From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f176.google.com (mail-yw1-f176.google.com [209.85.128.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 410DF37E2F3 for ; Tue, 25 Aug 2026 18:39:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.176 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787683179; cv=none; b=nMnVh2j4IsyKGkVFhl8Rn9J+j8mGoSK3biby0q23rH4plnsVFioclNgl4nQasLZqSqmuVTXfI0y4wiAdp/G4D+mjpU+qB4tZ0cCN9Slh0oEZ9UNDOSyQF5kiF3lW6jt8WRa8YK0DYSVgQb6OzyMRMOgD34OfV0BY7KjTiukz0ug= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787683179; c=relaxed/simple; bh=RdeEnUyZxdCR6MrqtuNxlBJrc3Eh5JtCEqB3t4sF5uw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dHnNwDwpuF/hDp1TutxGRQpMkMAEpuGyQDREopOeYSGftvN238/HPErDdll3gx+v7tyLkwjK046axUqToUGgFq2X9NFABWMfQDrr3+WGNoFrFZFzNbBngzoxuJQ+8YIzW8zmATTEp/Q2hP0KRG8PJkAexVBIDv4ormFblTHTmZs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ddZpj1LR; arc=none smtp.client-ip=209.85.128.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ddZpj1LR" Received: by mail-yw1-f176.google.com with SMTP id 00721157ae682-81c7245eebcso12297b3.1 for ; Tue, 25 Aug 2026 11:39:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787683177; x=1788287977; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DzDBNQWpaXJItDcAuhVID3lvsOEPud4hU73IGqDCIdQ=; b=ddZpj1LR9AKheN6rsa5JhlqXbXllfuPWAMS/Z+dvYFRz0SmNa6v634DDeD/gWtI2ye Z7rCn5l/ouOtgIwqiL2cl9TmMNbhNdHaoOJsMmrjHui3r4E2OLmKAC3A3ZrqduZpkkyR rFdcRnqrtCjDUFAgIbXDAxx4UCf+/xiqPkihXHaQ5mm0YLiEEPwIzcwlqBZKBU5FVMqV 7Ftugo1+DeHdfvPL+yiF/xfyxzQA/6XsqDQoNHbDZroriHwrSLL12bi3GNfOLOAPBGqv LtMs9Zis12hG1fd0un6SrXOZH993JLKjMgc7iOwkdR+vmWuk3QPlDudLpCUyyL37IyOW DRQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787683177; x=1788287977; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=DzDBNQWpaXJItDcAuhVID3lvsOEPud4hU73IGqDCIdQ=; b=m77CsogYVQQoCaBB1Octc3MD3Eu2xK792dfKqQcEgehqd5OdZU4K/2s+guNWvYjibv p4LvavomnqTqUnmBzzxAI1zCaV9j7IcLsAM4bq23TeuaiBm6qDHkqw1VL2FXO0rEaZNT lBM6kYozKvBPzBLVIrra26mkz8tiflTsDjBJNDl3bTd0u5nnIx9I9q0leff8ajBD6faS UbUbxtCwJt/XaWX1oNfg/bG19nBiAYsOzu7veG6xiIl336i8PoegMbjrAs2eo8r0gItF yR/0nQqDFEbyvqE/6kXXJNWNYgvFbT3EekzX2YQImfh+78uZpss0dQyw3x1k0cUOQWBU XtYQ== X-Gm-Message-State: AFuF++mC8gyTOun/RlG5X2ELCjhJZbliv9yTFMrYGT6gLDZpTtoVj68Y Ke2oyQfwyxKFxz1AIHJzoN2UAq+il09Pu0s5ximwNwU9T56v15AXVeTP X-Gm-Gg: AR+sD11u0yE/lVrLxbE2cu4rYDz6umiQjrwSGfLUBv0aXtcsfcSQAs80z8uOMgK0LGG 9HkU0IsGaH1t0f9cxD+d5ekkRCkt3WuCgQDmL44LrzwfSG0pUf0ruI8fNtptFaVUwvdWXf1fbl3 qWLSea9knmp7kZpu6JWQ3vLmKSbCCAfSUDWOf5P8oYoKl6lcyKVAS0I/02wEFPxd0kQ8aC+0m8n 88+sNoWb9waB75AL4snGYbo/yWkC4fXRNIP4Bgne4gNbFDi9FdTdlzRNg1RlxLpm3+7kSRMlbni qH0faa++RX6jKrbDAHDYr/z14uuZZG/MLquHGNIelFNlWLeISBKHSvUIFZuUAIWvU8MzMRxnTEy Bb6BY2dbq3lzRx/MIIfIvelWYrmaj1uEyK+HUP8Se3QPZtLCuLFmfQAmMUO+RplVTPFW8EWkOOj bolhC5B8ANC87AhaN7wyaOi1kJHIaMFHYwR/UThqXvQtb5moYwTgm4uR5nEAF2ZvUbb4dl16IqD 7SQqZSb4ZHSBTNQRHuWrTF1Jo8Jh38XqGasjkWRa74amzm2epaeXRBobA== X-Received: by 2002:a05:690c:c4e1:b0:820:100e:1abb with SMTP id 00721157ae682-8574105820cmr4191967b3.4.1787683177092; Tue, 25 Aug 2026 11:39:37 -0700 (PDT) Received: from localhost.localdomain (45.78.64.189.16clouds.com. [45.78.64.189]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8570d237bf4sm3988007b3.38.2026.08.25.11.39.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 11:39:36 -0700 (PDT) From: Chengfeng Ye To: Sean Christopherson , Paolo Bonzini , Kai Huang , Yan Zhao Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH v2] KVM: x86: Take SRCU in kvm_zap_gfn_range() Date: Wed, 26 Aug 2026 02:39:24 +0800 Message-ID: <20260825183924.237727-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260822190224.3788887-1-nicoyip.dev@gmail.com> References: <20260822190224.3788887-1-nicoyip.dev@gmail.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit kvm_zap_gfn_range() walks memslots and rmaps and may drop mmu_lock to reschedule. Callers that do not already hold kvm->srcu (or slots_lock) can race with memslot deletion: synchronize_srcu_expedited() does not wait, kvm_free_memslot() frees the old slot and its rmap, and the zap resumes on freed memory. The VFIO noncoherent-DMA path hits this by zapping the entire GPA space without SRCU. KASAN reported: BUG: KASAN: vmalloc-out-of-bounds in slot_rmap_walk_next+0x82/0x1c0 Read of size 8 at addr ffffc900005c1008 Call Trace: slot_rmap_walk_next+0x82/0x1c0 __kvm_rmap_zap_gfn_range+0x17a/0x280 kvm_zap_gfn_range+0x2a6/0x6a0 kvm_vfio_set_attr+0x576/0x770 kvm_device_ioctl+0x1ff/0x3b0 Take SRCU inside kvm_zap_gfn_range() so every caller is covered. Nesting with an existing kvm->srcu critical section is fine; the helper uses a local index. Drop the now-redundant SRCU pair from __kvm_set_or_clear_apicv_inhibit(). Fixes: 362ff6dca541 ("KVM: x86/mmu: Zap KVM TDP when noncoherent DMA assignment starts/stops") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- v2: - Take SRCU inside kvm_zap_gfn_range() with guard(srcu)(), as suggested by Sean Christopherson, instead of wrapping only the noncoherent-DMA caller. - Drop the now-redundant SRCU pair from __kvm_set_or_clear_apicv_inhibit(). Nested kvm->srcu is fine; only kvm_vcpu_srcu_read_lock() cannot nest with itself. arch/x86/kvm/mmu/mmu.c | 2 ++ arch/x86/kvm/x86.c | 2 -- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index a61750f8e1e3..ae55a77e5a05 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -7047,6 +7047,8 @@ void kvm_zap_gfn_range(struct kvm *kvm, gfn_t gfn_start, gfn_t gfn_end) if (WARN_ON_ONCE(gfn_end <= gfn_start)) return; + guard(srcu)(&kvm->srcu); + write_lock(&kvm->mmu_lock); kvm_mmu_invalidate_start(kvm); diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index 69469bbdc84a..adccd4a8e6c1 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -10986,10 +10986,8 @@ void __kvm_set_or_clear_apicv_inhibit(struct kvm *kvm, kvm->arch.apicv_inhibit_reasons = new; if (new) { unsigned long gfn = gpa_to_gfn(APIC_DEFAULT_PHYS_BASE); - int idx = srcu_read_lock(&kvm->srcu); kvm_zap_gfn_range(kvm, gfn, gfn+1); - srcu_read_unlock(&kvm->srcu, idx); } } else { kvm->arch.apicv_inhibit_reasons = new; -- 2.43.0