From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f173.google.com (mail-yw1-f173.google.com [209.85.128.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7655230276A for ; Thu, 25 Jun 2026 18:14:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782411272; cv=none; b=D67BEeQoT0Mf7Ww6OwTDghT/C6tGrxDoB36csD4VlHUlEaLNsEPmvnp8YANQiN+d1emqUyyIuIWroikIG5CCTc41nR8d6p8qLYESIeSrx/gAQELhdQ76sDzXxYs4H8JZvU630dekztGqQxvfJhXFWToqMmNAzM9WKCbMSiMFX1k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782411272; c=relaxed/simple; bh=oCDgq258AMaW4NdaSF471eM9Gj3tYv+ywa96wXZCOz0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=imOOgPeN9GaEaF7BkEilB83iG0YkPQQX1ZvYUjzR5yhq8Pwj5RwQUtKvX3sDTDhF9T/tYXblhAtRvPQ2uQe2FUUhpypcQSP+wwsyfiwj3E3izi0mjErJbf/Vr7sT+mWqlec/EXjG0OVgZweRRj8pCqs88tUXA63FsVadczUdlnY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=HDV29m6q; arc=none smtp.client-ip=209.85.128.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="HDV29m6q" Received: by mail-yw1-f173.google.com with SMTP id 00721157ae682-7fe8bc0a01bso2373227b3.1 for ; Thu, 25 Jun 2026 11:14:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782411270; x=1783016070; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=0001ivkwixrdliONYVWWSumm3/LwuGYj6UIz947Dh9M=; b=HDV29m6qrDEJf8MCE6ymG1K3Bu+s0p+vKcMIW8JmWBesqvp28sn0kVr5H6khDaIWwu y4Y0jbOtDD5sBjp9aZ/UBol9l6KN5ukGekTJ5vI/OTmkPU+6NCI8iaVqdxUA94omMneW L+FiR2L5m6Vja6ScKCOIw3m1RWxzx60zak50Y9Dmm5Ip86Mb40ryM1yWvvNPvge1NuB0 +GKVDBlD/SMM4OQd2AhsmPaZZbkkfTc1PvFdn+vy6Gs/pG4eQhrlGJW7M3rWlyZZl4ts 2cbeBknrcA2D8RWHDFa9hAnx7V1QvXKnWrl16HKWviavgQiQcKI9NiI5YEPZf9LjuPhP nPEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782411270; x=1783016070; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=0001ivkwixrdliONYVWWSumm3/LwuGYj6UIz947Dh9M=; b=ik/dnK9sXyK6SNjJNw8slEpf3wUm1IvbosaGgJb6UXODXvuiLbiwh5DsqPj0SpHzl0 sagkVVX+BSJfwADZnlv+D29OtDWNaMPfEr2oPSulbF5HuoENcyHQr84xGA3SKJrALvab bFxs/F5AyXHmE2eo2ervgm35ueNJeB94RBWsWZPk8fdnNbgUEo/eLRh2aO7QAttWHjhL x5Ft80ilDt87AoAJN1tY7xVP4pO+LXEf9hrkpcWHNMUelqygNLeDZEApxIELdoKZ3sxc IRm58Sc1XRUlKVWmo96ac2z+bUHPoMjLwob0ezMI5nYM0vfiA8NMGjVgI9ZSuDRkiqfA zP4g== X-Forwarded-Encrypted: i=1; AHgh+RpYDlFPxcCxdouclyD1lpoG1vtiV66BH0bNhZQiUenDmxj5Ob1GanNNDoab2BRfwOvG54R0c3XC0SJxGr8=@vger.kernel.org X-Gm-Message-State: AOJu0YzRw3OAF7LnkjgPe+GbqqNNgvJEA+atEIRssa4mtWKXxwATlXMp wS2DIoJkX5DKXVslL3qUs/H+tMzI1UhRa4RRF9UFmV68JNH5FtqijYiF X-Gm-Gg: AfdE7cluNKRS9nDfM6N6B+kJohc8nm1F21yI9VwnUDbH9bILLDRyarlsmuoEYTdtkXv PZIxo5S5S30smQkBkdfOYyoZQGY/Cb+5ztl1IgUY2l3Qu8LgKvh8zgFl4aJ88khMbsojWdnK0tc 6PE3p7av7ERbsY4231RpOZR60JXe0WP7QUOzkeCuaDJ0xJS2HqksV+PEkcXx3twpz8c8Y3hItQm NaW0YSg1ZPoBAdNpy62zaIvkOFP9rEkluVVYT+8nHBfJ8f7vl1AyOf7G4I4CUycTj4jkjrmpRC8 mi5MdPO4a0pweuPNcWX8pJo9LPbz/yr6GdhRNWT/KufHzDGz5cOU+XTI1giNpKyjNhnmE/3mKSx GFhp+LOle4yuXKnATh66Elww4anspnC5xpZKzh7wkEDlJNpyzkLCFF00TFlRWJaXDJriDfqtS17 LlIprf2mYTRDjtEXXSl40eTbxx1w== X-Received: by 2002:a05:690c:9690:b0:80a:30dd:c91b with SMTP id 00721157ae682-80a67dff343mr38354657b3.16.1782411270190; Thu, 25 Jun 2026 11:14:30 -0700 (PDT) Received: from Dev-Null-MSI ([2a0d:3344:52ac:a808:98a4:4381:be45:536f]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8079ef5c533sm29882317b3.41.2026.06.25.11.14.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 25 Jun 2026 11:14:29 -0700 (PDT) From: Yousef Alhouseen To: "K . Y . Srinivasan" , Haiyang Zhang , Wei Liu , Dexuan Cui , Long Li Cc: Michael Kelley , linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, Yousef Alhouseen Subject: [PATCH v2] mshv_vtl: clear hypercall output before copyout Date: Thu, 25 Jun 2026 20:13:14 +0200 Message-ID: <20260625181314.1399-1-alhouseenyousef@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260624172157.2790-1-alhouseenyousef@gmail.com> References: <20260624172157.2790-1-alhouseenyousef@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit mshv_vtl_hvcall_call() copies output_size bytes to userspace. The output page is freshly allocated. Userspace chooses the copyout length. If the hypercall writes less, the tail can contain stale page data. Clear the copied range before issuing the hypercall. Also check both bounce page allocations before either page is used. Signed-off-by: Yousef Alhouseen --- Changes in v2: - Use the mshv_vtl subject prefix. - Clear only the requested output byte range instead of the whole page. - Add a comment explaining why the output range is cleared. - Keep free_page() calls unconditional. - v1: https://lore.kernel.org/r/20260624172157.2790-1-alhouseenyousef@gmail.com drivers/hv/mshv_vtl_main.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/hv/mshv_vtl_main.c b/drivers/hv/mshv_vtl_main.c index 0d3d41619..dbf03b667 100644 --- a/drivers/hv/mshv_vtl_main.c +++ b/drivers/hv/mshv_vtl_main.c @@ -1148,12 +1148,22 @@ static int mshv_vtl_hvcall_call(struct mshv_vtl_hvcall_fd *fd, */ in = (void *)__get_free_page(GFP_KERNEL); out = (void *)__get_free_page(GFP_KERNEL); + if (!in || !out) { + ret = -ENOMEM; + goto free_pages; + } if (copy_from_user(in, (void __user *)hvcall.input_ptr, hvcall.input_size)) { ret = -EFAULT; goto free_pages; } + /* + * The caller supplies output_size, so clear the range copied back to + * userspace in case the hypercall writes fewer bytes than requested. + */ + memset(out, 0, hvcall.output_size); + hvcall.status = hv_do_hypercall(hvcall.control, in, out); if (copy_to_user((void __user *)hvcall.output_ptr, out, hvcall.output_size)) { -- 2.54.0