1cbc5b5f3SJordan Justen /*
2cbc5b5f3SJordan Justen * QEMU PC System Firmware
3cbc5b5f3SJordan Justen *
4cbc5b5f3SJordan Justen * Copyright (c) 2003-2004 Fabrice Bellard
5cbc5b5f3SJordan Justen * Copyright (c) 2011-2012 Intel Corporation
6cbc5b5f3SJordan Justen *
7cbc5b5f3SJordan Justen * Permission is hereby granted, free of charge, to any person obtaining a copy
8cbc5b5f3SJordan Justen * of this software and associated documentation files (the "Software"), to deal
9cbc5b5f3SJordan Justen * in the Software without restriction, including without limitation the rights
10cbc5b5f3SJordan Justen * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
11cbc5b5f3SJordan Justen * copies of the Software, and to permit persons to whom the Software is
12cbc5b5f3SJordan Justen * furnished to do so, subject to the following conditions:
13cbc5b5f3SJordan Justen *
14cbc5b5f3SJordan Justen * The above copyright notice and this permission notice shall be included in
15cbc5b5f3SJordan Justen * all copies or substantial portions of the Software.
16cbc5b5f3SJordan Justen *
17cbc5b5f3SJordan Justen * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
18cbc5b5f3SJordan Justen * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
19cbc5b5f3SJordan Justen * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
20cbc5b5f3SJordan Justen * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
21cbc5b5f3SJordan Justen * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
22cbc5b5f3SJordan Justen * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
23cbc5b5f3SJordan Justen * THE SOFTWARE.
24cbc5b5f3SJordan Justen */
25cbc5b5f3SJordan Justen
26b6a0aa05SPeter Maydell #include "qemu/osdep.h"
27da34e65cSMarkus Armbruster #include "qapi/error.h"
2832cad1ffSPhilippe Mathieu-Daudé #include "system/block-backend.h"
29b4a42f81SPaolo Bonzini #include "qemu/error-report.h"
30922a01a0SMarkus Armbruster #include "qemu/option.h"
31d471bf3eSPaolo Bonzini #include "qemu/units.h"
3283c9f4caSPaolo Bonzini #include "hw/sysbus.h"
33549e984eSSergio Lopez #include "hw/i386/x86.h"
340d09e41aSPaolo Bonzini #include "hw/i386/pc.h"
3583c9f4caSPaolo Bonzini #include "hw/loader.h"
36a27bd6c7SMarkus Armbruster #include "hw/qdev-properties.h"
370d09e41aSPaolo Bonzini #include "hw/block/flash.h"
3832cad1ffSPhilippe Mathieu-Daudé #include "system/kvm.h"
3963cda194SPhilippe Mathieu-Daudé #include "target/i386/sev.h"
40*cb5d65a8SXiaoyao Li #include "kvm/tdx.h"
41cbc5b5f3SJordan Justen
42ebc29e1bSMarkus Armbruster #define FLASH_SECTOR_SIZE 4096
43ebc29e1bSMarkus Armbruster
pc_isa_bios_init(PCMachineState * pcms,MemoryRegion * isa_bios,MemoryRegion * rom_memory,MemoryRegion * flash_mem)44413a6745SMichael Roth static void pc_isa_bios_init(PCMachineState *pcms, MemoryRegion *isa_bios,
45413a6745SMichael Roth MemoryRegion *rom_memory, MemoryRegion *flash_mem)
46bd183c79SJordan Justen {
47bd183c79SJordan Justen int isa_bios_size;
48bd183c79SJordan Justen uint64_t flash_size;
49bd183c79SJordan Justen void *flash_ptr, *isa_bios_ptr;
50bd183c79SJordan Justen
51bd183c79SJordan Justen flash_size = memory_region_size(flash_mem);
52bd183c79SJordan Justen
53bd183c79SJordan Justen /* map the last 128KB of the BIOS in ISA space */
54d471bf3eSPaolo Bonzini isa_bios_size = MIN(flash_size, 128 * KiB);
55413a6745SMichael Roth if (machine_require_guest_memfd(MACHINE(pcms))) {
56413a6745SMichael Roth memory_region_init_ram_guest_memfd(isa_bios, NULL, "isa-bios",
57413a6745SMichael Roth isa_bios_size, &error_fatal);
58413a6745SMichael Roth } else {
5998a99ce0SPeter Maydell memory_region_init_ram(isa_bios, NULL, "isa-bios", isa_bios_size,
60f8ed85acSMarkus Armbruster &error_fatal);
61413a6745SMichael Roth }
62bd183c79SJordan Justen memory_region_add_subregion_overlap(rom_memory,
63bd183c79SJordan Justen 0x100000 - isa_bios_size,
64bd183c79SJordan Justen isa_bios,
65bd183c79SJordan Justen 1);
66bd183c79SJordan Justen
67bd183c79SJordan Justen /* copy ISA rom image from top of flash memory */
68bd183c79SJordan Justen flash_ptr = memory_region_get_ram_ptr(flash_mem);
69bd183c79SJordan Justen isa_bios_ptr = memory_region_get_ram_ptr(isa_bios);
70bd183c79SJordan Justen memcpy(isa_bios_ptr,
71bd183c79SJordan Justen ((uint8_t*)flash_ptr) + (flash_size - isa_bios_size),
72bd183c79SJordan Justen isa_bios_size);
73bd183c79SJordan Justen
74413a6745SMichael Roth if (!machine_require_guest_memfd(current_machine)) {
75bd183c79SJordan Justen memory_region_set_readonly(isa_bios, true);
76bd183c79SJordan Justen }
77413a6745SMichael Roth }
78bd183c79SJordan Justen
pc_pflash_create(PCMachineState * pcms,const char * name,const char * alias_prop_name)79ebc29e1bSMarkus Armbruster static PFlashCFI01 *pc_pflash_create(PCMachineState *pcms,
80ebc29e1bSMarkus Armbruster const char *name,
81ebc29e1bSMarkus Armbruster const char *alias_prop_name)
82ebc29e1bSMarkus Armbruster {
83df707969SMarkus Armbruster DeviceState *dev = qdev_new(TYPE_PFLASH_CFI01);
84637a5acbSLaszlo Ersek
85ebc29e1bSMarkus Armbruster qdev_prop_set_uint64(dev, "sector-length", FLASH_SECTOR_SIZE);
86ebc29e1bSMarkus Armbruster qdev_prop_set_uint8(dev, "width", 1);
87ebc29e1bSMarkus Armbruster qdev_prop_set_string(dev, "name", name);
88d2623129SMarkus Armbruster object_property_add_child(OBJECT(pcms), name, OBJECT(dev));
89ebc29e1bSMarkus Armbruster object_property_add_alias(OBJECT(pcms), alias_prop_name,
90d2623129SMarkus Armbruster OBJECT(dev), "drive");
910b33521eSAlexander Bulekov /*
920b33521eSAlexander Bulekov * The returned reference is tied to the child property and
930b33521eSAlexander Bulekov * will be removed with object_unparent.
940b33521eSAlexander Bulekov */
950b33521eSAlexander Bulekov object_unref(OBJECT(dev));
96ebc29e1bSMarkus Armbruster return PFLASH_CFI01(dev);
97ebc29e1bSMarkus Armbruster }
98637a5acbSLaszlo Ersek
pc_system_flash_create(PCMachineState * pcms)99f2cb9f34SBernhard Beschow void pc_system_flash_create(PCMachineState *pcms)
1000fbe8d7cSBernhard Beschow {
1010fbe8d7cSBernhard Beschow PCMachineClass *pcmc = PC_MACHINE_GET_CLASS(pcms);
1020fbe8d7cSBernhard Beschow
1030fbe8d7cSBernhard Beschow if (pcmc->pci_enabled) {
1040fbe8d7cSBernhard Beschow pcms->flash[0] = pc_pflash_create(pcms, "system.flash0",
1050fbe8d7cSBernhard Beschow "pflash0");
1060fbe8d7cSBernhard Beschow pcms->flash[1] = pc_pflash_create(pcms, "system.flash1",
1070fbe8d7cSBernhard Beschow "pflash1");
1080fbe8d7cSBernhard Beschow }
1090fbe8d7cSBernhard Beschow }
1100fbe8d7cSBernhard Beschow
pc_system_flash_cleanup_unused(PCMachineState * pcms)111f2cb9f34SBernhard Beschow void pc_system_flash_cleanup_unused(PCMachineState *pcms)
112ebc29e1bSMarkus Armbruster {
113ebc29e1bSMarkus Armbruster char *prop_name;
114ebc29e1bSMarkus Armbruster int i;
115ebc29e1bSMarkus Armbruster
116ebc29e1bSMarkus Armbruster assert(PC_MACHINE_GET_CLASS(pcms)->pci_enabled);
117ebc29e1bSMarkus Armbruster
118ebc29e1bSMarkus Armbruster for (i = 0; i < ARRAY_SIZE(pcms->flash); i++) {
11958183abfSPhilippe Mathieu-Daudé if (!qdev_is_realized(DEVICE(pcms->flash[i]))) {
120ebc29e1bSMarkus Armbruster prop_name = g_strdup_printf("pflash%d", i);
121df4fe0b2SMarkus Armbruster object_property_del(OBJECT(pcms), prop_name);
122ebc29e1bSMarkus Armbruster g_free(prop_name);
12358183abfSPhilippe Mathieu-Daudé object_unparent(OBJECT(pcms->flash[i]));
124ebc29e1bSMarkus Armbruster pcms->flash[i] = NULL;
125ebc29e1bSMarkus Armbruster }
126ebc29e1bSMarkus Armbruster }
127ebc29e1bSMarkus Armbruster }
128ebc29e1bSMarkus Armbruster
129ebc29e1bSMarkus Armbruster /*
130ebc29e1bSMarkus Armbruster * Map the pcms->flash[] from 4GiB downward, and realize.
131ebc29e1bSMarkus Armbruster * Map them in descending order, i.e. pcms->flash[0] at the top,
132ebc29e1bSMarkus Armbruster * without gaps.
133ebc29e1bSMarkus Armbruster * Stop at the first pcms->flash[0] lacking a block backend.
134ebc29e1bSMarkus Armbruster * Set each flash's size from its block backend. Fatal error if the
135ebc29e1bSMarkus Armbruster * size isn't a non-zero multiple of 4KiB, or the total size exceeds
1360657c657SErich-McMillan * pcms->max_fw_size.
137637a5acbSLaszlo Ersek *
138ebc29e1bSMarkus Armbruster * If pcms->flash[0] has a block backend, its memory is passed to
139ebc29e1bSMarkus Armbruster * pc_isa_bios_init(). Merging several flash devices for isa-bios is
140637a5acbSLaszlo Ersek * not supported.
141637a5acbSLaszlo Ersek */
pc_system_flash_map(PCMachineState * pcms,MemoryRegion * rom_memory)142ebc29e1bSMarkus Armbruster static void pc_system_flash_map(PCMachineState *pcms,
143ebc29e1bSMarkus Armbruster MemoryRegion *rom_memory)
144bd183c79SJordan Justen {
14532d3ee87SBernhard Beschow X86MachineState *x86ms = X86_MACHINE(pcms);
146a44ea3faSBernhard Beschow PCMachineClass *pcmc = PC_MACHINE_GET_CLASS(pcms);
147ebc29e1bSMarkus Armbruster hwaddr total_size = 0;
148ebc29e1bSMarkus Armbruster int i;
1494be74634SMarkus Armbruster BlockBackend *blk;
150bd183c79SJordan Justen int64_t size;
15116434065SMarkus Armbruster PFlashCFI01 *system_flash;
152bd183c79SJordan Justen MemoryRegion *flash_mem;
153952e0668SBrijesh Singh void *flash_ptr;
154aacdb844SDavid Gibson int flash_size;
155bd183c79SJordan Justen
156ebc29e1bSMarkus Armbruster assert(PC_MACHINE_GET_CLASS(pcms)->pci_enabled);
157ebc29e1bSMarkus Armbruster
158ebc29e1bSMarkus Armbruster for (i = 0; i < ARRAY_SIZE(pcms->flash); i++) {
15977d1abd9SBrijesh Singh hwaddr gpa;
16077d1abd9SBrijesh Singh
161ebc29e1bSMarkus Armbruster system_flash = pcms->flash[i];
162ebc29e1bSMarkus Armbruster blk = pflash_cfi01_get_blk(system_flash);
163ebc29e1bSMarkus Armbruster if (!blk) {
164ebc29e1bSMarkus Armbruster break;
165ebc29e1bSMarkus Armbruster }
1664be74634SMarkus Armbruster size = blk_getlength(blk);
167637a5acbSLaszlo Ersek if (size < 0) {
168ebc29e1bSMarkus Armbruster error_report("can't get size of block device %s: %s",
169ebc29e1bSMarkus Armbruster blk_name(blk), strerror(-size));
170ebc29e1bSMarkus Armbruster exit(1);
171637a5acbSLaszlo Ersek }
1724cdd0a77SPhilippe Mathieu-Daudé if (size == 0 || !QEMU_IS_ALIGNED(size, FLASH_SECTOR_SIZE)) {
173ebc29e1bSMarkus Armbruster error_report("system firmware block device %s has invalid size "
174ebc29e1bSMarkus Armbruster "%" PRId64,
175ebc29e1bSMarkus Armbruster blk_name(blk), size);
176ebc29e1bSMarkus Armbruster info_report("its size must be a non-zero multiple of 0x%x",
177ebc29e1bSMarkus Armbruster FLASH_SECTOR_SIZE);
178ebc29e1bSMarkus Armbruster exit(1);
179637a5acbSLaszlo Ersek }
180ebc29e1bSMarkus Armbruster if ((hwaddr)size != size
181ebc29e1bSMarkus Armbruster || total_size > HWADDR_MAX - size
1820657c657SErich-McMillan || total_size + size > pcms->max_fw_size) {
183ebc29e1bSMarkus Armbruster error_report("combined size of system firmware exceeds "
184ebc29e1bSMarkus Armbruster "%" PRIu64 " bytes",
1850657c657SErich-McMillan pcms->max_fw_size);
186bd183c79SJordan Justen exit(1);
187bd183c79SJordan Justen }
188bd183c79SJordan Justen
189ebc29e1bSMarkus Armbruster total_size += size;
19077d1abd9SBrijesh Singh gpa = 0x100000000ULL - total_size; /* where the flash is mapped */
191ebc29e1bSMarkus Armbruster qdev_prop_set_uint32(DEVICE(system_flash), "num-blocks",
192ebc29e1bSMarkus Armbruster size / FLASH_SECTOR_SIZE);
1933c6ef471SMarkus Armbruster sysbus_realize_and_unref(SYS_BUS_DEVICE(system_flash), &error_fatal);
19477d1abd9SBrijesh Singh sysbus_mmio_map(SYS_BUS_DEVICE(system_flash), 0, gpa);
195bd183c79SJordan Justen
196ebc29e1bSMarkus Armbruster if (i == 0) {
197637a5acbSLaszlo Ersek flash_mem = pflash_cfi01_get_memory(system_flash);
198a44ea3faSBernhard Beschow if (pcmc->isa_bios_alias) {
199a44ea3faSBernhard Beschow x86_isa_bios_init(&x86ms->isa_bios, rom_memory, flash_mem,
200a44ea3faSBernhard Beschow true);
201a44ea3faSBernhard Beschow } else {
202413a6745SMichael Roth pc_isa_bios_init(pcms, &x86ms->isa_bios, rom_memory, flash_mem);
203a44ea3faSBernhard Beschow }
204952e0668SBrijesh Singh
2059617cddbSJames Bottomley /* Encrypt the pflash boot ROM */
2069617cddbSJames Bottomley if (sev_enabled()) {
207952e0668SBrijesh Singh flash_ptr = memory_region_get_ram_ptr(flash_mem);
208952e0668SBrijesh Singh flash_size = memory_region_size(flash_mem);
20977d1abd9SBrijesh Singh x86_firmware_configure(gpa, flash_ptr, flash_size);
210bd183c79SJordan Justen }
211637a5acbSLaszlo Ersek }
212637a5acbSLaszlo Ersek }
2139617cddbSJames Bottomley }
214bd183c79SJordan Justen
pc_system_firmware_init(PCMachineState * pcms,MemoryRegion * rom_memory)2155e640a9eSPhilippe Mathieu-Daudé void pc_system_firmware_init(PCMachineState *pcms,
2165e640a9eSPhilippe Mathieu-Daudé MemoryRegion *rom_memory)
217cbc5b5f3SJordan Justen {
2185e640a9eSPhilippe Mathieu-Daudé PCMachineClass *pcmc = PC_MACHINE_GET_CLASS(pcms);
219ebc29e1bSMarkus Armbruster int i;
220ebc29e1bSMarkus Armbruster BlockBackend *pflash_blk[ARRAY_SIZE(pcms->flash)];
2211d38574fSAnthony Liguori
222ebc29e1bSMarkus Armbruster if (!pcmc->pci_enabled) {
22384835184SBernhard Beschow x86_bios_rom_init(X86_MACHINE(pcms), "bios.bin", rom_memory, true);
224a904410aSPaolo Bonzini return;
225a904410aSPaolo Bonzini }
226a904410aSPaolo Bonzini
227ebc29e1bSMarkus Armbruster /* Map legacy -drive if=pflash to machine properties */
228ebc29e1bSMarkus Armbruster for (i = 0; i < ARRAY_SIZE(pcms->flash); i++) {
2292d731dbdSMarkus Armbruster pflash_cfi01_legacy_drive(pcms->flash[i],
2302d731dbdSMarkus Armbruster drive_get(IF_PFLASH, 0, i));
231c8d8ef00SMarkus Armbruster pflash_blk[i] = pflash_cfi01_get_blk(pcms->flash[i]);
232c8d8ef00SMarkus Armbruster }
233ebc29e1bSMarkus Armbruster
234ebc29e1bSMarkus Armbruster /* Reject gaps */
235ebc29e1bSMarkus Armbruster for (i = 1; i < ARRAY_SIZE(pcms->flash); i++) {
236ebc29e1bSMarkus Armbruster if (pflash_blk[i] && !pflash_blk[i - 1]) {
237ebc29e1bSMarkus Armbruster error_report("pflash%d requires pflash%d", i, i - 1);
238ebc29e1bSMarkus Armbruster exit(1);
239ebc29e1bSMarkus Armbruster }
240ebc29e1bSMarkus Armbruster }
241ebc29e1bSMarkus Armbruster
242ebc29e1bSMarkus Armbruster if (!pflash_blk[0]) {
243ebc29e1bSMarkus Armbruster /* Machine property pflash0 not set, use ROM mode */
24484835184SBernhard Beschow x86_bios_rom_init(X86_MACHINE(pcms), "bios.bin", rom_memory, false);
245ebc29e1bSMarkus Armbruster } else {
246a904410aSPaolo Bonzini if (kvm_enabled() && !kvm_readonly_mem_enabled()) {
247ebc29e1bSMarkus Armbruster /*
248ebc29e1bSMarkus Armbruster * Older KVM cannot execute from device memory. So, flash
249ebc29e1bSMarkus Armbruster * memory cannot be used unless the readonly memory kvm
250ebc29e1bSMarkus Armbruster * capability is present.
251ebc29e1bSMarkus Armbruster */
252ebc29e1bSMarkus Armbruster error_report("pflash with kvm requires KVM readonly memory support");
253dafb82e0SJordan Justen exit(1);
254dafb82e0SJordan Justen }
255dafb82e0SJordan Justen
256ebc29e1bSMarkus Armbruster pc_system_flash_map(pcms, rom_memory);
257ebc29e1bSMarkus Armbruster }
258ebc29e1bSMarkus Armbruster
259ebc29e1bSMarkus Armbruster pc_system_flash_cleanup_unused(pcms);
260cbc5b5f3SJordan Justen }
261966f1ca5SGerd Hoffmann
x86_firmware_configure(hwaddr gpa,void * ptr,int size)26277d1abd9SBrijesh Singh void x86_firmware_configure(hwaddr gpa, void *ptr, int size)
263966f1ca5SGerd Hoffmann {
264966f1ca5SGerd Hoffmann int ret;
265966f1ca5SGerd Hoffmann
266966f1ca5SGerd Hoffmann /*
267966f1ca5SGerd Hoffmann * OVMF places a GUIDed structures in the flash, so
268966f1ca5SGerd Hoffmann * search for them
269966f1ca5SGerd Hoffmann */
270966f1ca5SGerd Hoffmann pc_system_parse_ovmf_flash(ptr, size);
271966f1ca5SGerd Hoffmann
272966f1ca5SGerd Hoffmann if (sev_enabled()) {
273f3c30c57SBrijesh Singh
274f3c30c57SBrijesh Singh /* Copy the SEV metadata table (if it exists) */
275f3c30c57SBrijesh Singh pc_system_parse_sev_metadata(ptr, size);
276f3c30c57SBrijesh Singh
277966f1ca5SGerd Hoffmann ret = sev_es_save_reset_vector(ptr, size);
278966f1ca5SGerd Hoffmann if (ret) {
279966f1ca5SGerd Hoffmann error_report("failed to locate and/or save reset vector");
280966f1ca5SGerd Hoffmann exit(1);
281966f1ca5SGerd Hoffmann }
282966f1ca5SGerd Hoffmann
28377d1abd9SBrijesh Singh sev_encrypt_flash(gpa, ptr, size, &error_fatal);
284*cb5d65a8SXiaoyao Li } else if (is_tdx_vm()) {
285*cb5d65a8SXiaoyao Li ret = tdx_parse_tdvf(ptr, size);
286*cb5d65a8SXiaoyao Li if (ret) {
287*cb5d65a8SXiaoyao Li error_report("failed to parse TDVF for TDX VM");
288*cb5d65a8SXiaoyao Li exit(1);
289*cb5d65a8SXiaoyao Li }
290966f1ca5SGerd Hoffmann }
291966f1ca5SGerd Hoffmann }
292