From nobody Thu Sep 24 13:39:04 2026 Received: from va-2-35.ptr.blmpb.com (va-2-35.ptr.blmpb.com [209.127.231.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5C09144A40E for ; Wed, 23 Sep 2026 08:56:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.231.35 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790153823; cv=none; b=Zc6i3LVqczYo3MVI6exAtYQQHQmkzBBGPhlRVsIklxRmZSVxxKl+nL9OxPmwOOPeTiMpBXeL9oeATY3iPFaMv5c+uiDbdz6I0qE1+t9vqOe4BOgVIJo9TxgPe7tDb3Wa1A8TrMLXd5gOh7KYIsU77ZohWxahdC14E+ppx4uL81o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790153823; c=relaxed/simple; bh=yWMfnkEkfopRl7feST97mKplecVHptL+oDmvUWqqfoI=; h=Cc:From:Date:Mime-Version:Subject:Message-Id:Content-Type:To; b=egGu49RqiCFUNXOYOsf908e9WZYBO0c8c85VOswV+PR6+Rco/O2pgV5ZmbJTKzQnSzZfFE8nw+RjSokPAZSsSo49w8DcwnDvNQCRjE0ZiqO5BXZ0Ce3TLEs1pYiyjXUQlFS/rUOX82ZUrgTymNeMX9pNZ83J7kjrrKoM2keHjeQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=lanxincomputing.com; spf=pass smtp.mailfrom=lanxincomputing.com; dkim=pass (2048-bit key) header.d=lanxincomputing-com.20200927.dkim.feishu.cn header.i=@lanxincomputing-com.20200927.dkim.feishu.cn header.b=U1lhT1cQ; arc=none smtp.client-ip=209.127.231.35 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=lanxincomputing.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=lanxincomputing.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=lanxincomputing-com.20200927.dkim.feishu.cn header.i=@lanxincomputing-com.20200927.dkim.feishu.cn header.b="U1lhT1cQ" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=s1; d=lanxincomputing-com.20200927.dkim.feishu.cn; t=1790153815; h=from:subject:mime-version:from:date:message-id:subject:to:cc: reply-to:content-type:mime-version:in-reply-to:message-id; bh=RjYsFA+LmVEfysjLvCalbDJ75mUBdBuLNBKFMkkYENE=; b=U1lhT1cQUMbf/1D1Hym24eK+0N7ZdaWruSnoniAi/+M+KHmSWDH+zbGp+srry/TapNArrk tHi+ZS6O09hFagSrxgzKzfFq5BmPiDqzc3mMycyYowRyhm8sQw2N5QHSB6gNMbE+SgnGp9 csnCA2JbSz+EAKHiu6fEwqrLmmOm5OvUw2UCYYTBPNVxaPD+IdLGlHriUvUMP3vWu2UF/n rTlmbgZBNbt8boKRsNd83mHb/aHFeTpz7/ur3x8qGYE7xbG1MtFymYCnjwyJ+A7U/3m+Fw zoUTwBLvgd9E6Vc2LAXDYdYm2/A2aClLCqflsDIry5+LJZB3Cn+m28609Cra3g== Cc: , , , , , , , , , , , , From: "BillXiang" Date: Wed, 23 Sep 2026 16:56:31 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Received: from lanxin-ThinkBook-16-G5-IRH ([123.120.5.129]) by smtp.feishu.cn with ESMTP; Wed, 23 Sep 2026 16:56:52 +0800 Subject: [PATCH v2] RISC-V: KVM: Serialize and atomize the IMSIC's TOPEI read-and-clear operation Message-Id: <20260923085631.1384021-1-xiangwencheng@lanxincomputing.com> Content-Transfer-Encoding: quoted-printable To: X-Mailer: git-send-email 2.53.0 X-Lms-Return-Path: X-Original-From: BillXiang Content-Type: text/plain; charset="utf-8" The TOPEI read-and-clear must be atomic with respect to interrupt injection (set_bit in EIP). Otherwise an interrupt injected between the topei read and the clear_bit could be silently dropped. v2: - fix patch file curruption v1: https://lore.kernel.org/kvm-riscv/20260923070332.1376132-1-xiangwenchen= g@lanxincomputing.com/ Signed-off-by: BillXiang --- arch/riscv/kvm/aia_imsic.c | 42 +++++++++++++++++++++++++------------- 1 file changed, 28 insertions(+), 14 deletions(-) diff --git a/arch/riscv/kvm/aia_imsic.c b/arch/riscv/kvm/aia_imsic.c index c1af23e79ae0..490c55419eb2 100644 --- a/arch/riscv/kvm/aia_imsic.c +++ b/arch/riscv/kvm/aia_imsic.c @@ -607,26 +607,25 @@ static void imsic_vsfile_cleanup(struct imsic *imsic) kvm_riscv_aia_free_hgei(old_vsfile_cpu, old_vsfile_hgei); } =20 -static void imsic_swfile_extirq_update(struct kvm_vcpu *vcpu) +static void __imsic_swfile_extirq_update(struct kvm_vcpu *vcpu) { struct imsic *imsic =3D vcpu->arch.aia_context.imsic_state; struct imsic_mrif *mrif =3D imsic->swfile; - unsigned long flags; - - /* - * The critical section is necessary during external interrupt - * updates to avoid the risk of losing interrupts due to potential - * interruptions between reading topei and updating pending status. - */ - - raw_spin_lock_irqsave(&imsic->swfile_extirq_lock, flags); =20 if (imsic_mrif_atomic_read(mrif, &mrif->eidelivery) && imsic_mrif_topei(mrif, imsic->nr_eix, imsic->nr_msis)) kvm_riscv_vcpu_set_interrupt(vcpu, IRQ_VS_EXT); else kvm_riscv_vcpu_unset_interrupt(vcpu, IRQ_VS_EXT); +} + +static void imsic_swfile_extirq_update(struct kvm_vcpu *vcpu) +{ + struct imsic *imsic =3D vcpu->arch.aia_context.imsic_state; + unsigned long flags; =20 + raw_spin_lock_irqsave(&imsic->swfile_extirq_lock, flags); + __imsic_swfile_extirq_update(vcpu); raw_spin_unlock_irqrestore(&imsic->swfile_extirq_lock, flags); } =20 @@ -912,12 +911,15 @@ int kvm_riscv_vcpu_aia_imsic_rmw(struct kvm_vcpu *vcp= u, unsigned long isel, struct imsic_mrif_eix *eix; int r, rc =3D KVM_INSN_CONTINUE_NEXT_SEPC; struct imsic *imsic =3D vcpu->arch.aia_context.imsic_state; + unsigned long flags; =20 /* If IMSIC vCPU state not initialized then forward to user space */ if (!imsic) return KVM_INSN_EXIT_TO_USER_SPACE; =20 if (isel =3D=3D KVM_RISCV_AIA_IMSIC_TOPEI) { + raw_spin_lock_irqsave(&imsic->swfile_extirq_lock, flags); + /* Read pending and enabled interrupt with highest priority */ topei =3D imsic_mrif_topei(imsic->swfile, imsic->nr_eix, imsic->nr_msis); @@ -934,16 +936,20 @@ int kvm_riscv_vcpu_aia_imsic_rmw(struct kvm_vcpu *vcp= u, unsigned long isel, eix->eip); } } + if (wr_mask) + __imsic_swfile_extirq_update(vcpu); + + raw_spin_unlock_irqrestore(&imsic->swfile_extirq_lock, eflags); } else { r =3D imsic_mrif_rmw(imsic->swfile, imsic->nr_eix, isel, val, new_val, wr_mask); /* Forward unknown IMSIC register to user-space */ if (r) rc =3D (r =3D=3D -ENOENT) ? 0 : KVM_INSN_ILLEGAL_TRAP; - } =20 - if (wr_mask) - imsic_swfile_extirq_update(vcpu); + if (wr_mask) + imsic_swfile_extirq_update(vcpu); + } =20 return rc; } @@ -1050,9 +1056,17 @@ int kvm_riscv_vcpu_aia_imsic_inject(struct kvm_vcpu = *vcpu, if (imsic->vsfile_cpu >=3D 0) { writel(iid, imsic->vsfile_va + IMSIC_MMIO_SETIPNUM_LE); } else { + /* + * Serialize the EIP set + external-irq update against the + * TOPEI read-and-clear path so that an injected interrupt + * cannot be silently lost when the guest acknowledges a + * different (or the same) interrupt concurrently. + */ + raw_spin_lock(&imsic->swfile_extirq_lock); eix =3D &imsic->swfile->eix[iid / BITS_PER_TYPE(u64)]; set_bit(iid & (BITS_PER_TYPE(u64) - 1), eix->eip); - imsic_swfile_extirq_update(vcpu); + __imsic_swfile_extirq_update(vcpu); + raw_spin_unlock(&imsic->swfile_extirq_lock); } =20 read_unlock_irqrestore(&imsic->vsfile_lock, flags); --=20 2.53.0