From 65ba631bcb62c79eb33ebfde8a0471fd012c37a8 Mon Sep 17 00:00:00 2001 From: Daniel De Graaf Date: Fri, 4 Oct 2013 12:51:44 +0200 Subject: xsm: forbid PV guest console reads The CONSOLEIO_read operation was incorrectly allowed to PV guests if the hypervisor was compiled in debug mode (with VERBOSE defined). Reported-by: Jan Beulich Signed-off-by: Daniel De Graaf --- xen/include/xsm/dummy.h | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) (limited to 'xen') diff --git a/xen/include/xsm/dummy.h b/xen/include/xsm/dummy.h index 052f3e0111..52c651c402 100644 --- a/xen/include/xsm/dummy.h +++ b/xen/include/xsm/dummy.h @@ -222,10 +222,10 @@ static XSM_INLINE int xsm_console_io(XSM_DEFAULT_ARG struct domain *d, int cmd) { XSM_ASSERT_ACTION(XSM_OTHER); #ifdef VERBOSE - return xsm_default_action(XSM_HOOK, current->domain, NULL); -#else - return xsm_default_action(XSM_PRIV, current->domain, NULL); + if ( cmd == CONSOLEIO_write ) + return xsm_default_action(XSM_HOOK, d, NULL); #endif + return xsm_default_action(XSM_PRIV, d, NULL); } static XSM_INLINE int xsm_profile(XSM_DEFAULT_ARG struct domain *d, int op) -- cgit v1.2.3