From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f74.google.com (mail-wm1-f74.google.com [209.85.128.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 804913E0240 for ; Fri, 29 May 2026 12:18:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780057085; cv=none; b=VotG0j+HzEvAzfyHINBCSD+MGci/igs/wYyRVPTBPfJXqbYHR8DOKgq4JZHU7qfd7vDMVkqyYOwHQRvZCE0UdksZfDFboFqo+kj4Y1WYOc8HoNlmLeBlFSS3wD/d4v9EyiYU8BX8YLzPi1qVEyxO1mJ4dtPFXghNnKATeioYrh0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780057085; c=relaxed/simple; bh=XKVmY0P3IzoFeX03y+LKtJHuMV/YCFLbyf+QtduVf8E=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=SfZxMqMxf6MNTRiV5p9/fPFHIyXP74jIImA9MGyG9d23sohow3nJcoHOF7MlDB2gzhU80YCuN/qzCwyJsTf0N9Mx4lxD0alS0LYjNbPW4piV23AsfEQzxECcXew+IEaWwDFeeX9WFwSiKMRQwGrl9Q20OtsdNLemn9JeamSNutc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tabba.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=rTdXcFku; arc=none smtp.client-ip=209.85.128.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tabba.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="rTdXcFku" Received: by mail-wm1-f74.google.com with SMTP id 5b1f17b1804b1-4903dcb32f8so68477785e9.0 for ; Fri, 29 May 2026 05:18:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1780057080; x=1780661880; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=P7DIYy/NA1CowFMUedyn+8E7FgwfAdykU+tJsf37FuI=; b=rTdXcFku4BM08H2y/95LwSqYd3ru2eN2WPJrCXVmgx1etZ3T+YKLJfINr8Ve8TFBpL VLMSsw+jdXlKltoz1sijpXkq6vs7byWlG308mQfwhW0XGcx9Uy4Y4lr+pgQA5xzMemd9 BooS6mZ/3YsmL/QQBiPsUz7ocFUiak2KoTcAVFDne5RqNZT71u1xULhKL6+DlgYNyVu1 fJTs1Vj7JYf2TfJdnwmz8wLqJ1AlNJSOiHcavC4hoO36FNY3Gqxff5pON1C/JfIIszy9 p7oqMnLBWe869Sxx/wDt1ynee7yUxEmBuF9uvCMpCzrK5IuG2XgFE2b3aKKW80xfVyH7 PBmA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780057080; x=1780661880; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=P7DIYy/NA1CowFMUedyn+8E7FgwfAdykU+tJsf37FuI=; b=lK7t8Et0fL1wWZ+xU1jLQxFzIciIAFtfymvJeqms8l7H/W+ZiJHS6WPmNT/PeVX8TG nmcmfJZ/E394/Vl4xbH1KvDI2WqxLa3N/lmnaErMZmTQfr7JulQnn/yinVF6Af/XRe9G 3hXCYxEiocRaPqnaB5OY74HXGzcwAUB2rp09/fv1ZZlgrlInqNSU3KU8djnGjWZ2rhTM ALFyNMtwZ5m2JXx1L2S4qOhNfL63IzMgmdLNlAfmqUtkOdrTzcqmkmZkrqAQUiXQtgz9 1Wcia0M4tFlitR7UqDQPNq1g/Le7AzroEtWhWj4DfgsKMmOdLUhbPohqUvvHZOeG36sP yKOQ== X-Forwarded-Encrypted: i=1; AFNElJ981udFqVVQI0ulNZhz4MFM9h6epSku6nZEeWCh4Jkk48Fg+rAfpg6Zm9+OU02VdI1Zc7afZx8xd1MdJhI=@vger.kernel.org X-Gm-Message-State: AOJu0YxdWg0DMu1iMM83gLpvr0igMoaGNtrMIo3SftsFOeZX2zkehRTd gM2hlil0ntdV0aH6Yle0xXJUEJYyTTje1tSFiSrXwiyyo9CU+Vk1Xf2KJDm1C8EmswaxYBkoNLU jtA== X-Received: from wmjt12.prod.google.com ([2002:a7b:c3cc:0:b0:490:3974:b74f]) (user=tabba job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:1d09:b0:490:a1a6:6f24 with SMTP id 5b1f17b1804b1-490a1a67021mr16515805e9.15.1780057079441; Fri, 29 May 2026 05:17:59 -0700 (PDT) Date: Fri, 29 May 2026 13:17:54 +0100 In-Reply-To: <20260529121755.2923500-1-tabba@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260529121755.2923500-1-tabba@google.com> X-Mailer: git-send-email 2.54.0.929.g9b7fa37559-goog Message-ID: <20260529121755.2923500-3-tabba@google.com> Subject: [PATCH v2 2/3] KVM: arm64: Avoid host/hyp share desync on unshare hypercall failure From: tabba@google.com To: Marc Zyngier , Oliver Upton , Joey Gouly , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , Quentin Perret , Vincent Donnefort Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" unshare_pfn_hyp() erases the tracking node from hyp_shared_pfns and frees it before invoking __pkvm_host_unshare_hyp. If the hypercall fails (e.g. EL2 refcount still held, or page-state mismatch), the host loses its record while EL2 still holds the share, breaking later share/unshare attempts on the same pfn. Invoke the hypercall first; erase and free only on success. Document at the kvm_unshare_hyp() call site that the WARN_ON() is left non-fatal: a failed unshare leaks the page (it stays shared with the hypervisor) but breaks no isolation guarantee. Fixes: 52b28657ebd7 ("KVM: arm64: pkvm: Unshare guest structs during teardown") Reported-by: Sashiko (local):gemini-3.1-pro Suggested-by: Vincent Donnefort Signed-off-by: Fuad Tabba --- arch/arm64/kvm/mmu.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c index 4a928fb003ff..e08503e89fc4 100644 --- a/arch/arm64/kvm/mmu.c +++ b/arch/arm64/kvm/mmu.c @@ -524,13 +524,17 @@ static int unshare_pfn_hyp(u64 pfn) goto unlock; } - this->count--; - if (this->count) + if (this->count > 1) { + this->count--; + goto unlock; + } + + ret = kvm_call_hyp_nvhe(__pkvm_host_unshare_hyp, pfn); + if (ret) goto unlock; rb_erase(&this->node, &hyp_shared_pfns); kfree(this); - ret = kvm_call_hyp_nvhe(__pkvm_host_unshare_hyp, pfn); unlock: mutex_unlock(&hyp_shared_pfns_lock); @@ -581,6 +585,11 @@ void kvm_unshare_hyp(void *from, void *to) end = PAGE_ALIGN(__pa(to)); for (cur = start; cur < end; cur += PAGE_SIZE) { pfn = __phys_to_pfn(cur); + /* + * A failed unshare leaks the page: it stays shared with the + * hypervisor and is no longer reusable for pKVM. No isolation + * guarantee is broken, and this is not expected in practice. + */ WARN_ON(unshare_pfn_hyp(pfn)); } } -- 2.54.0.929.g9b7fa37559-goog