From: Jan Beulich Subject: platform-op/XSM: move resource-{,un}plug-core checks Integrate the checking with flask_platform_op(); there never really was a need to defer these checks, as the sub-op has always been known to the function. As a positive side effect, permissions are then checked at the same early point with and without Flask. This is CVE-2026-62427 / part of XSA-499. Signed-off-by: Jan Beulich Reviewed-by: Roger Pau Monné Reviewed-by: Andrew Cooper Acked-By: Daniel P. Smith --- a/xen/arch/x86/platform_hypercall.c +++ b/xen/arch/x86/platform_hypercall.c @@ -735,10 +735,6 @@ ret_t do_platform_op( { int cpu = op->u.cpu_ol.cpuid; - ret = xsm_resource_plug_core(XSM_HOOK); - if ( ret ) - break; - if ( cpu >= nr_cpu_ids || !cpu_present(cpu) || clocksource_is_tsc() ) { @@ -761,10 +757,6 @@ ret_t do_platform_op( { int cpu = op->u.cpu_ol.cpuid; - ret = xsm_resource_unplug_core(XSM_HOOK); - if ( ret ) - break; - if ( cpu == 0 ) { ret = -EOPNOTSUPP; @@ -789,20 +781,12 @@ ret_t do_platform_op( } case XENPF_cpu_hotadd: - ret = xsm_resource_plug_core(XSM_HOOK); - if ( ret ) - break; - ret = cpu_add(op->u.cpu_add.apic_id, op->u.cpu_add.acpi_id, op->u.cpu_add.pxm); break; case XENPF_mem_hotadd: - ret = xsm_resource_plug_core(XSM_HOOK); - if ( ret ) - break; - ret = memory_add(op->u.mem_add.spfn, op->u.mem_add.epfn, op->u.mem_add.pxm); --- a/xen/xsm/flask/hooks.c +++ b/xen/xsm/flask/hooks.c @@ -1207,6 +1207,7 @@ static int cf_check flask_pci_config_per } +#if defined(CONFIG_SYSCTL) || defined(CONFIG_X86) static int cf_check flask_resource_plug_core(void) { return avc_current_has_perm(SECINITSID_DOMXEN, SECCLASS_RESOURCE, RESOURCE__PLUG, NULL); @@ -1216,6 +1217,7 @@ static int cf_check flask_resource_unplu { return avc_current_has_perm(SECINITSID_DOMXEN, SECCLASS_RESOURCE, RESOURCE__UNPLUG, NULL); } +#endif /* CONFIG_SYSCTL || CONFIG_X86 */ #ifdef CONFIG_SYSCTL static int flask_resource_use_core(void) @@ -1536,12 +1538,13 @@ static int cf_check flask_platform_op(ui switch ( op ) { #ifdef CONFIG_X86 - /* These operations have their own XSM hooks */ case XENPF_cpu_online: - case XENPF_cpu_offline: case XENPF_cpu_hotadd: case XENPF_mem_hotadd: - return 0; + return flask_resource_plug_core(); + + case XENPF_cpu_offline: + return flask_resource_unplug_core(); #endif case XENPF_settime32: