summaryrefslogtreecommitdiff
path: root/include
AgeCommit message (Collapse)Author
10 hourstashaboot: devicetree relocate and grow, real chosen propertiesBradley Morgan
Firmware edits the devicetree it hands the kernel: new properties cannot go into a packed fdt in place, the blob moves to scratch first and the blocks grow there. The insert moves the strings block up by the prop size, opens the prop slot before /chosen's end token, the new name lands at the strings end, and all four header fields track the geometry, totalsize, off_dt_ strings, size_dt_strings and size_dt_struct. The last one bounds the token walk in libfdt and a stale value there reads as BADSTRUCTURE, the kernel parsed no memory node and panicked on page table allocation before the first print. The strings block length comes from the size_dt_strings header field, not totalsize minus off_dt_strings, qemu's tree carries a hole after the strings block and the subtraction drags it along as tree. The initrd start and end land in /chosen as real properties now, the initrd= bootargs shortcut is gone. receipt: smp brought up 1 node 4 cpus, run /init, userspace, busybox shell, the initrd mounted from the chosen cells.
13 hourstashaboot: smp, psci, initrd, timer, cache by vaBradley Morgan
The bootloader now does the whole job of machine firmware it owns: boots 4 cpus, hands over an initrd, answers PSCI, and carries the delay and cache primitives the arch layer needs. SMP: the secondary pen is the Wait For Event mechanism from the manual (B2-144, D1-2255), each secondary watches its spin gate, WFE, the release writes the entry and SEVs, the recheck after each wake covers a release that lands between the load and the sleep. The gates land in the dtb cpu-release-addr slots, rewritten in place by a small walker, no libfdt, structure per the devicetree specification, values only, the properties themselves are fixed at build time like firmware shipping a fixed blob. PSCI 0.2 at EL2 (DEN 0022): the HVC trap arrives at the current EL SP_ELx sync slot (EC 0x16 in ESR_EL2, the vector layout Table D1-7), dispatch on the standard function ids, VERSION, CPU_ON writes the target gate and SEVs, CPU_OFF clears the gate and returns to the pen, SYSTEM_OFF and SYSTEM_RESET drive RMR_EL2.RR. On qemu the cores are held by the machine's own firmware and released through its PSCI (hvc with -kernel, smc with virtualization=on), the handler here is the real hardware path where the bootloader is the conduit. The initrd handoff: loaded at a fixed address clear of the image and dtb, the dtb /chosen carries linux,initrd-start and -end. Delays are the generic timer (D10), CNTFRQ_EL0 frequency, CNTVCT_EL0 count, busy wait, no interrupts. Cache maintenance by virtual address, dc cvac, dc ivac, dc civac, ic ivau with the barrier pairs the manual requires, the by VA form beats set and way when the range is known. Boot receipt, 4 cpus, el2, initrd: tashaboot 0.1 initrd at 46000000 [ 0.000000] Booting Linux on physical CPU 0x0000000000 [ 0.130621] smp: Brought up 1 node, 4 CPUs [ 1.830692] Run /init as init process tashaboot linux userspace reached cores: 4 BusyBox v1.37.0 built-in shell (ash) ~ # Signed-off-by: Bradley Morgan <brads@mainlining.org>
14 hourstashaboot: arm64 bootloaderBradley Morgan
A small arm64 bootloader. No board code, no device tree porting, the architecture manual is the whole story: exception vectors in the fixed 16 slot layout (Table D1-7), ESR_ELx decoded by exception class (D1-2172), EL entry and eret chains per the programmers model (D1-2146), cache maintenance by set/way over the CLIDR_EL1 levels, semihosting for console and file io per DUI 0203, and the A64 boot protocol from Documentation/arch/arm64/booting.rst. The loader boots a stock mainline Image end to end on the qemu virt machine. Boot receipt with 7.3-rc3 (42MB Image): tashaboot 0.1 loaded 43450368 bytes at 40200000, entry 40200000 jumping [ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x411fd070] [ 0.000000] Linux version 7.3.0-rc3 [ 0.000000] Machine model: linux,dummy-virt [ 0.000000] earlycon: pl11 MMIO32:0x0000000009000000 ... ---[ end Kernel panic - not syncing: VFS: Unable to mount root fs ]--- The panic is the expected end state, no root filesystem is handed over yet. The boot chain, state per stage, start to payload: +-----------+-----+--------------+----------------------------------+ | stage | EL | state | work | +-----------+-----+--------------+----------------------------------+ | firmware | any | MMU maybe on | x0 = dtb, jump in | +-----------+-----+--------------+----------------------------------+ | tashaboot | 3-2 | | SCR_EL3.NS = 1, eret to EL2 | +-----------+-----+--------------+----------------------------------+ | | 2 | virt scrub | HCR/CNTHCTL/CPTR/HSTR, CNTFRQ, | | | | | VBAR_EL2, MMU off, tlbi alle2 | +-----------+-----+--------------+----------------------------------+ | | 2 | | load Image over semihosting, | | | | | validate header, place per | | | | | booting.rst | +-----------+-----+--------------+----------------------------------+ | | 2 | caches clean | flush dcache, inval icache, | | | | | args ride x20/x21, regs last | +-----------+-----+--------------+----------------------------------+ | payload | 2 | fresh start | x0 = dtb, x1-x3 = 0, DAIF | | | | | masked, br to image entry | +-----------+-----+--------------+----------------------------------+ Two handoff bugs the kernel caught, both AAPCS clobbers in the final jump. Cache maintenance was called after the register setup, x0-x18 are caller saved, so tb_flush_dcache_all() wiped the dtb pointer and the kernel spun in setup_machine_fdt() with an invalid device tree blob. The flush helpers also clobbered x1 (u-boot's void call convention left mov x1, x0 in cache.S) which handed the kernel a wild x0. The arguments ride in x20/x21 across the cache calls now, callee saved, and the register setup is the last thing before the branch. What is missing on purpose: no SMP bringup (secondary cores park), no PSCI, no initrd or root filesystem handoff, single serial console. Those come next. Signed-off-by: Bradley Morgan <brads@mainlining.org>