Re: [PATCH v6 13/14] KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory

[email protected]
Newsgroups org.kernel.vger.linux-s390,org.kernel.vger.kvm
Message-ID <[email protected]>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Unprivileged userspace can trigger a host-side WARN_ON_ONCE via KVM_BUG_ON by exhausting memory cgroup limits.
--

--- Patch [13]: [PATCH v6 13/14] KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory ---
commit c04a67c8bae206347441b13dff0d06941031c158
Author: Claudio Imbrenda <[email protected]>

KVM: s390: Fix kvm_arch_commit_memory_region() when low on memory

When low on memory, kvm_arch_commit_memory_region() might not perform
the required action completely. The patch attempts to fix this by refilling
the MMU cache and retrying, using KVM_BUG_ON if it still fails.

> diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
> index ba600c9488871..035476ec7fbc3 100644
> --- a/arch/s390/kvm/kvm-s390.c
> +++ b/arch/s390/kvm/kvm-s390.c
[ ... ]
> @@ -5862,11 +5860,17 @@ void kvm_arch_commit_memory_region(struct kvm *kvm,
>  		case KVM_MR_FLAGS_ONLY:
>  			break;
>  		default:
> +			rc = 0;
>  			WARN(1, "Unknown KVM MR CHANGE: %d\n", change);
>  		}
>  	}
> +	if (rc == -ENOMEM) {
> +		rc = kvm_s390_mmu_cache_topup(mc);
> +		if (!rc)
> +			goto retry;
> +	}
>  out:
> -	if (rc)
> +	if (KVM_BUG_ON(rc, kvm))

[Severity: High]
Could this KVM_BUG_ON() be triggered by an unprivileged host-userspace
process exhausting its memory cgroup limit?

If kvm_s390_new_mmu_cache() fails to allocate memory (for example, due to a
memcg limit restricting its GFP_KERNEL_ACCOUNT allocation), the function jumps
to the out label with rc set to -ENOMEM.

Passing this error to KVM_BUG_ON() executes a WARN_ON_ONCE. If the host has
panic_on_warn enabled, this would crash the system, potentially allowing a
host-side denial of service directly reachable from unprivileged userspace.

Is it possible to use pr_warn_once() or a similar logging mechanism here to
avoid assertions on userspace-driven inputs?

>  		pr_warn("failed to commit memory region\n");
>  	return;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=13
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.