Commit graph

1286 commits

Author SHA1 Message Date
Anna Lyons
b358a1c59c trivial: move isSchedulable to header 2019-08-22 11:22:41 +10:00
Anna Lyons
257a62c73f mcs: explicitly use ksCurSC
- in refill_[budget|split]_check.
- This simplifies the code and the proofs.
2019-08-22 11:22:41 +10:00
Anna Lyons
ef4ba6b69a mcs: Introduce firstPhase flag to invocations
Some invocations contain two phases, and certain operations cannot be
allowed to run in the first phase as it could effect the currently
running thread and result in an invalid system state for the second
phase. This change filters those invocations, preventing them from being
used in the first phase of a two-phase, blocking system call.
2019-08-22 11:22:41 +10:00
Anna Lyons
483f0ae22f mcs: SchedControlConfigure: charge correct core
Previously this code would incorrectly call chargeBudget twice, where it
was intended to be charging a specific core.
2019-08-22 11:22:39 +10:00
Anna Lyons
4f00022f7d mcs: Use cancelIPC instead of reply_clear
- reply_clear only does half the job
- remove reply_clear no longer used
2019-08-22 11:22:39 +10:00
Anna Lyons
f103ac223d mcs: Refactor replies to solve revoke problems
Before this change, we set the replyObject in the thread state on recv
with no back pointer such that stray pointers would be left in the
thread state when a reply object was completed.

The new semantics are clearer and fix this problem by doing the
following:

- tcb->tcbReply is removed and the thread state field is always used,
  this was unneccessary duplication previously
- the thread state value is set to the reply object only when the thread
  is in BlockedOnReply or BlockedOnRecv
- the reply contains a back pointer, replyTCB, which points to that
  thread
- if a thread has its reply removed, it must be set to
  ThreadState_Inactive.
- deletion is easy in the blockedOnRecv case, we just unlink the reply
  and the tcb.
- deletion is complicated for blockedOnReply. If we are deleing a tcb,
  we remove the actual reply object and the call chain is broken. If we
  are deleting a reply, we maintain the call chain by moving the tcb to
  the next reply.
- we refactor the reply object interface to solve the above.
    * reply_clear: removes the reply from any connections (tcb, sc)
    * reply_unlink: just unlinks the tcb and reply, and sets the thread
      state to inactive
    * reply_remove: removes the reply from the call chain
    * reply_remove_tcb: removes the exact reply that a tcb is bound to,
      as we are removing that tcb. Breaks the call chain.
2019-08-22 11:22:39 +10:00
Adrian Danis
4768465027 mcs: allow kernel WCET estimate to be scaled
This configuration option allows for building images destined for
simulators, which may not simulate as fast as hardware, to still be
used.
2019-08-22 11:22:39 +10:00
Anna Lyons
2329cd81dc mcs: add seL4_SchedContext_YieldTo
Implement seL4_SchedContext_YieldTo, which allows users to manipulate
the scheduling queues up to their MCP and can be used for user level
scheduling.
2019-08-22 11:22:38 +10:00
Anna Lyons
a38e62f2f9 mcs: timeout exceptions
- Add seL4_TCB_SetTimeoutEndpoint
- implement timeout exceptions
2019-08-22 11:22:38 +10:00
Anna Lyons
c405ef53d2 mcs: install fault endpoint into tcb cnode
- seL4_TCB_Configure no longer takes a fault endpoint.
- seL4_TCB_SetSpace takes a cap in the callers cspace for the
  fault endpoint, not the target tcbs.
- seL4_TCB_SetSchedParams now also takes a fault endpoint as above.

This change installs the fault endpoint cap into the tcb cnode
first validating it.

This means either of the functions that set it will now return an error
if the cap is not either a null cap or an endpoint with send and
grant rights.

Significantly, the cap passed to the function should be in the callers
cspace, not the target tcbs.
2019-08-22 11:22:38 +10:00
Anna Lyons
106b893ee0 mcs: configurable scheduling context size
This allows users to define custom amounts of refills without
increasing the scheduling context size system wide.

also add libsel4 functions for refill size
2019-08-22 11:22:38 +10:00
Anna Lyons
96798066f6 mcs: avoid rolling back time if acted upon
Otherwise strange things can happen where threads are in the future.
2019-08-22 11:22:37 +10:00
Anna Lyons
9253704d2c mcs: update refills based on spec
This is a list of fixes that came up while working on the verification
spec for the mcs changes.

- trigger a timer tick if we are unable to split a refill
due to the refill list being full.
- make refill_ordered more useful
- pull the thread out of the scheduler before updating it
- simplify refill logic at verifications request
- Add unused to refill_sum
- Don't refill_split_check if consumed is empty
- sched_control: fix double increment bug
- sched-control: charge before reconfiguring ksCurSC
- Charge round robin threads differently

Sporadic server refill rules do not behave correctly for round robin
threads, instead, change the logic. Round robin threads have 2 refills:
current and next.
2019-08-22 11:22:37 +10:00
Rafal Kolanski
e04dbb9594 mcs: verification spec for clzll
This is required for the proofs.
2019-08-22 11:22:37 +10:00
Anna Lyons
a22cb3d102 mcs: associate scheduling context + ntfn
This commit allows scheduling contexts to be bound
to notification objects. When a passive server
receives a notification it will receive the scheduling
context from the notification. When the server
blocks the scheduling context is returned.
2019-08-22 11:22:37 +10:00
Anna Lyons
554f812da3 mcs: scheduling context donation over ipc
After this commit, threads blocked on an endpoint can recieve a
scheduling context from the thread that wakes the blocked thread.
2019-08-22 11:22:37 +10:00
Anna Lyons
5fe1890a83 mcs: order EP and NTFN queues
Previously IPC signal queues were FIFO, as of this change they are
ordered by priority (FIFO for same prio threads).
2019-08-22 11:22:35 +10:00
Anna Lyons
34c1f920b1 mcs: add periodic scheduling
This commit adds periodic scheduling with sporadic servers.
2019-08-22 11:22:35 +10:00
Anna Lyons
4db4a3b882 kzm: implement MCS timer driver
- use gpt, so we can have overflow and compare interrupts at the same
time (epit only allows compare)
- set the gpt to use the ipg_highfreq timer, as the standard ipg is too
low and breaks the timer calculations
2019-08-22 11:22:35 +10:00
Anna Lyons
ea07ad0414 omap3: implement tickless timer driver
Update the existing omap driver to implement the new tickless api.
2019-08-22 11:22:35 +10:00
Anna Lyons
bdc56112bd arm: tickless generic timer implementation
Update the generic timer to implement the MCS kernels tickless timer
driver API and update all platforms that use the arm generic timers:

    - bcm2837
    - exynos5
    - hikey
    - imx7
    - odroidc2
    - tk1
    - tx1
    - tx2
    - zynq7000

Also move the generic timer constants to machine.h to avoid a circular
dependency.
2019-08-22 11:22:35 +10:00
Anna Lyons
a7fb6b56b7 cortex-a9: tickless global timer driver
- use in sabre (imx6) and zynq7000, the two platforms that were using
  the private timer.
2019-08-22 11:22:35 +10:00
Anna Lyons
742cabf15b mcs: provide tickless api for arm timers
This does not implement the timers for any platforms, but
provides the generic arm arch, and aarch32/aarch64 infrastructure for
tickless timer drivers.
2019-08-22 11:22:34 +10:00
Anna Lyons
acfc3c5257 mcs: tickless driver for x86
Add a tickless timer driver for x86. The driver defaults to using
TSC_DEADLINE mode, but falls back to the apic if that feature is not
available.
2019-08-22 11:22:34 +10:00
Anna Lyons
7124449936 mcs: tickless scheduler implementation
This changes the budget/remaining fields in scheduling contexts
to contain timer ticks, not number of abstract sel4ticks.

seL4_SchedControl_Configure now takes microseconds, not ticks.

This commit is plat-independant - the platform and arch specific
timer code follows in later commits.
2019-08-22 11:22:34 +10:00
Anna Lyons
952134d1b8 mcs: Add a scheduling context object
This is the first part of the seL4 MCS. This commit:

    * adds a scheduling context object. Threads without scheduling
      context objects cannot be scheduled.
    * replaces tcbTimeSlice with the scheduling context object
    * adds seL4_SchedControl caps for each core
    * adds seL4_SchedControl_Configure which allows users to configure
      amount of ticks a scheduling context has, and set a core for the
      scheduling context.
    * adds seL4_SchedContext_Bind, Unbind and UnbindObject, which allows
      a tcb to be bound to a scheduling context.
2019-08-22 11:22:34 +10:00
Anna Lyons
6746428a9d arm,gicv3: implement setIRQTarget
This allows SPIs to be routed to different cores.
2019-07-30 16:49:53 +10:00
Anna Lyons
0f139e7f6e arm,gicv3: update to use virtual ppi irqs
This commit updates the gic_v3 driver to translate virtual irqs to
hardware irq numbers, which enables PPI support for SMP.
2019-07-30 16:49:53 +10:00
Anna Lyons
794aad98f1 arm,gicv3: consisent sgi/ppi checks
This commit brings the gic_v3 is_sgi and is_ppi checks in line with
gicv2 making the code more consistent.

It also removes unneccessary conditionals in the checks, as is_sgi is
always called before is_ppi so the lower bounds checks are not required.
2019-07-30 16:49:53 +10:00
Anna Lyons
0d3692ede9 arm,gicv3: use SPI_START
This removes a redundant constant to use one from the gic_common header.
2019-07-30 16:49:53 +10:00
Anna Lyons
32952cc390 arm,gic: move gic helpers to gic_common
In order to support gic_v3 SMP, move helpers from gic_v2.h to
gic_common.h
2019-07-30 16:49:53 +10:00
Anna Lyons
0b9aa61a56 arm,gic: refactor constants into gic_common.h
Move common definitions from gic_v2.h and gic_v3.h into gic_common.h
2019-07-30 16:49:53 +10:00
Anna Lyons
21888e6a95 aarch64: add missing dsb
Co-authored-by: Yanyan Shen <yanyan.shen@data61.csiro.au>
2019-07-30 16:09:09 +10:00
Anna Lyons
7d55e2174c arm: CONFIG_L1_CACHE_LINE_SIZE_BITS in cmake
Move definition of L1_CACHE_LINE_SIZE_BITS to cmake where it is set
according to the arm processor family.

This removes duplication in the hardware.h header files and makes adding
a new processor family require less lines changed.
2019-07-30 16:09:08 +10:00
Kent McLeod
7bc76e8275 gicv2: Don't translate irqInvalid into array index
This also adds a check that translating a core + irq doesn't result in
an index that is irqInvalid.
2019-07-29 13:33:02 +10:00
Kent McLeod
51ee24fd59 trivial, gic_v2: Use CURRENT_CPU_INDEX() 2019-07-29 13:00:08 +10:00
Anna Lyons
b1788e02d5 aarch64: add support for 40-bit PA
This commit adds support for using a 40-bit physical addresses in
aarch64-hyp mode.

40-bit PA support is implemented by using a 3-stage translation, with a
13 bit page upper directory as the vspace root. PageGlobalDirectories
are not used in this configuration.

To use 40-bit PAs, platforms should set KernelArmPASizeBits40 to ON.

Co-authored-by: Yanyan Shen <yanyan.shen@data61.csiro.au>
Co-authored-by: Chris Guikema <chris.guikema@dornerworks.com>
2019-07-25 10:30:45 +10:00
Anna Lyons
8af1aa77f6 aarch64: abstract vspace_root in vspace code
On aarch64-hyp the virtual address translation structure can differ
depending on the physical address range. This commit prepares to support
more than a single physical address range by removing the assumption
that the top-level structure in a vspace is a PGD, replacing it with the
concept of a vspace_root.

Specifically:
    - add and use macros to refer to vtable bitfield generator functions
    - use the existing vspace_root_t type rather than pgde_t
    - pull performASIDPoolInvocation into header
    - add and use VSPACE_PTR rather than PGDE_PTR
    - rename decodeARMVPageGlobalDirectoryInvocation to refer to VSpace
    - update comments/error messages
    - rename variables
2019-07-25 09:59:17 +10:00
Anna Lyons
dfd8641c85 aarch64-hyp: check PA and granule sizes
Check that the configured physical address range is supported by the
processor and that the granule size (4KiB) is supported.
2019-07-25 09:19:34 +10:00
Chris Guikema
86a22fd343 trivial: properly mask vtcr macros 2019-07-25 09:19:00 +10:00
Sylvain Gauthier
121943c3c7 [SMP] Added PPI support for gic_v2
Correctly defined the macros to translate between virtual and hardware
IRQs such that PPIs can be properly handled on gic_v2. It is now
possible to create a per-core handler for PPIs on platforms using this
GIC.
2019-07-19 16:37:03 +10:00
Sylvain Gauthier
a6157d5d8e [SMP] Abstracted IRQ indexing to handle PPIs
irq_t is now a "virtual" interrupt type that encapsulates the
information of the core in case of a private interrupt. There is a
couple of macros that need to be defined on the interrupt controller
level to translate between virtual and hardware IRQs.
2019-07-19 16:37:03 +10:00
Sylvain Gauthier
1deb1d2696 [SMP] New IPI call to unmask remote IRQ
Added a new IPI on ARM to unmask a remote private interrupt.
2019-07-19 16:37:03 +10:00
Kent McLeod
dd6b8cb665 gic_v3: Support for aarch32 2019-07-18 13:47:23 +10:00
Japheth Lim
7ee63f9eb7 ARM boot: add MODE_RESERVED to MAX_NUM_FREEMEM_REG
This accounts for the ASID PD hole splitting the main memory region.
2019-07-05 10:19:00 +10:00
Kent McLeod
0d60f6f298 arm: Rename gic_pl390 to gic_v2
This is to reflect that this driver provides support for features that
are newer than gic_pl390 such as virtualisation.
2019-07-01 23:30:39 +10:00
Kent McLeod
466455f37b gic: Move common GIC definitions to shared header
Share definitions between gic_pl390.h and gic_v3.h.
2019-07-01 22:01:07 +10:00
Kent McLeod
759a8c7654 gic_v3: Add setIRQTrigger
This enables invocations to change the trigger mode of an IRQ.
2019-07-01 21:51:42 +10:00
Kent McLeod
53f080620e gic_v3: Change EOI mode to drop and deactivation
TODO: Decide what EOI mode we want.
2019-07-01 21:51:42 +10:00
Kent McLeod
ca01c8d9b8 gic_v3: Rename driver from gic_500
This driver should be compatible with GIC v3 implementations
2019-07-01 21:51:42 +10:00