Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Yeoreum Yun <yeoreum.yun@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Yeoreum Yun <yeoreum.yun@arm.com>, kvm@vger.kernel.org
Subject: Re: [PATCH RFC v3 09/21] loongarch: kvm: remove stack copy address of pXd in pXd_offset()
Date: Wed, 2 Sep 2026 13:38:13 +0100	[thread overview]
Message-ID: <apgYtdl_DjBIqikK@e129823.arm.com> (raw)
In-Reply-To: <20260902121912.CF9161F000E9@smtp.kernel.org>

On Wed, Sep 02, 2026 at 12:19:12PM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [High] Missing `pud_leaf()` / huge page check before traversing to PMD level, causing invalid memory dereference on 1GB huge pages.
> --
> 
> commit 7df2ea4ead6f791e1840ca23d67765ca06e93e1b
> Author: Yeoreum Yun <yeoreum.yun@arm.com>
> 
> loongarch: kvm: remove stack copy address of pXd in pXd_offset()
> 
> This commit refactors host_pfn_mapping_level() to prepare for generic
> compile-time folded page tables. It replaces direct uses of stack-based pXd
> values with pXd_offset_lockless(), passing the pointers directly.
> 
> > diff --git a/arch/loongarch/kvm/mmu.c b/arch/loongarch/kvm/mmu.c
> > index e104897aa5328..837b40bb694f4 100644
> > --- a/arch/loongarch/kvm/mmu.c
> > +++ b/arch/loongarch/kvm/mmu.c
> [ ... ]
> > @@ -698,19 +698,23 @@ static int host_pfn_mapping_level(struct kvm *kvm, gfn_t gfn,
> [ ... ]
> > -	pud = pudp_get(pud_offset(&p4d, hva));
> > +	pudp = pud_offset_lockless(p4dp, p4d, hva);
> > +	pud = pudp_get(pudp);
> >  	if (pud_none(pud) || !pud_present(pud))
> >  		goto out;
> >  
> > -	pmd = pmdp_get(pmd_offset(&pud, hva));
> > +	pmdp = pmd_offset_lockless(pudp, pud, hva);
> > +	pmd = pmdp_get(pmdp);
> 
> [Severity: High]
> This is a pre-existing issue, but does this code need a check to see if the
> PUD is a leaf entry before stepping down to the PMD level?
> 
> In arch/loongarch/kvm/mmu.c:host_pfn_mapping_level(), the code reads the PUD
> entry and verifies that it is present, but it does not check if it is a 1GB
> huge page leaf entry before traversing to the PMD level.
> 
> If a guest memory region is backed by a 1GB huge page on the host, the PUD
> entry will contain a PFN-encoded value and metadata flags. By unconditionally
> passing this to pmd_offset_lockless(), the macro may interpret the PFN encoded
> value as a kernel virtual address directory pointer. This produces a bogus
> pointer that pmdp_get() will then dereference, causing an invalid memory
> dereference and potentially crashing the host.
> 
> Could a pud_leaf() or kvm_pte_huge(pud_val(pud)) check be added before the
> pmd_offset_lockless() call to prevent this crash when 1GB huge pages are
> used?
> 
> >  	if (pmd_none(pmd) || !pmd_present(pmd))
> >  		goto out;

AFAIK, loongarch doesn't create the pud block mapping. so it seems
ignoralbe.

-- 
Sincerely,
Yeoreum Yun

  reply	other threads:[~2026-09-02 12:38 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 11:56 [PATCH RFC v3 00/21] mm: change behavior of pXdp_get()/pXd_page() in compile-time folded pgtable Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 01/21] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 02/21] ARM: mm: make 2-level " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 03/21] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 04/21] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 05/21] MIPS: " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 06/21] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-09-02 12:15   ` sashiko-bot
2026-09-02 11:56 ` [PATCH RFC v3 07/21] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 08/21] mm: vmscan: remove stack copy address of pud/pmd pass in walk_pud/pmd_range() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 09/21] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-09-02 12:19   ` sashiko-bot
2026-09-02 12:38     ` Yeoreum Yun [this message]
2026-09-02 11:56 ` [PATCH RFC v3 10/21] riscv: " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 11/21] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 12/21] mm/pgtable: redefine PGTABLE_LEVEL enum with ascend order from PGD Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 13/21] x86: mm: use pgtable_level enum in effective_prot_pXd() Yeoreum Yun
2026-09-02 20:48   ` Dave Hansen
2026-09-02 11:56 ` [PATCH RFC v3 14/21] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-09-02 20:46   ` Dave Hansen
2026-09-02 11:56 ` [PATCH RFC v3 15/21] x86: mm: skip collapse_pud_page() when CONFIG_X86_DIRECT_GBPAGES disabled Yeoreum Yun
2026-09-02 12:17   ` sashiko-bot
2026-09-02 12:29     ` Yeoreum Yun
2026-09-02 15:38   ` Dave Hansen
2026-09-02 16:48     ` Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 16/21] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 17/21] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 18/21] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 19/21] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 20/21] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-09-02 11:56 ` [PATCH RFC v3 21/21] Documentation: mm: clarify behaviour of compile-time folded page tables Yeoreum Yun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=apgYtdl_DjBIqikK@e129823.arm.com \
    --to=yeoreum.yun@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox