From: eric.auger@linaro.org (Eric Auger)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH 4/5] arm/arm64: KVM: Don't allow creating VCPUs after vgic_initialized
Date: Wed, 10 Dec 2014 13:35:08 +0100 [thread overview]
Message-ID: <54883DFC.4060001@linaro.org> (raw)
In-Reply-To: <1418139844-27892-5-git-send-email-christoffer.dall@linaro.org>
On 12/09/2014 04:44 PM, Christoffer Dall wrote:
> When the vgic initializes its internal state it does so based on the
> number of VCPUs available at the time. If we allow KVM to create more
> VCPUs after the VGIC has been initialized, we are likely to error out in
> unfortunate ways later, perform buffer overflows etc.
>
> Cc: Eric Auger <eric.auger@linaro.org>
> Signed-off-by: Christoffer Dall <christoffer.dall@linaro.org>
> ---
> This replaces Eric Auger's previous patch
> (https://lists.cs.columbia.edu/pipermail/kvmarm/2014-December/012646.html),
> because it fits better with testing to include it in this series and I
> realized that we need to add a check against irqchip_in_kernel() as
> well.
>
> arch/arm/kvm/arm.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/arch/arm/kvm/arm.c b/arch/arm/kvm/arm.c
> index a9d005f..d4da244 100644
> --- a/arch/arm/kvm/arm.c
> +++ b/arch/arm/kvm/arm.c
> @@ -213,6 +213,11 @@ struct kvm_vcpu *kvm_arch_vcpu_create(struct kvm *kvm, unsigned int id)
> int err;
> struct kvm_vcpu *vcpu;
>
> + if (irqchip_in_kernel(kvm) && vgic_initialized(kvm)) {
Reviewed-by: Eric Auger <eric.auger@linaro.org>
a question about that irqchip_in_kernel(kvm):
kvm->arch.vgic.in_kernel is set in kvm_vgic_create but nobody resets it,
especially in destroy, am i wrong?
if the vgic is initialized shouldn't it be also created? Shouldn't we
test irqchip_in_kernel in vgic_init instead?
Also in case we need irqchip_in_kernel(kvm) here we might need it also
in kvm_vgic_inject_irq because dist->lock is grabbed in
vgic_update_irq_pending.
Eric
> + err = -EBUSY;
> + goto out;
> + }
> +
> vcpu = kmem_cache_zalloc(kvm_vcpu_cache, GFP_KERNEL);
> if (!vcpu) {
> err = -ENOMEM;
>
WARNING: multiple messages have this Message-ID (diff)
From: Eric Auger <eric.auger@linaro.org>
To: Christoffer Dall <christoffer.dall@linaro.org>,
kvmarm@lists.cs.columbia.edu,
linux-arm-kernel@lists.infradead.org
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH 4/5] arm/arm64: KVM: Don't allow creating VCPUs after vgic_initialized
Date: Wed, 10 Dec 2014 13:35:08 +0100 [thread overview]
Message-ID: <54883DFC.4060001@linaro.org> (raw)
In-Reply-To: <1418139844-27892-5-git-send-email-christoffer.dall@linaro.org>
On 12/09/2014 04:44 PM, Christoffer Dall wrote:
> When the vgic initializes its internal state it does so based on the
> number of VCPUs available at the time. If we allow KVM to create more
> VCPUs after the VGIC has been initialized, we are likely to error out in
> unfortunate ways later, perform buffer overflows etc.
>
> Cc: Eric Auger <eric.auger@linaro.org>
> Signed-off-by: Christoffer Dall <christoffer.dall@linaro.org>
> ---
> This replaces Eric Auger's previous patch
> (https://lists.cs.columbia.edu/pipermail/kvmarm/2014-December/012646.html),
> because it fits better with testing to include it in this series and I
> realized that we need to add a check against irqchip_in_kernel() as
> well.
>
> arch/arm/kvm/arm.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/arch/arm/kvm/arm.c b/arch/arm/kvm/arm.c
> index a9d005f..d4da244 100644
> --- a/arch/arm/kvm/arm.c
> +++ b/arch/arm/kvm/arm.c
> @@ -213,6 +213,11 @@ struct kvm_vcpu *kvm_arch_vcpu_create(struct kvm *kvm, unsigned int id)
> int err;
> struct kvm_vcpu *vcpu;
>
> + if (irqchip_in_kernel(kvm) && vgic_initialized(kvm)) {
Reviewed-by: Eric Auger <eric.auger@linaro.org>
a question about that irqchip_in_kernel(kvm):
kvm->arch.vgic.in_kernel is set in kvm_vgic_create but nobody resets it,
especially in destroy, am i wrong?
if the vgic is initialized shouldn't it be also created? Shouldn't we
test irqchip_in_kernel in vgic_init instead?
Also in case we need irqchip_in_kernel(kvm) here we might need it also
in kvm_vgic_inject_irq because dist->lock is grabbed in
vgic_update_irq_pending.
Eric
> + err = -EBUSY;
> + goto out;
> + }
> +
> vcpu = kmem_cache_zalloc(kvm_vcpu_cache, GFP_KERNEL);
> if (!vcpu) {
> err = -ENOMEM;
>
next prev parent reply other threads:[~2014-12-10 12:35 UTC|newest]
Thread overview: 52+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-12-09 15:43 [PATCH 0/5] Fix vgic initialization problems Christoffer Dall
2014-12-09 15:43 ` Christoffer Dall
2014-12-09 15:44 ` [PATCH 1/5] arm/arm64: KVM: vgic: move reset initialization into vgic_init_maps() Christoffer Dall
2014-12-09 15:44 ` Christoffer Dall
2014-12-10 10:11 ` Eric Auger
2014-12-10 10:11 ` Eric Auger
2014-12-11 11:48 ` Christoffer Dall
2014-12-11 11:48 ` Christoffer Dall
2014-12-11 18:25 ` Marc Zyngier
2014-12-11 18:25 ` Marc Zyngier
2014-12-09 15:44 ` [PATCH 2/5] arm/arm64: KVM: Rename vgic_initialized to vgic_ready Christoffer Dall
2014-12-09 15:44 ` Christoffer Dall
2014-12-11 18:26 ` Marc Zyngier
2014-12-11 18:26 ` Marc Zyngier
2014-12-09 15:44 ` [PATCH 3/5] arm/arm64: KVM: Add (new) vgic_initialized macro Christoffer Dall
2014-12-09 15:44 ` Christoffer Dall
2014-12-10 10:27 ` Eric Auger
2014-12-10 10:27 ` Eric Auger
2014-12-11 11:48 ` Christoffer Dall
2014-12-11 11:48 ` Christoffer Dall
2014-12-11 18:28 ` Marc Zyngier
2014-12-11 18:28 ` Marc Zyngier
2014-12-09 15:44 ` [PATCH 4/5] arm/arm64: KVM: Don't allow creating VCPUs after vgic_initialized Christoffer Dall
2014-12-09 15:44 ` Christoffer Dall
2014-12-10 12:35 ` Eric Auger [this message]
2014-12-10 12:35 ` Eric Auger
2014-12-11 11:55 ` Christoffer Dall
2014-12-11 11:55 ` Christoffer Dall
2014-12-11 18:30 ` Marc Zyngier
2014-12-11 18:30 ` Marc Zyngier
2014-12-09 15:44 ` [PATCH 5/5] arm/arm64: KVM: Initialize the vgic on-demand when injecting IRQs Christoffer Dall
2014-12-09 15:44 ` Christoffer Dall
2014-12-10 12:45 ` Eric Auger
2014-12-10 12:45 ` Eric Auger
2014-12-11 12:01 ` Christoffer Dall
2014-12-11 12:01 ` Christoffer Dall
2014-12-11 12:38 ` Eric Auger
2014-12-11 12:38 ` Eric Auger
2014-12-12 11:06 ` Christoffer Dall
2014-12-12 11:06 ` Christoffer Dall
2014-12-15 10:43 ` Eric Auger
2014-12-15 10:43 ` Eric Auger
2014-12-11 18:35 ` Marc Zyngier
2014-12-11 18:35 ` Marc Zyngier
2014-12-12 11:14 ` Christoffer Dall
2014-12-12 11:14 ` Christoffer Dall
2014-12-12 11:23 ` Marc Zyngier
2014-12-12 11:23 ` Marc Zyngier
2014-12-12 11:37 ` Christoffer Dall
2014-12-12 11:37 ` Christoffer Dall
2014-12-12 20:24 ` Christoffer Dall
2014-12-12 20:24 ` Christoffer Dall
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=54883DFC.4060001@linaro.org \
--to=eric.auger@linaro.org \
--cc=linux-arm-kernel@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.