1bdd2596dSAchin Gupta /* 2bdd2596dSAchin Gupta * Copyright (c) 2020, ARM Limited and Contributors. All rights reserved. 3bdd2596dSAchin Gupta * 4bdd2596dSAchin Gupta * SPDX-License-Identifier: BSD-3-Clause 5bdd2596dSAchin Gupta */ 6bdd2596dSAchin Gupta 7bdd2596dSAchin Gupta #include <assert.h> 8bdd2596dSAchin Gupta #include <errno.h> 9bdd2596dSAchin Gupta #include <string.h> 10bdd2596dSAchin Gupta 11bdd2596dSAchin Gupta #include <arch_helpers.h> 1252696946SOlivier Deprez #include <arch/aarch64/arch_features.h> 13bdd2596dSAchin Gupta #include <bl31/bl31.h> 14bdd2596dSAchin Gupta #include <common/debug.h> 15bdd2596dSAchin Gupta #include <common/runtime_svc.h> 16bdd2596dSAchin Gupta #include <lib/el3_runtime/context_mgmt.h> 17bdd2596dSAchin Gupta #include <lib/smccc.h> 18bdd2596dSAchin Gupta #include <lib/spinlock.h> 19bdd2596dSAchin Gupta #include <lib/utils.h> 20bdd2596dSAchin Gupta #include <plat/common/common_def.h> 21bdd2596dSAchin Gupta #include <plat/common/platform.h> 22bdd2596dSAchin Gupta #include <platform_def.h> 23662af36dSJ-Alves #include <services/ffa_svc.h> 24bdd2596dSAchin Gupta #include <services/spmd_svc.h> 25bdd2596dSAchin Gupta #include <smccc_helpers.h> 26bdd2596dSAchin Gupta #include "spmd_private.h" 27bdd2596dSAchin Gupta 28bdd2596dSAchin Gupta /******************************************************************************* 29bdd2596dSAchin Gupta * SPM Core context information. 30bdd2596dSAchin Gupta ******************************************************************************/ 3152696946SOlivier Deprez static spmd_spm_core_context_t spm_core_context[PLATFORM_CORE_COUNT]; 32bdd2596dSAchin Gupta 33bdd2596dSAchin Gupta /******************************************************************************* 34bdd2596dSAchin Gupta * SPM Core attribute information read from its manifest. 35bdd2596dSAchin Gupta ******************************************************************************/ 3652696946SOlivier Deprez static spmc_manifest_attribute_t spmc_attrs; 370f14d02fSMax Shvetsov 380f14d02fSMax Shvetsov /******************************************************************************* 390f14d02fSMax Shvetsov * SPM Core entry point information. Discovered on the primary core and reused 400f14d02fSMax Shvetsov * on secondary cores. 410f14d02fSMax Shvetsov ******************************************************************************/ 420f14d02fSMax Shvetsov static entry_point_info_t *spmc_ep_info; 430f14d02fSMax Shvetsov 440f14d02fSMax Shvetsov /******************************************************************************* 4502d50bb0SOlivier Deprez * SPM Core context on CPU based on mpidr. 4602d50bb0SOlivier Deprez ******************************************************************************/ 4702d50bb0SOlivier Deprez spmd_spm_core_context_t *spmd_get_context_by_mpidr(uint64_t mpidr) 4802d50bb0SOlivier Deprez { 49*f7fb0bf7SMax Shvetsov int core_idx = plat_core_pos_by_mpidr(mpidr); 50*f7fb0bf7SMax Shvetsov 51*f7fb0bf7SMax Shvetsov if (core_idx < 0) { 52*f7fb0bf7SMax Shvetsov ERROR("Invalid mpidr: %llx, returned ID: %d\n", mpidr, core_idx); 53*f7fb0bf7SMax Shvetsov panic(); 54*f7fb0bf7SMax Shvetsov } 55*f7fb0bf7SMax Shvetsov 56*f7fb0bf7SMax Shvetsov return &spm_core_context[core_idx]; 5702d50bb0SOlivier Deprez } 5802d50bb0SOlivier Deprez 5902d50bb0SOlivier Deprez /******************************************************************************* 6052696946SOlivier Deprez * SPM Core context on current CPU get helper. 6152696946SOlivier Deprez ******************************************************************************/ 6252696946SOlivier Deprez spmd_spm_core_context_t *spmd_get_context(void) 6352696946SOlivier Deprez { 6402d50bb0SOlivier Deprez return spmd_get_context_by_mpidr(read_mpidr()); 6552696946SOlivier Deprez } 6652696946SOlivier Deprez 6752696946SOlivier Deprez /******************************************************************************* 68c0267cc9SOlivier Deprez * SPM Core entry point information get helper. 69c0267cc9SOlivier Deprez ******************************************************************************/ 70c0267cc9SOlivier Deprez entry_point_info_t *spmd_spmc_ep_info_get(void) 71c0267cc9SOlivier Deprez { 72c0267cc9SOlivier Deprez return spmc_ep_info; 73c0267cc9SOlivier Deprez } 74c0267cc9SOlivier Deprez 75c0267cc9SOlivier Deprez /******************************************************************************* 76a92bc73bSOlivier Deprez * SPM Core ID getter. 77a92bc73bSOlivier Deprez ******************************************************************************/ 78a92bc73bSOlivier Deprez uint16_t spmd_spmc_id_get(void) 79a92bc73bSOlivier Deprez { 80a92bc73bSOlivier Deprez return spmc_attrs.spmc_id; 81a92bc73bSOlivier Deprez } 82a92bc73bSOlivier Deprez 83a92bc73bSOlivier Deprez /******************************************************************************* 840f14d02fSMax Shvetsov * Static function declaration. 850f14d02fSMax Shvetsov ******************************************************************************/ 860f14d02fSMax Shvetsov static int32_t spmd_init(void); 8723d5ba86SOlivier Deprez static int spmd_spmc_init(void *pm_addr); 88662af36dSJ-Alves static uint64_t spmd_ffa_error_return(void *handle, 8952696946SOlivier Deprez int error_code); 9052696946SOlivier Deprez static uint64_t spmd_smc_forward(uint32_t smc_fid, 9152696946SOlivier Deprez bool secure_origin, 9252696946SOlivier Deprez uint64_t x1, 9352696946SOlivier Deprez uint64_t x2, 9452696946SOlivier Deprez uint64_t x3, 9552696946SOlivier Deprez uint64_t x4, 9652696946SOlivier Deprez void *handle); 97bdd2596dSAchin Gupta 98bdd2596dSAchin Gupta /******************************************************************************* 9952696946SOlivier Deprez * This function takes an SPMC context pointer and performs a synchronous 10052696946SOlivier Deprez * SPMC entry. 101bdd2596dSAchin Gupta ******************************************************************************/ 102bdd2596dSAchin Gupta uint64_t spmd_spm_core_sync_entry(spmd_spm_core_context_t *spmc_ctx) 103bdd2596dSAchin Gupta { 104bdd2596dSAchin Gupta uint64_t rc; 105bdd2596dSAchin Gupta 106bdd2596dSAchin Gupta assert(spmc_ctx != NULL); 107bdd2596dSAchin Gupta 108bdd2596dSAchin Gupta cm_set_context(&(spmc_ctx->cpu_ctx), SECURE); 109bdd2596dSAchin Gupta 110bdd2596dSAchin Gupta /* Restore the context assigned above */ 111bdd2596dSAchin Gupta cm_el1_sysregs_context_restore(SECURE); 112033039f8SMax Shvetsov #if SPMD_SPM_AT_SEL2 11328f39f02SMax Shvetsov cm_el2_sysregs_context_restore(SECURE); 114033039f8SMax Shvetsov #endif 115bdd2596dSAchin Gupta cm_set_next_eret_context(SECURE); 116bdd2596dSAchin Gupta 117033039f8SMax Shvetsov /* Enter SPMC */ 118bdd2596dSAchin Gupta rc = spmd_spm_core_enter(&spmc_ctx->c_rt_ctx); 119bdd2596dSAchin Gupta 120bdd2596dSAchin Gupta /* Save secure state */ 121bdd2596dSAchin Gupta cm_el1_sysregs_context_save(SECURE); 122033039f8SMax Shvetsov #if SPMD_SPM_AT_SEL2 12328f39f02SMax Shvetsov cm_el2_sysregs_context_save(SECURE); 124033039f8SMax Shvetsov #endif 125bdd2596dSAchin Gupta 126bdd2596dSAchin Gupta return rc; 127bdd2596dSAchin Gupta } 128bdd2596dSAchin Gupta 129bdd2596dSAchin Gupta /******************************************************************************* 13052696946SOlivier Deprez * This function returns to the place where spmd_spm_core_sync_entry() was 131bdd2596dSAchin Gupta * called originally. 132bdd2596dSAchin Gupta ******************************************************************************/ 133bdd2596dSAchin Gupta __dead2 void spmd_spm_core_sync_exit(uint64_t rc) 134bdd2596dSAchin Gupta { 13552696946SOlivier Deprez spmd_spm_core_context_t *ctx = spmd_get_context(); 136bdd2596dSAchin Gupta 13752696946SOlivier Deprez /* Get current CPU context from SPMC context */ 138bdd2596dSAchin Gupta assert(cm_get_context(SECURE) == &(ctx->cpu_ctx)); 139bdd2596dSAchin Gupta 140bdd2596dSAchin Gupta /* 141bdd2596dSAchin Gupta * The SPMD must have initiated the original request through a 142bdd2596dSAchin Gupta * synchronous entry into SPMC. Jump back to the original C runtime 143bdd2596dSAchin Gupta * context with the value of rc in x0; 144bdd2596dSAchin Gupta */ 145bdd2596dSAchin Gupta spmd_spm_core_exit(ctx->c_rt_ctx, rc); 146bdd2596dSAchin Gupta 147bdd2596dSAchin Gupta panic(); 148bdd2596dSAchin Gupta } 149bdd2596dSAchin Gupta 150bdd2596dSAchin Gupta /******************************************************************************* 15152696946SOlivier Deprez * Jump to the SPM Core for the first time. 152bdd2596dSAchin Gupta ******************************************************************************/ 153bdd2596dSAchin Gupta static int32_t spmd_init(void) 154bdd2596dSAchin Gupta { 15552696946SOlivier Deprez spmd_spm_core_context_t *ctx = spmd_get_context(); 15652696946SOlivier Deprez uint64_t rc; 1579dcf63ddSOlivier Deprez unsigned int linear_id = plat_my_core_pos(); 1589dcf63ddSOlivier Deprez unsigned int core_id; 159bdd2596dSAchin Gupta 16052696946SOlivier Deprez VERBOSE("SPM Core init start.\n"); 1619dcf63ddSOlivier Deprez ctx->state = SPMC_STATE_ON_PENDING; 1629dcf63ddSOlivier Deprez 1639dcf63ddSOlivier Deprez /* Set the SPMC context state on other CPUs to OFF */ 164f0d743dbSOlivier Deprez for (core_id = 0U; core_id < PLATFORM_CORE_COUNT; core_id++) { 1659dcf63ddSOlivier Deprez if (core_id != linear_id) { 1669dcf63ddSOlivier Deprez spm_core_context[core_id].state = SPMC_STATE_OFF; 16702d50bb0SOlivier Deprez spm_core_context[core_id].secondary_ep.entry_point = 0UL; 1689dcf63ddSOlivier Deprez } 1699dcf63ddSOlivier Deprez } 170bdd2596dSAchin Gupta 171bdd2596dSAchin Gupta rc = spmd_spm_core_sync_entry(ctx); 17252696946SOlivier Deprez if (rc != 0ULL) { 173bdd2596dSAchin Gupta ERROR("SPMC initialisation failed 0x%llx\n", rc); 17452696946SOlivier Deprez return 0; 175bdd2596dSAchin Gupta } 176bdd2596dSAchin Gupta 1779dcf63ddSOlivier Deprez ctx->state = SPMC_STATE_ON; 1789dcf63ddSOlivier Deprez 17952696946SOlivier Deprez VERBOSE("SPM Core init end.\n"); 180bdd2596dSAchin Gupta 181bdd2596dSAchin Gupta return 1; 182bdd2596dSAchin Gupta } 183bdd2596dSAchin Gupta 184bdd2596dSAchin Gupta /******************************************************************************* 18552696946SOlivier Deprez * Loads SPMC manifest and inits SPMC. 1860f14d02fSMax Shvetsov ******************************************************************************/ 18723d5ba86SOlivier Deprez static int spmd_spmc_init(void *pm_addr) 1880f14d02fSMax Shvetsov { 18952696946SOlivier Deprez spmd_spm_core_context_t *spm_ctx = spmd_get_context(); 1900f14d02fSMax Shvetsov uint32_t ep_attr; 19152696946SOlivier Deprez int rc; 1920f14d02fSMax Shvetsov 19352696946SOlivier Deprez /* Load the SPM Core manifest */ 19423d5ba86SOlivier Deprez rc = plat_spm_core_manifest_load(&spmc_attrs, pm_addr); 1950f14d02fSMax Shvetsov if (rc != 0) { 19652696946SOlivier Deprez WARN("No or invalid SPM Core manifest image provided by BL2\n"); 19752696946SOlivier Deprez return rc; 1980f14d02fSMax Shvetsov } 1990f14d02fSMax Shvetsov 2000f14d02fSMax Shvetsov /* 20152696946SOlivier Deprez * Ensure that the SPM Core version is compatible with the SPM 20252696946SOlivier Deprez * Dispatcher version. 2030f14d02fSMax Shvetsov */ 204662af36dSJ-Alves if ((spmc_attrs.major_version != FFA_VERSION_MAJOR) || 205662af36dSJ-Alves (spmc_attrs.minor_version > FFA_VERSION_MINOR)) { 206662af36dSJ-Alves WARN("Unsupported FFA version (%u.%u)\n", 2070f14d02fSMax Shvetsov spmc_attrs.major_version, spmc_attrs.minor_version); 20852696946SOlivier Deprez return -EINVAL; 2090f14d02fSMax Shvetsov } 2100f14d02fSMax Shvetsov 211662af36dSJ-Alves VERBOSE("FFA version (%u.%u)\n", spmc_attrs.major_version, 2120f14d02fSMax Shvetsov spmc_attrs.minor_version); 2130f14d02fSMax Shvetsov 21452696946SOlivier Deprez VERBOSE("SPM Core run time EL%x.\n", 215033039f8SMax Shvetsov SPMD_SPM_AT_SEL2 ? MODE_EL2 : MODE_EL1); 2160f14d02fSMax Shvetsov 217ac03ac5eSMax Shvetsov /* Validate the SPMC ID, Ensure high bit is set */ 21852696946SOlivier Deprez if (((spmc_attrs.spmc_id >> SPMC_SECURE_ID_SHIFT) & 21952696946SOlivier Deprez SPMC_SECURE_ID_MASK) == 0U) { 22052696946SOlivier Deprez WARN("Invalid ID (0x%x) for SPMC.\n", spmc_attrs.spmc_id); 22152696946SOlivier Deprez return -EINVAL; 222ac03ac5eSMax Shvetsov } 223ac03ac5eSMax Shvetsov 22452696946SOlivier Deprez /* Validate the SPM Core execution state */ 2250f14d02fSMax Shvetsov if ((spmc_attrs.exec_state != MODE_RW_64) && 2260f14d02fSMax Shvetsov (spmc_attrs.exec_state != MODE_RW_32)) { 22723d5ba86SOlivier Deprez WARN("Unsupported %s%x.\n", "SPM Core execution state 0x", 2280f14d02fSMax Shvetsov spmc_attrs.exec_state); 22952696946SOlivier Deprez return -EINVAL; 2300f14d02fSMax Shvetsov } 2310f14d02fSMax Shvetsov 23223d5ba86SOlivier Deprez VERBOSE("%s%x.\n", "SPM Core execution state 0x", 23323d5ba86SOlivier Deprez spmc_attrs.exec_state); 2340f14d02fSMax Shvetsov 235033039f8SMax Shvetsov #if SPMD_SPM_AT_SEL2 236033039f8SMax Shvetsov /* Ensure manifest has not requested AArch32 state in S-EL2 */ 237033039f8SMax Shvetsov if (spmc_attrs.exec_state == MODE_RW_32) { 238033039f8SMax Shvetsov WARN("AArch32 state at S-EL2 is not supported.\n"); 23952696946SOlivier Deprez return -EINVAL; 2400f14d02fSMax Shvetsov } 2410f14d02fSMax Shvetsov 2420f14d02fSMax Shvetsov /* 2430f14d02fSMax Shvetsov * Check if S-EL2 is supported on this system if S-EL2 2440f14d02fSMax Shvetsov * is required for SPM 2450f14d02fSMax Shvetsov */ 24652696946SOlivier Deprez if (!is_armv8_4_sel2_present()) { 24752696946SOlivier Deprez WARN("SPM Core run time S-EL2 is not supported.\n"); 24852696946SOlivier Deprez return -EINVAL; 2490f14d02fSMax Shvetsov } 250033039f8SMax Shvetsov #endif /* SPMD_SPM_AT_SEL2 */ 2510f14d02fSMax Shvetsov 2520f14d02fSMax Shvetsov /* Initialise an entrypoint to set up the CPU context */ 2530f14d02fSMax Shvetsov ep_attr = SECURE | EP_ST_ENABLE; 25452696946SOlivier Deprez if ((read_sctlr_el3() & SCTLR_EE_BIT) != 0ULL) { 2550f14d02fSMax Shvetsov ep_attr |= EP_EE_BIG; 2560f14d02fSMax Shvetsov } 2570f14d02fSMax Shvetsov 2580f14d02fSMax Shvetsov SET_PARAM_HEAD(spmc_ep_info, PARAM_EP, VERSION_1, ep_attr); 2590f14d02fSMax Shvetsov assert(spmc_ep_info->pc == BL32_BASE); 2600f14d02fSMax Shvetsov 2610f14d02fSMax Shvetsov /* 26252696946SOlivier Deprez * Populate SPSR for SPM Core based upon validated parameters from the 26352696946SOlivier Deprez * manifest. 2640f14d02fSMax Shvetsov */ 2650f14d02fSMax Shvetsov if (spmc_attrs.exec_state == MODE_RW_32) { 2660f14d02fSMax Shvetsov spmc_ep_info->spsr = SPSR_MODE32(MODE32_svc, SPSR_T_ARM, 2670f14d02fSMax Shvetsov SPSR_E_LITTLE, 2680f14d02fSMax Shvetsov DAIF_FIQ_BIT | 2690f14d02fSMax Shvetsov DAIF_IRQ_BIT | 2700f14d02fSMax Shvetsov DAIF_ABT_BIT); 2710f14d02fSMax Shvetsov } else { 272033039f8SMax Shvetsov 273033039f8SMax Shvetsov #if SPMD_SPM_AT_SEL2 274033039f8SMax Shvetsov static const uint32_t runtime_el = MODE_EL2; 275033039f8SMax Shvetsov #else 276033039f8SMax Shvetsov static const uint32_t runtime_el = MODE_EL1; 277033039f8SMax Shvetsov #endif 278033039f8SMax Shvetsov spmc_ep_info->spsr = SPSR_64(runtime_el, 2790f14d02fSMax Shvetsov MODE_SP_ELX, 2800f14d02fSMax Shvetsov DISABLE_ALL_EXCEPTIONS); 2810f14d02fSMax Shvetsov } 2820f14d02fSMax Shvetsov 28352696946SOlivier Deprez /* Initialise SPM Core context with this entry point information */ 2840f14d02fSMax Shvetsov cm_setup_context(&spm_ctx->cpu_ctx, spmc_ep_info); 2850f14d02fSMax Shvetsov 2860f14d02fSMax Shvetsov /* Reuse PSCI affinity states to mark this SPMC context as off */ 2870f14d02fSMax Shvetsov spm_ctx->state = AFF_STATE_OFF; 2880f14d02fSMax Shvetsov 28952696946SOlivier Deprez INFO("SPM Core setup done.\n"); 2900f14d02fSMax Shvetsov 291a334c4e6SOlivier Deprez /* Register power management hooks with PSCI */ 292a334c4e6SOlivier Deprez psci_register_spd_pm_hook(&spmd_pm); 293a334c4e6SOlivier Deprez 2940f14d02fSMax Shvetsov /* Register init function for deferred init. */ 2950f14d02fSMax Shvetsov bl31_register_bl32_init(&spmd_init); 2960f14d02fSMax Shvetsov 2970f14d02fSMax Shvetsov return 0; 2980f14d02fSMax Shvetsov } 2990f14d02fSMax Shvetsov 3000f14d02fSMax Shvetsov /******************************************************************************* 30152696946SOlivier Deprez * Initialize context of SPM Core. 302bdd2596dSAchin Gupta ******************************************************************************/ 3030f14d02fSMax Shvetsov int spmd_setup(void) 304bdd2596dSAchin Gupta { 30523d5ba86SOlivier Deprez void *spmc_manifest; 306bdd2596dSAchin Gupta int rc; 307bdd2596dSAchin Gupta 308bdd2596dSAchin Gupta spmc_ep_info = bl31_plat_get_next_image_ep_info(SECURE); 30952696946SOlivier Deprez if (spmc_ep_info == NULL) { 31052696946SOlivier Deprez WARN("No SPM Core image provided by BL2 boot loader.\n"); 31152696946SOlivier Deprez return -EINVAL; 312bdd2596dSAchin Gupta } 313bdd2596dSAchin Gupta 314bdd2596dSAchin Gupta /* Under no circumstances will this parameter be 0 */ 31552696946SOlivier Deprez assert(spmc_ep_info->pc != 0ULL); 316bdd2596dSAchin Gupta 317bdd2596dSAchin Gupta /* 318bdd2596dSAchin Gupta * Check if BL32 ep_info has a reference to 'tos_fw_config'. This will 31952696946SOlivier Deprez * be used as a manifest for the SPM Core at the next lower EL/mode. 320bdd2596dSAchin Gupta */ 32123d5ba86SOlivier Deprez spmc_manifest = (void *)spmc_ep_info->args.arg0; 32223d5ba86SOlivier Deprez if (spmc_manifest == NULL) { 32323d5ba86SOlivier Deprez ERROR("Invalid or absent SPM Core manifest.\n"); 32423d5ba86SOlivier Deprez return -EINVAL; 325bdd2596dSAchin Gupta } 326bdd2596dSAchin Gupta 3270f14d02fSMax Shvetsov /* Load manifest, init SPMC */ 32823d5ba86SOlivier Deprez rc = spmd_spmc_init(spmc_manifest); 3290f14d02fSMax Shvetsov if (rc != 0) { 33052696946SOlivier Deprez WARN("Booting device without SPM initialization.\n"); 331bdd2596dSAchin Gupta } 332bdd2596dSAchin Gupta 3330f14d02fSMax Shvetsov return rc; 3340f14d02fSMax Shvetsov } 3350f14d02fSMax Shvetsov 3360f14d02fSMax Shvetsov /******************************************************************************* 3370f14d02fSMax Shvetsov * Forward SMC to the other security state 3380f14d02fSMax Shvetsov ******************************************************************************/ 33952696946SOlivier Deprez static uint64_t spmd_smc_forward(uint32_t smc_fid, 34052696946SOlivier Deprez bool secure_origin, 34152696946SOlivier Deprez uint64_t x1, 34252696946SOlivier Deprez uint64_t x2, 34352696946SOlivier Deprez uint64_t x3, 34452696946SOlivier Deprez uint64_t x4, 34552696946SOlivier Deprez void *handle) 3460f14d02fSMax Shvetsov { 347c2901419SOlivier Deprez unsigned int secure_state_in = (secure_origin) ? SECURE : NON_SECURE; 348c2901419SOlivier Deprez unsigned int secure_state_out = (!secure_origin) ? SECURE : NON_SECURE; 34993ff138bSOlivier Deprez 3500f14d02fSMax Shvetsov /* Save incoming security state */ 35193ff138bSOlivier Deprez cm_el1_sysregs_context_save(secure_state_in); 352033039f8SMax Shvetsov #if SPMD_SPM_AT_SEL2 35393ff138bSOlivier Deprez cm_el2_sysregs_context_save(secure_state_in); 354033039f8SMax Shvetsov #endif 3550f14d02fSMax Shvetsov 3560f14d02fSMax Shvetsov /* Restore outgoing security state */ 35793ff138bSOlivier Deprez cm_el1_sysregs_context_restore(secure_state_out); 358033039f8SMax Shvetsov #if SPMD_SPM_AT_SEL2 35993ff138bSOlivier Deprez cm_el2_sysregs_context_restore(secure_state_out); 360033039f8SMax Shvetsov #endif 36193ff138bSOlivier Deprez cm_set_next_eret_context(secure_state_out); 3620f14d02fSMax Shvetsov 36393ff138bSOlivier Deprez SMC_RET8(cm_get_context(secure_state_out), smc_fid, x1, x2, x3, x4, 3640f14d02fSMax Shvetsov SMC_GET_GP(handle, CTX_GPREG_X5), 3650f14d02fSMax Shvetsov SMC_GET_GP(handle, CTX_GPREG_X6), 3660f14d02fSMax Shvetsov SMC_GET_GP(handle, CTX_GPREG_X7)); 3670f14d02fSMax Shvetsov } 3680f14d02fSMax Shvetsov 3690f14d02fSMax Shvetsov /******************************************************************************* 370662af36dSJ-Alves * Return FFA_ERROR with specified error code 3710f14d02fSMax Shvetsov ******************************************************************************/ 372662af36dSJ-Alves static uint64_t spmd_ffa_error_return(void *handle, int error_code) 3730f14d02fSMax Shvetsov { 374662af36dSJ-Alves SMC_RET8(handle, FFA_ERROR, 375662af36dSJ-Alves FFA_TARGET_INFO_MBZ, error_code, 376662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ, FFA_PARAM_MBZ, 377662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ); 378bdd2596dSAchin Gupta } 379bdd2596dSAchin Gupta 380f0d743dbSOlivier Deprez /******************************************************************************* 381f0d743dbSOlivier Deprez * spmd_check_address_in_binary_image 382f0d743dbSOlivier Deprez ******************************************************************************/ 383f0d743dbSOlivier Deprez bool spmd_check_address_in_binary_image(uint64_t address) 384f0d743dbSOlivier Deprez { 385f0d743dbSOlivier Deprez assert(!check_uptr_overflow(spmc_attrs.load_address, spmc_attrs.binary_size)); 386f0d743dbSOlivier Deprez 387f0d743dbSOlivier Deprez return ((address >= spmc_attrs.load_address) && 388f0d743dbSOlivier Deprez (address < (spmc_attrs.load_address + spmc_attrs.binary_size))); 389f0d743dbSOlivier Deprez } 390f0d743dbSOlivier Deprez 391c2901419SOlivier Deprez /****************************************************************************** 392c2901419SOlivier Deprez * spmd_is_spmc_message 393c2901419SOlivier Deprez *****************************************************************************/ 394c2901419SOlivier Deprez static bool spmd_is_spmc_message(unsigned int ep) 395c2901419SOlivier Deprez { 396c2901419SOlivier Deprez return ((ffa_endpoint_destination(ep) == SPMD_DIRECT_MSG_ENDPOINT_ID) 397c2901419SOlivier Deprez && (ffa_endpoint_source(ep) == spmc_attrs.spmc_id)); 398c2901419SOlivier Deprez } 399c2901419SOlivier Deprez 400f0d743dbSOlivier Deprez /****************************************************************************** 401f0d743dbSOlivier Deprez * spmd_handle_spmc_message 402f0d743dbSOlivier Deprez *****************************************************************************/ 403a92bc73bSOlivier Deprez static int spmd_handle_spmc_message(unsigned long long msg, 404a92bc73bSOlivier Deprez unsigned long long parm1, unsigned long long parm2, 405a92bc73bSOlivier Deprez unsigned long long parm3, unsigned long long parm4) 406f0d743dbSOlivier Deprez { 407f0d743dbSOlivier Deprez VERBOSE("%s %llx %llx %llx %llx %llx\n", __func__, 408f0d743dbSOlivier Deprez msg, parm1, parm2, parm3, parm4); 409f0d743dbSOlivier Deprez 410f0d743dbSOlivier Deprez switch (msg) { 411f0d743dbSOlivier Deprez case SPMD_DIRECT_MSG_SET_ENTRY_POINT: 412f0d743dbSOlivier Deprez return spmd_pm_secondary_core_set_ep(parm1, parm2, parm3); 413f0d743dbSOlivier Deprez default: 414f0d743dbSOlivier Deprez break; 415f0d743dbSOlivier Deprez } 416f0d743dbSOlivier Deprez 417f0d743dbSOlivier Deprez return -EINVAL; 418f0d743dbSOlivier Deprez } 419f0d743dbSOlivier Deprez 420bdd2596dSAchin Gupta /******************************************************************************* 421662af36dSJ-Alves * This function handles all SMCs in the range reserved for FFA. Each call is 422bdd2596dSAchin Gupta * either forwarded to the other security state or handled by the SPM dispatcher 423bdd2596dSAchin Gupta ******************************************************************************/ 42452696946SOlivier Deprez uint64_t spmd_smc_handler(uint32_t smc_fid, 42552696946SOlivier Deprez uint64_t x1, 42652696946SOlivier Deprez uint64_t x2, 42752696946SOlivier Deprez uint64_t x3, 42852696946SOlivier Deprez uint64_t x4, 42952696946SOlivier Deprez void *cookie, 43052696946SOlivier Deprez void *handle, 431bdd2596dSAchin Gupta uint64_t flags) 432bdd2596dSAchin Gupta { 43352696946SOlivier Deprez spmd_spm_core_context_t *ctx = spmd_get_context(); 43493ff138bSOlivier Deprez bool secure_origin; 43593ff138bSOlivier Deprez int32_t ret; 4364388f28fSJ-Alves uint32_t input_version; 437bdd2596dSAchin Gupta 438bdd2596dSAchin Gupta /* Determine which security state this SMC originated from */ 43993ff138bSOlivier Deprez secure_origin = is_caller_secure(flags); 440bdd2596dSAchin Gupta 44152696946SOlivier Deprez INFO("SPM: 0x%x 0x%llx 0x%llx 0x%llx 0x%llx 0x%llx 0x%llx 0x%llx\n", 442bdd2596dSAchin Gupta smc_fid, x1, x2, x3, x4, SMC_GET_GP(handle, CTX_GPREG_X5), 443bdd2596dSAchin Gupta SMC_GET_GP(handle, CTX_GPREG_X6), 444bdd2596dSAchin Gupta SMC_GET_GP(handle, CTX_GPREG_X7)); 445bdd2596dSAchin Gupta 446bdd2596dSAchin Gupta switch (smc_fid) { 447662af36dSJ-Alves case FFA_ERROR: 448bdd2596dSAchin Gupta /* 449bdd2596dSAchin Gupta * Check if this is the first invocation of this interface on 45052696946SOlivier Deprez * this CPU. If so, then indicate that the SPM Core initialised 451bdd2596dSAchin Gupta * unsuccessfully. 452bdd2596dSAchin Gupta */ 4539dcf63ddSOlivier Deprez if (secure_origin && (ctx->state == SPMC_STATE_ON_PENDING)) { 454bdd2596dSAchin Gupta spmd_spm_core_sync_exit(x2); 4550f14d02fSMax Shvetsov } 456bdd2596dSAchin Gupta 45793ff138bSOlivier Deprez return spmd_smc_forward(smc_fid, secure_origin, 4580f14d02fSMax Shvetsov x1, x2, x3, x4, handle); 459bdd2596dSAchin Gupta break; /* not reached */ 460bdd2596dSAchin Gupta 461662af36dSJ-Alves case FFA_VERSION: 4624388f28fSJ-Alves input_version = (uint32_t)(0xFFFFFFFF & x1); 463bdd2596dSAchin Gupta /* 4644388f28fSJ-Alves * If caller is secure and SPMC was initialized, 4654388f28fSJ-Alves * return FFA_VERSION of SPMD. 4664388f28fSJ-Alves * If caller is non secure and SPMC was initialized, 4674388f28fSJ-Alves * return SPMC's version. 4684388f28fSJ-Alves * Sanity check to "input_version". 469bdd2596dSAchin Gupta */ 4704388f28fSJ-Alves if ((input_version & FFA_VERSION_BIT31_MASK) || 4714388f28fSJ-Alves (ctx->state == SPMC_STATE_RESET)) { 4724388f28fSJ-Alves ret = FFA_ERROR_NOT_SUPPORTED; 4734388f28fSJ-Alves } else if (!secure_origin) { 4744388f28fSJ-Alves ret = MAKE_FFA_VERSION(spmc_attrs.major_version, spmc_attrs.minor_version); 4754388f28fSJ-Alves } else { 4764388f28fSJ-Alves ret = MAKE_FFA_VERSION(FFA_VERSION_MAJOR, FFA_VERSION_MINOR); 4774388f28fSJ-Alves } 4784388f28fSJ-Alves 4794388f28fSJ-Alves SMC_RET8(handle, ret, FFA_TARGET_INFO_MBZ, FFA_TARGET_INFO_MBZ, 480662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ, FFA_PARAM_MBZ, 481662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ); 482bdd2596dSAchin Gupta break; /* not reached */ 483bdd2596dSAchin Gupta 484662af36dSJ-Alves case FFA_FEATURES: 485bdd2596dSAchin Gupta /* 486bdd2596dSAchin Gupta * This is an optional interface. Do the minimal checks and 48752696946SOlivier Deprez * forward to SPM Core which will handle it if implemented. 488bdd2596dSAchin Gupta */ 489bdd2596dSAchin Gupta 490bdd2596dSAchin Gupta /* 491662af36dSJ-Alves * Check if x1 holds a valid FFA fid. This is an 492bdd2596dSAchin Gupta * optimization. 493bdd2596dSAchin Gupta */ 494662af36dSJ-Alves if (!is_ffa_fid(x1)) { 495662af36dSJ-Alves return spmd_ffa_error_return(handle, 496662af36dSJ-Alves FFA_ERROR_NOT_SUPPORTED); 4970f14d02fSMax Shvetsov } 498bdd2596dSAchin Gupta 49952696946SOlivier Deprez /* Forward SMC from Normal world to the SPM Core */ 50093ff138bSOlivier Deprez if (!secure_origin) { 50193ff138bSOlivier Deprez return spmd_smc_forward(smc_fid, secure_origin, 5020f14d02fSMax Shvetsov x1, x2, x3, x4, handle); 50352696946SOlivier Deprez } 50452696946SOlivier Deprez 505bdd2596dSAchin Gupta /* 506bdd2596dSAchin Gupta * Return success if call was from secure world i.e. all 507662af36dSJ-Alves * FFA functions are supported. This is essentially a 508bdd2596dSAchin Gupta * nop. 509bdd2596dSAchin Gupta */ 510662af36dSJ-Alves SMC_RET8(handle, FFA_SUCCESS_SMC32, x1, x2, x3, x4, 511bdd2596dSAchin Gupta SMC_GET_GP(handle, CTX_GPREG_X5), 512bdd2596dSAchin Gupta SMC_GET_GP(handle, CTX_GPREG_X6), 513bdd2596dSAchin Gupta SMC_GET_GP(handle, CTX_GPREG_X7)); 5140f14d02fSMax Shvetsov 515bdd2596dSAchin Gupta break; /* not reached */ 516bdd2596dSAchin Gupta 517662af36dSJ-Alves case FFA_ID_GET: 518ac03ac5eSMax Shvetsov /* 519662af36dSJ-Alves * Returns the ID of the calling FFA component. 520ac03ac5eSMax Shvetsov */ 521ac03ac5eSMax Shvetsov if (!secure_origin) { 522662af36dSJ-Alves SMC_RET8(handle, FFA_SUCCESS_SMC32, 523662af36dSJ-Alves FFA_TARGET_INFO_MBZ, FFA_NS_ENDPOINT_ID, 524662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ, 525662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ, 526662af36dSJ-Alves FFA_PARAM_MBZ); 52752696946SOlivier Deprez } 52852696946SOlivier Deprez 529662af36dSJ-Alves SMC_RET8(handle, FFA_SUCCESS_SMC32, 530662af36dSJ-Alves FFA_TARGET_INFO_MBZ, spmc_attrs.spmc_id, 531662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ, 532662af36dSJ-Alves FFA_PARAM_MBZ, FFA_PARAM_MBZ, 533662af36dSJ-Alves FFA_PARAM_MBZ); 534ac03ac5eSMax Shvetsov 535ac03ac5eSMax Shvetsov break; /* not reached */ 536ac03ac5eSMax Shvetsov 537f0d743dbSOlivier Deprez case FFA_MSG_SEND_DIRECT_REQ_SMC32: 538f0d743dbSOlivier Deprez if (secure_origin && spmd_is_spmc_message(x1)) { 539f0d743dbSOlivier Deprez ret = spmd_handle_spmc_message(x3, x4, 540f0d743dbSOlivier Deprez SMC_GET_GP(handle, CTX_GPREG_X5), 541f0d743dbSOlivier Deprez SMC_GET_GP(handle, CTX_GPREG_X6), 542f0d743dbSOlivier Deprez SMC_GET_GP(handle, CTX_GPREG_X7)); 543f0d743dbSOlivier Deprez 544f0d743dbSOlivier Deprez SMC_RET8(handle, FFA_SUCCESS_SMC32, 545f0d743dbSOlivier Deprez FFA_TARGET_INFO_MBZ, ret, 546f0d743dbSOlivier Deprez FFA_PARAM_MBZ, FFA_PARAM_MBZ, 547f0d743dbSOlivier Deprez FFA_PARAM_MBZ, FFA_PARAM_MBZ, 548f0d743dbSOlivier Deprez FFA_PARAM_MBZ); 549f0d743dbSOlivier Deprez } else { 550f0d743dbSOlivier Deprez /* Forward direct message to the other world */ 551f0d743dbSOlivier Deprez return spmd_smc_forward(smc_fid, secure_origin, 552f0d743dbSOlivier Deprez x1, x2, x3, x4, handle); 553f0d743dbSOlivier Deprez } 554f0d743dbSOlivier Deprez break; /* Not reached */ 555f0d743dbSOlivier Deprez 556f0d743dbSOlivier Deprez case FFA_MSG_SEND_DIRECT_RESP_SMC32: 557f0d743dbSOlivier Deprez if (secure_origin && spmd_is_spmc_message(x1)) { 558f0d743dbSOlivier Deprez spmd_spm_core_sync_exit(0); 559f0d743dbSOlivier Deprez } else { 560f0d743dbSOlivier Deprez /* Forward direct message to the other world */ 561f0d743dbSOlivier Deprez return spmd_smc_forward(smc_fid, secure_origin, 562f0d743dbSOlivier Deprez x1, x2, x3, x4, handle); 563f0d743dbSOlivier Deprez } 564f0d743dbSOlivier Deprez break; /* Not reached */ 565f0d743dbSOlivier Deprez 566662af36dSJ-Alves case FFA_RX_RELEASE: 567662af36dSJ-Alves case FFA_RXTX_MAP_SMC32: 568662af36dSJ-Alves case FFA_RXTX_MAP_SMC64: 569662af36dSJ-Alves case FFA_RXTX_UNMAP: 570545b8eb3SRuari Phipps case FFA_PARTITION_INFO_GET: 571545b8eb3SRuari Phipps /* 572545b8eb3SRuari Phipps * Should not be allowed to forward FFA_PARTITION_INFO_GET 573545b8eb3SRuari Phipps * from Secure world to Normal world 574545b8eb3SRuari Phipps * 575545b8eb3SRuari Phipps * Fall through to forward the call to the other world 576545b8eb3SRuari Phipps */ 577662af36dSJ-Alves case FFA_MSG_RUN: 578bdd2596dSAchin Gupta /* This interface must be invoked only by the Normal world */ 579545b8eb3SRuari Phipps 58093ff138bSOlivier Deprez if (secure_origin) { 581662af36dSJ-Alves return spmd_ffa_error_return(handle, 582662af36dSJ-Alves FFA_ERROR_NOT_SUPPORTED); 583bdd2596dSAchin Gupta } 584bdd2596dSAchin Gupta 585bdd2596dSAchin Gupta /* Fall through to forward the call to the other world */ 586662af36dSJ-Alves case FFA_MSG_SEND: 587662af36dSJ-Alves case FFA_MSG_SEND_DIRECT_REQ_SMC64: 588662af36dSJ-Alves case FFA_MSG_SEND_DIRECT_RESP_SMC64: 589662af36dSJ-Alves case FFA_MEM_DONATE_SMC32: 590662af36dSJ-Alves case FFA_MEM_DONATE_SMC64: 591662af36dSJ-Alves case FFA_MEM_LEND_SMC32: 592662af36dSJ-Alves case FFA_MEM_LEND_SMC64: 593662af36dSJ-Alves case FFA_MEM_SHARE_SMC32: 594662af36dSJ-Alves case FFA_MEM_SHARE_SMC64: 595662af36dSJ-Alves case FFA_MEM_RETRIEVE_REQ_SMC32: 596662af36dSJ-Alves case FFA_MEM_RETRIEVE_REQ_SMC64: 597662af36dSJ-Alves case FFA_MEM_RETRIEVE_RESP: 598662af36dSJ-Alves case FFA_MEM_RELINQUISH: 599662af36dSJ-Alves case FFA_MEM_RECLAIM: 600662af36dSJ-Alves case FFA_SUCCESS_SMC32: 601662af36dSJ-Alves case FFA_SUCCESS_SMC64: 602bdd2596dSAchin Gupta /* 603bdd2596dSAchin Gupta * TODO: Assume that no requests originate from EL3 at the 604bdd2596dSAchin Gupta * moment. This will change if a SP service is required in 605bdd2596dSAchin Gupta * response to secure interrupts targeted to EL3. Until then 606bdd2596dSAchin Gupta * simply forward the call to the Normal world. 607bdd2596dSAchin Gupta */ 608bdd2596dSAchin Gupta 60993ff138bSOlivier Deprez return spmd_smc_forward(smc_fid, secure_origin, 6100f14d02fSMax Shvetsov x1, x2, x3, x4, handle); 611bdd2596dSAchin Gupta break; /* not reached */ 612bdd2596dSAchin Gupta 613662af36dSJ-Alves case FFA_MSG_WAIT: 614bdd2596dSAchin Gupta /* 615bdd2596dSAchin Gupta * Check if this is the first invocation of this interface on 616bdd2596dSAchin Gupta * this CPU from the Secure world. If so, then indicate that the 61752696946SOlivier Deprez * SPM Core initialised successfully. 618bdd2596dSAchin Gupta */ 6199dcf63ddSOlivier Deprez if (secure_origin && (ctx->state == SPMC_STATE_ON_PENDING)) { 620bdd2596dSAchin Gupta spmd_spm_core_sync_exit(0); 621bdd2596dSAchin Gupta } 622bdd2596dSAchin Gupta 6230f14d02fSMax Shvetsov /* Fall through to forward the call to the other world */ 624bdd2596dSAchin Gupta 625662af36dSJ-Alves case FFA_MSG_YIELD: 626bdd2596dSAchin Gupta /* This interface must be invoked only by the Secure world */ 62793ff138bSOlivier Deprez if (!secure_origin) { 628662af36dSJ-Alves return spmd_ffa_error_return(handle, 629662af36dSJ-Alves FFA_ERROR_NOT_SUPPORTED); 630bdd2596dSAchin Gupta } 631bdd2596dSAchin Gupta 63293ff138bSOlivier Deprez return spmd_smc_forward(smc_fid, secure_origin, 6330f14d02fSMax Shvetsov x1, x2, x3, x4, handle); 634bdd2596dSAchin Gupta break; /* not reached */ 635bdd2596dSAchin Gupta 636bdd2596dSAchin Gupta default: 637bdd2596dSAchin Gupta WARN("SPM: Unsupported call 0x%08x\n", smc_fid); 638662af36dSJ-Alves return spmd_ffa_error_return(handle, FFA_ERROR_NOT_SUPPORTED); 639bdd2596dSAchin Gupta } 640bdd2596dSAchin Gupta } 641