Re: [PATCH 24/24] XSM: fold xsm_{,un}bind_pt_irq() hooks

"Daniel P. Smith" <[email protected]>
Newsgroups gmane.comp.emulators.xen.devel
Message-ID <[email protected]>

On 7/28/26 9:26 AM, Jan Beulich wrote:
> Like other resource management hooks they are mainly different in "add
> resource" vs "remove resource". Hence like in other cases a single hook
> can easily serve both purposes, with minor tweaking of
> flask_bind_pt_irq(). While adjusting that function, also defer the setting
> of "dperm", which is only needed in the "map" case.
> 
> Signed-off-by: Jan Beulich <[email protected]>
> 
> --- a/xen/arch/arm/domctl.c
> +++ b/xen/arch/arm/domctl.c
> @@ -104,7 +104,7 @@ long arch_do_domctl(struct xen_domctl *d
>           if ( rc )
>               return rc;
>   
> -        rc = xsm_bind_pt_irq(XSM_DM_PRIV, d, bind);
> +        rc = xsm_bind_pt_irq(XSM_DM_PRIV, d, bind, true);
>           if ( rc )
>               return rc;
>   
> @@ -140,7 +140,7 @@ long arch_do_domctl(struct xen_domctl *d
>           if ( irq != virq )
>               return -EINVAL;
>   
> -        rc = xsm_unbind_pt_irq(XSM_DM_PRIV, d, bind);
> +        rc = xsm_bind_pt_irq(XSM_DM_PRIV, d, bind, false);
>           if ( rc )
>               return rc;
>   
> --- a/xen/arch/x86/domctl.c
> +++ b/xen/arch/x86/domctl.c
> @@ -622,7 +622,7 @@ long arch_do_domctl(
>           if ( !is_hvm_domain(d) )
>               break;
>   
> -        ret = xsm_bind_pt_irq(XSM_DM_PRIV, d, bind);
> +        ret = xsm_bind_pt_irq(XSM_DM_PRIV, d, bind, true);
>           if ( ret )
>               break;
>   
> @@ -660,7 +660,7 @@ long arch_do_domctl(
>           if ( !is_hvm_domain(d) )
>               break;
>   
> -        ret = xsm_unbind_pt_irq(XSM_DM_PRIV, d, bind);
> +        ret = xsm_bind_pt_irq(XSM_DM_PRIV, d, bind, false);
>           if ( ret )
>               break;
>   
> --- a/xen/include/xsm/dummy.h
> +++ b/xen/include/xsm/dummy.h
> @@ -478,14 +478,8 @@ static XSM_INLINE int xsm_map_domain_irq
>   }
>   
>   static XSM_INLINE int xsm_bind_pt_irq(
> -    XSM_DEFAULT_ARG struct domain *d, struct xen_domctl_bind_pt_irq *bind)
> -{
> -    XSM_ASSERT_ACTION(XSM_DM_PRIV);
> -    return xsm_default_action(action, current->domain, d);
> -}
> -
> -static XSM_INLINE int xsm_unbind_pt_irq(
> -    XSM_DEFAULT_ARG struct domain *d, struct xen_domctl_bind_pt_irq *bind)
> +    XSM_DEFAULT_ARG struct domain *d, struct xen_domctl_bind_pt_irq *bind,
> +    bool allow)
>   {
>       XSM_ASSERT_ACTION(XSM_DM_PRIV);
>       return xsm_default_action(action, current->domain, d);
> --- a/xen/include/xsm/hooks.h
> +++ b/xen/include/xsm/hooks.h
> @@ -72,8 +72,8 @@ XSM_HOOK(int, map_domain_pirq, struct do
>   #endif
>   
>   XSM_HOOK(int, map_domain_irq, struct domain *, int, const pci_sbdf_t *, bool)
> -XSM_HOOK(int, bind_pt_irq, struct domain *, struct xen_domctl_bind_pt_irq *)
> -XSM_HOOK(int, unbind_pt_irq, struct domain *, struct xen_domctl_bind_pt_irq *)
> +XSM_HOOK(int, bind_pt_irq, struct domain *, struct xen_domctl_bind_pt_irq *,
> +                           bool)
>   
>   XSM_HOOK(int, irq_permission, struct domain *, int, bool)
>   XSM_HOOK(int, iomem_permission, struct domain *, uint64_t, uint64_t, bool)
> --- a/xen/xsm/flask/hooks.c
> +++ b/xen/xsm/flask/hooks.c
> @@ -1090,16 +1090,15 @@ static int cf_check flask_map_domain_irq
>   }
>   
>   static int cf_check flask_bind_pt_irq(
> -    struct domain *d, struct xen_domctl_bind_pt_irq *bind)
> +    struct domain *d, struct xen_domctl_bind_pt_irq *bind, bool access)
>   {
> -    uint32_t dsid, rsid;
> +    uint32_t dsid, rsid, dperm;
>       int rc = -EPERM;
>       int irq;
>       struct avc_audit_data ad;
> -    uint32_t dperm = flask_iommu_resource_use_perm(d);
>   
> -    rc = current_has_perm(d, SECCLASS_RESOURCE, RESOURCE__ADD);
> -    if ( rc )
> +    rc = current_has_perm(d, SECCLASS_RESOURCE, resource_to_perm(access));
> +    if ( rc || access )

Same as on patch 23, check is inverted.

v/r,
dps
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.