Smaug: Add NVDEC and TSEC carveouts
The NV security team requested that coreboot allocate the NVDEC and TSEC carveouts. Added code to set up NVDEC (1 region, 1MB) and TSEC (2 regions, splitting 2MB), and set their lock bits. Kernel/trusted code should be able to use the regions now. Note that this change sets the UNLOCKED bit in Carveout1Cfg0 and Carveout4Cfg0/5Cfg0 (bit 1) to 0 in the BCT .inc files (both 3GB and 4GB BCTs) so that the BOMs can be written. Any future revisions to these BCT files should take this into account. BUG=None BRANCH=None TEST=Built and booted on my P5 A44. Saw the carveout regions in the boot spew, and CBMEM living just below the last region (TSEC). Dumped the MC GeneralizedCarveoutX registers and verified their values (same as BCT, with only BOM/CFG0 changed). Signed-off-by: Patrick Georgi <patrick@georgi-clan.de> Original-Commit-Id: a34b0772cd721193640b322768ce5fcbb4624f23 Original-Change-Id: I2abc872fa1cc4ea669409ffc9f2e66dbbc4efcd0 Original-Signed-off-by: Tom Warren <twarren@nvidia.com> Original-Reviewed-on: https://chromium-review.googlesource.com/290452 Original-Reviewed-by: Furquan Shaikh <furquan@chromium.org> Original-(cherry picked from commit f3bbf25397db4d17044e9cfd135ecf73df0ffa60) Original-Reviewed-on: https://chromium-review.googlesource.com/291081 Original-Commit-Queue: Furquan Shaikh <furquan@chromium.org> Original-Trybot-Ready: Furquan Shaikh <furquan@chromium.org> Original-Tested-by: Furquan Shaikh <furquan@chromium.org> Change-Id: I924dfdae7b7c9b877cb1c93fd94f0ef98b728ac5 Reviewed-on: http://review.coreboot.org/11381 Tested-by: build bot (Jenkins) Reviewed-by: Stefan Reinauer <stefan.reinauer@coreboot.org>
This commit is contained in:
		
				
					committed by
					
						 Patrick Georgi
						Patrick Georgi
					
				
			
			
				
	
			
			
			
						parent
						
							84fb0bfdbb
						
					
				
				
					commit
					0bdb88b106
				
			| @@ -450,7 +450,7 @@ | |||||||
|   .McGeneralizedCarveout4ForceInternalAccess2 = 0x00000000, |   .McGeneralizedCarveout4ForceInternalAccess2 = 0x00000000, | ||||||
|   .McGeneralizedCarveout4ForceInternalAccess3 = 0x00000000, |   .McGeneralizedCarveout4ForceInternalAccess3 = 0x00000000, | ||||||
|   .McGeneralizedCarveout4ForceInternalAccess4 = 0x00000000, |   .McGeneralizedCarveout4ForceInternalAccess4 = 0x00000000, | ||||||
|   .McGeneralizedCarveout4Cfg0               = 0x04002442, |   .McGeneralizedCarveout4Cfg0               = 0x04002440, | ||||||
|   .McGeneralizedCarveout5Bom                = 0x00000000, |   .McGeneralizedCarveout5Bom                = 0x00000000, | ||||||
|   .McGeneralizedCarveout5BomHi              = 0x00000000, |   .McGeneralizedCarveout5BomHi              = 0x00000000, | ||||||
|   .McGeneralizedCarveout5Size128kb          = 0x00000008, |   .McGeneralizedCarveout5Size128kb          = 0x00000008, | ||||||
| @@ -464,7 +464,7 @@ | |||||||
|   .McGeneralizedCarveout5ForceInternalAccess2 = 0x00000000, |   .McGeneralizedCarveout5ForceInternalAccess2 = 0x00000000, | ||||||
|   .McGeneralizedCarveout5ForceInternalAccess3 = 0x00000000, |   .McGeneralizedCarveout5ForceInternalAccess3 = 0x00000000, | ||||||
|   .McGeneralizedCarveout5ForceInternalAccess4 = 0x00000000, |   .McGeneralizedCarveout5ForceInternalAccess4 = 0x00000000, | ||||||
|   .McGeneralizedCarveout5Cfg0               = 0x04002c42, |   .McGeneralizedCarveout5Cfg0               = 0x04002c40, | ||||||
|   .EmcCaTrainingEnable                      = 0x00000000, |   .EmcCaTrainingEnable                      = 0x00000000, | ||||||
|   .SwizzleRankByteEncode                    = 0x0000002e, |   .SwizzleRankByteEncode                    = 0x0000002e, | ||||||
|   .BootRomPatchControl                      = 0x00000000, |   .BootRomPatchControl                      = 0x00000000, | ||||||
|   | |||||||
| @@ -450,7 +450,7 @@ | |||||||
|   .McGeneralizedCarveout4ForceInternalAccess2 = 0x00000000, |   .McGeneralizedCarveout4ForceInternalAccess2 = 0x00000000, | ||||||
|   .McGeneralizedCarveout4ForceInternalAccess3 = 0x00000000, |   .McGeneralizedCarveout4ForceInternalAccess3 = 0x00000000, | ||||||
|   .McGeneralizedCarveout4ForceInternalAccess4 = 0x00000000, |   .McGeneralizedCarveout4ForceInternalAccess4 = 0x00000000, | ||||||
|   .McGeneralizedCarveout4Cfg0               = 0x04002442, |   .McGeneralizedCarveout4Cfg0               = 0x04002440, | ||||||
|   .McGeneralizedCarveout5Bom                = 0x00000000, |   .McGeneralizedCarveout5Bom                = 0x00000000, | ||||||
|   .McGeneralizedCarveout5BomHi              = 0x00000000, |   .McGeneralizedCarveout5BomHi              = 0x00000000, | ||||||
|   .McGeneralizedCarveout5Size128kb          = 0x00000008, |   .McGeneralizedCarveout5Size128kb          = 0x00000008, | ||||||
| @@ -464,7 +464,7 @@ | |||||||
|   .McGeneralizedCarveout5ForceInternalAccess2 = 0x00000000, |   .McGeneralizedCarveout5ForceInternalAccess2 = 0x00000000, | ||||||
|   .McGeneralizedCarveout5ForceInternalAccess3 = 0x00000000, |   .McGeneralizedCarveout5ForceInternalAccess3 = 0x00000000, | ||||||
|   .McGeneralizedCarveout5ForceInternalAccess4 = 0x00000000, |   .McGeneralizedCarveout5ForceInternalAccess4 = 0x00000000, | ||||||
|   .McGeneralizedCarveout5Cfg0               = 0x04002c42, |   .McGeneralizedCarveout5Cfg0               = 0x04002c40, | ||||||
|   .EmcCaTrainingEnable                      = 0x00000000, |   .EmcCaTrainingEnable                      = 0x00000000, | ||||||
|   .SwizzleRankByteEncode                    = 0x0000002e, |   .SwizzleRankByteEncode                    = 0x0000002e, | ||||||
|   .BootRomPatchControl                      = 0x00000000, |   .BootRomPatchControl                      = 0x00000000, | ||||||
|   | |||||||
| @@ -106,6 +106,31 @@ void carveout_range(int id, uintptr_t *base_mib, size_t *size_mib) | |||||||
| 					read32(&mc->security_carveout2_bom_hi), | 					read32(&mc->security_carveout2_bom_hi), | ||||||
| 					region_size_mb); | 					region_size_mb); | ||||||
| 		break; | 		break; | ||||||
|  | 	case CARVEOUT_NVDEC: | ||||||
|  | 		/* These carveout regs use 128KB granularity - convert to MB */ | ||||||
|  | 		region_size_mb = DIV_ROUND_UP(read32(&mc->security_carveout1_size_128kb), 8); | ||||||
|  |  | ||||||
|  | 		/* BOM address set in nvdec_region_init, below */ | ||||||
|  | 		carveout_from_regs(base_mib, size_mib, | ||||||
|  | 					read32(&mc->security_carveout1_bom), | ||||||
|  | 					read32(&mc->security_carveout1_bom_hi), | ||||||
|  | 					region_size_mb); | ||||||
|  | 		break; | ||||||
|  | 	case CARVEOUT_TSEC: | ||||||
|  | 		/* These carveout regs use 128KB granularity - convert to MB */ | ||||||
|  | 		region_size_mb = DIV_ROUND_UP(read32(&mc->security_carveout4_size_128kb), 8); | ||||||
|  |  | ||||||
|  | 		/* BOM address set in tsec_region_init, below. | ||||||
|  | 		 * Since the TSEC region consumes 2 carveouts, and is | ||||||
|  | 		 * expected to be split evenly between the two, size_mib | ||||||
|  | 		 * is doubled here. | ||||||
|  | 		 */ | ||||||
|  | 		region_size_mb *= 2; | ||||||
|  | 		carveout_from_regs(base_mib, size_mib, | ||||||
|  | 					read32(&mc->security_carveout4_bom), | ||||||
|  | 					read32(&mc->security_carveout4_bom_hi), | ||||||
|  | 					region_size_mb); | ||||||
|  | 		break; | ||||||
| 	default: | 	default: | ||||||
| 		break; | 		break; | ||||||
| 	} | 	} | ||||||
| @@ -182,7 +207,6 @@ static void memory_in_range(uintptr_t *base_mib, uintptr_t *end_mib, | |||||||
| 			continue; | 			continue; | ||||||
|  |  | ||||||
| 		carveout_range(i, &carveout_base, &carveout_size); | 		carveout_range(i, &carveout_base, &carveout_size); | ||||||
|  |  | ||||||
| 		if (carveout_size == 0) | 		if (carveout_size == 0) | ||||||
| 			continue; | 			continue; | ||||||
|  |  | ||||||
| @@ -281,3 +305,45 @@ void gpu_region_init(void) | |||||||
| 	/* Set the locked bit. This will lock out any other writes! */ | 	/* Set the locked bit. This will lock out any other writes! */ | ||||||
| 	setbits_le32(&mc->security_carveout3_cfg0, MC_SECURITY_CARVEOUT_LOCKED); | 	setbits_le32(&mc->security_carveout3_cfg0, MC_SECURITY_CARVEOUT_LOCKED); | ||||||
| } | } | ||||||
|  |  | ||||||
|  | void nvdec_region_init(void) | ||||||
|  | { | ||||||
|  | 	struct tegra_mc_regs * const mc = (void *)(uintptr_t)TEGRA_MC_BASE; | ||||||
|  | 	uintptr_t nvdec_base_mib = 0, end = 4096; | ||||||
|  | 	size_t nvdec_size_mib = NVDEC_CARVEOUT_SIZE_MB; | ||||||
|  |  | ||||||
|  | 	/* Get memory layout below 4GiB */ | ||||||
|  | 	memory_in_range(&nvdec_base_mib, &end, CARVEOUT_NVDEC); | ||||||
|  | 	nvdec_base_mib = end - nvdec_size_mib; | ||||||
|  |  | ||||||
|  | 	/* Set the carveout1 base address. Everything else has been set in the BCT cfg/inc */ | ||||||
|  | 	write32(&mc->security_carveout1_bom, nvdec_base_mib << 20); | ||||||
|  | 	write32(&mc->security_carveout1_bom_hi, 0); | ||||||
|  |  | ||||||
|  | 	/* Set the locked bit. This will lock out any other writes! */ | ||||||
|  | 	setbits_le32(&mc->security_carveout1_cfg0, MC_SECURITY_CARVEOUT_LOCKED); | ||||||
|  | } | ||||||
|  |  | ||||||
|  | void tsec_region_init(void) | ||||||
|  | { | ||||||
|  | 	struct tegra_mc_regs * const mc = (void *)(uintptr_t)TEGRA_MC_BASE; | ||||||
|  | 	uintptr_t tsec_base_mib = 0, end = 4096; | ||||||
|  | 	size_t tsec_size_mib = TSEC_CARVEOUT_SIZE_MB; | ||||||
|  |  | ||||||
|  | 	/* Get memory layout below 4GiB */ | ||||||
|  | 	memory_in_range(&tsec_base_mib, &end, CARVEOUT_TSEC); | ||||||
|  | 	tsec_base_mib = end - tsec_size_mib; | ||||||
|  |  | ||||||
|  | 	/* | ||||||
|  | 	 * Set the carveout4/5 base address. Everything else has been set in the BCT cfg/inc | ||||||
|  | 	 * Note that the TSEC range is split evenly between the 2 carveouts (i.e. 1MB each) | ||||||
|  | 	 */ | ||||||
|  | 	write32(&mc->security_carveout4_bom, tsec_base_mib << 20); | ||||||
|  | 	write32(&mc->security_carveout4_bom_hi, 0); | ||||||
|  | 	write32(&mc->security_carveout5_bom, (tsec_base_mib + (TSEC_CARVEOUT_SIZE_MB / 2)) << 20); | ||||||
|  | 	write32(&mc->security_carveout5_bom_hi, 0); | ||||||
|  |  | ||||||
|  | 	/* Set the locked bit. This will lock out any other writes! */ | ||||||
|  | 	setbits_le32(&mc->security_carveout4_cfg0, MC_SECURITY_CARVEOUT_LOCKED); | ||||||
|  | 	setbits_le32(&mc->security_carveout5_cfg0, MC_SECURITY_CARVEOUT_LOCKED); | ||||||
|  | } | ||||||
|   | |||||||
| @@ -104,7 +104,9 @@ enum { | |||||||
| 	TEGRA_I2C_BASE_COUNT = 6, | 	TEGRA_I2C_BASE_COUNT = 6, | ||||||
| }; | }; | ||||||
|  |  | ||||||
| #define GPU_CARVEOUT_SIZE_MB            1 | #define GPU_CARVEOUT_SIZE_MB		1 | ||||||
|  | #define NVDEC_CARVEOUT_SIZE_MB		1 | ||||||
|  | #define TSEC_CARVEOUT_SIZE_MB		2 | ||||||
|  |  | ||||||
| /* Return total size of DRAM memory configured on the platform. */ | /* Return total size of DRAM memory configured on the platform. */ | ||||||
| int sdram_size_mb(void); | int sdram_size_mb(void); | ||||||
| @@ -119,6 +121,8 @@ enum { | |||||||
| 	CARVEOUT_MTS, | 	CARVEOUT_MTS, | ||||||
| 	CARVEOUT_VPR, | 	CARVEOUT_VPR, | ||||||
| 	CARVEOUT_GPU, | 	CARVEOUT_GPU, | ||||||
|  | 	CARVEOUT_NVDEC, | ||||||
|  | 	CARVEOUT_TSEC, | ||||||
| 	CARVEOUT_NUM, | 	CARVEOUT_NUM, | ||||||
| }; | }; | ||||||
|  |  | ||||||
| @@ -142,5 +146,7 @@ void mainboard_add_memory_ranges(struct memranges *map); | |||||||
|  */ |  */ | ||||||
| void trustzone_region_init(void); | void trustzone_region_init(void); | ||||||
| void gpu_region_init(void); | void gpu_region_init(void); | ||||||
|  | void nvdec_region_init(void); | ||||||
|  | void tsec_region_init(void); | ||||||
|  |  | ||||||
| #endif /* __SOC_NVIDIA_TEGRA210_INCLUDE_SOC_ADDRESS_MAP_H__ */ | #endif /* __SOC_NVIDIA_TEGRA210_INCLUDE_SOC_ADDRESS_MAP_H__ */ | ||||||
|   | |||||||
| @@ -67,7 +67,10 @@ void romstage(void) | |||||||
| 	 */ | 	 */ | ||||||
| 	trustzone_region_init(); | 	trustzone_region_init(); | ||||||
|  |  | ||||||
|  | 	/* Now do various other carveouts */ | ||||||
| 	gpu_region_init(); | 	gpu_region_init(); | ||||||
|  | 	nvdec_region_init(); | ||||||
|  | 	tsec_region_init(); | ||||||
|  |  | ||||||
| 	/* | 	/* | ||||||
| 	 * When romstage is running it's always on the reboot path -- never a | 	 * When romstage is running it's always on the reboot path -- never a | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user