From: Tao Cui <cui.tao@linux.dev>
To: maobibo@loongson.cn
Cc: zhaotianrui@loongson.cn, chenhuacai@kernel.org,
kvm@vger.kernel.org, loongarch@lists.linux.dev,
linux-kernel@vger.kernel.org, cui.tao@linux.dev,
Tao Cui <cuitao@kylinos.cn>
Subject: [PATCH v2] LoongArch: KVM: Fix TOCTOU race on pv_features
Date: Fri, 14 Aug 2026 07:25:42 +0800 [thread overview]
Message-ID: <20260813232542.2098930-1-cui.tao@linux.dev> (raw)
From: Tao Cui <cuitao@kylinos.cn>
The check-then-set on kvm->arch.pv_features in
kvm_loongarch_cpucfg_set_attr() is lockless, so two vCPUs can race
past the validation and set different values. Add a spinlock to
serialize it.
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
---
Changes in v2: use a spinlock instead of a cmpxchg loop (Bibo Mao).
Link: https://lore.kernel.org/all/20260810081321.157258-1-cui.tao@linux.dev/
arch/loongarch/include/asm/kvm_host.h | 2 ++
arch/loongarch/kvm/vcpu.c | 6 +++++-
arch/loongarch/kvm/vm.c | 1 +
3 files changed, 8 insertions(+), 1 deletion(-)
diff --git a/arch/loongarch/include/asm/kvm_host.h b/arch/loongarch/include/asm/kvm_host.h
index 23cfbecebbd7..cdbbd90e0584 100644
--- a/arch/loongarch/include/asm/kvm_host.h
+++ b/arch/loongarch/include/asm/kvm_host.h
@@ -128,6 +128,8 @@ struct kvm_arch {
struct kvm_phyid_map *phyid_map;
/* Enabled PV features */
unsigned long pv_features;
+ /* Serializes pv_features updates */
+ spinlock_t pv_features_lock;
/* Supported KVM features */
unsigned long kvm_features;
diff --git a/arch/loongarch/kvm/vcpu.c b/arch/loongarch/kvm/vcpu.c
index 20c207d80e31..551ed39b2d1f 100644
--- a/arch/loongarch/kvm/vcpu.c
+++ b/arch/loongarch/kvm/vcpu.c
@@ -1165,10 +1165,14 @@ static int kvm_loongarch_cpucfg_set_attr(struct kvm_vcpu *vcpu,
return -EINVAL;
/* All vCPUs need set the same PV features */
+ spin_lock(&kvm->arch.pv_features_lock);
if ((kvm->arch.pv_features & LOONGARCH_PV_FEAT_UPDATED)
- && ((kvm->arch.pv_features & valid) != val))
+ && ((kvm->arch.pv_features & valid) != val)) {
+ spin_unlock(&kvm->arch.pv_features_lock);
return -EINVAL;
+ }
kvm->arch.pv_features = val | LOONGARCH_PV_FEAT_UPDATED;
+ spin_unlock(&kvm->arch.pv_features_lock);
return 0;
default:
return -ENXIO;
diff --git a/arch/loongarch/kvm/vm.c b/arch/loongarch/kvm/vm.c
index 1317c718f896..b984cc54f305 100644
--- a/arch/loongarch/kvm/vm.c
+++ b/arch/loongarch/kvm/vm.c
@@ -76,6 +76,7 @@ int kvm_arch_init_vm(struct kvm *kvm, unsigned long type)
return -ENOMEM;
}
spin_lock_init(&kvm->arch.phyid_map_lock);
+ spin_lock_init(&kvm->arch.pv_features_lock);
kvm_init_vmcs(kvm);
kvm_vm_init_features(kvm);
--
2.43.0
next reply other threads:[~2026-08-13 23:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 23:25 Tao Cui [this message]
2026-08-14 1:08 ` [PATCH v2] LoongArch: KVM: Fix TOCTOU race on pv_features Bibo Mao
2026-08-14 8:24 ` Huacai Chen
2026-08-14 9:28 ` Tao Cui
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260813232542.2098930-1-cui.tao@linux.dev \
--to=cui.tao@linux.dev \
--cc=chenhuacai@kernel.org \
--cc=cuitao@kylinos.cn \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=loongarch@lists.linux.dev \
--cc=maobibo@loongson.cn \
--cc=zhaotianrui@loongson.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.