2 * gtests/tests/vmx_tsc_adjust_test.c
4 * Copyright (C) 2018, Google LLC.
6 * This work is licensed under the terms of the GNU GPL, version 2.
11 * According to the SDM, "if an execution of WRMSR to the
12 * IA32_TIME_STAMP_COUNTER MSR adds (or subtracts) value X from the TSC,
13 * the logical processor also adds (or subtracts) value X from the
14 * IA32_TSC_ADJUST MSR.
16 * Note that when L1 doesn't intercept writes to IA32_TSC, a
17 * WRMSR(IA32_TSC) from L2 sets L1's TSC value, not L2's perceived TSC
20 * This test verifies that this unusual case is handled correctly.
23 #include "test_util.h"
29 #include <sys/ioctl.h>
31 #include "../kselftest.h"
33 #ifndef MSR_IA32_TSC_ADJUST
34 #define MSR_IA32_TSC_ADJUST 0x3b
37 #define PAGE_SIZE 4096
40 #define TSC_ADJUST_VALUE (1ll << 32)
41 #define TSC_OFFSET_VALUE -(1ll << 48)
57 struct kvm_single_msr {
58 struct kvm_msrs header;
59 struct kvm_msr_entry entry;
60 } __attribute__((packed));
62 /* The virtual machine object. */
63 static struct kvm_vm *vm;
65 #define exit_to_l0(_port, _arg) do_exit_to_l0(_port, (unsigned long) (_arg))
66 static void do_exit_to_l0(uint16_t port, unsigned long arg)
68 __asm__ __volatile__("in %[port], %%al"
70 : [port]"d"(port), "D"(arg)
75 #define GUEST_ASSERT(_condition) do { \
77 exit_to_l0(PORT_ABORT, "Failed guest assert: " #_condition); \
80 static void check_ia32_tsc_adjust(int64_t max)
84 adjust = rdmsr(MSR_IA32_TSC_ADJUST);
85 exit_to_l0(PORT_REPORT, adjust);
86 GUEST_ASSERT(adjust <= max);
89 static void l2_guest_code(void)
91 uint64_t l1_tsc = rdtsc() - TSC_OFFSET_VALUE;
93 wrmsr(MSR_IA32_TSC, l1_tsc - TSC_ADJUST_VALUE);
94 check_ia32_tsc_adjust(-2 * TSC_ADJUST_VALUE);
97 __asm__ __volatile__("vmcall");
100 static void l1_guest_code(struct vmx_pages *vmx_pages)
102 #define L2_GUEST_STACK_SIZE 64
103 unsigned long l2_guest_stack[L2_GUEST_STACK_SIZE];
107 GUEST_ASSERT(rdtsc() < TSC_ADJUST_VALUE);
108 wrmsr(MSR_IA32_TSC, rdtsc() - TSC_ADJUST_VALUE);
109 check_ia32_tsc_adjust(-1 * TSC_ADJUST_VALUE);
111 GUEST_ASSERT(prepare_for_vmx_operation(vmx_pages));
113 /* Prepare the VMCS for L2 execution. */
114 prepare_vmcs(vmx_pages, l2_guest_code,
115 &l2_guest_stack[L2_GUEST_STACK_SIZE]);
116 control = vmreadz(CPU_BASED_VM_EXEC_CONTROL);
117 control |= CPU_BASED_USE_MSR_BITMAPS | CPU_BASED_USE_TSC_OFFSETING;
118 vmwrite(CPU_BASED_VM_EXEC_CONTROL, control);
119 vmwrite(TSC_OFFSET, TSC_OFFSET_VALUE);
121 /* Jump into L2. First, test failure to load guest CR3. */
122 save_cr3 = vmreadz(GUEST_CR3);
123 vmwrite(GUEST_CR3, -1ull);
124 GUEST_ASSERT(!vmlaunch());
125 GUEST_ASSERT(vmreadz(VM_EXIT_REASON) ==
126 (EXIT_REASON_FAILED_VMENTRY | EXIT_REASON_INVALID_STATE));
127 check_ia32_tsc_adjust(-1 * TSC_ADJUST_VALUE);
128 vmwrite(GUEST_CR3, save_cr3);
130 GUEST_ASSERT(!vmlaunch());
131 GUEST_ASSERT(vmreadz(VM_EXIT_REASON) == EXIT_REASON_VMCALL);
133 check_ia32_tsc_adjust(-2 * TSC_ADJUST_VALUE);
135 exit_to_l0(PORT_DONE, 0);
138 void report(int64_t val)
140 printf("IA32_TSC_ADJUST is %ld (%lld * TSC_ADJUST_VALUE + %lld).\n",
141 val, val / TSC_ADJUST_VALUE, val % TSC_ADJUST_VALUE);
144 int main(int argc, char *argv[])
146 struct vmx_pages *vmx_pages;
147 vm_vaddr_t vmx_pages_gva;
148 struct kvm_cpuid_entry2 *entry = kvm_get_supported_cpuid_entry(1);
150 if (!(entry->ecx & CPUID_VMX)) {
151 fprintf(stderr, "nested VMX not enabled, skipping test\n");
155 vm = vm_create_default(VCPU_ID, (void *) l1_guest_code);
156 vcpu_set_cpuid(vm, VCPU_ID, kvm_get_supported_cpuid());
158 /* Allocate VMX pages and shared descriptors (vmx_pages). */
159 vmx_pages = vcpu_alloc_vmx(vm, &vmx_pages_gva);
160 vcpu_args_set(vm, VCPU_ID, 1, vmx_pages_gva);
163 volatile struct kvm_run *run = vcpu_state(vm, VCPU_ID);
164 struct kvm_regs regs;
166 vcpu_run(vm, VCPU_ID);
167 vcpu_regs_get(vm, VCPU_ID, ®s);
168 TEST_ASSERT(run->exit_reason == KVM_EXIT_IO,
169 "Got exit_reason other than KVM_EXIT_IO: %u (%s), rip=%lx\n",
171 exit_reason_str(run->exit_reason), regs.rip);
173 switch (run->io.port) {
175 TEST_ASSERT(false, "%s", (const char *) regs.rdi);
183 TEST_ASSERT(false, "Unknown port 0x%x.", run->io.port);