From 4256361421a2d857e8a1d5cdef45bdbcfef477ad Mon Sep 17 00:00:00 2001 From: Bradley Morgan Date: Sun, 4 Oct 2026 05:59:26 +0000 Subject: tashaboot: el3 secure monitor The resident firmware layer real machines ship, the thing the gic group lesson pointed at. The reset path configures EL3, SP_EL3 on its own region, the monitor vectors in VBAR_EL3, then hands the next stage non-secure EL2 in the manual's boot state and never comes back except through exceptions. Secondaries that enter at EL3 get the monitor before they park, a firmware call on any PE must land in a handler, and SCR_EL3.NS is set to match the primary so a released PE does not come up secure while the kernel runs non-secure. The SMC conduit traps into the lower EL AArch64 sync slot and dispatches through the same PSCI C code the hvc path uses, SMCCC register convention kept whole across the trap. On the emulator here the machine's own firmware shadow stands in front of the conduit, its PSCI answers before the monitor sees the call, and its secure memory map traps the kernel's flash probe after init starts. The monitor mechanics, the entry, the vectors, the stack, the eret, the SMC layout, are live on every secure boot, the call dispatch itself is the hardware receipt. receipt: secure boot through the monitor to four cpus and the init exec, plain boot unchanged to the busybox shell. --- Makefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'Makefile') diff --git a/Makefile b/Makefile index 6112249..eff00a7 100644 --- a/Makefile +++ b/Makefile @@ -18,7 +18,7 @@ CFLAGS := -nostdlib -ffreestanding -mgeneral-regs-only \ LDFLAGS := -T arch/arm64/kernel/tashaboot.lds -OBJS := arch/arm64/kernel/start.o \ +OBJS := arch/arm64/kernel/start.o arch/arm64/kernel/monitor.o \ arch/arm64/kernel/exceptions.o \ arch/arm64/kernel/halt.o \ arch/arm64/kernel/boot.o \ -- cgit v1.2.3