blob: f09cbd2365e8757fe512dec3ec7d07bab778c3a3 [file] [log] [blame]
David Brazdil66fc1202022-07-04 21:48:45 +01001// Copyright 2022, The Android Open Source Project
2//
3// Licensed under the Apache License, Version 2.0 (the "License");
4// you may not use this file except in compliance with the License.
5// You may obtain a copy of the License at
6//
7// http://www.apache.org/licenses/LICENSE-2.0
8//
9// Unless required by applicable law or agreed to in writing, software
10// distributed under the License is distributed on an "AS IS" BASIS,
11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12// See the License for the specific language governing permissions and
13// limitations under the License.
14
15//! Project Rialto main source file.
16
17#![no_main]
18#![no_std]
David Brazdil66fc1202022-07-04 21:48:45 +010019
Alice Wang4e082c32023-07-11 07:41:50 +000020mod communication;
Alice Wang9a8b39f2023-04-12 15:31:48 +000021mod error;
David Brazdil66fc1202022-07-04 21:48:45 +010022mod exceptions;
Alice Wang474c0ee2023-09-14 12:52:33 +000023mod fdt;
David Brazdil66fc1202022-07-04 21:48:45 +010024
25extern crate alloc;
David Brazdil66fc1202022-07-04 21:48:45 +010026
Alice Wang748b0322023-07-24 12:51:18 +000027use crate::communication::VsockStream;
Alice Wang9a8b39f2023-04-12 15:31:48 +000028use crate::error::{Error, Result};
Alice Wanga2228b92024-07-26 08:38:47 +000029use crate::fdt::{read_dice_range_from, read_is_strict_boot, read_vendor_hashtree_root_digest};
Alice Wang77639bf2023-09-21 06:57:12 +000030use alloc::boxed::Box;
Alice Wang953a6572023-08-24 13:40:10 +000031use ciborium_io::Write;
Alice Wang74f7f4b2023-06-13 08:24:50 +000032use core::num::NonZeroUsize;
Pierre-Clément Tosi3d4c5c32023-05-31 16:57:06 +000033use core::slice;
Alice Wang77639bf2023-09-21 06:57:12 +000034use diced_open_dice::{bcc_handover_parse, DiceArtifacts};
Alice Wangb6d2c642023-06-13 13:07:06 +000035use libfdt::FdtError;
Alice Wang9a8b39f2023-04-12 15:31:48 +000036use log::{debug, error, info};
Alice Wangb5d9a462024-02-09 10:10:47 +000037use service_vm_comm::{ServiceVmRequest, VmType};
Alice Wang4ac9c8b2023-12-05 16:23:14 +000038use service_vm_fake_chain::service_vm;
Alice Wang9eebbab2024-04-10 14:57:27 +000039use service_vm_requests::{process_request, RequestContext};
Alice Wang62183352023-07-04 08:33:27 +000040use virtio_drivers::{
Alice Wangd158e392023-08-30 12:51:12 +000041 device::socket::{VsockAddr, VMADDR_CID_HOST},
Alice Wang62183352023-07-04 08:33:27 +000042 transport::{pci::bus::PciRoot, DeviceType, Transport},
43 Hal,
44};
Alice Wang4b3cc112023-06-06 12:22:53 +000045use vmbase::{
Pierre-Clément Tosi6a4808c2023-06-29 09:19:38 +000046 configure_heap,
Pierre-Clément Tosif2c19d42024-10-01 17:42:04 +010047 fdt::pci::PciInfo,
Alice Wangb6d2c642023-06-13 13:07:06 +000048 fdt::SwiotlbInfo,
Frederick Mayle75842402024-08-05 19:32:08 -070049 generate_image_header,
Pierre-Clément Tosia9b345f2024-04-27 01:01:42 +010050 hyp::{get_mem_sharer, get_mmio_guard},
Pierre-Clément Tosi38a36212024-06-06 11:30:39 +010051 layout::{self, crosvm, UART_PAGE_ADDR},
Alice Wang89d29592023-06-12 09:41:29 +000052 main,
Alice Wang62183352023-07-04 08:33:27 +000053 memory::{MemoryTracker, PageTable, MEMORY, PAGE_SIZE, SIZE_128KB},
Alice Wang4b3cc112023-06-06 12:22:53 +000054 power::reboot,
Alice Wang62183352023-07-04 08:33:27 +000055 virtio::{
56 pci::{self, PciTransportIterator, VirtIOSocket},
57 HalImpl,
58 },
Alice Wang4b3cc112023-06-06 12:22:53 +000059};
David Brazdil66fc1202022-07-04 21:48:45 +010060
Alice Wanga2228b92024-07-26 08:38:47 +000061fn host_addr(fdt: &libfdt::Fdt) -> Result<VsockAddr> {
62 Ok(VsockAddr { cid: VMADDR_CID_HOST, port: vm_type(fdt)?.port() })
Alice Wang4e082c32023-07-11 07:41:50 +000063}
64
Alice Wanga2228b92024-07-26 08:38:47 +000065fn vm_type(fdt: &libfdt::Fdt) -> Result<VmType> {
66 if read_is_strict_boot(fdt)? {
67 Ok(VmType::ProtectedVm)
Alice Wang1d9a5872023-09-06 14:32:36 +000068 } else {
Alice Wanga2228b92024-07-26 08:38:47 +000069 Ok(VmType::NonProtectedVm)
Alice Wang1d9a5872023-09-06 14:32:36 +000070 }
Alice Wang4e082c32023-07-11 07:41:50 +000071}
72
Alice Wangb70bdb52023-06-12 08:17:58 +000073fn new_page_table() -> Result<PageTable> {
Alice Wangee5b1802023-06-07 07:41:54 +000074 let mut page_table = PageTable::default();
Pierre-Clément Tosi3d4c5c32023-05-31 16:57:06 +000075
Alice Wanga3931aa2023-07-05 12:52:09 +000076 page_table.map_data(&layout::scratch_range().into())?;
77 page_table.map_data(&layout::stack_range(40 * PAGE_SIZE).into())?;
78 page_table.map_code(&layout::text_range().into())?;
79 page_table.map_rodata(&layout::rodata_range().into())?;
Pierre-Clément Tosi38a36212024-06-06 11:30:39 +010080 page_table.map_device(&layout::console_uart_page().into())?;
David Brazdil66fc1202022-07-04 21:48:45 +010081
Alice Wangb70bdb52023-06-12 08:17:58 +000082 Ok(page_table)
David Brazdil66fc1202022-07-04 21:48:45 +010083}
84
Alice Wangdda3ba92023-05-25 15:15:30 +000085/// # Safety
86///
87/// Behavior is undefined if any of the following conditions are violated:
88/// * The `fdt_addr` must be a valid pointer and points to a valid `Fdt`.
89unsafe fn try_main(fdt_addr: usize) -> Result<()> {
David Brazdil66fc1202022-07-04 21:48:45 +010090 info!("Welcome to Rialto!");
Alice Wangb70bdb52023-06-12 08:17:58 +000091 let page_table = new_page_table()?;
92
93 MEMORY.lock().replace(MemoryTracker::new(
94 page_table,
95 crosvm::MEM_START..layout::MAX_VIRT_ADDR,
96 crosvm::MMIO_RANGE,
97 None, // Rialto doesn't have any payload for now.
98 ));
Alice Wang74f7f4b2023-06-13 08:24:50 +000099
100 let fdt_range = MEMORY
101 .lock()
102 .as_mut()
103 .unwrap()
104 .alloc(fdt_addr, NonZeroUsize::new(crosvm::FDT_MAX_SIZE).unwrap())?;
105 // SAFETY: The tracker validated the range to be in main memory, mapped, and not overlap.
106 let fdt = unsafe { slice::from_raw_parts(fdt_range.start as *mut u8, fdt_range.len()) };
Alice Wang674257a2023-06-13 09:44:53 +0000107 // We do not need to validate the DT since it is already validated in pvmfw.
Alice Wang74f7f4b2023-06-13 08:24:50 +0000108 let fdt = libfdt::Fdt::from_slice(fdt)?;
Alice Wang74f7f4b2023-06-13 08:24:50 +0000109
Alice Wang674257a2023-06-13 09:44:53 +0000110 let memory_range = fdt.first_memory_range()?;
Chris Wailes0f121752024-09-06 10:45:06 -0700111 MEMORY.lock().as_mut().unwrap().shrink(&memory_range).inspect_err(|_| {
Alice Wang674257a2023-06-13 09:44:53 +0000112 error!("Failed to use memory range value from DT: {memory_range:#x?}");
Alice Wang674257a2023-06-13 09:44:53 +0000113 })?;
Alice Wangb6d2c642023-06-13 13:07:06 +0000114
Pierre-Clément Tosi910a72d2023-06-29 14:29:29 +0000115 if let Some(mem_sharer) = get_mem_sharer() {
116 let granule = mem_sharer.granule()?;
Chris Wailes0f121752024-09-06 10:45:06 -0700117 MEMORY.lock().as_mut().unwrap().init_dynamic_shared_pool(granule).inspect_err(|_| {
Alice Wangb6d2c642023-06-13 13:07:06 +0000118 error!("Failed to initialize dynamically shared pool.");
Alice Wangb6d2c642023-06-13 13:07:06 +0000119 })?;
Pierre-Clément Tosi8937cb82023-07-06 15:07:38 +0000120 } else if let Ok(swiotlb_info) = SwiotlbInfo::new_from_fdt(fdt) {
121 let range = swiotlb_info.fixed_range().ok_or_else(|| {
Alice Wangb6d2c642023-06-13 13:07:06 +0000122 error!("Pre-shared pool range not specified in swiotlb node");
123 Error::from(FdtError::BadValue)
124 })?;
Chris Wailes0f121752024-09-06 10:45:06 -0700125 MEMORY.lock().as_mut().unwrap().init_static_shared_pool(range).inspect_err(|_| {
Alice Wangb6d2c642023-06-13 13:07:06 +0000126 error!("Failed to initialize pre-shared pool.");
Alice Wangb6d2c642023-06-13 13:07:06 +0000127 })?;
Pierre-Clément Tosi8937cb82023-07-06 15:07:38 +0000128 } else {
129 info!("No MEM_SHARE capability detected or swiotlb found: allocating buffers from heap.");
Chris Wailes0f121752024-09-06 10:45:06 -0700130 MEMORY.lock().as_mut().unwrap().init_heap_shared_pool().inspect_err(|_| {
Pierre-Clément Tosi8937cb82023-07-06 15:07:38 +0000131 error!("Failed to initialize heap-based pseudo-shared pool.");
Pierre-Clément Tosi8937cb82023-07-06 15:07:38 +0000132 })?;
Alice Wangb6d2c642023-06-13 13:07:06 +0000133 }
Alice Wang7b2ab942023-09-12 13:04:42 +0000134
Alice Wanga2228b92024-07-26 08:38:47 +0000135 let bcc_handover: Box<dyn DiceArtifacts> = match vm_type(fdt)? {
Alice Wang474c0ee2023-09-14 12:52:33 +0000136 VmType::ProtectedVm => {
137 let dice_range = read_dice_range_from(fdt)?;
138 info!("DICE range: {dice_range:#x?}");
Alice Wang9f3ca832023-09-20 09:33:14 +0000139 // SAFETY: This region was written by pvmfw in its writable_data region. The region
140 // has no overlap with the main memory region and is safe to be mapped as read-only
141 // data.
142 let res = unsafe {
143 MEMORY.lock().as_mut().unwrap().alloc_range_outside_main_memory(&dice_range)
144 };
Chris Wailes0f121752024-09-06 10:45:06 -0700145 res.inspect_err(|_| {
Alice Wang9f3ca832023-09-20 09:33:14 +0000146 error!("Failed to use DICE range from DT: {dice_range:#x?}");
Alice Wang9f3ca832023-09-20 09:33:14 +0000147 })?;
148 let dice_start = dice_range.start as *const u8;
149 // SAFETY: There's no memory overlap and the region is mapped as read-only data.
150 let bcc_handover = unsafe { slice::from_raw_parts(dice_start, dice_range.len()) };
Alice Wang77639bf2023-09-21 06:57:12 +0000151 Box::new(bcc_handover_parse(bcc_handover)?)
Alice Wang474c0ee2023-09-14 12:52:33 +0000152 }
Alice Wang77639bf2023-09-21 06:57:12 +0000153 // Currently, a sample DICE data is used for non-protected VMs, as these VMs only run
154 // in tests at the moment.
Alice Wang4ac9c8b2023-12-05 16:23:14 +0000155 VmType::NonProtectedVm => Box::new(service_vm::fake_service_vm_dice_artifacts()?),
Alice Wang474c0ee2023-09-14 12:52:33 +0000156 };
Alice Wangd36c7112023-07-04 09:50:45 +0000157
158 let pci_info = PciInfo::from_fdt(fdt)?;
159 debug!("PCI: {pci_info:#x?}");
Alice Wang62183352023-07-04 08:33:27 +0000160 let mut pci_root = pci::initialize(pci_info, MEMORY.lock().as_mut().unwrap())
Alice Wangd36c7112023-07-04 09:50:45 +0000161 .map_err(Error::PciInitializationFailed)?;
162 debug!("PCI root: {pci_root:#x?}");
Alice Wang62183352023-07-04 08:33:27 +0000163 let socket_device = find_socket_device::<HalImpl>(&mut pci_root)?;
164 debug!("Found socket device: guest cid = {:?}", socket_device.guest_cid());
Alice Wang9eebbab2024-04-10 14:57:27 +0000165 let vendor_hashtree_root_digest = read_vendor_hashtree_root_digest(fdt)?;
166 let request_context =
167 RequestContext { dice_artifacts: bcc_handover.as_ref(), vendor_hashtree_root_digest };
Alice Wang4e082c32023-07-11 07:41:50 +0000168
Alice Wanga2228b92024-07-26 08:38:47 +0000169 let mut vsock_stream = VsockStream::new(socket_device, host_addr(fdt)?)?;
Alice Wangfbdc85b2023-09-07 12:56:46 +0000170 while let ServiceVmRequest::Process(req) = vsock_stream.read_request()? {
Alice Wang2e6cdc12024-02-19 11:36:36 +0000171 info!("Received request: {}", req.name());
Alice Wang9eebbab2024-04-10 14:57:27 +0000172 let response = process_request(req, &request_context);
Alice Wang2e6cdc12024-02-19 11:36:36 +0000173 info!("Sending response: {}", response.name());
Alice Wangfbdc85b2023-09-07 12:56:46 +0000174 vsock_stream.write_response(&response)?;
175 vsock_stream.flush()?;
176 }
Alice Wang748b0322023-07-24 12:51:18 +0000177 vsock_stream.shutdown()?;
Alice Wang4e082c32023-07-11 07:41:50 +0000178
Alice Wang9a8b39f2023-04-12 15:31:48 +0000179 Ok(())
180}
181
Alice Wang62183352023-07-04 08:33:27 +0000182fn find_socket_device<T: Hal>(pci_root: &mut PciRoot) -> Result<VirtIOSocket<T>> {
183 PciTransportIterator::<T>::new(pci_root)
184 .find(|t| DeviceType::Socket == t.device_type())
185 .map(VirtIOSocket::<T>::new)
186 .transpose()
187 .map_err(Error::VirtIOSocketCreationFailed)?
188 .ok_or(Error::MissingVirtIOSocketDevice)
189}
190
Pierre-Clément Tosi910a72d2023-06-29 14:29:29 +0000191fn try_unshare_all_memory() -> Result<()> {
Alice Wang77d9dd32023-06-07 13:41:21 +0000192 info!("Starting unsharing memory...");
193
Alice Wang77d9dd32023-06-07 13:41:21 +0000194 // No logging after unmapping UART.
Pierre-Clément Tosi910a72d2023-06-29 14:29:29 +0000195 if let Some(mmio_guard) = get_mmio_guard() {
Pierre-Clément Tosi38a36212024-06-06 11:30:39 +0100196 mmio_guard.unmap(UART_PAGE_ADDR)?;
Alice Wangb70bdb52023-06-12 08:17:58 +0000197 }
198 // Unshares all memory and deactivates page table.
199 drop(MEMORY.lock().take());
Alice Wang77d9dd32023-06-07 13:41:21 +0000200 Ok(())
201}
202
Pierre-Clément Tosi910a72d2023-06-29 14:29:29 +0000203fn unshare_all_memory() {
204 if let Err(e) = try_unshare_all_memory() {
Alice Wang77d9dd32023-06-07 13:41:21 +0000205 error!("Failed to unshare the memory: {e}");
206 }
207}
208
Alice Wang9a8b39f2023-04-12 15:31:48 +0000209/// Entry point for Rialto.
Alice Wangdda3ba92023-05-25 15:15:30 +0000210pub fn main(fdt_addr: u64, _a1: u64, _a2: u64, _a3: u64) {
Pierre-Clément Tosid3305482023-06-29 15:03:48 +0000211 log::set_max_level(log::LevelFilter::Debug);
Alice Wangdda3ba92023-05-25 15:15:30 +0000212 // SAFETY: `fdt_addr` is supposed to be a valid pointer and points to
213 // a valid `Fdt`.
214 match unsafe { try_main(fdt_addr as usize) } {
Pierre-Clément Tosi910a72d2023-06-29 14:29:29 +0000215 Ok(()) => unshare_all_memory(),
Alice Wang9a8b39f2023-04-12 15:31:48 +0000216 Err(e) => {
217 error!("Rialto failed with {e}");
Pierre-Clément Tosi910a72d2023-06-29 14:29:29 +0000218 unshare_all_memory();
Alice Wang9a8b39f2023-04-12 15:31:48 +0000219 reboot()
220 }
221 }
David Brazdil66fc1202022-07-04 21:48:45 +0100222}
223
Alice Wang3ee72c72024-06-28 11:23:48 +0000224/// Flushes data caches over the provided address range.
225///
226/// # Safety
227///
228/// The provided address and size must be to an address range that is valid for read and write
229/// (typically on the stack, .bss, .data, or provided BCC) from a single allocation
230/// (e.g. stack array).
231#[no_mangle]
232unsafe extern "C" fn DiceClearMemory(
233 _ctx: *mut core::ffi::c_void,
234 size: usize,
235 addr: *mut core::ffi::c_void,
236) {
237 use core::slice;
238 use vmbase::memory::flushed_zeroize;
239
240 // SAFETY: We require our caller to provide a valid range within a single object. The open-dice
241 // always calls this on individual stack-allocated arrays which ensures that.
242 let region = unsafe { slice::from_raw_parts_mut(addr as *mut u8, size) };
243 flushed_zeroize(region)
244}
245
Frederick Mayle75842402024-08-05 19:32:08 -0700246generate_image_header!();
David Brazdil66fc1202022-07-04 21:48:45 +0100247main!(main);
Alice Wang65ea4cb2024-04-30 10:07:51 +0000248configure_heap!(SIZE_128KB * 2);