All of lore.kernel.org
 help / color / mirror / Atom feed
From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: Fuad Tabba <fuad.tabba@linux.dev>, kvm@vger.kernel.org
Cc: kvmarm@lists.linux.dev, Will Deacon <will@kernel.org>,
	Julien Thierry <julien.thierry.kdev@gmail.com>,
	Alexandru Elisei <alexandru.elisei@arm.com>,
	Andre Przywara <andre.przywara@arm.com>,
	Oliver Upton <oliver.upton@linux.dev>,
	Marc Zyngier <maz@kernel.org>, Fuad Tabba <tabba@google.com>
Subject: Re: [PATCH kvmtool 2/5] kvm: Bound-check the exit-reason string lookup
Date: Sat, 12 Sep 2026 08:35:06 +0100	[thread overview]
Message-ID: <15c60e02-e40a-42d2-b1f4-c58de2124e32@arm.com> (raw)
In-Reply-To: <20260831192406.1341841-3-fuad.tabba@linux.dev>

On 31/08/2026 20:24, Fuad Tabba wrote:
> kvm_cpu_thread()'s panic path uses the kernel's exit_reason to index
> kvm_exit_reasons[] without checking it against the array's size. The
> table does not cover every exit reason KVM can return, so a reason past
> its last entry reads out of bounds. KVM_EXIT_SYSTEM_EVENT and
> KVM_EXIT_ARM_NISV are both past it.
> 
> Move the table behind kvm__exit_reason_str(), which checks the index
> first. The array now has a single caller inside kvm.c, so make it
> static const.
> 
> Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>

Reviewed-by: Suzuki K Poulose <suzuki.poulose@arm.com>

> ---
>   builtin-run.c     |  2 +-
>   include/kvm/kvm.h |  2 +-
>   kvm.c             | 10 +++++++++-
>   3 files changed, 11 insertions(+), 3 deletions(-)
> 
> diff --git a/builtin-run.c b/builtin-run.c
> index 81f255f..f36d3e2 100644
> --- a/builtin-run.c
> +++ b/builtin-run.c
> @@ -298,7 +298,7 @@ static void *kvm_cpu_thread(void *arg)
>   panic_kvm:
>   	pr_err("KVM exit reason: %u (\"%s\")",
>   		current_kvm_cpu->kvm_run->exit_reason,
> -		kvm_exit_reasons[current_kvm_cpu->kvm_run->exit_reason]);
> +		kvm__exit_reason_str(current_kvm_cpu->kvm_run->exit_reason));
>   
>   	if (current_kvm_cpu->kvm_run->exit_reason == KVM_EXIT_UNKNOWN) {
>   		pr_err("KVM exit code: %llu",
> diff --git a/include/kvm/kvm.h b/include/kvm/kvm.h
> index a9376b6..8619070 100644
> --- a/include/kvm/kvm.h
> +++ b/include/kvm/kvm.h
> @@ -255,7 +255,7 @@ int kvm__for_each_mem_bank(struct kvm *kvm, enum kvm_mem_type type,
>    */
>   void kvm__dump_mem(struct kvm *kvm, unsigned long addr, unsigned long size, int debug_fd);
>   
> -extern const char *kvm_exit_reasons[];
> +const char *kvm__exit_reason_str(__u32 exit_reason);
>   
>   static inline bool host_ptr_in_ram(struct kvm *kvm, void *p)
>   {
> diff --git a/kvm.c b/kvm.c
> index 96583f9..b416f6f 100644
> --- a/kvm.c
> +++ b/kvm.c
> @@ -33,7 +33,7 @@
>   
>   #define DEFINE_KVM_EXIT_REASON(reason) [reason] = #reason
>   
> -const char *kvm_exit_reasons[] = {
> +static const char * const kvm_exit_reasons[] = {
>   	DEFINE_KVM_EXIT_REASON(KVM_EXIT_UNKNOWN),
>   	DEFINE_KVM_EXIT_REASON(KVM_EXIT_EXCEPTION),
>   	DEFINE_KVM_EXIT_REASON(KVM_EXIT_IO),
> @@ -57,6 +57,14 @@ const char *kvm_exit_reasons[] = {
>   #endif
>   };
>   
> +const char *kvm__exit_reason_str(__u32 exit_reason)
> +{
> +	if (exit_reason >= ARRAY_SIZE(kvm_exit_reasons))
> +		return "UNKNOWN";
> +
> +	return kvm_exit_reasons[exit_reason];
> +}
> +
>   static int pause_event;
>   static DEFINE_MUTEX(pause_lock);
>   static struct kvm_cpu *pause_req_cpu;


  reply	other threads:[~2026-09-12  7:35 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 19:24 [PATCH kvmtool 0/5] Fix diagnostics and capability probes for protected VMs Fuad Tabba
2026-08-31 19:24 ` [PATCH kvmtool 1/5] arm64: Do not abort on register-dump failures Fuad Tabba
2026-09-12  7:33   ` Suzuki K Poulose
2026-09-12 13:54     ` Fuad Tabba
2026-09-12 14:02       ` Fuad Tabba
2026-09-12 19:36         ` Suzuki K Poulose
2026-08-31 19:24 ` [PATCH kvmtool 2/5] kvm: Bound-check the exit-reason string lookup Fuad Tabba
2026-09-12  7:35   ` Suzuki K Poulose [this message]
2026-08-31 19:24 ` [PATCH kvmtool 3/5] kvm: Name every exit reason the UAPI header defines Fuad Tabba
2026-09-12  7:35   ` Suzuki K Poulose
2026-08-31 19:24 ` [PATCH kvmtool 4/5] arm64: Query steal-time support on the VM fd Fuad Tabba
2026-09-12  7:28   ` Suzuki K Poulose
2026-08-31 19:24 ` [PATCH kvmtool 5/5] arm64: Query counter-offset " Fuad Tabba
2026-09-12  7:29   ` Suzuki K Poulose

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=15c60e02-e40a-42d2-b1f4-c58de2124e32@arm.com \
    --to=suzuki.poulose@arm.com \
    --cc=alexandru.elisei@arm.com \
    --cc=andre.przywara@arm.com \
    --cc=fuad.tabba@linux.dev \
    --cc=julien.thierry.kdev@gmail.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oliver.upton@linux.dev \
    --cc=tabba@google.com \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.