[PATCH v2 0/7] s390/vfio_ccw fixes

From: Eric Farman

Date: Mon Jul 20 2026 - 16:20:43 EST


This series addresses some pre-existing issues found in the
s390 vfio_ccw (DASD passthrough) driver.

v1: https://lore.kernel.org/r/20260714232208.1683788-1-farman@xxxxxxxxxxxxx/
v1->v2:
- [sashiko] Reorder patches to put the cp_init and channel program segment
pieces at the head of the series
- [sashiko] Fix the out of bounds array check to break the loop correctly
- [sashiko] Move the nospec clamp to the default case, rather than the
entirety of the switch statement (to keep it in the default leg of the
switch where it's used, rather than outside the entire switch)
- [EF] Return -EINVAL if ccwchain count is exhausted, instead of -ENOMEM
- [EF] Drop calc_max_idal_len() logic in place of a comparison against
idaw[0] before/after the pair of vfio_dma_rw() calls
- [EF] Implement two new spin locks, one for struct channel_program in
struct vfio_ccw_private, and one for the list of CRWs in struct
vfio_ccw_private.

Eric Farman (7):
s390/vfio_ccw: free all memory if cp_init() fails
s390/vfio_ccw: limit the number of channel program segments
s390/vfio_ccw: fix out of bounds check on CCW array
s390/vfio_ccw: ensure first IDAW remains constant
s390/vfio_ccw: ensure index for read/write regions are within range
s390/vfio_ccw: implement a channel program lock
s390/vfio_ccw: implement a crw lock

drivers/s390/cio/vfio_ccw_chp.c | 15 ++++---
drivers/s390/cio/vfio_ccw_cp.c | 67 +++++++++++++++++++++++++----
drivers/s390/cio/vfio_ccw_cp.h | 8 ++++
drivers/s390/cio/vfio_ccw_drv.c | 10 ++++-
drivers/s390/cio/vfio_ccw_ops.c | 13 +++++-
drivers/s390/cio/vfio_ccw_private.h | 4 ++
6 files changed, 101 insertions(+), 16 deletions(-)

--
2.53.0