在bl2_main函数中的最后一句是:
smc(BL1_SMC_RUN_IMAGE, (unsigned long)next_bl_ep_info, 0, 0, 0, 0, 0, 0);
该函数将触发smc操作,而smc的handle在bl1阶段的时候被指定,调用该函数的时候带入command ID是BL1_SMC_RUN_IMAGE,故执行该函数之后,系统将跳转到中断处理函数:smc_handler64继续执行。该函数定义在bl1/aarch64/bl1_exception.S文件中,内容如下:
func smc_handler64
/* ----------------------------------------------
* Detect if this is a RUN_IMAGE or other SMC.
* ----------------------------------------------
*/
/* 判定触发smc操作时带入的参数是否是跳转执行image的操作 */
mov x30, #BL1_SMC_RUN_IMAGE //将BL1_SMC_RUN_IMAGE的值保存到x30
cmp x30, x0 //比较x30与x0的值
b.ne smc_handler //如果x30与x0不同则认为是普通类型的异常,进入到smc_handler进行处理
/* ------------------------------------------------
* Make sure only Secure world reaches here.
* ------------------------------------------------
*/
mrs x30, scr_el3 //获取scr寄存器的值
tst x30, #SCR_NS_BIT //比较scr寄存器中的NS位与SCR_NS_BIT是否相等
b.ne unexpected_sync_exception //如果当前NS位为非安全位,则证明不合法,产生异常
/* ----------------------------------------------
* Handling RUN_IMAGE SMC. First switch back to
* SP_EL0 for the C runtime stack.
* ----------------------------------------------
*/
ldr x30, [sp, #CTX_EL3STATE_OFFSET + CTX_RUNTIME_SP] /获取offset和sp的值
msr spsel, #0 //清空spsel中的值
mov sp, x30 //保存x30的值到sp寄存器,用于返回
/* ---------------------------------------------------------------------
* Pass EL3 control to next BL image.
* Here it expects X1 with the address of a entry_point_info_t
* structure describing the next BL image entrypoint.
* ---------------------------------------------------------------------
*/
mov x20, x1 //将x1中的数据保存到x20中
mov x0, x20 //将x20的数据保存到x0中
bl bl1_print_next_bl_ep_info //打印出bl3x镜像文件信息
ldp x0, x1, [x20, #ENTRY_POINT_INFO_PC_OFFSET] //将传入的参数和bl3x入口函数PC指针
msr elr_el3, x0
msr spsr_el3, x1
ubfx x0, x1, #MODE_EL_SHIFT, #2 //设定cortex模式
cmp x0, #MODE_EL3 //比较x0寄存器中的值是否为MODE_EL3
b.ne unexpected_sync_exception //如果x0中不是MODE_EL3则产生异常
bl disable_mmu_icache_el3 //禁止MMU的指令cache
tlbi alle3
#if SPIN_ON_BL1_EXIT
bl print_debug_loop_message
debug_loop:
b debug_loop
#endif
mov x0, x20
bl bl1_plat_prepare_exit/
* 设定返回参数 */
ldp x6, x7, [x20, #(ENTRY_POINT_INFO_ARGS_OFFSET + 0x30)]
ldp x4, x5, [x20, #(ENTRY_POINT_INFO_ARGS_OFFSET + 0x20)]
ldp x2, x3, [x20, #(ENTRY_POINT_INFO_ARGS_OFFSET + 0x10)]
ldp x0, x1, [x20, #(ENTRY_POINT_INFO_ARGS_OFFSET + 0x0)]
eret //跳转到bl3x执行
endfunc smc_handler64