From patchwork Sat Mar 28 09:21:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yufan Chen X-Patchwork-Id: 2217380 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; secure) header.d=lists.infradead.org header.i=@lists.infradead.org header.a=rsa-sha256 header.s=bombadil.20210309 header.b=WWPuRzmB; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=linux.dev header.i=@linux.dev header.a=rsa-sha256 header.s=key1 header.b=LQGQxLsP; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.infradead.org (client-ip=2607:7c80:54:3::133; helo=bombadil.infradead.org; envelope-from=kvm-riscv-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org; receiver=patchwork.ozlabs.org) Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4fjX9F0XzCz1xtJ for ; Sat, 28 Mar 2026 20:22:36 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:Message-ID:Date:Subject:Cc :To:From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References: List-Owner; bh=unkSkgiP8LzvensinrA917o4GdXFu1HmDRlvs7GaNL4=; b=WWPuRzmBKmqsGi L0/2DSO1ckyZJPZUh9UafQygjInjPY29jWaMh4NPqp+OxZP19SzHTH4+TC3iEjw4dyRt29CeE3JEL FlDmD7An4VkqpyCqwXIpH+eaEkf4TVzBY4LS3jboQWwjo7EY3sC0SOSeVc4AOqqQ9G4cw+y7vjnwX tiEsYwIqZAuBMCywdSVDW1lQpCEM5K91t3EN30FbgYORAXlecCnkxOsn7u5t89PfuG/qCUer4qNFh YOIHozqjItcSqM70fddIUj32aS5CUdFxSF8HIu0hVb+gkwOzlPKTdCrxGBEDkpTE/zDz/1o0BJMER U5HxLtfUtp5rgEMr1b9w==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.98.2 #2 (Red Hat Linux)) id 1w6PsF-00000008mNJ-2Xx9; Sat, 28 Mar 2026 09:22:31 +0000 Received: from out-180.mta0.migadu.com ([2001:41d0:1004:224b::b4]) by bombadil.infradead.org with esmtps (Exim 4.98.2 #2 (Red Hat Linux)) id 1w6PsC-00000008mM9-1Z6j for kvm-riscv@lists.infradead.org; Sat, 28 Mar 2026 09:22:29 +0000 X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1774689729; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=32F5mTJaAj0N/FgsyqUyjOrOpTIx3iyjz27Gm160YI0=; b=LQGQxLsPWUUKNiS9izD994OcRD4Qe8YmBJ2/6ybuHVLl7MGGBjWOElR2BGUgGHwfKmhtoT R48X4U/8G/SXxkly0CEAYbRZp/Aq9ovHcrfpLetqhPUx4ueSZOW3aZ6snWawrqEkigCePS lZf3p0VeRPJJHlDhgHnoU/ejGS4ypwU= From: Yufan Chen To: Anup Patel , Atish Patra , Paul Walmsley , Palmer Dabbelt , Albert Ou , Alexandre Ghiti , kvm@vger.kernel.org, kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org Cc: yufan.chen@linux.dev, Yufan Chen Subject: [PATCH] riscv/kvm: fix guest vector leak on host alloc failure Date: Sat, 28 Mar 2026 17:21:57 +0800 Message-ID: <20260328092157.75058-1-yufan.chen@linux.dev> MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=1515; i=ericterminal@gmail.com; h=from:subject; bh=NyfQPU3Jx0krdL2ohrnV2JS3MQSaKsafKvtyKGDOgko=; b=owGbwMvMwCXWM/dCzeS3H+sZT6slMWQen8OyTu1PtO8cubJjyjckVnkk+E65Zah1/P09Th+OB U7rTWz1OiayMIhxMViKKbLc/b9vbq7XrTnXuQ/nwsxhZQIZIi3SwAAELAx8uYl5pUY6Rnqm2oZ6 hkY6BjrGDFycAjDVU2MZGd4zLJKIWpTyzoVD/cjFfqWSN2ZpJjwVPv6+73b6bcgL9waqOHGO1yO s/cU5sdtR5p/XBW9Mjp9gr+62/dNR/4aaC0ksAA== X-Developer-Key: i=ericterminal@gmail.com; a=openpgp; fpr=DDFFBE9D6D4ADA9CD70BC36D8C9DD07C93EDF17F X-Migadu-Flow: FLOW_OUT X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260328_022228_576339_E4BE1D87 X-CRM114-Status: UNSURE ( 7.73 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -2.1 (--) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Yufan Chen When allocating vector context for a vCPU, guest_context.vector.datap is allocated before host_context.vector.datap. If the second allocation fails, the function returns -ENOMEM directly and leaks the [...] Content analysis details: (-2.1 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] X-BeenThere: kvm-riscv@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "kvm-riscv" Errors-To: kvm-riscv-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org From: Yufan Chen When allocating vector context for a vCPU, guest_context.vector.datap is allocated before host_context.vector.datap. If the second allocation fails, the function returns -ENOMEM directly and leaks the guest buffer. Switch the failure path to centralized cleanup. On host allocation failure, free guest_context.vector.datap, clear the pointer, and return -ENOMEM through a shared exit label. Signed-off-by: Yufan Chen --- arch/riscv/kvm/vcpu_vector.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/arch/riscv/kvm/vcpu_vector.c b/arch/riscv/kvm/vcpu_vector.c index 05f3cc2d8..4c2f92dce 100644 --- a/arch/riscv/kvm/vcpu_vector.c +++ b/arch/riscv/kvm/vcpu_vector.c @@ -75,15 +75,23 @@ void kvm_riscv_vcpu_host_vector_restore(struct kvm_cpu_context *cntx) int kvm_riscv_vcpu_alloc_vector_context(struct kvm_vcpu *vcpu) { + int rc = -ENOMEM; + vcpu->arch.guest_context.vector.datap = kzalloc(riscv_v_vsize, GFP_KERNEL); if (!vcpu->arch.guest_context.vector.datap) - return -ENOMEM; + goto out; vcpu->arch.host_context.vector.datap = kzalloc(riscv_v_vsize, GFP_KERNEL); if (!vcpu->arch.host_context.vector.datap) - return -ENOMEM; + goto free_guest_vector_datap; return 0; + +free_guest_vector_datap: + kfree(vcpu->arch.guest_context.vector.datap); + vcpu->arch.guest_context.vector.datap = NULL; +out: + return rc; } void kvm_riscv_vcpu_free_vector_context(struct kvm_vcpu *vcpu)