From 0567dd7e947d10a237405e4a9d965c57dd6b473e Mon Sep 17 00:00:00 2001 From: Bradley Morgan Date: Sun, 4 Oct 2026 05:04:50 +0000 Subject: tashaboot: serror resets, secondary release scrub, gic group truth An SError while the loader runs means the machine is already broken, handing the kernel a cpu that lost is worse than stopping. The handler reports the syndrome then drives the same reset domain PSCI SYSTEM_RESET does, with a park as the fallback when the reset request is ignored. Secondaries leave the pen in the manual's boot state now, interrupts masked, and CNTVOFF_EL2 zeroed at EL2 so every PE reads the same virtual counter. A loader cannot repair a per cpu counter offset below EL2, and the kernel has no way to repair it at all, whatever ran before could have left one. The gic group registers are deliberately untouched. The writes looked like firmware duty, but the group routing is the secure world's: a non-secure loader's IGROUPR writes are dropped on hardware implementing the security extension, and on the emulator here they accept the write and the timer per cpu interrupts stop reaching the kernel, the tick dies and the boot hangs past the console handoff. Group config belongs to the EL3 monitor, this loader runs without one, the comment says so at the register level. receipt: gic 8000000 off, smp brought up 1 node 4 cpus, run /init, busybox shell, two consecutive boots, the pen scrub exercised in the qemu spin table path. --- arch/arm64/lib/gic.c | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) (limited to 'arch/arm64/lib') diff --git a/arch/arm64/lib/gic.c b/arch/arm64/lib/gic.c index 11bb9cd..647e987 100644 --- a/arch/arm64/lib/gic.c +++ b/arch/arm64/lib/gic.c @@ -27,7 +27,6 @@ /* distributor registers, offsets from the GICD base */ #define GICD_CTLR 0x000 #define GICD_TYPER 0x004 -#define GICD_IGROUPR(n) (0x080 + (n) * 4) #define GICD_ISENABLER(n) (0x100 + (n) * 4) #define GICD_ICENABLER(n) (0x180 + (n) * 4) #define GICD_ICPENDR(n) (0x280 + (n) * 4) @@ -79,13 +78,14 @@ int tb_gic_init(uintptr_t gicd, uintptr_t gicc) lines = gicd_irq_lines(gicd); /* - * every interrupt in group 1, the non-secure group. the - * kernel does not see group 0 interrupts on non-secure - * hardware, and a bootloader that leaves any line in the - * secure group strands it. + * the group routing is deliberately untouched. the group + * registers are the secure world's, a non-secure loader's + * writes are dropped on hardware that implements the + * security extension, and on emulators that accept them + * the timer's per cpu interrupts stop reaching the + * kernel. group config belongs to the EL3 monitor, this + * loader runs without one. */ - for (n = 0; n < lines; n++) - writel(0xffffffff, REG32(gicd + GICD_IGROUPR(n))); /* no per interrupt enables, nothing pending */ for (n = 0; n < lines; n++) { -- cgit v1.2.3