• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright 2019 The Chromium OS Authors. All rights reserved.
3  * Use of this source code is governed by a BSD-style license that can be
4  * found in the LICENSE file.
5  */
6 
7 #include <errno.h>
8 #include <fcntl.h>
9 #include <linux/memfd.h>
10 #include <pthread.h>
11 #include <signal.h>
12 #include <stdint.h>
13 #include <stdio.h>
14 #include <stdlib.h>
15 #include <string.h>
16 #include <sys/mman.h>
17 #include <sys/syscall.h>
18 #include <time.h>
19 #include <unistd.h>
20 
21 #include "crosvm.h"
22 
23 #ifndef F_LINUX_SPECIFIC_BASE
24 #define F_LINUX_SPECIFIC_BASE 1024
25 #endif
26 
27 #ifndef F_ADD_SEALS
28 #define F_ADD_SEALS (F_LINUX_SPECIFIC_BASE + 9)
29 #endif
30 
31 #ifndef F_SEAL_SHRINK
32 #define F_SEAL_SHRINK 0x0002
33 #endif
34 
35 #define KILL_ADDRESS   0x3f9
36 #define HINT_ADDRESS   0x500
37 #define EAX_HINT_VALUE 0x77
38 
39 int g_kill_evt;
40 int got_regs = 0;
41 
vcpu_thread(void * arg)42 void *vcpu_thread(void *arg) {
43     struct crosvm_vcpu *vcpu = arg;
44     struct crosvm_vcpu_event evt;
45     while (crosvm_vcpu_wait(vcpu, &evt) == 0) {
46         if (evt.kind == CROSVM_VCPU_EVENT_KIND_INIT) {
47             struct kvm_sregs sregs;
48             crosvm_vcpu_get_sregs(vcpu, &sregs);
49             sregs.cs.base = 0;
50             sregs.cs.selector = 0;
51             sregs.es.base = KILL_ADDRESS;
52             sregs.es.selector = 0;
53             crosvm_vcpu_set_sregs(vcpu, &sregs);
54 
55             struct kvm_regs regs;
56             crosvm_vcpu_get_regs(vcpu, &regs);
57             regs.rip = 0x1000;
58             regs.rax = 2;
59             regs.rbx = 7;
60             regs.rflags = 2;
61             crosvm_vcpu_set_regs(vcpu, &regs);
62         }
63         if (evt.kind == CROSVM_VCPU_EVENT_KIND_IO_ACCESS) {
64             if (evt.io_access.address_space == CROSVM_ADDRESS_SPACE_IOPORT &&
65                 evt.io_access.address == HINT_ADDRESS &&
66                 evt.io_access.is_write &&
67                 evt.io_access.length == 1) {
68               struct kvm_regs regs = {0};
69               struct kvm_sregs sregs = {0};
70               struct kvm_debugregs debugregs = {0};
71 
72               /*
73                * In a properly running test the following
74                * get and set calls will return success despite
75                * crosvm being halted.
76                */
77               if (kill(getppid(), SIGSTOP)) {
78                 fprintf(stderr, "failed to send stop to crosvm\n");
79                 exit(1);
80               }
81 
82               printf("get regs query on crosvm\n");
83               if (crosvm_vcpu_get_regs(vcpu, &regs)) {
84                 /*
85                  * The failure mode for this test is that crosvm remains
86                  * halted (since the plugin hasn't returned from
87                  * crosvm_vcpu_[g|s]et_regs() to resume crosvm) and
88                  * the test times out.
89                  */
90                 fprintf(stderr, "failed to query regs on hint port\n");
91                 exit(1);
92               }
93 
94               printf("set regs query on crosvm\n");
95               if (crosvm_vcpu_set_regs(vcpu, &regs)) {
96                 fprintf(stderr, "failed to set regs on hint port\n");
97                 exit(1);
98               }
99 
100               printf("get sregs query on crosvm\n");
101               if (crosvm_vcpu_get_sregs(vcpu, &sregs)) {
102                 fprintf(stderr, "failed to query sregs on hint port\n");
103                 exit(1);
104               }
105               printf("set sregs query on crosvm\n");
106               if (crosvm_vcpu_set_sregs(vcpu, &sregs)) {
107                 fprintf(stderr, "failed to set sregs on hint port\n");
108                 exit(1);
109               }
110 
111               printf("get debugregs query on crosvm\n");
112               if (crosvm_vcpu_get_debugregs(vcpu, &debugregs)) {
113                 fprintf(stderr, "failed to query debugregs on hint port\n");
114                 exit(1);
115               }
116               printf("set debugregs query on crosvm\n");
117               if (crosvm_vcpu_set_debugregs(vcpu, &debugregs)) {
118                 fprintf(stderr, "failed to set debugregs on hint port\n");
119                 exit(1);
120               }
121 
122               got_regs = 1;
123 
124               if (kill(getppid(), SIGCONT)) {
125                 fprintf(stderr, "failed to send continue to crosvm\n");
126                 exit(1);
127               }
128             }
129             if (evt.io_access.address_space == CROSVM_ADDRESS_SPACE_IOPORT &&
130                 evt.io_access.address == KILL_ADDRESS &&
131                 evt.io_access.is_write &&
132                 evt.io_access.length == 1 &&
133                 evt.io_access.data[0] == 1)
134             {
135                 uint64_t dummy = 1;
136                 write(g_kill_evt, &dummy, sizeof(dummy));
137                 return NULL;
138             }
139         }
140 
141         crosvm_vcpu_resume(vcpu);
142     }
143 
144     return NULL;
145 }
146 
main(int argc,char ** argv)147 int main(int argc, char** argv) {
148     const uint8_t code[] = {
149     /*
150     B007    mov al,0x7
151     BA0005  mov dx,0x500
152     EE      out dx,al
153     BAF903  mov dx,0x3f9
154     B001    mov al,0x1
155     EE      out dx,al
156     F4      hlt
157     */
158         0xb0, EAX_HINT_VALUE,
159         0xba, (HINT_ADDRESS & 0xFF), ((HINT_ADDRESS >> 8) & 0xFF),
160         0xee,
161         0xba, (KILL_ADDRESS & 0xFF), ((KILL_ADDRESS >> 8) & 0xFF),
162         0xb0, 0x01,
163         0xee,
164         0xf4
165     };
166 
167     struct crosvm *crosvm;
168     int ret = crosvm_connect(&crosvm);
169     if (ret) {
170         fprintf(stderr, "failed to connect to crosvm: %d\n", ret);
171         return 1;
172     }
173 
174     /*
175      * Not strictly necessary, but demonstrates we can have as many connections
176      * as we please.
177      */
178     struct crosvm *extra_crosvm;
179     ret = crosvm_new_connection(crosvm, &extra_crosvm);
180     if (ret) {
181         fprintf(stderr, "failed to make new socket: %d\n", ret);
182         return 1;
183     }
184 
185     /* We needs this eventfd to know when to exit before being killed. */
186     g_kill_evt = crosvm_get_shutdown_eventfd(crosvm);
187     if (g_kill_evt < 0) {
188         fprintf(stderr, "failed to get kill eventfd: %d\n", g_kill_evt);
189         return 1;
190     }
191 
192     ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
193                                HINT_ADDRESS, 1);
194     if (ret) {
195         fprintf(stderr, "failed to reserve hint ioport range: %d\n", ret);
196         return 1;
197     }
198 
199     ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
200                                KILL_ADDRESS, 1);
201     if (ret) {
202         fprintf(stderr, "failed to reserve kill ioport range: %d\n", ret);
203         return 1;
204     }
205 
206     struct crosvm_hint_detail details = {0};
207     details.match_rax = 1;
208     details.rax = EAX_HINT_VALUE;
209     details.send_sregs = 1;
210     details.send_debugregs = 1;
211 
212     struct crosvm_hint hint = {0};
213     hint.address_space = CROSVM_ADDRESS_SPACE_IOPORT;
214     hint.address = HINT_ADDRESS;
215     hint.address_flags = CROSVM_HINT_ON_WRITE;
216     hint.details_count = 1;
217     hint.details = &details;
218 
219     ret = crosvm_set_hypercall_hint(crosvm, 1, &hint);
220     if (ret) {
221         fprintf(stderr, "failed to set hypercall hint: %d\n", ret);
222         return 1;
223     }
224 
225     int mem_size = 0x2000;
226     int mem_fd = syscall(SYS_memfd_create, "guest_mem",
227                          MFD_CLOEXEC | MFD_ALLOW_SEALING);
228     if (mem_fd < 0) {
229         fprintf(stderr, "failed to create guest memfd: %d\n", errno);
230         return 1;
231     }
232     ret = ftruncate(mem_fd, mem_size);
233     if (ret) {
234         fprintf(stderr, "failed to set size of guest memory: %d\n", errno);
235         return 1;
236     }
237     uint8_t *mem = mmap(NULL, mem_size, PROT_READ | PROT_WRITE, MAP_SHARED,
238                         mem_fd, 0x1000);
239     if (mem == MAP_FAILED) {
240         fprintf(stderr, "failed to mmap guest memory: %d\n", errno);
241         return 1;
242     }
243     fcntl(mem_fd, F_ADD_SEALS, F_SEAL_SHRINK);
244     memcpy(mem, code, sizeof(code));
245 
246     struct crosvm_memory *mem_obj;
247     ret = crosvm_create_memory(crosvm, mem_fd, 0x1000, 0x1000, 0x1000, false,
248                                false, &mem_obj);
249     if (ret) {
250         fprintf(stderr, "failed to create memory in crosvm: %d\n", ret);
251         return 1;
252     }
253 
254     /* get and creat a thread for each vcpu */
255     struct crosvm_vcpu *vcpus[32];
256     pthread_t vcpu_threads[32];
257     uint32_t vcpu_count;
258     for (vcpu_count = 0; vcpu_count < 32; vcpu_count++) {
259         ret = crosvm_get_vcpu(crosvm, vcpu_count, &vcpus[vcpu_count]);
260         if (ret == -ENOENT)
261             break;
262 
263         if (ret) {
264             fprintf(stderr, "error while getting all vcpus: %d\n", ret);
265             return 1;
266         }
267         pthread_create(&vcpu_threads[vcpu_count], NULL, vcpu_thread,
268                        vcpus[vcpu_count]);
269     }
270 
271     ret = crosvm_start(extra_crosvm);
272     if (ret) {
273         fprintf(stderr, "failed to tell crosvm to start: %d\n", ret);
274         return 1;
275     }
276 
277     /* Wait for crosvm to request that we exit otherwise we will be killed. */
278     uint64_t dummy;
279     read(g_kill_evt, &dummy, 8);
280 
281     ret = crosvm_destroy_memory(crosvm, &mem_obj);
282     if (ret) {
283         fprintf(stderr, "failed to destroy memory in crosvm: %d\n", ret);
284         return 1;
285     }
286 
287     ret = crosvm_set_hypercall_hint(crosvm, 0, NULL);
288     if (ret) {
289         fprintf(stderr, "failed to clear hypercall hint: %d\n", ret);
290         return 1;
291     }
292 
293     ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
294                                HINT_ADDRESS, 0);
295     if (ret) {
296         fprintf(stderr, "failed to unreserve hint ioport range: %d\n", ret);
297         return 1;
298     }
299 
300     ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
301                                KILL_ADDRESS, 0);
302     if (ret) {
303         fprintf(stderr, "failed to unreserve kill ioport range: %d\n", ret);
304         return 1;
305     }
306 
307     if (!got_regs) {
308       fprintf(stderr, "vm ran to completion without reg query\n");
309       return 1;
310     }
311 
312     return 0;
313 }
314