From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f73.google.com (mail-wm1-f73.google.com [209.85.128.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F2CC23328E6 for ; Fri, 29 May 2026 07:43:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.73 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780040626; cv=none; b=t4qB1akmqc06UlD9lnALvavPxUY2RyQHSENrio/Lo47Uv+mw7liDq8EhXH6m3r9WrofPRujkIlqqEKE03NxrnMt4k3qEc/XWlgwVfUbH47ZUIwNsZoLg97cQp9INb0UUS67m45DjdiX6mMrzvVbKwmuzjxRzbmy7mjcHhgq7JPI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780040626; c=relaxed/simple; bh=AQc5VySXy8q2Bk6xN/PY4/4Xyl5t9boY6mhk63Pe8VQ=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=fbsmbrYSriG/lQw5N8pgLTfQxa+Mle1MZhCXvTzJqLhKoHuarOKcfGLCvD7bYhpiar5yao/etOnVT1R0SWKbxmmOtOq432MMZepBpCi3Pexq8qO2s3LSKURAHEFZs6ygGrzDw4BcyFwSFCfXn1cr9o1N3WjLJA9iNdzu+osWtBE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tabba.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=C9A6WrZO; arc=none smtp.client-ip=209.85.128.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tabba.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="C9A6WrZO" Received: by mail-wm1-f73.google.com with SMTP id 5b1f17b1804b1-49045243094so97198475e9.2 for ; Fri, 29 May 2026 00:43:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1780040622; x=1780645422; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=QroFkfsIzFdk7bYeD2yDP4/NwbzDZKM8O5SP6AVtn2s=; b=C9A6WrZO4kmFWJROHuu2NEVCP6ipQ/UW3Hj89zWCqyoQPqzM1y/4fyrODd+zu81IOY wGDVeE8guNWyyCBrLcRb1PFXmiwIZvnVXL1VD10z7CjVVVOwWvrHnj7Y8lMgwUpC7oZY WniYLVUwmaqoplkrQfsPYddi3ZM450S+dVo+PInPnLTb8AbiOkKokghZJKjXVZGNG+mA BNOAs5jREBo1iqlNprOcR4J///R3RGVx+IBVE/hWfCEsVXsi9hc96nkKgJY0hf5Go7r7 mUAnxyQ6Zv/bTpVcRK690UzbsfOJMrhKIhtYQGxCMGlycipYUH4T+A53td9qIObos1OW P0/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780040622; x=1780645422; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=QroFkfsIzFdk7bYeD2yDP4/NwbzDZKM8O5SP6AVtn2s=; b=gYWkXF+wf8L+oM3Jec73nExZ+qUD8BHu0fgMbxuFu45wNfjz163U5lKegMNqDobGFg wpQAqn5m1hXuQ5C5NBD6cg29ni9DGdREbs3J60+0UDOweGAXzqVkdrB5Ow1bD+EFCpEa DelpvOLwaOFZtPoh8ymYuWkMfA8WgbGBnqwDsAJAWK9eOjIeC6rjM9XsBoKownGrWcg7 5b8yPv5ik7fccEydR2qokyMyElQF9sYPA1SoBkw5JkxEcLimZ6c0CwvWbUxYipGaWdM+ vIAyyXImQNN5IoN/PEAHqJmT1sd25HoK8HpfP7SfDOzrByGk9Q/ymiWi/AhdiwBox/oN E8rA== X-Forwarded-Encrypted: i=1; AFNElJ9LdgfzkfiEqLAyL5Fv+CyVK6sFrktWYjmY+qu373VNL920cBwrRtER80NYImaxGFN24Ms26FvEn3U6pjk=@vger.kernel.org X-Gm-Message-State: AOJu0Yy0jW7ZzwKcZFbJTjYSK9CJNQqAUl72cJlU81oL+WcBAL5ghmPJ eCAZOE5Kb05YUJW/8fIUW/tCgwyPQ/tr8UrvFGe/7gP0QdzBIJaQ6Kfi5qynjGS8AtE94fMfti7 Zag== X-Received: from wmco20.prod.google.com ([2002:a05:600c:a314:b0:48a:5531:d9cb]) (user=tabba job=prod-delivery.src-stubby-dispatcher) by 2002:a7b:cc1a:0:b0:490:845c:a1ea with SMTP id 5b1f17b1804b1-4909c0b0c32mr22550225e9.21.1780040622146; Fri, 29 May 2026 00:43:42 -0700 (PDT) Date: Fri, 29 May 2026 08:43:39 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.54.0.929.g9b7fa37559-goog Message-ID: <20260529074341.2271950-1-tabba@google.com> Subject: [PATCH 0/2] KVM: arm64: Fix host/hyp tracking on share/unshare hypercall failure From: tabba@google.com To: Marc Zyngier , Oliver Upton , Joey Gouly , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , Quentin Perret , Vincent Donnefort Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Hi folks, Yet another bug I found while testing Sashiko locally with fixes to review-prompts. share_pfn_hyp() and unshare_pfn_hyp() in arch/arm64/kvm/mmu.c maintain a host-side RB-tree mirroring the set of pages shared with EL2. Both invoke a hypercall that can fail (page-state mismatch, EL2 refcount still held), but neither cleans up on failure: - share_pfn_hyp() inserts the tracking node before the hypercall and leaves it in the tree on failure, leaking the allocation and presenting a phantom share to a later unshare. - unshare_pfn_hyp() erases the tracking node before the hypercall; on failure the host loses its record while EL2 still owns the share, breaking later operations on the same pfn. Severity is low (no isolation impact) and the failure paths are rare in practice, but the desync is real. Both patches are independent and apply cleanly to current mainline. In other words, this can wait for 7.2. Cheers, /fuad Fuad Tabba (2): KVM: arm64: Free hyp-share tracking node when share hypercall fails KVM: arm64: Avoid host/hyp share desync on unshare hypercall failure arch/arm64/kvm/mmu.c | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) -- 2.54.0.929.g9b7fa37559-goog