From nobody Tue Mar 3 03:02:46 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass header.i=dpsmith@apertussolutions.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=apertussolutions.com) ARC-Seal: i=2; a=rsa-sha256; t=1771442065; cv=pass; d=zohomail.com; s=zohoarc; b=ee0a4XQU2TBY5C4WJKoOnxpJWllzUhsKtno+u/Obc3sUEfvkYWHANDwWksFRH50JlDD4GJ7UxN+ED0n3zWNI+DtVSTbMfXWsp7QChw0KpeirYWFoBS1wUv9LY0hWeL78dZjlBrTVhwCyULY5pJOOc9fYm6YDSBr7cKc4oIXZT4k= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1771442065; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=co65X2ipz281/zfrv1FcGAsrzzR3sJZcw4PMaqb9Nn0=; b=efI+wo1e9llErn+mG0i09K5IwRTeYPXci4D6Nbr+OF2Q7AxB0DA9jL4qygo67+2KscJBSs2Hw8uz2Kei0RNPp6WU3ToviUl+FGXFF8p2iMDPPshMksbDGLg8kSYco4YrPqLwRY1JXTFnKThbJEESGdYNKptoEBpA9dXfbgtjNbA= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass header.i=dpsmith@apertussolutions.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=apertussolutions.com) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1771442065439138.00121761337425; Wed, 18 Feb 2026 11:14:25 -0800 (PST) Received: from list by lists.xenproject.org with outflank-mailman.1235944.1538751 (Exim 4.92) (envelope-from ) id 1vsmzd-0006Hu-Gj; Wed, 18 Feb 2026 19:13:49 +0000 Received: by outflank-mailman (output) from mailman id 1235944.1538751; Wed, 18 Feb 2026 19:13:49 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1vsmzd-0006Hn-Cr; Wed, 18 Feb 2026 19:13:49 +0000 Received: by outflank-mailman (input) for mailman id 1235944; Wed, 18 Feb 2026 19:13:48 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1vsmzc-0006Ha-LH for xen-devel@lists.xenproject.org; Wed, 18 Feb 2026 19:13:48 +0000 Received: from sender4-of-o50.zoho.com (sender4-of-o50.zoho.com [136.143.188.50]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id f18b903b-0cfd-11f1-9ccf-f158ae23cfc8; Wed, 18 Feb 2026 20:13:45 +0100 (CET) Received: by mx.zohomail.com with SMTPS id 1771442013028766.098741949677; Wed, 18 Feb 2026 11:13:33 -0800 (PST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: f18b903b-0cfd-11f1-9ccf-f158ae23cfc8 ARC-Seal: i=1; a=rsa-sha256; t=1771442015; cv=none; d=zohomail.com; s=zohoarc; b=Ge3gzbpeAUp+XtLApcWZpNBAZv0oLMDjCtHZgiiavFdmAlLGOEJ2cOngiFQMpvZTp8TVyEdm4FKKs8clWfZDGiMLV25gynnAHM3w7//FJUy1sBVvMGK3auguKGjhpQTvKgZa/qUhJfDNCxlQIZ5PaHKic2w4SSC/YMv0frt04TQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1771442015; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:MIME-Version:Message-ID:Subject:Subject:To:To:Message-Id:Reply-To; bh=co65X2ipz281/zfrv1FcGAsrzzR3sJZcw4PMaqb9Nn0=; b=g5qtz8xPoA22JrKZoTokwN3CYmdcsMk8E4Dd7Fxbd50b6EgLf6G5JtQbMhs+QrGT0EflNLV6IEALLAw/nSqrGVdRIZjCyiP1DfaO6qwmZLHNO6DpEi0sj1QekpI08MU+iJBWPkh7mWLeYHs1fzp9y3mmBF0eETFyLp6tA7JZnyk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=apertussolutions.com; spf=pass smtp.mailfrom=dpsmith@apertussolutions.com; dmarc=pass header.from= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1771442015; s=zoho; d=apertussolutions.com; i=dpsmith@apertussolutions.com; h=From:From:To:To:Cc:Cc:Subject:Subject:Date:Date:Message-Id:Message-Id:MIME-Version:Content-Transfer-Encoding:Reply-To; bh=co65X2ipz281/zfrv1FcGAsrzzR3sJZcw4PMaqb9Nn0=; b=gdxwCTZGZ6LJB3GJ0eTXlLhoMznXnsUYrbRbKl7V8U2U88fkXvImFYMoPdpXqyXN i6/0mv0ToNjpLc0nGmTVSEnhLZtz9Jm9aJjQ29A37kKJwcw4EBP3ZrK/TRptLPVumCF hB1lsBy38rJtcb9kji6d6wDpe7yBp77IxeZ4qEI4= From: "Daniel P. Smith" To: xen-devel@lists.xenproject.org Cc: "Daniel P. Smith" , Chris Rogers , Dmytro Firsov , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini Subject: [BUG v2] common/domctl: xsm update for get_domain_state access Date: Wed, 18 Feb 2026 14:08:55 -0500 Message-Id: <20260218190855.7272-1-dpsmith@apertussolutions.com> X-Mailer: git-send-email 2.39.5 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ZohoMailClient: External X-ZohoMail-DKIM: pass (identity dpsmith@apertussolutions.com) X-ZM-MESSAGEID: 1771442068853154100 Content-Type: text/plain; charset="utf-8" When using XSM Flask, passing DOMID_INVALID will result in a NULL pointer reference from the passing of NULL as the target domain to xsm_get_domain_state(). Simply not invoking xsm_get_domain_state() when the target domain is NULL opens the opportunity to circumvent the XSM get_domain_state access check. This is due to the fact that the call to xsm_domctl() for get_domain_state op is a no-op check, deferring to xsm_get_domain_state(). Modify the helper get_domain_state() to ensure the requesting domain has get_domain_state access for the target domain, whether the target domain is explicitly set or implicitly determined with a domain state search. In the = case of access not being allowed for a domain found during an implicit search, t= he search will continue to the next domain whose state has changed. Fixes: 3ad3df1bd0aa ("xen: add new domctl get_domain_state") Reported-by: Chris Rogers Reported-by: Dmytro Firsov Signed-off-by: Daniel P. Smith --- Changes in v2: - fix commit message - init dom as -1 - rework loop logic to use test_and_clear_bit() --- xen/common/domain.c | 27 +++++++++++++++++++++------ xen/common/domctl.c | 7 ++----- 2 files changed, 23 insertions(+), 11 deletions(-) diff --git a/xen/common/domain.c b/xen/common/domain.c index de6fdf59236e..2ffec331a8d1 100644 --- a/xen/common/domain.c +++ b/xen/common/domain.c @@ -210,7 +210,7 @@ static void set_domain_state_info(struct xen_domctl_get= _domain_state *info, int get_domain_state(struct xen_domctl_get_domain_state *info, struct doma= in *d, domid_t *domid) { - unsigned int dom; + unsigned int dom =3D -1; int rc =3D -ENOENT; struct domain *hdl; =20 @@ -219,6 +219,10 @@ int get_domain_state(struct xen_domctl_get_domain_stat= e *info, struct domain *d, =20 if ( d ) { + rc =3D xsm_get_domain_state(XSM_XS_PRIV, d); + if ( rc ) + return rc; + set_domain_state_info(info, d); =20 return 0; @@ -238,28 +242,39 @@ int get_domain_state(struct xen_domctl_get_domain_sta= te *info, struct domain *d, =20 while ( dom_state_changed ) { - dom =3D find_first_bit(dom_state_changed, DOMID_MASK + 1); + dom =3D find_next_bit(dom_state_changed, DOMID_MASK + 1, dom + 1); if ( dom >=3D DOMID_FIRST_RESERVED ) break; + + d =3D rcu_lock_domain_by_id(dom); + if ( d && xsm_get_domain_state(XSM_XS_PRIV, d) ) + { + rcu_unlock_domain(d); + d =3D NULL; + continue; + } + if ( test_and_clear_bit(dom, dom_state_changed) ) { *domid =3D dom; =20 - d =3D rcu_lock_domain_by_id(dom); - if ( d ) { set_domain_state_info(info, d); - rcu_unlock_domain(d); } else memset(info, 0, sizeof(*info)); =20 rc =3D 0; - break; } + + if ( d ) + { + rcu_unlock_domain(d); + d =3D NULL; + } } =20 out: diff --git a/xen/common/domctl.c b/xen/common/domctl.c index 29a7726d32d0..2eedc639c72a 100644 --- a/xen/common/domctl.c +++ b/xen/common/domctl.c @@ -860,12 +860,9 @@ long do_domctl(XEN_GUEST_HANDLE_PARAM(xen_domctl_t) u_= domctl) break; =20 case XEN_DOMCTL_get_domain_state: - ret =3D xsm_get_domain_state(XSM_XS_PRIV, d); - if ( ret ) - break; - - copyback =3D 1; ret =3D get_domain_state(&op->u.get_domain_state, d, &op->domain); + if ( !ret ) + copyback =3D 1; break; =20 default: --=20 2.39.5