dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>
Cc: "Oliver Upton" <oupton@kernel.org>,
	"Marc Zyngier" <maz@kernel.org>,
	kvmarm@lists.linux.dev, dri-devel@lists.freedesktop.org,
	media-ci@linuxtv.org
Subject: Re: [RFC PATCH v8 04/14] irqchip/gic-v3-its: Allocate shared tables using CoCo shared memory allocator
Date: Thu, 24 Sep 2026 10:19:27 +0000	[thread overview]
Message-ID: <20260924101928.380661F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924100529.1398790-5-aneesh.kumar@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] irqchip/gic-v3-its: buddy allocator corruption due to discarded shared_size
--

commit d897529703a71c914b0334abcb563ffb37979469
Author: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>

irqchip/gic-v3-its: Allocate shared tables using CoCo shared memory allocator

This commit updates the ITS allocator to route page allocations through
alloc_cc_shared_pages_node(). It reconstructs common allocation metadata
from the original ITS order and the architecture granule size on release.

> diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
> index ac5507acb1a0c..4814161df02ed 100644
> --- a/drivers/irqchip/irq-gic-v3-its.c
> +++ b/drivers/irqchip/irq-gic-v3-its.c

[ ... ]

> @@ -214,25 +213,13 @@ static gfp_t gfp_flags_quirk;
>  static struct page *its_alloc_pages_node(int node, gfp_t gfp,
>  					 unsigned int order)
>  {
> -	struct page *page;
> -	int ret = 0;
> -
> -	page = alloc_pages_node(node, gfp | gfp_flags_quirk, order);
> -
> -	if (!page)
> -		return NULL;
> +	struct cc_shared_pages mem;
>  
> -	ret = set_memory_decrypted((unsigned long)page_address(page),
> -				   1 << order);
> -	/*
> -	 * If set_memory_decrypted() fails then we don't know what state the
> -	 * page is in, so we can't free it. Instead we leak it.
> -	 * set_memory_decrypted() will already have WARNed.
> -	 */
> -	if (ret)
> +	if (alloc_cc_shared_pages_node(node, gfp | gfp_flags_quirk,
> +				       PAGE_SIZE << order, &mem))
>  		return NULL;
>  
> -	return page;
> +	return mem.page;
>  }

[Severity: High]
Is it safe to discard mem.shared_size here? The API contract seems to require
callers to retain the true allocated size so it can be passed back when
freeing the pages.

>  static struct page *its_alloc_pages(gfp_t gfp, unsigned int order)
> @@ -242,13 +229,15 @@ static struct page *its_alloc_pages(gfp_t gfp, unsigned int order)
>  
>  static void its_free_pages(void *addr, unsigned int order)
>  {
> -	/*
> -	 * If the memory cannot be encrypted again then we must leak the pages.
> -	 * set_memory_encrypted() will already have WARNed.
> -	 */
> -	if (set_memory_encrypted((unsigned long)addr, 1 << order))
> +	struct cc_shared_layout layout;
> +	struct cc_shared_pages mem;
> +
> +	if (WARN_ON(cc_shared_calc_layout(PAGE_SIZE << order, &layout)))
>  		return;
> -	free_pages((unsigned long)addr, order);
> +
> +	mem.page = virt_to_page(addr);
> +	mem.shared_size = layout.shared_size;
> +	free_cc_shared_pages(&mem);
>  }

[Severity: High]
Does recalculating the size here cause a mismatch on non-CC platforms?

When memory encryption is disabled, alloc_cc_shared_pages_node() does not
round up the allocation to the granule size; it simply allocates the
requested order.

However, cc_shared_calc_layout() unconditionally rounds up to the
architectural granule size. If the granule size exceeds the requested
allocation size, free_cc_shared_pages() will call __free_pages() with a
higher order than was actually allocated. Can this corrupt the buddy
allocator by freeing unallocated pages?

>  static struct gen_pool *itt_pool;
> @@ -273,7 +262,8 @@ static void *itt_alloc_pool(int node, int size)
>  		if (!page)
>  			break;
>  
> -		gen_pool_add(itt_pool, (unsigned long)page_address(page), PAGE_SIZE, node);
> +		gen_pool_add(itt_pool, (unsigned long)page_address(page),
> +			     cc_shared_granule_size(), node);
>  	} while (!addr);
>  
>  	return (void *)addr;

[Severity: High]
Will adding a hardcoded granule size to the generic pool advertise unallocated
out-of-bounds memory to consumers?

On non-CC platforms, the underlying allocation size is just a single page,
but this adds the full cc_shared_granule_size() bytes to the pool. Could
this lead to pool consumers accessing memory beyond what was actually
allocated?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924100529.1398790-1-aneesh.kumar@kernel.org?part=4

  reply	other threads:[~2026-09-24 10:19 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 10:05 [RFC PATCH v8 00/14] coco: guest: Add a shared-granule allocator for host-shared memory Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 01/14] mm: Add an allocator for CoCo shared memory Aneesh Kumar K.V (Arm)
2026-09-24 10:19   ` sashiko-bot
2026-09-24 14:22     ` Aneesh Kumar K.V
2026-09-24 18:26       ` Jason Gunthorpe
2026-09-24 10:05 ` [RFC PATCH v8 02/14] mm: Zero memory during shared memory transitions Aneesh Kumar K.V (Arm)
2026-09-24 10:22   ` sashiko-bot
2026-09-25 12:08   ` Kiryl Shutsemau
2026-09-24 10:05 ` [RFC PATCH v8 03/14] irqchip/gic-v3-its: Resolve the default NUMA node explicitly Aneesh Kumar K.V (Arm)
2026-09-24 10:19   ` sashiko-bot
2026-09-24 10:05 ` [RFC PATCH v8 04/14] irqchip/gic-v3-its: Allocate shared tables using CoCo shared memory allocator Aneesh Kumar K.V (Arm)
2026-09-24 10:19   ` sashiko-bot [this message]
2026-09-24 10:05 ` [RFC PATCH v8 05/14] dma-contiguous: Derive shared alignment from DMA attributes Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 06/14] dma-pool: Allocate CoCo atomic pools using CoCo shared memory allocator Aneesh Kumar K.V (Arm)
2026-09-24 10:19   ` sashiko-bot
2026-09-24 10:05 ` [RFC PATCH v8 07/14] dma-direct: Align CoCo shared DMA allocations to the shared granule size Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 08/14] swiotlb: Align shared IO TLB pools " Aneesh Kumar K.V (Arm)
2026-09-24 10:22   ` sashiko-bot
2026-09-24 10:05 ` [RFC PATCH v8 09/14] swiotlb: Reject misaligned restricted DMA pools for CoCo guests Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 10/14] dma-buf: system_heap: Limit scatterlist entries to the buffer size Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 11/14] dma-buf: system_heap: Allocate shared buffers using CoCo shared memory allocator Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 12/14] swiotlb: Make rounded shared pool capacity allocatable Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 13/14] mm: Assert CoCo shared allocations may sleep Aneesh Kumar K.V (Arm)
2026-09-24 10:05 ` [RFC PATCH v8 14/14] irqchip/gic-v3-its: Preallocate VPE L1 tables Aneesh Kumar K.V (Arm)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924101928.380661F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=aneesh.kumar@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=media-ci@linuxtv.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox