From nobody Sat Sep 26 07:14:51 2026 Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 91AEE4D9901 for ; Thu, 3 Sep 2026 16:07:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788451640; cv=none; b=h2LrksJLluAAHSAo2yEWuVL8vu//DX/oISsCEG8a1w4KoAcnSsJ7pHY4On2XDokeyagJSUXqzU905rEpYFppUPDPYyoyXW+eZJPT+CmpF3wM9kBpILmNnaWVrWegN1MEt/9OC5+jlHOHC/tnTS1awMS8PTkeo5gK9u+qznUmpBo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788451640; c=relaxed/simple; bh=xd7QfPoBvok/Ce3FnOcL4vksYEdiJx5bQP+Bx/J5PtU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Gu+1klI+I24wEjxLbbhyBwl8QU9a7auX65y6VKRX+lmvf4FdIiMuQa9MSH8ZsiuVJBkTpfPIbbgC2VyKLlKXYk2rAGBwV5DI6RO/T1Mhgtx8zjzXhcykaEIrW2LZmxCg1ag6nFfLs8U/lc/vAYcT/XawR5K1YWavTz2z4XQOXqg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=lkQvsfgS; arc=none smtp.client-ip=209.85.216.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="lkQvsfgS" Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-39647184c73so1198720a91.1 for ; Thu, 03 Sep 2026 09:07:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788451638; x=1789056438; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:reply-to:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=xyyusPI3FD+mQJM1H+4lN3LfiPaBkg/Gx00WGPfPItc=; b=lkQvsfgS+idHRawxzjt9k6zh8JLmR7pjTKtQMEL0WEYCIFd38dWAzRO1U0JVenUT7F tFMBJoFy4KLaVpHx4KHTJeXhVF563de9cXuaM8Vxd2rTi+Y3n1B8HkCCTe69WEd5/ATo cJoMppkf4c16BNAANW97+xzWI3wpgGLjwXl902yBoGpK9jQJGG4o71b9zrFshuRrvwfp INyHvo1YfYlZcLMszXtIe75EaSSyZwINaeq0PMyT+PTJCcjh1++KOjx0wExuO0Kofz9k czQq0+yz596FwAOXKfP448TJxMOiX3V5uFZ88j5cLRJ9nt2uzb/JPD0VGE52lPPYiRpS tszQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788451638; x=1789056438; h=content-transfer-encoding:mime-version:reply-to:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=xyyusPI3FD+mQJM1H+4lN3LfiPaBkg/Gx00WGPfPItc=; b=kgipVw9VO0vFQbpFk3ooFQvLTqd6Zq9Gdf+44TlnXcqUqn3RgOqTF6nqLx1cbO/pw2 ++c+sf/jGMaPa9KdTpFManimb6JFtaJd6Eq8PH+Nu1zjXA7MBE+hNvtppR5q3GRVBwtF HAg0hw5RPtxx33XXgFNu2Zi4b0nHVFWo4OHilX9dPWZ6B8sTZ6u1emWztg0TdxPUGRWZ V5sJgtyhVP6IsW9k6zPJ0uopKC54TDxw+Od27K7JARNc7S6fsfm3aG7YxtVGUXEz3SVr lGR1b4he/ZC6O+yRIHuYOFuroacO89NY4Fm8IlkKM6mUesFtOR4vvJUIgb31p1cJEqxw +/FA== X-Forwarded-Encrypted: i=1; AKwUvBxKAMm9qs3KXovnAmd/SQtevjxCm/dLN3sWxmCGvy4otJp27NKF6neFhLaTFJRq5UmGGL4mOXqvafnXKPo=@vger.kernel.org X-Gm-Message-State: AFuF++nHjhF7vYVFOAiXaswIRhZyUXuoq2XmLPiSAlettEvy0aCebUro 3GBkKBhOD+7zshV0TlNkIxTjPmTqtdhulUhqCWb3Ec73fVShgr2QklxB X-Gm-Gg: AYBFou3gYSc6p8zmyLDKA9gB0zDX8F1pCrN81mxv+3X9Y2qcf+f5mgzqB0VvBPU88Ts lpQaPAd54zHBal71Jj94Bw8NOc7UEoupqGcXC/vo4LgKMQFmOFPTn4LJURjHZs6N1iaUxL4kR+k MlspbNK53N9jaC1Sd6BTFFTtWh+taXzBYs2hvhZtaaQp+14c4UhN39+tdBql3manNlfkAWSoaDe 3tKKwyU+rpTG8CTvXVASFxfD6FgjHxz/1Z7sw45DPfJRjCYIg4T17yJbW6kjUVY1Hf1mtiJEjCe snKlv5mVsTK2hCRxSOLYt48wg+hcAKm8rXTt2/shLc7kgbcNsztq9AzS4WUVnsBu9+jr79TQLe3 z/Paevz0JASCtgOOvMC/XWys+iingzgbyVfE9ufNs+qijkdHFKZI2WF2RnF5QZRJaFj+dEEc5yZ QWa93ugDR/TUOSuWat2eabTC0mMEM/iHkJmu6v7buD8ReuyoN5EDCr/2c0IrkeXlUucw== X-Received: by 2002:a17:90b:4c4c:b0:395:8124:ac53 with SMTP id 98e67ed59e1d1-39b1322464emr3752631a91.6.1788451637343; Thu, 03 Sep 2026 09:07:17 -0700 (PDT) Received: from mhkubun.mshome.net ([50.34.2.22]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39ae8ccc72fsm3702020a91.2.2026.09.03.09.07.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 09:07:16 -0700 (PDT) From: Michael Kelley X-Google-Original-From: Michael Kelley To: kys@microsoft.com, haiyangz@microsoft.com, wei.liu@kernel.org, decui@microsoft.com, longli@microsoft.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, netdev@vger.kernel.org Subject: [PATCH 1/2] Drivers: hv: Add vmbus_leak_buffer() Date: Thu, 3 Sep 2026 09:06:50 -0700 Message-Id: <20260903160651.1637-2-mhklinux@outlook.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260903160651.1637-1-mhklinux@outlook.com> References: <20260903160651.1637-1-mhklinux@outlook.com> Reply-To: mhklinux@outlook.com Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" If an error case needs to leak the buffer memory allocated by vmbus_alloc_buffer(), doing so requires knowledge of how vmbus_free_buffer() works. In a CoCo VM buffers are allocated differently from a normal VM, and vmbus_free_buffer() handles the difference. Encapsulate this knowledge in a new function, vmbus_leak_buffer(), that error paths can call. After calling vmbus_leak_buffer(), a subsequent call to vmbus_free_buffer() frees the additional resources used in the CoCo VM case but does not free the actual buffer memory. As such, vmbus_leak_buffer() is callable in a context where accesses to the buffer memory may be in flight. Signed-off-by: Michael Kelley --- drivers/hv/channel.c | 26 ++++++++++++++++++++++++++ include/linux/hyperv.h | 4 ++++ 2 files changed, 30 insertions(+) diff --git a/drivers/hv/channel.c b/drivers/hv/channel.c index f4370617deac..d5d20e322831 100644 --- a/drivers/hv/channel.c +++ b/drivers/hv/channel.c @@ -648,6 +648,32 @@ void vmbus_free_buffer(void *addr, struct page **chunk= s, u32 chunk_cnt) } EXPORT_SYMBOL_GPL(vmbus_free_buffer); =20 +/** + * vmbus_leak_buffer - set up a buffer to be leaked by vmbus_free_buffer(). + * + * @addr: buffer address + * @chunks: chunks array from vmbus_alloc_buffer() + * @chunk_cnt: number of entries in @chunks + * + * When @chunks is NULL the buffer is a plain vzalloc() allocation and + * the buffer is leaked by setting @addr to NULL. Otherwise set + * @chunk_cnt to 0 so that vmbus_free_buffer() does not try to re-encrypt + * or free the buffer memory, but still releases the vmap address and + * the chunks memory. + * + * This function may be called in a context where the buffer is still + * being accessed. It must not remove any kernel virtual addresses of + * the buffer or change its encryption status. + */ +void vmbus_leak_buffer(void **addr, struct page ***chunks, u32 *chunk_cnt) +{ + if (*chunks) + *chunk_cnt =3D 0; + else + *addr =3D NULL; +} +EXPORT_SYMBOL_GPL(vmbus_leak_buffer); + /** * vmbus_alloc_buffer - allocate a host-visible, virtually-contiguous buff= er. * diff --git a/include/linux/hyperv.h b/include/linux/hyperv.h index e61f9a4cb7c3..c55de4d01cbb 100644 --- a/include/linux/hyperv.h +++ b/include/linux/hyperv.h @@ -1220,6 +1220,10 @@ extern void *vmbus_alloc_buffer(struct vmbus_channel= *channel, =20 extern void vmbus_free_buffer(void *addr, struct page **chunks, u32 chunk_= cnt); =20 +extern void vmbus_leak_buffer(void **addr, + struct page ***chunks, + u32 *chunk_cnt); + void vmbus_reset_channel_cb(struct vmbus_channel *channel); =20 extern int vmbus_recvpacket(struct vmbus_channel *channel, --=20 2.25.1 From nobody Sat Sep 26 07:14:51 2026 Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3D9664E8DEE for ; Thu, 3 Sep 2026 16:07:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788451642; cv=none; b=kJCOd67COVFNGphOR9sMZ3k0QW9fJhW511L4GnqExD3OYWqOwxB+jupUDXsUdp0z8XBhPeTWcZoSeF9veFxh1QX1kFQSoCcsKuTfBDVk5e4wAsbZebu5/G9ULmYg9E9HO1mWjZCvF4HBgxCAAu6x/1kVR+S5Zv1sMC1+TPrZgGA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788451642; c=relaxed/simple; bh=Jzu2KXstYOECbzt9rTNWK4DwBRqC3yCzhFkwK4z3dl8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=JyBTNu8eJWTKH2c7Mv6njSrmC/Y9v4o7PuWcC46EPJ7pJPSI6u++OlmIHxYSe+sCKP2HmjYGHsizL1ykQbkL0EEIbQq/+QK6Z1t/zSn35FnDCZafICWJfGbpW/6wnXIeDWfHGTROXQ949WygqczG3vBEtcIgnhQXjcjvA+XkMbk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FJq5qR6/; arc=none smtp.client-ip=209.85.216.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FJq5qR6/" Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-39647184c73so1198759a91.1 for ; Thu, 03 Sep 2026 09:07:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788451639; x=1789056439; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:reply-to:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Pk/3OnFOTIoRoKUZw9CsXTCFHsM4oEkvuCZPpwqZeus=; b=FJq5qR6/Uz7FKXcPGnqLfKVS/Ps4w0xrTa524Q3/Fo+4tngtg/xL4oTlegQC+tdVnC iJRY4l+4g96z+B3WohoayBr8/4u9LzYb9fXA9BXqlm08lCkxzDiiAfQfq3KzDDmX1Qqn 4bIKSENWUqsxgnsITag7dMbUdRTUdk/DxgZguO7FayIKPNMUId6mz+2b92aIjoPtZErW vEzkI1ypFykKNvKA3Q+c6B6f/2I7RUO2kHsXt/HwQk+w82RVLkLeFU/XxXSwcWA9IW6B 6g4w+0e5TFf9hB8yVedPhk3UI+TXSQy0NJg1wLAxqDxX+W6GiYH2TUvhfaK1AZYe3MMl jIRA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788451639; x=1789056439; h=content-transfer-encoding:mime-version:reply-to:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Pk/3OnFOTIoRoKUZw9CsXTCFHsM4oEkvuCZPpwqZeus=; b=ZUEEZFax+V7pYKOXTmc2E4DPqSlUpZOqpsCWB4QxDypDmlnM/FvyXPCM0CqKPPQuUh zrM4d7LLUgOw2PMiM/D/1tJY/Rh2o6TiMBk9MfrPSmkhR3UphoElRYv9Hd/3Bk8snqpd +GUf8eBlpN3MXEfrGpOvw8uVTWFlRh4Op2ginQu+uVEGR+cNhHFcVXFuYm+Laa2hrEY+ UeLe4shDpLnDBDeBOt/7Gzfw7cpQuwp668Txn3G4fqlb+UIb2FDeqd81qBmHSYth8FWq v4aFeFySK+lARy5IZPrCmhuCzca1lSGxQbGt2f1kJB5t52qwfFXYihiiic5lGAvTr+qh y+HQ== X-Forwarded-Encrypted: i=1; AKwUvBzAY7bSwkz92DJYqzMxDb6a1noUdNb4vgez4qop1lhVYSlKSKEPeyP00ObQ1PaAiCUXsF3UCqTNASC66kE=@vger.kernel.org X-Gm-Message-State: AFuF++mLuJpwZ8nkjce9UMQPijcuhfi15S1Wx+yoXn26aP/vKRMAD6nd mSypNNeXDGaA7zDOnTdWl13GDBvclu09HQ0W25/dpOo0rjXj//N2/sjo X-Gm-Gg: AYBFou33uTxH6DspbJaMK0TK8agdPKXnm2GvAi3Tmwj4mCXKKOK3aOANoI6qseQ1D4s klQustumn4iBlzrxR36dzkpnDaJkBefyLasJtQvh7fAlsVMQ3nvg5tH36fpxcmLxBVGzZrsQJSn i+3LP5Xy8cTMy5jA5jeo/v5a6ryimMcPxdA1N8WhwSjiqTZNsOikvSdODL6c2qDPwHvaGb/UmOR wfI8XRQy1Cqn0FtsukFAoi7MOvfn3tQuvxzmJBctORnsbGBXfnQSMRAZIOzl3VSDN+erad3ytBm iuAJSaXI59/EJ0Q1hzberD0bbVbQUoXpFMCu+oGS5l/9RykgRf8iN52kfTaS2/YPHUzsWL7DpaA 3anwFS8VmoJwECsdOnX6rse/UPViDI/oUO8CbNkOH/8cnaDpzsdkQ61T0jC0JgpQtr+gEy9voR4 GG1cHNY//bmTggKwOyxE7zPa5yMgV17Rx9KH/cBEP73y8P6e175sIgaLSWFD/jT9dlQA== X-Received: by 2002:a17:90b:3cc3:b0:398:9bd3:d6d4 with SMTP id 98e67ed59e1d1-39b132d819emr3821453a91.14.1788451639287; Thu, 03 Sep 2026 09:07:19 -0700 (PDT) Received: from mhkubun.mshome.net ([50.34.2.22]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39ae8ccc72fsm3702020a91.2.2026.09.03.09.07.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 09:07:17 -0700 (PDT) From: Michael Kelley X-Google-Original-From: Michael Kelley To: kys@microsoft.com, haiyangz@microsoft.com, wei.liu@kernel.org, decui@microsoft.com, longli@microsoft.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, netdev@vger.kernel.org Subject: [PATCH net 2/2] hv_netvsc: Leak send/recv buffers if GPADL teardown fails Date: Thu, 3 Sep 2026 09:06:51 -0700 Message-Id: <20260903160651.1637-3-mhklinux@outlook.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260903160651.1637-1-mhklinux@outlook.com> References: <20260903160651.1637-1-mhklinux@outlook.com> Reply-To: mhklinux@outlook.com Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" If GPADL teardown fails for the send or receive buffers, the Hyper-V host retains access to the buffers and might continue to access them. Per the code comments, the intent is to be safe by leaking the buffers instead of freeing them. The intended behavior existed prior to commit 02400fcee254 ("hv_netvsc: use RCU to fix concurrent rx and queue changes") because freeing the buffers was done in the same function as the GPADL teardown. The "return" statement in the error path effectively skipped freeing the memory. But commit 02400fcee254 moved the freeing to a separate function that is called later. It has no knowledge of the GPADL teardown error, and so frees the memory regardless. Fix this by calling vmbus_leak_buffer() if the respective GPADL teardown fails. The later call to vmbus_free_buffer() then skips freeing of the actual buffer, including any re-encryption required in a CoCo VM. Reported-by: Sashiko Closes: https://lore.kernel.org/linux-hyperv/20260731201210.3653C1F00AC4@sm= tp.kernel.org/ Fixes: 02400fcee254 ("hv_netvsc: use RCU to fix concurrent rx and queue cha= nges") Signed-off-by: Michael Kelley --- drivers/net/hyperv/netvsc.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/net/hyperv/netvsc.c b/drivers/net/hyperv/netvsc.c index 5cd084e5696c..449dc928cc44 100644 --- a/drivers/net/hyperv/netvsc.c +++ b/drivers/net/hyperv/netvsc.c @@ -316,6 +316,9 @@ static void netvsc_teardown_recv_gpadl(struct hv_device= *device, * rather than continue and a bugchk */ if (ret !=3D 0) { + vmbus_leak_buffer(&net_device->recv_buf, + &net_device->recv_buf_chunks, + &net_device->recv_buf_chunk_cnt); netdev_err(ndev, "unable to teardown receive buffer's gpadl\n"); return; @@ -337,6 +340,9 @@ static void netvsc_teardown_send_gpadl(struct hv_device= *device, * rather than continue and a bugchk */ if (ret !=3D 0) { + vmbus_leak_buffer(&net_device->send_buf, + &net_device->send_buf_chunks, + &net_device->send_buf_chunk_cnt); netdev_err(ndev, "unable to teardown send buffer's gpadl\n"); return; --=20 2.25.1