ROM Overview

This document is a high-level overview of the features, responsibilities, and organization of the Pavona ROM.

For information about specific ROM tasks, see the following:

Source Code Organization

The ROM for single-stage ROM designs and the first-stage ROM (ROM0) for dual-stage ROM designs are both built from the same top-level source file (//sw/device/silicon_creator/rom/rom.c) and Bazel target (//sw/device/silicon_creator/rom:rom). The second-stage of the dual-stage ROM (ROM1) has a separate target located at (//sw/device/silion_creator/second_rom:second_rom).

The //sw/device/silicon_creator/rom directory also contains several libraries that are shared between the single-stage ROM and the dual-stage ROM1 (second ROM). These libraries implement tasks, such as verifying the silicon creator firmware, that apply to both a single- and dual-stage ROM, but would be inappropriate for the ROM0 in dual-ROM designs. For example, the (first-stage) ROM, after performing the required low-level setup of the hardware, splits into one of two libraries, boot_creator_fw or boot_second_rom, in single-stage ROM and dual-stage ROM designs, respectively. In the latter case, the boot_creator_fw library is instead executed by second-stage ROM.

Note: There also exist minimal, non-production-ready ROM images in //sw/device/lib/testing/test_rom and //sw/device/lib/testing/test_second_rom. These images enable fewer security features and are intended for testing and debugging only. While the Bazel infrastructure does allow setting rom and second_rom separately in a test target, the test- and production-ROM images are not designed to be compatible with each other.

Dependencies

The code included by both ROM stages is mostly contained within the //sw/device/silicon_creator directory, with the following exceptions:

  • Base utility functions from //sw/device/lib/base.
  • Design-specific memory layout information from the device tables (//hw/top/dt/<hwip>.h).
  • Autogenerated register definitions for the target design (//hw/top:<hwip>_regs.h).

Manufacturing-specific Behavior

During provisioning, certain security features are disabled to facilitate testing and bring-up of the chip.

Notably:

  • The alert handler will not be configured or enabled in any of the TEST\_UNLOCKED lifecycle states.
  • Secure boot of the Silicon Creator firmware is disabled until the CREATOR_SW_CFG_ROM_SECURE_BOOT_EN OTP flag is set by the provisioning flow.

Boot Flow

The following sequence of events is executed in order. ID labels are assigned to each step for reference.

Steps executed in ROM / ROM0

The following steps are executed in both the single-stage ROM and in ROM0 in the dual-stage ROM.

ROM.ASM-RESET-START

  • Clear all machine defined interrupts.
  • Zero all CPU Registers.

ROM.ASM-AST-INIT

  • Copy the AST values from the CREATOR_SW_CFG_AST_CFG OTP words to the AST.

ROM.ASM-SRAM-INIT

  • Turn on the minimum level of entropy required to initialize memory scrambling.
  • Enable SRAM scrambling and initialize SRAM.

ROM.ASM-PMP-INIT

  • Initialize the RISC-V physical memory protection (ePMP).

The basic configuration is:

  • ReadExecute for the ROM .text section (executable code).
  • ReadOnly for non-executable regions of the ROM.
  • ReadWrite for main SRAM and memory-mapped hardware registers.

See here for details about the ePMP management.

ROM.ASM-CRT-INIT

  • Zero the .bss region and copy the .data region to RAM.
  • Initialize stack pointer and global pointer.
  • Load the interrupt vector into mtvec.
  • Jump to rom_main, which is implemented in C.

ROM.SEC-MMIO-INIT

  • Initialize the sec_mmio library. Rescan any OTPs read prior to this point to load the expectations into sec_mmio’s register tracking.

ROM.WATCHDOG-INIT

  • Initialize the watchdog timer to instigate a reset after the number of cycles given in the OWNER_SW_CFG_ROM_WATCHDOG_BITE_THRESHOLD_CYCLES OTP item.

ROM.PINMUX-INIT

  • Initialize pinmux to allow UART Output and reading of the strap pins.

ROM.UART-INIT

  • Initialize the UART. The baud rate is chosen based on both the top-level design and target platform (e.g. FPGA).
  • Print a banner to the UART that provides design/SKU information.

ROM.SHUTDOWN-INIT

  • Initialize the shutdown module with values from OTP.
  • Loads alert configurations and alert class configurations from OTP into the alert handler block.

See the here for details about the shutdown procedure.

ROM.FLASH-INIT

  • In designs with onboard flash, check that the flash hardware has finished initializing its scrambling parameters by waiting for FLASH_CTRL.STATUS.INIT_WIP to be zero.

ROM.RST-REASON-INIT

  • Read the reset reason.
  • If the reset reason indicates a power-on reset, initialize the retention SRAM.
  • Clear the reset reason from the reset manager.

ROM.BOOTSTRAP-MODE

  • In designs with onboard flash, read the value of the bootstrapping GPIO pins.
    • If the signal read from GPIO indicates a bootstrap request and bootstrap is permitted (via OTP ROM_BOOTSTRAP_DIS), perform the bootstrap protocol.
    • Otherwise, continue the normal boot process.

See here for details about the bootstrap protocol.

ROM.KEYMGR-INIT

  • Initialize the key manager.

Steps executed in ROM0 only

The following steps are executed by ROM0, only in the dual-stage ROM, directly after the above steps.

ROM.ROM-PATCH-VERIFY

  • Check for the existence of a ROM1 patch, which may be located in OTP or external flash, depending on the design.
  • If a patch exists, perform the following checks to verify its correctness:
    • Verify the correctness of the magic number (PVRP in ASCII).
    • Verify the signature on the ROM1 patch as specified in the signature verification specification.
    • If validation fails, exit rom_main with kErrorRomBootFailed, thus entering ROM.SHUTDOWN.
    • If validation succeeds, proceed to the next step.
  • If no patch exists, skip to ROM.BOOT-ROM1.

ROM.ROM-PATCH-APPLY

  • Apply the ROM patch by mapping the address range(s) specified by the patch to the corresponding address ranges in the patch memory, using Ibex’s address translation feature.

ROM.BOOT-ROM1

  • Configure ePMP to prepare for execution of ROM1. See [TODO] for details.
  • Verify sec_mmio expectations and ePMP configuration.
  • Jump to the ROM1.

Steps executed in ROM1 only

The following steps are executed by ROM1, only in the dual-stage ROM.

ROM.EPMP-ADVANCE

  • Lock access to the ROM0 memory regions in ePMP.

Steps executed in ROM / ROM1

The following steps are executed in both the single-stage ROM (after ROM.KEYMGR-INIT) and in ROM1 in the dual-stage ROM.

ROM.BOOT-POLICY-READ

  • In designs with onboard flash, read the boot policy from the FlashInfo region. Determine the parameters that will control the boot slot priority, temporary side override and any anti-rollback parameters.

ROM.SIG-VERIFY

  • Using the boot policy (if present), find and examine the manifest header for the silicon creator firmware. Depending on the top-level design, the silicon creator firmware may reside in internal flash, external flash, or CTN SRAM.
    • Verify the silicon creator firmware using the following procedure:
    • Verify the correctness of the magic number (PVSC in ASCII).
    • Verify header fields in the manifest against the boot policy (if present): code boundaries, code start address, anti-rollback parameters, etc.
    • Verify the signature over the silicon creator firmware as specified in the signature verification specification.
    • If validation fails, exit main with kErrorRomBootFailed, thus entering ROM.SHUTDOWN.
    • If validation succeeds, proceed to the next step.

ROM.BOOT-CREATOR-FIRMWARE

  • Diversify the key manager with the software binding tag from the validated manifest.
  • Update the ePMP configuration to prepare for execution of the silicon creator firmware.
  • In designs with onboard flash, unlock flash execution in the flash controller.
  • Verify sec_mmio expectations and ePMP configuration.
  • Jump to the silicon creator firmware at the entry point specified by its manifest.

Executed by ROM / ROM0 / ROM1 on shutdown

ROM.SHUTDOWN may be executed by any ROM stage if the secure boot process fails.

ROM.SHUTDOWN

  • Shutdown the chip according to the shutdown specification.
  • Print the boot fault code to the UART.
  • Initiate a shutdown via the alert handler (software triggerable alert).
  • In the event the alert handler fails to trigger shutdown, perform a best-effort shutdown using the following procedure:
    • Advance the all slots of the key manager to the Disabled state to prevent any further use of device identifying secrets until the next reset.
    • Disable access to flash, if applicable.
    • Reconfigure ePMP to disable access to everything but the shutdown infinite loop.
    • Scramble SRAM.
    • Hang (wfi) and wait for a watchdog reset.