aboutsummaryrefslogtreecommitdiffstats
path: root/drivers/lguest/lguest_user.c
diff options
context:
space:
mode:
Diffstat (limited to 'drivers/lguest/lguest_user.c')
-rw-r--r--drivers/lguest/lguest_user.c12
1 files changed, 10 insertions, 2 deletions
diff --git a/drivers/lguest/lguest_user.c b/drivers/lguest/lguest_user.c
index c4bfe5a2b6b7..9f0a44329947 100644
--- a/drivers/lguest/lguest_user.c
+++ b/drivers/lguest/lguest_user.c
@@ -55,11 +55,19 @@ static int user_send_irq(struct lguest *lg, const unsigned long __user *input)
55static ssize_t read(struct file *file, char __user *user, size_t size,loff_t*o) 55static ssize_t read(struct file *file, char __user *user, size_t size,loff_t*o)
56{ 56{
57 struct lguest *lg = file->private_data; 57 struct lguest *lg = file->private_data;
58 struct lg_cpu *cpu;
59 unsigned int cpu_id = *o;
58 60
59 /* You must write LHREQ_INITIALIZE first! */ 61 /* You must write LHREQ_INITIALIZE first! */
60 if (!lg) 62 if (!lg)
61 return -EINVAL; 63 return -EINVAL;
62 64
65 /* Watch out for arbitrary vcpu indexes! */
66 if (cpu_id >= lg->nr_cpus)
67 return -EINVAL;
68
69 cpu = &lg->cpus[cpu_id];
70
63 /* If you're not the task which owns the Guest, go away. */ 71 /* If you're not the task which owns the Guest, go away. */
64 if (current != lg->tsk) 72 if (current != lg->tsk)
65 return -EPERM; 73 return -EPERM;
@@ -85,7 +93,7 @@ static ssize_t read(struct file *file, char __user *user, size_t size,loff_t*o)
85 lg->pending_notify = 0; 93 lg->pending_notify = 0;
86 94
87 /* Run the Guest until something interesting happens. */ 95 /* Run the Guest until something interesting happens. */
88 return run_guest(lg, (unsigned long __user *)user); 96 return run_guest(cpu, (unsigned long __user *)user);
89} 97}
90 98
91static int lg_cpu_start(struct lg_cpu *cpu, unsigned id, unsigned long start_ip) 99static int lg_cpu_start(struct lg_cpu *cpu, unsigned id, unsigned long start_ip)
@@ -147,7 +155,7 @@ static int initialize(struct file *file, const unsigned long __user *input)
147 lg->pfn_limit = args[1]; 155 lg->pfn_limit = args[1];
148 156
149 /* This is the first cpu */ 157 /* This is the first cpu */
150 err = cpu_start(&lg->cpus[0], 0, args[3]); 158 err = lg_cpu_start(&lg->cpus[0], 0, args[3]);
151 if (err) 159 if (err)
152 goto release_guest; 160 goto release_guest;
153 161