mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v1 0/4] iommu: Fix attach handle publication ordering
@ 2026-09-29 21:51 Nicolin Chen
  2026-09-29 21:51 ` [PATCH v1 1/4] iommu: Unpublish the attach handle before the group detach callback Nicolin Chen
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Nicolin Chen @ 2026-09-29 21:51 UTC (permalink / raw)
  To: joro, Lu Baolu, Jason Gunthorpe
  Cc: Will Deacon, Robin Murphy, Kevin Tian, Jean-Philippe Brucker,
	Yi Liu, iommu, linux-kernel

Jason pointed out an issue in the attach handle replacing path:
https://lore.kernel.org/linux-iommu/20260923233920.GJ2545495@nvidia.com/

When an attachment is detached or replaced, the IOMMU core can still leave
the outgoing attach handle published while calling into the driver. A fault
report looks up the handle without the group mutex, so it can find the old
handle after the driver's fault flush and just before the caller frees it.

These four patches unpublish the outgoing handle before a driver callback
for both group and PASID detach and replace operations. Both replace paths
store XA_ZERO_ENTRY to reserve the slot and restore the old entry on error.

This blocks new lookups, but does not retire a fault that already obtained
the old handle. The driver must still synchronize those readers before the
handle is freed. A same-domain replacement skips the driver callback, so it
still needs a separate lifetime mechanism or fence.

This is on GitHub:
https://github.com/nicolinc/iommufd/commits/fix_iommu_attach_handle-v1

Nicolin Chen (4):
  iommu: Unpublish the attach handle before the group detach callback
  iommu: Unpublish the attach handle before the PASID detach callback
  iommu: Unpublish the old attach handle before the group replace
    callback
  iommu: Unpublish the old attach handle before the PASID replace
    callback

 drivers/iommu/iommu.c | 54 ++++++++++++++++++++++++++++---------------
 1 file changed, 35 insertions(+), 19 deletions(-)


base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
-- 
2.43.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-29 21:52 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29 21:51 [PATCH v1 0/4] iommu: Fix attach handle publication ordering Nicolin Chen
2026-09-29 21:51 ` [PATCH v1 1/4] iommu: Unpublish the attach handle before the group detach callback Nicolin Chen
2026-09-29 21:51 ` [PATCH v1 2/4] iommu: Unpublish the attach handle before the PASID " Nicolin Chen
2026-09-29 21:51 ` [PATCH v1 3/4] iommu: Unpublish the old attach handle before the group replace callback Nicolin Chen
2026-09-29 21:51 ` [PATCH v1 4/4] iommu: Unpublish the old attach handle before the PASID " Nicolin Chen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®