All of
 help / color / mirror / Atom feed
From: Paolo Bonzini <>
To: Emanuele Giuseppe Esposito <>,
Cc: Maxim Levitsky <>,
	Sean Christopherson <>,
	Vitaly Kuznetsov <>,
	Wanpeng Li <>,
	Jim Mattson <>, Joerg Roedel <>,
	Thomas Gleixner <>,
	Ingo Molnar <>, Borislav Petkov <>,, "H. Peter Anvin" <>,
Subject: Re: [PATCH v2 0/4] KVM: nSVM: avoid TOC/TOU race when checking vmcb12
Date: Tue, 28 Sep 2021 18:52:47 +0200	[thread overview]
Message-ID: <> (raw)
In-Reply-To: <>

On 17/09/21 14:03, Emanuele Giuseppe Esposito wrote:
> Currently there is a TOC/TOU race between the check of vmcb12's
> efer, cr0 and cr4 registers and the later save of their values in
> svm_set_*, because the guest could modify the values in the meanwhile.
> To solve this issue, this serie introuces and uses svm->
> structure in enter_svm_guest_mode to save the current value of efer,
> cr0 and cr4 and later use these to set the vcpu->arch.* state.
> Patch 1 just refactor the code to simplify the next two patches,
> patch 2 introduces svm-> to cache the efer, cr0 and cr4 fields
> and in patch 3 and 4 we use it to avoid TOC/TOU races.
> Signed-off-by: Emanuele Giuseppe Esposito <>

Most of my remarks from the RFC still apply, so I will wait for v3. 
Thanks, and sorry for the time between send and review.


      parent reply	other threads:[~2021-09-28 16:52 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-09-17 12:03 [PATCH v2 0/4] KVM: nSVM: avoid TOC/TOU race when checking vmcb12 Emanuele Giuseppe Esposito
2021-09-17 12:03 ` [PATCH v2 1/4] KVM: nSVM: move nested_vmcb_check_cr3_cr4 logic in nested_vmcb_valid_sregs Emanuele Giuseppe Esposito
2021-09-17 12:03 ` [PATCH v2 2/4] nSVM: introduce smv-> to cache save area fields Emanuele Giuseppe Esposito
2021-09-28 16:51   ` Paolo Bonzini
2021-09-17 12:03 ` [PATCH v2 3/4] nSVM: use vmcb_save_area_cached in nested_vmcb_valid_sregs() Emanuele Giuseppe Esposito
2021-09-17 12:03 ` [PATCH v2 4/4] nSVM: use svm-> to load vmcb12 registers and avoid TOC/TOU races Emanuele Giuseppe Esposito
2021-09-28 16:52 ` Paolo Bonzini [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.