From: sashiko-bot@kernel.org
To: "Wei Hu" <weh@linux.microsoft.com>
Cc: linux-hyperv@vger.kernel.org
Subject: Re: [PATCH v1 03/13] mshv: add SEV-SNP isolated page hypercalls
Date: Fri, 07 Aug 2026 14:21:38 +0000 [thread overview]
Message-ID: <20260807142139.69F531F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260807135134.303943-4-weh@linux.microsoft.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The `completed` variable is evaluated from `status` before the asynchronous completion handler updates it, leading to a stale completion count and an infinite loop.
--
--- Patch [3]: [PATCH v1 03/13] mshv: add SEV-SNP isolated page hypercalls ---
commit 3c19c21fc983589586a3386b97c714ce13aec72c
Author: Wei Liu <wei.liu@kernel.org>
mshv: add SEV-SNP isolated page hypercalls
Add helpers for importing isolated pages and completing isolated
imports. These are used by SEV-SNP guest launch flows to transfer
isolated page state to the hypervisor.
> diff --git a/drivers/hv/mshv_root_hv_call.c b/drivers/hv/mshv_root_hv_call.c
> index 48abe338c06f8..9ddc8dd73da7a 100644
> --- a/drivers/hv/mshv_root_hv_call.c
> +++ b/drivers/hv/mshv_root_hv_call.c
[ ... ]
> @@ -1010,6 +1014,99 @@ int hv_unmap_stats_page(enum hv_stats_object_type type,
> }
>
> #ifdef HV_SUPPORTS_SEV_SNP_GUESTS
> +int hv_call_import_isolated_pages(u64 partition_id, u64 *pages,
> + u64 num_pages,
> + enum hv_isolated_page_type page_type,
> + enum hv_isolated_page_size page_size,
> + void (*completion_handler)(void *data,
> + u64 *status),
> + void *completion_data)
> +{
[ ... ]
> + while (remaining) {
> + rep_count = min_t(unsigned long, remaining,
> + HV_ISOLATED_PAGE_BATCH_SIZE);
> +
> + local_irq_save(flags);
> + input = *this_cpu_ptr(hyperv_pcpu_input_arg);
> + memset(input, 0, sizeof(*input));
> + input->partition_id = partition_id;
> + input->page_type = page_type;
> + input->page_size = page_size;
> + memcpy(input->page_number, gpa, rep_count * sizeof(*gpa));
> + status = hv_do_rep_hypercall(HVCALL_IMPORT_ISOLATED_PAGES,
> + rep_count, 0, input, NULL);
> + local_irq_restore(flags);
> +
> + completed = hv_repcomp(status);
> + if (hv_result(status) == HV_STATUS_CALL_PENDING)
> + completion_handler(completion_data, &status);
[Severity: High]
If the hypercall returns HV_STATUS_CALL_PENDING, the completion_handler updates
the status variable, but the completed variable was already evaluated from the
initial status.
Could this lead to completed being 0 (or a stale value), which would then
prevent gpa and remaining from advancing correctly?
> +
> + if (!hv_result_success(status)) {
> + pr_err("%s: completed %llu of %llu, %s\n", __func__,
> + num_pages - remaining, num_pages,
> + hv_result_to_string(status));
> + return hv_result_to_errno(status);
> + }
> +
> + gpa += completed;
> + remaining -= completed;
[Severity: High]
If completed is not updated after the completion handler executes, does this
result in an infinite loop since remaining will not decrease?
> + }
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260807135134.303943-1-weh@linux.microsoft.com?part=3
next prev parent reply other threads:[~2026-08-07 14:21 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-07 13:51 [PATCH v1 00/13] mshv: add SEV-SNP support for MSHV root partitions Wei Hu
2026-08-07 13:51 ` [PATCH v1 01/13] mshv: add SEV-SNP UAPI definitions Wei Hu
2026-08-07 14:03 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 02/13] mshv: add SEV-SNP PSP request hypercall Wei Hu
2026-08-07 13:51 ` [PATCH v1 03/13] mshv: add SEV-SNP isolated page hypercalls Wei Hu
2026-08-07 14:21 ` sashiko-bot [this message]
2026-08-07 13:51 ` [PATCH v1 04/13] mshv: wire SEV-SNP partition ioctls Wei Hu
2026-08-07 14:45 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 05/13] hyperv: fix hv_input_get_system_property layout for SNP status Wei Hu
2026-08-07 13:51 ` [PATCH v1 06/13] mshv: detect and report SEV-SNP support at init Wei Hu
2026-08-07 15:04 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 07/13] mshv: default to safe partition CPU features Wei Hu
2026-08-07 15:15 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 08/13] mshv: accept partial CPU feature banks Wei Hu
2026-08-07 15:30 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 09/13] mshv: define full processor and xsave feature masks Wei Hu
2026-08-07 15:42 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 10/13] mshv: unmap SNP memory before state teardown Wei Hu
2026-08-07 15:53 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 11/13] mshv: unlock SNP pages on panic for crashdump collection Wei Hu
2026-08-07 16:11 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 12/13] hyperv: add MSHV Dom0 root-partition boot enablement (EFI HvLoader) Wei Hu
2026-08-07 16:22 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 13/13] mshv: set up own SynIC registers on a nested root partition Wei Hu
2026-08-07 16:36 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807142139.69F531F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=weh@linux.microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.