From: Sascha Bischoff <Sascha.Bischoff@arm.com>
To: "sashiko-reviews@lists.linux.dev" <sashiko-reviews@lists.linux.dev>
Cc: "maz@kernel.org" <maz@kernel.org>,
"kvmarm@lists.linux.dev" <kvmarm@lists.linux.dev>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"oupton@kernel.org" <oupton@kernel.org>, nd <nd@arm.com>
Subject: Re: [PATCH v5 08/49] KVM: arm64: gic-v5: Add VPE doorbell domain
Date: Fri, 4 Sep 2026 07:27:25 +0000 [thread overview]
Message-ID: <656d6e34e988102b53ed98c0bef1073ed00d5394.camel@arm.com> (raw)
In-Reply-To: <20260807124506.ED85C1F000E9@smtp.kernel.org>
On Fri, 2026-08-07 at 12:45 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 4 potential
> issue(s) to consider:
> - [High] Resource leak of GICv5 VPE doorbell domain and fwnode on
> VGIC initialization retry.
> - [High] TOCTOU race between `KVM_CREATE_VCPU` and
> `KVM_DEV_ARM_VGIC_CTRL_INIT` leads to undersized doorbell domain
> allocation.
> - [Medium] Fwnode ID collision for VMs created by the same userspace
> thread.
> - [Low] Unreachable dead code in doorbell domain error handling path.
> --
>
> --- Patch [8]: [PATCH v5 08/49] KVM: arm64: gic-v5: Add VPE doorbell
> domain ---
> commit 087989feef3777beedf75a01512da5b9e331b6fa
> Author: Sascha Bischoff <Sascha.Bischoff@arm.com>
> KVM: arm64: gic-v5: Add VPE doorbell domain
>
> This commit adds support for a per-VM VPE doorbell irq domain for
> GICv5.
> It creates the domain under the GICv5 LPI domain with one doorbell
> allocated
> per VPE, and stores the state for later IRS commands and wakeups.
>
> diff --git a/arch/arm64/kvm/vgic/vgic-v5.c
> b/arch/arm64/kvm/vgic/vgic-v5.c
> index 41ca2098ecb73..752329fc3d566 100644
> --- a/arch/arm64/kvm/vgic/vgic-v5.c
> +++ b/arch/arm64/kvm/vgic/vgic-v5.c
> [ ... ]
> > +static int vgic_v5_create_per_vm_domain(struct kvm *kvm)
> > +{
> > + struct vgic_v5_vm *vm = &kvm->arch.vgic.gicv5_vm;
> > + int nr_vcpus = atomic_read(&kvm->online_vcpus);
>
> [Severity: High]
> Can a race condition here lead to an undersized doorbell domain
> allocation?
>
> If a userspace thread calls the initialization ioctl, it checks for
> concurrent
> VCPU creation, but this check is performed locklessly with respect to
> the
> kvm->lock held during VCPU creation.
>
> Concurrently, a second thread could create a VCPU, which takes kvm-
> >lock and
> increments created_vcpus. Since initialization hasn't completed yet,
> VCPU
> creation is allowed to proceed.
>
> When the first thread reaches this point, it allocates exactly the
> number
> of online VCPUs at this moment. As the second thread completes and
> increments
> online_vcpus, the VM now has more VCPUs than allocated doorbell IRQs,
> which
> can lead to out-of-bounds IRQ array access later.
Agreed, I think that this is an issue. The existing check only detects
vCPU creation that is already in progress. Since CTRL_INIT does not
hold kvm->lock, another creation can start afterwards and leave the
per-vCPU resources, including the doorbell domain, undersized. FWIW, I
think this affects GICv4, too.
I will post a separate fixup to serialise CTRL_INIT against vCPU
creation.
>
> > + int id = task_pid_nr(current);
> > + int ret, db_virq = 0;
> > +
> > + if (!gicv5_global_data.lpi_domain) {
> > + kvm_err("LPI domain uninitialized, can't set up
> > KVM Doorbells\n");
> > + return -ENODEV;
> > + }
> > +
> > + vm->fwnode = irq_domain_alloc_named_id_fwnode("GICv5-vpe-
> > db", id);
>
> [Severity: High]
> Can this leak the GICv5 VPE doorbell domain and fwnode if
> initialization
> is retried?
>
> If the initialization fails later in the setup process (for example,
> if
> kvm_vgic_setup_default_irq_routing() fails in vgic_init()), the VGIC
> state
> remains uninitialized.
>
> If userspace then retries the initialization, this function is called
> again
> and unconditionally allocates a new fwnode and IRQ domain,
> overwriting
> the previous pointers without freeing them.
I've updated this commit to call vgic_v5_teardown() on subsequent
failure. This way no state is leaked.
>
>
> [Severity: Medium]
> Could using the thread ID here cause fwnode naming collisions?
>
> Since task_pid_nr(current) is used as the ID for the fwnode name, a
> single
> VMM thread sequentially creating multiple KVM VMs will cause them to
> share
> the exact same fwnode name.
>
> When the IRQ domain is registered, this duplicate name causes debugfs
> directory creation failures due to the directory already being
> present.
>
> Would it be more reliable to use the VM's unique vm_id instead?
The current code matches what GICv4 does for the fwnode. In my
knowledge, it isn't a common thing for a single thread to create
multiple VMs. If this is indeed an issue, it can be revisited and
fixed, but the for the time being I suggest leaving this as is.
>
> > + if (!vm->fwnode)
> > + return -ENOMEM;
> [ ... ]
> > + db_virq = irq_domain_alloc_irqs(vm->domain, nr_vcpus,
> > NUMA_NO_NODE, vm);
> > + if (db_virq <= 0) {
> > + ret = db_virq;
> > + goto err;
> > + }
> > +
> > + kvm->arch.vgic.gicv5_vm.vpe_db_base = db_virq;
> > +
> > + return 0;
> > +
> > +err:
> > + if (db_virq > 0)
>
> [Severity: Low]
> Is this error cleanup path unreachable?
>
> The only branch that jumps to the err label after modifying db_virq
> explicitly checks that db_virq is less than or equal to 0.
>
> Because db_virq can never be strictly positive at this label, the
> irq_domain_free_irqs() block will never be executed.
True. Dropped the unreachable code.
>
> > + irq_domain_free_irqs(db_virq, nr_vcpus);
> > + if (vm->domain)
> > + irq_domain_remove(vm->domain);
> [ ... ]
>
Thanks,
Sascha
next prev parent reply other threads:[~2026-09-04 7:28 UTC|newest]
Thread overview: 118+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-07 11:12 [PATCH v5 00/49] KVM: arm64: Add GICv5 IRS support Sascha Bischoff
2026-08-07 11:13 ` [PATCH v5 01/49] irqchip/gic-v5: Allow KVM setup without a maintenance IRQ Sascha Bischoff
2026-08-07 11:13 ` [PATCH v5 02/49] irqchip/gic-v5: Provide OF IRS config frame attrs to KVM Sascha Bischoff
2026-08-07 11:53 ` sashiko-bot
2026-09-03 14:20 ` Sascha Bischoff
2026-08-07 11:14 ` [PATCH v5 03/49] irqchip/gic-v5: Set up gic_kvm_info on ACPI hosts Sascha Bischoff
2026-08-07 12:01 ` sashiko-bot
2026-09-03 14:22 ` Sascha Bischoff
2026-08-07 13:44 ` Lorenzo Pieralisi
2026-09-03 14:25 ` Sascha Bischoff
2026-08-07 11:14 ` [PATCH v5 04/49] KVM: arm64: gic-v5: Define remaining IRS MMIO registers Sascha Bischoff
2026-08-07 12:05 ` sashiko-bot
2026-09-03 14:34 ` Sascha Bischoff
2026-08-07 11:15 ` [PATCH v5 05/49] arm64/sysreg: Add GICv5 GIC VDPEND encoding Sascha Bischoff
2026-08-07 11:15 ` [PATCH v5 06/49] arm64/sysreg: Update ICC_CR0_EL1 with LINK and LINK_IDLE fields Sascha Bischoff
2026-08-07 12:17 ` sashiko-bot
2026-09-03 16:33 ` Sascha Bischoff
2026-08-07 11:16 ` [PATCH v5 07/49] KVM: arm64: gic-v5: Cache host IRS ID registers Sascha Bischoff
2026-08-07 12:27 ` sashiko-bot
2026-09-04 6:36 ` Sascha Bischoff
2026-08-07 11:16 ` [PATCH v5 08/49] KVM: arm64: gic-v5: Add VPE doorbell domain Sascha Bischoff
2026-08-07 12:45 ` sashiko-bot
2026-09-04 7:27 ` Sascha Bischoff [this message]
2026-08-07 11:17 ` [PATCH v5 09/49] KVM: arm64: gic-v5: Create and manage VM and VPE tables Sascha Bischoff
2026-08-07 12:50 ` sashiko-bot
2026-09-04 8:00 ` Sascha Bischoff
2026-08-07 11:17 ` [PATCH v5 10/49] KVM: arm64: gic-v5: Introduce guest IST alloc and management Sascha Bischoff
2026-08-07 13:07 ` sashiko-bot
2026-09-04 8:08 ` Sascha Bischoff
2026-08-07 11:18 ` [PATCH v5 11/49] KVM: arm64: gic-v5: Implement VMT/vIST IRS MMIO Ops Sascha Bischoff
2026-08-07 13:13 ` sashiko-bot
2026-09-04 8:15 ` Sascha Bischoff
2026-08-07 11:18 ` [PATCH v5 12/49] KVM: arm64: gic-v5: Keep GICv5 vCPU limit model-specific Sascha Bischoff
2026-08-07 13:30 ` sashiko-bot
2026-09-04 10:03 ` Sascha Bischoff
2026-08-07 11:19 ` [PATCH v5 13/49] KVM: arm64: gic-v5: Implement VPE IRS MMIO Ops Sascha Bischoff
2026-08-07 11:19 ` [PATCH v5 14/49] KVM: arm64: gic-v5: Set up VMTEs and VPE doorbells Sascha Bischoff
2026-08-07 13:42 ` sashiko-bot
2026-09-04 8:22 ` Sascha Bischoff
2026-08-07 11:20 ` [PATCH v5 15/49] KVM: arm64: gic-v5: Add resident/non-resident hyp calls Sascha Bischoff
2026-08-07 11:20 ` [PATCH v5 16/49] KVM: arm64: gic-v5: Request doorbells when VPEs enter WFI Sascha Bischoff
2026-08-07 14:17 ` sashiko-bot
2026-09-04 8:31 ` Sascha Bischoff
2026-08-07 11:21 ` [PATCH v5 17/49] KVM: arm64: gic-v5: Introduce struct vgic_v5_irs and IRS base address Sascha Bischoff
2026-08-07 11:21 ` [PATCH v5 18/49] KVM: arm64: gic-v5: Add IRS IODEV support to MMIO handlers Sascha Bischoff
2026-08-07 11:22 ` [PATCH v5 19/49] KVM: arm64: gic-v5: Add KVM_VGIC_V5_ADDR_TYPE_IRS to UAPI Sascha Bischoff
2026-08-07 14:27 ` sashiko-bot
2026-09-04 8:42 ` Sascha Bischoff
2026-08-07 11:22 ` [PATCH v5 20/49] KVM: arm64: gic-v5: Add GICv5 IRS IODEV and MMIO emulation Sascha Bischoff
2026-08-07 14:34 ` sashiko-bot
2026-09-04 8:47 ` Sascha Bischoff
2026-08-07 11:23 ` [PATCH v5 21/49] KVM: arm64: gic-v5: Initialise per-VM IRS state Sascha Bischoff
2026-08-07 14:49 ` sashiko-bot
2026-09-04 8:51 ` Sascha Bischoff
2026-08-07 11:23 ` [PATCH v5 22/49] KVM: arm64: gic-v5: Register the IRS IODEV Sascha Bischoff
2026-08-07 14:52 ` sashiko-bot
2026-09-04 8:57 ` Sascha Bischoff
2026-08-07 11:24 ` [PATCH v5 23/49] KVM: arm64: gic-v5: Set IRICHPPIDIS based on IRS enable state Sascha Bischoff
2026-08-07 11:24 ` [PATCH v5 24/49] KVM: arm64: selftests: Update vGICv5 selftest to set IRS address Sascha Bischoff
2026-08-07 15:04 ` sashiko-bot
2026-09-04 9:03 ` Sascha Bischoff
2026-08-07 11:25 ` [PATCH v5 25/49] KVM: arm64: gic-v5: Add GIC VDPEND hyp call Sascha Bischoff
2026-08-07 11:25 ` [PATCH v5 26/49] KVM: arm64: gic: Introduce set_pending_state() to irq_ops Sascha Bischoff
2026-08-07 15:14 ` sashiko-bot
2026-09-04 9:28 ` Sascha Bischoff
2026-08-07 11:26 ` [PATCH v5 27/49] KVM: arm64: gic-v5: Support SPI injection Sascha Bischoff
2026-08-07 15:23 ` sashiko-bot
2026-09-04 9:22 ` Sascha Bischoff
2026-08-07 11:26 ` [PATCH v5 28/49] Documentation: KVM: Extend VGICv5 device attribute docs Sascha Bischoff
2026-08-07 15:29 ` sashiko-bot
2026-09-04 9:30 ` Sascha Bischoff
2026-08-07 11:27 ` [PATCH v5 29/49] KVM: arm64: gic-v5: Add GICv5 SPI injection to irqfd Sascha Bischoff
2026-08-07 15:40 ` sashiko-bot
2026-09-04 9:47 ` Sascha Bischoff
2026-08-07 11:27 ` [PATCH v5 30/49] KVM: arm64: gic-v5: Mask per-vCPU PPI state in vgic_v5_finalize_ppi_state() Sascha Bischoff
2026-08-07 11:28 ` [PATCH v5 31/49] KVM: arm64: gic-v5: Add GICv5 EL1 sysreg userspace accessors Sascha Bischoff
2026-08-07 16:27 ` sashiko-bot
2026-09-04 10:01 ` Sascha Bischoff
2026-08-07 11:28 ` [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region Sascha Bischoff
2026-08-07 16:20 ` sashiko-bot
2026-09-04 9:59 ` Sascha Bischoff
2026-08-07 11:29 ` [PATCH v5 33/49] KVM: arm64: gic-v5: Add CoreSight MMIO regs to IRS Sascha Bischoff
2026-08-07 11:29 ` [PATCH v5 34/49] KVM: arm64: gic-v5: Add VGICv5 IST save/restore UAPI Sascha Bischoff
2026-08-07 16:30 ` sashiko-bot
2026-09-04 10:06 ` Sascha Bischoff
2026-08-07 11:30 ` [PATCH v5 35/49] KVM: arm64: gic-v5: Implement save/restore mechanisms for ISTs Sascha Bischoff
2026-08-07 16:48 ` sashiko-bot
2026-09-04 10:23 ` Sascha Bischoff
2026-08-07 11:30 ` [PATCH v5 36/49] Documentation: KVM: Document KVM_DEV_ARM_VGIC_GRP_CPU_SYSREGS for VGICv5 Sascha Bischoff
2026-08-07 16:55 ` sashiko-bot
2026-09-04 11:04 ` Sascha Bischoff
2026-08-07 11:31 ` [PATCH v5 37/49] Documentation: KVM: Add KVM_DEV_ARM_VGIC_GRP_IRS_REGS to VGICv5 docs Sascha Bischoff
2026-08-07 16:52 ` sashiko-bot
2026-09-04 10:09 ` Sascha Bischoff
2026-08-07 11:31 ` [PATCH v5 38/49] Documentation: KVM: Add docs for KVM_DEV_ARM_VGIC_GRP_IST Sascha Bischoff
2026-08-07 11:32 ` [PATCH v5 39/49] Documentation: KVM: Add the VGICv5 IRS save/restore sequences Sascha Bischoff
2026-08-07 11:32 ` [PATCH v5 40/49] KVM: selftests: Add VGICv5 IRS address attribute tests Sascha Bischoff
2026-08-07 11:33 ` [PATCH v5 41/49] KVM: selftests: Add VGICv5 NR_IRQS " Sascha Bischoff
2026-08-07 17:12 ` sashiko-bot
2026-09-04 10:15 ` Sascha Bischoff
2026-08-07 11:33 ` [PATCH v5 42/49] KVM: selftests: Add VGICv5 IRS_REGS " Sascha Bischoff
2026-08-07 17:17 ` sashiko-bot
2026-09-04 10:38 ` Sascha Bischoff
2026-08-07 11:34 ` [PATCH v5 43/49] KVM: selftests: Add VGICv5 IST " Sascha Bischoff
2026-08-07 17:21 ` sashiko-bot
2026-09-04 10:45 ` Sascha Bischoff
2026-08-07 11:35 ` [PATCH v5 44/49] KVM: selftests: Add VGICv5 USERSPACE_PPIS tests Sascha Bischoff
2026-08-07 11:35 ` [PATCH v5 45/49] KVM: selftests: Add VGICv5 CPU sysreg attribute tests Sascha Bischoff
2026-08-07 11:36 ` [PATCH v5 46/49] KVM: selftests: Add VGICv5 SPI injection tests Sascha Bischoff
2026-08-07 11:36 ` [PATCH v5 47/49] KVM: selftests: Add VGICv5 LPI delivery tests Sascha Bischoff
2026-08-07 17:39 ` sashiko-bot
2026-09-04 10:48 ` Sascha Bischoff
2026-08-07 11:37 ` [PATCH v5 48/49] KVM: selftests: Add VGICv5 IST save/restore coverage Sascha Bischoff
2026-08-07 17:50 ` sashiko-bot
2026-09-04 10:54 ` Sascha Bischoff
2026-08-07 11:37 ` [PATCH v5 49/49] KVM: selftests: Add VGICv5 sparse vCPU IDs test Sascha Bischoff
2026-08-07 17:56 ` sashiko-bot
2026-09-04 10:57 ` Sascha Bischoff
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=656d6e34e988102b53ed98c0bef1073ed00d5394.camel@arm.com \
--to=sascha.bischoff@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=nd@arm.com \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox