All of lore.kernel.org
 help / color / mirror / Atom feed
From: Christoffer Dall <cdall@linaro.org>
To: Suzuki K Poulose <suzuki.poulose@arm.com>
Cc: linux-arm-kernel@lists.infradead.org, kvm@vger.kernel.org,
	ard.biesheuvel@linaro.org, marc.zyngier@arm.com,
	andreyknvl@google.com, will.deacon@arm.com,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kcc@google.com, syzkaller@googlegroups.com, dvyukov@google.com,
	catalin.marinas@arm.com, pbonzini@redhat.com,
	kvmarm@lists.cs.columbia.edu
Subject: Re: [PATCH 2/3] kvm: arm/arm64: Take mmap_sem in kvm_arch_prepare_memory_region
Date: Wed, 15 Mar 2017 12:05:26 +0100	[thread overview]
Message-ID: <20170315110526.GC31974@cbox> (raw)
In-Reply-To: <1489503154-20705-3-git-send-email-suzuki.poulose@arm.com>

On Tue, Mar 14, 2017 at 02:52:33PM +0000, Suzuki K Poulose wrote:
> From: Marc Zyngier <marc.zyngier@arm.com>
> 
> We don't hold the mmap_sem while searching for VMAs (via find_vma), in
> kvm_arch_prepare_memory_region, which can end up in expected failures.
> 
> Fixes: commit 8eef91239e57 ("arm/arm64: KVM: map MMIO regions at creation time")
> Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org>
> Cc: Christoffer Dall <christoffer.dall@linaro.org>
> Cc: Eric Auger <eric.auger@rehat.com>
> Cc: stable@vger.kernel.org # v3.18+
> Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
> [ Handle dirty page logging failure case ]
> Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>

Reviewed-by: Christoffer Dall <cdall@linaro.org>

> ---
>  arch/arm/kvm/mmu.c | 11 ++++++++---
>  1 file changed, 8 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/arm/kvm/mmu.c b/arch/arm/kvm/mmu.c
> index f2e2e0c..13b9c1f 100644
> --- a/arch/arm/kvm/mmu.c
> +++ b/arch/arm/kvm/mmu.c
> @@ -1803,6 +1803,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	    (KVM_PHYS_SIZE >> PAGE_SHIFT))
>  		return -EFAULT;
>  
> +	down_read(&current->mm->mmap_sem);
>  	/*
>  	 * A memory region could potentially cover multiple VMAs, and any holes
>  	 * between them, so iterate over all of them to find out if we can map
> @@ -1846,8 +1847,10 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  			pa += vm_start - vma->vm_start;
>  
>  			/* IO region dirty page logging not allowed */
> -			if (memslot->flags & KVM_MEM_LOG_DIRTY_PAGES)
> -				return -EINVAL;
> +			if (memslot->flags & KVM_MEM_LOG_DIRTY_PAGES) {
> +				ret = -EINVAL;
> +				goto out;
> +			}
>  
>  			ret = kvm_phys_addr_ioremap(kvm, gpa, pa,
>  						    vm_end - vm_start,
> @@ -1859,7 +1862,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	} while (hva < reg_end);
>  
>  	if (change == KVM_MR_FLAGS_ONLY)
> -		return ret;
> +		goto out;
>  
>  	spin_lock(&kvm->mmu_lock);
>  	if (ret)
> @@ -1867,6 +1870,8 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	else
>  		stage2_flush_memslot(kvm, memslot);
>  	spin_unlock(&kvm->mmu_lock);
> +out:
> +	up_read(&current->mm->mmap_sem);
>  	return ret;
>  }
>  
> -- 
> 2.7.4
> 

WARNING: multiple messages have this Message-ID (diff)
From: cdall@linaro.org (Christoffer Dall)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH 2/3] kvm: arm/arm64: Take mmap_sem in kvm_arch_prepare_memory_region
Date: Wed, 15 Mar 2017 12:05:26 +0100	[thread overview]
Message-ID: <20170315110526.GC31974@cbox> (raw)
In-Reply-To: <1489503154-20705-3-git-send-email-suzuki.poulose@arm.com>

On Tue, Mar 14, 2017 at 02:52:33PM +0000, Suzuki K Poulose wrote:
> From: Marc Zyngier <marc.zyngier@arm.com>
> 
> We don't hold the mmap_sem while searching for VMAs (via find_vma), in
> kvm_arch_prepare_memory_region, which can end up in expected failures.
> 
> Fixes: commit 8eef91239e57 ("arm/arm64: KVM: map MMIO regions at creation time")
> Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org>
> Cc: Christoffer Dall <christoffer.dall@linaro.org>
> Cc: Eric Auger <eric.auger@rehat.com>
> Cc: stable at vger.kernel.org # v3.18+
> Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
> [ Handle dirty page logging failure case ]
> Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>

Reviewed-by: Christoffer Dall <cdall@linaro.org>

> ---
>  arch/arm/kvm/mmu.c | 11 ++++++++---
>  1 file changed, 8 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/arm/kvm/mmu.c b/arch/arm/kvm/mmu.c
> index f2e2e0c..13b9c1f 100644
> --- a/arch/arm/kvm/mmu.c
> +++ b/arch/arm/kvm/mmu.c
> @@ -1803,6 +1803,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	    (KVM_PHYS_SIZE >> PAGE_SHIFT))
>  		return -EFAULT;
>  
> +	down_read(&current->mm->mmap_sem);
>  	/*
>  	 * A memory region could potentially cover multiple VMAs, and any holes
>  	 * between them, so iterate over all of them to find out if we can map
> @@ -1846,8 +1847,10 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  			pa += vm_start - vma->vm_start;
>  
>  			/* IO region dirty page logging not allowed */
> -			if (memslot->flags & KVM_MEM_LOG_DIRTY_PAGES)
> -				return -EINVAL;
> +			if (memslot->flags & KVM_MEM_LOG_DIRTY_PAGES) {
> +				ret = -EINVAL;
> +				goto out;
> +			}
>  
>  			ret = kvm_phys_addr_ioremap(kvm, gpa, pa,
>  						    vm_end - vm_start,
> @@ -1859,7 +1862,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	} while (hva < reg_end);
>  
>  	if (change == KVM_MR_FLAGS_ONLY)
> -		return ret;
> +		goto out;
>  
>  	spin_lock(&kvm->mmu_lock);
>  	if (ret)
> @@ -1867,6 +1870,8 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	else
>  		stage2_flush_memslot(kvm, memslot);
>  	spin_unlock(&kvm->mmu_lock);
> +out:
> +	up_read(&current->mm->mmap_sem);
>  	return ret;
>  }
>  
> -- 
> 2.7.4
> 

WARNING: multiple messages have this Message-ID (diff)
From: Christoffer Dall <cdall@linaro.org>
To: Suzuki K Poulose <suzuki.poulose@arm.com>
Cc: linux-arm-kernel@lists.infradead.org, andreyknvl@google.com,
	dvyukov@google.com, marc.zyngier@arm.com,
	christoffer.dall@linaro.org, kvmarm@lists.cs.columbia.edu,
	kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
	kcc@google.com, syzkaller@googlegroups.com, will.deacon@arm.com,
	catalin.marinas@arm.com, pbonzini@redhat.com,
	mark.rutland@arm.com, ard.biesheuvel@linaro.org,
	stable@vger.kernel.org
Subject: Re: [PATCH 2/3] kvm: arm/arm64: Take mmap_sem in kvm_arch_prepare_memory_region
Date: Wed, 15 Mar 2017 12:05:26 +0100	[thread overview]
Message-ID: <20170315110526.GC31974@cbox> (raw)
In-Reply-To: <1489503154-20705-3-git-send-email-suzuki.poulose@arm.com>

On Tue, Mar 14, 2017 at 02:52:33PM +0000, Suzuki K Poulose wrote:
> From: Marc Zyngier <marc.zyngier@arm.com>
> 
> We don't hold the mmap_sem while searching for VMAs (via find_vma), in
> kvm_arch_prepare_memory_region, which can end up in expected failures.
> 
> Fixes: commit 8eef91239e57 ("arm/arm64: KVM: map MMIO regions at creation time")
> Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org>
> Cc: Christoffer Dall <christoffer.dall@linaro.org>
> Cc: Eric Auger <eric.auger@rehat.com>
> Cc: stable@vger.kernel.org # v3.18+
> Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
> [ Handle dirty page logging failure case ]
> Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>

Reviewed-by: Christoffer Dall <cdall@linaro.org>

> ---
>  arch/arm/kvm/mmu.c | 11 ++++++++---
>  1 file changed, 8 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/arm/kvm/mmu.c b/arch/arm/kvm/mmu.c
> index f2e2e0c..13b9c1f 100644
> --- a/arch/arm/kvm/mmu.c
> +++ b/arch/arm/kvm/mmu.c
> @@ -1803,6 +1803,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	    (KVM_PHYS_SIZE >> PAGE_SHIFT))
>  		return -EFAULT;
>  
> +	down_read(&current->mm->mmap_sem);
>  	/*
>  	 * A memory region could potentially cover multiple VMAs, and any holes
>  	 * between them, so iterate over all of them to find out if we can map
> @@ -1846,8 +1847,10 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  			pa += vm_start - vma->vm_start;
>  
>  			/* IO region dirty page logging not allowed */
> -			if (memslot->flags & KVM_MEM_LOG_DIRTY_PAGES)
> -				return -EINVAL;
> +			if (memslot->flags & KVM_MEM_LOG_DIRTY_PAGES) {
> +				ret = -EINVAL;
> +				goto out;
> +			}
>  
>  			ret = kvm_phys_addr_ioremap(kvm, gpa, pa,
>  						    vm_end - vm_start,
> @@ -1859,7 +1862,7 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	} while (hva < reg_end);
>  
>  	if (change == KVM_MR_FLAGS_ONLY)
> -		return ret;
> +		goto out;
>  
>  	spin_lock(&kvm->mmu_lock);
>  	if (ret)
> @@ -1867,6 +1870,8 @@ int kvm_arch_prepare_memory_region(struct kvm *kvm,
>  	else
>  		stage2_flush_memslot(kvm, memslot);
>  	spin_unlock(&kvm->mmu_lock);
> +out:
> +	up_read(&current->mm->mmap_sem);
>  	return ret;
>  }
>  
> -- 
> 2.7.4
> 

  reply	other threads:[~2017-03-15 11:04 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-03-14 14:52 [PATCH 0/3] kvm: arm/arm64: Fixes for use after free problems Suzuki K Poulose
2017-03-14 14:52 ` Suzuki K Poulose
2017-03-14 14:52 ` Suzuki K Poulose
2017-03-14 14:52 ` [PATCH 1/3] kvm: arm/arm64: Take mmap_sem in stage2_unmap_vm Suzuki K Poulose
2017-03-14 14:52   ` Suzuki K Poulose
2017-03-14 14:52   ` Suzuki K Poulose
2017-03-15  9:17   ` Christoffer Dall
2017-03-15  9:17     ` Christoffer Dall
2017-03-15  9:34     ` Marc Zyngier
2017-03-15  9:34       ` Marc Zyngier
2017-03-15 11:05       ` Christoffer Dall
2017-03-15 11:05         ` Christoffer Dall
2017-03-15 11:05         ` Christoffer Dall
2017-03-15 13:29     ` Paolo Bonzini
2017-03-15 13:29       ` Paolo Bonzini
2017-03-15 13:29       ` Paolo Bonzini
2017-03-14 14:52 ` [PATCH 2/3] kvm: arm/arm64: Take mmap_sem in kvm_arch_prepare_memory_region Suzuki K Poulose
2017-03-14 14:52   ` Suzuki K Poulose
2017-03-14 14:52   ` Suzuki K Poulose
2017-03-15 11:05   ` Christoffer Dall [this message]
2017-03-15 11:05     ` Christoffer Dall
2017-03-15 11:05     ` Christoffer Dall
2017-03-14 14:52 ` [PATCH 3/3] kvm: arm/arm64: Fix locking for kvm_free_stage2_pgd Suzuki K Poulose
2017-03-14 14:52   ` Suzuki K Poulose
2017-03-14 14:52   ` Suzuki K Poulose
2017-03-15  9:21   ` Christoffer Dall
2017-03-15  9:21     ` Christoffer Dall
2017-03-15  9:21     ` Christoffer Dall
2017-03-15  9:39     ` Marc Zyngier
2017-03-15  9:39       ` Marc Zyngier
2017-03-15 10:56       ` Christoffer Dall
2017-03-15 10:56         ` Christoffer Dall
2017-03-15 10:56         ` Christoffer Dall
2017-03-15 13:28         ` Marc Zyngier
2017-03-15 13:28           ` Marc Zyngier
2017-03-15 13:28           ` Marc Zyngier
2017-03-15 13:35           ` Christoffer Dall
2017-03-15 13:35             ` Christoffer Dall
2017-03-15 13:35             ` Christoffer Dall
2017-03-15 13:43             ` Marc Zyngier
2017-03-15 13:43               ` Marc Zyngier
2017-03-15 13:43               ` Marc Zyngier
2017-03-15 13:50               ` Robin Murphy
2017-03-15 13:50                 ` Robin Murphy
2017-03-15 13:50                 ` Robin Murphy
2017-03-15 13:55                 ` Marc Zyngier
2017-03-15 13:55                   ` Marc Zyngier
2017-03-15 13:55                   ` Marc Zyngier
2017-03-15 14:33           ` Suzuki K Poulose
2017-03-15 14:33             ` Suzuki K Poulose
2017-03-15 14:33             ` Suzuki K Poulose
2017-03-15 15:07             ` Marc Zyngier
2017-03-15 15:07               ` Marc Zyngier
2017-03-15 15:07               ` Marc Zyngier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170315110526.GC31974@cbox \
    --to=cdall@linaro.org \
    --cc=andreyknvl@google.com \
    --cc=ard.biesheuvel@linaro.org \
    --cc=catalin.marinas@arm.com \
    --cc=dvyukov@google.com \
    --cc=kcc@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.cs.columbia.edu \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=marc.zyngier@arm.com \
    --cc=pbonzini@redhat.com \
    --cc=stable@vger.kernel.org \
    --cc=suzuki.poulose@arm.com \
    --cc=syzkaller@googlegroups.com \
    --cc=will.deacon@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.