| From a491e7582d463d1e5a830d912dc519cc43d83522 Mon Sep 17 00:00:00 2001 |
| From: Juergen Gross <jgross@suse.com> |
| Date: Thu, 17 Oct 2024 15:27:31 +0200 |
| Subject: x86/xen: remove hypercall page |
| |
| From: Juergen Gross <jgross@suse.com> |
| |
| commit 7fa0da5373685e7ed249af3fa317ab1e1ba8b0a6 upstream. |
| |
| The hypercall page is no longer needed. It can be removed, as from the |
| Xen perspective it is optional. |
| |
| But, from Linux's perspective, it removes naked RET instructions that |
| escape the speculative protections that Call Depth Tracking and/or |
| Untrain Ret are trying to achieve. |
| |
| This is part of XSA-466 / CVE-2024-53241. |
| |
| Reported-by: Andrew Cooper <andrew.cooper3@citrix.com> |
| Signed-off-by: Juergen Gross <jgross@suse.com> |
| Reviewed-by: Andrew Cooper <andrew.cooper3@citrix.com> |
| Reviewed-by: Jan Beulich <jbeulich@suse.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| arch/x86/include/asm/xen/hypercall.h | 2 -- |
| arch/x86/kernel/callthunks.c | 5 ----- |
| arch/x86/xen/enlighten.c | 2 -- |
| arch/x86/xen/enlighten_hvm.c | 9 +-------- |
| arch/x86/xen/enlighten_pvh.c | 7 ------- |
| arch/x86/xen/xen-head.S | 23 ----------------------- |
| 6 files changed, 1 insertion(+), 47 deletions(-) |
| |
| --- a/arch/x86/include/asm/xen/hypercall.h |
| +++ b/arch/x86/include/asm/xen/hypercall.h |
| @@ -88,8 +88,6 @@ struct xen_dm_op_buf; |
| * there aren't more than 5 arguments...) |
| */ |
| |
| -extern struct { char _entry[32]; } hypercall_page[]; |
| - |
| void xen_hypercall_func(void); |
| DECLARE_STATIC_CALL(xen_hypercall, xen_hypercall_func); |
| |
| --- a/arch/x86/kernel/callthunks.c |
| +++ b/arch/x86/kernel/callthunks.c |
| @@ -146,11 +146,6 @@ static bool skip_addr(void *dest) |
| dest < (void*)relocate_kernel + KEXEC_CONTROL_CODE_MAX_SIZE) |
| return true; |
| #endif |
| -#ifdef CONFIG_XEN |
| - if (dest >= (void *)hypercall_page && |
| - dest < (void*)hypercall_page + PAGE_SIZE) |
| - return true; |
| -#endif |
| return false; |
| } |
| |
| --- a/arch/x86/xen/enlighten.c |
| +++ b/arch/x86/xen/enlighten.c |
| @@ -27,8 +27,6 @@ |
| #include "smp.h" |
| #include "pmu.h" |
| |
| -EXPORT_SYMBOL_GPL(hypercall_page); |
| - |
| DEFINE_STATIC_CALL(xen_hypercall, xen_hypercall_hvm); |
| EXPORT_STATIC_CALL_TRAMP(xen_hypercall); |
| |
| --- a/arch/x86/xen/enlighten_hvm.c |
| +++ b/arch/x86/xen/enlighten_hvm.c |
| @@ -108,15 +108,8 @@ static void __init init_hvm_pv_info(void |
| /* PVH set up hypercall page in xen_prepare_pvh(). */ |
| if (xen_pvh_domain()) |
| pv_info.name = "Xen PVH"; |
| - else { |
| - u64 pfn; |
| - uint32_t msr; |
| - |
| + else |
| pv_info.name = "Xen HVM"; |
| - msr = cpuid_ebx(base + 2); |
| - pfn = __pa(hypercall_page); |
| - wrmsr_safe(msr, (u32)pfn, (u32)(pfn >> 32)); |
| - } |
| |
| xen_setup_features(); |
| |
| --- a/arch/x86/xen/enlighten_pvh.c |
| +++ b/arch/x86/xen/enlighten_pvh.c |
| @@ -28,17 +28,10 @@ EXPORT_SYMBOL_GPL(xen_pvh); |
| |
| void __init xen_pvh_init(struct boot_params *boot_params) |
| { |
| - u32 msr; |
| - u64 pfn; |
| - |
| xen_pvh = 1; |
| xen_domain_type = XEN_HVM_DOMAIN; |
| xen_start_flags = pvh_start_info.flags; |
| |
| - msr = cpuid_ebx(xen_cpuid_base() + 2); |
| - pfn = __pa(hypercall_page); |
| - wrmsr_safe(msr, (u32)pfn, (u32)(pfn >> 32)); |
| - |
| if (xen_initial_domain()) |
| x86_init.oem.arch_setup = xen_add_preferred_consoles; |
| x86_init.oem.banner = xen_banner; |
| --- a/arch/x86/xen/xen-head.S |
| +++ b/arch/x86/xen/xen-head.S |
| @@ -22,28 +22,6 @@ |
| #include <xen/interface/xen-mca.h> |
| #include <asm/xen/interface.h> |
| |
| -.pushsection .noinstr.text, "ax" |
| - .balign PAGE_SIZE |
| -SYM_CODE_START(hypercall_page) |
| - .rept (PAGE_SIZE / 32) |
| - UNWIND_HINT_FUNC |
| - ANNOTATE_NOENDBR |
| - ANNOTATE_UNRET_SAFE |
| - ret |
| - /* |
| - * Xen will write the hypercall page, and sort out ENDBR. |
| - */ |
| - .skip 31, 0xcc |
| - .endr |
| - |
| -#define HYPERCALL(n) \ |
| - .equ xen_hypercall_##n, hypercall_page + __HYPERVISOR_##n * 32; \ |
| - .type xen_hypercall_##n, @function; .size xen_hypercall_##n, 32 |
| -#include <asm/xen-hypercalls.h> |
| -#undef HYPERCALL |
| -SYM_CODE_END(hypercall_page) |
| -.popsection |
| - |
| #ifdef CONFIG_XEN_PV |
| __INIT |
| SYM_CODE_START(startup_xen) |
| @@ -198,7 +176,6 @@ SYM_FUNC_END(xen_hypercall_intel) |
| #else |
| # define FEATURES_DOM0 0 |
| #endif |
| - ELFNOTE(Xen, XEN_ELFNOTE_HYPERCALL_PAGE, _ASM_PTR hypercall_page) |
| ELFNOTE(Xen, XEN_ELFNOTE_SUPPORTED_FEATURES, |
| .long FEATURES_PV | FEATURES_PVH | FEATURES_DOM0) |
| ELFNOTE(Xen, XEN_ELFNOTE_LOADER, .asciz "generic") |