* [PATCH 0/7] sparc64: add Fujitsu M3000 support
@ 2026-10-02 16:14 Magnus Lindholm
2026-10-02 16:14 ` [PATCH 1/7] sparc64: return from the generic clear_page implementation Magnus Lindholm
` (6 more replies)
0 siblings, 7 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, netdev, linux-serial
Several years ago I salvaged an M3000 SPARC Enterprise box being
decommissioned at work. The box has been sitting ever since, it did
not run Linux. It did not seem impossible to get Linux running but
my earlier attempts failed. I recently found some documentation;
"SPARC JPS2: Common Specification" and the "Fujitsu SPARC64 II
Extensions", which gave me some of the missingpieces.
Getting this up and running required extensive testing, some
kernel instrumentation, debug printouts and many reboot iterations.
For thisi, Codex proved very helpful. Along the way, I stumbled upon
some generic sparc and driver bugs that this series addresses as well.
This series adds support for the Fujitsu SPARC Enterprise M3000, with
SPARC64 VII+, Oberon PCIe, BCM5718 networking and a firmware hvc console.
It applies to Linux v7.3-rc1, base cee9395acd8043be0644b25c34bfa86623f2b935.
Patches 1-3 fix existing sparc64 defects in generic clear_page, secondary
queued-spinlock acquisition and sun4u kernel huge-PUD mappings. Each has
a Fixes tag. Patches 4-7 add the CPU/MMU/SMP path, PCIe bridge, narrowly
matched tg3 firmware-state correction and console. They form one series
so the complete port can be built without collecting prerequisites.
VII context-write and demap synchronization follows the cited JPS2 and
SPARC64 VII manual sections. Existing Cheetah routines are unchanged:
similar assembly does not establish the same hardware requirement there.
The final tree includes the demap-all instruction synchronization in the
CPU/MMU patch. All seven cumulative prefixes build. The exact final image
boots Gentoo/OpenRC and SSH with eight threads; kernel taint is zero.
HugeTLB/THP, CPU offlining, Oberon MSI and complete RAS recovery remain
unsupported. Firmware console calls cannot be bounded if firmware stalls.
SPARC64 VII/VII+ support is currently opt-in through Kconfig while the new
CPU/MMU/SMP paths receive broader testing. The option also excludes HugeTLB
and THP configurations, which this implementation does not yet support.
The longer-term aim is to rely on runtime CPU detection once unsupported
huge-page configurations can be handled safely.
Magnus Lindholm (7):
sparc64: return from the generic clear_page implementation
sparc64: honor queued spinlock layout in secondary startup
sparc64: avoid huge kernel PUD mappings on sun4u
sparc64: add SPARC64 VII CPU, MMU and SMP support
sparc64: add M3000 Oberon PCIe support
tg3: normalize inherited M3000 register byte order
hvc: add an M3000 firmware console backend
MAINTAINERS | 6 +
arch/sparc/Kconfig | 19 +++
arch/sparc/include/asm/head_64.h | 15 ++
arch/sparc/include/asm/iommu_64.h | 1 +
arch/sparc/include/asm/irq_64.h | 1 +
arch/sparc/include/asm/setup.h | 5 +
arch/sparc/include/asm/smp_64.h | 4 +
arch/sparc/include/asm/spitfire.h | 1 +
arch/sparc/include/asm/trap_block.h | 6 +
arch/sparc/kernel/cpu.c | 3 +
arch/sparc/kernel/entry.h | 2 +
arch/sparc/kernel/head_64.S | 18 +++
arch/sparc/kernel/helpers.S | 41 +++++
arch/sparc/kernel/iommu.c | 44 ++++++
arch/sparc/kernel/irq_64.c | 50 ++++--
arch/sparc/kernel/pci_fire.c | 31 +++-
arch/sparc/kernel/pci_impl.h | 1 +
arch/sparc/kernel/prom_64.c | 6 +
arch/sparc/kernel/prom_irqtrans.c | 7 +
arch/sparc/kernel/ptrace_64.c | 7 +
arch/sparc/kernel/setup_64.c | 55 +++++++
arch/sparc/kernel/smp_64.c | 82 +++++++++-
arch/sparc/kernel/trampoline_64.S | 53 ++++++-
arch/sparc/kernel/traps_64.c | 27 ++++
arch/sparc/lib/GENpage.S | 3 +
arch/sparc/mm/init_64.c | 110 ++++++++++++-
arch/sparc/mm/tsb.c | 19 ++-
arch/sparc/mm/ultra.S | 236 ++++++++++++++++++++++++++++
drivers/net/ethernet/broadcom/tg3.c | 91 ++++++++++-
drivers/tty/hvc/Kconfig | 10 ++
drivers/tty/hvc/Makefile | 2 +
drivers/tty/hvc/hvc_m3000.c | 167 ++++++++++++++++++++
32 files changed, 1088 insertions(+), 35 deletions(-)
create mode 100644 drivers/tty/hvc/hvc_m3000.c
base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 1/7] sparc64: return from the generic clear_page implementation
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
2026-10-02 16:14 ` [PATCH 2/7] sparc64: honor queued spinlock layout in secondary startup Magnus Lindholm
` (5 subsequent siblings)
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, stable
GENclear_page falls through into generic_patch_pageops after clearing
its page. The patcher then rewrites kernel text on each invocation.
Return to the caller once the clear loop completes, as GENcopy_page does.
This affects processors using the generic page-operation fallback.
Fixes: 6c70b6fc7b6f ("[SPARC64]: Do not assume sun4v chips have load-twin/store-init support.")
Cc: stable@vger.kernel.org
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
arch/sparc/lib/GENpage.S | 3 +++
1 file changed, 3 insertions(+)
diff --git a/arch/sparc/lib/GENpage.S b/arch/sparc/lib/GENpage.S
index c143c4d1de3f..6ce11108e143 100644
--- a/arch/sparc/lib/GENpage.S
+++ b/arch/sparc/lib/GENpage.S
@@ -48,6 +48,9 @@ GENclear_user_page:
bne,pt %xcc, 1b
add %o0, 64, %o0
+ retl
+ nop
+
#define BRANCH_ALWAYS 0x10680000
#define NOP 0x01000000
#define GEN_DO_PATCH(OLD, NEW) \
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 2/7] sparc64: honor queued spinlock layout in secondary startup
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
2026-10-02 16:14 ` [PATCH 1/7] sparc64: return from the generic clear_page implementation Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
2026-10-02 16:14 ` [PATCH 3/7] sparc64: avoid huge kernel PUD mappings on sun4u Magnus Lindholm
` (4 subsequent siblings)
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, stable, Jane Chu, Shannon Nelson,
Vijay Kumar, Håkon Bugge
The trampoline's ldstub modifies the queue-tail byte of prom_entry_lock,
not its locked byte, because SPARC64 uses big-endian queued spinlocks.
Acquire the word with CASA, release byte three and poll while contended.
Retain the predicted-branch barriers for Spitfire erratum 51.
See qspinlock_types.h for the layout and JPS2 A.10/A.35 for CASA/MEMBAR.
Fixes: 145d97858597 ("arch/sparc: Enable queued spinlock support for SPARC")
Cc: stable@vger.kernel.org
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
arch/sparc/kernel/trampoline_64.S | 34 +++++++++++++++++++++++++++----
1 file changed, 30 insertions(+), 4 deletions(-)
diff --git a/arch/sparc/kernel/trampoline_64.S b/arch/sparc/kernel/trampoline_64.S
index 51bf1eb92a36..62f404b3079a 100644
--- a/arch/sparc/kernel/trampoline_64.S
+++ b/arch/sparc/kernel/trampoline_64.S
@@ -106,9 +106,19 @@ startup_continue:
* We lock 'num_kernel_image_mappings' consequetive entries.
*/
sethi %hi(prom_entry_lock), %g2
-1: ldstub [%g2 + %lo(prom_entry_lock)], %g1
+ /* Big-endian qspinlock: acquire the whole 32-bit value, not byte 0. */
+ or %g2, %lo(prom_entry_lock), %g2
+1: lduw [%g2], %g1
brnz,pn %g1, 1b
nop
+ mov 1, %g1
+ casa [%g2] ASI_P, %g0, %g1
+ brnz,pn %g1, 1b
+ nop
+ /* Spitfire erratum 51: barrier in a predicted-taken delay slot. */
+ ba,pt %xcc, 2f
+ membar #Sync
+2:
/* Get onto temporary stack which will be in the locked
* kernel image.
@@ -212,7 +222,10 @@ startup_continue:
nop
sethi %hi(prom_entry_lock), %g2
- stb %g0, [%g2 + %lo(prom_entry_lock)]
+ /* Match membar_safe() for Spitfire erratum 51. */
+ ba,pt %xcc, 2f
+ membar #StoreStore | #LoadStore
+2: stb %g0, [%g2 + %lo(prom_entry_lock) + 3]
ba,pt %xcc, after_lock_tlb
nop
@@ -326,9 +339,19 @@ after_lock_tlb:
wrpr %g0, 0, %wstate
sethi %hi(prom_entry_lock), %g2
-1: ldstub [%g2 + %lo(prom_entry_lock)], %g1
+ /* Big-endian qspinlock: acquire the whole 32-bit value, not byte 0. */
+ or %g2, %lo(prom_entry_lock), %g2
+1: lduw [%g2], %g1
brnz,pn %g1, 1b
nop
+ mov 1, %g1
+ casa [%g2] ASI_P, %g0, %g1
+ brnz,pn %g1, 1b
+ nop
+ /* Spitfire erratum 51: barrier in a predicted-taken delay slot. */
+ ba,pt %xcc, 2f
+ membar #Sync
+2:
/* As a hack, put &init_thread_union into %g6.
* prom_world() loads from here to restore the %asi
@@ -389,7 +412,10 @@ after_lock_tlb:
add %sp, (2047 + 128), %o0
3: sethi %hi(prom_entry_lock), %g2
- stb %g0, [%g2 + %lo(prom_entry_lock)]
+ /* Match membar_safe() for Spitfire erratum 51. */
+ ba,pt %xcc, 2f
+ membar #StoreStore | #LoadStore
+2: stb %g0, [%g2 + %lo(prom_entry_lock) + 3]
ldx [%l0], %g6
ldx [%g6 + TI_TASK], %g4
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 3/7] sparc64: avoid huge kernel PUD mappings on sun4u
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
2026-10-02 16:14 ` [PATCH 1/7] sparc64: return from the generic clear_page implementation Magnus Lindholm
2026-10-02 16:14 ` [PATCH 2/7] sparc64: honor queued spinlock layout in secondary startup Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
2026-10-02 16:14 ` [PATCH 4/7] sparc64: add SPARC64 VII CPU, MMU and SMP support Magnus Lindholm
` (3 subsequent siblings)
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, stable, Bob Picco
The kernel PUD refill path merges virtual address bits 32:28 into a
TTE, requiring a hardware page size of at least 256MB. On sun4u,
kern_linear_pte_xor[2] and [3] instead select the 4MB fallback TTE.
Consequently address bits 27:22 are lost when refilling a huge PUD.
Keep the kernel linear mapping at PMD granularity on sun4u. Its refill
path preserves bit 22, as required by the 4MB TTE. Leave the sun4v
mapping selection unchanged.
Fixes: 0dd5b7b09e13 ("sparc64: Fix physical memory management regressions with large max_phys_bits.")
Cc: stable@vger.kernel.org
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
arch/sparc/mm/init_64.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/arch/sparc/mm/init_64.c b/arch/sparc/mm/init_64.c
index 103db4683b16..0ae97e616435 100644
--- a/arch/sparc/mm/init_64.c
+++ b/arch/sparc/mm/init_64.c
@@ -1696,6 +1696,14 @@ static unsigned long __ref kernel_map_hugepud(unsigned long vstart,
static bool kernel_can_map_hugepud(unsigned long vstart, unsigned long vend,
bool guard)
{
+ /*
+ * The PUD miss path propagates VA bits 32:28, assuming at least
+ * 256MB hardware pages. Sun4u uses 4MB pages here: retain PMD
+ * mappings so bits 27:22 are not lost during TLB refill.
+ */
+ if (tlb_type != hypervisor)
+ return false;
+
if (guard && !(vstart & ~PUD_MASK) && (vend - vstart) >= PUD_SIZE)
return true;
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 4/7] sparc64: add SPARC64 VII CPU, MMU and SMP support
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
` (2 preceding siblings ...)
2026-10-02 16:14 ` [PATCH 3/7] sparc64: avoid huge kernel PUD mappings on sun4u Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
2026-10-02 16:14 ` [PATCH 5/7] sparc64: add M3000 Oberon PCIe support Magnus Lindholm
` (2 subsequent siblings)
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, Oleg Nesterov
Recognize implementation 7 and add the M3000 CPU/MMU/SMP path, including
topology, serialized interrupt dispatch and restrainable ECC handling.
Use physical TSB accesses to avoid sibling aliases in the shared TLB;
synchronize context writes and instruction demaps while preserving
supported firmware modes and the existing non-VII demap routines.
CPU offlining, HugeTLB and THP remain unsupported on this path.
Keep VII demap routines separate: similar Cheetah assembly does not
establish the same hardware synchronization requirement on Cheetah.
Hardware references (printed sections/pages):
- SPARC64 VII Extensions v1.0: 8.4.7 pp.42-43 (coherence), A.30 pp.64-65
(physical loads), F.10 pp.109-110 (MCNTL), F.10.4 (indexed TLBs),
F.12 p.129 (sibling sharing).
- VII N.1 pp.155-156, N.4.2/N.4.3 p.158, R.3 (IPIs/target IDs);
P.3.1 and P.7.1/P.7.4 pp.198-200 (error registers).
- JPS2 Common r1.0 F.10.1 p.488, F.10.11 pp.500-502 (MMU ordering).
JPS2 Commonality F.10.1 also requires a final instruction flush after
demap-all so subsequent instruction fetches observe the invalidation.
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
arch/sparc/Kconfig | 10 ++
arch/sparc/include/asm/head_64.h | 15 ++
arch/sparc/include/asm/setup.h | 5 +
arch/sparc/include/asm/smp_64.h | 4 +
arch/sparc/include/asm/spitfire.h | 1 +
arch/sparc/include/asm/trap_block.h | 6 +
arch/sparc/kernel/cpu.c | 3 +
arch/sparc/kernel/entry.h | 2 +
arch/sparc/kernel/head_64.S | 18 +++
arch/sparc/kernel/helpers.S | 41 +++++
arch/sparc/kernel/prom_64.c | 6 +
arch/sparc/kernel/ptrace_64.c | 7 +
arch/sparc/kernel/setup_64.c | 55 +++++++
arch/sparc/kernel/smp_64.c | 82 +++++++++-
arch/sparc/kernel/trampoline_64.S | 19 +++
arch/sparc/kernel/traps_64.c | 27 ++++
arch/sparc/mm/init_64.c | 102 +++++++++++-
arch/sparc/mm/tsb.c | 19 ++-
arch/sparc/mm/ultra.S | 236 ++++++++++++++++++++++++++++
19 files changed, 642 insertions(+), 16 deletions(-)
diff --git a/arch/sparc/Kconfig b/arch/sparc/Kconfig
index ab77d3f2536e..1263150a5702 100644
--- a/arch/sparc/Kconfig
+++ b/arch/sparc/Kconfig
@@ -250,6 +250,16 @@ config US3_MC
If in doubt, say Y, as this information can be very useful.
+config SPARC64_VII
+ bool "Fujitsu SPARC64 VII and VII+ support"
+ depends on SPARC64
+ depends on !HUGETLB_PAGE && !TRANSPARENT_HUGEPAGE
+ help
+ Support SPARC64 VII and VII+ processors in the Fujitsu M3000.
+ Firmware must leave context hashing and multiple-page-size
+ context mode disabled. HugeTLB and transparent huge pages are
+ not supported by this CPU path.
+
# Global things across all Sun machines.
config GENERIC_LOCKBREAK
bool
diff --git a/arch/sparc/include/asm/head_64.h b/arch/sparc/include/asm/head_64.h
index 69a2062d992c..62ea826f174b 100644
--- a/arch/sparc/include/asm/head_64.h
+++ b/arch/sparc/include/asm/head_64.h
@@ -20,6 +20,21 @@
#define RTRAP_PSTATE_IRQOFF (PSTATE_TSO|PSTATE_PEF|PSTATE_PRIV)
#define RTRAP_PSTATE_AG_IRQOFF (PSTATE_TSO|PSTATE_PEF|PSTATE_PRIV|PSTATE_AG)
+#define __SPARC64_VII_ID 0x00040007
+
+#ifdef CONFIG_SPARC64_VII
+#define BRANCH_IF_SPARC64_VII(tmp1, tmp2, label) \
+ rdpr %ver, %tmp1; \
+ srlx %tmp1, 32, %tmp1; \
+ sethi %hi(__SPARC64_VII_ID), %tmp2; \
+ or %tmp2, %lo(__SPARC64_VII_ID), %tmp2; \
+ cmp %tmp1, %tmp2; \
+ be,pn %icc, label; \
+ nop
+#else
+#define BRANCH_IF_SPARC64_VII(tmp1, tmp2, label)
+#endif
+
#define __CHEETAH_ID 0x003e0014
#define __JALAPENO_ID 0x003e0016
#define __SERRANO_ID 0x003e0022
diff --git a/arch/sparc/include/asm/setup.h b/arch/sparc/include/asm/setup.h
index 21bed5514028..ef6ff1169ec0 100644
--- a/arch/sparc/include/asm/setup.h
+++ b/arch/sparc/include/asm/setup.h
@@ -49,6 +49,11 @@ unsigned long safe_compute_effective_address(struct pt_regs *, unsigned int);
#ifdef CONFIG_SPARC64
void __init start_early_boot(void);
+extern unsigned int sparc64_ttable_tl0[], sparc64_ttable_tl1[];
+void sparc64_vii_fatal_trap(void);
+void sparc64_vii_ecc_trap(void);
+void sparc64_vii_ecc_trap_tl1(void);
+
/* unaligned_64.c */
int handle_ldf_stq(u32 insn, struct pt_regs *regs);
void handle_ld_nf(u32 insn, struct pt_regs *regs);
diff --git a/arch/sparc/include/asm/smp_64.h b/arch/sparc/include/asm/smp_64.h
index 759fb4a9530e..bbf171c9d1e9 100644
--- a/arch/sparc/include/asm/smp_64.h
+++ b/arch/sparc/include/asm/smp_64.h
@@ -34,6 +34,10 @@
DECLARE_PER_CPU(cpumask_t, cpu_sibling_map);
extern cpumask_t cpu_core_map[NR_CPUS];
+#ifdef CONFIG_SPARC64_VII
+extern unsigned long vii_startup_mcntl;
+#endif
+
void smp_init_cpu_poke(void);
void scheduler_poke(void);
diff --git a/arch/sparc/include/asm/spitfire.h b/arch/sparc/include/asm/spitfire.h
index 79b9dd5e9ac6..9bfa9348dd5a 100644
--- a/arch/sparc/include/asm/spitfire.h
+++ b/arch/sparc/include/asm/spitfire.h
@@ -75,6 +75,7 @@ enum ultra_tlb_layout {
cheetah = 1,
cheetah_plus = 2,
hypervisor = 3,
+ sparc64_vii = 4,
};
extern enum ultra_tlb_layout tlb_type;
diff --git a/arch/sparc/include/asm/trap_block.h b/arch/sparc/include/asm/trap_block.h
index 6cf2a60a0156..04f3d5826e16 100644
--- a/arch/sparc/include/asm/trap_block.h
+++ b/arch/sparc/include/asm/trap_block.h
@@ -67,6 +67,7 @@ struct cpuid_patch_entry {
unsigned int cheetah_jbus[4];
unsigned int starfire[4];
unsigned int sun4v[4];
+ unsigned int vii[4];
};
extern struct cpuid_patch_entry __cpuid_patch, __cpuid_patch_end;
@@ -146,6 +147,11 @@ extern struct sun4v_2insn_patch_entry __sun_m7_2insn_patch,
ldxa [REG] ASI_SCRATCHPAD, REG; \
nop; \
nop; \
+ /* SPARC64 VII: Jupiter ITID is bits 9:0. */ \
+ ldxa [%g0] ASI_UPA_CONFIG, REG; \
+ and REG, 0x3ff, REG; \
+ nop; \
+ nop; \
.previous;
#ifdef CONFIG_SMP
diff --git a/arch/sparc/kernel/cpu.c b/arch/sparc/kernel/cpu.c
index 79cd6ccfeac0..015bf4e5ca10 100644
--- a/arch/sparc/kernel/cpu.c
+++ b/arch/sparc/kernel/cpu.c
@@ -123,6 +123,7 @@ static const struct manufacturer_info __initconst manufacturer_info[] = {
FPU(-1, NULL)
}
},{
+ /* SPARC64 Fujitsu %ver manufacturer 4 shares the sparc32 TI value. */
PSR_IMPL_TI,
.cpu_info = {
CPU(0, "Texas Instruments, Inc. - SuperSparc-(II)"),
@@ -132,6 +133,7 @@ static const struct manufacturer_info __initconst manufacturer_info[] = {
CPU(3, "Texas Instruments, Inc. - SuperSparc 51"),
CPU(4, "Texas Instruments, Inc. - SuperSparc 61"),
CPU(5, "Texas Instruments, Inc. - unknown"),
+ CPU(7, "Fujitsu SPARC64 VII / VII+"),
CPU(-1, NULL)
},
.fpu_info = {
@@ -139,6 +141,7 @@ static const struct manufacturer_info __initconst manufacturer_info[] = {
FPU(0, "SuperSparc on-chip FPU"),
/* SparcClassic */
FPU(4, "TI MicroSparc on chip FPU"),
+ FPU(7, "Fujitsu SPARC64 VII integrated FPU"),
FPU(-1, NULL)
}
},{
diff --git a/arch/sparc/kernel/entry.h b/arch/sparc/kernel/entry.h
index c746c0fd5d6b..517eb1a054f2 100644
--- a/arch/sparc/kernel/entry.h
+++ b/arch/sparc/kernel/entry.h
@@ -249,5 +249,7 @@ extern unsigned long ivector_table_pa;
void init_irqwork_curcpu(void);
void sun4v_register_mondo_queues(int this_cpu);
+void sparc64_vii_ecc_error(struct pt_regs *regs);
+
#endif /* CONFIG_SPARC32 */
#endif /* _ENTRY_H */
diff --git a/arch/sparc/kernel/head_64.S b/arch/sparc/kernel/head_64.S
index cf0549134234..8f879abc07f0 100644
--- a/arch/sparc/kernel/head_64.S
+++ b/arch/sparc/kernel/head_64.S
@@ -485,6 +485,8 @@ EXPORT_SYMBOL(sun4v_chip_type)
80:
BRANCH_IF_SUN4V(g1, jump_to_sun4u_init)
+ /* Preserve Fujitsu firmware cache/MMU control, not Spitfire LSU. */
+ BRANCH_IF_SPARC64_VII(g1,g7,jump_to_sun4u_init)
BRANCH_IF_CHEETAH_BASE(g1,g7,cheetah_boot)
BRANCH_IF_CHEETAH_PLUS_OR_FOLLOWON(g1,g7,cheetah_plus_boot)
ba,pt %xcc, spitfire_boot
@@ -574,6 +576,7 @@ sun4v_init:
ba,a,pt %xcc, niagara_tlb_fixup
sun4u_continue:
+ BRANCH_IF_SPARC64_VII(g1,g7,sparc64_vii_tlb_fixup)
BRANCH_IF_ANY_CHEETAH(g1, g7, cheetah_tlb_fixup)
ba,a,pt %xcc, spitfire_tlb_fixup
@@ -692,6 +695,20 @@ cheetah_tlb_fixup:
ba,a,pt %xcc, tlb_fixup_done
+sparc64_vii_tlb_fixup:
+ mov 4, %g2
+ sethi %hi(tlb_type), %g1
+ stw %g2, [%g1 + %lo(tlb_type)]
+ call generic_patch_copyops
+ nop
+ call generic_patch_bzero
+ nop
+ call generic_patch_pageops
+ nop
+ call sparc64_vii_patch_cachetlbops
+ nop
+ ba,a,pt %xcc, tlb_fixup_done
+
spitfire_tlb_fixup:
/* Set TLB type to spitfire. */
mov 0, %g2
@@ -841,6 +858,7 @@ setup_trap_table:
sllx %o2, 32, %o2
wr %o2, 0, %tick_cmpr
+ BRANCH_IF_SPARC64_VII(o2, o3, 1f)
BRANCH_IF_ANY_CHEETAH(o2, o3, 1f)
ba,a,pt %xcc, 2f
diff --git a/arch/sparc/kernel/helpers.S b/arch/sparc/kernel/helpers.S
index 9b3f74706cfb..da5467db2de3 100644
--- a/arch/sparc/kernel/helpers.S
+++ b/arch/sparc/kernel/helpers.S
@@ -64,3 +64,44 @@ real_hard_smp_processor_id:
#endif
.size real_hard_smp_processor_id,.-real_hard_smp_processor_id
EXPORT_SYMBOL_GPL(real_hard_smp_processor_id)
+
+ .align 32
+ .globl sparc64_vii_ecc_trap
+sparc64_vii_ecc_trap:
+ TRAP(sparc64_vii_ecc_error)
+ .globl sparc64_vii_ecc_trap_tl1
+sparc64_vii_ecc_trap_tl1:
+ TRAPTL1(sparc64_vii_ecc_error)
+
+ .align 32
+ .globl sparc64_vii_fatal_trap
+sparc64_vii_fatal_trap:
+ wrpr %g0, 15, %pil
+ sethi %hi(sparc64_vii_fault_record), %g1
+ or %g1, %lo(sparc64_vii_fault_record), %g1
+ rdpr %tpc, %g2
+ stx %g2, [%g1 + 8]
+ rdpr %tnpc, %g2
+ stx %g2, [%g1 + 16]
+ rdpr %tstate, %g2
+ stx %g2, [%g1 + 24]
+ rdpr %tl, %g2
+ stx %g2, [%g1 + 32]
+ rdpr %tt, %g2
+ stx %g2, [%g1 + 40]
+ /* VII Appendix P: state-change error information, read-only here. */
+ mov 0x18, %g2
+ ldxa [%g2] 0x4c, %g2
+ stx %g2, [%g1 + 48]
+ sethi %hi(0x56494900), %g2
+ stx %g2, [%g1]
+ membar #Sync
+1: ba,pt %xcc, 1b
+ nop
+
+ .data
+ .align 64
+ .globl sparc64_vii_fault_record
+sparc64_vii_fault_record:
+ .xword 0, 0, 0, 0, 0, 0, 0, 0
+ .previous
diff --git a/arch/sparc/kernel/prom_64.c b/arch/sparc/kernel/prom_64.c
index aa4799cbb9c1..11437bbfc73b 100644
--- a/arch/sparc/kernel/prom_64.c
+++ b/arch/sparc/kernel/prom_64.c
@@ -564,6 +564,12 @@ static void *fill_in_one_cpu(struct device_node *dp, int cpuid, int arg)
cpu_data(cpuid).core_id = portid + 1;
cpu_data(cpuid).proc_id = portid;
+ if (tlb_type == sparc64_vii &&
+ of_property_match_string(of_root, "model", "IKKAKU") >= 0) {
+ /* IKKAKU: two adjacent ITIDs per physical core. */
+ cpu_data(cpuid).core_id = (cpuid >> 1) + 1;
+ cpu_data(cpuid).proc_id = 0;
+ }
} else {
cpu_data(cpuid).dcache_size =
of_getintprop_default(dp, "dcache-size", 16 * 1024);
diff --git a/arch/sparc/kernel/ptrace_64.c b/arch/sparc/kernel/ptrace_64.c
index 825ddf55fece..0d537ae7bef3 100644
--- a/arch/sparc/kernel/ptrace_64.c
+++ b/arch/sparc/kernel/ptrace_64.c
@@ -109,6 +109,13 @@ void flush_ptrace_access(struct vm_area_struct *vma, struct page *page,
{
BUG_ON(len > PAGE_SIZE);
+ if (tlb_type == sparc64_vii) {
+ /* VII caches are coherent; ASI_DCACHE_INVALIDATE is not valid. */
+ flush_icache_range((unsigned long)kaddr,
+ (unsigned long)kaddr + len);
+ return;
+ }
+
if (tlb_type == hypervisor)
return;
diff --git a/arch/sparc/kernel/setup_64.c b/arch/sparc/kernel/setup_64.c
index 63615f5c99b4..0f1187fc775f 100644
--- a/arch/sparc/kernel/setup_64.c
+++ b/arch/sparc/kernel/setup_64.c
@@ -184,6 +184,9 @@ static void __init per_cpu_patch(void)
else
insns = &p->cheetah_safari[0];
break;
+ case sparc64_vii:
+ insns = &p->vii[0];
+ break;
case hypervisor:
insns = &p->sun4v[0];
break;
@@ -349,6 +352,40 @@ static void __init pause_patch(void)
}
}
+/*
+ * Route restrainable ECC (0x63) to the VII C handler.
+ * Other patched errors record state and halt without touching Spitfire
+ * error/cache registers, including at TL>1.
+ */
+static void __init vii_patch_error_traps(void)
+{
+ static const unsigned int traps[] = { 0x0a, 0x32, 0x40, 0x63 };
+ unsigned int *tables[] = { sparc64_ttable_tl0, sparc64_ttable_tl1 };
+ int i, j;
+
+ for (i = 0; i < ARRAY_SIZE(tables); i++) {
+ for (j = 0; j < ARRAY_SIZE(traps); j++) {
+ unsigned int *slot = tables[i] + traps[j] * 8;
+ void (*handler)(void) = sparc64_vii_fatal_trap;
+ long delta;
+
+ if (traps[j] == 0x63)
+ handler = i ? sparc64_vii_ecc_trap_tl1 :
+ sparc64_vii_ecc_trap;
+ delta = (long)handler - (long)slot;
+
+ /* ba (disp22), followed by nop. */
+ if (delta < -(1L << 23) || delta >= (1L << 23))
+ prom_halt();
+ slot[1] = 0x01000000;
+ slot[0] = 0x10800000 | ((delta >> 2) & 0x3fffff);
+ /* Publish the trap instructions before synchronizing fetch. */
+ wmb();
+ __asm__ __volatile__("flush %0" : : "r" (slot));
+ }
+ }
+}
+
void __init start_early_boot(void)
{
int cpu;
@@ -358,6 +395,24 @@ void __init start_early_boot(void)
sun4v_patch();
smp_init_cpu_poke();
+ if (tlb_type == sparc64_vii) {
+ unsigned long mcntl;
+
+ vii_patch_error_traps();
+
+ __asm__ __volatile__("ldxa [%1] 0x45, %0"
+ : "=r" (mcntl) : "r" (8UL));
+ /*
+ * No context hashing, forced uncached instruction caching or
+ * multiple-page-size context mode is supported by this path.
+ * Preserve firmware state; stop if a mode transition is required.
+ */
+ if (mcntl & 0x101c0UL) {
+ prom_printf("VII-BOOT: incompatible inherited MCNTL; halted\n");
+ prom_halt();
+ }
+ }
+
cpu = hard_smp_processor_id();
if (cpu >= NR_CPUS) {
prom_printf("Serious problem, boot cpu id (%d) >= NR_CPUS (%d)\n",
diff --git a/arch/sparc/kernel/smp_64.c b/arch/sparc/kernel/smp_64.c
index 371460e34484..9717836bf441 100644
--- a/arch/sparc/kernel/smp_64.c
+++ b/arch/sparc/kernel/smp_64.c
@@ -288,7 +288,6 @@ static void smp_synchronize_one_tick(int cpu)
static void ldom_startcpu_cpuid(unsigned int cpu, unsigned long thread_reg,
void **descrp)
{
- extern unsigned long sparc64_ttable_tl0;
extern unsigned long kern_locked_tte_data;
struct hvtramp_descr *hdesc;
unsigned long trampoline_ra;
@@ -344,6 +343,11 @@ extern unsigned long sparc64_cpu_startup;
*/
static struct thread_info *cpu_new_thread = NULL;
+#ifdef CONFIG_SPARC64_VII
+/* Written before the secondary validates its inherited MMU control. */
+unsigned long vii_startup_mcntl;
+#endif
+
static int smp_boot_one_cpu(unsigned int cpu, struct task_struct *idle)
{
unsigned long entry =
@@ -354,6 +358,10 @@ static int smp_boot_one_cpu(unsigned int cpu, struct task_struct *idle)
int timeout, ret;
callin_flag = 0;
+#ifdef CONFIG_SPARC64_VII
+ if (tlb_type == sparc64_vii)
+ WRITE_ONCE(vii_startup_mcntl, ~0UL);
+#endif
cpu_new_thread = task_thread_info(idle);
if (tlb_type == hypervisor) {
@@ -381,6 +389,11 @@ static int smp_boot_one_cpu(unsigned int cpu, struct task_struct *idle)
ret = 0;
} else {
printk("Processor %d is stuck.\n", cpu);
+#ifdef CONFIG_SPARC64_VII
+ if (tlb_type == sparc64_vii)
+ pr_err("VII secondary CPU %u MCNTL=%lx (all ones: not reached)\n",
+ cpu, READ_ONCE(vii_startup_mcntl));
+#endif
ret = -ENODEV;
}
cpu_new_thread = NULL;
@@ -390,6 +403,55 @@ static int smp_boot_one_cpu(unsigned int cpu, struct task_struct *idle)
return ret;
}
+/*
+ * VII manual Appendix N: dispatch using BUSY/NACK pair zero, one target
+ * at a time. No Spitfire UDB erratum access and no hypervisor operation.
+ */
+static void vii_xcall_deliver(struct trap_per_cpu *tb, int cnt)
+{
+ u64 *data = __va(tb->cpu_mondo_block_pa);
+ u16 *cpus = __va(tb->cpu_list_pa);
+ unsigned long pstate, disabled;
+ int i;
+
+ __asm__ __volatile__("rdpr %%pstate, %0" : "=r" (pstate));
+ disabled = pstate & ~PSTATE_IE;
+ for (i = 0; i < cnt; i++) {
+ unsigned long target = ((unsigned long)cpus[i] << 14) | 0x70;
+ unsigned long status = 0;
+ int retry;
+
+ for (retry = 0; retry < 10000; retry++) {
+ int polls = 1000000;
+
+ __asm__ __volatile__("wrpr %0, 0, %%pstate\n\t"
+ "stxa %1, [%4] %7\n\t"
+ "stxa %2, [%5] %7\n\t"
+ "stxa %3, [%6] %7\n\t"
+ "membar #Sync\n\t"
+ "stxa %%g0, [%8] %7\n\t"
+ "membar #Sync"
+ : : "r" (disabled), "r" (data[0]), "r" (data[1]),
+ "r" (data[2]), "r" (0x40UL), "r" (0x50UL),
+ "r" (0x60UL), "i" (ASI_INTR_W), "r" (target)
+ : "memory");
+ do {
+ __asm__ __volatile__("ldxa [%%g0] %1, %0"
+ : "=r" (status) : "i" (ASI_INTR_DISPATCH_STAT));
+ } while ((status & 1) && --polls);
+ __asm__ __volatile__("wrpr %0, 0, %%pstate"
+ : : "r" (pstate) : "memory");
+ if (!polls)
+ panic("VII IPI busy timeout target=%u status=%lx", cpus[i], status);
+ if (!(status & 2))
+ break;
+ udelay(2);
+ }
+ if (retry == 10000)
+ panic("VII IPI NACK timeout target=%u status=%lx", cpus[i], status);
+ }
+}
+
static void spitfire_xcall_helper(u64 data0, u64 data1, u64 data2, u64 pstate, unsigned long cpu)
{
u64 result, target;
@@ -1205,7 +1267,9 @@ void __init smp_prepare_cpus(unsigned int max_cpus)
void __init smp_setup_processor_id(void)
{
- if (tlb_type == spitfire)
+ if (tlb_type == sparc64_vii)
+ xcall_deliver_impl = vii_xcall_deliver;
+ else if (tlb_type == spitfire)
xcall_deliver_impl = spitfire_xcall_deliver;
else if (tlb_type == cheetah || tlb_type == cheetah_plus)
xcall_deliver_impl = cheetah_xcall_deliver;
@@ -1256,8 +1320,14 @@ void smp_fill_in_sib_core_maps(void)
}
for_each_present_cpu(j) {
- if (cpu_data(i).proc_id ==
- cpu_data(j).proc_id)
+ bool sibling;
+
+ /* VII proc_id identifies the package, not the core. */
+ if (tlb_type == sparc64_vii)
+ sibling = cpu_data(i).core_id == cpu_data(j).core_id;
+ else
+ sibling = cpu_data(i).proc_id == cpu_data(j).proc_id;
+ if (sibling)
cpumask_set_cpu(j, &per_cpu(cpu_sibling_map, i));
}
}
@@ -1326,6 +1396,10 @@ int __cpu_disable(void)
cpuinfo_sparc *c;
int i;
+ /* VII secondary startup does not implement offline/restart. */
+ if (tlb_type == sparc64_vii)
+ return -EOPNOTSUPP;
+
for_each_cpu(i, &cpu_core_map[cpu])
cpumask_clear_cpu(cpu, &cpu_core_map[i]);
cpumask_clear(&cpu_core_map[cpu]);
diff --git a/arch/sparc/kernel/trampoline_64.S b/arch/sparc/kernel/trampoline_64.S
index 62f404b3079a..73838a021be6 100644
--- a/arch/sparc/kernel/trampoline_64.S
+++ b/arch/sparc/kernel/trampoline_64.S
@@ -40,6 +40,7 @@ tramp_stack:
.align 8
.globl sparc64_cpu_startup, sparc64_cpu_startup_end
sparc64_cpu_startup:
+ BRANCH_IF_SPARC64_VII(g1, g5, vii_startup)
BRANCH_IF_SUN4V(g1, niagara_startup)
BRANCH_IF_CHEETAH_BASE(g1, g5, cheetah_startup)
BRANCH_IF_CHEETAH_PLUS_OR_FOLLOWON(g1, g5, cheetah_plus_startup)
@@ -47,6 +48,23 @@ sparc64_cpu_startup:
ba,pt %xcc, spitfire_startup
nop
+#ifdef CONFIG_SPARC64_VII
+vii_startup:
+ /* Preserve firmware cache/MMU control, as on the boot CPU. */
+ mov 8, %g1
+ ldxa [%g1] 0x45, %g5
+ sethi %hi(vii_startup_mcntl), %g1
+ stx %g5, [%g1 + %lo(vii_startup_mcntl)]
+ membar #Sync
+ set 0x101c0, %g1
+ andcc %g5, %g1, %g0
+1: bne,pn %xcc, 1b
+ nop
+ ba,pt %xcc, niagara_startup
+ nop
+
+#endif /* CONFIG_SPARC64_VII */
+
cheetah_plus_startup:
/* Preserve OBP chosen DCU and DCR register settings. */
ba,pt %xcc, cheetah_generic_startup
@@ -144,6 +162,7 @@ startup_continue:
lduw [%l6 + %lo(num_kernel_image_mappings)], %l6
mov 15, %l7
+ BRANCH_IF_SPARC64_VII(g1,g5,2f)
BRANCH_IF_ANY_CHEETAH(g1,g5,2f)
mov 63, %l7
diff --git a/arch/sparc/kernel/traps_64.c b/arch/sparc/kernel/traps_64.c
index 28cb0d66ab40..3c693b7bd32b 100644
--- a/arch/sparc/kernel/traps_64.c
+++ b/arch/sparc/kernel/traps_64.c
@@ -2716,6 +2716,33 @@ void do_privact(struct pt_regs *regs)
do_privop(regs);
}
+/* SPARC64 VII Extensions, Appendix P.7.1 and P.7.4. */
+#define VII_AFSR_DEGRADATION ((1UL << 12) | (1UL << 11) | (1UL << 10))
+
+void sparc64_vii_ecc_error(struct pt_regs *regs)
+{
+ enum ctx_state prev_state = exception_enter();
+ unsigned long afsr;
+
+ __asm__ __volatile__("ldxa [%%g0] 0x4c, %0" : "=r" (afsr));
+ /* An ECC trap without a sticky error indication is explicitly allowed. */
+ if (!afsr)
+ goto out;
+
+ /* No data recovery is implemented for raw UE or store bus errors. */
+ if (afsr & ~VII_AFSR_DEGRADATION)
+ panic("SPARC64 VII: unhandled ECC error, CPU %u AFSR=%lx TPC=%lx",
+ smp_processor_id(), afsr, regs->tpc);
+
+ /* Hardware has already reduced the affected cache/TLB associativity. */
+ __asm__ __volatile__("stxa %0, [%%g0] 0x4c; membar #Sync"
+ : : "r" (afsr) : "memory");
+ pr_warn_ratelimited("SPARC64 VII: CPU %u cache/TLB degradation, AFSR=%lx\n",
+ smp_processor_id(), afsr);
+out:
+ exception_exit(prev_state);
+}
+
/* Trap level 1 stuff or other traps we should never see... */
void do_cee(struct pt_regs *regs)
{
diff --git a/arch/sparc/mm/init_64.c b/arch/sparc/mm/init_64.c
index 0ae97e616435..4918afdcc923 100644
--- a/arch/sparc/mm/init_64.c
+++ b/arch/sparc/mm/init_64.c
@@ -271,7 +271,8 @@ static inline void tsb_insert(struct tsb *ent, unsigned long tag, unsigned long
{
unsigned long tsb_addr = (unsigned long) ent;
- if (tlb_type == cheetah_plus || tlb_type == hypervisor)
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii)
tsb_addr = __pa(tsb_addr);
__tsb_insert(tsb_addr, tag, pte);
@@ -495,6 +496,12 @@ EXPORT_SYMBOL(flush_dcache_folio);
void __kprobes flush_icache_range(unsigned long start, unsigned long end)
{
+ if (tlb_type == sparc64_vii) {
+ /* Coherent caches still require instruction-stream synchronization. */
+ __asm__ __volatile__("membar #Sync\n\tflush %0"
+ : : "r" (start) : "memory");
+ return;
+ }
/* Cheetah and Hypervisor platform cpus have coherent I-cache. */
if (tlb_type == spitfire) {
unsigned long kaddr;
@@ -530,6 +537,8 @@ void mmu_info(struct seq_file *m)
seq_printf(m, "MMU Type\t: Cheetah\n");
else if (tlb_type == cheetah_plus)
seq_printf(m, "MMU Type\t: Cheetah+\n");
+ else if (tlb_type == sparc64_vii)
+ seq_puts(m, "MMU Type\t: Fujitsu SPARC64 VII\n");
else if (tlb_type == spitfire)
seq_printf(m, "MMU Type\t: Spitfire\n");
else if (tlb_type == hypervisor)
@@ -666,6 +675,50 @@ static void __init hypervisor_tlb_lock(unsigned long vaddr,
static unsigned long kern_large_tte(unsigned long paddr);
+/*
+ * Reserve two 4MB kernel mappings and an adjacent slot in the lower half
+ * of the fully associative bank. Check existing reservations, firmware
+ * status and physical slot readback before using the mappings.
+ */
+static void __init vii_check_slots(void)
+{
+ int i;
+
+ if (num_kernel_image_mappings > 2) {
+ prom_printf("VII-BOOT: kernel exceeds initial 8MB mapping budget\n");
+ prom_halt();
+ }
+ for (i = 15 - num_kernel_image_mappings; i <= 15; i++) {
+ unsigned long d = cheetah_get_ldtlb_data(i);
+ unsigned long t = cheetah_get_litlb_data(i);
+
+ if (((d & (_PAGE_VALID | _PAGE_L_4U)) ==
+ (_PAGE_VALID | _PAGE_L_4U)) ||
+ ((t & (_PAGE_VALID | _PAGE_L_4U)) ==
+ (_PAGE_VALID | _PAGE_L_4U))) {
+ prom_printf("VII-BOOT: reserved slot %d occupied; halted\n", i);
+ prom_halt();
+ }
+ }
+}
+
+static void __init vii_check_mapping(int slot, unsigned long va,
+ unsigned long tte)
+{
+ unsigned long mask = _PAGE_VALID | _PAGE_SZ4MB_4U |
+ _PAGE_PADDR_4U | _PAGE_L_4U;
+ unsigned long d = cheetah_get_ldtlb_data(slot);
+ unsigned long t = cheetah_get_litlb_data(slot);
+ unsigned long dt = cheetah_get_ldtlb_tag(slot);
+ unsigned long it = cheetah_get_litlb_tag(slot);
+
+ if ((d & mask) != (tte & mask) || (t & mask) != (tte & mask) ||
+ dt != va || it != va) {
+ prom_printf("VII-BOOT: mapping readback mismatch; halted\n");
+ prom_halt();
+ }
+}
+
static void __init remap_kernel(void)
{
unsigned long phys_page, tte_vaddr, tte_data;
@@ -677,6 +730,9 @@ static void __init remap_kernel(void)
kern_locked_tte_data = tte_data;
+ if (tlb_type == sparc64_vii)
+ vii_check_slots();
+
/* Now lock us into the TLBs via Hypervisor or OBP. */
if (tlb_type == hypervisor) {
for (i = 0; i < num_kernel_image_mappings; i++) {
@@ -687,8 +743,22 @@ static void __init remap_kernel(void)
}
} else {
for (i = 0; i < num_kernel_image_mappings; i++) {
- prom_dtlb_load(tlb_ent - i, tte_data, tte_vaddr);
- prom_itlb_load(tlb_ent - i, tte_data, tte_vaddr);
+ long ret;
+
+ ret = prom_dtlb_load(tlb_ent - i, tte_data, tte_vaddr);
+ if (ret && tlb_type == sparc64_vii) {
+ prom_printf("SUNW,dtlb-load failed: idx=%d va=%lx tte=%lx rc=%lx\n",
+ tlb_ent - i, tte_vaddr, tte_data, ret);
+ prom_halt();
+ }
+ ret = prom_itlb_load(tlb_ent - i, tte_data, tte_vaddr);
+ if (ret && tlb_type == sparc64_vii) {
+ prom_printf("SUNW,itlb-load failed: idx=%d va=%lx tte=%lx rc=%lx\n",
+ tlb_ent - i, tte_vaddr, tte_data, ret);
+ prom_halt();
+ }
+ if (tlb_type == sparc64_vii)
+ vii_check_mapping(tlb_ent - i, tte_vaddr, tte_data);
tte_vaddr += 0x400000;
tte_data += 0x400000;
}
@@ -724,6 +794,11 @@ void __flush_dcache_range(unsigned long start, unsigned long end)
{
unsigned long va;
+ if (tlb_type == sparc64_vii) {
+ __asm__ __volatile__("membar #Sync" : : : "memory");
+ return;
+ }
+
if (tlb_type == spitfire) {
int n = 0;
@@ -2347,7 +2422,8 @@ void __init paging_init(void)
else
sun4u_pgprot_init();
- if (tlb_type == cheetah_plus ||
+ /* VII supports ASI_QUAD_LDD_PHYS (0x34); avoid shared-TLB TSB aliases. */
+ if (tlb_type == cheetah_plus || tlb_type == sparc64_vii ||
tlb_type == hypervisor) {
tsb_phys_patch();
ktsb_phys_patch();
@@ -2369,6 +2445,15 @@ void __init paging_init(void)
read_obp_memory("available", &pavail[0], &pavail_ents);
read_obp_memory("available", &pavail[0], &pavail_ents);
+ if (tlb_type == sparc64_vii) {
+ for (i = 0; i < pall_ents; i++) {
+ if (pall[i].phys_addr >= (1UL << 40) ||
+ pall[i].reg_size > (1UL << 40) - pall[i].phys_addr) {
+ prom_printf("VII-BOOT: RAM exceeds initial PA layout\n");
+ prom_halt();
+ }
+ }
+ }
phys_base = 0xffffffffffffffffUL;
for (i = 0; i < pavail_ents; i++) {
phys_base = min(phys_base, pavail[i].phys_addr);
@@ -2402,7 +2487,7 @@ void __init paging_init(void)
memset(swapper_pg_dir, 0, sizeof(swapper_pg_dir));
inherit_prom_mappings();
-
+
/* Ok, we can use our TLB miss and window trap handlers safely. */
setup_tba();
@@ -2813,9 +2898,14 @@ void __flush_tlb_all(void)
spitfire_put_itlb_data(i, 0x0UL);
}
}
- } else if (tlb_type == cheetah || tlb_type == cheetah_plus) {
+ } else if (tlb_type == cheetah || tlb_type == cheetah_plus ||
+ tlb_type == sparc64_vii) {
cheetah_flush_dtlb_all();
cheetah_flush_itlb_all();
+ /* JPS2 F.10.1 requires instruction visibility after demap-all. */
+ if (tlb_type == sparc64_vii)
+ __asm__ __volatile__("flush %0"
+ : : "r" (KERNBASE) : "memory");
}
__asm__ __volatile__("wrpr %0, 0, %%pstate"
: : "r" (pstate));
diff --git a/arch/sparc/mm/tsb.c b/arch/sparc/mm/tsb.c
index 5fe52a64c7e7..ba5dec3cb0f7 100644
--- a/arch/sparc/mm/tsb.c
+++ b/arch/sparc/mm/tsb.c
@@ -126,7 +126,8 @@ void flush_tsb_user(struct tlb_batch *tb)
if (tb->hugepage_shift < REAL_HPAGE_SHIFT) {
base = (unsigned long) mm->context.tsb_block[MM_TSB_BASE].tsb;
nentries = mm->context.tsb_block[MM_TSB_BASE].tsb_nentries;
- if (tlb_type == cheetah_plus || tlb_type == hypervisor)
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii)
base = __pa(base);
if (tb->hugepage_shift == PAGE_SHIFT)
__flush_tsb_one(tb, PAGE_SHIFT, base, nentries);
@@ -140,7 +141,8 @@ void flush_tsb_user(struct tlb_batch *tb)
else if (mm->context.tsb_block[MM_TSB_HUGE].tsb) {
base = (unsigned long) mm->context.tsb_block[MM_TSB_HUGE].tsb;
nentries = mm->context.tsb_block[MM_TSB_HUGE].tsb_nentries;
- if (tlb_type == cheetah_plus || tlb_type == hypervisor)
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii)
base = __pa(base);
__flush_huge_tsb_one(tb, REAL_HPAGE_SHIFT, base, nentries,
tb->hugepage_shift);
@@ -159,7 +161,8 @@ void flush_tsb_user_page(struct mm_struct *mm, unsigned long vaddr,
if (hugepage_shift < REAL_HPAGE_SHIFT) {
base = (unsigned long) mm->context.tsb_block[MM_TSB_BASE].tsb;
nentries = mm->context.tsb_block[MM_TSB_BASE].tsb_nentries;
- if (tlb_type == cheetah_plus || tlb_type == hypervisor)
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii)
base = __pa(base);
if (hugepage_shift == PAGE_SHIFT)
__flush_tsb_one_entry(base, vaddr, PAGE_SHIFT,
@@ -174,7 +177,8 @@ void flush_tsb_user_page(struct mm_struct *mm, unsigned long vaddr,
else if (mm->context.tsb_block[MM_TSB_HUGE].tsb) {
base = (unsigned long) mm->context.tsb_block[MM_TSB_HUGE].tsb;
nentries = mm->context.tsb_block[MM_TSB_HUGE].tsb_nentries;
- if (tlb_type == cheetah_plus || tlb_type == hypervisor)
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii)
base = __pa(base);
__flush_huge_tsb_one_entry(base, vaddr, REAL_HPAGE_SHIFT,
nentries, hugepage_shift);
@@ -270,7 +274,9 @@ static void setup_tsb_params(struct mm_struct *mm, unsigned long tsb_idx, unsign
}
tte |= pte_sz_bits(page_sz);
- if (tlb_type == cheetah_plus || tlb_type == hypervisor) {
+ /* VII siblings share TLBs: per-mm TSBs cannot reuse a fixed VA/slot. */
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii) {
/* Physical mapping, no locked TLB entry for TSB. */
tsb_reg |= tsb_paddr;
@@ -502,7 +508,8 @@ void tsb_grow(struct mm_struct *mm, unsigned long tsb_index, unsigned long rss)
unsigned long old_tsb_base = (unsigned long) old_tsb;
unsigned long new_tsb_base = (unsigned long) new_tsb;
- if (tlb_type == cheetah_plus || tlb_type == hypervisor) {
+ if (tlb_type == cheetah_plus || tlb_type == hypervisor ||
+ tlb_type == sparc64_vii) {
old_tsb_base = __pa(old_tsb_base);
new_tsb_base = __pa(new_tsb_base);
}
diff --git a/arch/sparc/mm/ultra.S b/arch/sparc/mm/ultra.S
index 70e658d107e0..c4a9647d6eb0 100644
--- a/arch/sparc/mm/ultra.S
+++ b/arch/sparc/mm/ultra.S
@@ -981,6 +981,242 @@ xcall_kgdb_capture:
#endif /* CONFIG_SMP */
+/*
+ * Synchronize VII MMU stores before noninternal memory access or the end
+ * of a control-transfer delay slot (JPS2 F.10.1, p. 488).
+ * Instruction visibility also requires FLUSH or trap return (F.10.11,
+ * pp. 500-502); MEMBAR alone is insufficient.
+ */
+/*
+ * Absolute jumps preserve patch-slot sizes and caller return addresses
+ * without branch relocation. Local entries may clobber %g1; the xcall
+ * stub uses %g4 to preserve its address/context arguments in %g1/%g5.
+ */
+ .type __vii_flush_tlb_page_patch, #function
+__vii_flush_tlb_page_patch:
+ sethi %hi(__vii_flush_tlb_page), %g1
+ jmpl %g1 + %lo(__vii_flush_tlb_page), %g0
+ nop
+ .size __vii_flush_tlb_page_patch, .-__vii_flush_tlb_page_patch
+ .if (. - __vii_flush_tlb_page_patch) - 12
+ .error "VII TLB jump template must contain three instructions"
+ .endif
+
+ .type __vii_flush_tlb_page, #function
+__vii_flush_tlb_page:
+ /* %o0 = context, %o1 = vaddr */
+ rdpr %pstate, %g7
+ andn %g7, PSTATE_IE, %g2
+ wrpr %g2, 0x0, %pstate
+ wrpr %g0, 1, %tl
+ mov PRIMARY_CONTEXT, %o4
+ ldxa [%o4] ASI_DMMU, %g2
+ srlx %g2, CTX_PGSZ1_NUC_SHIFT, %o3
+ sllx %o3, CTX_PGSZ1_NUC_SHIFT, %o3
+ or %o0, %o3, %o0 /* Preserve nucleus page size fields */
+ stxa %o0, [%o4] ASI_DMMU
+ membar #Sync
+ andcc %o1, 1, %g0
+ be,pn %icc, 1f
+ andn %o1, 1, %o3
+ stxa %g0, [%o3] ASI_IMMU_DEMAP
+1: stxa %g0, [%o3] ASI_DMMU_DEMAP
+ membar #Sync
+ stxa %g2, [%o4] ASI_DMMU
+ sethi %hi(KERNBASE), %o4
+ flush %o4
+ wrpr %g0, 0, %tl
+ retl
+ wrpr %g7, 0x0, %pstate
+ .size __vii_flush_tlb_page, .-__vii_flush_tlb_page
+
+ .type __vii_flush_tlb_pending_patch, #function
+__vii_flush_tlb_pending_patch:
+ sethi %hi(__vii_flush_tlb_pending), %g1
+ jmpl %g1 + %lo(__vii_flush_tlb_pending), %g0
+ nop
+ .size __vii_flush_tlb_pending_patch, .-__vii_flush_tlb_pending_patch
+ .if (. - __vii_flush_tlb_pending_patch) - 12
+ .error "VII TLB jump template must contain three instructions"
+ .endif
+
+ .type __vii_flush_tlb_pending, #function
+__vii_flush_tlb_pending:
+ /* %o0 = context, %o1 = nr, %o2 = vaddrs[] */
+ rdpr %pstate, %g7
+ sllx %o1, 3, %o1
+ andn %g7, PSTATE_IE, %g2
+ wrpr %g2, 0x0, %pstate
+ wrpr %g0, 1, %tl
+ mov PRIMARY_CONTEXT, %o4
+ ldxa [%o4] ASI_DMMU, %g2
+ srlx %g2, CTX_PGSZ1_NUC_SHIFT, %o3
+ sllx %o3, CTX_PGSZ1_NUC_SHIFT, %o3
+ or %o0, %o3, %o0 /* Preserve nucleus page size fields */
+ stxa %o0, [%o4] ASI_DMMU
+ membar #Sync
+1: sub %o1, (1 << 3), %o1
+ ldx [%o2 + %o1], %o3
+ andcc %o3, 1, %g0
+ be,pn %icc, 2f
+ andn %o3, 1, %o3
+ stxa %g0, [%o3] ASI_IMMU_DEMAP
+2: stxa %g0, [%o3] ASI_DMMU_DEMAP
+ membar #Sync
+ brnz,pt %o1, 1b
+ nop
+ stxa %g2, [%o4] ASI_DMMU
+ sethi %hi(KERNBASE), %o4
+ flush %o4
+ wrpr %g0, 0, %tl
+ retl
+ wrpr %g7, 0x0, %pstate
+ .size __vii_flush_tlb_pending, .-__vii_flush_tlb_pending
+
+ .type __vii_flush_tlb_kernel_range_patch, #function
+__vii_flush_tlb_kernel_range_patch:
+ sethi %hi(__vii_flush_tlb_kernel_range), %g1
+ jmpl %g1 + %lo(__vii_flush_tlb_kernel_range), %g0
+ nop
+ .size __vii_flush_tlb_kernel_range_patch, .-__vii_flush_tlb_kernel_range_patch
+ .if (. - __vii_flush_tlb_kernel_range_patch) - 12
+ .error "VII TLB jump template must contain three instructions"
+ .endif
+
+ .type __vii_flush_tlb_kernel_range, #function
+__vii_flush_tlb_kernel_range:
+ /* %o0=start, %o1=end */
+ cmp %o0, %o1
+ be,pn %xcc, 2f
+ sub %o1, %o0, %o3
+ srlx %o3, 18, %o4
+ brnz,pn %o4, 3f
+ sethi %hi(PAGE_SIZE), %o4
+ sub %o3, %o4, %o3
+ or %o0, 0x20, %o0 ! Nucleus
+1: stxa %g0, [%o0 + %o3] ASI_DMMU_DEMAP
+ stxa %g0, [%o0 + %o3] ASI_IMMU_DEMAP
+ membar #Sync
+ brnz,pt %o3, 1b
+ sub %o3, %o4, %o3
+2: sethi %hi(KERNBASE), %o3
+ flush %o3
+ retl
+ nop
+3: mov 0x80, %o4
+ stxa %g0, [%o4] ASI_DMMU_DEMAP
+ membar #Sync
+ stxa %g0, [%o4] ASI_IMMU_DEMAP
+ membar #Sync
+ sethi %hi(KERNBASE), %o3
+ flush %o3
+ retl
+ nop
+ .size __vii_flush_tlb_kernel_range, .-__vii_flush_tlb_kernel_range
+
+#ifdef CONFIG_SMP
+ .type __vii_xcall_flush_tlb_page_patch, #function
+__vii_xcall_flush_tlb_page_patch:
+ sethi %hi(__vii_xcall_flush_tlb_page), %g4
+ jmpl %g4 + %lo(__vii_xcall_flush_tlb_page), %g0
+ nop
+ .size __vii_xcall_flush_tlb_page_patch, .-__vii_xcall_flush_tlb_page_patch
+ .if (. - __vii_xcall_flush_tlb_page_patch) - 12
+ .error "VII TLB jump template must contain three instructions"
+ .endif
+
+ .type __vii_xcall_flush_tlb_page, #function
+__vii_xcall_flush_tlb_page:
+ /* %g5=context, %g1=vaddr */
+ mov PRIMARY_CONTEXT, %g4
+ ldxa [%g4] ASI_DMMU, %g2
+ srlx %g2, CTX_PGSZ1_NUC_SHIFT, %g4
+ sllx %g4, CTX_PGSZ1_NUC_SHIFT, %g4
+ or %g5, %g4, %g5
+ mov PRIMARY_CONTEXT, %g4
+ stxa %g5, [%g4] ASI_DMMU
+ membar #Sync
+ andcc %g1, 0x1, %g0
+ be,pn %icc, 2f
+ andn %g1, 0x1, %g5
+ stxa %g0, [%g5] ASI_IMMU_DEMAP
+2: stxa %g0, [%g5] ASI_DMMU_DEMAP
+ membar #Sync
+ stxa %g2, [%g4] ASI_DMMU
+ retry
+ .size __vii_xcall_flush_tlb_page, .-__vii_xcall_flush_tlb_page
+
+#endif /* CONFIG_SMP */
+
+ .globl sparc64_vii_patch_cachetlbops
+sparc64_vii_patch_cachetlbops:
+ save %sp, -128, %sp
+
+ sethi %hi(__flush_tlb_mm), %o0
+ or %o0, %lo(__flush_tlb_mm), %o0
+ sethi %hi(__cheetah_flush_tlb_mm), %o1
+ or %o1, %lo(__cheetah_flush_tlb_mm), %o1
+ call tlb_patch_one
+ mov 19, %o2
+
+ sethi %hi(__flush_tlb_page), %o0
+ or %o0, %lo(__flush_tlb_page), %o0
+ sethi %hi(__vii_flush_tlb_page_patch), %o1
+ or %o1, %lo(__vii_flush_tlb_page_patch), %o1
+ call tlb_patch_one
+ mov 3, %o2
+
+ sethi %hi(__flush_tlb_pending), %o0
+ or %o0, %lo(__flush_tlb_pending), %o0
+ sethi %hi(__vii_flush_tlb_pending_patch), %o1
+ or %o1, %lo(__vii_flush_tlb_pending_patch), %o1
+ call tlb_patch_one
+ mov 3, %o2
+
+ sethi %hi(__flush_tlb_kernel_range), %o0
+ or %o0, %lo(__flush_tlb_kernel_range), %o0
+ sethi %hi(__vii_flush_tlb_kernel_range_patch), %o1
+ or %o1, %lo(__vii_flush_tlb_kernel_range_patch), %o1
+ call tlb_patch_one
+ mov 3, %o2
+
+#ifdef CONFIG_SMP
+ sethi %hi(xcall_flush_tlb_page), %o0
+ or %o0, %lo(xcall_flush_tlb_page), %o0
+ sethi %hi(__vii_xcall_flush_tlb_page_patch), %o1
+ or %o1, %lo(__vii_xcall_flush_tlb_page_patch), %o1
+ call tlb_patch_one
+ mov 3, %o2
+
+ /* VII uses 32-entry fTLBs: do not use the Spitfire 64-slot sweep. */
+ sethi %hi(xcall_flush_tlb_kernel_range), %o0
+ or %o0, %lo(xcall_flush_tlb_kernel_range), %o0
+ sethi %hi(__cheetah_xcall_flush_tlb_kernel_range), %o1
+ or %o1, %lo(__cheetah_xcall_flush_tlb_kernel_range), %o1
+ call tlb_patch_one
+ mov 44, %o2
+#endif
+
+#ifdef DCACHE_ALIASING_POSSIBLE
+ sethi %hi(__flush_dcache_page), %o0
+ or %o0, %lo(__flush_dcache_page), %o0
+ sethi %hi(__vii_flush_dcache_page), %o1
+ or %o1, %lo(__vii_flush_dcache_page), %o1
+ call tlb_patch_one
+ mov 3, %o2
+#endif /* DCACHE_ALIASING_POSSIBLE */
+
+ ret
+ restore
+
+/* VII caches are strongly coherent (VII manual section 8.4.7). */
+#ifdef DCACHE_ALIASING_POSSIBLE
+__vii_flush_dcache_page:
+ membar #Sync
+ retl
+ nop
+#endif
+
.globl cheetah_patch_cachetlbops
cheetah_patch_cachetlbops:
save %sp, -128, %sp
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 5/7] sparc64: add M3000 Oberon PCIe support
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
` (3 preceding siblings ...)
2026-10-02 16:14 ` [PATCH 4/7] sparc64: add SPARC64 VII CPU, MMU and SMP support Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
2026-10-02 16:14 ` [PATCH 6/7] tg3: normalize inherited M3000 register byte order Magnus Lindholm
2026-10-02 16:14 ` [PATCH 7/7] hvc: add an M3000 firmware console backend Magnus Lindholm
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm
Recognize Oberon while preserving firmware link setup. Flush DVMA
translations and changed noncoherent IOTSB cache lines, and route legacy
interrupts using the bridge's ten-bit target ID.
Cache the bridge type and share target encoding. Leave MSI queues
uninitialized so the existing architecture path uses legacy interrupts
even with CONFIG_PCI_MSI=y; native bridge error handling is not provided.
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
arch/sparc/Kconfig | 10 +++++++
arch/sparc/include/asm/iommu_64.h | 1 +
arch/sparc/include/asm/irq_64.h | 1 +
arch/sparc/kernel/iommu.c | 44 +++++++++++++++++++++++++++
arch/sparc/kernel/irq_64.c | 50 ++++++++++++++++++++++++-------
arch/sparc/kernel/pci_fire.c | 31 +++++++++++++++++--
arch/sparc/kernel/pci_impl.h | 1 +
arch/sparc/kernel/prom_irqtrans.c | 7 +++++
8 files changed, 132 insertions(+), 13 deletions(-)
diff --git a/arch/sparc/Kconfig b/arch/sparc/Kconfig
index 1263150a5702..96aa140815fe 100644
--- a/arch/sparc/Kconfig
+++ b/arch/sparc/Kconfig
@@ -387,6 +387,16 @@ endif
endmenu
menu "Bus options (PCI etc.)"
+
+config SPARC64_OBERON
+ bool "Fujitsu M3000 Oberon PCIe bridge"
+ depends on SPARC64_VII && PCI
+ help
+ Support Oberon enumeration, translated DMA and legacy interrupts.
+ Firmware link configuration is preserved. MSI and native bridge
+ error interrupt handling are not supported on Oberon.
+ Enable this option for the M3000 on-board network and disk devices.
+
config SBUS
bool
default y
diff --git a/arch/sparc/include/asm/iommu_64.h b/arch/sparc/include/asm/iommu_64.h
index 0ef6dedf747e..abd7bb0fa615 100644
--- a/arch/sparc/include/asm/iommu_64.h
+++ b/arch/sparc/include/asm/iommu_64.h
@@ -62,6 +62,7 @@ struct iommu {
unsigned long iommu_tsbbase;
unsigned long iommu_flush;
unsigned long iommu_flushinv;
+ unsigned long iommu_cache_flush; /* Oberon IOTSB cache */
unsigned long iommu_tags;
unsigned long iommu_ctxflush;
unsigned long write_complete_reg;
diff --git a/arch/sparc/include/asm/irq_64.h b/arch/sparc/include/asm/irq_64.h
index 8c4c0c87f998..c3e88f2f8e80 100644
--- a/arch/sparc/include/asm/irq_64.h
+++ b/arch/sparc/include/asm/irq_64.h
@@ -45,6 +45,7 @@ void irq_install_pre_handler(int irq,
void *arg1, void *arg2);
#define irq_canonicalize(irq) (irq)
unsigned int build_irq(int inofixup, unsigned long iclr, unsigned long imap);
+unsigned int oberon_build_irq(int inofixup, unsigned long iclr, unsigned long imap);
unsigned int sun4v_build_irq(u32 devhandle, unsigned int devino);
unsigned int sun4v_build_virq(u32 devhandle, unsigned int devino);
unsigned int sun4v_build_msi(u32 devhandle, unsigned int *irq_p,
diff --git a/arch/sparc/kernel/iommu.c b/arch/sparc/kernel/iommu.c
index 7613ab0ffb89..9132f0535ce4 100644
--- a/arch/sparc/kernel/iommu.c
+++ b/arch/sparc/kernel/iommu.c
@@ -52,6 +52,8 @@ static void iommu_flushall(struct iommu_map_table *iommu_map_table)
struct iommu *iommu = container_of(iommu_map_table, struct iommu, tbl);
if (iommu->iommu_flushinv) {
iommu_write(iommu->iommu_flushinv, ~(u64)0);
+ if (iommu->iommu_cache_flush)
+ (void)iommu_read(iommu->write_complete_reg);
} else {
unsigned long tag;
int entry;
@@ -67,6 +69,30 @@ static void iommu_flushall(struct iommu_map_table *iommu_map_table)
}
}
+/*
+ * Oberon's noncoherent IOTSB needs each changed 64-byte cache line flushed
+ * along with its DVMA translations. Call only for device-inactive mappings.
+ */
+static void iommu_sync_mapping(struct iommu *iommu, iopte_t *base,
+ unsigned long npages)
+{
+ unsigned long slot, i;
+
+ if (!iommu->iommu_cache_flush || !npages)
+ return;
+ slot = base - iommu->page_table;
+ /* Publish IOPTE stores before invalidating the hardware caches. */
+ wmb();
+ for (i = 0; i < npages; i++, slot++) {
+ iommu_write(iommu->iommu_flush,
+ iommu->tbl.table_map_base + (slot << IO_PAGE_SHIFT));
+ if ((slot & 7) == 7 || i == npages - 1)
+ iommu_write(iommu->iommu_cache_flush,
+ __pa(iommu->page_table + slot));
+ }
+ (void)iommu_read(iommu->write_complete_reg);
+}
+
#define IOPTE_CONSISTENT(CTX) \
(IOPTE_VALID | IOPTE_CACHE | \
(((CTX) << 47) & IOPTE_CONTEXT))
@@ -240,6 +266,8 @@ static void *dma_4u_alloc_coherent(struct device *dev, size_t size,
first_page += IO_PAGE_SIZE;
}
+ iommu_sync_mapping(iommu, iopte - (size >> IO_PAGE_SHIFT),
+ size >> IO_PAGE_SHIFT);
return ret;
}
@@ -253,6 +281,15 @@ static void dma_4u_free_coherent(struct device *dev, size_t size,
npages = IO_PAGE_ALIGN(size) >> IO_PAGE_SHIFT;
iommu = dev->archdata.iommu;
+ if (iommu->iommu_cache_flush) {
+ iopte_t *base = iommu->page_table +
+ ((dvma - iommu->tbl.table_map_base) >> IO_PAGE_SHIFT);
+ unsigned long i;
+
+ for (i = 0; i < npages; i++)
+ iopte_make_dummy(iommu, base + i);
+ iommu_sync_mapping(iommu, base, npages);
+ }
iommu_tbl_range_free(&iommu->tbl, dvma, npages, IOMMU_ERROR_CODE);
order = get_order(size);
@@ -316,6 +353,7 @@ static dma_addr_t dma_4u_map_phys(struct device *dev, phys_addr_t phys,
for (i = 0; i < npages; i++, base++, phys += IO_PAGE_SIZE)
iopte_val(*base) = iopte_protection | phys;
+ iommu_sync_mapping(iommu, base - npages, npages);
return ret;
@@ -432,6 +470,7 @@ static void dma_4u_unmap_phys(struct device *dev, dma_addr_t bus_addr,
/* Step 2: Clear out TSB entries. */
for (i = 0; i < npages; i++)
iopte_make_dummy(iommu, base + i);
+ iommu_sync_mapping(iommu, base, npages);
iommu_free_ctx(iommu, ctx);
spin_unlock_irqrestore(&iommu->lock, flags);
@@ -523,6 +562,9 @@ static int dma_4u_map_sg(struct device *dev, struct scatterlist *sglist,
paddr += IO_PAGE_SIZE;
}
+ iommu_sync_mapping(iommu, iommu->page_table + entry,
+ base - (iommu->page_table + entry));
+
/* If we are in an open segment, try merging */
if (segstart != s) {
/* We cannot merge if:
@@ -577,6 +619,7 @@ static int dma_4u_map_sg(struct device *dev, struct scatterlist *sglist,
for (j = 0; j < npages; j++)
iopte_make_dummy(iommu, base + j);
+ iommu_sync_mapping(iommu, base, npages);
iommu_tbl_range_free(&iommu->tbl, vaddr, npages,
IOMMU_ERROR_CODE);
@@ -653,6 +696,7 @@ static void dma_4u_unmap_sg(struct device *dev, struct scatterlist *sglist,
for (i = 0; i < npages; i++)
iopte_make_dummy(iommu, base + i);
+ iommu_sync_mapping(iommu, base, npages);
iommu_tbl_range_free(&iommu->tbl, dma_handle, npages,
IOMMU_ERROR_CODE);
diff --git a/arch/sparc/kernel/irq_64.c b/arch/sparc/kernel/irq_64.c
index 3f55c69d5f3b..b0f3b26656d4 100644
--- a/arch/sparc/kernel/irq_64.c
+++ b/arch/sparc/kernel/irq_64.c
@@ -206,6 +206,7 @@ struct irq_handler_data {
struct ino_bucket bucket;
unsigned long iclr;
unsigned long imap;
+ bool oberon;
};
static inline unsigned int irq_data_to_handle(struct irq_data *data)
@@ -364,6 +365,16 @@ static int irq_choose_cpu(unsigned int irq, const struct cpumask *affinity)
real_hard_smp_processor_id()
#endif
+/* Oberon IMAP destination is a ten-bit interrupt target ID. */
+#define OBERON_IMAP_TID_SHIFT 21
+#define OBERON_IMAP_TID_MASK (0x3ffUL << OBERON_IMAP_TID_SHIFT)
+
+static unsigned long oberon_imap_target(unsigned long val, unsigned int cpuid)
+{
+ return (val & ~OBERON_IMAP_TID_MASK) |
+ ((cpuid << OBERON_IMAP_TID_SHIFT) & OBERON_IMAP_TID_MASK);
+}
+
static void sun4u_irq_enable(struct irq_data *data)
{
struct irq_handler_data *handler_data;
@@ -377,12 +388,16 @@ static void sun4u_irq_enable(struct irq_data *data)
irq_data_get_affinity_mask(data));
imap = handler_data->imap;
- tid = sun4u_compute_tid(imap, cpuid);
-
val = upa_readq(imap);
- val &= ~(IMAP_TID_UPA | IMAP_TID_JBUS |
- IMAP_AID_SAFARI | IMAP_NID_SAFARI);
- val |= tid | IMAP_VALID;
+ if (handler_data->oberon) {
+ val = oberon_imap_target(val, cpuid);
+ } else {
+ tid = sun4u_compute_tid(imap, cpuid);
+ val &= ~(IMAP_TID_UPA | IMAP_TID_JBUS |
+ IMAP_AID_SAFARI | IMAP_NID_SAFARI);
+ val |= tid;
+ }
+ val |= IMAP_VALID;
upa_writeq(val, imap);
upa_writeq(ICLR_IDLE, handler_data->iclr);
}
@@ -401,12 +416,16 @@ static int sun4u_set_affinity(struct irq_data *data,
cpuid = irq_choose_cpu(data->irq, mask);
imap = handler_data->imap;
- tid = sun4u_compute_tid(imap, cpuid);
-
val = upa_readq(imap);
- val &= ~(IMAP_TID_UPA | IMAP_TID_JBUS |
- IMAP_AID_SAFARI | IMAP_NID_SAFARI);
- val |= tid | IMAP_VALID;
+ if (handler_data->oberon) {
+ val = oberon_imap_target(val, cpuid);
+ } else {
+ tid = sun4u_compute_tid(imap, cpuid);
+ val &= ~(IMAP_TID_UPA | IMAP_TID_JBUS |
+ IMAP_AID_SAFARI | IMAP_NID_SAFARI);
+ val |= tid;
+ }
+ val |= IMAP_VALID;
upa_writeq(val, imap);
upa_writeq(ICLR_IDLE, handler_data->iclr);
}
@@ -642,6 +661,17 @@ unsigned int build_irq(int inofixup, unsigned long iclr, unsigned long imap)
return irq;
}
+unsigned int oberon_build_irq(int inofixup, unsigned long iclr,
+ unsigned long imap)
+{
+ unsigned int irq = build_irq(inofixup, iclr, imap);
+ struct irq_handler_data *data = irq_get_handler_data(irq);
+
+ if (data)
+ data->oberon = true;
+ return irq;
+}
+
static unsigned int sun4v_build_common(u32 devhandle, unsigned int devino,
void (*handler_data_init)(struct irq_handler_data *data,
u32 devhandle, unsigned int devino),
diff --git a/arch/sparc/kernel/pci_fire.c b/arch/sparc/kernel/pci_fire.c
index c35a8e3c1eae..1921996298af 100644
--- a/arch/sparc/kernel/pci_fire.c
+++ b/arch/sparc/kernel/pci_fire.c
@@ -46,11 +46,21 @@ static int pci_fire_pbm_iommu_init(struct pci_pbm_info *pbm)
iommu->iommu_tsbbase = pbm->pbm_regs + FIRE_IOMMU_TSBBASE;
iommu->iommu_flush = pbm->pbm_regs + FIRE_IOMMU_FLUSH;
iommu->iommu_flushinv = pbm->pbm_regs + FIRE_IOMMU_FLUSHINV;
+ if (pbm->is_oberon) {
+ /*
+ * 0x40100 flushes an IOTSB cache line by physical address;
+ * 0x40010 flushes a translated DVMA page.
+ */
+ iommu->iommu_flush = pbm->pbm_regs + 0x40010UL;
+ iommu->iommu_cache_flush = pbm->pbm_regs + 0x40100UL;
+ iommu->write_complete_reg = iommu->iommu_control;
+ }
/* We use the main control/status register of FIRE as the write
* completion register.
*/
- iommu->write_complete_reg = pbm->controller_regs + 0x410000UL;
+ if (!iommu->iommu_cache_flush)
+ iommu->write_complete_reg = pbm->controller_regs + 0x410000UL;
/*
* Invalidate TLB Entries.
@@ -62,6 +72,8 @@ static int pci_fire_pbm_iommu_init(struct pci_pbm_info *pbm)
if (err)
return err;
+ /* Make initialized IOPTEs visible before publishing the table base. */
+ wmb();
upa_writeq(__pa(iommu->page_table) | 0x7UL, iommu->iommu_tsbbase);
control = upa_readq(iommu->iommu_control);
@@ -70,6 +82,10 @@ static int pci_fire_pbm_iommu_init(struct pci_pbm_info *pbm)
0x00000002 /* Bypass enable */ |
0x00000001 /* Translation enable */);
upa_writeq(control, iommu->iommu_control);
+ if (iommu->iommu_cache_flush) {
+ upa_writeq(~(u64)0, iommu->iommu_flushinv);
+ (void)upa_readq(iommu->iommu_control);
+ }
return 0;
}
@@ -419,6 +435,7 @@ static int pci_fire_pbm_init(struct pci_pbm_info *pbm,
int err;
pbm->numa_node = NUMA_NO_NODE;
+ pbm->is_oberon = of_device_is_compatible(dp, "pciex108e,80f8");
pbm->pci_ops = &sun4u_pci_ops;
pbm->config_space_reg_bits = 12;
@@ -439,13 +456,18 @@ static int pci_fire_pbm_init(struct pci_pbm_info *pbm,
pci_get_pbm_props(pbm);
- pci_fire_hw_init(pbm);
+ if (pbm->is_oberon)
+ pr_info("%s: experimental Oberon; preserving firmware link setup\n",
+ pbm->name);
+ else
+ pci_fire_hw_init(pbm);
err = pci_fire_pbm_iommu_init(pbm);
if (err)
return err;
- pci_fire_msi_init(pbm);
+ if (!pbm->is_oberon)
+ pci_fire_msi_init(pbm);
pbm->pci_bus = pci_scan_one_pbm(pbm, &op->dev);
@@ -505,6 +527,9 @@ static const struct of_device_id fire_match[] = {
.name = "pci",
.compatible = "pciex108e,80f0",
},
+#ifdef CONFIG_SPARC64_OBERON
+ { .name = "pci", .compatible = "pciex108e,80f8" },
+#endif
{},
};
diff --git a/arch/sparc/kernel/pci_impl.h b/arch/sparc/kernel/pci_impl.h
index 83718876f1d4..92505fcc3cf3 100644
--- a/arch/sparc/kernel/pci_impl.h
+++ b/arch/sparc/kernel/pci_impl.h
@@ -117,6 +117,7 @@ struct pci_pbm_info {
/* State of 66MHz capabilities on this PBM. */
int is_66mhz_capable;
int all_devs_66mhz;
+ bool is_oberon;
#ifdef CONFIG_PCI_MSI
/* MSI info. */
diff --git a/arch/sparc/kernel/prom_irqtrans.c b/arch/sparc/kernel/prom_irqtrans.c
index 5752bfd73ac0..60fd6b0f47e1 100644
--- a/arch/sparc/kernel/prom_irqtrans.c
+++ b/arch/sparc/kernel/prom_irqtrans.c
@@ -481,6 +481,7 @@ static void __init pci_sun4v_irq_trans_init(struct device_node *dp)
struct fire_irq_data {
unsigned long pbm_regs;
u32 portid;
+ bool oberon;
};
#define FIRE_IMAP_BASE 0x001000
@@ -537,6 +538,8 @@ static unsigned int fire_irq_build(struct device_node *dp,
*/
ino |= (irq_data->portid << 6);
ino -= int_ctrlr;
+ if (irq_data->oberon)
+ return oberon_build_irq(ino, iclr, imap);
return build_irq(ino, iclr, imap);
}
@@ -553,6 +556,7 @@ static void __init fire_irq_trans_init(struct device_node *dp)
regs = of_get_property(dp, "reg", NULL);
dp->irq_trans->data = irq_data;
+ irq_data->oberon = of_device_is_compatible(dp, "pciex108e,80f8");
irq_data->pbm_regs = regs[0].phys_addr;
irq_data->portid = of_getintprop_default(dp, "portid", 0);
}
@@ -778,6 +782,9 @@ static struct irq_trans __initdata pci_irq_trans_table[] = {
{ "pci108e,a801", tomatillo_irq_trans_init },
{ "SUNW,sun4v-pci", pci_sun4v_irq_trans_init },
{ "pciex108e,80f0", fire_irq_trans_init },
+#ifdef CONFIG_SPARC64_OBERON
+ { "pciex108e,80f8", fire_irq_trans_init },
+#endif
};
#endif
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 6/7] tg3: normalize inherited M3000 register byte order
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
` (4 preceding siblings ...)
2026-10-02 16:14 ` [PATCH 5/7] sparc64: add M3000 Oberon PCIe support Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
2026-10-02 16:14 ` [PATCH 7/7] hvc: add an M3000 firmware console backend Magnus Lindholm
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, Pavan Chebbi, Michael Chan,
Andrew Lunn, Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev
M3000 firmware can leave BCM5718 vendor registers byte-swapped while
standard PCI fields retain normal byte order. Match the Fujitsu 10cf:165a
subsystem, IKKAKU model and swapped revision/product signature before
restoring host control; reject failed PCI accesses or register readbacks.
Keep this in probe so failures can abort initialization; SPARC firmware
enumeration skips PCI_FIXUP_EARLY. Normal rebinds and other platforms
retain their existing path.
Use tg3.h's MISC_HOST_CTRL_BYTE_SWAP and TG3PCI_GEN2_PRODID_ASICREV;
the inherited state was observed on M3000 hardware.
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
drivers/net/ethernet/broadcom/tg3.c | 91 ++++++++++++++++++++++++++++-
1 file changed, 89 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/tg3.c b/drivers/net/ethernet/broadcom/tg3.c
index 73a4b569b03e..9335bcc0d8d3 100644
--- a/drivers/net/ethernet/broadcom/tg3.c
+++ b/drivers/net/ethernet/broadcom/tg3.c
@@ -56,6 +56,7 @@
#include <linux/hwmon-sysfs.h>
#include <linux/crc32.h>
#include <linux/dmi.h>
+#include <linux/of.h>
#include <net/checksum.h>
#include <net/gso.h>
@@ -16248,6 +16249,83 @@ static bool tg3_10_100_only_device(struct tg3 *tp,
return false;
}
+/* M3000 firmware can leave the on-board BCM5718 registers byte-swapped. */
+static bool tg3_is_m3000(struct pci_dev *pdev)
+{
+ struct device_node *root;
+ const char *model;
+ bool match;
+
+ if (pdev->vendor != PCI_VENDOR_ID_BROADCOM ||
+ pdev->device != TG3PCI_DEVICE_TIGON3_5718 ||
+ pdev->subsystem_vendor != 0x10cf ||
+ pdev->subsystem_device != 0x165a)
+ return false;
+
+ root = of_find_node_by_path("/");
+ match = !of_property_read_string(root, "model", &model) &&
+ !strcmp(model, "IKKAKU");
+ of_node_put(root);
+ return match;
+}
+
+static int tg3_m3000_fw_byteorder(struct tg3 *tp, u32 *misc_ctrl_reg)
+{
+ struct pci_dev *pdev = tp->pdev;
+ u32 prodid, expected_prodid, normalized, readback;
+ int reg, err;
+
+ if (!tg3_is_m3000(pdev) ||
+ (swab32(*misc_ctrl_reg) >> 28) != ASIC_REV_USE_PROD_ID_REG ||
+ !(swab32(*misc_ctrl_reg) & MISC_HOST_CTRL_BYTE_SWAP))
+ return 0;
+
+ /* Standard PCI fields are normal; verify the swapped vendor registers. */
+ reg = TG3PCI_GEN2_PRODID_ASICREV;
+ err = pci_read_config_dword(pdev, reg, &prodid);
+ if (err)
+ goto config_error;
+ expected_prodid = swab32(prodid);
+ if ((expected_prodid >> 12) != ASIC_REV_5717) {
+ dev_err(&pdev->dev, "M3000: unexpected swapped product ID %08x\n",
+ prodid);
+ return -ENODEV;
+ }
+
+ normalized = (swab32(*misc_ctrl_reg) & MISC_HOST_CTRL_CHIPREV) |
+ tp->misc_host_ctrl;
+ reg = TG3PCI_MISC_HOST_CTRL;
+ err = pci_write_config_dword(pdev, reg, swab32(normalized));
+ if (err)
+ goto config_error;
+ err = pci_read_config_dword(pdev, reg, &readback);
+ if (err)
+ goto config_error;
+ if (readback != normalized) {
+ dev_err(&pdev->dev, "M3000: host-control readback mismatch %08x\n",
+ readback);
+ return -EIO;
+ }
+
+ reg = TG3PCI_GEN2_PRODID_ASICREV;
+ err = pci_read_config_dword(pdev, reg, &prodid);
+ if (err)
+ goto config_error;
+ if (prodid != expected_prodid) {
+ dev_err(&pdev->dev, "M3000: product-ID readback mismatch %08x\n",
+ prodid);
+ return -EIO;
+ }
+ *misc_ctrl_reg = readback;
+ dev_info(&pdev->dev, "M3000: normalized firmware register byte order\n");
+ return 0;
+
+config_error:
+ dev_err(&pdev->dev, "M3000: PCI config access at %#x failed (%d)\n",
+ reg, err);
+ return pcibios_err_to_errno(err);
+}
+
static int tg3_get_invariants(struct tg3 *tp, const struct pci_device_id *ent)
{
u32 misc_ctrl_reg;
@@ -16272,8 +16350,17 @@ static int tg3_get_invariants(struct tg3 *tp, const struct pci_device_id *ent)
* sure that indirect register accesses are enabled before
* the first operation.
*/
- pci_read_config_dword(tp->pdev, TG3PCI_MISC_HOST_CTRL,
- &misc_ctrl_reg);
+ err = pci_read_config_dword(tp->pdev, TG3PCI_MISC_HOST_CTRL,
+ &misc_ctrl_reg);
+ if (err && tg3_is_m3000(tp->pdev)) {
+ dev_err(&tp->pdev->dev, "PCI host-control read failed (%d)\n",
+ err);
+ return pcibios_err_to_errno(err);
+ }
+ err = tg3_m3000_fw_byteorder(tp, &misc_ctrl_reg);
+ if (err)
+ return err;
+
tp->misc_host_ctrl |= (misc_ctrl_reg &
MISC_HOST_CTRL_CHIPREV);
pci_write_config_dword(tp->pdev, TG3PCI_MISC_HOST_CTRL,
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 7/7] hvc: add an M3000 firmware console backend
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
` (5 preceding siblings ...)
2026-10-02 16:14 ` [PATCH 6/7] tg3: normalize inherited M3000 register byte order Magnus Lindholm
@ 2026-10-02 16:14 ` Magnus Lindholm
6 siblings, 0 replies; 8+ messages in thread
From: Magnus Lindholm @ 2026-10-02 16:14 UTC (permalink / raw)
To: sparclinux, David S . Miller, Andreas Larsson
Cc: linux-kernel, Magnus Lindholm, Greg Kroah-Hartman, Jiri Slaby,
linuxppc-dev, linux-serial
Provide hvc0 through the IKKAKU Open Firmware pseudo-console, validating
model and console properties before matching. Serialize firmware calls,
keep the bounce buffer in locked mappings and poll input each open tick.
Keep output buffers const and bound no-progress retries because HVC
retries EAGAIN indefinitely. A stalled firmware call remains unbounded.
Use the existing SPARC p1275 interface and HVC output contract.
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
MAINTAINERS | 6 ++
drivers/tty/hvc/Kconfig | 10 +++
drivers/tty/hvc/Makefile | 2 +
drivers/tty/hvc/hvc_m3000.c | 167 ++++++++++++++++++++++++++++++++++++
4 files changed, 185 insertions(+)
create mode 100644 drivers/tty/hvc/hvc_m3000.c
diff --git a/MAINTAINERS b/MAINTAINERS
index 3a19da74d00c..5bc9b1cabd0a 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -10728,6 +10728,12 @@ L: platform-driver-x86@vger.kernel.org
S: Maintained
F: drivers/platform/x86/fujitsu-laptop.c
+FUJITSU M3000 FIRMWARE CONSOLE
+M: Magnus Lindholm <linmag7@gmail.com>
+L: linux-serial@vger.kernel.org
+S: Maintained
+F: drivers/tty/hvc/hvc_m3000.c
+
FUJITSU TABLET EXTRAS
M: Robert Gerlach <khnz@gmx.de>
L: platform-driver-x86@vger.kernel.org
diff --git a/drivers/tty/hvc/Kconfig b/drivers/tty/hvc/Kconfig
index 5866195de26a..0feb7ec98f4f 100644
--- a/drivers/tty/hvc/Kconfig
+++ b/drivers/tty/hvc/Kconfig
@@ -134,3 +134,13 @@ config HVCS
will depend on arch specific APIs exported from hvcserver.ko
which will also be compiled when this driver is built as a
module.
+
+config HVC_M3000
+ bool "M3000 firmware pseudo-console"
+ depends on SPARC64_VII
+ select HVC_DRIVER
+ help
+ Provide hvc0 using Open Firmware stdin/stdout on IKKAKU only.
+ Input is polled; no native UART registers are accessed.
+ Firmware calls are serialized and use a locked-image bounce buffer.
+ Say Y to use the M3000 firmware pseudo-console as hvc0.
diff --git a/drivers/tty/hvc/Makefile b/drivers/tty/hvc/Makefile
index 98880e357941..5b0277deb7c9 100644
--- a/drivers/tty/hvc/Makefile
+++ b/drivers/tty/hvc/Makefile
@@ -11,3 +11,5 @@ obj-$(CONFIG_HVC_IUCV) += hvc_iucv.o
obj-$(CONFIG_HVC_UDBG) += hvc_udbg.o
obj-$(CONFIG_HVC_RISCV_SBI) += hvc_riscv_sbi.o
obj-$(CONFIG_HVCS) += hvcs.o
+
+obj-$(CONFIG_HVC_M3000) += hvc_m3000.o
diff --git a/drivers/tty/hvc/hvc_m3000.c b/drivers/tty/hvc/hvc_m3000.c
new file mode 100644
index 000000000000..0ef4c888a6a2
--- /dev/null
+++ b/drivers/tty/hvc/hvc_m3000.c
@@ -0,0 +1,167 @@
+// SPDX-License-Identifier: GPL-2.0
+/* Experimental M3000 Open Firmware pseudo-console backend. */
+#include <linux/console.h>
+#include <linux/err.h>
+#include <linux/init.h>
+#include <linux/irqflags.h>
+#include <linux/string.h>
+#include <linux/spinlock.h>
+#include <linux/timer.h>
+#include <asm/oplib.h>
+#include <asm/spitfire.h>
+#include "hvc_console.h"
+
+#define M3000_WRITE_ATTEMPTS 8
+
+static int m3000_stdin;
+static bool m3000_ready;
+/* Keep firmware buffers within the locked kernel image mappings. */
+static u8 m3000_buffer[256];
+static DEFINE_RAW_SPINLOCK(m3000_buffer_lock);
+static struct timer_list m3000_poll_timer;
+static bool m3000_poll_active;
+
+/*
+ * HVC's idle backoff can exceed the firmware input FIFO's capacity.
+ * Wake its worker each tick while open; keep PROM calls out of the timer.
+ */
+static void m3000_poll_tick(struct timer_list *timer)
+{
+ if (!READ_ONCE(m3000_poll_active))
+ return;
+ hvc_kick();
+ mod_timer(&m3000_poll_timer, jiffies + 1);
+}
+
+static int m3000_open(struct hvc_struct *hp, int data)
+{
+ WRITE_ONCE(m3000_poll_active, true);
+ mod_timer(&m3000_poll_timer, jiffies + 1);
+ return 0;
+}
+
+static void m3000_close(struct hvc_struct *hp, int data)
+{
+ WRITE_ONCE(m3000_poll_active, false);
+ timer_delete_sync(&m3000_poll_timer);
+}
+
+static ssize_t m3000_io(u8 *in, const u8 *out, size_t count)
+{
+ unsigned long args[7], flags;
+ bool input = in != NULL;
+ int ret;
+
+ if (!count)
+ return 0;
+ count = min_t(size_t, count, input ? 1 : sizeof(m3000_buffer));
+ /* Serialize the bounce buffer; p1275 separately serializes firmware. */
+ raw_spin_lock_irqsave(&m3000_buffer_lock, flags);
+ if (!input)
+ memcpy(m3000_buffer, out, count);
+ args[0] = (unsigned long)(input ? "read" : "write");
+ args[1] = 3;
+ args[2] = 1;
+ args[3] = (unsigned int)(input ? m3000_stdin : prom_stdout);
+ args[4] = (unsigned long)m3000_buffer;
+ args[5] = count;
+ args[6] = (unsigned long)-1;
+ p1275_cmd_direct(args);
+ ret = (int)args[6];
+ if (ret > 0 && ret <= count && input)
+ memcpy(in, m3000_buffer, ret);
+ raw_spin_unlock_irqrestore(&m3000_buffer_lock, flags);
+ if (ret == -2 || ret == 0)
+ return input ? 0 : -EAGAIN;
+ if (ret < 0 || ret > count)
+ return -EIO;
+ return ret;
+}
+
+static ssize_t m3000_get(u32 termno, u8 *buf, size_t count)
+{
+ return m3000_io(buf, NULL, count);
+}
+
+static ssize_t m3000_put(u32 termno, const u8 *buf, size_t count)
+{
+ ssize_t ret;
+ int attempt;
+
+ /*
+ * HVC retries -EAGAIN forever, so drop this chunk without logging when
+ * the no-progress budget expires. This cannot bound a stalled firmware
+ * call or lock acquisition.
+ */
+ for (attempt = 0; attempt < M3000_WRITE_ATTEMPTS; attempt++) {
+ ret = m3000_io(NULL, buf, count);
+ if (ret != -EAGAIN)
+ return ret;
+ cpu_relax();
+ }
+ return -EIO;
+}
+
+static const struct hv_ops m3000_ops = {
+ .get_chars = m3000_get,
+ .put_chars = m3000_put,
+ .notifier_add = m3000_open,
+ .notifier_del = m3000_close,
+ .notifier_hangup = m3000_close,
+};
+
+static bool __init m3000_property_matches(phandle node, const char *prop,
+ const char *expected)
+{
+ char value[64];
+ int len;
+
+ len = prom_getproperty(node, prop, value, sizeof(value) - 1);
+ if (len <= 0)
+ return false;
+ value[len] = '\0';
+ return !strcmp(value, expected);
+}
+
+static int __init m3000_console_init(void)
+{
+ phandle node;
+ int ret;
+
+ if (tlb_type != sparc64_vii)
+ return -ENODEV;
+ if (!m3000_property_matches(prom_finddevice("/"), "model", "IKKAKU"))
+ return -ENODEV;
+ m3000_stdin = prom_getint(prom_chosen_node, "stdin");
+ if (!m3000_stdin || m3000_stdin == -1 || !prom_stdout || prom_stdout == -1)
+ return -ENODEV;
+ node = prom_inst2pkg(prom_stdout);
+ if (!m3000_property_matches(node, "name", "pseudo-console"))
+ return -ENODEV;
+ node = prom_inst2pkg(m3000_stdin);
+ if (!m3000_property_matches(node, "name", "pseudo-console"))
+ return -ENODEV;
+ ret = hvc_instantiate(0, 0, &m3000_ops);
+ if (ret < 0)
+ return ret;
+ m3000_ready = true;
+ return 0;
+}
+console_initcall(m3000_console_init);
+
+static int __init m3000_tty_init(void)
+{
+ struct hvc_struct *hp;
+
+ if (!m3000_ready)
+ return -ENODEV;
+ timer_setup(&m3000_poll_timer, m3000_poll_tick, 0);
+ hp = hvc_alloc(0, 0, &m3000_ops, sizeof(m3000_buffer));
+ if (IS_ERR(hp))
+ return PTR_ERR(hp);
+ hp->ws.ws_row = 24;
+ hp->ws.ws_col = 80;
+ pr_info("M3000: firmware-backed hvc0 tty ready (serialized, polled input)\n");
+ return 0;
+}
+device_initcall(m3000_tty_init);
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-10-02 16:17 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 16:14 [PATCH 0/7] sparc64: add Fujitsu M3000 support Magnus Lindholm
2026-10-02 16:14 ` [PATCH 1/7] sparc64: return from the generic clear_page implementation Magnus Lindholm
2026-10-02 16:14 ` [PATCH 2/7] sparc64: honor queued spinlock layout in secondary startup Magnus Lindholm
2026-10-02 16:14 ` [PATCH 3/7] sparc64: avoid huge kernel PUD mappings on sun4u Magnus Lindholm
2026-10-02 16:14 ` [PATCH 4/7] sparc64: add SPARC64 VII CPU, MMU and SMP support Magnus Lindholm
2026-10-02 16:14 ` [PATCH 5/7] sparc64: add M3000 Oberon PCIe support Magnus Lindholm
2026-10-02 16:14 ` [PATCH 6/7] tg3: normalize inherited M3000 register byte order Magnus Lindholm
2026-10-02 16:14 ` [PATCH 7/7] hvc: add an M3000 firmware console backend Magnus Lindholm
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®