From nobody Sun Dec 14 02:02:11 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=citrix.com ARC-Seal: i=1; a=rsa-sha256; t=1754499366; cv=none; d=zohomail.com; s=zohoarc; b=lBnmbX28HB7gYclJy3kFWUx1uyZT/6EGvibgUjMCg/YunGialniLes5rHxMtNZU/D1C0PjrTLlANvu6kFfhet7tJvacREhyzI+kZkhmUQ+9OAGr1MKgfTvZrtV7vafkJpe5umU6Qsspx4Xms5ixoXEH+dZpiCAzrjJpNqAmuF3g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1754499366; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wO9JfllS5FWCnVoHAuqpBc7KBOdxU641rFIfPFgpLTw=; b=iwPVDkAdtXohogmPAjJzOslVfWD+p9oXI6+8yPGnPC9FOGtdcRglX/nj0+c38RHzvK9fmnrZ+btHsaIKRvbCPqr+UzOa8h5RCTFqBa7q61IA/vMSOq9MKuJyUazSOHEtZ46BEoQpR3g8uK3UarOzSE/+8cH/I4+bA/bcL4olnZo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1754499366414893.7542877886542; Wed, 6 Aug 2025 09:56:06 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1072026.1435363 (Exim 4.92) (envelope-from ) id 1ujhQa-0000yj-7M; Wed, 06 Aug 2025 16:55:48 +0000 Received: by outflank-mailman (output) from mailman id 1072026.1435363; Wed, 06 Aug 2025 16:55:48 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1ujhQa-0000yc-3H; Wed, 06 Aug 2025 16:55:48 +0000 Received: by outflank-mailman (input) for mailman id 1072026; Wed, 06 Aug 2025 16:55:47 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1ujhQY-0000jh-VT for xen-devel@lists.xenproject.org; Wed, 06 Aug 2025 16:55:46 +0000 Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [2a00:1450:4864:20::435]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id 3271b7b4-72e6-11f0-a323-13f23c93f187; Wed, 06 Aug 2025 18:55:46 +0200 (CEST) Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-3b788feab29so10009f8f.2 for ; Wed, 06 Aug 2025 09:55:46 -0700 (PDT) Received: from localhost.localdomain (host-195-149-20-212.as13285.net. [195.149.20.212]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-3b79c485444sm23908165f8f.66.2025.08.06.09.55.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 06 Aug 2025 09:55:45 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 3271b7b4-72e6-11f0-a323-13f23c93f187 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=citrix.com; s=google; t=1754499346; x=1755104146; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=wO9JfllS5FWCnVoHAuqpBc7KBOdxU641rFIfPFgpLTw=; b=pDwjE5/im67z7/dTU21wKE51j1wSoIaZV7apokNRI+pNdduDxE+LQsmz9sC9fPicph Sq1l7F3nWO7yA2v12angKQs4BSY0gyL5QQjsqQWQ8QupiWIQBw/FcsYIxNzhu2F0745G LHlf01Q6/OCnaFU1sxvJaJX8aza7OWvhQjfRI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1754499346; x=1755104146; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=wO9JfllS5FWCnVoHAuqpBc7KBOdxU641rFIfPFgpLTw=; b=CJMmZmO7Woux7eS0bsj0kVcOy/Rfyy1eTLgHuMrNIdvi7SeE0FezvsHEpS5FFkYaMl ZuXajzXh00pnzVpGvwL0mQmZEJXP8iHIP284vnZWdfmwJoAyJdC4gHbn1ECwXUyhs8lO 7KJPw9TvwSjcRB569GQP/N5GySuGDvkAeiQrv9SpBm4uwKtoF9Rt9uLbPIsutLo/fLoY 7uBzA956siPx2xqsaRO+UymwpiY/6dUPtQXDRh9FO3Tp0F2Yu7EhoGThVEIFmRSjO6Ca uFeY69SKT2qL/J4EeznvmD2h4PsqrZ9GVi2Qcpqcfh1zM7EO/AyahDAZn+ZxxAgZxvq4 XSBA== X-Gm-Message-State: AOJu0YxNRU8kwSiAUaqzwAU7pTAMG7kUhyF28zqrRcZkp2GD+09/pMOX MQjiJDOD2mlvY1a1VVO2QTZ1azGi5gAaJogaX6VaZcxs/InE9MVJEcOXkwP4AOfzmnCoBYHaNc/ sHHA6sOQ= X-Gm-Gg: ASbGncsAqe3daMf1PrqIjCg8CIR35icEAj2CPKI4Hi0v1kAf9IoSvSEWHA4HuvAr7cR tav80MJDy+KQOq6/KXOgE4uU7f3y7Swva5oFS7+/RcC4vslK5+uRVUoAfyHbZZwhDgQ9mKdReeB hNpfjcwOgivr8OE7a2K4FR+0LEMlt15wRBvosSR7TRhPXBlXKDH5mKgmrJD7v+bkdFh9yVY7cbd NCxZ6V1o6FXlts2EGUtYsHyFsQS6V+lYLMbUNtMwSwh9XY+zjh96IUOX0BrCu4aO3WKnhNUbKh3 gWlqrsr+//myFzJchJsl0hFjLFIauB6UQNp/qBLj3az8sON1qcvTXC+sy6Lv8LTOfEwN8qt9hiy UjQ8KmBtQu1Odbf4AjTnnifdgtLIsJjNgMDwQAbKng/d4SsXuQmxEepm0KtpYoZQ9Gs4pPn7H58 08 X-Google-Smtp-Source: AGHT+IEKw27/CH5tQ523u/T3Z2EEXzij0UN9NFs09fawluLr4FOsc/yxHA8IG/WkRQbgAA41opXegw== X-Received: by 2002:a05:6000:258a:b0:3b7:9af4:9c93 with SMTP id ffacd0b85a97d-3b8f41c836cmr3450720f8f.35.1754499345637; Wed, 06 Aug 2025 09:55:45 -0700 (PDT) From: Andrew Cooper To: Xen-devel Cc: Andrew Cooper , Frediano Ziglio , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Ross Lagerwall Subject: [PATCH] x86/domctl: Reject XEN_DOMCTL_hypercall_init against oneself Date: Wed, 6 Aug 2025 17:55:43 +0100 Message-Id: <20250806165543.169140-1-andrew.cooper3@citrix.com> X-Mailer: git-send-email 2.39.5 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @citrix.com) X-ZM-MESSAGEID: 1754499367861116600 A toolstack is expected to use XEN_DOMCTL_hypercall_init where applicable to construct a new guest, but is absolutely not expected to use it against itself. Kernels have a stable ABI for accessing the same functionality, via MSR 0x40000000. Found when auditing hypercalls for Host UEFI-SecureBoot safety. Reported-by: Frediano Ziglio Signed-off-by: Andrew Cooper Reviewed-by: Jan Beulich --- CC: Anthony PERARD CC: Michal Orzel CC: Jan Beulich CC: Julien Grall CC: Roger Pau Monn=C3=A9 CC: Stefano Stabellini CC: Ross Lagerwall CC: Frediano Ziglio --- xen/arch/x86/domctl.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/xen/arch/x86/domctl.c b/xen/arch/x86/domctl.c index 3044f706de1c..bf1ee4ed51a0 100644 --- a/xen/arch/x86/domctl.c +++ b/xen/arch/x86/domctl.c @@ -372,6 +372,14 @@ long arch_do_domctl( struct page_info *page; void *hypercall_page; =20 + /* + * Kernels should use the MSR method to get a hypercall page. The + * toolstack should not be using the DOMCTL on itself. + */ + ret =3D -EINVAL; + if ( d =3D=3D currd ) + break; + page =3D get_page_from_gfn(d, gmfn, NULL, P2M_ALLOC); =20 if ( !page || !get_page_type(page, PGT_writable_page) ) base-commit: 68797a710f4e91cc09fe5650ee14478316010f88 --=20 2.39.5