Re: [PATCH] KVM: x86/xen: Fix data race on poll event channel

David Woodhouse <[email protected]>
Newsgroups org.kernel.vger.kvm,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Mon, 2026-08-24 at 19:43 +0800, Chengfeng Ye wrote:
> Use READ_ONCE() and WRITE_ONCE() for runtime accesses to poll_evtchn.
> This marks the intentionally concurrent scalar accesses and prevents the
> compiler from splitting, merging, or inventing accesses.
> 
> kvm_xen_schedop_poll() publishes the single port, or -1 for multiple
> ports, before setting poll_mask and halting the vCPU.  Event delivery can
> call kvm_xen_check_poller() on another CPU while the vCPU thread publishes
> that value or resets the field to zero after returning from
> kvm_vcpu_halt():
> 
>   vCPU thread                         event delivery thread
>   -----------                         ---------------------
>   poll_evtchn = port
>   set_bit(poll_mask)
>   kvm_vcpu_halt()
>                                       poll_evtchn = READ
>   poll_evtchn = 0
>   clear_bit(poll_mask)
> 
> The plain read and writes therefore race.  KCSAN reported:
> 
>   BUG: KCSAN: data-race in kvm_xen_hypercall / kvm_xen_set_evtchn_fast
> 
>   read to 0xffff888112f55af0 of 4 bytes by task 98:
>    kvm_xen_set_evtchn_fast+0x204/0x7c0
>    kvm_xen_hvm_evtchn_send+0xab/0x100
>    kvm_arch_vm_ioctl+0xb31/0xd90
>    kvm_vm_ioctl+0xf42/0x16c0
> 
>   write to 0xffff888112f55af0 of 4 bytes by task 96:
>    kvm_xen_hypercall+0xd8d/0xf50
>    kvm_emulate_hypercall+0x157/0x1d0
>    vmx_handle_exit+0x40f/0xae0
>    vcpu_run+0x137f/0x27d0
>    kvm_arch_vcpu_ioctl_run+0x5a5/0x970
> 
> The field is an aligned int on x86.  Access annotations preserve the
> existing matching, callback, and poll-mask control flow while making the
> single-copy access requirement explicit.
> 
> Fixes: 1a65105a5aba ("KVM: x86/xen: handle PV spinlocks slowpath")
> Cc: [email protected]
> Signed-off-by: Chengfeng Ye <[email protected]>

LGTM, thanks. I don't think we need Cc:stable for a KCSAN splat, and
possibly not even the Fixes: tag. I'll roll it into my series at
https://lore.kernel.org/all/[email protected]/
now sitting at
https://git.infradead.org/?p=users/dwmw2/linux.git;a=shortlog;h=refs/heads/xen-v3
smime.p7s (application/pkcs7-signature, 6 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.