From: Kane Chen <kane_chen@aspeedtech.com>
To: "Cédric Le Goater" <clg@kaod.org>,
"Peter Maydell" <peter.maydell@linaro.org>,
"Steven Lee" <steven_lee@aspeedtech.com>,
"Troy Lee" <leetroy@gmail.com>,
"Jamin Lin" <jamin_lin@aspeedtech.com>,
"Andrew Jeffery" <andrew@codeconstruct.com.au>,
"Joel Stanley" <joel@jms.id.au>,
"open list:ASPEED BMCs" <qemu-arm@nongnu.org>,
"open list:All patches CC here" <qemu-devel@nongnu.org>
Cc: Troy Lee <troy_lee@aspeedtech.com>, Kane Chen <kane_chen@aspeedtech.com>
Subject: [PATCH v1 1/2] hw/misc/aspeed_sbc: Derive ABR state from OTP config straps
Date: Mon, 31 Aug 2026 05:37:00 +0000 [thread overview]
Message-ID: <20260831053658.462203-2-kane_chen@aspeedtech.com> (raw)
In-Reply-To: <20260831053658.462203-1-kane_chen@aspeedtech.com>
The eMMC ABR (Alternate Boot Recovery) enable state was controlled by
a fixed "emmc-abr" machine property, and the logic reflecting it in
R_STATUS was broken so ABR could never actually be reported as
enabled.
Instead of relying on the property, read the ABR strap value directly
from the OTP configuration space and derive the enable state from it,
matching how the real hardware determines ABR. The now-unused
"emmc-abr" property is removed.
Signed-off-by: Kane-Chen-AS <kane_chen@aspeedtech.com>
---
include/hw/misc/aspeed_sbc.h | 1 -
hw/misc/aspeed_sbc.c | 35 ++++++++++++++++++++++++++++++++---
2 files changed, 32 insertions(+), 4 deletions(-)
diff --git a/include/hw/misc/aspeed_sbc.h b/include/hw/misc/aspeed_sbc.h
index 07c7c22a86..7152497b2a 100644
--- a/include/hw/misc/aspeed_sbc.h
+++ b/include/hw/misc/aspeed_sbc.h
@@ -32,7 +32,6 @@ OBJECT_DECLARE_TYPE(AspeedSBCState, AspeedSBCClass, ASPEED_SBC)
struct AspeedSBCState {
SysBusDevice parent;
- bool emmc_abr;
uint32_t signing_settings;
MemoryRegion iomem;
diff --git a/hw/misc/aspeed_sbc.c b/hw/misc/aspeed_sbc.c
index 1dfcf14e5b..5d4da39d30 100644
--- a/hw/misc/aspeed_sbc.c
+++ b/hw/misc/aspeed_sbc.c
@@ -60,6 +60,9 @@
#define MODE_REGISTER_A (0x3000)
#define MODE_REGISTER_B (0x5000)
+/* OTP Address */
+#define OTP_CFG0 (0x800)
+
static uint64_t aspeed_sbc_read(void *opaque, hwaddr addr, unsigned int size)
{
AspeedSBCState *s = ASPEED_SBC(opaque);
@@ -261,17 +264,44 @@ static const MemoryRegionOps aspeed_sbc_ops = {
},
};
+static bool aspeed_get_abr_state(AspeedSBCState *s)
+{
+ uint32_t value;
+ int i;
+ bool enable = false;
+ int config_offset;
+
+ /*
+ * ABR is a strap setting, and each strap setting consists of six
+ * sub-values. Read all sub-values to retrieve the latest setting.
+ */
+ for (i = 17; i < 28; i += 2) {
+ config_offset = OTP_CFG0;
+ config_offset |= (i / 8) * 0x200;
+ config_offset |= (i % 8) * 0x2;
+
+ aspeed_sbc_otp_read(s, config_offset);
+ value = s->regs[R_CAMP1];
+ enable ^= (value >> 11) & 0x1;
+ }
+
+ return enable;
+}
+
static void aspeed_sbc_reset_hold(Object *obj, ResetType type)
{
AspeedSBCState *s = ASPEED_SBC(obj);
+ bool abr;
memset(s->regs, 0, sizeof(s->regs));
+ abr = aspeed_get_abr_state(s);
+
/* Set secure boot enabled with RSA4096_SHA256 and enable eMMC ABR */
s->regs[R_STATUS] = OTP_IDLE | OTP_MEM_IDLE;
- if (s->emmc_abr) {
- s->regs[R_STATUS] &= ABR_EN;
+ if (abr) {
+ s->regs[R_STATUS] |= ABR_EN;
}
if (s->signing_settings) {
@@ -323,7 +353,6 @@ static const VMStateDescription vmstate_aspeed_sbc = {
};
static const Property aspeed_sbc_properties[] = {
- DEFINE_PROP_BOOL("emmc-abr", AspeedSBCState, emmc_abr, 0),
DEFINE_PROP_UINT32("signing-settings", AspeedSBCState, signing_settings, 0),
};
--
2.43.0
next prev parent reply other threads:[~2026-08-31 5:38 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 5:36 [PATCH v1 0/2] hw/misc/aspeed_sbc: Fix ABR and secure boot state reporting Kane Chen
2026-08-31 5:37 ` Kane Chen [this message]
2026-08-31 5:40 ` [PATCH v1 1/2] hw/misc/aspeed_sbc: Derive ABR state from OTP config straps Jamin Lin
2026-08-31 11:10 ` Cédric Le Goater
2026-09-01 9:25 ` Kane Chen
2026-09-03 7:22 ` Cédric Le Goater
2026-09-03 7:35 ` Kane Chen
2026-08-31 5:37 ` [PATCH v1 2/2] hw/misc/aspeed_sbc: Derive secure boot " Kane Chen
2026-08-31 5:41 ` Jamin Lin
2026-08-31 11:14 ` Cédric Le Goater
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831053658.462203-2-kane_chen@aspeedtech.com \
--to=kane_chen@aspeedtech.com \
--cc=andrew@codeconstruct.com.au \
--cc=clg@kaod.org \
--cc=jamin_lin@aspeedtech.com \
--cc=joel@jms.id.au \
--cc=leetroy@gmail.com \
--cc=peter.maydell@linaro.org \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=steven_lee@aspeedtech.com \
--cc=troy_lee@aspeedtech.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.