Commit graph

4001 commits

Author SHA1 Message Date
Axel Heider
7d37990465 use ULL_CONST() for timer value
Enforce the maximum possible integer size in the generated C headers
instead of doing this in CMake.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-21 10:46:54 +10:00
Axel Heider
852ead2e2c merge TIMER_FREQUENCY definitions
There is no need for separate definitions, they define the same value.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-21 10:46:54 +10:00
Axel Heider
d2b38a42d2 risc-v: remove unused L2 cache functions
The L2 cache handling functions were copied from the ARM code in the
initial port, but they are not used on RISC-V. Remove them from the
code base, they can be brought back if a platform has an L2 cache that
needs to be maintained.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-20 17:51:38 +10:00
Gerwin Klein
56098195f2 mcs: sc_active not always true in sc_sporadic
Turns out the invariant 17109eb8c9 refers to is hard to prove
because it is not true, and the runtime check is necessary. This
assertion fails in sel4test SCHED_CONTEXT_0003 (Basic
api_sc_bind/UnbindObject testing).

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-20 16:52:12 +10:00
Miki Tanaka
dc9ec49cf2 move scSporadic update
- in decodeSchedControl_ConfigureFlags
- a minor tweak to aid verification.

Signed-off-by: Miki Tanaka <miki.tanaka@data61.csiro.au>
2021-08-20 14:35:15 +10:00
Curtis Millar
17109eb8c9 mcs: Explicitly check that sporadic scs are active
Easier to check this explicitly than prove the invariant.

Signed-off-by: Curtis Millar <curtis@curtism.me>
2021-08-20 13:59:07 +10:00
Gerwin Klein
43b2029d02 github: clearer top-level name for compile action
Previous "Kernel" showed up for the badge and main checks group, which
is not very informative.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-20 13:42:48 +10:00
Gerwin Klein
cc32744ff3 README: adjust CI badge for seL4test
The badge now refers to the combined simulation + hw build + hw test +
deployment workflow.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-20 13:42:48 +10:00
Gerwin Klein
76532c1eae github: more fine-grained concurrency groups
Previously the `concurrency` statement also prevented concurrency
within the build matrix which we do not want.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-20 13:42:48 +10:00
Gerwin Klein
acbc4e6ddf github: separate sel4test for deployment on master
This commit pulls out a separate workflow for sel4test (simulation +
hardware runs) on pushes to master, and deploys a new default.xml to
sel4test-manifest when the test is successful.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-20 12:05:03 +10:00
Axel Heider
7e069b757e boot: improve comments
- Explain why restore_user_context() is not called in init_kernel()
directly.
- describe the parameters that init_kernel() expects.

Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-20 07:32:24 +10:00
Axel Heider
9ed91573ad boot: remove unsed references
Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-20 07:32:24 +10:00
Kent McLeod
b05d681621 cmake: Add seL4Config.cmake include CMakeLists.txt
seL4Config.cmake is responsible for generating a valid
CMAKE_TOOLCHAIN_FILE and setting up platform config options at the start
of the build. The CMAKE_TOOLCHAIN_FILE variable has to be set before the
first cmake `project()` function is processed to take effect.
Previously this file was required to be imported in a CMake script
before the kernel's CMakeLists.txt could be processed. This prevented
the main CMakeLists.txt file from being used without an additional
configuration file:
cmake -G Ninja -C ../configs/ARM_verified.cmake ../

Now it is possible to do:
cmake -G Ninja -DKernelPlatform=imx6 -DKernelARMPlatform=sabre ../

This should make it easier to invoke CMake for building kernel
configurations from other build environments.

Because this file is now imported in the Kernel's CMakeLists.txt
context, there is no longer a requirement to save all the intermediate
settings into the cache and then read them out again.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-08-19 09:24:31 +10:00
Gerwin Klein
82e7a0251d git hw test: enable zynqmp
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-19 08:46:24 +10:00
Axel Heider
2075f0cded ensure assert() macro is an atom
Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-19 08:28:27 +10:00
Gerwin Klein
dbab25c8d3 github: deploy verification-manifest on preprocess
Automatically keep verification-manifest in sync with
preprocess-equivalent changes.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-18 16:58:57 +10:00
Axel Heider
9c1508d8d9 Enforce '-fno-common'
GCC < 10 and clang < 11 put uninitialized global variables into a
'COMMON' section unless '-fno-common' is specified. The linker will put
anything from 'COMMON' as the end of the '.bss' it nothing else is
specified in the linker script. Besides making the variable placement
look odd, this also tends to waste a page because we puts large aligned
block at the end. Eventually, GCC 10 and clang 11 made '-fno-common'
the default, see
- https://gcc.gnu.org/gcc-10/changes.html
- https://releases.llvm.org/11.0.0/tools/clang/docs/ReleaseNotes.html

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 14:41:59 +10:00
Axel Heider
5ff8dce833 trivial: add comments about empty functions
Add a comment to clearly state the functions are empty on purpose, but
they still need to be provided to support the generic code flow.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 10:08:06 +10:00
Axel Heider
fe2d400f06 arm: remove obsolete function setInterruptMode()
The function setInterruptMode() is no longer in use, setIRQTrigger() is
used instead.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 10:08:06 +10:00
Axel Heider
b9781a0f19 trivial: remove superfluous empty lines
Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 10:08:06 +10:00
Axel Heider
248b9639ec boot: use SEL4_PRIx_word instead of 'lx'
All architectures define paddr_t as word_t, but the actual definition of
word_t is specific to every architecture's word size. For this reason, a
dedicated format specifier for word_t has been introduced, it hides
all these detail.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 09:42:08 +10:00
Axel Heider
74b81ede92 boot: make functions static
The functions insert_region() and create_rootserver_objects() are not
used outside of boot.c, so there is no reason to make it publicly
available.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-18 08:55:48 +10:00
Axel Heider
d57b2cd0f8 Ensure ksKernelEntry.core is always set
The field ksKernelEntry.core always exists, ensure it is properly set on
non-SMP configurations also.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-17 18:19:37 +10:00
Axel Heider
acd693db17 prefer macro CURRENT_CPU_INDEX()
Replace the macro SMP_TERNARY(getCurrentCPUIndex(), 0) by the much
simpler macro CURRENT_CPU_INDEX() that does the same.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-17 18:19:37 +10:00
Axel Heider
1e3c8011d6 define macro SEL4_WORD_CONST()
CURRENT_CPU_INDEX() is supported to return a word_t. The C parser from
the verification toolchain requires declaring word_t constants without
casting integer values to word_t.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-17 18:19:37 +10:00
Gerwin Klein
10d6cc0ae9 arm: flush cache to RAM on retype reset
This fixes a correctness and security issue where uncached user
mappings might see old data from before the clearMemory operation.

See also the discussion on GitHub issue #481

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-16 16:10:58 +10:00
Gerwin Klein
697430abf0 github: enable hw test for imx8mm
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-16 15:56:45 +10:00
Gerwin Klein
7f08674bb7 github: add TX2 to hardware test
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-13 18:16:54 +10:00
Axel Heider
16b82ecdb1 trivial: fix typos in comments
Signed-off-by: Axel Heider <axel.heider@hensoldt-cyber.de>
2021-08-13 09:05:42 +10:00
Axel Heider
9416cd8f97 clarify that parameter is initial thread's region
Align the parameter naming within each architecture's file and also
across architectures.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-08-13 08:31:26 +10:00
Gerwin Klein
1324734ffb github: adjust event name
Trigger moved to pull_request_target, so event name is changing as well.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-12 18:24:07 +10:00
Gerwin Klein
2e59eeae7d github: remove test branch trigger
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-12 18:24:07 +10:00
Gerwin Klein
f975153948 github/hw: rpi3 power-up not fully stable yet
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-10 17:54:24 +10:00
Gerwin Klein
934fc2642b github: split off more x86 sessions
More x86 boards have become available, so we can have one session
per mode and compiler.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-10 17:54:24 +10:00
Gerwin Klein
5688e6e9f6 trivial: fix link
The link will probably go back to .html when the website is finished,
but this commit will avoid annoying test failures in the meantime.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-10 17:54:24 +10:00
Gerwin Klein
302339fd8a for testing only
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-10 17:54:24 +10:00
Gerwin Klein
0fa13e059a github: add action for hardware test runs
This switched the action from pull_request to pull_request_target,
because we need access to secrets. GITHUB_TOKEN permissions are
downgraded to PR-like permissions, and the action needs to be triggered
manually by labelling with label 'hw-test'.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-08-10 17:54:24 +10:00
Axel Heider
89a5b8fd31 boot: move create_untypeds() to generic code
Also merge create_device_untypeds() and create_kernel_untypeds() into
create_untypeds() to simplify the code.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-30 08:46:12 +10:00
Kent McLeod
379bf5abe3 hardware_gen.py: Address some warning messages
CMake treats any text output that is generated by tools during the
configuration phase as important if it isn't part of a message(STATUS)
command. Output generated by hardware_gen.py often shows up as warnings
about device tree properties that are usually uninformative. Resolving
some of the warning conditions removes these messages for most
platforms.

- Setting kernel_size in hardware.yml to 0x1000 to handle cases where
  the kernel only needs the first page of a device that has a
  device-tree definition larger than that.
- Remove status print about each Interrupt processed as it's usually not
  useful information.
- Only process IRQs for a selected kernel device if the rule for that
  device has any interrupt queries. This prevents warnings for IRQ
  controllers that the script doesn't know how to process when it
  doesn't need to.

Signed-off-by: Kent McLeod <kent@kry10.com>
2021-07-29 16:03:01 +10:00
Gerwin Klein
d93aa01459 github: split sel4test into separate workflows
The reason is that with separate workflow files allow different
triggers. In particular, we don't want to re-run all simulations
on all `labeled` triggers, but if we explicitly skip the simulation
job for those triggers, than previous simulation runs are not
shown any more in the GitHub check status, so failed runs will be
overlooked.

This should achieve both: no unnecessary runs, and visible status.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-07-26 21:04:52 +10:00
Gerwin Klein
4cdd97c532 github: use correct label field
The trigger matched against the whole label object, not the name as
it should have.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-07-26 21:04:52 +10:00
Gerwin Klein
f1ac3d829e github sel4test: don't run on PRs to docs
Save some checking time for changes that are to docs only and
don't affect sources.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-07-26 14:58:09 +10:00
Gerwin Klein
bd9a8b2ff7 github: constrain triggers for longer builds
The previous trigger would start duplicate builds for each new
label added to a PR. This commit locks this down a bit more so
that builds only run when the trigger label is added or on other
triggers when the label is present.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-07-26 14:58:09 +10:00
Gerwin Klein
52a89f9e0f github: add action for hardware builds
The action is triggered on push to master or when the label "hw-build"
is present on pull requests.

Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-07-26 14:58:09 +10:00
Gerwin Klein
e80217f87e README: add badge for simulation test
Signed-off-by: Gerwin Klein <gerwin.klein@proofcraft.systems>
2021-07-19 14:57:10 +10:00
Axel Heider
d1a456bebd remove redundant defines
These defines are set up in the architecture specific bootinho.h.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-19 11:19:43 +10:00
Axel Heider
e20652f664 make definition for NULL generic
Make the definition for NULL generic, so it can be used in constants
that are shared by C and assembly code.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-19 10:45:20 +10:00
Axel Heider
fec1b90ef8 provide and use macro ULL_CONST()
- Provide the macro ULL_CONST() for 'unsigned long long' constants, and
  use it where applicable.
- Add a verbose explanation why the 'unsigned long long' type is used
  for time constants.

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-19 10:45:20 +10:00
Axel Heider
e27613b30f remove redundant definition of HZ_IN_KHZ
The constant HZ_IN_KHZ is defined in util.h already,

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-19 10:45:20 +10:00
Axel Heider
974458fde1 reorder and consolidate macro definitions
- Reorder the macro definitions to ensure things are define before they
  are used.
- provide a verbose explanation why the UL_CONST() macro is needed.
- make BIT() macro is defined generic by using UL_CONST().

Signed-off-by: Axel Heider <axelheider@gmx.de>
2021-07-19 10:45:20 +10:00