From adbde109f03932b9eee8106ce8bad4bc506d0713 Mon Sep 17 00:00:00 2001 From: Alexander Potapenko Date: Mon, 15 Sep 2025 16:23:10 +0200 Subject: sys/linux: executor: add IN_DX and OUT_DX to SYZOS x86 API Add SYZOS calls that correspond to the IN and OUT x86 instructions that perform port I/O. These instructions have different variants, for now we just implement the one that takes the port number from DX instead of encoding it in the opcode. --- sys/linux/dev_kvm_amd64.txt | 16 ++++++++++++++++ .../test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx | 19 +++++++++++++++++++ 2 files changed, 35 insertions(+) create mode 100644 sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx (limited to 'sys/linux') diff --git a/sys/linux/dev_kvm_amd64.txt b/sys/linux/dev_kvm_amd64.txt index 351f55827..41fb947cd 100644 --- a/sys/linux/dev_kvm_amd64.txt +++ b/sys/linux/dev_kvm_amd64.txt @@ -75,6 +75,20 @@ syzos_api_wr_drn { arg_value int64 } +x86_in_out_size = 1, 2, 4 + +syzos_api_in_dx { + arg_port int64[0:65535] + arg_size flags[x86_in_out_size, int64] +} + +# In fact the accepted value always fit into int32. +syzos_api_out_dx { + arg_port int64[0:65535] + arg_size flags[x86_in_out_size, int64] + arg_val int64 +} + syzos_api_call$x86 [ uexit syzos_api$x86[0, intptr] code syzos_api$x86[10, syzos_api_code$x86] @@ -83,6 +97,8 @@ syzos_api_call$x86 [ rdmsr syzos_api$x86[50, syzos_api_rdmsr] wr_crn syzos_api$x86[70, syzos_api_wr_crn] wr_drn syzos_api$x86[110, syzos_api_wr_drn] + in_dx syzos_api$x86[130, syzos_api_in_dx] + out_dx syzos_api$x86[170, syzos_api_out_dx] ] [varlen] kvm_text_x86 [ diff --git a/sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx b/sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx new file mode 100644 index 000000000..e6897f68a --- /dev/null +++ b/sys/linux/test/amd64-syz_kvm_setup_syzos_vm-in_dx-out_dx @@ -0,0 +1,19 @@ +# +# requires: arch=amd64 -threaded +# +r0 = openat$kvm(0, &AUTO='/dev/kvm\x00', 0x0, 0x0) +r1 = ioctl$KVM_CREATE_VM(r0, AUTO, 0x0) +r2 = syz_kvm_setup_syzos_vm$x86(r1, &(0x7f0000c00000/0x400000)=nil) + +# Writing to debug register DR3. +# +r3 = syz_kvm_add_vcpu$x86(r2, &AUTO={0x0, &AUTO=[@in_dx={AUTO, AUTO, {0x123, 0x2}}, @out_dx={AUTO, AUTO, {0x456, 0x4, 0xffffffff}}], AUTO}) +r4 = ioctl$KVM_GET_VCPU_MMAP_SIZE(r0, AUTO) +r5 = mmap$KVM_VCPU(&(0x7f0000009000/0x1000)=nil, r4, 0x3, 0x1, r3, 0x0) + +# Ensure that both IN and OUT exit with KVM_EXIT_IO. +# +ioctl$KVM_RUN(r3, AUTO, 0x0) +syz_kvm_assert_syzos_kvm_exit$x86(r5, 0x2) +ioctl$KVM_RUN(r3, AUTO, 0x0) +syz_kvm_assert_syzos_kvm_exit$x86(r5, 0x2) -- cgit mrf-deployment