1Allwinner ARMv8 SoCs 2==================== 3 4Trusted Firmware-A (TF-A) implements the EL3 firmware layer for Allwinner 5SoCs with ARMv8 cores. Only BL31 is used to provide proper EL3 setup and 6PSCI runtime services. 7 8Building TF-A 9------------- 10 11To build for machines with an A64 or H5 SoC: 12 13.. code:: shell 14 15 make CROSS_COMPILE=aarch64-linux-gnu- PLAT=sun50i_a64 DEBUG=1 bl31 16 17To build for machines with an H6 SoC: 18 19.. code:: shell 20 21 make CROSS_COMPILE=aarch64-linux-gnu- PLAT=sun50i_h6 DEBUG=1 bl31 22 23To build for machines with an H616 or H313 SoC: 24 25.. code:: shell 26 27 make CROSS_COMPILE=aarch64-linux-gnu- PLAT=sun50i_h616 DEBUG=1 bl31 28 29Platform-specific build options 30~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 31 32The default build options should generate a working firmware image. There are 33some build options that allow to fine-tune the firmware, or to disable support 34for optional features. 35 36- ``SUNXI_SETUP_REGULATORS`` : On SoCs that typically ship with a PMIC 37 power management controller, BL31 tries to set up all needed power rails, 38 programming them to their respective voltages. That allows bootloader 39 software like U-Boot to ignore power control via the PMIC. 40 This setting defaults to 1. In some situations that enables too many 41 regulators, or some regulators need to be enabled in a very specific 42 sequence. To avoid problems with those boards, ``SUNXI_SETUP_REGULATORS`` 43 can bet set to ``0`` on the build command line, to skip the PMIC setup 44 entirely. Any bootloader or OS would need to setup the PMIC on its own then. 45 46Installation 47------------ 48 49U-Boot's SPL acts as a loader, loading both BL31 and BL33 (typically U-Boot). 50Loading is done from SD card, eMMC or SPI flash, also via an USB debug 51interface (FEL). 52 53After building bl31.bin, the binary must be fed to the U-Boot build system 54to include it in the FIT image that the SPL loader will process. 55bl31.bin can be either copied (or sym-linked) into U-Boot's root directory, 56or the environment variable BL31 must contain the binary's path. 57See the respective `U-Boot documentation`_ for more details. 58 59.. _U-Boot documentation: https://gitlab.denx.de/u-boot/u-boot/-/blob/master/board/sunxi/README.sunxi64 60 61Memory layout 62------------- 63 64A64, H5 and H6 SoCs 65~~~~~~~~~~~~~~~~~~~ 66 67BL31 lives in SRAM A2, which is documented to be accessible from secure 68world only. Since this SRAM region is very limited (48 KB), we take 69several measures to reduce memory consumption. One of them is to confine 70BL31 to only 28 bits of virtual address space, which reduces the number 71of required page tables (each occupying 4KB of memory). 72The mapping we use on those SoCs is as follows: 73 74:: 75 76 0 64K 16M 1GB 1G+160M physical address 77 +-+------+-+---+------+--...---+-------+----+------+---------- 78 |B| |S|///| |//...///| |////| | 79 |R| SRAM |C|///| dev |//...///| (sec) |////| BL33 | DRAM ... 80 |O| |P|///| MMIO |//...///| DRAM |////| | 81 |M| | |///| |//...///| (32M) |////| | 82 +-+------+-+---+------+--...---+-------+----+------+---------- 83 | | | | | | / / / / 84 | | | | | | / / / / 85 | | | | | | / / / / 86 | | | | | | / // / 87 | | | | | | / / / 88 +-+------+-+---+------+--+-------+------+ 89 |B| |S|///| |//| | | 90 |R| SRAM |C|///| dev |//| sec | BL33 | 91 |O| |P|///| MMIO |//| DRAM | | 92 |M| | |///| |//| | | 93 +-+------+-+---+------+--+-------+------+ 94 0 64K 16M 160M 192M 256M virtual address 95 96 97H616 SoC 98~~~~~~~~ 99 100The H616 lacks the secure SRAM region present on the other SoCs, also 101lacks the "ARISC" management processor (SCP) we use. BL31 thus needs to 102run from DRAM, which prevents our compressed virtual memory map described 103above. Since running in DRAM also lifts the restriction of the limited 104SRAM size, we use the normal 1:1 mapping with 32 bits worth of virtual 105address space. So the virtual addresses used in BL31 match the physical 106addresses as presented above. 107 108Trusted OS dispatcher 109--------------------- 110 111One can boot Trusted OS(OP-TEE OS, bl32 image) along side bl31 image on Allwinner A64. 112 113In order to include the 'opteed' dispatcher in the image, pass 'SPD=opteed' on the command line 114while compiling the bl31 image and make sure the loader (SPL) loads the Trusted OS binary to 115the beginning of DRAM (0x40000000). 116