All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lu Baolu <baolu.lu@linux.intel.com>
To: Joerg Roedel <joro@8bytes.org>
Cc: ZhaoJinming <zhaojinming@uniontech.com>,
	Kevin Tian <kevin.tian@intel.com>,
	Dmitry Antipov <dmantipov@yandex.ru>,
	Guanghui Feng <guanghuifeng@linux.alibaba.com>,
	Li RongQing <lirongqing@baidu.com>,
	Desnes Nunes <desnesn@redhat.com>,
	iommu@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: [PATCH 15/20] iommu/vt-d: Fix copied_tables bitmap leak on error in copy_translation_tables
Date: Tue,  4 Aug 2026 10:37:09 +0800	[thread overview]
Message-ID: <20260804023714.3080506-16-baolu.lu@linux.intel.com> (raw)
In-Reply-To: <20260804023714.3080506-1-baolu.lu@linux.intel.com>

From: ZhaoJinming <zhaojinming@uniontech.com>

The iommu->copied_tables bitmap was introduced by the IOMMU live
update series to track which context entries have been copied from
the previous kernel.  The allocation via bitmap_zalloc() was added
inside copy_translation_tables(), but the error paths were not
updated to free it:

  1. When old_rt_phys is 0 (invalid root table address)
  2. When memremap(old_rt_phys) fails
  3. When kcalloc for ctxt_tbls fails (goto out_unmap, which only
     unmaps old_rt without releasing the bitmap)

The bitmap is only cleaned up by free_dmar_iommu(), which is
called from the free_iommu error label in init_dmars().  However,
when copy_translation_tables() fails, init_dmars() does not jump
to free_iommu -- it logs the error, falls through, and continues
with the next IOMMU.  As a result, copied_tables is leaked.

Fix this by converting the two early returns to goto a new
err_free_bitmap label, and by making out_unmap fall through to
it so that the bitmap is always freed on any error path.  The
success path performs memunmap(old_rt) inline and returns 0
directly, since copied_tables must remain allocated for
subsequent use.

Signed-off-by: ZhaoJinming <zhaojinming@uniontech.com>
Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
---
 drivers/iommu/intel/iommu.c | 19 +++++++++++++------
 1 file changed, 13 insertions(+), 6 deletions(-)

diff --git a/drivers/iommu/intel/iommu.c b/drivers/iommu/intel/iommu.c
index 5ea584b76f77..7098a6bf6a40 100644
--- a/drivers/iommu/intel/iommu.c
+++ b/drivers/iommu/intel/iommu.c
@@ -1557,12 +1557,16 @@ static int copy_translation_tables(struct intel_iommu *iommu)
 		return -ENOMEM;
 
 	old_rt_phys = rtaddr_reg & VTD_PAGE_MASK;
-	if (!old_rt_phys)
-		return -EINVAL;
+	if (!old_rt_phys) {
+		ret = -EINVAL;
+		goto err_free_bitmap;
+	}
 
 	old_rt = memremap(old_rt_phys, PAGE_SIZE, MEMREMAP_WB);
-	if (!old_rt)
-		return -ENOMEM;
+	if (!old_rt) {
+		ret = -ENOMEM;
+		goto err_free_bitmap;
+	}
 
 	/* This is too big for the stack - allocate it from slab */
 	ctxt_table_entries = ext ? 512 : 256;
@@ -1606,11 +1610,14 @@ static int copy_translation_tables(struct intel_iommu *iommu)
 
 	__iommu_flush_cache(iommu, iommu->root_entry, PAGE_SIZE);
 
-	ret = 0;
+	memunmap(old_rt);
+	return 0;
 
 out_unmap:
 	memunmap(old_rt);
-
+err_free_bitmap:
+	bitmap_free(iommu->copied_tables);
+	iommu->copied_tables = NULL;
 	return ret;
 }
 
-- 
2.43.0


  parent reply	other threads:[~2026-08-04  2:48 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04  2:36 [PATCH 00/20] [PULL REQUEST] Intel IOMMU updates for v7.3 Lu Baolu
2026-08-04  2:36 ` [PATCH 01/20] iommu/vt-d: Fix UCTP context table slot when copying root entries Lu Baolu
2026-08-04  2:36 ` [PATCH 02/20] iommu/vt-d: Use logical OR operator for privilege mode check Lu Baolu
2026-08-04  2:36 ` [PATCH 03/20] iommu/vt-d: Fix CACHE_TAG_NESTING_DEVTLB polluting shared variables in flush loop Lu Baolu
2026-08-04  3:16   ` 答复: [外部邮件] " Li,Rongqing
2026-08-04  5:28     ` Baolu Lu
2026-08-04  7:18       ` Baolu Lu
2026-08-04  2:36 ` [PATCH 04/20] iommu/vt-d: Use kstrtoint_from_user() in dmar_perf_latency_write() Lu Baolu
2026-08-04  2:36 ` [PATCH 05/20] iommu/vt-d: Fix no_iommu to disable platform opt-in Lu Baolu
2026-08-04  2:37 ` [PATCH 06/20] iommu/vt-d: Force requesting ACS when tboot is enabled Lu Baolu
2026-08-04  2:37 ` [PATCH 07/20] iommu/vt-d: Remove dead code when CONFIG_INTEL_IOMMU is not set Lu Baolu
2026-08-04  2:37 ` [PATCH 08/20] iommu/vt-d: Consolidate dmar policy management and force_on logic Lu Baolu
2026-08-04  2:37 ` [PATCH 09/20] iommu/vt-d: Use dmar_can_force_on() for platform opt-in Lu Baolu
2026-08-04  2:37 ` [PATCH 10/20] iommu/vt-d: Call dmar_can_force_on() for tboot opt-in Lu Baolu
2026-08-04  2:37 ` [PATCH 11/20] iommu/vt-d: Remove the 'force_on' variable Lu Baolu
2026-08-04  2:37 ` [PATCH 12/20] iommu/vt-d: Remove dmar_disabled Lu Baolu
2026-08-04  2:37 ` [PATCH 13/20] iommu/vt-d: Support the new DMA_REMAP_OPT_OUT flag bit Lu Baolu
2026-08-04  2:37 ` [PATCH 14/20] iommu/vt-d: Cache max domain ID to avoid redundant calculation Lu Baolu
2026-08-04  2:37 ` Lu Baolu [this message]
2026-08-04  2:37 ` [PATCH 16/20] iommu/vt-d: Fix shift overflow in qi_desc_dev_iotlb_pasid() Lu Baolu
2026-08-04  5:54   ` Baolu Lu
2026-08-04  2:37 ` [PATCH 17/20] iommu/vt-d: Clear Present bit before tearing down copied context entry Lu Baolu
2026-08-04  2:37 ` [PATCH 18/20] iommu/vt-d: Fix iopf_refcount leak on RID domain replacement Lu Baolu
2026-08-04  2:37 ` [PATCH 19/20] iommu/vt-d: Tear down scalable-mode context on probe failure Lu Baolu
2026-08-04  2:37 ` [PATCH 20/20] iommu/vt-d: Flush context cache with correct SID when tearing down aliases Lu Baolu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260804023714.3080506-16-baolu.lu@linux.intel.com \
    --to=baolu.lu@linux.intel.com \
    --cc=desnesn@redhat.com \
    --cc=dmantipov@yandex.ru \
    --cc=guanghuifeng@linux.alibaba.com \
    --cc=iommu@lists.linux.dev \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lirongqing@baidu.com \
    --cc=zhaojinming@uniontech.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.