From: Yeoreum Yun <yeoreum.yun@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Yeoreum Yun <yeoreum.yun@arm.com>, kvm@vger.kernel.org
Subject: Re: [PATCH RFC v2 09/20] loongarch: kvm: remove stack copy address of pXd in pXd_offset()
Date: Wed, 22 Jul 2026 20:51:18 +0100 [thread overview]
Message-ID: <amEfNn3OsxU4VYAC@e129823.arm.com> (raw)
In-Reply-To: <20260722155325.EDECD1F000E9@smtp.kernel.org>
On Wed, Jul 22, 2026 at 03:53:25PM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>
> Pre-existing issues:
> - [Critical] host_pfn_mapping_level() does not check if the PUD entry is a huge page (leaf) before traversing to the PMD level, leading to an unmapped/unaligned address dereference (Host Kernel Panic).
> --
>
> --- Patch [9]: [PATCH RFC v2 09/20] loongarch: kvm: remove stack copy address of pXd in pXd_offset() ---
> commit 2f6da9236b45d60a4f233dc4f7a63b29a762f060
> Author: Yeoreum Yun <yeoreum.yun@arm.com>
>
> loongarch: kvm: remove stack copy address of pXd in pXd_offset()
>
> This commit reworks host_pfn_mapping_level() to avoid using a stack copy
> of a pXd and passes it as an argument to pXd_offset_lockless(). This
> prepares the code for generic compile-time folded page tables.
>
> > diff --git a/arch/loongarch/kvm/mmu.c b/arch/loongarch/kvm/mmu.c
> > index e104897aa5328..837b40bb694f4 100644
> > --- a/arch/loongarch/kvm/mmu.c
> > +++ b/arch/loongarch/kvm/mmu.c
>
> [ ... ]
>
> > @@ -698,19 +698,23 @@ static int host_pfn_mapping_level(struct kvm *kvm, gfn_t gfn,
> > * value) and then p*d_offset() walks into the target huge page instead
> > * of the old page table (sees the new value).
> > */
> > - pgd = pgdp_get(pgd_offset(kvm->mm, hva));
> > + pgdp = pgd_offset(kvm->mm, hva);
> > + pgd = pgdp_get(pgdp);
> > if (pgd_none(pgd))
> > goto out;
> >
> > - p4d = p4dp_get(p4d_offset(&pgd, hva));
> > + p4dp = p4d_offset_lockless(pgdp, pgd, hva);
> > + p4d = p4dp_get(p4dp);
> > if (p4d_none(p4d) || !p4d_present(p4d))
> > goto out;
> >
> > - pud = pudp_get(pud_offset(&p4d, hva));
> > + pudp = pud_offset_lockless(p4dp, p4d, hva);
> > + pud = pudp_get(pudp);
> > if (pud_none(pud) || !pud_present(pud))
> > goto out;
> >
> > - pmd = pmdp_get(pmd_offset(&pud, hva));
> > + pmdp = pmd_offset_lockless(pudp, pud, hva);
> > + pmd = pmdp_get(pmdp);
>
> [Severity: Critical]
> This is a pre-existing issue, but could this cause a host kernel panic if the
> VM is backed by 1GB huge pages (PUD level)?
>
> In host_pfn_mapping_level(), there does not appear to be a check to see if the
> PUD entry is already a leaf before descending to the PMD level.
>
> If KVM walks the host page tables and reaches a PUD leaf entry, it seems it
> would pass the PUD leaf directly into pmd_offset_lockless() since there is no
> check similar to kvm_pte_huge() for the PUD.
>
> Because the raw PUD entry still contains flag bits like _PAGE_PRESENT and
> _PAGE_HUGE, converting it to a pointer and dereferencing it in pmdp_get() might
> result in an unaligned address dereference, leading to a crash.
>
> Would it make sense to check if the PUD is a huge page and return the mapping
> level early before trying to resolve the PMD?
>
> > if (pmd_none(pmd) || !pmd_present(pmd))
> > goto out;
AFAIK, loongarch doesn't support CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD.
So, the pud_leaf() checking is meaningless.
Therefore, this comment seems ignorable.
--
Sincerely,
Yeoreum Yun
next prev parent reply other threads:[~2026-07-22 19:51 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 15:30 [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 01/20] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 02/20] ARM: mm: make 2-level " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 03/20] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 04/20] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 05/20] MIPS: " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 06/20] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-07-22 15:51 ` sashiko-bot
2026-07-22 15:30 ` [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-07-22 15:58 ` sashiko-bot
2026-07-22 19:25 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 08/20] mm: vmscan: remove stack copy address of pud pass in wallk_pud_range() Yeoreum Yun
2026-07-22 15:56 ` sashiko-bot
2026-07-22 19:31 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 09/20] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-07-22 15:53 ` sashiko-bot
2026-07-22 19:51 ` Yeoreum Yun [this message]
2026-07-22 15:30 ` [PATCH RFC v2 10/20] riscv: " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 11/20] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 12/20] x86: mm: define pudp_set_access_flags() when CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD is enabled only Yeoreum Yun
2026-07-22 16:02 ` Dave Hansen
2026-07-22 17:27 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 13/20] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-07-22 16:07 ` sashiko-bot
2026-07-22 16:23 ` Yeoreum Yun
2026-07-22 16:11 ` Dave Hansen
2026-07-22 16:28 ` Yeoreum Yun
2026-07-22 17:37 ` Yeoreum Yun
2026-07-22 20:20 ` Dave Hansen
2026-07-22 21:00 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 14/20] x86: mm: skip pud setup when using generic compile-time folded pagetable Yeoreum Yun
2026-07-22 16:18 ` sashiko-bot
2026-07-22 19:08 ` Yeoreum Yun
2026-07-22 16:33 ` Dave Hansen
2026-07-22 17:18 ` Yeoreum Yun
2026-07-22 20:02 ` Dave Hansen
2026-07-22 20:18 ` Yeoreum Yun
2026-07-22 20:22 ` Dave Hansen
2026-07-22 20:28 ` H. Peter Anvin
2026-07-22 20:40 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 15/20] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels Yeoreum Yun
2026-07-22 16:15 ` sashiko-bot
2026-07-22 19:44 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 16/20] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 17/20] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 18/20] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 19/20] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 20/20] arm64: pgtable: convert pte_present() from macro to static inline Yeoreum Yun
2026-07-22 16:40 ` [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Dave Hansen
2026-07-22 17:30 ` Yeoreum Yun
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amEfNn3OsxU4VYAC@e129823.arm.com \
--to=yeoreum.yun@arm.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox