* [PATCH 1/3] xen, pvh: fix unbootable VMs (PVH + KASAN - AMD_MEM_ENCRYPT)
@ 2024-08-02 15:42 Alexey Dobriyan
2024-08-02 15:42 ` [PATCH 2/3] x86/cpu: fix unbootable VMs by inlining memcmp() in hypervisor_cpuid_base() Alexey Dobriyan
2024-08-02 15:42 ` [PATCH 3/3] xen, pvh: fix unbootable VMs by inlining memset() in xen_prepare_pvh() Alexey Dobriyan
0 siblings, 2 replies; 5+ messages in thread
From: Alexey Dobriyan @ 2024-08-02 15:42 UTC (permalink / raw)
To: jgross, boris.ostrovsky, tglx, mingo, bp, dave.hansen
Cc: adobriyan, linux-kernel, x86, hpa
Uninstrument arch/x86/platform/pvh/enlighten.c: KASAN has not been setup
_this_ early in the boot process.
Steps to reproduce:
make allnoconfig
make sure CONFIG_AMD_MEM_ENCRYPT is disabled
AMD_MEM_ENCRYPT independently uninstruments lib/string.o
so PVH boot code calls into uninstrumented memset() and
memcmp() which can make the bug disappear depending on
the compiler.
enable CONFIG_PVH
enable CONFIG_KASAN
enable serial console
this is fun exercise if you never done it from nothing :^)
make
qemu-system-x86_64 \
-enable-kvm \
-cpu host \
-smp cpus=1 \
-m 4096 \
-serial stdio \
-kernel vmlinux \
-append 'console=ttyS0 ignore_loglevel'
Messages on serial console will easily tell OK kernel from unbootable
kernel. In bad case qemu hangs in an infinite loop stroboscoping
"SeaBIOS" message.
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Acked-by: Juergen Gross <jgross@suse.com>
---
arch/x86/platform/pvh/Makefile | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/platform/pvh/Makefile b/arch/x86/platform/pvh/Makefile
index 5dec5067c9fb..c43fb7964dc4 100644
--- a/arch/x86/platform/pvh/Makefile
+++ b/arch/x86/platform/pvh/Makefile
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: GPL-2.0
OBJECT_FILES_NON_STANDARD_head.o := y
+KASAN_SANITIZE := n
obj-$(CONFIG_PVH) += enlighten.o
obj-$(CONFIG_PVH) += head.o
--
2.45.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 2/3] x86/cpu: fix unbootable VMs by inlining memcmp() in hypervisor_cpuid_base()
2024-08-02 15:42 [PATCH 1/3] xen, pvh: fix unbootable VMs (PVH + KASAN - AMD_MEM_ENCRYPT) Alexey Dobriyan
@ 2024-08-02 15:42 ` Alexey Dobriyan
2024-08-15 13:32 ` Jürgen Groß
2024-08-02 15:42 ` [PATCH 3/3] xen, pvh: fix unbootable VMs by inlining memset() in xen_prepare_pvh() Alexey Dobriyan
1 sibling, 1 reply; 5+ messages in thread
From: Alexey Dobriyan @ 2024-08-02 15:42 UTC (permalink / raw)
To: jgross, boris.ostrovsky, tglx, mingo, bp, dave.hansen
Cc: adobriyan, linux-kernel, x86, hpa
If this memcmp() is not inlined then PVH early boot code can call
into KASAN-instrumented memcmp() which results in unbootable VMs:
pvh_start_xen
xen_prepare_pvh
xen_cpuid_base
hypervisor_cpuid_base
memcmp
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
---
arch/x86/include/asm/cpuid.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/arch/x86/include/asm/cpuid.h b/arch/x86/include/asm/cpuid.h
index 6b122a31da06..80cc6386d7b1 100644
--- a/arch/x86/include/asm/cpuid.h
+++ b/arch/x86/include/asm/cpuid.h
@@ -196,7 +196,12 @@ static inline uint32_t hypervisor_cpuid_base(const char *sig, uint32_t leaves)
for_each_possible_hypervisor_cpuid_base(base) {
cpuid(base, &eax, &signature[0], &signature[1], &signature[2]);
- if (!memcmp(sig, signature, 12) &&
+ /*
+ * This must not compile to "call memcmp" because it's called
+ * from PVH early boot code before instrumentation is set up
+ * and memcmp() itself may be instrumented.
+ */
+ if (!__builtin_memcmp(sig, signature, 12) &&
(leaves == 0 || ((eax - base) >= leaves)))
return base;
}
--
2.45.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 3/3] xen, pvh: fix unbootable VMs by inlining memset() in xen_prepare_pvh()
2024-08-02 15:42 [PATCH 1/3] xen, pvh: fix unbootable VMs (PVH + KASAN - AMD_MEM_ENCRYPT) Alexey Dobriyan
2024-08-02 15:42 ` [PATCH 2/3] x86/cpu: fix unbootable VMs by inlining memcmp() in hypervisor_cpuid_base() Alexey Dobriyan
@ 2024-08-02 15:42 ` Alexey Dobriyan
2024-08-15 13:33 ` Jürgen Groß
1 sibling, 1 reply; 5+ messages in thread
From: Alexey Dobriyan @ 2024-08-02 15:42 UTC (permalink / raw)
To: jgross, boris.ostrovsky, tglx, mingo, bp, dave.hansen
Cc: adobriyan, linux-kernel, x86, hpa
If this memset() is not inlined than PVH early boot code can call
into KASAN-instrumented memset() which results in unbootable VMs.
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
---
arch/x86/platform/pvh/enlighten.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/arch/x86/platform/pvh/enlighten.c b/arch/x86/platform/pvh/enlighten.c
index 944e0290f2c0..2263885d16ba 100644
--- a/arch/x86/platform/pvh/enlighten.c
+++ b/arch/x86/platform/pvh/enlighten.c
@@ -130,7 +130,11 @@ void __init xen_prepare_pvh(void)
BUG();
}
- memset(&pvh_bootparams, 0, sizeof(pvh_bootparams));
+ /*
+ * This must not compile to "call memset" because memset() may be
+ * instrumented.
+ */
+ __builtin_memset(&pvh_bootparams, 0, sizeof(pvh_bootparams));
hypervisor_specific_init(xen_guest);
--
2.45.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH 2/3] x86/cpu: fix unbootable VMs by inlining memcmp() in hypervisor_cpuid_base()
2024-08-02 15:42 ` [PATCH 2/3] x86/cpu: fix unbootable VMs by inlining memcmp() in hypervisor_cpuid_base() Alexey Dobriyan
@ 2024-08-15 13:32 ` Jürgen Groß
0 siblings, 0 replies; 5+ messages in thread
From: Jürgen Groß @ 2024-08-15 13:32 UTC (permalink / raw)
To: Alexey Dobriyan, boris.ostrovsky, tglx, mingo, bp, dave.hansen
Cc: linux-kernel, x86, hpa
On 02.08.24 17:42, Alexey Dobriyan wrote:
> If this memcmp() is not inlined then PVH early boot code can call
> into KASAN-instrumented memcmp() which results in unbootable VMs:
>
> pvh_start_xen
> xen_prepare_pvh
> xen_cpuid_base
> hypervisor_cpuid_base
> memcmp
>
> Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Acked-by: Juergen Gross <jgross@suse.com>
Juergen
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 3/3] xen, pvh: fix unbootable VMs by inlining memset() in xen_prepare_pvh()
2024-08-02 15:42 ` [PATCH 3/3] xen, pvh: fix unbootable VMs by inlining memset() in xen_prepare_pvh() Alexey Dobriyan
@ 2024-08-15 13:33 ` Jürgen Groß
0 siblings, 0 replies; 5+ messages in thread
From: Jürgen Groß @ 2024-08-15 13:33 UTC (permalink / raw)
To: Alexey Dobriyan, boris.ostrovsky, tglx, mingo, bp, dave.hansen
Cc: linux-kernel, x86, hpa
On 02.08.24 17:42, Alexey Dobriyan wrote:
> If this memset() is not inlined than PVH early boot code can call
> into KASAN-instrumented memset() which results in unbootable VMs.
>
> Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Acked-by: Juergen Gross <jgross@suse.com>
Juergen
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2024-08-15 13:33 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-08-02 15:42 [PATCH 1/3] xen, pvh: fix unbootable VMs (PVH + KASAN - AMD_MEM_ENCRYPT) Alexey Dobriyan
2024-08-02 15:42 ` [PATCH 2/3] x86/cpu: fix unbootable VMs by inlining memcmp() in hypervisor_cpuid_base() Alexey Dobriyan
2024-08-15 13:32 ` Jürgen Groß
2024-08-02 15:42 ` [PATCH 3/3] xen, pvh: fix unbootable VMs by inlining memset() in xen_prepare_pvh() Alexey Dobriyan
2024-08-15 13:33 ` Jürgen Groß
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox