All of lore.kernel.org
 help / color / mirror / Atom feed
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
To: linux-kernel@vger.kernel.org
Cc: kvm@vger.kernel.org, linux-s390@vger.kernel.org,
	borntraeger@de.ibm.com, frankja@linux.ibm.com, david@kernel.org,
	seiden@linux.ibm.com, nrb@linux.ibm.com,
	schlameuss@linux.ibm.com, gra@linux.ibm.com
Subject: [PATCH v8 00/13] KVM: s390: Misc fixes
Date: Mon,  3 Aug 2026 14:40:27 +0200	[thread overview]
Message-ID: <20260803124040.126471-1-imbrenda@linux.ibm.com> (raw)

Fix a bunch of small issues that came up during the previous round of fixes.

They are mostly extremely unlikely races, but they should be fixed
nonetheless.

v7->v8
* Fix some patch descriptions.
* Remove KVM_BUG_ON() from code that should not be reached but could
  still be reached. Just return an appropriate error code.
* Drop the last patch. Will need a more complex fix, will be done in a
  different series.

v6->v7
* Do not free SCA in kvm_arch_init_vm() if it was not allocated
* Remove a KVM_BUG_ON() that could still be triggered from userspace
  with UCONTROL.
* Remove KVM_BUG_ON() if a memslot change could not be performed.
* Fence KVM_S390_INTERRUPT also for vCPUs for UCONTROL VMs.

v5->v6
* Move the memory accesses in sca_ext_call_pending() and
  sca_inject_ext_call() so that they only happen after the newly
  introduced checks. Otherwise an out of bounds access was still possible.
* Completely fence the KVM_S390_INTERRUPT ioctl for UCONTROL VMs.
* Move page table updates from kvm_arch_commit_memory_region() to
  kvm_arch_prepare_memory_region(), so that failures are not ignored.

v4->v5
* Improve / fix some comments
* Undo handle_mvpg_pei() changes
* cmma_d_count_pte() now clears the cmma_d bit, to avoid double counting
* Improve some patch descriptions
* Trigger KVM_BUG_ON() in sca_ext_call_pending() and
  sca_inject_ext_call() if called on UCONTROL vCPUs
* Reshuffle the order of the patches to hopefully get fewer false
  positives from sashiko
* Check and free cbrlo only if it's not zero

v3->v4
* Improve patch descriptions, add comments
* Use smp_store_release and smp_load_acquire in the first patch
* Multiple fixes in patch 4: potential NULL pointer dereference,
  incorrect behaviour in low memory condition
* Rework patch 8 to use scope-based cleanup instead of gotos.
* Three new patches:
  - KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory
  - KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma()
  - KVM: s390: Fix sca_clear_ext_call() for UCONTROL

v2->v3
* Use READ_ONCE to pair with WRITE_ONCE in the first patch
* Fix leaking PGM_ADDRESSING also in kvm_s390_keyop() and related functions
* Fix and improve commit messages
* Use slots_arch_lock instead of slots_lock for ESSA operations
* Use normal spin_{,un}lock() functions instead of scoped_guard to avoid
  mixing the two styles
* Use the newly introduced vcpu->arch.initialized to determine whether the
  SCA entry needs to be cleared
* Improve handling of -EINTR; handle_mvpg_pei() needed some refactoring to
  deal with it properly
* Three new patches:
  - Free the mmu cache when kvm_arch_vcpu_create() fails
  - Fix ordering when adding to SCA
  - Fix cleanup in kvm_s390_pv_create_cpu()

v1->v2
* Drop some patches that have been picked upstream in the meantime.
* Drop patch 3, as it was trying to fix a bug that does not exist
* Avoid the NULL gmap dereference by using a flag
* Fix the return value of kvm_s390_[gp]et_skeys too
* Use kvm->slots_arch_lock instead of kvm->slots_lock for CMMA and ESSA
  handling, to avoid potential deadlocks with the RCU.
* Three new patches to fix other issues that came out while fixing the
  other issues

Claudio Imbrenda (13):
  KVM: s390: Fix unlikely NULL gmap dereference
  KVM: s390: Do not free SCA if it was not allocated
  KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma()
  KVM: s390: Fix overclearing ESCA in case of error
  KVM: s390: ucontrol: Fix sca_clear_ext_call()
  KVM: s390: Fix leaking of PGM_ADDRESSING to userspace
  KVM: s390: Fix race in __do_essa()
  KVM: s390: cmma: Fix dirty tracking when removing memslot
  KVM: s390: ucontrol: Add missing locking around gmap_remove_child()
  KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails
  KVM: s390: Return -EINTR if a signal is pending while faulting-in
  KVM: s390: Fix ordering when adding to SCA
  KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu()

 arch/s390/include/asm/kvm_host.h |   1 +
 arch/s390/kvm/dat.c              |  23 ++++--
 arch/s390/kvm/dat.h              |   2 +-
 arch/s390/kvm/faultin.c          |   6 +-
 arch/s390/kvm/interrupt.c        |  19 +++--
 arch/s390/kvm/kvm-s390.c         | 125 ++++++++++++++++++++-----------
 arch/s390/kvm/priv.c             |  10 ++-
 arch/s390/kvm/pv.c               |  43 +++++------
 8 files changed, 144 insertions(+), 85 deletions(-)

-- 
2.55.0


             reply	other threads:[~2026-08-03 12:40 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03 12:40 Claudio Imbrenda [this message]
2026-08-03 12:40 ` [PATCH v8 01/13] KVM: s390: Fix unlikely NULL gmap dereference Claudio Imbrenda
2026-08-03 12:55   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 02/13] KVM: s390: Do not free SCA if it was not allocated Claudio Imbrenda
2026-08-03 12:55   ` sashiko-bot
2026-08-03 14:08   ` Christian Borntraeger
2026-08-03 14:13   ` Janosch Frank
2026-08-03 12:40 ` [PATCH v8 03/13] KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma() Claudio Imbrenda
2026-08-03 13:19   ` sashiko-bot
2026-08-03 14:30   ` Janosch Frank
2026-08-03 14:54     ` Claudio Imbrenda
2026-08-03 12:40 ` [PATCH v8 04/13] KVM: s390: Fix overclearing ESCA in case of error Claudio Imbrenda
2026-08-03 13:05   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 05/13] KVM: s390: ucontrol: Fix sca_clear_ext_call() Claudio Imbrenda
2026-08-03 13:21   ` sashiko-bot
2026-08-03 14:50   ` Janosch Frank
2026-08-03 15:03     ` Claudio Imbrenda
2026-08-03 12:40 ` [PATCH v8 06/13] KVM: s390: Fix leaking of PGM_ADDRESSING to userspace Claudio Imbrenda
2026-08-03 13:01   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 07/13] KVM: s390: Fix race in __do_essa() Claudio Imbrenda
2026-08-03 12:56   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 08/13] KVM: s390: cmma: Fix dirty tracking when removing memslot Claudio Imbrenda
2026-08-03 13:08   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 09/13] KVM: s390: ucontrol: Add missing locking around gmap_remove_child() Claudio Imbrenda
2026-08-03 12:59   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 10/13] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails Claudio Imbrenda
2026-08-03 12:51   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 11/13] KVM: s390: Return -EINTR if a signal is pending while faulting-in Claudio Imbrenda
2026-08-03 13:19   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 12/13] KVM: s390: Fix ordering when adding to SCA Claudio Imbrenda
2026-08-03 13:03   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 13/13] KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu() Claudio Imbrenda
2026-08-03 13:05   ` sashiko-bot
2026-08-03 15:06   ` Janosch Frank

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260803124040.126471-1-imbrenda@linux.ibm.com \
    --to=imbrenda@linux.ibm.com \
    --cc=borntraeger@de.ibm.com \
    --cc=david@kernel.org \
    --cc=frankja@linux.ibm.com \
    --cc=gra@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=nrb@linux.ibm.com \
    --cc=schlameuss@linux.ibm.com \
    --cc=seiden@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.