xref: /rk3399_ARM-atf/docs/components/ffa-manifest-binding.rst (revision fd1479d9194d3f3ec98d235e077c9d6e24276fa2)
11b17f4f1SOlivier DeprezFF-A manifest binding to device tree
21b17f4f1SOlivier Deprez========================================
31b17f4f1SOlivier Deprez
41b17f4f1SOlivier DeprezThis document defines the nodes and properties used to define a partition,
51b17f4f1SOlivier Deprezaccording to the FF-A specification.
61b17f4f1SOlivier Deprez
71b17f4f1SOlivier DeprezPartition Properties
879a91381SOlivier Deprez--------------------
91b17f4f1SOlivier Deprez
101b17f4f1SOlivier Deprez- compatible [mandatory]
111b17f4f1SOlivier Deprez   - value type: <string>
121b17f4f1SOlivier Deprez   - Must be the string "arm,ffa-manifest-X.Y" which specifies the major and
131b17f4f1SOlivier Deprez     minor versions of the device tree binding for the FFA manifest represented
141b17f4f1SOlivier Deprez     by this node. The minor number is incremented if the binding changes in a
151b17f4f1SOlivier Deprez     backwards compatible manner.
161b17f4f1SOlivier Deprez
171b17f4f1SOlivier Deprez      - X is an integer representing the major version number of this document.
181b17f4f1SOlivier Deprez      - Y is an integer representing the minor version number of this document.
191b17f4f1SOlivier Deprez
201b17f4f1SOlivier Deprez- ffa-version [mandatory]
211b17f4f1SOlivier Deprez   - value type: <u32>
221b17f4f1SOlivier Deprez   - Must be two 16 bits values (X, Y), concatenated as 31:16 -> X,
231b17f4f1SOlivier Deprez     15:0 -> Y, where:
241b17f4f1SOlivier Deprez
251b17f4f1SOlivier Deprez      - X is the major version of FF-A expected by the partition at the FFA
261b17f4f1SOlivier Deprez        instance it will execute.
271b17f4f1SOlivier Deprez      - Y is the minor version of FF-A expected by the partition at the FFA
281b17f4f1SOlivier Deprez        instance it will execute.
291b17f4f1SOlivier Deprez
301b17f4f1SOlivier Deprez- uuid [mandatory]
311b17f4f1SOlivier Deprez   - value type: <prop-encoded-array>
321b17f4f1SOlivier Deprez   - An array consisting of 4 <u32> values, identifying the UUID of the service
331b17f4f1SOlivier Deprez     implemented by this partition. The UUID format is described in RFC 4122.
341b17f4f1SOlivier Deprez
351b17f4f1SOlivier Deprez- id
361b17f4f1SOlivier Deprez   - value type: <u32>
371b17f4f1SOlivier Deprez   - Pre-allocated partition ID.
381b17f4f1SOlivier Deprez
391b17f4f1SOlivier Deprez- auxiliary-id
401b17f4f1SOlivier Deprez   - value type: <u32>
411b17f4f1SOlivier Deprez   - Pre-allocated ID that could be used in memory management transactions.
421b17f4f1SOlivier Deprez
431b17f4f1SOlivier Deprez- description
441b17f4f1SOlivier Deprez   - value type: <string>
451b17f4f1SOlivier Deprez   - Name of the partition e.g. for debugging purposes.
461b17f4f1SOlivier Deprez
471b17f4f1SOlivier Deprez- execution-ctx-count [mandatory]
481b17f4f1SOlivier Deprez   - value type: <u32>
491b17f4f1SOlivier Deprez   - Number of vCPUs that a VM or SP wants to instantiate.
501b17f4f1SOlivier Deprez
511b17f4f1SOlivier Deprez      - In the absence of virtualization, this is the number of execution
521b17f4f1SOlivier Deprez        contexts that a partition implements.
531b17f4f1SOlivier Deprez      - If value of this field = 1 and number of PEs > 1 then the partition is
541b17f4f1SOlivier Deprez        treated as UP & migrate capable.
551b17f4f1SOlivier Deprez      - If the value of this field > 1 then the partition is treated as a MP
561b17f4f1SOlivier Deprez        capable partition irrespective of the number of PEs.
571b17f4f1SOlivier Deprez
581b17f4f1SOlivier Deprez- exception-level [mandatory]
591b17f4f1SOlivier Deprez   - value type: <u32>
601b17f4f1SOlivier Deprez   - The target exception level for the partition:
611b17f4f1SOlivier Deprez
621b17f4f1SOlivier Deprez      - 0x0: EL1
631b17f4f1SOlivier Deprez      - 0x1: S_EL0
641b17f4f1SOlivier Deprez      - 0x2: S_EL1
651b17f4f1SOlivier Deprez
661b17f4f1SOlivier Deprez- execution-state [mandatory]
671b17f4f1SOlivier Deprez   - value type: <u32>
681b17f4f1SOlivier Deprez   - The target execution state of the partition:
691b17f4f1SOlivier Deprez
701b17f4f1SOlivier Deprez      - 0: AArch64
711b17f4f1SOlivier Deprez      - 1: AArch32
721b17f4f1SOlivier Deprez
731b17f4f1SOlivier Deprez- load-address
741b17f4f1SOlivier Deprez   - value type: <u64>
751b17f4f1SOlivier Deprez   - Physical base address of the partition in memory. Absence of this field
761b17f4f1SOlivier Deprez     indicates that the partition is position independent and can be loaded at
771b17f4f1SOlivier Deprez     any address chosen at boot time.
781b17f4f1SOlivier Deprez
791b17f4f1SOlivier Deprez- entrypoint-offset
801b17f4f1SOlivier Deprez   - value type: <u64>
811b17f4f1SOlivier Deprez   - Offset from the base of the partition's binary image to the entry point of
821b17f4f1SOlivier Deprez     the partition. Absence of this field indicates that the entry point is at
831b17f4f1SOlivier Deprez     offset 0x0 from the base of the partition's binary.
841b17f4f1SOlivier Deprez
851b17f4f1SOlivier Deprez- xlat-granule [mandatory]
861b17f4f1SOlivier Deprez   - value type: <u32>
871b17f4f1SOlivier Deprez   - Translation granule used with the partition:
881b17f4f1SOlivier Deprez
891b17f4f1SOlivier Deprez      - 0x0: 4k
901b17f4f1SOlivier Deprez      - 0x1: 16k
911b17f4f1SOlivier Deprez      - 0x2: 64k
921b17f4f1SOlivier Deprez
931b17f4f1SOlivier Deprez- boot-order
94*fd1479d9SKathleen Capella   - value type: <u16>
951b17f4f1SOlivier Deprez   - A unique number amongst all partitions that specifies if this partition
961b17f4f1SOlivier Deprez     must be booted before others. The partition with the smaller number will be
971b17f4f1SOlivier Deprez     booted first.
981b17f4f1SOlivier Deprez
991b17f4f1SOlivier Deprez- rx-tx-buffer
1001b17f4f1SOlivier Deprez   - value type: "memory-regions" node
1011b17f4f1SOlivier Deprez   - Specific "memory-regions" nodes that describe the RX/TX buffers expected
1021b17f4f1SOlivier Deprez     by the partition.
1031b17f4f1SOlivier Deprez     The "compatible" must be the string "arm,ffa-manifest-rx_tx-buffer".
1041b17f4f1SOlivier Deprez
1051b17f4f1SOlivier Deprez- messaging-method [mandatory]
106bb320dbcSMaksims Svecovs   - value type: <u8>
107bb320dbcSMaksims Svecovs   - Specifies which messaging methods are supported by the partition, set bit
108bb320dbcSMaksims Svecovs     means the feature is supported, clear bit - not supported:
1091b17f4f1SOlivier Deprez
11012349d33SMaksims Svecovs      - Bit[0]: partition can receive direct requests if set
11112349d33SMaksims Svecovs      - Bit[1]: partition can send direct requests if set
11212349d33SMaksims Svecovs      - Bit[2]: partition can send and receive indirect messages
11312349d33SMaksims Svecovs
11412349d33SMaksims Svecovs- managed-exit
11512349d33SMaksims Svecovs   - value type: <empty>
11612349d33SMaksims Svecovs   - Specifies if managed exit is supported.
11710b292e6SMadhukar Pappireddy   - This field is deprecated in favor of ns-interrupts-action field in the FF-A
11810b292e6SMadhukar Pappireddy     v1.1 EAC0 spec.
11910b292e6SMadhukar Pappireddy
12010b292e6SMadhukar Pappireddy- ns-interrupts-action [mandatory]
12110b292e6SMadhukar Pappireddy   - value type: <u32>
12210b292e6SMadhukar Pappireddy   - Specifies the action that the SPMC must take in response to a Non-secure
12310b292e6SMadhukar Pappireddy     physical interrupt.
12410b292e6SMadhukar Pappireddy
12510b292e6SMadhukar Pappireddy      - 0x0: Non-secure interrupt is queued
12610b292e6SMadhukar Pappireddy      - 0x1: Non-secure interrupt is signaled after a managed exit
12710b292e6SMadhukar Pappireddy      - 0x2: Non-secure interrupt is signaled
12810b292e6SMadhukar Pappireddy
12910b292e6SMadhukar Pappireddy   - This field supersedes the managed-exit field in the FF-A v1.0 spec.
1301b17f4f1SOlivier Deprez
131ae1d9d90SMadhukar Pappireddy- other-s-interrupts-action
132ae1d9d90SMadhukar Pappireddy   - value type: <u32>
133ae1d9d90SMadhukar Pappireddy   - Specifies the action that the SPMC must take in response to a Other-Secure
134ae1d9d90SMadhukar Pappireddy     physical interrupt.
135ae1d9d90SMadhukar Pappireddy
136ae1d9d90SMadhukar Pappireddy      - 0x0: Other-Secure interrupt is queued
137ae1d9d90SMadhukar Pappireddy      - 0x1: Other-Secure interrupt is signaled
138ae1d9d90SMadhukar Pappireddy
1391b17f4f1SOlivier Deprez- has-primary-scheduler
1401b17f4f1SOlivier Deprez   - value type: <empty>
1411b17f4f1SOlivier Deprez   - Presence of this field indicates that the partition implements the primary
1421b17f4f1SOlivier Deprez     scheduler. If so, run-time EL must be EL1.
1431b17f4f1SOlivier Deprez
1441b17f4f1SOlivier Deprez- time-slice-mem
1451b17f4f1SOlivier Deprez   - value type: <empty>
1461b17f4f1SOlivier Deprez   - Presence of this field indicates that the partition doesn't expect the
1471b17f4f1SOlivier Deprez     partition manager to time slice long running memory management functions.
1481b17f4f1SOlivier Deprez
1491b17f4f1SOlivier Deprez- gp-register-num
1501b17f4f1SOlivier Deprez   - value type: <u32>
151573ac373SJ-Alves   - The field specifies the general purpose register number but not its width.
1521b17f4f1SOlivier Deprez     The width is derived from the partition's execution state, as specified in
1531b17f4f1SOlivier Deprez     the partition properties. For example, if the number value is 1 then the
1541b17f4f1SOlivier Deprez     general-purpose register used will be x1 in AArch64 state and w1 in AArch32
1551b17f4f1SOlivier Deprez     state.
156573ac373SJ-Alves     Presence of this field indicates that the partition expects the address of
157573ac373SJ-Alves     the FF-A boot information blob to be passed in the specified general purpose
158573ac373SJ-Alves     register.
1591b17f4f1SOlivier Deprez
1601b17f4f1SOlivier Deprez- stream-endpoint-ids
1611b17f4f1SOlivier Deprez   - value type: <prop-encoded-array>
1621b17f4f1SOlivier Deprez   - List of <u32> tuples, identifying the IDs this partition is acting as
1631b17f4f1SOlivier Deprez     proxy for.
1641b17f4f1SOlivier Deprez
16559bd2ad8SMarc Bonnici- power-management-messages
16659bd2ad8SMarc Bonnici   - value type: <u32>
16759bd2ad8SMarc Bonnici   - Specifies which power management messages a partition subscribes to.
16859bd2ad8SMarc Bonnici     A set bit means the partition should be informed of the power event, clear
16959bd2ad8SMarc Bonnici     bit - should not be informed of event:
17059bd2ad8SMarc Bonnici
17159bd2ad8SMarc Bonnici      - Bit[0]: CPU_OFF
17259bd2ad8SMarc Bonnici      - Bit[1]: CPU_SUSPEND
17359bd2ad8SMarc Bonnici      - Bit[2]: CPU_SUSPEND_RESUME
17459bd2ad8SMarc Bonnici
1751b17f4f1SOlivier DeprezMemory Regions
1761b17f4f1SOlivier Deprez--------------
1771b17f4f1SOlivier Deprez
1781b17f4f1SOlivier Deprez- compatible [mandatory]
1791b17f4f1SOlivier Deprez   - value type: <string>
1801b17f4f1SOlivier Deprez   - Must be the string "arm,ffa-manifest-memory-regions".
1811b17f4f1SOlivier Deprez
1821b17f4f1SOlivier Deprez- description
1831b17f4f1SOlivier Deprez   - value type: <string>
1841b17f4f1SOlivier Deprez   - Name of the memory region e.g. for debugging purposes.
1851b17f4f1SOlivier Deprez
1861b17f4f1SOlivier Deprez- pages-count [mandatory]
1871b17f4f1SOlivier Deprez   - value type: <u32>
1881b17f4f1SOlivier Deprez   - Count of pages of memory region as a multiple of the translation granule
1891b17f4f1SOlivier Deprez     size
1901b17f4f1SOlivier Deprez
1911b17f4f1SOlivier Deprez- attributes [mandatory]
1921b17f4f1SOlivier Deprez   - value type: <u32>
1931b17f4f1SOlivier Deprez   - Mapping modes: ORed to get required permission
1941b17f4f1SOlivier Deprez
1951b17f4f1SOlivier Deprez      - 0x1: Read
1961b17f4f1SOlivier Deprez      - 0x2: Write
1971b17f4f1SOlivier Deprez      - 0x4: Execute
19879a91381SOlivier Deprez      - 0x8: Security state
1991b17f4f1SOlivier Deprez
2001b17f4f1SOlivier Deprez- base-address
2011b17f4f1SOlivier Deprez   - value type: <u64>
2021b17f4f1SOlivier Deprez   - Base address of the region. The address must be aligned to the translation
2031b17f4f1SOlivier Deprez     granule size.
2041b17f4f1SOlivier Deprez     The address given may be a Physical Address (PA), Virtual Address (VA), or
20579a91381SOlivier Deprez     Intermediate Physical Address (IPA). Refer to the FF-A specification for
2061b17f4f1SOlivier Deprez     more information on the restrictions around the address type.
2071b17f4f1SOlivier Deprez     If the base address is omitted then the partition manager must map a memory
2081b17f4f1SOlivier Deprez     region of the specified size into the partition's translation regime and
2091b17f4f1SOlivier Deprez     then communicate the region properties (including the base address chosen
2101b17f4f1SOlivier Deprez     by the partition manager) to the partition.
2111b17f4f1SOlivier Deprez
2121b17f4f1SOlivier DeprezDevice Regions
2131b17f4f1SOlivier Deprez--------------
2141b17f4f1SOlivier Deprez
2151b17f4f1SOlivier Deprez- compatible [mandatory]
2161b17f4f1SOlivier Deprez   - value type: <string>
2171b17f4f1SOlivier Deprez   - Must be the string "arm,ffa-manifest-device-regions".
2181b17f4f1SOlivier Deprez
2191b17f4f1SOlivier Deprez- description
2201b17f4f1SOlivier Deprez   - value type: <string>
2211b17f4f1SOlivier Deprez   - Name of the device region e.g. for debugging purposes.
2221b17f4f1SOlivier Deprez
22379a91381SOlivier Deprez- pages-count [mandatory]
22479a91381SOlivier Deprez   - value type: <u32>
22579a91381SOlivier Deprez   - Count of pages of memory region as a multiple of the translation granule
22679a91381SOlivier Deprez     size
2271b17f4f1SOlivier Deprez
2281b17f4f1SOlivier Deprez- attributes [mandatory]
2291b17f4f1SOlivier Deprez   - value type: <u32>
2301b17f4f1SOlivier Deprez   - Mapping modes: ORed to get required permission
2311b17f4f1SOlivier Deprez
2321b17f4f1SOlivier Deprez     - 0x1: Read
2331b17f4f1SOlivier Deprez     - 0x2: Write
2341b17f4f1SOlivier Deprez     - 0x4: Execute
23579a91381SOlivier Deprez     - 0x8: Security state
23679a91381SOlivier Deprez
23779a91381SOlivier Deprez- base-address [mandatory]
23879a91381SOlivier Deprez   - value type: <u64>
23979a91381SOlivier Deprez   - Base address of the region. The address must be aligned to the translation
24079a91381SOlivier Deprez     granule size.
24179a91381SOlivier Deprez     The address given may be a Physical Address (PA), Virtual Address (VA), or
24279a91381SOlivier Deprez     Intermediate Physical Address (IPA). Refer to the FF-A specification for
24379a91381SOlivier Deprez     more information on the restrictions around the address type.
2441b17f4f1SOlivier Deprez
2451b17f4f1SOlivier Deprez- smmu-id
2461b17f4f1SOlivier Deprez   - value type: <u32>
2471b17f4f1SOlivier Deprez   - On systems with multiple System Memory Management Units (SMMUs) this
2481b17f4f1SOlivier Deprez     identifier is used to inform the partition manager which SMMU the device is
2491b17f4f1SOlivier Deprez     upstream of. If the field is omitted then it is assumed that the device is
2501b17f4f1SOlivier Deprez     not upstream of any SMMU.
2511b17f4f1SOlivier Deprez
2521b17f4f1SOlivier Deprez- stream-ids
2531b17f4f1SOlivier Deprez   - value type: <prop-encoded-array>
2541b17f4f1SOlivier Deprez   - A list of (id, mem-manage) pair, where:
2551b17f4f1SOlivier Deprez
2561b17f4f1SOlivier Deprez      - id: A unique <u32> value amongst all devices assigned to the partition.
2571b17f4f1SOlivier Deprez
2581b17f4f1SOlivier Deprez- interrupts [mandatory]
2591b17f4f1SOlivier Deprez   - value type: <prop-encoded-array>
2601b17f4f1SOlivier Deprez   - A list of (id, attributes) pair describing the device interrupts, where:
2611b17f4f1SOlivier Deprez
2621b17f4f1SOlivier Deprez      - id: The <u32> interrupt IDs.
26379a91381SOlivier Deprez      - attributes: A <u32> value, containing attributes for each interrupt ID:
2641b17f4f1SOlivier Deprez
26579a91381SOlivier Deprez        +----------------------+----------+
26679a91381SOlivier Deprez        |Field                 | Bit(s)   |
26779a91381SOlivier Deprez        +----------------------+----------+
26879a91381SOlivier Deprez        | Priority	       | 7:0      |
26979a91381SOlivier Deprez        +----------------------+----------+
27079a91381SOlivier Deprez        | Security state       | 8        |
27179a91381SOlivier Deprez        +----------------------+----------+
27279a91381SOlivier Deprez        | Config(Edge/Level)   | 9        |
27379a91381SOlivier Deprez        +----------------------+----------+
27479a91381SOlivier Deprez        | Type(SPI/PPI/SGI)    | 11:10    |
27579a91381SOlivier Deprez        +----------------------+----------+
27679a91381SOlivier Deprez
27779a91381SOlivier Deprez        Security state:
27879a91381SOlivier Deprez          - Secure:       1
27979a91381SOlivier Deprez          - Non-secure:   0
28079a91381SOlivier Deprez
28179a91381SOlivier Deprez        Configuration:
28279a91381SOlivier Deprez          - Edge triggered:       0
28379a91381SOlivier Deprez          - Level triggered:      1
28479a91381SOlivier Deprez
28579a91381SOlivier Deprez        Type:
28679a91381SOlivier Deprez          - SPI:  0b10
28779a91381SOlivier Deprez          - PPI:  0b01
28879a91381SOlivier Deprez          - SGI:  0b00
2891b17f4f1SOlivier Deprez
2909b5a360fSRaghu Krishnamurthy- interrupts-target
2919b5a360fSRaghu Krishnamurthy   - value type: <prop-encoded-array>
2929b5a360fSRaghu Krishnamurthy   - A list of (id, mpdir upper bits, mpidr lower bits) tuples describing which
2939b5a360fSRaghu Krishnamurthy     mpidr the interrupt is routed to, where:
2949b5a360fSRaghu Krishnamurthy
2959b5a360fSRaghu Krishnamurthy      - id: The <u32> interrupt ID. Must be one of those specified in the
2969b5a360fSRaghu Krishnamurthy            "interrupts" field.
2979b5a360fSRaghu Krishnamurthy      - mpidr upper bits: The <u32> describing the upper bits of the 64 bits
2989b5a360fSRaghu Krishnamurthy                          mpidr
2999b5a360fSRaghu Krishnamurthy      - mpidr lower bits: The <u32> describing the lower bits of the 64 bits
3009b5a360fSRaghu Krishnamurthy                          mpidr
3019b5a360fSRaghu Krishnamurthy
3021b17f4f1SOlivier Deprez- exclusive-access
3031b17f4f1SOlivier Deprez   - value type: <empty>
3041b17f4f1SOlivier Deprez   - Presence of this field implies that this endpoint must be granted exclusive
3051b17f4f1SOlivier Deprez     access and ownership of this device's MMIO region.
3061b17f4f1SOlivier Deprez
3071b17f4f1SOlivier Deprez--------------
3081b17f4f1SOlivier Deprez
30979a91381SOlivier Deprez*Copyright (c) 2019-2022, Arm Limited and Contributors. All rights reserved.*
310