Bug 510087 - KVM: limit lapic periodic timer frequency
KVM: limit lapic periodic timer frequency
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: kvm (Show other bugs)
5.4
All Linux
low Severity medium
: rc
: ---
Assigned To: Marcelo Tosatti
Lawrence Lim
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-07-07 12:34 EDT by Marcelo Tosatti
Modified: 2014-03-25 20:58 EDT (History)
8 users (show)

See Also:
Fixed In Version: kvm-83-87.el5
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-09-02 05:36:10 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
KVM-lapic-limit-periodic-timer.patch (885 bytes, patch)
2009-07-07 12:34 EDT, Marcelo Tosatti
no flags Details | Diff
kvm-lapic-timer-test.tar.bz2 (56.16 KB, application/x-bzip2)
2009-07-07 12:35 EDT, Marcelo Tosatti
no flags Details

  None (edit)
Description Marcelo Tosatti 2009-07-07 12:34:52 EDT
Created attachment 350832 [details]
KVM-lapic-limit-periodic-timer.patch

Description of problem:

Its possible to DoS the host by programming lapic timer
with a very high frequency.


Steps to Reproduce:
1. download kvm-lapic-timer-test.tar.bz2 (attached to this BZ) 
2. run ./kvmctl bootstrap time.flat
3. host hangs
Comment 1 Marcelo Tosatti 2009-07-07 12:35:50 EDT
Created attachment 350833 [details]
kvm-lapic-timer-test.tar.bz2
Comment 8 lihuang 2009-07-11 10:14:45 EDT
lihuang ->   mtosatti

I have ran the reproducer in kvm-83-87.el5.can not reproduce the original issue.

 ./kvmctl bootstrap time.flat
GUEST: paging enabled
GUEST: apic version: 50014
GUEST: apic existence: PASS
GUEST: self ipi: PASS

waited more than 5 mins. the command is not return.it is OK ?


top - 14:10:56 up  9:46,  3 users,  load average: 0.02, 0.34, 0.56
Tasks:   1 total,   0 running,   1 sleeping,   0 stopped,   0 zombie
Cpu(s):  0.0%us,  0.1%sy,  0.0%ni, 99.9%id,  0.0%wa,  0.0%hi,  0.0%si,  0.0%st
Mem:   7912832k total,  1982024k used,  5930808k free,    18612k buffers
Swap:  8151032k total,       48k used,  8150984k free,  1816184k cached

  PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND            
 6172 root      18   0  145m 128m 128m S  0.0  1.7   0:00.18 kvmctl
Comment 9 Marcelo Tosatti 2009-07-13 09:55:12 EDT
lihuang, 

Yes, this is OK. Without the fix (before kvm-83-87.el5) the host would crash.
Comment 10 lihuang 2009-07-13 10:02:26 EDT
ok. Thank you (In reply to comment #9)
> lihuang, 
> 
> Yes, this is OK. Without the fix (before kvm-83-87.el5) the host would crash.  

OK .thank you 

setting to *VERIFIED*
Comment 12 errata-xmlrpc 2009-09-02 05:36:10 EDT
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHEA-2009-1272.html

Note You need to log in before you can comment on or make changes to this bug.