Reliability, Availability, and Serviceability (RAS) on AArch64. Fu Wei (Linaro LEG) Supreeth Venkatesh (ARM)

Size: px
Start display at page:

Download "Reliability, Availability, and Serviceability (RAS) on AArch64. Fu Wei (Linaro LEG) Supreeth Venkatesh (ARM)"

Transcription

1 Reliability, Availability, and Serviceability (RAS) on AArch64 Fu Wei (Linaro LEG) Supreeth Venkatesh (ARM)

2 AGENDA 1. Brief introduction of RAS 2. RAS on AArch64 3. Definition, Importance, History Overview Hardware support RAS Extension Software Architecture ARM-Trusted-Firmware, UEFI, APEI tables SDEI Prototype Solution for Firmware First Error Handling MM Secure Partition, Secure Partition Manager Uncorrected error -- HEST & MM Demo time Status and Future Plans

3 Brief introduction of RAS What is RAS? Why do we need RAS? History of RAS

4 What is RAS? -- Definition Reliability Continuity, Computation needs be correct and reliable. Availability Readiness, System needs to remain available as long as possible. Serviceability Ability to undergo modifications and repairs,system should provide information to administrator to aid in system servicing. The RAS architecture primarily cares about ERRORs produced from HARDWARE.

5 Why do we need RAS? -- Importance Impacts Continuity, Computation needs be correct and reliable. So we have to maintain system very well, and Operating Expense (OPEX) for maintenance is inevitable. Inevitability Although faults are rare, enterprise systems can be very large. So failures are inevitable. OPEX for maintenance is reduced by 1. replacing only failed parts 2. scheduled maintenance (is cheaper than unscheduled service outages)

6 Why do we need RAS? -- Importance Inevitability <DRAM Errors in the Wild: A Large-Scale Field Study> by Bianca Schroeder, Eduardo Pinheiro, Wolf-Dietrich Weber Benefit from ECC in DIMM Important Conclusion: The incidence of memory errors and the range of error rates across different DIMMs to be much higher than previously reported. Memory errors are strongly correlated. The incidence of CEs increases with age, while the incidence of UEs decreases with age (due to re-placements). Error rates are unlikely to be dominated by soft errors. Single-bit error --> CE Avoid (multi-bit errors)ues from beginning (Single-bit error, CEs) The statistical data of CEs/UEs could be a reference for maintenance to reduce the cost of unscheduled service outage.

7 Server without RAS How to avoid "Inevitability"? To Be Successful in Business, You Need a Little Luck. /* _ooooo_ o o 88". "88 ( -_- ) O\ = /O /`---'\.' \\ // `. / \\ : // \ / _ -:- - \ \\\ - /// \_ ''\---/'' \.-\ `-` /-. / `..' /--.--\ `..."" '< `. \_< >_/.' >'"". : `- \`.;`\ _ /`;.`/ - ` : \ \ `-. \ \ / /.-` / / ======`-. `-. \ /.-`.-'===== = `=---=' ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^ Buddha blessed No Error Forever */ --Richard Branson Emperor Yongzheng Defeat Ba A Ge (Bug)

8 History ECC in memory controllers and I/O RAMs Machine Check Architecture (MCA) A mechanism in which the CPU reports hardware errors to the OS model-specific registers (MSRs) set up machine checking record detected errors the info they contain is CPU specific Machine Check Exception (MCE) signals the detection of an uncorrected machine-check error handler collect information about error from MSRs Utility: mcelog Linux kernel EDAC (Error Detection and Correction) designed to report and possibly act on hardware errors inspect the hardware directly (system-specific handling and decoding.) only support memory controller and PCI/AGP errors Firmware (first) FF APEI UEFI PCI-E: Advanced Error Reporting (AER)

9 RAS on AArch64 Overview of Hardware & Software Prototype Solution for Firmware First Error Handling

10 Hardware support for RAS CPU ARMv8-A architecture (a mandatory extension to ARMv8.2) EL2, EL3, or both Virtualization extension or Security extensions or both GICv3 Interrupt routing modes Private and shared interrupts (PPI/SPI) Ability to set an interrupt pending event signaling and delegation Interrupt groups/priority RAS Extension ESB (Error Synchronization Barrier) instructions RAS Extension registers Corrupted data poisoning

11 RAS Extension ESB instruction ESB (Error Synchronization Barrier) can be used to isolate Unrecoverable errors. Software can determine that: The error was reported as Unrecoverable. The preferred return address of the SEI is an ESB instruction. The software between that ESB and the previous ESB can be isolated. ESB might update DISR_EL1 / DISR (Deferred Interrupt Status Register) and VDISR_EL2 / VDISR (Virtual Deferred Interrupt Status Register) RAS Extension registers: Feature Register/Component ID Register Error Record Register Feature Control Record Primary Syndrome Record Address Register Record Miscellaneous Registers Hypervisor Configuration Register Virtual SError Exception Syndrome Register Secure Configuration Register Or Interrupt Register for Fault-Handling and Recovery Device Affinity and Architecture Register

12 RAS Extension -- gather HW error info for FW ESB instruction Help to locate Error RAS Extension registers Provide the error info to FW Control the Interrupt by FW ARMv8-A RAS extensions standardize the interface between HW and FW

13 Software Architecture Firmware First error handling requires standard interfaces between multiple SW components.

14 Software Architecture

15 Firmware ARM Trusted Firmware Reference EL3 Runtime (BL31) Trusted boot firmware Standard power control (PSCI) Optional Trusted OS integration Optional Compatible with other firmware (like EDK2) Applicable to all segments Open Source at GitHub with BSD-3-clause license UEFI Unified Extensible Firmware Interface. Firmware interface between the platform and the operating system. Predominate interfaces are in the boot services (BS) or pre-os. Few runtime (RT) services. On AArch64, it (tianocore EDK2) works with ARM TF as BL33 in EL2

16 APEI (ACPI Platform Error Interfaces) For last crash BERT HEST For runtime APEI For Storage ERST Provides a standard way to convey error info from Firmware to OS EINJ For Testing

17 APEI tables HEST (Hardware Error Source Table) Key info: HOW to get trigger WHERE are the error records HOW to release records mem For ARM64 : GHES v2 HOW to get trigger: Notification Structure WHERE are the error records: Error Status Address For IA-32 : MCE/CMC/NMI For PCI: AER Root Port/Endpoint/Br idge For generic hardware: GHES (Generic Hardware Error Source) V1/V2 (GAS : Generic Address Structure) HOW to release records mem: Read Ack Register

18 APEI tables BERT: Boot Error Record Table Record fatal errors, then report it in the second boot CPER (in the Appendix of UEFI spec) Common Platform Error Record, with this help, OS can get all kinds of error we could think of.

19 APEI tables -- ERST & EINJ ERST: Error Record Serialization Table Operation abstract, provides details necessary to communicate with on-board persistent storage for error recording EINJ: Error Injection Table Operation abstract, provides a generic interface which OSPM can inject hardware errors to the platform without requiring platform specific software.

20 SDEI usage in RAS Software Delegated Exception Interface An interface between FW & OS, for registering, notifying and servicing system events using SMC/HVC. SDEI Specification (ARM DEN0054A)

21 Prototype Solution for Error Handling MM Secure Partition, Secure Partition Manager Uncorrected error -- HEST & MM

22 What Are We Doing Define standard interfaces to enable FF handling of AP RAS errors Demonstrate use of RAS extensions Demonstrate interfaces with reference software and platforms uncorrected DIMM & CPU errors

23 MM Secure Partition MM Secure Partition implements management functions, runs in S-EL0 to achieve isolation from S-EL1 & EL3 Leverages existing firmware code based on EDK2: Standalone MM Partition communicates with ARM TF through a standard interface: MM_COMMUNICATE SMC Partition is managed by ARM TF ARM TF BL31 stage owns EL3 and S-EL1 Secure partition resources are described in BL31 platform port Minimise code in EL3 and delegate RAS error handling

24 Secure Partition Manager (SPM) Secure Partition Manager in BL31 exports standard ABI to Initialize the partition Delegate SMC requests to the partition

25 Uncorrected Error -- HEST & MM

26 Uncorrected Error -- HEST & MM System boot: BootROM-->BL2-->BL3x a. BL31 initializes SPM (includes MM dispatcher) and SDEI dispatcher. b. UEFI (BL33), DXE, UEFI Platform Driver: i. query SPI (Secure Partition Image, BL32) for error source info ii. SPI return error source info back to UEFI iii. UEFI map in and mark error record region as Runtime Services Data Region iv. Update/add error source info in HEST OS starts running: HEST driver scan HEST table and register error handlers by SDEI UE occurred, the event will be routed to EL3 (SPM) SPM routes the event to RAS error handler in S-EL0 (MM Foundation) MM Foundation creates the CPER blobs by the info from RAS Extension SPM notifies SDEI to call the corresponding OS registered handler OS gets the CPER blobs by Error Status Address block, process the error, try to recovery. report the error event by RAS event rasdaemon log error info from RAS event to recorder

27 Demo Time Prototype RAS solution on FVP arm-trusted-firmware (bl1, bl2, bl31) tianocore edk2 (bl32, bl33) Linux kernel, Shell command

28 Status and Future Plans Current development status Ongoing development TODO list for Reference Solution

29 Current development status Hardware ARM engineers are working FVP, LEG team is developing on QEMU RAS spec has released (ARM DDI 0587A) Firmware SDEI SDEI Specification released (ARM DEN0054A) SDEI added as hardware error notification type in ACPI 6.2 Linux SDEI client implementation v3 patchset has been posted on kvmarm and devicetree mailing list. ACPICA support for SDEI up-streamed SDEI DT bindings acked ARM TF support posted to github and includes SDEI Dispatcher Framework for managing interrupts handled in EL3 OS (Linux): APEI on ARM64 can be enabled in kernel. Memory failure support merged

30 Ongoing development ARM TF Simplify error interrupt handling for platform ports Framework for handling External aborts (EA) in design RAS Extensions support in design ESB RAS Error Record driver EDK2 Driver for creating APEI HEST under development Library for creating APEI CPERs under development Prototyping use of Standalone MM partition to create error records on QEMU OS(Linux) KVM changes for virtualizing SDEI under development

31 TODO list Hardware Test on a real hardware (ARMv8.2, including RAS extension) Firmware ARM-TF Support for Double fault handling Support for v8.4 RAS Extensions EDK2: Support for BERT ERST and EINJ implementation

32 Acknowledgments ENGINEERS AND DEVICES WORKING TOGETHER Achin Gupta (ARM) John Feeney (Red Hat) Leif Lindholm (ARM) Supreeth Venkatesh (ARM)

33 Thank You #SFO17 BUD17 keynotes and videos on: connect.linaro.org For further information:

Reliability, Availability, and Serviceability(RAS) on ARM64. Wei Fu

Reliability, Availability, and Serviceability(RAS) on ARM64. Wei Fu Reliability, Availability, and Serviceability(RAS) on ARM64 Wei Fu AGENDA What is RAS? ARMv8 CPU requirements for RAS BERT and CPER, HEST and GHESv2, EINJ/ERST SW components for RAS(in example) CPU core,

More information

ARM64 Server RAS Solutions. Jonathan (Zhixiong) Zhang Cavium Inc.

ARM64 Server RAS Solutions. Jonathan (Zhixiong) Zhang Cavium Inc. ARM64 Server RAS Solutions Jonathan (Zhixiong) Zhang Cavium Inc. Agenda Overview Solutions Building blocks Reflections Overview Reliability, Availability, Serviceability RAS is one of the most important

More information

The Role UEFI Technologies Play in ARM Platform Architecture

The Role UEFI Technologies Play in ARM Platform Architecture presented by The Role UEFI Technologies Play in ARM Platform Architecture Spring 2017 UEFI Seminar and Plugfest March 27-31, 2017 Presented by Dong Wei (ARM) Updated 2011-06- 01 UEFI Plugfest March 2017

More information

ARM Trusted Firmware From Embedded to Enterprise. Dan Handley

ARM Trusted Firmware From Embedded to Enterprise. Dan Handley ARM Trusted Firmware From Embedded to Enterprise Dan Handley Agenda Quick recap Project news Security hardening AArch32 support ENGINEERS AND DEVICES WORKING TOGETHER Other enhancements Translation table

More information

ARM Trusted Firmware ARM UEFI SCT update

ARM Trusted Firmware ARM UEFI SCT update presented by ARM Trusted Firmware ARM UEFI SCT update UEFI US Fall Plugfest September 20-22, 2016 Presented by Charles García-Tobin (ARM) Updated 2011-06-01 Agenda ARM Trusted Firmware What and why UEFI

More information

Updates on Server Base System Architecture and Boot Requirements. Dong Wei

Updates on Server Base System Architecture and Boot Requirements. Dong Wei Updates on Server Base System Architecture and Boot Requirements Dong Wei Agenda SBSA/SBBR SBBA/SBBR Tests Ecosystem Questions ENGINEERS AND DEVICES WORKING TOGETHER ENGINEERS AND DEVICES WORKING TOGETHER

More information

UEFI updates, Secure firmware and Secure Services on Arm

UEFI updates, Secure firmware and Secure Services on Arm presented by UEFI updates, Secure firmware and Secure Services on Arm Spring 2018 UEFI Seminar and Plugfest March 26-30, 2018 Presented by Dong Wei & Matteo Carlini (Arm) Agenda UEFI and SBBR/EBBR Updates

More information

Standardized Firmware for ARMv8 based Volume Servers

Standardized Firmware for ARMv8 based Volume Servers presented by Standardized Firmware for ARMv8 based Volume Servers UEFI Spring Plugfest March 29-31, 2016 Presented by Jonathan Zhang, Robert Hsu Cavium Inc. & AMI Updated 2011-06-01 UEFI Plugfest March

More information

Dynamic secure firmware configuration. Dan Handley (Arm)

Dynamic secure firmware configuration. Dan Handley (Arm) Dynamic secure firmware configuration Dan Handley (Arm) Recap BUD17 had a session to discuss possible secure world use of kernel Device Tree (DT) Like the kernel, it s desirable to have a single set of

More information

Tailoring TrustZone as SMM Equivalent

Tailoring TrustZone as SMM Equivalent presented by Tailoring TrustZone as SMM Equivalent Tony C.S. Lo Senior Manager American Megatrends Inc. UEFI Plugfest March 2016 www.uefi.org 1 Agenda Introduction ARM TrustZone SMM-Like Services in TrustZone

More information

Embedded Base Boot Requirements. Dong Wei

Embedded Base Boot Requirements. Dong Wei Embedded Base Boot Requirements Dong Wei Platform Architecture Base System Architecture (BSA) Defines hardware requirements Base Boot Requirements (BBR) Defines firmware requirements These specifications

More information

ARM Trusted Firmware Evolution HKG15 February Andrew Thoelke Systems & Software, ARM

ARM Trusted Firmware Evolution HKG15 February Andrew Thoelke Systems & Software, ARM ARM Trusted Evolution HKG15 February 2015 Andrew Thoelke Systems & Software, ARM 1 ARM Trusted for 64-bit ARMv8-A A refresher Standardized EL3 Runtime For all 64-bit ARMv8-A systems Reducing porting and

More information

UEFI in Arm Platform Architecture

UEFI in Arm Platform Architecture presented by UEFI in Arm Platform Architecture Fall 2017 UEFI Seminar and Plugfest October 30 November 3, 2017 Presented by Dong Wei (Arm Limited) UEFI Plugfest October 2017 www.uefi.org 1 Agenda Arm @

More information

Back To The Future: A Radical Insecure Design of KVM on ARM

Back To The Future: A Radical Insecure Design of KVM on ARM Back To The Future: A Radical Insecure Design of KVM on ARM Abstract In ARM, there are certain instructions that generate exceptions. Such instructions are typically executed to request a service from

More information

ARM Reliability, Availability, and Serviceability (RAS) Specification ARMv8, for the ARMv8-A architecture profile Beta

ARM Reliability, Availability, and Serviceability (RAS) Specification ARMv8, for the ARMv8-A architecture profile Beta ARM Reliability, Availability, and Serviceability (RAS) Specification ARMv8, for the ARMv8-A architecture profile Beta Copyright 2017 ARM Limited or its affiliates. All rights reserved. Document number:

More information

ServerReady and Open Standards Accelerating Delivery

ServerReady and Open Standards Accelerating Delivery ServerReady and Open Standards Accelerating Delivery Dong Wei Senior Director and Lead Architect, DE Arm #Arm Tech Symposia Copyright 2018 Arm Tech Symposia, All rights reserved. The Cloud to Edge Infrastructure

More information

UEFI What is it? Spring 2017 UEFI Seminar and Plugfest March 27-31, 2017 Presented by Dong Wei (ARM) presented by. Updated

UEFI What is it? Spring 2017 UEFI Seminar and Plugfest March 27-31, 2017 Presented by Dong Wei (ARM) presented by. Updated presented by UEFI What is it? Spring 2017 UEFI Seminar and Plugfest March 27-31, 2017 Presented by Dong Wei (ARM) Updated 2011-06- 01 UEFI Plugfest March 2017 www.uefi.org 1 Agenda Introduction Background

More information

Arm Server Ready. Dong Wei

Arm Server Ready. Dong Wei Arm Server Ready Dong Wei Agenda Arm ServerReady Program SBSA/SBBR Updates PCIe Integration Updates UEFI Forum Updates Server Management Strategy ENGINEERS AND DEVICES WORKING TOGETHER Agenda Arm ServerReady

More information

UEFI ARM Update. Presented by Mitch Ishihara. UEFI Plugfest October presented by

UEFI ARM Update. Presented by Mitch Ishihara. UEFI Plugfest October presented by UEFI ARM Update Presented by Mitch Ishihara presented by UEFI Plugfest October 2014 Agenda Economics Objectives Status Overview Specifications Implementation Testing Technology Resources www.uefi.org 2

More information

Designing Security & Trust into Connected Devices

Designing Security & Trust into Connected Devices Designing Security & Trust into Connected Devices Eric Wang Sr. Technical Marketing Manager Tech Symposia China 2015 November 2015 Agenda Introduction Security Foundations on ARM Cortex -M Security Foundations

More information

UEFI Plugfest March

UEFI Plugfest March UEFI Plugfest March 2017 www.uefi.org 1 presented by The UEFI Forum State of UEFI Fall 2017 UEFI Seminar and Plugfest October 30 November 3, 2017 Presented by Mark Doran, UEFI Forum President www.uefi.org

More information

Trusted Firmware Deep Dive. Dan Handley Charles Garcia-Tobin

Trusted Firmware Deep Dive. Dan Handley Charles Garcia-Tobin Trusted Firmware Deep Dive Dan Handley Charles Garcia-Tobin 1 Agenda Architecture overview Memory usage Code organisation Cold boot deep dive PSCI deep dive 2 Example System Architecture Normal World Secure

More information

UEFI Secure Boot and DRI. Kalyan Kumar N

UEFI Secure Boot and DRI. Kalyan Kumar N UEFI Secure Boot and DRI Kalyan Kumar N Agenda Introduction RDK Boot Loader DRI (Disaster Recovery Image) RootFS Validation Build Environment Introduction Standardization of the RDK set-top box firmware

More information

Enabling Arm DynamIQ support. Dan Handley (Arm) Ionela Voinescu (Arm) Vincent Guittot (Linaro)

Enabling Arm DynamIQ support. Dan Handley (Arm) Ionela Voinescu (Arm) Vincent Guittot (Linaro) Enabling Arm DynamIQ support Dan Handley (Arm) Ionela Voinescu (Arm) Vincent Guittot (Linaro) Agenda DynamIQ introduction DynamIQ and Arm Trusted Firmware OS Power Management with DynamIQ L3 partial power-down

More information

LCA14-107: ACPI upstreaming. Wed-5-Mar, 11:15am, Al Stone, G Gregory, Hanjun Guo

LCA14-107: ACPI upstreaming. Wed-5-Mar, 11:15am, Al Stone, G Gregory, Hanjun Guo LCA14-107: ACPI upstreaming Wed-5-Mar, 11:15am, Al Stone, G Gregory, Hanjun Guo ACPI Upstreaming Staged for 3.15 (in linux-next): Odds and ends: APEI cleanups, white space, minor bugs in ACPI driver Reduced

More information

Introduction to Standards based approach to Server

Introduction to Standards based approach to Server Introduction to Standards based approach to Server Winnie Shao Server & Ecosystem Director Arm Copyright 2018 Arm, All rights reserved. Why do we need a standards-based approach? Arm architecture supports

More information

Designing Security & Trust into Connected Devices

Designing Security & Trust into Connected Devices Designing Security & Trust into Connected Devices Rob Coombs Security Marketing Director TechCon 11/10/15 Agenda Introduction Security Foundations on Cortex-M Security Foundations on Cortex-A Use cases

More information

Software Delegated Exception Interface (SDEI)

Software Delegated Exception Interface (SDEI) Software Delegated Exception Interface (SDEI) Platform Design Document Copyright 2017 ARM or its affiliates. All rights reserved. Document number: ARM DEN 0054A Software Delegated Exception Interface System

More information

ARM-KVM: Weather Report Korea Linux Forum

ARM-KVM: Weather Report Korea Linux Forum ARM-KVM: Weather Report Korea Linux Forum Mario Smarduch Senior Virtualization Architect m.smarduch@samsung.com 1 ARM-KVM This Year Key contributors Linaro, ARM Access to documentation & specialized HW

More information

mcelog Memory error handling in user space

mcelog Memory error handling in user space mcelog Memory error handling in user space Sept. 2010 Andi Kleen Linux Kongress 2010 Trends Many cores need more memory Important workloads need a lot of memory Maximum memory capacity growing quickly

More information

AMD SEV Update Linux Security Summit David Kaplan, Security Architect

AMD SEV Update Linux Security Summit David Kaplan, Security Architect AMD SEV Update Linux Security Summit 2018 David Kaplan, Security Architect WHY NOT TRUST THE HYPERVISOR? Guest Perspective o Hypervisor is code I don t control o I can t tell if the hypervisor is compromised

More information

KVM/ARM. Marc Zyngier LPC 12

KVM/ARM. Marc Zyngier LPC 12 KVM/ARM Marc Zyngier LPC 12 For example: if a processor is in Supervisor mode and Secure state, it is in Secure Supervisor mode ARM Architecture if a processor is Virtualization

More information

AArch64 Virtualization

AArch64 Virtualization Connect AArch64 User Virtualization Guide Version Version 0.11.0 Page 1 of 13 Revision Information The following revisions have been made to this User Guide. Date Issue Confidentiality Change 03 March

More information

HW isolation for automotive environment BoF

HW isolation for automotive environment BoF HW isolation for automotive environment BoF Michele Paolino m.paolino@virtualopensystems.com AGL All Member Meeting 2016, 2016-09-07, Munich, Germany http://www.tapps-project.eu/ Authorship and sponsorship

More information

Reliability, Availability, Serviceability (RAS) and Management for Non-Volatile Memory Storage

Reliability, Availability, Serviceability (RAS) and Management for Non-Volatile Memory Storage Reliability, Availability, Serviceability (RAS) and Management for Non-Volatile Memory Storage Mohan J. Kumar, Intel Corp Sammy Nachimuthu, Intel Corp Dimitris Ziakas, Intel Corp August 2015 1 Agenda NVDIMM

More information

EC H2020 dredbox: Seminar School at INSA Rennes

EC H2020 dredbox: Seminar School at INSA Rennes EC H2020 dredbox: Seminar School at INSA Rennes contact@virtualopensystems.com www.virtualopensystems.com Pierre LUCAS 2017-11-22 Open Part 1: Open Company Overview 2 OpenOpen Confidential & Proprietary

More information

viommu/arm: full emulation and virtio-iommu approaches Eric Auger KVM Forum 2017

viommu/arm: full emulation and virtio-iommu approaches Eric Auger KVM Forum 2017 viommu/arm: full emulation and virtio-iommu approaches Eric Auger KVM Forum 2017 Overview Goals & Terminology ARM IOMMU Emulation QEMU Device VHOST Integration VFIO Integration Challenges VIRTIO-IOMMU

More information

Intel SoC FPGA Embedded Development Suite (SoC EDS) Release Notes

Intel SoC FPGA Embedded Development Suite (SoC EDS) Release Notes Intel SoC FPGA Embedded Development Suite (SoC EDS) Release Notes Updated for Intel Quartus Prime Design Suite: 18.1 Subscribe Latest document on the web: PDF HTML Contents Contents Intel SoC FPGA Embedded

More information

ARM CORTEX-R52. Target Audience: Engineers and technicians who develop SoCs and systems based on the ARM Cortex-R52 architecture.

ARM CORTEX-R52. Target Audience: Engineers and technicians who develop SoCs and systems based on the ARM Cortex-R52 architecture. ARM CORTEX-R52 Course Family: ARMv8-R Cortex-R CPU Target Audience: Engineers and technicians who develop SoCs and systems based on the ARM Cortex-R52 architecture. Duration: 4 days Prerequisites and related

More information

UEFI ARM Update. UEFI PlugFest March 18-22, 2013 Andrew N. Sloss (ARM, Inc.) presented by

UEFI ARM Update. UEFI PlugFest March 18-22, 2013 Andrew N. Sloss (ARM, Inc.) presented by presented by UEFI ARM Update UEFI PlugFest March 18-22, 2013 Andrew N. Sloss (ARM, Inc.) Updated 2011-06-01 UEFI Spring PlugFest March 2013 www.uefi.org 1 AGENDA economics technology status summary questions

More information

UEFI Porting Update for ARM Platforms

UEFI Porting Update for ARM Platforms UEFI Porting Update for ARM Platforms What did we do since July? Leif Lindholm UEFI tech lead Linaro Enterprise Group presented by UEFI Plugfest May 2014 Agenda Introduction Linux Support EDK2 Development

More information

BKK16-309B Enterprise Firmware - The gold standard and how to get there. Jeff Underhill

BKK16-309B Enterprise Firmware - The gold standard and how to get there. Jeff Underhill BKK16-309B Enterprise Firmware - The gold standard and how to get there Jeff Underhill Why We Need Server Standards? 1. Installing Linux in 27 Easy Steps 2. OS / PlaOorm Support Matrix 3. UEFI + ACPI Appendix

More information

Xen on ARM ARMv7 with virtualization extensions

Xen on ARM ARMv7 with virtualization extensions Xen on ARM ARMv7 with virtualization extensions Stefano Stabellini Why? Why? smartphones: getting smarter Quad-core 1.4 GHz Cortex-A9 ARM Servers coming to market 4GB RAM, 4 cores per node 3 x 6 x 4 x

More information

ARM Server s Firmware Security

ARM Server s Firmware Security presented by ARM Server s Firmware Security Spring 2017 UEFI Seminar and Plugfest March 27-31, 2017 Presented by Zhixiong (Jonathan) Zhang (Cavium, Inc.) Updated 2011-06- 01 UEFI Plugfest March 2017 www.uefi.org

More information

viommu/arm: full emulation and virtio-iommu approaches Eric Auger KVM Forum 2017

viommu/arm: full emulation and virtio-iommu approaches Eric Auger KVM Forum 2017 viommu/arm: full emulation and virtio-iommu approaches Eric Auger KVM Forum 2017 Overview Goals & Terminology ARM IOMMU Emulation QEMU Device VHOST Integration VFIO Integration Challenges VIRTIO-IOMMU

More information

HKG Android Verified Boot 2.0 and U-boot. Igor Opaniuk, Texas Instruments

HKG Android Verified Boot 2.0 and U-boot. Igor Opaniuk, Texas Instruments HKG18-124 Android Verified Boot 2.0 and U-boot Igor Opaniuk, Texas Instruments Agenda Android Verified Boot 2.0 highlights Current status of AVB 2.0 integration in U-boot Tamper-evident storage and TEE

More information

Non-Trusted. software. data. hardware. Open Source Secure World Software Trusted Firmware. Trusted. software. data. Update October 2018

Non-Trusted. software. data. hardware. Open Source Secure World Software Trusted Firmware. Trusted. software. data. Update October 2018 data software Non-Trusted Trusted Open Source Secure World Software Trusted Firmware software Update October 2018 data hardware SPONSORED BY: HOSTED BY: Trusted Firmware with Open Governance Membership

More information

Building a reference IoT product with Zephyr. Ricardo Salveti Michael Scott Tyler Baker

Building a reference IoT product with Zephyr. Ricardo Salveti Michael Scott Tyler Baker Building a reference IoT product with Zephyr Ricardo Salveti Michael Scott Tyler Baker Introduction Linaro Technologies A small team within Linaro focusing on open source end-to-end solutions Who is here?

More information

An Introduction to Platform Security

An Introduction to Platform Security presented by An Introduction to Platform Security Spring 2018 UEFI Seminar and Plugfest March 26-30, 2018 Presented by Brent Holtsclaw and John Loucaides (Intel) Legal Notice No computer system can be

More information

Fall 2017 UEFI Plugfest Agenda

Fall 2017 UEFI Plugfest Agenda Fall 2017 UEFI Plugfest Agenda Day 1 Oct. 30 (Mon) Day 2 Oct. 31 (Tue) Day 3 Nov. 1 (Wed) Day 4 Nov. 2 (Thurs) Day 5 Nov. 3 (Fri) 08:00-08:30 Check-in (Event) / Breakfast 08:30-09:00 State of UEFI Mark

More information

Beyond TrustZone Security Enclaves Reed Hinkel Senior Manager Embedded Security Market Develop

Beyond TrustZone Security Enclaves Reed Hinkel Senior Manager Embedded Security Market Develop Beyond TrustZone Security Enclaves Reed Hinkel Senior Manager Embedded Security Market Develop Part2 Security Enclaves Tech Seminars 2017 Agenda New security technology for IoT Security Enclaves CryptoIsland

More information

O p t i m i z e d U E F I I m p l e m e n t a t i o n o n I n t e l X e o n B a s e d O C P P l a t f o r m

O p t i m i z e d U E F I I m p l e m e n t a t i o n o n I n t e l X e o n B a s e d O C P P l a t f o r m O p t i m i z e d U E F I I m p l e m e n t a t i o n o n I n t e l X e o n B a s e d O C P P l a t f o r m Sarathy Jayakumar, Principal Engineer, Intel Corp Mohan J. Kumar, Fellow, Intel Corp B a s e

More information

Managing Persistent Memory Tiffany Kasanicky Intel

Managing Persistent Memory Tiffany Kasanicky Intel Managing Persistent Memory Tiffany Kasanicky Intel 1 Agenda Managing* Be in charge of; administer; run. The process of dealing with or controlling things or people. Persistent Memory Memory that retains

More information

SFO15-100: 96Boards & the course upstream

SFO15-100: 96Boards & the course upstream SFO15-100: 96Boards & the course upstream Presented by Scott Bambrough David Mandala Date Monday 21 September 2015 Event SFO15 Scott Bambrough David Mandala Agenda 96Boards program status Hardware ecosystem

More information

Improving Fault Tolerance Using Memory Redundancy and Hot-Plug Actions in Dell PowerEdge Servers

Improving Fault Tolerance Using Memory Redundancy and Hot-Plug Actions in Dell PowerEdge Servers Improving Fault Tolerance Using Redundancy and Hot-Plug Actions in Dell PowerEdge Servers Features that enable redundancy across physical memory can enhance server reliability and help keep critical business

More information

QEMU for Xilinx ZynqMP. V Aug-20

QEMU for Xilinx ZynqMP. V Aug-20 QEMU for Xilinx ZynqMP Edgar E. Iglesias V2 2015-Aug-20 ZynqMP SoC New Chip (Zynq NG) Aggressive target for QEMU as early SW platform emulating WiP chip BootROMs, Boot-loaders,

More information

IA32 OS START-UP UEFI FIRMWARE. CS124 Operating Systems Fall , Lecture 6

IA32 OS START-UP UEFI FIRMWARE. CS124 Operating Systems Fall , Lecture 6 IA32 OS START-UP UEFI FIRMWARE CS124 Operating Systems Fall 2017-2018, Lecture 6 2 Last Time: IA32 Bootstrap Computers and operating systems employ a bootstrap process to load and start the operating system

More information

HOW TO INTEGRATE NFC FRONTENDS IN LINUX

HOW TO INTEGRATE NFC FRONTENDS IN LINUX HOW TO INTEGRATE NFC FRONTENDS IN LINUX JORDI JOFRE NFC READERS NFC EVERYWHERE 14/09/2017 WEBINAR SERIES: NFC SOFTWARE INTEGRATION PUBLIC Agenda NFC software integration webinar series Session I, 14th

More information

Trusted Execution Environments (TEE) and the Open Trust Protocol (OTrP) Hannes Tschofenig and Mingliang Pei 16 th July IETF 99 th, Prague

Trusted Execution Environments (TEE) and the Open Trust Protocol (OTrP) Hannes Tschofenig and Mingliang Pei 16 th July IETF 99 th, Prague Trusted Execution Environments (TEE) and the Open Trust Protocol (OTrP) Hannes Tschofenig and Mingliang Pei 16 th July 2017 -- IETF 99 th, Prague 2 What do we mean by security? Communication Security Aims

More information

Software Development Using Full System Simulation with Freescale QorIQ Communications Processors

Software Development Using Full System Simulation with Freescale QorIQ Communications Processors Patrick Keliher, Simics Field Application Engineer Software Development Using Full System Simulation with Freescale QorIQ Communications Processors 1 2013 Wind River. All Rights Reserved. Agenda Introduction

More information

Lecture 5. KVM for ARM. Christoffer Dall and Jason Nieh. 5 November, Operating Systems Practical. OSP Lecture 5, KVM for ARM 1/42

Lecture 5. KVM for ARM. Christoffer Dall and Jason Nieh. 5 November, Operating Systems Practical. OSP Lecture 5, KVM for ARM 1/42 Lecture 5 KVM for ARM Christoffer Dall and Jason Nieh Operating Systems Practical 5 November, 2014 OSP Lecture 5, KVM for ARM 1/42 Contents Virtualization KVM Virtualization on ARM KVM/ARM: System architecture

More information

2006/7/22. NTT Data Intellilink Corporation Fernando Luis Vázquez Cao. Copyright(C)2006 NTT Data Intellilink Corporation

2006/7/22. NTT Data Intellilink Corporation Fernando Luis Vázquez Cao. Copyright(C)2006 NTT Data Intellilink Corporation Evaluating Linux Kernel Crash Dumping Mechanisms 2006/7/22 NTT Data Intellilink Corporation Fernando Luis Vázquez Cao 1 Who am I? LKDTT (Linux Kernel Dump Test Tool) maintainer MKDump (Mini Kernel Dump)

More information

New Approaches to Connected Device Security

New Approaches to Connected Device Security New Approaches to Connected Device Security Erik Jacobson Architecture Marketing Director Arm Arm Techcon 2017 - If you connect it to the Internet, someone will try to hack it. - If what you put on the

More information

Hacking the Extensible Firmware Interface. John Heasman, Director of Research

Hacking the Extensible Firmware Interface. John Heasman, Director of Research Hacking the Extensible Firmware Interface John Heasman, Director of Research Agenda The role of the BIOS Attacking a legacy BIOS Limitations of the legacy BIOS Introduction to the EFI environment Attacking

More information

BUD17-301: KVM/ARM Nested Virtualization. Christoffer Dall

BUD17-301: KVM/ARM Nested Virtualization. Christoffer Dall BUD17-301: KVM/ARM Nested Virtualization Christoffer Dall Nested Virtualization VM VM VM App App App App App VM App Hypervisor Hypervisor Hardware Terminology Nested VM VM Nested VM L2 App App App App

More information

OP-TEE Using TrustZone to Protect Our Own Secrets

OP-TEE Using TrustZone to Protect Our Own Secrets OP-TEE Using TrustZone to Protect Our Own Secrets ROM-Code Bootloader OP-TEE Kernel Root File System ELC Europe 2017, 23.10.2017 Marc Kleine-Budde Slide 1 - http://www.pengutronix.de

More information

UEFI and the Security Development Lifecycle

UEFI and the Security Development Lifecycle presented by UEFI and the Security Development Lifecycle Spring 2018 UEFI Seminar and Plugfest March 26-30, 2018 Presented by Tim Lewis (Insyde Software) Agenda The Threat Is Real The Security Development

More information

Digging Into The Core of Boot

Digging Into The Core of Boot Digging Into The Core of Boot Yuriy Bulygin Oleksandr Bazhaniuk @c7zero @ABazhaniuk Agenda Intro Recap of MMIO BAR Issues in Coreboot & UEFI Coreboot ACPI GNVS Pointer Issue SMI Handler Issues in Coreboot

More information

Secure Containers with EPT Isolation

Secure Containers with EPT Isolation Secure Containers with EPT Isolation Chunyan Liu liuchunyan9@huawei.com Jixing Gu jixing.gu@intel.com Presenters Jixing Gu: Software Architect, from Intel CIG SW Team, working on secure container solution

More information

Nooks. Robert Grimm New York University

Nooks. Robert Grimm New York University Nooks Robert Grimm New York University The Three Questions What is the problem? What is new or different? What are the contributions and limitations? Design and Implementation Nooks Overview An isolation

More information

Xen and the Art of Virtualization. CSE-291 (Cloud Computing) Fall 2016

Xen and the Art of Virtualization. CSE-291 (Cloud Computing) Fall 2016 Xen and the Art of Virtualization CSE-291 (Cloud Computing) Fall 2016 Why Virtualization? Share resources among many uses Allow heterogeneity in environments Allow differences in host and guest Provide

More information

Intel Optane DC Persistent Memory Module (DCPMM) - DSM

Intel Optane DC Persistent Memory Module (DCPMM) - DSM Intel Optane DC Persistent Memory Module (DCPMM) - DSM Interface Revision V1.8 October, 2018 The following changes make up the publically released DSM V1.8 specification available on http://pmem.io/documents/:

More information

ARMv8: The Next Generation. Minlin Fan & Zenon Xiu December 8, 2015

ARMv8: The Next Generation. Minlin Fan & Zenon Xiu December 8, 2015 ARMv8: The Next Generation Minlin Fan & Zenon Xiu December 8, 2015 1 Introducing Ourselves Minlin Fan Application Engineering Manager Zenon Xiu Application Engineering Software Team Lead 2 ARM Partner

More information

ARM TrustZone for ARMv8-M for software engineers

ARM TrustZone for ARMv8-M for software engineers ARM TrustZone for ARMv8-M for software engineers Ashok Bhat Product Manager, HPC and Server tools ARM Tech Symposia India December 7th 2016 The need for security Communication protection Cryptography,

More information

STM/PE & XHIM. Eugene D. Myers Trust Mechanisms Information Assurance Research NSA/CSS Research Directorate May 24, 2018

STM/PE & XHIM. Eugene D. Myers Trust Mechanisms Information Assurance Research NSA/CSS Research Directorate May 24, 2018 STM/PE & XHIM Eugene D. Myers Trust Mechanisms Information Assurance Research NSA/CSS Research Directorate May 24, 2018 Overview SMM STM STM/PE XHIM, an STM/PE application Future Plans System Management

More information

Crashes, Panics and Other Oddities. Imed Chihi, Red Hat February 2008

Crashes, Panics and Other Oddities. Imed Chihi, Red Hat February 2008 Crashes, Panics and Other Oddities Imed Chihi, Red Hat February 2008 Agenda Defining some terms Analogy with User Space The BUG() Macro Bad Pointer Handling The NMI Watchdog Machine Check Exceptions EDAC

More information

AUTOBEST: A United AUTOSAR-OS And ARINC 653 Kernel. Alexander Züpke, Marc Bommert, Daniel Lohmann

AUTOBEST: A United AUTOSAR-OS And ARINC 653 Kernel. Alexander Züpke, Marc Bommert, Daniel Lohmann AUTOBEST: A United AUTOSAR-OS And ARINC 653 Kernel Alexander Züpke, Marc Bommert, Daniel Lohmann alexander.zuepke@hs-rm.de, marc.bommert@hs-rm.de, lohmann@cs.fau.de Motivation Automotive and Avionic industry

More information

UEFI Forum Update. UEFI Spring Plugfest March 29-31, 2016 Presented by Dong Wei (The UEFI Forum)

UEFI Forum Update. UEFI Spring Plugfest March 29-31, 2016 Presented by Dong Wei (The UEFI Forum) UEFI Forum Update UEFI Spring Plugfest March 29-31, 2016 Presented by Dong Wei (The UEFI Forum) Updated 2011-06-01 UEFI Plugfest March 2016 www.uefi.org 1 Agenda Organization Update Specifications Update

More information

Past, Present, and Future Justin Johnson Senior Principal Firmware Engineer

Past, Present, and Future Justin Johnson Senior Principal Firmware Engineer Dell Firmware Security Past, Present, and Future Justin Johnson Senior Principal Firmware Engineer justin.johnson1@dell.com Dell Security 2 What does BIOS do? Configure and Test System Memory Configure

More information

G Xen and Nooks. Robert Grimm New York University

G Xen and Nooks. Robert Grimm New York University G22.3250-001 Xen and Nooks Robert Grimm New York University Agenda! Altogether now: The three questions! The (gory) details of Xen! We already covered Disco, so let s focus on the details! Nooks! The grand

More information

Solaris FMA and Xen. Frank van der Linden Sun Microsystems

Solaris FMA and Xen. Frank van der Linden Sun Microsystems Solaris FMA and Xen Frank van der Linden Sun Microsystems 1 Overview What is FMA? Requirements to implement FMA Changes made to Xen Changes made to Solaris Status / future work 2 What is FMA? Fault Management

More information

Designing Security & Trust into Connected Devices

Designing Security & Trust into Connected Devices Designing Security & Trust into Connected Devices Eric Wang Senior Technical Marketing Manager Shenzhen / ARM Tech Forum / The Ritz-Carlton June 14, 2016 Agenda Introduction Security Foundations on Cortex-A

More information

96Boards - TV Platform

96Boards - TV Platform 96Boards - TV Platform Presented by Mark Gregotski Developing the Specification Date BKK16-303 March 9, 2016 Event Linaro Connect BKK16 Overview Motivation for a TV Platform Specification Comparison with

More information

libvirt integration and testing for enterprise KVM/ARM Drew Jones, Eric Auger Linaro Connect Budapest 2017 (BUD17)

libvirt integration and testing for enterprise KVM/ARM Drew Jones, Eric Auger Linaro Connect Budapest 2017 (BUD17) libvirt integration and testing for enterprise KVM/ARM Drew Jones, Eric Auger Linaro Connect Budapest 2017 (BUD17) Overview Enterprise guest requirements QEMU/KVM enterprise guest management libvirt A

More information

Xen on ARM. Stefano Stabellini

Xen on ARM. Stefano Stabellini Xen on ARM Stefano Stabellini What is Xen? a type-1 hypervisor small footprint (less than 90K LOC) Xen: Open Source GPLv2 with DCO (like Linux) Diverse contributor community Xen: Open Source source: Mike

More information

PROTECTING VM REGISTER STATE WITH AMD SEV-ES DAVID KAPLAN LSS 2017

PROTECTING VM REGISTER STATE WITH AMD SEV-ES DAVID KAPLAN LSS 2017 PROTECTING VM REGISTER STATE WITH AMD SEV-ES DAVID KAPLAN LSS 2017 BACKGROUND-- HARDWARE MEMORY ENCRYPTION AMD Secure Memory Encryption (SME) / AMD Secure Encrypted Virtualization (SEV) Hardware AES engine

More information

Porting Hyperkernel to the ARM Architecture

Porting Hyperkernel to the ARM Architecture Technical Report UW-CSE-17-08-02 Porting Hyperkernel to the ARM Architecture Dylan Johnson University of Washington dgj16@cs.washington.edu Keywords ARM, AArch64, Exokernel, Operating Systems, Virtualization

More information

UEFI Test Tools For Linux Developers

UEFI Test Tools For Linux Developers presented by UEFI Test Tools For Linux Developers Brian Richardson Intel Corporation Alex Hung Canonical, Ltd. August Updated 22, 2014 2011-06-01 Agenda UEFI & Linux Interoperability Using FWTS with UEFI

More information

HKG : OpenAMP Introduction. Wendy Liang

HKG : OpenAMP Introduction. Wendy Liang HKG2018-411: OpenAMP Introduction Wendy Liang Agenda OpenAMP Projects Overview OpenAMP Libraries Changes in Progress Future Improvements OpenAMP Projects Overview Introduction With today s sophisticated

More information

Xen on ARM. How fast is it, really? Stefano Stabellini. 18 August 2014

Xen on ARM. How fast is it, really? Stefano Stabellini. 18 August 2014 Xen on ARM How fast is it, really? Stefano Stabellini 18 August 2014 Status Xen Project 4.4 release: status Features: 64-bit guest support in ARMv8 stable hypercall ABI basic lifecycle operations memory

More information

Linux on Sun Logical Domains

Linux on Sun Logical Domains Linux on Sun Logical Domains linux.conf.au, MEL8OURNE, 2008 Outline 1 Background SUN4V and Niagara Sun s Logical Domains 2 Userland Simulator 3 Implementation LDC: Logical Domain Channels VIO: Virtual

More information

KVM/ARM: The Design and Implementation of the Linux ARM Hypervisor

KVM/ARM: The Design and Implementation of the Linux ARM Hypervisor KVM/ARM: The Design and Implementation of the Linux ARM Hypervisor Christoffer Dall Department of Computer Science Columbia University cdall@cs.columbia.edu Jason Nieh Department of Compouter Science Columbia

More information

ARM Device Tree status report

ARM Device Tree status report ARM Device Tree status report Grant Likely Secret Lab Technologies Ltd. October 28, 2010 Embedded Linux Conference Europe Cambridge, UK Overview Device Tree Overview Integration with the Linux device model

More information

How to Introduce Virtualization in AGL? Objectives, Plans and Targets for AGL EG-VIRT

How to Introduce Virtualization in AGL? Objectives, Plans and Targets for AGL EG-VIRT How to Introduce Virtualization in AGL? Objectives, Plans and Targets for AGL EG-VIRT Michele Paolino m.paolino@virtualopensystems.com Automotive Grade Linux Summit 2017 2017-06-01, Tokyo, Japan http://www.tapps-project.eu/

More information

How to get realistic C-states latency and residency? Vincent Guittot

How to get realistic C-states latency and residency? Vincent Guittot How to get realistic C-states latency and residency? Vincent Guittot Agenda Overview Exit latency Enter latency Residency Conclusion Overview Overview PMWG uses hikey960 for testing our dev on b/l system

More information

XID ERRORS. vr384 October XID Errors

XID ERRORS. vr384 October XID Errors ID ERRORS vr384 October 2017 ID Errors Introduction... 1 1.1. What Is an id Message... 1 1.2. How to Use id Messages... 1 Working with id Errors... 2 2.1. Viewing id Error Messages... 2 2.2. Tools That

More information

The following modifications have been made to this version of the DSM specification:

The following modifications have been made to this version of the DSM specification: NVDIMM DSM Interface Revision V1.6 August 9, 2017 The following modifications have been made to this version of the DSM specification: - General o Added two tables of supported Function Ids, Revision Ids

More information

ARMv8-A Software Development

ARMv8-A Software Development ARMv8-A Software Development Course Description ARMv8-A software development is a 4 days ARM official course. The course goes into great depth and provides all necessary know-how to develop software for

More information

1 FOSDEM like real computers - Making distributions work on single board computers André Przywara 04/02/2018

1 FOSDEM like real computers - Making distributions work on single board computers André Przywara 04/02/2018 1 FOSDEM 2018... like real computers - Making distributions work on single board computers André Przywara 04/02/2018 apritzel@freenode 2 FOSDEM 2018 2 FOSDEM 2018 2 FOSDEM 2018 2 FOSDEM 2018 3 FOSDEM 2018

More information

Trustzone Security IP for IoT

Trustzone Security IP for IoT Trustzone Security IP for IoT Udi Maor CryptoCell-7xx product manager Systems & Software Group ARM Tech Forum Singapore July 12 th 2017 Why is getting security right for IoT so important? When our everyday

More information