END_NODE 2
+#define FDT_PROP 3
+#define FDT_NOP 4
+#define FDT_END 9
+
+static uint32_t be32(const void *p)
+{
+ const uint8_t *b = p;
+
+ return ((uint32_t)b[0] << 24) | ((uint32_t)b[1] << 16) |
+ ((uint32_t)b[2] << 8) | (uint32_t)b[3];
+}
+
+static int name_eq(const char *a, const char *b)
+{
+ while (*a && *a != '@') {
+ if (*a != *b)
+ return 0;
+ a++;
+ b++;
+ }
+ return *b == '\0' || *b == '@';
+}
+
+/*
+ * find the first node whose name matches, at any depth. returns
+ * the offset of its FDT_BEGIN_NODE token or 0 when absent.
+ */
+static uint32_t fdt_find_node(uintptr_t dtb, const char *name)
+{
+ uint8_t *basep = (uint8_t *)dtb;
+ uint32_t off_struct = be32(basep + 8);
+ uint32_t totalsize = be32(basep + 4);
+ uint8_t *p = basep + off_struct;
+
+ if (be32(basep) != 0xd00dfeed)
+ return 0;
+
+ while (p < basep + totalsize) {
+ uint32_t token = be32(p);
+
+ if (token == FDT_BEGIN_NODE) {
+ char *n = (char *)(p + 4);
+ size_t nlen = strlen(n) + 1;
+
+ if (name_eq(n, name))
+ return (uint32_t)(p - basep);
+ p += 4 + ((nlen + 3) & ~3);
+ } else if (token == FDT_PROP) {
+ uint32_t plen = be32(p + 4);
+
+ p += 12 + ((plen + 3) & ~3);
+ } else if (token == FDT_END_NODE ||
+ token == FDT_NOP) {
+ p += 4;
+ } else if (token == FDT_END) {
+ break;
+ } else {
+ return 0;
+ }
+ }
+
+ return 0;
+}
+
+/*
+ * read the first reg pair of a node at the given token offset,
+ * honoring the root cell counts. pairs of 2 or 4 cells are the
+ * ones machines carry, anything else fails. the caller reads
+ * more pairs off the returned cursor if it needs them.
+ */
+int tb_dtb_reg0(uintptr_t dtb, uint32_t node_off, uintptr_t *addr,
+ size_t *size)
+{
+ uint8_t *basep = (uint8_t *)dtb;
+ uint32_t off_strings = be32(basep + 12);
+ uint8_t *p = basep + node_off;
+ uint32_t totalsize = be32(basep + 4);
+ uint32_t ac = 2;
+ uint32_t sc = 2;
+ /*
+ * zero, the node's own FDT_BEGIN_NODE below brings it to
+ * one and the props inside sit at depth one. starting at
+ * one instead skips every prop in the node.
+ */
+ int depth_open = 0;
+
+ while (p < basep + totalsize) {
+ uint32_t token = be32(p);
+
+ if (token == FDT_BEGIN_NODE) {
+ char *n = (char *)(p + 4);
+ size_t nlen = strlen(n) + 1;
+
+ depth_open++;
+ p += 4 + ((nlen + 3) & ~3);
+ } else if (token == FDT_END_NODE) {
+ depth_open--;
+ if (!depth_open)
+ return -1;
+ p += 4;
+ } else if (token == FDT_PROP) {
+ uint32_t plen = be32(p + 4);
+ const char *pname =
+ (char *)basep + off_strings + be32(p + 8);
+ uint8_t *val = p + 12;
+
+ if (depth_open == 1 &&
+ strcmp(pname, "#address-cells") == 0)
+ ac = be32(val);
+ if (depth_open == 1 &&
+ strcmp(pname, "#size-cells") == 0)
+ sc = be32(val);
+ if (depth_open == 1 && strcmp(pname, "reg") == 0) {
+ if (plen >= (ac + sc) * 4) {
+ uint64_t a = 0;
+ uint64_t s = 0;
+
+ for (uint32_t i = 0; i < ac; i++)
+ a = (a << 32) |
+ be32(val + i * 4);
+ for (uint32_t i = 0; i < sc; i++)
+ s = (s << 32) |
+ be32(val + (ac + i) * 4);
+ *addr = (uintptr_t)a;
+ if (size)
+ *size = (size_t)s;
+ return 0;
+ }
+ return -1;
+ }
+ p += 12 + ((plen + 3) & ~3);
+ } else if (token == FDT_NOP) {
+ p += 4;
+ } else if (token == FDT_END) {
+ return -1;
+ } else {
+ return -1;
+ }
+ }
+
+ return -1;
+}
+
+/*
+ * the whole lookup in one call: find the node, read its first
+ * reg pair.
+ */
+int tb_dtb_find_reg0(uintptr_t dtb, const char *name, uintptr_t *addr,
+ size_t *size)
+{
+ uint32_t off = fdt_find_node(dtb, name);
+
+ if (!off)
+ return -1;
+
+ return tb_dtb_reg0(dtb, off, addr, size);
+}
diff --git a/common/main.c b/common/main.c
index a8fdf58..a0237af 100644
--- a/common/main.c
+++ b/common/main.c
@@ -57,6 +57,7 @@ extern char __image_copy_end[];
extern void __NO_RETURN tb_boot_linux(uintptr_t ep, uintptr_t fw_arg);
extern uintptr_t tb_dtb_relocate(uintptr_t dtb, void *scratch,
size_t scratch_size, size_t grow);
+extern int tb_gic_init(uintptr_t gicd, uintptr_t gicc);
extern int tb_dtb_add_chosen_prop(uintptr_t dtb, const char *name,
const void *val, size_t len);
static size_t initrd_size;
@@ -165,6 +166,31 @@ void tashaboot_main(uintptr_t fw_arg)
}
fw_arg = newdtb;
+
+ /*
+ * the interrupt controller the machine told us
+ * about, found by name, the reg pair read with the
+ * root cell counts. the gic goes into the defined
+ * off state before the kernel brings its own irq
+ * handling up.
+ */
+ {
+ extern int tb_dtb_find_reg0(uintptr_t dtb,
+ const char *name,
+ uintptr_t *addr,
+ size_t *size);
+ uintptr_t gicd = 0;
+ uintptr_t gicc = 0;
+ size_t sz = 0;
+
+ if (tb_dtb_find_reg0(fw_arg, "intc", &gicd, &sz) == 0 &&
+ sz >= 0x10000) {
+ gicc = gicd + 0x10000;
+ tb_gic_init(gicd, gicc);
+ dprintf(ALWAYS, "gic: %lx off\n",
+ (unsigned long)gicd);
+ }
+ }
}
/*