All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Claudio Imbrenda" <imbrenda@linux.ibm.com>
Cc: "Heiko Carstens" <hca@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	kvm@vger.kernel.org
Subject: Re: [PATCH v4 11/13] KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory
Date: Tue, 28 Jul 2026 17:25:37 +0000	[thread overview]
Message-ID: <20260728172537.9832C1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728170708.294400-12-imbrenda@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] User-triggerable KVM_BUG_ON (WARN_ON_ONCE) on memcg OOM.
--

--- Patch [11]: [PATCH v4 11/13] KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory ---
commit 9bd2f3fe880640681d24faea9af3bd26f006d538
Author: Claudio Imbrenda <imbrenda@linux.ibm.com>

KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory
    
When low on memory, kvm_arch_commit_memory_region() attempts to refill
the MMU cache and retry. If the refill fails, it kills the VM using
KVM_BUG_ON.

> diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
> --- a/arch/s390/kvm/kvm-s390.c
> +++ b/arch/s390/kvm/kvm-s390.c
[ ... ]
> @@ -5850,11 +5848,17 @@ void kvm_arch_commit_memory_region(struct kvm *kvm,
>  		case KVM_MR_FLAGS_ONLY:
>  			break;
>  		default:
> +			rc = 0;
>  			WARN(1, "Unknown KVM MR CHANGE: %d\n", change);
>  		}
>  	}
> +	if (rc == -ENOMEM) {
> +		rc = kvm_s390_mmu_cache_topup(mc);
> +		if (!rc)
> +			goto retry;
> +	}
>  out:
> -	if (rc)
> +	if (KVM_BUG_ON(rc, kvm))

[Severity: High]
Could this KVM_BUG_ON() be triggered by a host-userspace process facing
memory pressure?

If an unprivileged userspace process creates a VM within a restricted memory
cgroup (memcg), and then calls KVM_SET_USER_MEMORY_REGION to modify a
memslot, kvm_s390_mmu_cache_topup() could return -ENOMEM due to the memcg
limit.

Since KVM_BUG_ON expands to WARN_ON_ONCE, wouldn't this allow a malicious
guest or unprivileged host process to cause a host-side denial of service
if panic_on_warn is enabled?

>  		pr_warn("failed to commit memory region\n");
>  	return;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260728170708.294400-1-imbrenda@linux.ibm.com?part=11

  reply	other threads:[~2026-07-28 17:25 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-28 17:06 [PATCH v4 00/13] KVM: s390: Misc fixes Claudio Imbrenda
2026-07-28 17:06 ` [PATCH v4 01/13] KVM: s390: Fix unlikely NULL gmap dereference Claudio Imbrenda
2026-07-28 17:27   ` sashiko-bot
2026-07-28 17:06 ` [PATCH v4 02/13] KVM: s390: Fix leaking of PGM_ADDRESSING to userspace Claudio Imbrenda
2026-07-28 17:16   ` sashiko-bot
2026-07-28 17:06 ` [PATCH v4 03/13] KVM: s390: Fix race in __do_essa() Claudio Imbrenda
2026-07-28 17:21   ` sashiko-bot
2026-07-28 17:06 ` [PATCH v4 04/13] KVM: s390: cmma: Fix dirty tracking when removing memslot Claudio Imbrenda
2026-07-28 17:22   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 05/13] KVM: s390: ucontrol: Add missing locking around gmap_remove_child() Claudio Imbrenda
2026-07-28 17:20   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 06/13] KVM: s390: Fix overclearing ESCA in case of error Claudio Imbrenda
2026-07-28 17:27   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 07/13] KVM: s390: Return -EINTR if a signal was pending while faulting-in Claudio Imbrenda
2026-07-28 17:32   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 08/13] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails Claudio Imbrenda
2026-07-28 17:27   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 09/13] KVM: s390: Fix ordering when adding to SCA Claudio Imbrenda
2026-07-28 17:15   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 10/13] KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu() Claudio Imbrenda
2026-07-28 17:14   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 11/13] KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory Claudio Imbrenda
2026-07-28 17:25   ` sashiko-bot [this message]
2026-07-28 17:07 ` [PATCH v4 12/13] KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma() Claudio Imbrenda
2026-07-28 17:24   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 13/13] KVM: s390: Fix sca_clear_ext_call() for UCONTROL Claudio Imbrenda
2026-07-28 17:39   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728172537.9832C1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.