2001-10-03 17:10:38 +04:00
|
|
|
/////////////////////////////////////////////////////////////////////////
|
2011-02-25 00:54:04 +03:00
|
|
|
// $Id$
|
2001-10-03 17:10:38 +04:00
|
|
|
/////////////////////////////////////////////////////////////////////////
|
|
|
|
//
|
2014-07-03 10:40:42 +04:00
|
|
|
// Copyright (C) 2001-2014 The Bochs Project
|
2001-04-10 05:04:59 +04:00
|
|
|
//
|
|
|
|
// This library is free software; you can redistribute it and/or
|
|
|
|
// modify it under the terms of the GNU Lesser General Public
|
|
|
|
// License as published by the Free Software Foundation; either
|
|
|
|
// version 2 of the License, or (at your option) any later version.
|
|
|
|
//
|
|
|
|
// This library is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
// Lesser General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Lesser General Public
|
|
|
|
// License along with this library; if not, write to the Free Software
|
2009-01-16 21:18:59 +03:00
|
|
|
// Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA B 02110-1301 USA
|
2007-11-18 02:28:33 +03:00
|
|
|
/////////////////////////////////////////////////////////////////////////
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2001-05-24 22:46:34 +04:00
|
|
|
#define NEED_CPU_REG_SHORTCUTS 1
|
2001-04-10 05:04:59 +04:00
|
|
|
#include "bochs.h"
|
2006-03-07 01:03:16 +03:00
|
|
|
#include "cpu.h"
|
merge in BRANCH-io-cleanup.
To see the commit logs for this use either cvsweb or
cvs update -r BRANCH-io-cleanup and then 'cvs log' the various files.
In general this provides a generic interface for logging.
logfunctions:: is a class that is inherited by some classes, and also
. allocated as a standalone global called 'genlog'. All logging uses
. one of the ::info(), ::error(), ::ldebug(), ::panic() methods of this
. class through 'BX_INFO(), BX_ERROR(), BX_DEBUG(), BX_PANIC()' macros
. respectively.
.
. An example usage:
. BX_INFO(("Hello, World!\n"));
iofunctions:: is a class that is allocated once by default, and assigned
as the iofunction of each logfunctions instance. It is this class that
maintains the file descriptor and other output related code, at this
point using vfprintf(). At some future point, someone may choose to
write a gui 'console' for bochs to which messages would be redirected
simply by assigning a different iofunction class to the various logfunctions
objects.
More cleanup is coming, but this works for now. If you want to see alot
of debugging output, in main.cc, change onoff[LOGLEV_DEBUG]=0 to =1.
Comments, bugs, flames, to me: todd@fries.net
2001-05-15 18:49:57 +04:00
|
|
|
#define LOG_THIS BX_CPU_THIS_PTR
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
// Notes:
|
|
|
|
// ======
|
|
|
|
|
|
|
|
// ======================
|
|
|
|
// 286 Task State Segment
|
|
|
|
// ======================
|
|
|
|
// dynamic item | hex dec offset
|
|
|
|
// 0 task LDT selector | 2a 42
|
|
|
|
// 1 DS selector | 28 40
|
|
|
|
// 1 SS selector | 26 38
|
|
|
|
// 1 CS selector | 24 36
|
|
|
|
// 1 ES selector | 22 34
|
|
|
|
// 1 DI | 20 32
|
|
|
|
// 1 SI | 1e 30
|
|
|
|
// 1 BP | 1c 28
|
|
|
|
// 1 SP | 1a 26
|
|
|
|
// 1 BX | 18 24
|
|
|
|
// 1 DX | 16 22
|
|
|
|
// 1 CX | 14 20
|
|
|
|
// 1 AX | 12 18
|
|
|
|
// 1 flag word | 10 16
|
|
|
|
// 1 IP (entry point) | 0e 14
|
|
|
|
// 0 SS for CPL 2 | 0c 12
|
|
|
|
// 0 SP for CPL 2 | 0a 10
|
|
|
|
// 0 SS for CPL 1 | 08 08
|
|
|
|
// 0 SP for CPL 1 | 06 06
|
|
|
|
// 0 SS for CPL 0 | 04 04
|
|
|
|
// 0 SP for CPL 0 | 02 02
|
|
|
|
// back link selector to TSS | 00 00
|
|
|
|
|
|
|
|
|
|
|
|
// ======================
|
|
|
|
// 386 Task State Segment
|
|
|
|
// ======================
|
2008-04-28 22:14:50 +04:00
|
|
|
// |31 16|15 0| hex dec
|
2019-12-20 10:42:07 +03:00
|
|
|
// | SSP | 68 104 dynamic
|
2008-04-28 22:14:50 +04:00
|
|
|
// |I/O Map Base |000000000000000000000|T| 64 100 static
|
|
|
|
// |0000000000000000| LDT | 60 96 static
|
|
|
|
// |0000000000000000| GS selector | 5c 92 dynamic
|
|
|
|
// |0000000000000000| FS selector | 58 88 dynamic
|
|
|
|
// |0000000000000000| DS selector | 54 84 dynamic
|
|
|
|
// |0000000000000000| SS selector | 50 80 dynamic
|
|
|
|
// |0000000000000000| CS selector | 4c 76 dynamic
|
|
|
|
// |0000000000000000| ES selector | 48 72 dynamic
|
|
|
|
// | EDI | 44 68 dynamic
|
|
|
|
// | ESI | 40 64 dynamic
|
|
|
|
// | EBP | 3c 60 dynamic
|
|
|
|
// | ESP | 38 56 dynamic
|
|
|
|
// | EBX | 34 52 dynamic
|
2009-05-07 16:02:34 +04:00
|
|
|
// | EDX | 30 48 dynamic
|
2008-04-28 22:14:50 +04:00
|
|
|
// | ECX | 2c 44 dynamic
|
|
|
|
// | EAX | 28 40 dynamic
|
|
|
|
// | EFLAGS | 24 36 dynamic
|
|
|
|
// | EIP (entry point) | 20 32 dynamic
|
|
|
|
// | CR3 (PDPR) | 1c 28 static
|
|
|
|
// |000000000000000 | SS for CPL 2 | 18 24 static
|
|
|
|
// | ESP for CPL 2 | 14 20 static
|
|
|
|
// |000000000000000 | SS for CPL 1 | 10 16 static
|
|
|
|
// | ESP for CPL 1 | 0c 12 static
|
|
|
|
// |000000000000000 | SS for CPL 0 | 08 08 static
|
|
|
|
// | ESP for CPL 0 | 04 04 static
|
|
|
|
// |000000000000000 | back link to prev TSS | 00 00 dynamic (updated only when return expected)
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
|
|
|
|
// ==================================================
|
|
|
|
// Effect of task switch on Busy, NT, and Link Fields
|
|
|
|
// ==================================================
|
|
|
|
|
|
|
|
// Field jump call/interrupt iret
|
|
|
|
// ------------------------------------------------------
|
|
|
|
// new busy bit Set Set No change
|
|
|
|
// old busy bit Cleared No change Cleared
|
|
|
|
// new NT flag No change Set No change
|
|
|
|
// old NT flag No change No change Cleared
|
|
|
|
// new link No change old TSS selector No change
|
|
|
|
// old link No change No change No change
|
|
|
|
// CR0.TS Set Set Set
|
|
|
|
|
|
|
|
// Note: I checked 386, 486, and Pentium, and they all exhibited
|
|
|
|
// exactly the same behaviour as above. There seems to
|
|
|
|
// be some misprints in the Intel docs.
|
|
|
|
|
2009-01-31 13:43:24 +03:00
|
|
|
void BX_CPU_C::task_switch(bxInstruction_c *i, bx_selector_t *tss_selector,
|
2001-04-10 05:04:59 +04:00
|
|
|
bx_descriptor_t *tss_descriptor, unsigned source,
|
2012-01-12 00:21:29 +04:00
|
|
|
Bit32u dword1, Bit32u dword2, bx_bool push_error, Bit32u error_code)
|
2001-04-10 05:04:59 +04:00
|
|
|
{
|
|
|
|
Bit32u obase32; // base address of old TSS
|
|
|
|
Bit32u nbase32; // base address of new TSS
|
|
|
|
Bit32u temp32, newCR3;
|
|
|
|
Bit16u raw_cs_selector, raw_ss_selector, raw_ds_selector, raw_es_selector,
|
|
|
|
raw_fs_selector, raw_gs_selector, raw_ldt_selector;
|
2009-10-08 22:07:50 +04:00
|
|
|
Bit16u trap_word;
|
2001-04-10 05:04:59 +04:00
|
|
|
bx_selector_t cs_selector, ss_selector, ds_selector, es_selector,
|
|
|
|
fs_selector, gs_selector, ldt_selector;
|
2005-08-28 21:37:37 +04:00
|
|
|
bx_descriptor_t cs_descriptor, ss_descriptor, ldt_descriptor;
|
2001-04-10 05:04:59 +04:00
|
|
|
Bit32u old_TSS_max, new_TSS_max, old_TSS_limit, new_TSS_limit;
|
|
|
|
Bit32u newEAX, newECX, newEDX, newEBX;
|
|
|
|
Bit32u newESP, newEBP, newESI, newEDI;
|
2005-11-22 00:10:59 +03:00
|
|
|
Bit32u newEFLAGS, newEIP;
|
2019-12-20 10:42:07 +03:00
|
|
|
#if BX_SUPPORT_CET
|
|
|
|
bx_bool pushCSLIPSSP = false, verifyCSLIP = false;
|
|
|
|
Bit64u tempSSP = 0, shadowLIP = 0, shadowCS = 0; // silence compiler warnings
|
|
|
|
Bit32u oldSSP = 0, oldCS = 0, oldRIP = 0;
|
|
|
|
Bit32u newSSP = 0;
|
|
|
|
#endif
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2006-06-10 02:29:07 +04:00
|
|
|
BX_DEBUG(("TASKING: ENTER"));
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
invalidate_prefetch_q();
|
|
|
|
|
|
|
|
// Discard any traps and inhibits for new context; traps will
|
|
|
|
// resume upon return.
|
2013-03-15 12:26:22 +04:00
|
|
|
BX_CPU_THIS_PTR debug_trap &= ~BX_DEBUG_SINGLE_STEP_BIT;
|
2001-04-10 05:04:59 +04:00
|
|
|
BX_CPU_THIS_PTR inhibit_mask = 0;
|
|
|
|
|
2005-11-22 00:10:59 +03:00
|
|
|
// STEP 1: The following checks are made before calling task_switch(),
|
|
|
|
// for JMP & CALL only. These checks are NOT made for exceptions,
|
|
|
|
// interrupts & IRET.
|
2001-04-10 05:04:59 +04:00
|
|
|
//
|
|
|
|
// 1) TSS DPL must be >= CPL
|
|
|
|
// 2) TSS DPL must be >= TSS selector RPL
|
2005-12-13 01:01:22 +03:00
|
|
|
// 3) TSS descriptor is not busy.
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2005-11-22 00:10:59 +03:00
|
|
|
// STEP 2: The processor performs limit-checking on the target TSS
|
|
|
|
// to verify that the TSS limit is greater than or equal
|
|
|
|
// to 67h (2Bh for 16-bit TSS).
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
// Gather info about new TSS
|
|
|
|
if (tss_descriptor->type <= 3) { // {1,3}
|
2008-04-28 22:14:50 +04:00
|
|
|
new_TSS_max = 0x2B;
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
else { // tss_descriptor->type = {9,11}
|
2008-04-28 22:14:50 +04:00
|
|
|
new_TSS_max = 0x67;
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2019-12-20 10:42:07 +03:00
|
|
|
#if BX_SUPPORT_CET
|
|
|
|
if (BX_CPU_THIS_PTR cr4.get_CET()) {
|
|
|
|
if (tss_descriptor->type <= 3) {
|
|
|
|
BX_ERROR(("task_switch(): 286 TSS when CR4.CET is enabled"));
|
|
|
|
exception(BX_TS_EXCEPTION, tss_selector->value & 0xfffc);
|
|
|
|
}
|
|
|
|
new_TSS_max = 0x6B; // add space for SPP
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2010-02-15 11:42:57 +03:00
|
|
|
nbase32 = (Bit32u) tss_descriptor->u.segment.base;
|
2009-04-05 23:09:44 +04:00
|
|
|
new_TSS_limit = tss_descriptor->u.segment.limit_scaled;
|
2006-05-22 00:41:48 +04:00
|
|
|
|
2009-04-14 13:23:36 +04:00
|
|
|
if (new_TSS_limit < new_TSS_max) {
|
2005-11-22 00:10:59 +03:00
|
|
|
BX_ERROR(("task_switch(): new TSS limit < %d", new_TSS_max));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, tss_selector->value & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
|
|
|
|
2011-12-28 20:12:28 +04:00
|
|
|
#if BX_SUPPORT_SVM
|
|
|
|
if (BX_CPU_THIS_PTR in_svm_guest) {
|
2012-01-12 00:21:29 +04:00
|
|
|
if (SVM_INTERCEPT(SVM_INTERCEPT0_TASK_SWITCH))
|
|
|
|
SvmInterceptTaskSwitch(tss_selector->value, source, push_error, error_code);
|
2011-12-28 20:12:28 +04:00
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2009-01-31 13:43:24 +03:00
|
|
|
#if BX_SUPPORT_VMX
|
2011-08-10 00:50:51 +04:00
|
|
|
if (BX_CPU_THIS_PTR in_vmx_guest)
|
2012-07-26 20:03:26 +04:00
|
|
|
VMexit_TaskSwitch(tss_selector->value, source);
|
2009-01-31 13:43:24 +03:00
|
|
|
#endif
|
|
|
|
|
2009-01-21 00:28:43 +03:00
|
|
|
// Gather info about old TSS
|
|
|
|
if (BX_CPU_THIS_PTR tr.cache.type <= 3) {
|
|
|
|
old_TSS_max = 0x29;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
old_TSS_max = 0x5F;
|
|
|
|
}
|
|
|
|
|
2009-04-05 23:09:44 +04:00
|
|
|
obase32 = (Bit32u) BX_CPU_THIS_PTR tr.cache.u.segment.base; // old TSS.base
|
|
|
|
old_TSS_limit = BX_CPU_THIS_PTR tr.cache.u.segment.limit_scaled;
|
2009-01-21 00:28:43 +03:00
|
|
|
|
2008-04-25 15:39:51 +04:00
|
|
|
if (old_TSS_limit < old_TSS_max) {
|
|
|
|
BX_ERROR(("task_switch(): old TSS limit < %d", old_TSS_max));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, BX_CPU_THIS_PTR tr.selector.value & 0xfffc);
|
2008-04-25 15:39:51 +04:00
|
|
|
}
|
|
|
|
|
2005-12-13 01:01:22 +03:00
|
|
|
if (obase32 == nbase32) {
|
|
|
|
BX_INFO(("TASK SWITCH: switching to the same TSS !"));
|
|
|
|
}
|
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
// Check that old TSS, new TSS, and all segment descriptors
|
|
|
|
// used in the task switch are paged in.
|
2007-07-09 19:16:14 +04:00
|
|
|
if (BX_CPU_THIS_PTR cr0.get_PG())
|
2005-03-05 00:03:22 +03:00
|
|
|
{
|
2019-12-09 21:37:02 +03:00
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(nbase32, 0), nbase32, 0, BX_READ); // old TSS
|
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(nbase32 + new_TSS_max, 0), nbase32 + new_TSS_max, 0, BX_READ);
|
2002-09-10 01:59:10 +04:00
|
|
|
|
|
|
|
// ??? Humm, we check the new TSS region with READ above,
|
|
|
|
// but sometimes we need to write the link field in that
|
|
|
|
// region. We also sometimes update other fields, perhaps
|
|
|
|
// we need to WRITE check them here also, so that we keep
|
|
|
|
// the written state consistent (ie, we don't encounter a
|
|
|
|
// page fault in the middle).
|
2005-11-22 00:10:59 +03:00
|
|
|
|
2009-01-16 00:52:52 +03:00
|
|
|
if (source == BX_TASK_FROM_CALL || source == BX_TASK_FROM_INT)
|
2005-11-22 00:10:59 +03:00
|
|
|
{
|
2019-12-09 21:37:02 +03:00
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(nbase32, 0), nbase32, 0, BX_WRITE);
|
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(nbase32 + 1, 0), nbase32 + 1, 0, BX_WRITE);
|
2005-11-22 00:10:59 +03:00
|
|
|
}
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2005-11-22 00:10:59 +03:00
|
|
|
// Privilege and busy checks done in CALL, JUMP, INT, IRET
|
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 3: If JMP or IRET, clear busy bit in old task TSS descriptor,
|
|
|
|
// otherwise leave set.
|
2005-11-22 00:10:59 +03:00
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// effect on Busy bit of old task
|
|
|
|
if (source == BX_TASK_FROM_JUMP || source == BX_TASK_FROM_IRET) {
|
|
|
|
// Bit is cleared
|
|
|
|
Bit32u laddr = (Bit32u) BX_CPU_THIS_PTR gdtr.base + (BX_CPU_THIS_PTR tr.selector.index<<3) + 4;
|
2014-07-03 10:40:42 +04:00
|
|
|
access_read_linear(laddr, 4, 0, BX_RW, 0x0, &temp32);
|
2010-02-11 11:06:25 +03:00
|
|
|
temp32 &= ~0x200;
|
2019-12-20 10:42:07 +03:00
|
|
|
access_write_linear(laddr, 4, 0, BX_WRITE, 0x0, &temp32);
|
2010-02-11 11:06:25 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
// STEP 4: If the task switch was initiated with an IRET instruction,
|
|
|
|
// clears the NT flag in a temporarily saved EFLAGS image;
|
|
|
|
// if initiated with a CALL or JMP instruction, an exception, or
|
|
|
|
// an interrupt, the NT flag is left unchanged.
|
2005-11-22 00:10:59 +03:00
|
|
|
|
|
|
|
Bit32u oldEFLAGS = read_eflags();
|
|
|
|
|
|
|
|
/* if moving to busy task, clear NT bit */
|
|
|
|
if (tss_descriptor->type == BX_SYS_SEGMENT_BUSY_286_TSS ||
|
|
|
|
tss_descriptor->type == BX_SYS_SEGMENT_BUSY_386_TSS)
|
|
|
|
{
|
|
|
|
oldEFLAGS &= ~EFlagsNTMask;
|
|
|
|
}
|
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// STEP 5: Save the current task state in the TSS. Up to this point,
|
|
|
|
// any exception that occurs aborts the task switch without
|
|
|
|
// changing the processor state.
|
|
|
|
|
|
|
|
/* save current machine state in old task's TSS */
|
|
|
|
|
2005-11-22 00:10:59 +03:00
|
|
|
if (BX_CPU_THIS_PTR tr.cache.type <= 3) {
|
2009-05-07 16:00:02 +04:00
|
|
|
// check that we won't page fault while writing
|
|
|
|
if (BX_CPU_THIS_PTR cr0.get_PG()) {
|
2013-01-27 23:27:30 +04:00
|
|
|
Bit32u start = Bit32u(obase32 + 14), end = Bit32u(obase32 + 41);
|
|
|
|
|
2019-12-09 21:37:02 +03:00
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(start, 0), start, 0, BX_WRITE);
|
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(end, 0), end, 0, BX_WRITE);
|
2009-05-07 16:00:02 +04:00
|
|
|
}
|
|
|
|
|
2009-10-08 22:07:50 +04:00
|
|
|
system_write_word(Bit32u(obase32 + 14), IP);
|
|
|
|
system_write_word(Bit32u(obase32 + 16), oldEFLAGS);
|
|
|
|
system_write_word(Bit32u(obase32 + 18), AX);
|
|
|
|
system_write_word(Bit32u(obase32 + 20), CX);
|
|
|
|
system_write_word(Bit32u(obase32 + 22), DX);
|
|
|
|
system_write_word(Bit32u(obase32 + 24), BX);
|
|
|
|
system_write_word(Bit32u(obase32 + 26), SP);
|
|
|
|
system_write_word(Bit32u(obase32 + 28), BP);
|
|
|
|
system_write_word(Bit32u(obase32 + 30), SI);
|
|
|
|
system_write_word(Bit32u(obase32 + 32), DI);
|
|
|
|
|
|
|
|
system_write_word(Bit32u(obase32 + 34),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_ES].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 36),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 38),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 40),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_DS].selector.value);
|
2005-11-22 00:10:59 +03:00
|
|
|
}
|
|
|
|
else {
|
2009-05-07 16:00:02 +04:00
|
|
|
// check that we won't page fault while writing
|
|
|
|
if (BX_CPU_THIS_PTR cr0.get_PG()) {
|
2013-01-27 23:27:30 +04:00
|
|
|
Bit32u start = Bit32u(obase32 + 0x20), end = Bit32u(obase32 + 0x5d);
|
|
|
|
|
2019-12-09 21:37:02 +03:00
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(start, 0), start, 0, BX_WRITE);
|
|
|
|
translate_linear(BX_DTLB_ENTRY_OF(end, 0), end, 0, BX_WRITE);
|
2009-05-07 16:00:02 +04:00
|
|
|
}
|
|
|
|
|
2009-10-08 22:07:50 +04:00
|
|
|
system_write_dword(Bit32u(obase32 + 0x20), EIP);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x24), oldEFLAGS);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x28), EAX);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x2c), ECX);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x30), EDX);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x34), EBX);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x38), ESP);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x3c), EBP);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x40), ESI);
|
|
|
|
system_write_dword(Bit32u(obase32 + 0x44), EDI);
|
|
|
|
|
|
|
|
system_write_word(Bit32u(obase32 + 0x48),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_ES].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 0x4c),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 0x50),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 0x54),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_DS].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 0x58),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_FS].selector.value);
|
|
|
|
system_write_word(Bit32u(obase32 + 0x5c),
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_GS].selector.value);
|
2005-11-22 00:10:59 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
// effect on link field of new task
|
2009-01-16 00:52:52 +03:00
|
|
|
if (source == BX_TASK_FROM_CALL || source == BX_TASK_FROM_INT)
|
2005-11-22 00:10:59 +03:00
|
|
|
{
|
|
|
|
// set to selector of old task's TSS
|
2009-10-08 22:07:50 +04:00
|
|
|
system_write_word(nbase32, BX_CPU_THIS_PTR tr.selector.value);
|
2005-11-22 00:10:59 +03:00
|
|
|
}
|
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// STEP 6: The new-task state is loaded from the TSS
|
2008-04-20 00:00:28 +04:00
|
|
|
|
|
|
|
if (tss_descriptor->type <= 3) {
|
2008-09-06 21:44:02 +04:00
|
|
|
newEIP = system_read_word(Bit32u(nbase32 + 14));
|
|
|
|
newEFLAGS = system_read_word(Bit32u(nbase32 + 16));
|
2008-04-20 00:00:28 +04:00
|
|
|
|
|
|
|
// incoming TSS is 16bit:
|
|
|
|
// - upper word of general registers is set to 0xFFFF
|
|
|
|
// - upper word of eflags is zero'd
|
|
|
|
// - FS, GS are zero'd
|
|
|
|
// - upper word of eIP is zero'd
|
2009-10-08 22:07:50 +04:00
|
|
|
Bit16u temp16 = system_read_word(Bit32u(nbase32 + 18));
|
2008-04-20 00:00:28 +04:00
|
|
|
newEAX = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 20));
|
2008-04-20 00:00:28 +04:00
|
|
|
newECX = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 22));
|
2008-04-20 00:00:28 +04:00
|
|
|
newEDX = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 24));
|
2008-04-20 00:00:28 +04:00
|
|
|
newEBX = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 26));
|
2008-04-20 00:00:28 +04:00
|
|
|
newESP = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 28));
|
2008-04-20 00:00:28 +04:00
|
|
|
newEBP = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 30));
|
2008-04-20 00:00:28 +04:00
|
|
|
newESI = 0xffff0000 | temp16;
|
2008-09-06 21:44:02 +04:00
|
|
|
temp16 = system_read_word(Bit32u(nbase32 + 32));
|
2008-04-20 00:00:28 +04:00
|
|
|
newEDI = 0xffff0000 | temp16;
|
|
|
|
|
2008-09-06 21:44:02 +04:00
|
|
|
raw_es_selector = system_read_word(Bit32u(nbase32 + 34));
|
|
|
|
raw_cs_selector = system_read_word(Bit32u(nbase32 + 36));
|
|
|
|
raw_ss_selector = system_read_word(Bit32u(nbase32 + 38));
|
|
|
|
raw_ds_selector = system_read_word(Bit32u(nbase32 + 40));
|
|
|
|
raw_ldt_selector = system_read_word(Bit32u(nbase32 + 42));
|
2008-04-20 00:00:28 +04:00
|
|
|
|
|
|
|
raw_fs_selector = 0; // use a NULL selector
|
|
|
|
raw_gs_selector = 0; // use a NULL selector
|
|
|
|
// No CR3 change for 286 task switch
|
|
|
|
newCR3 = 0; // keep compiler happy (not used)
|
|
|
|
trap_word = 0; // keep compiler happy (not used)
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
if (BX_CPU_THIS_PTR cr0.get_PG())
|
2008-09-06 21:44:02 +04:00
|
|
|
newCR3 = system_read_dword(Bit32u(nbase32 + 0x1c));
|
2008-04-20 00:00:28 +04:00
|
|
|
else
|
|
|
|
newCR3 = 0; // keep compiler happy (not used)
|
2008-09-06 21:44:02 +04:00
|
|
|
|
|
|
|
newEIP = system_read_dword(Bit32u(nbase32 + 0x20));
|
|
|
|
newEFLAGS = system_read_dword(Bit32u(nbase32 + 0x24));
|
|
|
|
newEAX = system_read_dword(Bit32u(nbase32 + 0x28));
|
|
|
|
newECX = system_read_dword(Bit32u(nbase32 + 0x2c));
|
|
|
|
newEDX = system_read_dword(Bit32u(nbase32 + 0x30));
|
|
|
|
newEBX = system_read_dword(Bit32u(nbase32 + 0x34));
|
|
|
|
newESP = system_read_dword(Bit32u(nbase32 + 0x38));
|
|
|
|
newEBP = system_read_dword(Bit32u(nbase32 + 0x3c));
|
|
|
|
newESI = system_read_dword(Bit32u(nbase32 + 0x40));
|
|
|
|
newEDI = system_read_dword(Bit32u(nbase32 + 0x44));
|
|
|
|
|
|
|
|
raw_es_selector = system_read_word(Bit32u(nbase32 + 0x48));
|
|
|
|
raw_cs_selector = system_read_word(Bit32u(nbase32 + 0x4c));
|
|
|
|
raw_ss_selector = system_read_word(Bit32u(nbase32 + 0x50));
|
|
|
|
raw_ds_selector = system_read_word(Bit32u(nbase32 + 0x54));
|
|
|
|
raw_fs_selector = system_read_word(Bit32u(nbase32 + 0x58));
|
|
|
|
raw_gs_selector = system_read_word(Bit32u(nbase32 + 0x5c));
|
|
|
|
raw_ldt_selector = system_read_word(Bit32u(nbase32 + 0x60));
|
|
|
|
trap_word = system_read_word(Bit32u(nbase32 + 0x64));
|
2019-12-20 10:42:07 +03:00
|
|
|
|
|
|
|
#if BX_SUPPORT_CET
|
|
|
|
if (BX_CPU_THIS_PTR cr4.get_CET() && source != BX_TASK_FROM_IRET)
|
|
|
|
newSSP = system_read_dword(Bit32u(nbase32 + 0x68));
|
|
|
|
#endif
|
2008-04-20 00:00:28 +04:00
|
|
|
}
|
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 7: If CALL, interrupt, or JMP, set busy flag in new task's
|
2005-11-22 00:10:59 +03:00
|
|
|
// TSS descriptor. If IRET, leave set.
|
|
|
|
|
2009-01-16 00:52:52 +03:00
|
|
|
if (source != BX_TASK_FROM_IRET)
|
2005-11-22 00:10:59 +03:00
|
|
|
{
|
|
|
|
// set the new task's busy bit
|
2008-04-19 15:08:39 +04:00
|
|
|
Bit32u laddr = (Bit32u)(BX_CPU_THIS_PTR gdtr.base) + (tss_selector->index<<3) + 4;
|
2014-07-03 10:40:42 +04:00
|
|
|
access_read_linear(laddr, 4, 0, BX_RW, 0x0, &dword2);
|
2008-04-19 15:08:39 +04:00
|
|
|
dword2 |= 0x200;
|
2019-12-20 10:42:07 +03:00
|
|
|
access_write_linear(laddr, 4, 0, BX_WRITE, 0x0, &dword2);
|
|
|
|
}
|
|
|
|
|
|
|
|
#if BX_SUPPORT_CET
|
|
|
|
if (ShadowStackEnabled(CPL)) {
|
|
|
|
unsigned new_CPL = (newEFLAGS & EFlagsVMMask) ? 3 : BX_SELECTOR_RPL(raw_cs_selector);
|
|
|
|
if (source == BX_TASK_FROM_CALL || source == BX_TASK_FROM_INT) {
|
|
|
|
if (new_CPL < CPL && CPL == 3) {
|
|
|
|
BX_CPU_THIS_PTR msr.ia32_pl_ssp[3] = SSP;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
pushCSLIPSSP = true;
|
|
|
|
oldSSP = SSP;
|
|
|
|
oldCS = BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].selector.value;
|
|
|
|
oldRIP = get_laddr(BX_SEG_REG_CS, EIP);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (source == BX_TASK_FROM_IRET) {
|
|
|
|
if (new_CPL == CPL || new_CPL < 3) {
|
|
|
|
tempSSP = shadow_stack_pop_64();
|
|
|
|
shadowLIP = shadow_stack_pop_64();
|
|
|
|
shadowCS = shadow_stack_pop_64();
|
|
|
|
verifyCSLIP = true;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
tempSSP = BX_CPU_THIS_PTR msr.ia32_pl_ssp[3];
|
|
|
|
}
|
|
|
|
shadow_stack_atomic_clear_busy(SSP, CPL);
|
|
|
|
SSP = 0;
|
|
|
|
}
|
2005-11-22 00:10:59 +03:00
|
|
|
}
|
2019-12-20 10:42:07 +03:00
|
|
|
#endif
|
2005-11-22 00:10:59 +03:00
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
//
|
|
|
|
// Commit point. At this point, we commit to the new
|
|
|
|
// context. If an unrecoverable error occurs in further
|
|
|
|
// processing, we complete the task switch without performing
|
|
|
|
// additional access and segment availablility checks and
|
|
|
|
// generate the appropriate exception prior to beginning
|
|
|
|
// execution of the new task.
|
|
|
|
//
|
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 8: Load the task register with the segment selector and
|
|
|
|
// descriptor for the new task TSS.
|
2005-11-22 00:10:59 +03:00
|
|
|
|
|
|
|
BX_CPU_THIS_PTR tr.selector = *tss_selector;
|
|
|
|
BX_CPU_THIS_PTR tr.cache = *tss_descriptor;
|
2008-04-19 15:08:39 +04:00
|
|
|
BX_CPU_THIS_PTR tr.cache.type |= 2; // mark TSS in TR as busy
|
2005-11-22 00:10:59 +03:00
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 9: Set TS flag in the CR0 image stored in the new task TSS.
|
2007-07-09 19:16:14 +04:00
|
|
|
BX_CPU_THIS_PTR cr0.set_TS(1);
|
2005-11-22 00:10:59 +03:00
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
// Task switch clears LE/L3/L2/L1/L0 in DR7
|
2011-03-15 23:20:15 +03:00
|
|
|
BX_CPU_THIS_PTR dr7.val32 &= ~0x00000155;
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 10: If call or interrupt, set the NT flag in the eflags
|
|
|
|
// image stored in new task's TSS. If IRET or JMP,
|
|
|
|
// NT is restored from new TSS eflags image. (no change)
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
// effect on NT flag of new task
|
2009-01-16 00:52:52 +03:00
|
|
|
if (source == BX_TASK_FROM_CALL || source == BX_TASK_FROM_INT) {
|
2005-11-22 00:10:59 +03:00
|
|
|
newEFLAGS |= EFlagsNTMask; // NT flag is set
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 11: Load the new task (dynamic) state from new TSS.
|
2001-04-10 05:04:59 +04:00
|
|
|
// Any errors associated with loading and qualification of
|
|
|
|
// segment descriptors in this step occur in the new task's
|
|
|
|
// context. State loaded here includes LDTR, CR3,
|
|
|
|
// EFLAGS, EIP, general purpose registers, and segment
|
|
|
|
// descriptor parts of the segment registers.
|
|
|
|
|
2007-11-24 17:22:34 +03:00
|
|
|
BX_CPU_THIS_PTR prev_rip = EIP = newEIP;
|
2005-11-22 00:10:59 +03:00
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
EAX = newEAX;
|
|
|
|
ECX = newECX;
|
|
|
|
EDX = newEDX;
|
|
|
|
EBX = newEBX;
|
|
|
|
ESP = newESP;
|
|
|
|
EBP = newEBP;
|
|
|
|
ESI = newESI;
|
|
|
|
EDI = newEDI;
|
|
|
|
|
2010-02-08 17:22:39 +03:00
|
|
|
BX_CPU_THIS_PTR speculative_rsp = 0;
|
|
|
|
|
2005-11-22 00:10:59 +03:00
|
|
|
writeEFlags(newEFLAGS, EFlagsValidMask);
|
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
// Fill in selectors for all segment registers. If errors
|
|
|
|
// occur later, the selectors will at least be loaded.
|
|
|
|
parse_selector(raw_cs_selector, &cs_selector);
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].selector = cs_selector;
|
2008-09-22 23:53:47 +04:00
|
|
|
parse_selector(raw_ss_selector, &ss_selector);
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS].selector = ss_selector;
|
2001-04-10 05:04:59 +04:00
|
|
|
parse_selector(raw_ds_selector, &ds_selector);
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_DS].selector = ds_selector;
|
2005-11-22 00:10:59 +03:00
|
|
|
parse_selector(raw_es_selector, &es_selector);
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_ES].selector = es_selector;
|
2001-04-10 05:04:59 +04:00
|
|
|
parse_selector(raw_fs_selector, &fs_selector);
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_FS].selector = fs_selector;
|
|
|
|
parse_selector(raw_gs_selector, &gs_selector);
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_GS].selector = gs_selector;
|
|
|
|
parse_selector(raw_ldt_selector, &ldt_selector);
|
2005-11-22 00:10:59 +03:00
|
|
|
BX_CPU_THIS_PTR ldtr.selector = ldt_selector;
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2008-09-22 23:53:47 +04:00
|
|
|
// Start out with invalid descriptor caches, fill in with
|
|
|
|
// values only as they are validated
|
2001-04-10 05:04:59 +04:00
|
|
|
BX_CPU_THIS_PTR ldtr.cache.valid = 0;
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].cache.valid = 0;
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS].cache.valid = 0;
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_DS].cache.valid = 0;
|
2008-09-22 23:53:47 +04:00
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_ES].cache.valid = 0;
|
2001-04-10 05:04:59 +04:00
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_FS].cache.valid = 0;
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_GS].cache.valid = 0;
|
|
|
|
|
2008-09-22 23:53:47 +04:00
|
|
|
if ((tss_descriptor->type >= 9) && BX_CPU_THIS_PTR cr0.get_PG()) {
|
|
|
|
// change CR3 only if it actually modified
|
|
|
|
if (newCR3 != BX_CPU_THIS_PTR cr3) {
|
2010-06-18 18:24:45 +04:00
|
|
|
BX_DEBUG(("task_switch changing CR3 to 0x%08x", newCR3));
|
2012-03-26 23:05:58 +04:00
|
|
|
|
|
|
|
if (! SetCR3(newCR3)) // Tell paging unit about new cr3 value
|
|
|
|
exception(BX_TS_EXCEPTION, 0);
|
|
|
|
|
2010-04-03 22:00:30 +04:00
|
|
|
#if BX_CPU_LEVEL >= 6
|
|
|
|
if (BX_CPU_THIS_PTR cr0.get_PG() && BX_CPU_THIS_PTR cr4.get_PAE()) {
|
|
|
|
if (! CheckPDPTR(newCR3)) {
|
2010-04-14 21:33:19 +04:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): PDPTR check failed !"));
|
2012-03-26 23:05:58 +04:00
|
|
|
|
|
|
|
// clear PDPTRs before raising task switch exception
|
|
|
|
for (unsigned n=0; n<4; n++)
|
|
|
|
BX_CPU_THIS_PTR PDPTR_CACHE.entry[n] = 0;
|
|
|
|
|
|
|
|
exception(BX_TS_EXCEPTION, 0);
|
2010-04-03 22:00:30 +04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
2012-03-26 23:05:58 +04:00
|
|
|
|
2011-11-28 14:08:03 +04:00
|
|
|
BX_INSTR_TLB_CNTRL(BX_CPU_ID, BX_INSTR_TASK_SWITCH, newCR3);
|
2008-09-22 23:53:47 +04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2009-05-01 18:59:21 +04:00
|
|
|
unsigned save_CPL = CPL;
|
|
|
|
/* set CPL to 3 to force a privilege level change and stack switch if SS
|
|
|
|
is not properly loaded */
|
|
|
|
CPL = 3;
|
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
// LDTR
|
|
|
|
if (ldt_selector.ti) {
|
|
|
|
// LDT selector must be in GDT
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_INFO(("task_switch(exception after commit point): bad LDT selector TI=1"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ldt_selector & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2008-02-15 22:03:54 +03:00
|
|
|
if ((raw_ldt_selector & 0xfffc) != 0) {
|
2005-03-05 00:03:22 +03:00
|
|
|
bx_bool good = fetch_raw_descriptor2(&ldt_selector, &dword1, &dword2);
|
2001-04-10 05:04:59 +04:00
|
|
|
if (!good) {
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): bad LDT fetch"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ldt_selector & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
parse_descriptor(dword1, dword2, &ldt_descriptor);
|
|
|
|
|
|
|
|
// LDT selector of new task is valid, else #TS(new task's LDT)
|
|
|
|
if (ldt_descriptor.valid==0 ||
|
2005-03-05 00:03:22 +03:00
|
|
|
ldt_descriptor.type!=BX_SYS_SEGMENT_LDT ||
|
2005-08-21 22:23:36 +04:00
|
|
|
ldt_descriptor.segment)
|
2005-03-05 00:03:22 +03:00
|
|
|
{
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): bad LDT segment"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ldt_selector & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
// LDT of new task is present in memory, else #TS(new tasks's LDT)
|
2005-07-11 00:32:32 +04:00
|
|
|
if (! IS_PRESENT(ldt_descriptor)) {
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): LDT not present"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ldt_selector & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2005-07-11 00:32:32 +04:00
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
// All checks pass, fill in LDTR shadow cache
|
|
|
|
BX_CPU_THIS_PTR ldtr.cache = ldt_descriptor;
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
else {
|
|
|
|
// NULL LDT selector is OK, leave cache invalid
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
|
|
|
if (v8086_mode()) {
|
|
|
|
// load seg regs as 8086 registers
|
|
|
|
load_seg_reg(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS], raw_ss_selector);
|
|
|
|
load_seg_reg(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_DS], raw_ds_selector);
|
|
|
|
load_seg_reg(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_ES], raw_es_selector);
|
|
|
|
load_seg_reg(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_FS], raw_fs_selector);
|
|
|
|
load_seg_reg(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_GS], raw_gs_selector);
|
2008-09-22 23:53:47 +04:00
|
|
|
load_seg_reg(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS], raw_cs_selector);
|
2009-05-01 18:59:21 +04:00
|
|
|
// CPL is set from CS selector
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
else {
|
|
|
|
|
2008-04-26 14:20:15 +04:00
|
|
|
// SS
|
|
|
|
if ((raw_ss_selector & 0xfffc) != 0)
|
|
|
|
{
|
|
|
|
bx_bool good = fetch_raw_descriptor2(&ss_selector, &dword1, &dword2);
|
|
|
|
if (!good) {
|
|
|
|
BX_ERROR(("task_switch(exception after commit point): bad SS fetch"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ss_selector & 0xfffc);
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
parse_descriptor(dword1, dword2, &ss_descriptor);
|
2008-09-22 23:53:47 +04:00
|
|
|
|
2008-04-26 14:20:15 +04:00
|
|
|
// SS selector must be within its descriptor table limits else #TS(SS)
|
|
|
|
// SS descriptor AR byte must must indicate writable data segment,
|
|
|
|
// else #TS(SS)
|
|
|
|
if (ss_descriptor.valid==0 || ss_descriptor.segment==0 ||
|
|
|
|
IS_CODE_SEGMENT(ss_descriptor.type) ||
|
|
|
|
!IS_DATA_SEGMENT_WRITEABLE(ss_descriptor.type))
|
|
|
|
{
|
|
|
|
BX_ERROR(("task_switch(exception after commit point): SS not valid or writeable segment"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ss_selector & 0xfffc);
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
//
|
|
|
|
// Stack segment is present in memory, else #SS(new stack segment)
|
|
|
|
//
|
|
|
|
if (! IS_PRESENT(ss_descriptor)) {
|
|
|
|
BX_ERROR(("task_switch(exception after commit point): SS not present"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_SS_EXCEPTION, raw_ss_selector & 0xfffc);
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
// Stack segment DPL matches CS.RPL, else #TS(new stack segment)
|
|
|
|
if (ss_descriptor.dpl != cs_selector.rpl) {
|
|
|
|
BX_ERROR(("task_switch(exception after commit point): SS.rpl != CS.RPL"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ss_selector & 0xfffc);
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
// Stack segment DPL matches selector RPL, else #TS(new stack segment)
|
|
|
|
if (ss_descriptor.dpl != ss_selector.rpl) {
|
|
|
|
BX_ERROR(("task_switch(exception after commit point): SS.dpl != SS.rpl"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ss_selector & 0xfffc);
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
|
2009-07-27 09:52:28 +04:00
|
|
|
touch_segment(&ss_selector, &ss_descriptor);
|
|
|
|
|
2008-04-26 14:20:15 +04:00
|
|
|
// All checks pass, fill in shadow cache
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS].cache = ss_descriptor;
|
2012-03-25 15:54:32 +04:00
|
|
|
|
|
|
|
invalidate_stack_cache();
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
else {
|
|
|
|
// SS selector is valid, else #TS(new stack segment)
|
|
|
|
BX_ERROR(("task_switch(exception after commit point): SS NULL"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_ss_selector & 0xfffc);
|
2008-04-26 14:20:15 +04:00
|
|
|
}
|
|
|
|
|
2008-09-22 23:53:47 +04:00
|
|
|
CPL = save_CPL;
|
|
|
|
|
|
|
|
task_switch_load_selector(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_DS],
|
|
|
|
&ds_selector, raw_ds_selector, cs_selector.rpl);
|
|
|
|
task_switch_load_selector(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_ES],
|
|
|
|
&es_selector, raw_es_selector, cs_selector.rpl);
|
|
|
|
task_switch_load_selector(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_FS],
|
|
|
|
&fs_selector, raw_fs_selector, cs_selector.rpl);
|
|
|
|
task_switch_load_selector(&BX_CPU_THIS_PTR sregs[BX_SEG_REG_GS],
|
|
|
|
&gs_selector, raw_gs_selector, cs_selector.rpl);
|
|
|
|
|
2005-08-28 21:37:37 +04:00
|
|
|
// if new selector is not null then perform following checks:
|
|
|
|
// index must be within its descriptor table limits else #TS(selector)
|
|
|
|
// AR byte must indicate data or readable code else #TS(selector)
|
|
|
|
// if data or non-conforming code then:
|
|
|
|
// DPL must be >= CPL else #TS(selector)
|
|
|
|
// DPL must be >= RPL else #TS(selector)
|
|
|
|
// AR byte must indicate PRESENT else #NP(selector)
|
|
|
|
// load cache with new segment descriptor and set valid bit
|
|
|
|
|
2005-03-05 00:03:22 +03:00
|
|
|
// CS
|
2008-02-15 22:03:54 +03:00
|
|
|
if ((raw_cs_selector & 0xfffc) != 0) {
|
2005-03-05 00:03:22 +03:00
|
|
|
bx_bool good = fetch_raw_descriptor2(&cs_selector, &dword1, &dword2);
|
|
|
|
if (!good) {
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): bad CS fetch"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_cs_selector & 0xfffc);
|
2001-04-10 05:04:59 +04:00
|
|
|
}
|
|
|
|
|
2005-03-05 00:03:22 +03:00
|
|
|
parse_descriptor(dword1, dword2, &cs_descriptor);
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2005-03-05 00:03:22 +03:00
|
|
|
// CS descriptor AR byte must indicate code segment else #TS(CS)
|
|
|
|
if (cs_descriptor.valid==0 || cs_descriptor.segment==0 ||
|
2006-06-12 20:58:27 +04:00
|
|
|
IS_DATA_SEGMENT(cs_descriptor.type))
|
2005-03-05 00:03:22 +03:00
|
|
|
{
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): CS not valid executable seg"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_cs_selector & 0xfffc);
|
2001-04-10 05:04:59 +04:00
|
|
|
}
|
2005-03-05 00:03:22 +03:00
|
|
|
|
|
|
|
// if non-conforming then DPL must equal selector RPL else #TS(CS)
|
2006-06-12 20:58:27 +04:00
|
|
|
if (IS_CODE_SEGMENT_NON_CONFORMING(cs_descriptor.type) &&
|
|
|
|
cs_descriptor.dpl != cs_selector.rpl)
|
2005-03-05 00:03:22 +03:00
|
|
|
{
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): non-conforming: CS.dpl!=CS.RPL"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_cs_selector & 0xfffc);
|
2001-04-10 05:04:59 +04:00
|
|
|
}
|
2005-03-05 00:03:22 +03:00
|
|
|
|
|
|
|
// if conforming then DPL must be <= selector RPL else #TS(CS)
|
2006-06-12 20:58:27 +04:00
|
|
|
if (IS_CODE_SEGMENT_CONFORMING(cs_descriptor.type) &&
|
|
|
|
cs_descriptor.dpl > cs_selector.rpl)
|
2005-03-05 00:03:22 +03:00
|
|
|
{
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): conforming: CS.dpl>RPL"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_cs_selector & 0xfffc);
|
2001-04-10 05:04:59 +04:00
|
|
|
}
|
|
|
|
|
2005-03-05 00:03:22 +03:00
|
|
|
// Code segment is present in memory, else #NP(new code segment)
|
2005-07-11 00:32:32 +04:00
|
|
|
if (! IS_PRESENT(cs_descriptor)) {
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): CS.p==0"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_NP_EXCEPTION, raw_cs_selector & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2009-07-27 09:52:28 +04:00
|
|
|
touch_segment(&cs_selector, &cs_descriptor);
|
|
|
|
|
2010-01-31 21:06:45 +03:00
|
|
|
#ifdef BX_SUPPORT_CS_LIMIT_DEMOTION
|
2012-01-12 00:21:29 +04:00
|
|
|
// Handle special case of CS.LIMIT demotion (new descriptor limit is smaller than current one)
|
2009-12-17 14:11:58 +03:00
|
|
|
if (BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].cache.u.segment.limit_scaled > cs_descriptor.u.segment.limit_scaled)
|
|
|
|
BX_CPU_THIS_PTR iCache.flushICacheEntries();
|
|
|
|
#endif
|
|
|
|
|
2005-03-05 00:03:22 +03:00
|
|
|
// All checks pass, fill in shadow cache
|
|
|
|
BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].cache = cs_descriptor;
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
// If new cs selector is null #TS(CS)
|
2007-12-14 02:17:50 +03:00
|
|
|
BX_ERROR(("task_switch(exception after commit point): CS NULL"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_cs_selector & 0xfffc);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
|
|
|
|
2010-04-22 21:51:37 +04:00
|
|
|
updateFetchModeMask(/* CS reloaded */);
|
2006-01-16 22:22:28 +03:00
|
|
|
|
2012-03-25 23:07:17 +04:00
|
|
|
#if BX_CPU_LEVEL >= 4
|
2007-11-21 00:22:03 +03:00
|
|
|
handleAlignmentCheck(); // task switch, CPL was modified
|
|
|
|
#endif
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2010-02-11 11:06:25 +03:00
|
|
|
if (tss_descriptor->type >= 9 && (trap_word & 0x1)) {
|
2009-02-01 23:47:06 +03:00
|
|
|
BX_CPU_THIS_PTR debug_trap |= BX_DEBUG_TRAP_TASK_SWITCH_BIT; // BT flag
|
2001-04-10 05:04:59 +04:00
|
|
|
BX_CPU_THIS_PTR async_event = 1; // so processor knows to check
|
2005-11-22 00:10:59 +03:00
|
|
|
BX_INFO(("task_switch: T bit set in new TSS"));
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2010-12-23 00:16:02 +03:00
|
|
|
#if BX_CPU_LEVEL >= 6
|
|
|
|
handleSseModeChange(); /* CR0.TS changes */
|
2011-03-19 23:09:34 +03:00
|
|
|
#if BX_SUPPORT_AVX
|
|
|
|
handleAvxModeChange();
|
|
|
|
#endif
|
2010-12-23 00:16:02 +03:00
|
|
|
#endif
|
|
|
|
|
2001-04-10 05:04:59 +04:00
|
|
|
//
|
2010-02-11 11:06:25 +03:00
|
|
|
// Step 12: Begin execution of new task.
|
2001-04-10 05:04:59 +04:00
|
|
|
//
|
2008-02-15 22:03:54 +03:00
|
|
|
BX_DEBUG(("TASKING: LEAVE"));
|
2012-01-12 00:21:29 +04:00
|
|
|
|
|
|
|
RSP_SPECULATIVE;
|
|
|
|
|
2019-12-20 10:42:07 +03:00
|
|
|
#if BX_SUPPORT_CET
|
|
|
|
if (ShadowStackEnabled(CPL) || EndbranchEnabled(CPL)) {
|
|
|
|
if (v8086_mode()) {
|
|
|
|
BX_ERROR(("task_switch: Shadowstack or Enbranch enabled in vm8086 mode"));
|
|
|
|
exception(BX_TS_EXCEPTION, BX_CPU_THIS_PTR tr.selector.value & 0xfffc);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (source != BX_TASK_FROM_IRET) {
|
|
|
|
if (ShadowStackEnabled(CPL)) {
|
2020-01-07 21:17:34 +03:00
|
|
|
if (newSSP & 0x7) {
|
|
|
|
BX_ERROR(("task_switch: newSSP is not aligned to 8 byte boundary"));
|
|
|
|
exception(BX_TS_EXCEPTION, BX_CPU_THIS_PTR tr.selector.value & 0xfffc);
|
|
|
|
}
|
2019-12-20 10:42:07 +03:00
|
|
|
shadow_stack_switch(newSSP);
|
|
|
|
if (pushCSLIPSSP) {
|
|
|
|
call_far_shadow_stack_push(oldCS, oldRIP, oldSSP);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
track_indirect(CPL);
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
if (verifyCSLIP) {
|
|
|
|
if (raw_cs_selector != shadowCS) {
|
|
|
|
BX_ERROR(("task switch: CS mismatch on shadow stack restore"));
|
|
|
|
exception(BX_CP_EXCEPTION, BX_CP_FAR_RET_IRET);
|
|
|
|
}
|
|
|
|
if (get_laddr(BX_SEG_REG_CS, EIP) != shadowLIP) {
|
|
|
|
BX_ERROR(("task switch: LIP mismatch on shadow stack restore"));
|
|
|
|
exception(BX_CP_EXCEPTION, BX_CP_FAR_RET_IRET);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (ShadowStackEnabled(CPL)) {
|
|
|
|
if (tempSSP & 0x3) {
|
|
|
|
BX_ERROR(("shadow_stack_restore: tempSSP must be 4-byte aligned"));
|
|
|
|
exception(BX_CP_EXCEPTION, BX_CP_FAR_RET_IRET);
|
|
|
|
}
|
|
|
|
if (GET32H(tempSSP)!=0) {
|
|
|
|
BX_ERROR(("shadow_stack_restore: prevSSP must be 32-bit in 32-bit mode"));
|
|
|
|
exception(BX_CP_EXCEPTION, BX_CP_FAR_RET_IRET);
|
|
|
|
}
|
|
|
|
SSP = tempSSP;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2012-01-12 00:21:29 +04:00
|
|
|
// push error code onto stack
|
|
|
|
if (push_error) {
|
|
|
|
if (tss_descriptor->type >= 9) // TSS386
|
|
|
|
push_32(error_code);
|
|
|
|
else
|
|
|
|
push_16(error_code);
|
|
|
|
}
|
|
|
|
|
|
|
|
// instruction pointer must be in CS limit, else #GP(0)
|
|
|
|
if (EIP > BX_CPU_THIS_PTR sregs[BX_SEG_REG_CS].cache.u.segment.limit_scaled) {
|
|
|
|
BX_ERROR(("task_switch: EIP > CS.limit"));
|
|
|
|
exception(BX_GP_EXCEPTION, 0);
|
|
|
|
}
|
|
|
|
|
|
|
|
RSP_COMMIT;
|
2001-04-10 05:04:59 +04:00
|
|
|
}
|
|
|
|
|
2005-09-03 15:39:26 +04:00
|
|
|
void BX_CPU_C::task_switch_load_selector(bx_segment_reg_t *seg,
|
|
|
|
bx_selector_t *selector, Bit16u raw_selector, Bit8u cs_rpl)
|
2005-08-28 21:37:37 +04:00
|
|
|
{
|
|
|
|
bx_descriptor_t descriptor;
|
|
|
|
Bit32u dword1, dword2;
|
|
|
|
|
|
|
|
// NULL selector is OK, will leave cache invalid
|
2006-06-12 20:58:27 +04:00
|
|
|
if ((raw_selector & 0xfffc) != 0)
|
2005-08-28 21:37:37 +04:00
|
|
|
{
|
2005-09-03 15:39:26 +04:00
|
|
|
bx_bool good = fetch_raw_descriptor2(selector, &dword1, &dword2);
|
2005-08-28 21:37:37 +04:00
|
|
|
if (!good) {
|
|
|
|
BX_ERROR(("task_switch(%s): bad selector fetch !", strseg(seg)));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_selector & 0xfffc);
|
2005-08-28 21:37:37 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
parse_descriptor(dword1, dword2, &descriptor);
|
|
|
|
|
2006-06-12 20:58:27 +04:00
|
|
|
/* AR byte must indicate data or readable code segment else #TS(selector) */
|
2008-02-03 00:46:54 +03:00
|
|
|
if (descriptor.segment==0 || (IS_CODE_SEGMENT(descriptor.type) &&
|
2006-06-12 20:58:27 +04:00
|
|
|
IS_CODE_SEGMENT_READABLE(descriptor.type) == 0))
|
2005-08-28 21:37:37 +04:00
|
|
|
{
|
2006-06-12 20:58:27 +04:00
|
|
|
BX_ERROR(("task_switch(%s): not data or readable code !", strseg(seg)));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_selector & 0xfffc);
|
2005-08-28 21:37:37 +04:00
|
|
|
}
|
|
|
|
|
2006-06-12 20:58:27 +04:00
|
|
|
/* If data or non-conforming code, then both the RPL and the CPL
|
|
|
|
* must be less than or equal to DPL in AR byte else #GP(selector) */
|
|
|
|
if (IS_DATA_SEGMENT(descriptor.type) ||
|
|
|
|
IS_CODE_SEGMENT_NON_CONFORMING(descriptor.type))
|
2005-08-28 21:37:37 +04:00
|
|
|
{
|
2006-06-12 20:58:27 +04:00
|
|
|
if ((selector->rpl > descriptor.dpl) || (cs_rpl > descriptor.dpl)) {
|
|
|
|
BX_ERROR(("load_seg_reg(%s): RPL & CPL must be <= DPL", strseg(seg)));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, raw_selector & 0xfffc);
|
2006-06-12 20:58:27 +04:00
|
|
|
}
|
2005-08-28 21:37:37 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
if (! IS_PRESENT(descriptor)) {
|
|
|
|
BX_ERROR(("task_switch(%s): descriptor not present !", strseg(seg)));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_NP_EXCEPTION, raw_selector & 0xfffc);
|
2005-08-28 21:37:37 +04:00
|
|
|
}
|
|
|
|
|
2009-07-27 09:52:28 +04:00
|
|
|
touch_segment(selector, &descriptor);
|
|
|
|
|
2005-08-28 21:37:37 +04:00
|
|
|
// All checks pass, fill in shadow cache
|
|
|
|
seg->cache = descriptor;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2005-03-05 00:03:22 +03:00
|
|
|
void BX_CPU_C::get_SS_ESP_from_TSS(unsigned pl, Bit16u *ss, Bit32u *esp)
|
2001-04-10 05:04:59 +04:00
|
|
|
{
|
|
|
|
if (BX_CPU_THIS_PTR tr.cache.valid==0)
|
2001-05-30 22:56:02 +04:00
|
|
|
BX_PANIC(("get_SS_ESP_from_TSS: TR.cache invalid"));
|
2001-04-10 05:04:59 +04:00
|
|
|
|
2008-04-17 02:22:10 +04:00
|
|
|
if (BX_CPU_THIS_PTR tr.cache.type==BX_SYS_SEGMENT_AVAIL_386_TSS ||
|
|
|
|
BX_CPU_THIS_PTR tr.cache.type==BX_SYS_SEGMENT_BUSY_386_TSS)
|
|
|
|
{
|
2001-04-10 05:04:59 +04:00
|
|
|
// 32-bit TSS
|
2005-03-05 00:03:22 +03:00
|
|
|
Bit32u TSSstackaddr = 8*pl + 4;
|
2009-04-05 23:09:44 +04:00
|
|
|
if ((TSSstackaddr+7) > BX_CPU_THIS_PTR tr.cache.u.segment.limit_scaled) {
|
2006-06-10 02:29:07 +04:00
|
|
|
BX_DEBUG(("get_SS_ESP_from_TSS(386): TSSstackaddr > TSS.LIMIT"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, BX_CPU_THIS_PTR tr.selector.value & 0xfffc);
|
2006-06-10 02:29:07 +04:00
|
|
|
}
|
2009-04-05 23:09:44 +04:00
|
|
|
*ss = system_read_word (BX_CPU_THIS_PTR tr.cache.u.segment.base + TSSstackaddr + 4);
|
|
|
|
*esp = system_read_dword(BX_CPU_THIS_PTR tr.cache.u.segment.base + TSSstackaddr);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2008-04-17 02:22:10 +04:00
|
|
|
else if (BX_CPU_THIS_PTR tr.cache.type==BX_SYS_SEGMENT_AVAIL_286_TSS ||
|
|
|
|
BX_CPU_THIS_PTR tr.cache.type==BX_SYS_SEGMENT_BUSY_286_TSS)
|
|
|
|
{
|
2001-04-10 05:04:59 +04:00
|
|
|
// 16-bit TSS
|
2005-03-05 00:03:22 +03:00
|
|
|
Bit32u TSSstackaddr = 4*pl + 2;
|
2009-04-05 23:09:44 +04:00
|
|
|
if ((TSSstackaddr+3) > BX_CPU_THIS_PTR tr.cache.u.segment.limit_scaled) {
|
2006-06-10 02:29:07 +04:00
|
|
|
BX_DEBUG(("get_SS_ESP_from_TSS(286): TSSstackaddr > TSS.LIMIT"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, BX_CPU_THIS_PTR tr.selector.value & 0xfffc);
|
2006-06-10 02:29:07 +04:00
|
|
|
}
|
2009-04-05 23:09:44 +04:00
|
|
|
*ss = system_read_word(BX_CPU_THIS_PTR tr.cache.u.segment.base + TSSstackaddr + 2);
|
|
|
|
*esp = (Bit32u) system_read_word(BX_CPU_THIS_PTR tr.cache.u.segment.base + TSSstackaddr);
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
else {
|
2010-02-11 11:06:25 +03:00
|
|
|
BX_PANIC(("get_SS_ESP_from_TSS: TR is bogus type (%u)", (unsigned) BX_CPU_THIS_PTR tr.cache.type));
|
2005-03-05 00:03:22 +03:00
|
|
|
}
|
2001-04-10 05:04:59 +04:00
|
|
|
}
|
2002-09-13 20:23:02 +04:00
|
|
|
|
|
|
|
#if BX_SUPPORT_X86_64
|
2008-09-06 21:44:02 +04:00
|
|
|
Bit64u BX_CPU_C::get_RSP_from_TSS(unsigned pl)
|
2002-09-13 20:23:02 +04:00
|
|
|
{
|
|
|
|
if (BX_CPU_THIS_PTR tr.cache.valid==0)
|
|
|
|
BX_PANIC(("get_RSP_from_TSS: TR.cache invalid"));
|
|
|
|
|
|
|
|
// 32-bit TSS
|
2005-03-05 00:03:22 +03:00
|
|
|
Bit32u TSSstackaddr = 8*pl + 4;
|
2009-04-05 23:09:44 +04:00
|
|
|
if ((TSSstackaddr+7) > BX_CPU_THIS_PTR tr.cache.u.segment.limit_scaled) {
|
2006-06-10 02:29:07 +04:00
|
|
|
BX_DEBUG(("get_RSP_from_TSS(): TSSstackaddr > TSS.LIMIT"));
|
2010-03-14 18:51:27 +03:00
|
|
|
exception(BX_TS_EXCEPTION, BX_CPU_THIS_PTR tr.selector.value & 0xfffc);
|
2006-06-10 02:29:07 +04:00
|
|
|
}
|
2002-09-13 20:23:02 +04:00
|
|
|
|
2009-04-05 23:09:44 +04:00
|
|
|
Bit64u rsp = system_read_qword(BX_CPU_THIS_PTR tr.cache.u.segment.base + TSSstackaddr);
|
2010-06-21 09:35:45 +04:00
|
|
|
|
|
|
|
if (! IsCanonical(rsp)) {
|
|
|
|
BX_ERROR(("get_RSP_from_TSS: canonical address failure 0x%08x%08x", GET32H(rsp), GET32L(rsp)));
|
|
|
|
exception(BX_SS_EXCEPTION, BX_CPU_THIS_PTR sregs[BX_SEG_REG_SS].selector.value & 0xfffc);
|
|
|
|
}
|
|
|
|
|
2008-09-06 21:44:02 +04:00
|
|
|
return rsp;
|
2002-09-13 20:23:02 +04:00
|
|
|
}
|
|
|
|
#endif // #if BX_SUPPORT_X86_64
|