Linux s390 Architecture development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Claudio Imbrenda" <imbrenda@linux.ibm.com>
Cc: kvm@vger.kernel.org, "Vasily Gorbik" <gor@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	linux-s390@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>
Subject: Re: [PATCH v8 08/13] KVM: s390: cmma: Fix dirty tracking when removing memslot
Date: Mon, 03 Aug 2026 13:08:42 +0000	[thread overview]
Message-ID: <20260803130844.0640B1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260803124040.126471-9-imbrenda@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The CMMA dirty pages counter leaks when unmapped pages (holes) with `cmma_d == 1` are deleted.
--

--- Patch [8]: [PATCH v8 08/13] KVM: s390: cmma: Fix dirty tracking when removing memslot ---
commit 914169226ab516b51f60cbd45659598a2b39525d
Author: Claudio Imbrenda <imbrenda@linux.ibm.com>

KVM: s390: cmma: Fix dirty tracking when removing memslot

This commit decrements the cmma-dirty counter when a memslot is removed
to ensure accurate dirty tracking during migration mode. It also
opportunistically adopts scope-based resource management for the
kvm_s390_mmu_cache.

> diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
> index e5c5e9f61cb24..ba811f0673d10 100644
> --- a/arch/s390/kvm/kvm-s390.c
> +++ b/arch/s390/kvm/kvm-s390.c
[ ... ]
> @@ -5830,6 +5846,12 @@ void kvm_arch_commit_memory_region(struct kvm *kvm,
>  	}
>  
>  	scoped_guard(write_lock, &kvm->mmu_lock) {
> +		if (kvm->arch.migration_mode && kvm->arch.use_cmma && old) {
> +			_dat_walk_gfn_range(old->base_gfn, old->base_gfn + old->npages,
> +					    kvm->arch.gmap->asce, &ops, DAT_WALK_IGN_HOLES,
> +					    &kvm->arch.cmma_dirty_pages);
> +		}
> +

[Severity: High]
Does this code leak the cmma_dirty_pages counter when unmapped pages (holes)
have cmma_d == 1?

Because this pre-walk uses DAT_WALK_IGN_HOLES without DAT_WALK_ANY,
dat_pte_walk_range() will skip calling cmma_d_count_pte() for holes:

arch/s390/kvm/dat.c:dat_pte_walk_range() {
	if (pte_hole(READ_ONCE(table->ptes[idx]))) {
		if (!(w->flags & DAT_WALK_IGN_HOLES))
			return -EFAULT;
		if (!(w->flags & DAT_WALK_ANY))
			continue;
	}
	...
}

If a guest page was dirtied (setting cmma_d = 1 and incrementing the
counter), and then the host unmaps the page (e.g., via page reclaim
or MADV_DONTNEED), the PTE becomes a hole but the PGSTE retains
cmma_d == 1.

When the memslot is removed, this pre-walk skips the hole, failing
to decrement cmma_dirty_pages. Then dat_delete_slot() walks the range
with DAT_WALK_ANY and clears cmma_d, causing the counter to permanently
leak.

If this counter never reaches 0, could it stall live migration by causing
userspace to infinite loop waiting for remaining dirty pages to drop to 0?

>  		switch (change) {
>  		case KVM_MR_DELETE:
>  			rc = dat_delete_slot(mc, kvm->arch.gmap->asce, old->base_gfn, old->npages);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260803124040.126471-1-imbrenda@linux.ibm.com?part=8

  reply	other threads:[~2026-08-03 13:08 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03 12:40 [PATCH v8 00/13] KVM: s390: Misc fixes Claudio Imbrenda
2026-08-03 12:40 ` [PATCH v8 01/13] KVM: s390: Fix unlikely NULL gmap dereference Claudio Imbrenda
2026-08-03 12:55   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 02/13] KVM: s390: Do not free SCA if it was not allocated Claudio Imbrenda
2026-08-03 12:55   ` sashiko-bot
2026-08-03 14:08   ` Christian Borntraeger
2026-08-03 14:13   ` Janosch Frank
2026-08-03 12:40 ` [PATCH v8 03/13] KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma() Claudio Imbrenda
2026-08-03 13:19   ` sashiko-bot
2026-08-03 14:30   ` Janosch Frank
2026-08-03 14:54     ` Claudio Imbrenda
2026-08-03 12:40 ` [PATCH v8 04/13] KVM: s390: Fix overclearing ESCA in case of error Claudio Imbrenda
2026-08-03 13:05   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 05/13] KVM: s390: ucontrol: Fix sca_clear_ext_call() Claudio Imbrenda
2026-08-03 13:21   ` sashiko-bot
2026-08-03 14:50   ` Janosch Frank
2026-08-03 15:03     ` Claudio Imbrenda
2026-08-03 12:40 ` [PATCH v8 06/13] KVM: s390: Fix leaking of PGM_ADDRESSING to userspace Claudio Imbrenda
2026-08-03 13:01   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 07/13] KVM: s390: Fix race in __do_essa() Claudio Imbrenda
2026-08-03 12:56   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 08/13] KVM: s390: cmma: Fix dirty tracking when removing memslot Claudio Imbrenda
2026-08-03 13:08   ` sashiko-bot [this message]
2026-08-03 12:40 ` [PATCH v8 09/13] KVM: s390: ucontrol: Add missing locking around gmap_remove_child() Claudio Imbrenda
2026-08-03 12:59   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 10/13] KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails Claudio Imbrenda
2026-08-03 12:51   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 11/13] KVM: s390: Return -EINTR if a signal is pending while faulting-in Claudio Imbrenda
2026-08-03 13:19   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 12/13] KVM: s390: Fix ordering when adding to SCA Claudio Imbrenda
2026-08-03 13:03   ` sashiko-bot
2026-08-03 12:40 ` [PATCH v8 13/13] KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu() Claudio Imbrenda
2026-08-03 13:05   ` sashiko-bot
2026-08-03 15:06   ` Janosch Frank

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260803130844.0640B1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox