From: Lu Baolu <baolu.lu@linux.intel.com>
To: Joerg Roedel <joro@8bytes.org>, Will Deacon <will@kernel.org>,
Robin Murphy <robin.murphy@arm.com>,
Jason Gunthorpe <jgg@ziepe.ca>, Kevin Tian <kevin.tian@intel.com>
Cc: iommu@lists.linux.dev, linux-kernel@vger.kernel.org,
Lu Baolu <baolu.lu@linux.intel.com>
Subject: [PATCH 2/7] iommu/vt-d: Do not ignore context table copy failures
Date: Wed, 9 Sep 2026 15:51:01 +0800 [thread overview]
Message-ID: <20260909075106.738691-3-baolu.lu@linux.intel.com> (raw)
In-Reply-To: <20260909075106.738691-1-baolu.lu@linux.intel.com>
copy_translation_tables() currently logs copy_context_table() failures
but still returns success, so partial copy failures are silently ignored.
That means Intel IOMMU may run with only part of the old tables copied.
Then some old domain IDs may not be reserved, and later may be reused by
new domains. With stale hardware cache entries still around, this can
cause bad DMA translations, DMA faults, or domain aliasing.
Fix by aborting on the first context-table copy failure, freeing temporary
context-table pages, and returning an error so caller falls back to a
clean root table path.
Fixes: f93b4ac5929a ("iommu/vt-d: Use ida to manage domain id")
Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
---
drivers/iommu/intel/iommu.c | 18 +++++++++++++++++-
1 file changed, 17 insertions(+), 1 deletion(-)
diff --git a/drivers/iommu/intel/iommu.c b/drivers/iommu/intel/iommu.c
index 2e3b3ab216f8..38e2a670df9a 100644
--- a/drivers/iommu/intel/iommu.c
+++ b/drivers/iommu/intel/iommu.c
@@ -1591,7 +1591,7 @@ static int copy_translation_tables(struct intel_iommu *iommu)
if (ret) {
pr_err("%s: Failed to copy context table for bus %d\n",
iommu->name, bus);
- continue;
+ goto err_free_ctxt_tbls;
}
}
@@ -1623,11 +1623,27 @@ static int copy_translation_tables(struct intel_iommu *iommu)
memunmap(old_rt);
return 0;
+err_free_ctxt_tbls:
+ /*
+ * None of these tables have been linked into iommu->root_entry yet,
+ * so they are unreachable and must be freed here.
+ */
+ for (bus = 0; bus < ctxt_table_entries; bus++)
+ iommu_free_pages(ctxt_tbls[bus]);
+ kfree(ctxt_tbls);
out_unmap:
memunmap(old_rt);
err_free_bitmap:
bitmap_free(iommu->copied_tables);
iommu->copied_tables = NULL;
+
+ /*
+ * Only reservations taken from the old context entries can be in the
+ * ida at this point; no domain has been allocated on this IOMMU yet.
+ * ida_destroy() empties it and leaves it ready for reuse.
+ */
+ ida_destroy(&iommu->domain_ida);
+
return ret;
}
--
2.43.0
next prev parent reply other threads:[~2026-09-09 8:03 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 7:50 [PATCH 0/7] iommu/vt-d: Fix issues reported by Sashiko Lu Baolu
2026-09-09 7:51 ` [PATCH 1/7] iommu/vt-d: Avoid out-of-range shift in qi_desc_dev_iotlb_pasid() Lu Baolu
2026-09-09 7:51 ` Lu Baolu [this message]
2026-09-09 7:51 ` [PATCH 3/7] iommu/vt-d: Handle DID reservation errors when copying context tables Lu Baolu
2026-09-09 7:51 ` [PATCH 4/7] iommu/vt-d: Reserve scalable-mode DIDs from PASID entries during copy Lu Baolu
2026-09-09 7:51 ` [PATCH 5/7] iommu/vt-d: Use old domain parameter when attaching the blocking domain Lu Baolu
2026-09-09 7:51 ` [PATCH 6/7] iommu/vt-d: Fix iopf refcount leak in nested attach Lu Baolu
2026-09-09 7:51 ` [PATCH 7/7] iommu/vt-d: Drop old iopf ref only after attach succeeds Lu Baolu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909075106.738691-3-baolu.lu@linux.intel.com \
--to=baolu.lu@linux.intel.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=kevin.tian@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=robin.murphy@arm.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®