* [PATCH] KVM: arm64: vgic-v3: Reinstate IRQ lock ordering for LPI xarray
@ 2025-11-07 1:29 Oliver Upton
2025-11-07 9:46 ` Zenghui Yu
0 siblings, 1 reply; 2+ messages in thread
From: Oliver Upton @ 2025-11-07 1:29 UTC (permalink / raw)
To: kvmarm; +Cc: Marc Zyngier, Joey Gouly, Suzuki K Poulose, Zenghui Yu,
Oliver Upton
Zenghui reports that running a KVM guest with an assigned device and
lockdep enabled produces an unfriendly splat due to an inconsistent irq
context when taking the lpi_xa's spinlock.
This is no good as in rare cases the last reference to an LPI can get
dropped after injection of a cached LPI translation. In this case,
vgic_put_irq() will release the IRQ struct and take the lpi_xa's
spinlock to erase it from the xarray.
Reinstate the IRQ ordering and update the lockdep hint accordingly. Note
that there is no irqsave equivalent of might_lock(), so just explictly
grab and release the spinlock on lockdep kernels.
Reported-by: Zenghui Yu <yuzenghui@huawei.com>
Closes: https://lore.kernel.org/kvmarm/b4d7cb0f-f007-0b81-46d1-998b15cc14bc@huawei.com/
Fixes: 982f31bbb5b0 ("KVM: arm64: vgic-v3: Don't require IRQs be disabled for LPI xarray lock")
Signed-off-by: Oliver Upton <oupton@kernel.org>
---
arch/arm64/kvm/vgic/vgic-init.c | 2 +-
arch/arm64/kvm/vgic/vgic-its.c | 7 ++++---
arch/arm64/kvm/vgic/vgic.c | 23 +++++++++++++++--------
3 files changed, 20 insertions(+), 12 deletions(-)
diff --git a/arch/arm64/kvm/vgic/vgic-init.c b/arch/arm64/kvm/vgic/vgic-init.c
index 1796b1a22a72..7208776ba4bf 100644
--- a/arch/arm64/kvm/vgic/vgic-init.c
+++ b/arch/arm64/kvm/vgic/vgic-init.c
@@ -53,7 +53,7 @@ void kvm_vgic_early_init(struct kvm *kvm)
{
struct vgic_dist *dist = &kvm->arch.vgic;
- xa_init(&dist->lpi_xa);
+ xa_init_flags(&dist->lpi_xa, XA_FLAGS_LOCK_IRQ);
}
/* CREATION */
diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c
index ce3e3ed3f29f..f162206adb48 100644
--- a/arch/arm64/kvm/vgic/vgic-its.c
+++ b/arch/arm64/kvm/vgic/vgic-its.c
@@ -78,6 +78,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
{
struct vgic_dist *dist = &kvm->arch.vgic;
struct vgic_irq *irq = vgic_get_irq(kvm, intid), *oldirq;
+ unsigned long flags;
int ret;
/* In this case there is no put, since we keep the reference. */
@@ -88,7 +89,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
if (!irq)
return ERR_PTR(-ENOMEM);
- ret = xa_reserve(&dist->lpi_xa, intid, GFP_KERNEL_ACCOUNT);
+ ret = xa_reserve_irq(&dist->lpi_xa, intid, GFP_KERNEL_ACCOUNT);
if (ret) {
kfree(irq);
return ERR_PTR(ret);
@@ -103,7 +104,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
irq->target_vcpu = vcpu;
irq->group = 1;
- xa_lock(&dist->lpi_xa);
+ xa_lock_irqsave(&dist->lpi_xa, flags);
/*
* There could be a race with another vgic_add_lpi(), so we need to
@@ -125,7 +126,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
}
out_unlock:
- xa_unlock(&dist->lpi_xa);
+ xa_unlock_irqrestore(&dist->lpi_xa, flags);
if (ret)
return ERR_PTR(ret);
diff --git a/arch/arm64/kvm/vgic/vgic.c b/arch/arm64/kvm/vgic/vgic.c
index 6dd5a10081e2..8d20c53faef0 100644
--- a/arch/arm64/kvm/vgic/vgic.c
+++ b/arch/arm64/kvm/vgic/vgic.c
@@ -28,7 +28,7 @@ struct vgic_global kvm_vgic_global_state __ro_after_init = {
* kvm->arch.config_lock (mutex)
* its->cmd_lock (mutex)
* its->its_lock (mutex)
- * vgic_dist->lpi_xa.xa_lock
+ * vgic_dist->lpi_xa.xa_lock must be taken with IRQs disabled
* vgic_cpu->ap_list_lock must be taken with IRQs disabled
* vgic_irq->irq_lock must be taken with IRQs disabled
*
@@ -141,32 +141,39 @@ static __must_check bool vgic_put_irq_norelease(struct kvm *kvm, struct vgic_irq
void vgic_put_irq(struct kvm *kvm, struct vgic_irq *irq)
{
struct vgic_dist *dist = &kvm->arch.vgic;
+ unsigned long flags;
- if (irq->intid >= VGIC_MIN_LPI)
- might_lock(&dist->lpi_xa.xa_lock);
+ /*
+ * Normally the lock is only taken when the refcount drops to 0.
+ * Acquire/release it early on lockdep kernels to make locking issues
+ * in rare release paths a bit more obvious.
+ */
+ if (IS_ENABLED(CONFIG_LOCKDEP) && irq->intid >= VGIC_MIN_LPI) {
+ guard(spinlock_irqsave)(&dist->lpi_xa.xa_lock);
+ }
if (!__vgic_put_irq(kvm, irq))
return;
- xa_lock(&dist->lpi_xa);
+ xa_lock_irqsave(&dist->lpi_xa, flags);
vgic_release_lpi_locked(dist, irq);
- xa_unlock(&dist->lpi_xa);
+ xa_unlock_irqrestore(&dist->lpi_xa, flags);
}
static void vgic_release_deleted_lpis(struct kvm *kvm)
{
struct vgic_dist *dist = &kvm->arch.vgic;
- unsigned long intid;
+ unsigned long flags, intid;
struct vgic_irq *irq;
- xa_lock(&dist->lpi_xa);
+ xa_lock_irqsave(&dist->lpi_xa, flags);
xa_for_each(&dist->lpi_xa, intid, irq) {
if (irq->pending_release)
vgic_release_lpi_locked(dist, irq);
}
- xa_unlock(&dist->lpi_xa);
+ xa_unlock_irqrestore(&dist->lpi_xa, flags);
}
void vgic_flush_pending_lpis(struct kvm_vcpu *vcpu)
base-commit: 6146a0f1dfae5d37442a9ddcba012add260bceb0
--
2.47.3
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] KVM: arm64: vgic-v3: Reinstate IRQ lock ordering for LPI xarray
2025-11-07 1:29 [PATCH] KVM: arm64: vgic-v3: Reinstate IRQ lock ordering for LPI xarray Oliver Upton
@ 2025-11-07 9:46 ` Zenghui Yu
0 siblings, 0 replies; 2+ messages in thread
From: Zenghui Yu @ 2025-11-07 9:46 UTC (permalink / raw)
To: Oliver Upton; +Cc: kvmarm, Marc Zyngier, Joey Gouly, Suzuki K Poulose
Hi Oliver,
On 2025/11/7 9:29, Oliver Upton wrote:
> Zenghui reports that running a KVM guest with an assigned device and
> lockdep enabled produces an unfriendly splat due to an inconsistent irq
> context when taking the lpi_xa's spinlock.
>
> This is no good as in rare cases the last reference to an LPI can get
> dropped after injection of a cached LPI translation. In this case,
> vgic_put_irq() will release the IRQ struct and take the lpi_xa's
> spinlock to erase it from the xarray.
>
> Reinstate the IRQ ordering and update the lockdep hint accordingly. Note
> that there is no irqsave equivalent of might_lock(), so just explictly
> grab and release the spinlock on lockdep kernels.
>
> Reported-by: Zenghui Yu <yuzenghui@huawei.com>
> Closes: https://lore.kernel.org/kvmarm/b4d7cb0f-f007-0b81-46d1-998b15cc14bc@huawei.com/
> Fixes: 982f31bbb5b0 ("KVM: arm64: vgic-v3: Don't require IRQs be disabled for LPI xarray lock")
> Signed-off-by: Oliver Upton <oupton@kernel.org>
> ---
> arch/arm64/kvm/vgic/vgic-init.c | 2 +-
> arch/arm64/kvm/vgic/vgic-its.c | 7 ++++---
> arch/arm64/kvm/vgic/vgic.c | 23 +++++++++++++++--------
> 3 files changed, 20 insertions(+), 12 deletions(-)
>
> diff --git a/arch/arm64/kvm/vgic/vgic-init.c b/arch/arm64/kvm/vgic/vgic-init.c
> index 1796b1a22a72..7208776ba4bf 100644
> --- a/arch/arm64/kvm/vgic/vgic-init.c
> +++ b/arch/arm64/kvm/vgic/vgic-init.c
> @@ -53,7 +53,7 @@ void kvm_vgic_early_init(struct kvm *kvm)
> {
> struct vgic_dist *dist = &kvm->arch.vgic;
>
> - xa_init(&dist->lpi_xa);
> + xa_init_flags(&dist->lpi_xa, XA_FLAGS_LOCK_IRQ);
> }
>
> /* CREATION */
> diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c
> index ce3e3ed3f29f..f162206adb48 100644
> --- a/arch/arm64/kvm/vgic/vgic-its.c
> +++ b/arch/arm64/kvm/vgic/vgic-its.c
> @@ -78,6 +78,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
> {
> struct vgic_dist *dist = &kvm->arch.vgic;
> struct vgic_irq *irq = vgic_get_irq(kvm, intid), *oldirq;
> + unsigned long flags;
> int ret;
>
> /* In this case there is no put, since we keep the reference. */
> @@ -88,7 +89,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
> if (!irq)
> return ERR_PTR(-ENOMEM);
>
> - ret = xa_reserve(&dist->lpi_xa, intid, GFP_KERNEL_ACCOUNT);
> + ret = xa_reserve_irq(&dist->lpi_xa, intid, GFP_KERNEL_ACCOUNT);
> if (ret) {
> kfree(irq);
> return ERR_PTR(ret);
> @@ -103,7 +104,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
> irq->target_vcpu = vcpu;
> irq->group = 1;
>
> - xa_lock(&dist->lpi_xa);
> + xa_lock_irqsave(&dist->lpi_xa, flags);
>
> /*
> * There could be a race with another vgic_add_lpi(), so we need to
> @@ -125,7 +126,7 @@ static struct vgic_irq *vgic_add_lpi(struct kvm *kvm, u32 intid,
> }
>
> out_unlock:
> - xa_unlock(&dist->lpi_xa);
> + xa_unlock_irqrestore(&dist->lpi_xa, flags);
>
> if (ret)
> return ERR_PTR(ret);
> diff --git a/arch/arm64/kvm/vgic/vgic.c b/arch/arm64/kvm/vgic/vgic.c
> index 6dd5a10081e2..8d20c53faef0 100644
> --- a/arch/arm64/kvm/vgic/vgic.c
> +++ b/arch/arm64/kvm/vgic/vgic.c
> @@ -28,7 +28,7 @@ struct vgic_global kvm_vgic_global_state __ro_after_init = {
> * kvm->arch.config_lock (mutex)
> * its->cmd_lock (mutex)
> * its->its_lock (mutex)
> - * vgic_dist->lpi_xa.xa_lock
> + * vgic_dist->lpi_xa.xa_lock must be taken with IRQs disabled
> * vgic_cpu->ap_list_lock must be taken with IRQs disabled
> * vgic_irq->irq_lock must be taken with IRQs disabled
There are still some places where lpi_xa.xa_lock is taken with IRQs
enabled:
iter_mark_lpis()/xa_set_mark()
iter_unmark_lpis()/xa_clear_mark()
Another point (unrelated to this patch) is that the error path in
vgic_add_lpi() would probably result in bad thing:
| xa_lock_irqsave(&dist->lpi_xa, flags);
|
| [ trimmed ]
| if (ret) {
| xa_release(&dist->lpi_xa, intid);
... as xa_release() takes the xa_lock again.
Thanks,
Zenghui
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-11-07 9:47 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-11-07 1:29 [PATCH] KVM: arm64: vgic-v3: Reinstate IRQ lock ordering for LPI xarray Oliver Upton
2025-11-07 9:46 ` Zenghui Yu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox