VirtualBox

source: vbox/trunk/src/VBox/VMM/VMMAll/TRPMAll.cpp@ 2018

Last change on this file since 2018 was 1976, checked in by vboxsync, 18 years ago

Never inject interrupts or traps before we sync the GDT/IDT/LDT and TSS.

  • Property svn:eol-style set to native
  • Property svn:keywords set to Id
File size: 32.0 KB
Line 
1/* $Id: TRPMAll.cpp 1976 2007-04-06 16:55:59Z vboxsync $ */
2/** @file
3 * TRPM - Trap Monitor - Any Context.
4 */
5
6/*
7 * Copyright (C) 2006 InnoTek Systemberatung GmbH
8 *
9 * This file is part of VirtualBox Open Source Edition (OSE), as
10 * available from http://www.virtualbox.org. This file is free software;
11 * you can redistribute it and/or modify it under the terms of the GNU
12 * General Public License as published by the Free Software Foundation,
13 * in version 2 as it comes in the "COPYING" file of the VirtualBox OSE
14 * distribution. VirtualBox OSE is distributed in the hope that it will
15 * be useful, but WITHOUT ANY WARRANTY of any kind.
16 *
17 * If you received this file as part of a commercial VirtualBox
18 * distribution, then only the terms of your commercial VirtualBox
19 * license agreement apply instead of the previous paragraph.
20 */
21
22
23/*******************************************************************************
24* Header Files *
25*******************************************************************************/
26#define LOG_GROUP LOG_GROUP_TRPM
27#include <VBox/trpm.h>
28#include <VBox/pgm.h>
29#include <VBox/mm.h>
30#include <VBox/patm.h>
31#include <VBox/selm.h>
32#include "TRPMInternal.h"
33#include <VBox/vm.h>
34#include <VBox/err.h>
35#include <VBox/x86.h>
36#include <VBox/em.h>
37
38#include <VBox/log.h>
39#include <iprt/assert.h>
40#include <iprt/asm.h>
41#include <iprt/param.h>
42
43
44
45/**
46 * Query info about the current active trap/interrupt.
47 * If no trap is active active an error code is returned.
48 *
49 * @returns VBox status code.
50 * @param pVM The virtual machine.
51 * @param pu8TrapNo Where to store the trap number.
52 * @param pfSoftwareInterrupt Where to store the software interrupt indicator.
53 */
54TRPMDECL(int) TRPMQueryTrap(PVM pVM, uint8_t *pu8TrapNo, bool *pfSoftwareInterrupt)
55{
56 /*
57 * Check if we have a trap at present.
58 */
59 if (pVM->trpm.s.uActiveVector != ~0U)
60 {
61 if (pu8TrapNo)
62 *pu8TrapNo = (uint8_t)pVM->trpm.s.uActiveVector;
63 if (pfSoftwareInterrupt)
64 *pfSoftwareInterrupt = !!pVM->trpm.s.fActiveSoftwareInterrupt;
65 return VINF_SUCCESS;
66 }
67
68 return VERR_TRPM_NO_ACTIVE_TRAP;
69}
70
71
72/**
73 * Gets the trap number for the current trap.
74 *
75 * The caller is responsible for making sure there is an active trap which
76 * takes an error code when making this request.
77 *
78 * @returns The current trap number.
79 * @param pVM VM handle.
80 */
81TRPMDECL(uint8_t) TRPMGetTrapNo(PVM pVM)
82{
83 AssertMsg(pVM->trpm.s.uActiveVector != ~0U, ("No active trap!\n"));
84 return (uint8_t)pVM->trpm.s.uActiveVector;
85}
86
87
88/**
89 * Gets the error code for the current trap.
90 *
91 * The caller is responsible for making sure there is an active trap which
92 * takes an error code when making this request.
93 *
94 * @returns Error code.
95 * @param pVM VM handle.
96 */
97TRPMDECL(RTGCUINT) TRPMGetErrorCode(PVM pVM)
98{
99 AssertMsg(pVM->trpm.s.uActiveVector != ~0U, ("No active trap!\n"));
100#ifdef VBOX_STRICT
101 switch (pVM->trpm.s.uActiveVector)
102 {
103 case 0x0a:
104 case 0x0b:
105 case 0x0c:
106 case 0x0d:
107 case 0x0e:
108 case 0x11:
109 case 0x08:
110 break;
111 default:
112 AssertMsgFailed(("This trap (%#x) doesn't have any error code\n", pVM->trpm.s.uActiveVector));
113 break;
114 }
115#endif
116 return pVM->trpm.s.uActiveErrorCode;
117}
118
119
120/**
121 * Gets the fault address for the current trap.
122 *
123 * The caller is responsible for making sure there is an active trap 0x0e when
124 * making this request.
125 *
126 * @returns Fault address associated with the trap.
127 * @param pVM VM handle.
128 */
129TRPMDECL(RTGCUINTPTR) TRPMGetFaultAddress(PVM pVM)
130{
131 AssertMsg(pVM->trpm.s.uActiveVector != ~0U, ("No active trap!\n"));
132 AssertMsg(pVM->trpm.s.uActiveVector == 0xe, ("Not trap 0e!\n"));
133 return pVM->trpm.s.uActiveCR2;
134}
135
136
137/**
138 * Clears the current active trap/exception/interrupt.
139 *
140 * The caller is responsible for making sure there is an active trap
141 * when making this request.
142 *
143 * @returns VBox status code.
144 * @param pVM The virtual machine handle.
145 */
146TRPMDECL(int) TRPMResetTrap(PVM pVM)
147{
148 /*
149 * Cannot reset non-existing trap!
150 */
151 if (pVM->trpm.s.uActiveVector == ~0U)
152 {
153 AssertMsgFailed(("No active trap!\n"));
154 return VERR_TRPM_NO_ACTIVE_TRAP;
155 }
156
157 /*
158 * Reset it.
159 */
160 pVM->trpm.s.uActiveVector = ~0U;
161 return VINF_SUCCESS;
162}
163
164
165/**
166 * Assert trap/exception/interrupt.
167 *
168 * The caller is responsible for making sure there is no active trap
169 * when making this request.
170 *
171 * @returns VBox status code.
172 * @param pVM The virtual machine.
173 * @param u8TrapNo The trap vector to assert.
174 * @param fSoftwareInterrupt Indicate if it's a software interrupt or not.
175 */
176TRPMDECL(int) TRPMAssertTrap(PVM pVM, uint8_t u8TrapNo, bool fSoftwareInterrupt)
177{
178 Log2(("TRPMAssertTrap: u8TrapNo=%02x fSoftwareInterrupt=%d\n", u8TrapNo, fSoftwareInterrupt));
179
180 /*
181 * Cannot assert a trap when one is already active.
182 */
183 if (pVM->trpm.s.uActiveVector != ~0U)
184 {
185 AssertMsgFailed(("Active trap %#x\n", pVM->trpm.s.uActiveVector));
186 return VERR_TRPM_ACTIVE_TRAP;
187 }
188
189 pVM->trpm.s.uActiveVector = u8TrapNo;
190 pVM->trpm.s.fActiveSoftwareInterrupt = fSoftwareInterrupt;
191 pVM->trpm.s.uActiveErrorCode = ~0;
192 pVM->trpm.s.uActiveCR2 = 0xdeadface;
193 return VINF_SUCCESS;
194}
195
196
197/**
198 * Sets the error code of the current trap.
199 * (This function is for use in trap handlers and such.)
200 *
201 * The caller is responsible for making sure there is an active trap
202 * which takes an errorcode when making this request.
203 *
204 * @param pVM The virtual machine.
205 * @param uErrorCode The new error code.
206 */
207TRPMDECL(void) TRPMSetErrorCode(PVM pVM, RTGCUINT uErrorCode)
208{
209 Log2(("TRPMSetErrorCode: uErrorCode=%VGv\n", uErrorCode));
210 AssertMsg(pVM->trpm.s.uActiveVector != ~0U, ("No active trap!\n"));
211 pVM->trpm.s.uActiveErrorCode = uErrorCode;
212#ifdef VBOX_STRICT
213 switch (pVM->trpm.s.uActiveVector)
214 {
215 case 0x0a: case 0x0b: case 0x0c: case 0x0d: case 0x0e:
216 AssertMsg(uErrorCode != ~(RTGCUINT)0, ("Invalid uErrorCode=%#x u8TrapNo=%d\n", uErrorCode, pVM->trpm.s.uActiveVector));
217 break;
218 case 0x11: case 0x08:
219 AssertMsg(uErrorCode == 0, ("Invalid uErrorCode=%#x u8TrapNo=%d\n", uErrorCode, pVM->trpm.s.uActiveVector));
220 break;
221 default:
222 AssertMsg(uErrorCode == ~(RTGCUINT)0, ("Invalid uErrorCode=%#x u8TrapNo=%d\n", uErrorCode, pVM->trpm.s.uActiveVector));
223 break;
224 }
225#endif
226}
227
228
229/**
230 * Sets the error code of the current trap.
231 * (This function is for use in trap handlers and such.)
232 *
233 * The caller is responsible for making sure there is an active trap 0e
234 * when making this request.
235 *
236 * @param pVM The virtual machine.
237 * @param uCR2 The new fault address (cr2 register).
238 */
239TRPMDECL(void) TRPMSetFaultAddress(PVM pVM, RTGCUINTPTR uCR2)
240{
241 Log2(("TRPMSetFaultAddress: uCR2=%VGv\n", uCR2));
242 AssertMsg(pVM->trpm.s.uActiveVector != ~0U, ("No active trap!\n"));
243 AssertMsg(pVM->trpm.s.uActiveVector == 0xe, ("Not trap 0e!\n"));
244 pVM->trpm.s.uActiveCR2 = uCR2;
245}
246
247
248/**
249 * Checks if the current active trap/interrupt/exception/fault/whatever is a software
250 * interrupt or not.
251 *
252 * The caller is responsible for making sure there is an active trap
253 * when making this request.
254 *
255 * @returns true if software interrupt, false if not.
256 *
257 * @param pVM VM handle.
258 */
259TRPMDECL(bool) TRPMIsSoftwareInterrupt(PVM pVM)
260{
261 AssertMsg(pVM->trpm.s.uActiveVector != ~0U, ("No active trap!\n"));
262 return !!pVM->trpm.s.fActiveSoftwareInterrupt;
263}
264
265
266/**
267 * Check if there is an active trap.
268 *
269 * @returns true if trap active, false if not.
270 * @param pVM The virtual machine.
271 */
272TRPMDECL(bool) TRPMHasTrap(PVM pVM)
273{
274 return pVM->trpm.s.uActiveVector != ~0U;
275}
276
277
278/**
279 * Query all info about the current active trap/interrupt.
280 * If no trap is active active an error code is returned.
281 *
282 * @returns VBox status code.
283 * @param pVM The virtual machine.
284 * @param pu8TrapNo Where to store the trap number.
285 * @param pfSoftwareInterrupt Where to store the software interrupt indicator.
286 * @param puErrorCode Where to store the error code associated with some traps.
287 * ~0U is stored if the trap has no error code.
288 * @param puCR2 Where to store the CR2 associated with a trap 0E.
289 */
290TRPMDECL(int) TRPMQueryTrapAll(PVM pVM, uint8_t *pu8TrapNo, bool *pfSoftwareInterrupt, PRTGCUINT puErrorCode, PRTGCUINTPTR puCR2)
291{
292 /*
293 * Check if we have a trap at present.
294 */
295 if (pVM->trpm.s.uActiveVector == ~0U)
296 return VERR_TRPM_NO_ACTIVE_TRAP;
297
298 if (pu8TrapNo)
299 *pu8TrapNo = (uint8_t)pVM->trpm.s.uActiveVector;
300 if (pfSoftwareInterrupt)
301 *pfSoftwareInterrupt = !!pVM->trpm.s.fActiveSoftwareInterrupt;
302 if (puErrorCode)
303 *puErrorCode = pVM->trpm.s.uActiveErrorCode;
304 if (puCR2)
305 *puCR2 = pVM->trpm.s.uActiveCR2;
306
307 return VINF_SUCCESS;
308}
309
310
311/**
312 * Save the active trap.
313 *
314 * This routine useful when doing try/catch in the hypervisor.
315 * Any function which uses temporary trap handlers should
316 * probably also use this facility to save the original trap.
317 *
318 * @param pVM VM handle.
319 */
320TRPMDECL(void) TRPMSaveTrap(PVM pVM)
321{
322 pVM->trpm.s.uSavedVector = pVM->trpm.s.uActiveVector;
323 pVM->trpm.s.fSavedSoftwareInterrupt = pVM->trpm.s.fActiveSoftwareInterrupt;
324 pVM->trpm.s.uSavedErrorCode = pVM->trpm.s.uActiveErrorCode;
325 pVM->trpm.s.uSavedCR2 = pVM->trpm.s.uActiveCR2;
326}
327
328
329/**
330 * Restore a saved trap.
331 *
332 * Multiple restores of a saved trap is possible.
333 *
334 * @param pVM VM handle.
335 */
336TRPMDECL(void) TRPMRestoreTrap(PVM pVM)
337{
338 pVM->trpm.s.uActiveVector = pVM->trpm.s.uSavedVector;
339 pVM->trpm.s.fActiveSoftwareInterrupt = pVM->trpm.s.fSavedSoftwareInterrupt;
340 pVM->trpm.s.uActiveErrorCode = pVM->trpm.s.uSavedErrorCode;
341 pVM->trpm.s.uActiveCR2 = pVM->trpm.s.uSavedCR2;
342}
343
344
345/**
346 * Forward trap or interrupt to the guest's handler
347 *
348 *
349 * @returns VBox status code.
350 * or does not return at all (when the trap is actually forwarded)
351 *
352 * @param pVM The VM to operate on.
353 * @param pRegFrame Pointer to the register frame for the trap.
354 * @param iGate Trap or interrupt gate number
355 * @param opsize Instruction size (only relevant for software interrupts)
356 * @param enmError TRPM_TRAP_HAS_ERRORCODE or TRPM_TRAP_NO_ERRORCODE.
357 * @param enmType TRPM event type
358 * @internal
359 */
360TRPMDECL(int) TRPMForwardTrap(PVM pVM, PCPUMCTXCORE pRegFrame, uint32_t iGate, uint32_t opsize, TRPMERRORCODE enmError, TRPMEVENT enmType)
361{
362#ifdef TRPM_FORWARD_TRAPS_IN_GC
363 X86EFLAGS eflags;
364
365 STAM_PROFILE_ADV_START(CTXSUFF(&pVM->trpm.s.StatForwardProf), a);
366
367#ifdef DEBUG
368 if (pRegFrame->eflags.Bits.u1VM)
369 Log(("TRPMForwardTrap-VM: eip=%04X:%04X iGate=%d\n", pRegFrame->cs, pRegFrame->eip, iGate));
370 else
371 Log(("TRPMForwardTrap: eip=%04X:%VGv iGate=%d\n", pRegFrame->cs, pRegFrame->eip, iGate));
372
373 switch (iGate) {
374 case 14:
375 if (pRegFrame->eip == pVM->trpm.s.uActiveCR2)
376 {
377 int rc;
378 RTGCPTR pCallerGC;
379#ifdef IN_GC
380 rc = MMGCRamRead(pVM, &pCallerGC, (RTGCPTR)pRegFrame->esp, sizeof(pCallerGC));
381#else
382 rc = PGMPhysReadGCPtr(pVM, &pCallerGC, (RTGCPTR)pRegFrame->esp, sizeof(pCallerGC));
383#endif
384 if (VBOX_SUCCESS(rc))
385 {
386 Log(("TRPMForwardTrap: caller=%VGv\n", pCallerGC));
387 }
388 }
389 /* no break */
390 case 8:
391 case 10:
392 case 11:
393 case 12:
394 case 13:
395 case 17:
396 Assert(enmError == TRPM_TRAP_HAS_ERRORCODE);
397 break;
398 default:
399 Assert(enmError == TRPM_TRAP_NO_ERRORCODE);
400 break;
401 }
402#endif /* DEBUG */
403
404 /* Retrieve the eflags including the virtualized bits. */
405 /* Note: hackish as the cpumctxcore structure doesn't contain the right value */
406 eflags.u32 = CPUMRawGetEFlags(pVM, pRegFrame);
407
408 /* VM_FF_INHIBIT_INTERRUPTS should be cleared upfront or don't call this function at all for dispatching hardware interrupts. */
409 Assert(enmType != TRPM_HARDWARE_INT || !VM_FF_ISSET(pVM, VM_FF_INHIBIT_INTERRUPTS));
410
411 /*
412 * If it's a real guest trap and the guest's page fault handler is marked as safe for GC execution, then we call it directly.
413 * Well, only if the IF flag is set.
414 */
415 /*
416 * @todo if the trap handler was modified and marked invalid, then we should *now* go back to the host context and install a new patch.
417 *
418 */
419 if ( pVM->trpm.s.aGuestTrapHandler[iGate]
420 && (eflags.Bits.u1IF)
421#ifndef VBOX_RAW_V86
422 && !(eflags.Bits.u1VM) /* @todo implement when needed (illegal for same privilege level transfers). */
423#endif
424 && !PATMIsPatchGCAddr(pVM, (RTGCPTR)pRegFrame->eip)
425 )
426 {
427 uint16_t cbIDT;
428 RTGCPTR GCPtrIDT = (RTGCPTR)CPUMGetGuestIDTR(pVM, &cbIDT);
429 uint32_t cpl;
430 VBOXIDTE GuestIdte;
431 RTGCPTR pIDTEntry;
432 int rc;
433
434 Assert(PATMAreInterruptsEnabledByCtxCore(pVM, pRegFrame));
435 Assert(!VM_FF_ISPENDING(pVM, VM_FF_SELM_SYNC_GDT | VM_FF_SELM_SYNC_LDT | VM_FF_TRPM_SYNC_IDT | VM_FF_SELM_SYNC_TSS));
436
437 /* Get the current privilege level. */
438 cpl = CPUMGetGuestCPL(pVM, pRegFrame);
439
440 if (GCPtrIDT && iGate * sizeof(VBOXIDTE) >= cbIDT)
441 goto failure;
442
443 /*
444 * BIG TODO: The checks are not complete. see trap and interrupt dispatching section in Intel docs for details
445 * All very obscure, but still necessary.
446 * Currently only some CS & TSS selector checks are missing.
447 *
448 */
449 pIDTEntry = (RTGCPTR)((RTGCUINTPTR)GCPtrIDT + sizeof(VBOXIDTE) * iGate);
450#ifdef IN_GC
451 rc = MMGCRamRead(pVM, &GuestIdte, pIDTEntry, sizeof(GuestIdte));
452#else
453 rc = PGMPhysReadGCPtr(pVM, &GuestIdte, pIDTEntry, sizeof(GuestIdte));
454#endif
455 if (VBOX_FAILURE(rc))
456 {
457 /* The page might be out of sync. (@todo might cross a page boundary) */
458 Log(("Page %VGv out of sync -> prefetch and try again\n", pIDTEntry));
459 rc = PGMPrefetchPage(pVM, pIDTEntry); /** @todo r=bird: rainy day: this isn't entirely safe because of access bit virtualiziation and CSAM. */
460 if (rc != VINF_SUCCESS)
461 {
462 Log(("TRPMForwardTrap: PGMPrefetchPage failed with rc=%Vrc\n", rc));
463 goto failure;
464 }
465#ifdef IN_GC
466 rc = MMGCRamRead(pVM, &GuestIdte, pIDTEntry, sizeof(GuestIdte));
467#else
468 rc = PGMPhysReadGCPtr(pVM, &GuestIdte, pIDTEntry, sizeof(GuestIdte));
469#endif
470 }
471 if ( VBOX_SUCCESS(rc)
472 && GuestIdte.Gen.u1Present
473 && (GuestIdte.Gen.u5Type2 == VBOX_IDTE_TYPE2_TRAP_32 || GuestIdte.Gen.u5Type2 == VBOX_IDTE_TYPE2_INT_32)
474 && (GuestIdte.Gen.u2DPL == 3 || GuestIdte.Gen.u2DPL == 0)
475 && (GuestIdte.Gen.u16SegSel & 0xfffc) /* must not be zero */
476 && (enmType == TRPM_TRAP || enmType == TRPM_HARDWARE_INT || cpl <= GuestIdte.Gen.u2DPL) /* CPL <= DPL if software int */
477 )
478 {
479 RTGCPTR pHandler, dummy;
480 GCPTRTYPE(uint32_t *)pTrapStackGC;
481#ifndef IN_GC
482 HCPTRTYPE(uint32_t *)pTrapStackHC;
483#endif
484
485 pHandler = (RTGCPTR)((GuestIdte.Gen.u16OffsetHigh << 16) | GuestIdte.Gen.u16OffsetLow);
486
487 /* Note: SELMValidateAndConvertCSAddr checks for code type, memory type, selector validity. */
488 /** @todo dpl <= cpl else GPF */
489
490 /* Note: don't use current eflags as we might be in V86 mode and the IDT always contains protected mode selectors */
491 X86EFLAGS fakeflags;
492 fakeflags.u32 = 0;
493
494 rc = SELMValidateAndConvertCSAddr(pVM, fakeflags, 0, GuestIdte.Gen.u16SegSel, NULL, pHandler, &dummy);
495 if (rc == VINF_SUCCESS)
496 {
497 VBOXGDTR gdtr = {0};
498 bool fConforming = false;
499 int idx = 0;
500 uint32_t dpl;
501 uint32_t ss_r0;
502 uint32_t esp_r0;
503 VBOXDESC Desc;
504 RTGCPTR pGdtEntry;
505
506 CPUMGetGuestGDTR(pVM, &gdtr);
507 Assert(gdtr.pGdt && gdtr.cbGdt > GuestIdte.Gen.u16SegSel);
508
509 if (!gdtr.pGdt)
510 goto failure;
511
512 pGdtEntry = (RTGCPTR)(uintptr_t)&((VBOXDESC *)gdtr.pGdt)[GuestIdte.Gen.u16SegSel >> X86_SEL_SHIFT]; /// @todo fix this
513#ifdef IN_GC
514 rc = MMGCRamRead(pVM, &Desc, pGdtEntry, sizeof(Desc));
515#else
516 rc = PGMPhysReadGCPtr(pVM, &Desc, pGdtEntry, sizeof(Desc));
517#endif
518 if (VBOX_FAILURE(rc))
519 {
520 /* The page might be out of sync. (@todo might cross a page boundary) */
521 Log(("Page %VGv out of sync -> prefetch and try again\n", pGdtEntry));
522 rc = PGMPrefetchPage(pVM, pGdtEntry); /** @todo r=bird: rainy day: this isn't entirely safe because of access bit virtualiziation and CSAM. */
523 if (rc != VINF_SUCCESS)
524 {
525 Log(("PGMPrefetchPage failed with rc=%Vrc\n", rc));
526 goto failure;
527 }
528#ifdef IN_GC
529 rc = MMGCRamRead(pVM, &Desc, pGdtEntry, sizeof(Desc));
530#else
531 rc = PGMPhysReadGCPtr(pVM, &Desc, pGdtEntry, sizeof(Desc));
532#endif
533 if (VBOX_FAILURE(rc))
534 {
535 Log(("MMGCRamRead failed with %Vrc\n", rc));
536 goto failure;
537 }
538 }
539
540 if (Desc.Gen.u4Type & X86_SEL_TYPE_CONF)
541 {
542 Log(("Conforming code selector\n"));
543 fConforming = true;
544 }
545 /** @todo check descriptor type!! */
546
547 dpl = Desc.Gen.u2Dpl;
548
549 if (!fConforming && dpl < cpl) /* to inner privilege level */
550 {
551 rc = SELMGetRing1Stack(pVM, &ss_r0, &esp_r0);
552 if (VBOX_FAILURE(rc))
553 goto failure;
554
555 Assert((ss_r0 & X86_SEL_RPL) == 1);
556
557 if ( !esp_r0
558 || !ss_r0
559 || (ss_r0 & X86_SEL_RPL) != ((dpl == 0) ? 1 : dpl)
560 || SELMToFlatEx(pVM, fakeflags, ss_r0, (RTGCPTR)esp_r0, SELMTOFLAT_FLAGS_CPL1, (PRTGCPTR)&pTrapStackGC, NULL) != VINF_SUCCESS
561 )
562 {
563 Log(("Invalid ring 0 stack %04X:%VGv\n", ss_r0, esp_r0));
564 goto failure;
565 }
566 }
567 else
568 if (fConforming || dpl == cpl) /* to the same privilege level */
569 {
570 ss_r0 = pRegFrame->ss;
571 esp_r0 = pRegFrame->esp;
572
573 if ( eflags.Bits.u1VM /* illegal */
574 || SELMToFlatEx(pVM, fakeflags, ss_r0, (RTGCPTR)esp_r0, SELMTOFLAT_FLAGS_CPL1, (PRTGCPTR)&pTrapStackGC, NULL) != VINF_SUCCESS)
575 {
576 AssertMsgFailed(("Invalid stack %04X:%VGv??? (VM=%d)\n", ss_r0, esp_r0, eflags.Bits.u1VM));
577 goto failure;
578 }
579 }
580 else
581 {
582 Log(("Invalid cpl-dpl combo %d vs %d\n", cpl, dpl));
583 goto failure;
584 }
585 /*
586 * Build trap stack frame on guest handler's stack
587 */
588#ifdef IN_GC
589 Assert(eflags.Bits.u1VM || (pRegFrame->ss & X86_SEL_RPL) != 0);
590 /* Check maximum amount we need (10 when executing in V86 mode) */
591 rc = PGMVerifyAccess(pVM, (RTGCUINTPTR)pTrapStackGC - 10*sizeof(uint32_t), 10 * sizeof(uint32_t), X86_PTE_RW);
592#else
593 Assert(eflags.Bits.u1VM || (pRegFrame->ss & X86_SEL_RPL) == 0 || (pRegFrame->ss & X86_SEL_RPL) == 3);
594 /* Check maximum amount we need (10 when executing in V86 mode) */
595 if ( PAGE_ADDRESS(pTrapStackGC) != PAGE_ADDRESS(pTrapStackGC - 10*sizeof(uint32_t)) /* fail if we cross a page boundary */
596 || VBOX_FAILURE((rc = PGMPhysGCPtr2HCPtr(pVM, pTrapStackGC, (PRTHCPTR)&pTrapStackHC)))
597 )
598 {
599 AssertRC(rc);
600 goto failure;
601 }
602#endif
603 if (rc == VINF_SUCCESS)
604 {
605 /** if eflags.Bits.u1VM then push gs, fs, ds, es */
606 if (eflags.Bits.u1VM)
607 {
608 Log(("TRAP%02X: (VM) Handler %04X:%08X Stack %04X:%08X RPL=%d CR2=%08X\n", iGate, GuestIdte.Gen.u16SegSel, pHandler, ss_r0, esp_r0, (pRegFrame->ss & X86_SEL_RPL), pVM->trpm.s.uActiveCR2));
609 CTXSUFF(pTrapStack)[--idx] = pRegFrame->gs;
610 CTXSUFF(pTrapStack)[--idx] = pRegFrame->fs;
611 CTXSUFF(pTrapStack)[--idx] = pRegFrame->ds;
612 CTXSUFF(pTrapStack)[--idx] = pRegFrame->es;
613
614 /* clear ds, es, fs & gs in current context */
615 pRegFrame->ds = pRegFrame->es = pRegFrame->fs = pRegFrame->gs = 0;
616 }
617 else
618 Log(("TRAP%02X: Handler %04X:%08X Stack %04X:%08X RPL=%d CR2=%08X\n", iGate, GuestIdte.Gen.u16SegSel, pHandler, ss_r0, esp_r0, (pRegFrame->ss & X86_SEL_RPL), pVM->trpm.s.uActiveCR2));
619
620 if (!fConforming && dpl < cpl)
621 {
622 if ((pRegFrame->ss & X86_SEL_RPL) == 1 && !eflags.Bits.u1VM)
623 CTXSUFF(pTrapStack)[--idx] = pRegFrame->ss & ~1; /* Mask away traces of raw ring execution (ring 1). */
624 else
625 CTXSUFF(pTrapStack)[--idx] = pRegFrame->ss;
626
627 CTXSUFF(pTrapStack)[--idx] = pRegFrame->esp;
628 }
629
630 /* Note: We use the eflags copy, that includes the virtualized bits! */
631 /* Note: Not really necessary as we grab include those bits in the trap/irq handler trampoline */
632 CTXSUFF(pTrapStack)[--idx] = eflags.u32;
633
634 if ((pRegFrame->cs & X86_SEL_RPL) == 1 && !eflags.Bits.u1VM)
635 CTXSUFF(pTrapStack)[--idx] = pRegFrame->cs & ~1; /* Mask away traces of raw ring execution (ring 1). */
636 else
637 CTXSUFF(pTrapStack)[--idx] = pRegFrame->cs;
638
639 if (enmType == TRPM_SOFTWARE_INT)
640 {
641 Assert(opsize);
642 CTXSUFF(pTrapStack)[--idx] = pRegFrame->eip + opsize; /* return address = next instruction */
643 }
644 else
645 CTXSUFF(pTrapStack)[--idx] = pRegFrame->eip;
646
647 if (enmError == TRPM_TRAP_HAS_ERRORCODE)
648 {
649 CTXSUFF(pTrapStack)[--idx] = pVM->trpm.s.uActiveErrorCode;
650 }
651
652 Assert(esp_r0 > -idx*sizeof(uint32_t));
653 /* Adjust ESP accordingly */
654 esp_r0 += idx*sizeof(uint32_t);
655
656 /* Mask away dangerous flags for the trap/interrupt handler. */
657 eflags.u32 &= ~(X86_EFL_TF | X86_EFL_VM | X86_EFL_RF | X86_EFL_NT);
658#ifdef DEBUG
659 for (int j=idx;j<0;j++)
660 {
661 LogFlow(("Stack %VGv pos %02d: %08x\n", &CTXSUFF(pTrapStack)[j], j, CTXSUFF(pTrapStack)[j]));
662 }
663 char *pszPrefix = "";
664 char *szEFlags = "";
665
666 LogFlow(( "%seax=%08x %sebx=%08x %secx=%08x %sedx=%08x %sesi=%08x %sedi=%08x\n"
667 "%seip=%08x %sesp=%08x %sebp=%08x %siopl=%d %*s\n"
668 "%scs=%04x %sds=%04x %ses=%04x %sfs=%04x %sgs=%04x %seflags=%08x\n",
669 pszPrefix, pRegFrame->eax, pszPrefix, pRegFrame->ebx, pszPrefix, pRegFrame->ecx, pszPrefix, pRegFrame->edx, pszPrefix, pRegFrame->esi, pszPrefix, pRegFrame->edi,
670 pszPrefix, pRegFrame->eip, pszPrefix, pRegFrame->esp, pszPrefix, pRegFrame->ebp, pszPrefix, eflags.Bits.u2IOPL, *pszPrefix ? 33 : 31, szEFlags,
671 pszPrefix, (RTSEL)pRegFrame->cs, pszPrefix, (RTSEL)pRegFrame->ds, pszPrefix, (RTSEL)pRegFrame->es,
672 pszPrefix, (RTSEL)pRegFrame->fs, pszPrefix, (RTSEL)pRegFrame->gs, pszPrefix, eflags.u32));
673#endif
674
675 Log(("PATM Handler %VGv Adjusted stack %08X new EFLAGS=%08X idx=%d dpl=%d cpl=%d\n", pVM->trpm.s.aGuestTrapHandler[iGate], esp_r0, eflags.u32, idx, dpl, cpl));
676
677 /* Make sure the internal guest context structure is up-to-date. */
678 CPUMSetGuestCR2(pVM, pVM->trpm.s.uActiveCR2);
679
680#ifdef IN_GC
681 /* Note: shouldn't be necessary */
682 ASMSetCR2(pVM->trpm.s.uActiveCR2);
683
684 /* Turn off interrupts for interrupt gates. */
685 if (GuestIdte.Gen.u5Type2 == VBOX_IDTE_TYPE2_INT_32)
686 CPUMRawSetEFlags(pVM, pRegFrame, eflags.u32 & ~X86_EFL_IF);
687
688 /* The virtualized bits must be removed again!! */
689 eflags.Bits.u1IF = 1;
690 eflags.Bits.u2IOPL = 0;
691
692 Assert(eflags.Bits.u1IF);
693 Assert(eflags.Bits.u2IOPL == 0);
694 STAM_COUNTER_INC(&pVM->trpm.s.CTXALLSUFF(paStatForwardedIRQ)[iGate]);
695 STAM_PROFILE_ADV_STOP(CTXSUFF(&pVM->trpm.s.StatForwardProf), a);
696
697 CPUMGCCallGuestTrapHandler(pRegFrame, GuestIdte.Gen.u16SegSel | 1, pVM->trpm.s.aGuestTrapHandler[iGate], eflags.u32, ss_r0, (RTGCPTR)esp_r0);
698 /* does not return */
699#else
700 /* Turn off interrupts for interrupt gates. */
701 if (GuestIdte.Gen.u5Type2 == VBOX_IDTE_TYPE2_INT_32)
702 eflags.Bits.u1IF = 0;
703
704 pRegFrame->eflags.u32 = eflags.u32;
705
706 pRegFrame->eip = pVM->trpm.s.aGuestTrapHandler[iGate];
707 pRegFrame->cs = GuestIdte.Gen.u16SegSel;
708 pRegFrame->esp = esp_r0;
709 pRegFrame->ss = ss_r0 & ~X86_SEL_RPL; /* set rpl to ring 0 */
710 STAM_PROFILE_ADV_STOP(CTXSUFF(&pVM->trpm.s.StatForwardProf), a);
711 return VINF_SUCCESS;
712#endif
713 }
714 else
715 Log(("TRAP%02X: PGMVerifyAccess %VGv failed with %Vrc -> forward to REM\n", iGate, pTrapStackGC, rc));
716 }
717 else
718 Log(("SELMValidateAndConvertCSAddr failed with %Vrc\n", rc));
719 }
720 else
721 Log(("MMRamRead %VGv size %d failed with %Vrc\n", (RTGCUINTPTR)GCPtrIDT + sizeof(VBOXIDTE) * iGate, sizeof(GuestIdte), rc));
722 }
723 else
724 {
725 Log(("Refused to forward trap: eflags=%08x IF=%d\n", eflags.u32, eflags.Bits.u1IF));
726#ifdef VBOX_WITH_STATISTICS
727 if (pVM->trpm.s.aGuestTrapHandler[iGate] == TRPM_INVALID_HANDLER)
728 STAM_COUNTER_INC(&pVM->trpm.s.StatForwardFailNoHandler);
729 else
730 if (PATMIsPatchGCAddr(pVM, (RTGCPTR)pRegFrame->eip))
731 STAM_COUNTER_INC(&pVM->trpm.s.StatForwardFailPatchAddr);
732#endif
733 }
734failure:
735 STAM_COUNTER_INC(&CTXSUFF(pVM->trpm.s.StatForwardFail));
736 STAM_PROFILE_ADV_STOP(CTXSUFF(&pVM->trpm.s.StatForwardProf), a);
737
738 Log(("TRAP%02X: forwarding to REM (ss rpl=%d eflags=%08X VMIF=%d handler=%08X\n", iGate, pRegFrame->ss & X86_SEL_RPL, pRegFrame->eflags.u32, PATMAreInterruptsEnabledByCtxCore(pVM, pRegFrame), pVM->trpm.s.aGuestTrapHandler[iGate]));
739#endif
740 return VINF_EM_RAW_GUEST_TRAP;
741}
742
743
744/**
745 * Raises a cpu exception which doesn't take an error code.
746 *
747 * This function may or may not dispatch the exception before returning.
748 *
749 * @returns VBox status code fit for scheduling.
750 * @retval VINF_EM_RAW_GUEST_TRAP if the exception was left pending.
751 * @retval VINF_TRPM_XCPT_DISPATCHED if the exception was raised and dispatched for raw-mode execution.
752 * @retval VINF_EM_RESCHEDULE_REM if the exception was dispatched and cannot be executed in raw-mode.
753 *
754 * @param pVM The VM handle.
755 * @param pCtxCore The CPU context core.
756 * @param enmXcpt The exception.
757 */
758TRPMDECL(int) TRPMRaiseXcpt(PVM pVM, PCPUMCTXCORE pCtxCore, X86XCPT enmXcpt)
759{
760 LogFlow(("TRPMRaiseXcptErr: cs:eip=%RTsel:%RX32 enmXcpt=%#x\n", pCtxCore->cs, pCtxCore->eip, enmXcpt));
761/** @todo dispatch the trap. */
762 pVM->trpm.s.uActiveVector = enmXcpt;
763 pVM->trpm.s.fActiveSoftwareInterrupt = false;
764 pVM->trpm.s.uActiveErrorCode = 0xdeadbeef;
765 pVM->trpm.s.uActiveCR2 = 0xdeadface;
766 return VINF_EM_RAW_GUEST_TRAP;
767}
768
769
770/**
771 * Raises a cpu exception with an errorcode.
772 *
773 * This function may or may not dispatch the exception before returning.
774 *
775 * @returns VBox status code fit for scheduling.
776 * @retval VINF_EM_RAW_GUEST_TRAP if the exception was left pending.
777 * @retval VINF_TRPM_XCPT_DISPATCHED if the exception was raised and dispatched for raw-mode execution.
778 * @retval VINF_EM_RESCHEDULE_REM if the exception was dispatched and cannot be executed in raw-mode.
779 *
780 * @param pVM The VM handle.
781 * @param pCtxCore The CPU context core.
782 * @param enmXcpt The exception.
783 * @param uErr The error code.
784 */
785TRPMDECL(int) TRPMRaiseXcptErr(PVM pVM, PCPUMCTXCORE pCtxCore, X86XCPT enmXcpt, uint32_t uErr)
786{
787 LogFlow(("TRPMRaiseXcptErr: cs:eip=%RTsel:%RX32 enmXcpt=%#x uErr=%RX32\n", pCtxCore->cs, pCtxCore->eip, enmXcpt, uErr));
788/** @todo dispatch the trap. */
789 pVM->trpm.s.uActiveVector = enmXcpt;
790 pVM->trpm.s.fActiveSoftwareInterrupt = false;
791 pVM->trpm.s.uActiveErrorCode = uErr;
792 pVM->trpm.s.uActiveCR2 = 0xdeadface;
793 return VINF_EM_RAW_GUEST_TRAP;
794}
795
796
797/**
798 * Raises a cpu exception with an errorcode and CR2.
799 *
800 * This function may or may not dispatch the exception before returning.
801 *
802 * @returns VBox status code fit for scheduling.
803 * @retval VINF_EM_RAW_GUEST_TRAP if the exception was left pending.
804 * @retval VINF_TRPM_XCPT_DISPATCHED if the exception was raised and dispatched for raw-mode execution.
805 * @retval VINF_EM_RESCHEDULE_REM if the exception was dispatched and cannot be executed in raw-mode.
806 *
807 * @param pVM The VM handle.
808 * @param pCtxCore The CPU context core.
809 * @param enmXcpt The exception.
810 * @param uErr The error code.
811 * @param uCR2 The CR2 value.
812 */
813TRPMDECL(int) TRPMRaiseXcptErrCR2(PVM pVM, PCPUMCTXCORE pCtxCore, X86XCPT enmXcpt, uint32_t uErr, RTGCUINTPTR uCR2)
814{
815 LogFlow(("TRPMRaiseXcptErr: cs:eip=%RTsel:%RX32 enmXcpt=%#x uErr=%RX32 uCR2=%RGv\n", pCtxCore->cs, pCtxCore->eip, enmXcpt, uErr, uCR2));
816/** @todo dispatch the trap. */
817 pVM->trpm.s.uActiveVector = enmXcpt;
818 pVM->trpm.s.fActiveSoftwareInterrupt = false;
819 pVM->trpm.s.uActiveErrorCode = uErr;
820 pVM->trpm.s.uActiveCR2 = uCR2;
821 return VINF_EM_RAW_GUEST_TRAP;
822}
823
824
825/**
826 * Clear guest trap/interrupt gate handler
827 *
828 * @returns VBox status code.
829 * @param pVM The VM to operate on.
830 * @param iTrap Interrupt/trap number.
831 */
832TRPMDECL(int) trpmClearGuestTrapHandler(PVM pVM, unsigned iTrap)
833{
834 /*
835 * Validate.
836 */
837 if (iTrap >= ELEMENTS(pVM->trpm.s.aIdt))
838 {
839 AssertMsg(iTrap < TRPM_HANDLER_INT_BASE, ("Illegal gate number %d!\n", iTrap));
840 return VERR_INVALID_PARAMETER;
841 }
842
843 if (ASMBitTest(&pVM->trpm.s.au32IdtPatched[0], iTrap))
844#ifdef IN_RING3
845 trpmR3ClearPassThroughHandler(pVM, iTrap);
846#else
847 AssertFailed();
848#endif
849
850 pVM->trpm.s.aGuestTrapHandler[iTrap] = TRPM_INVALID_HANDLER;
851 return VINF_SUCCESS;
852}
853
854
Note: See TracBrowser for help on using the repository browser.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette