\r
.const\r
\r
-m16Size DW offset InternalAsmThunk16 - offset m16Start\r
-mThunk16Attr DW offset _ThunkAttr - offset m16Start\r
-m16Gdt DW offset _NullSegDesc - offset m16Start\r
-m16GdtrBase DW offset _16GdtrBase - offset m16Start\r
-mTransition DW offset _EntryPoint - offset m16Start\r
+m16Size DW InternalAsmThunk16 - m16Start\r
+mThunk16Attr DW _ThunkAttr - m16Start\r
+m16Gdt DW _NullSeg - m16Start\r
+m16GdtrBase DW _16GdtrBase - m16Start\r
+mTransition DW _EntryPoint - m16Start\r
\r
.code\r
\r
m16Start LABEL BYTE\r
\r
-SavedGdt LABEL FWORD\r
- DW ?\r
- DQ ?\r
+SavedGdt LABEL FWORD\r
+ DW ?\r
+ DQ ?\r
\r
+;------------------------------------------------------------------------------\r
+; _BackFromUserCode() takes control in real mode after 'retf' has been executed\r
+; by user code. It will be shadowed to somewhere in memory below 1MB.\r
+;------------------------------------------------------------------------------\r
_BackFromUserCode PROC\r
DB 16h ; push ss\r
DB 0eh ; push cs\r
@2:\r
mov eax, ss\r
lea bp, [esp + sizeof (IA32_REGS)]\r
+ ;\r
+ ; rsi in the following 2 instructions is indeed bp in 16-bit code\r
+ ;\r
mov word ptr (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._ESP, bp\r
+ DB 66h\r
mov ebx, (IA32_REGS ptr [rsi - sizeof (IA32_REGS)])._EIP\r
shl ax, 4 ; shl eax, 4\r
add bp, ax ; add ebp, eax\r
+ mov ax, cs\r
+ shl ax, 4\r
+ lea ax, [eax + ebx + (@64BitCode - @Base)]\r
+ DB 66h, 2eh, 89h, 87h ; mov cs:[bx + (@64Eip - @Base)], eax\r
+ DW @64Eip - @Base\r
DB 66h, 0b8h ; mov eax, imm32\r
SavedCr4 DD ?\r
mov cr4, rax\r
+ ;\r
+ ; rdi in the instruction below is indeed bx in 16-bit code\r
+ ;\r
DB 66h, 2eh\r
- lgdt fword ptr [rdi + (offset SavedGdt - offset @Base)]\r
+ lgdt fword ptr [rdi + (SavedGdt - @Base)]\r
DB 66h\r
mov ecx, 0c0000080h\r
rdmsr\r
DB 66h, 0b8h ; mov eax, imm32\r
SavedCr0 DD ?\r
mov cr0, rax\r
- DB 0b8h ; mov ax, imm16\r
-SavedSs DW ?\r
- mov ss, eax\r
- DB 66h, 0bch ; mov esp, imm32\r
-SavedEsp DD ?\r
- DB 66h\r
- retf ; return to protected mode\r
+ DB 66h, 0eah ; jmp far cs:@64Bit\r
+@64Eip DD ?\r
+SavedCs DW ?\r
+@64BitCode:\r
+ DB 48h, 0b8h ; mov rax, imm64\r
+SavedRip DQ ?\r
+ jmp rax ; return to caller\r
_BackFromUserCode ENDP\r
\r
-_EntryPoint DD offset _ToUserCode - offset m16Start\r
- DW 8h\r
-_16Gdtr LABEL FWORD\r
- DW offset GdtEnd - offset _NullSegDesc - 1\r
-_16GdtrBase DQ offset _NullSegDesc\r
-_16Idtr FWORD (1 SHL 10) - 1\r
+_EntryPoint DD _ToUserCode - m16Start\r
+ DW CODE16\r
+_16Gdtr LABEL FWORD\r
+ DW GDT_SIZE - 1\r
+_16GdtrBase DQ _NullSeg\r
+_16Idtr FWORD (1 SHL 10) - 1\r
\r
+;------------------------------------------------------------------------------\r
+; _ToUserCode() takes control in real mode before passing control to user code.\r
+; It will be shadowed to somewhere in memory below 1MB.\r
+;------------------------------------------------------------------------------\r
_ToUserCode PROC\r
- mov edi, ss\r
mov ss, edx ; set new segment selectors\r
mov ds, edx\r
mov es, edx\r
wrmsr\r
mov cr4, rbp\r
mov ss, esi ; set up 16-bit stack segment\r
- xchg sp, bx ; set up 16-bit stack pointer\r
+ mov sp, bx ; set up 16-bit stack pointer\r
DB 66h\r
call @Base ; push eip\r
@Base:\r
- pop bp ; ebp <- offset @Base\r
+ pop bp ; ebp <- address of @Base\r
push [esp + sizeof (IA32_REGS) + 2]\r
- lea eax, [rsi + (offset @RealMode - offset @Base)]\r
+ lea eax, [rsi + (@RealMode - @Base)]\r
push rax\r
retf\r
@RealMode:\r
- DB 2eh ; cs:\r
- mov [rsi + (offset SavedSs - offset @Base)], edi\r
- DB 2eh ; cs:\r
- mov [rsi + (offset SavedEsp - offset @Base)], bx\r
DB 66h, 2eh ; CS and operand size override\r
- lidt fword ptr [rsi + (offset _16Idtr - offset @Base)]\r
+ lidt fword ptr [rsi + (_16Idtr - @Base)]\r
DB 66h, 61h ; popad\r
DB 1fh ; pop ds\r
DB 07h ; pop es\r
retf ; transfer control to user code\r
_ToUserCode ENDP\r
\r
-_NullSegDesc DQ 0\r
-_16CsDesc LABEL QWORD\r
- DW -1\r
- DW 0\r
- DB 0\r
- DB 9bh\r
- DB 8fh ; 16-bit segment, 4GB limit\r
- DB 0\r
-_16DsDesc LABEL QWORD\r
- DW -1\r
- DW 0\r
- DB 0\r
- DB 93h\r
- DB 8fh ; 16-bit segment, 4GB limit\r
- DB 0\r
-GdtEnd LABEL QWORD\r
+CODE16 = _16Code - $\r
+DATA16 = _16Data - $\r
+DATA32 = _32Data - $\r
\r
-;\r
-; @param RegSet Pointer to a IA32_DWORD_REGS structure\r
-; @param Transition Pointer to the transition code\r
-; @return The address of the 16-bit stack after returning from user code\r
-;\r
+_NullSeg DQ 0\r
+_16Code LABEL QWORD\r
+ DW -1\r
+ DW 0\r
+ DB 0\r
+ DB 9bh\r
+ DB 8fh ; 16-bit segment, 4GB limit\r
+ DB 0\r
+_16Data LABEL QWORD\r
+ DW -1\r
+ DW 0\r
+ DB 0\r
+ DB 93h\r
+ DB 8fh ; 16-bit segment, 4GB limit\r
+ DB 0\r
+_32Data LABEL QWORD\r
+ DW -1\r
+ DW 0\r
+ DB 0\r
+ DB 93h\r
+ DB 0cfh ; 16-bit segment, 4GB limit\r
+ DB 0\r
+\r
+GDT_SIZE = $ - _NullSeg\r
+\r
+;------------------------------------------------------------------------------\r
+; IA32_REGISTER_SET *\r
+; EFIAPI\r
+; InternalAsmThunk16 (\r
+; IN IA32_REGISTER_SET *RegisterSet,\r
+; IN OUT VOID *Transition\r
+; );\r
+;------------------------------------------------------------------------------\r
InternalAsmThunk16 PROC USES rbp rbx rsi rdi\r
mov r10d, ds\r
mov r11d, es\r
+ mov r9d, ss\r
push fs\r
push gs\r
mov rsi, rcx\r
mov edi, (IA32_REGS ptr [rsi])._ESP\r
lea rdi, [edi - (sizeof (IA32_REGS) + 4)]\r
imul eax, r8d, 16 ; eax <- r8d(stack segment) * 16\r
- mov ebx, edi ; ebx <- stack offset for 16-bit code\r
+ mov ebx, edi ; ebx <- stack for 16-bit code\r
push sizeof (IA32_REGS) / 4\r
add edi, eax ; edi <- linear address of 16-bit stack\r
pop rcx\r
rep movsd ; copy RegSet\r
- lea ecx, [rdx + (offset SavedCr4 - offset m16Start)]\r
+ lea ecx, [rdx + (SavedCr4 - m16Start)]\r
mov eax, edx ; eax <- transition code address\r
and edx, 0fh\r
shl eax, 12\r
- lea edx, [rdx + (offset _BackFromUserCode - offset m16Start)]\r
- mov ax, dx\r
+ lea ax, [rdx + (_BackFromUserCode - m16Start)]\r
stosd ; [edi] <- return address of user code\r
- sgdt fword ptr [rcx + (offset SavedGdt - offset SavedCr4)]\r
+ sgdt fword ptr [rcx + (SavedGdt - SavedCr4)]\r
sidt fword ptr [rsp + 38h] ; save IDT stack in argument space\r
mov rax, cr0\r
- mov [rcx + (offset SavedCr0 - offset SavedCr4)], eax\r
+ mov [rcx + (SavedCr0 - SavedCr4)], eax\r
and eax, 7ffffffeh ; clear PE, PG bits\r
mov rbp, cr4\r
mov [rcx], ebp ; save CR4 in SavedCr4\r
and ebp, 300h ; clear all but PCE and OSFXSR bits\r
mov esi, r8d ; esi <- 16-bit stack segment\r
- push 10h\r
- pop rdx ; rdx <- selector for data segments\r
- lgdt fword ptr [rcx + (offset _16Gdtr - offset SavedCr4)]\r
+ DB 6ah, DATA32 ; push DATA32\r
+ pop rdx ; rdx <- 32-bit data segment selector\r
+ lgdt fword ptr [rcx + (_16Gdtr - SavedCr4)]\r
+ mov ss, edx\r
pushfq\r
- call fword ptr [rcx + (offset _EntryPoint - offset SavedCr4)]\r
+ lea edx, [rdx + DATA16 - DATA32]\r
+ lea r8, @RetFromRealMode\r
+ mov [rcx + (SavedRip - SavedCr4)], r8\r
+ mov r8d, cs\r
+ mov [rcx + (SavedCs - SavedCr4)], r8w\r
+ mov r8, rsp\r
+ jmp fword ptr [rcx + (_EntryPoint - SavedCr4)]\r
+@RetFromRealMode:\r
+ mov rsp, r8\r
popfq\r
lidt fword ptr [rsp + 38h] ; restore protected mode IDTR\r
lea eax, [rbp - sizeof (IA32_REGS)]\r
pop gs\r
pop fs\r
+ mov ss, r9d\r
mov es, r11d\r
mov ds, r10d\r
ret\r