1 /*
2 * Copyright 2019 The Chromium OS Authors. All rights reserved.
3 * Use of this source code is governed by a BSD-style license that can be
4 * found in the LICENSE file.
5 */
6
7 #include <errno.h>
8 #include <fcntl.h>
9 #include <linux/memfd.h>
10 #include <pthread.h>
11 #include <signal.h>
12 #include <stdint.h>
13 #include <stdio.h>
14 #include <stdlib.h>
15 #include <string.h>
16 #include <sys/mman.h>
17 #include <sys/syscall.h>
18 #include <time.h>
19 #include <unistd.h>
20
21 #include "crosvm.h"
22
23 #ifndef F_LINUX_SPECIFIC_BASE
24 #define F_LINUX_SPECIFIC_BASE 1024
25 #endif
26
27 #ifndef F_ADD_SEALS
28 #define F_ADD_SEALS (F_LINUX_SPECIFIC_BASE + 9)
29 #endif
30
31 #ifndef F_SEAL_SHRINK
32 #define F_SEAL_SHRINK 0x0002
33 #endif
34
35 #define KILL_ADDRESS 0x3f9
36 #define HINT_ADDRESS 0x500
37 #define EAX_HINT_VALUE 0x77
38
39 int g_kill_evt;
40 int got_regs = 0;
41
vcpu_thread(void * arg)42 void *vcpu_thread(void *arg) {
43 struct crosvm_vcpu *vcpu = arg;
44 struct crosvm_vcpu_event evt;
45 while (crosvm_vcpu_wait(vcpu, &evt) == 0) {
46 if (evt.kind == CROSVM_VCPU_EVENT_KIND_INIT) {
47 struct kvm_sregs sregs;
48 crosvm_vcpu_get_sregs(vcpu, &sregs);
49 sregs.cs.base = 0;
50 sregs.cs.selector = 0;
51 sregs.es.base = KILL_ADDRESS;
52 sregs.es.selector = 0;
53 crosvm_vcpu_set_sregs(vcpu, &sregs);
54
55 struct kvm_regs regs;
56 crosvm_vcpu_get_regs(vcpu, ®s);
57 regs.rip = 0x1000;
58 regs.rax = 2;
59 regs.rbx = 7;
60 regs.rflags = 2;
61 crosvm_vcpu_set_regs(vcpu, ®s);
62 }
63 if (evt.kind == CROSVM_VCPU_EVENT_KIND_IO_ACCESS) {
64 if (evt.io_access.address_space == CROSVM_ADDRESS_SPACE_IOPORT &&
65 evt.io_access.address == HINT_ADDRESS &&
66 evt.io_access.is_write &&
67 evt.io_access.length == 1) {
68 struct kvm_regs regs = {0};
69 struct kvm_sregs sregs = {0};
70 struct kvm_debugregs debugregs = {0};
71
72 /*
73 * In a properly running test the following
74 * get and set calls will return success despite
75 * crosvm being halted.
76 */
77 if (kill(getppid(), SIGSTOP)) {
78 fprintf(stderr, "failed to send stop to crosvm\n");
79 exit(1);
80 }
81
82 printf("get regs query on crosvm\n");
83 if (crosvm_vcpu_get_regs(vcpu, ®s)) {
84 /*
85 * The failure mode for this test is that crosvm remains
86 * halted (since the plugin hasn't returned from
87 * crosvm_vcpu_[g|s]et_regs() to resume crosvm) and
88 * the test times out.
89 */
90 fprintf(stderr, "failed to query regs on hint port\n");
91 exit(1);
92 }
93
94 printf("set regs query on crosvm\n");
95 if (crosvm_vcpu_set_regs(vcpu, ®s)) {
96 fprintf(stderr, "failed to set regs on hint port\n");
97 exit(1);
98 }
99
100 printf("get sregs query on crosvm\n");
101 if (crosvm_vcpu_get_sregs(vcpu, &sregs)) {
102 fprintf(stderr, "failed to query sregs on hint port\n");
103 exit(1);
104 }
105 printf("set sregs query on crosvm\n");
106 if (crosvm_vcpu_set_sregs(vcpu, &sregs)) {
107 fprintf(stderr, "failed to set sregs on hint port\n");
108 exit(1);
109 }
110
111 printf("get debugregs query on crosvm\n");
112 if (crosvm_vcpu_get_debugregs(vcpu, &debugregs)) {
113 fprintf(stderr, "failed to query debugregs on hint port\n");
114 exit(1);
115 }
116 printf("set debugregs query on crosvm\n");
117 if (crosvm_vcpu_set_debugregs(vcpu, &debugregs)) {
118 fprintf(stderr, "failed to set debugregs on hint port\n");
119 exit(1);
120 }
121
122 got_regs = 1;
123
124 if (kill(getppid(), SIGCONT)) {
125 fprintf(stderr, "failed to send continue to crosvm\n");
126 exit(1);
127 }
128 }
129 if (evt.io_access.address_space == CROSVM_ADDRESS_SPACE_IOPORT &&
130 evt.io_access.address == KILL_ADDRESS &&
131 evt.io_access.is_write &&
132 evt.io_access.length == 1 &&
133 evt.io_access.data[0] == 1)
134 {
135 uint64_t dummy = 1;
136 write(g_kill_evt, &dummy, sizeof(dummy));
137 return NULL;
138 }
139 }
140
141 crosvm_vcpu_resume(vcpu);
142 }
143
144 return NULL;
145 }
146
main(int argc,char ** argv)147 int main(int argc, char** argv) {
148 const uint8_t code[] = {
149 /*
150 B007 mov al,0x7
151 BA0005 mov dx,0x500
152 EE out dx,al
153 BAF903 mov dx,0x3f9
154 B001 mov al,0x1
155 EE out dx,al
156 F4 hlt
157 */
158 0xb0, EAX_HINT_VALUE,
159 0xba, (HINT_ADDRESS & 0xFF), ((HINT_ADDRESS >> 8) & 0xFF),
160 0xee,
161 0xba, (KILL_ADDRESS & 0xFF), ((KILL_ADDRESS >> 8) & 0xFF),
162 0xb0, 0x01,
163 0xee,
164 0xf4
165 };
166
167 struct crosvm *crosvm;
168 int ret = crosvm_connect(&crosvm);
169 if (ret) {
170 fprintf(stderr, "failed to connect to crosvm: %d\n", ret);
171 return 1;
172 }
173
174 /*
175 * Not strictly necessary, but demonstrates we can have as many connections
176 * as we please.
177 */
178 struct crosvm *extra_crosvm;
179 ret = crosvm_new_connection(crosvm, &extra_crosvm);
180 if (ret) {
181 fprintf(stderr, "failed to make new socket: %d\n", ret);
182 return 1;
183 }
184
185 /* We needs this eventfd to know when to exit before being killed. */
186 g_kill_evt = crosvm_get_shutdown_eventfd(crosvm);
187 if (g_kill_evt < 0) {
188 fprintf(stderr, "failed to get kill eventfd: %d\n", g_kill_evt);
189 return 1;
190 }
191
192 ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
193 HINT_ADDRESS, 1);
194 if (ret) {
195 fprintf(stderr, "failed to reserve hint ioport range: %d\n", ret);
196 return 1;
197 }
198
199 ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
200 KILL_ADDRESS, 1);
201 if (ret) {
202 fprintf(stderr, "failed to reserve kill ioport range: %d\n", ret);
203 return 1;
204 }
205
206 struct crosvm_hint_detail details = {0};
207 details.match_rax = 1;
208 details.rax = EAX_HINT_VALUE;
209 details.send_sregs = 1;
210 details.send_debugregs = 1;
211
212 struct crosvm_hint hint = {0};
213 hint.address_space = CROSVM_ADDRESS_SPACE_IOPORT;
214 hint.address = HINT_ADDRESS;
215 hint.address_flags = CROSVM_HINT_ON_WRITE;
216 hint.details_count = 1;
217 hint.details = &details;
218
219 ret = crosvm_set_hypercall_hint(crosvm, 1, &hint);
220 if (ret) {
221 fprintf(stderr, "failed to set hypercall hint: %d\n", ret);
222 return 1;
223 }
224
225 int mem_size = 0x2000;
226 int mem_fd = syscall(SYS_memfd_create, "guest_mem",
227 MFD_CLOEXEC | MFD_ALLOW_SEALING);
228 if (mem_fd < 0) {
229 fprintf(stderr, "failed to create guest memfd: %d\n", errno);
230 return 1;
231 }
232 ret = ftruncate(mem_fd, mem_size);
233 if (ret) {
234 fprintf(stderr, "failed to set size of guest memory: %d\n", errno);
235 return 1;
236 }
237 uint8_t *mem = mmap(NULL, mem_size, PROT_READ | PROT_WRITE, MAP_SHARED,
238 mem_fd, 0x1000);
239 if (mem == MAP_FAILED) {
240 fprintf(stderr, "failed to mmap guest memory: %d\n", errno);
241 return 1;
242 }
243 fcntl(mem_fd, F_ADD_SEALS, F_SEAL_SHRINK);
244 memcpy(mem, code, sizeof(code));
245
246 struct crosvm_memory *mem_obj;
247 ret = crosvm_create_memory(crosvm, mem_fd, 0x1000, 0x1000, 0x1000, false,
248 false, &mem_obj);
249 if (ret) {
250 fprintf(stderr, "failed to create memory in crosvm: %d\n", ret);
251 return 1;
252 }
253
254 /* get and creat a thread for each vcpu */
255 struct crosvm_vcpu *vcpus[32];
256 pthread_t vcpu_threads[32];
257 uint32_t vcpu_count;
258 for (vcpu_count = 0; vcpu_count < 32; vcpu_count++) {
259 ret = crosvm_get_vcpu(crosvm, vcpu_count, &vcpus[vcpu_count]);
260 if (ret == -ENOENT)
261 break;
262
263 if (ret) {
264 fprintf(stderr, "error while getting all vcpus: %d\n", ret);
265 return 1;
266 }
267 pthread_create(&vcpu_threads[vcpu_count], NULL, vcpu_thread,
268 vcpus[vcpu_count]);
269 }
270
271 ret = crosvm_start(extra_crosvm);
272 if (ret) {
273 fprintf(stderr, "failed to tell crosvm to start: %d\n", ret);
274 return 1;
275 }
276
277 /* Wait for crosvm to request that we exit otherwise we will be killed. */
278 uint64_t dummy;
279 read(g_kill_evt, &dummy, 8);
280
281 ret = crosvm_destroy_memory(crosvm, &mem_obj);
282 if (ret) {
283 fprintf(stderr, "failed to destroy memory in crosvm: %d\n", ret);
284 return 1;
285 }
286
287 ret = crosvm_set_hypercall_hint(crosvm, 0, NULL);
288 if (ret) {
289 fprintf(stderr, "failed to clear hypercall hint: %d\n", ret);
290 return 1;
291 }
292
293 ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
294 HINT_ADDRESS, 0);
295 if (ret) {
296 fprintf(stderr, "failed to unreserve hint ioport range: %d\n", ret);
297 return 1;
298 }
299
300 ret = crosvm_reserve_range(crosvm, CROSVM_ADDRESS_SPACE_IOPORT,
301 KILL_ADDRESS, 0);
302 if (ret) {
303 fprintf(stderr, "failed to unreserve kill ioport range: %d\n", ret);
304 return 1;
305 }
306
307 if (!got_regs) {
308 fprintf(stderr, "vm ran to completion without reg query\n");
309 return 1;
310 }
311
312 return 0;
313 }
314