public inbox for kvm@vger.kernel.org
 help / color / mirror / Atom feed
From: Avi Kivity <avi-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
To: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
Cc: akpm-3NddpPZAyC0@public.gmane.org,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
Subject: [PATCH 7/9] KVM: Make loading cr3 more robust
Date: Fri, 05 Jan 2007 07:56:45 -0000	[thread overview]
Message-ID: <20070105075645.900B6250048@il.qumranet.com> (raw)
In-Reply-To: <459E02E7.5020407-atKUWr5tajBWk0Htik3J/w@public.gmane.org>

From: Ingo Molnar <mingo-X9Un+BFzKDI@public.gmane.org>

Prevent the guest's loading of a corrupt cr3 (pointing at no guest phsyical
page) from crashing the host.

Signed-off-by: Ingo Molnar <mingo-X9Un+BFzKDI@public.gmane.org>
Signed-off-by: Avi Kivity <avi-atKUWr5tajBWk0Htik3J/w@public.gmane.org>

Index: linux-2.6/drivers/kvm/kvm_main.c
===================================================================
--- linux-2.6.orig/drivers/kvm/kvm_main.c
+++ linux-2.6/drivers/kvm/kvm_main.c
@@ -463,7 +463,19 @@ void set_cr3(struct kvm_vcpu *vcpu, unsi
 
 	vcpu->cr3 = cr3;
 	spin_lock(&vcpu->kvm->lock);
-	vcpu->mmu.new_cr3(vcpu);
+	/*
+	 * Does the new cr3 value map to physical memory? (Note, we
+	 * catch an invalid cr3 even in real-mode, because it would
+	 * cause trouble later on when we turn on paging anyway.)
+	 *
+	 * A real CPU would silently accept an invalid cr3 and would
+	 * attempt to use it - with largely undefined (and often hard
+	 * to debug) behavior on the guest side.
+	 */
+	if (unlikely(!gfn_to_memslot(vcpu->kvm, cr3 >> PAGE_SHIFT)))
+		inject_gp(vcpu);
+	else
+		vcpu->mmu.new_cr3(vcpu);
 	spin_unlock(&vcpu->kvm->lock);
 }
 EXPORT_SYMBOL_GPL(set_cr3);

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV

  parent reply	other threads:[~2007-01-05  7:56 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-01-05  7:48 [PATCH 0/9] KVM: Flush out my patch queue Avi Kivity
     [not found] ` <459E02E7.5020407-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
2007-01-05  7:50   ` [PATCH 1/9] KVM: Improve reporting of vmwrite errors Avi Kivity
2007-01-05  7:51   ` [PATCH 2/9] KVM: Initialize vcpu->kvm a little earlier Avi Kivity
2007-01-05  7:52   ` [PATCH 3/9] KVM: Avoid oom on cr3 switch Avi Kivity
2007-01-05  7:53   ` [PATCH 4/9] KVM: Add missing 'break' Avi Kivity
2007-01-05  7:54   ` [PATCH 5/9] KVM: Don't set guest cr3 from vmx_vcpu_setup() Avi Kivity
2007-01-05  7:55   ` [PATCH 6/9] KVM: MMU: Add missing dirty bit Avi Kivity
2007-01-05  7:56   ` Avi Kivity [this message]
2007-01-05  7:57   ` [PATCH 8/9] KVM: Simplify mmu_alloc_roots() Avi Kivity
2007-01-05  7:58   ` [PATCH 9/9] KVM: Simplify test for interrupt window Avi Kivity

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070105075645.900B6250048@il.qumranet.com \
    --to=avi-atkuwr5tajbwk0htik3j/w@public.gmane.org \
    --cc=akpm-3NddpPZAyC0@public.gmane.org \
    --cc=kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org \
    --cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox