2 * SPDX-License-Identifier: BSD-2-Clause
4 * Copyright (c) 2015 Neel Natu <neel@freebsd.org>
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 #include <sys/param.h>
30 #include <sys/types.h>
34 #include <machine/vmm.h>
52 #define BOOTROM_SIZE (16 * 1024 * 1024) /* 16 MB */
55 * ROM region is 16 MB at the top of 4GB ("low") memory.
57 * The size is limited so it doesn't encroach into reserved MMIO space (e.g.,
60 * It is allocated in page-multiple blocks on a first-come first-serve basis,
61 * from high to low, during initialization, and does not change at runtime.
63 static char *romptr; /* Pointer to userspace-mapped bootrom region. */
64 static vm_paddr_t gpa_base; /* GPA of low end of region. */
65 static vm_paddr_t gpa_allocbot; /* Low GPA of free region. */
66 static vm_paddr_t gpa_alloctop; /* High GPA, minus 1, of free region. */
68 #define CFI_BCS_WRITE_BYTE 0x10
69 #define CFI_BCS_CLEAR_STATUS 0x50
70 #define CFI_BCS_READ_STATUS 0x70
71 #define CFI_BCS_READ_ARRAY 0xff
73 static struct bootrom_var_state {
78 } var = { NULL, 0, 0, CFI_BCS_READ_ARRAY };
81 * Emulate just those CFI basic commands that will convince EDK II
82 * that the Firmware Volume area is writable and persistent.
85 bootrom_var_mem_handler(struct vcpu *vcpu __unused, int dir, uint64_t addr,
86 int size, uint64_t *val, void *arg1 __unused, long arg2 __unused)
90 offset = addr - var.gpa;
91 if (offset + size > var.size || offset < 0 || offset + size <= offset)
94 if (dir == MEM_F_WRITE) {
96 case CFI_BCS_WRITE_BYTE:
97 memcpy(var.mmap + offset, val, size);
98 var.cmd = CFI_BCS_READ_ARRAY;
101 var.cmd = *(uint8_t *)val;
105 case CFI_BCS_CLEAR_STATUS:
106 case CFI_BCS_READ_STATUS:
107 memset(val, 0, size);
108 var.cmd = CFI_BCS_READ_ARRAY;
111 memcpy(val, var.mmap + offset, size);
119 init_bootrom(struct vmctx *ctx)
121 romptr = vm_create_devmem(ctx, VM_BOOTROM, "bootrom", BOOTROM_SIZE);
122 if (romptr == MAP_FAILED)
123 err(4, "%s: vm_create_devmem", __func__);
124 gpa_base = (1ULL << 32) - BOOTROM_SIZE;
125 gpa_allocbot = gpa_base;
126 gpa_alloctop = (1ULL << 32) - 1;
130 bootrom_alloc(struct vmctx *ctx, size_t len, int prot, int flags,
131 char **region_out, uint64_t *gpa_out)
133 static const int bootrom_valid_flags = BOOTROM_ALLOC_TOP;
138 if (flags & ~bootrom_valid_flags) {
139 warnx("%s: Invalid flags: %x", __func__,
140 flags & ~bootrom_valid_flags);
143 if (prot & ~_PROT_ALL) {
144 warnx("%s: Invalid protection: %x", __func__,
149 if (len == 0 || len > BOOTROM_SIZE) {
150 warnx("ROM size %zu is invalid", len);
153 if (len & PAGE_MASK) {
154 warnx("ROM size %zu is not a multiple of the page size",
159 if (flags & BOOTROM_ALLOC_TOP) {
160 gpa = (gpa_alloctop - len) + 1;
161 if (gpa < gpa_allocbot) {
162 warnx("No room for %zu ROM in bootrom region", len);
167 if (gpa > (gpa_alloctop - len) + 1) {
168 warnx("No room for %zu ROM in bootrom region", len);
173 segoff = gpa - gpa_base;
174 if (vm_mmap_memseg(ctx, gpa, VM_BOOTROM, segoff, len, prot) != 0) {
176 warn("%s: vm_mmap_mapseg", __func__);
180 if (flags & BOOTROM_ALLOC_TOP)
181 gpa_alloctop = gpa - 1;
183 gpa_allocbot = gpa + len;
185 *region_out = romptr + segoff;
192 bootrom_loadrom(struct vmctx *ctx, const nvlist_t *nvl)
196 off_t rom_size, var_size, total_size;
198 int fd, varfd, i, rv;
199 const char *bootrom, *varfile;
204 bootrom = get_config_value_node(nvl, "bootrom");
205 if (bootrom == NULL) {
210 * get_config_value_node may use a thread local buffer to return
211 * variables. So, when we query the second variable, the first variable
212 * might get overwritten. For that reason, the bootrom should be
215 romfile = strdup(bootrom);
216 if (romfile == NULL) {
220 fd = open(romfile, O_RDONLY);
222 EPRINTLN("Error opening bootrom \"%s\": %s",
223 romfile, strerror(errno));
227 if (fstat(fd, &sbuf) < 0) {
228 EPRINTLN("Could not fstat bootrom file \"%s\": %s", romfile,
233 rom_size = sbuf.st_size;
235 varfile = get_config_value_node(nvl, "bootvars");
237 if (varfile != NULL) {
238 varfd = open(varfile, O_RDWR);
240 EPRINTLN("Error opening bootrom variable file "
241 "\"%s\": %s", varfile, strerror(errno));
245 if (fstat(varfd, &sbuf) < 0) {
247 "Could not fstat bootrom variable file \"%s\": %s",
248 varfile, strerror(errno));
252 var_size = sbuf.st_size;
255 if (var_size > BOOTROM_SIZE ||
256 (var_size != 0 && var_size < PAGE_SIZE)) {
257 EPRINTLN("Invalid bootrom variable size %ld",
262 total_size = rom_size + var_size;
264 if (total_size > BOOTROM_SIZE) {
265 EPRINTLN("Invalid bootrom and variable aggregate size %ld",
270 /* Map the bootrom into the guest address space */
271 if (bootrom_alloc(ctx, rom_size, PROT_READ | PROT_EXEC,
272 BOOTROM_ALLOC_TOP, &ptr, NULL) != 0) {
276 /* Read 'romfile' into the guest address space */
277 for (i = 0; i < rom_size / PAGE_SIZE; i++) {
278 rlen = read(fd, ptr + i * PAGE_SIZE, PAGE_SIZE);
279 if (rlen != PAGE_SIZE) {
280 EPRINTLN("Incomplete read of page %d of bootrom "
281 "file %s: %ld bytes", i, romfile, rlen);
287 var.mmap = mmap(NULL, var_size, PROT_READ | PROT_WRITE,
288 MAP_SHARED, varfd, 0);
289 if (var.mmap == MAP_FAILED)
292 var.gpa = (gpa_alloctop - var_size) + 1;
293 gpa_alloctop = var.gpa - 1;
294 rv = register_mem(&(struct mem_range){
295 .name = "bootrom variable",
297 .handler = bootrom_var_mem_handler,