blob: 97e4b346c35feb6cb944eb621b473cb07e2e671f [file] [log] [blame]
Andrew Scull18834872018-10-12 11:48:09 +01001/*
Andrew Walbran692b3252019-03-07 15:51:31 +00002 * Copyright 2018 The Hafnium Authors.
Andrew Scull18834872018-10-12 11:48:09 +01003 *
Andrew Walbrane959ec12020-06-17 15:01:09 +01004 * Use of this source code is governed by a BSD-style
5 * license that can be found in the LICENSE file or at
6 * https://opensource.org/licenses/BSD-3-Clause.
Andrew Scull18834872018-10-12 11:48:09 +01007 */
8
Andrew Scull18c78fc2018-08-20 12:57:41 +01009#include "hf/load.h"
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010010
11#include <stdbool.h>
12
Fuad Tabba77a4b012019-11-15 12:13:08 +000013#include "hf/arch/vm.h"
14
Andrew Scull18c78fc2018-08-20 12:57:41 +010015#include "hf/api.h"
Andrew Walbran34ce72e2018-09-13 16:47:44 +010016#include "hf/boot_params.h"
Andrew Scull72b43c02019-09-18 13:53:45 +010017#include "hf/check.h"
Andrew Scull18c78fc2018-08-20 12:57:41 +010018#include "hf/dlog.h"
Fuad Tabba50469e02020-06-30 15:14:28 +010019#include "hf/fdt_patch.h"
Andrew Scull5991ec92018-10-08 14:55:02 +010020#include "hf/layout.h"
Andrew Scull18c78fc2018-08-20 12:57:41 +010021#include "hf/memiter.h"
22#include "hf/mm.h"
Andrew Walbran48699362019-05-20 14:38:00 +010023#include "hf/plat/console.h"
Andrew Scullb1a6d0d2020-01-29 11:25:12 +000024#include "hf/plat/iommu.h"
Andrew Scull877ae4b2019-07-02 12:52:33 +010025#include "hf/static_assert.h"
Andrew Scull8d9e1212019-04-05 13:52:55 +010026#include "hf/std.h"
Andrew Scull18c78fc2018-08-20 12:57:41 +010027#include "hf/vm.h"
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010028
Andrew Scull19503262018-09-20 14:48:39 +010029#include "vmapi/hf/call.h"
Manish Pandeyd34f8892020-06-19 17:41:07 +010030#include "vmapi/hf/ffa.h"
Andrew Scull19503262018-09-20 14:48:39 +010031
Andrew Walbran9daa57e2019-09-27 13:33:20 +010032alignas(PAGE_SIZE) static uint8_t tee_send_buffer[HF_MAILBOX_SIZE];
33alignas(PAGE_SIZE) static uint8_t tee_recv_buffer[HF_MAILBOX_SIZE];
34
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010035/**
36 * Copies data to an unmapped location by mapping it for write, copying the
37 * data, then unmapping it.
Andrew Sculld9225b32018-11-19 16:12:41 +000038 *
39 * The data is written so that it is available to all cores with the cache
40 * disabled. When switching to the partitions, the caching is initially disabled
41 * so the data must be available without the cache.
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010042 */
Andrew Scull3c0a90a2019-07-01 11:55:53 +010043static bool copy_to_unmapped(struct mm_stage1_locked stage1_locked, paddr_t to,
David Brazdil7a462ec2019-08-15 12:27:47 +010044 struct memiter *from_it, struct mpool *ppool)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010045{
David Brazdil7a462ec2019-08-15 12:27:47 +010046 const void *from = memiter_base(from_it);
47 size_t size = memiter_size(from_it);
Andrew Scull80871322018-08-06 12:04:09 +010048 paddr_t to_end = pa_add(to, size);
49 void *ptr;
Andrew Scull265ada92018-07-30 15:19:01 +010050
Andrew Scull3c0a90a2019-07-01 11:55:53 +010051 ptr = mm_identity_map(stage1_locked, to, to_end, MM_MODE_W, ppool);
Andrew Scull80871322018-08-06 12:04:09 +010052 if (!ptr) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010053 return false;
54 }
55
Andrew Sculla1aa2ba2019-04-05 11:49:02 +010056 memcpy_s(ptr, size, from, size);
Andrew Scullc059fbe2019-09-12 12:58:40 +010057 arch_mm_flush_dcache(ptr, size);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010058
Andrew Scull72b43c02019-09-18 13:53:45 +010059 CHECK(mm_unmap(stage1_locked, to, to_end, ppool));
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +010060
61 return true;
62}
63
Fuad Tabba50469e02020-06-30 15:14:28 +010064/**
65 * Loads the secondary VM's kernel.
66 * Stores the kernel size in kernel_size (if kernel_size is not NULL).
67 * Returns false if it cannot load the kernel.
68 */
Andrew Scull72b43c02019-09-18 13:53:45 +010069static bool load_kernel(struct mm_stage1_locked stage1_locked, paddr_t begin,
70 paddr_t end, const struct manifest_vm *manifest_vm,
Fuad Tabba50469e02020-06-30 15:14:28 +010071 const struct memiter *cpio, struct mpool *ppool,
72 size_t *kernel_size)
Andrew Scull72b43c02019-09-18 13:53:45 +010073{
Andrew Scull72b43c02019-09-18 13:53:45 +010074 struct memiter kernel;
Fuad Tabba50469e02020-06-30 15:14:28 +010075 size_t size;
Andrew Scull72b43c02019-09-18 13:53:45 +010076
David Brazdil136f2942019-09-23 14:11:03 +010077 if (!cpio_get_file(cpio, &manifest_vm->kernel_filename, &kernel)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +000078 dlog_error("Could not find kernel file \"%s\".\n",
79 string_data(&manifest_vm->kernel_filename));
Andrew Scull72b43c02019-09-18 13:53:45 +010080 return false;
81 }
82
Fuad Tabba50469e02020-06-30 15:14:28 +010083 size = memiter_size(&kernel);
84 if (pa_difference(begin, end) < size) {
Andrew Walbran17eebf92020-02-05 16:35:49 +000085 dlog_error("Kernel is larger than available memory.\n");
Andrew Scull72b43c02019-09-18 13:53:45 +010086 return false;
87 }
88
89 if (!copy_to_unmapped(stage1_locked, begin, &kernel, ppool)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +000090 dlog_error("Unable to copy kernel.\n");
Andrew Scull72b43c02019-09-18 13:53:45 +010091 return false;
92 }
93
Fuad Tabba50469e02020-06-30 15:14:28 +010094 if (kernel_size) {
95 *kernel_size = size;
96 }
97
Andrew Scull72b43c02019-09-18 13:53:45 +010098 return true;
99}
100
Manish Pandeyd34f8892020-06-19 17:41:07 +0100101/*
102 * Link RX/TX buffers provided in partition manifest to mailbox
103 */
104static bool link_rxtx_to_mailbox(struct mm_stage1_locked stage1_locked,
105 struct vm_locked vm_locked, struct rx_tx rxtx,
106 struct mpool *ppool)
107{
108 struct ffa_value ret;
109 ipaddr_t send;
110 ipaddr_t recv;
111 uint32_t page_count;
112
113 send = ipa_init(rxtx.tx_buffer->base_address);
114 recv = ipa_init(rxtx.rx_buffer->base_address);
115 page_count = rxtx.tx_buffer->page_count;
116
117 ret = api_vm_configure_pages(stage1_locked, vm_locked, send, recv,
118 page_count, ppool);
119 if (ret.func != FFA_SUCCESS_32) {
120 return false;
121 }
122
123 dlog_verbose(" mailbox: send = %#x, recv = %#x\n",
124 vm_locked.vm->mailbox.send, vm_locked.vm->mailbox.recv);
125
126 return true;
127}
128
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100129/**
Andrew Scullae9962e2019-10-03 16:51:16 +0100130 * Performs VM loading activities that are common between the primary and
131 * secondaries.
132 */
Manish Pandeyd34f8892020-06-19 17:41:07 +0100133static bool load_common(struct mm_stage1_locked stage1_locked,
134 struct vm_locked vm_locked,
135 const struct manifest_vm *manifest_vm,
136 struct mpool *ppool)
Andrew Scullae9962e2019-10-03 16:51:16 +0100137{
Manish Pandeyd34f8892020-06-19 17:41:07 +0100138 vm_locked.vm->smc_whitelist = manifest_vm->smc_whitelist;
139 vm_locked.vm->uuid = manifest_vm->sp.uuid;
Andrew Scullae9962e2019-10-03 16:51:16 +0100140
Manish Pandeyd34f8892020-06-19 17:41:07 +0100141 if (manifest_vm->is_ffa_partition) {
142 /* Link rxtx buffers to mailbox */
143 if (manifest_vm->sp.rxtx.available) {
144 if (!link_rxtx_to_mailbox(stage1_locked, vm_locked,
145 manifest_vm->sp.rxtx,
146 ppool)) {
147 dlog_error(
148 "Unable to Link RX/TX buffer with "
149 "mailbox.\n");
150 return false;
151 }
152 }
153 }
Fuad Tabba56970712020-01-10 11:20:09 +0000154 /* Initialize architecture-specific features. */
Manish Pandeyd34f8892020-06-19 17:41:07 +0100155 arch_vm_features_set(vm_locked.vm);
Fuad Tabba77a4b012019-11-15 12:13:08 +0000156
Andrew Scullae9962e2019-10-03 16:51:16 +0100157 return true;
158}
159
160/**
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100161 * Loads the primary VM.
162 */
Andrew Scull72b43c02019-09-18 13:53:45 +0100163static bool load_primary(struct mm_stage1_locked stage1_locked,
Andrew Scullae9962e2019-10-03 16:51:16 +0100164 const struct manifest_vm *manifest_vm,
Andrew Scullb5f49e02019-10-02 13:20:47 +0100165 const struct memiter *cpio,
166 const struct boot_params *params, struct mpool *ppool)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100167{
Olivier Deprez62d99e32020-01-09 15:58:07 +0100168 paddr_t primary_begin;
169 ipaddr_t primary_entry;
David Brazdile6f83222019-09-23 14:47:37 +0100170 struct vm *vm;
Andrew Scull3c257452019-11-26 13:32:50 +0000171 struct vm_locked vm_locked;
David Brazdile6f83222019-09-23 14:47:37 +0100172 struct vcpu_locked vcpu_locked;
Andrew Scullb5f49e02019-10-02 13:20:47 +0100173 size_t i;
Andrew Scull3c257452019-11-26 13:32:50 +0000174 bool ret;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100175
Olivier Deprez62d99e32020-01-09 15:58:07 +0100176 if (manifest_vm->is_ffa_partition) {
177 primary_begin = pa_init(manifest_vm->sp.load_addr);
178 primary_entry = ipa_add(ipa_from_pa(primary_begin),
179 manifest_vm->sp.ep_offset);
180 } else {
181 primary_begin =
182 (manifest_vm->primary.boot_address ==
183 MANIFEST_INVALID_ADDRESS)
184 ? layout_primary_begin()
185 : pa_init(manifest_vm->primary.boot_address);
186 primary_entry = ipa_from_pa(primary_begin);
187 }
188
David Brazdil080ee312020-02-25 15:30:30 -0800189 paddr_t primary_end = pa_add(primary_begin, RSIZE_MAX);
Andrew Scull72b43c02019-09-18 13:53:45 +0100190
Olivier Deprez62d99e32020-01-09 15:58:07 +0100191 /*
192 * Load the kernel if a filename is specified in the VM manifest.
193 * For an FF-A partition, kernel_filename is undefined indicating
194 * the partition package has already been loaded prior to Hafnium
195 * booting.
196 */
197 if (!string_is_empty(&manifest_vm->kernel_filename)) {
198 if (!load_kernel(stage1_locked, primary_begin, primary_end,
Fuad Tabba50469e02020-06-30 15:14:28 +0100199 manifest_vm, cpio, ppool, NULL)) {
Olivier Deprez62d99e32020-01-09 15:58:07 +0100200 dlog_error("Unable to load primary kernel.\n");
201 return false;
202 }
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100203 }
204
Andrew Walbran9daa57e2019-09-27 13:33:20 +0100205 if (!vm_init_next(MAX_CPUS, ppool, &vm)) {
Andrew Walbran7586e042020-02-18 18:19:26 +0000206 dlog_error("Unable to initialise primary VM.\n");
David Brazdile6f83222019-09-23 14:47:37 +0100207 return false;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100208 }
209
David Brazdile6f83222019-09-23 14:47:37 +0100210 if (vm->id != HF_PRIMARY_VM_ID) {
Andrew Walbran7586e042020-02-18 18:19:26 +0000211 dlog_error("Primary VM was not given correct ID.\n");
David Brazdile6f83222019-09-23 14:47:37 +0100212 return false;
213 }
214
Andrew Scull3c257452019-11-26 13:32:50 +0000215 vm_locked = vm_lock(vm);
216
Andrew Scull48929fd2020-01-28 10:39:10 +0000217 if (params->device_mem_ranges_count == 0) {
218 /*
219 * Map 1TB of address space as device memory to, most likely,
220 * make all devices available to the primary VM.
221 *
222 * TODO: remove this once all targets provide valid ranges.
223 */
Andrew Scullf6ab9bc2020-02-26 12:56:37 -0800224 dlog_warning(
225 "Device memory not provided, defaulting to 1 TB.\n");
Andrew Scull48929fd2020-01-28 10:39:10 +0000226
227 if (!vm_identity_map(
228 vm_locked, pa_init(0),
229 pa_init(UINT64_C(1024) * 1024 * 1024 * 1024),
230 MM_MODE_R | MM_MODE_W | MM_MODE_D, ppool, NULL)) {
231 dlog_error(
232 "Unable to initialise address space for "
Andrew Scullf6ab9bc2020-02-26 12:56:37 -0800233 "primary VM.\n");
Andrew Scull48929fd2020-01-28 10:39:10 +0000234 ret = false;
235 goto out;
236 }
David Brazdile6f83222019-09-23 14:47:37 +0100237 }
238
Andrew Scullb5f49e02019-10-02 13:20:47 +0100239 /* Map normal memory as such to permit caching, execution, etc. */
240 for (i = 0; i < params->mem_ranges_count; ++i) {
Andrew Scull3c257452019-11-26 13:32:50 +0000241 if (!vm_identity_map(vm_locked, params->mem_ranges[i].begin,
242 params->mem_ranges[i].end,
243 MM_MODE_R | MM_MODE_W | MM_MODE_X, ppool,
244 NULL)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000245 dlog_error(
Andrew Scullf6ab9bc2020-02-26 12:56:37 -0800246 "Unable to initialise memory for primary "
247 "VM.\n");
Andrew Scull3c257452019-11-26 13:32:50 +0000248 ret = false;
249 goto out;
Andrew Scullb5f49e02019-10-02 13:20:47 +0100250 }
251 }
252
Andrew Scull48929fd2020-01-28 10:39:10 +0000253 /* Map device memory as such to prevent execution, speculation etc. */
254 for (i = 0; i < params->device_mem_ranges_count; ++i) {
255 if (!vm_identity_map(
256 vm_locked, params->device_mem_ranges[i].begin,
257 params->device_mem_ranges[i].end,
258 MM_MODE_R | MM_MODE_W | MM_MODE_D, ppool, NULL)) {
259 dlog("Unable to initialise device memory for primary "
Andrew Scullf6ab9bc2020-02-26 12:56:37 -0800260 "VM.\n");
Andrew Scull48929fd2020-01-28 10:39:10 +0000261 ret = false;
262 goto out;
263 }
264 }
265
Manish Pandeyd34f8892020-06-19 17:41:07 +0100266 if (!load_common(stage1_locked, vm_locked, manifest_vm, ppool)) {
267 ret = false;
268 goto out;
269 }
270
Andrew Scull3c257452019-11-26 13:32:50 +0000271 if (!vm_unmap_hypervisor(vm_locked, ppool)) {
Andrew Scullf6ab9bc2020-02-26 12:56:37 -0800272 dlog_error("Unable to unmap hypervisor from primary VM.\n");
Andrew Scull3c257452019-11-26 13:32:50 +0000273 ret = false;
274 goto out;
David Brazdile6f83222019-09-23 14:47:37 +0100275 }
276
Andrew Scullb1a6d0d2020-01-29 11:25:12 +0000277 if (!plat_iommu_unmap_iommus(vm_locked, ppool)) {
Andrew Scullf6ab9bc2020-02-26 12:56:37 -0800278 dlog_error("Unable to unmap IOMMUs from primary VM.\n");
Andrew Scullb1a6d0d2020-01-29 11:25:12 +0000279 ret = false;
280 goto out;
281 }
282
Andrew Walbran7586e042020-02-18 18:19:26 +0000283 dlog_info("Loaded primary VM with %u vCPUs, entry at %#x.\n",
284 vm->vcpu_count, pa_addr(primary_begin));
285
David Brazdile6f83222019-09-23 14:47:37 +0100286 vcpu_locked = vcpu_lock(vm_get_vcpu(vm, 0));
Olivier Deprez62d99e32020-01-09 15:58:07 +0100287 vcpu_on(vcpu_locked, primary_entry, params->kernel_arg);
David Brazdile6f83222019-09-23 14:47:37 +0100288 vcpu_unlock(&vcpu_locked);
Andrew Scull3c257452019-11-26 13:32:50 +0000289 ret = true;
David Brazdile6f83222019-09-23 14:47:37 +0100290
Andrew Scull3c257452019-11-26 13:32:50 +0000291out:
292 vm_unlock(&vm_locked);
293
294 return ret;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100295}
296
Fuad Tabba50469e02020-06-30 15:14:28 +0100297/**
298 * Loads the secondary VM's FDT.
299 * Stores the total allocated size for the FDT in fdt_allocated_size (if
300 * fdt_allocated_size is not NULL). The allocated size includes additional space
301 * for potential patching.
302 */
303static bool load_secondary_fdt(struct mm_stage1_locked stage1_locked,
304 paddr_t end, size_t fdt_max_size,
305 const struct manifest_vm *manifest_vm,
306 const struct memiter *cpio, struct mpool *ppool,
307 paddr_t *fdt_addr, size_t *fdt_allocated_size)
308{
309 struct memiter fdt;
310 size_t allocated_size;
311
312 CHECK(!string_is_empty(&manifest_vm->secondary.fdt_filename));
313
314 if (!cpio_get_file(cpio, &manifest_vm->secondary.fdt_filename, &fdt)) {
315 dlog_error("Cannot open the secondary VM's FDT.\n");
316 return false;
317 }
318
319 /*
320 * Ensure the FDT has one additional page at the end for patching, and
321 * and align it to the page boundary.
322 */
323 allocated_size = align_up(memiter_size(&fdt), PAGE_SIZE) + PAGE_SIZE;
324
325 if (allocated_size > fdt_max_size) {
326 dlog_error(
327 "FDT allocated space (%u) is more than the specified "
328 "maximum to use (%u).\n",
329 allocated_size, fdt_max_size);
330 return false;
331 }
332
333 /* Load the FDT to the end of the VM's allocated memory space. */
334 *fdt_addr = pa_init(pa_addr(pa_sub(end, allocated_size)));
335
336 dlog_info("Loading secondary FDT of allocated size %u at 0x%x.\n",
337 allocated_size, pa_addr(*fdt_addr));
338
339 if (!copy_to_unmapped(stage1_locked, *fdt_addr, &fdt, ppool)) {
340 dlog_error("Unable to copy FDT.\n");
341 return false;
342 }
343
344 if (fdt_allocated_size) {
345 *fdt_allocated_size = allocated_size;
346 }
347
348 return true;
349}
350
Andrew Scull72b43c02019-09-18 13:53:45 +0100351/*
352 * Loads a secondary VM.
353 */
354static bool load_secondary(struct mm_stage1_locked stage1_locked,
Manish Pandey2145c212020-05-01 16:04:22 +0100355 struct vm_locked primary_vm_locked,
Andrew Scull72b43c02019-09-18 13:53:45 +0100356 paddr_t mem_begin, paddr_t mem_end,
357 const struct manifest_vm *manifest_vm,
358 const struct memiter *cpio, struct mpool *ppool)
359{
360 struct vm *vm;
Andrew Scull3c257452019-11-26 13:32:50 +0000361 struct vm_locked vm_locked;
Andrew Scull72b43c02019-09-18 13:53:45 +0100362 struct vcpu *vcpu;
363 ipaddr_t secondary_entry;
Andrew Scull3c257452019-11-26 13:32:50 +0000364 bool ret;
Fuad Tabba50469e02020-06-30 15:14:28 +0100365 paddr_t fdt_addr;
366 bool has_fdt;
367 size_t kernel_size = 0;
368 const size_t mem_size = pa_difference(mem_begin, mem_end);
Andrew Scull72b43c02019-09-18 13:53:45 +0100369
Olivier Deprez62d99e32020-01-09 15:58:07 +0100370 /*
371 * Load the kernel if a filename is specified in the VM manifest.
372 * For an FF-A partition, kernel_filename is undefined indicating
373 * the partition package has already been loaded prior to Hafnium
374 * booting.
375 */
376 if (!string_is_empty(&manifest_vm->kernel_filename)) {
377 if (!load_kernel(stage1_locked, mem_begin, mem_end, manifest_vm,
Fuad Tabba50469e02020-06-30 15:14:28 +0100378 cpio, ppool, &kernel_size)) {
Olivier Deprez62d99e32020-01-09 15:58:07 +0100379 dlog_error("Unable to load kernel.\n");
380 return false;
381 }
Andrew Scull72b43c02019-09-18 13:53:45 +0100382 }
383
Fuad Tabba50469e02020-06-30 15:14:28 +0100384 has_fdt = !string_is_empty(&manifest_vm->secondary.fdt_filename);
385 if (has_fdt) {
386 /*
387 * Ensure that the FDT does not overwrite the kernel or overlap
388 * its page, for the FDT to start at a page boundary.
389 */
390 const size_t fdt_max_size =
391 mem_size - align_up(kernel_size, PAGE_SIZE);
392
393 size_t fdt_allocated_size;
394
395 if (!load_secondary_fdt(stage1_locked, mem_end, fdt_max_size,
396 manifest_vm, cpio, ppool, &fdt_addr,
397 &fdt_allocated_size)) {
398 dlog_error("Unable to load FDT.\n");
399 return false;
400 }
401
402 if (!fdt_patch_mem(stage1_locked, fdt_addr, fdt_allocated_size,
403 mem_begin, mem_end, ppool)) {
404 dlog_error("Unable to patch FDT.\n");
405 return false;
406 }
407 }
408
Andrew Walbran9daa57e2019-09-27 13:33:20 +0100409 if (!vm_init_next(manifest_vm->secondary.vcpu_count, ppool, &vm)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000410 dlog_error("Unable to initialise VM.\n");
Andrew Scull72b43c02019-09-18 13:53:45 +0100411 return false;
412 }
413
Andrew Scull3c257452019-11-26 13:32:50 +0000414 vm_locked = vm_lock(vm);
415
Andrew Scull72b43c02019-09-18 13:53:45 +0100416 /* Grant the VM access to the memory. */
Andrew Scull3c257452019-11-26 13:32:50 +0000417 if (!vm_identity_map(vm_locked, mem_begin, mem_end,
418 MM_MODE_R | MM_MODE_W | MM_MODE_X, ppool,
419 &secondary_entry)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000420 dlog_error("Unable to initialise memory.\n");
Andrew Scull3c257452019-11-26 13:32:50 +0000421 ret = false;
422 goto out;
Andrew Scull72b43c02019-09-18 13:53:45 +0100423 }
424
Olivier Deprez62d99e32020-01-09 15:58:07 +0100425 if (manifest_vm->is_ffa_partition) {
Manish Pandey2145c212020-05-01 16:04:22 +0100426 int j = 0;
427 paddr_t region_begin;
428 paddr_t region_end;
429 paddr_t alloc_base = mem_end;
430 size_t size;
431 size_t total_alloc = 0;
432
433 /* Map memory-regions */
434 while (j < manifest_vm->sp.mem_region_count) {
435 size = manifest_vm->sp.mem_regions[j].page_count *
436 PAGE_SIZE;
437 /*
438 * For memory-regions without base-address, memory
439 * should be allocated inside partition's page table.
440 * Start allocating memory regions in partition's
441 * page table, starting from the end.
442 * TODO: Add mechanism to let partition know of these
443 * memory regions
444 */
445 if (manifest_vm->sp.mem_regions[j].base_address ==
446 MANIFEST_INVALID_ADDRESS) {
447 total_alloc += size;
448 /* Don't go beyond half the VM's memory space */
449 if (total_alloc >
450 (manifest_vm->secondary.mem_size / 2)) {
451 dlog_error(
452 "Not enough space for memory-"
453 "region allocation");
454 ret = false;
455 goto out;
456 }
457
458 region_end = alloc_base;
459 region_begin = pa_subtract(alloc_base, size);
460 alloc_base = region_begin;
461
462 if (!vm_identity_map(
463 vm_locked, region_begin, region_end,
464 manifest_vm->sp.mem_regions[j]
465 .attributes,
466 ppool, NULL)) {
467 dlog_error(
468 "Unable to map secondary VM "
469 "memory-region.\n");
470 ret = false;
471 goto out;
472 }
473
474 dlog_info(
475 " Memory region %#x - %#x allocated\n",
476 region_begin, region_end);
477 } else {
478 /*
479 * Identity map memory region for both case,
480 * VA(S-EL0) or IPA(S-EL1).
481 */
482 region_begin =
483 pa_init(manifest_vm->sp.mem_regions[j]
484 .base_address);
485 region_end = pa_add(region_begin, size);
486
487 if (!vm_identity_map(
488 vm_locked, region_begin, region_end,
489 manifest_vm->sp.mem_regions[j]
490 .attributes,
491 ppool, NULL)) {
492 dlog_error(
493 "Unable to map secondary VM "
494 "memory-region.\n");
495 ret = false;
496 goto out;
497 }
498 }
499
500 /* Deny the primary VM access to this memory */
501 if (!vm_unmap(primary_vm_locked, region_begin,
502 region_end, ppool)) {
503 dlog_error(
504 "Unable to unmap secondary VM memory-"
505 "region from primary VM.\n");
506 ret = false;
507 goto out;
508 }
509
510 j++;
511 }
512
513 /* Map device-regions */
514 j = 0;
515 while (j < manifest_vm->sp.dev_region_count) {
516 region_begin = pa_init(
517 manifest_vm->sp.dev_regions[j].base_address);
518 size = manifest_vm->sp.dev_regions[j].page_count *
519 PAGE_SIZE;
520 region_end = pa_add(region_begin, size);
521
522 if (!vm_identity_map(
523 vm_locked, region_begin, region_end,
524 manifest_vm->sp.dev_regions[j].attributes,
525 ppool, NULL)) {
526 dlog_error(
527 "Unable to map secondary VM "
528 "device-region.\n");
529 ret = false;
530 goto out;
531 }
532 /* Deny primary VM access to this region */
533 if (!vm_unmap(primary_vm_locked, region_begin,
534 region_end, ppool)) {
535 dlog_error(
536 "Unable to unmap secondary VM device-"
537 "region from primary VM.\n");
538 ret = false;
539 goto out;
540 }
541 j++;
542 }
543
Olivier Deprez62d99e32020-01-09 15:58:07 +0100544 secondary_entry =
545 ipa_add(secondary_entry, manifest_vm->sp.ep_offset);
546 }
547
Manish Pandeyd34f8892020-06-19 17:41:07 +0100548 if (!load_common(stage1_locked, vm_locked, manifest_vm, ppool)) {
549 ret = false;
550 goto out;
551 }
552
Manish Pandey2145c212020-05-01 16:04:22 +0100553 dlog_info("Loaded with %u vCPUs, entry at %#x.\n",
554 manifest_vm->secondary.vcpu_count, pa_addr(mem_begin));
555
Andrew Scull72b43c02019-09-18 13:53:45 +0100556 vcpu = vm_get_vcpu(vm, 0);
Fuad Tabba50469e02020-06-30 15:14:28 +0100557
558 if (has_fdt) {
559 vcpu_secondary_reset_and_start(vcpu, secondary_entry,
560 pa_addr(fdt_addr));
561 } else {
562 /*
563 * Without an FDT, secondary VMs expect the memory size to be
564 * passed in register x0, which is what
565 * vcpu_secondary_reset_and_start does in this case.
566 */
567 vcpu_secondary_reset_and_start(vcpu, secondary_entry, mem_size);
568 }
569
Andrew Scull3c257452019-11-26 13:32:50 +0000570 ret = true;
Andrew Scull72b43c02019-09-18 13:53:45 +0100571
Andrew Scull3c257452019-11-26 13:32:50 +0000572out:
573 vm_unlock(&vm_locked);
574
575 return ret;
Andrew Scull72b43c02019-09-18 13:53:45 +0100576}
577
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100578/**
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100579 * Try to find a memory range of the given size within the given ranges, and
580 * remove it from them. Return true on success, or false if no large enough
581 * contiguous range is found.
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100582 */
Hong-Seok Kim09648362019-05-23 15:47:11 +0900583static bool carve_out_mem_range(struct mem_range *mem_ranges,
584 size_t mem_ranges_count, uint64_t size_to_find,
585 paddr_t *found_begin, paddr_t *found_end)
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100586{
587 size_t i;
588
Wedson Almeida Filho81568c42019-01-04 13:33:02 +0000589 /*
590 * TODO(b/116191358): Consider being cleverer about how we pack VMs
591 * together, with a non-greedy algorithm.
592 */
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100593 for (i = 0; i < mem_ranges_count; ++i) {
594 if (size_to_find <=
Andrew Walbran2cb43392019-04-17 12:52:45 +0100595 pa_difference(mem_ranges[i].begin, mem_ranges[i].end)) {
Wedson Almeida Filhob2c159e2018-10-25 13:27:47 +0100596 /*
597 * This range is big enough, take some of it from the
598 * end and reduce its size accordingly.
599 */
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100600 *found_end = mem_ranges[i].end;
601 *found_begin = pa_init(pa_addr(mem_ranges[i].end) -
602 size_to_find);
603 mem_ranges[i].end = *found_begin;
604 return true;
605 }
606 }
607 return false;
608}
609
610/**
611 * Given arrays of memory ranges before and after memory was removed for
612 * secondary VMs, add the difference to the reserved ranges of the given update.
613 * Return true on success, or false if there would be more than MAX_MEM_RANGES
614 * reserved ranges after adding the new ones.
615 * `before` and `after` must be arrays of exactly `mem_ranges_count` elements.
616 */
Hong-Seok Kim09648362019-05-23 15:47:11 +0900617static bool update_reserved_ranges(struct boot_params_update *update,
618 const struct mem_range *before,
619 const struct mem_range *after,
620 size_t mem_ranges_count)
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100621{
622 size_t i;
623
624 for (i = 0; i < mem_ranges_count; ++i) {
625 if (pa_addr(after[i].begin) > pa_addr(before[i].begin)) {
626 if (update->reserved_ranges_count >= MAX_MEM_RANGES) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000627 dlog_error(
628 "Too many reserved ranges after "
629 "loading secondary VMs.\n");
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100630 return false;
631 }
632 update->reserved_ranges[update->reserved_ranges_count]
633 .begin = before[i].begin;
634 update->reserved_ranges[update->reserved_ranges_count]
635 .end = after[i].begin;
636 update->reserved_ranges_count++;
637 }
638 if (pa_addr(after[i].end) < pa_addr(before[i].end)) {
639 if (update->reserved_ranges_count >= MAX_MEM_RANGES) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000640 dlog_error(
641 "Too many reserved ranges after "
642 "loading secondary VMs.\n");
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100643 return false;
644 }
645 update->reserved_ranges[update->reserved_ranges_count]
646 .begin = after[i].end;
647 update->reserved_ranges[update->reserved_ranges_count]
648 .end = before[i].end;
649 update->reserved_ranges_count++;
650 }
651 }
652
653 return true;
654}
655
Andrew Scull72b43c02019-09-18 13:53:45 +0100656/*
657 * Loads alls VMs from the manifest.
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100658 */
Andrew Scull72b43c02019-09-18 13:53:45 +0100659bool load_vms(struct mm_stage1_locked stage1_locked,
660 const struct manifest *manifest, const struct memiter *cpio,
661 const struct boot_params *params,
662 struct boot_params_update *update, struct mpool *ppool)
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100663{
Andrew Scull19503262018-09-20 14:48:39 +0100664 struct vm *primary;
Andrew Walbran9daa57e2019-09-27 13:33:20 +0100665 struct vm *tee;
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100666 struct mem_range mem_ranges_available[MAX_MEM_RANGES];
Andrew Scull3c257452019-11-26 13:32:50 +0000667 struct vm_locked primary_vm_locked;
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100668 size_t i;
Andrew Scull3c257452019-11-26 13:32:50 +0000669 bool success = true;
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100670
Andrew Scullae9962e2019-10-03 16:51:16 +0100671 if (!load_primary(stage1_locked, &manifest->vm[HF_PRIMARY_VM_INDEX],
672 cpio, params, ppool)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000673 dlog_error("Unable to load primary VM.\n");
Andrew Scull72b43c02019-09-18 13:53:45 +0100674 return false;
675 }
676
Andrew Walbran9daa57e2019-09-27 13:33:20 +0100677 /*
678 * Initialise the dummy VM which represents TrustZone, and set up its
679 * RX/TX buffers.
680 */
681 tee = vm_init(HF_TEE_VM_ID, 0, ppool);
682 CHECK(tee != NULL);
683 tee->mailbox.send = &tee_send_buffer;
684 tee->mailbox.recv = &tee_recv_buffer;
685
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100686 static_assert(
687 sizeof(mem_ranges_available) == sizeof(params->mem_ranges),
688 "mem_range arrays must be the same size for memcpy.");
689 static_assert(sizeof(mem_ranges_available) < 500,
690 "This will use too much stack, either make "
691 "MAX_MEM_RANGES smaller or change this.");
Andrew Sculla1aa2ba2019-04-05 11:49:02 +0100692 memcpy_s(mem_ranges_available, sizeof(mem_ranges_available),
693 params->mem_ranges, sizeof(params->mem_ranges));
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100694
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100695 /* Round the last addresses down to the page size. */
696 for (i = 0; i < params->mem_ranges_count; ++i) {
Alfredo Mazzinghieb1997c2019-02-07 18:00:01 +0000697 mem_ranges_available[i].end = pa_init(align_down(
698 pa_addr(mem_ranges_available[i].end), PAGE_SIZE));
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100699 }
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100700
Andrew Scull3c257452019-11-26 13:32:50 +0000701 primary = vm_find(HF_PRIMARY_VM_ID);
702 primary_vm_locked = vm_lock(primary);
703
David Brazdil0251b942019-09-10 15:59:50 +0100704 for (i = 0; i < manifest->vm_count; ++i) {
David Brazdil0dbb41f2019-09-09 18:03:35 +0100705 const struct manifest_vm *manifest_vm = &manifest->vm[i];
Andrew Walbranb5ab43c2020-04-30 11:32:54 +0100706 ffa_vm_id_t vm_id = HF_VM_ID_OFFSET + i;
David Brazdil7a462ec2019-08-15 12:27:47 +0100707 uint64_t mem_size;
Andrew Scull80871322018-08-06 12:04:09 +0100708 paddr_t secondary_mem_begin;
709 paddr_t secondary_mem_end;
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100710
David Brazdil7a462ec2019-08-15 12:27:47 +0100711 if (vm_id == HF_PRIMARY_VM_ID) {
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100712 continue;
713 }
714
Olivier Deprez2a8ee342020-08-03 15:10:44 +0200715 dlog_info("Loading VM id %#x: %s.\n", vm_id,
Andrew Walbran17eebf92020-02-05 16:35:49 +0000716 manifest_vm->debug_name);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100717
David Brazdil7a462ec2019-08-15 12:27:47 +0100718 mem_size = align_up(manifest_vm->secondary.mem_size, PAGE_SIZE);
Olivier Deprez62d99e32020-01-09 15:58:07 +0100719
720 if (manifest_vm->is_ffa_partition) {
721 secondary_mem_begin =
722 pa_init(manifest_vm->sp.load_addr);
723 secondary_mem_end =
724 pa_init(manifest_vm->sp.load_addr + mem_size);
725 } else if (!carve_out_mem_range(mem_ranges_available,
726 params->mem_ranges_count,
727 mem_size, &secondary_mem_begin,
728 &secondary_mem_end)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000729 dlog_error("Not enough memory (%u bytes).\n", mem_size);
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100730 continue;
731 }
Andrew Scull80871322018-08-06 12:04:09 +0100732
Manish Pandey2145c212020-05-01 16:04:22 +0100733 if (!load_secondary(stage1_locked, primary_vm_locked,
734 secondary_mem_begin, secondary_mem_end,
735 manifest_vm, cpio, ppool)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000736 dlog_error("Unable to load VM.\n");
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100737 continue;
738 }
739
740 /* Deny the primary VM access to this memory. */
Andrew Scull3c257452019-11-26 13:32:50 +0000741 if (!vm_unmap(primary_vm_locked, secondary_mem_begin,
742 secondary_mem_end, ppool)) {
Andrew Walbran17eebf92020-02-05 16:35:49 +0000743 dlog_error(
744 "Unable to unmap secondary VM from primary "
745 "VM.\n");
Andrew Scull3c257452019-11-26 13:32:50 +0000746 success = false;
747 break;
Wedson Almeida Filho84a30a02018-07-23 20:05:05 +0100748 }
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100749 }
750
Andrew Scull3c257452019-11-26 13:32:50 +0000751 vm_unlock(&primary_vm_locked);
752
753 if (!success) {
754 return false;
755 }
756
Wedson Almeida Filhob2c159e2018-10-25 13:27:47 +0100757 /*
758 * Add newly reserved areas to update params by looking at the
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100759 * difference between the available ranges from the original params and
760 * the updated mem_ranges_available. We assume that the number and order
761 * of available ranges is the same, i.e. we don't remove any ranges
Wedson Almeida Filhob2c159e2018-10-25 13:27:47 +0100762 * above only make them smaller.
763 */
Andrew Walbran34ce72e2018-09-13 16:47:44 +0100764 return update_reserved_ranges(update, params->mem_ranges,
765 mem_ranges_available,
766 params->mem_ranges_count);
Wedson Almeida Filhofdf4afc2018-07-19 15:45:21 +0100767}