Skip to content

Commit c9d61dc

Browse files
committed
KVM: SEV: accept signals in sev_lock_two_vms
Generally, kvm->lock is not taken for a long time, but sev_lock_two_vms is different: it takes vCPU locks inside, so userspace can hold it back just by calling a vCPU ioctl. Play it safe and use mutex_lock_killable. Message-Id: <[email protected]> Signed-off-by: Paolo Bonzini <[email protected]>
1 parent 10a3792 commit c9d61dc

File tree

1 file changed

+16
-6
lines changed

1 file changed

+16
-6
lines changed

arch/x86/kvm/svm/sev.c

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1547,6 +1547,7 @@ static int sev_lock_two_vms(struct kvm *dst_kvm, struct kvm *src_kvm)
15471547
{
15481548
struct kvm_sev_info *dst_sev = &to_kvm_svm(dst_kvm)->sev_info;
15491549
struct kvm_sev_info *src_sev = &to_kvm_svm(src_kvm)->sev_info;
1550+
int r = -EBUSY;
15501551

15511552
if (dst_kvm == src_kvm)
15521553
return -EINVAL;
@@ -1558,14 +1559,23 @@ static int sev_lock_two_vms(struct kvm *dst_kvm, struct kvm *src_kvm)
15581559
if (atomic_cmpxchg_acquire(&dst_sev->migration_in_progress, 0, 1))
15591560
return -EBUSY;
15601561

1561-
if (atomic_cmpxchg_acquire(&src_sev->migration_in_progress, 0, 1)) {
1562-
atomic_set_release(&dst_sev->migration_in_progress, 0);
1563-
return -EBUSY;
1564-
}
1562+
if (atomic_cmpxchg_acquire(&src_sev->migration_in_progress, 0, 1))
1563+
goto release_dst;
15651564

1566-
mutex_lock(&dst_kvm->lock);
1567-
mutex_lock(&src_kvm->lock);
1565+
r = -EINTR;
1566+
if (mutex_lock_killable(&dst_kvm->lock))
1567+
goto release_src;
1568+
if (mutex_lock_killable(&src_kvm->lock))
1569+
goto unlock_dst;
15681570
return 0;
1571+
1572+
unlock_dst:
1573+
mutex_unlock(&dst_kvm->lock);
1574+
release_src:
1575+
atomic_set_release(&src_sev->migration_in_progress, 0);
1576+
release_dst:
1577+
atomic_set_release(&dst_sev->migration_in_progress, 0);
1578+
return r;
15691579
}
15701580

15711581
static void sev_unlock_two_vms(struct kvm *dst_kvm, struct kvm *src_kvm)

0 commit comments

Comments
 (0)