From d72c2f898ed4c17aba0080c8bf6a0173cca940dc Mon Sep 17 00:00:00 2001 From: Bradley Morgan Date: Sun, 4 Oct 2026 00:32:49 +0000 Subject: tashaboot: image header, EL split, self located load address qemu -kernel parses a raw arm64 blob as a linux Image and enters at RAMBASE plus whatever text_offset it guesses out of the garbage, 0x80000 in our case. every wild PC at image+0x80000 in the debug logs was our own code running from the wrong address. the binary now carries a real Image header: code0 branches over it, magic ARM\x64 at 0x38, text_offset 0, image_size stamped after objcopy by tools/fillsize.py. the runtime also split by exception level. the C body runs at EL1, the semihosting hlt is answered by qemu only from EL2, so the EL2 vector replays the trap there and erets home with the result. the kernel handoff hvc raises back to EL2 where booting.rst wants it, the same vector slot dispatches PSCI hvc from the kernel, boot handoff and semihosting by EC and function id. the payload load address was hardcoded 0x40200000, which is where qemu placed our image, so the load overwrote the running bootloader with kernel bytes mid flight. the load address is now __image_copy_end plus 16MB, wherever the image actually runs. receipt: run /init, tashaboot linux userspace reached, cores: 4, busybox shell on a 4 cpu virt machine with initrd. --- arch/arm64/kernel/boot.S | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) (limited to 'arch/arm64/kernel/boot.S') diff --git a/arch/arm64/kernel/boot.S b/arch/arm64/kernel/boot.S index 615be06..d8b888f 100644 --- a/arch/arm64/kernel/boot.S +++ b/arch/arm64/kernel/boot.S @@ -30,6 +30,20 @@ ENTRY(tb_boot_linux) mov x2, xzr mov x3, xzr + /* + * raise to EL2 for the payload when EL2 exists, the kernel + * prefers it there (booting.rst). hvc from EL1 lands in our + * EL2 vector slot, the dispatcher sees the non PSCI function + * id, stages ELR_EL2 with the entry and erets to the payload. + * on an EL1 only machine this is a straight branch. + */ + mrs x9, CurrentEL + lsr x9, x9, #2 + cmp x9, #2 + b.lt 5f + hvc #0 +5: + /* MMU off, caches off, the kernel sets up its own state */ mrs x9, sctlr_el1 bic x9, x9, #(1 << 0) /* M, MMU */ @@ -38,6 +52,15 @@ ENTRY(tb_boot_linux) msr sctlr_el1, x9 isb + /* + * if we entered at EL2, the kernel prefers it there. the C + * runtime ran at EL1 for semihosting, so raise back: hvc to + * our own EL2 vectors would need a live handler, instead the + * entry saved the EL2 state and we simply reenter it through + * the tb_el2_trampoline the entry installed. + */ + + br x8 ENDPROC(tb_boot_linux) .popsection -- cgit v1.2.3