From: sashiko-bot@kernel.org
To: "Wei Hu" <weh@linux.microsoft.com>
Cc: linux-hyperv@vger.kernel.org
Subject: Re: [PATCH v1 09/13] mshv: define full processor and xsave feature masks
Date: Fri, 07 Aug 2026 15:42:00 +0000 [thread overview]
Message-ID: <20260807154201.327A51F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260807135134.303943-10-weh@linux.microsoft.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] Uninitialized kernel stack memory is leaked to the hypervisor on non-x86 architectures when the legacy v1 ioctl is used.
- [Low] Typo in the bitfield name `vrew_clear_supported` (should be `verw_clear_supported`).
--
--- Patch [9]: [PATCH v1 09/13] mshv: define full processor and xsave feature masks ---
commit 758f4dc3eb51bb86e9e77dff7703639f92529960
Author: Wei Liu <wei.liu@kernel.org>
mshv: define full processor and xsave feature masks
Add the missing processor and xsave feature bit definitions and use
them when constructing the default disabled-feature mask, so legacy
SNP partition creation applies a complete, well-defined feature mask.
> diff --git a/drivers/hv/mshv_root_main.c b/drivers/hv/mshv_root_main.c
> index 729916e1eacff..c81a8d0493c19 100644
> --- a/drivers/hv/mshv_root_main.c
> +++ b/drivers/hv/mshv_root_main.c
> @@ -2406,11 +2406,21 @@ static long mshv_ioctl_process_pt_flags(void __user *user_arg, u64 *pt_flags,
[ ... ]
> disabled_xsave->as_uint64 = U64_MAX;
> disabled_xsave->xsave_support = 0;
> disabled_xsave->xsaveopt_support = 0;
> disabled_xsave->avx_support = 0;
> + disabled_xsave->xsave_comp_support = 0;
> + disabled_xsave->xsave_supervisor_support = 0;
> #endif
>
> /* Check if user provided newer struct with feature fields */
[Severity: Medium]
Does this leave disabled_xsave uninitialized on non-x86 architectures when
using the legacy v1 ioctl?
When MSHV_PT_BIT_CPU_AND_XSAVE_FEATURES is not set on ARM64, the fallback
initialization that clears disabled_xsave->as_uint64 is skipped because it is
nested inside the v2 struct check block further down in
mshv_ioctl_process_pt_flags().
This leaves 8 bytes of uninitialized kernel stack in
creation_properties.disabled_processor_xsave_features (allocated in
mshv_ioctl_create_partition()), which is then passed to the hypervisor via
hv_call_create_partition().
This appears to have been introduced earlier in this patch series in the commit
"mshv: default to safe partition CPU features" when the original else block
clearing the legacy features was removed.
> diff --git a/include/hyperv/hvhdk.h b/include/hyperv/hvhdk.h
> index 691ac495a095d..54b0e671a028f 100644
> --- a/include/hyperv/hvhdk.h
> +++ b/include/hyperv/hvhdk.h
> @@ -231,7 +231,47 @@ union hv_partition_processor_features {
> u64 fzlrep_movsb : 1;
> u64 fsrep_stosb : 1;
> u64 fsrep_cmpsb : 1;
> - u64 reserved_bank1 : 42;
[ ... ]
> + u64 sbpb_supported : 1;
> + u64 ibpb_br_type_supported : 1;
> + u64 srso_no_supported : 1;
> + u64 srso_user_kernel_no_supported : 1;
> + u64 vrew_clear_supported : 1;
[Severity: Low]
This isn't a bug, but there is a typo in the bitfield name vrew_clear_supported,
it should be verw_clear_supported.
> + u64 tsa_l1_no_supported : 1;
> + u64 tsa_sq_no_supported : 1;
> + u64 lass_support : 1;
> + u64 reserved_bank1 : 2;
> } __packed;
> };
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260807135134.303943-1-weh@linux.microsoft.com?part=9
next prev parent reply other threads:[~2026-08-07 15:42 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-07 13:51 [PATCH v1 00/13] mshv: add SEV-SNP support for MSHV root partitions Wei Hu
2026-08-07 13:51 ` [PATCH v1 01/13] mshv: add SEV-SNP UAPI definitions Wei Hu
2026-08-07 14:03 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 02/13] mshv: add SEV-SNP PSP request hypercall Wei Hu
2026-08-07 13:51 ` [PATCH v1 03/13] mshv: add SEV-SNP isolated page hypercalls Wei Hu
2026-08-07 14:21 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 04/13] mshv: wire SEV-SNP partition ioctls Wei Hu
2026-08-07 14:45 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 05/13] hyperv: fix hv_input_get_system_property layout for SNP status Wei Hu
2026-08-07 13:51 ` [PATCH v1 06/13] mshv: detect and report SEV-SNP support at init Wei Hu
2026-08-07 15:04 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 07/13] mshv: default to safe partition CPU features Wei Hu
2026-08-07 15:15 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 08/13] mshv: accept partial CPU feature banks Wei Hu
2026-08-07 15:30 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 09/13] mshv: define full processor and xsave feature masks Wei Hu
2026-08-07 15:42 ` sashiko-bot [this message]
2026-08-07 13:51 ` [PATCH v1 10/13] mshv: unmap SNP memory before state teardown Wei Hu
2026-08-07 15:53 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 11/13] mshv: unlock SNP pages on panic for crashdump collection Wei Hu
2026-08-07 16:11 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 12/13] hyperv: add MSHV Dom0 root-partition boot enablement (EFI HvLoader) Wei Hu
2026-08-07 16:22 ` sashiko-bot
2026-08-07 13:51 ` [PATCH v1 13/13] mshv: set up own SynIC registers on a nested root partition Wei Hu
2026-08-07 16:36 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807154201.327A51F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=weh@linux.microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.