From: Peng Fan <peng.fan@oss.nxp.com>
To: Nicolin Chen <nicolinc@nvidia.com>
Cc: Will Deacon <will@kernel.org>,
Robin Murphy <robin.murphy@arm.com>,
"Joerg Roedel (AMD)" <joro@8bytes.org>,
Jean-Philippe Brucker <jpb@kernel.org>,
Jason Gunthorpe <jgg@ziepe.ca>,
linux-arm-kernel@lists.infradead.org, iommu@lists.linux.dev,
linux-kernel@vger.kernel.org, Peng Fan <peng.fan@nxp.com>
Subject: Re: [PATCH RFC v3 1/3] iommu/arm-smmu-v3: Support shared SIDs in insert/remove_master
Date: Thu, 1 Oct 2026 20:51:19 +0800 [thread overview]
Message-ID: <ar5XR0l9WZ1Fnai2@shlinux89> (raw)
In-Reply-To: <ar1Q5y/xoa+Fcex7@nvidia.com>
On Wed, Sep 30, 2026 at 11:11:51AM -0700, Nicolin Chen wrote:
>On Wed, Sep 30, 2026 at 07:25:01PM +0800, Peng Fan (OSS) wrote:
>> @@ -4115,7 +4128,10 @@ static int arm_smmu_insert_master(struct arm_smmu_device *smmu,
>>
>> new_stream->id = fwspec->ids[i];
>> new_stream->master = master;
>> + new_stream->ste_installed = false;
>
>ste_installed is zero-ed.
Fix in V4.
>
>> @@ -4136,23 +4152,29 @@ static int arm_smmu_insert_master(struct arm_smmu_device *smmu,
>> existing = rb_find_add(&new_stream->node, &smmu->streams,
....
>>
>> kfree(master->streams);
>
>.. when the owner stream gets freed with the master_a, the shared
>stream would UAF:
>
> master_b->stream[0] --> new shared stream (SID=X) {shared_masters}
> |
> ---------------- shared_masters_elm ----------|
> v
> {freed}
>
>This should be changed to the model that I suggested in v2:
>
> |---------------------------------------------------------|
> | |
> | |----------- shared_masters_elm --------| |
> v | | |
> master_a->stream[0] --| v |
> |--> stream (SID=X) {shared_masters; master;}
> master_b->stream[0] --| ^
> | |
> |----------- shared_masters_elm --------|
>
>When any master is removed:
> * Delink its shared_masters_elm
> * Free the shared stream when its shared_masters is empty
>
>If shared_masters isn't empty but the owner is removed:
> * Give the ownership (stream->master pointer) to the next master
Thanks for detailed explanation. I just posted out v4, hope v4
is well following your suggestion if I not miss-understand anything.
Thanks,
Peng
>
>Nicolin
>
>
next prev parent reply other threads:[~2026-10-01 12:46 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 11:25 [PATCH RFC v3 0/3] iommu/arm-smmu-v3: Support shared Stream IDs Peng Fan (OSS)
2026-09-30 11:25 ` [PATCH RFC v3 1/3] iommu/arm-smmu-v3: Support shared SIDs in insert/remove_master Peng Fan (OSS)
2026-09-30 18:11 ` Nicolin Chen
2026-10-01 12:51 ` Peng Fan [this message]
2026-09-30 11:25 ` [PATCH RFC v3 2/3] iommu/arm-smmu-v3: Group aliasing devices into the same IOMMU group Peng Fan (OSS)
2026-09-30 11:25 ` [PATCH RFC v3 3/3] iommu/arm-smmu-v3: Wire up shared-SID STE ordering and feature gating Peng Fan (OSS)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar5XR0l9WZ1Fnai2@shlinux89 \
--to=peng.fan@oss.nxp.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=jpb@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nicolinc@nvidia.com \
--cc=peng.fan@nxp.com \
--cc=robin.murphy@arm.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®