From: sashiko-bot@kernel.org
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: linux-s390@vger.kernel.org, "Vasily Gorbik" <gor@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>
Subject: Re: [PATCH v3 09/13] s390/qdio_main: Use kzalloc() for the QDR
Date: Wed, 16 Sep 2026 12:16:49 +0000 [thread overview]
Message-ID: <20260916121650.597641F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260916-s390-cio-ready-v3-9-39e4894637d6@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] s390/qdio: kzalloc loses required hardware page alignment for QDR and CHSC
--
commit c802b7f29143c62b6663a20acaa96b4a8ed1cfb1
Author: Mike Rapoport (Microsoft) <rppt@kernel.org>
s390/qdio_main: Use kzalloc() for the QDR
This commit changes the allocation of the Queue Description Record (QDR) from
the page allocator to kzalloc(). The intent is to use a better API and avoid
tracking the size of the freed object, as both allocators use per-CPU lists
for the fast path.
Link: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com
> diff --git a/drivers/s390/cio/qdio_main.c b/drivers/s390/cio/qdio_main.c
> index 28eb8602ca97e..889f63f94a4a7 100644
> --- a/drivers/s390/cio/qdio_main.c
> +++ b/drivers/s390/cio/qdio_main.c
[ ... ]
> @@ -988,7 +988,7 @@ int qdio_allocate(struct ccw_device *cdev, unsigned int no_input_qs,
> goto err_chsc;
>
> /* qdr is used in ccw1.cda which is u32 */
> - irq_ptr->qdr = (struct qdr *) get_zeroed_page(GFP_KERNEL | GFP_DMA);
> + irq_ptr->qdr = kzalloc(PAGE_SIZE, GFP_KERNEL | GFP_DMA);
[Severity: High]
Will replacing the page allocator with kzalloc() break the 4K page-alignment
guarantee necessary for QDR hardware interactions?
When CONFIG_SLUB_DEBUG (redzoning) or KASAN is enabled, SLUB prepends metadata
to the object, shifting it away from the page boundary. If an unaligned
physical address is passed to the s390 channel subsystem hardware, it either
truncates the lower bits (causing silent DMA corruption by accessing adjacent
slab metadata) or raises a specification exception, leading to I/O device
failure. This could affect QDIO device initialization (e.g., zfcp, qeth) on
debug kernels.
Are there similar alignment issues with irq_ptr->chsc_page and irq_ptr
allocated earlier in qdio_allocate()? CHSC command blocks require strict 4K
page alignment, and struct qib (embedded in struct qdio_irq) requires 256-byte
hardware alignment. It appears kzalloc() will lose these guarantees under SLUB
debugging as well.
> if (!irq_ptr->qdr)
> goto err_qdr;
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916-s390-cio-ready-v3-0-39e4894637d6@kernel.org?part=9
next prev parent reply other threads:[~2026-09-16 12:16 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 12:03 [PATCH v3 00/13] s390/cio: replace page allocator calls with k[mz]alloc() Mike Rapoport (Microsoft)
2026-09-16 12:03 ` [PATCH v3 01/13] s390/chsc: Use kzalloc() for CUBs Mike Rapoport (Microsoft)
2026-09-16 12:15 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 02/13] s390/chsc: Use kzalloc() for the SEI work area Mike Rapoport (Microsoft)
2026-09-16 12:15 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 03/13] s390/chsc_sch: Use kzalloc() for CHSC requests Mike Rapoport (Microsoft)
2026-09-16 12:14 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 04/13] s390/chsc_sch: Use __free(kfree) for synchronous " Mike Rapoport (Microsoft)
2026-09-16 12:10 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 05/13] s390/cio: Use kzalloc() for CHSC work areas Mike Rapoport (Microsoft)
2026-09-16 12:12 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 06/13] s390/cmf: Use kmalloc() for the CMB area Mike Rapoport (Microsoft)
2026-09-16 12:18 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 07/13] s390/idals: Use kmalloc() for IDAL data buffers Mike Rapoport (Microsoft)
2026-09-16 12:16 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 08/13] s390/qdio_main: Use kzalloc() for the IRQ structure Mike Rapoport (Microsoft)
2026-09-16 12:17 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 09/13] s390/qdio_main: Use kzalloc() for the QDR Mike Rapoport (Microsoft)
2026-09-16 12:16 ` sashiko-bot [this message]
2026-09-16 12:03 ` [PATCH v3 10/13] s390/qdio_setup: Use kzalloc() for QDIO buffers Mike Rapoport (Microsoft)
2026-09-16 12:21 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 11/13] s390/qdio_setup: Use kmalloc() for the storage list Mike Rapoport (Microsoft)
2026-09-16 12:23 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 12/13] s390/qdio_setup: Use kmalloc() for the SSQD request Mike Rapoport (Microsoft)
2026-09-16 12:23 ` sashiko-bot
2026-09-16 12:03 ` [PATCH v3 13/13] s390/scm: Use kmalloc() for SCM information Mike Rapoport (Microsoft)
2026-09-16 12:23 ` sashiko-bot
2026-09-16 13:06 ` [PATCH v3 00/13] s390/cio: replace page allocator calls with k[mz]alloc() Heiko Carstens
2026-09-18 16:23 ` Peter Oberparleiter
2026-09-20 18:20 ` Heiko Carstens
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916121650.597641F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=rppt@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox