xref: /openbmc/qemu/target/i386/hvf/hvf.c (revision 5df022cf)
169e0a03cSPaolo Bonzini /* Copyright 2008 IBM Corporation
269e0a03cSPaolo Bonzini  *           2008 Red Hat, Inc.
369e0a03cSPaolo Bonzini  * Copyright 2011 Intel Corporation
469e0a03cSPaolo Bonzini  * Copyright 2016 Veertu, Inc.
569e0a03cSPaolo Bonzini  * Copyright 2017 The Android Open Source Project
669e0a03cSPaolo Bonzini  *
769e0a03cSPaolo Bonzini  * QEMU Hypervisor.framework support
869e0a03cSPaolo Bonzini  *
969e0a03cSPaolo Bonzini  * This program is free software; you can redistribute it and/or
1069e0a03cSPaolo Bonzini  * modify it under the terms of version 2 of the GNU General Public
1169e0a03cSPaolo Bonzini  * License as published by the Free Software Foundation.
1269e0a03cSPaolo Bonzini  *
1369e0a03cSPaolo Bonzini  * This program is distributed in the hope that it will be useful,
1469e0a03cSPaolo Bonzini  * but WITHOUT ANY WARRANTY; without even the implied warranty of
1569e0a03cSPaolo Bonzini  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
16e361a772SThomas Huth  * General Public License for more details.
1769e0a03cSPaolo Bonzini  *
18e361a772SThomas Huth  * You should have received a copy of the GNU General Public License
19e361a772SThomas Huth  * along with this program; if not, see <http://www.gnu.org/licenses/>.
20d781e24dSIzik Eidus  *
21d781e24dSIzik Eidus  * This file contain code under public domain from the hvdos project:
22d781e24dSIzik Eidus  * https://github.com/mist64/hvdos
234d98a8e5SPaolo Bonzini  *
244d98a8e5SPaolo Bonzini  * Parts Copyright (c) 2011 NetApp, Inc.
254d98a8e5SPaolo Bonzini  * All rights reserved.
264d98a8e5SPaolo Bonzini  *
274d98a8e5SPaolo Bonzini  * Redistribution and use in source and binary forms, with or without
284d98a8e5SPaolo Bonzini  * modification, are permitted provided that the following conditions
294d98a8e5SPaolo Bonzini  * are met:
304d98a8e5SPaolo Bonzini  * 1. Redistributions of source code must retain the above copyright
314d98a8e5SPaolo Bonzini  *    notice, this list of conditions and the following disclaimer.
324d98a8e5SPaolo Bonzini  * 2. Redistributions in binary form must reproduce the above copyright
334d98a8e5SPaolo Bonzini  *    notice, this list of conditions and the following disclaimer in the
344d98a8e5SPaolo Bonzini  *    documentation and/or other materials provided with the distribution.
354d98a8e5SPaolo Bonzini  *
364d98a8e5SPaolo Bonzini  * THIS SOFTWARE IS PROVIDED BY NETAPP, INC ``AS IS'' AND
374d98a8e5SPaolo Bonzini  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
384d98a8e5SPaolo Bonzini  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
394d98a8e5SPaolo Bonzini  * ARE DISCLAIMED.  IN NO EVENT SHALL NETAPP, INC OR CONTRIBUTORS BE LIABLE
404d98a8e5SPaolo Bonzini  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
414d98a8e5SPaolo Bonzini  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
424d98a8e5SPaolo Bonzini  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
434d98a8e5SPaolo Bonzini  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
444d98a8e5SPaolo Bonzini  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
454d98a8e5SPaolo Bonzini  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
464d98a8e5SPaolo Bonzini  * SUCH DAMAGE.
4769e0a03cSPaolo Bonzini  */
4854d31236SMarkus Armbruster 
4969e0a03cSPaolo Bonzini #include "qemu/osdep.h"
5069e0a03cSPaolo Bonzini #include "qemu-common.h"
5169e0a03cSPaolo Bonzini #include "qemu/error-report.h"
52*5df022cfSPeter Maydell #include "qemu/memalign.h"
5369e0a03cSPaolo Bonzini 
5469e0a03cSPaolo Bonzini #include "sysemu/hvf.h"
55d57bc3c1SAlexander Graf #include "sysemu/hvf_int.h"
5654d31236SMarkus Armbruster #include "sysemu/runstate.h"
57a1477da3SAlexander Graf #include "sysemu/cpus.h"
5869e0a03cSPaolo Bonzini #include "hvf-i386.h"
5969e0a03cSPaolo Bonzini #include "vmcs.h"
6069e0a03cSPaolo Bonzini #include "vmx.h"
6169e0a03cSPaolo Bonzini #include "x86.h"
6269e0a03cSPaolo Bonzini #include "x86_descr.h"
6369e0a03cSPaolo Bonzini #include "x86_mmu.h"
6469e0a03cSPaolo Bonzini #include "x86_decode.h"
6569e0a03cSPaolo Bonzini #include "x86_emu.h"
6669e0a03cSPaolo Bonzini #include "x86_task.h"
6769e0a03cSPaolo Bonzini #include "x86hvf.h"
6869e0a03cSPaolo Bonzini 
6969e0a03cSPaolo Bonzini #include <Hypervisor/hv.h>
7069e0a03cSPaolo Bonzini #include <Hypervisor/hv_vmx.h>
713b502b0eSVladislav Yaroshchuk #include <sys/sysctl.h>
7269e0a03cSPaolo Bonzini 
7369e0a03cSPaolo Bonzini #include "hw/i386/apic_internal.h"
7469e0a03cSPaolo Bonzini #include "qemu/main-loop.h"
75940e43aaSClaudio Fontana #include "qemu/accel.h"
7669e0a03cSPaolo Bonzini #include "target/i386/cpu.h"
7769e0a03cSPaolo Bonzini 
7869e0a03cSPaolo Bonzini void vmx_update_tpr(CPUState *cpu)
7969e0a03cSPaolo Bonzini {
8069e0a03cSPaolo Bonzini     /* TODO: need integrate APIC handling */
8169e0a03cSPaolo Bonzini     X86CPU *x86_cpu = X86_CPU(cpu);
8269e0a03cSPaolo Bonzini     int tpr = cpu_get_apic_tpr(x86_cpu->apic_state) << 4;
8369e0a03cSPaolo Bonzini     int irr = apic_get_highest_priority_irr(x86_cpu->apic_state);
8469e0a03cSPaolo Bonzini 
85b533450eSAlexander Graf     wreg(cpu->hvf->fd, HV_X86_TPR, tpr);
8669e0a03cSPaolo Bonzini     if (irr == -1) {
87b533450eSAlexander Graf         wvmcs(cpu->hvf->fd, VMCS_TPR_THRESHOLD, 0);
8869e0a03cSPaolo Bonzini     } else {
89b533450eSAlexander Graf         wvmcs(cpu->hvf->fd, VMCS_TPR_THRESHOLD, (irr > tpr) ? tpr >> 4 :
9069e0a03cSPaolo Bonzini               irr >> 4);
9169e0a03cSPaolo Bonzini     }
9269e0a03cSPaolo Bonzini }
9369e0a03cSPaolo Bonzini 
94583ae161SRoman Bolshakov static void update_apic_tpr(CPUState *cpu)
9569e0a03cSPaolo Bonzini {
9669e0a03cSPaolo Bonzini     X86CPU *x86_cpu = X86_CPU(cpu);
97b533450eSAlexander Graf     int tpr = rreg(cpu->hvf->fd, HV_X86_TPR) >> 4;
9869e0a03cSPaolo Bonzini     cpu_set_apic_tpr(x86_cpu->apic_state, tpr);
9969e0a03cSPaolo Bonzini }
10069e0a03cSPaolo Bonzini 
10169e0a03cSPaolo Bonzini #define VECTORING_INFO_VECTOR_MASK     0xff
10269e0a03cSPaolo Bonzini 
10369e0a03cSPaolo Bonzini void hvf_handle_io(CPUArchState *env, uint16_t port, void *buffer,
10469e0a03cSPaolo Bonzini                   int direction, int size, int count)
10569e0a03cSPaolo Bonzini {
10669e0a03cSPaolo Bonzini     int i;
10769e0a03cSPaolo Bonzini     uint8_t *ptr = buffer;
10869e0a03cSPaolo Bonzini 
10969e0a03cSPaolo Bonzini     for (i = 0; i < count; i++) {
11069e0a03cSPaolo Bonzini         address_space_rw(&address_space_io, port, MEMTXATTRS_UNSPECIFIED,
11169e0a03cSPaolo Bonzini                          ptr, size,
11269e0a03cSPaolo Bonzini                          direction);
11369e0a03cSPaolo Bonzini         ptr += size;
11469e0a03cSPaolo Bonzini     }
11569e0a03cSPaolo Bonzini }
11669e0a03cSPaolo Bonzini 
117ff2de166SPaolo Bonzini static bool ept_emulation_fault(hvf_slot *slot, uint64_t gpa, uint64_t ept_qual)
11869e0a03cSPaolo Bonzini {
11969e0a03cSPaolo Bonzini     int read, write;
12069e0a03cSPaolo Bonzini 
12169e0a03cSPaolo Bonzini     /* EPT fault on an instruction fetch doesn't make sense here */
12269e0a03cSPaolo Bonzini     if (ept_qual & EPT_VIOLATION_INST_FETCH) {
12369e0a03cSPaolo Bonzini         return false;
12469e0a03cSPaolo Bonzini     }
12569e0a03cSPaolo Bonzini 
12669e0a03cSPaolo Bonzini     /* EPT fault must be a read fault or a write fault */
12769e0a03cSPaolo Bonzini     read = ept_qual & EPT_VIOLATION_DATA_READ ? 1 : 0;
12869e0a03cSPaolo Bonzini     write = ept_qual & EPT_VIOLATION_DATA_WRITE ? 1 : 0;
12969e0a03cSPaolo Bonzini     if ((read | write) == 0) {
13069e0a03cSPaolo Bonzini         return false;
13169e0a03cSPaolo Bonzini     }
13269e0a03cSPaolo Bonzini 
13369e0a03cSPaolo Bonzini     if (write && slot) {
13469e0a03cSPaolo Bonzini         if (slot->flags & HVF_SLOT_LOG) {
13569e0a03cSPaolo Bonzini             memory_region_set_dirty(slot->region, gpa - slot->start, 1);
13669e0a03cSPaolo Bonzini             hv_vm_protect((hv_gpaddr_t)slot->start, (size_t)slot->size,
13769e0a03cSPaolo Bonzini                           HV_MEMORY_READ | HV_MEMORY_WRITE);
13869e0a03cSPaolo Bonzini         }
13969e0a03cSPaolo Bonzini     }
14069e0a03cSPaolo Bonzini 
14169e0a03cSPaolo Bonzini     /*
14269e0a03cSPaolo Bonzini      * The EPT violation must have been caused by accessing a
14369e0a03cSPaolo Bonzini      * guest-physical address that is a translation of a guest-linear
14469e0a03cSPaolo Bonzini      * address.
14569e0a03cSPaolo Bonzini      */
14669e0a03cSPaolo Bonzini     if ((ept_qual & EPT_VIOLATION_GLA_VALID) == 0 ||
14769e0a03cSPaolo Bonzini         (ept_qual & EPT_VIOLATION_XLAT_VALID) == 0) {
14869e0a03cSPaolo Bonzini         return false;
14969e0a03cSPaolo Bonzini     }
15069e0a03cSPaolo Bonzini 
151fbafbb6dSCameron Esfahani     if (!slot) {
152fbafbb6dSCameron Esfahani         return true;
153fbafbb6dSCameron Esfahani     }
154fbafbb6dSCameron Esfahani     if (!memory_region_is_ram(slot->region) &&
155fbafbb6dSCameron Esfahani         !(read && memory_region_is_romd(slot->region))) {
156fbafbb6dSCameron Esfahani         return true;
157fbafbb6dSCameron Esfahani     }
158fbafbb6dSCameron Esfahani     return false;
15969e0a03cSPaolo Bonzini }
16069e0a03cSPaolo Bonzini 
161cfe58455SAlexander Graf void hvf_arch_vcpu_destroy(CPUState *cpu)
16269e0a03cSPaolo Bonzini {
163fe76b09cSRoman Bolshakov     X86CPU *x86_cpu = X86_CPU(cpu);
164fe76b09cSRoman Bolshakov     CPUX86State *env = &x86_cpu->env;
165fe76b09cSRoman Bolshakov 
166fe76b09cSRoman Bolshakov     g_free(env->hvf_mmio_buf);
16769e0a03cSPaolo Bonzini }
16869e0a03cSPaolo Bonzini 
1693b502b0eSVladislav Yaroshchuk static void init_tsc_freq(CPUX86State *env)
1703b502b0eSVladislav Yaroshchuk {
1713b502b0eSVladislav Yaroshchuk     size_t length;
1723b502b0eSVladislav Yaroshchuk     uint64_t tsc_freq;
1733b502b0eSVladislav Yaroshchuk 
1743b502b0eSVladislav Yaroshchuk     if (env->tsc_khz != 0) {
1753b502b0eSVladislav Yaroshchuk         return;
1763b502b0eSVladislav Yaroshchuk     }
1773b502b0eSVladislav Yaroshchuk 
1783b502b0eSVladislav Yaroshchuk     length = sizeof(uint64_t);
1793b502b0eSVladislav Yaroshchuk     if (sysctlbyname("machdep.tsc.frequency", &tsc_freq, &length, NULL, 0)) {
1803b502b0eSVladislav Yaroshchuk         return;
1813b502b0eSVladislav Yaroshchuk     }
1823b502b0eSVladislav Yaroshchuk     env->tsc_khz = tsc_freq / 1000;  /* Hz to KHz */
1833b502b0eSVladislav Yaroshchuk }
1843b502b0eSVladislav Yaroshchuk 
1853b502b0eSVladislav Yaroshchuk static void init_apic_bus_freq(CPUX86State *env)
1863b502b0eSVladislav Yaroshchuk {
1873b502b0eSVladislav Yaroshchuk     size_t length;
1883b502b0eSVladislav Yaroshchuk     uint64_t bus_freq;
1893b502b0eSVladislav Yaroshchuk 
1903b502b0eSVladislav Yaroshchuk     if (env->apic_bus_freq != 0) {
1913b502b0eSVladislav Yaroshchuk         return;
1923b502b0eSVladislav Yaroshchuk     }
1933b502b0eSVladislav Yaroshchuk 
1943b502b0eSVladislav Yaroshchuk     length = sizeof(uint64_t);
1953b502b0eSVladislav Yaroshchuk     if (sysctlbyname("hw.busfrequency", &bus_freq, &length, NULL, 0)) {
1963b502b0eSVladislav Yaroshchuk         return;
1973b502b0eSVladislav Yaroshchuk     }
1983b502b0eSVladislav Yaroshchuk     env->apic_bus_freq = bus_freq;
1993b502b0eSVladislav Yaroshchuk }
2003b502b0eSVladislav Yaroshchuk 
2013b502b0eSVladislav Yaroshchuk static inline bool tsc_is_known(CPUX86State *env)
2023b502b0eSVladislav Yaroshchuk {
2033b502b0eSVladislav Yaroshchuk     return env->tsc_khz != 0;
2043b502b0eSVladislav Yaroshchuk }
2053b502b0eSVladislav Yaroshchuk 
2063b502b0eSVladislav Yaroshchuk static inline bool apic_bus_freq_is_known(CPUX86State *env)
2073b502b0eSVladislav Yaroshchuk {
2083b502b0eSVladislav Yaroshchuk     return env->apic_bus_freq != 0;
2093b502b0eSVladislav Yaroshchuk }
2103b502b0eSVladislav Yaroshchuk 
211a1477da3SAlexander Graf void hvf_kick_vcpu_thread(CPUState *cpu)
212a1477da3SAlexander Graf {
213a1477da3SAlexander Graf     cpus_kick_thread(cpu);
214a1477da3SAlexander Graf }
215a1477da3SAlexander Graf 
216ce7f5b1cSAlexander Graf int hvf_arch_init(void)
217ce7f5b1cSAlexander Graf {
218ce7f5b1cSAlexander Graf     return 0;
219ce7f5b1cSAlexander Graf }
220ce7f5b1cSAlexander Graf 
221cfe58455SAlexander Graf int hvf_arch_init_vcpu(CPUState *cpu)
22269e0a03cSPaolo Bonzini {
22369e0a03cSPaolo Bonzini     X86CPU *x86cpu = X86_CPU(cpu);
22469e0a03cSPaolo Bonzini     CPUX86State *env = &x86cpu->env;
22569e0a03cSPaolo Bonzini 
22669e0a03cSPaolo Bonzini     init_emu();
22769e0a03cSPaolo Bonzini     init_decoder();
22869e0a03cSPaolo Bonzini 
22969e0a03cSPaolo Bonzini     hvf_state->hvf_caps = g_new0(struct hvf_vcpu_caps, 1);
230fe76b09cSRoman Bolshakov     env->hvf_mmio_buf = g_new(char, 4096);
23169e0a03cSPaolo Bonzini 
2323b502b0eSVladislav Yaroshchuk     if (x86cpu->vmware_cpuid_freq) {
2333b502b0eSVladislav Yaroshchuk         init_tsc_freq(env);
2343b502b0eSVladislav Yaroshchuk         init_apic_bus_freq(env);
2353b502b0eSVladislav Yaroshchuk 
2363b502b0eSVladislav Yaroshchuk         if (!tsc_is_known(env) || !apic_bus_freq_is_known(env)) {
2373b502b0eSVladislav Yaroshchuk             error_report("vmware-cpuid-freq: feature couldn't be enabled");
2383b502b0eSVladislav Yaroshchuk         }
2393b502b0eSVladislav Yaroshchuk     }
2403b502b0eSVladislav Yaroshchuk 
24169e0a03cSPaolo Bonzini     if (hv_vmx_read_capability(HV_VMX_CAP_PINBASED,
24269e0a03cSPaolo Bonzini         &hvf_state->hvf_caps->vmx_cap_pinbased)) {
24369e0a03cSPaolo Bonzini         abort();
24469e0a03cSPaolo Bonzini     }
24569e0a03cSPaolo Bonzini     if (hv_vmx_read_capability(HV_VMX_CAP_PROCBASED,
24669e0a03cSPaolo Bonzini         &hvf_state->hvf_caps->vmx_cap_procbased)) {
24769e0a03cSPaolo Bonzini         abort();
24869e0a03cSPaolo Bonzini     }
24969e0a03cSPaolo Bonzini     if (hv_vmx_read_capability(HV_VMX_CAP_PROCBASED2,
25069e0a03cSPaolo Bonzini         &hvf_state->hvf_caps->vmx_cap_procbased2)) {
25169e0a03cSPaolo Bonzini         abort();
25269e0a03cSPaolo Bonzini     }
25369e0a03cSPaolo Bonzini     if (hv_vmx_read_capability(HV_VMX_CAP_ENTRY,
25469e0a03cSPaolo Bonzini         &hvf_state->hvf_caps->vmx_cap_entry)) {
25569e0a03cSPaolo Bonzini         abort();
25669e0a03cSPaolo Bonzini     }
25769e0a03cSPaolo Bonzini 
25869e0a03cSPaolo Bonzini     /* set VMCS control fields */
259b533450eSAlexander Graf     wvmcs(cpu->hvf->fd, VMCS_PIN_BASED_CTLS,
26069e0a03cSPaolo Bonzini           cap2ctrl(hvf_state->hvf_caps->vmx_cap_pinbased,
26169e0a03cSPaolo Bonzini           VMCS_PIN_BASED_CTLS_EXTINT |
26269e0a03cSPaolo Bonzini           VMCS_PIN_BASED_CTLS_NMI |
26369e0a03cSPaolo Bonzini           VMCS_PIN_BASED_CTLS_VNMI));
264b533450eSAlexander Graf     wvmcs(cpu->hvf->fd, VMCS_PRI_PROC_BASED_CTLS,
26569e0a03cSPaolo Bonzini           cap2ctrl(hvf_state->hvf_caps->vmx_cap_procbased,
26669e0a03cSPaolo Bonzini           VMCS_PRI_PROC_BASED_CTLS_HLT |
26769e0a03cSPaolo Bonzini           VMCS_PRI_PROC_BASED_CTLS_MWAIT |
26869e0a03cSPaolo Bonzini           VMCS_PRI_PROC_BASED_CTLS_TSC_OFFSET |
26969e0a03cSPaolo Bonzini           VMCS_PRI_PROC_BASED_CTLS_TPR_SHADOW) |
27069e0a03cSPaolo Bonzini           VMCS_PRI_PROC_BASED_CTLS_SEC_CONTROL);
271b533450eSAlexander Graf     wvmcs(cpu->hvf->fd, VMCS_SEC_PROC_BASED_CTLS,
27269e0a03cSPaolo Bonzini           cap2ctrl(hvf_state->hvf_caps->vmx_cap_procbased2,
27369e0a03cSPaolo Bonzini                    VMCS_PRI_PROC_BASED2_CTLS_APIC_ACCESSES));
27469e0a03cSPaolo Bonzini 
275b533450eSAlexander Graf     wvmcs(cpu->hvf->fd, VMCS_ENTRY_CTLS, cap2ctrl(hvf_state->hvf_caps->vmx_cap_entry,
27669e0a03cSPaolo Bonzini           0));
277b533450eSAlexander Graf     wvmcs(cpu->hvf->fd, VMCS_EXCEPTION_BITMAP, 0); /* Double fault */
27869e0a03cSPaolo Bonzini 
279b533450eSAlexander Graf     wvmcs(cpu->hvf->fd, VMCS_TPR_THRESHOLD, 0);
28069e0a03cSPaolo Bonzini 
28169e0a03cSPaolo Bonzini     x86cpu = X86_CPU(cpu);
282c0198c5fSDavid Edmondson     x86cpu->env.xsave_buf_len = 4096;
283c0198c5fSDavid Edmondson     x86cpu->env.xsave_buf = qemu_memalign(4096, x86cpu->env.xsave_buf_len);
28469e0a03cSPaolo Bonzini 
285fea45008SDavid Edmondson     /*
286fea45008SDavid Edmondson      * The allocated storage must be large enough for all of the
287fea45008SDavid Edmondson      * possible XSAVE state components.
288fea45008SDavid Edmondson      */
289fea45008SDavid Edmondson     assert(hvf_get_supported_cpuid(0xd, 0, R_ECX) <= x86cpu->env.xsave_buf_len);
290fea45008SDavid Edmondson 
291b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_STAR, 1);
292b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_LSTAR, 1);
293b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_CSTAR, 1);
294b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_FMASK, 1);
295b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_FSBASE, 1);
296b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_GSBASE, 1);
297b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_KERNELGSBASE, 1);
298b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_TSC_AUX, 1);
299b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_IA32_TSC, 1);
300b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_IA32_SYSENTER_CS, 1);
301b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_IA32_SYSENTER_EIP, 1);
302b533450eSAlexander Graf     hv_vcpu_enable_native_msr(cpu->hvf->fd, MSR_IA32_SYSENTER_ESP, 1);
30369e0a03cSPaolo Bonzini 
30469e0a03cSPaolo Bonzini     return 0;
30569e0a03cSPaolo Bonzini }
30669e0a03cSPaolo Bonzini 
30769e0a03cSPaolo Bonzini static void hvf_store_events(CPUState *cpu, uint32_t ins_len, uint64_t idtvec_info)
30869e0a03cSPaolo Bonzini {
30969e0a03cSPaolo Bonzini     X86CPU *x86_cpu = X86_CPU(cpu);
31069e0a03cSPaolo Bonzini     CPUX86State *env = &x86_cpu->env;
31169e0a03cSPaolo Bonzini 
312fd13f23bSLiran Alon     env->exception_nr = -1;
313fd13f23bSLiran Alon     env->exception_pending = 0;
314fd13f23bSLiran Alon     env->exception_injected = 0;
31569e0a03cSPaolo Bonzini     env->interrupt_injected = -1;
31669e0a03cSPaolo Bonzini     env->nmi_injected = false;
31764bef038SCameron Esfahani     env->ins_len = 0;
31864bef038SCameron Esfahani     env->has_error_code = false;
31969e0a03cSPaolo Bonzini     if (idtvec_info & VMCS_IDT_VEC_VALID) {
32069e0a03cSPaolo Bonzini         switch (idtvec_info & VMCS_IDT_VEC_TYPE) {
32169e0a03cSPaolo Bonzini         case VMCS_IDT_VEC_HWINTR:
32269e0a03cSPaolo Bonzini         case VMCS_IDT_VEC_SWINTR:
32369e0a03cSPaolo Bonzini             env->interrupt_injected = idtvec_info & VMCS_IDT_VEC_VECNUM;
32469e0a03cSPaolo Bonzini             break;
32569e0a03cSPaolo Bonzini         case VMCS_IDT_VEC_NMI:
32669e0a03cSPaolo Bonzini             env->nmi_injected = true;
32769e0a03cSPaolo Bonzini             break;
32869e0a03cSPaolo Bonzini         case VMCS_IDT_VEC_HWEXCEPTION:
32969e0a03cSPaolo Bonzini         case VMCS_IDT_VEC_SWEXCEPTION:
330fd13f23bSLiran Alon             env->exception_nr = idtvec_info & VMCS_IDT_VEC_VECNUM;
331fd13f23bSLiran Alon             env->exception_injected = 1;
33269e0a03cSPaolo Bonzini             break;
33369e0a03cSPaolo Bonzini         case VMCS_IDT_VEC_PRIV_SWEXCEPTION:
33469e0a03cSPaolo Bonzini         default:
33569e0a03cSPaolo Bonzini             abort();
33669e0a03cSPaolo Bonzini         }
33769e0a03cSPaolo Bonzini         if ((idtvec_info & VMCS_IDT_VEC_TYPE) == VMCS_IDT_VEC_SWEXCEPTION ||
33869e0a03cSPaolo Bonzini             (idtvec_info & VMCS_IDT_VEC_TYPE) == VMCS_IDT_VEC_SWINTR) {
33969e0a03cSPaolo Bonzini             env->ins_len = ins_len;
34069e0a03cSPaolo Bonzini         }
34164bef038SCameron Esfahani         if (idtvec_info & VMCS_IDT_VEC_ERRCODE_VALID) {
34269e0a03cSPaolo Bonzini             env->has_error_code = true;
343b533450eSAlexander Graf             env->error_code = rvmcs(cpu->hvf->fd, VMCS_IDT_VECTORING_ERROR);
34469e0a03cSPaolo Bonzini         }
34569e0a03cSPaolo Bonzini     }
346b533450eSAlexander Graf     if ((rvmcs(cpu->hvf->fd, VMCS_GUEST_INTERRUPTIBILITY) &
34769e0a03cSPaolo Bonzini         VMCS_INTERRUPTIBILITY_NMI_BLOCKING)) {
34869e0a03cSPaolo Bonzini         env->hflags2 |= HF2_NMI_MASK;
34969e0a03cSPaolo Bonzini     } else {
35069e0a03cSPaolo Bonzini         env->hflags2 &= ~HF2_NMI_MASK;
35169e0a03cSPaolo Bonzini     }
352b533450eSAlexander Graf     if (rvmcs(cpu->hvf->fd, VMCS_GUEST_INTERRUPTIBILITY) &
35369e0a03cSPaolo Bonzini          (VMCS_INTERRUPTIBILITY_STI_BLOCKING |
35469e0a03cSPaolo Bonzini          VMCS_INTERRUPTIBILITY_MOVSS_BLOCKING)) {
35569e0a03cSPaolo Bonzini         env->hflags |= HF_INHIBIT_IRQ_MASK;
35669e0a03cSPaolo Bonzini     } else {
35769e0a03cSPaolo Bonzini         env->hflags &= ~HF_INHIBIT_IRQ_MASK;
35869e0a03cSPaolo Bonzini     }
35969e0a03cSPaolo Bonzini }
36069e0a03cSPaolo Bonzini 
3613b502b0eSVladislav Yaroshchuk static void hvf_cpu_x86_cpuid(CPUX86State *env, uint32_t index, uint32_t count,
3623b502b0eSVladislav Yaroshchuk                               uint32_t *eax, uint32_t *ebx,
3633b502b0eSVladislav Yaroshchuk                               uint32_t *ecx, uint32_t *edx)
3643b502b0eSVladislav Yaroshchuk {
3653b502b0eSVladislav Yaroshchuk     /*
3663b502b0eSVladislav Yaroshchuk      * A wrapper extends cpu_x86_cpuid with 0x40000000 and 0x40000010 leafs,
3673b502b0eSVladislav Yaroshchuk      * leafs 0x40000001-0x4000000F are filled with zeros
3683b502b0eSVladislav Yaroshchuk      * Provides vmware-cpuid-freq support to hvf
3693b502b0eSVladislav Yaroshchuk      *
3703b502b0eSVladislav Yaroshchuk      * Note: leaf 0x40000000 not exposes HVF,
3713b502b0eSVladislav Yaroshchuk      * leaving hypervisor signature empty
3723b502b0eSVladislav Yaroshchuk      */
3733b502b0eSVladislav Yaroshchuk 
3743b502b0eSVladislav Yaroshchuk     if (index < 0x40000000 || index > 0x40000010 ||
3753b502b0eSVladislav Yaroshchuk         !tsc_is_known(env) || !apic_bus_freq_is_known(env)) {
3763b502b0eSVladislav Yaroshchuk 
3773b502b0eSVladislav Yaroshchuk         cpu_x86_cpuid(env, index, count, eax, ebx, ecx, edx);
3783b502b0eSVladislav Yaroshchuk         return;
3793b502b0eSVladislav Yaroshchuk     }
3803b502b0eSVladislav Yaroshchuk 
3813b502b0eSVladislav Yaroshchuk     switch (index) {
3823b502b0eSVladislav Yaroshchuk     case 0x40000000:
3833b502b0eSVladislav Yaroshchuk         *eax = 0x40000010;    /* Max available cpuid leaf */
3843b502b0eSVladislav Yaroshchuk         *ebx = 0;             /* Leave signature empty */
3853b502b0eSVladislav Yaroshchuk         *ecx = 0;
3863b502b0eSVladislav Yaroshchuk         *edx = 0;
3873b502b0eSVladislav Yaroshchuk         break;
3883b502b0eSVladislav Yaroshchuk     case 0x40000010:
3893b502b0eSVladislav Yaroshchuk         *eax = env->tsc_khz;
3903b502b0eSVladislav Yaroshchuk         *ebx = env->apic_bus_freq / 1000; /* Hz to KHz */
3913b502b0eSVladislav Yaroshchuk         *ecx = 0;
3923b502b0eSVladislav Yaroshchuk         *edx = 0;
3933b502b0eSVladislav Yaroshchuk         break;
3943b502b0eSVladislav Yaroshchuk     default:
3953b502b0eSVladislav Yaroshchuk         *eax = 0;
3963b502b0eSVladislav Yaroshchuk         *ebx = 0;
3973b502b0eSVladislav Yaroshchuk         *ecx = 0;
3983b502b0eSVladislav Yaroshchuk         *edx = 0;
3993b502b0eSVladislav Yaroshchuk         break;
4003b502b0eSVladislav Yaroshchuk     }
4013b502b0eSVladislav Yaroshchuk }
4023b502b0eSVladislav Yaroshchuk 
40369e0a03cSPaolo Bonzini int hvf_vcpu_exec(CPUState *cpu)
40469e0a03cSPaolo Bonzini {
40569e0a03cSPaolo Bonzini     X86CPU *x86_cpu = X86_CPU(cpu);
40669e0a03cSPaolo Bonzini     CPUX86State *env = &x86_cpu->env;
40769e0a03cSPaolo Bonzini     int ret = 0;
40869e0a03cSPaolo Bonzini     uint64_t rip = 0;
40969e0a03cSPaolo Bonzini 
41069e0a03cSPaolo Bonzini     if (hvf_process_events(cpu)) {
41169e0a03cSPaolo Bonzini         return EXCP_HLT;
41269e0a03cSPaolo Bonzini     }
41369e0a03cSPaolo Bonzini 
41469e0a03cSPaolo Bonzini     do {
41569e0a03cSPaolo Bonzini         if (cpu->vcpu_dirty) {
41669e0a03cSPaolo Bonzini             hvf_put_registers(cpu);
41769e0a03cSPaolo Bonzini             cpu->vcpu_dirty = false;
41869e0a03cSPaolo Bonzini         }
41969e0a03cSPaolo Bonzini 
42069e0a03cSPaolo Bonzini         if (hvf_inject_interrupts(cpu)) {
42169e0a03cSPaolo Bonzini             return EXCP_INTERRUPT;
42269e0a03cSPaolo Bonzini         }
42369e0a03cSPaolo Bonzini         vmx_update_tpr(cpu);
42469e0a03cSPaolo Bonzini 
42569e0a03cSPaolo Bonzini         qemu_mutex_unlock_iothread();
42669e0a03cSPaolo Bonzini         if (!cpu_is_bsp(X86_CPU(cpu)) && cpu->halted) {
42769e0a03cSPaolo Bonzini             qemu_mutex_lock_iothread();
42869e0a03cSPaolo Bonzini             return EXCP_HLT;
42969e0a03cSPaolo Bonzini         }
43069e0a03cSPaolo Bonzini 
431b533450eSAlexander Graf         hv_return_t r  = hv_vcpu_run(cpu->hvf->fd);
43269e0a03cSPaolo Bonzini         assert_hvf_ok(r);
43369e0a03cSPaolo Bonzini 
43469e0a03cSPaolo Bonzini         /* handle VMEXIT */
435b533450eSAlexander Graf         uint64_t exit_reason = rvmcs(cpu->hvf->fd, VMCS_EXIT_REASON);
436b533450eSAlexander Graf         uint64_t exit_qual = rvmcs(cpu->hvf->fd, VMCS_EXIT_QUALIFICATION);
437b533450eSAlexander Graf         uint32_t ins_len = (uint32_t)rvmcs(cpu->hvf->fd,
43869e0a03cSPaolo Bonzini                                            VMCS_EXIT_INSTRUCTION_LENGTH);
43969e0a03cSPaolo Bonzini 
440b533450eSAlexander Graf         uint64_t idtvec_info = rvmcs(cpu->hvf->fd, VMCS_IDT_VECTORING_INFO);
44169e0a03cSPaolo Bonzini 
44269e0a03cSPaolo Bonzini         hvf_store_events(cpu, ins_len, idtvec_info);
443b533450eSAlexander Graf         rip = rreg(cpu->hvf->fd, HV_X86_RIP);
444b533450eSAlexander Graf         env->eflags = rreg(cpu->hvf->fd, HV_X86_RFLAGS);
44569e0a03cSPaolo Bonzini 
44669e0a03cSPaolo Bonzini         qemu_mutex_lock_iothread();
44769e0a03cSPaolo Bonzini 
44869e0a03cSPaolo Bonzini         update_apic_tpr(cpu);
44969e0a03cSPaolo Bonzini         current_cpu = cpu;
45069e0a03cSPaolo Bonzini 
45169e0a03cSPaolo Bonzini         ret = 0;
45269e0a03cSPaolo Bonzini         switch (exit_reason) {
45369e0a03cSPaolo Bonzini         case EXIT_REASON_HLT: {
45469e0a03cSPaolo Bonzini             macvm_set_rip(cpu, rip + ins_len);
45569e0a03cSPaolo Bonzini             if (!((cpu->interrupt_request & CPU_INTERRUPT_HARD) &&
456967f4da2SRoman Bolshakov                 (env->eflags & IF_MASK))
45769e0a03cSPaolo Bonzini                 && !(cpu->interrupt_request & CPU_INTERRUPT_NMI) &&
45869e0a03cSPaolo Bonzini                 !(idtvec_info & VMCS_IDT_VEC_VALID)) {
45969e0a03cSPaolo Bonzini                 cpu->halted = 1;
46069e0a03cSPaolo Bonzini                 ret = EXCP_HLT;
4613b9c59daSChen Zhang                 break;
46269e0a03cSPaolo Bonzini             }
46369e0a03cSPaolo Bonzini             ret = EXCP_INTERRUPT;
46469e0a03cSPaolo Bonzini             break;
46569e0a03cSPaolo Bonzini         }
46669e0a03cSPaolo Bonzini         case EXIT_REASON_MWAIT: {
46769e0a03cSPaolo Bonzini             ret = EXCP_INTERRUPT;
46869e0a03cSPaolo Bonzini             break;
46969e0a03cSPaolo Bonzini         }
470fbafbb6dSCameron Esfahani         /* Need to check if MMIO or unmapped fault */
47169e0a03cSPaolo Bonzini         case EXIT_REASON_EPT_FAULT:
47269e0a03cSPaolo Bonzini         {
47369e0a03cSPaolo Bonzini             hvf_slot *slot;
474b533450eSAlexander Graf             uint64_t gpa = rvmcs(cpu->hvf->fd, VMCS_GUEST_PHYSICAL_ADDRESS);
47569e0a03cSPaolo Bonzini 
47669e0a03cSPaolo Bonzini             if (((idtvec_info & VMCS_IDT_VEC_VALID) == 0) &&
47769e0a03cSPaolo Bonzini                 ((exit_qual & EXIT_QUAL_NMIUDTI) != 0)) {
47869e0a03cSPaolo Bonzini                 vmx_set_nmi_blocking(cpu);
47969e0a03cSPaolo Bonzini             }
48069e0a03cSPaolo Bonzini 
481fbafbb6dSCameron Esfahani             slot = hvf_find_overlap_slot(gpa, 1);
48269e0a03cSPaolo Bonzini             /* mmio */
48369e0a03cSPaolo Bonzini             if (ept_emulation_fault(slot, gpa, exit_qual)) {
48469e0a03cSPaolo Bonzini                 struct x86_decode decode;
48569e0a03cSPaolo Bonzini 
48669e0a03cSPaolo Bonzini                 load_regs(cpu);
48769e0a03cSPaolo Bonzini                 decode_instruction(env, &decode);
48869e0a03cSPaolo Bonzini                 exec_instruction(env, &decode);
48969e0a03cSPaolo Bonzini                 store_regs(cpu);
49069e0a03cSPaolo Bonzini                 break;
49169e0a03cSPaolo Bonzini             }
49269e0a03cSPaolo Bonzini             break;
49369e0a03cSPaolo Bonzini         }
49469e0a03cSPaolo Bonzini         case EXIT_REASON_INOUT:
49569e0a03cSPaolo Bonzini         {
49669e0a03cSPaolo Bonzini             uint32_t in = (exit_qual & 8) != 0;
49769e0a03cSPaolo Bonzini             uint32_t size =  (exit_qual & 7) + 1;
49869e0a03cSPaolo Bonzini             uint32_t string =  (exit_qual & 16) != 0;
49969e0a03cSPaolo Bonzini             uint32_t port =  exit_qual >> 16;
50069e0a03cSPaolo Bonzini             /*uint32_t rep = (exit_qual & 0x20) != 0;*/
50169e0a03cSPaolo Bonzini 
50269e0a03cSPaolo Bonzini             if (!string && in) {
50369e0a03cSPaolo Bonzini                 uint64_t val = 0;
50469e0a03cSPaolo Bonzini                 load_regs(cpu);
50569e0a03cSPaolo Bonzini                 hvf_handle_io(env, port, &val, 0, size, 1);
50669e0a03cSPaolo Bonzini                 if (size == 1) {
50769e0a03cSPaolo Bonzini                     AL(env) = val;
50869e0a03cSPaolo Bonzini                 } else if (size == 2) {
50969e0a03cSPaolo Bonzini                     AX(env) = val;
51069e0a03cSPaolo Bonzini                 } else if (size == 4) {
51169e0a03cSPaolo Bonzini                     RAX(env) = (uint32_t)val;
51269e0a03cSPaolo Bonzini                 } else {
513da20f5cdSPaolo Bonzini                     RAX(env) = (uint64_t)val;
51469e0a03cSPaolo Bonzini                 }
5155d32173fSRoman Bolshakov                 env->eip += ins_len;
51669e0a03cSPaolo Bonzini                 store_regs(cpu);
51769e0a03cSPaolo Bonzini                 break;
51869e0a03cSPaolo Bonzini             } else if (!string && !in) {
519b533450eSAlexander Graf                 RAX(env) = rreg(cpu->hvf->fd, HV_X86_RAX);
52069e0a03cSPaolo Bonzini                 hvf_handle_io(env, port, &RAX(env), 1, size, 1);
52169e0a03cSPaolo Bonzini                 macvm_set_rip(cpu, rip + ins_len);
52269e0a03cSPaolo Bonzini                 break;
52369e0a03cSPaolo Bonzini             }
52469e0a03cSPaolo Bonzini             struct x86_decode decode;
52569e0a03cSPaolo Bonzini 
52669e0a03cSPaolo Bonzini             load_regs(cpu);
52769e0a03cSPaolo Bonzini             decode_instruction(env, &decode);
528e62963bfSPaolo Bonzini             assert(ins_len == decode.len);
52969e0a03cSPaolo Bonzini             exec_instruction(env, &decode);
53069e0a03cSPaolo Bonzini             store_regs(cpu);
53169e0a03cSPaolo Bonzini 
53269e0a03cSPaolo Bonzini             break;
53369e0a03cSPaolo Bonzini         }
53469e0a03cSPaolo Bonzini         case EXIT_REASON_CPUID: {
535b533450eSAlexander Graf             uint32_t rax = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RAX);
536b533450eSAlexander Graf             uint32_t rbx = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RBX);
537b533450eSAlexander Graf             uint32_t rcx = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RCX);
538b533450eSAlexander Graf             uint32_t rdx = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RDX);
53969e0a03cSPaolo Bonzini 
540106f91d5SAlexander Graf             if (rax == 1) {
541106f91d5SAlexander Graf                 /* CPUID1.ecx.OSXSAVE needs to know CR4 */
542b533450eSAlexander Graf                 env->cr[4] = rvmcs(cpu->hvf->fd, VMCS_GUEST_CR4);
543106f91d5SAlexander Graf             }
5443b502b0eSVladislav Yaroshchuk             hvf_cpu_x86_cpuid(env, rax, rcx, &rax, &rbx, &rcx, &rdx);
54569e0a03cSPaolo Bonzini 
546b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_RAX, rax);
547b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_RBX, rbx);
548b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_RCX, rcx);
549b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_RDX, rdx);
55069e0a03cSPaolo Bonzini 
55169e0a03cSPaolo Bonzini             macvm_set_rip(cpu, rip + ins_len);
55269e0a03cSPaolo Bonzini             break;
55369e0a03cSPaolo Bonzini         }
55469e0a03cSPaolo Bonzini         case EXIT_REASON_XSETBV: {
55569e0a03cSPaolo Bonzini             X86CPU *x86_cpu = X86_CPU(cpu);
55669e0a03cSPaolo Bonzini             CPUX86State *env = &x86_cpu->env;
557b533450eSAlexander Graf             uint32_t eax = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RAX);
558b533450eSAlexander Graf             uint32_t ecx = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RCX);
559b533450eSAlexander Graf             uint32_t edx = (uint32_t)rreg(cpu->hvf->fd, HV_X86_RDX);
56069e0a03cSPaolo Bonzini 
56169e0a03cSPaolo Bonzini             if (ecx) {
56269e0a03cSPaolo Bonzini                 macvm_set_rip(cpu, rip + ins_len);
56369e0a03cSPaolo Bonzini                 break;
56469e0a03cSPaolo Bonzini             }
56569e0a03cSPaolo Bonzini             env->xcr0 = ((uint64_t)edx << 32) | eax;
566b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_XCR0, env->xcr0 | 1);
56769e0a03cSPaolo Bonzini             macvm_set_rip(cpu, rip + ins_len);
56869e0a03cSPaolo Bonzini             break;
56969e0a03cSPaolo Bonzini         }
57069e0a03cSPaolo Bonzini         case EXIT_REASON_INTR_WINDOW:
57169e0a03cSPaolo Bonzini             vmx_clear_int_window_exiting(cpu);
57269e0a03cSPaolo Bonzini             ret = EXCP_INTERRUPT;
57369e0a03cSPaolo Bonzini             break;
57469e0a03cSPaolo Bonzini         case EXIT_REASON_NMI_WINDOW:
57569e0a03cSPaolo Bonzini             vmx_clear_nmi_window_exiting(cpu);
57669e0a03cSPaolo Bonzini             ret = EXCP_INTERRUPT;
57769e0a03cSPaolo Bonzini             break;
57869e0a03cSPaolo Bonzini         case EXIT_REASON_EXT_INTR:
57969e0a03cSPaolo Bonzini             /* force exit and allow io handling */
58069e0a03cSPaolo Bonzini             ret = EXCP_INTERRUPT;
58169e0a03cSPaolo Bonzini             break;
58269e0a03cSPaolo Bonzini         case EXIT_REASON_RDMSR:
58369e0a03cSPaolo Bonzini         case EXIT_REASON_WRMSR:
58469e0a03cSPaolo Bonzini         {
58569e0a03cSPaolo Bonzini             load_regs(cpu);
58669e0a03cSPaolo Bonzini             if (exit_reason == EXIT_REASON_RDMSR) {
58769e0a03cSPaolo Bonzini                 simulate_rdmsr(cpu);
58869e0a03cSPaolo Bonzini             } else {
58969e0a03cSPaolo Bonzini                 simulate_wrmsr(cpu);
59069e0a03cSPaolo Bonzini             }
5915d32173fSRoman Bolshakov             env->eip += ins_len;
59269e0a03cSPaolo Bonzini             store_regs(cpu);
59369e0a03cSPaolo Bonzini             break;
59469e0a03cSPaolo Bonzini         }
59569e0a03cSPaolo Bonzini         case EXIT_REASON_CR_ACCESS: {
59669e0a03cSPaolo Bonzini             int cr;
59769e0a03cSPaolo Bonzini             int reg;
59869e0a03cSPaolo Bonzini 
59969e0a03cSPaolo Bonzini             load_regs(cpu);
60069e0a03cSPaolo Bonzini             cr = exit_qual & 15;
60169e0a03cSPaolo Bonzini             reg = (exit_qual >> 8) & 15;
60269e0a03cSPaolo Bonzini 
60369e0a03cSPaolo Bonzini             switch (cr) {
60469e0a03cSPaolo Bonzini             case 0x0: {
605b533450eSAlexander Graf                 macvm_set_cr0(cpu->hvf->fd, RRX(env, reg));
60669e0a03cSPaolo Bonzini                 break;
60769e0a03cSPaolo Bonzini             }
60869e0a03cSPaolo Bonzini             case 4: {
609b533450eSAlexander Graf                 macvm_set_cr4(cpu->hvf->fd, RRX(env, reg));
61069e0a03cSPaolo Bonzini                 break;
61169e0a03cSPaolo Bonzini             }
61269e0a03cSPaolo Bonzini             case 8: {
61369e0a03cSPaolo Bonzini                 X86CPU *x86_cpu = X86_CPU(cpu);
61469e0a03cSPaolo Bonzini                 if (exit_qual & 0x10) {
61569e0a03cSPaolo Bonzini                     RRX(env, reg) = cpu_get_apic_tpr(x86_cpu->apic_state);
61669e0a03cSPaolo Bonzini                 } else {
61769e0a03cSPaolo Bonzini                     int tpr = RRX(env, reg);
61869e0a03cSPaolo Bonzini                     cpu_set_apic_tpr(x86_cpu->apic_state, tpr);
61969e0a03cSPaolo Bonzini                     ret = EXCP_INTERRUPT;
62069e0a03cSPaolo Bonzini                 }
62169e0a03cSPaolo Bonzini                 break;
62269e0a03cSPaolo Bonzini             }
62369e0a03cSPaolo Bonzini             default:
6242d9178d9SLaurent Vivier                 error_report("Unrecognized CR %d", cr);
62569e0a03cSPaolo Bonzini                 abort();
62669e0a03cSPaolo Bonzini             }
6275d32173fSRoman Bolshakov             env->eip += ins_len;
62869e0a03cSPaolo Bonzini             store_regs(cpu);
62969e0a03cSPaolo Bonzini             break;
63069e0a03cSPaolo Bonzini         }
63169e0a03cSPaolo Bonzini         case EXIT_REASON_APIC_ACCESS: { /* TODO */
63269e0a03cSPaolo Bonzini             struct x86_decode decode;
63369e0a03cSPaolo Bonzini 
63469e0a03cSPaolo Bonzini             load_regs(cpu);
63569e0a03cSPaolo Bonzini             decode_instruction(env, &decode);
63669e0a03cSPaolo Bonzini             exec_instruction(env, &decode);
63769e0a03cSPaolo Bonzini             store_regs(cpu);
63869e0a03cSPaolo Bonzini             break;
63969e0a03cSPaolo Bonzini         }
64069e0a03cSPaolo Bonzini         case EXIT_REASON_TPR: {
64169e0a03cSPaolo Bonzini             ret = 1;
64269e0a03cSPaolo Bonzini             break;
64369e0a03cSPaolo Bonzini         }
64469e0a03cSPaolo Bonzini         case EXIT_REASON_TASK_SWITCH: {
645b533450eSAlexander Graf             uint64_t vinfo = rvmcs(cpu->hvf->fd, VMCS_IDT_VECTORING_INFO);
64669e0a03cSPaolo Bonzini             x68_segment_selector sel = {.sel = exit_qual & 0xffff};
64769e0a03cSPaolo Bonzini             vmx_handle_task_switch(cpu, sel, (exit_qual >> 30) & 0x3,
64869e0a03cSPaolo Bonzini              vinfo & VMCS_INTR_VALID, vinfo & VECTORING_INFO_VECTOR_MASK, vinfo
64969e0a03cSPaolo Bonzini              & VMCS_INTR_T_MASK);
65069e0a03cSPaolo Bonzini             break;
65169e0a03cSPaolo Bonzini         }
65269e0a03cSPaolo Bonzini         case EXIT_REASON_TRIPLE_FAULT: {
65369e0a03cSPaolo Bonzini             qemu_system_reset_request(SHUTDOWN_CAUSE_GUEST_RESET);
65469e0a03cSPaolo Bonzini             ret = EXCP_INTERRUPT;
65569e0a03cSPaolo Bonzini             break;
65669e0a03cSPaolo Bonzini         }
65769e0a03cSPaolo Bonzini         case EXIT_REASON_RDPMC:
658b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_RAX, 0);
659b533450eSAlexander Graf             wreg(cpu->hvf->fd, HV_X86_RDX, 0);
66069e0a03cSPaolo Bonzini             macvm_set_rip(cpu, rip + ins_len);
66169e0a03cSPaolo Bonzini             break;
66269e0a03cSPaolo Bonzini         case VMX_REASON_VMCALL:
663fd13f23bSLiran Alon             env->exception_nr = EXCP0D_GPF;
664fd13f23bSLiran Alon             env->exception_injected = 1;
66569e0a03cSPaolo Bonzini             env->has_error_code = true;
66669e0a03cSPaolo Bonzini             env->error_code = 0;
66769e0a03cSPaolo Bonzini             break;
66869e0a03cSPaolo Bonzini         default:
6692d9178d9SLaurent Vivier             error_report("%llx: unhandled exit %llx", rip, exit_reason);
67069e0a03cSPaolo Bonzini         }
67169e0a03cSPaolo Bonzini     } while (ret == 0);
67269e0a03cSPaolo Bonzini 
67369e0a03cSPaolo Bonzini     return ret;
67469e0a03cSPaolo Bonzini }
675