Linux KVM/arm64 development list
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vincent Donnefort" <vdonnefort@google.com>
Cc: kvmarm@lists.linux.dev, "Oliver Upton" <oupton@kernel.org>,
	"Marc Zyngier" <maz@kernel.org>
Subject: Re: [PATCH v4 05/17] KVM: arm64: Allow kvm_hyp_memcache usage outside of stage-2
Date: Fri, 31 Jul 2026 14:51:08 +0000	[thread overview]
Message-ID: <20260731145109.4B2D71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260731143541.956291-6-vdonnefort@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] In pKVM, `user_mem_abort()` skips memcache topup during permission faults, leading to a NULL pointer dereference in `pkvm_pgtable_stage2_map()` if the fault triggers a THP block mapping upgrade.
--

--- Patch [5]: [PATCH v4 05/17] KVM: arm64: Allow kvm_hyp_memcache usage outside of stage-2 ---
commit 005835cc03d158de34bf975706ada05a2388636e
Author: Vincent Donnefort <vdonnefort@google.com>

KVM: arm64: Allow kvm_hyp_memcache usage outside of stage-2

This commit introduces init_hyp_memcache() and init_hyp_stage2_memcache()
to initialize generic and stage-2 specific memcaches. It modifies the
allocator to use GFP_KERNEL_ACCOUNT conditionally based on the new KMEMCG
flag.

> diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c
> index 6c941aaa10c63..1e37f2f56c680 100644
> --- a/arch/arm64/kvm/mmu.c
> +++ b/arch/arm64/kvm/mmu.c
[ ... ]
> @@ -1160,8 +1160,10 @@ static void *hyp_mc_alloc_fn(void *mc)
>  {
>  	struct kvm_hyp_memcache *memcache = mc;
>  	void *addr;
> +	gfp_t gfp;
>  
> -	addr = (void *)__get_free_page(GFP_KERNEL_ACCOUNT);
> +	gfp = memcache->flags & HYP_MEMCACHE_ACCOUNT_KMEMCG ? GFP_KERNEL_ACCOUNT : GFP_KERNEL;
> +	addr = (void *)__get_free_page(gfp);

[Severity: High]
This is a pre-existing issue, but while reviewing these memcache changes,
I noticed a potential NULL pointer dereference related to the memcache topup
logic across user_mem_abort() and pkvm_pgtable_stage2_map().

In arch/arm64/kvm/mmu.c:user_mem_abort(), topup_mmu_memcache() is skipped
during a permission fault:

	memcache = get_mmu_memcache(s2fd->vcpu);
	if (!perm_fault || (memslot_is_logging(s2fd->memslot) &&
			    kvm_is_write_fault(s2fd->vcpu))) {
		ret = topup_mmu_memcache(s2fd->vcpu, memcache);
		if (ret)
			return ret;
	}

If transparent_hugepage_adjust() then detects a THP and upgrades the mapping
to PMD_SIZE, pkvm_pgtable_stage2_map() will be called to install the block
mapping.

Since the memcache wasn't topped up, cache->mapping is NULL, and this code
subsequently dereferences it in arch/arm64/kvm/pkvm.c:pkvm_pgtable_stage2_map():

	swap(mapping, cache->mapping);
	mapping->gfn = gfn;

Could a guest trigger this by forcing a permission fault on a page that
khugepaged has collapsed into a THP, leading to a host kernel panic?

>  	if (addr && memcache->flags & HYP_MEMCACHE_ACCOUNT_STAGE2)
>  		kvm_account_pgtable_pages(addr, 1);
>

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260731143541.956291-1-vdonnefort@google.com?part=5

  reply	other threads:[~2026-07-31 14:51 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31 14:35 [PATCH v4 00/17] KVM: arm64: Introduce pKVM hypervisor heap allocator Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 01/17] KVM: arm64: Add pkvm_private_va_range_pa Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 02/17] KVM: arm64: Add pkvm_remove_mappings Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 03/17] KVM: arm64: Add pkvm_map_private_va_range Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 04/17] KVM: arm64: Add a heap allocator for the pKVM hyp Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 05/17] KVM: arm64: Allow kvm_hyp_memcache usage outside of stage-2 Vincent Donnefort
2026-07-31 14:51   ` sashiko-bot [this message]
2026-07-31 14:35 ` [PATCH v4 06/17] KVM: arm64: Add pkvm_hyp_req infrastructure Vincent Donnefort
2026-07-31 14:45   ` sashiko-bot
2026-07-31 14:35 ` [PATCH v4 07/17] KVM: arm64: Add PKVM_HYP_REQ_HYP_ALLOC request Vincent Donnefort
2026-07-31 14:52   ` sashiko-bot
2026-07-31 14:35 ` [PATCH v4 08/17] KVM: arm64: Add reclaim interface for the pKVM heap alloc Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 09/17] KVM: arm64: Add selftests for the pKVM heap allocator Vincent Donnefort
2026-07-31 15:03   ` sashiko-bot
2026-07-31 14:35 ` [PATCH v4 10/17] KVM: arm64: Add a shrinker for pKVM Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 11/17] KVM: arm64: Filter out non-kernel addresses in kern_hyp_va Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 12/17] KVM: arm64: Move hyp_vm refcount into the structure Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 13/17] KVM: arm64: Alloc pkvm_hyp_vm using pKVM heap allocator Vincent Donnefort
2026-07-31 15:06   ` sashiko-bot
2026-07-31 14:35 ` [PATCH v4 14/17] KVM: arm64: Alloc pkvm_hyp_vcpu " Vincent Donnefort
2026-07-31 15:04   ` sashiko-bot
2026-07-31 14:35 ` [PATCH v4 15/17] KVM: arm64: Reject hyp trace descriptors with fewer CPUs than hyp_nr_cpus Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 16/17] KVM: arm64: Reject hyp trace descriptors with fewer than 3 pages Vincent Donnefort
2026-07-31 14:35 ` [PATCH v4 17/17] KVM: arm64: Alloc simple_buffer_page using pKVM hyp allocator Vincent Donnefort

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731145109.4B2D71F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vdonnefort@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox