Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 0/7] KVM: arm64: vgic-v3: Make LPI disabling robust (and more)
@ 2026-09-29  9:35 Marc Zyngier
  2026-09-29  9:35 ` [PATCH v2 1/7] KVM: arm64: Move OUTSIDE_GUEST_MODE publication past context being saved Marc Zyngier
                   ` (9 more replies)
  0 siblings, 10 replies; 23+ messages in thread
From: Marc Zyngier @ 2026-09-29  9:35 UTC (permalink / raw)
  To: kvmarm, linux-arm-kernel
  Cc: Steffen Eiden, Joey Gouly, Suzuki K Poulose, Oliver Upton,
	Zenghui Yu, Fuad Tabba, Yuchao Zhang

This is v2 of this series addressing shortcomings of LPIs being
disabled on one CPU from another. It has now expanded into some more
common areas.

Yuchao Zhang reported that disabling LPIs on one CPU from another
could result in UAFs and other horrors.

There are two reasons for this:

- the last_lr_irq pointer does not contribute to LPI refcount, and
  that LPI being removed results in a dangling pointer

- LPIs can be deleted from a remote vcpu by disabling them while that
  vcpu is actually running, and has LPIs in its LRs.

Address the two issues in one go, by actively taking a refcount on all
IRQs referenced by last_lr_irq, and making sure that disabling LPIs
force all vcpus to be paused, making it safe.

Review of the initial version pointed out two more general issues:

- OUTSIDE_GUEST_MODE is published too early, when the guest state is
  not yet visible to other threads, resulting in the wrong state being
  evaluated from another CPU.

- kvm_{halt,resume}_guest() can be called without holding a global
  lock, and therefore can nest. This can result in a vcpu being
  restarted too early.

This is addressed by the first two patches.

Finally, MOVALL suffers from similar issues as LPI disabling, but also
appears to be broken (the filtering on the source RD was accidentally
removed a while ago). Fix the filtering and move MOVALL to a "stop the
world" approach.

* From v1 [1]:

  - Fix OUTSIDE_GUEST_MODE publication to occur after the saving of
    the guest state

  - Turn vcpu->arch.pause into an atomic counter, allowing nesting

  - Fix MOVALL to filter by source RD

  - Make MOVALL a "stop the world" command

[1] https://lore.kernel.org/r/20260922214212.3327146-1-maz@kernel.org

Marc Zyngier (7):
  KVM: arm64: Move OUTSIDE_GUEST_MODE publication past context being
    saved
  KVM: arm64: Turn vcpu->arch.pause into a counter
  KVM: arm64: vgic: Allow last_lr_irq to be NULL when LRs are not
    overflowing
  KVM: arm64: vgic: Take a refcount on IRQs referenced by last_lr_irq
  KVM: arm64: vgic: Stop the VM when disabling LPIs
  KVM: arm64: vgic-its: Fix MOVALL handling of source redistributor
  KVM: arm64: vgic-its: Stop the VM when handling MOVALL

 arch/arm64/include/asm/kvm_host.h  |  7 +++----
 arch/arm64/kvm/arm.c               | 28 ++++++++++++++++++----------
 arch/arm64/kvm/vgic/vgic-its.c     | 23 +++++++++++++++++++----
 arch/arm64/kvm/vgic/vgic-mmio-v3.c | 10 ++++++++++
 arch/arm64/kvm/vgic/vgic-v2.c      |  6 ++++--
 arch/arm64/kvm/vgic/vgic-v3.c      |  6 ++++--
 arch/arm64/kvm/vgic/vgic.c         | 21 ++++++++++++++++-----
 7 files changed, 74 insertions(+), 27 deletions(-)

-- 
2.47.3



^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2026-10-08 20:28 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29  9:35 [PATCH v2 0/7] KVM: arm64: vgic-v3: Make LPI disabling robust (and more) Marc Zyngier
2026-09-29  9:35 ` [PATCH v2 1/7] KVM: arm64: Move OUTSIDE_GUEST_MODE publication past context being saved Marc Zyngier
2026-09-29 12:59   ` Fuad Tabba
2026-09-29 14:13     ` Marc Zyngier
2026-09-29 14:46       ` Fuad Tabba
2026-10-02 13:07       ` Will Deacon
2026-09-29  9:35 ` [PATCH v2 2/7] KVM: arm64: Turn vcpu->arch.pause into a counter Marc Zyngier
2026-09-29 13:22   ` Fuad Tabba
2026-09-29  9:35 ` [PATCH v2 3/7] KVM: arm64: vgic: Allow last_lr_irq to be NULL when LRs are not overflowing Marc Zyngier
2026-09-29  9:35 ` [PATCH v2 4/7] KVM: arm64: vgic: Take a refcount on IRQs referenced by last_lr_irq Marc Zyngier
2026-09-29  9:35 ` [PATCH v2 5/7] KVM: arm64: vgic: Stop the VM when disabling LPIs Marc Zyngier
2026-09-29  9:35 ` [PATCH v2 6/7] KVM: arm64: vgic-its: Fix MOVALL handling of source redistributor Marc Zyngier
2026-09-29 18:14   ` Fuad Tabba
2026-09-29  9:35 ` [PATCH v2 7/7] KVM: arm64: vgic-its: Stop the VM when handling MOVALL Marc Zyngier
2026-09-29 18:45   ` Fuad Tabba
2026-09-29 19:04 ` [PATCH v1 0/2] KVM: arm64: selftests: Cover the ITS MOVALL command Fuad Tabba
2026-09-29 19:04   ` [PATCH v1 1/2] KVM: arm64: selftests: Add a MOVALL command to the ITS library Fuad Tabba
2026-09-29 19:04   ` [PATCH v1 2/2] KVM: arm64: selftests: Add an ITS MOVALL test Fuad Tabba
2026-09-30 12:21     ` Marc Zyngier
2026-09-30 12:34       ` Fuad Tabba
2026-09-29 19:32 ` (subset) [PATCH v2 0/7] KVM: arm64: vgic-v3: Make LPI disabling robust (and more) Oliver Upton
2026-10-08 18:15 ` Fuad Tabba
2026-10-08 20:28   ` Oliver Upton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox