Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1411144 > unrolled thread
| Started by | Paolo Bonzini <pbonzini@redhat.com> |
|---|---|
| First post | 2016-06-01 14:20 +0200 |
| Last post | 2016-06-01 18:10 +0200 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 0/7] KVM: syzkaller fixes Paolo Bonzini <pbonzini@redhat.com> - 2016-06-01 14:20 +0200
[PATCH 1/7] kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR Paolo Bonzini <pbonzini@redhat.com> - 2016-06-01 14:20 +0200
Re: [PATCH 0/7] KVM: syzkaller fixes Radim Krčmář <rkrcmar@redhat.com> - 2016-06-01 18:10 +0200
| From | Paolo Bonzini <pbonzini@redhat.com> |
|---|---|
| Date | 2016-06-01 14:20 +0200 |
| Subject | [PATCH 0/7] KVM: syzkaller fixes |
| Message-ID | <rFd8e-8fg-25@gated-at.bofh.it> |
These fix most of the bugs reported by Dmitry Vyukov a while back. I couldn't reproduce one of the bugs (patch 7) but the fix is easy. Probably, more VM ioctls should take kvm->lock, but I have not looked at it yet. I have only marked for stable the two patches that fix an oops. However, all of patches 1-6 could go in 4.7-rc, I think. Thanks, Paolo Paolo Bonzini (7): kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR KVM: x86: avoid vmalloc(0) in the KVM_SET_CPUID KVM: fail KVM_SET_VCPU_EVENTS with invalid exception number KVM: irqfd: fix NULL pointer dereference in kvm_irq_map_gsi KVM: x86: avoid vmalloc(0) in the KVM_SET_CPUID KVM: x86: fix OOPS after invalid KVM_SET_DEBUGREGS KVM: x86: protect KVM_CREATE_PIT/KVM_CREATE_PIT2 with kvm->lock arch/x86/kvm/cpuid.c | 22 ++++++++++++---------- arch/x86/kvm/i8254.c | 4 +++- arch/x86/kvm/x86.c | 15 ++++++++++++--- virt/kvm/irqchip.c | 2 +- virt/kvm/kvm_main.c | 22 ++++++++++++---------- 5 files changed, 40 insertions(+), 25 deletions(-) -- 1.8.3.1
[toc] | [next] | [standalone]
| From | Paolo Bonzini <pbonzini@redhat.com> |
|---|---|
| Date | 2016-06-01 14:20 +0200 |
| Subject | [PATCH 1/7] kvm: x86: avoid warning on repeated KVM_SET_TSS_ADDR |
| Message-ID | <rFdhT-8iE-19@gated-at.bofh.it> |
| In reply to | #1411144 |
Found by syzkaller:
WARNING: CPU: 3 PID: 15175 at arch/x86/kvm/x86.c:7705 __x86_set_memory_region+0x1dc/0x1f0 [kvm]()
CPU: 3 PID: 15175 Comm: a.out Tainted: G W 4.4.6-300.fc23.x86_64 #1
Hardware name: LENOVO 2325F51/2325F51, BIOS G2ET32WW (1.12 ) 05/30/2012
0000000000000286 00000000950899a7 ffff88011ab3fbf0 ffffffff813b542e
0000000000000000 ffffffffa0966496 ffff88011ab3fc28 ffffffff810a40f2
00000000000001fd 0000000000003000 ffff88014fc50000 0000000000000000
Call Trace:
[<ffffffff813b542e>] dump_stack+0x63/0x85
[<ffffffff810a40f2>] warn_slowpath_common+0x82/0xc0
[<ffffffff810a423a>] warn_slowpath_null+0x1a/0x20
[<ffffffffa09251cc>] __x86_set_memory_region+0x1dc/0x1f0 [kvm]
[<ffffffffa092521b>] x86_set_memory_region+0x3b/0x60 [kvm]
[<ffffffffa09bb61c>] vmx_set_tss_addr+0x3c/0x150 [kvm_intel]
[<ffffffffa092f4d4>] kvm_arch_vm_ioctl+0x654/0xbc0 [kvm]
[<ffffffffa091d31a>] kvm_vm_ioctl+0x9a/0x6f0 [kvm]
[<ffffffff81241248>] do_vfs_ioctl+0x298/0x480
[<ffffffff812414a9>] SyS_ioctl+0x79/0x90
[<ffffffff817a04ee>] entry_SYSCALL_64_fastpath+0x12/0x71
Testcase:
#include <unistd.h>
#include <sys/ioctl.h>
#include <fcntl.h>
#include <string.h>
#include <linux/kvm.h>
long r[8];
int main()
{
memset(r, -1, sizeof(r));
r[2] = open("/dev/kvm", O_RDONLY|O_TRUNC);
r[3] = ioctl(r[2], KVM_CREATE_VM, 0x0ul);
r[5] = ioctl(r[3], KVM_SET_TSS_ADDR, 0x20000000ul);
r[7] = ioctl(r[3], KVM_SET_TSS_ADDR, 0x20000000ul);
return 0;
}
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
arch/x86/kvm/x86.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 199a87c20a98..6c9793c64522 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -7828,7 +7828,7 @@ int __x86_set_memory_region(struct kvm *kvm, int id, gpa_t gpa, u32 size)
slot = id_to_memslot(slots, id);
if (size) {
- if (WARN_ON(slot->npages))
+ if (slot->npages)
return -EEXIST;
/*
--
1.8.3.1
[toc] | [prev] | [next] | [standalone]
| From | Radim Krčmář <rkrcmar@redhat.com> |
|---|---|
| Date | 2016-06-01 18:10 +0200 |
| Message-ID | <rFgSv-294-41@gated-at.bofh.it> |
| In reply to | #1411144 |
2016-06-01 14:09+0200, Paolo Bonzini: > These fix most of the bugs reported by Dmitry Vyukov a while back. > I couldn't reproduce one of the bugs (patch 7) but the fix is easy. > Probably, more VM ioctls should take kvm->lock, but I have not looked > at it yet. Applied, thanks. > I have only marked for stable the two patches that fix an oops. However, > all of patches 1-6 could go in 4.7-rc, I think. Normal userspaces don't exercise modified paths, so I'll prepare [1-6/7] for -rc1, as thorough testing wouldn't make a difference ...
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web