From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E84A22F8EB5; Sat, 25 Jul 2026 15:27:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784993239; cv=none; b=lLAkmBxYryi3f3rhAkWJYNfIrAlYu5odq7cQTD3PqIU0VEAqfcKOd0FSvYJ1NTTKRRoh8DI5MTOL1cgVq0EMv5+BzNpggKPR0Kn5cupa8SWe7aXc/0g23QuwFTRDKzLocLO00XTphyypTsJxKdT6NvRclDhT3ym5u0ziTGNxkN8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784993239; c=relaxed/simple; bh=vJs9xc/30hDx9JGZIF0UswmCWppURTGwpARUb6jic0E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=L92ypGFYQ2beDXjyrpXwIUz9MbVcYTp46Bzje+2bXS+FHYVNnXwxbj/ezywJjfgnK41QPqDY9s688gqJkddkwY5bq34rlpThCinQDK1aH1MA1uEHQCKjc4OvqR096Kwt5L4LDnN+h2Kd5fQFaNM1ETLC8XOqK8lnfuiKqNoslaw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=nksq56uI; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="nksq56uI" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66PDnnvw831538; Sat, 25 Jul 2026 15:27:15 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=pehW+LNYXXMR8byif W1tmfAYrofliG2hjo0xlZC76H0=; b=nksq56uI+68AoWp5EAnBXIJwjoI1NVpOM YoCIOhvS8Z//u33Hvr/6U4Gevu6M7Cvmb7uIc9le7U7XskkqRd5ByVBDM2dH1sWx 1baOB3ihwXLKLXh9afmE94miiZxGWkiG8g56hP2HhH8VYuuYN2L02plnP4gvs9jM DliO8FVI5dk7TX2k+BYb29o2jJKGYQzT2e5d+2hsUdU4sX0KVXE8oMiY0AwdC8YV rIdVmi40r0TuUaHQEmQJxsjSwIDrRS5oeT+77RumBErgXBdlhbL05v3dLuqqvaq2 df8NR08UcCf9TArM8GUcIUwMYK6uxXFlUlL28Pb+QxETeEs3xnu1A== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fmuwcgj5v-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sat, 25 Jul 2026 15:27:14 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 66PFQJI4016922; Sat, 25 Jul 2026 15:27:13 GMT Received: from smtprelay02.fra02v.mail.ibm.com ([9.218.2.226]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fmn331ntt-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sat, 25 Jul 2026 15:27:13 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay02.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 66PFR93553477636 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sat, 25 Jul 2026 15:27:09 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A02AA200B6; Sat, 25 Jul 2026 15:27:09 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 81C19200B3; Sat, 25 Jul 2026 15:27:09 +0000 (GMT) Received: from tuxmaker.boeblingen.de.ibm.com (unknown [9.87.85.9]) by smtpav07.fra02v.mail.ibm.com (Postfix) with SMTP; Sat, 25 Jul 2026 15:27:09 +0000 (GMT) Received: by tuxmaker.boeblingen.de.ibm.com (Postfix, from userid 4958) id 6C103162811; Sat, 25 Jul 2026 17:27:09 +0200 (CEST) From: Eric Farman To: linux-s390@vger.kernel.org, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Matthew Rosato , Halil Pasic , Christian Borntraeger , Eric Farman , stable@vger.kernel.org Subject: [PATCH v4 4/9] s390/vfio_ccw: ensure first IDAW remains constant Date: Sat, 25 Jul 2026 17:27:00 +0200 Message-ID: <20260725152705.3958100-5-farman@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260725152705.3958100-1-farman@linux.ibm.com> References: <20260725152705.3958100-1-farman@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-s390@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: ZOtjVh6DcmRlb23QP2nzOBKJuXj5WORQ X-Proofpoint-Spam-Info: AW1haW4tMjYwNzI1MDE0NCBTYWx0ZWRfX8YJQ0do0Z1/h B/qWNY+CenhJMmLQHSm90ykhYGrDmtqhW9GVQmnM5SJCDJ0zchhnDhNJun8k/RpMzgVszf3rDj0 MahTYh+ylMNjxGxa1HjW7+19Jv44oFw= X-Authority-Analysis: v=2.4 cv=E/z9Y6dl c=1 sm=1 tr=0 ts=6a64d5d2 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=TyQ-expsAN5g-WtpmiwA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzI1MDE0NCBTYWx0ZWRfX0DggT1pt2J6Q tQx+lbMPoZnA+MK395j2zk7YGF0H9aEkfJgEfTllBAktcr1aCRIUGbPmbvKuEQMjUP20yskjFHQ vBJOnH0HojF5u3f1ymaQHhDrx07qY69vcFZqQ6jKtqg+dGkPzdsmaToCp/W0kULtXZZ1ZR4duJt /3kxS1TBWsBShQ7DuBedquWAmiXG6Utks55+FFh/TBjuCC8NtCnCnoMCcEklcmvaA0Ya5sE4dsp vr5ZRcMgQJUnd63Kvj6S7/pXMoa1VhXizdM+jPWSGGRuMz5GcyET73JzeZ3EKpBBfoh3Jo+XPSl cZpnvz/FOETjZrp4NhrqS9lpBPzrYaxGSe2KirmnSmmVqUbFeJ3AMETwrUiY2cAMeB2d464mmfq Htb3ztSagJOAwItN8DYHZMaNIzrldhF1mTB3dKSN9o6BTJzyJIOtbzit7HuUGV2rbzo18ENNi9h SLBu195h64BGvXbB02w== X-Proofpoint-GUID: ZOtjVh6DcmRlb23QP2nzOBKJuXj5WORQ X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-25_04,2026-07-24_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 priorityscore=1501 spamscore=0 clxscore=1015 phishscore=0 lowpriorityscore=0 bulkscore=0 malwarescore=0 impostorscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607250144 The first IDAW in a list does not need to be on a 2K/4K boundary like all others, and so is read separately to accurately calculate the size of the buffer needed to read the full IDAL. Verify that the address found in the first IDAW is unchanged between reads, to ensure a consistent set of IDAWs being worked with. Fixes: 01aa26c672c0 ("s390/cio: Combine direct and indirect CCW paths") Cc: stable@vger.kernel.org Reviewed-by: Matthew Rosato Signed-off-by: Eric Farman --- drivers/s390/cio/vfio_ccw_cp.c | 16 ++++++++++++++++ drivers/s390/cio/vfio_ccw_cp.h | 2 ++ 2 files changed, 18 insertions(+) diff --git a/drivers/s390/cio/vfio_ccw_cp.c b/drivers/s390/cio/vfio_ccw_c= p.c index af632f9d5453..6275794751cb 100644 --- a/drivers/s390/cio/vfio_ccw_cp.c +++ b/drivers/s390/cio/vfio_ccw_cp.c @@ -523,6 +523,7 @@ static dma64_t *get_guest_idal(struct ccw1 *ccw, stru= ct channel_program *cp, int &container_of(cp, struct vfio_ccw_private, cp)->vdev; dma64_t *idaws; dma32_t *idaws_f1; + u64 first_idaw; int idal_len =3D idaw_nr * sizeof(*idaws); int idaw_size =3D idal_is_2k(cp) ? PAGE_SIZE / 2 : PAGE_SIZE; int idaw_mask =3D ~(idaw_size - 1); @@ -539,6 +540,18 @@ static dma64_t *get_guest_idal(struct ccw1 *ccw, str= uct channel_program *cp, int kfree(idaws); return ERR_PTR(ret); } + + idaws_f1 =3D (dma32_t *)idaws; + if (cp->orb.cmd.c64) + first_idaw =3D dma64_to_u64(idaws[0]); + else + first_idaw =3D dma32_to_u32(idaws_f1[0]); + + /* Unexpected mismatch from earlier read */ + if (first_idaw !=3D cp->guest_iova) { + kfree(idaws); + return ERR_PTR(-EINVAL); + } } else { /* Fabricate an IDAL based off CCW data address */ if (cp->orb.cmd.c64) { @@ -604,6 +617,9 @@ static int ccw_count_idaws(struct ccw1 *ccw, iova =3D dma32_to_u32(ccw->cda); } =20 + /* Save the read address for later */ + cp->guest_iova =3D iova; + /* Format-1 IDAWs operate on 2K each */ if (!cp->orb.cmd.c64) return idal_2k_nr_words((void *)iova, bytes); diff --git a/drivers/s390/cio/vfio_ccw_cp.h b/drivers/s390/cio/vfio_ccw_c= p.h index a9b1d8dbc6f6..9af98ff12d67 100644 --- a/drivers/s390/cio/vfio_ccw_cp.h +++ b/drivers/s390/cio/vfio_ccw_cp.h @@ -35,6 +35,7 @@ * @initialized: whether this instance is actually initialized * @guest_cp: copy of guest channel program * @ccwchain_count: number of channel program segments (linked by TIC) + * @guest_iova: first data address of a guest channel program * * @ccwchain_list is the head of a ccwchain list, that contents the * translated result of the guest channel program that pointed out by @@ -46,6 +47,7 @@ struct channel_program { bool initialized; struct ccw1 *guest_cp; unsigned int ccwchain_count; + u64 guest_iova; }; =20 int cp_init(struct channel_program *cp, union orb *orb); --=20 2.53.0