[RFC PATCH 0/5] Add Smsdid and Smmpt supervisor domain protection
Rahul Pathak <[email protected]> Wed, 22 Jul 2026 09:04:49 +0530
| Newsgroups | org.infradead.lists.opensbi |
|---|---|
| Message-ID | <[email protected]> |
This series adds OpenSBI support for the RISC-V SMMPT specification sub-extensions - Smsdid (supervisor domain ID) and Smmpt (supervisor domain memory protection). Together these let M-mode firmware confine each supervisor domain to a physical address space that is enforced in hardware, via a per domain memory protection table (MPT) selected by the mmpt CSR. Every supervisor domain gets its own MPT built from the memory regions of its SBI domain. Per-region XWR permissions are derived from the region's S/U access flags from SBI domain, so a region that does not have S/U access is mapped as an deny instead of skipped. The Root domain maps all physical memory, with the firmware region explicitly denied to S-mode. Regions may be shared between domains, each side keeping its own permissions. Testing: Booted Linux when Smmpt was active. The boot dump shows the expected perregion permissions. Also checked with a small self-test in Qemu which confirms the firmware region denied and the kernel region permitted from S-mode. The Qemu RISC-V Virt machine was used to test this. The new cli args requried to be passed to Qemu are - ./qemu-system-riscv64 -nographic -M virt -cpu rv64,x-smsdid=true,x-smmpt=true Please note that extra some logs in OpenSBI and Qemu are added for testing which will be removed later. The Qemu log for smmpt_check_access is currently commented in the qemu branch to let linux boot logs print. But its present there for anyone to enable and check. Boot Logs: sbi_mpt: mode=Smmpt52 SDIDLEN=6 max_domains=64 root_size=0x1000 root_align=0x1000 fw 0x0000000080000000+0x19e000 pool=global heap SDID 0 root=0x0000000080098000 regions=9 dom=root S-Domain0 Region01 : 0x0000000080000000+0x80000 : xwr=0 (---) S-Domain0 Region02 : 0x0000000080000000+0x200000 : xwr=0 (---) S-Domain0 Region03 : 0x0000000000100000+0x1000 : xwr=3 (RW-) S-Domain0 Region04 : 0x0000000010000000+0x1000 : xwr=3 (RW-) S-Domain0 Region05 : 0x0000000002000000+0x10000 : xwr=0 (---) S-Domain0 Region06 : 0x000000000c400000+0x200000 : xwr=3 (RW-) S-Domain0 Region07 : 0x000000000c000000+0x400000 : xwr=3 (RW-) S-Domain0 Region08 : 0x0000000080000000+0x19e000 : xwr=0 (---) [LOCKED] S-Domain0 Default : Rest of the address space : xwr=7 (RWX) [baseline, overlay by regions above] Boot HART ID : 0 Boot HART Domain : root Boot HART Priv Version : v1.12 Boot HART Base ISA : rv64imafdch Boot HART ISA Extensions : sstc,zicntr,zihpm,zicboz,zicbom,sdtrig,svadu,f,d,smsdid,smmpt Boot HART PMP Count : 16 Boot HART PMP Granularity : 2 bits Boot HART PMP Address Bits : 54 Boot HART MHPM Info : 16 (0x0007fff8) Boot HART Debug Triggers : 2 triggers Boot HART MIDELEG : 0x0000000000001666 Boot HART MEDELEG : 0x0000000000f4b509 QEMU: smmpt_check_access: addr=0x80010000 mode=2 sdid=0 mptppn=0x80098 xwr=0 accesstype=0 -> DENY QEMU: smmpt_check_access: addr=0x80200000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=2 -> PERMIT QEMU: SELFTEST fw(0x80010000)=DENY(ok) kernel(0x80200000)=PERMIT(ok) QEMU: smmpt_check_access: addr=0x80200000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=2 -> PERMIT QEMU: smmpt_check_access: addr=0x802010d8 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=2 -> PERMIT QEMU: smmpt_check_access: addr=0x81c25000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=1 -> PERMIT QEMU: smmpt_check_access: addr=0x81c26000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=1 -> PERMIT QEMU: smmpt_check_access: addr=0x81c27000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=1 -> PERMIT QEMU: smmpt_check_access: addr=0x81c28000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=1 -> PERMIT QEMU: smmpt_check_access: addr=0x81c29000 mode=2 sdid=0 mptppn=0x80098 xwr=7 accesstype=1 -> PERMIT The corresponding Qemu Smmpt support was also added which is present here - https://github.com/pathakraul/qemu/tree/rpathak_smmpt_v1 These OpenSBI changes are also present in github - https://github.com/pathakraul/opensbi/tree/rpathak_smmpt_v1 Further Development: This series add base infrastructure for Smsdid and Smmpt. Development and testing with more then one Supervisor Domain. Extensive testing with all the modes and other platform configurations. Rahul Pathak (5): riscv: Add Smsdid and Smmpt hart extensions mpt: Add Smsdid and Smmpt supervisor domain core platform/generic: Initialise MPT at boot sbi: hsm: Activate MPT for domain on hart start/resume sbi: init: Print supervisor domains at boot include/sbi/sbi_hart.h | 5 +- include/sbi/sbi_mpt.h | 321 +++++++++++++ lib/sbi/objects.mk | 2 + lib/sbi/sbi_hart.c | 2 + lib/sbi/sbi_hsm.c | 7 + lib/sbi/sbi_init.c | 4 + lib/sbi/sbi_mpt.c | 882 +++++++++++++++++++++++++++++++++++ lib/sbi/sbi_mpt_mode.c | 891 ++++++++++++++++++++++++++++++++++++ platform/generic/platform.c | 101 ++++ 9 files changed, 2214 insertions(+), 1 deletion(-) create mode 100644 include/sbi/sbi_mpt.h create mode 100644 lib/sbi/sbi_mpt.c create mode 100644 lib/sbi/sbi_mpt_mode.c -- 2.51.0 -- opensbi mailing list [email protected] http://lists.infradead.org/mailman/listinfo/opensbi