All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Claudio Imbrenda" <imbrenda@linux.ibm.com>
Cc: "Alexander Gordeev" <agordeev@linux.ibm.com>,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	"Heiko Carstens" <hca@linux.ibm.com>,
	linux-s390@vger.kernel.org, kvm@vger.kernel.org,
	"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH v1 5/6] KVM: s390: Add missing srcu in kvm_arch_vcpu_ioctl()
Date: Fri, 14 Aug 2026 14:52:03 +0000	[thread overview]
Message-ID: <20260814145204.0B3251F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260814144041.169025-6-imbrenda@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Circular deadlock between KVM SRCU lock and userfaultfd during copy_from_user().
--

--- Patch [5]: [PATCH v1 5/6] KVM: s390: Add missing srcu in kvm_arch_vcpu_ioctl() ---
commit 4558246eff181af6ab8735d60c453a1298252bfe
Author: Claudio Imbrenda <imbrenda@linux.ibm.com>

KVM: s390: Add missing srcu in kvm_arch_vcpu_ioctl()

This commit adds an SRCU read lock around kvm_s390_set_irq_state()
in kvm_arch_vcpu_ioctl().

> diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
> index 50eb72447fd53..7fb5a566e2d85 100644
> --- a/arch/s390/kvm/kvm-s390.c
> +++ b/arch/s390/kvm/kvm-s390.c
> @@ -5697,9 +5697,10 @@ long kvm_arch_vcpu_ioctl(struct file *filp,
>  			break;
>  		}
>  		/* do not use irq_state.flags, it will break old QEMUs */
> -		r = kvm_s390_set_irq_state(vcpu,
> -					   (void __user *) irq_state.buf,
> -					   irq_state.len);
> +		scoped_guard(srcu, &vcpu->kvm->srcu) {
> +			r = kvm_s390_set_irq_state(vcpu, (void __user *)irq_state.buf,
> +						   irq_state.len);
> +		}

[Severity: High]
Does this scoped_guard result in calling copy_from_user() while holding
the SRCU read lock?

Looking at kvm_s390_set_irq_state() in arch/s390/kvm/interrupt.c, it
performs a user copy:

int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len)
{
	...
	buf = vmalloc(len);
	if (!buf)
		return -ENOMEM;

	if (copy_from_user((void *)buf, irqstate, len))
		return -EFAULT;
	...
}

If userspace passes a userfaultfd-managed region as the irq state buffer,
copy_from_user() can block and wait for the userfaultfd manager.

If that manager then attempts an operation that updates KVM memslots
(such as KVM_SET_USER_MEMORY_REGION), it will acquire the slots lock
and wait on synchronize_srcu().

Could this cause a circular deadlock between the SRCU read lock held
here and the slots lock acquired by the userfaultfd manager?

>  		break;
>  	}
>  	case KVM_S390_GET_IRQ_STATE: {

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260814144041.169025-1-imbrenda@linux.ibm.com?part=5

  reply	other threads:[~2026-08-14 14:52 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-14 14:40 [PATCH v1 0/6] KVM: s390: Even more misc fixes Claudio Imbrenda
2026-08-14 14:40 ` [PATCH v1 1/6] KVM: s390: Fix dirty marking in adapter_indicators_set*() Claudio Imbrenda
2026-08-14 14:49   ` sashiko-bot
2026-08-14 14:40 ` [PATCH v1 2/6] KVM: s390: Fix _gaccess_shadow_fault() Claudio Imbrenda
2026-08-14 15:04   ` sashiko-bot
2026-08-14 14:40 ` [PATCH v1 3/6] KVM: s390: Refactor dat_set_slot() Claudio Imbrenda
2026-08-14 14:54   ` sashiko-bot
2026-08-14 14:40 ` [PATCH v1 4/6] KVM: s390: Move all code into kvm_arch_prepare_memory_region() Claudio Imbrenda
2026-08-14 14:50   ` sashiko-bot
2026-08-14 14:40 ` [PATCH v1 5/6] KVM: s390: Add missing srcu in kvm_arch_vcpu_ioctl() Claudio Imbrenda
2026-08-14 14:52   ` sashiko-bot [this message]
2026-08-14 14:40 ` [PATCH v1 6/6] KVM: s390: Fix potential race in dat_cond_set_storage_key() Claudio Imbrenda
2026-08-14 15:05   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260814145204.0B3251F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.