mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "David Woodhouse" <dwmw2@infradead.org>
Cc: linux-rt-devel@lists.linux.dev, kvm@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH 08/17] KVM: pfncache: Return -EAGAIN for a lookup which hits an invalid memslot
Date: Sun, 20 Sep 2026 21:53:40 +0000	[thread overview]
Message-ID: <20260920215341.5ECE91F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920211920.928306-9-dwmw2@infradead.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] kvm: ABBA deadlock in kvm_xen_set_evtchn() against memslot updates
--

commit d08948c3f01d34b213b2379e1b128830ccb5f086
Author: David Woodhouse <dwmw@amazon.co.uk>

KVM: pfncache: Return -EAGAIN for a lookup which hits an invalid memslot

This commit modifies the pfncache lookup to return -EAGAIN when a memslot
is marked KVM_MEMSLOT_INVALID. It also updates kvm_xen_set_evtchn() to
indefinitely retry the refresh on -EAGAIN instead of failing.

> diff --git a/arch/x86/kvm/xen.c b/arch/x86/kvm/xen.c
> index b6643b889320d..0b49eb67d06c0 100644
> --- a/arch/x86/kvm/xen.c
> +++ b/arch/x86/kvm/xen.c
> @@ -2026,7 +2026,17 @@ static int kvm_xen_set_evtchn(struct kvm_xen_evtchn *xe, struct kvm *kvm)
>  		idx = srcu_read_lock(&kvm->srcu);
>  		rc = kvm_gpc_refresh(gpc, PAGE_SIZE);
>  		srcu_read_unlock(&kvm->srcu, idx);
> -	} while(!rc);
> +
> +		/*
> +		 * A refresh which raced with a concurrent memslot update
> +		 * (-EAGAIN: the slot exists but is mid-DELETE/MOVE) will
> +		 * succeed once the update completes or reverts; giving up
> +		 * instead would drop the event. Only a genuinely unbacked
> +		 * gfn (-EFAULT etc.) is fatal.
> +		 */
> +		if (rc == -EAGAIN)
> +			cond_resched();
> +	} while (!rc || rc == -EAGAIN);

[Severity: High]
Does this create an ABBA deadlock against memslot updates when called from
the vcpu_run() path?

A guest VM issuing an EVTCHNOP_send hypercall operates inside vcpu_run(),
which holds the outer kvm->srcu read lock. If this races with a VMM memslot
update (e.g., KVM_SET_USER_MEMORY_REGION), kvm_xen_set_evtchn() will encounter
-EAGAIN and loop here waiting for the update to complete.

However, cond_resched() does not drop the outer kvm->srcu lock. The thread
performing the memslot update is blocked in synchronize_srcu(&kvm->srcu)
waiting for all existing readers (including this vCPU thread) to drop their
locks.

This results in an unbreakable deadlock where the vCPU thread waits for the
memslot update, while the update waits for the vCPU thread to drop kvm->srcu.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260920211920.928306-1-dwmw2@infradead.org?part=8

  reply	other threads:[~2026-09-20 21:53 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-20 20:49 [PATCH 00/17] KVM: Use atomic SRCU for gfn-to-pfn cache, reinstate guest mode for x86 nesting David Woodhouse
2026-09-20 20:49 ` [PATCH 01/17] KVM: pfncache: Use atomic SRCU for readers instead of a rwlock David Woodhouse
2026-09-20 21:55   ` sashiko-bot
2026-09-21  1:42   ` Hillf Danton
2026-09-21  9:54     ` David Woodhouse
2026-09-21 11:21       ` Hillf Danton
2026-09-21 11:29         ` Paolo Bonzini
2026-09-20 20:49 ` [PATCH 02/17] KVM: x86/xen: Extract delivery of event to vCPU into a separate helper David Woodhouse
2026-09-20 20:49 ` [PATCH 03/17] KVM: x86/xen: Explicitly tag "shared info" page as never being dirty tracked David Woodhouse
2026-09-20 20:49 ` [PATCH 04/17] KVM: x86/xen: Don't dirty track "vCPU info" page David Woodhouse
2026-09-20 20:49 ` [PATCH 05/17] KVM: x86: Request the guest TLB flush from record_steal_time() David Woodhouse
2026-09-20 20:49 ` [PATCH 06/17] KVM: x86: Use gfn_to_pfn_cache for steal time / preempted status David Woodhouse
2026-09-20 22:06   ` sashiko-bot
2026-09-20 20:49 ` [PATCH 07/17] KVM: pfncache: Add guest-mode pinning (GUEST_USES_PFN successor) David Woodhouse
2026-09-20 21:53   ` sashiko-bot
2026-09-21 14:17     ` David Woodhouse
2026-09-20 20:49 ` [PATCH 08/17] KVM: pfncache: Return -EAGAIN for a lookup which hits an invalid memslot David Woodhouse
2026-09-20 21:53   ` sashiko-bot [this message]
2026-09-20 20:49 ` [PATCH 09/17] KVM: x86: Post KVM_REQ_GET_NESTED_STATE_PAGES on memslot updates David Woodhouse
2026-09-20 20:49 ` [PATCH 10/17] KVM: nVMX: Implement cache for L1 MSR bitmap David Woodhouse
2026-09-20 21:56   ` sashiko-bot
2026-09-20 20:49 ` [PATCH 11/17] KVM: nVMX: Use pinned pfncache for L1 APIC virtualization pages David Woodhouse
2026-09-20 21:57   ` sashiko-bot
2026-09-21 14:31     ` David Woodhouse
2026-09-20 20:49 ` [PATCH 12/17] KVM: selftests: Add nested VMX APIC cache invalidation test David Woodhouse
2026-09-20 21:51   ` sashiko-bot
2026-09-20 20:49 ` [PATCH 13/17] KVM: x86: Move nested GPC lock helpers to x86.h as kvm_gpc_lock_page() David Woodhouse
2026-09-20 20:49 ` [PATCH 14/17] KVM: nSVM: Use a gfn_to_pfn_cache for the vmcb12 page David Woodhouse
2026-09-20 20:49 ` [PATCH 15/17] KVM: nSVM: Cache L1's MSR permissions map pages David Woodhouse
2026-09-20 20:49 ` [PATCH 16/17] KVM: nSVM: Cache L1's IO " David Woodhouse
2026-09-20 20:49 ` [PATCH 17/17] KVM: selftests: Add nested transition benchmark David Woodhouse
2026-09-20 21:52   ` sashiko-bot
2026-09-21 14:10 ` [PATCH 00/17] KVM: Use atomic SRCU for gfn-to-pfn cache, reinstate guest mode for x86 nesting David Woodhouse
2026-09-22  3:16 ` KunWu Chan
2026-09-22 10:37   ` David Woodhouse
2026-09-23  9:54     ` Kunwu Chan
2026-09-23 12:05       ` David Woodhouse
2026-09-23 15:58         ` KunWu Chan
2026-09-23 16:07           ` David Woodhouse
2026-09-23 16:26             ` KunWu Chan
2026-09-23 16:46               ` David Woodhouse
2026-09-24  1:04                 ` KunWu Chan
2026-09-23 21:56               ` David Woodhouse
2026-09-24  0:59                 ` KunWu Chan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260920215341.5ECE91F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dwmw2@infradead.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rt-devel@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®