KVM: x86/mmu: Explicitly disallow private accesses to emulated MMIO
authorSean Christopherson <seanjc@google.com>
Wed, 28 Feb 2024 02:41:42 +0000 (18:41 -0800)
committerPaolo Bonzini <pbonzini@redhat.com>
Tue, 7 May 2024 15:59:21 +0000 (11:59 -0400)
Explicitly detect and disallow private accesses to emulated MMIO in
kvm_handle_noslot_fault() instead of relying on kvm_faultin_pfn_private()
to perform the check.  This will allow the page fault path to go straight
to kvm_handle_noslot_fault() without bouncing through __kvm_faultin_pfn().

Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-ID: <20240228024147.41573-12-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
arch/x86/kvm/mmu/mmu.c

index ac7cdbb9ee0ae34727a4aff85028813a109b5a1a..f3cd70419e42d515d99751c427c0be86529472d6 100644 (file)
@@ -3261,6 +3261,11 @@ static int kvm_handle_noslot_fault(struct kvm_vcpu *vcpu,
 {
        gva_t gva = fault->is_tdp ? 0 : fault->addr;
 
+       if (fault->is_private) {
+               kvm_mmu_prepare_memory_fault_exit(vcpu, fault);
+               return -EFAULT;
+       }
+
        vcpu_cache_mmio_info(vcpu, gva, fault->gfn,
                             access & shadow_mmio_access_mask);