提交 9cf98828 编写于 作者: E Eddie Dong 提交者: Avi Kivity

KVM: Protect in-kernel pio using kvm->lock

pio operation and IRQ_LINE kvm_vm_ioctl is not kvm->lock
protected.  Add lock to same with IOAPIC MMIO operations.
Signed-off-by: NYaozu (Eddie) Dong <eddie.dong@intel.com>
Signed-off-by: NAvi Kivity <avi@qumranet.com>
上级 b6958ce4
...@@ -1790,6 +1790,7 @@ static void kernel_pio(struct kvm_io_device *pio_dev, ...@@ -1790,6 +1790,7 @@ static void kernel_pio(struct kvm_io_device *pio_dev,
{ {
/* TODO: String I/O for in kernel device */ /* TODO: String I/O for in kernel device */
mutex_lock(&vcpu->kvm->lock);
if (vcpu->pio.in) if (vcpu->pio.in)
kvm_iodevice_read(pio_dev, vcpu->pio.port, kvm_iodevice_read(pio_dev, vcpu->pio.port,
vcpu->pio.size, vcpu->pio.size,
...@@ -1798,6 +1799,7 @@ static void kernel_pio(struct kvm_io_device *pio_dev, ...@@ -1798,6 +1799,7 @@ static void kernel_pio(struct kvm_io_device *pio_dev,
kvm_iodevice_write(pio_dev, vcpu->pio.port, kvm_iodevice_write(pio_dev, vcpu->pio.port,
vcpu->pio.size, vcpu->pio.size,
pd); pd);
mutex_unlock(&vcpu->kvm->lock);
} }
static void pio_string_write(struct kvm_io_device *pio_dev, static void pio_string_write(struct kvm_io_device *pio_dev,
...@@ -1807,12 +1809,14 @@ static void pio_string_write(struct kvm_io_device *pio_dev, ...@@ -1807,12 +1809,14 @@ static void pio_string_write(struct kvm_io_device *pio_dev,
void *pd = vcpu->pio_data; void *pd = vcpu->pio_data;
int i; int i;
mutex_lock(&vcpu->kvm->lock);
for (i = 0; i < io->cur_count; i++) { for (i = 0; i < io->cur_count; i++) {
kvm_iodevice_write(pio_dev, io->port, kvm_iodevice_write(pio_dev, io->port,
io->size, io->size,
pd); pd);
pd += io->size; pd += io->size;
} }
mutex_unlock(&vcpu->kvm->lock);
} }
int kvm_emulate_pio (struct kvm_vcpu *vcpu, struct kvm_run *run, int in, int kvm_emulate_pio (struct kvm_vcpu *vcpu, struct kvm_run *run, int in,
...@@ -2818,6 +2822,7 @@ static long kvm_vm_ioctl(struct file *filp, ...@@ -2818,6 +2822,7 @@ static long kvm_vm_ioctl(struct file *filp,
if (copy_from_user(&irq_event, argp, sizeof irq_event)) if (copy_from_user(&irq_event, argp, sizeof irq_event))
goto out; goto out;
if (irqchip_in_kernel(kvm)) { if (irqchip_in_kernel(kvm)) {
mutex_lock(&kvm->lock);
if (irq_event.irq < 16) if (irq_event.irq < 16)
kvm_pic_set_irq(pic_irqchip(kvm), kvm_pic_set_irq(pic_irqchip(kvm),
irq_event.irq, irq_event.irq,
...@@ -2825,6 +2830,7 @@ static long kvm_vm_ioctl(struct file *filp, ...@@ -2825,6 +2830,7 @@ static long kvm_vm_ioctl(struct file *filp,
kvm_ioapic_set_irq(kvm->vioapic, kvm_ioapic_set_irq(kvm->vioapic,
irq_event.irq, irq_event.irq,
irq_event.level); irq_event.level);
mutex_unlock(&kvm->lock);
r = 0; r = 0;
} }
break; break;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册