On 20.09.23 г. 20:23 ч., Li, Xin3 wrote:
+struct fred_ss {
+ u64 ss : 16, // SS selector
Is this structure conformant to the return state as described in FRED 5.0?
— The stack segment of the interrupted context, 64 bits formatted as follows:
• Bits 15:0 contain the SS selector. < - WE HAVE THIS
• Bits 31:16 are not currently defined and will be zero until they are.
Where did you download the FRED 5.0 spec from?
Mine says bit 16 is sti, bit 17 for sw initiated events and bit 18 is NMI.
I guess you have FRED 3.0 spec, no?
Doh you are right, I was looking at the wrong version of the document
.... sorry for the noise.
< - MISSING > hole?
+ sti : 1, // STI state < -
+ swevent : 1, // Set if syscall, sysenter or INT n
+ nmi : 1, // Event is NMI type
+ : 13,