vmcb.h revision 249353
1/*-
2 * Copyright (c) 2013 Anish Gupta (akgupt3@gmail.com)
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 *    notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 *    notice, this list of conditions and the following disclaimer in the
12 *    documentation and/or other materials provided with the distribution.
13 *
14 * THIS SOFTWARE IS PROVIDED BY NETAPP, INC ``AS IS'' AND
15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17 * ARE DISCLAIMED.  IN NO EVENT SHALL NETAPP, INC OR CONTRIBUTORS BE LIABLE
18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24 * SUCH DAMAGE.
25 *
26 * $FreeBSD: projects/bhyve_svm/sys/amd64/vmm/amd/vmcb.h 249353 2013-04-11 06:52:19Z neel $
27 */
28
29#ifndef _VMCB_H_
30#define	_VMCB_H_
31
32#ifndef	BIT
33#define	BIT(bitpos)		(1UL << (bitpos))
34#endif
35
36#ifndef	ERR
37#define	ERR(...)
38#endif
39
40/*
41 * Secure Virtual Machine: AMD64 Programmer's Manual Vol2, Chapter 15
42 * Layout of VMCB: AMD64 Programmer's Manual Vol2, Appendix B
43 */
44
45/* VMCB Control offset 0xC */
46#define	VMCB_INTCPT_INTR		BIT(0)
47#define	VMCB_INTCPT_NMI			BIT(1)
48#define	VMCB_INTCPT_SMI			BIT(2)
49#define	VMCB_INTCPT_INIT		BIT(3)
50#define	VMCB_INTCPT_VINTR		BIT(4)
51#define	VMCB_INTCPT_CR0_WRITE		BIT(5)
52#define	VMCB_INTCPT_IDTR_READ		BIT(6)
53#define	VMCB_INTCPT_GDTR_READ		BIT(7)
54#define	VMCB_INTCPT_LDTR_READ		BIT(8)
55#define	VMCB_INTCPT_TR_READ		BIT(9)
56#define	VMCB_INTCPT_IDTR_WRITE		BIT(10)
57#define	VMCB_INTCPT_GDTR_WRITE		BIT(11)
58#define	VMCB_INTCPT_LDTR_WRITE		BIT(12)
59#define	VMCB_INTCPT_TR_WRITE		BIT(13)
60#define	VMCB_INTCPT_RDTSC		BIT(14)
61#define	VMCB_INTCPT_RDPMC		BIT(15)
62#define	VMCB_INTCPT_PUSHF		BIT(16)
63#define	VMCB_INTCPT_POPF		BIT(17)
64#define	VMCB_INTCPT_CPUID		BIT(18)
65#define	VMCB_INTCPT_RSM			BIT(19)
66#define	VMCB_INTCPT_IRET		BIT(20)
67#define	VMCB_INTCPT_INTn		BIT(21)
68#define	VMCB_INTCPT_INVD		BIT(22)
69#define	VMCB_INTCPT_PAUSE		BIT(23)
70#define	VMCB_INTCPT_HLT			BIT(24)
71#define	VMCB_INTCPT_INVPG		BIT(25)
72#define	VMCB_INTCPT_INVPGA		BIT(26)
73#define	VMCB_INTCPT_IO			BIT(27)
74#define	VMCB_INTCPT_MSR			BIT(28)
75#define	VMCB_INTCPT_TASK_SWITCH		BIT(29)
76#define	VMCB_INTCPT_FERR_FREEZE		BIT(30)
77#define	VMCB_INTCPT_SHUTDOWN		BIT(31)
78
79/* VMCB Control offset 0x10 */
80#define	VMCB_INTCPT_VMRUN		BIT(0)
81#define	VMCB_INTCPT_VMMCALL		BIT(1)
82#define	VMCB_INTCPT_VMLOAD		BIT(2)
83#define	VMCB_INTCPT_VMSAVE		BIT(3)
84#define	VMCB_INTCPT_STGI		BIT(4)
85#define	VMCB_INTCPT_CLGI		BIT(5)
86#define	VMCB_INTCPT_SKINIT		BIT(6)
87#define	VMCB_INTCPT_RDTSCP		BIT(7)
88#define	VMCB_INTCPT_ICEBP		BIT(8)
89#define	VMCB_INTCPT_WBINVD		BIT(9)
90#define	VMCB_INTCPT_MONITOR		BIT(10)
91#define	VMCB_INTCPT_MWAIT		BIT(11)
92#define	VMCB_INTCPT_MWAIT_ARMED		BIT(12)
93#define	VMCB_INTCPT_XSETBV		BIT(13)
94
95/* VMCB TLB control */
96#define	VMCB_TLB_FLUSH_NOTHING		0	/* Flush nothing */
97#define	VMCB_TLB_FLUSH_EVERYTHING	1	/* Flush entire TLB */
98#define	VMCB_TLB_FLUSH_GUEST		3	/* Flush all guest entries */
99#define	VMCB_TLB_FLUSH_GUEST_NONGLOBAL	7	/* Flush guest non-PG entries */
100
101/* VMCB state caching */
102#define	VMCB_CACHE_NONE			0	/* No caching */
103#define	VMCB_CACHE_I			BIT(0)	/* Cache vectors, TSC offset */
104#define	VMCB_CACHE_IOPM			BIT(1)	/* I/O and MSR permission */
105#define	VMCB_CACHE_ASID			BIT(2)	/* ASID */
106#define	VMCB_CACHE_TPR			BIT(3)	/* V_TPR to V_INTR_VECTOR */
107#define	VMCB_CACHE_NP			BIT(4)	/* Nested Paging */
108#define	VMCB_CACHE_CR			BIT(5)	/* CR0, CR3, CR4 & EFER */
109#define	VMCB_CACHE_DR			BIT(6)	/* Debug registers */
110#define	VMCB_CACHE_DT			BIT(7)	/* GDT/IDT */
111#define	VMCB_CACHE_SEG			BIT(8)	/* User segments, CPL */
112#define	VMCB_CACHE_CR2			BIT(9)	/* page fault address */
113#define	VMCB_CACHE_LBR			BIT(10)	/* Last branch */
114
115
116/* VMCB control event injection */
117#define	VMCB_EVENTINJ_EC_VALID		BIT(11)	/* Error Code valid */
118#define	VMCB_EVENTINJ_VALID		BIT(31)	/* Event valid */
119
120#define	VMCB_EVENTINJ_VECTOR_MASK	0xFF
121#define	VMCB_EVENTINJ_INTR_TYPE_SHIFT	8
122#define	VMCB_EVENTINJ_ERRCODE_SHIFT	32
123
124/* Event types that can be injected */
125#define	VMCB_EVENTINJ_TYPE_INTR		0
126#define	VMCB_EVENTINJ_TYPE_NMI		2
127#define	VMCB_EVENTINJ_TYPE_EXCEPTION	3
128#define	VMCB_EVENTINJ_TYPE_INTn		4
129
130/* VMCB exit code, APM vol2 Appendix C */
131#define	VMCB_EXIT_MC			0x52
132#define	VMCB_EXIT_INTR			0x60
133#define	VMCB_EXIT_PUSHF			0x70
134#define	VMCB_EXIT_POPF			0x71
135#define	VMCB_EXIT_CPUID			0x72
136#define	VMCB_EXIT_IRET			0x74
137#define	VMCB_EXIT_PAUSE			0x77
138#define	VMCB_EXIT_HLT			0x78
139#define	VMCB_EXIT_IO			0x7B
140#define	VMCB_EXIT_MSR			0x7C
141#define	VMCB_EXIT_SHUTDOWN		0x7F
142#define	VMCB_EXIT_VMSAVE		0x83
143#define	VMCB_EXIT_NPF			0x400
144#define	VMCB_EXIT_INVALID		-1
145
146/*
147 * Nested page fault.
148 * Bit definitions to decode EXITINFO1.
149 */
150#define	VMCB_NPF_INFO1_P		BIT(0) /* Nested page present. */
151#define	VMCB_NPF_INFO1_W		BIT(1) /* Access was write. */
152#define	VMCB_NPF_INFO1_U		BIT(2) /* Access was user access. */
153#define	VMCB_NPF_INFO1_RSV		BIT(3) /* Reserved bits present. */
154#define	VMCB_NPF_INFO1_ID		BIT(4) /* Code read. */
155
156#define	VMCB_NPF_INFO1_GPA		BIT(32) /* Guest physical address. */
157#define	VMCB_NPF_INFO1_GPT		BIT(33) /* Guest page table. */
158
159/* VMCB save state area segment format */
160struct vmcb_segment {
161	uint16_t	selector;
162	uint16_t	attrib;
163	uint32_t	limit;
164	uint64_t	base;
165} __attribute__ ((__packed__));
166CTASSERT(sizeof(struct vmcb_segment) == 16);
167
168/*
169 * The VMCB is divided into two areas - the first one contains various
170 * control bits including the intercept vector and the second one contains
171 * the guest state.
172 */
173
174/* VMCB control area - padded up to 1024 bytes */
175struct vmcb_ctrl {
176	uint16_t cr_read;	/* Offset 0, CR0-15 read/write */
177	uint16_t cr_write;
178	uint16_t dr_read;	/* Offset 4, DR0-DR15 */
179	uint16_t dr_write;
180	uint32_t exception;	/* Offset 8, bit mask for exceptions. */
181	uint32_t ctrl1;		/* Offset 0xC, intercept events1 */
182	uint32_t ctrl2;		/* Offset 0x10, intercept event2 */
183	uint8_t	 pad1[0x28];	/* Offsets 0x14-0x3B are reserved. */
184	uint16_t pause_filthresh; /* Offset 0x3C, PAUSE filter threshold */
185	uint16_t pause_filcnt;  /* Offset 0x3E, PAUSE filter count */
186	uint64_t iopm_base_pa;	/* 0x40: IOPM_BASE_PA */
187	uint64_t msrpm_base_pa; /* 0x48: MSRPM_BASE_PA */
188	uint64_t tsc_offset;	/* 0x50: TSC_OFFSET */
189	uint32_t asid;		/* 0x58: Guest ASID */
190	uint8_t	 tlb_ctrl;	/* 0x5C: TLB_CONTROL */
191	uint8_t  pad2[3];	/* 0x5D-0x5F: Reserved. */
192	uint8_t	 v_tpr;		/* 0x60: V_TPR, guest CR8 */
193	uint8_t	 v_irq:1;	/* Is virtual interrupt pending? */
194	uint8_t	:7; 		/* Padding */
195	uint8_t v_intr_prio:4;	/* 0x62: Priority for virtual interrupt. */
196	uint8_t v_ign_tpr:1;
197	uint8_t :3;
198	uint8_t	v_intr_masking:1; /* Guest and host sharing of RFLAGS. */
199	uint8_t	:7;
200	uint8_t	v_intr_vector;	/* 0x65: Vector for virtual interrupt. */
201	uint8_t pad3[3];	/* Bit64-40 Reserved. */
202	uint64_t intr_shadow:1; /* 0x68: Interrupt shadow, section15.2.1 APM2 */
203	uint64_t :63;
204	uint64_t exitcode;	/* 0x70, Exitcode */
205	uint64_t exitinfo1;	/* 0x78, EXITINFO1 */
206	uint64_t exitinfo2;	/* 0x80, EXITINFO2 */
207	uint64_t exitintinfo;	/* 0x88, Interrupt exit value. */
208	uint64_t np_enable:1;   /* 0x90, Nested paging enable. */
209	uint64_t :63;
210	uint8_t  pad4[0x10];	/* 0x98-0xA7 reserved. */
211	uint64_t eventinj;	/* 0xA8, Event injection. */
212	uint64_t n_cr3;		/* B0, Nested page table. */
213	uint64_t lbr_virt_en:1;	/* Enable LBR virtualization. */
214	uint64_t :63;
215	uint32_t vmcb_clean;	/* 0xC0: VMCB clean bits for caching */
216	uint32_t :32;		/* 0xC4: Reserved */
217	uint64_t nrip;		/* 0xC8: Guest next nRIP. */
218	uint8_t	inst_decode_size; /* 0xD0: Instruction decode */
219	uint8_t	inst_decode_bytes[15];
220	uint8_t	padd6[0x320];
221} __attribute__ ((__packed__));
222CTASSERT(sizeof(struct vmcb_ctrl) == 1024);
223
224struct vmcb_state {
225	struct   vmcb_segment es;
226	struct   vmcb_segment cs;
227	struct   vmcb_segment ss;
228	struct   vmcb_segment ds;
229	struct   vmcb_segment fs;
230	struct   vmcb_segment gs;
231	struct   vmcb_segment gdt;
232	struct   vmcb_segment ldt;
233	struct   vmcb_segment idt;
234	struct   vmcb_segment tr;
235	uint8_t	 pad1[0x2b];		/* Reserved: 0xA0-0xCA */
236	uint8_t	 cpl;
237	uint8_t  pad2[4];
238	uint64_t efer;
239	uint8_t	 pad3[0x70];		/* Reserved: 0xd8-0x147 */
240	uint64_t cr4;
241	uint64_t cr3;			/* Guest CR3 */
242	uint64_t cr0;
243	uint64_t dr7;
244	uint64_t dr6;
245	uint64_t rflags;
246	uint64_t rip;
247	uint8_t	 pad4[0x58]; 		/* Reserved: 0x180-0x1D7 */
248	uint64_t rsp;
249	uint8_t	 pad5[0x18]; 		/* Reserved 0x1E0-0x1F7 */
250	uint64_t rax;
251	uint64_t star;
252	uint64_t lstar;
253	uint64_t cstar;
254	uint64_t sfmask;
255	uint64_t kernelgsbase;
256	uint64_t sysenter_cs;
257	uint64_t sysenter_esp;
258	uint64_t sysenter_eip;
259	uint64_t cr2;
260	uint8_t	 pad6[0x20];
261	uint64_t g_pat;
262	uint64_t dbgctl;
263	uint64_t br_from;
264	uint64_t br_to;
265	uint64_t lastexcpfrom;
266	uint64_t lastexcpto;
267	uint8_t	 pad7[0x968];		/* Reserved upto end of VMCB */
268} __attribute__ ((__packed__));
269CTASSERT(sizeof(struct vmcb_state) == 0xC00);
270
271struct vmcb {
272	struct vmcb_ctrl ctrl;
273	struct vmcb_state state;
274} __attribute__ ((__packed__));
275CTASSERT(sizeof(struct vmcb) == PAGE_SIZE);
276CTASSERT(offsetof(struct vmcb, state) == 0x400);
277
278int	svm_init_vmcb(struct vmcb *vmcb, uint64_t iopm_base_pa,
279		      uint64_t msrpm_base_pa, uint64_t np_pml4);
280int	svm_set_vmcb(struct vmcb *vmcb, uint8_t asid);
281int	vmcb_read(struct vmcb *vmcb, int ident, uint64_t *retval);
282int	vmcb_write(struct vmcb *vmcb, int ident, uint64_t val);
283struct vmcb_segment *vmcb_seg(struct vmcb *vmcb, int type);
284int	vmcb_eventinject(struct vmcb_ctrl *ctrl, int type, int vector,
285			 uint32_t error, boolean_t ec_valid);
286
287#endif /* _VMCB_H_ */
288