1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
|
// Copyright 2018 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// +build amd64
package ring0
import (
"gvisor.dev/gvisor/pkg/sentry/arch"
)
// This is an assembly function.
//
// The sysenter function is invoked in two situations:
//
// (1) The guest kernel has executed a system call.
// (2) The guest application has executed a system call.
//
// The interrupt flag is examined to determine whether the system call was
// executed from kernel mode or not and the appropriate stub is called.
func sysenter()
// swapgs swaps the current GS value.
//
// This must be called prior to sysret/iret.
func swapgs()
// jumpToKernel jumps to the kernel version of the current RIP.
func jumpToKernel()
// sysret returns to userspace from a system call.
//
// The return code is the vector that interrupted execution.
//
// See stubs.go for a note regarding the frame size of this function.
func sysret(cpu *CPU, regs *arch.Registers, userCR3 uintptr) Vector
// "iret is the cadillac of CPL switching."
//
// -- Neel Natu
//
// iret is nearly identical to sysret, except an iret is used to fully restore
// all user state. This must be called in cases where all registers need to be
// restored.
func iret(cpu *CPU, regs *arch.Registers, userCR3 uintptr) Vector
// exception is the generic exception entry.
//
// This is called by the individual stub definitions.
func exception()
// resume is a stub that restores the CPU kernel registers.
//
// This is used when processing kernel exceptions and syscalls.
func resume()
// Start is the CPU entrypoint.
//
// The following start conditions must be satisfied:
//
// * AX should contain the CPU pointer.
// * c.GDT() should be loaded as the GDT.
// * c.IDT() should be loaded as the IDT.
// * c.CR0() should be the current CR0 value.
// * c.CR3() should be set to the kernel PageTables.
// * c.CR4() should be the current CR4 value.
// * c.EFER() should be the current EFER value.
//
// The CPU state will be set to c.Registers().
func Start()
// Exception stubs.
func divideByZero()
func debug()
func nmi()
func breakpoint()
func overflow()
func boundRangeExceeded()
func invalidOpcode()
func deviceNotAvailable()
func doubleFault()
func coprocessorSegmentOverrun()
func invalidTSS()
func segmentNotPresent()
func stackSegmentFault()
func generalProtectionFault()
func pageFault()
func x87FloatingPointException()
func alignmentCheck()
func machineCheck()
func simdFloatingPointException()
func virtualizationException()
func securityException()
func syscallInt80()
// Exception handler index.
var handlers = map[Vector]func(){
DivideByZero: divideByZero,
Debug: debug,
NMI: nmi,
Breakpoint: breakpoint,
Overflow: overflow,
BoundRangeExceeded: boundRangeExceeded,
InvalidOpcode: invalidOpcode,
DeviceNotAvailable: deviceNotAvailable,
DoubleFault: doubleFault,
CoprocessorSegmentOverrun: coprocessorSegmentOverrun,
InvalidTSS: invalidTSS,
SegmentNotPresent: segmentNotPresent,
StackSegmentFault: stackSegmentFault,
GeneralProtectionFault: generalProtectionFault,
PageFault: pageFault,
X87FloatingPointException: x87FloatingPointException,
AlignmentCheck: alignmentCheck,
MachineCheck: machineCheck,
SIMDFloatingPointException: simdFloatingPointException,
VirtualizationException: virtualizationException,
SecurityException: securityException,
SyscallInt80: syscallInt80,
}
|