]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
authorFarhan Ali <alifm@linux.ibm.com>
Thu, 23 Jul 2026 22:14:05 +0000 (15:14 -0700)
committerChristian Borntraeger <borntraeger@linux.ibm.com>
Fri, 24 Jul 2026 09:26:53 +0000 (11:26 +0200)
The account_mem() and unaccount_mem() functions call get_uid() which
increments the reference count of struct user_struct on every invocation.
But we don't decrement the count by calling free_uid(). It also
accounted/unaccounted the pages against the current->mm. But its possible
the unaccount_mem() can be called from a different process context than the
one that originally pinned the pages.

Let's fix this by storing the pinning process user_struct and mm_struct
when accounting for pinned pages, and subsequently free these resources
when the pages are unpinned.

Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Tested-by: Matthew Rosato <mjrosato@linux.ibm.com>
[borntraeger@linux.ibm.com: Fixed whitespace]
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
arch/s390/kvm/pci.c
arch/s390/kvm/pci.h

index d2a11cdf6941de6f76a4e670464794df6a806527..0741aed442bc15a793534bca961e4913fa285a04 100644 (file)
@@ -190,33 +190,54 @@ static int kvm_zpci_clear_airq(struct zpci_dev *zdev)
        return cc ? -EIO : 0;
 }
 
-static inline void unaccount_mem(unsigned long nr_pages)
+static inline void unaccount_mem(struct kvm_zdev *kzdev, unsigned long nr_pages)
 {
-       struct user_struct *user = get_uid(current_user());
+       struct user_struct *user = kzdev->user_account;
+       struct mm_struct *mm_account = kzdev->mm_account;
 
-       if (user)
+       if (user) {
                atomic_long_sub(nr_pages, &user->locked_vm);
-       if (current->mm)
-               atomic64_sub(nr_pages, &current->mm->pinned_vm);
+               free_uid(user);
+               kzdev->user_account = NULL;
+       }
+
+       if (mm_account) {
+               atomic64_sub(nr_pages, &mm_account->pinned_vm);
+               mmdrop(mm_account);
+               kzdev->mm_account = NULL;
+       }
 }
 
-static inline int account_mem(unsigned long nr_pages)
+static inline int account_mem(struct kvm_zdev *kzdev, unsigned long nr_pages)
 {
        struct user_struct *user = get_uid(current_user());
        unsigned long page_limit, cur_pages, new_pages;
+       int rc = 0;
 
        page_limit = rlimit(RLIMIT_MEMLOCK) >> PAGE_SHIFT;
 
        cur_pages = atomic_long_read(&user->locked_vm);
        do {
                new_pages = cur_pages + nr_pages;
-               if (new_pages > page_limit)
-                       return -ENOMEM;
+               if (new_pages > page_limit) {
+                       rc = -ENOMEM;
+                       goto out;
+               }
        } while (!atomic_long_try_cmpxchg(&user->locked_vm, &cur_pages, new_pages));
 
-       atomic64_add(nr_pages, &current->mm->pinned_vm);
+       if (current->mm) {
+               mmgrab(current->mm);
+               atomic64_add(nr_pages, &current->mm->pinned_vm);
+       }
+
+       kzdev->user_account = user;
+       kzdev->mm_account = current->mm;
 
        return 0;
+
+out:
+       free_uid(user);
+       return rc;
 }
 
 static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
@@ -279,7 +300,7 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
        }
 
        /* Account for pinned pages, roll back on failure */
-       if (account_mem(pcount))
+       if (account_mem(zdev->kzdev, pcount))
                goto unpin2;
 
        /* AISB must be allocated before we can fill in GAITE */
@@ -400,7 +421,7 @@ static int kvm_s390_pci_aif_disable(struct zpci_dev *zdev, bool force)
                pcount++;
        }
        if (pcount > 0)
-               unaccount_mem(pcount);
+               unaccount_mem(kzdev, pcount);
 out:
        mutex_unlock(&aift->aift_lock);
 
index ff0972dd5e71dc263351fc7fde4ad7b4db514db3..fdf8c7bf4ed082a3b3b141f5621e943b3be7d805 100644 (file)
@@ -22,6 +22,8 @@ struct kvm_zdev {
        struct kvm *kvm;
        struct zpci_fib fib;
        struct list_head entry;
+       struct user_struct *user_account;
+       struct mm_struct *mm_account;
 };
 
 struct zpci_gaite {