From: Alex Williamson <alex.williamson@redhat.com>
To: kvm@vger.kernel.org
Cc: eric.auger@redhat.com, alex.williamson@redhat.com,
linux-kernel@vger.kernel.org
Subject: [PATCH 0/7] vfio: Fix release ordering races and use driver_override
Date: Fri, 09 Jun 2017 15:59:25 -0600 [thread overview]
Message-ID: <20170609215816.31986.89321.stgit@gimli.home> (raw)
VM hotplug testing reveals a number of races in the vfio device,
group, container shutdown path, some attributed to libvirt's ask/take
unplug behavior and some long standing with groups potentially
composed of multiple devices, where each device can be independently
bound to drivers. Libvirt's ask/take behavior is a result of the
asynchronous nature of PCI hotplug, libvirt registers a hot-unplug
request (ask), which is acknowledged almost immediately and then
proceeds to try to unbind the device from the vfio bus driver (take).
This sets us off on racing paths where we allow the device to be
released from the group much like would happen in groups with multiple
devices, while the group and container are torn down separately.
These races are addressed in the first 3 patches of this series.
The long standing issue with removing devices from in-use groups is
that we feel that the system is compromised if we allow user and host
devices within the same non-isolated group. This triggers a BUG_ON
when we detect this condition after the rogue driver binding. Since
that code was put in place we've added driver_override support for
all of the physical buses supported by vfio, giving us a way to block
binding to such compromising drivers. We finally enable that in the
latter 4 patches of this series, minding that we need to allow
re-binding to non-compromising drivers, and also noting that a small
synchronization stall is effective in eliminating the need for this
blocking in the more common singleton device group case.
Reviews, comments, and acks appreciated. Thanks,
Alex
---
Alex Williamson (7):
vfio: Fix group release deadlock
kvm-vfio: Decouple only when we match a group
vfio: New external user group/file match
iommu: Add driver-not-bound notification
vfio: Create interface for vfio bus drivers to register
vfio: Register pci, platform, amba, and mdev bus drivers
vfio: Use driver_override to avert binding to compromising drivers
drivers/iommu/iommu.c | 2
drivers/vfio/mdev/vfio_mdev.c | 13 ++
drivers/vfio/pci/vfio_pci.c | 7 +
drivers/vfio/platform/vfio_amba.c | 24 +++
drivers/vfio/platform/vfio_platform.c | 24 +++
drivers/vfio/vfio.c | 252 ++++++++++++++++++++++++++++++++-
include/linux/iommu.h | 1
include/linux/vfio.h | 5 +
virt/kvm/vfio.c | 33 +++-
9 files changed, 338 insertions(+), 23 deletions(-)
next reply other threads:[~2017-06-09 21:59 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-06-09 21:59 Alex Williamson [this message]
2017-06-09 21:59 ` [PATCH 1/7] vfio: Fix group release deadlock Alex Williamson
2017-06-14 12:31 ` Auger Eric
2017-06-09 21:59 ` [PATCH 2/7] kvm-vfio: Decouple only when we match a group Alex Williamson
2017-06-12 16:28 ` Paolo Bonzini
2017-06-14 12:31 ` Auger Eric
2017-06-09 21:59 ` [PATCH 3/7] vfio: New external user group/file match Alex Williamson
2017-06-12 16:27 ` Paolo Bonzini
2017-06-14 12:42 ` Auger Eric
2017-06-09 21:59 ` [PATCH 4/7] iommu: Add driver-not-bound notification Alex Williamson
2017-06-09 22:21 ` Joerg Roedel
2017-06-09 22:43 ` Alex Williamson
2017-06-10 21:39 ` Joerg Roedel
2017-06-14 12:52 ` Auger Eric
2017-06-09 22:00 ` [PATCH 5/7] vfio: Create interface for vfio bus drivers to register Alex Williamson
2017-06-14 13:17 ` Auger Eric
2017-06-09 22:00 ` [PATCH 6/7] vfio: Register pci, platform, amba, and mdev bus drivers Alex Williamson
2017-06-14 13:17 ` Auger Eric
2017-06-09 22:00 ` [PATCH 7/7] vfio: Use driver_override to avert binding to compromising drivers Alex Williamson
2017-06-19 14:03 ` Auger Eric
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170609215816.31986.89321.stgit@gimli.home \
--to=alex.williamson@redhat.com \
--cc=eric.auger@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®