All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Eric Farman" <farman@linux.ibm.com>
Cc: "Vasily Gorbik" <gor@linux.ibm.com>,
	kvm@vger.kernel.org, linux-s390@vger.kernel.org,
	"Heiko Carstens" <hca@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>
Subject: Re: [PATCH v8 03/10] s390/vfio_ccw: fix out of bounds check on CCW array
Date: Tue, 28 Jul 2026 01:50:24 +0000	[thread overview]
Message-ID: <20260728015024.E33A71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728013509.1551753-4-farman@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The driver unconditionally attempts to read a full 2048-byte chunk (256 CCWs) from guest memory, which will fail if a valid, shorter channel program is located near the end of mapped guest memory.
--

--- Patch [3]: [PATCH v8 03/10] s390/vfio_ccw: fix out of bounds check on CCW array ---
commit f979cac6ff9095b28670a21c1bdc95dfaa156466
Author: Eric Farman <farman@linux.ibm.com>

s390/vfio_ccw: fix out of bounds check on CCW array

The routine ccwchain_calc_length() counts the number of channel
command words (CCWs) that are chained together in a single channel
program, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.
The loop is restructured to avoid checking memory outside the valid range.

Cc: stable@vger.kernel.org

> diff --git a/drivers/s390/cio/vfio_ccw_cp.c b/drivers/s390/cio/vfio_ccw_cp.c
> index 1c2890d139c6b..af632f9d54535 100644
> --- a/drivers/s390/cio/vfio_ccw_cp.c
> +++ b/drivers/s390/cio/vfio_ccw_cp.c
> @@ -377,11 +377,9 @@ static void ccwchain_cda_free(struct ccwchain *chain, int idx)
>  static int ccwchain_calc_length(u64 iova, struct channel_program *cp)
>  {
>  	struct ccw1 *ccw = cp->guest_cp;
> -	int cnt = 0;
> -
> -	do {
> -		cnt++;
> +	int cnt;
>  
> +	for (cnt = 1; cnt <= CCWCHAIN_LEN_MAX; cnt++, ccw++) {

[Severity: High]
This is a pre-existing issue, but since we are modifying the CCW bounds
checking here, could the unconditional 2K DMA read in ccwchain_handle_ccw()
inadvertently reject valid channel programs?

The driver unconditionally attempts to read a full 2048-byte chunk (256 CCWs)
from guest memory before calculating the actual length:

drivers/s390/cio/vfio_ccw_cp.c:ccwchain_handle_ccw() {
    ...
    /* Copy 2K (the most we support today) of possible CCWs */
    ret = vfio_dma_rw(vdev, gcda, cp->guest_cp,
                      CCWCHAIN_LEN_MAX * sizeof(struct ccw1), false);
    if (ret)
        return ret;
    ...
    /* Count the CCWs in the current chain */
    len = ccwchain_calc_length(gcda, cp);
    ...
}

If a guest uses a strict vIOMMU mapping and places a valid, shorter channel
program near the end of a mapped IOVA region, won't this read cross into an
unmapped page and fail with -EFAULT? This appears to render the device
partially or fully unusable for guests configuring their mappings this way.

>  		/*
>  		 * We want to keep counting if the current CCW has the
>  		 * command-chaining flag enabled, or if it is a TIC CCW

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260728013509.1551753-1-farman@linux.ibm.com?part=3

  reply	other threads:[~2026-07-28  1:50 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-28  1:34 [PATCH v8 00/10] s390/vfio_ccw fixes Eric Farman
2026-07-28  1:35 ` [PATCH v8 01/10] s390/vfio_ccw: free all memory if cp_init() fails Eric Farman
2026-07-28  1:51   ` sashiko-bot
2026-07-28  1:35 ` [PATCH v8 02/10] s390/vfio_ccw: limit the number of channel program segments Eric Farman
2026-07-28  1:52   ` sashiko-bot
2026-07-28  1:35 ` [PATCH v8 03/10] s390/vfio_ccw: fix out of bounds check on CCW array Eric Farman
2026-07-28  1:50   ` sashiko-bot [this message]
2026-07-28  1:35 ` [PATCH v8 04/10] s390/vfio_ccw: ensure first IDAW remains constant Eric Farman
2026-07-28  1:45   ` sashiko-bot
2026-07-28  1:35 ` [PATCH v8 05/10] s390/vfio_ccw: calculate idal length based on idaw type Eric Farman
2026-07-28  1:49   ` sashiko-bot
2026-07-28  1:35 ` [PATCH v8 06/10] s390/vfio_ccw: ensure index for read/write regions are within range Eric Farman
2026-07-28  1:54   ` sashiko-bot
2026-07-28  1:35 ` [PATCH v8 07/10] s390/vfio_ccw: cancel existing workqueues Eric Farman
2026-07-28  1:53   ` sashiko-bot
2026-07-28  2:07   ` Matthew Rosato
2026-07-28  1:35 ` [PATCH v8 08/10] s390/vfio_ccw: move cp cleanup out of not operational Eric Farman
2026-07-28  1:49   ` sashiko-bot
2026-07-28  2:08   ` Matthew Rosato
2026-07-28  3:23     ` Eric Farman
2026-07-28  1:35 ` [PATCH v8 09/10] s390/vfio_ccw: selectively expand io_mutex Eric Farman
2026-07-28  1:57   ` sashiko-bot
2026-07-28  2:08   ` Matthew Rosato
2026-07-28  1:35 ` [PATCH v8 10/10] s390/vfio_ccw: implement a crw lock Eric Farman
2026-07-28  2:01   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728015024.E33A71F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=farman@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.