Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>
Cc: linux-pci@vger.kernel.org, kvm@vger.kernel.org
Subject: Re: [PATCH v7 04/16] KVM/vfio: Use file-based reference counting for KVM
Date: Thu, 08 Oct 2026 06:27:33 +0000	[thread overview]
Message-ID: <sashiko-outbox-163691@kernel.org> (raw)
In-Reply-To: <20261008055955.4014342-5-aneesh.kumar@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] vfio: premature KVM reference release on failed cdev bind
--

commit 3b919032adda2d9cc906ebc24555fad4223ad7c1
Author: Steffen Eiden <seiden@linux.ibm.com>

KVM/vfio: Use file-based reference counting for KVM
    
Replace manual module reference counting with file-based reference
counting for KVM integration. Pass struct file pointers instead of
struct kvm pointers throughout the VFIO-KVM interface, leveraging the
kernel's existing file reference counting.

> diff --git a/drivers/vfio/vfio_main.c b/drivers/vfio/vfio_main.c
> index 423ead48aafe3..ed96acfa86358 100644
> --- a/drivers/vfio/vfio_main.c
> +++ b/drivers/vfio/vfio_main.c
> @@ -511,14 +489,7 @@ void vfio_device_put_kvm(struct vfio_device *device)
>  	if (!device->kvm)
>  		return;
>  
> -	if (WARN_ON(!device->put_kvm))
> -		goto clear;
> -
> -	device->put_kvm(device->kvm);
> -	device->put_kvm = NULL;
> -	symbol_put(kvm_put_kvm);
> -
> -clear:
> +	fput(device->kvm);
>  	device->kvm = NULL;
>  }
>  #endif

[Severity: High]
Does this code introduce a regression where the globally shared
device->kvm reference is prematurely released on a failed cdev bind?

Looking at drivers/vfio/device_cdev.c:vfio_df_ioctl_bind_iommufd(), if a
secondary cdev open attempts to bind, it can fail because
device->open_count != 0:

	vfio_df_open(df);
	if (ret)
		goto out_put_kvm;
...
out_put_kvm:
	vfio_device_put_kvm(device);

Unlike the group path which checks if device->open_count == 0, this cdev
error path unconditionally drops the device->kvm reference via
vfio_device_put_kvm(device). This drops the reference belonging to the
primary opener and clears the pointer to NULL.

When the primary opener eventually accesses KVM (or when it closes the
device), the driver skips unregistering the device from KVM, or relies
on a raw pointer (e.g., matrix_mdev->kvm) to a KVM VM that may have
already been freed. Can this regression result in a use-after-free?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008055955.4014342-1-aneesh.kumar@kernel.org?part=4

  reply	other threads:[~2026-10-08  6:27 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08  5:59 [PATCH v7 00/16] iommufd: vIOMMUs and TSM guest requests for confidential guests Aneesh Kumar K.V (Arm)
2026-10-08  5:59 ` [PATCH v7 01/16] KVM: Introduce file_to_kvm_<arch>() infrastructure Aneesh Kumar K.V (Arm)
2026-10-08  6:11   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 02/16] KVM: Add file back-pointer to struct kvm Aneesh Kumar K.V (Arm)
2026-10-08  6:16   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 03/16] KVM: x86: Use file_to_kvm_x86() in SEV Aneesh Kumar K.V (Arm)
2026-10-08  6:07   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 04/16] KVM/vfio: Use file-based reference counting for KVM Aneesh Kumar K.V (Arm)
2026-10-08  6:27   ` sashiko-bot [this message]
2026-10-08  5:59 ` [PATCH v7 05/16] KVM: Restrict kvm_get_kvm/kvm_put_kvm export to internal KVM modules Aneesh Kumar K.V (Arm)
2026-10-08  6:08   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 06/16] KVM: Remove unused file_is_kvm Aneesh Kumar K.V (Arm)
2026-10-08  6:06   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 07/16] iommufd/device: Associate KVM file pointer with iommufd_device Aneesh Kumar K.V (Arm)
2026-10-08  6:20   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 08/16] iommufd/viommu: Keep a reference to the KVM file Aneesh Kumar K.V (Arm)
2026-10-08  6:10   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 09/16] tsm: Remove the device from lookup before PCI teardown Aneesh Kumar K.V (Arm)
2026-10-08  6:15   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 10/16] iommufd: Add the vdevice TSM request ioctl Aneesh Kumar K.V (Arm)
2026-10-08  6:10   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 11/16] PCI/TSM: Remove the legacy guest request interface Aneesh Kumar K.V (Arm)
2026-10-08  6:11   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 12/16] PCI/TSM: Add vIOMMU-bound contexts for vdevices Aneesh Kumar K.V (Arm)
2026-10-08  6:18   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 13/16] iommufd/viommu: Select vIOMMU operations before allocation Aneesh Kumar K.V (Arm)
2026-10-08  6:27   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 14/16] iommufd/viommu: Allow PCI TSM backends to provide vIOMMU operations Aneesh Kumar K.V (Arm)
2026-10-08  6:19   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 15/16] iommufd: Allow vIOMMUs without a parent HWPT Aneesh Kumar K.V (Arm)
2026-10-08  6:24   ` sashiko-bot
2026-10-08  5:59 ` [PATCH v7 16/16] PCI/TSM: wait for vdevice contexts before removing a DSM Aneesh Kumar K.V (Arm)
2026-10-08  6:25   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-163691@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=aneesh.kumar@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox