[PATCH v2 2/2] KVM: TDX: Fix a benign off-by-one bug on the end GPA for INIT_MEM_REGION

Sean Christopherson <[email protected]>
Newsgroups org.kernel.vger.kvm,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
When verifying that the incoming GPA rage for INIT_MEM_REGION doesn't wrap,
check the inclusive last GPA, not the exclusive last GPA.  Super duper
technically, it's ok if the very last GPA is -1ull.  In practice, the flaw
is benign as KVM x86 disallows memslots with GPAs that exceed MAXPHYADDR,
i.e. INIT_MEM_REGION would fail with -EINVAL anyways due to the memslot
check in kvm_gmem_populate().

Opportunistically use check_add_overflow() instead of manually checking for
wrap, mostly so that the inclusive math doesn't need to be copy+pasted in
the "is private" check.

Fixes: c846b451d3c5 ("KVM: TDX: Add an ioctl to create initial guest memory")
Signed-off-by: Sean Christopherson <[email protected]>
---
 arch/x86/kvm/vmx/tdx.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c
index 929115aeb9ec..85699ea021fe 100644
--- a/arch/x86/kvm/vmx/tdx.c
+++ b/arch/x86/kvm/vmx/tdx.c
@@ -3219,7 +3219,7 @@ static int tdx_vcpu_init_mem_region(struct kvm_vcpu *vcpu, struct kvm_tdx_cmd *c
 	struct kvm_tdx *kvm_tdx = to_kvm_tdx(kvm);
 	struct kvm_tdx_init_mem_region region;
 	struct tdx_gmem_post_populate_arg arg;
-	gpa_t nr_bytes;
+	gpa_t nr_bytes, end_gpa;
 	long gmem_ret;
 	int ret;
 
@@ -3241,9 +3241,9 @@ static int tdx_vcpu_init_mem_region(struct kvm_vcpu *vcpu, struct kvm_tdx_cmd *c
 		return -EINVAL;
 
 	if (check_shl_overflow(region.nr_pages, PAGE_SHIFT, &nr_bytes) ||
-	    region.gpa + nr_bytes <= region.gpa ||
+	    check_add_overflow(region.gpa, nr_bytes - 1, &end_gpa) ||
 	    !vt_is_tdx_private_gpa(kvm, region.gpa) ||
-	    !vt_is_tdx_private_gpa(kvm, region.gpa + nr_bytes - 1))
+	    !vt_is_tdx_private_gpa(kvm, end_gpa))
 		return -EINVAL;
 
 	ret = 0;
-- 
2.55.0.679.g6767b8d81c-goog
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.