From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id A3ECAC5518F for ; Tue, 4 Aug 2026 14:44:47 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Type:MIME-Version: References:In-Reply-To:Subject:Cc:To:From:Message-ID:Date:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=aZ8CvjTsE8imig+joKU5SQ3EWoaGRndjO4SfRE71EXM=; b=tOogTzYvWRRyEpI/E71E9ql6jZ lMIcpCYCEM5DSBFlDLxWCGObb+q5y15wRVoCWvzqbzpA/KJp3Ychz7IhBrQ7MhXMQD3VR11kpu1bM K2u/TfP8AqquFVdPhItRXVi2IFSyBHzLOFkm8QD5+rXhGWIZogEa3xys0ZpUHz2W38HkFdAtG6Z2d Cv4vMVnTbtHWLCpW984mBPO/kK6GPkW/hTBOygYNKaXp/aymI1obFq3y1dSVU8FcWBARkJeLyGw3g U4lPEtgxBj1ZwpPg4ubO6H6mWGjwcH682B/Je3sMYtWUjOfsW8lGSPn4dKhqcpNXTPfqhbONK+KOA TwmPSd7g==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1wrGNl-000000026wG-233N; Tue, 04 Aug 2026 14:44:41 +0000 Received: from sea.source.kernel.org ([172.234.252.31]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1wrGNk-000000026wA-11V7 for linux-arm-kernel@lists.infradead.org; Tue, 04 Aug 2026 14:44:40 +0000 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by sea.source.kernel.org (Postfix) with ESMTP id ECE5E43C51; Tue, 4 Aug 2026 14:44:39 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id CE5D41F000E9; Tue, 4 Aug 2026 14:44:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785854679; bh=aZ8CvjTsE8imig+joKU5SQ3EWoaGRndjO4SfRE71EXM=; h=Date:From:To:Cc:Subject:In-Reply-To:References; b=aByPNJbbjlQ57OPBmEl8tJNjWE3LtGyGGF4aZBkdplun7csv9BKs4dRrYmdhKBYSe TggmkPB8+7WHmXzFr7Bg+vxLadqT/keWhiSLB72UTErsJe1SQzaS8OFc/40nSt+RJq 7GO7Tdw7BEpH0cIdWugqErMXWn5aE2wtRr7ogLFkjq0wjY1qbCzwP45hf4GFE9SVri HNBz420P0E0eo7+v3hTrjywcmA3Mt88KUROBncPZiL2gGwznHgBpYpuqyryB16DFQh JkbkOoJByf+quO6BbHh196/3uAcjVbuKwQ8oGH7w+EBrZdkPUYPHPcm8BrWtU5EY3k JTIB9tLgGObFg== Received: from sofa.misterjones.org ([185.219.108.64] helo=goblin-girl.misterjones.org) by disco-boy.misterjones.org with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wrGNh-0000000CFYa-0bPg; Tue, 04 Aug 2026 14:44:37 +0000 Date: Tue, 04 Aug 2026 15:44:36 +0100 Message-ID: <86ldamaqsr.wl-maz@kernel.org> From: Marc Zyngier To: Karl Mehltretter Cc: Oliver Upton , Fuad Tabba , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Paolo Bonzini , Shuah Khan , linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, linux-kselftest@vger.kernel.org Subject: Re: [PATCH 2/2] KVM: arm64: selftests: Add a nested S2 MMU realloc test In-Reply-To: <20260803224405.41468-2-kmehltretter@gmail.com> References: <20260803224405.41468-1-kmehltretter@gmail.com> <20260803224405.41468-2-kmehltretter@gmail.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM-LB/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL-LB/10.8 EasyPG/1.0.0 Emacs/30.1 (aarch64-unknown-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") Content-Type: text/plain; charset=US-ASCII X-SA-Exim-Connect-IP: 185.219.108.64 X-SA-Exim-Rcpt-To: kmehltretter@gmail.com, oupton@kernel.org, tabba@google.com, joey.gouly@arm.com, seiden@linux.ibm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, pbonzini@redhat.com, shuah@kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, linux-kselftest@vger.kernel.org X-SA-Exim-Mail-From: maz@kernel.org X-SA-Exim-Scanned: No (on disco-boy.misterjones.org); SAEximRunCond expanded to false X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Mon, 03 Aug 2026 23:44:05 +0100, Karl Mehltretter wrote: > > Add a regression test for a stale vcpu->arch.hw_mmu reference when > initialising a vCPU grows the nested S2 MMU table. > > The test drives vCPU0 into L2 through a minimal L1 stage-2 identity map, > pins it to a second pCPU where it spins in L2, and then initialises > vCPU1. That initialisation grows the nested MMU table while vCPU0 still > holds one of its entries; keeping vCPU0 on a pCPU of its own means the > reference stays live without relying on hw_mmu being retained across a > schedule-out. vCPU0 is then released and has to run to completion. > > Creating vCPU1 up front is what allows the in-kernel VGIC to be used: > kvm_arch_vcpu_precreate() refuses KVM_CREATE_VCPU once the VGIC has been > initialised, which the test does before its first KVM_RUN. Creation on > its own increments online_vcpus, so deferring vCPU1's KVM_ARM_VCPU_INIT > until vCPU0 is in L2 still grows the table. > > With KASAN enabled, an unfixed kernel reports a slab-use-after-free in > kvm_handle_guest_abort(); with the fix it completes cleanly. The problem is that we can't mandate selftests to rely on KASAN on the host. Selftests are there to verify that we match the architecture requirements. If anything, this is a nice hack to demonstrate the problem (and yes, it fires here). > > Assisted-by: Claude:claude-fable-5 > Signed-off-by: Karl Mehltretter > --- > > The test requires nested virtualization and two pCPUs. Under QEMU TCG > it takes ~233s, exceeding the 120s timeout in > tools/testing/selftests/kvm/settings; psci_test takes ~167s in the same > boot, so emulating the second vCPU is the dominant cost. # time /host/home/maz/nested_mmu_realloc_test Random seed: 0x6b8b4567 Running control thread on pCPU 0, vCPU thread on pCPU 1 vCPU0 is running in L2; initializing vCPU1 to grow the table vCPU1 initialized; releasing vCPU0 vCPU0 resumed after nested MMU resize real 0m0.161s user 0m0.007s sys 0m0.109s This is with KVM running as an L1 already... M. -- Without deviation from the norm, progress is not possible.