xref: /illumos-gate/usr/src/uts/intel/io/vmm/sys/vmm_kernel.h (revision 7d10cd4ddf12f982d3bc7edcd01cc8b8d1dcc464)
1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3  *
4  * Copyright (c) 2011 NetApp, Inc.
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY NETAPP, INC ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED.  IN NO EVENT SHALL NETAPP, INC OR CONTRIBUTORS BE LIABLE
20  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  *
28  * $FreeBSD$
29  */
30 /*
31  * This file and its contents are supplied under the terms of the
32  * Common Development and Distribution License ("CDDL"), version 1.0.
33  * You may only use this file in accordance with the terms of version
34  * 1.0 of the CDDL.
35  *
36  * A full copy of the text of the CDDL should have accompanied this
37  * source.  A copy of the CDDL is also available via the Internet at
38  * http://www.illumos.org/license/CDDL.
39  *
40  * Copyright 2015 Pluribus Networks Inc.
41  * Copyright 2019 Joyent, Inc.
42  * Copyright 2022 Oxide Computer Company
43  * Copyright 2021 OmniOS Community Edition (OmniOSce) Association.
44  */
45 
46 #ifndef _VMM_KERNEL_H_
47 #define	_VMM_KERNEL_H_
48 
49 #include <sys/sdt.h>
50 #include <x86/segments.h>
51 #include <sys/vmm.h>
52 #include <sys/vmm_data.h>
53 #include <sys/linker_set.h>
54 
55 SDT_PROVIDER_DECLARE(vmm);
56 
57 struct vm;
58 struct vm_exception;
59 struct seg_desc;
60 struct vm_exit;
61 struct vie;
62 struct vm_run;
63 struct vhpet;
64 struct vioapic;
65 struct vlapic;
66 struct vmspace;
67 struct vm_client;
68 struct vm_object;
69 struct vm_guest_paging;
70 struct vmm_data_req;
71 
72 typedef int	(*vmm_init_func_t)(void);
73 typedef int	(*vmm_cleanup_func_t)(void);
74 typedef void	(*vmm_resume_func_t)(void);
75 typedef void *	(*vmi_init_func_t)(struct vm *vm);
76 typedef int	(*vmi_run_func_t)(void *vmi, int vcpu, uint64_t rip);
77 typedef void	(*vmi_cleanup_func_t)(void *vmi);
78 typedef int	(*vmi_get_register_t)(void *vmi, int vcpu, int num,
79     uint64_t *retval);
80 typedef int	(*vmi_set_register_t)(void *vmi, int vcpu, int num,
81     uint64_t val);
82 typedef int	(*vmi_get_desc_t)(void *vmi, int vcpu, int num,
83     struct seg_desc *desc);
84 typedef int	(*vmi_set_desc_t)(void *vmi, int vcpu, int num,
85     const struct seg_desc *desc);
86 typedef int	(*vmi_get_cap_t)(void *vmi, int vcpu, int num, int *retval);
87 typedef int	(*vmi_set_cap_t)(void *vmi, int vcpu, int num, int val);
88 typedef struct vlapic *(*vmi_vlapic_init)(void *vmi, int vcpu);
89 typedef void	(*vmi_vlapic_cleanup)(void *vmi, struct vlapic *vlapic);
90 typedef void	(*vmi_savectx)(void *vmi, int vcpu);
91 typedef void	(*vmi_restorectx)(void *vmi, int vcpu);
92 
93 typedef int	(*vmi_get_msr_t)(void *vmi, int vcpu, uint32_t msr,
94     uint64_t *valp);
95 typedef int	(*vmi_set_msr_t)(void *vmi, int vcpu, uint32_t msr,
96     uint64_t val);
97 
98 struct vmm_ops {
99 	vmm_init_func_t		init;		/* module wide initialization */
100 	vmm_cleanup_func_t	cleanup;
101 	vmm_resume_func_t	resume;
102 
103 	vmi_init_func_t		vminit;		/* vm-specific initialization */
104 	vmi_run_func_t		vmrun;
105 	vmi_cleanup_func_t	vmcleanup;
106 	vmi_get_register_t	vmgetreg;
107 	vmi_set_register_t	vmsetreg;
108 	vmi_get_desc_t		vmgetdesc;
109 	vmi_set_desc_t		vmsetdesc;
110 	vmi_get_cap_t		vmgetcap;
111 	vmi_set_cap_t		vmsetcap;
112 	vmi_vlapic_init		vlapic_init;
113 	vmi_vlapic_cleanup	vlapic_cleanup;
114 
115 	vmi_savectx		vmsavectx;
116 	vmi_restorectx		vmrestorectx;
117 
118 	vmi_get_msr_t		vmgetmsr;
119 	vmi_set_msr_t		vmsetmsr;
120 };
121 
122 extern struct vmm_ops vmm_ops_intel;
123 extern struct vmm_ops vmm_ops_amd;
124 
125 int vm_create(uint64_t flags, struct vm **retvm);
126 void vm_destroy(struct vm *vm);
127 int vm_reinit(struct vm *vm, uint64_t);
128 uint16_t vm_get_maxcpus(struct vm *vm);
129 void vm_get_topology(struct vm *vm, uint16_t *sockets, uint16_t *cores,
130     uint16_t *threads, uint16_t *maxcpus);
131 int vm_set_topology(struct vm *vm, uint16_t sockets, uint16_t cores,
132     uint16_t threads, uint16_t maxcpus);
133 
134 /*
135  * APIs that race against hardware.
136  */
137 void vm_track_dirty_pages(struct vm *, uint64_t, size_t, uint8_t *);
138 
139 /*
140  * APIs that modify the guest memory map require all vcpus to be frozen.
141  */
142 int vm_mmap_memseg(struct vm *vm, vm_paddr_t gpa, int segid, vm_ooffset_t off,
143     size_t len, int prot, int flags);
144 int vm_munmap_memseg(struct vm *vm, vm_paddr_t gpa, size_t len);
145 int vm_alloc_memseg(struct vm *vm, int ident, size_t len, bool sysmem);
146 void vm_free_memseg(struct vm *vm, int ident);
147 int vm_map_mmio(struct vm *vm, vm_paddr_t gpa, size_t len, vm_paddr_t hpa);
148 int vm_unmap_mmio(struct vm *vm, vm_paddr_t gpa, size_t len);
149 int vm_assign_pptdev(struct vm *vm, int pptfd);
150 int vm_unassign_pptdev(struct vm *vm, int pptfd);
151 
152 /*
153  * APIs that inspect the guest memory map require only a *single* vcpu to
154  * be frozen. This acts like a read lock on the guest memory map since any
155  * modification requires *all* vcpus to be frozen.
156  */
157 int vm_mmap_getnext(struct vm *vm, vm_paddr_t *gpa, int *segid,
158     vm_ooffset_t *segoff, size_t *len, int *prot, int *flags);
159 int vm_get_memseg(struct vm *vm, int ident, size_t *len, bool *sysmem,
160     struct vm_object **objptr);
161 vm_paddr_t vmm_sysmem_maxaddr(struct vm *vm);
162 bool vm_mem_allocated(struct vm *vm, int vcpuid, vm_paddr_t gpa);
163 
164 int vm_get_register(struct vm *vm, int vcpu, int reg, uint64_t *retval);
165 int vm_set_register(struct vm *vm, int vcpu, int reg, uint64_t val);
166 int vm_get_seg_desc(struct vm *vm, int vcpu, int reg,
167     struct seg_desc *ret_desc);
168 int vm_set_seg_desc(struct vm *vm, int vcpu, int reg,
169     const struct seg_desc *desc);
170 int vm_get_run_state(struct vm *vm, int vcpuid, uint32_t *state,
171     uint8_t *sipi_vec);
172 int vm_set_run_state(struct vm *vm, int vcpuid, uint32_t state,
173     uint8_t sipi_vec);
174 int vm_get_fpu(struct vm *vm, int vcpuid, void *buf, size_t len);
175 int vm_set_fpu(struct vm *vm, int vcpuid, void *buf, size_t len);
176 int vm_run(struct vm *vm, int vcpuid, const struct vm_entry *);
177 int vm_suspend(struct vm *vm, enum vm_suspend_how how);
178 int vm_inject_nmi(struct vm *vm, int vcpu);
179 bool vm_nmi_pending(struct vm *vm, int vcpuid);
180 void vm_nmi_clear(struct vm *vm, int vcpuid);
181 int vm_inject_extint(struct vm *vm, int vcpu);
182 bool vm_extint_pending(struct vm *vm, int vcpuid);
183 void vm_extint_clear(struct vm *vm, int vcpuid);
184 int vm_inject_init(struct vm *vm, int vcpuid);
185 int vm_inject_sipi(struct vm *vm, int vcpuid, uint8_t vec);
186 struct vlapic *vm_lapic(struct vm *vm, int cpu);
187 struct vioapic *vm_ioapic(struct vm *vm);
188 struct vhpet *vm_hpet(struct vm *vm);
189 int vm_get_capability(struct vm *vm, int vcpu, int type, int *val);
190 int vm_set_capability(struct vm *vm, int vcpu, int type, int val);
191 int vm_get_x2apic_state(struct vm *vm, int vcpu, enum x2apic_state *state);
192 int vm_set_x2apic_state(struct vm *vm, int vcpu, enum x2apic_state state);
193 int vm_apicid2vcpuid(struct vm *vm, int apicid);
194 int vm_activate_cpu(struct vm *vm, int vcpu);
195 int vm_suspend_cpu(struct vm *vm, int vcpu);
196 int vm_resume_cpu(struct vm *vm, int vcpu);
197 struct vm_exit *vm_exitinfo(struct vm *vm, int vcpuid);
198 struct vie *vm_vie_ctx(struct vm *vm, int vcpuid);
199 void vm_exit_suspended(struct vm *vm, int vcpuid, uint64_t rip);
200 void vm_exit_debug(struct vm *vm, int vcpuid, uint64_t rip);
201 void vm_exit_astpending(struct vm *vm, int vcpuid, uint64_t rip);
202 void vm_exit_reqidle(struct vm *vm, int vcpuid, uint64_t rip);
203 void vm_exit_run_state(struct vm *vm, int vcpuid, uint64_t rip);
204 int vm_service_mmio_read(struct vm *vm, int cpuid, uint64_t gpa, uint64_t *rval,
205     int rsize);
206 int vm_service_mmio_write(struct vm *vm, int cpuid, uint64_t gpa, uint64_t wval,
207     int wsize);
208 
209 #ifdef _SYS__CPUSET_H_
210 cpuset_t vm_active_cpus(struct vm *vm);
211 cpuset_t vm_debug_cpus(struct vm *vm);
212 cpuset_t vm_suspended_cpus(struct vm *vm);
213 #endif	/* _SYS__CPUSET_H_ */
214 
215 bool vcpu_entry_bailout_checks(struct vm *vm, int vcpuid, uint64_t rip);
216 bool vcpu_run_state_pending(struct vm *vm, int vcpuid);
217 int vcpu_arch_reset(struct vm *vm, int vcpuid, bool init_only);
218 
219 /*
220  * Return true if device indicated by bus/slot/func is supposed to be a
221  * pci passthrough device.
222  *
223  * Return false otherwise.
224  */
225 bool vmm_is_pptdev(int bus, int slot, int func);
226 
227 void *vm_iommu_domain(struct vm *vm);
228 
229 enum vcpu_state {
230 	VCPU_IDLE,
231 	VCPU_FROZEN,
232 	VCPU_RUNNING,
233 	VCPU_SLEEPING,
234 };
235 
236 int vcpu_set_state(struct vm *vm, int vcpu, enum vcpu_state state,
237     bool from_idle);
238 enum vcpu_state vcpu_get_state(struct vm *vm, int vcpu, int *hostcpu);
239 void vcpu_block_run(struct vm *, int);
240 void vcpu_unblock_run(struct vm *, int);
241 
242 uint64_t vcpu_tsc_offset(struct vm *vm, int vcpuid, bool phys_adj);
243 hrtime_t vm_normalize_hrtime(struct vm *, hrtime_t);
244 hrtime_t vm_denormalize_hrtime(struct vm *, hrtime_t);
245 
246 static __inline bool
247 vcpu_is_running(struct vm *vm, int vcpu, int *hostcpu)
248 {
249 	return (vcpu_get_state(vm, vcpu, hostcpu) == VCPU_RUNNING);
250 }
251 
252 #ifdef _SYS_THREAD_H
253 static __inline int
254 vcpu_should_yield(struct vm *vm, int vcpu)
255 {
256 
257 	if (curthread->t_astflag)
258 		return (1);
259 	else if (CPU->cpu_runrun)
260 		return (1);
261 	else
262 		return (0);
263 }
264 #endif /* _SYS_THREAD_H */
265 
266 typedef enum vcpu_notify {
267 	VCPU_NOTIFY_NONE,
268 	VCPU_NOTIFY_APIC,	/* Posted intr notification (if possible) */
269 	VCPU_NOTIFY_EXIT,	/* IPI to cause VM exit */
270 } vcpu_notify_t;
271 
272 void *vcpu_stats(struct vm *vm, int vcpu);
273 void vcpu_notify_event(struct vm *vm, int vcpuid);
274 void vcpu_notify_event_type(struct vm *vm, int vcpuid, vcpu_notify_t);
275 struct vmspace *vm_get_vmspace(struct vm *vm);
276 struct vm_client *vm_get_vmclient(struct vm *vm, int vcpuid);
277 struct vatpic *vm_atpic(struct vm *vm);
278 struct vatpit *vm_atpit(struct vm *vm);
279 struct vpmtmr *vm_pmtmr(struct vm *vm);
280 struct vrtc *vm_rtc(struct vm *vm);
281 
282 /*
283  * Inject exception 'vector' into the guest vcpu. This function returns 0 on
284  * success and non-zero on failure.
285  *
286  * Wrapper functions like 'vm_inject_gp()' should be preferred to calling
287  * this function directly because they enforce the trap-like or fault-like
288  * behavior of an exception.
289  *
290  * This function should only be called in the context of the thread that is
291  * executing this vcpu.
292  */
293 int vm_inject_exception(struct vm *vm, int vcpuid, uint8_t vector,
294     bool err_valid, uint32_t errcode, bool restart_instruction);
295 
296 /*
297  * This function is called after a VM-exit that occurred during exception or
298  * interrupt delivery through the IDT. The format of 'intinfo' is described
299  * in Figure 15-1, "EXITINTINFO for All Intercepts", APM, Vol 2.
300  *
301  * If a VM-exit handler completes the event delivery successfully then it
302  * should call vm_exit_intinfo() to extinguish the pending event. For e.g.,
303  * if the task switch emulation is triggered via a task gate then it should
304  * call this function with 'intinfo=0' to indicate that the external event
305  * is not pending anymore.
306  *
307  * Return value is 0 on success and non-zero on failure.
308  */
309 int vm_exit_intinfo(struct vm *vm, int vcpuid, uint64_t intinfo);
310 
311 /*
312  * This function is called before every VM-entry to retrieve a pending
313  * event that should be injected into the guest. This function combines
314  * nested events into a double or triple fault.
315  *
316  * Returns false if there are no events that need to be injected into the guest.
317  */
318 bool vm_entry_intinfo(struct vm *vm, int vcpuid, uint64_t *info);
319 
320 int vm_get_intinfo(struct vm *vm, int vcpuid, uint64_t *info1, uint64_t *info2);
321 
322 enum vm_reg_name vm_segment_name(int seg_encoding);
323 
324 struct vm_copyinfo {
325 	uint64_t	gpa;
326 	size_t		len;
327 	int		prot;
328 	void		*hva;
329 	void		*cookie;
330 };
331 
332 /*
333  * Set up 'copyinfo[]' to copy to/from guest linear address space starting
334  * at 'gla' and 'len' bytes long. The 'prot' should be set to PROT_READ for
335  * a copyin or PROT_WRITE for a copyout.
336  *
337  * retval	is_fault	Interpretation
338  *   0		   0		Success
339  *   0		   1		An exception was injected into the guest
340  * EFAULT	  N/A		Unrecoverable error
341  *
342  * The 'copyinfo[]' can be passed to 'vm_copyin()' or 'vm_copyout()' only if
343  * the return value is 0. The 'copyinfo[]' resources should be freed by calling
344  * 'vm_copy_teardown()' after the copy is done.
345  */
346 int vm_copy_setup(struct vm *vm, int vcpuid, struct vm_guest_paging *paging,
347     uint64_t gla, size_t len, int prot, struct vm_copyinfo *copyinfo,
348     uint_t num_copyinfo, int *is_fault);
349 void vm_copy_teardown(struct vm *vm, int vcpuid, struct vm_copyinfo *copyinfo,
350     uint_t num_copyinfo);
351 void vm_copyin(struct vm *vm, int vcpuid, struct vm_copyinfo *copyinfo,
352     void *kaddr, size_t len);
353 void vm_copyout(struct vm *vm, int vcpuid, const void *kaddr,
354     struct vm_copyinfo *copyinfo, size_t len);
355 
356 int vcpu_trace_exceptions(struct vm *vm, int vcpuid);
357 
358 void vm_inject_ud(struct vm *vm, int vcpuid);
359 void vm_inject_gp(struct vm *vm, int vcpuid);
360 void vm_inject_ac(struct vm *vm, int vcpuid, uint32_t errcode);
361 void vm_inject_ss(struct vm *vm, int vcpuid, uint32_t errcode);
362 void vm_inject_pf(struct vm *vm, int vcpuid, uint32_t errcode, uint64_t cr2);
363 
364 /*
365  * Both SVM and VMX have complex logic for injecting events such as exceptions
366  * or interrupts into the guest.  Within those two backends, the progress of
367  * event injection is tracked by event_inject_state, hopefully making it easier
368  * to reason about.
369  */
370 enum event_inject_state {
371 	EIS_CAN_INJECT	= 0, /* exception/interrupt can be injected */
372 	EIS_EV_EXISTING	= 1, /* blocked by existing event */
373 	EIS_EV_INJECTED	= 2, /* blocked by injected event */
374 	EIS_GI_BLOCK	= 3, /* blocked by guest interruptability */
375 
376 	/*
377 	 * Flag to request an immediate exit from VM context after event
378 	 * injection in order to perform more processing
379 	 */
380 	EIS_REQ_EXIT	= (1 << 15),
381 };
382 
383 /* Possible result codes for MSR access emulation */
384 typedef enum vm_msr_result {
385 	VMR_OK		= 0, /* succesfully emulated */
386 	VMR_GP		= 1, /* #GP should be injected */
387 	VMR_UNHANLDED	= 2, /* handle in userspace, kernel cannot emulate */
388 } vm_msr_result_t;
389 
390 enum vm_cpuid_capability {
391 	VCC_NONE,
392 	VCC_NO_EXECUTE,
393 	VCC_FFXSR,
394 	VCC_TCE,
395 	VCC_LAST
396 };
397 
398 int x86_emulate_cpuid(struct vm *, int, uint64_t *, uint64_t *, uint64_t *,
399     uint64_t *);
400 bool vm_cpuid_capability(struct vm *, int, enum vm_cpuid_capability);
401 bool validate_guest_xcr0(uint64_t, uint64_t);
402 
403 void vmm_sol_glue_init(void);
404 void vmm_sol_glue_cleanup(void);
405 
406 void *vmm_contig_alloc(size_t);
407 void vmm_contig_free(void *, size_t);
408 
409 int vmm_mod_load(void);
410 int vmm_mod_unload(void);
411 
412 bool vmm_check_iommu(void);
413 
414 void vmm_call_trap(uint64_t);
415 
416 /*
417  * Because of tangled headers, this is not exposed directly via the vmm_drv
418  * interface, but rather mirrored as vmm_drv_iop_cb_t in vmm_drv.h.
419  */
420 typedef int (*ioport_handler_t)(void *, bool, uint16_t, uint8_t, uint32_t *);
421 
422 int vm_ioport_access(struct vm *vm, int vcpuid, bool in, uint16_t port,
423     uint8_t bytes, uint32_t *val);
424 
425 int vm_ioport_attach(struct vm *vm, uint16_t port, ioport_handler_t func,
426     void *arg, void **cookie);
427 int vm_ioport_detach(struct vm *vm, void **cookie, ioport_handler_t *old_func,
428     void **old_arg);
429 
430 int vm_ioport_hook(struct vm *, uint16_t, ioport_handler_t, void *, void **);
431 void vm_ioport_unhook(struct vm *, void **);
432 
433 enum vcpu_ustate {
434 	VU_INIT = 0,	/* initialized but has not yet attempted to run */
435 	VU_RUN,		/* running in guest context */
436 	VU_IDLE,	/* idle (HLTed, wait-for-SIPI, etc) */
437 	VU_EMU_KERN,	/* emulation performed in-kernel */
438 	VU_EMU_USER,	/* emulation performed in userspace */
439 	VU_SCHED,	/* off-cpu for interrupt, preempt, lock contention */
440 	VU_MAX
441 };
442 
443 void vcpu_ustate_change(struct vm *, int, enum vcpu_ustate);
444 
445 typedef struct vmm_kstats {
446 	kstat_named_t	vk_name;
447 } vmm_kstats_t;
448 
449 typedef struct vmm_vcpu_kstats {
450 	kstat_named_t	vvk_vcpu;
451 	kstat_named_t	vvk_time_init;
452 	kstat_named_t	vvk_time_run;
453 	kstat_named_t	vvk_time_idle;
454 	kstat_named_t	vvk_time_emu_kern;
455 	kstat_named_t	vvk_time_emu_user;
456 	kstat_named_t	vvk_time_sched;
457 } vmm_vcpu_kstats_t;
458 
459 #define	VMM_KSTAT_CLASS	"misc"
460 
461 int vmm_kstat_update_vcpu(struct kstat *, int);
462 
463 typedef struct vmm_data_req {
464 	uint16_t	vdr_class;
465 	uint16_t	vdr_version;
466 	uint32_t	vdr_flags;
467 	uint32_t	vdr_len;
468 	void		*vdr_data;
469 	uint32_t	*vdr_result_len;
470 } vmm_data_req_t;
471 typedef struct vmm_data_req vmm_data_req_t;
472 
473 typedef int (*vmm_data_writef_t)(void *, const vmm_data_req_t *);
474 typedef int (*vmm_data_readf_t)(void *, const vmm_data_req_t *);
475 
476 typedef struct vmm_data_version_entry {
477 	uint16_t		vdve_class;
478 	uint16_t		vdve_version;
479 	uint16_t		vdve_len_expect;
480 	uint16_t		vdve_len_per_item;
481 	vmm_data_readf_t	vdve_readf;
482 	vmm_data_writef_t	vdve_writef;
483 } vmm_data_version_entry_t;
484 
485 #define	VMM_DATA_VERSION(sym)	SET_ENTRY(vmm_data_version_entries, sym)
486 
487 int vmm_data_read(struct vm *, int, const vmm_data_req_t *);
488 int vmm_data_write(struct vm *, int, const vmm_data_req_t *);
489 
490 #endif /* _VMM_KERNEL_H_ */
491