David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 1 | /* |
Feder Liang | 5519438 | 2021-11-22 16:45:33 +0800 | [diff] [blame] | 2 | * Copyright (c) 2018-2022, Arm Limited. All rights reserved. |
Chris Brand | be5bec1 | 2022-10-18 11:41:59 -0700 | [diff] [blame^] | 3 | * Copyright (c) 2022 Cypress Semiconductor Corporation (an Infineon |
| 4 | * company) or an affiliate of Cypress Semiconductor Corporation. All rights |
| 5 | * reserved. |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 6 | * |
| 7 | * SPDX-License-Identifier: BSD-3-Clause |
| 8 | * |
| 9 | */ |
| 10 | #ifndef __TFM_ARCH_H__ |
| 11 | #define __TFM_ARCH_H__ |
| 12 | |
| 13 | /* This header file collects the architecture related operations. */ |
| 14 | |
Ken Liu | 1d96c13 | 2019-12-31 15:51:30 +0800 | [diff] [blame] | 15 | #include <stddef.h> |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 16 | #include <inttypes.h> |
Kevin Peng | bc5e5aa | 2019-10-16 10:55:17 +0800 | [diff] [blame] | 17 | #include "tfm_hal_device_header.h" |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 18 | #include "cmsis_compiler.h" |
| 19 | |
Ronald Cron | 312be68 | 2019-09-23 09:27:33 +0200 | [diff] [blame] | 20 | #if defined(__ARM_ARCH_8_1M_MAIN__) || \ |
| 21 | defined(__ARM_ARCH_8M_MAIN__) || defined(__ARM_ARCH_8M_BASE__) |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 22 | #include "tfm_arch_v8m.h" |
David Hu | 40455c9 | 2019-07-02 14:31:34 +0800 | [diff] [blame] | 23 | #elif defined(__ARM_ARCH_6M__) || defined(__ARM_ARCH_7M__) || \ |
| 24 | defined(__ARM_ARCH_7EM__) |
| 25 | #include "tfm_arch_v6m_v7m.h" |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 26 | #else |
| 27 | #error "Unsupported ARM Architecture." |
| 28 | #endif |
| 29 | |
Mingyang Sun | 620c856 | 2021-11-10 11:44:58 +0800 | [diff] [blame] | 30 | #define SCHEDULER_LOCKED 1 |
| 31 | #define SCHEDULER_UNLOCKED 0 |
| 32 | |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 33 | #define XPSR_T32 0x01000000 |
| 34 | |
Chris Brand | be5bec1 | 2022-10-18 11:41:59 -0700 | [diff] [blame^] | 35 | /* The lowest secure interrupt priority */ |
| 36 | #ifdef CONFIG_TFM_USE_TRUSTZONE |
| 37 | /* IMPORTANT NOTE: |
| 38 | * |
| 39 | * Although the priority of the secure PendSV must be the lowest possible |
| 40 | * among other interrupts in the Secure state, it must be ensured that |
| 41 | * PendSV is not preempted nor masked by Non-Secure interrupts to ensure |
| 42 | * the integrity of the Secure operation. |
| 43 | * When AIRCR.PRIS is set, the Non-Secure execution can act on |
| 44 | * FAULTMASK_NS, PRIMASK_NS or BASEPRI_NS register to boost its priority |
| 45 | * number up to the value 0x80. |
| 46 | * For this reason, set the priority of the PendSV interrupt to the next |
| 47 | * priority level configurable on the platform, just below 0x80. |
| 48 | */ |
| 49 | #define PENDSV_PRIO_FOR_SCHED ((1 << (__NVIC_PRIO_BITS - 1)) - 1) |
| 50 | #else |
| 51 | /* If TZ is not in use, we have the full priority range available */ |
| 52 | #define PENDSV_PRIO_FOR_SCHED ((1 << __NVIC_PRIO_BITS) - 1) |
| 53 | #endif |
| 54 | |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 55 | /* State context defined by architecture */ |
Ken Liu | 5a2b905 | 2019-08-15 19:03:29 +0800 | [diff] [blame] | 56 | struct tfm_state_context_t { |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 57 | uint32_t r0; |
| 58 | uint32_t r1; |
| 59 | uint32_t r2; |
| 60 | uint32_t r3; |
| 61 | uint32_t r12; |
Ken Liu | 5a2b905 | 2019-08-15 19:03:29 +0800 | [diff] [blame] | 62 | uint32_t lr; |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 63 | uint32_t ra; |
| 64 | uint32_t xpsr; |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 65 | }; |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 66 | |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 67 | /* Context addition to state context */ |
| 68 | struct tfm_additional_context_t { |
| 69 | uint32_t callee[8]; /* R4-R11. NOT ORDERED!! */ |
| 70 | }; |
| 71 | |
| 72 | /* Full thread context */ |
| 73 | struct full_context_t { |
| 74 | struct tfm_additional_context_t addi_ctx; |
| 75 | struct tfm_state_context_t stat_ctx; |
| 76 | }; |
| 77 | |
Ken Liu | ca4580f | 2022-03-09 21:27:43 +0800 | [diff] [blame] | 78 | /* |
| 79 | * Under cross call ABI, SPM can be preempted by interrupts, the interrupt |
| 80 | * handling can set SPM API return value and makes the initial SPM API |
| 81 | * return code invalid. Use one flag to indicate if the return code has been |
| 82 | * force updated by interrupts, then SPM return code can be discarded as it |
| 83 | * is out of date. |
| 84 | */ |
| 85 | #define CROSS_RETCODE_EMPTY 0xEEEEEEED |
| 86 | #define CROSS_RETCODE_UPDATED 0xEEEEEEEE |
| 87 | |
Sherry Zhang | b24f54d | 2022-07-04 14:26:07 +0800 | [diff] [blame] | 88 | /* Context control. |
| 89 | * CAUTION: Assembly references this structure. DO CHECK the below functions |
| 90 | * before changing the structure: |
| 91 | 'PendSV_Handler' |
| 92 | */ |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 93 | struct context_ctrl_t { |
Sherry Zhang | b24f54d | 2022-07-04 14:26:07 +0800 | [diff] [blame] | 94 | uint32_t sp; /* Stack pointer (higher address). |
| 95 | * THIS MUST BE THE FIRST MEMBER OF |
| 96 | * THE STRUCT. |
| 97 | */ |
| 98 | uint32_t exc_ret; /* EXC_RETURN pattern. |
| 99 | * THIS MUST BE THE SECOND MEMBER OF |
| 100 | * THE STRUCT. |
| 101 | */ |
Ken Liu | ca4580f | 2022-03-09 21:27:43 +0800 | [diff] [blame] | 102 | uint32_t sp_limit; /* Stack limit (lower address) */ |
Ken Liu | 63a176b | 2022-06-09 22:36:56 +0800 | [diff] [blame] | 103 | uint32_t sp_base; /* Stack usage start (higher addr) */ |
Ken Liu | ca4580f | 2022-03-09 21:27:43 +0800 | [diff] [blame] | 104 | uint32_t cross_frame; /* Cross call frame position. */ |
| 105 | uint32_t retcode_status; /* Cross call retcode status. */ |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 106 | }; |
| 107 | |
| 108 | /* |
| 109 | * The context on MSP when de-privileged FLIH Function calls SVC to return. |
| 110 | * It is the same when de-privileged FLIH Function is ready to run. |
| 111 | */ |
| 112 | struct context_flih_ret_t { |
| 113 | uint64_t stack_seal; /* Two words stack seal */ |
| 114 | struct tfm_additional_context_t addi_ctx; |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 115 | uint32_t psp; /* PSP when interrupt exception ocurrs */ |
Kevin Peng | ca59ec0 | 2021-12-09 14:35:50 +0800 | [diff] [blame] | 116 | uint32_t psplim; /* PSPLIM when interrupt exception ocurrs when */ |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 117 | struct tfm_state_context_t state_ctx; /* ctx on SVC_PREPARE_DEPRIV_FLIH */ |
| 118 | }; |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 119 | |
Ken Liu | ca4580f | 2022-03-09 21:27:43 +0800 | [diff] [blame] | 120 | /* A customized ABI format. */ |
| 121 | struct cross_call_abi_frame_t { |
| 122 | uint32_t a0; |
| 123 | uint32_t a1; |
| 124 | uint32_t a2; |
| 125 | uint32_t a3; |
| 126 | uint32_t unused0; |
| 127 | uint32_t unused1; |
| 128 | }; |
| 129 | |
Ken Liu | bf4681f | 2022-02-11 11:15:03 +0800 | [diff] [blame] | 130 | /* Assign stack and stack limit to the context control instance. */ |
Ken Liu | 63a176b | 2022-06-09 22:36:56 +0800 | [diff] [blame] | 131 | #define ARCH_CTXCTRL_INIT(x, buf, sz) do { \ |
| 132 | (x)->sp = ((uint32_t)(buf) + (uint32_t)(sz)) & ~0x7; \ |
| 133 | (x)->sp_limit = ((uint32_t)(buf) + 7) & ~0x7; \ |
| 134 | (x)->sp_base = (x)->sp; \ |
| 135 | (x)->exc_ret = 0; \ |
| 136 | (x)->cross_frame = 0; \ |
| 137 | (x)->retcode_status = CROSS_RETCODE_EMPTY; \ |
Ken Liu | bf4681f | 2022-02-11 11:15:03 +0800 | [diff] [blame] | 138 | } while (0) |
| 139 | |
| 140 | /* Allocate 'size' bytes in stack. */ |
Ken Liu | 63a176b | 2022-06-09 22:36:56 +0800 | [diff] [blame] | 141 | #define ARCH_CTXCTRL_ALLOCATE_STACK(x, size) \ |
| 142 | ((x)->sp -= ((size) + 7) & ~0x7) |
Ken Liu | bf4681f | 2022-02-11 11:15:03 +0800 | [diff] [blame] | 143 | |
Ken Liu | 63a176b | 2022-06-09 22:36:56 +0800 | [diff] [blame] | 144 | /* The last allocated pointer. */ |
Ken Liu | bf4681f | 2022-02-11 11:15:03 +0800 | [diff] [blame] | 145 | #define ARCH_CTXCTRL_ALLOCATED_PTR(x) ((x)->sp) |
| 146 | |
| 147 | /* Prepare a exception return pattern on the stack. */ |
| 148 | #define ARCH_CTXCTRL_EXCRET_PATTERN(x, param, pfn, pfnlr) do { \ |
| 149 | (x)->r0 = (uint32_t)(param); \ |
| 150 | (x)->ra = (uint32_t)(pfn); \ |
| 151 | (x)->lr = (uint32_t)(pfnlr); \ |
| 152 | (x)->xpsr = XPSR_T32; \ |
| 153 | } while (0) |
| 154 | |
Ken Liu | 63a176b | 2022-06-09 22:36:56 +0800 | [diff] [blame] | 155 | /* |
| 156 | * Claim a statically initialized context control instance. |
| 157 | * Make the start stack pointer at 'stack_buf[stack_size]' because |
| 158 | * the hardware acts in a 'Decrease-then-store' behaviour. |
| 159 | */ |
| 160 | #define ARCH_CLAIM_CTXCTRL_INSTANCE(name, stack_buf, stack_size) \ |
| 161 | struct context_ctrl_t name = { \ |
| 162 | .sp = (uint32_t)&stack_buf[stack_size], \ |
| 163 | .sp_base = (uint32_t)&stack_buf[stack_size], \ |
| 164 | .sp_limit = (uint32_t)stack_buf, \ |
| 165 | .exc_ret = 0, \ |
| 166 | } |
| 167 | |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 168 | /** |
| 169 | * \brief Get Link Register |
| 170 | * \details Returns the value of the Link Register (LR) |
| 171 | * \return LR value |
| 172 | */ |
TTornblom | dd233d1 | 2020-11-05 11:44:28 +0100 | [diff] [blame] | 173 | #if !defined ( __ICCARM__ ) |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 174 | __attribute__ ((always_inline)) __STATIC_INLINE uint32_t __get_LR(void) |
| 175 | { |
| 176 | register uint32_t result; |
| 177 | |
| 178 | __ASM volatile ("MOV %0, LR\n" : "=r" (result)); |
| 179 | return result; |
| 180 | } |
TTornblom | dd233d1 | 2020-11-05 11:44:28 +0100 | [diff] [blame] | 181 | #endif |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 182 | |
Ken Liu | 92ede9f | 2021-10-20 09:35:00 +0800 | [diff] [blame] | 183 | __STATIC_INLINE uint32_t __save_disable_irq(void) |
| 184 | { |
| 185 | uint32_t result; |
| 186 | |
| 187 | __ASM volatile ("mrs %0, primask \n cpsid i" : "=r" (result) :: "memory"); |
| 188 | return result; |
| 189 | } |
| 190 | |
| 191 | __STATIC_INLINE void __restore_irq(uint32_t status) |
| 192 | { |
| 193 | __ASM volatile ("msr primask, %0" :: "r" (status) : "memory"); |
| 194 | } |
| 195 | |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 196 | __attribute__ ((always_inline)) |
| 197 | __STATIC_INLINE uint32_t __get_active_exc_num(void) |
| 198 | { |
| 199 | IPSR_Type IPSR; |
| 200 | |
| 201 | /* if non-zero, exception is active. NOT banked S/NS */ |
| 202 | IPSR.w = __get_IPSR(); |
| 203 | return IPSR.b.ISR; |
| 204 | } |
| 205 | |
| 206 | __attribute__ ((always_inline)) |
| 207 | __STATIC_INLINE void __set_CONTROL_SPSEL(uint32_t SPSEL) |
| 208 | { |
| 209 | CONTROL_Type ctrl; |
| 210 | |
| 211 | ctrl.w = __get_CONTROL(); |
| 212 | ctrl.b.SPSEL = SPSEL; |
| 213 | __set_CONTROL(ctrl.w); |
| 214 | __ISB(); |
| 215 | } |
| 216 | |
Antonio de Angelis | 995e4a6 | 2022-10-19 15:46:42 +0100 | [diff] [blame] | 217 | |
| 218 | /** |
| 219 | * \brief Whether in privileged level |
| 220 | * |
| 221 | * \retval true If current execution runs in privileged level. |
| 222 | * \retval false If current execution runs in unprivileged level. |
| 223 | */ |
| 224 | __STATIC_INLINE bool tfm_arch_is_priv(void) |
| 225 | { |
| 226 | CONTROL_Type ctrl; |
| 227 | |
| 228 | /* If in Handler mode */ |
| 229 | if (__get_IPSR()) { |
| 230 | return true; |
| 231 | } |
| 232 | |
| 233 | /* If in privileged Thread mode */ |
| 234 | ctrl.w = __get_CONTROL(); |
| 235 | if (!ctrl.b.nPRIV) { |
| 236 | return true; |
| 237 | } |
| 238 | |
| 239 | return false; |
| 240 | } |
| 241 | |
Gabor Toth | 4d41411 | 2021-11-10 17:44:50 +0100 | [diff] [blame] | 242 | #if (CONFIG_TFM_FLOAT_ABI >= 1) && CONFIG_TFM_LAZY_STACKING |
Feder Liang | 42f5b56 | 2021-09-10 17:38:36 +0800 | [diff] [blame] | 243 | #define ARCH_FLUSH_FP_CONTEXT() __asm volatile("vmov s0, s0 \n":::"memory") |
| 244 | #else |
| 245 | #define ARCH_FLUSH_FP_CONTEXT() |
| 246 | #endif |
| 247 | |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 248 | /* Set secure exceptions priority. */ |
Ken Liu | 50e2109 | 2020-10-14 16:42:15 +0800 | [diff] [blame] | 249 | void tfm_arch_set_secure_exception_priorities(void); |
Jamie Fox | 3ede971 | 2020-09-28 23:14:54 +0100 | [diff] [blame] | 250 | |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 251 | /* Configure various extensions. */ |
Summer Qin | dea1f2c | 2021-01-11 14:46:34 +0800 | [diff] [blame] | 252 | void tfm_arch_config_extensions(void); |
Jamie Fox | 4558767 | 2020-08-17 18:31:14 +0100 | [diff] [blame] | 253 | |
Gabor Toth | 4d41411 | 2021-11-10 17:44:50 +0100 | [diff] [blame] | 254 | #if (CONFIG_TFM_FLOAT_ABI > 0) |
Ken Liu | 182fb40 | 2022-06-20 16:05:47 +0800 | [diff] [blame] | 255 | /* Clear float point data. */ |
Feder Liang | 42f5b56 | 2021-09-10 17:38:36 +0800 | [diff] [blame] | 256 | void tfm_arch_clear_fp_data(void); |
| 257 | #endif |
| 258 | |
Kevin Peng | 300c68d | 2021-08-12 17:40:17 +0800 | [diff] [blame] | 259 | /* |
| 260 | * This function is called after SPM has initialized. |
| 261 | * It frees the stack used by SPM initialization and do Exception Return. |
| 262 | * It does not return. |
| 263 | */ |
Ken Liu | dedbf4b | 2021-11-02 09:07:25 +0800 | [diff] [blame] | 264 | void tfm_arch_free_msp_and_exc_ret(uint32_t msp_base, uint32_t exc_return); |
Kevin Peng | 300c68d | 2021-08-12 17:40:17 +0800 | [diff] [blame] | 265 | |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 266 | /* |
| 267 | * This function sets return value on APIs that cause scheduling, for example |
| 268 | * psa_wait(), by manipulating the control context - this is usaully setting the |
| 269 | * R0 register of the thread context. |
| 270 | */ |
Ken Liu | ca4580f | 2022-03-09 21:27:43 +0800 | [diff] [blame] | 271 | void tfm_arch_set_context_ret_code(void *p_ctx_ctrl, uint32_t ret_code); |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 272 | |
| 273 | /* Init a thread context on thread stack and update the control context. */ |
| 274 | void tfm_arch_init_context(void *p_ctx_ctrl, |
Ken Liu | bf4681f | 2022-02-11 11:15:03 +0800 | [diff] [blame] | 275 | uintptr_t pfn, void *param, uintptr_t pfnlr); |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 276 | |
| 277 | /* |
| 278 | * Refresh the HW (sp, splimit) according to the given control context and |
| 279 | * returns the EXC_RETURN payload (caller might need it for following codes). |
| 280 | * |
Ken Liu | bf4681f | 2022-02-11 11:15:03 +0800 | [diff] [blame] | 281 | * The p_ctx_ctrl must have been initialized by 'tfm_arch_init_context'. |
Ken Liu | 5d73c87 | 2021-08-19 19:23:17 +0800 | [diff] [blame] | 282 | */ |
| 283 | uint32_t tfm_arch_refresh_hardware_context(void *p_ctx_ctrl); |
| 284 | |
Ken Liu | e07c3b7 | 2021-10-14 16:19:13 +0800 | [diff] [blame] | 285 | /* |
| 286 | * Triggers scheduler. A return type is assigned in case |
| 287 | * SPM returns values by the context. |
| 288 | */ |
| 289 | uint32_t tfm_arch_trigger_pendsv(void); |
| 290 | |
Ken Liu | e07c3b7 | 2021-10-14 16:19:13 +0800 | [diff] [blame] | 291 | /* |
| 292 | * Switch to a new stack area, lock scheduler and call function. |
| 293 | * If 'stk_base' is ZERO, stack won't be switched and re-use caller stack. |
| 294 | */ |
Ken Liu | ca4580f | 2022-03-09 21:27:43 +0800 | [diff] [blame] | 295 | void arch_non_preempt_call(uintptr_t fn_addr, uintptr_t frame_addr, |
| 296 | uint32_t stk_base, uint32_t stk_limit); |
Ken Liu | e07c3b7 | 2021-10-14 16:19:13 +0800 | [diff] [blame] | 297 | |
David Hu | 50711e3 | 2019-06-12 18:32:30 +0800 | [diff] [blame] | 298 | #endif |