All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Suthikulpanit, Suravee" <suravee.suthikulpanit@amd.com>
To: "guanghuifeng@linux.alibaba.com" <guanghuifeng@linux.alibaba.com>,
	linux-kernel@vger.kernel.org, iommu@lists.linux.dev,
	joro@8bytes.org, jgg@nvidia.com
Cc: yi.l.liu@intel.com, kevin.tian@intel.com, nicolinc@nvidia.com,
	vasant.hegde@amd.com, jon.grimm@amd.com, santosh.shukla@amd.com,
	Sairaj.K@amd.com, jay.chen@amd.com, wvw@google.com,
	wnliu@google.com, dantuluris@google.com, chriscli@google.com,
	kpsingh@google.com, alejandro.j.jimenez@oracle.com,
	joao.m.martins@oracle.com
Subject: Re: [PATCH 17/24] iommu/amd: Introduce helper function for updating domain ID mapping table
Date: Thu, 3 Sep 2026 10:26:10 +0700	[thread overview]
Message-ID: <8781af88-6006-4604-93d8-82b9b67269f3@amd.com> (raw)
In-Reply-To: <c5f7f26f-ea3f-48a8-a2ac-5320155fd824@linux.alibaba.com>



On 8/19/2026 5:45 PM, guanghuifeng@linux.alibaba.com wrote:
>> diff --git a/drivers/iommu/amd/viommu.c b/drivers/iommu/amd/viommu.c
>> index 91d0dd3ac912..708f2c7496a4 100644
>> --- a/drivers/iommu/amd/viommu.c
>> +++ b/drivers/iommu/amd/viommu.c
>> @@ -40,6 +40,8 @@
>>   #define VIOMMU_DOMID_MAPPING_BASE    0x2000000000ULL
>>   #define VIOMMU_DOMID_MAPPING_ENTRY_SIZE    (1 << 19)
>> +#define VIOMMU_VFCTRL_GUEST_DID_MAP_CONTROL1_OFFSET    0x08
>> +
>>   LIST_HEAD(viommu_devid_map);
>>   static int viommu_init_pci_vsc(struct amd_iommu *iommu)
>> @@ -420,6 +422,22 @@ static void __maybe_unused 
>> free_private_vm_region(struct amd_iommu *iommu, u64 *
>>       *entry = NULL;
>>   }
>> +static void viommu_clear_mapping(struct amd_iommu *iommu,
>> +                 struct amd_iommu_viommu *aviommu)
>> +{
>> +    int i;
>> +    u16 gid = aviommu->gid;
>> +
>> +    /*
>> +     * IOMMU hardware uses the domain ID mapping table to map gdom ID 
>> to hdom ID.
>> +     * If the mapping does not exist, the hardware would generate 
>> error in the event log.
>> +     * Therefore, initialize all gdom ID entries to map to parent 
>> domain ID to prevent
>> +     * unknown mapping scenario.
>> +     */
>> +    for (i = 0; i <= VIOMMU_MAX_GDOMID; i++)
>> +        amd_viommu_domain_id_update(iommu, gid, aviommu->parent->id, i);
>> +}
>> +
>>   void amd_viommu_uninit_one(struct amd_iommu *iommu, struct 
>> amd_iommu_viommu *aviommu)
>>   {
>>       pr_debug("%s: gid=%u\n", __func__, aviommu->gid);
>> @@ -432,6 +450,7 @@ void amd_viommu_uninit_one(struct amd_iommu 
>> *iommu, struct amd_iommu_viommu *avi
>>                      VIOMMU_DOMID_MAPPING_BASE,
>>                      VIOMMU_DOMID_MAPPING_ENTRY_SIZE,
>>                      aviommu->gid);
>> +    viommu_clear_mapping(iommu, aviommu);
>>   }
> 
> Use-after-free in vIOMMU teardown ordering
> The teardown path releases the DevID/DomID mapping table memory
> BEFORE resetting the vIOMMU state:
> 
>       free_private_vm_region(iommu, &aviommu->devid_table, ...);
>       free_private_vm_region(iommu, &aviommu->domid_table, ...);
>       ...
>       viommu_clear_mapping(iommu, aviommu);   /* too late */
> 
>     Since the IOMMU hardware may still reference these tables until the
>     guest vIOMMU state is reset, freeing the backing memory first can
>     result in a use-after-free by hardware.

Thanks. Fixing in v5.

Suravee

  reply	other threads:[~2026-09-03  3:27 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 13:28 [PATCH v4 00/24] iommu/amd: Introduce AMD Hardware-accelerated Virtualized IOMMU (vIOMMU) Support Suravee Suthikulpanit
2026-07-27 13:28 ` [PATCH 01/24] iommu/amd: Make amd_iommu_completion_wait() non-static Suravee Suthikulpanit
2026-08-05 17:01   ` Vasant Hegde
2026-09-01  7:56     ` Suthikulpanit, Suravee
2026-07-27 13:28 ` [PATCH 02/24] iommu/amd: Introduce vIOMMU-specific events and event Suravee Suthikulpanit
2026-08-10  7:12   ` Vasant Hegde
2026-09-01  8:28     ` Suthikulpanit, Suravee
2026-08-19  8:17   ` guanghuifeng
2026-09-01 14:21     ` Suthikulpanit, Suravee
2026-07-27 13:28 ` [PATCH 03/24] iommu/amd: Detect and initialize AMD vIOMMU feature Suravee Suthikulpanit
2026-08-10  8:13   ` Vasant Hegde
2026-09-01 16:32     ` Suthikulpanit, Suravee
2026-07-27 13:28 ` [PATCH 04/24] iommu/amd: Introduce IOMMUFD vIOMMU support for AMD Suravee Suthikulpanit
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:28 ` [PATCH 05/24] iommu/amd: Allocate Guest IDs for IOMMUFD vIOMMU instances Suravee Suthikulpanit
2026-08-10  9:21   ` Vasant Hegde
2026-09-02  7:49     ` Suthikulpanit, Suravee
2026-08-24 17:24   ` Jason Gunthorpe
2026-09-02  7:50     ` Suthikulpanit, Suravee
2026-07-27 13:28 ` [PATCH 06/24] iommu/amd: Map vIOMMU VF and VF Control MMIO BARs Suravee Suthikulpanit
2026-08-10 10:00   ` Vasant Hegde
2026-09-02 12:16     ` Suthikulpanit, Suravee
2026-08-19 13:18   ` guanghuifeng
2026-09-02 12:16     ` Suthikulpanit, Suravee
2026-07-27 13:28 ` [PATCH 07/24] iommu/amd: Add support for AMD vIOMMU VF MMIO region Suravee Suthikulpanit
2026-08-10 10:49   ` Vasant Hegde
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:28 ` [PATCH 08/24] iommu/amd: Introduce Reset vMMIO Command Suravee Suthikulpanit
2026-08-19  8:34   ` guanghuifeng
2026-09-02 22:33     ` Suthikulpanit, Suravee
2026-07-27 13:28 ` [PATCH 09/24] iommu/amd: Introduce and map vIOMMU private IPA region Suravee Suthikulpanit
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:28 ` [PATCH 10/24] iommu/amd: Pass iommu to device_flush_dte() Suravee Suthikulpanit
2026-08-10 11:07   ` Vasant Hegde
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:29 ` [PATCH 11/24] iommu/amd: Export amd_iommu_alloc_dev_data() helper Suravee Suthikulpanit
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:29 ` [PATCH 12/24] iommu/amd: Pass iommu and devid to amd_iommu_make_clear_dte() Suravee Suthikulpanit
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:29 ` [PATCH 13/24] iommu/amd: Assign IOMMU Private Address domain to IOMMU Suravee Suthikulpanit
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:29 ` [PATCH 14/24] iommu/amd: Add per-VM private IPA alloc/map helpers Suravee Suthikulpanit
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:29 ` [PATCH 15/24] iommu/amd: Add helper functions to manage DevID / DomID mapping tables Suravee Suthikulpanit
2026-08-19 13:30   ` guanghuifeng
2026-09-03  0:41     ` Suthikulpanit, Suravee
2026-07-27 13:29 ` [PATCH 16/24] iommu/amd: Introduce IOMMUFD vDevice support for AMD Suravee Suthikulpanit
2026-08-19 13:34   ` guanghuifeng
2026-09-03  2:41     ` Suthikulpanit, Suravee
2026-08-24 17:24   ` Jason Gunthorpe
2026-07-27 13:29 ` [PATCH 17/24] iommu/amd: Introduce helper function for updating domain ID mapping table Suravee Suthikulpanit
2026-08-19 10:45   ` guanghuifeng
2026-09-03  3:26     ` Suthikulpanit, Suravee [this message]
2026-07-27 13:29 ` [PATCH 18/24] iommu/amd: Introduce helper function for updating device " Suravee Suthikulpanit
2026-08-10 15:17   ` Vasant Hegde
2026-09-03  3:19     ` Suthikulpanit, Suravee
2026-08-19 10:26   ` guanghuifeng
2026-07-27 13:29 ` [PATCH 19/24] iommu/amd: Add per-segment translate device ID pool Suravee Suthikulpanit
2026-07-27 13:29 ` [PATCH 20/24] iommu/amd: Reserve translate-device-id for PCI requestor aliases Suravee Suthikulpanit
2026-07-27 13:29 ` [PATCH 21/24] iommu/amd: Add translation DTE and VFctrl TransDevID helpers Suravee Suthikulpanit
2026-07-27 13:29 ` [PATCH 22/24] iommu/amd: Add translate-device-id alloc/free with vIOMMU owner Suravee Suthikulpanit
2026-07-27 13:29 ` [PATCH 23/24] iommu/amd: Assign per-vIOMMU translate device ID Suravee Suthikulpanit
2026-08-19 10:18   ` guanghuifeng
2026-07-27 13:29 ` [PATCH 24/24] iommu/amd: Relocate vIOMMU translate-device-id on PCI reserve Suravee Suthikulpanit
2026-08-19  9:42   ` guanghuifeng
2026-09-03  3:56     ` Suthikulpanit, Suravee
2026-08-11  7:18 ` [PATCH v4 00/24] iommu/amd: Introduce AMD Hardware-accelerated Virtualized IOMMU (vIOMMU) Support Tian, Kevin
2026-08-24 17:24 ` Jason Gunthorpe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8781af88-6006-4604-93d8-82b9b67269f3@amd.com \
    --to=suravee.suthikulpanit@amd.com \
    --cc=Sairaj.K@amd.com \
    --cc=alejandro.j.jimenez@oracle.com \
    --cc=chriscli@google.com \
    --cc=dantuluris@google.com \
    --cc=guanghuifeng@linux.alibaba.com \
    --cc=iommu@lists.linux.dev \
    --cc=jay.chen@amd.com \
    --cc=jgg@nvidia.com \
    --cc=joao.m.martins@oracle.com \
    --cc=jon.grimm@amd.com \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=kpsingh@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nicolinc@nvidia.com \
    --cc=santosh.shukla@amd.com \
    --cc=vasant.hegde@amd.com \
    --cc=wnliu@google.com \
    --cc=wvw@google.com \
    --cc=yi.l.liu@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.