From nobody Tue Sep 29 04:09:43 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C6E2D38238F; Wed, 12 Aug 2026 17:09:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554598; cv=none; b=Nsoh7AOeEzmdyKtzTGoDbADbPrvVimHAWKQvLOZSyBVO9lkj6oG5UqYU7HJ/VkvZ9tkMupz87r979/57Sv4/r6useGsGzd5P1KBsnB/MNmVmZwekUgxZcl5VKNa3dNU7zS+XclzI2FZlYY8uzV0MY7vSH3q6hPjabHcvNgwkkqg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554598; c=relaxed/simple; bh=hAk5VFZTgMbDNPLe+AA+zMf0YOhx4PJoLsGEtIiKUxc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=BoIg7WzeAoLTEJKVNYry6/fdcYJB89ueRqqL8xjuLyh+LhF1MyKDma3YtoZXAzRdVpwTeasQruYTtnLc/iyQl1Ts0m/zppzizAGCm1jS13xBDt23DZ0HMZ3n27RdufxTQ/dHAJdvuILVQZt8XLUfVJ8bir36TwHT+gADRQ2Ztd8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=OrD+e9Hz; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="OrD+e9Hz" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1c692217969; Wed, 12 Aug 2026 17:09:50 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=+1ReYvhFvHs/C9ZAt kBPmRv/N1oXc4R/xDf8I9N/tjo=; b=OrD+e9HzAWcoidOsIUQBPIpOGJenSTe5V qiNOBTgZnBhhdH+ZV5xDaMFNWZ5FR5whAuER0QIaXjEbWFe2vA5kqaYbRQdkROyI aD9oDSznWM/fLbstx0yUBjmYxXPEAzSi1Jr9CIy1b03DL8Usjic4g3lw2DTOANtE WUauHh7rjmvXcHky1vVgPF38o0qV3AvT/X5vb8UdQLrRvyjrkq5O4K9/bhZbhSI9 5HbfVGq4SkdL3n99/OZkgjuUanh8i0/HnsJoDivnCqjvGJ5QHRY102I/L2DZzyQe 7phhxh2GURt67CuenSrmNSfxY5Uc18p3x06sEjCqmGtFB8I5oD2LA== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvk03p23-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:50 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGuoJG030559; Wed, 12 Aug 2026 17:09:49 GMT Received: from smtprelay02.dal12v.mail.ibm.com ([172.16.1.4]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxesq78qq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:49 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay02.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9muZ62849282 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:48 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 89A0A5805E; Wed, 12 Aug 2026 17:09:48 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 791B458055; Wed, 12 Aug 2026 17:09:47 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:47 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 1/9] s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove Date: Wed, 12 Aug 2026 13:09:37 -0400 Message-ID: <20260812170945.738351-2-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX7xy8qKebL+QG HdsdOmzu+QeARkpp6Yc0MxM0Ecx6hm5oLpIMrmuEO2kiy0qesSEm2wDFufz3ITVvbqQ8dVgq7Ci eSQGX2E7mnoJidz2zbZUgKc6SB2bWg/nHvL83jry8wqVfILMeqqDifGHnEuZFYwuu/u7SonjT0R NmElGQaHXTOSPdIIdupslVkbPTPcjX9daPDv8SXIsUgkmEWXvMnfpcw6/ciqEOYO66BVKeQJlp4 Zf6BZTWRcGGcFHPifNdqu3R5bw7SXRIbjX96cbV2bfpEeXAXc+AiN1LVeM864EjV3L14HPORT41 fePqfiPeDT1BVpSwFlQuxBl4dmRt7UtIi9Vq6tYdWwfR2oY6FxaXoz+lAgeDEYZnveWQRul+Np4 mZzohXsiodM653qXN8ob8fo9uJW3gtrhq164o3g3OIv7BbmYM2ubPIqTk58sXftXu12ucrcG4Br 1ccZK1D2VzLkbrWZtgw== X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX8/hl5pzNipOG dVsTpoiyiImZQaM36PiO54J4JlMPSZFV8IMUwoluiHDdR+57Gz7RyhOfR7zdISn2LA36n5STP/O umrrmoRwvDvWQY9JPyxmqA5UBngdGKI= X-Authority-Analysis: v=2.4 cv=RqD16imK c=1 sm=1 tr=0 ts=6a7ca8de cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=dlTjfeu_wqJGreSUTgMA:9 X-Proofpoint-GUID: dZ0AZPyxHHBTl8jfGVxxJhtIM0bDC1jT X-Proofpoint-ORIG-GUID: dZ0AZPyxHHBTl8jfGVxxJhtIM0bDC1jT X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 suspectscore=0 lowpriorityscore=0 clxscore=1015 adultscore=0 bulkscore=0 malwarescore=0 impostorscore=0 spamscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" The do_remove flag in vfio_ap_mdev_cfg_remove() is initialised to zero before the loop that iterates over the list of matrix mdevs, but is never reset at the start of each iteration. Since do_remove is OR-accumulated across iterations, a positive result from one mdev carries over to subsequent mdevs. The fix is to set the do_remove flag with the first call to bitmap_and; for example: do_remove =3D bitmap_an rather than do_remove |=3D bitmap_and. Fixes: eeb386aeb5b7 ("s390/vfio-ap: handle config changed and scan complete= notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 44b3a1dcc1b3..845c86ba8bc3 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2603,15 +2603,15 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *= ap_remove, DECLARE_BITMAP(aprem, AP_DEVICES); DECLARE_BITMAP(aqrem, AP_DOMAINS); DECLARE_BITMAP(cdrem, AP_DOMAINS); - int do_remove =3D 0; + int do_remove; =20 list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { mutex_lock(&matrix_mdev->kvm->lock); mutex_lock(&matrix_dev->mdevs_lock); =20 - do_remove |=3D bitmap_and(aprem, ap_remove, - matrix_mdev->matrix.apm, - AP_DEVICES); + do_remove =3D bitmap_and(aprem, ap_remove, + matrix_mdev->matrix.apm, + AP_DEVICES); do_remove |=3D bitmap_and(aqrem, aq_remove, matrix_mdev->matrix.aqm, AP_DOMAINS); --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BBC8B47ECC5; Wed, 12 Aug 2026 17:09:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554600; cv=none; b=QSgabpXNtfGq0a5ZqWCTMnXVbk66NABkA8OpjrH5++vzsNehvzXMpPaeWUl1Pg9dkff3M5G6vh//tEJmKGZFsSPVpG1TkK5v6oev6J90UG2t3ruVuTrvgyz/5YlZf3faH1n9nX1B2NPC8SWxL7yKJzRqBolUg/f7vIkpeAxpkps= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554600; c=relaxed/simple; bh=unPH0ftrwS/7HITiOcWhYpqJf1M5a1XSPmtX60f2Fe8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=QFVf1wVWav9hk5bmofKBJP0booLfwDyUxscxrhvL+VRZ2T/BEi0Wov/Ojhv73SS8NR94icFCkANCvS6tUuHgnbZo/z5CZIRNPoV8rjffp7AToVV4Mj7Bm7WsKvu+kztXKT/tPa/QJDUE1z+6rMlJAVQDRZe6/RlTXPyWr118pWU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=aehdPVHL; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="aehdPVHL" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1atO4088173; Wed, 12 Aug 2026 17:09:53 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=xd4tuIPEUtcZR3kxf Vor1dQGByJCCqoSk+q/LP6t7V0=; b=aehdPVHL5O/FOBGh6dPzLirKE+XQ9RhMt KPqIiG/Et6/t4IzEiFSPhPmgOInq4xKBaKzDAGpK3+S/a5ZSnDnJIcoS6YB3Du41 hwUt4EpFdKiJvU1GUghXKZShzc4tAdqnGKe6qxf88kuQHwJvRafSwjwRUk9K5xbk HEy+XP6jIj+/W2+mzvtde6J6Oprsoa/jV0mkUNnDpaLqk35tk4zw7fKAmMHtAyH+ hR9oHV3+05EMBM25ZymnL2Gq3vEftm84KVty+gU/oFAE2z5viR6A7lklHmQMYRTf w4rWD+tuqhTfGM3E5ndW2SYPb9xfOkp6Og7T8561ZZZ1+PLJxlHkg== Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvm9uqtk-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:52 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGuigt006038; Wed, 12 Aug 2026 17:09:51 GMT Received: from smtprelay01.wdc07v.mail.ibm.com ([172.16.1.68]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxhfy6w0w-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:51 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay01.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9n1R5899012 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:50 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id ADB4C58061; Wed, 12 Aug 2026 17:09:49 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A47E658055; Wed, 12 Aug 2026 17:09:48 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:48 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 2/9] s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL Date: Wed, 12 Aug 2026 13:09:38 -0400 Message-ID: <20260812170945.738351-3-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX1o+RtP/JAnhs lGd5yrkOubD4Mf/kBWsx1csGdPTAkTGzeW/bDwao1hXJQfQk5RlW/1OtnxENZfCQeWe0j4oZJI/ 09fQqQ3pqMUF3zIu4nkawcO+IppwSO+zLPpKNiDiYwiVk3FoHGQGfQId6dSxSXb0yqfGf1Mlr3V Bmroxum04E3SnqAB9JoGcStw6pDfZ2D62OphXZc+n/7yCN1YE8S8+Ew5mAvxf9R21eyqpAofQjD GlXxCp+ylUh1DZIvyzp2RldDLmLo0VVOw58tMhSW9iQTHj4kJaNcA/BkJ5iAi0QdqH3QFWibX36 BJTX+xmnrVrZqUXWh65VaHbQKGnRDS5DwsJDivHbnQAMWpx8uRW1i/2GL2krdFwc1KjoazH516P CkEMwA3NGH+28bj2plDL+2Dp5blCO3R+hdaqfN/AwKJdfd2jnw0Hc8Qa3CquD3UQ2tZEAoaGCc4 TLQThgDmQQRijw2+hkw== X-Proofpoint-ORIG-GUID: tsPd1YjkOTcAcNLM1JKWSa49wvEDQjUf X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX5T3kbdp4HNRn hUVUjgUmVFIdR7rK5d7ervGlmnT8veYt5mTYvleqn82qYYjuz3KbmlDNkKoRmO3ZKarK8JgNVsL yiUeRpqKvkx0tQtyw+gg+ye1H0+TUwo= X-Authority-Analysis: v=2.4 cv=IfK3n2qa c=1 sm=1 tr=0 ts=6a7ca8e0 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=7-PX2TBNVYp1iSTFOFgA:9 X-Proofpoint-GUID: tsPd1YjkOTcAcNLM1JKWSa49wvEDQjUf X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 impostorscore=0 bulkscore=0 clxscore=1015 lowpriorityscore=0 adultscore=0 malwarescore=0 spamscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" The ap_driver structure has two fields which are function pointers to callbacks: * .on_config_changed: called at the start of the AP bus scan function to notify the device driver that the host AP configuration has changed and the associated AP devices will be added or removed accordingly. This gives the implementor a chance to evaluate the configuration changes and respond to them before the associated devices are added or removed. * .on_scan_complete: Called at the end of the AP bus scan function to notify the device driver that the host AP configuration has changed and the AP devices have been added or removed accordingly. This gives the implementor the opportunity to respond to the changes after the associated devices are added or removed. These two callbacks are implemented in the vfio_ap device driver via the vfio_ap_on_cfg_changed and vfio_ap_on_scan_complete functions respectively. Within the call stack of these two callback functions the matrix_mdev->kvm->lock mutex is taken without checking whether matrix_mdev->kvm is NULL or not. If matrix_mdev->kvm has never been set, trying to take the lock will trigger a NULL pointer dereference. This patch adds checks for matrix_mdev->kvm =3D=3D NULL before taking the matrix_mdev->kvm->lock mutex. Note that the matrix_mdev->kvm->lock mutex taken in the vfio_ap_mdev_hot_plug_config function is moved to the calling function along with the matrix_dev->mdevs_lock which is needed there to access the fields of the matrix_mdev. It makes little sense to make the change the check for matrix_mdev->kvm there before taking the kvm->lock mutex only to have to move it out via another patch, so it is done in this patch. It is important to make note of the following: 1. The matrix_dev->guests_lock is acquired at the start of both callback functions. This ensures that matrix_mdev will not be removed via the vfio_ap_mdev_remove function because it too takes matrix_dev_guests_lock before removing the object; so, matrix_mdev will be available for the duration of the callback functions. 2. The matrix_dev->mdevs_lock mutex must be taken in order to access fields within the matrix_mdev structure 3. matrix_mdev->kvm->lock mutex must be taken before the matrix_dev->mdevs_lock to prevent a lockdep splat. 4: The kvm->lock must be held while plugging the guest's AP configuration into its SIE state description via the vfio_ap_mdev_update_guest_apcb function. 5. The vfio_ap_mdev_update_guest_apcb checks matrix_mdev->kvm to verify it is not NULL before doing the hot plug of the guest's AP configuration. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 39 ++++++++++++++++++++++++------- 1 file changed, 30 insertions(+), 9 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 845c86ba8bc3..c6bee69cc22f 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2605,8 +2605,20 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *a= p_remove, DECLARE_BITMAP(cdrem, AP_DOMAINS); int do_remove; =20 + /* + * It is safe to traverse this list here because the + * required guard - matrix_dev->guests_lock - is taken in the + * vfio_ap_on_cfg_changed function prior to this function getting + * called. + */ list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { - mutex_lock(&matrix_mdev->kvm->lock); + /* + * The mdevs_lock must be held to access fields within matrix_mdev, + * and kvm->lock must be taken before mdevs_lock to satisfy the lock + * ordering requirement and prevent a lockdep splat. + */ + if (matrix_mdev->kvm) + mutex_lock(&matrix_mdev->kvm->lock); mutex_lock(&matrix_dev->mdevs_lock); =20 do_remove =3D bitmap_and(aprem, ap_remove, @@ -2624,7 +2636,8 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *ap= _remove, cdrem); =20 mutex_unlock(&matrix_dev->mdevs_lock); - mutex_unlock(&matrix_mdev->kvm->lock); + if (matrix_mdev->kvm) + mutex_unlock(&matrix_mdev->kvm->lock); } } =20 @@ -2821,9 +2834,6 @@ static void vfio_ap_mdev_hot_plug_cfg(struct ap_matri= x_mdev *matrix_mdev) DECLARE_BITMAP(apm_filtered, AP_DEVICES); bool filter_domains, filter_adapters, filter_cdoms, do_hotplug =3D false; =20 - mutex_lock(&matrix_mdev->kvm->lock); - mutex_lock(&matrix_dev->mdevs_lock); - filter_adapters =3D bitmap_intersects(matrix_mdev->matrix.apm, matrix_mdev->apm_add, AP_DEVICES); filter_domains =3D bitmap_intersects(matrix_mdev->matrix.aqm, @@ -2841,9 +2851,6 @@ static void vfio_ap_mdev_hot_plug_cfg(struct ap_matri= x_mdev *matrix_mdev) vfio_ap_mdev_update_guest_apcb(matrix_mdev); =20 reset_queues_for_apids(matrix_mdev, apm_filtered); - - mutex_unlock(&matrix_dev->mdevs_lock); - mutex_unlock(&matrix_mdev->kvm->lock); } =20 void vfio_ap_on_scan_complete(struct ap_config_info *new_config_info, @@ -2854,15 +2861,29 @@ void vfio_ap_on_scan_complete(struct ap_config_info= *new_config_info, mutex_lock(&matrix_dev->guests_lock); =20 list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { + /* + * The mdevs_lock must be held to access fields within matrix_mdev, + * and kvm->lock must be taken before mdevs_lock to satisfy the lock + * ordering requirement and prevent a lockdep splat. + */ + if (matrix_mdev->kvm) + mutex_lock(&matrix_mdev->kvm->lock); + mutex_lock(&matrix_dev->mdevs_lock); + if (bitmap_empty(matrix_mdev->apm_add, AP_DEVICES) && bitmap_empty(matrix_mdev->aqm_add, AP_DOMAINS) && bitmap_empty(matrix_mdev->adm_add, AP_DOMAINS)) - continue; + goto do_unlock; =20 vfio_ap_mdev_hot_plug_cfg(matrix_mdev); bitmap_clear(matrix_mdev->apm_add, 0, AP_DEVICES); bitmap_clear(matrix_mdev->aqm_add, 0, AP_DOMAINS); bitmap_clear(matrix_mdev->adm_add, 0, AP_DOMAINS); + +do_unlock: + mutex_unlock(&matrix_dev->mdevs_lock); + if (matrix_mdev->kvm) + mutex_unlock(&matrix_mdev->kvm->lock); } =20 mutex_unlock(&matrix_dev->guests_lock); --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 94F92480948; Wed, 12 Aug 2026 17:10:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554604; cv=none; b=D6qUBM3hAPHtMZQ8LxZPfpFX2XPvtBP0Q+0j24LoUkZ3FrNZXvowSmsQ+a+T1evRdisn+a8o0USB7p1ZWO/2lyGEW3ue25cFjNduYl2EhlpWGq0BP0bxhTfsy/YLtz6u32hFrS4wV10tWHphocuz6bCpSdAsunS3hRFTAHWdtwU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554604; c=relaxed/simple; bh=fW5pD8sDwhcCDXWf8ZIJJ55PI3tKhL6NSCRDBnsVJy8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=QXxoX022s+X+zx4MLQ38Q5FjP2x68nrcbtOgpv/0juq4KJiENX7qqJuiqNDOB+S2kpreha6HRwpSGOCpnEQOIxLDptApjWKSFFBsNRXOuBbhexuuKMUTXbdUv9g1tUJP9T1yaIdsWEHn9gB2+mX6J/qUcoSftwlnpQZOYOOSWtA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=XqWWhy8B; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="XqWWhy8B" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1Sqe4040648; Wed, 12 Aug 2026 17:09:54 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=9zSYwEpZLHwXh7QUa MzdW+WRNO+WXyysEw6YZbqHS/w=; b=XqWWhy8BY2+E3Xq+rgcBaUpSogiiUiAxo /H1+GLnW+lRHCToEYx5ThYXqANfxQAAIwh/KarUmUiBJUh2CsLErnpA1nDSoteii wP1xgg7B8PaGOMXkW9lzeXkxA4AmQJGSVtGYh61FEdvbVMQ7V27PH2mdfIirl40Q TyvF9ipuPFtvQR47yadUqPwRMgIh6t8/N66N47BPngHhhPh9lZD4RIB2Tl3X26SM pHLFHllIGMC1H6NbJbg9F9jmxXlo4mbGrmdCb+ueuCIMvWdYfQM5BTWUzMUX2Z55 epgG4mlScVnrG8LDw/V4Ywo2lwPQ7XNi4I/mxfVeWMIKKreDQaR+A== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvq9kn89-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:53 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGuiKS021428; Wed, 12 Aug 2026 17:09:52 GMT Received: from smtprelay02.wdc07v.mail.ibm.com ([172.16.1.69]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxf5w7768-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:52 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay02.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9oPC26018354 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:51 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D50285805D; Wed, 12 Aug 2026 17:09:50 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C7CB358043; Wed, 12 Aug 2026 17:09:49 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:49 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 3/9] s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects Date: Wed, 12 Aug 2026 13:09:39 -0400 Message-ID: <20260812170945.738351-4-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: cRCagdXQcfINXcxyOSe2QjGeHERLUQD_ X-Authority-Analysis: v=2.4 cv=PbDPQChd c=1 sm=1 tr=0 ts=6a7ca8e1 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=9go2EFdEqeYIEFJGgSIA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX4XgAlKv0HREZ ZXbwd/X9wBwjjHRn+Fwqw/smrQf/jopnoxZ2PopiiUM7+wgXSw49P7Cd87M3jbkUQ5da/nEIbz3 zB5b1HdR+l+HNQpUoKVSJu8RvjOV/btEpVZvlYPXcF3rG8Snm6pwqI/dr4myJN7bk+nGs10ea63 YREz85RzeNE7v2Ll03o5iTACvOJfvHkHLtNl0hQ4c3WlvHHpcnSOH1qas6U/hrUMjo/WAGQK4X3 1fy9gayRhC/GGT6nsVXo6hUgBwiks34qp2VkbSx2M+Ecq8pGqKFwaFTsF+BtvMANcSxo2JzoLq2 2KhqS7CVchEX1pxQYS7G0A8dr6pn632sHhoWgdiLAtSWUkZr2oWMoRSTgKnVldzjIMoXaCzT+Qp leBxSuMbQSpABR7t052/h2zKMTXFcX4RGa+d5xXd3XI0rqJHgywperDIoDwCztdVYpwwxQQQ1CB dtfLetcNwHgcY5qZRMg== X-Proofpoint-ORIG-GUID: cRCagdXQcfINXcxyOSe2QjGeHERLUQD_ X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX6mv+7WI4RAvc EJxhP4S8PNe4Tkq3oqdAvSmaYBf1MocqqSvEwy7rfUoN93oLCNrY/SEBOeLY1Ou9ACW/1ix6p4l LUJ5IH8nrT63xca5l4TqBo2VbXMLHpo= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 impostorscore=0 malwarescore=0 adultscore=0 clxscore=1015 priorityscore=1501 suspectscore=0 phishscore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" In order to traverse or add/remove ap_matrix_mdev objects in the matrix_dev->mdev_list, the matrix_dev->guests_lock mutex must be held. There are two functions that access the list without holding the mutex: vfio_ap_mdev_probe function ~~~~~~~~~~~~~~~~~~~~~~~~~~~ The vfio_ap_mdev_probe function uses the matrix_dev->mdevs_lock mutex to guard the add of a newly created ap_matrix_mdev object to the matrix_dev->mdev_list. This mutex does not protect list access; its purpose is to guard against concurrent access to fields contained in an ap_matrix_mdev object. This could lead to kernel memory corruption or use-after-free if another mdev is created or removed concurrently. The adding of an ap_matrix_mdev object to matrix_dev->mdev_list is now guarded by the matrix_dev->guests_lock which is the correct way to protect against concurrent mdev_list access. Also removed the following two lines of code because the matrix_mdev is allocated via vfio_alloc_device macro which uses kzalloc, so req_trigger and cfg_chg_trigger are already zero-initialised when the struct is allocated before the call to vfio_register_emulated_iommu_dev. This prevents a window whereby these triggers are set to NULL after the device is exposed to userspace. matrix_mdev->req_trigger =3D NULL; matrix_mdev->cfg_chg_trigger =3D NULL; vfio_ap_mdev_for_queue function ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ The status_show function that supports display of the status attribute of the devices in /sys/bus/ap/devices calls the vfio_ap_mdev_for_queue function which iterates the matrix_dev->mdev_list to find the object representing the queue device whose status is to be displayed. In order to traverse this list, the matrix_dev->guests_lock mutex must be held. To fix this, the guests_lock mutex is taken prior to taking the matrix_dev->mdevs_lock mutex in the status_show function. It is taken there rather than the vfio_ap_mdev_for_queue function - where it is needed - because it must be taken prior to the mdevs_lock mutex in order to adhere to the proper locking order and prevent a lockdep splat; also because the mdevs_lock is needed there to access fields within the matrix_mdev object in that function. See the vfio-ap-locking.rst in the linux kernel tree. Fixes: 2c1ee8983aa3 ("s390/vfio-ap: prepare for dynamic update of guest's A= PCB on queue probe/remove") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 27 +++++++++++++++++++++++---- 1 file changed, 23 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index c6bee69cc22f..f2d662e388bd 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -800,12 +800,17 @@ static int vfio_ap_mdev_probe(struct mdev_device *mde= v) ret =3D vfio_register_emulated_iommu_dev(&matrix_mdev->vdev); if (ret) goto err_put_vdev; - matrix_mdev->req_trigger =3D NULL; - matrix_mdev->cfg_chg_trigger =3D NULL; + + /* + * Take the matrix_dev->guests_lock mutex before adding the matrix_mdev + * to the mdev_list. All functions that traverse the list must also hold + * this lock to guard against additions to or removals from the list + * while it is being traversed. + */ + mutex_lock(&matrix_dev->guests_lock); dev_set_drvdata(&mdev->dev, matrix_mdev); - mutex_lock(&matrix_dev->mdevs_lock); list_add(&matrix_mdev->node, &matrix_dev->mdev_list); - mutex_unlock(&matrix_dev->mdevs_lock); + mutex_unlock(&matrix_dev->guests_lock); return 0; =20 err_put_vdev: @@ -2297,6 +2302,8 @@ static struct ap_matrix_mdev *vfio_ap_mdev_for_queue(= struct vfio_ap_queue *q) unsigned long apid =3D AP_QID_CARD(q->apqn); unsigned long apqi =3D AP_QID_QUEUE(q->apqn); =20 + lockdep_assert_held(&matrix_dev->guests_lock); + list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { if (test_bit_inv(apid, matrix_mdev->matrix.apm) && test_bit_inv(apqi, matrix_mdev->matrix.aqm)) @@ -2316,6 +2323,7 @@ static ssize_t status_show(struct device *dev, struct ap_matrix_mdev *matrix_mdev; struct ap_device *apdev =3D to_ap_dev(dev); =20 + mutex_lock(&matrix_dev->guests_lock); mutex_lock(&matrix_dev->mdevs_lock); q =3D dev_get_drvdata(&apdev->device); matrix_mdev =3D vfio_ap_mdev_for_queue(q); @@ -2343,6 +2351,7 @@ static ssize_t status_show(struct device *dev, } =20 mutex_unlock(&matrix_dev->mdevs_lock); + mutex_unlock(&matrix_dev->guests_lock); =20 return nchars; } @@ -2761,6 +2770,12 @@ static void vfio_ap_mdev_cfg_add(unsigned long *apm_= add, unsigned long *aqm_add, =20 vfio_ap_filter_apid_by_qtype(apm_add, aqm_add); =20 + /* + * It is safe to traverse this list here because the + * required guard - matrix_dev->guests_lock - is taken in the + * vfio_ap_on_cfg_changed function prior to this function getting + * called. + */ list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { bitmap_and(matrix_mdev->apm_add, matrix_mdev->matrix.apm, apm_add, AP_DEVICES); @@ -2820,6 +2835,10 @@ void vfio_ap_on_cfg_changed(struct ap_config_info *c= ur_cfg_info, if (!cur_cfg_info || !prev_cfg_info) return; =20 + /* + * Take the guests_lock mutex here to guard access to the + * matrix_dev->mdev_list in the two functions called below. + */ mutex_lock(&matrix_dev->guests_lock); =20 vfio_ap_mdev_on_cfg_remove(cur_cfg_info, prev_cfg_info); --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3273447F780; Wed, 12 Aug 2026 17:09:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554601; cv=none; b=tQxg1KWxO4cgeg8esZwrQPB8+g2vJLNeDuKlRGfFCRjnJqQ2SssMLKiz0Y3LjMDcZXNm35WzZQu3sGigeA+AS9FOXRl49FuQdtMqfFBxIUkUFIsplo7NHuUDhGUaevP8+p5LMW4QzP2OqOLhYTC+6mMrfahqsoR5UBYGyOJdxWQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554601; c=relaxed/simple; bh=5yyNdGdxAelRtvmaSTyzi6Ux60obfEZJ1rH6Pw+dKr8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CTJQaOo2ZQHRhqK4dTdiRfDrj5vA/zUVFkwLB/t7B2pvx7ReJFqtgm5L0IajnknKMSQRk/5JDhvFQwVHihqw8muqFPE+zt5MNVySi8Hx4Um/J9rdMtyG/DsIKrZWdMQZlLoho5NAY9GjdGT7bCUCToo94aRPMpgpPlcOoXN97a0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=fKPxkwVx; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="fKPxkwVx" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1W0t4088083; Wed, 12 Aug 2026 17:09:54 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=m+vJqnk7rifev6aJu KE56s9GIpbulLzAG2kXbqJoKd8=; b=fKPxkwVxJIaraIoLmMI0q6mcV1saJMR3c 9PUij+H7V11vp/Uk2hrShupUcmDViC4CCt9Pf8hb02O7nFGL0zvsw2OvqMWy3s+n X8s6X4k5bZ/PGHHNpaUM9RO9EiQC6aj/XdfXTDxkAv3BDyBxRGvMQ/hs/ssh0ubQ 98VG5mr8Pa1jSGNxH28GCLff4Vg05R/39+s5xZI9A2+cng3/MyZw7WwY95tRKo5u B/9dE00FOV2u1moKrlkI0RD09bauWhkw5sna8cbDhMBNidcEwffPdAV6KC+6q6XC E6naG9rJ4l8ZpCjg/ptpW7JPDKYCOTPROjokhi+osD7NZr5DzPs2A== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvm9uqtr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:54 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGutmV031270; Wed, 12 Aug 2026 17:09:53 GMT Received: from smtprelay04.wdc07v.mail.ibm.com ([172.16.1.71]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxg9h71fj-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:53 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay04.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9qFj32637626 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:52 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0895F58043; Wed, 12 Aug 2026 17:09:52 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id F115C5805F; Wed, 12 Aug 2026 17:09:50 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:50 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 4/9] s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object Date: Wed, 12 Aug 2026 13:09:40 -0400 Message-ID: <20260812170945.738351-5-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX5IrtyeIkQBLT 7egHxeIog1Eumdw8e7+2ii/u+p9SR64vozowGPYvUC3j+xsjKVXwYvP/E1j4xGV6h8dNDbC3vtw gYEpS0PUSrIoA17maGPhWMUhUJAcRfMEbd4uFzvF5DxUyQBn+lbvDYIaosGiH361huTkpOsWodR AArfKjdSabbu3zg5GJpUKOM2O41Z6+Xe/ufw0bLFzgJJc0arDXQSsR9/xIzF6HwWm+4Z4L1ckbg BPTNAZzahN/HqhIEuG8RQsf1OlIMAragNdZ2vGowYTVObmkpNaAVM9SM4PHaureadYfS2XAafG1 UFgXnv73D/lrPUK0sYxcQJIcCfzziUWl2NGrGos82tmpKwEykTLLTdLQkgxjwwqkLuyu7KmM8vu z1j5gWzCmNR6yGXpkeIrK3ea2AIj8kcZ6M420p28K98HM0dfr8J1HdC1bic9WOGCtCANT26+HIH qNhiLNXIs1DfUYmY1YQ== X-Proofpoint-ORIG-GUID: ai5aBwHHn1saZEX8vrhA4-sHGL04sbNe X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfXw0QQjtZB3ftG 8W+KjRJE1DAa/+YYGAZ80zhgzeCQDy6JSb4NtPKuzZ2xpSaqMcffQuFjEj4TpSgDLwOTFwwnCb+ W2947HmYM2g3iYFTKhM/P2E+zq93vAk= X-Authority-Analysis: v=2.4 cv=IfK3n2qa c=1 sm=1 tr=0 ts=6a7ca8e2 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=mm-sKQyJWPVlA1vr6AIA:9 X-Proofpoint-GUID: ai5aBwHHn1saZEX8vrhA4-sHGL04sbNe X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 impostorscore=0 bulkscore=0 clxscore=1015 lowpriorityscore=0 adultscore=0 malwarescore=0 spamscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" In the vfio_ap_mdev_cfg_add function, the apm_add, aqm_add and adm_add fields of an ap_matrix_mdev object fields are modified while not holding the matrix_dev->mdevs_lock. This lock must be held while making these to guard against a race condition with another caller that may be concurrently modifying these fields or any of the fields in the matrix_mdev->matrix. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index f2d662e388bd..21c502598f8c 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2777,12 +2777,20 @@ static void vfio_ap_mdev_cfg_add(unsigned long *apm= _add, unsigned long *aqm_add, * called. */ list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { + /* + * The mdevs_lock must be held in order to access fields + * within matrix_mdev + */ + mutex_lock(&matrix_dev->mdevs_lock); + bitmap_and(matrix_mdev->apm_add, matrix_mdev->matrix.apm, apm_add, AP_DEVICES); bitmap_and(matrix_mdev->aqm_add, matrix_mdev->matrix.aqm, aqm_add, AP_DOMAINS); bitmap_and(matrix_mdev->adm_add, matrix_mdev->matrix.adm, adm_add, AP_DEVICES); + + mutex_unlock(&matrix_dev->mdevs_lock); } } =20 --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EE96F470E85; Wed, 12 Aug 2026 17:10:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554602; cv=none; b=cuZE7bM8R+lwW6TCtVUQciyhHTJ4HPOsVNwQeTbpEV5VjBlKhfgblW05Zf4kyxryhC12lSp6glg0HjRXEALnNAcK3UR4ZovYx3/Nq27yqZL7jFxUHYi2bvn4vA1g8leXqCjkqiUpmLXDsfWFdpN7dI1E+1nMrYcJXEfO6jqjhxI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554602; c=relaxed/simple; bh=EDCwJV+IvNOFK32sSxnYNd78nS1ko9lbivW41h8Ix9g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=m+WldhPFyS+OTAOQzaI6+SGO9hUkrmIf7zoOJf7vdB/koA6XdWbbAilfo/tAeqiNuXVRI9IvCSKpc8R7d8Uz08gca1sN5bcBYvsp+DzyW/ScKrBrV5DaT8j1bVgq+1llg9JpAQHA/KFVanuIlyAnLYXTSqcVJ0F4fpdHlGMnoRs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=PH0Q5Z+e; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="PH0Q5Z+e" Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1dlD2985352; Wed, 12 Aug 2026 17:09:56 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Fp8CEaAw34Vga6mTt owRd3t8SDWSYYHYv/RZc9nbQlg=; b=PH0Q5Z+eT3BDsWXD14Ci1T6a06RQc0WL6 hOqi6Fs1yt6MIfD/AYvPhVPX01WR6geldaHGLXRvEXHvpXJYHPTZOgJYc8TfDgnS RmLmae+QP+ETyAqqIXPn47AQDek5MDXAn9csYnA+8Qtz0PkNFwTnrgJse0+VLtrE hFvvI2xde6bfK5/n8lBOl4z6CdgPlUq02E3OZnWDu6jDjWNlRnQpdXXMklgSvLrT r267FCFpuU1yHCq4H+/OIKQNSZqzad16HP6GUywJk0/XIhkkhpHSE1/JXQbtqJa4 +BzusJm5RffHXddxsr4OPODHoI86P4RLIjlqpp1Vor1AvnuUOPkmw== Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fyb23v6w3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:55 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGutOe006549; Wed, 12 Aug 2026 17:09:55 GMT Received: from smtprelay05.wdc07v.mail.ibm.com ([172.16.1.72]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxhfy6w11-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:54 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay05.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9r8x1704464 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:53 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2C88A58060; Wed, 12 Aug 2026 17:09:53 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 234D358055; Wed, 12 Aug 2026 17:09:52 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:52 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 5/9] s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove Date: Wed, 12 Aug 2026 13:09:41 -0400 Message-ID: <20260812170945.738351-6-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=XqfK/1F9 c=1 sm=1 tr=0 ts=6a7ca8e3 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=fkyveIzhjB74ZASU3MYA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfXxzaOjLs+AZBV w/gf2KhlV6QjlWZ+MDOtSiirgMBsPPj5Pn+rRG4fd1aINbkdpdEkTBGA9ri2pjstVw06OPBN1mQ orfrFkfeAo7aO5FVSszEglpHRi1TDUSZrED5m+6qFVld6S53u8Z9Z9F0EV1thIQjAeip7clkro3 SaflWJwsnSboY4UclIE8EGOzZpRltq2YYGat2V5UgdAJDMTv20h2rI1C0+DIXAt7cGArhhE9KWG r8j3xoBhlPQ4uUekuW7HxZdoCDbsLHoiuLylu9gp9cO+fFq8NquTmQ7xAr83C4ay1rCyaUmqzyw 0fEnAKa0BbFoUEOhe1uTgnFNCsOECXnDYVabUxI6oe5HlbTirjT5pDOW7RTDM3le4mP1C3EXXaG qwjPR6g0AkHX7RZJNUoJvDgQRxGkFdnGuMBK5nSl5pEt37YZcGvKe/R2nEBJ1sKcp7708fMjsIb K5Wq3UNXe+vI0c8KeJw== X-Proofpoint-ORIG-GUID: 8ko3oj4cEiOTPAe0elS9fyd1hxQVYkLm X-Proofpoint-GUID: 8ko3oj4cEiOTPAe0elS9fyd1hxQVYkLm X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX/Wml1/74qxex mZ2coOI9mzE01TlbsbOBTbgb/TLsgYrXfFKApTRgwO5bGZd3CUI7RU63OghYfMYxMvZTixRMuBN VkTtBHPLazOpPbaixMqk1yNUIUvSCT8= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 spamscore=0 adultscore=0 malwarescore=0 clxscore=1015 suspectscore=0 priorityscore=1501 impostorscore=0 phishscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" The vfio_ap_config_remove function uses the bitmap_andnot function to clear bits from the matrix_mdev->matrix.adm bitmap (specifies the control domains assigned to the mdev). This prevents the explicitly unplugged control domains from being removed the KVM guest. The bitmap_and function is used instead. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 21c502598f8c..0f3537aadea8 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2636,9 +2636,9 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *ap= _remove, do_remove |=3D bitmap_and(aqrem, aq_remove, matrix_mdev->matrix.aqm, AP_DOMAINS); - do_remove |=3D bitmap_andnot(cdrem, cd_remove, - matrix_mdev->matrix.adm, - AP_DOMAINS); + do_remove |=3D bitmap_and(cdrem, cd_remove, + matrix_mdev->matrix.adm, + AP_DOMAINS); =20 if (do_remove) vfio_ap_mdev_hot_unplug_cfg(matrix_mdev, aprem, aqrem, --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 340AE38238F; Wed, 12 Aug 2026 17:10:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554602; cv=none; b=gLzFOg0Pomf9Uu8onz8Tdq5m9BnPkxnJnf1YleRr1eYSVUX+7AgsJFDvp47tfVNAQdUp07yZKCWbT4CwMAswDP/EMvlm6TvetO/VzHT5xJti2viRCIOaqHeExWBZdH7H8nOZFETtncfdgJimTtkEZvcryKu8pPXIzkIeX9uECSQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554602; c=relaxed/simple; bh=h3HrRTfDZXmhYYsK40T/QjDbLSUMRSd2z58bV1vXTC0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=U+XDW/l7xO3AQAH28N7qzcOVgOhk/SXKBZpVtn+atFbNC4NCRHh8JutypzTomo3FLeg4oTvxKM+DkyYot+dtjbEGIOOVLt4jwsJFKpW0wMx3IFwx3Bdi7nsl2Z9eKYLa1yAw/X8myGyzdLWFUVIJ+mQET6Xq61cA+xbLYMiAHuo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=fehCFD5W; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="fehCFD5W" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1twT4120761; Wed, 12 Aug 2026 17:09:56 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=ynarWxGMXhj6Ih6Rs R1tzlw/ljsTB/gbaRfr5yDpPtE=; b=fehCFD5W/1beApczKKZ8RUF7AZIFcM8Yq 5Yq51xsH2o+r9f1hDmvFWBu4RW8TieHI9mZ3iTpgqiM9yJgNy8iWi1K5AFXAXePV FkFuS5cA5+Q9EBajUofWDG4Fcys6NSANtEjo6RWg9BG9+vNks9G+2jj4Pj0xc6f8 KQIOu9gShJy4I25JuPE4qECDsjaGH/FDfhvgjlApnmbblb1rhqa2VPGoNG2tIimO L1HqwTOF0UAnz4p02cKy1M4lMGIHhkwpzmWNunWd0lQPQOXja5vZNMTNBW5VnKVw x1Ph4NHGP4h8HNT04ohb2hdGcI8luDGGb36ZHVGlq4dIDp59NlEhw== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvnwaubb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:56 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGulkL031219; Wed, 12 Aug 2026 17:09:55 GMT Received: from smtprelay06.wdc07v.mail.ibm.com ([172.16.1.73]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxg9h71fr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:55 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay06.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9s8465405378 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:54 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 5031658043; Wed, 12 Aug 2026 17:09:54 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4706358059; Wed, 12 Aug 2026 17:09:53 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:53 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 6/9] s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap Date: Wed, 12 Aug 2026 13:09:42 -0400 Message-ID: <20260812170945.738351-7-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RsP16imK c=1 sm=1 tr=0 ts=6a7ca8e4 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=bGM9o4fjUnjFpbELYA8A:9 X-Proofpoint-GUID: 72qeSOPsRckPQxYCeCMzlZWaGdQ_-aXP X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfXz/qxE4UKmxXd 7uKBpdKMCxCu+ReNZ6gtLcV5Yr9dkW9M8se5b38JcqCO0EkYKz9o1+B3yimeJsUl+DaOCvtB4M0 P+EfwOftm0DWQK0yirHaMhq/5eOQ3szA7Do7LbH60ysufhz9TYouwcPavI6c/e8DX1tvj96T2cF NHNkWJNFvJPCseEWT+HOYdQbotAuDDIBYnF7L2s9CERqTm8ZRnTgVFb5UbCS5ooIOqyP9mhdXlY RyPFJIeKnca4RGSN5PbxKX/3bRyFjo9HeLqwHKTVqRl4ZavAkm4cDqbqpU+Geq8FsqIEGtjfZw5 D0FmAEbHFo0AgOnMlFxqVLE1A0T/Rxsz4bLptAUi9jOOSB4DLNDK7yANSFGfsh8srHikOhvr7qH bLLt6x8Ww8hdPivmOO4s15v1xjRzD9x2cr/eEfmISMHluUE6Q+cLNzUmujtZjFrzWiO8/kh4ORR ELNnrVd0iERVfU4mSQg== X-Proofpoint-ORIG-GUID: 72qeSOPsRckPQxYCeCMzlZWaGdQ_-aXP X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX0nf5iTVX8fCV ZnqWSzb4eT1rP6gTwbG3Wv/0/Ft95BElBFFHXlYG1xYm2mVIyp8jx4M8uoKr3TeZSb5r+iXUrsv jgfDEhphw0pV9FI6p8eeTYAxI8xvPOE= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 suspectscore=0 clxscore=1015 malwarescore=0 phishscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap on the stack without zero-initializing it. In vfio_ap_mdev_hot_plug_cfg(), the vfio_ap_mdev_filter_matrix() function is only called to initialize and populate apm_filtered if either filter_adapters or filter_domains is true. If the hot plug configuration change only adds control domains (meaning filter_cdoms is true, but filter_adapters and filter_domains are both false), vfio_ap_mdev_filter_matrix() is bypassed. Consequently, apm_filtered is passed to reset_queues_for_apids() with uninitialized stack garbage. This can cause reset_queues_for_apids() to interpret arbitrary stack garbage bits as valid APIDs to reset, potentially performing unintended guest hardware queue resets. Fix this by zero-initializing the apm_filtered bitmap at the beginning of vfio_ap_mdev_hot_plug_cfg() using bitmap_zero(). Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 0f3537aadea8..d667ad4bbf70 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2861,6 +2861,15 @@ static void vfio_ap_mdev_hot_plug_cfg(struct ap_matr= ix_mdev *matrix_mdev) DECLARE_BITMAP(apm_filtered, AP_DEVICES); bool filter_domains, filter_adapters, filter_cdoms, do_hotplug =3D false; =20 + /* + * Zero out the apm_filtered bitmap in case there are no adapters or + * domains to be added, but only control domains. In that case, + * vfio_ap_mdev_filter_matrix() - which initializes apm_filtered - will + * not get called and the reset_queues_for_apids will crash because it + * will access an uninitialized bitmap. + */ + bitmap_zero(apm_filtered, AP_DEVICES); + filter_adapters =3D bitmap_intersects(matrix_mdev->matrix.apm, matrix_mdev->apm_add, AP_DEVICES); filter_domains =3D bitmap_intersects(matrix_mdev->matrix.aqm, --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3CA7948383B; Wed, 12 Aug 2026 17:10:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554605; cv=none; b=tp/PGQIwW44H8bh0uKOJuvyXT88oUxPTKpAbOC3IDpvuAZ6B3n30Cc/jOJIiFU+vEB5ZDJjfpF0+PotnFUoL5FVqnla6PP1mgNz7hx9CO57LcKNRtvn5Fsn6ZYmYfA11JLUwUhBzhP5h6HG3PpEBnNv+DxE38qBeG63AidxLFeI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554605; c=relaxed/simple; bh=FoFIW/AgoTdN4VWY1MQQkFfV8yq7HHNYQduDvhZY+EE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WLmYjaK0pHU7Xrely3CquzU11niuoJIxCzgXkJ53kc17NkAViSEKsSFfWchsY4buXSEHnyQHUFWgOP4Qy+NDfNjcsyEARJBBnB2xAw24SfqOKqDJngdXMRnl/i9Twu8YNNUZf1bwwUbGoDsqc+J9eTkn4+uUXXhzRqOeNhsarjU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=GnoN2pOb; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="GnoN2pOb" Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1eWm2985366; Wed, 12 Aug 2026 17:09:58 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=VoktGW2yg8hs6u4/C QidroR6kcaQw/g4WWLmh1kAKB0=; b=GnoN2pObjI3BPJziB4AdWFs/9DwbV+X4k 1fxKUC0hJ4D8KMQRvapc75kZwxiiSZ2nW/S4blGK4mg4Hg2ypTXSAm7f8OzDw+1r liO0U++GREx8d4+M25k52EoiCrytPdwo2/0cPoviAyNKBDSx4c/iWFvsEPw3+HKR 9yF1+yDakXy9IdJiNG+QpBbb2HVnn93OtA0WYO0QNsnUFzmg9YJXFPFFICBfYe/h VsxaH8fAQdw06Pegp8HeXS+Iqq6QbrULtteg6LCaKtxmuhcULVOK1XlH31N1MOxi 5MXqzmxM7fSz7JOdUO9/JVxRphqrWp2m6maEWnKQqxuELz5PjvjCA== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fyb23v6wd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:58 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGusK7008224; Wed, 12 Aug 2026 17:09:57 GMT Received: from smtprelay07.wdc07v.mail.ibm.com ([172.16.1.74]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxh0gey8a-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:57 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay07.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9tda6161096 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:55 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7DD8A5805F; Wed, 12 Aug 2026 17:09:55 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6C58C58055; Wed, 12 Aug 2026 17:09:54 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:54 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 7/9] s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed Date: Wed, 12 Aug 2026 13:09:43 -0400 Message-ID: <20260812170945.738351-8-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=XqfK/1F9 c=1 sm=1 tr=0 ts=6a7ca8e6 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=l_t73i4lE__BKQLLFKsA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX9eYb1P1FU4Pa gNaxUscGd0kTeB4jThqpQzCGXzLfxLxIF1oEOVtiyWyuUgzOGsNlah5PBp54ITkCJE8Ri39OuqB 4TuVeAQGopc8MLaPhDqMbpCBtyTvoAn6xevGp2mHfh9r+Xj/i+BQOG/HdrtxR90h3QDGvmYfdn9 2AUwcMnU6d+ss8WuRC4SlDXn+bfX5Wh8zclXWAAgpcgrlFl7SZwvrGuygB97eTvHWetTFTQDrr3 P9/tDzbUCgK9pcpfJNR8Ndc/RmZstr2iIayW7ee4AhRQFdyU5Q89R4bw3PgXtMkDgPETr+4B9LS CzksfwlKLd8V0vVmUQ+E8rmHcJfRhHxNgTUedGrxcAEKpdgcFpK3l5wMQr9Tjn9khigIJO4ItmF cC330RYF7lpN5LyjUw5XvwIkxs94FQBdNmIGbJVWmrLDs+mdS2Czj8GndDVPDBs4Zfck5sk4D8q 2WHiX9EQFJ1SThLhUtg== X-Proofpoint-ORIG-GUID: K_2ln_OdTnitBM8cpTslUGHA2ZuGAs_L X-Proofpoint-GUID: K_2ln_OdTnitBM8cpTslUGHA2ZuGAs_L X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfXxv0aZH30qNzq lc/XqCxyeqLzgUMPbDEhh1o/M3KFDYHgh1F5bV4TCStUxw3iZOcsW9HYZsBDT2823Xgk3mdAWxH 7Iwdwvmpu7qlKG2AY8EDqmJk9iPXDsA= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 spamscore=0 adultscore=0 malwarescore=0 clxscore=1015 suspectscore=0 priorityscore=1501 impostorscore=0 phishscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" The vfio_ap_mdev_hot_unplug_cfg() function uses the return value of bitmap_andnot() to determine whether the guest APCB needs to be updated. However, bitmap_andnot() returns false when the resulting destination bitmap is empty. This means that if the only adapter, domain or control domain assigned to an mdev is removed from the host's AP configuration, the bit is correctly cleared from the shadow APCB, but bitmap_andnot() returns false because the result is an empty bitmap. Consequently, do_hotplug remains 0 and vfio_ap_mdev_update_guest_apcb() is never called, leaving the KVM guest with stale hardware access to the unplugged AP devices. Fix this by replacing the bitmap_andnot() return value check with bitmap_intersects() to determine whether the shadow APCB actually overlaps with the removal mask. If there is an intersection, call bitmap_andnot() solely for its side effect of clearing the bits, then unconditionally set do_hotplug to trigger the guest APCB update. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 30 +++++++++++++++++------------- 1 file changed, 17 insertions(+), 13 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index d667ad4bbf70..16779cfc64e8 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2568,24 +2568,28 @@ static void vfio_ap_mdev_hot_unplug_cfg(struct ap_m= atrix_mdev *matrix_mdev, unsigned long *aqrem, unsigned long *cdrem) { - int do_hotplug =3D 0; + bool do_hotplug =3D false; =20 - if (!bitmap_empty(aprem, AP_DEVICES)) { - do_hotplug |=3D bitmap_andnot(matrix_mdev->shadow_apcb.apm, - matrix_mdev->shadow_apcb.apm, - aprem, AP_DEVICES); + if (bitmap_intersects(matrix_mdev->shadow_apcb.apm, aprem, AP_DEVICES)) { + bitmap_andnot(matrix_mdev->shadow_apcb.apm, + matrix_mdev->shadow_apcb.apm, + aprem, AP_DEVICES); + do_hotplug =3D true; } =20 - if (!bitmap_empty(aqrem, AP_DOMAINS)) { - do_hotplug |=3D bitmap_andnot(matrix_mdev->shadow_apcb.aqm, - matrix_mdev->shadow_apcb.aqm, - aqrem, AP_DEVICES); + if (bitmap_intersects(matrix_mdev->shadow_apcb.aqm, aqrem, AP_DOMAINS)) { + bitmap_andnot(matrix_mdev->shadow_apcb.aqm, + matrix_mdev->shadow_apcb.aqm, + aqrem, AP_DOMAINS); + do_hotplug =3D true; } =20 - if (!bitmap_empty(cdrem, AP_DOMAINS)) - do_hotplug |=3D bitmap_andnot(matrix_mdev->shadow_apcb.adm, - matrix_mdev->shadow_apcb.adm, - cdrem, AP_DOMAINS); + if (bitmap_intersects(matrix_mdev->shadow_apcb.adm, cdrem, AP_DOMAINS)) { + bitmap_andnot(matrix_mdev->shadow_apcb.adm, + matrix_mdev->shadow_apcb.adm, + cdrem, AP_DOMAINS); + do_hotplug =3D true; + } =20 if (do_hotplug) vfio_ap_mdev_update_guest_apcb(matrix_mdev); --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C042747D92D; Wed, 12 Aug 2026 17:10:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554606; cv=none; b=ug3phUigAUMTxF4HKNLlxJszEVA/CCyhwdeU8n7zFJ6nzFmxE1v0kpcfNAxrHhCdokJS80kZuiQ/Xz5n27n2HYvK9SPe7SruhVcRVghKM5lzn9FW1xRdQcy39Q7vBwqRp45JpAjM0Pno5FTGcduEHs4Jk33t3xXIaWXVpdaGsy0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554606; c=relaxed/simple; bh=7wEowosgqwNvBL9wNSauNwMUJLDB5cmOWLnbKw8E5Lc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lB+3qKbJJpolYJoq+F1Lfpq+wO72G5fXnpBh2PTdMZ1YxpvH65ZHlsKZUhiMVXlFoX3uD5NFBlXbtkRhmO9hN6i0JWGouANl7PsicDYgNORfH4G+aEuZqp+imUuVCqsVReSho0A2XLk7sHrIHhzwXjV2ZSDFqdQFB+ZV8bKN06E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=TG7DB6CS; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="TG7DB6CS" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1kXf4120545; Wed, 12 Aug 2026 17:09:58 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=4MTGCi lI8wGZcDEwCy4aLN6LL7cLxtttuhMymzxIX/g=; b=TG7DB6CS2r5/KryL5l8b8w xJbnM+8U2J1R3CCbsP+jDDVqplkcqupQe0JsOi0mEHWt/UUD8+IeJBXFp+2/H9TV dcgz6jkihDSdB7OXij95aarZjCgbuQDDg2F/9RvjUOb/vXSz/IIYOpFk0YB6s5J3 Syxdwd9a0fBm/WdcIZhbinaLSthJYm/cvsxkTiHC7iuASuwmXCfvv/P/gi9j14Th jnKCcYdItN7Kt0JnS2/vNLg6n9Piq+DrzmEQQzWkOgkpnsQAQNV23bi03YA0tKa4 WK12WN7NEMiZhkuFcHAkBAnHyP8lZuA3uFpslvkvrZ/mRCn+OjgR+CPPgV7DHxZA == Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvnwaubj-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:58 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGulQu031223; Wed, 12 Aug 2026 17:09:58 GMT Received: from smtprelay04.dal12v.mail.ibm.com ([172.16.1.6]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxg9h71g2-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:57 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay04.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9uj923003818 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:56 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A5E4F5805D; Wed, 12 Aug 2026 17:09:56 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 98CFB5805E; Wed, 12 Aug 2026 17:09:55 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:55 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 8/9] s390/vfio-ap: Fix NULL deref in status_show() during queue probe Date: Wed, 12 Aug 2026 13:09:44 -0400 Message-ID: <20260812170945.738351-9-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RsP16imK c=1 sm=1 tr=0 ts=6a7ca8e6 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=6WrCTVO_FsqHOomzZFMA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-GUID: K7iGlC2GYiPsQDmEdEOuthVcXZVgM2BT X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX02q7y0UgZvNs Vn+EOL/0GQvbNDRaNDW2gf313ahGjjZbJW68TvPFkzyTJs5VrBWfwWRSf/10/oB/YrU3AHgvyP9 cL+c2CGZXYS30FICsgyDJe123fyReWSsrOYO5+pBK/gU9B8yq+e5TkroaZ8mT2mPsRer9rI+MZT qBPvqgZq8zQb8xjuXVUXh8tRB/u0s5gOVvu9Gs2/SSQw4AklTYP+PxkogC6p3bPSGGuopOGYCZ4 p6jv3FedJNfRJvy0wROwcZxVAI5q6b6b11Kt59H7U+Xlvfd9VJKErf7OsjdI5hdM5bAZUGoT+rv 2Pc/VokIFE1DJwS8/IXxcVPfTglYB24tworiipzvrJ3yKIRYSF8a30S6EOqPaJd/DTDBH6X5LXx l8+38cKwY4QwCN8iBwp7Rnmp3uzEbp5QfVARdjIywnArdRmzGbVMQlGrPFf6x3AXx8alV4/oC7C 96ugf471ds0qsAuh2Ow== X-Proofpoint-ORIG-GUID: K7iGlC2GYiPsQDmEdEOuthVcXZVgM2BT X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX0zaFcGmB3NeR lhgsGFTs/b26V2Ip480vwViKQT+46YmEyzyDDmqec+GiGb3Ds4f5G/bcsvWhEQ8Gq8/qn3McZkm +Fwc76Drba/sg/lb1jhVKEv5PLO6Zec= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 suspectscore=0 clxscore=1015 malwarescore=0 phishscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released. As a bonus, the APQN no longer needs to be read from the queue struct after allocation =E2=80=94 it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds. Fixes: 260f3ea141382 ("s390/vfio-ap: move probe and remove callbacks to vfi= o_ap_ops.c") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak --- drivers/s390/crypto/vfio_ap_ops.c | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 16779cfc64e8..b0454a296c67 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2424,14 +2424,17 @@ void vfio_ap_mdev_unregister(void) =20 int vfio_ap_mdev_probe_queue(struct ap_device *apdev) { - int ret; + int ret, apqn; struct vfio_ap_queue *q; DECLARE_BITMAP(apm_filtered, AP_DEVICES); struct ap_matrix_mdev *matrix_mdev; =20 + apqn =3D to_ap_queue(&apdev->device)->qid; + matrix_mdev =3D get_update_locks_by_apqn(apqn); + ret =3D sysfs_create_group(&apdev->device.kobj, &vfio_queue_attr_group); if (ret) - return ret; + goto err_release_locks; =20 q =3D kzalloc_obj(*q); if (!q) { @@ -2439,11 +2442,10 @@ int vfio_ap_mdev_probe_queue(struct ap_device *apde= v) goto err_remove_group; } =20 - q->apqn =3D to_ap_queue(&apdev->device)->qid; + q->apqn =3D apqn; q->saved_isc =3D VFIO_AP_ISC_INVALID; memset(&q->reset_status, 0, sizeof(q->reset_status)); INIT_WORK(&q->reset_work, apq_reset_check); - matrix_mdev =3D get_update_locks_by_apqn(q->apqn); =20 if (matrix_mdev) { vfio_ap_mdev_link_queue(matrix_mdev, q); @@ -2472,8 +2474,13 @@ int vfio_ap_mdev_probe_queue(struct ap_device *apdev) return ret; =20 err_remove_group: + release_update_locks_for_mdev(matrix_mdev); sysfs_remove_group(&apdev->device.kobj, &vfio_queue_attr_group); return ret; + +err_release_locks: + release_update_locks_for_mdev(matrix_mdev); + return ret; } =20 void vfio_ap_mdev_remove_queue(struct ap_device *apdev) --=20 2.53.0 From nobody Tue Sep 29 04:09:43 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 54A2F4854E1; Wed, 12 Aug 2026 17:10:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554608; cv=none; b=IXl+mwllR/ZNzkU7ZycphtFTwb9W5lx2T4gIv3eNPjthZerWH3JpR2Eq7WVIglDVl5cABhIuqgAwivLk/gHeqNCmQ+H/x5E3Z+adfXG3Xj1WSbtxLsemGJtnPRIY4XBiaEg1Qor80EX0GcpDJdIDJdvoFKXcTuGj8iV1v4EeDrY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786554608; c=relaxed/simple; bh=LvcESi7r4phfMktiGhYDeMseRSCC8mk9Ng5I7F8w3PU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=p1H+aNBXTrEo5YawyK2fUro4c9iHwxlZzeugMbiksxV/QRdBuff8/DGOBMpHcHYbdoKyADl5kSyvmSrudZWDQ2PVJtrs4PUdC13QvLG6HdyG+YwtzwlxbEzHRjv4W78yAj2/OQ+F1HkuNH8PoEpUw2FUtMo5AETSvRZvvx0b2mE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=QaH8XDSE; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="QaH8XDSE" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CH1hws4088626; Wed, 12 Aug 2026 17:10:00 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=sazpVixfHdXirHhEV VGeSXrc+jqW3qBXKYpISBO9BHM=; b=QaH8XDSENVrjCBILKxWvVCXbfnLdi6LKn pwllABaSkupiogpoS42XB6dAwr6vkTeOLl6RBssAj5tUbSRnxFByybdT5PvtRAgi +ua8G+LgJj3NNZ2zTVhD2fHUe801RFnDRveym8SwNRSF9sPljDdS15UDdisMz0RT iavg8wp7NB1yelwa2PoT92ffwTNR8vLGnww1ketZXsPInylOCHuflcTMReFwDk66 /2jDP3A0BEp8GTZtgQAUcqCnPQY9NV0Xo1qaFVSxsKNHrL6N2HFJqNu/Ss3YaGMf aEPNerbo0Ad+jHFKbCKDH4+rZj/WKvFkQbb4V0KAODIkqnH6XAoPg== Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvm9uqu7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:10:00 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CGulhr009531; Wed, 12 Aug 2026 17:09:59 GMT Received: from smtprelay05.dal12v.mail.ibm.com ([172.16.1.7]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxfsjy3k4-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 17:09:59 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (smtpav06.dal12v.mail.ibm.com [10.241.53.105]) by smtprelay05.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CH9vtv25035312 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 17:09:58 GMT Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D09A25805D; Wed, 12 Aug 2026 17:09:57 +0000 (GMT) Received: from smtpav06.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C336E58043; Wed, 12 Aug 2026 17:09:56 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav06.dal12v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 17:09:56 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v4 9/9] s390/vfio-ap: Fix memory leak when queue removed from host AP config Date: Wed, 12 Aug 2026 13:09:45 -0400 Message-ID: <20260812170945.738351-10-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812170945.738351-1-akrowiak@linux.ibm.com> References: <20260812170945.738351-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX9FeJsAV30krf niOadG5VXbNgm1usQC/zpu2A2c/YMCy09GyHiM2myA3nKk8YKpaBXX+HgKFsKZmBa6szMzWJnx/ ++5KdO+jBczk+5nPZulGBvTlyvZuuLIAwQeiafKVNuLj5/WV95ueQElJ/UBe8sTios2PXTaS6g+ fV6PBNNnQIvFJlisEaZT24yIF8sPWEMH6XD3cst5uCDL+GKxWr0lKjgQRWAmsmNJwR/TLEbuNF8 oGkV/VnxI7RfGF3fq++tFsUAD+AJDWjD7fpXkc0oY35ybMQlvGYqR8zi4qt6N5/UMAOAs4S9U0r 0OraKmZVOZ2gTucdnMg9ReC2KWQavdmW/3bvbD7ROkwMyghP4Pp0z7yHOofi4wbHG8P+OqWTCEX p3AbaxgAET7imuK20kb7tyPhfqBI+/YbsGO++boAsUks7JFxK5lNv1BIwMdpE3GndF+bdn9CD/t LO8Fr9f+aCAPv79b/Aw== X-Proofpoint-ORIG-GUID: 4emw-hh6isvJIsIpsjEBDMcTLd_8ls_p X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDEzOCBTYWx0ZWRfX/FI385+EEL3f IeTe+rD8SZhNXfkpSYxWua75Xs+zryJxAoOLmzuoV0muqQzdd2DaBmo+8LEtgVL/YSfPbCT/pGi iamm4RXMQYqTMSO0DOIUXQgTcDcRUfo= X-Authority-Analysis: v=2.4 cv=IfK3n2qa c=1 sm=1 tr=0 ts=6a7ca8e8 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=VrB3zfVs-A4ss5GmTxoA:9 X-Proofpoint-GUID: 4emw-hh6isvJIsIpsjEBDMcTLd_8ls_p X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 impostorscore=0 bulkscore=0 clxscore=1015 lowpriorityscore=0 adultscore=0 malwarescore=0 spamscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120138 Content-Type: text/plain; charset="utf-8" When an adapter or domain is removed from the host's AP configuration, the AP bus invokes vfio_ap_on_cfg_changed() to notify the vfio_ap device driver. For each ap_matrix_mdev object to which the adapter or domain is assigned, vfio_ap_mdev_hot_unplug_cfg() is called and removes the adapter or domain from the matrix_mdev->shadow_apcb (i.e., the guest's AP configuration) and hot unplugs it if a guest is using it. The new host AP configuration (sans adapter or domain) is then stored in matrix_dev->info. When the AP bus subsequently unbinds the physical queue devices associated with the adapter or domain that has been removed, it invokes vfio_ap_mdev_remove_queue() for each queue removed. At this point, the adapter or domain will no longer be assigned to the matrix_mdev->shadow_apcb or the matrix_dev->info object because they would have been removed by vfio_ap_on_cfg_changed(). Consequently, vfio_ap_mdev_reset_queue(q) is bypassed and kfree(q) is called without executing vfio_ap_free_aqic_resources(). This indefinitely pins guest memory (q->saved_iova) and leaks KVM GISC resources (q->saved_isc). Note that resetting the queue would fail with an invalid APQN error due to the fact the queue is not longer in the host's AP configuration; however, it is still necessary to free the AQIC resources. The fix here is to call vfio_ap_free_aqic_resources if the adapter or domain is neither in matrix_mdev->shadow_apcb or matrix_dev->info. Fixes: b9bd10c43456d ("s390/vfio-ap: do not reset queue removed from host c= onfig") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index b0454a296c67..a8de98d5e71e 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2515,12 +2515,15 @@ void vfio_ap_mdev_remove_queue(struct ap_device *ap= dev) /* * If the queue is not in the host's AP configuration, then resetting * it will fail with response code 01, (APQN not valid); so, let's make - * sure it is in the host's config. + * sure it is in the host's config. If it is not, then free the KVM GISC + * resources. */ if (test_bit_inv(apid, (unsigned long *)matrix_dev->info.apm) && test_bit_inv(apqi, (unsigned long *)matrix_dev->info.aqm)) { vfio_ap_mdev_reset_queue(q); flush_work(&q->reset_work); + } else { + vfio_ap_free_aqic_resources(q); } =20 done: --=20 2.53.0