[PATCH v7 0/6] s390/vfio-ap: Fix pre-existing bugs in vfio_ap device driver

Anthony Krowiak posted 6 patches 3 weeks ago
There is a newer version of this series
drivers/s390/crypto/vfio_ap_ops.c | 539 ++++++++++++++++++++++++------
1 file changed, 441 insertions(+), 98 deletions(-)
[PATCH v7 0/6] s390/vfio-ap: Fix pre-existing bugs in vfio_ap device driver
Posted by Anthony Krowiak 3 weeks ago
The sashiko AI reported several pre-existing bugs in the vfio_ap device
driver code while reviewing unrelated patches. This series fixes four
such bugs.

Change log v6 => v7:
~~~~~~~~~~~~~~~~~~~
Patch: s390/vfio-ap: fix queue state leakage to guest and host

  apq_reset_check()
  - Fixed missing closing brace on -EIO early-return block that
    made the AP_RESET_MAX_WAIT timeout check unreachable.
  - Introduced apq_reset_finalize() helper to copy the final
    TAPQ status word to q->reset_status and set
    q->reset_status.response_code to AP_RESPONSE_NORMAL only
    when zeroization is confirmed (ret == 0). Replaces the
    done: label and goto.
  - Both pre-timeout and within-timeout completion paths now
    call apq_reset_finalize() directly.

  apq_status_check()
  - Signature changed from (int apqn, ...) to
    (struct vfio_ap_queue *q, ...) to support ratelimited
    warning reporting.

  vfio_ap_mdev_remove_queue()
  - Removed post-lock fallback unbounded reset block that had
    a use-after-free risk on q->matrix_mdev after
    release_update_locks_for_mdev().

Patch: s390/vfio-ap: replace guest-reachable WARNs with
       ratelimited warnings and add dmesg visibility to DBF_WARNs
       
This is a new patch created in response to review comments of the
v6 series.

  vfio_ap_wait_for_irqclear()
  - Signature changed from (int apqn) to
    (struct vfio_ap_queue *q).
  - Replaced WARN_ONCE calls with report_tapq_rc() and
    report_irqclear_timeout().

  vfio_ap_irq_disable()
  - Replaced three WARN_ONCE calls with
    report_aqic_disable_error().
  - Added AP_RESPONSE_STATE_CHANGE_IN_PROGRESS to retry case.
  - Added AP_RESPONSE_INVALID_GISA,
    AP_RESPONSE_ASSOC_SECRET_NOT_UNIQUE and
    AP_RESPONSE_ASSOC_FAILED as explicit end_fail cases.

  vfio_ap_irq_enable()
  - Added dev_warn_ratelimited() alongside each
    VFIO_AP_DBF_WARN() call for dmesg visibility.

  handle_pqap()
  - Added pr_warn_ratelimited() for AIV facility not installed
    and hook not registered cases.
  - Added dev_warn_ratelimited() for mdev not in use and queue
    not bound cases.

  apq_status_check()
  - Replaced WARN with report_tapq_rc().

  vfio_ap_mdev_reset_queue()
  - Replaced WARN with report_zapq_rc().
  - Removed AP_RESPONSE_BUSY from async-reset case (not a
    valid ZAPQ response code).

  New functions introduced:
  - apq_reset_finalize()
  - report_tapq_rc()
  - report_irqclear_timeout()
  - report_aqic_disable_error()
  - report_zapq_rc()
  
Anthony Krowiak (6):
  s390/vfio-ap: Fix leaks of pinned NIB and registered GISC
  s390/vfio-ap: Fix failure to release IRQ notification eventfd contexts
  s390/vfio-ap: Fix unbounded loop in apq_reset_check()
  s390/vfio-ap: Use AP_DOMAINS for adm_add bitmap size in
    vfio_ap_mdev_cfg_add()
  s390/vfio-ap: fix queue state leakage to guest and host
  s390/vfio-ap: replace guest-reachable WARNs with ratelimited          
        warnings and add dmesg visibility to DBF_WARNs

 drivers/s390/crypto/vfio_ap_ops.c | 539 ++++++++++++++++++++++++------
 1 file changed, 441 insertions(+), 98 deletions(-)

-- 
2.53.0