]>
Commit | Line | Data |
---|---|---|
b1ff428c | 1 | #------------------------------------------------------------------------------\r |
2 | #\r | |
4d4c535a | 3 | # Copyright (c) 2006 - 2010, Intel Corporation. All rights reserved.<BR>\r |
bb817c56 | 4 | # This program and the accompanying materials\r |
b1ff428c | 5 | # are licensed and made available under the terms and conditions of the BSD License\r |
6 | # which accompanies this distribution. The full text of the license may be found at\r | |
2fc59a00 | 7 | # http://opensource.org/licenses/bsd-license.php.\r |
b1ff428c | 8 | #\r |
9 | # THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,\r | |
10 | # WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.\r | |
11 | #\r | |
12 | # Module Name:\r | |
13 | #\r | |
14 | # Thunk16.S\r | |
15 | #\r | |
16 | # Abstract:\r | |
17 | #\r | |
18 | # Real mode thunk\r | |
19 | #\r | |
20 | #------------------------------------------------------------------------------\r | |
21 | \r | |
22 | #include <Library/BaseLib.h>\r | |
23 | \r | |
132f41f0 | 24 | ASM_GLOBAL ASM_PFX(m16Start)\r |
25 | ASM_GLOBAL ASM_PFX(m16Size)\r | |
26 | ASM_GLOBAL ASM_PFX(mThunk16Attr)\r | |
27 | ASM_GLOBAL ASM_PFX(m16Gdt)\r | |
28 | ASM_GLOBAL ASM_PFX(m16GdtrBase)\r | |
29 | ASM_GLOBAL ASM_PFX(mTransition)\r | |
30 | ASM_GLOBAL ASM_PFX(InternalAsmThunk16)\r | |
b1ff428c | 31 | \r |
32 | # define the structure of IA32_REGS\r | |
1afe0401 A |
33 | .set _EDI, 0 #size 4\r |
34 | .set _ESI, 4 #size 4\r | |
35 | .set _EBP, 8 #size 4\r | |
36 | .set _ESP, 12 #size 4\r | |
37 | .set _EBX, 16 #size 4\r | |
38 | .set _EDX, 20 #size 4\r | |
39 | .set _ECX, 24 #size 4\r | |
40 | .set _EAX, 28 #size 4\r | |
41 | .set _DS, 32 #size 2\r | |
42 | .set _ES, 34 #size 2\r | |
43 | .set _FS, 36 #size 2\r | |
44 | .set _GS, 38 #size 2\r | |
45 | .set _EFLAGS, 40 #size 8\r | |
46 | .set _EIP, 48 #size 4\r | |
47 | .set _CS, 52 #size 2\r | |
48 | .set _SS, 54 #size 2\r | |
49 | .set IA32_REGS_SIZE, 56\r | |
b1ff428c | 50 | \r |
51 | .data\r | |
bab427db | 52 | \r |
53 | .set Lm16Size, ASM_PFX(InternalAsmThunk16) - ASM_PFX(m16Start)\r | |
54 | ASM_PFX(m16Size): .word Lm16Size\r | |
55 | .set LmThunk16Attr, L_ThunkAttr - ASM_PFX(m16Start)\r | |
56 | ASM_PFX(mThunk16Attr): .word LmThunk16Attr\r | |
57 | .set Lm16Gdt, ASM_PFX(NullSeg) - ASM_PFX(m16Start)\r | |
58 | ASM_PFX(m16Gdt): .word Lm16Gdt\r | |
59 | .set Lm16GdtrBase, _16GdtrBase - ASM_PFX(m16Start)\r | |
60 | ASM_PFX(m16GdtrBase): .word Lm16GdtrBase\r | |
61 | .set LmTransition, _EntryPoint - ASM_PFX(m16Start)\r | |
62 | ASM_PFX(mTransition): .word LmTransition\r | |
b1ff428c | 63 | \r |
64 | .text\r | |
65 | \r | |
66 | ASM_PFX(m16Start):\r | |
67 | \r | |
68 | SavedGdt: .space 10\r | |
69 | \r | |
70 | #------------------------------------------------------------------------------\r | |
71 | # _BackFromUserCode() takes control in real mode after 'retf' has been executed\r | |
72 | # by user code. It will be shadowed to somewhere in memory below 1MB.\r | |
73 | #------------------------------------------------------------------------------\r | |
132f41f0 | 74 | ASM_GLOBAL ASM_PFX(BackFromUserCode)\r |
b1ff428c | 75 | ASM_PFX(BackFromUserCode):\r |
76 | #\r | |
77 | # The order of saved registers on the stack matches the order they appears\r | |
78 | # in IA32_REGS structure. This facilitates wrapper function to extract them\r | |
79 | # into that structure.\r | |
80 | #\r | |
81 | # Some instructions for manipulation of segment registers have to be written\r | |
82 | # in opcode since 64-bit MASM prevents accesses to those registers.\r | |
83 | #\r | |
84 | .byte 0x16 # push ss\r | |
85 | .byte 0xe # push cs\r | |
86 | .byte 0x66\r | |
87 | call L_Base # push eip\r | |
88 | L_Base: \r | |
89 | .byte 0x66\r | |
90 | pushq $0 # reserved high order 32 bits of EFlags\r | |
91 | .byte 0x66, 0x9c # pushfd actually\r | |
92 | cli # disable interrupts\r | |
93 | push %gs\r | |
94 | push %fs\r | |
95 | .byte 6 # push es\r | |
96 | .byte 0x1e # push ds\r | |
97 | .byte 0x66,0x60 # pushad\r | |
98 | .byte 0x66,0xba # mov edx, imm32\r | |
bab427db | 99 | L_ThunkAttr: .space 4\r |
b1ff428c | 100 | testb $THUNK_ATTRIBUTE_DISABLE_A20_MASK_INT_15, %dl\r |
101 | jz L_1\r | |
102 | movl $0x15cd2401,%eax # mov ax, 2401h & int 15h\r | |
103 | cli # disable interrupts\r | |
104 | jnc L_2\r | |
105 | L_1: \r | |
106 | testb $THUNK_ATTRIBUTE_DISABLE_A20_MASK_KBD_CTRL, %dl\r | |
107 | jz L_2\r | |
108 | inb $0x92,%al\r | |
109 | orb $2,%al\r | |
110 | outb %al, $0x92 # deactivate A20M#\r | |
111 | L_2: \r | |
4d4c535a | 112 | movw %ss,%ax\r |
b1ff428c | 113 | lea IA32_REGS_SIZE(%esp), %bp\r |
114 | #\r | |
115 | # rsi in the following 2 instructions is indeed bp in 16-bit code\r | |
116 | #\r | |
117 | movw %bp, (_ESP - IA32_REGS_SIZE)(%rsi)\r | |
118 | .byte 0x66\r | |
119 | movl (_EIP - IA32_REGS_SIZE)(%rsi), %ebx\r | |
120 | shlw $4,%ax # shl eax, 4\r | |
121 | addw %ax,%bp # add ebp, eax\r | |
122 | movw %cs,%ax\r | |
123 | shlw $4,%ax\r | |
124 | lea (L_64BitCode - L_Base)(%ebx, %eax), %ax\r | |
125 | .byte 0x66,0x2e,0x89,0x87 # mov cs:[bx + (L_64Eip - L_Base)], eax\r | |
126 | .word L_64Eip - L_Base\r | |
127 | .byte 0x66,0xb8 # mov eax, imm32\r | |
3c47fe65 | 128 | L_SavedCr4: .space 4\r |
b1ff428c | 129 | movq %rax, %cr4\r |
130 | #\r | |
131 | # rdi in the instruction below is indeed bx in 16-bit code\r | |
132 | #\r | |
133 | .byte 0x66,0x2e # 2eh is "cs:" segment override\r | |
134 | lgdt (SavedGdt - L_Base)(%rdi)\r | |
135 | .byte 0x66\r | |
136 | movl $0xc0000080,%ecx\r | |
137 | rdmsr\r | |
138 | orb $1,%ah\r | |
139 | wrmsr\r | |
140 | .byte 0x66,0xb8 # mov eax, imm32\r | |
3c47fe65 | 141 | L_SavedCr0: .space 4\r |
b1ff428c | 142 | movq %rax, %cr0\r |
143 | .byte 0x66,0xea # jmp far cs:L_64Bit\r | |
3c47fe65 EB |
144 | L_64Eip: .space 4\r |
145 | L_SavedCs: .space 2\r | |
146 | L_64BitCode:\r | |
0fe43214 | 147 | .byte 0x90\r |
148 | .byte 0x67,0xbc # mov esp, imm32\r | |
3c47fe65 | 149 | L_SavedSp: .space 4 # restore stack\r |
0fe43214 | 150 | nop\r |
b1ff428c | 151 | ret\r |
152 | \r | |
153 | _EntryPoint: .long ASM_PFX(ToUserCode) - ASM_PFX(m16Start)\r | |
154 | .word CODE16\r | |
155 | _16Gdtr: .word GDT_SIZE - 1\r | |
f2a4d593 | 156 | _16GdtrBase: .quad 0\r |
b1ff428c | 157 | _16Idtr: .word 0x3ff\r |
158 | .long 0\r | |
159 | \r | |
160 | #------------------------------------------------------------------------------\r | |
161 | # _ToUserCode() takes control in real mode before passing control to user code.\r | |
162 | # It will be shadowed to somewhere in memory below 1MB.\r | |
163 | #------------------------------------------------------------------------------\r | |
132f41f0 | 164 | ASM_GLOBAL ASM_PFX(ToUserCode)\r |
b1ff428c | 165 | ASM_PFX(ToUserCode):\r |
166 | movl %edx,%ss # set new segment selectors\r | |
167 | movl %edx,%ds\r | |
168 | movl %edx,%es\r | |
169 | movl %edx,%fs\r | |
170 | movl %edx,%gs\r | |
171 | .byte 0x66\r | |
172 | movl $0xc0000080,%ecx\r | |
173 | movq %rax, %cr0\r | |
174 | rdmsr\r | |
1afe0401 | 175 | andb $0xfe, %ah # $0b11111110\r |
b1ff428c | 176 | wrmsr\r |
177 | movq %rbp, %cr4\r | |
178 | movl %esi,%ss # set up 16-bit stack segment\r | |
179 | movw %bx,%sp # set up 16-bit stack pointer\r | |
180 | .byte 0x66 # make the following call 32-bit\r | |
181 | call L_Base1 # push eip\r | |
182 | L_Base1: \r | |
183 | popw %bp # ebp <- address of L_Base1\r | |
184 | pushq (IA32_REGS_SIZE + 2)(%esp)\r | |
185 | lea 0x0c(%rsi), %eax\r | |
186 | pushq %rax\r | |
187 | lret # execution begins at next instruction\r | |
188 | L_RealMode: \r | |
189 | .byte 0x66,0x2e # CS and operand size override\r | |
190 | lidt (_16Idtr - L_Base1)(%rsi)\r | |
191 | .byte 0x66,0x61 # popad\r | |
192 | .byte 0x1f # pop ds\r | |
193 | .byte 0x7 # pop es\r | |
194 | .byte 0x0f, 0xa1 # pop fs\r | |
195 | .byte 0x0f, 0xa9 # pop gs\r | |
196 | .byte 0x66, 0x9d # popfd\r | |
197 | leaw 4(%esp),%sp # skip high order 32 bits of EFlags\r | |
198 | .byte 0x66 # make the following retf 32-bit\r | |
199 | lret # transfer control to user code\r | |
200 | \r | |
1afe0401 A |
201 | .set CODE16, ASM_PFX(_16Code) - .\r |
202 | .set DATA16, ASM_PFX(_16Data) - .\r | |
203 | .set DATA32, ASM_PFX(_32Data) - .\r | |
b1ff428c | 204 | \r |
c9268416 | 205 | ASM_PFX(NullSeg): .quad 0\r |
206 | ASM_PFX(_16Code):\r | |
b1ff428c | 207 | .word -1\r |
208 | .word 0\r | |
209 | .byte 0\r | |
210 | .byte 0x9b\r | |
211 | .byte 0x8f # 16-bit segment, 4GB limit\r | |
212 | .byte 0\r | |
c9268416 | 213 | ASM_PFX(_16Data):\r |
b1ff428c | 214 | .word -1\r |
215 | .word 0\r | |
216 | .byte 0\r | |
217 | .byte 0x93\r | |
218 | .byte 0x8f # 16-bit segment, 4GB limit\r | |
219 | .byte 0\r | |
c9268416 | 220 | ASM_PFX(_32Data):\r |
b1ff428c | 221 | .word -1\r |
222 | .word 0\r | |
223 | .byte 0\r | |
224 | .byte 0x93\r | |
225 | .byte 0xcf # 16-bit segment, 4GB limit\r | |
226 | .byte 0\r | |
227 | \r | |
1afe0401 | 228 | .set GDT_SIZE, . - ASM_PFX(NullSeg)\r |
b1ff428c | 229 | \r |
230 | #------------------------------------------------------------------------------\r | |
231 | # IA32_REGISTER_SET *\r | |
232 | # EFIAPI\r | |
233 | # InternalAsmThunk16 (\r | |
234 | # IN IA32_REGISTER_SET *RegisterSet,\r | |
235 | # IN OUT VOID *Transition\r | |
236 | # );\r | |
237 | #------------------------------------------------------------------------------\r | |
b1ff428c | 238 | \r |
132f41f0 | 239 | ASM_GLOBAL ASM_PFX(InternalAsmThunk16)\r |
b1ff428c | 240 | ASM_PFX(InternalAsmThunk16):\r |
241 | pushq %rbp\r | |
242 | pushq %rbx\r | |
243 | pushq %rsi\r | |
244 | pushq %rdi\r | |
245 | \r | |
1afe0401 | 246 | movl %ds, %ebx\r |
0fe43214 | 247 | pushq %rbx # Save ds segment register on the stack\r |
1afe0401 | 248 | movl %es, %ebx\r |
0fe43214 | 249 | pushq %rbx # Save es segment register on the stack\r |
1afe0401 | 250 | movl %ss, %ebx\r |
0fe43214 | 251 | pushq %rbx # Save ss segment register on the stack\r |
252 | \r | |
b1ff428c | 253 | .byte 0x0f, 0xa0 #push fs\r |
254 | .byte 0x0f, 0xa8 #push gs\r | |
255 | movq %rcx, %rsi\r | |
256 | movzwl _SS(%rsi), %r8d\r | |
257 | movl _ESP(%rsi), %edi\r | |
258 | lea -(IA32_REGS_SIZE + 4)(%edi), %rdi\r | |
259 | imul $16, %r8d, %eax \r | |
260 | movl %edi,%ebx # ebx <- stack for 16-bit code\r | |
261 | pushq $(IA32_REGS_SIZE / 4)\r | |
262 | addl %eax,%edi # edi <- linear address of 16-bit stack\r | |
263 | popq %rcx\r | |
264 | rep\r | |
265 | movsl # copy RegSet\r | |
bab427db | 266 | lea (L_SavedCr4 - ASM_PFX(m16Start))(%rdx), %ecx\r |
b1ff428c | 267 | movl %edx,%eax # eax <- transition code address\r |
268 | andl $0xf,%edx\r | |
269 | shll $12,%eax # segment address in high order 16 bits\r | |
bab427db | 270 | .set LBackFromUserCodeDelta, ASM_PFX(BackFromUserCode) - ASM_PFX(m16Start) \r |
271 | lea (LBackFromUserCodeDelta)(%rdx), %ax\r | |
b1ff428c | 272 | stosl # [edi] <- return address of user code\r |
a1487801 | 273 | sgdt 0x60(%rsp) # save GDT stack in argument space\r |
274 | movzwq 0x60(%rsp), %r10 # r10 <- GDT limit \r | |
bab427db | 275 | lea ((ASM_PFX(InternalAsmThunk16) - L_SavedCr4) + 0xf)(%rcx), %r11 \r |
1afe0401 | 276 | andq $0xfffffffffffffff0, %r11 # r11 <- 16-byte aligned shadowed GDT table in real mode buffer \r |
a1487801 | 277 | \r |
bab427db | 278 | movw %r10w, (SavedGdt - L_SavedCr4)(%rcx) # save the limit of shadowed GDT table\r |
279 | movq %r11, (SavedGdt - L_SavedCr4 + 0x2)(%rcx) # save the base address of shadowed GDT table\r | |
a1487801 | 280 | \r |
281 | movq 0x62(%rsp) ,%rsi # rsi <- the original GDT base address\r | |
282 | xchg %r10, %rcx # save rcx to r10 and initialize rcx to be the limit of GDT table \r | |
283 | incq %rcx # rcx <- the size of memory to copy\r | |
284 | xchg %r11, %rdi # save rdi to r11 and initialize rdi to the base address of shadowed GDT table\r | |
285 | rep\r | |
286 | movsb # perform memory copy to shadow GDT table\r | |
287 | movq %r10, %rcx # restore the orignal rcx before memory copy\r | |
288 | movq %r11, %rdi # restore the original rdi before memory copy\r | |
289 | \r | |
0fe43214 | 290 | sidt 0x50(%rsp)\r |
b1ff428c | 291 | movq %cr0, %rax\r |
bab427db | 292 | .set LSavedCrDelta, L_SavedCr0 - L_SavedCr4\r |
293 | movl %eax, (LSavedCrDelta)(%rcx)\r | |
b1ff428c | 294 | andl $0x7ffffffe,%eax # clear PE, PG bits\r |
295 | movq %cr4, %rbp\r | |
296 | movl %ebp, (%rcx) # save CR4 in SavedCr4\r | |
297 | andl $0x300,%ebp # clear all but PCE and OSFXSR bits\r | |
298 | movl %r8d, %esi # esi <- 16-bit stack segment\r | |
299 | .byte 0x6a, DATA32\r | |
300 | popq %rdx\r | |
bab427db | 301 | lgdt (_16Gdtr - L_SavedCr4)(%rcx)\r |
b1ff428c | 302 | movl %edx,%ss\r |
303 | pushfq\r | |
304 | lea -8(%rdx), %edx\r | |
d48e8b0a | 305 | lea L_RetFromRealMode(%rip), %r8\r |
b1ff428c | 306 | pushq %r8\r |
307 | movl %cs, %r8d\r | |
bab427db | 308 | movw %r8w, (L_SavedCs - L_SavedCr4)(%rcx)\r |
309 | movl %esp, (L_SavedSp - L_SavedCr4)(%rcx)\r | |
310 | .byte 0xff, 0x69 # jmp (_EntryPoint - L_SavedCr4)(%rcx)\r | |
311 | .set Ltemp1, _EntryPoint - L_SavedCr4\r | |
312 | .byte Ltemp1\r | |
b1ff428c | 313 | L_RetFromRealMode: \r |
314 | popfq\r | |
a1487801 | 315 | lgdt 0x60(%rsp) # restore protected mode GDTR\r |
316 | lidt 0x50(%rsp) # restore protected mode IDTR\r | |
b1ff428c | 317 | lea -IA32_REGS_SIZE(%rbp), %eax\r |
318 | .byte 0x0f, 0xa9 # pop gs\r | |
319 | .byte 0x0f, 0xa1 # pop fs\r | |
0fe43214 | 320 | \r |
132f41f0 | 321 | popq %rbx\r |
1afe0401 | 322 | movl %ebx, %ss\r |
132f41f0 | 323 | popq %rbx\r |
1afe0401 | 324 | movl %ebx, %es\r |
132f41f0 | 325 | popq %rbx\r |
1afe0401 | 326 | movl %ebx, %ds\r |
b1ff428c | 327 | \r |
328 | popq %rdi\r | |
329 | popq %rsi\r | |
330 | popq %rbx\r | |
331 | popq %rbp\r | |
332 | \r | |
333 | ret\r |