blob: 78b57775dadbcba41ffc4e7dfa0beae9814f72aa [file] [log] [blame]
Andrew Scull18834872018-10-12 11:48:09 +01001/*
Andrew Walbran692b3252019-03-07 15:51:31 +00002 * Copyright 2018 The Hafnium Authors.
Andrew Scull18834872018-10-12 11:48:09 +01003 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * https://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Andrew Scull18c78fc2018-08-20 12:57:41 +010017#include "hf/load.h"
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010018
19#include <stdbool.h>
20
Andrew Scull18c78fc2018-08-20 12:57:41 +010021#include "hf/api.h"
Andrew Walbran34ce72e2018-09-13 16:47:44 +010022#include "hf/boot_params.h"
Andrew Scull18c78fc2018-08-20 12:57:41 +010023#include "hf/dlog.h"
Andrew Scull5991ec92018-10-08 14:55:02 +010024#include "hf/layout.h"
Andrew Scull18c78fc2018-08-20 12:57:41 +010025#include "hf/memiter.h"
26#include "hf/mm.h"
Andrew Walbran48699362019-05-20 14:38:00 +010027#include "hf/plat/console.h"
Andrew Scull877ae4b2019-07-02 12:52:33 +010028#include "hf/static_assert.h"
Andrew Scull8d9e1212019-04-05 13:52:55 +010029#include "hf/std.h"
Andrew Scull18c78fc2018-08-20 12:57:41 +010030#include "hf/vm.h"
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010031
Andrew Scull19503262018-09-20 14:48:39 +010032#include "vmapi/hf/call.h"
33
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010034/**
35 * Copies data to an unmapped location by mapping it for write, copying the
36 * data, then unmapping it.
Andrew Sculld9225b32018-11-19 16:12:41 +000037 *
38 * The data is written so that it is available to all cores with the cache
39 * disabled. When switching to the partitions, the caching is initially disabled
40 * so the data must be available without the cache.
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010041 */
Andrew Scull3c0a90a2019-07-01 11:55:53 +010042static bool copy_to_unmapped(struct mm_stage1_locked stage1_locked, paddr_t to,
43 const void *from, size_t size, struct mpool *ppool)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010044{
Andrew Scull80871322018-08-06 12:04:09 +010045 paddr_t to_end = pa_add(to, size);
46 void *ptr;
Andrew Scull265ada92018-07-30 15:19:01 +010047
Andrew Scull3c0a90a2019-07-01 11:55:53 +010048 ptr = mm_identity_map(stage1_locked, to, to_end, MM_MODE_W, ppool);
Andrew Scull80871322018-08-06 12:04:09 +010049 if (!ptr) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010050 return false;
51 }
52
Andrew Sculla1aa2ba2019-04-05 11:49:02 +010053 memcpy_s(ptr, size, from, size);
Andrew Sculld9225b32018-11-19 16:12:41 +000054 arch_mm_write_back_dcache(ptr, size);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010055
Andrew Scull3c0a90a2019-07-01 11:55:53 +010056 mm_unmap(stage1_locked, to, to_end, ppool);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010057
58 return true;
59}
60
61/**
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010062 * Looks for a file in the given cpio archive. The filename is not
63 * null-terminated, so we use a memory iterator to represent it. The file, if
64 * found, is returned in the "it" argument.
65 */
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +010066static bool memiter_find_file(const struct memiter *cpio,
67 const struct memiter *filename,
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010068 struct memiter *it)
69{
70 const char *fname;
71 const void *fcontents;
72 size_t fsize;
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +010073 struct memiter iter = *cpio;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010074
75 while (cpio_next(&iter, &fname, &fcontents, &fsize)) {
76 if (memiter_iseq(filename, fname)) {
77 memiter_init(it, fcontents, fsize);
78 return true;
79 }
80 }
81
82 return false;
83}
84
85/**
86 * Looks for a file in the given cpio archive. The file, if found, is returned
87 * in the "it" argument.
88 */
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +010089static bool find_file(const struct memiter *cpio, const char *name,
90 struct memiter *it)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010091{
92 const char *fname;
93 const void *fcontents;
94 size_t fsize;
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +010095 struct memiter iter = *cpio;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010096
97 while (cpio_next(&iter, &fname, &fcontents, &fsize)) {
98 if (!strcmp(fname, name)) {
99 memiter_init(it, fcontents, fsize);
100 return true;
101 }
102 }
103
104 return false;
105}
106
107/**
108 * Loads the primary VM.
109 */
Andrew Scull3c0a90a2019-07-01 11:55:53 +0100110bool load_primary(struct mm_stage1_locked stage1_locked,
111 const struct memiter *cpio, uintreg_t kernel_arg,
Wedson Almeida Filho22d5eaa2018-12-16 00:38:49 +0000112 struct memiter *initrd, struct mpool *ppool)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100113{
114 struct memiter it;
Andrew Scullf16c0c22018-10-26 18:41:24 +0100115 paddr_t primary_begin = layout_primary_begin();
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100116
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +0100117 if (!find_file(cpio, "vmlinuz", &it)) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100118 dlog("Unable to find vmlinuz\n");
119 return false;
120 }
121
Andrew Scullf16c0c22018-10-26 18:41:24 +0100122 dlog("Copying primary to %p\n", pa_addr(primary_begin));
Andrew Scull3c0a90a2019-07-01 11:55:53 +0100123 if (!copy_to_unmapped(stage1_locked, primary_begin, it.next,
124 it.limit - it.next, ppool)) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100125 dlog("Unable to relocate kernel for primary vm.\n");
126 return false;
127 }
128
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +0100129 if (!find_file(cpio, "initrd.img", initrd)) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100130 dlog("Unable to find initrd.img\n");
131 return false;
132 }
133
134 {
Andrew Scull19503262018-09-20 14:48:39 +0100135 struct vm *vm;
Andrew Walbranb58f8992019-04-15 12:29:31 +0100136 struct vcpu_locked vcpu_locked;
Andrew Scull19503262018-09-20 14:48:39 +0100137
Wedson Almeida Filho22d5eaa2018-12-16 00:38:49 +0000138 if (!vm_init(MAX_CPUS, ppool, &vm)) {
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100139 dlog("Unable to initialise primary vm\n");
140 return false;
141 }
142
Andrew Scull19503262018-09-20 14:48:39 +0100143 if (vm->id != HF_PRIMARY_VM_ID) {
144 dlog("Primary vm was not given correct id\n");
145 return false;
146 }
147
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100148 /* Map the 1TB of memory. */
149 /* TODO: We should do a whitelist rather than a blacklist. */
Andrew Scull78d6fd92018-09-06 15:08:36 +0100150 if (!mm_vm_identity_map(
Andrew Scull19503262018-09-20 14:48:39 +0100151 &vm->ptable, pa_init(0),
Andrew Scull78d6fd92018-09-06 15:08:36 +0100152 pa_init(UINT64_C(1024) * 1024 * 1024 * 1024),
Andrew Scullda241972019-01-05 18:17:48 +0000153 MM_MODE_R | MM_MODE_W | MM_MODE_X, NULL, ppool)) {
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100154 dlog("Unable to initialise memory for primary vm\n");
155 return false;
156 }
157
Andrew Scullda241972019-01-05 18:17:48 +0000158 if (!mm_vm_unmap_hypervisor(&vm->ptable, ppool)) {
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100159 dlog("Unable to unmap hypervisor from primary vm\n");
160 return false;
161 }
162
Andrew Walbrane1310df2019-04-29 17:28:28 +0100163 vcpu_locked = vcpu_lock(vm_get_vcpu(vm, 0));
Andrew Walbranb58f8992019-04-15 12:29:31 +0100164 vcpu_on(vcpu_locked, ipa_from_pa(primary_begin), kernel_arg);
165 vcpu_unlock(&vcpu_locked);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100166 }
167
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100168 return true;
169}
170
171/**
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100172 * Try to find a memory range of the given size within the given ranges, and
173 * remove it from them. Return true on success, or false if no large enough
174 * contiguous range is found.
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100175 */
Hong-Seok Kim09648362019-05-23 15:47:11 +0900176static bool carve_out_mem_range(struct mem_range *mem_ranges,
177 size_t mem_ranges_count, uint64_t size_to_find,
178 paddr_t *found_begin, paddr_t *found_end)
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100179{
180 size_t i;
181
Wedson Almeida Filho81568c42019-01-04 13:33:02 +0000182 /*
183 * TODO(b/116191358): Consider being cleverer about how we pack VMs
184 * together, with a non-greedy algorithm.
185 */
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100186 for (i = 0; i < mem_ranges_count; ++i) {
187 if (size_to_find <=
Andrew Walbran2cb43392019-04-17 12:52:45 +0100188 pa_difference(mem_ranges[i].begin, mem_ranges[i].end)) {
Wedson Almeida Filhob2c159e2018-10-25 13:27:47 +0100189 /*
190 * This range is big enough, take some of it from the
191 * end and reduce its size accordingly.
192 */
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100193 *found_end = mem_ranges[i].end;
194 *found_begin = pa_init(pa_addr(mem_ranges[i].end) -
195 size_to_find);
196 mem_ranges[i].end = *found_begin;
197 return true;
198 }
199 }
200 return false;
201}
202
203/**
204 * Given arrays of memory ranges before and after memory was removed for
205 * secondary VMs, add the difference to the reserved ranges of the given update.
206 * Return true on success, or false if there would be more than MAX_MEM_RANGES
207 * reserved ranges after adding the new ones.
208 * `before` and `after` must be arrays of exactly `mem_ranges_count` elements.
209 */
Hong-Seok Kim09648362019-05-23 15:47:11 +0900210static bool update_reserved_ranges(struct boot_params_update *update,
211 const struct mem_range *before,
212 const struct mem_range *after,
213 size_t mem_ranges_count)
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100214{
215 size_t i;
216
217 for (i = 0; i < mem_ranges_count; ++i) {
218 if (pa_addr(after[i].begin) > pa_addr(before[i].begin)) {
219 if (update->reserved_ranges_count >= MAX_MEM_RANGES) {
220 dlog("Too many reserved ranges after loading "
221 "secondary VMs.\n");
222 return false;
223 }
224 update->reserved_ranges[update->reserved_ranges_count]
225 .begin = before[i].begin;
226 update->reserved_ranges[update->reserved_ranges_count]
227 .end = after[i].begin;
228 update->reserved_ranges_count++;
229 }
230 if (pa_addr(after[i].end) < pa_addr(before[i].end)) {
231 if (update->reserved_ranges_count >= MAX_MEM_RANGES) {
232 dlog("Too many reserved ranges after loading "
233 "secondary VMs.\n");
234 return false;
235 }
236 update->reserved_ranges[update->reserved_ranges_count]
237 .begin = after[i].end;
238 update->reserved_ranges[update->reserved_ranges_count]
239 .end = before[i].end;
240 update->reserved_ranges_count++;
241 }
242 }
243
244 return true;
245}
246
247/**
248 * Loads all secondary VMs into the memory ranges from the given params.
249 * Memory reserved for the VMs is added to the `reserved_ranges` of `update`.
250 */
Andrew Scull3c0a90a2019-07-01 11:55:53 +0100251bool load_secondary(struct mm_stage1_locked stage1_locked,
252 const struct memiter *cpio,
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100253 const struct boot_params *params,
Wedson Almeida Filho22d5eaa2018-12-16 00:38:49 +0000254 struct boot_params_update *update, struct mpool *ppool)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100255{
Andrew Scull19503262018-09-20 14:48:39 +0100256 struct vm *primary;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100257 struct memiter it;
Andrew Scull36e4bae2018-09-27 17:50:56 +0100258 struct memiter name;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100259 uint64_t mem;
260 uint64_t cpu;
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100261 struct mem_range mem_ranges_available[MAX_MEM_RANGES];
262 size_t i;
263
264 static_assert(
265 sizeof(mem_ranges_available) == sizeof(params->mem_ranges),
266 "mem_range arrays must be the same size for memcpy.");
267 static_assert(sizeof(mem_ranges_available) < 500,
268 "This will use too much stack, either make "
269 "MAX_MEM_RANGES smaller or change this.");
Andrew Sculla1aa2ba2019-04-05 11:49:02 +0100270 memcpy_s(mem_ranges_available, sizeof(mem_ranges_available),
271 params->mem_ranges, sizeof(params->mem_ranges));
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100272
Andrew Walbran42347a92019-05-09 13:59:03 +0100273 primary = vm_find(HF_PRIMARY_VM_ID);
Andrew Scull19503262018-09-20 14:48:39 +0100274
Wedson Almeida Filho9ee60e92018-07-23 18:56:56 +0100275 if (!find_file(cpio, "vms.txt", &it)) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100276 dlog("vms.txt is missing\n");
277 return true;
278 }
279
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100280 /* Round the last addresses down to the page size. */
281 for (i = 0; i < params->mem_ranges_count; ++i) {
Alfredo Mazzinghieb1997c2019-02-07 18:00:01 +0000282 mem_ranges_available[i].end = pa_init(align_down(
283 pa_addr(mem_ranges_available[i].end), PAGE_SIZE));
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100284 }
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100285
Andrew Scull19503262018-09-20 14:48:39 +0100286 while (memiter_parse_uint(&it, &mem) && memiter_parse_uint(&it, &cpu) &&
287 memiter_parse_str(&it, &name)) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100288 struct memiter kernel;
Andrew Scull80871322018-08-06 12:04:09 +0100289 paddr_t secondary_mem_begin;
290 paddr_t secondary_mem_end;
291 ipaddr_t secondary_entry;
Andrew Scull36e4bae2018-09-27 17:50:56 +0100292 const char *p;
Andrew Scull19503262018-09-20 14:48:39 +0100293 struct vm *vm;
Andrew Walbran9a43fee2019-04-18 17:42:32 +0100294 struct vcpu *vcpu;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100295
Andrew Scull36e4bae2018-09-27 17:50:56 +0100296 dlog("Loading ");
297 for (p = name.next; p != name.limit; ++p) {
298 dlog("%c", *p);
299 }
300 dlog("\n");
301
302 if (!memiter_find_file(cpio, &name, &kernel)) {
303 dlog("Unable to load kernel\n");
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100304 continue;
305 }
306
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100307 /* Round up to page size. */
308 mem = (mem + PAGE_SIZE - 1) & ~(PAGE_SIZE - 1);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100309
310 if (mem < kernel.limit - kernel.next) {
Andrew Scull36e4bae2018-09-27 17:50:56 +0100311 dlog("Kernel is larger than available memory\n");
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100312 continue;
313 }
314
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100315 if (!carve_out_mem_range(
316 mem_ranges_available, params->mem_ranges_count, mem,
317 &secondary_mem_begin, &secondary_mem_end)) {
Andrew Scull36e4bae2018-09-27 17:50:56 +0100318 dlog("Not enough memory (%u bytes)\n", mem);
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100319 continue;
320 }
Andrew Scull80871322018-08-06 12:04:09 +0100321
Andrew Scull3c0a90a2019-07-01 11:55:53 +0100322 if (!copy_to_unmapped(stage1_locked, secondary_mem_begin,
323 kernel.next, kernel.limit - kernel.next,
324 ppool)) {
Andrew Scull36e4bae2018-09-27 17:50:56 +0100325 dlog("Unable to copy kernel\n");
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100326 continue;
327 }
328
Wedson Almeida Filho22d5eaa2018-12-16 00:38:49 +0000329 if (!vm_init(cpu, ppool, &vm)) {
Andrew Scull36e4bae2018-09-27 17:50:56 +0100330 dlog("Unable to initialise VM\n");
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100331 continue;
332 }
333
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100334 /* Grant the VM access to the memory. */
Andrew Scull19503262018-09-20 14:48:39 +0100335 if (!mm_vm_identity_map(&vm->ptable, secondary_mem_begin,
336 secondary_mem_end,
Andrew Scullda241972019-01-05 18:17:48 +0000337 MM_MODE_R | MM_MODE_W | MM_MODE_X,
Wedson Almeida Filho22d5eaa2018-12-16 00:38:49 +0000338 &secondary_entry, ppool)) {
Andrew Scull36e4bae2018-09-27 17:50:56 +0100339 dlog("Unable to initialise memory\n");
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100340 continue;
341 }
342
343 /* Deny the primary VM access to this memory. */
Andrew Scull19503262018-09-20 14:48:39 +0100344 if (!mm_vm_unmap(&primary->ptable, secondary_mem_begin,
Andrew Scullda241972019-01-05 18:17:48 +0000345 secondary_mem_end, ppool)) {
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100346 dlog("Unable to unmap secondary VM from primary VM\n");
347 return false;
348 }
349
Andrew Scull36e4bae2018-09-27 17:50:56 +0100350 dlog("Loaded with %u vcpus, entry at 0x%x\n", cpu,
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100351 pa_addr(secondary_mem_begin));
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100352
Andrew Walbrane1310df2019-04-29 17:28:28 +0100353 vcpu = vm_get_vcpu(vm, 0);
Andrew Walbran9a43fee2019-04-18 17:42:32 +0100354 vcpu_secondary_reset_and_start(
355 vcpu, secondary_entry,
Andrew Walbran2b87c702019-04-16 18:16:05 +0100356 pa_difference(secondary_mem_begin, secondary_mem_end));
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100357 }
358
Wedson Almeida Filhob2c159e2018-10-25 13:27:47 +0100359 /*
360 * Add newly reserved areas to update params by looking at the
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100361 * difference between the available ranges from the original params and
362 * the updated mem_ranges_available. We assume that the number and order
363 * of available ranges is the same, i.e. we don't remove any ranges
Wedson Almeida Filhob2c159e2018-10-25 13:27:47 +0100364 * above only make them smaller.
365 */
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100366 return update_reserved_ranges(update, params->mem_ranges,
367 mem_ranges_available,
368 params->mem_ranges_count);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100369}