From: Oliver Upton <oliver.upton@linux.dev>
To: kvmarm@lists.linux.dev
Cc: Marc Zyngier <maz@kernel.org>, Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Oliver Upton <oliver.upton@linux.dev>
Subject: [PATCH 0/5] KVM: arm64: vgic-v3: Fix yet another lock ordering turd
Date: Wed, 3 Sep 2025 23:23:43 -0700 [thread overview]
Message-ID: <20250904062348.223976-1-oliver.upton@linux.dev> (raw)
syzkaller found yet another locking bug in the VGIC [*], this time due
to nesting a 'plain' spinlock (xa_lock) inside of a raw spinlock
(ap_list_lock). Given the way we do refcounts on LPIs it is possible
for this exact sort of issue to crop up where the last reference may
be dropped in unexpected places.
Small series to fix the issue by deferring xarray modifications outside
of the ap_list_lock critical section along with some slight lockdep
hinting to make these rare bugs a bit more obvious.
Applies to 6.17-rc4.
Oliver Upton (5):
KVM: arm64: vgic-v3: Use bare refcount for VGIC LPIs
KVM: arm64: Spin off release helper from vgic_put_irq()
KVM: arm64: vgic-v3: Erase LPIs from xarray outside of raw spinlocks
KVM: arm64: vgic-v3: Don't require IRQs be disabled for LPI xarray
lock
KVM: arm64: vgic-v3: Indicate vgic_put_irq() may take LPI xarray lock
arch/arm64/kvm/vgic/vgic-debug.c | 2 +-
arch/arm64/kvm/vgic/vgic-init.c | 6 +--
arch/arm64/kvm/vgic/vgic-its.c | 15 +++---
arch/arm64/kvm/vgic/vgic-v4.c | 2 +-
arch/arm64/kvm/vgic/vgic.c | 78 +++++++++++++++++++++++---------
arch/arm64/kvm/vgic/vgic.h | 8 ++--
include/kvm/arm_vgic.h | 10 ++--
7 files changed, 80 insertions(+), 41 deletions(-)
base-commit: b320789d6883cc00ac78ce83bccbfe7ed58afcf0
--
2.39.5
next reply other threads:[~2025-09-04 7:28 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-04 6:23 Oliver Upton [this message]
2025-09-04 6:23 ` [PATCH 1/5] KVM: arm64: vgic-v3: Use bare refcount for VGIC LPIs Oliver Upton
2025-09-04 6:23 ` [PATCH 2/5] KVM: arm64: Spin off release helper from vgic_put_irq() Oliver Upton
2025-09-04 6:23 ` [PATCH 3/5] KVM: arm64: vgic-v3: Erase LPIs from xarray outside of raw spinlocks Oliver Upton
2025-09-05 7:44 ` Marc Zyngier
2025-09-05 7:19 ` Oliver Upton
2025-09-04 6:23 ` [PATCH 4/5] KVM: arm64: vgic-v3: Don't require IRQs be disabled for LPI xarray lock Oliver Upton
2025-09-05 8:13 ` Marc Zyngier
2025-09-05 8:55 ` Oliver Upton
2025-09-04 6:23 ` [PATCH 5/5] KVM: arm64: vgic-v3: Indicate vgic_put_irq() may take " Oliver Upton
2025-09-04 10:25 ` Ben Horgan
2025-09-04 8:19 ` Oliver Upton
2025-09-05 8:29 ` [PATCH 0/5] KVM: arm64: vgic-v3: Fix yet another lock ordering turd Marc Zyngier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250904062348.223976-1-oliver.upton@linux.dev \
--to=oliver.upton@linux.dev \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=suzuki.poulose@arm.com \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.