All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] xen/arm: ffa: Harden SEND2 against invented loads
@ 2026-08-18 12:16 Bertrand Marquis
  2026-08-18 12:40 ` Andrew Cooper
  2026-08-19  7:47 ` Orzel, Michal
  0 siblings, 2 replies; 10+ messages in thread
From: Bertrand Marquis @ 2026-08-18 12:16 UTC (permalink / raw)
  To: xen-devel
  Cc: Volodymyr Babchuk, Jens Wiklander, Stefano Stabellini,
	Julien Grall, Michal Orzel

Research into compiler-invented loads has flagged FFA_MSG_SEND2 as a
possible vulnerability.

ffa_handle_msg_send2() copies the message header from the guest-writable
TX buffer before validating and using its fields. A plain structure copy
does not prevent the compiler from re-deriving later field accesses from
the live TX mapping.

For VM-to-VM messages, msg_offset and msg_size are validated against the
source and destination buffers, then used to copy the payload. If a
sibling vCPU changes the header and the compiler reloads either field,
the checked and used values can differ. This can cause an out-of-bounds
read from the sender's TX buffer or an out-of-bounds write into the
receiver's RX buffer.

The cross-VM path is gated by CONFIG_FFA_VM_TO_VM, which is disabled by
default. The audit ranks the likelihood of such a reload as low, but the
C semantics do not guarantee that later accesses use the stack copy.

Add a compiler barrier immediately after copying the header so that
validation and use consume the same snapshot.

Link: https://github.com/xoreaxeaxeax/schrodingers-toctou/blob/main/observer-effect/audits/audit-xen-tee-mediator-RELEASE-4.21.1.md#tm-2--ff-a-txrx-buffers-ffa_shmc-ffa_msgc
Fixes: 98af565b1e61 ("xen/arm: ffa: Add indirect message between VM")
Signed-off-by: Bertrand Marquis <bertrand.marquis@arm.com>
---
 xen/arch/arm/tee/ffa_msg.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/xen/arch/arm/tee/ffa_msg.c b/xen/arch/arm/tee/ffa_msg.c
index 1eadc62870f2..39f561c8237f 100644
--- a/xen/arch/arm/tee/ffa_msg.c
+++ b/xen/arch/arm/tee/ffa_msg.c
@@ -257,6 +257,11 @@ int32_t ffa_handle_msg_send2(struct cpu_user_regs *regs)
 
     /* create a copy of the message header */
     memcpy(&src_msg, tx_buf, sizeof(src_msg));
+    /*
+     * Make sure that "tx_buf" which is shared with the guest isn't accessed
+     * again after this point.
+     */
+    barrier();
 
     src_id = src_msg.send_recv_id >> 16;
     dst_id = src_msg.send_recv_id & GENMASK(15,0);
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-08-19 10:22 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18 12:16 [PATCH] xen/arm: ffa: Harden SEND2 against invented loads Bertrand Marquis
2026-08-18 12:40 ` Andrew Cooper
2026-08-18 13:28   ` Bertrand Marquis
2026-08-18 14:46     ` Andrew Cooper
2026-08-19  6:39       ` Bertrand Marquis
2026-08-19 10:21         ` Andrew Cooper
2026-08-19  7:47 ` Orzel, Michal
2026-08-19  8:01   ` Bertrand Marquis
2026-08-19  8:09     ` Orzel, Michal
2026-08-19  8:18       ` Bertrand Marquis

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.