Re: [PATCH] KVM: x86/xen: Fix data race on poll event channel

From: David Woodhouse

Date: Tue Aug 25 2026 - 14:25:30 EST


On Mon, 2026-08-24 at 19:43 +0800, Chengfeng Ye wrote:
> Use READ_ONCE() and WRITE_ONCE() for runtime accesses to poll_evtchn.
> This marks the intentionally concurrent scalar accesses and prevents the
> compiler from splitting, merging, or inventing accesses.
>
> kvm_xen_schedop_poll() publishes the single port, or -1 for multiple
> ports, before setting poll_mask and halting the vCPU.  Event delivery can
> call kvm_xen_check_poller() on another CPU while the vCPU thread publishes
> that value or resets the field to zero after returning from
> kvm_vcpu_halt():
>
>   vCPU thread                         event delivery thread
>   -----------                         ---------------------
>   poll_evtchn = port
>   set_bit(poll_mask)
>   kvm_vcpu_halt()
>                                       poll_evtchn = READ
>   poll_evtchn = 0
>   clear_bit(poll_mask)
>
> The plain read and writes therefore race.  KCSAN reported:
>
>   BUG: KCSAN: data-race in kvm_xen_hypercall / kvm_xen_set_evtchn_fast
>
>   read to 0xffff888112f55af0 of 4 bytes by task 98:
>    kvm_xen_set_evtchn_fast+0x204/0x7c0
>    kvm_xen_hvm_evtchn_send+0xab/0x100
>    kvm_arch_vm_ioctl+0xb31/0xd90
>    kvm_vm_ioctl+0xf42/0x16c0
>
>   write to 0xffff888112f55af0 of 4 bytes by task 96:
>    kvm_xen_hypercall+0xd8d/0xf50
>    kvm_emulate_hypercall+0x157/0x1d0
>    vmx_handle_exit+0x40f/0xae0
>    vcpu_run+0x137f/0x27d0
>    kvm_arch_vcpu_ioctl_run+0x5a5/0x970
>
> The field is an aligned int on x86.  Access annotations preserve the
> existing matching, callback, and poll-mask control flow while making the
> single-copy access requirement explicit.
>
> Fixes: 1a65105a5aba ("KVM: x86/xen: handle PV spinlocks slowpath")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Chengfeng Ye <nicoyip.dev@xxxxxxxxx>

LGTM, thanks. I don't think we need Cc:stable for a KCSAN splat, and
possibly not even the Fixes: tag. I'll roll it into my series at
https://lore.kernel.org/all/20260811094829.98794-1-dwmw2@xxxxxxxxxxxxx/
now sitting at
https://git.infradead.org/?p=users/dwmw2/linux.git;a=shortlog;h=refs/heads/xen-v3

Attachment: smime.p7s
Description: S/MIME cryptographic signature