From: sashiko-bot@kernel.org
To: "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>
Cc: "Oliver Upton" <oupton@kernel.org>,
"Marc Zyngier" <maz@kernel.org>,
kvmarm@lists.linux.dev, dri-devel@lists.freedesktop.org,
media-ci@linuxtv.org
Subject: Re: [RFC PATCH v8 04/14] irqchip/gic-v3-its: Allocate shared tables using CoCo shared memory allocator
Date: Thu, 24 Sep 2026 10:19:27 +0000 [thread overview]
Message-ID: <20260924101928.380661F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924100529.1398790-5-aneesh.kumar@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] irqchip/gic-v3-its: buddy allocator corruption due to discarded shared_size
--
commit d897529703a71c914b0334abcb563ffb37979469
Author: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
irqchip/gic-v3-its: Allocate shared tables using CoCo shared memory allocator
This commit updates the ITS allocator to route page allocations through
alloc_cc_shared_pages_node(). It reconstructs common allocation metadata
from the original ITS order and the architecture granule size on release.
> diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
> index ac5507acb1a0c..4814161df02ed 100644
> --- a/drivers/irqchip/irq-gic-v3-its.c
> +++ b/drivers/irqchip/irq-gic-v3-its.c
[ ... ]
> @@ -214,25 +213,13 @@ static gfp_t gfp_flags_quirk;
> static struct page *its_alloc_pages_node(int node, gfp_t gfp,
> unsigned int order)
> {
> - struct page *page;
> - int ret = 0;
> -
> - page = alloc_pages_node(node, gfp | gfp_flags_quirk, order);
> -
> - if (!page)
> - return NULL;
> + struct cc_shared_pages mem;
>
> - ret = set_memory_decrypted((unsigned long)page_address(page),
> - 1 << order);
> - /*
> - * If set_memory_decrypted() fails then we don't know what state the
> - * page is in, so we can't free it. Instead we leak it.
> - * set_memory_decrypted() will already have WARNed.
> - */
> - if (ret)
> + if (alloc_cc_shared_pages_node(node, gfp | gfp_flags_quirk,
> + PAGE_SIZE << order, &mem))
> return NULL;
>
> - return page;
> + return mem.page;
> }
[Severity: High]
Is it safe to discard mem.shared_size here? The API contract seems to require
callers to retain the true allocated size so it can be passed back when
freeing the pages.
> static struct page *its_alloc_pages(gfp_t gfp, unsigned int order)
> @@ -242,13 +229,15 @@ static struct page *its_alloc_pages(gfp_t gfp, unsigned int order)
>
> static void its_free_pages(void *addr, unsigned int order)
> {
> - /*
> - * If the memory cannot be encrypted again then we must leak the pages.
> - * set_memory_encrypted() will already have WARNed.
> - */
> - if (set_memory_encrypted((unsigned long)addr, 1 << order))
> + struct cc_shared_layout layout;
> + struct cc_shared_pages mem;
> +
> + if (WARN_ON(cc_shared_calc_layout(PAGE_SIZE << order, &layout)))
> return;
> - free_pages((unsigned long)addr, order);
> +
> + mem.page = virt_to_page(addr);
> + mem.shared_size = layout.shared_size;
> + free_cc_shared_pages(&mem);
> }
[Severity: High]
Does recalculating the size here cause a mismatch on non-CC platforms?
When memory encryption is disabled, alloc_cc_shared_pages_node() does not
round up the allocation to the granule size; it simply allocates the
requested order.
However, cc_shared_calc_layout() unconditionally rounds up to the
architectural granule size. If the granule size exceeds the requested
allocation size, free_cc_shared_pages() will call __free_pages() with a
higher order than was actually allocated. Can this corrupt the buddy
allocator by freeing unallocated pages?
> static struct gen_pool *itt_pool;
> @@ -273,7 +262,8 @@ static void *itt_alloc_pool(int node, int size)
> if (!page)
> break;
>
> - gen_pool_add(itt_pool, (unsigned long)page_address(page), PAGE_SIZE, node);
> + gen_pool_add(itt_pool, (unsigned long)page_address(page),
> + cc_shared_granule_size(), node);
> } while (!addr);
>
> return (void *)addr;
[Severity: High]
Will adding a hardcoded granule size to the generic pool advertise unallocated
out-of-bounds memory to consumers?
On non-CC platforms, the underlying allocation size is just a single page,
but this adds the full cc_shared_granule_size() bytes to the pool. Could
this lead to pool consumers accessing memory beyond what was actually
allocated?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924100529.1398790-1-aneesh.kumar@kernel.org?part=4
next prev parent reply other threads:[~2026-09-24 10:19 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 10:05 [RFC PATCH v8 00/14] coco: guest: Add a shared-granule allocator for host-shared memory Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 01/14] mm: Add an allocator for CoCo shared memory Aneesh Kumar K.V (Arm)
2026-09-24 10:19 ` sashiko-bot
2026-09-24 14:22 ` Aneesh Kumar K.V
2026-09-24 18:26 ` Jason Gunthorpe
2026-09-24 10:05 ` [RFC PATCH v8 02/14] mm: Zero memory during shared memory transitions Aneesh Kumar K.V (Arm)
2026-09-24 10:22 ` sashiko-bot
2026-09-25 12:08 ` Kiryl Shutsemau
2026-09-24 10:05 ` [RFC PATCH v8 03/14] irqchip/gic-v3-its: Resolve the default NUMA node explicitly Aneesh Kumar K.V (Arm)
2026-09-24 10:19 ` sashiko-bot
2026-09-24 10:05 ` [RFC PATCH v8 04/14] irqchip/gic-v3-its: Allocate shared tables using CoCo shared memory allocator Aneesh Kumar K.V (Arm)
2026-09-24 10:19 ` sashiko-bot [this message]
2026-09-24 10:05 ` [RFC PATCH v8 05/14] dma-contiguous: Derive shared alignment from DMA attributes Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 06/14] dma-pool: Allocate CoCo atomic pools using CoCo shared memory allocator Aneesh Kumar K.V (Arm)
2026-09-24 10:19 ` sashiko-bot
2026-09-24 10:05 ` [RFC PATCH v8 07/14] dma-direct: Align CoCo shared DMA allocations to the shared granule size Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 08/14] swiotlb: Align shared IO TLB pools " Aneesh Kumar K.V (Arm)
2026-09-24 10:22 ` sashiko-bot
2026-09-24 10:05 ` [RFC PATCH v8 09/14] swiotlb: Reject misaligned restricted DMA pools for CoCo guests Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 10/14] dma-buf: system_heap: Limit scatterlist entries to the buffer size Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 11/14] dma-buf: system_heap: Allocate shared buffers using CoCo shared memory allocator Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 12/14] swiotlb: Make rounded shared pool capacity allocatable Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 13/14] mm: Assert CoCo shared allocations may sleep Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 14/14] irqchip/gic-v3-its: Preallocate VPE L1 tables Aneesh Kumar K.V (Arm)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924101928.380661F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=aneesh.kumar@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=media-ci@linuxtv.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox