Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ackerley Tng" <ackerleytng@google.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH RFC 12/17] KVM: selftests: Test guest_memfd with mounted tmpfs root directory
Date: Sat, 26 Sep 2026 01:01:04 +0000	[thread overview]
Message-ID: <20260926010105.4A5B01F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925-gmem-tmpfs-backend-v1-12-d36159822d18@google.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] selftests/kvm: guest_memfd_test unconditionally aborts on non-THP kernels
- [Low] selftests/kvm: unhandled TEST_ASSERT failures leak host tmpfs mounts
--

commit 7820bbcbdad0955765992f96c9032de44d05bad4
Author: Ackerley Tng <ackerleytng@google.com>

KVM: selftests: Test guest_memfd with mounted tmpfs root directory

This commit adds test coverage to verify that opening the root directory
of an existing mounted tmpfs filesystem and passing its file descriptor
as the resource pool succeeds across guest_memfd subtests.

> diff --git a/tools/testing/selftests/kvm/guest_memfd_test.c b/tools/testing/selftests/kvm/guest_memfd_test.c
> index 73212d5307049..94ef64474f2a0 100644
> --- a/tools/testing/selftests/kvm/guest_memfd_test.c
> +++ b/tools/testing/selftests/kvm/guest_memfd_test.c
> @@ -541,66 +543,122 @@ static void test_resource_fd_tmpfs_huge(struct kvm_vm *vm)
>  	close(pool_fd);
>  }

[Severity: Medium]
Does test_resource_fd_tmpfs_huge() unconditionally abort on non-THP kernels?

It appears this test calls create_tmpfs_pool_fd("always", ...) which relies on
TEST_ASSERT() to verify the fsconfig system call. If the host kernel is built
without Transparent Hugepage support (CONFIG_TRANSPARENT_HUGEPAGE=n), tmpfs
will reject the "huge" mount option with EINVAL.

Since the assertion fails, does this fatally terminate the entire test suite
rather than gracefully skipping this specific THP test?

> -#define ____gmem_test(__test, __vm, __flags, __gmem_size, args...)		\
> +enum gmem_pool_type {
> +	GMEM_POOL_NONE,
> +	GMEM_POOL_FSMOUNT,
> +	GMEM_POOL_MOUNTED_DIR,
> +};
> +
> +struct gmem_pool {
> +	int fd;
> +	char path[PATH_MAX];
> +	bool is_mounted;
> +};
> +
> +static struct gmem_pool create_gmem_pool(size_t size, enum gmem_pool_type type)
> +{
[ ... ]
> +	strcpy(pool.path, "/tmp/gmem_test_dir_XXXXXX");
> +	TEST_ASSERT(mkdtemp(pool.path), "mkdtemp failed");
> +
> +	if (syscall(__NR_move_mount, mnt_fd, "", AT_FDCWD, pool.path,
> +		    MOVE_MOUNT_F_EMPTY_PATH)) {
> +		close(mnt_fd);
> +		rmdir(pool.path);
> +		TEST_REQUIRE(false);
> +	}
> +	close(mnt_fd);
> +
> +	pool.fd = open(pool.path, O_RDONLY | O_DIRECTORY);
> +	TEST_ASSERT(pool.fd >= 0, "open mounted tmpfs root failed");
> +	pool.is_mounted = true;
> +
> +	return pool;
> +}
[ ... ]
> +#define ____gmem_test(__test, __vm, __flags, __pool_type, __gmem_size, args...)	\
>  do {										\
> -	int pool_fd = -1;							\
> +	struct gmem_pool pool = { .fd = -1 };					\
>  	int fd;									\
>  										\
>  	if ((__flags) & GUEST_MEMFD_FLAG_USE_RESOURCE) {			\
> -		pool_fd = create_tmpfs_pool_fd("never", true, __gmem_size);	\
> +		pool = create_gmem_pool(__gmem_size, __pool_type);		\
>  		fd = vm_create_guest_memfd_resource(__vm, __gmem_size,		\
> -						    __flags, pool_fd);		\
> +						    __flags, pool.fd);		\
>  	} else {								\
>  		fd = vm_create_guest_memfd(__vm, __gmem_size, __flags);	\
>  	}									\
>  										\
>  	test_##__test(args);							\
>  	close(fd);								\
> -	if (pool_fd >= 0)							\
> -		close(pool_fd);							\
> +	destroy_gmem_pool(&pool);						\
>  } while (0)

[Severity: Low]
Can TEST_ASSERT failures in the test macros leak host tmpfs mounts?

In create_gmem_pool(), the tmpfs mount is attached to a persistent host path
in the host's temporary directory when using GMEM_POOL_MOUNTED_DIR. This is
done without unsharing the mount namespace.

If test_##__test() triggers a TEST_ASSERT failure, process execution will
terminate immediately. This bypasses the call to destroy_gmem_pool(), leaving
persistent mount points in the host environment. Repeated test failures could
pollute the host environment and consume system resources over time.

Is there a way to unshare the mount namespace or register a cleanup handler
so that abrupt test terminations don't leak mounts on the host?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925-gmem-tmpfs-backend-v1-0-d36159822d18@google.com?part=12

  reply	other threads:[~2026-09-26  1:01 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26  0:50 [PATCH RFC 00/17] Allow guest_memfd to be created using a resource (pool) fd Ackerley Tng via B4 Relay
2026-09-26  0:50 ` [PATCH RFC 01/17] mm: shmem: Implement guest_memfd provider operations for tmpfs Ackerley Tng via B4 Relay
2026-09-26  1:08   ` sashiko-bot
2026-10-01 13:07   ` David Woodhouse
2026-10-01 14:17     ` Jason Gunthorpe
2026-10-01 15:47       ` David Woodhouse
2026-10-01 17:15         ` Jason Gunthorpe
2026-09-26  0:50 ` [PATCH RFC 02/17] KVM: guest_memfd: Support provider folio allocation Ackerley Tng via B4 Relay
2026-09-26  1:00   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 03/17] KVM: guest_memfd: Support provider folio invalidation Ackerley Tng via B4 Relay
2026-09-26  0:50 ` [PATCH RFC 04/17] KVM: guest_memfd: Add helper to attach resource provider file Ackerley Tng via B4 Relay
2026-09-26  1:13   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 05/17] KVM: selftests: Add helper to create guest_memfd with a resource file Ackerley Tng via B4 Relay
2026-09-26  1:00   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 06/17] KVM: selftests: Test negative validation of resource_fd argument Ackerley Tng via B4 Relay
2026-09-26  1:01   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 07/17] KVM: selftests: Test rejection of unsupported filesystem for resource_fd Ackerley Tng via B4 Relay
2026-09-26  0:56   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 08/17] KVM: selftests: Test rejection of tmpfs file " Ackerley Tng via B4 Relay
2026-09-26  0:50 ` [PATCH RFC 09/17] KVM: selftests: Test rejection of swap tmpfs mounts Ackerley Tng via B4 Relay
2026-09-26  0:57   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 10/17] KVM: selftests: Test rejection of hugepage " Ackerley Tng via B4 Relay
2026-09-26  0:58   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 11/17] KVM: selftests: Test guest_memfd with anonymous fsmount() tmpfs pool Ackerley Tng via B4 Relay
2026-09-26  1:02   ` sashiko-bot
2026-09-26  0:50 ` [PATCH RFC 12/17] KVM: selftests: Test guest_memfd with mounted tmpfs root directory Ackerley Tng via B4 Relay
2026-09-26  1:01   ` sashiko-bot [this message]
2026-09-26  0:51 ` [PATCH RFC 13/17] KVM: selftests: Test guest_memfd resource pool sharing across instances Ackerley Tng via B4 Relay
2026-09-26  0:51 ` [PATCH RFC 14/17] KVM: selftests: Test memory allocation against shared tmpfs resource pool Ackerley Tng via B4 Relay
2026-09-26  0:51 ` [PATCH RFC 15/17] KVM: selftests: Test that shared tmpfs resource pool size limit is respected Ackerley Tng via B4 Relay
2026-09-26  0:51 ` [PATCH RFC 16/17] KVM: selftests: Test guest execution with tmpfs-backed guest_memfd Ackerley Tng via B4 Relay
2026-09-26  1:07   ` sashiko-bot
2026-09-26  0:51 ` [PATCH RFC 17/17] KVM: selftests: Document testing TODOs Ackerley Tng via B4 Relay
2026-09-28 16:32 ` [PATCH RFC 00/17] Allow guest_memfd to be created using a resource (pool) fd David Woodhouse
2026-09-28 22:59   ` Ackerley Tng
2026-09-29 16:17     ` David Woodhouse
2026-09-29 23:41       ` Ackerley Tng
2026-09-30  0:08         ` David Woodhouse
2026-10-01 13:43 ` Gregory Price

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260926010105.4A5B01F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=ackerleytng@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox