From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 77D6F346FAE; Tue, 28 Jul 2026 03:30:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785209432; cv=none; b=VwKRa0jIx3IWxQMedlN2bLebAe85dsADwWbjmQsBKFR6Emxq/j8WlhXlNf/Irsne/V2AIUDwJJ3g3jALb+BjCDR/HX1RnjouLNwJy1PkakGDuqtdwbDU3BtlPYN35dl0b/4YtBFTqCnJKfEnwVLCY/V2CVVcTTxrXE87oQg49WI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785209432; c=relaxed/simple; bh=3EckSShkvG+H0FPgvbUGk1DwZ4vc5ZFCuqpJ/RHFI4A=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LwuQloeQ3jAZ5OUM4bH/2s+q/8dquQEejSIDK294bXPs6ycK0xemLaKXuRhR2rVN3fDlQFoAYof6YJZOVspPN8qc5cHhbCznhPjPTHXHsoVLXixkEN8kHMSmULW01pRUp6Nwe2ajcarAtQ1pqgCVjifFfwomwCvPafuGmB4XEQM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=Z779tln4; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="Z779tln4" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66S0m0Zi1888349; Tue, 28 Jul 2026 03:30:30 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=xs+m2F3zNULxZt7Bf rTJdMKPsHk4cB+6uiMDMsph1T0=; b=Z779tln4mg5Zz6c1373UiTBXa0VWOYCQB aVLZV2wTOzNQxja0HzF54Bdbz6cxjdYzmYJiAYC8salZ7MgAjvteatv9kXQrmt+J mmlGrVpJBQ3d56FVjEmZ+4zZwReNl7As52Xg646X4AvDUnEGc64K1+R+RwAytT6x 18fqJB0SEvE8ATPE6LCvG2bj2tdUZZ2BA4Ebg1+1RmlX+fKb6m3WwWyyZ0AQqpS5 6+EU2cDMq7yq/8aHaU6bovG1UMdcXvFf8y6x8dn1S9k6Qen/EmWm1RM5W+K4/GPN o7SSKJz3rjqv/Gn73Z/MK2stoBPk+JovVwnkfsX3OCFjLcPWH1OtA== Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fmuycb7uv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 28 Jul 2026 03:30:29 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 66S3QI3F024742; Tue, 28 Jul 2026 03:30:28 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fn8fk031k-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 28 Jul 2026 03:30:28 +0000 (GMT) Received: from smtpav06.fra02v.mail.ibm.com (smtpav06.fra02v.mail.ibm.com [10.20.54.105]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 66S3UOTK31982316 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 28 Jul 2026 03:30:24 GMT Received: from smtpav06.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4AF8D2004F; Tue, 28 Jul 2026 03:30:24 +0000 (GMT) Received: from smtpav06.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2B1622004D; Tue, 28 Jul 2026 03:30:24 +0000 (GMT) Received: from tuxmaker.boeblingen.de.ibm.com (unknown [9.87.85.9]) by smtpav06.fra02v.mail.ibm.com (Postfix) with SMTP; Tue, 28 Jul 2026 03:30:24 +0000 (GMT) Received: by tuxmaker.boeblingen.de.ibm.com (Postfix, from userid 4958) id 148B91627F0; Tue, 28 Jul 2026 05:30:24 +0200 (CEST) From: Eric Farman To: linux-s390@vger.kernel.org, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Matthew Rosato , Halil Pasic , Christian Borntraeger , Eric Farman , stable@vger.kernel.org Subject: [PATCH v9 02/10] s390/vfio_ccw: limit the number of channel program segments Date: Tue, 28 Jul 2026 05:30:14 +0200 Message-ID: <20260728033022.2658232-3-farman@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728033022.2658232-1-farman@linux.ibm.com> References: <20260728033022.2658232-1-farman@linux.ibm.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: 9HBXfBmk1unsfHWezqn4U_axp6RpJh97 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzI4MDAyOCBTYWx0ZWRfX6Dcils7KrW8a mKMghjmrkNu3c+ncnxacczwOqIzLa3EX/J/17WmEoJsmAa7ZfcZ+Fui3SQFBVeFF6+xnXykSGcT PsZESba6iT1Bv3mkvJbTt8oNE6Y8xrXr9GcHXoDSNhDix2IRZJq9K49mBkUXWZEoNXMZFo0evZF JUJShWuK65ysdCtmJN6qQvzfzVbAzyPL7SO/RmXZkv5GszMj0CCX0Lz1Dr5rVFyE1iB6BVMpmcq OBMZy8plpoEqvG3Js0O8DXaFK4YKJ+c14JBIYxvOxDmOK7DiHwrHrh4BvwsH3cNbkZcQHvrU9Cw pYBDi7x0Xv59UjCbEBPzy8mBbozHSXh2PB6Vfwzob1SrM43GkaYHwwUjZUKWpzTid4koChUct80 VT1ifuUqtKNwdw+L1I2SP3ZRG+9Le1rFMsrX0Izx4ws5S9S+wl7izgMUi3DTRvsr1shQPUy/66j 1O1fTdkdXzhd0Ea7opQ== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzI4MDAyOCBTYWx0ZWRfX8zmTlX6oV0jA gXxsR1ITX720Q9BeWb5CO9o+tugkp+13jwKpj8qc9hlaXMtSL8x+wqQFxDkI0Bfyw3nvHeHXB5P D69LNWmpeGP0Vfw3yIu6VRgwPjdF3hg= X-Authority-Analysis: v=2.4 cv=AZeB2XXG c=1 sm=1 tr=0 ts=6a682255 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=sBi1HX8ECoo2m5KYV-oA:9 X-Proofpoint-GUID: 9HBXfBmk1unsfHWezqn4U_axp6RpJh97 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-27_07,2026-07-27_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 priorityscore=1501 phishscore=0 adultscore=0 impostorscore=0 clxscore=1015 malwarescore=0 suspectscore=0 lowpriorityscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607280028 The processing of channel programs, and the CCWs within them, is done recursively. As such, there is an arbitrary (but not architectural) limit to the number of CCWs that can exist in a single channel program. The vfio-ccw logic breaks these channel programs into segments whenever it encounters a Transfer-In-Channel (TIC) CCW, and the combined number of segments count towards the global limit. Impose an equivalent limit to the number of segments until such logic can be made non-recursive. Fixes: 0a19e61e6d4c ("vfio: ccw: introduce channel program interfaces") Cc: stable@vger.kernel.org Reviewed-by: Matthew Rosato Signed-off-by: Eric Farman --- drivers/s390/cio/vfio_ccw_cp.c | 6 ++++++ drivers/s390/cio/vfio_ccw_cp.h | 8 ++++++++ 2 files changed, 14 insertions(+) diff --git a/drivers/s390/cio/vfio_ccw_cp.c b/drivers/s390/cio/vfio_ccw_c= p.c index 086d1b54bdb0..1c2890d139c6 100644 --- a/drivers/s390/cio/vfio_ccw_cp.c +++ b/drivers/s390/cio/vfio_ccw_cp.c @@ -332,6 +332,7 @@ static struct ccwchain *ccwchain_alloc(struct channel= _program *cp, int len) goto out_err; =20 list_add_tail(&chain->next, &cp->ccwchain_list); + cp->ccwchain_count++; =20 return chain; =20 @@ -441,6 +442,10 @@ static int ccwchain_handle_ccw(dma32_t cda, struct c= hannel_program *cp) if (len < 0) return len; =20 + /* Limit number of chains in a single channel program */ + if (cp->ccwchain_count >=3D CCWCHAIN_COUNT_MAX) + return -EINVAL; + /* Need alloc a new chain for this one. */ chain =3D ccwchain_alloc(cp, len); if (!chain) @@ -745,6 +750,7 @@ int cp_init(struct channel_program *cp, union orb *or= b) vdev->dev, "Prefetching channel program even though prefetch not specified in OR= B"); =20 + cp->ccwchain_count =3D 0; INIT_LIST_HEAD(&cp->ccwchain_list); memcpy(&cp->orb, orb, sizeof(*orb)); =20 diff --git a/drivers/s390/cio/vfio_ccw_cp.h b/drivers/s390/cio/vfio_ccw_c= p.h index fc31eb699807..a9b1d8dbc6f6 100644 --- a/drivers/s390/cio/vfio_ccw_cp.h +++ b/drivers/s390/cio/vfio_ccw_cp.h @@ -23,11 +23,18 @@ */ #define CCWCHAIN_LEN_MAX 256 =20 +/* + * Maximum number of chains + */ +#define CCWCHAIN_COUNT_MAX 16 + /** * struct channel_program - manage information for channel program * @ccwchain_list: list head of ccwchains * @orb: orb for the currently processed ssch request * @initialized: whether this instance is actually initialized + * @guest_cp: copy of guest channel program + * @ccwchain_count: number of channel program segments (linked by TIC) * * @ccwchain_list is the head of a ccwchain list, that contents the * translated result of the guest channel program that pointed out by @@ -38,6 +45,7 @@ struct channel_program { union orb orb; bool initialized; struct ccw1 *guest_cp; + unsigned int ccwchain_count; }; =20 int cp_init(struct channel_program *cp, union orb *orb); --=20 2.53.0