From: Claudio Imbrenda <imbrenda@linux.ibm.com>
To: linux-kernel@vger.kernel.org
Cc: kvm@vger.kernel.org, linux-s390@vger.kernel.org,
borntraeger@de.ibm.com, frankja@linux.ibm.com, david@kernel.org,
seiden@linux.ibm.com, nrb@linux.ibm.com,
schlameuss@linux.ibm.com, gra@linux.ibm.com
Subject: [PATCH v3 8/8] KVM: s390: Fix race in _destroy_pages_crste()
Date: Fri, 28 Aug 2026 13:54:39 +0200 [thread overview]
Message-ID: <20260828115439.145885-9-imbrenda@linux.ibm.com> (raw)
In-Reply-To: <20260828115439.145885-1-imbrenda@linux.ibm.com>
Use READ_ONCE() in _destroy_pages_crste() to read the crste, avoid
dereferencing the pointer multiple times.
Fixes: a2c17f9270cc ("KVM: s390: New gmap code")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
---
arch/s390/kvm/gmap/gmap.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/arch/s390/kvm/gmap/gmap.c b/arch/s390/kvm/gmap/gmap.c
index 4968330e9553..3f3fa864cc36 100644
--- a/arch/s390/kvm/gmap/gmap.c
+++ b/arch/s390/kvm/gmap/gmap.c
@@ -994,11 +994,13 @@ static long _destroy_pages_pte(union pte *ptep, gfn_t gfn, gfn_t next, struct da
static long _destroy_pages_crste(union crste *crstep, gfn_t gfn, gfn_t next, struct dat_walk *walk)
{
phys_addr_t origin, cur, end;
+ union crste crste;
- if (!crstep->h.fc || !crstep->s.fc1.pr)
+ crste = READ_ONCE(*crstep);
+ if (!crste.h.fc || !crste.s.fc1.pr)
return 0;
- origin = crste_origin_large(*crstep);
+ origin = crste_origin_large(crste);
cur = ((max(gfn, walk->start) - gfn) << PAGE_SHIFT) + origin;
end = ((min(next, walk->end) - gfn) << PAGE_SHIFT) + origin;
for ( ; cur < end; cur += PAGE_SIZE)
--
2.55.0
next prev parent reply other threads:[~2026-08-28 11:54 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 11:54 [PATCH v3 0/8] KVM: s390: Even more misc fixes Claudio Imbrenda
2026-08-28 11:54 ` [PATCH v3 1/8] KVM: s390: Fix dirty marking in adapter_indicators_set*() Claudio Imbrenda
2026-08-28 12:08 ` sashiko-bot
2026-08-28 11:54 ` [PATCH v3 2/8] KVM: s390: Fix compile warning for kvm_s390_update_cmma_dirty() Claudio Imbrenda
2026-08-28 12:02 ` sashiko-bot
2026-08-28 11:54 ` [PATCH v3 3/8] KVM: s390: Fix _gaccess_shadow_fault() Claudio Imbrenda
2026-08-28 12:08 ` sashiko-bot
2026-08-28 11:54 ` [PATCH v3 4/8] KVM: s390: Refactor dat_set_slot() Claudio Imbrenda
2026-08-28 12:05 ` sashiko-bot
2026-08-28 11:54 ` [PATCH v3 5/8] KVM: s390: Move all code into s390_kvm_mmu_prepare_memory_region() Claudio Imbrenda
2026-08-28 12:07 ` sashiko-bot
2026-08-28 11:54 ` [PATCH v3 6/8] KVM: s390: Add missing srcu in kvm_s390_set_irq_state() Claudio Imbrenda
2026-08-28 12:10 ` sashiko-bot
2026-08-28 11:54 ` [PATCH v3 7/8] KVM: s390: Fix potential races in dat skey functions Claudio Imbrenda
2026-08-28 12:08 ` sashiko-bot
2026-08-28 11:54 ` Claudio Imbrenda [this message]
2026-08-28 12:18 ` [PATCH v3 8/8] KVM: s390: Fix race in _destroy_pages_crste() sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260828115439.145885-9-imbrenda@linux.ibm.com \
--to=imbrenda@linux.ibm.com \
--cc=borntraeger@de.ibm.com \
--cc=david@kernel.org \
--cc=frankja@linux.ibm.com \
--cc=gra@linux.ibm.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=nrb@linux.ibm.com \
--cc=schlameuss@linux.ibm.com \
--cc=seiden@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox