[PATCH v2 2/2] RISC-V: KVM: Disallow GPA-width changes after AIA init

Nutty.Liu nutty.liu at hotmail.com
Wed Sep 23 02:45:32 PDT 2026


On 9/20/2026 9:09 PM, Pengpeng Hou wrote:
> KVM_ENABLE_CAP(KVM_CAP_VM_GPA_BITS) allows userspace to reduce the
> stage-2 GPA width while a VM has no vCPUs or memory slots.
>
> AIA initialization can complete with an APLIC and no vCPUs or memory
> slots. The APLIC MMIO device has then been registered, but the existing
> checks still allow userspace to shrink the GPA width below its address.
>
> Reject GPA-width changes after AIA initialization. Both paths hold
> kvm->lock, serializing the width change with AIA initialization.
>
> The issue was found by our static-analysis tool.
>
> Fixes: 7263b4fdb0b2 ("RISC-V: KVM: Reuse KVM_CAP_VM_GPA_BITS to select HGATP.MODE")
> Reviewed-by: Anup Patel <anup at brainfault.org>
> Assisted-by: gpt 5
> Signed-off-by: Pengpeng Hou <hppiscas at 163.com>
Reviewed-by: Nutty Liu <nutty.liu at hotmail.com>

Thanks,
Nutty
> ---
> Changes since v1: https://lore.kernel.org/r/4852f3b8985c353811fa065e4701d76dc9a7f086.1786512671.git.pengpeng@iscas.ac.cn/
> - No change to the code; retain Anup's Reviewed-by.
> - Rebase and clarify the locking description.
>
>   arch/riscv/kvm/vm.c | 3 ++-
>   1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/arch/riscv/kvm/vm.c b/arch/riscv/kvm/vm.c
> index a9f083f..66edfaa 100644
> --- a/arch/riscv/kvm/vm.c
> +++ b/arch/riscv/kvm/vm.c
> @@ -250,7 +250,8 @@ int kvm_vm_ioctl_enable_cap(struct kvm *kvm, struct kvm_enable_cap *cap)
>   		mutex_lock(&kvm->lock);
>   		mutex_lock(&kvm->slots_lock);
>   
> -		if (kvm->created_vcpus || !kvm_are_all_memslots_empty(kvm))
> +		if (kvm->created_vcpus || !kvm_are_all_memslots_empty(kvm) ||
> +		    kvm_riscv_aia_initialized(kvm))
>   			r = -EBUSY;
>   		else
>   			kvm->arch.pgd_levels = new_levels;
>



More information about the linux-riscv mailing list