Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1695558 > unrolled thread

[PATCH 0/3] fix xen hvm guest with kaslr enabled

Started byJuergen Gross <jgross@suse.com>
First post2017-07-25 12:00 +0200
Last post2017-07-25 16:50 +0200
Articles 5 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 0/3] fix xen hvm guest with kaslr enabled Juergen Gross <jgross@suse.com> - 2017-07-25 12:00 +0200
    [PATCH 3/3] xen: fix hvm guest with kaslr enabled Juergen Gross <jgross@suse.com> - 2017-07-25 12:00 +0200
    [PATCH 2/3] xen: split up xen_hvm_init_shared_info() Juergen Gross <jgross@suse.com> - 2017-07-25 12:00 +0200
      Re: [PATCH 2/3] xen: split up xen_hvm_init_shared_info() Boris Ostrovsky <boris.ostrovsky@oracle.com> - 2017-07-25 16:20 +0200
        Re: [PATCH 2/3] xen: split up xen_hvm_init_shared_info() Juergen Gross <jgross@suse.com> - 2017-07-25 16:50 +0200

#1695558 — [PATCH 0/3] fix xen hvm guest with kaslr enabled

FromJuergen Gross <jgross@suse.com>
Date2017-07-25 12:00 +0200
Subject[PATCH 0/3] fix xen hvm guest with kaslr enabled
Message-ID<u74Nb-1aa-11@gated-at.bofh.it>
This patch series fixes a regression introduced in 4.13-rc1: A Xen
HVM guest with KASLR enabled wouldn't boot any longer due to the usage
of __va() before kernel_randomize_memory() was called.

Juergen Gross (3):
  x86: provide an init_mem_mapping hypervisor hook
  xen: split up xen_hvm_init_shared_info()
  xen: fix hvm guest with kaslr enabled

 arch/x86/include/asm/hypervisor.h | 10 +++++++
 arch/x86/mm/init.c                |  3 ++
 arch/x86/xen/enlighten_hvm.c      | 59 ++++++++++++++++++++++++---------------
 3 files changed, 50 insertions(+), 22 deletions(-)

-- 
2.12.3

[toc] | [next] | [standalone]


#1695559 — [PATCH 3/3] xen: fix hvm guest with kaslr enabled

FromJuergen Gross <jgross@suse.com>
Date2017-07-25 12:00 +0200
Subject[PATCH 3/3] xen: fix hvm guest with kaslr enabled
Message-ID<u74Nc-1aa-25@gated-at.bofh.it>
In reply to#1695558
A Xen HVM guest running with KASLR enabled will die rather soon today
due to the shared info page mapping is using va() too early. This was
introduced by commit a5d5f328b0e2baa5ee7c119fd66324eb79eeeb66 ("xen:
allocate page for shared info page from low memory").

In order to fix this use early_memremap() to get a temporary virtual
address for shared info until va() can be used safely.

Signed-off-by: Juergen Gross <jgross@suse.com>
---
 arch/x86/xen/enlighten_hvm.c | 16 ++++++++++++++--
 1 file changed, 14 insertions(+), 2 deletions(-)

diff --git a/arch/x86/xen/enlighten_hvm.c b/arch/x86/xen/enlighten_hvm.c
index d23531f5f17e..de503c225ae1 100644
--- a/arch/x86/xen/enlighten_hvm.c
+++ b/arch/x86/xen/enlighten_hvm.c
@@ -12,6 +12,7 @@
 #include <asm/setup.h>
 #include <asm/hypervisor.h>
 #include <asm/e820/api.h>
+#include <asm/early_ioremap.h>
 
 #include <asm/xen/cpuid.h>
 #include <asm/xen/hypervisor.h>
@@ -21,6 +22,8 @@
 #include "mmu.h"
 #include "smp.h"
 
+static unsigned long shared_info_pfn;
+
 void xen_hvm_init_shared_info(void)
 {
 	struct xen_add_to_physmap xatp;
@@ -28,7 +31,7 @@ void xen_hvm_init_shared_info(void)
 	xatp.domid = DOMID_SELF;
 	xatp.idx = 0;
 	xatp.space = XENMAPSPACE_shared_info;
-	xatp.gpfn = virt_to_pfn(HYPERVISOR_shared_info);
+	xatp.gpfn = shared_info_pfn;
 	if (HYPERVISOR_memory_op(XENMEM_add_to_physmap, &xatp))
 		BUG();
 }
@@ -51,8 +54,16 @@ static void __init reserve_shared_info(void)
 	     pa += PAGE_SIZE)
 		;
 
+	shared_info_pfn = PHYS_PFN(pa);
+
 	memblock_reserve(pa, PAGE_SIZE);
-	HYPERVISOR_shared_info = __va(pa);
+	HYPERVISOR_shared_info = early_memremap(pa, PAGE_SIZE);
+}
+
+static void __init xen_hvm_init_mem_mapping(void)
+{
+	early_memunmap(HYPERVISOR_shared_info, PAGE_SIZE);
+	HYPERVISOR_shared_info = __va(PFN_PHYS(shared_info_pfn));
 }
 
 static void __init init_hvm_pv_info(void)
@@ -221,5 +232,6 @@ const struct hypervisor_x86 x86_hyper_xen_hvm = {
 	.init_platform          = xen_hvm_guest_init,
 	.pin_vcpu               = xen_pin_vcpu,
 	.x2apic_available       = xen_x2apic_para_available,
+	.init_mem_mapping	= xen_hvm_init_mem_mapping,
 };
 EXPORT_SYMBOL(x86_hyper_xen_hvm);
-- 
2.12.3

[toc] | [prev] | [next] | [standalone]


#1695560 — [PATCH 2/3] xen: split up xen_hvm_init_shared_info()

FromJuergen Gross <jgross@suse.com>
Date2017-07-25 12:00 +0200
Subject[PATCH 2/3] xen: split up xen_hvm_init_shared_info()
Message-ID<u74Nc-1aa-27@gated-at.bofh.it>
In reply to#1695558
Instead of calling xen_hvm_init_shared_info() on boot and resume split
it up into a boot time function searching for the pfn to use and a
mapping function doing the hypervisor mapping call.

Signed-off-by: Juergen Gross <jgross@suse.com>
---
 arch/x86/xen/enlighten_hvm.c | 45 +++++++++++++++++++++++---------------------
 1 file changed, 24 insertions(+), 21 deletions(-)

diff --git a/arch/x86/xen/enlighten_hvm.c b/arch/x86/xen/enlighten_hvm.c
index 87d791356ea9..d23531f5f17e 100644
--- a/arch/x86/xen/enlighten_hvm.c
+++ b/arch/x86/xen/enlighten_hvm.c
@@ -21,29 +21,9 @@
 #include "mmu.h"
 #include "smp.h"
 
-void __ref xen_hvm_init_shared_info(void)
+void xen_hvm_init_shared_info(void)
 {
 	struct xen_add_to_physmap xatp;
-	u64 pa;
-
-	if (HYPERVISOR_shared_info == &xen_dummy_shared_info) {
-		/*
-		 * Search for a free page starting at 4kB physical address.
-		 * Low memory is preferred to avoid an EPT large page split up
-		 * by the mapping.
-		 * Starting below X86_RESERVE_LOW (usually 64kB) is fine as
-		 * the BIOS used for HVM guests is well behaved and won't
-		 * clobber memory other than the first 4kB.
-		 */
-		for (pa = PAGE_SIZE;
-		     !e820__mapped_all(pa, pa + PAGE_SIZE, E820_TYPE_RAM) ||
-		     memblock_is_reserved(pa);
-		     pa += PAGE_SIZE)
-			;
-
-		memblock_reserve(pa, PAGE_SIZE);
-		HYPERVISOR_shared_info = __va(pa);
-	}
 
 	xatp.domid = DOMID_SELF;
 	xatp.idx = 0;
@@ -53,6 +33,28 @@ void __ref xen_hvm_init_shared_info(void)
 		BUG();
 }
 
+static void __init reserve_shared_info(void)
+{
+	u64 pa;
+
+	/*
+	 * Search for a free page starting at 4kB physical address.
+	 * Low memory is preferred to avoid an EPT large page split up
+	 * by the mapping.
+	 * Starting below X86_RESERVE_LOW (usually 64kB) is fine as
+	 * the BIOS used for HVM guests is well behaved and won't
+	 * clobber memory other than the first 4kB.
+	 */
+	for (pa = PAGE_SIZE;
+	     !e820__mapped_all(pa, pa + PAGE_SIZE, E820_TYPE_RAM) ||
+	     memblock_is_reserved(pa);
+	     pa += PAGE_SIZE)
+		;
+
+	memblock_reserve(pa, PAGE_SIZE);
+	HYPERVISOR_shared_info = __va(pa);
+}
+
 static void __init init_hvm_pv_info(void)
 {
 	int major, minor;
@@ -153,6 +155,7 @@ static void __init xen_hvm_guest_init(void)
 
 	init_hvm_pv_info();
 
+	reserve_shared_info();
 	xen_hvm_init_shared_info();
 
 	/*
-- 
2.12.3

[toc] | [prev] | [next] | [standalone]


#1695778 — Re: [PATCH 2/3] xen: split up xen_hvm_init_shared_info()

FromBoris Ostrovsky <boris.ostrovsky@oracle.com>
Date2017-07-25 16:20 +0200
SubjectRe: [PATCH 2/3] xen: split up xen_hvm_init_shared_info()
Message-ID<u78QO-3RN-31@gated-at.bofh.it>
In reply to#1695560
On 07/25/2017 05:50 AM, Juergen Gross wrote:
>  
> -void __ref xen_hvm_init_shared_info(void)
> +void xen_hvm_init_shared_info(void)

Why are you dropping __ref?

-boris

[toc] | [prev] | [next] | [standalone]


#1695797 — Re: [PATCH 2/3] xen: split up xen_hvm_init_shared_info()

FromJuergen Gross <jgross@suse.com>
Date2017-07-25 16:50 +0200
SubjectRe: [PATCH 2/3] xen: split up xen_hvm_init_shared_info()
Message-ID<u79jQ-420-9@gated-at.bofh.it>
In reply to#1695778
On 25/07/17 16:19, Boris Ostrovsky wrote:
> On 07/25/2017 05:50 AM, Juergen Gross wrote:
>>  
>> -void __ref xen_hvm_init_shared_info(void)
>> +void xen_hvm_init_shared_info(void)
> 
> Why are you dropping __ref?

The function no longer calls any __init function.


Juergen

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web