From: Bin Meng <bin.meng@processmission.com>
To: QEMU <qemu-devel@nongnu.org>
Cc: qemu-arm@nongnu.org
Subject: [PATCH v2 10/32] hw/misc: Add Phytium E2000 MHU doorbell
Date: Tue, 8 Sep 2026 18:41:19 +0800 [thread overview]
Message-ID: <20260908104159.1621764-11-bin.meng@processmission.com> (raw)
In-Reply-To: <20260908104159.1621764-1-bin.meng@processmission.com>
Add a model for the E2000 AP OS MHU channel used by vendor firmware.
Model its status, set and clear registers and complete nonzero
notifications by updating the shared SCMI mailbox.
The device also provides the mailbox seeding helper required by
the later PBR handoff. Board address mapping and SCP SRAM ownership
are intentionally left to a following machine-integration commit.
Signed-off-by: Bin Meng <bin.meng@processmission.com>
---
(no changes since v1)
include/hw/misc/phytium_e2000_mhu.h | 25 ++++
hw/misc/phytium_e2000_mhu.c | 185 ++++++++++++++++++++++++++++
hw/misc/meson.build | 1 +
3 files changed, 211 insertions(+)
create mode 100644 include/hw/misc/phytium_e2000_mhu.h
create mode 100644 hw/misc/phytium_e2000_mhu.c
diff --git a/include/hw/misc/phytium_e2000_mhu.h b/include/hw/misc/phytium_e2000_mhu.h
new file mode 100644
index 0000000000..0527d6fe8d
--- /dev/null
+++ b/include/hw/misc/phytium_e2000_mhu.h
@@ -0,0 +1,25 @@
+/*
+ * Phytium E2000 MHU/SCMI doorbell
+ *
+ * Copyright (c) 2026 Process Mission
+ *
+ * Author:
+ * Bin Meng <bin.meng@processmission.com>
+ *
+ * SPDX-License-Identifier: GPL-2.0-or-later
+ */
+
+#ifndef HW_MISC_PHYTIUM_E2000_MHU_H
+#define HW_MISC_PHYTIUM_E2000_MHU_H
+
+#include "hw/core/sysbus.h"
+#include "qom/object.h"
+
+#define TYPE_PHYTIUM_E2000_MHU "phytium-e2000-mhu"
+OBJECT_DECLARE_SIMPLE_TYPE(PhytiumE2000MHUState, PHYTIUM_E2000_MHU)
+
+#define PHYTIUM_E2000_MHU_MMIO_SIZE 0x1000
+
+void phytium_e2000_mhu_seed_mailbox(void);
+
+#endif
diff --git a/hw/misc/phytium_e2000_mhu.c b/hw/misc/phytium_e2000_mhu.c
new file mode 100644
index 0000000000..4ea23af900
--- /dev/null
+++ b/hw/misc/phytium_e2000_mhu.c
@@ -0,0 +1,185 @@
+/*
+ * Phytium E2000 MHU/SCMI doorbell
+ *
+ * This is a boot-oriented SCMI transport proxy. It acknowledges requests in
+ * shared SRAM so PBF can complete clock and platform setup; it is not a full
+ * SCMI protocol server.
+ *
+ * Copyright (c) 2026 Process Mission
+ *
+ * Author:
+ * Bin Meng <bin.meng@processmission.com>
+ *
+ * SPDX-License-Identifier: GPL-2.0-or-later
+ */
+
+#include "qemu/osdep.h"
+#include "hw/misc/phytium_e2000_mhu.h"
+
+#include "hw/core/register.h"
+#include "migration/vmstate.h"
+#include "qemu/module.h"
+#include "system/address-spaces.h"
+
+#define PHYTIUM_E2000_PBF_SCMI_MBOX_BASE 0x32a10400
+#define PHYTIUM_E2000_SCMI_STATUS_OFFSET 0x04
+#define PHYTIUM_E2000_SCMI_LEN_OFFSET 0x14
+#define PHYTIUM_E2000_SCMI_PAYLOAD_OFFSET 0x1c
+#define PHYTIUM_E2000_SCMI_STATUS_FREE BIT(0)
+
+/*
+ * The SDK defines AP OS status/set/clear at 0x100/0x108/0x110 within a
+ * channel. PBF selects the channel at MHU offset 0x200, producing the global
+ * offsets below. Writes to AP_OS_SET are the request notification.
+ */
+REG32(AP_OS_STAT, 0x300)
+REG32(AP_OS_SET, 0x308)
+REG32(AP_OS_CLR, 0x310)
+
+#define PHYTIUM_E2000_MHU_R_MAX \
+ (PHYTIUM_E2000_MHU_MMIO_SIZE / sizeof(uint32_t))
+
+struct PhytiumE2000MHUState {
+ SysBusDevice parent_obj;
+
+ uint32_t regs[PHYTIUM_E2000_MHU_R_MAX];
+ RegisterInfo regs_info[PHYTIUM_E2000_MHU_R_MAX];
+};
+
+static void phytium_e2000_mhu_complete_scmi(void)
+{
+ uint8_t buf[sizeof(uint32_t)];
+ uint32_t len;
+
+ /*
+ * Preserve the caller's message length, but reserve one status word for
+ * the minimal success response returned in the payload.
+ */
+ address_space_read(&address_space_memory,
+ PHYTIUM_E2000_PBF_SCMI_MBOX_BASE +
+ PHYTIUM_E2000_SCMI_LEN_OFFSET,
+ MEMTXATTRS_UNSPECIFIED, buf, sizeof(buf));
+ len = MAX(ldl_le_p(buf), (uint32_t)sizeof(uint32_t));
+
+ stl_le_p(buf, 0);
+ address_space_write(&address_space_memory,
+ PHYTIUM_E2000_PBF_SCMI_MBOX_BASE +
+ PHYTIUM_E2000_SCMI_PAYLOAD_OFFSET,
+ MEMTXATTRS_UNSPECIFIED, buf, sizeof(buf));
+ stl_le_p(buf, len);
+ address_space_write(&address_space_memory,
+ PHYTIUM_E2000_PBF_SCMI_MBOX_BASE +
+ PHYTIUM_E2000_SCMI_LEN_OFFSET,
+ MEMTXATTRS_UNSPECIFIED, buf, sizeof(buf));
+ stl_le_p(buf, PHYTIUM_E2000_SCMI_STATUS_FREE);
+ /*
+ * Publish the free bit last. PBF polls this field as the ownership handoff
+ * and may consume the response immediately after observing it.
+ */
+ address_space_write(&address_space_memory,
+ PHYTIUM_E2000_PBF_SCMI_MBOX_BASE +
+ PHYTIUM_E2000_SCMI_STATUS_OFFSET,
+ MEMTXATTRS_UNSPECIFIED, buf, sizeof(buf));
+}
+
+void phytium_e2000_mhu_seed_mailbox(void)
+{
+ /*
+ * PBR leaves the shared channel available before releasing PBF. Seed the
+ * same ownership and success state even before the first doorbell write.
+ */
+ phytium_e2000_mhu_complete_scmi();
+}
+
+static void phytium_e2000_mhu_doorbell_post_write(RegisterInfo *reg,
+ uint64_t value)
+{
+ /*
+ * Complete requests synchronously because no separate SCP CPU executes in
+ * this model. Zero writes only update doorbell storage.
+ */
+ if (value) {
+ phytium_e2000_mhu_complete_scmi();
+ }
+}
+
+static const RegisterAccessInfo phytium_e2000_mhu_regs_info[] = {
+ /*
+ * The functional transport does not model an SCP interrupt line. STAT is
+ * therefore idle, SET completes the shared-memory transaction, and CLR
+ * remains ordinary register storage for the firmware acknowledge path.
+ */
+ { .name = "AP_OS_STAT", .addr = A_AP_OS_STAT,
+ .ro = UINT32_MAX },
+ { .name = "AP_OS_SET", .addr = A_AP_OS_SET,
+ .post_write = phytium_e2000_mhu_doorbell_post_write },
+ { .name = "AP_OS_CLR", .addr = A_AP_OS_CLR },
+};
+
+static const MemoryRegionOps phytium_e2000_mhu_ops = {
+ .read = register_read_memory,
+ .write = register_write_memory,
+ .endianness = DEVICE_LITTLE_ENDIAN,
+ .valid = {
+ .min_access_size = 4,
+ .max_access_size = 4,
+ .unaligned = false,
+ },
+};
+
+static void phytium_e2000_mhu_reset(DeviceState *dev)
+{
+ PhytiumE2000MHUState *s = PHYTIUM_E2000_MHU(dev);
+ int i;
+
+ for (i = 0; i < ARRAY_SIZE(phytium_e2000_mhu_regs_info); i++) {
+ register_reset(&s->regs_info[
+ phytium_e2000_mhu_regs_info[i].addr / sizeof(uint32_t)]);
+ }
+}
+
+static void phytium_e2000_mhu_init(Object *obj)
+{
+ PhytiumE2000MHUState *s = PHYTIUM_E2000_MHU(obj);
+ RegisterInfoArray *reg_array;
+
+ reg_array = register_init_block32(
+ DEVICE(obj), phytium_e2000_mhu_regs_info,
+ ARRAY_SIZE(phytium_e2000_mhu_regs_info), s->regs_info, s->regs,
+ &phytium_e2000_mhu_ops, false, PHYTIUM_E2000_MHU_MMIO_SIZE);
+ sysbus_init_mmio(SYS_BUS_DEVICE(obj), ®_array->mem);
+}
+
+static const VMStateDescription phytium_e2000_mhu_vmsd = {
+ .name = TYPE_PHYTIUM_E2000_MHU,
+ .version_id = 1,
+ .minimum_version_id = 1,
+ .fields = (const VMStateField[]) {
+ VMSTATE_UINT32_ARRAY(regs, PhytiumE2000MHUState,
+ PHYTIUM_E2000_MHU_R_MAX),
+ VMSTATE_END_OF_LIST()
+ },
+};
+
+static void phytium_e2000_mhu_class_init(ObjectClass *klass, const void *data)
+{
+ DeviceClass *dc = DEVICE_CLASS(klass);
+
+ dc->vmsd = &phytium_e2000_mhu_vmsd;
+ device_class_set_legacy_reset(dc, phytium_e2000_mhu_reset);
+}
+
+static const TypeInfo phytium_e2000_mhu_info = {
+ .name = TYPE_PHYTIUM_E2000_MHU,
+ .parent = TYPE_SYS_BUS_DEVICE,
+ .instance_size = sizeof(PhytiumE2000MHUState),
+ .instance_init = phytium_e2000_mhu_init,
+ .class_init = phytium_e2000_mhu_class_init,
+};
+
+static void phytium_e2000_mhu_register_types(void)
+{
+ type_register_static(&phytium_e2000_mhu_info);
+}
+
+type_init(phytium_e2000_mhu_register_types)
diff --git a/hw/misc/meson.build b/hw/misc/meson.build
index dca5f67ca9..149ec8e797 100644
--- a/hw/misc/meson.build
+++ b/hw/misc/meson.build
@@ -17,6 +17,7 @@ system_ss.add(when: 'CONFIG_INTEGRATOR_DEBUG', if_true: files('arm_integrator_de
system_ss.add(when: 'CONFIG_A9SCU', if_true: files('a9scu.c'))
system_ss.add(when: 'CONFIG_ARM11SCU', if_true: files('arm11scu.c'))
system_ss.add(when: 'CONFIG_PHYTIUM_E2000', if_true: files('phytium_e2000_ddr.c'))
+system_ss.add(when: 'CONFIG_PHYTIUM_E2000', if_true: files('phytium_e2000_mhu.c'))
system_ss.add(when: 'CONFIG_ARM_V7M', if_true: files('armv7m_ras.c'))
--
2.53.0
next prev parent reply other threads:[~2026-09-08 10:43 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 10:41 [PATCH v2 00/32] hw/arm: Add Phytium E2000Q SoC and board support Bin Meng
2026-09-08 10:41 ` [PATCH v2 01/32] hw/arm: Add Phytium E2000 SoC and Phytium Pi machine Bin Meng
2026-09-08 10:41 ` [PATCH v2 02/32] hw/arm: phytium: Add Phytium E2000 PCIe host Bin Meng
2026-09-08 10:41 ` [PATCH v2 03/32] hw/sd: Add Synopsys DesignWare MCI controller Bin Meng
2026-09-08 10:41 ` [PATCH v2 04/32] hw/sd: Add Phytium E2000 " Bin Meng
2026-09-08 10:41 ` [PATCH v2 05/32] hw/arm: phytium: Connect Phytium E2000 MCI controllers Bin Meng
2026-09-08 10:41 ` [PATCH v2 06/32] tests/qtest: Add Synopsys DesignWare MCI coverage Bin Meng
2026-09-08 10:41 ` [PATCH v2 07/32] hw/arm: phytium: Connect Phytium E2000 GEM controllers Bin Meng
2026-09-08 10:41 ` [PATCH v2 08/32] hw/misc: Add Phytium E2000 DDR controller Bin Meng
2026-09-08 10:41 ` [PATCH v2 09/32] hw/arm: phytium: Connect the " Bin Meng
2026-09-08 10:41 ` Bin Meng [this message]
2026-09-08 10:41 ` [PATCH v2 11/32] hw/arm: phytium: Connect the Phytium E2000 MHU Bin Meng
2026-09-08 10:41 ` [PATCH v2 12/32] hw/ssi: Add Phytium E2000 QSPI controller Bin Meng
2026-09-08 10:41 ` [PATCH v2 13/32] hw/arm: phytium: Connect the " Bin Meng
2026-09-08 10:41 ` [PATCH v2 14/32] hw/misc: Add Phytium E2000 PBR model Bin Meng
2026-09-08 10:41 ` [PATCH v2 15/32] hw/arm: phytium: Integrate the Phytium E2000 PBR Bin Meng
2026-09-08 10:41 ` [PATCH v2 16/32] hw/arm: phytium: Add Phytium E2000 control region placeholders Bin Meng
2026-09-08 10:41 ` [PATCH v2 17/32] hw/misc: Support Phytium E2000 SCMI CPU power control Bin Meng
2026-09-08 10:41 ` [PATCH v2 18/32] hw/arm: phytium: Select the Phytium E2000 PBR boot medium Bin Meng
2026-09-08 10:41 ` [PATCH v2 19/32] hw/arm: phytium: Connect the Phytium E2000 I2C controller Bin Meng
2026-09-08 10:41 ` [PATCH v2 20/32] hw/arm: phytium: Add Phytium E2000 xHCI controllers Bin Meng
2026-09-08 10:41 ` [PATCH v2 21/32] hw/misc: Model the Phytium E2000 random generator Bin Meng
2026-09-08 10:41 ` [PATCH v2 22/32] hw/arm: phytium: Connect " Bin Meng
2026-09-08 10:41 ` [PATCH v2 23/32] hw/arm: phytium: Support Phytium E2000 direct Linux boot Bin Meng
2026-09-08 10:41 ` [PATCH v2 24/32] hw/arm: phytium: Add Phytium E2000Q COMe machine Bin Meng
2026-09-08 10:41 ` [PATCH v2 25/32] hw/block: m25p80: Add GigaDevice GD25Q128 flash Bin Meng
2026-09-08 10:41 ` [PATCH v2 26/32] hw/arm: phytium: Connect the Phytium E2000Q COMe QSPI flash Bin Meng
2026-09-08 10:41 ` [PATCH v2 27/32] hw/arm: phytium: Add Phytium E2000 AHCI controllers Bin Meng
2026-09-08 10:41 ` [PATCH v2 28/32] hw/arm: Add Phytium E2000 Linux SCMI channel Bin Meng
2026-09-08 10:41 ` [PATCH v2 29/32] hw/arm: phytium: Connect the Phytium E2000 SMMUv3 Bin Meng
2026-09-08 10:41 ` [PATCH v2 30/32] docs/system/arm: Document Phytium E2000 machines Bin Meng
2026-09-08 10:41 ` [PATCH v2 31/32] tests/functional/aarch64: Add Phytium Pi boot tests Bin Meng
2026-09-08 10:41 ` [PATCH v2 32/32] MAINTAINERS: Add Phytium E2000Q machines Bin Meng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908104159.1621764-11-bin.meng@processmission.com \
--to=bin.meng@processmission.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.