All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jörg Rödel" <joro@8bytes.org>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v2 4/8] KVM: SEV: Add direct VMSA capability
Date: Tue, 08 Sep 2026 10:53:19 +0000	[thread overview]
Message-ID: <20260908105319.AA0651F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908103338.427254-5-joro@8bytes.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] Using `guard(mutex)` inside a `switch` case without enclosing braces causes a compile-time error and bypasses variable initialization.
--

commit 14ba20ca988537a92ef023f074770d517f738803
Author: Joerg Roedel <joerg.roedel@amd.com>

KVM: SEV: Add direct VMSA capability

This commit introduces the KVM_CAP_SNP_DIRECT_VMSA capability, allowing
userspace to manage VMSA pages directly for SNP VMs. When enabled, it skips
KVM-owned VMSA allocation during vCPU creation and measurement at launch.

> diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
> index 7d59d301e1e54..98c5cffe2c227 100644
> --- a/arch/x86/kvm/svm/svm.c
> +++ b/arch/x86/kvm/svm/svm.c
[ ... ]
> +static int svm_enable_vm_cap(struct kvm *kvm, struct kvm_enable_cap *cap)
> +{
> +	switch (cap->cap) {
> +#ifdef CONFIG_KVM_AMD_SEV
> +	case KVM_CAP_SNP_DIRECT_VMSA:
> +		if (memchr_inv(cap->args, 0, sizeof(cap->args)) ||
> +		    kvm->arch.vm_type != KVM_X86_SNP_VM)
> +			return -EINVAL;
> +
> +		guard(mutex)(&kvm->lock);

[Severity: Low]
Does this code cause a build failure? Using guard(mutex) inside a switch case
without enclosing braces declares a variable in the wider scope of the switch
block.

> +		if (kvm->created_vcpus)
> +			return -EINVAL;
> +
> +		to_kvm_sev_info(kvm)->snp_direct_vmsa = true;
> +		return 0;
> +#endif
> +	default:
> +		return -EINVAL;

If execution jumps to this default label, it bypasses the initialization of
the cleanup variable declared by the guard in the case above. The cleanup
function will then attempt to run on an uninitialized pointer upon return.

Could the KVM_CAP_SNP_DIRECT_VMSA case be enclosed in curly braces to limit
the scope of the guard?

> +	}
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908103338.427254-1-joro@8bytes.org?part=4

  reply	other threads:[~2026-09-08 10:53 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 10:33 [PATCH v2 0/8] KVM: SVM: Support direct setting of VMSA for SEV-SNP guests Jörg Rödel
2026-09-08 10:33 ` [PATCH v2 1/8] KVM: SEV: Document SNP direct VMSA userspace ABI Jörg Rödel
2026-09-08 10:33 ` [PATCH v2 2/8] KVM: SVM: Implement GET_AP_APIC_IDS NAE event Jörg Rödel
2026-09-08 10:51   ` sashiko-bot
2026-09-08 10:33 ` [PATCH v2 3/8] KVM: SVM: Hold SRCU while reloading guest-owned VMSAs Jörg Rödel
2026-09-08 10:33 ` [PATCH v2 4/8] KVM: SEV: Add direct VMSA capability Jörg Rödel
2026-09-08 10:53   ` sashiko-bot [this message]
2026-09-08 10:33 ` [PATCH v2 5/8] KVM: SEV: Allow VMSA pages in SNP launch updates Jörg Rödel
2026-09-08 10:33 ` [PATCH v2 6/8] KVM: SEV: Add SNP vCPU state get and set commands Jörg Rödel
2026-09-08 10:49   ` sashiko-bot
2026-09-08 10:33 ` [PATCH v2 7/8] KVM: selftests: Test the SNP APIC-ID-list GHCB request Jörg Rödel
2026-09-08 10:33 ` [PATCH v2 8/8] KVM: selftests: Test SNP vCPU state and direct VMSA launch Jörg Rödel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908105319.AA0651F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=joro@8bytes.org \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.