1 #ifndef __SVM_H 2 #define __SVM_H 3 4 #include "libcflat.h" 5 6 enum { 7 INTERCEPT_INTR, 8 INTERCEPT_NMI, 9 INTERCEPT_SMI, 10 INTERCEPT_INIT, 11 INTERCEPT_VINTR, 12 INTERCEPT_SELECTIVE_CR0, 13 INTERCEPT_STORE_IDTR, 14 INTERCEPT_STORE_GDTR, 15 INTERCEPT_STORE_LDTR, 16 INTERCEPT_STORE_TR, 17 INTERCEPT_LOAD_IDTR, 18 INTERCEPT_LOAD_GDTR, 19 INTERCEPT_LOAD_LDTR, 20 INTERCEPT_LOAD_TR, 21 INTERCEPT_RDTSC, 22 INTERCEPT_RDPMC, 23 INTERCEPT_PUSHF, 24 INTERCEPT_POPF, 25 INTERCEPT_CPUID, 26 INTERCEPT_RSM, 27 INTERCEPT_IRET, 28 INTERCEPT_INTn, 29 INTERCEPT_INVD, 30 INTERCEPT_PAUSE, 31 INTERCEPT_HLT, 32 INTERCEPT_INVLPG, 33 INTERCEPT_INVLPGA, 34 INTERCEPT_IOIO_PROT, 35 INTERCEPT_MSR_PROT, 36 INTERCEPT_TASK_SWITCH, 37 INTERCEPT_FERR_FREEZE, 38 INTERCEPT_SHUTDOWN, 39 INTERCEPT_VMRUN, 40 INTERCEPT_VMMCALL, 41 INTERCEPT_VMLOAD, 42 INTERCEPT_VMSAVE, 43 INTERCEPT_STGI, 44 INTERCEPT_CLGI, 45 INTERCEPT_SKINIT, 46 INTERCEPT_RDTSCP, 47 INTERCEPT_ICEBP, 48 INTERCEPT_WBINVD, 49 INTERCEPT_MONITOR, 50 INTERCEPT_MWAIT, 51 INTERCEPT_MWAIT_COND, 52 }; 53 54 55 struct __attribute__ ((__packed__)) vmcb_control_area { 56 u16 intercept_cr_read; 57 u16 intercept_cr_write; 58 u16 intercept_dr_read; 59 u16 intercept_dr_write; 60 u32 intercept_exceptions; 61 u64 intercept; 62 u8 reserved_1[42]; 63 u16 pause_filter_count; 64 u64 iopm_base_pa; 65 u64 msrpm_base_pa; 66 u64 tsc_offset; 67 u32 asid; 68 u8 tlb_ctl; 69 u8 reserved_2[3]; 70 u32 int_ctl; 71 u32 int_vector; 72 u32 int_state; 73 u8 reserved_3[4]; 74 u32 exit_code; 75 u32 exit_code_hi; 76 u64 exit_info_1; 77 u64 exit_info_2; 78 u32 exit_int_info; 79 u32 exit_int_info_err; 80 u64 nested_ctl; 81 u8 reserved_4[16]; 82 u32 event_inj; 83 u32 event_inj_err; 84 u64 nested_cr3; 85 u64 lbr_ctl; 86 u64 reserved_5; 87 u64 next_rip; 88 u8 reserved_6[816]; 89 }; 90 91 92 #define TLB_CONTROL_DO_NOTHING 0 93 #define TLB_CONTROL_FLUSH_ALL_ASID 1 94 95 #define V_TPR_MASK 0x0f 96 97 #define V_IRQ_SHIFT 8 98 #define V_IRQ_MASK (1 << V_IRQ_SHIFT) 99 100 #define V_INTR_PRIO_SHIFT 16 101 #define V_INTR_PRIO_MASK (0x0f << V_INTR_PRIO_SHIFT) 102 103 #define V_IGN_TPR_SHIFT 20 104 #define V_IGN_TPR_MASK (1 << V_IGN_TPR_SHIFT) 105 106 #define V_INTR_MASKING_SHIFT 24 107 #define V_INTR_MASKING_MASK (1 << V_INTR_MASKING_SHIFT) 108 109 #define SVM_INTERRUPT_SHADOW_MASK 1 110 111 #define SVM_IOIO_STR_SHIFT 2 112 #define SVM_IOIO_REP_SHIFT 3 113 #define SVM_IOIO_SIZE_SHIFT 4 114 #define SVM_IOIO_ASIZE_SHIFT 7 115 116 #define SVM_IOIO_TYPE_MASK 1 117 #define SVM_IOIO_STR_MASK (1 << SVM_IOIO_STR_SHIFT) 118 #define SVM_IOIO_REP_MASK (1 << SVM_IOIO_REP_SHIFT) 119 #define SVM_IOIO_SIZE_MASK (7 << SVM_IOIO_SIZE_SHIFT) 120 #define SVM_IOIO_ASIZE_MASK (7 << SVM_IOIO_ASIZE_SHIFT) 121 122 #define SVM_VM_CR_VALID_MASK 0x001fULL 123 #define SVM_VM_CR_SVM_LOCK_MASK 0x0008ULL 124 #define SVM_VM_CR_SVM_DIS_MASK 0x0010ULL 125 126 struct __attribute__ ((__packed__)) vmcb_seg { 127 u16 selector; 128 u16 attrib; 129 u32 limit; 130 u64 base; 131 }; 132 133 struct __attribute__ ((__packed__)) vmcb_save_area { 134 struct vmcb_seg es; 135 struct vmcb_seg cs; 136 struct vmcb_seg ss; 137 struct vmcb_seg ds; 138 struct vmcb_seg fs; 139 struct vmcb_seg gs; 140 struct vmcb_seg gdtr; 141 struct vmcb_seg ldtr; 142 struct vmcb_seg idtr; 143 struct vmcb_seg tr; 144 u8 reserved_1[43]; 145 u8 cpl; 146 u8 reserved_2[4]; 147 u64 efer; 148 u8 reserved_3[112]; 149 u64 cr4; 150 u64 cr3; 151 u64 cr0; 152 u64 dr7; 153 u64 dr6; 154 u64 rflags; 155 u64 rip; 156 u8 reserved_4[88]; 157 u64 rsp; 158 u8 reserved_5[24]; 159 u64 rax; 160 u64 star; 161 u64 lstar; 162 u64 cstar; 163 u64 sfmask; 164 u64 kernel_gs_base; 165 u64 sysenter_cs; 166 u64 sysenter_esp; 167 u64 sysenter_eip; 168 u64 cr2; 169 u8 reserved_6[32]; 170 u64 g_pat; 171 u64 dbgctl; 172 u64 br_from; 173 u64 br_to; 174 u64 last_excp_from; 175 u64 last_excp_to; 176 }; 177 178 struct __attribute__ ((__packed__)) vmcb { 179 struct vmcb_control_area control; 180 struct vmcb_save_area save; 181 }; 182 183 #define SVM_CPUID_FEATURE_SHIFT 2 184 #define SVM_CPUID_FUNC 0x8000000a 185 186 #define SVM_VM_CR_SVM_DISABLE 4 187 188 #define SVM_SELECTOR_S_SHIFT 4 189 #define SVM_SELECTOR_DPL_SHIFT 5 190 #define SVM_SELECTOR_P_SHIFT 7 191 #define SVM_SELECTOR_AVL_SHIFT 8 192 #define SVM_SELECTOR_L_SHIFT 9 193 #define SVM_SELECTOR_DB_SHIFT 10 194 #define SVM_SELECTOR_G_SHIFT 11 195 196 #define SVM_SELECTOR_TYPE_MASK (0xf) 197 #define SVM_SELECTOR_S_MASK (1 << SVM_SELECTOR_S_SHIFT) 198 #define SVM_SELECTOR_DPL_MASK (3 << SVM_SELECTOR_DPL_SHIFT) 199 #define SVM_SELECTOR_P_MASK (1 << SVM_SELECTOR_P_SHIFT) 200 #define SVM_SELECTOR_AVL_MASK (1 << SVM_SELECTOR_AVL_SHIFT) 201 #define SVM_SELECTOR_L_MASK (1 << SVM_SELECTOR_L_SHIFT) 202 #define SVM_SELECTOR_DB_MASK (1 << SVM_SELECTOR_DB_SHIFT) 203 #define SVM_SELECTOR_G_MASK (1 << SVM_SELECTOR_G_SHIFT) 204 205 #define SVM_SELECTOR_WRITE_MASK (1 << 1) 206 #define SVM_SELECTOR_READ_MASK SVM_SELECTOR_WRITE_MASK 207 #define SVM_SELECTOR_CODE_MASK (1 << 3) 208 209 #define INTERCEPT_CR0_MASK 1 210 #define INTERCEPT_CR3_MASK (1 << 3) 211 #define INTERCEPT_CR4_MASK (1 << 4) 212 #define INTERCEPT_CR8_MASK (1 << 8) 213 214 #define INTERCEPT_DR0_MASK 1 215 #define INTERCEPT_DR1_MASK (1 << 1) 216 #define INTERCEPT_DR2_MASK (1 << 2) 217 #define INTERCEPT_DR3_MASK (1 << 3) 218 #define INTERCEPT_DR4_MASK (1 << 4) 219 #define INTERCEPT_DR5_MASK (1 << 5) 220 #define INTERCEPT_DR6_MASK (1 << 6) 221 #define INTERCEPT_DR7_MASK (1 << 7) 222 223 #define SVM_EVTINJ_VEC_MASK 0xff 224 225 #define SVM_EVTINJ_TYPE_SHIFT 8 226 #define SVM_EVTINJ_TYPE_MASK (7 << SVM_EVTINJ_TYPE_SHIFT) 227 228 #define SVM_EVTINJ_TYPE_INTR (0 << SVM_EVTINJ_TYPE_SHIFT) 229 #define SVM_EVTINJ_TYPE_NMI (2 << SVM_EVTINJ_TYPE_SHIFT) 230 #define SVM_EVTINJ_TYPE_EXEPT (3 << SVM_EVTINJ_TYPE_SHIFT) 231 #define SVM_EVTINJ_TYPE_SOFT (4 << SVM_EVTINJ_TYPE_SHIFT) 232 233 #define SVM_EVTINJ_VALID (1 << 31) 234 #define SVM_EVTINJ_VALID_ERR (1 << 11) 235 236 #define SVM_EXITINTINFO_VEC_MASK SVM_EVTINJ_VEC_MASK 237 #define SVM_EXITINTINFO_TYPE_MASK SVM_EVTINJ_TYPE_MASK 238 239 #define SVM_EXITINTINFO_TYPE_INTR SVM_EVTINJ_TYPE_INTR 240 #define SVM_EXITINTINFO_TYPE_NMI SVM_EVTINJ_TYPE_NMI 241 #define SVM_EXITINTINFO_TYPE_EXEPT SVM_EVTINJ_TYPE_EXEPT 242 #define SVM_EXITINTINFO_TYPE_SOFT SVM_EVTINJ_TYPE_SOFT 243 244 #define SVM_EXITINTINFO_VALID SVM_EVTINJ_VALID 245 #define SVM_EXITINTINFO_VALID_ERR SVM_EVTINJ_VALID_ERR 246 247 #define SVM_EXITINFOSHIFT_TS_REASON_IRET 36 248 #define SVM_EXITINFOSHIFT_TS_REASON_JMP 38 249 #define SVM_EXITINFOSHIFT_TS_HAS_ERROR_CODE 44 250 251 #define SVM_EXIT_READ_CR0 0x000 252 #define SVM_EXIT_READ_CR3 0x003 253 #define SVM_EXIT_READ_CR4 0x004 254 #define SVM_EXIT_READ_CR8 0x008 255 #define SVM_EXIT_WRITE_CR0 0x010 256 #define SVM_EXIT_WRITE_CR3 0x013 257 #define SVM_EXIT_WRITE_CR4 0x014 258 #define SVM_EXIT_WRITE_CR8 0x018 259 #define SVM_EXIT_READ_DR0 0x020 260 #define SVM_EXIT_READ_DR1 0x021 261 #define SVM_EXIT_READ_DR2 0x022 262 #define SVM_EXIT_READ_DR3 0x023 263 #define SVM_EXIT_READ_DR4 0x024 264 #define SVM_EXIT_READ_DR5 0x025 265 #define SVM_EXIT_READ_DR6 0x026 266 #define SVM_EXIT_READ_DR7 0x027 267 #define SVM_EXIT_WRITE_DR0 0x030 268 #define SVM_EXIT_WRITE_DR1 0x031 269 #define SVM_EXIT_WRITE_DR2 0x032 270 #define SVM_EXIT_WRITE_DR3 0x033 271 #define SVM_EXIT_WRITE_DR4 0x034 272 #define SVM_EXIT_WRITE_DR5 0x035 273 #define SVM_EXIT_WRITE_DR6 0x036 274 #define SVM_EXIT_WRITE_DR7 0x037 275 #define SVM_EXIT_EXCP_BASE 0x040 276 #define SVM_EXIT_INTR 0x060 277 #define SVM_EXIT_NMI 0x061 278 #define SVM_EXIT_SMI 0x062 279 #define SVM_EXIT_INIT 0x063 280 #define SVM_EXIT_VINTR 0x064 281 #define SVM_EXIT_CR0_SEL_WRITE 0x065 282 #define SVM_EXIT_IDTR_READ 0x066 283 #define SVM_EXIT_GDTR_READ 0x067 284 #define SVM_EXIT_LDTR_READ 0x068 285 #define SVM_EXIT_TR_READ 0x069 286 #define SVM_EXIT_IDTR_WRITE 0x06a 287 #define SVM_EXIT_GDTR_WRITE 0x06b 288 #define SVM_EXIT_LDTR_WRITE 0x06c 289 #define SVM_EXIT_TR_WRITE 0x06d 290 #define SVM_EXIT_RDTSC 0x06e 291 #define SVM_EXIT_RDPMC 0x06f 292 #define SVM_EXIT_PUSHF 0x070 293 #define SVM_EXIT_POPF 0x071 294 #define SVM_EXIT_CPUID 0x072 295 #define SVM_EXIT_RSM 0x073 296 #define SVM_EXIT_IRET 0x074 297 #define SVM_EXIT_SWINT 0x075 298 #define SVM_EXIT_INVD 0x076 299 #define SVM_EXIT_PAUSE 0x077 300 #define SVM_EXIT_HLT 0x078 301 #define SVM_EXIT_INVLPG 0x079 302 #define SVM_EXIT_INVLPGA 0x07a 303 #define SVM_EXIT_IOIO 0x07b 304 #define SVM_EXIT_MSR 0x07c 305 #define SVM_EXIT_TASK_SWITCH 0x07d 306 #define SVM_EXIT_FERR_FREEZE 0x07e 307 #define SVM_EXIT_SHUTDOWN 0x07f 308 #define SVM_EXIT_VMRUN 0x080 309 #define SVM_EXIT_VMMCALL 0x081 310 #define SVM_EXIT_VMLOAD 0x082 311 #define SVM_EXIT_VMSAVE 0x083 312 #define SVM_EXIT_STGI 0x084 313 #define SVM_EXIT_CLGI 0x085 314 #define SVM_EXIT_SKINIT 0x086 315 #define SVM_EXIT_RDTSCP 0x087 316 #define SVM_EXIT_ICEBP 0x088 317 #define SVM_EXIT_WBINVD 0x089 318 #define SVM_EXIT_MONITOR 0x08a 319 #define SVM_EXIT_MWAIT 0x08b 320 #define SVM_EXIT_MWAIT_COND 0x08c 321 #define SVM_EXIT_NPF 0x400 322 323 #define SVM_EXIT_ERR -1 324 325 #define SVM_CR0_SELECTIVE_MASK (X86_CR0_TS | X86_CR0_MP) 326 327 #define SVM_CR0_RESERVED_MASK 0xffffffff00000000U 328 #define SVM_CR3_LONG_RESERVED_MASK 0xfff0000000000000U 329 #define SVM_CR4_LEGACY_RESERVED_MASK 0xff88f000U 330 #define SVM_CR4_RESERVED_MASK 0xffffffffff88f000U 331 #define SVM_DR6_RESERVED_MASK 0xffffffffffff1ff0U 332 #define SVM_DR7_RESERVED_MASK 0xffffffff0000cc00U 333 #define SVM_EFER_RESERVED_MASK 0xffffffffffff0200U 334 335 #define MSR_BITMAP_SIZE 8192 336 337 struct svm_test { 338 const char *name; 339 bool (*supported)(void); 340 void (*prepare)(struct svm_test *test); 341 void (*prepare_gif_clear)(struct svm_test *test); 342 void (*guest_func)(struct svm_test *test); 343 bool (*finished)(struct svm_test *test); 344 bool (*succeeded)(struct svm_test *test); 345 int exits; 346 ulong scratch; 347 /* Alternative test interface. */ 348 void (*v2)(void); 349 }; 350 351 struct regs { 352 u64 rax; 353 u64 rbx; 354 u64 rcx; 355 u64 rdx; 356 u64 cr2; 357 u64 rbp; 358 u64 rsi; 359 u64 rdi; 360 u64 r8; 361 u64 r9; 362 u64 r10; 363 u64 r11; 364 u64 r12; 365 u64 r13; 366 u64 r14; 367 u64 r15; 368 u64 rflags; 369 }; 370 371 typedef void (*test_guest_func)(struct svm_test *); 372 373 u64 *npt_get_pte(u64 address); 374 u64 *npt_get_pde(u64 address); 375 u64 *npt_get_pdpe(void); 376 u64 *npt_get_pml4e(void); 377 bool smp_supported(void); 378 bool default_supported(void); 379 void default_prepare(struct svm_test *test); 380 void default_prepare_gif_clear(struct svm_test *test); 381 bool default_finished(struct svm_test *test); 382 bool npt_supported(void); 383 int get_test_stage(struct svm_test *test); 384 void set_test_stage(struct svm_test *test, int s); 385 void inc_test_stage(struct svm_test *test); 386 void vmcb_ident(struct vmcb *vmcb); 387 struct regs get_regs(void); 388 void vmmcall(void); 389 int svm_vmrun(void); 390 void test_set_guest(test_guest_func func); 391 392 extern struct vmcb *vmcb; 393 extern struct svm_test svm_tests[]; 394 395 #endif 396