From: Jan Beulich <jbeulich@suse.com>
Subject: platform-op/XSM: move resource-{,un}plug-core checks

Integrate the checking with flask_platform_op(); there never really was a
need to defer these checks, as the sub-op has always been known to the
function. As a positive side effect, permissions are then checked at the
same early point with and without Flask.

This is CVE-2026-62427 / part of XSA-499.

Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: Roger Pau Monné <roger.pau@citrix.com>
Reviewed-by: Andrew Cooper <andrew.cooper3@citrix.com>
Acked-By: Daniel P. Smith <dpsmith@apertussolutions.com>

--- a/xen/arch/x86/platform_hypercall.c
+++ b/xen/arch/x86/platform_hypercall.c
@@ -735,10 +735,6 @@ ret_t do_platform_op(
     {
         int cpu = op->u.cpu_ol.cpuid;
 
-        ret = xsm_resource_plug_core(XSM_HOOK);
-        if ( ret )
-            break;
-
         if ( cpu >= nr_cpu_ids || !cpu_present(cpu) ||
              clocksource_is_tsc() )
         {
@@ -761,10 +757,6 @@ ret_t do_platform_op(
     {
         int cpu = op->u.cpu_ol.cpuid;
 
-        ret = xsm_resource_unplug_core(XSM_HOOK);
-        if ( ret )
-            break;
-
         if ( cpu == 0 )
         {
             ret = -EOPNOTSUPP;
@@ -789,20 +781,12 @@ ret_t do_platform_op(
     }
 
     case XENPF_cpu_hotadd:
-        ret = xsm_resource_plug_core(XSM_HOOK);
-        if ( ret )
-            break;
-
         ret = cpu_add(op->u.cpu_add.apic_id,
                       op->u.cpu_add.acpi_id,
                       op->u.cpu_add.pxm);
         break;
 
     case XENPF_mem_hotadd:
-        ret = xsm_resource_plug_core(XSM_HOOK);
-        if ( ret )
-            break;
-
         ret = memory_add(op->u.mem_add.spfn,
                       op->u.mem_add.epfn,
                       op->u.mem_add.pxm);
--- a/xen/xsm/flask/hooks.c
+++ b/xen/xsm/flask/hooks.c
@@ -1207,6 +1207,7 @@ static int cf_check flask_pci_config_per
 
 }
 
+#if defined(CONFIG_SYSCTL) || defined(CONFIG_X86)
 static int cf_check flask_resource_plug_core(void)
 {
     return avc_current_has_perm(SECINITSID_DOMXEN, SECCLASS_RESOURCE, RESOURCE__PLUG, NULL);
@@ -1216,6 +1217,7 @@ static int cf_check flask_resource_unplu
 {
     return avc_current_has_perm(SECINITSID_DOMXEN, SECCLASS_RESOURCE, RESOURCE__UNPLUG, NULL);
 }
+#endif /* CONFIG_SYSCTL || CONFIG_X86 */
 
 #ifdef CONFIG_SYSCTL
 static int flask_resource_use_core(void)
@@ -1536,12 +1538,13 @@ static int cf_check flask_platform_op(ui
     switch ( op )
     {
 #ifdef CONFIG_X86
-    /* These operations have their own XSM hooks */
     case XENPF_cpu_online:
-    case XENPF_cpu_offline:
     case XENPF_cpu_hotadd:
     case XENPF_mem_hotadd:
-        return 0;
+        return flask_resource_plug_core();
+
+    case XENPF_cpu_offline:
+        return flask_resource_unplug_core();
 #endif
 
     case XENPF_settime32:
