From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f74.google.com (mail-wm1-f74.google.com [209.85.128.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD15B3CEBA7 for ; Fri, 29 May 2026 12:18:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780057085; cv=none; b=OrQct4TmJM9jc989vAMSCsxzXs3eIW14d7fClk8akRdxWEhxR/c+0O8xGgkuu1bf18WIGCWLyvD9OjqE7KrTUuYi+vZmqFok6RN2eR/yuOPdo8wnYYJFNwbpp7OVnMuLRd8GHZiZi3CtGtoTygUaOmS4f25U91FfQruusDSFdi4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780057085; c=relaxed/simple; bh=8w8KTrWj55Nni7jeJZogBJiEHTgA+V61G6RhH1ALm3Q=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=CNvaYHGRxop7YMEeEV3Wppt8QS+GWsYj7ie9BYNx+oCziDQ2rE3TwId1/aBr+OXX7eKsV9jb43ztUqdJ7tgHEdxJ5nX8+2Jx8DVoqHVOnFy/5h1I9yQgJbn7SIgH+w/dPNs0p83JgB0Ur2ZhtJ8MjuGRHCjrZupPCswQhNay75Y= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tabba.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=KQHWoudN; arc=none smtp.client-ip=209.85.128.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tabba.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="KQHWoudN" Received: by mail-wm1-f74.google.com with SMTP id 5b1f17b1804b1-4903dcb32f8so68477895e9.0 for ; Fri, 29 May 2026 05:18:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1780057081; x=1780661881; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=YSXsbIdnWInVilAPlZA6JhRFyCgRtF4/KyoHf0/oPWY=; b=KQHWoudNsbS/9ibQtxhmbvayu8qzGvfehulf8Qu6yxpkTtVwfKch41ex26lUjNi2NT HQpmiS0vWQtc1gcdtOnuhK4LSc05GtUk9MqqfmmPivTHwrHA13x+hvxIzsdD7nHKnp2W xQ9g4Tl3P42kO+N89Wdr99YJl2Rfu+zh5b1OtjXh2m8KqMey3wpkfYGHa64ljOBW997E bT7QK0O56vkewXdt98cskNHMGRaphGsuZA47drBx1ZSbtJdZ8P7XPaiPpPysdY0I8IFQ n/LP4fukfr0YfpaL7JimlniD29tVkUrtarpHUquDUoJ6vYxOcIENXcVfyDXWTbjusW4T 9DZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780057081; x=1780661881; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=YSXsbIdnWInVilAPlZA6JhRFyCgRtF4/KyoHf0/oPWY=; b=Ju64BXLRiRU6/5njtgAFASp/Hn8LPf9A7eDqVodnf3Nuc/uexQEeYNda7QapvdFRKk b18qtqabMnU8e26BgyBlJ+Z87rJA5bKiF7WC3tU7w+jRIklHd3bpUyIzXVGldgwMIleM iNulL3Zq4tzllxIJ+kQGIByw+g3SRn8mM5D9BB28TULZQfQmduqA9o7TdPfJJV/83n5k MCPySlCrK1Y0DXup5sRh0r+1d2VcbUy/l5EsPMc9YQA/cuw7oXM/YiCcGUf/U2HZ8Ps5 9P/Q490ajuPW7HBsGWrjsI+zKXujYZeocRPyBAS5h5LbmwLbxBR5k30PaoaZazzvDCZN 0Q5g== X-Forwarded-Encrypted: i=1; AFNElJ/+UnATGq346uZ1Z3oKR7HkO957+C9Q4BfZm18biDC9WvPKyX6w20jrqO0IS6p7QN2ZQ106rvvruFffb3g=@vger.kernel.org X-Gm-Message-State: AOJu0Yxbh2KzJjPqk8RlSzmeFCtRm7P20KIbImAb0s01ZnAOEI2N3PMa 3Y686GJSP00oRVEk1GHrjya1ggI2W+x2VKJ39123hx7V9DCeuwsVfRGQR3DknU93Uba1eTb56W0 VuQ== X-Received: from wmqa18.prod.google.com ([2002:a05:600c:3492:b0:490:538a:ee3a]) (user=tabba job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:a00a:b0:490:9d5c:a3e0 with SMTP id 5b1f17b1804b1-4909d5ca570mr41853905e9.9.1780057080700; Fri, 29 May 2026 05:18:00 -0700 (PDT) Date: Fri, 29 May 2026 13:17:55 +0100 In-Reply-To: <20260529121755.2923500-1-tabba@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260529121755.2923500-1-tabba@google.com> X-Mailer: git-send-email 2.54.0.929.g9b7fa37559-goog Message-ID: <20260529121755.2923500-4-tabba@google.com> Subject: [PATCH v2 3/3] KVM: arm64: Roll back partial shares on kvm_share_hyp() failure From: tabba@google.com To: Marc Zyngier , Oliver Upton , Joey Gouly , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , Quentin Perret , Vincent Donnefort Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" kvm_share_hyp() shares a range one page at a time. If share_pfn_hyp() fails partway through, the pages already shared by this call are left shared, while the caller treats the whole range as failed and never unshares them. Unshare those pages before returning the error. If an unshare itself fails the page is leaked: it stays shared with the hypervisor and is no longer reusable for pKVM, but no isolation guarantee is broken, so WARN and continue. Not expected in practice. Fixes: a83e2191b7f1 ("KVM: arm64: pkvm: Refcount the pages shared with EL2") Suggested-by: Vincent Donnefort Signed-off-by: Fuad Tabba --- arch/arm64/kvm/mmu.c | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c index e08503e89fc4..8811ad60cf72 100644 --- a/arch/arm64/kvm/mmu.c +++ b/arch/arm64/kvm/mmu.c @@ -544,8 +544,8 @@ static int unshare_pfn_hyp(u64 pfn) int kvm_share_hyp(void *from, void *to) { phys_addr_t start, end, cur; + int ret = 0; u64 pfn; - int ret; if (is_kernel_in_hyp_mode()) return 0; @@ -567,10 +567,24 @@ int kvm_share_hyp(void *from, void *to) pfn = __phys_to_pfn(cur); ret = share_pfn_hyp(pfn); if (ret) - return ret; + break; } - return 0; + if (!ret) + return 0; + + /* + * Roll back the pages shared by this call. A failed unshare leaks + * the page (it stays shared with the hypervisor and is no longer + * reusable for pKVM) but breaks no isolation guarantee, so warn and + * continue. Not expected in practice. + */ + for (end = cur, cur = start; cur < end; cur += PAGE_SIZE) { + pfn = __phys_to_pfn(cur); + WARN_ON(unshare_pfn_hyp(pfn)); + } + + return ret; } void kvm_unshare_hyp(void *from, void *to) -- 2.54.0.929.g9b7fa37559-goog