diff options
| author | Alexander Potapenko <glider@google.com> | 2024-08-06 14:59:07 +0200 |
|---|---|---|
| committer | Alexander Potapenko <glider@google.com> | 2024-08-07 16:00:37 +0000 |
| commit | f89fe08c7227fc4fa4bc40ab8d0e1eacca6c20f0 (patch) | |
| tree | 34d74e658913731252b27f9eb1dc25063bd26d35 /sys/linux/dev_kvm.txt | |
| parent | 0020fc2034b4113f0e6c59ba408795e2b63d5e43 (diff) | |
executor: arm64: add SYZOS_API_SMC
Provide an API call to invoke the ARM64 Secure Monitor Call instruction
with user-supplied function id and 5 parameters passed in registers x1-x5.
For now only `smc #0` is invoked, although in the future we may want to
pass other (reserved) immediate values to SMC.
Diffstat (limited to 'sys/linux/dev_kvm.txt')
| -rw-r--r-- | sys/linux/dev_kvm.txt | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/sys/linux/dev_kvm.txt b/sys/linux/dev_kvm.txt index 2066b8d78..4b702ed29 100644 --- a/sys/linux/dev_kvm.txt +++ b/sys/linux/dev_kvm.txt @@ -268,10 +268,27 @@ syzos_api_msr { arg_value int64 } +# Based on the "SMC Calling Convention" doc, https://documentation-service.arm.com/static/5f8ea482f86e16515cdbe3c6 +# Bit 31 is Standard (0) / Fast Call (1) +# Bit 30 is SMC32 (0) / SMC64 (1) +# Bits 29:24 denote the owning entity (relevant constants below are 0x01000000-0x3f000000 +# Bits 23:16 are ignored (must be zero in most cases) +# Bits 15:0 denote the function number (0-0xffff) within the specified range, so we list all the possible bit values +# here and hope that the fuzzer will be able to combine them into a number. +kvm_smc_id = 0x80000000, 0x40000000, 0x1000000, 0x2000000, 0x3000000, 0x4000000, 0x30000000, 0x31000000, 0x32000000, 0x3f000000, 0x0, 0x1, 0x2, 0x4, 0x8, 0x10, 0x20, 0x40, 0x80, 0x100, 0x200, 0x400, 0x800, 0x1000, 0x2000, 0x4000, 0x8000, 0xffff + +syzos_api_smc { + call const[3, int64] + size bytesize[parent, int64] + arg_id flags[kvm_smc_id, int32] + arg_params array[int64, 5] +} + syzos_api_call [ uexit syzos_api_uexit code syzos_api_code msr syzos_api_msr + smc syzos_api_smc ] [varlen] kvm_text_ppc64 { |
