xref: /kvm-unit-tests/x86/emulator.c (revision efd8e5aa7474352dd66b0e647948fd9cec3cadc6)
17d36db35SAvi Kivity #include "ioram.h"
27d36db35SAvi Kivity #include "vm.h"
37d36db35SAvi Kivity #include "libcflat.h"
4e7c37968SGleb Natapov #include "desc.h"
5d7143f32SAvi Kivity #include "types.h"
6b39a3e14SNadav Amit #include "processor.h"
7*efd8e5aaSPaolo Bonzini #include "vmalloc.h"
87d36db35SAvi Kivity 
97d36db35SAvi Kivity #define memset __builtin_memset
107d36db35SAvi Kivity #define TESTDEV_IO_PORT 0xe0
117d36db35SAvi Kivity 
12d7143f32SAvi Kivity static int exceptions;
13d7143f32SAvi Kivity 
14c5a2a731SArthur Chunqi Li struct regs {
15c5a2a731SArthur Chunqi Li 	u64 rax, rbx, rcx, rdx;
16c5a2a731SArthur Chunqi Li 	u64 rsi, rdi, rsp, rbp;
17c5a2a731SArthur Chunqi Li 	u64 r8, r9, r10, r11;
18c5a2a731SArthur Chunqi Li 	u64 r12, r13, r14, r15;
19c5a2a731SArthur Chunqi Li 	u64 rip, rflags;
20c5a2a731SArthur Chunqi Li };
21c5a2a731SArthur Chunqi Li struct regs inregs, outregs, save;
22c5a2a731SArthur Chunqi Li 
23c5a2a731SArthur Chunqi Li struct insn_desc {
24c5a2a731SArthur Chunqi Li 	u64 ptr;
25c5a2a731SArthur Chunqi Li 	size_t len;
26c5a2a731SArthur Chunqi Li };
27c5a2a731SArthur Chunqi Li 
287d36db35SAvi Kivity static char st1[] = "abcdefghijklmnop";
297d36db35SAvi Kivity 
307d36db35SAvi Kivity void test_stringio()
317d36db35SAvi Kivity {
327d36db35SAvi Kivity 	unsigned char r = 0;
337d36db35SAvi Kivity 	asm volatile("cld \n\t"
347d36db35SAvi Kivity 		     "movw %0, %%dx \n\t"
357d36db35SAvi Kivity 		     "rep outsb \n\t"
367d36db35SAvi Kivity 		     : : "i"((short)TESTDEV_IO_PORT),
377d36db35SAvi Kivity 		       "S"(st1), "c"(sizeof(st1) - 1));
387d36db35SAvi Kivity 	asm volatile("inb %1, %0\n\t" : "=a"(r) : "i"((short)TESTDEV_IO_PORT));
397d36db35SAvi Kivity 	report("outsb up", r == st1[sizeof(st1) - 2]); /* last char */
407d36db35SAvi Kivity 
417d36db35SAvi Kivity 	asm volatile("std \n\t"
427d36db35SAvi Kivity 		     "movw %0, %%dx \n\t"
437d36db35SAvi Kivity 		     "rep outsb \n\t"
447d36db35SAvi Kivity 		     : : "i"((short)TESTDEV_IO_PORT),
457d36db35SAvi Kivity 		       "S"(st1 + sizeof(st1) - 2), "c"(sizeof(st1) - 1));
467d36db35SAvi Kivity 	asm volatile("cld \n\t" : : );
477d36db35SAvi Kivity 	asm volatile("in %1, %0\n\t" : "=a"(r) : "i"((short)TESTDEV_IO_PORT));
487d36db35SAvi Kivity 	report("outsb down", r == st1[0]);
497d36db35SAvi Kivity }
507d36db35SAvi Kivity 
517d36db35SAvi Kivity void test_cmps_one(unsigned char *m1, unsigned char *m3)
527d36db35SAvi Kivity {
537d36db35SAvi Kivity 	void *rsi, *rdi;
547d36db35SAvi Kivity 	long rcx, tmp;
557d36db35SAvi Kivity 
567d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 30;
577d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
587d36db35SAvi Kivity 		     "repe/cmpsb"
597d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
607d36db35SAvi Kivity 		     : : "cc");
617d36db35SAvi Kivity 	report("repe/cmpsb (1)", rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30);
627d36db35SAvi Kivity 
6351ba4180SAvi Kivity 	rsi = m1; rdi = m3; rcx = 30;
6451ba4180SAvi Kivity 	asm volatile("or $1, %[tmp]\n\t" // clear ZF
6551ba4180SAvi Kivity 		     "repe/cmpsb"
6651ba4180SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
6751ba4180SAvi Kivity 		     : : "cc");
6851ba4180SAvi Kivity 	report("repe/cmpsb (1.zf)", rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30);
6951ba4180SAvi Kivity 
707d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 15;
717d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
727d36db35SAvi Kivity 		     "repe/cmpsw"
737d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
747d36db35SAvi Kivity 		     : : "cc");
757d36db35SAvi Kivity 	report("repe/cmpsw (1)", rcx == 0 && rsi == m1 + 30 && rdi == m3 + 30);
767d36db35SAvi Kivity 
777d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 7;
787d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
797d36db35SAvi Kivity 		     "repe/cmpsl"
807d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
817d36db35SAvi Kivity 		     : : "cc");
827d36db35SAvi Kivity 	report("repe/cmpll (1)", rcx == 0 && rsi == m1 + 28 && rdi == m3 + 28);
837d36db35SAvi Kivity 
847d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 4;
857d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
867d36db35SAvi Kivity 		     "repe/cmpsq"
877d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
887d36db35SAvi Kivity 		     : : "cc");
897d36db35SAvi Kivity 	report("repe/cmpsq (1)", rcx == 0 && rsi == m1 + 32 && rdi == m3 + 32);
907d36db35SAvi Kivity 
917d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 130;
927d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
937d36db35SAvi Kivity 		     "repe/cmpsb"
947d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
957d36db35SAvi Kivity 		     : : "cc");
967d36db35SAvi Kivity 	report("repe/cmpsb (2)",
977d36db35SAvi Kivity 	       rcx == 29 && rsi == m1 + 101 && rdi == m3 + 101);
987d36db35SAvi Kivity 
997d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 65;
1007d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
1017d36db35SAvi Kivity 		     "repe/cmpsw"
1027d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
1037d36db35SAvi Kivity 		     : : "cc");
1047d36db35SAvi Kivity 	report("repe/cmpsw (2)",
1057d36db35SAvi Kivity 	       rcx == 14 && rsi == m1 + 102 && rdi == m3 + 102);
1067d36db35SAvi Kivity 
1077d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 32;
1087d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
1097d36db35SAvi Kivity 		     "repe/cmpsl"
1107d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
1117d36db35SAvi Kivity 		     : : "cc");
1127d36db35SAvi Kivity 	report("repe/cmpll (2)",
1137d36db35SAvi Kivity 	       rcx == 6 && rsi == m1 + 104 && rdi == m3 + 104);
1147d36db35SAvi Kivity 
1157d36db35SAvi Kivity 	rsi = m1; rdi = m3; rcx = 16;
1167d36db35SAvi Kivity 	asm volatile("xor %[tmp], %[tmp] \n\t"
1177d36db35SAvi Kivity 		     "repe/cmpsq"
1187d36db35SAvi Kivity 		     : "+S"(rsi), "+D"(rdi), "+c"(rcx), [tmp]"=&r"(tmp)
1197d36db35SAvi Kivity 		     : : "cc");
1207d36db35SAvi Kivity 	report("repe/cmpsq (2)",
1217d36db35SAvi Kivity 	       rcx == 3 && rsi == m1 + 104 && rdi == m3 + 104);
1227d36db35SAvi Kivity 
1237d36db35SAvi Kivity }
1247d36db35SAvi Kivity 
1257d36db35SAvi Kivity void test_cmps(void *mem)
1267d36db35SAvi Kivity {
1277d36db35SAvi Kivity 	unsigned char *m1 = mem, *m2 = mem + 1024;
1287d36db35SAvi Kivity 	unsigned char m3[1024];
1297d36db35SAvi Kivity 
1307d36db35SAvi Kivity 	for (int i = 0; i < 100; ++i)
1317d36db35SAvi Kivity 		m1[i] = m2[i] = m3[i] = i;
1327d36db35SAvi Kivity 	for (int i = 100; i < 200; ++i)
1337d36db35SAvi Kivity 		m1[i] = (m3[i] = m2[i] = i) + 1;
1347d36db35SAvi Kivity 	test_cmps_one(m1, m3);
1357d36db35SAvi Kivity 	test_cmps_one(m1, m2);
1367d36db35SAvi Kivity }
1377d36db35SAvi Kivity 
13880a4ea7bSAvi Kivity void test_scas(void *mem)
13980a4ea7bSAvi Kivity {
14080a4ea7bSAvi Kivity     bool z;
14180a4ea7bSAvi Kivity     void *di;
14280a4ea7bSAvi Kivity 
14380a4ea7bSAvi Kivity     *(ulong *)mem = 0x77665544332211;
14480a4ea7bSAvi Kivity 
14580a4ea7bSAvi Kivity     di = mem;
14680a4ea7bSAvi Kivity     asm ("scasb; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff11));
14780a4ea7bSAvi Kivity     report("scasb match", di == mem + 1 && z);
14880a4ea7bSAvi Kivity 
14980a4ea7bSAvi Kivity     di = mem;
15080a4ea7bSAvi Kivity     asm ("scasb; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff54));
15180a4ea7bSAvi Kivity     report("scasb mismatch", di == mem + 1 && !z);
15280a4ea7bSAvi Kivity 
15380a4ea7bSAvi Kivity     di = mem;
15480a4ea7bSAvi Kivity     asm ("scasw; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff2211));
15580a4ea7bSAvi Kivity     report("scasw match", di == mem + 2 && z);
15680a4ea7bSAvi Kivity 
15780a4ea7bSAvi Kivity     di = mem;
15880a4ea7bSAvi Kivity     asm ("scasw; setz %0" : "=rm"(z), "+D"(di) : "a"(0xffdd11));
15980a4ea7bSAvi Kivity     report("scasw mismatch", di == mem + 2 && !z);
16080a4ea7bSAvi Kivity 
16180a4ea7bSAvi Kivity     di = mem;
16280a4ea7bSAvi Kivity     asm ("scasl; setz %0" : "=rm"(z), "+D"(di) : "a"(0xff44332211ul));
16380a4ea7bSAvi Kivity     report("scasd match", di == mem + 4 && z);
16480a4ea7bSAvi Kivity 
16580a4ea7bSAvi Kivity     di = mem;
16680a4ea7bSAvi Kivity     asm ("scasl; setz %0" : "=rm"(z), "+D"(di) : "a"(0x45332211));
16780a4ea7bSAvi Kivity     report("scasd mismatch", di == mem + 4 && !z);
16880a4ea7bSAvi Kivity 
16980a4ea7bSAvi Kivity     di = mem;
17080a4ea7bSAvi Kivity     asm ("scasq; setz %0" : "=rm"(z), "+D"(di) : "a"(0x77665544332211ul));
17180a4ea7bSAvi Kivity     report("scasq match", di == mem + 8 && z);
17280a4ea7bSAvi Kivity 
17380a4ea7bSAvi Kivity     di = mem;
17480a4ea7bSAvi Kivity     asm ("scasq; setz %0" : "=rm"(z), "+D"(di) : "a"(3));
17580a4ea7bSAvi Kivity     report("scasq mismatch", di == mem + 8 && !z);
17680a4ea7bSAvi Kivity }
17780a4ea7bSAvi Kivity 
1787d36db35SAvi Kivity void test_cr8(void)
1797d36db35SAvi Kivity {
1807d36db35SAvi Kivity 	unsigned long src, dst;
1817d36db35SAvi Kivity 
1827d36db35SAvi Kivity 	dst = 777;
1837d36db35SAvi Kivity 	src = 3;
1847d36db35SAvi Kivity 	asm volatile("mov %[src], %%cr8; mov %%cr8, %[dst]"
1857d36db35SAvi Kivity 		     : [dst]"+r"(dst), [src]"+r"(src));
186ce53c83bSPaolo Bonzini 	report("mov %%cr8", dst == 3 && src == 3);
1877d36db35SAvi Kivity }
1887d36db35SAvi Kivity 
1897d36db35SAvi Kivity void test_push(void *mem)
1907d36db35SAvi Kivity {
1917d36db35SAvi Kivity 	unsigned long tmp;
1927d36db35SAvi Kivity 	unsigned long *stack_top = mem + 4096;
1937d36db35SAvi Kivity 	unsigned long *new_stack_top;
1947d36db35SAvi Kivity 	unsigned long memw = 0x123456789abcdeful;
1957d36db35SAvi Kivity 
1967d36db35SAvi Kivity 	memset(mem, 0x55, (void *)stack_top - mem);
1977d36db35SAvi Kivity 
1987d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
1997d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2007d36db35SAvi Kivity 		     "pushq $-7 \n\t"
2017d36db35SAvi Kivity 		     "pushq %[reg] \n\t"
2027d36db35SAvi Kivity 		     "pushq (%[mem]) \n\t"
2037d36db35SAvi Kivity 		     "pushq $-7070707 \n\t"
2047d36db35SAvi Kivity 		     "mov %%rsp, %[new_stack_top] \n\t"
2057d36db35SAvi Kivity 		     "mov %[tmp], %%rsp"
2067d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp), [new_stack_top]"=r"(new_stack_top)
2077d36db35SAvi Kivity 		     : [stack_top]"r"(stack_top),
2087d36db35SAvi Kivity 		       [reg]"r"(-17l), [mem]"r"(&memw)
2097d36db35SAvi Kivity 		     : "memory");
2107d36db35SAvi Kivity 
2117d36db35SAvi Kivity 	report("push $imm8", stack_top[-1] == -7ul);
212ce53c83bSPaolo Bonzini 	report("push %%reg", stack_top[-2] == -17ul);
2137d36db35SAvi Kivity 	report("push mem", stack_top[-3] == 0x123456789abcdeful);
2147d36db35SAvi Kivity 	report("push $imm", stack_top[-4] == -7070707);
2157d36db35SAvi Kivity }
2167d36db35SAvi Kivity 
2177d36db35SAvi Kivity void test_pop(void *mem)
2187d36db35SAvi Kivity {
21928f04f22SAvi Kivity 	unsigned long tmp, tmp3, rsp, rbp;
2207d36db35SAvi Kivity 	unsigned long *stack_top = mem + 4096;
2217d36db35SAvi Kivity 	unsigned long memw = 0x123456789abcdeful;
2227d36db35SAvi Kivity 	static unsigned long tmp2;
2237d36db35SAvi Kivity 
2247d36db35SAvi Kivity 	memset(mem, 0x55, (void *)stack_top - mem);
2257d36db35SAvi Kivity 
2267d36db35SAvi Kivity 	asm volatile("pushq %[val] \n\t"
2277d36db35SAvi Kivity 		     "popq (%[mem])"
2287d36db35SAvi Kivity 		     : : [val]"m"(memw), [mem]"r"(mem) : "memory");
2297d36db35SAvi Kivity 	report("pop mem", *(unsigned long *)mem == memw);
2307d36db35SAvi Kivity 
2317d36db35SAvi Kivity 	memw = 7 - memw;
2327d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
2337d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2347d36db35SAvi Kivity 		     "pushq %[val] \n\t"
2357d36db35SAvi Kivity 		     "popq %[tmp2] \n\t"
2367d36db35SAvi Kivity 		     "mov %[tmp], %%rsp"
2377d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp), [tmp2]"=m"(tmp2)
2387d36db35SAvi Kivity 		     : [val]"r"(memw), [stack_top]"r"(stack_top)
2397d36db35SAvi Kivity 		     : "memory");
2407d36db35SAvi Kivity 	report("pop mem (2)", tmp2 == memw);
2417d36db35SAvi Kivity 
2427d36db35SAvi Kivity 	memw = 129443 - memw;
2437d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
2447d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2457d36db35SAvi Kivity 		     "pushq %[val] \n\t"
2467d36db35SAvi Kivity 		     "popq %[tmp2] \n\t"
2477d36db35SAvi Kivity 		     "mov %[tmp], %%rsp"
2487d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp), [tmp2]"=r"(tmp2)
2497d36db35SAvi Kivity 		     : [val]"r"(memw), [stack_top]"r"(stack_top)
2507d36db35SAvi Kivity 		     : "memory");
2517d36db35SAvi Kivity 	report("pop reg", tmp2 == memw);
2527d36db35SAvi Kivity 
2537d36db35SAvi Kivity 	asm volatile("mov %%rsp, %[tmp] \n\t"
2547d36db35SAvi Kivity 		     "mov %[stack_top], %%rsp \n\t"
2557d36db35SAvi Kivity 		     "push $1f \n\t"
2567d36db35SAvi Kivity 		     "ret \n\t"
2577d36db35SAvi Kivity 		     "2: jmp 2b \n\t"
2587d36db35SAvi Kivity 		     "1: mov %[tmp], %%rsp"
2597d36db35SAvi Kivity 		     : [tmp]"=&r"(tmp) : [stack_top]"r"(stack_top)
2607d36db35SAvi Kivity 		     : "memory");
2617d36db35SAvi Kivity 	report("ret", 1);
2625269d6e7SAvi Kivity 
2635269d6e7SAvi Kivity 	stack_top[-1] = 0x778899;
264c2aa6128SPeter Feiner 	asm volatile("mov %[stack_top], %%r8 \n\t"
265c2aa6128SPeter Feiner 		     "mov %%rsp, %%r9 \n\t"
266c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r8 \n\t"
2675269d6e7SAvi Kivity 		     "leave \n\t"
268c2aa6128SPeter Feiner 		     "xchg %%rsp, %%r9 \n\t"
269c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r8 \n\t"
270c2aa6128SPeter Feiner 		     "mov %%r9, %[tmp] \n\t"
271c2aa6128SPeter Feiner 		     "mov %%r8, %[tmp3]"
2725269d6e7SAvi Kivity 		     : [tmp]"=&r"(tmp), [tmp3]"=&r"(tmp3) : [stack_top]"r"(stack_top-1)
273c2aa6128SPeter Feiner 		     : "memory", "r8", "r9");
2745269d6e7SAvi Kivity 	report("leave", tmp == (ulong)stack_top && tmp3 == 0x778899);
27528f04f22SAvi Kivity 
27628f04f22SAvi Kivity 	rbp = 0xaa55aa55bb66bb66ULL;
27728f04f22SAvi Kivity 	rsp = (unsigned long)stack_top;
278c2aa6128SPeter Feiner 	asm volatile("mov %[rsp], %%r8 \n\t"
279c2aa6128SPeter Feiner 		     "mov %[rbp], %%r9 \n\t"
280c2aa6128SPeter Feiner 		     "xchg %%rsp, %%r8 \n\t"
281c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r9 \n\t"
28228f04f22SAvi Kivity 		     "enter $0x1238, $0 \n\t"
283c2aa6128SPeter Feiner 		     "xchg %%rsp, %%r8 \n\t"
284c2aa6128SPeter Feiner 		     "xchg %%rbp, %%r9 \n\t"
285c2aa6128SPeter Feiner 		     "xchg %%r8, %[rsp] \n\t"
286c2aa6128SPeter Feiner 		     "xchg %%r9, %[rbp]"
287c2aa6128SPeter Feiner 		     : [rsp]"+a"(rsp), [rbp]"+b"(rbp) : : "memory", "r8", "r9");
28828f04f22SAvi Kivity 	report("enter",
28928f04f22SAvi Kivity 	       rsp == (unsigned long)stack_top - 8 - 0x1238
29028f04f22SAvi Kivity 	       && rbp == (unsigned long)stack_top - 8
29128f04f22SAvi Kivity 	       && stack_top[-1] == 0xaa55aa55bb66bb66ULL);
2927d36db35SAvi Kivity }
2937d36db35SAvi Kivity 
2947d36db35SAvi Kivity void test_ljmp(void *mem)
2957d36db35SAvi Kivity {
2967d36db35SAvi Kivity     unsigned char *m = mem;
2977d36db35SAvi Kivity     volatile int res = 1;
2987d36db35SAvi Kivity 
2997d36db35SAvi Kivity     *(unsigned long**)m = &&jmpf;
3007d36db35SAvi Kivity     asm volatile ("data16/mov %%cs, %0":"=m"(*(m + sizeof(unsigned long))));
3017d36db35SAvi Kivity     asm volatile ("rex64/ljmp *%0"::"m"(*m));
3027d36db35SAvi Kivity     res = 0;
3037d36db35SAvi Kivity jmpf:
3047d36db35SAvi Kivity     report("ljmp", res);
3057d36db35SAvi Kivity }
3067d36db35SAvi Kivity 
3077d36db35SAvi Kivity void test_incdecnotneg(void *mem)
3087d36db35SAvi Kivity {
3097d36db35SAvi Kivity     unsigned long *m = mem, v = 1234;
3107d36db35SAvi Kivity     unsigned char *mb = mem, vb = 66;
3117d36db35SAvi Kivity 
3127d36db35SAvi Kivity     *m = 0;
3137d36db35SAvi Kivity 
3147d36db35SAvi Kivity     asm volatile ("incl %0":"+m"(*m));
3157d36db35SAvi Kivity     report("incl",  *m == 1);
3167d36db35SAvi Kivity     asm volatile ("decl %0":"+m"(*m));
3177d36db35SAvi Kivity     report("decl",  *m == 0);
3187d36db35SAvi Kivity     asm volatile ("incb %0":"+m"(*m));
3197d36db35SAvi Kivity     report("incb",  *m == 1);
3207d36db35SAvi Kivity     asm volatile ("decb %0":"+m"(*m));
3217d36db35SAvi Kivity     report("decb",  *m == 0);
3227d36db35SAvi Kivity 
3237d36db35SAvi Kivity     asm volatile ("lock incl %0":"+m"(*m));
3247d36db35SAvi Kivity     report("lock incl",  *m == 1);
3257d36db35SAvi Kivity     asm volatile ("lock decl %0":"+m"(*m));
3267d36db35SAvi Kivity     report("lock decl",  *m == 0);
3277d36db35SAvi Kivity     asm volatile ("lock incb %0":"+m"(*m));
3287d36db35SAvi Kivity     report("lock incb",  *m == 1);
3297d36db35SAvi Kivity     asm volatile ("lock decb %0":"+m"(*m));
3307d36db35SAvi Kivity     report("lock decb",  *m == 0);
3317d36db35SAvi Kivity 
3327d36db35SAvi Kivity     *m = v;
3337d36db35SAvi Kivity 
3347d36db35SAvi Kivity     asm ("lock negq %0" : "+m"(*m)); v = -v;
3357d36db35SAvi Kivity     report("lock negl", *m == v);
3367d36db35SAvi Kivity     asm ("lock notq %0" : "+m"(*m)); v = ~v;
3377d36db35SAvi Kivity     report("lock notl", *m == v);
3387d36db35SAvi Kivity 
3397d36db35SAvi Kivity     *mb = vb;
3407d36db35SAvi Kivity 
3417d36db35SAvi Kivity     asm ("lock negb %0" : "+m"(*mb)); vb = -vb;
3427d36db35SAvi Kivity     report("lock negb", *mb == vb);
3437d36db35SAvi Kivity     asm ("lock notb %0" : "+m"(*mb)); vb = ~vb;
3447d36db35SAvi Kivity     report("lock notb", *mb == vb);
3457d36db35SAvi Kivity }
3467d36db35SAvi Kivity 
3474003963dSNadav Amit void test_smsw(uint64_t *h_mem)
3487d36db35SAvi Kivity {
3497d36db35SAvi Kivity 	char mem[16];
3507d36db35SAvi Kivity 	unsigned short msw, msw_orig, *pmsw;
3517d36db35SAvi Kivity 	int i, zero;
3527d36db35SAvi Kivity 
3537d36db35SAvi Kivity 	msw_orig = read_cr0();
3547d36db35SAvi Kivity 
3557d36db35SAvi Kivity 	asm("smsw %0" : "=r"(msw));
3567d36db35SAvi Kivity 	report("smsw (1)", msw == msw_orig);
3577d36db35SAvi Kivity 
3587d36db35SAvi Kivity 	memset(mem, 0, 16);
3597d36db35SAvi Kivity 	pmsw = (void *)mem;
3607d36db35SAvi Kivity 	asm("smsw %0" : "=m"(pmsw[4]));
3617d36db35SAvi Kivity 	zero = 1;
3627d36db35SAvi Kivity 	for (i = 0; i < 8; ++i)
3637d36db35SAvi Kivity 		if (i != 4 && pmsw[i])
3647d36db35SAvi Kivity 			zero = 0;
3657d36db35SAvi Kivity 	report("smsw (2)", msw == pmsw[4] && zero);
3664003963dSNadav Amit 
3674003963dSNadav Amit 	/* Trigger exit on smsw */
3684003963dSNadav Amit 	*h_mem = 0x12345678abcdeful;
36911147080SChris J Arges 	asm volatile("smsw %0" : "+m"(*h_mem));
3704003963dSNadav Amit 	report("smsw (3)", msw == (unsigned short)*h_mem &&
3714003963dSNadav Amit 		(*h_mem & ~0xfffful) == 0x12345678ab0000ul);
3727d36db35SAvi Kivity }
3737d36db35SAvi Kivity 
3747d36db35SAvi Kivity void test_lmsw(void)
3757d36db35SAvi Kivity {
3767d36db35SAvi Kivity 	char mem[16];
3777d36db35SAvi Kivity 	unsigned short msw, *pmsw;
3787d36db35SAvi Kivity 	unsigned long cr0;
3797d36db35SAvi Kivity 
3807d36db35SAvi Kivity 	cr0 = read_cr0();
3817d36db35SAvi Kivity 
3827d36db35SAvi Kivity 	msw = cr0 ^ 8;
3837d36db35SAvi Kivity 	asm("lmsw %0" : : "r"(msw));
3847d36db35SAvi Kivity 	printf("before %lx after %lx\n", cr0, read_cr0());
3857d36db35SAvi Kivity 	report("lmsw (1)", (cr0 ^ read_cr0()) == 8);
3867d36db35SAvi Kivity 
3877d36db35SAvi Kivity 	pmsw = (void *)mem;
3887d36db35SAvi Kivity 	*pmsw = cr0;
3897d36db35SAvi Kivity 	asm("lmsw %0" : : "m"(*pmsw));
3907d36db35SAvi Kivity 	printf("before %lx after %lx\n", cr0, read_cr0());
3917d36db35SAvi Kivity 	report("lmsw (2)", cr0 == read_cr0());
3927d36db35SAvi Kivity 
3937d36db35SAvi Kivity 	/* lmsw can't clear cr0.pe */
3947d36db35SAvi Kivity 	msw = (cr0 & ~1ul) ^ 4;  /* change EM to force trap */
3957d36db35SAvi Kivity 	asm("lmsw %0" : : "r"(msw));
3967d36db35SAvi Kivity 	report("lmsw (3)", (cr0 ^ read_cr0()) == 4 && (cr0 & 1));
3977d36db35SAvi Kivity 
3987d36db35SAvi Kivity 	/* back to normal */
3997d36db35SAvi Kivity 	msw = cr0;
4007d36db35SAvi Kivity 	asm("lmsw %0" : : "r"(msw));
4017d36db35SAvi Kivity }
4027d36db35SAvi Kivity 
4037d36db35SAvi Kivity void test_xchg(void *mem)
4047d36db35SAvi Kivity {
4057d36db35SAvi Kivity 	unsigned long *memq = mem;
4067d36db35SAvi Kivity 	unsigned long rax;
4077d36db35SAvi Kivity 
4087d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4097d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4107d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4117d36db35SAvi Kivity 		     "xchg %%al, (%[memq])\n\t"
4127d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4137d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4147d36db35SAvi Kivity 		     : [memq]"r"(memq)
415c2aa6128SPeter Feiner 		     : "memory", "rax");
4167d36db35SAvi Kivity 	report("xchg reg, r/m (1)",
4177d36db35SAvi Kivity 	       rax == 0xfedcba98765432ef && *memq == 0x123456789abcd10);
4187d36db35SAvi Kivity 
4197d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4207d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4217d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4227d36db35SAvi Kivity 		     "xchg %%ax, (%[memq])\n\t"
4237d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4247d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4257d36db35SAvi Kivity 		     : [memq]"r"(memq)
426c2aa6128SPeter Feiner 		     : "memory", "rax");
4277d36db35SAvi Kivity 	report("xchg reg, r/m (2)",
4287d36db35SAvi Kivity 	       rax == 0xfedcba987654cdef && *memq == 0x123456789ab3210);
4297d36db35SAvi Kivity 
4307d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4317d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4327d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4337d36db35SAvi Kivity 		     "xchg %%eax, (%[memq])\n\t"
4347d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4357d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4367d36db35SAvi Kivity 		     : [memq]"r"(memq)
437c2aa6128SPeter Feiner 		     : "memory", "rax");
4387d36db35SAvi Kivity 	report("xchg reg, r/m (3)",
4397d36db35SAvi Kivity 	       rax == 0x89abcdef && *memq == 0x123456776543210);
4407d36db35SAvi Kivity 
4417d36db35SAvi Kivity 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4427d36db35SAvi Kivity 		     "mov %%rax, (%[memq])\n\t"
4437d36db35SAvi Kivity 		     "mov $0xfedcba9876543210, %%rax\n\t"
4447d36db35SAvi Kivity 		     "xchg %%rax, (%[memq])\n\t"
4457d36db35SAvi Kivity 		     "mov %%rax, %[rax]\n\t"
4467d36db35SAvi Kivity 		     : [rax]"=r"(rax)
4477d36db35SAvi Kivity 		     : [memq]"r"(memq)
448c2aa6128SPeter Feiner 		     : "memory", "rax");
4497d36db35SAvi Kivity 	report("xchg reg, r/m (4)",
4507d36db35SAvi Kivity 	       rax == 0x123456789abcdef && *memq == 0xfedcba9876543210);
4517d36db35SAvi Kivity }
4527d36db35SAvi Kivity 
4535647d55cSWei Yongjun void test_xadd(void *mem)
4545647d55cSWei Yongjun {
4555647d55cSWei Yongjun 	unsigned long *memq = mem;
4565647d55cSWei Yongjun 	unsigned long rax;
4575647d55cSWei Yongjun 
4585647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4595647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4605647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4615647d55cSWei Yongjun 		     "xadd %%al, (%[memq])\n\t"
4625647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4635647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4645647d55cSWei Yongjun 		     : [memq]"r"(memq)
465c2aa6128SPeter Feiner 		     : "memory", "rax");
4665647d55cSWei Yongjun 	report("xadd reg, r/m (1)",
4675647d55cSWei Yongjun 	       rax == 0xfedcba98765432ef && *memq == 0x123456789abcdff);
4685647d55cSWei Yongjun 
4695647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4705647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4715647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4725647d55cSWei Yongjun 		     "xadd %%ax, (%[memq])\n\t"
4735647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4745647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4755647d55cSWei Yongjun 		     : [memq]"r"(memq)
476c2aa6128SPeter Feiner 		     : "memory", "rax");
4775647d55cSWei Yongjun 	report("xadd reg, r/m (2)",
4785647d55cSWei Yongjun 	       rax == 0xfedcba987654cdef && *memq == 0x123456789abffff);
4795647d55cSWei Yongjun 
4805647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4815647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4825647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4835647d55cSWei Yongjun 		     "xadd %%eax, (%[memq])\n\t"
4845647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4855647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4865647d55cSWei Yongjun 		     : [memq]"r"(memq)
487c2aa6128SPeter Feiner 		     : "memory", "rax");
4885647d55cSWei Yongjun 	report("xadd reg, r/m (3)",
4895647d55cSWei Yongjun 	       rax == 0x89abcdef && *memq == 0x1234567ffffffff);
4905647d55cSWei Yongjun 
4915647d55cSWei Yongjun 	asm volatile("mov $0x123456789abcdef, %%rax\n\t"
4925647d55cSWei Yongjun 		     "mov %%rax, (%[memq])\n\t"
4935647d55cSWei Yongjun 		     "mov $0xfedcba9876543210, %%rax\n\t"
4945647d55cSWei Yongjun 		     "xadd %%rax, (%[memq])\n\t"
4955647d55cSWei Yongjun 		     "mov %%rax, %[rax]\n\t"
4965647d55cSWei Yongjun 		     : [rax]"=r"(rax)
4975647d55cSWei Yongjun 		     : [memq]"r"(memq)
498c2aa6128SPeter Feiner 		     : "memory", "rax");
4995647d55cSWei Yongjun 	report("xadd reg, r/m (4)",
5005647d55cSWei Yongjun 	       rax == 0x123456789abcdef && *memq == 0xffffffffffffffff);
5015647d55cSWei Yongjun }
5025647d55cSWei Yongjun 
503d4655eafSWei Yongjun void test_btc(void *mem)
504d4655eafSWei Yongjun {
505d4655eafSWei Yongjun 	unsigned int *a = mem;
506d4655eafSWei Yongjun 
5077e083f20SNadav Amit 	memset(mem, 0, 4 * sizeof(unsigned int));
508d4655eafSWei Yongjun 
509d4655eafSWei Yongjun 	asm ("btcl $32, %0" :: "m"(a[0]) : "memory");
510d4655eafSWei Yongjun 	asm ("btcl $1, %0" :: "m"(a[1]) : "memory");
511d4655eafSWei Yongjun 	asm ("btcl %1, %0" :: "m"(a[0]), "r"(66) : "memory");
512d4655eafSWei Yongjun 	report("btcl imm8, r/m", a[0] == 1 && a[1] == 2 && a[2] == 4);
513d4655eafSWei Yongjun 
514d4655eafSWei Yongjun 	asm ("btcl %1, %0" :: "m"(a[3]), "r"(-1) : "memory");
515d4655eafSWei Yongjun 	report("btcl reg, r/m", a[0] == 1 && a[1] == 2 && a[2] == 0x80000004);
5167e083f20SNadav Amit 
5177e083f20SNadav Amit 	asm ("btcq %1, %0" : : "m"(a[2]), "r"(-1l) : "memory");
5187e083f20SNadav Amit 	report("btcq reg, r/m", a[0] == 1 && a[1] == 0x80000002 &&
5197e083f20SNadav Amit 		a[2] == 0x80000004 && a[3] == 0);
520d4655eafSWei Yongjun }
521d4655eafSWei Yongjun 
5222e16c7f6SWei Yongjun void test_bsfbsr(void *mem)
5232e16c7f6SWei Yongjun {
524554de466SAvi Kivity 	unsigned long rax, *memq = mem;
525554de466SAvi Kivity 	unsigned eax, *meml = mem;
526554de466SAvi Kivity 	unsigned short ax, *memw = mem;
527554de466SAvi Kivity 	unsigned char z;
5282e16c7f6SWei Yongjun 
529554de466SAvi Kivity 	*memw = 0xc000;
530554de466SAvi Kivity 	asm("bsfw %[mem], %[a]" : [a]"=a"(ax) : [mem]"m"(*memw));
531554de466SAvi Kivity 	report("bsfw r/m, reg", ax == 14);
5322e16c7f6SWei Yongjun 
533554de466SAvi Kivity 	*meml = 0xc0000000;
534554de466SAvi Kivity 	asm("bsfl %[mem], %[a]" : [a]"=a"(eax) : [mem]"m"(*meml));
535554de466SAvi Kivity 	report("bsfl r/m, reg", eax == 30);
5362e16c7f6SWei Yongjun 
537554de466SAvi Kivity 	*memq = 0xc00000000000;
538554de466SAvi Kivity 	asm("bsfq %[mem], %[a]" : [a]"=a"(rax) : [mem]"m"(*memq));
5392e16c7f6SWei Yongjun 	report("bsfq r/m, reg", rax == 46);
5402e16c7f6SWei Yongjun 
541554de466SAvi Kivity 	*memq = 0;
542554de466SAvi Kivity 	asm("bsfq %[mem], %[a]; setz %[z]"
543554de466SAvi Kivity 	    : [a]"=a"(rax), [z]"=rm"(z) : [mem]"m"(*memq));
544554de466SAvi Kivity 	report("bsfq r/m, reg", z == 1);
5452e16c7f6SWei Yongjun 
546554de466SAvi Kivity 	*memw = 0xc000;
547554de466SAvi Kivity 	asm("bsrw %[mem], %[a]" : [a]"=a"(ax) : [mem]"m"(*memw));
548554de466SAvi Kivity 	report("bsrw r/m, reg", ax == 15);
5492e16c7f6SWei Yongjun 
550554de466SAvi Kivity 	*meml = 0xc0000000;
551554de466SAvi Kivity 	asm("bsrl %[mem], %[a]" : [a]"=a"(eax) : [mem]"m"(*meml));
552554de466SAvi Kivity 	report("bsrl r/m, reg", eax == 31);
5532e16c7f6SWei Yongjun 
554554de466SAvi Kivity 	*memq = 0xc00000000000;
555554de466SAvi Kivity 	asm("bsrq %[mem], %[a]" : [a]"=a"(rax) : [mem]"m"(*memq));
5562e16c7f6SWei Yongjun 	report("bsrq r/m, reg", rax == 47);
5572e16c7f6SWei Yongjun 
558554de466SAvi Kivity 	*memq = 0;
559554de466SAvi Kivity 	asm("bsrq %[mem], %[a]; setz %[z]"
560554de466SAvi Kivity 	    : [a]"=a"(rax), [z]"=rm"(z) : [mem]"m"(*memq));
561554de466SAvi Kivity 	report("bsrq r/m, reg", z == 1);
5622e16c7f6SWei Yongjun }
5632e16c7f6SWei Yongjun 
56451d65a3cSAvi Kivity static void test_imul(ulong *mem)
56551d65a3cSAvi Kivity {
56651d65a3cSAvi Kivity     ulong a;
56751d65a3cSAvi Kivity 
56851d65a3cSAvi Kivity     *mem = 51; a = 0x1234567812345678UL;
56951d65a3cSAvi Kivity     asm ("imulw %1, %%ax" : "+a"(a) : "m"(*mem));
57051d65a3cSAvi Kivity     report("imul ax, mem", a == 0x12345678123439e8);
57151d65a3cSAvi Kivity 
57251d65a3cSAvi Kivity     *mem = 51; a = 0x1234567812345678UL;
57351d65a3cSAvi Kivity     asm ("imull %1, %%eax" : "+a"(a) : "m"(*mem));
57451d65a3cSAvi Kivity     report("imul eax, mem", a == 0xa06d39e8);
57551d65a3cSAvi Kivity 
57651d65a3cSAvi Kivity     *mem = 51; a = 0x1234567812345678UL;
57751d65a3cSAvi Kivity     asm ("imulq %1, %%rax" : "+a"(a) : "m"(*mem));
57851d65a3cSAvi Kivity     report("imul rax, mem", a == 0xA06D39EBA06D39E8UL);
57951d65a3cSAvi Kivity 
58051d65a3cSAvi Kivity     *mem  = 0x1234567812345678UL; a = 0x8765432187654321L;
58151d65a3cSAvi Kivity     asm ("imulw $51, %1, %%ax" : "+a"(a) : "m"(*mem));
58251d65a3cSAvi Kivity     report("imul ax, mem, imm8", a == 0x87654321876539e8);
58351d65a3cSAvi Kivity 
58451d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
58551d65a3cSAvi Kivity     asm ("imull $51, %1, %%eax" : "+a"(a) : "m"(*mem));
58651d65a3cSAvi Kivity     report("imul eax, mem, imm8", a == 0xa06d39e8);
58751d65a3cSAvi Kivity 
58851d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
58951d65a3cSAvi Kivity     asm ("imulq $51, %1, %%rax" : "+a"(a) : "m"(*mem));
59051d65a3cSAvi Kivity     report("imul rax, mem, imm8", a == 0xA06D39EBA06D39E8UL);
59151d65a3cSAvi Kivity 
59251d65a3cSAvi Kivity     *mem  = 0x1234567812345678UL; a = 0x8765432187654321L;
59351d65a3cSAvi Kivity     asm ("imulw $311, %1, %%ax" : "+a"(a) : "m"(*mem));
59451d65a3cSAvi Kivity     report("imul ax, mem, imm", a == 0x8765432187650bc8);
59551d65a3cSAvi Kivity 
59651d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
59751d65a3cSAvi Kivity     asm ("imull $311, %1, %%eax" : "+a"(a) : "m"(*mem));
59851d65a3cSAvi Kivity     report("imul eax, mem, imm", a == 0x1d950bc8);
59951d65a3cSAvi Kivity 
60051d65a3cSAvi Kivity     *mem = 0x1234567812345678UL;
60151d65a3cSAvi Kivity     asm ("imulq $311, %1, %%rax" : "+a"(a) : "m"(*mem));
60251d65a3cSAvi Kivity     report("imul rax, mem, imm", a == 0x1D950BDE1D950BC8L);
60351d65a3cSAvi Kivity }
60451d65a3cSAvi Kivity 
605c2c43fcfSAvi Kivity static void test_muldiv(long *mem)
606f12d86b0SAvi Kivity {
607c2c43fcfSAvi Kivity     long a, d, aa, dd;
608f12d86b0SAvi Kivity     u8 ex = 1;
609f12d86b0SAvi Kivity 
610f12d86b0SAvi Kivity     *mem = 0; a = 1; d = 2;
611f12d86b0SAvi Kivity     asm (ASM_TRY("1f") "divq %3; movb $0, %2; 1:"
612f12d86b0SAvi Kivity 	 : "+a"(a), "+d"(d), "+q"(ex) : "m"(*mem));
613f12d86b0SAvi Kivity     report("divq (fault)", a == 1 && d == 2 && ex);
614f12d86b0SAvi Kivity 
615f12d86b0SAvi Kivity     *mem = 987654321098765UL; a = 123456789012345UL; d = 123456789012345UL;
616f12d86b0SAvi Kivity     asm (ASM_TRY("1f") "divq %3; movb $0, %2; 1:"
617f12d86b0SAvi Kivity 	 : "+a"(a), "+d"(d), "+q"(ex) : "m"(*mem));
618f12d86b0SAvi Kivity     report("divq (1)",
619f12d86b0SAvi Kivity 	   a == 0x1ffffffb1b963b33ul && d == 0x273ba4384ede2ul && !ex);
620c2c43fcfSAvi Kivity     aa = 0x1111111111111111; dd = 0x2222222222222222;
621c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
622c2c43fcfSAvi Kivity     asm("mulb %2" : "+a"(a), "+d"(d) : "m"(*mem));
623c2c43fcfSAvi Kivity     report("mulb mem", a == 0x1111111111110363 && d == dd);
624c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
625c2c43fcfSAvi Kivity     asm("mulw %2" : "+a"(a), "+d"(d) : "m"(*mem));
626c2c43fcfSAvi Kivity     report("mulw mem", a == 0x111111111111c963 && d == 0x2222222222220369);
627c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
628c2c43fcfSAvi Kivity     asm("mull %2" : "+a"(a), "+d"(d) : "m"(*mem));
629c2c43fcfSAvi Kivity     report("mull mem", a == 0x962fc963 && d == 0x369d036);
630c2c43fcfSAvi Kivity     *mem = 0x3333333333333333; a = aa; d = dd;
631c2c43fcfSAvi Kivity     asm("mulq %2" : "+a"(a), "+d"(d) : "m"(*mem));
632c2c43fcfSAvi Kivity     report("mulq mem", a == 0x2fc962fc962fc963 && d == 0x369d0369d0369d0);
633f12d86b0SAvi Kivity }
634f12d86b0SAvi Kivity 
635d7f3ee3cSAvi Kivity typedef unsigned __attribute__((vector_size(16))) sse128;
636d7f3ee3cSAvi Kivity 
637d7f3ee3cSAvi Kivity typedef union {
638d7f3ee3cSAvi Kivity     sse128 sse;
639d7f3ee3cSAvi Kivity     unsigned u[4];
640d7f3ee3cSAvi Kivity } sse_union;
641d7f3ee3cSAvi Kivity 
642d7f3ee3cSAvi Kivity static bool sseeq(sse_union *v1, sse_union *v2)
643d7f3ee3cSAvi Kivity {
644d7f3ee3cSAvi Kivity     bool ok = true;
645d7f3ee3cSAvi Kivity     int i;
646d7f3ee3cSAvi Kivity 
647d7f3ee3cSAvi Kivity     for (i = 0; i < 4; ++i) {
648d7f3ee3cSAvi Kivity 	ok &= v1->u[i] == v2->u[i];
649d7f3ee3cSAvi Kivity     }
650d7f3ee3cSAvi Kivity 
651d7f3ee3cSAvi Kivity     return ok;
652d7f3ee3cSAvi Kivity }
653d7f3ee3cSAvi Kivity 
654d7f3ee3cSAvi Kivity static void test_sse(sse_union *mem)
655d7f3ee3cSAvi Kivity {
656d7f3ee3cSAvi Kivity     sse_union v;
657d7f3ee3cSAvi Kivity 
658d7f3ee3cSAvi Kivity     write_cr0(read_cr0() & ~6); /* EM, TS */
659d7f3ee3cSAvi Kivity     write_cr4(read_cr4() | 0x200); /* OSFXSR */
660d7f3ee3cSAvi Kivity     v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4;
661d7f3ee3cSAvi Kivity     asm("movdqu %1, %0" : "=m"(*mem) : "x"(v.sse));
662d7f3ee3cSAvi Kivity     report("movdqu (read)", sseeq(&v, mem));
663d7f3ee3cSAvi Kivity     mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8;
664d7f3ee3cSAvi Kivity     asm("movdqu %1, %0" : "=x"(v.sse) : "m"(*mem));
665d7f3ee3cSAvi Kivity     report("movdqu (write)", sseeq(mem, &v));
666290ed5d5SIgor Mammedov 
667290ed5d5SIgor Mammedov     v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4;
668290ed5d5SIgor Mammedov     asm("movaps %1, %0" : "=m"(*mem) : "x"(v.sse));
669290ed5d5SIgor Mammedov     report("movaps (read)", sseeq(mem, &v));
670290ed5d5SIgor Mammedov     mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8;
671290ed5d5SIgor Mammedov     asm("movaps %1, %0" : "=x"(v.sse) : "m"(*mem));
672290ed5d5SIgor Mammedov     report("movaps (write)", sseeq(&v, mem));
673f068a46aSIgor Mammedov 
674f068a46aSIgor Mammedov     v.u[0] = 1; v.u[1] = 2; v.u[2] = 3; v.u[3] = 4;
675f068a46aSIgor Mammedov     asm("movapd %1, %0" : "=m"(*mem) : "x"(v.sse));
676f068a46aSIgor Mammedov     report("movapd (read)", sseeq(mem, &v));
677f068a46aSIgor Mammedov     mem->u[0] = 5; mem->u[1] = 6; mem->u[2] = 7; mem->u[3] = 8;
678f068a46aSIgor Mammedov     asm("movapd %1, %0" : "=x"(v.sse) : "m"(*mem));
679f068a46aSIgor Mammedov     report("movapd (write)", sseeq(&v, mem));
680d7f3ee3cSAvi Kivity }
681d7f3ee3cSAvi Kivity 
6823587082bSAvi Kivity static void test_mmx(uint64_t *mem)
6833587082bSAvi Kivity {
6843587082bSAvi Kivity     uint64_t v;
6853587082bSAvi Kivity 
6863587082bSAvi Kivity     write_cr0(read_cr0() & ~6); /* EM, TS */
6873587082bSAvi Kivity     asm volatile("fninit");
6883587082bSAvi Kivity     v = 0x0102030405060708ULL;
6893587082bSAvi Kivity     asm("movq %1, %0" : "=m"(*mem) : "y"(v));
6903587082bSAvi Kivity     report("movq (mmx, read)", v == *mem);
6913587082bSAvi Kivity     *mem = 0x8070605040302010ull;
6923587082bSAvi Kivity     asm("movq %1, %0" : "=y"(v) : "m"(*mem));
6933587082bSAvi Kivity     report("movq (mmx, write)", v == *mem);
6943587082bSAvi Kivity }
6953587082bSAvi Kivity 
6968cfa5a06SAvi Kivity static void test_rip_relative(unsigned *mem, char *insn_ram)
6978cfa5a06SAvi Kivity {
6988cfa5a06SAvi Kivity     /* movb $1, mem+2(%rip) */
6998cfa5a06SAvi Kivity     insn_ram[0] = 0xc6;
7008cfa5a06SAvi Kivity     insn_ram[1] = 0x05;
7018cfa5a06SAvi Kivity     *(unsigned *)&insn_ram[2] = 2 + (char *)mem - (insn_ram + 7);
7028cfa5a06SAvi Kivity     insn_ram[6] = 0x01;
7038cfa5a06SAvi Kivity     /* ret */
7048cfa5a06SAvi Kivity     insn_ram[7] = 0xc3;
7058cfa5a06SAvi Kivity 
7068cfa5a06SAvi Kivity     *mem = 0;
7078cfa5a06SAvi Kivity     asm("callq *%1" : "+m"(*mem) : "r"(insn_ram));
708ce53c83bSPaolo Bonzini     report("movb $imm, 0(%%rip)", *mem == 0x10000);
7098cfa5a06SAvi Kivity }
710d7f3ee3cSAvi Kivity 
711b212fcdaSAvi Kivity static void test_shld_shrd(u32 *mem)
712b212fcdaSAvi Kivity {
713b212fcdaSAvi Kivity     *mem = 0x12345678;
714b212fcdaSAvi Kivity     asm("shld %2, %1, %0" : "+m"(*mem) : "r"(0xaaaaaaaaU), "c"((u8)3));
715b212fcdaSAvi Kivity     report("shld (cl)", *mem == ((0x12345678 << 3) | 5));
716b212fcdaSAvi Kivity     *mem = 0x12345678;
717b212fcdaSAvi Kivity     asm("shrd %2, %1, %0" : "+m"(*mem) : "r"(0x55555555U), "c"((u8)3));
718b212fcdaSAvi Kivity     report("shrd (cl)", *mem == ((0x12345678 >> 3) | (5u << 29)));
719b212fcdaSAvi Kivity }
720b212fcdaSAvi Kivity 
72130762176SNadav Amit static void test_cmov(u32 *mem)
72230762176SNadav Amit {
72330762176SNadav Amit 	u64 val;
72430762176SNadav Amit 	*mem = 0xabcdef12u;
72530762176SNadav Amit 	asm ("movq $0x1234567812345678, %%rax\n\t"
72630762176SNadav Amit 	     "cmpl %%eax, %%eax\n\t"
72730762176SNadav Amit 	     "cmovnel (%[mem]), %%eax\n\t"
72830762176SNadav Amit 	     "movq %%rax, %[val]\n\t"
72930762176SNadav Amit 	     : [val]"=r"(val) : [mem]"r"(mem) : "%rax", "cc");
73030762176SNadav Amit 	report("cmovnel", val == 0x12345678ul);
73130762176SNadav Amit }
73230762176SNadav Amit 
733c5a2a731SArthur Chunqi Li #define INSN_XCHG_ALL				\
734c5a2a731SArthur Chunqi Li 	"xchg %rax, 0+save \n\t"		\
735c5a2a731SArthur Chunqi Li 	"xchg %rbx, 8+save \n\t"		\
736c5a2a731SArthur Chunqi Li 	"xchg %rcx, 16+save \n\t"		\
737c5a2a731SArthur Chunqi Li 	"xchg %rdx, 24+save \n\t"		\
738c5a2a731SArthur Chunqi Li 	"xchg %rsi, 32+save \n\t"		\
739c5a2a731SArthur Chunqi Li 	"xchg %rdi, 40+save \n\t"		\
740c5a2a731SArthur Chunqi Li 	"xchg %rsp, 48+save \n\t"		\
741c5a2a731SArthur Chunqi Li 	"xchg %rbp, 56+save \n\t"		\
742c5a2a731SArthur Chunqi Li 	"xchg %r8, 64+save \n\t"		\
743c5a2a731SArthur Chunqi Li 	"xchg %r9, 72+save \n\t"		\
744c5a2a731SArthur Chunqi Li 	"xchg %r10, 80+save \n\t"		\
745c5a2a731SArthur Chunqi Li 	"xchg %r11, 88+save \n\t"		\
746c5a2a731SArthur Chunqi Li 	"xchg %r12, 96+save \n\t"		\
747c5a2a731SArthur Chunqi Li 	"xchg %r13, 104+save \n\t"		\
748c5a2a731SArthur Chunqi Li 	"xchg %r14, 112+save \n\t"		\
749c5a2a731SArthur Chunqi Li 	"xchg %r15, 120+save \n\t"
750c5a2a731SArthur Chunqi Li 
751c5a2a731SArthur Chunqi Li asm(
752c5a2a731SArthur Chunqi Li 	".align 4096\n\t"
753c5a2a731SArthur Chunqi Li 	"insn_page:\n\t"
754c5a2a731SArthur Chunqi Li 	"ret\n\t"
755c5a2a731SArthur Chunqi Li 	"pushf\n\t"
756c5a2a731SArthur Chunqi Li 	"push 136+save \n\t"
757c5a2a731SArthur Chunqi Li 	"popf \n\t"
758c5a2a731SArthur Chunqi Li 	INSN_XCHG_ALL
759c5a2a731SArthur Chunqi Li 	"test_insn:\n\t"
760c5a2a731SArthur Chunqi Li 	"in  (%dx),%al\n\t"
761c5a2a731SArthur Chunqi Li 	".skip 31, 0x90\n\t"
762c5a2a731SArthur Chunqi Li 	"test_insn_end:\n\t"
763c5a2a731SArthur Chunqi Li 	INSN_XCHG_ALL
764c5a2a731SArthur Chunqi Li 	"pushf \n\t"
765c5a2a731SArthur Chunqi Li 	"pop 136+save \n\t"
766c5a2a731SArthur Chunqi Li 	"popf \n\t"
767c5a2a731SArthur Chunqi Li 	"ret \n\t"
768c5a2a731SArthur Chunqi Li 	"insn_page_end:\n\t"
769c5a2a731SArthur Chunqi Li 	".align 4096\n\t"
770c5a2a731SArthur Chunqi Li );
771c5a2a731SArthur Chunqi Li 
772c5a2a731SArthur Chunqi Li #define MK_INSN(name, str)				\
773c5a2a731SArthur Chunqi Li     asm (						\
774c5a2a731SArthur Chunqi Li 	 ".pushsection .data.insn  \n\t"		\
775c5a2a731SArthur Chunqi Li 	 "insn_" #name ": \n\t"				\
776c5a2a731SArthur Chunqi Li 	 ".quad 1001f, 1002f - 1001f \n\t"		\
777c5a2a731SArthur Chunqi Li 	 ".popsection \n\t"				\
778c5a2a731SArthur Chunqi Li 	 ".pushsection .text.insn, \"ax\" \n\t"		\
779c5a2a731SArthur Chunqi Li 	 "1001: \n\t"					\
780c5a2a731SArthur Chunqi Li 	 "insn_code_" #name ": " str " \n\t"		\
781c5a2a731SArthur Chunqi Li 	 "1002: \n\t"					\
782c5a2a731SArthur Chunqi Li 	 ".popsection"					\
783c5a2a731SArthur Chunqi Li     );							\
784c5a2a731SArthur Chunqi Li     extern struct insn_desc insn_##name;
785c5a2a731SArthur Chunqi Li 
786c5a2a731SArthur Chunqi Li static void trap_emulator(uint64_t *mem, void *alt_insn_page,
787c5a2a731SArthur Chunqi Li 			struct insn_desc *alt_insn)
788c5a2a731SArthur Chunqi Li {
789c5a2a731SArthur Chunqi Li 	ulong *cr3 = (ulong *)read_cr3();
790c5a2a731SArthur Chunqi Li 	void *insn_ram;
791c5a2a731SArthur Chunqi Li 	extern u8 insn_page[], test_insn[];
792c5a2a731SArthur Chunqi Li 
793c5a2a731SArthur Chunqi Li 	insn_ram = vmap(virt_to_phys(insn_page), 4096);
794c5a2a731SArthur Chunqi Li 	memcpy(alt_insn_page, insn_page, 4096);
795c5a2a731SArthur Chunqi Li 	memcpy(alt_insn_page + (test_insn - insn_page),
796c5a2a731SArthur Chunqi Li 			(void *)(alt_insn->ptr), alt_insn->len);
797c5a2a731SArthur Chunqi Li 	save = inregs;
798c5a2a731SArthur Chunqi Li 
799c5a2a731SArthur Chunqi Li 	/* Load the code TLB with insn_page, but point the page tables at
800c5a2a731SArthur Chunqi Li 	   alt_insn_page (and keep the data TLB clear, for AMD decode assist).
801c5a2a731SArthur Chunqi Li 	   This will make the CPU trap on the insn_page instruction but the
802c5a2a731SArthur Chunqi Li 	   hypervisor will see alt_insn_page. */
803c5a2a731SArthur Chunqi Li 	install_page(cr3, virt_to_phys(insn_page), insn_ram);
804c5a2a731SArthur Chunqi Li 	invlpg(insn_ram);
805c5a2a731SArthur Chunqi Li 	/* Load code TLB */
806c5a2a731SArthur Chunqi Li 	asm volatile("call *%0" : : "r"(insn_ram));
807c5a2a731SArthur Chunqi Li 	install_page(cr3, virt_to_phys(alt_insn_page), insn_ram);
808c5a2a731SArthur Chunqi Li 	/* Trap, let hypervisor emulate at alt_insn_page */
809c5a2a731SArthur Chunqi Li 	asm volatile("call *%0": : "r"(insn_ram+1));
810c5a2a731SArthur Chunqi Li 
811c5a2a731SArthur Chunqi Li 	outregs = save;
812c5a2a731SArthur Chunqi Li }
813c5a2a731SArthur Chunqi Li 
814c2aa6128SPeter Feiner static unsigned long rip_advance;
815c2aa6128SPeter Feiner 
816c2aa6128SPeter Feiner static void advance_rip_and_note_exception(struct ex_regs *regs)
817d7143f32SAvi Kivity {
818d7143f32SAvi Kivity     ++exceptions;
819c2aa6128SPeter Feiner     regs->rip += rip_advance;
820d7143f32SAvi Kivity }
821d7143f32SAvi Kivity 
822d7143f32SAvi Kivity static void test_mmx_movq_mf(uint64_t *mem, uint8_t *insn_page,
823d7143f32SAvi Kivity 			     uint8_t *alt_insn_page, void *insn_ram)
824d7143f32SAvi Kivity {
8253af6fbbeSArthur Chunqi Li     uint16_t fcw = 0;  /* all exceptions unmasked */
8263af6fbbeSArthur Chunqi Li     /* movq %mm0, (%rax) */
8273af6fbbeSArthur Chunqi Li     void *stack = alloc_page();
828d7143f32SAvi Kivity 
8293af6fbbeSArthur Chunqi Li     write_cr0(read_cr0() & ~6);  /* TS, EM */
830d7143f32SAvi Kivity     exceptions = 0;
831c2aa6128SPeter Feiner     handle_exception(MF_VECTOR, advance_rip_and_note_exception);
832d7143f32SAvi Kivity     asm volatile("fninit; fldcw %0" : : "m"(fcw));
8333af6fbbeSArthur Chunqi Li     asm volatile("fldz; fldz; fdivp"); /* generate exception */
8343af6fbbeSArthur Chunqi Li 
8353af6fbbeSArthur Chunqi Li     MK_INSN(mmx_movq_mf, "movq %mm0, (%rax) \n\t");
836c2aa6128SPeter Feiner     rip_advance = insn_mmx_movq_mf.len;
8373af6fbbeSArthur Chunqi Li     inregs = (struct regs){ .rsp=(u64)stack+1024 };
8383af6fbbeSArthur Chunqi Li     trap_emulator(mem, alt_insn_page, &insn_mmx_movq_mf);
8393af6fbbeSArthur Chunqi Li     /* exit MMX mode */
840d7143f32SAvi Kivity     asm volatile("fnclex; emms");
841d7143f32SAvi Kivity     report("movq mmx generates #MF", exceptions == 1);
842d7143f32SAvi Kivity     handle_exception(MF_VECTOR, 0);
843d7143f32SAvi Kivity }
844d7143f32SAvi Kivity 
845f413c1afSNadav Amit static void test_jmp_noncanonical(uint64_t *mem)
846f413c1afSNadav Amit {
847c2aa6128SPeter Feiner 	extern char nc_jmp_start, nc_jmp_end;
848c2aa6128SPeter Feiner 
849f413c1afSNadav Amit 	*mem = 0x1111111111111111ul;
850f413c1afSNadav Amit 
851f413c1afSNadav Amit 	exceptions = 0;
852c2aa6128SPeter Feiner 	rip_advance = &nc_jmp_end - &nc_jmp_start;
853c2aa6128SPeter Feiner 	handle_exception(GP_VECTOR, advance_rip_and_note_exception);
854c2aa6128SPeter Feiner 	asm volatile ("nc_jmp_start: jmp *%0; nc_jmp_end:" : : "m"(*mem));
855f413c1afSNadav Amit 	report("jump to non-canonical address", exceptions == 1);
856f413c1afSNadav Amit 	handle_exception(GP_VECTOR, 0);
857f413c1afSNadav Amit }
858f413c1afSNadav Amit 
85959033f47SPaolo Bonzini static void test_movabs(uint64_t *mem, uint8_t *insn_page,
86059033f47SPaolo Bonzini 		       uint8_t *alt_insn_page, void *insn_ram)
86159033f47SPaolo Bonzini {
8623af6fbbeSArthur Chunqi Li     /* mov $0x9090909090909090, %rcx */
8633af6fbbeSArthur Chunqi Li     MK_INSN(movabs, "mov $0x9090909090909090, %rcx\n\t");
8643af6fbbeSArthur Chunqi Li     inregs = (struct regs){ 0 };
8653af6fbbeSArthur Chunqi Li     trap_emulator(mem, alt_insn_page, &insn_movabs);
8663af6fbbeSArthur Chunqi Li     report("64-bit mov imm2", outregs.rcx == 0x9090909090909090);
86759033f47SPaolo Bonzini }
86859033f47SPaolo Bonzini 
869313f4efeSNadav Amit static void test_smsw_reg(uint64_t *mem, uint8_t *insn_page,
870313f4efeSNadav Amit 		      uint8_t *alt_insn_page, void *insn_ram)
871313f4efeSNadav Amit {
872313f4efeSNadav Amit 	unsigned long cr0 = read_cr0();
873313f4efeSNadav Amit 	inregs = (struct regs){ .rax = 0x1234567890abcdeful };
874313f4efeSNadav Amit 
875313f4efeSNadav Amit 	MK_INSN(smsww, "smsww %ax\n\t");
876313f4efeSNadav Amit 	trap_emulator(mem, alt_insn_page, &insn_smsww);
877313f4efeSNadav Amit 	report("16-bit smsw reg", (u16)outregs.rax == (u16)cr0 &&
878313f4efeSNadav Amit 				  outregs.rax >> 16 == inregs.rax >> 16);
879313f4efeSNadav Amit 
880313f4efeSNadav Amit 	MK_INSN(smswl, "smswl %eax\n\t");
881313f4efeSNadav Amit 	trap_emulator(mem, alt_insn_page, &insn_smswl);
882313f4efeSNadav Amit 	report("32-bit smsw reg", outregs.rax == (u32)cr0);
883313f4efeSNadav Amit 
884313f4efeSNadav Amit 	MK_INSN(smswq, "smswq %rax\n\t");
885313f4efeSNadav Amit 	trap_emulator(mem, alt_insn_page, &insn_smswq);
886313f4efeSNadav Amit 	report("64-bit smsw reg", outregs.rax == cr0);
887313f4efeSNadav Amit }
888313f4efeSNadav Amit 
889ae399010SNadav Amit static void test_nop(uint64_t *mem, uint8_t *insn_page,
890ae399010SNadav Amit 		uint8_t *alt_insn_page, void *insn_ram)
891ae399010SNadav Amit {
892ae399010SNadav Amit 	inregs = (struct regs){ .rax = 0x1234567890abcdeful };
893ae399010SNadav Amit 	MK_INSN(nop, "nop\n\t");
894ae399010SNadav Amit 	trap_emulator(mem, alt_insn_page, &insn_nop);
895ae399010SNadav Amit 	report("nop", outregs.rax == inregs.rax);
896ae399010SNadav Amit }
897ae399010SNadav Amit 
898b39a3e14SNadav Amit static void test_mov_dr(uint64_t *mem, uint8_t *insn_page,
899b39a3e14SNadav Amit 		uint8_t *alt_insn_page, void *insn_ram)
900b39a3e14SNadav Amit {
901b39a3e14SNadav Amit 	bool rtm_support = cpuid(7).b & (1 << 11);
902b39a3e14SNadav Amit 	unsigned long dr6_fixed_1 = rtm_support ? 0xfffe0ff0ul : 0xffff0ff0ul;
903b39a3e14SNadav Amit 	inregs = (struct regs){ .rax = 0 };
904b39a3e14SNadav Amit 	MK_INSN(mov_to_dr6, "movq %rax, %dr6\n\t");
905b39a3e14SNadav Amit 	trap_emulator(mem, alt_insn_page, &insn_mov_to_dr6);
906b39a3e14SNadav Amit 	MK_INSN(mov_from_dr6, "movq %dr6, %rax\n\t");
907b39a3e14SNadav Amit 	trap_emulator(mem, alt_insn_page, &insn_mov_from_dr6);
908b39a3e14SNadav Amit 	report("mov_dr6", outregs.rax == dr6_fixed_1);
909b39a3e14SNadav Amit }
910b39a3e14SNadav Amit 
91126311ca9SNadav Amit static void test_push16(uint64_t *mem)
91226311ca9SNadav Amit {
91326311ca9SNadav Amit 	uint64_t rsp1, rsp2;
91426311ca9SNadav Amit 	uint16_t r;
91526311ca9SNadav Amit 
91626311ca9SNadav Amit 	asm volatile (	"movq %%rsp, %[rsp1]\n\t"
91726311ca9SNadav Amit 			"pushw %[v]\n\t"
91826311ca9SNadav Amit 			"popw %[r]\n\t"
91926311ca9SNadav Amit 			"movq %%rsp, %[rsp2]\n\t"
92026311ca9SNadav Amit 			"movq %[rsp1], %%rsp\n\t" :
92126311ca9SNadav Amit 			[rsp1]"=r"(rsp1), [rsp2]"=r"(rsp2), [r]"=r"(r)
92226311ca9SNadav Amit 			: [v]"m"(*mem) : "memory");
92326311ca9SNadav Amit 	report("push16", rsp1 == rsp2);
92426311ca9SNadav Amit }
92526311ca9SNadav Amit 
926ec278ce3SAvi Kivity static void test_crosspage_mmio(volatile uint8_t *mem)
927ec278ce3SAvi Kivity {
928ec278ce3SAvi Kivity     volatile uint16_t w, *pw;
929ec278ce3SAvi Kivity 
930ec278ce3SAvi Kivity     pw = (volatile uint16_t *)&mem[4095];
931ec278ce3SAvi Kivity     mem[4095] = 0x99;
932ec278ce3SAvi Kivity     mem[4096] = 0x77;
933ec278ce3SAvi Kivity     asm volatile("mov %1, %0" : "=r"(w) : "m"(*pw) : "memory");
934ec278ce3SAvi Kivity     report("cross-page mmio read", w == 0x7799);
935ec278ce3SAvi Kivity     asm volatile("mov %1, %0" : "=m"(*pw) : "r"((uint16_t)0x88aa));
936ec278ce3SAvi Kivity     report("cross-page mmio write", mem[4095] == 0xaa && mem[4096] == 0x88);
937ec278ce3SAvi Kivity }
938ec278ce3SAvi Kivity 
939a19c7db7SXiao Guangrong static void test_string_io_mmio(volatile uint8_t *mem)
940a19c7db7SXiao Guangrong {
941a19c7db7SXiao Guangrong 	/* Cross MMIO pages.*/
942a19c7db7SXiao Guangrong 	volatile uint8_t *mmio = mem + 4032;
943a19c7db7SXiao Guangrong 
944a19c7db7SXiao Guangrong 	asm volatile("outw %%ax, %%dx  \n\t" : : "a"(0x9999), "d"(TESTDEV_IO_PORT));
945a19c7db7SXiao Guangrong 
946a19c7db7SXiao Guangrong 	asm volatile ("cld; rep insb" : : "d" (TESTDEV_IO_PORT), "D" (mmio), "c" (1024));
947a19c7db7SXiao Guangrong 
948a19c7db7SXiao Guangrong 	report("string_io_mmio", mmio[1023] == 0x99);
949a19c7db7SXiao Guangrong }
950a19c7db7SXiao Guangrong 
95156c6afa7SJan Kiszka /* kvm doesn't allow lidt/lgdt from mmio, so the test is disabled */
95256c6afa7SJan Kiszka #if 0
95347c1461aSAvi Kivity static void test_lgdt_lidt(volatile uint8_t *mem)
95447c1461aSAvi Kivity {
95547c1461aSAvi Kivity     struct descriptor_table_ptr orig, fresh = {};
95647c1461aSAvi Kivity 
95747c1461aSAvi Kivity     sgdt(&orig);
95847c1461aSAvi Kivity     *(struct descriptor_table_ptr *)mem = (struct descriptor_table_ptr) {
95947c1461aSAvi Kivity 	.limit = 0xf234,
96047c1461aSAvi Kivity 	.base = 0x12345678abcd,
96147c1461aSAvi Kivity     };
96247c1461aSAvi Kivity     cli();
96347c1461aSAvi Kivity     asm volatile("lgdt %0" : : "m"(*(struct descriptor_table_ptr *)mem));
96447c1461aSAvi Kivity     sgdt(&fresh);
96547c1461aSAvi Kivity     lgdt(&orig);
96647c1461aSAvi Kivity     sti();
96747c1461aSAvi Kivity     report("lgdt (long address)", orig.limit == fresh.limit && orig.base == fresh.base);
96847c1461aSAvi Kivity 
96947c1461aSAvi Kivity     sidt(&orig);
97047c1461aSAvi Kivity     *(struct descriptor_table_ptr *)mem = (struct descriptor_table_ptr) {
97147c1461aSAvi Kivity 	.limit = 0x432f,
97247c1461aSAvi Kivity 	.base = 0xdbca87654321,
97347c1461aSAvi Kivity     };
97447c1461aSAvi Kivity     cli();
97547c1461aSAvi Kivity     asm volatile("lidt %0" : : "m"(*(struct descriptor_table_ptr *)mem));
97647c1461aSAvi Kivity     sidt(&fresh);
97747c1461aSAvi Kivity     lidt(&orig);
97847c1461aSAvi Kivity     sti();
97947c1461aSAvi Kivity     report("lidt (long address)", orig.limit == fresh.limit && orig.base == fresh.base);
98047c1461aSAvi Kivity }
98156c6afa7SJan Kiszka #endif
98247c1461aSAvi Kivity 
983fc2f880bSAvi Kivity static void ss_bad_rpl(struct ex_regs *regs)
984fc2f880bSAvi Kivity {
985fc2f880bSAvi Kivity     extern char ss_bad_rpl_cont;
986fc2f880bSAvi Kivity 
987fc2f880bSAvi Kivity     ++exceptions;
988fc2f880bSAvi Kivity     regs->rip = (ulong)&ss_bad_rpl_cont;
989fc2f880bSAvi Kivity }
990fc2f880bSAvi Kivity 
991fc2f880bSAvi Kivity static void test_sreg(volatile uint16_t *mem)
992fc2f880bSAvi Kivity {
993fc2f880bSAvi Kivity     u16 ss = read_ss();
994fc2f880bSAvi Kivity 
995fc2f880bSAvi Kivity     // check for null segment load
996fc2f880bSAvi Kivity     *mem = 0;
997fc2f880bSAvi Kivity     asm volatile("mov %0, %%ss" : : "m"(*mem));
998488b6ffbSPaolo Bonzini     report("mov null, %%ss", read_ss() == 0);
999fc2f880bSAvi Kivity 
1000fc2f880bSAvi Kivity     // check for exception when ss.rpl != cpl on null segment load
1001fc2f880bSAvi Kivity     exceptions = 0;
1002fc2f880bSAvi Kivity     handle_exception(GP_VECTOR, ss_bad_rpl);
1003fc2f880bSAvi Kivity     *mem = 3;
1004fc2f880bSAvi Kivity     asm volatile("mov %0, %%ss; ss_bad_rpl_cont:" : : "m"(*mem));
1005488b6ffbSPaolo Bonzini     report("mov null, %%ss (with ss.rpl != cpl)", exceptions == 1 && read_ss() == 0);
1006fc2f880bSAvi Kivity     handle_exception(GP_VECTOR, 0);
1007fc2f880bSAvi Kivity     write_ss(ss);
1008fc2f880bSAvi Kivity }
1009fc2f880bSAvi Kivity 
10104425dba6SPeter Feiner /* Broken emulation causes triple fault, which skips the other tests. */
10114425dba6SPeter Feiner #if 0
1012cb615a4dSAvi Kivity static void test_lldt(volatile uint16_t *mem)
1013cb615a4dSAvi Kivity {
10144425dba6SPeter Feiner     u64 gdt[] = { 0, /* null descriptor */
10154425dba6SPeter Feiner #ifdef __X86_64__
10164425dba6SPeter Feiner 		  0, /* ldt descriptor is 16 bytes in long mode */
10174425dba6SPeter Feiner #endif
10184425dba6SPeter Feiner 		  0x0000f82000000ffffull /* ldt descriptor */ };
10194425dba6SPeter Feiner     struct descriptor_table_ptr gdt_ptr = { .limit = sizeof(gdt) - 1,
10204425dba6SPeter Feiner 					    .base = (ulong)&gdt };
1021cb615a4dSAvi Kivity     struct descriptor_table_ptr orig_gdt;
1022cb615a4dSAvi Kivity 
1023cb615a4dSAvi Kivity     cli();
1024cb615a4dSAvi Kivity     sgdt(&orig_gdt);
1025cb615a4dSAvi Kivity     lgdt(&gdt_ptr);
1026cb615a4dSAvi Kivity     *mem = 0x8;
1027cb615a4dSAvi Kivity     asm volatile("lldt %0" : : "m"(*mem));
1028cb615a4dSAvi Kivity     lgdt(&orig_gdt);
1029cb615a4dSAvi Kivity     sti();
1030cb615a4dSAvi Kivity     report("lldt", sldt() == *mem);
1031cb615a4dSAvi Kivity }
10324425dba6SPeter Feiner #endif
1033cb615a4dSAvi Kivity 
103458a9d81eSAvi Kivity static void test_ltr(volatile uint16_t *mem)
103558a9d81eSAvi Kivity {
103658a9d81eSAvi Kivity     struct descriptor_table_ptr gdt_ptr;
103758a9d81eSAvi Kivity     uint64_t *gdt, *trp;
103858a9d81eSAvi Kivity     uint16_t tr = str();
103958a9d81eSAvi Kivity     uint64_t busy_mask = (uint64_t)1 << 41;
104058a9d81eSAvi Kivity 
104158a9d81eSAvi Kivity     sgdt(&gdt_ptr);
104258a9d81eSAvi Kivity     gdt = (uint64_t *)gdt_ptr.base;
104358a9d81eSAvi Kivity     trp = &gdt[tr >> 3];
104458a9d81eSAvi Kivity     *trp &= ~busy_mask;
104558a9d81eSAvi Kivity     *mem = tr;
104658a9d81eSAvi Kivity     asm volatile("ltr %0" : : "m"(*mem) : "memory");
104758a9d81eSAvi Kivity     report("ltr", str() == tr && (*trp & busy_mask));
104858a9d81eSAvi Kivity }
104958a9d81eSAvi Kivity 
10506cff92ddSAvi Kivity static void test_simplealu(u32 *mem)
10516cff92ddSAvi Kivity {
10526cff92ddSAvi Kivity     *mem = 0x1234;
10536cff92ddSAvi Kivity     asm("or %1, %0" : "+m"(*mem) : "r"(0x8001));
10546cff92ddSAvi Kivity     report("or", *mem == 0x9235);
10556cff92ddSAvi Kivity     asm("add %1, %0" : "+m"(*mem) : "r"(2));
10566cff92ddSAvi Kivity     report("add", *mem == 0x9237);
10576cff92ddSAvi Kivity     asm("xor %1, %0" : "+m"(*mem) : "r"(0x1111));
10586cff92ddSAvi Kivity     report("xor", *mem == 0x8326);
10596cff92ddSAvi Kivity     asm("sub %1, %0" : "+m"(*mem) : "r"(0x26));
10606cff92ddSAvi Kivity     report("sub", *mem == 0x8300);
10616cff92ddSAvi Kivity     asm("clc; adc %1, %0" : "+m"(*mem) : "r"(0x100));
10626cff92ddSAvi Kivity     report("adc(0)", *mem == 0x8400);
10636cff92ddSAvi Kivity     asm("stc; adc %1, %0" : "+m"(*mem) : "r"(0x100));
10646cff92ddSAvi Kivity     report("adc(0)", *mem == 0x8501);
10656cff92ddSAvi Kivity     asm("clc; sbb %1, %0" : "+m"(*mem) : "r"(0));
10666cff92ddSAvi Kivity     report("sbb(0)", *mem == 0x8501);
10676cff92ddSAvi Kivity     asm("stc; sbb %1, %0" : "+m"(*mem) : "r"(0));
10686cff92ddSAvi Kivity     report("sbb(1)", *mem == 0x8500);
10696cff92ddSAvi Kivity     asm("and %1, %0" : "+m"(*mem) : "r"(0xfe77));
10706cff92ddSAvi Kivity     report("and", *mem == 0x8400);
10716cff92ddSAvi Kivity     asm("test %1, %0" : "+m"(*mem) : "r"(0xf000));
10726cff92ddSAvi Kivity     report("test", *mem == 0x8400);
10736cff92ddSAvi Kivity }
10746cff92ddSAvi Kivity 
107570bdcadbSNadav Amit static void illegal_movbe_handler(struct ex_regs *regs)
107670bdcadbSNadav Amit {
107770bdcadbSNadav Amit 	extern char bad_movbe_cont;
107870bdcadbSNadav Amit 
107970bdcadbSNadav Amit 	++exceptions;
108070bdcadbSNadav Amit 	regs->rip = (ulong)&bad_movbe_cont;
108170bdcadbSNadav Amit }
108270bdcadbSNadav Amit 
108370bdcadbSNadav Amit static void test_illegal_movbe(void)
108470bdcadbSNadav Amit {
108570bdcadbSNadav Amit 	if (!(cpuid(1).c & (1 << 22))) {
108632b9603cSRadim Krčmář 		report_skip("illegal movbe");
108770bdcadbSNadav Amit 		return;
108870bdcadbSNadav Amit 	}
108970bdcadbSNadav Amit 
109070bdcadbSNadav Amit 	exceptions = 0;
109170bdcadbSNadav Amit 	handle_exception(UD_VECTOR, illegal_movbe_handler);
109270bdcadbSNadav Amit 	asm volatile(".byte 0x0f; .byte 0x38; .byte 0xf0; .byte 0xc0;\n\t"
109370bdcadbSNadav Amit 		     " bad_movbe_cont:" : : : "rax");
109470bdcadbSNadav Amit 	report("illegal movbe", exceptions == 1);
109570bdcadbSNadav Amit 	handle_exception(UD_VECTOR, 0);
109670bdcadbSNadav Amit }
109770bdcadbSNadav Amit 
10987d36db35SAvi Kivity int main()
10997d36db35SAvi Kivity {
11007d36db35SAvi Kivity 	void *mem;
1101d7143f32SAvi Kivity 	void *insn_page, *alt_insn_page;
11028cfa5a06SAvi Kivity 	void *insn_ram;
11037d36db35SAvi Kivity 	unsigned long t1, t2;
11047d36db35SAvi Kivity 
11057d36db35SAvi Kivity 	setup_vm();
1106a526e20dSAvi Kivity 	setup_idt();
1107ec278ce3SAvi Kivity 	mem = alloc_vpages(2);
1108ec278ce3SAvi Kivity 	install_page((void *)read_cr3(), IORAM_BASE_PHYS, mem);
1109ec278ce3SAvi Kivity 	// install the page twice to test cross-page mmio
1110ec278ce3SAvi Kivity 	install_page((void *)read_cr3(), IORAM_BASE_PHYS, mem + 4096);
1111d7143f32SAvi Kivity 	insn_page = alloc_page();
1112d7143f32SAvi Kivity 	alt_insn_page = alloc_page();
1113d7143f32SAvi Kivity 	insn_ram = vmap(virt_to_phys(insn_page), 4096);
11147d36db35SAvi Kivity 
11157d36db35SAvi Kivity 	// test mov reg, r/m and mov r/m, reg
11167d36db35SAvi Kivity 	t1 = 0x123456789abcdef;
11177d36db35SAvi Kivity 	asm volatile("mov %[t1], (%[mem]) \n\t"
11187d36db35SAvi Kivity 		     "mov (%[mem]), %[t2]"
11197d36db35SAvi Kivity 		     : [t2]"=r"(t2)
11207d36db35SAvi Kivity 		     : [t1]"r"(t1), [mem]"r"(mem)
11217d36db35SAvi Kivity 		     : "memory");
11227d36db35SAvi Kivity 	report("mov reg, r/m (1)", t2 == 0x123456789abcdef);
11237d36db35SAvi Kivity 
11246cff92ddSAvi Kivity 	test_simplealu(mem);
11257d36db35SAvi Kivity 	test_cmps(mem);
112680a4ea7bSAvi Kivity 	test_scas(mem);
11277d36db35SAvi Kivity 
11287d36db35SAvi Kivity 	test_push(mem);
11297d36db35SAvi Kivity 	test_pop(mem);
11307d36db35SAvi Kivity 
11317d36db35SAvi Kivity 	test_xchg(mem);
11325647d55cSWei Yongjun 	test_xadd(mem);
11337d36db35SAvi Kivity 
11347d36db35SAvi Kivity 	test_cr8();
11357d36db35SAvi Kivity 
11364003963dSNadav Amit 	test_smsw(mem);
11377d36db35SAvi Kivity 	test_lmsw();
11387d36db35SAvi Kivity 	test_ljmp(mem);
11397d36db35SAvi Kivity 	test_stringio();
11407d36db35SAvi Kivity 	test_incdecnotneg(mem);
1141d4655eafSWei Yongjun 	test_btc(mem);
11422e16c7f6SWei Yongjun 	test_bsfbsr(mem);
114351d65a3cSAvi Kivity 	test_imul(mem);
1144c2c43fcfSAvi Kivity 	test_muldiv(mem);
1145d7f3ee3cSAvi Kivity 	test_sse(mem);
11463587082bSAvi Kivity 	test_mmx(mem);
11478cfa5a06SAvi Kivity 	test_rip_relative(mem, insn_ram);
1148b212fcdaSAvi Kivity 	test_shld_shrd(mem);
114947c1461aSAvi Kivity 	//test_lgdt_lidt(mem);
1150fc2f880bSAvi Kivity 	test_sreg(mem);
11514425dba6SPeter Feiner 	//test_lldt(mem);
115258a9d81eSAvi Kivity 	test_ltr(mem);
115330762176SNadav Amit 	test_cmov(mem);
11547d36db35SAvi Kivity 
1155d7143f32SAvi Kivity 	test_mmx_movq_mf(mem, insn_page, alt_insn_page, insn_ram);
115659033f47SPaolo Bonzini 	test_movabs(mem, insn_page, alt_insn_page, insn_ram);
1157313f4efeSNadav Amit 	test_smsw_reg(mem, insn_page, alt_insn_page, insn_ram);
1158ae399010SNadav Amit 	test_nop(mem, insn_page, alt_insn_page, insn_ram);
1159b39a3e14SNadav Amit 	test_mov_dr(mem, insn_page, alt_insn_page, insn_ram);
116026311ca9SNadav Amit 	test_push16(mem);
1161ec278ce3SAvi Kivity 	test_crosspage_mmio(mem);
1162ec278ce3SAvi Kivity 
1163a19c7db7SXiao Guangrong 	test_string_io_mmio(mem);
1164a19c7db7SXiao Guangrong 
1165f413c1afSNadav Amit 	test_jmp_noncanonical(mem);
116670bdcadbSNadav Amit 	test_illegal_movbe();
1167f413c1afSNadav Amit 
1168f3cdd159SJan Kiszka 	return report_summary();
11697d36db35SAvi Kivity }
1170