From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.6 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_PASS, URIBL_BLOCKED,USER_AGENT_MUTT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 23AF9C43219 for ; Sat, 27 Apr 2019 13:45:12 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id E561D208CA for ; Sat, 27 Apr 2019 13:45:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1556372712; bh=1fjSm4zSkxj+56+K4exMU8y3n8IBgaJGpxfqgcDUcEs=; h=Date:From:To:Cc:Subject:References:In-Reply-To:List-ID:From; b=KG8JmSLncaTz0QFt+OVf7t6MhHenHjNtWWYwWhlyaEzigKtxdHFYzB56APdW7ZrqP gD6cBYV7qODF7xlCMN0QHoDH3N4aGJSv7mAOCXkgQs66S+Sdyw/yIuixJgTOMaiU5V MNtZ1lCGd278crfY/IbW9ffV0qmhNBAVWLiVxHPo= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726050AbfD0NpL (ORCPT ); Sat, 27 Apr 2019 09:45:11 -0400 Received: from mail.kernel.org ([198.145.29.99]:38064 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725902AbfD0NpL (ORCPT ); Sat, 27 Apr 2019 09:45:11 -0400 Received: from localhost (c-73-47-72-35.hsd1.nh.comcast.net [73.47.72.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id D22FB208C2; Sat, 27 Apr 2019 13:45:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1556372710; bh=1fjSm4zSkxj+56+K4exMU8y3n8IBgaJGpxfqgcDUcEs=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=aJDQsT6A/dt4fS+crTD9aKjQzc2xgHE6MIqz+ekwRbkFq4a5j9f/qoCPlgVowMORG IUfHJDRkUzoTGYn10zsR4VWe5ZfXv7ND209BeES3H1128qhJf38utg5RkRibcpeAtG UzS0HTIwpW+pt7TvQeMhhv9F3z6rHyCPJ4EzUyl8= Date: Sat, 27 Apr 2019 09:45:08 -0400 From: Sasha Levin To: Zubin Mithra Cc: stable@vger.kernel.org, gregkh@linuxfoundation.org, groeck@chromium.org, pbonzini@redhat.com, rkrcmar@redhat.com, tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, hpa@zytor.com Subject: Re: [PATCH v4.4.y] KVM: fail KVM_SET_VCPU_EVENTS with invalid exception number Message-ID: <20190427134508.GD17719@sasha-vm> References: <20190426163401.17103-1-zsm@chromium.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20190426163401.17103-1-zsm@chromium.org> User-Agent: Mutt/1.10.1 (2018-07-13) Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org On Fri, Apr 26, 2019 at 09:34:01AM -0700, Zubin Mithra wrote: >From: Paolo Bonzini > >commit 78e546c824fa8f96d323b7edd6f5cad5b74af057 upstream > >This cannot be returned by KVM_GET_VCPU_EVENTS, so it is okay to return >EINVAL. It causes a WARN from exception_type: > > WARNING: CPU: 3 PID: 16732 at arch/x86/kvm/x86.c:345 exception_type+0x49/0x50 [kvm]() > CPU: 3 PID: 16732 Comm: a.out Tainted: G W 4.4.6-300.fc23.x86_64 #1 > Hardware name: LENOVO 2325F51/2325F51, BIOS G2ET32WW (1.12 ) 05/30/2012 > 0000000000000286 000000006308a48b ffff8800bec7fcf8 ffffffff813b542e > 0000000000000000 ffffffffa0966496 ffff8800bec7fd30 ffffffff810a40f2 > ffff8800552a8000 0000000000000000 00000000002c267c 0000000000000001 > Call Trace: > [] dump_stack+0x63/0x85 > [] warn_slowpath_common+0x82/0xc0 > [] warn_slowpath_null+0x1a/0x20 > [] exception_type+0x49/0x50 [kvm] > [] kvm_arch_vcpu_ioctl_run+0x10a2/0x14e0 [kvm] > [] kvm_vcpu_ioctl+0x33d/0x620 [kvm] > [] do_vfs_ioctl+0x298/0x480 > [] SyS_ioctl+0x79/0x90 > [] entry_SYSCALL_64_fastpath+0x12/0x71 > ---[ end trace b1a0391266848f50 ]--- > >Testcase (beautified/reduced from syzkaller output): > > #include > #include > #include > #include > #include > #include > #include > > long r[31]; > > int main() > { > memset(r, -1, sizeof(r)); > r[2] = open("/dev/kvm", O_RDONLY); > r[3] = ioctl(r[2], KVM_CREATE_VM, 0); > r[7] = ioctl(r[3], KVM_CREATE_VCPU, 0); > > struct kvm_vcpu_events ve = { > .exception.injected = 1, > .exception.nr = 0xd4 > }; > r[27] = ioctl(r[7], KVM_SET_VCPU_EVENTS, &ve); > r[30] = ioctl(r[7], KVM_RUN, 0); > return 0; > } > >Reported-by: Dmitry Vyukov >Signed-off-by: Paolo Bonzini >Signed-off-by: Radim Krčmář >Signed-off-by: Zubin Mithra >--- >Notes: >* Syzkaller triggered a WARNING in exception_type with the following stacktrace. >Call Trace: > __dump_stack lib/dump_stack.c:15 [inline] > dump_stack+0xbf/0x113 lib/dump_stack.c:51 > panic+0x1a6/0x361 kernel/panic.c:116 > __warn+0x168/0x1b0 kernel/panic.c:470 > warn_slowpath_null+0x3c/0x40 kernel/panic.c:514 > exception_type+0x33/0x7d arch/x86/kvm/x86.c:354 > inject_pending_event arch/x86/kvm/x86.c:6072 [inline] > vcpu_enter_guest arch/x86/kvm/x86.c:6551 [inline] > vcpu_run arch/x86/kvm/x86.c:6744 [inline] > kvm_arch_vcpu_ioctl_run+0x1b76/0x352e arch/x86/kvm/x86.c:6902 > kvm_vcpu_ioctl+0x396/0xa74 arch/x86/kvm/../../../virt/kvm/kvm_main.c:2432 > vfs_ioctl fs/ioctl.c:43 [inline] > do_vfs_ioctl+0xcb0/0xd0f fs/ioctl.c:630 > SYSC_ioctl fs/ioctl.c:645 [inline] > SyS_ioctl+0x71/0xad fs/ioctl.c:636 > entry_SYSCALL_64_fastpath+0x31/0xb3 > >* This patch resolves a conflict that arises when applying the original upstream >commit. The conflict arises as the following upstream patch was applied to 4.4.y: > 28bf28887976 ("KVM: x86: fix user triggerable warning in kvm_apic_accept_events()") > >* This commit is present in linux-4.9.y > >* Tests run: Chrome OS tryjobs, Syzkaller reproducer Queued, thanks! -- Thanks, Sasha