From: sashiko-bot@kernel.org
To: "Leon Romanovsky" <leon@kernel.org>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v2 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk
Date: Thu, 06 Aug 2026 11:44:32 +0000 [thread overview]
Message-ID: <20260806114433.D9FA81F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260806-fix-p2p-acs-v2-12-0cec14812965@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] pci_p2pdma_release() skips synchronize_rcu() when p2pdma->pool is NULL, leading to a Use-After-Free of the pci_p2pdma struct and its XArray inside RCU read-side critical sections.
--
--- Patch [12]: [PATCH v2 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk ---
commit c4a68b62f4ec894cc35240eda46bf42dc5f562d9
Author: Leon Romanovsky <leon@kernel.org>
PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk
Extend the ACS KUnit suite with end-to-end coverage of
calc_map_type_and_dist(), the provider-to-client hierarchy walk.
> diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
> index c7680964d8a64..18e5339bc49e9 100644
> --- a/drivers/pci/p2pdma.c
> +++ b/drivers/pci/p2pdma.c
[ ... ]
> @@ -859,6 +859,7 @@ calc_map_type_and_dist(struct pci_dev *provider, struct pci_dev *client,
> rcu_read_unlock();
> return map_type;
> }
> +EXPORT_SYMBOL_IF_KUNIT(calc_map_type_and_dist);
[Severity: High]
This is a pre-existing issue, but does this code have a race condition
leading to a use-after-free when interacting with pci_p2pdma_release()?
If a device acts as a P2PDMA provider without setting up an allocator pool
(for example, via vfio-pci or mlx5), pci_p2pdma_release() skips
synchronize_rcu() because p2pdma->pool is NULL:
drivers/pci/p2pdma.c:pci_p2pdma_release() {
...
if (p2pdma->pool)
synchronize_rcu();
...
}
When the provider driver is unbound, devres frees the pci_p2pdma structure
and destroys the XArray. Concurrently, calc_map_type_and_dist() executing
here inside its RCU read-side critical section can dereference the freed
p2pdma pointer and call xa_store() on the destroyed XArray.
Should synchronize_rcu() be called during release regardless of whether
the allocator pool is set up?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-fix-p2p-acs-v2-0-0cec14812965@nvidia.com?part=12
next prev parent reply other threads:[~2026-08-06 11:44 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 11:24 [PATCH v2 00/13] PCI/P2PDMA: Fix ACS egress control handling Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 01/13] PCI/P2PDMA: Safely terminate ACS redirect lists Leon Romanovsky
2026-08-06 11:32 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 02/13] PCI/P2PDMA: Report ACS ports when the paths share no upstream bridge Leon Romanovsky
2026-08-06 11:37 ` sashiko-bot
2026-08-07 14:35 ` Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 03/13] PCI/P2PDMA: Document the Address Type assumption Leon Romanovsky
2026-08-06 11:28 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 04/13] PCI: Account for Direct Translated P2P in ACS isolation checks Leon Romanovsky
2026-08-06 11:35 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 05/13] PCI: Add ACS egress control vector accessor Leon Romanovsky
2026-08-06 11:39 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 06/13] PCI: Account for ACS egress control in isolation checks Leon Romanovsky
2026-08-06 11:40 ` sashiko-bot
2026-08-07 16:07 ` Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 07/13] PCI/P2PDMA: Derive peer-to-peer routing from ACS control bits Leon Romanovsky
2026-08-06 11:33 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 08/13] PCI/P2PDMA: Honor ACS egress control vectors Leon Romanovsky
2026-08-06 11:47 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 09/13] PCI/P2PDMA: Document ACS egress control handling Leon Romanovsky
2026-08-06 11:29 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 10/13] PCI/P2PDMA: Extract pure ACS routing decision helpers Leon Romanovsky
2026-08-06 11:34 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 11/13] PCI/P2PDMA: Add KUnit tests for ACS routing decisions Leon Romanovsky
2026-08-06 11:34 ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk Leon Romanovsky
2026-08-06 11:44 ` sashiko-bot [this message]
2026-08-07 13:02 ` Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 13/13] PCI: Add KUnit coverage for ACS isolation checks Leon Romanovsky
2026-08-06 11:37 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260806114433.D9FA81F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=leon@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.