From nobody Sat Jul 25 06:09:12 2026 Received: from mail-pl1-f202.google.com (mail-pl1-f202.google.com [209.85.214.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 770C21DDC1D for ; Fri, 17 Jul 2026 00:24:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.202 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784247884; cv=none; b=V9ACM4haKwcQnMAOGFDgEfeIzUDYzAMfmD+L/YAlVp97qnFj8uIM3VPXmG8psp7obIN8kjLQuZgtlJgvF8uJyPKg2Uet+MfXhS+InxVgPS5DfUxFVEGTmPvgJorXA1D/g+eTP9abYdC1cR8ZyAX61ukxsVILYhW4K6iJZiFg+e8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784247884; c=relaxed/simple; bh=YWiHtTQfrKouiI2gIV/LBxL6/4x6FzP7KHrPoXsozeI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=UQdKTSpGj8P4TARerB843tUjN1L3uH8+roy7qHtfkbBtdRt3P/8jxstFYxePxpCpKwYhIqcMAkkAPJXHijV0hQ1w7+JXzFwnQn0v1LhPPJvpH51tPIsE7PwK0tUHmWNzVc5BVKx/0GYDZU8BMyvAIoYk9Jv4GNyLOyolx3EO9OM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--linkl.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=N5s0NrAm; arc=none smtp.client-ip=209.85.214.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--linkl.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="N5s0NrAm" Received: by mail-pl1-f202.google.com with SMTP id d9443c01a7336-2cce14a21faso19484075ad.0 for ; Thu, 16 Jul 2026 17:24:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784247883; x=1784852683; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=3BZOgadh0/WAQnS0GZRJ8uTk+OHst0wqYuvkCMlhb4s=; b=N5s0NrAmgBqeRVsTpenwjPG7gDJrH9TWE7heWeSFzPSoRsN5C3M+XqpKKlQSa7ld0J QTnlpa0lE13GGU1YU2ATZEPeQ3l5c100Nlu+oIpFyODaXjIjNFGCGisnnVlJISyAGOKC DFsjzJGuKmd7DARbMKTjDyB+RshT5Ss/IJ/rj/9/HGOng+F0+KfrNxnPRMXdydD/isJ9 /jEScbFttqP9T77X5VqgOE0RMKu34mhiuykFN0gHacdDxUx/aYUBUXMgdJ3fY0juwxFz Oo1GQkcoIQpYX5FFde2HxBywVUF6vn6dMPfjvCxfgCWh4vmpoqqPNb4jDO8oN092rhEi imjg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784247883; x=1784852683; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3BZOgadh0/WAQnS0GZRJ8uTk+OHst0wqYuvkCMlhb4s=; b=ddjvA7r8zd9eXfezZVXDBhhr8cjfY9lMxrPk2a4jLZRkPNjn4JxfHJZVfEBoKdiBek KPaIs28I+Agl1vOMoqQX2GU2yD831HmGfq2jzZdid8XbENs8aaTXEhVFRYZPYNJDOIZf S7Bm6HrJkhuBlH6SWjBDQcm5WLc0f6CFKIvb/u6EapZtWd7O6IWzxhW8qpTj94HpqZJJ Ik30xPIjvs4SuOduVE1yDr9nhI8oz9rFTg3jkNicmiHU2QR0TtDEnUPzlcKLm22juZCo Yo5UTKpMwddJfsDqx1XHdt6pj7VA+RLVMW/inZHR1rqqyBNP7IOI51a4nN+C60I0iMli XkQQ== X-Forwarded-Encrypted: i=1; AHgh+RpWf2nA475zN2QqHtZ8tlkXQ8EJJoNLreZvKnU5BX+FHiYledNBz+DDUm7SHBZgaPsBq48XDR6gIlam0X8=@vger.kernel.org X-Gm-Message-State: AOJu0Yy1cweAZ9MDTZZeUPNcG1FoTD4OvFQx8q2RuDCbfb5uMmJ13EIq XynjKFf2TTURa/FRSMcWFg7DNjzoGtonOyilfpHbQAzHI8zfVKzUbJQBc20/pXZAz/pTDxpwAhq UOA== X-Received: from plhv17.prod.google.com ([2002:a17:903:2391:b0:2ce:aea4:5e73]) (user=linkl job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:f683:b0:2cc:db7a:251 with SMTP id d9443c01a7336-2cf1f2561eemr47925045ad.2.1784247882515; Thu, 16 Jul 2026 17:24:42 -0700 (PDT) Date: Fri, 17 Jul 2026 00:22:20 +0000 In-Reply-To: <20260717002311.681748-1-linkl@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260717002311.681748-1-linkl@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260717002311.681748-2-linkl@google.com> Subject: [PATCH v2 1/2] mm/page_reporting: use system_freezable_wq to fix UAF during suspend From: Link Lin To: Andrew Morton , Vlastimil Babka , "Michael S . Tsirkin" , David Hildenbrand Cc: virtualization@lists.linux.dev, linux-mm@kvack.org, linux-kernel@vger.kernel.org, prasin@google.com, rientjes@google.com, duenwen@google.com, jasowang@redhat.com, xuanzhuo@linux.alibaba.com, Ammar Faizi , jiaqiyan@google.com, ahwilkins@google.com, Greg Thelen , Alexander Duyck , jthoughton@google.com, stable@vger.kernel.org, Link Lin , David Hildenbrand Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" During PM freeze (e.g. S3 suspend or S4 hibernation), device drivers like virtio_balloon reset their underlying virtio devices and delete their virtqueues via vdev->config->del_vqs(). However, page reporting work (page_reporting_process) was scheduled on the global system_wq. Because system_wq lacks the WQ_FREEZABLE flag, the PM freezer skips it, leaving page_reporting_process active during suspend. If pages are freed into the buddy allocator while suspending, page reporting invokes virtballoon_free_page_report() on deleted virtqueues: [ 196.795226] general protection fault, probably for non-canonical add= ress 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI [ 196.825967] Workqueue: events page_reporting_process [ 196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring] [ 196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon] [ 196.946943] page_reporting_process+0x370/0x4f0 Fix this by switching page reporting work to system_freezable_wq. This ensures that the PM freezer pauses page_reporting_process before device drivers destroy their reporting virtqueues. This aligns with the driver's existing design. The comment in virtballoon_freeze() states: /* * The workqueue is already frozen by the PM core before this * function is called. */ Suggested-by: David Hildenbrand Suggested-by: Michael S. Tsirkin Acked-by: David Rientjes Fixes: 924a663f75e2 ("virtio-balloon: Reporting free page reservations") Cc: stable@vger.kernel.org Signed-off-by: Link Lin Acked-by: David Hildenbrand (Arm) Acked-by: Michael S. Tsirkin --- mm/page_reporting.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/mm/page_reporting.c b/mm/page_reporting.c index 7418f2e500..4dc6f4b852 100644 --- a/mm/page_reporting.c +++ b/mm/page_reporting.c @@ -80,7 +80,8 @@ __page_reporting_request(struct page_reporting_dev_info *= prdev) * now we are limiting this to running no more than once every * couple of seconds. */ - schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY); + queue_delayed_work(system_freezable_wq, &prdev->work, + PAGE_REPORTING_DELAY); } =20 /* notify prdev of free page reporting request */ @@ -343,7 +344,8 @@ static void page_reporting_process(struct work_struct *= work) */ state =3D atomic_cmpxchg(&prdev->state, state, PAGE_REPORTING_IDLE); if (state =3D=3D PAGE_REPORTING_REQUESTED) - schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY); + queue_delayed_work(system_freezable_wq, &prdev->work, + PAGE_REPORTING_DELAY); } =20 static DEFINE_MUTEX(page_reporting_mutex); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 06:09:12 2026 Received: from mail-pj1-f73.google.com (mail-pj1-f73.google.com [209.85.216.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9DDD02147F9 for ; Fri, 17 Jul 2026 00:24:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.73 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784247886; cv=none; b=QAK/54yfaV6iC8Hygg/XFTw5JNAotqN6mnkvAbfJlkMWTKMBy9JkBU1rRKliNXCwrhoTHmhsGStcbpc0bf90L4Ib4d2NHWOUhH/tz0UtAbOFvqN1Bxl7NHUGZT6dp2BCfx4zmf2mxYrwmvdrZyaDgLKnfEj5bbXtaQRBV2jT02Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784247886; c=relaxed/simple; bh=JCyh+AtN6PAa02kmcYI4QuJSIXU7zu3BHW7iW+Zlpy0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=pEC+GWgbE4QeIWtRu65K07r1tqzaPeJeEi0CBREXMoUbWNI2bf2Yr6eHtaEUlKbMR9pJBi6QjSVkal57otluxJL6K0SGcVx5ESz0qqfT2QOapFdvtoXX2ZSekzZ1JKMWy6ZrAZC3lfkTPCE3eqvnYLO51pBJ+RWKI/WP47Zc2+8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--linkl.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=ZI4yXMxc; arc=none smtp.client-ip=209.85.216.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--linkl.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="ZI4yXMxc" Received: by mail-pj1-f73.google.com with SMTP id 98e67ed59e1d1-384419c6c74so9193686a91.1 for ; Thu, 16 Jul 2026 17:24:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784247884; x=1784852684; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=kvV/YUs48FxJuWf2yjxeyeKt50HRM0qCcCCbR1JgotU=; b=ZI4yXMxc8fFcATYQWBJmXgjV6gRM5jQ1EMNnri10Vxc2LAAaYNMP2/PgYx5QLOum94 Cxj5O1s8zrH1MTOcvujOcaElCGAAJSLG1Cj/B7hkFoNAHtNkCuA729tMK9cDd1hB9P9u polwWFeF5+F1bw1mIMCXjJJfLfWp+ujy0uqQ5Xi8F24FK/4tFDWNrSu1loUs+pmzo+qm uc18QTxPfARafGRh+NzarTy0JxZMPl7u4TCc8+EokUEJN7quEaf/VtAnwOxHBndFc0RD UtaA4AIyyBxf3B0PdL47QawgjnVuW8TYHrglyMMmTgerMPhpNmBu0nFXC/8j+x9u79V0 2JYw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784247884; x=1784852684; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=kvV/YUs48FxJuWf2yjxeyeKt50HRM0qCcCCbR1JgotU=; b=R5C15hbxDu9EA5qFiQgLS+uB9kFHAHPnIawq2k/+YGZFtU5nht012zmZjCQs1paN13 sUmrQsscHhleWcSmS3sw3OzkJPdhouJitVNXF6rwnqMKoPWDt3DspniBAlIIquv6wmci UL1sipJscf+wZNL1Usx9/OFQ5l0ur3I766cvSTq1Fq9xxiUDG0kIhthjrQ8pjYjnq4f9 NVFfPrsMI5e0aTT3jjP1hLtXNm2YBF0O3paA6nfJkfFB52numTUuOnXtNjWQrAsP7x2L yqJ6JVrRPDoGYMC4Q6jCM8kGPjPUj2GAvSGT4us9bQVtlGHmD0KO4kwAQiV67WjdsPlw AvLA== X-Forwarded-Encrypted: i=1; AHgh+Rr3+H2IiOJu0BNWyZKdo2oMy82ioHwg7P0jIkt+Tw0Xd4b+Ut4SZS/rdRAg+IfCaWXilUaV3Jix3F9Ct2I=@vger.kernel.org X-Gm-Message-State: AOJu0YwNbF4eWB4lNjpjlgLh7/k/kilchM1Wl6ArLwQo3MyY456iPNBG pRrgnXT8PQikqpCb7QawBStBMq4mp1CNrlQDPvGsHfs9X+8IJWoFHbRYidtWEus554QyjmC725K khA== X-Received: from pjbds23.prod.google.com ([2002:a17:90b:8d7:b0:389:a1f7:c74d]) (user=linkl job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:1345:b0:37f:9ce1:cdb0 with SMTP id 98e67ed59e1d1-38e4b55aeccmr247935a91.30.1784247883538; Thu, 16 Jul 2026 17:24:43 -0700 (PDT) Date: Fri, 17 Jul 2026 00:22:21 +0000 In-Reply-To: <20260717002311.681748-1-linkl@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260717002311.681748-1-linkl@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260717002311.681748-3-linkl@google.com> Subject: [PATCH v2 2/2] virtio_balloon: avoid shrinker execution during PM suspend From: Link Lin To: Andrew Morton , Vlastimil Babka , "Michael S . Tsirkin" , David Hildenbrand Cc: virtualization@lists.linux.dev, linux-mm@kvack.org, linux-kernel@vger.kernel.org, prasin@google.com, rientjes@google.com, duenwen@google.com, jasowang@redhat.com, xuanzhuo@linux.alibaba.com, Ammar Faizi , jiaqiyan@google.com, ahwilkins@google.com, Greg Thelen , Alexander Duyck , jthoughton@google.com, stable@vger.kernel.org, Link Lin Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" During PM freeze (e.g. S4 hibernation), virtballoon_freeze() calls remove_common() which resets the virtio device and deletes all virtqueues. However, the balloon shrinker remains registered with core MM. If memory pressure occurs during S4 hibernation image creation/saving, MM invokes virtio_balloon_shrinker_scan(), which attempts to reclaim free pages. Although return_free_pages_to_mm() only frees pages back to MM, reclaiming free pages under memory pressure can trigger page reporting which might access the deleted reporting virtqueue if it is not yet frozen, or interact with other parts of the driver in a teardown state. Avoid this by adding a `suspended` flag to `struct virtio_balloon`. Set this flag to true in virtballoon_freeze() and false in virtballoon_restore(). Check this flag in both shrinker callbacks (scan and count) and return 0 if the device is suspended, preventing any shrinker execution while virtqueues are deleted. Wrap the lockless reads in READ_ONCE() and writes in WRITE_ONCE() to prevent compiler optimization issues and KCSAN data race warnings. Fixes: 71019de8219b ("virtio_balloon: Add free page hinting support") Cc: stable@vger.kernel.org Acked-by: David Rientjes Signed-off-by: Link Lin Suggested-by: James Houghton --- drivers/virtio/virtio_balloon.c | 49 +++++++++++++++++++++++++++------ 1 file changed, 41 insertions(+), 8 deletions(-) diff --git a/drivers/virtio/virtio_balloon.c b/drivers/virtio/virtio_balloo= n.c index 088b3a0e6c..38e1166a64 100644 --- a/drivers/virtio/virtio_balloon.c +++ b/drivers/virtio/virtio_balloon.c @@ -68,6 +68,8 @@ struct virtio_balloon { /* Prevent updating balloon when it is being canceled. */ spinlock_t stop_update_lock; bool stop_update; + /* Prevent shrinker from running while device is suspended. */ + bool suspended; /* Bitmap to indicate if reading the related config fields are needed */ unsigned long config_read_bitmap; =20 @@ -471,9 +473,9 @@ static inline s64 towards_target(struct virtio_balloon = *vb) return target - vb->num_pages; } =20 -/* Gives back @num_to_return blocks of free pages to mm. */ -static unsigned long return_free_pages_to_mm(struct virtio_balloon *vb, - unsigned long num_to_return) +/* Helper: must be called with free_page_list_lock held */ +static unsigned long __return_free_pages_to_mm(struct virtio_balloon *vb, + unsigned long num_to_return) { unsigned long num_returned =3D 0; struct page *page, *next; @@ -481,8 +483,6 @@ static unsigned long return_free_pages_to_mm(struct vir= tio_balloon *vb, if (unlikely(!num_to_return)) return 0; =20 - spin_lock_irq(&vb->free_page_list_lock); - list_for_each_entry_safe(page, next, &vb->free_page_list, lru) { list_del(&page->lru); __free_pages(page, VIRTIO_BALLOON_HINT_BLOCK_ORDER); @@ -490,11 +490,27 @@ static unsigned long return_free_pages_to_mm(struct v= irtio_balloon *vb, break; } vb->num_free_page_blocks -=3D num_returned; - spin_unlock_irq(&vb->free_page_list_lock); =20 return num_returned; } =20 +/* Gives back @num_to_return blocks of free pages to mm. */ +static unsigned long return_free_pages_to_mm(struct virtio_balloon *vb, + unsigned long num_to_return) +{ + unsigned long ret; + + spin_lock_irq(&vb->free_page_list_lock); + if (vb->suspended) { + spin_unlock_irq(&vb->free_page_list_lock); + return 0; + } + ret =3D __return_free_pages_to_mm(vb, num_to_return); + spin_unlock_irq(&vb->free_page_list_lock); + + return ret; +} + static void virtio_balloon_queue_free_page_work(struct virtio_balloon *vb) { if (!virtio_has_feature(vb->vdev, VIRTIO_BALLOON_F_FREE_PAGE_HINT)) @@ -871,6 +887,9 @@ static unsigned long virtio_balloon_shrinker_scan(struc= t shrinker *shrinker, { struct virtio_balloon *vb =3D shrinker->private_data; =20 + if (READ_ONCE(vb->suspended)) + return 0; + return shrink_free_pages(vb, sc->nr_to_scan); } =20 @@ -879,6 +898,9 @@ static unsigned long virtio_balloon_shrinker_count(stru= ct shrinker *shrinker, { struct virtio_balloon *vb =3D shrinker->private_data; =20 + if (READ_ONCE(vb->suspended)) + return 0; + return vb->num_free_page_blocks * VIRTIO_BALLOON_HINT_BLOCK_PAGES; } =20 @@ -1089,8 +1111,11 @@ static void remove_common(struct virtio_balloon *vb) update_balloon_size(vb); =20 /* There might be free pages that are being reported: release them. */ - if (virtio_has_feature(vb->vdev, VIRTIO_BALLOON_F_FREE_PAGE_HINT)) - return_free_pages_to_mm(vb, ULONG_MAX); + if (virtio_has_feature(vb->vdev, VIRTIO_BALLOON_F_FREE_PAGE_HINT)) { + spin_lock_irq(&vb->free_page_list_lock); + __return_free_pages_to_mm(vb, ULONG_MAX); + spin_unlock_irq(&vb->free_page_list_lock); + } =20 /* Now we reset the device so we can clean up the queues. */ virtio_reset_device(vb->vdev); @@ -1133,6 +1158,10 @@ static int virtballoon_freeze(struct virtio_device *= vdev) * The workqueue is already frozen by the PM core before this * function is called. */ + spin_lock_irq(&vb->free_page_list_lock); + WRITE_ONCE(vb->suspended, true); + spin_unlock_irq(&vb->free_page_list_lock); + remove_common(vb); return 0; } @@ -1148,6 +1177,10 @@ static int virtballoon_restore(struct virtio_device = *vdev) =20 virtio_device_ready(vdev); =20 + spin_lock_irq(&vb->free_page_list_lock); + WRITE_ONCE(vb->suspended, false); + spin_unlock_irq(&vb->free_page_list_lock); + if (towards_target(vb)) virtballoon_changed(vdev); update_balloon_size(vb); --=20 2.55.0.229.g6434b31f56-goog