From: Lisa Wang <wyihan@google.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v15 16/23] KVM: selftests: Load per-vCPU guest stack in TDX boot parameters
Date: Wed, 7 Oct 2026 19:07:11 +0000 [thread overview]
Message-ID: <asaYX9uk48uWISHx@google.com> (raw)
In-Reply-To: <20261002091336.EA00B1F00899@smtp.kernel.org>
On Fri, Oct 02, 2026 at 09:13:36AM +0000, sashiko-bot@kernel.org wrote:
> > +void tdx_vcpu_load_boot_parameters(struct kvm_vm *vm, struct kvm_vcpu *vcpu)
> > +{
> > + struct td_boot_parameters *params =
> > + addr_gpa2hva(vm, TD_BOOT_PARAMETERS_GPA);
> > + struct td_per_vcpu_parameters *vcpu_params =
> > + ¶ms->per_vcpu[vcpu->id];
>
> [Severity: Medium]
> Will this lead to an out-of-bounds array access in
> tdx_vcpu_load_boot_parameters() if a test uses a sparse vcpu->id?
>
> The boot parameters region appears to allocate memory for exactly
> nr_runnable_vcpus instances of struct td_per_vcpu_parameters in
> tdx_vm_setup_boot_parameters_region():
>
> size_t boot_params_size = sizeof(struct td_boot_parameters) +
> nr_runnable_vcpus * sizeof(struct td_per_vcpu_parameters);
>
> Since vcpu->id represents the KVM vCPU ID (which can be the APIC ID on x86)
> and can be larger than or equal to nr_runnable_vcpus, could this write beyond
> the allocated bounds and corrupt adjacent host memory and guest physical pages?
>
> This could be triggered if a selftest creating a TDX VM specifies a sparse
> vcpu->id that is larger than or equal to the total number of runnable vCPUs
> passed to vm_create().
In KVM selftests, VMs already create vCPUs sequentially with vcpu->id
(via __vm_create_with_vcpus()). TDX selftests will not test sparse vCPU
IDs either, because TDH.VP.INIT always initializes %esi to the sequential
0-based vCPU index.
> > +
> > + vcpu_params->esp_gva = kvm_allocate_vcpu_stack(vm);
> > + TEST_ASSERT(vcpu_params->esp_gva < (1ULL << 32),
> > + "ESP GVA must be within 32-bit address space for 32-bit boot code");
>
> [Severity: Medium]
> Does this bounds check in tdx_vcpu_load_boot_parameters() actually work, or is
> the value silently truncated before the check?
>
> Because kvm_allocate_vcpu_stack() returns a 64-bit gva_t, assigning it
> to vcpu_params->esp_gva truncates the value to 32 bits since esp_gva is
> declared as a u32.
>
> The TEST_ASSERT then evaluates the already truncated 32-bit value against
> (1ULL << 32), which will always be true. Could this bypass the intended
> safety check and cause silent stack corruption and test failures instead of
> an explicit assertion failure?
>
> This could be triggered if a selftest allocates enough memory such that the
> guest stack virtual address exceeds 4GB.
Yes, will fix in the next series.
next prev parent reply other threads:[~2026-10-07 19:07 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 19:37 [PATCH v15 00/23] TDX KVM selftests Lisa Wang
2026-10-01 19:37 ` [PATCH v15 01/23] KVM: selftests: Add macros to simplify creating VM shapes for non-default types Lisa Wang
2026-10-01 19:37 ` [PATCH v15 02/23] KVM: selftests: Update kvm_init_vm_address_properties() for TDX Lisa Wang
2026-10-01 19:37 ` [PATCH v15 03/23] KVM: selftests: Initialize the TDX VM Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-05 21:26 ` Lisa Wang
2026-10-09 6:00 ` Xiaoyao Li
2026-10-10 2:05 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 04/23] KVM: selftests: Expose segment definitions to assembly files Lisa Wang
2026-10-01 19:37 ` [PATCH v15 05/23] tools: include: Add kbuild.h for assembly structure offsets Lisa Wang
2026-10-09 6:10 ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 06/23] KVM: selftests: Introduce structures for TDX guest boot parameters Lisa Wang
2026-10-09 6:13 ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 07/23] KVM: selftests: Add TDX boot code Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-05 22:31 ` Lisa Wang
2026-10-01 19:37 ` [PATCH v15 08/23] KVM: selftests: Expose functions to get default sregs values Lisa Wang
2026-10-01 19:37 ` [PATCH v15 09/23] KVM: selftests: Set up TDX boot code region Lisa Wang
2026-10-01 19:37 ` [PATCH v15 10/23] KVM: selftests: Set up TDX boot parameters region Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-05 22:33 ` Lisa Wang
2026-10-09 7:22 ` Xiaoyao Li
2026-10-10 2:46 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 11/23] KVM: selftests: Set shared attributes for ucall guest_memfd pages Lisa Wang
2026-10-09 15:44 ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 12/23] KVM: selftests: Require guest_memfd for TDX VMs Lisa Wang
2026-10-09 7:38 ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 13/23] KVM: selftests: Support guest_memfd in-place conversion Lisa Wang
2026-10-10 3:32 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 14/23] KVM: selftests: Expose function to allocate vCPU stack Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-09 7:56 ` Xiaoyao Li
2026-10-10 3:54 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 15/23] KVM: selftests: Call KVM_TDX_INIT_VCPU when creating a new TDX vcpu Lisa Wang
2026-10-09 8:02 ` Xiaoyao Li
2026-10-10 4:31 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 16/23] KVM: selftests: Load per-vCPU guest stack in TDX boot parameters Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-07 19:07 ` Lisa Wang [this message]
2026-10-01 19:37 ` [PATCH v15 17/23] KVM: selftests: Set entry point for TDX guest code Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-01 19:37 ` [PATCH v15 18/23] KVM: selftests: Add helpers to init TDX memory and finalize VM Lisa Wang
2026-10-01 19:37 ` [PATCH v15 19/23] KVM: selftests: Finalize TDX VM in kvm_arch_vm_finalize_vcpus() Lisa Wang
2026-10-09 8:12 ` Xiaoyao Li
2026-10-10 5:57 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 20/23] KVM: selftests: Add a helper to issue TDVMCALLs from the TDX vm Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-09 8:20 ` Xiaoyao Li
2026-10-09 8:23 ` Xiaoyao Li
2026-10-10 6:34 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 21/23] KVM: selftests: Add support for per-VM ucall ops on x86 Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-10 6:52 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 22/23] KVM: selftests: Add support for TDX ucalls, via TDVMCALL_REPORT_FATAL_ERROR Lisa Wang
2026-10-02 9:13 ` sashiko-bot
2026-10-10 7:30 ` Binbin Wu
2026-10-10 7:20 ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 23/23] KVM: selftests: Add TDX lifecycle test Lisa Wang
2026-10-10 7:40 ` Binbin Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asaYX9uk48uWISHx@google.com \
--to=wyihan@google.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.