[PATCH v6 00/10] s390/vfio_ccw fixes
From: Eric Farman
Date: Sun Jul 26 2026 - 13:22:41 EST
This series addresses some pre-existing issues found in the
s390 vfio_ccw (DASD passthrough) driver.
v1: https://lore.kernel.org/r/20260714232208.1683788-1-farman@xxxxxxxxxxxxx/
v2: https://lore.kernel.org/r/20260720201931.976660-1-farman@xxxxxxxxxxxxx/
v3: https://lore.kernel.org/r/20260723174751.1180334-1-farman@xxxxxxxxxxxxx/
v4: https://lore.kernel.org/r/20260725152705.3958100-1-farman@xxxxxxxxxxxxx/
v5: https://lore.kernel.org/r/20260726040129.2946151-1-farman@xxxxxxxxxxxxx/
v5->v6:
- [sashiko] Add cancel_work_sync() to vfio_ccw_mdev_close_dev() as the "usual"
cleanup, and keep them in vfio_ccw_mdev_release_dev() to cover corner cases
- [MR; offlist] Remove the proposed notoper_work queue, and move the cp_free
from the FSM to vfio_ccw_mdev_close_dev() to ensure we cover the case where
a device becomes not operational (due to sch_event) while I/O is in flight.
Eric Farman (10):
s390/vfio_ccw: free all memory if cp_init() fails
s390/vfio_ccw: limit the number of channel program segments
s390/vfio_ccw: fix out of bounds check on CCW array
s390/vfio_ccw: ensure first IDAW remains constant
s390/vfio_ccw: calculate idal length based on idaw type
s390/vfio_ccw: ensure index for read/write regions are within range
s390/vfio_ccw: cancel existing workqueues
s390/vfio_ccw: move cp cleanup out of not operational
s390/vfio_ccw: implement a channel program mutex
s390/vfio_ccw: implement a crw lock
drivers/s390/cio/vfio_ccw_async.c | 16 +++++
drivers/s390/cio/vfio_ccw_chp.c | 31 ++++++++--
drivers/s390/cio/vfio_ccw_cp.c | 96 ++++++++++++++++++++++-------
drivers/s390/cio/vfio_ccw_cp.h | 10 +++
drivers/s390/cio/vfio_ccw_drv.c | 10 +++
drivers/s390/cio/vfio_ccw_fsm.c | 23 ++++---
drivers/s390/cio/vfio_ccw_ops.c | 40 ++++++++++--
drivers/s390/cio/vfio_ccw_private.h | 7 +++
8 files changed, 191 insertions(+), 42 deletions(-)
--
2.53.0