From: "Roger Pau Monné" <roger.pau@citrix.com>
To: Jan Beulich <jbeulich@suse.com>
Cc: Andrew Cooper <andrew.cooper3@citrix.com>,
xen-devel@lists.xenproject.org
Subject: Re: [PATCH v5] x86/dom0: disable SMAP for PV domain building only
Date: Tue, 27 Aug 2024 15:43:24 +0200 [thread overview]
Message-ID: <Zs3X_OUy_EkfdKng@macbook.local> (raw)
In-Reply-To: <d939dffc-e8e3-40cf-8494-c03ae6978c90@suse.com>
On Tue, Aug 27, 2024 at 03:04:54PM +0200, Jan Beulich wrote:
> On 27.08.2024 14:59, Andrew Cooper wrote:
> > On 27/08/2024 1:39 pm, Roger Pau Monne wrote:
> >> --- a/xen/arch/x86/dom0_build.c
> >> +++ b/xen/arch/x86/dom0_build.c
> >> @@ -612,7 +612,24 @@ int __init construct_dom0(struct domain *d, const module_t *image,
> >> if ( is_hvm_domain(d) )
> >> rc = dom0_construct_pvh(d, image, image_headroom, initrd, cmdline);
> >> else if ( is_pv_domain(d) )
> >> + {
> >> + /*
> >> + * Temporarily clear SMAP in CR4 to allow user-accesses in
> >> + * construct_dom0(). This saves a large number of corner cases
> >> + * interactions with copy_from_user().
> >> + */
> >> + if ( boot_cpu_has(X86_FEATURE_XEN_SMAP) )
> >> + {
> >> + cr4_pv32_mask &= ~X86_CR4_SMAP;
> >> + write_cr4(read_cr4() & ~X86_CR4_SMAP);
> >> + }
> >> rc = dom0_construct_pv(d, image, image_headroom, initrd, cmdline);
> >> + if ( boot_cpu_has(X86_FEATURE_XEN_SMAP) )
> >> + {
> >> + write_cr4(read_cr4() | X86_CR4_SMAP);
> >> + cr4_pv32_mask |= X86_CR4_SMAP;
> >> + }
> >> + }
> >
> > I hate to drag this on further still, but can this logic be move it into
> > dom0_construct_pv() itself, rather than here?
>
> Just to mention it: I'm fine with this in principle, as long as this won't
> mean a pile of new goto-s in dom0_construct_pv(). If a new wrapper was
> introduced (with the present function becoming static), I'd be okay.
I've considered adding this inside of dom0_construct_pv(), but then I
would need to adjust the return paths to re-enable SMAP.
I can add a wrapper, I didn't do it that way because it seemed
cumbersome IMO.
I will prepare v6 then with that approach.
Thanks, Roger.
next prev parent reply other threads:[~2024-08-27 13:43 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-08-27 12:39 [PATCH v5] x86/dom0: disable SMAP for PV domain building only Roger Pau Monne
2024-08-27 12:59 ` Andrew Cooper
2024-08-27 13:04 ` Jan Beulich
2024-08-27 13:07 ` Andrew Cooper
2024-08-27 13:51 ` Roger Pau Monné
2024-08-27 13:53 ` Jan Beulich
2024-08-27 13:43 ` Roger Pau Monné [this message]
2024-08-28 9:49 ` Jan Beulich
2024-08-28 9:54 ` Andrew Cooper
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Zs3X_OUy_EkfdKng@macbook.local \
--to=roger.pau@citrix.com \
--cc=andrew.cooper3@citrix.com \
--cc=jbeulich@suse.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.