From nobody Sat Feb 7 15:21:43 2026 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.223.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E0CE73A9DB7 for ; Tue, 20 Jan 2026 20:13:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939991; cv=none; b=e/DUg6MRpEWxyLNeRkaTCn3Q40fRyBacgjWbm6vVL1wEn3/CkpCDYAu0O0nQvB1qBytpqPXxuSLSEs6PLaahoXS4dvSfvnwOQ4SXDpPtsmJlT1pkhapKkiSm3CjI9D7VXM5zP/xwa+7pQ3noluTnOnQSO8hrjrW3VW9zGA/FKBY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939991; c=relaxed/simple; bh=L6B1PVMX+6Q2yKq5yKMtijiLk5ugPodGLJx1L0SxCQE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lz7D7eYxGQ8IRzNP0+n97AS+gRYJdKUVK/Oq9dXUn+GT4DhqrRH7EIIviGg0SSPeQls0ykd7fScp+6NZ7Bf2gaOh5l10XJUVhIfYiT9lpkO6fuPRVX0r6JgSjERxqopJgwqjmzrYHbpwlajx81cyhJhMVB4nSKQ2uJUp7Ii1aqU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=Xrf3i+35; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=yAbdrTTL; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=Xrf3i+35; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=yAbdrTTL; arc=none smtp.client-ip=195.135.223.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="Xrf3i+35"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="yAbdrTTL"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="Xrf3i+35"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="yAbdrTTL" Received: from imap1.dmz-prg2.suse.org (imap1.dmz-prg2.suse.org [IPv6:2a07:de40:b281:104:10:150:64:97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id 4C5CB5BCCE; Tue, 20 Jan 2026 20:12:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939978; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JMimroRh4FFx5J8bvF8KVufVmKCBnQVJentzhJONIag=; b=Xrf3i+35yvhTti2zOjb/VbkMR98OxMvmHOPyqFU02wuW36IfTqT6bCYFKlwOCy/SyI77uG uX10UZ/LPorehpLpK5DgxpuD9i4ljeYVc/UdeC4cdP4eTNEAEcrMuI5D4bFTkyG54FKvtl h0Ev5Qv+1PrtT37Y8N1HvOVkII6cex4= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939978; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JMimroRh4FFx5J8bvF8KVufVmKCBnQVJentzhJONIag=; b=yAbdrTTLblcuyhH2NNhbgEo+AK+eHmxDG39//O3gd/NxT42hBJC2D8dOuzh/z7emy1qmV6 5pZKaN2gKYETbsCw== Authentication-Results: smtp-out2.suse.de; dkim=pass header.d=suse.de header.s=susede2_rsa header.b=Xrf3i+35; dkim=pass header.d=suse.de header.s=susede2_ed25519 header.b=yAbdrTTL DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939978; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JMimroRh4FFx5J8bvF8KVufVmKCBnQVJentzhJONIag=; b=Xrf3i+35yvhTti2zOjb/VbkMR98OxMvmHOPyqFU02wuW36IfTqT6bCYFKlwOCy/SyI77uG uX10UZ/LPorehpLpK5DgxpuD9i4ljeYVc/UdeC4cdP4eTNEAEcrMuI5D4bFTkyG54FKvtl h0Ev5Qv+1PrtT37Y8N1HvOVkII6cex4= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939978; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JMimroRh4FFx5J8bvF8KVufVmKCBnQVJentzhJONIag=; b=yAbdrTTLblcuyhH2NNhbgEo+AK+eHmxDG39//O3gd/NxT42hBJC2D8dOuzh/z7emy1qmV6 5pZKaN2gKYETbsCw== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id 6E3013EA63; Tue, 20 Jan 2026 20:12:57 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id mOB+F8nhb2nRMAAAD6G6ig (envelope-from ); Tue, 20 Jan 2026 20:12:57 +0000 From: =?UTF-8?q?Carlos=20L=C3=B3pez?= To: kvm@vger.kernel.org, seanjc@google.com, pbonzini@redhat.com Cc: pankaj.gupta@amd.com, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, linux-kernel@vger.kernel.org, =?UTF-8?q?Carlos=20L=C3=B3pez?= , Borislav Petkov Subject: [PATCH v2 1/6] KVM: SEV: use mutex guard in snp_launch_update() Date: Tue, 20 Jan 2026 21:10:09 +0100 Message-ID: <20260120201013.3931334-4-clopez@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260120201013.3931334-3-clopez@suse.de> References: <20260120201013.3931334-3-clopez@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Spamd-Result: default: False [-3.51 / 50.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM_LONG(-1.00)[-1.000]; MID_CONTAINS_FROM(1.00)[]; R_DKIM_ALLOW(-0.20)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.01)[]; MIME_TRACE(0.00)[0:+]; RCVD_VIA_SMTP_AUTH(0.00)[]; FUZZY_RATELIMITED(0.00)[rspamd.com]; RCPT_COUNT_TWELVE(0.00)[12]; ARC_NA(0.00)[]; RCVD_TLS_ALL(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:mid,suse.de:dkim,suse.de:email,imap1.dmz-prg2.suse.org:helo,imap1.dmz-prg2.suse.org:rdns]; DKIM_TRACE(0.00)[suse.de:+] X-Spam-Flag: NO X-Spam-Score: -3.51 X-Rspamd-Queue-Id: 4C5CB5BCCE X-Rspamd-Action: no action X-Rspamd-Server: rspamd2.dmz-prg2.suse.org X-Spam-Level: Simplify the error paths in snp_launch_update() by using a mutex guard, allowing early return instead of using gotos. Signed-off-by: Carlos L=C3=B3pez --- arch/x86/kvm/svm/sev.c | 31 ++++++++++++------------------- 1 file changed, 12 insertions(+), 19 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index f59c65abe3cf..59a0ad3e0917 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -2367,7 +2367,6 @@ static int snp_launch_update(struct kvm *kvm, struct = kvm_sev_cmd *argp) struct kvm_memory_slot *memslot; long npages, count; void __user *src; - int ret =3D 0; =20 if (!sev_snp_guest(kvm) || !sev->snp_context) return -EINVAL; @@ -2407,13 +2406,11 @@ static int snp_launch_update(struct kvm *kvm, struc= t kvm_sev_cmd *argp) * initial expected state and better guard against unexpected * situations. */ - mutex_lock(&kvm->slots_lock); + guard(mutex)(&kvm->slots_lock); =20 memslot =3D gfn_to_memslot(kvm, params.gfn_start); - if (!kvm_slot_has_gmem(memslot)) { - ret =3D -EINVAL; - goto out; - } + if (!kvm_slot_has_gmem(memslot)) + return -EINVAL; =20 sev_populate_args.sev_fd =3D argp->sev_fd; sev_populate_args.type =3D params.type; @@ -2425,22 +2422,18 @@ static int snp_launch_update(struct kvm *kvm, struc= t kvm_sev_cmd *argp) argp->error =3D sev_populate_args.fw_error; pr_debug("%s: kvm_gmem_populate failed, ret %ld (fw_error %d)\n", __func__, count, argp->error); - ret =3D -EIO; - } else { - params.gfn_start +=3D count; - params.len -=3D count * PAGE_SIZE; - if (params.type !=3D KVM_SEV_SNP_PAGE_TYPE_ZERO) - params.uaddr +=3D count * PAGE_SIZE; - - ret =3D 0; - if (copy_to_user(u64_to_user_ptr(argp->data), ¶ms, sizeof(params))) - ret =3D -EFAULT; + return -EIO; } =20 -out: - mutex_unlock(&kvm->slots_lock); + params.gfn_start +=3D count; + params.len -=3D count * PAGE_SIZE; + if (params.type !=3D KVM_SEV_SNP_PAGE_TYPE_ZERO) + params.uaddr +=3D count * PAGE_SIZE; =20 - return ret; + if (copy_to_user(u64_to_user_ptr(argp->data), ¶ms, sizeof(params))) + return -EFAULT; + + return 0; } =20 static int snp_launch_update_vmsa(struct kvm *kvm, struct kvm_sev_cmd *arg= p) --=20 2.51.0 From nobody Sat Feb 7 15:21:43 2026 Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ED5F03A9616 for ; Tue, 20 Jan 2026 20:13:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.130 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939984; cv=none; b=J7HuH2N9HTqw4wZRikBVUnIq92JjiU6OcipCElaiNxy9uTVnhChxg1cgn9eX6eDTSUzdbjBAEqncGzQhD2HZyXUsK2jCOu98IyvJu8LFYYm3FmzLfZQCPbCxZC3zLU9yzqKMa2ytMUS74lya+mse3wVYnqIwANIqjOnj+UOUctQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939984; c=relaxed/simple; bh=M+klrKG7t6pUf/GO4ORX5lUzkHkLnHeEVL/FJGabe+s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=dXEDG/EtcpugTbeRCTFL959l2zGIwPkA2AbLa0I7m8Q0jYySvo36jaJR9wdzRWJjaaZ0/SipUNBPfJbQniz/Derlx805hFGqFu9lB+WxXadlV9gfeDMMmK9TVVjtryb6zq7m17TNJjtu6eQsCBPqewsc7Jbsu+VUIBmE4H+7mw0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=XI1myI03; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=ax/outQG; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=XI1myI03; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=ax/outQG; arc=none smtp.client-ip=195.135.223.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="XI1myI03"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="ax/outQG"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="XI1myI03"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="ax/outQG" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 639E1336B7; Tue, 20 Jan 2026 20:12:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939979; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C6LsTZnO3E2g9e664OS7z1GS6NXqdu2qUpw+E2fuKwA=; b=XI1myI031B5QFIfaILYmYTP9qrAsMk4UIIuC5mPtyG/PH19b5qAK23LF4/7uDPmEXWphII VNyxGtsq7Vq64ps0friXTyoI59xpxVEkYKcWIfEwzoC1qoUgqpcQPm4vWtl3Jcvy+NRebH Rk41W+t9r9D4VpvRC/AWLwJ5Tlj2eDU= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939979; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C6LsTZnO3E2g9e664OS7z1GS6NXqdu2qUpw+E2fuKwA=; b=ax/outQGqaK4uRnMTfLgfXR5sOFO0X8VhFRb7NceA11m8HI9acnxRP9JWUr+ezMDndt6Be sU7IYZPfZGc3dxDQ== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939979; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C6LsTZnO3E2g9e664OS7z1GS6NXqdu2qUpw+E2fuKwA=; b=XI1myI031B5QFIfaILYmYTP9qrAsMk4UIIuC5mPtyG/PH19b5qAK23LF4/7uDPmEXWphII VNyxGtsq7Vq64ps0friXTyoI59xpxVEkYKcWIfEwzoC1qoUgqpcQPm4vWtl3Jcvy+NRebH Rk41W+t9r9D4VpvRC/AWLwJ5Tlj2eDU= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939979; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C6LsTZnO3E2g9e664OS7z1GS6NXqdu2qUpw+E2fuKwA=; b=ax/outQGqaK4uRnMTfLgfXR5sOFO0X8VhFRb7NceA11m8HI9acnxRP9JWUr+ezMDndt6Be sU7IYZPfZGc3dxDQ== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id 854163EA63; Tue, 20 Jan 2026 20:12:58 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id KB1NHcrhb2nRMAAAD6G6ig (envelope-from ); Tue, 20 Jan 2026 20:12:58 +0000 From: =?UTF-8?q?Carlos=20L=C3=B3pez?= To: kvm@vger.kernel.org, seanjc@google.com, pbonzini@redhat.com Cc: pankaj.gupta@amd.com, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, linux-kernel@vger.kernel.org, =?UTF-8?q?Carlos=20L=C3=B3pez?= , Borislav Petkov Subject: [PATCH v2 2/6] KVM: SEV: use mutex guard in sev_mem_enc_ioctl() Date: Tue, 20 Jan 2026 21:10:10 +0100 Message-ID: <20260120201013.3931334-5-clopez@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260120201013.3931334-3-clopez@suse.de> References: <20260120201013.3931334-3-clopez@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Spamd-Result: default: False [-3.30 / 50.00]; BAYES_HAM(-3.00)[100.00%]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; RCVD_TLS_ALL(0.00)[]; RCPT_COUNT_TWELVE(0.00)[12]; MIME_TRACE(0.00)[0:+]; FUZZY_RATELIMITED(0.00)[rspamd.com]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:mid,suse.de:email,imap1.dmz-prg2.suse.org:helo] X-Spam-Flag: NO X-Spam-Score: -3.30 X-Spam-Level: Simplify the error paths in sev_mem_enc_ioctl() by using a mutex guard, allowing early return instead of using gotos. Signed-off-by: Carlos L=C3=B3pez --- arch/x86/kvm/svm/sev.c | 25 ++++++++----------------- 1 file changed, 8 insertions(+), 17 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 59a0ad3e0917..bede01fc9086 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -2574,30 +2574,24 @@ int sev_mem_enc_ioctl(struct kvm *kvm, void __user = *argp) if (copy_from_user(&sev_cmd, argp, sizeof(struct kvm_sev_cmd))) return -EFAULT; =20 - mutex_lock(&kvm->lock); + guard(mutex)(&kvm->lock); =20 /* Only the enc_context_owner handles some memory enc operations. */ if (is_mirroring_enc_context(kvm) && - !is_cmd_allowed_from_mirror(sev_cmd.id)) { - r =3D -EINVAL; - goto out; - } + !is_cmd_allowed_from_mirror(sev_cmd.id)) + return -EINVAL; =20 /* * Once KVM_SEV_INIT2 initializes a KVM instance as an SNP guest, only * allow the use of SNP-specific commands. */ - if (sev_snp_guest(kvm) && sev_cmd.id < KVM_SEV_SNP_LAUNCH_START) { - r =3D -EPERM; - goto out; - } + if (sev_snp_guest(kvm) && sev_cmd.id < KVM_SEV_SNP_LAUNCH_START) + return -EPERM; =20 switch (sev_cmd.id) { case KVM_SEV_ES_INIT: - if (!sev_es_enabled) { - r =3D -ENOTTY; - goto out; - } + if (!sev_es_enabled) + return -ENOTTY; fallthrough; case KVM_SEV_INIT: r =3D sev_guest_init(kvm, &sev_cmd); @@ -2666,15 +2660,12 @@ int sev_mem_enc_ioctl(struct kvm *kvm, void __user = *argp) r =3D snp_launch_finish(kvm, &sev_cmd); break; default: - r =3D -EINVAL; - goto out; + return -EINVAL; } =20 if (copy_to_user(argp, &sev_cmd, sizeof(struct kvm_sev_cmd))) r =3D -EFAULT; =20 -out: - mutex_unlock(&kvm->lock); return r; } =20 --=20 2.51.0 From nobody Sat Feb 7 15:21:43 2026 Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3770F423162 for ; Tue, 20 Jan 2026 20:13:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.130 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939992; cv=none; b=nZ+uWpBAvmZzdr0HTNmSflKkX9jlQsQk1eeB39+LqbN4oI5EL4AzVa999FrHfw1gdqikRV66r6XQI5WP286NZoDthu8usVaP/opfKIWSReE00LphokAPBQq2mZF2qDQNCYiiBXC/oBKZxu7CdeNZwHf7ZCuimI6ruPqrxOJTrKg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939992; c=relaxed/simple; bh=KxCkJm2SpY4xHZq78uUaGcwf/wWSqXZC/SlJgCd/qCQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=SepqeLYotxthTrdxo9COVGKsGdT2BG37W9/UZUKt3T1Xl1skxIomEVQVHyVg+rRaWKsXpJ5WlO7nlxZ2hmdxoel6J4TIpq2CJY8+4ZFi6a+PwiTdGYT1R1Z2uhwC9HpO2nDWqaf74fz+XVlwBeXAy51HhizfSeZg5ecu85i4R+w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=pW52/uMf; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=UOaUWeKE; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=pW52/uMf; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=UOaUWeKE; arc=none smtp.client-ip=195.135.223.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="pW52/uMf"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="UOaUWeKE"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="pW52/uMf"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="UOaUWeKE" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 78DBE336BE; Tue, 20 Jan 2026 20:13:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939980; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2GDq9x24P3V2ERsKLShNWJSb7NtBBH1+qJAIRRPhGtg=; b=pW52/uMfKT6GgZsU59ZMMQwQVujYFpQ3bGqm28tfVhztjzxauhl/QNF9hDUQhtjhyPpxKk Nf1mxL7wEC0gWHWd4nJe5IJJs98foDkkAW5I7eQhrO5o7Yn7+MlhstshYZo513J/aHI4m5 LR436oQyD0R3iKbEgfDSIjUoMW5knxI= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939980; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2GDq9x24P3V2ERsKLShNWJSb7NtBBH1+qJAIRRPhGtg=; b=UOaUWeKEsNXFYlpX0zGivl8OifSQmk1Fqn6F86ZVNsoJ7Tt1hbGC2qBWiHQQdiKXjB11Yz iffsMPwTwy9Kh/Aw== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939980; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2GDq9x24P3V2ERsKLShNWJSb7NtBBH1+qJAIRRPhGtg=; b=pW52/uMfKT6GgZsU59ZMMQwQVujYFpQ3bGqm28tfVhztjzxauhl/QNF9hDUQhtjhyPpxKk Nf1mxL7wEC0gWHWd4nJe5IJJs98foDkkAW5I7eQhrO5o7Yn7+MlhstshYZo513J/aHI4m5 LR436oQyD0R3iKbEgfDSIjUoMW5knxI= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939980; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2GDq9x24P3V2ERsKLShNWJSb7NtBBH1+qJAIRRPhGtg=; b=UOaUWeKEsNXFYlpX0zGivl8OifSQmk1Fqn6F86ZVNsoJ7Tt1hbGC2qBWiHQQdiKXjB11Yz iffsMPwTwy9Kh/Aw== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id A0CB83EA63; Tue, 20 Jan 2026 20:12:59 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id kOOQI8vhb2nRMAAAD6G6ig (envelope-from ); Tue, 20 Jan 2026 20:12:59 +0000 From: =?UTF-8?q?Carlos=20L=C3=B3pez?= To: kvm@vger.kernel.org, seanjc@google.com, pbonzini@redhat.com Cc: pankaj.gupta@amd.com, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, linux-kernel@vger.kernel.org, =?UTF-8?q?Carlos=20L=C3=B3pez?= , Borislav Petkov Subject: [PATCH v2 3/6] KVM: SEV: use mutex guard in sev_mem_enc_register_region() Date: Tue, 20 Jan 2026 21:10:11 +0100 Message-ID: <20260120201013.3931334-6-clopez@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260120201013.3931334-3-clopez@suse.de> References: <20260120201013.3931334-3-clopez@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Spam-Score: -3.30 X-Spamd-Result: default: False [-3.30 / 50.00]; BAYES_HAM(-3.00)[100.00%]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; RCVD_TLS_ALL(0.00)[]; RCPT_COUNT_TWELVE(0.00)[12]; MIME_TRACE(0.00)[0:+]; FUZZY_RATELIMITED(0.00)[rspamd.com]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:mid,suse.de:email,imap1.dmz-prg2.suse.org:helo] X-Spam-Level: X-Spam-Flag: NO Simplify the error paths in sev_mem_enc_register_region() by using a mutex guard, allowing early return instead of using a goto. Signed-off-by: Carlos L=C3=B3pez --- arch/x86/kvm/svm/sev.c | 11 +++-------- 1 file changed, 3 insertions(+), 8 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index bede01fc9086..30f702c01caf 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -2690,13 +2690,13 @@ int sev_mem_enc_register_region(struct kvm *kvm, if (!region) return -ENOMEM; =20 - mutex_lock(&kvm->lock); + guard(mutex)(&kvm->lock); region->pages =3D sev_pin_memory(kvm, range->addr, range->size, ®ion->= npages, FOLL_WRITE | FOLL_LONGTERM); if (IS_ERR(region->pages)) { ret =3D PTR_ERR(region->pages); - mutex_unlock(&kvm->lock); - goto e_free; + kfree(region); + return ret; } =20 /* @@ -2713,13 +2713,8 @@ int sev_mem_enc_register_region(struct kvm *kvm, region->size =3D range->size; =20 list_add_tail(®ion->list, &sev->regions_list); - mutex_unlock(&kvm->lock); =20 return ret; - -e_free: - kfree(region); - return ret; } =20 static struct enc_region * --=20 2.51.0 From nobody Sat Feb 7 15:21:43 2026 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.223.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B4D0943DA5C for ; Tue, 20 Jan 2026 20:13:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939997; cv=none; b=AHn91oCJamXIQCo2TDgY7jHGlzuagZk7wU29eHOC1ZNCWmIVTTbXJSt05lRaIEpreNe7QeyxoIaYleEW4BFYg2HQQf3+xbb+9r+KIssZiYp3ert/NUfeH/LwRz28MD9mpOnOOkGKP/AJ5bT7tMd6Hhq/DG4IQMsv7wJ2OhrwM24= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939997; c=relaxed/simple; bh=MbDcAPRmY8tusJkjWgDCqncDR95ihIheKu4/9dlZAys=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=txHgqAxkLYDPUqDrRAqH9+3yaPFw4GuFzQLuPdpxtUKazST4YOBsH60QSkccrUjsZCsjk8QlqURUDTSEaljBI3Uu+HIcBBFvSic/qknHgyWvkDUleb4PPEdiyVq3oXF8MocjPz8FwgvvFPNxVBNdKg6qB9raZ/3/d9zNFcnijas= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=xkbp/cjd; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=WCc/Feqp; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=xkbp/cjd; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=WCc/Feqp; arc=none smtp.client-ip=195.135.223.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="xkbp/cjd"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="WCc/Feqp"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="xkbp/cjd"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="WCc/Feqp" Received: from imap1.dmz-prg2.suse.org (imap1.dmz-prg2.suse.org [IPv6:2a07:de40:b281:104:10:150:64:97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id 8A9085BCD0; Tue, 20 Jan 2026 20:13:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939981; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/XMjqsQFSIHe2r3eVttMF6hQmBpLtd2tPqBH0k5t4FE=; b=xkbp/cjdU2989uKONKIZTnEaHTtUsx3113g4iXjIrO7xI4cE7ENZs4KBDrcJyJaUlTTAwl FEaqKTxpcN1M1JQTZjyEK/t1NX2o1kPqWKEkEMxmgFOdqLlVGYblnWtZ3K2rvg4WnepPhq cltaRur7RBS8cp4p+hfTgJW2oA152xQ= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939981; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/XMjqsQFSIHe2r3eVttMF6hQmBpLtd2tPqBH0k5t4FE=; b=WCc/Feqpy4EZXXV9iuXh8/Xq5Pi6DfZTXm+/hFOKo+5NTEAd+GziIrNTu3OH0gnPRBZUA0 mPkj6tOXvZByGyCg== Authentication-Results: smtp-out2.suse.de; dkim=pass header.d=suse.de header.s=susede2_rsa header.b="xkbp/cjd"; dkim=pass header.d=suse.de header.s=susede2_ed25519 header.b="WCc/Feqp" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939981; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/XMjqsQFSIHe2r3eVttMF6hQmBpLtd2tPqBH0k5t4FE=; b=xkbp/cjdU2989uKONKIZTnEaHTtUsx3113g4iXjIrO7xI4cE7ENZs4KBDrcJyJaUlTTAwl FEaqKTxpcN1M1JQTZjyEK/t1NX2o1kPqWKEkEMxmgFOdqLlVGYblnWtZ3K2rvg4WnepPhq cltaRur7RBS8cp4p+hfTgJW2oA152xQ= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939981; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/XMjqsQFSIHe2r3eVttMF6hQmBpLtd2tPqBH0k5t4FE=; b=WCc/Feqpy4EZXXV9iuXh8/Xq5Pi6DfZTXm+/hFOKo+5NTEAd+GziIrNTu3OH0gnPRBZUA0 mPkj6tOXvZByGyCg== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id B8E293EA63; Tue, 20 Jan 2026 20:13:00 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id gLxsKczhb2nRMAAAD6G6ig (envelope-from ); Tue, 20 Jan 2026 20:13:00 +0000 From: =?UTF-8?q?Carlos=20L=C3=B3pez?= To: kvm@vger.kernel.org, seanjc@google.com, pbonzini@redhat.com Cc: pankaj.gupta@amd.com, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, linux-kernel@vger.kernel.org, =?UTF-8?q?Carlos=20L=C3=B3pez?= , Borislav Petkov Subject: [PATCH v2 4/6] KVM: SEV: use mutex guard in sev_mem_enc_unregister_region() Date: Tue, 20 Jan 2026 21:10:12 +0100 Message-ID: <20260120201013.3931334-7-clopez@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260120201013.3931334-3-clopez@suse.de> References: <20260120201013.3931334-3-clopez@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Spam-Score: -3.51 X-Spamd-Result: default: False [-3.51 / 50.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM_LONG(-1.00)[-1.000]; MID_CONTAINS_FROM(1.00)[]; R_DKIM_ALLOW(-0.20)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.01)[]; MIME_TRACE(0.00)[0:+]; RCVD_VIA_SMTP_AUTH(0.00)[]; FUZZY_RATELIMITED(0.00)[rspamd.com]; RCPT_COUNT_TWELVE(0.00)[12]; ARC_NA(0.00)[]; RCVD_TLS_ALL(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DBL_BLOCKED_OPENRESOLVER(0.00)[imap1.dmz-prg2.suse.org:rdns,imap1.dmz-prg2.suse.org:helo,suse.de:dkim,suse.de:mid,suse.de:email]; DKIM_TRACE(0.00)[suse.de:+] X-Spam-Level: X-Rspamd-Action: no action X-Rspamd-Queue-Id: 8A9085BCD0 X-Rspamd-Server: rspamd1.dmz-prg2.suse.org X-Spam-Flag: NO Simplify the error paths in sev_mem_enc_unregister_region() by using a mutex guard, allowing early return instead of using gotos. Signed-off-by: Carlos L=C3=B3pez --- arch/x86/kvm/svm/sev.c | 20 +++++--------------- 1 file changed, 5 insertions(+), 15 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 30f702c01caf..37ff48a876a5 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -2745,35 +2745,25 @@ int sev_mem_enc_unregister_region(struct kvm *kvm, struct kvm_enc_region *range) { struct enc_region *region; - int ret; =20 /* If kvm is mirroring encryption context it isn't responsible for it */ if (is_mirroring_enc_context(kvm)) return -EINVAL; =20 - mutex_lock(&kvm->lock); + guard(mutex)(&kvm->lock); =20 - if (!sev_guest(kvm)) { - ret =3D -ENOTTY; - goto failed; - } + if (!sev_guest(kvm)) + return -ENOTTY; =20 region =3D find_enc_region(kvm, range); - if (!region) { - ret =3D -EINVAL; - goto failed; - } + if (!region) + return -EINVAL; =20 sev_writeback_caches(kvm); =20 __unregister_enc_region_locked(kvm, region); =20 - mutex_unlock(&kvm->lock); return 0; - -failed: - mutex_unlock(&kvm->lock); - return ret; } =20 int sev_vm_copy_enc_context_from(struct kvm *kvm, unsigned int source_fd) --=20 2.51.0 From nobody Sat Feb 7 15:21:43 2026 Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9504C43D514 for ; Tue, 20 Jan 2026 20:13:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.130 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939999; cv=none; b=HusCoSZanKzOh/CV1edjGzr5U52X00v+2gzLqlAjn4JamG/te91EUeB9ykwnCYPYz9mqcHPXGg/fgwwTeEuPIVB06a2L18sk7w5BV6v9djxMJftmvAbGjOUqU4s5OKX8Gen/9/CsZpIpa+d3jLcEzW3qoJehqO6lpLmUG6/0kUg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768939999; c=relaxed/simple; bh=7vZVjEFQozotu3pAIMQMnmq402Kc52hWcAKb2p85NjA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=AGgYvZxutOQepASctvyUvkv6otzW4f++Vgn8+VrjRA9Nc7sCJ4iO17/Xa5oAbxEShv/7b0GEug7jatyii40V6BDlHmLvbKHSIC8rKnIqhIkYcnbwhMLg9unvFyf7C2JNnposSV6tZalNz2WqOEE/ENoPoy1Y3gCqmBXV/7t0suA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=Ae2pTOmT; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=N758PLfl; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=Ae2pTOmT; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=N758PLfl; arc=none smtp.client-ip=195.135.223.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="Ae2pTOmT"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="N758PLfl"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="Ae2pTOmT"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="N758PLfl" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 9C32F33734; Tue, 20 Jan 2026 20:13:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939982; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8laTTAit2FwvbftAMZeY2VDYr34Ix/IP7FRUTwr385A=; b=Ae2pTOmTATmF/q87yZZvIxdKHauxWadz9gSICdKkTVJoJxpchTuTUAjJWetETBNo27tu43 TqgR4j+E1srn77nEldkI79qm8ORZnPSPsLrmIXPk9dWn/ujy/0D3uAXMCVsuoiu0WP/2pr 0hw69XOP9rdsyVMNfVi/YLD/+QH+f9U= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939982; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8laTTAit2FwvbftAMZeY2VDYr34Ix/IP7FRUTwr385A=; b=N758PLfl3QSCNCJ1DTXmRJ2uTN2VaopCXiY3/ipZgm2bp6nBNlbDhg71qe06I7EbPrNUAV Dzg9i4xBMLICdsBA== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939982; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8laTTAit2FwvbftAMZeY2VDYr34Ix/IP7FRUTwr385A=; b=Ae2pTOmTATmF/q87yZZvIxdKHauxWadz9gSICdKkTVJoJxpchTuTUAjJWetETBNo27tu43 TqgR4j+E1srn77nEldkI79qm8ORZnPSPsLrmIXPk9dWn/ujy/0D3uAXMCVsuoiu0WP/2pr 0hw69XOP9rdsyVMNfVi/YLD/+QH+f9U= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939982; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8laTTAit2FwvbftAMZeY2VDYr34Ix/IP7FRUTwr385A=; b=N758PLfl3QSCNCJ1DTXmRJ2uTN2VaopCXiY3/ipZgm2bp6nBNlbDhg71qe06I7EbPrNUAV Dzg9i4xBMLICdsBA== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id C413F3EA63; Tue, 20 Jan 2026 20:13:01 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id 4A+JLM3hb2nRMAAAD6G6ig (envelope-from ); Tue, 20 Jan 2026 20:13:01 +0000 From: =?UTF-8?q?Carlos=20L=C3=B3pez?= To: kvm@vger.kernel.org, seanjc@google.com, pbonzini@redhat.com Cc: pankaj.gupta@amd.com, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, linux-kernel@vger.kernel.org, =?UTF-8?q?Carlos=20L=C3=B3pez?= , Borislav Petkov Subject: [PATCH v2 5/6] KVM: SEV: use mutex guard in snp_handle_guest_req() Date: Tue, 20 Jan 2026 21:10:13 +0100 Message-ID: <20260120201013.3931334-8-clopez@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260120201013.3931334-3-clopez@suse.de> References: <20260120201013.3931334-3-clopez@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Spamd-Result: default: False [-3.30 / 50.00]; BAYES_HAM(-3.00)[100.00%]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; TO_DN_SOME(0.00)[]; RCPT_COUNT_TWELVE(0.00)[12]; FUZZY_RATELIMITED(0.00)[rspamd.com]; RCVD_TLS_ALL(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FROM_HAS_DN(0.00)[]; R_RATELIMIT(0.00)[to_ip_from(RLtm3bmjtwwfkzb5ddzerbmdsq)]; FROM_EQ_ENVFROM(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:mid,suse.de:email,imap1.dmz-prg2.suse.org:helo] X-Spam-Flag: NO X-Spam-Score: -3.30 X-Spam-Level: Simplify the error paths in snp_handle_guest_req() by using a mutex guard, allowing early return instead of using gotos. Signed-off-by: Carlos L=C3=B3pez --- arch/x86/kvm/svm/sev.c | 23 ++++++++--------------- 1 file changed, 8 insertions(+), 15 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 37ff48a876a5..d3fa0963465d 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -4089,12 +4089,10 @@ static int snp_handle_guest_req(struct vcpu_svm *sv= m, gpa_t req_gpa, gpa_t resp_ if (!sev_snp_guest(kvm)) return -EINVAL; =20 - mutex_lock(&sev->guest_req_mutex); + guard(mutex)(&sev->guest_req_mutex); =20 - if (kvm_read_guest(kvm, req_gpa, sev->guest_req_buf, PAGE_SIZE)) { - ret =3D -EIO; - goto out_unlock; - } + if (kvm_read_guest(kvm, req_gpa, sev->guest_req_buf, PAGE_SIZE)) + return -EIO; =20 data.gctx_paddr =3D __psp_pa(sev->snp_context); data.req_paddr =3D __psp_pa(sev->guest_req_buf); @@ -4107,21 +4105,16 @@ static int snp_handle_guest_req(struct vcpu_svm *sv= m, gpa_t req_gpa, gpa_t resp_ */ ret =3D sev_issue_cmd(kvm, SEV_CMD_SNP_GUEST_REQUEST, &data, &fw_err); if (ret && !fw_err) - goto out_unlock; + return ret; =20 - if (kvm_write_guest(kvm, resp_gpa, sev->guest_resp_buf, PAGE_SIZE)) { - ret =3D -EIO; - goto out_unlock; - } + if (kvm_write_guest(kvm, resp_gpa, sev->guest_resp_buf, PAGE_SIZE)) + return -EIO; =20 /* No action is requested *from KVM* if there was a firmware error. */ svm_vmgexit_no_action(svm, SNP_GUEST_ERR(0, fw_err)); =20 - ret =3D 1; /* resume guest */ - -out_unlock: - mutex_unlock(&sev->guest_req_mutex); - return ret; + /* resume guest */ + return 1; } =20 static int snp_handle_ext_guest_req(struct vcpu_svm *svm, gpa_t req_gpa, g= pa_t resp_gpa) --=20 2.51.0 From nobody Sat Feb 7 15:21:43 2026 Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 78488423162 for ; Tue, 20 Jan 2026 20:13:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.130 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768940005; cv=none; b=Ag/k6KRqdRXS4cATMBJy/vW8LNTGdUum6q8BfDHntQ31HLOATC7bBnCt3kJqay3SK5FP4t8c1797e9KBchy0abGzf5/zLGpRuqhZrihHPMNtvp4lceWcAcmKZU4kTc0+KQtZcYmlMErj8QkmH3F0vUg1xEtOZJ5DaIZxdmoFltc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768940005; c=relaxed/simple; bh=qFXrG3NkyJKzCnGrH+sNdVBL1isCqyrB939wpVSCdo4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=hJ7VzwmDX+PwvU7WC8DJoVm4oEf4CaQf7duLeUK/xeAngQhyVo972a642rOBZ5vFGMG12qQ382lVAEbESIbWkCgmwum+d03/cRnB6t7fhWWbFkjSjj4yl21jl9Xm698FW9J/cIXNEuPohVyxiSWThfdzlSICs/bvaGmEmnL77DA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=awI+kUGA; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=jzmdzeqw; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=awI+kUGA; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=jzmdzeqw; arc=none smtp.client-ip=195.135.223.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="awI+kUGA"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="jzmdzeqw"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="awI+kUGA"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="jzmdzeqw" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id AFB8A33766; Tue, 20 Jan 2026 20:13:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939983; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=DQttywv9kkWJJ0SFatJC9sDq19fKr6EsEmunRpzN/mA=; b=awI+kUGAh8kUg/vo5UcVU5AhJD4f1QPaJiVwt2SBJUgJzGseShGq3KxlKRn9B55GK63x2x 4hpICeZNksfuzG77XHOQmTQCERWwz/LT+W8DeFTt0ENPNJSlSa70mWghO9/wNBQ6fmpYyS 832LzRh3Nv6pP6m7Uk1PYS34ykpahp8= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939983; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=DQttywv9kkWJJ0SFatJC9sDq19fKr6EsEmunRpzN/mA=; b=jzmdzeqwECx7aqyq7Ob7HwGNZ4uuWn3BztmysdUymsOHFiBiPPbCgiBJCdwP7eURFr+fz7 yPNHKCxPsZqiSqAw== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1768939983; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=DQttywv9kkWJJ0SFatJC9sDq19fKr6EsEmunRpzN/mA=; b=awI+kUGAh8kUg/vo5UcVU5AhJD4f1QPaJiVwt2SBJUgJzGseShGq3KxlKRn9B55GK63x2x 4hpICeZNksfuzG77XHOQmTQCERWwz/LT+W8DeFTt0ENPNJSlSa70mWghO9/wNBQ6fmpYyS 832LzRh3Nv6pP6m7Uk1PYS34ykpahp8= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1768939983; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=DQttywv9kkWJJ0SFatJC9sDq19fKr6EsEmunRpzN/mA=; b=jzmdzeqwECx7aqyq7Ob7HwGNZ4uuWn3BztmysdUymsOHFiBiPPbCgiBJCdwP7eURFr+fz7 yPNHKCxPsZqiSqAw== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id D5EB43EA63; Tue, 20 Jan 2026 20:13:02 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id yGjLMM7hb2nRMAAAD6G6ig (envelope-from ); Tue, 20 Jan 2026 20:13:02 +0000 From: =?UTF-8?q?Carlos=20L=C3=B3pez?= To: kvm@vger.kernel.org, seanjc@google.com, pbonzini@redhat.com Cc: pankaj.gupta@amd.com, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, linux-kernel@vger.kernel.org, =?UTF-8?q?Carlos=20L=C3=B3pez?= , Borislav Petkov Subject: [PATCH v2 6/6] KVM: SEV: use scoped mutex guard in sev_asid_new() Date: Tue, 20 Jan 2026 21:10:14 +0100 Message-ID: <20260120201013.3931334-9-clopez@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260120201013.3931334-3-clopez@suse.de> References: <20260120201013.3931334-3-clopez@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Spam-Score: -3.30 X-Spamd-Result: default: False [-3.30 / 50.00]; BAYES_HAM(-3.00)[99.99%]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; TO_DN_SOME(0.00)[]; RCPT_COUNT_TWELVE(0.00)[12]; FUZZY_RATELIMITED(0.00)[rspamd.com]; RCVD_TLS_ALL(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FROM_HAS_DN(0.00)[]; R_RATELIMIT(0.00)[to_ip_from(RLtm3bmjtwwfkzb5ddzerbmdsq)]; FROM_EQ_ENVFROM(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:mid,suse.de:email,imap1.dmz-prg2.suse.org:helo] X-Spam-Level: X-Spam-Flag: NO Simplify the lock management in sev_asid_new() by using a mutex guard, automatically releasing the mutex when following the goto. Signed-off-by: Carlos L=C3=B3pez --- arch/x86/kvm/svm/sev.c | 24 ++++++++++-------------- 1 file changed, 10 insertions(+), 14 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index d3fa0963465d..d8d5c3a703f9 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -231,24 +231,20 @@ static int sev_asid_new(struct kvm_sev_info *sev, uns= igned long vm_type) return ret; } =20 - mutex_lock(&sev_bitmap_lock); - + scoped_guard(mutex, &sev_bitmap_lock) { again: - asid =3D find_next_zero_bit(sev_asid_bitmap, max_asid + 1, min_asid); - if (asid > max_asid) { - if (retry && __sev_recycle_asids(min_asid, max_asid)) { - retry =3D false; - goto again; + asid =3D find_next_zero_bit(sev_asid_bitmap, max_asid + 1, min_asid); + if (asid > max_asid) { + if (retry && __sev_recycle_asids(min_asid, max_asid)) { + retry =3D false; + goto again; + } + ret =3D -EBUSY; + goto e_uncharge; } - mutex_unlock(&sev_bitmap_lock); - ret =3D -EBUSY; - goto e_uncharge; + __set_bit(asid, sev_asid_bitmap); } =20 - __set_bit(asid, sev_asid_bitmap); - - mutex_unlock(&sev_bitmap_lock); - sev->asid =3D asid; return 0; e_uncharge: --=20 2.51.0