From: Michal Orzel <michal.orzel@amd.com>
To: Julien Grall <julien@xen.org>, <xen-devel@lists.xenproject.org>
Cc: Stefano Stabellini <sstabellini@kernel.org>,
Bertrand Marquis <bertrand.marquis@arm.com>,
Volodymyr Babchuk <Volodymyr_Babchuk@epam.com>,
<ayankuma@amd.com>
Subject: Re: [PATCH 2/2] xen/arm: Add support for booting gzip compressed uImages
Date: Wed, 1 Feb 2023 12:01:32 +0100 [thread overview]
Message-ID: <7c09b900-6568-e57d-3256-2cf72a73690c@amd.com> (raw)
In-Reply-To: <f45dfe55-ca51-7aa0-ef9a-2788cfead470@xen.org>
Hi Julien,
On 01/02/2023 11:13, Julien Grall wrote:
>
>
> On 01/02/2023 09:48, Michal Orzel wrote:
>> Hi Julien,
>
> Hi Michal,
>
>>
>> On 31/01/2023 21:20, Julien Grall wrote:
>>>
>>>
>>> Hi,
>>>
>>> On 31/01/2023 15:13, Michal Orzel wrote:
>>>> At the moment, Xen does not support booting gzip compressed uImages.
>>>> This is because we are trying to decompress the kernel before probing
>>>> the u-boot header. This leads to a failure as the header always appears
>>>> at the top of the image (and therefore obscuring the gzip header).
>>>>
>>>> Move the call to kernel_uimage_probe before kernel_decompress and make
>>>> the function self-containing by taking the following actions:
>>>> - take a pointer to struct bootmodule as a parameter,
>>>> - check the comp field of a u-boot header to determine compression type,
>>>> - in case of compressed image, modify boot module start address and size
>>>> by taking the header size into account and call kernel_decompress,
>>>> - set up zimage.{kernel_addr,len} accordingly,
>>>> - return -ENOENT in case of a u-boot header not found to distinguish it
>>>> amongst other return values and make it the only case for falling
>>>> through to try to probe other image types.
>>>>
>>>> This is done to avoid splitting the uImage probing into 2 stages (executed
>>>> before and after decompression) which otherwise would be necessary to
>>>> properly update boot module start and size before decompression and
>>>> zimage.{kernel_addr,len} afterwards.
>>>
>>> AFAIU, it would be possible to have a zImage/Image header embedded in
>>> the uImage. So any reason to only handle a compressed binary?
>> Not sure if I understand you correctly as what you say is already supported.
>> The split or moving decompression is only needed in case of compressed uImage,
>> as u-boot header (not being part of compression) appears before gzip header.
>> This is not the case for zImage/Image header that is embedded into image
>> and gzip header is at the top.
>
> [...]
>
>>
>> In case of uImage added on top of zImage/Image, the load address/entry point are taken
>> from uImage header so basically the zImage/Image header is not parsed (this is
>> documented in our booting.txt).
>
> This is the case I am talking about. I think we need to parrse
> zImage/Image because it may contain additional information about the
> placement (for instance Image has a field to indicate the real size in
> memory).
As it was said during discussion on Ayan's patch, adding u-boot header on top of zImage/Image
is not a common behavior and the purpose is questionable. Also I've never heard of any SW
that would parse both headers. After all that is why u-boot has booti (Image), bootz (zImage)
and bootm (uImage) commands. When using bootm to load Image/zImage with u-boot header, u-boot
does not read the Image/zImage header but only u-boot header (this is what Xen does at the moment
and was writeen by Ayan in documentation). If we really decide to do such a step (quite innovative :))
I would prefer not to do this in this series as the goals are different. This series is to remove
the known Xen limitation.
>
>>
>> This patch makes the uImage compression works as the other combinations work fine already.
>> You can boot what you can already:
>> - zImage/Image
>> - compressed zImage/Image
>> - zImage/Image,raw with u-boot header
>> + this patch allows to boot:
>> - compressed uImage (i.e. zImage/Image/raw compressed with u-boot header)
>>
>>>
>>>>
>>>> Remove the limitation from the booting.txt documentation.
>>>>
>>>> Signed-off-by: Michal Orzel <michal.orzel@amd.com>
>>>> ---
>>>> docs/misc/arm/booting.txt | 3 ---
>>>> xen/arch/arm/kernel.c | 51 ++++++++++++++++++++++++++++++++++-----
>>>> 2 files changed, 45 insertions(+), 9 deletions(-)
>>>>
>>>> diff --git a/docs/misc/arm/booting.txt b/docs/misc/arm/booting.txt
>>>> index bd7bfe7f284a..02f7bb65ec6d 100644
>>>> --- a/docs/misc/arm/booting.txt
>>>> +++ b/docs/misc/arm/booting.txt
>>>> @@ -50,9 +50,6 @@ Also, it is to be noted that if user provides the legacy image header on
>>>> top of zImage or Image header, then Xen uses the attributes of legacy
>>>> image header to determine the load address, entry point, etc.
>>>>
>>>> -Known limitation: compressed kernels with a uboot headers are not
>>>> -working.
>>>> -
>>>>
>>>> Firmware/bootloader requirements
>>>> --------------------------------
>>>> diff --git a/xen/arch/arm/kernel.c b/xen/arch/arm/kernel.c
>>>> index 068fbf88e492..ea5f9618169e 100644
>>>> --- a/xen/arch/arm/kernel.c
>>>> +++ b/xen/arch/arm/kernel.c
>>>> @@ -265,11 +265,14 @@ static __init int kernel_decompress(struct bootmodule *mod)
>>>> #define IH_ARCH_ARM 2 /* ARM */
>>>> #define IH_ARCH_ARM64 22 /* ARM64 */
>>>>
>>>> +/* uImage Compression Types */
>>>> +#define IH_COMP_GZIP 1
>>>> +
>>>> /*
>>>> * Check if the image is a uImage and setup kernel_info
>>>> */
>>>> static int __init kernel_uimage_probe(struct kernel_info *info,
>>>> - paddr_t addr, paddr_t size)
>>>> + struct bootmodule *mod)
>>>> {
>>>> struct {
>>>> __be32 magic; /* Image Header Magic Number */
>>>> @@ -287,6 +290,8 @@ static int __init kernel_uimage_probe(struct kernel_info *info,
>>>> } uimage;
>>>>
>>>> uint32_t len;
>>>> + paddr_t addr = mod->start;
>>>> + paddr_t size = mod->size;
>>>>
>>>> if ( size < sizeof(uimage) )
>>>> return -EINVAL;
>>>> @@ -294,13 +299,21 @@ static int __init kernel_uimage_probe(struct kernel_info *info,
>>>> copy_from_paddr(&uimage, addr, sizeof(uimage));
>>>>
>>>> if ( be32_to_cpu(uimage.magic) != UIMAGE_MAGIC )
>>>> - return -EINVAL;
>>>> + return -ENOENT;
>>>>
>>>> len = be32_to_cpu(uimage.size);
>>>>
>>>> if ( len > size - sizeof(uimage) )
>>>> return -EINVAL;
>>>>
>>>> + /* Only gzip compression is supported. */
>>>> + if ( uimage.comp && uimage.comp != IH_COMP_GZIP )
>>>> + {
>>>> + printk(XENLOG_ERR
>>>> + "Unsupported uImage compression type %"PRIu8"\n", uimage.comp);
>>>> + return -EOPNOTSUPP;
>>>> + }
>>>> +
>>>> info->zimage.start = be32_to_cpu(uimage.load);
>>>> info->entry = be32_to_cpu(uimage.ep);
>>>>
>>>> @@ -330,8 +343,26 @@ static int __init kernel_uimage_probe(struct kernel_info *info,
>>>> return -EINVAL;
>>>> }
>>>>
>>>> - info->zimage.kernel_addr = addr + sizeof(uimage);
>>>> - info->zimage.len = len;
>>>> + if ( uimage.comp )
>>>> + {
>>>> + int rc;
>>>> +
>>>> + /* Prepare start and size for decompression. */
>>>> + mod->start += sizeof(uimage);
>>>> + mod->size -= sizeof(uimage);
>>>
>>> kernel_decompress() will free the compressed module once it is
>>> decompressed. By updating the region it means the free page will be not
>>> be freed (assuming start was previously page-aligned).
>> Ok, so the start address was previously page-aligned and by adding the uimage size
>> to it, it is no longer aligned. True. Do I understand you correctly that you refer
>> to the fw_unreserved_regions call from kernel_decompress where we will pass unaligned
>> address?
>
> Correct.
>
>> This could be solved by doing (not harmful in my opinion for common case)
>> addr &= PAGE_MASK.
> I don't quite understand your argument here. We need a check that work
> for everyone (not only in the common case).
As we assume the kernel module is at page aligned address (otherwise the issue you observed
can happen not only in uImage compressed case), having a check like
this is generic. I.e. for normal usecase (no uImage compressed), addr &= PAGE_MASK
does not modify the address. For uImage compressed usecase it causes the addr to get
back to the previous value (before we added header size to it).
Apart from the addr, we need to pass the correct size (as we extracted header size from it).
We could have the following (with appropriate comment):
size += addr - (addr & PAGE_MASK);
addr &= PAGE_MASK;
fw_unreserved_regions(addr, addr + size, init_domheap_pages, 0);
It does not look great but solves the uImage issue and does not modify
the previous behavior. Anyway, I'm open for suggestions.
>
> Cheers,
>
> --
> Julien Grall
~Michal
next prev parent reply other threads:[~2023-02-01 11:02 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-01-31 15:13 [PATCH 0/2] xen/arm: Support compressed uImages Michal Orzel
2023-01-31 15:13 ` [PATCH 1/2] xen/arm: Move kernel_uimage_probe definition after kernel_decompress Michal Orzel
2023-01-31 19:07 ` Ayan Kumar Halder
2023-01-31 19:54 ` Julien Grall
2023-01-31 15:13 ` [PATCH 2/2] xen/arm: Add support for booting gzip compressed uImages Michal Orzel
2023-01-31 19:06 ` Ayan Kumar Halder
2023-01-31 20:20 ` Julien Grall
2023-02-01 9:48 ` Michal Orzel
2023-02-01 10:13 ` Julien Grall
2023-02-01 11:01 ` Michal Orzel [this message]
2023-02-01 11:20 ` Julien Grall
2023-02-01 12:56 ` Michal Orzel
2023-02-01 18:54 ` Julien Grall
2023-02-02 8:06 ` Michal Orzel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7c09b900-6568-e57d-3256-2cf72a73690c@amd.com \
--to=michal.orzel@amd.com \
--cc=Volodymyr_Babchuk@epam.com \
--cc=ayankuma@amd.com \
--cc=bertrand.marquis@arm.com \
--cc=julien@xen.org \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.