|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [xen stable-4.20] platform-op/XSM: move resource-{,un}plug-core checks
commit 5d170c81126feb5e855c0dfea88d6a2fe6e93c5f
Author: Jan Beulich <jbeulich@xxxxxxxx>
AuthorDate: Mon Jul 20 16:41:00 2026 +0100
Commit: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
CommitDate: Tue Jul 28 13:08:27 2026 +0100
platform-op/XSM: move resource-{,un}plug-core checks
Integrate the checking with flask_platform_op(); there never really was a
need to defer these checks, as the sub-op has always been known to the
function. As a positive side effect, permissions are then checked at the
same early point with and without Flask.
This is CVE-2026-62427 / part of XSA-499.
Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
Reviewed-by: Roger Pau Monné <roger.pau@xxxxxxxxxx>
Reviewed-by: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
Acked-By: Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx>
(cherry picked from commit 4ef45cbe31427bb3cedb11be45c90b1706205ee9)
---
xen/arch/x86/platform_hypercall.c | 16 ----------------
xen/xsm/flask/hooks.c | 7 ++++---
2 files changed, 4 insertions(+), 19 deletions(-)
diff --git a/xen/arch/x86/platform_hypercall.c
b/xen/arch/x86/platform_hypercall.c
index 67f851237d..07f8439a6d 100644
--- a/xen/arch/x86/platform_hypercall.c
+++ b/xen/arch/x86/platform_hypercall.c
@@ -682,10 +682,6 @@ ret_t do_platform_op(
{
int cpu = op->u.cpu_ol.cpuid;
- ret = xsm_resource_plug_core(XSM_HOOK);
- if ( ret )
- break;
-
if ( cpu >= nr_cpu_ids || !cpu_present(cpu) ||
clocksource_is_tsc() )
{
@@ -708,10 +704,6 @@ ret_t do_platform_op(
{
int cpu = op->u.cpu_ol.cpuid;
- ret = xsm_resource_unplug_core(XSM_HOOK);
- if ( ret )
- break;
-
if ( cpu == 0 )
{
ret = -EOPNOTSUPP;
@@ -736,20 +728,12 @@ ret_t do_platform_op(
}
case XENPF_cpu_hotadd:
- ret = xsm_resource_plug_core(XSM_HOOK);
- if ( ret )
- break;
-
ret = cpu_add(op->u.cpu_add.apic_id,
op->u.cpu_add.acpi_id,
op->u.cpu_add.pxm);
break;
case XENPF_mem_hotadd:
- ret = xsm_resource_plug_core(XSM_HOOK);
- if ( ret )
- break;
-
ret = memory_add(op->u.mem_add.spfn,
op->u.mem_add.epfn,
op->u.mem_add.pxm);
diff --git a/xen/xsm/flask/hooks.c b/xen/xsm/flask/hooks.c
index 2c3bab1d18..baba5c727a 100644
--- a/xen/xsm/flask/hooks.c
+++ b/xen/xsm/flask/hooks.c
@@ -1564,12 +1564,13 @@ static int cf_check flask_platform_op(uint32_t op)
switch ( op )
{
#ifdef CONFIG_X86
- /* These operations have their own XSM hooks */
case XENPF_cpu_online:
- case XENPF_cpu_offline:
case XENPF_cpu_hotadd:
case XENPF_mem_hotadd:
- return 0;
+ return flask_resource_plug_core();
+
+ case XENPF_cpu_offline:
+ return flask_resource_unplug_core();
#endif
case XENPF_settime32:
--
generated by git-patchbot for /home/xen/git/xen.git#stable-4.20
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |