Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Sascha Bischoff <Sascha.Bischoff@arm.com>
To: "sashiko-reviews@lists.linux.dev" <sashiko-reviews@lists.linux.dev>
Cc: "maz@kernel.org" <maz@kernel.org>,
	"kvmarm@lists.linux.dev" <kvmarm@lists.linux.dev>,
	"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
	"oupton@kernel.org" <oupton@kernel.org>, nd <nd@arm.com>
Subject: Re: [PATCH v6 07/49] KVM: arm64: gic-v5: Cache host IRS ID registers
Date: Fri, 4 Sep 2026 12:37:10 +0000	[thread overview]
Message-ID: <14a47a452f68cd7d74a94551ace71048042c1309.camel@arm.com> (raw)
In-Reply-To: <20260904122530.607ED1F00A3D@smtp.kernel.org>

On Fri, 2026-09-04 at 12:25 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [High] Integer truncation in vgic_v5_irs_vped_size and
> vgic_v5_irs_vmd_size can lead to zero-sized allocations and host
> memory corruption.
> --
> 
> commit 04b027d3b388107549c9e9457c0e98e85ca72ba3
> Author: Sascha Bischoff <Sascha.Bischoff@arm.com>
> 
> KVM: arm64: gic-v5: Cache host IRS ID registers
> 
> This commit caches the GICv5 IRS ID registers (IRS_IDR2, IRS_IDR3,
> IRS_IDR4)
> instead of extracting their individual fields into
> kvm_vgic_global_state. It
> also introduces accessor helpers to derive capabilities directly from
> these
> cached registers.
> 
> > diff --git a/include/kvm/arm_vgic.h b/include/kvm/arm_vgic.h
> > index 086b7578e5f33..c82aa7c9e3f32 100644
> > --- a/include/kvm/arm_vgic.h
> > +++ b/include/kvm/arm_vgic.h
> [ ... ]
> > @@ -627,6 +643,65 @@ int vgic_v4_load(struct kvm_vcpu *vcpu);
> [ ... ]
> > +static inline u16 vgic_v5_irs_vmd_size(const struct
> > vgic_v5_irs_caps *caps)
> > +{
> > +	if (!(caps->idr3 & GICV5_IRS_IDR3_VMD))
> > +		return 0;
> > +
> > +	return BIT(FIELD_GET(GICV5_IRS_IDR3_VMD_SZ, caps->idr3));
> > +}
> 
> [Severity: High]
> Will this return type truncate the descriptor size to 0?
> 
> The hardware field GICV5_IRS_IDR3_VMD_SZ is 6 bits, allowing values
> up to 63.
> If the host hardware provides a size shift >= 16, BIT() will produce
> a value
> > = 65536. Casting this to u16 truncates it to 0.

No: The minimum valid value for this field is 3 and the maximum valid
value is 12.

> 
> When vgic_v5_probe() uses this size to allocate the descriptor
> tables, a
> 0-byte allocation results in a ZERO_SIZE_PTR. KVM will then program
> virt_to_phys(ZERO_SIZE_PTR) into the host GIC hardware, which can
> cause
> host physical memory corruption when the hardware accesses it.
> 
> > +
> > +static inline u16 vgic_v5_irs_vped_size(const struct
> > vgic_v5_irs_caps *caps)
> > +{
> > +	return BIT(FIELD_GET(GICV5_IRS_IDR4_VPED_SZ, caps->idr4));
> > +}
> 
> [Severity: High]
> Can the same truncation occur here?
> 
> Similar to the VMD size above, GICV5_IRS_IDR4_VPED_SZ is a 6-bit
> field. If
> the hardware reports a shift >= 16, BIT() produces a value that
> truncates
> to 0 in a u16 return type, leading to the same zero-sized allocation
> issue
> when programming the Virtual PE Descriptor size.

No: The minimum valid value for this field is 3 and the maximum valid
value is 12.
> 
> > +
> > +static inline u32 vgic_v5_irs_max_vpes(const struct
> > vgic_v5_irs_caps *caps)
> > +{
> [ ... ]
> 

Thanks,
Sascha

  reply	other threads:[~2026-09-04 12:37 UTC|newest]

Thread overview: 74+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04 11:34 [PATCH v6 00/49] KVM: arm64: Add GICv5 IRS support Sascha Bischoff
2026-09-04 11:34 ` [PATCH v6 01/49] irqchip/gic-v5: Allow KVM setup without a maintenance IRQ Sascha Bischoff
2026-09-04 11:35 ` [PATCH v6 02/49] irqchip/gic-v5: Provide OF IRS config frame attrs to KVM Sascha Bischoff
2026-09-04 11:35 ` [PATCH v6 03/49] irqchip/gic-v5: Set up gic_kvm_info on ACPI hosts Sascha Bischoff
2026-09-04 11:36 ` [PATCH v6 04/49] KVM: arm64: gic-v5: Define remaining IRS MMIO registers Sascha Bischoff
2026-09-04 12:07   ` sashiko-bot
2026-09-04 12:16     ` Sascha Bischoff
2026-09-04 11:36 ` [PATCH v6 05/49] arm64/sysreg: Add GICv5 GIC VDPEND encoding Sascha Bischoff
2026-09-04 11:37 ` [PATCH v6 06/49] arm64/sysreg: Update ICC_CR0_EL1 with LINK and LINK_IDLE fields Sascha Bischoff
2026-09-04 12:14   ` sashiko-bot
2026-09-04 12:21     ` Sascha Bischoff
2026-09-04 11:37 ` [PATCH v6 07/49] KVM: arm64: gic-v5: Cache host IRS ID registers Sascha Bischoff
2026-09-04 12:25   ` sashiko-bot
2026-09-04 12:37     ` Sascha Bischoff [this message]
2026-09-04 11:38 ` [PATCH v6 08/49] KVM: arm64: gic-v5: Add VPE doorbell domain Sascha Bischoff
2026-09-04 12:26   ` sashiko-bot
2026-09-04 11:38 ` [PATCH v6 09/49] KVM: arm64: gic-v5: Create and manage VM and VPE tables Sascha Bischoff
2026-09-04 12:24   ` sashiko-bot
2026-09-04 11:39 ` [PATCH v6 10/49] KVM: arm64: gic-v5: Introduce guest IST alloc and management Sascha Bischoff
2026-09-04 12:30   ` sashiko-bot
2026-09-04 11:39 ` [PATCH v6 11/49] KVM: arm64: gic-v5: Implement VMT/vIST IRS MMIO Ops Sascha Bischoff
2026-09-04 12:39   ` sashiko-bot
2026-09-04 11:40 ` [PATCH v6 12/49] KVM: arm64: vgic: Enforce model-specific vCPU limits Sascha Bischoff
2026-09-04 11:40 ` [PATCH v6 13/49] KVM: arm64: gic-v5: Implement VPE IRS MMIO Ops Sascha Bischoff
2026-09-04 12:36   ` sashiko-bot
2026-09-04 11:41 ` [PATCH v6 14/49] KVM: arm64: gic-v5: Set up VMTEs and VPE doorbells Sascha Bischoff
2026-09-04 12:50   ` sashiko-bot
2026-09-04 11:41 ` [PATCH v6 15/49] KVM: arm64: gic-v5: Add resident/non-resident hyp calls Sascha Bischoff
2026-09-04 12:42   ` sashiko-bot
2026-09-04 11:42 ` [PATCH v6 16/49] KVM: arm64: gic-v5: Request doorbells when VPEs enter WFI Sascha Bischoff
2026-09-04 13:08   ` sashiko-bot
2026-09-04 11:42 ` [PATCH v6 17/49] KVM: arm64: gic-v5: Introduce struct vgic_v5_irs and IRS base address Sascha Bischoff
2026-09-04 11:43 ` [PATCH v6 18/49] KVM: arm64: gic-v5: Add IRS IODEV support to MMIO handlers Sascha Bischoff
2026-09-04 11:43 ` [PATCH v6 19/49] KVM: arm64: gic-v5: Add KVM_VGIC_V5_ADDR_TYPE_IRS to UAPI Sascha Bischoff
2026-09-04 11:44 ` [PATCH v6 20/49] KVM: arm64: gic-v5: Add GICv5 IRS IODEV and MMIO emulation Sascha Bischoff
2026-09-04 12:59   ` sashiko-bot
2026-09-04 11:44 ` [PATCH v6 21/49] KVM: arm64: gic-v5: Initialise per-VM IRS state Sascha Bischoff
2026-09-04 13:00   ` sashiko-bot
2026-09-04 11:45 ` [PATCH v6 22/49] KVM: arm64: gic-v5: Register the IRS IODEV Sascha Bischoff
2026-09-04 13:10   ` sashiko-bot
2026-09-04 11:45 ` [PATCH v6 23/49] KVM: arm64: gic-v5: Set IRICHPPIDIS based on IRS enable state Sascha Bischoff
2026-09-04 13:05   ` sashiko-bot
2026-09-04 11:46 ` [PATCH v6 24/49] KVM: arm64: selftests: Update vGICv5 selftest to set IRS address Sascha Bischoff
2026-09-04 11:46 ` [PATCH v6 25/49] KVM: arm64: gic-v5: Add GIC VDPEND hyp call Sascha Bischoff
2026-09-04 11:47 ` [PATCH v6 26/49] KVM: arm64: gic: Introduce set_pending_state() to irq_ops Sascha Bischoff
2026-09-04 11:47 ` [PATCH v6 27/49] KVM: arm64: gic-v5: Support SPI injection Sascha Bischoff
2026-09-04 11:48 ` [PATCH v6 28/49] Documentation: KVM: Extend VGICv5 device attribute docs Sascha Bischoff
2026-09-04 13:25   ` sashiko-bot
2026-09-04 11:49 ` [PATCH v6 29/49] KVM: arm64: gic-v5: Add GICv5 SPI injection to irqfd Sascha Bischoff
2026-09-04 11:49 ` [PATCH v6 30/49] KVM: arm64: gic-v5: Mask per-vCPU PPI state in vgic_v5_finalize_ppi_state() Sascha Bischoff
2026-09-04 11:50 ` [PATCH v6 31/49] KVM: arm64: gic-v5: Add GICv5 EL1 sysreg userspace accessors Sascha Bischoff
2026-09-04 13:27   ` sashiko-bot
2026-09-04 11:50 ` [PATCH v6 32/49] KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region Sascha Bischoff
2026-09-04 13:34   ` sashiko-bot
2026-09-04 11:51 ` [PATCH v6 33/49] KVM: arm64: gic-v5: Add CoreSight MMIO regs to IRS Sascha Bischoff
2026-09-04 11:51 ` [PATCH v6 34/49] KVM: arm64: gic-v5: Add VGICv5 IST save/restore UAPI Sascha Bischoff
2026-09-04 11:52 ` [PATCH v6 35/49] KVM: arm64: gic-v5: Implement save/restore mechanisms for ISTs Sascha Bischoff
2026-09-04 13:45   ` sashiko-bot
2026-09-04 11:52 ` [PATCH v6 36/49] Documentation: KVM: Document KVM_DEV_ARM_VGIC_GRP_CPU_SYSREGS for VGICv5 Sascha Bischoff
2026-09-04 11:53 ` [PATCH v6 37/49] Documentation: KVM: Add KVM_DEV_ARM_VGIC_GRP_IRS_REGS to VGICv5 docs Sascha Bischoff
2026-09-04 11:53 ` [PATCH v6 38/49] Documentation: KVM: Add docs for KVM_DEV_ARM_VGIC_GRP_IST Sascha Bischoff
2026-09-04 11:54 ` [PATCH v6 39/49] Documentation: KVM: Add the VGICv5 IRS save/restore sequences Sascha Bischoff
2026-09-04 11:54 ` [PATCH v6 40/49] KVM: selftests: Add VGICv5 IRS address attribute tests Sascha Bischoff
2026-09-04 11:55 ` [PATCH v6 41/49] KVM: selftests: Add VGICv5 NR_IRQS " Sascha Bischoff
2026-09-04 11:55 ` [PATCH v6 42/49] KVM: selftests: Add VGICv5 IRS_REGS " Sascha Bischoff
2026-09-04 11:56 ` [PATCH v6 43/49] KVM: selftests: Add VGICv5 IST " Sascha Bischoff
2026-09-04 11:56 ` [PATCH v6 44/49] KVM: selftests: Add VGICv5 USERSPACE_PPIS tests Sascha Bischoff
2026-09-04 11:57 ` [PATCH v6 45/49] KVM: selftests: Add VGICv5 CPU sysreg attribute tests Sascha Bischoff
2026-09-04 11:57 ` [PATCH v6 46/49] KVM: selftests: Add VGICv5 SPI injection tests Sascha Bischoff
2026-09-04 11:58 ` [PATCH v6 47/49] KVM: selftests: Add VGICv5 LPI delivery tests Sascha Bischoff
2026-09-04 13:56   ` sashiko-bot
2026-09-04 11:58 ` [PATCH v6 48/49] KVM: selftests: Add VGICv5 IST save/restore coverage Sascha Bischoff
2026-09-04 13:58   ` sashiko-bot
2026-09-04 11:59 ` [PATCH v6 49/49] KVM: selftests: Add VGICv5 sparse vCPU IDs test Sascha Bischoff

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=14a47a452f68cd7d74a94551ace71048042c1309.camel@arm.com \
    --to=sascha.bischoff@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=nd@arm.com \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox