Commit 3f29f653 authored by David Hildenbrand's avatar David Hildenbrand Committed by Alexander Gordeev
Browse files

s390/uv: Don't call folio_wait_writeback() without a folio reference



folio_wait_writeback() requires that no spinlocks are held and that
a folio reference is held, as documented. After we dropped the PTL, the
folio could get freed concurrently. So grab a temporary reference.

Fixes: 214d9bbc ("s390/mm: provide memory management functions for protected KVM guests")
Reviewed-by: default avatarClaudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: default avatarDavid Hildenbrand <david@redhat.com>
Link: https://lore.kernel.org/r/20240508182955.358628-2-david@redhat.com


Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
Signed-off-by: default avatarAlexander Gordeev <agordeev@linux.ibm.com>
parent c3f38fa6
Loading
Loading
Loading
Loading
+8 −0
Original line number Diff line number Diff line
@@ -318,6 +318,13 @@ int gmap_make_secure(struct gmap *gmap, unsigned long gaddr, void *uvcb)
			rc = make_folio_secure(folio, uvcb);
			folio_unlock(folio);
		}

		/*
		 * Once we drop the PTL, the folio may get unmapped and
		 * freed immediately. We need a temporary reference.
		 */
		if (rc == -EAGAIN)
			folio_get(folio);
	}
unlock:
	pte_unmap_unlock(ptep, ptelock);
@@ -330,6 +337,7 @@ int gmap_make_secure(struct gmap *gmap, unsigned long gaddr, void *uvcb)
		 * completion, this is just a useless check, but it is safe.
		 */
		folio_wait_writeback(folio);
		folio_put(folio);
	} else if (rc == -EBUSY) {
		/*
		 * If we have tried a local drain and the folio refcount