summaryrefslogtreecommitdiff
path: root/lib/mpi/generic_mpih-rshift.c
diff options
context:
space:
mode:
authorPaul Mackerras <paulus@ozlabs.org>2018-10-04 07:51:11 +0300
committerPaul Mackerras <paulus@ozlabs.org>2018-10-04 07:51:11 +0300
commit6579804c431712d56956a63b1a01509441cc6800 (patch)
tree173e1622e1319cdf22fc63eb544228edc200c51a /lib/mpi/generic_mpih-rshift.c
parent71d29f43b6332badc5598c656616a62575e83342 (diff)
downloadlinux-6579804c431712d56956a63b1a01509441cc6800.tar.xz
KVM: PPC: Book3S HV: Avoid crash from THP collapse during radix page fault
Commit 71d29f43b633 ("KVM: PPC: Book3S HV: Don't use compound_order to determine host mapping size", 2018-09-11) added a call to __find_linux_pte() and a dereference of the returned PTE pointer to the radix page fault path in the common case where the page is normal system memory. Previously, __find_linux_pte() was only called for mappings to physical addresses which don't have a page struct (e.g. memory-mapped I/O) or where the page struct is marked as reserved memory. This exposes us to the possibility that the returned PTE pointer could be NULL, for example in the case of a concurrent THP collapse operation. Dereferencing the returned NULL pointer causes a host crash. To fix this, we check for NULL, and if it is NULL, we retry the operation by returning to the guest, with the expectation that it will generate the same page fault again (unless of course it has been fixed up by another CPU in the meantime). Fixes: 71d29f43b633 ("KVM: PPC: Book3S HV: Don't use compound_order to determine host mapping size") Signed-off-by: Paul Mackerras <paulus@ozlabs.org>
Diffstat (limited to 'lib/mpi/generic_mpih-rshift.c')
0 files changed, 0 insertions, 0 deletions