Linux s390 Architecture development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: "Vasily Gorbik" <gor@linux.ibm.com>,
	"Heiko Carstens" <hca@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>
Subject: Re: [PATCH v2 12/13] s390/qdio_setup: Use kzalloc() for the SSQD request
Date: Thu, 10 Sep 2026 11:19:53 +0000	[thread overview]
Message-ID: <20260910111953.D18B31F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260910-s390-cio-ready-v2-12-e931086fdde1@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Hardware Alignment Violation in CHSC command block allocation
--

commit 43772ff0bb381f4318bb2f363719b4922b09d117
Author: Mike Rapoport (Microsoft) <rppt@kernel.org>

s390/qdio_setup: Use kzalloc() for the SSQD request

This commit modifies qdio_setup_get_ssqd() to use kzalloc() instead of
__get_free_page() for allocating the Store Subchannel QDIO Data (SSQD)
CHSC command block. It also replaces the corresponding free_page() call
with kfree().

Link: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com

> diff --git a/drivers/s390/cio/qdio_setup.c b/drivers/s390/cio/qdio_setup.c
> --- a/drivers/s390/cio/qdio_setup.c
> +++ b/drivers/s390/cio/qdio_setup.c
> @@ -249,7 +249,7 @@ int qdio_setup_get_ssqd(struct qdio_irq *irq_ptr,
>  
>  	DBF_EVENT("getssqd:%4x", schid->sch_no);
>  	if (!irq_ptr) {
> -		ssqd = (struct chsc_ssqd_area *)__get_free_page(GFP_KERNEL);
> +		ssqd = kzalloc(PAGE_SIZE, GFP_KERNEL);

[Severity: High]
In drivers/s390/cio/qdio_setup.c:qdio_setup_get_ssqd(), does this allocation
maintain the strict page alignment (4K boundary) required by the S/390 CHSC
instruction?

While kzalloc() with PAGE_SIZE might naturally align to 4K on standard
configurations, this guarantee is lost when CONFIG_SLUB_DEBUG (e.g., object
poisoning or redzoning) or KASAN is enabled. Under these configurations, SLUB
adds metadata or padding before the object, shifting the returned pointer off
the page boundary.

Passing an unaligned address to the CHSC hardware instruction triggers a
hardware specification exception (Program Check 0x06) and a kernel crash
deterministically during QDIO device setup.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260910-s390-cio-ready-v2-0-e931086fdde1@kernel.org?part=12

  reply	other threads:[~2026-09-10 11:19 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10 11:00 [PATCH v2 00/13] s390/cio: replace page allocator calls with k[mz]alloc() Mike Rapoport (Microsoft)
2026-09-10 11:00 ` [PATCH v2 01/13] s390/chsc: Use kzalloc() for CUBs Mike Rapoport (Microsoft)
2026-09-10 11:11   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 02/13] s390/chsc: Use kzalloc() for the SEI work area Mike Rapoport (Microsoft)
2026-09-10 11:12   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 03/13] s390/chsc_sch: Use kzalloc() for CHSC requests Mike Rapoport (Microsoft)
2026-09-10 11:10   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 04/13] s390/chsc_sch: Use __free(kfree) for synchronous " Mike Rapoport (Microsoft)
2026-09-10 11:05   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 05/13] s390/cio: Use kzalloc() for CHSC work areas Mike Rapoport (Microsoft)
2026-09-10 11:12   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 06/13] s390/cmf: Use kmalloc() for the CMB area Mike Rapoport (Microsoft)
2026-09-10 11:15   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 07/13] s390/idals: Use kmalloc() for IDAL data buffers Mike Rapoport (Microsoft)
2026-09-10 11:14   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 08/13] s390/qdio_main: Use kzalloc() for the IRQ structure Mike Rapoport (Microsoft)
2026-09-10 11:20   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 09/13] s390/qdio_main: Use kzalloc() for the QDR Mike Rapoport (Microsoft)
2026-09-10 11:11   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 10/13] s390/qdio_setup: Use kzalloc() for QDIO buffers Mike Rapoport (Microsoft)
2026-09-10 11:15   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 11/13] s390/qdio_setup: Use kzalloc() for the storage list Mike Rapoport (Microsoft)
2026-09-10 11:16   ` sashiko-bot
2026-09-10 11:00 ` [PATCH v2 12/13] s390/qdio_setup: Use kzalloc() for the SSQD request Mike Rapoport (Microsoft)
2026-09-10 11:19   ` sashiko-bot [this message]
2026-09-10 11:00 ` [PATCH v2 13/13] s390/scm: Use kmalloc() for SCM information Mike Rapoport (Microsoft)
2026-09-10 11:22   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260910111953.D18B31F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=rppt@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox