All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Claudio Imbrenda" <imbrenda@linux.ibm.com>
Cc: kvm@vger.kernel.org, linux-s390@vger.kernel.org,
	"Heiko Carstens" <hca@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>
Subject: Re: [PATCH v4 08/13] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails
Date: Tue, 28 Jul 2026 17:27:45 +0000	[thread overview]
Message-ID: <20260728172745.CB67B1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728170708.294400-9-imbrenda@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] Unconditional call to `kvm_s390_vcpu_unsetup_cmma()` when PV VCPU creation fails causes freeing of physical page 0 if CMMA is disabled, leading to a host panic.
--

--- Patch [8]: [PATCH v4 08/13] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails ---
commit 30d38fd7067b631b7997fead40df5a9ae47fcfb8
Author: Claudio Imbrenda <imbrenda@linux.ibm.com>

KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails

This commit fixes a memory leak where the mmu cache is not freed if
vcpu creation fails. It also refactors kvm_arch_vcpu_create() to use
scope-based cleanup instead of goto-based error handling.

> diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
> --- a/arch/s390/kvm/kvm-s390.c
> +++ b/arch/s390/kvm/kvm-s390.c

[ ... ]

> @@ -3849,10 +3849,9 @@ int kvm_arch_vcpu_create(struct kvm_vcpu *vcpu)
>  	VM_EVENT(vcpu->kvm, 3, "create cpu %d at 0x%p, sie block at 0x%p",
>  		 vcpu->vcpu_id, vcpu, vcpu->arch.sie_block);
>  	trace_kvm_s390_create_vcpu(vcpu->vcpu_id, vcpu, vcpu->arch.sie_block);
>  
>  	rc = kvm_s390_vcpu_setup(vcpu);

[Severity: Critical]
This is a pre-existing issue, but could this lead to a host panic if a
Protected VM fails to create a VCPU and CMMA is disabled?

If kvm_s390_pv_create_cpu() fails (e.g., hitting a cgroup memory limit)
inside kvm_s390_vcpu_setup(), it unconditionally unsets CMMA:

kvm_s390_vcpu_setup() {
    ...
	if (kvm_s390_pv_is_protected(vcpu->kvm)) {
		rc = kvm_s390_pv_create_cpu(vcpu, &uvrc, &uvrrc);
		if (rc)
			kvm_s390_vcpu_unsetup_cmma(vcpu);
	}
    ...
}

If use_cmma is false, vcpu->arch.sie_block->cbrlo is 0. 
kvm_s390_vcpu_unsetup_cmma() then executes:

kvm_s390_vcpu_unsetup_cmma() {
    ...
	free_page((unsigned long)phys_to_virt(vcpu->arch.sie_block->cbrlo));
    ...
}

With KASLR enabled, phys_to_virt(0) evaluates to __identity_base 
(a non-zero address), which bypasses the safety check in free_pages(). 
Does this erroneously free physical page 0 (the lowcore page), leading 
to memory corruption or a fatal VM_BUG_ON_PAGE panic on the host?

> -	if (rc)
> -		goto out_ucontrol_uninit;
> +	if (rc) {
> +		if (kvm_is_ucontrol(vcpu->kvm)) {
> +			scoped_guard(spinlock, &vcpu->kvm->arch.gmap->children_lock)
> +				gmap_remove_child(vcpu->arch.gmap);
> +			vcpu->arch.gmap = gmap_put(vcpu->arch.gmap);
> +		}
> +		return rc;
> +	}
>  
> +	vcpu->arch.mc = no_free_ptr(mc);
> +	sie_page = NULL;
>  	kvm_s390_update_topology_change_report(vcpu->kvm, 1);
>  	return 0;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260728170708.294400-1-imbrenda@linux.ibm.com?part=8

  reply	other threads:[~2026-07-28 17:27 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-28 17:06 [PATCH v4 00/13] KVM: s390: Misc fixes Claudio Imbrenda
2026-07-28 17:06 ` [PATCH v4 01/13] KVM: s390: Fix unlikely NULL gmap dereference Claudio Imbrenda
2026-07-28 17:27   ` sashiko-bot
2026-07-28 17:06 ` [PATCH v4 02/13] KVM: s390: Fix leaking of PGM_ADDRESSING to userspace Claudio Imbrenda
2026-07-28 17:16   ` sashiko-bot
2026-07-28 17:06 ` [PATCH v4 03/13] KVM: s390: Fix race in __do_essa() Claudio Imbrenda
2026-07-28 17:21   ` sashiko-bot
2026-07-28 17:06 ` [PATCH v4 04/13] KVM: s390: cmma: Fix dirty tracking when removing memslot Claudio Imbrenda
2026-07-28 17:22   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 05/13] KVM: s390: ucontrol: Add missing locking around gmap_remove_child() Claudio Imbrenda
2026-07-28 17:20   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 06/13] KVM: s390: Fix overclearing ESCA in case of error Claudio Imbrenda
2026-07-28 17:27   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 07/13] KVM: s390: Return -EINTR if a signal was pending while faulting-in Claudio Imbrenda
2026-07-28 17:32   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 08/13] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails Claudio Imbrenda
2026-07-28 17:27   ` sashiko-bot [this message]
2026-07-28 17:07 ` [PATCH v4 09/13] KVM: s390: Fix ordering when adding to SCA Claudio Imbrenda
2026-07-28 17:15   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 10/13] KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu() Claudio Imbrenda
2026-07-28 17:14   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 11/13] KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory Claudio Imbrenda
2026-07-28 17:25   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 12/13] KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma() Claudio Imbrenda
2026-07-28 17:24   ` sashiko-bot
2026-07-28 17:07 ` [PATCH v4 13/13] KVM: s390: Fix sca_clear_ext_call() for UCONTROL Claudio Imbrenda
2026-07-28 17:39   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728172745.CB67B1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.