SHDW_REGION_WRITE_HOOK, // This region is mapped as read-only (page faults on write)
SHDW_REGION_FULL_HOOK, // This region is mapped as not present (always generate page faults)
SHDW_REGION_ALLOCATED, // Region is a section of host memory
+ SHDW_REGION_BASE,
} v3_shdw_region_type_t;
#define V3_MEM_CORE_ANY ((uint16_t)-1)
+
+typedef struct {
+ union {
+ uint16_t value;
+ struct {
+ uint8_t read : 1;
+ uint8_t write : 1;
+ uint8_t exec : 1;
+ uint8_t hook : 1;
+ uint8_t base : 1;
+ uint8_t alloced : 1;
+ } __attribute__((packed));
+ } __attribute__((packed));
+} __attribute__((packed)) v3_mem_flags_t;
+
+
+
struct v3_shadow_region {
addr_t guest_start;
addr_t guest_end;
v3_shdw_region_type_t host_type;
-
+ v3_mem_flags_t flags;
+
addr_t host_addr; // This either points to a host address mapping
// Called when data is read from a memory page
struct v3_shadow_region * v3_get_shadow_region(struct v3_vm_info * vm, uint16_t core_id, addr_t guest_addr);
-addr_t v3_get_shadow_addr(struct v3_shadow_region * reg, uint16_t core_id, addr_t guest_addr);
-
-
-
-void v3_print_mem_map(struct v3_vm_info * vm);
+addr_t v3_get_shadow_addr(struct v3_shadow_region * reg, uint16_t core_id, addr_t guest_addr);
-const uchar_t * v3_shdw_region_type_to_str(v3_shdw_region_type_t type);
+void v3_print_mem_map(struct v3_vm_info * vm);
-int handle_special_page_fault(struct guest_info * info, addr_t fault_addr, addr_t gp_addr, pf_error_t access_info);
+int v3_handle_mem_hook(struct guest_info * info, addr_t guest_va, addr_t guest_pa,
+ struct v3_shadow_region * reg, pf_error_t access_info);
-int v3_handle_mem_wr_hook(struct guest_info * info, addr_t guest_va, addr_t guest_pa,
- struct v3_shadow_region * reg, pf_error_t access_info);
-int v3_handle_mem_full_hook(struct guest_info * info, addr_t guest_va, addr_t guest_pa,
- struct v3_shadow_region * reg, pf_error_t access_info);
#endif // ! __V3VEE__
} else {
// Page fault handled by hook functions
- if (v3_handle_mem_full_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
guest_pte->dirty = 1;
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
//
} else {
- if (v3_handle_mem_full_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
} else {
// Page fault handled by hook functions
- if (v3_handle_mem_full_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
guest_pte->dirty = 1;
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
//
} else {
- if (v3_handle_mem_full_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
} else {
// Page fault handled by hook functions
- if (v3_handle_mem_full_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
guest_pte->dirty = 1;
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
//
} else {
- if (v3_handle_mem_full_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
} else {
// Page fault handled by hook functions
- if (v3_handle_mem_full_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
guest_pte->dirty = 1;
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
//
} else {
- if (v3_handle_mem_full_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
if (shdw_reg->host_type == SHDW_REGION_WRITE_HOOK) {
- if (v3_handle_mem_wr_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
+ if (v3_handle_mem_hook(info, fault_addr, guest_fault_pa, shdw_reg, error_code) == -1) {
PrintError("Special Page Fault handler returned error for address: %p\n", (void *)fault_addr);
return -1;
}
return -1;
}
- if (shdw_reg->host_type == SHDW_REGION_FULL_HOOK) {
- PrintError("In GPA->HPA: Could not find address in shadow map (addr=%p) (reg_type=%s)\n",
- (void *)guest_pa, v3_shdw_region_type_to_str(shdw_reg->host_type));
+ if (shdw_reg->flags.alloced == 0) {
+ PrintError("In GPA->HPA: Tried to translate physical address of non allocated page (addr=%p)\n",
+ (void *)guest_pa);
return -1;
}
pte[pte_index].page_base_addr = PAGE_BASE_ADDR(host_addr);
} else if (region->host_type == SHDW_REGION_FULL_HOOK) {
// trap all accesses
- return v3_handle_mem_full_hook(info, fault_addr, fault_addr, region, error_code);
+ return v3_handle_mem_hook(info, fault_addr, fault_addr, region, error_code);
} else {
PrintError("Unknown Region Type...\n");
return -1;
if ( (region->host_type == SHDW_REGION_WRITE_HOOK) &&
(error_code.write == 1) ) {
PrintDebug("Triggering Direct paging Write hook\n");
- return v3_handle_mem_wr_hook(info, fault_addr, fault_addr, region, error_code);
+ return v3_handle_mem_hook(info, fault_addr, fault_addr, region, error_code);
}
} else if (region->host_type == SHDW_REGION_FULL_HOOK) {
// trap all accesses
- return v3_handle_mem_full_hook(info, fault_addr, fault_addr, region, error_code);
+ return v3_handle_mem_hook(info, fault_addr, fault_addr, region, error_code);
} else {
PrintError("Unknown Region Type...\n");
if ( (region->host_type == SHDW_REGION_WRITE_HOOK) &&
(error_code.write == 1) ) {
- return v3_handle_mem_wr_hook(info, fault_addr, fault_addr, region, error_code);
+ return v3_handle_mem_hook(info, fault_addr, fault_addr, region, error_code);
}
return 0;
} else if (region->host_type == SHDW_REGION_FULL_HOOK) {
// trap all accesses
- return v3_handle_mem_full_hook(info, fault_addr, fault_addr, region, error_code);
+ return v3_handle_mem_hook(info, fault_addr, fault_addr, region, error_code);
} else {
PrintError("Unknown Region Type...\n");
if ( (region->host_type == SHDW_REGION_WRITE_HOOK) &&
(error_code.write == 1) ) {
- return v3_handle_mem_wr_hook(info, fault_addr, fault_addr, region, error_code);
+ return v3_handle_mem_hook(info, fault_addr, fault_addr, region, error_code);
}
return 0;
struct v3_mem_map * map = &(vm->mem_map);
addr_t mem_pages = vm->mem_size >> 12;
+ memset(&(map->base_region), 0, sizeof(struct v3_shadow_region));
+
map->shdw_regions.rb_node = NULL;
map->base_region.host_type = SHDW_REGION_ALLOCATED;
map->base_region.host_addr = (addr_t)V3_AllocPages(mem_pages);
+ map->base_region.flags.read = 1;
+ map->base_region.flags.write = 1;
+ map->base_region.flags.exec = 1;
+ map->base_region.flags.base = 1;
+ map->base_region.flags.alloced = 1;
if ((void *)map->base_region.host_addr == NULL) {
PrintError("Could not allocate Guest memory\n");
addr_t host_addr)
{
struct v3_shadow_region * entry = (struct v3_shadow_region *)V3_Malloc(sizeof(struct v3_shadow_region));
+ memset(entry, 0, sizeof(struct v3_shadow_region));
entry->guest_start = guest_addr_start;
entry->guest_end = guest_addr_end;
entry->priv_data = NULL;
entry->core_id = core_id;
+ entry->flags.read = 1;
+ entry->flags.write = 1;
+ entry->flags.exec = 1;
+ entry->flags.alloced = 1;
+
if (insert_shadow_region(vm, entry)) {
V3_Free(entry);
return -1;
void * priv_data) {
struct v3_shadow_region * entry = (struct v3_shadow_region *)V3_Malloc(sizeof(struct v3_shadow_region));
-
+ memset(entry, 0, sizeof(struct v3_shadow_region));
entry->guest_start = guest_addr_start;
entry->guest_end = guest_addr_end;
entry->priv_data = priv_data;
entry->core_id = core_id;
+ entry->flags.hook = 1;
+ entry->flags.read = 1;
+ entry->flags.exec = 1;
+ entry->flags.alloced = 1;
+
+
if (insert_shadow_region(vm, entry)) {
V3_Free(entry);
return -1;
void * priv_data) {
struct v3_shadow_region * entry = (struct v3_shadow_region *)V3_Malloc(sizeof(struct v3_shadow_region));
+ memset(entry, 0, sizeof(struct v3_shadow_region));
entry->guest_start = guest_addr_start;
entry->guest_end = guest_addr_end;
entry->priv_data = priv_data;
entry->core_id = core_id;
+ entry->flags.hook = 1;
+
if (insert_shadow_region(vm, entry)) {
V3_Free(entry);
return -1;
int v3_unhook_mem(struct v3_vm_info * vm, uint16_t core_id, addr_t guest_addr_start) {
struct v3_shadow_region * reg = v3_get_shadow_region(vm, core_id, guest_addr_start);
- if ((reg->host_type != SHDW_REGION_FULL_HOOK) ||
- (reg->host_type != SHDW_REGION_WRITE_HOOK)) {
+ if (!reg->flags.hook) {
PrintError("Trying to unhook a non hooked memory region (addr=%p)\n", (void *)guest_addr_start);
return -1;
}
-int handle_special_page_fault(struct guest_info * info,
- addr_t fault_gva, addr_t fault_gpa, pf_error_t access_info)
-{
- struct v3_shadow_region * reg = v3_get_shadow_region(info->vm_info, info->cpu_id, fault_gpa);
- PrintDebug("Handling Special Page Fault\n");
- switch (reg->host_type) {
- case SHDW_REGION_WRITE_HOOK:
- return v3_handle_mem_wr_hook(info, fault_gva, fault_gpa, reg, access_info);
- case SHDW_REGION_FULL_HOOK:
- return v3_handle_mem_full_hook(info, fault_gva, fault_gpa, reg, access_info);
- default:
- return -1;
- }
+int v3_handle_mem_hook(struct guest_info * info, addr_t guest_va, addr_t guest_pa,
+ struct v3_shadow_region * reg, pf_error_t access_info) {
- return 0;
-
-}
-
-int v3_handle_mem_wr_hook(struct guest_info * info, addr_t guest_va, addr_t guest_pa,
- struct v3_shadow_region * reg, pf_error_t access_info) {
+ addr_t op_addr = 0;
- addr_t dst_addr = (addr_t)V3_VAddr((void *)v3_get_shadow_addr(reg, info->cpu_id, guest_pa));
-
- if (v3_emulate_write_op(info, guest_va, guest_pa, dst_addr,
- reg->write_hook, reg->priv_data) == -1) {
- PrintError("Write hook emulation failed\n");
- return -1;
+ if (reg->flags.alloced == 0) {
+ op_addr = get_hook_hva(info);
+ } else {
+ op_addr = (addr_t)V3_VAddr((void *)v3_get_shadow_addr(reg, info->cpu_id, guest_pa));
}
- return 0;
-}
-
-int v3_handle_mem_full_hook(struct guest_info * info, addr_t guest_va, addr_t guest_pa,
- struct v3_shadow_region * reg, pf_error_t access_info) {
-
- addr_t op_addr = get_hook_hva(info);
+
+ if (access_info.write == 1) {
+ // Write Operation
- if (access_info.write == 1) {
if (v3_emulate_write_op(info, guest_va, guest_pa, op_addr,
reg->write_hook, reg->priv_data) == -1) {
PrintError("Write Full Hook emulation failed\n");
return -1;
}
} else {
+ // Read Operation
+
+ if (reg->flags.read == 1) {
+ PrintError("Tried to emulate read for a guest Readable page\n");
+ return -1;
+ }
+
if (v3_emulate_read_op(info, guest_va, guest_pa, op_addr,
reg->read_hook, reg->write_hook,
reg->priv_data) == -1) {
PrintError("Read Full Hook emulation failed\n");
return -1;
}
+
}
+
return 0;
}
+
struct v3_shadow_region * v3_get_shadow_region(struct v3_vm_info * vm, uint16_t core_id, addr_t guest_addr) {
struct rb_node * n = vm->mem_map.shdw_regions.rb_node;
struct v3_shadow_region * reg = NULL;
}
+
+
void v3_delete_shadow_region(struct v3_vm_info * vm, struct v3_shadow_region * reg) {
int i = 0;
addr_t v3_get_shadow_addr(struct v3_shadow_region * reg, uint16_t core_id, addr_t guest_addr) {
- if ( (reg) &&
- (reg->host_type != SHDW_REGION_FULL_HOOK)) {
+ if (reg && (reg->flags.alloced == 1)) {
return (guest_addr - reg->guest_start) + reg->host_addr;
} else {
// PrintError("MEM Region Invalid\n");
(void *)(reg->guest_end - 1),
(void *)(reg->host_addr));
- V3_Print("\t(%s) (WriteHook = 0x%p) (ReadHook = 0x%p)\n",
- v3_shdw_region_type_to_str(reg->host_type),
+ V3_Print("\t(flags=%x) (WriteHook = 0x%p) (ReadHook = 0x%p)\n",
+ reg->flags.value,
(void *)(reg->write_hook),
(void *)(reg->read_hook));
} while ((node = v3_rb_next(node)));
}
-
-static const uchar_t SHDW_REGION_WRITE_HOOK_STR[] = "SHDW_REGION_WRITE_HOOK";
-static const uchar_t SHDW_REGION_FULL_HOOK_STR[] = "SHDW_REGION_FULL_HOOK";
-static const uchar_t SHDW_REGION_ALLOCATED_STR[] = "SHDW_REGION_ALLOCATED";
-
-const uchar_t * v3_shdw_region_type_to_str(v3_shdw_region_type_t type) {
- switch (type) {
- case SHDW_REGION_WRITE_HOOK:
- return SHDW_REGION_WRITE_HOOK_STR;
- case SHDW_REGION_FULL_HOOK:
- return SHDW_REGION_FULL_HOOK_STR;
- case SHDW_REGION_ALLOCATED:
- return SHDW_REGION_ALLOCATED_STR;
- default:
- return (uchar_t *)"SHDW_REGION_INVALID";
- }
-}
-