diff options
| author | Marc Zyngier <marc.zyngier@arm.com> | 2016-07-17 13:00:49 +0100 | 
|---|---|---|
| committer | Marc Zyngier <marc.zyngier@arm.com> | 2016-07-18 18:15:17 +0100 | 
| commit | 333a53ff7fb9d836ff4a2b7f266ac9b2bb85e873 (patch) | |
| tree | b1a56c97b9322ce5ca31307e00b2beac7abbfa53 /virt | |
| parent | b90338b7cbb7c8cad8dbd3c4de4e64180ce0d88b (diff) | |
| download | linux-333a53ff7fb9d836ff4a2b7f266ac9b2bb85e873.tar.bz2 | |
KVM: arm64: vgic-its: Validate the device table L1 entry
Checking that the device_id fits if the table, and we must make
sure that the associated memory is also accessible.
Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
Diffstat (limited to 'virt')
| -rw-r--r-- | virt/kvm/arm/vgic/vgic-its.c | 13 | 
1 files changed, 11 insertions, 2 deletions
| diff --git a/virt/kvm/arm/vgic/vgic-its.c b/virt/kvm/arm/vgic/vgic-its.c index 268a0c7ea3a5..4943d6aebdd1 100644 --- a/virt/kvm/arm/vgic/vgic-its.c +++ b/virt/kvm/arm/vgic/vgic-its.c @@ -693,8 +693,17 @@ static bool vgic_its_check_device_id(struct kvm *kvm, struct vgic_its *its,  	gfn_t gfn; -	if (!(r & GITS_BASER_INDIRECT)) -		return device_id < (l1_tbl_size / GITS_BASER_ENTRY_SIZE(r)); +	if (!(r & GITS_BASER_INDIRECT)) { +		phys_addr_t addr; + +		if (device_id >= (l1_tbl_size / GITS_BASER_ENTRY_SIZE(r))) +			return false; + +		addr = BASER_ADDRESS(r) + device_id * GITS_BASER_ENTRY_SIZE(r); +		gfn = addr >> PAGE_SHIFT; + +		return kvm_is_visible_gfn(kvm, gfn); +	}  	/* calculate and check the index into the 1st level */  	index = device_id / (SZ_64K / GITS_BASER_ENTRY_SIZE(r)); |