From: Nicolin Chen <nicolinc@nvidia.com>
To: Robin Murphy <robin.murphy@arm.com>
Cc: Jason Gunthorpe <jgg@nvidia.com>, <iommu@lists.linux.dev>,
Joerg Roedel <joro@8bytes.org>, Kevin Tian <kevin.tian@intel.com>,
<linux-kselftest@vger.kernel.org>, Shuah Khan <shuah@kernel.org>,
Will Deacon <will@kernel.org>,
Lixiao Yang <lixiao.yang@intel.com>,
Matthew Rosato <mjrosato@linux.ibm.com>,
<patches@lists.linux.dev>, <stable@vger.kernel.org>,
<syzbot+c2f65e2801743ca64e08@syzkaller.appspotmail.com>,
Yi Liu <yi.l.liu@intel.com>
Subject: Re: [PATCH 2/2] iommufd/selftest: Test reserved regions near ULONG_MAX
Date: Fri, 18 Jul 2025 11:50:30 -0700 [thread overview]
Message-ID: <aHqXdjJbuO4e7r+X@Asurada-Nvidia> (raw)
In-Reply-To: <d18d7013-e82e-456a-87da-8acffc90d8db@arm.com>
On Fri, Jul 18, 2025 at 07:23:25PM +0100, Robin Murphy wrote:
> On 2025-07-18 9:13 am, Nicolin Chen wrote:
> > On Thu, Jul 17, 2025 at 07:45:51PM -0700, Nicolin Chen wrote:
> > > On Thu, Jul 17, 2025 at 04:15:09PM -0300, Jason Gunthorpe wrote:
> > >
> > > > +TEST_F(iommufd_ioas, reserved_overflow)
> > > > +{
> > > > + struct iommu_test_cmd test_cmd = {
> > > > + .size = sizeof(test_cmd),
> > > > + .op = IOMMU_TEST_OP_ADD_RESERVED,
> > > > + .id = self->ioas_id,
> > > > + .add_reserved = { .start = 6,
> > > > + .length = 0xffffffffffff8001 },
> > > > + };
> > > > + __u64 iova;
> > > > +
> > > > + ASSERT_EQ(0,
> > > > + ioctl(self->fd, _IOMMU_TEST_CMD(IOMMU_TEST_OP_ADD_RESERVED),
> > > > + &test_cmd));
> > > > + test_err_ioctl_ioas_map(ENOSPC, buffer, 0x5000, &iova);
> > >
> > > When:
> > > PAGE_SIZE=SZ_64K = 0x10000
> > > MOCK_PAGE_SIZE = PAGE_SIZE / 2 = 0x8000
> > >
> > > This likely fails the alignment test, returning -EINVAL instead:
> > >
> > > # iommufd.c:988:reserved_overflow:Expected 28 (28) == errno (22)
> > > # reserved_overflow: Test failed
> > > # FAIL iommufd_ioas.mock_domain_limit.reserved_overflow
> > >
> > > So, I think we'd have to pick a number aligned to MOCK_PAGE_SIZE?
> > > e.g. changing to 0x18000 for example can pass.
> >
> > I realized that we can't change the number as it won't reproduce
> > on PAGE_SIZE=4K. So, perhaps it should just SKIP other page sizes
> > than 4K.
>
> Shouldn't it work to parametrise both numbers accordingly, e.g. (if my
> Friday-evening maths holds up) reserve "1UL - MOCK_PAGE_SIZE * 16" then map
> "MOCK_PAGE_SIZE * 10"?
Ah, you are right, I forgot to change the reserved range.
0xfffffffffff80001 and 0x50000 could repro with 64K pages,
exactly what your math works :)
Thanks
Nicolin
next prev parent reply other threads:[~2025-07-18 18:50 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-17 19:15 [PATCH 0/2] Fix undetected overflow when allocating IOVA Jason Gunthorpe
2025-07-17 19:15 ` [PATCH 1/2] iommufd: Prevent ALIGN() overflow Jason Gunthorpe
2025-07-18 8:16 ` Nicolin Chen
2025-07-18 13:03 ` Yi Liu
2025-07-17 19:15 ` [PATCH 2/2] iommufd/selftest: Test reserved regions near ULONG_MAX Jason Gunthorpe
2025-07-17 19:15 ` kernel test robot
2025-07-18 2:45 ` Nicolin Chen
2025-07-18 8:13 ` Nicolin Chen
2025-07-18 16:21 ` Jason Gunthorpe
2025-07-18 18:23 ` Robin Murphy
2025-07-18 18:50 ` Nicolin Chen [this message]
2025-07-18 20:16 ` Jason Gunthorpe
2025-07-18 19:56 ` Jason Gunthorpe
2025-07-18 13:03 ` Yi Liu
2025-07-18 18:10 ` [PATCH 0/2] Fix undetected overflow when allocating IOVA Nicolin Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aHqXdjJbuO4e7r+X@Asurada-Nvidia \
--to=nicolinc@nvidia.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@nvidia.com \
--cc=joro@8bytes.org \
--cc=kevin.tian@intel.com \
--cc=linux-kselftest@vger.kernel.org \
--cc=lixiao.yang@intel.com \
--cc=mjrosato@linux.ibm.com \
--cc=patches@lists.linux.dev \
--cc=robin.murphy@arm.com \
--cc=shuah@kernel.org \
--cc=stable@vger.kernel.org \
--cc=syzbot+c2f65e2801743ca64e08@syzkaller.appspotmail.com \
--cc=will@kernel.org \
--cc=yi.l.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.