On Sat, 29 Aug 2026 at 06:50, Karl Mehltretter <[email protected]> wrote: > > kvm_smccc_set_filter() only rejects a range if its inclusive end, > base + nr_functions - 1, is below base. That catches an empty range > (nr_functions == 0) at every nonzero base, but at base 0 the end wraps > to U32_MAX and KVM tries to insert [0, U32_MAX], which overlaps the > reserved Arm Architecture Calls ranges. KVM_ARM_VM_SMCCC_FILTER then > returns -EEXIST instead of the -EINVAL that the smccc_filter selftest > expects for an empty range. > > Reject a zero function count explicitly. > > Tested with a userspace reproducer on an arm64 VHE host under QEMU TCG: > EEXIST before, EINVAL after. > > Fixes: 821d935c87bc ("KVM: arm64: Introduce support for userspace SMCCC > filtering") > Assisted-by: LLM
nit: this should be `Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2]` rather than LLM > Signed-off-by: Karl Mehltretter <[email protected]> I think Sashiko is onto something, but that's for another day. Reviewed-by: Fuad Tabba <[email protected]> Tested-by: Fuad Tabba < [email protected]> Cheers, /fuad > --- > arch/arm64/kvm/hypercalls.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/arch/arm64/kvm/hypercalls.c b/arch/arm64/kvm/hypercalls.c > index b11b8821c9fb..dfa25bb6f25d 100644 > --- a/arch/arm64/kvm/hypercalls.c > +++ b/arch/arm64/kvm/hypercalls.c > @@ -185,7 +185,8 @@ static int kvm_smccc_set_filter(struct kvm *kvm, struct > kvm_smccc_filter __user > start = filter.base; > end = start + filter.nr_functions - 1; > > - if (end < start || filter.action >= NR_SMCCC_FILTER_ACTIONS) > + if (!filter.nr_functions || end < start || > + filter.action >= NR_SMCCC_FILTER_ACTIONS) > return -EINVAL; > > mutex_lock(&kvm->arch.config_lock); > -- > 2.39.5 (Apple Git-154) >

