KVM: Explicitly initialize all fields at the start of kvm_vcpu_map()
Explicitly initialize the entire kvm_host_map structure when mapping a pfn, as some callers declare their struct on the stack, i.e. don't zero-initialize the struct, which makes the map->hva in kvm_vcpu_unmap() *very* suspect. Tested-by: Alex Bennée <alex.bennee@linaro.org> Signed-off-by: Sean Christopherson <seanjc@google.com> Tested-by: Dmitry Osipenko <dmitry.osipenko@collabora.com> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com> Message-ID: <20241010182427.1434605-22-seanjc@google.com>pull/1085/head
parent
0b139b877b
commit
5488499f9c
|
|
@ -3061,32 +3061,24 @@ void kvm_release_pfn(kvm_pfn_t pfn, bool dirty)
|
||||||
|
|
||||||
int kvm_vcpu_map(struct kvm_vcpu *vcpu, gfn_t gfn, struct kvm_host_map *map)
|
int kvm_vcpu_map(struct kvm_vcpu *vcpu, gfn_t gfn, struct kvm_host_map *map)
|
||||||
{
|
{
|
||||||
kvm_pfn_t pfn;
|
map->page = KVM_UNMAPPED_PAGE;
|
||||||
void *hva = NULL;
|
map->hva = NULL;
|
||||||
struct page *page = KVM_UNMAPPED_PAGE;
|
map->gfn = gfn;
|
||||||
|
|
||||||
pfn = gfn_to_pfn(vcpu->kvm, gfn);
|
map->pfn = gfn_to_pfn(vcpu->kvm, gfn);
|
||||||
if (is_error_noslot_pfn(pfn))
|
if (is_error_noslot_pfn(map->pfn))
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
if (pfn_valid(pfn)) {
|
if (pfn_valid(map->pfn)) {
|
||||||
page = pfn_to_page(pfn);
|
map->page = pfn_to_page(map->pfn);
|
||||||
hva = kmap(page);
|
map->hva = kmap(map->page);
|
||||||
#ifdef CONFIG_HAS_IOMEM
|
#ifdef CONFIG_HAS_IOMEM
|
||||||
} else {
|
} else {
|
||||||
hva = memremap(pfn_to_hpa(pfn), PAGE_SIZE, MEMREMAP_WB);
|
map->hva = memremap(pfn_to_hpa(map->pfn), PAGE_SIZE, MEMREMAP_WB);
|
||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!hva)
|
return map->hva ? 0 : -EFAULT;
|
||||||
return -EFAULT;
|
|
||||||
|
|
||||||
map->page = page;
|
|
||||||
map->hva = hva;
|
|
||||||
map->pfn = pfn;
|
|
||||||
map->gfn = gfn;
|
|
||||||
|
|
||||||
return 0;
|
|
||||||
}
|
}
|
||||||
EXPORT_SYMBOL_GPL(kvm_vcpu_map);
|
EXPORT_SYMBOL_GPL(kvm_vcpu_map);
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue