[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v2] xen/arm: validate non-common page-table ranges


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Gabriel Quintáns Souto <gabi.qs.mail@xxxxxxxxx>
  • Date: Mon, 5 Oct 2026 20:09:19 +0200
  • Arc-authentication-results: i=1; mx.google.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=+E3n7efndYsIolQFRyzLYwCoF9ey9KM05X/9TVoD4+w=; fh=quJY5mN2l4ZorNvEoO9ngNXalhEvTdq/+W8CvHWhECs=; b=THdt/8DqALbGVDfnUcbD6zVwMK7JFZ61VcyeTGx+n7r7jI7lk7v7rpwXLuVk/dlCcU 4SnE3J0rq02QIEjXqQBglxBM2/WLI2X8H3xy7yMf2i6Jv9yHYsL7TpVbXkgGoXjwVRY3 j2kaCcVN2S7dM/eHUmQLF7ccHO19KhZjT5UZyCAx/6qs/2/4MQ+GDU7u62X0DAczD930 eTKpZabwCpXV7aJAM1kv8DvVep/sm9T8Sg9usBcFt9Uu/Qz5PtPwIPvB+25VouY0K547 VImBT6OpcCZMlKu7A3osFKNsJO0e+3TczVdft66vMFOv/Z/wnB1yEJvX8iYPZ9vxrx8C hK4w==; darn=lists.xenproject.org
  • Arc-seal: i=1; a=rsa-sha256; t=1791223772; cv=none; d=google.com; s=arc-20260327; b=K848G0vjF9SSILmLk1/4FwPDccCK+MPo4a3vRWSRoJsTeBNK8sw7EQSGoRJ1lbZoL8 toxwR8XuvStwDeU8eNxPD57Y3naIDtRuFn0zwPCpoaeYqfRH2Zv0Qsuqi1c+E3581Jvk ES3SRFsiIDDmDtNEOb9D5+Nm8o7wsEJD1auvipa1H/IOCwLUwZYci2Cl6Cd9O6oIFLUy 94dRU3M/kRaUbuL0jUOfv25EyaHyvTb143F5TRX25CdZzC8vN9HuCRXNXAEKq0PnxykO KZvkP/UieZI3HNpUEY7BzDzcqIkj5iahnkWZoj28Z9yZxgCRF3l5U53+9JJ08yKWnd0E unkA==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=gmail.com header.i="@gmail.com" header.h="Content-Type:To:Subject:Message-ID:Date:From:In-Reply-To:References:MIME-Version"
  • Delivery-date: Mon, 05 Oct 2026 18:09:38 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

Sorry for the noise, please ignore v2, accidentally committed a local file. Just sent v3.

Best regards,
Gabriel

On Mon, Oct 5, 2026 at 7:54 PM Gabriel Quintáns Souto <gabi.qs.mail@xxxxxxxxx> wrote:
On arm32, page-tables are different on each CPUs, although they share some
common mappings.

The xen_pt_update function assumed that only said mappings would be
modified, but did not check this assumption.

Add a range check to reject modifications to non-common mappings.

Signed-off-by: Gabriel Quintáns Souto <gabi.qs.mail@xxxxxxxxx>
---
v2:
- Inverted polarity of xen_pt_range_is_non_common() as suggested.
- Moved xen_pt_range_is_common() implementation to arch-specific headers
(arm32 vs arm64) instead of keeping #ifdef CONFIG_ARM_32 in pt.c (tried
IS_ENABLED() for DCE, but ARM64 lacks definitions for
DOMHEAP_VIRT_START/TEMPORARY_AREA_ADDR, breaking the build).
- Added ASSERT_UNREACHABLE() on failure path in xen_pt_update().
---
 ...alidate-non-common-page-table-ranges.patch | 87 +++++++++++++++++++
 xen/arch/arm/include/asm/arm32/mm.h           | 24 +++++
 xen/arch/arm/include/asm/arm64/mm.h           | 10 +++
 xen/arch/arm/mmu/pt.c                         | 30 +------
 4 files changed, 125 insertions(+), 26 deletions(-)
 create mode 100644 v1-0001-xen-arm-validate-non-common-page-table-ranges.patch

diff --git a/v1-0001-xen-arm-validate-non-common-page-table-ranges.patch b/v1-0001-xen-arm-validate-non-common-page-table-ranges.patch
new file mode 100644
index 0000000..9f04107
--- /dev/null
+++ b/v1-0001-xen-arm-validate-non-common-page-table-ranges.patch
@@ -0,0 +1,87 @@
+From 21cd59798dafea289feeecd94f39890e99497525 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Gabriel=20Quint=C3=A1ns=20Souto?= <gabi.qs.mail@xxxxxxxxx>
+Date: Fri, 2 Oct 2026 20:17:05 +0200
+Subject: [PATCH v1] xen/arm: validate non-common page-table ranges
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+On arm32, page-tables are different on each CPUs, although they share some
+common mappings.
+
+The xen_pt_update function assumed that only said mappings would be
+modified, but did not check this assumption.
+
+Add a range check to reject modifications to non-common mappings.
+
+Signed-off-by: Gabriel Quintáns Souto <gabi.qs.mail@xxxxxxxxx>
+---
+ xen/arch/arm/mmu/pt.c | 36 +++++++++++++++++++++++++++++-------
+ 1 file changed, 29 insertions(+), 7 deletions(-)
+
+diff --git a/xen/arch/arm/mmu/pt.c b/xen/arch/arm/mmu/pt.c
+index 621b47d..ad0d1e6 100644
+--- a/xen/arch/arm/mmu/pt.c
++++ b/xen/arch/arm/mmu/pt.c
+@@ -13,6 +13,7 @@
+
+ #include <asm/current.h>
+ #include <asm/fixmap.h>
++#include <asm/mmu/layout.h>
+
+ #ifdef NDEBUG
+ static inline void
+@@ -589,6 +590,29 @@ static unsigned int xen_pt_check_contig(unsigned long vfn, mfn_t mfn,
+     return XEN_PT_4K_NR_CONTIG;
+ }
+
++#ifdef CONFIG_ARM_32
++static bool ranges_overlap(unsigned long start1, unsigned long size1,
++                           unsigned long start2, unsigned long size2)
++{
++    if ( start1 < start2 )
++        return start2 - start1 < size1;
++
++    return start1 - start2 < size2;
++}
++
++static bool xen_pt_range_is_non_common(unsigned long virt,
++                                       unsigned long size)
++{
++    unsigned long temporary_start = TEMPORARY_AREA_ADDR(0);
++    unsigned long temporary_size = XEN_PT_LEVEL_SIZE(1);
++
++    return ranges_overlap(virt, size,
++                          DOMHEAP_VIRT_START, DOMHEAP_VIRT_SIZE) ||
++           ranges_overlap(virt, size,
++                          temporary_start, temporary_size);
++}
++#endif
++
+ static DEFINE_SPINLOCK(xen_pt_lock);
+
+ static int xen_pt_update(unsigned long virt,
+@@ -601,15 +625,13 @@ static int xen_pt_update(unsigned long virt,
+     unsigned long vfn = virt >> PAGE_SHIFT;
+     unsigned long left = nr_mfns;
+
+-    /*
+-     * For arm32, page-tables are different on each CPUs. Yet, they share
+-     * some common mappings. It is assumed that only common mappings
+-     * will be modified with this function.
+-     *
+-     * XXX: Add a check.
+-     */
+     const mfn_t root = maddr_to_mfn(READ_SYSREG64(TTBR0_EL2));
+
++    #ifdef CONFIG_ARM_32
++    if ( xen_pt_range_is_non_common(virt, nr_mfns * PAGE_SIZE) )
++        return -EINVAL;
++    #endif
++
+     if ( flags_has_rwx(flags) )
+     {
+         mm_printk("Mappings should not be both Writeable and Executable.\n");
+--
+2.54.0
+
diff --git a/xen/arch/arm/include/asm/arm32/mm.h b/xen/arch/arm/include/asm/arm32/mm.h
index 856f2db..c7d09d3 100644
--- a/xen/arch/arm/include/asm/arm32/mm.h
+++ b/xen/arch/arm/include/asm/arm32/mm.h
@@ -16,6 +16,30 @@ static inline bool arch_mfns_in_directmap(unsigned long mfn, unsigned long nr)
     return false;
 }

+static inline bool ranges_overlap(unsigned long start1, unsigned long size1,
+                           unsigned long start2, unsigned long size2)
+{
+    if ( start1 < start2 )
+        return start2 - start1 < size1;
+
+    return start1 - start2 < size2;
+}
+
+/*
+ * On ARM32, page-tables differ between CPUs, so not all mappings are common.
+ */
+static inline bool xen_pt_range_is_common(unsigned long virt,
+                                       unsigned long size)
+{
+    unsigned long temporary_start = TEMPORARY_AREA_ADDR(0);
+    unsigned long temporary_size = XEN_PT_LEVEL_SIZE(1);
+
+    return !ranges_overlap(virt, size,
+                          DOMHEAP_VIRT_START, DOMHEAP_VIRT_SIZE) &&
+           !ranges_overlap(virt, size,
+                          temporary_start, temporary_size);
+}
+
 bool init_domheap_mappings(unsigned int cpu);

 static inline void arch_setup_page_tables(void)
diff --git a/xen/arch/arm/include/asm/arm64/mm.h b/xen/arch/arm/include/asm/arm64/mm.h
index b4f7545..a3cb56d 100644
--- a/xen/arch/arm/include/asm/arm64/mm.h
+++ b/xen/arch/arm/include/asm/arm64/mm.h
@@ -12,6 +12,16 @@ static inline bool arch_mfns_in_directmap(unsigned long mfn, unsigned long nr)
     return true;
 }

+/*
+ * On ARM64, the Xen page-tables are shared by all the CPUs,
+ * any range is therefore common.
+ */
+static inline bool xen_pt_range_is_common(unsigned long virt,
+                                          unsigned long size)
+{
+    return true;
+}
+
 void arch_setup_page_tables(void);

 void update_boot_mapping(bool enable);
diff --git a/xen/arch/arm/mmu/pt.c b/xen/arch/arm/mmu/pt.c
index ad0d1e6..5e1b427 100644
--- a/xen/arch/arm/mmu/pt.c
+++ b/xen/arch/arm/mmu/pt.c
@@ -590,29 +590,6 @@ static unsigned int xen_pt_check_contig(unsigned long vfn, mfn_t mfn,
     return XEN_PT_4K_NR_CONTIG;
 }

-#ifdef CONFIG_ARM_32
-static bool ranges_overlap(unsigned long start1, unsigned long size1,
-                           unsigned long start2, unsigned long size2)
-{
-    if ( start1 < start2 )
-        return start2 - start1 < size1;
-
-    return start1 - start2 < size2;
-}
-
-static bool xen_pt_range_is_non_common(unsigned long virt,
-                                       unsigned long size)
-{
-    unsigned long temporary_start = TEMPORARY_AREA_ADDR(0);
-    unsigned long temporary_size = XEN_PT_LEVEL_SIZE(1);
-
-    return ranges_overlap(virt, size,
-                          DOMHEAP_VIRT_START, DOMHEAP_VIRT_SIZE) ||
-           ranges_overlap(virt, size,
-                          temporary_start, temporary_size);
-}
-#endif
-
 static DEFINE_SPINLOCK(xen_pt_lock);

 static int xen_pt_update(unsigned long virt,
@@ -627,10 +604,11 @@ static int xen_pt_update(unsigned long virt,

     const mfn_t root = maddr_to_mfn(READ_SYSREG64(TTBR0_EL2));

-    #ifdef CONFIG_ARM_32
-    if ( xen_pt_range_is_non_common(virt, nr_mfns * PAGE_SIZE) )
+    if ( !xen_pt_range_is_common(virt, nr_mfns * PAGE_SIZE) )
+    {
+        ASSERT_UNREACHABLE();
         return -EINVAL;
-    #endif
+    }

     if ( flags_has_rwx(flags) )
     {
--
2.54.0


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.