From nobody Mon Apr 13 01:51:38 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass header.i=dpsmith@apertussolutions.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=apertussolutions.com) ARC-Seal: i=2; a=rsa-sha256; t=1771279406; cv=pass; d=zohomail.com; s=zohoarc; b=Zm8TF12tLFtRa0roa0yRWtL2tsX3OzCYJfokMr3hseRRGJy0HNq/B9dV80K4p5wCz/00Sal66IaszqKE/4F/VMrz6B62QkQ1Rhp+hzWimPxRpI/roTarTbNUhqV0zX9O0ak+4W3VTsMGzqTDoa092/DZf99SX7liQcESxHL4/kw= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1771279406; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4VEgKRoBkaKV62x2vF6xqW5mSzNd6FYxa2E8lFTgOn4=; b=mwLJfDvLx+xds9fNxEv+7rwhDJIi/azPmW+uF0UD7pAChYxIRvqZEOBBHyLx5LdzuSpSUohkmm/1/8DJD9+yV1Zvsj5dgLMC3+U2UTTE/qPbpbJbYb5PV21ngEYmsQAtb0n+f+HSFNrAG9zD0GJTgYjkcQ6m9sD7n3YBRPCNB/M= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass header.i=dpsmith@apertussolutions.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=apertussolutions.com) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1771279406433903.3592679129141; Mon, 16 Feb 2026 14:03:26 -0800 (PST) Received: from list by lists.xenproject.org with outflank-mailman.1234537.1537748 (Exim 4.92) (envelope-from ) id 1vs6gA-0005Ck-7N; Mon, 16 Feb 2026 22:02:54 +0000 Received: by outflank-mailman (output) from mailman id 1234537.1537748; Mon, 16 Feb 2026 22:02:54 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1vs6gA-0005Cd-45; Mon, 16 Feb 2026 22:02:54 +0000 Received: by outflank-mailman (input) for mailman id 1234537; Mon, 16 Feb 2026 22:02:53 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1vs6g8-0005CW-Rh for xen-devel@lists.xenproject.org; Mon, 16 Feb 2026 22:02:52 +0000 Received: from sender4-of-o50.zoho.com (sender4-of-o50.zoho.com [136.143.188.50]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id 3ba3a228-0b83-11f1-b164-2bf370ae4941; Mon, 16 Feb 2026 23:02:50 +0100 (CET) Received: by mx.zohomail.com with SMTPS id 1771279356362254.9074161418365; Mon, 16 Feb 2026 14:02:36 -0800 (PST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 3ba3a228-0b83-11f1-b164-2bf370ae4941 ARC-Seal: i=1; a=rsa-sha256; t=1771279359; cv=none; d=zohomail.com; s=zohoarc; b=fsJigS7W0oSYt93O6uP7xjEitmWGpEzqU1BDOq81q824QpAG27qnb/s7dWSnlBl5hcLwSzkwRF9BcPdie7JxgmCBo7rklaAypVqjOtXWegirTRquPIN7azNwegLsZySmngwtdEF47HJDvvrdcWWpu/+itI2xaOrh+3oZXrEda6g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1771279359; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:MIME-Version:Message-ID:Subject:Subject:To:To:Message-Id:Reply-To; bh=4VEgKRoBkaKV62x2vF6xqW5mSzNd6FYxa2E8lFTgOn4=; b=PCUwAUVZ3ovEorBfTmYjnKmDh9h1mOK0qCxxwllJSb/q6hq9wyDNz0B5DfSxH/jWofiYvuEjS//X+voQMS03zSMa9zrdlDoyINU2EhOPecvarW7QmgIqNGgNvLLsungMpvxDMEDZDSxYgFd17eDWOYhWW6mXETW9FuUYPOHhuBM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=apertussolutions.com; spf=pass smtp.mailfrom=dpsmith@apertussolutions.com; dmarc=pass header.from= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1771279359; s=zoho; d=apertussolutions.com; i=dpsmith@apertussolutions.com; h=From:From:To:To:Cc:Cc:Subject:Subject:Date:Date:Message-Id:Message-Id:MIME-Version:Content-Transfer-Encoding:Reply-To; bh=4VEgKRoBkaKV62x2vF6xqW5mSzNd6FYxa2E8lFTgOn4=; b=Q2nzDv9KGwZS7v97r2FYPEy6CB9nX2CwIN8D6Wc85W9x6iQNawZp8FoJGPJwtUk4 4ZFHOSIrgP27YtQkIFy7EnwA6aNRgagxjwrHa88WdOPubwsijtJsyNLSS+DNzBRmWii ZdcLzx92kthgy7j+ejFJ1mrbc2/EIBNFGUU1DKZU= From: "Daniel P. Smith" To: xen-devel@lists.xenproject.org Cc: "Daniel P. Smith" , Chris Rogers , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini Subject: [BUG] common/domctl: xsm update for get_domain_state access Date: Mon, 16 Feb 2026 16:57:48 -0500 Message-Id: <20260216215748.20398-1-dpsmith@apertussolutions.com> X-Mailer: git-send-email 2.39.5 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ZohoMailClient: External X-ZohoMail-DKIM: pass (identity dpsmith@apertussolutions.com) X-ZM-MESSAGEID: 1771279408001158500 Content-Type: text/plain; charset="utf-8" When using XSM Flask, passing DOMIND_INVALID will result in a NULL pointer reference from the passing of NULL as the target domain to xsm_get_domain_state(). Simply not invoking xsm_get_domain_state() when the target domain is NULL opens the opportunity to circumvent the XSM get_domain_state access check. This is due to the fact that the call to xsm_domctl() for get_domain_state op is a no-op check, deferring to xsm_get_domain_state(). Modify the helper get_domain_state() to ensure the requesting domain has get_domain_state access for the target domain, whether the target domain is explicitly set or implicitly determined with a domain state search. In the = case of access not being allowed for a domain found during an implicit search, t= he search will continue to the next domain whose state has changed. Signed-off-by: Daniel P. Smith Reported-by: Chris Rogers Fixes: 3ad3df1bd0aa ("xen: add new domctl get_domain_state") --- xen/common/domain.c | 22 +++++++++++++++++++--- xen/common/domctl.c | 7 ++----- 2 files changed, 21 insertions(+), 8 deletions(-) diff --git a/xen/common/domain.c b/xen/common/domain.c index de6fdf59236e..4886c59c874c 100644 --- a/xen/common/domain.c +++ b/xen/common/domain.c @@ -210,7 +210,7 @@ static void set_domain_state_info(struct xen_domctl_get= _domain_state *info, int get_domain_state(struct xen_domctl_get_domain_state *info, struct doma= in *d, domid_t *domid) { - unsigned int dom; + unsigned int dom =3D 0; int rc =3D -ENOENT; struct domain *hdl; =20 @@ -219,6 +219,10 @@ int get_domain_state(struct xen_domctl_get_domain_stat= e *info, struct domain *d, =20 if ( d ) { + rc =3D xsm_get_domain_state(XSM_XS_PRIV, d); + if ( rc ) + return rc; + set_domain_state_info(info, d); =20 return 0; @@ -238,10 +242,10 @@ int get_domain_state(struct xen_domctl_get_domain_sta= te *info, struct domain *d, =20 while ( dom_state_changed ) { - dom =3D find_first_bit(dom_state_changed, DOMID_MASK + 1); + dom =3D find_next_bit(dom_state_changed, DOMID_MASK + 1, dom); if ( dom >=3D DOMID_FIRST_RESERVED ) break; - if ( test_and_clear_bit(dom, dom_state_changed) ) + if ( test_bit(dom, dom_state_changed) ) { *domid =3D dom; =20 @@ -249,6 +253,15 @@ int get_domain_state(struct xen_domctl_get_domain_stat= e *info, struct domain *d, =20 if ( d ) { + rc =3D xsm_get_domain_state(XSM_XS_PRIV, d); + if ( rc ) + { + rcu_unlock_domain(d); + rc =3D -ENOENT; + dom++; + continue; + } + set_domain_state_info(info, d); =20 rcu_unlock_domain(d); @@ -256,10 +269,13 @@ int get_domain_state(struct xen_domctl_get_domain_sta= te *info, struct domain *d, else memset(info, 0, sizeof(*info)); =20 + clear_bit(dom, dom_state_changed); rc =3D 0; =20 break; } + + dom++; } =20 out: diff --git a/xen/common/domctl.c b/xen/common/domctl.c index 29a7726d32d0..2eedc639c72a 100644 --- a/xen/common/domctl.c +++ b/xen/common/domctl.c @@ -860,12 +860,9 @@ long do_domctl(XEN_GUEST_HANDLE_PARAM(xen_domctl_t) u_= domctl) break; =20 case XEN_DOMCTL_get_domain_state: - ret =3D xsm_get_domain_state(XSM_XS_PRIV, d); - if ( ret ) - break; - - copyback =3D 1; ret =3D get_domain_state(&op->u.get_domain_state, d, &op->domain); + if ( !ret ) + copyback =3D 1; break; =20 default: --=20 2.39.5