2 #include "BaseLibInternals.h"
4 ;------------------------------------------------------------------------------
6 ; Copyright (c) 2006 - 2008, Intel Corporation
7 ; All rights reserved. This program and the accompanying materials
8 ; are licensed and made available under the terms and conditions of the BSD License
9 ; which accompanies this distribution. The full text of the license may be found at
10 ; http://opensource.org/licenses/bsd-license.php
12 ; THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
13 ; WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
23 ;------------------------------------------------------------------------------
25 EXTERNDEF m16Start:BYTE
26 EXTERNDEF m16Size:WORD
27 EXTERNDEF mThunk16Attr:WORD
29 EXTERNDEF m16GdtrBase:WORD
30 EXTERNDEF mTransition:WORD
53 m16Size DW InternalAsmThunk16 - m16Start
54 mThunk16Attr DW _ThunkAttr - m16Start
55 m16Gdt DW _NullSeg - m16Start
56 m16GdtrBase DW _16GdtrBase - m16Start
57 mTransition DW _EntryPoint - m16Start
67 ;------------------------------------------------------------------------------
68 ; _BackFromUserCode() takes control in real mode after 'retf' has been executed
69 ; by user code. It will be shadowed to somewhere in memory below 1MB.
70 ;------------------------------------------------------------------------------
71 _BackFromUserCode PROC
73 ; The order of saved registers on the stack matches the order they appears
74 ; in IA32_REGS structure. This facilitates wrapper function to extract them
75 ; into that structure.
77 ; Some instructions for manipulation of segment registers have to be written
78 ; in opcode since 64-bit MASM prevents accesses to those registers.
86 push 0 ; reserved high order 32 bits of EFlags
87 pushf ; pushfd actually
88 cli ; disable interrupts
94 DB 66h, 0bah ; mov edx, imm32
96 test dl, THUNK_ATTRIBUTE_DISABLE_A20_MASK_INT_15
98 mov eax, 15cd2401h ; mov ax, 2401h & int 15h
99 cli ; disable interrupts
102 test dl, THUNK_ATTRIBUTE_DISABLE_A20_MASK_KBD_CTRL
106 out 92h, al ; deactivate A20M#
109 lea bp, [esp + sizeof (IA32_REGS)]
111 ; rsi in the following 2 instructions is indeed bp in 16-bit code
113 mov word ptr (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._ESP, bp
115 mov ebx, (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._EIP
116 shl ax, 4 ; shl eax, 4
117 add bp, ax ; add ebp, eax
120 lea ax, [eax + ebx + (@64BitCode - @Base)]
121 DB 66h, 2eh, 89h, 87h ; mov cs:[bx + (@64Eip - @Base)], eax
123 DB 66h, 0b8h ; mov eax, imm32
127 ; rdi in the instruction below is indeed bx in 16-bit code
129 DB 66h, 2eh ; 2eh is "cs:" segment override
130 lgdt fword ptr [rdi + (SavedGdt - @Base)]
136 DB 66h, 0b8h ; mov eax, imm32
139 DB 66h, 0eah ; jmp far cs:@64Bit
144 db 067h, 0bch ; mov esp, imm32
145 SavedSp DD ? ; restore stack
148 _BackFromUserCode ENDP
150 _EntryPoint DD _ToUserCode - m16Start
154 _16GdtrBase DQ _NullSeg
155 _16Idtr FWORD (1 SHL 10) - 1
157 ;------------------------------------------------------------------------------
158 ; _ToUserCode() takes control in real mode before passing control to user code.
159 ; It will be shadowed to somewhere in memory below 1MB.
160 ;------------------------------------------------------------------------------
162 mov ss, edx ; set new segment selectors
169 mov cr0, rax ; real mode starts at next instruction
174 mov ss, esi ; set up 16-bit stack segment
175 mov sp, bx ; set up 16-bit stack pointer
176 DB 66h ; make the following call 32-bit
177 call @Base ; push eip
179 pop bp ; ebp <- address of @Base
180 push [esp + sizeof (IA32_REGS) + 2]
181 lea eax, [rsi + (@RealMode - @Base)] ; rsi is "bp" in 16-bit code
183 retf ; execution begins at next instruction
185 DB 66h, 2eh ; CS and operand size override
186 lidt fword ptr [rsi + (_16Idtr - @Base)]
193 lea sp, [esp + 4] ; skip high order 32 bits of EFlags
194 DB 66h ; make the following retf 32-bit
195 retf ; transfer control to user code
208 DB 8fh ; 16-bit segment, 4GB limit
215 DB 8fh ; 16-bit segment, 4GB limit
222 DB 0cfh ; 16-bit segment, 4GB limit
225 GDT_SIZE = $ - _NullSeg
227 ;------------------------------------------------------------------------------
228 ; IA32_REGISTER_SET *
230 ; InternalAsmThunk16 (
231 ; IN IA32_REGISTER_SET *RegisterSet,
232 ; IN OUT VOID *Transition
234 ;------------------------------------------------------------------------------
235 InternalAsmThunk16 PROC USES rbp rbx rsi rdi
237 push rbx ; Save ds segment register on the stack
239 push rbx ; Save es segment register on the stack
241 push rbx ; Save ss segment register on the stack
246 movzx r8d, (IA32_REGS ptr [rsi])._SS
247 mov edi, (IA32_REGS ptr [rsi])._ESP
248 lea rdi, [edi - (sizeof (IA32_REGS) + 4)]
249 imul eax, r8d, 16 ; eax <- r8d(stack segment) * 16
250 mov ebx, edi ; ebx <- stack for 16-bit code
251 push sizeof (IA32_REGS) / 4
252 add edi, eax ; edi <- linear address of 16-bit stack
254 rep movsd ; copy RegSet
255 lea ecx, [rdx + (SavedCr4 - m16Start)]
256 mov eax, edx ; eax <- transition code address
258 shl eax, 12 ; segment address in high order 16 bits
259 lea ax, [rdx + (_BackFromUserCode - m16Start)] ; offset address
260 stosd ; [edi] <- return address of user code
262 sgdt fword ptr [rsp + 60h] ; save GDT stack in argument space
263 movzx r10, word ptr [rsp + 60h] ; r10 <- GDT limit
264 lea r11, [rcx + (InternalAsmThunk16 - SavedCr4) + 0xf]
265 and r11, 0xfffffff0 ; r11 <- 16-byte aligned shadowed GDT table in real mode buffer
267 mov word ptr [rcx + (SavedGdt - SavedCr4)], r10w ; save the limit of shadowed GDT table
268 mov qword ptr [rcx + (SavedGdt - SavedCr4) + 2], r11 ; save the base address of shadowed GDT table
270 mov rsi, qword ptr [rsp + 62h] ; rsi <- the original GDT base address
271 xchg rcx, r10 ; save rcx to r10 and initialize rcx to be the limit of GDT table
272 inc rcx ; rcx <- the size of memory to copy
273 xchg rdi, r11 ; save rdi to r11 and initialize rdi to the base address of shadowed GDT table
274 rep movsb ; perform memory copy to shadow GDT table
275 mov rcx, r10 ; restore the orignal rcx before memory copy
276 mov rdi, r11 ; restore the original rdi before memory copy
278 sidt fword ptr [rsp + 50h] ; save IDT stack in argument space
280 mov [rcx + (SavedCr0 - SavedCr4)], eax
281 and eax, 7ffffffeh ; clear PE, PG bits
283 mov [rcx], ebp ; save CR4 in SavedCr4
284 and ebp, 300h ; clear all but PCE and OSFXSR bits
285 mov esi, r8d ; esi <- 16-bit stack segment
286 DB 6ah, DATA32 ; push DATA32
287 pop rdx ; rdx <- 32-bit data segment selector
288 lgdt fword ptr [rcx + (_16Gdtr - SavedCr4)]
291 lea edx, [rdx + DATA16 - DATA32]
292 lea r8, @RetFromRealMode
295 mov [rcx + (SavedCs - SavedCr4)], r8w
296 mov [rcx + (SavedSp - SavedCr4)], esp
297 jmp fword ptr [rcx + (_EntryPoint - SavedCr4)]
300 lgdt fword ptr [rsp + 60h] ; restore protected mode GDTR
301 lidt fword ptr [rsp + 50h] ; restore protected mode IDTR
302 lea eax, [rbp - sizeof (IA32_REGS)]
312 InternalAsmThunk16 ENDP