debuggers.hg

view tools/tests/test_x86_emulator.c @ 0:7d21f7218375

Exact replica of unstable on 051908 + README-this
author Mukesh Rathor
date Mon May 19 15:34:57 2008 -0700 (2008-05-19)
parents
children 5c0bf00e371d
line source
1 #include <stdio.h>
2 #include <stdlib.h>
3 #include <string.h>
4 #include <stdint.h>
5 #include <public/xen.h>
6 #include <sys/mman.h>
8 #include "x86_emulate/x86_emulate.h"
9 #include "blowfish.h"
11 #define MMAP_SZ 16384
13 /* EFLAGS bit definitions. */
14 #define EFLG_OF (1<<11)
15 #define EFLG_DF (1<<10)
16 #define EFLG_SF (1<<7)
17 #define EFLG_ZF (1<<6)
18 #define EFLG_AF (1<<4)
19 #define EFLG_PF (1<<2)
20 #define EFLG_CF (1<<0)
22 static int read(
23 unsigned int seg,
24 unsigned long offset,
25 unsigned long *val,
26 unsigned int bytes,
27 struct x86_emulate_ctxt *ctxt)
28 {
29 *val = 0;
30 memcpy(val, (void *)offset, bytes);
31 return X86EMUL_OKAY;
32 }
34 static int write(
35 unsigned int seg,
36 unsigned long offset,
37 unsigned long val,
38 unsigned int bytes,
39 struct x86_emulate_ctxt *ctxt)
40 {
41 memcpy((void *)offset, &val, bytes);
42 return X86EMUL_OKAY;
43 }
45 static int cmpxchg(
46 unsigned int seg,
47 unsigned long offset,
48 void *old,
49 void *new,
50 unsigned int bytes,
51 struct x86_emulate_ctxt *ctxt)
52 {
53 memcpy((void *)offset, new, bytes);
54 return X86EMUL_OKAY;
55 }
57 static struct x86_emulate_ops emulops = {
58 .read = read,
59 .insn_fetch = read,
60 .write = write,
61 .cmpxchg = cmpxchg,
62 };
64 int main(int argc, char **argv)
65 {
66 struct x86_emulate_ctxt ctxt;
67 struct cpu_user_regs regs;
68 char *instr;
69 unsigned int *res, i;
70 int rc;
71 #ifndef __x86_64__
72 unsigned int bcdres_native, bcdres_emul;
73 #endif
75 ctxt.regs = &regs;
76 ctxt.force_writeback = 0;
77 ctxt.addr_size = 32;
78 ctxt.sp_size = 32;
80 res = mmap((void *)0x100000, MMAP_SZ, PROT_READ|PROT_WRITE,
81 MAP_FIXED|MAP_PRIVATE|MAP_ANONYMOUS, 0, 0);
82 if ( res == MAP_FAILED )
83 {
84 fprintf(stderr, "mmap to low address failed\n");
85 exit(1);
86 }
87 instr = (char *)res + 0x100;
89 printf("%-40s", "Testing addl %%ecx,(%%eax)...");
90 instr[0] = 0x01; instr[1] = 0x08;
91 regs.eflags = 0x200;
92 regs.eip = (unsigned long)&instr[0];
93 regs.ecx = 0x12345678;
94 regs.eax = (unsigned long)res;
95 *res = 0x7FFFFFFF;
96 rc = x86_emulate(&ctxt, &emulops);
97 if ( (rc != X86EMUL_OKAY) ||
98 (*res != 0x92345677) ||
99 (regs.eflags != 0xa94) ||
100 (regs.eip != (unsigned long)&instr[2]) )
101 goto fail;
102 printf("okay\n");
104 printf("%-40s", "Testing addl %%ecx,%%eax...");
105 instr[0] = 0x01; instr[1] = 0xc8;
106 regs.eflags = 0x200;
107 regs.eip = (unsigned long)&instr[0];
108 regs.ecx = 0x12345678;
109 regs.eax = 0x7FFFFFFF;
110 rc = x86_emulate(&ctxt, &emulops);
111 if ( (rc != X86EMUL_OKAY) ||
112 (regs.ecx != 0x12345678) ||
113 (regs.eax != 0x92345677) ||
114 (regs.eflags != 0xa94) ||
115 (regs.eip != (unsigned long)&instr[2]) )
116 goto fail;
117 printf("okay\n");
119 printf("%-40s", "Testing xorl (%%eax),%%ecx...");
120 instr[0] = 0x33; instr[1] = 0x08;
121 regs.eflags = 0x200;
122 regs.eip = (unsigned long)&instr[0];
123 #ifdef __x86_64__
124 regs.ecx = 0xFFFFFFFF12345678UL;
125 #else
126 regs.ecx = 0x12345678UL;
127 #endif
128 regs.eax = (unsigned long)res;
129 rc = x86_emulate(&ctxt, &emulops);
130 if ( (rc != X86EMUL_OKAY) ||
131 (*res != 0x92345677) ||
132 (regs.ecx != 0x8000000FUL) ||
133 (regs.eip != (unsigned long)&instr[2]) )
134 goto fail;
135 printf("okay\n");
137 printf("%-40s", "Testing movl (%%eax),%%ecx...");
138 instr[0] = 0x8b; instr[1] = 0x08;
139 regs.eflags = 0x200;
140 regs.eip = (unsigned long)&instr[0];
141 regs.ecx = ~0UL;
142 regs.eax = (unsigned long)res;
143 rc = x86_emulate(&ctxt, &emulops);
144 if ( (rc != X86EMUL_OKAY) ||
145 (*res != 0x92345677) ||
146 (regs.ecx != 0x92345677UL) ||
147 (regs.eip != (unsigned long)&instr[2]) )
148 goto fail;
149 printf("okay\n");
151 printf("%-40s", "Testing lock cmpxchgb %%cl,(%%ebx)...");
152 instr[0] = 0xf0; instr[1] = 0x0f; instr[2] = 0xb0; instr[3] = 0x0b;
153 regs.eflags = 0x200;
154 regs.eip = (unsigned long)&instr[0];
155 regs.eax = 0x92345677UL;
156 regs.ecx = 0xAA;
157 regs.ebx = (unsigned long)res;
158 rc = x86_emulate(&ctxt, &emulops);
159 if ( (rc != X86EMUL_OKAY) ||
160 (*res != 0x923456AA) ||
161 (regs.eflags != 0x244) ||
162 (regs.eax != 0x92345677UL) ||
163 (regs.eip != (unsigned long)&instr[4]) )
164 goto fail;
165 printf("okay\n");
167 printf("%-40s", "Testing lock cmpxchgb %%cl,(%%ebx)...");
168 instr[0] = 0xf0; instr[1] = 0x0f; instr[2] = 0xb0; instr[3] = 0x0b;
169 regs.eflags = 0x200;
170 regs.eip = (unsigned long)&instr[0];
171 regs.eax = 0xAABBCC77UL;
172 regs.ecx = 0xFF;
173 regs.ebx = (unsigned long)res;
174 rc = x86_emulate(&ctxt, &emulops);
175 if ( (rc != X86EMUL_OKAY) ||
176 (*res != 0x923456AA) ||
177 ((regs.eflags&0x240) != 0x200) ||
178 (regs.eax != 0xAABBCCAA) ||
179 (regs.ecx != 0xFF) ||
180 (regs.eip != (unsigned long)&instr[4]) )
181 goto fail;
182 printf("okay\n");
184 printf("%-40s", "Testing xchgl %%ecx,(%%eax)...");
185 instr[0] = 0x87; instr[1] = 0x08;
186 regs.eflags = 0x200;
187 regs.eip = (unsigned long)&instr[0];
188 regs.ecx = 0x12345678;
189 regs.eax = (unsigned long)res;
190 rc = x86_emulate(&ctxt, &emulops);
191 if ( (rc != X86EMUL_OKAY) ||
192 (*res != 0x12345678) ||
193 (regs.eflags != 0x200) ||
194 (regs.ecx != 0x923456AA) ||
195 (regs.eip != (unsigned long)&instr[2]) )
196 goto fail;
197 printf("okay\n");
199 printf("%-40s", "Testing lock cmpxchgl %%ecx,(%%ebx)...");
200 instr[0] = 0xf0; instr[1] = 0x0f; instr[2] = 0xb1; instr[3] = 0x0b;
201 regs.eflags = 0x200;
202 *res = 0x923456AA;
203 regs.eip = (unsigned long)&instr[0];
204 regs.eax = 0x923456AAUL;
205 regs.ecx = 0xDDEEFF00L;
206 regs.ebx = (unsigned long)res;
207 rc = x86_emulate(&ctxt, &emulops);
208 if ( (rc != X86EMUL_OKAY) ||
209 (*res != 0xDDEEFF00) ||
210 (regs.eflags != 0x244) ||
211 (regs.eax != 0x923456AAUL) ||
212 (regs.eip != (unsigned long)&instr[4]) )
213 goto fail;
214 printf("okay\n");
216 printf("%-40s", "Testing rep movsw...");
217 instr[0] = 0xf3; instr[1] = 0x66; instr[2] = 0xa5;
218 *res = 0x22334455;
219 regs.eflags = 0x200;
220 regs.ecx = 23;
221 regs.eip = (unsigned long)&instr[0];
222 regs.esi = (unsigned long)res + 0;
223 regs.edi = (unsigned long)res + 2;
224 rc = x86_emulate(&ctxt, &emulops);
225 if ( (rc != X86EMUL_OKAY) ||
226 (*res != 0x44554455) ||
227 (regs.eflags != 0x200) ||
228 (regs.ecx != 22) ||
229 (regs.esi != ((unsigned long)res + 2)) ||
230 (regs.edi != ((unsigned long)res + 4)) ||
231 (regs.eip != (unsigned long)&instr[0]) )
232 goto fail;
233 printf("okay\n");
235 printf("%-40s", "Testing btrl $0x1,(%edi)...");
236 instr[0] = 0x0f; instr[1] = 0xba; instr[2] = 0x37; instr[3] = 0x01;
237 *res = 0x2233445F;
238 regs.eflags = 0x200;
239 regs.eip = (unsigned long)&instr[0];
240 regs.edi = (unsigned long)res;
241 rc = x86_emulate(&ctxt, &emulops);
242 if ( (rc != X86EMUL_OKAY) ||
243 (*res != 0x2233445D) ||
244 ((regs.eflags&0x201) != 0x201) ||
245 (regs.eip != (unsigned long)&instr[4]) )
246 goto fail;
247 printf("okay\n");
249 printf("%-40s", "Testing btrl %eax,(%edi)...");
250 instr[0] = 0x0f; instr[1] = 0xb3; instr[2] = 0x07;
251 *res = 0x2233445F;
252 regs.eflags = 0x200;
253 regs.eip = (unsigned long)&instr[0];
254 regs.eax = -32;
255 regs.edi = (unsigned long)(res+1);
256 rc = x86_emulate(&ctxt, &emulops);
257 if ( (rc != X86EMUL_OKAY) ||
258 (*res != 0x2233445E) ||
259 ((regs.eflags&0x201) != 0x201) ||
260 (regs.eip != (unsigned long)&instr[3]) )
261 goto fail;
262 printf("okay\n");
264 res[0] = 0x12345678;
265 res[1] = 0x87654321;
267 printf("%-40s", "Testing cmpxchg8b (%edi) [succeeding]...");
268 instr[0] = 0x0f; instr[1] = 0xc7; instr[2] = 0x0f;
269 regs.eflags = 0x200;
270 regs.eax = res[0];
271 regs.edx = res[1];
272 regs.ebx = 0x9999AAAA;
273 regs.ecx = 0xCCCCFFFF;
274 regs.eip = (unsigned long)&instr[0];
275 regs.edi = (unsigned long)res;
276 rc = x86_emulate(&ctxt, &emulops);
277 if ( (rc != X86EMUL_OKAY) ||
278 (res[0] != 0x9999AAAA) ||
279 (res[1] != 0xCCCCFFFF) ||
280 ((regs.eflags&0x240) != 0x240) ||
281 (regs.eip != (unsigned long)&instr[3]) )
282 goto fail;
283 printf("okay\n");
285 printf("%-40s", "Testing cmpxchg8b (%edi) [failing]...");
286 instr[0] = 0x0f; instr[1] = 0xc7; instr[2] = 0x0f;
287 regs.eflags = 0x200;
288 regs.eip = (unsigned long)&instr[0];
289 regs.edi = (unsigned long)res;
290 rc = x86_emulate(&ctxt, &emulops);
291 if ( (rc != X86EMUL_OKAY) ||
292 (res[0] != 0x9999AAAA) ||
293 (res[1] != 0xCCCCFFFF) ||
294 (regs.eax != 0x9999AAAA) ||
295 (regs.edx != 0xCCCCFFFF) ||
296 ((regs.eflags&0x240) != 0x200) ||
297 (regs.eip != (unsigned long)&instr[3]) )
298 goto fail;
299 printf("okay\n");
301 printf("%-40s", "Testing movsxbd (%%eax),%%ecx...");
302 instr[0] = 0x0f; instr[1] = 0xbe; instr[2] = 0x08;
303 regs.eflags = 0x200;
304 regs.eip = (unsigned long)&instr[0];
305 regs.ecx = 0x12345678;
306 regs.eax = (unsigned long)res;
307 *res = 0x82;
308 rc = x86_emulate(&ctxt, &emulops);
309 if ( (rc != X86EMUL_OKAY) ||
310 (*res != 0x82) ||
311 (regs.ecx != 0xFFFFFF82) ||
312 ((regs.eflags&0x240) != 0x200) ||
313 (regs.eip != (unsigned long)&instr[3]) )
314 goto fail;
315 printf("okay\n");
317 printf("%-40s", "Testing movzxwd (%%eax),%%ecx...");
318 instr[0] = 0x0f; instr[1] = 0xb7; instr[2] = 0x08;
319 regs.eflags = 0x200;
320 regs.eip = (unsigned long)&instr[0];
321 regs.ecx = 0x12345678;
322 regs.eax = (unsigned long)res;
323 *res = 0x1234aa82;
324 rc = x86_emulate(&ctxt, &emulops);
325 if ( (rc != X86EMUL_OKAY) ||
326 (*res != 0x1234aa82) ||
327 (regs.ecx != 0xaa82) ||
328 ((regs.eflags&0x240) != 0x200) ||
329 (regs.eip != (unsigned long)&instr[3]) )
330 goto fail;
331 printf("okay\n");
333 printf("%-40s", "Testing xadd %%ax,(%%ecx)...");
334 instr[0] = 0x66; instr[1] = 0x0f; instr[2] = 0xc1; instr[3] = 0x01;
335 regs.eflags = 0x200;
336 regs.eip = (unsigned long)&instr[0];
337 regs.ecx = (unsigned long)res;
338 regs.eax = 0x12345678;
339 *res = 0x11111111;
340 rc = x86_emulate(&ctxt, &emulops);
341 if ( (rc != X86EMUL_OKAY) ||
342 (*res != 0x11116789) ||
343 (regs.eax != 0x12341111) ||
344 ((regs.eflags&0x240) != 0x200) ||
345 (regs.eip != (unsigned long)&instr[4]) )
346 goto fail;
347 printf("okay\n");
349 printf("%-40s", "Testing dec %%ax...");
350 instr[0] = 0x66; instr[1] = 0x48;
351 regs.eflags = 0x200;
352 regs.eip = (unsigned long)&instr[0];
353 regs.eax = 0x00000000;
354 rc = x86_emulate(&ctxt, &emulops);
355 if ( (rc != X86EMUL_OKAY) ||
356 (regs.eax != 0x0000ffff) ||
357 ((regs.eflags&0x240) != 0x200) ||
358 (regs.eip != (unsigned long)&instr[2]) )
359 goto fail;
360 printf("okay\n");
362 printf("%-40s", "Testing lea 8(%%ebp),%%eax...");
363 instr[0] = 0x8d; instr[1] = 0x45; instr[2] = 0x08;
364 regs.eflags = 0x200;
365 regs.eip = (unsigned long)&instr[0];
366 regs.eax = 0x12345678;
367 regs.ebp = 0xaaaaaaaa;
368 rc = x86_emulate(&ctxt, &emulops);
369 if ( (rc != X86EMUL_OKAY) ||
370 (regs.eax != 0xaaaaaab2) ||
371 ((regs.eflags&0x240) != 0x200) ||
372 (regs.eip != (unsigned long)&instr[3]) )
373 goto fail;
374 printf("okay\n");
376 printf("%-40s", "Testing daa/das (all inputs)...");
377 #ifndef __x86_64__
378 /* Bits 0-7: AL; Bit 8: EFLG_AF; Bit 9: EFLG_CF; Bit 10: DAA vs. DAS. */
379 for ( i = 0; i < 0x800; i++ )
380 {
381 regs.eflags = (i & 0x200) ? EFLG_CF : 0;
382 regs.eflags |= (i & 0x100) ? EFLG_AF : 0;
383 if ( i & 0x400 )
384 __asm__ (
385 "pushf; and $0xffffffee,(%%esp); or %1,(%%esp); popf; das; "
386 "pushf; popl %1"
387 : "=a" (bcdres_native), "=r" (regs.eflags)
388 : "0" (i & 0xff), "1" (regs.eflags) );
389 else
390 __asm__ (
391 "pushf; and $0xffffffee,(%%esp); or %1,(%%esp); popf; daa; "
392 "pushf; popl %1"
393 : "=a" (bcdres_native), "=r" (regs.eflags)
394 : "0" (i & 0xff), "1" (regs.eflags) );
395 bcdres_native |= (regs.eflags & EFLG_PF) ? 0x1000 : 0;
396 bcdres_native |= (regs.eflags & EFLG_ZF) ? 0x800 : 0;
397 bcdres_native |= (regs.eflags & EFLG_SF) ? 0x400 : 0;
398 bcdres_native |= (regs.eflags & EFLG_CF) ? 0x200 : 0;
399 bcdres_native |= (regs.eflags & EFLG_AF) ? 0x100 : 0;
401 instr[0] = (i & 0x400) ? 0x2f: 0x27; /* daa/das */
402 regs.eflags = (i & 0x200) ? EFLG_CF : 0;
403 regs.eflags |= (i & 0x100) ? EFLG_AF : 0;
404 regs.eip = (unsigned long)&instr[0];
405 regs.eax = (unsigned char)i;
406 rc = x86_emulate(&ctxt, &emulops);
407 bcdres_emul = regs.eax;
408 bcdres_emul |= (regs.eflags & EFLG_PF) ? 0x1000 : 0;
409 bcdres_emul |= (regs.eflags & EFLG_ZF) ? 0x800 : 0;
410 bcdres_emul |= (regs.eflags & EFLG_SF) ? 0x400 : 0;
411 bcdres_emul |= (regs.eflags & EFLG_CF) ? 0x200 : 0;
412 bcdres_emul |= (regs.eflags & EFLG_AF) ? 0x100 : 0;
413 if ( (rc != X86EMUL_OKAY) || (regs.eax > 255) ||
414 (regs.eip != (unsigned long)&instr[1]) )
415 goto fail;
417 if ( bcdres_emul != bcdres_native )
418 {
419 printf("%s: AL=%02x %s %s\n"
420 "Output: AL=%02x %s %s %s %s %s\n"
421 "Emul.: AL=%02x %s %s %s %s %s\n",
422 (i & 0x400) ? "DAS" : "DAA",
423 (unsigned char)i,
424 (i & 0x200) ? "CF" : " ",
425 (i & 0x100) ? "AF" : " ",
426 (unsigned char)bcdres_native,
427 (bcdres_native & 0x200) ? "CF" : " ",
428 (bcdres_native & 0x100) ? "AF" : " ",
429 (bcdres_native & 0x1000) ? "PF" : " ",
430 (bcdres_native & 0x800) ? "ZF" : " ",
431 (bcdres_native & 0x400) ? "SF" : " ",
432 (unsigned char)bcdres_emul,
433 (bcdres_emul & 0x200) ? "CF" : " ",
434 (bcdres_emul & 0x100) ? "AF" : " ",
435 (bcdres_emul & 0x1000) ? "PF" : " ",
436 (bcdres_emul & 0x800) ? "ZF" : " ",
437 (bcdres_emul & 0x400) ? "SF" : " ");
438 goto fail;
439 }
440 }
441 printf("okay\n");
442 #else
443 printf("skipped\n");
444 #endif
446 printf("Testing blowfish code sequence");
447 memcpy(res, blowfish_code, sizeof(blowfish_code));
448 regs.eax = 2;
449 regs.edx = 1;
450 regs.eip = (unsigned long)res;
451 regs.esp = (unsigned long)res + MMAP_SZ - 4;
452 *(uint32_t *)(unsigned long)regs.esp = 0x12345678;
453 regs.eflags = 2;
454 i = 0;
455 while ( (uint32_t)regs.eip != 0x12345678 )
456 {
457 if ( (i++ & 8191) == 0 )
458 printf(".");
459 rc = x86_emulate(&ctxt, &emulops);
460 if ( rc != X86EMUL_OKAY )
461 {
462 printf("failed at %%eip == %08x\n", (unsigned int)regs.eip);
463 return 1;
464 }
465 }
466 if ( (regs.esp != ((unsigned long)res + MMAP_SZ)) ||
467 (regs.eax != 2) || (regs.edx != 1) )
468 goto fail;
469 printf("okay\n");
471 #ifndef __x86_64__
472 printf("%-40s", "Testing blowfish native execution...");
473 asm volatile (
474 "movl $0x100000,%%ecx; call *%%ecx"
475 : "=a" (regs.eax), "=d" (regs.edx)
476 : "0" (2), "1" (1) : "ecx" );
477 if ( (regs.eax != 2) || (regs.edx != 1) )
478 goto fail;
479 printf("okay\n");
480 #endif
482 return 0;
484 fail:
485 printf("failed!\n");
486 return 1;
487 }