From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C84F022FE0E for ; Fri, 7 Aug 2026 02:55:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786071350; cv=none; b=KuVnko46pRJkbpXJd3eGPjBQQV4jNpONiVfwB8oNO2s5wlH1caICfnuzSCrf70vuCney9UP1ZuClbTEzK+jlcBw3uf9NFDL934VXhd/vD+aq9kSHeammkX8dgBJk1Khqxnnx0RAOcIqY5lorXImV98H9k/ZtrDNW00vrdPLODgU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786071350; c=relaxed/simple; bh=ehfupAjiBlPbXzgN3KQshK2fO0ZqW1VYU2bmsKIMqxU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qFlV4wcwoU2kxHzuYKV0KM5xFpa839csjQQeXw4rqE95rLb0BBbCoLOW2hnsjoJyI9m5lJOTNkiFOYlgIldOPss3XHrPQ+XRwrWvYNtTHe2zfxcSgOh/HahaiGNRE9BJQ2TIUGDhfKdrz11YztvcFZbLNX3fVoNl0kihxFh73as= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XioJjH09; arc=none smtp.client-ip=209.85.210.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XioJjH09" Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-849f2f32facso419124b3a.1 for ; Thu, 06 Aug 2026 19:55:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786071348; x=1786676148; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=pIGWzVgFBhi3QS++pGVJA0SUneFjy47jOKVOvjRMiOA=; b=XioJjH09zN590ZaYVtlWpRkzwrTZpP/xG2quAqqDWWtswCc7Q8I7YpNyUM323H3U8/ QVBn/iGx58VJeGyLuVzKcKIlCIVYzbeRuml/Bs0dUH++hvbneGEWp2a4Y308mNIp0xhk GnCZauaVpgRCS+u8npq4wSdg/hK5HMFCbdOAVfwSKUGgNSxDIuutqzg6IvBSyf25foNw PJYDXv9DKiRO9xx+/i2X5tqpIdH5i1tLgt41zVULVHVWk8ao7o0CypfEorhHcKaNly5S QLUxlUU/2WpR1NDsmZq6iUwBU1oWYEUSNpnmsN5uPRU2/P31Lg/X58o1jLkRs1V4X+ab rXRA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786071348; x=1786676148; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pIGWzVgFBhi3QS++pGVJA0SUneFjy47jOKVOvjRMiOA=; b=pmVcKHeRQ97P1QjvHDYcIxYHg9AfJlPcW9CDGCkRdUwAfyB3iz8txBoOsQCTOdYnmv FzxJZnIsr08JWecYZlq/KjthMpcUf02uCgIKbobZEMKykkYL02KQka5OfVloRX+r43uh ExcWyw8Xj/i5g7T4PJX9ADFmHsPe9G2+b0Hpd4IDOyIg2zOTQbOmchCeCZ4Hp02o7PJV wSEx6FUSbbWajplBRVuSPvXr+E3JEpKOuBrhEo3+NXhRjXvZLiGbQy/wj7F8JOtR1ADv PougzWQOZHvoCiVBhvT5YcfefPgZRSirHwmQA7T98ou+mVXqNHWXr1cTxV2ghMVsir1X LaXA== X-Forwarded-Encrypted: i=1; AHgh+Ro3rfIePtC8gioOX3qDzwY38AP6lZSG35rmTjzYAmU1J+BkiuIgG5fyn55N/W6CDjprAjYISgPDkGOu8WA=@vger.kernel.org X-Gm-Message-State: AOJu0YzzI2FsqLuoBUTDpoEJCAm6mvz+IVbVynU4ILoev0YSHOvYz29W sFag+9CwOVwnmvxaQhsV/4c0J84m1CqThP8WQukN6HHipixgEaJjjCCR X-Gm-Gg: AR+sD11YQDsR7b9arhxWgZm6fcM997kz4i9UlIqMdWRnEGsW5ZTGYuLChVX1s4hUUzX FUPjs1sSC7HADckrO36/w0hYmLQxuVwswwgy7z5ksSksA1S9GOL3jbGDh0wNd55MdVYD5nP65RX Zcwdew9XhSM3FKMxQ16L+3Ac9J9gNBQCey85RHLdySJUzlOW5UxlzntWaAZtQBOGyNWjmgvxpLn d1Bb4k6NsgltI2C+nGp8OcOGSAOzJBYFaAAYberoFEkoo/GGqFadCn6PHPljvXtGPczPJCNwtCN ldMqSfmLuJL4mS2Cz6azHYput8gWtM3tdjq/w9Q7V1bgy17YiHwBy+s6YkrMngpb+YLKo8bNPtP yDxTVgt2veUIaRQGxoS5VbRVQmwUbL8iqZIG0WIdhLnodAIci0iHFQ/kXSXWfDZ2RVz3Eh4fRZm ThwHuIxC/+5MEefz+HJ1w0Zk+n2z+rm16zmUxvNwWtl3QXYHtySayLQTL7GFPI6fj6/B6w3GHoj at7jxZHgTcM+fS59vqsE7xTLpA9Z3XN990IN1cH1/eK8ZnRYlY= X-Received: by 2002:a05:6300:648f:b0:3c6:61b9:9162 with SMTP id adf61e73a8af0-3cb863e0633mr15912712637.3.1786071347910; Thu, 06 Aug 2026 19:55:47 -0700 (PDT) Received: from localhost.localdomain ([139.159.170.90]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cbe8bbfc330sm143385a12.27.2026.08.06.19.55.44 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 06 Aug 2026 19:55:47 -0700 (PDT) From: Qihang To: maz@kernel.org, oupton@kernel.org Cc: catalin.marinas@arm.com, will@kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org, Qihang , stable@vger.kernel.org Subject: [PATCH v2] KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables Date: Fri, 7 Aug 2026 10:55:34 +0800 Message-ID: <20260807025534.34125-1-q.h.hack.winter@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit vgic_v3_save_pending_tables() iterates dist->lpi_xa using xa_for_each() and dereferences the returned struct vgic_irq in the loop body without holding a reference on the LPI. The xarray iterator only provides temporary RCU coverage while looking up the current entry. That is not sufficient for this loop body, which reads fields from struct vgic_irq and performs guest memory accesses before the iteration completes. A concurrent path can trigger this race: the irqfd cached injection path (vgic_its_inject_cached_translation) obtains a transient LPI reference via vgic_its_check_cache() without holding kvm->lock, vcpu->mutex, config_lock, or its_lock. If guest ITS DISCARD then drops the cache and ITE references under its_lock, the transient inject reference may become the final one. When vgic_put_irq() drops it, the LPI is erased from lpi_xa and freed via kfree_rcu(). Meanwhile, vgic_v3_save_pending_tables() may still hold a stale pointer obtained from the xarray iterator and dereference it after the RCU grace period completes. Fix this by re-fetching each iterated LPI via vgic_get_irq(), which takes a stable reference, and dropping it with vgic_put_irq() on all paths. This matches the pattern already used by other lpi_xa iterators in the vgic ITS code. Cc: stable@vger.kernel.org Signed-off-by: Qihang --- arch/arm64/kvm/vgic/vgic-v3.c | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) v2: - Add Cc: stable@vger.kernel.org as requested by Marc Zyngier diff --git a/arch/arm64/kvm/vgic/vgic-v3.c b/arch/arm64/kvm/vgic/vgic-v3.c index 9e841e7afd4a..c3a5e2f1d09a 100644 --- a/arch/arm64/kvm/vgic/vgic-v3.c +++ b/arch/arm64/kvm/vgic/vgic-v3.c @@ -605,47 +605,53 @@ int vgic_v3_save_pending_tables(struct kvm *kvm) } xa_for_each(&dist->lpi_xa, index, irq) { int byte_offset, bit_nr; struct kvm_vcpu *vcpu; gpa_t pendbase, ptr; bool is_pending; bool stored; + irq = vgic_get_irq(kvm, index); + if (!irq) + continue; + vcpu = irq->target_vcpu; if (!vcpu) - continue; + goto put_irq; pendbase = GICR_PENDBASER_ADDRESS(vcpu->arch.vgic_cpu.pendbaser); byte_offset = irq->intid / BITS_PER_BYTE; bit_nr = irq->intid % BITS_PER_BYTE; ptr = pendbase + byte_offset; if (ptr != last_ptr) { ret = kvm_read_guest_lock(kvm, ptr, &val, 1); if (ret) - goto out; + goto put_irq; last_ptr = ptr; } stored = val & (1U << bit_nr); is_pending = irq->pending_latch; if (irq->hw && vlpi_avail) vgic_v4_get_vlpi_state(irq, &is_pending); if (stored == is_pending) - continue; + goto put_irq; if (is_pending) val |= 1 << bit_nr; else val &= ~(1 << bit_nr); ret = vgic_write_guest_lock(kvm, ptr, &val, 1); +put_irq: + vgic_put_irq(kvm, irq); if (ret) goto out; } out: -- 2.50.1 (Apple Git-155)