From: sashiko-bot@kernel.org
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: "Alexander Gordeev" <agordeev@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
linux-s390@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH 05/13] s390/cio: Use kzalloc() for CHSC work areas
Date: Mon, 07 Sep 2026 10:37:34 +0000 [thread overview]
Message-ID: <20260907103735.27D691F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260907-s390-cio-ready-v1-5-ca7f39806234@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Replacing get_zeroed_page() with kzalloc() for CHSC (Channel Subsystem Call) memory blocks breaks the strict 4KB hardware alignment requirement when SLUB debugging or KASAN is enabled.
--
commit 9694c5915181f336b62527d191701841da8a5e9a
Author: Mike Rapoport (Microsoft) <rppt@kernel.org>
s390/cio: Use kzalloc() for CHSC work areas
chsc_init() allocates the work area for chsc commands and
qdio_allocate() allocates one for chsc calls during qdio_establish().
This commit replaces the use of get_zeroed_page() with kzalloc() and
free_page() with kfree() for these allocations.
Link: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com
> diff --git a/drivers/s390/cio/chsc.c b/drivers/s390/cio/chsc.c
> index c3186c0a372b4..d98f629e89295 100644
> --- a/drivers/s390/cio/chsc.c
> +++ b/drivers/s390/cio/chsc.c
> @@ -1143,7 +1143,7 @@ int __init chsc_init(void)
> int ret;
>
> sei_page = kzalloc(PAGE_SIZE, GFP_KERNEL | GFP_DMA);
> - chsc_page = (void *)get_zeroed_page(GFP_KERNEL | GFP_DMA);
> + chsc_page = kzalloc(PAGE_SIZE, GFP_KERNEL | GFP_DMA);
[Severity: High]
Does replacing get_zeroed_page() with kzalloc() cause a regression by
breaking the strict 4KB hardware alignment requirement for chsc command
blocks?
While kzalloc(PAGE_SIZE) might return page-aligned memory by default, if
slub debugging (like redzoning) or kasan is enabled, metadata is inserted
before the object, shifting the returned pointer away from the page boundary.
Passing this unaligned pointer to the chsc instruction could cause the
hardware to raise a specification exception and crash the system.
[ ... ]
> diff --git a/drivers/s390/cio/qdio_main.c b/drivers/s390/cio/qdio_main.c
> index c1e09fa34e774..d137bf8c70664 100644
> --- a/drivers/s390/cio/qdio_main.c
> +++ b/drivers/s390/cio/qdio_main.c
> @@ -986,7 +986,7 @@ int qdio_allocate(struct ccw_device *cdev, unsigned int no_input_qs,
> * qdio_establish. In case of low memory and swap on a zfcp disk
> * we may not be able to allocate memory otherwise.
> */
> - irq_ptr->chsc_page = get_zeroed_page(GFP_KERNEL);
> + irq_ptr->chsc_page = kzalloc(PAGE_SIZE, GFP_KERNEL);
[Severity: High]
Could this allocation introduce a similar regression with 4KB hardware
alignment?
Since the qdio chsc page is also used for hardware instructions in
qdio_setup_get_ssqd() and set_subchannel_ind(), losing the strict page
alignment guarantees of get_zeroed_page() when debugging is enabled might
lead to unaligned command blocks and hardware specification exceptions.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260907-s390-cio-ready-v1-0-ca7f39806234@kernel.org?part=5
next prev parent reply other threads:[~2026-09-07 10:37 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 10:23 [PATCH 00/13] s390/cio: replace page allocator calls with k[mz]alloc() Mike Rapoport (Microsoft)
2026-09-07 10:23 ` [PATCH 01/13] s390/chsc: Use kzalloc() for CUBs Mike Rapoport (Microsoft)
2026-09-07 10:37 ` sashiko-bot
2026-09-07 10:56 ` Mike Rapoport
2026-09-07 10:23 ` [PATCH 02/13] s390/chsc: Use kzalloc() for the SEI work area Mike Rapoport (Microsoft)
2026-09-07 10:34 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 03/13] s390/chsc_sch: Use kzalloc() for CHSC requests Mike Rapoport (Microsoft)
2026-09-07 10:39 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 04/13] s390/chsc_sch: Use __free(kfree) for synchronous " Mike Rapoport (Microsoft)
2026-09-07 10:30 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 05/13] s390/cio: Use kzalloc() for CHSC work areas Mike Rapoport (Microsoft)
2026-09-07 10:37 ` sashiko-bot [this message]
2026-09-07 10:23 ` [PATCH 06/13] s390/cmf: Use kmalloc() for the CMB area Mike Rapoport (Microsoft)
2026-09-07 10:35 ` sashiko-bot
2026-09-07 10:59 ` Mike Rapoport
2026-09-07 10:23 ` [PATCH 07/13] s390/idals: Use kmalloc() for IDAL data buffers Mike Rapoport (Microsoft)
2026-09-07 10:38 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 08/13] s390/qdio_main: Use kzalloc() for the IRQ structure Mike Rapoport (Microsoft)
2026-09-07 10:38 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 09/13] s390/qdio_main: Use kzalloc() for the QDR Mike Rapoport (Microsoft)
2026-09-07 10:33 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 10/13] s390/qdio_setup: Use kzalloc() for QDIO buffers Mike Rapoport (Microsoft)
2026-09-07 10:36 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 11/13] s390/qdio_setup: Use kzalloc() for the storage list Mike Rapoport (Microsoft)
2026-09-07 10:42 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 12/13] s390/qdio_setup: Use kzalloc() for the SSQD request Mike Rapoport (Microsoft)
2026-09-07 10:43 ` sashiko-bot
2026-09-07 10:23 ` [PATCH 13/13] s390/scm: Use kmalloc() for SCM information Mike Rapoport (Microsoft)
2026-09-07 10:44 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907103735.27D691F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=rppt@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox