All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Roman Vivchar" <rva333@protonmail.com>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org, robh@kernel.org
Subject: Re: [PATCH 2/3] iommu/mediatek-v1: fix IOMMU device binding
Date: Wed, 09 Sep 2026 14:30:12 +0000	[thread overview]
Message-ID: <20260909143012.8D40D1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260909-6572-iommu-v1-2-de261da09fb2@protonmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Moving `mtk_iommu_v1_create_mapping()` into `mtk_iommu_v1_probe_finalize()` introduces a data race that can corrupt the shared IOMMU mapping and domain, leading to memory leaks and incorrect domain assignments.
--

commit 506d7ce15633b781671040d746cf03c5adc6f9ca
Author: Roman Vivchar <rva333@protonmail.com>

iommu/mediatek-v1: fix IOMMU device binding

The driver silently fails to bind devices, causing DRM to fall back to PA mode.
This patch provides an of_xlate callback to properly bind devices and use VA
mode.

> diff --git a/drivers/iommu/mtk_iommu_v1.c b/drivers/iommu/mtk_iommu_v1.c
> index ac97dd2868d4b..72355f41c36af 100644
> --- a/drivers/iommu/mtk_iommu_v1.c
> +++ b/drivers/iommu/mtk_iommu_v1.c

[ ... ]

> @@ -519,9 +476,15 @@ static void mtk_iommu_v1_probe_finalize(struct device *dev)
>  	__maybe_unused struct mtk_iommu_v1_data *data = dev_iommu_priv_get(dev);
>  	int err;
>  
> +	err = mtk_iommu_v1_create_mapping(dev);

[Severity: High]
Does moving the call to mtk_iommu_v1_create_mapping() into
mtk_iommu_v1_probe_finalize() introduce a data race?

Previously, this was called from mtk_iommu_v1_probe_device(), which executes
under the iommu_probe_device_lock.  By moving it here, it executes without
synchronization.

If two client devices of the same MTK IOMMU probe concurrently (e.g., via
asynchronous probing or deferred probe), they can race in
mtk_iommu_v1_create_mapping():

drivers/iommu/mtk_iommu_v1.c:mtk_iommu_v1_create_mapping() {
        ...
        data = dev_iommu_priv_get(dev);
        mtk_mapping = data->mapping;
        if (!mtk_mapping) {
                /* MTK iommu support 4GB iova address space. */
                mtk_mapping = arm_iommu_create_mapping(dev, 0, 1ULL << 32);
                if (IS_ERR(mtk_mapping))
                        return PTR_ERR(mtk_mapping);

                data->mapping = mtk_mapping;
        }
        ...
}

Can this lead to a memory leak of the initial mapping and DMA failures for
the racing client device, as it might get attached to a software domain
that does not match the hardware page tables?

> +	if (err) {
> +		dev_err(dev, "Can't create IOMMU mapping - DMA-OPS will not work\n");
> +		return;
> +	}
> +
>  	err = arm_iommu_attach_device(dev, data->mapping);
>  	if (err)
> -		dev_err(dev, "Can't create IOMMU mapping - DMA-OPS will not work\n");
> +		dev_err(dev, "Can't attach to IOMMU mapping - DMA-OPS will not work\n");
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260909-6572-iommu-v1-0-de261da09fb2@protonmail.com?part=2

  reply	other threads:[~2026-09-09 14:30 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 14:14 [PATCH 0/3] iommu/mediatek-v1: fix the driver + mt6572 support Roman Vivchar
2026-09-09 14:14 ` Roman Vivchar via B4 Relay
2026-09-09 14:14 ` [PATCH 1/3] dt-bindings: iommu: mediatek: add mt6572 Roman Vivchar
2026-09-09 14:14   ` Roman Vivchar via B4 Relay
2026-09-09 14:22   ` sashiko-bot
2026-09-11  7:27   ` Krzysztof Kozlowski
2026-09-09 14:14 ` [PATCH 2/3] iommu/mediatek-v1: fix IOMMU device binding Roman Vivchar
2026-09-09 14:14   ` Roman Vivchar via B4 Relay
2026-09-09 14:30   ` sashiko-bot [this message]
2026-09-09 14:14 ` [PATCH 3/3] iommu/mediatek-v1: add mt6572 support Roman Vivchar
2026-09-09 14:14   ` Roman Vivchar via B4 Relay
2026-09-09 14:32   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909143012.8D40D1F00A3D@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=rva333@protonmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.