From: Ian Campbell <ian.campbell@citrix.com>
To: Julien Grall <julien.grall@linaro.org>
Cc: xen-devel@lists.xen.org, tim@xen.org,
Jan Beulich <JBeulich@suse.com>,
stefano.stabellini@eu.citrix.com
Subject: Re: [PATCH v2 4/9] xen: arm: correctly handle vtimer traps from userspace
Date: Wed, 25 Feb 2015 14:32:33 +0000 [thread overview]
Message-ID: <1424874753.20243.128.camel@citrix.com> (raw)
In-Reply-To: <1424358801.30924.85.camel@citrix.com>
On Thu, 2015-02-19 at 15:13 +0000, Ian Campbell wrote:
> On Thu, 2015-02-19 at 14:42 +0000, Julien Grall wrote:
> > >> Although, I think the debug message in bad_trap is useful to keep. It
> > >> may be handy to have the HSR and the guest stack trace printed if Xen
> > >> hit the condition.
> > >
> > > Doesn't BUG_ON include all that? It should really.
> >
> > Not really BUG_ON will jump into the exception mode and therefore print
> > the HSR of the exception (breakpoint for ARM64 and undef for ARM32).
>
> Hrm, good point.
>
> Rather than reintroducing the goto idiom what about some form of
> noreturn panic helper for checking for sane h/w state (since these
> failures are really of the "buggy hardware" variety) e.g.
> ASSERT_GUEST_STATE(is_32bit_domain(...)) which would dump the guest
> state and then panic?
Here is the sort of thing I was thinking about (only converted one
BUG_ON so far as an example, there are more candidates).
Jan, would this be useful for x86 do you think, i.e. would you like me
to put it in lib.h with regular ASSERT? (Although making it more widely
available concerns me due to the pretty huge caveat in its use).
Should it be on for debug=n too? (In which case it might want to become
GUEST_BUG_ON or similar). The argument for doing so is that it would
reduce the impact of potential security issues arising from h/w bugs (or
spec misunderstandings), in which case I would add to the comment:
* The intention is to limit the damage such h/w bugs (or spec
* misunderstandings) can do by turning them into Denial of Service
* attacks instead of e.g. information leaks or privilege escalations.
It's possible that in some cases the DoS might be worse than the actual
issue, i.e. this might turn a fairly minor info leak into a DoS for
example. Making it debug=y only helps here with catching the issues, but
doesn't protect end users (who run debug=n), but doesn't have this risk
of the cure being worse than the disease.
Ian.
diff --git a/xen/arch/arm/traps.c b/xen/arch/arm/traps.c
index 8fec036..198e3b8 100644
--- a/xen/arch/arm/traps.c
+++ b/xen/arch/arm/traps.c
@@ -63,6 +63,30 @@ static inline void check_stack_alignment_constraints(void) {
#endif
}
+/*
+ * GASSERT is intended for checking that the guest state has not been
+ * corrupted in hardware and/or that the hardware behaves as we
+ * believe it should (i.e. that certain traps can only occur when the
+ * guest is in a particular mode).
+ *
+ * GASSERT *MUST* *NOT* be used to check for guest controllable state!
+ *
+ * Compared with regular ASSERT it dumps the guest vcpu state instead
+ * of Xen's state.
+ */
+#ifndef NDEBUG
+#define gassert_failed(p) \
+do { \
+ show_execution_state(guest_cpu_user_regs()); \
+ panic("%pv: Guest assertion '%s' failed, line %d, file %s\n", p , \
+ current,__LINE__, __FILE__); \
+} while (0)
+#define GASSERT(p) \
+ do { if ( unlikely(!(p)) ) gassert_failed(#p); } while (0)
+#else
+#define GASSERT(p) do { if ( 0 && (p) ); } while (0)
+#endif
+
#ifdef CONFIG_ARM_32
static int debug_stack_lines = 20;
#define stack_words_per_line 8
@@ -2166,7 +2194,7 @@ asmlinkage void do_trap_hypervisor(struct cpu_user_regs *regs)
do_trap_hypercall(regs, ®s->x16, hsr.iss);
break;
case HSR_EC_SMC64:
- BUG_ON(psr_mode_is_32bit(regs->cpsr));
+ GASSERT(!psr_mode_is_32bit(regs->cpsr));
perfc_incr(trap_smc64);
inject_undef64_exception(regs, hsr.len);
break;
next prev parent reply other threads:[~2015-02-25 14:32 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-02-10 4:35 [PATCH v2 0/9] xen: arm: reenable support for 32-bit userspace running in 64-bit guest Ian Campbell
2015-02-10 4:45 ` [PATCH v2 1/9] xen: arm: Correct PMXEV cp register definitions Ian Campbell
2015-02-10 4:45 ` [PATCH v2 2/9] xen: arm: Factor out psr_mode_is_user Ian Campbell
2015-02-10 4:45 ` [PATCH v2 3/9] xen: arm: Handle 32-bit EL0 on 64-bit EL1 when advancing PC after trap Ian Campbell
2015-02-10 5:44 ` Julien Grall
2015-02-10 6:20 ` Ian Campbell
2015-02-10 4:45 ` [PATCH v2 4/9] xen: arm: correctly handle vtimer traps from userspace Ian Campbell
2015-02-10 6:41 ` Julien Grall
2015-02-19 12:10 ` Ian Campbell
2015-02-19 14:42 ` Julien Grall
2015-02-19 15:13 ` Ian Campbell
2015-02-25 14:32 ` Ian Campbell [this message]
2015-02-25 14:37 ` Julien Grall
2015-02-10 4:45 ` [PATCH v2 5/9] xen: arm: Handle CP15 register " Ian Campbell
2015-02-17 15:07 ` Julien Grall
2015-02-19 12:15 ` Ian Campbell
2015-02-19 14:53 ` Julien Grall
2015-02-19 15:07 ` Ian Campbell
2015-02-10 4:45 ` [PATCH v2 6/9] xen: arm: Handle CP14 32-bit register accesses " Ian Campbell
2015-02-17 15:20 ` Julien Grall
2015-02-10 4:45 ` [PATCH v2 7/9] xen: arm: correctly handle sysreg " Ian Campbell
2015-02-17 15:25 ` Julien Grall
2015-02-19 12:23 ` Ian Campbell
2015-02-19 14:55 ` Julien Grall
2015-02-10 4:45 ` [PATCH v2 8/9] xen: arm: handle remaining traps " Ian Campbell
2015-02-17 15:28 ` Julien Grall
2015-02-19 12:25 ` Ian Campbell
2015-02-10 4:45 ` [PATCH v2 9/9] xen: arm: Allow traps from 32 bit userspace on 64 bit hypervisors again Ian Campbell
2015-02-17 15:29 ` Julien Grall
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1424874753.20243.128.camel@citrix.com \
--to=ian.campbell@citrix.com \
--cc=JBeulich@suse.com \
--cc=julien.grall@linaro.org \
--cc=stefano.stabellini@eu.citrix.com \
--cc=tim@xen.org \
--cc=xen-devel@lists.xen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.