From nobody Tue Sep 29 04:09:44 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00FD03793B3; Wed, 12 Aug 2026 20:02:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564977; cv=none; b=KuxZk0QORVtOy5lRFKgICvbCoOsV4NsGotDrP5mRwbXHTYMLZ9f5QrtYMds9qJyQk1+oigqkonUuklOHLX/frad59H/IE2e2tyC/GjWdS8j9TerFNCZ5RYWlzHiHGXXazAl+IIzyVoyjBy1/YEQX3AK4HPDOCbZAXKZwTp1kgec= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564977; c=relaxed/simple; bh=hAk5VFZTgMbDNPLe+AA+zMf0YOhx4PJoLsGEtIiKUxc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=P2zObodfdrz/R+wVRbbnAnGg5vOkbPqVoqaucv1MeesaiWcxq6/qE5KRp+giec3V7u1eqQr2sh8OtdRdScg6ryhY3bkhz5mPxm8E1wggZcEIlJyyKKCpVroeX4KhdU0ghrG283keW+RzUKaDxyQtCzMm7WliJ2LIfyADyVGcJi0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=HW/fE1EZ; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="HW/fE1EZ" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2mdE196976; Wed, 12 Aug 2026 20:02:48 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=+1ReYvhFvHs/C9ZAt kBPmRv/N1oXc4R/xDf8I9N/tjo=; b=HW/fE1EZbnS0QK3JVGwUfzxaVwnYpqtpW 9oCdFQtCTjpRA8no0N0ty1ffg9/XATqoqEMN1pxT3CEe9gIwp7kubQttNbF80Hgs w+VlseTjD9GFttRoSWUUubcqEVFlmNJOev/1Prkwsi/9JAwNlnPTt8DAvYTaSbxS o0MYsC5TiCStQi0wnJP9Z6X+Y/N+i2YQyrnKobgnzjLZ5QBITFp5sxVOCf6x3405 DAbAgUX40qq7xLutcknVPAWdgv+cGcSH+Kxf8B8YIXgXJhrqp8r0DLXta9yzq2eN lZUQMbLYPV3aZ8VTUpsw2yF5rMMte2JKntwFhdWTWeXmQxTanHVLw== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvp33kga-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:48 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuJF3029536; Wed, 12 Aug 2026 20:02:46 GMT Received: from smtprelay06.dal12v.mail.ibm.com ([172.16.1.8]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxg9h7r3n-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:46 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay06.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2ioF23986724 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:45 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BFA9C58045; Wed, 12 Aug 2026 20:02:44 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1AE8958052; Wed, 12 Aug 2026 20:02:43 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:42 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 1/9] s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove Date: Wed, 12 Aug 2026 16:02:32 -0400 Message-ID: <20260812200240.818004-2-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=AMtp2X5w c=1 sm=1 tr=0 ts=6a7cd168 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=dlTjfeu_wqJGreSUTgMA:9 X-Proofpoint-GUID: mLcM70LTmGXiMsyNF6rt1AQUTj3QJ_HF X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfXyUpsr5whaLPB W7MLN8JOr9lPcVL06NC5hAkvRTaJSj6moBTm9OWN9jQc18trnMgw9kZnGN80vrfew1pcMvdkjBK kNARC2fRQtRgwVv+HDK3ME/v/SknEQ8s6R2Sr1CItmymT85ZX5L1QeXjOxylsv0z0yNtDHhNgkx T9zmQh7xmSWmHSLLm8FY4eIM8IGyC3ugpG27+L2ggd5TAvKB6JARG2GWvr/dJlHs0pY3VkyK2Sf 0MXqy7MWYDb00lGFAdjbyP34rLu6D8vsqZ221zxxUv7xvf+553xjkPpl054lCbSQNDtdON/tqCG gDSUBid5eBC438SUGEVggpvcsERiaHmKwzi+EhkPY9yY9/2XV9qcuaki+R8cu9DsxykV7h8KxPl F9/7Mi39V6ikp37LVax305UVRUUcgldzAgLnmK4TporMvDCweBBw3u1LI+X+scoClnWaPjudXof BiRw9NVjsZmmU08Yp1g== X-Proofpoint-ORIG-GUID: mLcM70LTmGXiMsyNF6rt1AQUTj3QJ_HF X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX/2GDlNa7lT1M 3vkWPA/kdLzarsD5kLZzmJgyid1ESGZPReB+3hvyLB9tgH+NIU6M7E4Qs0Ddkj6nij+WSfeVxon OnuX9JhFpYz9vDXZrZroIwTA2ziQ4A0= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 adultscore=0 lowpriorityscore=0 clxscore=1015 priorityscore=1501 impostorscore=0 phishscore=0 spamscore=0 bulkscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" The do_remove flag in vfio_ap_mdev_cfg_remove() is initialised to zero before the loop that iterates over the list of matrix mdevs, but is never reset at the start of each iteration. Since do_remove is OR-accumulated across iterations, a positive result from one mdev carries over to subsequent mdevs. The fix is to set the do_remove flag with the first call to bitmap_and; for example: do_remove =3D bitmap_an rather than do_remove |=3D bitmap_and. Fixes: eeb386aeb5b7 ("s390/vfio-ap: handle config changed and scan complete= notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 44b3a1dcc1b3..845c86ba8bc3 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2603,15 +2603,15 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *= ap_remove, DECLARE_BITMAP(aprem, AP_DEVICES); DECLARE_BITMAP(aqrem, AP_DOMAINS); DECLARE_BITMAP(cdrem, AP_DOMAINS); - int do_remove =3D 0; + int do_remove; =20 list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { mutex_lock(&matrix_mdev->kvm->lock); mutex_lock(&matrix_dev->mdevs_lock); =20 - do_remove |=3D bitmap_and(aprem, ap_remove, - matrix_mdev->matrix.apm, - AP_DEVICES); + do_remove =3D bitmap_and(aprem, ap_remove, + matrix_mdev->matrix.apm, + AP_DEVICES); do_remove |=3D bitmap_and(aqrem, aq_remove, matrix_mdev->matrix.aqm, AP_DOMAINS); --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D727364EBF; Wed, 12 Aug 2026 20:02:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564987; cv=none; b=f98nVbrI2Kxoqaacki1SBleuYb0wiM7cbf/dIpWy7uwn5wGW4naStvnFb2VvkisLmLlN2y7HY47qa1zxKrWkekSltXw1sske7fC5RV9JGdf4fSQRC2ra/dI2l9O/wymmm8ZC9gT0aED8KjS29TG7ZSAK7bWl2I+6zHbforiJG9c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564987; c=relaxed/simple; bh=unPH0ftrwS/7HITiOcWhYpqJf1M5a1XSPmtX60f2Fe8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=c2+3TEurXI7zjdiD4sHm/xf/WbhbA9SgVF09xe9JKg4W8O7jtcquRfKtsOsRgKbwR2qsYiBPmRXULUSNxnmxVhv1C3xcV2fswU13Uu/m9orxkMDDGSc/RalKcyMAYidCcIFl7//ZPZZOjI0mtr2JPtQz1xJ1ooOhHwDiIEBf1Us= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=ojuQ/nmw; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="ojuQ/nmw" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2eZe291763; Wed, 12 Aug 2026 20:02:49 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=xd4tuIPEUtcZR3kxf Vor1dQGByJCCqoSk+q/LP6t7V0=; b=ojuQ/nmwhF2xUFbMT26BvAW+naImmjlnX 0ECBLiXPDNNHikqgnhPQWQFOWLU9hzEA+PAeOxvXSJCYQOUnKdFNj0wrSY9AMlia gsZZfZHfwwX9h8siiXHv/9/fUGJSUWT/01gtTOaQz5uAsq26ayEKZBhOUzzkkB6z ElTNOj+zazsBUdaquY4TSt9kcs2n4vdkj2NuAMr5G/hnSF8rAlMLBIXTOJYBk00Y 1T4Hcuqqi4qwe6rXcZfSZwG9IR7hUt2vaPaLHWJhzGY1GTWOnG1PBbMXTvfljw4S ieH0Wi+WBMKSmWDAGJE43nyQmqLiylg7bwU46Na/LrQ9nuHNpK7bA== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvm9vh4b-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:49 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuF0Y030839; Wed, 12 Aug 2026 20:02:48 GMT Received: from smtprelay01.wdc07v.mail.ibm.com ([172.16.1.68]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxesq7y4j-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:48 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay01.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2kmf51577174 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:46 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8D2C058050; Wed, 12 Aug 2026 20:02:46 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E8A8F58056; Wed, 12 Aug 2026 20:02:44 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:44 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 2/9] s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL Date: Wed, 12 Aug 2026 16:02:33 -0400 Message-ID: <20260812200240.818004-3-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfXxGN1ul0wIKLc hRc3W30gzgcod1eWeu6jBp3FrWJz4/jAMI9mRAYtiOo3eNNyos/hVtpCKx4VFXVUdNyAalPObOr fu7V6N/S6YLIMkaTB626A1DH7VcsWtigS+p5/e7msVqBY53EiCuGNSNCh68KB+MLyqhtmCFQvoF xQny/+SwcW0SCCiPRdYYvDCzTSCeXC5WmcUl0vxYVgncSVERJRWk1zD6Z+Wn0PhzHnVtHbYtHhG U/jmPkFuvuI0IsDSNiEtMSutxCYmTi+6fPXK794f2SYq+cje16rxTHeEl+B5zdrC081SLzqtIse 4YhzE1otTlSZ2ab7tIGUmTPjp8YTs9ZcYz8Dsmf03t1Az0rsxO6u0OS40RXzSrDIwNg369R4dII UK6uf8LnAhlLkLSs3lQ2xr+C4/rVvV5p1OIU0/kj5Y4WlFI4zjQznQ/KsCWBLF3eOrN1D+IhyBr 3r0Bk8yPx+TrdFctHNA== X-Proofpoint-ORIG-GUID: e3Jo--IVfD4c9n9aCAXi4R998WMRvohV X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX5iyGiyEeOSra WsG+iwOscLzSBvWXZoRgm+x3c4fjYDT9Nh2E/xp04ZuBOBNFOc2nKtEEWQDxCLiyZVvsxXgaSAj vA67AD/I6ubrvY3h7v2Ij/9f4PgJjxs= X-Authority-Analysis: v=2.4 cv=IfK3n2qa c=1 sm=1 tr=0 ts=6a7cd169 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=7-PX2TBNVYp1iSTFOFgA:9 X-Proofpoint-GUID: e3Jo--IVfD4c9n9aCAXi4R998WMRvohV X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 impostorscore=0 bulkscore=0 clxscore=1015 lowpriorityscore=0 adultscore=0 malwarescore=0 spamscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" The ap_driver structure has two fields which are function pointers to callbacks: * .on_config_changed: called at the start of the AP bus scan function to notify the device driver that the host AP configuration has changed and the associated AP devices will be added or removed accordingly. This gives the implementor a chance to evaluate the configuration changes and respond to them before the associated devices are added or removed. * .on_scan_complete: Called at the end of the AP bus scan function to notify the device driver that the host AP configuration has changed and the AP devices have been added or removed accordingly. This gives the implementor the opportunity to respond to the changes after the associated devices are added or removed. These two callbacks are implemented in the vfio_ap device driver via the vfio_ap_on_cfg_changed and vfio_ap_on_scan_complete functions respectively. Within the call stack of these two callback functions the matrix_mdev->kvm->lock mutex is taken without checking whether matrix_mdev->kvm is NULL or not. If matrix_mdev->kvm has never been set, trying to take the lock will trigger a NULL pointer dereference. This patch adds checks for matrix_mdev->kvm =3D=3D NULL before taking the matrix_mdev->kvm->lock mutex. Note that the matrix_mdev->kvm->lock mutex taken in the vfio_ap_mdev_hot_plug_config function is moved to the calling function along with the matrix_dev->mdevs_lock which is needed there to access the fields of the matrix_mdev. It makes little sense to make the change the check for matrix_mdev->kvm there before taking the kvm->lock mutex only to have to move it out via another patch, so it is done in this patch. It is important to make note of the following: 1. The matrix_dev->guests_lock is acquired at the start of both callback functions. This ensures that matrix_mdev will not be removed via the vfio_ap_mdev_remove function because it too takes matrix_dev_guests_lock before removing the object; so, matrix_mdev will be available for the duration of the callback functions. 2. The matrix_dev->mdevs_lock mutex must be taken in order to access fields within the matrix_mdev structure 3. matrix_mdev->kvm->lock mutex must be taken before the matrix_dev->mdevs_lock to prevent a lockdep splat. 4: The kvm->lock must be held while plugging the guest's AP configuration into its SIE state description via the vfio_ap_mdev_update_guest_apcb function. 5. The vfio_ap_mdev_update_guest_apcb checks matrix_mdev->kvm to verify it is not NULL before doing the hot plug of the guest's AP configuration. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 39 ++++++++++++++++++++++++------- 1 file changed, 30 insertions(+), 9 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 845c86ba8bc3..c6bee69cc22f 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2605,8 +2605,20 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *a= p_remove, DECLARE_BITMAP(cdrem, AP_DOMAINS); int do_remove; =20 + /* + * It is safe to traverse this list here because the + * required guard - matrix_dev->guests_lock - is taken in the + * vfio_ap_on_cfg_changed function prior to this function getting + * called. + */ list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { - mutex_lock(&matrix_mdev->kvm->lock); + /* + * The mdevs_lock must be held to access fields within matrix_mdev, + * and kvm->lock must be taken before mdevs_lock to satisfy the lock + * ordering requirement and prevent a lockdep splat. + */ + if (matrix_mdev->kvm) + mutex_lock(&matrix_mdev->kvm->lock); mutex_lock(&matrix_dev->mdevs_lock); =20 do_remove =3D bitmap_and(aprem, ap_remove, @@ -2624,7 +2636,8 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *ap= _remove, cdrem); =20 mutex_unlock(&matrix_dev->mdevs_lock); - mutex_unlock(&matrix_mdev->kvm->lock); + if (matrix_mdev->kvm) + mutex_unlock(&matrix_mdev->kvm->lock); } } =20 @@ -2821,9 +2834,6 @@ static void vfio_ap_mdev_hot_plug_cfg(struct ap_matri= x_mdev *matrix_mdev) DECLARE_BITMAP(apm_filtered, AP_DEVICES); bool filter_domains, filter_adapters, filter_cdoms, do_hotplug =3D false; =20 - mutex_lock(&matrix_mdev->kvm->lock); - mutex_lock(&matrix_dev->mdevs_lock); - filter_adapters =3D bitmap_intersects(matrix_mdev->matrix.apm, matrix_mdev->apm_add, AP_DEVICES); filter_domains =3D bitmap_intersects(matrix_mdev->matrix.aqm, @@ -2841,9 +2851,6 @@ static void vfio_ap_mdev_hot_plug_cfg(struct ap_matri= x_mdev *matrix_mdev) vfio_ap_mdev_update_guest_apcb(matrix_mdev); =20 reset_queues_for_apids(matrix_mdev, apm_filtered); - - mutex_unlock(&matrix_dev->mdevs_lock); - mutex_unlock(&matrix_mdev->kvm->lock); } =20 void vfio_ap_on_scan_complete(struct ap_config_info *new_config_info, @@ -2854,15 +2861,29 @@ void vfio_ap_on_scan_complete(struct ap_config_info= *new_config_info, mutex_lock(&matrix_dev->guests_lock); =20 list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { + /* + * The mdevs_lock must be held to access fields within matrix_mdev, + * and kvm->lock must be taken before mdevs_lock to satisfy the lock + * ordering requirement and prevent a lockdep splat. + */ + if (matrix_mdev->kvm) + mutex_lock(&matrix_mdev->kvm->lock); + mutex_lock(&matrix_dev->mdevs_lock); + if (bitmap_empty(matrix_mdev->apm_add, AP_DEVICES) && bitmap_empty(matrix_mdev->aqm_add, AP_DOMAINS) && bitmap_empty(matrix_mdev->adm_add, AP_DOMAINS)) - continue; + goto do_unlock; =20 vfio_ap_mdev_hot_plug_cfg(matrix_mdev); bitmap_clear(matrix_mdev->apm_add, 0, AP_DEVICES); bitmap_clear(matrix_mdev->aqm_add, 0, AP_DOMAINS); bitmap_clear(matrix_mdev->adm_add, 0, AP_DOMAINS); + +do_unlock: + mutex_unlock(&matrix_dev->mdevs_lock); + if (matrix_mdev->kvm) + mutex_unlock(&matrix_mdev->kvm->lock); } =20 mutex_unlock(&matrix_dev->guests_lock); --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B31BB37EFFB; Wed, 12 Aug 2026 20:02:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564979; cv=none; b=u7H5lv8HTTppqbQvCxNaOEQNzwRIKkOyaGrwd1iJMDL+kZkKcq5J/vdHvwMikMlJBaElsD7kTJhVm9jFKizXOjlH+pz31Vt0cr8LWaQdURuqXglPt7rkri7AtHk0yB8B2LSivTEXT1ZQmHnbHligY5LToxFjqfHsG6AhedRCmeo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564979; c=relaxed/simple; bh=fW5pD8sDwhcCDXWf8ZIJJ55PI3tKhL6NSCRDBnsVJy8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Piv+Dnv5DSVkX9YSLVmtP5CsMWabPLfUDFzP8b3+REksWd3p3d3u2k34voQt9FexQWdEJEJvkGdwTNCKI0Nca0CpHsy+gxagoTQUlZ2lXqQqZLlGNgFm6ASHdkvicMwwO7BBci95YHm+VudNNP2PVdHNrMfOPjJu7OUef0fZeYI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=Sr7j0rij; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="Sr7j0rij" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2n4O242690; Wed, 12 Aug 2026 20:02:51 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=9zSYwEpZLHwXh7QUa MzdW+WRNO+WXyysEw6YZbqHS/w=; b=Sr7j0rijk7sSCf2vX38ioD10BnTisGNgs C8UFiZO7ekWIXhREsWDvz1XBnKM43Nx5lGOY/bUJZlqOhf3avTvN3s9i9zYxexcD 5+3mJO12VR4ALTDHBhVxa545jyaaI579yOnT3jN6Odsos+h25MLS/+uQSt+pym8J kdzIRSORTPFM3ly7ebRQv+LeycCRp/JYbPW3+UZl7km7Sn25J+avXJVfg5sKEaFp tVeHE1Rz1UfEuFPvMw9UNd78Q8rjgbTj89O7H8OUDidCoA/Q3gCXWXlnxR4rFuas CRQlqkKvsHvPoqZL/VScSjOxDRKPn57SCwdXn/Uc8/w+6U7aCiiMw== Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvq9meh5-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:50 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuXJX005189; Wed, 12 Aug 2026 20:02:49 GMT Received: from smtprelay03.wdc07v.mail.ibm.com ([172.16.1.70]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxhfy7krk-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:49 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay03.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2AhM11600638 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:10 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4F39658050; Wed, 12 Aug 2026 20:02:48 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B4F0658045; Wed, 12 Aug 2026 20:02:46 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:46 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 3/9] s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects Date: Wed, 12 Aug 2026 16:02:34 -0400 Message-ID: <20260812200240.818004-4-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: UviUfKZbtAMZzW0GtYftrv3vLP29CbH_ X-Authority-Analysis: v=2.4 cv=PbDPQChd c=1 sm=1 tr=0 ts=6a7cd16a cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=9go2EFdEqeYIEFJGgSIA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX3+hClaubEFd3 osrMWWlaCa3HUiKoQoF1/+ccpKQx80ajmxs2CatukAMFaH+zvnxenUz0CctfiKyPs5UicDswUGJ 4h+ch7ArEtjGYKDDZraT7lX7KhJqEjenvCy9pUMBMTkFU/sPETgT2A0lBH6FFUu08plo8s8ROS+ +IqB/B15PCZZPRhDZOtynhnc5tveIGU1mmN4OqAkAE9MgOR/YtJ0ecVAWhdSeuDjFooyVRLUxHt 6Ovj0YD9usy/2WSnl4fPLW01z35IVtLYMFWC4gzHchhkAHSLw80rk+8HO4O4BtMn9iZE3LpHtga VJw8nQDYk3XYwUbaEwbdEUHqQlzpJWibvEpWuBq9amZE3cvII6D4xbnBY/klL9pTTvaXuTvZZEl T4ES4aI1LE0veK4n4NHxnF3IWbxgo3jAgNR1EcrusZK5D8JEwmQha0/FhFcfATgEbvRdq7m7KDX Y+JC7aS4mGA0uLL9grA== X-Proofpoint-ORIG-GUID: UviUfKZbtAMZzW0GtYftrv3vLP29CbH_ X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfXxxmndHviwsqw LE70bnNlG6PLwA+SzqfpFxZbTsbmutUxjz1++kuOl7cfZYrIYYqqxd7/GZLE/0CLEZlE0gqS6v7 f6nKqOZ+Hb9vMjt1AXpu6otBL1HshSM= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 impostorscore=0 malwarescore=0 adultscore=0 clxscore=1015 priorityscore=1501 suspectscore=0 phishscore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" In order to traverse or add/remove ap_matrix_mdev objects in the matrix_dev->mdev_list, the matrix_dev->guests_lock mutex must be held. There are two functions that access the list without holding the mutex: vfio_ap_mdev_probe function ~~~~~~~~~~~~~~~~~~~~~~~~~~~ The vfio_ap_mdev_probe function uses the matrix_dev->mdevs_lock mutex to guard the add of a newly created ap_matrix_mdev object to the matrix_dev->mdev_list. This mutex does not protect list access; its purpose is to guard against concurrent access to fields contained in an ap_matrix_mdev object. This could lead to kernel memory corruption or use-after-free if another mdev is created or removed concurrently. The adding of an ap_matrix_mdev object to matrix_dev->mdev_list is now guarded by the matrix_dev->guests_lock which is the correct way to protect against concurrent mdev_list access. Also removed the following two lines of code because the matrix_mdev is allocated via vfio_alloc_device macro which uses kzalloc, so req_trigger and cfg_chg_trigger are already zero-initialised when the struct is allocated before the call to vfio_register_emulated_iommu_dev. This prevents a window whereby these triggers are set to NULL after the device is exposed to userspace. matrix_mdev->req_trigger =3D NULL; matrix_mdev->cfg_chg_trigger =3D NULL; vfio_ap_mdev_for_queue function ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ The status_show function that supports display of the status attribute of the devices in /sys/bus/ap/devices calls the vfio_ap_mdev_for_queue function which iterates the matrix_dev->mdev_list to find the object representing the queue device whose status is to be displayed. In order to traverse this list, the matrix_dev->guests_lock mutex must be held. To fix this, the guests_lock mutex is taken prior to taking the matrix_dev->mdevs_lock mutex in the status_show function. It is taken there rather than the vfio_ap_mdev_for_queue function - where it is needed - because it must be taken prior to the mdevs_lock mutex in order to adhere to the proper locking order and prevent a lockdep splat; also because the mdevs_lock is needed there to access fields within the matrix_mdev object in that function. See the vfio-ap-locking.rst in the linux kernel tree. Fixes: 2c1ee8983aa3 ("s390/vfio-ap: prepare for dynamic update of guest's A= PCB on queue probe/remove") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 27 +++++++++++++++++++++++---- 1 file changed, 23 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index c6bee69cc22f..f2d662e388bd 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -800,12 +800,17 @@ static int vfio_ap_mdev_probe(struct mdev_device *mde= v) ret =3D vfio_register_emulated_iommu_dev(&matrix_mdev->vdev); if (ret) goto err_put_vdev; - matrix_mdev->req_trigger =3D NULL; - matrix_mdev->cfg_chg_trigger =3D NULL; + + /* + * Take the matrix_dev->guests_lock mutex before adding the matrix_mdev + * to the mdev_list. All functions that traverse the list must also hold + * this lock to guard against additions to or removals from the list + * while it is being traversed. + */ + mutex_lock(&matrix_dev->guests_lock); dev_set_drvdata(&mdev->dev, matrix_mdev); - mutex_lock(&matrix_dev->mdevs_lock); list_add(&matrix_mdev->node, &matrix_dev->mdev_list); - mutex_unlock(&matrix_dev->mdevs_lock); + mutex_unlock(&matrix_dev->guests_lock); return 0; =20 err_put_vdev: @@ -2297,6 +2302,8 @@ static struct ap_matrix_mdev *vfio_ap_mdev_for_queue(= struct vfio_ap_queue *q) unsigned long apid =3D AP_QID_CARD(q->apqn); unsigned long apqi =3D AP_QID_QUEUE(q->apqn); =20 + lockdep_assert_held(&matrix_dev->guests_lock); + list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { if (test_bit_inv(apid, matrix_mdev->matrix.apm) && test_bit_inv(apqi, matrix_mdev->matrix.aqm)) @@ -2316,6 +2323,7 @@ static ssize_t status_show(struct device *dev, struct ap_matrix_mdev *matrix_mdev; struct ap_device *apdev =3D to_ap_dev(dev); =20 + mutex_lock(&matrix_dev->guests_lock); mutex_lock(&matrix_dev->mdevs_lock); q =3D dev_get_drvdata(&apdev->device); matrix_mdev =3D vfio_ap_mdev_for_queue(q); @@ -2343,6 +2351,7 @@ static ssize_t status_show(struct device *dev, } =20 mutex_unlock(&matrix_dev->mdevs_lock); + mutex_unlock(&matrix_dev->guests_lock); =20 return nchars; } @@ -2761,6 +2770,12 @@ static void vfio_ap_mdev_cfg_add(unsigned long *apm_= add, unsigned long *aqm_add, =20 vfio_ap_filter_apid_by_qtype(apm_add, aqm_add); =20 + /* + * It is safe to traverse this list here because the + * required guard - matrix_dev->guests_lock - is taken in the + * vfio_ap_on_cfg_changed function prior to this function getting + * called. + */ list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { bitmap_and(matrix_mdev->apm_add, matrix_mdev->matrix.apm, apm_add, AP_DEVICES); @@ -2820,6 +2835,10 @@ void vfio_ap_on_cfg_changed(struct ap_config_info *c= ur_cfg_info, if (!cur_cfg_info || !prev_cfg_info) return; =20 + /* + * Take the guests_lock mutex here to guard access to the + * matrix_dev->mdev_list in the two functions called below. + */ mutex_lock(&matrix_dev->guests_lock); =20 vfio_ap_mdev_on_cfg_remove(cur_cfg_info, prev_cfg_info); --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4DD2F382286; Wed, 12 Aug 2026 20:03:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564982; cv=none; b=BGoelEUgtAz9kjGzWObWcgbFTc6/QsM607cTF6IUDHr3WIP2GyIIjPuWuGAGzn+lxlTzEaspOhxfarFhc658ZtHB54rFfFs4rsgqnPjPv7oi5zgYzbzmF5PxGprIE8JtG+K0fSxa+1G9rvq05AXaex+sAdwMBEownEebF6JZyyQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564982; c=relaxed/simple; bh=5yyNdGdxAelRtvmaSTyzi6Ux60obfEZJ1rH6Pw+dKr8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=aHtvn23IDbwlcE5SwSKLQwD9Qe2QddeEN5nc7RfnqTSgIXAnz7K7Zupo6V4yFGD0i7KXRTCEGXx6Adt5n0W3yAI6kL7THB+fXY/PPiL4UnX/mEMrmRcxfM9/9U1lExILzn06sOiybyPsUNS+fDxcic9mZ4sML+toIMglzU3IcKs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=A75FbEOg; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="A75FbEOg" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2sBV323334; Wed, 12 Aug 2026 20:02:55 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=m+vJqnk7rifev6aJu KE56s9GIpbulLzAG2kXbqJoKd8=; b=A75FbEOgzORQTKcWBUnI5Z3owtPRClnz9 NhRhJd+SsbgOIiRKL2RabC4BAE0pd/6TgWsRjG6ynoe62pq1iYqoy22pPpW9jyDT H1vOauac/ZPpysu5NfpT/CFPyFmBp3fW8yhE3c+pXtixpTgdTCYGXkj4aiU1rCmT aFPcmJWv3xsfg1wwZ/e2pJSmSb3FTEVrHgHAIfHpfqE4ng4u03mzpamD3TiwMpOo ugd0DE/FXRIr5FwCqrPhy7iOCcm+pfJ4AtTXMS0KGRJiPwtAe7gKTNQL99FvVGOQ fa89/JLDO70QBnQR7Iq2TiVyfbo2bb1kK2qX0sK5N8izuiUU2vzeA== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvnwbk63-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:54 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuFkb030845; Wed, 12 Aug 2026 20:02:51 GMT Received: from smtprelay05.wdc07v.mail.ibm.com ([172.16.1.72]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxesq7y4t-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:51 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay05.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2oUl50135468 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:50 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1890F58052; Wed, 12 Aug 2026 20:02:50 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7778958045; Wed, 12 Aug 2026 20:02:48 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:48 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 4/9] s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object Date: Wed, 12 Aug 2026 16:02:35 -0400 Message-ID: <20260812200240.818004-5-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RsP16imK c=1 sm=1 tr=0 ts=6a7cd16f cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=mm-sKQyJWPVlA1vr6AIA:9 X-Proofpoint-GUID: uxSe5x358MCbGEq1Ur-5xR06yDDgGpxn X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX/S0c1y+jgYYr bPZOmYlFueHTyY3vt0SCfdB4j6o9gbjiUn/sbIiVSvOcC5B6kF/BLM1JglZcSuMK3/44c+k2ZQs cvha4ZRe4ZR1kGbgfyxxpDJVbaUt/vqteuA4MKKxOMuZGcMEWd/yzoy9Ew1gaWuQQITnN0imPJ5 wk5XmPGNHfDXP+Uy3ayzunasCokbeV6EkSxly1tzAEMS2qY6C6VMRiw/4Zkt6z+ftW27CDcdXrL hHVnTYRTrmI2EIggD6ac+SbUSyiZk6rzWVd95cu6tWWfvd7EEP15bA38nCM1KwdkjKW0i8eT5jU Ue9VWrecU6FlzfQYpLQkYrampN17W6pCXJ2FDZS9PkBni5+Wp1hq2uuWgSA4lXSRUXhKL+q4xOa 8gsJo6biTERAUD9VmAMFRoq94O5ukPR1UcXKsDV8QQ1QKEQsHuVDWk5tcwgWpmTp4+204ywR9vH NPZyd0v0/OboU33yb7Q== X-Proofpoint-ORIG-GUID: uxSe5x358MCbGEq1Ur-5xR06yDDgGpxn X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX9hdq89EBBZJF yjdmfz223PasW9PNM5yZUj7pBzYuVfVymD3uMXHax19KTLAhGlPFcDwMbya59Uy+GtSOfQqIhmX gYZSZSBzBBfT9yfeI5susp5THnx7CPc= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 suspectscore=0 clxscore=1015 malwarescore=0 phishscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" In the vfio_ap_mdev_cfg_add function, the apm_add, aqm_add and adm_add fields of an ap_matrix_mdev object fields are modified while not holding the matrix_dev->mdevs_lock. This lock must be held while making these to guard against a race condition with another caller that may be concurrently modifying these fields or any of the fields in the matrix_mdev->matrix. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index f2d662e388bd..21c502598f8c 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2777,12 +2777,20 @@ static void vfio_ap_mdev_cfg_add(unsigned long *apm= _add, unsigned long *aqm_add, * called. */ list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) { + /* + * The mdevs_lock must be held in order to access fields + * within matrix_mdev + */ + mutex_lock(&matrix_dev->mdevs_lock); + bitmap_and(matrix_mdev->apm_add, matrix_mdev->matrix.apm, apm_add, AP_DEVICES); bitmap_and(matrix_mdev->aqm_add, matrix_mdev->matrix.aqm, aqm_add, AP_DOMAINS); bitmap_and(matrix_mdev->adm_add, matrix_mdev->matrix.adm, adm_add, AP_DEVICES); + + mutex_unlock(&matrix_dev->mdevs_lock); } } =20 --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 404EB3914F5; Wed, 12 Aug 2026 20:03:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564988; cv=none; b=csGZ01FTZyNbJWnOgRR2/lfnVD8MeD/0W17ciTc8hHDkwGHOoW2YgHDsyElSkFmWtHquBt/aFfuf0uT0N26ULDYj0/Dpc5D8IGpd7lv80U6N1TQYkZufRx1UQeEcluOR8YR3/kQAeDT23fgdoS5CgXpvJkHZGG9d92CYL6rednU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564988; c=relaxed/simple; bh=EDCwJV+IvNOFK32sSxnYNd78nS1ko9lbivW41h8Ix9g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rqlix6wss9Cn2DU+SWmljpsid/DtvcEFtmWw4Y4pTxaHETy12z4ATOybLvyOm2GS0nViDe7MHpS8BR+BC0jpovXjB8suU6IdrSHyekNS5x1pTLOZShYrXdJwU8L/GU87XkgM8WqAQ/wJtYP2U8zI+anPd5jPTWEEXFiEnAXgCi8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=bhRQkzOF; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="bhRQkzOF" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2qS3197143; Wed, 12 Aug 2026 20:02:54 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Fp8CEaAw34Vga6mTt owRd3t8SDWSYYHYv/RZc9nbQlg=; b=bhRQkzOFsUCG7Zzd+CmlKxomHfXMYZd29 KecaTdh2MFFYhs+mwaP5YdGrWkcUX0YX20O0kJ2VomuEn09A1opj87JBv5n0PrkA 27klrq3OQlY+2USYe7MGIy6CxgcyqzKYnKMX3PCuNyiRe65T1govRBzqR6cI1r9/ 0TNlUDvfE+IQi13dZCMmw9A/pT35AMR7Tp8pmwpKaWeCZpk+zgnDx8RaLuu5MLDq i4A1FR0T1bRRMTSHf2OCc9EpvcTLEYO3b4xDEDjz8xO1EDB3f/HvrG6QXeBKTf2y iE9c9uGhuZbs6IvrwOQTAb7KDL8cFBEpMIFmMAmjn8s9aupGquELA== Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvp33kh4-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:54 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuIHH005088; Wed, 12 Aug 2026 20:02:53 GMT Received: from smtprelay06.wdc07v.mail.ibm.com ([172.16.1.73]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxhfy7ks5-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:53 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay06.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2pgZ32244242 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:52 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E2C8358052; Wed, 12 Aug 2026 20:02:51 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4140658045; Wed, 12 Aug 2026 20:02:50 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:50 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 5/9] s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove Date: Wed, 12 Aug 2026 16:02:36 -0400 Message-ID: <20260812200240.818004-6-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=AMtp2X5w c=1 sm=1 tr=0 ts=6a7cd16e cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=fkyveIzhjB74ZASU3MYA:9 X-Proofpoint-GUID: 7BthvVKpILelZtxclD1JgsetkAvI0vdw X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX91pkNA7AMTNL xo/JWxP4/19PNE9Lyr170yHTTtcm2JdwJnM/6r90sg6/RUmqkH6rQmasVMa5rhcdtj40lBOCuf7 w0i3UuoSgtOFp0gs8HiC6j/R2fzks8Wk3G2qCyk3X/+bJGxSiJbulsuA9cX7/I3NebHAQAlV8LV SqF1HVZlPHM2OR/pZUbS98w6QhZHebY/nKvuB1EIDrJELqx2ptHq/SWDvF2YkxVtL4k51CihHxL 3EjrtKYmfBQRZr2+shHwP4gyFXN6A0RLhL8lQw6mtlxGB4bWkQwmxGLdCK4PU3iUotWyAtooAkm Cjtd9nxwF4QeNd9COfv0FjpOWjIBwhOExRPCwVpOqSHwikWPvZteRa/EMzRx+cNezylficoyI7B Zq+8K3hC63y4jr6Gmw4NKma+2jL35dAgKhXkF1m8aEaJbBslNP+uOwicTh9byXifND7P8xYxSdB A9eW4XAOgvVcsf2q/mA== X-Proofpoint-ORIG-GUID: 7BthvVKpILelZtxclD1JgsetkAvI0vdw X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX2js0s2xPB/jB d6RX8G4DOnipXQodAh4G6mjzwojLEgV8cMmPyF8hdt6MCqJLIN5fKlQoYUlCRLDiagUYjD5Ap82 qJh0L5bSEeIMfkiXI7btzcMq9v/QJtM= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 adultscore=0 lowpriorityscore=0 clxscore=1015 priorityscore=1501 impostorscore=0 phishscore=0 spamscore=0 bulkscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" The vfio_ap_config_remove function uses the bitmap_andnot function to clear bits from the matrix_mdev->matrix.adm bitmap (specifies the control domains assigned to the mdev). This prevents the explicitly unplugged control domains from being removed the KVM guest. The bitmap_and function is used instead. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 21c502598f8c..0f3537aadea8 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2636,9 +2636,9 @@ static void vfio_ap_mdev_cfg_remove(unsigned long *ap= _remove, do_remove |=3D bitmap_and(aqrem, aq_remove, matrix_mdev->matrix.aqm, AP_DOMAINS); - do_remove |=3D bitmap_andnot(cdrem, cd_remove, - matrix_mdev->matrix.adm, - AP_DOMAINS); + do_remove |=3D bitmap_and(cdrem, cd_remove, + matrix_mdev->matrix.adm, + AP_DOMAINS); =20 if (do_remove) vfio_ap_mdev_hot_unplug_cfg(matrix_mdev, aprem, aqrem, --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D0A9C36B910; Wed, 12 Aug 2026 20:03:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564987; cv=none; b=KCTSL44uTuzlNLOm83cQ/8UvdZBtSo/HIv5hlE0eZ+zeHmyaEbdfkb7z9tIr8jygswS7jtzfQT2TWdBjlGnip5SOgirfjeHjDpz937lBQcxpf3SwIfZYC9rzevkau3OesG/mG1XcYV+nyTgVxgTDCZHWW8vmJWJ37ZulAboRINQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564987; c=relaxed/simple; bh=h3HrRTfDZXmhYYsK40T/QjDbLSUMRSd2z58bV1vXTC0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Gv+54AekjempxkyFWrAzJvpn4UZyY37umqiJYJOtM6Jk+CVNh2vhimlqZeCaxfkpDXumavbUbLwIJma2Cxby+P0RqUs5BLG2ikhxvGktoFYFZfC191cZfky50B4/ONh6HLuc9RGnDLoPkXPiv0M1LXIs8IieryKRt1m+Ae2e5Rs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=FGKwI1uL; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="FGKwI1uL" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2eaE2612965; Wed, 12 Aug 2026 20:02:56 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=ynarWxGMXhj6Ih6Rs R1tzlw/ljsTB/gbaRfr5yDpPtE=; b=FGKwI1uLsbi+jbk2TxnwEpF7+Q5uTi9sI gGp0WzQuz7VxEWGcV0HzZ4I0bIelKnKBBb96jUqQPsANuxzVQgShcpc2gSGDphse +3jq65u0blAImqa9cWXdpf/4jGj88r7BRvmycMv++r25Nl1JanIUtioBc30oNNUP /7FwBjDeto29dLiFlYXh/go5iqgYZHz2yFbEe5I/MVnoK3f/vbXR5l+nT+CFzcJj mLLWRJbYOI/FgaS4Cd+PxhL3Xh1mXNfi69nP6rRPEcm1OugZ8lzd977bejoa7y1+ 72v0yxIw/cqq42FFegqiMPyNfVZliD23+l/ynLki2UBtUhvkX7OSg== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvk04f63-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:56 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuQRx019477; Wed, 12 Aug 2026 20:02:55 GMT Received: from smtprelay02.dal12v.mail.ibm.com ([172.16.1.4]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fxf5w7wqf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:55 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay02.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2rdZ23069368 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:54 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A47205805F; Wed, 12 Aug 2026 20:02:53 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1794158045; Wed, 12 Aug 2026 20:02:52 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:51 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 6/9] s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap Date: Wed, 12 Aug 2026 16:02:37 -0400 Message-ID: <20260812200240.818004-7-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX3tKEevlL5UUd w7KDqBgtIP0lC3MlXyXiOX+l5vuGgdIvUmfC54ZErxnLlv8spt11dp6muk33J6lYXjxb5wfVwnq 4WGcPx4f+0Xc+l4PKHCTcKuOI91yvKLW8U445BfMi5wGfOaYWnyQLw16jIpP5npL15Jvl6k2NPq qLU/CasIrZ7xkW/7av376Ma9hDbdHJokAQNxPubj9UrW81m5qAxVcvKhTCCiyogtW1sHwDrWoad l0+QBNws7teDWsh1EqDAP5G+/NSf7e2RZaQQTQxKOOSnRzDnZMK5RGJ5vjLB2u9trcZlEEnmlwY tC5tGAZVPUz11poYlWl/V5gO0Z9AZzrZKagqoP6GJ/oz/DXL5u8IChjshtMpkaGg4/IwmNAIHz5 bseOetNb8+sg0wxb9wJ47Z9XGUUyQt8P1NZC+3sDHbdcdVovJehe3qCbGRoUKljrv5OO8F534Zp 86M/TdecptVbXV9CGRg== X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX0GbNygxCj9Sb tBevEwAPaMEEUZ3bRgHBqhq15Ox3bCjCjHyahFWHzD9NEqhFf+Ig8NTa6395km7cFu1mYzxwFvg PEAs0Eg9xffjOBocvWDmxZ9RcthwUqk= X-Authority-Analysis: v=2.4 cv=RqD16imK c=1 sm=1 tr=0 ts=6a7cd170 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=bGM9o4fjUnjFpbELYA8A:9 X-Proofpoint-GUID: 0t2RvG_dTqR7Et2V8lofGRZcplQ_W1eG X-Proofpoint-ORIG-GUID: 0t2RvG_dTqR7Et2V8lofGRZcplQ_W1eG X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 suspectscore=0 lowpriorityscore=0 clxscore=1015 adultscore=0 bulkscore=0 malwarescore=0 impostorscore=0 spamscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap on the stack without zero-initializing it. In vfio_ap_mdev_hot_plug_cfg(), the vfio_ap_mdev_filter_matrix() function is only called to initialize and populate apm_filtered if either filter_adapters or filter_domains is true. If the hot plug configuration change only adds control domains (meaning filter_cdoms is true, but filter_adapters and filter_domains are both false), vfio_ap_mdev_filter_matrix() is bypassed. Consequently, apm_filtered is passed to reset_queues_for_apids() with uninitialized stack garbage. This can cause reset_queues_for_apids() to interpret arbitrary stack garbage bits as valid APIDs to reset, potentially performing unintended guest hardware queue resets. Fix this by zero-initializing the apm_filtered bitmap at the beginning of vfio_ap_mdev_hot_plug_cfg() using bitmap_zero(). Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 0f3537aadea8..d667ad4bbf70 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2861,6 +2861,15 @@ static void vfio_ap_mdev_hot_plug_cfg(struct ap_matr= ix_mdev *matrix_mdev) DECLARE_BITMAP(apm_filtered, AP_DEVICES); bool filter_domains, filter_adapters, filter_cdoms, do_hotplug =3D false; =20 + /* + * Zero out the apm_filtered bitmap in case there are no adapters or + * domains to be added, but only control domains. In that case, + * vfio_ap_mdev_filter_matrix() - which initializes apm_filtered - will + * not get called and the reset_queues_for_apids will crash because it + * will access an uninitialized bitmap. + */ + bitmap_zero(apm_filtered, AP_DEVICES); + filter_adapters =3D bitmap_intersects(matrix_mdev->matrix.apm, matrix_mdev->apm_add, AP_DEVICES); filter_domains =3D bitmap_intersects(matrix_mdev->matrix.aqm, --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E33263911C6; Wed, 12 Aug 2026 20:03:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564986; cv=none; b=NpUJVdLiTk2kdB6AAfpCyU5SXU2q4H0DVEH3MJMDikTg+dT+0wSFeOaKK+Y4h4dy4wbcozIM4BtY/Zxf7Wt8lgR3F4BAitkslNJ50EUIv6EA+iaxGYmjoKQDYCfr4+0uXvFO3egiZ6DVwg2APIMMYrhRdqgoBsEt6M9xvP4Sfbo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564986; c=relaxed/simple; bh=FoFIW/AgoTdN4VWY1MQQkFfV8yq7HHNYQduDvhZY+EE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JMKEQV0F/p+R4N+JcC8OUayJBLsg5la0xYLTIRgV0wOBQLU56WkNKRwYKdu5kBIpHFOnq1xli1VWTVWoNlZ0dCuZmSEH+AxJaZkurqQdv8L+5ZON/sxq0WjMd1k4sLkZAgeClc92xpNAoMoe/bt4BSfdf8SGvw7qoGKLHAEkT/8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=dnedX8FJ; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="dnedX8FJ" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2rit197158; Wed, 12 Aug 2026 20:02:57 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=VoktGW2yg8hs6u4/C QidroR6kcaQw/g4WWLmh1kAKB0=; b=dnedX8FJkv3ZZV497dBjEWnmAIQOM0JTW Go1hHokA9ClfOBAdccoCBGtXg1Z7JjC29rT4tkU9AyiJrdYRhlebQ+2yNKTftzfd zlMJpczEIP4VapCora5uZzp3K6nHuPHL43xxmN6iupLZwVbFqJlsdzYWwt0y87TS I+5MisjrLMBX0Oca6Mk81lvtOdDlhgRu9ZzrBXsNieRm52bFTeOHkLs2GHmUjTky 3A4MFYjeAi/hrlh0s/tL4d5Yqu8Z4pQ+vK1QvIZPmeq0T3prLZnDfWNQ2mxSchVK CI/CvCRwStOgYBx9hPLjwBJOq9oepdaPl9G+ChpjDnsqqYn/DC0zQ== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvp33kj1-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:57 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuF0e030839; Wed, 12 Aug 2026 20:02:56 GMT Received: from smtprelay04.dal12v.mail.ibm.com ([172.16.1.6]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxesq7y5t-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:56 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay04.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2taf18219688 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:55 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 76CD95805F; Wed, 12 Aug 2026 20:02:55 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id CCBA858050; Wed, 12 Aug 2026 20:02:53 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:53 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 7/9] s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed Date: Wed, 12 Aug 2026 16:02:38 -0400 Message-ID: <20260812200240.818004-8-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=AMtp2X5w c=1 sm=1 tr=0 ts=6a7cd171 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=l_t73i4lE__BKQLLFKsA:9 X-Proofpoint-GUID: TeWBXmlqqj8LM3sO8s0_PQ_UDkjxs9CN X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfXx3vxrhcgXz3V b/Q5Q7hYERPaxvWcgd+hk1LgUUpOJPqn5tCvXIRAZ8iwzqg8fEs+z1QhzGXicMsTyIUpT2uBlok mJxRHu54flnW+CNSnhP1GZQsfNfyN3+39HtPIYyi0n/a7XHj5uMJkuwBF7YEowegashkKYD8DOC 75Px58m34HdEaWW5T7u4upwn4Sl6e2fToMun510foDhUkdbZiQOP41I8OOd4gerJWI3G1bUpnK8 TsozSXln25eGz0GD7B4XAcdHP8FSSaCZqKXN4jxowfdxJ0ekQ0AUsR/YXMEJlT8K55ir6vdM1+O hDDQdr6JuzoG0DfBdFolANdJec77Ms4dS8FatCI0NpQw7pWXsnwqKUfy830Dk3U7JEwKyVg57PZ jNQqtoS7Tp8Su/ltgU0LPRnFPFriAFpE9zefNWjkYOU+BSwkP4r/t99OPQ47Kdj9LGnOIup45WI tWttrgFDVZY/xe9JQwQ== X-Proofpoint-ORIG-GUID: TeWBXmlqqj8LM3sO8s0_PQ_UDkjxs9CN X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfXzu8+9cOiGGY4 Vvsi2ODwaTs2orZ7cb6bj0phQgOdJhbKaSHjENigoGgutTNTWfIFsAMlU3m0D7iDHnJ9wgOqiy/ w0ShMRzM2xEswM4EPXiF5aHnnlxcgKg= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 adultscore=0 lowpriorityscore=0 clxscore=1015 priorityscore=1501 impostorscore=0 phishscore=0 spamscore=0 bulkscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" The vfio_ap_mdev_hot_unplug_cfg() function uses the return value of bitmap_andnot() to determine whether the guest APCB needs to be updated. However, bitmap_andnot() returns false when the resulting destination bitmap is empty. This means that if the only adapter, domain or control domain assigned to an mdev is removed from the host's AP configuration, the bit is correctly cleared from the shadow APCB, but bitmap_andnot() returns false because the result is an empty bitmap. Consequently, do_hotplug remains 0 and vfio_ap_mdev_update_guest_apcb() is never called, leaving the KVM guest with stale hardware access to the unplugged AP devices. Fix this by replacing the bitmap_andnot() return value check with bitmap_intersects() to determine whether the shadow APCB actually overlaps with the removal mask. If there is an intersection, call bitmap_andnot() solely for its side effect of clearing the bits, then unconditionally set do_hotplug to trigger the guest APCB update. Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complet= e notification") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 30 +++++++++++++++++------------- 1 file changed, 17 insertions(+), 13 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index d667ad4bbf70..16779cfc64e8 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2568,24 +2568,28 @@ static void vfio_ap_mdev_hot_unplug_cfg(struct ap_m= atrix_mdev *matrix_mdev, unsigned long *aqrem, unsigned long *cdrem) { - int do_hotplug =3D 0; + bool do_hotplug =3D false; =20 - if (!bitmap_empty(aprem, AP_DEVICES)) { - do_hotplug |=3D bitmap_andnot(matrix_mdev->shadow_apcb.apm, - matrix_mdev->shadow_apcb.apm, - aprem, AP_DEVICES); + if (bitmap_intersects(matrix_mdev->shadow_apcb.apm, aprem, AP_DEVICES)) { + bitmap_andnot(matrix_mdev->shadow_apcb.apm, + matrix_mdev->shadow_apcb.apm, + aprem, AP_DEVICES); + do_hotplug =3D true; } =20 - if (!bitmap_empty(aqrem, AP_DOMAINS)) { - do_hotplug |=3D bitmap_andnot(matrix_mdev->shadow_apcb.aqm, - matrix_mdev->shadow_apcb.aqm, - aqrem, AP_DEVICES); + if (bitmap_intersects(matrix_mdev->shadow_apcb.aqm, aqrem, AP_DOMAINS)) { + bitmap_andnot(matrix_mdev->shadow_apcb.aqm, + matrix_mdev->shadow_apcb.aqm, + aqrem, AP_DOMAINS); + do_hotplug =3D true; } =20 - if (!bitmap_empty(cdrem, AP_DOMAINS)) - do_hotplug |=3D bitmap_andnot(matrix_mdev->shadow_apcb.adm, - matrix_mdev->shadow_apcb.adm, - cdrem, AP_DOMAINS); + if (bitmap_intersects(matrix_mdev->shadow_apcb.adm, cdrem, AP_DOMAINS)) { + bitmap_andnot(matrix_mdev->shadow_apcb.adm, + matrix_mdev->shadow_apcb.adm, + cdrem, AP_DOMAINS); + do_hotplug =3D true; + } =20 if (do_hotplug) vfio_ap_mdev_update_guest_apcb(matrix_mdev); --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 33D013911D6; Wed, 12 Aug 2026 20:03:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564987; cv=none; b=e6BTDefZiBV01kE3mYfRqEL8S2TANeR7avCKE6JtJ1X5AiOIVIxSdTKAShTsJw/xGJ+lOc5qNn7Vaye656+XOVsk58GgJwM9mvo7NMmzxjkutRoz7IIOml/Pp/2acWkvJgvpOnPq2nupipgG6AlfpDeH2CQfyIjQ2KKBJ0cl3L0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564987; c=relaxed/simple; bh=d99vcGOJvfvPZXApQgI+ctxLpqgWFFsgbNmNrrNCbgI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=BpIMEBfMxDgCd54WQ1u9liKKZMwlY3NAp8Trr2S+xaOoNQcMD69cC/BecQjfkFlYTL3DGtJkwcwa/TGprEstKzmwCp35YlgiFRo0lJ0JFLgoyVj97VMUJnjCYyIcT44jAf5WRj/6mMBjC6ABVEcgQt/B6kjXZKE/FkEZ6i5d8h4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=YTX8A7xI; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="YTX8A7xI" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2v8b323398; Wed, 12 Aug 2026 20:02:59 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=DJrwyF NBRJWvVCNo3GIDim/+5NMjplzUdik/G1asjTI=; b=YTX8A7xILiwY08/vDvDCi2 jGVPRcrxW5J9Q8pE3ElUrjybq6oYZhPZ/PayjvGpGJdpF5vl80KlScTAGSr4tKUk 9Ooli3PC6Zm9KIpXjQjIWIyoJy1wj//CtDiosoaNsOWB82cU4xmVf3IVtu0vyZWE MV15POq+xXvrsGqPqp890RypqxpsQHwmIqT7eQfCcSJN7r+AqbwlxEmt7OkhVBg3 T8cGnLb4WbylK+lU3fY9BPr0D4Ew22JuFLMVYCnhj9BE5qs18U7S26mzCMG31gwZ lPu7UTeyzn4figsy/xQFoM29cXQX4ZzGoEdSkD1Y6zLPtWza2fTDOvweWzcRYXBA == Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvnwbk7a-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:59 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuJcB006127; Wed, 12 Aug 2026 20:02:58 GMT Received: from smtprelay06.dal12v.mail.ibm.com ([172.16.1.8]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxh0gfnvu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:02:58 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay06.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2v1s3408514 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:57 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3C0C358054; Wed, 12 Aug 2026 20:02:57 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9F91958056; Wed, 12 Aug 2026 20:02:55 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:55 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 8/9] s390/vfio-ap: Fix NULL deref in status_show() during queue probe Date: Wed, 12 Aug 2026 16:02:39 -0400 Message-ID: <20260812200240.818004-9-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=RsP16imK c=1 sm=1 tr=0 ts=6a7cd173 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=apN4ZTo8cY6xQFFfCyEA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-GUID: ilKaj3sBk0HyDnN13kVmTbKMDsZtbK5q X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX/tok9fgkjMjn rPRgev8ak8wlcia70UCGz45bbwUWp0rSK1RmNOtvd4h29J6LniqnlUmtzCa0ZAjjA3FYPXFmK+V 4RdOOrts4M6u9TEDlErkSVNc3R2ZygFmQA+0yj04RpThUT+vXbQUERHBNlK688ryeMlGQYXCI5J kyYp/6nyl66uCPypVXL7WblL4z9WcOZf+iv+QgP/FNn6dqblgZkuOVCU7ZWCk0eR85h3GdN396G nEJalQvMKJjnR+dui9aufd6JmFkReoAR6S4KGOdNi8nXv7NLBFjxvLh64x0Mt+rBoh1C5WBB233 dghjZd8EsUMXgMy8EkTsT/v4Mkcj91Qyw6jhH94GK28wwjsnelmFcD9aNcvFhh8rkUehcetjeAC uZY+QPoqzC+8h/JdHenPPhGQ39z2N4gC3W66Up/eLkQ0eKkVClIM1EpXIF3ED91q67p+KdrqZan U6c2dW7AYFdGXarKzAA== X-Proofpoint-ORIG-GUID: ilKaj3sBk0HyDnN13kVmTbKMDsZtbK5q X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX2q8WNvZRrC3b URMWTponMTBqebt9YacSps7wSlRzN+6eHPZjeRa+i8XHlSHvgMOb6XROexsp7KO4kj/SKEN9bAw 0SK+VMm1ZM9ggJQE5mR2yCRv1oAJay4= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 suspectscore=0 clxscore=1015 malwarescore=0 phishscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released. As a bonus, the APQN no longer needs to be read from the queue struct after allocation =E2=80=94 it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds. Fixes: 260f3ea141382 ("s390/vfio-ap: move probe and remove callbacks to vfi= o_ap_ops.c") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak --- drivers/s390/crypto/vfio_ap_ops.c | 33 +++++++++++++++++++++++++++---- 1 file changed, 29 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 16779cfc64e8..1edd0b7a3cce 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2326,6 +2326,23 @@ static ssize_t status_show(struct device *dev, mutex_lock(&matrix_dev->guests_lock); mutex_lock(&matrix_dev->mdevs_lock); q =3D dev_get_drvdata(&apdev->device); + + /* + * Make sure the drvdata has been set before proceeding. There is a + * possibility that the drvdata was not set if the vfio_ap_queue object + * could not be allocated when the queue device was probed. In that case, + * the locks used in vfio_ap_mdev_probe_queue() are released prior to + * removing the sysfs status attribute to avoid a lockdep + * splat. That opens a very small window where the status attribute is + * still available without the vfio_ap_queue object having been + * stored in the device drvdata. In that case, indicate the queue is not + * assigned. + */ + if (!q) { + nchars =3D sysfs_emit(buf, "%s\n", AP_QUEUE_UNASSIGNED); + goto done; + } + matrix_mdev =3D vfio_ap_mdev_for_queue(q); =20 /* If the queue is assigned to the matrix mediated device, then @@ -2350,6 +2367,7 @@ static ssize_t status_show(struct device *dev, nchars =3D sysfs_emit(buf, "%s\n", AP_QUEUE_UNASSIGNED); } =20 +done: mutex_unlock(&matrix_dev->mdevs_lock); mutex_unlock(&matrix_dev->guests_lock); =20 @@ -2424,14 +2442,17 @@ void vfio_ap_mdev_unregister(void) =20 int vfio_ap_mdev_probe_queue(struct ap_device *apdev) { - int ret; + int ret, apqn; struct vfio_ap_queue *q; DECLARE_BITMAP(apm_filtered, AP_DEVICES); struct ap_matrix_mdev *matrix_mdev; =20 + apqn =3D to_ap_queue(&apdev->device)->qid; + matrix_mdev =3D get_update_locks_by_apqn(apqn); + ret =3D sysfs_create_group(&apdev->device.kobj, &vfio_queue_attr_group); if (ret) - return ret; + goto err_release_locks; =20 q =3D kzalloc_obj(*q); if (!q) { @@ -2439,11 +2460,10 @@ int vfio_ap_mdev_probe_queue(struct ap_device *apde= v) goto err_remove_group; } =20 - q->apqn =3D to_ap_queue(&apdev->device)->qid; + q->apqn =3D apqn; q->saved_isc =3D VFIO_AP_ISC_INVALID; memset(&q->reset_status, 0, sizeof(q->reset_status)); INIT_WORK(&q->reset_work, apq_reset_check); - matrix_mdev =3D get_update_locks_by_apqn(q->apqn); =20 if (matrix_mdev) { vfio_ap_mdev_link_queue(matrix_mdev, q); @@ -2472,8 +2492,13 @@ int vfio_ap_mdev_probe_queue(struct ap_device *apdev) return ret; =20 err_remove_group: + release_update_locks_for_mdev(matrix_mdev); sysfs_remove_group(&apdev->device.kobj, &vfio_queue_attr_group); return ret; + +err_release_locks: + release_update_locks_for_mdev(matrix_mdev); + return ret; } =20 void vfio_ap_mdev_remove_queue(struct ap_device *apdev) --=20 2.53.0 From nobody Tue Sep 29 04:09:44 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D61A3390CAE; Wed, 12 Aug 2026 20:03:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564988; cv=none; b=h7o6dYRMDwD7mrkEJsyeMolEyODNvdvb9H/nYd0yRakygYAFomxZmMGSalBJoUHSKvQpYwUPa9IEUIvLK83CjeUjj2ikpqMbZ3M3T+HEPEvGLOzZBYJs/WE1/32rC+RdfRbtLprqXixnB6PlBxVvPlQGQgchBNuwsrQgdSJnuq8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564988; c=relaxed/simple; bh=X//UKBUUpUskOIAgBTfpfSW+M6VENerl0FCCuO1HkbE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=KT9fuQSVWP3znSZT1YjKD9jlEc+Mui9RvKbb+P8my65iFj/LEk3vseKW6vvqR+8QX9zYWDGjICOKehSlabo0pw5QaEFSX0U1uRyYHsjUqnnSjAKooP0KyO4XpLWadCr6rtDpMZWJfX74tqzWEXknniFAoB6eDke6u1pBZTM+H/s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=pGWb9cpo; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="pGWb9cpo" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CK2oEJ197050; Wed, 12 Aug 2026 20:03:01 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=PnxY9uMnf06L5hMnn ymhC8gDi9LXvoWYazDhqSh9U3o=; b=pGWb9cpoPfzMXeFZlptZs16+WRwOywVGJ L+PgUGrDYiBMjacud66sUMPDALJ2/iDxUJ6aOQ6TVRLOwRyCDyqVtIYeoBwaCJcq mpsrBjqEOOx6tPHh9USyS8gNW8nFByXCTfXdErr1Uv2A4QHbTvX4t18+ZvxD4zNJ hIJEw9kcqEWXpqfSGKI4MM8/RVy4uJqx7PCE5/tq4vIa1snHdX9XXmSWR5CEOivt yXPdDyrzUraILLYjOmAc2loPvzsfbEo1UNmJhRH/Zx7YNDKmi3aDjD2ivxXuUmoh tTT8CiYzb1fO63tBIQD9Tl6HsVpsZGFUbu0nrmo1jInMUVJQfJyIw== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvp33kjp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:03:01 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67CJuHqY030878; Wed, 12 Aug 2026 20:03:00 GMT Received: from smtprelay01.wdc07v.mail.ibm.com ([172.16.1.68]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxesq7y6d-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 12 Aug 2026 20:03:00 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay01.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67CK2xO858589524 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 12 Aug 2026 20:02:59 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id F20CE58052; Wed, 12 Aug 2026 20:02:58 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6514858056; Wed, 12 Aug 2026 20:02:57 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.9.29]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Wed, 12 Aug 2026 20:02:57 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v5 9/9] s390/vfio-ap: Fix memory leak when queue removed from host AP config Date: Wed, 12 Aug 2026 16:02:40 -0400 Message-ID: <20260812200240.818004-10-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260812200240.818004-1-akrowiak@linux.ibm.com> References: <20260812200240.818004-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=AMtp2X5w c=1 sm=1 tr=0 ts=6a7cd175 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=VrB3zfVs-A4ss5GmTxoA:9 X-Proofpoint-GUID: GNSZ5PH5L9wWryeOC0YZU0f1iHgiRjS1 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX4Gq5/oA5g4qD wccyI6cCng8MIHbF11yZ+JNp/F6gvsGCKT/mA/8UI9etibM031Q+cc4KrzUn/nJ1G+KNDOPdGdV rbIZ49+Cb15B838iATU+W9goj7gd8oic/EI4T0bpG/hg+LU/cSQzGiygokSnNdKvNSOFp2ysMGL aLdS1vn1WTAMxneQpOxxf6qG2v4GnsS5adHxLug9Ap++A3e/PAoUZ4uc6fhhUNayjZYtjvzOCAG kmnThbpYyfzlvQ9KZguUwbX6Lm1Q4Ekce9+SOiDFp3dX+Da+3mx2znMBViWpw716r+mafPw8t/h 7ISRnSTZ1R4qfQwuxxmJsPH46baZJhsyLjUazfyL3eahzXWP6N4zoVLOlB2dlHHsXameNLMa89W uywB2f6VRE1Dkrst9iQA/b+zEKGn1Mg4IzFj2TDAYex2RNW026bvH1PXlRbu2OkaYWRKHk7FiE0 FyzeBuHJuPgao5wWAtA== X-Proofpoint-ORIG-GUID: GNSZ5PH5L9wWryeOC0YZU0f1iHgiRjS1 X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MSBTYWx0ZWRfX1dUTnYbXAXld PwwgNL9GXzo6DH4G9dQXAMv9/1Uz8aAdgwilv/TBNDZhhFT/eIQsoxB0w2V/S8+m0mRhcrRhfGy zOKj3vh3gVn8Bv/q0gToOgHQc5tM3QY= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_06,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 adultscore=0 lowpriorityscore=0 clxscore=1015 priorityscore=1501 impostorscore=0 phishscore=0 spamscore=0 bulkscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120161 Content-Type: text/plain; charset="utf-8" When an adapter or domain is removed from the host's AP configuration, the AP bus invokes vfio_ap_on_cfg_changed() to notify the vfio_ap device driver. For each ap_matrix_mdev object to which the adapter or domain is assigned, vfio_ap_mdev_hot_unplug_cfg() is called and removes the adapter or domain from the matrix_mdev->shadow_apcb (i.e., the guest's AP configuration) and hot unplugs it if a guest is using it. The new host AP configuration (sans adapter or domain) is then stored in matrix_dev->info. When the AP bus subsequently unbinds the physical queue devices associated with the adapter or domain that has been removed, it invokes vfio_ap_mdev_remove_queue() for each queue removed. At this point, the adapter or domain will no longer be assigned to the matrix_mdev->shadow_apcb or the matrix_dev->info object because they would have been removed by vfio_ap_on_cfg_changed(). Consequently, vfio_ap_mdev_reset_queue(q) is bypassed and kfree(q) is called without executing vfio_ap_free_aqic_resources(). This indefinitely pins guest memory (q->saved_iova) and leaks KVM GISC resources (q->saved_isc). Note that resetting the queue would fail with an invalid APQN error due to the fact the queue is not longer in the host's AP configuration; however, it is still necessary to free the AQIC resources. The fix here is to call vfio_ap_free_aqic_resources if the adapter or domain is neither in matrix_mdev->shadow_apcb or matrix_dev->info. Fixes: b9bd10c43456d ("s390/vfio-ap: do not reset queue removed from host c= onfig") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 1edd0b7a3cce..bd9d239caeba 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2533,12 +2533,15 @@ void vfio_ap_mdev_remove_queue(struct ap_device *ap= dev) /* * If the queue is not in the host's AP configuration, then resetting * it will fail with response code 01, (APQN not valid); so, let's make - * sure it is in the host's config. + * sure it is in the host's config. If it is not, then free the KVM GISC + * resources. */ if (test_bit_inv(apid, (unsigned long *)matrix_dev->info.apm) && test_bit_inv(apqi, (unsigned long *)matrix_dev->info.aqm)) { vfio_ap_mdev_reset_queue(q); flush_work(&q->reset_work); + } else { + vfio_ap_free_aqic_resources(q); } =20 done: --=20 2.53.0