xref: /kvm-unit-tests/x86/emulator.c (revision 215ad64c5f5c740573febe6dfa20321d14c09cae)
1f1dcfd54SSean Christopherson #include <asm/debugreg.h>
2f1dcfd54SSean Christopherson 
37d36db35SAvi Kivity #include "ioram.h"
47d36db35SAvi Kivity #include "vm.h"
57d36db35SAvi Kivity #include "libcflat.h"
6e7c37968SGleb Natapov #include "desc.h"
7d7143f32SAvi Kivity #include "types.h"
8b39a3e14SNadav Amit #include "processor.h"
9efd8e5aaSPaolo Bonzini #include "vmalloc.h"
105aca024eSPaolo Bonzini #include "alloc_page.h"
113ee1b91bSBin Meng #include "usermode.h"
127d36db35SAvi Kivity 
137d36db35SAvi Kivity #define TESTDEV_IO_PORT 0xe0
147d36db35SAvi Kivity 
153ee1b91bSBin Meng #define MAGIC_NUM 0xdeadbeefdeadbeefUL
163ee1b91bSBin Meng #define GS_BASE 0x400000
173ee1b91bSBin Meng 
18d7143f32SAvi Kivity static int exceptions;
19d7143f32SAvi Kivity 
207d36db35SAvi Kivity static char st1[] = "abcdefghijklmnop";
217d36db35SAvi Kivity 
227db17e21SThomas Huth static void test_stringio(void)
237d36db35SAvi Kivity {
247d36db35SAvi Kivity 	unsigned char r = 0;
257d36db35SAvi Kivity 	asm volatile("cld \n\t"
267d36db35SAvi Kivity 		     "movw %0, %%dx \n\t"
277d36db35SAvi Kivity 		     "rep outsb \n\t"
287d36db35SAvi Kivity 		     : : "i"((short)TESTDEV_IO_PORT),
297d36db35SAvi Kivity 		       "S"(st1), "c"(sizeof(st1) - 1));
307d36db35SAvi Kivity 	asm volatile("inb %1, %0\n\t" : "=a"(r) : "i"((short)TESTDEV_IO_PORT));
31a299895bSThomas Huth 	report(r == st1[sizeof(st1) - 2], "outsb up"); /* last char */
327d36db35SAvi Kivity 
337d36db35SAvi Kivity 	asm volatile("std \n\t"
347d36db35SAvi Kivity 		     "movw %0, %%dx \n\t"
357d36db35SAvi Kivity 		     "rep outsb \n\t"
367d36db35SAvi Kivity 		     : : "i"((short)TESTDEV_IO_PORT),
377d36db35SAvi Kivity 		       "S"(st1 + sizeof(st1) - 2), "c"(sizeof(st1) - 1));
387d36db35SAvi Kivity 	asm volatile("cld \n\t" : : );
397d36db35SAvi Kivity 	asm volatile("in %1, %0\n\t" : "=a"(r) : "i"((short)TESTDEV_IO_PORT));
40a299895bSThomas Huth 	report(r == st1[0], "outsb down");
417d36db35SAvi Kivity }
427d36db35SAvi Kivity 
43db4898e8SThomas Huth static void test_cmps_one(unsigned char *m1, unsigned char *m3)
447d36db35SAvi Kivity {
457d36db35SAvi Kivity 	void *rsi, *rdi;
467d36db35SAvi Kivity 	long rcx, tmp;
477d36db35SAvi Kivity 
487d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 30;
497d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
502d331a4dSRoman Bolshakov 		     "repe cmpsb"
517d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
527d36db35SAvi Kivity 		     : : "cc");
53a299895bSThomas Huth 	report(rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30, "repe/cmpsb (1)");
547d36db35SAvi Kivity 
5551ba4180SAvi Kivity 	rsi = m1; rdi = m3; rcx = 30;
5651ba4180SAvi Kivity 	asm volatile("or $1, %[tmp]\n\t" // clear ZF
572d331a4dSRoman Bolshakov 		     "repe cmpsb"
5851ba4180SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
5951ba4180SAvi Kivity 		     : : "cc");
60a299895bSThomas Huth 	report(rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30,
612d331a4dSRoman Bolshakov 	       "repe cmpsb (1.zf)");
6251ba4180SAvi Kivity 
637d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 15;
647d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
652d331a4dSRoman Bolshakov 		     "repe cmpsw"
667d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
677d36db35SAvi Kivity 		     : : "cc");
682d331a4dSRoman Bolshakov 	report(rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30, "repe cmpsw (1)");
697d36db35SAvi Kivity 
707d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 7;
717d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
722d331a4dSRoman Bolshakov 		     "repe cmpsl"
737d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
747d36db35SAvi Kivity 		     : : "cc");
752d331a4dSRoman Bolshakov 	report(rcx == 0 && rsi == m1 + 28 && rdi == m3 + 28, "repe cmpll (1)");
767d36db35SAvi Kivity 
777d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 4;
787d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
792d331a4dSRoman Bolshakov 		     "repe cmpsq"
807d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
817d36db35SAvi Kivity 		     : : "cc");
822d331a4dSRoman Bolshakov 	report(rcx == 0 && rsi == m1 + 32 && rdi == m3 + 32, "repe cmpsq (1)");
837d36db35SAvi Kivity 
847d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 130;
857d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
862d331a4dSRoman Bolshakov 		     "repe cmpsb"
877d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
887d36db35SAvi Kivity 		     : : "cc");
89a299895bSThomas Huth 	report(rcx == 29 && rsi == m1 + 101 && rdi == m3 + 101,
902d331a4dSRoman Bolshakov 	       "repe cmpsb (2)");
917d36db35SAvi Kivity 
927d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 65;
937d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
942d331a4dSRoman Bolshakov 		     "repe cmpsw"
957d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
967d36db35SAvi Kivity 		     : : "cc");
97a299895bSThomas Huth 	report(rcx == 14 && rsi == m1 + 102 && rdi == m3 + 102,
982d331a4dSRoman Bolshakov 	       "repe cmpsw (2)");
997d36db35SAvi Kivity 
1007d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 32;
1017d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
1022d331a4dSRoman Bolshakov 		     "repe cmpsl"
1037d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
1047d36db35SAvi Kivity 		     : : "cc");
105a299895bSThomas Huth 	report(rcx == 6 && rsi == m1 + 104 && rdi == m3 + 104,
1062d331a4dSRoman Bolshakov 	       "repe cmpll (2)");
1077d36db35SAvi Kivity 
1087d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 16;
1097d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
1102d331a4dSRoman Bolshakov 		     "repe cmpsq"
1117d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
1127d36db35SAvi Kivity 		     : : "cc");
113a299895bSThomas Huth 	report(rcx == 3 && rsi == m1 + 104 && rdi == m3 + 104,
1142d331a4dSRoman Bolshakov 	       "repe cmpsq (2)");
1157d36db35SAvi Kivity 
1167d36db35SAvi Kivity }
1177d36db35SAvi Kivity 
118db4898e8SThomas Huth static void test_cmps(void *mem)
1197d36db35SAvi Kivity {
1207d36db35SAvi Kivity 	unsigned char *m1 = mem, *m2 = mem + 1024;
1217d36db35SAvi Kivity 	unsigned char m3[1024];
1227d36db35SAvi Kivity 
1237d36db35SAvi Kivity 	for (int i = 0; i < 100; ++i)
1247d36db35SAvi Kivity 		m1[i] = m2[i] = m3[i] = i;
1257d36db35SAvi Kivity 	for (int i = 100; i < 200; ++i)
1267d36db35SAvi Kivity 		m1[i] = (m3[i] = m2[i] = i) + 1;
1277d36db35SAvi Kivity 	test_cmps_one(m1, m3);
1287d36db35SAvi Kivity 	test_cmps_one(m1, m2);
1297d36db35SAvi Kivity }
1307d36db35SAvi Kivity 
131db4898e8SThomas Huth static void test_scas(void *mem)
13280a4ea7bSAvi Kivity {
13380a4ea7bSAvi Kivity     bool z;
13480a4ea7bSAvi Kivity     void *di;
13580a4ea7bSAvi Kivity 
13680a4ea7bSAvi Kivity     *(ulong *)mem = 0x77665544332211;
13780a4ea7bSAvi Kivity 
13880a4ea7bSAvi Kivity     di = mem;
13980a4ea7bSAvi Kivity     asm ("scasb; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff11));
140a299895bSThomas Huth     report(di == mem + 1 && z, "scasb match");
14180a4ea7bSAvi Kivity 
14280a4ea7bSAvi Kivity     di = mem;
14380a4ea7bSAvi Kivity     asm ("scasb; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff54));
144a299895bSThomas Huth     report(di == mem + 1 && !z, "scasb mismatch");
14580a4ea7bSAvi Kivity 
14680a4ea7bSAvi Kivity     di = mem;
14780a4ea7bSAvi Kivity     asm ("scasw; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff2211));
148a299895bSThomas Huth     report(di == mem + 2 && z, "scasw match");
14980a4ea7bSAvi Kivity 
15080a4ea7bSAvi Kivity     di = mem;
15180a4ea7bSAvi Kivity     asm ("scasw; setz %0" : "=rm"(z), "+D"(di) : "a"(0xffdd11));
152a299895bSThomas Huth     report(di == mem + 2 && !z, "scasw mismatch");
15380a4ea7bSAvi Kivity 
15480a4ea7bSAvi Kivity     di = mem;
15580a4ea7bSAvi Kivity     asm ("scasl; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff44332211ul));
156a299895bSThomas Huth     report(di == mem + 4 && z, "scasd match");
15780a4ea7bSAvi Kivity 
15880a4ea7bSAvi Kivity     di = mem;
15980a4ea7bSAvi Kivity     asm ("scasl; setz %0" : "=rm"(z), "+D"(di) : "a"(0x45332211));
160a299895bSThomas Huth     report(di == mem + 4 && !z, "scasd mismatch");
16180a4ea7bSAvi Kivity 
16280a4ea7bSAvi Kivity     di = mem;
16380a4ea7bSAvi Kivity     asm ("scasq; setz %0" : "=rm"(z), "+D"(di) : "a"(0x77665544332211ul));
164a299895bSThomas Huth     report(di == mem + 8 && z, "scasq match");
16580a4ea7bSAvi Kivity 
16680a4ea7bSAvi Kivity     di = mem;
16780a4ea7bSAvi Kivity     asm ("scasq; setz %0" : "=rm"(z), "+D"(di) : "a"(3));
168a299895bSThomas Huth     report(di == mem + 8 && !z, "scasq mismatch");
16980a4ea7bSAvi Kivity }
17080a4ea7bSAvi Kivity 
171db4898e8SThomas Huth static void test_cr8(void)
1727d36db35SAvi Kivity {
1737d36db35SAvi Kivity 	unsigned long src, dst;
1747d36db35SAvi Kivity 
1757d36db35SAvi Kivity 	dst = 777;
1767d36db35SAvi Kivity 	src = 3;
1777d36db35SAvi Kivity 	asm volatile("mov %[src], %%cr8; mov %%cr8, %[dst]"
1787d36db35SAvi Kivity 		     : [dst]"+r"(dst), [src]"+r"(src));
179a299895bSThomas Huth 	report(dst == 3 && src == 3, "mov %%cr8");
1807d36db35SAvi Kivity }
1817d36db35SAvi Kivity 
182db4898e8SThomas Huth static void test_push(void *mem)
1837d36db35SAvi Kivity {
1847d36db35SAvi Kivity 	unsigned long tmp;
1857d36db35SAvi Kivity 	unsigned long *stack_top = mem + 4096;
1867d36db35SAvi Kivity 	unsigned long *new_stack_top;
1877d36db35SAvi Kivity 	unsigned long memw = 0x123456789abcdeful;
1887d36db35SAvi Kivity 
1897d36db35SAvi Kivity 	memset(mem, 0x55, (void *)stack_top - mem);
1907d36db35SAvi Kivity 
1917d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
1927d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
1937d36db35SAvi Kivity 		     "pushq $-7 \n\t"
1947d36db35SAvi Kivity 		     "pushq %[reg] \n\t"
1957d36db35SAvi Kivity 		     "pushq (%[mem]) \n\t"
1967d36db35SAvi Kivity 		     "pushq $-7070707 \n\t"
1977d36db35SAvi Kivity 		     "mov %%rsp, %[new_stack_top] \n\t"
1987d36db35SAvi Kivity 		     "mov %[tmp], %%rsp"
1997d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp), [new_stack_top]"=r"(new_stack_top)
2007d36db35SAvi Kivity 		     : [stack_top]"r"(stack_top),
2017d36db35SAvi Kivity 		       [reg]"r"(-17l), [mem]"r"(&memw)
2027d36db35SAvi Kivity 		     : "memory");
2037d36db35SAvi Kivity 
204a299895bSThomas Huth 	report(stack_top[-1] == -7ul, "push $imm8");
205a299895bSThomas Huth 	report(stack_top[-2] == -17ul, "push %%reg");
206a299895bSThomas Huth 	report(stack_top[-3] == 0x123456789abcdeful, "push mem");
207a299895bSThomas Huth 	report(stack_top[-4] == -7070707, "push $imm");
2087d36db35SAvi Kivity }
2097d36db35SAvi Kivity 
210db4898e8SThomas Huth static void test_pop(void *mem)
2117d36db35SAvi Kivity {
21228f04f22SAvi Kivity 	unsigned long tmp, tmp3, rsp, rbp;
2137d36db35SAvi Kivity 	unsigned long *stack_top = mem + 4096;
2147d36db35SAvi Kivity 	unsigned long memw = 0x123456789abcdeful;
2157d36db35SAvi Kivity 	static unsigned long tmp2;
2167d36db35SAvi Kivity 
2177d36db35SAvi Kivity 	memset(mem, 0x55, (void *)stack_top - mem);
2187d36db35SAvi Kivity 
2197d36db35SAvi Kivity 	asm volatile("pushq %[val] \n\t"
2207d36db35SAvi Kivity 		     "popq (%[mem])"
2217d36db35SAvi Kivity 		     : : [val]"m"(memw), [mem]"r"(mem) : "memory");
222a299895bSThomas Huth 	report(*(unsigned long *)mem == memw, "pop mem");
2237d36db35SAvi Kivity 
2247d36db35SAvi Kivity 	memw = 7 - memw;
2257d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
2267d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2277d36db35SAvi Kivity 		     "pushq %[val] \n\t"
2287d36db35SAvi Kivity 		     "popq %[tmp2] \n\t"
2297d36db35SAvi Kivity 		     "mov %[tmp], %%rsp"
2307d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp), [tmp2]"=m"(tmp2)
2317d36db35SAvi Kivity 		     : [val]"r"(memw), [stack_top]"r"(stack_top)
2327d36db35SAvi Kivity 		     : "memory");
233a299895bSThomas Huth 	report(tmp2 == memw, "pop mem (2)");
2347d36db35SAvi Kivity 
2357d36db35SAvi Kivity 	memw = 129443 - memw;
2367d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
2377d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2387d36db35SAvi Kivity 		     "pushq %[val] \n\t"
2397d36db35SAvi Kivity 		     "popq %[tmp2] \n\t"
2407d36db35SAvi Kivity 		     "mov %[tmp], %%rsp"
2417d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp), [tmp2]"=r"(tmp2)
2427d36db35SAvi Kivity 		     : [val]"r"(memw), [stack_top]"r"(stack_top)
2437d36db35SAvi Kivity 		     : "memory");
244a299895bSThomas Huth 	report(tmp2 == memw, "pop reg");
2457d36db35SAvi Kivity 
2467d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
2477d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2487bf8144eSZixuan Wang 		     "lea 1f(%%rip), %%rax \n\t"
2497bf8144eSZixuan Wang 		     "push %%rax \n\t"
2507d36db35SAvi Kivity 		     "ret \n\t"
2517d36db35SAvi Kivity 		     "2: jmp 2b \n\t"
2527d36db35SAvi Kivity 		     "1: mov %[tmp], %%rsp"
2537d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp) : [stack_top]"r"(stack_top)
2547bf8144eSZixuan Wang 		     : "memory", "rax");
2555c3582f0SJanis Schoetterl-Glausch 	report_pass("ret");
2565269d6e7SAvi Kivity 
2575269d6e7SAvi Kivity 	stack_top[-1] = 0x778899;
258c2aa6128SPeter Feiner 	asm volatile("mov %[stack_top], %%r8 \n\t"
259c2aa6128SPeter Feiner 		     "mov %%rsp, %%r9 \n\t"
260c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r8 \n\t"
2615269d6e7SAvi Kivity 		     "leave \n\t"
262c2aa6128SPeter Feiner 		     "xchg %%rsp, %%r9 \n\t"
263c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r8 \n\t"
264c2aa6128SPeter Feiner 		     "mov %%r9, %[tmp] \n\t"
265c2aa6128SPeter Feiner 		     "mov %%r8, %[tmp3]"
2665269d6e7SAvi Kivity 		     : [tmp]"=&r"(tmp), [tmp3]"=&r"(tmp3) : [stack_top]"r"(stack_top-1)
267c2aa6128SPeter Feiner 		     : "memory", "r8", "r9");
268a299895bSThomas Huth 	report(tmp == (ulong)stack_top && tmp3 == 0x778899, "leave");
26928f04f22SAvi Kivity 
27028f04f22SAvi Kivity 	rbp = 0xaa55aa55bb66bb66ULL;
27128f04f22SAvi Kivity 	rsp = (unsigned long)stack_top;
272c2aa6128SPeter Feiner 	asm volatile("mov %[rsp], %%r8 \n\t"
273c2aa6128SPeter Feiner 		     "mov %[rbp], %%r9 \n\t"
274c2aa6128SPeter Feiner 		     "xchg %%rsp, %%r8 \n\t"
275c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r9 \n\t"
27628f04f22SAvi Kivity 		     "enter $0x1238, $0 \n\t"
277c2aa6128SPeter Feiner 		     "xchg %%rsp, %%r8 \n\t"
278c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r9 \n\t"
279c2aa6128SPeter Feiner 		     "xchg %%r8, %[rsp] \n\t"
280c2aa6128SPeter Feiner 		     "xchg %%r9, %[rbp]"
281c2aa6128SPeter Feiner 		     : [rsp]"+a"(rsp), [rbp]"+b"(rbp) : : "memory", "r8", "r9");
282a299895bSThomas Huth 	report(rsp == (unsigned long)stack_top - 8 - 0x1238
28328f04f22SAvi Kivity 	       && rbp == (unsigned long)stack_top - 8
284a299895bSThomas Huth 	       && stack_top[-1] == 0xaa55aa55bb66bb66ULL,
285a299895bSThomas Huth 	       "enter");
2867d36db35SAvi Kivity }
2877d36db35SAvi Kivity 
288db4898e8SThomas Huth static void test_ljmp(void *mem)
2897d36db35SAvi Kivity {
2907d36db35SAvi Kivity     unsigned char *m = mem;
2917d36db35SAvi Kivity     volatile int res = 1;
2927d36db35SAvi Kivity 
2937d36db35SAvi Kivity     *(unsigned long**)m = &&jmpf;
2942d331a4dSRoman Bolshakov     asm volatile ("data16 mov %%cs, %0":"=m"(*(m + sizeof(unsigned long))));
2952d331a4dSRoman Bolshakov     asm volatile ("rex64 ljmp *%0"::"m"(*m));
2967d36db35SAvi Kivity     res = 0;
2977d36db35SAvi Kivity jmpf:
298a299895bSThomas Huth     report(res, "ljmp");
2997d36db35SAvi Kivity }
3007d36db35SAvi Kivity 
301db4898e8SThomas Huth static void test_incdecnotneg(void *mem)
3027d36db35SAvi Kivity {
3037d36db35SAvi Kivity     unsigned long *m = mem, v = 1234;
3047d36db35SAvi Kivity     unsigned char *mb = mem, vb = 66;
3057d36db35SAvi Kivity 
3067d36db35SAvi Kivity     *m = 0;
3077d36db35SAvi Kivity 
3087d36db35SAvi Kivity     asm volatile ("incl %0":"+m"(*m));
309a299895bSThomas Huth     report(*m == 1, "incl");
3107d36db35SAvi Kivity     asm volatile ("decl %0":"+m"(*m));
311a299895bSThomas Huth     report(*m == 0, "decl");
3127d36db35SAvi Kivity     asm volatile ("incb %0":"+m"(*m));
313a299895bSThomas Huth     report(*m == 1, "incb");
3147d36db35SAvi Kivity     asm volatile ("decb %0":"+m"(*m));
315a299895bSThomas Huth     report(*m == 0, "decb");
3167d36db35SAvi Kivity 
3177d36db35SAvi Kivity     asm volatile ("lock incl %0":"+m"(*m));
318a299895bSThomas Huth     report(*m == 1, "lock incl");
3197d36db35SAvi Kivity     asm volatile ("lock decl %0":"+m"(*m));
320a299895bSThomas Huth     report(*m == 0, "lock decl");
3217d36db35SAvi Kivity     asm volatile ("lock incb %0":"+m"(*m));
322a299895bSThomas Huth     report(*m == 1, "lock incb");
3237d36db35SAvi Kivity     asm volatile ("lock decb %0":"+m"(*m));
324a299895bSThomas Huth     report(*m == 0, "lock decb");
3257d36db35SAvi Kivity 
3267d36db35SAvi Kivity     *m = v;
3277d36db35SAvi Kivity 
3287d36db35SAvi Kivity     asm ("lock negq %0" : "+m"(*m)); v = -v;
329a299895bSThomas Huth     report(*m == v, "lock negl");
3307d36db35SAvi Kivity     asm ("lock notq %0" : "+m"(*m)); v = ~v;
331a299895bSThomas Huth     report(*m == v, "lock notl");
3327d36db35SAvi Kivity 
3337d36db35SAvi Kivity     *mb = vb;
3347d36db35SAvi Kivity 
3357d36db35SAvi Kivity     asm ("lock negb %0" : "+m"(*mb)); vb = -vb;
336a299895bSThomas Huth     report(*mb == vb, "lock negb");
3377d36db35SAvi Kivity     asm ("lock notb %0" : "+m"(*mb)); vb = ~vb;
338a299895bSThomas Huth     report(*mb == vb, "lock notb");
3397d36db35SAvi Kivity }
3407d36db35SAvi Kivity 
341db4898e8SThomas Huth static void test_smsw(uint64_t *h_mem)
3427d36db35SAvi Kivity {
3437d36db35SAvi Kivity 	char mem[16];
3447d36db35SAvi Kivity 	unsigned short msw, msw_orig, *pmsw;
3457d36db35SAvi Kivity 	int i, zero;
3467d36db35SAvi Kivity 
3477d36db35SAvi Kivity 	msw_orig = read_cr0();
3487d36db35SAvi Kivity 
3497d36db35SAvi Kivity 	asm("smsw %0" : "=r"(msw));
350a299895bSThomas Huth 	report(msw == msw_orig, "smsw (1)");
3517d36db35SAvi Kivity 
3527d36db35SAvi Kivity 	memset(mem, 0, 16);
3537d36db35SAvi Kivity 	pmsw = (void *)mem;
3547d36db35SAvi Kivity 	asm("smsw %0" : "=m"(pmsw[4]));
3557d36db35SAvi Kivity 	zero = 1;
3567d36db35SAvi Kivity 	for (i = 0; i < 8; ++i)
3577d36db35SAvi Kivity 		if (i != 4 && pmsw[i])
3587d36db35SAvi Kivity 			zero = 0;
359a299895bSThomas Huth 	report(msw == pmsw[4] && zero, "smsw (2)");
3604003963dSNadav Amit 
3614003963dSNadav Amit 	/* Trigger exit on smsw */
3624003963dSNadav Amit 	*h_mem = 0x12345678abcdeful;
36311147080SChris J Arges 	asm volatile("smsw %0" : "+m"(*h_mem));
364a299895bSThomas Huth 	report(msw == (unsigned short)*h_mem &&
365a299895bSThomas Huth 	       (*h_mem & ~0xfffful) == 0x12345678ab0000ul, "smsw (3)");
3667d36db35SAvi Kivity }
3677d36db35SAvi Kivity 
368db4898e8SThomas Huth static void test_lmsw(void)
3697d36db35SAvi Kivity {
3707d36db35SAvi Kivity 	char mem[16];
3717d36db35SAvi Kivity 	unsigned short msw, *pmsw;
3727d36db35SAvi Kivity 	unsigned long cr0;
3737d36db35SAvi Kivity 
3747d36db35SAvi Kivity 	cr0 = read_cr0();
3757d36db35SAvi Kivity 
3767d36db35SAvi Kivity 	msw = cr0 ^ 8;
3777d36db35SAvi Kivity 	asm("lmsw %0" : : "r"(msw));
3787d36db35SAvi Kivity 	printf("before %lx after %lx\n", cr0, read_cr0());
379a299895bSThomas Huth 	report((cr0 ^ read_cr0()) == 8, "lmsw (1)");
3807d36db35SAvi Kivity 
3817d36db35SAvi Kivity 	pmsw = (void *)mem;
3827d36db35SAvi Kivity 	*pmsw = cr0;
3837d36db35SAvi Kivity 	asm("lmsw %0" : : "m"(*pmsw));
3847d36db35SAvi Kivity 	printf("before %lx after %lx\n", cr0, read_cr0());
385a299895bSThomas Huth 	report(cr0 == read_cr0(), "lmsw (2)");
3867d36db35SAvi Kivity 
3877d36db35SAvi Kivity 	/* lmsw can't clear cr0.pe */
3887d36db35SAvi Kivity 	msw = (cr0 & ~1ul) ^ 4;  /* change EM to force trap */
3897d36db35SAvi Kivity 	asm("lmsw %0" : : "r"(msw));
390a299895bSThomas Huth 	report((cr0 ^ read_cr0()) == 4 && (cr0 & 1), "lmsw (3)");
3917d36db35SAvi Kivity 
3927d36db35SAvi Kivity 	/* back to normal */
3937d36db35SAvi Kivity 	msw = cr0;
3947d36db35SAvi Kivity 	asm("lmsw %0" : : "r"(msw));
3957d36db35SAvi Kivity }
3967d36db35SAvi Kivity 
397db4898e8SThomas Huth static void test_xchg(void *mem)
3987d36db35SAvi Kivity {
3997d36db35SAvi Kivity 	unsigned long *memq = mem;
4007d36db35SAvi Kivity 	unsigned long rax;
4017d36db35SAvi Kivity 
4027d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4037d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4047d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4057d36db35SAvi Kivity 		     "xchg %%al, (%[memq])\n\t"
4067d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4077d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4087d36db35SAvi Kivity 		     : [memq]"r"(memq)
409c2aa6128SPeter Feiner 		     : "memory", "rax");
410a299895bSThomas Huth 	report(rax == 0xfedcba98765432ef && *memq == 0x123456789abcd10,
411a299895bSThomas Huth 	       "xchg reg, r/m (1)");
4127d36db35SAvi Kivity 
4137d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4147d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4157d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4167d36db35SAvi Kivity 		     "xchg %%ax, (%[memq])\n\t"
4177d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4187d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4197d36db35SAvi Kivity 		     : [memq]"r"(memq)
420c2aa6128SPeter Feiner 		     : "memory", "rax");
421a299895bSThomas Huth 	report(rax == 0xfedcba987654cdef && *memq == 0x123456789ab3210,
422a299895bSThomas Huth 	       "xchg reg, r/m (2)");
4237d36db35SAvi Kivity 
4247d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4257d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4267d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4277d36db35SAvi Kivity 		     "xchg %%eax, (%[memq])\n\t"
4287d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4297d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4307d36db35SAvi Kivity 		     : [memq]"r"(memq)
431c2aa6128SPeter Feiner 		     : "memory", "rax");
432a299895bSThomas Huth 	report(rax == 0x89abcdef && *memq == 0x123456776543210,
433a299895bSThomas Huth 	       "xchg reg, r/m (3)");
4347d36db35SAvi Kivity 
4357d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4367d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4377d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4387d36db35SAvi Kivity 		     "xchg %%rax, (%[memq])\n\t"
4397d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4407d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4417d36db35SAvi Kivity 		     : [memq]"r"(memq)
442c2aa6128SPeter Feiner 		     : "memory", "rax");
443a299895bSThomas Huth 	report(rax == 0x123456789abcdef && *memq == 0xfedcba9876543210,
444a299895bSThomas Huth 	       "xchg reg, r/m (4)");
4457d36db35SAvi Kivity }
4467d36db35SAvi Kivity 
447db4898e8SThomas Huth static void test_xadd(void *mem)
4485647d55cSWei Yongjun {
4495647d55cSWei Yongjun 	unsigned long *memq = mem;
4505647d55cSWei Yongjun 	unsigned long rax;
4515647d55cSWei Yongjun 
4525647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4535647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4545647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4555647d55cSWei Yongjun 		     "xadd %%al, (%[memq])\n\t"
4565647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4575647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4585647d55cSWei Yongjun 		     : [memq]"r"(memq)
459c2aa6128SPeter Feiner 		     : "memory", "rax");
460a299895bSThomas Huth 	report(rax == 0xfedcba98765432ef && *memq == 0x123456789abcdff,
461a299895bSThomas Huth 	       "xadd reg, r/m (1)");
4625647d55cSWei Yongjun 
4635647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4645647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4655647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4665647d55cSWei Yongjun 		     "xadd %%ax, (%[memq])\n\t"
4675647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4685647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4695647d55cSWei Yongjun 		     : [memq]"r"(memq)
470c2aa6128SPeter Feiner 		     : "memory", "rax");
471a299895bSThomas Huth 	report(rax == 0xfedcba987654cdef && *memq == 0x123456789abffff,
472a299895bSThomas Huth 	       "xadd reg, r/m (2)");
4735647d55cSWei Yongjun 
4745647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4755647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4765647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4775647d55cSWei Yongjun 		     "xadd %%eax, (%[memq])\n\t"
4785647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4795647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4805647d55cSWei Yongjun 		     : [memq]"r"(memq)
481c2aa6128SPeter Feiner 		     : "memory", "rax");
482a299895bSThomas Huth 	report(rax == 0x89abcdef && *memq == 0x1234567ffffffff,
483a299895bSThomas Huth 	       "xadd reg, r/m (3)");
4845647d55cSWei Yongjun 
4855647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4865647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4875647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4885647d55cSWei Yongjun 		     "xadd %%rax, (%[memq])\n\t"
4895647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4905647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4915647d55cSWei Yongjun 		     : [memq]"r"(memq)
492c2aa6128SPeter Feiner 		     : "memory", "rax");
493a299895bSThomas Huth 	report(rax == 0x123456789abcdef && *memq == 0xffffffffffffffff,
494a299895bSThomas Huth 	       "xadd reg, r/m (4)");
4955647d55cSWei Yongjun }
4965647d55cSWei Yongjun 
497db4898e8SThomas Huth static void test_btc(void *mem)
498d4655eafSWei Yongjun {
499d4655eafSWei Yongjun 	unsigned int *a = mem;
500d4655eafSWei Yongjun 
5017e083f20SNadav Amit 	memset(mem, 0, 4 * sizeof(unsigned int));
502d4655eafSWei Yongjun 
503d4655eafSWei Yongjun 	asm ("btcl $32, %0" :: "m"(a[0]) : "memory");
504d4655eafSWei Yongjun 	asm ("btcl $1, %0" :: "m"(a[1]) : "memory");
505d4655eafSWei Yongjun 	asm ("btcl %1, %0" :: "m"(a[0]), "r"(66) : "memory");
506a299895bSThomas Huth 	report(a[0] == 1 && a[1] == 2 && a[2] == 4, "btcl imm8, r/m");
507d4655eafSWei Yongjun 
508d4655eafSWei Yongjun 	asm ("btcl %1, %0" :: "m"(a[3]), "r"(-1) : "memory");
509a299895bSThomas Huth 	report(a[0] == 1 && a[1] == 2 && a[2] == 0x80000004, "btcl reg, r/m");
5107e083f20SNadav Amit 
5117e083f20SNadav Amit 	asm ("btcq %1, %0" : : "m"(a[2]), "r"(-1l) : "memory");
512a299895bSThomas Huth 	report(a[0] == 1 && a[1] == 0x80000002 && a[2] == 0x80000004 && a[3] == 0,
513a299895bSThomas Huth 	       "btcq reg, r/m");
514d4655eafSWei Yongjun }
515d4655eafSWei Yongjun 
516db4898e8SThomas Huth static void test_bsfbsr(void *mem)
5172e16c7f6SWei Yongjun {
518554de466SAvi Kivity 	unsigned long rax, *memq = mem;
519554de466SAvi Kivity 	unsigned eax, *meml = mem;
520554de466SAvi Kivity 	unsigned short ax, *memw = mem;
521554de466SAvi Kivity 	unsigned char z;
5222e16c7f6SWei Yongjun 
523554de466SAvi Kivity 	*memw = 0xc000;
524554de466SAvi Kivity 	asm("bsfw %[mem], %[a]" : [a]"=a"(ax) : [mem]"m"(*memw));
525a299895bSThomas Huth 	report(ax == 14, "bsfw r/m, reg");
5262e16c7f6SWei Yongjun 
527554de466SAvi Kivity 	*meml = 0xc0000000;
528554de466SAvi Kivity 	asm("bsfl %[mem], %[a]" : [a]"=a"(eax) : [mem]"m"(*meml));
529a299895bSThomas Huth 	report(eax == 30, "bsfl r/m, reg");
5302e16c7f6SWei Yongjun 
531554de466SAvi Kivity 	*memq = 0xc00000000000;
532554de466SAvi Kivity 	asm("bsfq %[mem], %[a]" : [a]"=a"(rax) : [mem]"m"(*memq));
533a299895bSThomas Huth 	report(rax == 46, "bsfq r/m, reg");
5342e16c7f6SWei Yongjun 
535554de466SAvi Kivity 	*memq = 0;
536554de466SAvi Kivity 	asm("bsfq %[mem], %[a]; setz %[z]"
537554de466SAvi Kivity 	    : [a]"=a"(rax), [z]"=rm"(z) : [mem]"m"(*memq));
538a299895bSThomas Huth 	report(z == 1, "bsfq r/m, reg");
5392e16c7f6SWei Yongjun 
540554de466SAvi Kivity 	*memw = 0xc000;
541554de466SAvi Kivity 	asm("bsrw %[mem], %[a]" : [a]"=a"(ax) : [mem]"m"(*memw));
542a299895bSThomas Huth 	report(ax == 15, "bsrw r/m, reg");
5432e16c7f6SWei Yongjun 
544554de466SAvi Kivity 	*meml = 0xc0000000;
545554de466SAvi Kivity 	asm("bsrl %[mem], %[a]" : [a]"=a"(eax) : [mem]"m"(*meml));
546a299895bSThomas Huth 	report(eax == 31, "bsrl r/m, reg");
5472e16c7f6SWei Yongjun 
548554de466SAvi Kivity 	*memq = 0xc00000000000;
549554de466SAvi Kivity 	asm("bsrq %[mem], %[a]" : [a]"=a"(rax) : [mem]"m"(*memq));
550a299895bSThomas Huth 	report(rax == 47, "bsrq r/m, reg");
5512e16c7f6SWei Yongjun 
552554de466SAvi Kivity 	*memq = 0;
553554de466SAvi Kivity 	asm("bsrq %[mem], %[a]; setz %[z]"
554554de466SAvi Kivity 	    : [a]"=a"(rax), [z]"=rm"(z) : [mem]"m"(*memq));
555a299895bSThomas Huth 	report(z == 1, "bsrq r/m, reg");
5562e16c7f6SWei Yongjun }
5572e16c7f6SWei Yongjun 
55851d65a3cSAvi Kivity static void test_imul(ulong *mem)
55951d65a3cSAvi Kivity {
56051d65a3cSAvi Kivity     ulong a;
56151d65a3cSAvi Kivity 
56251d65a3cSAvi Kivity     *mem = 51; a = 0x1234567812345678UL;
56351d65a3cSAvi Kivity     asm ("imulw %1, %%ax" : "+a"(a) : "m"(*mem));
564a299895bSThomas Huth     report(a == 0x12345678123439e8, "imul ax, mem");
56551d65a3cSAvi Kivity 
56651d65a3cSAvi Kivity     *mem = 51; a = 0x1234567812345678UL;
56751d65a3cSAvi Kivity     asm ("imull %1, %%eax" : "+a"(a) : "m"(*mem));
568a299895bSThomas Huth     report(a == 0xa06d39e8, "imul eax, mem");
56951d65a3cSAvi Kivity 
57051d65a3cSAvi Kivity     *mem = 51; a = 0x1234567812345678UL;
57151d65a3cSAvi Kivity     asm ("imulq %1, %%rax" : "+a"(a) : "m"(*mem));
572a299895bSThomas Huth     report(a == 0xA06D39EBA06D39E8UL, "imul rax, mem");
57351d65a3cSAvi Kivity 
57451d65a3cSAvi Kivity     *mem  = 0x1234567812345678UL; a = 0x8765432187654321L;
57551d65a3cSAvi Kivity     asm ("imulw $51, %1, %%ax" : "+a"(a) : "m"(*mem));
576a299895bSThomas Huth     report(a == 0x87654321876539e8, "imul ax, mem, imm8");
57751d65a3cSAvi Kivity 
57851d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
57951d65a3cSAvi Kivity     asm ("imull $51, %1, %%eax" : "+a"(a) : "m"(*mem));
580a299895bSThomas Huth     report(a == 0xa06d39e8, "imul eax, mem, imm8");
58151d65a3cSAvi Kivity 
58251d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
58351d65a3cSAvi Kivity     asm ("imulq $51, %1, %%rax" : "+a"(a) : "m"(*mem));
584a299895bSThomas Huth     report(a == 0xA06D39EBA06D39E8UL, "imul rax, mem, imm8");
58551d65a3cSAvi Kivity 
58651d65a3cSAvi Kivity     *mem  = 0x1234567812345678UL; a = 0x8765432187654321L;
58751d65a3cSAvi Kivity     asm ("imulw $311, %1, %%ax" : "+a"(a) : "m"(*mem));
588a299895bSThomas Huth     report(a == 0x8765432187650bc8, "imul ax, mem, imm");
58951d65a3cSAvi Kivity 
59051d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
59151d65a3cSAvi Kivity     asm ("imull $311, %1, %%eax" : "+a"(a) : "m"(*mem));
592a299895bSThomas Huth     report(a == 0x1d950bc8, "imul eax, mem, imm");
59351d65a3cSAvi Kivity 
59451d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
59551d65a3cSAvi Kivity     asm ("imulq $311, %1, %%rax" : "+a"(a) : "m"(*mem));
596a299895bSThomas Huth     report(a == 0x1D950BDE1D950BC8L, "imul rax, mem, imm");
59751d65a3cSAvi Kivity }
59851d65a3cSAvi Kivity 
599c2c43fcfSAvi Kivity static void test_muldiv(long *mem)
600f12d86b0SAvi Kivity {
601c2c43fcfSAvi Kivity     long a, d, aa, dd;
602f12d86b0SAvi Kivity     u8 ex = 1;
603f12d86b0SAvi Kivity 
604f12d86b0SAvi Kivity     *mem = 0; a = 1; d = 2;
605f12d86b0SAvi Kivity     asm (ASM_TRY("1f") "divq %3; movb $0, %2; 1:"
606f12d86b0SAvi Kivity 	 : "+a"(a), "+d"(d), "+q"(ex) : "m"(*mem));
607a299895bSThomas Huth     report(a == 1 && d == 2 && ex, "divq (fault)");
608f12d86b0SAvi Kivity 
609f12d86b0SAvi Kivity     *mem = 987654321098765UL; a = 123456789012345UL; d = 123456789012345UL;
610f12d86b0SAvi Kivity     asm (ASM_TRY("1f") "divq %3; movb $0, %2; 1:"
611f12d86b0SAvi Kivity 	 : "+a"(a), "+d"(d), "+q"(ex) : "m"(*mem));
612a299895bSThomas Huth     report(a == 0x1ffffffb1b963b33ul && d == 0x273ba4384ede2ul && !ex,
613a299895bSThomas Huth            "divq (1)");
614c2c43fcfSAvi Kivity     aa = 0x1111111111111111; dd = 0x2222222222222222;
615c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
616c2c43fcfSAvi Kivity     asm("mulb %2" : "+a"(a), "+d"(d) : "m"(*mem));
617a299895bSThomas Huth     report(a == 0x1111111111110363 && d == dd, "mulb mem");
618c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
619c2c43fcfSAvi Kivity     asm("mulw %2" : "+a"(a), "+d"(d) : "m"(*mem));
620a299895bSThomas Huth     report(a == 0x111111111111c963 && d == 0x2222222222220369, "mulw mem");
621c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
622c2c43fcfSAvi Kivity     asm("mull %2" : "+a"(a), "+d"(d) : "m"(*mem));
623a299895bSThomas Huth     report(a == 0x962fc963 && d == 0x369d036, "mull mem");
624c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
625c2c43fcfSAvi Kivity     asm("mulq %2" : "+a"(a), "+d"(d) : "m"(*mem));
626a299895bSThomas Huth     report(a == 0x2fc962fc962fc963 && d == 0x369d0369d0369d0, "mulq mem");
627f12d86b0SAvi Kivity }
628f12d86b0SAvi Kivity 
629d7f3ee3cSAvi Kivity typedef unsigned __attribute__((vector_size(16))) sse128;
630d7f3ee3cSAvi Kivity 
63193a3ae40SJacob Xu static bool sseeq(uint32_t *v1, uint32_t *v2)
632d7f3ee3cSAvi Kivity {
633d7f3ee3cSAvi Kivity     bool ok = true;
634d7f3ee3cSAvi Kivity     int i;
635d7f3ee3cSAvi Kivity 
636d7f3ee3cSAvi Kivity     for (i = 0; i < 4; ++i) {
63793a3ae40SJacob Xu 	ok &= v1[i] == v2[i];
638d7f3ee3cSAvi Kivity     }
639d7f3ee3cSAvi Kivity 
640d7f3ee3cSAvi Kivity     return ok;
641d7f3ee3cSAvi Kivity }
642d7f3ee3cSAvi Kivity 
64393a3ae40SJacob Xu static __attribute__((target("sse2"))) void test_sse(uint32_t *mem)
644d7f3ee3cSAvi Kivity {
64593a3ae40SJacob Xu 	sse128 vv;
64693a3ae40SJacob Xu 	uint32_t *v = (uint32_t *)&vv;
647d7f3ee3cSAvi Kivity 
648d7f3ee3cSAvi Kivity 	write_cr0(read_cr0() & ~6); /* EM, TS */
649d7f3ee3cSAvi Kivity 	write_cr4(read_cr4() | 0x200); /* OSFXSR */
65093a3ae40SJacob Xu 	memset(&vv, 0, sizeof(vv));
651290ed5d5SIgor Mammedov 
6528726f977SJacob Xu #define TEST_RW_SSE(insn) do { \
65393a3ae40SJacob Xu 		v[0] = 1; v[1] = 2; v[2] = 3; v[3] = 4; \
65493a3ae40SJacob Xu 		asm(insn " %1, %0" : "=m"(*mem) : "x"(vv) : "memory"); \
65593a3ae40SJacob Xu 		report(sseeq(v, mem), insn " (read)"); \
65693a3ae40SJacob Xu 		mem[0] = 5; mem[1] = 6; mem[2] = 7; mem[3] = 8; \
65793a3ae40SJacob Xu 		asm(insn " %1, %0" : "=x"(vv) : "m"(*mem) : "memory"); \
65893a3ae40SJacob Xu 		report(sseeq(v, mem), insn " (write)"); \
6598726f977SJacob Xu } while (0)
660f068a46aSIgor Mammedov 
6618726f977SJacob Xu 	TEST_RW_SSE("movdqu");
6628726f977SJacob Xu 	TEST_RW_SSE("movaps");
6638726f977SJacob Xu 	TEST_RW_SSE("movapd");
6648726f977SJacob Xu 	TEST_RW_SSE("movups");
6658726f977SJacob Xu 	TEST_RW_SSE("movupd");
6668726f977SJacob Xu #undef TEST_RW_SSE
667d7f3ee3cSAvi Kivity }
668d7f3ee3cSAvi Kivity 
669e5e76263SJacob Xu static void unaligned_movaps_handler(struct ex_regs *regs)
670e5e76263SJacob Xu {
671e5e76263SJacob Xu 	extern char unaligned_movaps_cont;
672e5e76263SJacob Xu 
673e5e76263SJacob Xu 	++exceptions;
674e5e76263SJacob Xu 	regs->rip = (ulong)&unaligned_movaps_cont;
675e5e76263SJacob Xu }
676e5e76263SJacob Xu 
677e5e76263SJacob Xu static void cross_movups_handler(struct ex_regs *regs)
678e5e76263SJacob Xu {
679e5e76263SJacob Xu 	extern char cross_movups_cont;
680e5e76263SJacob Xu 
681e5e76263SJacob Xu 	++exceptions;
682e5e76263SJacob Xu 	regs->rip = (ulong)&cross_movups_cont;
683e5e76263SJacob Xu }
684e5e76263SJacob Xu 
685e5e76263SJacob Xu static __attribute__((target("sse2"))) void test_sse_exceptions(void *cross_mem)
686e5e76263SJacob Xu {
68793a3ae40SJacob Xu 	sse128 vv;
68893a3ae40SJacob Xu 	uint32_t *v = (uint32_t *)&vv;
68993a3ae40SJacob Xu 	uint32_t *mem;
690e5e76263SJacob Xu 	uint8_t *bytes = cross_mem; // aligned on PAGE_SIZE*2
691e5e76263SJacob Xu 	void *page2 = (void *)(&bytes[4096]);
692e5e76263SJacob Xu 	struct pte_search search;
693e5e76263SJacob Xu 	pteval_t orig_pte;
69415bfae71SMichal Luczaj 	handler old;
695e5e76263SJacob Xu 
696e5e76263SJacob Xu 	// setup memory for unaligned access
69793a3ae40SJacob Xu 	mem = (uint32_t *)(&bytes[8]);
698e5e76263SJacob Xu 
699e5e76263SJacob Xu 	// test unaligned access for movups, movupd and movaps
70093a3ae40SJacob Xu 	v[0] = 1; v[1] = 2; v[2] = 3; v[3] = 4;
70193a3ae40SJacob Xu 	mem[0] = 5; mem[1] = 6; mem[2] = 8; mem[3] = 9;
70293a3ae40SJacob Xu 	asm("movups %1, %0" : "=m"(*mem) : "x"(vv) : "memory");
70393a3ae40SJacob Xu 	report(sseeq(v, mem), "movups unaligned");
704e5e76263SJacob Xu 
70593a3ae40SJacob Xu 	v[0] = 1; v[1] = 2; v[2] = 3; v[3] = 4;
70693a3ae40SJacob Xu 	mem[0] = 5; mem[1] = 6; mem[2] = 7; mem[3] = 8;
70793a3ae40SJacob Xu 	asm("movupd %1, %0" : "=m"(*mem) : "x"(vv) : "memory");
70893a3ae40SJacob Xu 	report(sseeq(v, mem), "movupd unaligned");
709e5e76263SJacob Xu 	exceptions = 0;
71015bfae71SMichal Luczaj 	old = handle_exception(GP_VECTOR, unaligned_movaps_handler);
711e5e76263SJacob Xu 	asm("movaps %1, %0\n\t unaligned_movaps_cont:"
71293a3ae40SJacob Xu 			: "=m"(*mem) : "x"(vv));
71315bfae71SMichal Luczaj 	handle_exception(GP_VECTOR, old);
714e5e76263SJacob Xu 	report(exceptions == 1, "unaligned movaps exception");
715e5e76263SJacob Xu 
716e5e76263SJacob Xu 	// setup memory for cross page access
71793a3ae40SJacob Xu 	mem = (uint32_t *)(&bytes[4096-8]);
71893a3ae40SJacob Xu 	v[0] = 1; v[1] = 2; v[2] = 3; v[3] = 4;
71993a3ae40SJacob Xu 	mem[0] = 5; mem[1] = 6; mem[2] = 7; mem[3] = 8;
720e5e76263SJacob Xu 
72193a3ae40SJacob Xu 	asm("movups %1, %0" : "=m"(*mem) : "x"(vv) : "memory");
72293a3ae40SJacob Xu 	report(sseeq(v, mem), "movups unaligned crosspage");
723e5e76263SJacob Xu 
724e5e76263SJacob Xu 	// invalidate second page
725e5e76263SJacob Xu 	search = find_pte_level(current_page_table(), page2, 1);
726e5e76263SJacob Xu 	orig_pte = *search.pte;
727e5e76263SJacob Xu 	install_pte(current_page_table(), 1, page2, 0, NULL);
728e5e76263SJacob Xu 	invlpg(page2);
729e5e76263SJacob Xu 
730e5e76263SJacob Xu 	exceptions = 0;
73115bfae71SMichal Luczaj 	old = handle_exception(PF_VECTOR, cross_movups_handler);
73293a3ae40SJacob Xu 	asm("movups %1, %0\n\t cross_movups_cont:" : "=m"(*mem) : "x"(vv) :
73393a3ae40SJacob Xu 			"memory");
73415bfae71SMichal Luczaj 	handle_exception(PF_VECTOR, old);
735e5e76263SJacob Xu 	report(exceptions == 1, "movups crosspage exception");
736e5e76263SJacob Xu 
737e5e76263SJacob Xu 	// restore invalidated page
738e5e76263SJacob Xu 	install_pte(current_page_table(), 1, page2, orig_pte, NULL);
739e5e76263SJacob Xu }
740e5e76263SJacob Xu 
7413587082bSAvi Kivity static void test_mmx(uint64_t *mem)
7423587082bSAvi Kivity {
7433587082bSAvi Kivity     uint64_t v;
7443587082bSAvi Kivity 
7453587082bSAvi Kivity     write_cr0(read_cr0() & ~6); /* EM, TS */
7463587082bSAvi Kivity     asm volatile("fninit");
7473587082bSAvi Kivity     v = 0x0102030405060708ULL;
7483587082bSAvi Kivity     asm("movq %1, %0" : "=m"(*mem) : "y"(v));
749a299895bSThomas Huth     report(v == *mem, "movq (mmx, read)");
7503587082bSAvi Kivity     *mem = 0x8070605040302010ull;
7513587082bSAvi Kivity     asm("movq %1, %0" : "=y"(v) : "m"(*mem));
752a299895bSThomas Huth     report(v == *mem, "movq (mmx, write)");
7533587082bSAvi Kivity }
7543587082bSAvi Kivity 
7558cfa5a06SAvi Kivity static void test_rip_relative(unsigned *mem, char *insn_ram)
7568cfa5a06SAvi Kivity {
7578cfa5a06SAvi Kivity     /* movb $1, mem+2(%rip) */
7588cfa5a06SAvi Kivity     insn_ram[0] = 0xc6;
7598cfa5a06SAvi Kivity     insn_ram[1] = 0x05;
7608cfa5a06SAvi Kivity     *(unsigned *)&insn_ram[2] = 2 + (char *)mem - (insn_ram + 7);
7618cfa5a06SAvi Kivity     insn_ram[6] = 0x01;
7628cfa5a06SAvi Kivity     /* ret */
7638cfa5a06SAvi Kivity     insn_ram[7] = 0xc3;
7648cfa5a06SAvi Kivity 
7658cfa5a06SAvi Kivity     *mem = 0;
7668cfa5a06SAvi Kivity     asm("callq *%1" : "+m"(*mem) : "r"(insn_ram));
767a299895bSThomas Huth     report(*mem == 0x10000, "movb $imm, 0(%%rip)");
7688cfa5a06SAvi Kivity }
769d7f3ee3cSAvi Kivity 
770b212fcdaSAvi Kivity static void test_shld_shrd(u32 *mem)
771b212fcdaSAvi Kivity {
772b212fcdaSAvi Kivity     *mem = 0x12345678;
773b212fcdaSAvi Kivity     asm("shld %2, %1, %0" : "+m"(*mem) : "r"(0xaaaaaaaaU), "c"((u8)3));
774a299895bSThomas Huth     report(*mem == ((0x12345678 << 3) | 5), "shld (cl)");
775b212fcdaSAvi Kivity     *mem = 0x12345678;
776b212fcdaSAvi Kivity     asm("shrd %2, %1, %0" : "+m"(*mem) : "r"(0x55555555U), "c"((u8)3));
777a299895bSThomas Huth     report(*mem == ((0x12345678 >> 3) | (5u << 29)), "shrd (cl)");
778b212fcdaSAvi Kivity }
779b212fcdaSAvi Kivity 
78030762176SNadav Amit static void test_cmov(u32 *mem)
78130762176SNadav Amit {
78230762176SNadav Amit 	u64 val;
78330762176SNadav Amit 	*mem = 0xabcdef12u;
78430762176SNadav Amit 	asm ("movq $0x1234567812345678, %%rax\n\t"
78530762176SNadav Amit 	     "cmpl %%eax, %%eax\n\t"
78630762176SNadav Amit 	     "cmovnel (%[mem]), %%eax\n\t"
78730762176SNadav Amit 	     "movq %%rax, %[val]\n\t"
78830762176SNadav Amit 	     : [val]"=r"(val) : [mem]"r"(mem) : "%rax", "cc");
789a299895bSThomas Huth 	report(val == 0x12345678ul, "cmovnel");
79030762176SNadav Amit }
79130762176SNadav Amit 
792c2aa6128SPeter Feiner static unsigned long rip_advance;
793c2aa6128SPeter Feiner 
794c2aa6128SPeter Feiner static void advance_rip_and_note_exception(struct ex_regs *regs)
795d7143f32SAvi Kivity {
796d7143f32SAvi Kivity     ++exceptions;
797c2aa6128SPeter Feiner     regs->rip += rip_advance;
798d7143f32SAvi Kivity }
799d7143f32SAvi Kivity 
80045fdc228SPaolo Bonzini static void test_mmx_movq_mf(uint64_t *mem)
801d7143f32SAvi Kivity {
8023af6fbbeSArthur Chunqi Li 	/* movq %mm0, (%rax) */
80345fdc228SPaolo Bonzini 	extern char movq_start, movq_end;
80415bfae71SMichal Luczaj 	handler old;
805d7143f32SAvi Kivity 
80645fdc228SPaolo Bonzini 	uint16_t fcw = 0;  /* all exceptions unmasked */
8073af6fbbeSArthur Chunqi Li 	write_cr0(read_cr0() & ~6);  /* TS, EM */
808d7143f32SAvi Kivity 	exceptions = 0;
80915bfae71SMichal Luczaj 	old = handle_exception(MF_VECTOR, advance_rip_and_note_exception);
810d7143f32SAvi Kivity 	asm volatile("fninit; fldcw %0" : : "m"(fcw));
8113af6fbbeSArthur Chunqi Li 	asm volatile("fldz; fldz; fdivp"); /* generate exception */
8123af6fbbeSArthur Chunqi Li 
81345fdc228SPaolo Bonzini 	rip_advance = &movq_end - &movq_start;
81445fdc228SPaolo Bonzini 	asm(KVM_FEP "movq_start: movq %mm0, (%rax); movq_end:");
8153af6fbbeSArthur Chunqi Li 	/* exit MMX mode */
816d7143f32SAvi Kivity 	asm volatile("fnclex; emms");
817a299895bSThomas Huth 	report(exceptions == 1, "movq mmx generates #MF");
81815bfae71SMichal Luczaj 	handle_exception(MF_VECTOR, old);
819d7143f32SAvi Kivity }
820d7143f32SAvi Kivity 
821f413c1afSNadav Amit static void test_jmp_noncanonical(uint64_t *mem)
822f413c1afSNadav Amit {
823c2aa6128SPeter Feiner 	extern char nc_jmp_start, nc_jmp_end;
82415bfae71SMichal Luczaj 	handler old;
825c2aa6128SPeter Feiner 
826f413c1afSNadav Amit 	*mem = 0x1111111111111111ul;
827f413c1afSNadav Amit 
828f413c1afSNadav Amit 	exceptions = 0;
829c2aa6128SPeter Feiner 	rip_advance = &nc_jmp_end - &nc_jmp_start;
83015bfae71SMichal Luczaj 	old = handle_exception(GP_VECTOR, advance_rip_and_note_exception);
831c2aa6128SPeter Feiner 	asm volatile ("nc_jmp_start: jmp *%0; nc_jmp_end:" : : "m"(*mem));
832a299895bSThomas Huth 	report(exceptions == 1, "jump to non-canonical address");
83315bfae71SMichal Luczaj 	handle_exception(GP_VECTOR, old);
834f413c1afSNadav Amit }
835f413c1afSNadav Amit 
83645fdc228SPaolo Bonzini static void test_movabs(uint64_t *mem)
83759033f47SPaolo Bonzini {
8383af6fbbeSArthur Chunqi Li     /* mov $0x9090909090909090, %rcx */
83945fdc228SPaolo Bonzini     unsigned long rcx;
84045fdc228SPaolo Bonzini     asm(KVM_FEP "mov $0x9090909090909090, %0" : "=c" (rcx) : "0" (0));
841a299895bSThomas Huth     report(rcx == 0x9090909090909090, "64-bit mov imm2");
84259033f47SPaolo Bonzini }
84359033f47SPaolo Bonzini 
84445fdc228SPaolo Bonzini static void test_smsw_reg(uint64_t *mem)
845313f4efeSNadav Amit {
846313f4efeSNadav Amit 	unsigned long cr0 = read_cr0();
84745fdc228SPaolo Bonzini 	unsigned long rax;
84845fdc228SPaolo Bonzini 	const unsigned long in_rax = 0x1234567890abcdeful;
849313f4efeSNadav Amit 
85045fdc228SPaolo Bonzini 	asm(KVM_FEP "smsww %w0\n\t" : "=a" (rax) : "0" (in_rax));
851a299895bSThomas Huth 	report((u16)rax == (u16)cr0 && rax >> 16 == in_rax >> 16,
852a299895bSThomas Huth 	       "16-bit smsw reg");
853313f4efeSNadav Amit 
85445fdc228SPaolo Bonzini 	asm(KVM_FEP "smswl %k0\n\t" : "=a" (rax) : "0" (in_rax));
855a299895bSThomas Huth 	report(rax == (u32)cr0, "32-bit smsw reg");
856313f4efeSNadav Amit 
8572f394044SBill Wendling 	asm(KVM_FEP "smswq %q0\n\t" : "=a" (rax) : "0" (in_rax));
858a299895bSThomas Huth 	report(rax == cr0, "64-bit smsw reg");
859313f4efeSNadav Amit }
860313f4efeSNadav Amit 
86145fdc228SPaolo Bonzini static void test_nop(uint64_t *mem)
862ae399010SNadav Amit {
86345fdc228SPaolo Bonzini 	unsigned long rax;
86445fdc228SPaolo Bonzini 	const unsigned long in_rax = 0x1234567890abcdeful;
86545fdc228SPaolo Bonzini 	asm(KVM_FEP "nop\n\t" : "=a" (rax) : "0" (in_rax));
866a299895bSThomas Huth 	report(rax == in_rax, "nop");
867ae399010SNadav Amit }
868ae399010SNadav Amit 
86945fdc228SPaolo Bonzini static void test_mov_dr(uint64_t *mem)
870b39a3e14SNadav Amit {
87145fdc228SPaolo Bonzini 	unsigned long rax;
872f1dcfd54SSean Christopherson 
87345fdc228SPaolo Bonzini 	asm(KVM_FEP "movq %0, %%dr6\n\t"
874f1dcfd54SSean Christopherson 	    KVM_FEP "movq %%dr6, %0\n\t" : "=a" (rax) : "a" (0));
875f1dcfd54SSean Christopherson 
876f1dcfd54SSean Christopherson 	if (this_cpu_has(X86_FEATURE_RTM))
877f1dcfd54SSean Christopherson 		report(rax == (DR6_ACTIVE_LOW & ~DR6_RTM), "mov_dr6");
878f1dcfd54SSean Christopherson 	else
879f1dcfd54SSean Christopherson 		report(rax == DR6_ACTIVE_LOW, "mov_dr6");
880b39a3e14SNadav Amit }
881b39a3e14SNadav Amit 
8820dcb3fbaSMichal Luczaj static void test_illegal_lea(void)
8830dcb3fbaSMichal Luczaj {
8840dcb3fbaSMichal Luczaj 	unsigned int vector;
8850dcb3fbaSMichal Luczaj 
8860dcb3fbaSMichal Luczaj 	asm volatile (ASM_TRY_FEP("1f")
8870dcb3fbaSMichal Luczaj 		      ".byte 0x8d; .byte 0xc0\n\t"
8880dcb3fbaSMichal Luczaj 		      "1:"
8890dcb3fbaSMichal Luczaj 		      : : : "memory", "eax");
8900dcb3fbaSMichal Luczaj 
8910dcb3fbaSMichal Luczaj 	vector = exception_vector();
8920dcb3fbaSMichal Luczaj 	report(vector == UD_VECTOR,
8930dcb3fbaSMichal Luczaj 	       "Wanted #UD on LEA with /reg, got vector = %u", vector);
8940dcb3fbaSMichal Luczaj }
8950dcb3fbaSMichal Luczaj 
89626311ca9SNadav Amit static void test_push16(uint64_t *mem)
89726311ca9SNadav Amit {
89826311ca9SNadav Amit 	uint64_t rsp1, rsp2;
89926311ca9SNadav Amit 	uint16_t r;
90026311ca9SNadav Amit 
90126311ca9SNadav Amit 	asm volatile (	"movq %%rsp, %[rsp1]\n\t"
90226311ca9SNadav Amit 			"pushw %[v]\n\t"
90326311ca9SNadav Amit 			"popw %[r]\n\t"
90426311ca9SNadav Amit 			"movq %%rsp, %[rsp2]\n\t"
90526311ca9SNadav Amit 			"movq %[rsp1], %%rsp\n\t" :
90626311ca9SNadav Amit 			[rsp1]"=r"(rsp1), [rsp2]"=r"(rsp2), [r]"=r"(r)
90726311ca9SNadav Amit 			: [v]"m"(*mem) : "memory");
908a299895bSThomas Huth 	report(rsp1 == rsp2, "push16");
90926311ca9SNadav Amit }
91026311ca9SNadav Amit 
911ec278ce3SAvi Kivity static void test_crosspage_mmio(volatile uint8_t *mem)
912ec278ce3SAvi Kivity {
913ec278ce3SAvi Kivity     volatile uint16_t w, *pw;
914ec278ce3SAvi Kivity 
915ec278ce3SAvi Kivity     pw = (volatile uint16_t *)&mem[4095];
916ec278ce3SAvi Kivity     mem[4095] = 0x99;
917ec278ce3SAvi Kivity     mem[4096] = 0x77;
918ec278ce3SAvi Kivity     asm volatile("mov %1, %0" : "=r"(w) : "m"(*pw) : "memory");
919a299895bSThomas Huth     report(w == 0x7799, "cross-page mmio read");
920ec278ce3SAvi Kivity     asm volatile("mov %1, %0" : "=m"(*pw) : "r"((uint16_t)0x88aa));
921a299895bSThomas Huth     report(mem[4095] == 0xaa && mem[4096] == 0x88, "cross-page mmio write");
922ec278ce3SAvi Kivity }
923ec278ce3SAvi Kivity 
924a19c7db7SXiao Guangrong static void test_string_io_mmio(volatile uint8_t *mem)
925a19c7db7SXiao Guangrong {
926a19c7db7SXiao Guangrong 	/* Cross MMIO pages.*/
927a19c7db7SXiao Guangrong 	volatile uint8_t *mmio = mem + 4032;
928a19c7db7SXiao Guangrong 
929a19c7db7SXiao Guangrong 	asm volatile("outw %%ax, %%dx  \n\t" : : "a"(0x9999), "d"(TESTDEV_IO_PORT));
930a19c7db7SXiao Guangrong 
931a19c7db7SXiao Guangrong 	asm volatile ("cld; rep insb" : : "d" (TESTDEV_IO_PORT), "D" (mmio), "c" (1024));
932a19c7db7SXiao Guangrong 
933a299895bSThomas Huth 	report(mmio[1023] == 0x99, "string_io_mmio");
934a19c7db7SXiao Guangrong }
935a19c7db7SXiao Guangrong 
93656c6afa7SJan Kiszka /* kvm doesn't allow lidt/lgdt from mmio, so the test is disabled */
93756c6afa7SJan Kiszka #if 0
93847c1461aSAvi Kivity static void test_lgdt_lidt(volatile uint8_t *mem)
93947c1461aSAvi Kivity {
94047c1461aSAvi Kivity     struct descriptor_table_ptr orig, fresh = {};
94147c1461aSAvi Kivity 
94247c1461aSAvi Kivity     sgdt(&orig);
94347c1461aSAvi Kivity     *(struct descriptor_table_ptr *)mem = (struct descriptor_table_ptr) {
94447c1461aSAvi Kivity 	.limit = 0xf234,
94547c1461aSAvi Kivity 	.base = 0x12345678abcd,
94647c1461aSAvi Kivity     };
94747c1461aSAvi Kivity     cli();
94847c1461aSAvi Kivity     asm volatile("lgdt %0" : : "m"(*(struct descriptor_table_ptr *)mem));
94947c1461aSAvi Kivity     sgdt(&fresh);
95047c1461aSAvi Kivity     lgdt(&orig);
95147c1461aSAvi Kivity     sti();
952a299895bSThomas Huth     report(orig.limit == fresh.limit && orig.base == fresh.base,
953a299895bSThomas Huth            "lgdt (long address)");
95447c1461aSAvi Kivity 
95547c1461aSAvi Kivity     sidt(&orig);
95647c1461aSAvi Kivity     *(struct descriptor_table_ptr *)mem = (struct descriptor_table_ptr) {
95747c1461aSAvi Kivity 	.limit = 0x432f,
95847c1461aSAvi Kivity 	.base = 0xdbca87654321,
95947c1461aSAvi Kivity     };
96047c1461aSAvi Kivity     cli();
96147c1461aSAvi Kivity     asm volatile("lidt %0" : : "m"(*(struct descriptor_table_ptr *)mem));
96247c1461aSAvi Kivity     sidt(&fresh);
96347c1461aSAvi Kivity     lidt(&orig);
96447c1461aSAvi Kivity     sti();
965a299895bSThomas Huth     report(orig.limit == fresh.limit && orig.base == fresh.base,
966a299895bSThomas Huth            "lidt (long address)");
96747c1461aSAvi Kivity }
96856c6afa7SJan Kiszka #endif
96947c1461aSAvi Kivity 
970fc2f880bSAvi Kivity static void ss_bad_rpl(struct ex_regs *regs)
971fc2f880bSAvi Kivity {
972fc2f880bSAvi Kivity     extern char ss_bad_rpl_cont;
973fc2f880bSAvi Kivity 
974fc2f880bSAvi Kivity     ++exceptions;
975fc2f880bSAvi Kivity     regs->rip = (ulong)&ss_bad_rpl_cont;
976fc2f880bSAvi Kivity }
977fc2f880bSAvi Kivity 
978fc2f880bSAvi Kivity static void test_sreg(volatile uint16_t *mem)
979fc2f880bSAvi Kivity {
980fc2f880bSAvi Kivity 	u16 ss = read_ss();
98115bfae71SMichal Luczaj 	handler old;
982fc2f880bSAvi Kivity 
983fc2f880bSAvi Kivity 	// check for null segment load
984fc2f880bSAvi Kivity 	*mem = 0;
985fc2f880bSAvi Kivity 	asm volatile("mov %0, %%ss" : : "m"(*mem));
986a299895bSThomas Huth 	report(read_ss() == 0, "mov null, %%ss");
987fc2f880bSAvi Kivity 
988fc2f880bSAvi Kivity 	// check for exception when ss.rpl != cpl on null segment load
989fc2f880bSAvi Kivity 	exceptions = 0;
99015bfae71SMichal Luczaj 	old = handle_exception(GP_VECTOR, ss_bad_rpl);
991fc2f880bSAvi Kivity 	*mem = 3;
992fc2f880bSAvi Kivity 	asm volatile("mov %0, %%ss; ss_bad_rpl_cont:" : : "m"(*mem));
993a299895bSThomas Huth 	report(exceptions == 1 && read_ss() == 0,
994a299895bSThomas Huth 	       "mov null, %%ss (with ss.rpl != cpl)");
99515bfae71SMichal Luczaj 	handle_exception(GP_VECTOR, old);
996fc2f880bSAvi Kivity 	write_ss(ss);
997fc2f880bSAvi Kivity }
998fc2f880bSAvi Kivity 
9993ee1b91bSBin Meng static uint64_t usr_gs_mov(void)
10003ee1b91bSBin Meng {
10013ee1b91bSBin Meng     static uint64_t dummy = MAGIC_NUM;
10023ee1b91bSBin Meng     uint64_t dummy_ptr = (uint64_t)&dummy;
10033ee1b91bSBin Meng     uint64_t ret;
10043ee1b91bSBin Meng 
10053ee1b91bSBin Meng     dummy_ptr -= GS_BASE;
10063ee1b91bSBin Meng     asm volatile("mov %%gs:(%%rcx), %%rax" : "=a"(ret): "c"(dummy_ptr) :);
10073ee1b91bSBin Meng 
10083ee1b91bSBin Meng     return ret;
10093ee1b91bSBin Meng }
10103ee1b91bSBin Meng 
10113ee1b91bSBin Meng static void test_iret(void)
10123ee1b91bSBin Meng {
10133ee1b91bSBin Meng     uint64_t val;
10143ee1b91bSBin Meng     bool raised_vector;
10153ee1b91bSBin Meng 
10163ee1b91bSBin Meng     /* Update GS base to 4MiB */
10173ee1b91bSBin Meng     wrmsr(MSR_GS_BASE, GS_BASE);
10183ee1b91bSBin Meng 
10193ee1b91bSBin Meng     /*
10203ee1b91bSBin Meng      * Per the SDM, jumping to user mode via `iret`, which is returning to
10213ee1b91bSBin Meng      * outer privilege level, for segment registers (ES, FS, GS, and DS)
10223ee1b91bSBin Meng      * if the check fails, the segment selector becomes null.
10233ee1b91bSBin Meng      *
10243ee1b91bSBin Meng      * In our test case, GS becomes null.
10253ee1b91bSBin Meng      */
10263ee1b91bSBin Meng     val = run_in_user((usermode_func)usr_gs_mov, GP_VECTOR,
10273ee1b91bSBin Meng                       0, 0, 0, 0, &raised_vector);
10283ee1b91bSBin Meng 
10293ee1b91bSBin Meng     report(val == MAGIC_NUM, "Test ret/iret with a nullified segment");
10303ee1b91bSBin Meng }
10313ee1b91bSBin Meng 
10324425dba6SPeter Feiner /* Broken emulation causes triple fault, which skips the other tests. */
10334425dba6SPeter Feiner #if 0
1034cb615a4dSAvi Kivity static void test_lldt(volatile uint16_t *mem)
1035cb615a4dSAvi Kivity {
10364425dba6SPeter Feiner     u64 gdt[] = { 0, /* null descriptor */
10374425dba6SPeter Feiner #ifdef __X86_64__
10384425dba6SPeter Feiner 		  0, /* ldt descriptor is 16 bytes in long mode */
10394425dba6SPeter Feiner #endif
10404425dba6SPeter Feiner 		  0x0000f82000000ffffull /* ldt descriptor */ };
10414425dba6SPeter Feiner     struct descriptor_table_ptr gdt_ptr = { .limit = sizeof(gdt) - 1,
10424425dba6SPeter Feiner 					    .base = (ulong)&gdt };
1043cb615a4dSAvi Kivity     struct descriptor_table_ptr orig_gdt;
1044cb615a4dSAvi Kivity 
1045cb615a4dSAvi Kivity     cli();
1046cb615a4dSAvi Kivity     sgdt(&orig_gdt);
1047cb615a4dSAvi Kivity     lgdt(&gdt_ptr);
1048cb615a4dSAvi Kivity     *mem = 0x8;
1049cb615a4dSAvi Kivity     asm volatile("lldt %0" : : "m"(*mem));
1050cb615a4dSAvi Kivity     lgdt(&orig_gdt);
1051cb615a4dSAvi Kivity     sti();
1052a299895bSThomas Huth     report(sldt() == *mem, "lldt");
1053cb615a4dSAvi Kivity }
10544425dba6SPeter Feiner #endif
1055cb615a4dSAvi Kivity 
105658a9d81eSAvi Kivity static void test_ltr(volatile uint16_t *mem)
105758a9d81eSAvi Kivity {
105858a9d81eSAvi Kivity     struct descriptor_table_ptr gdt_ptr;
105958a9d81eSAvi Kivity     uint64_t *gdt, *trp;
106058a9d81eSAvi Kivity     uint16_t tr = str();
106158a9d81eSAvi Kivity     uint64_t busy_mask = (uint64_t)1 << 41;
106258a9d81eSAvi Kivity 
106358a9d81eSAvi Kivity     sgdt(&gdt_ptr);
106458a9d81eSAvi Kivity     gdt = (uint64_t *)gdt_ptr.base;
106558a9d81eSAvi Kivity     trp = &gdt[tr >> 3];
106658a9d81eSAvi Kivity     *trp &= ~busy_mask;
106758a9d81eSAvi Kivity     *mem = tr;
106858a9d81eSAvi Kivity     asm volatile("ltr %0" : : "m"(*mem) : "memory");
1069a299895bSThomas Huth     report(str() == tr && (*trp & busy_mask), "ltr");
107058a9d81eSAvi Kivity }
107158a9d81eSAvi Kivity 
1072*215ad64cSSean Christopherson static void test_mov(void *mem)
1073*215ad64cSSean Christopherson {
1074*215ad64cSSean Christopherson 	unsigned long t1, t2;
1075*215ad64cSSean Christopherson 
1076*215ad64cSSean Christopherson 	// test mov reg, r/m and mov r/m, reg
1077*215ad64cSSean Christopherson 	t1 = 0x123456789abcdef;
1078*215ad64cSSean Christopherson 	asm volatile("mov %[t1], (%[mem]) \n\t"
1079*215ad64cSSean Christopherson 		     "mov (%[mem]), %[t2]"
1080*215ad64cSSean Christopherson 		     : [t2]"=r"(t2)
1081*215ad64cSSean Christopherson 		     : [t1]"r"(t1), [mem]"r"(mem)
1082*215ad64cSSean Christopherson 		     : "memory");
1083*215ad64cSSean Christopherson 	report(t2 == 0x123456789abcdef, "mov reg, r/m (1)");
1084*215ad64cSSean Christopherson }
1085*215ad64cSSean Christopherson 
10866cff92ddSAvi Kivity static void test_simplealu(u32 *mem)
10876cff92ddSAvi Kivity {
10886cff92ddSAvi Kivity     *mem = 0x1234;
10896cff92ddSAvi Kivity     asm("or %1, %0" : "+m"(*mem) : "r"(0x8001));
1090a299895bSThomas Huth     report(*mem == 0x9235, "or");
10916cff92ddSAvi Kivity     asm("add %1, %0" : "+m"(*mem) : "r"(2));
1092a299895bSThomas Huth     report(*mem == 0x9237, "add");
10936cff92ddSAvi Kivity     asm("xor %1, %0" : "+m"(*mem) : "r"(0x1111));
1094a299895bSThomas Huth     report(*mem == 0x8326, "xor");
10956cff92ddSAvi Kivity     asm("sub %1, %0" : "+m"(*mem) : "r"(0x26));
1096a299895bSThomas Huth     report(*mem == 0x8300, "sub");
10976cff92ddSAvi Kivity     asm("clc; adc %1, %0" : "+m"(*mem) : "r"(0x100));
1098a299895bSThomas Huth     report(*mem == 0x8400, "adc(0)");
10996cff92ddSAvi Kivity     asm("stc; adc %1, %0" : "+m"(*mem) : "r"(0x100));
1100a299895bSThomas Huth     report(*mem == 0x8501, "adc(0)");
11016cff92ddSAvi Kivity     asm("clc; sbb %1, %0" : "+m"(*mem) : "r"(0));
1102a299895bSThomas Huth     report(*mem == 0x8501, "sbb(0)");
11036cff92ddSAvi Kivity     asm("stc; sbb %1, %0" : "+m"(*mem) : "r"(0));
1104a299895bSThomas Huth     report(*mem == 0x8500, "sbb(1)");
11056cff92ddSAvi Kivity     asm("and %1, %0" : "+m"(*mem) : "r"(0xfe77));
1106a299895bSThomas Huth     report(*mem == 0x8400, "and");
11076cff92ddSAvi Kivity     asm("test %1, %0" : "+m"(*mem) : "r"(0xf000));
1108a299895bSThomas Huth     report(*mem == 0x8400, "test");
11096cff92ddSAvi Kivity }
11106cff92ddSAvi Kivity 
111170bdcadbSNadav Amit static void test_illegal_movbe(void)
111270bdcadbSNadav Amit {
11133af47210SMichal Luczaj 	unsigned int vector;
11143af47210SMichal Luczaj 
1115badc98caSKrish Sadhukhan 	if (!this_cpu_has(X86_FEATURE_MOVBE)) {
11163af47210SMichal Luczaj 		report_skip("MOVBE unsupported by CPU");
111770bdcadbSNadav Amit 		return;
111870bdcadbSNadav Amit 	}
111970bdcadbSNadav Amit 
11203af47210SMichal Luczaj 	asm volatile(ASM_TRY("1f")
11213af47210SMichal Luczaj 		     ".byte 0x0f; .byte 0x38; .byte 0xf0; .byte 0xc0;\n\t"
11223af47210SMichal Luczaj 		     "1:"
11233af47210SMichal Luczaj 		     : : : "memory", "rax");
11243af47210SMichal Luczaj 
11253af47210SMichal Luczaj 	vector = exception_vector();
11263af47210SMichal Luczaj 	report(vector == UD_VECTOR,
11273af47210SMichal Luczaj 	       "Wanted #UD on MOVBE with /reg, got vector = %u", vector);
112870bdcadbSNadav Amit }
112970bdcadbSNadav Amit 
11307db17e21SThomas Huth int main(void)
11317d36db35SAvi Kivity {
11327d36db35SAvi Kivity 	void *mem;
113345fdc228SPaolo Bonzini 	void *insn_page;
11348cfa5a06SAvi Kivity 	void *insn_ram;
1135e5e76263SJacob Xu 	void *cross_mem;
11367d36db35SAvi Kivity 
11377d36db35SAvi Kivity 	setup_vm();
113845fdc228SPaolo Bonzini 
1139ec278ce3SAvi Kivity 	mem = alloc_vpages(2);
1140ec278ce3SAvi Kivity 	install_page((void *)read_cr3(), IORAM_BASE_PHYS, mem);
1141ec278ce3SAvi Kivity 	// install the page twice to test cross-page mmio
1142ec278ce3SAvi Kivity 	install_page((void *)read_cr3(), IORAM_BASE_PHYS, mem + 4096);
1143d7143f32SAvi Kivity 	insn_page = alloc_page();
1144d7143f32SAvi Kivity 	insn_ram = vmap(virt_to_phys(insn_page), 4096);
1145e5e76263SJacob Xu 	cross_mem = vmap(virt_to_phys(alloc_pages(2)), 2 * PAGE_SIZE);
11467d36db35SAvi Kivity 
1147*215ad64cSSean Christopherson 	test_mov(mem);
11486cff92ddSAvi Kivity 	test_simplealu(mem);
11497d36db35SAvi Kivity 	test_cmps(mem);
115080a4ea7bSAvi Kivity 	test_scas(mem);
11517d36db35SAvi Kivity 
11527d36db35SAvi Kivity 	test_push(mem);
11537d36db35SAvi Kivity 	test_pop(mem);
11547d36db35SAvi Kivity 
11557d36db35SAvi Kivity 	test_xchg(mem);
11565647d55cSWei Yongjun 	test_xadd(mem);
11577d36db35SAvi Kivity 
11587d36db35SAvi Kivity 	test_cr8();
11597d36db35SAvi Kivity 
11604003963dSNadav Amit 	test_smsw(mem);
11617d36db35SAvi Kivity 	test_lmsw();
11627d36db35SAvi Kivity 	test_ljmp(mem);
11637d36db35SAvi Kivity 	test_stringio();
11647d36db35SAvi Kivity 	test_incdecnotneg(mem);
1165d4655eafSWei Yongjun 	test_btc(mem);
11662e16c7f6SWei Yongjun 	test_bsfbsr(mem);
116751d65a3cSAvi Kivity 	test_imul(mem);
1168c2c43fcfSAvi Kivity 	test_muldiv(mem);
1169d7f3ee3cSAvi Kivity 	test_sse(mem);
1170e5e76263SJacob Xu 	test_sse_exceptions(cross_mem);
11713587082bSAvi Kivity 	test_mmx(mem);
11728cfa5a06SAvi Kivity 	test_rip_relative(mem, insn_ram);
1173b212fcdaSAvi Kivity 	test_shld_shrd(mem);
117447c1461aSAvi Kivity 	//test_lgdt_lidt(mem);
1175fc2f880bSAvi Kivity 	test_sreg(mem);
11763ee1b91bSBin Meng 	test_iret();
11774425dba6SPeter Feiner 	//test_lldt(mem);
117858a9d81eSAvi Kivity 	test_ltr(mem);
117930762176SNadav Amit 	test_cmov(mem);
11807d36db35SAvi Kivity 
11817948d4b6SSean Christopherson 	if (is_fep_available()) {
118245fdc228SPaolo Bonzini 		test_mmx_movq_mf(mem);
118345fdc228SPaolo Bonzini 		test_movabs(mem);
118445fdc228SPaolo Bonzini 		test_smsw_reg(mem);
118545fdc228SPaolo Bonzini 		test_nop(mem);
118645fdc228SPaolo Bonzini 		test_mov_dr(mem);
11870dcb3fbaSMichal Luczaj 		test_illegal_lea();
118845fdc228SPaolo Bonzini 	} else {
118945fdc228SPaolo Bonzini 		report_skip("skipping register-only tests, "
1190622ad98fSSiddharth Chandrasekaran 			    "use kvm.force_emulation_prefix=1 to enable");
119145fdc228SPaolo Bonzini 	}
119245fdc228SPaolo Bonzini 
119326311ca9SNadav Amit 	test_push16(mem);
1194ec278ce3SAvi Kivity 	test_crosspage_mmio(mem);
1195ec278ce3SAvi Kivity 
1196a19c7db7SXiao Guangrong 	test_string_io_mmio(mem);
1197a19c7db7SXiao Guangrong 
1198f413c1afSNadav Amit 	test_jmp_noncanonical(mem);
119970bdcadbSNadav Amit 	test_illegal_movbe();
1200f413c1afSNadav Amit 
1201f3cdd159SJan Kiszka 	return report_summary();
12027d36db35SAvi Kivity }
1203