All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0 of 2] Fix correctness race in xc_mem_paging_prep
@ 2011-11-29 21:52 Andres Lagar-Cavilla
  2011-11-29 21:52 ` [PATCH 1 of 2] After preparing a page for page-in, allow immediate fill-in of the page contents Andres Lagar-Cavilla
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Andres Lagar-Cavilla @ 2011-11-29 21:52 UTC (permalink / raw)
  To: xen-devel
  Cc: ian.campbell, andres, tim, keir.xen, JBeulich, ian.jackson, adin

P2m_mem_paging_prep ensures that an mfn is backing the paged-out gfn, and
transitions to the next state in the paging state machine for this page. 
Foreign mappings of the gfn will now succeed. This is the key idea, as it 
allows the pager to now map the gfn and fill in its contents.

Unfortunately, it also allows any other foreign mapper to map the gfn and read
its contents. This is particularly dangerous when the populate is launched
by a foreign mapper in the first place, which will be actively retrying the
map operation and might race with the pager. Qemu-dm being a prime example.

Fix the race by allowing a buffer to be optionally passed in the prep
operation, and having the hypervisor memcpy from that buffer into the newly
prepped page before promoting the gfn type.

Second patch is a tools patch, cc'ed maintainers.

Signed-off-by: Andres Lagar-Cavilla <andres@lagarcavilla.org>

 xen/arch/x86/mm/mem_event.c  |   2 +-
 xen/arch/x86/mm/mem_paging.c |   2 +-
 xen/arch/x86/mm/p2m.c        |  52 +++++++++++++++++++++++++++++++++++++++++--
 xen/include/asm-x86/p2m.h    |   2 +-
 xen/include/public/domctl.h  |   8 +++++-
 tools/libxc/xc_mem_event.c   |   4 +-
 tools/libxc/xc_mem_paging.c  |  23 +++++++++++++++++++
 tools/libxc/xenctrl.h        |   2 +
 8 files changed, 85 insertions(+), 10 deletions(-)

^ permalink raw reply	[flat|nested] 11+ messages in thread
* [PATCH 0 of 2] Fix correctness race in xc_mem_paging_prep
@ 2011-11-29 20:32 Andres Lagar-Cavilla
  0 siblings, 0 replies; 11+ messages in thread
From: Andres Lagar-Cavilla @ 2011-11-29 20:32 UTC (permalink / raw)
  To: xen-devel
  Cc: ian.campbell, andres, tim, keir.xen, JBeulich, ian.jackson, adin

ging_prep ensures that an mfn is backing the paged-out gfn, and
transitions to the next state in the paging state machine for this page. 
Foreign mappings of the gfn will now succeed. This is the key idea, as it 
allows the pager to now map the gfn and fill in its contents.

Unfortunately, it also allows any other foreign mapper to map the gfn and read
its contents. This is particularly dangerous when the populate is launched
by a foreign mapper in the first place, which will be actively retrying the
map operation and might race with the pager. Qemu-dm being a prime example.

Fix the race by allowing a buffer to be optionally passed in the prep
operation, and having the hypervisor memcpy from that buffer into the newly
prepped page before promoting the gfn type.

Second patch is a tools patch, cc'ed maintainers.

Signed-off-by: Andres Lagar-Cavilla <andres@lagarcavilla.org>

 xen/arch/x86/mm/mem_event.c  |   2 +-
 xen/arch/x86/mm/mem_paging.c |   2 +-
 xen/arch/x86/mm/p2m.c        |  52 +++++++++++++++++++++++++++++++++++++++++--
 xen/include/asm-x86/p2m.h    |   2 +-
 xen/include/public/domctl.h  |   8 +++++-
 tools/libxc/xc_mem_event.c   |   4 +-
 tools/libxc/xc_mem_paging.c  |  23 +++++++++++++++++++
 tools/libxc/xenctrl.h        |   2 +
 8 files changed, 85 insertions(+), 10 deletions(-)

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2011-12-01 16:11 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-11-29 21:52 [PATCH 0 of 2] Fix correctness race in xc_mem_paging_prep Andres Lagar-Cavilla
2011-11-29 21:52 ` [PATCH 1 of 2] After preparing a page for page-in, allow immediate fill-in of the page contents Andres Lagar-Cavilla
2011-11-30 14:46   ` Ian Jackson
2011-11-30 15:13     ` Andres Lagar-Cavilla
2011-12-01 16:11       ` Ian Jackson
2011-12-01 15:53   ` Tim Deegan
2011-12-01 15:58     ` Andres Lagar-Cavilla
2011-11-29 21:52 ` [PATCH 2 of 2] Tools: Libxc wrappers to automatically fill in page oud page contents on prepare Andres Lagar-Cavilla
2011-11-30 13:21 ` [PATCH 0 of 2] Fix correctness race in xc_mem_paging_prep Olaf Hering
2011-12-01 12:43   ` Olaf Hering
  -- strict thread matches above, loose matches on Subject: below --
2011-11-29 20:32 Andres Lagar-Cavilla

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.