From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 23EA2C433FE for ; Thu, 29 Sep 2022 22:45:24 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 9CC1F8D0009; Thu, 29 Sep 2022 18:45:23 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 97C518D0007; Thu, 29 Sep 2022 18:45:23 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 843AF8D0009; Thu, 29 Sep 2022 18:45:23 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id 764A88D0007 for ; Thu, 29 Sep 2022 18:45:23 -0400 (EDT) Received: from smtpin21.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay06.hostedemail.com (Postfix) with ESMTP id 3CE1BABBE2 for ; Thu, 29 Sep 2022 22:45:23 +0000 (UTC) X-FDA: 79966605726.21.8C3C04A Received: from mail-pf1-f175.google.com (mail-pf1-f175.google.com [209.85.210.175]) by imf20.hostedemail.com (Postfix) with ESMTP id 9D5121C0008 for ; Thu, 29 Sep 2022 22:45:21 +0000 (UTC) Received: by mail-pf1-f175.google.com with SMTP id d82so2675881pfd.10 for ; Thu, 29 Sep 2022 15:45:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date; bh=ByScpYkyRiCU42lbuVk6qEFlopY8wZGmivn5KTd4TkE=; b=lCAg7J5XBsmL67S4ZX++/AHEh9LqfKfUqfXAwLH9JogkhvyRO83RZ1Du9C4di0rODz kLZh/NE3uWWM/16Hp3uljQIoX0MFNKNuV3C68eln7snytpYC2ZwiQ/V0cLeGd1eHLwBC xZUPST6xsPprIa2dWHCykDOU91y140Q5KWomGApBmM0iNB3o1LdjW/DQ7VqhYIf1E8u2 h43ebHa7BCSKFwUduXxQhPuT5TwVny9wTPKsyTwC1K3cE1PDMdpfFs5LAi7yM1CLwhBA SRQHTIlNp9clZhJVcQu1Dmhn2ngA/E21LXi/BXNoOBp9H7PEa/hZUshHWpvqrAmmDNji +OWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date; bh=ByScpYkyRiCU42lbuVk6qEFlopY8wZGmivn5KTd4TkE=; b=Elz6B7xCkSb8nlE2NjSQmrgmDvWjRVq72zJtO9HjzQzeFO6F4bYOe8w4WT9at+3C/S t/KAQXspHgzBJLuJIr1tMVfCe6NEgqDs1YCRhCrdtWR2lxFiREUyta8S8Mkwbd5qpwqy ZTuQswgPNdsRrzgHH3/lbRWxz1+CRO4D9Me5zC3YkoAaVvATh2p+SbwnYSgG40yn/F7i q7/fy64jhubKxLe5WPshye/5mivW11b7nf/n8BUJiU95jKXaXVfo7CQN0XEhXkIsMYlK RPvQ8rHySqZMYG2bUJ43wkTcPg6huzjqETU589FHZpw2cL8DLcUnRtZJyZ+8FbzJtyGz 8ftw== X-Gm-Message-State: ACrzQf2hvlTjLH6UdACgOvERg3Y/a9AvoZoo+bj0Zy3vjTOfUp7+W0EA ieGtI995Fh3HZ588f69E8hI= X-Google-Smtp-Source: AMsMyM6MQvFe701ujja7rvZea79ByiauTnUf8YlkU9ZkqGQBYquDrfuLbNd+uGgJ3lljB5PQecL3LA== X-Received: by 2002:a63:4d4:0:b0:438:ce28:757f with SMTP id 203-20020a6304d4000000b00438ce28757fmr4873802pge.441.1664491520310; Thu, 29 Sep 2022 15:45:20 -0700 (PDT) Received: from localhost ([192.55.54.55]) by smtp.gmail.com with ESMTPSA id u11-20020a170903124b00b001754cfb5e21sm415508plh.96.2022.09.29.15.45.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 29 Sep 2022 15:45:18 -0700 (PDT) Date: Thu, 29 Sep 2022 15:45:16 -0700 From: Isaku Yamahata To: Chao Peng Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, linux-fsdevel@vger.kernel.org, linux-api@vger.kernel.org, linux-doc@vger.kernel.org, qemu-devel@nongnu.org, Paolo Bonzini , Jonathan Corbet , Sean Christopherson , Vitaly Kuznetsov , Wanpeng Li , Jim Mattson , Joerg Roedel , Thomas Gleixner , Ingo Molnar , Borislav Petkov , x86@kernel.org, "H . Peter Anvin" , Hugh Dickins , Jeff Layton , "J . Bruce Fields" , Andrew Morton , Shuah Khan , Mike Rapoport , Steven Price , "Maciej S . Szmigiero" , Vlastimil Babka , Vishal Annapurve , Yu Zhang , "Kirill A . Shutemov" , luto@kernel.org, jun.nakajima@intel.com, dave.hansen@intel.com, ak@linux.intel.com, david@redhat.com, aarcange@redhat.com, ddutile@redhat.com, dhildenb@redhat.com, Quentin Perret , Michael Roth , mhocko@suse.com, Muchun Song , wei.w.wang@intel.com, isaku.yamahata@gmail.com Subject: Re: [PATCH v8 2/8] KVM: Extend the memslot to support fd-based private memory Message-ID: <20220929224516.GA2260388@ls.amr.corp.intel.com> References: <20220915142913.2213336-1-chao.p.peng@linux.intel.com> <20220915142913.2213336-3-chao.p.peng@linux.intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20220915142913.2213336-3-chao.p.peng@linux.intel.com> ARC-Authentication-Results: i=1; imf20.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=lCAg7J5X; spf=pass (imf20.hostedemail.com: domain of isaku.yamahata@gmail.com designates 209.85.210.175 as permitted sender) smtp.mailfrom=isaku.yamahata@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1664491521; a=rsa-sha256; cv=none; b=AlKPtOoOqD0gfVzqQuF+DH76iq97tD/He961/+KpPlHu5BMuRkeNgy8XvCvhNp3juVQcBP A/x0a4rixnPfovY/bdSvkoyYC1evmcukPf7l2GJk8edn+MpzdUQ4dMTzApNFX31XHS34L1 xhQtKuT2HZhyZsNLGaauKsjkDV09BEk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1664491521; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=ByScpYkyRiCU42lbuVk6qEFlopY8wZGmivn5KTd4TkE=; b=j4S7Kzc9o2pBEQ0XGBqTSIMqC5otgMx6G6FlUMV6+uGYsNjQETREamslUlVbqLHCu3jFyt K43C+RdR+qTCdgrIYQAS0JqdAvBmDbkhJYQ0cVgaAhJRGTH8kOOgBPqDZmjLKsV2OeSPkZ wv1kh8kMhyd1axTRNvgSF3VfBWIwU9w= Authentication-Results: imf20.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=lCAg7J5X; spf=pass (imf20.hostedemail.com: domain of isaku.yamahata@gmail.com designates 209.85.210.175 as permitted sender) smtp.mailfrom=isaku.yamahata@gmail.com; dmarc=pass (policy=none) header.from=gmail.com X-Stat-Signature: tyidcnbpxnrhbka7g7ppmm4qqz3f7pwj X-Rspamd-Queue-Id: 9D5121C0008 X-Rspam-User: X-Rspamd-Server: rspam11 X-HE-Tag: 1664491521-164885 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, Sep 15, 2022 at 10:29:07PM +0800, Chao Peng wrote: ... > diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c > index 584a5bab3af3..12dc0dc57b06 100644 > --- a/virt/kvm/kvm_main.c > +++ b/virt/kvm/kvm_main.c ... > @@ -4622,6 +4622,33 @@ static int kvm_vm_ioctl_get_stats_fd(struct kvm *kvm) > return fd; > } > > +#define SANITY_CHECK_MEM_REGION_FIELD(field) \ > +do { \ > + BUILD_BUG_ON(offsetof(struct kvm_user_mem_region, field) != \ > + offsetof(struct kvm_userspace_memory_region, field)); \ > + BUILD_BUG_ON(sizeof_field(struct kvm_user_mem_region, field) != \ > + sizeof_field(struct kvm_userspace_memory_region, field)); \ > +} while (0) > + > +#define SANITY_CHECK_MEM_REGION_EXT_FIELD(field) \ > +do { \ > + BUILD_BUG_ON(offsetof(struct kvm_user_mem_region, field) != \ > + offsetof(struct kvm_userspace_memory_region_ext, field)); \ > + BUILD_BUG_ON(sizeof_field(struct kvm_user_mem_region, field) != \ > + sizeof_field(struct kvm_userspace_memory_region_ext, field)); \ > +} while (0) > + > +static void kvm_sanity_check_user_mem_region_alias(void) > +{ > + SANITY_CHECK_MEM_REGION_FIELD(slot); > + SANITY_CHECK_MEM_REGION_FIELD(flags); > + SANITY_CHECK_MEM_REGION_FIELD(guest_phys_addr); > + SANITY_CHECK_MEM_REGION_FIELD(memory_size); > + SANITY_CHECK_MEM_REGION_FIELD(userspace_addr); > + SANITY_CHECK_MEM_REGION_EXT_FIELD(private_offset); > + SANITY_CHECK_MEM_REGION_EXT_FIELD(private_fd); > +} > + > static long kvm_vm_ioctl(struct file *filp, > unsigned int ioctl, unsigned long arg) > { > @@ -4645,14 +4672,20 @@ static long kvm_vm_ioctl(struct file *filp, > break; > } > case KVM_SET_USER_MEMORY_REGION: { > - struct kvm_userspace_memory_region kvm_userspace_mem; > + struct kvm_user_mem_region mem; > + unsigned long size = sizeof(struct kvm_userspace_memory_region); > + > + kvm_sanity_check_user_mem_region_alias(); > > r = -EFAULT; > - if (copy_from_user(&kvm_userspace_mem, argp, > - sizeof(kvm_userspace_mem))) > + if (copy_from_user(&mem, argp, size); > + goto out; > + > + r = -EINVAL; > + if (mem.flags & KVM_MEM_PRIVATE) > goto out; Nit: It's better to check if padding is zero. Maybe rename it to reserved. + if (mem.pad1 || memchr_inv(mem.pad2, 0, sizeof(mem.pad2))) + goto out; -- Isaku Yamahata