From: Jan Beulich Date: Thu, 23 May 2013 13:16:06 +0000 (+0200) Subject: x86/shadow: fix off-by-one in MMIO permission check X-Git-Tag: 4.1.6-rc1~51 X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=a7dcae35f14db7d36bca7a5fbecfea468da152e4;p=xen.git x86/shadow: fix off-by-one in MMIO permission check iomem_access_permitted() wants an inclusive range as input. Also use pfn_to_paddr() in nearby code instead of open coding it. Signed-off-by: Jan Beulich Acked-by: Tim Deegan master commit: afa65ddfd88184a894d9364bec587554c28c20e0 master date: 2013-05-15 14:34:05 +0200 --- diff --git a/xen/arch/x86/mm/shadow/multi.c b/xen/arch/x86/mm/shadow/multi.c index 91879cfc9e..944a8ec6e7 100644 --- a/xen/arch/x86/mm/shadow/multi.c +++ b/xen/arch/x86/mm/shadow/multi.c @@ -602,13 +602,13 @@ _sh_propagate(struct vcpu *v, else if ( d->arch.hvm_domain.is_in_uc_mode ) sflags |= pat_type_2_pte_flags(PAT_TYPE_UNCACHABLE); else - if ( iomem_access_permitted(d, mfn_x(target_mfn), mfn_x(target_mfn) + 1) ) + if ( iomem_access_permitted(d, mfn_x(target_mfn), mfn_x(target_mfn)) ) { if ( p2mt == p2m_mmio_direct ) sflags |= get_pat_flags(v, gflags, gfn_to_paddr(target_gfn), - ((paddr_t)mfn_x(target_mfn)) << PAGE_SHIFT, + pfn_to_paddr(mfn_x(target_mfn)), MTRR_TYPE_UNCACHABLE); else if ( iommu_snoop ) sflags |= pat_type_2_pte_flags(PAT_TYPE_WRBACK); @@ -616,7 +616,7 @@ _sh_propagate(struct vcpu *v, sflags |= get_pat_flags(v, gflags, gfn_to_paddr(target_gfn), - ((paddr_t)mfn_x(target_mfn)) << PAGE_SHIFT, + pfn_to_paddr(mfn_x(target_mfn)), NO_HARDCODE_MEM_TYPE); } }