From nobody Thu Aug 13 09:22:18 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=xenproject.org ARC-Seal: i=1; a=rsa-sha256; t=1786031391; cv=none; d=zohomail.com; s=zohoarc; b=hJzyo0VLNcvxb6VpgShyzx7jRqWO66yprOs/3g4NYrag5z7tSGoOCODh3ucAQjb18d8z+rf8hKdEvX6wChZMTpQkO4Lt1xIC/GovtPYflPZJWLULK1wnsoDQ2/kC9ePIeTvY0+1YhV4tBMhgDoXmH68c7RB+BpBBoerYUTfj4/M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786031391; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4D0z06vjOYg9blHCRUsB77y4tATWODBBrawlmczEE3k=; b=EISL/8wQPpuqGmo2khGYosvCw//9lzz8ozZl72WnGClNoSASgEEkkB9o3+f1FMtVEZj2T0VJwQsPXqkWBkO1xOVWn2Spf2c/2AFbNSfWXYRIVTtaW2PiCPlhS3TI/TZvdtHcYORR/6y2S2AeeonSuYmfhGlQNTJwKQsWhKCSNqQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1786031390946855.3360251840328; Thu, 6 Aug 2026 08:49:50 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1384954.1627646 (Exim 4.92) (envelope-from ) id 1ws0LY-0004t2-Vq; Thu, 06 Aug 2026 15:49:28 +0000 Received: by outflank-mailman (output) from mailman id 1384954.1627646; Thu, 06 Aug 2026 15:49:28 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1ws0LY-0004ss-TF; Thu, 06 Aug 2026 15:49:28 +0000 Received: by outflank-mailman (input) for mailman id 1384954; Thu, 06 Aug 2026 15:49:27 +0000 Received: from mail.xenproject.org ([104.130.215.37]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1ws0LX-0004sV-Pv for xen-devel@lists.xenproject.org; Thu, 06 Aug 2026 15:49:27 +0000 Received: from xenbits.xenproject.org ([104.239.192.120]) by mail.xenproject.org with esmtp (Exim 4.96) (envelope-from ) id 1ws0LX-00834N-1a; Thu, 06 Aug 2026 15:49:27 +0000 Received: from 224.pool85-54-217.dynamic.orange.es ([85.54.217.224] helo=localhost) by xenbits.xenproject.org with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1ws0LW-009qdZ-2z; Thu, 06 Aug 2026 15:49:27 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=xenproject.org; s=20200302mail; h=Content-Transfer-Encoding:Content-Type: MIME-Version:References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From; bh=4D0z06vjOYg9blHCRUsB77y4tATWODBBrawlmczEE3k=; b=1FpGpzkxrMGxAJSJ6Ab7WQRMjd SFsrpewCbERnt7CjwpKqp4f2Wq8cXbDeMLDvxEUV+HGSVDzrhWRsgoUe1Eg+wqrLYzdWaTWwBnSHj YHYBpLyrI5rf8h38BaHm7Fu3MORoI+ikSlF0XUrKdCsNYDTXB8lfSyDfetTtrFTy8HWo=; From: Roger Pau Monne To: xen-devel@lists.xenproject.org Cc: Roger Pau Monne , Jan Beulich , Andrew Cooper , Teddy Astie Subject: [PATCH v2 1/2] x86/pci: prevent cross-device accesses in pci_mmcfg_{read,write}() Date: Thu, 6 Aug 2026 17:26:18 +0200 Message-ID: <20260806152619.23881-2-roger@xenproject.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260806152619.23881-1-roger@xenproject.org> References: <20260806152619.23881-1-roger@xenproject.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @xenproject.org) X-ZM-MESSAGEID: 1786031391992158500 Introduce a specific check that prevents an accesses from spilling across two devices. Signed-off-by: Roger Pau Monn=C3=A9 Reviewed-by: Jan Beulich Reviewed-by: Stewart Hildebrand --- Changes since v1: - New in this version. --- xen/arch/x86/x86_64/mmconfig_64.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/xen/arch/x86/x86_64/mmconfig_64.c b/xen/arch/x86/x86_64/mmconf= ig_64.c index 940cf6d7471b..91b1a398e646 100644 --- a/xen/arch/x86/x86_64/mmconfig_64.c +++ b/xen/arch/x86/x86_64/mmconfig_64.c @@ -61,7 +61,8 @@ int pci_mmcfg_read(unsigned int seg, unsigned int bus, char __iomem *addr; =20 /* Why do we have this when nobody checks it. How about a BUG()!? -AK = */ - if (unlikely((bus > 255) || (devfn > 255) || (reg > 4095))) { + if (unlikely((bus > 255) || (devfn > 255) || + (reg + len > PCI_CFG_SPACE_EXP_SIZE))) { err: *value =3D -1; return -EINVAL; } @@ -91,7 +92,8 @@ int pci_mmcfg_write(unsigned int seg, unsigned int bus, char __iomem *addr; =20 /* Why do we have this when nobody checks it. How about a BUG()!? -AK = */ - if (unlikely((bus > 255) || (devfn > 255) || (reg > 4095))) + if (unlikely((bus > 255) || (devfn > 255) || + (reg + len > PCI_CFG_SPACE_EXP_SIZE))) return -EINVAL; =20 addr =3D pci_dev_base(seg, bus, devfn); --=20 2.53.0 From nobody Thu Aug 13 09:22:18 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=xenproject.org ARC-Seal: i=1; a=rsa-sha256; t=1786031399; cv=none; d=zohomail.com; s=zohoarc; b=hrUP/xquY1vqFp9GVdG5i4TTyTtFf8nlo62pIRhrOkGqnNJzM3z5nvC3VoPHptxYZMH85oFd/8NpQJGixJt+FWBXA0yY92n1QFjF+ZYPq3cm+V9iV3k8p5G4aPY1a4rwa5WJ8kJiGpwxhg/IV5oHhZJlPhhBK5/JqQFE4JKBQtk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786031399; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=v8h1wppUhC/u/nkKEBQJ22KAaFfqUX8DZenk5l0qwSs=; b=hfIy+6LVHxL0VcvbcdDbAPXpF6KFtvGs1R1b6k7yjTDdIhNpBgZD90toNw/+IOosv0vXZQ2estrvSndQTAaLsqeoYbhpeInQNyUGX3h2VqMbby3hVeWQeEj/swOhBGx3y1Dj0iUL4i5Wf6JtYuHkgrUyw6wLaCXZ/Fri5MaXu6o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1786031399499396.0512371698791; Thu, 6 Aug 2026 08:49:59 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1384955.1627656 (Exim 4.92) (envelope-from ) id 1ws0Le-000588-98; Thu, 06 Aug 2026 15:49:34 +0000 Received: by outflank-mailman (output) from mailman id 1384955.1627656; Thu, 06 Aug 2026 15:49:34 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1ws0Le-000580-4X; Thu, 06 Aug 2026 15:49:34 +0000 Received: by outflank-mailman (input) for mailman id 1384955; Thu, 06 Aug 2026 15:49:32 +0000 Received: from mail.xenproject.org ([104.130.215.37]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1ws0Lc-000579-S3 for xen-devel@lists.xenproject.org; Thu, 06 Aug 2026 15:49:32 +0000 Received: from xenbits.xenproject.org ([104.239.192.120]) by mail.xenproject.org with esmtp (Exim 4.96) (envelope-from ) id 1ws0Lc-00834V-28; Thu, 06 Aug 2026 15:49:32 +0000 Received: from 224.pool85-54-217.dynamic.orange.es ([85.54.217.224] helo=localhost) by xenbits.xenproject.org with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1ws0Lc-009r6I-0L; Thu, 06 Aug 2026 15:49:32 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=xenproject.org; s=20200302mail; h=Content-Transfer-Encoding:Content-Type: MIME-Version:References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From; bh=v8h1wppUhC/u/nkKEBQJ22KAaFfqUX8DZenk5l0qwSs=; b=E3djs5jXPwiXuhHLhTg9/Zkj/V BUEnWf+1Uz1xhEse4IKMmlZxHISKW5NFHqUzbijq8DDScnvR9y0sEWsKLv8kojb/QLURb9HkRHnSy rnEfu87ivdlfZDUnuXA9O+B1qTT17bpzIEnCU0sJrQuMFPphb0CdfikQg+O24mSr+w2s=; From: Roger Pau Monne To: xen-devel@lists.xenproject.org Cc: Roger Pau Monne , Anthony PERARD , Jan Beulich , Andrew Cooper , Teddy Astie , Stewart Hildebrand , Jason Andryuk Subject: [PATCH v2 2/2] xen/vpci: allow unaligned accesses by the hardware domain Date: Thu, 6 Aug 2026 17:26:19 +0200 Message-ID: <20260806152619.23881-3-roger@xenproject.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260806152619.23881-1-roger@xenproject.org> References: <20260806152619.23881-1-roger@xenproject.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @xenproject.org) X-ZM-MESSAGEID: 1786031401488158500 It's possible for domains to generate unaligned PCI config space accesses when using ECAM, and hence vPCI should support those at least for the hardware domain. Such unaligned accesses to the PCI config space have been reported to come from ACPI logic. Relax the checking in vpci_access_allowed() to allow such accesses for the hardware domain, and fix the handling in pci_conf_{read,write}{16,32}() to fulfill them using MMCFG. MMCFG regions are identity exposed to the hardware domain, and hence such unaligned accesses can only come as a result of the host having MMCFG in the first place, as otherwise MMCFG won't be exposed to the hardware domain either. Note that vpci_ecam_{read,write}() already refuse accesses that cross a device boundary unconditionally. Reported-by: Jason Andryuk Signed-off-by: Roger Pau Monn=C3=A9 Reviewed-by: Jan Beulich Reviewed-by: Stewart Hildebrand --- tools/include/xen-tools/common-macros.h | 2 ++ xen/arch/x86/x86_64/pci.c | 8 ++++---- xen/drivers/vpci/vpci.c | 6 ++++-- 3 files changed, 10 insertions(+), 6 deletions(-) diff --git a/tools/include/xen-tools/common-macros.h b/tools/include/xen-to= ols/common-macros.h index 88b4a0e5a693..1f9146b23b0e 100644 --- a/tools/include/xen-tools/common-macros.h +++ b/tools/include/xen-tools/common-macros.h @@ -68,6 +68,8 @@ }) #endif =20 +#define IS_ALIGNED(val, align) (!((val) & ((align) - 1))) + #define ROUNDUP(x, a) (((x) + (a) - 1) & ~((a) - 1)) #define ROUNDDOWN(x, a) ((x) & ~((a) - 1)) =20 diff --git a/xen/arch/x86/x86_64/pci.c b/xen/arch/x86/x86_64/pci.c index 8d33429103b9..6298141c3ca7 100644 --- a/xen/arch/x86/x86_64/pci.c +++ b/xen/arch/x86/x86_64/pci.c @@ -26,7 +26,7 @@ uint8_t pci_conf_read8(pci_sbdf_t sbdf, unsigned int reg) =20 uint16_t pci_conf_read16(pci_sbdf_t sbdf, unsigned int reg) { - if ( sbdf.seg || reg > 255 ) + if ( sbdf.seg || reg > 255 || !IS_ALIGNED(reg, 2) ) { uint32_t value; =20 @@ -39,7 +39,7 @@ uint16_t pci_conf_read16(pci_sbdf_t sbdf, unsigned int re= g) =20 uint32_t pci_conf_read32(pci_sbdf_t sbdf, unsigned int reg) { - if ( sbdf.seg || reg > 255 ) + if ( sbdf.seg || reg > 255 || !IS_ALIGNED(reg, 4) ) { uint32_t value; =20 @@ -60,7 +60,7 @@ void pci_conf_write8(pci_sbdf_t sbdf, unsigned int reg, u= int8_t data) =20 void pci_conf_write16(pci_sbdf_t sbdf, unsigned int reg, uint16_t data) { - if ( sbdf.seg || reg > 255 ) + if ( sbdf.seg || reg > 255 || !IS_ALIGNED(reg, 2) ) pci_mmcfg_write(sbdf.seg, sbdf.bus, sbdf.devfn, reg, 2, data); else pci_conf_write(PCI_CONF_ADDRESS(sbdf, reg), reg & 2, 2, data); @@ -68,7 +68,7 @@ void pci_conf_write16(pci_sbdf_t sbdf, unsigned int reg, = uint16_t data) =20 void pci_conf_write32(pci_sbdf_t sbdf, unsigned int reg, uint32_t data) { - if ( sbdf.seg || reg > 255 ) + if ( sbdf.seg || reg > 255 || !IS_ALIGNED(reg, 4) ) pci_mmcfg_write(sbdf.seg, sbdf.bus, sbdf.devfn, reg, 4, data); else pci_conf_write(PCI_CONF_ADDRESS(sbdf, reg), 0, 4, data); diff --git a/xen/drivers/vpci/vpci.c b/xen/drivers/vpci/vpci.c index 0ac9ec8b0475..9e2c27e3a300 100644 --- a/xen/drivers/vpci/vpci.c +++ b/xen/drivers/vpci/vpci.c @@ -685,6 +685,8 @@ void vpci_write(pci_sbdf_t sbdf, unsigned int reg, unsi= gned int size, /* Helper function to check an access size and alignment on vpci space. */ bool vpci_access_allowed(unsigned int reg, unsigned int len) { + const struct domain *currd =3D current->domain; + /* Check access size. */ if ( len !=3D 1 && len !=3D 2 && len !=3D 4 && len !=3D 8 ) return false; @@ -695,8 +697,8 @@ bool vpci_access_allowed(unsigned int reg, unsigned int= len) return false; #endif =20 - /* Check that access is size aligned. */ - if ( (reg & (len - 1)) ) + /* Refuse unaligned accesses for non-hardware domains. */ + if ( !is_hardware_domain(currd) && !IS_ALIGNED(reg, len) ) return false; =20 return true; --=20 2.53.0