17d36db35SAvi Kivity #include "ioram.h" 27d36db35SAvi Kivity #include "vm.h" 37d36db35SAvi Kivity #include "libcflat.h" 4e7c37968SGleb Natapov #include "desc.h" 5d7143f32SAvi Kivity #include "types.h" 6b39a3e14SNadav Amit #include "processor.h" 7efd8e5aaSPaolo Bonzini #include "vmalloc.h" 85aca024eSPaolo Bonzini #include "alloc_page.h" 93ee1b91bSBin Meng #include "usermode.h" 107d36db35SAvi Kivity 117d36db35SAvi Kivity #define memset __builtin_memset 127d36db35SAvi Kivity #define TESTDEV_IO_PORT 0xe0 137d36db35SAvi Kivity 143ee1b91bSBin Meng #define MAGIC_NUM 0xdeadbeefdeadbeefUL 153ee1b91bSBin Meng #define GS_BASE 0x400000 163ee1b91bSBin Meng 17d7143f32SAvi Kivity static int exceptions; 18d7143f32SAvi Kivity 1945fdc228SPaolo Bonzini /* Forced emulation prefix, used to invoke the emulator unconditionally. */ 2045fdc228SPaolo Bonzini #define KVM_FEP "ud2; .byte 'k', 'v', 'm';" 2145fdc228SPaolo Bonzini #define KVM_FEP_LENGTH 5 2245fdc228SPaolo Bonzini static int fep_available = 1; 2345fdc228SPaolo Bonzini 24c5a2a731SArthur Chunqi Li struct regs { 25c5a2a731SArthur Chunqi Li u64 rax, rbx, rcx, rdx; 26c5a2a731SArthur Chunqi Li u64 rsi, rdi, rsp, rbp; 27c5a2a731SArthur Chunqi Li u64 r8, r9, r10, r11; 28c5a2a731SArthur Chunqi Li u64 r12, r13, r14, r15; 29c5a2a731SArthur Chunqi Li u64 rip, rflags; 30c5a2a731SArthur Chunqi Li }; 31c5a2a731SArthur Chunqi Li struct regs inregs, outregs, save; 32c5a2a731SArthur Chunqi Li 33c5a2a731SArthur Chunqi Li struct insn_desc { 34c5a2a731SArthur Chunqi Li u64 ptr; 35c5a2a731SArthur Chunqi Li size_t len; 36c5a2a731SArthur Chunqi Li }; 37c5a2a731SArthur Chunqi Li 387d36db35SAvi Kivity static char st1[] = "abcdefghijklmnop"; 397d36db35SAvi Kivity 407db17e21SThomas Huth static void test_stringio(void) 417d36db35SAvi Kivity { 427d36db35SAvi Kivity unsigned char r = 0; 437d36db35SAvi Kivity asm volatile("cld \n\t" 447d36db35SAvi Kivity "movw %0, %%dx \n\t" 457d36db35SAvi Kivity "rep outsb \n\t" 467d36db35SAvi Kivity : : "i"((short)TESTDEV_IO_PORT), 477d36db35SAvi Kivity "S"(st1), "c"(sizeof(st1) - 1)); 487d36db35SAvi Kivity asm volatile("inb %1, %0\n\t" : "=a"(r) : "i"((short)TESTDEV_IO_PORT)); 49a299895bSThomas Huth report(r == st1[sizeof(st1) - 2], "outsb up"); /* last char */ 507d36db35SAvi Kivity 517d36db35SAvi Kivity asm volatile("std \n\t" 527d36db35SAvi Kivity "movw %0, %%dx \n\t" 537d36db35SAvi Kivity "rep outsb \n\t" 547d36db35SAvi Kivity : : "i"((short)TESTDEV_IO_PORT), 557d36db35SAvi Kivity "S"(st1 + sizeof(st1) - 2), "c"(sizeof(st1) - 1)); 567d36db35SAvi Kivity asm volatile("cld \n\t" : : ); 577d36db35SAvi Kivity asm volatile("in %1, %0\n\t" : "=a"(r) : "i"((short)TESTDEV_IO_PORT)); 58a299895bSThomas Huth report(r == st1[0], "outsb down"); 597d36db35SAvi Kivity } 607d36db35SAvi Kivity 61db4898e8SThomas Huth static void test_cmps_one(unsigned char *m1, unsigned char *m3) 627d36db35SAvi Kivity { 637d36db35SAvi Kivity void *rsi, *rdi; 647d36db35SAvi Kivity long rcx, tmp; 657d36db35SAvi Kivity 667d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 30; 677d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 682d331a4dSRoman Bolshakov "repe cmpsb" 697d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 707d36db35SAvi Kivity : : "cc"); 71a299895bSThomas Huth report(rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30, "repe/cmpsb (1)"); 727d36db35SAvi Kivity 7351ba4180SAvi Kivity rsi = m1; rdi = m3; rcx = 30; 7451ba4180SAvi Kivity asm volatile("or $1, %[tmp]\n\t" // clear ZF 752d331a4dSRoman Bolshakov "repe cmpsb" 7651ba4180SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 7751ba4180SAvi Kivity : : "cc"); 78a299895bSThomas Huth report(rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30, 792d331a4dSRoman Bolshakov "repe cmpsb (1.zf)"); 8051ba4180SAvi Kivity 817d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 15; 827d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 832d331a4dSRoman Bolshakov "repe cmpsw" 847d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 857d36db35SAvi Kivity : : "cc"); 862d331a4dSRoman Bolshakov report(rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30, "repe cmpsw (1)"); 877d36db35SAvi Kivity 887d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 7; 897d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 902d331a4dSRoman Bolshakov "repe cmpsl" 917d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 927d36db35SAvi Kivity : : "cc"); 932d331a4dSRoman Bolshakov report(rcx == 0 && rsi == m1 + 28 && rdi == m3 + 28, "repe cmpll (1)"); 947d36db35SAvi Kivity 957d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 4; 967d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 972d331a4dSRoman Bolshakov "repe cmpsq" 987d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 997d36db35SAvi Kivity : : "cc"); 1002d331a4dSRoman Bolshakov report(rcx == 0 && rsi == m1 + 32 && rdi == m3 + 32, "repe cmpsq (1)"); 1017d36db35SAvi Kivity 1027d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 130; 1037d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 1042d331a4dSRoman Bolshakov "repe cmpsb" 1057d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 1067d36db35SAvi Kivity : : "cc"); 107a299895bSThomas Huth report(rcx == 29 && rsi == m1 + 101 && rdi == m3 + 101, 1082d331a4dSRoman Bolshakov "repe cmpsb (2)"); 1097d36db35SAvi Kivity 1107d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 65; 1117d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 1122d331a4dSRoman Bolshakov "repe cmpsw" 1137d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 1147d36db35SAvi Kivity : : "cc"); 115a299895bSThomas Huth report(rcx == 14 && rsi == m1 + 102 && rdi == m3 + 102, 1162d331a4dSRoman Bolshakov "repe cmpsw (2)"); 1177d36db35SAvi Kivity 1187d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 32; 1197d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 1202d331a4dSRoman Bolshakov "repe cmpsl" 1217d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 1227d36db35SAvi Kivity : : "cc"); 123a299895bSThomas Huth report(rcx == 6 && rsi == m1 + 104 && rdi == m3 + 104, 1242d331a4dSRoman Bolshakov "repe cmpll (2)"); 1257d36db35SAvi Kivity 1267d36db35SAvi Kivity rsi = m1; rdi = m3; rcx = 16; 1277d36db35SAvi Kivity asm volatile("xor %[tmp], %[tmp] \n\t" 1282d331a4dSRoman Bolshakov "repe cmpsq" 1297d36db35SAvi Kivity : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp) 1307d36db35SAvi Kivity : : "cc"); 131a299895bSThomas Huth report(rcx == 3 && rsi == m1 + 104 && rdi == m3 + 104, 1322d331a4dSRoman Bolshakov "repe cmpsq (2)"); 1337d36db35SAvi Kivity 1347d36db35SAvi Kivity } 1357d36db35SAvi Kivity 136db4898e8SThomas Huth static void test_cmps(void *mem) 1377d36db35SAvi Kivity { 1387d36db35SAvi Kivity unsigned char *m1 = mem, *m2 = mem + 1024; 1397d36db35SAvi Kivity unsigned char m3[1024]; 1407d36db35SAvi Kivity 1417d36db35SAvi Kivity for (int i = 0; i < 100; ++i) 1427d36db35SAvi Kivity m1[i] = m2[i] = m3[i] = i; 1437d36db35SAvi Kivity for (int i = 100; i < 200; ++i) 1447d36db35SAvi Kivity m1[i] = (m3[i] = m2[i] = i) + 1; 1457d36db35SAvi Kivity test_cmps_one(m1, m3); 1467d36db35SAvi Kivity test_cmps_one(m1, m2); 1477d36db35SAvi Kivity } 1487d36db35SAvi Kivity 149db4898e8SThomas Huth static void test_scas(void *mem) 15080a4ea7bSAvi Kivity { 15180a4ea7bSAvi Kivity bool z; 15280a4ea7bSAvi Kivity void *di; 15380a4ea7bSAvi Kivity 15480a4ea7bSAvi Kivity *(ulong *)mem = 0x77665544332211; 15580a4ea7bSAvi Kivity 15680a4ea7bSAvi Kivity di = mem; 15780a4ea7bSAvi Kivity asm ("scasb; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff11)); 158a299895bSThomas Huth report(di == mem + 1 && z, "scasb match"); 15980a4ea7bSAvi Kivity 16080a4ea7bSAvi Kivity di = mem; 16180a4ea7bSAvi Kivity asm ("scasb; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff54)); 162a299895bSThomas Huth report(di == mem + 1 && !z, "scasb mismatch"); 16380a4ea7bSAvi Kivity 16480a4ea7bSAvi Kivity di = mem; 16580a4ea7bSAvi Kivity asm ("scasw; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff2211)); 166a299895bSThomas Huth report(di == mem + 2 && z, "scasw match"); 16780a4ea7bSAvi Kivity 16880a4ea7bSAvi Kivity di = mem; 16980a4ea7bSAvi Kivity asm ("scasw; setz %0" : "=rm"(z), "+D"(di) : "a"(0xffdd11)); 170a299895bSThomas Huth report(di == mem + 2 && !z, "scasw mismatch"); 17180a4ea7bSAvi Kivity 17280a4ea7bSAvi Kivity di = mem; 17380a4ea7bSAvi Kivity asm ("scasl; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff44332211ul)); 174a299895bSThomas Huth report(di == mem + 4 && z, "scasd match"); 17580a4ea7bSAvi Kivity 17680a4ea7bSAvi Kivity di = mem; 17780a4ea7bSAvi Kivity asm ("scasl; setz %0" : "=rm"(z), "+D"(di) : "a"(0x45332211)); 178a299895bSThomas Huth report(di == mem + 4 && !z, "scasd mismatch"); 17980a4ea7bSAvi Kivity 18080a4ea7bSAvi Kivity di = mem; 18180a4ea7bSAvi Kivity asm ("scasq; setz %0" : "=rm"(z), "+D"(di) : "a"(0x77665544332211ul)); 182a299895bSThomas Huth report(di == mem + 8 && z, "scasq match"); 18380a4ea7bSAvi Kivity 18480a4ea7bSAvi Kivity di = mem; 18580a4ea7bSAvi Kivity asm ("scasq; setz %0" : "=rm"(z), "+D"(di) : "a"(3)); 186a299895bSThomas Huth report(di == mem + 8 && !z, "scasq mismatch"); 18780a4ea7bSAvi Kivity } 18880a4ea7bSAvi Kivity 189db4898e8SThomas Huth static void test_cr8(void) 1907d36db35SAvi Kivity { 1917d36db35SAvi Kivity unsigned long src, dst; 1927d36db35SAvi Kivity 1937d36db35SAvi Kivity dst = 777; 1947d36db35SAvi Kivity src = 3; 1957d36db35SAvi Kivity asm volatile("mov %[src], %%cr8; mov %%cr8, %[dst]" 1967d36db35SAvi Kivity : [dst]"+r"(dst), [src]"+r"(src)); 197a299895bSThomas Huth report(dst == 3 && src == 3, "mov %%cr8"); 1987d36db35SAvi Kivity } 1997d36db35SAvi Kivity 200db4898e8SThomas Huth static void test_push(void *mem) 2017d36db35SAvi Kivity { 2027d36db35SAvi Kivity unsigned long tmp; 2037d36db35SAvi Kivity unsigned long *stack_top = mem + 4096; 2047d36db35SAvi Kivity unsigned long *new_stack_top; 2057d36db35SAvi Kivity unsigned long memw = 0x123456789abcdeful; 2067d36db35SAvi Kivity 2077d36db35SAvi Kivity memset(mem, 0x55, (void *)stack_top - mem); 2087d36db35SAvi Kivity 2097d36db35SAvi Kivity asm volatile("mov %%rsp, %[tmp] \n\t" 2107d36db35SAvi Kivity "mov %[stack_top], %%rsp \n\t" 2117d36db35SAvi Kivity "pushq $-7 \n\t" 2127d36db35SAvi Kivity "pushq %[reg] \n\t" 2137d36db35SAvi Kivity "pushq (%[mem]) \n\t" 2147d36db35SAvi Kivity "pushq $-7070707 \n\t" 2157d36db35SAvi Kivity "mov %%rsp, %[new_stack_top] \n\t" 2167d36db35SAvi Kivity "mov %[tmp], %%rsp" 2177d36db35SAvi Kivity : [tmp]"=&r"(tmp), [new_stack_top]"=r"(new_stack_top) 2187d36db35SAvi Kivity : [stack_top]"r"(stack_top), 2197d36db35SAvi Kivity [reg]"r"(-17l), [mem]"r"(&memw) 2207d36db35SAvi Kivity : "memory"); 2217d36db35SAvi Kivity 222a299895bSThomas Huth report(stack_top[-1] == -7ul, "push $imm8"); 223a299895bSThomas Huth report(stack_top[-2] == -17ul, "push %%reg"); 224a299895bSThomas Huth report(stack_top[-3] == 0x123456789abcdeful, "push mem"); 225a299895bSThomas Huth report(stack_top[-4] == -7070707, "push $imm"); 2267d36db35SAvi Kivity } 2277d36db35SAvi Kivity 228db4898e8SThomas Huth static void test_pop(void *mem) 2297d36db35SAvi Kivity { 23028f04f22SAvi Kivity unsigned long tmp, tmp3, rsp, rbp; 2317d36db35SAvi Kivity unsigned long *stack_top = mem + 4096; 2327d36db35SAvi Kivity unsigned long memw = 0x123456789abcdeful; 2337d36db35SAvi Kivity static unsigned long tmp2; 2347d36db35SAvi Kivity 2357d36db35SAvi Kivity memset(mem, 0x55, (void *)stack_top - mem); 2367d36db35SAvi Kivity 2377d36db35SAvi Kivity asm volatile("pushq %[val] \n\t" 2387d36db35SAvi Kivity "popq (%[mem])" 2397d36db35SAvi Kivity : : [val]"m"(memw), [mem]"r"(mem) : "memory"); 240a299895bSThomas Huth report(*(unsigned long *)mem == memw, "pop mem"); 2417d36db35SAvi Kivity 2427d36db35SAvi Kivity memw = 7 - memw; 2437d36db35SAvi Kivity asm volatile("mov %%rsp, %[tmp] \n\t" 2447d36db35SAvi Kivity "mov %[stack_top], %%rsp \n\t" 2457d36db35SAvi Kivity "pushq %[val] \n\t" 2467d36db35SAvi Kivity "popq %[tmp2] \n\t" 2477d36db35SAvi Kivity "mov %[tmp], %%rsp" 2487d36db35SAvi Kivity : [tmp]"=&r"(tmp), [tmp2]"=m"(tmp2) 2497d36db35SAvi Kivity : [val]"r"(memw), [stack_top]"r"(stack_top) 2507d36db35SAvi Kivity : "memory"); 251a299895bSThomas Huth report(tmp2 == memw, "pop mem (2)"); 2527d36db35SAvi Kivity 2537d36db35SAvi Kivity memw = 129443 - memw; 2547d36db35SAvi Kivity asm volatile("mov %%rsp, %[tmp] \n\t" 2557d36db35SAvi Kivity "mov %[stack_top], %%rsp \n\t" 2567d36db35SAvi Kivity "pushq %[val] \n\t" 2577d36db35SAvi Kivity "popq %[tmp2] \n\t" 2587d36db35SAvi Kivity "mov %[tmp], %%rsp" 2597d36db35SAvi Kivity : [tmp]"=&r"(tmp), [tmp2]"=r"(tmp2) 2607d36db35SAvi Kivity : [val]"r"(memw), [stack_top]"r"(stack_top) 2617d36db35SAvi Kivity : "memory"); 262a299895bSThomas Huth report(tmp2 == memw, "pop reg"); 2637d36db35SAvi Kivity 2647d36db35SAvi Kivity asm volatile("mov %%rsp, %[tmp] \n\t" 2657d36db35SAvi Kivity "mov %[stack_top], %%rsp \n\t" 2667d36db35SAvi Kivity "push $1f \n\t" 2677d36db35SAvi Kivity "ret \n\t" 2687d36db35SAvi Kivity "2: jmp 2b \n\t" 2697d36db35SAvi Kivity "1: mov %[tmp], %%rsp" 2707d36db35SAvi Kivity : [tmp]"=&r"(tmp) : [stack_top]"r"(stack_top) 2717d36db35SAvi Kivity : "memory"); 272a299895bSThomas Huth report(1, "ret"); 2735269d6e7SAvi Kivity 2745269d6e7SAvi Kivity stack_top[-1] = 0x778899; 275c2aa6128SPeter Feiner asm volatile("mov %[stack_top], %%r8 \n\t" 276c2aa6128SPeter Feiner "mov %%rsp, %%r9 \n\t" 277c2aa6128SPeter Feiner "xchg %%rbp, %%r8 \n\t" 2785269d6e7SAvi Kivity "leave \n\t" 279c2aa6128SPeter Feiner "xchg %%rsp, %%r9 \n\t" 280c2aa6128SPeter Feiner "xchg %%rbp, %%r8 \n\t" 281c2aa6128SPeter Feiner "mov %%r9, %[tmp] \n\t" 282c2aa6128SPeter Feiner "mov %%r8, %[tmp3]" 2835269d6e7SAvi Kivity : [tmp]"=&r"(tmp), [tmp3]"=&r"(tmp3) : [stack_top]"r"(stack_top-1) 284c2aa6128SPeter Feiner : "memory", "r8", "r9"); 285a299895bSThomas Huth report(tmp == (ulong)stack_top && tmp3 == 0x778899, "leave"); 28628f04f22SAvi Kivity 28728f04f22SAvi Kivity rbp = 0xaa55aa55bb66bb66ULL; 28828f04f22SAvi Kivity rsp = (unsigned long)stack_top; 289c2aa6128SPeter Feiner asm volatile("mov %[rsp], %%r8 \n\t" 290c2aa6128SPeter Feiner "mov %[rbp], %%r9 \n\t" 291c2aa6128SPeter Feiner "xchg %%rsp, %%r8 \n\t" 292c2aa6128SPeter Feiner "xchg %%rbp, %%r9 \n\t" 29328f04f22SAvi Kivity "enter $0x1238, $0 \n\t" 294c2aa6128SPeter Feiner "xchg %%rsp, %%r8 \n\t" 295c2aa6128SPeter Feiner "xchg %%rbp, %%r9 \n\t" 296c2aa6128SPeter Feiner "xchg %%r8, %[rsp] \n\t" 297c2aa6128SPeter Feiner "xchg %%r9, %[rbp]" 298c2aa6128SPeter Feiner : [rsp]"+a"(rsp), [rbp]"+b"(rbp) : : "memory", "r8", "r9"); 299a299895bSThomas Huth report(rsp == (unsigned long)stack_top - 8 - 0x1238 30028f04f22SAvi Kivity && rbp == (unsigned long)stack_top - 8 301a299895bSThomas Huth && stack_top[-1] == 0xaa55aa55bb66bb66ULL, 302a299895bSThomas Huth "enter"); 3037d36db35SAvi Kivity } 3047d36db35SAvi Kivity 305db4898e8SThomas Huth static void test_ljmp(void *mem) 3067d36db35SAvi Kivity { 3077d36db35SAvi Kivity unsigned char *m = mem; 3087d36db35SAvi Kivity volatile int res = 1; 3097d36db35SAvi Kivity 3107d36db35SAvi Kivity *(unsigned long**)m = &&jmpf; 3112d331a4dSRoman Bolshakov asm volatile ("data16 mov %%cs, %0":"=m"(*(m + sizeof(unsigned long)))); 3122d331a4dSRoman Bolshakov asm volatile ("rex64 ljmp *%0"::"m"(*m)); 3137d36db35SAvi Kivity res = 0; 3147d36db35SAvi Kivity jmpf: 315a299895bSThomas Huth report(res, "ljmp"); 3167d36db35SAvi Kivity } 3177d36db35SAvi Kivity 318db4898e8SThomas Huth static void test_incdecnotneg(void *mem) 3197d36db35SAvi Kivity { 3207d36db35SAvi Kivity unsigned long *m = mem, v = 1234; 3217d36db35SAvi Kivity unsigned char *mb = mem, vb = 66; 3227d36db35SAvi Kivity 3237d36db35SAvi Kivity *m = 0; 3247d36db35SAvi Kivity 3257d36db35SAvi Kivity asm volatile ("incl %0":"+m"(*m)); 326a299895bSThomas Huth report(*m == 1, "incl"); 3277d36db35SAvi Kivity asm volatile ("decl %0":"+m"(*m)); 328a299895bSThomas Huth report(*m == 0, "decl"); 3297d36db35SAvi Kivity asm volatile ("incb %0":"+m"(*m)); 330a299895bSThomas Huth report(*m == 1, "incb"); 3317d36db35SAvi Kivity asm volatile ("decb %0":"+m"(*m)); 332a299895bSThomas Huth report(*m == 0, "decb"); 3337d36db35SAvi Kivity 3347d36db35SAvi Kivity asm volatile ("lock incl %0":"+m"(*m)); 335a299895bSThomas Huth report(*m == 1, "lock incl"); 3367d36db35SAvi Kivity asm volatile ("lock decl %0":"+m"(*m)); 337a299895bSThomas Huth report(*m == 0, "lock decl"); 3387d36db35SAvi Kivity asm volatile ("lock incb %0":"+m"(*m)); 339a299895bSThomas Huth report(*m == 1, "lock incb"); 3407d36db35SAvi Kivity asm volatile ("lock decb %0":"+m"(*m)); 341a299895bSThomas Huth report(*m == 0, "lock decb"); 3427d36db35SAvi Kivity 3437d36db35SAvi Kivity *m = v; 3447d36db35SAvi Kivity 3457d36db35SAvi Kivity asm ("lock negq %0" : "+m"(*m)); v = -v; 346a299895bSThomas Huth report(*m == v, "lock negl"); 3477d36db35SAvi Kivity asm ("lock notq %0" : "+m"(*m)); v = ~v; 348a299895bSThomas Huth report(*m == v, "lock notl"); 3497d36db35SAvi Kivity 3507d36db35SAvi Kivity *mb = vb; 3517d36db35SAvi Kivity 3527d36db35SAvi Kivity asm ("lock negb %0" : "+m"(*mb)); vb = -vb; 353a299895bSThomas Huth report(*mb == vb, "lock negb"); 3547d36db35SAvi Kivity asm ("lock notb %0" : "+m"(*mb)); vb = ~vb; 355a299895bSThomas Huth report(*mb == vb, "lock notb"); 3567d36db35SAvi Kivity } 3577d36db35SAvi Kivity 358db4898e8SThomas Huth static void test_smsw(uint64_t *h_mem) 3597d36db35SAvi Kivity { 3607d36db35SAvi Kivity char mem[16]; 3617d36db35SAvi Kivity unsigned short msw, msw_orig, *pmsw; 3627d36db35SAvi Kivity int i, zero; 3637d36db35SAvi Kivity 3647d36db35SAvi Kivity msw_orig = read_cr0(); 3657d36db35SAvi Kivity 3667d36db35SAvi Kivity asm("smsw %0" : "=r"(msw)); 367a299895bSThomas Huth report(msw == msw_orig, "smsw (1)"); 3687d36db35SAvi Kivity 3697d36db35SAvi Kivity memset(mem, 0, 16); 3707d36db35SAvi Kivity pmsw = (void *)mem; 3717d36db35SAvi Kivity asm("smsw %0" : "=m"(pmsw[4])); 3727d36db35SAvi Kivity zero = 1; 3737d36db35SAvi Kivity for (i = 0; i < 8; ++i) 3747d36db35SAvi Kivity if (i != 4 && pmsw[i]) 3757d36db35SAvi Kivity zero = 0; 376a299895bSThomas Huth report(msw == pmsw[4] && zero, "smsw (2)"); 3774003963dSNadav Amit 3784003963dSNadav Amit /* Trigger exit on smsw */ 3794003963dSNadav Amit *h_mem = 0x12345678abcdeful; 38011147080SChris J Arges asm volatile("smsw %0" : "+m"(*h_mem)); 381a299895bSThomas Huth report(msw == (unsigned short)*h_mem && 382a299895bSThomas Huth (*h_mem & ~0xfffful) == 0x12345678ab0000ul, "smsw (3)"); 3837d36db35SAvi Kivity } 3847d36db35SAvi Kivity 385db4898e8SThomas Huth static void test_lmsw(void) 3867d36db35SAvi Kivity { 3877d36db35SAvi Kivity char mem[16]; 3887d36db35SAvi Kivity unsigned short msw, *pmsw; 3897d36db35SAvi Kivity unsigned long cr0; 3907d36db35SAvi Kivity 3917d36db35SAvi Kivity cr0 = read_cr0(); 3927d36db35SAvi Kivity 3937d36db35SAvi Kivity msw = cr0 ^ 8; 3947d36db35SAvi Kivity asm("lmsw %0" : : "r"(msw)); 3957d36db35SAvi Kivity printf("before %lx after %lx\n", cr0, read_cr0()); 396a299895bSThomas Huth report((cr0 ^ read_cr0()) == 8, "lmsw (1)"); 3977d36db35SAvi Kivity 3987d36db35SAvi Kivity pmsw = (void *)mem; 3997d36db35SAvi Kivity *pmsw = cr0; 4007d36db35SAvi Kivity asm("lmsw %0" : : "m"(*pmsw)); 4017d36db35SAvi Kivity printf("before %lx after %lx\n", cr0, read_cr0()); 402a299895bSThomas Huth report(cr0 == read_cr0(), "lmsw (2)"); 4037d36db35SAvi Kivity 4047d36db35SAvi Kivity /* lmsw can't clear cr0.pe */ 4057d36db35SAvi Kivity msw = (cr0 & ~1ul) ^ 4; /* change EM to force trap */ 4067d36db35SAvi Kivity asm("lmsw %0" : : "r"(msw)); 407a299895bSThomas Huth report((cr0 ^ read_cr0()) == 4 && (cr0 & 1), "lmsw (3)"); 4087d36db35SAvi Kivity 4097d36db35SAvi Kivity /* back to normal */ 4107d36db35SAvi Kivity msw = cr0; 4117d36db35SAvi Kivity asm("lmsw %0" : : "r"(msw)); 4127d36db35SAvi Kivity } 4137d36db35SAvi Kivity 414db4898e8SThomas Huth static void test_xchg(void *mem) 4157d36db35SAvi Kivity { 4167d36db35SAvi Kivity unsigned long *memq = mem; 4177d36db35SAvi Kivity unsigned long rax; 4187d36db35SAvi Kivity 4197d36db35SAvi Kivity asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4207d36db35SAvi Kivity "mov %%rax, (%[memq])\n\t" 4217d36db35SAvi Kivity "mov $0xfedcba9876543210, %%rax\n\t" 4227d36db35SAvi Kivity "xchg %%al, (%[memq])\n\t" 4237d36db35SAvi Kivity "mov %%rax, %[rax]\n\t" 4247d36db35SAvi Kivity : [rax]"=r"(rax) 4257d36db35SAvi Kivity : [memq]"r"(memq) 426c2aa6128SPeter Feiner : "memory", "rax"); 427a299895bSThomas Huth report(rax == 0xfedcba98765432ef && *memq == 0x123456789abcd10, 428a299895bSThomas Huth "xchg reg, r/m (1)"); 4297d36db35SAvi Kivity 4307d36db35SAvi Kivity asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4317d36db35SAvi Kivity "mov %%rax, (%[memq])\n\t" 4327d36db35SAvi Kivity "mov $0xfedcba9876543210, %%rax\n\t" 4337d36db35SAvi Kivity "xchg %%ax, (%[memq])\n\t" 4347d36db35SAvi Kivity "mov %%rax, %[rax]\n\t" 4357d36db35SAvi Kivity : [rax]"=r"(rax) 4367d36db35SAvi Kivity : [memq]"r"(memq) 437c2aa6128SPeter Feiner : "memory", "rax"); 438a299895bSThomas Huth report(rax == 0xfedcba987654cdef && *memq == 0x123456789ab3210, 439a299895bSThomas Huth "xchg reg, r/m (2)"); 4407d36db35SAvi Kivity 4417d36db35SAvi Kivity asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4427d36db35SAvi Kivity "mov %%rax, (%[memq])\n\t" 4437d36db35SAvi Kivity "mov $0xfedcba9876543210, %%rax\n\t" 4447d36db35SAvi Kivity "xchg %%eax, (%[memq])\n\t" 4457d36db35SAvi Kivity "mov %%rax, %[rax]\n\t" 4467d36db35SAvi Kivity : [rax]"=r"(rax) 4477d36db35SAvi Kivity : [memq]"r"(memq) 448c2aa6128SPeter Feiner : "memory", "rax"); 449a299895bSThomas Huth report(rax == 0x89abcdef && *memq == 0x123456776543210, 450a299895bSThomas Huth "xchg reg, r/m (3)"); 4517d36db35SAvi Kivity 4527d36db35SAvi Kivity asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4537d36db35SAvi Kivity "mov %%rax, (%[memq])\n\t" 4547d36db35SAvi Kivity "mov $0xfedcba9876543210, %%rax\n\t" 4557d36db35SAvi Kivity "xchg %%rax, (%[memq])\n\t" 4567d36db35SAvi Kivity "mov %%rax, %[rax]\n\t" 4577d36db35SAvi Kivity : [rax]"=r"(rax) 4587d36db35SAvi Kivity : [memq]"r"(memq) 459c2aa6128SPeter Feiner : "memory", "rax"); 460a299895bSThomas Huth report(rax == 0x123456789abcdef && *memq == 0xfedcba9876543210, 461a299895bSThomas Huth "xchg reg, r/m (4)"); 4627d36db35SAvi Kivity } 4637d36db35SAvi Kivity 464db4898e8SThomas Huth static void test_xadd(void *mem) 4655647d55cSWei Yongjun { 4665647d55cSWei Yongjun unsigned long *memq = mem; 4675647d55cSWei Yongjun unsigned long rax; 4685647d55cSWei Yongjun 4695647d55cSWei Yongjun asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4705647d55cSWei Yongjun "mov %%rax, (%[memq])\n\t" 4715647d55cSWei Yongjun "mov $0xfedcba9876543210, %%rax\n\t" 4725647d55cSWei Yongjun "xadd %%al, (%[memq])\n\t" 4735647d55cSWei Yongjun "mov %%rax, %[rax]\n\t" 4745647d55cSWei Yongjun : [rax]"=r"(rax) 4755647d55cSWei Yongjun : [memq]"r"(memq) 476c2aa6128SPeter Feiner : "memory", "rax"); 477a299895bSThomas Huth report(rax == 0xfedcba98765432ef && *memq == 0x123456789abcdff, 478a299895bSThomas Huth "xadd reg, r/m (1)"); 4795647d55cSWei Yongjun 4805647d55cSWei Yongjun asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4815647d55cSWei Yongjun "mov %%rax, (%[memq])\n\t" 4825647d55cSWei Yongjun "mov $0xfedcba9876543210, %%rax\n\t" 4835647d55cSWei Yongjun "xadd %%ax, (%[memq])\n\t" 4845647d55cSWei Yongjun "mov %%rax, %[rax]\n\t" 4855647d55cSWei Yongjun : [rax]"=r"(rax) 4865647d55cSWei Yongjun : [memq]"r"(memq) 487c2aa6128SPeter Feiner : "memory", "rax"); 488a299895bSThomas Huth report(rax == 0xfedcba987654cdef && *memq == 0x123456789abffff, 489a299895bSThomas Huth "xadd reg, r/m (2)"); 4905647d55cSWei Yongjun 4915647d55cSWei Yongjun asm volatile("mov $0x123456789abcdef, %%rax\n\t" 4925647d55cSWei Yongjun "mov %%rax, (%[memq])\n\t" 4935647d55cSWei Yongjun "mov $0xfedcba9876543210, %%rax\n\t" 4945647d55cSWei Yongjun "xadd %%eax, (%[memq])\n\t" 4955647d55cSWei Yongjun "mov %%rax, %[rax]\n\t" 4965647d55cSWei Yongjun : [rax]"=r"(rax) 4975647d55cSWei Yongjun : [memq]"r"(memq) 498c2aa6128SPeter Feiner : "memory", "rax"); 499a299895bSThomas Huth report(rax == 0x89abcdef && *memq == 0x1234567ffffffff, 500a299895bSThomas Huth "xadd reg, r/m (3)"); 5015647d55cSWei Yongjun 5025647d55cSWei Yongjun asm volatile("mov $0x123456789abcdef, %%rax\n\t" 5035647d55cSWei Yongjun "mov %%rax, (%[memq])\n\t" 5045647d55cSWei Yongjun "mov $0xfedcba9876543210, %%rax\n\t" 5055647d55cSWei Yongjun "xadd %%rax, (%[memq])\n\t" 5065647d55cSWei Yongjun "mov %%rax, %[rax]\n\t" 5075647d55cSWei Yongjun : [rax]"=r"(rax) 5085647d55cSWei Yongjun : [memq]"r"(memq) 509c2aa6128SPeter Feiner : "memory", "rax"); 510a299895bSThomas Huth report(rax == 0x123456789abcdef && *memq == 0xffffffffffffffff, 511a299895bSThomas Huth "xadd reg, r/m (4)"); 5125647d55cSWei Yongjun } 5135647d55cSWei Yongjun 514db4898e8SThomas Huth static void test_btc(void *mem) 515d4655eafSWei Yongjun { 516d4655eafSWei Yongjun unsigned int *a = mem; 517d4655eafSWei Yongjun 5187e083f20SNadav Amit memset(mem, 0, 4 * sizeof(unsigned int)); 519d4655eafSWei Yongjun 520d4655eafSWei Yongjun asm ("btcl $32, %0" :: "m"(a[0]) : "memory"); 521d4655eafSWei Yongjun asm ("btcl $1, %0" :: "m"(a[1]) : "memory"); 522d4655eafSWei Yongjun asm ("btcl %1, %0" :: "m"(a[0]), "r"(66) : "memory"); 523a299895bSThomas Huth report(a[0] == 1 && a[1] == 2 && a[2] == 4, "btcl imm8, r/m"); 524d4655eafSWei Yongjun 525d4655eafSWei Yongjun asm ("btcl %1, %0" :: "m"(a[3]), "r"(-1) : "memory"); 526a299895bSThomas Huth report(a[0] == 1 && a[1] == 2 && a[2] == 0x80000004, "btcl reg, r/m"); 5277e083f20SNadav Amit 5287e083f20SNadav Amit asm ("btcq %1, %0" : : "m"(a[2]), "r"(-1l) : "memory"); 529a299895bSThomas Huth report(a[0] == 1 && a[1] == 0x80000002 && a[2] == 0x80000004 && a[3] == 0, 530a299895bSThomas Huth "btcq reg, r/m"); 531d4655eafSWei Yongjun } 532d4655eafSWei Yongjun 533db4898e8SThomas Huth static void test_bsfbsr(void *mem) 5342e16c7f6SWei Yongjun { 535554de466SAvi Kivity unsigned long rax, *memq = mem; 536554de466SAvi Kivity unsigned eax, *meml = mem; 537554de466SAvi Kivity unsigned short ax, *memw = mem; 538554de466SAvi Kivity unsigned char z; 5392e16c7f6SWei Yongjun 540554de466SAvi Kivity *memw = 0xc000; 541554de466SAvi Kivity asm("bsfw %[mem], %[a]" : [a]"=a"(ax) : [mem]"m"(*memw)); 542a299895bSThomas Huth report(ax == 14, "bsfw r/m, reg"); 5432e16c7f6SWei Yongjun 544554de466SAvi Kivity *meml = 0xc0000000; 545554de466SAvi Kivity asm("bsfl %[mem], %[a]" : [a]"=a"(eax) : [mem]"m"(*meml)); 546a299895bSThomas Huth report(eax == 30, "bsfl r/m, reg"); 5472e16c7f6SWei Yongjun 548554de466SAvi Kivity *memq = 0xc00000000000; 549554de466SAvi Kivity asm("bsfq %[mem], %[a]" : [a]"=a"(rax) : [mem]"m"(*memq)); 550a299895bSThomas Huth report(rax == 46, "bsfq r/m, reg"); 5512e16c7f6SWei Yongjun 552554de466SAvi Kivity *memq = 0; 553554de466SAvi Kivity asm("bsfq %[mem], %[a]; setz %[z]" 554554de466SAvi Kivity : [a]"=a"(rax), [z]"=rm"(z) : [mem]"m"(*memq)); 555a299895bSThomas Huth report(z == 1, "bsfq r/m, reg"); 5562e16c7f6SWei Yongjun 557554de466SAvi Kivity *memw = 0xc000; 558554de466SAvi Kivity asm("bsrw %[mem], %[a]" : [a]"=a"(ax) : [mem]"m"(*memw)); 559a299895bSThomas Huth report(ax == 15, "bsrw r/m, reg"); 5602e16c7f6SWei Yongjun 561554de466SAvi Kivity *meml = 0xc0000000; 562554de466SAvi Kivity asm("bsrl %[mem], %[a]" : [a]"=a"(eax) : [mem]"m"(*meml)); 563a299895bSThomas Huth report(eax == 31, "bsrl r/m, reg"); 5642e16c7f6SWei Yongjun 565554de466SAvi Kivity *memq = 0xc00000000000; 566554de466SAvi Kivity asm("bsrq %[mem], %[a]" : [a]"=a"(rax) : [mem]"m"(*memq)); 567a299895bSThomas Huth report(rax == 47, "bsrq r/m, reg"); 5682e16c7f6SWei Yongjun 569554de466SAvi Kivity *memq = 0; 570554de466SAvi Kivity asm("bsrq %[mem], %[a]; setz %[z]" 571554de466SAvi Kivity : [a]"=a"(rax), [z]"=rm"(z) : [mem]"m"(*memq)); 572a299895bSThomas Huth report(z == 1, "bsrq r/m, reg"); 5732e16c7f6SWei Yongjun } 5742e16c7f6SWei Yongjun 57551d65a3cSAvi Kivity static void test_imul(ulong *mem) 57651d65a3cSAvi Kivity { 57751d65a3cSAvi Kivity ulong a; 57851d65a3cSAvi Kivity 57951d65a3cSAvi Kivity *mem = 51; a = 0x1234567812345678UL; 58051d65a3cSAvi Kivity asm ("imulw %1, %%ax" : "+a"(a) : "m"(*mem)); 581a299895bSThomas Huth report(a == 0x12345678123439e8, "imul ax, mem"); 58251d65a3cSAvi Kivity 58351d65a3cSAvi Kivity *mem = 51; a = 0x1234567812345678UL; 58451d65a3cSAvi Kivity asm ("imull %1, %%eax" : "+a"(a) : "m"(*mem)); 585a299895bSThomas Huth report(a == 0xa06d39e8, "imul eax, mem"); 58651d65a3cSAvi Kivity 58751d65a3cSAvi Kivity *mem = 51; a = 0x1234567812345678UL; 58851d65a3cSAvi Kivity asm ("imulq %1, %%rax" : "+a"(a) : "m"(*mem)); 589a299895bSThomas Huth report(a == 0xA06D39EBA06D39E8UL, "imul rax, mem"); 59051d65a3cSAvi Kivity 59151d65a3cSAvi Kivity *mem = 0x1234567812345678UL; a = 0x8765432187654321L; 59251d65a3cSAvi Kivity asm ("imulw $51, %1, %%ax" : "+a"(a) : "m"(*mem)); 593a299895bSThomas Huth report(a == 0x87654321876539e8, "imul ax, mem, imm8"); 59451d65a3cSAvi Kivity 59551d65a3cSAvi Kivity *mem = 0x1234567812345678UL; 59651d65a3cSAvi Kivity asm ("imull $51, %1, %%eax" : "+a"(a) : "m"(*mem)); 597a299895bSThomas Huth report(a == 0xa06d39e8, "imul eax, mem, imm8"); 59851d65a3cSAvi Kivity 59951d65a3cSAvi Kivity *mem = 0x1234567812345678UL; 60051d65a3cSAvi Kivity asm ("imulq $51, %1, %%rax" : "+a"(a) : "m"(*mem)); 601a299895bSThomas Huth report(a == 0xA06D39EBA06D39E8UL, "imul rax, mem, imm8"); 60251d65a3cSAvi Kivity 60351d65a3cSAvi Kivity *mem = 0x1234567812345678UL; a = 0x8765432187654321L; 60451d65a3cSAvi Kivity asm ("imulw $311, %1, %%ax" : "+a"(a) : "m"(*mem)); 605a299895bSThomas Huth report(a == 0x8765432187650bc8, "imul ax, mem, imm"); 60651d65a3cSAvi Kivity 60751d65a3cSAvi Kivity *mem = 0x1234567812345678UL; 60851d65a3cSAvi Kivity asm ("imull $311, %1, %%eax" : "+a"(a) : "m"(*mem)); 609a299895bSThomas Huth report(a == 0x1d950bc8, "imul eax, mem, imm"); 61051d65a3cSAvi Kivity 61151d65a3cSAvi Kivity *mem = 0x1234567812345678UL; 61251d65a3cSAvi Kivity asm ("imulq $311, %1, %%rax" : "+a"(a) : "m"(*mem)); 613a299895bSThomas Huth report(a == 0x1D950BDE1D950BC8L, "imul rax, mem, imm"); 61451d65a3cSAvi Kivity } 61551d65a3cSAvi Kivity 616c2c43fcfSAvi Kivity static void test_muldiv(long *mem) 617f12d86b0SAvi Kivity { 618c2c43fcfSAvi Kivity long a, d, aa, dd; 619f12d86b0SAvi Kivity u8 ex = 1; 620f12d86b0SAvi Kivity 621f12d86b0SAvi Kivity *mem = 0; a = 1; d = 2; 622f12d86b0SAvi Kivity asm (ASM_TRY("1f") "divq %3; movb $0, %2; 1:" 623f12d86b0SAvi Kivity : "+a"(a), "+d"(d), "+q"(ex) : "m"(*mem)); 624a299895bSThomas Huth report(a == 1 && d == 2 && ex, "divq (fault)"); 625f12d86b0SAvi Kivity 626f12d86b0SAvi Kivity *mem = 987654321098765UL; a = 123456789012345UL; d = 123456789012345UL; 627f12d86b0SAvi Kivity asm (ASM_TRY("1f") "divq %3; movb $0, %2; 1:" 628f12d86b0SAvi Kivity : "+a"(a), "+d"(d), "+q"(ex) : "m"(*mem)); 629a299895bSThomas Huth report(a == 0x1ffffffb1b963b33ul && d == 0x273ba4384ede2ul && !ex, 630a299895bSThomas Huth "divq (1)"); 631c2c43fcfSAvi Kivity aa = 0x1111111111111111; dd = 0x2222222222222222; 632c2c43fcfSAvi Kivity *mem = 0x3333333333333333; a = aa; d = dd; 633c2c43fcfSAvi Kivity asm("mulb %2" : "+a"(a), "+d"(d) : "m"(*mem)); 634a299895bSThomas Huth report(a == 0x1111111111110363 && d == dd, "mulb mem"); 635c2c43fcfSAvi Kivity *mem = 0x3333333333333333; a = aa; d = dd; 636c2c43fcfSAvi Kivity asm("mulw %2" : "+a"(a), "+d"(d) : "m"(*mem)); 637a299895bSThomas Huth report(a == 0x111111111111c963 && d == 0x2222222222220369, "mulw mem"); 638c2c43fcfSAvi Kivity *mem = 0x3333333333333333; a = aa; d = dd; 639c2c43fcfSAvi Kivity asm("mull %2" : "+a"(a), "+d"(d) : "m"(*mem)); 640a299895bSThomas Huth report(a == 0x962fc963 && d == 0x369d036, "mull mem"); 641c2c43fcfSAvi Kivity *mem = 0x3333333333333333; a = aa; d = dd; 642c2c43fcfSAvi Kivity asm("mulq %2" : "+a"(a), "+d"(d) : "m"(*mem)); 643a299895bSThomas Huth report(a == 0x2fc962fc962fc963 && d == 0x369d0369d0369d0, "mulq mem"); 644f12d86b0SAvi Kivity } 645f12d86b0SAvi Kivity 646d7f3ee3cSAvi Kivity typedef unsigned __attribute__((vector_size(16))) sse128; 647d7f3ee3cSAvi Kivity 648d7f3ee3cSAvi Kivity typedef union { 649d7f3ee3cSAvi Kivity sse128 sse; 650d7f3ee3cSAvi Kivity unsigned u[4]; 651d7f3ee3cSAvi Kivity } sse_union; 652d7f3ee3cSAvi Kivity 653d7f3ee3cSAvi Kivity static bool sseeq(sse_union *v1, sse_union *v2) 654d7f3ee3cSAvi Kivity { 655d7f3ee3cSAvi Kivity bool ok = true; 656d7f3ee3cSAvi Kivity int i; 657d7f3ee3cSAvi Kivity 658d7f3ee3cSAvi Kivity for (i = 0; i < 4; ++i) { 659d7f3ee3cSAvi Kivity ok &= v1->u[i] == v2->u[i]; 660d7f3ee3cSAvi Kivity } 661d7f3ee3cSAvi Kivity 662d7f3ee3cSAvi Kivity return ok; 663d7f3ee3cSAvi Kivity } 664d7f3ee3cSAvi Kivity 66531eaca95SBill Wendling static __attribute__((target("sse2"))) void test_sse(sse_union *mem) 666d7f3ee3cSAvi Kivity { 667d7f3ee3cSAvi Kivity sse_union v; 668d7f3ee3cSAvi Kivity 669d7f3ee3cSAvi Kivity write_cr0(read_cr0() & ~6); /* EM, TS */ 670d7f3ee3cSAvi Kivity write_cr4(read_cr4() | 0x200); /* OSFXSR */ 671290ed5d5SIgor Mammedov 6728726f977SJacob Xu #define TEST_RW_SSE(insn) do { \ 6738726f977SJacob Xu v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4; \ 6748726f977SJacob Xu asm(insn " %1, %0" : "=m"(*mem) : "x"(v.sse)); \ 6758726f977SJacob Xu report(sseeq(&v, mem), insn " (read)"); \ 6768726f977SJacob Xu mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8; \ 6778726f977SJacob Xu asm(insn " %1, %0" : "=x"(v.sse) : "m"(*mem)); \ 6788726f977SJacob Xu report(sseeq(&v, mem), insn " (write)"); \ 6798726f977SJacob Xu } while (0) 680f068a46aSIgor Mammedov 6818726f977SJacob Xu TEST_RW_SSE("movdqu"); 6828726f977SJacob Xu TEST_RW_SSE("movaps"); 6838726f977SJacob Xu TEST_RW_SSE("movapd"); 6848726f977SJacob Xu TEST_RW_SSE("movups"); 6858726f977SJacob Xu TEST_RW_SSE("movupd"); 6868726f977SJacob Xu #undef TEST_RW_SSE 687d7f3ee3cSAvi Kivity } 688d7f3ee3cSAvi Kivity 689*e5e76263SJacob Xu static void unaligned_movaps_handler(struct ex_regs *regs) 690*e5e76263SJacob Xu { 691*e5e76263SJacob Xu extern char unaligned_movaps_cont; 692*e5e76263SJacob Xu 693*e5e76263SJacob Xu ++exceptions; 694*e5e76263SJacob Xu regs->rip = (ulong)&unaligned_movaps_cont; 695*e5e76263SJacob Xu } 696*e5e76263SJacob Xu 697*e5e76263SJacob Xu static void cross_movups_handler(struct ex_regs *regs) 698*e5e76263SJacob Xu { 699*e5e76263SJacob Xu extern char cross_movups_cont; 700*e5e76263SJacob Xu 701*e5e76263SJacob Xu ++exceptions; 702*e5e76263SJacob Xu regs->rip = (ulong)&cross_movups_cont; 703*e5e76263SJacob Xu } 704*e5e76263SJacob Xu 705*e5e76263SJacob Xu static __attribute__((target("sse2"))) void test_sse_exceptions(void *cross_mem) 706*e5e76263SJacob Xu { 707*e5e76263SJacob Xu sse_union v; 708*e5e76263SJacob Xu sse_union *mem; 709*e5e76263SJacob Xu uint8_t *bytes = cross_mem; // aligned on PAGE_SIZE*2 710*e5e76263SJacob Xu void *page2 = (void *)(&bytes[4096]); 711*e5e76263SJacob Xu struct pte_search search; 712*e5e76263SJacob Xu pteval_t orig_pte; 713*e5e76263SJacob Xu 714*e5e76263SJacob Xu // setup memory for unaligned access 715*e5e76263SJacob Xu mem = (sse_union *)(&bytes[8]); 716*e5e76263SJacob Xu 717*e5e76263SJacob Xu // test unaligned access for movups, movupd and movaps 718*e5e76263SJacob Xu v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4; 719*e5e76263SJacob Xu mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8; 720*e5e76263SJacob Xu asm("movups %1, %0" : "=m"(*mem) : "x"(v.sse)); 721*e5e76263SJacob Xu report(sseeq(&v, mem), "movups unaligned"); 722*e5e76263SJacob Xu 723*e5e76263SJacob Xu v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4; 724*e5e76263SJacob Xu mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8; 725*e5e76263SJacob Xu asm("movupd %1, %0" : "=m"(*mem) : "x"(v.sse)); 726*e5e76263SJacob Xu report(sseeq(&v, mem), "movupd unaligned"); 727*e5e76263SJacob Xu exceptions = 0; 728*e5e76263SJacob Xu handle_exception(GP_VECTOR, unaligned_movaps_handler); 729*e5e76263SJacob Xu asm("movaps %1, %0\n\t unaligned_movaps_cont:" 730*e5e76263SJacob Xu : "=m"(*mem) : "x"(v.sse)); 731*e5e76263SJacob Xu handle_exception(GP_VECTOR, 0); 732*e5e76263SJacob Xu report(exceptions == 1, "unaligned movaps exception"); 733*e5e76263SJacob Xu 734*e5e76263SJacob Xu // setup memory for cross page access 735*e5e76263SJacob Xu mem = (sse_union *)(&bytes[4096-8]); 736*e5e76263SJacob Xu v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4; 737*e5e76263SJacob Xu mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8; 738*e5e76263SJacob Xu 739*e5e76263SJacob Xu asm("movups %1, %0" : "=m"(*mem) : "x"(v.sse)); 740*e5e76263SJacob Xu report(sseeq(&v, mem), "movups unaligned crosspage"); 741*e5e76263SJacob Xu 742*e5e76263SJacob Xu // invalidate second page 743*e5e76263SJacob Xu search = find_pte_level(current_page_table(), page2, 1); 744*e5e76263SJacob Xu orig_pte = *search.pte; 745*e5e76263SJacob Xu install_pte(current_page_table(), 1, page2, 0, NULL); 746*e5e76263SJacob Xu invlpg(page2); 747*e5e76263SJacob Xu 748*e5e76263SJacob Xu exceptions = 0; 749*e5e76263SJacob Xu handle_exception(PF_VECTOR, cross_movups_handler); 750*e5e76263SJacob Xu asm("movups %1, %0\n\t cross_movups_cont:" : "=m"(*mem) : "x"(v.sse)); 751*e5e76263SJacob Xu handle_exception(PF_VECTOR, 0); 752*e5e76263SJacob Xu report(exceptions == 1, "movups crosspage exception"); 753*e5e76263SJacob Xu 754*e5e76263SJacob Xu // restore invalidated page 755*e5e76263SJacob Xu install_pte(current_page_table(), 1, page2, orig_pte, NULL); 756*e5e76263SJacob Xu } 757*e5e76263SJacob Xu 7583587082bSAvi Kivity static void test_mmx(uint64_t *mem) 7593587082bSAvi Kivity { 7603587082bSAvi Kivity uint64_t v; 7613587082bSAvi Kivity 7623587082bSAvi Kivity write_cr0(read_cr0() & ~6); /* EM, TS */ 7633587082bSAvi Kivity asm volatile("fninit"); 7643587082bSAvi Kivity v = 0x0102030405060708ULL; 7653587082bSAvi Kivity asm("movq %1, %0" : "=m"(*mem) : "y"(v)); 766a299895bSThomas Huth report(v == *mem, "movq (mmx, read)"); 7673587082bSAvi Kivity *mem = 0x8070605040302010ull; 7683587082bSAvi Kivity asm("movq %1, %0" : "=y"(v) : "m"(*mem)); 769a299895bSThomas Huth report(v == *mem, "movq (mmx, write)"); 7703587082bSAvi Kivity } 7713587082bSAvi Kivity 7728cfa5a06SAvi Kivity static void test_rip_relative(unsigned *mem, char *insn_ram) 7738cfa5a06SAvi Kivity { 7748cfa5a06SAvi Kivity /* movb $1, mem+2(%rip) */ 7758cfa5a06SAvi Kivity insn_ram[0] = 0xc6; 7768cfa5a06SAvi Kivity insn_ram[1] = 0x05; 7778cfa5a06SAvi Kivity *(unsigned *)&insn_ram[2] = 2 + (char *)mem - (insn_ram + 7); 7788cfa5a06SAvi Kivity insn_ram[6] = 0x01; 7798cfa5a06SAvi Kivity /* ret */ 7808cfa5a06SAvi Kivity insn_ram[7] = 0xc3; 7818cfa5a06SAvi Kivity 7828cfa5a06SAvi Kivity *mem = 0; 7838cfa5a06SAvi Kivity asm("callq *%1" : "+m"(*mem) : "r"(insn_ram)); 784a299895bSThomas Huth report(*mem == 0x10000, "movb $imm, 0(%%rip)"); 7858cfa5a06SAvi Kivity } 786d7f3ee3cSAvi Kivity 787b212fcdaSAvi Kivity static void test_shld_shrd(u32 *mem) 788b212fcdaSAvi Kivity { 789b212fcdaSAvi Kivity *mem = 0x12345678; 790b212fcdaSAvi Kivity asm("shld %2, %1, %0" : "+m"(*mem) : "r"(0xaaaaaaaaU), "c"((u8)3)); 791a299895bSThomas Huth report(*mem == ((0x12345678 << 3) | 5), "shld (cl)"); 792b212fcdaSAvi Kivity *mem = 0x12345678; 793b212fcdaSAvi Kivity asm("shrd %2, %1, %0" : "+m"(*mem) : "r"(0x55555555U), "c"((u8)3)); 794a299895bSThomas Huth report(*mem == ((0x12345678 >> 3) | (5u << 29)), "shrd (cl)"); 795b212fcdaSAvi Kivity } 796b212fcdaSAvi Kivity 79730762176SNadav Amit static void test_cmov(u32 *mem) 79830762176SNadav Amit { 79930762176SNadav Amit u64 val; 80030762176SNadav Amit *mem = 0xabcdef12u; 80130762176SNadav Amit asm ("movq $0x1234567812345678, %%rax\n\t" 80230762176SNadav Amit "cmpl %%eax, %%eax\n\t" 80330762176SNadav Amit "cmovnel (%[mem]), %%eax\n\t" 80430762176SNadav Amit "movq %%rax, %[val]\n\t" 80530762176SNadav Amit : [val]"=r"(val) : [mem]"r"(mem) : "%rax", "cc"); 806a299895bSThomas Huth report(val == 0x12345678ul, "cmovnel"); 80730762176SNadav Amit } 80830762176SNadav Amit 809c2aa6128SPeter Feiner static unsigned long rip_advance; 810c2aa6128SPeter Feiner 811c2aa6128SPeter Feiner static void advance_rip_and_note_exception(struct ex_regs *regs) 812d7143f32SAvi Kivity { 813d7143f32SAvi Kivity ++exceptions; 814c2aa6128SPeter Feiner regs->rip += rip_advance; 815d7143f32SAvi Kivity } 816d7143f32SAvi Kivity 81745fdc228SPaolo Bonzini static void test_mmx_movq_mf(uint64_t *mem) 818d7143f32SAvi Kivity { 8193af6fbbeSArthur Chunqi Li /* movq %mm0, (%rax) */ 82045fdc228SPaolo Bonzini extern char movq_start, movq_end; 821d7143f32SAvi Kivity 82245fdc228SPaolo Bonzini uint16_t fcw = 0; /* all exceptions unmasked */ 8233af6fbbeSArthur Chunqi Li write_cr0(read_cr0() & ~6); /* TS, EM */ 824d7143f32SAvi Kivity exceptions = 0; 825c2aa6128SPeter Feiner handle_exception(MF_VECTOR, advance_rip_and_note_exception); 826d7143f32SAvi Kivity asm volatile("fninit; fldcw %0" : : "m"(fcw)); 8273af6fbbeSArthur Chunqi Li asm volatile("fldz; fldz; fdivp"); /* generate exception */ 8283af6fbbeSArthur Chunqi Li 82945fdc228SPaolo Bonzini rip_advance = &movq_end - &movq_start; 83045fdc228SPaolo Bonzini asm(KVM_FEP "movq_start: movq %mm0, (%rax); movq_end:"); 8313af6fbbeSArthur Chunqi Li /* exit MMX mode */ 832d7143f32SAvi Kivity asm volatile("fnclex; emms"); 833a299895bSThomas Huth report(exceptions == 1, "movq mmx generates #MF"); 834d7143f32SAvi Kivity handle_exception(MF_VECTOR, 0); 835d7143f32SAvi Kivity } 836d7143f32SAvi Kivity 837f413c1afSNadav Amit static void test_jmp_noncanonical(uint64_t *mem) 838f413c1afSNadav Amit { 839c2aa6128SPeter Feiner extern char nc_jmp_start, nc_jmp_end; 840c2aa6128SPeter Feiner 841f413c1afSNadav Amit *mem = 0x1111111111111111ul; 842f413c1afSNadav Amit 843f413c1afSNadav Amit exceptions = 0; 844c2aa6128SPeter Feiner rip_advance = &nc_jmp_end - &nc_jmp_start; 845c2aa6128SPeter Feiner handle_exception(GP_VECTOR, advance_rip_and_note_exception); 846c2aa6128SPeter Feiner asm volatile ("nc_jmp_start: jmp *%0; nc_jmp_end:" : : "m"(*mem)); 847a299895bSThomas Huth report(exceptions == 1, "jump to non-canonical address"); 848f413c1afSNadav Amit handle_exception(GP_VECTOR, 0); 849f413c1afSNadav Amit } 850f413c1afSNadav Amit 85145fdc228SPaolo Bonzini static void test_movabs(uint64_t *mem) 85259033f47SPaolo Bonzini { 8533af6fbbeSArthur Chunqi Li /* mov $0x9090909090909090, %rcx */ 85445fdc228SPaolo Bonzini unsigned long rcx; 85545fdc228SPaolo Bonzini asm(KVM_FEP "mov $0x9090909090909090, %0" : "=c" (rcx) : "0" (0)); 856a299895bSThomas Huth report(rcx == 0x9090909090909090, "64-bit mov imm2"); 85759033f47SPaolo Bonzini } 85859033f47SPaolo Bonzini 85945fdc228SPaolo Bonzini static void test_smsw_reg(uint64_t *mem) 860313f4efeSNadav Amit { 861313f4efeSNadav Amit unsigned long cr0 = read_cr0(); 86245fdc228SPaolo Bonzini unsigned long rax; 86345fdc228SPaolo Bonzini const unsigned long in_rax = 0x1234567890abcdeful; 864313f4efeSNadav Amit 86545fdc228SPaolo Bonzini asm(KVM_FEP "smsww %w0\n\t" : "=a" (rax) : "0" (in_rax)); 866a299895bSThomas Huth report((u16)rax == (u16)cr0 && rax >> 16 == in_rax >> 16, 867a299895bSThomas Huth "16-bit smsw reg"); 868313f4efeSNadav Amit 86945fdc228SPaolo Bonzini asm(KVM_FEP "smswl %k0\n\t" : "=a" (rax) : "0" (in_rax)); 870a299895bSThomas Huth report(rax == (u32)cr0, "32-bit smsw reg"); 871313f4efeSNadav Amit 8722f394044SBill Wendling asm(KVM_FEP "smswq %q0\n\t" : "=a" (rax) : "0" (in_rax)); 873a299895bSThomas Huth report(rax == cr0, "64-bit smsw reg"); 874313f4efeSNadav Amit } 875313f4efeSNadav Amit 87645fdc228SPaolo Bonzini static void test_nop(uint64_t *mem) 877ae399010SNadav Amit { 87845fdc228SPaolo Bonzini unsigned long rax; 87945fdc228SPaolo Bonzini const unsigned long in_rax = 0x1234567890abcdeful; 88045fdc228SPaolo Bonzini asm(KVM_FEP "nop\n\t" : "=a" (rax) : "0" (in_rax)); 881a299895bSThomas Huth report(rax == in_rax, "nop"); 882ae399010SNadav Amit } 883ae399010SNadav Amit 88445fdc228SPaolo Bonzini static void test_mov_dr(uint64_t *mem) 885b39a3e14SNadav Amit { 88645fdc228SPaolo Bonzini unsigned long rax; 88745fdc228SPaolo Bonzini const unsigned long in_rax = 0; 888badc98caSKrish Sadhukhan bool rtm_support = this_cpu_has(X86_FEATURE_RTM); 889b39a3e14SNadav Amit unsigned long dr6_fixed_1 = rtm_support ? 0xfffe0ff0ul : 0xffff0ff0ul; 89045fdc228SPaolo Bonzini asm(KVM_FEP "movq %0, %%dr6\n\t" 89145fdc228SPaolo Bonzini KVM_FEP "movq %%dr6, %0\n\t" : "=a" (rax) : "a" (in_rax)); 892a299895bSThomas Huth report(rax == dr6_fixed_1, "mov_dr6"); 893b39a3e14SNadav Amit } 894b39a3e14SNadav Amit 89526311ca9SNadav Amit static void test_push16(uint64_t *mem) 89626311ca9SNadav Amit { 89726311ca9SNadav Amit uint64_t rsp1, rsp2; 89826311ca9SNadav Amit uint16_t r; 89926311ca9SNadav Amit 90026311ca9SNadav Amit asm volatile ( "movq %%rsp, %[rsp1]\n\t" 90126311ca9SNadav Amit "pushw %[v]\n\t" 90226311ca9SNadav Amit "popw %[r]\n\t" 90326311ca9SNadav Amit "movq %%rsp, %[rsp2]\n\t" 90426311ca9SNadav Amit "movq %[rsp1], %%rsp\n\t" : 90526311ca9SNadav Amit [rsp1]"=r"(rsp1), [rsp2]"=r"(rsp2), [r]"=r"(r) 90626311ca9SNadav Amit : [v]"m"(*mem) : "memory"); 907a299895bSThomas Huth report(rsp1 == rsp2, "push16"); 90826311ca9SNadav Amit } 90926311ca9SNadav Amit 910ec278ce3SAvi Kivity static void test_crosspage_mmio(volatile uint8_t *mem) 911ec278ce3SAvi Kivity { 912ec278ce3SAvi Kivity volatile uint16_t w, *pw; 913ec278ce3SAvi Kivity 914ec278ce3SAvi Kivity pw = (volatile uint16_t *)&mem[4095]; 915ec278ce3SAvi Kivity mem[4095] = 0x99; 916ec278ce3SAvi Kivity mem[4096] = 0x77; 917ec278ce3SAvi Kivity asm volatile("mov %1, %0" : "=r"(w) : "m"(*pw) : "memory"); 918a299895bSThomas Huth report(w == 0x7799, "cross-page mmio read"); 919ec278ce3SAvi Kivity asm volatile("mov %1, %0" : "=m"(*pw) : "r"((uint16_t)0x88aa)); 920a299895bSThomas Huth report(mem[4095] == 0xaa && mem[4096] == 0x88, "cross-page mmio write"); 921ec278ce3SAvi Kivity } 922ec278ce3SAvi Kivity 923a19c7db7SXiao Guangrong static void test_string_io_mmio(volatile uint8_t *mem) 924a19c7db7SXiao Guangrong { 925a19c7db7SXiao Guangrong /* Cross MMIO pages.*/ 926a19c7db7SXiao Guangrong volatile uint8_t *mmio = mem + 4032; 927a19c7db7SXiao Guangrong 928a19c7db7SXiao Guangrong asm volatile("outw %%ax, %%dx \n\t" : : "a"(0x9999), "d"(TESTDEV_IO_PORT)); 929a19c7db7SXiao Guangrong 930a19c7db7SXiao Guangrong asm volatile ("cld; rep insb" : : "d" (TESTDEV_IO_PORT), "D" (mmio), "c" (1024)); 931a19c7db7SXiao Guangrong 932a299895bSThomas Huth report(mmio[1023] == 0x99, "string_io_mmio"); 933a19c7db7SXiao Guangrong } 934a19c7db7SXiao Guangrong 93556c6afa7SJan Kiszka /* kvm doesn't allow lidt/lgdt from mmio, so the test is disabled */ 93656c6afa7SJan Kiszka #if 0 93747c1461aSAvi Kivity static void test_lgdt_lidt(volatile uint8_t *mem) 93847c1461aSAvi Kivity { 93947c1461aSAvi Kivity struct descriptor_table_ptr orig, fresh = {}; 94047c1461aSAvi Kivity 94147c1461aSAvi Kivity sgdt(&orig); 94247c1461aSAvi Kivity *(struct descriptor_table_ptr *)mem = (struct descriptor_table_ptr) { 94347c1461aSAvi Kivity .limit = 0xf234, 94447c1461aSAvi Kivity .base = 0x12345678abcd, 94547c1461aSAvi Kivity }; 94647c1461aSAvi Kivity cli(); 94747c1461aSAvi Kivity asm volatile("lgdt %0" : : "m"(*(struct descriptor_table_ptr *)mem)); 94847c1461aSAvi Kivity sgdt(&fresh); 94947c1461aSAvi Kivity lgdt(&orig); 95047c1461aSAvi Kivity sti(); 951a299895bSThomas Huth report(orig.limit == fresh.limit && orig.base == fresh.base, 952a299895bSThomas Huth "lgdt (long address)"); 95347c1461aSAvi Kivity 95447c1461aSAvi Kivity sidt(&orig); 95547c1461aSAvi Kivity *(struct descriptor_table_ptr *)mem = (struct descriptor_table_ptr) { 95647c1461aSAvi Kivity .limit = 0x432f, 95747c1461aSAvi Kivity .base = 0xdbca87654321, 95847c1461aSAvi Kivity }; 95947c1461aSAvi Kivity cli(); 96047c1461aSAvi Kivity asm volatile("lidt %0" : : "m"(*(struct descriptor_table_ptr *)mem)); 96147c1461aSAvi Kivity sidt(&fresh); 96247c1461aSAvi Kivity lidt(&orig); 96347c1461aSAvi Kivity sti(); 964a299895bSThomas Huth report(orig.limit == fresh.limit && orig.base == fresh.base, 965a299895bSThomas Huth "lidt (long address)"); 96647c1461aSAvi Kivity } 96756c6afa7SJan Kiszka #endif 96847c1461aSAvi Kivity 969fc2f880bSAvi Kivity static void ss_bad_rpl(struct ex_regs *regs) 970fc2f880bSAvi Kivity { 971fc2f880bSAvi Kivity extern char ss_bad_rpl_cont; 972fc2f880bSAvi Kivity 973fc2f880bSAvi Kivity ++exceptions; 974fc2f880bSAvi Kivity regs->rip = (ulong)&ss_bad_rpl_cont; 975fc2f880bSAvi Kivity } 976fc2f880bSAvi Kivity 977fc2f880bSAvi Kivity static void test_sreg(volatile uint16_t *mem) 978fc2f880bSAvi Kivity { 979fc2f880bSAvi Kivity u16 ss = read_ss(); 980fc2f880bSAvi Kivity 981fc2f880bSAvi Kivity // check for null segment load 982fc2f880bSAvi Kivity *mem = 0; 983fc2f880bSAvi Kivity asm volatile("mov %0, %%ss" : : "m"(*mem)); 984a299895bSThomas Huth report(read_ss() == 0, "mov null, %%ss"); 985fc2f880bSAvi Kivity 986fc2f880bSAvi Kivity // check for exception when ss.rpl != cpl on null segment load 987fc2f880bSAvi Kivity exceptions = 0; 988fc2f880bSAvi Kivity handle_exception(GP_VECTOR, ss_bad_rpl); 989fc2f880bSAvi Kivity *mem = 3; 990fc2f880bSAvi Kivity asm volatile("mov %0, %%ss; ss_bad_rpl_cont:" : : "m"(*mem)); 991a299895bSThomas Huth report(exceptions == 1 && read_ss() == 0, 992a299895bSThomas Huth "mov null, %%ss (with ss.rpl != cpl)"); 993fc2f880bSAvi Kivity handle_exception(GP_VECTOR, 0); 994fc2f880bSAvi Kivity write_ss(ss); 995fc2f880bSAvi Kivity } 996fc2f880bSAvi Kivity 9973ee1b91bSBin Meng static uint64_t usr_gs_mov(void) 9983ee1b91bSBin Meng { 9993ee1b91bSBin Meng static uint64_t dummy = MAGIC_NUM; 10003ee1b91bSBin Meng uint64_t dummy_ptr = (uint64_t)&dummy; 10013ee1b91bSBin Meng uint64_t ret; 10023ee1b91bSBin Meng 10033ee1b91bSBin Meng dummy_ptr -= GS_BASE; 10043ee1b91bSBin Meng asm volatile("mov %%gs:(%%rcx), %%rax" : "=a"(ret): "c"(dummy_ptr) :); 10053ee1b91bSBin Meng 10063ee1b91bSBin Meng return ret; 10073ee1b91bSBin Meng } 10083ee1b91bSBin Meng 10093ee1b91bSBin Meng static void test_iret(void) 10103ee1b91bSBin Meng { 10113ee1b91bSBin Meng uint64_t val; 10123ee1b91bSBin Meng bool raised_vector; 10133ee1b91bSBin Meng 10143ee1b91bSBin Meng /* Update GS base to 4MiB */ 10153ee1b91bSBin Meng wrmsr(MSR_GS_BASE, GS_BASE); 10163ee1b91bSBin Meng 10173ee1b91bSBin Meng /* 10183ee1b91bSBin Meng * Per the SDM, jumping to user mode via `iret`, which is returning to 10193ee1b91bSBin Meng * outer privilege level, for segment registers (ES, FS, GS, and DS) 10203ee1b91bSBin Meng * if the check fails, the segment selector becomes null. 10213ee1b91bSBin Meng * 10223ee1b91bSBin Meng * In our test case, GS becomes null. 10233ee1b91bSBin Meng */ 10243ee1b91bSBin Meng val = run_in_user((usermode_func)usr_gs_mov, GP_VECTOR, 10253ee1b91bSBin Meng 0, 0, 0, 0, &raised_vector); 10263ee1b91bSBin Meng 10273ee1b91bSBin Meng report(val == MAGIC_NUM, "Test ret/iret with a nullified segment"); 10283ee1b91bSBin Meng } 10293ee1b91bSBin Meng 10304425dba6SPeter Feiner /* Broken emulation causes triple fault, which skips the other tests. */ 10314425dba6SPeter Feiner #if 0 1032cb615a4dSAvi Kivity static void test_lldt(volatile uint16_t *mem) 1033cb615a4dSAvi Kivity { 10344425dba6SPeter Feiner u64 gdt[] = { 0, /* null descriptor */ 10354425dba6SPeter Feiner #ifdef __X86_64__ 10364425dba6SPeter Feiner 0, /* ldt descriptor is 16 bytes in long mode */ 10374425dba6SPeter Feiner #endif 10384425dba6SPeter Feiner 0x0000f82000000ffffull /* ldt descriptor */ }; 10394425dba6SPeter Feiner struct descriptor_table_ptr gdt_ptr = { .limit = sizeof(gdt) - 1, 10404425dba6SPeter Feiner .base = (ulong)&gdt }; 1041cb615a4dSAvi Kivity struct descriptor_table_ptr orig_gdt; 1042cb615a4dSAvi Kivity 1043cb615a4dSAvi Kivity cli(); 1044cb615a4dSAvi Kivity sgdt(&orig_gdt); 1045cb615a4dSAvi Kivity lgdt(&gdt_ptr); 1046cb615a4dSAvi Kivity *mem = 0x8; 1047cb615a4dSAvi Kivity asm volatile("lldt %0" : : "m"(*mem)); 1048cb615a4dSAvi Kivity lgdt(&orig_gdt); 1049cb615a4dSAvi Kivity sti(); 1050a299895bSThomas Huth report(sldt() == *mem, "lldt"); 1051cb615a4dSAvi Kivity } 10524425dba6SPeter Feiner #endif 1053cb615a4dSAvi Kivity 105458a9d81eSAvi Kivity static void test_ltr(volatile uint16_t *mem) 105558a9d81eSAvi Kivity { 105658a9d81eSAvi Kivity struct descriptor_table_ptr gdt_ptr; 105758a9d81eSAvi Kivity uint64_t *gdt, *trp; 105858a9d81eSAvi Kivity uint16_t tr = str(); 105958a9d81eSAvi Kivity uint64_t busy_mask = (uint64_t)1 << 41; 106058a9d81eSAvi Kivity 106158a9d81eSAvi Kivity sgdt(&gdt_ptr); 106258a9d81eSAvi Kivity gdt = (uint64_t *)gdt_ptr.base; 106358a9d81eSAvi Kivity trp = &gdt[tr >> 3]; 106458a9d81eSAvi Kivity *trp &= ~busy_mask; 106558a9d81eSAvi Kivity *mem = tr; 106658a9d81eSAvi Kivity asm volatile("ltr %0" : : "m"(*mem) : "memory"); 1067a299895bSThomas Huth report(str() == tr && (*trp & busy_mask), "ltr"); 106858a9d81eSAvi Kivity } 106958a9d81eSAvi Kivity 10706cff92ddSAvi Kivity static void test_simplealu(u32 *mem) 10716cff92ddSAvi Kivity { 10726cff92ddSAvi Kivity *mem = 0x1234; 10736cff92ddSAvi Kivity asm("or %1, %0" : "+m"(*mem) : "r"(0x8001)); 1074a299895bSThomas Huth report(*mem == 0x9235, "or"); 10756cff92ddSAvi Kivity asm("add %1, %0" : "+m"(*mem) : "r"(2)); 1076a299895bSThomas Huth report(*mem == 0x9237, "add"); 10776cff92ddSAvi Kivity asm("xor %1, %0" : "+m"(*mem) : "r"(0x1111)); 1078a299895bSThomas Huth report(*mem == 0x8326, "xor"); 10796cff92ddSAvi Kivity asm("sub %1, %0" : "+m"(*mem) : "r"(0x26)); 1080a299895bSThomas Huth report(*mem == 0x8300, "sub"); 10816cff92ddSAvi Kivity asm("clc; adc %1, %0" : "+m"(*mem) : "r"(0x100)); 1082a299895bSThomas Huth report(*mem == 0x8400, "adc(0)"); 10836cff92ddSAvi Kivity asm("stc; adc %1, %0" : "+m"(*mem) : "r"(0x100)); 1084a299895bSThomas Huth report(*mem == 0x8501, "adc(0)"); 10856cff92ddSAvi Kivity asm("clc; sbb %1, %0" : "+m"(*mem) : "r"(0)); 1086a299895bSThomas Huth report(*mem == 0x8501, "sbb(0)"); 10876cff92ddSAvi Kivity asm("stc; sbb %1, %0" : "+m"(*mem) : "r"(0)); 1088a299895bSThomas Huth report(*mem == 0x8500, "sbb(1)"); 10896cff92ddSAvi Kivity asm("and %1, %0" : "+m"(*mem) : "r"(0xfe77)); 1090a299895bSThomas Huth report(*mem == 0x8400, "and"); 10916cff92ddSAvi Kivity asm("test %1, %0" : "+m"(*mem) : "r"(0xf000)); 1092a299895bSThomas Huth report(*mem == 0x8400, "test"); 10936cff92ddSAvi Kivity } 10946cff92ddSAvi Kivity 109570bdcadbSNadav Amit static void illegal_movbe_handler(struct ex_regs *regs) 109670bdcadbSNadav Amit { 109770bdcadbSNadav Amit extern char bad_movbe_cont; 109870bdcadbSNadav Amit 109970bdcadbSNadav Amit ++exceptions; 110070bdcadbSNadav Amit regs->rip = (ulong)&bad_movbe_cont; 110170bdcadbSNadav Amit } 110270bdcadbSNadav Amit 110370bdcadbSNadav Amit static void test_illegal_movbe(void) 110470bdcadbSNadav Amit { 1105badc98caSKrish Sadhukhan if (!this_cpu_has(X86_FEATURE_MOVBE)) { 110632b9603cSRadim Krčmář report_skip("illegal movbe"); 110770bdcadbSNadav Amit return; 110870bdcadbSNadav Amit } 110970bdcadbSNadav Amit 111070bdcadbSNadav Amit exceptions = 0; 111170bdcadbSNadav Amit handle_exception(UD_VECTOR, illegal_movbe_handler); 111270bdcadbSNadav Amit asm volatile(".byte 0x0f; .byte 0x38; .byte 0xf0; .byte 0xc0;\n\t" 111370bdcadbSNadav Amit " bad_movbe_cont:" : : : "rax"); 1114a299895bSThomas Huth report(exceptions == 1, "illegal movbe"); 111570bdcadbSNadav Amit handle_exception(UD_VECTOR, 0); 111670bdcadbSNadav Amit } 111770bdcadbSNadav Amit 111845fdc228SPaolo Bonzini static void record_no_fep(struct ex_regs *regs) 111945fdc228SPaolo Bonzini { 112045fdc228SPaolo Bonzini fep_available = 0; 112145fdc228SPaolo Bonzini regs->rip += KVM_FEP_LENGTH; 112245fdc228SPaolo Bonzini } 112345fdc228SPaolo Bonzini 11247db17e21SThomas Huth int main(void) 11257d36db35SAvi Kivity { 11267d36db35SAvi Kivity void *mem; 112745fdc228SPaolo Bonzini void *insn_page; 11288cfa5a06SAvi Kivity void *insn_ram; 1129*e5e76263SJacob Xu void *cross_mem; 11307d36db35SAvi Kivity unsigned long t1, t2; 11317d36db35SAvi Kivity 11327d36db35SAvi Kivity setup_vm(); 113345fdc228SPaolo Bonzini handle_exception(UD_VECTOR, record_no_fep); 113445fdc228SPaolo Bonzini asm(KVM_FEP "nop"); 113545fdc228SPaolo Bonzini handle_exception(UD_VECTOR, 0); 113645fdc228SPaolo Bonzini 1137ec278ce3SAvi Kivity mem = alloc_vpages(2); 1138ec278ce3SAvi Kivity install_page((void *)read_cr3(), IORAM_BASE_PHYS, mem); 1139ec278ce3SAvi Kivity // install the page twice to test cross-page mmio 1140ec278ce3SAvi Kivity install_page((void *)read_cr3(), IORAM_BASE_PHYS, mem + 4096); 1141d7143f32SAvi Kivity insn_page = alloc_page(); 1142d7143f32SAvi Kivity insn_ram = vmap(virt_to_phys(insn_page), 4096); 1143*e5e76263SJacob Xu cross_mem = vmap(virt_to_phys(alloc_pages(2)), 2 * PAGE_SIZE); 11447d36db35SAvi Kivity 11457d36db35SAvi Kivity // test mov reg, r/m and mov r/m, reg 11467d36db35SAvi Kivity t1 = 0x123456789abcdef; 11477d36db35SAvi Kivity asm volatile("mov %[t1], (%[mem]) \n\t" 11487d36db35SAvi Kivity "mov (%[mem]), %[t2]" 11497d36db35SAvi Kivity : [t2]"=r"(t2) 11507d36db35SAvi Kivity : [t1]"r"(t1), [mem]"r"(mem) 11517d36db35SAvi Kivity : "memory"); 1152a299895bSThomas Huth report(t2 == 0x123456789abcdef, "mov reg, r/m (1)"); 11537d36db35SAvi Kivity 11546cff92ddSAvi Kivity test_simplealu(mem); 11557d36db35SAvi Kivity test_cmps(mem); 115680a4ea7bSAvi Kivity test_scas(mem); 11577d36db35SAvi Kivity 11587d36db35SAvi Kivity test_push(mem); 11597d36db35SAvi Kivity test_pop(mem); 11607d36db35SAvi Kivity 11617d36db35SAvi Kivity test_xchg(mem); 11625647d55cSWei Yongjun test_xadd(mem); 11637d36db35SAvi Kivity 11647d36db35SAvi Kivity test_cr8(); 11657d36db35SAvi Kivity 11664003963dSNadav Amit test_smsw(mem); 11677d36db35SAvi Kivity test_lmsw(); 11687d36db35SAvi Kivity test_ljmp(mem); 11697d36db35SAvi Kivity test_stringio(); 11707d36db35SAvi Kivity test_incdecnotneg(mem); 1171d4655eafSWei Yongjun test_btc(mem); 11722e16c7f6SWei Yongjun test_bsfbsr(mem); 117351d65a3cSAvi Kivity test_imul(mem); 1174c2c43fcfSAvi Kivity test_muldiv(mem); 1175d7f3ee3cSAvi Kivity test_sse(mem); 1176*e5e76263SJacob Xu test_sse_exceptions(cross_mem); 11773587082bSAvi Kivity test_mmx(mem); 11788cfa5a06SAvi Kivity test_rip_relative(mem, insn_ram); 1179b212fcdaSAvi Kivity test_shld_shrd(mem); 118047c1461aSAvi Kivity //test_lgdt_lidt(mem); 1181fc2f880bSAvi Kivity test_sreg(mem); 11823ee1b91bSBin Meng test_iret(); 11834425dba6SPeter Feiner //test_lldt(mem); 118458a9d81eSAvi Kivity test_ltr(mem); 118530762176SNadav Amit test_cmov(mem); 11867d36db35SAvi Kivity 118745fdc228SPaolo Bonzini if (fep_available) { 118845fdc228SPaolo Bonzini test_mmx_movq_mf(mem); 118945fdc228SPaolo Bonzini test_movabs(mem); 119045fdc228SPaolo Bonzini test_smsw_reg(mem); 119145fdc228SPaolo Bonzini test_nop(mem); 119245fdc228SPaolo Bonzini test_mov_dr(mem); 119345fdc228SPaolo Bonzini } else { 119445fdc228SPaolo Bonzini report_skip("skipping register-only tests, " 119545fdc228SPaolo Bonzini "use kvm.forced_emulation_prefix=1 to enable"); 119645fdc228SPaolo Bonzini } 119745fdc228SPaolo Bonzini 119826311ca9SNadav Amit test_push16(mem); 1199ec278ce3SAvi Kivity test_crosspage_mmio(mem); 1200ec278ce3SAvi Kivity 1201a19c7db7SXiao Guangrong test_string_io_mmio(mem); 1202a19c7db7SXiao Guangrong 1203f413c1afSNadav Amit test_jmp_noncanonical(mem); 120470bdcadbSNadav Amit test_illegal_movbe(); 1205f413c1afSNadav Amit 1206f3cdd159SJan Kiszka return report_summary(); 12077d36db35SAvi Kivity } 1208