]> xenbits.xensource.com Git - people/pauldu/xenbus.git/log
people/pauldu/xenbus.git
7 years agoRevert "Simplify EVTCHN Unmask" master
Paul Durrant [Fri, 20 Oct 2017 15:00:11 +0000 (16:00 +0100)]
Revert "Simplify EVTCHN Unmask"

This reverts commit 3ad02ccc6c68e98ad9a83f340cd5787e45924ace.

7 years agoRemove unused static functions
Paul Durrant [Fri, 20 Oct 2017 16:16:19 +0000 (17:16 +0100)]
Remove unused static functions

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoFix EvtchnSend functions to match prototypes
Paul Durrant [Fri, 20 Oct 2017 14:56:15 +0000 (15:56 +0100)]
Fix EvtchnSend functions to match prototypes

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoVeto zero length range pop, get and put
Paul Durrant [Fri, 13 Oct 2017 15:17:32 +0000 (16:17 +0100)]
Veto zero length range pop, get and put

It clearly makes no sense to allocate a zero length range, but
both RangeSetPop() and RangeSetGet() currently allow it. RangeSetPut()
also allows such a range to be freed but trips over an assertion in
a checked build and will hopelessly confuse the code in a free build
probably leading to a subsequent crash.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoGet rid of old XenServer-ism
Paul Durrant [Tue, 22 Aug 2017 11:04:36 +0000 (12:04 +0100)]
Get rid of old XenServer-ism

Old versions of XenServer used to require that Windows tell the hypervisor
whether it was 64-bit or 32-bit so that the shared info page could be layed
out correctly.

This requirement was dropped in later versions of XenServer but some
versions had a bug where the domain wallclock time was not updated
correctly unless the old mechanism was used.

All such versions of XenServer have long been out of support and such hacks
really have no place in the Xen Project code-base anyway.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoRemove now-unused HVMOP
Paul Durrant [Tue, 22 Aug 2017 09:33:01 +0000 (10:33 +0100)]
Remove now-unused HVMOP

The previous patch removed the only call-site for HvmGetTime(). This patch
removes the function now that it is no longer used.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoWallclock Time Calculation Checks Update Versions For Consistency
Eric Mackay [Mon, 21 Aug 2017 14:58:15 +0000 (15:58 +0100)]
Wallclock Time Calculation Checks Update Versions For Consistency

Checking the shared_info update versions is necessary to get a
consistent set of values. The version is incremented once when the
update starts, and then incremented again after the update has
completed. To verify that a set of values obtained from shared_info
is consistent, the version must not only look at equality of
versions, but the version must also be even. Data can only be safely
be captured within the version check loop.

There is no need to use a hypercall to get the system time, since
this is alredy captured in the shared_info struct. A cached version
of the time since boot is stored in structures for each vcpu, but
this has to be combined with the timestamp counter and some scaling
factors to get the actual current time since boot.

Clock synchronization can also occur, and the dom0 will ensure that
the values in the shared_info and vcpu_time_info structs are kept
current to reflect this.

Signed-off-by: Eric Mackay <mackayem@amazon.com>
Don't introduce new macro for the sake of testing LSB.
Use compiler intrinsic for reading TSC.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoRevert "Make sure registry updates and deletes are flushed"
Paul Durrant [Thu, 3 Aug 2017 09:43:50 +0000 (10:43 +0100)]
Revert "Make sure registry updates and deletes are flushed"

It transpires that, on certain versions of Windows, calling ZwFlushKey()
early in boot not only fails (which is not surprising) but also logs
an error event.

This patch reverts commit 690f5474a9c6257fb15bc07b96c56cb64f193f65 to
avoid such noise in the event logs. There is clearly no option but
to trust Windows lazy flush to DTRT.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoFix ASSERTion failure
Paul Durrant [Wed, 2 Aug 2017 14:06:42 +0000 (15:06 +0100)]
Fix ASSERTion failure

Commit 6aef63e0 "Add optional log level settings" introduced an ASSERTion
failure during unload of XENBUS, because the ConsoleLogLevel field of the
driver structure was not being zeroed.

This patch fixes the problem.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoAdd optional log level settings
Owen Smith [Tue, 25 Jul 2017 09:50:36 +0000 (10:50 +0100)]
Add optional log level settings

Adds XenLogLevel and QemuLogLevel to xen.sys and ConsoleLogLevel
to xenbus.sys, which can be used to override the default log levels.
Each value is a REG_MULTI_SZ that contains an enumerated list of
log levels; TRACE, INFO, WARNING, ERROR, CRITICAL are defined.

Signed-off-by: Owen Smith <owen.smith@citrix.com>
Minor style tweaks.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoUpdate XENBUS_EVTCHN Wait method to avoid races
Paul Durrant [Fri, 26 May 2017 19:57:51 +0000 (15:57 -0400)]
Update XENBUS_EVTCHN Wait method to avoid races

Use of the XENBUS_EVTCHN method is prone to races in that a client
usually wants to check that something that should be triggered by an
event and, if it has not occurred, wait for the next event.
The problem is that the client may makes its check, the event then occurs,
and then the client waits. Thus the event is missed and the client only
wakes up when the timeout expires.

This patch changes the Wait method to take an explicit event count to wait
for, and adds a method to sample the current event count. A client can
then avoid a race as described above by sampling the event count first,
making its check and then waiting for the event count to increment by one.
If the event occurred between the check and the wait, the wait will now
return immediately.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoRemove interface versions no longer exposed through PDO revisions
Paul Durrant [Fri, 26 May 2017 19:04:10 +0000 (15:04 -0400)]
Remove interface versions no longer exposed through PDO revisions

XENBUS_EVTCHN_INTERFACE versions prior to 4 and
XENBUS_SHARED_INFO_INTERFACE version 1 are no longer available for
external query and nothing internal to the XENBUS package uses them, so
the code can be removed.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoRemove VS2012 and VS2013 build scripts
Paul Durrant [Thu, 18 May 2017 11:55:18 +0000 (12:55 +0100)]
Remove VS2012 and VS2013 build scripts

This patch removes the scripts for building under VS2013 and VS2013 and
also fixes the package destination when building using VS2015.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
7 years agoReboot request keys should be volatile
Paul Durrant [Mon, 8 May 2017 15:58:43 +0000 (16:58 +0100)]
Reboot request keys should be volatile

When a driver makes a reboot request it should use a volatile registry key.
The monitor service will explicitly remove the key prior to reboot but,
if the reboot is initiated in some other way and the key is non-volatile,
the monitor service will then needlessly prompt for a second reboot.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoUpdate the XENBUS_CONSOLE interface
Paul Durrant [Wed, 26 Apr 2017 13:25:10 +0000 (14:25 +0100)]
Update the XENBUS_CONSOLE interface

With this patch the interface has enough functionality to support my
prototype XENCONS driver.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoAdd a synthetic PDO for a new XENCONS driver
Paul Durrant [Wed, 26 Apr 2017 10:49:41 +0000 (11:49 +0100)]
Add a synthetic PDO for a new XENCONS driver

I am working on a new XENCONS driver which will surface the PV console to
user-space as a character device. It needs a node to bind to and this
patch provides one.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoMake XENBUS_CONSOLE interface available to other drivers
Paul Durrant [Wed, 26 Apr 2017 10:47:53 +0000 (11:47 +0100)]
Make XENBUS_CONSOLE interface available to other drivers

This patch adds the interface to the set of that may be queried via the
PDO.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoRemove unused data structure
Paul Durrant [Wed, 26 Apr 2017 12:18:55 +0000 (13:18 +0100)]
Remove unused data structure

XENBUS_CONSOLE_BUFFER is no longer required, so remove the struct
declaration and typedef.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoMake the XENBUS_CONSOLE Write method properly synchronous
Paul Durrant [Wed, 8 Mar 2017 13:13:18 +0000 (13:13 +0000)]
Make the XENBUS_CONSOLE Write method properly synchronous

Have the method directly write into the console ring (and potentially
block). This removes a lot of complexity from the code and makes the
method safe to be called at IRQL > DISPATCH_LEVEL.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoUpdate XENBUS_EVTCHN interface with new Send method
Paul Durrant [Wed, 8 Mar 2017 13:10:10 +0000 (13:10 +0000)]
Update XENBUS_EVTCHN interface with new Send method

The new version of the method has the same arguments and return of the
previous version but does not modify IRQL. It must therefore be called
with IRQL >= DISPATCH_LEVEL. Most callers already do this (usually
because they have a spin lock held) so the overhead of calling
KeRaiseIrql() and KeLowerIrql() can be saved. Also, it makes the method
safe to be called at > DISPATCH_LEVEL.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoSanity check number of parameters in an exception record
Paul Durrant [Wed, 1 Mar 2017 14:00:37 +0000 (14:00 +0000)]
Sanity check number of parameters in an exception record

When the BugCheck intercept dumps an exception record, make sure that
the number of parameters dumped is no more than the maximum possible
in the record.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
Reported-by: Igor Druzhinin <igor.druzhinin@citrix.com>
---
Cc: Igor Druzhinin <igor.druzhinin@citrix.com>
8 years agoAdd basic support for PV console
Paul Durrant [Thu, 2 Feb 2017 16:04:02 +0000 (16:04 +0000)]
Add basic support for PV console

Xen toolstacks have, for some time, created a PV console even for HVM
guests but, so far, Windows has had no frontend for this.

This patch adds the basic plumbing for the PV console, under a new
interface called XENBUS_CONSOLE. This interface is currently private to
XENBUS (so not accessible by child drivers) and will initially only support
writing.
The patch adds a new log disposition that will write INFO, WARNING and
ERROR level messages, so these can now be seen by attaching to the console
backend in the toolstack domain.

Future patches will add read support and a new character device to make
the console available to user-space.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoUpdate xen headers to RELEASE-4.8.0
Paul Durrant [Mon, 30 Jan 2017 11:53:39 +0000 (11:53 +0000)]
Update xen headers to RELEASE-4.8.0

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoCorrect a small DPC accounting oversight in STORE
Paul Durrant [Thu, 2 Feb 2017 10:03:10 +0000 (10:03 +0000)]
Correct a small DPC accounting oversight in STORE

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoFix memory leak in __FreePage()
Paul Durrant [Fri, 6 Jan 2017 13:48:33 +0000 (13:48 +0000)]
Fix memory leak in __FreePage()

The pool memory for the MDL also needs to be freed.

Also, generalise __AllocatePage() and __FreePage() to __AllocatePages()
and __FreePages() to allow for multi-page allocations in future.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoUpdate BUILD.md with VS2015/WDK10 information
Paul Durrant [Wed, 14 Dec 2016 16:28:47 +0000 (16:28 +0000)]
Update BUILD.md with VS2015/WDK10 information

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoFixes for VS2015/WDK10 build
Paul Durrant [Wed, 14 Dec 2016 15:36:36 +0000 (15:36 +0000)]
Fixes for VS2015/WDK10 build

The package build was not working correctly and caused the overall build
to fail.
At least part of the reason for this is that Microsoft, in their infinite
wisdom, have removed the DIFx redist from WDK10. This patch makes use of
a new environment variable 'DPINST_REDIST' to find the copy of dpinst.exe
to package such that this can be pointed at an older WDK or alternative
location where dpinst.exe can be found.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoAdd support for building under VS2015/WDK10
Paul Durrant [Fri, 9 Dec 2016 14:54:16 +0000 (14:54 +0000)]
Add support for building under VS2015/WDK10

Moving to the new toolchain also threw up a few new warnings, which this
patch either fixes or squashes. Also, SDV appears to be fragile in new
ways (and whinge about some new things) so there are fixes for that too.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoUpdate driver version from 8.2.0 to 9.0.0
Paul Durrant [Mon, 12 Dec 2016 15:16:06 +0000 (15:16 +0000)]
Update driver version from 8.2.0 to 9.0.0

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoSmall whitespace fix to last commit
Paul Durrant [Tue, 22 Nov 2016 11:12:03 +0000 (11:12 +0000)]
Small whitespace fix to last commit

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoFixed improper translation of SCHEDOP_Shutdown return code
David Buches [Tue, 22 Nov 2016 11:08:36 +0000 (11:08 +0000)]
Fixed improper translation of SCHEDOP_Shutdown return code

The documentation for the SCHEDOP_Shutdown hyper-call states that when
invoked with the SHUTDOWN_Suspend reason code, the return value indicates
that the guest domain either suspended (and resumed) in a new domain (0),
or that the operation was canceled (1).

The problem - the SchedShutdown() wrapper wasn't properly translating the
return value for SHUTDOWN_Suspend - it returned a success value for both
successful and canceled suspend operations, which resulted in suspend
callbacks erroneously being invoked for canceled operations, producing
undesirable side effects (suspend callbacks are only supposed to be
invoked when resuming on a new domain).

The code now returns an appropriate status value when SHUTDOWN_Suspend
operations are canceled.

Signed-off-by: David Buches <davebuch@amazon.com>
Slightly re-factored for cosmetic reasons.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoRevert 2a9df19f "Log module loading"
Paul Durrant [Fri, 11 Nov 2016 15:26:44 +0000 (15:26 +0000)]
Revert 2a9df19f "Log module loading"

This is a debug patch that should not have been pushed.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoMake sure we don't specify an interrupt processor group...
Paul Durrant [Fri, 11 Nov 2016 15:23:04 +0000 (15:23 +0000)]
Make sure we don't specify an interrupt processor group...

...on OS prior to Windows 7.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoLog module loading
Paul Durrant [Fri, 11 Nov 2016 14:23:12 +0000 (14:23 +0000)]
Log module loading

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoFix build warnings
Paul Durrant [Thu, 3 Nov 2016 10:30:57 +0000 (10:30 +0000)]
Fix build warnings

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoRemove S4 BUG_ONs for interface that don't depend on Xen
Paul Durrant [Wed, 2 Nov 2016 11:00:11 +0000 (11:00 +0000)]
Remove S4 BUG_ONs for interface that don't depend on Xen

Some interfaces don't depend on Xen (e.g. CACHE, RANGE_SET) and so it
is safe for them to have outstanding references across an S4 transtion
or suspend/resume (i.e. transitions which result in a new domain). Only
interfaces that actually depend on Xen (e.g. GNTTAB, EVTCHN) cannot
have outstanding reference in these cases, so limit the BUG_ONs to those.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoFix a couple of issues picked up by Windows 10 verifier
Paul Durrant [Wed, 21 Sep 2016 12:49:20 +0000 (13:49 +0100)]
Fix a couple of issues picked up by Windows 10 verifier

- It's possible for MmAllocatePagesForMdlEx() not to satisfy the
  full allocation request, but not fail. Thus AllocatePage() should
  check that the completed allocation actually matches what it
  asks for.

- RegistryCreateKey() has a memory leak.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoLog Value in UnplugSetRequest() as well as ValueName
Paul Durrant [Wed, 21 Sep 2016 12:31:46 +0000 (13:31 +0100)]
Log Value in UnplugSetRequest() as well as ValueName

A zero value is equivalent to a non-existent registry parameter so
not logging the value can sometimes be misleading.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoStep through hardware revision list in reverse order
Owen Smith [Tue, 20 Sep 2016 17:06:14 +0000 (18:06 +0100)]
Step through hardware revision list in reverse order

Windows treats the HardwareID list as a decending order of specialization
where the first entry is the most specific, and last entry is least
specific. This can lead to install issues when the newer driver has a
less-specific HardwareID, as the older ("more-specific") HardwareID is
used for the match. Reordering the HardwareID list, so that the newest
revision is first, will stop Windows selecting the wrong driver package
to install.

Signed-off-by: Owen Smith <owen.smith@citrix.com>
Re-factored slightly for code consistency.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoDon't assume a 32-page grant table
Paul Durrant [Mon, 22 Aug 2016 12:59:10 +0000 (13:59 +0100)]
Don't assume a 32-page grant table

The default grant tabled size in Xen is 32 pages, but it is tunable.
This patch allows the XENBUS_GNTTAB interface to take advantage of an
inreased grant table size.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoThe SOFTWARE registry hive is not accessible at boot time
Paul Durrant [Mon, 22 Aug 2016 07:42:41 +0000 (08:42 +0100)]
The SOFTWARE registry hive is not accessible at boot time

Hence it cannot be used for the monitor request key, otherwise XENVBD
cannot necessarily access it.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoAdd missing patch
Paul Durrant [Mon, 22 Aug 2016 07:40:58 +0000 (08:40 +0100)]
Add missing patch

I missed a 'git add' for the latest code in registry.c resulting in the
code here being slightly behind that in XENVIF and XENVBD. This patch
brings it into line.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoBring RegistryCreateKey()'s semantics in line with Win32 RegCreateKeyEx()
Paul Durrant [Fri, 19 Aug 2016 10:29:41 +0000 (11:29 +0100)]
Bring RegistryCreateKey()'s semantics in line with Win32 RegCreateKeyEx()

RegCreateKeyEx() will create intermediate keys in a path whereas
ZwCreateKey() will not. Thus, to align the semantics, this patch will
parse the path passwed to RegistryCreateKey() and create subkeys one by
one.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agomonitor: Create RequestKey in code rather then in the INF
Paul Durrant [Wed, 17 Aug 2016 11:38:37 +0000 (12:38 +0100)]
monitor: Create RequestKey in code rather then in the INF

Also do the name in the XENBUS DriverRequestReboot() function so that it
is not at the mercy of service start ordering.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agomonitor: get dialog paramaters from the registry
Paul Durrant [Fri, 12 Aug 2016 13:39:35 +0000 (14:39 +0100)]
monitor: get dialog paramaters from the registry

It is easier to localise the monitor dialog if it picks up the reboot dialog
title and message from registry parameters rather than having the hardcoded
or in a string table. This patch does this and sets default values in the
the INF file.

This patchs also adds a call to wait for driver installations to complete
before initialiating a reboot.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoRe-work monitor service registry keys
Paul Durrant [Mon, 8 Aug 2016 15:18:59 +0000 (16:18 +0100)]
Re-work monitor service registry keys

Instead of using the monitor service key directly to place reboot
requests, use a key under HKLM\SOFTWARE. This is a better place to handle
interactions between separate PV driver packages.

Also, give the monitor service a description and add a parameter to control
the reboot prompt dialog timeout.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoAdd missing comma to INF
Owen Smith [Thu, 4 Aug 2016 11:13:05 +0000 (12:13 +0100)]
Add missing comma to INF

HLK-1607 picked up the error (Code 1267, Line 96) during the
"DF - InfVerif INF Verification" test. This patch fixes that
failure.

Signed-off-by: Owen Smith <owen.smith@citrix.com>
8 years agoRe-register DbgPrint callback on resume from S4
Paul Durrant [Mon, 1 Aug 2016 14:09:51 +0000 (15:09 +0100)]
Re-register DbgPrint callback on resume from S4

Windows seems to lose knowledge of the callback when it cycles into and
out of S4 so we need to re-register.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoMake DMA interception less chatty in free builds
Paul Durrant [Fri, 29 Jul 2016 13:53:15 +0000 (14:53 +0100)]
Make DMA interception less chatty in free builds

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoXENBUS_MONITOR: don't delete the registry value until a reboot is pending
Paul Durrant [Thu, 28 Jul 2016 09:34:13 +0000 (10:34 +0100)]
XENBUS_MONITOR: don't delete the registry value until a reboot is pending

If a reboot is requested whilst there is no active session then the
monitor will not be able to prompt for reboot. We need to leave the
registry value in place until we have prompted.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoXENBUS_MONITOR refinements
Paul Durrant [Wed, 27 Jul 2016 09:53:02 +0000 (10:53 +0100)]
XENBUS_MONITOR refinements

Use a string table for the dialog message rather than coding it inline.
Also, trim the DisplayName pulled from the registry because Windows 10
seems to prefix it with useless tags.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoUse new service to request reboot rather than SetupAPI
Paul Durrant [Wed, 20 Jul 2016 15:15:40 +0000 (16:15 +0100)]
Use new service to request reboot rather than SetupAPI

This means more code can be removed from the co-installer and we get a
more meaningful message displayed to the user.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoCheck 'Reboot' value in the 'Request' key
Paul Durrant [Wed, 20 Jul 2016 13:40:23 +0000 (14:40 +0100)]
Check 'Reboot' value in the 'Request' key

If the 'Reboot' value is set with a service name then pop up a message in
the active session indicating that the specified service requires a system
reboot in order to complete installation. If the session user responds
affirmatively to the message then initiate a reboot.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoAdd code to monitor 'Request' key
Paul Durrant [Wed, 13 Jul 2016 09:41:18 +0000 (10:41 +0100)]
Add code to monitor 'Request' key

The xenbus_monitor service key has a sub-key called 'Request'. This
patch adss code to register for a notification event on the key.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoAdd a new monitor service
Paul Durrant [Fri, 8 Jul 2016 16:29:37 +0000 (17:29 +0100)]
Add a new monitor service

This patch adds the boilerplate for a service called XENBUS_MONITOR.
The service does not yet have any functionality. This will be added
by subsequent patches.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoReduce priority of suspend thread
Paul Durrant [Tue, 19 Jul 2016 13:13:51 +0000 (14:13 +0100)]
Reduce priority of suspend thread

In cycles of repeated suspend/resume attempt to make sure other threads
get to run by:

a) Dropping the priority of the suspend thread as low as possible.
b) Deliberately waiting for DPSc on other CPUs to complete before
   checking xenstore again.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoClear Unplug keys when PDO names change
Paul Durrant [Wed, 6 Jul 2016 12:58:49 +0000 (13:58 +0100)]
Clear Unplug keys when PDO names change

When upgrading XENBUS the names of PDOs may change because a new
interface version is added.
The co-installer will check for compatibility with child drivers, but
even a compatible child driver will need to re-bind if the name of the PDO
to which is binds has changed. This is a problem for boot-start drivers
because the CDDB was removed in Windows 7, which means the setupapi must
do the re-bind and that means a 0x7B BSOD will ensue if XENVBD's binding
needs to change.
To avoid this problem, if the co-installer detects that PDO names will
change, the Unplug keys are cleared causing a fall-back to emulated devices
on reboot thus allowing the setupapi to run and fix the bindings of other
PV drivers.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
8 years agoDon't free memory at HIGH IRQL
Paul Durrant [Thu, 12 May 2016 09:14:19 +0000 (10:14 +0100)]
Don't free memory at HIGH IRQL

The hash table remove function is invoked by the EVTCHN early callback on
resume from suspend. This means it is invoked at HIGH level with interrupts
disabled, which means that memory can neither be allocated nor freed. The
code, however, does indeed free a data structure and this may well lead
to memory corruption. This patch addresses the issue by deferring freeing
the memory to a subsequently scheduled DPC.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoDon't veto everything on InitSafeModeMode
Paul Durrant [Tue, 1 Mar 2016 14:04:00 +0000 (14:04 +0000)]
Don't veto everything on InitSafeModeMode

In safe mode we want to fall back to using emulated devices (which have
in-box drivers) just in case there is a problem using PV devices. However,
the current scheme of bailing very early in DriverEntry() hence not
supplying an AddDevice() entry point, hence not creating any FDOs and hence
no PDOs is problematic. This is because, when no child FDOs are created,
un-installing a child driver does not invoke the child driver co-installer
and thus cleanup, such as removing unplug registry keys, does not occur.
This then leads to a potential 0x7B BSOD on reboot if XENVBD was removed in
safe mode.

This patch gets rid of the global veto and instead simply vetoes unplug of
emulated devices. This should be sufficient for other PV drivers to
deactivate and let Windows use the emulated devices, but won't get in the
way of normal driver un-install behaviour.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAvoid evaluating assertion expressions in free builds
Paul Durrant [Fri, 22 Jan 2016 16:06:59 +0000 (16:06 +0000)]
Avoid evaluating assertion expressions in free builds

The evaluations are pointless and the warnings generated by not evaluating
can be squashed with a couple of #pragmas.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoReturn more error codes from Inflate/Deflate
Owen Smith [Tue, 15 Dec 2015 11:30:20 +0000 (11:30 +0000)]
Return more error codes from Inflate/Deflate

Signed-off-by: Owen Smith <owen.smith@citrix.com>
Cosmetic fixes.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoMove balloon failure conditions to Inflate/Deflate calls
Owen Smith [Tue, 15 Dec 2015 11:30:19 +0000 (11:30 +0000)]
Move balloon failure conditions to Inflate/Deflate calls

Signed-off-by: Owen Smith <owen.smith@citrix.com>
9 years agoBSOD if initial balloon thread has not completed within 20 minutes
Owen Smith [Tue, 15 Dec 2015 11:30:18 +0000 (11:30 +0000)]
BSOD if initial balloon thread has not completed within 20 minutes

Since there is no way of reporting balloon failures to the toolstack,
the only way of stopping a VM from attempting to balloon indefinitely
is to BSOD after a large timeout.

Signed-off-by: Owen Smith <owen.smith@citrix.com>
Largely cosmetic changes (comments and #defines).

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoIntroduce __FreePoolWithTag()
Paul Durrant [Thu, 10 Dec 2015 11:03:50 +0000 (11:03 +0000)]
Introduce __FreePoolWithTag()

Being able to interpose on memory allocation can be useful during
debugging. We already have __AllocatePoolWithTag() so this patch matches
it with __FreePoolWithTag().

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoDon't use C runtime versions of toupper() and tolower()
Paul Durrant [Thu, 10 Dec 2015 10:37:07 +0000 (10:37 +0000)]
Don't use C runtime versions of toupper() and tolower()

It seems that, despite their trivial functionality, the runtime
implementation insists on converting to Unicode! This means those functions
are actually only safe at PASSIVE_LEVEL.
This patch implements __toupper() and __tolower() as replacements with
no such hidden nastiness and modifies callers to use those.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoUse new SystemProcessorCount() function for XENBUS_EVTCHN initialization
Paul Durrant [Wed, 9 Dec 2015 14:35:42 +0000 (14:35 +0000)]
Use new SystemProcessorCount() function for XENBUS_EVTCHN initialization

Since it's necessary in a few places in the EVTCHN code to map processor
number to vcpu_id, the available processors should be limited to that for
which such a mapping exists.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoSize XENBUS_CACHE Magazine array to maximum processor count
Paul Durrant [Wed, 9 Dec 2015 14:15:35 +0000 (14:15 +0000)]
Size XENBUS_CACHE Magazine array to maximum processor count

Sizing to active processor count means that the array will be too small if
a processor is onlined after cache creation.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix assertion failure in WLK Hot Add Device Test
Paul Durrant [Wed, 9 Dec 2015 13:29:12 +0000 (13:29 +0000)]
Fix assertion failure in WLK Hot Add Device Test

SystemProcessorChangeCallback needs to whitelist another processor state
change.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoSkip interface checks on non-active FDO
Paul Durrant [Fri, 4 Dec 2015 16:01:03 +0000 (16:01 +0000)]
Skip interface checks on non-active FDO

If the non-active FDO powers down before the active one then we end up
with the BUG_ONs firing erroneously.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix snafu on setting active device when no vendor device is set
Paul Durrant [Thu, 3 Dec 2015 12:33:38 +0000 (12:33 +0000)]
Fix snafu on setting active device when no vendor device is set

If XENBUS is built with no vendor device then the check for vendor device
presences was using NULL. This patch skips the check in that case.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoVerify that all interfaces have been released when going into S4
Paul Durrant [Thu, 3 Dec 2015 12:31:57 +0000 (12:31 +0000)]
Verify that all interfaces have been released when going into S4

Because a transition into and out of S4 means a new domain is built, it's
crucial that all XENBUS interfaces are released (so that things like
event channels, grant tables and the xenstore ring get re-constructed).

This patch adds BUG_ONs to ensure this is the case.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoMake sure registry updates and deletes are flushed
Paul Durrant [Thu, 26 Nov 2015 16:17:14 +0000 (16:17 +0000)]
Make sure registry updates and deletes are flushed

In most cases it is desirable to makre sure any updates are committed to
the registry hive on storage before any further operations are performed.
This patch adds ZwFlushKey() calls to ensure that is the case.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoRemove defunct XENFILT_PVDEVICE interface
Paul Durrant [Thu, 26 Nov 2015 13:10:02 +0000 (13:10 +0000)]
Remove defunct XENFILT_PVDEVICE interface

Nothing should now need this interface so the code can be removed.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoUse the registry to check for vendor device
Paul Durrant [Thu, 26 Nov 2015 12:43:50 +0000 (12:43 +0000)]
Use the registry to check for vendor device

Using the XENFILT_PVDEVICE interface to select active device (which entails
checking for the presence of a vendor device) means that XENBUS requires a
reboot on installation before any instance can create PDOs. By using the
registry to check for vendor device presence (by looking if there is a key
under HKLM/System/CurrentControlset/Enum) there is no longer any need for
that reboot.

This patch amends the code as necessary, essentially pulling most of the
implementation of XENFILT_PVDEVICE into src/xenbus/driver.c.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix SDV build
Paul Durrant [Wed, 25 Nov 2015 13:52:55 +0000 (13:52 +0000)]
Fix SDV build

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoPublish distribution information to xenstore
Paul Durrant [Tue, 24 Nov 2015 11:52:50 +0000 (11:52 +0000)]
Publish distribution information to xenstore

My recent patch series to Xen added a documented path and format for
publishing information about PV driver distributions to xenstore.

This patch adds code to populate the documented path (should it exist)
with information about the XENBUS driver package.

Suggested-by: Owen Smith <owen.smith@citrix.com>
Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAdd STORE watchdog
Paul Durrant [Tue, 3 Nov 2015 11:48:30 +0000 (11:48 +0000)]
Add STORE watchdog

There have been occasions during testing when xenstored has apparently
missed sending notification to the frontend that data is on the ring.
This patch adds a watchdog to the code to notice when either of the rings
has stalled and try to move things along.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoDump information about viridian enlightenments
Paul Durrant [Fri, 23 Oct 2015 10:39:06 +0000 (11:39 +0100)]
Dump information about viridian enlightenments

Sometimes, for diagnosis, it's useful to have a log of what viridian
enlightenments are visiable to a VM. This patch adds new code into the
XEN system module to dump relevant information at boot time.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAdd a registry override to veto driver installations
Paul Durrant [Fri, 9 Oct 2015 16:07:48 +0000 (17:07 +0100)]
Add a registry override to veto driver installations

There are certain cases where a local installer package may wish to
prevent Windows Update installations of drivers. This can be achieved by
having the co-installer check for a registry value and fail it's pre-install
phase if the value is present.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoChange coinstaller log level to TXTLOG_WARNING
Paul Durrant [Thu, 22 Oct 2015 13:48:46 +0000 (14:48 +0100)]
Change coinstaller log level to TXTLOG_WARNING

Windows 10 does not enable logging of TXTLOG_DETAILS in setupapi.dev.log by
default, so use TXTLOG_WARNING to make sure the messages appear.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAdd missing parameterization of vendor device
Paul Durrant [Thu, 22 Oct 2015 11:24:41 +0000 (12:24 +0100)]
Add missing parameterization of vendor device

The vendor device check in XENFILT was incorrectly hard-coded to C000 rather
than the prevailing vendor device id set at build time.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoDefine a new PDO revision for updated interfaces
=Rafal Wojdyla [Fri, 11 Sep 2015 12:30:49 +0000 (14:30 +0200)]
Define a new PDO revision for updated interfaces

PDO revision 0x0800000B includes STORE interface version 2 (added
StorePermissionsSet()) and GNTTAB interface version 2 (added
GnttabMapForeignPages() and GnttabUnmapForeignPages()).

Signed-off-by: Rafal Wojdyla <omeg@invisiblethingslab.com>
Acked-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAdd support for changing key permissions to the STORE interface
Rafal Wojdyla [Fri, 11 Sep 2015 12:30:44 +0000 (14:30 +0200)]
Add support for changing key permissions to the STORE interface

STORE interface now includes a function to change key permissions. This
allows granting key access to other, non-privileged domains.

Signed-off-by: Rafal Wojdyla <omeg@invisiblethingslab.com>
Cosmetic tweaking

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAdd foreign page mapping functions to the GNTTAB interface
Rafal Wojdyla [Fri, 11 Sep 2015 12:30:25 +0000 (14:30 +0200)]
Add foreign page mapping functions to the GNTTAB interface

GNTTAB interface now includes functions to map and unmap memory pages
granted by a foreign domain. The page(s) are mapped under an address
allocated from the PCI BAR space.

Signed-off-by: Rafal Wojdyla <omeg@invisiblethingslab.com>
Some cosmetic tweaking and BUG_ON unmap failure rather than using a
dedicated bugcheck code. The Errors in grant_table.c are changed
to Warnings with expanded information on the precise map/unmap
that failed.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix list walking in hash_table.c
Paul Durrant [Thu, 10 Sep 2015 09:05:01 +0000 (10:05 +0100)]
Fix list walking in hash_table.c

Neither HashTableLookup() nor HashTableRemove() update the iterator in their
attempted list walks, leading to an endless spin. This patch changes the
while loops to for loops and fixes the problem.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
Reported-by: Rafal Wojdyla <omeg@invisiblethingslab.com>
9 years agoAdd Wait method to XENBUS_EVTCHN and use it in XENBUS_STORE
Paul Durrant [Wed, 9 Sep 2015 15:37:46 +0000 (16:37 +0100)]
Add Wait method to XENBUS_EVTCHN and use it in XENBUS_STORE

This patch adds a Wait method to the XENBUS_EVTCHN interface to allow
a subscriber to wait for an event channel to be signalled. This is useful
in XENBUS_STORE to avoid polling the ring state too often.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix hash table overflow
Paul Durrant [Wed, 9 Sep 2015 12:39:13 +0000 (13:39 +0100)]
Fix hash table overflow

There is a flaw in HashTableHash() which means that, for example, an Array
value of 0xff added to an Accumulator value of 0xff will lead to more than
4 bits of Overflow. The 5th bit is missed by the mask and is hence not
folded back into the lower order bits of the Accumulator. The upshot of the
this is an ASSERTion failure for a debug build or an array overflow in the
caller for a non-debug build.
This patch fixes this issue by increasing the overflow mask to 8 bits
instead of 4 (although 5 bit would actually be sufficient).

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
Reported-by: Rafal Wojdyla <omeg@invisiblethingslab.com>
Tested-by: Rafal Wojdyla <omeg@invisiblethingslab.com>
9 years agoParameterize vendor prefix and PCI device id
Paul Durrant [Tue, 8 Sep 2015 15:21:25 +0000 (16:21 +0100)]
Parameterize vendor prefix and PCI device id

The XenServer PV vendor prefix ('XS') and PCI device (C000) are still
hard-coded into the XENBUS package. These need to be stripped out and
replaced by values that can be customized at build time. This patch does
that.

The patch also reverts to building version.h and customizing xenbus.inf
directly in build.py.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoDon't treat a missing Driver key as a hard failure
Paul Durrant [Tue, 8 Sep 2015 13:20:19 +0000 (14:20 +0100)]
Don't treat a missing Driver key as a hard failure

When looking to see whether an incumbent child driver will patch the
PDO names created by the new version of XENBUS, ignore any cases where
we find that the Driver key referenced in the Device key is actually
missing.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoUpdate to 8.2.0
Paul Durrant [Fri, 4 Sep 2015 15:06:49 +0000 (16:06 +0100)]
Update to 8.2.0

I also removed CHANGELOG as it's pretty useless and will likely become
misleading.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoAdd Type parameter to RegistryQuerySzValue()
Paul Durrant [Fri, 7 Aug 2015 12:31:16 +0000 (13:31 +0100)]
Add Type parameter to RegistryQuerySzValue()

This allows the type of any existent UpperFilters value to be verified and
brings the registry code into line with XENVIF.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix SDV build
Paul Durrant [Thu, 6 Aug 2015 10:42:10 +0000 (11:42 +0100)]
Fix SDV build

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix potential NULL-pointer dereference...
Paul Durrant [Wed, 5 Aug 2015 11:58:45 +0000 (12:58 +0100)]
Fix potential NULL-pointer dereference...

...in parsing SystemStartOptions.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoRevert commit 632cc904 "Remove PDO set/is-missing logic from...
Paul Durrant [Wed, 5 Aug 2015 09:19:04 +0000 (10:19 +0100)]
Revert commit 632cc904 "Remove PDO set/is-missing logic from...

... XENFILT" and re-work PnP code again.

In WHQL testing I suspect the removal and re-creation of filter objects
when IRP_MN_REMOVE_DEVICE is processed in the case that underlying PDO is
not actually going away may cause problems.

By reverting 632cc904 this bouncing is prevented but the code needs more
work to fix the hanging object references from filtDO to PDO that were the
motivation for 632cc904 in the first place.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoRegistry string value types cannot be inferred
Paul Durrant [Wed, 5 Aug 2015 07:56:56 +0000 (08:56 +0100)]
Registry string value types cannot be inferred

For instance, the UpperFilters key needs to be a REG_MULTI_SZ
even if it contains only one string. Thus the type needs to be
passed explicitly to RegistryUpdateSzValue.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoFix incorrect registry key setting
Paul Durrant [Wed, 5 Aug 2015 07:56:23 +0000 (08:56 +0100)]
Fix incorrect registry key setting

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoLog when filters are actually installed or removed
Paul Durrant [Mon, 3 Aug 2015 15:19:07 +0000 (16:19 +0100)]
Log when filters are actually installed or removed

...rather then merely when the functions are called.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoUpdate docs and set version to 8.1.0
Paul Durrant [Fri, 24 Jul 2015 11:50:04 +0000 (12:50 +0100)]
Update docs and set version to 8.1.0

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoOnly the active device should unplug emulated devices
Paul Durrant [Thu, 23 Jul 2015 15:38:37 +0000 (16:38 +0100)]
Only the active device should unplug emulated devices

...and populate the hypercall table.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>
9 years agoMake sure XENFILT PDOs get moved from Present to Enumerated
Paul Durrant [Thu, 23 Jul 2015 14:10:13 +0000 (15:10 +0100)]
Make sure XENFILT PDOs get moved from Present to Enumerated

The code to adjust the state was mistakenly removed in a previous patch.

Signed-off-by: Paul Durrant <paul.durrant@citrix.com>