# HG changeset patch
# User Christian Limpach <Christian.Limpach@xxxxxxxxxxxxx>
# Date 1172770051 0
# Node ID 5dac445200e31d26b2616f3feb7c499dff8ed6d7
# Parent 10eb93864df57806aacd650d74635b136567b92c
[XEN] Check that the cr3 mfn is valid before using it.
Signed-off-by: Christian Limpach <Christian.Limpach@xxxxxxxxxxxxx>
---
xen/arch/x86/domain.c | 18 ++++++++++--------
1 files changed, 10 insertions(+), 8 deletions(-)
diff -r 10eb93864df5 -r 5dac445200e3 xen/arch/x86/domain.c
--- a/xen/arch/x86/domain.c Thu Mar 01 15:56:45 2007 +0000
+++ b/xen/arch/x86/domain.c Thu Mar 01 17:27:31 2007 +0000
@@ -630,10 +630,11 @@ int arch_set_info_guest(
{
cr3_pfn = gmfn_to_mfn(d, xen_cr3_to_pfn(c.nat->ctrlreg[3]));
- if ( paging_mode_refcounts(d)
- ? !get_page(mfn_to_page(cr3_pfn), d)
- : !get_page_and_type(mfn_to_page(cr3_pfn), d,
- PGT_base_page_table) )
+ if ( !mfn_valid(cr3_pfn) ||
+ (paging_mode_refcounts(d)
+ ? !get_page(mfn_to_page(cr3_pfn), d)
+ : !get_page_and_type(mfn_to_page(cr3_pfn), d,
+ PGT_base_page_table)) )
{
destroy_gdt(v);
return -EINVAL;
@@ -648,10 +649,11 @@ int arch_set_info_guest(
cr3_pfn = gmfn_to_mfn(d, compat_cr3_to_pfn(c.cmp->ctrlreg[3]));
- if ( paging_mode_refcounts(d)
- ? !get_page(mfn_to_page(cr3_pfn), d)
- : !get_page_and_type(mfn_to_page(cr3_pfn), d,
- PGT_l3_page_table) )
+ if ( !mfn_valid(cr3_pfn) ||
+ (paging_mode_refcounts(d)
+ ? !get_page(mfn_to_page(cr3_pfn), d)
+ : !get_page_and_type(mfn_to_page(cr3_pfn), d,
+ PGT_l3_page_table)) )
{
destroy_gdt(v);
return -EINVAL;
_______________________________________________
Xen-changelog mailing list
Xen-changelog@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-changelog
|