From a6542288d3a3803dfe683c62e7692b7dcd679402 Mon Sep 17 00:00:00 2001 From: Andrew Cooper Date: Wed, 18 Jan 2017 09:51:53 +0100 Subject: [PATCH] x86/emul: Correct the return value handling of VMFUNC The bracketing of x86_emulate() calling the ops->vmfunc() hook is wrong with respect to the assignment to rc, which can trip the new assertions in x86_emulate_wrapper(). The hvmemul_vmfunc() hook should only raise #UD if X86EMUL_EXCEPTION is returned. This is only a latent bug at the moment. Signed-off-by: Andrew Cooper Reviewed-by: Jan Beulich master commit: 3ab1876504d409689824e161a8b04e57e1e5dd46 master date: 2016-12-22 13:32:46 +0000 --- xen/arch/x86/hvm/emulate.c | 2 +- xen/arch/x86/x86_emulate/x86_emulate.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/xen/arch/x86/hvm/emulate.c b/xen/arch/x86/hvm/emulate.c index f32b7dc210..40fa4f0345 100644 --- a/xen/arch/x86/hvm/emulate.c +++ b/xen/arch/x86/hvm/emulate.c @@ -1697,7 +1697,7 @@ static int hvmemul_vmfunc( if ( !hvm_funcs.altp2m_vcpu_emulate_vmfunc ) return X86EMUL_UNHANDLEABLE; rc = hvm_funcs.altp2m_vcpu_emulate_vmfunc(ctxt->regs); - if ( rc != X86EMUL_OKAY ) + if ( rc == X86EMUL_EXCEPTION ) hvmemul_inject_hw_exception(TRAP_invalid_op, HVM_DELIVER_NO_ERROR_CODE, ctxt); diff --git a/xen/arch/x86/x86_emulate/x86_emulate.c b/xen/arch/x86/x86_emulate/x86_emulate.c index 6bb3c74621..b06c456286 100644 --- a/xen/arch/x86/x86_emulate/x86_emulate.c +++ b/xen/arch/x86/x86_emulate/x86_emulate.c @@ -4356,7 +4356,7 @@ x86_emulate( generate_exception_if(lock_prefix | rep_prefix() | (vex.pfx == vex_66), EXC_UD, -1); fail_if(!ops->vmfunc); - if ( (rc = ops->vmfunc(ctxt) != X86EMUL_OKAY) ) + if ( (rc = ops->vmfunc(ctxt)) != X86EMUL_OKAY ) goto done; goto no_writeback; -- 2.30.2