2 * This file is part of the coreboot project.
4 * Copyright (C) 2008 coresystems GmbH
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License as
8 * published by the Free Software Foundation; version 2 of
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston,
22 /* NOTE: This handler assumes the SMM window goes from 0xa0000
23 * to 0xaffff. In fact, at least on Intel Core CPUs (i945 chipset)
24 * the SMM window is 128K big, covering 0xa0000 to 0xbffff.
25 * So there is a lot of potential for growth in here. Let's stick
26 * to 64k if we can though.
30 * +--------------------------------+ 0xaffff
31 * | Save State Map Node 0 |
32 * | Save State Map Node 1 |
33 * | Save State Map Node 2 |
34 * | Save State Map Node 3 |
36 * +--------------------------------+ 0xaf000
40 * +--------------------------------+ 0xa8400
41 * | SMM Entry Node 0 (+ stack) |
42 * +--------------------------------+ 0xa8000
43 * | SMM Entry Node 1 (+ stack) |
44 * | SMM Entry Node 2 (+ stack) |
45 * | SMM Entry Node 3 (+ stack) |
47 * +--------------------------------+ 0xa7400
51 * +--------------------------------+ 0xa0000
55 #define LAPIC_ID 0xfee00020
57 /* SMM_HANDLER_OFFSET is the 16bit offset within the ASEG
58 * at which smm_handler_start lives. At the moment the handler
59 * lives right at 0xa0000, so the offset is 0.
62 #define SMM_HANDLER_OFFSET 0x0000
64 /* initially SMM is some sort of real mode. Let gcc know
65 * how to treat the SMM handler stub
68 .section ".handler", "a", @progbits
73 * SMM code to enable protected mode and jump to the
74 * C-written function void smi_handler(u32 smm_revision)
76 * All the bad magic is not all that bad after all.
79 movw $(smm_gdtptr16 - smm_handler_start + SMM_HANDLER_OFFSET), %bx
83 andl $0x7FFAFFD1, %eax /* PG,AM,WP,NE,TS,EM,MP = 0 */
84 orl $0x60000001, %eax /* CD, NW, PE = 1 */
87 /* Enable protected mode */
88 data32 ljmp $0x08, $1f
92 /* flush the cache after disabling it */
95 /* Use flat data segment */
103 /* Get this CPU's LAPIC ID */
108 /* calculate stack offset by multiplying the APIC ID
109 * by 1024 (0x400), and save that offset in ebp.
114 /* We put the stack for each core right above
115 * its SMM entry point. Core 0 starts at 0xa8000,
116 * we spare 0x10 bytes for the jump to be sure.
119 subl %ecx, %eax /* subtract offset, see above */
120 movl %eax, %ebx /* Save bottom of stack in ebx */
122 #define SMM_STACK_SIZE (0x400 - 0x10)
126 movl $(SMM_STACK_SIZE >> 2), %ecx
131 addl $SMM_STACK_SIZE, %ebx
134 /* Get SMM revision */
135 movl $0xa8000 + 0x7efc, %ebx /* core 0 address */
136 subl %ebp, %ebx /* subtract core X offset */
140 /* Call 32bit C handler */
143 /* To return, just do rsm. It will "clean up" protected mode */
151 .word smm_gdt_end - smm_gdt - 1
152 .long smm_gdt - smm_handler_start + 0xa0000 + SMM_HANDLER_OFFSET
157 /* The first GDT entry can not be used. Keep it zero */
158 .long 0x00000000, 0x00000000
160 /* gdt selector 0x08, flat code segment */
162 .byte 0x00, 0x9b, 0xcf, 0x00 /* G=1 and 0x0f, 4GB limit */
164 /* gdt selector 0x10, flat data segment */
166 .byte 0x00, 0x93, 0xcf, 0x00
171 .section ".jumptable", "a", @progbits
173 /* This is the SMM jump table. All cores use the same SMM handler
174 * for simplicity. But SMM Entry needs to be different due to the
175 * save state area. The jump table makes sure all CPUs jump into the
176 * real handler on SMM entry.
179 /* This code currently supports up to 4 CPU cores. If more than 4 CPU cores
180 * shall be used, below table has to be updated, as well as smm.ld
183 /* GNU AS/LD will always generate code that assumes CS is 0xa000. In reality
184 * CS will be set to SMM_BASE[19:4] though. Knowing that the smm handler is the
185 * first thing in the ASEG, we do a far jump here, to set CS to 0xa000.
191 ljmp $0xa000, $SMM_HANDLER_OFFSET
194 ljmp $0xa000, $SMM_HANDLER_OFFSET
197 ljmp $0xa000, $SMM_HANDLER_OFFSET
200 ljmp $0xa000, $SMM_HANDLER_OFFSET