Skip to content

Instantly share code, notes, and snippets.

@ntddk
Created March 18, 2015 18:04
Show Gist options
  • Select an option

  • Save ntddk/e199b7586f3fe42a2df0 to your computer and use it in GitHub Desktop.

Select an option

Save ntddk/e199b7586f3fe42a2df0 to your computer and use it in GitHub Desktop.
pemu のみに存在: .git
diff -ur qemu-1.5.3/.gitignore pemu/.gitignore
--- qemu-1.5.3/.gitignore 2013-08-28 00:05:28.000000000 +0900
+++ pemu/.gitignore 2015-03-19 02:57:47.725691930 +0900
@@ -106,4 +106,7 @@
cscope.*
tags
TAGS
+build
*~
+!xed2/xed2-intel64/lib/libxed.a
+!xed2/xed2-ia32/lib/libxed.a
diff -ur qemu-1.5.3/Makefile pemu/Makefile
--- qemu-1.5.3/Makefile 2013-08-28 00:05:28.000000000 +0900
+++ pemu/Makefile 2015-03-19 02:57:47.725691930 +0900
@@ -115,6 +115,8 @@
ifneq ($(wildcard config-host.mak),)
include $(SRC_PATH)/Makefile.objs
+#jzeng
+#include $(SRC_PATH)/build/elf-parser/Makefile
include $(SRC_PATH)/tests/Makefile
endif
ifeq ($(CONFIG_SMARTCARD_NSS),y)
qemu-1.5.3 のみに存在: README
pemu のみに存在: README.md
pemu のみに存在: \
diff -ur qemu-1.5.3/configure pemu/configure
--- qemu-1.5.3/configure 2013-08-28 00:05:28.000000000 +0900
+++ pemu/configure 2015-03-19 02:57:47.779513528 +0900
@@ -133,6 +133,12 @@
libs_qga=""
debug_info="yes"
+#jzeng
+#mkdir elf-parser
+#cd ./elf-parser
+#../../elf-parser/configure
+#cd -
+
# Don't accept a target_list environment variable.
unset target_list
@@ -1318,7 +1324,7 @@
LDFLAGS="-pie $LDFLAGS"
pie="yes"
if compile_prog "" "-Wl,-z,relro -Wl,-z,now" ; then
- LDFLAGS="-Wl,-z,relro -Wl,-z,now $LDFLAGS"
+ LDFLAGS="-Wl,-z,relro -Wl,-E -Wl,-z,now $LDFLAGS" #jzeng: add -Wl,-E
fi
else
if test "$pie" = "yes"; then
@@ -2595,6 +2601,51 @@
fi
fi
+#jzeng
+
+# xed support
+
+HST=`uname -m`
+if test "$HST" = "x86_64"; then
+ HOST_ARCH=ia32e
+fi
+if test "$HST" = "amd_64"; then
+ HOST_ARCH=ia32e
+fi
+if test "$HST" = "i686"; then
+ HOST_ARCH=ia32
+fi
+if test "$HST" = "x86"; then
+ HOST_ARCH=ia32
+fi
+if test "$HST" = "i386"; then
+ HOST_ARCH=ia32
+fi
+if test "$HST" = "ia64"; then
+ HOST_ARCH=ipf
+fi
+
+TARGET=$HOST_ARCH
+
+#define TARGET_LONG
+if test "$HOST_ARCH" = "ia32e"; then
+ TARGET_LONG=intel64
+fi
+if test "$HOST_ARCH" = "ia32"; then
+ TARGET_LONG=ia32
+fi
+if test "$HOST_ARCH" = "ipf"; then
+ TARGET_LONG=ia64
+fi
+
+#XEDKIT=$source_path/xed2/xed2-intel64
+#XEDLPATH=-L$XEDKIT/lib
+#XEDCFLAG=-I$XEDKIT/include
+
+XEDKIT=$source_path/xed2/xed2-$TARGET_LONG
+XEDLPATH=-L$XEDKIT/lib
+XEDCFLAG=-I$XEDKIT/include
+
#
# Check for xxxat() functions when we are building linux-user
# emulator. This is done because older glibc versions don't
@@ -4066,6 +4117,8 @@
fi
echo "PYTHON=$python" >> $config_host_mak
echo "CC=$cc" >> $config_host_mak
+#jzeng
+echo "CXX=g++" >> $config_host_mak
echo "CC_I386=$cc_i386" >> $config_host_mak
echo "HOST_CC=$host_cc" >> $config_host_mak
echo "OBJCC=$objcc" >> $config_host_mak
@@ -4078,7 +4131,7 @@
echo "LIBTOOL=$libtool" >> $config_host_mak
echo "CFLAGS=$CFLAGS" >> $config_host_mak
echo "QEMU_CFLAGS=$QEMU_CFLAGS" >> $config_host_mak
-echo "QEMU_INCLUDES=$QEMU_INCLUDES" >> $config_host_mak
+echo "QEMU_INCLUDES=$QEMU_INCLUDES $XEDCFLAG" >> $config_host_mak
if test "$sparse" = "yes" ; then
echo "CC := REAL_CC=\"\$(CC)\" cgcc" >> $config_host_mak
echo "HOST_CC := REAL_CC=\"\$(HOST_CC)\" cgcc" >> $config_host_mak
@@ -4091,7 +4144,7 @@
fi
echo "LDFLAGS=$LDFLAGS" >> $config_host_mak
echo "LIBTOOLFLAGS=$LIBTOOLFLAGS" >> $config_host_mak
-echo "LIBS+=$LIBS" >> $config_host_mak
+echo "LIBS+=$LIBS $XEDLPATH -lxed" >> $config_host_mak
echo "LIBS_TOOLS+=$libs_tools" >> $config_host_mak
echo "EXESUF=$EXESUF" >> $config_host_mak
echo "LIBS_QGA+=$libs_qga" >> $config_host_mak
qemu-1.5.3/dtc のみに存在: .git
diff -ur qemu-1.5.3/exec.c pemu/exec.c
--- qemu-1.5.3/exec.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/exec.c 2015-03-19 02:57:47.894845525 +0900
@@ -2637,3 +2637,17 @@
memory_region_is_romd(section->mr));
}
#endif
+
+//jzeng
+uint8_t * get_ram_addr(void)
+{
+ RAMBlock *block, *new_block;
+ QTAILQ_FOREACH(block, &ram_list.blocks, next) {
+ if (block->offset == 0x0) {
+ //printf("get_ram_addr:%x\n", block->host+ram_size);
+ return block->host + ram_size;
+ }
+ }
+ return 0;
+}
+//end
diff -ur qemu-1.5.3/hmp-commands.hx pemu/hmp-commands.hx
--- qemu-1.5.3/hmp-commands.hx 2013-08-28 00:05:28.000000000 +0900
+++ pemu/hmp-commands.hx 2015-03-19 02:57:47.921756323 +0900
@@ -258,6 +258,22 @@
},
STEXI
+@item pemu @var{tag}|@var{id}
+@findex pemu
+Set the whole virtual machine to the snapshot identified by the tag
+@var{tag} or the unique snapshot ID @var{id}.
+ETEXI
+
+ {
+ .name = "pemu",
+ .args_type = "prog:s,plugin:s",
+ .params = "prog,plugin",
+ .help = "start pemu",
+ .mhandler.cmd = do_command,
+
+ },
+
+STEXI
@item logfile @var{filename}
@findex logfile
Output logs to @var{filename}.
diff -ur qemu-1.5.3/hw/i386/pc.c pemu/hw/i386/pc.c
--- qemu-1.5.3/hw/i386/pc.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/hw/i386/pc.c 2015-03-19 02:57:48.079376719 +0900
@@ -1016,6 +1016,9 @@
}
}
+//jzeng
+#define PEMU_EXTRA_MEMORY 0x200000
+//end
void *pc_memory_init(MemoryRegion *system_memory,
const char *kernel_filename,
const char *kernel_cmdline,
@@ -1037,13 +1040,15 @@
* with older qemus that used qemu_ram_alloc().
*/
ram = g_malloc(sizeof(*ram));
+ //jzeng
memory_region_init_ram(ram, "pc.ram",
- below_4g_mem_size + above_4g_mem_size);
+ below_4g_mem_size + above_4g_mem_size + PEMU_EXTRA_MEMORY);
vmstate_register_ram_global(ram);
*ram_memory = ram;
ram_below_4g = g_malloc(sizeof(*ram_below_4g));
memory_region_init_alias(ram_below_4g, "ram-below-4g", ram,
- 0, below_4g_mem_size);
+ 0, below_4g_mem_size + PEMU_EXTRA_MEMORY);
+ //end
memory_region_add_subregion(system_memory, 0, ram_below_4g);
if (above_4g_mem_size > 0) {
ram_above_4g = g_malloc(sizeof(*ram_above_4g));
diff -ur qemu-1.5.3/monitor.c pemu/monitor.c
--- qemu-1.5.3/monitor.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/monitor.c 2015-03-19 02:57:48.571459907 +0900
@@ -2448,6 +2448,56 @@
return fd;
}
+
+//jzeng:
+#include "target-i386/PEMU/pemu.h"
+#include <dlfcn.h>
+static void *handle;
+static pthread_t PEMUThread;
+
+void *do_PEMUThread(void *param)
+{
+ char *error;
+ handle = dlopen(pemu_exec_stats.PEMU_plugin_name, RTLD_NOW);
+ if (0 != (error = dlerror())){
+ fprintf(stderr, "error: %s\n", error);
+ }else{
+ void*(*plugin_main) (void) = dlsym(handle, "main");
+ if (0 != (error = dlerror())) {
+ fprintf(stderr, "error initializing: %s\n", error);
+ }
+ else {
+ int r = (int)plugin_main();
+ fprintf(stdout, "PEMU_start\t%x\t%d\t%x\n", pemu_exec_stats.PEMU_start, r, plugin_main);
+ }
+ }
+}
+void PEMU_start_PEMUThread(void)
+{
+ pthread_create(&PEMUThread, NULL, &do_PEMUThread, (void *) 0);
+}
+
+
+static void do_command(Monitor *mon, const QDict *qdict)
+{
+ const char *pname;
+
+ pname = qdict_get_str(qdict, "prog");
+ strcpy(pemu_exec_stats.PEMU_binary_name, pname);
+
+ pname = qdict_get_str(qdict, "plugin");
+ sprintf(pemu_exec_stats.PEMU_plugin_name, "../../plugins/%s", pname);
+
+ PEMU_init(mon_get_cpu());
+
+ fprintf(stdout, "program: %s\tplugin: %s\n", pemu_exec_stats.PEMU_binary_name,
+ pemu_exec_stats.PEMU_plugin_name);
+
+ pemu_exec_stats.PEMU_start = 1;
+}
+
+
+
/* Please update hmp-commands.hx when adding or changing commands */
static mon_cmd_t info_cmds[] = {
{
pemu のみに存在: myconfig
qemu-1.5.3/pixman のみに存在: .git
pemu のみに存在: plugins
qemu-1.5.3/roms/SLOF のみに存在: FlashingSLOF.pdf
qemu-1.5.3/roms/SLOF/clients/net-snk のみに存在: make.depend
qemu-1.5.3/roms/ipxe/src のみに存在: bin
qemu-1.5.3/roms/ipxe/src/config のみに存在: local
diff -ur qemu-1.5.3/rules.mak pemu/rules.mak
--- qemu-1.5.3/rules.mak 2013-08-28 00:05:28.000000000 +0900
+++ pemu/rules.mak 2015-03-19 02:58:02.980270748 +0900
@@ -10,6 +10,9 @@
%.c:
%.m:
%.mak:
+#jzeng
+%.cpp:
+#end
# Flags for dependency generation
QEMU_DGFLAGS += -MMD -MP -MT $@ -MF $(*D)/$(*F).d
@@ -17,6 +20,10 @@
# Same as -I$(SRC_PATH) -I., but for the nested source/object directories
QEMU_INCLUDES += -I$(<D) -I$(@D)
+#jzeng
+%.o: %.cpp
+ $(call quiet-command,$(CXX) $(QEMU_INCLUDES) $(QEMU_CFLAGS) $(QEMU_DGFLAGS) $(CFLAGS) -std=c++0x -c -o $@ $<," CXX $(TARGET_DIR)$@")
+#end
%.o: %.c
$(call quiet-command,$(CC) $(QEMU_INCLUDES) $(QEMU_CFLAGS) $(QEMU_DGFLAGS) $(CFLAGS) -c -o $@ $<," CC $(TARGET_DIR)$@")
%.o: %.rc
@@ -37,7 +44,7 @@
LINK = $(call quiet-command,\
$(if $(filter %.lo %.la,$^),$(LIBTOOL) --mode=link --tag=CC \
- )$(CC) $(QEMU_CFLAGS) $(CFLAGS) $(LDFLAGS) -o $@ \
+ )$(CXX) $(QEMU_CFLAGS) $(CFLAGS) $(LDFLAGS) -o $@ \
$(sort $(filter %.o, $1)) $(filter-out %.o, $1) \
$(if $(filter %.lo %.la,$^),$(version-lobj-y),$(version-obj-y)) \
$(if $(filter %.lo %.la,$^),$(LIBTOOLFLAGS)) \
@@ -70,7 +77,8 @@
cc-option = $(if $(shell $(CC) $1 $2 -S -o /dev/null -xc /dev/null \
>/dev/null 2>&1 && echo OK), $2, $3)
-VPATH_SUFFIXES = %.c %.h %.S %.m %.mak %.texi %.sh %.rc
+#jzeng
+VPATH_SUFFIXES = %.c %.h %.S %.m %.mak %.texi %.sh %.rc %.cpp
set-vpath = $(if $1,$(foreach PATTERN,$(VPATH_SUFFIXES),$(eval vpath $(PATTERN) $1)))
# find-in-path
qemu-1.5.3 のみに存在: target-alpha
qemu-1.5.3 のみに存在: target-arm
qemu-1.5.3 のみに存在: target-cris
diff -ur qemu-1.5.3/target-i386/Makefile.objs pemu/target-i386/Makefile.objs
--- qemu-1.5.3/target-i386/Makefile.objs 2013-08-28 00:05:28.000000000 +0900
+++ pemu/target-i386/Makefile.objs 2015-03-19 02:58:03.099447144 +0900
@@ -6,3 +6,21 @@
obj-$(CONFIG_NO_KVM) += kvm-stub.o
obj-$(CONFIG_LINUX_USER) += ioport-user.o
obj-$(CONFIG_BSD_USER) += ioport-user.o
+#jzeng
+obj-y += PEMU/pemu_hook_helper.o PEMU/qemu-pemu.o PEMU/pemu.o PEMU/parse_operand.o PEMU/linux.o
+obj-y += PEMU/PIN/pin.o PEMU/PIN/controlling_and_initializing.o
+obj-y += PEMU/PIN/generic_inspection_api.o
+obj-y += PEMU/PIN/inst_instrumentation_api.o
+obj-y += PEMU/PIN/img.o
+obj-y += PEMU/PIN/trace.o
+obj-y += PEMU/PIN/sec.o
+obj-y += PEMU/PIN/rtn.o
+obj-y += PEMU/PIN/sym.o
+obj-y += PEMU/PIN/bbl.o
+obj-y += PEMU/PIN/reg32.o
+obj-y += PEMU/PIN/pin_objs.o
+obj-y += PEMU/PIN/context_manipulation_api.o PEMU/PIN/systemcall_api.o
+obj-y += PEMU/PIN/thread_api.o
+obj-y += PEMU/PIN/pin_qemu.o
+obj-y += PEMU/hashTable.o PEMU/DISAS/disas.o PEMU/DISAS/disas_cache.o
+obj-y += PEMU/INTROSPECT/introspect.o PEMU/INTROSPECT/semaphore_pemu.o PEMU/INTROSPECT/dispsys.o
pemu/target-i386 のみに存在: PEMU
diff -ur qemu-1.5.3/target-i386/cpu.h pemu/target-i386/cpu.h
--- qemu-1.5.3/target-i386/cpu.h 2013-08-28 00:05:28.000000000 +0900
+++ pemu/target-i386/cpu.h 2015-03-19 02:58:13.856145281 +0900
@@ -450,7 +450,7 @@
#define CPUID_EXT2_DE (1 << 2)
#define CPUID_EXT2_PSE (1 << 3)
#define CPUID_EXT2_TSC (1 << 4)
-#define CPUID_EXT2_MSR (1 << 5)
+#define CPUID_EXT2_MSR (1 << 5)
#define CPUID_EXT2_PAE (1 << 6)
#define CPUID_EXT2_MCE (1 << 7)
#define CPUID_EXT2_CX8 (1 << 8)
diff -ur qemu-1.5.3/target-i386/helper.c pemu/target-i386/helper.c
--- qemu-1.5.3/target-i386/helper.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/target-i386/helper.c 2015-03-19 02:58:13.856145281 +0900
@@ -441,8 +441,43 @@
/* XXX: in legacy PAE mode, generate a GPF if reserved bits are set in
the PDPT */
+
+ //jzeng
+#include "PEMU/linux.h"
+#include "PEMU/pemu.h"
+void PEMU_start_PEMUThread(void);
+//yang
+void helper_find_process(target_ulong pc)
+{
+ if(pemu_exec_stats.PEMU_cr3 == 0
+ && pemu_exec_stats.PEMU_start)
+ {
+ if(PEMU_find_process(0)) {
+ PEMU_start_PEMUThread();
+ if(pemu_exec_stats.PEMU_cr3 == cpu_single_env->cr[3])
+ {
+ tb_flush(cpu_single_env);
+ pemu_exec_stats.PEMU_already_flush = 1;
+ pemu_exec_stats.PEMU_int_level = -1;
+ }
+ }
+ }
+}
void cpu_x86_update_cr3(CPUX86State *env, target_ulong new_cr3)
{
+
+ helper_find_process(0);
+ //jzeng.begin
+ if(!pemu_exec_stats.PEMU_already_flush
+ && pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 != 0
+ && pemu_exec_stats.PEMU_cr3 == new_cr3) {
+ tb_flush(env);
+ pemu_exec_stats.PEMU_already_flush = 1;
+ pemu_exec_stats.PEMU_int_level = -1;
+ }
+ //end
+
env->cr[3] = new_cr3;
if (env->cr[0] & CR0_PG_MASK) {
#if defined(DEBUG_MMU)
diff -ur qemu-1.5.3/target-i386/helper.h pemu/target-i386/helper.h
--- qemu-1.5.3/target-i386/helper.h 2013-08-28 00:05:28.000000000 +0900
+++ pemu/target-i386/helper.h 2015-03-19 02:58:13.856145281 +0900
@@ -196,6 +196,26 @@
DEF_HELPER_FLAGS_2(pdep, TCG_CALL_NO_RWG_SE, tl, tl, tl)
DEF_HELPER_FLAGS_2(pext, TCG_CALL_NO_RWG_SE, tl, tl, tl)
+//jzeng
+//DEF_HELPER_0(inst_hook_0, void)
+DEF_HELPER_1(pemu_trace, void, int)
+DEF_HELPER_1(find_process, void, int)
+DEF_HELPER_1(inst_hook_1, void, ptr)
+DEF_HELPER_2(inst_hook_2, void, ptr, ptr)
+DEF_HELPER_3(inst_hook_3, void, ptr, ptr, ptr)
+DEF_HELPER_4(inst_hook_4, void, ptr, ptr, ptr, ptr)
+DEF_HELPER_5(inst_hook_5, void, ptr, ptr, ptr, ptr, ptr)
+
+DEF_HELPER_1(introspect_hook, void, int)
+#if 0
+DEF_HELPER_1(bbl_hook_1, void, ptr)
+DEF_HELPER_2(bbl_hook_2, void, ptr, ptr)
+DEF_HELPER_3(bbl_hook_3, void, ptr, ptr, ptr)
+DEF_HELPER_4(bbl_hook_4, void, ptr, ptr, ptr, ptr)
+DEF_HELPER_5(bbl_hook_5, void, ptr, ptr, ptr, ptr, ptr)
+#endif
+//end
+
/* MMX/SSE */
DEF_HELPER_2(ldmxcsr, void, env, i32)
diff -ur qemu-1.5.3/target-i386/seg_helper.c pemu/target-i386/seg_helper.c
--- qemu-1.5.3/target-i386/seg_helper.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/target-i386/seg_helper.c 2015-03-19 02:58:13.867922080 +0900
@@ -1158,9 +1158,38 @@
* the int instruction. next_eip is the EIP value AFTER the interrupt
* instruction. It is only relevant if is_int is TRUE.
*/
+//jzeng
+#include "PEMU/pemu.h"
+#include "PEMU/PIN/pin.h"
+#include "PEMU/pemu_config.h"
static void do_interrupt_all(CPUX86State *env, int intno, int is_int,
int error_code, target_ulong next_eip, int is_hw)
{
+ if(pemu_exec_stats.PEMU_start && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()){
+ if(intno == 0x80){
+ pemu_exec_stats.PEMU_int_level = 0; //jzeng
+ pemu_exec_stats.PEMU_start_trace_syscall = 1;
+ if(pemu_hook_funcs.enter_syscall_hook != 0){
+ pemu_hook_funcs.enter_syscall_hook(pemu_exec_stats.PEMU_pid, pin_context, SYSCALL_STANDARD_IA32_LINUX, 0);
+ }
+
+ //yang
+ if(cpu_single_env->regs[R_EAX] == 252)
+ {
+ if(pemu_hook_funcs.fini_hook) {
+ pemu_hook_funcs.fini_hook(0, 0);
+ pemu_exec_stats.PEMU_start = 0;
+ }
+ }
+#ifdef PEMU_DEBUG
+ //fprintf(stdout, "int80 start syscall\t%x\n", cpu_single_env->regs[R_EAX]);
+#endif
+ }else{
+ pemu_exec_stats.PEMU_int_level++;
+ }
+ }
+//end
+
if (qemu_loglevel_mask(CPU_LOG_INT)) {
if ((env->cr[0] & CR0_PE_MASK)) {
static int count;
@@ -1961,6 +1990,9 @@
}
/* protected mode iret */
+//jzeng
+long PEMU_iret_target_pc;
+//end
static inline void helper_ret_protected(CPUX86State *env, int shift,
int is_iret, int addend)
{
@@ -2015,6 +2047,10 @@
LOG_PCALL("lret new %04x:" TARGET_FMT_lx " s=%d addend=0x%x\n",
new_cs, new_eip, shift, addend);
LOG_PCALL_STATE(env);
+ //jzeng
+ PEMU_iret_target_pc = new_eip;
+ //end
+
if ((new_cs & 0xfffc) == 0) {
raise_exception_err(env, EXCP0D_GPF, new_cs & 0xfffc);
}
@@ -2187,6 +2223,7 @@
int tss_selector, type;
uint32_t e1, e2;
+
/* specific case for TSS */
if (env->eflags & NT_MASK) {
#ifdef TARGET_X86_64
@@ -2211,6 +2248,47 @@
helper_ret_protected(env, shift, 1, 0);
}
env->hflags2 &= ~HF2_NMI_MASK;
+
+//jzeng
+ if(pemu_exec_stats.PEMU_start && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()) {
+#if 0
+ if(pemu_exec_stats.PEMU_start_trace_syscall) {
+ pemu_exec_stats.PEMU_int_level--;
+ if(pemu_exec_stats.PEMU_int_level == -1) {
+ pemu_exec_stats.PEMU_start_trace_syscall = 0;
+ pemu_exec_stats.PEMU_int_level = 0;
+ if(pemu_hook_funcs.exit_syscall_hook != 0) {
+ pemu_hook_funcs.exit_syscall_hook(pemu_exec_stats.PEMU_pid, pin_context, SYSCALL_STANDARD_IA32_LINUX, 0);
+ }
+ }
+ }
+#endif
+ //yang
+ pemu_exec_stats.PEMU_int_level--;
+ if((cpu_single_env->hflags & HF_CPL_MASK) == 3)
+ {
+ pemu_exec_stats.PEMU_int_level = 0;
+ if(pemu_exec_stats.PEMU_start_trace_syscall) {
+ pemu_exec_stats.PEMU_start_trace_syscall = 0;
+ if(pemu_hook_funcs.exit_syscall_hook != 0) {
+ pemu_hook_funcs.exit_syscall_hook(pemu_exec_stats.PEMU_pid, pin_context, SYSCALL_STANDARD_IA32_LINUX, 0);
+ }
+ }
+ }
+
+ }
+//end
+
+
+ //jzeng
+#if 0
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ && PEMU_iret_target_pc < 0xc0000000) {
+ introspect_int80_mmap_return(cpu_single_env);
+ }
+#endif
+ //end
}
void helper_lret_protected(CPUX86State *env, int shift, int addend)
@@ -2220,6 +2298,24 @@
void helper_sysenter(CPUX86State *env)
{
+
+//jzeng
+ if(pemu_exec_stats.PEMU_start && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()){
+ pemu_exec_stats.PEMU_start_trace_syscall = 1;
+ pemu_exec_stats.PEMU_int_level = 0;
+ //fprintf(stdout, "sysenter system call: %d eip=%x\n", env->regs[R_EAX], env->eip);
+ if(pemu_hook_funcs.enter_syscall_hook != 0){
+ pemu_hook_funcs.enter_syscall_hook(pemu_exec_stats.PEMU_pid, pin_context, SYSCALL_STANDARD_IA32_LINUX, 0);
+ }
+ if(cpu_single_env->regs[R_EAX] == 252) {
+ if(pemu_hook_funcs.fini_hook) {
+ pemu_hook_funcs.fini_hook(0, 0);
+ pemu_exec_stats.PEMU_start = 0;
+ }
+ }
+ }
+//end
+
if (env->sysenter_cs == 0) {
raise_exception_err(env, EXCP0D_GPF, 0);
}
@@ -2290,6 +2386,11 @@
}
ESP = ECX;
EIP = EDX;
+ //jzeng
+ //if(pemu_exec_stats.PEMU_start && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()){
+ //introspect_sysexit(env);
+ //}
+ //end
}
target_ulong helper_lsl(CPUX86State *env, target_ulong selector1)
diff -ur qemu-1.5.3/target-i386/translate.c pemu/target-i386/translate.c
--- qemu-1.5.3/target-i386/translate.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/target-i386/translate.c 2015-03-19 02:58:13.875773279 +0900
@@ -4661,11 +4661,43 @@
}
}
+
+//jzeng
+#include "PEMU/pemu.h"
+#include "PEMU/hashTable.h"
+int out_asm = 0;
/* convert one instruction. s->is_jmp is set if the translation must
be stopped. Return the next pc value */
static target_ulong disas_insn(CPUX86State *env, DisasContext *s,
- target_ulong pc_start)
+ target_ulong pc_start, int search_pc)
{
+ //adding instrumentation code into tcg
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ //&& pemu_exec_stats.PEMU_start_trace_syscall == 0
+ && pemu_exec_stats.PEMU_int_level == 0
+ //&& pc_start < 0xc0000000
+ ) {
+ long pc = lookup_hashTable(pc_start);
+ if(pc != 0) {
+ if(1) {
+ pemu_exec_stats.pin_exec_stats.pin_args[IARG_INST_PTR] = pc_start;
+ }
+ PEMU_instrument_code(pc, s->tb->pc, search_pc);
+ }
+ }
+#if 0
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ && pemu_exec_stats.PEMU_start_trace_syscall == 1
+ && pemu_exec_stats.PEMU_int_level == 0
+ //&& pc_start < 0xc0000000
+ ) {
+ gen_helper_introspect_hook(tcg_const_i32(pc_start));
+ }
+ //end
+#endif
+
int b, prefixes, aflag, dflag;
int shift, ot;
int modrm, reg, rm, mod, reg_addr, op, opreg, offset_addr, val;
@@ -6804,7 +6836,7 @@
break;
case 0xe8: /* call im */
{
- if (dflag)
+ if (dflag)
tval = (int32_t)insn_get(env, s, OT_LONG);
else
tval = (int16_t)insn_get(env, s, OT_WORD);
@@ -8166,17 +8198,20 @@
break;
default:
goto illegal_op;
- }
+ }
+
/* lock generation */
if (s->prefix & PREFIX_LOCK)
gen_helper_unlock();
return s->pc;
+
illegal_op:
if (s->prefix & PREFIX_LOCK)
gen_helper_unlock();
/* XXX: ensure that no lock was generated */
gen_exception(s, EXCP06_ILLOP, pc_start - s->cs_base);
- return s->pc;
+
+ return s->pc;
}
void optimize_flags_init(void)
@@ -8336,6 +8371,37 @@
if (max_insns == 0)
max_insns = CF_COUNT_MASK;
+ //jzeng: routine instrumentation
+ //end
+
+ //jzeng: basic block instrumentation
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ && pemu_exec_stats.PEMU_int_level == 0
+ && (tb->pc < 0xc0000000)
+ ) {
+ //yang.begin
+ // if(tb->pc >=0x8000000 && tb->pc <=0x8100000)
+ {
+ if(pemu_exec_stats.PEMU_disas_start == 0)
+ {
+ PEMU_disas_trace(tb->pc);
+ PEMU_set_trace(tb->pc);
+ pemu_exec_stats.PEMU_disas_start = 1;
+ }else if(PEMU_trace_need_disas(tb->pc))
+ {
+ PEMU_disas_trace(tb->pc);
+ PEMU_set_trace(tb->pc);
+ }
+ }
+ //yang.end
+ if(pemu_hook_funcs.bbl_hook != 0) {
+ //fprintf(stdout, "new bbl %x\n", tb->pc);
+ disas_basic_block_ex(tb->pc, &pemu_bbl);
+ pemu_hook_funcs.bbl_hook(pemu_bbl.bbl, 0);
+ }
+ }
+ //end
gen_tb_start();
for(;;) {
if (unlikely(!QTAILQ_EMPTY(&env->breakpoints))) {
@@ -8362,11 +8428,55 @@
if (num_insns + 1 == max_insns && (tb->cflags & CF_LAST_IO))
gen_io_start();
- pc_ptr = disas_insn(env, dc, pc_ptr);
+ //jzeng: inst instrumentation
+ target_ulong cur_ptr = pc_ptr;
+
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ && pemu_exec_stats.PEMU_int_level == 0
+ ) {
+ //yang.begin
+ if(pc_ptr < 0xc0000000)
+ {
+ if(PEMU_disas_handle_branch(pc_ptr))
+ gen_helper_pemu_trace(tcg_const_i32(pc_ptr));
+ }
+ //yang.end
+
+#if 0
+ if(pemu_hook_funcs.inst_hook != 0) {
+ //fprintf(stdout, "new inst %x\n", tb->pc);
+ //pemu_hook_funcs.inst_hook(pemu_bbl.inst, 0);
+ if(disas_one_inst_ex(pc_ptr, &pemu_inst) == XED_ERROR_NONE) {
+ pemu_inst.PEMU_inst_pc = pc_ptr;
+ pemu_hook_funcs.inst_hook(&pemu_inst.PEMU_xedd_g, 0);
+ }
+ }
+#endif
+ }
+ //end
+
+ //yang
+ pc_ptr = disas_insn(env, dc, pc_ptr, search_pc);
+#if 0
+ //jzeng: for introspection
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ //&& pemu_exec_stats.PEMU_start_trace_syscall == 0
+ //&& pemu_exec_stats.PEMU_int_level != 0
+ && cur_ptr < 0xc0000000
+ ) {
+ printf("translate: %x\n", cur_ptr);
+ gen_helper_introspec_hook(tcg_const_i32(cur_ptr));
+ }
+ //end
+#endif
+
num_insns++;
/* stop translation if indicated */
if (dc->is_jmp)
break;
+
/* if single step mode, we generate only one instruction and
generate an exception */
/* if irq were inhibited with HF_INHIBIT_IRQ_MASK, we clear
@@ -8376,7 +8486,7 @@
(flags & HF_INHIBIT_IRQ_MASK)) {
gen_jmp_im(pc_ptr - dc->cs_base);
gen_eob(dc);
- break;
+ break;
}
/* if too long translation, stop generation too */
if (tcg_ctx.gen_opc_ptr >= gen_opc_end ||
@@ -8405,7 +8515,9 @@
}
#ifdef DEBUG_DISAS
- if (qemu_loglevel_mask(CPU_LOG_TB_IN_ASM)) {
+ if (qemu_loglevel_mask(CPU_LOG_TB_IN_ASM) &&
+ pemu_exec_stats.PEMU_cr3 == env->cr[3] && pc_start <0xc0000000) {
+ out_asm = 1;
int disas_flags;
qemu_log("----------------\n");
qemu_log("IN: %s\n", lookup_symbol(pc_start));
@@ -8422,8 +8534,23 @@
if (!search_pc) {
tb->size = pc_ptr - pc_start;
- tb->icount = num_insns;
- }
+ //yang
+ //tb->icount = num_insns;
+ tb->icount = tcg_ctx.gen_opc_ptr - tcg_ctx.gen_opc_buf;
+ }else
+ if(tb->icount != (tcg_ctx.gen_opc_ptr - tcg_ctx.gen_opc_buf))
+ printf("ERROR %x %x %x\n", tb->pc, tb->icount, tcg_ctx.gen_opc_ptr - tcg_ctx.gen_opc_buf);
+
+ //jzeng
+ if(pemu_exec_stats.PEMU_start
+ && pemu_exec_stats.PEMU_cr3 == PEMU_get_cr3()
+ //&& (tb->pc >= 0x8048394 && tb->pc <= 0x80483e1)
+ ) {
+ if(pemu_hook_funcs.bbl_hook != 0){
+ end_basic_block(pemu_bbl.bbl);
+ }
+ }
+ //end
}
void gen_intermediate_code(CPUX86State *env, TranslationBlock *tb)
pemu/target-i386 のみに存在: translate2.c
qemu-1.5.3 のみに存在: target-lm32
qemu-1.5.3 のみに存在: target-m68k
qemu-1.5.3 のみに存在: target-microblaze
qemu-1.5.3 のみに存在: target-mips
qemu-1.5.3 のみに存在: target-moxie
qemu-1.5.3 のみに存在: target-openrisc
qemu-1.5.3 のみに存在: target-ppc
qemu-1.5.3 のみに存在: target-s390x
qemu-1.5.3 のみに存在: target-sh4
qemu-1.5.3 のみに存在: target-sparc
qemu-1.5.3 のみに存在: target-unicore32
qemu-1.5.3 のみに存在: target-xtensa
pemu のみに存在: task-info
qemu-1.5.3/tests/tcg/cris のみに存在: .gdbinit
diff -ur qemu-1.5.3/translate-all.c pemu/translate-all.c
--- qemu-1.5.3/translate-all.c 2013-08-28 00:05:28.000000000 +0900
+++ pemu/translate-all.c 2015-03-19 02:58:14.672670060 +0900
@@ -181,8 +181,15 @@
s->code_out_len += gen_code_size;
#endif
+
#ifdef DEBUG_DISAS
- if (qemu_loglevel_mask(CPU_LOG_TB_OUT_ASM)) {
+ //yang
+ extern int out_asm;
+
+ // if (qemu_loglevel_mask(CPU_LOG_TB_OUT_ASM)) {
+ if(out_asm){
+ out_asm = 0;
+ qemu_log("OUT pc %x\n", tb->pc);
qemu_log("OUT: [size=%d]\n", *gen_code_size_ptr);
log_disas(tb->tc_ptr, *gen_code_size_ptr);
qemu_log("\n");
@@ -210,7 +217,7 @@
tcg_func_start(s);
gen_intermediate_code_pc(env, tb);
-
+
if (use_icount) {
/* Reset the cycle counter to the start of the block. */
env->icount_decr.u16.low += tb->icount;
@@ -232,6 +239,22 @@
s->tb_next = tb->tb_next;
#endif
j = tcg_gen_code_search_pc(s, (uint8_t *)tc_ptr, searched_pc - tc_ptr);
+
+ //yang
+ extern int out_asm;
+ if(out_asm)
+ {
+ qemu_log("restore %x %x\n", tb->pc, searched_pc);
+ out_asm = 0;
+#if 0
+ qemu_log("OUT pc %x\n", tb->pc);
+ qemu_log("OUT: [size=%d]\n", *gen_code_size_ptr);
+ log_disas(tb->tc_ptr, *gen_code_size_ptr);
+ qemu_log("\n");
+ qemu_log_flush();
+#endif
+ }
+
if (j < 0)
return -1;
/* now find start of instruction before */
pemu のみに存在: xed2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment