From: Claudio Imbrenda <imbrenda@linux.ibm.com>
To: Janosch Frank <frankja@linux.ibm.com>
Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
linux-s390@vger.kernel.org, borntraeger@de.ibm.com,
david@kernel.org, seiden@linux.ibm.com, nrb@linux.ibm.com,
schlameuss@linux.ibm.com, gra@linux.ibm.com
Subject: Re: [PATCH v3 10/10] KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu()
Date: Tue, 28 Jul 2026 16:43:09 +0200 [thread overview]
Message-ID: <20260728164309.5a172dac@p-imbrenda> (raw)
In-Reply-To: <dd83d8ba-e8fc-48ec-b980-d9331d2e29c8@linux.ibm.com>
On Tue, 28 Jul 2026 16:12:15 +0200
Janosch Frank <frankja@linux.ibm.com> wrote:
> On 7/27/26 17:02, Claudio Imbrenda wrote:
> > If creating a protected vCPU in kvm_s390_pv_create_cpu() fails,
> > kvm_s390_pv_destroy_cpu() was called, which checks whether the vCPU has
> > a PV handle and exits doing nothing otherwise. At that point, due to
> > not having created the protected vCPU, the PV handle will not be set,
> > and kvm_s390_pv_destroy_cpu() will do nothing, thus leaking the
> > allocated memory.
> >
> > Fix by factoring out the code to free and reset a PV vCPU; call it from
> > kvm_s390_pv_destroy_cpu() and kvm_s390_pv_create_cpu().
> >
> > Fixes: d4074324b07a ("KVM: s390: pv: avoid double free of sida page")
> > Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
> > ---
> > arch/s390/kvm/pv.c | 41 +++++++++++++++++++++--------------------
> > 1 file changed, 21 insertions(+), 20 deletions(-)
> >
> > diff --git a/arch/s390/kvm/pv.c b/arch/s390/kvm/pv.c
> > index dc204b521052..b02e0159d3cd 100644
> > --- a/arch/s390/kvm/pv.c
> > +++ b/arch/s390/kvm/pv.c
> > @@ -244,6 +244,24 @@ static void kvm_s390_clear_pv_state(struct kvm *kvm)
> > kvm->arch.pv.stor_var = NULL;
> > }
> >
> > +static void kvm_s390_pv_dispose_cpu(struct kvm_vcpu *vcpu, bool free_stor_base)
> > +{
> > + if (free_stor_base)
> > + free_pages(vcpu->arch.pv.stor_base, get_order(uv_info.guest_cpu_stor_len));
> > + free_page((unsigned long)sida_addr(vcpu->arch.sie_block));
> > + vcpu->arch.sie_block->pv_handle_cpu = 0;
> > + vcpu->arch.sie_block->pv_handle_config = 0;
> > + memset(&vcpu->arch.pv, 0, sizeof(vcpu->arch.pv));
> > + vcpu->arch.sie_block->sdf = 0;
> > + /*
> > + * The sidad field (for sdf == 2) is now the gbea field (for sdf == 0).
> > + * Use the reset value of gbea to avoid leaking the kernel pointer of
> > + * the just freed sida.
> > + */
> > + vcpu->arch.sie_block->gbea = 1;
> > + kvm_make_request(KVM_REQ_TLB_FLUSH, vcpu);
> > +}
> > +
> > int kvm_s390_pv_destroy_cpu(struct kvm_vcpu *vcpu, u16 *rc, u16 *rrc)
> > {
> > int cc;
> > @@ -258,24 +276,9 @@ int kvm_s390_pv_destroy_cpu(struct kvm_vcpu *vcpu, u16 *rc, u16 *rrc)
> > WARN_ONCE(cc, "protvirt destroy cpu failed rc %x rrc %x", *rc, *rrc);
> >
> > /* Intended memory leak for something that should never happen. */
>
> That comment doesn't make a lot of sense anymore after your changes.
how so?
potentially calling the helper function with free_stor_base == false
prev parent reply other threads:[~2026-07-28 14:43 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 15:02 [PATCH v3 00/10] KVM: s390: Misc fixes Claudio Imbrenda
2026-07-27 15:02 ` [PATCH v3 01/10] KVM: s390: Fix unlikely NULL gmap dereference Claudio Imbrenda
2026-07-27 15:24 ` sashiko-bot
2026-07-28 14:16 ` Janosch Frank
2026-07-28 15:09 ` Christian Borntraeger
2026-07-27 15:02 ` [PATCH v3 02/10] KVM: s390: Fix leaking of PGM_ADDRESSING to userspace Claudio Imbrenda
2026-07-27 15:33 ` sashiko-bot
2026-07-27 15:02 ` [PATCH v3 03/10] KVM: s390: Fix race in __do_essa() Claudio Imbrenda
2026-07-27 15:43 ` sashiko-bot
2026-07-27 15:02 ` [PATCH v3 04/10] KVM: s390: cmma: Fix dirty tracking when removing memslot Claudio Imbrenda
2026-07-27 16:03 ` sashiko-bot
2026-07-27 15:02 ` [PATCH v3 05/10] KVM: s390: ucontrol: Add missing locking around gmap_remove_child() Claudio Imbrenda
2026-07-27 16:14 ` sashiko-bot
2026-07-27 15:02 ` [PATCH v3 06/10] KVM: s390: Fix overclearing ESCA in case of error Claudio Imbrenda
2026-07-27 16:33 ` sashiko-bot
2026-07-27 15:02 ` [PATCH v3 07/10] KVM: s390: Return -EINTR if a signal was pending while faulting-in Claudio Imbrenda
2026-07-27 16:59 ` sashiko-bot
2026-07-28 14:28 ` Janosch Frank
2026-07-28 14:49 ` Claudio Imbrenda
2026-07-27 15:02 ` [PATCH v3 08/10] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails Claudio Imbrenda
2026-07-27 17:06 ` sashiko-bot
2026-07-28 12:33 ` Steffen Eiden
2026-07-27 15:02 ` [PATCH v3 09/10] KVM: s390: Fix ordering when adding to SCA Claudio Imbrenda
2026-07-27 17:12 ` sashiko-bot
2026-07-28 12:35 ` Steffen Eiden
2026-07-28 14:13 ` Janosch Frank
2026-07-27 15:02 ` [PATCH v3 10/10] KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu() Claudio Imbrenda
2026-07-27 17:18 ` sashiko-bot
2026-07-28 12:40 ` Steffen Eiden
2026-07-28 14:12 ` Janosch Frank
2026-07-28 14:43 ` Claudio Imbrenda [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728164309.5a172dac@p-imbrenda \
--to=imbrenda@linux.ibm.com \
--cc=borntraeger@de.ibm.com \
--cc=david@kernel.org \
--cc=frankja@linux.ibm.com \
--cc=gra@linux.ibm.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=nrb@linux.ibm.com \
--cc=schlameuss@linux.ibm.com \
--cc=seiden@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.