Re: [PATCH v7 1/6] x86/tdx: Fix "in-kernel MMIO" check

From: Dave Hansen
Date: Fri Sep 13 2024 - 13:18:48 EST


On 9/13/24 10:05, Alexey Gladkov wrote:
> TDX only supports kernel-initiated MMIO operations. The handle_mmio()
> function checks if the #VE exception occurred in the kernel and rejects
> the operation if it did not.
>
> However, userspace can deceive the kernel into performing MMIO on its
> behalf. For example, if userspace can point a syscall to an MMIO address,
> syscall does get_user() or put_user() on it, triggering MMIO #VE. The
> kernel will treat the #VE as in-kernel MMIO.
>
> Ensure that the target MMIO address is within the kernel before decoding
> instruction.

Acked-by: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>