aboutsummaryrefslogtreecommitdiffstats
path: root/sys/linux
diff options
context:
space:
mode:
authorAlexander Potapenko <glider@google.com>2025-09-15 16:23:10 +0200
committerAlexander Potapenko <glider@google.com>2025-09-19 08:38:14 +0000
commitadbde109f03932b9eee8106ce8bad4bc506d0713 (patch)
tree1ba09463fde777a99591884afea2ad12255e2cc6 /sys/linux
parentdd232cacbbd407c55bf26299264db0a2c3f0cfcf (diff)
sys/linux: executor: add IN_DX and OUT_DX to SYZOS x86 API
Add SYZOS calls that correspond to the IN and OUT x86 instructions that perform port I/O. These instructions have different variants, for now we just implement the one that takes the port number from DX instead of encoding it in the opcode.
Diffstat (limited to 'sys/linux')
-rw-r--r--sys/linux/dev_kvm_amd64.txt16
-rw-r--r--sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx19
2 files changed, 35 insertions, 0 deletions
diff --git a/sys/linux/dev_kvm_amd64.txt b/sys/linux/dev_kvm_amd64.txt
index 351f55827..41fb947cd 100644
--- a/sys/linux/dev_kvm_amd64.txt
+++ b/sys/linux/dev_kvm_amd64.txt
@@ -75,6 +75,20 @@ syzos_api_wr_drn {
arg_value int64
}
+x86_in_out_size = 1, 2, 4
+
+syzos_api_in_dx {
+ arg_port int64[0:65535]
+ arg_size flags[x86_in_out_size, int64]
+}
+
+# In fact the accepted value always fit into int32.
+syzos_api_out_dx {
+ arg_port int64[0:65535]
+ arg_size flags[x86_in_out_size, int64]
+ arg_val int64
+}
+
syzos_api_call$x86 [
uexit syzos_api$x86[0, intptr]
code syzos_api$x86[10, syzos_api_code$x86]
@@ -83,6 +97,8 @@ syzos_api_call$x86 [
rdmsr syzos_api$x86[50, syzos_api_rdmsr]
wr_crn syzos_api$x86[70, syzos_api_wr_crn]
wr_drn syzos_api$x86[110, syzos_api_wr_drn]
+ in_dx syzos_api$x86[130, syzos_api_in_dx]
+ out_dx syzos_api$x86[170, syzos_api_out_dx]
] [varlen]
kvm_text_x86 [
diff --git a/sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx b/sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx
new file mode 100644
index 000000000..e6897f68a
--- /dev/null
+++ b/sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx
@@ -0,0 +1,19 @@
+#
+# requires: arch=amd64 -threaded
+#
+r0 = openat$kvm(0, &AUTO='/dev/kvm\x00', 0x0, 0x0)
+r1 = ioctl$KVM_CREATE_VM(r0, AUTO, 0x0)
+r2 = syz_kvm_setup_syzos_vm$x86(r1, &(0x7f0000c00000/0x400000)=nil)
+
+# Writing to debug register DR3.
+#
+r3 = syz_kvm_add_vcpu$x86(r2, &AUTO={0x0, &AUTO=[@in_dx={AUTO, AUTO, {0x123, 0x2}}, @out_dx={AUTO, AUTO, {0x456, 0x4, 0xffffffff}}], AUTO})
+r4 = ioctl$KVM_GET_VCPU_MMAP_SIZE(r0, AUTO)
+r5 = mmap$KVM_VCPU(&(0x7f0000009000/0x1000)=nil, r4, 0x3, 0x1, r3, 0x0)
+
+# Ensure that both IN and OUT exit with KVM_EXIT_IO.
+#
+ioctl$KVM_RUN(r3, AUTO, 0x0)
+syz_kvm_assert_syzos_kvm_exit$x86(r5, 0x2)
+ioctl$KVM_RUN(r3, AUTO, 0x0)
+syz_kvm_assert_syzos_kvm_exit$x86(r5, 0x2)