Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1358855
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.12 55/58] xen/pciback: Do not install an IRQ handler for MSI interrupts. |
| Date | 2016-03-16 12:10 +0100 |
| Message-ID | <rdhuY-896-69@gated-at.bofh.it> (permalink) |
| References | <rdhlg-7Px-15@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
From: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit a396f3a210c3a61e94d6b87ec05a75d0be2a60d0 upstream.
Otherwise an guest can subvert the generic MSI code to trigger
an BUG_ON condition during MSI interrupt freeing:
for (i = 0; i < entry->nvec_used; i++)
BUG_ON(irq_has_action(entry->irq + i));
Xen PCI backed installs an IRQ handler (request_irq) for
the dev->irq whenever the guest writes PCI_COMMAND_MEMORY
(or PCI_COMMAND_IO) to the PCI_COMMAND register. This is
done in case the device has legacy interrupts the GSI line
is shared by the backend devices.
To subvert the backend the guest needs to make the backend
to change the dev->irq from the GSI to the MSI interrupt line,
make the backend allocate an interrupt handler, and then command
the backend to free the MSI interrupt and hit the BUG_ON.
Since the backend only calls 'request_irq' when the guest
writes to the PCI_COMMAND register the guest needs to call
XEN_PCI_OP_enable_msi before any other operation. This will
cause the generic MSI code to setup an MSI entry and
populate dev->irq with the new PIRQ value.
Then the guest can write to PCI_COMMAND PCI_COMMAND_MEMORY
and cause the backend to setup an IRQ handler for dev->irq
(which instead of the GSI value has the MSI pirq). See
'xen_pcibk_control_isr'.
Then the guest disables the MSI: XEN_PCI_OP_disable_msi
which ends up triggering the BUG_ON condition in 'free_msi_irqs'
as there is an IRQ handler for the entry->irq (dev->irq).
Note that this cannot be done using MSI-X as the generic
code does not over-write dev->irq with the MSI-X PIRQ values.
The patch inhibits setting up the IRQ handler if MSI or
MSI-X (for symmetry reasons) code had been called successfully.
P.S.
Xen PCIBack when it sets up the device for the guest consumption
ends up writting 0 to the PCI_COMMAND (see xen_pcibk_reset_device).
XSA-120 addendum patch removed that - however when upstreaming said
addendum we found that it caused issues with qemu upstream. That
has now been fixed in qemu upstream.
This is part of XSA-157
Reviewed-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/xen/xen-pciback/pciback_ops.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/xen/xen-pciback/pciback_ops.c b/drivers/xen/xen-pciback/pciback_ops.c
index 32cbafcece76..dc939671ba5f 100644
--- a/drivers/xen/xen-pciback/pciback_ops.c
+++ b/drivers/xen/xen-pciback/pciback_ops.c
@@ -70,6 +70,13 @@ static void xen_pcibk_control_isr(struct pci_dev *dev, int reset)
enable ? "enable" : "disable");
if (enable) {
+ /*
+ * The MSI or MSI-X should not have an IRQ handler. Otherwise
+ * if the guest terminates we BUG_ON in free_msi_irqs.
+ */
+ if (dev->msi_enabled || dev->msix_enabled)
+ goto out;
+
rc = request_irq(dev_data->irq,
xen_pcibk_guest_interrupt, IRQF_SHARED,
dev_data->irq_name, dev);
--
2.7.3
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.12 00/58] 3.12.57-stable review Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:00 +0100
[PATCH 3.12 01/58] nfsd: fix problem with setting ACL on directories Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:00 +0100
[PATCH 3.12 44/58] KVM: x86: move steal time initialization to vcpu entry time Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 48/58] efi: Make our variable validation list include the guid Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 15/58] x86/entry/compat: Add missing CLAC to entry_INT80_32 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 34/58] MIPS: traps: Fix SIGFPE information leak from `do_ov' and `do_trap_or_bp' Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 29/58] ALSA: hdspm: Fix zero-division Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 43/58] powerpc: Fix dedotify for binutils >= 2.26 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 40/58] ASoC: wm8958: Fix enum ctl accesses in a wrong type Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 37/58] KVM: VMX: disable PEBS before a guest entry Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 42/58] mac80211: minstrel_ht: set default tx aggregation timeout to 0 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 47/58] efi: Do variable name validation tests in utf8 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 33/58] USB: serial: option: add support for Quectel UC20 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 57/58] xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set. Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 27/58] ALSA: hdspm: Fix wrong boolean ctl value accesses Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 13/58] CIFS: Fix SMB2+ interim response processing for read requests Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 46/58] efi: Use ucs2_as_utf8 in efivarfs instead of open coding a bad version Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 20/58] Revert "jffs2: Fix lock acquisition order bug in jffs2_write_begin" Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 45/58] lib/ucs2_string: Add ucs2 -> utf8 helper functions Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 38/58] tracing: Fix check for cpu online when event is disabled Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 12/58] cifs: fix out-of-bounds access in lease parsing Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 28/58] ALSA: hdsp: Fix wrong boolean ctl value accesses Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 36/58] Revert "drm/radeon: hold reference to fences in radeon_sa_bo_new" Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
Re: [PATCH 3.12 36/58] Revert "drm/radeon: hold reference to fences in radeon_sa_bo_new" Nicolai Hähnle <nicolai.haehnle@amd.com> - 2016-03-16 20:50 +0100
[PATCH 3.12 53/58] xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 56/58] xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled. Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 39/58] ASoC: wm8994: Fix enum ctl accesses in a wrong type Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 50/58] efi: Add pstore variables to the deletion whitelist Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 58/58] xen/pciback: Check PF instead of VF for PCI_COMMAND_MEMORY Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 55/58] xen/pciback: Do not install an IRQ handler for MSI interrupts. Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 32/58] USB: serial: option: add support for Telit LE922 PID 0x1045 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 35/58] ubi: Fix out of bounds write in volume update code Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 41/58] wext: fix message delay/ordering Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 49/58] efi: Make efivarfs entries immutable by default Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 31/58] USB: cp210x: Add ID for Parrot NMEA GPS Flight Recorder Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 54/58] xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 52/58] modules: fix longstanding /proc/kallsyms vs module insertion race. Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 51/58] lib/ucs2_string: Correct ucs2 -> utf8 conversion Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:10 +0100
[PATCH 3.12 16/58] drm/ast: Fix incorrect register check for DRAM width Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 21/58] jffs2: Fix page lock / f->sem deadlock Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 07/58] [media] usbvision fix overflow of interfaces array Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 04/58] USB: cp210x: flush device queues at close Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 18/58] libata: Align ata_device's id on a cacheline Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 11/58] genksyms: Handle string literals with spaces in reference files Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 17/58] libata: fix HDIO_GET_32BIT ioctl Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 09/58] ixgbe: use correct FCoE DDP max check Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 10/58] ixgbe: fix broken PFC with X550 Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 26/58] ALSA: seq: oss: Don't drain at closing a client Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 23/58] ALSA: ctl: Fix ioctls for X32 ABI Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 02/58] unix: properly account for FDs passed over unix sockets Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 25/58] ALSA: timer: Fix ioctls for X32 ABI Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 05/58] USB: cp210x: relocate private data from USB interface to port Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 19/58] PM / sleep / x86: Fix crash on graph trace through x86 suspend Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 24/58] ALSA: rawmidi: Fix ioctls X32 ABI Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 14/58] iommu/amd: Fix boot warning when device 00:00.0 is not iommu covered Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 22/58] Fix directory hardlinks from deleted directories Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 30/58] ALSA: timer: Fix broken compat timer user status ioctl Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 06/58] USB: cp210x: work around cp2108 GET_LINE_CTL bug Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
[PATCH 3.12 08/58] usb: Add connected retry on resume for non SS devices Jiri Slaby <jslaby@suse.cz> - 2016-03-16 12:20 +0100
Re: [PATCH 3.12 01/58] nfsd: fix problem with setting ACL on directories Sergio Gelato <Sergio.Gelato@astro.su.se> - 2016-03-16 13:40 +0100
Re: [PATCH 3.12 00/58] 3.12.57-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-03-16 16:50 +0100
Re: [PATCH 3.12 00/58] 3.12.57-stable review Guenter Roeck <linux@roeck-us.net> - 2016-03-16 19:00 +0100
Re: [PATCH 3.12 00/58] 3.12.57-stable review Jiri Slaby <jslaby@suse.cz> - 2016-03-16 19:20 +0100
Re: [PATCH 3.12 00/58] 3.12.57-stable review Guenter Roeck <linux@roeck-us.net> - 2016-03-17 04:30 +0100
csiph-web