Skip to content

Diag log - #46

Draft
pawarai123 wants to merge 19 commits into
qualcomm-linux:qcom-nextfrom
pawarai123:diag-log
Draft

pawarai123 wants to merge 19 commits into
qualcomm-linux:qcom-nextfrom
pawarai123:diag-log

Conversation

@pawarai123

Copy link
Copy Markdown
Contributor

No description provided.

CFG_QCOM_RPMH_CLIENT ?= n
CFG_QCOM_PAS_PTA ?= n

CFG_QCOM_DIAG_LOG ?= $(CFG_TEE_CORE_DEBUG)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Functional bug: enabling diag log on a platform that lacks TCSR_BOOT_MISC_DETECT breaks the debug build.

This enables CFG_QCOM_DIAG_LOG (defaulting to CFG_TEE_CORE_DEBUG), which compiles diag_log.c. That file uses TCSR_BOOT_MISC_DETECT at file scope (in register_phys_mem_pgdir(...)), but neither bruin/shikra/target_config.h nor bruin/arch_config.h defines it (only bobcat/hoya/cacao do). Debug builds for shikra fail to compile. Same issue for nord (wildcat/nord/target.mk, no define in wildcat/arch_config.h or wildcat/nord/target_config.h).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Harshal/Pawan, please help to address this comment.
Is this same issue where we need to configure IMEM to enable TZ log?

…files

Nord was the only Wildcat chip in the tree, so its GIC base addresses
and DARE-TZ TZDRAM region settings were placed in the shared Wildcat
architecture layer.  Adding a second Wildcat chip with different
addresses makes the architecture layer the wrong home for them.

Move GICD_BASE and GICR_BASE from arch_config.h to
nord/target_config.h, and move the DARE-TZ TZDRAM region configuration
from qcom-arch.mk to nord/target.mk, so the shared Wildcat layer stays
chip-agnostic.  Add SPDX licence identifier to qcom-arch.mk while there.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Tested-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Cacao is a Qualcomm XR chipset in the Wildcat architecture family,
featuring an octa-core Oryon CPU, a GICv4 interrupt controller, and
DARE-TZ in-line memory encryption managed by the TME root-of-trust.
OP-TEE runs in a DARE-TZ protected DRAM region and does not need a
separate DARE driver.

Testing: Tested on Rumi.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Tested-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Add PLATFORM=qcom-cacao build to the CI.

Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Shikra is a Qualcomm IoT chipset in the Bruin architecture family,
featuring a quad-core Cortex-A55 CPU and a GICv3 interrupt controller.

Tested optee boot-up on Shikra board.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Tested-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Add PLATFORM=qcom-shikra build to the CI.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Fix the address mappings for DRAM on Nord IQ-10. DRAM0 has a size of
0x8000 0000 while DRAM1 starts at 0x8 8000 0000 with a size of
0x7 8000 0000. Also, there exists a DRAM2 region which the Linux kernel
maps as HIGHMEM for allocating memory for userspace applications.
Since this region starting at 0x88 0000 0000 is not mapped by OP-TEE,
TEE_IOC_SHM_REGISTER ioctl fails because OP-TEE doesn't recognize it as
Non-secure memory.

Validated by running xtest 1002 after building OP-TEE with
CFG_TEE_CORE_EMBED_INTERNAL_TESTS=y which was failing otherwise.

Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Add a pseudo-TA for the Qualcomm Inline Crypto Engine (ICE) that lets the
kernel dm-crypt/inline-crypt path program raw software keys into ICE key
slots for inline storage encryption.

Two commands are exposed:
  - PTA_CMD_ICE_INVALIDATE_KEY: wipe a key slot with random data.
  - PTA_CMD_ICE_SET_CONFIG_KEY: program key/salt, cipher mode and
    data-unit size for AES-XTS-128/256 and AES-CBC-128/256.

Only the REE kernel may open a session on this PTA. The PTA is gated by
CFG_ICE_FS_ENC_PTA and is not built unless a platform enables it.

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Turn on CFG_ICE_FS_ENC_PTA for ipq52xx and ipq96xx, which carry the SDCC
ICE block used for eMMC inline encryption, and point the generic
ICE_LUT_KEYS at the SDCC LUT-keys register region.

Testing:
Booted to the kernel, dispatched an ICE software-key config from the
kernel to this PTA, then wrote and read back a file on the encrypted
filesystem and confirmed matching md5sums.

Tested-on: IPQ52xx, IPQ96xx
Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
This file already lives under drivers/clk/qcom/, so repeating qcom in
its own name is redundant, and inconsistent with how other vendor
subdirectories (sam/, stm32) name their own files.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:opus-5

Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Vinod Kumar Amanaganti <vinoda@qti.qualcomm.com>
The QUP SE clock driver's CX/MX voltage vote needs a rail's supported
corner ordinals, which for ARC resources live in the auxiliary data
blob RPMh commands index into rather than a raw voltage. Add
cmd_db_get_aux() to fetch it by resource ID.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:opus-5

Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Vinod Kumar Amanaganti <vinoda@qti.qualcomm.com>
Some clock rates need a higher CX/MX voltage corner than others, and
a corner may be shared by multiple RCGs; rail_vote() refcounts per
corner over RPMh so each rail is only raised for as long as some
caller actually needs it, and CX/MX are resolved independently since
they don't necessarily share the same hlvl encoding.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:opus-5
Assisted-by: Claude:sonnet-5

Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Vinod Kumar Amanaganti <vinoda@qti.qualcomm.com>
Lemans has no secure DT, so register each QUPv3 SE clock as a plain
struct clk, modeling the PLL/RCG/branch as separate objects so the
generic framework's own refcounting governs each PLL vote.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:opus-5
Assisted-by: Claude:sonnet-5

Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Vinod Kumar Amanaganti <vinoda@qti.qualcomm.com>
The RPMh command MSGID encodes a MSG_LENGTH field describing the
payload length, in bytes, of the command. This field was hardcoded
to 1 which is leading to unpredictable behavior on the
AOP side (including the command never being acknowledged, causing timeouts).

Changing it to 8 (the correct length for the single 32-bit data
word every RPMh command carries).
Using MSGID_WRITE since it's a write command.

Fixes: b6ff325 (drivers: qcom: rpmh: add RPMH client driver)
Signed-off-by: Shivam Sanjay <shivsanj@qti.qualcomm.com>
Reviewed-by: Dinesh Choudhary <idinesh@qti.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Add PAS support for the ipq96xx CDSP (Turing/NSP) remote processor:
load the firmware and its DTB, program the QDSP6 boot registers, run
the two-stage boot FSM, and handle shutdown/reset via GCC. Also adds
the Turing clock bring-up.

ipq96xx gates these windows to secure-only accesses via XPU, so a new
qcom_pas_data::secure flag maps them MEM_AREA_IO_SEC instead of
MEM_AREA_IO_NSEC; other platforms are unaffected.

Testing:
Built for PLATFORM_FLAVOR=ipq96xx and kodiak with aarch64-linux-gnu-.
CDSP boot verified on ipq96xx hardware.

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Enable the PAS PTA and Qualcomm clock driver on ipq96xx, add the CDSP
(Turing/NSP) register window bases (Turing, GCC, MPM2, TCSR), and
register the PAS pseudo TA as an in-tree early TA.

Testing:
Built for PLATFORM_FLAVOR=ipq96xx with aarch64-linux-gnu-; the CDSP PAS
and clock objects link into the image and the PAS early TA is signed.

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Add the platform configuration required by the diagnostic ring buffer
on the Wildcat architecture, including the buffer layout shared by all
Wildcat targets and the IMEM base and size for Nord.

Default CFG_QCOM_DIAG_LOG to CFG_TEE_CORE_DEBUG so that the buffer
is enabled on debug builds.

Change-Id: I440a6aeb25624e6c87877faad774478fb491dca2
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Cacao already carries IMEM_BASE and IMEM_SIZE in its target_config.h,
and the Wildcat arch_config.h now defines the shared buffer layout
(IMEM_DIAG_OFFSET, DIAG_SIZE, DIAG_BASE, DIAG_LOG_START_INFO).

Default CFG_QCOM_DIAG_LOG to CFG_TEE_CORE_DEBUG so that the buffer
is enabled on debug builds.

Change-Id: Ia472203bda34c738e36e06b65326d42a83ee421d
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Shikra already carries IMEM_BASE and IMEM_SIZE in its target_config.h.
Add the shared buffer layout macros (IMEM_DIAG_OFFSET, DIAG_SIZE,
DIAG_BASE, DIAG_LOG_START_INFO) to the Bruin arch_config.h, and
default CFG_QCOM_DIAG_LOG to CFG_TEE_CORE_DEBUG so the buffer is
enabled on debug builds.

Change-Id: Ie924e5f56d80a4103be60c5061fbfeadb69b5635
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Parse the OP-TEE diagnostic ring buffer written into IMEM by
diag_log.c. Handles full RAM dumps (OCIMEM.BIN) with either a
known DIAG_BASE offset (--offset) or automatic magic-scan mode
(--scan), as well as pre-extracted DIAG region slices.

Change-Id: I49a1145c9983d32b2c3ac8b50a6ec4916de606e0
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants