From: sashiko-bot@kernel.org
To: "Rick Edgecombe" <rick.p.edgecombe@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v10 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put()
Date: Thu, 03 Sep 2026 02:03:02 +0000 [thread overview]
Message-ID: <20260903020303.349961F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903015113.93343-6-rick.p.edgecombe@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] tdx_find_dpamt_refcount() uses an unchecked PFN to index the dpamt_refcounts array, leading to out-of-bounds memory access.
--
commit 413476a1747fac53ffdaf87030c42cb8b25bc668
Author: Rick Edgecombe <rick.p.edgecombe@intel.com>
x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put()
This patch refcounts the dynamic PAMT additions for 2MB regions so multiple
callers can safely share them. It also drops the "__" prefix from the
helpers and exports them for use by KVM.
> diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
> index e8bdeacd989d6..a126e395f5f6a 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.c
> +++ b/arch/x86/virt/vmx/tdx/tdx.c
> @@ -292,7 +292,7 @@ static __init void free_dpamt_refcounts(void)
> dpamt_refcounts = NULL;
> }
>
> -static __maybe_unused atomic_t *tdx_find_dpamt_refcount(unsigned long pfn)
> +static atomic_t *tdx_find_dpamt_refcount(unsigned long pfn)
> {
> /* Find which PMD a PFN is in. */
> unsigned long index = pfn >> (PMD_SHIFT - PAGE_SHIFT);
>
> return &dpamt_refcounts[index];
[Severity: High]
Does this index calculation need bounds checking?
If memory is hotplugged after boot, increasing the global max_pfn, and KVM
allocates private guest memory that lands in this hotplugged region (e.g.,
via guest_memfd), the returned PFN could be greater than the boot-time
max_pfn used to size the dpamt_refcounts array. This would lead to an
out-of-bounds pointer being returned here.
[ ... ]
> @@ -2150,41 +2144,59 @@ static int __tdx_pamt_get(kvm_pfn_t pfn)
[ ... ]
> out_free:
> + spin_unlock(&dpamt_lock);
> free_pamt_array(pamt_pages);
>
> return ret;
> }
> +EXPORT_SYMBOL_FOR_KVM(tdx_pamt_get);
[Severity: High]
Is it safe to export this function without adding bounds checking to
tdx_find_dpamt_refcount()?
Exporting this helper allows external callers like KVM to pass in arbitrary
or hotplugged PFNs. If a hotplugged PFN is passed, the resulting
out-of-bounds pointer from tdx_find_dpamt_refcount() will be modified by
atomic_inc_not_zero() and atomic_set() within this function, potentially
causing memory corruption or a host kernel panic.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260903015113.93343-1-rick.p.edgecombe@intel.com?part=5
next prev parent reply other threads:[~2026-09-03 2:03 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 1:51 [PATCH v10 00/11] Dynamic PAMT Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 01/11] x86/virt/tdx: Simplify PAMT layout calculation Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 03/11] x86/virt/tdx: Add __tdx_pamt_get/put() helpers Rick Edgecombe
2026-09-03 15:28 ` Dave Hansen
2026-09-03 1:51 ` [PATCH v10 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory Rick Edgecombe
2026-09-03 15:30 ` Dave Hansen
2026-09-03 18:33 ` Edgecombe, Rick P
2026-09-03 1:51 ` [PATCH v10 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put() Rick Edgecombe
2026-09-03 2:03 ` sashiko-bot [this message]
2026-09-03 23:16 ` Edgecombe, Rick P
2026-09-03 1:51 ` [PATCH v10 06/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 07/11] x86/virt/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-09-03 1:51 ` [PATCH v10 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
2026-09-03 2:14 ` sashiko-bot
2026-09-03 22:44 ` Edgecombe, Rick P
2026-09-03 1:51 ` [PATCH v10 09/11] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
2026-09-03 15:38 ` Dave Hansen
2026-09-03 1:51 ` [PATCH v10 10/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-09-03 15:47 ` Dave Hansen
2026-09-03 19:31 ` Edgecombe, Rick P
2026-09-03 19:36 ` Dave Hansen
2026-09-03 20:39 ` Edgecombe, Rick P
2026-09-03 20:45 ` Dave Hansen
2026-09-03 1:51 ` [PATCH v10 11/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903020303.349961F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=rick.p.edgecombe@intel.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.