ia64/xen-unstable

view xen/arch/x86/x86_32/entry.S @ 16263:23582bcda6e1

x86: Clean up NMI delivery logic. Allow set_trap_table vector 2 to be
specified as not disabling event delivery, just like any other vector.
Signed-off-by: Keir Fraser <keir@xensource.com>
author Keir Fraser <keir@xensource.com>
date Mon Oct 29 09:49:39 2007 +0000 (2007-10-29)
parents 4970cbf9b19e
children e48453f82d30
line source
1 /*
2 * Hypercall and fault low-level handling routines.
3 *
4 * Copyright (c) 2002-2004, K A Fraser
5 * Copyright (c) 1991, 1992 Linus Torvalds
6 *
7 * Calling back to a guest OS:
8 * ===========================
9 *
10 * First, we require that all callbacks (either via a supplied
11 * interrupt-descriptor-table, or via the special event or failsafe callbacks
12 * in the shared-info-structure) are to ring 1. This just makes life easier,
13 * in that it means we don't have to do messy GDT/LDT lookups to find
14 * out which the privilege-level of the return code-selector. That code
15 * would just be a hassle to write, and would need to account for running
16 * off the end of the GDT/LDT, for example. For all callbacks we check
17 * that the provided return CS is not == __HYPERVISOR_{CS,DS}. Apart from that
18 * we're safe as don't allow a guest OS to install ring-0 privileges into the
19 * GDT/LDT. It's up to the guest OS to ensure all returns via the IDT are to
20 * ring 1. If not, we load incorrect SS/ESP values from the TSS (for ring 1
21 * rather than the correct ring) and bad things are bound to ensue -- IRET is
22 * likely to fault, and we may end up killing the domain (no harm can
23 * come to Xen, though).
24 *
25 * When doing a callback, we check if the return CS is in ring 0. If so,
26 * callback is delayed until next return to ring != 0.
27 * If return CS is in ring 1, then we create a callback frame
28 * starting at return SS/ESP. The base of the frame does an intra-privilege
29 * interrupt-return.
30 * If return CS is in ring > 1, we create a callback frame starting
31 * at SS/ESP taken from appropriate section of the current TSS. The base
32 * of the frame does an inter-privilege interrupt-return.
33 *
34 * Note that the "failsafe callback" uses a special stackframe:
35 * { return_DS, return_ES, return_FS, return_GS, return_EIP,
36 * return_CS, return_EFLAGS[, return_ESP, return_SS] }
37 * That is, original values for DS/ES/FS/GS are placed on stack rather than
38 * in DS/ES/FS/GS themselves. Why? It saves us loading them, only to have them
39 * saved/restored in guest OS. Furthermore, if we load them we may cause
40 * a fault if they are invalid, which is a hassle to deal with. We avoid
41 * that problem if we don't load them :-) This property allows us to use
42 * the failsafe callback as a fallback: if we ever fault on loading DS/ES/FS/GS
43 * on return to ring != 0, we can simply package it up as a return via
44 * the failsafe callback, and let the guest OS sort it out (perhaps by
45 * killing an application process). Note that we also do this for any
46 * faulting IRET -- just let the guest OS handle it via the event
47 * callback.
48 *
49 * We terminate a domain in the following cases:
50 * - creating a callback stack frame (due to bad ring-1 stack).
51 * - faulting IRET on entry to failsafe callback handler.
52 * So, each domain must keep its ring-1 %ss/%esp and failsafe callback
53 * handler in good order (absolutely no faults allowed!).
54 */
56 #include <xen/config.h>
57 #include <xen/errno.h>
58 #include <xen/softirq.h>
59 #include <asm/asm_defns.h>
60 #include <asm/apicdef.h>
61 #include <asm/page.h>
62 #include <public/xen.h>
64 #define GET_GUEST_REGS(reg) \
65 movl $~(STACK_SIZE-1),reg; \
66 andl %esp,reg; \
67 orl $(STACK_SIZE-CPUINFO_sizeof),reg;
69 #define GET_CURRENT(reg) \
70 movl $STACK_SIZE-4, reg; \
71 orl %esp, reg; \
72 andl $~3,reg; \
73 movl (reg),reg;
75 ALIGN
76 restore_all_guest:
77 ASSERT_INTERRUPTS_DISABLED
78 testl $X86_EFLAGS_VM,UREGS_eflags(%esp)
79 popl %ebx
80 popl %ecx
81 popl %edx
82 popl %esi
83 popl %edi
84 popl %ebp
85 popl %eax
86 leal 4(%esp),%esp
87 jnz .Lrestore_iret_guest
88 #ifdef CONFIG_X86_SUPERVISOR_MODE_KERNEL
89 testb $2,UREGS_cs-UREGS_eip(%esp)
90 jnz .Lrestore_sregs_guest
91 call restore_ring0_guest
92 jmp .Lrestore_iret_guest
93 #endif
94 .Lrestore_sregs_guest:
95 .Lft1: mov UREGS_ds-UREGS_eip(%esp),%ds
96 .Lft2: mov UREGS_es-UREGS_eip(%esp),%es
97 .Lft3: mov UREGS_fs-UREGS_eip(%esp),%fs
98 .Lft4: mov UREGS_gs-UREGS_eip(%esp),%gs
99 .Lrestore_iret_guest:
100 .Lft5: iret
101 .section .fixup,"ax"
102 .Lfx1: sti
103 SAVE_ALL_GPRS
104 mov UREGS_error_code(%esp),%esi
105 pushfl # EFLAGS
106 movl $__HYPERVISOR_CS,%eax
107 pushl %eax # CS
108 movl $.Ldf1,%eax
109 pushl %eax # EIP
110 pushl %esi # error_code/entry_vector
111 jmp handle_exception
112 .Ldf1: GET_CURRENT(%ebx)
113 jmp test_all_events
114 failsafe_callback:
115 GET_CURRENT(%ebx)
116 leal VCPU_trap_bounce(%ebx),%edx
117 movl VCPU_failsafe_addr(%ebx),%eax
118 movl %eax,TRAPBOUNCE_eip(%edx)
119 movl VCPU_failsafe_sel(%ebx),%eax
120 movw %ax,TRAPBOUNCE_cs(%edx)
121 movb $TBF_FAILSAFE,TRAPBOUNCE_flags(%edx)
122 bt $_VGCF_failsafe_disables_events,VCPU_guest_context_flags(%ebx)
123 jnc 1f
124 orb $TBF_INTERRUPT,TRAPBOUNCE_flags(%edx)
125 1: call create_bounce_frame
126 xorl %eax,%eax
127 movl %eax,UREGS_ds(%esp)
128 movl %eax,UREGS_es(%esp)
129 movl %eax,UREGS_fs(%esp)
130 movl %eax,UREGS_gs(%esp)
131 jmp test_all_events
132 .previous
133 .section __pre_ex_table,"a"
134 .long .Lft1,.Lfx1
135 .long .Lft2,.Lfx1
136 .long .Lft3,.Lfx1
137 .long .Lft4,.Lfx1
138 .long .Lft5,.Lfx1
139 .previous
140 .section __ex_table,"a"
141 .long .Ldf1,failsafe_callback
142 .previous
144 ALIGN
145 restore_all_xen:
146 popl %ebx
147 popl %ecx
148 popl %edx
149 popl %esi
150 popl %edi
151 popl %ebp
152 popl %eax
153 addl $4,%esp
154 iret
156 ALIGN
157 ENTRY(hypercall)
158 subl $4,%esp
159 FIXUP_RING0_GUEST_STACK
160 SAVE_ALL(1f,1f)
161 1: sti
162 GET_CURRENT(%ebx)
163 cmpl $NR_hypercalls,%eax
164 jae bad_hypercall
165 PERFC_INCR(PERFC_hypercalls, %eax, %ebx)
166 #ifndef NDEBUG
167 /* Create shadow parameters and corrupt those not used by this call. */
168 pushl %eax
169 pushl UREGS_eip+4(%esp)
170 pushl 28(%esp) # EBP
171 pushl 28(%esp) # EDI
172 pushl 28(%esp) # ESI
173 pushl 28(%esp) # EDX
174 pushl 28(%esp) # ECX
175 pushl 28(%esp) # EBX
176 movzb hypercall_args_table(,%eax,1),%ecx
177 leal (%esp,%ecx,4),%edi
178 subl $6,%ecx
179 negl %ecx
180 movl %eax,%esi
181 movl $0xDEADBEEF,%eax
182 rep stosl
183 movl %esi,%eax
184 #define SHADOW_BYTES 32 /* 6 shadow parameters + EIP + hypercall # */
185 #else
186 /*
187 * We need shadow parameters even on non-debug builds. We depend on the
188 * original versions not being clobbered (needed to create a hypercall
189 * continuation). But that isn't guaranteed by the function-call ABI.
190 */
191 pushl 20(%esp) # EBP
192 pushl 20(%esp) # EDI
193 pushl 20(%esp) # ESI
194 pushl 20(%esp) # EDX
195 pushl 20(%esp) # ECX
196 pushl 20(%esp) # EBX
197 #define SHADOW_BYTES 24 /* 6 shadow parameters */
198 #endif
199 cmpb $0,tb_init_done
200 je tracing_off
201 call trace_hypercall
202 /* Now restore all the registers that trace_hypercall clobbered */
203 movl UREGS_eax+SHADOW_BYTES(%esp),%eax /* Hypercall # */
204 #undef SHADOW_BYTES
205 tracing_off:
206 call *hypercall_table(,%eax,4)
207 addl $24,%esp # Discard the shadow parameters
208 #ifndef NDEBUG
209 /* Deliberately corrupt real parameter regs used by this hypercall. */
210 popl %ecx # Shadow EIP
211 cmpl %ecx,UREGS_eip+4(%esp)
212 popl %ecx # Shadow hypercall index
213 jne skip_clobber # If EIP has changed then don't clobber
214 movzb hypercall_args_table(,%ecx,1),%ecx
215 movl %esp,%edi
216 movl %eax,%esi
217 movl $0xDEADBEEF,%eax
218 rep stosl
219 movl %esi,%eax
220 skip_clobber:
221 #endif
222 movl %eax,UREGS_eax(%esp) # save the return value
224 test_all_events:
225 xorl %ecx,%ecx
226 notl %ecx
227 cli # tests must not race interrupts
228 /*test_softirqs:*/
229 movl VCPU_processor(%ebx),%eax
230 shl $IRQSTAT_shift,%eax
231 test %ecx,irq_stat(%eax,1)
232 jnz process_softirqs
233 testb $1,VCPU_nmi_pending(%ebx)
234 jnz process_nmi
235 test_guest_events:
236 movl VCPU_vcpu_info(%ebx),%eax
237 testb $0xFF,VCPUINFO_upcall_mask(%eax)
238 jnz restore_all_guest
239 testb $0xFF,VCPUINFO_upcall_pending(%eax)
240 jz restore_all_guest
241 /*process_guest_events:*/
242 sti
243 leal VCPU_trap_bounce(%ebx),%edx
244 movl VCPU_event_addr(%ebx),%eax
245 movl %eax,TRAPBOUNCE_eip(%edx)
246 movl VCPU_event_sel(%ebx),%eax
247 movw %ax,TRAPBOUNCE_cs(%edx)
248 movb $TBF_INTERRUPT,TRAPBOUNCE_flags(%edx)
249 call create_bounce_frame
250 jmp test_all_events
252 ALIGN
253 process_softirqs:
254 sti
255 call do_softirq
256 jmp test_all_events
258 ALIGN
259 process_nmi:
260 testb $1,VCPU_nmi_masked(%ebx)
261 jnz test_guest_events
262 sti
263 movb $0,VCPU_nmi_pending(%ebx)
264 call set_guest_nmi_trapbounce
265 test %eax,%eax
266 jz test_all_events
267 movb $1,VCPU_nmi_masked(%ebx)
268 leal VCPU_trap_bounce(%ebx),%edx
269 call create_bounce_frame
270 jmp test_all_events
272 bad_hypercall:
273 movl $-ENOSYS,UREGS_eax(%esp)
274 jmp test_all_events
276 /* CREATE A BASIC EXCEPTION FRAME ON GUEST OS (RING-1) STACK: */
277 /* {EIP, CS, EFLAGS, [ESP, SS]} */
278 /* %edx == trap_bounce, %ebx == struct vcpu */
279 /* %eax,%ecx are clobbered. %gs:%esi contain new UREGS_ss/UREGS_esp. */
280 create_bounce_frame:
281 ASSERT_INTERRUPTS_ENABLED
282 movl UREGS_eflags+4(%esp),%ecx
283 movb UREGS_cs+4(%esp),%cl
284 testl $(2|X86_EFLAGS_VM),%ecx
285 jz ring1 /* jump if returning to an existing ring-1 activation */
286 movl VCPU_kernel_sp(%ebx),%esi
287 .Lft6: mov VCPU_kernel_ss(%ebx),%gs
288 testl $X86_EFLAGS_VM,UREGS_eflags+4(%esp)
289 jz .Lnvm86_1
290 subl $16,%esi /* push ES/DS/FS/GS (VM86 stack frame) */
291 movl UREGS_es+4(%esp),%eax
292 .Lft7: movl %eax,%gs:(%esi)
293 movl UREGS_ds+4(%esp),%eax
294 .Lft8: movl %eax,%gs:4(%esi)
295 movl UREGS_fs+4(%esp),%eax
296 .Lft9: movl %eax,%gs:8(%esi)
297 movl UREGS_gs+4(%esp),%eax
298 .Lft10: movl %eax,%gs:12(%esi)
299 .Lnvm86_1:
300 subl $8,%esi /* push SS/ESP (inter-priv iret) */
301 movl UREGS_esp+4(%esp),%eax
302 .Lft11: movl %eax,%gs:(%esi)
303 movl UREGS_ss+4(%esp),%eax
304 .Lft12: movl %eax,%gs:4(%esi)
305 jmp 1f
306 ring1: /* obtain ss/esp from oldss/oldesp -- a ring-1 activation exists */
307 movl UREGS_esp+4(%esp),%esi
308 .Lft13: mov UREGS_ss+4(%esp),%gs
309 1: /* Construct a stack frame: EFLAGS, CS/EIP */
310 movb TRAPBOUNCE_flags(%edx),%cl
311 subl $12,%esi
312 movl UREGS_eip+4(%esp),%eax
313 .Lft14: movl %eax,%gs:(%esi)
314 movl VCPU_vcpu_info(%ebx),%eax
315 pushl VCPUINFO_upcall_mask(%eax)
316 testb $TBF_INTERRUPT,%cl
317 setnz %ch # TBF_INTERRUPT -> set upcall mask
318 orb %ch,VCPUINFO_upcall_mask(%eax)
319 popl %eax
320 shll $16,%eax # Bits 16-23: saved_upcall_mask
321 movw UREGS_cs+4(%esp),%ax # Bits 0-15: CS
322 #ifdef CONFIG_X86_SUPERVISOR_MODE_KERNEL
323 testw $2,%ax
324 jnz .Lft15
325 and $~3,%ax # RPL 1 -> RPL 0
326 #endif
327 .Lft15: movl %eax,%gs:4(%esi)
328 test $0x00FF0000,%eax # Bits 16-23: saved_upcall_mask
329 setz %ch # %ch == !saved_upcall_mask
330 movl UREGS_eflags+4(%esp),%eax
331 andl $~X86_EFLAGS_IF,%eax
332 shlb $1,%ch # Bit 9 (EFLAGS.IF)
333 orb %ch,%ah # Fold EFLAGS.IF into %eax
334 .Lft16: movl %eax,%gs:8(%esi)
335 test $TBF_EXCEPTION_ERRCODE,%cl
336 jz 1f
337 subl $4,%esi # push error_code onto guest frame
338 movl TRAPBOUNCE_error_code(%edx),%eax
339 .Lft17: movl %eax,%gs:(%esi)
340 1: testb $TBF_FAILSAFE,%cl
341 jz 2f
342 subl $16,%esi # add DS/ES/FS/GS to failsafe stack frame
343 testl $X86_EFLAGS_VM,UREGS_eflags+4(%esp)
344 jz .Lnvm86_2
345 xorl %eax,%eax # VM86: we write zero selector values
346 .Lft18: movl %eax,%gs:(%esi)
347 .Lft19: movl %eax,%gs:4(%esi)
348 .Lft20: movl %eax,%gs:8(%esi)
349 .Lft21: movl %eax,%gs:12(%esi)
350 jmp 2f
351 .Lnvm86_2:
352 movl UREGS_ds+4(%esp),%eax # non-VM86: write real selector values
353 .Lft22: movl %eax,%gs:(%esi)
354 movl UREGS_es+4(%esp),%eax
355 .Lft23: movl %eax,%gs:4(%esi)
356 movl UREGS_fs+4(%esp),%eax
357 .Lft24: movl %eax,%gs:8(%esi)
358 movl UREGS_gs+4(%esp),%eax
359 .Lft25: movl %eax,%gs:12(%esi)
360 2: testl $X86_EFLAGS_VM,UREGS_eflags+4(%esp)
361 jz .Lnvm86_3
362 xorl %eax,%eax /* zero DS-GS, just as a real CPU would */
363 movl %eax,UREGS_ds+4(%esp)
364 movl %eax,UREGS_es+4(%esp)
365 movl %eax,UREGS_fs+4(%esp)
366 movl %eax,UREGS_gs+4(%esp)
367 .Lnvm86_3:
368 /* Rewrite our stack frame and return to ring 1. */
369 /* IA32 Ref. Vol. 3: TF, VM, RF and NT flags are cleared on trap. */
370 andl $~(X86_EFLAGS_VM|X86_EFLAGS_RF|\
371 X86_EFLAGS_NT|X86_EFLAGS_TF),UREGS_eflags+4(%esp)
372 mov %gs,UREGS_ss+4(%esp)
373 movl %esi,UREGS_esp+4(%esp)
374 movzwl TRAPBOUNCE_cs(%edx),%eax
375 /* Null selectors (0-3) are not allowed. */
376 testl $~3,%eax
377 jz domain_crash_synchronous
378 movl %eax,UREGS_cs+4(%esp)
379 movl TRAPBOUNCE_eip(%edx),%eax
380 movl %eax,UREGS_eip+4(%esp)
381 ret
382 .section __ex_table,"a"
383 .long .Lft6,domain_crash_synchronous , .Lft7,domain_crash_synchronous
384 .long .Lft8,domain_crash_synchronous , .Lft9,domain_crash_synchronous
385 .long .Lft10,domain_crash_synchronous , .Lft11,domain_crash_synchronous
386 .long .Lft12,domain_crash_synchronous , .Lft13,domain_crash_synchronous
387 .long .Lft14,domain_crash_synchronous , .Lft15,domain_crash_synchronous
388 .long .Lft16,domain_crash_synchronous , .Lft17,domain_crash_synchronous
389 .long .Lft18,domain_crash_synchronous , .Lft19,domain_crash_synchronous
390 .long .Lft20,domain_crash_synchronous , .Lft21,domain_crash_synchronous
391 .long .Lft22,domain_crash_synchronous , .Lft23,domain_crash_synchronous
392 .long .Lft24,domain_crash_synchronous , .Lft25,domain_crash_synchronous
393 .previous
395 domain_crash_synchronous_string:
396 .asciz "domain_crash_sync called from entry.S (%lx)\n"
398 domain_crash_synchronous:
399 pushl $domain_crash_synchronous_string
400 call printk
401 jmp __domain_crash_synchronous
403 ALIGN
404 ENTRY(ret_from_intr)
405 GET_CURRENT(%ebx)
406 movl UREGS_eflags(%esp),%eax
407 movb UREGS_cs(%esp),%al
408 testl $(3|X86_EFLAGS_VM),%eax
409 jnz test_all_events
410 jmp restore_all_xen
412 ENTRY(divide_error)
413 pushl $TRAP_divide_error<<16
414 ALIGN
415 handle_exception:
416 FIXUP_RING0_GUEST_STACK
417 SAVE_ALL(1f,2f)
418 .text 1
419 /* Exception within Xen: make sure we have valid %ds,%es. */
420 1: mov %ecx,%ds
421 mov %ecx,%es
422 jmp 2f
423 .previous
424 2: testb $X86_EFLAGS_IF>>8,UREGS_eflags+1(%esp)
425 jz exception_with_ints_disabled
426 sti # re-enable interrupts
427 1: xorl %eax,%eax
428 movw UREGS_entry_vector(%esp),%ax
429 movl %esp,%edx
430 pushl %edx # push the cpu_user_regs pointer
431 GET_CURRENT(%ebx)
432 PERFC_INCR(PERFC_exceptions, %eax, %ebx)
433 call *exception_table(,%eax,4)
434 addl $4,%esp
435 movl UREGS_eflags(%esp),%eax
436 movb UREGS_cs(%esp),%al
437 testl $(3|X86_EFLAGS_VM),%eax
438 jz restore_all_xen
439 leal VCPU_trap_bounce(%ebx),%edx
440 testb $TBF_EXCEPTION,TRAPBOUNCE_flags(%edx)
441 jz test_all_events
442 call create_bounce_frame
443 movb $0,TRAPBOUNCE_flags(%edx)
444 jmp test_all_events
446 exception_with_ints_disabled:
447 movl UREGS_eflags(%esp),%eax
448 movb UREGS_cs(%esp),%al
449 testl $(3|X86_EFLAGS_VM),%eax # interrupts disabled outside Xen?
450 jnz FATAL_exception_with_ints_disabled
451 pushl %esp
452 call search_pre_exception_table
453 addl $4,%esp
454 testl %eax,%eax # no fixup code for faulting EIP?
455 jz 1b
456 movl %eax,UREGS_eip(%esp)
457 movl %esp,%esi
458 subl $4,%esp
459 movl %esp,%edi
460 movl $UREGS_kernel_sizeof/4,%ecx
461 rep; movsl # make room for error_code/entry_vector
462 movl UREGS_error_code(%esp),%eax # error_code/entry_vector
463 movl %eax,UREGS_kernel_sizeof(%esp)
464 jmp restore_all_xen # return to fixup code
466 FATAL_exception_with_ints_disabled:
467 xorl %esi,%esi
468 movw UREGS_entry_vector(%esp),%si
469 movl %esp,%edx
470 pushl %edx # push the cpu_user_regs pointer
471 pushl %esi # push the trapnr (entry vector)
472 call fatal_trap
473 ud2
475 ENTRY(coprocessor_error)
476 pushl $TRAP_copro_error<<16
477 jmp handle_exception
479 ENTRY(simd_coprocessor_error)
480 pushl $TRAP_simd_error<<16
481 jmp handle_exception
483 ENTRY(device_not_available)
484 pushl $TRAP_no_device<<16
485 jmp handle_exception
487 ENTRY(debug)
488 pushl $TRAP_debug<<16
489 jmp handle_exception
491 ENTRY(int3)
492 pushl $TRAP_int3<<16
493 jmp handle_exception
495 ENTRY(overflow)
496 pushl $TRAP_overflow<<16
497 jmp handle_exception
499 ENTRY(bounds)
500 pushl $TRAP_bounds<<16
501 jmp handle_exception
503 ENTRY(invalid_op)
504 pushl $TRAP_invalid_op<<16
505 jmp handle_exception
507 ENTRY(coprocessor_segment_overrun)
508 pushl $TRAP_copro_seg<<16
509 jmp handle_exception
511 ENTRY(invalid_TSS)
512 movw $TRAP_invalid_tss,2(%esp)
513 jmp handle_exception
515 ENTRY(segment_not_present)
516 movw $TRAP_no_segment,2(%esp)
517 jmp handle_exception
519 ENTRY(stack_segment)
520 movw $TRAP_stack_error,2(%esp)
521 jmp handle_exception
523 ENTRY(general_protection)
524 movw $TRAP_gp_fault,2(%esp)
525 jmp handle_exception
527 ENTRY(alignment_check)
528 movw $TRAP_alignment_check,2(%esp)
529 jmp handle_exception
531 ENTRY(page_fault)
532 movw $TRAP_page_fault,2(%esp)
533 jmp handle_exception
535 ENTRY(spurious_interrupt_bug)
536 pushl $TRAP_spurious_int<<16
537 jmp handle_exception
539 ENTRY(early_page_fault)
540 SAVE_ALL(1f,1f)
541 1: movl %esp,%eax
542 pushl %eax
543 call do_early_page_fault
544 addl $4,%esp
545 jmp restore_all_xen
547 handle_nmi_mce:
548 #ifdef CONFIG_X86_SUPERVISOR_MODE_KERNEL
549 # NMI/MCE entry protocol is incompatible with guest kernel in ring 0.
550 addl $4,%esp
551 iret
552 #else
553 # Save state but do not trash the segment registers!
554 SAVE_ALL(.Lnmi_mce_xen,.Lnmi_mce_common)
555 .Lnmi_mce_common:
556 xorl %eax,%eax
557 movw UREGS_entry_vector(%esp),%ax
558 movl %esp,%edx
559 pushl %edx
560 call *exception_table(,%eax,4)
561 addl $4,%esp
562 /*
563 * NB. We may return to Xen context with polluted %ds/%es. But in such
564 * cases we have put guest DS/ES on the guest stack frame, which will
565 * be detected by SAVE_ALL(), or we have rolled back restore_guest.
566 */
567 jmp ret_from_intr
568 .Lnmi_mce_xen:
569 /* Check the outer (guest) context for %ds/%es state validity. */
570 GET_GUEST_REGS(%ebx)
571 testl $X86_EFLAGS_VM,%ss:UREGS_eflags(%ebx)
572 mov %ds,%eax
573 mov %es,%edx
574 jnz .Lnmi_mce_vm86
575 /* We may have interrupted Xen while messing with %ds/%es... */
576 cmpw %ax,%cx
577 mov %ecx,%ds /* Ensure %ds is valid */
578 cmove UREGS_ds(%ebx),%eax /* Grab guest DS if it wasn't in %ds */
579 cmpw %dx,%cx
580 movl %eax,UREGS_ds(%ebx) /* Ensure guest frame contains guest DS */
581 cmove UREGS_es(%ebx),%edx /* Grab guest ES if it wasn't in %es */
582 mov %ecx,%es /* Ensure %es is valid */
583 movl $.Lrestore_sregs_guest,%ecx
584 movl %edx,UREGS_es(%ebx) /* Ensure guest frame contains guest ES */
585 cmpl %ecx,UREGS_eip(%esp)
586 jbe .Lnmi_mce_common
587 cmpl $.Lrestore_iret_guest,UREGS_eip(%esp)
588 ja .Lnmi_mce_common
589 /* Roll outer context restore_guest back to restoring %ds/%es. */
590 movl %ecx,UREGS_eip(%esp)
591 jmp .Lnmi_mce_common
592 .Lnmi_mce_vm86:
593 /* vm86 is easy: the CPU saved %ds/%es so we can safely stomp them. */
594 mov %ecx,%ds
595 mov %ecx,%es
596 jmp .Lnmi_mce_common
597 #endif /* !CONFIG_X86_SUPERVISOR_MODE_KERNEL */
599 ENTRY(nmi)
600 pushl $TRAP_nmi<<16
601 jmp handle_nmi_mce
603 ENTRY(machine_check)
604 pushl $TRAP_machine_check<<16
605 jmp handle_nmi_mce
607 ENTRY(setup_vm86_frame)
608 mov %ecx,%ds
609 mov %ecx,%es
610 # Copies the entire stack frame forwards by 16 bytes.
611 .macro copy_vm86_words count=18
612 .if \count
613 pushl ((\count-1)*4)(%esp)
614 popl ((\count-1)*4)+16(%esp)
615 copy_vm86_words "(\count-1)"
616 .endif
617 .endm
618 copy_vm86_words
619 addl $16,%esp
620 ret
622 .data
624 ENTRY(exception_table)
625 .long do_divide_error
626 .long do_debug
627 .long do_nmi
628 .long do_int3
629 .long do_overflow
630 .long do_bounds
631 .long do_invalid_op
632 .long do_device_not_available
633 .long 0 # double fault
634 .long do_coprocessor_segment_overrun
635 .long do_invalid_TSS
636 .long do_segment_not_present
637 .long do_stack_segment
638 .long do_general_protection
639 .long do_page_fault
640 .long do_spurious_interrupt_bug
641 .long do_coprocessor_error
642 .long do_alignment_check
643 .long do_machine_check
644 .long do_simd_coprocessor_error
646 ENTRY(hypercall_table)
647 .long do_set_trap_table /* 0 */
648 .long do_mmu_update
649 .long do_set_gdt
650 .long do_stack_switch
651 .long do_set_callbacks
652 .long do_fpu_taskswitch /* 5 */
653 .long do_sched_op_compat
654 .long do_platform_op
655 .long do_set_debugreg
656 .long do_get_debugreg
657 .long do_update_descriptor /* 10 */
658 .long do_ni_hypercall
659 .long do_memory_op
660 .long do_multicall
661 .long do_update_va_mapping
662 .long do_set_timer_op /* 15 */
663 .long do_event_channel_op_compat
664 .long do_xen_version
665 .long do_console_io
666 .long do_physdev_op_compat
667 .long do_grant_table_op /* 20 */
668 .long do_vm_assist
669 .long do_update_va_mapping_otherdomain
670 .long do_iret
671 .long do_vcpu_op
672 .long do_ni_hypercall /* 25 */
673 .long do_mmuext_op
674 .long do_xsm_op
675 .long do_nmi_op
676 .long do_sched_op
677 .long do_callback_op /* 30 */
678 .long do_xenoprof_op
679 .long do_event_channel_op
680 .long do_physdev_op
681 .long do_hvm_op
682 .long do_sysctl /* 35 */
683 .long do_domctl
684 .long do_kexec_op
685 .rept NR_hypercalls-((.-hypercall_table)/4)
686 .long do_ni_hypercall
687 .endr
689 ENTRY(hypercall_args_table)
690 .byte 1 /* do_set_trap_table */ /* 0 */
691 .byte 4 /* do_mmu_update */
692 .byte 2 /* do_set_gdt */
693 .byte 2 /* do_stack_switch */
694 .byte 4 /* do_set_callbacks */
695 .byte 1 /* do_fpu_taskswitch */ /* 5 */
696 .byte 2 /* do_sched_op_compat */
697 .byte 1 /* do_platform_op */
698 .byte 2 /* do_set_debugreg */
699 .byte 1 /* do_get_debugreg */
700 .byte 4 /* do_update_descriptor */ /* 10 */
701 .byte 0 /* do_ni_hypercall */
702 .byte 2 /* do_memory_op */
703 .byte 2 /* do_multicall */
704 .byte 4 /* do_update_va_mapping */
705 .byte 2 /* do_set_timer_op */ /* 15 */
706 .byte 1 /* do_event_channel_op_compat */
707 .byte 2 /* do_xen_version */
708 .byte 3 /* do_console_io */
709 .byte 1 /* do_physdev_op_compat */
710 .byte 3 /* do_grant_table_op */ /* 20 */
711 .byte 2 /* do_vm_assist */
712 .byte 5 /* do_update_va_mapping_otherdomain */
713 .byte 0 /* do_iret */
714 .byte 3 /* do_vcpu_op */
715 .byte 0 /* do_ni_hypercall */ /* 25 */
716 .byte 4 /* do_mmuext_op */
717 .byte 1 /* do_xsm_op */
718 .byte 2 /* do_nmi_op */
719 .byte 2 /* do_sched_op */
720 .byte 2 /* do_callback_op */ /* 30 */
721 .byte 2 /* do_xenoprof_op */
722 .byte 2 /* do_event_channel_op */
723 .byte 2 /* do_physdev_op */
724 .byte 2 /* do_hvm_op */
725 .byte 1 /* do_sysctl */ /* 35 */
726 .byte 1 /* do_domctl */
727 .byte 2 /* do_kexec_op */
728 .rept NR_hypercalls-(.-hypercall_args_table)
729 .byte 0 /* do_ni_hypercall */
730 .endr