From: sashiko-bot@kernel.org
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: linux-s390@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH 13/13] s390/scm: Use kmalloc() for SCM information
Date: Mon, 07 Sep 2026 10:44:37 +0000 [thread overview]
Message-ID: <20260907104439.163361F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260907-s390-cio-ready-v1-13-ca7f39806234@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Replacing `__get_free_page()` with `kmalloc(PAGE_SIZE)` breaks the strict 4K page-alignment requirement of the CHSC instruction when SLUB debugging is enabled.
--
commit ad79881d62e47e7d8ac373d9ac1ace6a762ae9a4
Author: Mike Rapoport (Microsoft) <rppt@kernel.org>
s390/scm: Use kmalloc() for SCM information
This commit replaces the allocation of the CHSC Store SCM Information command
response buffer from __get_free_page() to kmalloc(). It also updates the
local response buffer to use the __free(kfree) scope-based cleanup helper.
Link: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com
> diff --git a/drivers/s390/cio/scm.c b/drivers/s390/cio/scm.c
> index 171212a6d2d9c..b79fe023ab8d1 100644
> --- a/drivers/s390/cio/scm.c
> +++ b/drivers/s390/cio/scm.c
[ ... ]
> @@ -224,12 +225,12 @@ static int scm_add(struct chsc_scm_info *scm_info, size_t num)
>
> int scm_update_information(void)
> {
> - struct chsc_scm_info *scm_info;
> + struct chsc_scm_info *scm_info __free(kfree) = NULL;
> u64 token = 0;
> size_t num;
> int ret;
>
> - scm_info = (void *)__get_free_page(GFP_KERNEL | GFP_DMA);
> + scm_info = kmalloc(PAGE_SIZE, GFP_KERNEL | GFP_DMA);
[Severity: High]
Does this change break the 4K page-alignment requirement for the CHSC
instruction?
In drivers/s390/cio/scm.c:scm_update_information(), replacing the natively
page-aligned __get_free_page() with kmalloc(PAGE_SIZE) means the returned
pointer can be unaligned when SLUB debugging or KASAN is enabled, due to
padding added before the object.
This scm_info pointer is passed down and ultimately used by the CHSC
instruction in drivers/s390/cio/ioasm.c:chsc(). The s390 architecture
strictly mandates that CHSC command blocks be placed on a 4K-byte boundary.
Executing the instruction with an unaligned address triggers a hardware
Specification Exception kernel crash.
> if (!scm_info)
> return -ENOMEM;
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260907-s390-cio-ready-v1-0-ca7f39806234@kernel.org?part=13
prev parent reply other threads:[~2026-09-07 10:44 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 10:23 [PATCH 00/13] s390/cio: replace page allocator calls with k[mz]alloc() Mike Rapoport (Microsoft)
2026-09-07 10:23 ` [PATCH 01/13] s390/chsc: Use kzalloc() for CUBs Mike Rapoport (Microsoft)
2026-09-07 10:37 ` sashiko-bot
2026-09-07 10:56 ` Mike Rapoport
2026-09-07 10:23 ` [PATCH 02/13] s390/chsc: Use kzalloc() for the SEI work area Mike Rapoport (Microsoft)
2026-09-07 10:34 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 03/13] s390/chsc_sch: Use kzalloc() for CHSC requests Mike Rapoport (Microsoft)
2026-09-07 10:39 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 04/13] s390/chsc_sch: Use __free(kfree) for synchronous " Mike Rapoport (Microsoft)
2026-09-07 10:30 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 05/13] s390/cio: Use kzalloc() for CHSC work areas Mike Rapoport (Microsoft)
2026-09-07 10:37 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 06/13] s390/cmf: Use kmalloc() for the CMB area Mike Rapoport (Microsoft)
2026-09-07 10:35 ` sashiko-bot
2026-09-07 10:59 ` Mike Rapoport
2026-09-07 10:23 ` [PATCH 07/13] s390/idals: Use kmalloc() for IDAL data buffers Mike Rapoport (Microsoft)
2026-09-07 10:38 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 08/13] s390/qdio_main: Use kzalloc() for the IRQ structure Mike Rapoport (Microsoft)
2026-09-07 10:38 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 09/13] s390/qdio_main: Use kzalloc() for the QDR Mike Rapoport (Microsoft)
2026-09-07 10:33 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 10/13] s390/qdio_setup: Use kzalloc() for QDIO buffers Mike Rapoport (Microsoft)
2026-09-07 10:36 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 11/13] s390/qdio_setup: Use kzalloc() for the storage list Mike Rapoport (Microsoft)
2026-09-07 10:42 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 12/13] s390/qdio_setup: Use kzalloc() for the SSQD request Mike Rapoport (Microsoft)
2026-09-07 10:43 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 13/13] s390/scm: Use kmalloc() for SCM information Mike Rapoport (Microsoft)
2026-09-07 10:44 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907104439.163361F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=rppt@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.