2 * Copyright (C) 2007 Michael Brown <mbrown@fensystems.co.uk>.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License as
6 * published by the Free Software Foundation; either version 2 of the
7 * License, or any later version.
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12 * General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the Free Software
16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
19 * You can also choose to distribute this program under the terms of
20 * the Unmodified Binary Distribution Licence (as given in the file
21 * COPYING.UBDL), provided that you have satisfied its requirements.
24 FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL );
29 * Linux bzImage image format
41 #include <ipxe/uaccess.h>
42 #include <ipxe/image.h>
43 #include <ipxe/segment.h>
44 #include <ipxe/init.h>
45 #include <ipxe/cpio.h>
46 #include <ipxe/features.h>
48 FEATURE ( FEATURE_IMAGE, "bzImage", DHCP_EB_FEATURE_BZIMAGE, 1 );
53 struct bzimage_context {
54 /** Boot protocol version */
56 /** Real-mode kernel portion load segment address */
57 unsigned int rm_kernel_seg;
58 /** Real-mode kernel portion load address */
60 /** Real-mode kernel portion file size */
62 /** Real-mode heap top (offset from rm_kernel) */
64 /** Command line (offset from rm_kernel) */
66 /** Command line maximum length */
68 /** Real-mode kernel portion total memory size */
70 /** Non-real-mode kernel portion load address */
72 /** Non-real-mode kernel portion file and memory size */
75 unsigned int vid_mode;
79 physaddr_t ramdisk_image;
81 physaddr_t ramdisk_size;
83 /** Command line magic block */
84 struct bzimage_cmdline cmdline_magic;
86 struct bzimage_header bzhdr;
90 * Parse bzImage header
92 * @v image bzImage file
93 * @v bzimg bzImage context
94 * @v src bzImage to parse
95 * @ret rc Return status code
97 static int bzimage_parse_header ( struct image *image,
98 struct bzimage_context *bzimg,
100 unsigned int syssize;
104 if ( image->len < ( BZI_HDR_OFFSET + sizeof ( bzimg->bzhdr ) ) ) {
105 DBGC ( image, "bzImage %p too short for kernel header\n",
110 /* Read in header structures */
111 memset ( bzimg, 0, sizeof ( *bzimg ) );
112 copy_from_user ( &bzimg->cmdline_magic, src, BZI_CMDLINE_OFFSET,
113 sizeof ( bzimg->cmdline_magic ) );
114 copy_from_user ( &bzimg->bzhdr, src, BZI_HDR_OFFSET,
115 sizeof ( bzimg->bzhdr ) );
117 /* Calculate size of real-mode portion */
118 bzimg->rm_filesz = ( ( ( bzimg->bzhdr.setup_sects ?
119 bzimg->bzhdr.setup_sects : 4 ) + 1 ) << 9 );
120 if ( bzimg->rm_filesz > image->len ) {
121 DBGC ( image, "bzImage %p too short for %zd byte of setup\n",
122 image, bzimg->rm_filesz );
125 bzimg->rm_memsz = BZI_ASSUMED_RM_SIZE;
127 /* Calculate size of protected-mode portion */
128 bzimg->pm_sz = ( image->len - bzimg->rm_filesz );
129 syssize = ( ( bzimg->pm_sz + 15 ) / 16 );
131 /* Check for signatures and determine version */
132 if ( bzimg->bzhdr.boot_flag != BZI_BOOT_FLAG ) {
133 DBGC ( image, "bzImage %p missing 55AA signature\n", image );
136 if ( bzimg->bzhdr.header == BZI_SIGNATURE ) {
138 bzimg->version = bzimg->bzhdr.version;
140 /* Pre-2.00. Check that the syssize field is correct,
141 * as a guard against accepting arbitrary binary data,
142 * since the 55AA check is pretty lax. Note that the
143 * syssize field is unreliable for protocols between
144 * 2.00 and 2.03 inclusive, so we should not always
147 bzimg->version = 0x0100;
148 if ( bzimg->bzhdr.syssize != syssize ) {
149 DBGC ( image, "bzImage %p bad syssize %x (expected "
150 "%x)\n", image, bzimg->bzhdr.syssize, syssize );
155 /* Determine image type */
156 is_bzimage = ( ( bzimg->version >= 0x0200 ) ?
157 ( bzimg->bzhdr.loadflags & BZI_LOAD_HIGH ) : 0 );
159 /* Calculate load address of real-mode portion */
160 bzimg->rm_kernel_seg = ( is_bzimage ? 0x1000 : 0x9000 );
161 bzimg->rm_kernel = real_to_user ( bzimg->rm_kernel_seg, 0 );
163 /* Allow space for the stack and heap */
164 bzimg->rm_memsz += BZI_STACK_SIZE;
165 bzimg->rm_heap = bzimg->rm_memsz;
167 /* Allow space for the command line */
168 bzimg->rm_cmdline = bzimg->rm_memsz;
169 bzimg->rm_memsz += BZI_CMDLINE_SIZE;
171 /* Calculate load address of protected-mode portion */
172 bzimg->pm_kernel = phys_to_user ( is_bzimage ? BZI_LOAD_HIGH_ADDR
173 : BZI_LOAD_LOW_ADDR );
175 /* Extract video mode */
176 bzimg->vid_mode = bzimg->bzhdr.vid_mode;
178 /* Extract memory limit */
179 bzimg->mem_limit = ( ( bzimg->version >= 0x0203 ) ?
180 bzimg->bzhdr.initrd_addr_max : BZI_INITRD_MAX );
182 /* Extract command line size */
183 bzimg->cmdline_size = ( ( bzimg->version >= 0x0206 ) ?
184 bzimg->bzhdr.cmdline_size : BZI_CMDLINE_SIZE );
186 DBGC ( image, "bzImage %p version %04x RM %#lx+%#zx PM %#lx+%#zx "
187 "cmdlen %zd\n", image, bzimg->version,
188 user_to_phys ( bzimg->rm_kernel, 0 ), bzimg->rm_filesz,
189 user_to_phys ( bzimg->pm_kernel, 0 ), bzimg->pm_sz,
190 bzimg->cmdline_size );
196 * Update bzImage header in loaded kernel
198 * @v image bzImage file
199 * @v bzimg bzImage context
200 * @v dst bzImage to update
202 static void bzimage_update_header ( struct image *image,
203 struct bzimage_context *bzimg,
206 /* Set loader type */
207 if ( bzimg->version >= 0x0200 )
208 bzimg->bzhdr.type_of_loader = BZI_LOADER_TYPE_IPXE;
210 /* Set heap end pointer */
211 if ( bzimg->version >= 0x0201 ) {
212 bzimg->bzhdr.heap_end_ptr = ( bzimg->rm_heap - 0x200 );
213 bzimg->bzhdr.loadflags |= BZI_CAN_USE_HEAP;
216 /* Set command line */
217 if ( bzimg->version >= 0x0202 ) {
218 bzimg->bzhdr.cmd_line_ptr = user_to_phys ( bzimg->rm_kernel,
221 bzimg->cmdline_magic.magic = BZI_CMDLINE_MAGIC;
222 bzimg->cmdline_magic.offset = bzimg->rm_cmdline;
223 if ( bzimg->version >= 0x0200 )
224 bzimg->bzhdr.setup_move_size = bzimg->rm_memsz;
228 bzimg->bzhdr.vid_mode = bzimg->vid_mode;
230 /* Set initrd address */
231 if ( bzimg->version >= 0x0200 ) {
232 bzimg->bzhdr.ramdisk_image = bzimg->ramdisk_image;
233 bzimg->bzhdr.ramdisk_size = bzimg->ramdisk_size;
236 /* Write out header structures */
237 copy_to_user ( dst, BZI_CMDLINE_OFFSET, &bzimg->cmdline_magic,
238 sizeof ( bzimg->cmdline_magic ) );
239 copy_to_user ( dst, BZI_HDR_OFFSET, &bzimg->bzhdr,
240 sizeof ( bzimg->bzhdr ) );
242 DBGC ( image, "bzImage %p vidmode %d\n", image, bzimg->vid_mode );
246 * Parse kernel command line for bootloader parameters
248 * @v image bzImage file
249 * @v bzimg bzImage context
250 * @v cmdline Kernel command line
251 * @ret rc Return status code
253 static int bzimage_parse_cmdline ( struct image *image,
254 struct bzimage_context *bzimg,
255 const char *cmdline ) {
259 /* Look for "vga=" */
260 if ( ( vga = strstr ( cmdline, "vga=" ) ) ) {
262 if ( strcmp ( vga, "normal" ) == 0 ) {
263 bzimg->vid_mode = BZI_VID_MODE_NORMAL;
264 } else if ( strcmp ( vga, "ext" ) == 0 ) {
265 bzimg->vid_mode = BZI_VID_MODE_EXT;
266 } else if ( strcmp ( vga, "ask" ) == 0 ) {
267 bzimg->vid_mode = BZI_VID_MODE_ASK;
269 bzimg->vid_mode = strtoul ( vga, &vga, 0 );
270 if ( *vga && ( *vga != ' ' ) ) {
271 DBGC ( image, "bzImage %p strange \"vga=\""
272 "terminator '%c'\n", image, *vga );
277 /* Look for "mem=" */
278 if ( ( mem = strstr ( cmdline, "mem=" ) ) ) {
280 bzimg->mem_limit = strtoul ( mem, &mem, 0 );
284 bzimg->mem_limit <<= 10;
287 bzimg->mem_limit <<= 10;
290 bzimg->mem_limit <<= 10;
296 DBGC ( image, "bzImage %p strange \"mem=\" "
297 "terminator '%c'\n", image, *mem );
300 bzimg->mem_limit -= 1;
309 * @v image bzImage image
310 * @v bzimg bzImage context
311 * @v cmdline Kernel command line
313 static void bzimage_set_cmdline ( struct image *image,
314 struct bzimage_context *bzimg,
315 const char *cmdline ) {
318 /* Copy command line down to real-mode portion */
319 cmdline_len = ( strlen ( cmdline ) + 1 );
320 if ( cmdline_len > bzimg->cmdline_size )
321 cmdline_len = bzimg->cmdline_size;
322 copy_to_user ( bzimg->rm_kernel, bzimg->rm_cmdline,
323 cmdline, cmdline_len );
324 DBGC ( image, "bzImage %p command line \"%s\"\n", image, cmdline );
328 * Parse standalone image command line for cpio parameters
330 * @v image bzImage file
331 * @v cpio CPIO header
332 * @v cmdline Command line
334 static void bzimage_parse_cpio_cmdline ( struct image *image,
335 struct cpio_header *cpio,
336 const char *cmdline ) {
341 /* Look for "mode=" */
342 if ( ( arg = strstr ( cmdline, "mode=" ) ) ) {
344 mode = strtoul ( arg, &end, 8 /* Octal for file mode */ );
345 if ( *end && ( *end != ' ' ) ) {
346 DBGC ( image, "bzImage %p strange \"mode=\""
347 "terminator '%c'\n", image, *end );
349 cpio_set_field ( cpio->c_mode, ( 0100000 | mode ) );
354 * Align initrd length
357 * @ret len Length rounded up to INITRD_ALIGN
359 static inline size_t bzimage_align ( size_t len ) {
361 return ( ( len + INITRD_ALIGN - 1 ) & ~( INITRD_ALIGN - 1 ) );
367 * @v image bzImage image
368 * @v initrd initrd image
369 * @v address Address at which to load, or UNULL
370 * @ret len Length of loaded image, excluding zero-padding
372 static size_t bzimage_load_initrd ( struct image *image,
373 struct image *initrd,
374 userptr_t address ) {
375 char *filename = initrd->cmdline;
377 struct cpio_header cpio;
382 /* Do not include kernel image itself as an initrd */
383 if ( initrd == image )
386 /* Create cpio header for non-prebuilt images */
387 if ( filename && filename[0] ) {
388 cmdline = strchr ( filename, ' ' );
389 name_len = ( ( cmdline ? ( ( size_t ) ( cmdline - filename ) )
390 : strlen ( filename ) ) + 1 /* NUL */ );
391 memset ( &cpio, '0', sizeof ( cpio ) );
392 memcpy ( cpio.c_magic, CPIO_MAGIC, sizeof ( cpio.c_magic ) );
393 cpio_set_field ( cpio.c_mode, 0100644 );
394 cpio_set_field ( cpio.c_nlink, 1 );
395 cpio_set_field ( cpio.c_filesize, initrd->len );
396 cpio_set_field ( cpio.c_namesize, name_len );
398 bzimage_parse_cpio_cmdline ( image, &cpio,
399 ( cmdline + 1 /* ' ' */ ));
401 offset = ( ( sizeof ( cpio ) + name_len + 0x03 ) & ~0x03 );
407 /* Copy in initrd image body (and cpio header if applicable) */
409 memmove_user ( address, offset, initrd->data, 0, initrd->len );
411 memset_user ( address, 0, 0, offset );
412 copy_to_user ( address, 0, &cpio, sizeof ( cpio ) );
413 copy_to_user ( address, sizeof ( cpio ), filename,
414 ( name_len - 1 /* NUL (or space) */ ) );
416 DBGC ( image, "bzImage %p initrd %p [%#08lx,%#08lx,%#08lx)"
417 "%s%s\n", image, initrd, user_to_phys ( address, 0 ),
418 user_to_phys ( address, offset ),
419 user_to_phys ( address, ( offset + initrd->len ) ),
420 ( filename ? " " : "" ), ( filename ? filename : "" ) );
421 DBGC2_MD5A ( image, user_to_phys ( address, offset ),
422 user_to_virt ( address, offset ), initrd->len );
424 offset += initrd->len;
426 /* Zero-pad to next INITRD_ALIGN boundary */
427 pad_len = ( ( -offset ) & ( INITRD_ALIGN - 1 ) );
429 memset_user ( address, offset, 0, pad_len );
435 * Check that initrds can be loaded
437 * @v image bzImage image
438 * @v bzimg bzImage context
439 * @ret rc Return status code
441 static int bzimage_check_initrds ( struct image *image,
442 struct bzimage_context *bzimg ) {
443 struct image *initrd;
448 /* Calculate total loaded length of initrds */
449 for_each_image ( initrd ) {
452 if ( initrd == image )
455 /* Calculate length */
456 len += bzimage_load_initrd ( image, initrd, UNULL );
457 len = bzimage_align ( len );
459 DBGC ( image, "bzImage %p initrd %p from [%#08lx,%#08lx)%s%s\n",
460 image, initrd, user_to_phys ( initrd->data, 0 ),
461 user_to_phys ( initrd->data, initrd->len ),
462 ( initrd->cmdline ? " " : "" ),
463 ( initrd->cmdline ? initrd->cmdline : "" ) );
464 DBGC2_MD5A ( image, user_to_phys ( initrd->data, 0 ),
465 user_to_virt ( initrd->data, 0 ), initrd->len );
468 /* Calculate lowest usable address */
469 bottom = userptr_add ( bzimg->pm_kernel, bzimg->pm_sz );
471 /* Check that total length fits within space available for
472 * reshuffling. This is a conservative check, since CPIO
473 * headers are not present during reshuffling, but this
474 * doesn't hurt and keeps the code simple.
476 if ( ( rc = initrd_reshuffle_check ( len, bottom ) ) != 0 ) {
477 DBGC ( image, "bzImage %p failed reshuffle check: %s\n",
478 image, strerror ( rc ) );
482 /* Check that total length fits within kernel's memory limit */
483 if ( user_to_phys ( bottom, len ) > bzimg->mem_limit ) {
484 DBGC ( image, "bzImage %p not enough space for initrds\n",
493 * Load initrds, if any
495 * @v image bzImage image
496 * @v bzimg bzImage context
498 static void bzimage_load_initrds ( struct image *image,
499 struct bzimage_context *bzimg ) {
500 struct image *initrd;
501 struct image *highest = NULL;
508 /* Reshuffle initrds into desired order */
509 initrd_reshuffle ( userptr_add ( bzimg->pm_kernel, bzimg->pm_sz ) );
511 /* Find highest initrd */
512 for_each_image ( initrd ) {
513 if ( ( highest == NULL ) ||
514 ( userptr_sub ( initrd->data, highest->data ) > 0 ) ) {
519 /* Do nothing if there are no initrds */
523 /* Find highest usable address */
524 top = userptr_add ( highest->data, bzimage_align ( highest->len ) );
525 if ( user_to_phys ( top, 0 ) > bzimg->mem_limit )
526 top = phys_to_user ( bzimg->mem_limit );
527 DBGC ( image, "bzImage %p loading initrds from %#08lx downwards\n",
528 image, user_to_phys ( top, 0 ) );
530 /* Load initrds in order */
531 for_each_image ( initrd ) {
533 /* Calculate cumulative length of following
534 * initrds (including padding).
537 for_each_image ( other ) {
538 if ( other == initrd )
540 offset += bzimage_load_initrd ( image, other, UNULL );
541 offset = bzimage_align ( offset );
544 /* Load initrd at this address */
545 dest = userptr_add ( top, -offset );
546 len = bzimage_load_initrd ( image, initrd, dest );
548 /* Record initrd location */
549 if ( ! bzimg->ramdisk_image )
550 bzimg->ramdisk_image = user_to_phys ( dest, 0 );
551 bzimg->ramdisk_size = ( user_to_phys ( dest, len ) -
552 bzimg->ramdisk_image );
554 DBGC ( image, "bzImage %p initrds at [%#08lx,%#08lx)\n",
555 image, bzimg->ramdisk_image,
556 ( bzimg->ramdisk_image + bzimg->ramdisk_size ) );
560 * Execute bzImage image
562 * @v image bzImage image
563 * @ret rc Return status code
565 static int bzimage_exec ( struct image *image ) {
566 struct bzimage_context bzimg;
567 const char *cmdline = ( image->cmdline ? image->cmdline : "" );
570 /* Read and parse header from image */
571 if ( ( rc = bzimage_parse_header ( image, &bzimg,
572 image->data ) ) != 0 )
575 /* Prepare segments */
576 if ( ( rc = prep_segment ( bzimg.rm_kernel, bzimg.rm_filesz,
577 bzimg.rm_memsz ) ) != 0 ) {
578 DBGC ( image, "bzImage %p could not prepare RM segment: %s\n",
579 image, strerror ( rc ) );
582 if ( ( rc = prep_segment ( bzimg.pm_kernel, bzimg.pm_sz,
583 bzimg.pm_sz ) ) != 0 ) {
584 DBGC ( image, "bzImage %p could not prepare PM segment: %s\n",
585 image, strerror ( rc ) );
589 /* Parse command line for bootloader parameters */
590 if ( ( rc = bzimage_parse_cmdline ( image, &bzimg, cmdline ) ) != 0)
593 /* Check that initrds can be loaded */
594 if ( ( rc = bzimage_check_initrds ( image, &bzimg ) ) != 0 )
597 /* Remove kernel from image list (without invalidating image pointer) */
598 unregister_image ( image_get ( image ) );
601 memcpy_user ( bzimg.rm_kernel, 0, image->data,
602 0, bzimg.rm_filesz );
603 memcpy_user ( bzimg.pm_kernel, 0, image->data,
604 bzimg.rm_filesz, bzimg.pm_sz );
606 /* Store command line */
607 bzimage_set_cmdline ( image, &bzimg, cmdline );
609 /* Prepare for exiting. Must do this before loading initrds,
610 * since loading the initrds will corrupt the external heap.
614 /* Load any initrds */
615 bzimage_load_initrds ( image, &bzimg );
617 /* Update kernel header */
618 bzimage_update_header ( image, &bzimg, bzimg.rm_kernel );
620 DBGC ( image, "bzImage %p jumping to RM kernel at %04x:0000 "
621 "(stack %04x:%04zx)\n", image, ( bzimg.rm_kernel_seg + 0x20 ),
622 bzimg.rm_kernel_seg, bzimg.rm_heap );
624 /* Jump to the kernel */
625 __asm__ __volatile__ ( REAL_CODE ( "movw %w0, %%ds\n\t"
634 : : "r" ( bzimg.rm_kernel_seg ),
635 "r" ( bzimg.rm_heap ),
636 "r" ( bzimg.rm_kernel_seg + 0x20 ) );
638 /* There is no way for the image to return, since we provide
643 return -ECANCELED; /* -EIMPOSSIBLE */
647 * Probe bzImage image
649 * @v image bzImage file
650 * @ret rc Return status code
652 int bzimage_probe ( struct image *image ) {
653 struct bzimage_context bzimg;
656 /* Read and parse header from image */
657 if ( ( rc = bzimage_parse_header ( image, &bzimg,
658 image->data ) ) != 0 )
664 /** Linux bzImage image type */
665 struct image_type bzimage_image_type __image_type ( PROBE_NORMAL ) = {
667 .probe = bzimage_probe,
668 .exec = bzimage_exec,