From: Bin Meng <bin.meng@processmission.com>
To: QEMU <qemu-devel@nongnu.org>
Cc: "Alistair Francis" <alistair.francis@wdc.com>,
"Alistair Francis" <alistair@alistair23.me>,
"Bin Meng" <bmeng.cn@gmail.com>,
"Chao Liu" <chao.liu@processmission.com>,
"Conor Dooley" <conor@kernel.org>,
"Daniel Henrique Barboza" <daniel.barboza@oss.qualcomm.com>,
"Edgar E. Iglesias" <edgar.iglesias@gmail.com>,
"Fabiano Rosas" <farosas@suse.de>,
"Laurent Vivier" <lvivier@redhat.com>,
"Liu Zhiwei" <zhiwei_liu@linux.alibaba.com>,
"Markus Armbruster" <armbru@redhat.com>,
"Palmer Dabbelt" <palmer@dabbelt.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Peter Maydell" <peter.maydell@linaro.org>,
"Philippe Mathieu-Daudé" <philmd@oss.qualcomm.com>,
"Pierrick Bouvier" <pierrick.bouvier@oss.qualcomm.com>,
"Sebastian Huber" <sebastian.huber@embedded-brains.de>,
"Thomas Huth" <thuth@redhat.com>,
"Weiwei Li" <liwei1518@gmail.com>,
qemu-arm@nongnu.org, qemu-block@nongnu.org,
qemu-riscv@nongnu.org
Subject: [PATCH v2 00/24] hw/riscv: Restore Microchip PolarFire SoC Icicle Kit firmware boot
Date: Fri, 4 Sep 2026 23:57:19 +0800 [thread overview]
Message-ID: <20260904155758.3833179-1-bin.meng@processmission.com> (raw)
The microchip-icicle-kit machine was originally validated with an older
Hart Software Services (HSS) firmware stack. HSS v2024.06 cannot boot
through U-Boot to Linux because several firmware-visible parts of the
PolarFire SoC are missing or incomplete.
The first failure occurs before the UART is initialized because the L2
zero window is not mapped. HSS then needs additional L2 cache controller
and DDR training behavior. Later boot stages exercise system services,
the RTC, SDHC version 4 DMA, and high-capacity SD card block sizing,
along with the complete DDR aliases. The existing models ither reject
these accesses or expose behavior that does not match the hardware
specifications.
This series restores the complete firmware boot flow. With these
changes, QEMU boots the HSS v2024.06 eNVM image, loads its U-Boot
payload from an SD card, and reaches the Buildroot 2026.05 Linux
login prompt.
The changes are organized around the firmware boot sequence:
* Correct the L2-LIM size, map the L2 zero window, and provide the DMC
status transitions required by HSS DDR initialization.
* Model the documented L2CC Config, WayEnable, and WayMask registers,
and resize L2-LIM as cache ways are enabled.
* Complete SDHCI version 4 support used by the Cadence controller,
including Host Control 2, SDMA system addressing, 64-bit ADMA2
descriptors, and SDMA boundary continuation.
* Run ADMA from a bounded timer-driven engine instead of performing work
from command or unrelated MMIO accesses. This keeps DMA progress
independent of guest register traffic and avoids consuming a polling
deadline inside the command write.
* Keep SDHC and SDXC memory transfers at their fixed 512-byte block
size, and advertise the Cadence controller's 64-bit system bus
support.
* Add the PolarFire SoC serial-number system service and RTC, and honor
the system-service notification control bit.
* Correct the DDR aliases and fix the board topology at its physical
configuration of 2 GiB of RAM and five harts.
* Document direct and HSS boot, add focused qtests and a full firmware
functional test, and restore the machine's Supported maintainer
status.
Testing performed:
* Built qemu-system-riscv64 and the documentation.
* Passed various newly added qtests.
* Booted HSS v2024.06, U-Boot, and Buildroot 2026.05 Linux to the login
prompt using the functional-test image.
The functional test downloads this versioned image archive:
https://github.com/processmission/qemu-machine-images/releases/download/
v1.0.0/riscv64-microchip-icicle-kit-v1.0.0.tar.zst
When restoring the HSS boot support, 3 potential bugs were identified in
the upstream HSS source codes that either blocks the DDR training from
succeed or traps in a multi-core race at the very beginning or after
a succesfully DDR training but stuck at OpenSBI/U-Boot hand-off. There
are already bug reports filed aginst various upstream projects.
Changes in v2:
- Use the Resettable API instead of a legacy reset handler
- tests/qtest: add Cadence SDHCI ADMA pacing/MMIO reproducer
- Assert bounded ADMA pacing and MMIO-independent progress
- Reuse existing SDHCI definitions and command helpers
- Verify transferred data against a known image pattern
- Make 64-bit system bus support a device property
- hw/riscv: pfsoc: Enable 64-bit SDHCI system bus support
- Reset the RTC to the documented hardware values
- Expect the documented hardware state after RTC reset
- MAINTAINERS: Move Conor Dooley to PolarFire SoC reviewer
- Drop sdhci patches that are already merged
Bin Meng (23):
hw/riscv: pfsoc: Correct the L2LIM maximum mapped size
hw/riscv: pfsoc: Map the L2 zero device window
hw/misc: pfsoc: Support DDR training with newer HSS
hw/misc: pfsoc: Model L2 cache controller registers
hw/riscv: pfsoc: Couple L2CC to L2-LIM
tests/qtest: Add PolarFire SoC L2CC coverage
hw/sd: sdhci: Run ADMA independently of MMIO
hw/sd: sd: Keep high-capacity memory blocks at 512 bytes
hw/sd: cadence: Add 64-bit system bus property
hw/riscv: pfsoc: Enable 64-bit SDHCI system bus support
hw/misc: pfsoc: Model PolarFire SoC serial number service
hw/rtc: Add PolarFire SoC RTC model
hw/riscv: pfsoc: Add PolarFire SoC RTC to Icicle Kit
tests/qtest: Add PolarFire SoC RTC coverage
hw/misc: pfsoc: Honor PolarFire service notification requests
hw/riscv: pfsoc: Correct PolarFire SoC DDR aliases
hw/riscv: pfsoc: Fix Icicle Kit RAM size at 2 GiB
hw/riscv: pfsoc: Fix Icicle Kit hart count at five
docs/system/riscv: Document Icicle Kit HSS boot
docs/system/riscv: pfsoc: Document CLINT topology for direct Linux
boot
tests/functional/riscv64: Add Icicle Kit firmware boot test
MAINTAINERS: Add PolarFire SoC Icicle Kit maintainer
MAINTAINERS: Move Conor Dooley to PolarFire SoC reviewer
Wadim Mueller (1):
tests/qtest: add Cadence SDHCI ADMA pacing/MMIO reproducer
MAINTAINERS | 13 +-
docs/system/riscv/microchip-icicle-kit.rst | 129 ++++-
include/hw/misc/mchp_pfsoc_dmc.h | 6 +
include/hw/misc/mchp_pfsoc_ioscb.h | 8 +
include/hw/misc/mchp_pfsoc_l2cc.h | 31 ++
include/hw/riscv/microchip_pfsoc.h | 7 +
include/hw/rtc/mchp_pfsoc_rtc.h | 46 ++
include/hw/sd/cadence_sdhci.h | 1 +
hw/misc/mchp_pfsoc_dmc.c | 273 +++++++++-
hw/misc/mchp_pfsoc_ioscb.c | 174 ++++++-
hw/misc/mchp_pfsoc_l2cc.c | 231 +++++++++
hw/misc/mchp_pfsoc_sysreg.c | 9 +-
hw/riscv/microchip_pfsoc.c | 94 ++--
hw/rtc/mchp_pfsoc_rtc.c | 477 ++++++++++++++++++
hw/sd/cadence_sdhci.c | 11 +
hw/sd/sd.c | 43 +-
hw/sd/sdhci.c | 143 ++++--
tests/qtest/cadence-sdhci-test.c | 282 +++++++++++
tests/qtest/mchp_pfsoc_l2cc_test.c | 221 ++++++++
tests/qtest/mchp_pfsoc_rtc_test.c | 315 ++++++++++++
hw/misc/Kconfig | 3 +
hw/misc/meson.build | 1 +
hw/riscv/Kconfig | 2 +
hw/rtc/Kconfig | 3 +
hw/rtc/meson.build | 1 +
tests/functional/riscv64/meson.build | 2 +
.../riscv64/test_microchip_icicle_kit.py | 56 ++
tests/qtest/meson.build | 6 +
28 files changed, 2429 insertions(+), 159 deletions(-)
create mode 100644 include/hw/misc/mchp_pfsoc_l2cc.h
create mode 100644 include/hw/rtc/mchp_pfsoc_rtc.h
create mode 100644 hw/misc/mchp_pfsoc_l2cc.c
create mode 100644 hw/rtc/mchp_pfsoc_rtc.c
create mode 100644 tests/qtest/cadence-sdhci-test.c
create mode 100644 tests/qtest/mchp_pfsoc_l2cc_test.c
create mode 100644 tests/qtest/mchp_pfsoc_rtc_test.c
create mode 100644 tests/functional/riscv64/test_microchip_icicle_kit.py
---
base-commit: d2843fbf80260e4346c856819e8cea11768c9d0e
branch: icicle-kit
--
2.53.0
next reply other threads:[~2026-09-04 15:58 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 15:57 Bin Meng [this message]
2026-09-04 15:57 ` [PATCH v2 01/24] hw/riscv: pfsoc: Correct the L2LIM maximum mapped size Bin Meng
2026-09-04 15:57 ` [PATCH v2 02/24] hw/riscv: pfsoc: Map the L2 zero device window Bin Meng
2026-09-04 15:57 ` [PATCH v2 03/24] hw/misc: pfsoc: Support DDR training with newer HSS Bin Meng
2026-09-04 15:57 ` [PATCH v2 04/24] hw/misc: pfsoc: Model L2 cache controller registers Bin Meng
2026-09-04 15:57 ` [PATCH v2 05/24] hw/riscv: pfsoc: Couple L2CC to L2-LIM Bin Meng
2026-09-04 15:57 ` [PATCH v2 06/24] tests/qtest: Add PolarFire SoC L2CC coverage Bin Meng
2026-09-04 15:57 ` [PATCH v2 07/24] hw/sd: sdhci: Run ADMA independently of MMIO Bin Meng
2026-09-04 15:57 ` [PATCH v2 08/24] tests/qtest: add Cadence SDHCI ADMA pacing/MMIO reproducer Bin Meng
2026-09-04 15:57 ` [PATCH v2 09/24] hw/sd: sd: Keep high-capacity memory blocks at 512 bytes Bin Meng
2026-09-04 15:57 ` [PATCH v2 10/24] hw/sd: cadence: Add 64-bit system bus property Bin Meng
2026-09-04 15:57 ` [PATCH v2 11/24] hw/riscv: pfsoc: Enable 64-bit SDHCI system bus support Bin Meng
2026-09-04 15:57 ` [PATCH v2 12/24] hw/misc: pfsoc: Model PolarFire SoC serial number service Bin Meng
2026-09-04 15:57 ` [PATCH v2 13/24] hw/rtc: Add PolarFire SoC RTC model Bin Meng
2026-09-04 15:57 ` [PATCH v2 14/24] hw/riscv: pfsoc: Add PolarFire SoC RTC to Icicle Kit Bin Meng
2026-09-04 15:57 ` [PATCH v2 15/24] tests/qtest: Add PolarFire SoC RTC coverage Bin Meng
2026-09-04 15:57 ` [PATCH v2 16/24] hw/misc: pfsoc: Honor PolarFire service notification requests Bin Meng
2026-09-04 15:57 ` [PATCH v2 17/24] hw/riscv: pfsoc: Correct PolarFire SoC DDR aliases Bin Meng
2026-09-04 15:57 ` [PATCH v2 18/24] hw/riscv: pfsoc: Fix Icicle Kit RAM size at 2 GiB Bin Meng
2026-09-04 15:57 ` [PATCH v2 19/24] hw/riscv: pfsoc: Fix Icicle Kit hart count at five Bin Meng
2026-09-04 15:57 ` [PATCH v2 20/24] docs/system/riscv: Document Icicle Kit HSS boot Bin Meng
2026-09-04 15:57 ` [PATCH v2 21/24] docs/system/riscv: pfsoc: Document CLINT topology for direct Linux boot Bin Meng
2026-09-04 15:57 ` [PATCH v2 22/24] tests/functional/riscv64: Add Icicle Kit firmware boot test Bin Meng
2026-09-04 15:57 ` [PATCH v2 23/24] MAINTAINERS: Add PolarFire SoC Icicle Kit maintainer Bin Meng
2026-09-04 15:57 ` [PATCH v2 24/24] MAINTAINERS: Move Conor Dooley to PolarFire SoC reviewer Bin Meng
2026-09-04 16:11 ` [PATCH v2 00/24] hw/riscv: Restore Microchip PolarFire SoC Icicle Kit firmware boot Philippe Mathieu-Daudé
2026-09-07 13:29 ` Conor Dooley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904155758.3833179-1-bin.meng@processmission.com \
--to=bin.meng@processmission.com \
--cc=alistair.francis@wdc.com \
--cc=alistair@alistair23.me \
--cc=armbru@redhat.com \
--cc=bmeng.cn@gmail.com \
--cc=chao.liu@processmission.com \
--cc=conor@kernel.org \
--cc=daniel.barboza@oss.qualcomm.com \
--cc=edgar.iglesias@gmail.com \
--cc=farosas@suse.de \
--cc=liwei1518@gmail.com \
--cc=lvivier@redhat.com \
--cc=palmer@dabbelt.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=philmd@oss.qualcomm.com \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=qemu-riscv@nongnu.org \
--cc=sebastian.huber@embedded-brains.de \
--cc=thuth@redhat.com \
--cc=zhiwei_liu@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.