2 #include "BaseLibInternals.h"
4 ;------------------------------------------------------------------------------
6 ; Copyright (c) 2006 - 2013, Intel Corporation. All rights reserved.<BR>
7 ; This program and the accompanying materials
8 ; are licensed and made available under the terms and conditions of the BSD License
9 ; which accompanies this distribution. The full text of the license may be found at
10 ; http://opensource.org/licenses/bsd-license.php.
12 ; THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
13 ; WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
23 ;------------------------------------------------------------------------------
25 EXTERNDEF m16Start:BYTE
26 EXTERNDEF m16Size:WORD
27 EXTERNDEF mThunk16Attr:WORD
29 EXTERNDEF m16GdtrBase:WORD
30 EXTERNDEF mTransition:WORD
53 m16Size DW InternalAsmThunk16 - m16Start
54 mThunk16Attr DW _ThunkAttr - m16Start
55 m16Gdt DW _NullSeg - m16Start
56 m16GdtrBase DW _16GdtrBase - m16Start
57 mTransition DW _EntryPoint - m16Start
67 ;------------------------------------------------------------------------------
68 ; _BackFromUserCode() takes control in real mode after 'retf' has been executed
69 ; by user code. It will be shadowed to somewhere in memory below 1MB.
70 ;------------------------------------------------------------------------------
71 _BackFromUserCode PROC
73 ; The order of saved registers on the stack matches the order they appears
74 ; in IA32_REGS structure. This facilitates wrapper function to extract them
75 ; into that structure.
77 ; Some instructions for manipulation of segment registers have to be written
78 ; in opcode since 64-bit MASM prevents accesses to those registers.
86 push 0 ; reserved high order 32 bits of EFlags
87 pushf ; pushfd actually
88 cli ; disable interrupts
94 DB 66h, 0bah ; mov edx, imm32
96 test dl, THUNK_ATTRIBUTE_DISABLE_A20_MASK_INT_15
98 mov eax, 15cd2401h ; mov ax, 2401h & int 15h
99 cli ; disable interrupts
102 test dl, THUNK_ATTRIBUTE_DISABLE_A20_MASK_KBD_CTRL
106 out 92h, al ; deactivate A20M#
108 xor ax, ax ; xor eax, eax
109 mov eax, ss ; mov ax, ss
110 lea bp, [esp + sizeof (IA32_REGS)]
112 ; rsi in the following 2 instructions is indeed bp in 16-bit code
114 mov word ptr (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._ESP, bp
116 mov ebx, (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._EIP
117 shl ax, 4 ; shl eax, 4
118 add bp, ax ; add ebp, eax
121 lea ax, [eax + ebx + (@64BitCode - @Base)]
122 DB 66h, 2eh, 89h, 87h ; mov cs:[bx + (@64Eip - @Base)], eax
124 DB 66h, 0b8h ; mov eax, imm32
128 ; rdi in the instruction below is indeed bx in 16-bit code
130 DB 66h, 2eh ; 2eh is "cs:" segment override
131 lgdt fword ptr [rdi + (SavedGdt - @Base)]
137 DB 66h, 0b8h ; mov eax, imm32
140 DB 66h, 0eah ; jmp far cs:@64Bit
145 db 048h, 0bch ; mov rsp, imm64
146 SavedSp DQ ? ; restore stack
149 _BackFromUserCode ENDP
151 _EntryPoint DD _ToUserCode - m16Start
155 _16GdtrBase DQ _NullSeg
156 _16Idtr FWORD (1 SHL 10) - 1
158 ;------------------------------------------------------------------------------
159 ; _ToUserCode() takes control in real mode before passing control to user code.
160 ; It will be shadowed to somewhere in memory below 1MB.
161 ;------------------------------------------------------------------------------
163 mov ss, edx ; set new segment selectors
170 mov cr0, rax ; real mode starts at next instruction
175 mov ss, esi ; set up 16-bit stack segment
176 mov sp, bx ; set up 16-bit stack pointer
177 DB 66h ; make the following call 32-bit
178 call @Base ; push eip
180 pop bp ; ebp <- address of @Base
181 push [esp + sizeof (IA32_REGS) + 2]
182 lea eax, [rsi + (@RealMode - @Base)] ; rsi is "bp" in 16-bit code
184 retf ; execution begins at next instruction
186 DB 66h, 2eh ; CS and operand size override
187 lidt fword ptr [rsi + (_16Idtr - @Base)]
194 lea sp, [esp + 4] ; skip high order 32 bits of EFlags
195 DB 66h ; make the following retf 32-bit
196 retf ; transfer control to user code
209 DB 8fh ; 16-bit segment, 4GB limit
216 DB 8fh ; 16-bit segment, 4GB limit
223 DB 0cfh ; 16-bit segment, 4GB limit
226 GDT_SIZE = $ - _NullSeg
228 ;------------------------------------------------------------------------------
229 ; IA32_REGISTER_SET *
231 ; InternalAsmThunk16 (
232 ; IN IA32_REGISTER_SET *RegisterSet,
233 ; IN OUT VOID *Transition
235 ;------------------------------------------------------------------------------
236 InternalAsmThunk16 PROC USES rbp rbx rsi rdi
238 push rbx ; Save ds segment register on the stack
240 push rbx ; Save es segment register on the stack
242 push rbx ; Save ss segment register on the stack
247 movzx r8d, (IA32_REGS ptr [rsi])._SS
248 mov edi, (IA32_REGS ptr [rsi])._ESP
249 lea rdi, [edi - (sizeof (IA32_REGS) + 4)]
250 imul eax, r8d, 16 ; eax <- r8d(stack segment) * 16
251 mov ebx, edi ; ebx <- stack for 16-bit code
252 push sizeof (IA32_REGS) / 4
253 add edi, eax ; edi <- linear address of 16-bit stack
255 rep movsd ; copy RegSet
256 lea ecx, [rdx + (SavedCr4 - m16Start)]
257 mov eax, edx ; eax <- transition code address
259 shl eax, 12 ; segment address in high order 16 bits
260 lea ax, [rdx + (_BackFromUserCode - m16Start)] ; offset address
261 stosd ; [edi] <- return address of user code
263 sgdt fword ptr [rsp + 60h] ; save GDT stack in argument space
264 movzx r10, word ptr [rsp + 60h] ; r10 <- GDT limit
265 lea r11, [rcx + (InternalAsmThunk16 - SavedCr4) + 0xf]
266 and r11, 0xfffffff0 ; r11 <- 16-byte aligned shadowed GDT table in real mode buffer
268 mov word ptr [rcx + (SavedGdt - SavedCr4)], r10w ; save the limit of shadowed GDT table
269 mov qword ptr [rcx + (SavedGdt - SavedCr4) + 2], r11 ; save the base address of shadowed GDT table
271 mov rsi, qword ptr [rsp + 62h] ; rsi <- the original GDT base address
272 xchg rcx, r10 ; save rcx to r10 and initialize rcx to be the limit of GDT table
273 inc rcx ; rcx <- the size of memory to copy
274 xchg rdi, r11 ; save rdi to r11 and initialize rdi to the base address of shadowed GDT table
275 rep movsb ; perform memory copy to shadow GDT table
276 mov rcx, r10 ; restore the orignal rcx before memory copy
277 mov rdi, r11 ; restore the original rdi before memory copy
279 sidt fword ptr [rsp + 50h] ; save IDT stack in argument space
281 mov [rcx + (SavedCr0 - SavedCr4)], eax
282 and eax, 7ffffffeh ; clear PE, PG bits
284 mov [rcx], ebp ; save CR4 in SavedCr4
285 and ebp, NOT 30h ; clear PAE, PSE bits
286 mov esi, r8d ; esi <- 16-bit stack segment
287 DB 6ah, DATA32 ; push DATA32
288 pop rdx ; rdx <- 32-bit data segment selector
289 lgdt fword ptr [rcx + (_16Gdtr - SavedCr4)]
292 lea edx, [rdx + DATA16 - DATA32]
293 lea r8, @RetFromRealMode
296 mov [rcx + (SavedCs - SavedCr4)], r8w
297 mov [rcx + (SavedSp - SavedCr4)], rsp
298 jmp fword ptr [rcx + (_EntryPoint - SavedCr4)]
301 lgdt fword ptr [rsp + 60h] ; restore protected mode GDTR
302 lidt fword ptr [rsp + 50h] ; restore protected mode IDTR
303 lea eax, [rbp - sizeof (IA32_REGS)]
313 InternalAsmThunk16 ENDP