Dan Handley | 610e7e1 | 2018-03-01 18:44:00 +0000 | [diff] [blame] | 1 | Arm CPU Specific Build Macros |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 2 | ============================= |
| 3 | |
| 4 | |
| 5 | .. section-numbering:: |
| 6 | :suffix: . |
| 7 | |
| 8 | .. contents:: |
| 9 | |
| 10 | This document describes the various build options present in the CPU specific |
| 11 | operations framework to enable errata workarounds and to enable optimizations |
| 12 | for a specific CPU on a platform. |
| 13 | |
Dimitris Papastamos | 446f7f1 | 2017-11-30 14:53:53 +0000 | [diff] [blame] | 14 | Security Vulnerability Workarounds |
| 15 | ---------------------------------- |
| 16 | |
Dan Handley | 610e7e1 | 2018-03-01 18:44:00 +0000 | [diff] [blame] | 17 | TF-A exports a series of build flags which control which security |
| 18 | vulnerability workarounds should be applied at runtime. |
Dimitris Papastamos | 446f7f1 | 2017-11-30 14:53:53 +0000 | [diff] [blame] | 19 | |
| 20 | - ``WORKAROUND_CVE_2017_5715``: Enables the security workaround for |
Dimitris Papastamos | 6d1f499 | 2018-03-28 12:06:40 +0100 | [diff] [blame] | 21 | `CVE-2017-5715`_. This flag can be set to 0 by the platform if none |
| 22 | of the PEs in the system need the workaround. Setting this flag to 0 provides |
| 23 | no performance benefit for non-affected platforms, it just helps to comply |
| 24 | with the recommendation in the spec regarding workaround discovery. |
| 25 | Defaults to 1. |
Dimitris Papastamos | 446f7f1 | 2017-11-30 14:53:53 +0000 | [diff] [blame] | 26 | |
Dimitris Papastamos | e6625ec | 2018-04-05 14:38:26 +0100 | [diff] [blame] | 27 | - ``WORKAROUND_CVE_2018_3639``: Enables the security workaround for |
| 28 | `CVE-2018-3639`_. Defaults to 1. The TF-A project recommends to keep |
| 29 | the default value of 1 even on platforms that are unaffected by |
| 30 | CVE-2018-3639, in order to comply with the recommendation in the spec |
| 31 | regarding workaround discovery. |
| 32 | |
Dimitris Papastamos | ba51d9e | 2018-05-16 11:36:14 +0100 | [diff] [blame] | 33 | - ``DYNAMIC_WORKAROUND_CVE_2018_3639``: Enables dynamic mitigation for |
| 34 | `CVE-2018-3639`_. This build option should be set to 1 if the target |
| 35 | platform contains at least 1 CPU that requires dynamic mitigation. |
| 36 | Defaults to 0. |
| 37 | |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 38 | CPU Errata Workarounds |
| 39 | ---------------------- |
| 40 | |
Dan Handley | 610e7e1 | 2018-03-01 18:44:00 +0000 | [diff] [blame] | 41 | TF-A exports a series of build flags which control the errata workarounds that |
| 42 | are applied to each CPU by the reset handler. The errata details can be found |
| 43 | in the CPU specific errata documents published by Arm: |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 44 | |
| 45 | - `Cortex-A53 MPCore Software Developers Errata Notice`_ |
| 46 | - `Cortex-A57 MPCore Software Developers Errata Notice`_ |
Eleanor Bonnici | c3b4ca1 | 2017-08-02 18:33:41 +0100 | [diff] [blame] | 47 | - `Cortex-A72 MPCore Software Developers Errata Notice`_ |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 48 | |
| 49 | The errata workarounds are implemented for a particular revision or a set of |
| 50 | processor revisions. This is checked by the reset handler at runtime. Each |
| 51 | errata workaround is identified by its ``ID`` as specified in the processor's |
| 52 | errata notice document. The format of the define used to enable/disable the |
| 53 | errata workaround is ``ERRATA_<Processor name>_<ID>``, where the ``Processor name`` |
| 54 | is for example ``A57`` for the ``Cortex_A57`` CPU. |
| 55 | |
| 56 | Refer to the section *CPU errata status reporting* in |
Eleanor Bonnici | 0c9bd27 | 2017-08-02 16:35:04 +0100 | [diff] [blame] | 57 | `Firmware Design guide`_ for information on how to write errata workaround |
| 58 | functions. |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 59 | |
| 60 | All workarounds are disabled by default. The platform is responsible for |
| 61 | enabling these workarounds according to its requirement by defining the |
| 62 | errata workaround build flags in the platform specific makefile. In case |
| 63 | these workarounds are enabled for the wrong CPU revision then the errata |
| 64 | workaround is not applied. In the DEBUG build, this is indicated by |
| 65 | printing a warning to the crash console. |
| 66 | |
| 67 | In the current implementation, a platform which has more than 1 variant |
| 68 | with different revisions of a processor has no runtime mechanism available |
| 69 | for it to specify which errata workarounds should be enabled or not. |
| 70 | |
John Tsichritzis | 4daa1de | 2018-07-23 09:11:59 +0100 | [diff] [blame] | 71 | The value of the build flags is 0 by default, that is, disabled. A value of 1 |
| 72 | will enable it. |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 73 | |
Ambroise Vincent | d4a51eb | 2019-03-04 16:56:26 +0000 | [diff] [blame] | 74 | For Cortex-A15, the following errata build flags are defined : |
| 75 | |
| 76 | - ``ERRATA_A15_816470``: This applies errata 816470 workaround to Cortex-A15 |
| 77 | CPU. This needs to be enabled only for revision >= r3p0 of the CPU. |
| 78 | |
Ambroise Vincent | 68b3812 | 2019-03-05 09:54:21 +0000 | [diff] [blame] | 79 | - ``ERRATA_A15_827671``: This applies errata 827671 workaround to Cortex-A15 |
| 80 | CPU. This needs to be enabled only for revision >= r3p0 of the CPU. |
| 81 | |
Ambroise Vincent | 8cf9eef | 2019-02-28 16:23:53 +0000 | [diff] [blame] | 82 | For Cortex-A17, the following errata build flags are defined : |
| 83 | |
| 84 | - ``ERRATA_A17_852421``: This applies errata 852421 workaround to Cortex-A17 |
| 85 | CPU. This needs to be enabled only for revision <= r1p2 of the CPU. |
| 86 | |
Ambroise Vincent | fa5c951 | 2019-03-04 13:20:56 +0000 | [diff] [blame] | 87 | - ``ERRATA_A17_852423``: This applies errata 852423 workaround to Cortex-A17 |
| 88 | CPU. This needs to be enabled only for revision <= r1p2 of the CPU. |
| 89 | |
John Tsichritzis | 4daa1de | 2018-07-23 09:11:59 +0100 | [diff] [blame] | 90 | For Cortex-A53, the following errata build flags are defined : |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 91 | |
Ambroise Vincent | f5fdfbc | 2019-02-21 14:16:24 +0000 | [diff] [blame] | 92 | - ``ERRATA_A53_819472``: This applies errata 819472 workaround to all |
| 93 | CPUs. This needs to be enabled only for revision <= r0p1 of Cortex-A53. |
| 94 | |
| 95 | - ``ERRATA_A53_824069``: This applies errata 824069 workaround to all |
| 96 | CPUs. This needs to be enabled only for revision <= r0p2 of Cortex-A53. |
| 97 | |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 98 | - ``ERRATA_A53_826319``: This applies errata 826319 workaround to Cortex-A53 |
| 99 | CPU. This needs to be enabled only for revision <= r0p2 of the CPU. |
| 100 | |
Ambroise Vincent | f5fdfbc | 2019-02-21 14:16:24 +0000 | [diff] [blame] | 101 | - ``ERRATA_A53_827319``: This applies errata 827319 workaround to all |
| 102 | CPUs. This needs to be enabled only for revision <= r0p2 of Cortex-A53. |
| 103 | |
Douglas Raillard | b52353a | 2017-07-17 14:14:52 +0100 | [diff] [blame] | 104 | - ``ERRATA_A53_835769``: This applies erratum 835769 workaround at compile and |
| 105 | link time to Cortex-A53 CPU. This needs to be enabled for some variants of |
| 106 | revision <= r0p4. This workaround can lead the linker to create ``*.stub`` |
| 107 | sections. |
| 108 | |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 109 | - ``ERRATA_A53_836870``: This applies errata 836870 workaround to Cortex-A53 |
| 110 | CPU. This needs to be enabled only for revision <= r0p3 of the CPU. From |
| 111 | r0p4 and onwards, this errata is enabled by default in hardware. |
| 112 | |
Douglas Raillard | b52353a | 2017-07-17 14:14:52 +0100 | [diff] [blame] | 113 | - ``ERRATA_A53_843419``: This applies erratum 843419 workaround at link time |
| 114 | to Cortex-A53 CPU. This needs to be enabled for some variants of revision |
| 115 | <= r0p4. This workaround can lead the linker to emit ``*.stub`` sections |
| 116 | which are 4kB aligned. |
| 117 | |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 118 | - ``ERRATA_A53_855873``: This applies errata 855873 workaround to Cortex-A53 |
| 119 | CPUs. Though the erratum is present in every revision of the CPU, |
| 120 | this workaround is only applied to CPUs from r0p3 onwards, which feature |
Sandrine Bailleux | 15530dd | 2019-02-08 15:26:36 +0100 | [diff] [blame] | 121 | a chicken bit in CPUACTLR_EL1 to enable a hardware workaround. |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 122 | Earlier revisions of the CPU have other errata which require the same |
| 123 | workaround in software, so they should be covered anyway. |
| 124 | |
Ambroise Vincent | 7927fa0 | 2019-02-21 16:20:43 +0000 | [diff] [blame] | 125 | For Cortex-A55, the following errata build flags are defined : |
| 126 | |
| 127 | - ``ERRATA_A55_768277``: This applies errata 768277 workaround to Cortex-A55 |
| 128 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 129 | |
Ambroise Vincent | 6f31960 | 2019-02-21 16:25:37 +0000 | [diff] [blame] | 130 | - ``ERRATA_A55_778703``: This applies errata 778703 workaround to Cortex-A55 |
| 131 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 132 | |
Ambroise Vincent | 6a77f05 | 2019-02-21 16:27:34 +0000 | [diff] [blame] | 133 | - ``ERRATA_A55_798797``: This applies errata 798797 workaround to Cortex-A55 |
| 134 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 135 | |
Ambroise Vincent | dd961f7 | 2019-02-21 16:29:16 +0000 | [diff] [blame] | 136 | - ``ERRATA_A55_846532``: This applies errata 846532 workaround to Cortex-A55 |
| 137 | CPU. This needs to be enabled only for revision <= r0p1 of the CPU. |
| 138 | |
Ambroise Vincent | a1d6446 | 2019-02-21 16:29:50 +0000 | [diff] [blame] | 139 | - ``ERRATA_A55_903758``: This applies errata 903758 workaround to Cortex-A55 |
| 140 | CPU. This needs to be enabled only for revision <= r0p1 of the CPU. |
| 141 | |
John Tsichritzis | 4daa1de | 2018-07-23 09:11:59 +0100 | [diff] [blame] | 142 | For Cortex-A57, the following errata build flags are defined : |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 143 | |
| 144 | - ``ERRATA_A57_806969``: This applies errata 806969 workaround to Cortex-A57 |
| 145 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 146 | |
| 147 | - ``ERRATA_A57_813419``: This applies errata 813419 workaround to Cortex-A57 |
| 148 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 149 | |
| 150 | - ``ERRATA_A57_813420``: This applies errata 813420 workaround to Cortex-A57 |
| 151 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 152 | |
Ambroise Vincent | 1b0db76 | 2019-02-21 16:35:07 +0000 | [diff] [blame] | 153 | - ``ERRATA_A57_814670``: This applies errata 814670 workaround to Cortex-A57 |
| 154 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 155 | |
Ambroise Vincent | aa2c029 | 2019-02-21 16:35:49 +0000 | [diff] [blame] | 156 | - ``ERRATA_A57_817169``: This applies errata 817169 workaround to Cortex-A57 |
| 157 | CPU. This needs to be enabled only for revision <= r0p1 of the CPU. |
| 158 | |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 159 | - ``ERRATA_A57_826974``: This applies errata 826974 workaround to Cortex-A57 |
| 160 | CPU. This needs to be enabled only for revision <= r1p1 of the CPU. |
| 161 | |
| 162 | - ``ERRATA_A57_826977``: This applies errata 826977 workaround to Cortex-A57 |
| 163 | CPU. This needs to be enabled only for revision <= r1p1 of the CPU. |
| 164 | |
| 165 | - ``ERRATA_A57_828024``: This applies errata 828024 workaround to Cortex-A57 |
| 166 | CPU. This needs to be enabled only for revision <= r1p1 of the CPU. |
| 167 | |
| 168 | - ``ERRATA_A57_829520``: This applies errata 829520 workaround to Cortex-A57 |
| 169 | CPU. This needs to be enabled only for revision <= r1p2 of the CPU. |
| 170 | |
| 171 | - ``ERRATA_A57_833471``: This applies errata 833471 workaround to Cortex-A57 |
| 172 | CPU. This needs to be enabled only for revision <= r1p2 of the CPU. |
| 173 | |
Eleanor Bonnici | 0c9bd27 | 2017-08-02 16:35:04 +0100 | [diff] [blame] | 174 | - ``ERRATA_A57_859972``: This applies errata 859972 workaround to Cortex-A57 |
| 175 | CPU. This needs to be enabled only for revision <= r1p3 of the CPU. |
| 176 | |
Eleanor Bonnici | c3b4ca1 | 2017-08-02 18:33:41 +0100 | [diff] [blame] | 177 | |
John Tsichritzis | 4daa1de | 2018-07-23 09:11:59 +0100 | [diff] [blame] | 178 | For Cortex-A72, the following errata build flags are defined : |
Eleanor Bonnici | c3b4ca1 | 2017-08-02 18:33:41 +0100 | [diff] [blame] | 179 | |
| 180 | - ``ERRATA_A72_859971``: This applies errata 859971 workaround to Cortex-A72 |
| 181 | CPU. This needs to be enabled only for revision <= r0p3 of the CPU. |
| 182 | |
Louis Mayencourt | 4405de6 | 2019-02-21 16:38:16 +0000 | [diff] [blame] | 183 | For Cortex-A73, the following errata build flags are defined : |
| 184 | |
Louis Mayencourt | d69722c | 2019-02-27 14:24:16 +0000 | [diff] [blame] | 185 | - ``ERRATA_A73_852427``: This applies errata 852427 workaround to Cortex-A73 |
| 186 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 187 | |
Louis Mayencourt | 4405de6 | 2019-02-21 16:38:16 +0000 | [diff] [blame] | 188 | - ``ERRATA_A73_855423``: This applies errata 855423 workaround to Cortex-A73 |
| 189 | CPU. This needs to be enabled only for revision <= r0p1 of the CPU. |
| 190 | |
Louis Mayencourt | 78a0aed | 2019-02-20 12:11:41 +0000 | [diff] [blame] | 191 | For Cortex-A75, the following errata build flags are defined : |
| 192 | |
| 193 | - ``ERRATA_A75_764081``: This applies errata 764081 workaround to Cortex-A75 |
| 194 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 195 | |
Louis Mayencourt | 8d86870 | 2019-02-25 14:57:57 +0000 | [diff] [blame] | 196 | - ``ERRATA_A75_790748``: This applies errata 790748 workaround to Cortex-A75 |
| 197 | CPU. This needs to be enabled only for revision r0p0 of the CPU. |
| 198 | |
Louis Mayencourt | 0992447 | 2019-02-21 17:35:07 +0000 | [diff] [blame] | 199 | For Cortex-A76, the following errata build flags are defined : |
| 200 | |
Louis Mayencourt | 59fa218 | 2019-02-25 15:17:44 +0000 | [diff] [blame] | 201 | - ``ERRATA_A76_1073348``: This applies errata 1073348 workaround to Cortex-A76 |
| 202 | CPU. This needs to be enabled only for revision <= r1p0 of the CPU. |
| 203 | |
Louis Mayencourt | 0992447 | 2019-02-21 17:35:07 +0000 | [diff] [blame] | 204 | - ``ERRATA_A76_1130799``: This applies errata 1130799 workaround to Cortex-A76 |
| 205 | CPU. This needs to be enabled only for revision <= r2p0 of the CPU. |
| 206 | |
Louis Mayencourt | adda9d4 | 2019-02-25 11:37:38 +0000 | [diff] [blame] | 207 | - ``ERRATA_A76_1220197``: This applies errata 1220197 workaround to Cortex-A76 |
| 208 | CPU. This needs to be enabled only for revision <= r2p0 of the CPU. |
| 209 | |
John Tsichritzis | 4daa1de | 2018-07-23 09:11:59 +0100 | [diff] [blame] | 210 | DSU Errata Workarounds |
| 211 | ---------------------- |
| 212 | |
| 213 | Similar to CPU errata, TF-A also implements workarounds for DSU (DynamIQ |
| 214 | Shared Unit) errata. The DSU errata details can be found in the respective Arm |
| 215 | documentation: |
| 216 | |
| 217 | - `Arm DSU Software Developers Errata Notice`_. |
| 218 | |
| 219 | Each erratum is identified by an ``ID``, as defined in the DSU errata notice |
| 220 | document. Thus, the build flags which enable/disable the errata workarounds |
| 221 | have the format ``ERRATA_DSU_<ID>``. The implementation and application logic |
| 222 | of DSU errata workarounds are similar to `CPU errata workarounds`_. |
| 223 | |
| 224 | For DSU errata, the following build flags are defined: |
| 225 | |
| 226 | - ``ERRATA_DSU_936184``: This applies errata 936184 workaround for the |
| 227 | affected DSU configurations. This errata applies only for those DSUs that |
| 228 | contain the ACP interface **and** the DSU revision is older than r2p0 (on |
| 229 | r2p0 it is fixed). However, please note that this workaround results in |
| 230 | increased DSU power consumption on idle. |
| 231 | |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 232 | CPU Specific optimizations |
| 233 | -------------------------- |
| 234 | |
| 235 | This section describes some of the optimizations allowed by the CPU micro |
| 236 | architecture that can be enabled by the platform as desired. |
| 237 | |
| 238 | - ``SKIP_A57_L1_FLUSH_PWR_DWN``: This flag enables an optimization in the |
| 239 | Cortex-A57 cluster power down sequence by not flushing the Level 1 data |
| 240 | cache. The L1 data cache and the L2 unified cache are inclusive. A flush |
| 241 | of the L2 by set/way flushes any dirty lines from the L1 as well. This |
| 242 | is a known safe deviation from the Cortex-A57 TRM defined power down |
| 243 | sequence. Each Cortex-A57 based platform must make its own decision on |
| 244 | whether to use the optimization. |
| 245 | |
| 246 | - ``A53_DISABLE_NON_TEMPORAL_HINT``: This flag disables the cache non-temporal |
| 247 | hint. The LDNP/STNP instructions as implemented on Cortex-A53 do not behave |
| 248 | in a way most programmers expect, and will most probably result in a |
Dan Handley | 610e7e1 | 2018-03-01 18:44:00 +0000 | [diff] [blame] | 249 | significant speed degradation to any code that employs them. The Armv8-A |
| 250 | architecture (see Arm DDI 0487A.h, section D3.4.3) allows cores to ignore |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 251 | the non-temporal hint and treat LDNP/STNP as LDP/STP instead. Enabling this |
| 252 | flag enforces this behaviour. This needs to be enabled only for revisions |
| 253 | <= r0p3 of the CPU and is enabled by default. |
| 254 | |
| 255 | - ``A57_DISABLE_NON_TEMPORAL_HINT``: This flag has the same behaviour as |
| 256 | ``A53_DISABLE_NON_TEMPORAL_HINT`` but for Cortex-A57. This needs to be |
| 257 | enabled only for revisions <= r1p2 of the CPU and is enabled by default, |
| 258 | as recommended in section "4.7 Non-Temporal Loads/Stores" of the |
| 259 | `Cortex-A57 Software Optimization Guide`_. |
| 260 | |
| 261 | -------------- |
| 262 | |
Dan Handley | 610e7e1 | 2018-03-01 18:44:00 +0000 | [diff] [blame] | 263 | *Copyright (c) 2014-2018, Arm Limited and Contributors. All rights reserved.* |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 264 | |
John Tsichritzis | 3eeac41 | 2018-09-04 10:56:53 +0100 | [diff] [blame] | 265 | .. _CVE-2017-5715: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715 |
| 266 | .. _CVE-2018-3639: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3639 |
Paul Beesley | 2437ddc | 2019-02-08 16:43:05 +0000 | [diff] [blame] | 267 | .. _Cortex-A53 MPCore Software Developers Errata Notice: http://infocenter.arm.com/help/topic/com.arm.doc.epm048406/index.html |
| 268 | .. _Cortex-A57 MPCore Software Developers Errata Notice: http://infocenter.arm.com/help/topic/com.arm.doc.epm049219/index.html |
Eleanor Bonnici | c3b4ca1 | 2017-08-02 18:33:41 +0100 | [diff] [blame] | 269 | .. _Cortex-A72 MPCore Software Developers Errata Notice: http://infocenter.arm.com/help/topic/com.arm.doc.epm012079/index.html |
Douglas Raillard | d7c21b7 | 2017-06-28 15:23:03 +0100 | [diff] [blame] | 270 | .. _Firmware Design guide: firmware-design.rst |
| 271 | .. _Cortex-A57 Software Optimization Guide: http://infocenter.arm.com/help/topic/com.arm.doc.uan0015b/Cortex_A57_Software_Optimization_Guide_external.pdf |
Sandrine Bailleux | 15530dd | 2019-02-08 15:26:36 +0100 | [diff] [blame] | 272 | .. _Arm DSU Software Developers Errata Notice: http://infocenter.arm.com/help/topic/com.arm.doc.epm138168/index.html |