1*bb4ee6a4SAndroid Build Coastguard Worker /*
2*bb4ee6a4SAndroid Build Coastguard Worker * Copyright 2017 The ChromiumOS Authors
3*bb4ee6a4SAndroid Build Coastguard Worker * Use of this source code is governed by a BSD-style license that can be
4*bb4ee6a4SAndroid Build Coastguard Worker * found in the LICENSE file.
5*bb4ee6a4SAndroid Build Coastguard Worker */
6*bb4ee6a4SAndroid Build Coastguard Worker
7*bb4ee6a4SAndroid Build Coastguard Worker #include <errno.h>
8*bb4ee6a4SAndroid Build Coastguard Worker #include <fcntl.h>
9*bb4ee6a4SAndroid Build Coastguard Worker #include <linux/memfd.h>
10*bb4ee6a4SAndroid Build Coastguard Worker #include <pthread.h>
11*bb4ee6a4SAndroid Build Coastguard Worker #include <stdint.h>
12*bb4ee6a4SAndroid Build Coastguard Worker #include <stdio.h>
13*bb4ee6a4SAndroid Build Coastguard Worker #include <stdlib.h>
14*bb4ee6a4SAndroid Build Coastguard Worker #include <string.h>
15*bb4ee6a4SAndroid Build Coastguard Worker #include <sys/mman.h>
16*bb4ee6a4SAndroid Build Coastguard Worker #include <sys/syscall.h>
17*bb4ee6a4SAndroid Build Coastguard Worker #include <time.h>
18*bb4ee6a4SAndroid Build Coastguard Worker #include <unistd.h>
19*bb4ee6a4SAndroid Build Coastguard Worker
20*bb4ee6a4SAndroid Build Coastguard Worker #include "crosvm.h"
21*bb4ee6a4SAndroid Build Coastguard Worker
22*bb4ee6a4SAndroid Build Coastguard Worker #ifndef F_LINUX_SPECIFIC_BASE
23*bb4ee6a4SAndroid Build Coastguard Worker #define F_LINUX_SPECIFIC_BASE 1024
24*bb4ee6a4SAndroid Build Coastguard Worker #endif
25*bb4ee6a4SAndroid Build Coastguard Worker
26*bb4ee6a4SAndroid Build Coastguard Worker #ifndef F_ADD_SEALS
27*bb4ee6a4SAndroid Build Coastguard Worker #define F_ADD_SEALS (F_LINUX_SPECIFIC_BASE + 9)
28*bb4ee6a4SAndroid Build Coastguard Worker #endif
29*bb4ee6a4SAndroid Build Coastguard Worker
30*bb4ee6a4SAndroid Build Coastguard Worker #ifndef F_SEAL_SHRINK
31*bb4ee6a4SAndroid Build Coastguard Worker #define F_SEAL_SHRINK 0x0002
32*bb4ee6a4SAndroid Build Coastguard Worker #endif
33*bb4ee6a4SAndroid Build Coastguard Worker
34*bb4ee6a4SAndroid Build Coastguard Worker #define LOAD_ADDRESS 0x1000
35*bb4ee6a4SAndroid Build Coastguard Worker #define DATAMATCH_VAL 0x88
36*bb4ee6a4SAndroid Build Coastguard Worker #define KILL_ADDRESS 0x4000
37*bb4ee6a4SAndroid Build Coastguard Worker
38*bb4ee6a4SAndroid Build Coastguard Worker int g_kill_evt;
39*bb4ee6a4SAndroid Build Coastguard Worker
vcpu_thread(void * arg)40*bb4ee6a4SAndroid Build Coastguard Worker void *vcpu_thread(void *arg) {
41*bb4ee6a4SAndroid Build Coastguard Worker struct crosvm_vcpu *vcpu = arg;
42*bb4ee6a4SAndroid Build Coastguard Worker struct crosvm_vcpu_event evt;
43*bb4ee6a4SAndroid Build Coastguard Worker int i = 0;
44*bb4ee6a4SAndroid Build Coastguard Worker while (crosvm_vcpu_wait(vcpu, &evt) == 0) {
45*bb4ee6a4SAndroid Build Coastguard Worker if (evt.kind == CROSVM_VCPU_EVENT_KIND_INIT) {
46*bb4ee6a4SAndroid Build Coastguard Worker struct kvm_sregs sregs;
47*bb4ee6a4SAndroid Build Coastguard Worker crosvm_vcpu_get_sregs(vcpu, &sregs);
48*bb4ee6a4SAndroid Build Coastguard Worker sregs.cs.base = 0;
49*bb4ee6a4SAndroid Build Coastguard Worker sregs.cs.selector = 0;
50*bb4ee6a4SAndroid Build Coastguard Worker sregs.es.base = KILL_ADDRESS;
51*bb4ee6a4SAndroid Build Coastguard Worker sregs.es.selector = 0;
52*bb4ee6a4SAndroid Build Coastguard Worker crosvm_vcpu_set_sregs(vcpu, &sregs);
53*bb4ee6a4SAndroid Build Coastguard Worker
54*bb4ee6a4SAndroid Build Coastguard Worker struct kvm_regs regs;
55*bb4ee6a4SAndroid Build Coastguard Worker crosvm_vcpu_get_regs(vcpu, ®s);
56*bb4ee6a4SAndroid Build Coastguard Worker regs.rflags = 2;
57*bb4ee6a4SAndroid Build Coastguard Worker regs.rip = LOAD_ADDRESS;
58*bb4ee6a4SAndroid Build Coastguard Worker regs.rax = DATAMATCH_VAL;
59*bb4ee6a4SAndroid Build Coastguard Worker regs.rbx = DATAMATCH_VAL - 1;
60*bb4ee6a4SAndroid Build Coastguard Worker crosvm_vcpu_set_regs(vcpu, ®s);
61*bb4ee6a4SAndroid Build Coastguard Worker }
62*bb4ee6a4SAndroid Build Coastguard Worker
63*bb4ee6a4SAndroid Build Coastguard Worker if (evt.kind == CROSVM_VCPU_EVENT_KIND_IO_ACCESS &&
64*bb4ee6a4SAndroid Build Coastguard Worker evt.io_access.address_space == CROSVM_ADDRESS_SPACE_MMIO &&
65*bb4ee6a4SAndroid Build Coastguard Worker evt.io_access.address == KILL_ADDRESS &&
66*bb4ee6a4SAndroid Build Coastguard Worker evt.io_access.is_write &&
67*bb4ee6a4SAndroid Build Coastguard Worker evt.io_access.length == 1 &&
68*bb4ee6a4SAndroid Build Coastguard Worker evt.io_access.data[0] == 1)
69*bb4ee6a4SAndroid Build Coastguard Worker {
70*bb4ee6a4SAndroid Build Coastguard Worker uint64_t dummy = 1;
71*bb4ee6a4SAndroid Build Coastguard Worker write(g_kill_evt, &dummy, sizeof(dummy));
72*bb4ee6a4SAndroid Build Coastguard Worker return NULL;
73*bb4ee6a4SAndroid Build Coastguard Worker }
74*bb4ee6a4SAndroid Build Coastguard Worker
75*bb4ee6a4SAndroid Build Coastguard Worker crosvm_vcpu_resume(vcpu);
76*bb4ee6a4SAndroid Build Coastguard Worker }
77*bb4ee6a4SAndroid Build Coastguard Worker
78*bb4ee6a4SAndroid Build Coastguard Worker return NULL;
79*bb4ee6a4SAndroid Build Coastguard Worker }
80*bb4ee6a4SAndroid Build Coastguard Worker
main(int argc,char ** argv)81*bb4ee6a4SAndroid Build Coastguard Worker int main(int argc, char** argv) {
82*bb4ee6a4SAndroid Build Coastguard Worker const uint8_t code[] = {
83*bb4ee6a4SAndroid Build Coastguard Worker /*
84*bb4ee6a4SAndroid Build Coastguard Worker 0000 BAF803 mov dx,0x3f8
85*bb4ee6a4SAndroid Build Coastguard Worker 0003 88C3 mov bl,al
86*bb4ee6a4SAndroid Build Coastguard Worker 0005 EE out dx,al
87*bb4ee6a4SAndroid Build Coastguard Worker 0006 B000 mov al,0x0
88*bb4ee6a4SAndroid Build Coastguard Worker 0008 EE out dx,al
89*bb4ee6a4SAndroid Build Coastguard Worker 0009 88D8 mov al,bl
90*bb4ee6a4SAndroid Build Coastguard Worker 000B EE out dx,al
91*bb4ee6a4SAndroid Build Coastguard Worker 0014 26C606000001 mov byte [es:0x0],0x1
92*bb4ee6a4SAndroid Build Coastguard Worker 000C F4 hlt
93*bb4ee6a4SAndroid Build Coastguard Worker */
94*bb4ee6a4SAndroid Build Coastguard Worker 0xba, 0xf8, 0x03,
95*bb4ee6a4SAndroid Build Coastguard Worker 0x88, 0xc3,
96*bb4ee6a4SAndroid Build Coastguard Worker 0xee,
97*bb4ee6a4SAndroid Build Coastguard Worker 0xb0, 0x00,
98*bb4ee6a4SAndroid Build Coastguard Worker 0xee,
99*bb4ee6a4SAndroid Build Coastguard Worker 0x88, 0xd8,
100*bb4ee6a4SAndroid Build Coastguard Worker 0xee,
101*bb4ee6a4SAndroid Build Coastguard Worker 0x26, 0xc6, 0x06, 0x00, 0x00, 0x01,
102*bb4ee6a4SAndroid Build Coastguard Worker 0xf4,
103*bb4ee6a4SAndroid Build Coastguard Worker };
104*bb4ee6a4SAndroid Build Coastguard Worker
105*bb4ee6a4SAndroid Build Coastguard Worker struct crosvm *crosvm;
106*bb4ee6a4SAndroid Build Coastguard Worker int ret = crosvm_connect(&crosvm);
107*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
108*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to connect to crosvm: %d\n", ret);
109*bb4ee6a4SAndroid Build Coastguard Worker return 1;
110*bb4ee6a4SAndroid Build Coastguard Worker }
111*bb4ee6a4SAndroid Build Coastguard Worker
112*bb4ee6a4SAndroid Build Coastguard Worker g_kill_evt = crosvm_get_shutdown_eventfd(crosvm);
113*bb4ee6a4SAndroid Build Coastguard Worker if (g_kill_evt < 0) {
114*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to get kill eventfd: %d\n", g_kill_evt);
115*bb4ee6a4SAndroid Build Coastguard Worker return 1;
116*bb4ee6a4SAndroid Build Coastguard Worker }
117*bb4ee6a4SAndroid Build Coastguard Worker
118*bb4ee6a4SAndroid Build Coastguard Worker ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_MMIO, KILL_ADDRESS, 1);
119*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
120*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to reserve mmio range: %d\n", ret);
121*bb4ee6a4SAndroid Build Coastguard Worker return 1;
122*bb4ee6a4SAndroid Build Coastguard Worker }
123*bb4ee6a4SAndroid Build Coastguard Worker
124*bb4ee6a4SAndroid Build Coastguard Worker uint8_t datamatch = DATAMATCH_VAL;
125*bb4ee6a4SAndroid Build Coastguard Worker struct crosvm_io *io;
126*bb4ee6a4SAndroid Build Coastguard Worker ret = crosvm_create_io_event(crosvm, CROSVM_ADDRESS_SPACE_IOPORT, 0x3f8, 1, &datamatch, &io);
127*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
128*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to create ioevent: %d\n", ret);
129*bb4ee6a4SAndroid Build Coastguard Worker return 1;
130*bb4ee6a4SAndroid Build Coastguard Worker }
131*bb4ee6a4SAndroid Build Coastguard Worker
132*bb4ee6a4SAndroid Build Coastguard Worker int ioeventfd = crosvm_io_event_fd(io);
133*bb4ee6a4SAndroid Build Coastguard Worker
134*bb4ee6a4SAndroid Build Coastguard Worker int mem_size = 0x4000;
135*bb4ee6a4SAndroid Build Coastguard Worker int mem_fd = syscall(SYS_memfd_create, "guest_mem", MFD_CLOEXEC | MFD_ALLOW_SEALING);
136*bb4ee6a4SAndroid Build Coastguard Worker if (mem_fd < 0) {
137*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to create guest memfd: %d\n", errno);
138*bb4ee6a4SAndroid Build Coastguard Worker return 1;
139*bb4ee6a4SAndroid Build Coastguard Worker }
140*bb4ee6a4SAndroid Build Coastguard Worker ret = ftruncate(mem_fd, mem_size);
141*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
142*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to set size of guest memory: %d\n", errno);
143*bb4ee6a4SAndroid Build Coastguard Worker return 1;
144*bb4ee6a4SAndroid Build Coastguard Worker }
145*bb4ee6a4SAndroid Build Coastguard Worker uint8_t *mem = mmap(NULL, mem_size, PROT_READ | PROT_WRITE, MAP_SHARED, mem_fd, 0);
146*bb4ee6a4SAndroid Build Coastguard Worker if (mem == MAP_FAILED) {
147*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to mmap guest memory: %d\n", errno);
148*bb4ee6a4SAndroid Build Coastguard Worker return 1;
149*bb4ee6a4SAndroid Build Coastguard Worker }
150*bb4ee6a4SAndroid Build Coastguard Worker fcntl(mem_fd, F_ADD_SEALS, F_SEAL_SHRINK);
151*bb4ee6a4SAndroid Build Coastguard Worker memcpy(mem + LOAD_ADDRESS, code, sizeof(code));
152*bb4ee6a4SAndroid Build Coastguard Worker
153*bb4ee6a4SAndroid Build Coastguard Worker struct crosvm_memory *mem_obj;
154*bb4ee6a4SAndroid Build Coastguard Worker ret = crosvm_create_memory(crosvm, mem_fd, 0, mem_size, 0, false, false, &mem_obj);
155*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
156*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to create memory in crosvm: %d\n", ret);
157*bb4ee6a4SAndroid Build Coastguard Worker return 1;
158*bb4ee6a4SAndroid Build Coastguard Worker }
159*bb4ee6a4SAndroid Build Coastguard Worker
160*bb4ee6a4SAndroid Build Coastguard Worker /* get and creat a thread for each vcpu */
161*bb4ee6a4SAndroid Build Coastguard Worker struct crosvm_vcpu *vcpus[32];
162*bb4ee6a4SAndroid Build Coastguard Worker pthread_t vcpu_threads[32];
163*bb4ee6a4SAndroid Build Coastguard Worker uint32_t vcpu_count;
164*bb4ee6a4SAndroid Build Coastguard Worker for (vcpu_count = 0; vcpu_count < 32; vcpu_count++) {
165*bb4ee6a4SAndroid Build Coastguard Worker ret = crosvm_get_vcpu(crosvm, vcpu_count, &vcpus[vcpu_count]);
166*bb4ee6a4SAndroid Build Coastguard Worker if (ret == -ENOENT)
167*bb4ee6a4SAndroid Build Coastguard Worker break;
168*bb4ee6a4SAndroid Build Coastguard Worker
169*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
170*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "error while getting all vcpus: %d\n", ret);
171*bb4ee6a4SAndroid Build Coastguard Worker return 1;
172*bb4ee6a4SAndroid Build Coastguard Worker }
173*bb4ee6a4SAndroid Build Coastguard Worker pthread_create(&vcpu_threads[vcpu_count], NULL, vcpu_thread, vcpus[vcpu_count]);
174*bb4ee6a4SAndroid Build Coastguard Worker }
175*bb4ee6a4SAndroid Build Coastguard Worker
176*bb4ee6a4SAndroid Build Coastguard Worker ret = crosvm_start(crosvm);
177*bb4ee6a4SAndroid Build Coastguard Worker if (ret) {
178*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to tell crosvm to start: %d\n", ret);
179*bb4ee6a4SAndroid Build Coastguard Worker return 1;
180*bb4ee6a4SAndroid Build Coastguard Worker }
181*bb4ee6a4SAndroid Build Coastguard Worker
182*bb4ee6a4SAndroid Build Coastguard Worker uint64_t dummy;
183*bb4ee6a4SAndroid Build Coastguard Worker read(g_kill_evt, &dummy, 8);
184*bb4ee6a4SAndroid Build Coastguard Worker
185*bb4ee6a4SAndroid Build Coastguard Worker ret = read(ioeventfd, &dummy, sizeof(dummy));
186*bb4ee6a4SAndroid Build Coastguard Worker if (ret == -1) {
187*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "failed to read ioeventfd: %d\n", errno);
188*bb4ee6a4SAndroid Build Coastguard Worker return 1;
189*bb4ee6a4SAndroid Build Coastguard Worker }
190*bb4ee6a4SAndroid Build Coastguard Worker
191*bb4ee6a4SAndroid Build Coastguard Worker if (dummy != 2) {
192*bb4ee6a4SAndroid Build Coastguard Worker fprintf(stderr, "ioeventfd was not triggered the expected number of times: %d\n", dummy);
193*bb4ee6a4SAndroid Build Coastguard Worker return 1;
194*bb4ee6a4SAndroid Build Coastguard Worker }
195*bb4ee6a4SAndroid Build Coastguard Worker
196*bb4ee6a4SAndroid Build Coastguard Worker return 0;
197*bb4ee6a4SAndroid Build Coastguard Worker }
198