plugin_hint.c 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313
  1. /*
  2. * Copyright 2019 The ChromiumOS Authors
  3. * Use of this source code is governed by a BSD-style license that can be
  4. * found in the LICENSE file.
  5. */
  6. #include <errno.h>
  7. #include <fcntl.h>
  8. #include <linux/memfd.h>
  9. #include <pthread.h>
  10. #include <signal.h>
  11. #include <stdint.h>
  12. #include <stdio.h>
  13. #include <stdlib.h>
  14. #include <string.h>
  15. #include <sys/mman.h>
  16. #include <sys/syscall.h>
  17. #include <time.h>
  18. #include <unistd.h>
  19. #include "crosvm.h"
  20. #ifndef F_LINUX_SPECIFIC_BASE
  21. #define F_LINUX_SPECIFIC_BASE 1024
  22. #endif
  23. #ifndef F_ADD_SEALS
  24. #define F_ADD_SEALS (F_LINUX_SPECIFIC_BASE + 9)
  25. #endif
  26. #ifndef F_SEAL_SHRINK
  27. #define F_SEAL_SHRINK 0x0002
  28. #endif
  29. #define KILL_ADDRESS 0x3f9
  30. #define HINT_ADDRESS 0x500
  31. #define EAX_HINT_VALUE 0x77
  32. int g_kill_evt;
  33. int got_regs = 0;
  34. void *vcpu_thread(void *arg) {
  35. struct crosvm_vcpu *vcpu = arg;
  36. struct crosvm_vcpu_event evt;
  37. while (crosvm_vcpu_wait(vcpu, &evt) == 0) {
  38. if (evt.kind == CROSVM_VCPU_EVENT_KIND_INIT) {
  39. struct kvm_sregs sregs;
  40. crosvm_vcpu_get_sregs(vcpu, &sregs);
  41. sregs.cs.base = 0;
  42. sregs.cs.selector = 0;
  43. sregs.es.base = KILL_ADDRESS;
  44. sregs.es.selector = 0;
  45. crosvm_vcpu_set_sregs(vcpu, &sregs);
  46. struct kvm_regs regs;
  47. crosvm_vcpu_get_regs(vcpu, &regs);
  48. regs.rip = 0x1000;
  49. regs.rax = 2;
  50. regs.rbx = 7;
  51. regs.rflags = 2;
  52. crosvm_vcpu_set_regs(vcpu, &regs);
  53. }
  54. if (evt.kind == CROSVM_VCPU_EVENT_KIND_IO_ACCESS) {
  55. if (evt.io_access.address_space == CROSVM_ADDRESS_SPACE_IOPORT &&
  56. evt.io_access.address == HINT_ADDRESS &&
  57. evt.io_access.is_write &&
  58. evt.io_access.length == 1) {
  59. struct kvm_regs regs = {0};
  60. struct kvm_sregs sregs = {0};
  61. struct kvm_debugregs debugregs = {0};
  62. /*
  63. * In a properly running test the following
  64. * get and set calls will return success despite
  65. * crosvm being halted.
  66. */
  67. if (kill(getppid(), SIGSTOP)) {
  68. fprintf(stderr, "failed to send stop to crosvm\n");
  69. exit(1);
  70. }
  71. printf("get regs query on crosvm\n");
  72. if (crosvm_vcpu_get_regs(vcpu, &regs)) {
  73. /*
  74. * The failure mode for this test is that crosvm remains
  75. * halted (since the plugin hasn't returned from
  76. * crosvm_vcpu_[g|s]et_regs() to resume crosvm) and
  77. * the test times out.
  78. */
  79. fprintf(stderr, "failed to query regs on hint port\n");
  80. exit(1);
  81. }
  82. printf("set regs query on crosvm\n");
  83. if (crosvm_vcpu_set_regs(vcpu, &regs)) {
  84. fprintf(stderr, "failed to set regs on hint port\n");
  85. exit(1);
  86. }
  87. printf("get sregs query on crosvm\n");
  88. if (crosvm_vcpu_get_sregs(vcpu, &sregs)) {
  89. fprintf(stderr, "failed to query sregs on hint port\n");
  90. exit(1);
  91. }
  92. printf("set sregs query on crosvm\n");
  93. if (crosvm_vcpu_set_sregs(vcpu, &sregs)) {
  94. fprintf(stderr, "failed to set sregs on hint port\n");
  95. exit(1);
  96. }
  97. printf("get debugregs query on crosvm\n");
  98. if (crosvm_vcpu_get_debugregs(vcpu, &debugregs)) {
  99. fprintf(stderr, "failed to query debugregs on hint port\n");
  100. exit(1);
  101. }
  102. printf("set debugregs query on crosvm\n");
  103. if (crosvm_vcpu_set_debugregs(vcpu, &debugregs)) {
  104. fprintf(stderr, "failed to set debugregs on hint port\n");
  105. exit(1);
  106. }
  107. got_regs = 1;
  108. if (kill(getppid(), SIGCONT)) {
  109. fprintf(stderr, "failed to send continue to crosvm\n");
  110. exit(1);
  111. }
  112. }
  113. if (evt.io_access.address_space == CROSVM_ADDRESS_SPACE_IOPORT &&
  114. evt.io_access.address == KILL_ADDRESS &&
  115. evt.io_access.is_write &&
  116. evt.io_access.length == 1 &&
  117. evt.io_access.data[0] == 1)
  118. {
  119. uint64_t dummy = 1;
  120. write(g_kill_evt, &dummy, sizeof(dummy));
  121. return NULL;
  122. }
  123. }
  124. crosvm_vcpu_resume(vcpu);
  125. }
  126. return NULL;
  127. }
  128. int main(int argc, char** argv) {
  129. const uint8_t code[] = {
  130. /*
  131. B007 mov al,0x7
  132. BA0005 mov dx,0x500
  133. EE out dx,al
  134. BAF903 mov dx,0x3f9
  135. B001 mov al,0x1
  136. EE out dx,al
  137. F4 hlt
  138. */
  139. 0xb0, EAX_HINT_VALUE,
  140. 0xba, (HINT_ADDRESS & 0xFF), ((HINT_ADDRESS >> 8) & 0xFF),
  141. 0xee,
  142. 0xba, (KILL_ADDRESS & 0xFF), ((KILL_ADDRESS >> 8) & 0xFF),
  143. 0xb0, 0x01,
  144. 0xee,
  145. 0xf4
  146. };
  147. struct crosvm *crosvm;
  148. int ret = crosvm_connect(&crosvm);
  149. if (ret) {
  150. fprintf(stderr, "failed to connect to crosvm: %d\n", ret);
  151. return 1;
  152. }
  153. /*
  154. * Not strictly necessary, but demonstrates we can have as many connections
  155. * as we please.
  156. */
  157. struct crosvm *extra_crosvm;
  158. ret = crosvm_new_connection(crosvm, &extra_crosvm);
  159. if (ret) {
  160. fprintf(stderr, "failed to make new socket: %d\n", ret);
  161. return 1;
  162. }
  163. /* We needs this eventfd to know when to exit before being killed. */
  164. g_kill_evt = crosvm_get_shutdown_eventfd(crosvm);
  165. if (g_kill_evt < 0) {
  166. fprintf(stderr, "failed to get kill eventfd: %d\n", g_kill_evt);
  167. return 1;
  168. }
  169. ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
  170. HINT_ADDRESS, 1);
  171. if (ret) {
  172. fprintf(stderr, "failed to reserve hint ioport range: %d\n", ret);
  173. return 1;
  174. }
  175. ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
  176. KILL_ADDRESS, 1);
  177. if (ret) {
  178. fprintf(stderr, "failed to reserve kill ioport range: %d\n", ret);
  179. return 1;
  180. }
  181. struct crosvm_hint_detail details = {0};
  182. details.match_rax = 1;
  183. details.rax = EAX_HINT_VALUE;
  184. details.send_sregs = 1;
  185. details.send_debugregs = 1;
  186. struct crosvm_hint hint = {0};
  187. hint.address_space = CROSVM_ADDRESS_SPACE_IOPORT;
  188. hint.address = HINT_ADDRESS;
  189. hint.address_flags = CROSVM_HINT_ON_WRITE;
  190. hint.details_count = 1;
  191. hint.details = &details;
  192. ret = crosvm_set_hypercall_hint(crosvm, 1, &hint);
  193. if (ret) {
  194. fprintf(stderr, "failed to set hypercall hint: %d\n", ret);
  195. return 1;
  196. }
  197. int mem_size = 0x2000;
  198. int mem_fd = syscall(SYS_memfd_create, "guest_mem",
  199. MFD_CLOEXEC | MFD_ALLOW_SEALING);
  200. if (mem_fd < 0) {
  201. fprintf(stderr, "failed to create guest memfd: %d\n", errno);
  202. return 1;
  203. }
  204. ret = ftruncate(mem_fd, mem_size);
  205. if (ret) {
  206. fprintf(stderr, "failed to set size of guest memory: %d\n", errno);
  207. return 1;
  208. }
  209. uint8_t *mem = mmap(NULL, mem_size, PROT_READ | PROT_WRITE, MAP_SHARED,
  210. mem_fd, 0x1000);
  211. if (mem == MAP_FAILED) {
  212. fprintf(stderr, "failed to mmap guest memory: %d\n", errno);
  213. return 1;
  214. }
  215. fcntl(mem_fd, F_ADD_SEALS, F_SEAL_SHRINK);
  216. memcpy(mem, code, sizeof(code));
  217. struct crosvm_memory *mem_obj;
  218. ret = crosvm_create_memory(crosvm, mem_fd, 0x1000, 0x1000, 0x1000, false,
  219. false, &mem_obj);
  220. if (ret) {
  221. fprintf(stderr, "failed to create memory in crosvm: %d\n", ret);
  222. return 1;
  223. }
  224. /* get and creat a thread for each vcpu */
  225. struct crosvm_vcpu *vcpus[32];
  226. pthread_t vcpu_threads[32];
  227. uint32_t vcpu_count;
  228. for (vcpu_count = 0; vcpu_count < 32; vcpu_count++) {
  229. ret = crosvm_get_vcpu(crosvm, vcpu_count, &vcpus[vcpu_count]);
  230. if (ret == -ENOENT)
  231. break;
  232. if (ret) {
  233. fprintf(stderr, "error while getting all vcpus: %d\n", ret);
  234. return 1;
  235. }
  236. pthread_create(&vcpu_threads[vcpu_count], NULL, vcpu_thread,
  237. vcpus[vcpu_count]);
  238. }
  239. ret = crosvm_start(extra_crosvm);
  240. if (ret) {
  241. fprintf(stderr, "failed to tell crosvm to start: %d\n", ret);
  242. return 1;
  243. }
  244. /* Wait for crosvm to request that we exit otherwise we will be killed. */
  245. uint64_t dummy;
  246. read(g_kill_evt, &dummy, 8);
  247. ret = crosvm_destroy_memory(crosvm, &mem_obj);
  248. if (ret) {
  249. fprintf(stderr, "failed to destroy memory in crosvm: %d\n", ret);
  250. return 1;
  251. }
  252. ret = crosvm_set_hypercall_hint(crosvm, 0, NULL);
  253. if (ret) {
  254. fprintf(stderr, "failed to clear hypercall hint: %d\n", ret);
  255. return 1;
  256. }
  257. ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
  258. HINT_ADDRESS, 0);
  259. if (ret) {
  260. fprintf(stderr, "failed to unreserve hint ioport range: %d\n", ret);
  261. return 1;
  262. }
  263. ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
  264. KILL_ADDRESS, 0);
  265. if (ret) {
  266. fprintf(stderr, "failed to unreserve kill ioport range: %d\n", ret);
  267. return 1;
  268. }
  269. if (!got_regs) {
  270. fprintf(stderr, "vm ran to completion without reg query\n");
  271. return 1;
  272. }
  273. return 0;
  274. }