summaryrefslogtreecommitdiff
path: root/test/payload.S
blob: d1891a250fa31361f5808036e10371a6ef1ec059 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
/* SPDX-License-Identifier: GPL-2.0+ */
/*
 * payload.S - tiny arm64 image for testing tashaboot. carries the real
 * Image header from Documentation/arch/arm64/booting.rst, prints one
 * line on the virt uart, parks. built with the same conventions the
 * kernel itself uses so the header math in tashaboot is exercised for
 * real, not against a fake.
 *
 * Copyright (C) 2026 Bradley Morgan <brads@mainlining.org>
 */

#include <asm/linkage.h>

/* the header the bootloader validates */
#define ARM64_IMAGE_MAGIC	0x644d5241

.section .text.head
.globl _start
_start:
	/* code0/code1: branch over the header, like the kernel does */
	b	1f
	.long	0

	/* text_offset, 0x80000 like every kernel since forever */
	.quad	0x80000
	/* image_size, filled at build time by scripts/mkpayload.sh */
	.quad	payload_end - _start
	/* flags, bit 3 = anywhere in memory is fine */
	.quad	(1 << 3)
	.quad	0
	.quad	0
	.quad	0
	/* magic "ARM\x64" */
	.long	ARM64_IMAGE_MAGIC
	.long	0
1:
	/* the payload entry: x0 = dtb from the bootloader */
	ldr	x1, =0x09000000		/* pl011 on qemu virt */
	adr	x2, msg
2:	ldrb	w3, [x2], #1
	cbz	w3, 3f
	str	w3, [x1]
	b	2b
3:	/* clean exit through semihosting, proof we got here */
	mov	x0, #0x18		/* SYS_EXIT */
	ldr	x1, =0x20026		/* ADP_Stopped_ApplicationExit */
	hlt	#0xF000
	b	3b

msg:	.asciz "payload: alive, tashaboot jumped here\n"
	.balign 8
payload_end: