mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	Jan Beulich <jbeulich@novell.com>,
	Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Subject: [24/35] xen/x86: replace order-based range checking of M2P table by linear one
Date: Fri, 26 Aug 2011 14:49:41 -0700	[thread overview]
Message-ID: <20110826215055.355019099@clark.kroah.org> (raw)
In-Reply-To: <20110826215139.GA11498@kroah.com>

3.0-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Jan Beulich <JBeulich@novell.com>

commit ccbcdf7cf1b5f6c6db30d84095b9c6c53043af55 upstream.

The order-based approach is not only less efficient (requiring a shift
and a compare, typical generated code looking like this

	mov	eax, [machine_to_phys_order]
	mov	ecx, eax
	shr	ebx, cl
	test	ebx, ebx
	jnz	...

whereas a direct check requires just a compare, like in

	cmp	ebx, [machine_to_phys_nr]
	jae	...

), but also slightly dangerous in the 32-on-64 case - the element
address calculation can wrap if the next power of two boundary is
sufficiently far away from the actual upper limit of the table, and
hence can result in user space addresses being accessed (with it being
unknown what may actually be mapped there).

Additionally, the elimination of the mistaken use of fls() here (should
have been __fls()) fixes a latent issue on x86-64 that would trigger
if the code was run on a system with memory extending beyond the 44-bit
boundary.

Signed-off-by: Jan Beulich <jbeulich@novell.com>
[v1: Based on Jeremy's feedback]
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 arch/x86/include/asm/xen/page.h |    4 ++--
 arch/x86/xen/enlighten.c        |    4 ++--
 arch/x86/xen/mmu.c              |   12 ++++++++----
 3 files changed, 12 insertions(+), 8 deletions(-)

--- a/arch/x86/include/asm/xen/page.h
+++ b/arch/x86/include/asm/xen/page.h
@@ -39,7 +39,7 @@ typedef struct xpaddr {
     ((unsigned long)((u64)CONFIG_XEN_MAX_DOMAIN_MEMORY * 1024 * 1024 * 1024 / PAGE_SIZE))
 
 extern unsigned long *machine_to_phys_mapping;
-extern unsigned int   machine_to_phys_order;
+extern unsigned long  machine_to_phys_nr;
 
 extern unsigned long get_phys_to_machine(unsigned long pfn);
 extern bool set_phys_to_machine(unsigned long pfn, unsigned long mfn);
@@ -87,7 +87,7 @@ static inline unsigned long mfn_to_pfn(u
 	if (xen_feature(XENFEAT_auto_translated_physmap))
 		return mfn;
 
-	if (unlikely((mfn >> machine_to_phys_order) != 0)) {
+	if (unlikely(mfn >= machine_to_phys_nr)) {
 		pfn = ~0;
 		goto try_override;
 	}
--- a/arch/x86/xen/enlighten.c
+++ b/arch/x86/xen/enlighten.c
@@ -77,8 +77,8 @@ EXPORT_SYMBOL_GPL(xen_domain_type);
 
 unsigned long *machine_to_phys_mapping = (void *)MACH2PHYS_VIRT_START;
 EXPORT_SYMBOL(machine_to_phys_mapping);
-unsigned int   machine_to_phys_order;
-EXPORT_SYMBOL(machine_to_phys_order);
+unsigned long  machine_to_phys_nr;
+EXPORT_SYMBOL(machine_to_phys_nr);
 
 struct start_info *xen_start_info;
 EXPORT_SYMBOL_GPL(xen_start_info);
--- a/arch/x86/xen/mmu.c
+++ b/arch/x86/xen/mmu.c
@@ -1626,15 +1626,19 @@ static void __init xen_map_identity_earl
 void __init xen_setup_machphys_mapping(void)
 {
 	struct xen_machphys_mapping mapping;
-	unsigned long machine_to_phys_nr_ents;
 
 	if (HYPERVISOR_memory_op(XENMEM_machphys_mapping, &mapping) == 0) {
 		machine_to_phys_mapping = (unsigned long *)mapping.v_start;
-		machine_to_phys_nr_ents = mapping.max_mfn + 1;
+		machine_to_phys_nr = mapping.max_mfn + 1;
 	} else {
-		machine_to_phys_nr_ents = MACH2PHYS_NR_ENTRIES;
+		machine_to_phys_nr = MACH2PHYS_NR_ENTRIES;
 	}
-	machine_to_phys_order = fls(machine_to_phys_nr_ents - 1);
+#ifdef CONFIG_X86_32
+	if ((machine_to_phys_mapping + machine_to_phys_nr)
+	    < machine_to_phys_mapping)
+		machine_to_phys_nr = (unsigned long *)NULL
+				     - machine_to_phys_mapping;
+#endif
 }
 
 #ifdef CONFIG_X86_64



  parent reply	other threads:[~2011-08-27 14:58 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-08-26 21:51 [00/35] 3.0.4-stable review Greg KH
2011-08-26 21:49 ` [01/35] genirq: Fix wrong bit operation Greg KH
2011-08-26 21:49 ` [02/35] cifs: demote cERROR in build_path_from_dentry to cFYI Greg KH
2011-08-26 21:49 ` [03/35] befs: Validate length of long symbolic links Greg KH
2011-08-26 21:49 ` [04/35] i7core_edac: fixed typo in error count calculation Greg KH
2011-08-26 21:49 ` [05/35] [CIFS] possible memory corruption on mount Greg KH
2011-08-26 21:49 ` [06/35] x86, intel, power: Correct the MSR_IA32_ENERGY_PERF_BIAS message Greg KH
2011-08-26 21:49 ` [07/35] pnfs-obj: Fix the comp_index != 0 case Greg KH
2011-08-26 21:49 ` [08/35] pnfs-obj: Bug when we are running out of bio Greg KH
2011-08-26 21:49 ` [09/35] NFSv4.1: Fix the callback highest_used_slotid behaviour Greg KH
2011-08-26 21:49 ` [10/35] NFSv4.1: Return NFS4ERR_BADSESSION to callbacks during session resets Greg KH
2011-08-26 21:49 ` [11/35] x86, mtrr: lock stop machine during MTRR rendezvous sequence Greg KH
2011-08-26 21:49 ` [12/35] Btrfs: detect wether a device supports discard Greg KH
2011-08-26 21:49 ` [13/35] loop: fix deadlock when sysfs and LOOP_CLR_FD race against each other Greg KH
2011-08-26 21:49 ` [14/35] Btrfs: fix an oops of log replay Greg KH
2011-08-26 21:49 ` [15/35] ALSA: usb-audio - Fix missing mixer dB information Greg KH
2011-08-26 21:49 ` [16/35] ALSA: snd_usb_caiaq: track submitted output urbs Greg KH
2011-08-26 21:49 ` [17/35] ALSA: ac97: Add HP Compaq dc5100 SFF(PT003AW) to Headphone Jack Sense whitelist Greg KH
2011-08-26 21:49 ` [18/35] ext4: Fix ext4_should_writeback_data() for no-journal mode Greg KH
2011-08-26 21:49 ` [19/35] ext4: call ext4_ioend_wait and ext4_flush_completed_IO in ext4_evict_inode Greg KH
2011-08-26 21:49 ` [20/35] ext4: Resolve the hang of direct i/o read in handling EXT4_IO_END_UNWRITTEN Greg KH
2011-08-26 21:49 ` [21/35] ext4: fix nomblk_io_submit option so it correctly converts uninit blocks Greg KH
2011-08-26 21:49 ` [22/35] xen-blkfront: Drop name and minor adjustments for emulated scsi devices Greg KH
2011-08-26 21:49 ` [23/35] xen-blkfront: Fix one off warning about name clash Greg KH
2011-08-26 21:49 ` Greg KH [this message]
2011-08-26 21:49 ` [25/35] xen: Do not enable PV IPIs when vector callback not present Greg KH
2011-08-26 21:49 ` [26/35] x86, olpc: Wait for last byte of EC command to be accepted Greg KH
2011-08-26 21:49 ` [27/35] x86-32, vdso: On system call restart after SYSENTER, use int $0x80 Greg KH
2011-08-26 21:49 ` [28/35] x86, UV: Remove UV delay in starting slave cpus Greg KH
2011-08-26 21:49 ` [29/35] drm/ttm: fix ttm_bo_add_ttm(user) failure path Greg KH
2011-08-26 21:49 ` [30/35] drm/radeon: Extended DDC Probing for Toshiba L300D Radeon Mobility X1100 HDMI-A Connector Greg KH
2011-08-26 21:49 ` [31/35] fuse: check size of FUSE_NOTIFY_INVAL_ENTRY message Greg KH
2011-08-26 21:49 ` [32/35] rt2x00: fix order of entry flags modification Greg KH
2011-08-29  8:29   ` Stanislaw Gruszka
2011-08-30 21:53     ` [stable] " Greg KH
2011-08-26 21:49 ` [33/35] mmc: sdhci: fix retuning timer wrongly deleted in sdhci_tasklet_finish Greg KH
2011-08-26 21:49 ` [34/35] igb: Fix lack of flush after register write and before delay Greg KH
2011-08-26 21:49 ` [35/35] Add a personality to report 2.6.x version numbers Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110826215055.355019099@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=jbeulich@novell.com \
    --cc=konrad.wilk@oracle.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®