diff options
| author | Marios Pomonis <pomonis@google.com> | 2025-01-13 01:58:24 -0800 |
|---|---|---|
| committer | Alexander Potapenko <glider@google.com> | 2025-01-14 13:47:06 +0000 |
| commit | 7315a7cf6c6eb74abe6888b820a131efaae8a0f4 (patch) | |
| tree | de67e4c585bbb1fb6180cbf1b019a32c58c242aa /sys/linux | |
| parent | f310a27df235861819a0d8fb1f440f62dcad373a (diff) | |
executor: arm64: add SYZOS_API_MRS
Add support for the MRS instruction in a similar manner to MSR.
Diffstat (limited to 'sys/linux')
| -rw-r--r-- | sys/linux/dev_kvm_arm64.txt | 5 | ||||
| -rw-r--r-- | sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-mrs | 25 | ||||
| -rw-r--r-- | sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-msr (renamed from sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu) | 0 | ||||
| -rw-r--r-- | sys/linux/test/arm64-syz_kvm_setup_syzos_vm-mrs | 17 |
4 files changed, 47 insertions, 0 deletions
diff --git a/sys/linux/dev_kvm_arm64.txt b/sys/linux/dev_kvm_arm64.txt index 686cf2575..aff892a5f 100644 --- a/sys/linux/dev_kvm_arm64.txt +++ b/sys/linux/dev_kvm_arm64.txt @@ -100,6 +100,10 @@ syzos_api_code { ret const[0xd65f03c0, int32] } [packed] +syzos_api_mrs { + arg_reg flags[kvm_regs_arm64_sys, int64] +} + syzos_api_msr { arg_reg flags[kvm_regs_arm64_sys, int64] arg_value int64 @@ -207,4 +211,5 @@ syzos_api_call [ memwrite syzos_api[6, syzos_api_memwrite] its_setup syzos_api[7, syzos_api_its_setup] its_send_cmd syzos_api[8, syzos_api_its_send_cmd] + mrs syzos_api[9, syzos_api_mrs] ] [varlen] diff --git a/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-mrs b/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-mrs new file mode 100644 index 000000000..d0bf5b073 --- /dev/null +++ b/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-mrs @@ -0,0 +1,25 @@ +# +# requires: arch=arm64 -threaded +# +r0 = openat$kvm(0, &AUTO='/dev/kvm\x00', 0x0, 0x0) +r1 = ioctl$KVM_CREATE_VM(r0, AUTO, 0x0) +r2 = syz_kvm_setup_syzos_vm(r1, &(0x7f0000c00000/0x400000)=nil) +# +# 0x603000000013df40 is PMEVCNTR0_EL0, write to it will trigger access_pmu_evcntr() in arch/arm64/kvm/sys_regs.c +# This is done to illustrate that PMU is accessible. +# 0x8 corresponds to the KVM_ARM_VCPU_PMU_V3 feature bit and is required to enable PMU. +# +r3 = syz_kvm_add_vcpu(r2, &AUTO={0x0, &AUTO=[@mrs={AUTO, AUTO, {0x603000000013df40}}], AUTO}, &AUTO=[@featur1={0x1, 0x8}], 0x1) +# +# Call ioctl(KVM_SET_DEVICE_ATTR) with group=KVM_ARM_VCPU_PMU_V3_CTRL and attr=KVM_ARM_VCPU_PMU_V3_INIT, +# as per https://www.kernel.org/doc/Documentation/virt/kvm/devices/vcpu.rst. +# +ioctl$KVM_SET_DEVICE_ATTR_vcpu(r3, AUTO, &AUTO=@attr_pmu_init) + +r4 = ioctl$KVM_GET_VCPU_MMAP_SIZE(r0, AUTO) +r5 = mmap$KVM_VCPU(&(0x7f0000009000/0x1000)=nil, r4, 0x3, 0x1, r3, 0x0) +# +# Run till the end of guest_main(). 0xffffffffffffffff is UEXIT_END. +# +ioctl$KVM_RUN(r3, AUTO, 0x0) +syz_kvm_assert_syzos_uexit(r5, 0xffffffffffffffff) diff --git a/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu b/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-msr index eee1ce9db..eee1ce9db 100644 --- a/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu +++ b/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-enable-pmu-msr diff --git a/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-mrs b/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-mrs new file mode 100644 index 000000000..d5a6c5bb6 --- /dev/null +++ b/sys/linux/test/arm64-syz_kvm_setup_syzos_vm-mrs @@ -0,0 +1,17 @@ +# +# requires: arch=arm64 -threaded +# +r0 = openat$kvm(0, &AUTO='/dev/kvm\x00', 0x0, 0x0) +r1 = ioctl$KVM_CREATE_VM(r0, AUTO, 0x0) +r2 = syz_kvm_setup_syzos_vm(r1, &(0x7f0000c00000/0x400000)=nil) +# +# 0x6030000000138010 is MDCCINT_EL1. +# +r3 = syz_kvm_add_vcpu(r2, &AUTO={0x0, &AUTO=[@mrs={AUTO, AUTO, {0x6030000000138010}}], AUTO}, 0x0, 0x0) +r4 = ioctl$KVM_GET_VCPU_MMAP_SIZE(r0, AUTO) +r5 = mmap$KVM_VCPU(&(0x7f0000009000/0x1000)=nil, r4, 0x3, 0x1, r3, 0x0) + +# Run till the end of guest_main(). 0xffffffffffffffff is UEXIT_END. +# +ioctl$KVM_RUN(r3, AUTO, 0x0) +syz_kvm_assert_syzos_uexit(r5, 0xffffffffffffffff) |
