From: Oleksandr Andrushchenko <andr2000@gmail.com>
To: xen-devel@lists.xenproject.org
Cc: julien@xen.org, sstabellini@kernel.org,
oleksandr_tyshchenko@epam.com, volodymyr_babchuk@epam.com,
Artem_Mygaiev@epam.com, roger.pau@citrix.com, jbeulich@suse.com,
andrew.cooper3@citrix.com, george.dunlap@citrix.com,
paul@xen.org, bertrand.marquis@arm.com, rahul.singh@arm.com,
Oleksandr Andrushchenko <oleksandr_andrushchenko@epam.com>
Subject: [PATCH v5 14/14] vpci: add TODO for the registers not explicitly handled
Date: Thu, 25 Nov 2021 13:02:51 +0200 [thread overview]
Message-ID: <20211125110251.2877218-15-andr2000@gmail.com> (raw)
In-Reply-To: <20211125110251.2877218-1-andr2000@gmail.com>
From: Oleksandr Andrushchenko <oleksandr_andrushchenko@epam.com>
For unprivileged guests vpci_{read|write} need to be re-worked
to not passthrough accesses to the registers not explicitly handled
by the corresponding vPCI handlers: without fixing that passthrough
to guests is completely unsafe as Xen allows them full access to
the registers.
Xen needs to be sure that every register a guest accesses is not
going to cause the system to malfunction, so Xen needs to keep a
list of the registers it is safe for a guest to access.
For example, we should only expose the PCI capabilities that we know
are safe for a guest to use, i.e.: MSI and MSI-X initially.
The rest of the capabilities should be blocked from guest access,
unless we audit them and declare safe for a guest to access.
As a reference we might want to look at the approach currently used
by QEMU in order to do PCI passthrough. A very limited set of PCI
capabilities known to be safe for untrusted access are exposed to the
guest and registers need to be explicitly handled or else access is
rejected. Xen needs a fairly similar model in vPCI or else none of
this will be safe for unprivileged access.
Add the corresponding TODO comment to highlight there is a problem that
needs to be fixed.
Suggested-by: Roger Pau Monné <roger.pau@citrix.com>
Suggested-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: Oleksandr Andrushchenko <oleksandr_andrushchenko@epam.com>
---
New in v5
---
xen/drivers/vpci/vpci.c | 23 +++++++++++++++++++++++
1 file changed, 23 insertions(+)
diff --git a/xen/drivers/vpci/vpci.c b/xen/drivers/vpci/vpci.c
index bdc8c63f73fa..4fb77d08825a 100644
--- a/xen/drivers/vpci/vpci.c
+++ b/xen/drivers/vpci/vpci.c
@@ -493,6 +493,29 @@ uint32_t vpci_read(pci_sbdf_t sbdf, unsigned int reg, unsigned int size)
if ( !pdev->vpci )
{
spin_unlock(&pdev->vpci_lock);
+ /*
+ * TODO: for unprivileged guests vpci_{read|write} need to be re-worked
+ * to not passthrough accesses to the registers not explicitly handled
+ * by the corresponding vPCI handlers: without fixing that passthrough
+ * to guests is completely unsafe as Xen allows them full access to
+ * the registers.
+ *
+ * Xen needs to be sure that every register a guest accesses is not
+ * going to cause the system to malfunction, so Xen needs to keep a
+ * list of the registers it is safe for a guest to access.
+ *
+ * For example, we should only expose the PCI capabilities that we know
+ * are safe for a guest to use, i.e.: MSI and MSI-X initially.
+ * The rest of the capabilities should be blocked from guest access,
+ * unless we audit them and declare safe for a guest to access.
+ *
+ * As a reference we might want to look at the approach currently used
+ * by QEMU in order to do PCI passthrough. A very limited set of PCI
+ * capabilities known to be safe for untrusted access are exposed to the
+ * guest and registers need to be explicitly handled or else access is
+ * rejected. Xen needs a fairly similar model in vPCI or else none of
+ * this will be safe for unprivileged access.
+ */
return vpci_read_hw(sbdf, reg, size);
}
--
2.25.1
next prev parent reply other threads:[~2021-11-25 11:03 UTC|newest]
Thread overview: 130+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-11-25 11:02 [PATCH v5 00/14] PCI devices passthrough on Arm, part 3 Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 01/14] rangeset: add RANGESETF_no_print flag Oleksandr Andrushchenko
2021-11-25 11:06 ` Jan Beulich
2021-11-25 11:08 ` Oleksandr Andrushchenko
2021-12-15 3:20 ` Volodymyr Babchuk
2021-12-15 5:53 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 02/14] vpci: fix function attributes for vpci_process_pending Oleksandr Andrushchenko
2021-12-10 17:55 ` Julien Grall
2021-12-11 8:20 ` Roger Pau Monné
2021-12-11 8:57 ` Oleksandr Andrushchenko
2022-01-26 8:31 ` Oleksandr Andrushchenko
2022-01-26 10:54 ` Jan Beulich
2021-11-25 11:02 ` [PATCH v5 03/14] vpci: move lock outside of struct vpci Oleksandr Andrushchenko
2022-01-11 15:17 ` Roger Pau Monné
2022-01-12 14:42 ` Jan Beulich
2022-01-26 8:40 ` Oleksandr Andrushchenko
2022-01-26 11:13 ` Roger Pau Monné
2022-01-31 7:41 ` Oleksandr Andrushchenko
2022-01-12 14:57 ` Jan Beulich
2022-01-12 15:42 ` Roger Pau Monné
2022-01-12 15:52 ` Jan Beulich
2022-01-13 8:58 ` Roger Pau Monné
2022-01-28 14:15 ` Oleksandr Andrushchenko
2022-01-31 8:56 ` Roger Pau Monné
2022-01-31 9:00 ` Oleksandr Andrushchenko
2022-01-28 14:12 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 04/14] vpci: cancel pending map/unmap on vpci removal Oleksandr Andrushchenko
2022-01-11 16:57 ` Roger Pau Monné
2022-01-12 15:27 ` Jan Beulich
2022-01-28 12:21 ` Oleksandr Andrushchenko
2022-01-31 7:53 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 05/14] vpci: add hooks for PCI device assign/de-assign Oleksandr Andrushchenko
2022-01-12 12:12 ` Roger Pau Monné
2022-01-31 8:43 ` Oleksandr Andrushchenko
2022-01-13 11:40 ` Roger Pau Monné
2022-01-31 8:45 ` Oleksandr Andrushchenko
2022-02-01 8:56 ` Oleksandr Andrushchenko
2022-02-01 10:23 ` Roger Pau Monné
2021-11-25 11:02 ` [PATCH v5 06/14] vpci/header: implement guest BAR register handlers Oleksandr Andrushchenko
2021-11-25 16:28 ` Bertrand Marquis
2021-11-26 12:19 ` Oleksandr Andrushchenko
2022-02-03 12:36 ` Oleksandr Andrushchenko
2022-02-03 12:44 ` Jan Beulich
2022-02-03 12:48 ` Oleksandr Andrushchenko
2022-02-03 12:50 ` Jan Beulich
2022-02-03 12:53 ` Oleksandr Andrushchenko
2022-01-12 12:35 ` Roger Pau Monné
2022-01-31 9:47 ` Oleksandr Andrushchenko
2022-01-31 10:40 ` Oleksandr Andrushchenko
2022-01-31 10:54 ` Jan Beulich
2022-01-31 11:04 ` Oleksandr Andrushchenko
2022-01-31 11:27 ` Roger Pau Monné
2022-01-31 11:30 ` Oleksandr Andrushchenko
2022-01-31 11:10 ` Roger Pau Monné
2022-01-31 11:23 ` Oleksandr Andrushchenko
2022-01-31 11:31 ` Roger Pau Monné
2022-01-31 11:39 ` Jan Beulich
2022-01-31 13:30 ` Oleksandr Andrushchenko
2022-01-31 13:36 ` Jan Beulich
2022-01-31 13:41 ` Oleksandr Andrushchenko
2022-01-31 13:51 ` Jan Beulich
2022-01-31 13:58 ` Oleksandr Andrushchenko
2022-01-31 11:04 ` Roger Pau Monné
2022-01-31 14:51 ` Oleksandr Andrushchenko
2022-01-31 15:06 ` Oleksandr Andrushchenko
2022-01-31 15:50 ` Jan Beulich
2022-02-01 7:31 ` Oleksandr Andrushchenko
2022-02-01 10:10 ` Roger Pau Monné
2022-02-01 10:41 ` Oleksandr Andrushchenko
2022-01-12 17:34 ` Roger Pau Monné
2022-01-31 9:53 ` Oleksandr Andrushchenko
2022-01-31 10:56 ` Roger Pau Monné
2022-02-03 12:45 ` Oleksandr Andrushchenko
2022-02-03 12:54 ` Jan Beulich
2022-02-03 13:30 ` Oleksandr Andrushchenko
2022-02-03 14:04 ` Jan Beulich
2022-02-03 14:19 ` Oleksandr Andrushchenko
2022-02-03 14:05 ` Roger Pau Monné
2022-02-03 14:26 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 07/14] vpci/header: handle p2m range sets per BAR Oleksandr Andrushchenko
2022-01-12 15:15 ` Roger Pau Monné
2022-01-12 15:18 ` Jan Beulich
2022-02-02 6:44 ` Oleksandr Andrushchenko
2022-02-02 9:56 ` Roger Pau Monné
2022-02-02 10:02 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 08/14] vpci/header: program p2m with guest BAR view Oleksandr Andrushchenko
2022-01-13 10:22 ` Roger Pau Monné
2022-02-02 8:23 ` Oleksandr Andrushchenko
2022-02-02 9:46 ` Oleksandr Andrushchenko
2022-02-02 10:34 ` Roger Pau Monné
2022-02-02 10:44 ` Oleksandr Andrushchenko
2022-02-02 11:11 ` Jan Beulich
2022-02-02 11:14 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 09/14] vpci/header: emulate PCI_COMMAND register for guests Oleksandr Andrushchenko
2022-01-13 10:50 ` Roger Pau Monné
2022-02-02 12:49 ` Oleksandr Andrushchenko
2022-02-02 13:32 ` Jan Beulich
2022-02-02 13:47 ` Oleksandr Andrushchenko
2022-02-02 14:18 ` Jan Beulich
2022-02-02 14:26 ` Oleksandr Andrushchenko
2022-02-02 14:31 ` Jan Beulich
2022-02-02 15:04 ` Oleksandr Andrushchenko
2022-02-02 15:08 ` Jan Beulich
2022-02-02 15:12 ` Oleksandr Andrushchenko
2022-02-02 15:31 ` Jan Beulich
2021-11-25 11:02 ` [PATCH v5 10/14] vpci/header: reset the command register when adding devices Oleksandr Andrushchenko
2022-01-13 11:07 ` Roger Pau Monné
2022-02-02 12:58 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 11/14] vpci: add initial support for virtual PCI bus topology Oleksandr Andrushchenko
2022-01-12 15:39 ` Jan Beulich
2022-02-02 13:15 ` Oleksandr Andrushchenko
2022-01-13 11:35 ` Roger Pau Monné
2022-02-02 13:17 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 12/14] xen/arm: translate virtual PCI bus topology for guests Oleksandr Andrushchenko
2022-01-13 12:18 ` Roger Pau Monné
2022-02-02 13:58 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` [PATCH v5 13/14] xen/arm: account IO handlers for emulated PCI MSI-X Oleksandr Andrushchenko
2022-01-13 13:23 ` Roger Pau Monné
2022-02-02 14:08 ` Oleksandr Andrushchenko
2021-11-25 11:02 ` Oleksandr Andrushchenko [this message]
2021-11-25 11:17 ` [PATCH v5 14/14] vpci: add TODO for the registers not explicitly handled Jan Beulich
2021-11-25 11:20 ` Oleksandr Andrushchenko
2022-01-13 13:27 ` Roger Pau Monné
2022-01-13 13:38 ` Jan Beulich
2022-01-28 13:03 ` Oleksandr Andrushchenko
2021-12-15 11:56 ` [PATCH v5 00/14] PCI devices passthrough on Arm, part 3 Oleksandr Andrushchenko
2021-12-15 12:07 ` Jan Beulich
2021-12-15 12:22 ` Oleksandr Andrushchenko
2021-12-15 14:51 ` Roger Pau Monné
2021-12-15 15:02 ` Oleksandr Andrushchenko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20211125110251.2877218-15-andr2000@gmail.com \
--to=andr2000@gmail.com \
--cc=Artem_Mygaiev@epam.com \
--cc=andrew.cooper3@citrix.com \
--cc=bertrand.marquis@arm.com \
--cc=george.dunlap@citrix.com \
--cc=jbeulich@suse.com \
--cc=julien@xen.org \
--cc=oleksandr_andrushchenko@epam.com \
--cc=oleksandr_tyshchenko@epam.com \
--cc=paul@xen.org \
--cc=rahul.singh@arm.com \
--cc=roger.pau@citrix.com \
--cc=sstabellini@kernel.org \
--cc=volodymyr_babchuk@epam.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.