All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yeoreum Yun" <yeoreum.yun@arm.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH RFC v3 09/21] loongarch: kvm: remove stack copy address of pXd in pXd_offset()
Date: Wed, 02 Sep 2026 12:19:12 +0000	[thread overview]
Message-ID: <20260902121912.CF9161F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260902-dummy_ptxp3-v3-9-5d8f5b17c25c@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Missing `pud_leaf()` / huge page check before traversing to PMD level, causing invalid memory dereference on 1GB huge pages.
--

commit 7df2ea4ead6f791e1840ca23d67765ca06e93e1b
Author: Yeoreum Yun <yeoreum.yun@arm.com>

loongarch: kvm: remove stack copy address of pXd in pXd_offset()

This commit refactors host_pfn_mapping_level() to prepare for generic
compile-time folded page tables. It replaces direct uses of stack-based pXd
values with pXd_offset_lockless(), passing the pointers directly.

> diff --git a/arch/loongarch/kvm/mmu.c b/arch/loongarch/kvm/mmu.c
> index e104897aa5328..837b40bb694f4 100644
> --- a/arch/loongarch/kvm/mmu.c
> +++ b/arch/loongarch/kvm/mmu.c
[ ... ]
> @@ -698,19 +698,23 @@ static int host_pfn_mapping_level(struct kvm *kvm, gfn_t gfn,
[ ... ]
> -	pud = pudp_get(pud_offset(&p4d, hva));
> +	pudp = pud_offset_lockless(p4dp, p4d, hva);
> +	pud = pudp_get(pudp);
>  	if (pud_none(pud) || !pud_present(pud))
>  		goto out;
>  
> -	pmd = pmdp_get(pmd_offset(&pud, hva));
> +	pmdp = pmd_offset_lockless(pudp, pud, hva);
> +	pmd = pmdp_get(pmdp);

[Severity: High]
This is a pre-existing issue, but does this code need a check to see if the
PUD is a leaf entry before stepping down to the PMD level?

In arch/loongarch/kvm/mmu.c:host_pfn_mapping_level(), the code reads the PUD
entry and verifies that it is present, but it does not check if it is a 1GB
huge page leaf entry before traversing to the PMD level.

If a guest memory region is backed by a 1GB huge page on the host, the PUD
entry will contain a PFN-encoded value and metadata flags. By unconditionally
passing this to pmd_offset_lockless(), the macro may interpret the PFN encoded
value as a kernel virtual address directory pointer. This produces a bogus
pointer that pmdp_get() will then dereference, causing an invalid memory
dereference and potentially crashing the host.

Could a pud_leaf() or kvm_pte_huge(pud_val(pud)) check be added before the
pmd_offset_lockless() call to prevent this crash when 1GB huge pages are
used?

>  	if (pmd_none(pmd) || !pmd_present(pmd))
>  		goto out;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260902-dummy_ptxp3-v3-0-5d8f5b17c25c@arm.com?part=9

  reply	other threads:[~2026-09-02 12:19 UTC|newest]

Thread overview: 107+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 11:56 [PATCH RFC v3 00/21] mm: change behavior of pXdp_get()/pXd_page() in compile-time folded pgtable Yeoreum Yun
2026-09-02 11:56 ` Yeoreum Yun
2026-09-02 11:56 ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 01/21] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 02/21] ARM: mm: make 2-level " Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 03/21] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 04/21] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 05/21] MIPS: " Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 06/21] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 12:15   ` sashiko-bot
2026-09-02 11:56 ` [PATCH RFC v3 07/21] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 08/21] mm: vmscan: remove stack copy address of pud/pmd pass in walk_pud/pmd_range() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 09/21] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 12:19   ` sashiko-bot [this message]
2026-09-02 12:38     ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 10/21] riscv: " Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 11/21] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 12/21] mm/pgtable: redefine PGTABLE_LEVEL enum with ascend order from PGD Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-10 11:05   ` David Hildenbrand (Arm)
2026-09-10 11:05     ` David Hildenbrand (Arm)
2026-09-10 11:05     ` David Hildenbrand (Arm)
2026-09-02 11:56 ` [PATCH RFC v3 13/21] x86: mm: use pgtable_level enum in effective_prot_pXd() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 20:48   ` Dave Hansen
2026-09-02 20:48     ` Dave Hansen
2026-09-02 20:48     ` Dave Hansen
2026-09-07  8:06     ` Yeoreum Yun
2026-09-07  8:06       ` Yeoreum Yun
2026-09-07  8:06       ` Yeoreum Yun
2026-09-10 11:02     ` David Hildenbrand (Arm)
2026-09-10 11:02       ` David Hildenbrand (Arm)
2026-09-10 11:02       ` David Hildenbrand (Arm)
2026-09-10 15:29       ` Dave Hansen
2026-09-10 15:29         ` Dave Hansen
2026-09-10 15:29         ` Dave Hansen
2026-09-10 11:03   ` David Hildenbrand (Arm)
2026-09-10 11:03     ` David Hildenbrand (Arm)
2026-09-10 11:03     ` David Hildenbrand (Arm)
2026-09-02 11:56 ` [PATCH RFC v3 14/21] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 20:46   ` Dave Hansen
2026-09-02 20:46     ` Dave Hansen
2026-09-02 20:46     ` Dave Hansen
2026-09-10 11:06   ` David Hildenbrand (Arm)
2026-09-10 11:06     ` David Hildenbrand (Arm)
2026-09-10 11:06     ` David Hildenbrand (Arm)
2026-09-02 11:56 ` [PATCH RFC v3 15/21] x86: mm: skip collapse_pud_page() when CONFIG_X86_DIRECT_GBPAGES disabled Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 12:17   ` sashiko-bot
2026-09-02 12:29     ` Yeoreum Yun
2026-09-02 15:38   ` Dave Hansen
2026-09-02 15:38     ` Dave Hansen
2026-09-02 15:38     ` Dave Hansen
2026-09-02 16:48     ` Yeoreum Yun
2026-09-02 16:48       ` Yeoreum Yun
2026-09-02 16:48       ` Yeoreum Yun
2026-09-10 11:07   ` David Hildenbrand (Arm)
2026-09-10 11:07     ` David Hildenbrand (Arm)
2026-09-10 11:07     ` David Hildenbrand (Arm)
2026-09-02 11:56 ` [PATCH RFC v3 16/21] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 17/21] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 18/21] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 19/21] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 20/21] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 21/21] Documentation: mm: clarify behaviour of compile-time folded page tables Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-02 11:56   ` Yeoreum Yun
2026-09-10 11:12 ` [PATCH RFC v3 00/21] mm: change behavior of pXdp_get()/pXd_page() in compile-time folded pgtable David Hildenbrand (Arm)
2026-09-10 11:12   ` David Hildenbrand (Arm)
2026-09-10 11:12   ` David Hildenbrand (Arm)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260902121912.CF9161F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yeoreum.yun@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.