From a3d1dbc607dbf6c1ec77e91dd44afdbed7ff6cc4 Mon Sep 17 00:00:00 2001 From: Stefano Stabellini Date: Tue, 9 Oct 2012 15:05:34 +0100 Subject: [PATCH] xen/arm: create_p2m_entries should not call free_domheap_page The guest is entitled to leak a page from its p2m (by overwriting it) if it wants to. Since the memory is effectively lost to it (can't even be recovered by XENMEM increase reservation etc). In these cases we shouldn't call free_domheap_page to free the existing page from create_p2m_entries, because it resets the reference counting but the page is still allocated to the guest (even if not in the p2m anymore) and common grant_table code is also going to call put_page on it. Signed-off-by: Stefano Stabellini Acked-by: Ian Campbell Committed-by: Ian Campbell --- xen/arch/arm/p2m.c | 5 ----- 1 file changed, 5 deletions(-) diff --git a/xen/arch/arm/p2m.c b/xen/arch/arm/p2m.c index 7c23b7d183..7ae451596e 100644 --- a/xen/arch/arm/p2m.c +++ b/xen/arch/arm/p2m.c @@ -189,12 +189,7 @@ static int create_p2m_entries(struct domain *d, /* else: third already valid */ if ( third[third_table_offset(addr)].p2m.valid ) - { - /* p2m entry already present */ - free_domheap_page( - mfn_to_page(third[third_table_offset(addr)].p2m.base)); flush_tlb_all_local(); - } /* Allocate a new RAM page and attach */ switch (op) { -- 2.30.2