Palacios Public Git Repository

To checkout Palacios execute

  git clone http://v3vee.org/palacios/palacios.web/palacios.git
This will give you the master branch. You probably want the devel branch or one of the release branches. To switch to the devel branch, simply execute
  cd palacios
  git checkout --track -b devel origin/devel
The other branches are similar.


Disallow startup with shadow paging + memory region outside 4GB boundary
[palacios.git] / palacios / src / palacios / vmx_ctrl_regs.c
index d83d51f..2b0bfb5 100644 (file)
@@ -100,6 +100,28 @@ int v3_vmx_handle_cr4_access(struct guest_info * info, struct vmx_exit_cr_qual *
     return -1;
 }
 
+int v3_vmx_handle_cr8_access(struct guest_info * info, struct vmx_exit_cr_qual * cr_qual) {
+    if (cr_qual->access_type < 2) {
+
+       if (cr_qual->access_type == 0) {
+           if (v3_handle_cr8_write(info) != 0) {
+               PrintError("Could not handle CR8 write\n");
+               return -1;
+           }
+       } else {
+           if (v3_handle_cr8_read(info) != 0) {
+               PrintError("Could not handle CR8 read\n");
+               return -1;
+           }
+       }
+       
+       return 0;
+    }
+    
+    PrintError("Invalid CR8 Access type?? (type=%d)\n", cr_qual->access_type);
+    return -1;
+}
+
 static int handle_mov_to_cr3(struct guest_info * info, v3_reg_t * cr3_reg) {
 
     if (info->shdw_pg_mode == SHADOW_PAGING) {
@@ -166,13 +188,14 @@ static int handle_mov_to_cr0(struct guest_info * info, v3_reg_t * new_cr0, struc
     struct cr0_32 * new_shdw_cr0 = (struct cr0_32 *)new_cr0;
     struct vmx_data * vmx_info = (struct vmx_data *)info->vmm_data;
     uint_t paging_transition = 0;
+    extern v3_cpu_arch_t v3_mach_type;
+
 
-    /*
-      PrintDebug("Old shadow CR0: 0x%x, New shadow CR0: 0x%x\n",
-      (uint32_t)info->shdw_pg_state.guest_cr0, (uint32_t)*new_cr0);
-    */
+    PrintDebug("Mov to CR0\n");
+    PrintDebug("Old shadow CR0: 0x%x, New shadow CR0: 0x%x\n",
+              (uint32_t)info->shdw_pg_state.guest_cr0, (uint32_t)*new_cr0);
 
-    if (new_shdw_cr0->pe != shdw_cr0->pe) {
+    if ((new_shdw_cr0->pe != shdw_cr0->pe) && (vmx_info->assist_state != VMXASSIST_DISABLED)) {
        /*
          PrintDebug("Guest CR0: 0x%x\n", *(uint32_t *)guest_cr0);
          PrintDebug("Old shadow CR0: 0x%x\n", *(uint32_t *)shdw_cr0);
@@ -184,7 +207,7 @@ static int handle_mov_to_cr0(struct guest_info * info, v3_reg_t * new_cr0, struc
             return -1;
         }
        
-        if (vmx_info->assist_state == VMXASSIST_ENABLED) {
+        if (vmx_info->assist_state == VMXASSIST_ON) {
             PrintDebug("Loading VMXASSIST at RIP: %p\n", (void *)(addr_t)info->rip);
         } else {
             PrintDebug("Leaving VMXASSIST and entering protected mode at RIP: %p\n",
@@ -202,34 +225,58 @@ static int handle_mov_to_cr0(struct guest_info * info, v3_reg_t * new_cr0, struc
        if (new_shdw_cr0->pg != shdw_cr0->pg) {
            paging_transition = 1;
        }
-       
-       // The shadow always reflects the new value
-       *shdw_cr0 = *new_shdw_cr0;
-       
-       // We don't care about most of the flags, so lets go for it 
-       // and set them to the guest values
-       *guest_cr0 = *shdw_cr0;
+
        
        // Except PG, PE, and NE, which are always set
-       guest_cr0->pe = 1;
-       guest_cr0->pg = 1;
+       if ((info->shdw_pg_mode == SHADOW_PAGING) ||  
+           (v3_mach_type != V3_VMX_EPT_UG_CPU)) {
+           
+           // The shadow always reflects the new value
+           *shdw_cr0 = *new_shdw_cr0;
+           
+
+           // We don't care about most of the flags, so lets go for it 
+           // and set them to the guest values
+           *guest_cr0 = *shdw_cr0;
+       
+           guest_cr0->pe = 1;
+           guest_cr0->pg = 1;
+       } else {
+           // Unrestricted guest 
+           //    *(uint32_t *)shdw_cr0 = (0x00000020 & *(uint32_t *)new_shdw_cr0);
+
+           *guest_cr0 = *new_shdw_cr0;
+       }
+
        guest_cr0->ne = 1;
+       guest_cr0->et = 1;
+
        
-       if ((paging_transition)) {
+       if (paging_transition) {
            // Paging transition
            
            if (v3_get_vm_mem_mode(info) == VIRTUAL_MEM) {
                struct efer_64 * vm_efer = (struct efer_64 *)&(info->shdw_pg_state.guest_efer);
                struct efer_64 * hw_efer = (struct efer_64 *)&(info->ctrl_regs.efer);
                
-               if (vm_efer->lme) {
-                   //     PrintDebug("Enabling long mode\n");
-                   
-                   hw_efer->lma = 1;
-                   hw_efer->lme = 1;
-                   
-                   vmx_info->entry_ctrls.guest_ia32e = 1;
-               }
+               if (vmx_info->assist_state != VMXASSIST_DISABLED) {
+                   if (vm_efer->lme) {
+                       PrintDebug("Enabling long mode\n");
+                       
+                       hw_efer->lma = 1;
+                       hw_efer->lme = 1;
+                       
+                       vmx_info->entry_ctrls.guest_ia32e = 1;
+                   }
+               } else {
+                   if (hw_efer->lme) {
+                       PrintDebug("Enabling long mode\n");
+                       
+                       hw_efer->lma = 1;
+                       
+                       vmx_info->entry_ctrls.guest_ia32e = 1;
+                   }
+               }
                
                //            PrintDebug("Activating Shadow Page tables\n");