VirtualBox

source: vbox/trunk/src/VBox/VMM/VMMR3/PGM.cpp

Last change on this file was 108968, checked in by vboxsync, 4 weeks ago

VMM,Main,Devices: Respect VBOX_VMM_TARGET_ARMV8 correctly on amd64 hosts (for IEM debugging purposes). jiraref:VBP-1598

  • Property svn:eol-style set to native
  • Property svn:keywords set to Id Revision
File size: 153.2 KB
Line 
1/* $Id: PGM.cpp 108968 2025-04-14 20:45:36Z vboxsync $ */
2/** @file
3 * PGM - Page Manager and Monitor. (Mixing stuff here, not good?)
4 */
5
6/*
7 * Copyright (C) 2006-2024 Oracle and/or its affiliates.
8 *
9 * This file is part of VirtualBox base platform packages, as
10 * available from https://www.215389.xyz.
11 *
12 * This program is free software; you can redistribute it and/or
13 * modify it under the terms of the GNU General Public License
14 * as published by the Free Software Foundation, in version 3 of the
15 * License.
16 *
17 * This program is distributed in the hope that it will be useful, but
18 * WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
20 * General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License
23 * along with this program; if not, see <https://www.gnu.org/licenses>.
24 *
25 * SPDX-License-Identifier: GPL-3.0-only
26 */
27
28
29/** @page pg_pgm PGM - The Page Manager and Monitor
30 *
31 * @sa @ref grp_pgm
32 * @subpage pg_pgm_pool
33 * @subpage pg_pgm_phys
34 *
35 *
36 * @section sec_pgm_modes Paging Modes
37 *
38 * There are three memory contexts: Host Context (HC), Guest Context (GC)
39 * and intermediate context. When talking about paging HC can also be referred
40 * to as "host paging", and GC referred to as "shadow paging".
41 *
42 * We define three basic paging modes: 32-bit, PAE and AMD64. The host paging mode
43 * is defined by the host operating system. The mode used in the shadow paging mode
44 * depends on the host paging mode and what the mode the guest is currently in. The
45 * following relation between the two is defined:
46 *
47 * @verbatim
48 Host > 32-bit | PAE | AMD64 |
49 Guest | | | |
50 ==v================================
51 32-bit 32-bit PAE PAE
52 -------|--------|--------|--------|
53 PAE PAE PAE PAE
54 -------|--------|--------|--------|
55 AMD64 AMD64 AMD64 AMD64
56 -------|--------|--------|--------| @endverbatim
57 *
58 * All configuration except those in the diagonal (upper left) are expected to
59 * require special effort from the switcher (i.e. a bit slower).
60 *
61 *
62 *
63 *
64 * @section sec_pgm_shw The Shadow Memory Context
65 *
66 *
67 * [..]
68 *
69 * Because of guest context mappings requires PDPT and PML4 entries to allow
70 * writing on AMD64, the two upper levels will have fixed flags whatever the
71 * guest is thinking of using there. So, when shadowing the PD level we will
72 * calculate the effective flags of PD and all the higher levels. In legacy
73 * PAE mode this only applies to the PWT and PCD bits (the rest are
74 * ignored/reserved/MBZ). We will ignore those bits for the present.
75 *
76 *
77 *
78 * @section sec_pgm_int The Intermediate Memory Context
79 *
80 * The world switch goes thru an intermediate memory context which purpose it is
81 * to provide different mappings of the switcher code. All guest mappings are also
82 * present in this context.
83 *
84 * The switcher code is mapped at the same location as on the host, at an
85 * identity mapped location (physical equals virtual address), and at the
86 * hypervisor location. The identity mapped location is for when the world
87 * switches that involves disabling paging.
88 *
89 * PGM maintain page tables for 32-bit, PAE and AMD64 paging modes. This
90 * simplifies switching guest CPU mode and consistency at the cost of more
91 * code to do the work. All memory use for those page tables is located below
92 * 4GB (this includes page tables for guest context mappings).
93 *
94 * Note! The intermediate memory context is also used for 64-bit guest
95 * execution on 32-bit hosts. Because we need to load 64-bit registers
96 * prior to switching to guest context, we need to be in 64-bit mode
97 * first. So, HM has some 64-bit worker routines in VMMRC.rc that get
98 * invoked via the special world switcher code in LegacyToAMD64.asm.
99 *
100 *
101 * @subsection subsec_pgm_int_gc Guest Context Mappings
102 *
103 * During assignment and relocation of a guest context mapping the intermediate
104 * memory context is used to verify the new location.
105 *
106 * Guest context mappings are currently restricted to below 4GB, for reasons
107 * of simplicity. This may change when we implement AMD64 support.
108 *
109 *
110 *
111 *
112 * @section sec_pgm_misc Misc
113 *
114 *
115 * @subsection sec_pgm_misc_A20 The A20 Gate
116 *
117 * PGM implements the A20 gate masking when translating a virtual guest address
118 * into a physical address for CPU access, i.e. PGMGstGetPage (and friends) and
119 * the code reading the guest page table entries during shadowing. The masking
120 * is done consistenly for all CPU modes, paged ones included. Large pages are
121 * also masked correctly. (On current CPUs, experiments indicates that AMD does
122 * not apply A20M in paged modes and intel only does it for the 2nd MB of
123 * memory.)
124 *
125 * The A20 gate implementation is per CPU core. It can be configured on a per
126 * core basis via the keyboard device and PC architecture device. This is
127 * probably not exactly how real CPUs do it, but SMP and A20 isn't a place where
128 * guest OSes try pushing things anyway, so who cares. (On current real systems
129 * the A20M signal is probably only sent to the boot CPU and it affects all
130 * thread and probably all cores in that package.)
131 *
132 * The keyboard device and the PC architecture device doesn't OR their A20
133 * config bits together, rather they are currently implemented such that they
134 * mirror the CPU state. So, flipping the bit in either of them will change the
135 * A20 state. (On real hardware the bits of the two devices should probably be
136 * ORed together to indicate enabled, i.e. both needs to be cleared to disable
137 * A20 masking.)
138 *
139 * The A20 state will change immediately, transmeta fashion. There is no delays
140 * due to buses, wiring or other physical stuff. (On real hardware there are
141 * normally delays, the delays differs between the two devices and probably also
142 * between chipsets and CPU generations. Note that it's said that transmeta CPUs
143 * does the change immediately like us, they apparently intercept/handles the
144 * port accesses in microcode. Neat.)
145 *
146 * @sa http://en.wikipedia.org/wiki/A20_line#The_80286_and_the_high_memory_area
147 *
148 *
149 * @subsection subsec_pgm_misc_diff Differences Between Legacy PAE and Long Mode PAE
150 *
151 * The differences between legacy PAE and long mode PAE are:
152 * -# PDPE bits 1, 2, 5 and 6 are defined differently. In leagcy mode they are
153 * all marked down as must-be-zero, while in long mode 1, 2 and 5 have the
154 * usual meanings while 6 is ignored (AMD). This means that upon switching to
155 * legacy PAE mode we'll have to clear these bits and when going to long mode
156 * they must be set. This applies to both intermediate and shadow contexts,
157 * however we don't need to do it for the intermediate one since we're
158 * executing with CR0.WP at that time.
159 * -# CR3 allows a 32-byte aligned address in legacy mode, while in long mode
160 * a page aligned one is required.
161 *
162 *
163 * @section sec_pgm_handlers Access Handlers
164 *
165 * Placeholder.
166 *
167 *
168 * @subsection sec_pgm_handlers_phys Physical Access Handlers
169 *
170 * Placeholder.
171 *
172 *
173 * @subsection sec_pgm_handlers_virt Virtual Access Handlers (obsolete)
174 *
175 * We currently implement three types of virtual access handlers: ALL, WRITE
176 * and HYPERVISOR (WRITE). See PGMVIRTHANDLERKIND for some more details.
177 *
178 * The HYPERVISOR access handlers is kept in a separate tree since it doesn't apply
179 * to physical pages (PGMTREES::HyperVirtHandlers) and only needs to be consulted in
180 * a special \#PF case. The ALL and WRITE are in the PGMTREES::VirtHandlers tree, the
181 * rest of this section is going to be about these handlers.
182 *
183 * We'll go thru the life cycle of a handler and try make sense of it all, don't know
184 * how successful this is gonna be...
185 *
186 * 1. A handler is registered thru the PGMR3HandlerVirtualRegister and
187 * PGMHandlerVirtualRegisterEx APIs. We check for conflicting virtual handlers
188 * and create a new node that is inserted into the AVL tree (range key). Then
189 * a full PGM resync is flagged (clear pool, sync cr3, update virtual bit of PGMPAGE).
190 *
191 * 2. The following PGMSyncCR3/SyncCR3 operation will first make invoke HandlerVirtualUpdate.
192 *
193 * 2a. HandlerVirtualUpdate will will lookup all the pages covered by virtual handlers
194 * via the current guest CR3 and update the physical page -> virtual handler
195 * translation. Needless to say, this doesn't exactly scale very well. If any changes
196 * are detected, it will flag a virtual bit update just like we did on registration.
197 * PGMPHYS pages with changes will have their virtual handler state reset to NONE.
198 *
199 * 2b. The virtual bit update process will iterate all the pages covered by all the
200 * virtual handlers and update the PGMPAGE virtual handler state to the max of all
201 * virtual handlers on that page.
202 *
203 * 2c. Back in SyncCR3 we will now flush the entire shadow page cache to make sure
204 * we don't miss any alias mappings of the monitored pages.
205 *
206 * 2d. SyncCR3 will then proceed with syncing the CR3 table.
207 *
208 * 3. \#PF(np,read) on a page in the range. This will cause it to be synced
209 * read-only and resumed if it's a WRITE handler. If it's an ALL handler we
210 * will call the handlers like in the next step. If the physical mapping has
211 * changed we will - some time in the future - perform a handler callback
212 * (optional) and update the physical -> virtual handler cache.
213 *
214 * 4. \#PF(,write) on a page in the range. This will cause the handler to
215 * be invoked.
216 *
217 * 5. The guest invalidates the page and changes the physical backing or
218 * unmaps it. This should cause the invalidation callback to be invoked
219 * (it might not yet be 100% perfect). Exactly what happens next... is
220 * this where we mess up and end up out of sync for a while?
221 *
222 * 6. The handler is deregistered by the client via PGMHandlerVirtualDeregister.
223 * We will then set all PGMPAGEs in the physical -> virtual handler cache for
224 * this handler to NONE and trigger a full PGM resync (basically the same
225 * as int step 1). Which means 2 is executed again.
226 *
227 *
228 * @subsubsection sub_sec_pgm_handler_virt_todo TODOs
229 *
230 * There is a bunch of things that needs to be done to make the virtual handlers
231 * work 100% correctly and work more efficiently.
232 *
233 * The first bit hasn't been implemented yet because it's going to slow the
234 * whole mess down even more, and besides it seems to be working reliably for
235 * our current uses. OTOH, some of the optimizations might end up more or less
236 * implementing the missing bits, so we'll see.
237 *
238 * On the optimization side, the first thing to do is to try avoid unnecessary
239 * cache flushing. Then try team up with the shadowing code to track changes
240 * in mappings by means of access to them (shadow in), updates to shadows pages,
241 * invlpg, and shadow PT discarding (perhaps).
242 *
243 * Some idea that have popped up for optimization for current and new features:
244 * - bitmap indicating where there are virtual handlers installed.
245 * (4KB => 2**20 pages, page 2**12 => covers 32-bit address space 1:1!)
246 * - Further optimize this by min/max (needs min/max avl getters).
247 * - Shadow page table entry bit (if any left)?
248 *
249 */
250
251
252/** @page pg_pgm_phys PGM Physical Guest Memory Management
253 *
254 *
255 * Objectives:
256 * - Guest RAM over-commitment using memory ballooning,
257 * zero pages and general page sharing.
258 * - Moving or mirroring a VM onto a different physical machine.
259 *
260 *
261 * @section sec_pgmPhys_Definitions Definitions
262 *
263 * Allocation chunk - A RTR0MemObjAllocPhysNC or RTR0MemObjAllocPhys allocate
264 * memory object and the tracking machinery associated with it.
265 *
266 *
267 *
268 *
269 * @section sec_pgmPhys_AllocPage Allocating a page.
270 *
271 * Initially we map *all* guest memory to the (per VM) zero page, which
272 * means that none of the read functions will cause pages to be allocated.
273 *
274 * Exception, access bit in page tables that have been shared. This must
275 * be handled, but we must also make sure PGMGst*Modify doesn't make
276 * unnecessary modifications.
277 *
278 * Allocation points:
279 * - PGMPhysSimpleWriteGCPhys and PGMPhysWrite.
280 * - Replacing a zero page mapping at \#PF.
281 * - Replacing a shared page mapping at \#PF.
282 * - ROM registration (currently MMR3RomRegister).
283 * - VM restore (pgmR3Load).
284 *
285 * For the first three it would make sense to keep a few pages handy
286 * until we've reached the max memory commitment for the VM.
287 *
288 * For the ROM registration, we know exactly how many pages we need
289 * and will request these from ring-0. For restore, we will save
290 * the number of non-zero pages in the saved state and allocate
291 * them up front. This would allow the ring-0 component to refuse
292 * the request if the isn't sufficient memory available for VM use.
293 *
294 * Btw. for both ROM and restore allocations we won't be requiring
295 * zeroed pages as they are going to be filled instantly.
296 *
297 *
298 * @section sec_pgmPhys_FreePage Freeing a page
299 *
300 * There are a few points where a page can be freed:
301 * - After being replaced by the zero page.
302 * - After being replaced by a shared page.
303 * - After being ballooned by the guest additions.
304 * - At reset.
305 * - At restore.
306 *
307 * When freeing one or more pages they will be returned to the ring-0
308 * component and replaced by the zero page.
309 *
310 * The reasoning for clearing out all the pages on reset is that it will
311 * return us to the exact same state as on power on, and may thereby help
312 * us reduce the memory load on the system. Further it might have a
313 * (temporary) positive influence on memory fragmentation (@see subsec_pgmPhys_Fragmentation).
314 *
315 * On restore, as mention under the allocation topic, pages should be
316 * freed / allocated depending on how many is actually required by the
317 * new VM state. The simplest approach is to do like on reset, and free
318 * all non-ROM pages and then allocate what we need.
319 *
320 * A measure to prevent some fragmentation, would be to let each allocation
321 * chunk have some affinity towards the VM having allocated the most pages
322 * from it. Also, try make sure to allocate from allocation chunks that
323 * are almost full. Admittedly, both these measures might work counter to
324 * our intentions and its probably not worth putting a lot of effort,
325 * cpu time or memory into this.
326 *
327 *
328 * @section sec_pgmPhys_SharePage Sharing a page
329 *
330 * The basic idea is that there there will be a idle priority kernel
331 * thread walking the non-shared VM pages hashing them and looking for
332 * pages with the same checksum. If such pages are found, it will compare
333 * them byte-by-byte to see if they actually are identical. If found to be
334 * identical it will allocate a shared page, copy the content, check that
335 * the page didn't change while doing this, and finally request both the
336 * VMs to use the shared page instead. If the page is all zeros (special
337 * checksum and byte-by-byte check) it will request the VM that owns it
338 * to replace it with the zero page.
339 *
340 * To make this efficient, we will have to make sure not to try share a page
341 * that will change its contents soon. This part requires the most work.
342 * A simple idea would be to request the VM to write monitor the page for
343 * a while to make sure it isn't modified any time soon. Also, it may
344 * make sense to skip pages that are being write monitored since this
345 * information is readily available to the thread if it works on the
346 * per-VM guest memory structures (presently called PGMRAMRANGE).
347 *
348 *
349 * @section sec_pgmPhys_Fragmentation Fragmentation Concerns and Counter Measures
350 *
351 * The pages are organized in allocation chunks in ring-0, this is a necessity
352 * if we wish to have an OS agnostic approach to this whole thing. (On Linux we
353 * could easily work on a page-by-page basis if we liked. Whether this is possible
354 * or efficient on NT I don't quite know.) Fragmentation within these chunks may
355 * become a problem as part of the idea here is that we wish to return memory to
356 * the host system.
357 *
358 * For instance, starting two VMs at the same time, they will both allocate the
359 * guest memory on-demand and if permitted their page allocations will be
360 * intermixed. Shut down one of the two VMs and it will be difficult to return
361 * any memory to the host system because the page allocation for the two VMs are
362 * mixed up in the same allocation chunks.
363 *
364 * To further complicate matters, when pages are freed because they have been
365 * ballooned or become shared/zero the whole idea is that the page is supposed
366 * to be reused by another VM or returned to the host system. This will cause
367 * allocation chunks to contain pages belonging to different VMs and prevent
368 * returning memory to the host when one of those VM shuts down.
369 *
370 * The only way to really deal with this problem is to move pages. This can
371 * either be done at VM shutdown and or by the idle priority worker thread
372 * that will be responsible for finding sharable/zero pages. The mechanisms
373 * involved for coercing a VM to move a page (or to do it for it) will be
374 * the same as when telling it to share/zero a page.
375 *
376 *
377 * @section sec_pgmPhys_Tracking Tracking Structures And Their Cost
378 *
379 * There's a difficult balance between keeping the per-page tracking structures
380 * (global and guest page) easy to use and keeping them from eating too much
381 * memory. We have limited virtual memory resources available when operating in
382 * 32-bit kernel space (on 64-bit there'll it's quite a different story). The
383 * tracking structures will be attempted designed such that we can deal with up
384 * to 32GB of memory on a 32-bit system and essentially unlimited on 64-bit ones.
385 *
386 *
387 * @subsection subsec_pgmPhys_Tracking_Kernel Kernel Space
388 *
389 * @see pg_GMM
390 *
391 * @subsection subsec_pgmPhys_Tracking_PerVM Per-VM
392 *
393 * Fixed info is the physical address of the page (HCPhys) and the page id
394 * (described above). Theoretically we'll need 48(-12) bits for the HCPhys part.
395 * Today we've restricting ourselves to 40(-12) bits because this is the current
396 * restrictions of all AMD64 implementations (I think Barcelona will up this
397 * to 48(-12) bits, not that it really matters) and I needed the bits for
398 * tracking mappings of a page. 48-12 = 36. That leaves 28 bits, which means a
399 * decent range for the page id: 2^(28+12) = 1024TB.
400 *
401 * In additions to these, we'll have to keep maintaining the page flags as we
402 * currently do. Although it wouldn't harm to optimize these quite a bit, like
403 * for instance the ROM shouldn't depend on having a write handler installed
404 * in order for it to become read-only. A RO/RW bit should be considered so
405 * that the page syncing code doesn't have to mess about checking multiple
406 * flag combinations (ROM || RW handler || write monitored) in order to
407 * figure out how to setup a shadow PTE. But this of course, is second
408 * priority at present. Current this requires 12 bits, but could probably
409 * be optimized to ~8.
410 *
411 * Then there's the 24 bits used to track which shadow page tables are
412 * currently mapping a page for the purpose of speeding up physical
413 * access handlers, and thereby the page pool cache. More bit for this
414 * purpose wouldn't hurt IIRC.
415 *
416 * Then there is a new bit in which we need to record what kind of page
417 * this is, shared, zero, normal or write-monitored-normal. This'll
418 * require 2 bits. One bit might be needed for indicating whether a
419 * write monitored page has been written to. And yet another one or
420 * two for tracking migration status. 3-4 bits total then.
421 *
422 * Whatever is left will can be used to record the sharabilitiy of a
423 * page. The page checksum will not be stored in the per-VM table as
424 * the idle thread will not be permitted to do modifications to it.
425 * It will instead have to keep its own working set of potentially
426 * shareable pages and their check sums and stuff.
427 *
428 * For the present we'll keep the current packing of the
429 * PGMRAMRANGE::aHCPhys to keep the changes simple, only of course,
430 * we'll have to change it to a struct with a total of 128-bits at
431 * our disposal.
432 *
433 * The initial layout will be like this:
434 * @verbatim
435 RTHCPHYS HCPhys; The current stuff.
436 63:40 Current shadow PT tracking stuff.
437 39:12 The physical page frame number.
438 11:0 The current flags.
439 uint32_t u28PageId : 28; The page id.
440 uint32_t u2State : 2; The page state { zero, shared, normal, write monitored }.
441 uint32_t fWrittenTo : 1; Whether a write monitored page was written to.
442 uint32_t u1Reserved : 1; Reserved for later.
443 uint32_t u32Reserved; Reserved for later, mostly sharing stats.
444 @endverbatim
445 *
446 * The final layout will be something like this:
447 * @verbatim
448 RTHCPHYS HCPhys; The current stuff.
449 63:48 High page id (12+).
450 47:12 The physical page frame number.
451 11:0 Low page id.
452 uint32_t fReadOnly : 1; Whether it's readonly page (rom or monitored in some way).
453 uint32_t u3Type : 3; The page type {RESERVED, MMIO, MMIO2, ROM, shadowed ROM, RAM}.
454 uint32_t u2PhysMon : 2; Physical access handler type {none, read, write, all}.
455 uint32_t u2VirtMon : 2; Virtual access handler type {none, read, write, all}..
456 uint32_t u2State : 2; The page state { zero, shared, normal, write monitored }.
457 uint32_t fWrittenTo : 1; Whether a write monitored page was written to.
458 uint32_t u20Reserved : 20; Reserved for later, mostly sharing stats.
459 uint32_t u32Tracking; The shadow PT tracking stuff, roughly.
460 @endverbatim
461 *
462 * Cost wise, this means we'll double the cost for guest memory. There isn't anyway
463 * around that I'm afraid. It means that the cost of dealing out 32GB of memory
464 * to one or more VMs is: (32GB >> GUEST_PAGE_SHIFT) * 16 bytes, or 128MBs. Or
465 * another example, the VM heap cost when assigning 1GB to a VM will be: 4MB.
466 *
467 * A couple of cost examples for the total cost per-VM + kernel.
468 * 32-bit Windows and 32-bit linux:
469 * 1GB guest ram, 256K pages: 4MB + 2MB(+) = 6MB
470 * 4GB guest ram, 1M pages: 16MB + 8MB(+) = 24MB
471 * 32GB guest ram, 8M pages: 128MB + 64MB(+) = 192MB
472 * 64-bit Windows and 64-bit linux:
473 * 1GB guest ram, 256K pages: 4MB + 3MB(+) = 7MB
474 * 4GB guest ram, 1M pages: 16MB + 12MB(+) = 28MB
475 * 32GB guest ram, 8M pages: 128MB + 96MB(+) = 224MB
476 *
477 * UPDATE - 2007-09-27:
478 * Will need a ballooned flag/state too because we cannot
479 * trust the guest 100% and reporting the same page as ballooned more
480 * than once will put the GMM off balance.
481 *
482 *
483 * @section sec_pgmPhys_Serializing Serializing Access
484 *
485 * Initially, we'll try a simple scheme:
486 *
487 * - The per-VM RAM tracking structures (PGMRAMRANGE) is only modified
488 * by the EMT thread of that VM while in the pgm critsect.
489 * - Other threads in the VM process that needs to make reliable use of
490 * the per-VM RAM tracking structures will enter the critsect.
491 * - No process external thread or kernel thread will ever try enter
492 * the pgm critical section, as that just won't work.
493 * - The idle thread (and similar threads) doesn't not need 100% reliable
494 * data when performing it tasks as the EMT thread will be the one to
495 * do the actual changes later anyway. So, as long as it only accesses
496 * the main ram range, it can do so by somehow preventing the VM from
497 * being destroyed while it works on it...
498 *
499 * - The over-commitment management, including the allocating/freeing
500 * chunks, is serialized by a ring-0 mutex lock (a fast one since the
501 * more mundane mutex implementation is broken on Linux).
502 * - A separate mutex is protecting the set of allocation chunks so
503 * that pages can be shared or/and freed up while some other VM is
504 * allocating more chunks. This mutex can be take from under the other
505 * one, but not the other way around.
506 *
507 *
508 * @section sec_pgmPhys_Request VM Request interface
509 *
510 * When in ring-0 it will become necessary to send requests to a VM so it can
511 * for instance move a page while defragmenting during VM destroy. The idle
512 * thread will make use of this interface to request VMs to setup shared
513 * pages and to perform write monitoring of pages.
514 *
515 * I would propose an interface similar to the current VMReq interface, similar
516 * in that it doesn't require locking and that the one sending the request may
517 * wait for completion if it wishes to. This shouldn't be very difficult to
518 * realize.
519 *
520 * The requests themselves are also pretty simple. They are basically:
521 * -# Check that some precondition is still true.
522 * -# Do the update.
523 * -# Update all shadow page tables involved with the page.
524 *
525 * The 3rd step is identical to what we're already doing when updating a
526 * physical handler, see pgmHandlerPhysicalSetRamFlagsAndFlushShadowPTs.
527 *
528 *
529 *
530 * @section sec_pgmPhys_MappingCaches Mapping Caches
531 *
532 * In order to be able to map in and out memory and to be able to support
533 * guest with more RAM than we've got virtual address space, we'll employing
534 * a mapping cache. Normally ring-0 and ring-3 can share the same cache,
535 * however on 32-bit darwin the ring-0 code is running in a different memory
536 * context and therefore needs a separate cache. In raw-mode context we also
537 * need a separate cache. The 32-bit darwin mapping cache and the one for
538 * raw-mode context share a lot of code, see PGMRZDYNMAP.
539 *
540 *
541 * @subsection subsec_pgmPhys_MappingCaches_R3 Ring-3
542 *
543 * We've considered implementing the ring-3 mapping cache page based but found
544 * that this was bother some when one had to take into account TLBs+SMP and
545 * portability (missing the necessary APIs on several platforms). There were
546 * also some performance concerns with this approach which hadn't quite been
547 * worked out.
548 *
549 * Instead, we'll be mapping allocation chunks into the VM process. This simplifies
550 * matters greatly quite a bit since we don't need to invent any new ring-0 stuff,
551 * only some minor RTR0MEMOBJ mapping stuff. The main concern here is that mapping
552 * compared to the previous idea is that mapping or unmapping a 1MB chunk is more
553 * costly than a single page, although how much more costly is uncertain. We'll
554 * try address this by using a very big cache, preferably bigger than the actual
555 * VM RAM size if possible. The current VM RAM sizes should give some idea for
556 * 32-bit boxes, while on 64-bit we can probably get away with employing an
557 * unlimited cache.
558 *
559 * The cache have to parts, as already indicated, the ring-3 side and the
560 * ring-0 side.
561 *
562 * The ring-0 will be tied to the page allocator since it will operate on the
563 * memory objects it contains. It will therefore require the first ring-0 mutex
564 * discussed in @ref sec_pgmPhys_Serializing. We some double house keeping wrt
565 * to who has mapped what I think, since both VMMR0.r0 and RTR0MemObj will keep
566 * track of mapping relations
567 *
568 * The ring-3 part will be protected by the pgm critsect. For simplicity, we'll
569 * require anyone that desires to do changes to the mapping cache to do that
570 * from within this critsect. Alternatively, we could employ a separate critsect
571 * for serializing changes to the mapping cache as this would reduce potential
572 * contention with other threads accessing mappings unrelated to the changes
573 * that are in process. We can see about this later, contention will show
574 * up in the statistics anyway, so it'll be simple to tell.
575 *
576 * The organization of the ring-3 part will be very much like how the allocation
577 * chunks are organized in ring-0, that is in an AVL tree by chunk id. To avoid
578 * having to walk the tree all the time, we'll have a couple of lookaside entries
579 * like in we do for I/O ports and MMIO in IOM.
580 *
581 * The simplified flow of a PGMPhysRead/Write function:
582 * -# Enter the PGM critsect.
583 * -# Lookup GCPhys in the ram ranges and get the Page ID.
584 * -# Calc the Allocation Chunk ID from the Page ID.
585 * -# Check the lookaside entries and then the AVL tree for the Chunk ID.
586 * If not found in cache:
587 * -# Call ring-0 and request it to be mapped and supply
588 * a chunk to be unmapped if the cache is maxed out already.
589 * -# Insert the new mapping into the AVL tree (id + R3 address).
590 * -# Update the relevant lookaside entry and return the mapping address.
591 * -# Do the read/write according to monitoring flags and everything.
592 * -# Leave the critsect.
593 *
594 *
595 * @section sec_pgmPhys_Changes Changes
596 *
597 * Breakdown of the changes involved?
598 */
599
600
601/*********************************************************************************************************************************
602* Header Files *
603*********************************************************************************************************************************/
604#define LOG_GROUP LOG_GROUP_PGM
605#define VBOX_WITHOUT_PAGING_BIT_FIELDS /* 64-bit bitfields are just asking for trouble. See @bugref{9841} and others. */
606#include <VBox/vmm/dbgf.h>
607#include <VBox/vmm/pgm.h>
608#include <VBox/vmm/cpum.h>
609#include <VBox/vmm/iom.h>
610#include <VBox/sup.h>
611#include <VBox/vmm/mm.h>
612#include <VBox/vmm/em.h>
613#include <VBox/vmm/stam.h>
614#include <VBox/vmm/selm.h>
615#include <VBox/vmm/ssm.h>
616#include <VBox/vmm/hm.h>
617#include "PGMInternal.h"
618#include <VBox/vmm/vmcc.h>
619#include <VBox/vmm/uvm.h>
620#include "PGMInline.h"
621
622#include <VBox/dbg.h>
623#include <VBox/param.h>
624#include <VBox/err.h>
625
626#include <iprt/asm.h>
627#if defined(RT_ARCH_AMD64) || defined(RT_ARCH_X86)
628# include <iprt/asm-amd64-x86.h>
629#endif
630#include <iprt/assert.h>
631#include <iprt/env.h>
632#include <iprt/file.h>
633#include <iprt/mem.h>
634#include <iprt/rand.h>
635#include <iprt/string.h>
636#include <iprt/thread.h>
637#ifdef RT_OS_LINUX
638# include <iprt/linux/sysfs.h>
639#endif
640
641
642/*********************************************************************************************************************************
643* Structures and Typedefs *
644*********************************************************************************************************************************/
645/**
646 * Argument package for pgmR3RElocatePhysHnadler, pgmR3RelocateVirtHandler and
647 * pgmR3RelocateHyperVirtHandler.
648 */
649typedef struct PGMRELOCHANDLERARGS
650{
651 RTGCINTPTR offDelta;
652 PVM pVM;
653} PGMRELOCHANDLERARGS;
654/** Pointer to a page access handlere relocation argument package. */
655typedef PGMRELOCHANDLERARGS const *PCPGMRELOCHANDLERARGS;
656
657
658/*********************************************************************************************************************************
659* Internal Functions *
660*********************************************************************************************************************************/
661#ifdef VBOX_VMM_TARGET_X86
662static int pgmR3InitPaging(PVM pVM);
663#endif
664static int pgmR3InitStats(PVM pVM);
665static DECLCALLBACK(void) pgmR3PhysInfo(PVM pVM, PCDBGFINFOHLP pHlp, const char *pszArgs);
666#ifdef VBOX_VMM_TARGET_X86
667static DECLCALLBACK(void) pgmR3InfoMode(PVM pVM, PCDBGFINFOHLP pHlp, const char *pszArgs);
668static DECLCALLBACK(void) pgmR3InfoCr3(PVM pVM, PCDBGFINFOHLP pHlp, const char *pszArgs);
669#endif
670#ifdef VBOX_STRICT
671static FNVMATSTATE pgmR3ResetNoMorePhysWritesFlag;
672#endif
673
674#ifdef VBOX_WITH_DEBUGGER
675# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
676static FNDBGCCMD pgmR3CmdError;
677static FNDBGCCMD pgmR3CmdSync;
678static FNDBGCCMD pgmR3CmdSyncAlways;
679# ifdef VBOX_STRICT
680static FNDBGCCMD pgmR3CmdAssertCR3;
681# endif
682# endif /* !VBOX_WITH_ONLY_PGM_NEM_MODE */
683static FNDBGCCMD pgmR3CmdPhysToFile;
684#endif
685
686
687/*********************************************************************************************************************************
688* Global Variables *
689*********************************************************************************************************************************/
690#ifdef VBOX_WITH_DEBUGGER
691# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
692/** Argument descriptors for '.pgmerror' and '.pgmerroroff'. */
693static const DBGCVARDESC g_aPgmErrorArgs[] =
694{
695 /* cTimesMin, cTimesMax, enmCategory, fFlags, pszName, pszDescription */
696 { 0, 1, DBGCVAR_CAT_STRING, 0, "where", "Error injection location." },
697};
698# endif
699
700static const DBGCVARDESC g_aPgmPhysToFileArgs[] =
701{
702 /* cTimesMin, cTimesMax, enmCategory, fFlags, pszName, pszDescription */
703 { 1, 1, DBGCVAR_CAT_STRING, 0, "file", "The file name." },
704 { 0, 1, DBGCVAR_CAT_STRING, 0, "nozero", "If present, zero pages are skipped." },
705};
706
707/** Command descriptors. */
708static const DBGCCMD g_aCmds[] =
709{
710 /* pszCmd, cArgsMin, cArgsMax, paArgDesc, cArgDescs, fFlags, pfnHandler pszSyntax, ....pszDescription */
711# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
712 { "pgmsync", 0, 0, NULL, 0, 0, pgmR3CmdSync, "", "Sync the CR3 page." },
713 { "pgmerror", 0, 1, &g_aPgmErrorArgs[0], 1, 0, pgmR3CmdError, "", "Enables inject runtime of errors into parts of PGM." },
714 { "pgmerroroff", 0, 1, &g_aPgmErrorArgs[0], 1, 0, pgmR3CmdError, "", "Disables inject runtime errors into parts of PGM." },
715# ifdef VBOX_STRICT
716# ifdef VBOX_VMM_TARGET_X86
717 { "pgmassertcr3", 0, 0, NULL, 0, 0, pgmR3CmdAssertCR3, "", "Check the shadow CR3 mapping." },
718# endif
719# ifdef VBOX_WITH_PAGE_SHARING
720 { "pgmcheckduppages", 0, 0, NULL, 0, 0, pgmR3CmdCheckDuplicatePages, "", "Check for duplicate pages in all running VMs." },
721 { "pgmsharedmodules", 0, 0, NULL, 0, 0, pgmR3CmdShowSharedModules, "", "Print shared modules info." },
722# endif
723# endif
724 { "pgmsyncalways", 0, 0, NULL, 0, 0, pgmR3CmdSyncAlways, "", "Toggle permanent CR3 syncing." },
725# endif /* !VBOX_WITH_ONLY_PGM_NEM_MODE */
726 { "pgmphystofile", 1, 2, &g_aPgmPhysToFileArgs[0], 2, 0, pgmR3CmdPhysToFile, "", "Save the physical memory to file." },
727};
728#endif
729
730#ifdef VBOX_WITH_PGM_NEM_MODE
731
732/**
733 * Interface that NEM uses to switch PGM into simplified memory managment mode.
734 *
735 * This call occurs before PGMR3Init.
736 *
737 * @param pVM The cross context VM structure.
738 */
739VMMR3_INT_DECL(void) PGMR3EnableNemMode(PVM pVM)
740{
741 AssertFatal(!PDMCritSectIsInitialized(&pVM->pgm.s.CritSectX));
742# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
743 if (!pVM->pgm.s.fNemMode)
744 {
745 LogRel(("PGM: Enabling NEM mode\n"));
746 pVM->pgm.s.fNemMode = true;
747 }
748# endif
749}
750
751
752/**
753 * Checks whether the simplificed memory management mode for NEM is enabled.
754 *
755 * @returns true if enabled, false if not.
756 * @param pVM The cross context VM structure.
757 */
758VMMR3_INT_DECL(bool) PGMR3IsNemModeEnabled(PVM pVM)
759{
760 RT_NOREF(pVM);
761 return PGM_IS_IN_NEM_MODE(pVM);
762}
763
764#endif /* VBOX_WITH_PGM_NEM_MODE */
765
766/**
767 * Initiates the paging of VM.
768 *
769 * @returns VBox status code.
770 * @param pVM The cross context VM structure.
771 */
772VMMR3DECL(int) PGMR3Init(PVM pVM)
773{
774 LogFlow(("PGMR3Init:\n"));
775 PCFGMNODE pCfgPGM = CFGMR3GetChild(CFGMR3GetRoot(pVM), "/PGM");
776 int rc;
777
778 /*
779 * Assert alignment and sizes.
780 */
781 AssertCompile(sizeof(pVM->pgm.s) <= sizeof(pVM->pgm.padding));
782 AssertCompile(sizeof(pVM->apCpusR3[0]->pgm.s) <= sizeof(pVM->apCpusR3[0]->pgm.padding));
783 AssertCompileMemberAlignment(PGM, CritSectX, sizeof(uintptr_t));
784
785 /*
786 * If we're in driveless mode we have to use the simplified memory mode.
787 */
788 bool const fDriverless = SUPR3IsDriverless();
789 if (fDriverless)
790 {
791#ifdef VBOX_WITH_PGM_NEM_MODE
792# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
793 if (!PGM_IS_IN_NEM_MODE(pVM))
794 {
795 LogRel(("PGM: Enabling NEM mode (driverless)\n"));
796 pVM->pgm.s.fNemMode = true;
797 }
798# endif
799#else
800 return VMR3SetError(pVM->pUVM, VERR_SUP_DRIVERLESS, RT_SRC_POS,
801 "Driverless requires that VBox is built with VBOX_WITH_PGM_NEM_MODE defined");
802#endif
803 }
804
805 /*
806 * Init the structure.
807 */
808 /*pVM->pgm.s.fRestoreRomPagesAtReset = false;*/
809
810 for (unsigned i = 0; i < RT_ELEMENTS(pVM->pgm.s.aHandyPages); i++)
811 {
812 pVM->pgm.s.aHandyPages[i].HCPhysGCPhys = NIL_GMMPAGEDESC_PHYS;
813 pVM->pgm.s.aHandyPages[i].fZeroed = false;
814 pVM->pgm.s.aHandyPages[i].idPage = NIL_GMM_PAGEID;
815 pVM->pgm.s.aHandyPages[i].idSharedPage = NIL_GMM_PAGEID;
816 }
817
818 for (unsigned i = 0; i < RT_ELEMENTS(pVM->pgm.s.aLargeHandyPage); i++)
819 {
820 pVM->pgm.s.aLargeHandyPage[i].HCPhysGCPhys = NIL_GMMPAGEDESC_PHYS;
821 pVM->pgm.s.aLargeHandyPage[i].fZeroed = false;
822 pVM->pgm.s.aLargeHandyPage[i].idPage = NIL_GMM_PAGEID;
823 pVM->pgm.s.aLargeHandyPage[i].idSharedPage = NIL_GMM_PAGEID;
824 }
825
826 AssertReleaseReturn(pVM->pgm.s.cPhysHandlerTypes == 0, VERR_WRONG_ORDER);
827 for (size_t i = 0; i < RT_ELEMENTS(pVM->pgm.s.aPhysHandlerTypes); i++)
828 {
829#if defined(VBOX_WITH_R0_MODULES) && !defined(VBOX_WITH_MINIMAL_R0)
830 if (fDriverless)
831#endif
832 pVM->pgm.s.aPhysHandlerTypes[i].hType = i | (RTRandU64() & ~(uint64_t)PGMPHYSHANDLERTYPE_IDX_MASK);
833 pVM->pgm.s.aPhysHandlerTypes[i].enmKind = PGMPHYSHANDLERKIND_INVALID;
834 pVM->pgm.s.aPhysHandlerTypes[i].pfnHandler = pgmR3HandlerPhysicalHandlerInvalid;
835 }
836
837 /* Init the per-CPU part. */
838 for (VMCPUID idCpu = 0; idCpu < pVM->cCpus; idCpu++)
839 {
840 PVMCPU pVCpu = pVM->apCpusR3[idCpu];
841 PPGMCPU pPGM = &pVCpu->pgm.s;
842
843#ifdef VBOX_VMM_TARGET_X86
844 pPGM->enmShadowMode = PGMMODE_INVALID;
845 pPGM->enmGuestMode = PGMMODE_INVALID;
846 pPGM->enmGuestSlatMode = PGMSLAT_INVALID;
847 pPGM->idxGuestModeData = UINT8_MAX;
848 pPGM->idxShadowModeData = UINT8_MAX;
849 pPGM->idxBothModeData = UINT8_MAX;
850
851 pPGM->GCPhysCR3 = NIL_RTGCPHYS;
852 pPGM->GCPhysNstGstCR3 = NIL_RTGCPHYS;
853 pPGM->GCPhysPaeCR3 = NIL_RTGCPHYS;
854
855 pPGM->pGst32BitPdR3 = NULL;
856 pPGM->pGstPaePdptR3 = NULL;
857 pPGM->pGstAmd64Pml4R3 = NULL;
858 pPGM->pGst32BitPdR0 = NIL_RTR0PTR;
859 pPGM->pGstPaePdptR0 = NIL_RTR0PTR;
860 pPGM->pGstAmd64Pml4R0 = NIL_RTR0PTR;
861# ifdef VBOX_WITH_NESTED_HWVIRT_VMX_EPT
862 pPGM->pGstEptPml4R3 = NULL;
863 pPGM->pGstEptPml4R0 = NIL_RTR0PTR;
864 pPGM->uEptPtr = 0;
865# endif
866 for (unsigned i = 0; i < RT_ELEMENTS(pVCpu->pgm.s.apGstPaePDsR3); i++)
867 {
868 pPGM->apGstPaePDsR3[i] = NULL;
869 pPGM->apGstPaePDsR0[i] = NIL_RTR0PTR;
870 pPGM->aGCPhysGstPaePDs[i] = NIL_RTGCPHYS;
871 }
872
873 pPGM->fA20Enabled = true;
874 pPGM->GCPhysA20Mask = ~((RTGCPHYS)!pPGM->fA20Enabled << 20);
875
876#elif defined(VBOX_VMM_TARGET_ARMV8)
877 /* Poison the cached register values to force an initial change. */
878 for (uint8_t idxEl = 0; idxEl < RT_ELEMENTS(pPGM->au64RegSctlrEl); idxEl++)
879 {
880 pPGM->au64RegSctlrEl[idxEl] = UINT64_MAX;
881 pPGM->au64RegTcrEl[idxEl] = UINT64_MAX;
882 pPGM->aenmGuestMode[idxEl] = PGMMODE_INVALID;
883 }
884#else
885# error "port me"
886#endif
887 }
888
889#ifdef VBOX_VMM_TARGET_X86
890 pVM->pgm.s.enmHostMode = SUPPAGINGMODE_INVALID;
891 pVM->pgm.s.GCPhys4MBPSEMask = RT_BIT_64(32) - 1; /* default; checked later */
892#endif
893
894 /*
895 * RAM pre alloc
896 */
897 rc = CFGMR3QueryBoolDef(CFGMR3GetRoot(pVM), "RamPreAlloc", &pVM->pgm.s.fRamPreAlloc,
898#ifdef VBOX_WITH_PREALLOC_RAM_BY_DEFAULT
899 true
900#else
901 false
902#endif
903 );
904 AssertLogRelRCReturn(rc, rc);
905
906 /*
907 * RAM Mapping
908 */
909#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
910# if HC_ARCH_BITS == 32
911# ifdef RT_OS_DARWIN
912 rc = CFGMR3QueryU32Def(pCfgPGM, "MaxRing3Chunks", &pVM->pgm.s.ChunkR3Map.cMax, _1G / GMM_CHUNK_SIZE * 3);
913# else
914 rc = CFGMR3QueryU32Def(pCfgPGM, "MaxRing3Chunks", &pVM->pgm.s.ChunkR3Map.cMax, _1G / GMM_CHUNK_SIZE);
915# endif
916# else
917 rc = CFGMR3QueryU32Def(pCfgPGM, "MaxRing3Chunks", &pVM->pgm.s.ChunkR3Map.cMax, UINT32_MAX);
918# endif
919 AssertLogRelRCReturn(rc, rc);
920 for (uint32_t i = 0; i < RT_ELEMENTS(pVM->pgm.s.ChunkR3Map.Tlb.aEntries); i++)
921 pVM->pgm.s.ChunkR3Map.Tlb.aEntries[i].idChunk = NIL_GMM_CHUNKID;
922#endif
923
924 /*
925 * Get the configured RAM size - to estimate saved state size.
926 */
927 uint64_t cbRam;
928 rc = CFGMR3QueryU64(CFGMR3GetRoot(pVM), "RamSize", &cbRam);
929 if (rc == VERR_CFGM_VALUE_NOT_FOUND)
930 cbRam = 0;
931 else if (RT_SUCCESS(rc))
932 {
933 if (cbRam < GUEST_PAGE_SIZE)
934 cbRam = 0;
935 cbRam = RT_ALIGN_64(cbRam, GUEST_PAGE_SIZE);
936 }
937 else
938 {
939 AssertMsgFailed(("Configuration error: Failed to query integer \"RamSize\", rc=%Rrc.\n", rc));
940 return rc;
941 }
942
943 /*
944 * Check for PCI pass-through and other configurables.
945 */
946#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
947 rc = CFGMR3QueryBoolDef(pCfgPGM, "PciPassThrough", &pVM->pgm.s.fPciPassthrough, false);
948 AssertMsgRCReturn(rc, ("Configuration error: Failed to query integer \"PciPassThrough\", rc=%Rrc.\n", rc), rc);
949 AssertLogRelReturn(!pVM->pgm.s.fPciPassthrough || pVM->pgm.s.fRamPreAlloc, VERR_INVALID_PARAMETER);
950#endif
951
952#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
953 rc = CFGMR3QueryBoolDef(CFGMR3GetRoot(pVM), "PageFusionAllowed", &pVM->pgm.s.fPageFusionAllowed, false);
954 AssertLogRelRCReturn(rc, rc);
955#endif
956
957 /** @cfgm{/PGM/ZeroRamPagesOnReset, boolean, true}
958 * Whether to clear RAM pages on (hard) reset. */
959 rc = CFGMR3QueryBoolDef(pCfgPGM, "ZeroRamPagesOnReset", &pVM->pgm.s.fZeroRamPagesOnReset, true);
960 AssertLogRelRCReturn(rc, rc);
961
962 /*
963 * Register callbacks, string formatters and the saved state data unit.
964 */
965#ifdef VBOX_STRICT
966 VMR3AtStateRegister(pVM->pUVM, pgmR3ResetNoMorePhysWritesFlag, NULL);
967#endif
968 PGMRegisterStringFormatTypes();
969
970 rc = pgmR3InitSavedState(pVM, cbRam);
971 if (RT_FAILURE(rc))
972 return rc;
973
974 /*
975 * Initialize the PGM critical section and flush the phys TLBs
976 */
977 rc = PDMR3CritSectInit(pVM, &pVM->pgm.s.CritSectX, RT_SRC_POS, "PGM");
978 AssertRCReturn(rc, rc);
979
980#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
981 pgmR3PhysChunkInvalidateTLB(pVM, false /*fInRendezvous*/); /* includes pgmPhysInvalidatePageMapTLB call */
982#endif
983
984 /*
985 * For the time being we sport a full set of handy pages in addition to the base
986 * memory to simplify things.
987 */
988 rc = MMR3ReserveHandyPages(pVM, RT_ELEMENTS(pVM->pgm.s.aHandyPages)); /** @todo this should be changed to PGM_HANDY_PAGES_MIN but this needs proper testing... */
989 AssertRCReturn(rc, rc);
990
991#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
992 /*
993 * Setup the zero page (HCPHysZeroPg is set by ring-0).
994 */
995 RT_ZERO(pVM->pgm.s.abZeroPg); /* paranoia */
996 if (fDriverless)
997 pVM->pgm.s.HCPhysZeroPg = _4G - GUEST_PAGE_SIZE * 2 /* fake to avoid PGM_PAGE_INIT_ZERO assertion */;
998 AssertRelease(pVM->pgm.s.HCPhysZeroPg != NIL_RTHCPHYS);
999 AssertRelease(pVM->pgm.s.HCPhysZeroPg != 0);
1000 Log(("HCPhysZeroPg=%RHp abZeroPg=%p\n", pVM->pgm.s.HCPhysZeroPg, pVM->pgm.s.abZeroPg));
1001
1002 /*
1003 * Setup the invalid MMIO page (HCPhysMmioPg is set by ring-0).
1004 * (The invalid bits in HCPhysInvMmioPg are set later on init complete.)
1005 */
1006 ASMMemFill32(pVM->pgm.s.abMmioPg, sizeof(pVM->pgm.s.abMmioPg), 0xfeedface);
1007 if (fDriverless)
1008 pVM->pgm.s.HCPhysMmioPg = _4G - GUEST_PAGE_SIZE * 3 /* fake to avoid PGM_PAGE_INIT_ZERO assertion */;
1009 AssertRelease(pVM->pgm.s.HCPhysMmioPg != NIL_RTHCPHYS);
1010 AssertRelease(pVM->pgm.s.HCPhysMmioPg != 0);
1011 pVM->pgm.s.HCPhysInvMmioPg = pVM->pgm.s.HCPhysMmioPg;
1012 Log(("HCPhysInvMmioPg=%RHp abMmioPg=%p\n", pVM->pgm.s.HCPhysMmioPg, pVM->pgm.s.abMmioPg));
1013#endif
1014
1015
1016 /*
1017 * Initialize physical access handlers.
1018 */
1019 /** @cfgm{/PGM/MaxPhysicalAccessHandlers, uint32_t, 32, 65536, 6144}
1020 * Number of physical access handlers allowed (subject to rounding). This is
1021 * managed as one time allocation during initializations. The default is
1022 * lower for a driverless setup. */
1023 /** @todo can lower it for nested paging too, at least when there is no
1024 * nested guest involved. */
1025 uint32_t cAccessHandlers = 0;
1026 rc = CFGMR3QueryU32Def(pCfgPGM, "MaxPhysicalAccessHandlers", &cAccessHandlers, !fDriverless ? 6144 : 640);
1027 AssertLogRelRCReturn(rc, rc);
1028 AssertLogRelMsgStmt(cAccessHandlers >= 32, ("cAccessHandlers=%#x, min 32\n", cAccessHandlers), cAccessHandlers = 32);
1029 AssertLogRelMsgStmt(cAccessHandlers <= _64K, ("cAccessHandlers=%#x, max 65536\n", cAccessHandlers), cAccessHandlers = _64K);
1030#if defined(VBOX_WITH_R0_MODULES) && !defined(VBOX_WITH_MINIMAL_R0)
1031 if (!fDriverless)
1032 {
1033 rc = VMMR3CallR0(pVM, VMMR0_DO_PGM_PHYS_HANDLER_INIT, cAccessHandlers, NULL);
1034 AssertRCReturn(rc, rc);
1035 AssertPtr(pVM->pgm.s.pPhysHandlerTree);
1036 AssertPtr(pVM->pgm.s.PhysHandlerAllocator.m_paNodes);
1037 AssertPtr(pVM->pgm.s.PhysHandlerAllocator.m_pbmAlloc);
1038 }
1039 else
1040#endif
1041 {
1042 uint32_t cbTreeAndBitmap = 0;
1043 uint32_t const cbTotalAligned = pgmHandlerPhysicalCalcTableSizes(&cAccessHandlers, &cbTreeAndBitmap);
1044 uint8_t *pb = NULL;
1045 rc = SUPR3PageAlloc(cbTotalAligned >> HOST_PAGE_SHIFT_DYNAMIC, 0, (void **)&pb);
1046 AssertLogRelRCReturn(rc, rc);
1047
1048 pVM->pgm.s.PhysHandlerAllocator.initSlabAllocator(cAccessHandlers, (PPGMPHYSHANDLER)&pb[cbTreeAndBitmap],
1049 (uint64_t *)&pb[sizeof(PGMPHYSHANDLERTREE)]);
1050 pVM->pgm.s.pPhysHandlerTree = (PPGMPHYSHANDLERTREE)pb;
1051 pVM->pgm.s.pPhysHandlerTree->initWithAllocator(&pVM->pgm.s.PhysHandlerAllocator);
1052 }
1053
1054 /*
1055 * Register the physical access handler protecting ROMs.
1056 */
1057 if (RT_SUCCESS(rc))
1058 /** @todo why isn't pgmPhysRomWriteHandler registered for ring-0? */
1059 rc = PGMR3HandlerPhysicalTypeRegister(pVM, PGMPHYSHANDLERKIND_WRITE, 0 /*fFlags*/, pgmPhysRomWriteHandler,
1060 "ROM write protection", &pVM->pgm.s.hRomPhysHandlerType);
1061
1062 /*
1063 * Register the physical access handler doing dirty MMIO2 tracing.
1064 */
1065 if (RT_SUCCESS(rc))
1066 rc = PGMR3HandlerPhysicalTypeRegister(pVM, PGMPHYSHANDLERKIND_WRITE, PGMPHYSHANDLER_F_KEEP_PGM_LOCK,
1067 pgmPhysMmio2WriteHandler, "MMIO2 dirty page tracing",
1068 &pVM->pgm.s.hMmio2DirtyPhysHandlerType);
1069
1070#ifdef VBOX_VMM_TARGET_X86
1071 /*
1072 * Init the paging.
1073 */
1074 if (RT_SUCCESS(rc))
1075 rc = pgmR3InitPaging(pVM);
1076
1077# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1078 /*
1079 * Init the page pool.
1080 */
1081 if (RT_SUCCESS(rc))
1082 rc = pgmR3PoolInit(pVM);
1083# endif
1084
1085 if (RT_SUCCESS(rc))
1086 {
1087 for (VMCPUID i = 0; i < pVM->cCpus; i++)
1088 {
1089 PVMCPU pVCpu = pVM->apCpusR3[i];
1090 rc = PGMHCChangeMode(pVM, pVCpu, PGMMODE_REAL, false /* fForce */);
1091 if (RT_FAILURE(rc))
1092 break;
1093 }
1094 }
1095
1096#elif defined(VBOX_VMM_TARGET_ARMV8)
1097 for (VMCPUID i = 0; i < pVM->cCpus; i++)
1098 {
1099 PVMCPU pVCpu = pVM->apCpusR3[i];
1100
1101 /* This ASSUMES that SCTLR_ELx and TCR_ELx are reset to 0 in CPUM. */
1102 rc = PGMChangeMode(pVCpu, 1 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
1103 if (RT_FAILURE(rc))
1104 break;
1105
1106 rc = PGMChangeMode(pVCpu, 2 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
1107 if (RT_FAILURE(rc))
1108 break;
1109
1110 rc = PGMChangeMode(pVCpu, 3 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
1111 if (RT_FAILURE(rc))
1112 break;
1113 }
1114#else
1115# error "Port me"
1116#endif /* VBOX_VMM_TARGET_X86 */
1117
1118 if (RT_SUCCESS(rc))
1119 {
1120 /*
1121 * Info & statistics
1122 */
1123#ifdef VBOX_VMM_TARGET_X86
1124 DBGFR3InfoRegisterInternalEx(pVM, "mode",
1125 "Shows the current paging mode. "
1126 "Recognizes 'all', 'guest', 'shadow' and 'host' as arguments, defaulting to 'all' if nothing is given.",
1127 pgmR3InfoMode,
1128 DBGFINFO_FLAGS_ALL_EMTS);
1129 DBGFR3InfoRegisterInternal(pVM, "pgmcr3",
1130 "Dumps all the entries in the top level paging table. No arguments.",
1131 pgmR3InfoCr3);
1132#endif
1133 DBGFR3InfoRegisterInternal(pVM, "phys",
1134 "Dumps all the physical address ranges. Pass 'verbose' to get more details.",
1135 pgmR3PhysInfo);
1136 DBGFR3InfoRegisterInternal(pVM, "handlers",
1137 "Dumps physical, virtual and hyper virtual handlers. "
1138 "Pass 'phys', 'virt', 'hyper' as argument if only one kind is wanted."
1139 "Add 'nost' if the statistics are unwanted, use together with 'all' or explicit selection.",
1140 pgmR3InfoHandlers);
1141
1142 pgmR3InitStats(pVM);
1143
1144#ifdef VBOX_WITH_DEBUGGER
1145 /*
1146 * Debugger commands.
1147 */
1148 static bool s_fRegisteredCmds = false;
1149 if (!s_fRegisteredCmds)
1150 {
1151 int rc2 = DBGCRegisterCommands(&g_aCmds[0], RT_ELEMENTS(g_aCmds));
1152 if (RT_SUCCESS(rc2))
1153 s_fRegisteredCmds = true;
1154 }
1155#endif
1156
1157#ifdef RT_OS_LINUX
1158 /*
1159 * Log the /proc/sys/vm/max_map_count value on linux as that is
1160 * frequently giving us grief when too low.
1161 */
1162 int64_t cMaxMapCount = 0;
1163 int rc2 = RTLinuxSysFsReadIntFile(10, &cMaxMapCount, "/proc/sys/vm/max_map_count");
1164# ifdef VBOX_WITH_ONLY_PGM_NEM_MODE
1165 LogRel(("PGM: /proc/sys/vm/max_map_count = %RI64 (rc2=%Rrc)\n", cMaxMapCount, rc2));
1166# else
1167 int64_t const cGuessNeeded = MMR3PhysGetRamSize(pVM) / _2M + 16384 /*guesstimate*/;
1168 LogRel(("PGM: /proc/sys/vm/max_map_count = %RI64 (rc2=%Rrc); cGuessNeeded=%RI64\n", cMaxMapCount, rc2, cGuessNeeded));
1169 if (RT_SUCCESS(rc2) && cMaxMapCount < cGuessNeeded)
1170 LogRel(("PGM: WARNING!!\n"
1171 "PGM: WARNING!! Please increase /proc/sys/vm/max_map_count to at least %RI64 (or reduce the amount of RAM assigned to the VM)!\n"
1172 "PGM: WARNING!!\n", cMaxMapCount));
1173# endif
1174#endif
1175
1176 return VINF_SUCCESS;
1177 }
1178
1179 /* Almost no cleanup necessary, MM frees all memory. */
1180 PDMR3CritSectDelete(pVM, &pVM->pgm.s.CritSectX);
1181
1182 return rc;
1183}
1184
1185
1186#ifdef VBOX_VMM_TARGET_X86
1187/**
1188 * Init paging.
1189 *
1190 * Since we need to check what mode the host is operating in before we can choose
1191 * the right paging functions for the host we have to delay this until R0 has
1192 * been initialized.
1193 *
1194 * @returns VBox status code.
1195 * @param pVM The cross context VM structure.
1196 */
1197static int pgmR3InitPaging(PVM pVM)
1198{
1199 /*
1200 * Force a recalculation of modes and switcher so everyone gets notified.
1201 */
1202 for (VMCPUID i = 0; i < pVM->cCpus; i++)
1203 {
1204 PVMCPU pVCpu = pVM->apCpusR3[i];
1205
1206 pVCpu->pgm.s.enmShadowMode = PGMMODE_INVALID;
1207 pVCpu->pgm.s.enmGuestMode = PGMMODE_INVALID;
1208 pVCpu->pgm.s.enmGuestSlatMode = PGMSLAT_INVALID;
1209 pVCpu->pgm.s.idxGuestModeData = UINT8_MAX;
1210 pVCpu->pgm.s.idxShadowModeData = UINT8_MAX;
1211 pVCpu->pgm.s.idxBothModeData = UINT8_MAX;
1212 }
1213
1214 pVM->pgm.s.enmHostMode = SUPPAGINGMODE_INVALID;
1215
1216 /*
1217 * Initialize paging workers and mode from current host mode
1218 * and the guest running in real mode.
1219 */
1220 pVM->pgm.s.enmHostMode = SUPR3GetPagingMode();
1221 switch (pVM->pgm.s.enmHostMode)
1222 {
1223 case SUPPAGINGMODE_32_BIT:
1224 case SUPPAGINGMODE_32_BIT_GLOBAL:
1225 case SUPPAGINGMODE_PAE:
1226 case SUPPAGINGMODE_PAE_GLOBAL:
1227 case SUPPAGINGMODE_PAE_NX:
1228 case SUPPAGINGMODE_PAE_GLOBAL_NX:
1229
1230 case SUPPAGINGMODE_AMD64:
1231 case SUPPAGINGMODE_AMD64_GLOBAL:
1232 case SUPPAGINGMODE_AMD64_NX:
1233 case SUPPAGINGMODE_AMD64_GLOBAL_NX:
1234 if (ARCH_BITS != 64)
1235 {
1236 AssertMsgFailed(("Host mode %d (64-bit) is not supported by non-64bit builds\n", pVM->pgm.s.enmHostMode));
1237 LogRel(("PGM: Host mode %d (64-bit) is not supported by non-64bit builds\n", pVM->pgm.s.enmHostMode));
1238 return VERR_PGM_UNSUPPORTED_HOST_PAGING_MODE;
1239 }
1240 break;
1241#if !defined(RT_ARCH_AMD64) && !defined(RT_ARCH_X86)
1242 case SUPPAGINGMODE_INVALID:
1243 pVM->pgm.s.enmHostMode = SUPPAGINGMODE_AMD64_GLOBAL_NX;
1244 break;
1245#endif
1246 default:
1247 AssertMsgFailed(("Host mode %d is not supported\n", pVM->pgm.s.enmHostMode));
1248 return VERR_PGM_UNSUPPORTED_HOST_PAGING_MODE;
1249 }
1250
1251 LogFlow(("pgmR3InitPaging: returns successfully\n"));
1252#if HC_ARCH_BITS == 64 && 0
1253 LogRel(("PGM: HCPhysInterPD=%RHp HCPhysInterPaePDPT=%RHp HCPhysInterPaePML4=%RHp\n",
1254 pVM->pgm.s.HCPhysInterPD, pVM->pgm.s.HCPhysInterPaePDPT, pVM->pgm.s.HCPhysInterPaePML4));
1255 LogRel(("PGM: apInterPTs={%RHp,%RHp} apInterPaePTs={%RHp,%RHp} apInterPaePDs={%RHp,%RHp,%RHp,%RHp} pInterPaePDPT64=%RHp\n",
1256 MMPage2Phys(pVM, pVM->pgm.s.apInterPTs[0]), MMPage2Phys(pVM, pVM->pgm.s.apInterPTs[1]),
1257 MMPage2Phys(pVM, pVM->pgm.s.apInterPaePTs[0]), MMPage2Phys(pVM, pVM->pgm.s.apInterPaePTs[1]),
1258 MMPage2Phys(pVM, pVM->pgm.s.apInterPaePDs[0]), MMPage2Phys(pVM, pVM->pgm.s.apInterPaePDs[1]), MMPage2Phys(pVM, pVM->pgm.s.apInterPaePDs[2]), MMPage2Phys(pVM, pVM->pgm.s.apInterPaePDs[3]),
1259 MMPage2Phys(pVM, pVM->pgm.s.pInterPaePDPT64)));
1260#endif
1261
1262 /*
1263 * Log the host paging mode. It may come in handy.
1264 */
1265 const char *pszHostMode;
1266 switch (pVM->pgm.s.enmHostMode)
1267 {
1268 case SUPPAGINGMODE_32_BIT: pszHostMode = "32-bit"; break;
1269 case SUPPAGINGMODE_32_BIT_GLOBAL: pszHostMode = "32-bit+PGE"; break;
1270 case SUPPAGINGMODE_PAE: pszHostMode = "PAE"; break;
1271 case SUPPAGINGMODE_PAE_GLOBAL: pszHostMode = "PAE+PGE"; break;
1272 case SUPPAGINGMODE_PAE_NX: pszHostMode = "PAE+NXE"; break;
1273 case SUPPAGINGMODE_PAE_GLOBAL_NX: pszHostMode = "PAE+PGE+NXE"; break;
1274 case SUPPAGINGMODE_AMD64: pszHostMode = "AMD64"; break;
1275 case SUPPAGINGMODE_AMD64_GLOBAL: pszHostMode = "AMD64+PGE"; break;
1276 case SUPPAGINGMODE_AMD64_NX: pszHostMode = "AMD64+NX"; break;
1277 case SUPPAGINGMODE_AMD64_GLOBAL_NX: pszHostMode = "AMD64+PGE+NX"; break;
1278 default: pszHostMode = "???"; break;
1279 }
1280 LogRel(("PGM: Host paging mode: %s\n", pszHostMode));
1281
1282 return VINF_SUCCESS;
1283}
1284#endif /* VBOX_VMM_TARGET_X86 */
1285
1286
1287/**
1288 * Init statistics
1289 * @returns VBox status code.
1290 */
1291static int pgmR3InitStats(PVM pVM)
1292{
1293 PPGM pPGM = &pVM->pgm.s;
1294 int rc;
1295
1296 /*
1297 * Release statistics.
1298 */
1299 /* Common - misc variables */
1300 STAM_REL_REG(pVM, &pPGM->cAllPages, STAMTYPE_U32, "/PGM/Page/cAllPages", STAMUNIT_COUNT, "The total number of pages.");
1301 STAM_REL_REG(pVM, &pPGM->cPrivatePages, STAMTYPE_U32, "/PGM/Page/cPrivatePages", STAMUNIT_COUNT, "The number of private pages.");
1302 STAM_REL_REG(pVM, &pPGM->cSharedPages, STAMTYPE_U32, "/PGM/Page/cSharedPages", STAMUNIT_COUNT, "The number of shared pages.");
1303 STAM_REL_REG(pVM, &pPGM->cReusedSharedPages, STAMTYPE_U32, "/PGM/Page/cReusedSharedPages", STAMUNIT_COUNT, "The number of reused shared pages.");
1304 STAM_REL_REG(pVM, &pPGM->cZeroPages, STAMTYPE_U32, "/PGM/Page/cZeroPages", STAMUNIT_COUNT, "The number of zero backed pages.");
1305 STAM_REL_REG(pVM, &pPGM->cPureMmioPages, STAMTYPE_U32, "/PGM/Page/cPureMmioPages", STAMUNIT_COUNT, "The number of pure MMIO pages.");
1306 STAM_REL_REG(pVM, &pPGM->cMonitoredPages, STAMTYPE_U32, "/PGM/Page/cMonitoredPages", STAMUNIT_COUNT, "The number of write monitored pages.");
1307 STAM_REL_REG(pVM, &pPGM->cWrittenToPages, STAMTYPE_U32, "/PGM/Page/cWrittenToPages", STAMUNIT_COUNT, "The number of previously write monitored pages that have been written to.");
1308 STAM_REL_REG(pVM, &pPGM->cWriteLockedPages, STAMTYPE_U32, "/PGM/Page/cWriteLockedPages", STAMUNIT_COUNT, "The number of write(/read) locked pages.");
1309 STAM_REL_REG(pVM, &pPGM->cReadLockedPages, STAMTYPE_U32, "/PGM/Page/cReadLockedPages", STAMUNIT_COUNT, "The number of read (only) locked pages.");
1310 STAM_REL_REG(pVM, &pPGM->cBalloonedPages, STAMTYPE_U32, "/PGM/Page/cBalloonedPages", STAMUNIT_COUNT, "The number of ballooned pages.");
1311 STAM_REL_REG(pVM, &pPGM->cHandyPages, STAMTYPE_U32, "/PGM/Page/cHandyPages", STAMUNIT_COUNT, "The number of handy pages (not included in cAllPages).");
1312 STAM_REL_REG(pVM, &pPGM->cLargePages, STAMTYPE_U32, "/PGM/Page/cLargePages", STAMUNIT_COUNT, "The number of large pages allocated (includes disabled).");
1313 STAM_REL_REG(pVM, &pPGM->cLargePagesDisabled, STAMTYPE_U32, "/PGM/Page/cLargePagesDisabled", STAMUNIT_COUNT, "The number of disabled large pages.");
1314#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1315 STAM_REL_REG(pVM, &pPGM->ChunkR3Map.c, STAMTYPE_U32, "/PGM/ChunkR3Map/c", STAMUNIT_COUNT, "Number of mapped chunks.");
1316 STAM_REL_REG(pVM, &pPGM->ChunkR3Map.cMax, STAMTYPE_U32, "/PGM/ChunkR3Map/cMax", STAMUNIT_COUNT, "Maximum number of mapped chunks.");
1317 STAM_REL_REG(pVM, &pPGM->cMappedChunks, STAMTYPE_U32, "/PGM/ChunkR3Map/Mapped", STAMUNIT_COUNT, "Number of times we mapped a chunk.");
1318 STAM_REL_REG(pVM, &pPGM->cUnmappedChunks, STAMTYPE_U32, "/PGM/ChunkR3Map/Unmapped", STAMUNIT_COUNT, "Number of times we unmapped a chunk.");
1319#endif
1320
1321 STAM_REL_REG(pVM, &pPGM->StatLargePageReused, STAMTYPE_COUNTER, "/PGM/LargePage/Reused", STAMUNIT_OCCURENCES, "The number of times we've reused a large page.");
1322 STAM_REL_REG(pVM, &pPGM->StatLargePageRefused, STAMTYPE_COUNTER, "/PGM/LargePage/Refused", STAMUNIT_OCCURENCES, "The number of times we couldn't use a large page.");
1323 STAM_REL_REG(pVM, &pPGM->StatLargePageRecheck, STAMTYPE_COUNTER, "/PGM/LargePage/Recheck", STAMUNIT_OCCURENCES, "The number of times we've rechecked a disabled large page.");
1324
1325 STAM_REL_REG(pVM, &pPGM->StatShModCheck, STAMTYPE_PROFILE, "/PGM/ShMod/Check", STAMUNIT_TICKS_PER_CALL, "Profiles the shared module checking.");
1326 STAM_REL_REG(pVM, &pPGM->StatMmio2QueryAndResetDirtyBitmap, STAMTYPE_PROFILE, "/PGM/Mmio2QueryAndResetDirtyBitmap", STAMUNIT_TICKS_PER_CALL, "Profiles calls to PGMR3PhysMmio2QueryAndResetDirtyBitmap (sans locking).");
1327
1328 /* Live save */
1329 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.fActive, STAMTYPE_U8, "/PGM/LiveSave/fActive", STAMUNIT_COUNT, "Active or not.");
1330 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.cIgnoredPages, STAMTYPE_U32, "/PGM/LiveSave/cIgnoredPages", STAMUNIT_COUNT, "The number of ignored pages in the RAM ranges (i.e. MMIO, MMIO2 and ROM).");
1331 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.cDirtyPagesLong, STAMTYPE_U32, "/PGM/LiveSave/cDirtyPagesLong", STAMUNIT_COUNT, "Longer term dirty page average.");
1332 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.cDirtyPagesShort, STAMTYPE_U32, "/PGM/LiveSave/cDirtyPagesShort", STAMUNIT_COUNT, "Short term dirty page average.");
1333 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.cPagesPerSecond, STAMTYPE_U32, "/PGM/LiveSave/cPagesPerSecond", STAMUNIT_COUNT, "Pages per second.");
1334 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.cSavedPages, STAMTYPE_U64, "/PGM/LiveSave/cSavedPages", STAMUNIT_COUNT, "The total number of saved pages.");
1335 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Ram.cReadyPages, STAMTYPE_U32, "/PGM/LiveSave/Ram/cReadPages", STAMUNIT_COUNT, "RAM: Ready pages.");
1336 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Ram.cDirtyPages, STAMTYPE_U32, "/PGM/LiveSave/Ram/cDirtyPages", STAMUNIT_COUNT, "RAM: Dirty pages.");
1337 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Ram.cZeroPages, STAMTYPE_U32, "/PGM/LiveSave/Ram/cZeroPages", STAMUNIT_COUNT, "RAM: Ready zero pages.");
1338 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Ram.cMonitoredPages, STAMTYPE_U32, "/PGM/LiveSave/Ram/cMonitoredPages", STAMUNIT_COUNT, "RAM: Write monitored pages.");
1339 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Rom.cReadyPages, STAMTYPE_U32, "/PGM/LiveSave/Rom/cReadPages", STAMUNIT_COUNT, "ROM: Ready pages.");
1340 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Rom.cDirtyPages, STAMTYPE_U32, "/PGM/LiveSave/Rom/cDirtyPages", STAMUNIT_COUNT, "ROM: Dirty pages.");
1341 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Rom.cZeroPages, STAMTYPE_U32, "/PGM/LiveSave/Rom/cZeroPages", STAMUNIT_COUNT, "ROM: Ready zero pages.");
1342 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Rom.cMonitoredPages, STAMTYPE_U32, "/PGM/LiveSave/Rom/cMonitoredPages", STAMUNIT_COUNT, "ROM: Write monitored pages.");
1343 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Mmio2.cReadyPages, STAMTYPE_U32, "/PGM/LiveSave/Mmio2/cReadPages", STAMUNIT_COUNT, "MMIO2: Ready pages.");
1344 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Mmio2.cDirtyPages, STAMTYPE_U32, "/PGM/LiveSave/Mmio2/cDirtyPages", STAMUNIT_COUNT, "MMIO2: Dirty pages.");
1345 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Mmio2.cZeroPages, STAMTYPE_U32, "/PGM/LiveSave/Mmio2/cZeroPages", STAMUNIT_COUNT, "MMIO2: Ready zero pages.");
1346 STAM_REL_REG_USED(pVM, &pPGM->LiveSave.Mmio2.cMonitoredPages,STAMTYPE_U32, "/PGM/LiveSave/Mmio2/cMonitoredPages",STAMUNIT_COUNT, "MMIO2: Write monitored pages.");
1347
1348#define PGM_REG_COUNTER(a, b, c) \
1349 rc = STAMR3RegisterF(pVM, a, STAMTYPE_COUNTER, STAMVISIBILITY_ALWAYS, STAMUNIT_OCCURENCES, c, b); \
1350 AssertRC(rc);
1351
1352#define PGM_REG_U64(a, b, c) \
1353 rc = STAMR3RegisterF(pVM, a, STAMTYPE_U64, STAMVISIBILITY_ALWAYS, STAMUNIT_OCCURENCES, c, b); \
1354 AssertRC(rc);
1355
1356#define PGM_REG_U64_RESET(a, b, c) \
1357 rc = STAMR3RegisterF(pVM, a, STAMTYPE_U64_RESET, STAMVISIBILITY_ALWAYS, STAMUNIT_OCCURENCES, c, b); \
1358 AssertRC(rc);
1359
1360#define PGM_REG_U32(a, b, c) \
1361 rc = STAMR3RegisterF(pVM, a, STAMTYPE_U32, STAMVISIBILITY_ALWAYS, STAMUNIT_OCCURENCES, c, b); \
1362 AssertRC(rc);
1363
1364#define PGM_REG_COUNTER_BYTES(a, b, c) \
1365 rc = STAMR3RegisterF(pVM, a, STAMTYPE_COUNTER, STAMVISIBILITY_ALWAYS, STAMUNIT_BYTES, c, b); \
1366 AssertRC(rc);
1367
1368#define PGM_REG_PROFILE(a, b, c) \
1369 rc = STAMR3RegisterF(pVM, a, STAMTYPE_PROFILE, STAMVISIBILITY_ALWAYS, STAMUNIT_TICKS_PER_CALL, c, b); \
1370 AssertRC(rc);
1371#define PGM_REG_PROFILE_NS(a, b, c) \
1372 rc = STAMR3RegisterF(pVM, a, STAMTYPE_PROFILE, STAMVISIBILITY_ALWAYS, STAMUNIT_NS_PER_CALL, c, b); \
1373 AssertRC(rc);
1374
1375#ifdef VBOX_WITH_STATISTICS
1376 PGMSTATS *pStats = &pPGM->Stats;
1377#endif
1378
1379#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1380 PGM_REG_PROFILE_NS(&pPGM->StatLargePageAlloc, "/PGM/LargePage/Alloc", "Time spent by the host OS for large page allocation.");
1381 PGM_REG_COUNTER(&pPGM->StatLargePageAllocFailed, "/PGM/LargePage/AllocFailed", "Number of allocation failures.");
1382 PGM_REG_COUNTER(&pPGM->StatLargePageOverflow, "/PGM/LargePage/Overflow", "The number of times allocating a large page took too long.");
1383 PGM_REG_COUNTER(&pPGM->StatLargePageTlbFlush, "/PGM/LargePage/TlbFlush", "The number of times a full VCPU TLB flush was required after a large allocation.");
1384 PGM_REG_COUNTER(&pPGM->StatLargePageZeroEvict, "/PGM/LargePage/ZeroEvict", "The number of zero page mappings we had to evict when allocating a large page.");
1385#endif
1386#ifdef VBOX_WITH_STATISTICS
1387# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1388 PGM_REG_PROFILE(&pStats->StatLargePageAlloc2, "/PGM/LargePage/Alloc2", "Time spent allocating large pages.");
1389 PGM_REG_PROFILE(&pStats->StatLargePageSetup, "/PGM/LargePage/Setup", "Time spent setting up the newly allocated large pages.");
1390 PGM_REG_PROFILE(&pStats->StatR3IsValidLargePage, "/PGM/LargePage/IsValidR3", "pgmPhysIsValidLargePage profiling - R3.");
1391 PGM_REG_PROFILE(&pStats->StatRZIsValidLargePage, "/PGM/LargePage/IsValidRZ", "pgmPhysIsValidLargePage profiling - RZ.");
1392
1393 PGM_REG_COUNTER(&pStats->StatR3DetectedConflicts, "/PGM/R3/DetectedConflicts", "The number of times PGMR3CheckMappingConflicts() detected a conflict.");
1394 PGM_REG_PROFILE(&pStats->StatR3ResolveConflict, "/PGM/R3/ResolveConflict", "pgmR3SyncPTResolveConflict() profiling (includes the entire relocation).");
1395# endif
1396 PGM_REG_COUNTER(&pStats->StatR3PhysRead, "/PGM/R3/Phys/Read", "The number of times PGMPhysRead was called.");
1397 PGM_REG_COUNTER_BYTES(&pStats->StatR3PhysReadBytes, "/PGM/R3/Phys/Read/Bytes", "The number of bytes read by PGMPhysRead.");
1398 PGM_REG_COUNTER(&pStats->StatR3PhysWrite, "/PGM/R3/Phys/Write", "The number of times PGMPhysWrite was called.");
1399 PGM_REG_COUNTER_BYTES(&pStats->StatR3PhysWriteBytes, "/PGM/R3/Phys/Write/Bytes", "The number of bytes written by PGMPhysWrite.");
1400 PGM_REG_COUNTER(&pStats->StatR3PhysSimpleRead, "/PGM/R3/Phys/Simple/Read", "The number of times PGMPhysSimpleReadGCPtr was called.");
1401 PGM_REG_COUNTER_BYTES(&pStats->StatR3PhysSimpleReadBytes, "/PGM/R3/Phys/Simple/Read/Bytes", "The number of bytes read by PGMPhysSimpleReadGCPtr.");
1402 PGM_REG_COUNTER(&pStats->StatR3PhysSimpleWrite, "/PGM/R3/Phys/Simple/Write", "The number of times PGMPhysSimpleWriteGCPtr was called.");
1403 PGM_REG_COUNTER_BYTES(&pStats->StatR3PhysSimpleWriteBytes, "/PGM/R3/Phys/Simple/Write/Bytes", "The number of bytes written by PGMPhysSimpleWriteGCPtr.");
1404
1405# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1406 PGM_REG_COUNTER(&pStats->StatRZChunkR3MapTlbHits, "/PGM/ChunkR3Map/TlbHitsRZ", "TLB hits.");
1407 PGM_REG_COUNTER(&pStats->StatRZChunkR3MapTlbMisses, "/PGM/ChunkR3Map/TlbMissesRZ", "TLB misses.");
1408 PGM_REG_PROFILE(&pStats->StatChunkAging, "/PGM/ChunkR3Map/Map/Aging", "Chunk aging profiling.");
1409 PGM_REG_PROFILE(&pStats->StatChunkFindCandidate, "/PGM/ChunkR3Map/Map/Find", "Chunk unmap find profiling.");
1410 PGM_REG_PROFILE(&pStats->StatChunkUnmap, "/PGM/ChunkR3Map/Map/Unmap", "Chunk unmap of address space profiling.");
1411 PGM_REG_PROFILE(&pStats->StatChunkMap, "/PGM/ChunkR3Map/Map/Map", "Chunk map of address space profiling.");
1412
1413 PGM_REG_COUNTER(&pStats->StatRZPageMapTlbHits, "/PGM/RZ/Page/MapTlbHits", "TLB hits.");
1414 PGM_REG_COUNTER(&pStats->StatRZPageMapTlbMisses, "/PGM/RZ/Page/MapTlbMisses", "TLB misses.");
1415 PGM_REG_COUNTER(&pStats->StatR3ChunkR3MapTlbHits, "/PGM/ChunkR3Map/TlbHitsR3", "TLB hits.");
1416 PGM_REG_COUNTER(&pStats->StatR3ChunkR3MapTlbMisses, "/PGM/ChunkR3Map/TlbMissesR3", "TLB misses.");
1417 PGM_REG_COUNTER(&pStats->StatR3PageMapTlbHits, "/PGM/R3/Page/MapTlbHits", "TLB hits.");
1418 PGM_REG_COUNTER(&pStats->StatR3PageMapTlbMisses, "/PGM/R3/Page/MapTlbMisses", "TLB misses.");
1419 PGM_REG_COUNTER(&pStats->StatPageMapTlbFlushes, "/PGM/R3/Page/MapTlbFlushes", "TLB flushes (all contexts).");
1420 PGM_REG_COUNTER(&pStats->StatPageMapTlbFlushEntry, "/PGM/R3/Page/MapTlbFlushEntry", "TLB entry flushes (all contexts).");
1421# endif
1422
1423 PGM_REG_COUNTER(&pStats->StatRZRamRangeTlbHits, "/PGM/RZ/RamRange/TlbHits", "TLB hits.");
1424 PGM_REG_COUNTER(&pStats->StatRZRamRangeTlbMisses, "/PGM/RZ/RamRange/TlbMisses", "TLB misses.");
1425 PGM_REG_COUNTER(&pStats->StatR3RamRangeTlbHits, "/PGM/R3/RamRange/TlbHits", "TLB hits.");
1426 PGM_REG_COUNTER(&pStats->StatR3RamRangeTlbMisses, "/PGM/R3/RamRange/TlbMisses", "TLB misses.");
1427
1428 PGM_REG_COUNTER(&pStats->StatRZPhysHandlerReset, "/PGM/RZ/PhysHandlerReset", "The number of times PGMHandlerPhysicalReset is called.");
1429 PGM_REG_COUNTER(&pStats->StatR3PhysHandlerReset, "/PGM/R3/PhysHandlerReset", "The number of times PGMHandlerPhysicalReset is called.");
1430 PGM_REG_COUNTER(&pStats->StatRZPhysHandlerLookupHits, "/PGM/RZ/PhysHandlerLookupHits", "The number of cache hits when looking up physical handlers.");
1431 PGM_REG_COUNTER(&pStats->StatR3PhysHandlerLookupHits, "/PGM/R3/PhysHandlerLookupHits", "The number of cache hits when looking up physical handlers.");
1432 PGM_REG_COUNTER(&pStats->StatRZPhysHandlerLookupMisses, "/PGM/RZ/PhysHandlerLookupMisses", "The number of cache misses when looking up physical handlers.");
1433 PGM_REG_COUNTER(&pStats->StatR3PhysHandlerLookupMisses, "/PGM/R3/PhysHandlerLookupMisses", "The number of cache misses when looking up physical handlers.");
1434#endif /* VBOX_WITH_STATISTICS */
1435 PPGMPHYSHANDLERTREE pPhysHndlTree = pVM->pgm.s.pPhysHandlerTree;
1436 PGM_REG_U32(&pPhysHndlTree->m_cErrors, "/PGM/PhysHandlerTree/ErrorsTree", "Physical access handler tree errors.");
1437 PGM_REG_U32(&pVM->pgm.s.PhysHandlerAllocator.m_cErrors, "/PGM/PhysHandlerTree/ErrorsAllocatorR3", "Physical access handler tree allocator errors (ring-3 only).");
1438 PGM_REG_U64_RESET(&pPhysHndlTree->m_cInserts, "/PGM/PhysHandlerTree/Inserts", "Physical access handler tree inserts.");
1439 PGM_REG_U32(&pVM->pgm.s.PhysHandlerAllocator.m_cNodes, "/PGM/PhysHandlerTree/MaxHandlers", "Max physical access handlers.");
1440 PGM_REG_U64_RESET(&pPhysHndlTree->m_cRemovals, "/PGM/PhysHandlerTree/Removals", "Physical access handler tree removals.");
1441 PGM_REG_U64_RESET(&pPhysHndlTree->m_cRebalancingOperations, "/PGM/PhysHandlerTree/RebalancingOperations", "Physical access handler tree rebalancing transformations.");
1442
1443#ifdef VBOX_WITH_STATISTICS
1444 PGM_REG_COUNTER(&pStats->StatRZPageReplaceShared, "/PGM/RZ/Page/ReplacedShared", "Times a shared page was replaced.");
1445 PGM_REG_COUNTER(&pStats->StatRZPageReplaceZero, "/PGM/RZ/Page/ReplacedZero", "Times the zero page was replaced.");
1446/// @todo PGM_REG_COUNTER(&pStats->StatRZPageHandyAllocs, "/PGM/RZ/Page/HandyAllocs", "Number of times we've allocated more handy pages.");
1447 PGM_REG_COUNTER(&pStats->StatR3PageReplaceShared, "/PGM/R3/Page/ReplacedShared", "Times a shared page was replaced.");
1448 PGM_REG_COUNTER(&pStats->StatR3PageReplaceZero, "/PGM/R3/Page/ReplacedZero", "Times the zero page was replaced.");
1449/// @todo PGM_REG_COUNTER(&pStats->StatR3PageHandyAllocs, "/PGM/R3/Page/HandyAllocs", "Number of times we've allocated more handy pages.");
1450
1451 PGM_REG_COUNTER(&pStats->StatRZPhysRead, "/PGM/RZ/Phys/Read", "The number of times PGMPhysRead was called.");
1452 PGM_REG_COUNTER_BYTES(&pStats->StatRZPhysReadBytes, "/PGM/RZ/Phys/Read/Bytes", "The number of bytes read by PGMPhysRead.");
1453 PGM_REG_COUNTER(&pStats->StatRZPhysWrite, "/PGM/RZ/Phys/Write", "The number of times PGMPhysWrite was called.");
1454 PGM_REG_COUNTER_BYTES(&pStats->StatRZPhysWriteBytes, "/PGM/RZ/Phys/Write/Bytes", "The number of bytes written by PGMPhysWrite.");
1455 PGM_REG_COUNTER(&pStats->StatRZPhysSimpleRead, "/PGM/RZ/Phys/Simple/Read", "The number of times PGMPhysSimpleReadGCPtr was called.");
1456 PGM_REG_COUNTER_BYTES(&pStats->StatRZPhysSimpleReadBytes, "/PGM/RZ/Phys/Simple/Read/Bytes", "The number of bytes read by PGMPhysSimpleReadGCPtr.");
1457 PGM_REG_COUNTER(&pStats->StatRZPhysSimpleWrite, "/PGM/RZ/Phys/Simple/Write", "The number of times PGMPhysSimpleWriteGCPtr was called.");
1458 PGM_REG_COUNTER_BYTES(&pStats->StatRZPhysSimpleWriteBytes, "/PGM/RZ/Phys/Simple/Write/Bytes", "The number of bytes written by PGMPhysSimpleWriteGCPtr.");
1459
1460 /* GC only: */
1461# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1462 PGM_REG_COUNTER(&pStats->StatRCInvlPgConflict, "/PGM/RC/InvlPgConflict", "Number of times PGMInvalidatePage() detected a mapping conflict.");
1463 PGM_REG_COUNTER(&pStats->StatRCInvlPgSyncMonCR3, "/PGM/RC/InvlPgSyncMonitorCR3", "Number of times PGMInvalidatePage() ran into PGM_SYNC_MONITOR_CR3.");
1464#endif
1465
1466 PGM_REG_COUNTER(&pStats->StatRCPhysRead, "/PGM/RC/Phys/Read", "The number of times PGMPhysRead was called.");
1467 PGM_REG_COUNTER_BYTES(&pStats->StatRCPhysReadBytes, "/PGM/RC/Phys/Read/Bytes", "The number of bytes read by PGMPhysRead.");
1468 PGM_REG_COUNTER(&pStats->StatRCPhysWrite, "/PGM/RC/Phys/Write", "The number of times PGMPhysWrite was called.");
1469 PGM_REG_COUNTER_BYTES(&pStats->StatRCPhysWriteBytes, "/PGM/RC/Phys/Write/Bytes", "The number of bytes written by PGMPhysWrite.");
1470 PGM_REG_COUNTER(&pStats->StatRCPhysSimpleRead, "/PGM/RC/Phys/Simple/Read", "The number of times PGMPhysSimpleReadGCPtr was called.");
1471 PGM_REG_COUNTER_BYTES(&pStats->StatRCPhysSimpleReadBytes, "/PGM/RC/Phys/Simple/Read/Bytes", "The number of bytes read by PGMPhysSimpleReadGCPtr.");
1472 PGM_REG_COUNTER(&pStats->StatRCPhysSimpleWrite, "/PGM/RC/Phys/Simple/Write", "The number of times PGMPhysSimpleWriteGCPtr was called.");
1473 PGM_REG_COUNTER_BYTES(&pStats->StatRCPhysSimpleWriteBytes, "/PGM/RC/Phys/Simple/Write/Bytes", "The number of bytes written by PGMPhysSimpleWriteGCPtr.");
1474
1475# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1476 PGM_REG_COUNTER(&pStats->StatTrackVirgin, "/PGM/Track/Virgin", "The number of first time shadowings");
1477 PGM_REG_COUNTER(&pStats->StatTrackAliased, "/PGM/Track/Aliased", "The number of times switching to cRef2, i.e. the page is being shadowed by two PTs.");
1478 PGM_REG_COUNTER(&pStats->StatTrackAliasedMany, "/PGM/Track/AliasedMany", "The number of times we're tracking using cRef2.");
1479 PGM_REG_COUNTER(&pStats->StatTrackAliasedLots, "/PGM/Track/AliasedLots", "The number of times we're hitting pages which has overflowed cRef2");
1480 PGM_REG_COUNTER(&pStats->StatTrackOverflows, "/PGM/Track/Overflows", "The number of times the extent list grows too long.");
1481 PGM_REG_COUNTER(&pStats->StatTrackNoExtentsLeft, "/PGM/Track/NoExtentLeft", "The number of times the extent list was exhausted.");
1482 PGM_REG_PROFILE(&pStats->StatTrackDeref, "/PGM/Track/Deref", "Profiling of SyncPageWorkerTrackDeref (expensive).");
1483# endif
1484#endif
1485
1486#undef PGM_REG_COUNTER
1487#undef PGM_REG_U64
1488#undef PGM_REG_U64_RESET
1489#undef PGM_REG_U32
1490#undef PGM_REG_PROFILE
1491#undef PGM_REG_PROFILE_NS
1492
1493 /*
1494 * Note! The layout below matches the member layout exactly!
1495 */
1496
1497 /*
1498 * Common - stats
1499 */
1500 for (VMCPUID idCpu = 0; idCpu < pVM->cCpus; idCpu++)
1501 {
1502 PPGMCPU pPgmCpu = &pVM->apCpusR3[idCpu]->pgm.s;
1503
1504#define PGM_REG_COUNTER(a, b, c) \
1505 rc = STAMR3RegisterF(pVM, a, STAMTYPE_COUNTER, STAMVISIBILITY_ALWAYS, STAMUNIT_OCCURENCES, c, b, idCpu); \
1506 AssertRC(rc);
1507#define PGM_REG_PROFILE(a, b, c) \
1508 rc = STAMR3RegisterF(pVM, a, STAMTYPE_PROFILE, STAMVISIBILITY_ALWAYS, STAMUNIT_TICKS_PER_CALL, c, b, idCpu); \
1509 AssertRC(rc);
1510
1511#ifdef VBOX_VMM_TARGET_X86
1512 PGM_REG_COUNTER(&pPgmCpu->cGuestModeChanges, "/PGM/CPU%u/cGuestModeChanges", "Number of guest mode changes.");
1513 PGM_REG_COUNTER(&pPgmCpu->cA20Changes, "/PGM/CPU%u/cA20Changes", "Number of A20 gate changes.");
1514#endif
1515
1516 PGM_REG_COUNTER(&pPgmCpu->StatRZRamRangeTlbMisses, "/PGM/CPU%u/RZ/RamRange/TlbMisses", "TLB misses (lockless).");
1517 PGM_REG_COUNTER(&pPgmCpu->StatRZRamRangeTlbLocking, "/PGM/CPU%u/RZ/RamRange/TlbLocking", "Lockless TLB failed, falling back on locked lookup.");
1518 PGM_REG_COUNTER(&pPgmCpu->StatRZPageMapTlbMisses, "/PGM/CPU%u/RZ/Page/MapTlbMisses", "Lockless page map TLB failed, falling back on locked lookup.");
1519
1520 PGM_REG_COUNTER(&pPgmCpu->StatR3RamRangeTlbMisses, "/PGM/CPU%u/R3/RamRange/TlbMisses", "TLB misses (lockless).");
1521 PGM_REG_COUNTER(&pPgmCpu->StatR3RamRangeTlbLocking, "/PGM/CPU%u/R3/RamRange/TlbLocking", "Lockless TLB failed, falling back on locked lookup.");
1522 PGM_REG_COUNTER(&pPgmCpu->StatR3PageMapTlbMisses, "/PGM/CPU%u/R3/Page/MapTlbMisses", "Lockless page map TLB failed, falling back on locked lookup.");
1523
1524#ifdef VBOX_WITH_STATISTICS
1525# ifdef VBOX_VMM_TARGET_X86
1526 PGMCPUSTATS *pCpuStats = &pVM->apCpusR3[idCpu]->pgm.s.Stats;
1527
1528# if 0 /* rarely useful; leave for debugging. */
1529 for (unsigned j = 0; j < RT_ELEMENTS(pPgmCpu->StatSyncPtPD); j++)
1530 STAMR3RegisterF(pVM, &pCpuStats->StatSyncPtPD[i], STAMTYPE_COUNTER, STAMVISIBILITY_USED, STAMUNIT_OCCURENCES,
1531 "The number of SyncPT per PD n.", "/PGM/CPU%u/PDSyncPT/%04X", i, j);
1532 for (unsigned j = 0; j < RT_ELEMENTS(pCpuStats->StatSyncPagePD); j++)
1533 STAMR3RegisterF(pVM, &pCpuStats->StatSyncPagePD[i], STAMTYPE_COUNTER, STAMVISIBILITY_USED, STAMUNIT_OCCURENCES,
1534 "The number of SyncPage per PD n.", "/PGM/CPU%u/PDSyncPage/%04X", i, j);
1535# endif
1536 /* R0 only: */
1537 PGM_REG_PROFILE(&pCpuStats->StatR0NpMiscfg, "/PGM/CPU%u/R0/NpMiscfg", "PGMR0Trap0eHandlerNPMisconfig() profiling.");
1538 PGM_REG_COUNTER(&pCpuStats->StatR0NpMiscfgSyncPage, "/PGM/CPU%u/R0/NpMiscfgSyncPage", "SyncPage calls from PGMR0Trap0eHandlerNPMisconfig().");
1539
1540 /* RZ only: */
1541 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0e, "/PGM/CPU%u/RZ/Trap0e", "Profiling of the PGMTrap0eHandler() body.");
1542 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2Ballooned, "/PGM/CPU%u/RZ/Trap0e/Time2/Ballooned", "Profiling of the Trap0eHandler body when the cause is read access to a ballooned page.");
1543 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2DirtyAndAccessed, "/PGM/CPU%u/RZ/Trap0e/Time2/DirtyAndAccessedBits", "Profiling of the Trap0eHandler body when the cause is dirty and/or accessed bit emulation.");
1544 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2GuestTrap, "/PGM/CPU%u/RZ/Trap0e/Time2/GuestTrap", "Profiling of the Trap0eHandler body when the cause is a guest trap.");
1545 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2HndPhys, "/PGM/CPU%u/RZ/Trap0e/Time2/HandlerPhysical", "Profiling of the Trap0eHandler body when the cause is a physical handler.");
1546 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2HndUnhandled, "/PGM/CPU%u/RZ/Trap0e/Time2/HandlerUnhandled", "Profiling of the Trap0eHandler body when the cause is access outside the monitored areas of a monitored page.");
1547 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2InvalidPhys, "/PGM/CPU%u/RZ/Trap0e/Time2/InvalidPhys", "Profiling of the Trap0eHandler body when the cause is access to an invalid physical guest address.");
1548 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2MakeWritable, "/PGM/CPU%u/RZ/Trap0e/Time2/MakeWritable", "Profiling of the Trap0eHandler body when the cause is that a page needed to be made writeable.");
1549 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2Misc, "/PGM/CPU%u/RZ/Trap0e/Time2/Misc", "Profiling of the Trap0eHandler body when the cause is not known.");
1550 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2OutOfSync, "/PGM/CPU%u/RZ/Trap0e/Time2/OutOfSync", "Profiling of the Trap0eHandler body when the cause is an out-of-sync page.");
1551 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2OutOfSyncHndPhys, "/PGM/CPU%u/RZ/Trap0e/Time2/OutOfSyncHndPhys", "Profiling of the Trap0eHandler body when the cause is an out-of-sync physical handler page.");
1552 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2OutOfSyncHndObs, "/PGM/CPU%u/RZ/Trap0e/Time2/OutOfSyncObsHnd", "Profiling of the Trap0eHandler body when the cause is an obsolete handler page.");
1553 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2PageZeroing, "/PGM/CPU%u/RZ/Trap0e/Time2/PageZeroing", "Profiling of the Trap0eHandler body when the cause is that a zero page is being zeroed.");
1554 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2SyncPT, "/PGM/CPU%u/RZ/Trap0e/Time2/SyncPT", "Profiling of the Trap0eHandler body when the cause is lazy syncing of a PT.");
1555 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2WPEmulation, "/PGM/CPU%u/RZ/Trap0e/Time2/WPEmulation", "Profiling of the Trap0eHandler body when the cause is CR0.WP emulation.");
1556 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2Wp0RoUsHack, "/PGM/CPU%u/RZ/Trap0e/Time2/WP0R0USHack", "Profiling of the Trap0eHandler body when the cause is CR0.WP and netware hack to be enabled.");
1557 PGM_REG_PROFILE(&pCpuStats->StatRZTrap0eTime2Wp0RoUsUnhack, "/PGM/CPU%u/RZ/Trap0e/Time2/WP0R0USUnhack", "Profiling of the Trap0eHandler body when the cause is CR0.WP and netware hack to be disabled.");
1558 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eConflicts, "/PGM/CPU%u/RZ/Trap0e/Conflicts", "The number of times #PF was caused by an undetected conflict.");
1559 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eHandlersOutOfSync, "/PGM/CPU%u/RZ/Trap0e/Handlers/OutOfSync", "Number of traps due to out-of-sync handled pages.");
1560 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eHandlersPhysAll, "/PGM/CPU%u/RZ/Trap0e/Handlers/PhysAll", "Number of traps due to physical all-access handlers.");
1561 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eHandlersPhysAllOpt, "/PGM/CPU%u/RZ/Trap0e/Handlers/PhysAllOpt", "Number of the physical all-access handler traps using the optimization.");
1562 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eHandlersPhysWrite, "/PGM/CPU%u/RZ/Trap0e/Handlers/PhysWrite", "Number of traps due to physical write-access handlers.");
1563 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eHandlersUnhandled, "/PGM/CPU%u/RZ/Trap0e/Handlers/Unhandled", "Number of traps due to access outside range of monitored page(s).");
1564 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eHandlersInvalid, "/PGM/CPU%u/RZ/Trap0e/Handlers/Invalid", "Number of traps due to access to invalid physical memory.");
1565 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eUSNotPresentRead, "/PGM/CPU%u/RZ/Trap0e/Err/User/NPRead", "Number of user mode not present read page faults.");
1566 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eUSNotPresentWrite, "/PGM/CPU%u/RZ/Trap0e/Err/User/NPWrite", "Number of user mode not present write page faults.");
1567 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eUSWrite, "/PGM/CPU%u/RZ/Trap0e/Err/User/Write", "Number of user mode write page faults.");
1568 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eUSReserved, "/PGM/CPU%u/RZ/Trap0e/Err/User/Reserved", "Number of user mode reserved bit page faults.");
1569 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eUSNXE, "/PGM/CPU%u/RZ/Trap0e/Err/User/NXE", "Number of user mode NXE page faults.");
1570 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eUSRead, "/PGM/CPU%u/RZ/Trap0e/Err/User/Read", "Number of user mode read page faults.");
1571 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eSVNotPresentRead, "/PGM/CPU%u/RZ/Trap0e/Err/Supervisor/NPRead", "Number of supervisor mode not present read page faults.");
1572 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eSVNotPresentWrite, "/PGM/CPU%u/RZ/Trap0e/Err/Supervisor/NPWrite", "Number of supervisor mode not present write page faults.");
1573 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eSVWrite, "/PGM/CPU%u/RZ/Trap0e/Err/Supervisor/Write", "Number of supervisor mode write page faults.");
1574 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eSVReserved, "/PGM/CPU%u/RZ/Trap0e/Err/Supervisor/Reserved", "Number of supervisor mode reserved bit page faults.");
1575 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eSNXE, "/PGM/CPU%u/RZ/Trap0e/Err/Supervisor/NXE", "Number of supervisor mode NXE page faults.");
1576 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eGuestPF, "/PGM/CPU%u/RZ/Trap0e/GuestPF", "Number of real guest page faults.");
1577 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eWPEmulInRZ, "/PGM/CPU%u/RZ/Trap0e/WP/InRZ", "Number of guest page faults due to X86_CR0_WP emulation.");
1578 PGM_REG_COUNTER(&pCpuStats->StatRZTrap0eWPEmulToR3, "/PGM/CPU%u/RZ/Trap0e/WP/ToR3", "Number of guest page faults due to X86_CR0_WP emulation (forward to R3 for emulation).");
1579# if 0 /* rarely useful; leave for debugging. */
1580 for (unsigned j = 0; j < RT_ELEMENTS(pCpuStats->StatRZTrap0ePD); j++)
1581 STAMR3RegisterF(pVM, &pCpuStats->StatRZTrap0ePD[i], STAMTYPE_COUNTER, STAMVISIBILITY_USED, STAMUNIT_OCCURENCES,
1582 "The number of traps in page directory n.", "/PGM/CPU%u/RZ/Trap0e/PD/%04X", i, j);
1583# endif
1584 PGM_REG_COUNTER(&pCpuStats->StatRZGuestCR3WriteHandled, "/PGM/CPU%u/RZ/CR3WriteHandled", "The number of times the Guest CR3 change was successfully handled.");
1585 PGM_REG_COUNTER(&pCpuStats->StatRZGuestCR3WriteUnhandled, "/PGM/CPU%u/RZ/CR3WriteUnhandled", "The number of times the Guest CR3 change was passed back to the recompiler.");
1586 PGM_REG_COUNTER(&pCpuStats->StatRZGuestCR3WriteConflict, "/PGM/CPU%u/RZ/CR3WriteConflict", "The number of times the Guest CR3 monitoring detected a conflict.");
1587 PGM_REG_COUNTER(&pCpuStats->StatRZGuestROMWriteHandled, "/PGM/CPU%u/RZ/ROMWriteHandled", "The number of times the Guest ROM change was successfully handled.");
1588 PGM_REG_COUNTER(&pCpuStats->StatRZGuestROMWriteUnhandled, "/PGM/CPU%u/RZ/ROMWriteUnhandled", "The number of times the Guest ROM change was passed back to the recompiler.");
1589
1590 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapMigrateInvlPg, "/PGM/CPU%u/RZ/DynMap/MigrateInvlPg", "invlpg count in PGMR0DynMapMigrateAutoSet.");
1591 PGM_REG_PROFILE(&pCpuStats->StatRZDynMapGCPageInl, "/PGM/CPU%u/RZ/DynMap/PageGCPageInl", "Calls to pgmR0DynMapGCPageInlined.");
1592 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapGCPageInlHits, "/PGM/CPU%u/RZ/DynMap/PageGCPageInl/Hits", "Hash table lookup hits.");
1593 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapGCPageInlMisses, "/PGM/CPU%u/RZ/DynMap/PageGCPageInl/Misses", "Misses that falls back to the code common.");
1594 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapGCPageInlRamHits, "/PGM/CPU%u/RZ/DynMap/PageGCPageInl/RamHits", "1st ram range hits.");
1595 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapGCPageInlRamMisses, "/PGM/CPU%u/RZ/DynMap/PageGCPageInl/RamMisses", "1st ram range misses, takes slow path.");
1596 PGM_REG_PROFILE(&pCpuStats->StatRZDynMapHCPageInl, "/PGM/CPU%u/RZ/DynMap/PageHCPageInl", "Calls to pgmRZDynMapHCPageInlined.");
1597 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapHCPageInlHits, "/PGM/CPU%u/RZ/DynMap/PageHCPageInl/Hits", "Hash table lookup hits.");
1598 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapHCPageInlMisses, "/PGM/CPU%u/RZ/DynMap/PageHCPageInl/Misses", "Misses that falls back to the code common.");
1599 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPage, "/PGM/CPU%u/RZ/DynMap/Page", "Calls to pgmR0DynMapPage");
1600 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapSetOptimize, "/PGM/CPU%u/RZ/DynMap/Page/SetOptimize", "Calls to pgmRZDynMapOptimizeAutoSet.");
1601 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapSetSearchFlushes, "/PGM/CPU%u/RZ/DynMap/Page/SetSearchFlushes", "Set search restoring to subset flushes.");
1602 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapSetSearchHits, "/PGM/CPU%u/RZ/DynMap/Page/SetSearchHits", "Set search hits.");
1603 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapSetSearchMisses, "/PGM/CPU%u/RZ/DynMap/Page/SetSearchMisses", "Set search misses.");
1604 PGM_REG_PROFILE(&pCpuStats->StatRZDynMapHCPage, "/PGM/CPU%u/RZ/DynMap/Page/HCPage", "Calls to pgmRZDynMapHCPageCommon (ring-0).");
1605 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageHits0, "/PGM/CPU%u/RZ/DynMap/Page/Hits0", "Hits at iPage+0");
1606 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageHits1, "/PGM/CPU%u/RZ/DynMap/Page/Hits1", "Hits at iPage+1");
1607 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageHits2, "/PGM/CPU%u/RZ/DynMap/Page/Hits2", "Hits at iPage+2");
1608 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageInvlPg, "/PGM/CPU%u/RZ/DynMap/Page/InvlPg", "invlpg count in pgmR0DynMapPageSlow.");
1609 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageSlow, "/PGM/CPU%u/RZ/DynMap/Page/Slow", "Calls to pgmR0DynMapPageSlow - subtract this from pgmR0DynMapPage to get 1st level hits.");
1610 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageSlowLoopHits, "/PGM/CPU%u/RZ/DynMap/Page/SlowLoopHits" , "Hits in the loop path.");
1611 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageSlowLoopMisses, "/PGM/CPU%u/RZ/DynMap/Page/SlowLoopMisses", "Misses in the loop path. NonLoopMisses = Slow - SlowLoopHit - SlowLoopMisses");
1612 //PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPageSlowLostHits, "/PGM/CPU%u/R0/DynMap/Page/SlowLostHits", "Lost hits.");
1613 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapSubsets, "/PGM/CPU%u/RZ/DynMap/Subsets", "Times PGMRZDynMapPushAutoSubset was called.");
1614 PGM_REG_COUNTER(&pCpuStats->StatRZDynMapPopFlushes, "/PGM/CPU%u/RZ/DynMap/SubsetPopFlushes", "Times PGMRZDynMapPopAutoSubset flushes the subset.");
1615 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[0], "/PGM/CPU%u/RZ/DynMap/SetFilledPct000..09", "00-09% filled (RC: min(set-size, dynmap-size))");
1616 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[1], "/PGM/CPU%u/RZ/DynMap/SetFilledPct010..19", "10-19% filled (RC: min(set-size, dynmap-size))");
1617 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[2], "/PGM/CPU%u/RZ/DynMap/SetFilledPct020..29", "20-29% filled (RC: min(set-size, dynmap-size))");
1618 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[3], "/PGM/CPU%u/RZ/DynMap/SetFilledPct030..39", "30-39% filled (RC: min(set-size, dynmap-size))");
1619 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[4], "/PGM/CPU%u/RZ/DynMap/SetFilledPct040..49", "40-49% filled (RC: min(set-size, dynmap-size))");
1620 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[5], "/PGM/CPU%u/RZ/DynMap/SetFilledPct050..59", "50-59% filled (RC: min(set-size, dynmap-size))");
1621 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[6], "/PGM/CPU%u/RZ/DynMap/SetFilledPct060..69", "60-69% filled (RC: min(set-size, dynmap-size))");
1622 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[7], "/PGM/CPU%u/RZ/DynMap/SetFilledPct070..79", "70-79% filled (RC: min(set-size, dynmap-size))");
1623 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[8], "/PGM/CPU%u/RZ/DynMap/SetFilledPct080..89", "80-89% filled (RC: min(set-size, dynmap-size))");
1624 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[9], "/PGM/CPU%u/RZ/DynMap/SetFilledPct090..99", "90-99% filled (RC: min(set-size, dynmap-size))");
1625 PGM_REG_COUNTER(&pCpuStats->aStatRZDynMapSetFilledPct[10], "/PGM/CPU%u/RZ/DynMap/SetFilledPct100", "100% filled (RC: min(set-size, dynmap-size))");
1626
1627 /* HC only: */
1628
1629 /* RZ & R3: */
1630 PGM_REG_PROFILE(&pCpuStats->StatRZSyncCR3, "/PGM/CPU%u/RZ/SyncCR3", "Profiling of the PGMSyncCR3() body.");
1631 PGM_REG_PROFILE(&pCpuStats->StatRZSyncCR3Handlers, "/PGM/CPU%u/RZ/SyncCR3/Handlers", "Profiling of the PGMSyncCR3() update handler section.");
1632 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3Global, "/PGM/CPU%u/RZ/SyncCR3/Global", "The number of global CR3 syncs.");
1633 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3NotGlobal, "/PGM/CPU%u/RZ/SyncCR3/NotGlobal", "The number of non-global CR3 syncs.");
1634 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3DstCacheHit, "/PGM/CPU%u/RZ/SyncCR3/DstChacheHit", "The number of times we got some kind of a cache hit.");
1635 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3DstFreed, "/PGM/CPU%u/RZ/SyncCR3/DstFreed", "The number of times we've had to free a shadow entry.");
1636 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3DstFreedSrcNP, "/PGM/CPU%u/RZ/SyncCR3/DstFreedSrcNP", "The number of times we've had to free a shadow entry for which the source entry was not present.");
1637 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3DstNotPresent, "/PGM/CPU%u/RZ/SyncCR3/DstNotPresent", "The number of times we've encountered a not present shadow entry for a present guest entry.");
1638 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3DstSkippedGlobalPD, "/PGM/CPU%u/RZ/SyncCR3/DstSkippedGlobalPD", "The number of times a global page directory wasn't flushed.");
1639 PGM_REG_COUNTER(&pCpuStats->StatRZSyncCR3DstSkippedGlobalPT, "/PGM/CPU%u/RZ/SyncCR3/DstSkippedGlobalPT", "The number of times a page table with only global entries wasn't flushed.");
1640 PGM_REG_PROFILE(&pCpuStats->StatRZSyncPT, "/PGM/CPU%u/RZ/SyncPT", "Profiling of the pfnSyncPT() body.");
1641 PGM_REG_COUNTER(&pCpuStats->StatRZSyncPTFailed, "/PGM/CPU%u/RZ/SyncPT/Failed", "The number of times pfnSyncPT() failed.");
1642 PGM_REG_COUNTER(&pCpuStats->StatRZSyncPT4K, "/PGM/CPU%u/RZ/SyncPT/4K", "Nr of 4K PT syncs");
1643 PGM_REG_COUNTER(&pCpuStats->StatRZSyncPT4M, "/PGM/CPU%u/RZ/SyncPT/4M", "Nr of 4M PT syncs");
1644 PGM_REG_COUNTER(&pCpuStats->StatRZSyncPagePDNAs, "/PGM/CPU%u/RZ/SyncPagePDNAs", "The number of time we've marked a PD not present from SyncPage to virtualize the accessed bit.");
1645 PGM_REG_COUNTER(&pCpuStats->StatRZSyncPagePDOutOfSync, "/PGM/CPU%u/RZ/SyncPagePDOutOfSync", "The number of time we've encountered an out-of-sync PD in SyncPage.");
1646 PGM_REG_COUNTER(&pCpuStats->StatRZAccessedPage, "/PGM/CPU%u/RZ/AccessedPage", "The number of pages marked not present for accessed bit emulation.");
1647 PGM_REG_PROFILE(&pCpuStats->StatRZDirtyBitTracking, "/PGM/CPU%u/RZ/DirtyPage", "Profiling the dirty bit tracking in CheckPageFault().");
1648 PGM_REG_COUNTER(&pCpuStats->StatRZDirtyPage, "/PGM/CPU%u/RZ/DirtyPage/Mark", "The number of pages marked read-only for dirty bit tracking.");
1649 PGM_REG_COUNTER(&pCpuStats->StatRZDirtyPageBig, "/PGM/CPU%u/RZ/DirtyPage/MarkBig", "The number of 4MB pages marked read-only for dirty bit tracking.");
1650 PGM_REG_COUNTER(&pCpuStats->StatRZDirtyPageSkipped, "/PGM/CPU%u/RZ/DirtyPage/Skipped", "The number of pages already dirty or readonly.");
1651 PGM_REG_COUNTER(&pCpuStats->StatRZDirtyPageTrap, "/PGM/CPU%u/RZ/DirtyPage/Trap", "The number of traps generated for dirty bit tracking.");
1652 PGM_REG_COUNTER(&pCpuStats->StatRZDirtyPageStale, "/PGM/CPU%u/RZ/DirtyPage/Stale", "The number of traps generated for dirty bit tracking (stale tlb entries).");
1653 PGM_REG_COUNTER(&pCpuStats->StatRZDirtiedPage, "/PGM/CPU%u/RZ/DirtyPage/SetDirty", "The number of pages marked dirty because of write accesses.");
1654 PGM_REG_COUNTER(&pCpuStats->StatRZDirtyTrackRealPF, "/PGM/CPU%u/RZ/DirtyPage/RealPF", "The number of real pages faults during dirty bit tracking.");
1655 PGM_REG_COUNTER(&pCpuStats->StatRZPageAlreadyDirty, "/PGM/CPU%u/RZ/DirtyPage/AlreadySet", "The number of pages already marked dirty because of write accesses.");
1656 PGM_REG_PROFILE(&pCpuStats->StatRZInvalidatePage, "/PGM/CPU%u/RZ/InvalidatePage", "PGMInvalidatePage() profiling.");
1657 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePage4KBPages, "/PGM/CPU%u/RZ/InvalidatePage/4KBPages", "The number of times PGMInvalidatePage() was called for a 4KB page.");
1658 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePage4MBPages, "/PGM/CPU%u/RZ/InvalidatePage/4MBPages", "The number of times PGMInvalidatePage() was called for a 4MB page.");
1659 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePage4MBPagesSkip, "/PGM/CPU%u/RZ/InvalidatePage/4MBPagesSkip","The number of times PGMInvalidatePage() skipped a 4MB page.");
1660 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePagePDNAs, "/PGM/CPU%u/RZ/InvalidatePage/PDNAs", "The number of times PGMInvalidatePage() was called for a not accessed page directory.");
1661 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePagePDNPs, "/PGM/CPU%u/RZ/InvalidatePage/PDNPs", "The number of times PGMInvalidatePage() was called for a not present page directory.");
1662 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePagePDOutOfSync, "/PGM/CPU%u/RZ/InvalidatePage/PDOutOfSync", "The number of times PGMInvalidatePage() was called for an out of sync page directory.");
1663 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePageSizeChanges, "/PGM/CPU%u/RZ/InvalidatePage/SizeChanges", "The number of times PGMInvalidatePage() was called on a page size change (4KB <-> 2/4MB).");
1664 PGM_REG_COUNTER(&pCpuStats->StatRZInvalidatePageSkipped, "/PGM/CPU%u/RZ/InvalidatePage/Skipped", "The number of times PGMInvalidatePage() was skipped due to not present shw or pending pending SyncCR3.");
1665 PGM_REG_COUNTER(&pCpuStats->StatRZPageOutOfSyncSupervisor, "/PGM/CPU%u/RZ/OutOfSync/SuperVisor", "Number of traps due to pages out of sync (P) and times VerifyAccessSyncPage calls SyncPage.");
1666 PGM_REG_COUNTER(&pCpuStats->StatRZPageOutOfSyncUser, "/PGM/CPU%u/RZ/OutOfSync/User", "Number of traps due to pages out of sync (P) and times VerifyAccessSyncPage calls SyncPage.");
1667 PGM_REG_COUNTER(&pCpuStats->StatRZPageOutOfSyncSupervisorWrite,"/PGM/CPU%u/RZ/OutOfSync/SuperVisorWrite", "Number of traps due to pages out of sync (RW) and times VerifyAccessSyncPage calls SyncPage.");
1668 PGM_REG_COUNTER(&pCpuStats->StatRZPageOutOfSyncUserWrite, "/PGM/CPU%u/RZ/OutOfSync/UserWrite", "Number of traps due to pages out of sync (RW) and times VerifyAccessSyncPage calls SyncPage.");
1669 PGM_REG_COUNTER(&pCpuStats->StatRZPageOutOfSyncBallloon, "/PGM/CPU%u/RZ/OutOfSync/Balloon", "The number of times a ballooned page was accessed (read).");
1670 PGM_REG_PROFILE(&pCpuStats->StatRZPrefetch, "/PGM/CPU%u/RZ/Prefetch", "PGMPrefetchPage profiling.");
1671 PGM_REG_PROFILE(&pCpuStats->StatRZFlushTLB, "/PGM/CPU%u/RZ/FlushTLB", "Profiling of the PGMFlushTLB() body.");
1672 PGM_REG_COUNTER(&pCpuStats->StatRZFlushTLBNewCR3, "/PGM/CPU%u/RZ/FlushTLB/NewCR3", "The number of times PGMFlushTLB was called with a new CR3, non-global. (switch)");
1673 PGM_REG_COUNTER(&pCpuStats->StatRZFlushTLBNewCR3Global, "/PGM/CPU%u/RZ/FlushTLB/NewCR3Global", "The number of times PGMFlushTLB was called with a new CR3, global. (switch)");
1674 PGM_REG_COUNTER(&pCpuStats->StatRZFlushTLBSameCR3, "/PGM/CPU%u/RZ/FlushTLB/SameCR3", "The number of times PGMFlushTLB was called with the same CR3, non-global. (flush)");
1675 PGM_REG_COUNTER(&pCpuStats->StatRZFlushTLBSameCR3Global, "/PGM/CPU%u/RZ/FlushTLB/SameCR3Global", "The number of times PGMFlushTLB was called with the same CR3, global. (flush)");
1676 PGM_REG_PROFILE(&pCpuStats->StatRZGstModifyPage, "/PGM/CPU%u/RZ/GstModifyPage", "Profiling of the PGMGstModifyPage() body.");
1677 PGM_REG_COUNTER(&pCpuStats->StatRZRamRangeTlbHits, "/PGM/CPU%u/RZ/RamRange/TlbHits", "TLB hits (lockless).");
1678 PGM_REG_COUNTER(&pCpuStats->StatRZPageMapTlbHits, "/PGM/CPU%u/RZ/Page/MapTlbHits", "TLB hits (lockless).");
1679
1680 PGM_REG_PROFILE(&pCpuStats->StatR3SyncCR3, "/PGM/CPU%u/R3/SyncCR3", "Profiling of the PGMSyncCR3() body.");
1681 PGM_REG_PROFILE(&pCpuStats->StatR3SyncCR3Handlers, "/PGM/CPU%u/R3/SyncCR3/Handlers", "Profiling of the PGMSyncCR3() update handler section.");
1682 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3Global, "/PGM/CPU%u/R3/SyncCR3/Global", "The number of global CR3 syncs.");
1683 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3NotGlobal, "/PGM/CPU%u/R3/SyncCR3/NotGlobal", "The number of non-global CR3 syncs.");
1684 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3DstCacheHit, "/PGM/CPU%u/R3/SyncCR3/DstChacheHit", "The number of times we got some kind of a cache hit.");
1685 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3DstFreed, "/PGM/CPU%u/R3/SyncCR3/DstFreed", "The number of times we've had to free a shadow entry.");
1686 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3DstFreedSrcNP, "/PGM/CPU%u/R3/SyncCR3/DstFreedSrcNP", "The number of times we've had to free a shadow entry for which the source entry was not present.");
1687 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3DstNotPresent, "/PGM/CPU%u/R3/SyncCR3/DstNotPresent", "The number of times we've encountered a not present shadow entry for a present guest entry.");
1688 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3DstSkippedGlobalPD, "/PGM/CPU%u/R3/SyncCR3/DstSkippedGlobalPD", "The number of times a global page directory wasn't flushed.");
1689 PGM_REG_COUNTER(&pCpuStats->StatR3SyncCR3DstSkippedGlobalPT, "/PGM/CPU%u/R3/SyncCR3/DstSkippedGlobalPT", "The number of times a page table with only global entries wasn't flushed.");
1690 PGM_REG_PROFILE(&pCpuStats->StatR3SyncPT, "/PGM/CPU%u/R3/SyncPT", "Profiling of the pfnSyncPT() body.");
1691 PGM_REG_COUNTER(&pCpuStats->StatR3SyncPTFailed, "/PGM/CPU%u/R3/SyncPT/Failed", "The number of times pfnSyncPT() failed.");
1692 PGM_REG_COUNTER(&pCpuStats->StatR3SyncPT4K, "/PGM/CPU%u/R3/SyncPT/4K", "Nr of 4K PT syncs");
1693 PGM_REG_COUNTER(&pCpuStats->StatR3SyncPT4M, "/PGM/CPU%u/R3/SyncPT/4M", "Nr of 4M PT syncs");
1694 PGM_REG_COUNTER(&pCpuStats->StatR3SyncPagePDNAs, "/PGM/CPU%u/R3/SyncPagePDNAs", "The number of time we've marked a PD not present from SyncPage to virtualize the accessed bit.");
1695 PGM_REG_COUNTER(&pCpuStats->StatR3SyncPagePDOutOfSync, "/PGM/CPU%u/R3/SyncPagePDOutOfSync", "The number of time we've encountered an out-of-sync PD in SyncPage.");
1696 PGM_REG_COUNTER(&pCpuStats->StatR3AccessedPage, "/PGM/CPU%u/R3/AccessedPage", "The number of pages marked not present for accessed bit emulation.");
1697 PGM_REG_PROFILE(&pCpuStats->StatR3DirtyBitTracking, "/PGM/CPU%u/R3/DirtyPage", "Profiling the dirty bit tracking in CheckPageFault().");
1698 PGM_REG_COUNTER(&pCpuStats->StatR3DirtyPage, "/PGM/CPU%u/R3/DirtyPage/Mark", "The number of pages marked read-only for dirty bit tracking.");
1699 PGM_REG_COUNTER(&pCpuStats->StatR3DirtyPageBig, "/PGM/CPU%u/R3/DirtyPage/MarkBig", "The number of 4MB pages marked read-only for dirty bit tracking.");
1700 PGM_REG_COUNTER(&pCpuStats->StatR3DirtyPageSkipped, "/PGM/CPU%u/R3/DirtyPage/Skipped", "The number of pages already dirty or readonly.");
1701 PGM_REG_COUNTER(&pCpuStats->StatR3DirtyPageTrap, "/PGM/CPU%u/R3/DirtyPage/Trap", "The number of traps generated for dirty bit tracking.");
1702 PGM_REG_COUNTER(&pCpuStats->StatR3DirtiedPage, "/PGM/CPU%u/R3/DirtyPage/SetDirty", "The number of pages marked dirty because of write accesses.");
1703 PGM_REG_COUNTER(&pCpuStats->StatR3DirtyTrackRealPF, "/PGM/CPU%u/R3/DirtyPage/RealPF", "The number of real pages faults during dirty bit tracking.");
1704 PGM_REG_COUNTER(&pCpuStats->StatR3PageAlreadyDirty, "/PGM/CPU%u/R3/DirtyPage/AlreadySet", "The number of pages already marked dirty because of write accesses.");
1705 PGM_REG_PROFILE(&pCpuStats->StatR3InvalidatePage, "/PGM/CPU%u/R3/InvalidatePage", "PGMInvalidatePage() profiling.");
1706 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePage4KBPages, "/PGM/CPU%u/R3/InvalidatePage/4KBPages", "The number of times PGMInvalidatePage() was called for a 4KB page.");
1707 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePage4MBPages, "/PGM/CPU%u/R3/InvalidatePage/4MBPages", "The number of times PGMInvalidatePage() was called for a 4MB page.");
1708 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePage4MBPagesSkip, "/PGM/CPU%u/R3/InvalidatePage/4MBPagesSkip","The number of times PGMInvalidatePage() skipped a 4MB page.");
1709 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePagePDNAs, "/PGM/CPU%u/R3/InvalidatePage/PDNAs", "The number of times PGMInvalidatePage() was called for a not accessed page directory.");
1710 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePagePDNPs, "/PGM/CPU%u/R3/InvalidatePage/PDNPs", "The number of times PGMInvalidatePage() was called for a not present page directory.");
1711 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePagePDOutOfSync, "/PGM/CPU%u/R3/InvalidatePage/PDOutOfSync", "The number of times PGMInvalidatePage() was called for an out of sync page directory.");
1712 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePageSizeChanges, "/PGM/CPU%u/R3/InvalidatePage/SizeChanges", "The number of times PGMInvalidatePage() was called on a page size change (4KB <-> 2/4MB).");
1713 PGM_REG_COUNTER(&pCpuStats->StatR3InvalidatePageSkipped, "/PGM/CPU%u/R3/InvalidatePage/Skipped", "The number of times PGMInvalidatePage() was skipped due to not present shw or pending pending SyncCR3.");
1714 PGM_REG_COUNTER(&pCpuStats->StatR3PageOutOfSyncSupervisor, "/PGM/CPU%u/R3/OutOfSync/SuperVisor", "Number of traps due to pages out of sync and times VerifyAccessSyncPage calls SyncPage.");
1715 PGM_REG_COUNTER(&pCpuStats->StatR3PageOutOfSyncUser, "/PGM/CPU%u/R3/OutOfSync/User", "Number of traps due to pages out of sync and times VerifyAccessSyncPage calls SyncPage.");
1716 PGM_REG_COUNTER(&pCpuStats->StatR3PageOutOfSyncBallloon, "/PGM/CPU%u/R3/OutOfSync/Balloon", "The number of times a ballooned page was accessed (read).");
1717 PGM_REG_PROFILE(&pCpuStats->StatR3Prefetch, "/PGM/CPU%u/R3/Prefetch", "PGMPrefetchPage profiling.");
1718 PGM_REG_PROFILE(&pCpuStats->StatR3FlushTLB, "/PGM/CPU%u/R3/FlushTLB", "Profiling of the PGMFlushTLB() body.");
1719 PGM_REG_COUNTER(&pCpuStats->StatR3FlushTLBNewCR3, "/PGM/CPU%u/R3/FlushTLB/NewCR3", "The number of times PGMFlushTLB was called with a new CR3, non-global. (switch)");
1720 PGM_REG_COUNTER(&pCpuStats->StatR3FlushTLBNewCR3Global, "/PGM/CPU%u/R3/FlushTLB/NewCR3Global", "The number of times PGMFlushTLB was called with a new CR3, global. (switch)");
1721 PGM_REG_COUNTER(&pCpuStats->StatR3FlushTLBSameCR3, "/PGM/CPU%u/R3/FlushTLB/SameCR3", "The number of times PGMFlushTLB was called with the same CR3, non-global. (flush)");
1722 PGM_REG_COUNTER(&pCpuStats->StatR3FlushTLBSameCR3Global, "/PGM/CPU%u/R3/FlushTLB/SameCR3Global", "The number of times PGMFlushTLB was called with the same CR3, global. (flush)");
1723 PGM_REG_PROFILE(&pCpuStats->StatR3GstModifyPage, "/PGM/CPU%u/R3/GstModifyPage", "Profiling of the PGMGstModifyPage() body.");
1724 PGM_REG_COUNTER(&pCpuStats->StatR3RamRangeTlbHits, "/PGM/CPU%u/R3/RamRange/TlbHits", "TLB hits (lockless).");
1725 PGM_REG_COUNTER(&pCpuStats->StatR3PageMapTlbHits, "/PGM/CPU%u/R3/Page/MapTlbHits", "TLB hits (lockless).");
1726# endif /* VBOX_VMM_TARGET_X86 */
1727#endif /* VBOX_WITH_STATISTICS */
1728
1729#undef PGM_REG_PROFILE
1730#undef PGM_REG_COUNTER
1731 }
1732
1733 return VINF_SUCCESS;
1734}
1735
1736
1737/**
1738 * Ring-3 init finalizing.
1739 *
1740 * @returns VBox status code.
1741 * @param pVM The cross context VM structure.
1742 */
1743VMMR3DECL(int) PGMR3InitFinalize(PVM pVM)
1744{
1745#ifdef VBOX_VMM_TARGET_X86
1746 /*
1747 * Determine the max physical address width (MAXPHYADDR) and apply it to
1748 * all the mask members and stuff.
1749 */
1750# if defined(RT_ARCH_AMD64) || defined(RT_ARCH_X86)
1751 uint32_t cMaxPhysAddrWidth;
1752 uint32_t uMaxExtLeaf = ASMCpuId_EAX(0x80000000);
1753 if ( uMaxExtLeaf >= 0x80000008
1754 && uMaxExtLeaf <= 0x80000fff)
1755 {
1756 cMaxPhysAddrWidth = ASMCpuId_EAX(0x80000008) & 0xff;
1757 LogRel(("PGM: The CPU physical address width is %u bits\n", cMaxPhysAddrWidth));
1758 cMaxPhysAddrWidth = RT_MIN(52, cMaxPhysAddrWidth);
1759 pVM->pgm.s.fLessThan52PhysicalAddressBits = cMaxPhysAddrWidth < 52;
1760 for (uint32_t iBit = cMaxPhysAddrWidth; iBit < 52; iBit++)
1761 pVM->pgm.s.HCPhysInvMmioPg |= RT_BIT_64(iBit);
1762 }
1763 else
1764 {
1765 LogRel(("PGM: ASSUMING CPU physical address width of 48 bits (uMaxExtLeaf=%#x)\n", uMaxExtLeaf));
1766 cMaxPhysAddrWidth = 48;
1767 pVM->pgm.s.fLessThan52PhysicalAddressBits = true;
1768 pVM->pgm.s.HCPhysInvMmioPg |= UINT64_C(0x000f0000000000);
1769 }
1770 /* Disabled the below assertion -- triggers 24 vs 39 on my Intel Skylake box for a 32-bit (Guest-type Other/Unknown) VM. */
1771 //AssertMsg(pVM->cpum.ro.GuestFeatures.cMaxPhysAddrWidth == cMaxPhysAddrWidth,
1772 // ("CPUM %u - PGM %u\n", pVM->cpum.ro.GuestFeatures.cMaxPhysAddrWidth, cMaxPhysAddrWidth));
1773# else
1774 uint32_t const cMaxPhysAddrWidth = pVM->cpum.ro.GuestFeatures.cMaxPhysAddrWidth;
1775 LogRel(("PGM: The (guest) CPU physical address width is %u bits\n", cMaxPhysAddrWidth));
1776# endif
1777
1778 /** @todo query from CPUM. */
1779 pVM->pgm.s.GCPhysInvAddrMask = 0;
1780 for (uint32_t iBit = cMaxPhysAddrWidth; iBit < 64; iBit++)
1781 pVM->pgm.s.GCPhysInvAddrMask |= RT_BIT_64(iBit);
1782
1783 /*
1784 * Initialize the invalid paging entry masks, assuming NX is disabled.
1785 */
1786 uint64_t fMbzPageFrameMask = pVM->pgm.s.GCPhysInvAddrMask & UINT64_C(0x000ffffffffff000);
1787# ifdef VBOX_WITH_NESTED_HWVIRT_VMX_EPT
1788 uint64_t const fEptVpidCap = CPUMGetGuestIa32VmxEptVpidCap(pVM->apCpusR3[0]); /* should be identical for all VCPUs */
1789 uint64_t const fGstEptMbzBigPdeMask = EPT_PDE2M_MBZ_MASK
1790 | (RT_BF_GET(fEptVpidCap, VMX_BF_EPT_VPID_CAP_PDE_2M) ^ 1) << EPT_E_BIT_LEAF;
1791 uint64_t const fGstEptMbzBigPdpteMask = EPT_PDPTE1G_MBZ_MASK
1792 | (RT_BF_GET(fEptVpidCap, VMX_BF_EPT_VPID_CAP_PDPTE_1G) ^ 1) << EPT_E_BIT_LEAF;
1793 //uint64_t const GCPhysRsvdAddrMask = pVM->pgm.s.GCPhysInvAddrMask & UINT64_C(0x000fffffffffffff); /* bits 63:52 ignored */
1794# endif
1795 for (VMCPUID idCpu = 0; idCpu < pVM->cCpus; idCpu++)
1796 {
1797 PVMCPU pVCpu = pVM->apCpusR3[idCpu];
1798
1799 /** @todo The manuals are not entirely clear whether the physical
1800 * address width is relevant. See table 5-9 in the intel
1801 * manual vs the PDE4M descriptions. Write testcase (NP). */
1802 pVCpu->pgm.s.fGst32BitMbzBigPdeMask = ((uint32_t)(fMbzPageFrameMask >> (32 - 13)) & X86_PDE4M_PG_HIGH_MASK)
1803 | X86_PDE4M_MBZ_MASK;
1804
1805 pVCpu->pgm.s.fGstPaeMbzPteMask = fMbzPageFrameMask | X86_PTE_PAE_MBZ_MASK_NO_NX;
1806 pVCpu->pgm.s.fGstPaeMbzPdeMask = fMbzPageFrameMask | X86_PDE_PAE_MBZ_MASK_NO_NX;
1807 pVCpu->pgm.s.fGstPaeMbzBigPdeMask = fMbzPageFrameMask | X86_PDE2M_PAE_MBZ_MASK_NO_NX;
1808 pVCpu->pgm.s.fGstPaeMbzPdpeMask = fMbzPageFrameMask | X86_PDPE_PAE_MBZ_MASK;
1809
1810 pVCpu->pgm.s.fGstAmd64MbzPteMask = fMbzPageFrameMask | X86_PTE_LM_MBZ_MASK_NO_NX;
1811 pVCpu->pgm.s.fGstAmd64MbzPdeMask = fMbzPageFrameMask | X86_PDE_LM_MBZ_MASK_NX;
1812 pVCpu->pgm.s.fGstAmd64MbzBigPdeMask = fMbzPageFrameMask | X86_PDE2M_LM_MBZ_MASK_NX;
1813 pVCpu->pgm.s.fGstAmd64MbzPdpeMask = fMbzPageFrameMask | X86_PDPE_LM_MBZ_MASK_NO_NX;
1814 pVCpu->pgm.s.fGstAmd64MbzBigPdpeMask = fMbzPageFrameMask | X86_PDPE1G_LM_MBZ_MASK_NO_NX;
1815 pVCpu->pgm.s.fGstAmd64MbzPml4eMask = fMbzPageFrameMask | X86_PML4E_MBZ_MASK_NO_NX;
1816
1817 pVCpu->pgm.s.fGst64ShadowedPteMask = X86_PTE_P | X86_PTE_RW | X86_PTE_US | X86_PTE_G | X86_PTE_A | X86_PTE_D;
1818 pVCpu->pgm.s.fGst64ShadowedPdeMask = X86_PDE_P | X86_PDE_RW | X86_PDE_US | X86_PDE_A;
1819 pVCpu->pgm.s.fGst64ShadowedBigPdeMask = X86_PDE4M_P | X86_PDE4M_RW | X86_PDE4M_US | X86_PDE4M_A;
1820 pVCpu->pgm.s.fGst64ShadowedBigPde4PteMask
1821 = X86_PDE4M_P | X86_PDE4M_RW | X86_PDE4M_US | X86_PDE4M_G | X86_PDE4M_A | X86_PDE4M_D;
1822 pVCpu->pgm.s.fGstAmd64ShadowedPdpeMask = X86_PDPE_P | X86_PDPE_RW | X86_PDPE_US | X86_PDPE_A;
1823 pVCpu->pgm.s.fGstAmd64ShadowedPml4eMask = X86_PML4E_P | X86_PML4E_RW | X86_PML4E_US | X86_PML4E_A;
1824
1825# ifdef VBOX_WITH_NESTED_HWVIRT_VMX_EPT
1826 pVCpu->pgm.s.uEptVpidCapMsr = fEptVpidCap;
1827 pVCpu->pgm.s.fGstEptMbzPteMask = fMbzPageFrameMask | EPT_PTE_MBZ_MASK;
1828 pVCpu->pgm.s.fGstEptMbzPdeMask = fMbzPageFrameMask | EPT_PDE_MBZ_MASK;
1829 pVCpu->pgm.s.fGstEptMbzBigPdeMask = fMbzPageFrameMask | fGstEptMbzBigPdeMask;
1830 pVCpu->pgm.s.fGstEptMbzPdpteMask = fMbzPageFrameMask | EPT_PDPTE_MBZ_MASK;
1831 pVCpu->pgm.s.fGstEptMbzBigPdpteMask = fMbzPageFrameMask | fGstEptMbzBigPdpteMask;
1832 pVCpu->pgm.s.fGstEptMbzPml4eMask = fMbzPageFrameMask | EPT_PML4E_MBZ_MASK;
1833
1834 /* If any of the features in the assert below are enabled, additional bits would need to be shadowed. */
1835 Assert( !pVM->cpum.ro.GuestFeatures.fVmxModeBasedExecuteEpt
1836 && !pVM->cpum.ro.GuestFeatures.fVmxSppEpt
1837 && !pVM->cpum.ro.GuestFeatures.fVmxEptXcptVe
1838 && !(fEptVpidCap & MSR_IA32_VMX_EPT_VPID_CAP_ACCESS_DIRTY));
1839 /* We currently do -not- shadow reserved bits in guest page tables but instead trap them using non-present permissions,
1840 see todo in (NestedSyncPT). */
1841 pVCpu->pgm.s.fGstEptShadowedPteMask = EPT_PRESENT_MASK;
1842 pVCpu->pgm.s.fGstEptShadowedPdeMask = EPT_PRESENT_MASK;
1843 pVCpu->pgm.s.fGstEptShadowedBigPdeMask = EPT_PRESENT_MASK | EPT_E_LEAF;
1844 pVCpu->pgm.s.fGstEptShadowedPdpteMask = EPT_PRESENT_MASK;
1845 pVCpu->pgm.s.fGstEptShadowedPml4eMask = EPT_PRESENT_MASK | EPT_PML4E_MBZ_MASK;
1846 /* If mode-based execute control for EPT is enabled, we would need to include bit 10 in the present mask. */
1847 pVCpu->pgm.s.fGstEptPresentMask = EPT_PRESENT_MASK;
1848# endif
1849 }
1850
1851 /*
1852 * Note that AMD uses all the 8 reserved bits for the address (so 40 bits in total);
1853 * Intel only goes up to 36 bits, so we stick to 36 as well.
1854 * Update: More recent intel manuals specifies 40 bits just like AMD.
1855 */
1856 uint32_t u32Dummy, u32Features;
1857 CPUMGetGuestCpuId(VMMGetCpu(pVM), 1, 0, -1 /*f64BitMode*/, &u32Dummy, &u32Dummy, &u32Dummy, &u32Features);
1858 if (u32Features & X86_CPUID_FEATURE_EDX_PSE36)
1859 pVM->pgm.s.GCPhys4MBPSEMask = RT_BIT_64(RT_MAX(36, cMaxPhysAddrWidth)) - 1;
1860 else
1861 pVM->pgm.s.GCPhys4MBPSEMask = RT_BIT_64(32) - 1;
1862#endif /* VBOX_VMM_TARGET_X86 */
1863
1864 /*
1865 * Allocate memory if we're supposed to do that.
1866 */
1867 int rc = VINF_SUCCESS;
1868#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1869 if (pVM->pgm.s.fRamPreAlloc)
1870 rc = pgmR3PhysRamPreAllocate(pVM);
1871#endif
1872
1873 //pgmLogState(pVM);
1874#ifdef VBOX_VMM_TARGET_X86
1875 LogRel(("PGM: PGMR3InitFinalize: 4 MB PSE mask %RGp -> %Rrc\n", pVM->pgm.s.GCPhys4MBPSEMask, rc));
1876#else
1877 LogRel(("PGM: PGMR3InitFinalize: -> %Rrc\n", rc));
1878 RT_NOREF(pVM);
1879#endif
1880 return rc;
1881}
1882
1883
1884/**
1885 * Init phase completed callback.
1886 *
1887 * @returns VBox status code.
1888 * @param pVM The cross context VM structure.
1889 * @param enmWhat What has been completed.
1890 * @thread EMT(0)
1891 */
1892VMMR3_INT_DECL(int) PGMR3InitCompleted(PVM pVM, VMINITCOMPLETED enmWhat)
1893{
1894 switch (enmWhat)
1895 {
1896 case VMINITCOMPLETED_HM:
1897#ifdef VBOX_WITH_PCI_PASSTHROUGH
1898 if (pVM->pgm.s.fPciPassthrough)
1899 {
1900 AssertLogRelReturn(pVM->pgm.s.fRamPreAlloc, VERR_PCI_PASSTHROUGH_NO_RAM_PREALLOC);
1901 AssertLogRelReturn(HMIsEnabled(pVM), VERR_PCI_PASSTHROUGH_NO_HM);
1902 AssertLogRelReturn(HMIsNestedPagingActive(pVM), VERR_PCI_PASSTHROUGH_NO_NESTED_PAGING);
1903
1904 /*
1905 * Report assignments to the IOMMU (hope that's good enough for now).
1906 */
1907 if (pVM->pgm.s.fPciPassthrough)
1908 {
1909 int rc = VMMR3CallR0(pVM, VMMR0_DO_PGM_PHYS_SETUP_IOMMU, 0, NULL);
1910 AssertRCReturn(rc, rc);
1911 }
1912 }
1913#else
1914 AssertLogRelReturn(!pVM->pgm.s.fPciPassthrough, VERR_PGM_PCI_PASSTHRU_MISCONFIG);
1915#endif
1916 break;
1917
1918 default:
1919 /* shut up gcc */
1920 break;
1921 }
1922
1923 return VINF_SUCCESS;
1924}
1925
1926
1927/**
1928 * Applies relocations to data and code managed by this component.
1929 *
1930 * This function will be called at init and whenever the VMM need to relocate it
1931 * self inside the GC.
1932 *
1933 * @param pVM The cross context VM structure.
1934 * @param offDelta Relocation delta relative to old location.
1935 */
1936VMMR3DECL(void) PGMR3Relocate(PVM pVM, RTGCINTPTR offDelta)
1937{
1938#ifdef VBOX_VMM_TARGET_X86
1939 LogFlow(("PGMR3Relocate: offDelta=%RGv\n", offDelta));
1940
1941 /*
1942 * Paging stuff.
1943 */
1944
1945 /* Shadow, guest and both mode switch & relocation for each VCPU. */
1946 for (VMCPUID i = 0; i < pVM->cCpus; i++)
1947 {
1948 PVMCPU pVCpu = pVM->apCpusR3[i];
1949
1950 uintptr_t idxShw = pVCpu->pgm.s.idxShadowModeData;
1951 if ( idxShw < RT_ELEMENTS(g_aPgmShadowModeData)
1952 && g_aPgmShadowModeData[idxShw].pfnRelocate)
1953 g_aPgmShadowModeData[idxShw].pfnRelocate(pVCpu, offDelta);
1954 else
1955 AssertFailed();
1956
1957 uintptr_t const idxGst = pVCpu->pgm.s.idxGuestModeData;
1958 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
1959 && g_aPgmGuestModeData[idxGst].pfnRelocate)
1960 g_aPgmGuestModeData[idxGst].pfnRelocate(pVCpu, offDelta);
1961 else
1962 AssertFailed();
1963 }
1964
1965# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
1966 /*
1967 * The page pool.
1968 */
1969 pgmR3PoolRelocate(pVM);
1970# endif
1971
1972#else
1973 RT_NOREF(pVM, offDelta);
1974#endif
1975}
1976
1977
1978/**
1979 * Resets a virtual CPU when unplugged.
1980 *
1981 * @param pVM The cross context VM structure.
1982 * @param pVCpu The cross context virtual CPU structure.
1983 */
1984VMMR3DECL(void) PGMR3ResetCpu(PVM pVM, PVMCPU pVCpu)
1985{
1986#ifdef VBOX_VMM_TARGET_X86
1987 uintptr_t const idxGst = pVCpu->pgm.s.idxGuestModeData;
1988 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
1989 && g_aPgmGuestModeData[idxGst].pfnExit)
1990 {
1991 int rc = g_aPgmGuestModeData[idxGst].pfnExit(pVCpu);
1992 AssertReleaseRC(rc);
1993 }
1994 pVCpu->pgm.s.GCPhysCR3 = NIL_RTGCPHYS;
1995 pVCpu->pgm.s.GCPhysNstGstCR3 = NIL_RTGCPHYS;
1996 pVCpu->pgm.s.GCPhysPaeCR3 = NIL_RTGCPHYS;
1997
1998 int rc = PGMHCChangeMode(pVM, pVCpu, PGMMODE_REAL, false /* fForce */);
1999 AssertReleaseRC(rc);
2000
2001 STAM_REL_COUNTER_RESET(&pVCpu->pgm.s.cGuestModeChanges);
2002
2003# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2004 pgmR3PoolResetUnpluggedCpu(pVM, pVCpu);
2005# endif
2006
2007 /*
2008 * Re-init other members.
2009 */
2010 pVCpu->pgm.s.fA20Enabled = true;
2011 pVCpu->pgm.s.GCPhysA20Mask = ~((RTGCPHYS)!pVCpu->pgm.s.fA20Enabled << 20);
2012
2013 /*
2014 * Clear the FFs PGM owns.
2015 */
2016 VMCPU_FF_CLEAR(pVCpu, VMCPU_FF_PGM_SYNC_CR3);
2017 VMCPU_FF_CLEAR(pVCpu, VMCPU_FF_PGM_SYNC_CR3_NON_GLOBAL);
2018
2019#elif defined(VBOX_VMM_TARGET_ARMV8)
2020 RT_NOREF(pVM);
2021
2022 for (uint8_t i = 0; i < RT_ELEMENTS(pVCpu->pgm.s.aidxGuestModeDataTtbr0); i++)
2023 {
2024 uintptr_t const idxGst = pVCpu->pgm.s.aidxGuestModeDataTtbr0[i];
2025 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
2026 && g_aPgmGuestModeData[idxGst].pfnExit)
2027 {
2028 int rc = g_aPgmGuestModeData[idxGst].pfnExit(pVCpu);
2029 AssertReleaseRC(rc);
2030 }
2031 }
2032
2033 for (uint8_t i = 0; i < RT_ELEMENTS(pVCpu->pgm.s.aidxGuestModeDataTtbr1); i++)
2034 {
2035 uintptr_t const idxGst = pVCpu->pgm.s.aidxGuestModeDataTtbr1[i];
2036 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
2037 && g_aPgmGuestModeData[idxGst].pfnExit)
2038 {
2039 int rc = g_aPgmGuestModeData[idxGst].pfnExit(pVCpu);
2040 AssertReleaseRC(rc);
2041 }
2042 }
2043
2044 /* This ASSUMES that SCTLR_EL1 and TCR_EL1 are reset to 0 in CPUM. */
2045 int rc = PGMChangeMode(pVCpu, 1 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
2046 AssertReleaseRC(rc);
2047
2048 rc = PGMChangeMode(pVCpu, 2 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
2049 AssertReleaseRC(rc);
2050
2051 rc = PGMChangeMode(pVCpu, 3 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
2052 AssertReleaseRC(rc);
2053
2054 STAM_REL_COUNTER_RESET(&pVCpu->pgm.s.cGuestModeChanges);
2055#else
2056 RT_NOREF(pVM, pVCpu);
2057#endif
2058}
2059
2060
2061/**
2062 * The VM is being reset.
2063 *
2064 * For the PGM component this means that any PD write monitors
2065 * needs to be removed.
2066 *
2067 * @param pVM The cross context VM structure.
2068 */
2069VMMR3_INT_DECL(void) PGMR3Reset(PVM pVM)
2070{
2071 LogFlow(("PGMR3Reset:\n"));
2072 VM_ASSERT_EMT(pVM);
2073
2074 PGM_LOCK_VOID(pVM);
2075
2076 /*
2077 * Exit the guest paging mode before the pgm pool gets reset.
2078 * Important to clean up the amd64 case.
2079 */
2080 for (VMCPUID i = 0; i < pVM->cCpus; i++)
2081 {
2082 PVMCPU pVCpu = pVM->apCpusR3[i];
2083
2084#ifdef VBOX_VMM_TARGET_X86
2085 uintptr_t const idxGst = pVCpu->pgm.s.idxGuestModeData;
2086 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
2087 && g_aPgmGuestModeData[idxGst].pfnExit)
2088 {
2089 int rc = g_aPgmGuestModeData[idxGst].pfnExit(pVCpu);
2090 AssertReleaseRC(rc);
2091 }
2092 pVCpu->pgm.s.GCPhysCR3 = NIL_RTGCPHYS;
2093 pVCpu->pgm.s.GCPhysNstGstCR3 = NIL_RTGCPHYS;
2094
2095#elif defined(VBOX_VMM_TARGET_ARMV8)
2096 for (uint8_t iEl = 0; iEl < RT_ELEMENTS(pVCpu->pgm.s.aidxGuestModeDataTtbr0); iEl++)
2097 {
2098 uintptr_t const idxGst = pVCpu->pgm.s.aidxGuestModeDataTtbr0[iEl];
2099 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
2100 && g_aPgmGuestModeData[idxGst].pfnExit)
2101 {
2102 int rc = g_aPgmGuestModeData[idxGst].pfnExit(pVCpu);
2103 AssertReleaseRC(rc);
2104 }
2105 }
2106
2107 for (uint8_t iEl = 0; iEl < RT_ELEMENTS(pVCpu->pgm.s.aidxGuestModeDataTtbr1); iEl++)
2108 {
2109 uintptr_t const idxGst = pVCpu->pgm.s.aidxGuestModeDataTtbr1[iEl];
2110 if ( idxGst < RT_ELEMENTS(g_aPgmGuestModeData)
2111 && g_aPgmGuestModeData[idxGst].pfnExit)
2112 {
2113 int rc = g_aPgmGuestModeData[idxGst].pfnExit(pVCpu);
2114 AssertReleaseRC(rc);
2115 }
2116 }
2117
2118#else
2119 RT_NOREF(pVCpu);
2120#endif
2121 }
2122
2123#ifdef DEBUG
2124 DBGFR3_INFO_LOG_SAFE(pVM, "mappings", NULL);
2125 DBGFR3_INFO_LOG_SAFE(pVM, "handlers", "all nostat");
2126#endif
2127
2128 /*
2129 * Switch mode back to real mode. (Before resetting the pgm pool!)
2130 */
2131 for (VMCPUID i = 0; i < pVM->cCpus; i++)
2132 {
2133 PVMCPU pVCpu = pVM->apCpusR3[i];
2134
2135#ifdef VBOX_VMM_TARGET_X86
2136 int rc = PGMHCChangeMode(pVM, pVCpu, PGMMODE_REAL, false /* fForce */);
2137 AssertReleaseRC(rc);
2138
2139 STAM_REL_COUNTER_RESET(&pVCpu->pgm.s.cA20Changes);
2140
2141#elif defined(VBOX_VMM_TARGET_ARMV8)
2142 /* This ASSUMES that SCTLR_EL1 and TCR_EL1 are reset to 0 in CPUM. */
2143 int rc = PGMChangeMode(pVCpu, 1 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
2144 AssertReleaseRC(rc);
2145
2146 rc = PGMChangeMode(pVCpu, 2 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
2147 AssertReleaseRC(rc);
2148
2149 rc = PGMChangeMode(pVCpu, 3 /*bEl*/, 0 /* u64RegSctlr*/, 0 /* u64RegTcr*/);
2150 AssertReleaseRC(rc);
2151
2152#else
2153 RT_NOREF(pVCpu);
2154#endif
2155
2156 STAM_REL_COUNTER_RESET(&pVCpu->pgm.s.cGuestModeChanges);
2157 }
2158
2159#ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2160 /*
2161 * Reset the shadow page pool.
2162 */
2163 pgmR3PoolReset(pVM);
2164#endif
2165
2166#ifdef VBOX_VMM_TARGET_X86
2167 /*
2168 * Re-init various other members and clear the FFs that PGM owns.
2169 */
2170 for (VMCPUID i = 0; i < pVM->cCpus; i++)
2171 {
2172 PVMCPU pVCpu = pVM->apCpusR3[i];
2173
2174 pVCpu->pgm.s.fGst32BitPageSizeExtension = false;
2175 PGMNotifyNxeChanged(pVCpu, false);
2176
2177 VMCPU_FF_CLEAR(pVCpu, VMCPU_FF_PGM_SYNC_CR3);
2178 VMCPU_FF_CLEAR(pVCpu, VMCPU_FF_PGM_SYNC_CR3_NON_GLOBAL);
2179
2180 if (!pVCpu->pgm.s.fA20Enabled)
2181 {
2182 pVCpu->pgm.s.fA20Enabled = true;
2183 pVCpu->pgm.s.GCPhysA20Mask = ~((RTGCPHYS)!pVCpu->pgm.s.fA20Enabled << 20);
2184# ifdef PGM_WITH_A20
2185 VMCPU_FF_SET(pVCpu, VMCPU_FF_PGM_SYNC_CR3);
2186# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2187 pgmR3RefreshShadowModeAfterA20Change(pVCpu);
2188 HMFlushTlb(pVCpu);
2189# endif
2190# endif
2191 }
2192 }
2193#endif /* VBOX_VMM_TARGET_X86 */
2194
2195 //pgmLogState(pVM);
2196 PGM_UNLOCK(pVM);
2197}
2198
2199
2200/**
2201 * Memory setup after VM construction or reset.
2202 *
2203 * @param pVM The cross context VM structure.
2204 * @param fAtReset Indicates the context, after reset if @c true or after
2205 * construction if @c false.
2206 */
2207VMMR3_INT_DECL(void) PGMR3MemSetup(PVM pVM, bool fAtReset)
2208{
2209 if (fAtReset)
2210 {
2211 PGM_LOCK_VOID(pVM);
2212
2213 int rc = pgmR3PhysRamZeroAll(pVM);
2214 AssertReleaseRC(rc);
2215
2216 rc = pgmR3PhysRomReset(pVM);
2217 AssertReleaseRC(rc);
2218
2219 PGM_UNLOCK(pVM);
2220 }
2221}
2222
2223
2224#ifdef VBOX_STRICT
2225/**
2226 * VM state change callback for clearing fNoMorePhysWrites after
2227 * a snapshot has been created.
2228 */
2229static DECLCALLBACK(void) pgmR3ResetNoMorePhysWritesFlag(PUVM pUVM, PCVMMR3VTABLE pVMM, VMSTATE enmState,
2230 VMSTATE enmOldState, void *pvUser)
2231{
2232 if ( enmState == VMSTATE_RUNNING
2233 || enmState == VMSTATE_RESUMING)
2234 pUVM->pVM->pgm.s.fNoMorePhysWrites = false;
2235 RT_NOREF(pVMM, enmOldState, pvUser);
2236}
2237#endif
2238
2239/**
2240 * Private API to reset fNoMorePhysWrites.
2241 */
2242VMMR3_INT_DECL(void) PGMR3ResetNoMorePhysWritesFlag(PVM pVM)
2243{
2244 pVM->pgm.s.fNoMorePhysWrites = false;
2245}
2246
2247/**
2248 * Terminates the PGM.
2249 *
2250 * @returns VBox status code.
2251 * @param pVM The cross context VM structure.
2252 */
2253VMMR3DECL(int) PGMR3Term(PVM pVM)
2254{
2255 /* Must free shared pages here. */
2256 PGM_LOCK_VOID(pVM);
2257 pgmR3PhysRamTerm(pVM);
2258 pgmR3PhysRomTerm(pVM);
2259 PGM_UNLOCK(pVM);
2260
2261 PGMDeregisterStringFormatTypes();
2262 return PDMR3CritSectDelete(pVM, &pVM->pgm.s.CritSectX);
2263}
2264
2265
2266#ifdef VBOX_VMM_TARGET_X86
2267/**
2268 * Show paging mode.
2269 *
2270 * @param pVM The cross context VM structure.
2271 * @param pHlp The info helpers.
2272 * @param pszArgs "all" (default), "guest", "shadow" or "host".
2273 */
2274static DECLCALLBACK(void) pgmR3InfoMode(PVM pVM, PCDBGFINFOHLP pHlp, const char *pszArgs)
2275{
2276 /* digest argument. */
2277 bool fGuest, fShadow, fHost;
2278 if (pszArgs)
2279 pszArgs = RTStrStripL(pszArgs);
2280 if (!pszArgs || !*pszArgs || strstr(pszArgs, "all"))
2281 fShadow = fHost = fGuest = true;
2282 else
2283 {
2284 fShadow = fHost = fGuest = false;
2285 if (strstr(pszArgs, "guest"))
2286 fGuest = true;
2287 if (strstr(pszArgs, "shadow"))
2288 fShadow = true;
2289 if (strstr(pszArgs, "host"))
2290 fHost = true;
2291 }
2292
2293 PVMCPU pVCpu = VMMGetCpu(pVM);
2294 if (!pVCpu)
2295 pVCpu = pVM->apCpusR3[0];
2296
2297
2298 /* print info. */
2299 if (fGuest)
2300 {
2301 pHlp->pfnPrintf(pHlp, "Guest paging mode (VCPU #%u): %s (changed %RU64 times), A20 %s (changed %RU64 times)\n",
2302 pVCpu->idCpu, PGMGetModeName(pVCpu->pgm.s.enmGuestMode), pVCpu->pgm.s.cGuestModeChanges.c,
2303 pVCpu->pgm.s.fA20Enabled ? "enabled" : "disabled", pVCpu->pgm.s.cA20Changes.c);
2304# ifdef VBOX_WITH_NESTED_HWVIRT_VMX_EPT
2305 if (pVCpu->pgm.s.enmGuestSlatMode != PGMSLAT_INVALID)
2306 pHlp->pfnPrintf(pHlp, "Guest SLAT mode (VCPU #%u): %s\n", pVCpu->idCpu,
2307 PGMGetSlatModeName(pVCpu->pgm.s.enmGuestSlatMode));
2308# endif
2309 }
2310 if (fShadow)
2311 pHlp->pfnPrintf(pHlp, "Shadow paging mode (VCPU #%u): %s\n", pVCpu->idCpu, PGMGetModeName(pVCpu->pgm.s.enmShadowMode));
2312 if (fHost)
2313 {
2314 const char *psz;
2315 switch (pVM->pgm.s.enmHostMode)
2316 {
2317 case SUPPAGINGMODE_INVALID: psz = "invalid"; break;
2318 case SUPPAGINGMODE_32_BIT: psz = "32-bit"; break;
2319 case SUPPAGINGMODE_32_BIT_GLOBAL: psz = "32-bit+G"; break;
2320 case SUPPAGINGMODE_PAE: psz = "PAE"; break;
2321 case SUPPAGINGMODE_PAE_GLOBAL: psz = "PAE+G"; break;
2322 case SUPPAGINGMODE_PAE_NX: psz = "PAE+NX"; break;
2323 case SUPPAGINGMODE_PAE_GLOBAL_NX: psz = "PAE+G+NX"; break;
2324 case SUPPAGINGMODE_AMD64: psz = "AMD64"; break;
2325 case SUPPAGINGMODE_AMD64_GLOBAL: psz = "AMD64+G"; break;
2326 case SUPPAGINGMODE_AMD64_NX: psz = "AMD64+NX"; break;
2327 case SUPPAGINGMODE_AMD64_GLOBAL_NX: psz = "AMD64+G+NX"; break;
2328 default: psz = "unknown"; break;
2329 }
2330 pHlp->pfnPrintf(pHlp, "Host paging mode: %s\n", psz);
2331 }
2332}
2333#endif /* VBOX_VMM_TARGET_X86 */
2334
2335
2336/**
2337 * Display the RAM range info.
2338 *
2339 * @param pVM The cross context VM structure.
2340 * @param pHlp The info helpers.
2341 * @param pszArgs Arguments, ignored.
2342 */
2343static DECLCALLBACK(void) pgmR3PhysInfo(PVM pVM, PCDBGFINFOHLP pHlp, const char *pszArgs)
2344{
2345 bool const fVerbose = pszArgs && strstr(pszArgs, "verbose") != NULL;
2346
2347 pHlp->pfnPrintf(pHlp,
2348 "RAM ranges (pVM=%p)\n"
2349 "%.*s %.*s\n",
2350 pVM,
2351 sizeof(RTGCPHYS) * 4 + 1, "GC Phys Range ",
2352 sizeof(RTHCPTR) * 2, "pbR3 ");
2353
2354 /*
2355 * Traverse the lookup table so we only display mapped MMIO and get it in sorted order.
2356 */
2357 uint32_t const cRamRangeLookupEntries = RT_MIN(pVM->pgm.s.RamRangeUnion.cLookupEntries,
2358 RT_ELEMENTS(pVM->pgm.s.aRamRangeLookup));
2359 for (uint32_t idxLookup = 0; idxLookup < cRamRangeLookupEntries; idxLookup++)
2360 {
2361 uint32_t const idRamRange = PGMRAMRANGELOOKUPENTRY_GET_ID(pVM->pgm.s.aRamRangeLookup[idxLookup]);
2362 AssertContinue(idRamRange < RT_ELEMENTS(pVM->pgm.s.apRamRanges));
2363 PPGMRAMRANGE const pCur = pVM->pgm.s.apRamRanges[idRamRange];
2364 if (pCur != NULL) { /*likely*/ }
2365 else continue;
2366
2367 pHlp->pfnPrintf(pHlp,
2368 "%RGp-%RGp %RHv %s\n",
2369 pCur->GCPhys,
2370 pCur->GCPhysLast,
2371 pCur->pbR3,
2372 pCur->pszDesc);
2373 if (fVerbose)
2374 {
2375 RTGCPHYS const cPages = pCur->cb >> X86_PAGE_SHIFT;
2376 RTGCPHYS iPage = 0;
2377 while (iPage < cPages)
2378 {
2379 RTGCPHYS const iFirstPage = iPage;
2380 PGMPAGETYPE const enmType = (PGMPAGETYPE)PGM_PAGE_GET_TYPE(&pCur->aPages[iPage]);
2381 do
2382 iPage++;
2383 while (iPage < cPages && (PGMPAGETYPE)PGM_PAGE_GET_TYPE(&pCur->aPages[iPage]) == enmType);
2384 const char *pszType;
2385 const char *pszMore = NULL;
2386 switch (enmType)
2387 {
2388 case PGMPAGETYPE_RAM:
2389 pszType = "RAM";
2390 break;
2391
2392 case PGMPAGETYPE_MMIO2:
2393 pszType = "MMIO2";
2394 break;
2395
2396 case PGMPAGETYPE_MMIO2_ALIAS_MMIO:
2397 pszType = "MMIO2-alias-MMIO";
2398 break;
2399
2400 case PGMPAGETYPE_SPECIAL_ALIAS_MMIO:
2401 pszType = "special-alias-MMIO";
2402 break;
2403
2404 case PGMPAGETYPE_ROM_SHADOW:
2405 case PGMPAGETYPE_ROM:
2406 {
2407 pszType = enmType == PGMPAGETYPE_ROM_SHADOW ? "ROM-shadowed" : "ROM";
2408
2409 RTGCPHYS const GCPhysFirstPg = iFirstPage << GUEST_PAGE_SHIFT;
2410 uint32_t const cRomRanges = RT_MIN(pVM->pgm.s.cRomRanges, RT_ELEMENTS(pVM->pgm.s.apRomRanges));
2411 for (uint32_t idxRom = 0; idxRom < cRomRanges; idxRom++)
2412 {
2413 PPGMROMRANGE const pRomRange = pVM->pgm.s.apRomRanges[idxRom];
2414 if ( pRomRange
2415 && GCPhysFirstPg < pRomRange->GCPhysLast
2416 && GCPhysFirstPg >= pRomRange->GCPhys)
2417 {
2418 pszMore = pRomRange->pszDesc;
2419 break;
2420 }
2421 }
2422 break;
2423 }
2424
2425 case PGMPAGETYPE_MMIO:
2426 {
2427 pszType = "MMIO";
2428 PGM_LOCK_VOID(pVM);
2429 PPGMPHYSHANDLER pHandler;
2430 int rc = pgmHandlerPhysicalLookup(pVM, iFirstPage * X86_PAGE_SIZE, &pHandler);
2431 if (RT_SUCCESS(rc))
2432 pszMore = pHandler->pszDesc;
2433 PGM_UNLOCK(pVM);
2434 break;
2435 }
2436
2437 case PGMPAGETYPE_INVALID:
2438 pszType = "invalid";
2439 break;
2440
2441 default:
2442 pszType = "bad";
2443 break;
2444 }
2445 if (pszMore)
2446 pHlp->pfnPrintf(pHlp, " %RGp-%RGp %-20s %s\n",
2447 pCur->GCPhys + iFirstPage * X86_PAGE_SIZE,
2448 pCur->GCPhys + iPage * X86_PAGE_SIZE - 1,
2449 pszType, pszMore);
2450 else
2451 pHlp->pfnPrintf(pHlp, " %RGp-%RGp %s\n",
2452 pCur->GCPhys + iFirstPage * X86_PAGE_SIZE,
2453 pCur->GCPhys + iPage * X86_PAGE_SIZE - 1,
2454 pszType);
2455
2456 }
2457 }
2458 }
2459}
2460
2461#ifdef VBOX_VMM_TARGET_X86
2462
2463/**
2464 * Dump the page directory to the log.
2465 *
2466 * @param pVM The cross context VM structure.
2467 * @param pHlp The info helpers.
2468 * @param pszArgs Arguments, ignored.
2469 */
2470static DECLCALLBACK(void) pgmR3InfoCr3(PVM pVM, PCDBGFINFOHLP pHlp, const char *pszArgs)
2471{
2472 /** @todo SMP support!! */
2473 PVMCPU pVCpu = pVM->apCpusR3[0];
2474
2475/** @todo fix this! Convert the PGMR3DumpHierarchyHC functions to do guest stuff. */
2476 /* Big pages supported? */
2477 const bool fPSE = !!(CPUMGetGuestCR4(pVCpu) & X86_CR4_PSE);
2478
2479 /* Global pages supported? */
2480 const bool fPGE = !!(CPUMGetGuestCR4(pVCpu) & X86_CR4_PGE);
2481
2482 NOREF(pszArgs);
2483
2484 /*
2485 * Get page directory addresses.
2486 */
2487 PGM_LOCK_VOID(pVM);
2488 PX86PD pPDSrc = pgmGstGet32bitPDPtr(pVCpu);
2489 Assert(pPDSrc);
2490
2491 /*
2492 * Iterate the page directory.
2493 */
2494 for (unsigned iPD = 0; iPD < RT_ELEMENTS(pPDSrc->a); iPD++)
2495 {
2496 X86PDE PdeSrc = pPDSrc->a[iPD];
2497 if (PdeSrc.u & X86_PDE_P)
2498 {
2499 if ((PdeSrc.u & X86_PDE_PS) && fPSE)
2500 pHlp->pfnPrintf(pHlp,
2501 "%04X - %RGp P=%d U=%d RW=%d G=%d - BIG\n",
2502 iPD,
2503 pgmGstGet4MBPhysPage(pVM, PdeSrc), PdeSrc.u & X86_PDE_P, !!(PdeSrc.u & X86_PDE_US),
2504 !!(PdeSrc.u & X86_PDE_RW), (PdeSrc.u & X86_PDE4M_G) && fPGE);
2505 else
2506 pHlp->pfnPrintf(pHlp,
2507 "%04X - %RGp P=%d U=%d RW=%d [G=%d]\n",
2508 iPD,
2509 (RTGCPHYS)(PdeSrc.u & X86_PDE_PG_MASK), PdeSrc.u & X86_PDE_P, !!(PdeSrc.u & X86_PDE_US),
2510 !!(PdeSrc.u & X86_PDE_RW), (PdeSrc.u & X86_PDE4M_G) && fPGE);
2511 }
2512 }
2513 PGM_UNLOCK(pVM);
2514}
2515
2516# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2517
2518/**
2519 * Called by pgmPoolFlushAllInt prior to flushing the pool.
2520 *
2521 * @returns VBox status code, fully asserted.
2522 * @param pVCpu The cross context virtual CPU structure.
2523 */
2524int pgmR3ExitShadowModeBeforePoolFlush(PVMCPU pVCpu)
2525{
2526 /* Unmap the old CR3 value before flushing everything. */
2527 int rc = VINF_SUCCESS;
2528 uintptr_t idxBth = pVCpu->pgm.s.idxBothModeData;
2529 if ( idxBth < RT_ELEMENTS(g_aPgmBothModeData)
2530 && g_aPgmBothModeData[idxBth].pfnUnmapCR3)
2531 {
2532 rc = g_aPgmBothModeData[idxBth].pfnUnmapCR3(pVCpu);
2533 AssertRC(rc);
2534 }
2535
2536 /* Exit the current shadow paging mode as well; nested paging and EPT use a root CR3 which will get flushed here. */
2537 uintptr_t idxShw = pVCpu->pgm.s.idxShadowModeData;
2538 if ( idxShw < RT_ELEMENTS(g_aPgmShadowModeData)
2539 && g_aPgmShadowModeData[idxShw].pfnExit)
2540 {
2541 rc = g_aPgmShadowModeData[idxShw].pfnExit(pVCpu);
2542 AssertMsgRCReturn(rc, ("Exit failed for shadow mode %d: %Rrc\n", pVCpu->pgm.s.enmShadowMode, rc), rc);
2543 }
2544
2545# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2546 Assert(pVCpu->pgm.s.pShwPageCR3R3 == NULL);
2547# endif
2548 return rc;
2549}
2550
2551
2552/**
2553 * Called by pgmPoolFlushAllInt after flushing the pool.
2554 *
2555 * @returns VBox status code, fully asserted.
2556 * @param pVM The cross context VM structure.
2557 * @param pVCpu The cross context virtual CPU structure.
2558 */
2559int pgmR3ReEnterShadowModeAfterPoolFlush(PVM pVM, PVMCPU pVCpu)
2560{
2561 pVCpu->pgm.s.enmShadowMode = PGMMODE_INVALID;
2562 int rc = PGMHCChangeMode(pVM, pVCpu, PGMGetGuestMode(pVCpu), false /* fForce */);
2563 Assert(VMCPU_FF_IS_SET(pVCpu, VMCPU_FF_PGM_SYNC_CR3));
2564 AssertRCReturn(rc, rc);
2565 AssertRCSuccessReturn(rc, VERR_IPE_UNEXPECTED_INFO_STATUS);
2566
2567# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2568 Assert(pVCpu->pgm.s.pShwPageCR3R3 != NULL || pVCpu->pgm.s.enmShadowMode == PGMMODE_NONE);
2569# endif
2570 AssertMsg( pVCpu->pgm.s.enmShadowMode >= PGMMODE_NESTED_32BIT
2571 || CPUMGetHyperCR3(pVCpu) == PGMGetHyperCR3(pVCpu),
2572 ("%RHp != %RHp %s\n", (RTHCPHYS)CPUMGetHyperCR3(pVCpu), PGMGetHyperCR3(pVCpu), PGMGetModeName(pVCpu->pgm.s.enmShadowMode)));
2573 return rc;
2574}
2575
2576
2577/**
2578 * Called by PGMR3PhysSetA20 after changing the A20 state.
2579 *
2580 * @param pVCpu The cross context virtual CPU structure.
2581 */
2582void pgmR3RefreshShadowModeAfterA20Change(PVMCPU pVCpu)
2583{
2584 /** @todo Probably doing a bit too much here. */
2585 int rc = pgmR3ExitShadowModeBeforePoolFlush(pVCpu);
2586 AssertReleaseRC(rc);
2587 rc = pgmR3ReEnterShadowModeAfterPoolFlush(pVCpu->CTX_SUFF(pVM), pVCpu);
2588 AssertReleaseRC(rc);
2589}
2590
2591# endif /* !VBOX_WITH_ONLY_PGM_NEM_MODE */
2592#endif /* VBOX_VMM_TARGET_X86 */
2593#ifdef VBOX_WITH_DEBUGGER
2594# ifndef VBOX_WITH_ONLY_PGM_NEM_MODE
2595
2596/**
2597 * @callback_method_impl{FNDBGCCMD, The '.pgmerror' and '.pgmerroroff' commands.}
2598 */
2599static DECLCALLBACK(int) pgmR3CmdError(PCDBGCCMD pCmd, PDBGCCMDHLP pCmdHlp, PUVM pUVM, PCDBGCVAR paArgs, unsigned cArgs)
2600{
2601 /*
2602 * Validate input.
2603 */
2604 DBGC_CMDHLP_REQ_UVM_RET(pCmdHlp, pCmd, pUVM);
2605 PVM pVM = pUVM->pVM;
2606 DBGC_CMDHLP_ASSERT_PARSER_RET(pCmdHlp, pCmd, 0, cArgs == 0 || (cArgs == 1 && paArgs[0].enmType == DBGCVAR_TYPE_STRING));
2607
2608 if (!cArgs)
2609 {
2610 /*
2611 * Print the list of error injection locations with status.
2612 */
2613 DBGCCmdHlpPrintf(pCmdHlp, "PGM error inject locations:\n");
2614 DBGCCmdHlpPrintf(pCmdHlp, " handy - %RTbool\n", pVM->pgm.s.fErrInjHandyPages);
2615 }
2616 else
2617 {
2618 /*
2619 * String switch on where to inject the error.
2620 */
2621 bool const fNewState = !strcmp(pCmd->pszCmd, "pgmerror");
2622 const char *pszWhere = paArgs[0].u.pszString;
2623 if (!strcmp(pszWhere, "handy"))
2624 ASMAtomicWriteBool(&pVM->pgm.s.fErrInjHandyPages, fNewState);
2625 else
2626 return DBGCCmdHlpPrintf(pCmdHlp, "error: Invalid 'where' value: %s.\n", pszWhere);
2627 DBGCCmdHlpPrintf(pCmdHlp, "done\n");
2628 }
2629 return VINF_SUCCESS;
2630}
2631
2632
2633/**
2634 * @callback_method_impl{FNDBGCCMD, The '.pgmsync' command.}
2635 */
2636static DECLCALLBACK(int) pgmR3CmdSync(PCDBGCCMD pCmd, PDBGCCMDHLP pCmdHlp, PUVM pUVM, PCDBGCVAR paArgs, unsigned cArgs)
2637{
2638 /*
2639 * Validate input.
2640 */
2641 NOREF(pCmd); NOREF(paArgs); NOREF(cArgs);
2642 DBGC_CMDHLP_REQ_UVM_RET(pCmdHlp, pCmd, pUVM);
2643 PVMCPU pVCpu = VMMR3GetCpuByIdU(pUVM, DBGCCmdHlpGetCurrentCpu(pCmdHlp));
2644 if (!pVCpu)
2645 return DBGCCmdHlpFail(pCmdHlp, pCmd, "Invalid CPU ID");
2646
2647 /*
2648 * Force page directory sync.
2649 */
2650 VMCPU_FF_SET(pVCpu, VMCPU_FF_PGM_SYNC_CR3);
2651
2652 int rc = DBGCCmdHlpPrintf(pCmdHlp, "Forcing page directory sync.\n");
2653 if (RT_FAILURE(rc))
2654 return rc;
2655
2656 return VINF_SUCCESS;
2657}
2658
2659# if defined(VBOX_STRICT) && defined(VBOX_VMM_TARGET_X86)
2660
2661/**
2662 * EMT callback for pgmR3CmdAssertCR3.
2663 *
2664 * @returns VBox status code.
2665 * @param pUVM The user mode VM handle.
2666 * @param pcErrors Where to return the error count.
2667 */
2668static DECLCALLBACK(int) pgmR3CmdAssertCR3EmtWorker(PUVM pUVM, unsigned *pcErrors)
2669{
2670 PVM pVM = pUVM->pVM;
2671 VM_ASSERT_VALID_EXT_RETURN(pVM, VERR_INVALID_VM_HANDLE);
2672 PVMCPU pVCpu = VMMGetCpu(pVM);
2673
2674 *pcErrors = PGMAssertCR3(pVM, pVCpu, CPUMGetGuestCR3(pVCpu), CPUMGetGuestCR4(pVCpu));
2675
2676 return VINF_SUCCESS;
2677}
2678
2679
2680/**
2681 * @callback_method_impl{FNDBGCCMD, The '.pgmassertcr3' command.}
2682 */
2683static DECLCALLBACK(int) pgmR3CmdAssertCR3(PCDBGCCMD pCmd, PDBGCCMDHLP pCmdHlp, PUVM pUVM, PCDBGCVAR paArgs, unsigned cArgs)
2684{
2685 /*
2686 * Validate input.
2687 */
2688 NOREF(pCmd); NOREF(paArgs); NOREF(cArgs);
2689 DBGC_CMDHLP_REQ_UVM_RET(pCmdHlp, pCmd, pUVM);
2690
2691 int rc = DBGCCmdHlpPrintf(pCmdHlp, "Checking shadow CR3 page tables for consistency.\n");
2692 if (RT_FAILURE(rc))
2693 return rc;
2694
2695 unsigned cErrors = 0;
2696 rc = VMR3ReqCallWaitU(pUVM, DBGCCmdHlpGetCurrentCpu(pCmdHlp), (PFNRT)pgmR3CmdAssertCR3EmtWorker, 2, pUVM, &cErrors);
2697 if (RT_FAILURE(rc))
2698 return DBGCCmdHlpFail(pCmdHlp, pCmd, "VMR3ReqCallWaitU failed: %Rrc", rc);
2699 if (cErrors > 0)
2700 return DBGCCmdHlpFail(pCmdHlp, pCmd, "PGMAssertCR3: %u error(s)", cErrors);
2701 return DBGCCmdHlpPrintf(pCmdHlp, "PGMAssertCR3: OK\n");
2702}
2703
2704# endif /* VBOX_STRICT */
2705
2706/**
2707 * @callback_method_impl{FNDBGCCMD, The '.pgmsyncalways' command.}
2708 */
2709static DECLCALLBACK(int) pgmR3CmdSyncAlways(PCDBGCCMD pCmd, PDBGCCMDHLP pCmdHlp, PUVM pUVM, PCDBGCVAR paArgs, unsigned cArgs)
2710{
2711 /*
2712 * Validate input.
2713 */
2714 NOREF(pCmd); NOREF(paArgs); NOREF(cArgs);
2715 DBGC_CMDHLP_REQ_UVM_RET(pCmdHlp, pCmd, pUVM);
2716 PVMCPU pVCpu = VMMR3GetCpuByIdU(pUVM, DBGCCmdHlpGetCurrentCpu(pCmdHlp));
2717 if (!pVCpu)
2718 return DBGCCmdHlpFail(pCmdHlp, pCmd, "Invalid CPU ID");
2719
2720 /*
2721 * Force page directory sync.
2722 */
2723 int rc;
2724 if (pVCpu->pgm.s.fSyncFlags & PGM_SYNC_ALWAYS)
2725 {
2726 ASMAtomicAndU32(&pVCpu->pgm.s.fSyncFlags, ~PGM_SYNC_ALWAYS);
2727 rc = DBGCCmdHlpPrintf(pCmdHlp, "Disabled permanent forced page directory syncing.\n");
2728 }
2729 else
2730 {
2731 ASMAtomicOrU32(&pVCpu->pgm.s.fSyncFlags, PGM_SYNC_ALWAYS);
2732 VMCPU_FF_SET(pVCpu, VMCPU_FF_PGM_SYNC_CR3);
2733 rc = DBGCCmdHlpPrintf(pCmdHlp, "Enabled permanent forced page directory syncing.\n");
2734 }
2735 return rc;
2736}
2737
2738# endif /* !VBOX_WITH_ONLY_PGM_NEM_MODE */
2739
2740/**
2741 * @callback_method_impl{FNDBGCCMD, The '.pgmphystofile' command.}
2742 */
2743static DECLCALLBACK(int) pgmR3CmdPhysToFile(PCDBGCCMD pCmd, PDBGCCMDHLP pCmdHlp, PUVM pUVM, PCDBGCVAR paArgs, unsigned cArgs)
2744{
2745 /*
2746 * Validate input.
2747 */
2748 NOREF(pCmd);
2749 DBGC_CMDHLP_REQ_UVM_RET(pCmdHlp, pCmd, pUVM);
2750 PVM pVM = pUVM->pVM;
2751 DBGC_CMDHLP_ASSERT_PARSER_RET(pCmdHlp, pCmd, 0, cArgs == 1 || cArgs == 2);
2752 DBGC_CMDHLP_ASSERT_PARSER_RET(pCmdHlp, pCmd, 0, paArgs[0].enmType == DBGCVAR_TYPE_STRING);
2753 if (cArgs == 2)
2754 {
2755 DBGC_CMDHLP_ASSERT_PARSER_RET(pCmdHlp, pCmd, 1, paArgs[1].enmType == DBGCVAR_TYPE_STRING);
2756 if (strcmp(paArgs[1].u.pszString, "nozero"))
2757 return DBGCCmdHlpFail(pCmdHlp, pCmd, "Invalid 2nd argument '%s', must be 'nozero'.\n", paArgs[1].u.pszString);
2758 }
2759 bool fIncZeroPgs = cArgs < 2;
2760
2761 /*
2762 * Open the output file and get the ram parameters.
2763 */
2764 RTFILE hFile;
2765 int rc = RTFileOpen(&hFile, paArgs[0].u.pszString, RTFILE_O_WRITE | RTFILE_O_CREATE_REPLACE | RTFILE_O_DENY_WRITE);
2766 if (RT_FAILURE(rc))
2767 return DBGCCmdHlpPrintf(pCmdHlp, "error: RTFileOpen(,'%s',) -> %Rrc.\n", paArgs[0].u.pszString, rc);
2768
2769 uint32_t cbRamHole = 0;
2770 CFGMR3QueryU32Def(CFGMR3GetRootU(pUVM), "RamHoleSize", &cbRamHole, MM_RAM_HOLE_SIZE_DEFAULT);
2771 uint64_t cbRam = 0;
2772 CFGMR3QueryU64Def(CFGMR3GetRootU(pUVM), "RamSize", &cbRam, 0);
2773 RTGCPHYS GCPhysEnd = cbRam + cbRamHole;
2774
2775 /*
2776 * Dump the physical memory, page by page.
2777 */
2778 RTGCPHYS GCPhys = 0;
2779 char abZeroPg[GUEST_PAGE_SIZE];
2780 RT_ZERO(abZeroPg);
2781
2782 PGM_LOCK_VOID(pVM);
2783
2784 uint32_t const cRamRangeLookupEntries = RT_MIN(pVM->pgm.s.RamRangeUnion.cLookupEntries,
2785 RT_ELEMENTS(pVM->pgm.s.aRamRangeLookup));
2786 for (uint32_t idxLookup = 0; idxLookup < cRamRangeLookupEntries && RT_SUCCESS(rc); idxLookup++)
2787 {
2788 if (PGMRAMRANGELOOKUPENTRY_GET_FIRST(pVM->pgm.s.aRamRangeLookup[idxLookup]) >= GCPhysEnd)
2789 break;
2790 uint32_t const idRamRange = PGMRAMRANGELOOKUPENTRY_GET_ID(pVM->pgm.s.aRamRangeLookup[idxLookup]);
2791 AssertContinue(idRamRange < RT_ELEMENTS(pVM->pgm.s.apRamRanges));
2792 PPGMRAMRANGE const pRam = pVM->pgm.s.apRamRanges[idRamRange];
2793 AssertContinue(pRam);
2794 Assert(pRam->GCPhys == PGMRAMRANGELOOKUPENTRY_GET_FIRST(pVM->pgm.s.aRamRangeLookup[idxLookup]));
2795
2796 /* fill the gap */
2797 if (pRam->GCPhys > GCPhys && fIncZeroPgs)
2798 {
2799 while (pRam->GCPhys > GCPhys && RT_SUCCESS(rc))
2800 {
2801 rc = RTFileWrite(hFile, abZeroPg, GUEST_PAGE_SIZE, NULL);
2802 GCPhys += GUEST_PAGE_SIZE;
2803 }
2804 }
2805
2806 PCPGMPAGE pPage = &pRam->aPages[0];
2807 while (GCPhys < pRam->GCPhysLast && RT_SUCCESS(rc))
2808 {
2809 if ( PGM_PAGE_IS_ZERO(pPage)
2810 || PGM_PAGE_IS_BALLOONED(pPage))
2811 {
2812 if (fIncZeroPgs)
2813 {
2814 rc = RTFileWrite(hFile, abZeroPg, GUEST_PAGE_SIZE, NULL);
2815 if (RT_FAILURE(rc))
2816 DBGCCmdHlpPrintf(pCmdHlp, "error: RTFileWrite -> %Rrc at GCPhys=%RGp.\n", rc, GCPhys);
2817 }
2818 }
2819 else
2820 {
2821 switch (PGM_PAGE_GET_TYPE(pPage))
2822 {
2823 case PGMPAGETYPE_RAM:
2824 case PGMPAGETYPE_ROM_SHADOW: /* trouble?? */
2825 case PGMPAGETYPE_ROM:
2826 case PGMPAGETYPE_MMIO2:
2827 {
2828 void const *pvPage;
2829 PGMPAGEMAPLOCK Lock;
2830 rc = PGMPhysGCPhys2CCPtrReadOnly(pVM, GCPhys, &pvPage, &Lock);
2831 if (RT_SUCCESS(rc))
2832 {
2833 rc = RTFileWrite(hFile, pvPage, GUEST_PAGE_SIZE, NULL);
2834 PGMPhysReleasePageMappingLock(pVM, &Lock);
2835 if (RT_FAILURE(rc))
2836 DBGCCmdHlpPrintf(pCmdHlp, "error: RTFileWrite -> %Rrc at GCPhys=%RGp.\n", rc, GCPhys);
2837 }
2838 else
2839 DBGCCmdHlpPrintf(pCmdHlp, "error: PGMPhysGCPhys2CCPtrReadOnly -> %Rrc at GCPhys=%RGp.\n", rc, GCPhys);
2840 break;
2841 }
2842
2843 default:
2844 AssertFailed();
2845 RT_FALL_THRU();
2846 case PGMPAGETYPE_MMIO:
2847 case PGMPAGETYPE_MMIO2_ALIAS_MMIO:
2848 case PGMPAGETYPE_SPECIAL_ALIAS_MMIO:
2849 if (fIncZeroPgs)
2850 {
2851 rc = RTFileWrite(hFile, abZeroPg, GUEST_PAGE_SIZE, NULL);
2852 if (RT_FAILURE(rc))
2853 DBGCCmdHlpPrintf(pCmdHlp, "error: RTFileWrite -> %Rrc at GCPhys=%RGp.\n", rc, GCPhys);
2854 }
2855 break;
2856 }
2857 }
2858
2859
2860 /* advance */
2861 GCPhys += GUEST_PAGE_SIZE;
2862 pPage++;
2863 }
2864 }
2865 PGM_UNLOCK(pVM);
2866
2867 RTFileClose(hFile);
2868 if (RT_SUCCESS(rc))
2869 return DBGCCmdHlpPrintf(pCmdHlp, "Successfully saved physical memory to '%s'.\n", paArgs[0].u.pszString);
2870 return VINF_SUCCESS;
2871}
2872
2873#endif /* VBOX_WITH_DEBUGGER */
2874
2875/**
2876 * pvUser argument of the pgmR3CheckIntegrity*Node callbacks.
2877 */
2878typedef struct PGMCHECKINTARGS
2879{
2880 bool fLeftToRight; /**< true: left-to-right; false: right-to-left. */
2881 uint32_t cErrors;
2882 PPGMPHYSHANDLER pPrevPhys;
2883 PVM pVM;
2884} PGMCHECKINTARGS, *PPGMCHECKINTARGS;
2885
2886/**
2887 * Validate a node in the physical handler tree.
2888 *
2889 * @returns 0 on if ok, other wise 1.
2890 * @param pNode The handler node.
2891 * @param pvUser pVM.
2892 */
2893static DECLCALLBACK(int) pgmR3CheckIntegrityPhysHandlerNode(PPGMPHYSHANDLER pNode, void *pvUser)
2894{
2895 PPGMCHECKINTARGS pArgs = (PPGMCHECKINTARGS)pvUser;
2896
2897 AssertLogRelMsgReturnStmt(!((uintptr_t)pNode & 7), ("pNode=%p\n", pNode), pArgs->cErrors++, VERR_INVALID_POINTER);
2898
2899 AssertLogRelMsgStmt(pNode->Key <= pNode->KeyLast,
2900 ("pNode=%p %RGp-%RGp %s\n", pNode, pNode->Key, pNode->KeyLast, pNode->pszDesc),
2901 pArgs->cErrors++);
2902
2903 AssertLogRelMsgStmt( !pArgs->pPrevPhys
2904 || ( pArgs->fLeftToRight
2905 ? pArgs->pPrevPhys->KeyLast < pNode->Key
2906 : pArgs->pPrevPhys->KeyLast > pNode->Key),
2907 ("pPrevPhys=%p %RGp-%RGp %s\n"
2908 " pNode=%p %RGp-%RGp %s\n",
2909 pArgs->pPrevPhys, pArgs->pPrevPhys->Key, pArgs->pPrevPhys->KeyLast, pArgs->pPrevPhys->pszDesc,
2910 pNode, pNode->Key, pNode->KeyLast, pNode->pszDesc),
2911 pArgs->cErrors++);
2912
2913 pArgs->pPrevPhys = pNode;
2914 return 0;
2915}
2916
2917
2918/**
2919 * Perform an integrity check on the PGM component.
2920 *
2921 * @returns VINF_SUCCESS if everything is fine.
2922 * @returns VBox error status after asserting on integrity breach.
2923 * @param pVM The cross context VM structure.
2924 */
2925VMMR3DECL(int) PGMR3CheckIntegrity(PVM pVM)
2926{
2927 /*
2928 * Check the trees.
2929 */
2930 PGMCHECKINTARGS Args = { true, 0, NULL, pVM };
2931 int rc = pVM->pgm.s.pPhysHandlerTree->doWithAllFromLeft(&pVM->pgm.s.PhysHandlerAllocator,
2932 pgmR3CheckIntegrityPhysHandlerNode, &Args);
2933 AssertLogRelRCReturn(rc, rc);
2934
2935 Args.fLeftToRight = false;
2936 Args.pPrevPhys = NULL;
2937 rc = pVM->pgm.s.pPhysHandlerTree->doWithAllFromRight(&pVM->pgm.s.PhysHandlerAllocator,
2938 pgmR3CheckIntegrityPhysHandlerNode, &Args);
2939 AssertLogRelMsgReturn(pVM->pgm.s.pPhysHandlerTree->m_cErrors == 0,
2940 ("m_cErrors=%#x\n", pVM->pgm.s.pPhysHandlerTree->m_cErrors == 0),
2941 VERR_INTERNAL_ERROR);
2942
2943 return Args.cErrors == 0 ? VINF_SUCCESS : VERR_INTERNAL_ERROR;
2944}
2945
Note: See TracBrowser for help on using the repository browser.

© 2025 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette