2251 Commits
Author SHA1 Message Date
Benoît Monin 6ad246a149 platform: generic: metanoia/mt2824: configure PMA for DSP memory regions
Set up the memory attribute for the XOR RAM, MRAS memory, and RSC table
used by the DSPs as non-cacheable and bufferable during final init.

Signed-off-by: Benoît Monin <benoit.monin@bootlin.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260902-mt2824-pma-v1-1-ada8f836365d@bootlin.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-28 18:06:25 +05:30
Shibo Zhu 2de7dfb681 lib: sbi_mpxy: Fix shared memory size rounding
The sbi_mpxy_register_channel() currently performs ceiling division by
PAGE_SIZE but stores the resulting page count in mpxy_shmem_size. All
consumers interpret mpxy_shmem_size as a byte count, so channels requiring
more than one page get an undersized shared memory value.

Address the above issue by using ROUNDUP() to keep the rounded value in
bytes.

Fixes: ec09918426 ("lib: sbi: Update MPXY framework and SBI extension as per latest spec")
Signed-off-by: Shibo Zhu <3499129952@qq.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/tencent_14AA3BA0083001905C262A5CD64E442FC205@qq.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-28 17:42:15 +05:30
Chen Pei 0ffaa1bc65 lib/utils/fdt: Reserve exactly enough FDT space for fdt_cpu_fixup
fdt_cpu_fixup() reserves a hardcoded 32 extra bytes, plus 16 more per
HART inside the "zicntr" loop. Those 32 bytes also have to cover every
"status" property rewritten to "disabled", so once more than a handful
of HARTs are disabled the fixups fail with FDT_ERR_NOSPACE (-3).

Bumping the reservation to a fixed worst case is not safe either:
fdt_open_into() cannot know how much space the caller's buffer really
has, it just trusts the requested size. As OpenSBI does not own the
memory following a device tree passed in by the previous booting stage,
over-declaring the blob risks corrupting whatever follows it.

Walk the HART nodes once without modifying them instead, and reserve
exactly what the fixups need. The read-only decision logic is factored
into fdt_cpu_fixup_needed() so the sizing and fixup passes cannot drift
apart, which also makes the per-HART fdt_open_into() redundant. Check
the return values of fdt_setprop_string() and fdt_appendprop_string()
as well, as running out of space used to fail silently.

Fixes: dd9439fbac ("lib: utils: Add a fdt_cpu_fixup() helper")
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260817084303.1232-1-cp0613@linux.alibaba.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-28 11:41:25 +05:30
Trevor Gamblin 5b1e739428 Makefile: don't grep when setting CC_SUPPORT_SAVE_RESTORE
Check exit status from the compiler/linker check directly (similar to
OPENSBI_LD_PIE), rather than using grep to search for a pattern. This
avoids potential unrelated matches in the command.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260923-makefile_extension_grep-v2-3-0eb97b8ac076@baylibre.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-28 11:03:50 +05:30
Trevor Gamblin f3ed2c4e5c Makefile: don't grep when setting CC_SUPPORT_STRICT_ALIGN
Check exit status from the compiler/linker check directly (similar to
OPENSBI_LD_PIE), rather than using grep to search for a pattern. This
avoids potential unrelated matches in the command.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260923-makefile_extension_grep-v2-2-0eb97b8ac076@baylibre.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-28 11:03:50 +05:30
Trevor Gamblin 7b4c152c8f Makefile: don't grep when setting CC_SUPPORT_ZICSR_ZIFENCEI
Check exit status from the compiler/linker check directly (similar to
OPENSBI_LD_PIE), rather than using grep to search for a pattern. This
avoids potential unrelated matches in the command.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260923-makefile_extension_grep-v2-1-0eb97b8ac076@baylibre.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-28 11:03:50 +05:30
Zong Li 5a17501726 docs: firmware: document the OpenSBI firmware header
Add docs/firmware/fw_header.md describing the layout of the 128-byte
OpenSBI firmware header, the a0/a1/a2 override flags, what a previous
booting stage is expected to put in each register, and an example of how
to patch the header. Also point at it from fw.md, next to the
description of the registers the previous booting stage passes.

Signed-off-by: Zong Li <zong.li@sifive.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260918081313.659655-4-zong.li@sifive.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-18 16:52:39 +05:30
Zong Li f83d6a730b firmware: fw_base.S: override a0, a1 and a2 from the firmware header
Wire up the flags word and the three override values in the OpenSBI
firmware header. When the previous booting stage sets one of the
FW_HEADER_FLAGS_OVERRIDE_A[012] bits, the cold boot path replaces the
matching register with the value stored in the header before doing
anything else with the boot arguments.

This lets a previous booting stage which cannot pass the boot arguments
in registers hand them over by patching a few words in the firmware
image instead. For example, a booting stage running on a dedicated boot
processor can load the OpenSBI image, patch the header with the hart id,
the DTB address and, for FW_DYNAMIC, the address of a struct
fw_dynamic_info it built somewhere in DRAM, and then release the hart
that runs OpenSBI, without ever being able to set up that hart's
registers itself.

The flags word is zero in a freshly built image, so nothing is
overridden and every existing booting stage keeps passing a0, a1 and a2
in registers as before.

Suggested-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Zong Li <zong.li@sifive.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260918081313.659655-3-zong.li@sifive.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-18 16:52:39 +05:30
Zong Li 1854901adc firmware: fw_base.S: add a formatted OpenSBI firmware header
Add a fixed 128-byte header at the very beginning of every OpenSBI
firmware image, regardless of the firmware type. The header lets the
previous booting stage identify an OpenSBI image and, more importantly,
gives it a well-known place inside the image to hand over information
to OpenSBI by patching a few words instead of setting up registers.

This first patch only introduces the layout:

  - a 4-byte jump over the header to _start_real, so that _start stays
    the entry point of the image. The jump is assembled with
    '.option norvc' so that the fields behind it are always at a fixed
    offset, even for a build with compressed instructions enabled,

  - the 'OSBI' magic, a header version, the XLEN the firmware was built
    for and the size of the firmware image, so that the previous booting
    stage can validate the image and figure out how much memory it
    occupies,

  - a flags word and three 8-byte override values, which are unused
    (and zero) for now and are wired up by the next patch.

The layout is deliberately identical for RV32 and RV64 so that the
previous booting stage can parse the header without knowing the XLEN of
the firmware upfront. Each override value is followed by a reserved
8-byte slot so that the same layout can be extended to RV128 later.

Suggested-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Zong Li <zong.li@sifive.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260918081313.659655-2-zong.li@sifive.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-18 16:52:39 +05:30
Carlos López 9476b78361 Makefile: enable Thread Safety Analysis
Now that all locking code has been properly annotated, enable clang's
Thread Safety Analysis.

Two flags are available, -Wthread-safety, and the more recent
-Wthread-safety-pointer. The former was introduced before clang gained
RISC-V support, so it is guaranteed to be available. The latter was
introduced in clang 21, so check if the provided compiler supports it
before enabling it.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-16-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 92b24d6acb lib: test: disable TSA for spinlock tests
The spinlock tests deliberately use unconventional locking patterns to
test edge cases. Disable thread safety analysis for them so that they
don't generate false positives when the feature is enabled.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-15-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 8f80b2651f lib: sbi_sse: add TSA annotations
Now that the lock relationship between an event and its owner hart is
explicit, add TSA annotations for the SSE handling code. This includes
indicating which fields are protected by a spinlock, as well as
annotating which functions need to run under a spinlock.

Exclude sse_local_init(), which initializes the spinlock to be acquired,
and sse_event_get() / sse_event_put(), which perform conditional locking
that TSA is not able to follow properly.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-14-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 43bb3df782 lib: sbi_sse: pass SSE hart state explicitly
In preparation to add TSA annotations, pass the SSE hart state owning an
event, instead of relying on sse_get_hart_state() to retrieve it from
the event itself. This makes the relationship more explicit, and will
allow the compiler to reason about the state of locks.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-13-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López fc1ae7a641 lib: sbi_sse: inline enable event locking
In preparation to add TSA annotations, inline sse_enabled_event_lock()
and sse_enabled_event_unlock(). This will help the compiler reason about
locking of the hart state by explicitly acquiring the spinlock in the
callers.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-12-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 8740e0a38c lib: sbi_domain: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the domain handling
code. This includes indicating which fields are protected by a spinlock,
and annotating which functions acquire a spinlock, in order to prevent
nesting. Exclude sbi_domain_register() from analysis, as it initializes
a domain's spinlock.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-11-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 1ba332872b lib: htif: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the HTIF driver
implementation.

This requires annotating the tohost/fromhost and htif_console_buf
globals to indicate that they are protected by htif_lock.
htif_system_reset() can be excluded since it is only called under
special circumstances from sbi_system_reset(), when all other harts
have been stopped.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-10-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López f5fd674f18 lib: sbi_timer: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the timer
implementation. This includes indicating which fields are protected
by a spinlock, and annotating which functions must be called under a
spinlock. Exclude sbi_timer_init(), as the spinlock cannot be acquired
before it is initialized.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-9-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 497ca4ccad lib: rpmi: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the RPMI mailbox
implementation. This includes indicating which fields are protected
by a spinlock, and annotating which functions must be called under a
spinlock. Exclude rpmi_shmem_transport_init(), as the spinlock cannot be
acquired before it is initialized.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-8-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 2d34c0e0e1 lib: sbi_scratch: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the scratch space
implementation. This only consists of annotating that the extra_offset
global must be accessed under the extra_lock spinlock.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-7-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López eaac726ea1 lib: sbi_heap: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the heap allocator.
This includes indicating which fields are protected by a spinlock and
annotating functions that must be called under a spinlock. Exclude
sbi_heap_init_new(), as the spinlock cannot be acquired before it is
initialized.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-6-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 832ede6a8f lib: sbi_fifo: add TSA annotations
Add Thread Safety Analysis (TSA) annotations for the FIFO
implementation. This consists of indicating which fields are protected
by a spinlock and annotating functionst that must be called under a
spinlock. sbi_fifo_init() must be excluded, as acquiring a spinlock
before it is initialized does not make sense.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-5-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López b8f7e9ea80 lib: sbi_locks: annotate spinlock APIs for TSA
Add Thread Safety Analysis (TSA) annotations for spinlock APIs, allowing
the compiler to reason about lock acquisition and release.

Annotations have a different meaning if used in header declarations vs C
file implementations. In header declarations, they specify the semantics
of the given function, meaning that we must specify that the spinlock
functions acquire and release a lock ("capability" in clang terms).
In function implementations, attributes affect the function body and
callers in the same translation unit; since the spinlock functions
contain inline assembly, they must be excluded from analysis.

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-4-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Carlos López 8d109c7e87 include: sbi: add thread safety analysis macros
Add macros to properly guard clang's thread safety analysis attributes
keeping compatibility with GCC, on top of making things more readable.

Clang < 19 does not support guarded_by() [0], so do not define the
macros in that case.

[0] https://github.com/llvm/llvm-project/pull/94216

Signed-off-by: Carlos López <carlos.lopezr4096@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260909162322.29778-3-carlos.lopezr4096@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:48:30 +05:30
Anup Patel 55b6b73435 lib: sbi_domain: Introduce domain intialization order
Currently, the domain initialization order is implied by the order
in which domains are populated by sbi_platform_domains_init() from
sbi_domain_finalize(). This is not documented anywhere and forces
unecessary ordering between domain DT nodes.

To address the above, introduce per-domain 32-bit integer to represent
intialization order (aka "init_order") where domain with a lower
initialization order will be booted first and two domains must not
have same initialization order. For DT based domain creation, new
"init-order" DT property can be used in domain DT node to specify
the initialization order. The ROOT domain is assumed to have lowest
initialization order (aka 0xffffffff).

Signed-off-by: Anup Patel <anup.patel@oss.qualcomm.com>
Reviewed-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Tested-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Reviewed-by: Yu-Chien Peter Lin <peter.lin@sifive.com>
Link: https://lore.kernel.org/r/20260905131748.922920-4-anup.patel@oss.qualcomm.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:21:21 +05:30
Anup Patel 71faf5a307 lib: sbi_domain: Re-work boot-time assignment of HARTs to non-ROOT domains
Assign a non-ROOT domain to a HART on first come first serve basis if the
HART is listed as a possible HART of the non-ROOT domain. If no non-ROOT
domain list a HART as possible HART then the HART is assigned to the ROOT
domain.

This allows us to drop the OpenSBI specific DT property from each CPU DT
node (aka "opensbi-domain" Dt property).

Signed-off-by: Anup Patel <anup.patel@oss.qualcomm.com>
Reviewed-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Tested-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Reviewed-by: Yu-Chien Peter Lin <peter.lin@sifive.com>
Link: https://lore.kernel.org/r/20260905131748.922920-3-anup.patel@oss.qualcomm.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:21:21 +05:30
Anup Patel 6dc5a896b1 lib: sbi_domain: Check possible harts in sbi_domain_context_enter/exit()
When context switching to a domain the current hart MUST be part
of the possible harts of that domain. Add appropriate checks in
sbi_domain_context_enter/exit() along these lines.

Signed-off-by: Anup Patel <anup.patel@oss.qualcomm.com>
Reviewed-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Tested-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Reviewed-by: Yu-Chien Peter Lin <peter.lin@sifive.com>
Link: https://lore.kernel.org/r/20260905131748.922920-2-anup.patel@oss.qualcomm.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-16 09:21:21 +05:30
Rahul Pathak 3593a5facc lib: sbi_domain: Rename per-domain data to per-domain state
The per-domain sbi_domain_data hold each domain
associated state like hart context in sbi_domain_context,
mpxy state in sbi_mpxy, and others like each domain backed
by the corresponding MPT (SMMPT).
DATA reads as a generic name, while every use stores state.
Rename functions and macros appropriately. There are no
functional changes.

Signed-off-by: Rahul Pathak <rahul.pathak@oss.qualcomm.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260820121309.2551296-3-rahul.pathak@oss.qualcomm.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-05 12:53:15 +05:30
Rahul Pathak 35af7c8c7e lib: sbi: Rename map_range/unmap_range functions
*_map_range and *_unmap_range functions are required
in M-Mode to get the temporary access to S-Mode and U-Mode
regions. Thse functions only operate using the TYPE_MEMORY
memory protection mechanisms. Rename them to reflect the
actual usage of these functions and let generic map/unmap_range
names to implement generic functions

Signed-off-by: Rahul Pathak <rahul.pathak@oss.qualcomm.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Reviewed-by: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260820121309.2551296-2-rahul.pathak@oss.qualcomm.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-05 12:52:39 +05:30
whensun 7774b82e4a lib: sbi: Fix FP state enable in sbi_fp_save
sbi_fp_save() currently sets mstatus.VS before executing floating-point
store instructions. VS controls vector state and does not enable
floating-point instructions.

Set mstatus.FS instead, matching sbi_fp_restore(), so floating-point
state can be saved when FS was previously Off.

Fixes: 718e1d194f ("lib: sbi: Add floating-point context save/restore support.")
Signed-off-by: whensun <theodoruswensanfebruanto025@gmail.com>
Co-developed-by: Huamao Wu <huamao.wu@spacemit.com>
Signed-off-by: Huamao Wu <huamao.wu@spacemit.com>
Link: https://lore.kernel.org/r/20260828213104.84490-1-theodoruswensanfebruanto025@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-05 12:33:48 +05:30
Heinrich Schuchardt bf459f85bf lib: sbi_irqchip: error handling in sbi_irqchip_raw_handler_default()
sbi_irqchip_find_handler() may return NULL.
Check the return value before dereferencing.

Addresses-Coverity-ID: 1677408 Dereference null return value
Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260820134431.167336-1-heinrich.schuchardt@canonical.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-04 13:55:01 +05:30
Ben Zong-You Xie 7384968e02 lib: sbi: respect scounteren when emulating timeh
beef2f6937 ("lib: sbi: Respect scounteren when emulating the time
CSR") restored it for TIME only, so on RV32 supervisor software still
cannot restrict U-mode or VS-mode access to time: rdtime traps as
intended while rdtimeh keeps returning the upper half.

Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260805093354.1022980-1-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-04 13:44:57 +05:30
David E. Garcia Porras c5077d497d lib: sbi_pmu: Fix counter and event info error codes as per SBI v3.0 spec
Align the PMU extension implementation with the error codes required
by the SBI v3.0 specification, chapter 11:

 - sbi_pmu_counter_start and sbi_pmu_counter_stop (secs 11.9-11.10,
   tables 39-42): the start_flags/stop_flags bits 2:(XLEN-1) are
   reserved and must be zero, so return SBI_ERR_INVALID_PARAM when any
   reserved flag bit is set. Introduce SBI_PMU_START_FLAGS_MASK and
   SBI_PMU_STOP_FLAGS_MASK for the valid bits of each function.

 - sbi_pmu_counter_start and sbi_pmu_counter_stop (tables 40 and 42):
   return SBI_ERR_ALREADY_STARTED / SBI_ERR_ALREADY_STOPPED when the
   set of counters includes a counter which is already started or
   stopped, instead of ignoring the error returned for each counter.

 - sbi_pmu_event_get_info (sec 11.14, table 47): the output word must
   indicate whether the event is supported, but firmware events were
   only matched against the hardware event map and were always
   reported as unsupported. Report a validated firmware event as
   supported.

Signed-off-by: David E. Garcia Porras <david.garcia@aheadcomputing.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260818210023.466462-4-david.garcia@aheadcomputing.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-04 11:43:53 +05:30
David E. Garcia Porras d34a39df77 lib: sbi_pmu: Match raw event selector only against raw event map entries
sbi_pmu_event_get_info() walks hw_event_map[] to decide whether a
requested event is supported. For SBI_PMU_EVENT_RAW_IDX and
SBI_PMU_EVENT_RAW_V2_IDX it compares the requested event_data against
temp->select / temp->select_mask without first checking that the map
entry being examined is itself a raw event entry.

Non-raw hardware event entries are added via sbi_pmu_add_hw_event_counter_map(),
leave select and select_mask at zero, hence they satisfy:

	temp->select == (event_data & temp->select_mask)

so the first non-raw entry visited will always match.
The issue's observability depends purely on the ordering of hw_event_map[]:
if the platform registers its raw events last, every raw event query, including
unsupported ones, will be reported as supported.

Fix it by checking event_idx against temp->start_idx and temp->end_idx before
comparing select/select_mask.

Fixes: e434584216 ("lib: sbi_pmu: Implement SBI PMU event info function")
Signed-off-by: David E. Garcia Porras <david.garcia@aheadcomputing.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260818210023.466462-3-david.garcia@aheadcomputing.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-03 13:37:34 +05:30
David E. Garcia Porras d97cfb33ae lib: sbi_pmu: Return invalid param error for reserved event_idx bits
As per section 11.14 of the SBI specification (Function: Get PMU Event
Info, FID #8), Table 47, the event_idx word of an event info entry
only uses BIT[0:19]; BIT[20:31] are reserved for the future purpose
and must be zero. Table 48 further requires the SBI implementation to
return SBI_ERR_INVALID_PARAM if any reserved bit in an event_idx word
is set.

sbi_pmu_event_get_info() does not check the reserved bits, so a
malformed event_idx is silently passed on to pmu_event_validate()
instead of failing the call. Add SBI_PMU_EVENT_IDX_MBZ_MASK covering
the must-be-zero bits and return SBI_ERR_INVALID_PARAM when any of
them are set.

Fixes: e434584216 ("lib: sbi_pmu: Implement SBI PMU event info function")
Signed-off-by: David E. Garcia Porras <david.garcia@aheadcomputing.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260818210023.466462-2-david.garcia@aheadcomputing.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-03 13:27:45 +05:30
Zhanpeng Zhang 35511bc6ee lib: sbi: sse: clear SPV for non-virtualized events
SSE injection sets hstatus.SPV to the virtualization state of the
interrupted context before entering the supervisor handler. This patch
completes that existing requirement and does not change the SSE ABI.

The existing code sets SPV when the interrupted context is virtualized,
but leaves it unchanged otherwise. A stale SPV value can therefore make
an event that interrupted host execution appear to have interrupted a
guest. Event completion can then resume with virtualization enabled.

Clear SPV when the interrupted context is not virtualized so the
handler-visible state matches the interrupted context. This also lets
supervisor software, such as the Linux PMU and perf code, reliably tell
whether an SSE interrupted host or virtualized execution.

Fixes: c8cdf01d8f ("lib: sbi: Add support for Supervisor Software Events extension")
Signed-off-by: Zhanpeng Zhang <zhangzhanpeng.jasper@bytedance.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260731071820.7318-1-zhangzhanpeng.jasper@bytedance.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 12:57:33 +05:30
Randolph 22a5f98b39 platform: generic/andes: fix 32-bit shift overflow in decode_pmaaddrx()
decode_pmaaddrx() reconstructs the NAPOT region start and size from a
pmaaddr CSR value using "1 << (k + 3)" and "1 << k". The integer
literal 1 has type int, so these shifts are performed in 32-bit
precision. Shifting a 32-bit value by 32 or more bits is undefined
behavior, and on RV64 the compiler emits sllw, which truncates the
shift amount modulo 32.

As a result, any PMA region with size >= 4 GiB (k >= 29) is decoded
incorrectly. For example, on the Andes QiLai SoC the PCIe region
0x1000000000 - 0x17ffffffff (pmaaddr = 0x4ffffffff, k = 32) is decoded
as an 8-byte region at 0x13fffffffc.

This is not merely cosmetic: decode_pmaaddrx() is used by
has_pma_region_overlap() and andes_sbi_free_pma(), so overlap checks
are performed against bogus ranges and freeing such an entry by its
physical address always fails.

Promote the shifts to unsigned long so they are performed in the
native register width.

Fixes: aa56084c4d ("platform: generic: andes: add a new Andes SBI call to set up a PMA entry")
Signed-off-by: Randolph Lin <randolph@andestech.com>
Tested-by: Benoît Monin <benoit.monin@bootlin.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260729092317.2848665-1-randolph@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:59:55 +05:30
Ben Zong-You Xie 06af8bd61b lib: utils/andes: arm the SMU sleep command last
Once the sleep command is written, the next WFI puts the core to sleep,
so everything that can fail has to run before it.

Also, use writel() so the command store cannot still be in flight at the
WFI.

Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-8-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
Ben Zong-You Xie 0fb4799307 lib: utils/suspend: wait for the secondary Andes harts to sleep
A secondary hart may not have reached the target sleep state by the time
the primary checks, so the one-shot check could fail spuriously. Poll
each PCS status instead and give up after HART_SLEEP_TIMEOUT_MS.

Rework atcsmu_pcs_is_sleep() into the atcsmu_hart_is_sleep() predicate so
sbi_timer_waitms_until() can drive it.

Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-7-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
Ben Zong-You Xie e01bd7926b lib: utils/hsm: wake sleeping Andes harts with an IPI
An IPI wakes a hart from light sleep and, once MSIP is kept as an SMU
wakeup event, from deep sleep too. Drop the WAKEUP_CMD path and the boot
state, hart type and sleep type conditions that selected it.

Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-6-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
Ben Zong-You Xie 9ceaf4738a lib: utils/suspend: restore Andes CSRs on system-suspend resume
A deep sleep resume leaves the boot hart in SUSPENDED state, so
init_warmboot() dispatches to init_warm_resume(), which calls the SUSP
device's system_resume callback and not sbi_platform_early_init(). The
restore in ae350_early_init() is dead code on that path.

Fixes: b27ecec76b ("lib: utils/suspend: add Andes ATCSMU suspend driver")
Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-5-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
Ben Zong-You Xie 733867c0c8 platform: generic/andes: pair non-retentive CSR save/restore with a flag
The restore was gated on sbi_init_count() and the current sleep type,
which is only a proxy for "did this hart actually save its CSRs". Track
it explicitly instead, so restore is self-guarding and the call site
needs no conditions.

Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-4-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
Ben Zong-You Xie 4c5d9d9f93 lib: utils/andes: add the SMU and LLC registers to the root domain
When a hart implements Smepmp, S-mode and U-mode cannot reach either
device unless its region is shared explicitly. Suspend and resume then
take an access violation as soon as the supervisor touches the SMU or
the LLC.

Share both regions, and take their sizes from the DT nodes rather than
ignoring them.

Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-3-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
Ben Zong-You Xie 344428d832 lib: utils/cache: fix andes_llcache_enable() return value
The driver returned 1 on success where callers expect 0, so the suspend
to RAM aborted right after disabling the LLC and before flushing it.

Fixes: 82b0961821 ("lib: utils/cache: add Andes last level cache controller")
Signed-off-by: Ben Zong-You Xie <ben717@andestech.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260728081041.2724668-2-ben717@andestech.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:46:23 +05:30
David E. Garcia Porras 27d9545384 lib: sbi: dbtr: add platform device for per-slot trigger capabilities
The tinfo probe only discovers trigger types; WARL fields tied off
inside an implemented trigger CSR (e.g. an mcontrol6 trigger without
load/store address match) are not discoverable. sbi_alloc_trigger()
also selects the first free trigger slot irrespective of the requested
trigger type or configuration. Unsupported configurations are thus
silently dropped by the hardware while SBI reports success, where SBI
v3.0 sections 19.4 / 19.5 require SBI_ERR_NOT_SUPPORTED.

Add an optional platform device, struct sbi_dbtr_device, with a
trigger_supported(idx, tdata1, tdata2, tdata3) callback reporting
whether the trigger slot selected by idx (the tselect value) supports
a given configuration. Use it, together with the probed per-slot
type_mask, to:

  - allocate only trigger slots supporting the requested configuration
    (new dbtr_find_free_slot() helper)
  - reject unsupportable install/update requests with
    SBI_ERR_NOT_SUPPORTED
  - count only supporting slots in sbi_dbtr_num_trig() (SBI v3.0
    section 19.1)

The install path now dry-runs the allocation of the whole batch before
programming any trigger, so a partially-installed batch is never left
behind. Without a registered device, only the type matching applies (unchanged behavior).

Fixes: 97f234f15c ("lib: sbi: Introduce the SBI debug triggers extension support")
Signed-off-by: David E. Garcia Porras <david.garcia@aheadcomputing.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260727183041.258377-2-david.garcia@aheadcomputing.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-09-01 10:36:07 +05:30
David E. Garcia Porras 548518e675 lib: sbi: dbtr: return SBI_ERR_INVALID_PARAM for invalid trigger configuration
sbi_dbtr_install_trig() returns the generic SBI_ERR_FAILED when
dbtr_trigger_valid() rejects a trigger configuration (dmode or M-mode
bits set), where SBI v3.0 section 19.4 defines SBI_ERR_INVALID_PARAM
for an invalid trigger configuration entry. Return
SBI_ERR_INVALID_PARAM instead.

Fixes: 97f234f15c ("lib: sbi: Introduce the SBI debug triggers extension support")
Signed-off-by: David E. Garcia Porras <david.garcia@aheadcomputing.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260727183041.258377-4-david.garcia@aheadcomputing.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-08-31 21:12:18 +05:30
David E. Garcia Porras 3e21ee3496 lib: sbi: dbtr: return SBI_ERR_BAD_RANGE for invalid trigger index range
sbi_dbtr_read_trig() returns SBI_ERR_INVALID_PARAM for an out-of-range
trigger index range, where SBI v3.0 section 19.3 defines
SBI_ERR_BAD_RANGE. Return SBI_ERR_BAD_RANGE, matching the equivalent
range check in sbi_dbtr_update_trig().

Fixes: 324021423d ("lib: sbi: dbtr: Fix update_triggers to match SBI")
Signed-off-by: David E. Garcia Porras <david.garcia@aheadcomputing.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260727183041.258377-3-david.garcia@aheadcomputing.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-08-31 21:12:18 +05:30
Yudistira Putra f95648d395 lib: sbi: clamp sbi_ecall_get_extensions_str buffer offset
sbi_ecall_get_extensions_str() advanced offset by the nominal extension
name length without checking remaining capacity. When the caller buffer
was smaller than the concatenated extension list, offset could pass
exts_str_size, so (exts_str_size - offset) became negative and was
passed to sbi_snprintf() as a large u32, and the trailing NUL write
could step past the caller buffer.

The helper can write beyond a caller-provided destination when the
registered extension list exceeds the supplied capacity.

Mirror the guard already used by sbi_hart_get_extensions_str(): stop
appending when the next name would not fit. Add an SBIUNIT regression
that registers several extensions into a 16-byte buffer with a redzone
and verifies no out-of-bounds write.

Closes: https://github.com/riscv-software-src/opensbi/issues/416
Signed-off-by: Yudistira Putra <pyudistira519@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260719101125.190314-1-pyudistira519@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-08-31 18:08:50 +05:30
Xiang W 4e79fd7de5 platform: generic: sophgo: Move SG2042 timer memregion workaround
Commit 4813a20420 ("lib: sbi_init: Call hart init and timer init
before platform early init") reordered the cold/warm boot sequence so
that sbi_timer_init() runs before sbi_platform_early_init().

The SG2042 platform workaround that merges the 16 separate timer
regions into a single domain memregion was previously performed in
early_init().  After the reordering the MTIMER driver therefore adds
the individual regions first, defeating the purpose of the combined
region (and wasting PMP entries).

Move the addition of the combined memregion into extensions_init(),
which is invoked from sbi_hart_init() and consequently still executes
before sbi_timer_init().

Signed-off-by: Han Gao <gaohan@iscas.ac.cn>
Signed-off-by: Xiang W <wangxiang@iscas.ac.cn>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260721150844.741606-1-wangxiang@iscas.ac.cn
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-08-20 20:46:25 +05:30
Xiang W f465413402 lib: sbi: Allow platforms to override local TLB operations
Some T-Head based processors, for example the Sophgo SG2044, have a
JTLB errata that requires special handling of certain TLB maintenance
instructions (sfence.vma).

Introduce a sbi_tlb_local_operations structure so platforms can provide
custom local TLB flush implementations. Use it to implement the JTLB
workaround on affected SoCs (currently Sophgo SG2044).

Signed-off-by: Xiang W <wangxiang@iscas.ac.cn>
Signed-off-by: Han Gao <gaohan@iscas.ac.cn>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260617112925.1144190-2-wangxiang@iscas.ac.cn
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-08-20 20:30:48 +05:30
Michael Ellerman 65be0e37c4 Makefile: Support make -s to silence the build
Add support for silencing the build with make -s, which means nothing is
printed unless there is an error. Similar to the way Linux does it.

Signed-off-by: Michael Ellerman <mpe@kernel.org>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260622-upstream-v1-1-792e1847e96e@kernel.org
Signed-off-by: Anup Patel <anup@brainfault.org>
2026-08-20 20:16:42 +05:30