From: Jan Beulich Date: Tue, 12 Dec 2017 14:13:30 +0000 (+0100) Subject: x86/paging: don't unconditionally BUG() on finding SHARED_M2P_ENTRY X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=refs%2Fheads%2Fstable-4.5;p=xen.git x86/paging: don't unconditionally BUG() on finding SHARED_M2P_ENTRY PV guests can fully control the values written into the P2M. This is XSA-251. Signed-off-by: Jan Beulich Reviewed-by: Andrew Cooper master commit: b4d0218cff66b7eaa9c9b8dc9bd71e7b089b016d master date: 2017-12-12 14:30:17 +0100 --- diff --git a/xen/arch/x86/mm/paging.c b/xen/arch/x86/mm/paging.c index 8d7f5cbc31..149a59aa8d 100644 --- a/xen/arch/x86/mm/paging.c +++ b/xen/arch/x86/mm/paging.c @@ -285,7 +285,7 @@ void paging_mark_dirty(struct domain *d, unsigned long guest_mfn) /* We /really/ mean PFN here, even for non-translated guests. */ pfn = get_gpfn_from_mfn(mfn_x(gmfn)); /* Shared MFNs should NEVER be marked dirty */ - BUG_ON(SHARED_M2P(pfn)); + BUG_ON(paging_mode_translate(d) && SHARED_M2P(pfn)); /* * Values with the MSB set denote MFNs that aren't really part of the