[PATCH v8 29/29] KVM: s390: Enforce no unexpected external symbol exports in s390 KVM
From: Steffen Eiden
Date: Fri Sep 18 2026 - 10:28:20 EST
Add a Makefile check to arch/s390/kvm that fails the build on any
EXPORT_SYMBOL_GPL or EXPORT_SYMBOL not in the allowed list. A symbol
may only use EXPORT_SYMBOL_GPL if it is defined in exactly one of the
two s390 KVM modules (kvm or kvm-arm64). A symbol defined in both
modules could cause a link conflict if built builtin.
While at it remove the unnecessary EXPORT_SYMBOL_GPL from
kvm_s390_pv_is_protected, which has no external callers.
Signed-off-by: Steffen Eiden <seiden@xxxxxxxxxxxxx>
---
arch/s390/kvm/Makefile | 1 +
arch/s390/kvm/arm64/Makefile | 14 ++++++++++++++
arch/s390/kvm/s390/Makefile | 16 ++++++++++++++++
arch/s390/kvm/s390/pv.c | 1 -
4 files changed, 31 insertions(+), 1 deletion(-)
diff --git a/arch/s390/kvm/Makefile b/arch/s390/kvm/Makefile
index 380db443a0e9..0e474335bb78 100644
--- a/arch/s390/kvm/Makefile
+++ b/arch/s390/kvm/Makefile
@@ -5,3 +5,4 @@
obj-$(CONFIG_KVM) += s390/
obj-$(CONFIG_KVM) += arm64/
+
diff --git a/arch/s390/kvm/arm64/Makefile b/arch/s390/kvm/arm64/Makefile
index bd78d64939d1..d84d3be74037 100644
--- a/arch/s390/kvm/arm64/Makefile
+++ b/arch/s390/kvm/arm64/Makefile
@@ -3,6 +3,7 @@
KVM := ../../../../virt/kvm
KVM_DEV_NAME = kvm_arm64
KVM_DEV_MINOR = MISC_DYNAMIC_MINOR
+KVM_CHECK_EXPORT_DIRS ?= $(srctree)/virt/kvm $(srctree)/arch/s390/kvm/gmap $(src)
include $(srctree)/virt/kvm/Makefile.kvm
include $(srctree)/arch/s390/kvm/gmap/Makefile
include $(src)/Makefile.gen
@@ -91,3 +92,16 @@ targets += kvm-unnamespaced.o kvm_symbol_list kvm-namespaced.o
endif
obj-$(CONFIG_KVM) += kvm-arm64.o
+
+# Fail the build if there is unexpected EXPORT_SYMBOL_GPL (or EXPORT_SYMBOL)
+# usage in arm64 KVM code. A symbol may only use EXPORT_SYMBOL_GPL if it is
+# defined in exactly one of the two s390 KVM modules (kvm or kvm_arm64). A
+# symbol defined in both would cause a conflict during linking if builtin is
+# selected. Catch the issue early.
+
+# This "symbol" is not exported by arm on s390 but still in the source code and the
+# export check scans unexpanded source code.
+kvm_exports_allowed := kvm_file_to_kvm_fn
+
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL_GPL))
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL))
diff --git a/arch/s390/kvm/s390/Makefile b/arch/s390/kvm/s390/Makefile
index b91334db90a2..5d6eb45d3037 100644
--- a/arch/s390/kvm/s390/Makefile
+++ b/arch/s390/kvm/s390/Makefile
@@ -1,6 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
KVM := ../../../../virt/kvm
+KVM_CHECK_EXPORT_DIRS ?= $(srctree)/virt/kvm $(srctree)/arch/$(ARCH)/kvm/gmap $(src)
include $(srctree)/virt/kvm/Makefile.kvm
include $(srctree)/arch/s390/kvm/gmap/Makefile
@@ -12,3 +13,18 @@ kvm-y += $(gmap-y)
kvm-$(CONFIG_VFIO_PCI_ZDEV_KVM) += pci.o
obj-$(CONFIG_KVM) += kvm.o
+
+# Fail the build if there is unexpected EXPORT_SYMBOL_GPL (or EXPORT_SYMBOL)
+# usage in s390 KVM code. A symbol may only use EXPORT_SYMBOL_GPL if it is
+# defined in exactly one of the two s390 KVM modules (kvm or kvm_arm64). A
+# symbol defined in both would cause a conflict during linking if builtin is
+# selected. Catch the issue early.
+kvm_exports_allowed := kvm_s390_pv_cpu_is_protected \
+ kvm_arch_crypto_set_masks \
+ kvm_arch_crypto_clear_masks \
+ kvm_s390_gisc_register \
+ kvm_s390_gisc_unregister \
+ kvm_file_to_kvm_fn
+
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL_GPL))
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL))
diff --git a/arch/s390/kvm/s390/pv.c b/arch/s390/kvm/s390/pv.c
index b18abd0e29ef..1fec224e4d2b 100644
--- a/arch/s390/kvm/s390/pv.c
+++ b/arch/s390/kvm/s390/pv.c
@@ -29,7 +29,6 @@ bool kvm_s390_pv_is_protected(struct kvm *kvm)
lockdep_assert_held(&kvm->lock);
return !!kvm_s390_pv_get_handle(kvm);
}
-EXPORT_SYMBOL_GPL(kvm_s390_pv_is_protected);
bool kvm_s390_pv_cpu_is_protected(struct kvm_vcpu *vcpu)
{
--
2.53.0