From: "Alexandre Courbot" <acourbot@nvidia.com>
To: "John Hubbard" <jhubbard@nvidia.com>
Cc: "Danilo Krummrich" <dakr@kernel.org>,
"Joel Fernandes" <joelagnelf@nvidia.com>,
"Timur Tabi" <ttabi@nvidia.com>,
"Alistair Popple" <apopple@nvidia.com>,
"Eliot Courtney" <ecourtney@nvidia.com>,
"Shashank Sharma" <shashanks@nvidia.com>,
"Zhi Wang" <zhiw@nvidia.com>, "David Airlie" <airlied@gmail.com>,
"Simona Vetter" <simona@ffwll.ch>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Alex Gaynor" <alex.gaynor@gmail.com>,
"Boqun Feng" <boqun.feng@gmail.com>,
"Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
rust-for-linux@vger.kernel.org,
LKML <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH v6 28/34] gpu: nova-core: Hopper/Blackwell: add FSP Chain of Trust boot
Date: Tue, 17 Mar 2026 17:20:50 +0900 [thread overview]
Message-ID: <DH4WT8UFJNN7.1K6B6AP1T0A6@nvidia.com> (raw)
In-Reply-To: <20260310021125.117855-29-jhubbard@nvidia.com>
On Tue Mar 10, 2026 at 11:11 AM JST, John Hubbard wrote:
> Add boot_fmc() which builds and sends the Chain of Trust message to FSP,
> and FmcBootArgs which bundles the DMA-coherent boot parameters that FSP
> reads at boot time. The FspFirmware struct fields become pub(crate) and
> fmc_full changes from DmaObject to KVec<u8> for CPU-side signature
> extraction.
>
> Co-developed-by: Alexandre Courbot <acourbot@nvidia.com>
> Signed-off-by: Alexandre Courbot <acourbot@nvidia.com>
> Signed-off-by: John Hubbard <jhubbard@nvidia.com>
> ---
> drivers/gpu/nova-core/firmware/fsp.rs | 14 ++-
> drivers/gpu/nova-core/fsp.rs | 134 +++++++++++++++++++++++++-
> drivers/gpu/nova-core/gpu.rs | 1 -
> drivers/gpu/nova-core/mctp.rs | 2 -
> 4 files changed, 141 insertions(+), 10 deletions(-)
>
> diff --git a/drivers/gpu/nova-core/firmware/fsp.rs b/drivers/gpu/nova-core/firmware/fsp.rs
> index cea9532ba5ff..bb35f363b998 100644
> --- a/drivers/gpu/nova-core/firmware/fsp.rs
> +++ b/drivers/gpu/nova-core/firmware/fsp.rs
> @@ -13,16 +13,16 @@
> gpu::Chipset, //
> };
>
> -#[expect(unused)]
> +#[expect(dead_code)]
> pub(crate) struct FspFirmware {
> /// FMC firmware image data (only the "image" ELF section).
> - fmc_image: DmaObject,
> + pub(crate) fmc_image: DmaObject,
> /// Full FMC ELF data (for signature extraction).
> - fmc_full: DmaObject,
> + pub(crate) fmc_full: KVec<u8>,
This looks like `fmc_full` should have been a `KVec` since the beginning
- unless I missed something there was no point in keeping it as a
`DmaObject` for a while.
> }
>
> impl FspFirmware {
> - #[expect(unused)]
> + #[expect(dead_code)]
> pub(crate) fn new(
> dev: &device::Device<device::Bound>,
> chipset: Chipset,
> @@ -36,9 +36,13 @@ pub(crate) fn new(
> EINVAL
> })?;
>
> + // Copy the full ELF into a kernel vector for CPU-side signature extraction
> + let mut fmc_full = KVec::with_capacity(fw.data().len(), GFP_KERNEL)?;
> + fmc_full.extend_from_slice(fw.data(), GFP_KERNEL)?;
> +
> Ok(Self {
> fmc_image: DmaObject::from_data(dev, fmc_image_data)?,
> - fmc_full: DmaObject::from_data(dev, fw.data())?,
> + fmc_full,
> })
> }
> }
> diff --git a/drivers/gpu/nova-core/fsp.rs b/drivers/gpu/nova-core/fsp.rs
> index 8926dd814a83..c66ad0a102a6 100644
> --- a/drivers/gpu/nova-core/fsp.rs
> +++ b/drivers/gpu/nova-core/fsp.rs
> @@ -8,8 +8,14 @@
>
> use kernel::{
> device,
> + dma::CoherentAllocation,
> io::poll::read_poll_timeout,
> prelude::*,
> + ptr::{
> + Alignable,
> + Alignment, //
> + },
> + sizes::{SZ_1M, SZ_2M},
Nit: import format. (can't wait for the rustfmt support for that one).
> time::Delta,
> transmute::{
> AsBytes,
> @@ -38,7 +44,6 @@ pub(crate) const fn new(version: u16) -> Self {
> }
>
> /// Return the raw protocol version number for the wire format.
> - #[expect(dead_code)]
> pub(crate) const fn raw(self) -> u16 {
> self.0
> }
> @@ -221,6 +226,73 @@ impl MessageToFsp for FspMessage {
> const NVDM_TYPE: u32 = NvdmType::Cot as u32;
> }
>
> +/// Bundled arguments for FMC boot via FSP Chain of Trust.
> +pub(crate) struct FmcBootArgs<'a> {
> + chipset: crate::gpu::Chipset,
> + fmc_image_fw: &'a crate::dma::DmaObject,
> + fmc_boot_params: kernel::dma::CoherentAllocation<GspFmcBootParams>,
> + resume: bool,
> + signatures: &'a FmcSignatures,
> +}
> +
> +impl<'a> FmcBootArgs<'a> {
> + /// Build FMC boot arguments, allocating the DMA-coherent boot parameter
> + /// structure that FSP will read.
> + #[expect(dead_code)]
> + #[allow(clippy::too_many_arguments)]
> + pub(crate) fn new(
> + dev: &device::Device<device::Bound>,
> + chipset: crate::gpu::Chipset,
> + fmc_image_fw: &'a crate::dma::DmaObject,
> + wpr_meta_addr: u64,
> + wpr_meta_size: u32,
> + libos_addr: u64,
> + resume: bool,
> + signatures: &'a FmcSignatures,
> + ) -> Result<Self> {
> + const GSP_DMA_TARGET_COHERENT_SYSTEM: u32 = 1;
> + const GSP_DMA_TARGET_NONCOHERENT_SYSTEM: u32 = 2;
I see these in OpenRM's
src/nvidia/arch/nvalloc/common/inc/gsp/gspifpub.h - can we add them to
the bindings?
> +
> + let fmc_boot_params = CoherentAllocation::<GspFmcBootParams>::alloc_coherent(
> + dev,
> + 1,
> + GFP_KERNEL | __GFP_ZERO,
> + )?;
> +
> + kernel::dma_write!(
> + fmc_boot_params[0].boot_gsp_rm_params.target = GSP_DMA_TARGET_COHERENT_SYSTEM
> + )?;
Note: on the latest drm-rust-next, this needs to be updated to
kernel::dma_write!(
fmc_boot_params,
[0]?.boot_gsp_rm_params.target,
GSP_DMA_TARGET_COHERENT_SYSTEM
);
(same the those below)
> + kernel::dma_write!(
> + fmc_boot_params[0].boot_gsp_rm_params.gsp_rm_desc_offset = wpr_meta_addr
> + )?;
> + kernel::dma_write!(fmc_boot_params[0].boot_gsp_rm_params.gsp_rm_desc_size = wpr_meta_size)?;
> +
> + // Blackwell FSP expects wpr_carveout_offset and wpr_carveout_size to be zero;
> + // it obtains WPR info from other sources.
> + kernel::dma_write!(fmc_boot_params[0].boot_gsp_rm_params.b_is_gsp_rm_boot = 1)?;
... or better, if we factor these writes into a single one:
kernel::dma_write!(
fmc_boot_params,
[0]?.boot_gsp_rm_params,
GspAcrBootGspRmParams {
target: GSP_DMA_TARGET_COHERENT_SYSTEM,
gsp_rm_desc_offset: wpr_meta_addr,
gsp_rm_desc_size: wpr_meta_size,
..Default::default()
}
);
> +
> + kernel::dma_write!(
> + fmc_boot_params[0].gsp_rm_params.target = GSP_DMA_TARGET_NONCOHERENT_SYSTEM
> + )?;
> + kernel::dma_write!(fmc_boot_params[0].gsp_rm_params.boot_args_offset = libos_addr)?;
Here as well:
kernel::dma_write!(
fmc_boot_params,
[0]?.gsp_rm_params,
GspRmParams {
target: GSP_DMA_TARGET_NONCOHERENT_SYSTEM,
boot_args_offset: libos_addr,
}
);
> +
> + Ok(Self {
> + chipset,
> + fmc_image_fw,
> + fmc_boot_params,
> + resume,
> + signatures,
> + })
> + }
> +
> + /// DMA address of the FMC boot parameters, needed after boot for lockdown
> + /// release polling.
> + #[expect(dead_code)]
> + pub(crate) fn boot_params_dma_handle(&self) -> u64 {
> + self.fmc_boot_params.dma_handle()
> + }
> +}
> +
> /// FSP interface for Hopper/Blackwell GPUs.
> pub(crate) struct Fsp;
>
> @@ -315,8 +387,66 @@ pub(crate) fn extract_fmc_signatures(
> Ok(signatures)
> }
>
> - /// Send message to FSP and wait for response.
> + /// Boot GSP FMC via FSP Chain of Trust.
> + ///
> + /// Builds the COT message from the pre-configured [`FmcBootArgs`], sends it
> + /// to FSP, and waits for the response.
> #[expect(dead_code)]
> + pub(crate) fn boot_fmc(
> + dev: &device::Device<device::Bound>,
> + bar: &crate::driver::Bar0,
> + fsp_falcon: &crate::falcon::Falcon<crate::falcon::fsp::Fsp>,
> + args: &FmcBootArgs<'_>,
> + ) -> Result {
> + dev_dbg!(dev, "Starting FSP boot sequence for {}\n", args.chipset);
> +
> + let fmc_addr = args.fmc_image_fw.dma_handle();
> + let fmc_boot_params_addr = args.fmc_boot_params.dma_handle();
> +
> + // frts_offset is relative to FB end: FRTS_location = FB_END - frts_offset
> + let frts_offset = if !args.resume {
> + let mut frts_reserved_size = crate::fb::calc_non_wpr_heap_size(args.chipset);
> +
> + frts_reserved_size += u64::from(crate::fb::PMU_RESERVED_SIZE);
Let's use a checked operation here.
next prev parent reply other threads:[~2026-03-17 8:21 UTC|newest]
Thread overview: 52+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-10 2:10 [PATCH v6 00/34] gpu: nova-core: firmware: Hopper/Blackwell support John Hubbard
2026-03-10 2:10 ` [PATCH v6 01/34] gpu: nova-core: print FB sizes, along with ranges John Hubbard
2026-03-10 11:21 ` Alexandre Courbot
2026-03-10 2:10 ` [PATCH v6 02/34] gpu: nova-core: add FbRange.len() and use it in boot.rs John Hubbard
2026-03-10 11:21 ` Alexandre Courbot
2026-03-10 2:10 ` [PATCH v6 03/34] gpu: nova-core: Hopper/Blackwell: basic GPU identification John Hubbard
2026-03-10 8:06 ` Alexandre Courbot
2026-03-10 16:54 ` John Hubbard
2026-03-10 2:10 ` [PATCH v6 04/34] gpu: nova-core: factor .fwsignature* selection into a new find_gsp_sigs_section() John Hubbard
2026-03-10 2:10 ` [PATCH v6 05/34] gpu: nova-core: use GPU Architecture to simplify HAL selections John Hubbard
2026-03-10 2:10 ` [PATCH v6 06/34] gpu: nova-core: apply the one "use" item per line policy to commands.rs John Hubbard
2026-03-10 11:21 ` Alexandre Courbot
2026-03-10 2:10 ` [PATCH v6 07/34] gpu: nova-core: move GPU init and DMA mask setup into Gpu::new() John Hubbard
2026-03-10 8:23 ` Alexandre Courbot
2026-03-10 2:10 ` [PATCH v6 08/34] gpu: nova-core: set DMA mask width based on GPU architecture John Hubbard
2026-03-10 2:10 ` [PATCH v6 09/34] gpu: nova-core: Hopper/Blackwell: skip GFW boot waiting John Hubbard
2026-03-10 10:23 ` Alexandre Courbot
2026-03-10 2:11 ` [PATCH v6 10/34] gpu: nova-core: move firmware image parsing code to firmware.rs John Hubbard
2026-03-10 10:28 ` Alexandre Courbot
2026-03-10 2:11 ` [PATCH v6 11/34] gpu: nova-core: factor out an elf_str() function John Hubbard
2026-03-10 2:11 ` [PATCH v6 12/34] gpu: nova-core: don't assume 64-bit firmware images John Hubbard
2026-03-10 10:38 ` Alexandre Courbot
2026-03-10 2:11 ` [PATCH v6 13/34] gpu: nova-core: add support for 32-bit " John Hubbard
2026-03-10 2:11 ` [PATCH v6 14/34] gpu: nova-core: add auto-detection of 32-bit, 64-bit " John Hubbard
2026-03-10 2:11 ` [PATCH v6 15/34] gpu: nova-core: Hopper/Blackwell: add FMC firmware image, in support of FSP John Hubbard
2026-03-10 2:11 ` [PATCH v6 16/34] gpu: nova-core: Hopper/Blackwell: add FSP falcon engine stub John Hubbard
2026-03-10 2:11 ` [PATCH v6 17/34] gpu: nova-core: Hopper/Blackwell: add FSP falcon EMEM operations John Hubbard
2026-03-10 2:11 ` [PATCH v6 18/34] gpu: nova-core: Hopper/Blackwell: add FSP message infrastructure John Hubbard
2026-03-10 10:57 ` Alexandre Courbot
2026-03-11 17:53 ` Timur Tabi
2026-03-10 2:11 ` [PATCH v6 19/34] rust: ptr: add const_align_up() John Hubbard
2026-03-10 2:11 ` [PATCH v6 20/34] gpu: nova-core: Hopper/Blackwell: calculate reserved FB heap size John Hubbard
2026-03-10 2:11 ` [PATCH v6 21/34] gpu: nova-core: add MCTP/NVDM protocol types for firmware communication John Hubbard
2026-03-10 10:53 ` Alexandre Courbot
2026-03-10 2:11 ` [PATCH v6 22/34] gpu: nova-core: Hopper/Blackwell: add FSP secure boot completion waiting John Hubbard
2026-03-10 2:11 ` [PATCH v6 23/34] gpu: nova-core: Hopper/Blackwell: add FSP message structures John Hubbard
2026-03-10 11:01 ` Alexandre Courbot
2026-03-10 2:11 ` [PATCH v6 24/34] gpu: nova-core: Hopper/Blackwell: add FMC signature extraction John Hubbard
2026-03-10 2:11 ` [PATCH v6 25/34] gpu: nova-core: Hopper/Blackwell: add FSP send/receive messaging John Hubbard
2026-03-10 2:11 ` [PATCH v6 26/34] gpu: nova-core: Hopper/Blackwell: add FspCotVersion type John Hubbard
2026-03-10 2:11 ` [PATCH v6 27/34] gpu: nova-core: Hopper/Blackwell: larger non-WPR heap John Hubbard
2026-03-10 2:11 ` [PATCH v6 28/34] gpu: nova-core: Hopper/Blackwell: add FSP Chain of Trust boot John Hubbard
2026-03-17 8:20 ` Alexandre Courbot [this message]
2026-03-10 2:11 ` [PATCH v6 29/34] gpu: nova-core: Blackwell: use correct sysmem flush registers John Hubbard
2026-03-10 2:11 ` [PATCH v6 30/34] gpu: nova-core: Hopper/Blackwell: larger WPR2 (GSP) heap John Hubbard
2026-03-17 8:25 ` Alexandre Courbot
2026-03-10 2:11 ` [PATCH v6 31/34] gpu: nova-core: refactor SEC2 booter loading into BooterFirmware::run() John Hubbard
2026-03-10 2:11 ` [PATCH v6 32/34] gpu: nova-core: Hopper/Blackwell: add GSP lockdown release polling John Hubbard
2026-03-10 2:11 ` [PATCH v6 33/34] gpu: nova-core: Hopper/Blackwell: new location for PCI config mirror John Hubbard
2026-03-17 8:27 ` Alexandre Courbot
2026-03-17 22:17 ` John Hubbard
2026-03-10 2:11 ` [PATCH v6 34/34] gpu: nova-core: Hopper/Blackwell: integrate FSP boot path into boot() John Hubbard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DH4WT8UFJNN7.1K6B6AP1T0A6@nvidia.com \
--to=acourbot@nvidia.com \
--cc=a.hindborg@kernel.org \
--cc=airlied@gmail.com \
--cc=alex.gaynor@gmail.com \
--cc=aliceryhl@google.com \
--cc=apopple@nvidia.com \
--cc=bhelgaas@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=dakr@kernel.org \
--cc=ecourtney@nvidia.com \
--cc=gary@garyguo.net \
--cc=jhubbard@nvidia.com \
--cc=joelagnelf@nvidia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=shashanks@nvidia.com \
--cc=simona@ffwll.ch \
--cc=tmgross@umich.edu \
--cc=ttabi@nvidia.com \
--cc=zhiw@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.