github.com/google/syzkaller@v0.0.0-20251211124644-a066d2bc4b02/sys/linux/test/arm64-syz_kvm_setup_syzos_vm (about)

     1  #
     2  # requires: arch=arm64 -threaded
     3  #
     4  r0 = openat$kvm(0, &AUTO='/dev/kvm\x00', 0x0, 0x0)
     5  r1 = ioctl$KVM_CREATE_VM(r0, AUTO, 0x0)
     6  r2 = syz_kvm_setup_syzos_vm$arm64(r1, &(0x7f0000c00000/0x400000)=nil)
     7  # Perform two uexits. The first one is done via a code blob:
     8  #       d2802000        mov     x0, #0x100                      // #256
     9  #       f2bbbba0        movk    x0, #0xdddd, lsl #16
    10  #       f900001f        str     xzr, [x0]
    11  # , which assumes registers x24-28 are zeroes.
    12  # The second uexit is done via a syzos API command that sets uexit exit code to 0xaaaa.
    13  #
    14  r3 = syz_kvm_add_vcpu$arm64(r2, &AUTO={0x0, &AUTO=[@code={AUTO, AUTO, {"002080d2a0bbbbf21f0000f9", 0xd65f03c0}}, @uexit={AUTO, AUTO, 0xaaaa}], AUTO}, 0x0, 0x0)
    15  
    16  r4 = ioctl$KVM_GET_VCPU_MMAP_SIZE(r0, AUTO)
    17  r5 = mmap$KVM_VCPU(&(0x7f0000009000/0x1000)=nil, r4, 0x3, 0x1, r3, 0x0)
    18  
    19  # Run till the first uexit.
    20  #
    21  ioctl$KVM_RUN(r3, AUTO, 0x0)
    22  syz_kvm_assert_syzos_uexit$arm64(r5, 0x0)
    23  # Run till the second uexit.
    24  #
    25  ioctl$KVM_RUN(r3, AUTO, 0x0)
    26  syz_kvm_assert_syzos_uexit$arm64(r5, 0xaaaa)
    27  # Run till the end of guest_main(). 0xffffffffffffffff is UEXIT_END.
    28  #
    29  ioctl$KVM_RUN(r3, AUTO, 0x0)
    30  syz_kvm_assert_syzos_uexit$arm64(r5, 0xffffffffffffffff)