From: Jan Beulich <jbeulich@suse.com>
To: Andrew Cooper <andrew.cooper3@citrix.com>
Cc: "Roger Pau Monné" <roger.pau@citrix.com>, "Wei Liu" <wl@xen.org>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Julien Grall" <julien@xen.org>,
"Volodymyr Babchuk" <Volodymyr_Babchuk@epam.com>,
"Bertrand Marquis" <bertrand.marquis@arm.com>,
"Henry Wang" <Henry.Wang@arm.com>,
"Anthony PERARD" <anthony.perard@citrix.com>,
Xen-devel <xen-devel@lists.xenproject.org>
Subject: Re: [PATCH 2/4] tools/tests: Unit test for paging mempool size
Date: Thu, 17 Nov 2022 11:39:58 +0100 [thread overview]
Message-ID: <3ede581f-3393-9290-b929-6c28450b007a@suse.com> (raw)
In-Reply-To: <20221117010804.9384-3-andrew.cooper3@citrix.com>
On 17.11.2022 02:08, Andrew Cooper wrote:
> Exercise some basic functionality of the new
> xc_{get,set}_paging_mempool_size() hypercalls.
>
> This passes on x86, but fails currently on ARM. ARM will be fixed up in
> future patches.
>
> This is part of XSA-409 / CVE-2022-33747.
>
> Signed-off-by: Andrew Cooper <andrew.cooper3@citrix.com>
> Release-acked-by: Henry Wang <Henry.Wang@arm.com>
Acked-by: Jan Beulich <jbeulich@suse.com>
(if this counts anything, since as it stands the new stuff all falls
under tool stack maintainership)
> --- /dev/null
> +++ b/tools/tests/paging-mempool/test-paging-mempool.c
> @@ -0,0 +1,181 @@
> +#include <err.h>
> +#include <errno.h>
> +#include <inttypes.h>
> +#include <stdio.h>
> +#include <string.h>
> +#include <sys/mman.h>
> +
> +#include <xenctrl.h>
> +#include <xenforeignmemory.h>
> +#include <xengnttab.h>
> +#include <xen-tools/libs.h>
> +
> +static unsigned int nr_failures;
> +#define fail(fmt, ...) \
> +({ \
> + nr_failures++; \
> + (void)printf(fmt, ##__VA_ARGS__); \
> +})
> +
> +static xc_interface *xch;
> +static uint32_t domid;
> +
> +static struct xen_domctl_createdomain create = {
> + .flags = XEN_DOMCTL_CDF_hvm | XEN_DOMCTL_CDF_hap,
I understand that it is accepted that this test will thus fail when run
on HAP-incapable hardware (including when run with Xen itself running on
top of another hypervisor not surfacing HAP capabilities)? Oh, I notice
you're actually translating EINVAL and EOPNOTSUPP failures into "skip".
That'll probably do, albeit personally I consider skipping when EINVAL
(which we use all over the place) as a overly relaxed.
> +static void run_tests(void)
> +{
> + xen_pfn_t physmap[] = { 0 };
I have to admit that I'm uncertain whether Arm (or other architectures
that Xen is being planned to be ported to) have constraints which may
cause populating of GFN 0 to fail.
> + uint64_t size_bytes, old_size_bytes;
> + int rc;
> +
> + printf("Test default mempool size\n");
> +
> + rc = xc_get_paging_mempool_size(xch, domid, &size_bytes);
> + if ( rc )
> + return fail(" Fail: get mempool size: %d - %s\n",
> + errno, strerror(errno));
> +
> + printf("mempool size %"PRIu64" bytes (%"PRIu64"kB, %"PRIu64"MB)\n",
> + size_bytes, size_bytes >> 10, size_bytes >> 20);
> +
> +
> + /*
> + * Check that the domain has the expected default allocation size. This
> + * will fail if the logic in Xen is altered without an equivelent
Nit: equivalent
> + * adjustment here.
> + */
> + if ( size_bytes != default_mempool_size_bytes )
> + return fail(" Fail: size %"PRIu64" != expected size %"PRIu64"\n",
> + size_bytes, default_mempool_size_bytes);
> +
> +
> + printf("Test that allocate doesn't alter pool size\n");
> +
> + /*
> + * Populate the domain with some RAM. This will cause more of the mempool
> + * to be used.
> + */
> + old_size_bytes = size_bytes;
> +
> + rc = xc_domain_setmaxmem(xch, domid, -1);
> + if ( rc )
> + return fail(" Fail: setmaxmem: : %d - %s\n",
> + errno, strerror(errno));
> +
> + rc = xc_domain_populate_physmap_exact(xch, domid, 1, 0, 0, physmap);
> + if ( rc )
> + return fail(" Fail: populate physmap: %d - %s\n",
> + errno, strerror(errno));
> +
> + /*
> + * Re-get the p2m size. Should not have changed as a consequence of
> + * populate physmap.
> + */
> + rc = xc_get_paging_mempool_size(xch, domid, &size_bytes);
> + if ( rc )
> + return fail(" Fail: get mempool size: %d - %s\n",
> + errno, strerror(errno));
> +
> + if ( old_size_bytes != size_bytes )
> + return fail(" Fail: mempool size changed %"PRIu64" => %"PRIu64"\n",
> + old_size_bytes, size_bytes);
> +
> +
> +
> + printf("Test bad set size\n");
> +
> + /*
> + * Check that setting a non-page size results in failure.
> + */
> + rc = xc_set_paging_mempool_size(xch, domid, size_bytes + 1);
> + if ( rc != -1 || errno != EINVAL )
> + return fail(" Fail: Bad set size: expected -1/EINVAL, got %d/%d - %s\n",
> + rc, errno, strerror(errno));
> +
> +
> + printf("Test very large set size\n");
Maybe drop "very", as 64M isn't all that much (and would, in particular,
not expose any 32-bit truncation issues)?
Jan
next prev parent reply other threads:[~2022-11-17 10:40 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-11-17 1:08 [PATCH for-4.17 0/4] XSA-409 fixes Andrew Cooper
2022-11-17 1:08 ` [PATCH 1/4] xen: Introduce non-broken hypercalls for the paging mempool size Andrew Cooper
2022-11-17 2:08 ` Stefano Stabellini
2022-11-17 10:18 ` Jan Beulich
2022-11-17 15:51 ` Andrew Cooper
2022-11-17 14:10 ` Anthony PERARD
2022-11-17 1:08 ` [PATCH 2/4] tools/tests: Unit test for " Andrew Cooper
2022-11-17 10:39 ` Jan Beulich [this message]
2022-11-17 16:27 ` Andrew Cooper
2022-11-17 14:20 ` Anthony PERARD
2022-11-17 1:08 ` [PATCH 3/4] xen/arm, libxl: Revert XEN_DOMCTL_shadow_op; use p2m mempool hypercalls Andrew Cooper
2022-11-17 2:12 ` Stefano Stabellini
2022-11-17 14:07 ` Anthony PERARD
2022-11-17 1:08 ` [PATCH 4/4] xen/arm: Correct the p2m pool size calculations Andrew Cooper
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3ede581f-3393-9290-b929-6c28450b007a@suse.com \
--to=jbeulich@suse.com \
--cc=Henry.Wang@arm.com \
--cc=Volodymyr_Babchuk@epam.com \
--cc=andrew.cooper3@citrix.com \
--cc=anthony.perard@citrix.com \
--cc=bertrand.marquis@arm.com \
--cc=julien@xen.org \
--cc=roger.pau@citrix.com \
--cc=sstabellini@kernel.org \
--cc=wl@xen.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.