|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] [RFC][v3][PATCH 2/6] xen:x86: introduce a new hypercall to get RMRR mappings
On 15/08/14 09:27, Tiejun Chen wrote:
> We need this new hypercall to get RMRR mapping for VM.
>
> Signed-off-by: Tiejun Chen <tiejun.chen@xxxxxxxxx>
> ---
> xen/arch/x86/x86_64/compat/mm.c | 9 +++++++++
> xen/include/public/memory.h | 14 +++++++++++++-
> 2 files changed, 22 insertions(+), 1 deletion(-)
>
> diff --git a/xen/arch/x86/x86_64/compat/mm.c b/xen/arch/x86/x86_64/compat/mm.c
> index 69c6195..ff16f17 100644
> --- a/xen/arch/x86/x86_64/compat/mm.c
> +++ b/xen/arch/x86/x86_64/compat/mm.c
> @@ -132,6 +132,15 @@ int compat_arch_memory_op(unsigned long cmd,
> XEN_GUEST_HANDLE_PARAM(void) arg)
> break;
> }
>
> + case XENMEM_reserved_device_memory_map:
> + {
> + /* Currently we just need to cover RMRR. */
> + if ( copy_to_guest(arg, &rmrr_maps, 1) )
> + return -EFAULT;
This will trivially clobber the hypercaller's stack/heap.
You are not even using the correct indirection of
xen_rmrr_memory_map_t.buffer
You *must* start by copying xen_rmrr_memory_map_t from the guest.
~Andrew
> +
> + return 0;
> + }
> +
> case XENMEM_machphys_mapping:
> {
> struct domain *d = current->domain;
> diff --git a/xen/include/public/memory.h b/xen/include/public/memory.h
> index 2c57aa0..13e539f 100644
> --- a/xen/include/public/memory.h
> +++ b/xen/include/public/memory.h
> @@ -523,7 +523,19 @@ DEFINE_XEN_GUEST_HANDLE(xen_mem_sharing_op_t);
>
> #endif /* defined(__XEN__) || defined(__XEN_TOOLS__) */
>
> -/* Next available subop number is 26 */
> +/*
> + * Some devices may reserve some range.
> + *
> + * Currently we just have RMRR
> + * - Reserved memory Region Reporting Structure,
> + * So returns the RMRR memory map as it was when the domain
> + * was started.
> + */
> +#define XENMEM_reserved_device_memory_map 26
> +typedef struct xen_memory_map xen_rmrr_memory_map_t;
> +DEFINE_XEN_GUEST_HANDLE(xen_rmrr_memory_map_t);
> +
> +/* Next available subop number is 27 */
>
> #endif /* __XEN_PUBLIC_MEMORY_H__ */
>
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |