1 From 65ff5ef37b4cb5a58173c359693a0f22f99c8344 Mon Sep 17 00:00:00 2001
2 From: Paul Mackerras <paulus@ozlabs.org>
3 Date: Wed, 29 May 2019 11:54:00 +1000
4 Subject: KVM: PPC: Book3S: Use new mutex to synchronize access to rtas token
7 [ Upstream commit 1659e27d2bc1ef47b6d031abe01b467f18cb72d9 ]
9 Currently the Book 3S KVM code uses kvm->lock to synchronize access
10 to the kvm->arch.rtas_tokens list. Because this list is scanned
11 inside kvmppc_rtas_hcall(), which is called with the vcpu mutex held,
12 taking kvm->lock cause a lock inversion problem, which could lead to
15 To fix this, we add a new mutex, kvm->arch.rtas_token_lock, which nests
16 inside the vcpu mutexes, and use that instead of kvm->lock when
17 accessing the rtas token list.
19 This removes the lockdep_assert_held() in kvmppc_rtas_tokens_free().
20 At this point we don't hold the new mutex, but that is OK because
21 kvmppc_rtas_tokens_free() is only called when the whole VM is being
22 destroyed, and at that point nothing can be looking up a token in
25 Signed-off-by: Paul Mackerras <paulus@ozlabs.org>
26 Signed-off-by: Sasha Levin <sashal@kernel.org>
28 arch/powerpc/include/asm/kvm_host.h | 1 +
29 arch/powerpc/kvm/book3s.c | 1 +
30 arch/powerpc/kvm/book3s_rtas.c | 14 ++++++--------
31 3 files changed, 8 insertions(+), 8 deletions(-)
33 diff --git a/arch/powerpc/include/asm/kvm_host.h b/arch/powerpc/include/asm/kvm_host.h
34 index e3ba58f64c3d..5070b34b12fd 100644
35 --- a/arch/powerpc/include/asm/kvm_host.h
36 +++ b/arch/powerpc/include/asm/kvm_host.h
37 @@ -296,6 +296,7 @@ struct kvm_arch {
38 #ifdef CONFIG_PPC_BOOK3S_64
39 struct list_head spapr_tce_tables;
40 struct list_head rtas_tokens;
41 + struct mutex rtas_token_lock;
42 DECLARE_BITMAP(enabled_hcalls, MAX_HCALL_OPCODE/4 + 1);
44 #ifdef CONFIG_KVM_MPIC
45 diff --git a/arch/powerpc/kvm/book3s.c b/arch/powerpc/kvm/book3s.c
46 index 72d977e30952..d38280b01ef0 100644
47 --- a/arch/powerpc/kvm/book3s.c
48 +++ b/arch/powerpc/kvm/book3s.c
49 @@ -836,6 +836,7 @@ int kvmppc_core_init_vm(struct kvm *kvm)
51 INIT_LIST_HEAD_RCU(&kvm->arch.spapr_tce_tables);
52 INIT_LIST_HEAD(&kvm->arch.rtas_tokens);
53 + mutex_init(&kvm->arch.rtas_token_lock);
56 return kvm->arch.kvm_ops->init_vm(kvm);
57 diff --git a/arch/powerpc/kvm/book3s_rtas.c b/arch/powerpc/kvm/book3s_rtas.c
58 index 2d3b2b1cc272..8f2355138f80 100644
59 --- a/arch/powerpc/kvm/book3s_rtas.c
60 +++ b/arch/powerpc/kvm/book3s_rtas.c
61 @@ -146,7 +146,7 @@ static int rtas_token_undefine(struct kvm *kvm, char *name)
63 struct rtas_token_definition *d, *tmp;
65 - lockdep_assert_held(&kvm->lock);
66 + lockdep_assert_held(&kvm->arch.rtas_token_lock);
68 list_for_each_entry_safe(d, tmp, &kvm->arch.rtas_tokens, list) {
69 if (rtas_name_matches(d->handler->name, name)) {
70 @@ -167,7 +167,7 @@ static int rtas_token_define(struct kvm *kvm, char *name, u64 token)
74 - lockdep_assert_held(&kvm->lock);
75 + lockdep_assert_held(&kvm->arch.rtas_token_lock);
77 list_for_each_entry(d, &kvm->arch.rtas_tokens, list) {
78 if (d->token == token)
79 @@ -206,14 +206,14 @@ int kvm_vm_ioctl_rtas_define_token(struct kvm *kvm, void __user *argp)
80 if (copy_from_user(&args, argp, sizeof(args)))
83 - mutex_lock(&kvm->lock);
84 + mutex_lock(&kvm->arch.rtas_token_lock);
87 rc = rtas_token_define(kvm, args.name, args.token);
89 rc = rtas_token_undefine(kvm, args.name);
91 - mutex_unlock(&kvm->lock);
92 + mutex_unlock(&kvm->arch.rtas_token_lock);
96 @@ -245,7 +245,7 @@ int kvmppc_rtas_hcall(struct kvm_vcpu *vcpu)
97 orig_rets = args.rets;
98 args.rets = &args.args[be32_to_cpu(args.nargs)];
100 - mutex_lock(&vcpu->kvm->lock);
101 + mutex_lock(&vcpu->kvm->arch.rtas_token_lock);
104 list_for_each_entry(d, &vcpu->kvm->arch.rtas_tokens, list) {
105 @@ -256,7 +256,7 @@ int kvmppc_rtas_hcall(struct kvm_vcpu *vcpu)
109 - mutex_unlock(&vcpu->kvm->lock);
110 + mutex_unlock(&vcpu->kvm->arch.rtas_token_lock);
113 args.rets = orig_rets;
114 @@ -282,8 +282,6 @@ void kvmppc_rtas_tokens_free(struct kvm *kvm)
116 struct rtas_token_definition *d, *tmp;
118 - lockdep_assert_held(&kvm->lock);
120 list_for_each_entry_safe(d, tmp, &kvm->arch.rtas_tokens, list) {