WO2025112463A1 - 应用于arm服务器的arm安全固件配置方法及装置 - Google Patents

应用于arm服务器的arm安全固件配置方法及装置 Download PDF

Info

Publication number
WO2025112463A1
WO2025112463A1 PCT/CN2024/099921 CN2024099921W WO2025112463A1 WO 2025112463 A1 WO2025112463 A1 WO 2025112463A1 CN 2024099921 W CN2024099921 W CN 2024099921W WO 2025112463 A1 WO2025112463 A1 WO 2025112463A1
Authority
WO
WIPO (PCT)
Prior art keywords
pci
arm
firmware
server
security firmware
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2024/099921
Other languages
English (en)
French (fr)
Inventor
孙秀强
韩国志
刘宝俊
艾山彬
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Suzhou Metabrain Intelligent Technology Co Ltd
Original Assignee
Suzhou Metabrain Intelligent Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Suzhou Metabrain Intelligent Technology Co Ltd filed Critical Suzhou Metabrain Intelligent Technology Co Ltd
Priority to US19/144,055 priority Critical patent/US20260119436A1/en
Publication of WO2025112463A1 publication Critical patent/WO2025112463A1/zh
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/004Error avoidance
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/4401Bootstrapping
    • G06F9/4403Processor initialisation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/4401Bootstrapping
    • G06F9/4406Loading of operating system
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/4401Bootstrapping
    • G06F9/4411Configuring for operating with peripheral devices; Loading of device drivers

Definitions

  • the present application relates to the field of chip technology, and in particular to an ARM security firmware configuration method and device applied to an ARM server.
  • ARM Advanced RISC Machines
  • AI Artificial Intelligence
  • T4 cards T4 cards
  • DPU Graphics Processing Unit cards
  • customers are accustomed to installing the hard disk of the DPU device as a virtual cloud disk.
  • all PCI peripheral devices of the ARM server are initialized and used in the virtual cloud disk system of the DPU. Because the DPU can support the installation and use of multiple virtual cloud disks, the PCI peripheral devices in the ARM server can be used by different cloud disk systems at any time.
  • the PCI device such as the T4 card needs to be restarted. After the T4 card is restarted, another cloud disk system can use this physical T4 card normally.
  • the embodiment of the present application provides an ARM security firmware configuration method and device applied to an ARM server to solve the problem in the related art that when the ARM server is restarted under the cloud disk system, a crash occurs, resulting in the T4 card under the cloud disk system being unable to restart and the entire ARM server also crashing and unable to be used normally.
  • an embodiment of the present application provides an ARM security firmware configuration method applied to an ARM server, the method comprising:
  • the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
  • the ARM security firmware of the ARM server is called to configure the space registers of the PCI link bridge and the N layers of PCI devices under the PCI link bridge, including:
  • the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results;
  • space registers are configured for the N levels of PCI devices under the PCI link bridge.
  • the PCI device configuration space registers of N levels under the PCI link bridge include:
  • the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results;
  • calling the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs also includes:
  • the PCI link bridge and N-level PCI devices are scanned according to the splitting status of the PCI link bridge.
  • the PCI device configuration space registers of N levels under the PCI link bridge include:
  • the method further includes:
  • the space registers of the N levels of PCI devices subsequently connected are configured in the reserved register configuration space.
  • AER error identification information of all CPUs of the ARM server is added, including:
  • AER error identification information of all PCI devices under the link bridges under all CPUs is added, including:
  • the method further includes:
  • the UEFI firmware of the ARM server is started, and the virtual cloud disk system is started and loaded.
  • Register configuration and AER error identification information addition are performed on the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge in turn.
  • the UEFI firmware of the ARM server after starting the UEFI firmware of the ARM server and starting to load the virtual cloud disk system, it also includes:
  • the PCI device does not experience a restart or downtime problem, and the virtual cloud disk operating system does not experience a restart or downtime problem, it is determined that the ARM server has not experienced a downtime phenomenon.
  • the method further includes:
  • a downtime alarm message is output.
  • the ARM server includes at least one CPU.
  • an embodiment of the present application provides an ARM security firmware configuration device applied to an ARM server, the device comprising:
  • a register configuration module is used to call the ARM security firmware of the ARM server to configure space registers for the PCI link bridge and N layers of PCI devices under the PCI link bridge.
  • the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
  • the AER information adding module is used to add the AER error identification information of all CPUs of the ARM server in the ARM security firmware.
  • the register configuration module includes:
  • a scanning result acquisition unit is used to call the ARM security firmware during the loading and startup process of the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results;
  • the space register configuration unit includes:
  • a PCI device initialization subunit is used to initialize N layers of PCI devices under the PCI link bridge;
  • the space register configuration subunit is used to configure the space registers of the N layers of PCI devices under the PCI link bridge.
  • the apparatus comprises:
  • An ARM security firmware loading module used to load the ARM security firmware in response to the ARM server being started and the BIOS being loaded successfully;
  • Secure boot verification module used to perform secure boot verification on ARM security firmware
  • the memory initialization module is used to initialize the memory of the ARM security firmware in response to the success of the secure boot verification of the ARM security firmware.
  • the scanning result acquisition unit includes:
  • a scanning result acquisition subunit is used to call the ARM security firmware in response to the completion of the memory initialization of the ARM security firmware, scan the PCI link bridge and N-level PCI devices of all CPUs, and obtain the scanning result;
  • the PCI configuration space configuration subunit is used to configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
  • the register configuration subunit is used to configure space registers for N layers of PCI devices under the PCI link bridge in the PCI configuration space.
  • the apparatus further comprises:
  • the configuration space reservation module is used to reserve the register configuration space corresponding to the PCI link bridge in the PCI configuration space when the scanning result indicates that the level of the PCI device under the PCI link bridge is less than N.
  • the AER information adding module includes:
  • a PCI device acquisition unit is used to acquire link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs;
  • the AER information adding unit is used to add the AER error identification information of all PCI devices under the link bridges under all CPUs in the ARM security firmware.
  • the AER information adding unit includes:
  • a configuration information acquisition subunit is used to acquire the AER configuration information of the link bridges under all CPUs
  • the AER information adding subunit is used to initialize all PCI devices under the link bridges under all CPUs in the ARM security firmware based on the AER configuration information to add AER error identification information.
  • the apparatus further comprises:
  • the configuration completion detection module is used to detect whether the PCI devices under all PCI link bridges under the ARM security firmware are configured;
  • the virtual cloud disk system loading module is used to start the UEFI firmware of the ARM server and start loading the virtual cloud disk system in response to the configuration of all PCI devices under the PCI link bridge.
  • the apparatus further comprises:
  • An unconfigured device acquisition module used for acquiring the PCI devices under the unconfigured PCI link bridge in response to the presence of an unconfigured PCI link bridge among the PCI devices under all the PCI link bridges;
  • the PCI device configuration module is used to sequentially configure registers of an unconfigured PCI link bridge and PCI devices under the unconfigured PCI link bridge and add AER error identification information.
  • the apparatus further comprises:
  • a downtime determination module is used to determine whether the ARM server has a downtime phenomenon when the PCI device is restarted and the virtual cloud disk system is restarted;
  • the configuration success determination module is used to determine that the ARM security firmware is configured successfully in response to the ARM server not experiencing a downtime phenomenon.
  • an electronic device including:
  • an embodiment of the present application provides a computer non-volatile readable storage medium.
  • the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute any of the above-mentioned ARM security firmware configuration methods applied to an ARM server.
  • the PCI link bridge and the PCI device configuration space registers of N layers under the PCI link bridge are configured by calling the ARM security firmware of the ARM server, the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
  • the ARM security firmware the AER error identification information of all CPUs of the ARM server is added.
  • the embodiment of the present application increases the scanning level of the PCI link bridge and the PCI device in the ATF firmware and configures the register settings.
  • each PCI link bridge and PCI device of all CPUs needs to add the AER error information recognition function in the ATF, which can effectively solve the problem of restarting under the DPU virtual cloud disk system or restarting the PCI device under the DPU virtual cloud disk system.
  • FIG1 is a flowchart of a method for configuring an ARM security firmware applied to an ARM server according to an embodiment of the present application
  • FIG2 is a flowchart of a method for configuring a space register according to an embodiment of the present application
  • FIG3 is a flowchart of another method for configuring a space register according to an embodiment of the present application.
  • FIG4 is a flowchart of the steps of an ARM secure firmware startup method provided in an embodiment of the present application.
  • FIG5 is a flowchart of a method for configuring a PCI configuration space according to an embodiment of the present application
  • FIG6 is a flowchart of a method for adding AER error identification information provided by an embodiment of the present application.
  • FIG7 is a flowchart of another method for adding AER error identification information provided by an embodiment of the present application.
  • FIG8 is a flowchart of a method for configuring a PCI device according to an embodiment of the present application.
  • FIG9 is a flowchart of a method for determining successful configuration of an ARM secure firmware according to an embodiment of the present application
  • FIG. 10 is a flowchart of restarting a PCI device under an ARM server support system provided in an embodiment of the present application
  • FIG11 is a schematic diagram of a hardware architecture provided in an embodiment of the present application.
  • FIG12 is a schematic diagram of the structure of an ARM security firmware configuration device applied to an ARM server provided in an embodiment of the present application;
  • FIG. 13 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
  • ARM architecture processor firmware can be divided into two parts, one is the ATF (Arm Trusted Firmware) firmware unique to the ARM architecture, and the other is the traditional UEFI firmware.
  • UEFI firmware is required to be supported by any architecture processor and has unified various standard protocols, while ATF firmware is unique to the ARM architecture.
  • ATF firmware involves ARM's secure boot verification, memory initialization, PCI (Peripheral Component Interconnect) link initialization and hot plugging and other basic functions of PCI devices.
  • PCI Peripheral Component Interconnect
  • the initialization of the PCI link involves one level, that is, the root bridge of the PCI link of the CPU (Central Processing Unit) and the PCI devices under the root bridge are initialized, and in the DPU (Data Processing Unit) of the ARM server
  • the T4 card is a second-level PCI device under the PCI device in the DPU virtual cloud disk system, rather than a first-level PCI device under the PCI link bridge in the ARM system. This results in no downtime when restarting the T4 card in the non-DPU virtual cloud disk system in the ARM server system, but a downtime problem occurs when restarting the T4 card in the DPU virtual cloud disk system in the ARM system.
  • ATF needs to be enabled for multi-level PCI device initialization and register setting.
  • the AER identification function of the PCI device needs to be added. If it is not added, an AER (Advanced Error Reporting) error will be generated, causing the system to continue to crash.
  • the ARM server supports both single-channel and dual-channel startup, if only the PCI AER error identification information of the single channel, i.e., CPU0, is added to ATF, the restart of the T4 card device will still report an error when the single-channel or dual-channel startup is used. Therefore, it is necessary to add the PCI AER error identification information setting for dual-channel startup in ATF. On this basis, after single-channel or dual-channel startup, the restart setting of the T4 card in the DPU virtual cloud disk system will not cause the AER crash problem. Therefore, the technical problem of the crash of the PCI device when restarting in the ARM server DPU virtual cloud disk system can be solved based on the above two adjustments in the ATF firmware.
  • the ARM security firmware configuration method applied to the ARM server may include: step 101 and step 102.
  • Step 101 Call the ARM security firmware of the ARM server to configure space registers for the PCI link bridge and N levels of PCI devices under the PCI link bridge.
  • the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
  • the embodiments of the present application can be applied to increase the scanning levels of the CPU's PCI link and PCI device to multiple levels in the ARM security firmware part, and add the AER error information recognition function to the PCI link bridges and PCI devices of all CPUs to solve the scenario of restarting the PCI device under the system or the crash problem when the system restarts.
  • the embodiments of the present application can be applied to an ARM server, that is, the execution subject is an ARM server, wherein the ARM server may include: a BIOS (Basic Input Output System), in which an ARM security firmware (that is, ATF (firmware) and UEFI firmware are arranged.
  • BIOS Basic Input Output System
  • ATF firmware
  • UEFI User Data Management Function
  • the BIOS can be loaded first, and then the ARM security firmware can be loaded.
  • the PCI link bridge and the N-level PCI device configuration space registers under the PCI link bridge can be configured by the ARM security firmware.
  • N is a positive integer greater than or equal to 3.
  • the ARM security firmware can be called to scan the PCI link bridge and multi-level PCI devices of all CPUs (i.e., all CPUs in the ARM server, which can be a single CPU or multiple CPUs), and perform space register configuration on the scanned multi-level PCI devices.
  • all CPUs i.e., all CPUs in the ARM server, which can be a single CPU or multiple CPUs
  • space register configuration on the scanned multi-level PCI devices.
  • the method for configuring a space register may include: step 201 and step 202 .
  • Step 201 During the loading and starting process of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results.
  • ARM security firmware can be loaded, and during the loading and startup process of ARM security firmware, ARM security firmware is called to scan PCI link bridges and N-level PCI devices of all CPUs to obtain scanning results. Specifically, ARM security firmware can scan all link bridges under the CPU and N-level PCI devices under each link bridge to obtain scanning results.
  • the ARM security firmware when performing a security scan, may be loaded first and a security boot check and memory initialization may be performed before the scan is performed.
  • the implementation process may be described in detail as follows in conjunction with FIG.
  • the method for configuring a PCI configuration space may include: step 401 , step 402 , and step 403 .
  • Step 401 Load ARM security firmware.
  • the ARM security firmware may be loaded.
  • step 402 is executed.
  • Step 402 Perform a secure boot check on the ARM security firmware.
  • the ARM security firmware can be checked for secure booting to check whether the ARM security firmware is securely booted. If the ARM security firmware is not securely booted, the process ends. If the ARM security firmware is securely booted, step 403 is executed.
  • Step 403 In response to the ARM security firmware security boot verification being successful, the ARM security firmware is memory initialized.
  • the memory of the ARM secure firmware can be initialized to configure the memory space for the ARM secure firmware to facilitate the subsequent configuration of the space registers.
  • the ARM security firmware can be called to execute the scanning process.
  • the PCI configuration space corresponding to the PCI link bridge can be configured to provide memory for the subsequent configuration of the space register.
  • the method for configuring a PCI configuration space may include: step 501 and step 502 .
  • Step 501 In response to the completion of the ARM security firmware memory initialization, the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scan results.
  • the ARM security firmware can be called to scan the PCI link bridge and N levels of PCI devices of all CPUs to obtain the scanning results.
  • Step 502 Configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
  • a PCI configuration space corresponding to the PCI link bridge may be configured in the initial memory, and the PCI configuration space may be used to configure space registers of subsequent PCI devices.
  • step 202 After calling the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs and obtaining the scan results, step 202 is executed.
  • the space registers of the N-level PCI devices under the PCI link bridge can be configured. Specifically, the N-level PCI devices under the PCI link bridge can be initialized and the space registers can be configured.
  • the method for configuring a control register may include: step 301 and step 302 .
  • Step 301 Initialize N layers of PCI devices under the PCI link bridge.
  • the N levels of PCI devices under the PCI link bridge may be initialized.
  • Step 302 configure space registers for N levels of PCI devices under the PCI link bridge.
  • the space registers of the N-level PCI devices under the PCI link bridge can be configured.
  • the initialization process of the device can write the space register into the corresponding space.
  • This application can solve the problem of PCI device crash when restarting in a DPU virtual cloud disk system under an ARM server system by performing multi-level PCI device initialization and register setting enablement on ATF.
  • the space registers for the N levels of PCI devices under the PCI link bridge can be configured respectively in the PCI configuration space.
  • the register configuration space corresponding to the PCI link bridge is reserved in the PCI configuration space.
  • step 102 is executed.
  • Step 102 Add AER error identification information of all CPUs of the ARM server in the ARM security firmware.
  • the AER error identification information of all CPUs of the ARM server can be added in the ARM security firmware.
  • the embodiment of the present application adds AER error identification information to all CPUs of the ARM server. On this basis, after single-channel or dual-channel startup, the restart setting such as the T4 card in the DPU virtual cloud disk system will not cause AER downtime problems.
  • corresponding AER error identification information can be added to all PCI devices under link bridges under all CPUs in the ARM security firmware.
  • the implementation process can be described in detail as follows in conjunction with FIG.
  • the method for adding AER error identification information may include: step 601 and step 602 .
  • Step 601 Acquire the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs.
  • the link bridges under all CPUs of the ARM server can be obtained.
  • the ARM server may have only one CPU, two CPUs, or four CPUs, etc. Specifically, the number of CPUs in the ARM server may be determined according to actual conditions, and this embodiment does not impose any limitation on this.
  • the link bridge under each CPU may be scanned for PCI devices to obtain all PCI devices under the link bridges under all CPUs.
  • step 602 After acquiring the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs, step 602 is executed.
  • Step 602 Add AER error identification information of all PCI devices under link bridges under all CPUs in the ARM security firmware.
  • AER error identification information is added for both single-channel and dual-channel servers, thereby solving the problem of AER downtime when restarting the T4 card in the DPU virtual cloud disk system after the ARM server is started.
  • the AER configuration information of the link bridges under all CPUs can be obtained, and the AER error identification information can be added based on the AER configuration information.
  • the implementation process can be described in detail as follows in conjunction with FIG.
  • the method for adding AER error identification information may include: step 701 and step 702 .
  • the AER configuration information of the link bridges under all CPUs can be obtained.
  • Step 702 In the ARM security firmware, based on the AER configuration information, all PCI devices under the link bridges under all CPUs are initialized to add AER error identification information.
  • all PCI devices under the link bridges under all CPUs can be initialized in the ARM security firmware based on the AER configuration information to add AER error identification information.
  • the embodiment of the present application adds AER error identification information to all PCI devices under the link bridge in combination with AER configuration information, thereby satisfying the function of restarting the normal use of PCI devices in a multi-level system.
  • the method for configuring a PCI device may include: step 801 and step 802 .
  • Step 801 In response to the existence of an unconfigured PCI link bridge among the PCI devices under all PCI link bridges, the PCI devices under the unconfigured PCI link bridge are acquired.
  • the PCI devices under the unconfigured PCI link bridge can be acquired.
  • Step 802 sequentially perform register configuration and add AER error identification information to the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge.
  • register configuration and AER error identification information addition can be performed on the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge in sequence.
  • the embodiment of the present application can avoid the omission of PCI link bridges or PCI devices by detecting unconfigured PCI link bridges, which may cause the PCI devices under the PCI link bridge to crash due to the failure to perform the above configuration.
  • the method for determining configuration completion may include: step 901 and step 902 .
  • Step 901 When the PCI device and the virtual cloud disk system are restarted, determine whether the ARM server is down.
  • the PCI device after starting to load the virtual cloud disk system, the PCI device can be restarted under the ARM server, and the virtual cloud disk system can be restarted to detect whether the ARM server is down. Specifically, after the DPU virtual cloud disk operating system, the PCI device T4 card is restarted through the system PCI command, and the DPU virtual cloud disk operating system is restarted through the system command. At the same time, whether the ARM server is down is detected.
  • Step 902 In response to the ARM server not experiencing a downtime phenomenon, it is determined that the ARM security firmware is configured successfully.
  • a crash alarm message can be output to prompt the operation and maintenance personnel to find the cause of the crash.
  • FIG. 10 a flowchart of restarting a PCI device in an ARM server support system provided by an embodiment of the present application is shown. As shown in Figure 10, the process may include the following steps:
  • Step 1 The ARM server (in this example, an ARM server with a dual-boot mechanism) is powered on, the BIOS firmware is loaded, and the ATF image firmware is loaded first.
  • Step 2 During the ATF loading and booting process, after the secure boot and memory initialization are completed, the PCI link initialization part is performed, and the PCI link bridge and PCI devices are scanned and initialized according to the splitting of the PCI link bridge. At this time, ATF changes the scheme of scanning and initializing the PCI link bridge and one-level PCI devices to the scheme of scanning the PCI link and multiple-level PCI devices. If there are multiple levels of devices in the current PCI link, the multiple-level PCI device scan and initialization are performed. If there are no multiple levels of devices in the current PCI link, the function of multi-level scanning PCI device space is turned on and reserved, that is, the register configuration space is reserved.
  • Step 3 After completing step 2 above, the AER table of the PCI link bridge (including the AER configuration information of the PCI link bridge) can be initialized. Failure to initialize the AER table will cause the system to crash when restarting the PCI device.
  • the initialization table needs to initialize the PCI links and PCI devices of both CPUs. If only the PCI link of any one CPU is initialized, the system will crash when restarting the PCI device. Initializing the AER table requires setting the AER information of the PCI link and multi-level PCI devices to meet the function of restarting the PCI device for normal use in a multi-level system.
  • Step 4 After the ARM server firmware has initialized the ATF firmware, start the UEFI firmware, continue to start and enter the DPU virtual cloud disk operating system.
  • Step 5 After the DPU virtual cloud disk operating system is turned on, the PCI device T4 card does not experience a restart downtime problem by restarting the system through the PCI command. Alternatively, restarting the DPU virtual cloud disk operating system through the system command also does not experience a restart downtime problem. Therefore, the restart PCI device downtime problem is completely solved.
  • Step 6 when AER error identification information is added to the PCI link bridge and multi-level PCI devices of only one of the two CPUs, after starting and loading the virtual cloud disk system, restarting the PCI device T4 card through the system PCI command will cause a restart downtime problem, or restarting the DPU virtual cloud disk operating system through the system command will cause a restart downtime problem.
  • the root cause of the problem is located to ATF, which needs to support multi-level scanning of PCI devices and configure management registers.
  • the downtime caused by the AER error can be solved by adding the AER error information recognition function to the PCI link bridge and PCI device of CPU0 and PCI in ATF.
  • the hardware architecture of this embodiment may include: an ARM server and an OS (Operating System) operating system, as well as BIOS under the ARM server, UTF firmware and UEFI firmware under the BIOS.
  • OS Operating System
  • the ARM server can be started first, and after the ARM server is started, the BIOS image can be loaded. Then, the ATF image firmware can be loaded. During the ATF firmware startup process, a secure boot check can be performed, and after completion, the memory is initialized.
  • the PCI link bridge and PCI devices can be initialized. At this time, the PCI link bridge and PCI devices can be scanned at multiple levels, and the PCI configuration space can be configured.
  • the scanning result it is determined whether there are multi-level PCI devices under the PCI link bridge. If there are no multi-level PCI devices under the PCI link bridge, the space for the PCI device configuration space register, i.e., the register configuration space, is reserved. If there are multi-level PCI devices under the PCI link bridge, the multi-level PCI device configuration space register can be configured.
  • AER error identification information to the multi-level PCI devices of the PCI link bridge of CPU0 and CPU1. If you choose to add AER error identification information to the multi-level PCI devices of the PCI link bridge of CPU0 and CPU1, the AER table is initialized to set the AER information of the PCI link and the multi-level PCI devices.
  • the embodiment of the present application is aimed at the firmware division of ARM architecture servers and the specific practical application of ARM servers.
  • the PCI link bridge and PCI device are scanned at multiple levels in ATF and the management registers are configured.
  • each PCI link bridge and PCI device of CPU0 and CPU1 is added with an AER error information recognition function. If it is not added, a secondary downtime will occur during the restart. Therefore, this solution can solve the two downtime problems that occur when the system is restarted and the PCI device is restarted.
  • the ARM security firmware configuration method applied to the ARM server provided in the embodiment of the present application is implemented by calling the ARM server
  • the ARM security firmware of the server configures the space registers of the PCI link bridge and the PCI devices of N levels under the PCI link bridge.
  • the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
  • the AER error identification information of all CPUs of the ARM server is added.
  • the embodiment of the present application increases the scanning level of the PCI link bridge and PCI devices in the ATF firmware and configures the register settings.
  • the ARM security firmware configuration device 1200 applied to an ARM server may include the following modules:
  • the register configuration module 1210 is used to call the ARM security firmware of the ARM server to configure the space registers of the PCI link bridge and the N-level PCI devices under the PCI link bridge, where the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3;
  • the AER information adding module 1220 is used to add the AER error identification information of all CPUs of the ARM server in the ARM security firmware.
  • the register configuration module includes:
  • a scanning result acquisition unit is used to call the ARM security firmware during the loading and startup process of the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results;
  • the space register configuration unit is used to configure space registers for the N-level PCI devices under the PCI link bridge when the scanning result indicates that there are N-level PCI devices under the PCI link bridge.
  • the space register configuration unit includes:
  • a PCI device initialization subunit is used to initialize N layers of PCI devices under the PCI link bridge;
  • the space register configuration subunit is used to configure the space registers of the N layers of PCI devices under the PCI link bridge.
  • the apparatus comprises:
  • An ARM security firmware loading module used to load the ARM security firmware in response to the ARM server being started and the BIOS being loaded successfully;
  • Secure boot verification module used to perform secure boot verification on ARM security firmware
  • the memory initialization module is used to initialize the memory of the ARM security firmware in response to the success of the secure boot verification of the ARM security firmware.
  • the scanning result acquisition unit includes:
  • a scanning result acquisition subunit is used to call the ARM security firmware in response to the completion of the memory initialization of the ARM security firmware, scan the PCI link bridge and N-level PCI devices of all CPUs, and obtain the scanning result;
  • the PCI configuration space configuration subunit is used to configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
  • the space register configuration unit includes:
  • the register configuration subunit is used to configure space registers for N layers of PCI devices under the PCI link bridge in the PCI configuration space.
  • the configuration space reservation module is used to reserve the register configuration space corresponding to the PCI link bridge in the PCI configuration space when the scanning result indicates that the level of the PCI device under the PCI link bridge is less than N.
  • the AER information adding module includes:
  • a PCI device acquisition unit is used to acquire link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs;
  • the AER information adding unit is used to add the AER error identification information of all PCI devices under the link bridges under all CPUs in the ARM security firmware.
  • the AER information adding unit includes:
  • a configuration information acquisition subunit is used to acquire the AER configuration information of the link bridges under all CPUs
  • the AER information adding subunit is used to initialize all PCI devices under the link bridges under all CPUs in the ARM security firmware based on the AER configuration information to add AER error identification information.
  • the apparatus further comprises:
  • the configuration completion detection module is used to detect whether the PCI devices under all PCI link bridges under the ARM security firmware are configured;
  • the virtual cloud disk system loading module is used to start the UEFI firmware of the ARM server and start loading the virtual cloud disk system in response to the configuration of all PCI devices under the PCI link bridge.
  • the apparatus further comprises:
  • An unconfigured device acquisition module used for acquiring the PCI devices under the unconfigured PCI link bridge in response to the presence of an unconfigured PCI link bridge among the PCI devices under all the PCI link bridges;
  • the PCI device configuration module is used to sequentially configure registers of an unconfigured PCI link bridge and PCI devices under the unconfigured PCI link bridge and add AER error identification information.
  • the apparatus further comprises:
  • a downtime determination module is used to determine whether the ARM server has a downtime phenomenon when the PCI device is restarted and the virtual cloud disk system is restarted;
  • the configuration success determination module is used to determine that the ARM security firmware is configured successfully in response to the ARM server not experiencing a downtime phenomenon.
  • the ARM security firmware configuration device applied to the ARM server configureds the space registers of the PCI link bridge and the PCI devices of N levels under the PCI link bridge by calling the ARM security firmware of the ARM server.
  • the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
  • the AER error identification information of all CPUs of the ARM server is added.
  • the embodiment of the present application increases the scanning level of the PCI link bridge and the PCI device in the ATF firmware and configures the register settings.
  • an embodiment of the present application also provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the above-mentioned ARM security firmware configuration method applied to the ARM server is implemented.
  • FIG13 shows a schematic diagram of the structure of an electronic device 1300 of an embodiment of the present application.
  • the electronic device 1300 includes a central processing unit (CPU) 1301, which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 1302 or computer program instructions loaded from a storage unit 1308 into a random access memory (RAM) 1303.
  • ROM read-only memory
  • RAM random access memory
  • CPU1301, ROM1302 and RAM1303 are connected to each other via a bus 1304.
  • An input/output (I/O) interface 1305 is also connected to the bus 1304.
  • the I/O interface 1305 includes: an input unit 1306, such as a keyboard, a mouse, a microphone, etc.; an output unit 1307, such as various types of displays, speakers, etc.; a storage unit 1308, such as a disk, an optical disk, etc.; and a communication unit 1309, such as a network card, a modem, a wireless communication transceiver, etc.
  • the communication unit 1309 allows the electronic device 1300 to exchange information/data with other devices through a computer network such as the Internet and/or various telecommunication networks.
  • the various processes and processing described above may be performed by the processing unit 1301.
  • the method of any of the above embodiments may be implemented as a computer software program, which is tangibly contained in a computer-readable medium, such as the storage unit 1308.
  • part or all of the computer program may be loaded and/or installed on the electronic device 1300 via the ROM 1302 and/or the communication unit 1309.
  • the computer program is loaded into the RAM 1303 and executed by the CPU 1301, one or more actions in the method described above may be performed.
  • the embodiment of the present application also provides a computer non-volatile readable storage medium, on which a computer program is stored.
  • a computer program When the computer program is executed by a processor, each process of the above-mentioned ARM security firmware configuration method embodiment applied to an ARM server is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here.
  • the computer non-volatile readable storage medium such as a read-only memory (Read-Only Memory, referred to as ROM), a random access memory (Random Access Memory, referred to as RAM), a disk or an optical disk, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Quality & Reliability (AREA)
  • Stored Programmes (AREA)
  • Computer Hardware Design (AREA)

Abstract

本申请提供了一种应用于ARM服务器的ARM安全固件配置方法及装置。所述方法包括:调用所述ARM服务器的ARM安全固件,对PCI链路桥和所述PCI链路桥下N个层级的PCI设备配置空间寄存器,所述ARM安全固件为所述ARM服务器的处理器固件,N为大于等于3的正整数;在所述ARM安全固件内,添加所述ARM服务器的所有CPU的AER错误识别信息。本申请实施例可以有效解决DPU虚拟云盘系统下重启或者DPU虚拟云盘系统下重启PCI设备宕机的问题。

Description

应用于ARM服务器的ARM安全固件配置方法及装置
相关申请的交叉引用
本申请要求于2023年11月30日提交中国专利局,申请号为202311628371.X,申请名称为“应用于ARM服务器的ARM安全固件配置方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及芯片技术领域,尤其涉及一种应用于ARM服务器的ARM安全固件配置方法及装置。
背景技术
互联网客户采购ARM(Advanced RISC Machines)服务器除了支持替换传统X86服务器的存储功能、云业务外,也支持AI(Artificial Intelligence,人工智能)领域的功能替换,如基于ARM服务器搭配T4卡和DPU(Graphics Processing Unit,图形处理器)卡进行物理组合的配置。在此种配置前提下,客户习惯将DPU设备的硬盘进行虚拟云盘安装,同时,将ARM服务器的所有PCI外设设备都在DPU的虚拟云盘系统中进行初始化使用,因DPU可以支持多个虚拟云盘的安装及使用,这就导致ARM服务器中的PCI外设设备可随时被不同的云盘系统所使用。在一个云盘系统中使用完毕时,需要对此PCI设备如T4卡进行重启,当T4卡重启完成后另外一个云盘系统才能正常使用这张物理T4卡。
然而,在ARM服务器的云盘系统下重启时会出现宕机导致云盘系统下的T4卡无法进行重启且整个ARM服务器也宕机无法正常使用。
发明内容
本申请实施例提供一种应用于ARM服务器的ARM安全固件配置方法及装置,以解决相关技术中在ARM服务器的云盘系统下重启时会出现宕机导致云盘系统下的T4卡无法进行重启且整个ARM服务器也宕机无法正常使用的问题。
为了解决上述技术问题,本申请实施例是这样实现的:
第一方面,本申请实施例提供了一种应用于ARM服务器的ARM安全固件配置方法,方法包括:
调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数;
在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。
在一些实施例中,调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,包括:
在ARM安全固件加载启动过程中,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
在扫描结果指示PCI链路桥下存在N个层级的PCI设备的情况下,对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在一些实施例中,对PCI链路桥下N个层级的PCI设备配置空间寄存器,包括:
对PCI链路桥下N个层级的PCI设备进行初始化;
对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在一些实施例中,在调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果之前,包括:
响应于ARM服务器启动且BIOS加载成功,加载ARM安全固件;
对ARM安全固件进行安全启动校验;
响应于ARM安全固件安全启动校验成功,对ARM安全固件进行内存初始化。
在一些实施例中,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果,包括:
响应于ARM安全固件内存初始化完成,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
在初始化的内存中配置PCI链路桥对应的PCI配置空间。
在一些实施例中,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,还包括:
根据PCI链路桥的拆分情况对PCI链路桥及N个层级的PCI设备进行扫描。
在一些实施例中,对PCI链路桥下N个层级的PCI设备配置空间寄存器,包括:
在PCI配置空间内,对PCI链路桥下N个层级的PCI设备分别配置空间寄存器。
在一些实施例中,在调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果之后,还包括:
在扫描结果指示PCI链路桥下的PCI设备的层级小于N的情况下,在PCI配置空间内预留PCI链路桥对应的寄存器配置空间。
在一些实施例中,在PCI配置空间内预留PCI链路桥对应的寄存器配置空间之后,还包括:
在预留的寄存器配置空间内对后续接入的N个层级的PCI设备配置空间寄存器。
在一些实施例中,在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息,包括:
获取ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备;
在ARM安全固件内,添加所有CPU下的链路桥下的所有PCI设备的AER错误识别信息。
在一些实施例中,在ARM安全固件内,添加所有CPU下的链路桥下的所有PCI设备的AER错误识别信息,包括:
获取所有CPU下的链路桥的AER配置信息;
在ARM安全固件内,基于AER配置信息,对所有CPU下的链路桥下的所有PCI设备进行初始化,以添加AER错误识别信息。
在一些实施例中,在添加ARM服务器的所有CPU的AER错误识别信息之后,还包括:
检测ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成;
响应于所有PCI链路桥下的PCI设备均配置完成,启动ARM服务器的UEFI固件,并启动加载虚拟云盘系统。
在一些实施例中,在检测ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成之后,还包括:
响应于所有PCI链路桥下的PCI设备存在未配置的PCI链路桥,获取未配置的PCI链路桥 下的PCI设备;
依次对未配置的PCI链路桥和未配置的PCI链路桥下的PCI设备进行寄存器配置和AER错误识别信息的添加。
在一些实施例中,在启动ARM服务器的UEFI固件,并启动加载虚拟云盘系统之后,还包括:
在重启PCI设备和重启虚拟云盘系统的情况下,确定ARM服务器是否出现宕机现象;
响应于ARM服务器未出现宕机现象,确定ARM安全固件配置成功。
在一些实施例中,在重启PCI设备和重启虚拟云盘系统的情况下,确定ARM服务器是否出现宕机现象,包括:
当PCI设备未出现重启宕机问题,以及虚拟云盘操作系统也未出现重启宕机问题,则确定ARM服务器未出现宕机现象。
在一些实施例中,在确定ARM服务器是否出现宕机现象之后,还包括:
响应于ARM服务器出现宕机现象,输出宕机报警信息。
在一些实施例中,ARM服务器至少包括一个CPU。
第二方面,本申请实施例提供了一种应用于ARM服务器的ARM安全固件配置装置,装置包括:
寄存器配置模块,用于调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数;
AER信息添加模块,用于在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。
在一些实施例中,寄存器配置模块包括:
扫描结果获取单元,用于在ARM安全固件加载启动过程中,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
空间寄存器配置单元,用于在扫描结果指示PCI链路桥下存在N个层级的PCI设备的情况下,对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在一些实施例中,空间寄存器配置单元包括:
PCI设备初始化子单元,用于对PCI链路桥下N个层级的PCI设备进行初始化;
空间寄存器配置子单元,用于对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在一些实施例中,装置包括:
ARM安全固件加载模块,用于响应于ARM服务器启动且BIOS加载成功,加载ARM安全固件;
安全启动校验模块,用于对ARM安全固件进行安全启动校验;
内存初始化模块,用于响应于ARM安全固件安全启动校验成功,对ARM安全固件进行内存初始化。
在一些实施例中,扫描结果获取单元包括:
扫描结果获取子单元,用于响应于ARM安全固件内存初始化完成,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
PCI配置空间配置子单元,用于在初始化的内存中配置PCI链路桥对应的PCI配置空间。
在一些实施例中,空间寄存器配置单元包括:
寄存器配置子单元,用于在PCI配置空间内,对PCI链路桥下N个层级的PCI设备分别配置空间寄存器。
在一些实施例中,装置还包括:
配置空间预留模块,用于在扫描结果指示PCI链路桥下的PCI设备的层级小于N的情况下,在PCI配置空间内预留PCI链路桥对应的寄存器配置空间。
在一些实施例中,AER信息添加模块包括:
PCI设备获取单元,用于获取ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备;
AER信息添加单元,用于在ARM安全固件内,添加所有CPU下的链路桥下的所有PCI设备的AER错误识别信息。
在一些实施例中,AER信息添加单元包括:
配置信息获取子单元,用于获取所有CPU下的链路桥的AER配置信息;
AER信息添加子单元,用于在ARM安全固件内,基于AER配置信息,对所有CPU下的链路桥下的所有PCI设备进行初始化,以添加AER错误识别信息。
在一些实施例中,装置还包括:
配置完成检测模块,用于检测ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成;
虚拟云盘系统加载模块,用于响应于所有PCI链路桥下的PCI设备均配置完成,启动ARM服务器的UEFI固件,并启动加载虚拟云盘系统。
在一些实施例中,装置还包括:
未配置设备获取模块,用于响应于所有PCI链路桥下的PCI设备存在未配置的PCI链路桥,获取未配置的PCI链路桥下的PCI设备;
PCI设备配置模块,用于依次对未配置的PCI链路桥和未配置的PCI链路桥下的PCI设备进行寄存器配置和AER错误识别信息的添加。
在一些实施例中,装置还包括:
宕机现象确定模块,用于在重启PCI设备和重启虚拟云盘系统的情况下,确定ARM服务器是否出现宕机现象;
配置成功确定模块,用于响应于ARM服务器未出现宕机现象,确定ARM安全固件配置成功。
第三方面,本申请实施例提供了一种电子设备,包括:
存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,计算机程序被处理器执行时实现上述任一项的应用于ARM服务器的ARM安全固件配置方法。
第四方面,本申请实施例提供了一种计算机非易失性可读存储介质,当所述存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行上述任一项的应用于ARM服务器的ARM安全固件配置方法。
在本申请实施例中,通过调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数。在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。 本申请实施例通过增加PCI链路桥及PCI设备在ATF固件中的扫描层级并配置寄存器设置,同时,无论是单路还是双路服务器都需要在ATF中增加所有CPU的每个PCI链路桥及PCI设备添加AER错误信息识别功能,可以有效解决DPU虚拟云盘系统下重启或者DPU虚拟云盘系统下重启PCI设备宕机的问题。
上述说明仅是本申请技术方案的概述,为了能够更清楚了解本申请的技术手段,而可依照说明书的内容予以实施,并且为了让本申请的上述和其它目的、特征和优点能够更明显易懂,以下特举本申请的具体实施方式。
附图说明
为了更清楚地说明本申请实施例的技术方案,下面将对本申请实施例的描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本申请实施例提供的一种应用于ARM服务器的ARM安全固件配置方法的步骤流程图;
图2为本申请实施例提供的一种空间寄存器配置方法的步骤流程图;
图3为本申请实施例提供的另一种空间寄存器配置方法的步骤流程图;
图4为本申请实施例提供的一种ARM安全固件启动方法的步骤流程图;
图5为本申请实施例提供的一种PCI配置空间配置方法的步骤流程图;
图6为本申请实施例提供的一种AER错误识别信息添加方法的步骤流程图;
图7为本申请实施例提供的另一种AER错误识别信息添加方法的步骤流程图;
图8为本申请实施例提供的一种PCI设备配置方法的步骤流程图;
图9为本申请实施例提供的一种ARM安全固件配置成功确定方法的步骤流程图;
图10为本申请实施例提供的一种ARM服务器支持系统下重启PCI设备的流程图;
图11为本申请实施例提供的一种硬件架构的示意图;
图12为本申请实施例提供的一种应用于ARM服务器的ARM安全固件配置装置的结构示意图;
图13为本申请实施例提供的一种电子设备的结构示意图。
具体实施方式
ARM架构处理器固件可以划分为两个部分,一部分是ARM架构独有的ATF(Arm Trusted Firmware,ARM安全固件)固件,另一部分是传统的UEFI固件,UEFI固件是任何架构处理器都需要支持且各种规范协议均统一,而ATF固件则是ARM架构独有的固件,ATF固件涉及ARM的安全启动校验、内存初始化、PCI(Peripheral Component Interconnect,外设部件互连标准)链路的初始化及热插拔等PCI设备的基本功能的支持,在ATF固件中对PCI链路的初始化涉及到了一层级,即对CPU(Central Processing Unit,中央处理器)的PCI链路的根桥、根桥下的PCI设备进行初始化,而在ARM服务器的DPU(Data Processing Unit,数据处理器)虚拟系统中,T4卡是在DPU虚拟云盘的系统下属于PCI设备下的二级层级的PCI设备,而不是ARM系统下的PCI链路桥下的一级PCI设备,这就导致在ARM服务器系统下非DPU虚拟云盘系统下重启T4卡是无任何宕机问题的,但是在ARM系统下的DPU虚拟云盘系统下重启T4卡则会出现宕机问题,这是T4卡在不同系统下的PCI设备层级不同,ATF的初始 化并未考虑到二级甚至三级层级的PCI重启设置的需求,此时,需要对ATF进行多级PCI设备初始化及寄存器设置使能。除了在ATF中增加PCI链路初始化层级外,还需要添加PCI设备的AER识别功能,若未添加的话则会产生AER(Advanced Error Reporting,高级错误报告)报错导致系统继续宕机,因为ARM服务器既支持单路启动也支持双路启动,若只在ATF中添加单路即CPU0的PCI AER错误识别信息的话在单路或者双路启动时使用重启T4卡设备仍旧会报错,故需要在ATF中添加双路启动时的PCI AER错误识别信息设定才行,在此基础上进行单路或者双路启动后在DPU的虚拟云盘系统下进行T4卡的重启设置则不会出现AER宕机问题,故基于上述ATF固件中的两处调整方可解决ARM服务器DPU虚拟云盘系统下重启PCI设备宕机的技术问题。
接下来,结合具体实施例对本申请实施例的技术方案进行如下详细描述。
参照图1,示出了本申请实施例提供的一种应用于ARM服务器的ARM安全固件配置方法的步骤流程图,如图1所示,该应用于ARM服务器的ARM安全固件配置方法可以包括:步骤101和步骤102。
步骤101:调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数。
本申请实施例可以应用于在ARM安全固件部分将CPU的PCI链路及PCI设备的扫描层级增多至多级,并将所有CPU的PCI链路桥及PCI设备添加AER错误信息识别功能,以解决系统下重启PCI设备或者系统重启时的宕机问题的场景中。
本申请实施例可以应用于ARM服务器,即执行主体为ARM服务器,其中,ARM服务器可以包括:BIOS(Basic Input Output System,基本输入输出系统),在BIOS内设置有ARM安全固件(即ATF(固件)和UEFI固件。
在具体实现中,在ARM服务器开机启动之后,可以率先加载BIOS,然后可以加载ARM安全固件,并在ARM安全固件加载启动过程中,通过ARM安全固件对PCI链路桥和PCI链路桥下的N个层级的PCI设备配置空间寄存器。其中,N为大于等于3的正整数。
在具体实现中,可以在ARM安全固件加载启动过程中,调用ARM安全固件对所有CPU(即ARM服务器内所有的CPU,可以为单个CPU,也可以为多个CPU)进行PCI链路桥及多层级PCI设备扫描,并对扫描得到的多层级PCI设备进行空间寄存器配置。对于该实现过程可以结合图2进行如下详细描述。
参照图2,示出了本申请实施例提供的一种空间寄存器配置方法的步骤流程图。如图2所示,该空间寄存器配置方法可以包括:步骤201和步骤202。
步骤201:在ARM安全固件加载启动过程中,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果。
在本实施例中,在加载BIOS之后,可以加载ARM安全固件,并在ARM安全固件加载启动过程中,调用ARM安全固件对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果。具体地,可以通过ARM安全固件扫描CPU下的所有链路桥,以及每个链路桥下的N个层级的PCI设备,从而得到扫描结果。
在具体实现中,在进行安全扫描时,可以先加载ARM安全固件并进行安全启动检验和内存初始化,然后再进行扫描。对于该实现过程可以结合图4进行如下详细描述。
参照图4,示出了本申请实施例提供的一种PCI配置空间配置方法的步骤流程图。如图4所示,该PCI配置空间配置方法可以包括:步骤401、步骤402和步骤403。
步骤401:加载ARM安全固件。
在本实施例中,在加载BIOS之后,可以加载ARM安全固件。
在加载ARM安全固件之后,执行步骤402。
步骤402:对ARM安全固件进行安全启动校验。
在加载ARM安全固件之后,可以对ARM安全固件进行安全启动的校验,以校验ARM安全固件是否安全启动。若ARM安全固件未安全启动,则结束。若ARM安全固件安全启动,则执行步骤403。
步骤403:响应于ARM安全固件安全启动校验成功,对ARM安全固件进行内存初始化。
在ARM安全固件安全启动校验成功之后,可以对ARM安全固件进行内存初始化,以为ARM安全固件配置内存空间,以便于后续空间寄存器的配置。
在完成上述安全校验和内存初始化之后,则可以调用ARM安全固件执行扫描流程,同时,可以配置PCI链路桥对应的PCI配置空间,以为后续的空间寄存器的配置提供内存。对于该实现过程可以结合图5进行如下详细描述。
参照图5,示出了本申请实施例提供的一种PCI配置空间配置方法的步骤流程图。如图5所示,该PCI配置空间配置方法可以包括:步骤501和步骤502。
步骤501:响应于ARM安全固件内存初始化完成,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果。
在本申请实施例中,在对ARM安全固件内存初始化完成之后,可以调用ARM安全固件对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果。
步骤502:在初始化的内存中配置PCI链路桥对应的PCI配置空间。
然后,可以在初始的内存中配置PCI链路桥对应的PCI配置空间,该PCI配置空间可以用于进行后续的PCI设备的空间寄存器的配置。
在调用ARM安全固件对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果之后,执行步骤202。
步骤202:在扫描结果指示PCI链路桥下存在N个层级的PCI设备的情况下,对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在调用ARM安全固件对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果之后,在扫描结果指示PCI链路桥下存在N个层级的PCI设备的情况下,则可以对PCI链路桥下N个层级的PCI设备配置空间寄存器。具体地,可以对PCI链路桥下N个层级的PCI设备进行初始化,并配置空间寄存器。对于该实现过程可以结合图3进行如下详细描述。
参照图3,示出了本申请实施例提供的另一种空间寄存器配置方法的步骤流程图。如图3所示,该控件寄存器配置方法可以包括:步骤301和步骤302。
步骤301:对PCI链路桥下N个层级的PCI设备进行初始化。
在本实施例中,在扫描结果指示PCI链路桥下存在N个层级的PCI设备的情况下,则可以对PCI链路桥下N个层级的PCI设备进行初始化。
步骤302:对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在初始化的过程中,可以对PCI链路桥下N个层级的PCI设备配置空间寄存器。即对PCI 设备的初始过程可以将空间寄存器写入对应的空间内。
本申请通过对ATF进行多级PCI设备初始化及寄存器设置使能,可以解决在ARM服务器系统下DPU虚拟云盘系统下重启PCI设备出现宕机的问题。
在对PCI链路桥下N个层级的PCI设备分别配置空间寄存器时,由于已经在初始化的ARM安全固件的内存中配置了PCI配置空间,则可以在PCI配置空间内,对PCI链路桥下N个层级的PCI设备分别配置空间寄存器。
在本申请的一种具体实现中,在扫描结果指示PCI链路桥下的PCI设备的层级小于N的情况下,在PCI配置空间内预留PCI链路桥对应的寄存器配置空间。通过预留寄存器配置空间,可以在后续接入多层级的PCI设备时,以及时在预留的寄存器配置空间内对接入的PCI设备进行空间寄存器的配置。
在调用ARM服务器的ARM安全固件对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器之后,执行步骤102。
步骤102:在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。
在调用ARM服务器的ARM安全固件对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器之后,则可以在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。
本申请实施例通过对ARM服务器的所有CPU添加AER错误识别信息,在此基础上,进行单路或者双路启动后在DPU虚拟云盘系统下进行如T4卡的重启设置则不会出现AER宕机问题。
在具体实现中,在进行AER错误识别信息的添加时,可以在ARM安全固件内对所有CPU下的链路桥下的所有PCI设备均添加相应的AER错误识别信息。对于该实现过程可以结合图6进行如下详细描述。
参照图6,示出了本申请实施例提供的一种AER错误识别信息添加方法的步骤流程图。如图6所示,该AER错误识别信息添加方法可以包括:步骤601和步骤602。
步骤601:获取ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备。
在本申请实施例中,在进行AER错误识别信息的添加时,可以获取ARM服务器的所有CPU下的链路桥。
在本示例中,ARM服务器中可以仅有一个CPU,也可以有两个CPU,或者四个CPU等,具体地,对于ARM服务器中CPU的数量可以根据实际情况而定,本实施例对此不加以限制。
在获取到ARM服务器的所有CPU下的链路桥之后,则可以对每个CPU下的链路桥进行PCI设备的扫描,以得到所有CPU下的链路桥下的所有PCI设备。
在获取到ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备之后,执行步骤602。
步骤602:在ARM安全固件内,添加所有CPU下的链路桥下的所有PCI设备的AER错误识别信息。
在获取到ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备之后,则可以在ARM安全固件内,添加所有CPU下的链路桥下的所有PCI设备的AER错误识 别信息。
本申请实施例中,无论是单路服务器还是双路服务器均进行AER错误识别信息的添加,从而可以解决在ARM服务器启动后在DPU虚拟云盘系统下进行如T4卡的重启设置出现AER宕机的问题。
在具体实现中,在进行AER错误识别信息的添加时,可以获取所有CPU下的链路桥的AER配置信息,并基于AER配置信息进行AER错误识别信息的添加。对于该实现过程可以结合图7进行如下详细描述。
参照图7,示出了本申请实施例提供的另一种AER错误识别信息添加方法的步骤流程图。如图7所示,该AER错误识别信息添加方法可以包括:步骤701和步骤702。
步骤701:获取所有CPU下的链路桥的AER配置信息。
在本申请实施例中,在获取到ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备之后,可以获取所有CPU下的链路桥的AER配置信息。
在获取到所有CPU下的链路桥的AER配置信息之后,执行步骤702。
步骤702:在ARM安全固件内,基于AER配置信息,对所有CPU下的链路桥下的所有PCI设备进行初始化,以添加AER错误识别信息。
在获取到所有CPU下的链路桥的AER配置信息之后,则可以在ARM安全固件内,基于AER配置信息,对所有CPU下的链路桥下的所有PCI设备进行初始化,以添加AER错误识别信息。
本申请实施例通过结合AER配置信息对链路桥下的所有PCI设备进行AER错误识别信息的添加,可以满足多层级系统下重启PCI设备正常使用的功能。
在具体实现中,在添加ARM服务器的所有CPU的AER错误识别信息之后,则可以检测ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成。若所有PCI链路桥下的PCI设备均配置完成,则可以启动ARM服务器的UEFI固件,并启动加载虚拟云盘系统(如DPU虚拟云盘系统等)。
若所有PCI链路桥下的PCI设备存在未配置的PCI链路桥,则对未配置的PCI链路桥继续进行配置流程。对于该实现过程可以结合图8进行如下详细描述。
参照图8,示出了本申请实施例提供的一种PCI设备配置方法的步骤流程图。如图8所示,该PCI设备配置方法可以包括:步骤801和步骤802。
步骤801:响应于所有PCI链路桥下的PCI设备存在未配置的PCI链路桥,获取未配置的PCI链路桥下的PCI设备。
在本实施例中,在所有PCI链路桥下的PCI设备存在未配置的PCI链路桥的情况下,可以获取未配置的PCI链路桥下的PCI设备。
步骤802:依次对未配置的PCI链路桥和未配置的PCI链路桥下的PCI设备进行寄存器配置和AER错误识别信息的添加。
进而,可以依次对未配置的PCI链路桥和未配置的PCI链路桥下的PCI设备进行寄存器配置和AER错误识别信息的添加。
本申请实施例通过对未配置PCI链路桥的检测,可以避免出现PCI链路桥或PCI设备的遗漏,导致PCI链路桥下的PCI设备未进行上述配置出现宕机的情况发生。
在具体实现中,在启动虚拟云盘系统之后,可以在重启PCI设备和重启虚拟云盘系统的 情况下,确定是否出现ARM服务器出现宕机现象。对于该实现过程可以结合图9进行如下详细描述。
参照图9,示出了本申请实施例提供的一种配置完成确定方法的步骤流程图。如图9所示,该配置完成确定方法可以包括:步骤901和步骤902。
步骤901:在重启PCI设备和重启虚拟云盘系统的情况下,确定ARM服务器是否出现宕机现象。
在本实施例中,在启动加载虚拟云盘系统之后,可以在ARM服务器下重启PCI设备,并重启虚拟云盘系统,以检测ARM服务器是否出现宕机现象。具体地,DPU虚拟云盘操作系统后,通过系统下PCI命令重启如PCI设备T4卡,并通过系统命令重启DPU虚拟云盘操作系统。同时检测ARM服务器是否出现宕机现象。
步骤902:响应于ARM服务器未出现宕机现象,确定ARM安全固件配置成功。
若确定出ARM服务器未出现宕机现象,则可以确定ARM安全固件配置成功,已彻底解决重启PCI设备宕机问题。
当然,若ARM服务器仍出现宕机现象,则有可能是由于其它原因造成的,此时,可以输出宕机报警信息,以提示运维人员查找产生宕机现象的原因。
对于ARM服务器支持系统下重启PCI设备的流程可以结合图10进行如下详细描述。
参照图10,示出了本申请实施例提供的一种ARM服务器支持系统下重启PCI设备的流程图。如图10所示,该流程可以包括以下步骤:
步骤1、ARM服务器(本示例中为双路启动机制的ARM服务器)开机启动,BIOS固件加载,率先加载ATF镜像固件。
步骤2、ATF加载启动过程中,当安全启动及内存初始化启动完成后,进行PCI链路初始化部分,根据PCI链路桥的拆分情况对PCI链路桥及PCI设备进行扫描并初始化。此时,ATF由扫描初始化PCI链路桥及一层级PCI设备的方案改为扫描PCI链路及多层级PCI设备的方案。若当前PCI链路存在多级设备则进行多级PCI设备扫描并初始化,若当前PCI链路不存在多级设备,则将多级扫描PCI设备空间的功能进行开启并预留,即预留寄存器配置空间。
步骤3、在完成上述步骤2之后,可以对PCI链路桥的AER表格(包含PCI链路桥的AER配置信息)进行初始化,若不初始化AER表格将导致系统下重启PCI设备宕机问题出现,初始化表格需要对两个CPU的PCI链路及PCI设备均进行初始化,若只初始化任意1个CPU的PCI链路则会出现系统下重启PCI设备宕机问题,初始化AER表格需要将PCI链路及多层级的PCI设备的AER信息进行设置,以满足多层级系统下重启PCI设备正常使用的功能。
步骤4、当ARM服务器固件初始化完成ATF固件后,则启动UEFI固件,继续启动并进入DPU虚拟云盘操作系统。
步骤5、DPU虚拟云盘操作系统后,通过系统下PCI命令重启如PCI设备T4卡未出现重启宕机问题,或者,通过系统命令重启DPU虚拟云盘操作系统也未出现重启宕机问题,故重启PCI设备宕机问题彻底解决。
步骤6、当然,在仅对两个CPU中的任意一个CPU的PCI链路桥及多层级PCI设备添加AER错误识别信息的情况下,启动加载虚拟云盘系统后,通过系统下PCI命令重启如PCI设备T4卡会出现重启宕机问题,或者,通过系统命令重启DPU虚拟云盘操作系统会出现重启宕机问题。
在本实施例中,根据ARM服务器固件的特性及DPU虚拟云盘系统下重启PCI设备或者虚拟云盘系统重启导致的系统宕机问题,通过对问题的根因定位到ATF需要支持PCI设备多层级扫描并配置管理寄存器方可。同时,因在DPU虚拟云盘系统下重启PCI设备或者重启系统导致AER错误产生且继续宕机的现象,通过在ATF中对CPU0和PCI的PCI链路桥及PCI设备添加AER错误信息识别功能,方可解决AER错误导致的宕机问题,上述2点必须同时存在才能彻底解决DPU虚拟云盘系统下重启PCI设备或者重启系统导致的系统宕机问题,若CPU0和CPU1中的任意一个添加了PCI桥及PCI设备的AER错误信息识别功能则将继续导致宕机问题的存在,无论物理是单路服务器还是双路服务器都需要对CPU0和CPU1的PCI链路桥及PCI设备添加AER错误信息识别功能才行。故本申请实施例在ATF固件部分将CPU的PCI链路及PCI设备的扫描层级增多至多级,最少3层级及以上,同时,将CPU0和CPU1的PCI链路桥及PCI设备添加AER错误信息识别功能方可解决系统下重启PCI设备或者系统重启时的宕机问题。
接下来,结合硬件架构对配置流程进行如下详细描述。
参照图11,示出了本申请实施例提供的一种硬件架构的示意图。如图11所示,本实施例的硬件架构可以包括:ARM服务器以及OS(Operating System)操作系统,以及ARM服务器下的BIOS,BIOS下的UTF固件和UEFI固件。
在具体流程中,可以先启动ARM服务器,ARM服务器启动之后,可以加载BIOS镜像。进而,可以加载ATF镜像固件。在ATF固件启动过程可以进行安全启动校验,完成之后,对进行内存初始化。
在内存初始化完成之后,可以对PCI链路桥及PCI设备初始化,此时,可以进行PCI链路桥以及PCI设备多层级扫描,并配置PCI配置空间。
根据扫描结果,确定PCI链路桥下是否存在多层级PCI设备。若PCI链路桥下不存在多层级PCI设备则预留PCI设备配置空间寄存器的空间,即寄存器配置空间。若PCI链路桥下存在多层级PCI设备,则可以对多层级PCI设备配置空间寄存器。
然后,可以选择是否对CPU0和CPU1的PCI链路桥的多层级PCI设备添加AER错误识别信息。若选择对CPU0和CPU1的PCI链路桥的多层级PCI设备添加AER错误识别信息,则初始化AER表格将PCI链路及多层级的PCI设备的AER信息进行设置。
在ATF固件初始化完成之后,可以加载UEFI固件,并启动加载DPU虚拟云盘系统。
通过系统下PCI命令重启如PCI设备T4卡未出现重启宕机问题,或者,通过系统命令重启DPU虚拟云盘操作系统也未出现重启宕机问题,故重启PCI设备宕机问题彻底解决。
本申请实施例针对ARM架构服务器的固件划分及ARM服务器的具体实际应用情况,针对DPU虚拟云盘重启或者虚拟云盘下重启PCI设备时出现的宕机问题,在ATF中将PCI链路桥及PCI设备进行多层级扫描并配置管理寄存器,同时,将CPU0和CPU1的每个PCI链路桥及PCI设备添加AER错误信息识别功能,倘若不添加则出现重启时的二次宕机出现,故采用此方案可解决系统下重启和PCI设备重启时出现的两次宕机问题,所以,本实施例通过增加PCI链路桥及PCI设备在ATF固件中的扫描层级并配置寄存器设置,同时,无论是单路还是双路服务器都需要在ATF中增加PU0和CPU1的每个PCI链路桥及PCI设备添加AER错误信息识别功能即可,能彻底解决DPU虚拟云盘系统下重启或者DPU虚拟云盘系统下重启PCI设备宕机的问题。
本申请实施例提供的应用于ARM服务器的ARM安全固件配置方法,通过调用ARM服务 器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数。在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。本申请实施例通过增加PCI链路桥及PCI设备在ATF固件中的扫描层级并配置寄存器设置,同时,无论是单路还是双路服务器都需要在ATF中增加所有CPU的每个PCI链路桥及PCI设备添加AER错误信息识别功能,可以有效解决DPU虚拟云盘系统下重启或者DPU虚拟云盘系统下重启PCI设备宕机的问题。
参照图12,示出了本申请实施例提供的一种应用于ARM服务器的ARM安全固件配置装置的结构示意图。如图12所示,该应用于ARM服务器的ARM安全固件配置装置1200可以包括以下模块:
寄存器配置模块1210,用于调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数;
AER信息添加模块1220,用于在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。
在一些实施例中,寄存器配置模块包括:
扫描结果获取单元,用于在ARM安全固件加载启动过程中,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
空间寄存器配置单元,用于在扫描结果指示PCI链路桥下存在N个层级的PCI设备的情况下,对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在一些实施例中,空间寄存器配置单元包括:
PCI设备初始化子单元,用于对PCI链路桥下N个层级的PCI设备进行初始化;
空间寄存器配置子单元,用于对PCI链路桥下N个层级的PCI设备配置空间寄存器。
在一些实施例中,装置包括:
ARM安全固件加载模块,用于响应于ARM服务器启动且BIOS加载成功,加载ARM安全固件;
安全启动校验模块,用于对ARM安全固件进行安全启动校验;
内存初始化模块,用于响应于ARM安全固件安全启动校验成功,对ARM安全固件进行内存初始化。
在一些实施例中,扫描结果获取单元包括:
扫描结果获取子单元,用于响应于ARM安全固件内存初始化完成,调用ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
PCI配置空间配置子单元,用于在初始化的内存中配置PCI链路桥对应的PCI配置空间。
在一些实施例中,空间寄存器配置单元包括:
寄存器配置子单元,用于在PCI配置空间内,对PCI链路桥下N个层级的PCI设备分别配置空间寄存器。
在一些实施例中,装置还包括:
配置空间预留模块,用于在扫描结果指示PCI链路桥下的PCI设备的层级小于N的情况下,在PCI配置空间内预留PCI链路桥对应的寄存器配置空间。
在一些实施例中,AER信息添加模块包括:
PCI设备获取单元,用于获取ARM服务器的所有CPU下的链路桥,及所有CPU下的链路桥下的所有PCI设备;
AER信息添加单元,用于在ARM安全固件内,添加所有CPU下的链路桥下的所有PCI设备的AER错误识别信息。
在一些实施例中,AER信息添加单元包括:
配置信息获取子单元,用于获取所有CPU下的链路桥的AER配置信息;
AER信息添加子单元,用于在ARM安全固件内,基于AER配置信息,对所有CPU下的链路桥下的所有PCI设备进行初始化,以添加AER错误识别信息。
在一些实施例中,装置还包括:
配置完成检测模块,用于检测ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成;
虚拟云盘系统加载模块,用于响应于所有PCI链路桥下的PCI设备均配置完成,启动ARM服务器的UEFI固件,并启动加载虚拟云盘系统。
在一些实施例中,装置还包括:
未配置设备获取模块,用于响应于所有PCI链路桥下的PCI设备存在未配置的PCI链路桥,获取未配置的PCI链路桥下的PCI设备;
PCI设备配置模块,用于依次对未配置的PCI链路桥和未配置的PCI链路桥下的PCI设备进行寄存器配置和AER错误识别信息的添加。
在一些实施例中,装置还包括:
宕机现象确定模块,用于在重启PCI设备和重启虚拟云盘系统的情况下,确定ARM服务器是否出现宕机现象;
配置成功确定模块,用于响应于ARM服务器未出现宕机现象,确定ARM安全固件配置成功。
本申请实施例提供的应用于ARM服务器的ARM安全固件配置装置,通过调用ARM服务器的ARM安全固件,对PCI链路桥和PCI链路桥下N个层级的PCI设备配置空间寄存器,ARM安全固件为ARM服务器的处理器固件,N为大于等于3的正整数。在ARM安全固件内,添加ARM服务器的所有CPU的AER错误识别信息。本申请实施例通过增加PCI链路桥及PCI设备在ATF固件中的扫描层级并配置寄存器设置,同时,无论是单路还是双路服务器都需要在ATF中增加所有CPU的每个PCI链路桥及PCI设备添加AER错误信息识别功能,可以有效解决DPU虚拟云盘系统下重启或者DPU虚拟云盘系统下重启PCI设备宕机的问题。
另外地,本申请实施例还提供了一种电子设备,包括:存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,计算机程序被处理器执行时实现上述应用于ARM服务器的ARM安全固件配置方法。
图13示出了本申请实施例的一种电子设备1300的结构示意图。如图13所示,电子设备1300包括中央处理单元(CPU)1301,其可以根据存储在只读存储器(ROM)1302中的计算机程序指令或者从存储单元1308加载到随机访问存储器(RAM)1303中的计算机程序指令,来执行各种适当的动作和处理。在RAM1303中,还可存储电子设备1300操作所需的各种程序和数据。CPU1301、ROM1302以及RAM1303通过总线1304彼此相连。输入/输出(I/O)接口1305也连接至总线1304。
电子设备1300中的多个部件连接至I/O接口1305,包括:输入单元1306,例如键盘、鼠标、麦克风等;输出单元1307,例如各种类型的显示器、扬声器等;存储单元1308,例如磁盘、光盘等;以及通信单元1309,例如网卡、调制解调器、无线通信收发机等。通信单元1309允许电子设备1300通过诸如因特网的计算机网络和/或各种电信网络与其他设备交换信息/数据。
上文所描述的各个过程和处理,可由处理单元1301执行。例如,上述任一实施例的方法可被实现为计算机软件程序,其被有形地包含于计算机可读介质,例如存储单元1308。在一些实施例中,计算机程序的部分或者全部可以经由ROM1302和/或通信单元1309而被载入和/或安装到电子设备1300上。当计算机程序被加载到RAM1303并由CPU1301执行时,可以执行上文描述的方法中的一个或多个动作。
本申请实施例还提供了一种计算机非易失性可读存储介质,计算机非易失性可读存储介质上存储有计算机程序,计算机程序被处理器执行时实现上述应用于ARM服务器的ARM安全固件配置方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。其中,计算机非易失性可读存储介质,如只读存储器(Read-Only Memory,简称ROM)、随机存取存储器(Random Access Memory,简称RAM)、磁碟或者光盘等。
以上,仅为本申请的一些实施例,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以权利要求的保护范围为准。

Claims (20)

  1. 一种应用于ARM服务器的ARM安全固件配置方法,其特征在于,所述方法包括:
    调用所述ARM服务器的ARM安全固件,对PCI链路桥和所述PCI链路桥下N个层级的PCI设备配置空间寄存器,所述ARM安全固件为所述ARM服务器的处理器固件,N为大于等于3的正整数;
    在所述ARM安全固件内,添加所述ARM服务器的所有CPU的AER错误识别信息。
  2. 根据权利要求1所述的方法,其特征在于,所述调用所述ARM服务器的ARM安全固件,对PCI链路桥和所述PCI链路桥下N个层级的PCI设备配置空间寄存器,包括:
    在所述ARM安全固件加载启动过程中,调用所述ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
    在所述扫描结果指示所述PCI链路桥下存在N个层级的PCI设备的情况下,对所述PCI链路桥下N个层级的PCI设备配置所述空间寄存器。
  3. 根据权利要求2所述的方法,其特征在于,所述对所述PCI链路桥下N个层级的PCI设备配置所述空间寄存器,包括:
    对所述PCI链路桥下N个层级的PCI设备进行初始化;
    对所述PCI链路桥下N个层级的PCI设备配置所述空间寄存器。
  4. 根据权利要求2所述的方法,其特征在于,在所述调用所述ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果之前,包括:
    响应于所述ARM服务器启动且BIOS加载成功,加载所述ARM安全固件;
    对所述ARM安全固件进行安全启动校验;
    响应于所述ARM安全固件安全启动校验成功,对所述ARM安全固件进行内存初始化。
  5. 根据权利要求4所述的方法,其特征在于,所述调用所述ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果,包括:
    响应于所述ARM安全固件内存初始化完成,调用所述ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果;
    在初始化的内存中配置所述PCI链路桥对应的PCI配置空间。
  6. 根据权利要求5所述的方法,其特征在于,所述调用所述ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,还包括:
    根据所述PCI链路桥的拆分情况对所述PCI链路桥及N个层级的PCI设备进行扫描。
  7. 根据权利要求5所述的方法,其特征在于,所述对所述PCI链路桥下N个层级的PCI设备配置所述空间寄存器,包括:
    在所述PCI配置空间内,对所述PCI链路桥下N个层级的PCI设备分别配置所述空间寄存器。
  8. 根据权利要求5所述的方法,其特征在于,在所述调用所述ARM安全固件,对所有CPU进行PCI链路桥及N个层级的PCI设备扫描,得到扫描结果之后,还包括:
    在所述扫描结果指示所述PCI链路桥下的PCI设备的层级小于N的情况下,在PCI配置空间内预留所述PCI链路桥对应的寄存器配置空间。
  9. 根据权利要求8所述的方法,其特征在于,所述在PCI配置空间内预留所述PCI链路 桥对应的寄存器配置空间之后,还包括:
    在预留的寄存器配置空间内对后续接入的N个层级的PCI设备配置所述空间寄存器。
  10. 根据权利要求1所述的方法,其特征在于,所述在所述ARM安全固件内,添加所述ARM服务器的所有CPU的AER错误识别信息,包括:
    获取所述ARM服务器的所有CPU下的链路桥,及所述所有CPU下的链路桥下的所有PCI设备;
    在所述ARM安全固件内,添加所述所有CPU下的链路桥下的所有PCI设备的AER错误识别信息。
  11. 根据权利要求10所述的方法,其特征在于,所述在所述ARM安全固件内,添加所述所有CPU下的链路桥下的所有PCI设备的AER错误识别信息,包括:
    获取所述所有CPU下的链路桥的AER配置信息;
    在所述ARM安全固件内,基于所述AER配置信息,对所述所有CPU下的链路桥下的所有PCI设备进行初始化,以添加所述AER错误识别信息。
  12. 根据权利要求1所述的方法,其特征在于,在所述添加所述ARM服务器的所有CPU的AER错误识别信息之后,还包括:
    检测所述ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成;
    响应于所述所有PCI链路桥下的PCI设备均配置完成,启动所述ARM服务器的UEFI固件,并启动加载虚拟云盘系统。
  13. 根据权利要求12所述的方法,其特征在于,在所述检测所述ARM安全固件下的所有PCI链路桥下的PCI设备是否均配置完成之后,还包括:
    响应于所述所有PCI链路桥下的PCI设备存在未配置的PCI链路桥,获取所述未配置的PCI链路桥下的PCI设备;
    依次对所述未配置的PCI链路桥和所述未配置的PCI链路桥下的PCI设备进行寄存器配置和AER错误识别信息的添加。
  14. 根据权利要求12所述的方法,其特征在于,在所述启动所述ARM服务器的UEFI固件,并启动加载虚拟云盘系统之后,还包括:
    在重启PCI设备和重启所述虚拟云盘系统的情况下,确定所述ARM服务器是否出现宕机现象;
    响应于所述ARM服务器未出现宕机现象,确定所述ARM安全固件配置成功。
  15. 根据权利要求14所述的方法,其特征在于,所述在重启PCI设备和重启所述虚拟云盘系统的情况下,确定所述ARM服务器是否出现宕机现象,包括:
    当所述PCI设备未出现重启宕机问题,以及所述虚拟云盘操作系统也未出现重启宕机问题,则确定所述ARM服务器未出现宕机现象。
  16. 根据权利要求14所述的方法,其特征在于,在所述确定所述ARM服务器是否出现宕机现象之后,还包括:
    响应于所述ARM服务器出现宕机现象,输出宕机报警信息。
  17. 根据权利要求1所述的方法,其特征在于,所述ARM服务器至少包括一个CPU。
  18. 一种应用于ARM服务器的ARM安全固件配置装置,其特征在于,所述装置包括:
    寄存器配置模块,用于调用所述ARM服务器的ARM安全固件,对PCI链路桥和所述 PCI链路桥下N个层级的PCI设备配置空间寄存器,所述ARM安全固件为所述ARM服务器的处理器固件,N为大于等于3的正整数;
    AER信息添加模块,用于在所述ARM安全固件内,添加所述ARM服务器的所有CPU的AER错误识别信息。
  19. 一种电子设备,其特征在于,包括:
    存储器、处理器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如权利要求1至17中任一项所述的应用于ARM服务器的ARM安全固件配置方法。
  20. 一种计算机非易失性可读存储介质,其特征在于,当所述计算机非易失性可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行权利要求1至17任一项所述的应用于ARM服务器的ARM安全固件配置方法。
PCT/CN2024/099921 2023-11-30 2024-06-18 应用于arm服务器的arm安全固件配置方法及装置 Pending WO2025112463A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US19/144,055 US20260119436A1 (en) 2023-11-30 2024-06-18 Arm security firmware configuration method and apparatus applied to arm server

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202311628371.X 2023-11-30
CN202311628371.XA CN117331723B (zh) 2023-11-30 2023-11-30 应用于arm服务器的arm安全固件配置方法及装置

Publications (1)

Publication Number Publication Date
WO2025112463A1 true WO2025112463A1 (zh) 2025-06-05

Family

ID=89279620

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/099921 Pending WO2025112463A1 (zh) 2023-11-30 2024-06-18 应用于arm服务器的arm安全固件配置方法及装置

Country Status (3)

Country Link
US (1) US20260119436A1 (zh)
CN (1) CN117331723B (zh)
WO (1) WO2025112463A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117331723B (zh) * 2023-11-30 2024-02-27 苏州元脑智能科技有限公司 应用于arm服务器的arm安全固件配置方法及装置

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170068636A1 (en) * 2015-09-03 2017-03-09 Avago Technologies General IP (Singapore) Pte. Ltd . Virtual expansion rom in a pcie environment
CN109614259A (zh) * 2018-11-28 2019-04-12 郑州云海信息技术有限公司 一种服务器PCIe设备定位故障原因的系统及方法
CN114185607A (zh) * 2022-02-14 2022-03-15 苏州浪潮智能科技有限公司 Arm服务器中pci设备的启动控制方法、装置及设备
CN114201360A (zh) * 2021-11-26 2022-03-18 苏州浪潮智能科技有限公司 一种aer功能管理方法、装置、服务器和存储介质
CN116700821A (zh) * 2023-05-10 2023-09-05 苏州浪潮智能科技有限公司 Arm服务器的pci参数调整方法、装置、计算机设备及介质
CN117331723A (zh) * 2023-11-30 2024-01-02 苏州元脑智能科技有限公司 应用于arm服务器的arm安全固件配置方法及装置

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109542752A (zh) * 2018-11-28 2019-03-29 郑州云海信息技术有限公司 一种服务器PCIe设备故障记录的系统及方法
CN114138587B (zh) * 2021-10-25 2024-01-12 苏州浪潮智能科技有限公司 服务器电源固件升级的可靠性验证方法、装置和设备
CN116302145A (zh) * 2022-08-26 2023-06-23 苏州浪潮智能科技有限公司 一种aer功能配置方法、装置、设备及介质

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170068636A1 (en) * 2015-09-03 2017-03-09 Avago Technologies General IP (Singapore) Pte. Ltd . Virtual expansion rom in a pcie environment
CN109614259A (zh) * 2018-11-28 2019-04-12 郑州云海信息技术有限公司 一种服务器PCIe设备定位故障原因的系统及方法
CN114201360A (zh) * 2021-11-26 2022-03-18 苏州浪潮智能科技有限公司 一种aer功能管理方法、装置、服务器和存储介质
CN114185607A (zh) * 2022-02-14 2022-03-15 苏州浪潮智能科技有限公司 Arm服务器中pci设备的启动控制方法、装置及设备
CN116700821A (zh) * 2023-05-10 2023-09-05 苏州浪潮智能科技有限公司 Arm服务器的pci参数调整方法、装置、计算机设备及介质
CN117331723A (zh) * 2023-11-30 2024-01-02 苏州元脑智能科技有限公司 应用于arm服务器的arm安全固件配置方法及装置

Also Published As

Publication number Publication date
US20260119436A1 (en) 2026-04-30
CN117331723B (zh) 2024-02-27
CN117331723A (zh) 2024-01-02

Similar Documents

Publication Publication Date Title
TWI754317B (zh) 用於網路裝置之最佳啟動路徑之方法和系統
US11226919B1 (en) Communication link recovery
US12001285B2 (en) System booting method and apparatus, node device, and computer-readable storage medium
CN112970002B (zh) 用于可配置错误处理的系统
US20100162045A1 (en) Method, apparatus and system for restarting an emulated mainframe iop
CN114817105B (zh) 设备枚举的方法、装置、计算机设备以及存储介质
US12079072B2 (en) Orchestration of automated virtual machine failure replacement in a node cluster
US11321077B1 (en) Live updating of firmware behavior
US12197939B2 (en) Provisioning DPU management operating systems
CN117687695A (zh) 信息处理方法、装置、电子设备及存储介质
CN118152182A (zh) 服务器开机处理方法、装置、电子设备及存储介质
CN117667465B (zh) 代码共享方法、装置、交换机、多主机系统、设备和介质
WO2025130139A1 (zh) 一种启动校验系统、方法、电子设备及存储介质
TWI777664B (zh) 嵌入式系統的開機方法
WO2025112463A1 (zh) 应用于arm服务器的arm安全固件配置方法及装置
US20240241779A1 (en) Signaling host kernel crashes to dpu
CN115221092B (zh) Pci-e卡可分配的总线确定方法、装置、设备及存储介质
CN110795211A (zh) 升级虚拟机配置的方法、装置、电子设备及可读存储介质
CN118672664B (zh) 选项只读存储器加载方法、计算机程序产品、设备及介质
CN120353506A (zh) 服务器的启动方法、装置、电子设备和存储介质
US20240241728A1 (en) Host and dpu coordination for dpu maintenance events
CN110688130A (zh) 物理机部署方法、装置、可读存储介质及电子设备
TWI554876B (zh) 節點置換處理方法與使用其之伺服器系統
US8359220B2 (en) Technical support routing among members of a technical support group
CN103186403A (zh) 节点置换处理方法与使用该方法的服务器系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24895566

Country of ref document: EP

Kind code of ref document: A1