[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH v3 27/32] nvdimm: support DSM_CMD_IMPLEMENTED fu
From: |
Stefan Hajnoczi |
Subject: |
Re: [Qemu-devel] [PATCH v3 27/32] nvdimm: support DSM_CMD_IMPLEMENTED function |
Date: |
Wed, 14 Oct 2015 10:40:12 +0100 |
User-agent: |
Mutt/1.5.24 (2015-08-30) |
On Sun, Oct 11, 2015 at 11:52:59AM +0800, Xiao Guangrong wrote:
> static void dsm_write(void *opaque, hwaddr addr,
> uint64_t val, unsigned size)
> {
> + NVDIMMState *state = opaque;
> + MemoryRegion *dsm_ram_mr;
> + dsm_in *in;
> + dsm_out *out;
> + uint32_t revision, function, handle;
> +
> if (val != NOTIFY_VALUE) {
> fprintf(stderr, "BUG: unexepected notify value 0x%" PRIx64, val);
> }
> +
> + dsm_ram_mr = memory_region_find(&state->mr, state->page_size,
> + state->page_size).mr;
> + memory_region_unref(dsm_ram_mr);
> + in = memory_region_get_ram_ptr(dsm_ram_mr);
This looks suspicious. Shouldn't the memory_region_unref(dsm_ram_mr)
happen after we're done using it?
> + out = (dsm_out *)in;
> +
> + revision = in->arg1;
> + function = in->arg2;
> + handle = in->handle;
> + le32_to_cpus(&revision);
> + le32_to_cpus(&function);
> + le32_to_cpus(&handle);
> +
> + nvdebug("UUID " UUID_FMT ".\n", in->arg0[0], in->arg0[1], in->arg0[2],
> + in->arg0[3], in->arg0[4], in->arg0[5], in->arg0[6],
> + in->arg0[7], in->arg0[8], in->arg0[9], in->arg0[10],
> + in->arg0[11], in->arg0[12], in->arg0[13], in->arg0[14],
> + in->arg0[15]);
> + nvdebug("Revision %#x Function %#x Handler %#x.\n", revision, function,
> + handle);
> +
> + if (revision != DSM_REVISION) {
> + nvdebug("Revision %#x is not supported, expect %#x.\n",
> + revision, DSM_REVISION);
> + goto exit;
> + }
> +
> + if (!handle) {
> + if (!dsm_is_root_uuid(in->arg0)) {
Please don't dereference 'in' or pass it to other functions. Avoid race
conditions with guest vcpus by coping in the entire dsm_in struct.
This is like a system call - the kernel cannot trust userspace memory
and must copy in before accessing data. The same rules apply.
- [Qemu-devel] [PATCH v3 28/32] nvdimm: support DSM_CMD_NAMESPACE_LABEL_SIZE function, (continued)
- [Qemu-devel] [PATCH v3 28/32] nvdimm: support DSM_CMD_NAMESPACE_LABEL_SIZE function, Xiao Guangrong, 2015/10/10
- [Qemu-devel] [PATCH v3 05/32] acpi: add aml_concatenate, Xiao Guangrong, 2015/10/10
- [Qemu-devel] [PATCH v3 06/32] acpi: add aml_object_type, Xiao Guangrong, 2015/10/10
- [Qemu-devel] [PATCH v3 09/32] exec: allow file_ram_alloc to work on file, Xiao Guangrong, 2015/10/10
- [Qemu-devel] [PATCH v3 19/32] dimm: keep the state of the whole backend memory, Xiao Guangrong, 2015/10/10
- [Qemu-devel] [PATCH v3 27/32] nvdimm: support DSM_CMD_IMPLEMENTED function, Xiao Guangrong, 2015/10/10
- Re: [Qemu-devel] [PATCH v3 27/32] nvdimm: support DSM_CMD_IMPLEMENTED function,
Stefan Hajnoczi <=
- Re: [Qemu-devel] [PATCH v3 27/32] nvdimm: support DSM_CMD_IMPLEMENTED function, Stefan Hajnoczi, 2015/10/15
- Re: [Qemu-devel] [PATCH v3 27/32] nvdimm: support DSM_CMD_IMPLEMENTED function, Xiao Guangrong, 2015/10/15
[Qemu-devel] [PATCH v3 30/32] nvdimm: support DSM_CMD_SET_NAMESPACE_LABEL_DATA, Xiao Guangrong, 2015/10/10
[Qemu-devel] [PATCH v3 31/32] nvdimm: allow using whole backend memory as pmem, Xiao Guangrong, 2015/10/10
[Qemu-devel] [PATCH v3 01/32] acpi: add aml_derefof, Xiao Guangrong, 2015/10/10
[Qemu-devel] [PATCH v3 02/32] acpi: add aml_sizeof, Xiao Guangrong, 2015/10/10