From: Gleb Natapov <gleb@redhat.com>
To: "李春奇 <Arthur Chunqi Li>" <yzt356@gmail.com>
Cc: kvm <kvm@vger.kernel.org>, Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [PATCH 1/2] kvm-unit-tests: Add a func to run instruction in emulator
Date: Sun, 9 Jun 2013 15:58:43 +0300 [thread overview]
Message-ID: <20130609125843.GV4725@redhat.com> (raw)
In-Reply-To: <CABpY8MLPmvX2HaOEaM1Gnm7yLWmE=8mMWKbZ-FRQ8QJjo0ysFg@mail.gmail.com>
On Sun, Jun 09, 2013 at 08:56:04PM +0800, 李春奇 <Arthur Chunqi Li> wrote:
> On Sun, Jun 9, 2013 at 8:49 PM, Gleb Natapov <gleb@redhat.com> wrote:
> > On Sun, Jun 09, 2013 at 08:44:32PM +0800, 李春奇 <Arthur Chunqi Li> wrote:
> >> On Sun, Jun 9, 2013 at 7:07 PM, Gleb Natapov <gleb@redhat.com> wrote:
> >> > On Fri, Jun 07, 2013 at 10:31:38AM +0800, Arthur Chunqi Li wrote:
> >> >> Add a function trap_emulator to run an instruction in emulator.
> >> >> Set inregs first (%rax, %rsp, %rbp, %rflags have special usage and
> >> >> cannot set in inregs), put instruction codec in alt_insn and call
> >> >> func with alt_insn_length. Get results in outregs.
> >> >>
> >> > Why %rax, %rsp, %rbp, %rflags cannot be set in inregs?
> >> >
> >> > %rax because trapping instruction uses it? Use one that does not use
> >> > register at all: MOV r/m32, imm32
> >> I don't know why set %rax before call alt_insn_page can cause error. I
> >> use "xchg %%rax, 0+%[save]" before "call *%1" and the %rcx is not set
> >> correctly.
> > We better find this out :)
> I will try to trace it.
> >
> >> >
> >> > %rsp and %rbp because of ret on instruction page? Use the same trick
> >> > realmode.c test uses: have the code that sets/saves registers in
> >> > insn_page/alt_insn_page itself and copy the instruction you want to test
> >> > into the page itself instead of doing call.
> >> I don't know how instructions between calling insn_page and
> >> alt_insn_page are executed (function install_page and some other
> >> instructions before call *%1". If these insns are executed after
> >> insn_page is called, changes before the trapping instruction may
> >> affect the executing of these instructions.
> >>
> > Not sure what do you mean here.
> Simply, I mean what is the executing sequence in that piece of codes.
> Why instruction in alt_insn_page will be emulated?
>
For the same reason it is emulated now. The trick is to have trapping
instruction and instruction we want to emulate at the same offset on
insn_page and alt_insn_page. Now the offset is 0, but it does not have
to be.
> >> >
> >> > Not sure what is so special about %rflags.
> >> >
> >> >> Signed-off-by: Arthur Chunqi Li <yzt356@gmail.com>
> >> >> ---
> >> >> x86/emulator.c | 67 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++
> >> >> 1 file changed, 67 insertions(+)
> >> >> mode change 100644 => 100755 x86/emulator.c
> >> >>
> >> >> diff --git a/x86/emulator.c b/x86/emulator.c
> >> >> old mode 100644
> >> >> new mode 100755
> >> >> index 96576e5..770e8f7
> >> >> --- a/x86/emulator.c
> >> >> +++ b/x86/emulator.c
> >> >> @@ -11,6 +11,13 @@ int fails, tests;
> >> >>
> >> >> static int exceptions;
> >> >>
> >> >> +struct regs {
> >> >> + u64 rax, rbx, rcx, rdx;
> >> >> + u64 rsi, rdi, rsp, rbp;
> >> >> + u64 rip, rflags;
> >> >> +};
> >> >> +static struct regs inregs, outregs;
> >> >> +
> >> >> void report(const char *name, int result)
> >> >> {
> >> >> ++tests;
> >> >> @@ -685,6 +692,66 @@ static void test_shld_shrd(u32 *mem)
> >> >> report("shrd (cl)", *mem == ((0x12345678 >> 3) | (5u << 29)));
> >> >> }
> >> >>
> >> >> +static void trap_emulator(uint64_t *mem, uint8_t *insn_page,
> >> >> + uint8_t *alt_insn_page, void *insn_ram,
> >> >> + uint8_t *alt_insn, int alt_insn_length)
> >> >> +{
> >> >> + ulong *cr3 = (ulong *)read_cr3();
> >> >> + int i;
> >> >> + static struct regs save;
> >> >> +
> >> >> + // Pad with RET instructions
> >> >> + memset(insn_page, 0xc3, 4096);
> >> >> + memset(alt_insn_page, 0xc3, 4096);
> >> >> +
> >> >> + // Place a trapping instruction in the page to trigger a VMEXIT
> >> >> + insn_page[0] = 0x89; // mov %eax, (%rax)
> >> >> + insn_page[1] = 0x00;
> >> >> + insn_page[2] = 0x90; // nop
> >> >> + insn_page[3] = 0xc3; // ret
> >> >> +
> >> >> + // Place the instruction we want the hypervisor to see in the alternate page
> >> >> + for (i=0; i<alt_insn_length; i++)
> >> >> + alt_insn_page[i] = alt_insn[i];
> >> >> + save = inregs;
> >> >> +
> >> >> + // Load the code TLB with insn_page, but point the page tables at
> >> >> + // alt_insn_page (and keep the data TLB clear, for AMD decode assist).
> >> >> + // This will make the CPU trap on the insn_page instruction but the
> >> >> + // hypervisor will see alt_insn_page.
> >> >> + install_page(cr3, virt_to_phys(insn_page), insn_ram);
> >> >> + invlpg(insn_ram);
> >> >> + // Load code TLB
> >> >> + asm volatile("call *%0" : : "r"(insn_ram + 3));
> >> >> + install_page(cr3, virt_to_phys(alt_insn_page), insn_ram);
> >> >> + // Trap, let hypervisor emulate at alt_insn_page
> >> >> + asm volatile(
> >> >> + "xchg %%rbx, 8+%[save] \n\t"
> >> >> + "xchg %%rcx, 16+%[save] \n\t"
> >> >> + "xchg %%rdx, 24+%[save] \n\t"
> >> >> + "xchg %%rsi, 32+%[save] \n\t"
> >> >> + "xchg %%rdi, 40+%[save] \n\t"
> >> >> +
> >> >> + "call *%1\n\t"
> >> >> +
> >> >> + "mov %%rax, 0+%[save] \n\t"
> >> >> + "xchg %%rbx, 8+%[save] \n\t"
> >> >> + "xchg %%rcx, 16+%[save] \n\t"
> >> >> + "xchg %%rdx, 24+%[save] \n\t"
> >> >> + "xchg %%rsi, 32+%[save] \n\t"
> >> >> + "xchg %%rdi, 40+%[save] \n\t"
> >> >> + "mov %%rsp, 48+%[save] \n\t"
> >> >> + "mov %%rbp, 56+%[save] \n\t"
> >> >> + /* Save RFLAGS in outregs*/
> >> >> + "pushf \n\t"
> >> >> + "popq 72+%[save] \n\t"
> >> >> + : [save]"+m"(save)
> >> >> + : "r"(insn_ram), "a"(mem)
> >> >> + : "memory", "cc"
> >> >> + );
> >> >> + outregs = save;
> >> >> +}
> >> >> +
> >> >> static void advance_rip_by_3_and_note_exception(struct ex_regs *regs)
> >> >> {
> >> >> ++exceptions;
> >> >> --
> >> >> 1.7.9.5
> >> >
> >> > --
> >> > Gleb.
> >>
> >>
> >>
> >> --
> >> Arthur Chunqi Li
> >> Department of Computer Science
> >> School of EECS
> >> Peking University
> >> Beijing, China
> >
> > --
> > Gleb.
>
>
>
> --
> Arthur Chunqi Li
> Department of Computer Science
> School of EECS
> Peking University
> Beijing, China
--
Gleb.
next prev parent reply other threads:[~2013-06-09 12:58 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-06-07 2:31 [PATCH 1/2] kvm-unit-tests: Add a func to run instruction in emulator Arthur Chunqi Li
2013-06-07 2:31 ` [PATCH 2/2] kvm-unit-tests: Change two cases to use trap_emulator Arthur Chunqi Li
2013-06-09 11:07 ` [PATCH 1/2] kvm-unit-tests: Add a func to run instruction in emulator Gleb Natapov
2013-06-09 12:44 ` 李春奇 <Arthur Chunqi Li>
2013-06-09 12:49 ` Gleb Natapov
2013-06-09 12:56 ` 李春奇 <Arthur Chunqi Li>
2013-06-09 12:58 ` Gleb Natapov [this message]
2013-06-09 13:22 ` 李春奇 <Arthur Chunqi Li>
2013-06-09 14:09 ` Gleb Natapov
2013-06-09 15:23 ` 李春奇 <Arthur Chunqi Li>
2013-06-09 16:00 ` Gleb Natapov
2013-06-09 17:09 ` 李春奇 <Arthur Chunqi Li>
2013-06-09 17:13 ` Gleb Natapov
2013-06-09 17:28 ` 李春奇 <Arthur Chunqi Li>
2013-06-09 17:39 ` Gleb Natapov
-- strict thread matches above, loose matches on Subject: below --
2013-06-20 10:45 Arthur Chunqi Li
2013-06-20 10:47 ` Jan Kiszka
2013-06-20 12:32 ` Gleb Natapov
2013-06-19 15:00 Arthur Chunqi Li
2013-06-19 15:07 ` 李春奇 <Arthur Chunqi Li>
2013-06-19 16:03 ` Gleb Natapov
2013-06-19 17:48 ` Gmail
2013-06-20 5:42 ` Gleb Natapov
2013-06-20 8:29 ` Paolo Bonzini
2013-06-20 8:31 ` Gleb Natapov
2013-06-20 8:48 ` Gleb Natapov
2013-06-20 8:58 ` Gmail
2013-06-13 15:16 Arthur Chunqi Li
2013-06-10 13:38 Arthur Chunqi Li
2013-06-10 17:36 ` Gleb Natapov
2013-06-06 15:24 Arthur Chunqi Li
2013-06-07 2:14 ` 李春奇 <Arthur Chunqi Li>
2013-06-12 20:50 ` Paolo Bonzini
2013-06-13 4:50 ` 李春奇 <Arthur Chunqi Li>
2013-06-13 9:30 ` 李春奇 <Arthur Chunqi Li>
2013-06-13 13:12 ` Paolo Bonzini
2013-06-18 12:45 ` Gleb Natapov
2013-06-18 13:40 ` 李春奇 <Arthur Chunqi Li>
2013-06-18 14:28 ` 李春奇 <Arthur Chunqi Li>
2013-06-18 15:47 ` Gleb Natapov
2013-06-18 15:56 ` 李春奇 <Arthur Chunqi Li>
2013-06-18 16:09 ` Gleb Natapov
2013-06-18 16:14 ` 李春奇 <Arthur Chunqi Li>
2013-06-18 16:44 ` Gleb Natapov
2013-06-19 1:26 ` 李春奇 <Arthur Chunqi Li>
2013-06-19 9:31 ` Gleb Natapov
2013-06-19 12:18 ` 李春奇 <Arthur Chunqi Li>
2013-06-19 12:26 ` Gleb Natapov
2013-06-19 12:30 ` 李春奇 <Arthur Chunqi Li>
2013-06-19 12:32 ` Gleb Natapov
2013-06-19 14:01 ` 李春奇 <Arthur Chunqi Li>
2013-06-19 14:13 ` Gleb Natapov
2013-06-19 14:20 ` 李春奇 <Arthur Chunqi Li>
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130609125843.GV4725@redhat.com \
--to=gleb@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=yzt356@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.