Re: [PATCH] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Sergey Senozhatsky <[email protected]>
| Newsgroups | org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On (26/08/08 15:22), Sergey Senozhatsky wrote: > From: Sean Christopherson <[email protected]> > > Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, > after making MMU pages available for the shadow MMU. If reclaiming shadow > pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to > map memory into an invalid root. On its own, populating an invalid root is > "fine", but because child shadow pages inherit their parent's role, any > children created during the map/fetch will be created as invalid pages, > thus violating KVM's invariant that invalid pages are never on the list of > active MMU pages. > > Note, the underlying flaw has existed since KVM first started tracking > invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root > pagetables"), but the true badness only came along in 2020 (Linux 5.9) > with the invariant that invalid shadow pages can't be on the list of > active pages. > > Note #2, inheriting role.invalid when creating child shadow pages is also > far from ideal; that flaw will be addressed separately. > > Conflicts: > arch/x86/kvm/mmu/mmu.c > arch/x86/kvm/mmu/paging_tmpl.h Sean, can you please take a look if conflict resolution was done correctly?