All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mukesh R" <mrathor@linux.microsoft.com>
Cc: linux-hyperv@vger.kernel.org
Subject: Re: [PATCH V1 2/3] mshv: Import data structs around device domains from hyperv headers
Date: Thu, 24 Sep 2026 02:13:32 +0000	[thread overview]
Message-ID: <20260924021332.B1E2A1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924020221.128762-3-mrathor@linux.microsoft.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mshv: incorrect bitfield layout for union hv_device_domain_id corrupts hypercall ABI
--

commit a37c5c0ca47021bec11c9aa7d2a0eb2626dc10ce
Author: Mukesh R <mrathor@linux.microsoft.com>

mshv: Import data structs around device domains from hyperv headers

Copy/import from Hyper-V public headers, definitions and declarations that
are related to creating iommu domains in the hypervisor, attaching devices
to them, doing the reverse, etc.

> diff --git a/include/hyperv/hvhdk_mini.h b/include/hyperv/hvhdk_mini.h
> index 035ba20870f73..3dbfb338bcba1 100644
> --- a/include/hyperv/hvhdk_mini.h
> +++ b/include/hyperv/hvhdk_mini.h

[ ... ]

> +#define HV_DEVICE_DOMAIN_ID_S2_NULL    0xFFFFFFFFULL
> +
> +union hv_device_domain_id {
> +	u64 as_uint64;
> +	struct {
> +		u32 type : 4;
> +		u32 reserved : 28;
> +		u32 id;
> +	};
> +} __packed;

[Severity: High]
Does this struct incorrectly define type and reserved before id, placing id in
the upper 32 bits of the 64-bit union instead of the lower 32 bits?

The imported constant HV_DEVICE_DOMAIN_ID_S2_NULL is defined as 0xFFFFFFFFULL,
which has 0xFFFFFFFF in the lower 32 bits and 0 in the upper 32 bits. This
indicates the hypervisor expects the 32-bit id field to be in the lower 32
bits (LSB) and the type to be in the upper 32 bits.

Because C bitfields in little-endian architectures populate the lowest bits
first, defining type and reserved before id places the type field in the
lower 32 bits and the id field in the upper 32 bits.

Could this layout mismatch cause hypercalls to create or attach device domains
to send a corrupted 64-bit domain ID? If the hypervisor misinterprets the
domain type and ID, this would lead to hypercall failures and break IOMMU
isolation for devices when the driver populates domain_id.type and
domain_id.id.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924020221.128762-1-mrathor@linux.microsoft.com?part=2

  reply	other threads:[~2026-09-24  2:13 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  2:02 [PATCH V1 0/3] Hyper-V: root VM iommu kernel only driver Mukesh R
2026-09-24  2:02 ` [PATCH V1 1/3] PCI: hv: Export hv_build_devid_type_pci() and change return type Mukesh R
2026-09-24  2:02 ` [PATCH V1 2/3] mshv: Import data structs around device domains from hyperv headers Mukesh R
2026-09-24  2:13   ` sashiko-bot [this message]
2026-09-24 17:48   ` Easwar Hariharan
2026-09-24  2:02 ` [PATCH V1 3/3] x86/hyperv: Implement root VM IOMMU kernel only driver Mukesh R
2026-09-24  2:16   ` sashiko-bot
2026-09-24 13:35   ` Jörg Rödel
2026-09-25  0:14     ` Mukesh R
2026-09-25  7:13       ` Jörg Rödel
2026-09-28 22:33         ` Mukesh R
2026-09-28 13:38   ` Jason Gunthorpe
2026-09-28 16:35     ` Easwar Hariharan
2026-09-28 23:33     ` Mukesh R
2026-09-28 23:36       ` Jason Gunthorpe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924021332.B1E2A1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-hyperv@vger.kernel.org \
    --cc=mrathor@linux.microsoft.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.