2014-05-01 01:36:13 +02:00
|
|
|
/*
|
|
|
|
* This file is part of the coreboot project.
|
|
|
|
*
|
|
|
|
* Copyright (C) 2014 Google Inc.
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation; version 2 of the License.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <types.h>
|
|
|
|
#include <string.h>
|
|
|
|
#include <device/device.h>
|
|
|
|
#include <device/pci.h>
|
2019-03-01 12:43:02 +01:00
|
|
|
#include <device/pci_ops.h>
|
2014-05-01 01:36:13 +02:00
|
|
|
#include <cpu/x86/cache.h>
|
|
|
|
#include <cpu/x86/lapic.h>
|
|
|
|
#include <cpu/x86/mp.h>
|
|
|
|
#include <cpu/x86/msr.h>
|
|
|
|
#include <cpu/x86/mtrr.h>
|
|
|
|
#include <cpu/x86/smm.h>
|
2019-08-10 16:27:01 +02:00
|
|
|
#include <cpu/intel/em64t101_save_state.h>
|
2019-08-14 04:41:41 +02:00
|
|
|
#include <cpu/intel/smm_reloc.h>
|
2014-05-01 01:36:13 +02:00
|
|
|
#include <console/console.h>
|
2014-10-20 22:46:39 +02:00
|
|
|
#include <soc/cpu.h>
|
|
|
|
#include <soc/msr.h>
|
|
|
|
#include <soc/pci_devs.h>
|
|
|
|
#include <soc/smm.h>
|
|
|
|
#include <soc/systemagent.h>
|
2014-05-01 01:36:13 +02:00
|
|
|
|
|
|
|
/* This gets filled in and used during relocation. */
|
|
|
|
static struct smm_relocation_params smm_reloc_params;
|
|
|
|
|
|
|
|
static inline void write_smrr(struct smm_relocation_params *relo_params)
|
|
|
|
{
|
|
|
|
printk(BIOS_DEBUG, "Writing SMRR. base = 0x%08x, mask=0x%08x\n",
|
|
|
|
relo_params->smrr_base.lo, relo_params->smrr_mask.lo);
|
2018-07-20 23:31:59 +02:00
|
|
|
wrmsr(IA32_SMRR_PHYS_BASE, relo_params->smrr_base);
|
|
|
|
wrmsr(IA32_SMRR_PHYS_MASK, relo_params->smrr_mask);
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
static inline void write_prmrr(struct smm_relocation_params *relo_params)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
2019-08-11 07:45:40 +02:00
|
|
|
printk(BIOS_DEBUG, "Writing PRMRR. base = 0x%08x, mask=0x%08x\n",
|
|
|
|
relo_params->prmrr_base.lo, relo_params->prmrr_mask.lo);
|
|
|
|
wrmsr(MSR_PRMRR_PHYS_BASE, relo_params->prmrr_base);
|
|
|
|
wrmsr(MSR_PRMRR_PHYS_MASK, relo_params->prmrr_mask);
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
static inline void write_uncore_prmrr(struct smm_relocation_params *relo_params)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
|
|
|
printk(BIOS_DEBUG,
|
2019-08-11 07:45:40 +02:00
|
|
|
"Writing UNCORE_PRMRR. base = 0x%08x, mask=0x%08x\n",
|
|
|
|
relo_params->uncore_prmrr_base.lo,
|
|
|
|
relo_params->uncore_prmrr_mask.lo);
|
|
|
|
wrmsr(MSR_UNCORE_PRMRR_PHYS_BASE, relo_params->uncore_prmrr_base);
|
|
|
|
wrmsr(MSR_UNCORE_PRMRR_PHYS_MASK, relo_params->uncore_prmrr_mask);
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
static void update_save_state(int cpu, uintptr_t curr_smbase,
|
|
|
|
uintptr_t staggered_smbase,
|
|
|
|
struct smm_relocation_params *relo_params)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
|
|
|
u32 smbase;
|
|
|
|
u32 iedbase;
|
|
|
|
|
|
|
|
/* The relocated handler runs with all CPUs concurrently. Therefore
|
|
|
|
* stagger the entry points adjusting SMBASE downwards by save state
|
|
|
|
* size * CPU num. */
|
2016-05-03 23:48:19 +02:00
|
|
|
smbase = staggered_smbase;
|
2014-05-01 01:36:13 +02:00
|
|
|
iedbase = relo_params->ied_base;
|
|
|
|
|
|
|
|
printk(BIOS_DEBUG, "New SMBASE=0x%08x IEDBASE=0x%08x\n",
|
|
|
|
smbase, iedbase);
|
|
|
|
|
|
|
|
/* All threads need to set IEDBASE and SMBASE to the relocated
|
|
|
|
* handler region. However, the save state location depends on the
|
|
|
|
* smm_save_state_in_msrs field in the relocation parameters. If
|
|
|
|
* smm_save_state_in_msrs is non-zero then the CPUs are relocating
|
|
|
|
* the SMM handler in parallel, and each CPUs save state area is
|
|
|
|
* located in their respective MSR space. If smm_save_state_in_msrs
|
|
|
|
* is zero then the SMM relocation is happening serially so the
|
|
|
|
* save state is at the same default location for all CPUs. */
|
|
|
|
if (relo_params->smm_save_state_in_msrs) {
|
|
|
|
msr_t smbase_msr;
|
|
|
|
msr_t iedbase_msr;
|
|
|
|
|
|
|
|
smbase_msr.lo = smbase;
|
|
|
|
smbase_msr.hi = 0;
|
|
|
|
|
|
|
|
/* According the BWG the IEDBASE MSR is in bits 63:32. It's
|
|
|
|
* not clear why it differs from the SMBASE MSR. */
|
|
|
|
iedbase_msr.lo = 0;
|
|
|
|
iedbase_msr.hi = iedbase;
|
|
|
|
|
|
|
|
wrmsr(SMBASE_MSR, smbase_msr);
|
|
|
|
wrmsr(IEDBASE_MSR, iedbase_msr);
|
|
|
|
} else {
|
|
|
|
em64t101_smm_state_save_area_t *save_state;
|
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
save_state = (void *)(curr_smbase + SMM_DEFAULT_SIZE -
|
|
|
|
sizeof(*save_state));
|
2014-05-01 01:36:13 +02:00
|
|
|
|
|
|
|
save_state->smbase = smbase;
|
|
|
|
save_state->iedbase = iedbase;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Returns 1 if SMM MSR save state was set. */
|
|
|
|
static int bsp_setup_msr_save_state(struct smm_relocation_params *relo_params)
|
|
|
|
{
|
|
|
|
msr_t smm_mca_cap;
|
|
|
|
|
|
|
|
smm_mca_cap = rdmsr(SMM_MCA_CAP_MSR);
|
|
|
|
if (smm_mca_cap.hi & SMM_CPU_SVRSTR_MASK) {
|
|
|
|
msr_t smm_feature_control;
|
|
|
|
|
|
|
|
smm_feature_control = rdmsr(SMM_FEATURE_CONTROL_MSR);
|
|
|
|
smm_feature_control.hi = 0;
|
|
|
|
smm_feature_control.lo |= SMM_CPU_SAVE_EN;
|
|
|
|
wrmsr(SMM_FEATURE_CONTROL_MSR, smm_feature_control);
|
|
|
|
relo_params->smm_save_state_in_msrs = 1;
|
|
|
|
}
|
|
|
|
return relo_params->smm_save_state_in_msrs;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* The relocation work is actually performed in SMM context, but the code
|
|
|
|
* resides in the ramstage module. This occurs by trampolining from the default
|
|
|
|
* SMRAM entry point to here. */
|
2016-05-03 23:48:19 +02:00
|
|
|
void smm_relocation_handler(int cpu, uintptr_t curr_smbase,
|
|
|
|
uintptr_t staggered_smbase)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
|
|
|
msr_t mtrr_cap;
|
2016-05-03 23:48:19 +02:00
|
|
|
struct smm_relocation_params *relo_params = &smm_reloc_params;
|
2014-05-01 01:36:13 +02:00
|
|
|
|
2016-07-29 18:31:16 +02:00
|
|
|
printk(BIOS_DEBUG, "In relocation handler: CPU %d\n", cpu);
|
2014-05-01 01:36:13 +02:00
|
|
|
|
|
|
|
/* Determine if the processor supports saving state in MSRs. If so,
|
|
|
|
* enable it before the non-BSPs run so that SMM relocation can occur
|
|
|
|
* in parallel in the non-BSP CPUs. */
|
|
|
|
if (cpu == 0) {
|
|
|
|
/* If smm_save_state_in_msrs is 1 then that means this is the
|
|
|
|
* 2nd time through the relocation handler for the BSP.
|
|
|
|
* Parallel SMM handler relocation is taking place. However,
|
|
|
|
* it is desired to access other CPUs save state in the real
|
|
|
|
* SMM handler. Therefore, disable the SMM save state in MSRs
|
|
|
|
* feature. */
|
|
|
|
if (relo_params->smm_save_state_in_msrs) {
|
|
|
|
msr_t smm_feature_control;
|
|
|
|
|
|
|
|
smm_feature_control = rdmsr(SMM_FEATURE_CONTROL_MSR);
|
|
|
|
smm_feature_control.lo &= ~SMM_CPU_SAVE_EN;
|
|
|
|
wrmsr(SMM_FEATURE_CONTROL_MSR, smm_feature_control);
|
|
|
|
} else if (bsp_setup_msr_save_state(relo_params))
|
|
|
|
/* Just return from relocation handler if MSR save
|
|
|
|
* state is enabled. In that case the BSP will come
|
|
|
|
* back into the relocation handler to setup the new
|
|
|
|
* SMBASE as well disabling SMM save state in MSRs. */
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Make appropriate changes to the save state map. */
|
2016-05-03 23:48:19 +02:00
|
|
|
update_save_state(cpu, curr_smbase, staggered_smbase, relo_params);
|
2014-05-01 01:36:13 +02:00
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
/* Write PRMRR and SMRR MSRs based on indicated support. */
|
2015-10-01 05:23:09 +02:00
|
|
|
mtrr_cap = rdmsr(MTRR_CAP_MSR);
|
2014-05-01 01:36:13 +02:00
|
|
|
if (mtrr_cap.lo & SMRR_SUPPORTED)
|
|
|
|
write_smrr(relo_params);
|
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
if (mtrr_cap.lo & PRMRR_SUPPORTED) {
|
|
|
|
write_prmrr(relo_params);
|
|
|
|
/* UNCORE_PRMRR msrs are package level. Therefore, only
|
2014-05-01 01:36:13 +02:00
|
|
|
* configure these MSRs on the BSP. */
|
|
|
|
if (cpu == 0)
|
2019-08-11 07:45:40 +02:00
|
|
|
write_uncore_prmrr(relo_params);
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-05-27 16:30:36 +02:00
|
|
|
static u32 northbridge_get_base_reg(struct device *dev, int reg)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
|
|
|
u32 value;
|
|
|
|
|
|
|
|
value = pci_read_config32(dev, reg);
|
|
|
|
/* Base registers are at 1MiB granularity. */
|
|
|
|
value &= ~((1 << 20) - 1);
|
|
|
|
return value;
|
|
|
|
}
|
|
|
|
|
2018-05-27 16:30:36 +02:00
|
|
|
static void fill_in_relocation_params(struct device *dev,
|
2017-03-17 02:47:55 +01:00
|
|
|
struct smm_relocation_params *params)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
|
|
|
u32 tseg_size;
|
|
|
|
u32 tsegmb;
|
|
|
|
u32 bgsm;
|
2019-08-11 07:45:40 +02:00
|
|
|
u32 prmrr_base;
|
|
|
|
u32 prmrr_size;
|
2014-05-01 01:36:13 +02:00
|
|
|
int phys_bits;
|
|
|
|
/* All range registers are aligned to 4KiB */
|
|
|
|
const u32 rmask = ~((1 << 12) - 1);
|
|
|
|
|
|
|
|
/* Some of the range registers are dependent on the number of physical
|
|
|
|
* address bits supported. */
|
|
|
|
phys_bits = cpuid_eax(0x80000008) & 0xff;
|
|
|
|
|
|
|
|
/* The range bounded by the TSEGMB and BGSM registers encompasses the
|
|
|
|
* SMRAM range as well as the IED range. However, the SMRAM available
|
|
|
|
* to the handler is 4MiB since the IEDRAM lives TSEGMB + 4MiB.
|
|
|
|
*/
|
|
|
|
tsegmb = northbridge_get_base_reg(dev, TSEG);
|
|
|
|
bgsm = northbridge_get_base_reg(dev, BGSM);
|
|
|
|
tseg_size = bgsm - tsegmb;
|
|
|
|
|
|
|
|
params->smram_base = tsegmb;
|
|
|
|
params->smram_size = 4 << 20;
|
|
|
|
params->ied_base = tsegmb + params->smram_size;
|
|
|
|
params->ied_size = tseg_size - params->smram_size;
|
|
|
|
|
|
|
|
/* Adjust available SMM handler memory size. */
|
|
|
|
params->smram_size -= CONFIG_SMM_RESERVED_SIZE;
|
|
|
|
|
|
|
|
/* SMRR has 32-bits of valid address aligned to 4KiB. */
|
|
|
|
params->smrr_base.lo = (params->smram_base & rmask) | MTRR_TYPE_WRBACK;
|
|
|
|
params->smrr_base.hi = 0;
|
2017-03-17 18:56:08 +01:00
|
|
|
params->smrr_mask.lo = (~(tseg_size - 1) & rmask)
|
|
|
|
| MTRR_PHYS_MASK_VALID;
|
2014-05-01 01:36:13 +02:00
|
|
|
params->smrr_mask.hi = 0;
|
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
/* The PRMRR and UNCORE_PRMRR are at IEDBASE + 2MiB */
|
|
|
|
prmrr_base = (params->ied_base + (2 << 20)) & rmask;
|
|
|
|
prmrr_size = params->ied_size - (2 << 20);
|
2014-05-01 01:36:13 +02:00
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
/* PRMRR has 46 bits of valid address aligned to 4KiB. It's dependent
|
2014-05-01 01:36:13 +02:00
|
|
|
* on the number of physical address bits supported. */
|
2019-08-11 07:45:40 +02:00
|
|
|
params->prmrr_base.lo = prmrr_base | MTRR_TYPE_WRBACK;
|
|
|
|
params->prmrr_base.hi = 0;
|
|
|
|
params->prmrr_mask.lo = (~(prmrr_size - 1) & rmask)
|
2017-03-17 18:56:08 +01:00
|
|
|
| MTRR_PHYS_MASK_VALID;
|
2019-08-11 07:45:40 +02:00
|
|
|
params->prmrr_mask.hi = (1 << (phys_bits - 32)) - 1;
|
2014-05-01 01:36:13 +02:00
|
|
|
|
2019-08-11 07:45:40 +02:00
|
|
|
/* UNCORE_PRMRR has 39 bits of valid address aligned to 4KiB. */
|
|
|
|
params->uncore_prmrr_base.lo = prmrr_base;
|
|
|
|
params->uncore_prmrr_base.hi = 0;
|
|
|
|
params->uncore_prmrr_mask.lo = (~(prmrr_size - 1) & rmask) |
|
2017-03-17 02:47:55 +01:00
|
|
|
MTRR_PHYS_MASK_VALID;
|
2019-08-11 07:45:40 +02:00
|
|
|
params->uncore_prmrr_mask.hi = (1 << (39 - 32)) - 1;
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
static void setup_ied_area(struct smm_relocation_params *params)
|
|
|
|
{
|
|
|
|
char *ied_base;
|
|
|
|
|
|
|
|
struct ied_header ied = {
|
|
|
|
.signature = "INTEL RSVD",
|
|
|
|
.size = params->ied_size,
|
|
|
|
.reserved = {0},
|
|
|
|
};
|
|
|
|
|
|
|
|
ied_base = (void *)params->ied_base;
|
|
|
|
|
|
|
|
/* Place IED header at IEDBASE. */
|
|
|
|
memcpy(ied_base, &ied, sizeof(ied));
|
|
|
|
|
|
|
|
/* Zero out 32KiB at IEDBASE + 1MiB */
|
|
|
|
memset(ied_base + (1 << 20), 0, (32 << 10));
|
|
|
|
}
|
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
void smm_info(uintptr_t *perm_smbase, size_t *perm_smsize,
|
|
|
|
size_t *smm_save_state_size)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
2019-07-12 12:10:19 +02:00
|
|
|
struct device *dev = pcidev_path_on_root(SA_DEVFN_ROOT);
|
2014-05-01 01:36:13 +02:00
|
|
|
|
|
|
|
printk(BIOS_DEBUG, "Setting up SMI for CPU\n");
|
|
|
|
|
|
|
|
fill_in_relocation_params(dev, &smm_reloc_params);
|
|
|
|
|
|
|
|
setup_ied_area(&smm_reloc_params);
|
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
*perm_smbase = smm_reloc_params.smram_base;
|
|
|
|
*perm_smsize = smm_reloc_params.smram_size;
|
|
|
|
*smm_save_state_size = sizeof(em64t101_smm_state_save_area_t);
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
void smm_initialize(void)
|
2014-05-01 01:36:13 +02:00
|
|
|
{
|
|
|
|
/* Clear the SMM state in the southbridge. */
|
2019-08-14 04:41:41 +02:00
|
|
|
smm_southbridge_clear_state();
|
2014-05-01 01:36:13 +02:00
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
/*
|
|
|
|
* Run the relocation handler for on the BSP to check and set up
|
|
|
|
* parallel SMM relocation.
|
|
|
|
*/
|
2014-05-01 01:36:13 +02:00
|
|
|
smm_initiate_relocation();
|
|
|
|
|
2017-03-17 18:43:25 +01:00
|
|
|
if (smm_reloc_params.smm_save_state_in_msrs)
|
2014-05-01 01:36:13 +02:00
|
|
|
printk(BIOS_DEBUG, "Doing parallel SMM relocation.\n");
|
|
|
|
}
|
|
|
|
|
2016-05-03 23:48:19 +02:00
|
|
|
/* The default SMM entry can happen in parallel or serially. If the
|
|
|
|
* default SMM entry is done in parallel the BSP has already setup
|
|
|
|
* the saving state to each CPU's MSRs. At least one save state size
|
|
|
|
* is required for the initial SMM entry for the BSP to determine if
|
|
|
|
* parallel SMM relocation is even feasible. */
|
2014-05-01 01:36:13 +02:00
|
|
|
void smm_relocate(void)
|
|
|
|
{
|
|
|
|
/*
|
|
|
|
* If smm_save_state_in_msrs is non-zero then parallel SMM relocation
|
|
|
|
* shall take place. Run the relocation handler a second time on the
|
|
|
|
* BSP to do * the final move. For APs, a relocation handler always
|
|
|
|
* needs to be run.
|
|
|
|
*/
|
|
|
|
if (smm_reloc_params.smm_save_state_in_msrs)
|
|
|
|
smm_initiate_relocation_parallel();
|
|
|
|
else if (!boot_cpu())
|
|
|
|
smm_initiate_relocation();
|
|
|
|
}
|
|
|
|
|
|
|
|
void smm_lock(void)
|
|
|
|
{
|
2019-07-12 12:10:19 +02:00
|
|
|
struct device *sa_dev = pcidev_path_on_root(SA_DEVFN_ROOT);
|
2014-05-01 01:36:13 +02:00
|
|
|
/* LOCK the SMM memory window and enable normal SMM.
|
|
|
|
* After running this function, only a full reset can
|
|
|
|
* make the SMM registers writable again.
|
|
|
|
*/
|
|
|
|
printk(BIOS_DEBUG, "Locking SMM.\n");
|
2019-07-12 12:10:19 +02:00
|
|
|
pci_write_config8(sa_dev, SMRAM, D_LCK | G_SMRAME | C_BASE_SEG);
|
2014-05-01 01:36:13 +02:00
|
|
|
}
|