From mboxrd@z Thu Jan 1 00:00:00 1970 From: Sean Christopherson Date: Thu, 06 Feb 2020 16:28:18 +0000 Subject: Re: [PATCH v5 12/19] KVM: Move memslot deletion to helper function Message-Id: <20200206162818.GD13067@linux.intel.com> List-Id: References: <20200121223157.15263-1-sean.j.christopherson@intel.com> <20200121223157.15263-13-sean.j.christopherson@intel.com> <20200206161415.GA695333@xz-x1> In-Reply-To: <20200206161415.GA695333@xz-x1> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Peter Xu Cc: Paolo Bonzini , Paul Mackerras , Christian Borntraeger , Janosch Frank , David Hildenbrand , Cornelia Huck , Vitaly Kuznetsov , Wanpeng Li , Jim Mattson , Joerg Roedel , Marc Zyngier , James Morse , Julien Thierry , Suzuki K Poulose , linux-mips@vger.kernel.org, kvm@vger.kernel.org, kvm-ppc@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.cs.columbia.edu, linux-kernel@vger.kernel.org, Christoffer Dall , Philippe =?iso-8859-1?Q?Mathieu-Daud=E9?= On Thu, Feb 06, 2020 at 11:14:15AM -0500, Peter Xu wrote: > On Tue, Jan 21, 2020 at 02:31:50PM -0800, Sean Christopherson wrote: > > Move memslot deletion into its own routine so that the success path for > > other memslot updates does not need to use kvm_free_memslot(), i.e. can > > explicitly destroy the dirty bitmap when necessary. This paves the way > > for dropping @dont from kvm_free_memslot(), i.e. all callers now pass > > NULL for @dont. > > > > Add a comment above the code to make a copy of the existing memslot > > prior to deletion, it is not at all obvious that the pointer will become > > stale during sorting and/or installation of new memslots. > > Could you help explain a bit on this explicit comment? I can follow > up with the patch itself which looks all correct to me, but I failed > to catch what this extra comment wants to emphasize... It's tempting to write the code like this (I know, because I did it): if (!mem->memory_size) return kvm_delete_memslot(kvm, mem, slot, as_id); new = *slot; Where @slot is a pointer to the memslot to be deleted. At first, second, and third glances, this seems perfectly sane. The issue is that slot was pulled from struct kvm_memslots.memslots, e.g. slot = &slots->memslots[index]; Note that slots->memslots holds actual "struct kvm_memory_slot" objects, not pointers to slots. When update_memslots() sorts the slots, it swaps the actual slot objects, not pointers. I.e. after update_memslots(), even though @slot points at the same address, it's could be pointing at a different slot. As a result kvm_free_memslot() in kvm_delete_memslot() will free the dirty page info and arch-specific points for some random slot, not the intended slot, and will set npages=0 for that random slot.