rtdrv.s 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321
  1. # rtdrv.s -- call runtime entries, with known arguments, and report what
  2. # happened. Assembled by tests/rt_exec.py into a complete .COM image.
  3. #
  4. # This replaces the Unicorn harness. The expectations did not change; only the
  5. # machine did. Everything here exists because qemu, unlike an emulator with a
  6. # Python API, gives you one thing: a serial port. So a check has to be
  7. # expressed as a program that reports on itself.
  8. #
  9. # The report is a framed record on the serial port:
  10. #
  11. # 01 <case index, 2 hex digits> 02 <whatever the entries printed> 03
  12. # <dumplen bytes at dumpaddr, 2 hex digits each> 04
  13. #
  14. # The four control bytes occur in no expected output, and rt_exec.py REFUSES to
  15. # run a case whose expectation contains one -- so a marker can never be mistaken
  16. # for output, and a driver that emitted nothing is a parse failure rather than
  17. # a silent pass.
  18. #
  19. # Why one qemu boot per check instead of one boot for all of them: the runtime
  20. # keeps state that outlives a call -- the one-character pushback slot, and the
  21. # input cursor the boot sector's INT 21h shim owns. One boot for everything
  22. # would make each check depend on the ones before it, so a check could fail
  23. # because of its neighbour and a green run would prove less than it appears to.
  24. # A boot costs about a tenth of a second and 35 of them cost under four, which
  25. # buys every check a machine that has provably never executed anything. (The
  26. # input descriptor is still re-armed on every boot, because it lives in the
  27. # image and the image is the same bytes each time.)
  28. #
  29. # Two things about the 8086 shape the code below, and both were found by
  30. # running it rather than by reading it:
  31. #
  32. # * Every entry preserves BP and SP and NO other register. So the cursor
  33. # into the case record is BP: a loop counter in CX or DI would be destroyed
  34. # by the first call. The entry's own BP frame is pushed and restored, so
  35. # our BP comes back.
  36. #
  37. # * `movb n(%bp), %cl' leaves the HIGH byte of CX exactly as it was. Reading
  38. # the input length that way and then writing CX to INLEN handed the boot
  39. # sector's INT 21h shim a 16-bit length with an undefined top half. The
  40. # 8086 has no memory-to-memory move and no zero-extending byte load, so the
  41. # high half has to be cleared by hand, every time.
  42. #
  43. # * `dec' sets the sign flag from the RESULT, so `decw cnt / js done' runs the
  44. # body for cnt = 1 (1 -> 0, SF clear) and stops on the wrap (0 -> FFFF).
  45. # It reads like an off-by-one and is not; the comment at the loop says so
  46. # again because the next person will wonder.
  47. #
  48. # The image is assembled in ONE piece, here, so every address is a label or an
  49. # .org and nothing has to be agreed with Python in two places. What Python does
  50. # have to agree about -- the runtime's base, and the input descriptor -- is
  51. # checked rather than trusted: it assembles this file and then asserts that the
  52. # blob it got from RtProbe really is at RT_BASE in the bytes that came out.
  53. .set LOAD_BIAS, 0x0100 # a .COM lives at CS:0100 (that is the PSP)
  54. .set SOH, 0x01
  55. .set STX, 0x02
  56. .set ETX, 0x03
  57. .set EOT, 0x04
  58. # Restated from tests/exec/bootcom.s's layout block ON PURPOSE. A harness that
  59. # asks the boot sector where its input buffer is proves only that the two agree
  60. # with each other; two independent statements of the same layout have to be
  61. # written down, and a disagreement is a loud failure rather than a program that
  62. # is fed nothing. (Same reasoning, and the same lesson, as the hard-coded
  63. # RT_SZ that run_com_tests.sh used to carry: the descriptor has to be where the
  64. # shim looks, and the only way to be sure is to have written both down and
  65. # checked.)
  66. .set INLEN, 0x2000 # word: how many input bytes follow
  67. .set INCUR, 0x2002 # word: index into INBUF, NOT an address
  68. .set INBUF, 0x2004 # the bytes themselves
  69. # The case record, as rt_exec.py writes it. These offsets are the contract; the
  70. # two places that read them (this file, and case_bytes() over there) are
  71. # separate statements of it on purpose, and the cases only pass if both are
  72. # right. SLOT0 is the one that was wrong the first time round.
  73. .set OFF_DUMPLEN, 0 # word how many bytes to report
  74. .set OFF_DUMPADR, 2 # word image offset to report them from
  75. .set OFF_INLEN, 4 # byte bytes of input to hand the shim
  76. .set OFF_INBUF, 5 # byte inbuf[8]
  77. .set OFF_CASE, 13 # byte the index printed in the header
  78. .set OFF_NCALLS, 14 # word how many call slots follow
  79. .set SLOT0, 16 # call slots, 6 bytes each:
  80. # +0 word entry, +2 word arg,
  81. # +4 byte flags, +5 pad
  82. .set SLOT_SZ, 6
  83. .set CASE_SZ, 40 # 16 + 4 slots
  84. # The image layout. RT_BASE is where the runtime blob goes; everything else is
  85. # above 0x0800 so that a runtime which grew by a few hundred bytes would not
  86. # silently run into the test scaffolding. rt_exec.py asserts
  87. # RT_BASE + blob size <= HDR, so the bound is a checked one.
  88. .set RT_BASE, 0x0200
  89. .set HDR, 0x0800
  90. .set DATA, 0x0810
  91. .set DLEN, 32 # bytes of data area for initmem to clear
  92. .set STORE, 0x0840 # where a read entry's result is stored
  93. .set CASE, 0x0860 # the case record
  94. .set D_DUMPLEN, 0x0890 # the driver's own three words
  95. .set D_DUMPADR, 0x0892
  96. .set D_CNT, 0x0894
  97. .code16
  98. .text
  99. .globl _start
  100. # The entry JMP -- the same three bytes every image this compiler writes opens
  101. # with. bootcom.s jumps to 0000:0100, which is this instruction. It is
  102. # written as raw bytes rather than `jmp drive' because gas would shorten that to
  103. # a two-byte EB 00 short jump, and the byte it dropped would then be executed as
  104. # the first instruction of the driver.
  105. _start:
  106. .byte 0xE9 # JMP rel16
  107. .word drive - _start - 3
  108. # --------------------------------------------------------------- the driver
  109. drive:
  110. cld
  111. # 1. Poison the two places a check is allowed to look. STORE gets EEEH so
  112. # a read entry that stores nothing is visible as such, and the data
  113. # area gets AAH so initmem has something to clear. The storage below
  114. # is zeroed; the poison is what turns a zero into a RESULT.
  115. movw $STORE + LOAD_BIAS, %si
  116. movw $0xEEEE, %ax
  117. movw %ax, (%si)
  118. movw $DATA + LOAD_BIAS, %si
  119. movw $DLEN, %cx
  120. movb $0xAA, %al
  121. .Lpoison:
  122. movb %al, (%si)
  123. incw %si
  124. loop .Lpoison
  125. # BP is the case-record cursor, and it is the only register that survives a
  126. # call into the runtime, so everything the loop needs is read through it
  127. # or parked in the driver's own words first.
  128. movw $CASE + LOAD_BIAS, %bp
  129. # 2. Open the record: SOH, the case index as two hex digits, STX.
  130. movb $SOH, %al
  131. call putc
  132. movb OFF_CASE(%bp), %al
  133. call hexb
  134. movb $STX, %al
  135. call putc
  136. # 3. Arm the input. INCUR is an INDEX into INBUF, and zeroing it is what
  137. # makes this boot's input start at its first byte. CX is cleared
  138. # first: see the note at the top about the high byte of CX.
  139. xorw %cx, %cx
  140. movb OFF_INLEN(%bp), %cl
  141. movw %cx, INLEN
  142. movw $0, INCUR
  143. movw $CASE + OFF_INBUF + LOAD_BIAS, %si
  144. movw $INBUF, %di
  145. xorw %ax, %ax
  146. repe cmpsb
  147. # 4. The calls. dumplen and the report address are needed after the loop,
  148. # by which time BP has moved, so they are parked now; so is the count,
  149. # because CX is gone by the second iteration.
  150. movw OFF_DUMPLEN(%bp), %ax
  151. movw %ax, D_DUMPLEN + LOAD_BIAS
  152. movw OFF_DUMPADR(%bp), %ax
  153. movw %ax, D_DUMPADR + LOAD_BIAS
  154. movw OFF_NCALLS(%bp), %ax
  155. movw %ax, D_CNT + LOAD_BIAS
  156. addw $SLOT0, %bp # BP now points AT the first call slot
  157. .Lcall:
  158. decw D_CNT + LOAD_BIAS # 1 -> 0 has SF clear, so the body runs once;
  159. jns .Lgo # 0 -> FFFF is what ends the loop
  160. jmp .Lcalldone
  161. .Lgo:
  162. call doslot
  163. addw $SLOT_SZ, %bp
  164. jmp .Lcall
  165. .Lcalldone:
  166. # 5. Close the output half and report the memory. A store that never
  167. # happened is the EEEH left in step 1, which is why it is there.
  168. movb $ETX, %al
  169. call putc
  170. movw D_DUMPLEN + LOAD_BIAS, %cx
  171. jcxz .Lnodump
  172. movw D_DUMPADR + LOAD_BIAS, %si
  173. addw $LOAD_BIAS, %si
  174. .Ldump:
  175. lodsb
  176. call hexb
  177. loop .Ldump
  178. .Lnodump:
  179. movb $EOT, %al
  180. call putc
  181. # 6. Exit. Reaching here IS the assertion that every entry returned: an
  182. # entry that hung produces no EOT, and the harness says so.
  183. movw $0x4C00, %ax # INT 21h AH=4Ch, AL=0
  184. int $0x21
  185. # doslot: call the entry described by the 6 bytes at BP, with the same
  186. # conventions Compiler.IoCall uses -- one 16-bit argument on the stack, popped
  187. # by the caller -- except for initmem, which takes the header in AX.
  188. #
  189. # The flags are re-read after the call because the entry has just used AX.
  190. doslot:
  191. movb 4(%bp), %al
  192. testb $1, %al
  193. jz .Lnostack
  194. pushw 2(%bp)
  195. .Lnostack:
  196. testb $2, %al
  197. jz .Lnoax
  198. movw 2(%bp), %ax
  199. .Lnoax:
  200. movw (%bp), %si # image-absolute, as RT_Entry reports it
  201. addw $LOAD_BIAS, %si # so the load bias is added here, not baked in
  202. testb $4, %al
  203. jnz .Linl
  204. call *%si
  205. movb 4(%bp), %al
  206. testb $1, %al
  207. jz .Lnoclean
  208. addw $2, %sp # caller-cleaned
  209. .Lnoclean:
  210. ret
  211. # wrtinl's argument is NOT a stack word: the entry reads a length byte and that
  212. # many characters from its own return address. That is the caller's half of
  213. # the contract, so it is written literally here -- the length byte and the
  214. # characters must be the bytes immediately after the call, which is why this is
  215. # a second copy of the instruction rather than a jump. The compiler's own
  216. # placement of the same three things is what the string-literal fixtures in
  217. # run_com_exec.py check; duplicating a variable one here would be a second
  218. # thing to keep right, and a check that cannot fail is not a check.
  219. .Linl:
  220. call *%si
  221. .byte 5
  222. .byte 'h', 'e', 'l', 'l', 'o'
  223. ret
  224. # putc: AL to the serial port. No status polling -- qemu's 16550 always accepts,
  225. # and a poll that never went ready would hang the harness instead of failing it.
  226. putc:
  227. pushw %ax
  228. movw $0x03f8, %dx
  229. outb %al, %dx
  230. popw %ax
  231. ret
  232. # hexb: AL as two uppercase hex digits, high nibble first.
  233. #
  234. # The 8086 has no `SHR r/m16, imm8' and no shift-by-four, so the high nibble
  235. # comes from four one-bit shifts through CL. Both facts have to be written
  236. # down: gas assembles `shr $4, %ah' without complaint and rejects `shrw $1, %ah'
  237. # outright, so the only thing standing between this file and an image that
  238. # assembles cleanly and dies on a real 8086 is refusing the modern encodings.
  239. hexb:
  240. pushw %ax
  241. pushw %cx
  242. movb %al, %ah
  243. movb $1, %cl
  244. shrw %cl, %ax
  245. shrw %cl, %ax
  246. shrw %cl, %ax
  247. shrw %cl, %ax
  248. popw %cx
  249. call putdig
  250. popw %ax
  251. andb $0x0f, %al
  252. movb %al, %ah
  253. call putdig
  254. ret
  255. # putdig: the nibble in AH as one character, moved into AL so that setting AH for
  256. # INT 21h AH=02h cannot overwrite the digit it is about to print.
  257. putdig:
  258. movb %ah, %al
  259. cmpb $10, %al
  260. jb .Ldigit
  261. addb $0x37, %al # 0Ah + 37h = 'A'
  262. jmp .Lemit
  263. .Ldigit:
  264. addb $0x30, %al # '0'
  265. .Lemit:
  266. movb $2, %ah
  267. int $0x21
  268. ret
  269. # --------------------------------------------------------------- the image
  270. # The runtime blob, from tests/RtProbe.mod built at RT_BASE. The gap is the
  271. # checked bound: rt_exec.py asserts that 0x0180..RT_BASE is still all zeros, so
  272. # a driver that outgrew its space fails the suite instead of overwriting the
  273. # library it is testing.
  274. .org RT_BASE
  275. .incbin "rtblob.bin"
  276. # The program header initmem is handed: +0 flag, +2 code, +4 data base, +6 data
  277. # end. Built HERE, from the same DATA and DLEN the poison loop uses, because
  278. # the compiler's own header layout is a separate claim with its own check and
  279. # this harness is not that check. The two fields initmem READS are memory
  280. # addresses, so they carry the bias; the caller passes AX the header's memory
  281. # address too, which is the one thing rt_exec.py gets right only by saying so
  282. # here and in case_bytes().
  283. .org HDR
  284. HDR:
  285. .word 1 # hdrFlag
  286. .word 0 # hdrCS, unused by initmem
  287. .word DATA + LOAD_BIAS # hdrDS = data base
  288. .word DATA + DLEN + LOAD_BIAS # hdrHeap = data end
  289. .org DATA
  290. .zero DLEN # poisoned to AAH by the driver
  291. .org STORE
  292. .zero 2 # poisoned to EEEH by the driver
  293. .org CASE
  294. .incbin "rtcase.bin"
  295. .org D_DUMPLEN
  296. .zero 6 # D_DUMPLEN, D_DUMPADR, D_CNT