1 /* 2 * ITS emulation for a GICv3-based system 3 * 4 * Copyright Linaro.org 2021 5 * 6 * Authors: 7 * Shashi Mallela <shashi.mallela@linaro.org> 8 * 9 * This work is licensed under the terms of the GNU GPL, version 2 or (at your 10 * option) any later version. See the COPYING file in the top-level directory. 11 * 12 */ 13 14 #include "qemu/osdep.h" 15 #include "qemu/log.h" 16 #include "hw/qdev-properties.h" 17 #include "hw/intc/arm_gicv3_its_common.h" 18 #include "gicv3_internal.h" 19 #include "qom/object.h" 20 #include "qapi/error.h" 21 22 typedef struct GICv3ITSClass GICv3ITSClass; 23 /* This is reusing the GICv3ITSState typedef from ARM_GICV3_ITS_COMMON */ 24 DECLARE_OBJ_CHECKERS(GICv3ITSState, GICv3ITSClass, 25 ARM_GICV3_ITS, TYPE_ARM_GICV3_ITS) 26 27 struct GICv3ITSClass { 28 GICv3ITSCommonClass parent_class; 29 void (*parent_reset)(DeviceState *dev); 30 }; 31 32 /* 33 * This is an internal enum used to distinguish between LPI triggered 34 * via command queue and LPI triggered via gits_translater write. 35 */ 36 typedef enum ItsCmdType { 37 NONE = 0, /* internal indication for GITS_TRANSLATER write */ 38 CLEAR = 1, 39 DISCARD = 2, 40 INTERRUPT = 3, 41 } ItsCmdType; 42 43 typedef struct { 44 uint32_t iteh; 45 uint64_t itel; 46 } IteEntry; 47 48 static uint64_t baser_base_addr(uint64_t value, uint32_t page_sz) 49 { 50 uint64_t result = 0; 51 52 switch (page_sz) { 53 case GITS_PAGE_SIZE_4K: 54 case GITS_PAGE_SIZE_16K: 55 result = FIELD_EX64(value, GITS_BASER, PHYADDR) << 12; 56 break; 57 58 case GITS_PAGE_SIZE_64K: 59 result = FIELD_EX64(value, GITS_BASER, PHYADDRL_64K) << 16; 60 result |= FIELD_EX64(value, GITS_BASER, PHYADDRH_64K) << 48; 61 break; 62 63 default: 64 break; 65 } 66 return result; 67 } 68 69 static bool get_cte(GICv3ITSState *s, uint16_t icid, uint64_t *cte, 70 MemTxResult *res) 71 { 72 AddressSpace *as = &s->gicv3->dma_as; 73 uint64_t l2t_addr; 74 uint64_t value; 75 bool valid_l2t; 76 uint32_t l2t_id; 77 uint32_t num_l2_entries; 78 79 if (s->ct.indirect) { 80 l2t_id = icid / (s->ct.page_sz / L1TABLE_ENTRY_SIZE); 81 82 value = address_space_ldq_le(as, 83 s->ct.base_addr + 84 (l2t_id * L1TABLE_ENTRY_SIZE), 85 MEMTXATTRS_UNSPECIFIED, res); 86 87 if (*res == MEMTX_OK) { 88 valid_l2t = (value & L2_TABLE_VALID_MASK) != 0; 89 90 if (valid_l2t) { 91 num_l2_entries = s->ct.page_sz / s->ct.entry_sz; 92 93 l2t_addr = value & ((1ULL << 51) - 1); 94 95 *cte = address_space_ldq_le(as, l2t_addr + 96 ((icid % num_l2_entries) * GITS_CTE_SIZE), 97 MEMTXATTRS_UNSPECIFIED, res); 98 } 99 } 100 } else { 101 /* Flat level table */ 102 *cte = address_space_ldq_le(as, s->ct.base_addr + 103 (icid * GITS_CTE_SIZE), 104 MEMTXATTRS_UNSPECIFIED, res); 105 } 106 107 return FIELD_EX64(*cte, CTE, VALID); 108 } 109 110 static bool update_ite(GICv3ITSState *s, uint32_t eventid, uint64_t dte, 111 IteEntry ite) 112 { 113 AddressSpace *as = &s->gicv3->dma_as; 114 uint64_t itt_addr; 115 MemTxResult res = MEMTX_OK; 116 117 itt_addr = FIELD_EX64(dte, DTE, ITTADDR); 118 itt_addr <<= ITTADDR_SHIFT; /* 256 byte aligned */ 119 120 address_space_stq_le(as, itt_addr + (eventid * (sizeof(uint64_t) + 121 sizeof(uint32_t))), ite.itel, MEMTXATTRS_UNSPECIFIED, 122 &res); 123 124 if (res == MEMTX_OK) { 125 address_space_stl_le(as, itt_addr + (eventid * (sizeof(uint64_t) + 126 sizeof(uint32_t))) + sizeof(uint32_t), ite.iteh, 127 MEMTXATTRS_UNSPECIFIED, &res); 128 } 129 if (res != MEMTX_OK) { 130 return false; 131 } else { 132 return true; 133 } 134 } 135 136 static bool get_ite(GICv3ITSState *s, uint32_t eventid, uint64_t dte, 137 uint16_t *icid, uint32_t *pIntid, MemTxResult *res) 138 { 139 AddressSpace *as = &s->gicv3->dma_as; 140 uint64_t itt_addr; 141 bool status = false; 142 IteEntry ite = {}; 143 144 itt_addr = FIELD_EX64(dte, DTE, ITTADDR); 145 itt_addr <<= ITTADDR_SHIFT; /* 256 byte aligned */ 146 147 ite.itel = address_space_ldq_le(as, itt_addr + 148 (eventid * (sizeof(uint64_t) + 149 sizeof(uint32_t))), MEMTXATTRS_UNSPECIFIED, 150 res); 151 152 if (*res == MEMTX_OK) { 153 ite.iteh = address_space_ldl_le(as, itt_addr + 154 (eventid * (sizeof(uint64_t) + 155 sizeof(uint32_t))) + sizeof(uint32_t), 156 MEMTXATTRS_UNSPECIFIED, res); 157 158 if (*res == MEMTX_OK) { 159 if (FIELD_EX64(ite.itel, ITE_L, VALID)) { 160 int inttype = FIELD_EX64(ite.itel, ITE_L, INTTYPE); 161 if (inttype == ITE_INTTYPE_PHYSICAL) { 162 *pIntid = FIELD_EX64(ite.itel, ITE_L, INTID); 163 *icid = FIELD_EX32(ite.iteh, ITE_H, ICID); 164 status = true; 165 } 166 } 167 } 168 } 169 return status; 170 } 171 172 static uint64_t get_dte(GICv3ITSState *s, uint32_t devid, MemTxResult *res) 173 { 174 AddressSpace *as = &s->gicv3->dma_as; 175 uint64_t l2t_addr; 176 uint64_t value; 177 bool valid_l2t; 178 uint32_t l2t_id; 179 uint32_t num_l2_entries; 180 181 if (s->dt.indirect) { 182 l2t_id = devid / (s->dt.page_sz / L1TABLE_ENTRY_SIZE); 183 184 value = address_space_ldq_le(as, 185 s->dt.base_addr + 186 (l2t_id * L1TABLE_ENTRY_SIZE), 187 MEMTXATTRS_UNSPECIFIED, res); 188 189 if (*res == MEMTX_OK) { 190 valid_l2t = (value & L2_TABLE_VALID_MASK) != 0; 191 192 if (valid_l2t) { 193 num_l2_entries = s->dt.page_sz / s->dt.entry_sz; 194 195 l2t_addr = value & ((1ULL << 51) - 1); 196 197 value = address_space_ldq_le(as, l2t_addr + 198 ((devid % num_l2_entries) * GITS_DTE_SIZE), 199 MEMTXATTRS_UNSPECIFIED, res); 200 } 201 } 202 } else { 203 /* Flat level table */ 204 value = address_space_ldq_le(as, s->dt.base_addr + 205 (devid * GITS_DTE_SIZE), 206 MEMTXATTRS_UNSPECIFIED, res); 207 } 208 209 return value; 210 } 211 212 /* 213 * This function handles the processing of following commands based on 214 * the ItsCmdType parameter passed:- 215 * 1. triggering of lpi interrupt translation via ITS INT command 216 * 2. triggering of lpi interrupt translation via gits_translater register 217 * 3. handling of ITS CLEAR command 218 * 4. handling of ITS DISCARD command 219 */ 220 static bool process_its_cmd(GICv3ITSState *s, uint64_t value, uint32_t offset, 221 ItsCmdType cmd) 222 { 223 AddressSpace *as = &s->gicv3->dma_as; 224 uint32_t devid, eventid; 225 MemTxResult res = MEMTX_OK; 226 bool dte_valid; 227 uint64_t dte = 0; 228 uint64_t num_eventids; 229 uint16_t icid = 0; 230 uint32_t pIntid = 0; 231 bool ite_valid = false; 232 uint64_t cte = 0; 233 bool cte_valid = false; 234 bool result = false; 235 uint64_t rdbase; 236 237 if (cmd == NONE) { 238 devid = offset; 239 } else { 240 devid = ((value & DEVID_MASK) >> DEVID_SHIFT); 241 242 offset += NUM_BYTES_IN_DW; 243 value = address_space_ldq_le(as, s->cq.base_addr + offset, 244 MEMTXATTRS_UNSPECIFIED, &res); 245 } 246 247 if (res != MEMTX_OK) { 248 return result; 249 } 250 251 eventid = (value & EVENTID_MASK); 252 253 dte = get_dte(s, devid, &res); 254 255 if (res != MEMTX_OK) { 256 return result; 257 } 258 dte_valid = FIELD_EX64(dte, DTE, VALID); 259 260 if (dte_valid) { 261 num_eventids = 1ULL << (FIELD_EX64(dte, DTE, SIZE) + 1); 262 263 ite_valid = get_ite(s, eventid, dte, &icid, &pIntid, &res); 264 265 if (res != MEMTX_OK) { 266 return result; 267 } 268 269 if (ite_valid) { 270 cte_valid = get_cte(s, icid, &cte, &res); 271 } 272 273 if (res != MEMTX_OK) { 274 return result; 275 } 276 } else { 277 qemu_log_mask(LOG_GUEST_ERROR, 278 "%s: invalid command attributes: " 279 "invalid dte: %"PRIx64" for %d (MEM_TX: %d)\n", 280 __func__, dte, devid, res); 281 return result; 282 } 283 284 285 /* 286 * In this implementation, in case of guest errors we ignore the 287 * command and move onto the next command in the queue. 288 */ 289 if (devid >= s->dt.num_ids) { 290 qemu_log_mask(LOG_GUEST_ERROR, 291 "%s: invalid command attributes: devid %d>=%d", 292 __func__, devid, s->dt.num_ids); 293 294 } else if (!dte_valid || !ite_valid || !cte_valid) { 295 qemu_log_mask(LOG_GUEST_ERROR, 296 "%s: invalid command attributes: " 297 "dte: %s, ite: %s, cte: %s\n", 298 __func__, 299 dte_valid ? "valid" : "invalid", 300 ite_valid ? "valid" : "invalid", 301 cte_valid ? "valid" : "invalid"); 302 } else if (eventid >= num_eventids) { 303 qemu_log_mask(LOG_GUEST_ERROR, 304 "%s: invalid command attributes: eventid %d >= %" 305 PRId64 "\n", 306 __func__, eventid, num_eventids); 307 } else { 308 /* 309 * Current implementation only supports rdbase == procnum 310 * Hence rdbase physical address is ignored 311 */ 312 rdbase = FIELD_EX64(cte, CTE, RDBASE); 313 314 if (rdbase >= s->gicv3->num_cpu) { 315 return result; 316 } 317 318 if ((cmd == CLEAR) || (cmd == DISCARD)) { 319 gicv3_redist_process_lpi(&s->gicv3->cpu[rdbase], pIntid, 0); 320 } else { 321 gicv3_redist_process_lpi(&s->gicv3->cpu[rdbase], pIntid, 1); 322 } 323 324 if (cmd == DISCARD) { 325 IteEntry ite = {}; 326 /* remove mapping from interrupt translation table */ 327 result = update_ite(s, eventid, dte, ite); 328 } 329 } 330 331 return result; 332 } 333 334 static bool process_mapti(GICv3ITSState *s, uint64_t value, uint32_t offset, 335 bool ignore_pInt) 336 { 337 AddressSpace *as = &s->gicv3->dma_as; 338 uint32_t devid, eventid; 339 uint32_t pIntid = 0; 340 uint64_t num_eventids; 341 uint32_t max_Intid; 342 bool dte_valid; 343 MemTxResult res = MEMTX_OK; 344 uint16_t icid = 0; 345 uint64_t dte = 0; 346 bool result = false; 347 348 devid = ((value & DEVID_MASK) >> DEVID_SHIFT); 349 offset += NUM_BYTES_IN_DW; 350 value = address_space_ldq_le(as, s->cq.base_addr + offset, 351 MEMTXATTRS_UNSPECIFIED, &res); 352 353 if (res != MEMTX_OK) { 354 return result; 355 } 356 357 eventid = (value & EVENTID_MASK); 358 359 if (ignore_pInt) { 360 pIntid = eventid; 361 } else { 362 pIntid = ((value & pINTID_MASK) >> pINTID_SHIFT); 363 } 364 365 offset += NUM_BYTES_IN_DW; 366 value = address_space_ldq_le(as, s->cq.base_addr + offset, 367 MEMTXATTRS_UNSPECIFIED, &res); 368 369 if (res != MEMTX_OK) { 370 return result; 371 } 372 373 icid = value & ICID_MASK; 374 375 dte = get_dte(s, devid, &res); 376 377 if (res != MEMTX_OK) { 378 return result; 379 } 380 dte_valid = FIELD_EX64(dte, DTE, VALID); 381 num_eventids = 1ULL << (FIELD_EX64(dte, DTE, SIZE) + 1); 382 max_Intid = (1ULL << (GICD_TYPER_IDBITS + 1)) - 1; 383 384 if ((devid >= s->dt.num_ids) || (icid >= s->ct.num_ids) 385 || !dte_valid || (eventid >= num_eventids) || 386 (((pIntid < GICV3_LPI_INTID_START) || (pIntid > max_Intid)) && 387 (pIntid != INTID_SPURIOUS))) { 388 qemu_log_mask(LOG_GUEST_ERROR, 389 "%s: invalid command attributes " 390 "devid %d or icid %d or eventid %d or pIntid %d or" 391 "unmapped dte %d\n", __func__, devid, icid, eventid, 392 pIntid, dte_valid); 393 /* 394 * in this implementation, in case of error 395 * we ignore this command and move onto the next 396 * command in the queue 397 */ 398 } else { 399 /* add ite entry to interrupt translation table */ 400 IteEntry ite = {}; 401 ite.itel = FIELD_DP64(ite.itel, ITE_L, VALID, dte_valid); 402 ite.itel = FIELD_DP64(ite.itel, ITE_L, INTTYPE, ITE_INTTYPE_PHYSICAL); 403 ite.itel = FIELD_DP64(ite.itel, ITE_L, INTID, pIntid); 404 ite.itel = FIELD_DP64(ite.itel, ITE_L, DOORBELL, INTID_SPURIOUS); 405 ite.iteh = FIELD_DP32(ite.iteh, ITE_H, ICID, icid); 406 407 result = update_ite(s, eventid, dte, ite); 408 } 409 410 return result; 411 } 412 413 static bool update_cte(GICv3ITSState *s, uint16_t icid, bool valid, 414 uint64_t rdbase) 415 { 416 AddressSpace *as = &s->gicv3->dma_as; 417 uint64_t value; 418 uint64_t l2t_addr; 419 bool valid_l2t; 420 uint32_t l2t_id; 421 uint32_t num_l2_entries; 422 uint64_t cte = 0; 423 MemTxResult res = MEMTX_OK; 424 425 if (!s->ct.valid) { 426 return true; 427 } 428 429 if (valid) { 430 /* add mapping entry to collection table */ 431 cte = FIELD_DP64(cte, CTE, VALID, 1); 432 cte = FIELD_DP64(cte, CTE, RDBASE, rdbase); 433 } 434 435 /* 436 * The specification defines the format of level 1 entries of a 437 * 2-level table, but the format of level 2 entries and the format 438 * of flat-mapped tables is IMPDEF. 439 */ 440 if (s->ct.indirect) { 441 l2t_id = icid / (s->ct.page_sz / L1TABLE_ENTRY_SIZE); 442 443 value = address_space_ldq_le(as, 444 s->ct.base_addr + 445 (l2t_id * L1TABLE_ENTRY_SIZE), 446 MEMTXATTRS_UNSPECIFIED, &res); 447 448 if (res != MEMTX_OK) { 449 return false; 450 } 451 452 valid_l2t = (value & L2_TABLE_VALID_MASK) != 0; 453 454 if (valid_l2t) { 455 num_l2_entries = s->ct.page_sz / s->ct.entry_sz; 456 457 l2t_addr = value & ((1ULL << 51) - 1); 458 459 address_space_stq_le(as, l2t_addr + 460 ((icid % num_l2_entries) * GITS_CTE_SIZE), 461 cte, MEMTXATTRS_UNSPECIFIED, &res); 462 } 463 } else { 464 /* Flat level table */ 465 address_space_stq_le(as, s->ct.base_addr + (icid * GITS_CTE_SIZE), 466 cte, MEMTXATTRS_UNSPECIFIED, &res); 467 } 468 if (res != MEMTX_OK) { 469 return false; 470 } else { 471 return true; 472 } 473 } 474 475 static bool process_mapc(GICv3ITSState *s, uint32_t offset) 476 { 477 AddressSpace *as = &s->gicv3->dma_as; 478 uint16_t icid; 479 uint64_t rdbase; 480 bool valid; 481 MemTxResult res = MEMTX_OK; 482 bool result = false; 483 uint64_t value; 484 485 offset += NUM_BYTES_IN_DW; 486 offset += NUM_BYTES_IN_DW; 487 488 value = address_space_ldq_le(as, s->cq.base_addr + offset, 489 MEMTXATTRS_UNSPECIFIED, &res); 490 491 if (res != MEMTX_OK) { 492 return result; 493 } 494 495 icid = value & ICID_MASK; 496 497 rdbase = (value & R_MAPC_RDBASE_MASK) >> R_MAPC_RDBASE_SHIFT; 498 rdbase &= RDBASE_PROCNUM_MASK; 499 500 valid = (value & CMD_FIELD_VALID_MASK); 501 502 if ((icid >= s->ct.num_ids) || (rdbase >= s->gicv3->num_cpu)) { 503 qemu_log_mask(LOG_GUEST_ERROR, 504 "ITS MAPC: invalid collection table attributes " 505 "icid %d rdbase %" PRIu64 "\n", icid, rdbase); 506 /* 507 * in this implementation, in case of error 508 * we ignore this command and move onto the next 509 * command in the queue 510 */ 511 } else { 512 result = update_cte(s, icid, valid, rdbase); 513 } 514 515 return result; 516 } 517 518 static bool update_dte(GICv3ITSState *s, uint32_t devid, bool valid, 519 uint8_t size, uint64_t itt_addr) 520 { 521 AddressSpace *as = &s->gicv3->dma_as; 522 uint64_t value; 523 uint64_t l2t_addr; 524 bool valid_l2t; 525 uint32_t l2t_id; 526 uint32_t num_l2_entries; 527 uint64_t dte = 0; 528 MemTxResult res = MEMTX_OK; 529 530 if (s->dt.valid) { 531 if (valid) { 532 /* add mapping entry to device table */ 533 dte = FIELD_DP64(dte, DTE, VALID, 1); 534 dte = FIELD_DP64(dte, DTE, SIZE, size); 535 dte = FIELD_DP64(dte, DTE, ITTADDR, itt_addr); 536 } 537 } else { 538 return true; 539 } 540 541 /* 542 * The specification defines the format of level 1 entries of a 543 * 2-level table, but the format of level 2 entries and the format 544 * of flat-mapped tables is IMPDEF. 545 */ 546 if (s->dt.indirect) { 547 l2t_id = devid / (s->dt.page_sz / L1TABLE_ENTRY_SIZE); 548 549 value = address_space_ldq_le(as, 550 s->dt.base_addr + 551 (l2t_id * L1TABLE_ENTRY_SIZE), 552 MEMTXATTRS_UNSPECIFIED, &res); 553 554 if (res != MEMTX_OK) { 555 return false; 556 } 557 558 valid_l2t = (value & L2_TABLE_VALID_MASK) != 0; 559 560 if (valid_l2t) { 561 num_l2_entries = s->dt.page_sz / s->dt.entry_sz; 562 563 l2t_addr = value & ((1ULL << 51) - 1); 564 565 address_space_stq_le(as, l2t_addr + 566 ((devid % num_l2_entries) * GITS_DTE_SIZE), 567 dte, MEMTXATTRS_UNSPECIFIED, &res); 568 } 569 } else { 570 /* Flat level table */ 571 address_space_stq_le(as, s->dt.base_addr + (devid * GITS_DTE_SIZE), 572 dte, MEMTXATTRS_UNSPECIFIED, &res); 573 } 574 if (res != MEMTX_OK) { 575 return false; 576 } else { 577 return true; 578 } 579 } 580 581 static bool process_mapd(GICv3ITSState *s, uint64_t value, uint32_t offset) 582 { 583 AddressSpace *as = &s->gicv3->dma_as; 584 uint32_t devid; 585 uint8_t size; 586 uint64_t itt_addr; 587 bool valid; 588 MemTxResult res = MEMTX_OK; 589 bool result = false; 590 591 devid = ((value & DEVID_MASK) >> DEVID_SHIFT); 592 593 offset += NUM_BYTES_IN_DW; 594 value = address_space_ldq_le(as, s->cq.base_addr + offset, 595 MEMTXATTRS_UNSPECIFIED, &res); 596 597 if (res != MEMTX_OK) { 598 return result; 599 } 600 601 size = (value & SIZE_MASK); 602 603 offset += NUM_BYTES_IN_DW; 604 value = address_space_ldq_le(as, s->cq.base_addr + offset, 605 MEMTXATTRS_UNSPECIFIED, &res); 606 607 if (res != MEMTX_OK) { 608 return result; 609 } 610 611 itt_addr = (value & ITTADDR_MASK) >> ITTADDR_SHIFT; 612 613 valid = (value & CMD_FIELD_VALID_MASK); 614 615 if ((devid >= s->dt.num_ids) || 616 (size > FIELD_EX64(s->typer, GITS_TYPER, IDBITS))) { 617 qemu_log_mask(LOG_GUEST_ERROR, 618 "ITS MAPD: invalid device table attributes " 619 "devid %d or size %d\n", devid, size); 620 /* 621 * in this implementation, in case of error 622 * we ignore this command and move onto the next 623 * command in the queue 624 */ 625 } else { 626 result = update_dte(s, devid, valid, size, itt_addr); 627 } 628 629 return result; 630 } 631 632 /* 633 * Current implementation blocks until all 634 * commands are processed 635 */ 636 static void process_cmdq(GICv3ITSState *s) 637 { 638 uint32_t wr_offset = 0; 639 uint32_t rd_offset = 0; 640 uint32_t cq_offset = 0; 641 uint64_t data; 642 AddressSpace *as = &s->gicv3->dma_as; 643 MemTxResult res = MEMTX_OK; 644 bool result = true; 645 uint8_t cmd; 646 int i; 647 648 if (!(s->ctlr & R_GITS_CTLR_ENABLED_MASK)) { 649 return; 650 } 651 652 wr_offset = FIELD_EX64(s->cwriter, GITS_CWRITER, OFFSET); 653 654 if (wr_offset >= s->cq.num_entries) { 655 qemu_log_mask(LOG_GUEST_ERROR, 656 "%s: invalid write offset " 657 "%d\n", __func__, wr_offset); 658 return; 659 } 660 661 rd_offset = FIELD_EX64(s->creadr, GITS_CREADR, OFFSET); 662 663 if (rd_offset >= s->cq.num_entries) { 664 qemu_log_mask(LOG_GUEST_ERROR, 665 "%s: invalid read offset " 666 "%d\n", __func__, rd_offset); 667 return; 668 } 669 670 while (wr_offset != rd_offset) { 671 cq_offset = (rd_offset * GITS_CMDQ_ENTRY_SIZE); 672 data = address_space_ldq_le(as, s->cq.base_addr + cq_offset, 673 MEMTXATTRS_UNSPECIFIED, &res); 674 if (res != MEMTX_OK) { 675 result = false; 676 } 677 cmd = (data & CMD_MASK); 678 679 switch (cmd) { 680 case GITS_CMD_INT: 681 res = process_its_cmd(s, data, cq_offset, INTERRUPT); 682 break; 683 case GITS_CMD_CLEAR: 684 res = process_its_cmd(s, data, cq_offset, CLEAR); 685 break; 686 case GITS_CMD_SYNC: 687 /* 688 * Current implementation makes a blocking synchronous call 689 * for every command issued earlier, hence the internal state 690 * is already consistent by the time SYNC command is executed. 691 * Hence no further processing is required for SYNC command. 692 */ 693 break; 694 case GITS_CMD_MAPD: 695 result = process_mapd(s, data, cq_offset); 696 break; 697 case GITS_CMD_MAPC: 698 result = process_mapc(s, cq_offset); 699 break; 700 case GITS_CMD_MAPTI: 701 result = process_mapti(s, data, cq_offset, false); 702 break; 703 case GITS_CMD_MAPI: 704 result = process_mapti(s, data, cq_offset, true); 705 break; 706 case GITS_CMD_DISCARD: 707 result = process_its_cmd(s, data, cq_offset, DISCARD); 708 break; 709 case GITS_CMD_INV: 710 case GITS_CMD_INVALL: 711 /* 712 * Current implementation doesn't cache any ITS tables, 713 * but the calculated lpi priority information. We only 714 * need to trigger lpi priority re-calculation to be in 715 * sync with LPI config table or pending table changes. 716 */ 717 for (i = 0; i < s->gicv3->num_cpu; i++) { 718 gicv3_redist_update_lpi(&s->gicv3->cpu[i]); 719 } 720 break; 721 default: 722 break; 723 } 724 if (result) { 725 rd_offset++; 726 rd_offset %= s->cq.num_entries; 727 s->creadr = FIELD_DP64(s->creadr, GITS_CREADR, OFFSET, rd_offset); 728 } else { 729 /* 730 * in this implementation, in case of dma read/write error 731 * we stall the command processing 732 */ 733 s->creadr = FIELD_DP64(s->creadr, GITS_CREADR, STALLED, 1); 734 qemu_log_mask(LOG_GUEST_ERROR, 735 "%s: %x cmd processing failed\n", __func__, cmd); 736 break; 737 } 738 } 739 } 740 741 /* 742 * This function extracts the ITS Device and Collection table specific 743 * parameters (like base_addr, size etc) from GITS_BASER register. 744 * It is called during ITS enable and also during post_load migration 745 */ 746 static void extract_table_params(GICv3ITSState *s) 747 { 748 uint16_t num_pages = 0; 749 uint8_t page_sz_type; 750 uint8_t type; 751 uint32_t page_sz = 0; 752 uint64_t value; 753 754 for (int i = 0; i < 8; i++) { 755 TableDesc *td; 756 int idbits; 757 758 value = s->baser[i]; 759 760 if (!value) { 761 continue; 762 } 763 764 page_sz_type = FIELD_EX64(value, GITS_BASER, PAGESIZE); 765 766 switch (page_sz_type) { 767 case 0: 768 page_sz = GITS_PAGE_SIZE_4K; 769 break; 770 771 case 1: 772 page_sz = GITS_PAGE_SIZE_16K; 773 break; 774 775 case 2: 776 case 3: 777 page_sz = GITS_PAGE_SIZE_64K; 778 break; 779 780 default: 781 g_assert_not_reached(); 782 } 783 784 num_pages = FIELD_EX64(value, GITS_BASER, SIZE) + 1; 785 786 type = FIELD_EX64(value, GITS_BASER, TYPE); 787 788 switch (type) { 789 case GITS_BASER_TYPE_DEVICE: 790 td = &s->dt; 791 idbits = FIELD_EX64(s->typer, GITS_TYPER, DEVBITS) + 1; 792 break; 793 case GITS_BASER_TYPE_COLLECTION: 794 td = &s->ct; 795 if (FIELD_EX64(s->typer, GITS_TYPER, CIL)) { 796 idbits = FIELD_EX64(s->typer, GITS_TYPER, CIDBITS) + 1; 797 } else { 798 /* 16-bit CollectionId supported when CIL == 0 */ 799 idbits = 16; 800 } 801 break; 802 default: 803 /* 804 * GITS_BASER<n>.TYPE is read-only, so GITS_BASER_RO_MASK 805 * ensures we will only see type values corresponding to 806 * the values set up in gicv3_its_reset(). 807 */ 808 g_assert_not_reached(); 809 } 810 811 memset(td, 0, sizeof(*td)); 812 td->valid = FIELD_EX64(value, GITS_BASER, VALID); 813 /* 814 * If GITS_BASER<n>.Valid is 0 for any <n> then we will not process 815 * interrupts. (GITS_TYPER.HCC is 0 for this implementation, so we 816 * do not have a special case where the GITS_BASER<n>.Valid bit is 0 817 * for the register corresponding to the Collection table but we 818 * still have to process interrupts using non-memory-backed 819 * Collection table entries.) 820 */ 821 if (!td->valid) { 822 continue; 823 } 824 td->page_sz = page_sz; 825 td->indirect = FIELD_EX64(value, GITS_BASER, INDIRECT); 826 td->entry_sz = FIELD_EX64(value, GITS_BASER, ENTRYSIZE) + 1; 827 td->base_addr = baser_base_addr(value, page_sz); 828 if (!td->indirect) { 829 td->num_entries = (num_pages * page_sz) / td->entry_sz; 830 } else { 831 td->num_entries = (((num_pages * page_sz) / 832 L1TABLE_ENTRY_SIZE) * 833 (page_sz / td->entry_sz)); 834 } 835 td->num_ids = 1ULL << idbits; 836 } 837 } 838 839 static void extract_cmdq_params(GICv3ITSState *s) 840 { 841 uint16_t num_pages = 0; 842 uint64_t value = s->cbaser; 843 844 num_pages = FIELD_EX64(value, GITS_CBASER, SIZE) + 1; 845 846 memset(&s->cq, 0 , sizeof(s->cq)); 847 s->cq.valid = FIELD_EX64(value, GITS_CBASER, VALID); 848 849 if (s->cq.valid) { 850 s->cq.num_entries = (num_pages * GITS_PAGE_SIZE_4K) / 851 GITS_CMDQ_ENTRY_SIZE; 852 s->cq.base_addr = FIELD_EX64(value, GITS_CBASER, PHYADDR); 853 s->cq.base_addr <<= R_GITS_CBASER_PHYADDR_SHIFT; 854 } 855 } 856 857 static MemTxResult gicv3_its_translation_write(void *opaque, hwaddr offset, 858 uint64_t data, unsigned size, 859 MemTxAttrs attrs) 860 { 861 GICv3ITSState *s = (GICv3ITSState *)opaque; 862 bool result = true; 863 uint32_t devid = 0; 864 865 switch (offset) { 866 case GITS_TRANSLATER: 867 if (s->ctlr & R_GITS_CTLR_ENABLED_MASK) { 868 devid = attrs.requester_id; 869 result = process_its_cmd(s, data, devid, NONE); 870 } 871 break; 872 default: 873 break; 874 } 875 876 if (result) { 877 return MEMTX_OK; 878 } else { 879 return MEMTX_ERROR; 880 } 881 } 882 883 static bool its_writel(GICv3ITSState *s, hwaddr offset, 884 uint64_t value, MemTxAttrs attrs) 885 { 886 bool result = true; 887 int index; 888 889 switch (offset) { 890 case GITS_CTLR: 891 if (value & R_GITS_CTLR_ENABLED_MASK) { 892 s->ctlr |= R_GITS_CTLR_ENABLED_MASK; 893 extract_table_params(s); 894 extract_cmdq_params(s); 895 s->creadr = 0; 896 process_cmdq(s); 897 } else { 898 s->ctlr &= ~R_GITS_CTLR_ENABLED_MASK; 899 } 900 break; 901 case GITS_CBASER: 902 /* 903 * IMPDEF choice:- GITS_CBASER register becomes RO if ITS is 904 * already enabled 905 */ 906 if (!(s->ctlr & R_GITS_CTLR_ENABLED_MASK)) { 907 s->cbaser = deposit64(s->cbaser, 0, 32, value); 908 s->creadr = 0; 909 s->cwriter = s->creadr; 910 } 911 break; 912 case GITS_CBASER + 4: 913 /* 914 * IMPDEF choice:- GITS_CBASER register becomes RO if ITS is 915 * already enabled 916 */ 917 if (!(s->ctlr & R_GITS_CTLR_ENABLED_MASK)) { 918 s->cbaser = deposit64(s->cbaser, 32, 32, value); 919 s->creadr = 0; 920 s->cwriter = s->creadr; 921 } 922 break; 923 case GITS_CWRITER: 924 s->cwriter = deposit64(s->cwriter, 0, 32, 925 (value & ~R_GITS_CWRITER_RETRY_MASK)); 926 if (s->cwriter != s->creadr) { 927 process_cmdq(s); 928 } 929 break; 930 case GITS_CWRITER + 4: 931 s->cwriter = deposit64(s->cwriter, 32, 32, value); 932 break; 933 case GITS_CREADR: 934 if (s->gicv3->gicd_ctlr & GICD_CTLR_DS) { 935 s->creadr = deposit64(s->creadr, 0, 32, 936 (value & ~R_GITS_CREADR_STALLED_MASK)); 937 } else { 938 /* RO register, ignore the write */ 939 qemu_log_mask(LOG_GUEST_ERROR, 940 "%s: invalid guest write to RO register at offset " 941 TARGET_FMT_plx "\n", __func__, offset); 942 } 943 break; 944 case GITS_CREADR + 4: 945 if (s->gicv3->gicd_ctlr & GICD_CTLR_DS) { 946 s->creadr = deposit64(s->creadr, 32, 32, value); 947 } else { 948 /* RO register, ignore the write */ 949 qemu_log_mask(LOG_GUEST_ERROR, 950 "%s: invalid guest write to RO register at offset " 951 TARGET_FMT_plx "\n", __func__, offset); 952 } 953 break; 954 case GITS_BASER ... GITS_BASER + 0x3f: 955 /* 956 * IMPDEF choice:- GITS_BASERn register becomes RO if ITS is 957 * already enabled 958 */ 959 if (!(s->ctlr & R_GITS_CTLR_ENABLED_MASK)) { 960 index = (offset - GITS_BASER) / 8; 961 962 if (offset & 7) { 963 value <<= 32; 964 value &= ~GITS_BASER_RO_MASK; 965 s->baser[index] &= GITS_BASER_RO_MASK | MAKE_64BIT_MASK(0, 32); 966 s->baser[index] |= value; 967 } else { 968 value &= ~GITS_BASER_RO_MASK; 969 s->baser[index] &= GITS_BASER_RO_MASK | MAKE_64BIT_MASK(32, 32); 970 s->baser[index] |= value; 971 } 972 } 973 break; 974 case GITS_IIDR: 975 case GITS_IDREGS ... GITS_IDREGS + 0x2f: 976 /* RO registers, ignore the write */ 977 qemu_log_mask(LOG_GUEST_ERROR, 978 "%s: invalid guest write to RO register at offset " 979 TARGET_FMT_plx "\n", __func__, offset); 980 break; 981 default: 982 result = false; 983 break; 984 } 985 return result; 986 } 987 988 static bool its_readl(GICv3ITSState *s, hwaddr offset, 989 uint64_t *data, MemTxAttrs attrs) 990 { 991 bool result = true; 992 int index; 993 994 switch (offset) { 995 case GITS_CTLR: 996 *data = s->ctlr; 997 break; 998 case GITS_IIDR: 999 *data = gicv3_iidr(); 1000 break; 1001 case GITS_IDREGS ... GITS_IDREGS + 0x2f: 1002 /* ID registers */ 1003 *data = gicv3_idreg(offset - GITS_IDREGS); 1004 break; 1005 case GITS_TYPER: 1006 *data = extract64(s->typer, 0, 32); 1007 break; 1008 case GITS_TYPER + 4: 1009 *data = extract64(s->typer, 32, 32); 1010 break; 1011 case GITS_CBASER: 1012 *data = extract64(s->cbaser, 0, 32); 1013 break; 1014 case GITS_CBASER + 4: 1015 *data = extract64(s->cbaser, 32, 32); 1016 break; 1017 case GITS_CREADR: 1018 *data = extract64(s->creadr, 0, 32); 1019 break; 1020 case GITS_CREADR + 4: 1021 *data = extract64(s->creadr, 32, 32); 1022 break; 1023 case GITS_CWRITER: 1024 *data = extract64(s->cwriter, 0, 32); 1025 break; 1026 case GITS_CWRITER + 4: 1027 *data = extract64(s->cwriter, 32, 32); 1028 break; 1029 case GITS_BASER ... GITS_BASER + 0x3f: 1030 index = (offset - GITS_BASER) / 8; 1031 if (offset & 7) { 1032 *data = extract64(s->baser[index], 32, 32); 1033 } else { 1034 *data = extract64(s->baser[index], 0, 32); 1035 } 1036 break; 1037 default: 1038 result = false; 1039 break; 1040 } 1041 return result; 1042 } 1043 1044 static bool its_writell(GICv3ITSState *s, hwaddr offset, 1045 uint64_t value, MemTxAttrs attrs) 1046 { 1047 bool result = true; 1048 int index; 1049 1050 switch (offset) { 1051 case GITS_BASER ... GITS_BASER + 0x3f: 1052 /* 1053 * IMPDEF choice:- GITS_BASERn register becomes RO if ITS is 1054 * already enabled 1055 */ 1056 if (!(s->ctlr & R_GITS_CTLR_ENABLED_MASK)) { 1057 index = (offset - GITS_BASER) / 8; 1058 s->baser[index] &= GITS_BASER_RO_MASK; 1059 s->baser[index] |= (value & ~GITS_BASER_RO_MASK); 1060 } 1061 break; 1062 case GITS_CBASER: 1063 /* 1064 * IMPDEF choice:- GITS_CBASER register becomes RO if ITS is 1065 * already enabled 1066 */ 1067 if (!(s->ctlr & R_GITS_CTLR_ENABLED_MASK)) { 1068 s->cbaser = value; 1069 s->creadr = 0; 1070 s->cwriter = s->creadr; 1071 } 1072 break; 1073 case GITS_CWRITER: 1074 s->cwriter = value & ~R_GITS_CWRITER_RETRY_MASK; 1075 if (s->cwriter != s->creadr) { 1076 process_cmdq(s); 1077 } 1078 break; 1079 case GITS_CREADR: 1080 if (s->gicv3->gicd_ctlr & GICD_CTLR_DS) { 1081 s->creadr = value & ~R_GITS_CREADR_STALLED_MASK; 1082 } else { 1083 /* RO register, ignore the write */ 1084 qemu_log_mask(LOG_GUEST_ERROR, 1085 "%s: invalid guest write to RO register at offset " 1086 TARGET_FMT_plx "\n", __func__, offset); 1087 } 1088 break; 1089 case GITS_TYPER: 1090 /* RO registers, ignore the write */ 1091 qemu_log_mask(LOG_GUEST_ERROR, 1092 "%s: invalid guest write to RO register at offset " 1093 TARGET_FMT_plx "\n", __func__, offset); 1094 break; 1095 default: 1096 result = false; 1097 break; 1098 } 1099 return result; 1100 } 1101 1102 static bool its_readll(GICv3ITSState *s, hwaddr offset, 1103 uint64_t *data, MemTxAttrs attrs) 1104 { 1105 bool result = true; 1106 int index; 1107 1108 switch (offset) { 1109 case GITS_TYPER: 1110 *data = s->typer; 1111 break; 1112 case GITS_BASER ... GITS_BASER + 0x3f: 1113 index = (offset - GITS_BASER) / 8; 1114 *data = s->baser[index]; 1115 break; 1116 case GITS_CBASER: 1117 *data = s->cbaser; 1118 break; 1119 case GITS_CREADR: 1120 *data = s->creadr; 1121 break; 1122 case GITS_CWRITER: 1123 *data = s->cwriter; 1124 break; 1125 default: 1126 result = false; 1127 break; 1128 } 1129 return result; 1130 } 1131 1132 static MemTxResult gicv3_its_read(void *opaque, hwaddr offset, uint64_t *data, 1133 unsigned size, MemTxAttrs attrs) 1134 { 1135 GICv3ITSState *s = (GICv3ITSState *)opaque; 1136 bool result; 1137 1138 switch (size) { 1139 case 4: 1140 result = its_readl(s, offset, data, attrs); 1141 break; 1142 case 8: 1143 result = its_readll(s, offset, data, attrs); 1144 break; 1145 default: 1146 result = false; 1147 break; 1148 } 1149 1150 if (!result) { 1151 qemu_log_mask(LOG_GUEST_ERROR, 1152 "%s: invalid guest read at offset " TARGET_FMT_plx 1153 "size %u\n", __func__, offset, size); 1154 /* 1155 * The spec requires that reserved registers are RAZ/WI; 1156 * so use false returns from leaf functions as a way to 1157 * trigger the guest-error logging but don't return it to 1158 * the caller, or we'll cause a spurious guest data abort. 1159 */ 1160 *data = 0; 1161 } 1162 return MEMTX_OK; 1163 } 1164 1165 static MemTxResult gicv3_its_write(void *opaque, hwaddr offset, uint64_t data, 1166 unsigned size, MemTxAttrs attrs) 1167 { 1168 GICv3ITSState *s = (GICv3ITSState *)opaque; 1169 bool result; 1170 1171 switch (size) { 1172 case 4: 1173 result = its_writel(s, offset, data, attrs); 1174 break; 1175 case 8: 1176 result = its_writell(s, offset, data, attrs); 1177 break; 1178 default: 1179 result = false; 1180 break; 1181 } 1182 1183 if (!result) { 1184 qemu_log_mask(LOG_GUEST_ERROR, 1185 "%s: invalid guest write at offset " TARGET_FMT_plx 1186 "size %u\n", __func__, offset, size); 1187 /* 1188 * The spec requires that reserved registers are RAZ/WI; 1189 * so use false returns from leaf functions as a way to 1190 * trigger the guest-error logging but don't return it to 1191 * the caller, or we'll cause a spurious guest data abort. 1192 */ 1193 } 1194 return MEMTX_OK; 1195 } 1196 1197 static const MemoryRegionOps gicv3_its_control_ops = { 1198 .read_with_attrs = gicv3_its_read, 1199 .write_with_attrs = gicv3_its_write, 1200 .valid.min_access_size = 4, 1201 .valid.max_access_size = 8, 1202 .impl.min_access_size = 4, 1203 .impl.max_access_size = 8, 1204 .endianness = DEVICE_NATIVE_ENDIAN, 1205 }; 1206 1207 static const MemoryRegionOps gicv3_its_translation_ops = { 1208 .write_with_attrs = gicv3_its_translation_write, 1209 .valid.min_access_size = 2, 1210 .valid.max_access_size = 4, 1211 .impl.min_access_size = 2, 1212 .impl.max_access_size = 4, 1213 .endianness = DEVICE_NATIVE_ENDIAN, 1214 }; 1215 1216 static void gicv3_arm_its_realize(DeviceState *dev, Error **errp) 1217 { 1218 GICv3ITSState *s = ARM_GICV3_ITS_COMMON(dev); 1219 int i; 1220 1221 for (i = 0; i < s->gicv3->num_cpu; i++) { 1222 if (!(s->gicv3->cpu[i].gicr_typer & GICR_TYPER_PLPIS)) { 1223 error_setg(errp, "Physical LPI not supported by CPU %d", i); 1224 return; 1225 } 1226 } 1227 1228 gicv3_its_init_mmio(s, &gicv3_its_control_ops, &gicv3_its_translation_ops); 1229 1230 address_space_init(&s->gicv3->dma_as, s->gicv3->dma, 1231 "gicv3-its-sysmem"); 1232 1233 /* set the ITS default features supported */ 1234 s->typer = FIELD_DP64(s->typer, GITS_TYPER, PHYSICAL, 1); 1235 s->typer = FIELD_DP64(s->typer, GITS_TYPER, ITT_ENTRY_SIZE, 1236 ITS_ITT_ENTRY_SIZE - 1); 1237 s->typer = FIELD_DP64(s->typer, GITS_TYPER, IDBITS, ITS_IDBITS); 1238 s->typer = FIELD_DP64(s->typer, GITS_TYPER, DEVBITS, ITS_DEVBITS); 1239 s->typer = FIELD_DP64(s->typer, GITS_TYPER, CIL, 1); 1240 s->typer = FIELD_DP64(s->typer, GITS_TYPER, CIDBITS, ITS_CIDBITS); 1241 } 1242 1243 static void gicv3_its_reset(DeviceState *dev) 1244 { 1245 GICv3ITSState *s = ARM_GICV3_ITS_COMMON(dev); 1246 GICv3ITSClass *c = ARM_GICV3_ITS_GET_CLASS(s); 1247 1248 c->parent_reset(dev); 1249 1250 /* Quiescent bit reset to 1 */ 1251 s->ctlr = FIELD_DP32(s->ctlr, GITS_CTLR, QUIESCENT, 1); 1252 1253 /* 1254 * setting GITS_BASER0.Type = 0b001 (Device) 1255 * GITS_BASER1.Type = 0b100 (Collection Table) 1256 * GITS_BASER<n>.Type,where n = 3 to 7 are 0b00 (Unimplemented) 1257 * GITS_BASER<0,1>.Page_Size = 64KB 1258 * and default translation table entry size to 16 bytes 1259 */ 1260 s->baser[0] = FIELD_DP64(s->baser[0], GITS_BASER, TYPE, 1261 GITS_BASER_TYPE_DEVICE); 1262 s->baser[0] = FIELD_DP64(s->baser[0], GITS_BASER, PAGESIZE, 1263 GITS_BASER_PAGESIZE_64K); 1264 s->baser[0] = FIELD_DP64(s->baser[0], GITS_BASER, ENTRYSIZE, 1265 GITS_DTE_SIZE - 1); 1266 1267 s->baser[1] = FIELD_DP64(s->baser[1], GITS_BASER, TYPE, 1268 GITS_BASER_TYPE_COLLECTION); 1269 s->baser[1] = FIELD_DP64(s->baser[1], GITS_BASER, PAGESIZE, 1270 GITS_BASER_PAGESIZE_64K); 1271 s->baser[1] = FIELD_DP64(s->baser[1], GITS_BASER, ENTRYSIZE, 1272 GITS_CTE_SIZE - 1); 1273 } 1274 1275 static void gicv3_its_post_load(GICv3ITSState *s) 1276 { 1277 if (s->ctlr & R_GITS_CTLR_ENABLED_MASK) { 1278 extract_table_params(s); 1279 extract_cmdq_params(s); 1280 } 1281 } 1282 1283 static Property gicv3_its_props[] = { 1284 DEFINE_PROP_LINK("parent-gicv3", GICv3ITSState, gicv3, "arm-gicv3", 1285 GICv3State *), 1286 DEFINE_PROP_END_OF_LIST(), 1287 }; 1288 1289 static void gicv3_its_class_init(ObjectClass *klass, void *data) 1290 { 1291 DeviceClass *dc = DEVICE_CLASS(klass); 1292 GICv3ITSClass *ic = ARM_GICV3_ITS_CLASS(klass); 1293 GICv3ITSCommonClass *icc = ARM_GICV3_ITS_COMMON_CLASS(klass); 1294 1295 dc->realize = gicv3_arm_its_realize; 1296 device_class_set_props(dc, gicv3_its_props); 1297 device_class_set_parent_reset(dc, gicv3_its_reset, &ic->parent_reset); 1298 icc->post_load = gicv3_its_post_load; 1299 } 1300 1301 static const TypeInfo gicv3_its_info = { 1302 .name = TYPE_ARM_GICV3_ITS, 1303 .parent = TYPE_ARM_GICV3_ITS_COMMON, 1304 .instance_size = sizeof(GICv3ITSState), 1305 .class_init = gicv3_its_class_init, 1306 .class_size = sizeof(GICv3ITSClass), 1307 }; 1308 1309 static void gicv3_its_register_types(void) 1310 { 1311 type_register_static(&gicv3_its_info); 1312 } 1313 1314 type_init(gicv3_its_register_types) 1315