2 * Copyright (c) 2017 Apple Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
31 * Microcode updater interface sysctl
34 #include <kern/locks.h>
35 #include <i386/ucode.h>
36 #include <sys/errno.h>
37 #include <i386/proc_reg.h>
38 #include <i386/cpuid.h>
39 #include <vm/vm_kern.h>
40 #include <i386/mp.h> // mp_broadcast
42 #include <machine/cpu_number.h> // cpu_number
43 #include <pexpert/pexpert.h> // boot-args
45 #define IA32_BIOS_UPDT_TRIG (0x79) /* microcode update trigger MSR */
47 struct intel_ucupdate
*global_update
= NULL
;
49 /* Exceute the actual update! */
51 update_microcode(void)
53 /* SDM Example 9-8 code shows that we load the
54 * address of the UpdateData within the microcode blob,
55 * not the address of the header.
57 wrmsr64(IA32_BIOS_UPDT_TRIG
, (uint64_t)(uintptr_t)&global_update
->data
);
61 static lck_grp_attr_t
*ucode_slock_grp_attr
= NULL
;
62 static lck_grp_t
*ucode_slock_grp
= NULL
;
63 static lck_attr_t
*ucode_slock_attr
= NULL
;
64 static lck_spin_t
*ucode_slock
= NULL
;
69 /* already allocated? */
70 if (ucode_slock_grp_attr
&& ucode_slock_grp
&& ucode_slock_attr
&& ucode_slock
)
73 /* allocate lock group attribute and group */
74 if (!(ucode_slock_grp_attr
= lck_grp_attr_alloc_init()))
77 lck_grp_attr_setstat(ucode_slock_grp_attr
);
79 if (!(ucode_slock_grp
= lck_grp_alloc_init("uccode_lock", ucode_slock_grp_attr
)))
82 /* Allocate lock attribute */
83 if (!(ucode_slock_attr
= lck_attr_alloc_init()))
86 /* Allocate the spin lock */
87 /* We keep one global spin-lock. We could have one per update
88 * request... but srsly, why would you update microcode like that?
90 if (!(ucode_slock
= lck_spin_alloc_init(ucode_slock_grp
, ucode_slock_attr
)))
98 lck_spin_free(ucode_slock
, ucode_slock_grp
);
100 lck_attr_free(ucode_slock_attr
);
102 lck_grp_free(ucode_slock_grp
);
103 if (ucode_slock_grp_attr
)
104 lck_grp_attr_free(ucode_slock_grp_attr
);
106 return KERN_NO_SPACE
;
109 /* Copy in an update */
111 copyin_update(uint64_t inaddr
)
113 struct intel_ucupdate update_header
;
114 struct intel_ucupdate
*update
;
119 /* Copy in enough header to peek at the size */
120 error
= copyin((user_addr_t
)inaddr
, (void *)&update_header
, sizeof(update_header
));
124 /* Get the actual, alleged size */
125 size
= update_header
.total_size
;
127 /* huge bogus piece of data that somehow made it through? */
128 if (size
>= 1024 * 1024)
131 /* Old microcodes? */
133 size
= 2048; /* default update size; see SDM */
136 * create the buffer for the update
137 * It need only be aligned to 16-bytes, according to the SDM.
138 * This also wires it down
140 ret
= kmem_alloc_kobject(kernel_map
, (vm_offset_t
*)&update
, size
, VM_KERN_MEMORY_OSFMK
);
141 if (ret
!= KERN_SUCCESS
)
145 error
= copyin((user_addr_t
)inaddr
, (void*)update
, size
);
147 kmem_free(kernel_map
, (vm_offset_t
)update
, size
);
151 global_update
= update
;
156 * This is called once by every CPU on a wake from sleep/hibernate
157 * and is meant to re-apply a microcode update that got lost
164 kprintf("ucode: Re-applying update after wake (CPU #%d)\n", cpu_number());
168 kprintf("ucode: No update to apply (CPU #%d)\n", cpu_number());
174 cpu_update(__unused
void *arg
)
177 lck_spin_lock(ucode_slock
);
179 /* execute the update */
182 /* release the lock */
183 lck_spin_unlock(ucode_slock
);
187 ucode_cpuid_set_info(void)
189 uint64_t saved_xcr0
, dest_xcr0
;
190 int need_xcr0_restore
= 0;
191 boolean_t intrs_enabled
= ml_set_interrupts_enabled(FALSE
);
194 * Before we cache the CPUID information, we must configure XCR0 with the maximal set of
195 * features to ensure the save area returned in the xsave leaf is correctly-sized.
197 * Since we are guaranteed that init_fpu() has already happened, we can use state
198 * variables set there that were already predicated on the presence of explicit
199 * boot-args enables/disables.
202 if (fpu_capability
== AVX512
|| fpu_capability
== AVX
) {
203 saved_xcr0
= xgetbv(XCR0
);
204 dest_xcr0
= (fpu_capability
== AVX512
) ? AVX512_XMASK
: AVX_XMASK
;
205 assert((get_cr4() & CR4_OSXSAVE
) != 0);
206 if (saved_xcr0
!= dest_xcr0
) {
207 need_xcr0_restore
= 1;
208 xsetbv(dest_xcr0
>> 32, dest_xcr0
& 0xFFFFFFFFUL
);
214 if (need_xcr0_restore
) {
215 xsetbv(saved_xcr0
>> 32, saved_xcr0
& 0xFFFFFFFFUL
);
218 ml_set_interrupts_enabled(intrs_enabled
);
221 /* Farm an update out to all CPUs */
225 if (register_locks() != KERN_SUCCESS
)
228 /* Get all CPUs to perform the update */
229 mp_broadcast(cpu_update
, NULL
);
231 /* Update the cpuid info */
232 ucode_cpuid_set_info();
240 ucode_interface(uint64_t addr
)
245 if (PE_parse_boot_argn("-x", arg
, sizeof (arg
))) {
246 printf("ucode: no updates in safe mode\n");
252 * Userland may only call this once per boot. Anything else
253 * would not make sense (all updates are cumulative), and also
254 * leak memory, because we don't free previous updates.
260 /* Get the whole microcode */
261 error
= copyin_update(addr
);
266 /* Farm out the updates */