Page MenuHomeFreeBSD

vmm: Fix a page wiring leak in MOVS emulation
ClosedPublic

Authored by hayzam_gmail.com on Fri, Sep 18, 7:46 PM.
Tags
None
Referenced Files
F174090182: D59823.id187142.diff
Wed, Sep 30, 1:32 PM
F174089541: D59823.id187344.diff
Wed, Sep 30, 1:24 PM
Unknown Object (File)
Tue, Sep 29, 11:59 AM
Unknown Object (File)
Tue, Sep 29, 8:58 AM
Unknown Object (File)
Mon, Sep 28, 3:10 PM
Unknown Object (File)
Mon, Sep 28, 7:16 AM
Unknown Object (File)
Mon, Sep 28, 1:36 AM
Unknown Object (File)
Sun, Sep 27, 10:40 PM
Subscribers

Details

Summary

When emulating a MOVS from MMIO to guest RAM, the kernel's
vm_copy_setup() wires the destination pages. If the subsequent
MMIO read fails, emulate_movs() skips vm_copy_teardown(), leaking
the page wire references acquired during setup.

Run vm_copy_teardown() regardless of the MMIO read result, and
only copy the value to guest memory if the read succeeds.
Preserve the existing error return.

This matches illumos change 13309.

Obtained from: illumos 83cd75bb2949d26e6eb38ddefc60fdeed1909643
Sponsored by: The FreeBSD Foundation

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77068
Build 73951: arc lint + arc unit