4 * Copyright (c) 2003 Fabrice Bellard
5 * Copyright (c) 2006 Pierre d'Herbemont
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, see <http://www.gnu.org/licenses/>.
27 #include <sys/syscall.h>
31 #include "qemu-common.h"
33 #define DEBUG_LOGFILE "/tmp/qemu.log"
36 #include <crt_externs.h>
37 # define environ (*_NSGetEnviron())
40 #include <mach/mach_init.h>
41 #include <mach/vm_map.h>
45 const char *interp_prefix
= "";
47 asm(".zerofill __STD_PROG_ZONE, __STD_PROG_ZONE, __std_prog_zone, 0x0dfff000");
49 /* XXX: on x86 MAP_GROWSDOWN only works if ESP <= address + 32, so
50 we allocate a bigger stack. Need a better solution, for example
51 by remapping the process stack directly at the right place */
52 unsigned long stack_size
= 512 * 1024;
54 void qerror(const char *fmt
, ...)
59 vfprintf(stderr
, fmt
, ap
);
61 fprintf(stderr
, "\n");
65 void gemu_log(const char *fmt
, ...)
70 vfprintf(stderr
, fmt
, ap
);
74 int cpu_get_pic_interrupt(CPUArchState
*env
)
80 static inline uint64_t cpu_ppc_get_tb(CPUPPCState
*env
)
86 uint64_t cpu_ppc_load_tbl(CPUPPCState
*env
)
88 return cpu_ppc_get_tb(env
);
91 uint32_t cpu_ppc_load_tbu(CPUPPCState
*env
)
93 return cpu_ppc_get_tb(env
) >> 32;
96 uint64_t cpu_ppc_load_atbl(CPUPPCState
*env
)
98 return cpu_ppc_get_tb(env
);
101 uint32_t cpu_ppc_load_atbu(CPUPPCState
*env
)
103 return cpu_ppc_get_tb(env
) >> 32;
106 uint32_t cpu_ppc601_load_rtcu(CPUPPCState
*env
)
108 cpu_ppc_load_tbu(env
);
111 uint32_t cpu_ppc601_load_rtcl(CPUPPCState
*env
)
113 return cpu_ppc_load_tbl(env
) & 0x3FFFFF80;
116 /* XXX: to be fixed */
117 int ppc_dcr_read (ppc_dcr_t
*dcr_env
, int dcrn
, uint32_t *valp
)
122 int ppc_dcr_write (ppc_dcr_t
*dcr_env
, int dcrn
, uint32_t val
)
127 #define EXCP_DUMP(env, fmt, ...) \
129 fprintf(stderr, fmt , ## __VA_ARGS__); \
130 cpu_dump_state(env, stderr, fprintf, 0); \
131 qemu_log(fmt, ## __VA_ARGS__); \
132 log_cpu_state(env, 0); \
135 void cpu_loop(CPUPPCState
*env
)
139 target_siginfo_t info
;
142 trapnr
= cpu_ppc_exec(env
);
144 case POWERPC_EXCP_NONE
:
147 case POWERPC_EXCP_CRITICAL
: /* Critical input */
148 cpu_abort(env
, "Critical interrupt while in user mode. "
151 case POWERPC_EXCP_MCHECK
: /* Machine check exception */
152 cpu_abort(env
, "Machine check exception while in user mode. "
155 case POWERPC_EXCP_DSI
: /* Data storage exception */
157 /* To deal with multiple qemu header version as host for the darwin-user code */
160 EXCP_DUMP(env
, "Invalid data memory access: 0x" TARGET_FMT_lx
"\n",
162 /* Handle this via the gdb */
163 gdb_handlesig (env
, SIGSEGV
);
165 info
.si_addr
= (void*)env
->nip
;
166 queue_signal(info
.si_signo
, &info
);
168 case POWERPC_EXCP_ISI
: /* Instruction storage exception */
169 EXCP_DUMP(env
, "Invalid instruction fetch: 0x\n" TARGET_FMT_lx
"\n",
171 /* Handle this via the gdb */
172 gdb_handlesig (env
, SIGSEGV
);
174 info
.si_addr
= (void*)(env
->nip
- 4);
175 queue_signal(info
.si_signo
, &info
);
177 case POWERPC_EXCP_EXTERNAL
: /* External input */
178 cpu_abort(env
, "External interrupt while in user mode. "
181 case POWERPC_EXCP_ALIGN
: /* Alignment exception */
182 EXCP_DUMP(env
, "Unaligned memory access\n");
184 info
.si_code
= BUS_ADRALN
;
185 info
.si_addr
= (void*)(env
->nip
- 4);
186 queue_signal(info
.si_signo
, &info
);
188 case POWERPC_EXCP_PROGRAM
: /* Program exception */
189 /* XXX: check this */
190 switch (env
->error_code
& ~0xF) {
191 case POWERPC_EXCP_FP
:
192 EXCP_DUMP(env
, "Floating point program exception\n");
194 info
.si_signo
= SIGFPE
;
196 switch (env
->error_code
& 0xF) {
197 case POWERPC_EXCP_FP_OX
:
198 info
.si_code
= FPE_FLTOVF
;
200 case POWERPC_EXCP_FP_UX
:
201 info
.si_code
= FPE_FLTUND
;
203 case POWERPC_EXCP_FP_ZX
:
204 case POWERPC_EXCP_FP_VXZDZ
:
205 info
.si_code
= FPE_FLTDIV
;
207 case POWERPC_EXCP_FP_XX
:
208 info
.si_code
= FPE_FLTRES
;
210 case POWERPC_EXCP_FP_VXSOFT
:
211 info
.si_code
= FPE_FLTINV
;
213 case POWERPC_EXCP_FP_VXSNAN
:
214 case POWERPC_EXCP_FP_VXISI
:
215 case POWERPC_EXCP_FP_VXIDI
:
216 case POWERPC_EXCP_FP_VXIMZ
:
217 case POWERPC_EXCP_FP_VXVC
:
218 case POWERPC_EXCP_FP_VXSQRT
:
219 case POWERPC_EXCP_FP_VXCVI
:
220 info
.si_code
= FPE_FLTSUB
;
223 EXCP_DUMP(env
, "Unknown floating point exception (%02x)\n",
228 case POWERPC_EXCP_INVAL
:
229 EXCP_DUMP(env
, "Invalid instruction\n");
230 info
.si_signo
= SIGILL
;
232 switch (env
->error_code
& 0xF) {
233 case POWERPC_EXCP_INVAL_INVAL
:
234 info
.si_code
= ILL_ILLOPC
;
236 case POWERPC_EXCP_INVAL_LSWX
:
237 info
.si_code
= ILL_ILLOPN
;
239 case POWERPC_EXCP_INVAL_SPR
:
240 info
.si_code
= ILL_PRVREG
;
242 case POWERPC_EXCP_INVAL_FP
:
243 info
.si_code
= ILL_COPROC
;
246 EXCP_DUMP(env
, "Unknown invalid operation (%02x)\n",
247 env
->error_code
& 0xF);
248 info
.si_code
= ILL_ILLADR
;
251 /* Handle this via the gdb */
252 gdb_handlesig (env
, SIGSEGV
);
254 case POWERPC_EXCP_PRIV
:
255 EXCP_DUMP(env
, "Privilege violation\n");
256 info
.si_signo
= SIGILL
;
258 switch (env
->error_code
& 0xF) {
259 case POWERPC_EXCP_PRIV_OPC
:
260 info
.si_code
= ILL_PRVOPC
;
262 case POWERPC_EXCP_PRIV_REG
:
263 info
.si_code
= ILL_PRVREG
;
266 EXCP_DUMP(env
, "Unknown privilege violation (%02x)\n",
267 env
->error_code
& 0xF);
268 info
.si_code
= ILL_PRVOPC
;
272 case POWERPC_EXCP_TRAP
:
273 cpu_abort(env
, "Tried to call a TRAP\n");
276 /* Should not happen ! */
277 cpu_abort(env
, "Unknown program exception (%02x)\n",
281 info
.si_addr
= (void*)(env
->nip
- 4);
282 queue_signal(info
.si_signo
, &info
);
284 case POWERPC_EXCP_FPU
: /* Floating-point unavailable exception */
285 EXCP_DUMP(env
, "No floating point allowed\n");
286 info
.si_signo
= SIGILL
;
288 info
.si_code
= ILL_COPROC
;
289 info
.si_addr
= (void*)(env
->nip
- 4);
290 queue_signal(info
.si_signo
, &info
);
292 case POWERPC_EXCP_SYSCALL
: /* System call exception */
293 cpu_abort(env
, "Syscall exception while in user mode. "
296 case POWERPC_EXCP_APU
: /* Auxiliary processor unavailable */
297 EXCP_DUMP(env
, "No APU instruction allowed\n");
298 info
.si_signo
= SIGILL
;
300 info
.si_code
= ILL_COPROC
;
301 info
.si_addr
= (void*)(env
->nip
- 4);
302 queue_signal(info
.si_signo
, &info
);
304 case POWERPC_EXCP_DECR
: /* Decrementer exception */
305 cpu_abort(env
, "Decrementer interrupt while in user mode. "
308 case POWERPC_EXCP_FIT
: /* Fixed-interval timer interrupt */
309 cpu_abort(env
, "Fix interval timer interrupt while in user mode. "
312 case POWERPC_EXCP_WDT
: /* Watchdog timer interrupt */
313 cpu_abort(env
, "Watchdog timer interrupt while in user mode. "
316 case POWERPC_EXCP_DTLB
: /* Data TLB error */
317 cpu_abort(env
, "Data TLB exception while in user mode. "
320 case POWERPC_EXCP_ITLB
: /* Instruction TLB error */
321 cpu_abort(env
, "Instruction TLB exception while in user mode. "
324 case POWERPC_EXCP_DEBUG
: /* Debug interrupt */
325 gdb_handlesig (env
, SIGTRAP
);
327 case POWERPC_EXCP_SPEU
: /* SPE/embedded floating-point unavail. */
328 EXCP_DUMP(env
, "No SPE/floating-point instruction allowed\n");
329 info
.si_signo
= SIGILL
;
331 info
.si_code
= ILL_COPROC
;
332 info
.si_addr
= (void*)(env
->nip
- 4);
333 queue_signal(info
.si_signo
, &info
);
335 case POWERPC_EXCP_EFPDI
: /* Embedded floating-point data IRQ */
336 cpu_abort(env
, "Embedded floating-point data IRQ not handled\n");
338 case POWERPC_EXCP_EFPRI
: /* Embedded floating-point round IRQ */
339 cpu_abort(env
, "Embedded floating-point round IRQ not handled\n");
341 case POWERPC_EXCP_EPERFM
: /* Embedded performance monitor IRQ */
342 cpu_abort(env
, "Performance monitor exception not handled\n");
344 case POWERPC_EXCP_DOORI
: /* Embedded doorbell interrupt */
345 cpu_abort(env
, "Doorbell interrupt while in user mode. "
348 case POWERPC_EXCP_DOORCI
: /* Embedded doorbell critical interrupt */
349 cpu_abort(env
, "Doorbell critical interrupt while in user mode. "
352 case POWERPC_EXCP_RESET
: /* System reset exception */
353 cpu_abort(env
, "Reset interrupt while in user mode. "
356 case POWERPC_EXCP_DSEG
: /* Data segment exception */
357 cpu_abort(env
, "Data segment exception while in user mode. "
360 case POWERPC_EXCP_ISEG
: /* Instruction segment exception */
361 cpu_abort(env
, "Instruction segment exception "
362 "while in user mode. Aborting\n");
364 case POWERPC_EXCP_HDECR
: /* Hypervisor decrementer exception */
365 cpu_abort(env
, "Hypervisor decrementer interrupt "
366 "while in user mode. Aborting\n");
368 case POWERPC_EXCP_TRACE
: /* Trace exception */
370 * we use this exception to emulate step-by-step execution mode.
373 case POWERPC_EXCP_HDSI
: /* Hypervisor data storage exception */
374 cpu_abort(env
, "Hypervisor data storage exception "
375 "while in user mode. Aborting\n");
377 case POWERPC_EXCP_HISI
: /* Hypervisor instruction storage excp */
378 cpu_abort(env
, "Hypervisor instruction storage exception "
379 "while in user mode. Aborting\n");
381 case POWERPC_EXCP_HDSEG
: /* Hypervisor data segment exception */
382 cpu_abort(env
, "Hypervisor data segment exception "
383 "while in user mode. Aborting\n");
385 case POWERPC_EXCP_HISEG
: /* Hypervisor instruction segment excp */
386 cpu_abort(env
, "Hypervisor instruction segment exception "
387 "while in user mode. Aborting\n");
389 case POWERPC_EXCP_VPU
: /* Vector unavailable exception */
390 EXCP_DUMP(env
, "No Altivec instructions allowed\n");
391 info
.si_signo
= SIGILL
;
393 info
.si_code
= ILL_COPROC
;
394 info
.si_addr
= (void*)(env
->nip
- 4);
395 queue_signal(info
.si_signo
, &info
);
397 case POWERPC_EXCP_PIT
: /* Programmable interval timer IRQ */
398 cpu_abort(env
, "Programmable interval timer interrupt "
399 "while in user mode. Aborting\n");
401 case POWERPC_EXCP_IO
: /* IO error exception */
402 cpu_abort(env
, "IO error exception while in user mode. "
405 case POWERPC_EXCP_RUNM
: /* Run mode exception */
406 cpu_abort(env
, "Run mode exception while in user mode. "
409 case POWERPC_EXCP_EMUL
: /* Emulation trap exception */
410 cpu_abort(env
, "Emulation trap exception not handled\n");
412 case POWERPC_EXCP_IFTLB
: /* Instruction fetch TLB error */
413 cpu_abort(env
, "Instruction fetch TLB exception "
414 "while in user-mode. Aborting");
416 case POWERPC_EXCP_DLTLB
: /* Data load TLB miss */
417 cpu_abort(env
, "Data load TLB exception while in user-mode. "
420 case POWERPC_EXCP_DSTLB
: /* Data store TLB miss */
421 cpu_abort(env
, "Data store TLB exception while in user-mode. "
424 case POWERPC_EXCP_FPA
: /* Floating-point assist exception */
425 cpu_abort(env
, "Floating-point assist exception not handled\n");
427 case POWERPC_EXCP_IABR
: /* Instruction address breakpoint */
428 cpu_abort(env
, "Instruction address breakpoint exception "
431 case POWERPC_EXCP_SMI
: /* System management interrupt */
432 cpu_abort(env
, "System management interrupt while in user mode. "
435 case POWERPC_EXCP_THERM
: /* Thermal interrupt */
436 cpu_abort(env
, "Thermal interrupt interrupt while in user mode. "
439 case POWERPC_EXCP_PERFM
: /* Embedded performance monitor IRQ */
440 cpu_abort(env
, "Performance monitor exception not handled\n");
442 case POWERPC_EXCP_VPUA
: /* Vector assist exception */
443 cpu_abort(env
, "Vector assist exception not handled\n");
445 case POWERPC_EXCP_SOFTP
: /* Soft patch exception */
446 cpu_abort(env
, "Soft patch exception not handled\n");
448 case POWERPC_EXCP_MAINT
: /* Maintenance exception */
449 cpu_abort(env
, "Maintenance exception while in user mode. "
452 case POWERPC_EXCP_STOP
: /* stop translation */
453 /* We did invalidate the instruction cache. Go on */
455 case POWERPC_EXCP_BRANCH
: /* branch instruction: */
456 /* We just stopped because of a branch. Go on */
458 case POWERPC_EXCP_SYSCALL_USER
:
459 /* system call in user-mode emulation */
461 if(((int)env
->gpr
[0]) <= SYS_MAXSYSCALL
&& ((int)env
->gpr
[0])>0)
462 ret
= do_unix_syscall(env
, env
->gpr
[0]/*, env->gpr[3], env->gpr[4],
463 env->gpr[5], env->gpr[6], env->gpr[7],
464 env->gpr[8], env->gpr[9], env->gpr[10]*/);
465 else if(((int)env
->gpr
[0])<0)
466 ret
= do_mach_syscall(env
, env
->gpr
[0], env
->gpr
[3], env
->gpr
[4],
467 env
->gpr
[5], env
->gpr
[6], env
->gpr
[7],
468 env
->gpr
[8], env
->gpr
[9], env
->gpr
[10]);
470 ret
= do_thread_syscall(env
, env
->gpr
[0], env
->gpr
[3], env
->gpr
[4],
471 env
->gpr
[5], env
->gpr
[6], env
->gpr
[7],
472 env
->gpr
[8], env
->gpr
[9], env
->gpr
[10]);
474 /* Unix syscall error signaling */
475 if(((int)env
->gpr
[0]) <= SYS_MAXSYSCALL
&& ((int)env
->gpr
[0])>0)
487 /* just indicate that signals should be handled asap */
490 cpu_abort(env
, "Unknown exception 0x%d. Aborting\n", trapnr
);
493 process_pending_signals(env
);
501 /***********************************************************/
502 /* CPUX86 core interface */
504 uint64_t cpu_get_tsc(CPUX86State
*env
)
506 return cpu_get_real_ticks();
510 write_dt(void *ptr
, unsigned long addr
, unsigned long limit
,
514 e1
= (addr
<< 16) | (limit
& 0xffff);
515 e2
= ((addr
>> 16) & 0xff) | (addr
& 0xff000000) | (limit
& 0x000f0000);
517 stl((uint8_t *)ptr
, e1
);
518 stl((uint8_t *)ptr
+ 4, e2
);
521 static void set_gate(void *ptr
, unsigned int type
, unsigned int dpl
,
522 unsigned long addr
, unsigned int sel
)
525 e1
= (addr
& 0xffff) | (sel
<< 16);
526 e2
= (addr
& 0xffff0000) | 0x8000 | (dpl
<< 13) | (type
<< 8);
527 stl((uint8_t *)ptr
, e1
);
528 stl((uint8_t *)ptr
+ 4, e2
);
531 #define GDT_TABLE_SIZE 14
532 #define LDT_TABLE_SIZE 15
533 #define IDT_TABLE_SIZE 256
535 uint64_t gdt_table
[GDT_TABLE_SIZE
];
536 uint64_t ldt_table
[LDT_TABLE_SIZE
];
537 uint64_t idt_table
[IDT_TABLE_SIZE
];
538 uint32_t tss
[TSS_SIZE
];
540 /* only dpl matters as we do only user space emulation */
541 static void set_idt(int n
, unsigned int dpl
)
543 set_gate(idt_table
+ n
, 0, dpl
, 0, 0);
546 /* ABI convention: after a syscall if there was an error the CF flag is set */
547 static inline void set_error(CPUX86State
*env
, int ret
)
550 env
->eflags
= env
->eflags
| 0x1;
553 env
->regs
[R_EAX
] = ret
;
556 void cpu_loop(CPUX86State
*env
)
561 target_siginfo_t info
;
564 trapnr
= cpu_x86_exec(env
);
565 uint32_t *params
= (uint32_t *)env
->regs
[R_ESP
];
567 case 0x79: /* Our commpage hack back door exit is here */
568 do_commpage(env
, env
->eip
, *(params
+ 1), *(params
+ 2),
569 *(params
+ 3), *(params
+ 4),
570 *(params
+ 5), *(params
+ 6),
571 *(params
+ 7), *(params
+ 8));
573 case 0x81: /* mach syscall */
575 ret
= do_mach_syscall(env
, env
->regs
[R_EAX
],
576 *(params
+ 1), *(params
+ 2),
577 *(params
+ 3), *(params
+ 4),
578 *(params
+ 5), *(params
+ 6),
579 *(params
+ 7), *(params
+ 8));
583 case 0x90: /* unix backdoor */
585 /* after sysenter, stack is in R_ECX, new eip in R_EDX (sysexit will flip them back)*/
586 int saved_stack
= env
->regs
[R_ESP
];
587 env
->regs
[R_ESP
] = env
->regs
[R_ECX
];
589 ret
= do_unix_syscall(env
, env
->regs
[R_EAX
]);
591 env
->regs
[R_ECX
] = env
->regs
[R_ESP
];
592 env
->regs
[R_ESP
] = saved_stack
;
597 case 0x80: /* unix syscall */
599 ret
= do_unix_syscall(env
, env
->regs
[R_EAX
]/*,
600 *(params + 1), *(params + 2),
601 *(params + 3), *(params + 4),
602 *(params + 5), *(params + 6),
603 *(params + 7), *(params + 8)*/);
607 case 0x82: /* thread syscall */
609 ret
= do_thread_syscall(env
, env
->regs
[R_EAX
],
610 *(params
+ 1), *(params
+ 2),
611 *(params
+ 3), *(params
+ 4),
612 *(params
+ 5), *(params
+ 6),
613 *(params
+ 7), *(params
+ 8));
619 info
.si_signo
= SIGBUS
;
621 info
.si_code
= BUS_NOOP
;
623 gdb_handlesig (env
, SIGBUS
);
624 queue_signal(info
.si_signo
, &info
);
627 info
.si_signo
= SIGSEGV
;
629 info
.si_code
= SEGV_NOOP
;
631 gdb_handlesig (env
, SIGSEGV
);
632 queue_signal(info
.si_signo
, &info
);
635 info
.si_signo
= SIGSEGV
;
637 if (!(env
->error_code
& 1))
638 info
.si_code
= SEGV_MAPERR
;
640 info
.si_code
= SEGV_ACCERR
;
641 info
.si_addr
= (void*)env
->cr
[2];
642 gdb_handlesig (env
, SIGSEGV
);
643 queue_signal(info
.si_signo
, &info
);
646 /* division by zero */
647 info
.si_signo
= SIGFPE
;
649 info
.si_code
= FPE_INTDIV
;
650 info
.si_addr
= (void*)env
->eip
;
651 gdb_handlesig (env
, SIGFPE
);
652 queue_signal(info
.si_signo
, &info
);
656 info
.si_signo
= SIGTRAP
;
658 info
.si_code
= TRAP_BRKPT
;
659 info
.si_addr
= (void*)env
->eip
;
660 gdb_handlesig (env
, SIGTRAP
);
661 queue_signal(info
.si_signo
, &info
);
665 info
.si_signo
= SIGSEGV
;
667 info
.si_code
= SEGV_NOOP
;
669 gdb_handlesig (env
, SIGSEGV
);
670 queue_signal(info
.si_signo
, &info
);
673 info
.si_signo
= SIGILL
;
675 info
.si_code
= ILL_ILLOPN
;
676 info
.si_addr
= (void*)env
->eip
;
677 gdb_handlesig (env
, SIGILL
);
678 queue_signal(info
.si_signo
, &info
);
681 /* just indicate that signals should be handled asap */
687 sig
= gdb_handlesig (env
, SIGTRAP
);
692 info
.si_code
= TRAP_BRKPT
;
693 queue_signal(info
.si_signo
, &info
);
698 pc
= (void*)(env
->segs
[R_CS
].base
+ env
->eip
);
699 fprintf(stderr
, "qemu: 0x%08lx: unhandled CPU exception 0x%x - aborting\n",
703 process_pending_signals(env
);
708 static void usage(void)
710 printf("qemu-" TARGET_ARCH
" version " QEMU_VERSION
", Copyright (c) 2003-2004 Fabrice Bellard\n"
711 "usage: qemu-" TARGET_ARCH
" [-h] [-d opts] [-L path] [-s size] program [arguments...]\n"
712 "Darwin CPU emulator (compiled for %s emulation)\n"
714 "-h print this help\n"
715 "-L path set the %s library path (default='%s')\n"
716 "-s size set the stack size in bytes (default=%ld)\n"
719 "-d options activate log (logfile='%s')\n"
720 "-g wait for gdb on port 1234\n"
721 "-p pagesize set the host page size to 'pagesize'\n",
722 "-singlestep always run in singlestep mode\n"
731 /* XXX: currently only used for async signals (see signal.c) */
732 CPUArchState
*global_env
;
734 /* used to free thread contexts */
735 TaskState
*first_task_state
;
737 int main(int argc
, char **argv
)
739 const char *filename
;
740 const char *log_file
= DEBUG_LOGFILE
;
741 const char *log_mask
= NULL
;
742 struct target_pt_regs regs1
, *regs
= ®s1
;
743 TaskState ts1
, *ts
= &ts1
;
746 short use_gdbstub
= 0;
748 const char *cpu_model
;
753 module_call_init(MODULE_INIT_QOM
);
764 if (!strcmp(r
, "-")) {
766 } else if (!strcmp(r
, "d")) {
767 if (optind
>= argc
) {
770 log_mask
= argv
[optind
++];
771 } else if (!strcmp(r
, "D")) {
772 if (optind
>= argc
) {
775 log_file
= argv
[optind
++];
776 } else if (!strcmp(r
, "s")) {
778 stack_size
= strtol(r
, (char **)&r
, 0);
782 stack_size
*= 1024 * 1024;
783 else if (*r
== 'k' || *r
== 'K')
785 } else if (!strcmp(r
, "L")) {
786 interp_prefix
= argv
[optind
++];
787 } else if (!strcmp(r
, "p")) {
788 qemu_host_page_size
= atoi(argv
[optind
++]);
789 if (qemu_host_page_size
== 0 ||
790 (qemu_host_page_size
& (qemu_host_page_size
- 1)) != 0) {
791 fprintf(stderr
, "page size must be a power of two\n");
795 if (!strcmp(r
, "g")) {
797 } else if (!strcmp(r
, "cpu")) {
798 cpu_model
= argv
[optind
++];
799 if (strcmp(cpu_model
, "?") == 0) {
800 /* XXX: implement xxx_cpu_list for targets that still miss it */
801 #if defined(cpu_list)
802 cpu_list(stdout
, &fprintf
);
806 } else if (!strcmp(r
, "singlestep")) {
815 cpu_set_log_filename(log_file
);
820 mask
= cpu_str_to_log_mask(log_mask
);
822 printf("Log items (comma separated):\n");
823 for (item
= cpu_log_items
; item
->mask
!= 0; item
++) {
824 printf("%-10s %s\n", item
->name
, item
->help
);
831 if (optind
>= argc
) {
834 filename
= argv
[optind
];
837 memset(regs
, 0, sizeof(struct target_pt_regs
));
839 if (cpu_model
== NULL
) {
840 #if defined(TARGET_I386)
842 cpu_model
= "qemu64";
844 cpu_model
= "qemu32";
846 #elif defined(TARGET_PPC)
853 #error unsupported CPU
858 /* NOTE: we need to init the CPU at this stage to get
859 qemu_host_page_size */
860 env
= cpu_init(cpu_model
);
861 cpu_state_reset(env
);
863 printf("Starting %s with qemu\n----------------\n", filename
);
867 if (mach_exec(filename
, argv
+optind
, environ
, regs
) != 0) {
868 printf("Error loading %s\n", filename
);
876 /* build Task State */
877 memset(ts
, 0, sizeof(TaskState
));
881 #if defined(TARGET_I386)
882 cpu_x86_set_cpl(env
, 3);
884 env
->cr
[0] = CR0_PG_MASK
| CR0_WP_MASK
| CR0_PE_MASK
;
885 env
->hflags
|= HF_PE_MASK
;
887 if (env
->cpuid_features
& CPUID_SSE
) {
888 env
->cr
[4] |= CR4_OSFXSR_MASK
;
889 env
->hflags
|= HF_OSFXSR_MASK
;
892 /* flags setup : we activate the IRQs by default as in user mode */
893 env
->eflags
|= IF_MASK
;
895 /* darwin register setup */
896 env
->regs
[R_EAX
] = regs
->eax
;
897 env
->regs
[R_EBX
] = regs
->ebx
;
898 env
->regs
[R_ECX
] = regs
->ecx
;
899 env
->regs
[R_EDX
] = regs
->edx
;
900 env
->regs
[R_ESI
] = regs
->esi
;
901 env
->regs
[R_EDI
] = regs
->edi
;
902 env
->regs
[R_EBP
] = regs
->ebp
;
903 env
->regs
[R_ESP
] = regs
->esp
;
904 env
->eip
= regs
->eip
;
906 /* Darwin LDT setup */
907 /* 2 - User code segment
908 3 - User data segment
910 bzero(ldt_table
, LDT_TABLE_SIZE
* sizeof(ldt_table
[0]));
911 env
->ldt
.base
= (uint32_t) ldt_table
;
912 env
->ldt
.limit
= sizeof(ldt_table
) - 1;
914 write_dt(ldt_table
+ 2, 0, 0xfffff,
915 DESC_G_MASK
| DESC_B_MASK
| DESC_P_MASK
| DESC_S_MASK
|
916 (3 << DESC_DPL_SHIFT
) | (0xa << DESC_TYPE_SHIFT
));
917 write_dt(ldt_table
+ 3, 0, 0xfffff,
918 DESC_G_MASK
| DESC_B_MASK
| DESC_P_MASK
| DESC_S_MASK
|
919 (3 << DESC_DPL_SHIFT
) | (0x2 << DESC_TYPE_SHIFT
));
920 write_dt(ldt_table
+ 4, 0, 0xfffff,
921 DESC_G_MASK
| DESC_B_MASK
| DESC_P_MASK
| DESC_S_MASK
|
922 (3 << DESC_DPL_SHIFT
) | (0x2 << DESC_TYPE_SHIFT
));
925 * has changed a lot between old Darwin/x86 (pre-Mac Intel) and Mac OS X/x86,
926 now everything is done via int 0x81(mach) int 0x82 (thread) and sysenter/sysexit(unix) */
927 bzero(gdt_table
, sizeof(gdt_table
));
928 env
->gdt
.base
= (uint32_t)gdt_table
;
929 env
->gdt
.limit
= sizeof(gdt_table
) - 1;
931 /* Set up a back door to handle sysenter syscalls (unix) */
932 char * syscallbackdoor
= malloc(64);
933 page_set_flags((int)syscallbackdoor
, (int)syscallbackdoor
+ 64, PROT_EXEC
| PROT_READ
| PAGE_VALID
);
936 syscallbackdoor
[i
++] = 0xcd;
937 syscallbackdoor
[i
++] = 0x90; /* int 0x90 */
938 syscallbackdoor
[i
++] = 0x0F;
939 syscallbackdoor
[i
++] = 0x35; /* sysexit */
941 /* Darwin sysenter/sysexit setup */
942 env
->sysenter_cs
= 0x1; //XXX
943 env
->sysenter_eip
= (int)syscallbackdoor
;
944 env
->sysenter_esp
= (int)malloc(64);
947 This must match up with GDT[4] */
948 env
->tr
.base
= (uint32_t) tss
;
949 env
->tr
.limit
= sizeof(tss
) - 1;
950 env
->tr
.flags
= DESC_P_MASK
| (0x9 << DESC_TYPE_SHIFT
);
951 stw(tss
+ 2, 0x10); // ss0 = 0x10 = GDT[2] = Kernel Data Segment
953 /* Darwin interrupt setup */
954 bzero(idt_table
, sizeof(idt_table
));
955 env
->idt
.base
= (uint32_t) idt_table
;
956 env
->idt
.limit
= sizeof(idt_table
) - 1;
977 /* Syscalls are done via
978 int 0x80 (unix) (rarely used)
981 int 0x83 (diag) (not handled here)
982 sysenter/sysexit (unix) -> we redirect that to int 0x90 */
983 set_idt(0x79, 3); /* Commpage hack, here is our backdoor interrupt */
984 set_idt(0x80, 3); /* Unix Syscall */
985 set_idt(0x81, 3); /* Mach Syscalls */
986 set_idt(0x82, 3); /* thread Syscalls */
988 set_idt(0x90, 3); /* qemu-darwin-user's Unix syscalls backdoor */
991 cpu_x86_load_seg(env
, R_CS
, __USER_CS
);
992 cpu_x86_load_seg(env
, R_DS
, __USER_DS
);
993 cpu_x86_load_seg(env
, R_ES
, __USER_DS
);
994 cpu_x86_load_seg(env
, R_SS
, __USER_DS
);
995 cpu_x86_load_seg(env
, R_FS
, __USER_DS
);
996 cpu_x86_load_seg(env
, R_GS
, __USER_DS
);
998 #elif defined(TARGET_PPC)
1002 #if defined(TARGET_PPC64)
1003 #if defined(TARGET_ABI32)
1004 env
->msr
&= ~((target_ulong
)1 << MSR_SF
);
1006 env
->msr
|= (target_ulong
)1 << MSR_SF
;
1009 env
->nip
= regs
->nip
;
1010 for(i
= 0; i
< 32; i
++) {
1011 env
->gpr
[i
] = regs
->gpr
[i
];
1015 #error unsupported target CPU
1019 printf("Waiting for gdb Connection on port 1234...\n");
1020 gdbserver_start (1234);
1021 gdb_handlesig(env
, 0);