]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
KVM: Explicitly disallow activatating a gfn_to_pfn_cache with INVALID_GPA
authorSean Christopherson <seanjc@google.com>
Wed, 20 Mar 2024 00:15:42 +0000 (17:15 -0700)
committerSean Christopherson <seanjc@google.com>
Mon, 8 Apr 2024 20:20:24 +0000 (13:20 -0700)
Explicit disallow activating a gfn_to_pfn_cache with an error gpa, i.e.
INVALID_GPA, to ensure that KVM doesn't mistake a GPA-based cache for an
HVA-based cache (KVM uses INVALID_GPA as a magic value to differentiate
between GPA-based and HVA-based caches).

WARN if KVM attempts to activate a cache with INVALID_GPA, purely so that
new caches need to at least consider what to do with a "bad" GPA, as all
existing usage of kvm_gpc_activate() guarantees gpa != INVALID_GPA.  I.e.
removing the WARN in the future is completely reasonable if doing so would
yield cleaner/better code overall.

Reviewed-by: David Woodhouse <dwmw@amazon.co.uk>
Reviewed-by: Paul Durrant <paul@xen.org>
Link: https://lore.kernel.org/r/20240320001542.3203871-4-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
virt/kvm/pfncache.c

index 91b0e329006ba4379c2e468afd1a195fb2018098..f618719644e04244ef69f7970d7ac9e78a2262b5 100644 (file)
@@ -418,6 +418,13 @@ static int __kvm_gpc_activate(struct gfn_to_pfn_cache *gpc, gpa_t gpa, unsigned
 
 int kvm_gpc_activate(struct gfn_to_pfn_cache *gpc, gpa_t gpa, unsigned long len)
 {
+       /*
+        * Explicitly disallow INVALID_GPA so that the magic value can be used
+        * by KVM to differentiate between GPA-based and HVA-based caches.
+        */
+       if (WARN_ON_ONCE(kvm_is_error_gpa(gpa)))
+               return -EINVAL;
+
        return __kvm_gpc_activate(gpc, gpa, KVM_HVA_ERR_BAD, len);
 }