From patchwork Mon Oct 9 16:01:36 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ian Jackson X-Patchwork-Id: 9993819 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 5A92E60230 for ; Mon, 9 Oct 2017 16:03:47 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 4CE38285E8 for ; Mon, 9 Oct 2017 16:03:47 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 41A642880F; Mon, 9 Oct 2017 16:03:47 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.2 required=2.0 tests=BAYES_00, RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 2FF3F285E8 for ; Mon, 9 Oct 2017 16:03:45 +0000 (UTC) Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1e1aVI-0007s8-Vu; Mon, 09 Oct 2017 16:02:04 +0000 Received: from mail6.bemta6.messagelabs.com ([193.109.254.103]) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1e1aVG-0007pK-VM for xen-devel@lists.xenproject.org; Mon, 09 Oct 2017 16:02:03 +0000 Received: from [85.158.143.35] by server-10.bemta-6.messagelabs.com id C2/68-03761-A7D9BD95; Mon, 09 Oct 2017 16:02:02 +0000 X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprKIsWRWlGSWpSXmKPExsXitHRDpG7Z3Nu RBt2fdC2+b5nM5MDocfjDFZYAxijWzLyk/IoE1oxHH++yFLSLV9x/s5WtgfGaUBcjJ4eEgL/E sf33mUFsNgFdiaYtf9lAbBEBaYn+Oe3sXYxcHMwC85kkDs9bzAqSEBZwkGh+3crUxcjBwSKgI rGxOQAkzCvgIXFudyczxEw5ifPHf4LZnAKeEmtnT2MDKRcCqvmzIBzCVJOYuz4eolNQ4uTMJy wgNrOAhMTBFy+YJzDyzkKSmoUktYCRaRWjRnFqUVlqka6xkV5SUWZ6RkluYmaOrqGBmV5uanF xYnpqTmJSsV5yfu4mRmDgMADBDsbT6wIPMUpyMCmJ8s6bcTtSiC8pP6UyI7E4I76oNCe1+BCj DAeHkgSv4RygnGBRanpqRVpmDjCEYdISHDxKIryzZwOleYsLEnOLM9MhUqcYjTmObbr8h4mj4 +bdP0xCLHn5ealS4rwVIJMEQEozSvPgBsFi6xKjrJQwLyPQaUI8BalFuZklqPKvGMU5GJWEee VApvBk5pXA7XsFdAoT0CmMxTdATilJREhJNTDyBacq5D0IVjVc88Q8oyq8ZrNfTbq73asPW1e 9tbQU9s/o4eubsriraEUWj/WfpoWCk+zmVVZdW2I6heXY0c+RvcoPvxg+qjFY2XKaS2eGyCfT ig+B/lGOhnYnmI6vtOvKc5ePN3b4tPzc2mXLcs82H5rwnpktQcrowRKO+vuP22+fzzkcO0eJp Tgj0VCLuag4EQBgs9X9qAIAAA== X-Env-Sender: prvs=4484f2008=Ian.Jackson@citrix.com X-Msg-Ref: server-9.tower-21.messagelabs.com!1507564912!76190308!2 X-Originating-IP: [66.165.176.89] X-SpamReason: No, hits=0.0 required=7.0 tests=sa_preprocessor: VHJ1c3RlZCBJUDogNjYuMTY1LjE3Ni44OSA9PiAyMDMwMDc=\n, received_headers: No Received headers X-StarScan-Received: X-StarScan-Version: 9.4.45; banners=-,-,- X-VirusChecked: Checked Received: (qmail 21920 invoked from network); 9 Oct 2017 16:01:58 -0000 Received: from smtp.citrix.com (HELO SMTP.CITRIX.COM) (66.165.176.89) by server-9.tower-21.messagelabs.com with RC4-SHA encrypted SMTP; 9 Oct 2017 16:01:58 -0000 X-IronPort-AV: E=Sophos;i="5.42,500,1500940800"; d="scan'208";a="443013707" From: Ian Jackson To: Date: Mon, 9 Oct 2017 17:01:36 +0100 Message-ID: <1507564902-9000-3-git-send-email-ian.jackson@eu.citrix.com> X-Mailer: git-send-email 2.1.4 In-Reply-To: <1507564902-9000-1-git-send-email-ian.jackson@eu.citrix.com> References: <1507564902-9000-1-git-send-email-ian.jackson@eu.citrix.com> MIME-Version: 1.0 Cc: Juergen Gross , Stefano Stabellini , Ian Jackson , Ross Lagerwall , Anthony PERARD , xen-devel@lists.xenproject.org Subject: [Xen-devel] [PATCH 2/8] xen: restrict: use xentoolcore_restrict_all X-BeenThere: xen-devel@lists.xen.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xen.org Sender: "Xen-devel" X-Virus-Scanned: ClamAV using ClamSMTP And insist that it works. Drop individual use of xendevicemodel_restrict and xenforeignmemory_restrict. These are not actually effective in this version of qemu, because qemu has a large number of fds open onto various Xen control devices. The restriction arrangements are still not right, because the restriction needs to be done very late - after qemu has opened all of its control fds. xentoolcore_restrict_all and xentoolcore.h are available in Xen 4.10 and later, only. Provide a compatibility stub. And drop the compatibility stubs for the old functions. Signed-off-by: Ian Jackson Reviewed-by: Anthony PERARD --- v2: Modify the compatibility code, too. Bump this patch ahead of "defer call to xen_restrict until running" Retain call to xentoolcore_restrict_all Signed-off-by: Ian Jackson --- include/hw/xen/xen_common.h | 46 +++++++++++---------------------------------- 1 file changed, 11 insertions(+), 35 deletions(-) diff --git a/include/hw/xen/xen_common.h b/include/hw/xen/xen_common.h index 86c7f26..3f44a63 100644 --- a/include/hw/xen/xen_common.h +++ b/include/hw/xen/xen_common.h @@ -91,6 +91,16 @@ static inline void *xenforeignmemory_map2(xenforeignmemory_handle *h, return xenforeignmemory_map(h, dom, prot, pages, arr, err); } +static inline int xentoolcore_restrict_all(domid_t domid) +{ + errno = ENOTTY; + return -1; +} + +#else /* CONFIG_XEN_CTRL_INTERFACE_VERSION >= 41000 */ + +#include + #endif #if CONFIG_XEN_CTRL_INTERFACE_VERSION < 40900 @@ -218,20 +228,6 @@ static inline int xendevicemodel_set_mem_type( return xc_hvm_set_mem_type(dmod, domid, mem_type, first_pfn, nr); } -static inline int xendevicemodel_restrict( - xendevicemodel_handle *dmod, domid_t domid) -{ - errno = ENOTTY; - return -1; -} - -static inline int xenforeignmemory_restrict( - xenforeignmemory_handle *fmem, domid_t domid) -{ - errno = ENOTTY; - return -1; -} - #else /* CONFIG_XEN_CTRL_INTERFACE_VERSION >= 40900 */ #undef XC_WANT_COMPAT_DEVICEMODEL_API @@ -290,28 +286,8 @@ static inline int xen_modified_memory(domid_t domid, uint64_t first_pfn, static inline int xen_restrict(domid_t domid) { int rc; - - /* Attempt to restrict devicemodel operations */ - rc = xendevicemodel_restrict(xen_dmod, domid); + rc = xentoolcore_restrict_all(domid); trace_xen_domid_restrict(rc ? errno : 0); - - if (rc < 0) { - /* - * If errno is ENOTTY then restriction is not implemented so - * there's no point in trying to restrict other types of - * operation, but it should not be treated as a failure. - */ - if (errno == ENOTTY) { - return 0; - } - - return rc; - } - - /* Restrict foreignmemory operations */ - rc = xenforeignmemory_restrict(xen_fmem, domid); - trace_xen_domid_restrict(rc ? errno : 0); - return rc; }