124dba2b3SPaul BeesleyQEMU virt Armv8-A 224dba2b3SPaul Beesley================= 36f625747SDouglas Raillard 44def07d5SDan HandleyTrusted Firmware-A (TF-A) implements the EL3 firmware layer for QEMU virt 54def07d5SDan HandleyArmv8-A. BL1 is used as the BootROM, supplied with the -bios argument. 66f625747SDouglas RaillardWhen QEMU starts all CPUs are released simultaneously, BL1 selects a 76f625747SDouglas Raillardprimary CPU to handle the boot and the secondaries are placed in a polling 86f625747SDouglas Raillardloop to be released by normal world via PSCI. 96f625747SDouglas Raillard 106f625747SDouglas RaillardBL2 edits the Flattened Device Tree, FDT, generated by QEMU at run-time to 116f625747SDouglas Raillardadd a node describing PSCI and also enable methods for the CPUs. 126f625747SDouglas Raillard 1374464d5bSAndrew WalbranIf ``ARM_LINUX_KERNEL_AS_BL33`` is set to 1 then this FDT will be passed to BL33 1474464d5bSAndrew Walbranvia register x0, as expected by a Linux kernel. This allows a Linux kernel image 1574464d5bSAndrew Walbranto be booted directly as BL33 rather than using a bootloader. 1674464d5bSAndrew Walbran 1762038be7SMasahiro YamadaAn ARM64 defconfig v5.5 Linux kernel is known to boot, FDT doesn't need to be 186f625747SDouglas Raillardprovided as it's generated by QEMU. 196f625747SDouglas Raillard 206f625747SDouglas RaillardCurrent limitations: 216f625747SDouglas Raillard 226f625747SDouglas Raillard- Only cold boot is supported 236f625747SDouglas Raillard 24a66f0309SMasahiro YamadaGetting non-TF images 25a66f0309SMasahiro Yamada--------------------- 26a66f0309SMasahiro Yamada 27a66f0309SMasahiro Yamada``QEMU_EFI.fd`` can be downloaded from 2862038be7SMasahiro Yamadahttp://snapshots.linaro.org/components/kernel/leg-virt-tianocore-edk2-upstream/latest/QEMU-KERNEL-AARCH64/RELEASE_GCC5/QEMU_EFI.fd 296f625747SDouglas Raillard 30a66f0309SMasahiro Yamadaor, can be built as follows: 31a66f0309SMasahiro Yamada 32a66f0309SMasahiro Yamada.. code:: shell 33a66f0309SMasahiro Yamada 34a66f0309SMasahiro Yamada git clone https://github.com/tianocore/edk2.git 35a66f0309SMasahiro Yamada cd edk2 36a66f0309SMasahiro Yamada git submodule update --init 37a66f0309SMasahiro Yamada make -C BaseTools 38a66f0309SMasahiro Yamada source edksetup.sh 39a66f0309SMasahiro Yamada export GCC5_AARCH64_PREFIX=aarch64-linux-gnu- 40a66f0309SMasahiro Yamada build -a AARCH64 -t GCC5 -p ArmVirtPkg/ArmVirtQemuKernel.dsc 41a66f0309SMasahiro Yamada 42a66f0309SMasahiro Yamada```` 43a66f0309SMasahiro Yamada 44a66f0309SMasahiro YamadaThen, you will get ``Build/ArmVirtQemuKernel-AARCH64/DEBUG_GCC5/FV/QEMU_EFI.fd`` 45a66f0309SMasahiro Yamada 46a66f0309SMasahiro YamadaPlease note you do not need to use GCC 5 in spite of the environment variable 47a66f0309SMasahiro Yamada``GCC5_AARCH64_PREFIX`` 48a66f0309SMasahiro Yamada 49a66f0309SMasahiro YamadaThe rootfs can be built by using Buildroot as follows: 50a66f0309SMasahiro Yamada 51a66f0309SMasahiro Yamada.. code:: shell 52a66f0309SMasahiro Yamada 53a66f0309SMasahiro Yamada git clone git://git.buildroot.net/buildroot.git 54a66f0309SMasahiro Yamada cd buildroot 55a66f0309SMasahiro Yamada make qemu_aarch64_virt_defconfig 56a66f0309SMasahiro Yamada utils/config -e BR2_TARGET_ROOTFS_CPIO 57a66f0309SMasahiro Yamada utils/config -e BR2_TARGET_ROOTFS_CPIO_GZIP 58a66f0309SMasahiro Yamada make olddefconfig 59a66f0309SMasahiro Yamada make 60a66f0309SMasahiro Yamada 61a66f0309SMasahiro YamadaThen, you will get ``output/images/rootfs.cpio.gz``. 62a66f0309SMasahiro Yamada 634ebbea95SSumit GargBooting via semi-hosting option 644ebbea95SSumit Garg------------------------------- 654ebbea95SSumit Garg 666f625747SDouglas RaillardBoot binaries, except BL1, are primarily loaded via semi-hosting so all 676f625747SDouglas Raillardbinaries has to reside in the same directory as QEMU is started from. This 686f625747SDouglas Raillardis conveniently achieved with symlinks the local names as: 696f625747SDouglas Raillard 706f625747SDouglas Raillard- ``bl2.bin`` -> BL2 716f625747SDouglas Raillard- ``bl31.bin`` -> BL31 726f625747SDouglas Raillard- ``bl33.bin`` -> BL33 (``QEMU_EFI.fd``) 7362038be7SMasahiro Yamada- ``Image`` -> linux/arch/arm64/boot/Image 746f625747SDouglas Raillard 756f625747SDouglas RaillardTo build: 766f625747SDouglas Raillard 7729c02529SPaul Beesley.. code:: shell 786f625747SDouglas Raillard 796f625747SDouglas Raillard make CROSS_COMPILE=aarch64-none-elf- PLAT=qemu 806f625747SDouglas Raillard 81231d0b35SMasahiro YamadaTo start (QEMU v5.0.0): 826f625747SDouglas Raillard 8329c02529SPaul Beesley.. code:: shell 846f625747SDouglas Raillard 856f625747SDouglas Raillard qemu-system-aarch64 -nographic -machine virt,secure=on -cpu cortex-a57 \ 866f625747SDouglas Raillard -kernel Image \ 87624120e0SMasahiro Yamada -append "console=ttyAMA0,38400 keep_bootcon" \ 88a66f0309SMasahiro Yamada -initrd rootfs.cpio.gz -smp 2 -m 1024 -bios bl1.bin \ 896f625747SDouglas Raillard -d unimp -semihosting-config enable,target=native 904ebbea95SSumit Garg 914ebbea95SSumit GargBooting via flash based firmwares 924ebbea95SSumit Garg--------------------------------- 934ebbea95SSumit Garg 944ebbea95SSumit GargBoot firmwares are loaded via secure FLASH0 device so ``bl1.bin`` and 954ebbea95SSumit Garg``fip.bin`` should be concatenated to create a ``flash.bin`` that is flashed 964ebbea95SSumit Gargonto secure FLASH0. 974ebbea95SSumit Garg 984ebbea95SSumit Garg- ``bl32.bin`` -> BL32 (``tee-header_v2.bin``) 994ebbea95SSumit Garg- ``bl32_extra1.bin`` -> BL32 Extra1 (``tee-pager_v2.bin``) 1004ebbea95SSumit Garg- ``bl32_extra2.bin`` -> BL32 Extra2 (``tee-pageable_v2.bin``) 1014ebbea95SSumit Garg- ``bl33.bin`` -> BL33 (``QEMU_EFI.fd``) 1024ebbea95SSumit Garg- ``Image`` -> linux/arch/arm64/boot/Image 1034ebbea95SSumit Garg 1044ebbea95SSumit GargTo build: 1054ebbea95SSumit Garg 1064ebbea95SSumit Garg.. code:: shell 1074ebbea95SSumit Garg 1084ebbea95SSumit Garg make CROSS_COMPILE=aarch64-linux-gnu- PLAT=qemu BL32=bl32.bin \ 1094ebbea95SSumit Garg BL32_EXTRA1=bl32_extra1.bin BL32_EXTRA2=bl32_extra2.bin \ 1104ebbea95SSumit Garg BL33=bl33.bin BL32_RAM_LOCATION=tdram SPD=opteed all fip 1114ebbea95SSumit Garg 1124ebbea95SSumit GargTo build with TBBR enabled, BL31 and BL32 encrypted with test key: 1134ebbea95SSumit Garg 1144ebbea95SSumit Garg.. code:: shell 1154ebbea95SSumit Garg 1164ebbea95SSumit Garg make CROSS_COMPILE=aarch64-linux-gnu- PLAT=qemu BL32=bl32.bin \ 1174ebbea95SSumit Garg BL32_EXTRA1=bl32_extra1.bin BL32_EXTRA2=bl32_extra2.bin \ 1184ebbea95SSumit Garg BL33=bl33.bin BL32_RAM_LOCATION=tdram SPD=opteed all fip \ 1194ebbea95SSumit Garg MBEDTLS_DIR=<path-to-mbedtls-repo> TRUSTED_BOARD_BOOT=1 \ 1204ebbea95SSumit Garg GENERATE_COT=1 DECRYPTION_SUPPORT=aes_gcm FW_ENC_STATUS=0 \ 1214ebbea95SSumit Garg ENCRYPT_BL31=1 ENCRYPT_BL32=1 1224ebbea95SSumit Garg 1234ebbea95SSumit GargTo build flash.bin: 1244ebbea95SSumit Garg 1254ebbea95SSumit Garg.. code:: shell 1264ebbea95SSumit Garg 1274ebbea95SSumit Garg dd if=build/qemu/release/bl1.bin of=flash.bin bs=4096 conv=notrunc 1284ebbea95SSumit Garg dd if=build/qemu/release/fip.bin of=flash.bin seek=64 bs=4096 conv=notrunc 1294ebbea95SSumit Garg 130231d0b35SMasahiro YamadaTo start (QEMU v5.0.0): 1314ebbea95SSumit Garg 1324ebbea95SSumit Garg.. code:: shell 1334ebbea95SSumit Garg 1344ebbea95SSumit Garg qemu-system-aarch64 -nographic -machine virt,secure=on -cpu cortex-a57 \ 1354ebbea95SSumit Garg -kernel Image -no-acpi \ 136624120e0SMasahiro Yamada -append 'console=ttyAMA0,38400 keep_bootcon' \ 137a66f0309SMasahiro Yamada -initrd rootfs.cpio.gz -smp 2 -m 1024 -bios flash.bin \ 1384ebbea95SSumit Garg -d unimp 139*a5667be0SHarrison Mutai 140*a5667be0SHarrison MutaiRunning QEMU in OpenCI 141*a5667be0SHarrison Mutai----------------------- 142*a5667be0SHarrison Mutai 143*a5667be0SHarrison MutaiLinaro's continuous integration platform OpenCI supports running emulated tests 144*a5667be0SHarrison Mutaion QEMU. The tests are kicked off on Jenkins and deployed through the Linaro 145*a5667be0SHarrison MutaiAutomation and Validation Architecture `LAVA`_. 146*a5667be0SHarrison Mutai 147*a5667be0SHarrison MutaiThere are a set of Linux boot tests provided in OpenCI. They rely on prebuilt 148*a5667be0SHarrison Mutai`binaries`_ for UEFI, the kernel, root file system, as well as, any other TF-A 149*a5667be0SHarrison Mutaidependencies, and are run as part of the OpenCI TF-A `daily job`_. To run them 150*a5667be0SHarrison Mutaimanually, a `builder`_ job may be triggered with the test configuration 151*a5667be0SHarrison Mutai``qemu-boot-tests``. 152*a5667be0SHarrison Mutai 153*a5667be0SHarrison Mutai 154*a5667be0SHarrison MutaiYou may see the following warning repeated several times in the boot logs: 155*a5667be0SHarrison Mutai 156*a5667be0SHarrison Mutai.. code:: shell 157*a5667be0SHarrison Mutai 158*a5667be0SHarrison Mutai pflash_write: Write to buffer emulation is flawed 159*a5667be0SHarrison Mutai 160*a5667be0SHarrison MutaiPlease ignore this as it is an unresolved `issue in QEMU`_, it is an internal 161*a5667be0SHarrison MutaiQEMU warning that logs flawed use of "write to buffer". 162*a5667be0SHarrison Mutai 163*a5667be0SHarrison Mutai.. note:: 164*a5667be0SHarrison Mutai For more information on how to trigger jobs in OpenCI, please refer to 165*a5667be0SHarrison Mutai Linaro's CI documentation, which explains how to trigger a `manual job`_. 166*a5667be0SHarrison Mutai 167*a5667be0SHarrison Mutai.. _binaries: https://downloads.trustedfirmware.org/tf-a/linux_boot/ 168*a5667be0SHarrison Mutai.. _daily job: https://ci.trustedfirmware.org/view/TF-A/job/tf-a-main/ 169*a5667be0SHarrison Mutai.. _builder: https://ci.trustedfirmware.org/view/TF-A/job/tf-a-builder/ 170*a5667be0SHarrison Mutai.. _LAVA: https://tf.validation.linaro.org/ 171*a5667be0SHarrison Mutai.. _manual job: https://tf-ci-users-guide.readthedocs.io/en/latest/#manual-job-trigger 172*a5667be0SHarrison Mutai.. _issue in QEMU: https://git.qemu.org/?p=qemu.git;a=blob;f=hw/block/pflash_cfi01.c;h=0cbc2fb4cbf62c9a033b8dd89012374ff74ed610;hb=refs/heads/master#l500 173