Commit graph

1569 commits

Author SHA1 Message Date
Axel Heider
32daaa1932 remove Arch_finaliseInterrupt()
The function Arch_finaliseInterrupt() is empty now and can be removed as
it serves no purpose any longer. There has never been a guarantee that
it gets only called due to kernel entry caused by an interrupt. Instead,
getActiveIRQ() is called in various places of the kernel to check if
there is a pending interrupt. There is a guarantee that the generic
kernel code calls ackInterrupt() within the same kernel entry call
path eventually, when it has finished processing this interrupt. Any
architecture or platform specific cleanup can be done there is this is
necessary.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-10-01 15:18:51 +10:00
Axel Heider
f0e3a22e09 pc99: use ackInterrupt()
PC99 is the only platform that uses Arch_finaliseInterrupt() instead of
ackInterrupt(). There seem no reason for this, thus the code is moved
from Arch_finaliseInterrupt() to ackInterrupt() now.
Arch_finaliseInterrupt() is empty now, but still kept, because it is
part of the proofs and provides a hook that might be useful one day.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-10-01 15:18:51 +10:00
Kent McLeod
a94d90598f aarch64,hyp: Move PPTR_BASE down to 0x8000000000
On aarch64 in EL2, there aren't any addresses after 2^48 and so the
any kernel device untypeds that have very large physical addresses could
potentially move into an invalid address range when translated to a
Kernel window PPTR address when being stored in a cap slot. The kernel
in EL2 doesn't need to share its address space with user level and so we
can make the kernel window start low enough that we can't get overflows.
We start from the second entry in the top level page table so that we
don't conflict with any setup code running in the lowest 512GiB of
virtual addresses.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-10-01 12:55:18 +10:00
Kent McLeod
4d4dfdc9c9 CONFIG_PRINTING, CONFIG_DEBUG_BUILD: Make compile
CONFIG_DEBUG_BUILD and CONFIG_PRINTING are different config options that
can be used independently from each other. CONFIG_PRINTING controls the
backend of kernel print functions while CONFIG_DEBUG_BUILD controls
other kernel debug features.
Note that CONFIG_VERIFICATION_BUILD is the config option that controls
whether any of these options can be used.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-30 19:07:03 +10:00
Kent McLeod
9d3cbd027f armv6: Remove remaining armv6 specific features
- KernelGlobalsFrame caused the definition of seL4_GlobalsFrame which
  was a reservation at the top of the user address space on ARMv6
  platforms.
- KernelDangerousCodeInjectionOnUndefInstr was used to implement calling
  user code in kernel mode won ARMv6.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-30 18:07:19 +10:00
Kent McLeod
35fed131b0 ARMv6: Remove architecture support
Remove all support for ARMv6 architectures now that all platforms and
CPUs that use this architecture have been removed.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-30 18:07:19 +10:00
Kent McLeod
449855855d ARM11: Remove CPU support
Remove support for ARM1136JF_S ARMv6 CPU as ARMv6 support is being
removed.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-30 18:07:19 +10:00
Kent McLeod
3defbff461 Remove KZM/imx31 platform
The platform was the original verification target of seL4 over 10 years
ago and by now there doesn't appear to be any ways to obtain new
hardware.

Currently, the KZM platform is the only ARMv6 platform and supporting it
requires a few work-arounds for emulating mechanisms that newer hardware
supports. Removing this platform also implies removing armv6 support
soon.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-30 18:07:19 +10:00
Axel Heider
ee7a52d927 move type checks to mode/types.h
Moving the type checks avoid the need for conditional compilation. This
also allows simplifying some include file dependencies.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-28 09:20:01 +10:00
Axel Heider
30d4fe1937 remove unnecessary brackets
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-27 23:09:09 +10:00
Axel Heider
98f28676b2 trivial: remove superfluous empty lines
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-27 23:09:09 +10:00
Axel Heider
b21faf8a9c risc-v: clenaup U54/U74 PLIC handling code
- Use SMP_TERNARY() macro.
- Rename get_hart_id() to plic_get_current_hart_id(), as this is just a
  helper function for the other PLIC code in this file.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-09-26 11:31:51 +10:00
Axel Heider
14314983a6 risc-v: clarify PLIC is for SiFive U54/U74
RISC-V defines the concept of a PLIC, but leaves the details open. The
driver is for the PLIC of the SiFive U54/U74 SOC, which is used on
the HiFive Unleashed/Unmatched and Polarfire board.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-09-26 11:31:51 +10:00
Axel Heider
1400a8a8a2 risc-v: improve PLIC driver API and documentation
- describe PLIC behavior and corner cases.
- provide a common header file for the API.
- add a dummy PLIC driver for spike.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-09-26 11:31:51 +10:00
Axel Heider
624786b95f risc-v: move SIE access wrappers to generic code
- Move CSR SIE access wrappers to generic code.
- Move CSR SIE/SIP bit constants to header file.
- Rename CSR SIE/SIP bit constants to use the names from the RISC-V
  specification.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-09-26 11:31:51 +10:00
Axel Heider
c2bf323d0a boot/risc-v: remove unused MODE_RESERVED
MODE_RESERVED is unused on RISC-V, so remove it from the code base. It
can be brought back when needed based on the state of the ARM
implementation, which has been clean up to remove global dependencies.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-26 09:50:53 +10:00
Axel Heider
699a4cd803 boot: define NUM_RESERVED_REGIONS
- define NUM_RESERVED_REGIONS to align ARM and RSIC-V code
- add runtime checks to catch errors. These checks can't be static or
  use assert(), as the parameters are passed by a kernel loader. They
  must be considered dynamic and can potentially change any time out
  of the kernel's control.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-26 09:50:53 +10:00
Axel Heider
415fb2090c boot/arm: add missing includes
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-26 09:50:53 +10:00
Axel Heider
d76f9f93a6 boot: improve comments
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-26 09:50:53 +10:00
Indan Zupancic
f3addaa0fb Trivial: Remove now incorrect comment
Signed-off-by: Indan Zupancic <Indan.Zupancic@mep-info.com>
2021-09-10 20:48:04 +10:00
Axel Heider
6b8cbc96d1 risc-v: add comment about SBI constants
Explan the origin of the SBI constants.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-09-07 20:09:26 +10:00
Axel Heider
f8054d41dc risc-v: fix signature for Arch_setTLSRegister()
Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-09-07 15:56:31 +10:00
Axel Heider
2f18705be0 boot: use helper variable to simplify code
- Improve comments about macros
- use helper variable to simplify code

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-06 09:22:04 +10:00
Axel Heider
dbda7046b9 Clarify assumptions about boot info frame size
- Improve comments
- allocate BI_FRAME_SIZE_BITS and not seL4_PageBits

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-06 09:22:04 +10:00
Kent McLeod
c7d5bb0ed4 libsel4: Fix name for AARCH64_VSPACE_S2_START_L1
CONFIG_AARCH64_VSPACE_S2_START_L1 has the correct namespace for a kernel
config option.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-06 08:08:54 +10:00
Kent McLeod
b6de9db07a libsel4: Fix Config name for ENABLE_SMP_SUPPORT
CONFIG_ENABLE_SMP_SUPPORT has the correct namespace for a kernel config
option.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-06 08:08:54 +10:00
Kent McLeod
e4262a90d2 arm,gic: GICv3 only supports max 16 list registers
Update GIC_VCPU_MAX_NUM_LR constant to reflect that only 16 list
registers are supported on GICv3. The kernel still reads the actual
number of supported list registers out of the GICH_VTR register so the
kernel would still do the right thing before this change.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-09-03 10:23:06 +10:00
Ben Leslie
0c6229d598 Add support for GICv3 virtualization
This adds sufficient kernel support for the GICv3 interrupt controller
to be used in a virtualization context on aarch64.

This set of changes has some limitations, however it is still an
improvement on the status quo.

Limitations:

1: This only provides support for aarch64. Anyone wanting support
for aarch32 + GICv3 + virtualization would need to add additional
code.

2: This code only supports 32 priority levels. Support for more
than 32 priority requires changing the get/set_gic_vcpu_ctrl_apr
interface. This is feasible, but requires a more invasive set of
changes. 32 priority levels has been shown to be sufficient in
practise.

Impacts on verification:

This set of changes should only impact Aarch64 Hypervisor
configurations. This is not yet verified so should not have
an impact on verification.

Level of testing:

This has been tested on an iMX8QXP based board. Testing
has at this point in time been limited to a single virtual
machine.

Note: support for this board is not yet upstrea, but is
currently being prepared.

Explanation of changes:

Ideally a new config item would not be required and this
could be driven purely by DTS and hardware.yml configuration.
However, the structures.bf requires changes. This can only
deal with config.h header files, not other more complex
header files. As such it was necessary to introduce a config
item which can be used for this purpose.

The appropriate platforms (as determined by examination of
DTS files) have been updated with the appropriate config
setting. This config setting only has any relevance if
hypervisor mode is already enabled, so should not cause
any difficulty for existing code or configuration.

Note: No testing has been performed on the updated
platforms.

There may be alternative factorings of this, which could
be considered in future work.

Signed-off-by: Ben Leslie <benno@brkawy.com>
2021-09-03 10:23:06 +10:00
Axel Heider
f46aac30b8 boot: remove ndks_boot.slot_pos_max
- The field 'slot_pos_max' from 'ndks_boot' is not needed, the value
  stored there is the constant BIT(CONFIG_ROOT_CNODE_SIZE_BITS).
- Improve the error message if the limit has been reached

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-09-02 08:44:24 +10:00
Axel Heider
f8c3ad0c58 add comment about empty Arch_finaliseInterrupt()
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-31 10:53:31 +10:00
Axel Heider
54ae03f951 trivial: improve style for code and comments
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-31 10:53:31 +10:00
Axel Heider
da0aad0330 make kernel device frame handling more generic
The structure actually describes kernel frames and not kernel devices.
In most of the cases a peripherals will fit into one page, but some can
need more pages. On some platform there are no kernel devices at all.
Provides the macro NUM_KERNEL_DEVICE_FRAMES as simple way to find out if
there are mapping that hides the corner cases. This eventually allows
implementing a generic handling even on RISC-V without much overhead, so
the hack for HiFive/Spike can be removed.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-27 21:15:11 +10:00
Axel Heider
fc72f5e957 trivial: remove trailing empty lines
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-27 21:15:11 +10:00
Axel Heider
3220f3016f trivial: add empty line after include guard
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-27 21:15:11 +10:00
Axel Heider
c72ecc7dd8 boot: reduce amount of helper functions
The python code generator ensures avail_p_regs always exists.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-24 16:14:26 +10:00
Axel Heider
b64e2deb3a boot: remove obsolete prototypes
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-24 16:14:26 +10:00
Gerwin Klein
02ddcd110a mcs: Remove domain time check from preemptionPoint
This removes the operations that trigger a reschedule or reprogram the
timer from `preemptionPoint` to ensure the relevant state updates in
the proof occur where they are easier to verify.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-24 10:22:33 +10:00
Axel Heider
d2b38a42d2 risc-v: remove unused L2 cache functions
The L2 cache handling functions were copied from the ARM code in the
initial port, but they are not used on RISC-V. Remove them from the
code base, they can be brought back if a platform has an L2 cache that
needs to be maintained.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-20 17:51:38 +10:00
Gerwin Klein
56098195f2 mcs: sc_active not always true in sc_sporadic
Turns out the invariant 17109eb8c9 refers to is hard to prove
because it is not true, and the runtime check is necessary. This
assertion fails in sel4test SCHED_CONTEXT_0003 (Basic
api_sc_bind/UnbindObject testing).

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-20 16:52:12 +10:00
Curtis Millar
17109eb8c9 mcs: Explicitly check that sporadic scs are active
Easier to check this explicitly than prove the invariant.

Signed-off-by: Curtis Millar <curtis@curtism.me>
2021-08-20 13:59:07 +10:00
Axel Heider
2075f0cded ensure assert() macro is an atom
Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-19 08:28:27 +10:00
Axel Heider
5ff8dce833 trivial: add comments about empty functions
Add a comment to clearly state the functions are empty on purpose, but
they still need to be provided to support the generic code flow.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 10:08:06 +10:00
Axel Heider
fe2d400f06 arm: remove obsolete function setInterruptMode()
The function setInterruptMode() is no longer in use, setIRQTrigger() is
used instead.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 10:08:06 +10:00
Axel Heider
b9781a0f19 trivial: remove superfluous empty lines
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 10:08:06 +10:00
Axel Heider
74b81ede92 boot: make functions static
The functions insert_region() and create_rootserver_objects() are not
used outside of boot.c, so there is no reason to make it publicly
available.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 08:55:48 +10:00
Axel Heider
acd693db17 prefer macro CURRENT_CPU_INDEX()
Replace the macro SMP_TERNARY(getCurrentCPUIndex(), 0) by the much
simpler macro CURRENT_CPU_INDEX() that does the same.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-17 18:19:37 +10:00
Axel Heider
1e3c8011d6 define macro SEL4_WORD_CONST()
CURRENT_CPU_INDEX() is supported to return a word_t. The C parser from
the verification toolchain requires declaring word_t constants without
casting integer values to word_t.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-17 18:19:37 +10:00
Gerwin Klein
10d6cc0ae9 arm: flush cache to RAM on retype reset
This fixes a correctness and security issue where uncached user
mappings might see old data from before the clearMemory operation.

See also the discussion on GitHub issue #481

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-16 16:10:58 +10:00
Axel Heider
16b82ecdb1 trivial: fix typos in comments
Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-13 09:05:42 +10:00
Axel Heider
89a5b8fd31 boot: move create_untypeds() to generic code
Also merge create_device_untypeds() and create_kernel_untypeds() into
create_untypeds() to simplify the code.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-30 08:46:12 +10:00