2 * FILE: ntoskrnl/ke/i386/trap.S
3 * COPYRIGHT: See COPYING in the top level directory
4 * PURPOSE: System Traps, Entrypoints and Exitpoints
5 * PROGRAMMER: Alex Ionescu (alex@relsoft.net)
6 * NOTE: See asmmacro.S for the shared entry/exit code.
9 /* INCLUDES ******************************************************************/
12 #include <internal/i386/asmmacro.S>
13 .intel_syntax noprefix
15 /* GLOBALS *******************************************************************/
19 /* This is the Software Interrupt Table that we handle in this file: */
20 idt _KiTrap0, INT_32_DPL0 /* INT 00: Divide Error (#DE) */
21 idt _KiTrap1, INT_32_DPL0 /* INT 01: Debug Exception (#DB) */
22 idt _KiTrap2, INT_32_DPL0 /* INT 02: NMI Interrupt */
23 idt _KiTrap3, INT_32_DPL3 /* INT 03: Breakpoint Exception (#BP) */
24 idt _KiTrap4, INT_32_DPL3 /* INT 04: Overflow Exception (#OF) */
25 idt _KiTrap5, INT_32_DPL0 /* INT 05: BOUND Range Exceeded (#BR) */
26 idt _KiTrap6, INT_32_DPL0 /* INT 06: Invalid Opcode Code (#UD) */
27 idt _KiTrap7, INT_32_DPL0 /* INT 07: Device Not Available (#NM) */
28 idt _KiTrap8, INT_32_DPL0 /* INT 08: Double Fault Exception (#DF) */
29 idt _KiTrap9, INT_32_DPL0 /* INT 09: RESERVED */
30 idt _KiTrap10, INT_32_DPL0 /* INT 0A: Invalid TSS Exception (#TS) */
31 idt _KiTrap11, INT_32_DPL0 /* INT 0B: Segment Not Present (#NP) */
32 idt _KiTrap12, INT_32_DPL0 /* INT 0C: Stack Fault Exception (#SS) */
33 idt _KiTrap13, INT_32_DPL0 /* INT 0D: General Protection (#GP) */
34 idt _KiTrap14, INT_32_DPL0 /* INT 0E: Page-Fault Exception (#PF) */
35 idt _KiTrap0F, INT_32_DPL0 /* INT 0F: RESERVED */
36 idt _KiTrap16, INT_32_DPL0 /* INT 10: x87 FPU Error (#MF) */
37 idt _KiTrap17, INT_32_DPL0 /* INT 11: Align Check Exception (#AC) */
38 idt _KiTrap0F, INT_32_DPL0 /* INT 12: Machine Check Exception (#MC)*/
39 idt _KiTrap0F, INT_32_DPL0 /* INT 13: SIMD FPU Exception (#XF) */
41 idt _KiTrap0F, INT_32_DPL0 /* INT 14-29: UNDEFINED INTERRUPTS */
43 idt _KiGetTickCount, INT_32_DPL3 /* INT 2A: Get Tick Count Handler */
44 idt _KiCallbackReturn, INT_32_DPL3 /* INT 2B: User-Mode Callback Return */
45 idt _KiRaiseAssertion, INT_32_DPL3 /* INT 2C: Debug Assertion Handler */
46 idt _KiDebugService, INT_32_DPL3 /* INT 2D: Debug Service Handler */
47 idt _KiSystemService, INT_32_DPL3 /* INT 2E: System Call Service Handler */
48 idt _KiTrap0F, INT_32_DPL0 /* INT 2F: RESERVED */
49 GENERATE_IDT_STUBS /* INT 30-FF: UNEXPECTED INTERRUPTS */
51 /* System call entrypoints: */
52 .globl _KiFastCallEntry
53 .globl _KiSystemService
55 /* And special system-defined software traps: */
56 .globl _NtRaiseException@12
59 /* Interrupt template entrypoints */
60 .globl _KiInterruptTemplate
61 .globl _KiInterruptTemplateObject
62 .globl _KiInterruptTemplateDispatch
64 /* Chained and Normal generic interrupt handlers for 1st and 2nd level entry*/
65 .globl _KiChainedDispatch2ndLvl@0
66 .globl _KiInterruptDispatch@0
67 .globl _KiChainedDispatch@0
69 /* We implement the following trap exit points: */
70 .globl _KiServiceExit /* Exit from syscall */
71 .globl _KiServiceExit2 /* Exit from syscall with complete frame*/
72 .globl _Kei386EoiHelper@0 /* Exit from interrupt or H/W trap */
73 .globl _Kei386EoiHelper2ndEntry /* Exit from unexpected interrupt */
75 .globl _KiIdtDescriptor
80 .globl _KiUnexpectedEntrySize
81 _KiUnexpectedEntrySize:
82 .long _KiUnexpectedInterrupt1 - _KiUnexpectedInterrupt0
85 .asciz "\n\x7\x7!!! Unexpected Interrupt %02lx !!!\n"
88 .asciz "\n\x7\x7!!! Broken TrapFrame. Magic: %08lx MagicB: %08lx!!!\n"
90 /* SOFTWARE INTERRUPT SERVICES ***********************************************/
100 /* Enter the shared system call prolog */
103 /* Jump to the actual handler */
107 .func KiFastCallEntry
114 /* Set DS/ES to Kernel Selector */
115 mov ecx, KGDT_R0_DATA
119 /* Set the current stack to Kernel Stack */
120 mov ecx, [fs:KPCR_TSS]
121 mov esp, ss:[ecx+KTSS_ESP0]
123 /* Set up a fake INT Stack. */
124 push KGDT_R3_DATA + RPL_MASK
125 push edx /* Ring 3 SS:ESP */
126 pushf /* Ring 3 EFLAGS */
127 push 2 /* Ring 0 EFLAGS */
128 add edx, 8 /* Skip user parameter list */
129 popf /* Set our EFLAGS */
130 or dword ptr [esp], EFLAGS_INTERRUPT_MASK /* Re-enable IRQs in EFLAGS, to fake INT */
131 push KGDT_R3_CODE + RPL_MASK
132 push KUSER_SHARED_SYSCALL_RET
134 /* Setup the Trap Frame stack */
140 push KGDT_R3_TEB + RPL_MASK
142 /* Save pointer to our PCR */
143 mov ebx, [fs:KPCR_SELF]
145 /* Get a pointer to the current thread */
146 mov esi, [ebx+KPCR_CURRENT_THREAD]
148 /* Set the exception handler chain terminator */
149 push [ebx+KPCR_EXCEPTION_LIST]
150 mov dword ptr [ebx+KPCR_EXCEPTION_LIST], -1
152 /* Use the thread's stack */
153 mov ebp, [esi+KTHREAD_INITIAL_STACK]
155 /* Push previous mode */
158 /* Skip the other registers */
161 /* Hack: it seems that on VMWare someone damages ES/DS on exit. Investigate! */
162 mov dword ptr [esp+KTRAP_FRAME_DS], KGDT_R3_DATA + RPL_MASK
163 mov dword ptr [esp+KTRAP_FRAME_ES], KGDT_R3_DATA + RPL_MASK
165 /* Make space for us on the stack */
168 /* Write the previous mode */
169 mov byte ptr [esi+KTHREAD_PREVIOUS_MODE], UserMode
176 and dword ptr [ebp+KTRAP_FRAME_DR7], 0
178 /* Check if the thread was being debugged */
179 test byte ptr [esi+KTHREAD_DEBUG_ACTIVE], 0xFF
181 /* Set the thread's trap frame */
182 mov [esi+KTHREAD_TRAP_FRAME], ebp
184 /* Save DR registers if needed */
185 //jnz Dr_FastCallDrSave
187 /* Set the trap frame debug header */
190 /* Enable interrupts */
196 * Find out which table offset to use. Converts 0x1124 into 0x10.
197 * The offset is related to the Table Index as such: Offset = TableIndex x 10
200 shr edi, SERVICE_TABLE_SHIFT
201 and edi, SERVICE_TABLE_MASK
204 /* Now add the thread's base system table to the offset */
205 add edi, [esi+KTHREAD_SERVICE_TABLE]
207 /* Get the true syscall ID and check it */
209 and eax, SERVICE_NUMBER_MASK
210 cmp eax, [edi+SERVICE_DESCRIPTOR_LIMIT]
212 /* Invalid ID, try to load Win32K Table */
213 jnb KiBBTUnexpectedRange
215 /* Check if this was Win32K */
216 cmp ecx, SERVICE_TABLE_TEST
220 mov ecx, [fs:KPCR_TEB]
222 /* Check if we should flush the User Batch */
224 or ebx, [ecx+TEB_GDI_BATCH_COUNT]
230 //call [_KeGdiFlushUserBatch]
235 /* Increase total syscall count */
236 inc dword ptr fs:[KPCR_SYSTEM_CALLS]
239 /* Increase per-syscall count */
240 mov ecx, [edi+SERVICE_DESCRIPTOR_COUNT]
242 inc dword ptr [ecx+eax*4]
245 /* Users's current stack frame pointer is source */
249 /* Allocate room for argument list from kernel stack */
250 mov ebx, [edi+SERVICE_DESCRIPTOR_NUMBER]
254 /* Get pointer to function */
255 mov edi, [edi+SERVICE_DESCRIPTOR_BASE]
258 /* Allocate space on our stack */
261 /* Set the size of the arguments and the destination */
265 /* Make sure we're within the User Probe Address */
266 cmp esi, _MmUserProbeAddress
270 /* Copy the parameters */
275 * The following lines are for the benefit of GDB. It will see the return
276 * address of the "call ebx" below, find the last label before it and
277 * thinks that that's the start of the function. It will then check to see
278 * if it starts with a standard function prolog (push ebp, mov ebp,esp1).
279 * When that standard function prolog is not found, it will stop the
280 * stack backtrace. Since we do want to backtrace into usermode, let's
281 * make GDB happy and create a standard prolog.
289 /* Do the System Call */
294 /* Make sure the user-mode call didn't return at elevated IRQL */
295 test byte ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
297 mov esi, eax /* We need to save the syscall's return val */
298 call _KeGetCurrentIrql@0
301 mov eax, esi /* Restore it */
303 /* Get our temporary current thread pointer for sanity check */
304 mov ecx, fs:[KPCR_CURRENT_THREAD]
306 /* Make sure that we are not attached and that APCs are not disabled */
307 mov dl, [ecx+KTHREAD_APC_STATE_INDEX]
310 mov edx, [ecx+KTHREAD_COMBINED_APC_DISABLE]
317 /* Deallocate the kernel stack frame */
320 KeReturnFromSystemCall:
322 /* Get the Current Thread */
323 mov ecx, [fs:KPCR_CURRENT_THREAD]
325 /* Restore the old trap frame pointer */
326 mov edx, [ebp+KTRAP_FRAME_EDX]
327 mov [ecx+KTHREAD_TRAP_FRAME], edx
332 /* Disable interrupts */
335 /* Check for, and deliver, User-Mode APCs if needed */
336 CHECK_FOR_APC_DELIVER 1
338 /* Hack for VMWare: Sometimes ES/DS seem to be invalid when returning to user-mode. Investigate! */
339 mov es, [ebp+KTRAP_FRAME_ES]
340 mov ds, [ebp+KTRAP_FRAME_DS]
342 /* Exit and cleanup */
343 TRAP_EPILOG FromSystemCall, DoRestorePreviousMode, DoNotRestoreSegments, DoNotRestoreVolatiles, DoRestoreEverything
346 KiBBTUnexpectedRange:
348 /* If this isn't a Win32K call, fail */
349 cmp ecx, SERVICE_TABLE_TEST
352 /* Set up Win32K Table */
355 call _PsConvertToGuiThread@0
357 /* Check return code */
360 /* Restore registers */
364 /* Reset trap frame address */
366 mov [esi+KTHREAD_TRAP_FRAME], ebp
368 /* Try the Call again, if we suceeded */
372 * The Shadow Table should have a special byte table which tells us
373 * whether we should return FALSE, -1 or STATUS_INVALID_SYSTEM_SERVICE.
376 /* Get the table limit and base */
377 lea edx, _KeServiceDescriptorTableShadow + SERVICE_TABLE_TEST
378 mov ecx, [edx+SERVICE_DESCRIPTOR_LIMIT]
379 mov edx, [edx+SERVICE_DESCRIPTOR_BASE]
381 /* Get the table address and add our index into the array */
383 and eax, SERVICE_NUMBER_MASK
386 /* Find out what we should return */
387 movsx eax, byte ptr [edx]
390 /* Return either 0 or -1, we've set it in EAX */
391 jle KeReturnFromSystemCall
393 /* Set STATUS_INVALID_SYSTEM_SERVICE */
394 mov eax, STATUS_INVALID_SYSTEM_SERVICE
395 jmp KeReturnFromSystemCall
399 /* Invalid System Call */
400 mov eax, STATUS_INVALID_SYSTEM_SERVICE
401 jmp KeReturnFromSystemCall
405 /* Check if this came from kernel-mode */
406 test byte ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
408 /* It's fine, go ahead with it */
411 /* Caller sent invalid parameters, fail here */
412 mov eax, STATUS_ACCESS_VIOLATION
417 /* Restore ESP0 stack */
418 mov ecx, [fs:KPCR_TSS]
419 mov esp, ss:[ecx+KTSS_ESP0]
421 /* Generate V86M Stack for Trap 6 */
427 /* Generate interrupt stack for Trap 6 */
428 push KGDT_R3_DATA + RPL_MASK
431 push KGDT_R3_CODE + RPL_MASK
437 /* Save current IRQL */
440 /* Set us at passive */
441 mov dword ptr fs:[KPCR_IRQL], 0
449 push IRQL_GT_ZERO_AT_SYSTEM_SERVICE
450 call _KeBugCheckEx@20
454 /* Get the index and APC state */
455 movzx eax, byte ptr [ecx+KTHREAD_APC_STATE_INDEX]
456 mov edx, [ecx+KTHREAD_COMBINED_APC_DISABLE]
463 push APC_INDEX_MISMATCH
464 call _KeBugCheckEx@20
471 /* Disable interrupts */
474 /* Check for, and deliver, User-Mode APCs if needed */
475 CHECK_FOR_APC_DELIVER 0
477 /* Exit and cleanup */
478 TRAP_EPILOG NotFromSystemCall, DoRestorePreviousMode, DoRestoreSegments, DoRestoreVolatiles, DoNotRestoreEverything
481 .func Kei386EoiHelper@0
484 /* Disable interrupts */
487 /* Check for, and deliver, User-Mode APCs if needed */
488 CHECK_FOR_APC_DELIVER 0
490 /* Exit and cleanup */
491 _Kei386EoiHelper2ndEntry:
492 TRAP_EPILOG NotFromSystemCall, DoNotRestorePreviousMode, DoRestoreSegments, DoRestoreVolatiles, DoNotRestoreEverything
496 /* Move to EDX position */
497 add esp, KTRAP_FRAME_EDX
499 /* Restore volatiles */
504 /* Move to non-volatiles */
505 lea esp, [ebp+KTRAP_FRAME_EDI]
511 /* Skip error code and return */
516 /* Not yet supported */
522 /* Push error code */
528 /* Increase EIP so we skip the INT3 */
529 //inc dword ptr [ebp+KTRAP_FRAME_EIP]
531 /* Call debug service dispatcher */
532 mov eax, [ebp+KTRAP_FRAME_EAX]
533 mov ecx, [ebp+KTRAP_FRAME_ECX]
534 mov edx, [ebp+KTRAP_FRAME_EAX]
536 /* Check for V86 mode */
537 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
540 /* Check if this is kernel or user-mode */
541 test byte ptr [ebp+KTRAP_FRAME_CS], 1
543 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R3_CODE + RPL_MASK
546 /* Re-enable interrupts */
550 /* Call the debug routine */
559 call _KdpServiceDispatcher@12
563 /* Get the current process */
564 mov ebx, [fs:KPCR_CURRENT_THREAD]
565 mov ebx, [ebx+KTHREAD_APCSTATE_PROCESS]
567 /* Check if this is a VDM Process */
568 //cmp dword ptr [ebx+KPROCESS_VDM_OBJECTS], 0
571 /* Exit through common routine */
572 jmp _Kei386EoiHelper@0
575 .func NtRaiseException@12
576 _NtRaiseException@12:
578 /* NOTE: We -must- be called by Zw* to have the right frame! */
579 /* Push the stack frame */
582 /* Get the current thread and restore its trap frame */
583 mov ebx, [fs:KPCR_CURRENT_THREAD]
584 mov edx, [ebp+KTRAP_FRAME_EDX]
585 mov [ebx+KTHREAD_TRAP_FRAME], edx
587 /* Set up stack frame */
590 /* Get the Trap Frame in EBX */
593 /* Get the exception list and restore */
594 mov eax, [ebx+KTRAP_FRAME_EXCEPTION_LIST]
595 mov [fs:KPCR_EXCEPTION_LIST], eax
597 /* Get the parameters */
598 mov edx, [ebp+16] /* Search frames */
599 mov ecx, [ebp+12] /* Context */
600 mov eax, [ebp+8] /* Exception Record */
602 /* Raise the exception */
608 call _KiRaiseException@20
610 /* Restore trap frame in EBP */
614 /* Check the result */
618 /* Restore debug registers too */
625 /* NOTE: We -must- be called by Zw* to have the right frame! */
626 /* Push the stack frame */
629 /* Get the current thread and restore its trap frame */
630 mov ebx, [fs:KPCR_CURRENT_THREAD]
631 mov edx, [ebp+KTRAP_FRAME_EDX]
632 mov [ebx+KTHREAD_TRAP_FRAME], edx
634 /* Set up stack frame */
637 /* Save the parameters */
641 /* Call KiContinue */
647 /* Check if we failed (bad context record) */
651 /* Check if test alert was requested */
652 cmp dword ptr [ebp+12], 0
655 /* Test alert for the thread */
656 mov al, [ebx+KTHREAD_PREVIOUS_MODE]
658 call _KeTestAlertThread@4
661 /* Return to previous context */
672 /* EXCEPTION DISPATCHERS *****************************************************/
674 .func CommonDispatchException
675 _CommonDispatchException:
677 /* Make space for an exception record */
678 sub esp, EXCEPTION_RECORD_LENGTH
681 mov [esp+EXCEPTION_RECORD_EXCEPTION_CODE], eax
683 mov [esp+EXCEPTION_RECORD_EXCEPTION_FLAGS], eax
684 mov [esp+EXCEPTION_RECORD_EXCEPTION_RECORD], eax
685 mov [esp+EXCEPTION_RECORD_EXCEPTION_ADDRESS], ebx
686 mov [esp+EXCEPTION_RECORD_NUMBER_PARAMETERS], ecx
688 /* Check parameter count */
692 /* Get information */
693 lea ebx, [esp+SIZEOF_EXCEPTION_RECORD]
700 /* Set the record in ECX and check if this was V86 */
702 test dword ptr [esp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
711 /* Calculate the previous mode */
712 mov eax, [ebp+KTRAP_FRAME_CS]
716 /* Dispatch the exception */
722 call _KiDispatchException@20
726 jmp _Kei386EoiHelper@0
729 .func DispatchNoParam
731 /* Call the common dispatcher */
733 call _CommonDispatchException
736 .func DispatchOneParam
738 /* Call the common dispatcher */
741 call _CommonDispatchException
744 .func DispatchTwoParam
746 /* Call the common dispatcher */
749 call _CommonDispatchException
752 /* HARDWARE TRAP HANDLERS ****************************************************/
756 /* Push error code */
763 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
766 /* Check if the frame was from kernelmode */
767 test word ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
770 /* Check the old mode */
771 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R3_CODE + RPL_MASK
775 /* Re-enable interrupts for user-mode and send the exception */
777 mov eax, STATUS_INTEGER_DIVIDE_BY_ZERO
778 mov ebx, [ebp+KTRAP_FRAME_EIP]
782 /* Check if this is a VDM process */
783 mov ebx, [fs:KPCR_CURRENT_THREAD]
784 mov ebx, [ebx+KTHREAD_APCSTATE_PROCESS]
785 cmp dword ptr [ebx+EPROCESS_VDM_OBJECTS], 0
788 /* We don't support this yet! */
795 /* Push error code */
802 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
805 /* Check if the frame was from kernelmode */
806 test word ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
809 /* Check the old mode */
810 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R3_CODE + RPL_MASK
814 /* Enable interrupts for user-mode */
818 /* Prepare the exception */
819 and dword ptr [ebp+KTRAP_FRAME_EFLAGS], ~EFLAGS_TF
820 mov ebx, [ebp+KTRAP_FRAME_EIP]
821 mov eax, STATUS_SINGLE_STEP
825 /* Check if this is a VDM process */
826 mov ebx, [fs:KPCR_CURRENT_THREAD]
827 mov ebx, [ebx+KTHREAD_APCSTATE_PROCESS]
828 cmp dword ptr [ebx+EPROCESS_VDM_OBJECTS], 0
831 /* We don't support VDM! */
838 /* FIXME: This is an NMI, nothing like a normal exception */
840 jmp _KiSystemFatalException
845 /* Push error code */
852 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
855 /* Check if the frame was from kernelmode */
856 test word ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
859 /* Check the old mode */
860 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R3_CODE + RPL_MASK
864 /* Enable interrupts for user-mode */
868 /* Prepare the exception */
873 /* Setup EIP, NTSTATUS and parameter count, then dispatch */
874 mov ebx, [ebp+KTRAP_FRAME_EIP]
876 mov eax, STATUS_BREAKPOINT
878 call _CommonDispatchException
881 /* Check if this is a VDM process */
882 mov ebx, [fs:KPCR_CURRENT_THREAD]
883 mov ebx, [ebx+KTHREAD_APCSTATE_PROCESS]
884 cmp dword ptr [ebx+EPROCESS_VDM_OBJECTS], 0
887 /* We don't support VDM! */
893 /* Push error code */
900 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
903 /* Check if the frame was from kernelmode */
904 test word ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
907 /* Check the old mode */
908 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R3_CODE + RPL_MASK
912 /* Re-enable interrupts for user-mode and send the exception */
914 mov eax, STATUS_INTEGER_OVERFLOW
915 mov ebx, [ebp+KTRAP_FRAME_EIP]
920 /* Check if this is a VDM process */
921 mov ebx, [fs:KPCR_CURRENT_THREAD]
922 mov ebx, [ebx+KTHREAD_APCSTATE_PROCESS]
923 cmp dword ptr [ebx+EPROCESS_VDM_OBJECTS], 0
926 /* We don't support this yet! */
933 /* Push error code */
940 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
943 /* Check if the frame was from kernelmode */
944 test word ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
947 /* It did, and this should never happen */
949 jmp _KiSystemFatalException
951 /* Check the old mode */
953 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R3_CODE + RPL_MASK
956 /* Re-enable interrupts for user-mode and send the exception */
959 mov eax, STATUS_ARRAY_BOUNDS_EXCEEDED
960 mov ebx, [ebp+KTRAP_FRAME_EIP]
964 /* Check if this is a VDM process */
965 mov ebx, [fs:KPCR_CURRENT_THREAD]
966 mov ebx, [ebx+KTHREAD_APCSTATE_PROCESS]
967 cmp dword ptr [ebx+EPROCESS_VDM_OBJECTS], 0
970 /* We don't support this yet! */
977 /* Push error code */
983 /* Call the C exception handler */
989 /* Check for v86 recovery */
992 /* Return to caller */
993 jne _Kei386EoiHelper@0
999 /* Push error code */
1005 /* Get the current thread and stack */
1007 mov eax, [fs:KPCR_CURRENT_THREAD]
1008 mov ecx, [eax+KTHREAD_INITIAL_STACK]
1009 sub ecx, NPX_FRAME_LENGTH
1011 /* Check if emulation is enabled */
1012 test dword ptr [ecx+FN_CR0_NPX_STATE], CR0_EM
1013 jnz EmulationEnabled
1016 /* Check if the NPX state is loaded */
1017 cmp byte ptr [eax+KTHREAD_NPX_STATE], NPX_STATE_LOADED
1022 and ebx, ~(CR0_MP + CR0_TS + CR0_EM)
1025 /* Check the NPX thread */
1026 mov edx, [fs:KPCR_NPX_THREAD]
1030 /* Get the NPX Stack */
1031 mov esi, [edx+KTHREAD_INITIAL_STACK]
1032 sub esi, NPX_FRAME_LENGTH
1034 /* Check if we have FXSR and check which operand to use */
1035 test byte ptr _KeI386FxsrPresent, 1
1044 /* Set the thread's state to dirty */
1045 mov byte ptr [edx+KTHREAD_NPX_STATE], NPX_STATE_NOT_LOADED
1048 /* Check if we have FXSR and choose which operand to use */
1049 test byte ptr _KeI386FxsrPresent, 1
1058 /* Set state loaded */
1059 mov byte ptr [eax+KTHREAD_NPX_STATE], NPX_STATE_LOADED
1060 mov [fs:KPCR_NPX_THREAD], eax
1062 /* Enable interrupts to happen now */
1066 /* Check if CR0 needs to be reloaded due to a context switch */
1067 cmp dword ptr [ecx+FN_CR0_NPX_STATE], 0
1068 jz _Kei386EoiHelper@0
1070 /* We have to reload CR0... disable interrupts */
1073 /* Get CR0 and update it */
1075 or ebx, [ecx+FN_CR0_NPX_STATE]
1078 /* Restore interrupts and check if TS is back on */
1081 jz _Kei386EoiHelper@0
1083 /* Clear TS, and loop handling again */
1089 /* Check if TS is set */
1091 jnz TsSetOnLoadedState
1093 /* Check if the trap came from user-mode */
1097 /* Did this come from kernel-mode? */
1098 cmp word ptr [ebp+KTRAP_FRAME_CS], KGDT_R0_CODE
1101 /* It came from user-mode, so this would only be valid inside a VDM */
1102 /* Since we don't actually have VDMs in ROS, bugcheck. */
1106 /* TS shouldn't be set, unless this we don't have a Math Processor */
1110 /* Strange that we got a trap at all, but ignore and continue */
1112 jmp _Kei386EoiHelper@0
1115 /* Cause a bugcheck */
1121 push TRAP_CAUSE_UNKNOWN
1122 call _KeBugCheckEx@20
1125 /* Cause a bugcheck */
1130 push TRAP_CAUSE_UNKNOWN
1131 call _KeBugCheckEx@20
1138 /* Can't really do too much */
1140 jmp _KiSystemFatalException
1145 /* Push error code */
1151 /* Enable interrupts and bugcheck */
1154 jmp _KiSystemFatalException
1163 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAGS_V86_MASK
1166 /* Check if the frame was from kernelmode */
1167 test word ptr [ebp+KTRAP_FRAME_CS], MODE_MASK
1171 /* Check if OF was set during iretd */
1172 test dword ptr [ebp+KTRAP_FRAME_EFLAGS], EFLAG_ZERO
1176 /* It was, just mask it out */
1177 and dword ptr [ebp+KTRAP_FRAME_EFLAGS], ~EFLAG_ZERO
1178 jmp _Kei386EoiHelper@0
1181 /* TSS failure for some other reason: crash */
1183 jmp _KiSystemFatalException
1191 /* FIXME: ROS Doesn't handle segment faults yet */
1193 jmp _KiSystemFatalException
1201 /* FIXME: ROS Doesn't handle stack faults yet */
1203 jmp _KiSystemFatalException
1211 /* Call the C exception handler */
1217 /* Check for v86 recovery */
1220 /* Return to caller */
1221 jne _Kei386EoiHelper@0
1230 /* Call the C exception handler */
1233 call _KiPageFaultHandler
1236 /* Return to caller */
1237 jmp _Kei386EoiHelper@0
1242 /* Push error code */
1249 /* Raise a fatal exception */
1251 jmp _KiSystemFatalException
1256 /* Push error code */
1262 /* FIXME: ROS Doesn't handle FPU faults yet */
1264 jmp _KiSystemFatalException
1269 /* Push error code */
1275 /* FIXME: ROS Doesn't handle alignment faults yet */
1277 jmp _KiSystemFatalException
1280 .func KiSystemFatalException
1281 _KiSystemFatalException:
1283 /* Push the trap frame */
1286 /* Push empty parameters */
1291 /* Push trap number and bugcheck code */
1293 push UNEXPECTED_KERNEL_MODE_TRAP
1294 call _KeBugCheckWithTf@24
1298 /* UNEXPECTED INTERRUPT HANDLERS **********************************************/
1300 .globl _KiStartUnexpectedRange@0
1301 _KiStartUnexpectedRange@0:
1303 GENERATE_INT_HANDLERS
1305 .globl _KiEndUnexpectedRange@0
1306 _KiEndUnexpectedRange@0:
1307 jmp _KiUnexpectedInterruptTail
1309 .func KiUnexpectedInterruptTail
1310 _KiUnexpectedInterruptTail:
1312 /* Enter interrupt trap */
1313 INT_PROLOG kui, DoNotPushFakeErrorCode
1315 /* Increase interrupt count */
1316 inc dword ptr [fs:KPCR_PRCB_INTERRUPT_COUNT]
1318 /* Put vector in EBX and make space for KIRQL */
1322 /* Begin interrupt */
1326 call _HalBeginSystemInterrupt@12
1328 /* Check if it was spurious or not */
1332 /* Spurious, ignore it */
1334 jmp _Kei386EoiHelper2ndEntry
1337 /* Unexpected interrupt, print a message on debug builds */
1340 push offset _UnexpectedMsg
1345 /* Exit the interrupt */
1348 call _HalEndSystemInterrupt@8
1349 jmp _Kei386EoiHelper@0
1352 .globl _KiUnexpectedInterrupt
1353 _KiUnexpectedInterrupt:
1355 /* Bugcheck with invalid interrupt code */
1359 /* INTERRUPT HANDLERS ********************************************************/
1361 .func KiInterruptTemplate
1362 _KiInterruptTemplate:
1364 /* Enter interrupt trap */
1365 INT_PROLOG kit, DoPushFakeErrorCode
1368 _KiInterruptTemplate2ndDispatch:
1369 /* Dummy code, will be replaced by the address of the KINTERRUPT */
1372 _KiInterruptTemplateObject:
1373 /* Dummy jump, will be replaced by the actual jump */
1374 jmp _KeSynchronizeExecution@12
1376 _KiInterruptTemplateDispatch:
1377 /* Marks the end of the template so that the jump above can be edited */
1379 .func KiChainedDispatch2ndLvl@0
1380 _KiChainedDispatch2ndLvl@0:
1382 /* Not yet supported */
1386 .func KiChainedDispatch@0
1387 _KiChainedDispatch@0:
1389 /* Increase interrupt count */
1390 inc dword ptr [fs:KPCR_PRCB_INTERRUPT_COUNT]
1392 /* Save trap frame */
1395 /* Save vector and IRQL */
1396 mov eax, [edi+KINTERRUPT_VECTOR]
1397 mov ecx, [edi+KINTERRUPT_IRQL]
1403 /* Begin interrupt */
1407 call _HalBeginSystemInterrupt@12
1409 /* Check if it was handled */
1413 /* Call the 2nd-level handler */
1414 call _KiChainedDispatch2ndLvl@0
1416 /* Exit the interrupt */
1419 call _HalEndSystemInterrupt@8
1420 jmp _Kei386EoiHelper@0
1423 .func KiInterruptDispatch@0
1424 _KiInterruptDispatch@0:
1426 /* Increase interrupt count */
1427 inc dword ptr [fs:KPCR_PRCB_INTERRUPT_COUNT]
1429 /* Save trap frame */
1432 /* Save vector and IRQL */
1433 mov eax, [edi+KINTERRUPT_VECTOR]
1434 mov ecx, [edi+KINTERRUPT_SYNCHRONIZE_IRQL]
1440 /* Begin interrupt */
1444 call _HalBeginSystemInterrupt@12
1446 /* Check if it was handled */
1451 /* Acquire the lock */
1453 mov esi, [edi+KINTERRUPT_ACTUAL_LOCK]
1454 ACQUIRE_SPINLOCK(esi, IntSpin)
1457 mov eax, [edi+KINTERRUPT_SERVICE_CONTEXT]
1460 call [edi+KINTERRUPT_SERVICE_ROUTINE]
1462 /* Release the lock */
1463 RELEASE_SPINLOCK(esi)
1465 /* Clean up the stack */
1468 /* Exit the interrupt */
1471 call _HalEndSystemInterrupt@8
1472 jmp _Kei386EoiHelper@0
1475 /* Exit the interrupt */
1478 jmp _Kei386EoiHelper@0
1482 SPIN_ON_LOCK esi, GetIntLock