All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Farhan Ali" <alifm@linux.ibm.com>
Cc: "Alexander Gordeev" <agordeev@linux.ibm.com>,
	linux-s390@vger.kernel.org, kvm@vger.kernel.org,
	"Heiko Carstens" <hca@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH v4 6/6] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
Date: Wed, 22 Jul 2026 17:26:51 +0000	[thread overview]
Message-ID: <20260722172651.848261F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260722170621.1686-7-alifm@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The AIBV size calculation systematically overestimates the required memory size, leading to false rejection of valid AIBV configurations located near page boundaries.
--

--- Patch [6]: [PATCH v4 6/6] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages ---
commit 4b6ef516a235f953d1559a623689c91ffb836199
Author: Farhan Ali <alifm@linux.ibm.com>

KVM: s390: pci: Validate AIBV and AISB before pinning guest pages

This commit adds validation checks for the guest-provided AIBV and AISB 
addresses before pinning them. It ensures the AIBV does not exceed a single 
page boundary and that the AISB is aligned properly to 8 bytes.

> diff --git a/arch/s390/kvm/pci.c b/arch/s390/kvm/pci.c
> index d76b2c5484aca..e55e75b81b516 100644
> --- a/arch/s390/kvm/pci.c
> +++ b/arch/s390/kvm/pci.c

[ ... ]

> @@ -268,6 +268,14 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
>  		return gisc;
>  
>  	/* Replace AIBV address */
> +	size = BITS_TO_LONGS(msi_vecs) * sizeof(unsigned long);
> +	size += (fib->fmt0.aibvo / 8) + 1;
> +	npages = DIV_ROUND_UP((fib->fmt0.aibv & ~PAGE_MASK) + size, PAGE_SIZE);
> +	if (npages > 1) {
> +		rc = -EINVAL;
> +		goto out;
> +	}
> +

[Severity: High]
Does this size calculation artificially inflate the required AIBV memory space 
and falsely reject valid guest configurations?

If a guest places a 1-MSI vector AIBV near the end of a physical page, such 
as at page offset 4088, the size formula calculates at least 9 bytes (8 
bytes from BITS_TO_LONGS(1) plus 1 arbitrary byte). 

This inflated size (4088 + 9 = 4097) crosses the page boundary, causing KVM 
to mistakenly reject a perfectly valid, 8-byte aligned memory placement with 
-EINVAL. Can this formula be adjusted to calculate the exact size required?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260722170621.1686-1-alifm@linux.ibm.com?part=6

      reply	other threads:[~2026-07-22 17:26 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 17:06 [PATCH v4 0/6] KVM s390x PCI fixes Farhan Ali
2026-07-22 17:06 ` [PATCH v4 1/6] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled Farhan Ali
2026-07-22 17:25   ` sashiko-bot
2026-07-22 17:06 ` [PATCH v4 2/6] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages Farhan Ali
2026-07-22 17:21   ` sashiko-bot
2026-07-22 17:06 ` [PATCH v4 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting Farhan Ali
2026-07-22 17:17   ` sashiko-bot
2026-07-22 17:06 ` [PATCH v4 4/6] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure Farhan Ali
2026-07-22 17:19   ` sashiko-bot
2026-07-22 17:06 ` [PATCH v4 5/6] KVM: s390: pci: Fix resource leak on IRQ registration failure Farhan Ali
2026-07-22 17:15   ` sashiko-bot
2026-07-22 17:06 ` [PATCH v4 6/6] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages Farhan Ali
2026-07-22 17:26   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722172651.848261F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=alifm@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.