Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp4342241imu; Tue, 18 Dec 2018 13:07:37 -0800 (PST) X-Google-Smtp-Source: AFSGD/U50r3ttyzxjYYniPXvUNS6RfHvhWzccBhbTNgO7xnXaxfFuLJ2V6qrvE0IlsI7AzsQ2xoL X-Received: by 2002:a62:8949:: with SMTP id v70mr17633229pfd.85.1545167257028; Tue, 18 Dec 2018 13:07:37 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1545167257; cv=none; d=google.com; s=arc-20160816; b=0Mkf9RVZzibDmwUuKXf0MANrJuPFAsUfL03+KtY96bBfv23f7UKqdCjv2xq9Kt23dz HDbVHKR+h7OZ2H10jq4T7j8A7e/qWFf+3t8Kb+7pJS07qdp+fBtj18lV4UIJ7e/MF32L Fu+pXBTKAbTorWN+OZS3ea8qKsXEgLU+5ilZWqbLd8G3wFBbKyZvJHqoLVmQFQL5U6+r kOX6L1GGa4AYUTDGe7kkPP9/JiD+eorzrfx1fznN2ZZHCz64IgP3FQ8vbfzNL2yQCHo1 bFzzudQGQKIR5wy3z4zpPnfPkzs5rSnMhs59WoerpiSmKJRbJ6DzEqYn8xq5whNtOJga oOVQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:autocrypt:openpgp:from:references:cc:to:subject :dkim-signature; bh=F+1Jl4CIRfiPBTM5FoEi5pium7S9mvLaBFwu+RPulf4=; b=BA/vpEV57E3CMWHMPIi0M3Y5nN6WQhUHbOgd9VERRxyyxUR9F+O2EnpxfXUZe0+Lwh ho/t2DDg4wVjxXBnna47nCyx/AKMLLESYPR1k8U92hyqJXNywEM6fN1sKxE160mJvicF oUZLLLBnHK9KD810f1gGRz6UTsjyXynLArPEMOX1fGgGI8r+R0VkIDD6AxJKzlWM8kgr KCh0bSSkDYRUf0lHFVF6PwXp4v3yaBnYETZDwe4GbVjg6cAvpvM5zFcqUlVSqe4E1VUL 1oESITCI1VqJTRVNDrmmTmZyDprCJ9ZKbcdk/L9xj6EY4v0YRDQntT5Exwta1q4xdBmN vb0g== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b=px+WCovD; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id v189si13723850pgb.398.2018.12.18.13.07.21; Tue, 18 Dec 2018 13:07:36 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b=px+WCovD; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727693AbeLRVFZ (ORCPT + 99 others); Tue, 18 Dec 2018 16:05:25 -0500 Received: from mail-wm1-f68.google.com ([209.85.128.68]:51620 "EHLO mail-wm1-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726422AbeLRVFY (ORCPT ); Tue, 18 Dec 2018 16:05:24 -0500 Received: by mail-wm1-f68.google.com with SMTP id b11so3978417wmj.1; Tue, 18 Dec 2018 13:05:22 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:subject:to:cc:references:from:openpgp:autocrypt:message-id :date:user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=F+1Jl4CIRfiPBTM5FoEi5pium7S9mvLaBFwu+RPulf4=; b=px+WCovDxwA2RPpCvj+PiecdaWNWnxA01VWg15aaLK/Mn1VkZncszjTUN4IO59VNDS rabe5nTCpoD70Nai+AGTqGm0yehilAtrAxtMXgUzRS+YX+0Rpv6JStJp1r4/611rQdfJ 3Pib/Igna6I4y9q+1T7FkzFsUOQ90Y61QmUZwDDKSj+Yl2f1gcVvSJw0haAXt+Fik0hu NnHf83WI6CKu+otoBhrQz7SLiY8qrpddlpQvIyS2uN898LA3NLQvPrT90Mhz+FhO1eu1 jEmQWIS+YJ8eTkQgI2FQcI00DtvIhgqJKOSu+02Fd1BqgA0KkWEqfBMatJQJxM55Ykbb qmTg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:subject:to:cc:references:from:openpgp :autocrypt:message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=F+1Jl4CIRfiPBTM5FoEi5pium7S9mvLaBFwu+RPulf4=; b=ZUaJW3YaIbTUODFGG/4jWw/2r8mPictjw/SaaYcy1FkExzzNaOWuL5YfOdrzyOxRqI 5eIQRO6uttMxtH9QA1tdkHZe1j9Y+NSsYhQi0muoqOViKRi2GeOmSh3KoMpkhMPsEm67 irHSsP9HH4DK578AMXz4HGXjb7N6GErDvCyrQS82i9tt57HTv0Ey5JjYqesIgWALn0R7 RLGESa4cSntfYAD7vswSYc5Uz6i3Sayg6A+6HXqT2cgkbaKXwFZpSQNeyWzCc3O1rkWD BrHY+l7VDlp+PpP7EvhWXUSYNVyt44UEJHHo7ZgPeOJv0Pv49zZWSXqMmqkfZjoL6HRQ JadQ== X-Gm-Message-State: AA+aEWaYyxgZ6n2FET2oehedBFbRRAA/lXiusDqadWseXN/nTFkfDwV0 KhVj1E+MShrpW83GnQd4Nog= X-Received: by 2002:a1c:7fca:: with SMTP id a193mr4695894wmd.36.1545167121632; Tue, 18 Dec 2018 13:05:21 -0800 (PST) Received: from [192.168.10.165] ([93.56.166.5]) by smtp.googlemail.com with ESMTPSA id a1sm4378137wrw.76.2018.12.18.13.05.19 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 18 Dec 2018 13:05:20 -0800 (PST) Subject: Re: [PATCH] KVM: X86: Fix NULL deref in vcpu_scan_ioapic To: Wanpeng Li , linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= References: <1545014603-4109-1-git-send-email-wanpengli@tencent.com> From: Paolo Bonzini Openpgp: preference=signencrypt Autocrypt: addr=pbonzini@redhat.com; keydata= mQHhBFRCcBIBDqDGsz4K0zZun3jh+U6Z9wNGLKQ0kSFyjN38gMqU1SfP+TUNQepFHb/Gc0E2 CxXPkIBTvYY+ZPkoTh5xF9oS1jqI8iRLzouzF8yXs3QjQIZ2SfuCxSVwlV65jotcjD2FTN04 hVopm9llFijNZpVIOGUTqzM4U55sdsCcZUluWM6x4HSOdw5F5Utxfp1wOjD/v92Lrax0hjiX DResHSt48q+8FrZzY+AUbkUS+Jm34qjswdrgsC5uxeVcLkBgWLmov2kMaMROT0YmFY6A3m1S P/kXmHDXxhe23gKb3dgwxUTpENDBGcfEzrzilWueOeUWiOcWuFOed/C3SyijBx3Av/lbCsHU Vx6pMycNTdzU1BuAroB+Y3mNEuW56Yd44jlInzG2UOwt9XjjdKkJZ1g0P9dwptwLEgTEd3Fo UdhAQyRXGYO8oROiuh+RZ1lXp6AQ4ZjoyH8WLfTLf5g1EKCTc4C1sy1vQSdzIRu3rBIjAvnC tGZADei1IExLqB3uzXKzZ1BZ+Z8hnt2og9hb7H0y8diYfEk2w3R7wEr+Ehk5NQsT2MPI2QBd wEv1/Aj1DgUHZAHzG1QN9S8wNWQ6K9DqHZTBnI1hUlkp22zCSHK/6FwUCuYp1zcAEQEAAbQj UGFvbG8gQm9uemluaSA8cGJvbnppbmlAcmVkaGF0LmNvbT6JAg0EEwECACMFAlRCcBICGwMH CwkIBwMCAQYVCAIJCgsEFgIDAQIeAQIXgAAKCRB+FRAMzTZpsbceDp9IIN6BIA0Ol7MoB15E 11kRz/ewzryFY54tQlMnd4xxfH8MTQ/mm9I482YoSwPMdcWFAKnUX6Yo30tbLiNB8hzaHeRj jx12K+ptqYbg+cevgOtbLAlL9kNgLLcsGqC2829jBCUTVeMSZDrzS97ole/YEez2qFpPnTV0 VrRWClWVfYh+JfzpXmgyhbkuwUxNFk421s4Ajp3d8nPPFUGgBG5HOxzkAm7xb1cjAuJ+oi/K CHfkuN+fLZl/u3E/fw7vvOESApLU5o0icVXeakfSz0LsygEnekDbxPnE5af/9FEkXJD5EoYG SEahaEtgNrR4qsyxyAGYgZlS70vkSSYJ+iT2rrwEiDlo31MzRo6Ba2FfHBSJ7lcYdPT7bbk9 AO3hlNMhNdUhoQv7M5HsnqZ6unvSHOKmReNaS9egAGdRN0/GPDWr9wroyJ65ZNQsHl9nXBqE AukZNr5oJO5vxrYiAuuTSd6UI/xFkjtkzltG3mw5ao2bBpk/V/YuePrJsnPFHG7NhizrxttB nTuOSCMo45pfHQ+XYd5K1+Cv/NzZFNWscm5htJ0HznY+oOsZvHTyGz3v91pn51dkRYN0otqr bQ4tlFFuVjArBZcapSIe6NV8C4cEiSS5AQ0EVEJxcwEIAK+nUrsUz3aP2aBjIrX3a1+C+39R nctpNIPcJjFJ/8WafRiwcEuLjbvJ/4kyM6K7pWUIQftl1P8Woxwb5nqL7zEFHh5I+hKS3haO 5pgco//V0tWBGMKinjqntpd4U4Dl299dMBZ4rRbPvmI8rr63sCENxTnHhTECyHdGFpqSzWzy 97rH68uqMpxbUeggVwYkYihZNd8xt1+lf7GWYNEO/QV8ar/qbRPG6PEfiPPHQd/sldGYavmd //o6TQLSJsvJyJDt7KxulnNT8Q2X/OdEuVQsRT5glLaSAeVAABcLAEnNgmCIGkX7TnQF8a6w gHGrZIR9ZCoKvDxAr7RP6mPeS9sAEQEAAYkDEgQYAQIACQUCVEJxcwIbAgEpCRB+FRAMzTZp scBdIAQZAQIABgUCVEJxcwAKCRC/+9JfeMeug/SlCACl7QjRnwHo/VzENWD9G2VpUOd9eRnS DZGQmPo6Mp3Wy8vL7snGFBfRseT9BevXBSkxvtOnUUV2YbyLmolAODqUGzUI8ViF339poOYN i6Ffek0E19IMQ5+CilqJJ2d5ZvRfaq70LA/Ly9jmIwwX4auvXrWl99/2wCkqnWZI+PAepkcX JRD4KY2fsvRi64/aoQmcxTiyyR7q3/52Sqd4EdMfj0niYJV0Xb9nt8G57Dp9v3Ox5JeWZKXS krFqy1qyEIypIrqcMbtXM7LSmiQ8aJRM4ZHYbvgjChJKR4PsKNQZQlMWGUJO4nVFSkrixc9R Z49uIqQK3b3ENB1QkcdMg9cxsB0Onih8zR+Wp1uDZXnz1ekto+EivLQLqvTjCCwLxxJafwKI bqhQ+hGR9jF34EFur5eWt9jJGloEPVv0GgQflQaE+rRGe+3f5ZDgRe5Y/EJVNhBhKcafcbP8 MzmLRh3UDnYDwaeguYmxuSlMdjFL96YfhRBXs8tUw6SO9jtCgBvoOIBDCxxAJjShY4KIvEpK b2hSNr8KxzelKKlSXMtB1bbHbQxiQcerAipYiChUHq1raFc3V0eOyCXK205rLtknJHhM5pfG 6taABGAMvJgm/MrVILIxvBuERj1FRgcgoXtiBmLEJSb7akcrRlqe3MoPTntSTNvNzAJmfWhd SvP0G1WDLolqvX0OtKMppI91AWVu72f1kolJg43wbaKpRJg1GMkKEI3H+jrrlTBrNl/8e20m TElPRDKzPiowmXeZqFSS1A6Azv0TJoo9as+lWF+P4zCXt40+Zhh5hdHO38EV7vFAVG3iuay6 7ToF8Uy7tgc3mdH98WQSmHcn/H5PFYk3xTP3KHB7b0FZPdFPQXBZb9+tJeZBi9gMqcjMch+Y R8dmTcQRQX14bm5nXlBF7VpSOPZMR392LY7wzAvRdhz7aeIUkdO7VelaspFk2nT7wOj1Y6uL nRxQlLkBDQRUQnHuAQgAx4dxXO6/Zun0eVYOnr5GRl76+2UrAAemVv9Yfn2PbDIbxXqLff7o yVJIkw4WdhQIIvvtu5zH24iYjmdfbg8iWpP7NqxUQRUZJEWbx2CRwkMHtOmzQiQ2tSLjKh/c HeyFH68xjeLcinR7jXMrHQK+UCEw6jqi1oeZzGvfmxarUmS0uRuffAb589AJW50kkQK9VD/9 QC2FJISSUDnRC0PawGSZDXhmvITJMdD4TjYrePYhSY4uuIV02v028TVAaYbIhxvDY0hUQE4r 8ZbGRLn52bEzaIPgl1p/adKfeOUeMReg/CkyzQpmyB1TSk8lDMxQzCYHXAzwnGi8WU9iuE1P 0wARAQABiQHzBBgBAgAJBQJUQnHuAhsMAAoJEH4VEAzNNmmxp1EOoJy0uZggJm7gZKeJ7iUp eX4eqUtqelUw6gU2daz2hE/jsxsTbC/w5piHmk1H1VWDKEM4bQBTuiJ0bfo55SWsUNN+c9hh IX+Y8LEe22izK3w7mRpvGcg+/ZRG4DEMHLP6JVsv5GMpoYwYOmHnplOzCXHvmdlW0i6SrMsB Dl9rw4AtIa6bRwWLim1lQ6EM3PWifPrWSUPrPcw4OLSwFk0CPqC4HYv/7ZnASVkR5EERFF3+ 6iaaVi5OgBd81F1TCvCX2BEyIDRZLJNvX3TOd5FEN+lIrl26xecz876SvcOb5SL5SKg9/rCB ufdPSjojkGFWGziHiFaYhbuI2E+NfWLJtd+ZvWAAV+O0d8vFFSvriy9enJ8kxJwhC0ECbSKF Y+W1eTIhMD3aeAKY90drozWEyHhENf4l/V+Ja5vOnW+gCDQkGt2Y1lJAPPSIqZKvHzGShdh8 DduC0U3xYkfbGAUvbxeepjgzp0uEnBXfPTy09JGpgWbg0w91GyfT/ujKaGd4vxG2Ei+MMNDm S1SMx7wu0evvQ5kT9NPzyq8R2GIhVSiAd2jioGuTjX6AZCFv3ToO53DliFMkVTecLptsXaes uUHgL9dKIfvpm+rNXRn9wAwGjk0X/A== Message-ID: Date: Tue, 18 Dec 2018 22:03:08 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.3.1 MIME-Version: 1.0 In-Reply-To: <1545014603-4109-1-git-send-email-wanpengli@tencent.com> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 17/12/18 03:43, Wanpeng Li wrote: > From: Wanpeng Li > > Reported by syzkaller: > > CPU: 1 PID: 5962 Comm: syz-executor118 Not tainted 4.20.0-rc6+ #374 > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 > RIP: 0010:kvm_apic_hw_enabled arch/x86/kvm/lapic.h:169 [inline] > RIP: 0010:vcpu_scan_ioapic arch/x86/kvm/x86.c:7449 [inline] > RIP: 0010:vcpu_enter_guest arch/x86/kvm/x86.c:7602 [inline] > RIP: 0010:vcpu_run arch/x86/kvm/x86.c:7874 [inline] > RIP: 0010:kvm_arch_vcpu_ioctl_run+0x5296/0x7320 arch/x86/kvm/x86.c:8074 > Call Trace: > kvm_vcpu_ioctl+0x5c8/0x1150 arch/x86/kvm/../../../virt/kvm/kvm_main.c:2596 > vfs_ioctl fs/ioctl.c:46 [inline] > file_ioctl fs/ioctl.c:509 [inline] > do_vfs_ioctl+0x1de/0x1790 fs/ioctl.c:696 > ksys_ioctl+0xa9/0xd0 fs/ioctl.c:713 > __do_sys_ioctl fs/ioctl.c:720 [inline] > __se_sys_ioctl fs/ioctl.c:718 [inline] > __x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:718 > do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290 > entry_SYSCALL_64_after_hwframe+0x49/0xbe > > The reason is that the testcase writes hyperv synic HV_X64_MSR_SINT14 msr > and triggers scan ioapic logic to load synic vectors into EOI exit bitmap. > However, irqchip is not initialized by this simple testcase, ioapic/apic > objects should not be accessed. > > This patch fixes it by also considering whether or not apic is present. > > Reported-by: syzbot+39810e6c400efadfef71@syzkaller.appspotmail.com > Cc: Paolo Bonzini > Cc: Radim Krčmář > Signed-off-by: Wanpeng Li > --- > arch/x86/kvm/x86.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c > index 4f786fc..c7c1197 100644 > --- a/arch/x86/kvm/x86.c > +++ b/arch/x86/kvm/x86.c > @@ -7510,7 +7510,7 @@ void kvm_make_scan_ioapic_request(struct kvm *kvm) > > static void vcpu_scan_ioapic(struct kvm_vcpu *vcpu) > { > - if (!kvm_apic_hw_enabled(vcpu->arch.apic)) > + if (!kvm_apic_present(vcpu)) > return; > > bitmap_zero(vcpu->arch.ioapic_handled_vectors, 256); > Queued, thanks. Paolo