Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "David Woodhouse" <dwmw2@infradead.org>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v7 35/36] KVM: selftests: Add Xen/generic CPUID timing leaf test
Date: Tue, 28 Jul 2026 15:23:57 +0000	[thread overview]
Message-ID: <20260728152357.9C2581F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728144954.355376-36-dwmw2@infradead.org>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [Medium] The TSC scale ratio verification test will spuriously fail if the host TSC frequency is within KVM's 250 ppm tolerance of a target frequency.
- [Medium] Unsafe `realloc` pattern overwrites the original pointer, leading to a memory leak and immediate NULL pointer dereference on allocation failure.
- [Low] Commit message typo: duplicates 'KVM_VCPU_TSC_SCALE'.
--

--- Patch [35]: [PATCH v7 35/36] KVM: selftests: Add Xen/generic CPUID timing leaf test ---
commit f482c86f3dcfdbeb8ea33ae05535bd28d7cd5656
Author: David Woodhouse <dwmw@amazon.co.uk>

KVM: selftests: Add Xen/generic CPUID timing leaf test

This commit adds a test to verify that userspace can correctly populate Xen
and generic CPUID timing leaves. It validates this using native and scaled
TSC frequencies.

> Verify that userspace can correctly populate Xen and generic CPUID
> timing leaves using the KVM_VCPU_TSC_SCALE and
> KVM_VCPU_TSC_SCALE attributes.

[Severity: Low]
This isn't a bug, but there's a typo in the commit message where
"KVM_VCPU_TSC_SCALE" is duplicated instead of mentioning both
KVM_GET_TSC_KHZ and KVM_VCPU_TSC_SCALE.

> diff --git a/tools/testing/selftests/kvm/x86/xen_cpuid_timing_test.c b/tools/testing/selftests/kvm/x86/xen_cpuid_timing_test.c
> new file mode 100644
> index 0000000000000..2098cb511ef02
> --- /dev/null
> +++ b/tools/testing/selftests/kvm/x86/xen_cpuid_timing_test.c

[ ... ]

> +static void add_cpuid_entry(struct kvm_vcpu *vcpu, uint32_t function,
> +			    uint32_t index, uint32_t eax, uint32_t ebx,
> +			    uint32_t ecx, uint32_t edx)
> +{
> +	struct kvm_cpuid2 *cpuid = vcpu->cpuid;
> +	struct kvm_cpuid_entry2 *entry;
> +	int n = cpuid->nent;
> +
> +	vcpu->cpuid = realloc(vcpu->cpuid,
> +			      sizeof(*cpuid) + (n + 1) * sizeof(*entry));
> +	cpuid = vcpu->cpuid;
> +	cpuid->nent = n + 1;

[Severity: Medium]
Will this cause a memory leak and immediate NULL pointer dereference if
realloc() fails?

If realloc() returns NULL due to memory exhaustion, the original pointer in
vcpu->cpuid is overwritten, leaking the memory. Then cpuid->nent = n + 1
will immediately dereference that NULL pointer.

[ ... ]

> +static void run_test(uint64_t tsc_khz)
> +{

[ ... ]

> +	effective_tsc_khz = __vcpu_ioctl(vcpu, KVM_GET_TSC_KHZ, NULL);
> +	bus_cycle_ns = vm_check_cap(vm, KVM_CAP_X86_APIC_BUS_CYCLES_NS);
> +	effective_bus_khz = bus_cycle_ns > 0 ? 1000000 / bus_cycle_ns : 1000000;
> +
> +	/* If scaling wasn't applied, skip this frequency */
> +	if (tsc_khz && effective_tsc_khz == host_khz) {

[Severity: Medium]
Could this check fail to skip properly if the requested frequency is within 
KVM's 250 ppm tolerance of the host TSC? 

If the target frequency is close to the host frequency (within tolerance), 
KVM disables TSC scaling (setting the ratio to 1.0) but still returns the 
requested frequency in effective_tsc_khz. Since effective_tsc_khz differs
from host_khz, this check evaluates to false even though scaling wasn't 
actually applied.

> +		pr_info("  TSC scaling not available, skipping\n");
> +		kvm_vm_free(vm);
> +		return;
> +	}

[ ... ]

> +			if (tsc_khz) {
> +				uint64_t computed = ((__uint128_t)host_khz * scale.ratio) >> scale.frac_bits;
> +				int64_t diff = (int64_t)computed - (int64_t)effective_tsc_khz;
> +
> +				TEST_ASSERT(diff >= -1 && diff <= 1,
> +					    "TSC_SCALE ratio mismatch: computed %lu vs effective %u (diff %ld)",
> +					    computed, effective_tsc_khz, diff);

[Severity: Medium]
Does this cause a spurious test failure due to the unskipped ppm tolerance 
case above?

If scaling wasn't applied but the test didn't skip (because the ratio is 1.0), 
computed will equal host_khz. The assertion will then check if 
host_khz is within 1 kHz of effective_tsc_khz. If the difference 
between them was just large enough (e.g., 100 kHz) but still within KVM's 
ppm tolerance, this assertion will fail.

> +			}
> +		}
> +	}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260728144954.355376-1-dwmw2@infradead.org?part=35

  reply	other threads:[~2026-07-28 15:23 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-28 14:39 [PATCH v7 00/36] Cleaning up the KVM clock mess David Woodhouse
2026-07-28 14:39 ` [PATCH v7 01/36] KVM: x86: Improve accuracy of KVM clock when TSC scaling is in force David Woodhouse
2026-07-28 14:39 ` [PATCH v7 02/36] KVM: x86: Explicitly disable TSC scaling without CONSTANT_TSC David Woodhouse
2026-07-28 14:39 ` [PATCH v7 03/36] KVM: x86: Activate master clock immediately on vCPU creation David Woodhouse
2026-07-28 15:17   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 04/36] KVM: x86: Avoid NTP frequency skew for KVM clock on 32-bit host David Woodhouse
2026-07-28 14:39 ` [PATCH v7 05/36] KVM: x86: Fold __get_kvmclock() into get_kvmclock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 06/36] KVM: x86: Drop CPU pinning in get_kvmclock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 07/36] KVM: x86: Restructure get_kvmclock() David Woodhouse
2026-07-28 15:11   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 08/36] KVM: x86: Fix KVM clock precision in get_kvmclock() with TSC scaling David Woodhouse
2026-07-28 14:39 ` [PATCH v7 09/36] KVM: x86: Use get_kvmclock() in kvm_get_wall_clock_epoch() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 10/36] KVM: x86: Fix compute_guest_tsc() to handle negative time deltas David Woodhouse
2026-07-28 14:39 ` [PATCH v7 11/36] KVM: x86: Restructure kvm_guest_time_update() for TSC upscaling David Woodhouse
2026-07-28 15:11   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 12/36] KVM: x86: Simplify and comment kvm_get_time_scale() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 13/36] KVM: x86: Remove implicit rdtsc() from kvm_compute_l1_tsc_offset() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 14/36] KVM: x86: Improve synchronization in kvm_synchronize_tsc() David Woodhouse
2026-07-28 15:08   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 15/36] KVM: x86: Kill last_tsc_{nsec,write,offset} fields David Woodhouse
2026-07-28 15:09   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 16/36] KVM: x86: Replace nr_vcpus_matched_tsc count with all_vcpus_matched_tsc bool David Woodhouse
2026-07-28 14:39 ` [PATCH v7 17/36] KVM: x86: Allow KVM master clock mode when TSCs are offset from each other David Woodhouse
2026-07-28 14:39 ` [PATCH v7 18/36] KVM: x86: Factor out kvm_use_master_clock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 19/36] KVM: x86: Avoid gratuitous global clock updates David Woodhouse
2026-07-28 14:40 ` [PATCH v7 20/36] KVM: x86/xen: Prevent runstate times from becoming negative David Woodhouse
2026-07-28 15:15   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 21/36] KVM: x86: Avoid redundant masterclock updates from multiple vCPUs David Woodhouse
2026-07-28 15:23   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 22/36] KVM: x86: Remove runtime Xen TSC frequency CPUID update David Woodhouse
2026-07-28 15:18   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 23/36] KVM: x86: Re-synchronize TSC after KVM_SET_TSC_KHZ David Woodhouse
2026-07-28 15:19   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 24/36] KVM: x86: Use ktime_get_snapshot_id() for master clock David Woodhouse
2026-07-28 15:21   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 25/36] KVM: x86: Compute kvmclock base without pvclock_gtod_data David Woodhouse
2026-07-28 14:40 ` [PATCH v7 26/36] KVM: x86: Cache host vclock_mode for masterclock eligibility checks David Woodhouse
2026-07-28 15:26   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 27/36] KVM: x86: Remove pvclock_gtod_data and private timekeeping code David Woodhouse
2026-07-28 15:25   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 28/36] KVM: x86: Activate master clock from kvm_arch_init_vm() David Woodhouse
2026-07-28 15:31   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 29/36] UAPI: x86: Move pvclock-abi to UAPI for x86 platforms David Woodhouse
2026-07-28 14:40 ` [PATCH v7 30/36] KVM: selftests: Use UAPI pvclock-abi.h in xen_shinfo_test David Woodhouse
2026-07-28 14:40 ` [PATCH v7 31/36] KVM: x86: Add KVM_[GS]ET_CLOCK_GUEST for accurate KVM clock migration David Woodhouse
2026-07-28 14:40 ` [PATCH v7 32/36] KVM: x86: Add KVM_VCPU_TSC_SCALE and fix the documentation on TSC migration David Woodhouse
2026-07-28 15:26   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 33/36] KVM: selftests: Add KVM/PV clock selftest to prove timer correction David Woodhouse
2026-07-28 14:40 ` [PATCH v7 34/36] KVM: selftests: Add master clock offset test David Woodhouse
2026-07-28 15:22   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 35/36] KVM: selftests: Add Xen/generic CPUID timing leaf test David Woodhouse
2026-07-28 15:23   ` sashiko-bot [this message]
2026-07-28 14:40 ` [PATCH v7 36/36] KVM: selftests: Add Xen runstate migration test David Woodhouse

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728152357.9C2581F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dwmw2@infradead.org \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox