All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Lisa Wang" <wyihan@google.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v15 03/23] KVM: selftests: Initialize the TDX VM
Date: Fri, 02 Oct 2026 09:13:30 +0000	[thread overview]
Message-ID: <20261002091331.1148B1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001-tdx-selftests-v15-3-7c62a5d8a992@google.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] selftests/kvm: uninitialized padding causes KVM_TDX_INIT_VM failure
- [Medium] selftests/kvm: data race on static tdx_cap in tdx_read_capabilities()
--

commit 3680cc9e7726e14977411713d50e23fbb8635ddc
Author: Sagi Shahar <sagis@google.com>

KVM: selftests: Initialize the TDX VM

Add tdx_init_vm() to handle the mandatory VM-level initialization
sequence required for Intel TDX. For TDX, the VM's CPUID configuration
must be "sealed" during KVM_TDX_INIT_VM before any vCPUs are created.
This commit masks the host-supported CPUID against the configurable
bits reported by KVM_TDX_CAPABILITIES.

> diff --git a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
> new file mode 100644
> index 0000000000000..3a8900ff25404
> --- /dev/null
> +++ b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
> @@ -0,0 +1,121 @@
> +// SPDX-License-Identifier: GPL-2.0-only
> +
> +#include "processor.h"
> +#include "tdx/tdx_util.h"
> +
> +static const struct kvm_tdx_capabilities *tdx_read_capabilities(struct kvm_vm *vm)
> +{
> +	static struct kvm_tdx_capabilities *tdx_cap;
> +	int nr_cpuid_configs = 4;
> +	int rc = -1;
> +	int i;
> +
> +	if (tdx_cap)
> +		return tdx_cap;
> +
> +	do {
> +		nr_cpuid_configs *= 2;
> +
> +		tdx_cap = realloc(tdx_cap, sizeof(*tdx_cap) +
> +					   (sizeof(struct kvm_cpuid_entry2) * nr_cpuid_configs));

[Severity: Medium]
Could this realloc() cause a data race if multiple threads attempt to
create TDX VMs concurrently?

If tdx_read_capabilities() checks and reallocates the static pointer
tdx_cap without locking, concurrent calls might race on the realloc(),
potentially leading to memory corruption, a double free, or a
use-after-free during test execution.

[ ... ]
> +void tdx_init_vm(struct kvm_vm *vm)
> +{
> +	struct kvm_tdx_init_vm *init_vm;
> +	const struct kvm_cpuid2 *tmp;
> +	struct kvm_cpuid2 *cpuid;
> +
> +	tmp = kvm_get_supported_cpuid();
> +
> +	cpuid = allocate_kvm_cpuid2(tmp->nent);
> +	memcpy(cpuid, tmp, kvm_cpuid2_size(tmp->nent));
> +	tdx_filter_cpuid(vm, cpuid);
> +
> +	init_vm = calloc(1, sizeof(*init_vm) +
> +			 sizeof(init_vm->cpuid.entries[0]) * cpuid->nent);
> +	TEST_ASSERT(init_vm, "init_vm allocation failed");
> +
> +	memcpy(&init_vm->cpuid, cpuid, kvm_cpuid2_size(cpuid->nent));

[Severity: Medium]
Does this memcpy() copy uninitialized padding into the ioctl payload?

Since allocate_kvm_cpuid2() allocates struct kvm_cpuid2 using malloc(),
the padding field can be left uninitialized. The kernel's
KVM_GET_SUPPORTED_CPUID ioctl does not clear this padding, and it is
subsequently copied into init_vm->cpuid here.

Because the KVM_TDX_INIT_VM ioctl strictly validates that cpuid.padding
is zero, could this cause KVM_TDX_INIT_VM to fail with -EINVAL if the
padding contains garbage?

> +	free(cpuid);
> +
> +	init_vm->attributes = 0;
> +	init_vm->xfam = 0;
> +
> +	tdx_vm_ioctl(vm, KVM_TDX_INIT_VM, 0, init_vm);
> +
> +	free(init_vm);
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-tdx-selftests-v15-0-7c62a5d8a992@google.com?part=3

  reply	other threads:[~2026-10-02  9:13 UTC|newest]

Thread overview: 59+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 19:37 [PATCH v15 00/23] TDX KVM selftests Lisa Wang
2026-10-01 19:37 ` [PATCH v15 01/23] KVM: selftests: Add macros to simplify creating VM shapes for non-default types Lisa Wang
2026-10-01 19:37 ` [PATCH v15 02/23] KVM: selftests: Update kvm_init_vm_address_properties() for TDX Lisa Wang
2026-10-01 19:37 ` [PATCH v15 03/23] KVM: selftests: Initialize the TDX VM Lisa Wang
2026-10-02  9:13   ` sashiko-bot [this message]
2026-10-05 21:26     ` Lisa Wang
2026-10-09  6:00   ` Xiaoyao Li
2026-10-10  2:05   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 04/23] KVM: selftests: Expose segment definitions to assembly files Lisa Wang
2026-10-01 19:37 ` [PATCH v15 05/23] tools: include: Add kbuild.h for assembly structure offsets Lisa Wang
2026-10-09  6:10   ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 06/23] KVM: selftests: Introduce structures for TDX guest boot parameters Lisa Wang
2026-10-09  6:13   ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 07/23] KVM: selftests: Add TDX boot code Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-05 22:31     ` Lisa Wang
2026-10-01 19:37 ` [PATCH v15 08/23] KVM: selftests: Expose functions to get default sregs values Lisa Wang
2026-10-01 19:37 ` [PATCH v15 09/23] KVM: selftests: Set up TDX boot code region Lisa Wang
2026-10-01 19:37 ` [PATCH v15 10/23] KVM: selftests: Set up TDX boot parameters region Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-05 22:33     ` Lisa Wang
2026-10-09  7:22   ` Xiaoyao Li
2026-10-10  2:46   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 11/23] KVM: selftests: Set shared attributes for ucall guest_memfd pages Lisa Wang
2026-10-09 15:44   ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 12/23] KVM: selftests: Require guest_memfd for TDX VMs Lisa Wang
2026-10-09  7:38   ` Xiaoyao Li
2026-10-01 19:37 ` [PATCH v15 13/23] KVM: selftests: Support guest_memfd in-place conversion Lisa Wang
2026-10-10  3:32   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 14/23] KVM: selftests: Expose function to allocate vCPU stack Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-09  7:56   ` Xiaoyao Li
2026-10-10  3:54     ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 15/23] KVM: selftests: Call KVM_TDX_INIT_VCPU when creating a new TDX vcpu Lisa Wang
2026-10-09  8:02   ` Xiaoyao Li
2026-10-10  4:31   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 16/23] KVM: selftests: Load per-vCPU guest stack in TDX boot parameters Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-07 19:07     ` Lisa Wang
2026-10-01 19:37 ` [PATCH v15 17/23] KVM: selftests: Set entry point for TDX guest code Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-01 19:37 ` [PATCH v15 18/23] KVM: selftests: Add helpers to init TDX memory and finalize VM Lisa Wang
2026-10-01 19:37 ` [PATCH v15 19/23] KVM: selftests: Finalize TDX VM in kvm_arch_vm_finalize_vcpus() Lisa Wang
2026-10-09  8:12   ` Xiaoyao Li
2026-10-10  5:57   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 20/23] KVM: selftests: Add a helper to issue TDVMCALLs from the TDX vm Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-09  8:20     ` Xiaoyao Li
2026-10-09  8:23   ` Xiaoyao Li
2026-10-10  6:34   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 21/23] KVM: selftests: Add support for per-VM ucall ops on x86 Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-10  6:52   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 22/23] KVM: selftests: Add support for TDX ucalls, via TDVMCALL_REPORT_FATAL_ERROR Lisa Wang
2026-10-02  9:13   ` sashiko-bot
2026-10-10  7:30     ` Binbin Wu
2026-10-10  7:20   ` Binbin Wu
2026-10-01 19:37 ` [PATCH v15 23/23] KVM: selftests: Add TDX lifecycle test Lisa Wang
2026-10-10  7:40   ` Binbin Wu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002091331.1148B1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wyihan@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.