• Top
    • Documentation
    • Books
    • Boolean-reasoning
    • Projects
      • Apt
      • Zfc
      • Acre
      • Milawa
      • Smtlink
      • Abnf
      • Vwsim
      • Isar
      • Wp-gen
      • Dimacs-reader
      • Pfcs
      • Legacy-defrstobj
      • Proof-checker-array
      • Soft
      • C
      • Farray
      • Rp-rewriter
      • Instant-runoff-voting
      • Imp-language
      • Sidekick
      • Leftist-trees
      • Java
      • Taspi
      • Bitcoin
      • Riscv
      • Des
      • Ethereum
      • X86isa
        • Program-execution
        • Sdm-instruction-set-summary
        • Tlb
        • Running-linux
        • Introduction
        • Asmtest
        • X86isa-build-instructions
        • Publications
        • Contributors
        • Machine
          • X86isa-state
          • Syscalls
          • Cpuid
          • Linear-memory
          • Rflag-specifications
          • Characterizing-undefined-behavior
          • Top-level-memory
          • App-view
          • X86-decoder
          • Physical-memory
          • Decoding-and-spec-utils
          • Instructions
            • Two-byte-opcodes
              • X86-vandp?/vandnp?/vorp?/vxorp?/vpand/vpandn/vpor/vpxor-vex
              • X86-endbr32/endbr64
              • X86-adds?/subs?/muls?/divs?/maxs?/mins?-op/en-rm
              • X86-push-segment-register
              • X86-andp?/andnp?/orp?/xorp?/pand/pandn/por/pxor-op/en-rm
              • X86-addps/subps/mulps/divps/maxps/minps-op/en-rm
              • X86-lldt
              • X86-addpd/subpd/mulpd/divpd/maxpd/minpd-op/en-rm
              • X86-cmovcc
              • X86-two-byte-jcc
              • X86-setcc
              • X86-cvts?2si/cvtts?2si-op/en-rm
              • X86-comis?/ucomis?-op/en-rm
              • X86-cmpps-op/en-rmi
              • X86-vpsubb/vpsubw/vpsubd/vpsubq-vex
              • X86-vpaddb/vpaddw/vpaddd/vpaddq-vex
              • X86-movups/movupd/movdqu-op/en-rm
              • X86-sysret
                • X86-pmovmskb-op/en-rm
                • X86-unpck?ps-op/en-rm
                • X86-lidt
                • X86-lgdt
                • X86-cmppd-op/en-rmi
                • X86-sqrtps-op/en-rm
                • X86-rdrand
                • X86-vmovups-vex-b
                • X86-unpck?pd-op/en-rm
                • X86-cvtsi2s?-op/en-rm
                • X86-cmpss/cmpsd-op/en-rmi
                • X86-vmovups-vex-a
                • X86-shufps-op/en-rmi
                • X86-fxsave/fxsave64
                • X86-fxrstor/fxrstor64
                • X86-cvtpd2ps-op/en-rm
                • X86-btr-0f-b3
                • X86-bt-0f-ba
                • X86-bt-0f-ab
                • X86-sqrtpd-op/en-rm
                • X86-cvts?2s?-op/en-rm
                • X86-vzeroupper
                • X86-two-byte-nop
                • X86-sgdt
                • X86-psubb/psubw/psubd/psubq-sse
                • X86-paddb/paddw/paddd/paddq-sse
                • X86-movups/movupd/movdqu-op/en-mr
                • X86-cvtps2pd-op/en-rm
                • X86-sqrts?-op/en-rm
                • X86-imul-op/en-rm
                • X86-bt-0f-a3
                • X86-syscall
                • X86-shufpd-op/en-rmi
                • X86-punpckh-sse
                • X86-movss/movsd-op/en-rm
                • X86-movss/movsd-op/en-mr
                • X86-movhps/movhpd-op/en-mr
                • X86-movaps/movapd-op/en-mr
                • X86-cmpxchg8b/16b
                • X86-bswap
                • X86-punpckl-sse
                • X86-movlps/movlpd-op/en-rm
                • X86-movlps/movlpd-op/en-mr
                • X86-movhps/movhpd-op/en-rm
                • X86-movaps/movapd-op/en-rm
                • X86-ldmxcsr/stmxcsr-op/en-m
                • X86-bsf-op/en-rm
                • X86-syscall-app-view
                • X86-psrl-xmm-sse
                • X86-psll-xmm-sse
                • X86-movsx
                • X86-cmpxchg
                • X86-pcmpgt-sse
                • X86-pcmpeq-sse
                • X86-movhlps-sse
                • X86-psrl-imm-sse
                • X86-psra-xmm-sse
                • X86-psll-imm-sse
                • X86-pslldq/psrldq
                • X86-movzx
                • X86-tzcnt
                • X86-psra-imm-sse
                • X86-pshuflw
                • X86-pshufhw
                • X86-pshufd
                • X86-movd/movq-from-xmm
                • X86-movdqa-from-xmm
                • X86-ltr
                • X86-bsr
                • X86-popcnt
                • X86-packuswb-sse
                • X86-movq-to-xmm/mem
                • X86-movdqa-to-xmm
                • X86-movq-from-xmm/mem
                • X86-movd/movq-to-xmm
                • X86-mov-control-regs-op/en-rm
                • X86-mov-control-regs-op/en-mr
                • X86-invlpg
                • X86-cpuid
                • X86-wrmsr
                • X86-syscall-both-views
                • X86-rdmsr
                • X86-one-byte-nop
              • One-byte-opcodes
              • Fp-opcodes
              • Instruction-semantic-functions
              • X86-illegal-instruction
              • Implemented-opcodes
              • Opcode-maps
              • X86-general-protection
              • X86-device-not-available
              • X86-step-unimplemented
              • Privileged-opcodes
              • Three-byte-opcodes
            • Register-readers-and-writers
            • X86-modes
            • Segmentation
            • Other-non-deterministic-computations
            • Environment
            • Paging
          • Implemented-opcodes
          • To-do
          • Proof-utilities
          • Peripherals
          • Model-validation
          • Modelcalls
          • Concrete-simulation-examples
          • Utils
          • Debugging-code-proofs
        • Sha-2
        • Yul
        • Zcash
        • Proof-checker-itp13
        • Regex
        • ACL2-programming-language
        • Json
        • Jfkr
        • Equational
        • Cryptography
        • Poseidon
        • Where-do-i-place-my-book
        • Axe
        • Bigmems
        • Builtins
        • Execloader
        • Aleo
        • Solidity
        • Paco
        • Concurrent-programs
        • Bls12-377-curves
      • Debugging
      • Std
      • Proof-automation
      • Macro-libraries
      • ACL2
      • Interfacing-tools
      • Hardware-verification
      • Software-verification
      • Math
      • Testing-utilities
    • Two-byte-opcodes

    X86-sysret

    Return from fast system call to user code at privilege level 3

    Signature
    (x86-sysret proc-mode start-rip temp-rip 
                prefixes rex-byte opcode modr/m sib x86) 
     
      → 
    x86
    Returns
    x86 — Type (x86p x86), given (x86p x86).

    Op/En: NP
    0F 07: SYSRET
    REX.W + 0F 07: SYSRET

    SYSRET when REX.W is not set is not supported yet because 0F 07 (as opposed to REX.W + 0F 07) switches the machine to compatibility mode, not 64-bit mode.

    Definitions and Theorems

    Function: x86-sysret

    (defun x86-sysret
           (proc-mode start-rip temp-rip
                      prefixes rex-byte opcode modr/m sib x86)
     (declare (xargs :stobjs (x86)))
     (declare (type (integer 0 4) proc-mode)
              (type (signed-byte 48) start-rip)
              (type (signed-byte 48) temp-rip)
              (type (unsigned-byte 52) prefixes)
              (type (unsigned-byte 8) rex-byte)
              (type (unsigned-byte 8) opcode)
              (type (unsigned-byte 8) modr/m)
              (type (unsigned-byte 8) sib))
     (declare (ignorable proc-mode start-rip temp-rip
                         prefixes rex-byte opcode modr/m sib))
     (declare (xargs :guard (and (prefixes-p prefixes)
                                 (modr/m-p modr/m)
                                 (sib-p sib)
                                 (rip-guard-okp proc-mode temp-rip))))
     (let ((__function__ 'x86-sysret))
      (declare (ignorable __function__))
      (b* ((?ctx 'x86-sysret))
       (b*
        (((when (not (logbitp 3 rex-byte)))
          (!!ms-fresh :unsupported-sysret-because-rex.w!=1 rex-byte))
         (ia32-efer (n12 (msri *ia32_efer-idx* x86)))
         ((the (unsigned-byte 1) ia32-efer-sce)
          (ia32_eferbits->sce ia32-efer))
         ((when (mbe :logic (zp ia32-efer-sce)
                     :exec (equal 0 ia32-efer-sce)))
          (!!fault-fresh :ud nil
                         :ia32-efer-sce=0 (cons 'ia32_efer ia32-efer)))
         (current-cs-register (the (unsigned-byte 16)
                                   (seg-visiblei 1 x86)))
         (cpl (segment-selectorbits->rpl current-cs-register))
         ((when (not (equal 0 cpl)))
          (!!fault-fresh :gp 0
                         :cpl!=0 (cons 'cs-register
                                       current-cs-register)))
         (rcx (rgfi *rcx* x86))
         ((when (not (canonical-address-p rcx)))
          (!!ms-fresh :rcx-non-canonical rcx))
         (x86 (!rip rcx x86))
         (r11 (n32 (rgfi *r11* x86)))
         (x86 (!rflags (logior (logand r11 3964887) 2)
                       x86))
         (star (msri *ia32_star-idx* x86))
         (new-cs-selector (+ (part-select star :low 48 :high 63)
                             16))
         ((when (not (n16p new-cs-selector)))
          (!!ms-fresh :new-cs-selector-too-large new-cs-selector))
         (new-cs-selector
              (!segment-selectorbits->rpl 3 new-cs-selector))
         (x86 (!seg-visiblei 1 new-cs-selector x86))
         (cs-base-addr 0)
         (cs-limit 4294967295)
         ((the (unsigned-byte 16) cs-attr)
          (seg-hidden-attri 1 x86))
         (cs-attr
           (change-code-segment-descriptor-attributesbits cs-attr
                                                          :a 1
                                                          :r 1
                                                          :c 0
                                                          :msb-of-type 1
                                                          :s 1
                                                          :dpl 3
                                                          :p 1
                                                          :l 1
                                                          :d 0
                                                          :g 1))
         (x86 (!seg-hidden-basei 1 cs-base-addr x86))
         (x86 (!seg-hidden-limiti 1 cs-limit x86))
         (x86 (!seg-hidden-attri 1 cs-attr x86))
         (new-ss-selector (+ (part-select star :low 48 :high 63)
                             8))
         ((when (not (n16p new-ss-selector)))
          (!!ms-fresh :new-ss-selector-too-large new-ss-selector))
         (new-ss-selector
              (!segment-selectorbits->rpl 3 new-ss-selector))
         (x86 (!seg-visiblei 2 new-ss-selector x86))
         (ss-base-addr 0)
         (ss-limit 4294967295)
         ((the (unsigned-byte 16) ss-attr)
          (seg-hidden-attri 2 x86))
         (ss-attr
           (change-data-segment-descriptor-attributesbits ss-attr
                                                          :a 1
                                                          :w 1
                                                          :e 0
                                                          :msb-of-type 0
                                                          :s 1
                                                          :dpl 3
                                                          :p 1
                                                          :d/b 1
                                                          :g 1))
         (x86 (!seg-hidden-basei 2 ss-base-addr x86))
         (x86 (!seg-hidden-limiti 2 ss-limit x86))
         (x86 (!seg-hidden-attri 2 ss-attr x86)))
        x86))))

    Theorem: x86p-of-x86-sysret

    (defthm x86p-of-x86-sysret
      (implies
           (x86p x86)
           (b* ((x86 (x86-sysret proc-mode start-rip temp-rip prefixes
                                 rex-byte opcode modr/m sib x86)))
             (x86p x86)))
      :rule-classes :rewrite)