x86/sev: Check IOBM for IOIO exceptions from user-space
authorJoerg Roedel <jroedel@suse.de>
Wed, 21 Jun 2023 15:42:42 +0000 (17:42 +0200)
committerBorislav Petkov (AMD) <bp@alien8.de>
Mon, 9 Oct 2023 13:47:57 +0000 (15:47 +0200)
commitb9cb9c45583b911e0db71d09caa6b56469eb2bdf
treeb8046c802a8613737f7603624dbfb6d7dbe48db4
parenta37cd2a59d0cb270b1bba568fd3a3b8668b9d3ba
x86/sev: Check IOBM for IOIO exceptions from user-space

Check the IO permission bitmap (if present) before emulating IOIO #VC
exceptions for user-space. These permissions are checked by hardware
already before the #VC is raised, but due to the VC-handler decoding
race it needs to be checked again in software.

Fixes: 25189d08e516 ("x86/sev-es: Add support for handling IOIO exceptions")
Reported-by: Tom Dohrmann <erbse.13@gmx.de>
Signed-off-by: Joerg Roedel <jroedel@suse.de>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Tested-by: Tom Dohrmann <erbse.13@gmx.de>
Cc: <stable@kernel.org>
arch/x86/boot/compressed/sev.c
arch/x86/kernel/sev-shared.c
arch/x86/kernel/sev.c