From patchwork Wed Jun 21 09:33:31 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jan Beulich X-Patchwork-Id: 9801333 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 8AF0C60329 for ; Wed, 21 Jun 2017 09:35:37 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 778AB1FF12 for ; Wed, 21 Jun 2017 09:35:37 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 6C28A262AE; Wed, 21 Jun 2017 09:35:37 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.2 required=2.0 tests=BAYES_00, RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id EA6361FF12 for ; Wed, 21 Jun 2017 09:35:36 +0000 (UTC) Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dNc12-0008GS-82; Wed, 21 Jun 2017 09:33:36 +0000 Received: from mail6.bemta6.messagelabs.com ([193.109.254.103]) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dNc11-0008GB-Sb for xen-devel@lists.xenproject.org; Wed, 21 Jun 2017 09:33:35 +0000 Received: from [193.109.254.147] by server-2.bemta-6.messagelabs.com id 66/95-03058-F6D3A495; Wed, 21 Jun 2017 09:33:35 +0000 X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrKIsWRWlGSWpSXmKPExsXS6fjDSzfP1iv SYPIMZYvvWyYzOTB6HP5whSWAMYo1My8pvyKBNePOscXMBe18FevnnmdpYFzG3cXIySEkkCcx Z/dWFhCbV8BOYtX5eWwgtoSAocTphTeB4hwcLAKqEgv7qkDCbALqEm3PtrOChEUEDCTOHU3qY uTiYBb4xSgx58IUsDHCAp4Smxd9Y4MYXySx9cBqdhCbU8BeYs6y12wgvbwCghJ/dwiDhJmBth 48v41xAiPPLITMLCQZCFtL4uGvWywQtrbEsoWvmUHKmQWkJZb/44AI20jMmDOHDVUJiO0uMf/ PA9YFjByrGDWKU4vKUot0DU30kooy0zNKchMzc3QNDcz0clOLixPTU3MSk4r1kvNzNzECg5UB CHYwXt8YcIhRkoNJSZT3gqxXpBBfUn5KZUZicUZ8UWlOavEhRg0ODoFtu1ZfYJRiycvPS1WS4 A2wAaoTLEpNT61Iy8wBxhNMqQQHj5II7zJzoDRvcUFibnFmOkTqFKMux4bV678wCYHNkBLnFQ SZIQBSlFGaBzcCFtuXGGWlhHkZgQ4U4ilILcrNLEGVf8UozsGoJAxxCU9mXgncpldARzABHfH iiAfIESWJCCmpBsaDZo3zy/Rrt8b7lexbwZgV72jCstupveKdjYaiWfThOWvXvX5p0FwtXlP7 ueKrnowtv6ltRdqmaQXhvfPcW+NPJxz40WHcc3BvaZnGqk9LurzmiqVLvj5hsj/xQ/mXJ/dF7 Hg0d9y0PlyxtfmiyNQOLZ2/UYUJB2Z8bs6y3qOQuoX5vtZdCyWW4oxEQy3mouJEALjBxcLoAg AA X-Env-Sender: JBeulich@suse.com X-Msg-Ref: server-3.tower-27.messagelabs.com!1498037613!108445355!1 X-Originating-IP: [137.65.248.74] X-SpamReason: No, hits=0.0 required=7.0 tests= X-StarScan-Received: X-StarScan-Version: 9.4.19; banners=-,-,- X-VirusChecked: Checked Received: (qmail 12337 invoked from network); 21 Jun 2017 09:33:34 -0000 Received: from prv-mh.provo.novell.com (HELO prv-mh.provo.novell.com) (137.65.248.74) by server-3.tower-27.messagelabs.com with DHE-RSA-AES256-GCM-SHA384 encrypted SMTP; 21 Jun 2017 09:33:34 -0000 Received: from INET-PRV-MTA by prv-mh.provo.novell.com with Novell_GroupWise; Wed, 21 Jun 2017 03:33:32 -0600 Message-Id: <594A598B0200007800165056@prv-mh.provo.novell.com> X-Mailer: Novell GroupWise Internet Agent 14.2.2 Date: Wed, 21 Jun 2017 03:33:31 -0600 From: "Jan Beulich" To: "xen-devel" References: <594A57B10200007800165012@prv-mh.provo.novell.com> <594A57B10200007800165012@prv-mh.provo.novell.com> In-Reply-To: <594A57B10200007800165012@prv-mh.provo.novell.com> Mime-Version: 1.0 Cc: Stefano Stabellini , Wei Liu , George Dunlap , Andrew Cooper , Ian Jackson , Tim Deegan Subject: [Xen-devel] [PATCH 04/11] domctl: restrict DOMCTL_set_target to HVM domains X-BeenThere: xen-devel@lists.xen.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xen.org Sender: "Xen-devel" X-Virus-Scanned: ClamAV using ClamSMTP Both the XSA-217 fix and lists.xenproject.org/archives/html/xen-devel/2017-04/msg02945.html make this assumption, so let's enforce it. Signed-off-by: Jan Beulich domctl: restrict DOMCTL_set_target to HVM domains Both the XSA-217 fix and lists.xenproject.org/archives/html/xen-devel/2017-04/msg02945.html make this assumption, so let's enforce it. Signed-off-by: Jan Beulich --- a/xen/common/domctl.c +++ b/xen/common/domctl.c @@ -1071,7 +1071,9 @@ long do_domctl(XEN_GUEST_HANDLE_PARAM(xe break; } - ret = xsm_set_target(XSM_HOOK, d, e); + ret = -EOPNOTSUPP; + if ( is_hvm_domain(e) ) + ret = xsm_set_target(XSM_HOOK, d, e); if ( ret ) { put_domain(e); break; Reviewed-by: Andrew Cooper , although... --- a/xen/common/domctl.c +++ b/xen/common/domctl.c @@ -1071,7 +1071,9 @@ long do_domctl(XEN_GUEST_HANDLE_PARAM(xe break; } - ret = xsm_set_target(XSM_HOOK, d, e); + ret = -EOPNOTSUPP; + if ( is_hvm_domain(e) ) + ret = xsm_set_target(XSM_HOOK, d, e); if ( ret ) { put_domain(e); break;