Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 1 | /* |
Andrew Walbran | 692b325 | 2019-03-07 15:51:31 +0000 | [diff] [blame] | 2 | * Copyright 2018 The Hafnium Authors. |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * https://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | extern "C" { |
| 18 | #include "vmapi/hf/abi.h" |
| 19 | } |
| 20 | |
| 21 | #include <gmock/gmock.h> |
| 22 | |
| 23 | namespace |
| 24 | { |
| 25 | using ::testing::Eq; |
| 26 | |
| 27 | /** |
| 28 | * Simulate an uninitialized hf_vcpu_run_return so it can be detected if any |
| 29 | * uninitialized fields make their way into the encoded form which would |
| 30 | * indicate a data leak. |
| 31 | */ |
| 32 | struct hf_vcpu_run_return dirty_vcpu_run_return() |
| 33 | { |
| 34 | struct hf_vcpu_run_return res; |
| 35 | memset(&res, 0xc5, sizeof(res)); |
| 36 | return res; |
| 37 | } |
| 38 | |
| 39 | /** |
Andrew Scull | 33fecd3 | 2019-01-08 14:48:27 +0000 | [diff] [blame] | 40 | * Encode a preempted response without leaking. |
| 41 | */ |
| 42 | TEST(abi, hf_vcpu_run_return_encode_preempted) |
| 43 | { |
| 44 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 45 | res.code = HF_VCPU_RUN_PREEMPTED; |
| 46 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0)); |
| 47 | } |
| 48 | |
| 49 | /** |
| 50 | * Decode a preempted response ignoring the irrelevant bits. |
| 51 | */ |
| 52 | TEST(abi, hf_vcpu_run_return_decode_preempted) |
| 53 | { |
| 54 | struct hf_vcpu_run_return res = |
| 55 | hf_vcpu_run_return_decode(0x1a1a1a1a2b2b2b00); |
| 56 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_PREEMPTED)); |
| 57 | } |
| 58 | |
| 59 | /** |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 60 | * Encode a yield response without leaking. |
| 61 | */ |
| 62 | TEST(abi, hf_vcpu_run_return_encode_yield) |
| 63 | { |
| 64 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 65 | res.code = HF_VCPU_RUN_YIELD; |
Andrew Scull | 33fecd3 | 2019-01-08 14:48:27 +0000 | [diff] [blame] | 66 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(1)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 67 | } |
| 68 | |
| 69 | /** |
| 70 | * Decode a yield response ignoring the irrelevant bits. |
| 71 | */ |
| 72 | TEST(abi, hf_vcpu_run_return_decode_yield) |
| 73 | { |
| 74 | struct hf_vcpu_run_return res = |
Andrew Scull | 33fecd3 | 2019-01-08 14:48:27 +0000 | [diff] [blame] | 75 | hf_vcpu_run_return_decode(0x1a1a1a1a2b2b2b01); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 76 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_YIELD)); |
| 77 | } |
| 78 | |
| 79 | /** |
| 80 | * Encode wait-for-interrupt response without leaking. |
| 81 | */ |
| 82 | TEST(abi, hf_vcpu_run_return_encode_wait_for_interrupt) |
| 83 | { |
| 84 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 85 | res.code = HF_VCPU_RUN_WAIT_FOR_INTERRUPT; |
Andrew Scull | b06d175 | 2019-02-04 10:15:48 +0000 | [diff] [blame] | 86 | res.sleep.ns = HF_SLEEP_INDEFINITE; |
| 87 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0xffffffffffffff02)); |
| 88 | } |
| 89 | |
| 90 | /** |
| 91 | * Encoding wait-for-interrupt response with too large sleep duration will drop |
| 92 | * the top octet. |
| 93 | */ |
| 94 | TEST(abi, hf_vcpu_run_return_encode_wait_for_interrupt_sleep_too_long) |
| 95 | { |
| 96 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 97 | res.code = HF_VCPU_RUN_WAIT_FOR_INTERRUPT; |
| 98 | res.sleep.ns = 0xcc22888888888888; |
| 99 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0x2288888888888802)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 100 | } |
| 101 | |
| 102 | /** |
| 103 | * Decode a wait-for-interrupt response ignoring the irrelevant bits. |
| 104 | */ |
| 105 | TEST(abi, hf_vcpu_run_return_decode_wait_for_interrupt) |
| 106 | { |
| 107 | struct hf_vcpu_run_return res = |
Andrew Scull | 33fecd3 | 2019-01-08 14:48:27 +0000 | [diff] [blame] | 108 | hf_vcpu_run_return_decode(0x1234abcdbadb0102); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 109 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_WAIT_FOR_INTERRUPT)); |
Andrew Scull | b06d175 | 2019-02-04 10:15:48 +0000 | [diff] [blame] | 110 | EXPECT_THAT(res.sleep.ns, Eq(0x1234abcdbadb01)); |
| 111 | } |
| 112 | |
| 113 | /** |
| 114 | * Encode wait-for-message response without leaking. |
| 115 | */ |
| 116 | TEST(abi, hf_vcpu_run_return_encode_wait_for_message) |
| 117 | { |
| 118 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 119 | res.code = HF_VCPU_RUN_WAIT_FOR_MESSAGE; |
| 120 | res.sleep.ns = HF_SLEEP_INDEFINITE; |
| 121 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0xffffffffffffff03)); |
| 122 | } |
| 123 | |
| 124 | /** |
| 125 | * Encoding wait-for-message response with too large sleep duration will drop |
| 126 | * the top octet. |
| 127 | */ |
| 128 | TEST(abi, hf_vcpu_run_return_encode_wait_for_message_sleep_too_long) |
| 129 | { |
| 130 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 131 | res.code = HF_VCPU_RUN_WAIT_FOR_MESSAGE; |
| 132 | res.sleep.ns = 0xaa99777777777777; |
| 133 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0x9977777777777703)); |
| 134 | } |
| 135 | |
| 136 | /** |
| 137 | * Decode a wait-for-message response ignoring the irrelevant bits. |
| 138 | */ |
| 139 | TEST(abi, hf_vcpu_run_return_decode_wait_for_message) |
| 140 | { |
| 141 | struct hf_vcpu_run_return res = |
| 142 | hf_vcpu_run_return_decode(0x12347654badb0103); |
| 143 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_WAIT_FOR_MESSAGE)); |
| 144 | EXPECT_THAT(res.sleep.ns, Eq(0x12347654badb01)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 145 | } |
| 146 | |
| 147 | /** |
| 148 | * Encode wake up response without leaking. |
| 149 | */ |
| 150 | TEST(abi, hf_vcpu_run_return_encode_wake_up) |
| 151 | { |
| 152 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 153 | res.code = HF_VCPU_RUN_WAKE_UP; |
Andrew Walbran | 9553492 | 2019-06-19 11:32:54 +0100 | [diff] [blame] | 154 | res.wake_up.vm_id = 0x1234; |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 155 | res.wake_up.vcpu = 0xabcd; |
Andrew Walbran | 9553492 | 2019-06-19 11:32:54 +0100 | [diff] [blame] | 156 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0x1234abcd0004)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 157 | } |
| 158 | |
| 159 | /** |
| 160 | * Decode a wake up response ignoring the irrelevant bits. |
| 161 | */ |
| 162 | TEST(abi, hf_vcpu_run_return_decode_wake_up) |
| 163 | { |
| 164 | struct hf_vcpu_run_return res = |
Andrew Walbran | 9553492 | 2019-06-19 11:32:54 +0100 | [diff] [blame] | 165 | hf_vcpu_run_return_decode(0xbeeff00daf04); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 166 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_WAKE_UP)); |
Andrew Walbran | 9553492 | 2019-06-19 11:32:54 +0100 | [diff] [blame] | 167 | EXPECT_THAT(res.wake_up.vm_id, Eq(0xbeef)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 168 | EXPECT_THAT(res.wake_up.vcpu, Eq(0xf00d)); |
| 169 | } |
| 170 | |
| 171 | /** |
| 172 | * Encode message response without leaking. |
| 173 | */ |
| 174 | TEST(abi, hf_vcpu_run_return_encode_message) |
| 175 | { |
| 176 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 177 | res.code = HF_VCPU_RUN_MESSAGE; |
Andrew Scull | b06d175 | 2019-02-04 10:15:48 +0000 | [diff] [blame] | 178 | res.message.vm_id = 0xf007; |
Andrew Scull | 8023236 | 2019-04-01 12:37:41 +0100 | [diff] [blame] | 179 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(0x0000000000f00705)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 180 | } |
| 181 | |
| 182 | /** |
| 183 | * Decode a wake up response ignoring the irrelevant bits. |
| 184 | */ |
| 185 | TEST(abi, hf_vcpu_run_return_decode_message) |
| 186 | { |
| 187 | struct hf_vcpu_run_return res = |
Andrew Scull | b06d175 | 2019-02-04 10:15:48 +0000 | [diff] [blame] | 188 | hf_vcpu_run_return_decode(0x1123581314916205); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 189 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_MESSAGE)); |
Andrew Scull | 8023236 | 2019-04-01 12:37:41 +0100 | [diff] [blame] | 190 | EXPECT_THAT(res.message.vm_id, Eq(0x9162)); |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 191 | } |
| 192 | |
| 193 | /** |
Andrew Scull | 9726c25 | 2019-01-23 13:44:19 +0000 | [diff] [blame] | 194 | * Encode a 'notify waiters' response without leaking. |
| 195 | */ |
| 196 | TEST(abi, hf_vcpu_run_return_encode_notify_waiters) |
| 197 | { |
| 198 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 199 | res.code = HF_VCPU_RUN_NOTIFY_WAITERS; |
| 200 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(6)); |
| 201 | } |
| 202 | |
| 203 | /** |
| 204 | * Decode a 'notify waiters' response ignoring the irrelevant bits. |
| 205 | */ |
| 206 | TEST(abi, hf_vcpu_run_return_decode_notify_waiters) |
| 207 | { |
| 208 | struct hf_vcpu_run_return res = |
| 209 | hf_vcpu_run_return_decode(0x1a1a1a1a2b2b2b06); |
| 210 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_NOTIFY_WAITERS)); |
| 211 | } |
| 212 | |
| 213 | /** |
| 214 | * Encode an aborted response without leaking. |
| 215 | */ |
| 216 | TEST(abi, hf_vcpu_run_return_encode_aborted) |
| 217 | { |
| 218 | struct hf_vcpu_run_return res = dirty_vcpu_run_return(); |
| 219 | res.code = HF_VCPU_RUN_ABORTED; |
| 220 | EXPECT_THAT(hf_vcpu_run_return_encode(res), Eq(7)); |
| 221 | } |
| 222 | |
| 223 | /** |
| 224 | * Decode an aborted response ignoring the irrelevant bits. |
| 225 | */ |
| 226 | TEST(abi, hf_vcpu_run_return_decode_aborted) |
| 227 | { |
| 228 | struct hf_vcpu_run_return res = |
| 229 | hf_vcpu_run_return_decode(0x31dbac4810fbc507); |
| 230 | EXPECT_THAT(res.code, Eq(HF_VCPU_RUN_ABORTED)); |
| 231 | } |
| 232 | |
Andrew Scull | 6d2db33 | 2018-10-10 15:28:17 +0100 | [diff] [blame] | 233 | } /* namespace */ |