From: Marc Zyngier <maz@kernel.org>
To: kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org
Cc: Steffen Eiden <seiden@linux.ibm.com>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Oliver Upton <oupton@kernel.org>,
Zenghui Yu <yuzenghui@huawei.com>,
Fuad Tabba <fuad.tabba@linux.dev>,
Yuchao Zhang <ndaugoing@gmail.com>
Subject: [PATCH v2 0/7] KVM: arm64: vgic-v3: Make LPI disabling robust (and more)
Date: Tue, 29 Sep 2026 10:35:41 +0100 [thread overview]
Message-ID: <20260929093548.3598547-1-maz@kernel.org> (raw)
This is v2 of this series addressing shortcomings of LPIs being
disabled on one CPU from another. It has now expanded into some more
common areas.
Yuchao Zhang reported that disabling LPIs on one CPU from another
could result in UAFs and other horrors.
There are two reasons for this:
- the last_lr_irq pointer does not contribute to LPI refcount, and
that LPI being removed results in a dangling pointer
- LPIs can be deleted from a remote vcpu by disabling them while that
vcpu is actually running, and has LPIs in its LRs.
Address the two issues in one go, by actively taking a refcount on all
IRQs referenced by last_lr_irq, and making sure that disabling LPIs
force all vcpus to be paused, making it safe.
Review of the initial version pointed out two more general issues:
- OUTSIDE_GUEST_MODE is published too early, when the guest state is
not yet visible to other threads, resulting in the wrong state being
evaluated from another CPU.
- kvm_{halt,resume}_guest() can be called without holding a global
lock, and therefore can nest. This can result in a vcpu being
restarted too early.
This is addressed by the first two patches.
Finally, MOVALL suffers from similar issues as LPI disabling, but also
appears to be broken (the filtering on the source RD was accidentally
removed a while ago). Fix the filtering and move MOVALL to a "stop the
world" approach.
* From v1 [1]:
- Fix OUTSIDE_GUEST_MODE publication to occur after the saving of
the guest state
- Turn vcpu->arch.pause into an atomic counter, allowing nesting
- Fix MOVALL to filter by source RD
- Make MOVALL a "stop the world" command
[1] https://lore.kernel.org/r/20260922214212.3327146-1-maz@kernel.org
Marc Zyngier (7):
KVM: arm64: Move OUTSIDE_GUEST_MODE publication past context being
saved
KVM: arm64: Turn vcpu->arch.pause into a counter
KVM: arm64: vgic: Allow last_lr_irq to be NULL when LRs are not
overflowing
KVM: arm64: vgic: Take a refcount on IRQs referenced by last_lr_irq
KVM: arm64: vgic: Stop the VM when disabling LPIs
KVM: arm64: vgic-its: Fix MOVALL handling of source redistributor
KVM: arm64: vgic-its: Stop the VM when handling MOVALL
arch/arm64/include/asm/kvm_host.h | 7 +++----
arch/arm64/kvm/arm.c | 28 ++++++++++++++++++----------
arch/arm64/kvm/vgic/vgic-its.c | 23 +++++++++++++++++++----
arch/arm64/kvm/vgic/vgic-mmio-v3.c | 10 ++++++++++
arch/arm64/kvm/vgic/vgic-v2.c | 6 ++++--
arch/arm64/kvm/vgic/vgic-v3.c | 6 ++++--
arch/arm64/kvm/vgic/vgic.c | 21 ++++++++++++++++-----
7 files changed, 74 insertions(+), 27 deletions(-)
--
2.47.3
next reply other threads:[~2026-09-29 9:36 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 9:35 Marc Zyngier [this message]
2026-09-29 9:35 ` [PATCH v2 1/7] KVM: arm64: Move OUTSIDE_GUEST_MODE publication past context being saved Marc Zyngier
2026-09-29 12:59 ` Fuad Tabba
2026-09-29 14:13 ` Marc Zyngier
2026-09-29 14:46 ` Fuad Tabba
2026-10-02 13:07 ` Will Deacon
2026-09-29 9:35 ` [PATCH v2 2/7] KVM: arm64: Turn vcpu->arch.pause into a counter Marc Zyngier
2026-09-29 13:22 ` Fuad Tabba
2026-09-29 9:35 ` [PATCH v2 3/7] KVM: arm64: vgic: Allow last_lr_irq to be NULL when LRs are not overflowing Marc Zyngier
2026-09-29 9:35 ` [PATCH v2 4/7] KVM: arm64: vgic: Take a refcount on IRQs referenced by last_lr_irq Marc Zyngier
2026-09-29 9:35 ` [PATCH v2 5/7] KVM: arm64: vgic: Stop the VM when disabling LPIs Marc Zyngier
2026-09-29 9:35 ` [PATCH v2 6/7] KVM: arm64: vgic-its: Fix MOVALL handling of source redistributor Marc Zyngier
2026-09-29 18:14 ` Fuad Tabba
2026-09-29 9:35 ` [PATCH v2 7/7] KVM: arm64: vgic-its: Stop the VM when handling MOVALL Marc Zyngier
2026-09-29 18:45 ` Fuad Tabba
2026-09-29 19:04 ` [PATCH v1 0/2] KVM: arm64: selftests: Cover the ITS MOVALL command Fuad Tabba
2026-09-29 19:04 ` [PATCH v1 1/2] KVM: arm64: selftests: Add a MOVALL command to the ITS library Fuad Tabba
2026-09-29 19:04 ` [PATCH v1 2/2] KVM: arm64: selftests: Add an ITS MOVALL test Fuad Tabba
2026-09-30 12:21 ` Marc Zyngier
2026-09-30 12:34 ` Fuad Tabba
2026-09-29 19:32 ` (subset) [PATCH v2 0/7] KVM: arm64: vgic-v3: Make LPI disabling robust (and more) Oliver Upton
2026-10-08 18:15 ` Fuad Tabba
2026-10-08 20:28 ` Oliver Upton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929093548.3598547-1-maz@kernel.org \
--to=maz@kernel.org \
--cc=fuad.tabba@linux.dev \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=ndaugoing@gmail.com \
--cc=oupton@kernel.org \
--cc=seiden@linux.ibm.com \
--cc=suzuki.poulose@arm.com \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox