|
An SError while the loader runs means the machine is already
broken, handing the kernel a cpu that lost is worse than
stopping. The handler reports the syndrome then drives the
same reset domain PSCI SYSTEM_RESET does, with a park as the
fallback when the reset request is ignored.
Secondaries leave the pen in the manual's boot state now,
interrupts masked, and CNTVOFF_EL2 zeroed at EL2 so every PE
reads the same virtual counter. A loader cannot repair a per
cpu counter offset below EL2, and the kernel has no way to
repair it at all, whatever ran before could have left one.
The gic group registers are deliberately untouched. The
writes looked like firmware duty, but the group routing is
the secure world's: a non-secure loader's IGROUPR writes are
dropped on hardware implementing the security extension, and
on the emulator here they accept the write and the timer per
cpu interrupts stop reaching the kernel, the tick dies and
the boot hangs past the console handoff. Group config belongs
to the EL3 monitor, this loader runs without one, the comment
says so at the register level.
receipt: gic 8000000 off, smp brought up 1 node 4 cpus, run
/init, busybox shell, two consecutive boots, the pen scrub
exercised in the qemu spin table path.
|
|
The interrupt controller state the kernel inherits is the
bootloader's to define. On real hardware the secure world
owns which interrupts the non-secure kernel will ever see,
and a distributor left with random enables or secure group
bits can fire before the kernel's irqchip driver is up. The
gic goes into the defined state here, distributor off, every
line in the non-secure group, per interrupt enables, pending
and active cleared, cpu interface off. The kernel programs
everything it runs with itself, it starts from zero instead
of from whatever the last stage left.
The controller is found in the devicetree, no hardcoded
address. The new walker locates a node by name at any depth
and decodes the first reg pair with the root cell counts,
the same parse the kernel does. The node's own begin token
starts the walk at depth zero, starting at one skips every
prop in the node, the first version matched nothing.
receipt: gic 8000000 off, root irq handler gic_handle_irq,
smp brought up 1 node 4 cpus, run /init, busybox shell, the
uart console driven by irq 14 through the gic the kernel
reprogrammed over our off state.
|