From: sashiko-bot@kernel.org
To: "Christoph Schlameuss" <schlameuss@linux.ibm.com>
Cc: kvm@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.vom>,
"Vasily Gorbik" <gor@linux.ibm.com>,
linux-s390@vger.kernel.org,
"Alexander Gordeev" <agordeev@linux.ibm.com>
Subject: Re: [PATCH v4 13/20] KVM: s390: vsie: Add struct vsie_sca with pin and unpin methods
Date: Wed, 12 Aug 2026 15:43:59 +0000 [thread overview]
Message-ID: <20260812154359.C5F501F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260812-vsie-sigpi-v4-13-f19e49666315@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Guest-triggerable WARN_ON_ONCE and implicit cast of negative error code to unsigned int in pin_sca().
--
--- Patch [13]: [PATCH v4 13/20] KVM: s390: vsie: Add struct vsie_sca with pin and unpin methods ---
commit ba3e6e1a8cfd384294d05c97179c56428f5bc9cf
Author: Christoph Schlameuss <schlameuss@linux.ibm.com>
KVM: s390: vsie: Add struct vsie_sca with pin and unpin methods
Introduce the struct vsie_sca to hold the SSCA and required management
data along with alloc and free methods to use with the struct. On this
basis we can also add methods {,un}pin_sca() to simplify the pinning
SCAs in g1.
> diff --git a/arch/s390/kvm/vsie.c b/arch/s390/kvm/vsie.c
> index 442e7997ee51b..e632311222002 100644
> --- a/arch/s390/kvm/vsie.c
> +++ b/arch/s390/kvm/vsie.c
[ ... ]
> @@ -845,6 +872,74 @@ static int pin_scb(struct kvm_vcpu *vcpu, struct vsie_page *vsie_page)
> return 0;
> }
>
> +/*
> + * Unpin g2 original sca in g1 memory.
> + *
> + * Called with vsie_sca_lock held.
> + */
> +static void unpin_sca(struct kvm *kvm, struct vsie_sca *vsie_sca)
[ ... ]
> +/*
> + * Pin g2 original sca in g1 memory.
> + *
> + * Called with vsie_sca_lock held.
> + */
> +static int pin_sca(struct kvm *kvm, struct vsie_sca *vsie_sca)
> +{
> + bool is_esca = test_bit(VSIE_SCA_ESCA, &vsie_sca->flags);
> + gpa_t offset = vsie_sca->sca_gpa & ~PAGE_MASK;
> + int nr_pages;
> +
> + if (test_bit(VSIE_SCA_SCA_PINNED, &vsie_sca->flags))
> + return 0;
> +
> + if (is_esca) {
> + nr_pages = 4;
> + if (offset + sizeof(struct esca_block) > 4 * PAGE_SIZE)
> + nr_pages = 5;
> + } else {
> + nr_pages = 1;
> + if (offset + sizeof(struct bsca_block) > PAGE_SIZE)
> + nr_pages = 2;
> + }
> +
> + vsie_sca->sca_o_nr_pages = pin_guest_pages(kvm, vsie_sca->sca_gpa, nr_pages,
> + vsie_sca->sca_o_pages);
> + if (WARN_ON_ONCE(vsie_sca->sca_o_nr_pages != nr_pages))
> + return -EIO;
[Severity: High]
Can a malicious guest trigger this WARN_ON_ONCE?
If the guest provides an invalid or unmapped physical address for the SCA,
pin_guest_pages() can fail and return a negative error code (like -EINVAL).
Since vsie_sca->sca_o_nr_pages is declared as an unsigned int, the negative
error code is implicitly cast to a large unsigned value. This causes the
subsequent comparison vsie_sca->sca_o_nr_pages != nr_pages to evaluate to true,
triggering the WARN_ON_ONCE.
Because guest-reachable warnings can cause a host panic when panic_on_warn is
enabled, should this code gracefully handle the error code from
pin_guest_pages() and return it without warning?
> + __set_bit(VSIE_SCA_SCA_PINNED, &vsie_sca->flags);
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260812-vsie-sigpi-v4-0-f19e49666315@linux.ibm.com?part=13
next prev parent reply other threads:[~2026-08-12 15:44 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 13:52 [PATCH v4 00/20] KVM: s390: vsie: Add VSIE SIGP ECALL and SRSI Interpretation Christoph Schlameuss
2026-08-12 13:52 ` [PATCH v4 01/20] KVM: s390: vsie: Add SCAO read and write helpers Christoph Schlameuss
2026-08-12 13:58 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 02/20] KVM: s390: vsie: Move SCAO validation into a function Christoph Schlameuss
2026-08-12 15:13 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 03/20] KVM: s390: vsie: Add vsie_interp_extf detection Christoph Schlameuss
2026-08-12 13:58 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 04/20] KVM: s390: vsie: Add ssca_block and ssca_entry structs Christoph Schlameuss
2026-08-12 13:57 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 05/20] KVM: s390: vsie: Move pin/unpin_scb methods Christoph Schlameuss
2026-08-12 14:03 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 06/20] KVM: s390: vsie: Move pin/unpin guest page Christoph Schlameuss
2026-08-12 14:08 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 07/20] KVM: s390: vsie: Move release/acquire gmap shadow Christoph Schlameuss
2026-08-12 14:02 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 08/20] KVM: s390: vsie: Create helpers to alloc and free vsie_pages Christoph Schlameuss
2026-08-12 14:04 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 09/20] KVM: s390: vsie: Replace radix_tree with xarray addr_to_page Christoph Schlameuss
2026-08-12 14:03 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 10/20] KVM: s390: vsie: Add helper to release gmap shadow Christoph Schlameuss
2026-08-12 14:04 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 11/20] KVM: s390: vsie: Lazily keep original scb pinned after vsie exit Christoph Schlameuss
2026-08-12 15:28 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 12/20] KVM: s390: vsie: Add helper to pin and unpin multiple guest pages Christoph Schlameuss
2026-08-12 14:11 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 13/20] KVM: s390: vsie: Add struct vsie_sca with pin and unpin methods Christoph Schlameuss
2026-08-12 15:43 ` sashiko-bot [this message]
2026-08-12 13:52 ` [PATCH v4 14/20] KVM: s390: vsie: Shadow VSIE SCA in guest-1 Christoph Schlameuss
2026-08-12 16:10 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 15/20] KVM: s390: vsie: Guard against invalid CPU address Christoph Schlameuss
2026-08-12 16:23 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 16/20] KVM: s390: vsie: Allow guest-3 cpu add and remove with ssca Christoph Schlameuss
2026-08-12 16:40 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 17/20] KVM: s390: vsie: Add VSIE max shadow configuration Christoph Schlameuss
2026-08-12 16:53 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 18/20] KVM: s390: vsie: Add VSIE shadow stat counters Christoph Schlameuss
2026-08-12 17:02 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 19/20] KVM: s390: vsie: Create minimal scb shadows for not running g3 blocks Christoph Schlameuss
2026-08-12 17:26 ` sashiko-bot
2026-08-12 13:52 ` [PATCH v4 20/20] KVM: s390: vsie: Enable use of VSIE SSCA Christoph Schlameuss
2026-08-12 17:45 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260812154359.C5F501F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.vom \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=kvm@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=schlameuss@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.