Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rick Edgecombe" <rick.p.edgecombe@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v10 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put()
Date: Thu, 03 Sep 2026 02:03:02 +0000	[thread overview]
Message-ID: <20260903020303.349961F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903015113.93343-6-rick.p.edgecombe@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] tdx_find_dpamt_refcount() uses an unchecked PFN to index the dpamt_refcounts array, leading to out-of-bounds memory access.
--

commit 413476a1747fac53ffdaf87030c42cb8b25bc668
Author: Rick Edgecombe <rick.p.edgecombe@intel.com>

x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put()

This patch refcounts the dynamic PAMT additions for 2MB regions so multiple
callers can safely share them. It also drops the "__" prefix from the
helpers and exports them for use by KVM.

> diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
> index e8bdeacd989d6..a126e395f5f6a 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.c
> +++ b/arch/x86/virt/vmx/tdx/tdx.c
> @@ -292,7 +292,7 @@ static __init void free_dpamt_refcounts(void)
>  	dpamt_refcounts = NULL;
>  }
>  
> -static __maybe_unused atomic_t *tdx_find_dpamt_refcount(unsigned long pfn)
> +static atomic_t *tdx_find_dpamt_refcount(unsigned long pfn)
>  {
>  	/* Find which PMD a PFN is in. */
>  	unsigned long index = pfn >> (PMD_SHIFT - PAGE_SHIFT);
> 
>  	return &dpamt_refcounts[index];

[Severity: High]
Does this index calculation need bounds checking?

If memory is hotplugged after boot, increasing the global max_pfn, and KVM
allocates private guest memory that lands in this hotplugged region (e.g.,
via guest_memfd), the returned PFN could be greater than the boot-time
max_pfn used to size the dpamt_refcounts array. This would lead to an
out-of-bounds pointer being returned here.

[ ... ]

> @@ -2150,41 +2144,59 @@ static int __tdx_pamt_get(kvm_pfn_t pfn)
[ ... ]
>  out_free:
> +	spin_unlock(&dpamt_lock);
>  	free_pamt_array(pamt_pages);
>  
>  	return ret;
>  }
> +EXPORT_SYMBOL_FOR_KVM(tdx_pamt_get);

[Severity: High]
Is it safe to export this function without adding bounds checking to
tdx_find_dpamt_refcount()?

Exporting this helper allows external callers like KVM to pass in arbitrary
or hotplugged PFNs. If a hotplugged PFN is passed, the resulting
out-of-bounds pointer from tdx_find_dpamt_refcount() will be modified by
atomic_inc_not_zero() and atomic_set() within this function, potentially
causing memory corruption or a host kernel panic.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903015113.93343-1-rick.p.edgecombe@intel.com?part=5

  reply	other threads:[~2026-09-03  2:03 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  1:51 [PATCH v10 00/11] Dynamic PAMT Rick Edgecombe
2026-09-03  1:51 ` [PATCH v10 01/11] x86/virt/tdx: Simplify PAMT layout calculation Rick Edgecombe
2026-09-03  1:51 ` [PATCH v10 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-09-03  1:51 ` [PATCH v10 03/11] x86/virt/tdx: Add __tdx_pamt_get/put() helpers Rick Edgecombe
2026-09-03 15:28   ` Dave Hansen
2026-09-03  1:51 ` [PATCH v10 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory Rick Edgecombe
2026-09-03 15:30   ` Dave Hansen
2026-09-03 18:33     ` Edgecombe, Rick P
2026-09-03  1:51 ` [PATCH v10 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put() Rick Edgecombe
2026-09-03  2:03   ` sashiko-bot [this message]
2026-09-03 23:16     ` Edgecombe, Rick P
2026-09-03  1:51 ` [PATCH v10 06/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-09-03  1:51 ` [PATCH v10 07/11] x86/virt/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-09-03  1:51 ` [PATCH v10 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
2026-09-03  2:14   ` sashiko-bot
2026-09-03 22:44     ` Edgecombe, Rick P
2026-09-03  1:51 ` [PATCH v10 09/11] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
2026-09-03 15:38   ` Dave Hansen
2026-09-03  1:51 ` [PATCH v10 10/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-09-03 15:47   ` Dave Hansen
2026-09-03 19:31     ` Edgecombe, Rick P
2026-09-03 19:36       ` Dave Hansen
2026-09-03 20:39         ` Edgecombe, Rick P
2026-09-03 20:45           ` Dave Hansen
2026-09-03  1:51 ` [PATCH v10 11/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903020303.349961F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox