Re: FAILED: patch "[PATCH] KVM: s390: pci: Fix memory accounting for pinned/unpinned" failed to apply to 6.12-stable tree

Farhan Ali <[email protected]>
Newsgroups org.kernel.vger.stable
Message-ID <[email protected]>
Hi Greg,

This patch has a dependency on the following commit from Linus's tree:

5618c53d96d1 ("KVM: s390: Use try_cmpxchg() instead of cmpxchg() loops")

Applying this dependency patch and then cherry-picking should resolve 
the conflict. It's the same issue for failing to apply 36f6999ecde3 
("KVM: s390: pci: Fix memory accounting for pinned/unpinned pages") in 
stable version 6.1, 6.6. Is it possible to apply the dependency patch 
and try again?

Also there were multiple fixes that we wanted to backport, but I think 
only 3 of the patches were attempted across (6.1, 6.6, 6.12 and 6.18). 
The entire backport would be:

868d32ac72cb KVM: s390: pci: Validate AIBV and AISB before pinning guest 
pages
5580c9858f1e KVM: s390: pci: Fix resource leak on IRQ registration failure
8bf09b9b7d32 KVM: s390: pci: Fix NULL dereference on AIBV allocation 
failure
f86842e4d6c4 KVM: s390: pci: Fix missing error codes and memory 
unaccounting
36f6999ecde3 KVM: s390: pci: Fix memory accounting for pinned/unpinned 
pages
8fa01be5a614 KVM: s390: pci: Reject adapter interrupt forwarding if 
already enabled
5618c53d96d1 KVM: s390: Use try_cmpxchg() instead of cmpxchg() loops

Would appreciate any guidance on how we can proceed with this.

Thanks

Farhan


On 8/5/2026 2:35 AM, [email protected] wrote:
> The patch below does not apply to the 6.12-stable tree.
> If someone wants it applied there, or to any other stable or longterm
> tree, then please email the backport, including the original git commit
> id to <[email protected]>.
>
> To reproduce the conflict and resubmit, you may use the following commands:
>
> git fetch https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/ linux-6.12.y
> git checkout FETCH_HEAD
> git cherry-pick -x 36f6999ecde3976731a8bfc0b8e667da6f593069
> # <resolve conflicts, build, test, etc.>
> git commit -s
> git send-email --to '<[email protected]>' --in-reply-to '2026080507-senior-manpower-f5ab@gregkh' --subject-prefix 'PATCH 6.12.y' 'HEAD^..'
>
> Possible dependencies:
>
>
>
> thanks,
>
> greg k-h
>
> ------------------ original commit in Linus's tree ------------------
>
>  From 36f6999ecde3976731a8bfc0b8e667da6f593069 Mon Sep 17 00:00:00 2001
> From: Farhan Ali <[email protected]>
> Date: Thu, 23 Jul 2026 15:14:05 -0700
> Subject: [PATCH] KVM: s390: pci: Fix memory accounting for pinned/unpinned
>   pages
>
> The account_mem() and unaccount_mem() functions call get_uid() which
> increments the reference count of struct user_struct on every invocation.
> But we don't decrement the count by calling free_uid(). It also
> accounted/unaccounted the pages against the current->mm. But its possible
> the unaccount_mem() can be called from a different process context than the
> one that originally pinned the pages.
>
> Let's fix this by storing the pinning process user_struct and mm_struct
> when accounting for pinned pages, and subsequently free these resources
> when the pages are unpinned.
>
> Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
> Cc: [email protected]
> Reviewed-by: Christian Borntraeger <[email protected]>
> Reviewed-by: Matthew Rosato <[email protected]>
> Signed-off-by: Farhan Ali <[email protected]>
> Tested-by: Matthew Rosato <[email protected]>
> [[email protected]: Fixed whitespace]
> Signed-off-by: Christian Borntraeger <[email protected]>
>
> diff --git a/arch/s390/kvm/pci.c b/arch/s390/kvm/pci.c
> index d2a11cdf6941..0741aed442bc 100644
> --- a/arch/s390/kvm/pci.c
> +++ b/arch/s390/kvm/pci.c
> @@ -190,33 +190,54 @@ static int kvm_zpci_clear_airq(struct zpci_dev *zdev)
>   	return cc ? -EIO : 0;
>   }
>   
> -static inline void unaccount_mem(unsigned long nr_pages)
> +static inline void unaccount_mem(struct kvm_zdev *kzdev, unsigned long nr_pages)
>   {
> -	struct user_struct *user = get_uid(current_user());
> +	struct user_struct *user = kzdev->user_account;
> +	struct mm_struct *mm_account = kzdev->mm_account;
>   
> -	if (user)
> +	if (user) {
>   		atomic_long_sub(nr_pages, &user->locked_vm);
> -	if (current->mm)
> -		atomic64_sub(nr_pages, &current->mm->pinned_vm);
> +		free_uid(user);
> +		kzdev->user_account = NULL;
> +	}
> +
> +	if (mm_account) {
> +		atomic64_sub(nr_pages, &mm_account->pinned_vm);
> +		mmdrop(mm_account);
> +		kzdev->mm_account = NULL;
> +	}
>   }
>   
> -static inline int account_mem(unsigned long nr_pages)
> +static inline int account_mem(struct kvm_zdev *kzdev, unsigned long nr_pages)
>   {
>   	struct user_struct *user = get_uid(current_user());
>   	unsigned long page_limit, cur_pages, new_pages;
> +	int rc = 0;
>   
>   	page_limit = rlimit(RLIMIT_MEMLOCK) >> PAGE_SHIFT;
>   
>   	cur_pages = atomic_long_read(&user->locked_vm);
>   	do {
>   		new_pages = cur_pages + nr_pages;
> -		if (new_pages > page_limit)
> -			return -ENOMEM;
> +		if (new_pages > page_limit) {
> +			rc = -ENOMEM;
> +			goto out;
> +		}
>   	} while (!atomic_long_try_cmpxchg(&user->locked_vm, &cur_pages, new_pages));
>   
> -	atomic64_add(nr_pages, &current->mm->pinned_vm);
> +	if (current->mm) {
> +		mmgrab(current->mm);
> +		atomic64_add(nr_pages, &current->mm->pinned_vm);
> +	}
> +
> +	kzdev->user_account = user;
> +	kzdev->mm_account = current->mm;
>   
>   	return 0;
> +
> +out:
> +	free_uid(user);
> +	return rc;
>   }
>   
>   static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
> @@ -279,7 +300,7 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
>   	}
>   
>   	/* Account for pinned pages, roll back on failure */
> -	if (account_mem(pcount))
> +	if (account_mem(zdev->kzdev, pcount))
>   		goto unpin2;
>   
>   	/* AISB must be allocated before we can fill in GAITE */
> @@ -400,7 +421,7 @@ static int kvm_s390_pci_aif_disable(struct zpci_dev *zdev, bool force)
>   		pcount++;
>   	}
>   	if (pcount > 0)
> -		unaccount_mem(pcount);
> +		unaccount_mem(kzdev, pcount);
>   out:
>   	mutex_unlock(&aift->aift_lock);
>   
> diff --git a/arch/s390/kvm/pci.h b/arch/s390/kvm/pci.h
> index ff0972dd5e71..fdf8c7bf4ed0 100644
> --- a/arch/s390/kvm/pci.h
> +++ b/arch/s390/kvm/pci.h
> @@ -22,6 +22,8 @@ struct kvm_zdev {
>   	struct kvm *kvm;
>   	struct zpci_fib fib;
>   	struct list_head entry;
> +	struct user_struct *user_account;
> +	struct mm_struct *mm_account;
>   };
>   
>   struct zpci_gaite {
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.