Imported from wffx/binRev (
skills/recover-hypervisor-scheduler/SKILL.md). Install upstream withnpx skills add wffx/binRev --skill recover-hypervisor-scheduler. Copyright stays with the author.
Recover Hypervisor Scheduler
Purpose
Recover static scheduler structure and vCPU selection evidence. This Skill may directly read IDA through IDA MCP without asking for a separate connection confirmation. It must not mutate IDA.
Inputs
Require:
S05/runtime-object-model.jsonS05/types.jsonlS05/resource-ownership.jsonlS04/context-layouts.jsonlS04/architecture-events.jsonlS03/call-graph.json- accepted IDA checkpoint or IDA MCP session
Workflow
-
Enforce upstream gates.
- Require accepted S03-S05.
- If runtime ownership is not accepted, emit
blocked_by_upstream.
-
Find scheduling anchors.
- Track runqueue-like lists, current/next vCPU references, affinity masks, timer/IRQ wakeups, locks, and world-switch calls.
- Record state writes and comparisons before naming states.
-
Recover state transitions.
- Emit candidate
state_0xNvalues when names are unknown. - Distinguish runnable/block/preempt/wakeup candidates only with control-flow and data-write evidence.
- Emit candidate
-
Link to runtime objects.
- Bind scheduler actions to vCPU/CPU/context candidates from S05.
- Preserve ambiguous ownership as Unknown.
Outputs
Produce:
S06/scheduler-model.jsonS06/state-machines.jsonlS06/records/recover-hypervisor-scheduler.evidence.jsonlS06/records/recover-hypervisor-scheduler.decisions.jsonlS06/records/recover-hypervisor-scheduler.unknowns.jsonl
Boundaries
- Do not recover VM config or interrupt routing tables.
- Do not infer fairness or policy names without evidence.
- Do not modify S05 ownership.
- Do not apply IDA writes directly.
