From: Joerg Roedel <joerg.roedel@amd.com>
To: Avi Kivity <avi@redhat.com>, Marcelo Tosatti <mtosatti@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
Joerg Roedel <joerg.roedel@amd.com>,
stable@kernel.org
Subject: [PATCH 06/11] KVM: SVM: Fix nested msr intercept handling
Date: Fri, 19 Feb 2010 16:23:05 +0100 [thread overview]
Message-ID: <1266592990-8911-7-git-send-email-joerg.roedel@amd.com> (raw)
In-Reply-To: <1266592990-8911-1-git-send-email-joerg.roedel@amd.com>
The nested_svm_exit_handled_msr() function maps only one
page of the guests msr permission bitmap. This patch changes
the code to use kvm_read_guest to fix the bug.
Cc: stable@kernel.org
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
---
arch/x86/kvm/svm.c | 13 +++----------
1 files changed, 3 insertions(+), 10 deletions(-)
diff --git a/arch/x86/kvm/svm.c b/arch/x86/kvm/svm.c
index 4becefd..f22ced1 100644
--- a/arch/x86/kvm/svm.c
+++ b/arch/x86/kvm/svm.c
@@ -1456,19 +1456,13 @@ static bool nested_svm_exit_handled_msr(struct vcpu_svm *svm)
{
u32 param = svm->vmcb->control.exit_info_1 & 1;
u32 msr = svm->vcpu.arch.regs[VCPU_REGS_RCX];
- struct page *page;
bool ret = false;
u32 t0, t1;
- u8 *msrpm;
+ u8 val;
if (!(svm->nested.intercept & (1ULL << INTERCEPT_MSR_PROT)))
return false;
- msrpm = nested_svm_map(svm, svm->nested.vmcb_msrpm, &page);
-
- if (!msrpm)
- goto out;
-
switch (msr) {
case 0 ... 0x1fff:
t0 = (msr * 2) % 8;
@@ -1489,11 +1483,10 @@ static bool nested_svm_exit_handled_msr(struct vcpu_svm *svm)
goto out;
}
- ret = msrpm[t1] & ((1 << param) << t0);
+ if (!kvm_read_guest(svm->vcpu.kvm, svm->nested.vmcb_msrpm + t1, &val, 1))
+ ret = val & ((1 << param) << t0);
out:
- nested_svm_unmap(page);
-
return ret;
}
--
1.6.6
next prev parent reply other threads:[~2010-02-19 15:30 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-02-19 15:22 [PATCH 0/11] Nested SVM fixes v2 Joerg Roedel
2010-02-19 15:23 ` [PATCH 01/11] KVM: SVM: Don't use kmap_atomic in nested_svm_map Joerg Roedel
2010-02-19 15:23 ` [PATCH 02/11] KVM: SVM: Fix wrong interrupt injection in enable_irq_windows Joerg Roedel
2010-02-22 10:29 ` Joerg Roedel
2010-02-22 11:05 ` Avi Kivity
2010-02-19 15:23 ` [PATCH 03/11] KVM: SVM: Fix schedule-while-atomic on nested exception handling Joerg Roedel
2010-02-19 15:23 ` [PATCH 04/11] KVM: SVM: Sync all control registers on nested vmexit Joerg Roedel
2010-02-19 15:23 ` [PATCH 05/11] KVM: SVM: Annotate nested_svm_map with might_sleep() Joerg Roedel
2010-02-19 15:23 ` Joerg Roedel [this message]
2010-02-19 15:23 ` [PATCH 07/11] KVM: SVM: Don't sync nested cr8 to lapic and back Joerg Roedel
2010-02-19 15:23 ` [PATCH 08/11] KVM: SVM: Activate nested state only when guest state is complete Joerg Roedel
2010-02-19 15:23 ` [PATCH 09/11] KVM: SVM: Make lazy FPU switching work with nested svm Joerg Roedel
2010-02-19 15:23 ` [PATCH 10/11] KVM: SVM: Remove newlines from nested trace points Joerg Roedel
2010-02-19 15:23 ` [PATCH 11/11] KVM: SVM: Don't call instruction emulator for invd and wbinvd Joerg Roedel
2010-02-21 9:53 ` Avi Kivity
2010-02-21 11:37 ` Joerg Roedel
2010-02-21 12:00 ` Avi Kivity
2010-02-21 12:12 ` Joerg Roedel
2010-02-21 9:56 ` [PATCH 0/11] Nested SVM fixes v2 Avi Kivity
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1266592990-8911-7-git-send-email-joerg.roedel@amd.com \
--to=joerg.roedel@amd.com \
--cc=avi@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mtosatti@redhat.com \
--cc=stable@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®