lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Thu, 15 Sep 2016 17:25:13 +0200
From:   Radim Krčmář <rkrcmar@...hat.com>
To:     Paolo Bonzini <pbonzini@...hat.com>
Cc:     linux-kernel@...r.kernel.org, kvm@...r.kernel.org,
        Joerg Roedel <jroedel@...e.de>,
        David Gilbert <dgilbert@...hat.com>
Subject: Re: [PATCH] kvm: x86: correctly reset dest_map->vector when
 restoring LAPIC state

2016-09-14 23:48+0200, Paolo Bonzini:
> When userspace sends KVM_SET_LAPIC, KVM schedules a check between
> the vCPU's IRR and ISR and the IOAPIC redirection table, in order
> to re-establish the IOAPIC's dest_map (the list of CPUs servicing
> the real-time clock interrupt with the corresponding vectors).
> 
> However, __rtc_irq_eoi_tracking_restore_one was forgetting to
> set dest_map->vectors.  Because of this, the IOAPIC did not process
> the real-time clock interrupt EOI, ioapic->rtc_status.pending_eoi
> got stuck at a non-zero value, and further RTC interrupts were
> reported to userspace as coalesced.
> 
> Fixes: 9e4aabe2bb3454c83dac8139cf9974503ee044db
> Fixes: 4d99ba898dd0c521ca6cdfdde55c9b58aea3cb3d
> Cc: Joerg Roedel <jroedel@...e.de>
> Cc: David Gilbert <dgilbert@...hat.com>
> Cc: Radim Krčmář <rkrcmar@...hat.com>
> Signed-off-by: Paolo Bonzini <pbonzini@...hat.com>
> ---

Nice catch,

Reviewed-by: Radim Krčmář <rkrcmar@...hat.com>

(It is sad that the RTC EOI tracking exists ...)

>  arch/x86/kvm/ioapic.c | 8 +++++---
>  1 file changed, 5 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/x86/kvm/ioapic.c b/arch/x86/kvm/ioapic.c
> index 5f42d038fcb4..c7220ba94aa7 100644
> --- a/arch/x86/kvm/ioapic.c
> +++ b/arch/x86/kvm/ioapic.c
> @@ -109,6 +109,7 @@ static void __rtc_irq_eoi_tracking_restore_one(struct kvm_vcpu *vcpu)
>  {
>  	bool new_val, old_val;
>  	struct kvm_ioapic *ioapic = vcpu->kvm->arch.vioapic;
> +	struct dest_map *dest_map = &ioapic->rtc_status.dest_map;
>  	union kvm_ioapic_redirect_entry *e;
>  
>  	e = &ioapic->redirtbl[RTC_GSI];
> @@ -117,16 +118,17 @@ static void __rtc_irq_eoi_tracking_restore_one(struct kvm_vcpu *vcpu)
>  		return;
>  
>  	new_val = kvm_apic_pending_eoi(vcpu, e->fields.vector);
> -	old_val = test_bit(vcpu->vcpu_id, ioapic->rtc_status.dest_map.map);
> +	old_val = test_bit(vcpu->vcpu_id, dest_map->map);
>  
>  	if (new_val == old_val)
>  		return;
>  
>  	if (new_val) {
> -		__set_bit(vcpu->vcpu_id, ioapic->rtc_status.dest_map.map);
> +		__set_bit(vcpu->vcpu_id, dest_map->map);
> +		dest_map->vectors[vcpu->vcpu_id] = e->fields.vector;
>  		ioapic->rtc_status.pending_eoi++;
>  	} else {
> -		__clear_bit(vcpu->vcpu_id, ioapic->rtc_status.dest_map.map);
> +		__clear_bit(vcpu->vcpu_id, dest_map->map);
>  		ioapic->rtc_status.pending_eoi--;
>  		rtc_status_pending_eoi_check_valid(ioapic);
>  	}
> -- 
> 1.8.3.1
> 

Powered by blists - more mailing lists