mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Ahmad Fatoum <>
	Ahmad Fatoum <>
Subject: [PATCH master v2] ARM: cpu: don't clobber sp when booted in HYP mode
Date: Tue, 31 May 2022 10:29:14 +0200	[thread overview]
Message-ID: <> (raw)

arm_cpu_lowlevel_init() is usually called first thing and will ensure
barebox runs in SVC mode. If barebox is started in HYP mode instead,
like is the case on Raspberry Pi 2-3, it will do an exception return
into SVC mode, which will bank the previously used SP_Hyp and
restore SP_Svc that may not have been properly initialized by barebox.

This wasn't too bad so far, because arm_setup_stack was usually called
after arm_cpu_lowlevel_init, but with ENTRY_FUNCTION_WITHSTACK, SP is
initialized early on in the naked entry point with
arm_cpu_lowlevel_init() being called after that.

This can lead to spurious boot hangs in the Raspberry Pi 2 and 3 entry
points. Fix this by always saving sp to r3 and restoring it, like we do
with lr. This is safe to do, because r3 isn't clobbered by any
instruction in arm_cpu_lowlevel_init() and because it's an argument
register, callers have to expect it being overwritten by the callee.

Fixes: b267578d0567 ("ARM: rpi: use ENTRY_FUNCTION_WITHSTACK to prepare for ARM64 support")
Fixes: 41292192c01b ("ARM: safely switch from HYP to SVC mode if required")
Signed-off-by: Ahmad Fatoum <>
v1 -> v2:
  - add source code comment on why sp is saved (Sascha)
 arch/arm/cpu/lowlevel.S | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/arch/arm/cpu/lowlevel.S b/arch/arm/cpu/lowlevel.S
index 5a7dd3c2093f..960a92b78c0a 100644
--- a/arch/arm/cpu/lowlevel.S
+++ b/arch/arm/cpu/lowlevel.S
@@ -9,6 +9,8 @@
 	/* save lr, since it may be banked away with a processor mode change */
 	mov	r2, lr
+	/* save sp, because possible HYP -> SVC transition below clobbers it */
+	mov	r3, sp
 #ifdef CONFIG_CPU_32v7
 	/* careful: the hyp install corrupts r0 and r1 */
@@ -77,6 +79,7 @@ THUMB(	orr	r12, r12, #PSR_T_BIT	)
 	mcr	p15, 0, r12, c1, c0, 0		/* SCTLR */
+	mov	sp, r3
 	mov	pc, r2

barebox mailing list

             reply	other threads:[~2022-05-31  8:30 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-05-31  8:29 Ahmad Fatoum [this message]
2022-06-01  9:51 ` Sascha Hauer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \ \ \ \ \ \

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox