From: Jon Medhurst (Tixy) <tixy@linaro.org>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH v2] vexpress: disable cci ace slave ports when booting in non-sec/hyp mode
Date: Mon, 26 Sep 2016 13:30:00 +0100 [thread overview]
Message-ID: <1474893000.2898.18.camel@linaro.org> (raw)
In-Reply-To: <1474648719-2910-1-git-send-email-sudeep.holla@arm.com>
On Fri, 2016-09-23 at 17:38 +0100, Sudeep Holla wrote:
> Commit f225d39d3093 ("vexpress: Check TC2 firmware support before defaulting
> to nonsec booting") added support to check if the firmware on TC2 is
> configured appropriately before booting in nonsec/hyp mode.
>
> However when booting in non-secure/hyp mode, CCI control must be done in
> secure firmware and can't be done in non-secure/hyp mode. In order to
> ensure that, this patch disables the cci slave port inteface so that it
> is not accessed at all.
>
> Cc: Jon Medhurst <tixy@linaro.org>
> Acked-by: Marc Zyngier <marc.zyngier@arm.com>
> Signed-off-by: Sudeep Holla <sudeep.holla@arm.com>
> ---
Acked-by: Jon Medhurst <tixy@linaro.org>
Tested-by: Jon Medhurst <tixy@linaro.org>
> board/armltd/vexpress/vexpress_tc2.c | 52 ++++++++++++++++++++++++++++++++++++
> configs/vexpress_ca15_tc2_defconfig | 1 +
> 2 files changed, 53 insertions(+)
>
> Hi,
>
> This change is needed to avoid the kernel panic while attempting to access
> CCI ports when booting in non-sec/HYP mode. The kernel patches to fix
> this are available @[1]
>
> Regards,
> Sudeep
>
> v1->v2:
> - Fix compilation with !CONFIG_ARMV7_NONSEC(Thanks to Tixy)
>
> [1] http://www.spinics.net/lists/arm-kernel/msg533715.html
>
> diff --git a/board/armltd/vexpress/vexpress_tc2.c b/board/armltd/vexpress/vexpress_tc2.c
> index ebb41a8833ab..c7adf950f579 100644
> --- a/board/armltd/vexpress/vexpress_tc2.c
> +++ b/board/armltd/vexpress/vexpress_tc2.c
> @@ -7,7 +7,11 @@
> * SPDX-License-Identifier: GPL-2.0+
> */
>
> +#include <asm/armv7.h>
> #include <asm/io.h>
> +#include <asm/u-boot.h>
> +#include <common.h>
> +#include <libfdt.h>
>
> #define SCC_BASE 0x7fff0000
>
> @@ -31,3 +35,51 @@ bool armv7_boot_nonsec_default(void)
> return (readl((u32 *)(SCC_BASE + 0x700)) & ((1 << 12) | (1 << 13))) == 0;
> #endif
> }
> +
> +#ifdef CONFIG_OF_BOARD_SETUP
> +int ft_board_setup(void *fdt, bd_t *bd)
> +{
> + int offset, tmp, len;
> + const struct fdt_property *prop;
> + const char *cci_compatible = "arm,cci-400-ctrl-if";
> +
> +#ifdef CONFIG_ARMV7_NONSEC
> + if (!armv7_boot_nonsec())
> + return 0;
> +#else
> + return 0;
> +#endif
> + /* Booting in nonsec mode, disable CCI access */
> + offset = fdt_path_offset(fdt, "/cpus");
> + if (offset < 0) {
> + printf("couldn't find /cpus\n");
> + return offset;
> + }
> +
> + /* delete cci-control-port in each cpu node */
> + for (tmp = fdt_first_subnode(fdt, offset); tmp >= 0;
> + tmp = fdt_next_subnode(fdt, tmp))
> + fdt_delprop(fdt, tmp, "cci-control-port");
> +
> + /* disable all ace cci slave ports */
> + offset = fdt_node_offset_by_prop_value(fdt, offset, "compatible",
> + cci_compatible, 20);
> + while (offset > 0) {
> + prop = fdt_get_property(fdt, offset, "interface-type",
> + &len);
> + if (!prop)
> + continue;
> + if (len < 4)
> + continue;
> + if (strcmp(prop->data, "ace"))
> + continue;
> +
> + fdt_setprop_string(fdt, offset, "status", "disabled");
> +
> + offset = fdt_node_offset_by_prop_value(fdt, offset, "compatible",
> + cci_compatible, 20);
> + }
> +
> + return 0;
> +}
> +#endif /* CONFIG_OF_BOARD_SETUP */
> diff --git a/configs/vexpress_ca15_tc2_defconfig b/configs/vexpress_ca15_tc2_defconfig
> index 2f141dda06c6..5154803b7c65 100644
> --- a/configs/vexpress_ca15_tc2_defconfig
> +++ b/configs/vexpress_ca15_tc2_defconfig
> @@ -1,5 +1,6 @@
> CONFIG_ARM=y
> CONFIG_TARGET_VEXPRESS_CA15_TC2=y
> +CONFIG_OF_BOARD_SETUP=y
> CONFIG_HUSH_PARSER=y
> # CONFIG_CMD_CONSOLE is not set
> # CONFIG_CMD_BOOTD is not set
> --
> 2.7.4
>
next prev parent reply other threads:[~2016-09-26 12:30 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-09-23 15:10 [U-Boot] [PATCH] vexpress: disable cci ace slave ports when booting in non-sec/hyp mode Sudeep Holla
2016-09-23 15:27 ` Marc Zyngier
2016-09-23 16:03 ` Jon Medhurst
2016-09-23 16:13 ` Sudeep Holla
2016-09-23 16:38 ` [U-Boot] [PATCH v2] " Sudeep Holla
2016-09-26 11:30 ` Jon Medhurst
2016-09-26 11:35 ` Sudeep Holla
2016-09-26 11:37 ` Sudeep Holla
2016-09-26 12:30 ` Jon Medhurst [this message]
2016-09-26 12:38 ` Sudeep Holla
2016-09-26 13:19 ` Jon Medhurst
2016-09-26 13:24 ` Sudeep Holla
2016-10-08 17:06 ` [U-Boot] [U-Boot, " Tom Rini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1474893000.2898.18.camel@linaro.org \
--to=tixy@linaro.org \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox