xlat_tables_common.c 11.9 KB
Newer Older
1
/*
2
 * Copyright (c) 2016-2018, ARM Limited and Contributors. All rights reserved.
3
 *
dp-arm's avatar
dp-arm committed
4
 * SPDX-License-Identifier: BSD-3-Clause
5
6
7
 */

#include <assert.h>
8
#include <stdbool.h>
9
#include <stdint.h>
10
#include <string.h>
11
12
13
14
15
16
17
18
19
20
21

#include <platform_def.h>

#include <arch.h>
#include <arch_helpers.h>
#include <common/debug.h>
#include <lib/cassert.h>
#include <lib/utils.h>
#include <lib/xlat_tables/xlat_tables.h>
#include <plat/common/common_def.h>

22
#include "xlat_tables_private.h"
23
24
25
26
27
28
29

#if LOG_LEVEL >= LOG_LEVEL_VERBOSE
#define LVL0_SPACER ""
#define LVL1_SPACER "  "
#define LVL2_SPACER "    "
#define LVL3_SPACER "      "
#define get_level_spacer(level)		\
30
31
32
			(((level) == U(0)) ? LVL0_SPACER : \
			(((level) == U(1)) ? LVL1_SPACER : \
			(((level) == U(2)) ? LVL2_SPACER : LVL3_SPACER)))
33
#define debug_print(...) printf(__VA_ARGS__)
34
35
36
37
#else
#define debug_print(...) ((void)0)
#endif

38
#define UNSET_DESC	~0ULL
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
39
#define MT_UNKNOWN	~0U
40
41
42
43

static uint64_t xlat_tables[MAX_XLAT_TABLES][XLAT_TABLE_ENTRIES]
			__aligned(XLAT_TABLE_SIZE) __section("xlat_table");

44
static unsigned int next_xlat;
45
46
47
static unsigned long long xlat_max_pa;
static uintptr_t xlat_max_va;

48
static uint64_t execute_never_mask;
49
static uint64_t ap1_mask;
50

51
52
53
54
55
56
57
58
59
60
61
62
/*
 * Array of all memory regions stored in order of ascending base address.
 * The list is terminated by the first entry with size == 0.
 */
static mmap_region_t mmap[MAX_MMAP_REGIONS + 1];


void print_mmap(void)
{
#if LOG_LEVEL >= LOG_LEVEL_VERBOSE
	debug_print("mmap:\n");
	mmap_region_t *mm = mmap;
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
63
	while (mm->size != 0U) {
64
65
66
67
68
69
70
71
72
73
		debug_print(" VA:%p  PA:0x%llx  size:0x%zx  attr:0x%x\n",
				(void *)mm->base_va, mm->base_pa,
				mm->size, mm->attr);
		++mm;
	};
	debug_print("\n");
#endif
}

void mmap_add_region(unsigned long long base_pa, uintptr_t base_va,
74
		     size_t size, unsigned int attr)
75
76
{
	mmap_region_t *mm = mmap;
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
77
78
79
	const mmap_region_t *mm_last = mm + ARRAY_SIZE(mmap) - 1U;
	unsigned long long end_pa = base_pa + size - 1U;
	uintptr_t end_va = base_va + size - 1U;
80
81
82
83
84

	assert(IS_PAGE_ALIGNED(base_pa));
	assert(IS_PAGE_ALIGNED(base_va));
	assert(IS_PAGE_ALIGNED(size));

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
85
	if (size == 0U)
86
87
		return;

88
89
90
	assert(base_pa < end_pa); /* Check for overflows */
	assert(base_va < end_va);

91
	assert((base_va + (uintptr_t)size - (uintptr_t)1) <=
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
92
					(PLAT_VIRT_ADDR_SPACE_SIZE - 1U));
93
	assert((base_pa + (unsigned long long)size - 1ULL) <=
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
94
					(PLAT_PHY_ADDR_SPACE_SIZE - 1U));
95

96
#if ENABLE_ASSERTIONS
97
98
99
100

	/* Check for PAs and VAs overlaps with all other regions */
	for (mm = mmap; mm->size; ++mm) {

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
101
		uintptr_t mm_end_va = mm->base_va + mm->size - 1U;
102
103
104
105
106

		/*
		 * Check if one of the regions is completely inside the other
		 * one.
		 */
107
108
109
		bool fully_overlapped_va =
			((base_va >= mm->base_va) && (end_va <= mm_end_va)) ||
			((mm->base_va >= base_va) && (mm_end_va <= end_va));
110
111
112
113
114
115

		/*
		 * Full VA overlaps are only allowed if both regions are
		 * identity mapped (zero offset) or have the same VA to PA
		 * offset. Also, make sure that it's not the exact same area.
		 */
116
		if (fully_overlapped_va) {
117
118
119
120
121
122
123
124
125
126
127
128
129
			assert((mm->base_va - mm->base_pa) ==
			       (base_va - base_pa));
			assert((base_va != mm->base_va) || (size != mm->size));
		} else {
			/*
			 * If the regions do not have fully overlapping VAs,
			 * then they must have fully separated VAs and PAs.
			 * Partial overlaps are not allowed
			 */

			unsigned long long mm_end_pa =
						     mm->base_pa + mm->size - 1;

130
131
132
133
			bool separated_pa = (end_pa < mm->base_pa) ||
				(base_pa > mm_end_pa);
			bool separated_va = (end_va < mm->base_va) ||
				(base_va > mm_end_va);
134

135
			assert(separated_va && separated_pa);
136
137
138
139
140
		}
	}

	mm = mmap; /* Restore pointer to the start of the array */

141
#endif /* ENABLE_ASSERTIONS */
142

143
	/* Find correct place in mmap to insert new region */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
144
	while ((mm->base_va < base_va) && (mm->size != 0U))
145
146
		++mm;

147
148
149
150
151
152
153
154
155
156
157
158
159
160
	/*
	 * If a section is contained inside another one with the same base
	 * address, it must be placed after the one it is contained in:
	 *
	 * 1st |-----------------------|
	 * 2nd |------------|
	 * 3rd |------|
	 *
	 * This is required for mmap_region_attr() to get the attributes of the
	 * small region correctly.
	 */
	while ((mm->base_va == base_va) && (mm->size > size))
		++mm;

161
	/* Make room for new region by moving other regions up by one place */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
162
	(void)memmove(mm + 1, mm, (uintptr_t)mm_last - (uintptr_t)mm);
163
164

	/* Check we haven't lost the empty sentinal from the end of the array */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
165
	assert(mm_last->size == 0U);
166
167
168
169
170
171

	mm->base_pa = base_pa;
	mm->base_va = base_va;
	mm->size = size;
	mm->attr = attr;

172
173
174
175
	if (end_pa > xlat_max_pa)
		xlat_max_pa = end_pa;
	if (end_va > xlat_max_va)
		xlat_max_va = end_va;
176
177
178
179
}

void mmap_add(const mmap_region_t *mm)
{
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
180
181
	const mmap_region_t *mm_cursor = mm;

182
	while ((mm_cursor->size != 0U) || (mm_cursor->attr != 0U)) {
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
183
184
185
		mmap_add_region(mm_cursor->base_pa, mm_cursor->base_va,
				mm_cursor->size, mm_cursor->attr);
		mm_cursor++;
186
187
188
	}
}

189
190
static uint64_t mmap_desc(unsigned int attr, unsigned long long addr_pa,
			  unsigned int level)
191
{
192
	uint64_t desc;
193
194
	int mem_type;

195
	/* Make sure that the granularity is fine enough to map this address. */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
196
	assert((addr_pa & XLAT_BLOCK_MASK(level)) == 0U);
197

198
	desc = addr_pa;
199
200
201
202
203
	/*
	 * There are different translation table descriptors for level 3 and the
	 * rest.
	 */
	desc |= (level == XLAT_TABLE_LEVEL_MAX) ? PAGE_DESC : BLOCK_DESC;
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
204
205
	desc |= ((attr & MT_NS) != 0U) ? LOWER_ATTRS(NS) : 0U;
	desc |= ((attr & MT_RW) != 0U) ? LOWER_ATTRS(AP_RW) : LOWER_ATTRS(AP_RO);
206
207
208
209
	/*
	 * Always set the access flag, as this library assumes access flag
	 * faults aren't managed.
	 */
210
	desc |= LOWER_ATTRS(ACCESS_FLAG);
211
	desc |= ap1_mask;
212

213
214
215
216
217
218
219
220
221
222
	/*
	 * Deduce shareability domain and executability of the memory region
	 * from the memory type.
	 *
	 * Data accesses to device memory and non-cacheable normal memory are
	 * coherent for all observers in the system, and correspondingly are
	 * always treated as being Outer Shareable. Therefore, for these 2 types
	 * of memory, it is not strictly needed to set the shareability field
	 * in the translation tables.
	 */
223
	mem_type = MT_TYPE(attr);
224
	if (mem_type == MT_DEVICE) {
225
		desc |= LOWER_ATTRS(ATTR_DEVICE_INDEX | OSH);
226
227
228
229
230
231
		/*
		 * Always map device memory as execute-never.
		 * This is to avoid the possibility of a speculative instruction
		 * fetch, which could be an issue if this memory region
		 * corresponds to a read-sensitive peripheral.
		 */
232
233
		desc |= execute_never_mask;

234
235
236
	} else { /* Normal memory */
		/*
		 * Always map read-write normal memory as execute-never.
237
238
239
240
		 * This library assumes that it is used by software that does
		 * not self-modify its code, therefore R/W memory is reserved
		 * for data storage, which must not be executable.
		 *
241
		 * Note that setting the XN bit here is for consistency only.
242
		 * The function that enables the MMU sets the SCTLR_ELx.WXN bit,
243
244
245
		 * which makes any writable memory region to be treated as
		 * execute-never, regardless of the value of the XN bit in the
		 * translation table.
246
247
248
		 *
		 * For read-only memory, rely on the MT_EXECUTE/MT_EXECUTE_NEVER
		 * attribute to figure out the value of the XN bit.
249
		 */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
250
		if (((attr & MT_RW) != 0U) || ((attr & MT_EXECUTE_NEVER) != 0U)) {
251
252
			desc |= execute_never_mask;
		}
253
254
255
256
257
258
259

		if (mem_type == MT_MEMORY) {
			desc |= LOWER_ATTRS(ATTR_IWBWA_OWBWA_NTR_INDEX | ISH);
		} else {
			assert(mem_type == MT_NON_CACHEABLE);
			desc |= LOWER_ATTRS(ATTR_NON_CACHEABLE_INDEX | OSH);
		}
260
261
262
263
	}

	debug_print((mem_type == MT_MEMORY) ? "MEM" :
		((mem_type == MT_NON_CACHEABLE) ? "NC" : "DEV"));
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
264
265
266
	debug_print(((attr & MT_RW) != 0U) ? "-RW" : "-RO");
	debug_print(((attr & MT_NS) != 0U) ? "-NS" : "-S");
	debug_print(((attr & MT_EXECUTE_NEVER) != 0U) ? "-XN" : "-EXEC");
267
268
269
	return desc;
}

270
/*
271
272
273
274
275
 * Look for the innermost region that contains the area at `base_va` with size
 * `size`. Populate *attr with the attributes of this region.
 *
 * On success, this function returns 0.
 * If there are partial overlaps (meaning that a smaller size is needed) or if
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
276
277
 * the region can't be found in the given area, it returns MT_UNKNOWN. In this
 * case the value pointed by attr should be ignored by the caller.
278
 */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
279
280
static unsigned int mmap_region_attr(const mmap_region_t *mm, uintptr_t base_va,
				     size_t size, unsigned int *attr)
281
{
282
	/* Don't assume that the area is contained in the first region */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
283
	unsigned int ret = MT_UNKNOWN;
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299

	/*
	 * Get attributes from last (innermost) region that contains the
	 * requested area. Don't stop as soon as one region doesn't contain it
	 * because there may be other internal regions that contain this area:
	 *
	 * |-----------------------------1-----------------------------|
	 * |----2----|     |-------3-------|    |----5----|
	 *                   |--4--|
	 *
	 *                   |---| <- Area we want the attributes of.
	 *
	 * In this example, the area is contained in regions 1, 3 and 4 but not
	 * in region 2. The loop shouldn't stop at region 2 as inner regions
	 * have priority over outer regions, it should stop at region 5.
	 */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
300
	for ( ; ; ++mm) {
301

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
302
		if (mm->size == 0U)
303
			return ret; /* Reached end of list */
304

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
305
		if (mm->base_va > (base_va + size - 1U))
306
			return ret; /* Next region is after area so end */
307

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
308
		if ((mm->base_va + mm->size - 1U) < base_va)
309
310
			continue; /* Next region has already been overtaken */

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
311
		if ((ret == 0U) && (mm->attr == *attr))
312
313
			continue; /* Region doesn't override attribs so skip */

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
314
315
316
		if ((mm->base_va > base_va) ||
			((mm->base_va + mm->size - 1U) < (base_va + size - 1U)))
			return MT_UNKNOWN; /* Region doesn't fully cover area */
317

318
		*attr = mm->attr;
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
319
		ret = 0U;
320
	}
321
	return ret;
322
323
324
325
326
}

static mmap_region_t *init_xlation_table_inner(mmap_region_t *mm,
					uintptr_t base_va,
					uint64_t *table,
327
					unsigned int level)
328
{
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
329
330
	assert((level >= XLAT_TABLE_LEVEL_MIN) &&
	       (level <= XLAT_TABLE_LEVEL_MAX));
331

332
333
334
335
336
	unsigned int level_size_shift =
		       L0_XLAT_ADDRESS_SHIFT - level * XLAT_TABLE_ENTRIES_SHIFT;
	u_register_t level_size = (u_register_t)1 << level_size_shift;
	u_register_t level_index_mask =
		((u_register_t)XLAT_TABLE_ENTRIES_MASK) << level_size_shift;
337
338
339
340
341
342

	debug_print("New xlat table:\n");

	do  {
		uint64_t desc = UNSET_DESC;

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
343
		if (mm->size == 0U) {
344
345
			/* Done mapping regions; finish zeroing the table */
			desc = INVALID_DESC;
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
346
		} else if ((mm->base_va + mm->size - 1U) < base_va) {
347
			/* This area is after the region so get next region */
348
349
350
351
			++mm;
			continue;
		}

352
353
		debug_print("%s VA:%p size:0x%llx ", get_level_spacer(level),
			(void *)base_va, (unsigned long long)level_size);
354

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
355
		if (mm->base_va > (base_va + level_size - 1U)) {
356
			/* Next region is after this area. Nothing to map yet */
357
			desc = INVALID_DESC;
358
359
		/* Make sure that the current level allows block descriptors */
		} else if (level >= XLAT_BLOCK_LEVEL_MIN) {
360
361
362
363
364
			/*
			 * Try to get attributes of this area. It will fail if
			 * there are partially overlapping regions. On success,
			 * it will return the innermost region's attributes.
			 */
365
			unsigned int attr;
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
366
367
			unsigned int r = mmap_region_attr(mm, base_va,
							  level_size, &attr);
368

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
369
			if (r == 0U) {
370
371
372
				desc = mmap_desc(attr,
					base_va - mm->base_va + mm->base_pa,
					level);
373
			}
374
375
376
377
		}

		if (desc == UNSET_DESC) {
			/* Area not covered by a region so need finer table */
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
378
379
380
			uint64_t *new_table = xlat_tables[next_xlat];

			next_xlat++;
381
			assert(next_xlat <= MAX_XLAT_TABLES);
382
			desc = TABLE_DESC | (uintptr_t)new_table;
383
384
385

			/* Recurse to fill in new table */
			mm = init_xlation_table_inner(mm, base_va,
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
386
						new_table, level + 1U);
387
388
389
390
391
392
		}

		debug_print("\n");

		*table++ = desc;
		base_va += level_size;
393
	} while ((base_va & level_index_mask) &&
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
394
		 ((base_va - 1U) < (PLAT_VIRT_ADDR_SPACE_SIZE - 1U)));
395
396
397
398
399

	return mm;
}

void init_xlation_table(uintptr_t base_va, uint64_t *table,
400
			unsigned int level, uintptr_t *max_va,
401
402
			unsigned long long *max_pa)
{
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
403
	unsigned int el = xlat_arch_current_el();
404
405
406

	execute_never_mask = xlat_arch_get_xn_desc(el);

Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
407
	if (el == 3U) {
408
409
		ap1_mask = LOWER_ATTRS(AP_ONE_VA_RANGE_RES1);
	} else {
Antonio Nino Diaz's avatar
Antonio Nino Diaz committed
410
411
		assert(el == 1U);
		ap1_mask = 0ULL;
412
413
	}

414
415
416
417
	init_xlation_table_inner(mmap, base_va, table, level);
	*max_va = xlat_max_va;
	*max_pa = xlat_max_pa;
}