Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1411144 > unrolled thread

[PATCH 0/7] KVM: syzkaller fixes

Started byPaolo Bonzini <pbonzini@redhat.com>
First post2016-06-01 14:20 +0200
Last post2016-06-01 18:10 +0200
Articles 3 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 0/7] KVM: syzkaller fixes Paolo Bonzini <pbonzini@redhat.com> - 2016-06-01 14:20 +0200
    [PATCH 1/7] kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR Paolo Bonzini <pbonzini@redhat.com> - 2016-06-01 14:20 +0200
    Re: [PATCH 0/7] KVM: syzkaller fixes Radim Krčmář <rkrcmar@redhat.com> - 2016-06-01 18:10 +0200

#1411144 — [PATCH 0/7] KVM: syzkaller fixes

FromPaolo Bonzini <pbonzini@redhat.com>
Date2016-06-01 14:20 +0200
Subject[PATCH 0/7] KVM: syzkaller fixes
Message-ID<rFd8e-8fg-25@gated-at.bofh.it>
These fix most of the bugs reported by Dmitry Vyukov a while back.
I couldn't reproduce one of the bugs (patch 7) but the fix is easy.
Probably, more VM ioctls should take kvm->lock, but I have not looked
at it yet.

I have only marked for stable the two patches that fix an oops.  However,
all of patches 1-6 could go in 4.7-rc, I think.

Thanks,

Paolo

Paolo Bonzini (7):
  kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR
  KVM: x86: avoid vmalloc(0) in the KVM_SET_CPUID
  KVM: fail KVM_SET_VCPU_EVENTS with invalid exception number
  KVM: irqfd: fix NULL pointer dereference in kvm_irq_map_gsi
  KVM: x86: avoid vmalloc(0) in the KVM_SET_CPUID
  KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS
  KVM: x86: protect KVM_CREATE_PIT/KVM_CREATE_PIT2 with kvm->lock

 arch/x86/kvm/cpuid.c |   22 ++++++++++++----------
 arch/x86/kvm/i8254.c |    4 +++-
 arch/x86/kvm/x86.c   |   15 ++++++++++++---
 virt/kvm/irqchip.c   |    2 +-
 virt/kvm/kvm_main.c  |   22 ++++++++++++----------
 5 files changed, 40 insertions(+), 25 deletions(-)

-- 
1.8.3.1

[toc] | [next] | [standalone]


#1411147 — [PATCH 1/7] kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR

FromPaolo Bonzini <pbonzini@redhat.com>
Date2016-06-01 14:20 +0200
Subject[PATCH 1/7] kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR
Message-ID<rFdhT-8iE-19@gated-at.bofh.it>
In reply to#1411144
Found by syzkaller:

    WARNING: CPU: 3 PID: 15175 at arch/x86/kvm/x86.c:7705 __x86_set_memory_region+0x1dc/0x1f0 [kvm]()
    CPU: 3 PID: 15175 Comm: a.out Tainted: G        W       4.4.6-300.fc23.x86_64 #1
    Hardware name: LENOVO 2325F51/2325F51, BIOS G2ET32WW (1.12 ) 05/30/2012
     0000000000000286 00000000950899a7 ffff88011ab3fbf0 ffffffff813b542e
     0000000000000000 ffffffffa0966496 ffff88011ab3fc28 ffffffff810a40f2
     00000000000001fd 0000000000003000 ffff88014fc50000 0000000000000000
    Call Trace:
     [<ffffffff813b542e>] dump_stack+0x63/0x85
     [<ffffffff810a40f2>] warn_slowpath_common+0x82/0xc0
     [<ffffffff810a423a>] warn_slowpath_null+0x1a/0x20
     [<ffffffffa09251cc>] __x86_set_memory_region+0x1dc/0x1f0 [kvm]
     [<ffffffffa092521b>] x86_set_memory_region+0x3b/0x60 [kvm]
     [<ffffffffa09bb61c>] vmx_set_tss_addr+0x3c/0x150 [kvm_intel]
     [<ffffffffa092f4d4>] kvm_arch_vm_ioctl+0x654/0xbc0 [kvm]
     [<ffffffffa091d31a>] kvm_vm_ioctl+0x9a/0x6f0 [kvm]
     [<ffffffff81241248>] do_vfs_ioctl+0x298/0x480
     [<ffffffff812414a9>] SyS_ioctl+0x79/0x90
     [<ffffffff817a04ee>] entry_SYSCALL_64_fastpath+0x12/0x71

Testcase:

    #include <unistd.h>
    #include <sys/ioctl.h>
    #include <fcntl.h>
    #include <string.h>
    #include <linux/kvm.h>

    long r[8];

    int main()
    {
        memset(r, -1, sizeof(r));
	r[2] = open("/dev/kvm", O_RDONLY|O_TRUNC);
        r[3] = ioctl(r[2], KVM_CREATE_VM, 0x0ul);
        r[5] = ioctl(r[3], KVM_SET_TSS_ADDR, 0x20000000ul);
        r[7] = ioctl(r[3], KVM_SET_TSS_ADDR, 0x20000000ul);
        return 0;
    }

Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 arch/x86/kvm/x86.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 199a87c20a98..6c9793c64522 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -7828,7 +7828,7 @@ int __x86_set_memory_region(struct kvm *kvm, int id, gpa_t gpa, u32 size)
 
 	slot = id_to_memslot(slots, id);
 	if (size) {
-		if (WARN_ON(slot->npages))
+		if (slot->npages)
 			return -EEXIST;
 
 		/*
-- 
1.8.3.1

[toc] | [prev] | [next] | [standalone]


#1411372

FromRadim Krčmář <rkrcmar@redhat.com>
Date2016-06-01 18:10 +0200
Message-ID<rFgSv-294-41@gated-at.bofh.it>
In reply to#1411144
2016-06-01 14:09+0200, Paolo Bonzini:
> These fix most of the bugs reported by Dmitry Vyukov a while back.
> I couldn't reproduce one of the bugs (patch 7) but the fix is easy.
> Probably, more VM ioctls should take kvm->lock, but I have not looked
> at it yet.

Applied, thanks.

> I have only marked for stable the two patches that fix an oops.  However,
> all of patches 1-6 could go in 4.7-rc, I think.

Normal userspaces don't exercise modified paths, so I'll prepare [1-6/7]
for -rc1, as thorough testing wouldn't make a difference ...

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web