1 ;------------------------------------------------------------------------------
3 ; Copyright (c) 2006, Intel Corporation
4 ; All rights reserved. This program and the accompanying materials
5 ; are licensed and made available under the terms and conditions of the BSD License
6 ; which accompanies this distribution. The full text of the license may be found at
7 ; http://opensource.org/licenses/bsd-license.php
9 ; THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
10 ; WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
20 ;------------------------------------------------------------------------------
22 EXTERNDEF m16Start:BYTE
23 EXTERNDEF m16Size:WORD
24 EXTERNDEF mThunk16Attr:WORD
26 EXTERNDEF m16GdtrBase:WORD
27 EXTERNDEF mTransition:WORD
50 m16Size DW InternalAsmThunk16 - m16Start
51 mThunk16Attr DW _ThunkAttr - m16Start
52 m16Gdt DW _NullSeg - m16Start
53 m16GdtrBase DW _16GdtrBase - m16Start
54 mTransition DW _EntryPoint - m16Start
64 ;------------------------------------------------------------------------------
65 ; _BackFromUserCode() takes control in real mode after 'retf' has been executed
66 ; by user code. It will be shadowed to somewhere in memory below 1MB.
67 ;------------------------------------------------------------------------------
68 _BackFromUserCode PROC
75 push 0 ; reserved high order 32 bits of EFlags
76 pushf ; pushfd actually
77 cli ; disable interrupts
83 DB 66h, 0bah ; mov edx, imm32
85 test dl, THUNK_ATTRIBUTE_DISABLE_A20_MASK_INT_15
87 mov eax, 15cd2401h ; mov ax, 2401h & int 15h
88 cli ; disable interrupts
91 test dl, THUNK_ATTRIBUTE_DISABLE_A20_MASK_KBD_CTRL
95 out 92h, al ; deactivate A20M#
98 lea bp, [esp + sizeof (IA32_REGS)]
100 ; rsi in the following 2 instructions is indeed bp in 16-bit code
102 mov word ptr (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._ESP, bp
104 mov ebx, (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._EIP
105 shl ax, 4 ; shl eax, 4
106 add bp, ax ; add ebp, eax
109 lea ax, [eax + ebx + (@64BitCode - @Base)]
110 DB 66h, 2eh, 89h, 87h ; mov cs:[bx + (@64Eip - @Base)], eax
112 DB 66h, 0b8h ; mov eax, imm32
116 ; rdi in the instruction below is indeed bx in 16-bit code
119 lgdt fword ptr [rdi + (SavedGdt - @Base)]
125 DB 66h, 0b8h ; mov eax, imm32
128 DB 66h, 0eah ; jmp far cs:@64Bit
132 DB 48h, 0b8h ; mov rax, imm64
134 jmp rax ; return to caller
135 _BackFromUserCode ENDP
137 _EntryPoint DD _ToUserCode - m16Start
141 _16GdtrBase DQ _NullSeg
142 _16Idtr FWORD (1 SHL 10) - 1
144 ;------------------------------------------------------------------------------
145 ; _ToUserCode() takes control in real mode before passing control to user code.
146 ; It will be shadowed to somewhere in memory below 1MB.
147 ;------------------------------------------------------------------------------
149 mov ss, edx ; set new segment selectors
156 mov cr0, rax ; real mode starts at next instruction
161 mov ss, esi ; set up 16-bit stack segment
162 mov sp, bx ; set up 16-bit stack pointer
164 call @Base ; push eip
166 pop bp ; ebp <- address of @Base
167 push [esp + sizeof (IA32_REGS) + 2]
168 lea eax, [rsi + (@RealMode - @Base)]
172 DB 66h, 2eh ; CS and operand size override
173 lidt fword ptr [rsi + (_16Idtr - @Base)]
180 lea sp, [esp + 4] ; skip high order 32 bits of EFlags
182 retf ; transfer control to user code
195 DB 8fh ; 16-bit segment, 4GB limit
202 DB 8fh ; 16-bit segment, 4GB limit
209 DB 0cfh ; 16-bit segment, 4GB limit
212 GDT_SIZE = $ - _NullSeg
214 ;------------------------------------------------------------------------------
215 ; IA32_REGISTER_SET *
217 ; InternalAsmThunk16 (
218 ; IN IA32_REGISTER_SET *RegisterSet,
219 ; IN OUT VOID *Transition
221 ;------------------------------------------------------------------------------
222 InternalAsmThunk16 PROC USES rbp rbx rsi rdi
229 movzx r8d, (IA32_REGS ptr [rsi])._SS
230 mov edi, (IA32_REGS ptr [rsi])._ESP
231 lea rdi, [edi - (sizeof (IA32_REGS) + 4)]
232 imul eax, r8d, 16 ; eax <- r8d(stack segment) * 16
233 mov ebx, edi ; ebx <- stack for 16-bit code
234 push sizeof (IA32_REGS) / 4
235 add edi, eax ; edi <- linear address of 16-bit stack
237 rep movsd ; copy RegSet
238 lea ecx, [rdx + (SavedCr4 - m16Start)]
239 mov eax, edx ; eax <- transition code address
242 lea ax, [rdx + (_BackFromUserCode - m16Start)]
243 stosd ; [edi] <- return address of user code
244 sgdt fword ptr [rcx + (SavedGdt - SavedCr4)]
245 sidt fword ptr [rsp + 38h] ; save IDT stack in argument space
247 mov [rcx + (SavedCr0 - SavedCr4)], eax
248 and eax, 7ffffffeh ; clear PE, PG bits
250 mov [rcx], ebp ; save CR4 in SavedCr4
251 and ebp, 300h ; clear all but PCE and OSFXSR bits
252 mov esi, r8d ; esi <- 16-bit stack segment
253 DB 6ah, DATA32 ; push DATA32
254 pop rdx ; rdx <- 32-bit data segment selector
255 lgdt fword ptr [rcx + (_16Gdtr - SavedCr4)]
258 lea edx, [rdx + DATA16 - DATA32]
259 lea r8, @RetFromRealMode
260 mov [rcx + (SavedRip - SavedCr4)], r8
262 mov [rcx + (SavedCs - SavedCr4)], r8w
264 jmp fword ptr [rcx + (_EntryPoint - SavedCr4)]
268 lidt fword ptr [rsp + 38h] ; restore protected mode IDTR
269 lea eax, [rbp - sizeof (IA32_REGS)]
276 InternalAsmThunk16 ENDP