[PATCH v8 29/29] KVM: s390: Enforce no unexpected external symbol exports in s390 KVM

Steffen Eiden seiden at linux.ibm.com
Fri Sep 18 06:31:06 PDT 2026


Add a Makefile check to arch/s390/kvm that fails the build on any
EXPORT_SYMBOL_GPL or EXPORT_SYMBOL not in the allowed list. A symbol
may only use EXPORT_SYMBOL_GPL if it is defined in exactly one of the
two s390 KVM modules (kvm or kvm-arm64). A symbol defined in both
modules could cause a link conflict if built builtin.

While at it remove the unnecessary EXPORT_SYMBOL_GPL from
kvm_s390_pv_is_protected, which has no external callers.

Signed-off-by: Steffen Eiden <seiden at linux.ibm.com>
---
 arch/s390/kvm/Makefile       |  1 +
 arch/s390/kvm/arm64/Makefile | 14 ++++++++++++++
 arch/s390/kvm/s390/Makefile  | 16 ++++++++++++++++
 arch/s390/kvm/s390/pv.c      |  1 -
 4 files changed, 31 insertions(+), 1 deletion(-)

diff --git a/arch/s390/kvm/Makefile b/arch/s390/kvm/Makefile
index 380db443a0e9..0e474335bb78 100644
--- a/arch/s390/kvm/Makefile
+++ b/arch/s390/kvm/Makefile
@@ -5,3 +5,4 @@
 
 obj-$(CONFIG_KVM) += s390/
 obj-$(CONFIG_KVM) += arm64/
+
diff --git a/arch/s390/kvm/arm64/Makefile b/arch/s390/kvm/arm64/Makefile
index bd78d64939d1..d84d3be74037 100644
--- a/arch/s390/kvm/arm64/Makefile
+++ b/arch/s390/kvm/arm64/Makefile
@@ -3,6 +3,7 @@
 KVM := ../../../../virt/kvm
 KVM_DEV_NAME = kvm_arm64
 KVM_DEV_MINOR = MISC_DYNAMIC_MINOR
+KVM_CHECK_EXPORT_DIRS ?= $(srctree)/virt/kvm $(srctree)/arch/s390/kvm/gmap $(src)
 include $(srctree)/virt/kvm/Makefile.kvm
 include $(srctree)/arch/s390/kvm/gmap/Makefile
 include $(src)/Makefile.gen
@@ -91,3 +92,16 @@ targets += kvm-unnamespaced.o kvm_symbol_list kvm-namespaced.o
 endif
 
 obj-$(CONFIG_KVM) += kvm-arm64.o
+
+# Fail the build if there is unexpected EXPORT_SYMBOL_GPL (or EXPORT_SYMBOL)
+# usage in arm64 KVM code. A symbol may only use EXPORT_SYMBOL_GPL if it is
+# defined in exactly one of the two s390 KVM modules (kvm or kvm_arm64). A
+# symbol defined in both would cause a conflict during linking if builtin is
+# selected. Catch the issue early.
+
+# This "symbol" is not exported by arm on s390 but still in the source code and the
+# export check scans unexpanded source code.
+kvm_exports_allowed := kvm_file_to_kvm_fn
+
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL_GPL))
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL))
diff --git a/arch/s390/kvm/s390/Makefile b/arch/s390/kvm/s390/Makefile
index b91334db90a2..5d6eb45d3037 100644
--- a/arch/s390/kvm/s390/Makefile
+++ b/arch/s390/kvm/s390/Makefile
@@ -1,6 +1,7 @@
 # SPDX-License-Identifier: GPL-2.0
 
 KVM := ../../../../virt/kvm
+KVM_CHECK_EXPORT_DIRS ?= $(srctree)/virt/kvm $(srctree)/arch/$(ARCH)/kvm/gmap $(src)
 include $(srctree)/virt/kvm/Makefile.kvm
 include $(srctree)/arch/s390/kvm/gmap/Makefile
 
@@ -12,3 +13,18 @@ kvm-y += $(gmap-y)
 
 kvm-$(CONFIG_VFIO_PCI_ZDEV_KVM) += pci.o
 obj-$(CONFIG_KVM) += kvm.o
+
+# Fail the build if there is unexpected EXPORT_SYMBOL_GPL (or EXPORT_SYMBOL)
+# usage in s390 KVM code. A symbol may only use EXPORT_SYMBOL_GPL if it is
+# defined in exactly one of the two s390 KVM modules (kvm or kvm_arm64). A
+# symbol defined in both would cause a conflict during linking if builtin is
+# selected. Catch the issue early.
+kvm_exports_allowed := kvm_s390_pv_cpu_is_protected \
+		       kvm_arch_crypto_set_masks \
+		       kvm_arch_crypto_clear_masks \
+		       kvm_s390_gisc_register \
+		       kvm_s390_gisc_unregister \
+		       kvm_file_to_kvm_fn
+
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL_GPL))
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL))
diff --git a/arch/s390/kvm/s390/pv.c b/arch/s390/kvm/s390/pv.c
index b18abd0e29ef..1fec224e4d2b 100644
--- a/arch/s390/kvm/s390/pv.c
+++ b/arch/s390/kvm/s390/pv.c
@@ -29,7 +29,6 @@ bool kvm_s390_pv_is_protected(struct kvm *kvm)
 	lockdep_assert_held(&kvm->lock);
 	return !!kvm_s390_pv_get_handle(kvm);
 }
-EXPORT_SYMBOL_GPL(kvm_s390_pv_is_protected);
 
 bool kvm_s390_pv_cpu_is_protected(struct kvm_vcpu *vcpu)
 {
-- 
2.53.0




More information about the linux-arm-kernel mailing list