]>
git.proxmox.com Git - mirror_qemu.git/blob - tests/qtest/fdc-test.c
4 * Copyright (c) 2012 Kevin Wolf <kwolf@redhat.com>
6 * Permission is hereby granted, free of charge, to any person obtaining a copy
7 * of this software and associated documentation files (the "Software"), to deal
8 * in the Software without restriction, including without limitation the rights
9 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10 * copies of the Software, and to permit persons to whom the Software is
11 * furnished to do so, subject to the following conditions:
13 * The above copyright notice and this permission notice shall be included in
14 * all copies or substantial portions of the Software.
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
25 #include "qemu/osdep.h"
28 #include "libqtest-single.h"
29 #include "qapi/qmp/qdict.h"
30 #include "qemu-common.h"
32 /* TODO actually test the results and get rid of this */
33 #define qmp_discard_response(...) qobject_unref(qmp(__VA_ARGS__))
35 #define DRIVE_FLOPPY_BLANK \
36 "-drive if=floppy,file=null-co://,file.read-zeroes=on,format=raw,size=1440k"
38 #define TEST_IMAGE_SIZE 1440 * 1024
40 #define FLOPPY_BASE 0x3f0
59 CMD_RELATIVE_SEEK_OUT
= 0x8f,
60 CMD_RELATIVE_SEEK_IN
= 0xcf,
72 static char test_image
[] = "/tmp/qtest.XXXXXX";
74 #define assert_bit_set(data, mask) g_assert_cmphex((data) & (mask), ==, (mask))
75 #define assert_bit_clear(data, mask) g_assert_cmphex((data) & (mask), ==, 0)
77 static uint8_t base
= 0x70;
83 static void floppy_send(uint8_t byte
)
87 msr
= inb(FLOPPY_BASE
+ reg_msr
);
88 assert_bit_set(msr
, RQM
);
89 assert_bit_clear(msr
, DIO
);
91 outb(FLOPPY_BASE
+ reg_fifo
, byte
);
94 static uint8_t floppy_recv(void)
98 msr
= inb(FLOPPY_BASE
+ reg_msr
);
99 assert_bit_set(msr
, RQM
| DIO
);
101 return inb(FLOPPY_BASE
+ reg_fifo
);
104 /* pcn: Present Cylinder Number */
105 static void ack_irq(uint8_t *pcn
)
109 g_assert(get_irq(FLOPPY_IRQ
));
110 floppy_send(CMD_SENSE_INT
);
118 g_assert(!get_irq(FLOPPY_IRQ
));
121 static uint8_t send_read_command(uint8_t cmd
)
126 uint8_t sect_addr
= 1;
127 uint8_t sect_size
= 2;
138 floppy_send(head
<< 2 | drive
);
139 g_assert(!get_irq(FLOPPY_IRQ
));
142 floppy_send(sect_addr
);
143 floppy_send(sect_size
);
151 msr
= inb(FLOPPY_BASE
+ reg_msr
);
177 static uint8_t send_read_no_dma_command(int nb_sect
, uint8_t expected_st0
)
182 uint8_t sect_addr
= 1;
183 uint8_t sect_size
= 2;
184 uint8_t eot
= nb_sect
;
193 floppy_send(CMD_READ
);
194 floppy_send(head
<< 2 | drive
);
195 g_assert(!get_irq(FLOPPY_IRQ
));
198 floppy_send(sect_addr
);
199 floppy_send(sect_size
);
207 msr
= inb(FLOPPY_BASE
+ reg_msr
);
208 if (msr
== (BUSY
| NONDMA
| DIO
| RQM
)) {
219 for (i
= 0; i
< 512 * 2 * nb_sect
; i
++) {
220 msr
= inb(FLOPPY_BASE
+ reg_msr
);
221 assert_bit_set(msr
, BUSY
| RQM
| DIO
);
222 inb(FLOPPY_BASE
+ reg_fifo
);
225 msr
= inb(FLOPPY_BASE
+ reg_msr
);
226 assert_bit_set(msr
, BUSY
| RQM
| DIO
);
227 g_assert(get_irq(FLOPPY_IRQ
));
230 if (st0
!= expected_st0
) {
239 g_assert(get_irq(FLOPPY_IRQ
));
242 /* Check that we're back in command phase */
243 msr
= inb(FLOPPY_BASE
+ reg_msr
);
244 assert_bit_clear(msr
, BUSY
| DIO
);
245 assert_bit_set(msr
, RQM
);
246 g_assert(!get_irq(FLOPPY_IRQ
));
251 static void send_seek(int cyl
)
256 floppy_send(CMD_SEEK
);
257 floppy_send(head
<< 2 | drive
);
258 g_assert(!get_irq(FLOPPY_IRQ
));
263 static uint8_t cmos_read(uint8_t reg
)
266 return inb(base
+ 1);
269 static void test_cmos(void)
273 cmos
= cmos_read(CMOS_FLOPPY
);
274 g_assert(cmos
== 0x40 || cmos
== 0x50);
277 static void test_no_media_on_start(void)
281 /* Media changed bit must be set all time after start if there is
282 * no media in drive. */
283 dir
= inb(FLOPPY_BASE
+ reg_dir
);
284 assert_bit_set(dir
, DSKCHG
);
285 dir
= inb(FLOPPY_BASE
+ reg_dir
);
286 assert_bit_set(dir
, DSKCHG
);
288 dir
= inb(FLOPPY_BASE
+ reg_dir
);
289 assert_bit_set(dir
, DSKCHG
);
290 dir
= inb(FLOPPY_BASE
+ reg_dir
);
291 assert_bit_set(dir
, DSKCHG
);
294 static void test_read_without_media(void)
298 ret
= send_read_command(CMD_READ
);
302 static void test_media_insert(void)
306 /* Insert media in drive. DSKCHK should not be reset until a step pulse
308 qmp_discard_response("{'execute':'blockdev-change-medium', 'arguments':{"
309 " 'id':'floppy0', 'filename': %s, 'format': 'raw' }}",
312 dir
= inb(FLOPPY_BASE
+ reg_dir
);
313 assert_bit_set(dir
, DSKCHG
);
314 dir
= inb(FLOPPY_BASE
+ reg_dir
);
315 assert_bit_set(dir
, DSKCHG
);
318 dir
= inb(FLOPPY_BASE
+ reg_dir
);
319 assert_bit_set(dir
, DSKCHG
);
320 dir
= inb(FLOPPY_BASE
+ reg_dir
);
321 assert_bit_set(dir
, DSKCHG
);
323 /* Step to next track should clear DSKCHG bit. */
325 dir
= inb(FLOPPY_BASE
+ reg_dir
);
326 assert_bit_clear(dir
, DSKCHG
);
327 dir
= inb(FLOPPY_BASE
+ reg_dir
);
328 assert_bit_clear(dir
, DSKCHG
);
331 static void test_media_change(void)
337 /* Eject the floppy and check that DSKCHG is set. Reading it out doesn't
339 qmp_discard_response("{'execute':'eject', 'arguments':{"
340 " 'id':'floppy0' }}");
342 dir
= inb(FLOPPY_BASE
+ reg_dir
);
343 assert_bit_set(dir
, DSKCHG
);
344 dir
= inb(FLOPPY_BASE
+ reg_dir
);
345 assert_bit_set(dir
, DSKCHG
);
348 dir
= inb(FLOPPY_BASE
+ reg_dir
);
349 assert_bit_set(dir
, DSKCHG
);
350 dir
= inb(FLOPPY_BASE
+ reg_dir
);
351 assert_bit_set(dir
, DSKCHG
);
354 dir
= inb(FLOPPY_BASE
+ reg_dir
);
355 assert_bit_set(dir
, DSKCHG
);
356 dir
= inb(FLOPPY_BASE
+ reg_dir
);
357 assert_bit_set(dir
, DSKCHG
);
360 static void test_sense_interrupt(void)
367 floppy_send(CMD_SENSE_INT
);
369 g_assert(ret
== 0x80);
371 floppy_send(CMD_SEEK
);
372 floppy_send(head
<< 2 | drive
);
373 g_assert(!get_irq(FLOPPY_IRQ
));
376 floppy_send(CMD_SENSE_INT
);
378 g_assert(ret
== 0x20);
382 static void test_relative_seek(void)
389 /* Send seek to track 0 */
392 /* Send relative seek to increase track by 1 */
393 floppy_send(CMD_RELATIVE_SEEK_IN
);
394 floppy_send(head
<< 2 | drive
);
395 g_assert(!get_irq(FLOPPY_IRQ
));
401 /* Send relative seek to decrease track by 1 */
402 floppy_send(CMD_RELATIVE_SEEK_OUT
);
403 floppy_send(head
<< 2 | drive
);
404 g_assert(!get_irq(FLOPPY_IRQ
));
411 static void test_read_id(void)
419 /* Seek to track 0 and check with READ ID */
422 floppy_send(CMD_READ_ID
);
423 g_assert(!get_irq(FLOPPY_IRQ
));
424 floppy_send(head
<< 2 | drive
);
426 msr
= inb(FLOPPY_BASE
+ reg_msr
);
427 if (!get_irq(FLOPPY_IRQ
)) {
428 assert_bit_set(msr
, BUSY
);
429 assert_bit_clear(msr
, RQM
);
432 while (!get_irq(FLOPPY_IRQ
)) {
433 /* qemu involves a timer with READ ID... */
434 clock_step(1000000000LL / 50);
437 msr
= inb(FLOPPY_BASE
+ reg_msr
);
438 assert_bit_set(msr
, BUSY
| RQM
| DIO
);
444 head
= floppy_recv();
446 g_assert(get_irq(FLOPPY_IRQ
));
448 g_assert(!get_irq(FLOPPY_IRQ
));
450 g_assert_cmpint(cyl
, ==, 0);
451 g_assert_cmpint(head
, ==, 0);
452 g_assert_cmpint(st0
, ==, head
<< 2);
454 /* Seek to track 8 on head 1 and check with READ ID */
458 floppy_send(CMD_SEEK
);
459 floppy_send(head
<< 2 | drive
);
460 g_assert(!get_irq(FLOPPY_IRQ
));
462 g_assert(get_irq(FLOPPY_IRQ
));
465 floppy_send(CMD_READ_ID
);
466 g_assert(!get_irq(FLOPPY_IRQ
));
467 floppy_send(head
<< 2 | drive
);
469 msr
= inb(FLOPPY_BASE
+ reg_msr
);
470 if (!get_irq(FLOPPY_IRQ
)) {
471 assert_bit_set(msr
, BUSY
);
472 assert_bit_clear(msr
, RQM
);
475 while (!get_irq(FLOPPY_IRQ
)) {
476 /* qemu involves a timer with READ ID... */
477 clock_step(1000000000LL / 50);
480 msr
= inb(FLOPPY_BASE
+ reg_msr
);
481 assert_bit_set(msr
, BUSY
| RQM
| DIO
);
487 head
= floppy_recv();
489 g_assert(get_irq(FLOPPY_IRQ
));
491 g_assert(!get_irq(FLOPPY_IRQ
));
493 g_assert_cmpint(cyl
, ==, 8);
494 g_assert_cmpint(head
, ==, 1);
495 g_assert_cmpint(st0
, ==, head
<< 2);
498 static void test_read_no_dma_1(void)
502 outb(FLOPPY_BASE
+ reg_dor
, inb(FLOPPY_BASE
+ reg_dor
) & ~0x08);
504 ret
= send_read_no_dma_command(1, 0x04);
508 static void test_read_no_dma_18(void)
512 outb(FLOPPY_BASE
+ reg_dor
, inb(FLOPPY_BASE
+ reg_dor
) & ~0x08);
514 ret
= send_read_no_dma_command(18, 0x04);
518 static void test_read_no_dma_19(void)
522 outb(FLOPPY_BASE
+ reg_dor
, inb(FLOPPY_BASE
+ reg_dor
) & ~0x08);
524 ret
= send_read_no_dma_command(19, 0x20);
528 static void test_verify(void)
532 ret
= send_read_command(CMD_VERIFY
);
536 /* success if no crash or abort */
537 static void fuzz_registers(void)
541 for (i
= 0; i
< 1000; i
++) {
544 reg
= (uint8_t)g_test_rand_int_range(0, 8);
545 val
= (uint8_t)g_test_rand_int_range(0, 256);
547 outb(FLOPPY_BASE
+ reg
, val
);
548 inb(FLOPPY_BASE
+ reg
);
552 static bool qtest_check_clang_sanitizer(void)
554 #if defined(__SANITIZE_ADDRESS__) || __has_feature(address_sanitizer)
557 g_test_skip("QEMU not configured using --enable-sanitizers");
561 static void test_cve_2021_20196(void)
565 if (!qtest_check_clang_sanitizer()) {
569 s
= qtest_initf("-nographic -m 32M -nodefaults " DRIVE_FLOPPY_BLANK
);
571 qtest_outw(s
, 0x3f4, 0x0500);
572 qtest_outb(s
, 0x3f5, 0x00);
573 qtest_outb(s
, 0x3f5, 0x00);
574 qtest_outw(s
, 0x3f4, 0x0000);
575 qtest_outb(s
, 0x3f5, 0x00);
576 qtest_outw(s
, 0x3f1, 0x0400);
577 qtest_outw(s
, 0x3f4, 0x0000);
578 qtest_outw(s
, 0x3f4, 0x0000);
579 qtest_outb(s
, 0x3f5, 0x00);
580 qtest_outb(s
, 0x3f5, 0x01);
581 qtest_outw(s
, 0x3f1, 0x0500);
582 qtest_outb(s
, 0x3f5, 0x00);
586 int main(int argc
, char **argv
)
591 /* Create a temporary raw image */
592 fd
= mkstemp(test_image
);
594 ret
= ftruncate(fd
, TEST_IMAGE_SIZE
);
599 g_test_init(&argc
, &argv
, NULL
);
601 qtest_start("-machine pc -device floppy,id=floppy0");
602 qtest_irq_intercept_in(global_qtest
, "ioapic");
603 qtest_add_func("/fdc/cmos", test_cmos
);
604 qtest_add_func("/fdc/no_media_on_start", test_no_media_on_start
);
605 qtest_add_func("/fdc/read_without_media", test_read_without_media
);
606 qtest_add_func("/fdc/media_change", test_media_change
);
607 qtest_add_func("/fdc/sense_interrupt", test_sense_interrupt
);
608 qtest_add_func("/fdc/relative_seek", test_relative_seek
);
609 qtest_add_func("/fdc/read_id", test_read_id
);
610 qtest_add_func("/fdc/verify", test_verify
);
611 qtest_add_func("/fdc/media_insert", test_media_insert
);
612 qtest_add_func("/fdc/read_no_dma_1", test_read_no_dma_1
);
613 qtest_add_func("/fdc/read_no_dma_18", test_read_no_dma_18
);
614 qtest_add_func("/fdc/read_no_dma_19", test_read_no_dma_19
);
615 qtest_add_func("/fdc/fuzz-registers", fuzz_registers
);
616 qtest_add_func("/fdc/fuzz/cve_2021_20196", test_cve_2021_20196
);