xref: /openbmc/qemu/tests/qtest/boot-sector.c (revision 1d76437b45ab9982307b95d325d627f7b6f06088)
1 /*
2  * QEMU boot sector testing helpers.
3  *
4  * Copyright (c) 2016 Red Hat Inc.
5  *
6  * Authors:
7  *  Michael S. Tsirkin <mst@redhat.com>
8  *  Victor Kaplansky <victork@redhat.com>
9  *
10  * This work is licensed under the terms of the GNU GPL, version 2 or later.
11  * See the COPYING file in the top-level directory.
12  */
13 #include "qemu/osdep.h"
14 #include "boot-sector.h"
15 #include "qemu-common.h"
16 #include "libqos/libqtest.h"
17 
18 #define LOW(x) ((x) & 0xff)
19 #define HIGH(x) ((x) >> 8)
20 
21 #define SIGNATURE 0xdead
22 #define SIGNATURE_OFFSET 0x10
23 #define BOOT_SECTOR_ADDRESS 0x7c00
24 #define SIGNATURE_ADDR (BOOT_SECTOR_ADDRESS + SIGNATURE_OFFSET)
25 
26 /* x86 boot sector code: write SIGNATURE into memory,
27  * then halt.
28  */
29 static uint8_t x86_boot_sector[512] = {
30     /* The first sector will be placed at RAM address 00007C00, and
31      * the BIOS transfers control to 00007C00
32      */
33 
34     /* Data Segment register should be initialized, since pxe
35      * boot loader can leave it dirty.
36      */
37 
38     /* 7c00: move $0000,%ax */
39     [0x00] = 0xb8,
40     [0x01] = 0x00,
41     [0x02] = 0x00,
42     /* 7c03: move %ax,%ds */
43     [0x03] = 0x8e,
44     [0x04] = 0xd8,
45 
46     /* 7c05: mov $0xdead,%ax */
47     [0x05] = 0xb8,
48     [0x06] = LOW(SIGNATURE),
49     [0x07] = HIGH(SIGNATURE),
50     /* 7c08:  mov %ax,0x7c10 */
51     [0x08] = 0xa3,
52     [0x09] = LOW(SIGNATURE_ADDR),
53     [0x0a] = HIGH(SIGNATURE_ADDR),
54 
55     /* 7c0b cli */
56     [0x0b] = 0xfa,
57     /* 7c0c: hlt */
58     [0x0c] = 0xf4,
59     /* 7c0e: jmp 0x7c07=0x7c0f-3 */
60     [0x0d] = 0xeb,
61     [0x0e] = LOW(-3),
62     /* We mov 0xdead here: set value to make debugging easier */
63     [SIGNATURE_OFFSET] = LOW(0xface),
64     [SIGNATURE_OFFSET + 1] = HIGH(0xface),
65     /* End of boot sector marker */
66     [0x1FE] = 0x55,
67     [0x1FF] = 0xAA,
68 };
69 
70 /* For s390x, use a mini "kernel" with the appropriate signature */
71 static const uint8_t s390x_psw_and_magic[] = {
72     0x00, 0x08, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00,  /* Program status word  */
73     0x02, 0x00, 0x00, 0x18, 0x60, 0x00, 0x00, 0x50,  /* Magic:               */
74     0x02, 0x00, 0x00, 0x68, 0x60, 0x00, 0x00, 0x50,  /* see linux_s390_magic */
75     0x40, 0x40, 0x40, 0x40, 0x40, 0x40, 0x40, 0x40   /* in the s390-ccw bios */
76 };
77 static const uint8_t s390x_code[] = {
78     0xa7, 0xf4, 0x00, 0x08,                                /* j 0x10010 */
79     0x00, 0x00, 0x00, 0x00,
80     'S', '3', '9', '0',
81     'E', 'P', 0x00, 0x01,
82     0xa7, 0x39, HIGH(SIGNATURE_ADDR), LOW(SIGNATURE_ADDR), /* lghi r3,0x7c10 */
83     0xa7, 0x48, LOW(SIGNATURE), HIGH(SIGNATURE),           /* lhi r4,0xadde */
84     0x40, 0x40, 0x30, 0x00,                                /* sth r4,0(r3) */
85     0xa7, 0xf4, 0xff, 0xfa                                 /* j 0x10010 */
86 };
87 
88 /* Create boot disk file.  */
89 int boot_sector_init(char *fname)
90 {
91     int fd, ret;
92     size_t len;
93     char *boot_code;
94     const char *arch = qtest_get_arch();
95 
96     fd = mkstemp(fname);
97     if (fd < 0) {
98         fprintf(stderr, "Couldn't open \"%s\": %s", fname, strerror(errno));
99         return 1;
100     }
101 
102     if (g_str_equal(arch, "i386") || g_str_equal(arch, "x86_64")) {
103         /* Q35 requires a minimum 0x7e000 bytes disk (bug or feature?) */
104         len = MAX(0x7e000, sizeof(x86_boot_sector));
105         boot_code = g_malloc0(len);
106         memcpy(boot_code, x86_boot_sector, sizeof(x86_boot_sector));
107     } else if (g_str_equal(arch, "ppc64")) {
108         /* For Open Firmware based system, use a Forth script */
109         boot_code = g_strdup_printf("\\ Bootscript\n%x %x c! %x %x c!\n",
110                                     LOW(SIGNATURE), SIGNATURE_ADDR,
111                                     HIGH(SIGNATURE), SIGNATURE_ADDR + 1);
112         len = strlen(boot_code);
113     } else if (g_str_equal(arch, "s390x")) {
114         len = 0x10000 + sizeof(s390x_code);
115         boot_code = g_malloc0(len);
116         memcpy(boot_code, s390x_psw_and_magic, sizeof(s390x_psw_and_magic));
117         memcpy(&boot_code[0x10000], s390x_code, sizeof(s390x_code));
118     } else {
119         g_assert_not_reached();
120     }
121 
122     ret = write(fd, boot_code, len);
123     close(fd);
124 
125     g_free(boot_code);
126 
127     if (ret != len) {
128         fprintf(stderr, "Could not write \"%s\"", fname);
129         return 1;
130     }
131 
132     return 0;
133 }
134 
135 /* Loop until signature in memory is OK.  */
136 void boot_sector_test(QTestState *qts)
137 {
138     uint8_t signature_low;
139     uint8_t signature_high;
140     uint16_t signature;
141     QDict *qrsp, *qret;
142     int i;
143 
144     /* Wait at most 600 seconds (test is slow with TCI and --enable-debug) */
145 #define TEST_DELAY (1 * G_USEC_PER_SEC / 10)
146 #define TEST_CYCLES MAX((600 * G_USEC_PER_SEC / TEST_DELAY), 1)
147 
148     /* Poll until code has run and modified memory.  Once it has we know BIOS
149      * initialization is done.  TODO: check that IP reached the halt
150      * instruction.
151      */
152     for (i = 0; i < TEST_CYCLES; ++i) {
153         signature_low = qtest_readb(qts, SIGNATURE_ADDR);
154         signature_high = qtest_readb(qts, SIGNATURE_ADDR + 1);
155         signature = (signature_high << 8) | signature_low;
156         if (signature == SIGNATURE) {
157             break;
158         }
159 
160         /* check that guest is still in "running" state and did not panic */
161         qrsp = qtest_qmp(qts, "{ 'execute': 'query-status' }");
162         qret = qdict_get_qdict(qrsp, "return");
163         g_assert_nonnull(qret);
164         g_assert_cmpstr(qdict_get_try_str(qret, "status"), ==, "running");
165         qobject_unref(qrsp);
166 
167         g_usleep(TEST_DELAY);
168     }
169 
170     g_assert_cmphex(signature, ==, SIGNATURE);
171 }
172 
173 /* unlink boot disk file.  */
174 void boot_sector_cleanup(const char *fname)
175 {
176     unlink(fname);
177 }
178