|
|
Intel® 64 and IA-32 Architectures
Software Developer’s Manual
Volume 3A:
System Programming Guide, Part 1
NOTE: The Intel® 64 and IA-32 Architectures Software Developer's Manual consists of ten volumes:
Basic Architecture, Order Number 253665; Instruction Set Reference, A-L, Order Number 253666;
Instruction Set Reference, M-U, Order Number 253667; Instruction Set Reference, V, Order Number
326018; Instruction Set Reference, W-Z, Order Number 334569; System Programming Guide, Part 1,
Order Number 253668; System Programming Guide, Part
2, Order Number 253669; System
Programming Guide, Part 3, Order Number 326019; System Programming Guide, Part 4, Order Number
332831; Model-Specific Registers, Order Number 335592. Refer to all ten volumes when evaluating
your design needs.
Order Number: 253668-082US
December 2023
CONTENTS
PAGE
CHAPTER 1
ABOUT THIS MANUAL
1.1
INTEL® 64 AND IA-32 PROCESSORS COVERED IN THIS MANUAL
1-1
1.2
OVERVIEW OF THE SYSTEM PROGRAMMING GUIDE
1-4
1.3
NOTATIONAL CONVENTIONS
1-7
1.3.1
Bit and Byte Order
1-7
1.3.2
Reserved Bits and Software Compatibility
1-7
1.3.3
Instruction Operands
1-8
1.3.4
Hexadecimal and Binary Numbers
1-8
1.3.5
Segmented Addressing
1-8
1.3.6
Syntax for CPUID, CR, and MSR Values
1-9
1.3.7
Exceptions
1-10
1.4
RELATED LITERATURE
1-10
CHAPTER 2
SYSTEM ARCHITECTURE OVERVIEW
2.1
OVERVIEW OF THE SYSTEM-LEVEL ARCHITECTURE
2-1
2.1.1
Global and Local Descriptor Tables
2-3
2.1.1.1
Global and Local Descriptor Tables in IA-32e Mode
2-4
2.1.2
System Segments, Segment Descriptors, and Gates
2-4
2.1.2.1
Gates in IA-32e Mode
2-4
2.1.3
Task-State Segments and Task Gates
2-5
2.1.3.1
Task-State Segments in IA-32e Mode
2-5
2.1.4
Interrupt and Exception Handling
2-5
2.1.4.1
Interrupt and Exception Handling IA-32e Mode
2-5
2.1.5
Memory Management
2-6
2.1.5.1
Memory Management in IA-32e Mode
2-6
2.1.6
System Registers
2-6
2.1.6.1
System Registers in IA-32e Mode
2-7
2.1.7
Other System Resources
2-7
2.2
MODES OF OPERATION
2-7
2.2.1
Extended Feature Enable Register
2-9
2.3
SYSTEM FLAGS AND FIELDS IN THE EFLAGS REGISTER
2-9
2.3.1
System Flags and Fields in IA-32e Mode
2-11
2.4
MEMORY-MANAGEMENT REGISTERS
2-11
2.4.1
Global Descriptor Table Register (GDTR)
2-12
2.4.2
Local Descriptor Table Register (LDTR)
2-12
2.4.3
IDTR Interrupt Descriptor Table Register
2-12
2.4.4
Task Register (TR)
2-13
2.5
CONTROL REGISTERS
2-13
2.5.1
CPUID Qualification of Control Register Flags
2-20
2.6
EXTENDED CONTROL REGISTERS (INCLUDING XCR0)
2-20
2.7
PROTECTION-KEY RIGHTS REGISTERS (PKRU AND IA32_PKRS)
2-22
2.8
SYSTEM INSTRUCTION SUMMARY
2-23
2.8.1
Loading and Storing System Registers
2-24
2.8.2
Verifying of Access Privileges
2-24
2.8.3
Loading and Storing Debug Registers
2-25
2.8.4
Invalidating Caches and TLBs
2-25
2.8.5
Controlling the Processor
2-26
2.8.6
Reading Performance-Monitoring and Time-Stamp Counters
2-26
2.8.6.1
Reading Counters in 64-Bit Mode
2-27
2.8.7
Reading and Writing Model-Specific Registers
2-27
2.8.7.1
Reading and Writing Model-Specific Registers in 64-Bit Mode
2-27
2.8.8
Enabling Processor Extended States
2-27
CHAPTER 3
PROTECTED-MODE MEMORY MANAGEMENT
3.1
MEMORY MANAGEMENT OVERVIEW
3-1
Vol. 3A iii
CONTENTS
PAGE
3.2
USING SEGMENTS
3-2
3.2.1
Basic Flat Model
3-3
3.2.2
Protected Flat Model
3-3
3.2.3
Multi-Segment Model
3-4
3.2.4
Segmentation in IA-32e Mode
3-5
3.2.5
Paging and Segmentation
3-5
3.3
PHYSICAL ADDRESS SPACE
3-6
3.3.1
Intel® 64 Processors and Physical Address Space
3-6
3.4
LOGICAL AND LINEAR ADDRESSES
3-6
3.4.1
Logical Address Translation in IA-32e Mode
3-7
3.4.2
Segment Selectors
3-7
3.4.3
Segment Registers
3-8
3.4.4
Segment Loading Instructions in IA-32e Mode
3-9
3.4.5
Segment Descriptors
3-9
3.4.5.1
Code- and Data-Segment Descriptor Types
3-12
3.5
SYSTEM DESCRIPTOR TYPES
3-13
3.5.1
Segment Descriptor Tables
3-14
3.5.2
Segment Descriptor Tables in IA-32e Mode
3-16
CHAPTER 4
PAGING
4.1
PAGING MODES AND CONTROL BITS
4-1
4.1.1
Four Paging Modes
4-1
4.1.2
Paging-Mode Enabling
4-3
4.1.3
Paging-Mode Modifiers
4-4
4.1.4
Enumeration of Paging Features by CPUID
4-5
4.2
HIERARCHICAL PAGING STRUCTURES: AN OVERVIEW
4-7
4.3
32-BIT PAGING
4-9
4.4
PAE PAGING
4-14
4.4.1
PDPTE Registers
4-14
4.4.2
Linear-Address Translation with PAE Paging
4-15
4.5
4-LEVEL PAGING AND 5-LEVEL PAGING
4-20
4.5.1
Ordinary Paging and HLAT Paging
4-20
4.5.2
Use of CR3 with Ordinary 4-Level Paging and 5-Level Paging
4-20
4.5.3
Use of HLATP with HLAT 4-Level Paging and 5-Level Paging
4-21
4.5.4
Linear-Address Translation with 4-Level Paging and 5-Level Paging
4-22
4.5.5
Restart of HLAT Paging
4-33
4.6
ACCESS RIGHTS
4-33
4.6.1
Determination of Access Rights
4-33
4.6.2
Protection Keys
4-36
4.7
PAGE-FAULT EXCEPTIONS
4-37
4.8
ACCESSED AND DIRTY FLAGS
4-39
4.9
PAGING AND MEMORY TYPING
4-39
4.9.1
Paging and Memory Typing When the PAT is Not Supported (Pentium Pro and Pentium II Processors)
4-40
4.9.2
Paging and Memory Typing When the PAT is Supported (Pentium III and More Recent Processor Families)
4-40
4.9.3
Caching Paging-Related Information about Memory Typing
4-41
4.10
CACHING TRANSLATION INFORMATION
4-41
4.10.1
Process-Context Identifiers (PCIDs)
4-41
4.10.2
Translation Lookaside Buffers (TLBs)
4-42
4.10.2.1
Page Numbers, Page Frames, and Page Offsets
4-42
4.10.2.2
Caching Translations in TLBs
4-43
4.10.2.3
Details of TLB Use
4-43
4.10.2.4
Global Pages
4-44
4.10.3
Paging-Structure Caches
4-44
4.10.3.1
Caches for Paging Structures
4-44
4.10.3.2
Using the Paging-Structure Caches to Translate Linear Addresses
4-47
4.10.3.3
Multiple Cached Entries for a Single Paging-Structure Entry
4-47
4.10.4
Invalidation of TLBs and Paging-Structure Caches
4-48
4.10.4.1
Operations that Invalidate TLBs and Paging-Structure Caches
4-48
4.10.4.2
Recommended Invalidation
4-50
4.10.4.3
Optional Invalidation
4-51
4.10.4.4
Delayed Invalidation
4-52
4.10.5
Propagation of Paging-Structure Changes to Multiple Processors
4-52
4.11
INTERACTIONS WITH VIRTUAL-MACHINE EXTENSIONS (VMX)
4-53
iv Vol. 3A
CONTENTS
PAGE
4.11.1
VMX Transitions
4-53
4.11.2
VMX Support for Address Translation
4-54
4.12
USING PAGING FOR VIRTUAL MEMORY
4-54
4.13
MAPPING SEGMENTS TO PAGES
4-54
CHAPTER 5
PROTECTION
5.1
ENABLING AND DISABLING SEGMENT AND PAGE PROTECTION
5-1
5.2
FIELDS AND FLAGS USED FOR SEGMENT-LEVEL AND PAGE-LEVEL PROTECTION
5-2
5.2.1
Code-Segment Descriptor in 64-bit Mode
5-3
5.3
LIMIT CHECKING
5-4
5.3.1
Limit Checking in 64-bit Mode
5-5
5.4
TYPE CHECKING
5-5
5.4.1
Null Segment Selector Checking
5-6
5.4.1.1
NULL Segment Checking in 64-bit Mode
5-6
5.5
PRIVILEGE LEVELS
5-6
5.6
PRIVILEGE LEVEL CHECKING WHEN ACCESSING DATA SEGMENTS
5-8
5.6.1
Accessing Data in Code Segments
5-9
5.7
PRIVILEGE LEVEL CHECKING WHEN LOADING THE SS REGISTER
5-10
5.8
PRIVILEGE LEVEL CHECKING WHEN TRANSFERRING PROGRAM CONTROL BETWEEN CODE SEGMENTS
5-10
5.8.1
Direct Calls or Jumps to Code Segments
5-10
5.8.1.1
Accessing Nonconforming Code Segments
5-11
5.8.1.2
Accessing Conforming Code Segments
5-12
5.8.2
Gate Descriptors
5-13
5.8.3
Call Gates
5-13
5.8.3.1
IA-32e Mode Call Gates
5-14
5.8.4
Accessing a Code Segment Through a Call Gate
5-15
5.8.5
Stack Switching
5-17
5.8.5.1
Stack Switching in 64-bit Mode
5-19
5.8.6
Returning from a Called Procedure
5-20
5.8.7
Performing Fast Calls to System Procedures with the SYSENTER and SYSEXIT Instructions
5-20
5.8.7.1
SYSENTER and SYSEXIT Instructions in IA-32e Mode
5-21
5.8.8
Fast System Calls in 64-Bit Mode
5-22
5.9
PRIVILEGED INSTRUCTIONS
5-23
5.10
POINTER VALIDATION
5-24
5.10.1
Checking Access Rights (LAR Instruction)
5-24
5.10.2
Checking Read/Write Rights (VERR and VERW Instructions)
5-25
5.10.3
Checking That the Pointer Offset Is Within Limits (LSL Instruction)
5-25
5.10.4
Checking Caller Access Privileges (ARPL Instruction)
5-26
5.10.5
Checking Alignment
5-27
5.11
PAGE-LEVEL PROTECTION
5-27
5.11.1
Page-Protection Flags
5-28
5.11.2
Restricting Addressable Domain
5-28
5.11.3
Page Type
5-28
5.11.4
Combining Protection of Both Levels of Page Tables
5-28
5.11.5
Overrides to Page Protection
5-29
5.12
COMBINING PAGE AND SEGMENT PROTECTION
5-29
5.13
PAGE-LEVEL PROTECTION AND EXECUTE-DISABLE BIT
5-30
5.13.1
Detecting and Enabling the Execute-Disable Capability
5-30
5.13.2
Execute-Disable Page Protection
5-30
5.13.3
Reserved Bit Checking
5-31
5.13.4
Exception Handling
5-32
CHAPTER 6
INTERRUPT AND EXCEPTION HANDLING
6.1
INTERRUPT AND EXCEPTION OVERVIEW
6-1
6.2
EXCEPTION AND INTERRUPT VECTORS
6-1
6.3
SOURCES OF INTERRUPTS
6-2
6.3.1
External Interrupts
6-2
6.3.2
Maskable Hardware Interrupts
6-3
6.3.3
Software-Generated Interrupts
6-4
6.4
SOURCES OF EXCEPTIONS
6-4
Vol. 3A v
CONTENTS
PAGE
6.4.1
Program-Error Exceptions
6-4
6.4.2
Software-Generated Exceptions
6-4
6.4.3
Machine-Check Exceptions
6-4
6.5
EXCEPTION CLASSIFICATIONS
6-5
6.6
PROGRAM OR TASK RESTART
6-5
6.7
NONMASKABLE INTERRUPT (NMI)
6-6
6.7.1
Handling Multiple NMIs
6-6
6.8
ENABLING AND DISABLING INTERRUPTS
6-6
6.8.1
Masking Maskable Hardware Interrupts
6-7
6.8.2
Masking Instruction Breakpoints
6-7
6.8.3
Masking Exceptions and Interrupts When Switching Stacks
6-8
6.9
PRIORITIZATION OF CONCURRENT EVENTS
6-8
6.10
INTERRUPT DESCRIPTOR TABLE (IDT)
6-9
6.11
IDT DESCRIPTORS
6-10
6.12
EXCEPTION AND INTERRUPT HANDLING
6-11
6.12.1
Exception- or Interrupt-Handler Procedures
6-12
6.12.1.1
Shadow Stack Usage on Transfers to Interrupt and Exception Handling Routines
6-14
6.12.1.2
Protection of Exception- and Interrupt-Handler Procedures
6-16
6.12.1.3
Flag Usage By Exception- or Interrupt-Handler Procedure
6-17
6.12.2
Interrupt Tasks
6-17
6.13
ERROR CODE
6-18
6.14
EXCEPTION AND INTERRUPT HANDLING IN 64-BIT MODE
6-19
6.14.1
64-Bit Mode IDT
6-19
6.14.2
64-Bit Mode Stack Frame
6-20
6.14.3
IRET in IA-32e Mode
6-21
6.14.4
Stack Switching in IA-32e Mode
6-21
6.14.5
Interrupt Stack Table
6-22
6.15
EXCEPTION AND INTERRUPT REFERENCE
6-23
Interrupt 0-Divide Error Exception (#DE)
6-24
Interrupt 1-Debug Exception (#DB)
6-25
Interrupt 2-NMI Interrupt
6-27
Interrupt 3-Breakpoint Exception (#BP)
6-28
Interrupt 4-Overflow Exception (#OF)
6-29
Interrupt 5-BOUND Range Exceeded Exception (#BR)
6-30
Interrupt 6-Invalid Opcode Exception (#UD)
6-31
Interrupt 7-Device Not Available Exception (#NM)
6-32
Interrupt 8-Double Fault Exception (#DF)
6-33
Interrupt 9-Coprocessor Segment Overrun
6-35
Interrupt 10-Invalid TSS Exception (#TS)
6-36
Interrupt 11-Segment Not Present (#NP)
6-38
Interrupt 12-Stack Fault Exception (#SS)
6-40
Interrupt 13-General Protection Exception (#GP)
6-41
Interrupt 14-Page-Fault Exception (#PF)
6-44
Interrupt 16-x87 FPU Floating-Point Error (#MF)
6-48
Interrupt 17-Alignment Check Exception (#AC)
6-50
Interrupt 18-Machine-Check Exception (#MC)
6-52
Interrupt 19-SIMD Floating-Point Exception (#XM)
6-53
Interrupt 20-Virtualization Exception (#VE)
6-55
Interrupt 21-Control Protection Exception (#CP)
6-56
Interrupts 32 to 255-User Defined Interrupts
6-58
CHAPTER 7
USER INTERRUPTS
7.1
INTRODUCTION
7-1
7.2
ENUMERATION AND ENABLING
7-1
7.3
USER-INTERRUPT STATE AND USER-INTERRUPT MSRS
7-1
7.3.1
User-Interrupt State
7-2
7.3.2
User-Interrupt MSRs
7-2
7.4
EVALUATION AND DELIVERY OF USER INTERRUPTS
7-3
7.4.1
User-Interrupt Recognition
7-3
7.4.2
User-Interrupt Delivery
7-4
vi Vol. 3A
CONTENTS
PAGE
7.5
USER-INTERRUPT NOTIFICATION IDENTIFICATION AND PROCESSING
7-5
7.5.1
User-Interrupt Notification Identification
7-6
7.5.2
User-Interrupt Notification Processing
7-6
7.6
USER-INTERRUPT INSTRUCTIONS
7-7
7.7
USER IPIS
7-7
CHAPTER 8
TASK MANAGEMENT
8.1
TASK MANAGEMENT OVERVIEW
8-1
8.1.1
Task Structure
8-1
8.1.2
Task State
8-2
8.1.3
Executing a Task
8-2
8.2
TASK MANAGEMENT DATA STRUCTURES
8-3
8.2.1
Task-State Segment (TSS)
8-3
8.2.2
TSS Descriptor
8-5
8.2.3
TSS Descriptor in 64-bit mode
8-6
8.2.4
Task Register
8-7
8.2.5
Task-Gate Descriptor
8-8
8.3
TASK SWITCHING
8-9
8.4
TASK LINKING
8-15
8.4.1
Use of Busy Flag To Prevent Recursive Task Switching
8-16
8.4.2
Modifying Task Linkages
8-16
8.5
TASK ADDRESS SPACE
8-16
8.5.1
Mapping Tasks to the Linear and Physical Address Spaces
8-17
8.5.2
Task Logical Address Space
8-18
8.6
16-BIT TASK-STATE SEGMENT (TSS)
8-18
8.7
TASK MANAGEMENT IN 64-BIT MODE
8-19
CHAPTER 9
MULTIPLE-PROCESSOR MANAGEMENT
9.1
LOCKED ATOMIC OPERATIONS
9-1
9.1.1
Guaranteed Atomic Operations
9-2
9.1.2
Bus Locking
9-3
9.1.2.1
Automatic Locking
9-3
9.1.2.2
Software Controlled Bus Locking
9-4
9.1.2.3
Features to Disable Bus Locks
9-4
9.1.3
Handling Self- and Cross-Modifying Code
9-5
9.1.4
Effects of a LOCK Operation on Internal Processor Caches
9-6
9.2
MEMORY ORDERING
9-6
9.2.1
Memory Ordering in the Intel® Pentium® and Intel486™ Processors
9-6
9.2.2
Memory Ordering in P6 and More Recent Processor Families
9-7
9.2.3
Examples Illustrating the Memory-Ordering Principles
9-8
9.2.3.1
Assumptions, Terminology, and Notation
9-8
9.2.3.2
Neither Loads Nor Stores Are Reordered with Like Operations
9-9
9.2.3.3
Stores Are Not Reordered With Earlier Loads
9-9
9.2.3.4
Loads May Be Reordered with Earlier Stores to Different Locations
9-10
9.2.3.5
Intra-Processor Forwarding Is Allowed
9-11
9.2.3.6
Stores Are Transitively Visible
9-11
9.2.3.7
Stores Are Seen in a Consistent Order by Other Processors
9-12
9.2.3.8
Locked Instructions Have a Total Order
9-12
9.2.3.9
Loads and Stores Are Not Reordered with Locked Instructions
9-12
9.2.4
Fast-String Operation and Out-of-Order Stores
9-13
9.2.4.1
Memory-Ordering Model for String Operations on Write-Back (WB) Memory
9-13
9.2.4.2
Examples Illustrating Memory-Ordering Principles for String Operations
9-14
9.2.5
Strengthening or Weakening the Memory-Ordering Model
9-16
9.3
SERIALIZING INSTRUCTIONS
9-17
9.4
MULTIPLE-PROCESSOR (MP) INITIALIZATION
9-19
9.4.1
BSP and AP Processors
9-19
9.4.2
MP Initialization Protocol Requirements and Restrictions
9-20
9.4.3
MP Initialization Protocol Algorithm for MP Systems
9-20
9.4.4
MP Initialization Example
9-21
9.4.4.1
Typical BSP Initialization Sequence
9-21
Vol. 3A vii
CONTENTS
PAGE
9.4.4.2
Typical AP Initialization Sequence
9-23
9.4.5
Identifying Logical Processors in an MP System
9-24
9.5
INTEL® HYPER-THREADING TECHNOLOGY AND INTEL® MULTI-CORE TECHNOLOGY
9-25
9.6
DETECTING HARDWARE MULTI-THREADING SUPPORT AND TOPOLOGY
9-25
9.6.1
Initializing Processors Supporting Intel® Hyper-Threading Technology
9-26
9.6.2
Initializing Multi-Core Processors
9-26
9.6.3
Executing Multiple Threads on an Intel® 64 or IA-32 Processor Supporting Hardware Multi-Threading
9-27
9.6.4
Handling Interrupts on an IA-32 Processor Supporting Hardware Multi-Threading
9-27
9.7
INTEL® HYPER-THREADING TECHNOLOGY ARCHITECTURE
9-27
9.7.1
State of the Logical Processors
9-28
9.7.2
APIC Functionality
9-29
9.7.3
Memory Type Range Registers (MTRR)
9-29
9.7.4
Page Attribute Table (PAT)
9-29
9.7.5
Machine Check Architecture
9-29
9.7.6
Debug Registers and Extensions
9-30
9.7.7
Performance Monitoring Counters
9-30
9.7.8
IA32_MISC_ENABLE MSR
9-30
9.7.9
Memory Ordering
9-30
9.7.10
Serializing Instructions
9-30
9.7.11
Microcode Update Resources
9-30
9.7.12
Self Modifying Code
9-31
9.7.13
Implementation-Specific Intel® HT Technology Facilities
9-31
9.7.13.1
Processor Caches
9-31
9.7.13.2
Processor Translation Lookaside Buffers (TLBs)
9-31
9.7.13.3
Thermal Monitor
9-32
9.7.13.4
External Signal Compatibility
9-32
9.8
MULTI-CORE ARCHITECTURE
9-32
9.8.1
Logical Processor Support
9-33
9.8.2
Memory Type Range Registers (MTRR)
9-33
9.8.3
Performance Monitoring Counters
9-33
9.8.4
IA32_MISC_ENABLE MSR
9-33
9.8.5
Microcode Update Resources
9-33
9.9
PROGRAMMING CONSIDERATIONS FOR HARDWARE MULTI-THREADING CAPABLE PROCESSORS
9-34
9.9.1
Hierarchical Mapping of Shared Resources
9-34
9.9.2
Hierarchical Mapping of CPUID Extended Topology Leaf
9-36
9.9.3
Hierarchical ID of Logical Processors in an MP System
9-39
9.9.3.1
Hierarchical ID of Logical Processors with x2APIC ID
9-40
9.9.4
Algorithm for Three-Domain Mappings of APIC_ID
9-41
9.9.5
Identifying Topological Relationships in an MP System
9-45
9.10
MANAGEMENT OF IDLE AND BLOCKED CONDITIONS
9-48
9.10.1
HLT Instruction
9-48
9.10.2
PAUSE Instruction
9-48
9.10.3
Detecting Support MONITOR/MWAIT Instruction
9-49
9.10.4
MONITOR/MWAIT Instruction
9-49
9.10.5
Monitor/Mwait Address Range Determination
9-50
9.10.6
Required Operating System Support
9-51
9.10.6.1
Use the PAUSE Instruction in Spin-Wait Loops
9-51
9.10.6.2
Potential Usage of MONITOR/MWAIT in C0 Idle Loops
9-51
9.10.6.3
Halt Idle Logical Processors
9-53
9.10.6.4
Potential Usage of MONITOR/MWAIT in C1 Idle Loops
9-53
9.10.6.5
Guidelines for Scheduling Threads on Logical Processors Sharing Execution Resources
9-54
9.10.6.6
Eliminate Execution-Based Timing Loops
9-54
9.10.6.7
Place Locks and Semaphores in Aligned, 128-Byte Blocks of Memory
9-54
9.11
MP INITIALIZATION FOR P6 FAMILY PROCESSORS
9-54
9.11.1
Overview of the MP Initialization Process for P6 Family Processors
9-55
9.11.2
MP Initialization Protocol Algorithm
9-55
9.11.2.1
Error Detection and Handling During the MP Initialization Protocol
9-57
CHAPTER 10
PROCESSOR MANAGEMENT AND INITIALIZATION
10.1
INITIALIZATION OVERVIEW
10-1
10.1.1
Processor State After Reset
10-2
10.1.2
Processor Built-In Self-Test (BIST)
10-5
10.1.3
Model and Stepping Information
10-5
viii Vol. 3A
CONTENTS
PAGE
10.1.4
First Instruction Executed
10-5
10.2
X87 FPU INITIALIZATION
10-5
10.2.1
Configuring the x87 FPU Environment
10-6
10.2.2
Setting the Processor for x87 FPU Software Emulation
10-6
10.3
CACHE ENABLING
10-7
10.4
MODEL-SPECIFIC REGISTERS (MSRS)
10-7
10.5
MEMORY TYPE RANGE REGISTERS (MTRRS)
10-8
10.6
INITIALIZING SSE/SSE2/SSE3/SSSE3 EXTENSIONS
10-8
10.7
SOFTWARE INITIALIZATION FOR REAL-ADDRESS MODE OPERATION
10-8
10.7.1
Real-Address Mode IDT
10-8
10.7.2
NMI Interrupt Handling
10-9
10.8
SOFTWARE INITIALIZATION FOR PROTECTED-MODE OPERATION
10-9
10.8.1
Protected-Mode System Data Structures
10-9
10.8.2
Initializing Protected-Mode Exceptions and Interrupts
10-10
10.8.3
Initializing Paging
10-10
10.8.4
Initializing Multitasking
10-10
10.8.5
Initializing IA-32e Mode
10-11
10.8.5.1
IA-32e Mode System Data Structures
10-11
10.8.5.2
IA-32e Mode Interrupts and Exceptions
10-12
10.8.5.3
64-bit Mode and Compatibility Mode Operation
10-12
10.8.5.4
Switching Out of IA-32e Mode Operation
10-12
10.9
MODE SWITCHING
10-13
10.9.1
Switching to Protected Mode
10-13
10.9.2
Switching Back to Real-Address Mode
10-14
10.10
INITIALIZATION AND MODE SWITCHING EXAMPLE
10-14
10.10.1
Assembler Usage
10-16
10.10.2
STARTUP.ASM Listing
10-16
10.10.3
MAIN.ASM Source Code
10-25
10.10.4
Supporting Files
10-25
10.11
MICROCODE UPDATE FACILITIES
10-27
10.11.1
Microcode Update
10-28
10.11.2
Optional Extended Signature Table
10-31
10.11.3
Processor Identification
10-32
10.11.4
Platform Identification
10-32
10.11.5
Microcode Update Checksum
10-33
10.11.6
Microcode Update Loader
10-34
10.11.6.1
Hard Resets in Update Loading
10-35
10.11.6.2
Update in a Multiprocessor System
10-35
10.11.6.3
Update in a System Supporting Intel Hyper-Threading Technology
10-35
10.11.6.4
Update in a System Supporting Dual-Core Technology
10-35
10.11.6.5
Update Loader Enhancements
10-35
10.11.7
Update Signature and Verification
10-36
10.11.7.1
Determining the Signature
10-36
10.11.7.2
Authenticating the Update
10-37
10.11.8
Optional Processor Microcode Update Specifications
10-37
10.11.8.1
Responsibilities of the BIOS
10-38
10.11.8.2
Responsibilities of the Calling Program
10-39
10.11.8.3
Microcode Update Functions
10-42
10.11.8.4
INT 15H-based Interface
10-42
10.11.8.5
Function 00H-Presence Test
10-42
10.11.8.6
Function 01H-Write Microcode Update Data
10-43
10.11.8.7
Function 02H-Microcode Update Control
10-46
10.11.8.8
Function 03H-Read Microcode Update Data
10-47
10.11.8.9
Return Codes
10-48
CHAPTER 11
ADVANCED PROGRAMMABLE INTERRUPT CONTROLLER (APIC)
11.1
LOCAL AND I/O APIC OVERVIEW
11-1
11.2
SYSTEM BUS VS. APIC BUS
11-3
11.3
THE INTEL® 82489DX EXTERNAL APIC, THE APIC, THE XAPIC, AND THE X2APIC
11-4
11.4
LOCAL APIC
11-4
11.4.1
The Local APIC Block Diagram
11-4
11.4.2
Presence of the Local APIC
11-7
11.4.3
Enabling or Disabling the Local APIC
11-7
Vol. 3A ix
CONTENTS
PAGE
11.4.4
Local APIC Status and Location
11-8
11.4.5
Relocating the Local APIC Registers
11-9
11.4.6
Local APIC ID
11-9
11.4.7
Local APIC State
11-10
11.4.7.1
Local APIC State After Power-Up or Reset
11-10
11.4.7.2
Local APIC State After It Has Been Software Disabled
11-10
11.4.7.3
Local APIC State After an INIT Reset (“Wait-for-SIPI” State)
11-10
11.4.7.4
Local APIC State After It Receives an INIT-Deassert IPI
11-11
11.4.8
Local APIC Version Register
11-11
11.5
HANDLING LOCAL INTERRUPTS
11-12
11.5.1
Local Vector Table
11-12
11.5.2
Valid Interrupt Vectors
11-15
11.5.3
Error Handling
11-15
11.5.4
APIC Timer
11-16
11.5.4.1
TSC-Deadline Mode
11-17
11.5.5
Local Interrupt Acceptance
11-18
11.6
ISSUING INTERPROCESSOR INTERRUPTS
11-19
11.6.1
Interrupt Command Register (ICR)
11-19
11.6.2
Determining IPI Destination
11-22
11.6.2.1
Physical Destination Mode
11-23
11.6.2.2
Logical Destination Mode
11-23
11.6.2.3
Broadcast/Self Delivery Mode
11-25
11.6.2.4
Lowest Priority Delivery Mode
11-25
11.6.3
IPI Delivery and Acceptance
11-26
11.7
SYSTEM AND APIC BUS ARBITRATION
11-26
11.8
HANDLING INTERRUPTS
11-26
11.8.1
Interrupt Handling with the Pentium 4 and Intel Xeon Processors
11-27
11.8.2
Interrupt Handling with the P6 Family and Pentium Processors
11-27
11.8.3
Interrupt, Task, and Processor Priority
11-28
11.8.3.1
Task and Processor Priorities
11-29
11.8.4
Interrupt Acceptance for Fixed Interrupts
11-30
11.8.5
Signaling Interrupt Servicing Completion
11-31
11.8.6
Task Priority in IA-32e Mode
11-31
11.8.6.1
Interaction of Task Priorities between CR8 and APIC
11-32
11.9
SPURIOUS INTERRUPT
11-32
11.10
APIC BUS MESSAGE PASSING MECHANISM AND PROTOCOL (P6 FAMILY, PENTIUM PROCESSORS)
11-33
11.10.1
Bus Message Formats
11-34
11.11
MESSAGE SIGNALLED INTERRUPTS
11-34
11.11.1
Message Address Register Format
11-34
11.11.2
Message Data Register Format
11-35
11.12
EXTENDED XAPIC (X2APIC)
11-36
11.12.1
Detecting and Enabling x2APIC Mode
11-37
11.12.1.1
Instructions to Access APIC Registers
11-37
11.12.1.2
x2APIC Register Address Space
11-38
11.12.1.3
Reserved Bit Checking
11-40
11.12.2
x2APIC Register Availability
11-40
11.12.3
MSR Access in x2APIC Mode
11-40
11.12.4
VM-Exit Controls for MSRs and x2APIC Registers
11-41
11.12.5
x2APIC State Transitions
11-41
11.12.5.1
x2APIC States
11-41
x2APIC After Reset
11-42
x2APIC Transitions From x2APIC Mode
11-42
x2APIC Transitions From Disabled Mode
11-43
State Changes From xAPIC Mode to x2APIC Mode
11-43
11.12.6
Routing of Device Interrupts in x2APIC Mode
11-43
11.12.7
Initialization by System Software
11-43
11.12.8
CPUID Extensions And Topology Enumeration
11-43
11.12.8.1
Consistency of APIC IDs and CPUID
11-44
11.12.9
ICR Operation in x2APIC Mode
11-44
11.12.10
Determining IPI Destination in x2APIC Mode
11-45
11.12.10.1
Logical Destination Mode in x2APIC Mode
11-45
11.12.10.2
Deriving Logical x2APIC ID from the Local x2APIC ID
11-46
11.12.11
SELF IPI Register
11-47
11.13
APIC BUS MESSAGE FORMATS
11-47
x Vol. 3A
CONTENTS
PAGE
11.13.1
Bus Message Formats
11-47
11.13.2
EOI Message
11-47
11.13.2.1
Short Message
11-48
11.13.2.2
Non-focused Lowest Priority Message
11-49
11.13.2.3
APIC Bus Status Cycles
11-50
CHAPTER 12
MEMORY CACHE CONTROL
12.1
INTERNAL CACHES, TLBS, AND BUFFERS
12-1
12.2
CACHING TERMINOLOGY
12-5
12.3
METHODS OF CACHING AVAILABLE
12-6
12.3.1
Buffering of Write Combining Memory Locations
12-8
12.3.2
Choosing a Memory Type
12-8
12.3.3
Code Fetches in Uncacheable Memory
12-9
12.4
CACHE CONTROL PROTOCOL
12-9
12.5
CACHE CONTROL
12-10
12.5.1
Cache Control Registers and Bits
12-10
12.5.2
Precedence of Cache Controls
12-13
12.5.2.1
Selecting Memory Types for Pentium Pro and Pentium II Processors
12-14
12.5.2.2
Selecting Memory Types for Pentium III and More Recent Processor Families
12-15
12.5.2.3
Writing Values Across Pages with Different Memory Types
12-16
12.5.3
Preventing Caching
12-16
12.5.4
Disabling and Enabling the L3 Cache
12-17
12.5.5
Cache Management Instructions
12-17
12.5.6
L1 Data Cache Context Mode
12-18
12.5.6.1
Adaptive Mode
12-18
12.5.6.2
Shared Mode
12-18
12.6
SELF-MODIFYING CODE
12-18
12.7
IMPLICIT CACHING (PENTIUM 4, INTEL® XEON®, AND P6 FAMILY PROCESSORS)
12-19
12.8
EXPLICIT CACHING
12-19
12.9
INVALIDATING THE TRANSLATION LOOKASIDE BUFFERS (TLBS)
12-19
12.10
STORE BUFFER
12-20
12.11
MEMORY TYPE RANGE REGISTERS (MTRRS)
12-20
12.11.1
MTRR Feature Identification
12-21
12.11.2
Setting Memory Ranges with MTRRs
12-22
12.11.2.1
IA32_MTRR_DEF_TYPE MSR
12-22
12.11.2.2
Fixed Range MTRRs
12-23
12.11.2.3
Variable Range MTRRs
12-23
12.11.2.4
System-Management Range Register Interface
12-25
12.11.3
Example Base and Mask Calculations
12-26
12.11.3.1
Base and Mask Calculations for Greater-Than 36-bit Physical Address Support
12-27
12.11.4
Range Size and Alignment Requirement
12-28
12.11.4.1
MTRR Precedences
12-28
12.11.5
MTRR Initialization
12-29
12.11.6
Remapping Memory Types
12-29
12.11.7
MTRR Maintenance Programming Interface
12-29
12.11.7.1
MemTypeGet() Function
12-29
12.11.7.2
MemTypeSet() Function
12-31
12.11.8
MTRR Considerations in MP Systems
12-32
12.11.9
Large Page Size Considerations
12-33
12.12
PAGE ATTRIBUTE TABLE (PAT)
12-33
12.12.1
Detecting Support for the PAT Feature
12-34
12.12.2
IA32_PAT MSR
12-34
12.12.3
Selecting a Memory Type from the PAT
12-35
12.12.4
Programming the PAT
12-35
12.12.5
PAT Compatibility with Earlier IA-32 Processors
12-36
CHAPTER 13
INTEL® MMX™ TECHNOLOGY SYSTEM PROGRAMMING
13.1
EMULATION OF THE MMX INSTRUCTION SET
13-1
13.2
THE MMX STATE AND MMX REGISTER ALIASING
13-1
13.2.1
Effect of MMX, x87 FPU, FXSAVE, and FXRSTOR Instructions on the x87 FPU Tag Word
13-3
Vol. 3A xi
CONTENTS
PAGE
13.3
SAVING AND RESTORING THE MMX STATE AND REGISTERS
13-3
13.4
SAVING MMX STATE ON TASK OR CONTEXT SWITCHES
13-4
13.5
EXCEPTIONS THAT CAN OCCUR WHEN EXECUTING MMX INSTRUCTIONS
13-4
13.5.1
Effect of MMX Instructions on Pending x87 Floating-Point Exceptions
13-5
13.6
DEBUGGING MMX CODE
13-5
CHAPTER 14
SYSTEM PROGRAMMING FOR INSTRUCTION SET EXTENSIONS AND PROCESSOR EXTENDED
STATES
14.1
PROVIDING OPERATING SYSTEM SUPPORT FOR SSE EXTENSIONS
14-1
14.1.1
Adding Support to an Operating System for SSE Extensions
14-2
14.1.2
Checking for CPU Support
14-2
14.1.3
Initialization of the SSE Extensions
14-2
14.1.4
Providing Non-Numeric Exception Handlers for Exceptions Generated by the SSE Instructions
14-4
14.1.5
Providing a Handler for the SIMD Floating-Point Exception (#XM)
14-5
14.1.5.1
Numeric Error flag and IGNNE#
14-6
14.2
EMULATION OF SSE EXTENSIONS
14-6
14.3
SAVING AND RESTORING SSE STATE
14-6
14.4
DESIGNING OS FACILITIES FOR SAVING X87 FPU, SSE, AND EXTENDED STATES ON TASK OR CONTEXT SWITCHES
14-6
14.4.1
Using the TS Flag to Control the Saving of the x87 FPU and SSE State
14-7
14.5
THE XSAVE FEATURE SET AND PROCESSOR EXTENDED STATE MANAGEMENT
14-7
14.5.1
Checking the Support for XSAVE Feature Set
14-8
14.5.2
Determining the XSAVE Managed Feature States And The Required Buffer Size
14-8
14.5.3
Enable the Use Of XSAVE Feature Set And XSAVE State Components
14-9
14.5.4
Provide an Initialization for the XSAVE State Components
14-9
14.5.5
Providing the Required Exception Handlers
14-9
14.6
INTEROPERABILITY OF THE XSAVE FEATURE SET AND FXSAVE/FXRSTOR
14-9
14.7
THE XSAVE FEATURE SET AND PROCESSOR SUPERVISOR STATE MANAGEMENT
14-10
14.8
SYSTEM PROGRAMMING FOR XSAVE MANAGED FEATURES
14-10
14.8.1
Intel® Advanced Vector Extensions (Intel® AVX)
14-11
14.8.2
Intel® Advanced Vector Extensions 512 (Intel® AVX-512)
14-11
CHAPTER 15
POWER AND THERMAL MANAGEMENT
15.1
ENHANCED INTEL SPEEDSTEP® TECHNOLOGY
15-1
15.1.1
Software Interface For Initiating Performance State Transitions
15-1
15.2
P-STATE HARDWARE COORDINATION
15-1
15.3
SYSTEM SOFTWARE CONSIDERATIONS AND OPPORTUNISTIC PROCESSOR PERFORMANCE OPERATION
15-3
15.3.1
Intel® Dynamic Acceleration Technology
15-3
15.3.2
System Software Interfaces for Opportunistic Processor Performance Operation
15-3
15.3.2.1
Discover Hardware Support and Enabling of Opportunistic Processor Performance Operation
15-3
15.3.2.2
OS Control of Opportunistic Processor Performance Operation
15-4
15.3.2.3
Required Changes to OS Power Management P-State Policy
15-4
15.3.3
Intel® Turbo Boost Technology
15-5
15.3.4
Performance and Energy Bias Hint Support
15-5
15.4
HARDWARE-CONTROLLED PERFORMANCE STATES (HWP)
15-5
15.4.1
HWP Programming Interfaces
15-6
15.4.2
Enabling HWP
15-7
15.4.3
HWP Performance Range and Dynamic Capabilities
15-7
15.4.4
Managing HWP
15-8
15.4.4.1
IA32_HWP_REQUEST MSR (Address: 774H Logical Processor Scope)
15-8
15.4.4.2
IA32_HWP_REQUEST_PKG MSR (Address: 772H Package Scope)
15-11
15.4.4.3
IA32_HWP_PECI_REQUEST_INFO MSR (Address 775H Package Scope)
15-11
15.4.4.4
IA32_HWP_CTL MSR (Address: 776H Logical Processor Scope)
15-12
15.4.5
HWP Feedback
15-13
15.4.5.1
Non-Architectural HWP Feedback
15-15
15.4.6
HWP Notifications
15-16
15.4.7
Idle Logical Processor Impact on Core Frequency
15-16
15.4.8
Fast Write of Uncore MSR (Model Specific Feature)
15-17
15.4.8.1
FAST_UNCORE_MSRS_CAPABILITY (Address: 0x65F, Logical Processor Scope)
15-17
15.4.8.2
FAST_UNCORE_MSRS_CTL (Address: 0x657, Logical Processor Scope)
15-17
15.4.8.3
FAST_UNCORE_MSRS_STATUS (Address: 0x65E, Logical Processor Scope)
15-18
xii Vol. 3A
CONTENTS
PAGE
15.4.9
Fast_IA32_HWP_REQUEST CPUID
15-18
15.4.10
Recommendations for OS use of HWP Controls
15-18
15.5
HARDWARE DUTY CYCLING (HDC)
15-20
15.5.1
Hardware Duty Cycling Programming Interfaces
15-20
15.5.2
Package level Enabling HDC
15-21
15.5.3
Logical-Processor Level HDC Control
15-22
15.5.4
HDC Residency Counters
15-22
15.5.4.1
IA32_THREAD_STALL
15-22
15.5.4.2
Non-Architectural HDC Residency Counters
15-23
15.5.5
MPERF and APERF Counters Under HDC
15-25
15.6
HARDWARE FEEDBACK INTERFACE AND INTEL® THREAD DIRECTOR
15-25
15.6.1
Hardware Feedback Interface Table Structure
15-25
15.6.2
Intel® Thread Director Table Structure
15-27
15.6.3
Intel® Thread Director Usage Model
15-30
15.6.4
Hardware Feedback Interface Pointer
15-31
15.6.5
Hardware Feedback Interface Configuration
15-31
15.6.6
Hardware Feedback Interface Notifications
15-32
15.6.7
Hardware Feedback Interface and Intel® Thread Director Structure Dynamic Update
15-33
15.6.8
Logical Processor Scope Intel® Thread Director Configuration
15-33
15.6.9
Implicit Reset of Package and Logical Processor Scope Configuration MSRs
15-34
15.6.10
Logical Processor Scope Intel® Thread Director Run Time Characteristics
15-34
15.6.11
Logical Processor Scope History
15-34
15.6.11.1
Enabling Intel® Thread Director History Reset
15-35
15.6.11.2
Implicit Intel® Thread Director History Reset
15-35
15.7
MWAIT EXTENSIONS FOR ADVANCED POWER MANAGEMENT
15-35
15.8
THERMAL MONITORING AND PROTECTION
15-36
15.8.1
Catastrophic Shutdown Detector
15-37
15.8.2
Thermal Monitor
15-37
15.8.2.1
Thermal Monitor 1
15-37
15.8.2.2
Thermal Monitor 2
15-37
15.8.2.3
Two Methods for Enabling TM2
15-37
15.8.2.4
Performance State Transitions and Thermal Monitoring
15-38
15.8.2.5
Thermal Status Information
15-38
15.8.2.6
Adaptive Thermal Monitor
15-39
15.8.3
Software Controlled Clock Modulation
15-40
15.8.3.1
Extension of Software Controlled Clock Modulation
15-41
15.8.4
Detection of Thermal Monitor and Software Controlled Clock Modulation Facilities
15-41
15.8.4.1
Detection of Software Controlled Clock Modulation Extension
15-41
15.8.5
On Die Digital Thermal Sensors
15-42
15.8.5.1
Digital Thermal Sensor Enumeration
15-42
15.8.5.2
Reading the Digital Sensor
15-42
15.8.6
Power Limit Notification
15-45
15.9
PACKAGE LEVEL THERMAL MANAGEMENT
15-45
15.9.1
Support for Passive and Active cooling
15-47
15.10
PLATFORM SPECIFIC POWER MANAGEMENT SUPPORT
15-48
15.10.1
RAPL Interfaces
15-48
15.10.2
RAPL Domains and Platform Specificity
15-49
15.10.3
Package RAPL Domain
15-50
15.10.4
PP0/PP1 RAPL Domains
15-52
15.10.5
DRAM RAPL Domain
15-54
CHAPTER 16
MACHINE-CHECK ARCHITECTURE
16.1
MACHINE-CHECK ARCHITECTURE
16-1
16.2
COMPATIBILITY WITH PENTIUM PROCESSOR
16-1
16.3
MACHINE-CHECK MSRS
16-2
16.3.1
Machine-Check Global Control MSRs
16-2
16.3.1.1
IA32_MCG_CAP MSR
16-2
16.3.1.2
IA32_MCG_STATUS MSR
16-4
16.3.1.3
IA32_MCG_CTL MSR
16-4
16.3.1.4
IA32_MCG_EXT_CTL MSR
16-4
16.3.1.5
Enabling Local Machine Check
16-5
16.3.2
Error-Reporting Register Banks
16-5
16.3.2.1
IA32_MCi_CTL MSRs
16-5
Vol. 3A xiii
CONTENTS
PAGE
16.3.2.2
IA32_MCi_STATUS MSRS
16-6
16.3.2.3
IA32_MCi_ADDR MSRs
16-9
16.3.2.4
IA32_MCi_MISC MSRs
16-9
16.3.2.5
IA32_MCi_CTL2 MSRs
16-11
16.3.2.6
IA32_MCG Extended Machine Check State MSRs
16-12
16.3.3
Mapping of the Pentium Processor Machine-Check Errors to the Machine-Check Architecture
16-13
16.4
ENHANCED CACHE ERROR REPORTING
16-13
16.5
CORRECTED MACHINE CHECK ERROR INTERRUPT
16-14
16.5.1
CMCI Local APIC Interface
16-14
16.5.2
System Software Recommendation for Managing CMCI and Machine Check Resources
16-15
16.5.2.1
CMCI Initialization
16-15
16.5.2.2
CMCI Threshold Management
16-16
16.5.2.3
CMCI Interrupt Handler
16-16
16.6
RECOVERY OF UNCORRECTED RECOVERABLE (UCR) ERRORS
16-16
16.6.1
Detection of Software Error Recovery Support
16-16
16.6.2
UCR Error Reporting and Logging
16-16
16.6.3
UCR Error Classification
16-17
16.6.4
UCR Error Overwrite Rules
16-18
16.7
MACHINE-CHECK AVAILABILITY
16-19
16.8
MACHINE-CHECK INITIALIZATION
16-19
16.9
INTERPRETING THE MCA ERROR CODES
16-20
16.9.1
Simple Error Codes
16-20
16.9.2
Compound Error Codes
16-21
16.9.2.1
Correction Report Filtering (F) Bit
16-21
16.9.2.2
Transaction Type (TT) Sub-Field
16-22
16.9.2.3
Level (LL) Sub-Field
16-22
16.9.2.4
Request (RRRR) Sub-Field
16-22
16.9.2.5
Bus and Interconnect Errors
16-23
16.9.2.6
Memory Controller and Extended Memory Errors
16-24
16.9.3
Architecturally Defined UCR Errors
16-24
16.9.3.1
Architecturally Defined SRAO Errors
16-24
16.9.3.2
Architecturally Defined SRAR Errors
16-25
16.9.4
Multiple MCA Errors
16-27
16.9.5
Machine-Check Error Codes Interpretation
16-27
16.10
GUIDELINES FOR WRITING MACHINE-CHECK SOFTWARE
16-28
16.10.1
Machine-Check Exception Handler
16-28
16.10.2
Pentium Processor Machine-Check Exception Handling
16-29
16.10.3
Logging Correctable Machine-Check Errors
16-29
16.10.4
Machine-Check Software Handler Guidelines for Error Recovery
16-31
16.10.4.1
Machine-Check Exception Handler for Error Recovery
16-31
16.10.4.2
Corrected Machine-Check Handler for Error Recovery
16-35
CHAPTER 17
INTERPRETING MACHINE CHECK ERROR CODES
17.1
INCREMENTAL DECODING INFORMATION: PROCESSOR FAMILY 06H, MACHINE ERROR CODES FOR MACHINE CHECK. . . 17-1
17.2
INCREMENTAL DECODING INFORMATION: INTEL® CORE™ 2 PROCESSOR FAMILY, MACHINE ERROR CODES FOR MACHINE
CHECK
17-3
17.2.1
Model-Specific Machine Check Error Codes for Intel® Xeon® Processor 7400 Series
17-5
17.2.1.1
Processor Machine Check Status Register, Incremental MCA Error Code Definition
17-6
17.2.2
Intel® Xeon® Processor 7400 Model Specific Error Code Field
17-6
17.2.2.1
Processor Model Specific Error Code Field, Type B: Bus and Interconnect Error Codes
17-6
17.2.2.2
Processor Model Specific Error Code Field, Type C: Cache Bus Controller Error Codes
17-7
17.3
INCREMENTAL DECODING INFORMATION: INTEL® XEON® PROCESSOR 3400, 3500, 5500 SERIES, MACHINE ERROR
CODES FOR MACHINE CHECK
17-7
17.3.1
Intel® QPI Machine Check Errors
17-8
17.3.2
Internal Machine Check Errors
17-9
17.3.3
Memory Controller Errors
17-9
17.4
INCREMENTAL DECODING INFORMATION: INTEL® XEON® PROCESSOR E5 FAMILY, MACHINE ERROR CODES FOR MACHINE
CHECK
17-10
17.4.1
Internal Machine Check Errors
17-10
17.4.2
Intel® QPI Machine Check Errors
17-11
17.4.3
Integrated Memory Controller Machine Check Errors
17-11
17.5
INCREMENTAL DECODING INFORMATION: INTEL® XEON® PROCESSOR E5 V2 AND INTEL® XEON® PROCESSOR E7 V2
FAMILIES, MACHINE ERROR CODES FOR MACHINE CHECK
17-13
xiv Vol. 3A
CONTENTS
PAGE
17.5.1
Internal Machine Check Errors
17-13
17.5.2
Integrated Memory Controller Machine Check Errors
17-14
17.5.3
Home Agent Machine Check Errors
17-15
17.6
INCREMENTAL DECODING INFORMATION: INTEL® XEON® PROCESSOR E5 V3 FAMILY, MACHINE ERROR CODES FOR
MACHINE CHECK
17-15
17.6.1
Internal Machine Check Errors
17-16
17.6.2
Intel® QPI Machine Check Errors
17-17
17.6.3
Integrated Memory Controller Machine Check Errors
17-17
17.6.4
Home Agent Machine Check Errors
17-19
17.7
INCREMENTAL DECODING INFORMATION: INTEL® XEON® PROCESSOR D FAMILY, MACHINE ERROR CODES FOR MACHINE
CHECK
17-19
17.7.1
Internal Machine Check Errors
17-19
17.7.2
Integrated Memory Controller Machine Check Errors
17-20
17.8
INCREMENTAL DECODING INFORMATION: INTEL® XEON® PROCESSOR E5 V4 FAMILY, MACHINE ERROR CODES FOR
MACHINE CHECK
17-21
17.8.1
Integrated Memory Controller Machine Check Errors
17-21
17.8.2
Home Agent Machine Check Errors
17-21
17.9
INCREMENTAL DECODING INFORMATION: INTEL® XEON® SCALABLE PROCESSOR FAMILY, MACHINE ERROR CODES FOR
MACHINE CHECK
17-22
17.9.1
Internal Machine Check Errors
17-22
17.9.2
Interconnect Machine Check Errors
17-24
17.9.3
Integrated Memory Controller Machine Check Errors
17-25
17.9.4
M2M Machine Check Errors
17-26
17.9.5
Home Agent Machine Check Errors
17-27
17.10
INCREMENTAL DECODING INFORMATION: PROCESSOR FAMILY WITH CPUID DISPLAYFAMILY_DISPLAYMODEL SIGNATURE
06_5FH, MACHINE ERROR CODES FOR MACHINE CHECK
17-28
17.10.1
Integrated Memory Controller Machine Check Errors
17-28
17.11
INCREMENTAL DECODING INFORMATION: 3RD GENERATION INTEL® XEON® SCALABLE PROCESSOR FAMILY, MACHINE
ERROR CODES FOR MACHINE CHECK
17-28
17.11.1
Internal Machine Check Errors
17-29
17.11.2
Interconnect Machine Check Errors
17-31
17.11.3
Integrated Memory Controller Machine Check Errors
17-32
17.11.4
M2M Machine Check Errors
17-36
17.12
INCREMENTAL DECODING INFORMATION: PROCESSOR FAMILY WITH CPUID DISPLAYFAMILY_DISPLAYMODEL SIGNATURE
06_86H, MACHINE ERROR CODES FOR MACHINE CHECK
17-36
17.12.1
Integrated Memory Controller Machine Check Errors
17-36
17.12.2
M2M Machine Check Errors
17-37
17.13
INCREMENTAL DECODING INFORMATION: 4TH GENERATION INTEL® XEON® SCALABLE PROCESSOR FAMILY, MACHINE
ERROR CODES FOR MACHINE CHECK
17-37
17.13.1
Internal Machine Check Errors
17-37
17.13.2
Interconnect Machine Check Errors
17-39
17.13.3
Integrated Memory Controller Machine Check Errors
17-41
17.13.4
M2M Machine Check Errors
17-43
17.13.5
High Bandwidth Memory Machine Check Errors
17-44
17.14
INCREMENTAL DECODING INFORMATION: PROCESSOR FAMILY 0FH, MACHINE ERROR CODES FOR MACHINE CHECK. . 17-44
17.14.1
Model-Specific Machine Check Error Codes for the Intel® Xeon® Processor MP 7100 Series
17-45
17.14.1.1
Processor Machine Check Status Register MCA Error Code Definition
17-46
17.14.2
Other_Info Field (All MCA Error Types)
17-47
17.14.3
Processor Model Specific Error Code Field
17-48
17.14.3.1
MCA Error Type A: L3 Error
17-48
17.14.3.2
Processor Model Specific Error Code Field Type B: Bus and Interconnect Error
17-48
17.14.3.3
Processor Model Specific Error Code Field Type C: Cache Bus Controller Error
17-49
CHAPTER 18
DEBUG, BRANCH PROFILE, TSC, AND INTEL® RESOURCE DIRECTOR TECHNOLOGY (INTEL® RDT)
FEATURES
18.1
OVERVIEW OF DEBUG SUPPORT FACILITIES
18-1
18.2
DEBUG REGISTERS
18-2
18.2.1
Debug Address Registers (DR0-DR3)
18-4
18.2.2
Debug Registers DR4 and DR5
18-4
18.2.3
Debug Status Register (DR6)
18-4
18.2.4
Debug Control Register (DR7)
18-4
18.2.5
Breakpoint Field Recognition
18-6
Vol. 3A xv
CONTENTS
PAGE
18.2.6
Debug Registers and Intel® 64 Processors
18-7
18.3
DEBUG EXCEPTIONS
18-7
18.3.1
Debug Exception (#DB)-Interrupt Vector 1
18-7
18.3.1.1
Instruction-Breakpoint Exception Condition
18-9
18.3.1.2
Data Memory and I/O Breakpoint Exception Conditions
18-10
18.3.1.3
General-Detect Exception Condition
18-10
18.3.1.4
Single-Step Exception Condition
18-11
18.3.1.5
Task-Switch Exception Condition
18-11
18.3.1.6
OS Bus-Lock Detection
18-11
18.3.2
Breakpoint Exception (#BP)-Interrupt Vector 3
18-11
18.3.3
Debug Exceptions, Breakpoint Exceptions, and Restricted Transactional Memory (RTM)
18-12
18.4
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING OVERVIEW
18-12
18.4.1
IA32_DEBUGCTL MSR
18-13
18.4.2
Monitoring Branches, Exceptions, and Interrupts
18-14
18.4.3
Single-Stepping on Branches
18-14
18.4.4
Branch Trace Messages
18-15
18.4.4.1
Branch Trace Message Visibility
18-15
18.4.5
Branch Trace Store (BTS)
18-15
18.4.6
CPL-Qualified Branch Trace Mechanism
18-15
18.4.7
Freezing LBR and Performance Counters on PMI
18-15
18.4.8
LBR Stack
18-17
18.4.8.1
LBR Stack and Intel® 64 Processors
18-18
18.4.8.2
LBR Stack and IA-32 Processors
18-19
18.4.8.3
Last Exception Records and Intel 64 Architecture
18-19
18.4.9
BTS and DS Save Area
18-19
18.4.9.1
64 Bit Format of the DS Save Area
18-22
18.4.9.2
Setting Up the DS Save Area
18-24
18.4.9.3
Setting Up the BTS Buffer
18-25
18.4.9.4
Setting Up CPL-Qualified BTS
18-26
18.4.9.5
Writing the DS Interrupt Service Routine
18-26
18.5
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING (INTEL® CORE™ 2 DUO AND INTEL ATOM® PROCESSORS) . . 18-27
18.5.1
LBR Stack
18-27
18.5.2
LBR Stack in Intel Atom® Processors based on the Silvermont Microarchitecture
18-28
18.6
LAST BRANCH, CALL STACK, INTERRUPT, AND EXCEPTION RECORDING FOR PROCESSORS BASED ON GOLDMONT
MICROARCHITECTURE
18-28
18.7
LAST BRANCH, CALL STACK, INTERRUPT, AND EXCEPTION RECORDING FOR PROCESSORS BASED ON GOLDMONT PLUS
MICROARCHITECTURE
18-29
18.8
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING FOR INTEL® XEON PHI™ PROCESSOR 7200/5200/3200 . . . 18-29
18.9
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING FOR PROCESSORS BASED ON NEHALEM
MICROARCHITECTURE
18-29
18.9.1
LBR Stack
18-30
18.9.2
Filtering of Last Branch Records
18-31
18.10
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING FOR PROCESSORS BASED ON SANDY BRIDGE
MICROARCHITECTURE
18-31
18.11
LAST BRANCH, CALL STACK, INTERRUPT, AND EXCEPTION RECORDING FOR PROCESSORS BASED ON HASWELL
MICROARCHITECTURE
18-32
18.11.1
LBR Stack Enhancement
18-33
18.12
LAST BRANCH, CALL STACK, INTERRUPT, AND EXCEPTION RECORDING FOR PROCESSORS BASED ON SKYLAKE
MICROARCHITECTURE
18-33
18.12.1
MSR_LBR_INFO_x MSR
18-34
18.12.2
Streamlined Freeze_LBRs_On_PMI Operation
18-34
18.12.3
LBR Behavior and Deep C-State
18-35
18.13
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING (PROCESSORS BASED ON INTEL NETBURST®
MICROARCHITECTURE)
18-35
18.13.1
MSR_DEBUGCTLA MSR
18-35
18.13.2
LBR Stack for Processors Based on Intel NetBurst® Microarchitecture
18-36
18.13.3
Last Exception Records
18-37
18.14
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING (INTEL® CORE™ SOLO AND INTEL® CORE™ DUO
PROCESSORS)
18-38
18.15
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING (PENTIUM M PROCESSORS)
18-39
18.16
LAST BRANCH, INTERRUPT, AND EXCEPTION RECORDING (P6 FAMILY PROCESSORS)
18-40
18.16.1
DEBUGCTLMSR Register
18-40
18.16.2
Last Branch and Last Exception MSRs
18-41
18.16.3
Monitoring Branches, Exceptions, and Interrupts
18-42
18.17
TIME-STAMP COUNTER
18-42
xvi Vol. 3A
CONTENTS
PAGE
18.17.1
Invariant TSC
18-43
18.17.2
IA32_TSC_AUX Register and RDTSCP Support
18-43
18.17.3
Time-Stamp Counter Adjustment
18-44
18.17.4
Invariant Time-Keeping
18-44
18.18
INTEL® RESOURCE DIRECTOR TECHNOLOGY (INTEL® RDT) MONITORING FEATURES
18-44
18.18.1
Overview of Cache Monitoring Technology and Memory Bandwidth Monitoring
18-45
18.18.2
Enabling Monitoring: Usage Flow
18-45
18.18.3
Enumeration and Detecting Support of Cache Monitoring Technology and Memory Bandwidth Monitoring
18-46
18.18.4
Monitoring Resource Type and Capability Enumeration
18-46
18.18.5
Feature-Specific Enumeration
18-47
18.18.5.1
Cache Monitoring Technology
18-48
18.18.5.2
Memory Bandwidth Monitoring
18-48
18.18.6
Monitoring Resource RMID Association
18-49
18.18.7
Monitoring Resource Selection and Reporting Infrastructure
18-50
18.18.8
Monitoring Programming Considerations
18-51
18.18.8.1
Monitoring Dynamic Configuration
18-51
18.18.8.2
Monitoring Operation With Power Saving Features
18-51
18.18.8.3
Monitoring Operation with Other Operating Modes
18-52
18.18.8.4
Monitoring Operation with RAS Features
18-52
18.19
INTEL® RESOURCE DIRECTOR TECHNOLOGY (INTEL® RDT) ALLOCATION FEATURES
18-52
18.19.1
Introduction to Cache Allocation Technology (CAT)
18-52
18.19.2
Cache Allocation Technology Architecture
18-53
18.19.3
Code and Data Prioritization (CDP) Technology
18-56
18.19.4
Enabling Cache Allocation Technology Usage Flow
18-57
18.19.4.1
Enumeration and Detection Support of Cache Allocation Technology
18-57
18.19.4.2
Cache Allocation Technology: Resource Type and Capability Enumeration
18-58
18.19.4.3
Cache Allocation Technology: Cache Mask Configuration
18-61
18.19.4.4
Class of Service to Cache Mask Association: Common Across Allocation Features
18-61
18.19.5
Code and Data Prioritization (CDP): Enumerating and Enabling L3 CDP Technology
18-62
18.19.5.1
Mapping Between L3 CDP Masks and CAT Masks
18-62
18.19.6
Code and Data Prioritization (CDP): Enumerating and Enabling L2 CDP Technology
18-63
18.19.6.1
Mapping Between L2 CDP Masks and L2 CAT Masks
18-64
18.19.6.2
Common L2 and L3 CDP Programming Considerations
18-64
18.19.6.3
Cache Allocation Technology Dynamic Configuration
18-64
18.19.6.4
Cache Allocation Technology Operation With Power Saving Features
18-65
18.19.6.5
Cache Allocation Technology Operation with Other Operating Modes
18-65
18.19.6.6
Associating Threads with CAT/CDP Classes of Service
18-65
18.19.7
Introduction to Memory Bandwidth Allocation
18-66
18.19.7.1
Memory Bandwidth Allocation Enumeration
18-66
18.19.7.2
Memory Bandwidth Allocation Configuration
18-67
18.19.7.3
Memory Bandwidth Allocation Usage Considerations
18-68
18.20
INTEL® RESOURCE DIRECTOR TECHNOLOGY (INTEL® RDT) FOR NON-CPU AGENTS
18-68
18.20.1
Non-CPU Agent Intel® RDT Features Enumeration Details
18-69
18.20.1.1
CPUID-Based Enumeration for Non-CPU Agent Intel® RDT Feature
18-69
18.20.1.2
ACPI Enumeration
18-70
18.20.2
Non-CPU Agent Intel® RDT Feature Enable MSR
18-70
CHAPTER 19
LAST BRANCH RECORDS
19.1
BEHAVIOR
19-1
19.1.1
Logged Operations
19-1
19.1.2
Configuration
19-2
19.1.2.1
Enabling and Disabling
19-2
19.1.2.2
LBR Depth
19-2
19.1.2.3
Branch Type Enabling and Filtering
19-2
19.1.2.4
Call-Stack Mode
19-3
Call-Stack Mode and LBR Freeze
19-3
19.1.2.5
CPL Filtering
19-4
19.1.3
Record Data
19-4
19.1.3.1
IP Fields
19-4
19.1.3.2
Branch Types
19-4
19.1.3.3
Cycle Time
19-4
19.1.3.4
Mispredict Information
19-5
Vol. 3A xvii
CONTENTS
PAGE
19.1.3.5
Intel® TSX Information
19-5
19.1.4
Interaction with Other Processor Features
19-5
19.1.4.1
SMM
19-5
19.1.4.2
SMM Transfer Monitor (STM)
19-5
19.1.4.3
VMX
19-5
19.1.4.4
Intel® SGX
19-6
19.1.4.5
Debug Exceptions
19-6
19.1.4.6
SMX
19-6
19.1.4.7
MWAIT
19-6
19.1.4.8
Processor Event-Based Sampling (PEBS)
19-6
19.2
MSRS
19-6
19.3
FAST LBR READ ACCESS
19-6
19.4
OTHER IMPACTS
19-7
19.4.1
Branch Trace Store on Intel Atom® Processors
19-7
19.4.2
IA32_DEBUGCTL
19-7
19.4.3
IA32_PERF_CAPABILITIES
19-7
CHAPTER 20
PERFORMANCE MONITORING
20.1
PERFORMANCE MONITORING OVERVIEW
20-1
20.2
ARCHITECTURAL PERFORMANCE MONITORING
20-2
20.2.1
Architectural Performance Monitoring Version 1
20-3
20.2.1.1
Architectural Performance Monitoring Version 1 Facilities
20-3
20.2.1.2
Pre-defined Architectural Performance Events
20-5
20.2.2
Architectural Performance Monitoring Version 2
20-7
20.2.3
Architectural Performance Monitoring Version 3
20-10
20.2.3.1
AnyThread Counting and Software Evolution
20-13
20.2.4
Architectural Performance Monitoring Version 4
20-13
20.2.4.1
Enhancement in IA32_PERF_GLOBAL_STATUS
20-13
20.2.4.2
IA32_PERF_GLOBAL_STATUS_RESET and IA32_PERF_GLOBAL_STATUS_SET MSRS
20-15
20.2.4.3
IA32_PERF_GLOBAL_INUSE MSR
20-15
20.2.5
Architectural Performance Monitoring Version 5
20-17
20.2.5.1
AnyThread Mode Deprecation
20-17
20.2.5.2
Fixed Counter Enumeration
20-17
20.2.5.3
Domain Separation
20-17
20.2.6
Full-Width Writes to Performance Counter Registers
20-17
20.3
PERFORMANCE MONITORING (INTEL® CORE™ PROCESSORS AND INTEL® XEON® PROCESSORS)
20-17
20.3.1
Performance Monitoring for Processors Based on Nehalem Microarchitecture
20-17
20.3.1.1
Enhancements of Performance Monitoring in the Processor Core
20-18
20.3.1.2
Performance Monitoring Facility in the Uncore
20-26
20.3.1.3
Intel® Xeon® Processor 7500 Series Performance Monitoring Facility
20-31
20.3.2
Performance Monitoring for Processors Based on Westmere Microarchitecture
20-32
20.3.3
Intel® Xeon® Processor E7 Family Performance Monitoring Facility
20-33
20.3.4
Performance Monitoring for Processors Based on Sandy Bridge Microarchitecture
20-33
20.3.4.1
Global Counter Control Facilities in Sandy Bridge Microarchitecture
20-34
20.3.4.2
Counter Coalescence
20-36
20.3.4.3
Full Width Writes to Performance Counters
20-36
20.3.4.4
PEBS Support in Sandy Bridge Microarchitecture
20-36
20.3.4.5
Off-core Response Performance Monitoring
20-41
20.3.4.6
Uncore Performance Monitoring Facilities in the Intel® Core™ i7-2xxx, Intel® Core™ i5-2xxx, and Intel® Core™ i3-2xxx
Processor Series
20-44
20.3.4.7
Intel® Xeon® Processor E5 Family Performance Monitoring Facility
20-46
20.3.4.8
Intel® Xeon® Processor E5 Family Uncore Performance Monitoring Facility
20-47
20.3.5
3rd Generation Intel® Core™ Processor Performance Monitoring Facility
20-47
20.3.5.1
Intel® Xeon® Processor E5 v2 and E7 v2 Family Uncore Performance Monitoring Facility
20-47
20.3.6
4th Generation Intel® Core™ Processor Performance Monitoring Facility
20-47
20.3.6.1
Processor Event Based Sampling (PEBS) Facility
20-48
20.3.6.2
PEBS Data Format
20-49
20.3.6.3
PEBS Data Address Profiling
20-50
20.3.6.4
Off-core Response Performance Monitoring
20-51
20.3.6.5
Performance Monitoring and Intel® TSX
20-53
20.3.6.6
Uncore Performance Monitoring Facilities in the 4th Generation Intel® Core™ Processors
20-55
20.3.6.7
Intel® Xeon® Processor E5 v3 Family Uncore Performance Monitoring Facility
20-55
20.3.7
5th Generation Intel® Core™ Processor and Intel® Core™ M Processor Performance Monitoring Facility
20-56
xviii Vol. 3A
CONTENTS
PAGE
20.3.8
6th Generation, 7th Generation and 8th Generation Intel® Core™ Processor Performance Monitoring Facility
20-57
20.3.8.1
Processor Event Based Sampling (PEBS) Facility
20-58
20.3.8.2
Frontend Retired Facility
20-61
20.3.8.3
Off-core Response Performance Monitoring
20-63
20.3.8.4
Uncore Performance Monitoring Facilities on Intel® Core™ Processors Based on Cannon Lake Microarchitecture.20-66
20.3.9
10th Generation Intel® Core™ Processor Performance Monitoring Facility
20-66
20.3.9.1
Processor Event Based Sampling (PEBS) Facility
20-67
20.3.9.2
Off-core Response Performance Monitoring
20-67
20.3.9.3
Performance Metrics
20-69
20.3.10
12th and 13th Generation Intel® Core™ Processors, and 4th Generation Intel® Xeon® Scalable Processor Family
Performance Monitoring Facility
20-70
20.3.10.1
P-core Performance Monitoring Unit
20-70
20.3.10.2
E-core Performance Monitoring Unit
20-73
20.3.10.3
Unhalted Reference Cycles
20-75
20.4
PERFORMANCE MONITORING (INTEL® XEON™ PHI PROCESSORS)
20-76
20.4.1
Intel® Xeon Phi™ Processor 7200/5200/3200 Performance Monitoring
20-76
20.4.1.1
Enhancements of Performance Monitoring in the Intel® Xeon Phi™ Processor Tile
20-76
20.5
PERFORMANCE MONITORING (INTEL ATOM® PROCESSORS)
20-80
20.5.1
Performance Monitoring (45 nm and 32 nm Intel Atom® Processors)
20-80
20.5.2
Performance Monitoring for Silvermont Microarchitecture
20-80
20.5.2.1
Enhancements of Performance Monitoring in the Processor Core
20-80
20.5.2.2
Offcore Response Event
20-82
20.5.2.3
Average Offcore Request Latency Measurement
20-85
20.5.3
Performance Monitoring for Goldmont Microarchitecture
20-85
20.5.3.1
Processor Event Based Sampling (PEBS)
20-86
20.5.3.2
Offcore Response Event
20-89
20.5.3.3
Average Offcore Request Latency Measurement
20-90
20.5.4
Performance Monitoring for Goldmont Plus Microarchitecture
20-91
20.5.4.1
Extended PEBS
20-91
20.5.5
Performance Monitoring for Tremont Microarchitecture
20-91
20.5.5.1
Adaptive PEBS
20-92
20.5.5.2
PEBS output to Intel® Processor Trace
20-92
20.5.5.3
Precise Distribution Support on Fixed Counter 0
20-94
20.5.5.4
Compatibility Enhancements to Offcore Response MSRs
20-94
20.6
PERFORMANCE MONITORING (LEGACY INTEL PROCESSORS)
20-96
20.6.1
Performance Monitoring (Intel® Core™ Solo and Intel® Core™ Duo Processors)
20-96
20.6.2
Performance Monitoring (Processors Based on Intel® Core™ Microarchitecture)
20-97
20.6.2.1
Fixed-function Performance Counters
20-98
20.6.2.2
Global Counter Control Facilities
20-99
20.6.2.3
At-Retirement Events
20-101
20.6.2.4
Processor Event Based Sampling (PEBS)
20-101
20.6.3
Performance Monitoring (Processors Based on Intel NetBurst® Microarchitecture)
20-104
20.6.3.1
ESCR MSRs
20-107
20.6.3.2
Performance Counters
20-108
20.6.3.3
CCCR MSRs
20-109
20.6.3.4
Debug Store (DS) Mechanism
20-111
20.6.3.5
Programming the Performance Counters for Non-Retirement Events
20-111
20.6.3.6
At-Retirement Counting
20-117
20.6.3.7
Tagging Mechanism for Replay_event
20-118
20.6.3.8
Processor Event-Based Sampling (PEBS)
20-119
20.6.3.9
Operating System Implications
20-120
20.6.4
Performance Monitoring and Intel® Hyper-Threading Technology in Processors Based on Intel NetBurst®
Microarchitecture
20-120
20.6.4.1
ESCR MSRs
20-120
20.6.4.2
CCCR MSRs
20-121
20.6.4.3
IA32_PEBS_ENABLE MSR
20-123
20.6.4.4
Performance Monitoring Events
20-123
20.6.4.5
Counting Clocks on systems with Intel® Hyper-Threading Technology in Processors Based on Intel NetBurst®
Microarchitecture
20-124
20.6.5
Performance Monitoring and Dual-Core Technology
20-125
20.6.6
Performance Monitoring on 64-bit Intel® Xeon® Processor MP with Up to 8-MByte L3 Cache
20-125
20.6.7
Performance Monitoring on L3 and Caching Bus Controller Sub-Systems
20-127
20.6.7.1
Overview of Performance Monitoring with L3/Caching Bus Controller
20-129
20.6.7.2
GBSQ Event Interface
20-130
20.6.7.3
GSNPQ Event Interface
20-131
Vol. 3A xix
CONTENTS
PAGE
20.6.7.4
FSB Event Interface
20-132
20.6.7.5
Common Event Control Interface
20-133
20.6.8
Performance Monitoring (P6 Family Processor)
20-133
20.6.8.1
PerfEvtSel0 and PerfEvtSel1 MSRs
20-134
20.6.8.2
PerfCtr0 and PerfCtr1 MSRs
20-135
20.6.8.3
Starting and Stopping the Performance-Monitoring Counters
20-135
20.6.8.4
Event and Time-Stamp Monitoring Software
20-135
20.6.8.5
Monitoring Counter Overflow
20-136
20.6.9
Performance Monitoring (Pentium Processors)
20-136
20.6.9.1
Control and Event Select Register (CESR)
20-137
20.6.9.2
Use of the Performance-Monitoring Pins
20-137
20.6.9.3
Events Counted
20-138
20.7
COUNTING CLOCKS
20-138
20.7.1
Non-Halted Reference Clockticks
20-139
20.7.2
Cycle Counting and Opportunistic Processor Operation
20-139
20.7.3
Determining the Processor Base Frequency
20-140
20.7.3.1
For Intel® Processors Based on Sandy Bridge, Ivy Bridge, Haswell, and Broadwell Microarchitectures
20-140
20.7.3.2
For Intel® Processors Based on Nehalem Microarchitecture
20-140
20.7.3.3
For Intel Atom® Processors Based on Silvermont Microarchitecture (Including Intel Processors Based on Airmont
Microarchitecture)
20-140
20.7.3.4
For Intel® Core™ 2 Processor Family and for Intel® Xeon® Processors Based on Intel Core Microarchitecture . . . 20-140
20.8
IA32_PERF_CAPABILITIES MSR ENUMERATION
20-141
20.8.1
Filtering of SMM Handler Overhead
20-142
20.9
PEBS FACILITY
20-142
20.9.1
Extended PEBS
20-142
20.9.2
Adaptive PEBS
20-144
20.9.2.1
Adaptive_Record Counter Control
20-145
20.9.2.2
PEBS Record Format
20-146
20.9.2.3
MSR_PEBS_DATA_CFG
20-150
20.9.2.4
PEBS Record Examples
20-151
20.9.3
Precise Distribution of Instructions Retired (PDIR) Facility
20-153
20.9.4
Reduced Skid PEBS
20-153
20.9.5
EPT-Friendly PEBS
20-154
20.9.6
PDist: Precise Distribution
20-154
20.9.7
Load Latency Facility
20-154
20.9.8
Store Latency Facility
20-155
CHAPTER 21
8086 EMULATION
21.1
REAL-ADDRESS MODE
21-1
21.1.1
Address Translation in Real-Address Mode
21-2
21.1.2
Registers Supported in Real-Address Mode
21-3
21.1.3
Instructions Supported in Real-Address Mode
21-3
21.1.4
Interrupt and Exception Handling
21-4
21.2
VIRTUAL-8086 MODE
21-5
21.2.1
Enabling Virtual-8086 Mode
21-6
21.2.2
Structure of a Virtual-8086 Task
21-7
21.2.3
Paging of Virtual-8086 Tasks
21-7
21.2.4
Protection within a Virtual-8086 Task
21-8
21.2.5
Entering Virtual-8086 Mode
21-8
21.2.6
Leaving Virtual-8086 Mode
21-9
21.2.7
Sensitive Instructions
21-10
21.2.8
Virtual-8086 Mode I/O
21-10
21.2.8.1
I/O-Port-Mapped I/O
21-11
21.2.8.2
Memory-Mapped I/O
21-11
21.2.8.3
Special I/O Buffers
21-11
21.3
INTERRUPT AND EXCEPTION HANDLING IN VIRTUAL-8086 MODE
21-11
21.3.1
Class 1-Hardware Interrupt and Exception Handling in Virtual-8086 Mode
21-12
21.3.1.1
Handling an Interrupt or Exception Through a Protected-Mode Trap or Interrupt Gate
21-12
21.3.1.2
Handling an Interrupt or Exception With an 8086 Program Interrupt or Exception Handler
21-14
21.3.1.3
Handling an Interrupt or Exception Through a Task Gate
21-14
21.3.2
Class 2-Maskable Hardware Interrupt Handling in Virtual-8086 Mode Using the Virtual Interrupt Mechanism
21-15
21.3.3
Class 3-Software Interrupt Handling in Virtual-8086 Mode
21-16
21.3.3.1
Method 1: Software Interrupt Handling
21-18
xx Vol. 3A
CONTENTS
PAGE
21.3.3.2
Methods 2 and 3: Software Interrupt Handling
21-18
21.3.3.3
Method 4: Software Interrupt Handling
21-19
21.3.3.4
Method 5: Software Interrupt Handling
21-19
21.3.3.5
Method 6: Software Interrupt Handling
21-19
21.4
PROTECTED-MODE VIRTUAL INTERRUPTS
21-20
CHAPTER 22
MIXING 16-BIT AND 32-BIT CODE
22.1
DEFINING 16-BIT AND 32-BIT PROGRAM MODULES
22-1
22.2
MIXING 16-BIT AND 32-BIT OPERATIONS WITHIN A CODE SEGMENT
22-2
22.3
SHARING DATA AMONG MIXED-SIZE CODE SEGMENTS
22-3
22.4
TRANSFERRING CONTROL AMONG MIXED-SIZE CODE SEGMENTS
22-3
22.4.1
Code-Segment Pointer Size
22-4
22.4.2
Stack Management for Control Transfer
22-4
22.4.2.1
Controlling the Operand-Size Attribute For a Call
22-5
22.4.2.2
Passing Parameters With a Gate
22-6
22.4.3
Interrupt Control Transfers
22-6
22.4.4
Parameter Translation
22-6
22.4.5
Writing Interface Procedures
22-6
CHAPTER 23
ARCHITECTURE COMPATIBILITY
23.1
PROCESSOR FAMILIES AND CATEGORIES
23-1
23.2
RESERVED BITS
23-2
23.3
ENABLING NEW FUNCTIONS AND MODES
23-2
23.4
DETECTING THE PRESENCE OF NEW FEATURES THROUGH SOFTWARE
23-2
23.5
INTEL MMX TECHNOLOGY
23-2
23.6
STREAMING SIMD EXTENSIONS (SSE)
23-3
23.7
STREAMING SIMD EXTENSIONS 2 (SSE2)
23-3
23.8
STREAMING SIMD EXTENSIONS 3 (SSE3)
23-3
23.9
ADDITIONAL STREAMING SIMD EXTENSIONS
23-3
23.10
INTEL HYPER-THREADING TECHNOLOGY
23-3
23.11
MULTI-CORE TECHNOLOGY
23-4
23.12
SPECIFIC FEATURES OF DUAL-CORE PROCESSOR
23-4
23.13
NEW INSTRUCTIONS IN THE PENTIUM AND LATER IA-32 PROCESSORS
23-4
23.13.1
Instructions Added Prior to the Pentium Processor
23-4
23.14
OBSOLETE INSTRUCTIONS
23-5
23.15
UNDEFINED OPCODES
23-5
23.16
NEW FLAGS IN THE EFLAGS REGISTER
23-6
23.16.1
Using EFLAGS Flags to Distinguish Between 32-Bit IA-32 Processors
23-6
23.17
STACK OPERATIONS AND USER SOFTWARE
23-7
23.17.1
PUSH SP
23-7
23.17.2
EFLAGS Pushed on the Stack
23-7
23.18
X87 FPU
23-7
23.18.1
Control Register CR0 Flags
23-8
23.18.2
x87 FPU Status Word
23-8
23.18.2.1
Condition Code Flags (C0 through C3)
23-8
23.18.2.2
Stack Fault Flag
23-8
23.18.3
x87 FPU Control Word
23-9
23.18.4
x87 FPU Tag Word
23-9
23.18.5
Data Types
23-9
23.18.5.1
NaNs
23-9
23.18.5.2
Pseudo-zero, Pseudo-NaN, Pseudo-infinity, and Unnormal Formats
23-9
23.18.6
Floating-Point Exceptions
23-10
23.18.6.1
Denormal Operand Exception (#D)
23-10
23.18.6.2
Numeric Overflow Exception (#O)
23-10
23.18.6.3
Numeric Underflow Exception (#U)
23-10
23.18.6.4
Exception Precedence
23-10
23.18.6.5
CS and EIP For FPU Exceptions
23-11
23.18.6.6
FPU Error Signals
23-11
23.18.6.7
Assertion of the FERR# Pin
23-11
23.18.6.8
Invalid Operation Exception On Denormals
23-11
Vol. 3A xxi
CONTENTS
PAGE
23.18.6.9
Alignment Check Exceptions (#AC)
23-11
23.18.6.10
Segment Not Present Exception During FLDENV
23-12
23.18.6.11
Device Not Available Exception (#NM)
23-12
23.18.6.12
Coprocessor Segment Overrun Exception
23-12
23.18.6.13
General Protection Exception (#GP)
23-12
23.18.6.14
Floating-Point Error Exception (#MF)
23-12
23.18.7
Changes to Floating-Point Instructions
23-12
23.18.7.1
FDIV, FPREM, and FSQRT Instructions
23-12
23.18.7.2
FSCALE Instruction
23-12
23.18.7.3
FPREM1 Instruction
23-13
23.18.7.4
FPREM Instruction
23-13
23.18.7.5
FUCOM, FUCOMP, and FUCOMPP Instructions
23-13
23.18.7.6
FPTAN Instruction
23-13
23.18.7.7
Stack Overflow
23-13
23.18.7.8
FSIN, FCOS, and FSINCOS Instructions
23-13
23.18.7.9
FPATAN Instruction
23-13
23.18.7.10
F2XM1 Instruction
23-13
23.18.7.11
FLD Instruction
23-14
23.18.7.12
FXTRACT Instruction
23-14
23.18.7.13
Load Constant Instructions
23-14
23.18.7.14
FXAM Instruction
23-14
23.18.7.15
FSAVE and FSTENV Instructions
23-14
23.18.8
Transcendental Instructions
23-14
23.18.9
Obsolete Instructions and Undefined Opcodes
23-15
23.18.10
WAIT/FWAIT Prefix Differences
23-15
23.18.11
Operands Split Across Segments and/or Pages
23-15
23.18.12
FPU Instruction Synchronization
23-15
23.19
SERIALIZING INSTRUCTIONS
23-16
23.20
FPU AND MATH COPROCESSOR INITIALIZATION
23-16
23.20.1
Intel® 387 and Intel® 287 Math Coprocessor Initialization
23-16
23.20.2
Intel486 SX Processor and Intel 487 SX Math Coprocessor Initialization
23-16
23.21
CONTROL REGISTERS
23-17
23.22
MEMORY MANAGEMENT FACILITIES
23-19
23.22.1
New Memory Management Control Flags
23-19
23.22.1.1
Physical Memory Addressing Extension
23-19
23.22.1.2
Global Pages
23-19
23.22.1.3
Larger Page Sizes
23-19
23.22.2
CD and NW Cache Control Flags
23-19
23.22.3
Descriptor Types and Contents
23-19
23.22.4
Changes in Segment Descriptor Loads
23-20
23.23
DEBUG FACILITIES
23-20
23.23.1
Differences in Debug Register DR6
23-20
23.23.2
Differences in Debug Register DR7
23-20
23.23.3
Debug Registers DR4 and DR5
23-20
23.24
RECOGNITION OF BREAKPOINTS
23-20
23.25
EXCEPTIONS AND/OR EXCEPTION CONDITIONS
23-21
23.25.1
Machine-Check Architecture
23-22
23.25.2
Priority of Exceptions
23-22
23.25.3
Exception Conditions of Legacy SIMD Instructions Operating on MMX Registers
23-22
23.26
INTERRUPTS
23-27
23.26.1
Interrupt Propagation Delay
23-27
23.26.2
NMI Interrupts
23-27
23.26.3
IDT Limit
23-27
23.27
ADVANCED PROGRAMMABLE INTERRUPT CONTROLLER (APIC)
23-27
23.27.1
Software Visible Differences Between the Local APIC and the 82489DX
23-28
23.27.2
New Features Incorporated in the Local APIC for the P6 Family and Pentium Processors
23-28
23.27.3
New Features Incorporated in the Local APIC of the Pentium 4 and Intel Xeon Processors
23-28
23.28
TASK SWITCHING AND TSS
23-28
23.28.1
P6 Family and Pentium Processor TSS
23-29
23.28.2
TSS Selector Writes
23-29
23.28.3
Order of Reads/Writes to the TSS
23-29
23.28.4
Using A 16-Bit TSS with 32-Bit Constructs
23-29
23.28.5
Differences in I/O Map Base Addresses
23-29
23.29
CACHE MANAGEMENT
23-30
23.29.1
Self-Modifying Code with Cache Enabled
23-30
xxii Vol. 3A
CONTENTS
PAGE
23.29.2
Disabling the L3 Cache
23-31
23.30
PAGING
23-31
23.30.1
Large Pages
23-31
23.30.2
PCD and PWT Flags
23-31
23.30.3
Enabling and Disabling Paging
23-32
23.31
STACK OPERATIONS AND SUPERVISOR SOFTWARE
23-32
23.31.1
Selector Pushes and Pops
23-32
23.31.2
Error Code Pushes
23-32
23.31.3
Fault Handling Effects on the Stack
23-33
23.31.4
Interlevel RET/IRET From a 16-Bit Interrupt or Call Gate
23-33
23.32
MIXING 16- AND 32-BIT SEGMENTS
23-33
23.33
SEGMENT AND ADDRESS WRAPAROUND
23-33
23.33.1
Segment Wraparound
23-34
23.34
STORE BUFFERS AND MEMORY ORDERING
23-34
23.35
BUS LOCKING
23-35
23.36
BUS HOLD
23-35
23.37
MODEL-SPECIFIC EXTENSIONS TO THE IA-32
23-35
23.37.1
Model-Specific Registers
23-36
23.37.2
RDMSR and WRMSR Instructions
23-36
23.37.3
Memory Type Range Registers
23-36
23.37.4
Machine-Check Exception and Architecture
23-36
23.37.5
Performance-Monitoring Counters
23-37
23.38
TWO WAYS TO RUN INTEL 286 PROCESSOR TASKS
23-37
23.39
INITIAL STATE OF PENTIUM, PENTIUM PRO AND PENTIUM 4 PROCESSORS
23-37
CHAPTER 24
INTRODUCTION TO VIRTUAL MACHINE EXTENSIONS
24.1
OVERVIEW
24-1
24.2
VIRTUAL MACHINE ARCHITECTURE
24-1
24.3
INTRODUCTION TO VMX OPERATION
24-1
24.4
LIFE CYCLE OF VMM SOFTWARE
24-2
24.5
VIRTUAL-MACHINE CONTROL STRUCTURE
24-2
24.6
DISCOVERING SUPPORT FOR VMX
24-2
24.7
ENABLING AND ENTERING VMX OPERATION
24-3
24.8
RESTRICTIONS ON VMX OPERATION
24-3
CHAPTER 25
VIRTUAL MACHINE CONTROL STRUCTURES
25.1
OVERVIEW
25-1
25.2
FORMAT OF THE VMCS REGION
25-2
25.3
ORGANIZATION OF VMCS DATA
25-3
25.4
GUEST-STATE AREA
25-4
25.4.1
Guest Register State
25-4
25.4.2
Guest Non-Register State
25-6
25.5
HOST-STATE AREA
25-8
25.6
VM-EXECUTION CONTROL FIELDS
25-9
25.6.1
Pin-Based VM-Execution Controls
25-9
25.6.2
Processor-Based VM-Execution Controls
25-10
25.6.3
Exception Bitmap
25-14
25.6.4
I/O-Bitmap Addresses
25-14
25.6.5
Time-Stamp Counter Offset and Multiplier
25-14
25.6.6
Guest/Host Masks and Read Shadows for CR0 and CR4
25-14
25.6.7
CR3-Target Controls
25-14
25.6.8
Controls for APIC Virtualization
25-15
25.6.9
MSR-Bitmap Address
25-16
25.6.10
Executive-VMCS Pointer
25-16
25.6.11
Extended-Page-Table Pointer (EPTP)
25-17
25.6.12
Virtual-Processor Identifier (VPID)
25-17
25.6.13
Controls for PAUSE-Loop Exiting
25-17
25.6.14
VM-Function Controls
25-18
25.6.15
VMCS Shadowing Bitmap Addresses
25-18
25.6.16
ENCLS-Exiting Bitmap
25-18
Vol. 3A xxiii
CONTENTS
PAGE
25.6.17
ENCLV-Exiting Bitmap
25-18
25.6.18
PCONFIG-Exiting Bitmap
25-18
25.6.19
Control Field for Page-Modification Logging
25-19
25.6.20
Controls for Virtualization Exceptions
25-19
25.6.21
XSS-Exiting Bitmap
25-19
25.6.22
Sub-Page-Permission-Table Pointer (SPPTP)
25-19
25.6.23
Fields Related to Hypervisor-Managed Linear-Address Translation
25-20
25.6.24
Fields Related to PASID Translation
25-20
25.6.25
Instruction-Timeout Control
25-20
25.6.26
Fields Controlling Virtualization of the IA32_SPEC_CTRL MSR
25-21
25.7
VM-EXIT CONTROL FIELDS
25-21
25.7.1
VM-Exit Controls
25-21
25.7.2
VM-Exit Controls for MSRs
25-22
25.8
VM-ENTRY CONTROL FIELDS
25-23
25.8.1
VM-Entry Controls
25-23
25.8.2
VM-Entry Controls for MSRs
25-24
25.8.3
VM-Entry Controls for Event Injection
25-24
25.9
VM-EXIT INFORMATION FIELDS
25-25
25.9.1
Basic VM-Exit Information
25-26
25.9.2
Information for VM Exits Due to Vectored Events
25-27
25.9.3
Information for VM Exits That Occur During Event Delivery
25-27
25.9.4
Information for VM Exits Due to Instruction Execution
25-28
25.9.5
VM-Instruction Error Field
25-29
25.10
VMCS TYPES: ORDINARY AND SHADOW
25-29
25.11
SOFTWARE USE OF THE VMCS AND RELATED STRUCTURES
25-29
25.11.1
Software Use of Virtual-Machine Control Structures
25-29
25.11.2
VMREAD, VMWRITE, and Encodings of VMCS Fields
25-30
25.11.3
Initializing a VMCS
25-32
25.11.4
Software Access to Related Structures
25-32
25.11.5
VMXON Region
25-32
CHAPTER 26
VMX NON-ROOT OPERATION
26.1
INSTRUCTIONS THAT CAUSE VM EXITS
26-1
26.1.1
Relative Priority of Faults and VM Exits
26-1
26.1.2
Instructions That Cause VM Exits Unconditionally
26-2
26.1.3
Instructions That Cause VM Exits Conditionally
26-2
26.2
OTHER CAUSES OF VM EXITS
26-5
26.3
CHANGES TO INSTRUCTION BEHAVIOR IN VMX NON-ROOT OPERATION
26-7
26.4
OTHER CHANGES IN VMX NON-ROOT OPERATION
26-13
26.4.1
Event Blocking
26-13
26.4.2
Treatment of Task Switches
26-13
26.4.3
Shadow-Stack Updates
26-14
26.5
FEATURES SPECIFIC TO VMX NON-ROOT OPERATION
26-14
26.5.1
VMX-Preemption Timer
26-14
26.5.2
Monitor Trap Flag
26-15
26.5.3
Translation of Guest-Physical Addresses Using EPT
26-16
26.5.4
Translation of Guest-Physical Addresses Used by Intel Processor Trace
26-16
26.5.4.1
Guest-Physical Address Translation for Intel PT: Details
26-16
26.5.4.2
Trace-Address Pre-Translation (TAPT)
26-17
26.5.5
APIC Virtualization
26-17
26.5.6
VM Functions
26-17
26.5.6.1
Enabling VM Functions
26-17
26.5.6.2
General Operation of the VMFUNC Instruction
26-18
26.5.6.3
EPTP Switching
26-18
26.5.7
Virtualization Exceptions
26-19
26.5.7.1
Convertible EPT Violations
26-20
26.5.7.2
Virtualization-Exception Information
26-20
26.5.7.3
Delivery of Virtualization Exceptions
26-21
26.5.8
PASID Translation
26-21
26.6
UNRESTRICTED GUESTS
26-22
xxiv Vol. 3A
CONTENTS
PAGE
CHAPTER 27
VM ENTRIES
27.1
BASIC VM-ENTRY CHECKS
27-2
27.2
CHECKS ON VMX CONTROLS AND HOST-STATE AREA
27-2
27.2.1
Checks on VMX Controls
27-2
27.2.1.1
VM-Execution Control Fields
27-2
27.2.1.2
VM-Exit Control Fields
27-5
27.2.1.3
VM-Entry Control Fields
27-6
27.2.2
Checks on Host Control Registers, MSRs, and SSP
27-7
27.2.3
Checks on Host Segment and Descriptor-Table Registers
27-7
27.2.4
Checks Related to Address-Space Size
27-8
27.3
CHECKING AND LOADING GUEST STATE
27-8
27.3.1
Checks on the Guest State Area
27-8
27.3.1.1
Checks on Guest Control Registers, Debug Registers, and MSRs
27-8
27.3.1.2
Checks on Guest Segment Registers
27-10
27.3.1.3
Checks on Guest Descriptor-Table Registers
27-12
27.3.1.4
Checks on Guest RIP, RFLAGS, and SSP
27-12
27.3.1.5
Checks on Guest Non-Register State
27-13
27.3.1.6
Checks on Guest Page-Directory-Pointer-Table Entries
27-15
27.3.2
Loading Guest State
27-15
27.3.2.1
Loading Guest Control Registers, Debug Registers, and MSRs
27-15
27.3.2.2
Loading Guest Segment Registers and Descriptor-Table Registers
27-17
27.3.2.3
Loading Guest RIP, RSP, RFLAGS, and SSP
27-17
27.3.2.4
Loading Page-Directory-Pointer-Table Entries
27-18
27.3.2.5
Updating Non-Register State
27-18
27.3.3
Clearing Address-Range Monitoring
27-18
27.4
LOADING MSRS
27-18
27.5
TRACE-ADDRESS PRE-TRANSLATION (TAPT)
27-19
27.6
EVENT INJECTION
27-19
27.6.1
Vectored-Event Injection
27-19
27.6.1.1
Details of Vectored-Event Injection
27-20
27.6.1.2
VM Exits During Event Injection
27-21
27.6.1.3
Event Injection for VM Entries to Real-Address Mode
27-22
27.6.2
Injection of Pending MTF VM Exits
27-22
27.7
SPECIAL FEATURES OF VM ENTRY
27-22
27.7.1
Interruptibility State
27-22
27.7.2
Activity State
27-23
27.7.3
Delivery of Pending Debug Exceptions after VM Entry
27-24
27.7.4
VMX-Preemption Timer
27-25
27.7.5
Interrupt-Window Exiting and Virtual-Interrupt Delivery
27-25
27.7.6
NMI-Window Exiting
27-25
27.7.7
VM Exits Induced by the TPR Threshold
27-25
27.7.8
Pending MTF VM Exits
27-26
27.7.9
VM Entries and Advanced Debugging Features
27-26
27.7.10
User-Interrupt Recognition After VM Entry
27-26
27.8
VM-ENTRY FAILURES DURING OR AFTER LOADING GUEST STATE
27-26
27.9
MACHINE-CHECK EVENTS DURING VM ENTRY
27-27
CHAPTER 28
VM EXITS
28.1
ARCHITECTURAL STATE BEFORE A VM EXIT
28-1
28.2
RECORDING VM-EXIT INFORMATION AND UPDATING VM-ENTRY CONTROL FIELDS
28-4
28.2.1
Basic VM-Exit Information
28-4
28.2.2
Information for VM Exits Due to Vectored Events
28-12
28.2.3
Information About NMI Unblocking Due to IRET
28-13
28.2.4
Information for VM Exits During Event Delivery
28-13
28.2.5
Information for VM Exits Due to Instruction Execution
28-15
28.3
SAVING GUEST STATE
28-21
28.3.1
Saving Control Registers, Debug Registers, and MSRs
28-23
28.3.2
Saving Segment Registers and Descriptor-Table Registers
28-23
28.3.3
Saving RIP, RSP, RFLAGS, and SSP
28-24
28.3.4
Saving Non-Register State
28-26
28.4
SAVING MSRS
28-28
Vol. 3A xxv
CONTENTS
PAGE
28.5
LOADING HOST STATE
28-28
28.5.1
Loading Host Control Registers, Debug Registers, MSRs
28-28
28.5.2
Loading Host Segment and Descriptor-Table Registers
28-30
28.5.3
Loading Host RIP, RSP, RFLAGS, and SSP
28-31
28.5.4
Checking and Loading Host Page-Directory-Pointer-Table Entries
28-31
28.5.5
Updating Non-Register State
28-31
28.5.6
Clearing Address-Range Monitoring
28-32
28.6
LOADING MSRS
28-32
28.7
VMX ABORTS
28-32
28.8
MACHINE-CHECK EVENTS DURING VM EXIT
28-33
28.9
USER-INTERRUPT RECOGNITION AFTER VM EXIT
28-34
CHAPTER 29
VMX SUPPORT FOR ADDRESS TRANSLATION
29.1
VIRTUAL PROCESSOR IDENTIFIERS (VPIDS)
29-1
29.2
HYPERVISOR-MANAGED LINEAR-ADDRESS TRANSLATION (HLAT)
29-1
29.3
THE EXTENDED PAGE TABLE MECHANISM (EPT)
29-1
29.3.1
EPT Overview
29-2
29.3.2
EPT Translation Mechanism
29-3
29.3.3
EPT-Induced VM Exits
29-10
29.3.3.1
EPT Misconfigurations
29-10
29.3.3.2
EPT Violations
29-12
29.3.3.3
Prioritization of EPT Misconfigurations and EPT Violations
29-15
29.3.4
Sub-Page Write Permissions
29-16
29.3.4.1
Write Accesses That Are Eligible for Sub-Page Write Permissions
29-17
29.3.4.2
Determining an Access’s Sub-Page Write Permission
29-17
29.3.5
Accessed and Dirty Flags for EPT
29-18
29.3.6
Page-Modification Logging
29-19
29.3.7
EPT and Memory Typing
29-19
29.3.7.1
Memory Type Used for Accessing EPT Paging Structures
29-19
29.3.7.2
Memory Type Used for Translated Guest-Physical Addresses
29-19
29.4
CACHING TRANSLATION INFORMATION
29-20
29.4.1
Information That May Be Cached
29-20
29.4.2
Creating and Using Cached Translation Information
29-21
29.4.3
Invalidating Cached Translation Information
29-22
29.4.3.1
Operations that Invalidate Cached Mappings
29-22
29.4.3.2
Operations that Need Not Invalidate Cached Mappings
29-24
29.4.3.3
Guidelines for Use of the INVVPID Instruction
29-24
29.4.3.4
Guidelines for Use of the INVEPT Instruction
29-25
CHAPTER 30
APIC VIRTUALIZATION AND VIRTUAL INTERRUPTS
30.1
VIRTUAL APIC STATE
30-1
30.1.1
Virtualized APIC Registers
30-2
30.1.2
TPR Virtualization
30-2
30.1.3
PPR Virtualization
30-2
30.1.4
EOI Virtualization
30-3
30.1.5
Self-IPI Virtualization
30-3
30.1.6
IPI Virtualization
30-3
30.2
EVALUATION AND DELIVERY OF VIRTUAL INTERRUPTS
30-4
30.2.1
Evaluation of Pending Virtual Interrupts
30-4
30.2.2
Virtual-Interrupt Delivery
30-5
30.2.3
Virtualizing User-Interrupt Notifications
30-6
30.3
VIRTUALIZING CR8-BASED TPR ACCESSES
30-6
30.4
VIRTUALIZING MEMORY-MAPPED APIC ACCESSES
30-6
30.4.1
Priority of APIC-Access VM Exits
30-7
30.4.2
Virtualizing Reads from the APIC-Access Page
30-8
30.4.3
Virtualizing Writes to the APIC-Access Page
30-9
30.4.3.1
Determining Whether a Write Access is Virtualized
30-9
30.4.3.2
APIC-Write Emulation
30-10
30.4.3.3
APIC-Write VM Exits
30-11
30.4.4
Instruction-Specific Considerations
30-11
xxvi Vol. 3A
CONTENTS
PAGE
30.4.5
Issues Pertaining to Page Size and TLB Management
30-12
30.4.6
APIC Accesses Not Directly Resulting From Linear Addresses
30-12
30.4.6.1
Guest-Physical Accesses to the APIC-Access Page
30-13
30.4.6.2
Physical Accesses to the APIC-Access Page
30-13
30.5
VIRTUALIZING MSR-BASED APIC ACCESSES
30-14
30.6
POSTED-INTERRUPT PROCESSING
30-15
30.7
VIRTUALIZING SENDUIPI
30-16
CHAPTER 31
VMX INSTRUCTION REFERENCE
31.1
OVERVIEW
31-1
31.2
CONVENTIONS
31-2
31.3
VMX INSTRUCTIONS
31-2
INVEPT- Invalidate Translations Derived from EPT
31-3
INVVPID- Invalidate Translations Based on VPID
31-6
VMCALL-Call to VM Monitor
31-9
VMCLEAR-Clear Virtual-Machine Control Structure
31-11
VMFUNC-Invoke VM function
31-13
VMLAUNCH/VMRESUME-Launch/Resume Virtual Machine
31-14
VMPTRLD-Load Pointer to Virtual-Machine Control Structure
31-17
VMPTRST-Store Pointer to Virtual-Machine Control Structure
31-19
VMREAD-Read Field from Virtual-Machine Control Structure
31-21
VMRESUME-Resume Virtual Machine
31-23
VMWRITE-Write Field to Virtual-Machine Control Structure
31-24
VMXOFF-Leave VMX Operation
31-26
VMXON-Enter VMX Operation
31-28
31.4
VM INSTRUCTION ERROR NUMBERS
31-31
CHAPTER 32
SYSTEM MANAGEMENT MODE
32.1
SYSTEM MANAGEMENT MODE OVERVIEW
32-1
32.1.1
System Management Mode and VMX Operation
32-2
32.2
SYSTEM MANAGEMENT INTERRUPT (SMI)
32-2
32.3
SWITCHING BETWEEN SMM AND THE OTHER PROCESSOR OPERATING MODES
32-2
32.3.1
Entering SMM
32-2
32.3.2
Exiting From SMM
32-3
32.4
SMRAM
32-4
32.4.1
SMRAM State Save Map
32-4
32.4.1.1
SMRAM State Save Map and Intel 64 Architecture
32-6
32.4.2
SMRAM Caching
32-8
32.4.2.1
System Management Range Registers (SMRR)
32-9
32.5
SMI HANDLER EXECUTION ENVIRONMENT
32-9
32.5.1
Initial SMM Execution Environment
32-9
32.5.2
SMI Handler Operating Mode Switching
32-10
32.5.3
Control-flow Enforcement Technology Interactions
32-11
32.6
EXCEPTIONS AND INTERRUPTS WITHIN SMM
32-11
32.7
MANAGING SYNCHRONOUS AND ASYNCHRONOUS SYSTEM MANAGEMENT INTERRUPTS
32-12
32.7.1
I/O State Implementation
32-12
32.8
NMI HANDLING WHILE IN SMM
32-13
32.9
SMM REVISION IDENTIFIER
32-13
32.10
AUTO HALT RESTART
32-14
32.10.1
Executing the HLT Instruction in SMM
32-14
32.11
SMBASE RELOCATION
32-14
32.12
I/O INSTRUCTION RESTART
32-15
32.12.1
Back-to-Back SMI Interrupts When I/O Instruction Restart Is Being Used
32-16
32.13
SMM MULTIPLE-PROCESSOR CONSIDERATIONS
32-16
32.14
DEFAULT TREATMENT OF SMIS AND SMM WITH VMX OPERATION AND SMX OPERATION
32-16
32.14.1
Default Treatment of SMI Delivery
32-17
32.14.2
Default Treatment of RSM
32-18
32.14.3
Protection of CR4.VMXE in SMM
32-19
32.14.4
VMXOFF and SMI Unblocking
32-19
Vol. 3A xxvii
CONTENTS
PAGE
32.15
DUAL-MONITOR TREATMENT OF SMIs AND SMM
32-19
32.15.1
Dual-Monitor Treatment Overview
32-19
32.15.2
SMM VM Exits
32-20
32.15.2.1
Architectural State Before a VM Exit
32-20
32.15.2.2
Updating the Current-VMCS and Executive-VMCS Pointers
32-20
32.15.2.3
Recording VM-Exit Information
32-20
32.15.2.4
Saving Guest State
32-21
32.15.2.5
Updating State
32-21
32.15.3
Operation of the SMM-Transfer Monitor
32-22
32.15.4
VM Entries that Return from SMM
32-22
32.15.4.1
Checks on the Executive-VMCS Pointer Field
32-22
32.15.4.2
Checks on VM-Execution Control Fields
32-22
32.15.4.3
Checks on VM-Entry Control Fields
32-23
32.15.4.4
Checks on the Guest State Area
32-23
32.15.4.5
Loading Guest State
32-23
32.15.4.6
VMX-Preemption Timer
32-23
32.15.4.7
Updating the Current-VMCS and SMM-Transfer VMCS Pointers
32-24
32.15.4.8
VM Exits Induced by VM Entry
32-24
32.15.4.9
SMI Blocking
32-24
32.15.4.10
Failures of VM Entries That Return from SMM
32-24
32.15.5
Enabling the Dual-Monitor Treatment
32-25
32.15.6
Activating the Dual-Monitor Treatment
32-26
32.15.6.1
Initial Checks
32-26
32.15.6.2
Updating the Current-VMCS and Executive-VMCS Pointers
32-27
32.15.6.3
Saving Guest State
32-27
32.15.6.4
Saving MSRs
32-27
32.15.6.5
Loading Host State
32-27
32.15.6.6
Loading MSRs
32-29
32.15.7
Deactivating the Dual-Monitor Treatment
32-29
32.16
SMI AND PROCESSOR EXTENDED STATE MANAGEMENT
32-29
32.17
MODEL-SPECIFIC SYSTEM MANAGEMENT ENHANCEMENT
32-30
32.17.1
SMM Handler Code Access Control
32-30
32.17.2
SMI Delivery Delay Reporting
32-30
32.17.3
Blocked SMI Reporting
32-30
CHAPTER 33
INTEL® PROCESSOR TRACE
33.1
OVERVIEW
33-1
33.1.1
Features and Capabilities
33-1
33.1.1.1
Packet Summary
33-1
33.2
INTEL® PROCESSOR TRACE OPERATIONAL MODEL
33-2
33.2.1
Change of Flow Instruction (COFI) Tracing
33-2
33.2.1.1
Direct Transfer COFI
33-3
33.2.1.2
Indirect Transfer COFI
33-3
33.2.1.3
Far Transfer COFI
33-4
33.2.2
Software Trace Instrumentation with PTWRITE
33-4
33.2.3
Power Event Tracing
33-4
33.2.4
Event Tracing
33-5
33.2.5
Trace Filtering
33-5
33.2.5.1
Filtering by Current Privilege Level (CPL)
33-5
33.2.5.2
Filtering by CR3
33-5
33.2.5.3
Filtering by IP
33-6
33.2.6
Packet Generation Enable Controls
33-7
33.2.6.1
Packet Enable (PacketEn)
33-7
33.2.6.2
Trigger Enable (TriggerEn)
33-8
33.2.6.3
Context Enable (ContextEn)
33-8
33.2.6.4
Branch Enable (BranchEn)
33-8
33.2.6.5
Filter Enable (FilterEn)
33-8
33.2.7
Trace Output
33-9
33.2.7.1
Single Range Output
33-9
33.2.7.2
Table of Physical Addresses (ToPA)
33-10
Single Output Region ToPA Implementation
33-12
ToPA Table Entry Format
33-12
xxviii Vol. 3A
CONTENTS
PAGE
ToPA STOP
33-13
ToPA PMI
33-13
PMI Preservation
33-14
ToPA PMI and Single Output Region ToPA Implementation
33-14
ToPA PMI and XSAVES/XRSTORS State Handling
33-15
ToPA Errors
33-15
33.2.7.3
Trace Transport Subsystem
33-16
33.2.7.4
Restricted Memory Access
33-16
Modifications to Restricted Memory Regions
33-16
33.2.8
Enabling and Configuration MSRs
33-17
33.2.8.1
General Considerations
33-17
33.2.8.2
IA32_RTIT_CTL MSR
33-17
33.2.8.3
Enabling and Disabling Packet Generation with TraceEn
33-20
Disabling Packet Generation
33-21
Other Writes to IA32_RTIT_CTL
33-21
33.2.8.4
IA32_RTIT_STATUS MSR
33-21
33.2.8.5
IA32_RTIT_ADDRn_A and IA32_RTIT_ADDRn_B MSRs
33-22
33.2.8.6
IA32_RTIT_CR3_MATCH MSR
33-22
33.2.8.7
IA32_RTIT_OUTPUT_BASE MSR
33-23
33.2.8.8
IA32_RTIT_OUTPUT_MASK_PTRS MSR
33-23
33.2.9
Interaction of Intel® Processor Trace and Other Processor Features
33-24
33.2.9.1
Intel® Transactional Synchronization Extensions (Intel® TSX)
33-24
33.2.9.2
TSX and IP Filtering
33-25
33.2.9.3
System Management Mode (SMM)
33-25
33.2.9.4
Virtual-Machine Extensions (VMX)
33-26
33.2.9.5
Intel® Software Guard Extensions (Intel® SGX)
33-26
33.2.9.6
SENTER/ENTERACCS and ACM
33-26
33.2.9.7
Intel® Memory Protection Extensions (Intel® MPX)
33-26
33.3
CONFIGURATION AND PROGRAMMING GUIDELINE
33-26
33.3.1
Detection of Intel Processor Trace and Capability Enumeration
33-26
33.3.1.1
Packet Decoding of RIP versus LIP
33-30
33.3.1.2
Model Specific Capability Restrictions
33-30
33.3.2
Enabling and Configuration of Trace Packet Generation
33-30
33.3.2.1
Enabling Packet Generation
33-30
33.3.2.2
Disabling Packet Generation
33-31
33.3.3
Flushing Trace Output
33-31
33.3.4
Warm Reset
33-31
33.3.5
Context Switch Consideration
33-31
33.3.5.1
Manual Trace Configuration Context Switch
33-31
33.3.5.2
Trace Configuration Context Switch Using XSAVES/XRSTORS
33-32
33.3.6
Cycle-Accurate Mode
33-32
33.3.6.1
Cycle Counter
33-33
33.3.6.2
Cycle Packet Semantics
33-33
33.3.6.3
Cycle Thresholds
33-33
33.3.7
Decoder Synchronization (PSB+)
33-34
33.3.8
Internal Buffer Overflow
33-35
33.3.8.1
Overflow Impact on Enables
33-35
33.3.8.2
Overflow Impact on Timing Packets
33-35
33.3.9
TNT Disable
33-36
33.3.10
Operational Errors
33-36
33.4
TRACE PACKETS AND DATA TYPES
33-36
33.4.1
Packet Relationships and Ordering
33-36
33.4.1.1
Packet Blocks
33-37
Decoder Implications
33-37
33.4.2
Packet Definitions
33-38
33.4.2.1
Taken/Not-taken (TNT) Packet
33-39
33.4.2.2
Target IP (TIP) Packet
33-40
IP Compression
33-40
Indirect Transfer Compression for Returns (RET)
33-41
33.4.2.3
Deferred TIPs
33-42
33.4.2.4
Packet Generation Enable (TIP.PGE) Packet
33-43
33.4.2.5
Packet Generation Disable (TIP.PGD) Packet
33-44
33.4.2.6
Flow Update (FUP) Packet
33-45
Vol. 3A xxix
CONTENTS
PAGE
FUP IP Payload
33-45
33.4.2.7
Paging Information (PIP) Packet
33-47
33.4.2.8
MODE Packets
33-47
MODE.Exec Packet
33-48
MODE.TSX Packet
33-49
33.4.2.9
TraceStop Packet
33-50
33.4.2.10
Core:Bus Ratio (CBR) Packet
33-50
33.4.2.11
Timestamp Counter (TSC) Packet
33-51
33.4.2.12
Mini Time Counter (MTC) Packet
33-52
33.4.2.13
TSC/MTC Alignment (TMA) Packet
33-53
33.4.2.14
Cycle Count (CYC) Packet
33-54
33.4.2.15
VMCS Packet
33-55
33.4.2.16
Overflow (OVF) Packet
33-56
33.4.2.17
Packet Stream Boundary (PSB) Packet
33-56
33.4.2.18
PSBEND Packet
33-57
33.4.2.19
Maintenance (MNT) Packet
33-58
33.4.2.20
PAD Packet
33-58
33.4.2.21
PTWRITE (PTW) Packet
33-59
33.4.2.22
Execution Stop (EXSTOP) Packet
33-60
33.4.2.23
MWAIT Packet
33-61
33.4.2.24
Power Entry (PWRE) Packet
33-62
33.4.2.25
Power Exit (PWRX) Packet
33-63
33.4.2.26
Block Begin Packet (BBP)
33-64
33.4.2.27
Block Item Packet (BIP)
33-65
BIP State Value Encodings
33-65
33.4.2.28
Block End Packet (BEP)
33-70
33.4.2.29
Control Flow Event (CFE) Packet
33-71
CFE Packet Type and Vector Fields
33-71
33.4.2.30
Event Data (EVD) Packet
33-73
33.5
TRACING IN VMX OPERATION
33-73
33.5.1
VMX-Specific Packets and VMCS Controls
33-74
33.5.2
Managing Trace Packet Generation Across VMX Transitions
33-74
33.5.2.1
System-Wide Tracing
33-75
33.5.2.2
Guest-Only Tracing
33-75
33.5.2.3
Emulation of Intel PT Traced State
33-76
33.5.2.4
TSC Scaling
33-76
33.5.2.5
Failed VM Entry
33-76
33.5.2.6
VMX Abort
33-77
33.6
TRACING AND SMM TRANSFER MONITOR (STM)
33-77
33.7
PACKET GENERATION SCENARIOS
33-77
33.8
SOFTWARE CONSIDERATIONS
33-81
33.8.1
Tracing SMM Code
33-81
33.8.2
Cooperative Transition of Multiple Trace Collection Agents
33-81
33.8.3
Tracking Time
33-81
33.8.3.1
Time Domain Relationships
33-82
33.8.3.2
Estimating TSC within Intel PT
33-82
33.8.3.3
VMX TSC Manipulation
33-83
33.8.3.4
Calculating Frequency with Intel PT
33-83
CHAPTER 34
INTRODUCTION TO INTEL® SOFTWARE GUARD EXTENSIONS
34.1
OVERVIEW
34-1
34.2
ENCLAVE INTERACTION AND PROTECTION
34-1
34.3
ENCLAVE LIFE CYCLE
34-2
34.4
DATA STRUCTURES AND ENCLAVE OPERATION
34-2
34.5
ENCLAVE PAGE CACHE
34-2
34.5.1
Enclave Page Cache Map (EPCM)
34-3
34.6
ENCLAVE INSTRUCTIONS AND INTEL® SGX
34-3
34.7
DISCOVERING SUPPORT FOR INTEL® SGX AND ENABLING ENCLAVE INSTRUCTIONS
34-4
34.7.1
Intel® SGX Opt-In Configuration
34-5
34.7.2
Intel® SGX Resource Enumeration Leaves
34-5
34.8
INTEL® SGX INTERACTIONS WITH CONTROL-FLOW ENFORCEMENT TECHNOLOGY
34-7
34.8.1
CET in Enclaves Model
34-7
xxx Vol. 3A
CONTENTS
PAGE
34.8.2
Operations Not Supported on Shadow Stack Pages
34-8
34.8.3
Indirect Branch Tracking - Legacy Compatibility Treatment
34-8
CHAPTER 35
ENCLAVE ACCESS CONTROL AND DATA STRUCTURES
35.1
OVERVIEW OF ENCLAVE EXECUTION ENVIRONMENT
35-1
35.2
TERMINOLOGY
35-1
35.3
ACCESS-CONTROL REQUIREMENTS
35-1
35.4
SEGMENT-BASED ACCESS CONTROL
35-2
35.5
PAGE-BASED ACCESS CONTROL
35-2
35.5.1
Access-control for Accesses that Originate from Non-SGX Instructions
35-2
35.5.2
Memory Accesses that Split Across ELRANGE
35-2
35.5.3
Implicit vs. Explicit Accesses
35-3
35.5.3.1
Explicit Accesses
35-3
35.5.3.2
Implicit Accesses
35-3
35.6
INTEL® SGX DATA STRUCTURES OVERVIEW
35-4
35.7
SGX ENCLAVE CONTROL STRUCTURE (SECS)
35-5
35.7.1
ATTRIBUTES
35-6
35.7.2
SECS.MISCSELECT Field
35-6
35.7.3
SECS.CET_ATTRIBUTES Field
35-6
35.8
THREAD CONTROL STRUCTURE (TCS)
35-7
35.8.1
TCS.FLAGS
35-8
35.8.2
State Save Area Offset (OSSA)
35-8
35.8.3
Current State Save Area Frame (CSSA)
35-8
35.8.4
Number of State Save Area Frames (NSSA)
35-8
35.9
STATE SAVE AREA (SSA) FRAME
35-8
35.9.1
GPRSGX Region
35-9
35.9.1.1
EXITINFO
35-10
35.9.1.2
VECTOR Field Definition
35-10
35.9.2
MISC Region
35-11
35.9.2.1
EXINFO Structure
35-11
35.9.2.2
Page Fault Error Code
35-12
35.10
CET STATE SAVE AREA FRAME
35-12
35.11
PAGE INFORMATION (PAGEINFO)
35-12
35.12
SECURITY INFORMATION (SECINFO)
35-13
35.12.1
SECINFO.FLAGS
35-13
35.12.2
PAGE_TYPE Field Definition
35-13
35.13
PAGING CRYPTO METADATA (PCMD)
35-14
35.14
ENCLAVE SIGNATURE STRUCTURE (SIGSTRUCT)
35-14
35.15
EINIT TOKEN STRUCTURE (EINITTOKEN)
35-15
35.16
REPORT (REPORT)
35-16
35.16.1
REPORTDATA
35-17
35.17
REPORT TARGET INFO (TARGETINFO)
35-17
35.18
KEY REQUEST (KEYREQUEST)
35-17
35.18.1
KEY REQUEST KeyNames
35-18
35.18.2
Key Request Policy Structure
35-18
35.19
VERSION ARRAY (VA)
35-19
35.20
ENCLAVE PAGE CACHE MAP (EPCM)
35-19
35.21
READ INFO (RDINFO)
35-19
35.21.1
RDINFO Status Structure
35-20
35.21.2
RDINFO Flags Structure
35-20
CHAPTER 36
ENCLAVE OPERATION
36.1
CONSTRUCTING AN ENCLAVE
36-1
36.1.1
ECREATE
36-2
36.1.2
EADD and EEXTEND Interaction
36-2
36.1.3
EINIT Interaction
36-2
36.1.4
Intel® SGX Launch Control Configuration
36-3
36.2
ENCLAVE ENTRY AND EXITING
36-3
36.2.1
Controlled Entry and Exit
36-3
36.2.2
Asynchronous Enclave Exit (AEX)
36-4
Vol. 3A xxxi
CONTENTS
PAGE
36.2.3
Resuming Execution After AEX
36-4
36.2.3.1
ERESUME Interaction
36-5
36.2.3.2
Asynchronous Enclave Exit Notify and EDECCSSA
36-5
36.3
CALLING ENCLAVE PROCEDURES
36-6
36.3.1
Calling Convention
36-6
36.3.2
Register Preservation
36-6
36.3.3
Returning to Caller
36-6
36.4
INTEL® SGX KEY AND ATTESTATION
36-6
36.4.1
Enclave Measurement and Identification
36-6
36.4.1.1
MRENCLAVE
36-6
36.4.1.2
MRSIGNER
36-7
36.4.1.3
CONFIGID
36-7
36.4.2
Security Version Numbers (SVN)
36-7
36.4.2.1
Enclave Security Version
36-8
36.4.2.2
Hardware Security Version
36-8
36.4.2.3
CONFIGID Security Version
36-8
36.4.3
Keys
36-8
36.4.3.1
Sealing Enclave Data
36-9
36.4.3.2
Using REPORTs for Local Attestation
36-9
36.5
EPC AND MANAGEMENT OF EPC PAGES
36-10
36.5.1
EPC Implementation
36-10
36.5.2
OS Management of EPC Pages
36-10
36.5.2.1
Enhancement to Managing EPC Pages
36-10
36.5.3
Eviction of Enclave Pages
36-10
36.5.4
Loading an Enclave Page
36-11
36.5.5
Eviction of an SECS Page
36-11
36.5.6
Eviction of a Version Array Page
36-12
36.5.7
Allocating a Regular Page
36-12
36.5.8
Allocating a TCS Page
36-12
36.5.9
Trimming a Page
36-13
36.5.10
Restricting the EPCM Permissions of a Page
36-13
36.5.11
Extending the EPCM Permissions of a Page
36-14
36.5.12
VMM Oversubscription of EPC
36-14
36.6
CHANGES TO INSTRUCTION BEHAVIOR INSIDE AN ENCLAVE
36-14
36.6.1
Illegal Instructions
36-15
36.6.2
RDRAND and RDSEED Instructions
36-15
36.6.3
PAUSE Instruction
36-15
36.6.4
Executions of INT1 and INT3 Inside an Enclave
36-16
36.6.5
INVD Handling when Enclaves Are Enabled
36-16
CHAPTER 37
ENCLAVE EXITING EVENTS
37.1
COMPATIBLE SWITCH TO THE EXITING STACK OF AEX
37-1
37.2
STATE SAVING BY AEX
37-2
37.3
SYNTHETIC STATE ON ASYNCHRONOUS ENCLAVE EXIT
37-3
37.3.1
Processor Synthetic State on Asynchronous Enclave Exit
37-3
37.3.2
Synthetic State for Extended Features
37-3
37.3.3
Synthetic State for MISC Features
37-4
37.4
AEX FLOW
37-4
37.4.1
AEX Operational Detail
37-5
CHAPTER 38
INTEL® SGX INSTRUCTION REFERENCES
38.1
INTEL® SGX INSTRUCTION SYNTAX AND OPERATION
38-1
38.1.1
ENCLS Register Usage Summary
38-1
38.1.2
ENCLU Register Usage Summary
38-2
38.1.3
ENCLV Register Usage Summary
38-2
38.1.4
Information and Error Codes
38-2
38.1.5
Internal CREGs
38-3
38.1.6
Concurrent Operation Restrictions
38-4
38.1.6.1
Concurrency Tables of Intel® SGX Instructions
38-4
38.2
INTEL® SGX INSTRUCTION REFERENCE
38-8
xxxii Vol. 3A
CONTENTS
PAGE
ENCLS-Execute an Enclave System Function of Specified Leaf Number
38-9
ENCLU-Execute an Enclave User Function of Specified Leaf Number
38-11
ENCLV-Execute an Enclave VMM Function of Specified Leaf Number
38-14
38.3
INTEL® SGX SYSTEM LEAF FUNCTION REFERENCE
38-16
EADD-Add a Page to an Uninitialized Enclave
38-17
EAUG-Add a Page to an Initialized Enclave
38-22
EBLOCK-Mark a page in EPC as Blocked
38-27
ECREATE-Create an SECS page in the Enclave Page Cache
38-30
EDBGRD-Read From a Debug Enclave
38-36
EDBGWR-Write to a Debug Enclave
38-40
EEXTEND-Extend Uninitialized Enclave Measurement by 256 Bytes
38-44
EINIT-Initialize an Enclave for Execution
38-47
ELDB/ELDU/ELDBC/ELDUC-Load an EPC Page and Mark its State
38-55
EMODPR-Restrict the Permissions of an EPC Page
38-61
EMODT-Change the Type of an EPC Page
38-64
EPA-Add Version Array
38-67
ERDINFO-Read Type and Status Information About an EPC Page
38-69
EREMOVE-Remove a page from the EPC
38-73
ETRACK-Activates EBLOCK Checks
38-77
ETRACKC-Activates EBLOCK Checks
38-80
EWB-Invalidate an EPC Page and Write out to Main Memory
38-84
38.4
INTEL® SGX USER LEAF FUNCTION REFERENCE
38-89
EACCEPT-Accept Changes to an EPC Page
38-90
EACCEPTCOPY-Initialize a Pending Page
38-95
EDECCSSA-Decrements TCS.CSSA
38-99
EENTER-Enters an Enclave
38-103
EEXIT-Exits an Enclave
38-112
EGETKEY-Retrieves a Cryptographic Key
38-115
EMODPE-Extend an EPC Page Permissions
38-125
EREPORT-Create a Cryptographic Report of the Enclave
38-128
ERESUME-Re-Enters an Enclave
38-133
38.5
INTEL® SGX VIRTUALIZATION LEAF FUNCTION REFERENCE
38-145
EDECVIRTCHILD-Decrement VIRTCHILDCNT in SECS
38-146
EINCVIRTCHILD-Increment VIRTCHILDCNT in SECS
38-150
ESETCONTEXT-Set the ENCLAVECONTEXT Field in SECS
38-153
CHAPTER 39
INTEL® SGX INTERACTIONS WITH IA32 AND INTEL® 64 ARCHITECTURE
39.1
INTEL® SGX AVAILABILITY IN VARIOUS PROCESSOR MODES
39-1
39.2
IA32_FEATURE_CONTROL
39-1
39.2.1
Availability of Intel SGX
39-1
39.2.2
Intel SGX Launch Control Configuration
39-1
39.3
INTERACTIONS WITH SEGMENTATION
39-1
39.3.1
Scope of Interaction
39-1
39.3.2
Interactions of Intel® SGX Instructions with Segment, Operand, and Addressing Prefixes
39-2
39.3.3
Interaction of Intel® SGX Instructions with Segmentation
39-2
39.3.4
Interactions of Enclave Execution with Segmentation
39-2
39.4
INTERACTIONS WITH PAGING
39-2
39.5
INTERACTIONS WITH VMX
39-3
39.5.1
VMM Controls to Configure Guest Support of Intel® SGX
39-3
39.5.2
Interactions with the Extended Page Table Mechanism (EPT)
39-3
39.5.3
Interactions with APIC Virtualization
39-4
39.5.4
Interactions with VT and SGX concurrency
39-4
39.5.5
Virtual Child Tracking
39-5
39.5.6
Handling EPCM Entry Lock Conflicts
39-5
39.5.7
Context Tracking
39-6
39.6
INTEL® SGX INTERACTIONS WITH ARCHITECTURALLY-VISIBLE EVENTS
39-6
39.7
INTERACTIONS WITH THE PROCESSOR EXTENDED STATE AND MISCELLANEOUS STATE
39-6
39.7.1
Requirements and Architecture Overview
39-6
39.7.2
Relevant Fields in Various Data Structures
39-7
Vol. 3A xxxiii
CONTENTS
PAGE
39.7.2.1
SECS.ATTRIBUTES.XFRM
39-7
39.7.2.2
SECS.SSAFRAMESIZE
39-8
39.7.2.3
XSAVE Area in SSA
39-8
39.7.2.4
MISC Area in SSA
39-8
39.7.2.5
SIGSTRUCT Fields
39-8
39.7.2.6
REPORT.ATTRIBUTES.XFRM and REPORT.MISCSELECT
39-9
39.7.2.7
KEYREQUEST
39-9
39.7.3
Processor Extended States and ENCLS[ECREATE]
39-9
39.7.4
Processor Extended States and ENCLU[EENTER]
39-9
39.7.4.1
Fault Checking
39-9
39.7.4.2
State Loading
39-9
39.7.5
Processor Extended States and AEX
39-10
39.7.5.1
State Saving
39-10
39.7.5.2
State Synthesis
39-10
39.7.6
Processor Extended States and ENCLU[ERESUME]
39-10
39.7.6.1
Fault Checking
39-10
39.7.6.2
State Loading
39-10
39.7.7
Processor Extended States and ENCLU[EEXIT]
39-10
39.7.8
Processor Extended States and ENCLU[EREPORT]
39-11
39.7.9
Processor Extended States and ENCLU[EGETKEY]
39-11
39.8
INTERACTIONS WITH SMM
39-11
39.8.1
Availability of Intel® SGX instructions in SMM
39-11
39.8.2
SMI while Inside an Enclave
39-11
39.8.3
SMRAM Synthetic State of AEX Triggered by SMI
39-11
39.9
INTERACTIONS OF INIT, SIPI, AND WAIT-FOR-SIPI WITH INTEL® SGX
39-12
39.10
INTERACTIONS WITH DMA
39-12
39.11
INTERACTIONS WITH TXT
39-12
39.11.1
Enclaves Created Prior to Execution of GETSEC
39-12
39.11.2
Interaction of GETSEC with Intel® SGX
39-12
39.11.3
Interactions with Authenticated Code Modules (ACMs)
39-13
39.12
INTERACTIONS WITH CACHING OF LINEAR-ADDRESS TRANSLATIONS
39-13
39.13
INTERACTIONS WITH INTEL® TRANSACTIONAL SYNCHRONIZATION EXTENSIONS (INTEL® TSX)
39-13
39.13.1
HLE and RTM Debug
39-14
39.14
INTEL® SGX INTERACTIONS WITH S STATES
39-14
39.15
INTEL® SGX INTERACTIONS WITH MACHINE CHECK ARCHITECTURE (MCA)
39-14
39.15.1
Interactions with MCA Events
39-14
39.15.2
Machine Check Enables (IA32_MCi_CTL)
39-14
39.15.3
CR4.MCE
39-14
39.16
INTEL® SGX INTERACTIONS WITH PROTECTED MODE VIRTUAL INTERRUPTS
39-15
39.17
INTEL SGX INTERACTION WITH PROTECTION KEYS
39-15
CHAPTER 40
ENCLAVE CODE DEBUG AND PROFILING
40.1
CONFIGURATION AND CONTROLS
40-1
40.1.1
Debug Enclave vs. Production Enclave
40-1
40.1.2
Tool-Chain Opt-in
40-1
40.1.3
Debugging an Enclave That Uses Asynchronous Enclave Exit Notify
40-1
40.2
SINGLE STEP DEBUG
40-1
40.2.1
Single Stepping ENCLS Instruction Leafs
40-1
40.2.2
Single Stepping ENCLU Instruction Leafs
40-2
40.2.3
Single-Stepping Enclave Entry with Opt-out Entry
40-2
40.2.3.1
Single Stepping without AEX
40-2
40.2.3.2
Single Step Preempted by AEX Due to Non-SMI Event
40-2
40.2.4
RFLAGS.TF Treatment on AEX
40-3
40.2.5
Restriction on Setting of TF after an Opt-Out Entry
40-3
40.2.6
Trampoline Code Considerations
40-3
40.3
CODE AND DATA BREAKPOINTS
40-3
40.3.1
Breakpoint Suppression
40-3
40.3.2
Reporting of Instruction Breakpoint on Next Instruction on a Debug Trap
40-4
40.3.3
RF Treatment on AEX
40-4
40.3.4
Breakpoint Matching in Intel® SGX Instruction Flows
40-4
40.4
CONSIDERATION OF THE INT1 AND INT3 INSTRUCTIONS
40-4
40.4.1
Behavior of INT1 and INT3 Inside an Enclave
40-4
40.4.2
Debugger Considerations
40-4
xxxiv Vol. 3A
CONTENTS
PAGE
40.4.3
VMM Considerations
40-5
40.5
BRANCH TRACING
40-5
40.5.1
BTF Treatment
40-5
40.5.2
LBR Treatment
40-5
40.5.2.1
LBR Stack on Opt-in Entry
40-5
40.5.2.2
LBR Stack on Opt-out Entry
40-6
40.5.2.3
Mispredict Bit, Record Type, and Filtering
40-7
40.6
INTERACTION WITH PERFORMANCE MONITORING
40-7
40.6.1
IA32_PERF_GLOBAL_STATUS Enhancement
40-7
40.6.2
Performance Monitoring with Opt-in Entry
40-7
40.6.3
Performance Monitoring with Opt-out Entry
40-8
40.6.4
Enclave Exit and Performance Monitoring
40-8
40.6.5
PEBS Record Generation on Intel® SGX Instructions
40-8
40.6.6
Exception-Handling on PEBS/BTS Loads/Stores after AEX
40-8
40.6.6.1
Other Interactions with Performance Monitoring
40-9
APPENDIX A
VMX CAPABILITY REPORTING FACILITY
A.1
BASIC VMX INFORMATION
A-1
A.2
RESERVED CONTROLS AND DEFAULT SETTINGS
A-2
A.3
VM-EXECUTION CONTROLS
A-2
A.3.1
Pin-Based VM-Execution Controls
A-2
A.3.2
Primary Processor-Based VM-Execution Controls
A-3
A.3.3
Secondary Processor-Based VM-Execution Controls
A-4
A.3.4
Tertiary Processor-Based VM-Execution Controls
A-4
A.4
VM-EXIT CONTROLS
A-4
A.4.1
Primary VM-Exit Controls
A-4
A.4.2
Secondary VM-Exit Controls
A-5
A.5
VM-ENTRY CONTROLS
A-5
A.6
MISCELLANEOUS DATA
A-6
A.7
VMX-FIXED BITS IN CR0
A-7
A.8
VMX-FIXED BITS IN CR4
A-7
A.9
VMCS ENUMERATION
A-7
A.10
VPID AND EPT CAPABILITIES
A-8
A.11
VM FUNCTIONS
A-9
APPENDIX B
FIELD ENCODING IN VMCS
B.1
16-BIT FIELDS
B-1
B.1.1
16-Bit Control Fields
B-1
B.1.2
16-Bit Guest-State Fields
B-1
B.1.3
16-Bit Host-State Fields
B-2
B.2
64-BIT FIELDS
B-2
B.2.1
64-Bit Control Fields
B-2
B.2.2
64-Bit Read-Only Data Field
B-5
B.2.3
64-Bit Guest-State Fields
B-5
B.2.4
64-Bit Host-State Fields
B-6
B.3
32-BIT FIELDS
B-7
B.3.1
32-Bit Control Fields
B-7
B.3.2
32-Bit Read-Only Data Fields
B-8
B.3.3
32-Bit Guest-State Fields
B-8
B.3.4
32-Bit Host-State Field
B-9
B.4
NATURAL-WIDTH FIELDS
B-9
B.4.1
Natural-Width Control Fields
B-9
B.4.2
Natural-Width Read-Only Data Fields
B-10
B.4.3
Natural-Width Guest-State Fields
B-10
B.4.4
Natural-Width Host-State Fields
B-11
APPENDIX C
VMX BASIC EXIT REASONS
Vol. 3A xxxv
CONTENTS
PAGE
FIGURES
Figure 1-1.
Bit and Byte Order
1-8
Figure 1-2.
Syntax for CPUID, CR, and MSR Data Presentation
1-9
Figure 2-1.
IA-32 System-Level Registers and Data Structures
2-2
Figure 2-2.
System-Level Registers and Data Structures in IA-32e Mode and 4-Level Paging
2-3
Figure 2-3.
Transitions Among the Processor’s Operating Modes
2-8
Figure 2-4.
IA32_EFER MSR Layout
2-9
Figure 2-5.
System Flags in the EFLAGS Register
2-10
Figure 2-6.
Memory Management Registers
2-12
Figure 2-7.
Control Registers
2-14
Figure 2-8.
XCR0
2-21
Figure 2-9.
Format of Protection-Key Rights Registers
2-22
Figure 2-10.
WBINVD Invalidation of Shared and Non-Shared Cache Hierarchy
2-26
Figure 3-1.
Segmentation and Paging
3-2
Figure 3-2.
Flat Model
3-3
Figure 3-3.
Protected Flat Model
3-4
Figure 3-4.
Multi-Segment Model
3-5
Figure 3-5.
Logical Address to Linear Address Translation
3-7
Figure 3-6.
Segment Selector
3-7
Figure 3-7.
Segment Registers
3-8
Figure 3-8.
Segment Descriptor
3-10
Figure 3-9.
Segment Descriptor When Segment-Present Flag Is Clear
3-11
Figure 3-10.
Global and Local Descriptor Tables
3-15
Figure 3-11.
Pseudo-Descriptor Formats
3-16
Figure 4-1.
Enabling and Changing Paging Modes
4-4
Figure 4-2.
Linear-Address Translation to a 4-KByte Page using 32-Bit Paging
4-10
Figure 4-4.
Formats of CR3 and Paging-Structure Entries with 32-Bit Paging
4-11
Figure 4-3.
Linear-Address Translation to a 4-MByte Page using 32-Bit Paging
4-11
Figure 4-5.
Linear-Address Translation to a 4-KByte Page using PAE Paging
4-16
Figure 4-6.
Linear-Address Translation to a 2-MByte Page using PAE Paging
4-17
Figure 4-7.
Formats of CR3 and Paging-Structure Entries with PAE Paging
4-19
Figure 4-8.
Linear-Address Translation to a 4-KByte Page Using 4-Level Paging
4-22
Figure 4-9.
Linear-Address Translation to a 2-MByte Page using 4-Level Paging
4-23
Figure 4-10.
Linear-Address Translation to a 1-GByte Page using 4-Level Paging
4-23
Figure 4-11.
Formats of CR3 and Paging-Structure Entries with 4-Level Paging and 5-Level Paging
4-32
Figure 4-12.
Page-Fault Error Code
4-37
Figure 4-13.
Memory Management Convention That Assigns a Page Table to Each Segment
4-55
Figure 5-1.
Descriptor Fields Used for Protection
5-3
Figure 5-2.
Descriptor Fields with Flags used in IA-32e Mode
5-4
Figure 5-3.
Protection Rings
5-7
Figure 5-4.
Privilege Check for Data Access
5-8
Figure 5-5.
Examples of Accessing Data Segments From Various Privilege Levels
5-9
Figure 5-6.
Privilege Check for Control Transfer Without Using a Gate
5-11
Figure 5-7.
Examples of Accessing Conforming and Nonconforming Code Segments From Various Privilege Levels
5-12
Figure 5-8.
Call-Gate Descriptor
5-13
Figure 5-9.
Call-Gate Descriptor in IA-32e Mode
5-14
Figure 5-10.
Call-Gate Mechanism
5-15
Figure 5-11.
Privilege Check for Control Transfer with Call Gate
5-16
Figure 5-12.
Example of Accessing Call Gates At Various Privilege Levels
5-17
Figure 5-13.
Stack Switching During an Interprivilege-Level Call
5-19
Figure 5-14.
MSRs Used by SYSCALL and SYSRET
5-23
Figure 5-15.
Use of RPL to Weaken Privilege Level of Called Procedure
5-26
Figure 6-1.
Relationship of the IDTR and IDT
6-10
Figure 6-2.
IDT Gate Descriptors
6-11
Figure 6-3.
Interrupt Procedure Call
6-12
Figure 6-4.
Stack Usage on Transfers to Interrupt and Exception-Handling Routines
6-13
Figure 6-5.
Shadow Stack Usage on Transfers to Interrupt and Exception-Handling Routines
6-15
Figure 6-6.
Interrupt Task Switch
6-18
Figure 6-7.
Error Code
6-19
Figure 6-8.
64-Bit IDT Gate Descriptors
6-20
Figure 6-9.
IA-32e Mode Stack Usage After Privilege Level Change
6-22
Figure 6-10.
Interrupt Shadow Stack Table
6-23
Figure 6-11.
Page-Fault Error Code
6-46
xxxvi Vol. 3A
CONTENTS
PAGE
Figure 6-12.
Exception Error Code Information
6-56
Figure 8-1.
Structure of a Task
8-2
Figure 8-2.
32-Bit Task-State Segment (TSS)
8-4
Figure 8-3.
TSS Descriptor
8-6
Figure 8-4.
Format of TSS and LDT Descriptors in 64-bit Mode
8-7
Figure 8-5.
Task Register
8-8
Figure 8-6.
Task-Gate Descriptor
8-8
Figure 8-7.
Task Gates Referencing the Same Task
8-9
Figure 8-8.
Nested Tasks
8-15
Figure 8-9.
Overlapping Linear-to-Physical Mappings
8-17
Figure 8-10.
16-Bit TSS Format
8-19
Figure 8-11.
64-Bit TSS Format
8-20
Figure 9-1.
Example of Write Ordering in Multiple-Processor Systems
9-8
Figure 9-2.
Interpretation of APIC ID in Early MP Systems
9-25
Figure 9-3.
Local APICs and I/O APIC in MP System Supporting Intel HT Technology
9-27
Figure 9-4.
IA-32 Processor with Two Logical Processors Supporting Intel HT Technology
9-28
Figure 9-5.
Generalized Seven-Domain Interpretation of the APIC ID
9-35
Figure 9-6.
Conceptual Six-Domain Topology and 32-bit APIC ID Composition
9-36
Figure 9-7.
Topological Relationships Between Hierarchical IDs in a Hypothetical MP Platform
9-39
Figure 9-8.
MP System With Multiple Pentium III Processors
9-56
Figure 10-1.
Contents of CR0 Register after Reset
10-2
Figure 10-2.
Version Information in the EDX Register after Reset
10-5
Figure 10-3.
Processor State After Reset
10-15
Figure 10-4.
Constructing Temporary GDT and Switching to Protected Mode (Lines 162-172 of List File)
10-23
Figure 10-5.
Moving the GDT, IDT, and TSS from ROM to RAM (Lines 196-261 of List File)
10-24
Figure 10-6.
Task Switching (Lines 282-296 of List File)
10-25
Figure 10-7.
Applying Microcode Updates
10-28
Figure 10-8.
Microcode Update Write Operation Flow [1]
10-45
Figure 10-9.
Microcode Update Write Operation Flow [2]
10-46
Figure 11-1.
Relationship of Local APIC and I/O APIC In Single-Processor Systems
11-2
Figure 11-2.
Local APICs and I/O APIC When Intel Xeon Processors Are Used in Multiple-Processor Systems
11-3
Figure 11-3.
Local APICs and I/O APIC When P6 Family Processors Are Used in Multiple-Processor Systems
11-3
Figure 11-4.
Local APIC Structure
11-5
Figure 11-5.
IA32_APIC_BASE MSR (APIC_BASE_MSR in P6 Family)
11-9
Figure 11-6.
Local APIC ID Register
11-9
Figure 11-7.
Local APIC Version Register
11-11
Figure 11-8.
Local Vector Table (LVT)
11-13
Figure 11-9.
Error Status Register (ESR)
11-15
Figure 11-10.
Divide Configuration Register
11-17
Figure 11-11.
Initial Count and Current Count Registers
11-17
Figure 11-12.
Interrupt Command Register (ICR)
11-19
Figure 11-13.
Logical Destination Register (LDR)
11-24
Figure 11-14.
Destination Format Register (DFR)
11-24
Figure 11-15.
Arbitration Priority Register (APR)
11-25
Figure 11-16.
Interrupt Acceptance Flow Chart for the Local APIC (Pentium 4 and Intel Xeon Processors)
11-27
Figure 11-17.
Interrupt Acceptance Flow Chart for the Local APIC (P6 Family and Pentium Processors)
11-28
Figure 11-18.
Task-Priority Register (TPR)
11-29
Figure 11-19.
Processor-Priority Register (PPR)
11-29
Figure 11-20.
IRR, ISR, and TMR Registers
11-30
Figure 11-21.
EOI Register
11-31
Figure 11-22.
CR8 Register
11-32
Figure 11-23.
Spurious-Interrupt Vector Register (SVR)
11-33
Figure 11-24.
Layout of the MSI Message Address Register
11-34
Figure 11-25.
Layout of the MSI Message Data Register
11-36
Figure 11-26.
IA32_APIC_BASE MSR Supporting x2APIC
11-37
Figure 11-27.
Local x2APIC State Transitions with IA32_APIC_BASE, INIT, and Reset
11-42
Figure 11-28.
Interrupt Command Register (ICR) in x2APIC Mode
11-45
Figure 11-29.
Logical Destination Register in x2APIC Mode
11-46
Figure 11-30.
SELF IPI register
11-47
Figure 12-1.
Cache Structure of the Pentium 4 and Intel Xeon Processors
12-1
Figure 12-2.
Cache Structure of the Intel Core i7 Processors
12-2
Figure 12-3.
Cache-Control Registers and Bits Available in Intel 64 and IA-32 Processors
12-11
Figure 12-4.
Mapping Physical Memory With MTRRs
12-21
Figure 12-5.
IA32_MTRRCAP Register
12-22
Figure 12-6.
IA32_MTRR_DEF_TYPE MSR
12-23
Vol. 3A xxxvii
CONTENTS
PAGE
Figure 12-7.
IA32_MTRR_PHYSBASEn and IA32_MTRR_PHYSMASKn Variable-Range Register Pair
12-25
Figure 12-8.
IA32_SMRR_PHYSBASE and IA32_SMRR_PHYSMASK SMRR Pair
12-26
Figure 12-9.
IA32_PAT MSR
12-34
Figure 13-1.
Mapping of MMX Registers to Floating-Point Registers
13-2
Figure 13-2.
Mapping of MMX Registers to x87 FPU Data Register Stack
13-5
Figure 15-1.
IA32_MPERF MSR and IA32_APERF MSR for P-state Coordination
15-2
Figure 15-2.
IA32_PERF_CTL Register
15-4
Figure 15-3.
IA32_ENERGY_PERF_BIAS Register
15-5
Figure 15-4.
IA32_PM_ENABLE MSR
15-7
Figure 15-5.
IA32_HWP_CAPABILITIES Register
15-8
Figure 15-6.
IA32_HWP_REQUEST Register
15-9
Figure 15-7.
IA32_HWP_REQUEST_PKG Register
15-11
Figure 15-8.
IA32_HWP_PECI_REQUEST_INFO MSR
15-11
Figure 15-9.
IA32_HWP_STATUS MSR
15-14
Figure 15-10.
IA32_THERM_STATUS Register With HWP Feedback
15-15
Figure 15-11.
MSR_PPERF MSR
15-15
Figure 15-12.
IA32_HWP_INTERRUPT MSR
15-16
Figure 15-13.
FAST_UNCORE_MSRS_CAPABILITY MSR
15-17
Figure 15-14.
FAST_UNCORE_MSRS_CTL MSR
15-18
Figure 15-15.
FAST_UNCORE_MSRS_STATUS MSR
15-18
Figure 15-16.
IA32_PKG_HDC_CTL MSR
15-21
Figure 15-17.
IA32_PM_CTL1 MSR
15-22
Figure 15-18.
IA32_THREAD_STALL MSR
15-22
Figure 15-19.
MSR_CORE_HDC_RESIDENCY MSR
15-23
Figure 15-20.
MSR_PKG_HDC_SHALLOW_RESIDENCY MSR
15-23
Figure 15-21.
MSR_PKG_HDC_DEEP_RESIDENCY MSR
15-24
Figure 15-22.
MSR_PKG_HDC_CONFIG MSR
15-24
Figure 15-23.
Example of Effective Frequency Reduction and Forced Idle Period of HDC
15-25
Figure 15-24.
Processor Modulation Through Stop-Clock Mechanism
15-36
Figure 15-25.
MSR_THERM2_CTL Register On Processors with CPUID Family/Model/Stepping Signature Encoded as 0x69n or
0x6Dn
15-38
Figure 15-26.
MSR_THERM2_CTL Register for Supporting TM2
15-38
Figure 15-27.
IA32_THERM_STATUS MSR
15-39
Figure 15-28.
IA32_THERM_INTERRUPT MSR
15-39
Figure 15-29.
IA32_CLOCK_MODULATION MSR
15-40
Figure 15-30.
IA32_CLOCK_MODULATION MSR with Clock Modulation Extension
15-41
Figure 15-31.
IA32_THERM_STATUS Register
15-42
Figure 15-32.
IA32_THERM_INTERRUPT Register
15-44
Figure 15-33.
IA32_PACKAGE_THERM_STATUS Register
15-45
Figure 15-34.
IA32_PACKAGE_THERM_INTERRUPT Register
15-47
Figure 15-35.
MSR_RAPL_POWER_UNIT Register
15-49
Figure 15-36.
MSR_PKG_POWER_LIMIT Register
15-50
Figure 15-37.
MSR_PKG_ENERGY_STATUS MSR
15-51
Figure 15-38.
MSR_PKG_POWER_INFO Register
15-51
Figure 15-39.
MSR_PKG_PERF_STATUS MSR
15-52
Figure 15-40.
MSR_PP0_POWER_LIMIT/MSR_PP1_POWER_LIMIT Register
15-52
Figure 15-41.
MSR_PP0_ENERGY_STATUS/MSR_PP1_ENERGY_STATUS MSR
15-53
Figure 15-42.
MSR_PP0_POLICY/MSR_PP1_POLICY Register
15-53
Figure 15-43.
MSR_PP0_PERF_STATUS MSR
15-54
Figure 15-44.
MSR_DRAM_POWER_LIMIT Register
15-54
Figure 15-45.
MSR_DRAM_ENERGY_STATUS MSR
15-55
Figure 15-46.
MSR_DRAM_POWER_INFO Register
15-55
Figure 15-47.
MSR_DRAM_PERF_STATUS MSR
15-55
Figure 16-1.
Machine-Check MSRs
16-2
Figure 16-2.
IA32_MCG_CAP Register
16-3
Figure 16-3.
IA32_MCG_STATUS Register
16-4
Figure 16-4.
IA32_MCG_EXT_CTL Register
16-5
Figure 16-5.
IA32_MCi_CTL Register
16-6
Figure 16-6.
IA32_MCi_STATUS Register
16-7
Figure 16-7.
IA32_MCi_ADDR MSR
16-9
Figure 16-8.
UCR Support in IA32_MCi_MISC Register
16-10
Figure 16-9.
IA32_MCi_CTL2 Register
16-11
Figure 16-10.
CMCI Behavior
16-14
Figure 18-1.
Debug Registers
18-3
Figure 18-2.
DR6/DR7 Layout on Processors Supporting Intel® 64 Architecture
18-8
xxxviii Vol. 3A
CONTENTS
PAGE
Figure 18-3.
IA32_DEBUGCTL MSR for Processors Based on Intel® Core™ Microarchitecture
18-13
Figure 18-4.
64-bit Address Layout of LBR MSR
18-18
Figure 18-5.
DS Save Area Example
18-21
Figure 18-6.
32-bit Branch Trace Record Format
18-22
Figure 18-7.
PEBS Record Format
18-22
Figure 18-8.
IA-32e Mode DS Save Area Example
18-23
Figure 18-9.
64-bit Branch Trace Record Format
18-23
Figure 18-10.
64-bit PEBS Record Format
18-24
Figure 18-11.
IA32_DEBUGCTL MSR for Processors Based on Nehalem Microarchitecture
18-30
Figure 18-12.
MSR_DEBUGCTLA MSR for Pentium 4 and Intel Xeon Processors
18-36
Figure 18-13.
LBR MSR Branch Record Layout for the Pentium 4 and Intel® Xeon® Processor Family
18-37
Figure 18-14.
IA32_DEBUGCTL MSR for Intel® Core™ Solo and Intel® Core™ Duo Processors
18-38
Figure 18-15.
LBR Branch Record Layout for the Intel® Core™ Solo and Intel® Core™ Duo Processor
18-39
Figure 18-16.
MSR_DEBUGCTLB MSR for Pentium M Processors
18-40
Figure 18-17.
LBR Branch Record Layout for the Pentium M Processor
18-40
Figure 18-18.
DEBUGCTLMSR Register (P6 Family Processors)
18-41
Figure 18-19.
Platform Shared Resource Monitoring Usage Flow
18-46
Figure 18-20.
CPUID.(EAX=0FH, ECX=0H) Monitoring Resource Type Enumeration
18-47
Figure 18-21.
L3 Cache Monitoring Capability Enumeration Data (CPUID.(EAX=0FH, ECX=1H) )
18-47
Figure 18-22.
L3 Cache Monitoring Capability Enumeration Event Type Bit Vector (CPUID.(EAX=0FH, ECX=1H) )
18-48
Figure 18-23.
IA32_PQR_ASSOC MSR
18-49
Figure 18-24.
IA32_QM_EVTSEL and IA32_QM_CTR MSRs
18-51
Figure 18-25.
Software Usage of Cache Monitoring Resources
18-51
Figure 18-26.
Cache Allocation Technology Enables Allocation of More Resources to High Priority Applications
18-53
Figure 18-27.
Examples of Cache Capacity Bitmasks
18-54
Figure 18-28.
Class of Service and Cache Capacity Bitmasks
18-55
Figure 18-29.
Code and Data Capacity Bitmasks of CDP
18-56
Figure 18-30.
Cache Allocation Technology Usage Flow
18-57
Figure 18-31.
CPUID.(EAX=10H, ECX=0H) Available Resource Type Identification
18-58
Figure 18-32.
L3 Cache Allocation Technology and CDP Enumeration
18-59
Figure 18-33.
L2 Cache Allocation Technology
18-60
Figure 18-34.
IA32_PQR_ASSOC, IA32_L3_MASK_n MSRs
18-61
Figure 18-35.
IA32_L2_MASK_n MSRs
18-61
Figure 18-36.
Layout of IA32_L3_QOS_CFG
18-62
Figure 18-37.
Layout of IA32_L2_QOS_CFG
18-63
Figure 18-38.
CPUID.(EAX=10H, ECX=3H) MBA Feature Details Identification
18-67
Figure 18-39.
IA32_L2_QoS_Ext_BW_Thrtl_n MSR Definition
18-68
Figure 18-40.
Layout of the IA32_L3_IO_QOS_CFG MSR for Enabling Non-CPU Agent Intel® RDT
18-70
Figure 20-1.
Layout of IA32_PERFEVTSELx MSRs
20-4
Figure 20-2.
Layout of IA32_FIXED_CTR_CTRL MSR
20-8
Figure 20-3.
Layout of IA32_PERF_GLOBAL_CTRL MSR
20-8
Figure 20-4.
Layout of IA32_PERF_GLOBAL_STATUS MSR
20-10
Figure 20-5.
Layout of IA32_PERF_GLOBAL_OVF_CTRL MSR
20-10
Figure 20-6.
Layout of IA32_PERFEVTSELx MSRs Supporting Architectural Performance Monitoring Version 3
20-11
Figure 20-7.
IA32_FIXED_CTR_CTRL MSR Supporting Architectural Performance Monitoring Version 3
20-11
Figure 20-8.
Layout of Global Performance Monitoring Control MSR
20-12
Figure 20-9.
Global Performance Monitoring Overflow Status and Control MSRs
20-12
Figure 20-10.
IA32_PERF_GLOBAL_STATUS MSR and Architectural Perfmon Version 4
20-14
Figure 20-11.
IA32_PERF_GLOBAL_STATUS_RESET MSR and Architectural Perfmon Version 4
20-15
Figure 20-12.
IA32_PERF_GLOBAL_STATUS_SET MSR and Architectural Perfmon Version 4
20-15
Figure 20-13.
IA32_PERF_GLOBAL_INUSE MSR and Architectural Perfmon Version 4
20-16
Figure 20-14.
IA32_PERF_GLOBAL_STATUS MSR
20-18
Figure 20-15.
Layout of IA32_PEBS_ENABLE MSR
20-19
Figure 20-16.
PEBS Programming Environment
20-21
Figure 20-17.
Layout of MSR_PEBS_LD_LAT MSR
20-24
Figure 20-18.
Layout of MSR_OFFCORE_RSP_0 and MSR_OFFCORE_RSP_1 to Configure Off-core Response Events
20-25
Figure 20-19.
Layout of MSR_UNCORE_PERF_GLOBAL_CTRL MSR
20-27
Figure 20-20.
Layout of MSR_UNCORE_PERF_GLOBAL_STATUS MSR
20-28
Figure 20-21.
Layout of MSR_UNCORE_PERF_GLOBAL_OVF_CTRL MSR
20-28
Figure 20-22.
Layout of MSR_UNCORE_PERFEVTSELx MSRs
20-29
Figure 20-23.
Layout of MSR_UNCORE_FIXED_CTR_CTRL MSR
20-29
Figure 20-24.
Layout of MSR_UNCORE_ADDR_OPCODE_MATCH MSR
20-30
Figure 20-25.
Distributed Units of the Uncore of Intel® Xeon® Processor 7500 Series
20-31
Figure 20-26.
IA32_PERF_GLOBAL_CTRL MSR in Sandy Bridge Microarchitecture
20-34
Figure 20-27.
IA32_PERF_GLOBAL_STATUS MSR in Sandy Bridge Microarchitecture
20-35
Vol. 3A xxxix
CONTENTS
PAGE
Figure 20-28.
IA32_PERF_GLOBAL_OVF_CTRL MSR in Sandy Bridge Microarchitecture
20-36
Figure 20-29.
Layout of IA32_PEBS_ENABLE MSR
20-38
Figure 20-30.
Request_Type Fields for MSR_OFFCORE_RSP_x
20-42
Figure 20-31.
Response_Supplier and Snoop Info Fields for MSR_OFFCORE_RSP_x
20-43
Figure 20-32.
Layout of Uncore PERFEVTSEL MSR for a C-Box Unit or the ARB Unit
20-44
Figure 20-33.
Layout of MSR_UNC_PERF_GLOBAL_CTRL MSR for Uncore
20-45
Figure 20-34.
Layout of IA32_PERFEVTSELx MSRs Supporting Intel TSX
20-54
Figure 20-35.
IA32_PERF_GLOBAL_STATUS MSR in Broadwell Microarchitecture
20-56
Figure 20-36.
IA32_PERF_GLOBAL_OVF_CTRL MSR in Broadwell microarchitecture
20-56
Figure 20-37.
MSR_PERF_METRICS Definition
20-69
Figure 20-38.
PERF_METRICS MSR Definition for 12th Generation Intel® Core™ Processor P-core
20-71
Figure 20-39.
Deducing Implied Level 2 Metrics in the Core PMU for12th Generation Intel® Core™ Processor P-core
20-72
Figure 20-40.
Request_Type Fields for MSR_OFFCORE_RSPx
20-83
Figure 20-41.
Response_Supplier and Snoop Info Fields for MSR_OFFCORE_RSPx
20-84
Figure 20-42.
IA32_PEBS_ENABLE MSR with PEBS Output to Intel® Processor Trace
20-93
Figure 20-43.
Layout of IA32_FIXED_CTR_CTRL MSR
20-99
Figure 20-44.
Layout of MSR_PERF_GLOBAL_CTRL MSR
20-100
Figure 20-45.
Layout of MSR_PERF_GLOBAL_STATUS MSR
20-100
Figure 20-46.
Layout of MSR_PERF_GLOBAL_OVF_CTRL MSR
20-101
Figure 20-47.
Event Selection Control Register (ESCR) for Pentium 4 and Intel® Xeon® Processors without Intel HT Technology
Support
20-107
Figure 20-48.
Performance Counter (Pentium 4 and Intel® Xeon® Processors)
20-109
Figure 20-49.
Counter Configuration Control Register (CCCR)
20-110
Figure 20-50.
Effects of Edge Filtering
20-113
Figure 20-51.
Event Selection Control Register (ESCR) for the Pentium 4 Processor, Intel® Xeon® Processor, and Intel® Xeon®
Processor MP Supporting Hyper-Threading Technology
20-121
Figure 20-52.
Counter Configuration Control Register (CCCR)
20-122
Figure 20-53.
Block Diagram of 64-bit Intel® Xeon® Processor MP with 8-MByte L3
20-125
Figure 20-54.
MSR_IFSB_IBUSQx, Addresses: 107CCH and 107CDH
20-126
Figure 20-55.
MSR_IFSB_ISNPQx, Addresses: 107CEH and 107CFH
20-126
Figure 20-56.
MSR_EFSB_DRDYx, Addresses: 107D0H and 107D1H
20-127
Figure 20-57.
MSR_IFSB_CTL6, Address: 107D2H; MSR_IFSB_CNTR7, Address: 107D3H
20-127
Figure 20-58.
Block Diagram of the Intel® Xeon® Processor 7400 Series
20-128
Figure 20-59.
Block Diagram of the Intel® Xeon® Processor 7100 Series
20-129
Figure 20-60.
MSR_EMON_L3_CTR_CTL0/1, Addresses: 107CCH/107CDH
20-130
Figure 20-61.
MSR_EMON_L3_CTR_CTL2/3, Addresses: 107CEH/107CFH
20-132
Figure 20-62.
MSR_EMON_L3_CTR_CTL4/5/6/7, Addresses: 107D0H-107D3H
20-132
Figure 20-63.
PerfEvtSel0 and PerfEvtSel1 MSRs
20-134
Figure 20-64.
CESR MSR (Pentium Processor Only)
20-137
Figure 20-65.
Layout of IA32_PERF_CAPABILITIES MSR
20-142
Figure 20-66.
Layout of IA32_PEBS_ENABLE MSR
20-143
Figure 20-67.
PEBS Programming Environment
20-144
Figure 20-68.
Layout of IA32_PerfEvtSelX MSR Supporting Adaptive PEBS
20-145
Figure 20-69.
Layout of IA32_FIXED_CTR_CTRL MSR Supporting Adaptive PEBS
20-146
Figure 20-70.
MSR_PEBS_DATA_CFG
20-150
Figure 21-1.
Real-Address Mode Address Translation
21-3
Figure 21-2.
Interrupt Vector Table in Real-Address Mode
21-5
Figure 21-3.
Entering and Leaving Virtual-8086 Mode
21-9
Figure 21-4.
Privilege Level 0 Stack After Interrupt or Exception in Virtual-8086 Mode
21-13
Figure 21-5.
Software Interrupt Redirection Bit Map in TSS
21-18
Figure 22-1.
Stack after Far 16- and 32-Bit Calls
22-5
Figure 23-1.
I/O Map Base Address Differences
23-30
Figure 24-1.
Interaction of a Virtual-Machine Monitor and Guests
24-2
Figure 25-1.
States of VMCS X
25-2
Figure 29-1.
Formats of EPTP and EPT Paging-Structure Entries
29-13
Figure 31-1.
INVEPT Descriptor
31-3
Figure 31-2.
INVVPID Descriptor
31-6
Figure 32-1.
SMRAM Usage
32-4
Figure 32-2.
SMM Revision Identifier
32-13
Figure 32-3.
Auto HALT Restart Field
32-14
Figure 32-4.
SMBASE Relocation Field
32-15
Figure 32-5.
I/O Instruction Restart Field
32-15
Figure 33-1.
ToPA Memory Illustration
33-11
Figure 33-2.
Layout of ToPA Table Entry
33-12
Figure 33-3.
Interpreting Tabular Definition of Packet Format
33-38
xl Vol. 3A
|
||
|
|
|