code wiki / _hdl_build / _gpu_dxg_r4d_probe2.nx

_gpu_dxg_r4d_probe2.nx

buildroot/runtime/_hdl_build/_gpu_dxg_r4d_probe2.nx

5808 B87 linesdepth 2pulls 2 transitivereach 0 importersview sourcekind probetopic gpu
docsdependenciesstructsconstsfunctions

about

_gpu_dxg_r4d_probe2.nx -- SOVEREIGN-GPU ladder R4d PROBE pass 2: locate the allocation_info pointer. Probe-1 found alloc_count @44 (set @44=1 -> kernel reads the NULL allocation_info array -> -EFAULT(-14)). Now, with device@0 + alloc_count@44=1, point each 8-aligned u64 offset at a VALID readable buffer: the offset that makes the -14 EFAULT go AWAY (kernel successfully reads the d3dkmt_allocationinfo2 entry, then fails later with -EINVAL etc.) IS `allocation_info`. (@40 is skipped: a u64 there would clobber alloc_count@44.) raw syscalls only. No log writes. license_tier: ORIGINAL

dependencies 1 imports · 0 importers

nx_syscalls.nx _gpu_dxg_r4d_probe2.nx

imports: nx_syscalls.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main p sys_write sys_openat_rd sys_exit sys_mmap sys_ioctl rd32 query_type sys_mmap ↻ sys_ioctl ↻ rd32 ↻ open_from_luid sys_mmap ↻ sys_ioctl ↻ rd32 ↻ create_device sys_mmap ↻ sys_ioctl ↻ rd32 ↻ fire_ptr sys_mmap ↻ sys_ioctl ↻ n sys_mmap ↻ sys_write ↻ sys_close

structs

none

consts

10const ENUM2_CODE: i64 = 0xC0104714
11const QAI_CODE: i64 = 0xC0184709
12const OAFL_CODE: i64 = 0xC00C4701
13const CDEV_CODE: i64 = 0xC0404702
14const CALLOC_CODE: i64 = 0xC0484706

functions

16func p(s: *u8) -> i64 { var nn: i64=0; while s[nn]!=(0 as u8){nn=nn+1} sys_write(1,s,nn); return 0 }
called by 2: xmain calls 1: sys_write
17func n(v: i64) -> i64 { let bb: *u8=sys_mmap(28); var m: i64=v; if m<0{m=0-m;sys_write(1,"-" as *u8,1)}; let t: *u8=sys_mmap(28); var k: i64=0; if m==0{t[0]=48;k=1}; while m>0{t[k]=(48+(m%10)) as u8;m=m/10;k=k+1}; var i: i64=0; while i<k{bb[i]=t[k-1-i];i=i+1}; sys_write(1,bb,k); return 0 }
called by 1: main calls 2: sys_mmapsys_write
18func x(v: i64) -> i64 { p("0x" as *u8); let bb:*u8=sys_mmap(20); var k:i64=0; var m:i64=v; if m==0{bb[0]=48;k=1}; while m>0{ let d:i64=m&15; if d<10{bb[k]=(48+d) as u8}else{bb[k]=(87+d) as u8}; m=(m>>4); k=k+1 } var i:i64=0; let o:*u8=sys_mmap(20); while i<k{o[i]=bb[k-1-i];i=i+1} sys_write(1,o,k); return 0 }
19func rd32(buf: *u8, off: i64) -> i64 { return (buf[off] as i64)|((buf[off+1] as i64)<<8)|((buf[off+2] as i64)<<16)|((buf[off+3] as i64)<<24) }
21func query_type(fd: i64, handle: i64, qtype: i64, psize: i64, outv: *i64) -> i64
called by 1: main calls 3: sys_mmapsys_ioctlrd32
29func open_from_luid(fd: i64, luid_lo: i64, luid_hi: i64, outh: *i64) -> i64
called by 1: main calls 3: sys_mmapsys_ioctlrd32
34func create_device(fd: i64, adapter: i64, outd: *i64) -> i64
called by 1: main calls 3: sys_mmapsys_ioctlrd32
40func fire_ptr(fd: i64, device: i64, cnt: i64, ptroff: i64, ptrval: i64) -> i64
called by 1: main calls 2: sys_mmapsys_ioctl
49func main() -> i64