[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 30/34] Fix WHPX issue leaking tpr values
From: |
Paolo Bonzini |
Subject: |
[Qemu-devel] [PULL 30/34] Fix WHPX issue leaking tpr values |
Date: |
Tue, 6 Mar 2018 14:19:26 +0100 |
From: "Justin Terry (VM) via Qemu-devel" <address@hidden>
Fixes an issue where if the tpr is assigned to the array but not a different
value from what is already expected on the vp the code will skip incrementing
the reg_count. In this case its possible that we set an invalid memory section
of the next call for DeliverabilityNotifications that was not expected.
The fix is to use a local variable to store the temporary tpr and only update
the array if the local tpr value is different than the vp context.
Signed-off-by: Justin Terry (VM) <address@hidden>
Message-Id: <address@hidden>
Signed-off-by: Paolo Bonzini <address@hidden>
Signed-off-by: Justin Terry (VM) via Qemu-devel <address@hidden>
---
target/i386/whpx-all.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/target/i386/whpx-all.c b/target/i386/whpx-all.c
index 7e58d5f..47a6935 100644
--- a/target/i386/whpx-all.c
+++ b/target/i386/whpx-all.c
@@ -687,6 +687,7 @@ static void whpx_vcpu_pre_run(CPUState *cpu)
struct CPUX86State *env = (CPUArchState *)(cpu->env_ptr);
X86CPU *x86_cpu = X86_CPU(cpu);
int irq;
+ uint8_t tpr;
WHV_X64_PENDING_INTERRUPTION_REGISTER new_int = {0};
UINT32 reg_count = 0;
WHV_REGISTER_VALUE reg_values[3] = {0};
@@ -746,9 +747,10 @@ static void whpx_vcpu_pre_run(CPUState *cpu)
}
/* Sync the TPR to the CR8 if was modified during the intercept */
- reg_values[reg_count].Reg64 = cpu_get_apic_tpr(x86_cpu->apic_state);
- if (reg_values[reg_count].Reg64 != vcpu->tpr) {
- vcpu->tpr = reg_values[reg_count].Reg64;
+ tpr = cpu_get_apic_tpr(x86_cpu->apic_state);
+ if (tpr != vcpu->tpr) {
+ vcpu->tpr = tpr;
+ reg_values[reg_count].Reg64 = tpr;
cpu->exit_request = 1;
reg_names[reg_count] = WHvX64RegisterCr8;
reg_count += 1;
--
1.8.3.1
- [Qemu-devel] [PULL 16/34] memory: inline some performance-sensitive accessors, (continued)
- [Qemu-devel] [PULL 16/34] memory: inline some performance-sensitive accessors, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 20/34] address_space_map: address_space_to_flatview needs RCU lock, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 21/34] address_space_rw: address_space_to_flatview needs RCU lock, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 23/34] checkpatch: add check for `while` and `for`, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 24/34] Revert "build-sys: compile with -Og or -O1 when --enable-debug", Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 25/34] Fixing WHPX casing to match SDK, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 27/34] Remove unnecessary WHPX __debugbreak();, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 26/34] Resolves WHPX breaking changes in SDK 17095, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 29/34] Fix WHPX typo in 'mmio', Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 30/34] Fix WHPX issue leaking tpr values,
Paolo Bonzini <=
- [Qemu-devel] [PULL 34/34] use g_path_get_basename instead of basename, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 31/34] WHXP Removes the use of WHvGetExitContextSize, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 32/34] WHPX improve interrupt notification registration, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 33/34] balloon: Fix documentation of the --balloon parameter and deprecate it, Paolo Bonzini, 2018/03/06
- [Qemu-devel] [PULL 28/34] Fix WHPX additional lock acquisition, Paolo Bonzini, 2018/03/06
- Re: [Qemu-devel] [PULL 00/34] Misc patches for 2018-03-06, no-reply, 2018/03/06
- Re: [Qemu-devel] [PULL 00/34] Misc patches for 2018-03-06, Peter Maydell, 2018/03/06
- Re: [Qemu-devel] [PULL 00/34] Misc patches for 2018-03-06, Thomas Huth, 2018/03/07