public inbox for linux-arm-kernel@lists.infradead.org 
 help / color / mirror / Atom feed
From: marc.zyngier@arm•com (Marc Zyngier)
To: linux-arm-kernel@lists•infradead.org
Subject: [PATCH] KVM: ARM: vgic: plug irq injection race
Date: Fri, 14 Mar 2014 14:40:22 +0000	[thread overview]
Message-ID: <86d2horgh5.fsf@arm.com> (raw)
In-Reply-To: <20140314042052.GH24808@cbox> (Christoffer Dall's message of "Fri, 14 Mar 2014 04:20:52 +0000")

On Fri, Mar 14 2014 at 04:20:52 AM, Christoffer Dall <christoffer.dall@linaro•org> wrote:
> On Fri, Feb 14, 2014 at 02:28:06PM +0000, Marc Zyngier wrote:
>> As it stands, nothing prevents userspace from injecting an interrupt
>> before the guest's GIC is actually initialized.
>> 
>> This goes unnoticed so far (as everything is pretty much statically
>> allocated), but ends up exploding in a spectacular way once we switch
>> to a more dynamic allocation (the GIC data structure isn't there yet).
>> 
>> The fix is to test for the "ready" flag in the VGIC distributor before
>> trying to inject the interrupt. Note that in order to avoid breaking
>> userspace, we have to ignore what is essentially an error.
>> 
>> Signed-off-by: Marc Zyngier <marc.zyngier@arm•com>
>> ---
>>  virt/kvm/arm/vgic.c | 3 ++-
>>  1 file changed, 2 insertions(+), 1 deletion(-)
>> 
>> diff --git a/virt/kvm/arm/vgic.c b/virt/kvm/arm/vgic.c
>> index be456ce..d40fe61 100644
>> --- a/virt/kvm/arm/vgic.c
>> +++ b/virt/kvm/arm/vgic.c
>> @@ -1386,7 +1386,8 @@ out:
>>  int kvm_vgic_inject_irq(struct kvm *kvm, int cpuid, unsigned int irq_num,
>>  			bool level)
>>  {
>> -	if (vgic_update_irq_state(kvm, cpuid, irq_num, level))
>> +	if (likely(vgic_initialized(kvm)) &&
>
> Do we need a barrier in kvm_vgic_init before setting the
> kvm->arch.vgic.ready to ensure we observe the correctly initialized
> values of the irq_spi_cpu field here?

Ah, I see. Yes, possibly.

>> +	    vgic_update_irq_state(kvm, cpuid, irq_num, level))
>>  		vgic_kick_vcpus(kvm);
>>  
>>  	return 0;
>> -- 
>> 1.8.3.4
>> 
>
> Otherwise looks good, nicely spotted!

I'll respin something early next week.

Cheers,

	M.
-- 
Jazz is not dead. It just smells funny.

  reply	other threads:[~2014-03-14 14:40 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-02-14 14:28 [PATCH] KVM: ARM: vgic: plug irq injection race Marc Zyngier
2014-03-14  4:20 ` Christoffer Dall
2014-03-14 14:40   ` Marc Zyngier [this message]
2014-03-14 19:09     ` Christoffer Dall

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=86d2horgh5.fsf@arm.com \
    --to=marc.zyngier@arm$(echo .)com \
    --cc=linux-arm-kernel@lists$(echo .)infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox