qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: "Jason J. Herne" <jjherne@us.ibm.com>
To: borntraeger@de.ibm.com, qemu-devel@nongnu.org,
	jan.kiszka@siemens.com, agraf@suse.de, jfrei@linux.vnet.ibm.com,
	graalfs@linux.vnet.ibm.com
Cc: "Jason J. Herne" <jjherne@us.ibm.com>
Subject: [Qemu-devel] [PATCH 7/7] KVM regsync: Fix do_kvm_cpu_synchronize_state data integrity issue
Date: Fri, 21 Dec 2012 08:56:31 -0500	[thread overview]
Message-ID: <1356098191-4998-1-git-send-email-jjherne@us.ibm.com> (raw)

From: "Jason J. Herne" <jjherne@us.ibm.com>

Modify syncing algorithm in do_kvm_cpu_synchronize_state to avoid
overwriting previously synced register data by calling
do_kvm_cpu_synchronize_state twice.

The problem occurs if the following sequence of events occurs:
1. kvm_arch_get_registers(env, KVM_REGSYNC_RUNTIME_STATE)
2. Use the runtime state
3. kvm_arch_get_registers(env, KVM_REGSYNC_FULL_STATE) (ignored)
4. Use the full state.

In step 4 the call to kvm_arch_get_registers() does nothing (to avoid squashing
local changes to the runtime registers), but the caller assumes the full
register state is now available.

This is fixed by encoding which registers are synced in env->kvm_vcpu_dirty and
calling kvm_arch_put_registers() to sync local changes back to KVM before
calling kvm_arch_get_registers() if we are expanding the set of synced
registers.

Signed-off-by: Jason J. Herne <jjherne@us.ibm.com>
Reviewed-by: Christian Borntraeger <borntraeger@de.ibm.com>
---
 include/exec/cpu-defs.h |    6 ++++++
 kvm-all.c               |   14 ++++++++++----
 2 files changed, 16 insertions(+), 4 deletions(-)

diff --git a/include/exec/cpu-defs.h b/include/exec/cpu-defs.h
index aea0ece..af3b6aa 100644
--- a/include/exec/cpu-defs.h
+++ b/include/exec/cpu-defs.h
@@ -208,6 +208,12 @@ typedef struct CPUWatchpoint {
     struct KVMState *kvm_state;                                         \
     struct kvm_run *kvm_run;                                            \
     int kvm_fd;                                                         \
+                                                                        \
+    /* Register level indicating which vcpu registers have been synced  \
+       from KVM, are potentially dirty due to local modifications, and  \
+       will need to be written back to KVM.  Valid values are 0, which  \
+       indicates no registers are dirty, or any of the KVM_REGSYNC_*    \
+       constants defined in kvm.h */                                    \
     int kvm_vcpu_dirty;
 
 #endif
diff --git a/kvm-all.c b/kvm-all.c
index aee5bdd..858a636 100644
--- a/kvm-all.c
+++ b/kvm-all.c
@@ -230,7 +230,7 @@ int kvm_init_vcpu(CPUArchState *env)
 
     env->kvm_fd = ret;
     env->kvm_state = s;
-    env->kvm_vcpu_dirty = 1;
+    env->kvm_vcpu_dirty = KVM_REGSYNC_FULL_STATE;
 
     mmap_size = kvm_ioctl(s, KVM_GET_VCPU_MMAP_SIZE, 0);
     if (mmap_size < 0) {
@@ -1489,10 +1489,16 @@ void kvm_flush_coalesced_mmio_buffer(void)
 static void do_kvm_cpu_synchronize_state(void *_args)
 {
     struct kvm_cpu_syncstate_args *args = _args;
+    CPUArchState *env = args->env;
+    int register_level = args->register_level;
 
     if (!args->env->kvm_vcpu_dirty) {
-        kvm_arch_get_registers(args->env, args->register_level);
-        args->env->kvm_vcpu_dirty = 1;
+        kvm_arch_get_registers(env, register_level);
+        env->kvm_vcpu_dirty = register_level;
+    } else if (register_level > env->kvm_vcpu_dirty) {
+        kvm_arch_put_registers(env, env->kvm_vcpu_dirty);
+        kvm_arch_get_registers(env, register_level);
+        env->kvm_vcpu_dirty = register_level;
     }
 }
 
@@ -1535,7 +1541,7 @@ int kvm_cpu_exec(CPUArchState *env)
 
     do {
         if (env->kvm_vcpu_dirty) {
-            kvm_arch_put_registers(env, KVM_REGSYNC_RUNTIME_STATE);
+            kvm_arch_put_registers(env, env->kvm_vcpu_dirty);
             env->kvm_vcpu_dirty = 0;
         }
 
-- 
1.7.9.5

             reply	other threads:[~2012-12-21 13:57 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-12-21 13:56 Jason J. Herne [this message]
2013-01-03 13:56 ` [Qemu-devel] [PATCH 7/7] KVM regsync: Fix do_kvm_cpu_synchronize_state data integrity issue Alexander Graf
2013-01-03 18:48   ` Jason J. Herne
2013-01-03 19:09     ` Alexander Graf
2013-01-04  1:38       ` Marcelo Tosatti
2013-01-04  4:22         ` Bhushan Bharat-R65777
2013-01-04  8:40           ` Alexander Graf
2013-01-04  8:57             ` Bhushan Bharat-R65777
2013-01-04  9:01               ` Alexander Graf
2013-01-04 10:23             ` Bhushan Bharat-R65777
2013-01-04 10:29               ` Alexander Graf
2013-01-04 10:32                 ` Bhushan Bharat-R65777
2013-01-04 10:36                   ` Alexander Graf
2013-01-04 11:01                     ` Bhushan Bharat-R65777
2013-01-04 11:03                       ` Alexander Graf
2013-01-04 15:25                         ` Jason J. Herne
2013-01-04 16:27                           ` Alexander Graf
2013-01-04 17:39                             ` Jason J. Herne
2013-01-06 14:43                               ` Bhushan Bharat-R65777
2013-01-07 15:43                             ` Jason J. Herne
2013-01-07 15:49                               ` Alexander Graf
2013-01-07 18:19                                 ` Jason J. Herne
2013-01-07 18:42                                   ` Alexander Graf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1356098191-4998-1-git-send-email-jjherne@us.ibm.com \
    --to=jjherne@us.ibm.com \
    --cc=agraf@suse.de \
    --cc=borntraeger@de.ibm.com \
    --cc=graalfs@linux.vnet.ibm.com \
    --cc=jan.kiszka@siemens.com \
    --cc=jfrei@linux.vnet.ibm.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).