Arm security firmware configuration method and apparatus applied to arm server
By configuring the registers of PCI devices in the ARM security firmware of the ARM server and adding AER error identification information, the downtime problem of ARM server restarting under the cloud disk system is solved, and the normal restart and use of the ARM server is achieved.
Patent Information
- Application Number
- PCT/CN2024/099921
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-30
- Filing Date
- 2024-06-18
- Publication Date
- 2025-06-05
AI Technical Summary
When restarting the cloud disk system of the ARM server, the crash will occur, resulting in the T4 card under the cloud disk system being unable to restart and the entire ARM server also being down and unable to use normally.
By calling the ARM security firmware of the ARM server, the space registers are configured for PCI devices at N levels under the PCI link bridge and PCI link bridge, and the AER error identification information of all CPUs of the ARM server is added in the ARM security firmware.
It effectively solves the downtime problem of ARM server when restarting under cloud disk system, and ensures the normal restart and use of T4 card and the entire ARM server.
Smart Images

Figure CN2024099921_05062025_PF_FP_ABST
Abstract
Description
ARM security firmware configuration method and device applied to ARM server
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to a Chinese patent application filed with the Patent Office of China on November 30, 2023, with application number 202311628371.X, entitled “ARM Security Firmware Configuration Method and Device for ARM Servers,” the entire contents of which are incorporated herein by reference. Technical Field
[0003] The present application relates to the field of chip technology, and in particular to an ARM security firmware configuration method and device applied to an ARM server. Background Art
[0004] Internet customers purchasing ARM (Advanced RISC Machines) servers not only support replacing the storage and cloud services of traditional X86 servers, but also support functional replacement in the AI (Artificial Intelligence) field. For example, a physical configuration based on an ARM server with a T4 card and a DPU (Graphics Processing Unit) card is used. In this configuration, customers typically install the DPU's hard drive as a virtual cloud disk and initialize all PCI peripherals in the ARM server within the DPU's virtual cloud disk system. Because the DPU supports the installation and use of multiple virtual cloud disks, the PCI peripherals in the ARM server can be used by different cloud disk systems at any time. After use in one cloud disk system, the PCI device, such as the T4 card, needs to be restarted. Only after the T4 card restarts can the physical T4 card be used normally in another cloud disk system.
[0005] However, when the ARM server's cloud disk system is restarted, a crash occurs, causing the T4 card in the cloud disk system to be unable to restart and the entire ARM server to crash and be unable to be used normally.
[0006] Summary of the Invention
[0007] The embodiments of the present application provide an ARM security firmware configuration method and device applied to an ARM server to solve the problem in the related art that when the ARM server is restarted under the cloud disk system, a crash occurs, resulting in the T4 card under the cloud disk system being unable to restart and the entire ARM server also crashing and unable to be used normally.
[0008] In order to solve the above technical problems, the embodiments of the present application are implemented as follows:
[0009] In a first aspect, an embodiment of the present application provides an ARM secure firmware configuration method applied to an ARM server, the method comprising:
[0010] Call the ARM security firmware of the ARM server to configure the space registers of the PCI link bridge and the N layers of PCI devices under the PCI link bridge. The ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
[0011] Add AER error identification information for all CPUs in ARM servers to the ARM security firmware.
[0012] In some embodiments, the ARM security firmware of the ARM server is called to configure space registers of the PCI link bridge and the N levels of PCI devices under the PCI link bridge, including:
[0013] During the loading and startup process of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridges and N-level PCI devices of all CPUs to obtain the scan results;
[0014] When the scanning result indicates that there are N levels of PCI devices under the PCI link bridge, space registers are configured for the N levels of PCI devices under the PCI link bridge.
[0015] In some embodiments, configuring space registers for PCI devices at N levels below the PCI link bridge includes:
[0016] Initialize N layers of PCI devices under the PCI link bridge;
[0017] Configure space registers for N levels of PCI devices under the PCI link bridge.
[0018] In some embodiments, before calling the ARM security firmware to scan the PCI link bridge and N-level PCI devices on all CPUs and obtaining the scan results, the following steps are included:
[0019] In response to the ARM server being started and the BIOS being loaded successfully, loading the ARM security firmware;
[0020] Perform secure boot verification on ARM security firmware;
[0021] In response to the ARM security firmware successfully performing secure boot verification, the ARM security firmware is memory initialized.
[0022] In some embodiments, the ARM security firmware is called to scan the PCI link bridges and N-level PCI devices of all CPUs, and the scan results include:
[0023] In response to the completion of the ARM security firmware memory initialization, the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scan results;
[0024] Configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
[0025] In some embodiments, calling the ARM security firmware to scan the PCI link bridges and N-level PCI devices on all CPUs also includes:
[0026] The PCI link bridge and N-level PCI devices are scanned according to the splitting status of the PCI link bridge.
[0027] In some embodiments, configuring space registers for PCI devices at N levels below the PCI link bridge includes:
[0028] In the PCI configuration space, space registers are configured for each of the N levels of PCI devices under the PCI link bridge.
[0029] In some embodiments, after calling the ARM security firmware to scan the PCI link bridges and N-level PCI devices on all CPUs and obtaining the scan results, the method further includes:
[0030] When the scanning result indicates that the level of the PCI devices under the PCI link bridge is less than N, a register configuration space corresponding to the PCI link bridge is reserved in the PCI configuration space.
[0031] In some embodiments, after reserving register configuration space corresponding to the PCI link bridge in the PCI configuration space, the method further includes:
[0032] The space registers of the N levels of PCI devices subsequently connected are configured in the reserved register configuration space.
[0033] In some embodiments, AER error identification information of all CPUs of the ARM server is added to the ARM secure firmware, including:
[0034] Get the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs;
[0035] In the ARM security firmware, add AER error identification information for all PCI devices under the link bridge under all CPUs.
[0036] In some embodiments, in the ARM security firmware, AER error identification information of all PCI devices under all link bridges under the CPU is added, including:
[0037] Get the AER configuration information of the link bridges under all CPUs;
[0038] In the ARM security firmware, based on the AER configuration information, all PCI devices under the link bridges under all CPUs are initialized to add AER error identification information.
[0039] In some embodiments, after adding the AER error identification information of all CPUs of the ARM server, the method further includes:
[0040] Check whether all PCI devices under the PCI link bridge under the ARM security firmware are configured;
[0041] In response to the configuration of all PCI devices under the PCI link bridge being completed, the UEFI firmware of the ARM server is started, and the virtual cloud disk system is started and loaded.
[0042] In some embodiments, after detecting whether all PCI devices under the PCI link bridges under the ARM security firmware are configured, the method further includes:
[0043] In response to the presence of an unconfigured PCI link bridge among all the PCI devices under the PCI link bridges, acquiring the PCI devices under the unconfigured PCI link bridge;
[0044] Register configuration and AER error identification information are added to the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge in sequence.
[0045] In some embodiments, after starting the UEFI firmware of the ARM server and starting to load the virtual cloud disk system, the following steps are further included:
[0046] After restarting the PCI device and the virtual cloud disk system, determine whether the ARM server has experienced a downtime.
[0047] In response to the ARM server not experiencing a downtime phenomenon, it is determined that the ARM security firmware is configured successfully.
[0048] In some embodiments, when the PCI device and the virtual cloud disk system are restarted, determining whether the ARM server is down includes:
[0049] If the PCI device does not experience any restart or downtime issues, and the virtual cloud disk operating system does not experience any restart or downtime issues, it is determined that the ARM server has not experienced any downtime.
[0050] In some embodiments, after determining whether the ARM server is down, the method further includes:
[0051] In response to a downtime phenomenon of the ARM server, a downtime alarm message is output.
[0052] In some embodiments, the ARM server includes at least one CPU.
[0053] In a second aspect, an embodiment of the present application provides an ARM secure firmware configuration device applied to an ARM server, the device comprising:
[0054] A register configuration module is used to call the ARM security firmware of the ARM server to configure space registers for the PCI link bridge and N layers of PCI devices under the PCI link bridge. The ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
[0055] The AER information adding module is used to add AER error identification information of all CPUs of the ARM server in the ARM security firmware.
[0056] In some embodiments, the register configuration module includes:
[0057] A scanning result acquisition unit is used to call the ARM security firmware during the loading and startup process of the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results;
[0058] The space register configuration unit is used to configure space registers for the N levels of PCI devices under the PCI link bridge when the scanning result indicates that there are N levels of PCI devices under the PCI link bridge.
[0059] In some embodiments, the space register configuration unit includes:
[0060] The PCI device initialization subunit is used to initialize the N layers of PCI devices under the PCI link bridge;
[0061] The space register configuration subunit is used to configure the space registers of the N layers of PCI devices under the PCI link bridge.
[0062] In some embodiments, the apparatus comprises:
[0063] An ARM security firmware loading module, configured to load the ARM security firmware in response to the ARM server being started and the BIOS being loaded successfully;
[0064] Secure boot verification module, used to perform secure boot verification on ARM security firmware;
[0065] The memory initialization module is used to initialize the memory of the ARM security firmware in response to the success of the secure boot verification of the ARM security firmware.
[0066] In some embodiments, the scanning result obtaining unit includes:
[0067] A scanning result acquisition subunit is used to call the ARM security firmware in response to the completion of the ARM security firmware memory initialization, perform a PCI link bridge scan and N-level PCI device scan on all CPUs, and obtain a scanning result;
[0068] The PCI configuration space configuration subunit is used to configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
[0069] In some embodiments, the space register configuration unit includes:
[0070] The register configuration subunit is used to configure space registers for N levels of PCI devices under the PCI link bridge in the PCI configuration space.
[0071] In some embodiments, the apparatus further comprises:
[0072] The configuration space reservation module is used to reserve register configuration space corresponding to the PCI link bridge in the PCI configuration space when the scanning result indicates that the level of the PCI device under the PCI link bridge is less than N.
[0073] In some embodiments, the AER information adding module includes:
[0074] A PCI device acquisition unit is used to acquire the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs;
[0075] The AER information adding unit is used to add AER error identification information of all PCI devices under the link bridges under all CPUs in the ARM security firmware.
[0076] In some embodiments, the AER information adding unit includes:
[0077] The configuration information acquisition subunit is used to obtain the AER configuration information of the link bridges under all CPUs;
[0078] The AER information adding subunit is used to initialize all PCI devices under the link bridges under all CPUs in the ARM security firmware based on the AER configuration information to add AER error identification information.
[0079] In some embodiments, the apparatus further comprises:
[0080] The configuration completion detection module is used to detect whether the PCI devices under all PCI link bridges under the ARM security firmware are configured;
[0081] The virtual cloud disk system loading module is used to start the UEFI firmware of the ARM server and start loading the virtual cloud disk system in response to the configuration of all PCI devices under the PCI link bridge.
[0082] In some embodiments, the apparatus further comprises:
[0083] an unconfigured device acquisition module, configured to acquire the PCI devices under the unconfigured PCI link bridge in response to the presence of an unconfigured PCI link bridge among the PCI devices under all the PCI link bridges;
[0084] The PCI device configuration module is used to sequentially configure registers of an unconfigured PCI link bridge and PCI devices under the unconfigured PCI link bridge and add AER error identification information.
[0085] In some embodiments, the apparatus further comprises:
[0086] A downtime determination module is used to determine whether the ARM server has experienced a downtime phenomenon when restarting the PCI device and restarting the virtual cloud disk system;
[0087] The configuration success determination module is used to determine that the ARM security firmware is successfully configured in response to the ARM server not experiencing a downtime phenomenon.
[0088] In a third aspect, an embodiment of the present application provides an electronic device, including:
[0089] A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, any one of the above-mentioned ARM secure firmware configuration methods applied to an ARM server is implemented.
[0090] In a fourth aspect, an embodiment of the present application provides a computer non-volatile readable storage medium, which, when the instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to execute any of the above-mentioned ARM security firmware configuration methods applied to an ARM server.
[0091] In an embodiment of the present application, by calling the ARM security firmware of the ARM server, the PCI link bridge and the PCI device configuration space registers of N levels under the PCI link bridge are configured. The ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3. In the ARM security firmware, the AER error identification information of all CPUs of the ARM server is added. In the embodiment of the present application, by increasing the scanning level of the PCI link bridge and PCI devices in the ATF firmware and configuring the register settings, at the same time, whether it is a single-channel or dual-channel server, each PCI link bridge and PCI device of all CPUs needs to be added to the ATF to add the AER error information identification function, which can effectively solve the problem of restarting under the DPU virtual cloud disk system or restarting the PCI device under the DPU virtual cloud disk system.
[0092] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0093] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0094] FIG1 is a flowchart of a method for configuring ARM secure firmware for an ARM server according to an embodiment of the present application;
[0095] FIG2 is a flowchart of a method for configuring a space register according to an embodiment of the present application;
[0096] FIG3 is a flowchart of another method for configuring a space register according to an embodiment of the present application;
[0097] FIG4 is a flowchart of the steps of an ARM secure firmware startup method provided in an embodiment of the present application;
[0098] FIG5 is a flowchart of a method for configuring a PCI configuration space according to an embodiment of the present application;
[0099] FIG6 is a flowchart of a method for adding AER error identification information according to an embodiment of the present application;
[0100] FIG7 is a flowchart of another method for adding AER error identification information provided by an embodiment of the present application;
[0101] FIG8 is a flowchart of a method for configuring a PCI device according to an embodiment of the present application;
[0102] FIG9 is a flowchart of a method for determining successful configuration of an ARM secure firmware according to an embodiment of the present application;
[0103] FIG10 is a flowchart of restarting a PCI device under an ARM server support system provided in an embodiment of the present application;
[0104] FIG11 is a schematic diagram of a hardware architecture provided in an embodiment of the present application;
[0105] FIG12 is a schematic diagram of the structure of an ARM security firmware configuration device applied to an ARM server provided in an embodiment of the present application;
[0106] FIG13 is a schematic structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0107] ARM architecture processor firmware can be divided into two parts, one is the ATF (Arm Trusted Firmware) firmware unique to the ARM architecture, and the other is the traditional UEFI firmware. UEFI firmware is required to be supported by any architecture processor and has unified various standard protocols, while ATF firmware is unique to the ARM architecture. ATF firmware involves ARM's secure boot verification, memory initialization, PCI (Peripheral Component Interconnect) link initialization and hot plugging and other basic functions of PCI devices. In the ATF firmware, the initialization of the PCI link involves one level, that is, the root bridge of the PCI link of the CPU (Central Processing Unit) and the PCI devices under the root bridge are initialized. In the DPU (Data Processing Unit) of the ARM server, the root bridge and the PCI devices under the root bridge are initialized. In the Data Processor (Data Processor) virtual system, the T4 card is a second-level PCI device under the PCI device in the DPU virtual cloud disk system, rather than a first-level PCI device under the PCI link bridge in the ARM system. This results in no downtime when restarting the T4 card in a non-DPU virtual cloud disk system in the ARM server system, but a downtime problem will occur when restarting the T4 card in the DPU virtual cloud disk system in the ARM system. This is because the PCI device level of the T4 card in different systems is different, and the initialization of ATF does not take into account the requirements of the second-level or even third-level PCI restart settings. At this time, ATF needs to perform multi-level PCI device initialization and register setting enablement. In addition to adding the PCI link initialization level in ATF, it is also necessary to add the AER identification function of the PCI device. If it is not added, an AER (Advanced Error Reporting) error will be generated, causing the system to continue to crash. Because ARM servers support both single-channel and dual-channel booting, if only the PCI AER error identification information of the single channel, i.e. CPU0, is added in ATF, then the restart of the T4 card device will still result in an error during single-channel or dual-channel booting. Therefore, it is necessary to add the PCI AER error identification information setting for dual-channel booting in ATF. On this basis, after single-channel or dual-channel booting, the restart setting of the T4 card under the DPU virtual cloud disk system will not cause the AER crash problem. Therefore, based on the above two adjustments in the ATF firmware, the technical problem of the crash of the PCI device when restarting under the ARM server DPU virtual cloud disk system can be solved.
[0108] Next, the technical solutions of the embodiments of the present application are described in detail with reference to specific embodiments.
[0109] 1 , a flowchart of the steps of an ARM security firmware configuration method applied to an ARM server provided in an embodiment of the present application is shown. As shown in FIG1 , the ARM security firmware configuration method applied to an ARM server may include: step 101 and step 102 .
[0110] Step 101: Call the ARM security firmware of the ARM server to configure space registers for the PCI link bridge and N layers of PCI devices under the PCI link bridge. The ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3.
[0111] The embodiments of the present application can be applied to increase the scanning level of the CPU's PCI link and PCI device to multiple levels in the ARM security firmware part, and add the AER error information recognition function to the PCI link bridges and PCI devices of all CPUs to solve the scenario of restarting the PCI device under the system or the downtime problem when the system restarts.
[0112] The embodiments of the present application can be applied to an ARM server, that is, the execution subject is an ARM server, wherein the ARM server may include: a BIOS (Basic Input Output System), in which ARM security firmware (i.e., ATF (firmware) and UEFI firmware are set.
[0113] In a specific implementation, after the ARM server is powered on, the BIOS can be loaded first, followed by the ARM secure firmware. During the loading and startup process of the ARM secure firmware, the ARM secure firmware configures the space registers of the PCI link bridge and the N layers of PCI devices under the PCI link bridge. Where N is a positive integer greater than or equal to 3.
[0114] In a specific implementation, during the ARM secure firmware loading and startup process, the ARM secure firmware can be called to scan all CPUs (i.e., all CPUs in the ARM server, which can be a single CPU or multiple CPUs) for PCI link bridges and multi-level PCI devices, and then configure the space registers for the scanned multi-level PCI devices. This implementation process is described in detail below with reference to Figure 2.
[0115] 2 , there is shown a flowchart of the steps of a space register configuration method provided by an embodiment of the present application. As shown in FIG2 , the space register configuration method may include: step 201 and step 202 .
[0116] Step 201: During the loading and startup process of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridges and N-level PCI devices of all CPUs to obtain the scan results.
[0117] In this embodiment, after loading the BIOS, the ARM security firmware can be loaded. During the loading and startup process of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridges and N layers of PCI devices of all CPUs to obtain the scan results. Specifically, the ARM security firmware can scan all link bridges under the CPU and the N layers of PCI devices under each link bridge to obtain the scan results.
[0118] In a specific implementation, when performing a security scan, the ARM security firmware can be loaded first and a secure boot check and memory initialization can be performed before the scan is performed. This implementation process can be described in detail below in conjunction with FIG4 .
[0119] 4 , a flowchart of a method for configuring a PCI configuration space according to an embodiment of the present invention is shown. As shown in FIG4 , the method for configuring a PCI configuration space may include: step 401 , step 402 , and step 403 .
[0120] Step 401: Load the ARM security firmware.
[0121] In this embodiment, after loading the BIOS, the ARM security firmware may be loaded.
[0122] After the ARM security firmware is loaded, step 402 is executed.
[0123] Step 402: Perform secure boot verification on the ARM security firmware.
[0124] After loading the ARM security firmware, a secure boot check can be performed on the ARM security firmware to verify whether the ARM security firmware is securely booted. If the ARM security firmware is not securely booted, the process ends. If the ARM security firmware is securely booted, step 403 is executed.
[0125] Step 403: In response to the ARM security firmware successfully performing secure boot verification, the ARM security firmware is memory initialized.
[0126] After the secure boot verification of the ARM security firmware is successful, the memory of the ARM security firmware can be initialized to configure memory space for the ARM security firmware to facilitate the subsequent configuration of space registers.
[0127] After completing the above security verification and memory initialization, the ARM security firmware can be called to perform the scanning process. At the same time, the PCI configuration space corresponding to the PCI link bridge can be configured to provide memory for the subsequent configuration of the space registers. The implementation process can be described in detail below with reference to Figure 5.
[0128] 5 , a flowchart of a method for configuring a PCI configuration space according to an embodiment of the present invention is shown. As shown in FIG5 , the method for configuring a PCI configuration space may include: step 501 and step 502 .
[0129] Step 501: In response to the completion of the memory initialization of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scan results.
[0130] In an embodiment of the present application, after the ARM security firmware memory is initialized, the ARM security firmware can be called to scan the PCI link bridge and N levels of PCI devices on all CPUs to obtain the scan results.
[0131] Step 502: Configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
[0132] Then, a PCI configuration space corresponding to the PCI link bridge may be configured in the initial memory, and the PCI configuration space may be used to configure space registers of subsequent PCI devices.
[0133] After the ARM security firmware is called to scan the PCI link bridges and N-level PCI devices of all CPUs and the scan results are obtained, step 202 is executed.
[0134] Step 202: When the scanning result indicates that there are N levels of PCI devices under the PCI link bridge, configure space registers for the N levels of PCI devices under the PCI link bridge.
[0135] After invoking the ARM security firmware to scan the PCI link bridge and N layers of PCI devices across all CPUs and obtaining scan results, if the scan results indicate the presence of N layers of PCI devices under the PCI link bridge, space registers for the N layers of PCI devices under the PCI link bridge can be configured. Specifically, the N layers of PCI devices under the PCI link bridge can be initialized and space registers configured. This implementation process is described in detail below with reference to Figure 3.
[0136] 3 , there is shown a flowchart of another method for configuring a space register according to an embodiment of the present application. As shown in FIG3 , the method for configuring a control register may include: step 301 and step 302 .
[0137] Step 301: Initialize N layers of PCI devices under the PCI link bridge.
[0138] In this embodiment, when the scanning result indicates that there are N levels of PCI devices under the PCI link bridge, the N levels of PCI devices under the PCI link bridge may be initialized.
[0139] Step 302: Configure space registers for N levels of PCI devices under the PCI link bridge.
[0140] During the initialization process, the space registers of the PCI devices at N levels below the PCI link bridge can be configured. That is, the space registers of the PCI devices can be written into the corresponding space during the initialization process.
[0141] This application can solve the problem of PCI device crash when restarting in DPU virtual cloud disk system under ARM server system by enabling multi-level PCI device initialization and register setting of ATF.
[0142] When configuring space registers for N levels of PCI devices under the PCI link bridge respectively, since the PCI configuration space has been configured in the memory of the initialized ARM security firmware, the space registers for the N levels of PCI devices under the PCI link bridge can be configured respectively in the PCI configuration space.
[0143] In a specific implementation of the present application, if the scan result indicates that the number of PCI devices under the PCI link bridge is less than N, register configuration space corresponding to the PCI link bridge is reserved within the PCI configuration space. By reserving the register configuration space, when multiple PCI devices are subsequently connected, the space registers of the connected PCI devices can be configured promptly within the reserved register configuration space.
[0144] After the ARM security firmware of the ARM server is called to configure space registers for the PCI link bridge and the N levels of PCI devices under the PCI link bridge, step 102 is executed.
[0145] Step 102: Add AER error identification information of all CPUs of the ARM server to the ARM security firmware.
[0146] After calling the ARM security firmware of the ARM server to configure the space registers of the PCI link bridge and the N layers of PCI devices under the PCI link bridge, the AER error identification information of all CPUs of the ARM server can be added to the ARM security firmware.
[0147] The embodiment of the present application adds AER error identification information to all CPUs of the ARM server. On this basis, after single-channel or dual-channel startup, the restart setting such as T4 card in the DPU virtual cloud disk system will not cause AER downtime problem.
[0148] In a specific implementation, when adding AER error identification information, the corresponding AER error identification information can be added to all PCI devices under the link bridges under all CPUs in the ARM security firmware. The implementation process can be described in detail below with reference to FIG6 .
[0149] 6 , a flowchart of a method for adding AER error identification information according to an embodiment of the present application is shown. As shown in FIG6 , the method for adding AER error identification information may include: step 601 and step 602 .
[0150] Step 601: Acquire the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs.
[0151] In an embodiment of the present application, when adding AER error identification information, the link bridges under all CPUs of the ARM server can be obtained.
[0152] In this example, the ARM server may have only one CPU, two CPUs, or four CPUs, etc. Specifically, the number of CPUs in the ARM server may be determined according to actual conditions, and this embodiment does not impose any limitation on this.
[0153] After obtaining the link bridges under all CPUs of the ARM server, a PCI device scan may be performed on the link bridge under each CPU to obtain all PCI devices under the link bridges under all CPUs.
[0154] After obtaining the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs, step 602 is executed.
[0155] Step 602: Add AER error identification information of all PCI devices under the link bridges under all CPUs in the ARM security firmware.
[0156] After obtaining the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs, AER error identification information of all PCI devices under the link bridges under all CPUs can be added to the ARM security firmware.
[0157] In the embodiment of the present application, AER error identification information is added for both single-channel and dual-channel servers, thereby solving the problem of AER downtime caused by restart settings such as T4 cards in the DPU virtual cloud disk system after the ARM server is started.
[0158] In a specific implementation, when adding AER error identification information, the AER configuration information of the link bridges under all CPUs can be obtained, and the AER error identification information can be added based on the AER configuration information. The implementation process can be described in detail below with reference to FIG7 .
[0159] 7 , there is shown a flowchart of another method for adding AER error identification information provided by an embodiment of the present application. As shown in FIG7 , the method for adding AER error identification information may include: step 701 and step 702 .
[0160] Step 701: Acquire the AER configuration information of the link bridges under all CPUs.
[0161] In an embodiment of the present application, after obtaining the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs, the AER configuration information of the link bridges under all CPUs can be obtained.
[0162] After the AER configuration information of the link bridges under all CPUs is obtained, step 702 is executed.
[0163] Step 702: In the ARM security firmware, based on the AER configuration information, all PCI devices under the link bridges under all CPUs are initialized to add AER error identification information.
[0164] After obtaining the AER configuration information of the link bridges under all CPUs, all PCI devices under the link bridges under all CPUs can be initialized in the ARM security firmware based on the AER configuration information to add AER error identification information.
[0165] The embodiment of the present application adds AER error identification information to all PCI devices under the link bridge in combination with AER configuration information, thereby meeting the function of restarting the normal use of PCI devices in a multi-level system.
[0166] In a specific implementation, after adding the AER error identification information of all CPUs in the ARM server, it is possible to check whether all PCI devices under the PCI link bridges under the ARM security firmware are configured. If all PCI devices under the PCI link bridges are configured, the UEFI firmware of the ARM server can be started and the virtual cloud disk system (such as the DPU virtual cloud disk system) can be started.
[0167] If there is an unconfigured PCI link bridge among all the PCI devices under the PCI link bridge, the configuration process will continue for the unconfigured PCI link bridge.
[0168] 8 , a flowchart of a method for configuring a PCI device according to an embodiment of the present invention is shown. As shown in FIG8 , the method for configuring a PCI device may include: step 801 and step 802 .
[0169] Step 801: In response to the existence of an unconfigured PCI link bridge among the PCI devices under all PCI link bridges, obtain the PCI devices under the unconfigured PCI link bridge.
[0170] In this embodiment, when there is an unconfigured PCI link bridge among the PCI devices under all PCI link bridges, the PCI devices under the unconfigured PCI link bridge can be acquired.
[0171] Step 802: sequentially configure registers of the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge and add AER error identification information.
[0172] Furthermore, register configuration and AER error identification information addition can be performed on the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge in sequence.
[0173] The embodiment of the present application can avoid the omission of PCI link bridges or PCI devices by detecting unconfigured PCI link bridges, which may cause the PCI devices under the PCI link bridge to crash due to the failure to perform the above configuration.
[0174] In a specific implementation, after starting the virtual cloud disk system, it is possible to determine whether the ARM server has experienced a downtime phenomenon when restarting the PCI device and restarting the virtual cloud disk system. This implementation process can be described in detail below in conjunction with FIG9 .
[0175] 9 , a flowchart of a method for determining configuration completion according to an embodiment of the present application is shown. As shown in FIG9 , the method for determining configuration completion may include: step 901 and step 902 .
[0176] Step 901: When the PCI device and the virtual cloud disk system are restarted, determine whether the ARM server is down.
[0177] In this embodiment, after the virtual cloud disk system is loaded, the PCI device can be restarted on the ARM server, and the virtual cloud disk system can be restarted to detect whether the ARM server has crashed. Specifically, after the DPU virtual cloud disk operating system is running, a system-run PCI command is used to restart the PCI device, such as the T4 card, and then a system command is used to restart the DPU virtual cloud disk operating system. Simultaneously, the ARM server is checked for crashes.
[0178] Step 902: In response to the ARM server not experiencing a downtime phenomenon, it is determined that the ARM security firmware is configured successfully.
[0179] If it is determined that the ARM server has not crashed, it can be determined that the ARM security firmware has been configured successfully and the problem of PCI device crashes after restarting has been completely solved.
[0180] Of course, if the ARM server still crashes, it may be due to other reasons. At this time, a crash alarm message can be output to prompt the operation and maintenance personnel to find the cause of the crash.
[0181] The process of restarting the PCI device in the ARM server support system can be described in detail with reference to FIG10 .
[0182] 10, a flowchart of restarting a PCI device in an ARM server support system provided by an embodiment of the present application is shown. As shown in FIG10, the process may include the following steps:
[0183] Step 1: The ARM server (in this example, an ARM server with a dual-boot mechanism) is powered on and the BIOS firmware is loaded, with the ATF image firmware being loaded first.
[0184] Step 2: During the ATF loading and startup process, after the secure boot and memory initialization are complete, the PCI link initialization part is performed. The PCI link bridge and PCI devices are scanned and initialized according to the split of the PCI link bridge. At this time, the ATF changes from scanning and initializing the PCI link bridge and one-level PCI devices to scanning the PCI link and multiple-level PCI devices. If there are multiple levels of devices in the current PCI link, the multi-level PCI device scan and initialization are performed. If there are no multiple levels of devices in the current PCI link, the multi-level scanning PCI device space function is enabled and reserved, that is, the register configuration space is reserved.
[0185] Step 3. After completing step 2 above, you can initialize the AER table of the PCI link bridge (including the AER configuration information of the PCI link bridge). If the AER table is not initialized, the system will crash when the PCI device is restarted. The initialization table needs to initialize the PCI links and PCI devices of both CPUs. If only the PCI link of any one CPU is initialized, the system will crash when the PCI device is restarted. The initialization of the AER table requires setting the AER information of the PCI link and multi-level PCI devices to meet the function of restarting the PCI device for normal use in a multi-level system.
[0186] Step 4: After the ARM server firmware completes initialization of the ATF firmware, it starts the UEFI firmware, continues to boot and enters the DPU virtual cloud disk operating system.
[0187] Step 5. After the DPU virtual cloud disk operating system is running, restart the PCI device T4 card through the system PCI command. No restart downtime problem occurs. Alternatively, restarting the DPU virtual cloud disk operating system through the system command also does not cause restart downtime problem. Therefore, the restart PCI device downtime problem is completely solved.
[0188] Step 6. Of course, if AER error identification information is added to the PCI link bridge and multi-level PCI devices of only one of the two CPUs, after starting and loading the virtual cloud disk system, restarting the PCI device T4 card through the system PCI command will cause a restart and downtime problem, or restarting the DPU virtual cloud disk operating system through the system command will cause a restart and downtime problem.
[0189] In this embodiment, based on the characteristics of the ARM server firmware and the system downtime caused by restarting PCI devices or the virtual cloud disk system in a DPU virtual cloud disk system, the root cause of the problem is determined to be the need for ATF to support multi-level scanning of PCI devices and configure management registers. Furthermore, the phenomenon of AER errors and continued downtime caused by restarting PCI devices or restarting the system in a DPU virtual cloud disk system can be resolved by adding AER error information recognition functionality to the PCI link bridge and PCI devices of CPU0 and PCI in ATF. These two points must be present simultaneously to completely resolve the system downtime caused by restarting PCI devices or restarting the system in a DPU virtual cloud disk system. If either CPU0 or CPU1 has AER error information recognition functionality for the PCI bridge and PCI devices, the downtime problem will continue. Whether the server is a single-socket or dual-socket server, the AER error information recognition functionality must be added to the PCI link bridge and PCI devices of CPU0 and CPU1. Therefore, in the embodiment of the present application, the scanning level of the CPU's PCI link and PCI device is increased to multiple levels in the ATF firmware part, at least 3 levels or above. At the same time, the PCI link bridge and PCI device of CPU0 and CPU1 are added with the AER error information recognition function to solve the problem of restarting the PCI device under the system or the crash when the system is restarted.
[0190] Next, the configuration process is described in detail in conjunction with the hardware architecture.
[0191] Referring to Figure 11, a schematic diagram of a hardware architecture provided by an embodiment of the present application is shown. As shown in Figure 11, the hardware architecture of this embodiment may include: an ARM server and an OS (Operating System) operating system, as well as the BIOS under the ARM server, UTF firmware under the BIOS, and UEFI firmware.
[0192] In the specific process, the ARM server can be started first. After the ARM server is started, the BIOS image can be loaded. Then, the ATF image firmware can be loaded. During the ATF firmware startup process, a secure boot check can be performed. After completion, the memory is initialized.
[0193] After the memory initialization is completed, the PCI link bridge and PCI devices can be initialized. At this time, the PCI link bridge and PCI device multi-level scanning can be performed and the PCI configuration space can be configured.
[0194] Based on the scan results, it is determined whether there are multiple layers of PCI devices under the PCI link bridge. If there are no multiple layers of PCI devices under the PCI link bridge, space for PCI device configuration space registers, i.e., register configuration space, is reserved. If there are multiple layers of PCI devices under the PCI link bridge, the multiple layers of PCI device configuration space registers can be configured.
[0195] Next, you can choose whether to add AER error identification information to the multi-level PCI devices of the PCI link bridge between CPU0 and CPU1. If you choose to add AER error identification information to the multi-level PCI devices of the PCI link bridge between CPU0 and CPU1, the AER table is initialized to set the AER information of the PCI link and the multi-level PCI devices.
[0196] After the ATF firmware is initialized, you can load the UEFI firmware and start loading the DPU virtual cloud disk system.
[0197] Restarting the PCI device T4 card through the system PCI command does not cause the restart downtime problem, or restarting the DPU virtual cloud disk operating system through the system command does not cause the restart downtime problem. Therefore, the restart PCI device downtime problem is completely solved.
[0198] The embodiment of the present application is aimed at the firmware division of ARM architecture servers and the specific practical application of ARM servers. For the downtime problem that occurs when the DPU virtual cloud disk is restarted or the PCI device is restarted under the virtual cloud disk, the PCI link bridge and PCI device are scanned at multiple levels in ATF and the management registers are configured. At the same time, each PCI link bridge and PCI device of CPU0 and CPU1 is added with an AER error information recognition function. If not added, a secondary downtime will occur during the restart. Therefore, this solution can solve the two downtime problems that occur when the system is restarted and the PCI device is restarted. Therefore, this embodiment increases the scanning level of the PCI link bridge and PCI device in the ATF firmware and configures the register settings. At the same time, whether it is a single-channel or dual-channel server, each PCI link bridge and PCI device of PU0 and CPU1 needs to be added with an AER error information recognition function in the ATF, which can completely solve the problem of downtime when the DPU virtual cloud disk system is restarted or the PCI device is restarted under the DPU virtual cloud disk system.
[0199] The embodiment of the present application provides an ARM security firmware configuration method for an ARM server, which configures space registers for the PCI link bridge and the PCI devices of N levels under the PCI link bridge by calling the ARM security firmware of the ARM server. The ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3. In the ARM security firmware, the AER error identification information of all CPUs of the ARM server is added. The embodiment of the present application increases the scanning level of the PCI link bridge and PCI devices in the ATF firmware and configures the register settings. At the same time, whether it is a single-channel or dual-channel server, it is necessary to add the AER error information identification function to each PCI link bridge and PCI device of all CPUs in the ATF, which can effectively solve the problem of restarting under the DPU virtual cloud disk system or restarting the PCI device under the DPU virtual cloud disk system.
[0200] 12, a schematic diagram of the structure of an ARM security firmware configuration device for an ARM server provided by an embodiment of the present application is shown. As shown in FIG12, the ARM security firmware configuration device 1200 for an ARM server may include the following modules:
[0201] The register configuration module 1210 is used to call the ARM security firmware of the ARM server to configure the space registers of the PCI link bridge and the N layers of PCI devices under the PCI link bridge, where the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3;
[0202] The AER information adding module 1220 is used to add the AER error identification information of all CPUs of the ARM server in the ARM security firmware.
[0203] In some embodiments, the register configuration module includes:
[0204] A scanning result acquisition unit is used to call the ARM security firmware during the loading and startup process of the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results;
[0205] The space register configuration unit is used to configure space registers for the N levels of PCI devices under the PCI link bridge when the scanning result indicates that there are N levels of PCI devices under the PCI link bridge.
[0206] In some embodiments, the space register configuration unit includes:
[0207] The PCI device initialization subunit is used to initialize the N layers of PCI devices under the PCI link bridge;
[0208] The space register configuration subunit is used to configure the space registers of the N layers of PCI devices under the PCI link bridge.
[0209] In some embodiments, the apparatus comprises:
[0210] An ARM security firmware loading module, configured to load the ARM security firmware in response to the ARM server being started and the BIOS being loaded successfully;
[0211] Secure boot verification module, used to perform secure boot verification on ARM security firmware;
[0212] The memory initialization module is used to initialize the memory of the ARM security firmware in response to the success of the secure boot verification of the ARM security firmware.
[0213] In some embodiments, the scanning result obtaining unit includes:
[0214] A scanning result acquisition subunit is used to call the ARM security firmware in response to the completion of the ARM security firmware memory initialization, perform a PCI link bridge scan and N-level PCI device scan on all CPUs, and obtain a scanning result;
[0215] The PCI configuration space configuration subunit is used to configure the PCI configuration space corresponding to the PCI link bridge in the initialized memory.
[0216] In some embodiments, the space register configuration unit includes:
[0217] The register configuration subunit is used to configure space registers for N levels of PCI devices under the PCI link bridge in the PCI configuration space.
[0218] In some embodiments, the apparatus further comprises:
[0219] The configuration space reservation module is used to reserve register configuration space corresponding to the PCI link bridge in the PCI configuration space when the scanning result indicates that the level of the PCI device under the PCI link bridge is less than N.
[0220] In some embodiments, the AER information adding module includes:
[0221] A PCI device acquisition unit is used to acquire the link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs;
[0222] The AER information adding unit is used to add AER error identification information of all PCI devices under the link bridges under all CPUs in the ARM security firmware.
[0223] In some embodiments, the AER information adding unit includes:
[0224] The configuration information acquisition subunit is used to obtain the AER configuration information of the link bridges under all CPUs;
[0225] The AER information adding subunit is used to initialize all PCI devices under the link bridges under all CPUs in the ARM security firmware based on the AER configuration information to add AER error identification information.
[0226] In some embodiments, the apparatus further comprises:
[0227] The configuration completion detection module is used to detect whether the PCI devices under all PCI link bridges under the ARM security firmware are configured;
[0228] The virtual cloud disk system loading module is used to start the UEFI firmware of the ARM server and start loading the virtual cloud disk system in response to the configuration of all PCI devices under the PCI link bridge.
[0229] In some embodiments, the apparatus further comprises:
[0230] an unconfigured device acquisition module, configured to acquire the PCI devices under the unconfigured PCI link bridge in response to the presence of an unconfigured PCI link bridge among the PCI devices under all the PCI link bridges;
[0231] The PCI device configuration module is used to sequentially configure registers of an unconfigured PCI link bridge and PCI devices under the unconfigured PCI link bridge and add AER error identification information.
[0232] In some embodiments, the apparatus further comprises:
[0233] A downtime determination module is used to determine whether the ARM server has experienced a downtime phenomenon when restarting the PCI device and restarting the virtual cloud disk system;
[0234] The configuration success determination module is used to determine that the ARM security firmware is successfully configured in response to the ARM server not experiencing a downtime phenomenon.
[0235] The embodiment of the present application provides an ARM security firmware configuration device for an ARM server. By calling the ARM security firmware of the ARM server, the PCI link bridge and the PCI device configuration space registers of N levels under the PCI link bridge are configured. The ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3. In the ARM security firmware, the AER error identification information of all CPUs of the ARM server is added. The embodiment of the present application increases the scanning level of the PCI link bridge and PCI device in the ATF firmware and configures the register settings. At the same time, whether it is a single-channel or dual-channel server, each PCI link bridge and PCI device of all CPUs needs to be added to the ATF to add the AER error information identification function. This can effectively solve the problem of restarting under the DPU virtual cloud disk system or restarting the PCI device under the DPU virtual cloud disk system.
[0236] In addition, an embodiment of the present application also provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the above-mentioned ARM security firmware configuration method applied to the ARM server is implemented.
[0237] Figure 13 shows a schematic diagram of the structure of an electronic device 1300 according to an embodiment of the present application. As shown in Figure 13, the electronic device 1300 includes a central processing unit (CPU) 1301, which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 1302 or computer program instructions loaded from a storage unit 1308 into a random access memory (RAM) 1303. In RAM 1303, various programs and data required for the operation of the electronic device 1300 can also be stored. CPU 1301, ROM 1302, and RAM 1303 are connected to each other via a bus 1304. An input / output (I / O) interface 1305 is also connected to the bus 1304.
[0238] Multiple components in electronic device 1300 are connected to I / O interface 1305, including: an input unit 1306, such as a keyboard, mouse, microphone, etc.; an output unit 1307, such as various types of displays, speakers, etc.; a storage unit 1308, such as a magnetic disk, optical disk, etc.; and a communication unit 1309, such as a network card, modem, wireless communication transceiver, etc. The communication unit 1309 allows electronic device 1300 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0239] The various processes and procedures described above may be executed by the processing unit 1301. For example, the method of any of the above embodiments may be implemented as a computer software program, which is tangibly contained in a computer-readable medium, such as the storage unit 1308. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 1300 via the ROM 1302 and / or the communication unit 1309. When the computer program is loaded into the RAM 1303 and executed by the CPU 1301, one or more actions in the method described above may be performed.
[0240] The present application also provides a non-volatile computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the various processes of the embodiment of the ARM secure firmware configuration method applied to the ARM server, and can achieve the same technical effect. To avoid repetition, it is not repeated here. The non-volatile computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0241] The above are only some embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. An ARM security firmware configuration method applied to an ARM server, characterized in that: The method comprises: Calling the ARM security firmware of the ARM server to configure space registers for the PCI link bridge and N layers of PCI devices under the PCI link bridge, where the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3; In the ARM security firmware, AER error identification information of all CPUs of the ARM server is added.
2. The method according to claim 1, characterized in that The calling of the ARM security firmware of the ARM server to configure space registers of the PCI link bridge and the N levels of PCI devices under the PCI link bridge includes: During the loading and starting process of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results; When the scanning result indicates that there are N levels of PCI devices under the PCI link bridge, the space registers are configured for the N levels of PCI devices under the PCI link bridge.
3. The method according to claim 2, characterized in that The configuring the space registers for the PCI devices of N levels under the PCI link bridge includes: Initializing N layers of PCI devices under the PCI link bridge; The space registers are configured for the N levels of PCI devices under the PCI link bridge.
4. The method according to claim 2, characterized in that: Before calling the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs and obtaining the scan results, the method includes: In response to the ARM server being started and the BIOS being loaded successfully, loading the ARM security firmware; Performing a secure boot check on the ARM security firmware; In response to the ARM security firmware successfully completing the secure boot verification, the ARM security firmware is memory initialized.
5. The method according to claim 4, characterized in that The calling of the ARM security firmware scans the PCI link bridge and N-level PCI devices of all CPUs to obtain the scanning results, including: In response to the completion of memory initialization of the ARM security firmware, the ARM security firmware is called to scan the PCI link bridge and N-level PCI devices of all CPUs to obtain a scan result; A PCI configuration space corresponding to the PCI link bridge is configured in the initialized memory.
6. The method according to claim 5, characterized in that The calling of the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs also includes: The PCI link bridge and N levels of PCI devices are scanned according to the splitting status of the PCI link bridge.
7. The method according to claim 5, characterized in that The configuring the space registers for the PCI devices of N levels under the PCI link bridge includes: In the PCI configuration space, the space registers are respectively configured for the PCI devices of N levels under the PCI link bridge.
8. The method according to claim 5, characterized in that After calling the ARM security firmware to scan the PCI link bridge and N-level PCI devices of all CPUs and obtaining the scan results, the method further includes: When the scanning result indicates that the level of the PCI device under the PCI link bridge is less than N, a register configuration space corresponding to the PCI link bridge is reserved in the PCI configuration space.
9. The method according to claim 8, characterized in that After reserving the register configuration space corresponding to the PCI link bridge in the PCI configuration space, the method further includes: The space registers are configured in the reserved register configuration space for the N layers of PCI devices that are subsequently connected.
10. The method according to claim 1, characterized in that Adding AER error identification information of all CPUs of the ARM server in the ARM security firmware includes: Obtain link bridges under all CPUs of the ARM server and all PCI devices under the link bridges under all CPUs; In the ARM security firmware, AER error identification information of all PCI devices under the link bridges under all CPUs is added.
11. The method according to claim 10, characterized in that In the ARM security firmware, the AER error identification information of all PCI devices under the link bridges under all CPUs is added, including: Obtaining AER configuration information of link bridges under all CPUs; In the ARM security firmware, based on the AER configuration information, all PCI devices under the link bridges under all the CPUs are initialized to add the AER error identification information.
12. The method according to claim 1, characterized in that After the AER error identification information of all CPUs of the ARM server is added, the method further includes: Check whether all PCI devices under the PCI link bridges under the ARM security firmware are configured; In response to the configuration of all PCI devices under the PCI link bridges being completed, the UEFI firmware of the ARM server is started, and the loading of the virtual cloud disk system is started.
13. The method according to claim 12, characterized in that After detecting whether all PCI devices under the PCI link bridges under the ARM security firmware are configured, the method further includes: In response to the PCI devices under all the PCI link bridges having an unconfigured PCI link bridge, acquiring the PCI devices under the unconfigured PCI link bridge; Register configuration and AER error identification information addition are performed on the unconfigured PCI link bridge and the PCI devices under the unconfigured PCI link bridge in sequence.
14. The method according to claim 12, characterized in that After starting the UEFI firmware of the ARM server and starting to load the virtual cloud disk system, it also includes: When the PCI device and the virtual cloud disk system are restarted, determining whether the ARM server is down; In response to the ARM server not experiencing a downtime phenomenon, it is determined that the ARM security firmware is configured successfully.
15. The method according to claim 14, characterized in that In the case of restarting the PCI device and restarting the virtual cloud disk system, determining whether the ARM server is down includes: When the PCI device does not have a restart downtime problem, and the virtual cloud disk operating system also does not have a restart downtime problem, it is determined that the ARM server does not have a downtime phenomenon.
16. The method according to claim 14, characterized in that After determining whether the ARM server is down, the method further includes: In response to a downtime phenomenon of the ARM server, downtime alarm information is output.
17. The method according to claim 1, characterized in that The ARM server includes at least one CPU.
18. An ARM security firmware configuration device applied to an ARM server, characterized in that: The device comprises: A register configuration module is used to call the ARM security firmware of the ARM server to configure the PCI link bridge and the N levels of PCI device configuration space registers under the PCI link bridge, the ARM security firmware is the processor firmware of the ARM server, and N is a positive integer greater than or equal to 3; The AER information adding module is used to add the AER error identification information of all CPUs of the ARM server in the ARM security firmware.
19. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the ARM secure firmware configuration method applied to an ARM server as described in any one of claims 1 to 17 is implemented.
20. A computer non-volatile readable storage medium, characterized in that: When the instructions in the computer non-volatile readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the ARM security firmware configuration method applied to an ARM server as described in any one of claims 1 to 17.
Citation Information
Patent Citations
System and a method for server PCIe equipment to position fault causes
CN109614259A
Start control method, device and equipment for PCI (Peripheral Component Interconnect) equipment in ARM (
CN114185607A
AER function management method and device, server and storage medium
CN114201360A
PCI parameter adjusting method and device of ARM server, computer equipment and medium
CN116700821A
ARM security firmware configuration method and device applied to ARM server
CN117331723A