xref: /rk3399_ARM-atf/bl31/aarch64/ea_delegate.S (revision 1d6d6802dd547c8b378a9a47572ee72e68cceb3b)
1df8f3188SJeenu Viswambharan/*
297215e0fSDaniel Boulby * Copyright (c) 2018-2022, ARM Limited and Contributors. All rights reserved.
3df56e9d1SVarun Wadekar * Copyright (c) 2022, NVIDIA Corporation. All rights reserved.
4df8f3188SJeenu Viswambharan *
5df8f3188SJeenu Viswambharan * SPDX-License-Identifier: BSD-3-Clause
6df8f3188SJeenu Viswambharan */
7df8f3188SJeenu Viswambharan
8df8f3188SJeenu Viswambharan
9d5a23af5SJeenu Viswambharan#include <assert_macros.S>
10df8f3188SJeenu Viswambharan#include <asm_macros.S>
11ee6ff1bbSJeenu Viswambharan#include <assert_macros.S>
1209d40e0eSAntonio Nino Diaz#include <bl31/ea_handle.h>
13df8f3188SJeenu Viswambharan#include <context.h>
1409d40e0eSAntonio Nino Diaz#include <lib/extensions/ras_arch.h>
1580942622Slaurenw-arm#include <cpu_macros.S>
1680942622Slaurenw-arm#include <context.h>
17df8f3188SJeenu Viswambharan
18df8f3188SJeenu Viswambharan	.globl	handle_lower_el_ea_esb
196f7de9a8SManish Pandey	.globl	handle_lower_el_sync_ea
20c2d32a5fSMadhukar Pappireddy	.globl	handle_lower_el_async_ea
21df8f3188SJeenu Viswambharan
22df8f3188SJeenu Viswambharan
23df8f3188SJeenu Viswambharan/*
24df8f3188SJeenu Viswambharan * Function to delegate External Aborts synchronized by ESB instruction at EL3
25df8f3188SJeenu Viswambharan * vector entry. This function assumes GP registers x0-x29 have been saved, and
26df8f3188SJeenu Viswambharan * are available for use. It delegates the handling of the EA to platform
27df8f3188SJeenu Viswambharan * handler, and returns only upon successfully handling the EA; otherwise
28df8f3188SJeenu Viswambharan * panics. On return from this function, the original exception handler is
29df8f3188SJeenu Viswambharan * expected to resume.
30df8f3188SJeenu Viswambharan */
31df8f3188SJeenu Viswambharanfunc handle_lower_el_ea_esb
32df8f3188SJeenu Viswambharan	mov	x0, #ERROR_EA_ESB
33df8f3188SJeenu Viswambharan	mrs	x1, DISR_EL1
34df8f3188SJeenu Viswambharan	b	ea_proceed
35df8f3188SJeenu Viswambharanendfunc handle_lower_el_ea_esb
36df8f3188SJeenu Viswambharan
37df8f3188SJeenu Viswambharan
38df8f3188SJeenu Viswambharan/*
39df8f3188SJeenu Viswambharan * This function forms the tail end of Synchronous Exception entry from lower
4080942622Slaurenw-arm * EL, and expects to handle Synchronous External Aborts from lower EL and CPU
4180942622Slaurenw-arm * Implementation Defined Exceptions. If any other kind of exception is detected,
4280942622Slaurenw-arm * then this function reports unhandled exception.
43df8f3188SJeenu Viswambharan *
446f7de9a8SManish Pandey * It delegates the handling of the EA to platform handler, and upon successfully
456f7de9a8SManish Pandey * handling the EA, exits EL3; otherwise panics.
466f7de9a8SManish Pandey *
476f7de9a8SManish Pandey * This function assumes x30 has been saved.
48df8f3188SJeenu Viswambharan */
496f7de9a8SManish Pandeyfunc handle_lower_el_sync_ea
50df8f3188SJeenu Viswambharan	mrs	x30, esr_el3
51df8f3188SJeenu Viswambharan	ubfx	x30, x30, #ESR_EC_SHIFT, #ESR_EC_LENGTH
52df8f3188SJeenu Viswambharan
53df8f3188SJeenu Viswambharan	/* Check for I/D aborts from lower EL */
54df8f3188SJeenu Viswambharan	cmp	x30, #EC_IABORT_LOWER_EL
55df8f3188SJeenu Viswambharan	b.eq	1f
56df8f3188SJeenu Viswambharan
57df8f3188SJeenu Viswambharan	cmp	x30, #EC_DABORT_LOWER_EL
5880942622Slaurenw-arm	b.eq	1f
5980942622Slaurenw-arm
6080942622Slaurenw-arm	/* Save GP registers */
6180942622Slaurenw-arm	stp	x0, x1, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_X0]
6280942622Slaurenw-arm	stp	x2, x3, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_X2]
6380942622Slaurenw-arm	stp	x4, x5, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_X4]
6480942622Slaurenw-arm
6580942622Slaurenw-arm	/* Get the cpu_ops pointer */
6680942622Slaurenw-arm	bl	get_cpu_ops_ptr
6780942622Slaurenw-arm
6880942622Slaurenw-arm	/* Get the cpu_ops exception handler */
6980942622Slaurenw-arm	ldr	x0, [x0, #CPU_E_HANDLER_FUNC]
7080942622Slaurenw-arm
7180942622Slaurenw-arm	/*
7280942622Slaurenw-arm	 * If the reserved function pointer is NULL, this CPU does not have an
7380942622Slaurenw-arm	 * implementation defined exception handler function
7480942622Slaurenw-arm	 */
7580942622Slaurenw-arm	cbz	x0, 2f
7680942622Slaurenw-arm	mrs	x1, esr_el3
7780942622Slaurenw-arm	ubfx	x1, x1, #ESR_EC_SHIFT, #ESR_EC_LENGTH
7880942622Slaurenw-arm	blr	x0
7980942622Slaurenw-arm	b	2f
80df8f3188SJeenu Viswambharan
81df8f3188SJeenu Viswambharan1:
82e290a8fcSAlexei Fedorov	/*
83ed108b56SAlexei Fedorov	 * Save general purpose and ARMv8.3-PAuth registers (if enabled).
84*1d6d6802SBoyan Karatotev	 * Also save PMCR_EL0 and set the PSTATE to a known state.
85e290a8fcSAlexei Fedorov	 */
8697215e0fSDaniel Boulby	bl	prepare_el3_entry
87e290a8fcSAlexei Fedorov
88b86048c4SAntonio Nino Diaz#if ENABLE_PAUTH
89ed108b56SAlexei Fedorov	/* Load and program APIAKey firmware key */
90ed108b56SAlexei Fedorov	bl	pauth_load_bl31_apiakey
91b86048c4SAntonio Nino Diaz#endif
925283962eSAntonio Nino Diaz
93df8f3188SJeenu Viswambharan	/* Setup exception class and syndrome arguments for platform handler */
94df8f3188SJeenu Viswambharan	mov	x0, #ERROR_EA_SYNC
95df8f3188SJeenu Viswambharan	mrs	x1, esr_el3
96bb9549baSJan Dabros	bl	delegate_sync_ea
97df8f3188SJeenu Viswambharan
98bb9549baSJan Dabros	/* el3_exit assumes SP_EL0 on entry */
99bb9549baSJan Dabros	msr	spsel, #MODE_SP_EL0
100bb9549baSJan Dabros	b	el3_exit
101df8f3188SJeenu Viswambharan2:
10280942622Slaurenw-arm	ldp	x0, x1, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_X0]
10380942622Slaurenw-arm	ldp	x2, x3, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_X2]
10480942622Slaurenw-arm	ldp	x4, x5, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_X4]
10580942622Slaurenw-arm
106df8f3188SJeenu Viswambharan	/* Synchronous exceptions other than the above are assumed to be EA */
107df8f3188SJeenu Viswambharan	ldr	x30, [sp, #CTX_GPREGS_OFFSET + CTX_GPREG_LR]
108df8f3188SJeenu Viswambharan	no_ret	report_unhandled_exception
1096f7de9a8SManish Pandeyendfunc handle_lower_el_sync_ea
110df8f3188SJeenu Viswambharan
111df8f3188SJeenu Viswambharan
112df8f3188SJeenu Viswambharan/*
113df8f3188SJeenu Viswambharan * This function handles SErrors from lower ELs.
114df8f3188SJeenu Viswambharan *
1156f7de9a8SManish Pandey * It delegates the handling of the EA to platform handler, and upon successfully
1166f7de9a8SManish Pandey * handling the EA, exits EL3; otherwise panics.
1176f7de9a8SManish Pandey *
1186f7de9a8SManish Pandey * This function assumes x30 has been saved.
119df8f3188SJeenu Viswambharan */
1206f7de9a8SManish Pandeyfunc handle_lower_el_async_ea
121df8f3188SJeenu Viswambharan
122e290a8fcSAlexei Fedorov	/*
123ed108b56SAlexei Fedorov	 * Save general purpose and ARMv8.3-PAuth registers (if enabled).
124*1d6d6802SBoyan Karatotev	 * Also save PMCR_EL0 and set the PSTATE to a known state.
125e290a8fcSAlexei Fedorov	 */
12697215e0fSDaniel Boulby	bl	prepare_el3_entry
127e290a8fcSAlexei Fedorov
128b86048c4SAntonio Nino Diaz#if ENABLE_PAUTH
129ed108b56SAlexei Fedorov	/* Load and program APIAKey firmware key */
130ed108b56SAlexei Fedorov	bl	pauth_load_bl31_apiakey
131b86048c4SAntonio Nino Diaz#endif
1325283962eSAntonio Nino Diaz
133df8f3188SJeenu Viswambharan	/* Setup exception class and syndrome arguments for platform handler */
134df8f3188SJeenu Viswambharan	mov	x0, #ERROR_EA_ASYNC
135df8f3188SJeenu Viswambharan	mrs	x1, esr_el3
136bb9549baSJan Dabros	bl	delegate_async_ea
137bb9549baSJan Dabros
138bb9549baSJan Dabros	/* el3_exit assumes SP_EL0 on entry */
139bb9549baSJan Dabros	msr	spsel, #MODE_SP_EL0
140bb9549baSJan Dabros	b	el3_exit
1416f7de9a8SManish Pandeyendfunc handle_lower_el_async_ea
142df8f3188SJeenu Viswambharan
143df8f3188SJeenu Viswambharan
144df8f3188SJeenu Viswambharan/*
145b56dc2a9SJeenu Viswambharan * Prelude for Synchronous External Abort handling. This function assumes that
146b56dc2a9SJeenu Viswambharan * all GP registers have been saved by the caller.
147b56dc2a9SJeenu Viswambharan *
148b56dc2a9SJeenu Viswambharan * x0: EA reason
149b56dc2a9SJeenu Viswambharan * x1: EA syndrome
150b56dc2a9SJeenu Viswambharan */
151b56dc2a9SJeenu Viswambharanfunc delegate_sync_ea
152b56dc2a9SJeenu Viswambharan#if RAS_EXTENSION
153b56dc2a9SJeenu Viswambharan	/*
154b56dc2a9SJeenu Viswambharan	 * Check for Uncontainable error type. If so, route to the platform
155b56dc2a9SJeenu Viswambharan	 * fatal error handler rather than the generic EA one.
156b56dc2a9SJeenu Viswambharan	 */
157b56dc2a9SJeenu Viswambharan	ubfx    x2, x1, #EABORT_SET_SHIFT, #EABORT_SET_WIDTH
158b56dc2a9SJeenu Viswambharan	cmp     x2, #ERROR_STATUS_SET_UC
159b56dc2a9SJeenu Viswambharan	b.ne    1f
160b56dc2a9SJeenu Viswambharan
161b56dc2a9SJeenu Viswambharan	/* Check fault status code */
162b56dc2a9SJeenu Viswambharan	ubfx    x3, x1, #EABORT_DFSC_SHIFT, #EABORT_DFSC_WIDTH
163b56dc2a9SJeenu Viswambharan	cmp     x3, #SYNC_EA_FSC
164b56dc2a9SJeenu Viswambharan	b.ne    1f
165b56dc2a9SJeenu Viswambharan
166b56dc2a9SJeenu Viswambharan	no_ret  plat_handle_uncontainable_ea
167b56dc2a9SJeenu Viswambharan1:
168b56dc2a9SJeenu Viswambharan#endif
169b56dc2a9SJeenu Viswambharan
170b56dc2a9SJeenu Viswambharan	b       ea_proceed
171b56dc2a9SJeenu Viswambharanendfunc delegate_sync_ea
172b56dc2a9SJeenu Viswambharan
173b56dc2a9SJeenu Viswambharan
174b56dc2a9SJeenu Viswambharan/*
175b56dc2a9SJeenu Viswambharan * Prelude for Asynchronous External Abort handling. This function assumes that
176b56dc2a9SJeenu Viswambharan * all GP registers have been saved by the caller.
177b56dc2a9SJeenu Viswambharan *
178b56dc2a9SJeenu Viswambharan * x0: EA reason
179b56dc2a9SJeenu Viswambharan * x1: EA syndrome
180b56dc2a9SJeenu Viswambharan */
181b56dc2a9SJeenu Viswambharanfunc delegate_async_ea
182b56dc2a9SJeenu Viswambharan#if RAS_EXTENSION
183d435238dSManish Pandey	/* Check Exception Class to ensure SError, as this function should
184d435238dSManish Pandey	 * only be invoked for SError. If that is not the case, which implies
185d435238dSManish Pandey	 * either an HW error or programming error, panic.
186d435238dSManish Pandey	 */
187d435238dSManish Pandey	ubfx	x2, x1, #ESR_EC_SHIFT, #ESR_EC_LENGTH
188d435238dSManish Pandey	cmp	x2, EC_SERROR
189bd62ce98SGovindraj Raja	b.ne	el3_panic
190b56dc2a9SJeenu Viswambharan	/*
191b56dc2a9SJeenu Viswambharan	 * Check for Implementation Defined Syndrome. If so, skip checking
192b56dc2a9SJeenu Viswambharan	 * Uncontainable error type from the syndrome as the format is unknown.
193b56dc2a9SJeenu Viswambharan	 */
194b56dc2a9SJeenu Viswambharan	tbnz	x1, #SERROR_IDS_BIT, 1f
195b56dc2a9SJeenu Viswambharan
196d435238dSManish Pandey	/* AET only valid when DFSC is 0x11 */
197d435238dSManish Pandey	ubfx	x2, x1, #EABORT_DFSC_SHIFT, #EABORT_DFSC_WIDTH
198d435238dSManish Pandey	cmp	x2, #DFSC_SERROR
199d435238dSManish Pandey	b.ne	1f
200d435238dSManish Pandey
201b56dc2a9SJeenu Viswambharan	/*
202b56dc2a9SJeenu Viswambharan	 * Check for Uncontainable error type. If so, route to the platform
203b56dc2a9SJeenu Viswambharan	 * fatal error handler rather than the generic EA one.
204b56dc2a9SJeenu Viswambharan	 */
205d435238dSManish Pandey	ubfx	x3, x1, #EABORT_AET_SHIFT, #EABORT_AET_WIDTH
206d435238dSManish Pandey	cmp	x3, #ERROR_STATUS_UET_UC
207b56dc2a9SJeenu Viswambharan	b.ne	1f
208b56dc2a9SJeenu Viswambharan
209b56dc2a9SJeenu Viswambharan	no_ret	plat_handle_uncontainable_ea
210b56dc2a9SJeenu Viswambharan1:
211b56dc2a9SJeenu Viswambharan#endif
212b56dc2a9SJeenu Viswambharan
213b56dc2a9SJeenu Viswambharan	b	ea_proceed
214b56dc2a9SJeenu Viswambharanendfunc delegate_async_ea
215b56dc2a9SJeenu Viswambharan
216b56dc2a9SJeenu Viswambharan
217b56dc2a9SJeenu Viswambharan/*
218df8f3188SJeenu Viswambharan * Delegate External Abort handling to platform's EA handler. This function
219df8f3188SJeenu Viswambharan * assumes that all GP registers have been saved by the caller.
220df8f3188SJeenu Viswambharan *
221df8f3188SJeenu Viswambharan * x0: EA reason
222df8f3188SJeenu Viswambharan * x1: EA syndrome
223df8f3188SJeenu Viswambharan */
224df8f3188SJeenu Viswambharanfunc ea_proceed
225d5a23af5SJeenu Viswambharan	/*
226d5a23af5SJeenu Viswambharan	 * If the ESR loaded earlier is not zero, we were processing an EA
227d5a23af5SJeenu Viswambharan	 * already, and this is a double fault.
228d5a23af5SJeenu Viswambharan	 */
229d5a23af5SJeenu Viswambharan	ldr	x5, [sp, #CTX_EL3STATE_OFFSET + CTX_ESR_EL3]
230d5a23af5SJeenu Viswambharan	cbz	x5, 1f
231d5a23af5SJeenu Viswambharan	no_ret	plat_handle_double_fault
232d5a23af5SJeenu Viswambharan
233d5a23af5SJeenu Viswambharan1:
234df8f3188SJeenu Viswambharan	/* Save EL3 state */
235df8f3188SJeenu Viswambharan	mrs	x2, spsr_el3
236df8f3188SJeenu Viswambharan	mrs	x3, elr_el3
237df8f3188SJeenu Viswambharan	stp	x2, x3, [sp, #CTX_EL3STATE_OFFSET + CTX_SPSR_EL3]
238df8f3188SJeenu Viswambharan
239df8f3188SJeenu Viswambharan	/*
240df8f3188SJeenu Viswambharan	 * Save ESR as handling might involve lower ELs, and returning back to
241df8f3188SJeenu Viswambharan	 * EL3 from there would trample the original ESR.
242df8f3188SJeenu Viswambharan	 */
243df8f3188SJeenu Viswambharan	mrs	x4, scr_el3
244df8f3188SJeenu Viswambharan	mrs	x5, esr_el3
245df8f3188SJeenu Viswambharan	stp	x4, x5, [sp, #CTX_EL3STATE_OFFSET + CTX_SCR_EL3]
246df8f3188SJeenu Viswambharan
247df8f3188SJeenu Viswambharan	/*
248df8f3188SJeenu Viswambharan	 * Setup rest of arguments, and call platform External Abort handler.
249df8f3188SJeenu Viswambharan	 *
250df8f3188SJeenu Viswambharan	 * x0: EA reason (already in place)
251df8f3188SJeenu Viswambharan	 * x1: Exception syndrome (already in place).
252df8f3188SJeenu Viswambharan	 * x2: Cookie (unused for now).
253df8f3188SJeenu Viswambharan	 * x3: Context pointer.
254df8f3188SJeenu Viswambharan	 * x4: Flags (security state from SCR for now).
255df8f3188SJeenu Viswambharan	 */
256df8f3188SJeenu Viswambharan	mov	x2, xzr
257df8f3188SJeenu Viswambharan	mov	x3, sp
258df8f3188SJeenu Viswambharan	ubfx	x4, x4, #0, #1
259df8f3188SJeenu Viswambharan
260df8f3188SJeenu Viswambharan	/* Switch to runtime stack */
261df8f3188SJeenu Viswambharan	ldr	x5, [sp, #CTX_EL3STATE_OFFSET + CTX_RUNTIME_SP]
262ed108b56SAlexei Fedorov	msr	spsel, #MODE_SP_EL0
263df8f3188SJeenu Viswambharan	mov	sp, x5
264df8f3188SJeenu Viswambharan
265df8f3188SJeenu Viswambharan	mov	x29, x30
266ee6ff1bbSJeenu Viswambharan#if ENABLE_ASSERTIONS
267ee6ff1bbSJeenu Viswambharan	/* Stash the stack pointer */
268ee6ff1bbSJeenu Viswambharan	mov	x28, sp
269ee6ff1bbSJeenu Viswambharan#endif
270df8f3188SJeenu Viswambharan	bl	plat_ea_handler
271df8f3188SJeenu Viswambharan
272ee6ff1bbSJeenu Viswambharan#if ENABLE_ASSERTIONS
273ee6ff1bbSJeenu Viswambharan	/*
274ee6ff1bbSJeenu Viswambharan	 * Error handling flows might involve long jumps; so upon returning from
275ee6ff1bbSJeenu Viswambharan	 * the platform error handler, validate that the we've completely
276ee6ff1bbSJeenu Viswambharan	 * unwound the stack.
277ee6ff1bbSJeenu Viswambharan	 */
278ee6ff1bbSJeenu Viswambharan	mov	x27, sp
279ee6ff1bbSJeenu Viswambharan	cmp	x28, x27
280ee6ff1bbSJeenu Viswambharan	ASM_ASSERT(eq)
281ee6ff1bbSJeenu Viswambharan#endif
282ee6ff1bbSJeenu Viswambharan
283df8f3188SJeenu Viswambharan	/* Make SP point to context */
284ed108b56SAlexei Fedorov	msr	spsel, #MODE_SP_ELX
285df8f3188SJeenu Viswambharan
286d5a23af5SJeenu Viswambharan	/* Restore EL3 state and ESR */
287df8f3188SJeenu Viswambharan	ldp	x1, x2, [sp, #CTX_EL3STATE_OFFSET + CTX_SPSR_EL3]
288df8f3188SJeenu Viswambharan	msr	spsr_el3, x1
289df8f3188SJeenu Viswambharan	msr	elr_el3, x2
290df8f3188SJeenu Viswambharan
291df8f3188SJeenu Viswambharan	/* Restore ESR_EL3 and SCR_EL3 */
292df8f3188SJeenu Viswambharan	ldp	x3, x4, [sp, #CTX_EL3STATE_OFFSET + CTX_SCR_EL3]
293df8f3188SJeenu Viswambharan	msr	scr_el3, x3
294df8f3188SJeenu Viswambharan	msr	esr_el3, x4
295df8f3188SJeenu Viswambharan
296d5a23af5SJeenu Viswambharan#if ENABLE_ASSERTIONS
297d5a23af5SJeenu Viswambharan	cmp	x4, xzr
298d5a23af5SJeenu Viswambharan	ASM_ASSERT(ne)
299d5a23af5SJeenu Viswambharan#endif
300d5a23af5SJeenu Viswambharan
301d5a23af5SJeenu Viswambharan	/* Clear ESR storage */
302d5a23af5SJeenu Viswambharan	str	xzr, [sp, #CTX_EL3STATE_OFFSET + CTX_ESR_EL3]
303d5a23af5SJeenu Viswambharan
304d5a23af5SJeenu Viswambharan	ret	x29
305df8f3188SJeenu Viswambharanendfunc ea_proceed
306