From nobody Fri Sep 4 05:20:02 2026 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7A9293126A0 for ; Fri, 4 Sep 2026 00:43:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482627; cv=none; b=SKEB5Hy5RbltYEdktl63o4smirqap9iM1cj8wFChngBVk5x8Gc1n7yKMX8TWb6NiV3+VpWASq6XtzCOWuEKfzygrUvA4iuZwWohyatPodtZSjQhW95zT/1c+SsVUVCELkmt1xQ4YCUaefzcy1p2vqR8p2PisEXMQ0JWiclSvrNM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482627; c=relaxed/simple; bh=uPpdSve/KMXyb4J63L091m+vctxs7emvRo1xsJVEMuo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=rlncdlL6Z4+nKYuY1CSX0EeBbve7wuJAEiCCDu3bHZGs+VTDLoJ4xbd5TRMPj419+3tMQozLaMj1VRIzovs3aT575xXRYuyR8NRGfz9s/vLgm656CsQaaasQIl34J+vzyninfI1VuCzDTqWkNkzivLyOzZAKo2TdDi428OKs58A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=VucA2pEG; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="VucA2pEG" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-84a67b16217so603033b3a.3 for ; Thu, 03 Sep 2026 17:43:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788482626; x=1789087426; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gKWtQCST/EuxgO5WVT81LHcHZYensAAKyMOkSmJAd+8=; b=VucA2pEGA3pUjx/KhO36omYw4b99bykPHfieut70Te0EI9RVA9L6oH2UChqeJXJL1g moB+e1gVZd2AUqSqR9m8jHxhdqytQ3S1kJFtdormyyEYzjPEmFUbEk1LVMaPbFX8cg38 OHNb9R9erXJNOc47ZVmxn2UOTuMZVQf/x4zlXW0S+ltR/lSRHoRVCa3prCgcOJ77CUm6 HxruI5kTCKIlWG4x1L8L1gO5MpgDDej0uYW29NiFKbi2Xn2SM/khM4Y55v+Yw1CMlX2f OyPb48MbDjBmU8HCJoTQgwBDOdQwPG4dZMCnG1ukXPu5KG4kL1IPcB8ev+wDAjO8abXs LTrQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788482626; x=1789087426; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=gKWtQCST/EuxgO5WVT81LHcHZYensAAKyMOkSmJAd+8=; b=U8oUwoYbkPh7jXIAN4bIu4wrTZEtajLOPBqsvKhH68ethO/GPQhUwsvtAAPuHc3Y4g 3W4piWl7NQD9FOYjCLzR0bkAK4zytsi+sczGQI1uSh4xnAO5o3oybdahF6P/gA/xicpm F6JqYTUIF5R/C4hOyFtqmQu9y4BJUJj91uuEKM0JLJd3LwFV4gO5BtBLYSBVUC5rqj98 ouvLQ5GtqcrFlCqrH1zkgzW06pUBYclC6WMfB9NU1VRn9QZwdwDw/WgMKczrtpTFPZhV gtpGEBXKkNXW9USPX3lRFnnf82m5pxbFontirMFMgK2F4loLaoYoUwaGZ1JvrR8S4yLD VZag== X-Forwarded-Encrypted: i=1; AKwUvBwT/sD0fLgUPL0SnLxm5EVTEynIfav6sLXUJ7rPlwPEfC96okOIR/koN+kNMPpJbuRolS3QNx5fINLVMi8=@vger.kernel.org X-Gm-Message-State: AFuF++n7owjVH6F3TIDvdvr8K5yC79jjIHWrupDalso2fatmX0nUGwEs SegTF54JeKgEvJkK0nypWpQj+qKjzpoMweSUyDW2bnCvmrFbj1ZloSvNAMDJmSCImj38DNm3/bO kbX+58A== X-Received: from pfem13-n1.prod.google.com ([2002:a05:6a00:c08d:10b0:851:c4fc:fe2b]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:2c97:b0:857:7337:5db9 with SMTP id d2e1a72fcca58-8616af6486fmr3815983b3a.23.1788482625135; Thu, 03 Sep 2026 17:43:45 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 3 Sep 2026 17:43:39 -0700 In-Reply-To: <20260904004342.3162959-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904004342.3162959-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904004342.3162959-2-seanjc@google.com> Subject: [PATCH v3 1/4] KVM: guest_memfd: Gracefully handle xarray errors when binding a memslot From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: David Hildenbrand , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Teodorescu , Dennis Tighe , Sashiko Bot , Yan Zhao Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" If inserting a memslot into a guest_memfd's bindings xarray fails, propagate the error back to the caller, i.e. fail memslot creation as well. Signalling success and continuing on with memslot creation results in use-after-free, as the guest_memfd instance will remain reachable via the memslot after the file is freed (kvm_gmem_release() won't nullify the file pointer due to lack of a valid binding). Opportunistically WARN and reject binding if KVM_MEMSLOT_GMEM_ONLY is already set, partly to guard against goofs elsewhere, but mostly so that KVM doesn't need to worry about clobbering flags when unwinding on failure. Fixes: a7800aa80ea4 ("KVM: Add KVM_CREATE_GUEST_MEMFD ioctl() for guest-spe= cific backing memory") Cc: stable@vger.kernel.org Reported-by: Stefan Teodorescu Reported-by: Dennis Tighe Reported-by: Sashiko Bot Closes: https://lore.kernel.org/all/20260823135031.4F6DC1F000E9%40smtp.kern= el.org Signed-off-by: Sean Christopherson --- virt/kvm/guest_memfd.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c index b596486d184c..0b48e9a775aa 100644 --- a/virt/kvm/guest_memfd.c +++ b/virt/kvm/guest_memfd.c @@ -612,10 +612,14 @@ int kvm_gmem_bind(struct kvm *kvm, struct kvm_memory_= slot *slot, struct inode *inode; struct file *file; int r =3D -EINVAL; + void *xar; =20 BUILD_BUG_ON(sizeof(gpa_t) !=3D sizeof(offset)); BUILD_BUG_ON(sizeof(gfn_t) !=3D sizeof(slot->gmem.pgoff)); =20 + if (WARN_ON_ONCE(slot->flags & KVM_MEMSLOT_GMEM_ONLY)) + return -EINVAL; + file =3D fget(fd); if (!file) return -EBADF; @@ -654,7 +658,15 @@ int kvm_gmem_bind(struct kvm *kvm, struct kvm_memory_s= lot *slot, if (kvm_gmem_supports_mmap(inode)) slot->flags |=3D KVM_MEMSLOT_GMEM_ONLY; =20 - xa_store_range(&f->bindings, start, end - 1, slot, GFP_KERNEL); + xar =3D xa_store_range(&f->bindings, start, end - 1, slot, GFP_KERNEL); + + r =3D xa_is_err(xar) ? xa_err(xar) : 0; + if (r) { + xa_store_range(&f->bindings, start, end - 1, NULL, GFP_KERNEL); + slot->gmem.file =3D NULL; + slot->gmem.pgoff =3D 0; + slot->flags &=3D ~KVM_MEMSLOT_GMEM_ONLY; + } filemap_invalidate_unlock(inode->i_mapping); =20 /* @@ -662,7 +674,6 @@ int kvm_gmem_bind(struct kvm *kvm, struct kvm_memory_sl= ot *slot, * not the other way 'round. Active bindings are invalidated if the * file is closed before memslots are destroyed. */ - r =3D 0; err: fput(file); return r; --=20 2.55.0.979.g7e5102b832-goog From nobody Fri Sep 4 05:20:02 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 73B68325494 for ; Fri, 4 Sep 2026 00:43:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482628; cv=none; b=UdsxpV7nWEMYgz+7PJH+Y8rERnopKFUWoBAp45se/TtP18arg05lEvF4s+AVrpRZTDG4LlZXCrJaBkROjYaLUltdm7igqAYB1XiA4etTg9NsIoJy8UKxCEmDueuxz7WudCTYm0LrN48KjhcMy8LhSL+pZIw67xCb/Iz4vO9VdLM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482628; c=relaxed/simple; bh=MqvkRlvP3U3NczrZYJ3FMOO7WFdag2M3s3OFWKM5J84=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=fwIvjOZZ6i39p35N3k3SMV9kQuPyWQi4wBboz1cxMfTqQKFcFbSHSLHpVNV8nPcnUy98VVFrL/HpB8YDrIoyNXv6OzCcLDDUdvP1iEN/lDSdWQYFhHNDN8PCGQJ6iMK2SxmTE20DTVMGBhtC+ddWvpGlnI3LARGkd9H75kquUTQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=UJSdAI6M; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="UJSdAI6M" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-c856470fe9fso523900a12.2 for ; Thu, 03 Sep 2026 17:43:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788482627; x=1789087427; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=HKx1UbmkHdZWwP93GWvKxJAzVfbjWV3VN7p9EAmhWKI=; b=UJSdAI6MemqFkfUOYcokJ093Q8Vd+kgMJ+ORxp3dtxuxV6yBxnd6BCyS0XzhOSeejo rOW6t56mB3xlHkH36Ap18IL8f3kUhbbn3nA+5vUb8ynqKCLYXNKZri69uyTvyrLbNoYp XTj3p60OgtycpesL0qPI0Jp2AQPDrupKGyCy6oOCeNP8deczQgSo9mzUwQUXIC+Pw4Lw 1ZeJCXB4fZRoqjNcQp3C/NNgyMd+4ajmu/Y5Xl1voC3U7vIVQDFK+8vZAX3DqFcQC9JK SSABPoZ+/0d06wNZX4wxiwg+q75uFhXn7/AOWnpNxPxsFz9i9U1PqxEVytd15bRYFvKI IWXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788482627; x=1789087427; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=HKx1UbmkHdZWwP93GWvKxJAzVfbjWV3VN7p9EAmhWKI=; b=dh2EgcQBSo217S3Xb6R+A7sodR1ydxnWev1N++mEQjtGIQC6qkT44rAFzDaU83/48m uO0n5vmNWmLLvMZfe/NYy9zLol39yz3JeT2WQb5fziShT7DuQdNDX0VKDPmvVPQcsAfl lMbSw7Yvz4rJjWzCpJyBYkNbF0NJhNQx2QbRjHVY0vbMT+jrz7/j7Qzh17zNFnXgL9W8 9pWyrSIV5g9hov1Zix5VkX9p8r16roAHTL/YFambsVadTwuKjtxhgQQgiA+mXkGFT83t 5RE/feiPsw37sEah5lvwxABv0dL62aPfn9VX3c24PLsVLjgJfEUeivPd8KAPukuvTdoP 8ILw== X-Forwarded-Encrypted: i=1; AKwUvBzHnHsHt7awkMvIT8H69eR+YdggroB2e1Ptn13Ov8Exnq8L8f50oa3cUVpSJIKHZKZQKitU5TpFcQJSZpA=@vger.kernel.org X-Gm-Message-State: AFuF++kB/MSGYx3WO9pjEP8fFb33fKyrJGE1vOiYtgKv/ziSX8tvl7Bt PHQMmOWyoS1Y0fsyfFc9Sv3p2p5jFJuk/dhBv9nUV0At/r9aMDSESik7FNn0UkeksXgFOYSdYEN XkllYag== X-Received: from pgbq19.prod.google.com ([2002:a63:5c13:0:b0:cc2:9b7a:38a]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:2291:b0:3d0:88f5:f812 with SMTP id adf61e73a8af0-3da39d147e0mr3721581637.10.1788482626470; Thu, 03 Sep 2026 17:43:46 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 3 Sep 2026 17:43:40 -0700 In-Reply-To: <20260904004342.3162959-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904004342.3162959-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904004342.3162959-3-seanjc@google.com> Subject: [PATCH v3 2/4] KVM: Use goto to handle errors during memslot preparation From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: David Hildenbrand , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Teodorescu , Dennis Tighe , Sashiko Bot , Yan Zhao Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use a goto to unwind early memslot changes if preparing for a memslot operation fails. This will allow moving the creation of guest_memfd bindings into kvm_set_memslot() without needing to copy+paste the unwind logic. No functional change intended. Signed-off-by: Sean Christopherson --- virt/kvm/kvm_main.c | 31 ++++++++++++++++--------------- 1 file changed, 16 insertions(+), 15 deletions(-) diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index 65eb26a0520d..3c0dbe60a5b4 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -1931,21 +1931,8 @@ static int kvm_set_memslot(struct kvm *kvm, } =20 r =3D kvm_prepare_memory_region(kvm, old, new, change); - if (r) { - /* - * For DELETE/MOVE, revert the above INVALID change. No - * modifications required since the original slot was preserved - * in the inactive slots. Changing the active memslots also - * release slots_arch_lock. - */ - if (change =3D=3D KVM_MR_DELETE || change =3D=3D KVM_MR_MOVE) { - kvm_activate_memslot(kvm, invalid_slot, old); - kfree(invalid_slot); - } else { - mutex_unlock(&kvm->slots_arch_lock); - } - return r; - } + if (r) + goto err; =20 /* * For DELETE and MOVE, the working slot is now active as the INVALID @@ -1977,6 +1964,20 @@ static int kvm_set_memslot(struct kvm *kvm, kvm_commit_memory_region(kvm, old, new, change); =20 return 0; + +err: + /* + * For DELETE/MOVE, revert the above INVALID change. No modifications + * required since the original slot was preserved in the inactive slots. + * Changing the active memslots also release slots_arch_lock. + */ + if (change =3D=3D KVM_MR_DELETE || change =3D=3D KVM_MR_MOVE) { + kvm_activate_memslot(kvm, invalid_slot, old); + kfree(invalid_slot); + } else { + mutex_unlock(&kvm->slots_arch_lock); + } + return r; } =20 static bool kvm_check_memslot_overlap(struct kvm_memslots *slots, int id, --=20 2.55.0.979.g7e5102b832-goog From nobody Fri Sep 4 05:20:02 2026 Received: from mail-pf1-f197.google.com (mail-pf1-f197.google.com [209.85.210.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 90838328B75 for ; Fri, 4 Sep 2026 00:43:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482634; cv=none; b=rWX7YxOfz04A4oIxnOYOAPObQ9K5xXT2D0zPs5jzRffZYxCb7co/93lXO3XpYNiquP3eGvC+GV5Zfd7JvDkeQ2Hp3+lFxaVlbFncJHEjlADxDSdRaVXJzqlgr4MUYx/MZnLb+YuJ74cxv7/rxft47SNDZpufPPJuC7bWRbO1oCw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482634; c=relaxed/simple; bh=KqmZnMW17GKDTxrpUxX/v6jIjCcXy4jjn0p1/v764G8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=ttj2/Oi6bQQEr+15uhvWZnthhIE31Iu//Iqj9owuBfaPz8K66ZAAgG2WWjHjRfffokWPZjJ9vSdqVLwYfEuFsW3Qa/OEfidve+H0zpveedYgWLaeVybHjbWPEf0itvZptRYIxqkbZ0Bo3uZngFB+1lXx3LI5Nv128XpbKAMTxME= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=qzbYebzR; arc=none smtp.client-ip=209.85.210.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="qzbYebzR" Received: by mail-pf1-f197.google.com with SMTP id d2e1a72fcca58-85f3a39f3beso638327b3a.0 for ; Thu, 03 Sep 2026 17:43:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788482628; x=1789087428; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=wyxdAUXsugT5mSZpd8+DhZJsNmxQcD4LPrqDMHJbC/U=; b=qzbYebzRM0X7N8Ox2Q7DIldnIX8WwijE4/Q4YlZRIh240T3yKZ3/swFjSLwBkudlKG fEx8p8HUfNlSqUYcin2TB/k+AbaKEEzR6+FuwO6U0s2j2dJhRPXQXX5+ybEGvvnDHzYq HpCiYz2jEhpNnJXKKUsl1i2/QgOpGolI86NJsTa65mIyJla4yXjoPABerQLmlhl3Jurv xy5CVYOcfFUoi+mXDo9bIEw2IfbxKBNkCaTsWNthWNkyFxvuYPbSGTq8dChAO+sSNzC9 NEKIGQId7kHPbIfPT6U2Hnen3H4enCGoTxKUZuxypxZULQNNBY4+DXe89guENEjP7nA/ KRog== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788482628; x=1789087428; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=wyxdAUXsugT5mSZpd8+DhZJsNmxQcD4LPrqDMHJbC/U=; b=rfmlQ0LmmTbjBgpVhaPLq7Efi3GWEKASzH9HFLfKHuplDdBzto9Y30ze8CdO+JIwwb BIUTC/iI9w4AOvTgatJBF3UIGrIDGgxwlJhaC0EpfNbWZHHsXaKH3jQgwCELgdLEweBv DBqMavnsUeGUFwYkew+/smQHE65SpRDUsSlwjYwy/qGfS7ldEBOnpE8/nfH1jw8XBrXR y3Y0qj8SzqZetPDvn8SrVCL4SmNV1d8sQdex4EoZ+JYmfojp/OIrxBRjpFjPID5RVb+r TU6FbXxId1PXtGwosvJ/uzEqDOOuDnptm9c1geSZuflGxuYzBTFkn9RnvepNZW/S5OFR 2fcQ== X-Forwarded-Encrypted: i=1; AKwUvByZK4OsCuxFzJQU25CNopzcaiLDzEHX26j6fSmglYOhtQtdZqHJPh5MndhWkEQfmhSrzUDAuu9m63EK2tc=@vger.kernel.org X-Gm-Message-State: AFuF++nKyBK9BFfNiHZQ9nQTsW+e+5xSSjUhSt9L2TgOUpg/ANj2YiHv gDUuHPK/gJYjjey6UE6gTjdTanCWwo7jrYvdCIcsEym3+9VN3E6xLFA5MDZL/vlQfFBMObxRHpY KCSjsCg== X-Received: from pfbfo2.prod.google.com ([2002:a05:6a00:6002:b0:848:569f:3464]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4f81:b0:837:e9cc:d474 with SMTP id d2e1a72fcca58-86167aa9520mr3211481b3a.2.1788482627624; Thu, 03 Sep 2026 17:43:47 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 3 Sep 2026 17:43:41 -0700 In-Reply-To: <20260904004342.3162959-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904004342.3162959-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904004342.3162959-4-seanjc@google.com> Subject: [PATCH v3 3/4] KVM: guest_memfd: Establish memslot<=>guest_memfd bindings *after* memslot is ready From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: David Hildenbrand , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Teodorescu , Dennis Tighe , Sashiko Bot , Yan Zhao Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Wait to bind a memslot to a guest_memfd instance until *after* the memslot is fully prepared, as creating the binding in guest_memfd will effectively expose the memslot to readers. As pointed out by Sashiko, binding the memslot before it's ready to be exposed to the rest of the world can break various memslot assumption and rules. E.g. x86 could observe a NULL rmap pointer if a PUNCH_HOLE hit the guest_memfd after the binding was created, but before KVM made it through kvm_prepare_memory_region(). Begrudgingly resort to passing in the guest_memfd fd+offset pair to kvm_set_memslot(), as creating the binding really does need to happen in the middle of setting the new memslot. Alternatively, to preserve the aesthetically pleasing function prototype, "struct kvm_memory_slot" could be expanded to track the fd and the file, but that would create the possibility for TOCTOU bugs on the fd vs. file, and would add zero value beyond making kvm_set_memslot() look pretty. Fixes:a7800aa80ea4 ("KVM: Add KVM_CREATE_GUEST_MEMFD ioctl() for guest-spec= ific backing memory") Cc: stable@vger.kernel.org Reported-by: Sashiko Bot Closes: https://lore.kernel.org/all/20260826170551.BEF801F000E9@smtp.kernel= .org Signed-off-by: Sean Christopherson --- virt/kvm/kvm_main.c | 34 ++++++++++++++++++++++------------ 1 file changed, 22 insertions(+), 12 deletions(-) diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index 3c0dbe60a5b4..21c10cbbac66 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -1887,7 +1887,8 @@ static void kvm_update_flags_memslot(struct kvm *kvm, static int kvm_set_memslot(struct kvm *kvm, struct kvm_memory_slot *old, struct kvm_memory_slot *new, - enum kvm_mr_change change) + enum kvm_mr_change change, + unsigned int gmem_fd, uoff_t gmem_offset) { struct kvm_memory_slot *invalid_slot; int r; @@ -1934,6 +1935,15 @@ static int kvm_set_memslot(struct kvm *kvm, if (r) goto err; =20 + if (new && new->flags & KVM_MEM_GUEST_MEMFD) { + if (WARN_ON_ONCE(change !=3D KVM_MR_CREATE)) + goto err_bind; + + r =3D kvm_gmem_bind(kvm, new, gmem_fd, gmem_offset); + if (r) + goto err_bind; + } + /* * For DELETE and MOVE, the working slot is now active as the INVALID * version of the old slot. MOVE is particularly special as it reuses @@ -1965,6 +1975,13 @@ static int kvm_set_memslot(struct kvm *kvm, =20 return 0; =20 +err_bind: + if (new) { + kvm_arch_free_memslot(kvm, new); + + if (new->dirty_bitmap && (!old || !old->dirty_bitmap)) + kvm_destroy_dirty_bitmap(new); + } err: /* * For DELETE/MOVE, revert the above INVALID change. No modifications @@ -2059,7 +2076,7 @@ static int kvm_set_memory_region(struct kvm *kvm, if (WARN_ON_ONCE(kvm->nr_memslot_pages < old->npages)) return -EIO; =20 - return kvm_set_memslot(kvm, old, NULL, KVM_MR_DELETE); + return kvm_set_memslot(kvm, old, NULL, KVM_MR_DELETE, -1, 0); } =20 base_gfn =3D (mem->guest_phys_addr >> PAGE_SHIFT); @@ -2106,21 +2123,14 @@ static int kvm_set_memory_region(struct kvm *kvm, new->npages =3D npages; new->flags =3D mem->flags; new->userspace_addr =3D mem->userspace_addr; - if (mem->flags & KVM_MEM_GUEST_MEMFD) { - r =3D kvm_gmem_bind(kvm, new, mem->guest_memfd, mem->guest_memfd_offset); - if (r) - goto out; - } =20 - r =3D kvm_set_memslot(kvm, old, new, change); + r =3D kvm_set_memslot(kvm, old, new, change, + mem->guest_memfd, mem->guest_memfd_offset); if (r) - goto out_unbind; + goto out; =20 return 0; =20 -out_unbind: - if (mem->flags & KVM_MEM_GUEST_MEMFD) - kvm_gmem_unbind(new); out: kfree(new); return r; --=20 2.55.0.979.g7e5102b832-goog From nobody Fri Sep 4 05:20:02 2026 Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF98A154458 for ; Fri, 4 Sep 2026 00:43:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482634; cv=none; b=cf6AViVWkevgwRxM/B1CU/ay24KFimgPqilQmQiwkYmrkPNqTo2i6FoEgpNPN5ZDa1855B4O64cW6Y8HnKGBXNp6VhyhulUZx4ZNCdfE5uq+tRsRZP4sVhz03KdOYu8ToSJPL/qYaNEqGcNYY9HtKe1Jj/mxWdbqoA59CUkb+v0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788482634; c=relaxed/simple; bh=6EXt8N4NB6wdsJJax8tCW8eA4hmgUvS/E4AdZRLfLIY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=sxgNy1Rh6DsG0XcMT7iIhVSa46ppYujowKmWWHifZmUrhS62kL8/mg4wioDrbFsj8sU3qjn4Vx/9J/gIGBh43rEE00SFMwVd5Najh7BAKwxaXy+rwv0moLANkMEZia5RV0dRibSi924RyJVXqxQ+wSgnGReDaXetS+sYClDFF40= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=VsPDfhJ/; arc=none smtp.client-ip=209.85.214.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="VsPDfhJ/" Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2d6fb956002so6043905ad.1 for ; Thu, 03 Sep 2026 17:43:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788482629; x=1789087429; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=fmFU3kERqueHfMT+w5tRedl69A06EilNg6dxFGGZ7ys=; b=VsPDfhJ/SJbIod8bTMSAW68lMosWE+eZ+TBYuHESbG874P87EC5wmJK+lYdlPKzd69 oqB4Z5zGXFluVoYerNRrBS0dv/yXAT8+EnQd8iROAK7ZkAhOkLIv1schG5KsRR9v6QDm tTJnDnp5jqdddpuU0PHtMijlcKKMPIwHtn6cy6nmejieCYMtoGm/RyCU21tKW0qBZA4e 5698sINJLNaIx5VIT6HDG0g+SQT1s+ijIo6QnwIKG4L0+DUbwcleNgTrc5msoY9riBik m/cnSBS4mKflpjt6M2l5Ub7JXGzAKMBUMs+pQZnZU54yq7s9uxDvsl1NPjBJ5nBB+T0p zkZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788482629; x=1789087429; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=fmFU3kERqueHfMT+w5tRedl69A06EilNg6dxFGGZ7ys=; b=nRQkyGlgGNjS7HER4vKaZpnB8cue4yYQ2e3cXwdgrHwE7oO+DMC+qqMuDoYr4u+KDq G8dSlRIG5kSJPvJIEcs/mRx4++7/2IfTJZ9VXI3omrV6mIKxHQ9vcTPGvDCTgImqwqUy /EkHgeAGUgIUoRuc8YXBSYk0ahPN3SLbQA+y78mGhqgZFmpqqdn9noC9BhEYRLvtyXvr s6s3O2uk4fJpWSoNsa2BN9Xyhi1nW5JQdfrRb+kM7RpsfcNbfsjUn2QuVoP+i5pFeXzg pYoR7by6nNEPeiZDmphpKTi9lFmONi1qQQrv2OeiCHIeJH1eR3Ik0pM/njLnxQ3Xbf+I G3UQ== X-Forwarded-Encrypted: i=1; AKwUvBzDNK+hXZIlJyN0PUUFTLHk6ZfFerH2lhbJDjNfwJAOhmV9JVNDuT/3yqaSfVQ8FS1bYeKBWxeS4SCeOTQ=@vger.kernel.org X-Gm-Message-State: AFuF++nT86h/iu5GqosyrPyLbiwa/zdFhRzVX/tfR4IF7SSuT5o+xK1t UXIJSUpWJDpaJ5Ha0HwJXLVYOXUXLQrlLJKdNrIxD8SGGEqEx5/ffY/qY+6PJzjEd7AB+d7QsRh +qPGjLg== X-Received: from pltt21.prod.google.com ([2002:a17:902:d155:b0:2cf:afd2:6506]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:f64b:b0:2da:eccf:751d with SMTP id d9443c01a7336-2db126b5ed0mr37542275ad.22.1788482628767; Thu, 03 Sep 2026 17:43:48 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 3 Sep 2026 17:43:42 -0700 In-Reply-To: <20260904004342.3162959-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904004342.3162959-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904004342.3162959-5-seanjc@google.com> Subject: [PATCH v3 4/4] KVM: guest_memfd: Drop superfluous WRITE_ONCE() when binding a memslot From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: David Hildenbrand , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Teodorescu , Dennis Tighe , Sashiko Bot , Yan Zhao Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Drop the superfluous WRITE_ONCE() when setting a memslot's guest_memfd file during initial binding, as the memslot *must* be inactive and unreachable. The superfluous WRITE_ONCE() was added by commit 67b43038ce14 ("KVM: guest_memfd: Remove RCU-protected attribute from slot->gmem.file") to maintain rough "parity" with the existing rcu_assign_pointer(), not realizing that the only reason rcu_assign_pointer() was used was to make sparse and other checkers happy. Cc: Yan Zhao Signed-off-by: Sean Christopherson --- virt/kvm/guest_memfd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c index 0b48e9a775aa..6c8df67382fc 100644 --- a/virt/kvm/guest_memfd.c +++ b/virt/kvm/guest_memfd.c @@ -653,7 +653,7 @@ int kvm_gmem_bind(struct kvm *kvm, struct kvm_memory_sl= ot *slot, * kvm_gmem_bind() must occur on a new memslot. Because the memslot * is not visible yet, kvm_gmem_get_pfn() is guaranteed to see the file. */ - WRITE_ONCE(slot->gmem.file, file); + slot->gmem.file =3D file; slot->gmem.pgoff =3D start; if (kvm_gmem_supports_mmap(inode)) slot->flags |=3D KVM_MEMSLOT_GMEM_ONLY; --=20 2.55.0.979.g7e5102b832-goog