mirror of
https://git.yoctoproject.org/meta-arm
synced 2026-07-19 16:57:09 +00:00
Compare commits
279 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9bcc166bd5 | |||
| 0e35e4b951 | |||
| bbe2d63100 | |||
| 2b57548b36 | |||
| c6380674f5 | |||
| 6e199b354e | |||
| 7c67197694 | |||
| 85b0e80e7d | |||
| 821fa15a73 | |||
| 18edb7bcff | |||
| 10c355b9c7 | |||
| 1a15a5b052 | |||
| 0bf2afab93 | |||
| c1201c0c3a | |||
| fd7cb4d462 | |||
| 7d4cc90156 | |||
| 1bfb03f9a6 | |||
| bef3c42e38 | |||
| 779594c5d8 | |||
| bd0c162e37 | |||
| 4a946ac8de | |||
| d0b423c63c | |||
| 5024b767e3 | |||
| 00bff355e5 | |||
| 4a7198a135 | |||
| 7bd239d4f3 | |||
| b1a9fd76be | |||
| 58a97781d5 | |||
| e995c42311 | |||
| 5e05b281f4 | |||
| cb811a559b | |||
| 0d7ee992c1 | |||
| 45206b21b9 | |||
| 5c19e4a87a | |||
| 065e86ab5f | |||
| b3c96e3fc3 | |||
| 48abf0167d | |||
| adea344855 | |||
| 809d2b43f9 | |||
| 15d6b7c4e9 | |||
| 2ffe50d4b5 | |||
| b25e1ef90d | |||
| 8db460fa5d | |||
| 36f77ab664 | |||
| 6850977577 | |||
| 91b504e686 | |||
| 50624c6f2f | |||
| 0b5724266a | |||
| c60d7865dd | |||
| 7f0c57f7c6 | |||
| 95e535b0a1 | |||
| b3c7b2d7a5 | |||
| ea407ce849 | |||
| 6405018ced | |||
| a091d49db1 | |||
| 1596147a84 | |||
| 387465c622 | |||
| a46ddc804e | |||
| 2d8bc0be8e | |||
| 173c9d887e | |||
| f54a9f37eb | |||
| 524203dc17 | |||
| 323362f682 | |||
| 0b528b731a | |||
| efa053885f | |||
| 5da8393712 | |||
| 1f2e4e7ff5 | |||
| 3a7f746057 | |||
| 32908f1f9e | |||
| 8f62e0bff8 | |||
| 8acd61c427 | |||
| 5a62ce8561 | |||
| 0e5f5ac81f | |||
| 794c7bfd12 | |||
| d2661fa7c0 | |||
| 50e74acd97 | |||
| 3b4ab43d2f | |||
| 9e57aa4f50 | |||
| b3c60cd3fa | |||
| 91725e95c9 | |||
| 9b6c8c95e4 | |||
| 9171569eb3 | |||
| 0483b73a4c | |||
| 92f6b82929 | |||
| 24eb1a9775 | |||
| 2be960d8b7 | |||
| df726cbfad | |||
| 1caacf78c7 | |||
| 2db12df861 | |||
| 21092272fd | |||
| 99a3b07d52 | |||
| b39fc31d76 | |||
| dcc81b56ff | |||
| fa5fffd287 | |||
| 8b581f3de3 | |||
| 4bfa191ada | |||
| e7c5876380 | |||
| b55cd3d627 | |||
| 360a278c44 | |||
| 1da8d2fdb5 | |||
| 27125aff1c | |||
| 7c8ce7f5a0 | |||
| eb9c47a4e1 | |||
| d5c024f1f5 | |||
| 68aae5fcaf | |||
| a208647149 | |||
| eab2a4a0c1 | |||
| a947750cbc | |||
| dca1c18725 | |||
| 19767152e3 | |||
| f474a0fee9 | |||
| 064a97e745 | |||
| de82f2269b | |||
| 81aaae5754 | |||
| 1f6d2b2692 | |||
| 19452d568f | |||
| b3ac88b4e8 | |||
| cbe0ce7992 | |||
| 1fdb75d465 | |||
| fd3b56802e | |||
| 047be751ca | |||
| 69b73682b3 | |||
| c5bf035490 | |||
| ae3b219887 | |||
| 402cfcc4e8 | |||
| 93f5170eb2 | |||
| 7fee7ee600 | |||
| 557e89242e | |||
| ac39c6d4cc | |||
| ae0dd2a58c | |||
| 3af64cee5b | |||
| f0945f499c | |||
| 5914ae11f4 | |||
| 79b44a4d32 | |||
| 0617555fa5 | |||
| 3d39ae853c | |||
| 0d7489a055 | |||
| dc10b73cc5 | |||
| 70fbe7fe12 | |||
| 37fd476ae1 | |||
| 894e309eaf | |||
| 03574e9173 | |||
| 30796fb798 | |||
| 5577b38164 | |||
| 47872289ae | |||
| 4704bf1292 | |||
| 8891820e97 | |||
| 7ac8d1e2a5 | |||
| aecbb77f72 | |||
| b1a9035176 | |||
| e545d4ce5d | |||
| 834f5aa990 | |||
| 3d51e1117d | |||
| 508ed52a4f | |||
| 23feaec9b4 | |||
| 99b769e6ce | |||
| bf204866e8 | |||
| d8383c11f3 | |||
| 1b8ee250f3 | |||
| 94f28592ad | |||
| 33b816e03a | |||
| 9166b5deee | |||
| cf43a3c398 | |||
| 9b6457de82 | |||
| 12cd5e1859 | |||
| 0099eee0d0 | |||
| 15e59127ee | |||
| dc36e1de6b | |||
| 513d085a16 | |||
| 6b98584ae3 | |||
| a51d4704cc | |||
| 3f35573acb | |||
| a7d911310e | |||
| 314b3b2eb7 | |||
| d3a0c441cd | |||
| 725281582a | |||
| fdf95798bc | |||
| d9db8b7075 | |||
| bba5bc9138 | |||
| 146e9a5178 | |||
| c0f3a83179 | |||
| f7fafc58a1 | |||
| 393e37c90e | |||
| 5c42f084f7 | |||
| ddc67dc4bb | |||
| 0c4bfbe40a | |||
| befd9f1567 | |||
| 8015efe2f1 | |||
| a6211b6067 | |||
| 529d18e8a5 | |||
| 3d9c97a0cc | |||
| 3259a2a840 | |||
| b061104c87 | |||
| ef20a1c9b5 | |||
| 74f0ce7028 | |||
| 95f83818ab | |||
| a57d99be63 | |||
| 9952e98bb5 | |||
| 64b51c5e5c | |||
| 4d87fe01d1 | |||
| 132089830b | |||
| c7b85230a2 | |||
| 64d1f783b9 | |||
| dafc5ec028 | |||
| bd12f11348 | |||
| 1bdc38cdb7 | |||
| 391265fe3f | |||
| 52bbe75624 | |||
| 29b5d0df19 | |||
| 735f560aeb | |||
| c32c4043ff | |||
| 1ba7d646da | |||
| 37bc037bea | |||
| 0e398c77ec | |||
| b5909b7bc4 | |||
| f39f483e4d | |||
| 02b430d045 | |||
| fd57859e18 | |||
| 05ce44eb40 | |||
| e407b94815 | |||
| 9699e6698e | |||
| e695d0ee25 | |||
| 8023f902ac | |||
| 29fa253f00 | |||
| dacbabae70 | |||
| 3786d6d016 | |||
| ffd0aca508 | |||
| 11698cd358 | |||
| f7c9f58eeb | |||
| 7fcff00498 | |||
| 23aed71692 | |||
| 7b4c17632d | |||
| a68a2a206e | |||
| d5f132b199 | |||
| 79e78fb31d | |||
| 2265bffdc7 | |||
| 81e0cf090b | |||
| 721bec250d | |||
| c97a9c5b39 | |||
| f52d4f63d7 | |||
| 129dcef079 | |||
| fcf6f0699c | |||
| bdf559155a | |||
| d5f68b256d | |||
| f6ae857b04 | |||
| 53d592c6de | |||
| 2132c21a87 | |||
| 24f2eea0a5 | |||
| ff583cd9a1 | |||
| 11018cbc35 | |||
| b772d97496 | |||
| 4243e66182 | |||
| 8724733e07 | |||
| 3b7347cd67 | |||
| 59c3e948e8 | |||
| 75c252049c | |||
| 49b23ff619 | |||
| 7683a6d1d1 | |||
| 3080a94bde | |||
| 518294d518 | |||
| 8d7f3c03ef | |||
| 50cd8f9c9f | |||
| 0e7c1bb30e | |||
| 30e78c0552 | |||
| d1666f4da2 | |||
| 9771beb103 | |||
| bcba4a6c5f | |||
| dc4a702aaf | |||
| 8bde04ca23 | |||
| ba41fd5e1e | |||
| 2fffdd9234 | |||
| ba196a90a7 | |||
| a8075e1471 | |||
| a27735f0d6 | |||
| 3e7dc144b1 | |||
| 7730ae58ac | |||
| 242023336f | |||
| 14c7e5b336 | |||
| f83c5ad19e |
@@ -1 +1,2 @@
|
|||||||
__pycache__
|
__pycache__
|
||||||
|
build
|
||||||
|
|||||||
+91
-45
@@ -1,4 +1,13 @@
|
|||||||
image: ghcr.io/siemens/kas/kas:latest-release
|
image: ghcr.io/siemens/kas/kas:3.2.3
|
||||||
|
|
||||||
|
variables:
|
||||||
|
CPU_REQUEST: ""
|
||||||
|
DEFAULT_TAG: ""
|
||||||
|
CACHE_DIR: $CI_BUILDS_DIR/persist
|
||||||
|
# These are needed as the k8s executor doesn't respect the container entrypoint
|
||||||
|
# by default
|
||||||
|
FF_KUBERNETES_HONOR_ENTRYPOINT: 1
|
||||||
|
FF_USE_LEGACY_KUBERNETES_EXECUTION_STRATEGY: 0
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
- prep
|
- prep
|
||||||
@@ -6,15 +15,17 @@ stages:
|
|||||||
|
|
||||||
# Common job fragment to get a worker ready
|
# Common job fragment to get a worker ready
|
||||||
.setup:
|
.setup:
|
||||||
|
tags:
|
||||||
|
- $DEFAULT_TAG
|
||||||
stage: build
|
stage: build
|
||||||
interruptible: true
|
interruptible: true
|
||||||
variables:
|
variables:
|
||||||
KAS_WORK_DIR: $CI_PROJECT_DIR/work
|
KAS_WORK_DIR: $CI_PROJECT_DIR/work
|
||||||
KAS_REPO_REF_DIR: $CI_BUILDS_DIR/persist/repos
|
KAS_REPO_REF_DIR: $CACHE_DIR/repos
|
||||||
SSTATE_DIR: $CI_BUILDS_DIR/persist/sstate
|
SSTATE_DIR: $CACHE_DIR/sstate
|
||||||
DL_DIR: $CI_BUILDS_DIR/persist/downloads
|
DL_DIR: $CACHE_DIR/downloads
|
||||||
BB_LOGCONFIG: $CI_PROJECT_DIR/ci/logging.yml
|
BB_LOGCONFIG: $CI_PROJECT_DIR/ci/logging.yml
|
||||||
TOOLCHAIN_DIR: $CI_BUILDS_DIR/persist/toolchains
|
TOOLCHAIN_DIR: $CACHE_DIR/toolchains
|
||||||
IMAGE_DIR: $CI_PROJECT_DIR/work/build/tmp/deploy/images
|
IMAGE_DIR: $CI_PROJECT_DIR/work/build/tmp/deploy/images
|
||||||
TOOLCHAIN_LINK_DIR: $CI_PROJECT_DIR/work/build/toolchains
|
TOOLCHAIN_LINK_DIR: $CI_PROJECT_DIR/work/build/toolchains
|
||||||
before_script:
|
before_script:
|
||||||
@@ -25,14 +36,30 @@ stages:
|
|||||||
- mkdir --verbose --parents $KAS_WORK_DIR $KAS_REPO_REF_DIR $SSTATE_DIR $DL_DIR $TOOLCHAIN_DIR $TOOLCHAIN_LINK_DIR
|
- mkdir --verbose --parents $KAS_WORK_DIR $KAS_REPO_REF_DIR $SSTATE_DIR $DL_DIR $TOOLCHAIN_DIR $TOOLCHAIN_LINK_DIR
|
||||||
# Must do this here, as it's the only way to make sure the toolchain is installed on the same builder
|
# Must do this here, as it's the only way to make sure the toolchain is installed on the same builder
|
||||||
- ./ci/get-binary-toolchains $DL_DIR $TOOLCHAIN_DIR $TOOLCHAIN_LINK_DIR
|
- ./ci/get-binary-toolchains $DL_DIR $TOOLCHAIN_DIR $TOOLCHAIN_LINK_DIR
|
||||||
- sudo apt-get update && sudo apt-get install --yes telnet python3-subunit
|
|
||||||
|
|
||||||
# Generalised fragment to do a Kas build
|
# Generalised fragment to do a Kas build
|
||||||
.build:
|
.build:
|
||||||
extends: .setup
|
extends: .setup
|
||||||
|
variables:
|
||||||
|
KUBERNETES_CPU_REQUEST: $CPU_REQUEST
|
||||||
|
rules:
|
||||||
|
# Don't run MR pipelines
|
||||||
|
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
|
||||||
|
when: never
|
||||||
|
# Don't run pipelines for tags
|
||||||
|
- if: $CI_COMMIT_TAG
|
||||||
|
when: never
|
||||||
|
# Don't run if BUILD_ENABLE_REGEX is set, but the job doesn't match the regex
|
||||||
|
- if: '$BUILD_ENABLE_REGEX != null && $CI_JOB_NAME !~ $BUILD_ENABLE_REGEX'
|
||||||
|
when: never
|
||||||
|
# Allow the dev kernels to fail and not fail the overall build
|
||||||
|
- if: '$KERNEL == "linux-yocto-dev"'
|
||||||
|
allow_failure: true
|
||||||
|
# Catch all for everything else
|
||||||
|
- if: '$KERNEL != "linux-yocto-dev"'
|
||||||
script:
|
script:
|
||||||
- KASFILES=$(./ci/jobs-to-kas "$CI_JOB_NAME")
|
- KASFILES=$(./ci/jobs-to-kas "$CI_JOB_NAME")
|
||||||
- kas shell --update --force-checkout $KASFILES -c 'cat conf/*.conf'
|
- kas dump --update --force-checkout --resolve-refs --resolve-env $KASFILES
|
||||||
- kas build $KASFILES
|
- kas build $KASFILES
|
||||||
- ./ci/check-warnings $KAS_WORK_DIR/build/warnings.log
|
- ./ci/check-warnings $KAS_WORK_DIR/build/warnings.log
|
||||||
artifacts:
|
artifacts:
|
||||||
@@ -40,9 +67,11 @@ stages:
|
|||||||
when: on_failure
|
when: on_failure
|
||||||
paths:
|
paths:
|
||||||
- $CI_PROJECT_DIR/work/build/tmp/work*/**/temp/log.do_*.*
|
- $CI_PROJECT_DIR/work/build/tmp/work*/**/temp/log.do_*.*
|
||||||
|
- $CI_PROJECT_DIR/work/build/tmp/work*/**/testimage/*
|
||||||
|
|
||||||
#
|
#
|
||||||
# Prep stage, update repositories once
|
# Prep stage, update repositories once.
|
||||||
|
# Set the CI variable CI_CLEAN_REPOS=1 to refetch the respositories from scratch
|
||||||
#
|
#
|
||||||
update-repos:
|
update-repos:
|
||||||
extends: .setup
|
extends: .setup
|
||||||
@@ -54,9 +83,12 @@ update-repos:
|
|||||||
# Build stage, the actual build jobs
|
# Build stage, the actual build jobs
|
||||||
#
|
#
|
||||||
# Available options for building are
|
# Available options for building are
|
||||||
|
# DISTRO: [poky, poky-tiny]
|
||||||
|
# KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
# TOOLCHAINS: [gcc, clang, armgcc, external-gccarm]
|
# TOOLCHAINS: [gcc, clang, armgcc, external-gccarm]
|
||||||
# TCLIBC: [glibc, musl]
|
# TCLIBC: [glibc, musl]
|
||||||
# FIRMWARE: [uboot, edk2]
|
# FIRMWARE: [u-boot, edk2]
|
||||||
|
# TS: [none, trusted-services]
|
||||||
# VIRT: [none, xen]
|
# VIRT: [none, xen]
|
||||||
# TESTING: testimage
|
# TESTING: testimage
|
||||||
|
|
||||||
@@ -72,7 +104,7 @@ corstone1000-fvp:
|
|||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TESTING: [testimage,tftf]
|
- TESTING: [testimage, tftf]
|
||||||
tags:
|
tags:
|
||||||
- x86_64
|
- x86_64
|
||||||
|
|
||||||
@@ -84,17 +116,7 @@ fvp-base:
|
|||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TESTING: testimage
|
- TESTING: testimage
|
||||||
tags:
|
- FIRMWARE: edk2
|
||||||
- x86_64
|
|
||||||
|
|
||||||
fvp-base-arm32:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- TOOLCHAINS: [gcc, external-gccarm]
|
|
||||||
TESTING: testimage
|
|
||||||
tags:
|
|
||||||
- x86_64
|
|
||||||
|
|
||||||
fvp-baser-aemv8r64:
|
fvp-baser-aemv8r64:
|
||||||
extends: .build
|
extends: .build
|
||||||
@@ -107,15 +129,6 @@ fvp-baser-aemv8r64:
|
|||||||
fvps:
|
fvps:
|
||||||
extends: .build
|
extends: .build
|
||||||
|
|
||||||
gem5-arm64:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- VIRT: [none, xen]
|
|
||||||
|
|
||||||
gem5-atp-arm64:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
generic-arm64:
|
generic-arm64:
|
||||||
extends: .build
|
extends: .build
|
||||||
|
|
||||||
@@ -124,7 +137,7 @@ juno:
|
|||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, clang]
|
- TOOLCHAINS: [gcc, clang]
|
||||||
FIRMWARE: [uboot, edk2]
|
FIRMWARE: [u-boot, edk2]
|
||||||
|
|
||||||
musca-b1:
|
musca-b1:
|
||||||
extends: .build
|
extends: .build
|
||||||
@@ -137,29 +150,36 @@ n1sdp:
|
|||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, armgcc]
|
- TOOLCHAINS: [gcc, armgcc]
|
||||||
|
TS: [none, n1sdp-ts]
|
||||||
|
|
||||||
qemu-generic-arm64:
|
qemu-generic-arm64:
|
||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, clang]
|
- KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
TESTING: testimage
|
TESTING: testimage
|
||||||
|
|
||||||
qemuarm64-secureboot:
|
qemuarm64-secureboot:
|
||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, clang]
|
- KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
TCLIBC: [glibc, musl]
|
TCLIBC: [glibc, musl]
|
||||||
TS: [none, trusted-services]
|
TS: [none, qemuarm64-secureboot-ts]
|
||||||
TESTING: testimage
|
TESTING: testimage
|
||||||
|
|
||||||
qemuarm64:
|
qemuarm64:
|
||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, clang]
|
- DISTRO: poky
|
||||||
EFI: [uboot, edk2]
|
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
FIRMWARE: [u-boot, edk2]
|
||||||
|
TESTING: testimage
|
||||||
|
- DISTRO: poky-tiny
|
||||||
TESTING: testimage
|
TESTING: testimage
|
||||||
- VIRT: xen
|
- VIRT: xen
|
||||||
|
|
||||||
@@ -167,15 +187,20 @@ qemuarm-secureboot:
|
|||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, clang]
|
- KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang, external-gccarm]
|
||||||
TESTING: testimage
|
TESTING: testimage
|
||||||
|
|
||||||
qemuarm:
|
qemuarm:
|
||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TOOLCHAINS: [gcc, clang]
|
- DISTRO: poky
|
||||||
EFI: [uboot, edk2]
|
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
FIRMWARE: [u-boot, edk2]
|
||||||
|
TESTING: testimage
|
||||||
|
- DISTRO: poky-tiny
|
||||||
TESTING: testimage
|
TESTING: testimage
|
||||||
- VIRT: xen
|
- VIRT: xen
|
||||||
|
|
||||||
@@ -183,13 +208,20 @@ qemuarmv5:
|
|||||||
extends: .build
|
extends: .build
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TESTING: testimage
|
- DISTRO: poky
|
||||||
|
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TESTING: testimage
|
||||||
|
- DISTRO: poky-tiny
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
sgi575:
|
sgi575:
|
||||||
extends: .build
|
extends: .build
|
||||||
|
|
||||||
tc1:
|
tc1:
|
||||||
extends: .build
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- TESTING: testimage
|
||||||
tags:
|
tags:
|
||||||
- x86_64
|
- x86_64
|
||||||
|
|
||||||
@@ -210,7 +242,7 @@ check-layers:
|
|||||||
"yocto-check-layer-wrapper $CI_PROJECT_DIR/$LAYER --dependency $CI_PROJECT_DIR/meta-* $KAS_WORK_DIR/meta-openembedded/meta-oe --no-auto-dependency"
|
"yocto-check-layer-wrapper $CI_PROJECT_DIR/$LAYER --dependency $CI_PROJECT_DIR/meta-* $KAS_WORK_DIR/meta-openembedded/meta-oe --no-auto-dependency"
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- LAYER: [meta-arm, meta-arm-bsp, meta-arm-toolchain, meta-gem5]
|
- LAYER: [meta-arm, meta-arm-bsp, meta-arm-toolchain]
|
||||||
|
|
||||||
pending-updates:
|
pending-updates:
|
||||||
extends: .setup
|
extends: .setup
|
||||||
@@ -220,16 +252,15 @@ pending-updates:
|
|||||||
script:
|
script:
|
||||||
- rm -fr update-report
|
- rm -fr update-report
|
||||||
# This configuration has all of the layers we need enabled
|
# This configuration has all of the layers we need enabled
|
||||||
- kas shell ci/gem5-arm64.yml --command \
|
- kas shell --update --force-checkout ci/qemuarm64.yml:ci/meta-openembedded.yml --command \
|
||||||
"$CI_PROJECT_DIR/scripts/machine-summary.py -t report -o $CI_PROJECT_DIR/update-report $($CI_PROJECT_DIR/ci/listmachines.py meta-arm meta-arm-bsp meta-gem5)"
|
"$CI_PROJECT_DIR/scripts/machine-summary.py -t report -o $CI_PROJECT_DIR/update-report $($CI_PROJECT_DIR/ci/listmachines.py meta-arm meta-arm-bsp)"
|
||||||
# Do this on x86 whilst the compilers are x86-only
|
# Do this on x86 whilst the compilers are x86-only
|
||||||
tags:
|
tags:
|
||||||
- x86_64
|
- x86_64
|
||||||
|
|
||||||
# What percentage of machines in the layer do we build
|
# What percentage of machines in the layer do we build
|
||||||
machine-coverage:
|
machine-coverage:
|
||||||
stage: build
|
extends: .setup
|
||||||
interruptible: true
|
|
||||||
script:
|
script:
|
||||||
- ./ci/check-machine-coverage
|
- ./ci/check-machine-coverage
|
||||||
coverage: '/Coverage: \d+/'
|
coverage: '/Coverage: \d+/'
|
||||||
@@ -242,3 +273,18 @@ metrics:
|
|||||||
script:
|
script:
|
||||||
- kas shell --update --force-checkout ci/base.yml --command \
|
- kas shell --update --force-checkout ci/base.yml --command \
|
||||||
"$CI_PROJECT_DIR/ci/patchreview $CI_PROJECT_DIR/meta-* --verbose --metrics $CI_PROJECT_DIR/metrics.txt"
|
"$CI_PROJECT_DIR/ci/patchreview $CI_PROJECT_DIR/meta-* --verbose --metrics $CI_PROJECT_DIR/metrics.txt"
|
||||||
|
|
||||||
|
documentation:
|
||||||
|
extends: .setup
|
||||||
|
script:
|
||||||
|
- |
|
||||||
|
sudo pip3 install -r meta-arm-bsp/documentation/requirements.txt
|
||||||
|
for CONF in meta-*/documentation/*/conf.py ; do
|
||||||
|
SOURCE_DIR=$(dirname $CONF)
|
||||||
|
MACHINE=$(basename $SOURCE_DIR)
|
||||||
|
sphinx-build -vW $SOURCE_DIR build-docs/$MACHINE
|
||||||
|
done
|
||||||
|
test -d build-docs/
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- build-docs/
|
||||||
|
|||||||
@@ -6,10 +6,6 @@ This repository contains the Arm layers for OpenEmbedded.
|
|||||||
|
|
||||||
This layer contains general recipes for the Arm architecture, such as firmware, FVPs, and Arm-specific integration.
|
This layer contains general recipes for the Arm architecture, such as firmware, FVPs, and Arm-specific integration.
|
||||||
|
|
||||||
* meta-arm-autonomy
|
|
||||||
|
|
||||||
This layer is the distribution for a reference stack for autonomous systems.
|
|
||||||
|
|
||||||
* meta-arm-bsp
|
* meta-arm-bsp
|
||||||
|
|
||||||
This layer contains machines for Arm reference platforms, for example FVP Base, N1SDP, and Juno.
|
This layer contains machines for Arm reference platforms, for example FVP Base, N1SDP, and Juno.
|
||||||
@@ -18,15 +14,6 @@ This repository contains the Arm layers for OpenEmbedded.
|
|||||||
|
|
||||||
This layer contains recipes for Arm's binary toolchains (GCC and Clang for -A and -M), and a recipe to build Arm's GCC.
|
This layer contains recipes for Arm's binary toolchains (GCC and Clang for -A and -M), and a recipe to build Arm's GCC.
|
||||||
|
|
||||||
* meta-atp
|
|
||||||
|
|
||||||
This layer contains recipes for the Adaptive Traffic Generation integration into meta-gem5.
|
|
||||||
|
|
||||||
* meta-gem5
|
|
||||||
|
|
||||||
This layer contains recipes and machines for gem5, a system-level and processor simulator.
|
|
||||||
|
|
||||||
|
|
||||||
Other Directories
|
Other Directories
|
||||||
-----------------
|
-----------------
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -3,4 +3,4 @@ header:
|
|||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
cc: |
|
cc: |
|
||||||
GCCVERSION = "arm-11.3"
|
GCCVERSION = "arm-12.2"
|
||||||
|
|||||||
+4
-9
@@ -5,7 +5,7 @@ distro: poky
|
|||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
repos:
|
repos:
|
||||||
refspec: master
|
refspec: mickledore
|
||||||
|
|
||||||
repos:
|
repos:
|
||||||
meta-arm:
|
meta-arm:
|
||||||
@@ -26,13 +26,7 @@ env:
|
|||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
base: |
|
base: |
|
||||||
BB_SERVER_TIMEOUT = "60"
|
|
||||||
CONF_VERSION = "2"
|
CONF_VERSION = "2"
|
||||||
BB_NUMBER_THREADS = "16"
|
|
||||||
PARALLEL_MAKE = "-j16"
|
|
||||||
XZ_MEMLIMIT = "25%"
|
|
||||||
XZ_THREADS = "16"
|
|
||||||
ZSTD_THREADS = "16"
|
|
||||||
LICENSE_FLAGS_ACCEPTED += "Arm-FVP-EULA"
|
LICENSE_FLAGS_ACCEPTED += "Arm-FVP-EULA"
|
||||||
setup: |
|
setup: |
|
||||||
PACKAGE_CLASSES = "package_ipk"
|
PACKAGE_CLASSES = "package_ipk"
|
||||||
@@ -41,8 +35,9 @@ local_conf_header:
|
|||||||
PACKAGECONFIG:append:pn-perf = " coresight"
|
PACKAGECONFIG:append:pn-perf = " coresight"
|
||||||
INHERIT += "rm_work"
|
INHERIT += "rm_work"
|
||||||
DISTRO_FEATURES:remove = "ptest"
|
DISTRO_FEATURES:remove = "ptest"
|
||||||
perf: |
|
extrapackages: |
|
||||||
CORE_IMAGE_EXTRA_INSTALL += "perf"
|
CORE_IMAGE_EXTRA_INSTALL += "perf opencsd"
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL:append:aarch64 = " gator-daemon"
|
||||||
|
|
||||||
machine: unset
|
machine: unset
|
||||||
|
|
||||||
|
|||||||
+4
-1
@@ -6,5 +6,8 @@ repos:
|
|||||||
url: https://github.com/kraj/meta-clang
|
url: https://github.com/kraj/meta-clang
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
clang: |
|
toolchain: |
|
||||||
TOOLCHAIN = "clang"
|
TOOLCHAIN = "clang"
|
||||||
|
# This is needed to stop bitbake getting confused about what clang/llvm is
|
||||||
|
# being used, see https://github.com/kraj/meta-clang/pull/766
|
||||||
|
BBMASK += "/meta/recipes-devtools/llvm/llvm.*\.bb"
|
||||||
|
|||||||
@@ -3,13 +3,12 @@ header:
|
|||||||
includes:
|
includes:
|
||||||
- ci/base.yml
|
- ci/base.yml
|
||||||
- ci/meta-openembedded.yml
|
- ci/meta-openembedded.yml
|
||||||
|
- ci/poky-tiny.yml
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
perf: |
|
extrapackages: |
|
||||||
# Intentionally blank to prevent perf from being added to the image in base.yml
|
# Intentionally blank to prevent perf from being added to the image in base.yml
|
||||||
|
|
||||||
distro: poky-tiny
|
|
||||||
|
|
||||||
target:
|
target:
|
||||||
- corstone1000-image
|
- corstone1000-image
|
||||||
- perf
|
- perf
|
||||||
|
|||||||
@@ -2,11 +2,11 @@ header:
|
|||||||
version: 11
|
version: 11
|
||||||
includes:
|
includes:
|
||||||
- ci/corstone1000-common.yml
|
- ci/corstone1000-common.yml
|
||||||
|
- ci/fvp.yml
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
fvp-config: |
|
fvp-config: |
|
||||||
# Remove Dropbear SSH as it will not fit into the corstone1000 image.
|
# Remove Dropbear SSH as it will not fit into the corstone1000 image.
|
||||||
IMAGE_FEATURES:remove = " ssh-server-dropbear"
|
IMAGE_FEATURES:remove = " ssh-server-dropbear"
|
||||||
INHERIT += "fvpboot"
|
|
||||||
|
|
||||||
machine: corstone1000-fvp
|
machine: corstone1000-fvp
|
||||||
|
|||||||
+3
-10
@@ -2,18 +2,11 @@ header:
|
|||||||
version: 11
|
version: 11
|
||||||
includes:
|
includes:
|
||||||
- ci/base.yml
|
- ci/base.yml
|
||||||
|
- ci/fvp.yml
|
||||||
|
- ci/poky-tiny.yml
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
testimagefvp: |
|
fvp-config: |
|
||||||
INHERIT += "fvpboot"
|
|
||||||
IMAGE_FEATURES:remove = " ssh-server-dropbear"
|
IMAGE_FEATURES:remove = " ssh-server-dropbear"
|
||||||
perf: |
|
|
||||||
# Intentionally blank to prevent perf from being added to the image in base.yml
|
|
||||||
|
|
||||||
machine: corstone500
|
machine: corstone500
|
||||||
|
|
||||||
distro: poky-tiny
|
|
||||||
|
|
||||||
target:
|
|
||||||
- core-image-minimal
|
|
||||||
- perf
|
|
||||||
|
|||||||
+1
-12
@@ -2,17 +2,6 @@ header:
|
|||||||
version: 11
|
version: 11
|
||||||
includes:
|
includes:
|
||||||
- ci/base.yml
|
- ci/base.yml
|
||||||
|
- ci/fvp.yml
|
||||||
|
|
||||||
machine: fvp-base
|
machine: fvp-base
|
||||||
|
|
||||||
local_conf_header:
|
|
||||||
testimagefvp: |
|
|
||||||
INHERIT += "fvpboot"
|
|
||||||
# This fails but we can't add to the ignorelist from meta-arm yet
|
|
||||||
# https://bugzilla.yoctoproject.org/show_bug.cgi?id=14604
|
|
||||||
TEST_SUITES:remove = "parselogs"
|
|
||||||
# Tell testimage to connect to localhost:8022, and forward that to SSH in the FVP.
|
|
||||||
TEST_TARGET_IP = "localhost:8022"
|
|
||||||
FVP_CONFIG[bp.virtio_net.hostbridge.userNetPorts] ?= "8022=22"
|
|
||||||
failing_tests: |
|
|
||||||
TEST_SUITES:remove = "xorg"
|
|
||||||
|
|||||||
@@ -1,18 +1,11 @@
|
|||||||
header:
|
header:
|
||||||
version: 11
|
version: 11
|
||||||
includes:
|
|
||||||
- ci/base.yml
|
|
||||||
|
|
||||||
machine: fvp-base-arm32
|
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
testimagefvp: |
|
testimagefvp: |
|
||||||
INHERIT = "fvpboot"
|
INHERIT += "fvpboot"
|
||||||
# This fails but we can't add to the ignorelist from meta-arm yet
|
# This fails but we can't add to the ignorelist from meta-arm yet
|
||||||
# https://bugzilla.yoctoproject.org/show_bug.cgi?id=14604
|
# https://bugzilla.yoctoproject.org/show_bug.cgi?id=14604
|
||||||
TEST_SUITES:remove = "parselogs"
|
TEST_SUITES:remove = "parselogs"
|
||||||
# Tell testimage to connect to localhost:8122, and forward that to SSH in the FVP.
|
|
||||||
TEST_TARGET_IP = "127.0.0.1:8122"
|
|
||||||
FVP_CONFIG[bp.virtio_net.hostbridge.userNetPorts] = "8122=22"
|
|
||||||
failing_tests: |
|
failing_tests: |
|
||||||
TEST_SUITES:remove = "xorg"
|
TEST_SUITES:remove = "xorg"
|
||||||
+3
-2
@@ -13,7 +13,8 @@ local_conf_header:
|
|||||||
|
|
||||||
target:
|
target:
|
||||||
- nativesdk-fvp-base-a-aem
|
- nativesdk-fvp-base-a-aem
|
||||||
- nativesdk-fvp-n1-edge
|
|
||||||
- nativesdk-fvp-sgi575
|
|
||||||
- nativesdk-fvp-corstone500
|
- nativesdk-fvp-corstone500
|
||||||
- nativesdk-fvp-corstone1000
|
- nativesdk-fvp-corstone1000
|
||||||
|
- nativesdk-fvp-n1-edge
|
||||||
|
- nativesdk-fvp-sgi575
|
||||||
|
- nativesdk-fvp-tc1
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
header:
|
||||||
|
version: 11
|
||||||
|
|
||||||
|
#NOTE: This is the default for poky. This is only being added for completeness/clarity
|
||||||
|
local_conf_header:
|
||||||
|
toolchain: |
|
||||||
|
TOOLCHAIN = "gcc"
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
header:
|
|
||||||
version: 11
|
|
||||||
includes:
|
|
||||||
- ci/base.yml
|
|
||||||
- ci/meta-openembedded.yml
|
|
||||||
|
|
||||||
repos:
|
|
||||||
meta-arm:
|
|
||||||
layers:
|
|
||||||
meta-gem5:
|
|
||||||
|
|
||||||
machine: gem5-arm64
|
|
||||||
|
|
||||||
target:
|
|
||||||
- core-image-minimal
|
|
||||||
- gem5-aarch64-native
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
header:
|
|
||||||
version: 11
|
|
||||||
includes:
|
|
||||||
- ci/gem5-arm64.yml
|
|
||||||
|
|
||||||
repos:
|
|
||||||
meta-arm:
|
|
||||||
layers:
|
|
||||||
meta-atp:
|
|
||||||
|
|
||||||
machine: gem5-atp-arm64
|
|
||||||
|
|
||||||
target:
|
|
||||||
- atp-native
|
|
||||||
- core-image-minimal
|
|
||||||
+23
-19
@@ -1,8 +1,9 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -u
|
set -u -e
|
||||||
|
|
||||||
HOST_ARCH=$(uname -m)
|
BASENAME=arm-gnu-toolchain
|
||||||
VER="11.3.rel1"
|
VER=${VER:-12.2.rel1}
|
||||||
|
HOST_ARCH=${HOST_ARCH:-$(uname -m)}
|
||||||
|
|
||||||
DOWNLOAD_DIR=$1
|
DOWNLOAD_DIR=$1
|
||||||
TOOLCHAIN_DIR=$2
|
TOOLCHAIN_DIR=$2
|
||||||
@@ -11,36 +12,39 @@ TOOLCHAIN_LINK_DIR=$3
|
|||||||
# These should be already created by .gitlab-ci.yml, but do here if run outside of that env
|
# These should be already created by .gitlab-ci.yml, but do here if run outside of that env
|
||||||
mkdir -p $DOWNLOAD_DIR $TOOLCHAIN_DIR $TOOLCHAIN_LINK_DIR
|
mkdir -p $DOWNLOAD_DIR $TOOLCHAIN_DIR $TOOLCHAIN_LINK_DIR
|
||||||
|
|
||||||
|
download() {
|
||||||
|
TRIPLE=$1
|
||||||
|
URL=https://developer.arm.com/-/media/Files/downloads/gnu/$VER/binrel/$BASENAME-$VER-$HOST_ARCH-$TRIPLE.tar.xz
|
||||||
|
wget -P $DOWNLOAD_DIR -nc $URL
|
||||||
|
}
|
||||||
|
|
||||||
if [ $HOST_ARCH = "aarch64" ]; then
|
if [ $HOST_ARCH = "aarch64" ]; then
|
||||||
#AArch64 Linux hosted cross compilers
|
# AArch64 Linux hosted cross compilers
|
||||||
|
|
||||||
#AArch32 target with hard float (arm-none-linux-gnueabihf)
|
# AArch32 target with hard float
|
||||||
wget -P $DOWNLOAD_DIR -nc https://developer.arm.com/-/media/Files/downloads/gnu/$VER/binrel/arm-gnu-toolchain-$VER-$HOST_ARCH-arm-none-linux-gnueabihf.tar.xz
|
download arm-none-linux-gnueabihf
|
||||||
elif [ $HOST_ARCH = "x86_64" ]; then
|
elif [ $HOST_ARCH = "x86_64" ]; then
|
||||||
#x86_64 Linux hosted cross compilers
|
# x86_64 Linux hosted cross compilers
|
||||||
|
|
||||||
#AArch32 target with hard float (arm-linux-none-gnueabihf)
|
# AArch32 target with hard float
|
||||||
wget -P $DOWNLOAD_DIR -nc https://developer.arm.com/-/media/Files/downloads/gnu/$VER/binrel/arm-gnu-toolchain-$VER-$HOST_ARCH-arm-none-linux-gnueabihf.tar.xz
|
download arm-none-linux-gnueabihf
|
||||||
|
|
||||||
#AArch64 GNU/Linux target (aarch64-none-linux-gnu)
|
# AArch64 GNU/Linux target
|
||||||
wget -P $DOWNLOAD_DIR -nc https://developer.arm.com/-/media/Files/downloads/gnu/$VER/binrel/arm-gnu-toolchain-$VER-$HOST_ARCH-aarch64-none-linux-gnu.tar.xz
|
download aarch64-none-linux-gnu
|
||||||
|
|
||||||
#AArch64 GNU/Linux target (aarch64_be-none-linux-gnu)
|
|
||||||
wget -P $DOWNLOAD_DIR -nc https://developer.arm.com/-/media/Files/downloads/gnu/$VER/binrel/arm-gnu-toolchain-$VER-$HOST_ARCH-aarch64_be-none-linux-gnu.tar.xz
|
|
||||||
else
|
else
|
||||||
echo "ERROR - Unknown build arch of $HOST_ARCH"
|
echo "ERROR - Unknown build arch of $HOST_ARCH"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
for i in arm aarch64 aarch64_be; do
|
for i in arm aarch64; do
|
||||||
if [ ! -d $TOOLCHAIN_DIR/arm-gnu-toolchain-$VER-$HOST_ARCH-$i-none-linux-gnu*/ ]; then
|
if [ ! -d $TOOLCHAIN_DIR/$BASENAME-$VER-$HOST_ARCH-$i-none-linux-gnu*/ ]; then
|
||||||
if [ ! -f $DOWNLOAD_DIR/arm-gnu-toolchain-$VER-$HOST_ARCH-$i-none-linux-gnu*.tar.xz ]; then
|
if [ ! -f $DOWNLOAD_DIR/$BASENAME-$VER-$HOST_ARCH-$i-none-linux-gnu*.tar.xz ]; then
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
|
|
||||||
tar -C $TOOLCHAIN_DIR -axvf $DOWNLOAD_DIR/arm-gnu-toolchain-$VER-$HOST_ARCH-$i-none-linux-gnu*.tar.xz
|
tar -C $TOOLCHAIN_DIR -axvf $DOWNLOAD_DIR/$BASENAME-$VER-$HOST_ARCH-$i-none-linux-gnu*.tar.xz
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Setup a link for the toolchain to use local to the building machine (e.g., not in a shared location)
|
# Setup a link for the toolchain to use local to the building machine (e.g., not in a shared location)
|
||||||
ln -s $TOOLCHAIN_DIR/arm-gnu-toolchain-$VER-$HOST_ARCH-$i-none-linux-gnu* $TOOLCHAIN_LINK_DIR/$i
|
ln -s $TOOLCHAIN_DIR/$BASENAME-$VER-$HOST_ARCH-$i-none-linux-gnu* $TOOLCHAIN_LINK_DIR/$i
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
header:
|
||||||
|
version: 11
|
||||||
|
|
||||||
|
#NOTE: This is the default for poky. This is only being added for completeness/clarity
|
||||||
|
local_conf_header:
|
||||||
|
libc: |
|
||||||
|
TCLIBC = "glibc"
|
||||||
+1
-1
@@ -18,7 +18,7 @@ for i in $(echo $1 | cut -s -d ':' -f 2 | sed 's/[][,]//g'); do
|
|||||||
# defaults, we can simply ignore those parameters. They are necessary
|
# defaults, we can simply ignore those parameters. They are necessary
|
||||||
# to pass in so that matrix can correctly setup all of the permutations
|
# to pass in so that matrix can correctly setup all of the permutations
|
||||||
# of each individual run.
|
# of each individual run.
|
||||||
if [[ $i == 'none' || $i == 'gcc' || $i == 'glibc' || $i == 'uboot' ]]; then
|
if [[ $i == 'none' ]]; then
|
||||||
continue
|
continue
|
||||||
fi
|
fi
|
||||||
FILES+=":ci/$i.yml"
|
FILES+=":ci/$i.yml"
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
header:
|
||||||
|
version: 9
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
kernel: |
|
||||||
|
PREFERRED_PROVIDER_virtual/kernel = "linux-yocto-dev"
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
header:
|
||||||
|
version: 9
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
kernel: |
|
||||||
|
PREFERRED_PROVIDER_virtual/kernel = "linux-yocto-rt"
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
header:
|
||||||
|
version: 9
|
||||||
|
|
||||||
|
#NOTE: This is the default for poky. This is only being added for completeness/clarity
|
||||||
|
local_conf_header:
|
||||||
|
kernel: |
|
||||||
|
PREFERRED_PROVIDER_virtual/kernel = "linux-yocto"
|
||||||
@@ -6,8 +6,8 @@ header:
|
|||||||
local_conf_header:
|
local_conf_header:
|
||||||
trusted_services: |
|
trusted_services: |
|
||||||
TEST_SUITES:append = " trusted_services"
|
TEST_SUITES:append = " trusted_services"
|
||||||
# Include TS Crypto, Storage, ITS, Attestation and SMM-Gateway SPs into optee-os image
|
# Include TS Crypto, TS Protected Storage, TS Internal and Trusted Storage SPs into optee-os image
|
||||||
MACHINE_FEATURES:append = " arm-ffa ts-crypto ts-storage ts-its ts-attestation ts-smm-gateway"
|
MACHINE_FEATURES:append = " arm-ffa ts-crypto ts-storage ts-its"
|
||||||
# Include TS demo/test tools into image
|
# Include TS demo/test tools into image
|
||||||
IMAGE_INSTALL:append = " packagegroup-ts-tests"
|
IMAGE_INSTALL:append = " packagegroup-ts-tests"
|
||||||
# Include TS PSA Arch tests into image
|
# Include TS PSA Arch tests into image
|
||||||
@@ -4,3 +4,7 @@ header:
|
|||||||
- ci/base.yml
|
- ci/base.yml
|
||||||
|
|
||||||
machine: n1sdp
|
machine: n1sdp
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
unsupported_trusted_services: |
|
||||||
|
MACHINE_FEATURES:remove = "ts-smm-gateway"
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
header:
|
||||||
|
version: 9
|
||||||
|
|
||||||
|
distro: poky-tiny
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
hacking: |
|
||||||
|
TEST_SUITES = "ping"
|
||||||
|
extrapackages: |
|
||||||
|
# Intentionally blank to prevent perf from being added to the image in base.yml
|
||||||
|
|
||||||
|
target:
|
||||||
|
- core-image-minimal
|
||||||
|
- perf
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
header:
|
||||||
|
version: 9
|
||||||
|
|
||||||
|
distro: poky
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
header:
|
||||||
|
version: 11
|
||||||
|
includes:
|
||||||
|
- ci/meta-openembedded.yml
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
trusted_services: |
|
||||||
|
TEST_SUITES:append = " trusted_services"
|
||||||
|
# Include TS Crypto, TS Protected Storage, TS Internal Trusted Storage and SMM-Gateway SPs into optee-os image
|
||||||
|
MACHINE_FEATURES:append = " arm-ffa ts-crypto ts-storage ts-its ts-smm-gateway"
|
||||||
|
# Include TS demo/test tools into image
|
||||||
|
IMAGE_INSTALL:append = " packagegroup-ts-tests"
|
||||||
|
# Include TS PSA Arch tests into image
|
||||||
|
IMAGE_INSTALL:append = " packagegroup-ts-tests-psa"
|
||||||
+4
-1
@@ -2,8 +2,11 @@ header:
|
|||||||
version: 11
|
version: 11
|
||||||
includes:
|
includes:
|
||||||
- ci/base.yml
|
- ci/base.yml
|
||||||
|
- ci/fvp.yml
|
||||||
|
- ci/meta-openembedded.yml
|
||||||
|
|
||||||
machine: tc1
|
machine: tc1
|
||||||
|
|
||||||
target:
|
target:
|
||||||
- tc-artifacts-image
|
- core-image-minimal
|
||||||
|
- trusted-firmware-m
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
header:
|
||||||
|
version: 11
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
bootfirmware: |
|
||||||
|
PREFERRED_PROVIDER_virtual/bootloader = "u-boot"
|
||||||
|
TFA_UBOOT = "1"
|
||||||
|
TFA_UEFI = "0"
|
||||||
+7
-1
@@ -4,6 +4,7 @@
|
|||||||
|
|
||||||
import sys
|
import sys
|
||||||
import os
|
import os
|
||||||
|
import shutil
|
||||||
import subprocess
|
import subprocess
|
||||||
import pathlib
|
import pathlib
|
||||||
|
|
||||||
@@ -34,9 +35,14 @@ if __name__ == "__main__":
|
|||||||
|
|
||||||
for repo in repositories:
|
for repo in repositories:
|
||||||
repodir = base_repodir / repo_shortname(repo)
|
repodir = base_repodir / repo_shortname(repo)
|
||||||
|
|
||||||
|
if "CI_CLEAN_REPOS" in os.environ:
|
||||||
|
print("Cleaning %s..." % repo)
|
||||||
|
shutil.rmtree(repodir, ignore_errors=True)
|
||||||
|
|
||||||
if repodir.exists():
|
if repodir.exists():
|
||||||
print("Updating %s..." % repo)
|
print("Updating %s..." % repo)
|
||||||
subprocess.run(["git", "-C", repodir, "fetch"], check=True)
|
subprocess.run(["git", "-C", repodir, "-c", "gc.autoDetach=false", "fetch"], check=True)
|
||||||
else:
|
else:
|
||||||
print("Cloning %s..." % repo)
|
print("Cloning %s..." % repo)
|
||||||
subprocess.run(["git", "clone", "--bare", repo, repodir], check=True)
|
subprocess.run(["git", "clone", "--bare", repo, repodir], check=True)
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ OE-Core's [oeqa][OEQA] framework provides a method of performing runtime tests o
|
|||||||
|
|
||||||
Tests can be configured to run automatically post-build by setting the variable `TESTIMAGE_AUTO="1"`, e.g. in your Kas file or local.conf.
|
Tests can be configured to run automatically post-build by setting the variable `TESTIMAGE_AUTO="1"`, e.g. in your Kas file or local.conf.
|
||||||
|
|
||||||
There are two main methods of testing, using different test "targets".
|
There are two main methods of testing, using different test "targets". Both test targets generate an additional log file with the prefix 'fvp_log' in the image recipe's `${WORKDIR}/testimage` containing the FVP's stdout.
|
||||||
|
|
||||||
## OEFVPTarget
|
## OEFVPTarget
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# The Trusted Services: framework for developing root-of-trust services
|
# The Trusted Services: framework for developing root-of-trust services
|
||||||
|
|
||||||
meta-arm layer includes recipes for [Trusted Services][1] Secure Partitions and Normal World applications
|
meta-arm layer includes recipes for [Trusted Services][^1] Secure Partitions and Normal World applications
|
||||||
in `meta-arm/recipes-security/trusted-services`
|
in `meta-arm/recipes-security/trusted-services`
|
||||||
|
|
||||||
## Secure Partitions recipes
|
## Secure Partitions recipes
|
||||||
@@ -12,7 +12,7 @@ These files are automatically included into optee-os image accordingly to define
|
|||||||
### How to include TS SPs
|
### How to include TS SPs
|
||||||
|
|
||||||
To include TS SPs into optee-os image you need to add into MACHINE_FEATURES
|
To include TS SPs into optee-os image you need to add into MACHINE_FEATURES
|
||||||
features for each [Secure Partition][2] you would like to include:
|
features for each [Secure Partition][^2] you would like to include:
|
||||||
|
|
||||||
| Secure Partition | MACHINE_FEATURE |
|
| Secure Partition | MACHINE_FEATURE |
|
||||||
| ----------------- | --------------- |
|
| ----------------- | --------------- |
|
||||||
@@ -22,32 +22,44 @@ features for each [Secure Partition][2] you would like to include:
|
|||||||
| Protected Storage | ts-storage |
|
| Protected Storage | ts-storage |
|
||||||
| se-proxy | ts-se-proxy |
|
| se-proxy | ts-se-proxy |
|
||||||
| smm-gateway | ts-smm-gateway |
|
| smm-gateway | ts-smm-gateway |
|
||||||
|
| spm-test[1-3] | optee-spmc-test |
|
||||||
|
|
||||||
Other steps depend on your machine/platform definition:
|
Other steps depend on your machine/platform definition:
|
||||||
|
|
||||||
1. For communications between Secure and Normal Words Linux kernel option `CONFIG_ARM_FFA_TRANSPORT=y`
|
1. For communications between Secure and Normal Words Linux kernel option `CONFIG_ARM_FFA_TRANSPORT=y`
|
||||||
is required. If your platform doesn't include it already you can add `arm-ffa` into MACHINE_FEATURES.
|
is required. If your platform doesn't include it already you can add `arm-ffa` into MACHINE_FEATURES.
|
||||||
|
(Please see ` meta-arm/recipes-kernel/arm-ffa-tee`.)
|
||||||
|
|
||||||
|
For running the `uefi-test` or the `xtest -t ffa_spmc` tests under Linux the `arm-ffa-user` drivel is required. This is
|
||||||
|
enabled if the `ts-smm-gateway` and/or the `optee-spmc-test` machine features are enabled.
|
||||||
|
(Please see ` meta-arm/recipes-kernel/arm-ffa-user`.)
|
||||||
|
|
||||||
2. optee-os might require platform specific OP-TEE build parameters (for example what SEL the SPM Core is implemented at).
|
2. optee-os might require platform specific OP-TEE build parameters (for example what SEL the SPM Core is implemented at).
|
||||||
You can find examples in `meta-arm/recipes-security/optee/optee-os_%.bbappend` for qemuarm64-secureboot machine
|
You can find examples in `meta-arm/recipes-security/optee/optee-os_%.bbappend` for qemuarm64-secureboot machine
|
||||||
and in `meta-arm-bsp/recipes-security/optee/optee-os-n1sdp.inc` and `meta-arm-bsp/recipes-security/optee/optee-os-corstone1000-common.inc`
|
and in `meta-arm-bsp/recipes-security/optee/optee-os-n1sdp.inc` and `meta-arm-bsp/recipes-security/optee/optee-os-corstone1000-common.inc`
|
||||||
for N1SDP and Corstone1000 platforms accordingly.
|
for N1SDP and Corstone1000 platforms accordingly.
|
||||||
|
|
||||||
3. trusted-firmware-a might require platform specific TF-A build parameters (SPD and SPMC details on the platform).
|
3. trusted-firmware-a might require platform specific TF-A build parameters (SPD and SPMC details on the platform).
|
||||||
See `meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a_%.bbappend` for qemuarm64-secureboot machine
|
See `meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a_%.bbappend` for qemuarm64-secureboot machine
|
||||||
and in `meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-n1sdp.inc` and
|
and in `meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-n1sdp.inc` and
|
||||||
`meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-corstone1000.inc` for N1SDP and Corstone1000 platforms.
|
`meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-corstone1000.inc` for N1SDP and Corstone1000 platforms.
|
||||||
|
|
||||||
## Normal World applications
|
## Normal World applications
|
||||||
|
|
||||||
Optionally for testing purposes you can add `packagegroup-ts-tests` and `packagegroup-ts-tests-psa` package groups into your image.
|
Optionally for testing purposes you can add `packagegroup-ts-tests` into your image. It includes
|
||||||
They include [Trusted Services test and demo tools][3]
|
[Trusted Services test and demo tools][^3] and [xtest][^4] configured to include the `ffa_spmc` tests.
|
||||||
|
|
||||||
## OEQA Trusted Services tests
|
## OEQA Trusted Services tests
|
||||||
|
|
||||||
meta-arm also includes Trusted Service OEQA tests which can be used for automated testing.
|
meta-arm also includes Trusted Service OEQA tests which can be used for automated testing.
|
||||||
See `ci/trusted-services.yml` for an example how to include them into an image.
|
See `ci/trusted-services.yml` for an example how to include them into an image.
|
||||||
|
|
||||||
[1] https://trusted-services.readthedocs.io/en/integration/overview/introduction.html
|
|
||||||
[2] https://trusted-services.readthedocs.io/en/integration/developer/deployments/secure-partitions.html
|
------
|
||||||
[3] https://trusted-services.readthedocs.io/en/integration/developer/deployments/test-executables.html
|
[^1]: https://trusted-services.readthedocs.io/en/integration/overview/index.html
|
||||||
|
|
||||||
|
[^2]: https://trusted-services.readthedocs.io/en/integration/deployments/secure-partitions.html
|
||||||
|
|
||||||
|
[^3]: https://trusted-services.readthedocs.io/en/integration/deployments/test-executables.html
|
||||||
|
|
||||||
|
[^4]: https://optee.readthedocs.io/en/latest/building/gits/optee_test.html
|
||||||
@@ -5,7 +5,7 @@ distro: poky-tiny
|
|||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
repos:
|
repos:
|
||||||
refspec: master
|
refspec: mickledore
|
||||||
|
|
||||||
repos:
|
repos:
|
||||||
meta-arm:
|
meta-arm:
|
||||||
@@ -16,7 +16,7 @@ repos:
|
|||||||
|
|
||||||
poky:
|
poky:
|
||||||
url: https://git.yoctoproject.org/git/poky
|
url: https://git.yoctoproject.org/git/poky
|
||||||
refspec: master
|
refspec: 31dd418207f6c95ef0aad589cd03cd2a4c9a8bf2
|
||||||
layers:
|
layers:
|
||||||
meta:
|
meta:
|
||||||
meta-poky:
|
meta-poky:
|
||||||
@@ -24,7 +24,7 @@ repos:
|
|||||||
|
|
||||||
meta-openembedded:
|
meta-openembedded:
|
||||||
url: https://git.openembedded.org/meta-openembedded
|
url: https://git.openembedded.org/meta-openembedded
|
||||||
refspec: master
|
refspec: 5a01ab461c9bcabcbb2298236602373948f8f073
|
||||||
layers:
|
layers:
|
||||||
meta-oe:
|
meta-oe:
|
||||||
meta-python:
|
meta-python:
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ BBFILE_COLLECTIONS += "meta-arm-bsp"
|
|||||||
BBFILE_PATTERN_meta-arm-bsp = "^${LAYERDIR}/"
|
BBFILE_PATTERN_meta-arm-bsp = "^${LAYERDIR}/"
|
||||||
BBFILE_PRIORITY_meta-arm-bsp = "5"
|
BBFILE_PRIORITY_meta-arm-bsp = "5"
|
||||||
|
|
||||||
LAYERSERIES_COMPAT_meta-arm-bsp = "langdale"
|
LAYERSERIES_COMPAT_meta-arm-bsp = "mickledore"
|
||||||
|
|
||||||
LAYERDEPENDS_meta-arm-bsp = "core meta-arm"
|
LAYERDEPENDS_meta-arm-bsp = "core meta-arm"
|
||||||
# This won't be used by layerindex-fetch, but works everywhere else
|
# This won't be used by layerindex-fetch, but works everywhere else
|
||||||
|
|||||||
@@ -29,9 +29,10 @@ FVP_CONFIG[board.se_flash_size] ?= "8192"
|
|||||||
FVP_CONFIG[diagnostics] ?= "4"
|
FVP_CONFIG[diagnostics] ?= "4"
|
||||||
FVP_CONFIG[disable_visualisation] ?= "true"
|
FVP_CONFIG[disable_visualisation] ?= "true"
|
||||||
FVP_CONFIG[se.nvm.update_raw_image] ?= "0"
|
FVP_CONFIG[se.nvm.update_raw_image] ?= "0"
|
||||||
|
FVP_CONFIG[se.cryptocell.USER_OTP_FILTERING_DISABLE] ?= "1"
|
||||||
|
|
||||||
# Boot image
|
# Boot image
|
||||||
FVP_DATA ?= "board.flash0=${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.rootfs.wic.nopt@0x68100000"
|
FVP_DATA ?= "board.flash0=${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.rootfs.wic@0x68000000"
|
||||||
|
|
||||||
# External system (cortex-M3)
|
# External system (cortex-M3)
|
||||||
FVP_CONFIG[extsys_harness0.extsys_flashloader.fname] ?= "${DEPLOY_DIR_IMAGE}/es_flashfw.bin"
|
FVP_CONFIG[extsys_harness0.extsys_flashloader.fname] ?= "${DEPLOY_DIR_IMAGE}/es_flashfw.bin"
|
||||||
@@ -42,3 +43,9 @@ FVP_TERMINALS[host.host_terminal_1] ?= "Secure World Console"
|
|||||||
FVP_TERMINALS[se.secenc_terminal] ?= "Secure Enclave Console"
|
FVP_TERMINALS[se.secenc_terminal] ?= "Secure Enclave Console"
|
||||||
FVP_TERMINALS[extsys0.extsys_terminal] ?= "Cortex M3"
|
FVP_TERMINALS[extsys0.extsys_terminal] ?= "Cortex M3"
|
||||||
|
|
||||||
|
# MMC card configuration
|
||||||
|
FVP_CONFIG[board.msd_mmc.card_type] ?= "SDHC"
|
||||||
|
FVP_CONFIG[board.msd_mmc.p_fast_access] ?= "0"
|
||||||
|
FVP_CONFIG[board.msd_mmc.diagnostics] ?= "2"
|
||||||
|
FVP_CONFIG[board.msd_mmc.p_max_block_count] ?= "0xFFFF"
|
||||||
|
FVP_CONFIG[board.msd_config.pl180_fifo_depth] ?= "16"
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ require conf/machine/include/arm/armv7a/tune-cortexa5.inc
|
|||||||
# apply.
|
# apply.
|
||||||
#
|
#
|
||||||
PREFERRED_PROVIDER_virtual/kernel:forcevariable = "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel:forcevariable = "linux-yocto"
|
||||||
PREFERRED_VERSION_linux-yocto ?= "5.19%"
|
PREFERRED_VERSION_linux-yocto ?= "6.1%"
|
||||||
|
|
||||||
EXTRA_IMAGEDEPENDS += "trusted-firmware-a u-boot"
|
EXTRA_IMAGEDEPENDS += "trusted-firmware-a u-boot"
|
||||||
|
|
||||||
@@ -26,7 +26,7 @@ SERIAL_CONSOLES = "115200;ttyAMA0"
|
|||||||
UBOOT_MACHINE = "corstone500_defconfig"
|
UBOOT_MACHINE = "corstone500_defconfig"
|
||||||
UBOOT_IMAGE_ENTRYPOINT = "0x84000000"
|
UBOOT_IMAGE_ENTRYPOINT = "0x84000000"
|
||||||
UBOOT_IMAGE_LOADADDRESS = "0x84000000"
|
UBOOT_IMAGE_LOADADDRESS = "0x84000000"
|
||||||
PREFERRED_VERSION_u-boot ?= "2022.07"
|
PREFERRED_VERSION_u-boot ?= "2023.01"
|
||||||
|
|
||||||
# making sure EXTRA_IMAGEDEPENDS will be used while creating the image
|
# making sure EXTRA_IMAGEDEPENDS will be used while creating the image
|
||||||
WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
||||||
@@ -43,3 +43,6 @@ FVP_DATA ?= "css.cluster.cpu0=${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.rootfs.wic.nopt@
|
|||||||
FVP_CONSOLE ?= "terminal_0"
|
FVP_CONSOLE ?= "terminal_0"
|
||||||
FVP_TERMINALS[css.terminal_0] ?= "console"
|
FVP_TERMINALS[css.terminal_0] ?= "console"
|
||||||
FVP_TERMINALS[css.terminal_1] ?= ""
|
FVP_TERMINALS[css.terminal_1] ?= ""
|
||||||
|
|
||||||
|
# Disable openssl in kmod to shink the initramfs size
|
||||||
|
PACKAGECONFIG:remove:pn-kmod = "openssl"
|
||||||
|
|||||||
@@ -1,23 +0,0 @@
|
|||||||
# Configuration for Armv7-A Base Platform FVP
|
|
||||||
|
|
||||||
#@TYPE: Machine
|
|
||||||
#@NAME: Armv7-A Base Platform FVP machine
|
|
||||||
#@DESCRIPTION: Machine configuration for Armv7-A Base Platform FVP model
|
|
||||||
|
|
||||||
require conf/machine/include/fvp-common.inc
|
|
||||||
require conf/machine/include/arm/arch-armv7a.inc
|
|
||||||
|
|
||||||
# FVP u-boot configuration
|
|
||||||
PREFERRED_VERSION_u-boot ?= "2022.04"
|
|
||||||
UBOOT_MACHINE = "vexpress_aemv8a_aarch32_defconfig"
|
|
||||||
|
|
||||||
KERNEL_IMAGETYPE = "zImage"
|
|
||||||
|
|
||||||
FVP_CONFIG[cluster0.cpu0.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster0.cpu1.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster0.cpu2.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster0.cpu3.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster1.cpu0.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster1.cpu1.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster1.cpu2.CONFIG64] = "0"
|
|
||||||
FVP_CONFIG[cluster1.cpu3.CONFIG64] = "0"
|
|
||||||
@@ -9,11 +9,11 @@ require conf/machine/include/arm/arch-armv8a.inc
|
|||||||
|
|
||||||
TUNE_FEATURES = "aarch64"
|
TUNE_FEATURES = "aarch64"
|
||||||
|
|
||||||
PREFERRED_VERSION_u-boot ?= "2022.04"
|
PREFERRED_VERSION_u-boot ?= "2023.01"
|
||||||
PREFERRED_VERSION_linux-yocto ?= "5.15%"
|
|
||||||
PREFERRED_VERSION_linux-yocto-rt ?= "5.15%"
|
|
||||||
|
|
||||||
# FVP u-boot configuration
|
# FVP u-boot configuration
|
||||||
UBOOT_MACHINE = "vexpress_aemv8a_semi_defconfig"
|
UBOOT_MACHINE = "vexpress_aemv8a_semi_defconfig"
|
||||||
|
|
||||||
KERNEL_IMAGETYPE = "Image"
|
KERNEL_IMAGETYPE = "Image"
|
||||||
|
|
||||||
|
FVP_CONFIG[bp.virtio_rng.enabled] ?= "1"
|
||||||
|
|||||||
@@ -9,9 +9,7 @@ require conf/machine/include/arm/armv8r/arch-armv8r64.inc
|
|||||||
EXTRA_IMAGEDEPENDS += "boot-wrapper-aarch64"
|
EXTRA_IMAGEDEPENDS += "boot-wrapper-aarch64"
|
||||||
|
|
||||||
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
||||||
PREFERRED_VERSION_linux-yocto ?= "5.15%"
|
PREFERRED_VERSION_u-boot ?= "2022.10"
|
||||||
PREFERRED_VERSION_linux-yocto-rt ?= "5.15%"
|
|
||||||
PREFERRED_VERSION_u-boot ?= "2022.07"
|
|
||||||
|
|
||||||
KERNEL_IMAGETYPE = "Image"
|
KERNEL_IMAGETYPE = "Image"
|
||||||
KERNEL_DEVICETREE = "arm/fvp-baser-aemv8r64.dtb"
|
KERNEL_DEVICETREE = "arm/fvp-baser-aemv8r64.dtb"
|
||||||
@@ -27,9 +25,7 @@ EFI_PROVIDER ?= "grub-efi"
|
|||||||
MACHINE_FEATURES:append = " efi"
|
MACHINE_FEATURES:append = " efi"
|
||||||
|
|
||||||
# As this is a virtual target that will not be used in the real world there is
|
# As this is a virtual target that will not be used in the real world there is
|
||||||
# no need for real SSH keys. Disable rng-tools (which takes too long to
|
# no need for real SSH keys.
|
||||||
# initialise) and install the pre-generated keys.
|
|
||||||
PACKAGECONFIG:remove:pn-openssh = "rng-tools"
|
|
||||||
MACHINE_EXTRA_RRECOMMENDS += "ssh-pregen-hostkeys"
|
MACHINE_EXTRA_RRECOMMENDS += "ssh-pregen-hostkeys"
|
||||||
|
|
||||||
# testimage configuration
|
# testimage configuration
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ TFM_SIGN_PRIVATE_KEY = "${libdir}/tfm-scripts/root-RSA-3072_1.pem"
|
|||||||
RE_IMAGE_OFFSET = "0x1000"
|
RE_IMAGE_OFFSET = "0x1000"
|
||||||
|
|
||||||
# u-boot
|
# u-boot
|
||||||
PREFERRED_VERSION_u-boot ?= "2022.07"
|
PREFERRED_VERSION_u-boot ?= "2023.01"
|
||||||
EXTRA_IMAGEDEPENDS += "u-boot"
|
EXTRA_IMAGEDEPENDS += "u-boot"
|
||||||
|
|
||||||
UBOOT_CONFIG ??= "EFI"
|
UBOOT_CONFIG ??= "EFI"
|
||||||
@@ -34,7 +34,7 @@ UBOOT_ARCH = "arm"
|
|||||||
UBOOT_EXTLINUX = "0"
|
UBOOT_EXTLINUX = "0"
|
||||||
|
|
||||||
#optee
|
#optee
|
||||||
PREFERRED_VERSION_optee-os ?= "3.18.%"
|
PREFERRED_VERSION_optee-os ?= "3.20.%"
|
||||||
PREFERRED_VERSION_optee-client ?= "3.18.%"
|
PREFERRED_VERSION_optee-client ?= "3.18.%"
|
||||||
EXTRA_IMAGEDEPENDS += "optee-os"
|
EXTRA_IMAGEDEPENDS += "optee-os"
|
||||||
OPTEE_ARCH = "arm64"
|
OPTEE_ARCH = "arm64"
|
||||||
@@ -43,13 +43,14 @@ OPTEE_BINARY = "tee-pager_v2.bin"
|
|||||||
# Include smm-gateway and se-proxy SPs into optee-os binary
|
# Include smm-gateway and se-proxy SPs into optee-os binary
|
||||||
MACHINE_FEATURES += "ts-smm-gateway ts-se-proxy"
|
MACHINE_FEATURES += "ts-smm-gateway ts-se-proxy"
|
||||||
TS_PLATFORM = "arm/corstone1000"
|
TS_PLATFORM = "arm/corstone1000"
|
||||||
|
TS_SP_SE_PROXY_CONFIG = "corstone1000"
|
||||||
|
|
||||||
# External System(Cortex-M3)
|
# External System(Cortex-M3)
|
||||||
EXTRA_IMAGEDEPENDS += "external-system"
|
EXTRA_IMAGEDEPENDS += "external-system"
|
||||||
|
|
||||||
# Linux kernel
|
# Linux kernel
|
||||||
PREFERRED_PROVIDER_virtual/kernel:forcevariable = "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel:forcevariable = "linux-yocto"
|
||||||
PREFERRED_VERSION_linux-yocto = "5.19%"
|
PREFERRED_VERSION_linux-yocto = "6.1%"
|
||||||
KERNEL_IMAGETYPE = "Image.gz"
|
KERNEL_IMAGETYPE = "Image.gz"
|
||||||
|
|
||||||
INITRAMFS_IMAGE_BUNDLE ?= "1"
|
INITRAMFS_IMAGE_BUNDLE ?= "1"
|
||||||
@@ -73,3 +74,6 @@ SERIAL_CONSOLES ?= "115200;ttyAMA0"
|
|||||||
WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
||||||
|
|
||||||
WKS_FILE ?= "corstone1000-image.corstone1000.wks"
|
WKS_FILE ?= "corstone1000-image.corstone1000.wks"
|
||||||
|
|
||||||
|
# Disable openssl in kmod to shink the initramfs size
|
||||||
|
PACKAGECONFIG:remove:pn-kmod = "openssl"
|
||||||
|
|||||||
@@ -16,21 +16,22 @@ PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
|||||||
|
|
||||||
KERNEL_DEVICETREE = "arm/fvp-base-revc.dtb"
|
KERNEL_DEVICETREE = "arm/fvp-base-revc.dtb"
|
||||||
|
|
||||||
EXTRA_IMAGEDEPENDS += "trusted-firmware-a u-boot"
|
EXTRA_IMAGEDEPENDS += "trusted-firmware-a"
|
||||||
|
|
||||||
# As this is a virtual target that will not be used in the real world there is
|
# As this is a virtual target that will not be used in the real world there is
|
||||||
# no need for real SSH keys. Disable rng-tools (which takes too long to
|
# no need for real SSH keys.
|
||||||
# initialise) and install the pre-generated keys.
|
|
||||||
PACKAGECONFIG:remove:pn-openssh = "rng-tools"
|
|
||||||
MACHINE_EXTRA_RRECOMMENDS += "ssh-pregen-hostkeys"
|
MACHINE_EXTRA_RRECOMMENDS += "ssh-pregen-hostkeys"
|
||||||
|
|
||||||
TEST_TARGET = "OEFVPTarget"
|
TEST_TARGET = "OEFVPTarget"
|
||||||
|
TEST_TARGET_IP = "127.0.0.1:8022"
|
||||||
|
|
||||||
FVP_PROVIDER ?= "fvp-base-a-aem-native"
|
FVP_PROVIDER ?= "fvp-base-a-aem-native"
|
||||||
FVP_EXE ?= "FVP_Base_RevC-2xAEMvA"
|
FVP_EXE ?= "FVP_Base_RevC-2xAEMvA"
|
||||||
FVP_CONFIG[bp.ve_sysregs.exit_on_shutdown] ?= "1"
|
FVP_CONFIG[bp.ve_sysregs.exit_on_shutdown] ?= "1"
|
||||||
FVP_CONFIG[bp.virtio_net.enabled] ?= "1"
|
FVP_CONFIG[bp.virtio_net.enabled] ?= "1"
|
||||||
FVP_CONFIG[bp.virtio_net.hostbridge.userNetworking] ?= "1"
|
FVP_CONFIG[bp.virtio_net.hostbridge.userNetworking] ?= "1"
|
||||||
|
# Tell testimage to connect to localhost:8022, and forward that to SSH in the FVP.
|
||||||
|
FVP_CONFIG[bp.virtio_net.hostbridge.userNetPorts] = "8022=22"
|
||||||
FVP_CONFIG[cache_state_modelled] ?= "0"
|
FVP_CONFIG[cache_state_modelled] ?= "0"
|
||||||
FVP_CONFIG[bp.secureflashloader.fname] ?= "${DEPLOY_DIR_IMAGE}/bl1-fvp.bin"
|
FVP_CONFIG[bp.secureflashloader.fname] ?= "${DEPLOY_DIR_IMAGE}/bl1-fvp.bin"
|
||||||
FVP_CONFIG[bp.flashloader0.fname] ?= "${DEPLOY_DIR_IMAGE}/fip-fvp.bin"
|
FVP_CONFIG[bp.flashloader0.fname] ?= "${DEPLOY_DIR_IMAGE}/fip-fvp.bin"
|
||||||
|
|||||||
@@ -11,16 +11,6 @@ UBOOT_RD_LOADADDRESS = "0x88000000"
|
|||||||
UBOOT_RD_ENTRYPOINT = "0x88000000"
|
UBOOT_RD_ENTRYPOINT = "0x88000000"
|
||||||
UBOOT_LOADADDRESS = "0x80080000"
|
UBOOT_LOADADDRESS = "0x80080000"
|
||||||
UBOOT_ENTRYPOINT = "0x80080000"
|
UBOOT_ENTRYPOINT = "0x80080000"
|
||||||
# Below options will generate a key to sign the kernel Image and INITRAMFS_IMAGE
|
|
||||||
# according to the default parameters of kernel-fitimage.bbclass. If the user
|
|
||||||
# would prefer to use their own keys, disable the key generation using the
|
|
||||||
# FIT_GENERATE_KEYS parameter and specify the location of the keys using the
|
|
||||||
# below paramters.
|
|
||||||
UBOOT_SIGN_ENABLE = "1"
|
|
||||||
UBOOT_MKIMAGE_DTCOPTS = "-I dts -O dtb"
|
|
||||||
UBOOT_SIGN_KEYNAME = "dev_key"
|
|
||||||
UBOOT_SIGN_KEYDIR = "${DEPLOY_DIR_IMAGE}/keys"
|
|
||||||
FIT_GENERATE_KEYS = "1"
|
|
||||||
|
|
||||||
PREFERRED_PROVIDER_virtual/kernel ?= "linux-arm64-ack"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-arm64-ack"
|
||||||
|
|
||||||
@@ -38,3 +28,8 @@ IMAGE_FSTYPES += "cpio.gz"
|
|||||||
INITRAMFS_IMAGE ?= "core-image-minimal"
|
INITRAMFS_IMAGE ?= "core-image-minimal"
|
||||||
|
|
||||||
SERIAL_CONSOLES = "115200;ttyAMA0"
|
SERIAL_CONSOLES = "115200;ttyAMA0"
|
||||||
|
|
||||||
|
EXTRA_IMAGEDEPENDS += "trusted-firmware-a optee-os"
|
||||||
|
# FIXME - there is signed image dependency/race with testimage.
|
||||||
|
# This should be fixed in oe-core
|
||||||
|
TESTIMAGEDEPENDS:append = " virtual/kernel:do_deploy"
|
||||||
|
|||||||
@@ -10,18 +10,20 @@ require conf/machine/include/arm/arch-armv8a.inc
|
|||||||
|
|
||||||
MACHINE_FEATURES = "usbhost usbgadget alsa screen wifi bluetooth optee pci"
|
MACHINE_FEATURES = "usbhost usbgadget alsa screen wifi bluetooth optee pci"
|
||||||
|
|
||||||
KERNEL_IMAGETYPE = "Image"
|
KERNEL_IMAGETYPE = "Image.gz"
|
||||||
KERNEL_DEVICETREE = "arm/juno.dtb arm/juno-r1.dtb arm/juno-r2.dtb"
|
KERNEL_DEVICETREE = "arm/juno.dtb arm/juno-r1.dtb arm/juno-r2.dtb"
|
||||||
|
|
||||||
IMAGE_FSTYPES += "tar.bz2 ext4"
|
IMAGE_FSTYPES += "tar.bz2 ext4 cpio.gz"
|
||||||
|
|
||||||
SERIAL_CONSOLES = "115200;ttyAMA0"
|
SERIAL_CONSOLES = "115200;ttyAMA0"
|
||||||
|
|
||||||
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
||||||
PREFERRED_VERSION_u-boot ?= "2022.04"
|
|
||||||
PREFERRED_PROVIDER_virtual/bootloader ?= "u-boot"
|
PREFERRED_PROVIDER_virtual/bootloader ?= "u-boot"
|
||||||
|
|
||||||
EXTRA_IMAGEDEPENDS += "trusted-firmware-a virtual/bootloader firmware-image-juno"
|
EXTRA_IMAGEDEPENDS += "trusted-firmware-a virtual/bootloader firmware-image-juno"
|
||||||
|
|
||||||
# Juno u-boot configuration
|
# Juno u-boot configuration
|
||||||
UBOOT_MACHINE = "vexpress_aemv8a_juno_defconfig"
|
UBOOT_MACHINE = "vexpress_aemv8a_juno_defconfig"
|
||||||
|
|
||||||
|
INITRAMFS_IMAGE_BUNDLE ?= "1"
|
||||||
|
INITRAMFS_IMAGE = "core-image-minimal"
|
||||||
|
|||||||
@@ -20,4 +20,4 @@ QB_GRAPHICS = "-nographic -vga none"
|
|||||||
QB_MEM = "512k"
|
QB_MEM = "512k"
|
||||||
QB_RNG = ""
|
QB_RNG = ""
|
||||||
|
|
||||||
TFM_PLATFORM = "arm/musca_b1/sse_200"
|
TFM_PLATFORM = "arm/musca_b1"
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
|||||||
|
|
||||||
# Use kernel provided by yocto
|
# Use kernel provided by yocto
|
||||||
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
||||||
PREFERRED_VERSION_linux-yocto ?= "5.19%"
|
PREFERRED_VERSION_linux-yocto ?= "6.1%"
|
||||||
|
|
||||||
# RTL8168E Gigabit Ethernet Controller is attached to the PCIe interface
|
# RTL8168E Gigabit Ethernet Controller is attached to the PCIe interface
|
||||||
MACHINE_ESSENTIAL_EXTRA_RDEPENDS += "linux-firmware-rtl8168"
|
MACHINE_ESSENTIAL_EXTRA_RDEPENDS += "linux-firmware-rtl8168"
|
||||||
@@ -29,9 +29,10 @@ EXTRA_IMAGEDEPENDS += "virtual/control-processor-firmware"
|
|||||||
|
|
||||||
#UEFI EDK2 firmware
|
#UEFI EDK2 firmware
|
||||||
EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
||||||
|
PREFERRED_VERSION_edk2-firmware ?= "202211"
|
||||||
|
|
||||||
#optee
|
#optee
|
||||||
PREFERRED_VERSION_optee-os ?= "3.18.%"
|
PREFERRED_VERSION_optee-os ?= "3.20.%"
|
||||||
|
|
||||||
#grub-efi
|
#grub-efi
|
||||||
EFI_PROVIDER ?= "grub-efi"
|
EFI_PROVIDER ?= "grub-efi"
|
||||||
|
|||||||
@@ -5,3 +5,27 @@
|
|||||||
#@DESCRIPTION: Machine configuration for TC1
|
#@DESCRIPTION: Machine configuration for TC1
|
||||||
|
|
||||||
require conf/machine/include/tc.inc
|
require conf/machine/include/tc.inc
|
||||||
|
|
||||||
|
TEST_TARGET = "OEFVPSerialTarget"
|
||||||
|
TEST_SUITES = "linuxboot"
|
||||||
|
|
||||||
|
# FVP Config
|
||||||
|
FVP_PROVIDER ?= "fvp-tc1-native"
|
||||||
|
FVP_EXE ?= "FVP_TC1"
|
||||||
|
|
||||||
|
# FVP Parameters
|
||||||
|
FVP_CONFIG[css.scp.ROMloader.fname] ?= "${DEPLOY_DIR_IMAGE}/scp_romfw.bin"
|
||||||
|
FVP_CONFIG[css.trustedBootROMloader.fname] ?= "${DEPLOY_DIR_IMAGE}/bl1-tc.bin"
|
||||||
|
FVP_CONFIG[board.flashloader0.fname] ?= "${DEPLOY_DIR_IMAGE}/fip_gpt-tc.bin"
|
||||||
|
|
||||||
|
#FVP_CONFIG[board.hostbridge.userNetworking] ?= "true"
|
||||||
|
#FVP_CONFIG[board.hostbridge.userNetPorts] ?= "8022=22"
|
||||||
|
#smsc ethernet takes a very long time to come up. disable now to prevent testimage timeout
|
||||||
|
#FVP_CONFIG[board.smsc_91c111.enabled] ?= "1"
|
||||||
|
|
||||||
|
FVP_CONSOLE = "terminal_s1"
|
||||||
|
FVP_TERMINALS[soc.terminal_s0] ?= "Secure Console"
|
||||||
|
FVP_TERMINALS[soc.terminal_s1] ?= "Console"
|
||||||
|
|
||||||
|
# Boot image
|
||||||
|
FVP_DATA ?= "board.dram=${DEPLOY_DIR_IMAGE}/fitImage-core-image-minimal-tc1-tc1@0x20000000"
|
||||||
|
|||||||
@@ -0,0 +1,230 @@
|
|||||||
|
..
|
||||||
|
# Copyright (c) 2022-2023, Arm Limited.
|
||||||
|
#
|
||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
##########
|
||||||
|
Change Log
|
||||||
|
##########
|
||||||
|
|
||||||
|
This document contains a summary of the new features, changes and
|
||||||
|
fixes in each release of Corstone-1000 software stack.
|
||||||
|
|
||||||
|
***************
|
||||||
|
Version 2023.06
|
||||||
|
***************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
|
||||||
|
- GPT support (in TF-M, TF-A, U-boot)
|
||||||
|
- Use TF-M BL1 code as the ROM code instead of MCUboot (the next stage bootloader BL2 remains to be MCUboot)
|
||||||
|
- Secure Enclave uses CC312 OTP as the provisioning backend in FVP and FPGA
|
||||||
|
- NVMXIP block storage support in U-Boot
|
||||||
|
- Upgrading the SW stack recipes
|
||||||
|
- Upgrades for the U-Boot FF-A driver and MM communication
|
||||||
|
|
||||||
|
Corstone-1000 components versions
|
||||||
|
=================================
|
||||||
|
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| arm-ffa-tee | 1.1.2-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| arm-ffa-user | 5.0.1-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| corstone1000-external-sys-tests | 1.0+gitAUTOINC+2945cd92f7-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| external-system | 0.1.0+gitAUTOINC+8c9dca74b1-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| linux-yocto | 6.1.25+gitAUTOINC+36901b5b29_581dc1aa2f-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| u-boot | 2023.01-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| optee-client | 3.18.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| optee-os | 3.20.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| trusted-firmware-a | 2.8.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| trusted-firmware-m | 1.7.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| ts-newlib | 4.1.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| ts-psa-{crypto, iat, its. ps}-api-test | 38cb53a4d9 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
| ts-sp-{se-proxy, smm-gateway} | 08b3d39471 |
|
||||||
|
+-------------------------------------------+--------------------------------------------+
|
||||||
|
|
||||||
|
Yocto distribution components versions
|
||||||
|
======================================
|
||||||
|
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| meta-arm | mickledore |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| poky | mickledore |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| meta-openembedded | mickledore |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| busybox | 1.36.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| musl | 1.2.3+gitAUTOINC+7d756e1c04-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| gcc-arm-none-eabi-native | 11.2-2022.02 |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| gcc-cross-aarch64 | 12.2.rel1-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
| openssl | 3.1.0-r0 |
|
||||||
|
+-------------------------------------------+--------------------------------+
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2022.11.23
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
|
||||||
|
- Booting the External System (Cortex-M3) with RTX RTOS
|
||||||
|
- Adding MHU communication between the HOST (Cortex-A35) and the External System
|
||||||
|
- Adding a Linux application to test the External System
|
||||||
|
- Adding ESRT (EFI System Resource Table) support
|
||||||
|
- Upgrading the SW stack recipes
|
||||||
|
- Upgrades for the U-Boot FF-A driver and MM communication
|
||||||
|
|
||||||
|
Corstone-1000 components versions
|
||||||
|
=================================
|
||||||
|
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| arm-ffa-tee | 1.1.1 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| arm-ffa-user | 5.0.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| corstone1000-external-sys-tests | 1.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| external-system | 0.1.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| linux-yocto | 5.19 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| u-boot | 2022.07 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| optee-client | 3.18.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| optee-os | 3.18.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| trusted-firmware-a | 2.7.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| trusted-firmware-m | 1.6.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| ts-newlib | 4.1.0 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| ts-psa-{crypto, iat, its. ps}-api-test | 451aa087a4 |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
| ts-sp-{se-proxy, smm-gateway} | 3d4956770f |
|
||||||
|
+-------------------------------------------+------------+
|
||||||
|
|
||||||
|
Yocto distribution components versions
|
||||||
|
======================================
|
||||||
|
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| meta-arm | langdale |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| poky | langdale |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| meta-openembedded | langdale |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| busybox | 1.35.0 |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| musl | 1.2.3+git37e18b7bf3 |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| gcc-arm-none-eabi-native | 11.2-2022.02 |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| gcc-cross-aarch64 | 12.2 |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
| openssl | 3.0.5 |
|
||||||
|
+-------------------------------------------+---------------------+
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2022.04.04
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- Linux distro openSUSE, raw image installation and boot in the FVP.
|
||||||
|
- SCT test support in FVP.
|
||||||
|
- Manual capsule update support in FVP.
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2022.02.25
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- Building and running psa-arch-tests on Corstone-1000 FVP
|
||||||
|
- Enabled smm-gateway partition in Trusted Service on Corstone-1000 FVP
|
||||||
|
- Enabled MHU driver in Trusted Service on Corstone-1000 FVP
|
||||||
|
- Enabled OpenAMP support in SE proxy SP on Corstone-1000 FVP
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2022.02.21
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- psa-arch-tests: recipe is dropped and merged into the secure-partitons recipe.
|
||||||
|
- psa-arch-tests: The tests are align with latest tfm version for psa-crypto-api suite.
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2022.01.18
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- psa-arch-tests: change master to main for psa-arch-tests
|
||||||
|
- U-Boot: fix null pointer exception for get_image_info
|
||||||
|
- TF-M: fix capsule instability issue for Corstone-1000
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2022.01.07
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- Corstone-1000: fix SystemReady-IR ACS test (SCT, FWTS) failures.
|
||||||
|
- U-Boot: send bootcomplete event to secure enclave.
|
||||||
|
- U-Boot: support populating Corstone-1000 image_info to ESRT table.
|
||||||
|
- U-Boot: add ethernet device and enable configs to support bootfromnetwork SCT.
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2021.12.15
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- Enabling Corstone-1000 FPGA support on:
|
||||||
|
- Linux 5.10
|
||||||
|
- OP-TEE 3.14
|
||||||
|
- Trusted Firmware-A 2.5
|
||||||
|
- Trusted Firmware-M 1.5
|
||||||
|
- Building and running psa-arch-tests
|
||||||
|
- Adding openamp support in SE proxy SP
|
||||||
|
- OP-TEE: adding smm-gateway partition
|
||||||
|
- U-Boot: introducing Arm FF-A and MM support
|
||||||
|
|
||||||
|
******************
|
||||||
|
Version 2021.10.29
|
||||||
|
******************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
- Enabling Corstone-1000 FVP support on:
|
||||||
|
- Linux 5.10
|
||||||
|
- OP-TEE 3.14
|
||||||
|
- Trusted Firmware-A 2.5
|
||||||
|
- Trusted Firmware-M 1.4
|
||||||
|
- Linux kernel: enabling EFI, adding FF-A debugfs driver, integrating ARM_FFA_TRANSPORT.
|
||||||
|
- U-Boot: Extending EFI support
|
||||||
|
- python3-imgtool: adding recipe for Trusted-firmware-m
|
||||||
|
- python3-imgtool: adding the Yocto recipe used in signing host images (based on MCUBOOT format)
|
||||||
|
|
||||||
|
--------------
|
||||||
|
|
||||||
|
*Copyright (c) 2022-2023, Arm Limited. All rights reserved.*
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
# Configuration file for the Sphinx documentation builder.
|
||||||
|
#
|
||||||
|
# This file only contains a selection of the most common options. For a full
|
||||||
|
# list see the documentation:
|
||||||
|
# https://www.sphinx-doc.org/en/master/usage/configuration.html
|
||||||
|
|
||||||
|
# -- Path setup --------------------------------------------------------------
|
||||||
|
|
||||||
|
# If extensions (or modules to document with autodoc) are in another directory,
|
||||||
|
# add these directories to sys.path here. If the directory is relative to the
|
||||||
|
# documentation root, use os.path.abspath to make it absolute, like shown here.
|
||||||
|
#
|
||||||
|
# import os
|
||||||
|
# import sys
|
||||||
|
# sys.path.insert(0, os.path.abspath('.'))
|
||||||
|
|
||||||
|
|
||||||
|
# -- Project information -----------------------------------------------------
|
||||||
|
|
||||||
|
project = 'corstone1000'
|
||||||
|
copyright = '2020-2022, Arm Limited'
|
||||||
|
author = 'Arm Limited'
|
||||||
|
|
||||||
|
|
||||||
|
# -- General configuration ---------------------------------------------------
|
||||||
|
|
||||||
|
# Add any Sphinx extension module names here, as strings. They can be
|
||||||
|
# extensions coming with Sphinx (named 'sphinx.ext.*') or your custom
|
||||||
|
# ones.
|
||||||
|
extensions = [
|
||||||
|
]
|
||||||
|
|
||||||
|
# Add any paths that contain templates here, relative to this directory.
|
||||||
|
templates_path = ['_templates']
|
||||||
|
|
||||||
|
# List of patterns, relative to source directory, that match files and
|
||||||
|
# directories to ignore when looking for source files.
|
||||||
|
# This pattern also affects html_static_path and html_extra_path.
|
||||||
|
exclude_patterns = ['_build', 'Thumbs.db', '.DS_Store', 'docs/infra']
|
||||||
|
|
||||||
|
|
||||||
|
# -- Options for HTML output -------------------------------------------------
|
||||||
|
|
||||||
|
# The theme to use for HTML and HTML Help pages. See the documentation for
|
||||||
|
# a list of builtin themes.
|
||||||
|
#
|
||||||
|
html_theme = 'sphinx_rtd_theme'
|
||||||
|
|
||||||
|
# Add any paths that contain custom static files (such as style sheets) here,
|
||||||
|
# relative to this directory. They are copied after the builtin static files,
|
||||||
|
# so a file named "default.css" will overwrite the builtin "default.css".
|
||||||
|
#html_static_path = ['_static']
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 77 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 40 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 93 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 60 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 57 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 65 KiB |
@@ -0,0 +1,16 @@
|
|||||||
|
..
|
||||||
|
# Copyright (c) 2022, Arm Limited.
|
||||||
|
#
|
||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
################
|
||||||
|
ARM Corstone1000
|
||||||
|
################
|
||||||
|
|
||||||
|
.. toctree::
|
||||||
|
:maxdepth: 1
|
||||||
|
|
||||||
|
software-architecture
|
||||||
|
user-guide
|
||||||
|
release-notes
|
||||||
|
change-log
|
||||||
@@ -0,0 +1,199 @@
|
|||||||
|
..
|
||||||
|
# Copyright (c) 2022-2023, Arm Limited.
|
||||||
|
#
|
||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
#############
|
||||||
|
Release notes
|
||||||
|
#############
|
||||||
|
|
||||||
|
|
||||||
|
*************************
|
||||||
|
Disclaimer
|
||||||
|
*************************
|
||||||
|
|
||||||
|
You expressly assume all liabilities and risks relating to your use or operation
|
||||||
|
of Your Software and Your Hardware designed or modified using the Arm Tools,
|
||||||
|
including without limitation, Your software or Your Hardware designed or
|
||||||
|
intended for safety-critical applications. Should Your Software or Your Hardware
|
||||||
|
prove defective, you assume the entire cost of all necessary servicing, repair
|
||||||
|
or correction.
|
||||||
|
|
||||||
|
***********************
|
||||||
|
Release notes - 2023.06
|
||||||
|
***********************
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- FPGA supports Linux distro install and boot through installer. However, FVP only supports openSUSE raw image installation and boot.
|
||||||
|
- Due to the performance uplimit of MPS3 FPGA and FVP, some Linux distros like Fedora Rawhide can not boot on Corstone-1000 (i.e. user may experience timeouts or boot hang).
|
||||||
|
- PSA Crypto tests (psa-crypto-api-test command) take 30 minutes to complete for FVP and 1 hour for MPS3.
|
||||||
|
- Corstone-1000 SoC on FVP doesn't have a secure debug peripheral. It does on the MPS3 .
|
||||||
|
- The following limitations listed in the previous release are still applicable:
|
||||||
|
|
||||||
|
- UEFI Compliant - Boot from network protocols must be implemented -- FAILURE
|
||||||
|
|
||||||
|
- Known limitations regarding ACS tests - see previous release's notes.
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
-----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v2
|
||||||
|
https://developer.arm.com/downloads/-/download-fpga-images
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.19_21
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
**************************
|
||||||
|
Release notes - 2022.11.23
|
||||||
|
**************************
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- The external-system can not be reset individually on (or using) AN550_v1 FPGA release. However, the system-wide reset still applies to the external-system.
|
||||||
|
- FPGA supports Linux distro install and boot through installer. However, FVP only supports openSUSE raw image installation and boot.
|
||||||
|
- Due to the performance uplimit of MPS3 FPGA and FVP, some Linux distros like Fedora Rawhide can not boot on Corstone-1000 (i.e. user may experience timeouts or boot hang).
|
||||||
|
- Below SCT FAILURE is a known issues in the FVP:
|
||||||
|
UEFI Compliant - Boot from network protocols must be implemented -- FAILURE
|
||||||
|
- Below SCT FAILURE is a known issue when a terminal emulator (in the system where the user connects to serial ports) does not support 80x25 or 80x50 mode:
|
||||||
|
EFI_SIMPLE_TEXT_OUT_PROTOCOL.SetMode - SetMode() with valid mode -- FAILURE
|
||||||
|
- Known limitations regarding ACS tests: The behavior after running ACS tests on FVP is not consistent. Both behaviors are expected and are valid;
|
||||||
|
The system might boot till the Linux prompt. Or, the system might wait after finishing the ACS tests.
|
||||||
|
In both cases, the system executes the entire test suite and writes the results as stated in the user guide.
|
||||||
|
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
-----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v1
|
||||||
|
https://developer.arm.com/downloads/-/download-fpga-images
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.19_21
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
**************************
|
||||||
|
Release notes - 2022.04.04
|
||||||
|
**************************
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- FPGA support Linux distro install and boot through installer. However,
|
||||||
|
FVP only support openSUSE raw image installation and boot.
|
||||||
|
- Due to the performance uplimit of MPS3 FPGA and FVP, some Linux distros like Fedora Rawhide
|
||||||
|
cannot boot on Corstone-1000 (i.e. user may experience timeouts or boot hang).
|
||||||
|
- Below SCT FAILURE is a known issues in the FVP:
|
||||||
|
UEFI Compliant - Boot from network protocols must be implemented -- FAILURE
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
-----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v1
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.17_23
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
**************************
|
||||||
|
Release notes - 2022.02.25
|
||||||
|
**************************
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- The following tests only work on Corstone-1000 FPGA: ACS tests (SCT, FWTS,
|
||||||
|
BSA), manual capsule update test, Linux distro install and boot.
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v1
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.17_23
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
Release notes - 2022.02.21
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- The following tests only work on Corstone-1000 FPGA: ACS tests (SCT, FWTS,
|
||||||
|
BSA), manual capsule update test, Linux distro install and boot, psa-arch-test.
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v1
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.16.21
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
Release notes - 2022.01.18
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
|
||||||
|
- Before running each SystemReady-IR tests: ACS tests (SCT, FWTS, BSA), manual
|
||||||
|
capsule update test, Linux distro install and boot, etc., the SecureEnclave
|
||||||
|
flash must be cleaned. See user-guide "Clean Secure Flash Before Testing"
|
||||||
|
section.
|
||||||
|
|
||||||
|
Release notes - 2021.12.15
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
Software Features
|
||||||
|
------------------
|
||||||
|
The following components are present in the release:
|
||||||
|
|
||||||
|
- Yocto version Honister
|
||||||
|
- Linux kernel version 5.10
|
||||||
|
- U-Boot 2021.07
|
||||||
|
- OP-TEE version 3.14
|
||||||
|
- Trusted Firmware-A 2.5
|
||||||
|
- Trusted Firmware-M 1.5
|
||||||
|
- OpenAMP 347397decaa43372fc4d00f965640ebde042966d
|
||||||
|
- Trusted Services a365a04f937b9b76ebb2e0eeade226f208cbc0d2
|
||||||
|
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v1
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.16.21
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- The following tests only work on Corstone-1000 FPGA: ACS tests (SCT, FWTS,
|
||||||
|
BSA), manual capsule update test, Linux distro install and boot, and
|
||||||
|
psa-arch-tests.
|
||||||
|
- Only the manual capsule update from UEFI shell is supported on FPGA.
|
||||||
|
- Due to flash size limitation and to support A/B banks,the wic image provided
|
||||||
|
by the user should be smaller than 15MB.
|
||||||
|
- The failures in PSA Arch Crypto Test are known limitations with crypto
|
||||||
|
library. It requires further investigation. The user can refer to `PSA Arch Crypto Test Failure Analysis In TF-M V1.5 Release <https://developer.trustedfirmware.org/w/tf_m/release/psa_arch_crypto_test_failure_analysis_in_tf-m_v1.5_release/>`__
|
||||||
|
for the reason for each failing test.
|
||||||
|
|
||||||
|
|
||||||
|
Release notes - 2021.10.29
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
Software Features
|
||||||
|
-----------------
|
||||||
|
This initial release of Corstone-1000 supports booting Linux on the Cortex-A35
|
||||||
|
and TF-M/MCUBOOT in the Secure Enclave. The following components are present in
|
||||||
|
the release:
|
||||||
|
|
||||||
|
- Linux kernel version 5.10
|
||||||
|
- U-Boot 2021.07
|
||||||
|
- OP-TEE version 3.14
|
||||||
|
- Trusted Firmware-A 2.5
|
||||||
|
- Trusted Firmware-M 1.4
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
----------------
|
||||||
|
- This Software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.16.21
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
- No software support for external system(Cortex M3)
|
||||||
|
- No communication established between A35 and M0+
|
||||||
|
- Very basic functionality of booting Secure Enclave, Trusted Firmware-A , OP-TEE , u-boot and Linux are performed
|
||||||
|
|
||||||
|
Support
|
||||||
|
-------
|
||||||
|
For technical support email: support-subsystem-iot@arm.com
|
||||||
|
|
||||||
|
For all security issues, contact Arm by email at arm-security@arm.com.
|
||||||
|
|
||||||
|
--------------
|
||||||
|
|
||||||
|
*Copyright (c) 2022-2023, Arm Limited. All rights reserved.*
|
||||||
@@ -0,0 +1,242 @@
|
|||||||
|
..
|
||||||
|
# Copyright (c) 2022-2023, Arm Limited.
|
||||||
|
#
|
||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
######################
|
||||||
|
Software architecture
|
||||||
|
######################
|
||||||
|
|
||||||
|
|
||||||
|
*****************
|
||||||
|
Arm Corstone-1000
|
||||||
|
*****************
|
||||||
|
|
||||||
|
Arm Corstone-1000 is a reference solution for IoT devices. It is part of
|
||||||
|
Total Solution for IoT which consists of hardware and software reference
|
||||||
|
implementation.
|
||||||
|
|
||||||
|
Corstone-1000 software plus hardware reference solution is PSA Level-2 ready
|
||||||
|
certified (`PSA L2 Ready`_) as well as System Ready IR certified(`SRIR cert`_).
|
||||||
|
More information on the Corstone-1000 subsystem product and design can be
|
||||||
|
found at:
|
||||||
|
`Arm corstone1000 Software`_ and `Arm corstone1000 Technical Overview`_.
|
||||||
|
|
||||||
|
This readme explicitly focuses on the software part of the solution and
|
||||||
|
provides internal details on the software components. The reference
|
||||||
|
software package of the platform can be retrieved following instructions
|
||||||
|
present in the user-guide document.
|
||||||
|
|
||||||
|
***************
|
||||||
|
Design Overview
|
||||||
|
***************
|
||||||
|
|
||||||
|
The software architecture of Corstone-1000 platform is a reference
|
||||||
|
implementation of Platform Security Architecture (`PSA`_) which provides
|
||||||
|
framework to build secure IoT devices.
|
||||||
|
|
||||||
|
The base system architecture of the platform is created from three
|
||||||
|
different types of systems: Secure Enclave, Host and External System.
|
||||||
|
Each subsystem provides different functionality to overall SoC.
|
||||||
|
|
||||||
|
|
||||||
|
.. image:: images/CorstoneSubsystems.png
|
||||||
|
:width: 720
|
||||||
|
:alt: CorstoneSubsystems
|
||||||
|
|
||||||
|
|
||||||
|
The Secure Enclave System, provides PSA Root of Trust (RoT) and
|
||||||
|
cryptographic functions. It is based on an Cortex-M0+ processor,
|
||||||
|
CC312 Cryptographic Accelerator and peripherals, such as watchdog and
|
||||||
|
secure flash. Software running on the Secure Enclave is isolated via
|
||||||
|
hardware for enhanced security. Communication with the Secure Encalve
|
||||||
|
is achieved using Message Handling Units (MHUs) and shared memory.
|
||||||
|
On system power on, the Secure Enclave boots first. Its software
|
||||||
|
comprises of a ROM code (TF-M BL1), Mcuboot BL2, and
|
||||||
|
TrustedFirmware-M(`TF-M`_) as runtime software. The software design on
|
||||||
|
Secure Enclave follows Firmware Framework for M class
|
||||||
|
processor (`FF-M`_) specification.
|
||||||
|
|
||||||
|
The Host System is based on ARM Cotex-A35 processor with standardized
|
||||||
|
peripherals to allow for the booting of a Linux OS. The Cortex-A35 has
|
||||||
|
the TrustZone technology that allows secure and non-secure security
|
||||||
|
states in the processor. The software design in the Host System follows
|
||||||
|
Firmware Framework for A class procseeor (`FF-A`_) specification.
|
||||||
|
The boot process follows Trusted Boot Base Requirement (`TBBR`_).
|
||||||
|
The Host Subsystem is taken out of reset by the Secure Enclave system
|
||||||
|
during its final stages of the initialization. The Host subsystem runs
|
||||||
|
FF-A Secure Partitions(based on `Trusted Services`_) and OPTEE-OS
|
||||||
|
(`OPTEE-OS`_) in the secure world, and U-Boot(`U-Boot repo`_) and
|
||||||
|
linux (`linux repo`_) in the non-secure world. The communication between
|
||||||
|
non-secure and the secure world is performed via FF-A messages.
|
||||||
|
|
||||||
|
An external system is intended to implement use-case specific
|
||||||
|
functionality. The system is based on Cortex-M3 and run RTX RTOS.
|
||||||
|
Communictaion between external system and Host(cortex-A35) is performed
|
||||||
|
using MHU as transport mechanism and rpmsg messaging system.
|
||||||
|
|
||||||
|
Overall, the Corstone-1000 architecture is designed to cover a range
|
||||||
|
of Power, Performance, and Area (PPA) applications, and enable extension
|
||||||
|
for use-case specific applications, for example, sensors, cloud
|
||||||
|
connectivitiy, and edge computing.
|
||||||
|
|
||||||
|
*****************
|
||||||
|
Secure Boot Chain
|
||||||
|
*****************
|
||||||
|
|
||||||
|
For the security of a device, it is essential that only authorized
|
||||||
|
software should run on the device. The Corstone-1000 boot uses a
|
||||||
|
Secure Boot Chain process where an already authenticated image verifies
|
||||||
|
and loads the following software in the chain. For the boot chain
|
||||||
|
process to work, the start of the chain should be trusted, forming the
|
||||||
|
Root of Trust (RoT) of the device. The RoT of the device is immutable in
|
||||||
|
nature and encoded into the device by the device owner before it
|
||||||
|
is deployed into the field. In Corstone-1000, the BL1 image of the secure
|
||||||
|
enclave and content of the CC312 OTP (One Time Programmable) memory
|
||||||
|
forms the RoT. The BL1 image exists in ROM (Read Only Memory).
|
||||||
|
|
||||||
|
.. image:: images/SecureBootChain.png
|
||||||
|
:width: 870
|
||||||
|
:alt: SecureBootChain
|
||||||
|
|
||||||
|
It is a lengthy chain to boot the software on Corstone-1000. On power on,
|
||||||
|
the secure enclave starts executing BL1 code from the ROM which is the RoT
|
||||||
|
of the device. Authentication of an image involves the steps listed below:
|
||||||
|
|
||||||
|
- Load image from flash to dynamic RAM.
|
||||||
|
- The public key present in the image header is validated by comparing with the hash.
|
||||||
|
Depending on the image, the hash of the public key is either stored in the OTP or part
|
||||||
|
of the software which is being already verified in the previous stages.
|
||||||
|
- The image is validated using the public key.
|
||||||
|
|
||||||
|
In the secure enclave, BL1 authenticates the BL2 and passes the execution
|
||||||
|
control. BL2 authenticates the initial boot loader of the host (Host TF-A BL2)
|
||||||
|
and TF-M. The execution control is now passed to TF-M. TF-M being the run
|
||||||
|
time executable of secure enclave which initializes itself and, at the end,
|
||||||
|
brings the host CPU out of rest. The host follows the boot standard defined
|
||||||
|
in the `TBBR`_ to authenticate the secure and non-secure software.
|
||||||
|
|
||||||
|
***************
|
||||||
|
Secure Services
|
||||||
|
***************
|
||||||
|
|
||||||
|
Corstone-1000 is unique in providing a secure environment to run a secure
|
||||||
|
workload. The platform has TrustZone technology in the Host subsystem but
|
||||||
|
it also has hardware isolated secure enclave environment to run such secure
|
||||||
|
workloads. In Corstone-1000, known Secure Services such as Crypto, Protected
|
||||||
|
Storage, Internal Trusted Storage and Attestation are available via PSA
|
||||||
|
Functional APIs in TF-M. There is no difference for a user communicating to
|
||||||
|
these services which are running on a secure enclave instead of the
|
||||||
|
secure world of the host subsystem. The below diagram presents the data
|
||||||
|
flow path for such calls.
|
||||||
|
|
||||||
|
|
||||||
|
.. image:: images/SecureServices.png
|
||||||
|
:width: 930
|
||||||
|
:alt: SecureServices
|
||||||
|
|
||||||
|
|
||||||
|
The SE Proxy SP (Secure Enclave Proxy Secure Partition) is a proxy partition
|
||||||
|
managed by OPTEE which forwards such calls to the secure enclave. The
|
||||||
|
solution relies on OpenAMP which uses shared memory and MHU interrupts as
|
||||||
|
a doorbell for communication between two cores. Corstone-1000 implements
|
||||||
|
isolation level 2. Cortex-M0+ MPU (Memory Protection Unit) is used to implement
|
||||||
|
isolation level 2.
|
||||||
|
|
||||||
|
For a user to define its own secure service, both the options of the host
|
||||||
|
secure world or secure encalve are available. It's a trade-off between
|
||||||
|
lower latency vs higher security. Services running on a secure enclave are
|
||||||
|
secure by real hardware isolation but have a higher latency path. In the
|
||||||
|
second scenario, the services running on the secure world of the host
|
||||||
|
subsystem have lower latency but virtual hardware isolation created by
|
||||||
|
TrustZone technology.
|
||||||
|
|
||||||
|
|
||||||
|
**********************
|
||||||
|
Secure Firmware Update
|
||||||
|
**********************
|
||||||
|
|
||||||
|
Apart from always booting the authorized images, it is also essential that
|
||||||
|
the device only accepts the authorized images in the firmware update
|
||||||
|
process. Corstone-1000 supports OTA (Over the Air) firmware updates and
|
||||||
|
follows Platform Security Firmware Update sepcification (`FWU`_).
|
||||||
|
|
||||||
|
As standardized into `FWU`_, the external flash is divided into two
|
||||||
|
banks of which one bank has currently running images and the other bank is
|
||||||
|
used for staging new images. There are four updatable units, i.e. Secure
|
||||||
|
Enclave's BL2 and TF-M, and Host's FIP (Firmware Image Package) and Kernel
|
||||||
|
Image (the initramfs bundle). The new images are accepted in the form of a UEFI capsule.
|
||||||
|
|
||||||
|
|
||||||
|
.. image:: images/ExternalFlash.png
|
||||||
|
:width: 690
|
||||||
|
:alt: ExternalFlash
|
||||||
|
|
||||||
|
|
||||||
|
The Metadata Block in the flash has the below firmware update state machine.
|
||||||
|
TF-M runs an OTA service that is responsible for accepting and updating the
|
||||||
|
images in the flash. The communication between the UEFI Capsule update
|
||||||
|
subsystem and the OTA service follows the same data path explained above.
|
||||||
|
The OTA service writes the new images to the passive bank after successful
|
||||||
|
capsule verification. It changes the state of the system to trial state and
|
||||||
|
triggers the reset. Boot loaders in Secure Enclave and Host read the Metadata
|
||||||
|
block to get the information on the boot bank. In the successful trial stage,
|
||||||
|
the acknowledgment from the host moves the state of the system from trial to
|
||||||
|
regular. Any failure in the trial stage or system hangs leads to a system
|
||||||
|
reset. This is made sure by the use of watchdog hardware. The Secure Enclave's
|
||||||
|
BL1 has the logic to identify multiple resets and eventually switch back to the
|
||||||
|
previous good bank. The ability to revert to the previous bank is crucial to
|
||||||
|
guarantee the availability of the device.
|
||||||
|
|
||||||
|
|
||||||
|
.. image:: images/SecureFirmwareUpdate.png
|
||||||
|
:width: 430
|
||||||
|
:alt: SecureFirmwareUpdate
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
******************************
|
||||||
|
UEFI Runtime Support in U-Boot
|
||||||
|
******************************
|
||||||
|
|
||||||
|
Implementation of UEFI boottime and runtime APIs require variable storage.
|
||||||
|
In Corstone-1000, these UEFI variables are stored in the Protected Storage
|
||||||
|
service. The below diagram presents the data flow to store UEFI variables.
|
||||||
|
The U-Boot implementation of the UEFI subsystem uses the U-Boot FF-A driver to
|
||||||
|
communicate with the SMM Service in the secure world. The backend of the
|
||||||
|
SMM service uses the proxy PS from the SE Proxy SP. From there on, the PS
|
||||||
|
calls are forwarded to the secure enclave as explained above.
|
||||||
|
|
||||||
|
|
||||||
|
.. image:: images/UEFISupport.png
|
||||||
|
:width: 590
|
||||||
|
:alt: UEFISupport
|
||||||
|
|
||||||
|
|
||||||
|
***************
|
||||||
|
References
|
||||||
|
***************
|
||||||
|
`ARM corstone1000 Search`_
|
||||||
|
|
||||||
|
`Arm security features`_
|
||||||
|
|
||||||
|
--------------
|
||||||
|
|
||||||
|
*Copyright (c) 2022-2023, Arm Limited. All rights reserved.*
|
||||||
|
|
||||||
|
.. _Arm corstone1000 Technical Overview: https://developer.arm.com/documentation/102360/0000
|
||||||
|
.. _Arm corstone1000 Software: https://developer.arm.com/Tools%20and%20Software/Corstone-1000%20Software
|
||||||
|
.. _Arm corstone1000 Search: https://developer.arm.com/search#q=corstone-1000
|
||||||
|
.. _Arm security features: https://www.arm.com/architecture/security-features/platform-security
|
||||||
|
.. _linux repo: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
|
||||||
|
.. _FF-A: https://developer.arm.com/documentation/den0077/latest
|
||||||
|
.. _FF-M: https://developer.arm.com/-/media/Files/pdf/PlatformSecurityArchitecture/Architect/DEN0063-PSA_Firmware_Framework-1.0.0-2.pdf?revision=2d1429fa-4b5b-461a-a60e-4ef3d8f7f4b4&hash=3BFD6F3E687F324672F18E5BE9F08EDC48087C93
|
||||||
|
.. _FWU: https://developer.arm.com/documentation/den0118/a/
|
||||||
|
.. _OPTEE-OS: https://github.com/OP-TEE/optee_os
|
||||||
|
.. _PSA: https://www.psacertified.org/
|
||||||
|
.. _PSA L2 Ready: https://www.psacertified.org/products/corstone-1000/
|
||||||
|
.. _SRIR cert: https://armkeil.blob.core.windows.net/developer/Files/pdf/certificate-list/arm-systemready-ir-certification-arm-corstone-1000.pdf
|
||||||
|
.. _TBBR: https://developer.arm.com/documentation/den0006/latest
|
||||||
|
.. _TF-M: https://www.trustedfirmware.org/projects/tf-m/
|
||||||
|
.. _Trusted Services: https://www.trustedfirmware.org/projects/trusted-services/
|
||||||
|
.. _U-Boot repo: https://github.com/u-boot/u-boot.git
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,61 +0,0 @@
|
|||||||
# Armv7-A Base Platform FVP Support in meta-arm-bsp
|
|
||||||
|
|
||||||
## How to build and run
|
|
||||||
|
|
||||||
### Configuration:
|
|
||||||
In the local.conf file, MACHINE should be set as follows:
|
|
||||||
MACHINE ?= "fvp-base-arm32"
|
|
||||||
|
|
||||||
### Build:
|
|
||||||
```bash$ bitbake core-image-minimal```
|
|
||||||
|
|
||||||
### Run:
|
|
||||||
To Run the Fixed Virtual Platform simulation tool you must download "Armv8-A
|
|
||||||
Base Platform FVP" from Arm developer (This might require the user to
|
|
||||||
register) from this address:
|
|
||||||
https://developer.arm.com/tools-and-software/simulation-models/fixed-virtual-platforms
|
|
||||||
and install it on your host PC.
|
|
||||||
|
|
||||||
Fast Models Fixed Virtual Platforms (FVP) Reference Guide:
|
|
||||||
https://developer.arm.com/docs/100966/latest
|
|
||||||
|
|
||||||
Armv8‑A Foundation Platform User Guide:
|
|
||||||
https://developer.arm.com/docs/100961/latest/
|
|
||||||
|
|
||||||
|
|
||||||
Once done, do the following to build and run an image:
|
|
||||||
```bash$ bitbake core-image-minimal```
|
|
||||||
```bash$ export YOCTO_DEPLOY_IMGS_DIR="<yocto-build-dir/tmp/deploy/images/fvp-base-arm32>"```
|
|
||||||
```bash$ cd <path-to-Base_RevC_AEMv8A_pkg-dir/models/Linux64_GCC-X.X/>```
|
|
||||||
```
|
|
||||||
bash$ ./FVP_Base_RevC-2xAEMv8A -C bp.virtio_net.enabled=1 \
|
|
||||||
-C cache_state_modelled=0 \
|
|
||||||
-C bp.secureflashloader.fname=${YOCTO_DEPLOY_IMGS_DIR}/bl1-fvp.bin \
|
|
||||||
-C bp.flashloader0.fname=${YOCTO_DEPLOY_IMGS_DIR}/fip-fvp.bin \
|
|
||||||
--data cluster0.cpu0=${YOCTO_DEPLOY_IMGS_DIR}/Image@0x80080000 \
|
|
||||||
-C bp.virtioblockdevice.image_path=${YOCTO_DEPLOY_IMGS_DIR}/core-image-minimal-fvp-base-arm32.wic \
|
|
||||||
-C cluster0.cpu0.CONFIG64=0 \
|
|
||||||
-C cluster0.cpu1.CONFIG64=0 \
|
|
||||||
-C cluster0.cpu2.CONFIG64=0 \
|
|
||||||
-C cluster0.cpu3.CONFIG64=0 \
|
|
||||||
-C cluster1.cpu0.CONFIG64=0 \
|
|
||||||
-C cluster1.cpu1.CONFIG64=0 \
|
|
||||||
-C cluster1.cpu2.CONFIG64=0 \
|
|
||||||
-C cluster1.cpu3.CONFIG64=0 \
|
|
||||||
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
If you have built a configuration without a ramdisk, you can use the following
|
|
||||||
command in U-boot to start Linux:
|
|
||||||
```fvp32# bootz 0x80080000 - 0x82000000```
|
|
||||||
|
|
||||||
## Devices supported in the kernel
|
|
||||||
- serial
|
|
||||||
- virtio disk
|
|
||||||
- network
|
|
||||||
- watchdog
|
|
||||||
- rtc
|
|
||||||
|
|
||||||
## Devices not supported or not functional
|
|
||||||
None
|
|
||||||
@@ -3,45 +3,22 @@
|
|||||||
## Howto Build and Run
|
## Howto Build and Run
|
||||||
|
|
||||||
### Configuration:
|
### Configuration:
|
||||||
In the local.conf file, MACHINE should be set as follow:
|
In the local.conf file, `MACHINE` should be set:
|
||||||
MACHINE ?= "fvp-base"
|
```
|
||||||
|
MACHINE = "fvp-base"
|
||||||
|
```
|
||||||
|
|
||||||
### Build:
|
### Build:
|
||||||
```bash$ bitbake core-image-minimal```
|
```
|
||||||
|
$ bitbake core-image-base
|
||||||
|
```
|
||||||
|
|
||||||
### Run:
|
### Run:
|
||||||
To Run the Fixed Virtual Platform simulation tool you must download "Armv8-A
|
The `fvp-base` machine has support for the `runfvp` script, so running is simple:
|
||||||
Base Platform FVP" from Arm developer (This might require the user to
|
|
||||||
register) from this address:
|
|
||||||
https://developer.arm.com/tools-and-software/simulation-models/fixed-virtual-platforms
|
|
||||||
and install it on your host PC.
|
|
||||||
|
|
||||||
Fast Models Fixed Virtual Platforms (FVP) Reference Guide:
|
|
||||||
https://developer.arm.com/docs/100966/latest
|
|
||||||
|
|
||||||
Armv8‑A Foundation Platform User Guide:
|
|
||||||
https://developer.arm.com/docs/100961/latest/
|
|
||||||
|
|
||||||
|
|
||||||
Once done, do the following to build and run an image:
|
|
||||||
```bash$ bitbake core-image-minimal```
|
|
||||||
```bash$ export YOCTO_DEPLOY_IMGS_DIR="<yocto-build-dir/tmp/deploy/images/fvp-base>"```
|
|
||||||
```bash$ cd <path-to-Base_RevC_AEMv8A_pkg-dir/models/Linux64_GCC-X.X/>```
|
|
||||||
```
|
```
|
||||||
bash$ ./FVP_Base_RevC-2xAEMv8A -C bp.virtio_net.enabled=1 \
|
$ runfvp tmp/deploy/images/fvp-base/core-image-base-fvp-base.fvpconf
|
||||||
-C cache_state_modelled=0 \
|
|
||||||
-C bp.secureflashloader.fname=${YOCTO_DEPLOY_IMGS_DIR}/bl1-fvp.bin \
|
|
||||||
-C bp.flashloader0.fname=${YOCTO_DEPLOY_IMGS_DIR}/fip-fvp.bin \
|
|
||||||
--data cluster0.cpu0=${YOCTO_DEPLOY_IMGS_DIR}/Image@0x80080000 \
|
|
||||||
--data cluster0.cpu0=${YOCTO_DEPLOY_IMGS_DIR}/fvp-base-gicv3-psci-custom.dtb@0x83000000 \
|
|
||||||
-C bp.virtioblockdevice.image_path=${YOCTO_DEPLOY_IMGS_DIR}/core-image-minimal-fvp-base.wic
|
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
If you have built a configuration without a ramdisk, you can use the following
|
|
||||||
command in U-boot to start Linux:
|
|
||||||
```VExpress64# booti 0x80080000 - 0x83000000```
|
|
||||||
|
|
||||||
## Devices supported in the kernel
|
## Devices supported in the kernel
|
||||||
- serial
|
- serial
|
||||||
- virtio disk
|
- virtio disk
|
||||||
|
|||||||
@@ -27,9 +27,9 @@ The fvp-baser-aemv8r64 Yocto MACHINE supports the following BSP components,
|
|||||||
where either a standard or Real-Time Linux kernel (PREEMPT\_RT) can be built
|
where either a standard or Real-Time Linux kernel (PREEMPT\_RT) can be built
|
||||||
and run:
|
and run:
|
||||||
|
|
||||||
- FVP_Base_AEMv8R: v11.19.14
|
- FVP_Base_AEMv8R: v11.20.15
|
||||||
- boot-wrapper-aarch64: provides PSCI support
|
- boot-wrapper-aarch64: provides PSCI support
|
||||||
- U-Boot: v2022.04 - provides UEFI services
|
- U-Boot: v2022.07 - provides UEFI services
|
||||||
- Linux kernel: linux-yocto-5.15
|
- Linux kernel: linux-yocto-5.15
|
||||||
- Linux kernel with PREEMPT\_RT support: linux-yocto-rt-5.15
|
- Linux kernel with PREEMPT\_RT support: linux-yocto-rt-5.15
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,12 @@
|
|||||||
|
# Copyright (c) 2022, Arm Limited.
|
||||||
|
#
|
||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
# Read The Docs specific
|
||||||
|
jinja2==3.1.1
|
||||||
|
|
||||||
|
# Required to build the documentation
|
||||||
|
sphinx==4.5.0
|
||||||
|
sphinx_rtd_theme==1.0.0
|
||||||
|
sphinx-copybutton==0.5.0
|
||||||
|
docutils==0.17.1
|
||||||
+7
-7
@@ -1,4 +1,4 @@
|
|||||||
From 3e7cfbe39a2a053d2a6b0d928cc172ed9d1c6da8 Mon Sep 17 00:00:00 2001
|
From 545f6950ae4dc55b4974986aa9629adb16eaf4e1 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 May 2021 07:25:00 +0100
|
Date: Tue, 25 May 2021 07:25:00 +0100
|
||||||
Subject: [PATCH] aarch64: Rename labels and prepare for lower EL booting
|
Subject: [PATCH] aarch64: Rename labels and prepare for lower EL booting
|
||||||
@@ -18,10 +18,10 @@ Signed-off-by: Jaxson Han <jaxson.han@arm.com>
|
|||||||
3 files changed, 27 insertions(+), 14 deletions(-)
|
3 files changed, 27 insertions(+), 14 deletions(-)
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index 27ba449..84e1646 100644
|
index d682ba5..fab694e 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -21,18 +21,30 @@ ASM_FUNC(_start)
|
@@ -34,18 +34,30 @@ ASM_FUNC(_start)
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* EL3 initialisation
|
* EL3 initialisation
|
||||||
@@ -56,7 +56,7 @@ index 27ba449..84e1646 100644
|
|||||||
orr x0, x0, #(1 << 0) // Non-secure EL1
|
orr x0, x0, #(1 << 0) // Non-secure EL1
|
||||||
orr x0, x0, #(1 << 8) // HVC enable
|
orr x0, x0, #(1 << 8) // HVC enable
|
||||||
|
|
||||||
@@ -124,7 +136,7 @@ ASM_FUNC(_start)
|
@@ -145,7 +157,7 @@ ASM_FUNC(_start)
|
||||||
|
|
||||||
bl gic_secure_init
|
bl gic_secure_init
|
||||||
|
|
||||||
@@ -65,7 +65,7 @@ index 27ba449..84e1646 100644
|
|||||||
|
|
||||||
err_invalid_id:
|
err_invalid_id:
|
||||||
b .
|
b .
|
||||||
@@ -151,7 +163,7 @@ ASM_FUNC(jump_kernel)
|
@@ -172,7 +184,7 @@ ASM_FUNC(jump_kernel)
|
||||||
bl find_logical_id
|
bl find_logical_id
|
||||||
bl setup_stack // Reset stack pointer
|
bl setup_stack // Reset stack pointer
|
||||||
|
|
||||||
@@ -74,7 +74,7 @@ index 27ba449..84e1646 100644
|
|||||||
cmp w0, #0 // Prepare Z flag
|
cmp w0, #0 // Prepare Z flag
|
||||||
|
|
||||||
mov x0, x20
|
mov x0, x20
|
||||||
@@ -160,7 +172,7 @@ ASM_FUNC(jump_kernel)
|
@@ -181,7 +193,7 @@ ASM_FUNC(jump_kernel)
|
||||||
mov x3, x23
|
mov x3, x23
|
||||||
|
|
||||||
b.eq 1f
|
b.eq 1f
|
||||||
@@ -83,7 +83,7 @@ index 27ba449..84e1646 100644
|
|||||||
|
|
||||||
1: mov x4, #SPSR_KERNEL
|
1: mov x4, #SPSR_KERNEL
|
||||||
|
|
||||||
@@ -178,5 +190,5 @@ ASM_FUNC(jump_kernel)
|
@@ -199,5 +211,5 @@ ASM_FUNC(jump_kernel)
|
||||||
|
|
||||||
.data
|
.data
|
||||||
.align 3
|
.align 3
|
||||||
|
|||||||
+4
-4
@@ -1,4 +1,4 @@
|
|||||||
From 26f9b5354c2de9cc052531096ff92b04c3a3846f Mon Sep 17 00:00:00 2001
|
From bad32d3fc127a421be416b17e4f7d6d514f06abb Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 May 2021 07:25:00 +0100
|
Date: Tue, 25 May 2021 07:25:00 +0100
|
||||||
Subject: [PATCH] aarch64: Prepare for EL1 booting
|
Subject: [PATCH] aarch64: Prepare for EL1 booting
|
||||||
@@ -15,10 +15,10 @@ Reviewed-by: Andre Przywara <andre.przywara@arm.com>
|
|||||||
2 files changed, 6 insertions(+), 1 deletion(-)
|
2 files changed, 6 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index 84e1646..b589744 100644
|
index fab694e..5105b41 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -156,10 +156,14 @@ ASM_FUNC(jump_kernel)
|
@@ -177,10 +177,14 @@ ASM_FUNC(jump_kernel)
|
||||||
ldr x0, =SCTLR_EL1_KERNEL
|
ldr x0, =SCTLR_EL1_KERNEL
|
||||||
msr sctlr_el1, x0
|
msr sctlr_el1, x0
|
||||||
|
|
||||||
@@ -35,7 +35,7 @@ index 84e1646..b589744 100644
|
|||||||
bl setup_stack // Reset stack pointer
|
bl setup_stack // Reset stack pointer
|
||||||
|
|
||||||
diff --git a/arch/aarch64/include/asm/cpu.h b/arch/aarch64/include/asm/cpu.h
|
diff --git a/arch/aarch64/include/asm/cpu.h b/arch/aarch64/include/asm/cpu.h
|
||||||
index 63eb1c3..b1003f4 100644
|
index 49d3f86..3767da3 100644
|
||||||
--- a/arch/aarch64/include/asm/cpu.h
|
--- a/arch/aarch64/include/asm/cpu.h
|
||||||
+++ b/arch/aarch64/include/asm/cpu.h
|
+++ b/arch/aarch64/include/asm/cpu.h
|
||||||
@@ -11,6 +11,7 @@
|
@@ -11,6 +11,7 @@
|
||||||
|
|||||||
+6
-6
@@ -1,4 +1,4 @@
|
|||||||
From ce628de7699dd6401ddf713efaa49872e2733619 Mon Sep 17 00:00:00 2001
|
From 252cbd36e51414b60ab68306f9c38e358709494d Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 May 2021 07:25:00 +0100
|
Date: Tue, 25 May 2021 07:25:00 +0100
|
||||||
Subject: [PATCH] aarch64: Prepare for lower EL booting
|
Subject: [PATCH] aarch64: Prepare for lower EL booting
|
||||||
@@ -17,11 +17,11 @@ Reviewed-by: Andre Przywara <andre.przywara@arm.com>
|
|||||||
1 file changed, 13 insertions(+), 2 deletions(-)
|
1 file changed, 13 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index b589744..6b45afc 100644
|
index 5105b41..243198d 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -130,7 +130,16 @@ el3_init:
|
@@ -151,7 +151,16 @@ el3_init:
|
||||||
mov x0, #ZCR_EL3_LEN_MASK // SVE: Enable full vector len
|
mov x0, #ZCR_EL3_LEN_MAX // SVE: Enable full vector len
|
||||||
msr ZCR_EL3, x0 // for EL2.
|
msr ZCR_EL3, x0 // for EL2.
|
||||||
|
|
||||||
-1:
|
-1:
|
||||||
@@ -38,7 +38,7 @@ index b589744..6b45afc 100644
|
|||||||
ldr x0, =COUNTER_FREQ
|
ldr x0, =COUNTER_FREQ
|
||||||
msr cntfrq_el0, x0
|
msr cntfrq_el0, x0
|
||||||
|
|
||||||
@@ -178,7 +187,7 @@ ASM_FUNC(jump_kernel)
|
@@ -199,7 +208,7 @@ ASM_FUNC(jump_kernel)
|
||||||
b.eq 1f
|
b.eq 1f
|
||||||
br x19 // Keep current EL
|
br x19 // Keep current EL
|
||||||
|
|
||||||
@@ -47,7 +47,7 @@ index b589744..6b45afc 100644
|
|||||||
|
|
||||||
/*
|
/*
|
||||||
* If bit 0 of the kernel address is set, we're entering in AArch32
|
* If bit 0 of the kernel address is set, we're entering in AArch32
|
||||||
@@ -196,3 +205,5 @@ ASM_FUNC(jump_kernel)
|
@@ -217,3 +226,5 @@ ASM_FUNC(jump_kernel)
|
||||||
.align 3
|
.align 3
|
||||||
flag_keep_el:
|
flag_keep_el:
|
||||||
.long 0
|
.long 0
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
From 483d363bf825082b6db6de3c57d169e741861891 Mon Sep 17 00:00:00 2001
|
From bff110a95a5e4c9db2d61e629b4aa4b84530201e Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 May 2021 07:25:00 +0100
|
Date: Tue, 25 May 2021 07:25:00 +0100
|
||||||
Subject: [PATCH] gic-v3: Prepare for gicv3 with EL2
|
Subject: [PATCH] gic-v3: Prepare for gicv3 with EL2
|
||||||
|
|||||||
+3
-3
@@ -1,4 +1,4 @@
|
|||||||
From be814863cdd5f61d9a16eec012d500550053c8c6 Mon Sep 17 00:00:00 2001
|
From ba955efb35ce1d41b562190d7c2fbcbcf8ef97ff Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 May 2021 07:25:00 +0100
|
Date: Tue, 25 May 2021 07:25:00 +0100
|
||||||
Subject: [PATCH] aarch64: Prepare for booting with EL2
|
Subject: [PATCH] aarch64: Prepare for booting with EL2
|
||||||
@@ -15,10 +15,10 @@ Reviewed-by: Andre Przywara <andre.przywara@arm.com>
|
|||||||
2 files changed, 17 insertions(+), 1 deletion(-)
|
2 files changed, 17 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index 6b45afc..908764a 100644
|
index 243198d..3593ca5 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -195,10 +195,18 @@ ASM_FUNC(jump_kernel)
|
@@ -216,10 +216,18 @@ ASM_FUNC(jump_kernel)
|
||||||
*/
|
*/
|
||||||
bfi x4, x19, #5, #1
|
bfi x4, x19, #5, #1
|
||||||
|
|
||||||
|
|||||||
+7
-7
@@ -1,4 +1,4 @@
|
|||||||
From 81df76f8d94cb6c31c01739b078a72bdb8497441 Mon Sep 17 00:00:00 2001
|
From 8e44fac113d935affed1550480631f3fe7f30584 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 May 2021 07:25:00 +0100
|
Date: Tue, 25 May 2021 07:25:00 +0100
|
||||||
Subject: [PATCH] aarch64: Introduce EL2 boot code for Armv8-R AArch64
|
Subject: [PATCH] aarch64: Introduce EL2 boot code for Armv8-R AArch64
|
||||||
@@ -36,10 +36,10 @@ Signed-off-by: Jaxson Han <jaxson.han@arm.com>
|
|||||||
2 files changed, 92 insertions(+), 2 deletions(-)
|
2 files changed, 92 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index 908764a..def9192 100644
|
index 3593ca5..a219ea7 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -24,16 +24,24 @@ ASM_FUNC(_start)
|
@@ -37,16 +37,24 @@ ASM_FUNC(_start)
|
||||||
* Boot sequence
|
* Boot sequence
|
||||||
* If CurrentEL == EL3, then goto EL3 initialisation and drop to
|
* If CurrentEL == EL3, then goto EL3 initialisation and drop to
|
||||||
* lower EL before entering the kernel.
|
* lower EL before entering the kernel.
|
||||||
@@ -66,7 +66,7 @@ index 908764a..def9192 100644
|
|||||||
mov w0, #1
|
mov w0, #1
|
||||||
ldr x1, =flag_keep_el
|
ldr x1, =flag_keep_el
|
||||||
str w0, [x1]
|
str w0, [x1]
|
||||||
@@ -139,6 +147,85 @@ el3_init:
|
@@ -160,6 +168,85 @@ el3_init:
|
||||||
str w0, [x1]
|
str w0, [x1]
|
||||||
b el_max_init
|
b el_max_init
|
||||||
|
|
||||||
@@ -152,7 +152,7 @@ index 908764a..def9192 100644
|
|||||||
el_max_init:
|
el_max_init:
|
||||||
ldr x0, =COUNTER_FREQ
|
ldr x0, =COUNTER_FREQ
|
||||||
msr cntfrq_el0, x0
|
msr cntfrq_el0, x0
|
||||||
@@ -148,6 +235,7 @@ el_max_init:
|
@@ -169,6 +256,7 @@ el_max_init:
|
||||||
b start_el_max
|
b start_el_max
|
||||||
|
|
||||||
err_invalid_id:
|
err_invalid_id:
|
||||||
@@ -161,7 +161,7 @@ index 908764a..def9192 100644
|
|||||||
|
|
||||||
/*
|
/*
|
||||||
diff --git a/arch/aarch64/include/asm/cpu.h b/arch/aarch64/include/asm/cpu.h
|
diff --git a/arch/aarch64/include/asm/cpu.h b/arch/aarch64/include/asm/cpu.h
|
||||||
index b1003f4..91f803c 100644
|
index 3767da3..3c0e00d 100644
|
||||||
--- a/arch/aarch64/include/asm/cpu.h
|
--- a/arch/aarch64/include/asm/cpu.h
|
||||||
+++ b/arch/aarch64/include/asm/cpu.h
|
+++ b/arch/aarch64/include/asm/cpu.h
|
||||||
@@ -25,6 +25,7 @@
|
@@ -25,6 +25,7 @@
|
||||||
@@ -172,7 +172,7 @@ index b1003f4..91f803c 100644
|
|||||||
#define SPSR_EL2H (9 << 0) /* EL2 Handler mode */
|
#define SPSR_EL2H (9 << 0) /* EL2 Handler mode */
|
||||||
#define SPSR_HYP (0x1a << 0) /* M[3:0] = hyp, M[4] = AArch32 */
|
#define SPSR_HYP (0x1a << 0) /* M[3:0] = hyp, M[4] = AArch32 */
|
||||||
|
|
||||||
@@ -43,6 +44,7 @@
|
@@ -50,6 +51,7 @@
|
||||||
#else
|
#else
|
||||||
#define SCTLR_EL1_KERNEL SCTLR_EL1_RES1
|
#define SCTLR_EL1_KERNEL SCTLR_EL1_RES1
|
||||||
#define SPSR_KERNEL (SPSR_A | SPSR_D | SPSR_I | SPSR_F | SPSR_EL2H)
|
#define SPSR_KERNEL (SPSR_A | SPSR_D | SPSR_I | SPSR_F | SPSR_EL2H)
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
From f5a31b4f4ea8daaa0d337d5a2322ddb1912083fc Mon Sep 17 00:00:00 2001
|
From 0b9a966b8a28961b078215ee7169e32a976d5e7d Mon Sep 17 00:00:00 2001
|
||||||
From: Qi Feng <qi.feng@arm.com>
|
From: Qi Feng <qi.feng@arm.com>
|
||||||
Date: Wed, 26 May 2021 17:52:01 +0800
|
Date: Wed, 26 May 2021 17:52:01 +0800
|
||||||
Subject: [PATCH] Allow --enable-psci to choose between smc and hvc
|
Subject: [PATCH] Allow --enable-psci to choose between smc and hvc
|
||||||
@@ -40,7 +40,7 @@ Signed-off-by: Huifeng Zhang <Huifeng.Zhang@arm.com>
|
|||||||
2 files changed, 14 insertions(+), 10 deletions(-)
|
2 files changed, 14 insertions(+), 10 deletions(-)
|
||||||
|
|
||||||
diff --git a/Makefile.am b/Makefile.am
|
diff --git a/Makefile.am b/Makefile.am
|
||||||
index f941b07..88a27de 100644
|
index 5731a19..fc66662 100644
|
||||||
--- a/Makefile.am
|
--- a/Makefile.am
|
||||||
+++ b/Makefile.am
|
+++ b/Makefile.am
|
||||||
@@ -50,11 +50,11 @@ endif
|
@@ -50,11 +50,11 @@ endif
|
||||||
|
|||||||
+3
-3
@@ -1,4 +1,4 @@
|
|||||||
From 3f4614e02f0f8d2522510578da2752f8e3511bb3 Mon Sep 17 00:00:00 2001
|
From 521c121eccb386aca7c75d92528e495546adccec Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Mon, 25 Oct 2021 17:09:13 +0800
|
Date: Mon, 25 Oct 2021 17:09:13 +0800
|
||||||
Subject: [PATCH] aarch64: Disable CNTPCT_EL0 trap for v8-R64
|
Subject: [PATCH] aarch64: Disable CNTPCT_EL0 trap for v8-R64
|
||||||
@@ -24,10 +24,10 @@ Change-Id: I4147e66341c8153312021e6f2ab67d0037246da1
|
|||||||
1 file changed, 12 insertions(+)
|
1 file changed, 12 insertions(+)
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index def9192..6dbd5cc 100644
|
index a219ea7..27b1139 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -219,6 +219,18 @@ el2_init:
|
@@ -240,6 +240,18 @@ el2_init:
|
||||||
orr x0, x0, #(1 << 41) // HCR_EL2.API
|
orr x0, x0, #(1 << 41) // HCR_EL2.API
|
||||||
|
|
||||||
1: msr hcr_el2, x0
|
1: msr hcr_el2, x0
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
From 2851f0e6c1216894b9498d7b91256bb1ef49e544 Mon Sep 17 00:00:00 2001
|
From 780df234d98db81485b1f351f902a68def35c9d4 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 2 Nov 2021 15:10:28 +0800
|
Date: Tue, 2 Nov 2021 15:10:28 +0800
|
||||||
Subject: [PATCH] lds: Mark the mem range
|
Subject: [PATCH] lds: Mark the mem range
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
From fadf04f44b679d85e55b2e5f220fecbebb52ad03 Mon Sep 17 00:00:00 2001
|
From b3762b6c5a56bf594bc5cb63d145e8efd86e106e Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 28 Dec 2021 17:02:17 +0800
|
Date: Tue, 28 Dec 2021 17:02:17 +0800
|
||||||
Subject: [PATCH] common: Introduce the libfdt
|
Subject: [PATCH] common: Introduce the libfdt
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
From 0f2c7ca446063be6b193fbf870d38c0af19e15c5 Mon Sep 17 00:00:00 2001
|
From e2eff4f80e65cb3fcbe6345b5376a6bf7de7e2cc Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 28 Dec 2021 17:28:25 +0800
|
Date: Tue, 28 Dec 2021 17:28:25 +0800
|
||||||
Subject: [PATCH] common: Add essential libc functions
|
Subject: [PATCH] common: Add essential libc functions
|
||||||
|
|||||||
+6
-6
@@ -1,4 +1,4 @@
|
|||||||
From de5d2b6c200ae5dd8113751e58bf7cf5844eec5a Mon Sep 17 00:00:00 2001
|
From f4d5cf4c3424598a2b3bb391717313b70c79ea28 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 28 Dec 2021 17:42:48 +0800
|
Date: Tue, 28 Dec 2021 17:42:48 +0800
|
||||||
Subject: [PATCH] Makefile: Add the libfdt to the Makefile system
|
Subject: [PATCH] Makefile: Add the libfdt to the Makefile system
|
||||||
@@ -17,7 +17,7 @@ Change-Id: I472bc28cdc5cde3b22461a4b7d7a3752ae382b4b
|
|||||||
1 file changed, 9 insertions(+), 2 deletions(-)
|
1 file changed, 9 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
diff --git a/Makefile.am b/Makefile.am
|
diff --git a/Makefile.am b/Makefile.am
|
||||||
index 88a27de..5e8668a 100644
|
index fc66662..ab2c3a9 100644
|
||||||
--- a/Makefile.am
|
--- a/Makefile.am
|
||||||
+++ b/Makefile.am
|
+++ b/Makefile.am
|
||||||
@@ -36,6 +36,9 @@ PSCI_CPU_OFF := 0x84000002
|
@@ -36,6 +36,9 @@ PSCI_CPU_OFF := 0x84000002
|
||||||
@@ -30,10 +30,10 @@ index 88a27de..5e8668a 100644
|
|||||||
ARCH_OBJ := boot.o stack.o utils.o
|
ARCH_OBJ := boot.o stack.o utils.o
|
||||||
|
|
||||||
if BOOTWRAPPER_32
|
if BOOTWRAPPER_32
|
||||||
@@ -125,11 +128,12 @@ CHOSEN_NODE := chosen { \
|
@@ -127,11 +130,12 @@ CFLAGS += -I$(top_srcdir)/include/ -I$(top_srcdir)/$(ARCH_SRC)/include/
|
||||||
CPPFLAGS += $(INITRD_FLAGS)
|
|
||||||
CFLAGS += -I$(top_srcdir)/include/ -I$(top_srcdir)/$(ARCH_SRC)/include/
|
|
||||||
CFLAGS += -Wall -fomit-frame-pointer
|
CFLAGS += -Wall -fomit-frame-pointer
|
||||||
|
CFLAGS += -ffreestanding -nostdlib
|
||||||
|
CFLAGS += -fno-stack-protector
|
||||||
+CFLAGS += -fno-stack-protector
|
+CFLAGS += -fno-stack-protector
|
||||||
CFLAGS += -ffunction-sections -fdata-sections
|
CFLAGS += -ffunction-sections -fdata-sections
|
||||||
CFLAGS += -fno-pic -fno-pie
|
CFLAGS += -fno-pic -fno-pie
|
||||||
@@ -44,7 +44,7 @@ index 88a27de..5e8668a 100644
|
|||||||
|
|
||||||
# Don't lookup all prerequisites in $(top_srcdir), only the source files. When
|
# Don't lookup all prerequisites in $(top_srcdir), only the source files. When
|
||||||
# building outside the source tree $(ARCH_SRC) needs to be created.
|
# building outside the source tree $(ARCH_SRC) needs to be created.
|
||||||
@@ -150,10 +154,13 @@ $(ARCH_SRC):
|
@@ -152,10 +156,13 @@ $(ARCH_SRC):
|
||||||
$(COMMON_SRC):
|
$(COMMON_SRC):
|
||||||
$(MKDIR_P) $@
|
$(MKDIR_P) $@
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
From 5b8cb5192dbd0332e027e8999c3afe4433983291 Mon Sep 17 00:00:00 2001
|
From f0ece5e8cac761a76a86df7204bae7c6ef09215f Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Wed, 29 Dec 2021 10:50:21 +0800
|
Date: Wed, 29 Dec 2021 10:50:21 +0800
|
||||||
Subject: [PATCH] platform: Add print_hex func
|
Subject: [PATCH] platform: Add print_hex func
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
From b447242cd2457bec20d47fe6a8a5758d97a3bde3 Mon Sep 17 00:00:00 2001
|
From f4704146e1af9f6e0a2220db6b39a328c813fac1 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Wed, 19 Jan 2022 16:19:02 +0800
|
Date: Wed, 19 Jan 2022 16:19:02 +0800
|
||||||
Subject: [PATCH] common: Add mem usage to /memreserve/
|
Subject: [PATCH] common: Add mem usage to /memreserve/
|
||||||
@@ -20,7 +20,7 @@ Change-Id: I2ea80cdf736a910fa2c3deb622e21d50f04be960
|
|||||||
create mode 100644 common/device_tree.c
|
create mode 100644 common/device_tree.c
|
||||||
|
|
||||||
diff --git a/Makefile.am b/Makefile.am
|
diff --git a/Makefile.am b/Makefile.am
|
||||||
index 5e8668a..734de92 100644
|
index ab2c3a9..e905602 100644
|
||||||
--- a/Makefile.am
|
--- a/Makefile.am
|
||||||
+++ b/Makefile.am
|
+++ b/Makefile.am
|
||||||
@@ -34,7 +34,7 @@ endif
|
@@ -34,7 +34,7 @@ endif
|
||||||
|
|||||||
+5
-5
@@ -1,4 +1,4 @@
|
|||||||
From 8271c21bcff260295203214b7b8c87cdb8236453 Mon Sep 17 00:00:00 2001
|
From 5995f83592aea874f5b423538e36675e2204582b Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 4 Jan 2022 17:01:55 +0800
|
Date: Tue, 4 Jan 2022 17:01:55 +0800
|
||||||
Subject: [PATCH] boot: Add the --enable-keep-el compile option
|
Subject: [PATCH] boot: Add the --enable-keep-el compile option
|
||||||
@@ -23,7 +23,7 @@ Change-Id: I3ba9c87cf0b59d163ca433f74c9e3a46e5ca2c63
|
|||||||
4 files changed, 20 insertions(+), 1 deletion(-)
|
4 files changed, 20 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a/Makefile.am b/Makefile.am
|
diff --git a/Makefile.am b/Makefile.am
|
||||||
index 734de92..054becd 100644
|
index e905602..6604baa 100644
|
||||||
--- a/Makefile.am
|
--- a/Makefile.am
|
||||||
+++ b/Makefile.am
|
+++ b/Makefile.am
|
||||||
@@ -33,6 +33,10 @@ PSCI_CPU_ON := 0xc4000003
|
@@ -33,6 +33,10 @@ PSCI_CPU_ON := 0xc4000003
|
||||||
@@ -38,10 +38,10 @@ index 734de92..054becd 100644
|
|||||||
COMMON_OBJ := boot.o bakery_lock.o platform.o lib.o device_tree.o
|
COMMON_OBJ := boot.o bakery_lock.o platform.o lib.o device_tree.o
|
||||||
|
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index 6dbd5cc..157c097 100644
|
index 27b1139..c079d22 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -233,7 +233,11 @@ el2_init:
|
@@ -254,7 +254,11 @@ el2_init:
|
||||||
msr cnthctl_el2, x0
|
msr cnthctl_el2, x0
|
||||||
isb
|
isb
|
||||||
|
|
||||||
@@ -53,7 +53,7 @@ index 6dbd5cc..157c097 100644
|
|||||||
ldr x1, =spsr_to_elx
|
ldr x1, =spsr_to_elx
|
||||||
str w0, [x1]
|
str w0, [x1]
|
||||||
// fall through
|
// fall through
|
||||||
@@ -313,5 +317,5 @@ ASM_FUNC(jump_kernel)
|
@@ -334,5 +338,5 @@ ASM_FUNC(jump_kernel)
|
||||||
.align 3
|
.align 3
|
||||||
flag_keep_el:
|
flag_keep_el:
|
||||||
.long 0
|
.long 0
|
||||||
|
|||||||
+2
-5
@@ -1,4 +1,4 @@
|
|||||||
From dd3e3f414d0e6ed1643c2e2ccac676b7fc1dc7a9 Mon Sep 17 00:00:00 2001
|
From 0c0695cd3160ccdb95bae29b7668918015c0b6aa Mon Sep 17 00:00:00 2001
|
||||||
From: Peter Hoyes <Peter.Hoyes@arm.com>
|
From: Peter Hoyes <Peter.Hoyes@arm.com>
|
||||||
Date: Tue, 1 Feb 2022 11:28:46 +0000
|
Date: Tue, 1 Feb 2022 11:28:46 +0000
|
||||||
Subject: [PATCH] Makefile: Change COUNTER_FREQ to 100 MHz
|
Subject: [PATCH] Makefile: Change COUNTER_FREQ to 100 MHz
|
||||||
@@ -17,7 +17,7 @@ Change-Id: Ia9ad0f8ee488d1a887791f1fa1d8f3bf9c5887fd
|
|||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a/Makefile.am b/Makefile.am
|
diff --git a/Makefile.am b/Makefile.am
|
||||||
index 40bc5d6..b48173c 100644
|
index 6604baa..cc6504e 100644
|
||||||
--- a/Makefile.am
|
--- a/Makefile.am
|
||||||
+++ b/Makefile.am
|
+++ b/Makefile.am
|
||||||
@@ -13,7 +13,7 @@ SCRIPT_DIR := $(top_srcdir)/scripts
|
@@ -13,7 +13,7 @@ SCRIPT_DIR := $(top_srcdir)/scripts
|
||||||
@@ -29,6 +29,3 @@ index 40bc5d6..b48173c 100644
|
|||||||
|
|
||||||
CPU_IDS := $(shell perl -I $(SCRIPT_DIR) $(SCRIPT_DIR)/findcpuids.pl $(KERNEL_DTB))
|
CPU_IDS := $(shell perl -I $(SCRIPT_DIR) $(SCRIPT_DIR)/findcpuids.pl $(KERNEL_DTB))
|
||||||
NR_CPUS := $(shell echo $(CPU_IDS) | tr ',' ' ' | wc -w)
|
NR_CPUS := $(shell echo $(CPU_IDS) | tr ',' ' ' | wc -w)
|
||||||
--
|
|
||||||
2.25.1
|
|
||||||
|
|
||||||
|
|||||||
+1
-4
@@ -1,4 +1,4 @@
|
|||||||
From 6923f2a0c59cf92ba5ad50ec1d658a357b4ba5d7 Mon Sep 17 00:00:00 2001
|
From fa73d885be85eee4369b292ec601e7b024a68807 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 2 Nov 2021 10:48:39 +0800
|
Date: Tue, 2 Nov 2021 10:48:39 +0800
|
||||||
Subject: [PATCH] PSCI: Apply flush cache after setting branch_data
|
Subject: [PATCH] PSCI: Apply flush cache after setting branch_data
|
||||||
@@ -47,6 +47,3 @@ index 945780b..6efc695 100644
|
|||||||
return PSCI_RET_SUCCESS;
|
return PSCI_RET_SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
--
|
|
||||||
2.25.1
|
|
||||||
|
|
||||||
|
|||||||
+1
-4
@@ -1,4 +1,4 @@
|
|||||||
From ed46e83df2400b1b3f3364169aacf787bd91bd45 Mon Sep 17 00:00:00 2001
|
From 9da48e3433b919868650cd60e28827273a42c63b Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 25 Jan 2022 14:56:36 +0800
|
Date: Tue, 25 Jan 2022 14:56:36 +0800
|
||||||
Subject: [PATCH] PSCI: Add function call entry point
|
Subject: [PATCH] PSCI: Add function call entry point
|
||||||
@@ -69,6 +69,3 @@ index 6efc695..8fdefb5 100644
|
|||||||
void __noreturn psci_first_spin(unsigned int cpu)
|
void __noreturn psci_first_spin(unsigned int cpu)
|
||||||
{
|
{
|
||||||
if (cpu == MPIDR_INVALID)
|
if (cpu == MPIDR_INVALID)
|
||||||
--
|
|
||||||
2.25.1
|
|
||||||
|
|
||||||
|
|||||||
+1
-4
@@ -1,4 +1,4 @@
|
|||||||
From 36b5fa3f4db49ac7aef42ff1d58a895226c7e96c Mon Sep 17 00:00:00 2001
|
From 7c5e40d9f8699a55ac2187c035429c643e6d0ef0 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Tue, 2 Nov 2021 15:10:28 +0800
|
Date: Tue, 2 Nov 2021 15:10:28 +0800
|
||||||
Subject: [PATCH] lds: Rearrange and mark the sections
|
Subject: [PATCH] lds: Rearrange and mark the sections
|
||||||
@@ -56,6 +56,3 @@ index ab98ddf..85451f9 100644
|
|||||||
PROVIDE(firmware_end = .);
|
PROVIDE(firmware_end = .);
|
||||||
|
|
||||||
ASSERT(etext <= (PHYS_OFFSET + TEXT_LIMIT), ".text overflow!")
|
ASSERT(etext <= (PHYS_OFFSET + TEXT_LIMIT), ".text overflow!")
|
||||||
--
|
|
||||||
2.25.1
|
|
||||||
|
|
||||||
|
|||||||
+1
-4
@@ -1,4 +1,4 @@
|
|||||||
From 8bdbb64d13f14d40546b71dbcfee2b2a8ea002a5 Mon Sep 17 00:00:00 2001
|
From 3c1140c29c39561848056fb4b9a03042b00279f3 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Wed, 29 Dec 2021 15:17:38 +0800
|
Date: Wed, 29 Dec 2021 15:17:38 +0800
|
||||||
Subject: [PATCH] common: Provide firmware info using libfdt
|
Subject: [PATCH] common: Provide firmware info using libfdt
|
||||||
@@ -340,6 +340,3 @@ index 4d0876c..7f7befc 100644
|
|||||||
+
|
+
|
||||||
+ dt_dump_all(fw_node);
|
+ dt_dump_all(fw_node);
|
||||||
+}
|
+}
|
||||||
--
|
|
||||||
2.25.1
|
|
||||||
|
|
||||||
|
|||||||
+8
-11
@@ -1,4 +1,4 @@
|
|||||||
From 6dfc937d1ae54d2ae9f8c60ca29ba73ca14dc8c4 Mon Sep 17 00:00:00 2001
|
From b1105e862e8f770fc195bc20e9c64d231dd32f66 Mon Sep 17 00:00:00 2001
|
||||||
From: Jaxson Han <jaxson.han@arm.com>
|
From: Jaxson Han <jaxson.han@arm.com>
|
||||||
Date: Wed, 29 Dec 2021 15:33:17 +0800
|
Date: Wed, 29 Dec 2021 15:33:17 +0800
|
||||||
Subject: [PATCH] boot: Enable firmware node initialization
|
Subject: [PATCH] boot: Enable firmware node initialization
|
||||||
@@ -29,7 +29,7 @@ Change-Id: Ib274485a34d26215595fd0cd737be86610289817
|
|||||||
3 files changed, 12 insertions(+), 2 deletions(-)
|
3 files changed, 12 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
diff --git a/Makefile.am b/Makefile.am
|
diff --git a/Makefile.am b/Makefile.am
|
||||||
index 054becd..b01809c 100644
|
index cc6504e..fbe6b81 100644
|
||||||
--- a/Makefile.am
|
--- a/Makefile.am
|
||||||
+++ b/Makefile.am
|
+++ b/Makefile.am
|
||||||
@@ -23,7 +23,7 @@ DEFINES += -DCPU_IDS=$(CPU_IDS)
|
@@ -23,7 +23,7 @@ DEFINES += -DCPU_IDS=$(CPU_IDS)
|
||||||
@@ -41,20 +41,20 @@ index 054becd..b01809c 100644
|
|||||||
|
|
||||||
if KERNEL_32
|
if KERNEL_32
|
||||||
DEFINES += -DKERNEL_32
|
DEFINES += -DKERNEL_32
|
||||||
@@ -132,7 +132,7 @@ CHOSEN_NODE := chosen { \
|
@@ -134,7 +134,7 @@ CFLAGS += -I$(top_srcdir)/include/ -I$(top_srcdir)/$(ARCH_SRC)/include/
|
||||||
CPPFLAGS += $(INITRD_FLAGS)
|
|
||||||
CFLAGS += -I$(top_srcdir)/include/ -I$(top_srcdir)/$(ARCH_SRC)/include/
|
|
||||||
CFLAGS += -Wall -fomit-frame-pointer
|
CFLAGS += -Wall -fomit-frame-pointer
|
||||||
|
CFLAGS += -ffreestanding -nostdlib
|
||||||
|
CFLAGS += -fno-stack-protector
|
||||||
-CFLAGS += -fno-stack-protector
|
-CFLAGS += -fno-stack-protector
|
||||||
+CFLAGS += -fno-stack-protector -fno-builtin
|
+CFLAGS += -fno-stack-protector -fno-builtin
|
||||||
CFLAGS += -ffunction-sections -fdata-sections
|
CFLAGS += -ffunction-sections -fdata-sections
|
||||||
CFLAGS += -fno-pic -fno-pie
|
CFLAGS += -fno-pic -fno-pie
|
||||||
LDFLAGS += --gc-sections
|
LDFLAGS += --gc-sections
|
||||||
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
diff --git a/arch/aarch64/boot.S b/arch/aarch64/boot.S
|
||||||
index 157c097..f310387 100644
|
index c079d22..daaa674 100644
|
||||||
--- a/arch/aarch64/boot.S
|
--- a/arch/aarch64/boot.S
|
||||||
+++ b/arch/aarch64/boot.S
|
+++ b/arch/aarch64/boot.S
|
||||||
@@ -240,6 +240,10 @@ el2_init:
|
@@ -261,6 +261,10 @@ el2_init:
|
||||||
#endif
|
#endif
|
||||||
ldr x1, =spsr_to_elx
|
ldr x1, =spsr_to_elx
|
||||||
str w0, [x1]
|
str w0, [x1]
|
||||||
@@ -65,7 +65,7 @@ index 157c097..f310387 100644
|
|||||||
// fall through
|
// fall through
|
||||||
|
|
||||||
el_max_init:
|
el_max_init:
|
||||||
@@ -319,3 +323,5 @@ flag_keep_el:
|
@@ -340,3 +344,5 @@ flag_keep_el:
|
||||||
.long 0
|
.long 0
|
||||||
ASM_DATA(spsr_to_elx)
|
ASM_DATA(spsr_to_elx)
|
||||||
.long 0
|
.long 0
|
||||||
@@ -93,6 +93,3 @@ index ee2bea0..38b2dca 100644
|
|||||||
|
|
||||||
*mbox = (unsigned long)&entrypoint;
|
*mbox = (unsigned long)&entrypoint;
|
||||||
sevl();
|
sevl();
|
||||||
--
|
|
||||||
2.25.1
|
|
||||||
|
|
||||||
|
|||||||
@@ -8,7 +8,8 @@ LICENSE = "BSD-3-Clause & Apache-2.0"
|
|||||||
LIC_FILES_CHKSUM = "file://license.md;md5=e44b2531cd6ffe9dece394dbe988d9a0 \
|
LIC_FILES_CHKSUM = "file://license.md;md5=e44b2531cd6ffe9dece394dbe988d9a0 \
|
||||||
file://cmsis/LICENSE.txt;md5=e3fc50a88d0a364313df4b21ef20c29e"
|
file://cmsis/LICENSE.txt;md5=e3fc50a88d0a364313df4b21ef20c29e"
|
||||||
|
|
||||||
SRC_URI = "gitsm://git.gitlab.arm.com/arm-reference-solutions/corstone1000/external_system/rtx.git;protocol=https;branch=master"
|
SRC_URI = "gitsm://git.gitlab.arm.com/arm-reference-solutions/corstone1000/external_system/rtx.git;protocol=https;branch=master \
|
||||||
|
file://race.patch"
|
||||||
SRCREV = "8c9dca74b104ff6c9722fb0738ba93dd3719c080"
|
SRCREV = "8c9dca74b104ff6c9722fb0738ba93dd3719c080"
|
||||||
PV .= "+git${SRCPV}"
|
PV .= "+git${SRCPV}"
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,66 @@
|
|||||||
|
Upstream-Status: Submitted [https://gitlab.arm.com/arm-reference-solutions/corstone1000/external_system/rtx/-/issues/1]
|
||||||
|
Signed-off-by: Ross Burton <ross.burton@arm.com>
|
||||||
|
|
||||||
|
From 34e1c04534607f5605255f39fb46e26261fc9c4e Mon Sep 17 00:00:00 2001
|
||||||
|
From: Ross Burton <ross.burton@arm.com>
|
||||||
|
Date: Tue, 8 Sep 2020 11:49:08 +0100
|
||||||
|
Subject: [PATCH] tools/gen_module_code: atomically rewrite the generated files
|
||||||
|
|
||||||
|
The gen_module rule in rules.mk is marked as .PHONY, so make will
|
||||||
|
execute it whenever it is mentioned. This results in gen_module_code
|
||||||
|
being executed 64 times for a Juno build.
|
||||||
|
|
||||||
|
However in heavily parallel builds there's a good chance that
|
||||||
|
gen_module_code is writing a file whilst the compiler is reading it
|
||||||
|
because make also doesn't know what files are generated by
|
||||||
|
gen_module_code.
|
||||||
|
|
||||||
|
The correct fix is to adjust the Makefiles so that the dependencies are
|
||||||
|
correct but this isn't trivial, so band-aid the problem by atomically
|
||||||
|
writing the generated files.
|
||||||
|
|
||||||
|
Change-Id: I82d44f9ea6537a91002e1f80de8861d208571630
|
||||||
|
Signed-off-by: Ross Burton <ross.burton@arm.com>
|
||||||
|
---
|
||||||
|
tools/gen_module_code.py | 19 ++++++++++++++-----
|
||||||
|
1 file changed, 14 insertions(+), 5 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/tools/gen_module_code.py b/tools/gen_module_code.py
|
||||||
|
index 7b3953845..ee099b713 100755
|
||||||
|
--- a/tools/gen_module_code.py
|
||||||
|
+++ b/tools/gen_module_code.py
|
||||||
|
@@ -17,6 +17,7 @@
|
||||||
|
import argparse
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
+import tempfile
|
||||||
|
|
||||||
|
DEFAULT_PATH = 'build/'
|
||||||
|
|
||||||
|
@@ -53,13 +54,21 @@
|
||||||
|
|
||||||
|
def generate_file(path, filename, content):
|
||||||
|
full_filename = os.path.join(path, filename)
|
||||||
|
- with open(full_filename, 'a+') as f:
|
||||||
|
- f.seek(0)
|
||||||
|
- if f.read() != content:
|
||||||
|
+
|
||||||
|
+ try:
|
||||||
|
+ with open(full_filename) as f:
|
||||||
|
+ rewrite = f.read() != content
|
||||||
|
+ except FileNotFoundError:
|
||||||
|
+ rewrite = True
|
||||||
|
+
|
||||||
|
+ if rewrite:
|
||||||
|
+ with tempfile.NamedTemporaryFile(prefix="gen-module-code",
|
||||||
|
+ dir=path,
|
||||||
|
+ delete=False,
|
||||||
|
+ mode="wt") as f:
|
||||||
|
print("[GEN] {}...".format(full_filename))
|
||||||
|
- f.seek(0)
|
||||||
|
- f.truncate()
|
||||||
|
f.write(content)
|
||||||
|
+ os.replace(f.name, full_filename)
|
||||||
|
|
||||||
|
|
||||||
|
def generate_header(path, modules):
|
||||||
+12
-14
@@ -1,7 +1,7 @@
|
|||||||
From c8bd941579fb062359b683b184b851eea2ddb761 Mon Sep 17 00:00:00 2001
|
From f526797b83113cc64e3e658c22d8a5d269896a2a Mon Sep 17 00:00:00 2001
|
||||||
From: Ben Horgan <ben.horgan@arm.com>
|
From: Ben Horgan <ben.horgan@arm.com>
|
||||||
Date: Fri, 4 Mar 2022 16:48:14 +0000
|
Date: Fri, 4 Mar 2022 16:48:14 +0000
|
||||||
Subject: [PATCH 1/5] feat: emulate cntp timer register accesses using cnthps
|
Subject: [PATCH] feat: emulate cntp timer register accesses using cnthps
|
||||||
|
|
||||||
Upstream-Status: Inappropriate [Experimental feature]
|
Upstream-Status: Inappropriate [Experimental feature]
|
||||||
Signed-off-by: Ben Horgan <ben.horgan@arm.com>
|
Signed-off-by: Ben Horgan <ben.horgan@arm.com>
|
||||||
@@ -19,10 +19,10 @@ Change-Id: I67508203273baf3bd8e6be2d99717028db945715
|
|||||||
create mode 100644 src/arch/aarch64/hypervisor/timer_el1.h
|
create mode 100644 src/arch/aarch64/hypervisor/timer_el1.h
|
||||||
|
|
||||||
diff --git a/Makefile b/Makefile
|
diff --git a/Makefile b/Makefile
|
||||||
index c9fb16f..6371a8a 100644
|
index 95cab9a5..21cca938 100644
|
||||||
--- a/Makefile
|
--- a/Makefile
|
||||||
+++ b/Makefile
|
+++ b/Makefile
|
||||||
@@ -59,7 +59,8 @@ CHECKPATCH := $(CURDIR)/third_party/linux/scripts/checkpatch.pl \
|
@@ -60,7 +60,8 @@ CHECKPATCH := $(CURDIR)/third_party/linux/scripts/checkpatch.pl \
|
||||||
# debug_el1.c : uses XMACROS, which checkpatch doesn't understand.
|
# debug_el1.c : uses XMACROS, which checkpatch doesn't understand.
|
||||||
# perfmon.c : uses XMACROS, which checkpatch doesn't understand.
|
# perfmon.c : uses XMACROS, which checkpatch doesn't understand.
|
||||||
# feature_id.c : uses XMACROS, which checkpatch doesn't understand.
|
# feature_id.c : uses XMACROS, which checkpatch doesn't understand.
|
||||||
@@ -33,7 +33,7 @@ index c9fb16f..6371a8a 100644
|
|||||||
OUT ?= out/$(PROJECT)
|
OUT ?= out/$(PROJECT)
|
||||||
OUT_DIR = out/$(PROJECT)
|
OUT_DIR = out/$(PROJECT)
|
||||||
diff --git a/src/arch/aarch64/hypervisor/BUILD.gn b/src/arch/aarch64/hypervisor/BUILD.gn
|
diff --git a/src/arch/aarch64/hypervisor/BUILD.gn b/src/arch/aarch64/hypervisor/BUILD.gn
|
||||||
index 6068d1e..de1a414 100644
|
index 6068d1e8..de1a414d 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/BUILD.gn
|
--- a/src/arch/aarch64/hypervisor/BUILD.gn
|
||||||
+++ b/src/arch/aarch64/hypervisor/BUILD.gn
|
+++ b/src/arch/aarch64/hypervisor/BUILD.gn
|
||||||
@@ -45,6 +45,7 @@ source_set("hypervisor") {
|
@@ -45,6 +45,7 @@ source_set("hypervisor") {
|
||||||
@@ -45,10 +45,10 @@ index 6068d1e..de1a414 100644
|
|||||||
]
|
]
|
||||||
|
|
||||||
diff --git a/src/arch/aarch64/hypervisor/cpu.c b/src/arch/aarch64/hypervisor/cpu.c
|
diff --git a/src/arch/aarch64/hypervisor/cpu.c b/src/arch/aarch64/hypervisor/cpu.c
|
||||||
index c6cebdd..cb41e6e 100644
|
index bcf5ffce..d2df77d8 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/cpu.c
|
--- a/src/arch/aarch64/hypervisor/cpu.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/cpu.c
|
+++ b/src/arch/aarch64/hypervisor/cpu.c
|
||||||
@@ -91,13 +91,20 @@ void arch_regs_reset(struct vcpu *vcpu)
|
@@ -98,13 +98,20 @@ void arch_regs_reset(struct vcpu *vcpu)
|
||||||
if (is_primary) {
|
if (is_primary) {
|
||||||
/*
|
/*
|
||||||
* cnthctl_el2 is redefined when VHE is enabled.
|
* cnthctl_el2 is redefined when VHE is enabled.
|
||||||
@@ -72,7 +72,7 @@ index c6cebdd..cb41e6e 100644
|
|||||||
}
|
}
|
||||||
|
|
||||||
diff --git a/src/arch/aarch64/hypervisor/handler.c b/src/arch/aarch64/hypervisor/handler.c
|
diff --git a/src/arch/aarch64/hypervisor/handler.c b/src/arch/aarch64/hypervisor/handler.c
|
||||||
index cd64d68..c9068c5 100644
|
index 4bd8a3b4..4c1b6e48 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/handler.c
|
--- a/src/arch/aarch64/hypervisor/handler.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/handler.c
|
+++ b/src/arch/aarch64/hypervisor/handler.c
|
||||||
@@ -34,6 +34,7 @@
|
@@ -34,6 +34,7 @@
|
||||||
@@ -83,7 +83,7 @@ index cd64d68..c9068c5 100644
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Hypervisor Fault Address Register Non-Secure.
|
* Hypervisor Fault Address Register Non-Secure.
|
||||||
@@ -1276,6 +1277,11 @@ void handle_system_register_access(uintreg_t esr_el2)
|
@@ -1277,6 +1278,11 @@ void handle_system_register_access(uintreg_t esr_el2)
|
||||||
inject_el1_unknown_exception(vcpu, esr_el2);
|
inject_el1_unknown_exception(vcpu, esr_el2);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -97,7 +97,7 @@ index cd64d68..c9068c5 100644
|
|||||||
return;
|
return;
|
||||||
diff --git a/src/arch/aarch64/hypervisor/timer_el1.c b/src/arch/aarch64/hypervisor/timer_el1.c
|
diff --git a/src/arch/aarch64/hypervisor/timer_el1.c b/src/arch/aarch64/hypervisor/timer_el1.c
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000..c30e554
|
index 00000000..c30e5543
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/src/arch/aarch64/hypervisor/timer_el1.c
|
+++ b/src/arch/aarch64/hypervisor/timer_el1.c
|
||||||
@@ -0,0 +1,104 @@
|
@@ -0,0 +1,104 @@
|
||||||
@@ -207,7 +207,7 @@ index 0000000..c30e554
|
|||||||
+}
|
+}
|
||||||
diff --git a/src/arch/aarch64/hypervisor/timer_el1.h b/src/arch/aarch64/hypervisor/timer_el1.h
|
diff --git a/src/arch/aarch64/hypervisor/timer_el1.h b/src/arch/aarch64/hypervisor/timer_el1.h
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000..04a43b6
|
index 00000000..04a43b6c
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/src/arch/aarch64/hypervisor/timer_el1.h
|
+++ b/src/arch/aarch64/hypervisor/timer_el1.h
|
||||||
@@ -0,0 +1,20 @@
|
@@ -0,0 +1,20 @@
|
||||||
@@ -232,7 +232,7 @@ index 0000000..04a43b6
|
|||||||
+bool timer_el1_process_access(struct vcpu *vcpu, ffa_vm_id_t vm_id,
|
+bool timer_el1_process_access(struct vcpu *vcpu, ffa_vm_id_t vm_id,
|
||||||
+ uintreg_t esr);
|
+ uintreg_t esr);
|
||||||
diff --git a/src/arch/aarch64/msr.h b/src/arch/aarch64/msr.h
|
diff --git a/src/arch/aarch64/msr.h b/src/arch/aarch64/msr.h
|
||||||
index cd6778b..55e7833 100644
|
index cd6778b4..55e78330 100644
|
||||||
--- a/src/arch/aarch64/msr.h
|
--- a/src/arch/aarch64/msr.h
|
||||||
+++ b/src/arch/aarch64/msr.h
|
+++ b/src/arch/aarch64/msr.h
|
||||||
@@ -126,3 +126,11 @@
|
@@ -126,3 +126,11 @@
|
||||||
@@ -247,6 +247,4 @@ index cd6778b..55e7833 100644
|
|||||||
+#define MSR_CNTHPS_CTL_EL2 S3_4_C14_C5_1
|
+#define MSR_CNTHPS_CTL_EL2 S3_4_C14_C5_1
|
||||||
+#define MSR_CNTHPS_CVAL_EL2 S3_4_C14_C5_2
|
+#define MSR_CNTHPS_CVAL_EL2 S3_4_C14_C5_2
|
||||||
+#define MSR_CNTHPS_TVAL_EL2 S3_4_C14_C5_0
|
+#define MSR_CNTHPS_TVAL_EL2 S3_4_C14_C5_0
|
||||||
--
|
|
||||||
2.17.1
|
|
||||||
|
|
||||||
|
|||||||
+8
-7
@@ -1,18 +1,19 @@
|
|||||||
From e918cc5179241e1d35ba4b465b035b74b88e55d2 Mon Sep 17 00:00:00 2001
|
From 613dea068fa546956717ce0b60328e39d451f661 Mon Sep 17 00:00:00 2001
|
||||||
From: Arunachalam Ganapathy <arunachalam.ganapathy@arm.com>
|
From: Arunachalam Ganapathy <arunachalam.ganapathy@arm.com>
|
||||||
Date: Fri, 29 Apr 2022 20:07:50 +0100
|
Date: Fri, 29 Apr 2022 20:07:50 +0100
|
||||||
Subject: [PATCH] tc: increase heap pages
|
Subject: [PATCH] tc: increase heap pages
|
||||||
|
|
||||||
|
Upstream-Status: Pending
|
||||||
Signed-off-by: Arunachalam Ganapathy <arunachalam.ganapathy@arm.com>
|
Signed-off-by: Arunachalam Ganapathy <arunachalam.ganapathy@arm.com>
|
||||||
---
|
---
|
||||||
/BUILD.gn | 2 +-
|
BUILD.gn | 2 +-
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a//BUILD.gn b//BUILD.gn
|
diff --git a/BUILD.gn b/BUILD.gn
|
||||||
index 5d84d13..4ea0890 100644
|
index 6b9b383..62ba763 100644
|
||||||
--- a//BUILD.gn
|
--- a/BUILD.gn
|
||||||
+++ b//BUILD.gn
|
+++ b/BUILD.gn
|
||||||
@@ -233,7 +233,7 @@ aarch64_toolchains("secure_tc") {
|
@@ -235,7 +235,7 @@ aarch64_toolchains("secure_tc") {
|
||||||
gicd_base_address = "0x30000000"
|
gicd_base_address = "0x30000000"
|
||||||
gicr_base_address = "0x30080000"
|
gicr_base_address = "0x30080000"
|
||||||
gicr_frames = 8
|
gicr_frames = 8
|
||||||
+7
-9
@@ -1,7 +1,7 @@
|
|||||||
From 380f2cf944dd5db36c168a11d31a46ad14cdcb6d Mon Sep 17 00:00:00 2001
|
From 97a8ca1835f5d9512dacda497540d5523e56c7dd Mon Sep 17 00:00:00 2001
|
||||||
From: Arunachalam Ganapathy <arunachalam.ganapathy@arm.com>
|
From: Arunachalam Ganapathy <arunachalam.ganapathy@arm.com>
|
||||||
Date: Tue, 26 Apr 2022 14:43:58 +0100
|
Date: Tue, 26 Apr 2022 14:43:58 +0100
|
||||||
Subject: [PATCH 4/5] feat: emulate interrupt controller register access
|
Subject: [PATCH] feat: emulate interrupt controller register access
|
||||||
|
|
||||||
This emulates ICC_SGI1R_EL1 and ICC_IGRPEN1_EL1 register
|
This emulates ICC_SGI1R_EL1 and ICC_IGRPEN1_EL1 register
|
||||||
|
|
||||||
@@ -16,10 +16,10 @@ Upstream-Status: Inappropriate [Experimental feature]
|
|||||||
4 files changed, 97 insertions(+)
|
4 files changed, 97 insertions(+)
|
||||||
|
|
||||||
diff --git a/src/arch/aarch64/hypervisor/handler.c b/src/arch/aarch64/hypervisor/handler.c
|
diff --git a/src/arch/aarch64/hypervisor/handler.c b/src/arch/aarch64/hypervisor/handler.c
|
||||||
index c9068c5..b9aa5d8 100644
|
index 4c1b6e48..cd5146bd 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/handler.c
|
--- a/src/arch/aarch64/hypervisor/handler.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/handler.c
|
+++ b/src/arch/aarch64/hypervisor/handler.c
|
||||||
@@ -1282,6 +1282,11 @@ void handle_system_register_access(uintreg_t esr_el2)
|
@@ -1283,6 +1283,11 @@ void handle_system_register_access(uintreg_t esr_el2)
|
||||||
inject_el1_unknown_exception(vcpu, esr_el2);
|
inject_el1_unknown_exception(vcpu, esr_el2);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -32,7 +32,7 @@ index c9068c5..b9aa5d8 100644
|
|||||||
inject_el1_unknown_exception(vcpu, esr_el2);
|
inject_el1_unknown_exception(vcpu, esr_el2);
|
||||||
return;
|
return;
|
||||||
diff --git a/src/arch/aarch64/hypervisor/perfmon.c b/src/arch/aarch64/hypervisor/perfmon.c
|
diff --git a/src/arch/aarch64/hypervisor/perfmon.c b/src/arch/aarch64/hypervisor/perfmon.c
|
||||||
index f13b035..05e216c 100644
|
index f13b0354..05e216c8 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/perfmon.c
|
--- a/src/arch/aarch64/hypervisor/perfmon.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/perfmon.c
|
+++ b/src/arch/aarch64/hypervisor/perfmon.c
|
||||||
@@ -116,6 +116,10 @@
|
@@ -116,6 +116,10 @@
|
||||||
@@ -131,7 +131,7 @@ index f13b035..05e216c 100644
|
|||||||
+ return true;
|
+ return true;
|
||||||
+}
|
+}
|
||||||
diff --git a/src/arch/aarch64/hypervisor/perfmon.h b/src/arch/aarch64/hypervisor/perfmon.h
|
diff --git a/src/arch/aarch64/hypervisor/perfmon.h b/src/arch/aarch64/hypervisor/perfmon.h
|
||||||
index 81669ba..c90d45b 100644
|
index 81669ba1..c90d45bf 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/perfmon.h
|
--- a/src/arch/aarch64/hypervisor/perfmon.h
|
||||||
+++ b/src/arch/aarch64/hypervisor/perfmon.h
|
+++ b/src/arch/aarch64/hypervisor/perfmon.h
|
||||||
@@ -70,3 +70,8 @@ bool perfmon_process_access(struct vcpu *vcpu, ffa_vm_id_t vm_id,
|
@@ -70,3 +70,8 @@ bool perfmon_process_access(struct vcpu *vcpu, ffa_vm_id_t vm_id,
|
||||||
@@ -144,7 +144,7 @@ index 81669ba..c90d45b 100644
|
|||||||
+bool intr_ctrl_el1_process_access(struct vcpu *vcpu, ffa_vm_id_t vm_id,
|
+bool intr_ctrl_el1_process_access(struct vcpu *vcpu, ffa_vm_id_t vm_id,
|
||||||
+ uintreg_t esr);
|
+ uintreg_t esr);
|
||||||
diff --git a/src/arch/aarch64/msr.h b/src/arch/aarch64/msr.h
|
diff --git a/src/arch/aarch64/msr.h b/src/arch/aarch64/msr.h
|
||||||
index 55e7833..82aa884 100644
|
index 55e78330..82aa8846 100644
|
||||||
--- a/src/arch/aarch64/msr.h
|
--- a/src/arch/aarch64/msr.h
|
||||||
+++ b/src/arch/aarch64/msr.h
|
+++ b/src/arch/aarch64/msr.h
|
||||||
@@ -134,3 +134,6 @@
|
@@ -134,3 +134,6 @@
|
||||||
@@ -154,6 +154,4 @@ index 55e7833..82aa884 100644
|
|||||||
+
|
+
|
||||||
+#define ICC_IGRPEN1_EL1 S3_0_C12_C12_7
|
+#define ICC_IGRPEN1_EL1 S3_0_C12_C12_7
|
||||||
+#define ICC_SGI1R_EL1 S3_0_C12_C11_5
|
+#define ICC_SGI1R_EL1 S3_0_C12_C11_5
|
||||||
--
|
|
||||||
2.17.1
|
|
||||||
|
|
||||||
|
|||||||
+1
-4
@@ -1,4 +1,4 @@
|
|||||||
From c235511a06a54bcccec97b3067c1004d3957b1d8 Mon Sep 17 00:00:00 2001
|
From 1fef5bd2504ce3a203c56a3b66dba773cd4893c6 Mon Sep 17 00:00:00 2001
|
||||||
From: Davidson K <davidson.kumaresan@arm.com>
|
From: Davidson K <davidson.kumaresan@arm.com>
|
||||||
Date: Thu, 8 Sep 2022 10:47:10 +0530
|
Date: Thu, 8 Sep 2022 10:47:10 +0530
|
||||||
Subject: [PATCH] feat(vhe): enable vhe and disable branch protection for TC
|
Subject: [PATCH] feat(vhe): enable vhe and disable branch protection for TC
|
||||||
@@ -29,6 +29,3 @@ index 62ba763..f26ce03 100644
|
|||||||
+ enable_vhe = "1"
|
+ enable_vhe = "1"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
--
|
|
||||||
2.34.1
|
|
||||||
|
|
||||||
+9
-11
@@ -1,4 +1,4 @@
|
|||||||
From 1e24b45a8ff34af45dda45c57f8403452d384f99 Mon Sep 17 00:00:00 2001
|
From 1c4d28493faed6cf189c75fa91d19131e6a34e04 Mon Sep 17 00:00:00 2001
|
||||||
From: Olivier Deprez <olivier.deprez@arm.com>
|
From: Olivier Deprez <olivier.deprez@arm.com>
|
||||||
Date: Mon, 8 Aug 2022 19:14:23 +0200
|
Date: Mon, 8 Aug 2022 19:14:23 +0200
|
||||||
Subject: [PATCH] feat: disable alignment check for EL0 partitions
|
Subject: [PATCH] feat: disable alignment check for EL0 partitions
|
||||||
@@ -40,7 +40,7 @@ Upstream-Status: Submitted [https://review.trustedfirmware.org/c/hafnium/hafnium
|
|||||||
8 files changed, 59 insertions(+), 30 deletions(-)
|
8 files changed, 59 insertions(+), 30 deletions(-)
|
||||||
|
|
||||||
diff --git a/src/arch/aarch64/hypervisor/cpu.c b/src/arch/aarch64/hypervisor/cpu.c
|
diff --git a/src/arch/aarch64/hypervisor/cpu.c b/src/arch/aarch64/hypervisor/cpu.c
|
||||||
index d2df77d..a000159 100644
|
index d2df77d8..a000159b 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/cpu.c
|
--- a/src/arch/aarch64/hypervisor/cpu.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/cpu.c
|
+++ b/src/arch/aarch64/hypervisor/cpu.c
|
||||||
@@ -115,7 +115,9 @@ void arch_regs_reset(struct vcpu *vcpu)
|
@@ -115,7 +115,9 @@ void arch_regs_reset(struct vcpu *vcpu)
|
||||||
@@ -69,7 +69,7 @@ index d2df77d..a000159 100644
|
|||||||
r->lazy.vttbr_el2 = pa_addr(table) | ((uint64_t)vm_id << 48);
|
r->lazy.vttbr_el2 = pa_addr(table) | ((uint64_t)vm_id << 48);
|
||||||
#if SECURE_WORLD == 1
|
#if SECURE_WORLD == 1
|
||||||
diff --git a/src/arch/aarch64/hypervisor/exceptions.S b/src/arch/aarch64/hypervisor/exceptions.S
|
diff --git a/src/arch/aarch64/hypervisor/exceptions.S b/src/arch/aarch64/hypervisor/exceptions.S
|
||||||
index 539e196..d3732f8 100644
|
index 539e196d..d3732f86 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/exceptions.S
|
--- a/src/arch/aarch64/hypervisor/exceptions.S
|
||||||
+++ b/src/arch/aarch64/hypervisor/exceptions.S
|
+++ b/src/arch/aarch64/hypervisor/exceptions.S
|
||||||
@@ -20,6 +20,9 @@
|
@@ -20,6 +20,9 @@
|
||||||
@@ -147,7 +147,7 @@ index 539e196..d3732f8 100644
|
|||||||
ret
|
ret
|
||||||
#endif
|
#endif
|
||||||
diff --git a/src/arch/aarch64/hypervisor/feature_id.c b/src/arch/aarch64/hypervisor/feature_id.c
|
diff --git a/src/arch/aarch64/hypervisor/feature_id.c b/src/arch/aarch64/hypervisor/feature_id.c
|
||||||
index ed3bf8f..57f3262 100644
|
index ed3bf8f1..57f32627 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/feature_id.c
|
--- a/src/arch/aarch64/hypervisor/feature_id.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/feature_id.c
|
+++ b/src/arch/aarch64/hypervisor/feature_id.c
|
||||||
@@ -175,7 +175,7 @@ void feature_set_traps(struct vm *vm, struct arch_regs *regs)
|
@@ -175,7 +175,7 @@ void feature_set_traps(struct vm *vm, struct arch_regs *regs)
|
||||||
@@ -177,7 +177,7 @@ index ed3bf8f..57f3262 100644
|
|||||||
vm->arch.tid3_masks.id_aa64isar1_el1 &= ~ID_AA64ISAR1_EL1_GPI;
|
vm->arch.tid3_masks.id_aa64isar1_el1 &= ~ID_AA64ISAR1_EL1_GPI;
|
||||||
vm->arch.tid3_masks.id_aa64isar1_el1 &= ~ID_AA64ISAR1_EL1_GPA;
|
vm->arch.tid3_masks.id_aa64isar1_el1 &= ~ID_AA64ISAR1_EL1_GPA;
|
||||||
diff --git a/src/arch/aarch64/hypervisor/handler.c b/src/arch/aarch64/hypervisor/handler.c
|
diff --git a/src/arch/aarch64/hypervisor/handler.c b/src/arch/aarch64/hypervisor/handler.c
|
||||||
index cd5146b..8a3d628 100644
|
index cd5146bd..8a3d6289 100644
|
||||||
--- a/src/arch/aarch64/hypervisor/handler.c
|
--- a/src/arch/aarch64/hypervisor/handler.c
|
||||||
+++ b/src/arch/aarch64/hypervisor/handler.c
|
+++ b/src/arch/aarch64/hypervisor/handler.c
|
||||||
@@ -272,9 +272,9 @@ noreturn void sync_current_exception_noreturn(uintreg_t elr, uintreg_t spsr)
|
@@ -272,9 +272,9 @@ noreturn void sync_current_exception_noreturn(uintreg_t elr, uintreg_t spsr)
|
||||||
@@ -241,7 +241,7 @@ index cd5146b..8a3d628 100644
|
|||||||
|
|
||||||
#if SECURE_WORLD == 1
|
#if SECURE_WORLD == 1
|
||||||
diff --git a/src/arch/aarch64/inc/hf/arch/types.h b/src/arch/aarch64/inc/hf/arch/types.h
|
diff --git a/src/arch/aarch64/inc/hf/arch/types.h b/src/arch/aarch64/inc/hf/arch/types.h
|
||||||
index 6379d73..6b8b24f 100644
|
index 6379d73e..6b8b24f1 100644
|
||||||
--- a/src/arch/aarch64/inc/hf/arch/types.h
|
--- a/src/arch/aarch64/inc/hf/arch/types.h
|
||||||
+++ b/src/arch/aarch64/inc/hf/arch/types.h
|
+++ b/src/arch/aarch64/inc/hf/arch/types.h
|
||||||
@@ -79,8 +79,13 @@ struct arch_regs {
|
@@ -79,8 +79,13 @@ struct arch_regs {
|
||||||
@@ -261,7 +261,7 @@ index 6379d73..6b8b24f 100644
|
|||||||
/*
|
/*
|
||||||
* System registers.
|
* System registers.
|
||||||
diff --git a/src/arch/aarch64/mm.c b/src/arch/aarch64/mm.c
|
diff --git a/src/arch/aarch64/mm.c b/src/arch/aarch64/mm.c
|
||||||
index 8ee65ca..487ae35 100644
|
index 8ee65ca0..487ae353 100644
|
||||||
--- a/src/arch/aarch64/mm.c
|
--- a/src/arch/aarch64/mm.c
|
||||||
+++ b/src/arch/aarch64/mm.c
|
+++ b/src/arch/aarch64/mm.c
|
||||||
@@ -886,7 +886,7 @@ bool arch_mm_init(paddr_t table)
|
@@ -886,7 +886,7 @@ bool arch_mm_init(paddr_t table)
|
||||||
@@ -274,7 +274,7 @@ index 8ee65ca..487ae35 100644
|
|||||||
(0 << 30) | /* SA. */
|
(0 << 30) | /* SA. */
|
||||||
(0 << 29) | /* SW. */
|
(0 << 29) | /* SW. */
|
||||||
diff --git a/src/arch/aarch64/sysregs.c b/src/arch/aarch64/sysregs.c
|
diff --git a/src/arch/aarch64/sysregs.c b/src/arch/aarch64/sysregs.c
|
||||||
index e8c154b..087ba4e 100644
|
index e8c154b1..087ba4ed 100644
|
||||||
--- a/src/arch/aarch64/sysregs.c
|
--- a/src/arch/aarch64/sysregs.c
|
||||||
+++ b/src/arch/aarch64/sysregs.c
|
+++ b/src/arch/aarch64/sysregs.c
|
||||||
@@ -159,7 +159,7 @@ uintreg_t get_cptr_el2_value(void)
|
@@ -159,7 +159,7 @@ uintreg_t get_cptr_el2_value(void)
|
||||||
@@ -303,7 +303,7 @@ index e8c154b..087ba4e 100644
|
|||||||
sctlr_el2_value |= SCTLR_EL2_SA;
|
sctlr_el2_value |= SCTLR_EL2_SA;
|
||||||
sctlr_el2_value |= SCTLR_EL2_I;
|
sctlr_el2_value |= SCTLR_EL2_I;
|
||||||
diff --git a/src/arch/aarch64/sysregs.h b/src/arch/aarch64/sysregs.h
|
diff --git a/src/arch/aarch64/sysregs.h b/src/arch/aarch64/sysregs.h
|
||||||
index babd237..6fdab58 100644
|
index babd2375..6fdab58e 100644
|
||||||
--- a/src/arch/aarch64/sysregs.h
|
--- a/src/arch/aarch64/sysregs.h
|
||||||
+++ b/src/arch/aarch64/sysregs.h
|
+++ b/src/arch/aarch64/sysregs.h
|
||||||
@@ -668,7 +668,7 @@ uintreg_t get_mdcr_el2_value(void);
|
@@ -668,7 +668,7 @@ uintreg_t get_mdcr_el2_value(void);
|
||||||
@@ -315,6 +315,4 @@ index babd237..6fdab58 100644
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Branch Target Identification mechanism support in AArch64 state.
|
* Branch Target Identification mechanism support in AArch64 state.
|
||||||
--
|
|
||||||
2.34.1
|
|
||||||
|
|
||||||
+2
-5
@@ -1,4 +1,4 @@
|
|||||||
From 02c8afc4f7315b4e12098ffeb8bd5e64e4891e78 Mon Sep 17 00:00:00 2001
|
From 4b59905d2fec01cc17038b1c167b4e57e7835adf Mon Sep 17 00:00:00 2001
|
||||||
From: Davidson K <davidson.kumaresan@arm.com>
|
From: Davidson K <davidson.kumaresan@arm.com>
|
||||||
Date: Thu, 7 Oct 2021 12:20:08 +0530
|
Date: Thu, 7 Oct 2021 12:20:08 +0530
|
||||||
Subject: [PATCH] feat(vhe): set STAGE1_NS while mapping memory from NWd to SWd
|
Subject: [PATCH] feat(vhe): set STAGE1_NS while mapping memory from NWd to SWd
|
||||||
@@ -17,7 +17,7 @@ Upstream-Status: Pending [Not submitted to upstream yet]
|
|||||||
1 file changed, 12 insertions(+)
|
1 file changed, 12 insertions(+)
|
||||||
|
|
||||||
diff --git a/src/ffa_memory.c b/src/ffa_memory.c
|
diff --git a/src/ffa_memory.c b/src/ffa_memory.c
|
||||||
index 048cca9..8910cc7 100644
|
index 048cca9c..8910cc79 100644
|
||||||
--- a/src/ffa_memory.c
|
--- a/src/ffa_memory.c
|
||||||
+++ b/src/ffa_memory.c
|
+++ b/src/ffa_memory.c
|
||||||
@@ -2483,6 +2483,18 @@ struct ffa_value ffa_memory_retrieve(struct vm_locked to_locked,
|
@@ -2483,6 +2483,18 @@ struct ffa_value ffa_memory_retrieve(struct vm_locked to_locked,
|
||||||
@@ -39,6 +39,3 @@ index 048cca9..8910cc7 100644
|
|||||||
ret = ffa_retrieve_check_update(
|
ret = ffa_retrieve_check_update(
|
||||||
to_locked, memory_region->sender, share_state->fragments,
|
to_locked, memory_region->sender, share_state->fragments,
|
||||||
share_state->fragment_constituent_counts,
|
share_state->fragment_constituent_counts,
|
||||||
--
|
|
||||||
2.34.1
|
|
||||||
|
|
||||||
@@ -9,15 +9,15 @@ PV = "2.7+git${SRCPV}"
|
|||||||
|
|
||||||
FILESEXTRAPATHS:prepend:tc := "${THISDIR}/files/tc:"
|
FILESEXTRAPATHS:prepend:tc := "${THISDIR}/files/tc:"
|
||||||
|
|
||||||
SRC_URI:remove = "file://0001-Fix-build-with-clang-15.patch"
|
SRC_URI:remove = "file://0003-Fix-build-with-clang-15.patch"
|
||||||
|
|
||||||
SRC_URI:append = " \
|
SRC_URI:append = " \
|
||||||
file://0001-feat-emulate-cntp-timer-register-accesses-using-cnth.patch \
|
file://0001-feat-emulate-cntp-timer-register-accesses-using-cnth.patch \
|
||||||
file://0002-feat-emulate-interrupt-controller-register-access.patch \
|
file://0002-feat-emulate-interrupt-controller-register-access.patch \
|
||||||
file://0003-tc-increase-heap-pages.patch;patchdir=project/reference \
|
file://0003-feat-disable-alignment-check-for-EL0-partitions.patch \
|
||||||
file://0004-feat-disable-alignment-check-for-EL0-partitions.patch \
|
file://0004-feat-vhe-set-STAGE1_NS-while-mapping-memory-from-NWd.patch \
|
||||||
file://0005-feat-vhe-set-STAGE1_NS-while-mapping-memory-from-NWd.patch \
|
file://0001-tc-increase-heap-pages.patch;patchdir=project/reference \
|
||||||
file://0006-feat-vhe-enable-vhe-and-disable-branch-protection-fo.patch;patchdir=project/reference \
|
file://0002-feat-vhe-enable-vhe-and-disable-branch-protection-fo.patch;patchdir=project/reference \
|
||||||
"
|
"
|
||||||
|
|
||||||
do_compile() {
|
do_compile() {
|
||||||
|
|||||||
@@ -6,11 +6,16 @@ LICENSE = "MIT"
|
|||||||
COMPATIBLE_MACHINE = "corstone1000"
|
COMPATIBLE_MACHINE = "corstone1000"
|
||||||
|
|
||||||
inherit image
|
inherit image
|
||||||
inherit wic_nopt tfm_sign_image
|
inherit tfm_sign_image
|
||||||
|
inherit uefi_capsule
|
||||||
|
|
||||||
PACKAGE_INSTALL = ""
|
PACKAGE_INSTALL = ""
|
||||||
|
|
||||||
IMAGE_FSTYPES += "wic wic.nopt"
|
IMAGE_FSTYPES += "wic uefi_capsule"
|
||||||
|
|
||||||
|
UEFI_FIRMWARE_BINARY = "${PN}-${MACHINE}.${CAPSULE_IMGTYPE}"
|
||||||
|
UEFI_CAPSULE_CONFIG = "${THISDIR}/files/${PN}-capsule-update-image.json"
|
||||||
|
CAPSULE_IMGTYPE = "wic"
|
||||||
|
|
||||||
do_sign_images() {
|
do_sign_images() {
|
||||||
# Sign TF-A BL2
|
# Sign TF-A BL2
|
||||||
@@ -19,7 +24,8 @@ do_sign_images() {
|
|||||||
|
|
||||||
# Update BL2 in the FIP image
|
# Update BL2 in the FIP image
|
||||||
cp ${RECIPE_SYSROOT}/firmware/${TFA_FIP_BINARY} .
|
cp ${RECIPE_SYSROOT}/firmware/${TFA_FIP_BINARY} .
|
||||||
fiptool update --tb-fw ${TFM_IMAGE_SIGN_DIR}/signed_${TFA_BL2_BINARY} \
|
fiptool update --tb-fw \
|
||||||
|
${TFM_IMAGE_SIGN_DEPLOY_DIR}/signed_${TFA_BL2_BINARY} \
|
||||||
${TFM_IMAGE_SIGN_DIR}/${TFA_FIP_BINARY}
|
${TFM_IMAGE_SIGN_DIR}/${TFA_FIP_BINARY}
|
||||||
|
|
||||||
# Sign the FIP image
|
# Sign the FIP image
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{
|
||||||
|
"Payloads": [
|
||||||
|
{
|
||||||
|
"FwVersion": "5",
|
||||||
|
"Guid": "e2bb9c06-70e9-4b14-97a3-5a7913176e3f",
|
||||||
|
"LowestSupportedVersion": "1",
|
||||||
|
"Payload": "$UEFI_FIRMWARE_BINARY",
|
||||||
|
"UpdateImageIndex": "0"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -63,10 +63,10 @@ do_deploy() {
|
|||||||
done
|
done
|
||||||
|
|
||||||
if [ "${INITRAMFS_IMAGE_BUNDLE}" -eq 1 ]; then
|
if [ "${INITRAMFS_IMAGE_BUNDLE}" -eq 1 ]; then
|
||||||
cp -L -f ${DEPLOY_DIR_IMAGE}/Image-initramfs-juno.bin \
|
cp -L -f ${DEPLOY_DIR_IMAGE}/Image.gz-initramfs-juno.bin \
|
||||||
${D}/${UNPACK_DIR}/SOFTWARE/Image
|
${D}/${UNPACK_DIR}/SOFTWARE/Image
|
||||||
else
|
else
|
||||||
cp -L -f ${DEPLOY_DIR_IMAGE}/Image ${D}/${UNPACK_DIR}/SOFTWARE/
|
cp -L -f ${DEPLOY_DIR_IMAGE}/${KERNEL_IMAGETYPE} ${D}/${UNPACK_DIR}/SOFTWARE/
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Compress the files
|
# Compress the files
|
||||||
|
|||||||
@@ -13,7 +13,8 @@ COMPATIBLE_MACHINE = "n1sdp"
|
|||||||
|
|
||||||
SRC_URI = "git://git.gitlab.arm.com/arm-reference-solutions/board-firmware.git;protocol=https;branch=n1sdp"
|
SRC_URI = "git://git.gitlab.arm.com/arm-reference-solutions/board-firmware.git;protocol=https;branch=n1sdp"
|
||||||
|
|
||||||
SRCREV = "6d5253584a9c2fdc2edbdc39bf6f2436215d1382"
|
SRCREV = "70ba494265eee76747faff38264860c19e214540"
|
||||||
|
PV .= "+git${SRCPV}"
|
||||||
|
|
||||||
S = "${WORKDIR}/git"
|
S = "${WORKDIR}/git"
|
||||||
|
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ do_install:append() {
|
|||||||
for TYPE in ${FW_INSTALL}; do
|
for TYPE in ${FW_INSTALL}; do
|
||||||
if [ "$TYPE" = "romfw_bypass" ]; then
|
if [ "$TYPE" = "romfw_bypass" ]; then
|
||||||
install -D "${B}/${TYPE}/${FW_TARGETS}/bin/${SCP_PLATFORM}-bl1-bypass.bin" "${D}/firmware/${FW}_${TYPE}.bin"
|
install -D "${B}/${TYPE}/${FW_TARGETS}/bin/${SCP_PLATFORM}-bl1-bypass.bin" "${D}/firmware/${FW}_${TYPE}.bin"
|
||||||
install -D "${B}/${TYPE}/${FW_TARGETS}/bin/${SCP_PLATFORM}-bl1-bypass" "${D}/firmware/${FW}_${TYPE}.elf"
|
install -D "${B}/${TYPE}/${FW_TARGETS}/bin/${SCP_PLATFORM}-bl1-bypass.elf" "${D}/firmware/${FW}_${TYPE}.elf"
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,9 +3,6 @@
|
|||||||
SCP_PLATFORM = "n1sdp"
|
SCP_PLATFORM = "n1sdp"
|
||||||
SCP_LOG_LEVEL = "INFO"
|
SCP_LOG_LEVEL = "INFO"
|
||||||
|
|
||||||
SRCREV = "de7e464ecd77130147103cf48328099c2d0e6289"
|
|
||||||
PV .= "+git${SRCPV}"
|
|
||||||
|
|
||||||
COMPATIBLE_MACHINE:n1sdp = "n1sdp"
|
COMPATIBLE_MACHINE:n1sdp = "n1sdp"
|
||||||
|
|
||||||
DEPENDS += "fiptool-native"
|
DEPENDS += "fiptool-native"
|
||||||
|
|||||||
+167
@@ -0,0 +1,167 @@
|
|||||||
|
From 360aa32846a97e775750e06865d462c6258179fa Mon Sep 17 00:00:00 2001
|
||||||
|
From: Mohamed Omar Asaker <mohamed.omarasaker@arm.com>
|
||||||
|
Date: Mon, 9 Jan 2023 13:59:06 +0000
|
||||||
|
Subject: [PATCH] feat(corstone1000): bl2 loads fip based on metadata
|
||||||
|
|
||||||
|
Previously bl2 was reading the boot_index directly with a hard coded
|
||||||
|
address and then set the fip image spec with fip offsets base based on
|
||||||
|
the boot_index value.
|
||||||
|
This commit removes this logic and rely on PSA_FWU_SUPPORT
|
||||||
|
which reads the fip partition based on the active firmware bank written in
|
||||||
|
metadata.
|
||||||
|
|
||||||
|
Note: fip partition contains signature area at the begining. Hence, the fip
|
||||||
|
image starts at fip partition + fip signature area size.
|
||||||
|
|
||||||
|
Upstream-Status: Pending
|
||||||
|
Signed-off-by: Mohamed Omar Asaker <mohamed.omarasaker@arm.com>
|
||||||
|
|
||||||
|
%% original patch: 0002-feat-corstone1000-bl2-loads-fip-based-on-metadata.patch
|
||||||
|
---
|
||||||
|
bl2/bl2_main.c | 4 +++
|
||||||
|
.../corstone1000/common/corstone1000_plat.c | 32 ++++++-------------
|
||||||
|
.../common/include/platform_def.h | 12 +++----
|
||||||
|
tools/cert_create/Makefile | 4 +--
|
||||||
|
tools/fiptool/Makefile | 4 +--
|
||||||
|
5 files changed, 24 insertions(+), 32 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bl2/bl2_main.c b/bl2/bl2_main.c
|
||||||
|
index 5da803795..f25dc3029 100644
|
||||||
|
--- a/bl2/bl2_main.c
|
||||||
|
+++ b/bl2/bl2_main.c
|
||||||
|
@@ -86,6 +86,10 @@ void bl2_main(void)
|
||||||
|
/* Perform remaining generic architectural setup in S-EL1 */
|
||||||
|
bl2_arch_setup();
|
||||||
|
|
||||||
|
+#if ARM_GPT_SUPPORT
|
||||||
|
+ partition_init(GPT_IMAGE_ID);
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
#if PSA_FWU_SUPPORT
|
||||||
|
fwu_init();
|
||||||
|
#endif /* PSA_FWU_SUPPORT */
|
||||||
|
diff --git a/plat/arm/board/corstone1000/common/corstone1000_plat.c b/plat/arm/board/corstone1000/common/corstone1000_plat.c
|
||||||
|
index 0235f8b84..7f9708a82 100644
|
||||||
|
--- a/plat/arm/board/corstone1000/common/corstone1000_plat.c
|
||||||
|
+++ b/plat/arm/board/corstone1000/common/corstone1000_plat.c
|
||||||
|
@@ -33,36 +33,17 @@ const mmap_region_t plat_arm_mmap[] = {
|
||||||
|
static void set_fip_image_source(void)
|
||||||
|
{
|
||||||
|
const struct plat_io_policy *policy;
|
||||||
|
- /*
|
||||||
|
- * metadata for firmware update is written at 0x0000 offset of the flash.
|
||||||
|
- * PLAT_ARM_BOOT_BANK_FLAG contains the boot bank that TF-M is booted.
|
||||||
|
- * As per firmware update spec, at a given point of time, only one bank
|
||||||
|
- * is active. This means, TF-A should boot from the same bank as TF-M.
|
||||||
|
- */
|
||||||
|
- volatile uint32_t *boot_bank_flag = (uint32_t *)(PLAT_ARM_BOOT_BANK_FLAG);
|
||||||
|
-
|
||||||
|
- if (*boot_bank_flag > 1) {
|
||||||
|
- VERBOSE("Boot_bank is set higher than possible values");
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
- VERBOSE("Boot bank flag = %u.\n\r", *boot_bank_flag);
|
||||||
|
|
||||||
|
policy = FCONF_GET_PROPERTY(arm, io_policies, FIP_IMAGE_ID);
|
||||||
|
|
||||||
|
assert(policy != NULL);
|
||||||
|
assert(policy->image_spec != 0UL);
|
||||||
|
|
||||||
|
+ /* FIP Partition contains Signature area at the begining which TF-A doesn't expect */
|
||||||
|
io_block_spec_t *spec = (io_block_spec_t *)policy->image_spec;
|
||||||
|
+ spec->offset += FIP_SIGNATURE_AREA_SIZE;
|
||||||
|
+ spec->length -= FIP_SIGNATURE_AREA_SIZE;
|
||||||
|
|
||||||
|
- if ((*boot_bank_flag) == 0) {
|
||||||
|
- VERBOSE("Booting from bank 0: fip offset = 0x%lx\n\r",
|
||||||
|
- PLAT_ARM_FIP_BASE_BANK0);
|
||||||
|
- spec->offset = PLAT_ARM_FIP_BASE_BANK0;
|
||||||
|
- } else {
|
||||||
|
- VERBOSE("Booting from bank 1: fip offset = 0x%lx\n\r",
|
||||||
|
- PLAT_ARM_FIP_BASE_BANK1);
|
||||||
|
- spec->offset = PLAT_ARM_FIP_BASE_BANK1;
|
||||||
|
- }
|
||||||
|
}
|
||||||
|
|
||||||
|
void bl2_platform_setup(void)
|
||||||
|
@@ -75,6 +56,13 @@ void bl2_platform_setup(void)
|
||||||
|
set_fip_image_source();
|
||||||
|
}
|
||||||
|
|
||||||
|
+void bl2_early_platform_setup2(u_register_t arg0, u_register_t arg1,
|
||||||
|
+ u_register_t arg2, u_register_t arg3)
|
||||||
|
+{
|
||||||
|
+ arm_bl2_early_platform_setup((uintptr_t)arg0, (meminfo_t *)arg1);
|
||||||
|
+ NOTICE("CS1k: early at bl2_platform_setup\n");
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
/* corstone1000 only has one always-on power domain and there
|
||||||
|
* is no power control present
|
||||||
|
*/
|
||||||
|
diff --git a/plat/arm/board/corstone1000/common/include/platform_def.h b/plat/arm/board/corstone1000/common/include/platform_def.h
|
||||||
|
index 584d485f3..0bfab05a4 100644
|
||||||
|
--- a/plat/arm/board/corstone1000/common/include/platform_def.h
|
||||||
|
+++ b/plat/arm/board/corstone1000/common/include/platform_def.h
|
||||||
|
@@ -173,16 +173,16 @@
|
||||||
|
|
||||||
|
/* NOR Flash */
|
||||||
|
|
||||||
|
-#define PLAT_ARM_BOOT_BANK_FLAG UL(0x08002000)
|
||||||
|
-#define PLAT_ARM_FIP_BASE_BANK0 UL(0x081EF000)
|
||||||
|
-#define PLAT_ARM_FIP_BASE_BANK1 UL(0x0916F000)
|
||||||
|
-#define PLAT_ARM_FIP_MAX_SIZE UL(0x1ff000) /* 1.996 MB */
|
||||||
|
-
|
||||||
|
#define PLAT_ARM_NVM_BASE V2M_FLASH0_BASE
|
||||||
|
#define PLAT_ARM_NVM_SIZE (SZ_32M) /* 32 MB */
|
||||||
|
+#define PLAT_ARM_FIP_MAX_SIZE UL(0x1ff000) /* 1.996 MB */
|
||||||
|
|
||||||
|
-#define PLAT_ARM_FLASH_IMAGE_BASE PLAT_ARM_FIP_BASE_BANK0
|
||||||
|
+#define PLAT_ARM_FLASH_IMAGE_BASE UL(0x08000000)
|
||||||
|
#define PLAT_ARM_FLASH_IMAGE_MAX_SIZE PLAT_ARM_FIP_MAX_SIZE
|
||||||
|
+#define PLAT_ARM_FIP_OFFSET_IN_GPT (0x86000)
|
||||||
|
+
|
||||||
|
+/* FIP Information */
|
||||||
|
+#define FIP_SIGNATURE_AREA_SIZE (0x1000) /* 4 KB */
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Some data must be aligned on the biggest cache line size in the platform.
|
||||||
|
diff --git a/tools/cert_create/Makefile b/tools/cert_create/Makefile
|
||||||
|
index ca548b836..32b5486a0 100644
|
||||||
|
--- a/tools/cert_create/Makefile
|
||||||
|
+++ b/tools/cert_create/Makefile
|
||||||
|
@@ -69,8 +69,8 @@ INC_DIR += -I ./include -I ${PLAT_INCLUDE} -I ${OPENSSL_DIR}/include
|
||||||
|
# directory. However, for a local build of OpenSSL, the built binaries are
|
||||||
|
# located under the main project directory (i.e.: ${OPENSSL_DIR}, not
|
||||||
|
# ${OPENSSL_DIR}/lib/).
|
||||||
|
-LIB_DIR := -L ${OPENSSL_DIR}/lib -L ${OPENSSL_DIR}
|
||||||
|
-LIB := -lssl -lcrypto
|
||||||
|
+LIB_DIR := -L ${OPENSSL_DIR}/lib -L ${OPENSSL_DIR} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS}
|
||||||
|
+LIB := -lssl -lcrypto ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS}
|
||||||
|
|
||||||
|
HOSTCC ?= gcc
|
||||||
|
|
||||||
|
diff --git a/tools/fiptool/Makefile b/tools/fiptool/Makefile
|
||||||
|
index e6aeba95b..7c047479e 100644
|
||||||
|
--- a/tools/fiptool/Makefile
|
||||||
|
+++ b/tools/fiptool/Makefile
|
||||||
|
@@ -29,7 +29,7 @@ endif
|
||||||
|
# directory. However, for a local build of OpenSSL, the built binaries are
|
||||||
|
# located under the main project directory (i.e.: ${OPENSSL_DIR}, not
|
||||||
|
# ${OPENSSL_DIR}/lib/).
|
||||||
|
-LDLIBS := -L${OPENSSL_DIR}/lib -L${OPENSSL_DIR} -lcrypto
|
||||||
|
+LDLIBS := -L${OPENSSL_DIR}/lib -L${OPENSSL_DIR} -lcrypto ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS}
|
||||||
|
|
||||||
|
ifeq (${V},0)
|
||||||
|
Q := @
|
||||||
|
@@ -37,7 +37,7 @@ else
|
||||||
|
Q :=
|
||||||
|
endif
|
||||||
|
|
||||||
|
-INCLUDE_PATHS := -I../../include/tools_share -I${OPENSSL_DIR}/include
|
||||||
|
+INCLUDE_PATHS := -I../../include/tools_share -I${OPENSSL_DIR}/include ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS}
|
||||||
|
|
||||||
|
HOSTCC ?= gcc
|
||||||
|
|
||||||
|
--
|
||||||
|
2.25.1
|
||||||
|
|
||||||
+42
@@ -0,0 +1,42 @@
|
|||||||
|
From 2d305094f8f500362079e9e7637d46129bf980e4 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Adam Johnston <adam.johnston@arm.com>
|
||||||
|
Date: Tue, 25 Jul 2023 16:05:51 +0000
|
||||||
|
Subject: [PATCH] n1sdp: Reserve OP-TEE memory from NWd
|
||||||
|
|
||||||
|
The physical memory which is used to run OP-TEE on the N1SDP is known
|
||||||
|
to the secure world via TOS_FW_CONFIG, but it may not be known to the
|
||||||
|
normal world.
|
||||||
|
|
||||||
|
As a precaution, explicitly reserve this memory via NT_FW_CONFIG to
|
||||||
|
prevent the normal world from using it. This is not required on most
|
||||||
|
platforms as the Trusted OS is run from secure RAM.
|
||||||
|
|
||||||
|
Upstream-Status: Pending (not yet submitted to upstream)
|
||||||
|
Signed-off-by: Adam Johnston <adam.johnston@arm.com>
|
||||||
|
Signed-off-by: Mariam Elshakfy <mariam.elshakfy@arm.com>
|
||||||
|
---
|
||||||
|
plat/arm/board/n1sdp/fdts/n1sdp_nt_fw_config.dts | 12 ++++++++++++
|
||||||
|
1 file changed, 12 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/plat/arm/board/n1sdp/fdts/n1sdp_nt_fw_config.dts b/plat/arm/board/n1sdp/fdts/n1sdp_nt_fw_config.dts
|
||||||
|
index da5e04ddb6..b7e2d4e86f 100644
|
||||||
|
--- a/plat/arm/board/n1sdp/fdts/n1sdp_nt_fw_config.dts
|
||||||
|
+++ b/plat/arm/board/n1sdp/fdts/n1sdp_nt_fw_config.dts
|
||||||
|
@@ -20,4 +20,16 @@
|
||||||
|
local-ddr-size = <0x0>;
|
||||||
|
remote-ddr-size = <0x0>;
|
||||||
|
};
|
||||||
|
+
|
||||||
|
+ reserved-memory {
|
||||||
|
+ #address-cells = <2>;
|
||||||
|
+ #size-cells = <2>;
|
||||||
|
+ ranges;
|
||||||
|
+
|
||||||
|
+ optee@0xDE000000 {
|
||||||
|
+ compatible = "removed-dma-pool";
|
||||||
|
+ reg = <0x0 0xDE000000 0x0 0x02000000>;
|
||||||
|
+ no-map;
|
||||||
|
+ };
|
||||||
|
+ };
|
||||||
|
};
|
||||||
|
\ No newline at end of file
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user