From mboxrd@z Thu Jan 1 00:00:00 1970 From: Paul Durrant Subject: Re: [PATCH 2/5] x86/hvm: Switch hvm_allow_set_param() to use a whitelist Date: Thu, 6 Sep 2018 09:08:27 +0000 Message-ID: <4bf4acfc9c0a43cda81b7c6eb74bc96b@AMSPEX02CL03.citrite.net> References: <1536171124-27053-1-git-send-email-andrew.cooper3@citrix.com> <1536171124-27053-3-git-send-email-andrew.cooper3@citrix.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: In-Reply-To: <1536171124-27053-3-git-send-email-andrew.cooper3@citrix.com> Content-Language: en-US List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Sender: "Xen-devel" To: Xen-devel Cc: Stefano Stabellini , Wei Liu , Andrew Cooper , Julien Grall , Jan Beulich , Roger Pau Monne List-Id: xen-devel@lists.xenproject.org PiAtLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0KPiBGcm9tOiBBbmRyZXcgQ29vcGVyIFttYWls dG86YW5kcmV3LmNvb3BlcjNAY2l0cml4LmNvbV0NCj4gU2VudDogMDUgU2VwdGVtYmVyIDIwMTgg MTk6MTINCj4gVG86IFhlbi1kZXZlbCA8eGVuLWRldmVsQGxpc3RzLnhlbi5vcmc+DQo+IENjOiBB bmRyZXcgQ29vcGVyIDxBbmRyZXcuQ29vcGVyM0BjaXRyaXguY29tPjsgSmFuIEJldWxpY2gNCj4g PEpCZXVsaWNoQHN1c2UuY29tPjsgV2VpIExpdSA8d2VpLmxpdTJAY2l0cml4LmNvbT47IFJvZ2Vy IFBhdSBNb25uZQ0KPiA8cm9nZXIucGF1QGNpdHJpeC5jb20+OyBQYXVsIER1cnJhbnQgPFBhdWwu RHVycmFudEBjaXRyaXguY29tPjsgU3RlZmFubw0KPiBTdGFiZWxsaW5pIDxzc3RhYmVsbGluaUBr ZXJuZWwub3JnPjsgSnVsaWVuIEdyYWxsIDxqdWxpZW4uZ3JhbGxAYXJtLmNvbT4NCj4gU3ViamVj dDogW1BBVENIIDIvNV0geDg2L2h2bTogU3dpdGNoIGh2bV9hbGxvd19zZXRfcGFyYW0oKSB0byB1 c2UgYQ0KPiB3aGl0ZWxpc3QNCj4gDQo+IFRoZXJlIGFyZSBob2xlcyBpbiB0aGUgSFZNX1BBUkFN IHNwYWNlLCBzb21lIG9mIHdoaWNoIGFyZSBmcm9tDQo+IGRlcHJlY2F0ZWQNCj4gcGFyYW1ldGVy cywgYnV0IHRvb2xzdGFjayBhbmQgZGV2aWNlIG1vZGVscyBjdXJyZW50bHkgaGFzIChhbG1vc3Qp IGJsYW5rZXQNCg0Kcy9oYXMvaGF2ZQ0KDQo+IHdyaXRlIGFjY2Vzcy4NCj4gDQo+IFJlYXJyYW5n ZSBodm1fYWxsb3dfZ2V0X3BhcmFtKCkgdG8gaGF2ZSBhIHdoaXRlbGlzdCBvZiB0b29sc3RhY2st d3JpdGVhYmxlDQoNCnMvZ2V0L3NldA0KDQo+IHBhcmFtZXRlcnMsIHdpdGggdGhlIGRlZmF1bHQg Y2FzZSBmYWlsaW5nIHdpdGggLUVJTlZBTC4gIFRoaXMgc3Vic3VtZXMgdGhlDQo+IEhWTV9OUl9Q QVJBTVMgY2hlY2ssIGFzIHdlbGwgYXMgdGhlIE1FTU9SWV9FVkVOVF8qIGRlcHJlY2F0ZWQNCj4g YmxvY2ssIGFuZCB0aGUNCj4gQlVGSU9SRVFfRVZUQ0hOIFhlbi13cml0ZS1vbmx5IHZhbHVlLg0K PiANCj4gTm8gZXhwZWN0ZWQgY2hhbmdlIGZvciB0aGUgZGVmaW5lZCwgaW4tdXNlIHBhcmFtcy4N Cj4gDQo+IFNpZ25lZC1vZmYtYnk6IEFuZHJldyBDb29wZXIgPGFuZHJldy5jb29wZXIzQGNpdHJp eC5jb20+DQo+IC0tLQ0KPiBDQzogSmFuIEJldWxpY2ggPEpCZXVsaWNoQHN1c2UuY29tPg0KPiBD QzogV2VpIExpdSA8d2VpLmxpdTJAY2l0cml4LmNvbT4NCj4gQ0M6IFJvZ2VyIFBhdSBNb25uw6kg PHJvZ2VyLnBhdUBjaXRyaXguY29tPg0KPiBDQzogUGF1bCBEdXJyYW50IDxwYXVsLmR1cnJhbnRA Y2l0cml4LmNvbT4NCj4gQ0M6IFN0ZWZhbm8gU3RhYmVsbGluaSA8c3N0YWJlbGxpbmlAa2VybmVs Lm9yZz4NCj4gQ0M6IEp1bGllbiBHcmFsbCA8anVsaWVuLmdyYWxsQGFybS5jb20+DQo+IC0tLQ0K PiAgeGVuL2FyY2gveDg2L2h2bS9odm0uYyB8IDUzICsrKysrKysrKysrKysrKysrKysrKysrKysr KysrLS0tLS0tLS0tDQo+IC0tLS0tLS0tLS0tLQ0KPiAgMSBmaWxlIGNoYW5nZWQsIDMxIGluc2Vy dGlvbnMoKyksIDIyIGRlbGV0aW9ucygtKQ0KPiANCj4gZGlmZiAtLWdpdCBhL3hlbi9hcmNoL3g4 Ni9odm0vaHZtLmMgYi94ZW4vYXJjaC94ODYvaHZtL2h2bS5jDQo+IGluZGV4IDk2YTYzMjMuLmQx OWFlMzUgMTAwNjQ0DQo+IC0tLSBhL3hlbi9hcmNoL3g4Ni9odm0vaHZtLmMNCj4gKysrIGIveGVu L2FyY2gveDg2L2h2bS9odm0uYw0KPiBAQCAtNDA3Myw3ICs0MDczLDcgQEAgc3RhdGljIGludCBo dm1fYWxsb3dfc2V0X3BhcmFtKHN0cnVjdCBkb21haW4gKmQsDQo+IA0KPiAgICAgIHN3aXRjaCAo IGEtPmluZGV4ICkNCj4gICAgICB7DQo+IC0gICAgLyogVGhlIGZvbGxvd2luZyBwYXJhbWV0ZXJz IGNhbiBiZSBzZXQgYnkgdGhlIGd1ZXN0LiAqLw0KPiArICAgICAgICAvKiBUaGUgZm9sbG93aW5n IHBhcmFtZXRlcnMgY2FuIGJlIHNldCBieSB0aGUgZ3Vlc3QgYW5kIHRvb2xzdGFjay4gKi8NCg0K UGVyc29uYWxseSBJJ20gZmluZGluZyB0aGlzIGluZGVudGF0aW9uIG9mIGNvbW1lbnQgaW5jb25n cnVvdXMuIFN1Y2ggY29tbWVudHMgYXJlIGxvZ2ljYWxseSBvdXRzaWRlIG9mIGFueSBwYXJ0aWN1 bGFyIGNhc2Ugc3RhdGVtZW50IHNvIEkgdGhpbmsgdGhleSBzaG91bGQgaGF2ZSB0aGUgc2FtZSBs ZXZlbCBvZiBpbmRlbnRhdGlvbiBhcyB0aGUgY2FzZSBzdGF0ZW1lbnRzIHRoZW1zZWx2ZXMuDQoN Cj4gICAgICBjYXNlIEhWTV9QQVJBTV9DQUxMQkFDS19JUlE6DQo+ICAgICAgY2FzZSBIVk1fUEFS QU1fVk04Nl9UU1M6DQo+ICAgICAgY2FzZSBIVk1fUEFSQU1fVk04Nl9UU1NfU0laRUQ6DQo+IEBA IC00MDgzLDE4ICs0MDgzLDQwIEBAIHN0YXRpYyBpbnQgaHZtX2FsbG93X3NldF9wYXJhbShzdHJ1 Y3QgZG9tYWluDQo+ICpkLA0KPiAgICAgIGNhc2UgSFZNX1BBUkFNX0NPTlNPTEVfRVZUQ0hOOg0K PiAgICAgIGNhc2UgSFZNX1BBUkFNX1g4N19GSVBfV0lEVEg6DQo+ICAgICAgICAgIGJyZWFrOw0K PiAtICAgIC8qDQo+IC0gICAgICogVGhlIGZvbGxvd2luZyBwYXJhbWV0ZXJzIG11c3Qgbm90IGJl IHNldCBieSB0aGUgZ3Vlc3QNCj4gLSAgICAgKiBzaW5jZSB0aGUgZG9tYWluIG1heSBuZWVkIHRv IGJlIHBhdXNlZC4NCj4gLSAgICAgKi8NCj4gKw0KPiArICAgICAgICAvKg0KPiArICAgICAgICAg KiBUaGUgZm9sbG93aW5nIHBhcmFtZXRlcnMgYXJlIGludGVuZGVkIGZvciB0b29sc3RhY2sgdXNh Z2Ugb25seS4NCj4gKyAgICAgICAgICogU29tZSByZXF1aXJlIHRoZSBkb21haW4gdG8gYmUgcGF1 c2VkIHdoaWxlIG90aGVycyBjb250cm9sDQo+ICsgICAgICAgICAqIHBlcm1pc3Npb25zIGluIFhl biwgYW5kIHRoZXJlZm9yZSBtYXkgbm90IHNldCBieSB0aGUgZG9tYWluLg0KPiArICAgICAgICAg Ki8NCj4gKyAgICBjYXNlIEhWTV9QQVJBTV9TVE9SRV9QRk46DQo+ICsgICAgY2FzZSBIVk1fUEFS QU1fUEFFX0VOQUJMRUQ6DQo+ICsgICAgY2FzZSBIVk1fUEFSQU1fSU9SRVFfUEZOOg0KPiArICAg IGNhc2UgSFZNX1BBUkFNX0JVRklPUkVRX1BGTjoNCj4gKyAgICBjYXNlIEhWTV9QQVJBTV9WSVJJ RElBTjoNCj4gKyAgICBjYXNlIEhWTV9QQVJBTV9USU1FUl9NT0RFOg0KPiArICAgIGNhc2UgSFZN X1BBUkFNX0hQRVRfRU5BQkxFRDoNCj4gICAgICBjYXNlIEhWTV9QQVJBTV9JREVOVF9QVDoNCj4g ICAgICBjYXNlIEhWTV9QQVJBTV9ETV9ET01BSU46DQo+ICAgICAgY2FzZSBIVk1fUEFSQU1fQUNQ SV9TX1NUQVRFOg0KPiAtICAgIC8qIFRoZSByZW1haW5pbmcgcGFyYW1ldGVycyBzaG91bGQgbm90 IGJlIHNldCBieSB0aGUgZ3Vlc3QuICovDQo+IC0gICAgZGVmYXVsdDoNCj4gKyAgICBjYXNlIEhW TV9QQVJBTV9WUFRfQUxJR046DQo+ICsgICAgY2FzZSBIVk1fUEFSQU1fQ09OU09MRV9QRk46DQo+ ICsgICAgY2FzZSBIVk1fUEFSQU1fTkVTVEVESFZNOg0KPiArICAgIGNhc2UgSFZNX1BBUkFNX1BB R0lOR19SSU5HX1BGTjoNCj4gKyAgICBjYXNlIEhWTV9QQVJBTV9NT05JVE9SX1JJTkdfUEZOOg0K PiArICAgIGNhc2UgSFZNX1BBUkFNX1NIQVJJTkdfUklOR19QRk46DQo+ICsgICAgY2FzZSBIVk1f UEFSQU1fVFJJUExFX0ZBVUxUX1JFQVNPTjoNCj4gKyAgICBjYXNlIEhWTV9QQVJBTV9JT1JFUV9T RVJWRVJfUEZOOg0KPiArICAgIGNhc2UgSFZNX1BBUkFNX05SX0lPUkVRX1NFUlZFUl9QQUdFUzoN Cj4gKyAgICBjYXNlIEhWTV9QQVJBTV9NQ0FfQ0FQOg0KPiAgICAgICAgICBpZiAoIGQgPT0gY3Vy cmVudC0+ZG9tYWluICkNCj4gICAgICAgICAgICAgIHJjID0gLUVQRVJNOw0KPiAgICAgICAgICBi cmVhazsNCj4gKw0KPiArICAgICAgICAvKiBXcml0ZWFibGUgb25seSBieSBYZW4sIGhvbGUsIGRl cHJlY2F0ZWQsIG9yIG91dC1vZi1yYW5nZS4gKi8NCj4gKyAgICBkZWZhdWx0Og0KPiArICAgICAg ICByYyA9IC1FSU5WQUw7DQo+ICsgICAgICAgIGJyZWFrOw0KPiAgICAgIH0NCj4gDQo+ICAgICAg aWYgKCByYyApDQo+IEBAIC00MTMwLDkgKzQxNTIsNiBAQCBzdGF0aWMgaW50IGh2bW9wX3NldF9w YXJhbSgNCj4gICAgICBpZiAoIGNvcHlfZnJvbV9ndWVzdCgmYSwgYXJnLCAxKSApDQo+ICAgICAg ICAgIHJldHVybiAtRUZBVUxUOw0KPiANCj4gLSAgICBpZiAoIGEuaW5kZXggPj0gSFZNX05SX1BB UkFNUyApDQo+IC0gICAgICAgIHJldHVybiAtRUlOVkFMOw0KPiAtDQoNCkFnYWluLCBJIHRoaW5r IGFuIEFTU0VSVCBoZXJlIHdvdWxkIGJlIGdvb2QuDQoNCj4gICAgICBkID0gcmN1X2xvY2tfZG9t YWluX2J5X2FueV9pZChhLmRvbWlkKTsNCj4gICAgICBpZiAoIGQgPT0gTlVMTCApDQo+ICAgICAg ICAgIHJldHVybiAtRVNSQ0g7DQo+IEBAIC00MjA5LDE1ICs0MjI4LDcgQEAgc3RhdGljIGludCBo dm1vcF9zZXRfcGFyYW0oDQo+ICAgICAgY2FzZSBIVk1fUEFSQU1fQUNQSV9JT1BPUlRTX0xPQ0FU SU9OOg0KPiAgICAgICAgICByYyA9IHBtdGltZXJfY2hhbmdlX2lvcG9ydChkLCBhLnZhbHVlKTsN Cj4gICAgICAgICAgYnJlYWs7DQo+IC0gICAgY2FzZSBIVk1fUEFSQU1fTUVNT1JZX0VWRU5UX0NS MDoNCj4gLSAgICBjYXNlIEhWTV9QQVJBTV9NRU1PUllfRVZFTlRfQ1IzOg0KPiAtICAgIGNhc2Ug SFZNX1BBUkFNX01FTU9SWV9FVkVOVF9DUjQ6DQo+IC0gICAgY2FzZSBIVk1fUEFSQU1fTUVNT1JZ X0VWRU5UX0lOVDM6DQo+IC0gICAgY2FzZSBIVk1fUEFSQU1fTUVNT1JZX0VWRU5UX1NJTkdMRV9T VEVQOg0KPiAtICAgIGNhc2UgSFZNX1BBUkFNX01FTU9SWV9FVkVOVF9NU1I6DQo+IC0gICAgICAg IC8qIERlcHJlY2F0ZWQgKi8NCj4gLSAgICAgICAgcmMgPSAtRU9QTk9UU1VQUDsNCj4gLSAgICAg ICAgYnJlYWs7DQoNCkRvZXMgYW55dGhpbmcgcmVseSBvbiB0aGlzIEVPUE5PVFNVUFAgdnMgdGhl IEVJTlZBTCB0aGF0IHdvdWxkIGJlIHJldHVybmVkIGFmdGVyIHRoaXMgcGF0Y2ggaXMgYXBwbGll ZD8NCg0KICBQYXVsDQoNCj4gKw0KPiAgICAgIGNhc2UgSFZNX1BBUkFNX05FU1RFREhWTToNCj4g ICAgICAgICAgcmMgPSB4c21faHZtX3BhcmFtX25lc3RlZChYU01fUFJJViwgZCk7DQo+ICAgICAg ICAgIGlmICggcmMgKQ0KPiBAQCAtNDI1Myw5ICs0MjY0LDcgQEAgc3RhdGljIGludCBodm1vcF9z ZXRfcGFyYW0oDQo+ICAgICAgICAgICAgICAgZC0+YXJjaC5odm0ucGFyYW1zW0hWTV9QQVJBTV9O RVNURURIVk1dICkNCj4gICAgICAgICAgICAgIHJjID0gLUVJTlZBTDsNCj4gICAgICAgICAgYnJl YWs7DQo+IC0gICAgY2FzZSBIVk1fUEFSQU1fQlVGSU9SRVFfRVZUQ0hOOg0KPiAtICAgICAgICBy YyA9IC1FSU5WQUw7DQo+IC0gICAgICAgIGJyZWFrOw0KPiArDQo+ICAgICAgY2FzZSBIVk1fUEFS QU1fVFJJUExFX0ZBVUxUX1JFQVNPTjoNCj4gICAgICAgICAgaWYgKCBhLnZhbHVlID4gU0hVVERP V05fTUFYICkNCj4gICAgICAgICAgICAgIHJjID0gLUVJTlZBTDsNCj4gLS0NCj4gMi4xLjQNCg0K X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KWGVuLWRldmVs IG1haWxpbmcgbGlzdApYZW4tZGV2ZWxAbGlzdHMueGVucHJvamVjdC5vcmcKaHR0cHM6Ly9saXN0 cy54ZW5wcm9qZWN0Lm9yZy9tYWlsbWFuL2xpc3RpbmZvL3hlbi1kZXZlbA==