1 // SPDX-License-Identifier: GPL-2.0+
3 * EFI application memory management
5 * Copyright (c) 2016 Alexander Graf
9 #include <efi_loader.h>
14 #include <linux/list_sort.h>
15 #include <linux/sizes.h>
17 DECLARE_GLOBAL_DATA_PTR;
19 /* Magic number identifying memory allocated from pool */
20 #define EFI_ALLOC_POOL_MAGIC 0x1fe67ddf6491caa2
22 efi_uintn_t efi_memory_map_key;
25 struct list_head link;
26 struct efi_mem_desc desc;
29 #define EFI_CARVE_NO_OVERLAP -1
30 #define EFI_CARVE_LOOP_AGAIN -2
31 #define EFI_CARVE_OVERLAPS_NONRAM -3
33 /* This list contains all memory map items */
36 #ifdef CONFIG_EFI_LOADER_BOUNCE_BUFFER
37 void *efi_bounce_buffer;
41 * struct efi_pool_allocation - memory block allocated from pool
43 * @num_pages: number of pages allocated
45 * @data: allocated pool memory
47 * U-Boot services each UEFI AllocatePool() request as a separate
48 * (multiple) page allocation. We have to track the number of pages
49 * to be able to free the correct amount later.
51 * The checksum calculated in function checksum() is used in FreePool() to avoid
52 * freeing memory not allocated by AllocatePool() and duplicate freeing.
54 * EFI requires 8 byte alignment for pool allocations, so we can
55 * prepend each allocation with these header fields.
57 struct efi_pool_allocation {
60 char data[] __aligned(ARCH_DMA_MINALIGN);
64 * checksum() - calculate checksum for memory allocated from pool
66 * @alloc: allocation header
67 * Return: checksum, always non-zero
69 static u64 checksum(struct efi_pool_allocation *alloc)
71 u64 addr = (uintptr_t)alloc;
72 u64 ret = (addr >> 32) ^ (addr << 32) ^ alloc->num_pages ^
80 * Sorts the memory list from highest address to lowest address
82 * When allocating memory we should always start from the highest
83 * address chunk, so sort the memory list such that the first list
84 * iterator gets the highest address and goes lower from there.
86 static int efi_mem_cmp(void *priv, struct list_head *a, struct list_head *b)
88 struct efi_mem_list *mema = list_entry(a, struct efi_mem_list, link);
89 struct efi_mem_list *memb = list_entry(b, struct efi_mem_list, link);
91 if (mema->desc.physical_start == memb->desc.physical_start)
93 else if (mema->desc.physical_start < memb->desc.physical_start)
99 static uint64_t desc_get_end(struct efi_mem_desc *desc)
101 return desc->physical_start + (desc->num_pages << EFI_PAGE_SHIFT);
104 static void efi_mem_sort(void)
106 struct list_head *lhandle;
107 struct efi_mem_list *prevmem = NULL;
108 bool merge_again = true;
110 list_sort(NULL, &efi_mem, efi_mem_cmp);
112 /* Now merge entries that can be merged */
113 while (merge_again) {
115 list_for_each(lhandle, &efi_mem) {
116 struct efi_mem_list *lmem;
117 struct efi_mem_desc *prev = &prevmem->desc;
118 struct efi_mem_desc *cur;
121 lmem = list_entry(lhandle, struct efi_mem_list, link);
129 if ((desc_get_end(cur) == prev->physical_start) &&
130 (prev->type == cur->type) &&
131 (prev->attribute == cur->attribute)) {
132 /* There is an existing map before, reuse it */
133 pages = cur->num_pages;
134 prev->num_pages += pages;
135 prev->physical_start -= pages << EFI_PAGE_SHIFT;
136 prev->virtual_start -= pages << EFI_PAGE_SHIFT;
137 list_del(&lmem->link);
149 /** efi_mem_carve_out - unmap memory region
152 * @carve_desc: memory region to unmap
153 * @overlap_only_ram: the carved out region may only overlap RAM
154 * Return Value: the number of overlapping pages which have been
155 * removed from the map,
156 * EFI_CARVE_NO_OVERLAP, if the regions don't overlap,
157 * EFI_CARVE_OVERLAPS_NONRAM, if the carve and map overlap,
158 * and the map contains anything but free ram
159 * (only when overlap_only_ram is true),
160 * EFI_CARVE_LOOP_AGAIN, if the mapping list should be
161 * traversed again, as it has been altered.
163 * Unmaps all memory occupied by the carve_desc region from the list entry
166 * In case of EFI_CARVE_OVERLAPS_NONRAM it is the callers responsibility
167 * to re-add the already carved out pages to the mapping.
169 static s64 efi_mem_carve_out(struct efi_mem_list *map,
170 struct efi_mem_desc *carve_desc,
171 bool overlap_only_ram)
173 struct efi_mem_list *newmap;
174 struct efi_mem_desc *map_desc = &map->desc;
175 uint64_t map_start = map_desc->physical_start;
176 uint64_t map_end = map_start + (map_desc->num_pages << EFI_PAGE_SHIFT);
177 uint64_t carve_start = carve_desc->physical_start;
178 uint64_t carve_end = carve_start +
179 (carve_desc->num_pages << EFI_PAGE_SHIFT);
181 /* check whether we're overlapping */
182 if ((carve_end <= map_start) || (carve_start >= map_end))
183 return EFI_CARVE_NO_OVERLAP;
185 /* We're overlapping with non-RAM, warn the caller if desired */
186 if (overlap_only_ram && (map_desc->type != EFI_CONVENTIONAL_MEMORY))
187 return EFI_CARVE_OVERLAPS_NONRAM;
189 /* Sanitize carve_start and carve_end to lie within our bounds */
190 carve_start = max(carve_start, map_start);
191 carve_end = min(carve_end, map_end);
193 /* Carving at the beginning of our map? Just move it! */
194 if (carve_start == map_start) {
195 if (map_end == carve_end) {
196 /* Full overlap, just remove map */
197 list_del(&map->link);
200 map->desc.physical_start = carve_end;
201 map->desc.virtual_start = carve_end;
202 map->desc.num_pages = (map_end - carve_end)
206 return (carve_end - carve_start) >> EFI_PAGE_SHIFT;
210 * Overlapping maps, just split the list map at carve_start,
211 * it will get moved or removed in the next iteration.
213 * [ map_desc |__carve_start__| newmap ]
216 /* Create a new map from [ carve_start ... map_end ] */
217 newmap = calloc(1, sizeof(*newmap));
218 newmap->desc = map->desc;
219 newmap->desc.physical_start = carve_start;
220 newmap->desc.virtual_start = carve_start;
221 newmap->desc.num_pages = (map_end - carve_start) >> EFI_PAGE_SHIFT;
222 /* Insert before current entry (descending address order) */
223 list_add_tail(&newmap->link, &map->link);
225 /* Shrink the map to [ map_start ... carve_start ] */
226 map_desc->num_pages = (carve_start - map_start) >> EFI_PAGE_SHIFT;
228 return EFI_CARVE_LOOP_AGAIN;
232 * efi_add_memory_map() - add memory area to the memory map
234 * @start: start address, must be a multiple of EFI_PAGE_SIZE
235 * @pages: number of pages to add
236 * @memory_type: type of memory added
237 * @overlap_only_ram: the memory area must overlap existing
238 * Return: status code
240 efi_status_t efi_add_memory_map(uint64_t start, uint64_t pages, int memory_type,
241 bool overlap_only_ram)
243 struct list_head *lhandle;
244 struct efi_mem_list *newlist;
246 uint64_t carved_pages = 0;
247 struct efi_event *evt;
249 EFI_PRINT("%s: 0x%llx 0x%llx %d %s\n", __func__,
250 start, pages, memory_type, overlap_only_ram ? "yes" : "no");
252 if (memory_type >= EFI_MAX_MEMORY_TYPE)
253 return EFI_INVALID_PARAMETER;
258 ++efi_memory_map_key;
259 newlist = calloc(1, sizeof(*newlist));
260 newlist->desc.type = memory_type;
261 newlist->desc.physical_start = start;
262 newlist->desc.virtual_start = start;
263 newlist->desc.num_pages = pages;
265 switch (memory_type) {
266 case EFI_RUNTIME_SERVICES_CODE:
267 case EFI_RUNTIME_SERVICES_DATA:
268 newlist->desc.attribute = EFI_MEMORY_WB | EFI_MEMORY_RUNTIME;
271 newlist->desc.attribute = EFI_MEMORY_RUNTIME;
274 newlist->desc.attribute = EFI_MEMORY_WB;
278 /* Add our new map */
281 list_for_each(lhandle, &efi_mem) {
282 struct efi_mem_list *lmem;
285 lmem = list_entry(lhandle, struct efi_mem_list, link);
286 r = efi_mem_carve_out(lmem, &newlist->desc,
289 case EFI_CARVE_OVERLAPS_NONRAM:
291 * The user requested to only have RAM overlaps,
292 * but we hit a non-RAM region. Error out.
294 return EFI_NO_MAPPING;
295 case EFI_CARVE_NO_OVERLAP:
296 /* Just ignore this list entry */
298 case EFI_CARVE_LOOP_AGAIN:
300 * We split an entry, but need to loop through
301 * the list again to actually carve it.
306 /* We carved a number of pages */
313 /* The list changed, we need to start over */
317 } while (carve_again);
319 if (overlap_only_ram && (carved_pages != pages)) {
321 * The payload wanted to have RAM overlaps, but we overlapped
322 * with an unallocated region. Error out.
324 return EFI_NO_MAPPING;
327 /* Add our new map */
328 list_add_tail(&newlist->link, &efi_mem);
330 /* And make sure memory is listed in descending order */
333 /* Notify that the memory map was changed */
334 list_for_each_entry(evt, &efi_events, link) {
337 &efi_guid_event_group_memory_map_change)) {
338 efi_signal_event(evt);
347 * efi_check_allocated() - validate address to be freed
349 * Check that the address is within allocated memory:
351 * * The address must be in a range of the memory map.
352 * * The address may not point to EFI_CONVENTIONAL_MEMORY.
354 * Page alignment is not checked as this is not a requirement of
357 * @addr: address of page to be freed
358 * @must_be_allocated: return success if the page is allocated
359 * Return: status code
361 static efi_status_t efi_check_allocated(u64 addr, bool must_be_allocated)
363 struct efi_mem_list *item;
365 list_for_each_entry(item, &efi_mem, link) {
366 u64 start = item->desc.physical_start;
367 u64 end = start + (item->desc.num_pages << EFI_PAGE_SHIFT);
369 if (addr >= start && addr < end) {
370 if (must_be_allocated ^
371 (item->desc.type == EFI_CONVENTIONAL_MEMORY))
374 return EFI_NOT_FOUND;
378 return EFI_NOT_FOUND;
381 static uint64_t efi_find_free_memory(uint64_t len, uint64_t max_addr)
383 struct list_head *lhandle;
386 * Prealign input max address, so we simplify our matching
387 * logic below and can just reuse it as return pointer.
389 max_addr &= ~EFI_PAGE_MASK;
391 list_for_each(lhandle, &efi_mem) {
392 struct efi_mem_list *lmem = list_entry(lhandle,
393 struct efi_mem_list, link);
394 struct efi_mem_desc *desc = &lmem->desc;
395 uint64_t desc_len = desc->num_pages << EFI_PAGE_SHIFT;
396 uint64_t desc_end = desc->physical_start + desc_len;
397 uint64_t curmax = min(max_addr, desc_end);
398 uint64_t ret = curmax - len;
400 /* We only take memory from free RAM */
401 if (desc->type != EFI_CONVENTIONAL_MEMORY)
404 /* Out of bounds for max_addr */
405 if ((ret + len) > max_addr)
408 /* Out of bounds for upper map limit */
409 if ((ret + len) > desc_end)
412 /* Out of bounds for lower map limit */
413 if (ret < desc->physical_start)
416 /* Return the highest address in this map within bounds */
424 * Allocate memory pages.
426 * @type type of allocation to be performed
427 * @memory_type usage type of the allocated memory
428 * @pages number of pages to be allocated
429 * @memory allocated memory
430 * @return status code
432 efi_status_t efi_allocate_pages(int type, int memory_type,
433 efi_uintn_t pages, uint64_t *memory)
435 u64 len = pages << EFI_PAGE_SHIFT;
439 /* Check import parameters */
440 if (memory_type >= EFI_PERSISTENT_MEMORY_TYPE &&
441 memory_type <= 0x6FFFFFFF)
442 return EFI_INVALID_PARAMETER;
444 return EFI_INVALID_PARAMETER;
447 case EFI_ALLOCATE_ANY_PAGES:
449 addr = efi_find_free_memory(len, -1ULL);
451 return EFI_OUT_OF_RESOURCES;
453 case EFI_ALLOCATE_MAX_ADDRESS:
455 addr = efi_find_free_memory(len, *memory);
457 return EFI_OUT_OF_RESOURCES;
459 case EFI_ALLOCATE_ADDRESS:
460 /* Exact address, reserve it. The addr is already in *memory. */
461 ret = efi_check_allocated(*memory, false);
462 if (ret != EFI_SUCCESS)
463 return EFI_NOT_FOUND;
467 /* UEFI doesn't specify other allocation types */
468 return EFI_INVALID_PARAMETER;
471 /* Reserve that map in our memory maps */
472 if (efi_add_memory_map(addr, pages, memory_type, true) != EFI_SUCCESS)
473 /* Map would overlap, bail out */
474 return EFI_OUT_OF_RESOURCES;
481 void *efi_alloc(uint64_t len, int memory_type)
484 uint64_t pages = efi_size_in_pages(len);
487 r = efi_allocate_pages(EFI_ALLOCATE_ANY_PAGES, memory_type, pages,
489 if (r == EFI_SUCCESS)
490 return (void*)(uintptr_t)ret;
496 * efi_free_pages() - free memory pages
498 * @memory: start of the memory area to be freed
499 * @pages: number of pages to be freed
500 * Return: status code
502 efi_status_t efi_free_pages(uint64_t memory, efi_uintn_t pages)
506 ret = efi_check_allocated(memory, true);
507 if (ret != EFI_SUCCESS)
511 if (!memory || (memory & EFI_PAGE_MASK) || !pages) {
512 printf("%s: illegal free 0x%llx, 0x%zx\n", __func__,
514 return EFI_INVALID_PARAMETER;
517 ret = efi_add_memory_map(memory, pages, EFI_CONVENTIONAL_MEMORY, false);
518 /* Merging of adjacent free regions is missing */
520 if (ret != EFI_SUCCESS)
521 return EFI_NOT_FOUND;
527 * efi_allocate_pool - allocate memory from pool
529 * @pool_type: type of the pool from which memory is to be allocated
530 * @size: number of bytes to be allocated
531 * @buffer: allocated memory
532 * Return: status code
534 efi_status_t efi_allocate_pool(int pool_type, efi_uintn_t size, void **buffer)
538 struct efi_pool_allocation *alloc;
539 u64 num_pages = efi_size_in_pages(size +
540 sizeof(struct efi_pool_allocation));
543 return EFI_INVALID_PARAMETER;
550 r = efi_allocate_pages(EFI_ALLOCATE_ANY_PAGES, pool_type, num_pages,
552 if (r == EFI_SUCCESS) {
553 alloc = (struct efi_pool_allocation *)(uintptr_t)addr;
554 alloc->num_pages = num_pages;
555 alloc->checksum = checksum(alloc);
556 *buffer = alloc->data;
563 * efi_free_pool() - free memory from pool
565 * @buffer: start of memory to be freed
566 * Return: status code
568 efi_status_t efi_free_pool(void *buffer)
571 struct efi_pool_allocation *alloc;
574 return EFI_INVALID_PARAMETER;
576 ret = efi_check_allocated((uintptr_t)buffer, true);
577 if (ret != EFI_SUCCESS)
580 alloc = container_of(buffer, struct efi_pool_allocation, data);
582 /* Check that this memory was allocated by efi_allocate_pool() */
583 if (((uintptr_t)alloc & EFI_PAGE_MASK) ||
584 alloc->checksum != checksum(alloc)) {
585 printf("%s: illegal free 0x%p\n", __func__, buffer);
586 return EFI_INVALID_PARAMETER;
588 /* Avoid double free */
591 ret = efi_free_pages((uintptr_t)alloc, alloc->num_pages);
597 * Get map describing memory usage.
599 * @memory_map_size on entry the size, in bytes, of the memory map buffer,
600 * on exit the size of the copied memory map
601 * @memory_map buffer to which the memory map is written
602 * @map_key key for the memory map
603 * @descriptor_size size of an individual memory descriptor
604 * @descriptor_version version number of the memory descriptor structure
605 * @return status code
607 efi_status_t efi_get_memory_map(efi_uintn_t *memory_map_size,
608 struct efi_mem_desc *memory_map,
609 efi_uintn_t *map_key,
610 efi_uintn_t *descriptor_size,
611 uint32_t *descriptor_version)
613 efi_uintn_t map_size = 0;
615 struct list_head *lhandle;
616 efi_uintn_t provided_map_size;
618 if (!memory_map_size)
619 return EFI_INVALID_PARAMETER;
621 provided_map_size = *memory_map_size;
623 list_for_each(lhandle, &efi_mem)
626 map_size = map_entries * sizeof(struct efi_mem_desc);
628 *memory_map_size = map_size;
631 *descriptor_size = sizeof(struct efi_mem_desc);
633 if (descriptor_version)
634 *descriptor_version = EFI_MEMORY_DESCRIPTOR_VERSION;
636 if (provided_map_size < map_size)
637 return EFI_BUFFER_TOO_SMALL;
640 return EFI_INVALID_PARAMETER;
642 /* Copy list into array */
643 /* Return the list in ascending order */
644 memory_map = &memory_map[map_entries - 1];
645 list_for_each(lhandle, &efi_mem) {
646 struct efi_mem_list *lmem;
648 lmem = list_entry(lhandle, struct efi_mem_list, link);
649 *memory_map = lmem->desc;
654 *map_key = efi_memory_map_key;
660 * efi_add_conventional_memory_map() - add a RAM memory area to the map
662 * @ram_start: start address of a RAM memory area
663 * @ram_end: end address of a RAM memory area
664 * @ram_top: max address to be used as conventional memory
665 * Return: status code
667 efi_status_t efi_add_conventional_memory_map(u64 ram_start, u64 ram_end,
672 /* Remove partial pages */
673 ram_end &= ~EFI_PAGE_MASK;
674 ram_start = (ram_start + EFI_PAGE_MASK) & ~EFI_PAGE_MASK;
676 if (ram_end <= ram_start) {
677 /* Invalid mapping */
678 return EFI_INVALID_PARAMETER;
681 pages = (ram_end - ram_start) >> EFI_PAGE_SHIFT;
683 efi_add_memory_map(ram_start, pages,
684 EFI_CONVENTIONAL_MEMORY, false);
687 * Boards may indicate to the U-Boot memory core that they
688 * can not support memory above ram_top. Let's honor this
689 * in the efi_loader subsystem too by declaring any memory
690 * above ram_top as "already occupied by firmware".
692 if (ram_top < ram_start) {
693 /* ram_top is before this region, reserve all */
694 efi_add_memory_map(ram_start, pages,
695 EFI_BOOT_SERVICES_DATA, true);
696 } else if ((ram_top >= ram_start) && (ram_top < ram_end)) {
697 /* ram_top is inside this region, reserve parts */
698 pages = (ram_end - ram_top) >> EFI_PAGE_SHIFT;
700 efi_add_memory_map(ram_top, pages,
701 EFI_BOOT_SERVICES_DATA, true);
707 __weak void efi_add_known_memory(void)
709 u64 ram_top = board_get_usable_ram_top(0) & ~EFI_PAGE_MASK;
713 * ram_top is just outside mapped memory. So use an offset of one for
714 * mapping the sandbox address.
716 ram_top = (uintptr_t)map_sysmem(ram_top - 1, 0) + 1;
718 /* Fix for 32bit targets with ram_top at 4G */
720 ram_top = 0x100000000ULL;
723 for (i = 0; i < CONFIG_NR_DRAM_BANKS; i++) {
724 u64 ram_end, ram_start;
726 ram_start = (uintptr_t)map_sysmem(gd->bd->bi_dram[i].start, 0);
727 ram_end = ram_start + gd->bd->bi_dram[i].size;
729 efi_add_conventional_memory_map(ram_start, ram_end, ram_top);
733 /* Add memory regions for U-Boot's memory and for the runtime services code */
734 static void add_u_boot_and_runtime(void)
736 unsigned long runtime_start, runtime_end, runtime_pages;
737 unsigned long runtime_mask = EFI_PAGE_MASK;
738 unsigned long uboot_start, uboot_pages;
739 unsigned long uboot_stack_size = 16 * 1024 * 1024;
742 uboot_start = ((uintptr_t)map_sysmem(gd->start_addr_sp, 0) -
743 uboot_stack_size) & ~EFI_PAGE_MASK;
744 uboot_pages = ((uintptr_t)map_sysmem(gd->ram_top - 1, 0) -
745 uboot_start + EFI_PAGE_MASK) >> EFI_PAGE_SHIFT;
746 efi_add_memory_map(uboot_start, uboot_pages, EFI_LOADER_DATA, false);
748 #if defined(__aarch64__)
750 * Runtime Services must be 64KiB aligned according to the
751 * "AArch64 Platforms" section in the UEFI spec (2.7+).
754 runtime_mask = SZ_64K - 1;
758 * Add Runtime Services. We mark surrounding boottime code as runtime as
759 * well to fulfill the runtime alignment constraints but avoid padding.
761 runtime_start = (ulong)&__efi_runtime_start & ~runtime_mask;
762 runtime_end = (ulong)&__efi_runtime_stop;
763 runtime_end = (runtime_end + runtime_mask) & ~runtime_mask;
764 runtime_pages = (runtime_end - runtime_start) >> EFI_PAGE_SHIFT;
765 efi_add_memory_map(runtime_start, runtime_pages,
766 EFI_RUNTIME_SERVICES_CODE, false);
769 int efi_memory_init(void)
771 efi_add_known_memory();
773 add_u_boot_and_runtime();
775 #ifdef CONFIG_EFI_LOADER_BOUNCE_BUFFER
776 /* Request a 32bit 64MB bounce buffer region */
777 uint64_t efi_bounce_buffer_addr = 0xffffffff;
779 if (efi_allocate_pages(EFI_ALLOCATE_MAX_ADDRESS, EFI_LOADER_DATA,
780 (64 * 1024 * 1024) >> EFI_PAGE_SHIFT,
781 &efi_bounce_buffer_addr) != EFI_SUCCESS)
784 efi_bounce_buffer = (void*)(uintptr_t)efi_bounce_buffer_addr;