From patchwork Fri May 18 09:27:10 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jia He X-Patchwork-Id: 10409135 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 7F015601F9 for ; Fri, 18 May 2018 09:29:31 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 6C35C285CE for ; Fri, 18 May 2018 09:29:31 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 5EC7028879; Fri, 18 May 2018 09:29:31 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.8 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, MAILING_LIST_MULTI, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id E6BF2285CE for ; Fri, 18 May 2018 09:29:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:MIME-Version:Cc:List-Subscribe: List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:References: In-Reply-To:Message-Id:Date:Subject:To:From:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Owner; bh=Ca6hQ/BK6sn0ei6xVrlczW34S77ZoC1Euh72nNLY1iw=; b=O3+kAC7q8a3HsE2oyspw91WrOC ALEwSKpQnUQAyrIquq3C7RBtjxP2kKGpR2YrGRnNO+HsuY217prkoHbreotHT4h1wA+WQgnPR4Fjl +Fa4mF6MDUHlhweAQxNNGWqXbV2poBrZx1wm0iIxDcGXVs15r7epd/KIZpPReZmCDaLcW0NIl0xEe 0NHUsIjAijxb6R1G3R9Fr0Iua2l58XJjJXhrZrSLLPEtTqE8WqpSKgz9g3nsKrsYcuK9tu1r1UX+h 6AvC8W3ryhUGoePc5D2xoQgl+b3c2GuEh0n8Cqkf/VSzrpkLPfd/vexMYB1GNtqq8oLIvZvFmcNvV lMvHCQ+Q==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.90_1 #2 (Red Hat Linux)) id 1fJbhR-0000Kr-AE; Fri, 18 May 2018 09:29:21 +0000 Received: from mail-pl0-x242.google.com ([2607:f8b0:400e:c01::242]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1fJbgA-000861-1V for linux-arm-kernel@lists.infradead.org; Fri, 18 May 2018 09:28:03 +0000 Received: by mail-pl0-x242.google.com with SMTP id c19-v6so4262494pls.6 for ; Fri, 18 May 2018 02:27:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=0PtTQjEcu7ACoXBpujgsY2VcR05/eApz77R5SIX6bmI=; b=c3v4nsnspXp/PsoAhsKMtcs8ZzXgWPDRTGyRCnUfae4NyIkM+KCaIGdsWcB0/TwM0U +w02MUJyEyCpuPGOGVXCJW7XX67WJoIYnWvJIM+em5+gm+8rXIE0KZa41pTSeAl9+/Jf MqfxtCaA/6EGcJcaHDOitHv7yuHTYNF3qc/uJRxCC4Cwh2k53+0oTYRRokCUhIluEjn8 jdRWjfPThRj0qNLVab99HH+QWMOveqNl9JB6RS8YIvujQjXLyqTC8wd9/N2P+V01V4+g pQlCprObCDrBCqA7hs9iHsHs9yzHZbUXMPC451dXPQvvuxPXkMpwnQX16GHAkYqxy0Gh sEoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=0PtTQjEcu7ACoXBpujgsY2VcR05/eApz77R5SIX6bmI=; b=ajd6/chK7KTOxoesrVn6EgMoNI9Sg3GBxdmGaVXQ9gIJ9gYj5W5qaaBJ31giLS22wY JZ9ffG9YSyjaUlwJL+6In4LsqBR98lilXf0jpORusAGvfKsDt9G9yhk0RKSMfqM8DBLF RIS6cNYxTBh0/nYLzjIvbD4qmaWZv/5wRv0I8yAPwfanUYlA09qBoqafyOyupDzPe8Ox bGfZivW1hSGwnLoPLlGsMdb7EjWzkzmbKNhr90yQsahjjR/A9LW+9vifph+gcW3+FpUd dXusIz+/v0VWfJzeZg78i6yh8QSqkQA3A5TLQwhOgIm3Hyqe3ZPY1M36/MrE4aCQiz+R R9Qg== X-Gm-Message-State: ALKqPwfF1nVpzsgCmXBFZOSr+uZVBeWFhrQemhBcZp+0MQhNFR8q8CCj 1kmK+sTeouaaoXb78oudZwU= X-Google-Smtp-Source: AB8JxZrvH1gXkCtWrAOUuPO/8m65AGoXXg98Dp+FiwJcAPIe26vcc57Vzfo+AX9h4gc8Y//fwTFEBg== X-Received: by 2002:a17:902:a9c1:: with SMTP id b1-v6mr8920465plr.181.1526635671237; Fri, 18 May 2018 02:27:51 -0700 (PDT) Received: from ct7host.localdomain ([38.106.11.25]) by smtp.gmail.com with ESMTPSA id o10-v6sm9162338pgp.30.2018.05.18.02.27.47 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 18 May 2018 02:27:50 -0700 (PDT) From: Jia He To: Christoffer Dall , Marc Zyngier , linux-arm-kernel@lists.infradead.org, kvmarm@lists.cs.columbia.edu Subject: [PATCH v2 2/2] KVM: arm/arm64: harden unmap_stage2_ptes in case end is not PAGE_SIZE aligned Date: Fri, 18 May 2018 17:27:10 +0800 Message-Id: <1526635630-18917-2-git-send-email-hejianet@gmail.com> X-Mailer: git-send-email 1.8.3.1 In-Reply-To: <1526635630-18917-1-git-send-email-hejianet@gmail.com> References: <1526635630-18917-1-git-send-email-hejianet@gmail.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20180518_022802_079510_4E45A21A X-CRM114-Status: GOOD ( 12.62 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: jia.he@hxt-semitech.com, Jia He , linux-kernel@vger.kernel.org, Suzuki.Poulose@arm.com MIME-Version: 1.0 Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP If it passes addr=0x202920000,size=0xfe00 to unmap_stage2_range-> ...->unmap_stage2_ptes, unmap_stage2_ptes will get addr=0x202920000, end=0x20292fe00. After first while loop addr=0x202930000, end=0x20292fe00, then addr!=end. Thus it will touch another pages by put_pages() in the 2nd loop. This patch fixes it by hardening the break condition of while loop. Signed-off-by: jia.he@hxt-semitech.com --- v2: newly added virt/kvm/arm/mmu.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/virt/kvm/arm/mmu.c b/virt/kvm/arm/mmu.c index 8dac311..45cd040 100644 --- a/virt/kvm/arm/mmu.c +++ b/virt/kvm/arm/mmu.c @@ -217,7 +217,7 @@ static void unmap_stage2_ptes(struct kvm *kvm, pmd_t *pmd, put_page(virt_to_page(pte)); } - } while (pte++, addr += PAGE_SIZE, addr != end); + } while (pte++, addr += PAGE_SIZE, addr < end); if (stage2_pte_table_empty(start_pte)) clear_stage2_pmd_entry(kvm, pmd, start_addr);