All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jason Gunthorpe <jgg@nvidia.com>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: iommu@lists.linux.dev, kvm@vger.kernel.org,
	linux-kernel@vger.kernel.org, Kevin Tian <kevin.tian@intel.com>
Subject: [GIT PULL] Please pull IOMMUFD subsystem changes
Date: Thu, 30 Jul 2026 18:34:59 -0300	[thread overview]
Message-ID: <amvDg1M6+Wu3HwSr@nvidia.com> (raw)

[-- Attachment #1: Type: text/plain, Size: 2065 bytes --]

Hi Linus,

Collection of bugs for iommufd. It seems there has been some
additional bug detections by a non-Google syzkaller, along with some
AI stuff.

Thanks,
Jason

The following changes since commit a13c140cc289c0b7b3770bce5b3ad42ab35074aa:

  Linux 7.2-rc3 (2026-07-12 14:16:39 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/jgg/iommufd.git tags/for-linus-iommufd

for you to fetch changes up to 738e6f32e61d80b554e37015ecb7bc620b88001c:

  iommu/iommufd: Fix IOPF group ownership UAF (2026-07-26 13:16:21 -0300)

----------------------------------------------------------------
iommufd v7.2 first rc pull request

Several bug fixes found by tools and fuzzing:

- Incorrect domain passed during replace to ack faults

- Block the access API from using dmabuf

- Missing unlock on error unwind

- Race seeing a partially setup vdevice in the xarray

- Do not allow vdevices to have multiple stream ids in SMMUv3

- Possible UAF if racing faults with domain changes

----------------------------------------------------------------
Nicolin Chen (3):
      iommufd/viommu: Release the igroup lock on the vdevice_size error path
      iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
      iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE

Peiyang He (3):
      iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
      iommufd: Reject DMABUF pages from the access pin path
      iommu/iommufd: Fix IOPF group ownership UAF

 .../iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c    | 15 ++++++++++++++
 drivers/iommu/io-pgfault.c                         | 24 +++++++++++++++++-----
 drivers/iommu/iommufd/device.c                     |  2 +-
 drivers/iommu/iommufd/eventq.c                     |  2 ++
 drivers/iommu/iommufd/pages.c                      |  3 +++
 drivers/iommu/iommufd/viommu.c                     | 22 ++++++++++++++------
 include/linux/iommu.h                              |  5 +++++
 7 files changed, 61 insertions(+), 12 deletions(-)

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

             reply	other threads:[~2026-07-30 21:35 UTC|newest]

Thread overview: 72+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30 21:34 Jason Gunthorpe [this message]
2026-07-30 22:15 ` [GIT PULL] Please pull IOMMUFD subsystem changes pr-tracker-bot
  -- strict thread matches above, loose matches on Subject: below --
2026-08-18 20:36 Jason Gunthorpe
2026-06-17 17:30 Jason Gunthorpe
2026-06-17 19:40 ` pr-tracker-bot
2026-04-16 17:33 Jason Gunthorpe
2026-04-17  4:27 ` pr-tracker-bot
2026-01-30 23:41 Jason Gunthorpe
2026-01-31  1:20 ` pr-tracker-bot
2025-12-18 18:52 Jason Gunthorpe
2025-12-18 20:39 ` pr-tracker-bot
2025-12-02 17:50 Jason Gunthorpe
2025-12-05  3:01 ` pr-tracker-bot
2025-11-25 15:09 Jason Gunthorpe
2025-11-25 16:38 ` pr-tracker-bot
2025-11-07 18:51 Jason Gunthorpe
2025-11-07 21:21 ` pr-tracker-bot
2025-10-02 14:29 Jason Gunthorpe
2025-10-04  1:40 ` pr-tracker-bot
2025-09-22 14:33 Jason Gunthorpe
2025-09-22 18:27 ` pr-tracker-bot
2025-08-22 14:21 Jason Gunthorpe
2025-08-22 21:28 ` pr-tracker-bot
2025-07-30 18:47 Jason Gunthorpe
2025-07-31 20:01 ` pr-tracker-bot
2025-07-02 14:14 Jason Gunthorpe
2025-07-02 17:06 ` pr-tracker-bot
2025-03-31 16:12 Jason Gunthorpe
2025-04-02  1:50 ` pr-tracker-bot
2025-01-23 16:59 Jason Gunthorpe
2025-01-24 21:45 ` pr-tracker-bot
2024-12-05 18:44 Jason Gunthorpe
2024-12-05 23:08 ` pr-tracker-bot
2024-11-20 14:53 Jason Gunthorpe
2024-11-21 21:20 ` pr-tracker-bot
2024-09-23 17:45 Jason Gunthorpe
2024-09-24 19:36 ` pr-tracker-bot
2024-08-20 22:48 Jason Gunthorpe
2024-08-20 23:52 ` pr-tracker-bot
2024-07-17 18:46 Jason Gunthorpe
2024-07-19 18:09 ` pr-tracker-bot
2024-04-19 17:29 Jason Gunthorpe
2024-04-19 21:07 ` pr-tracker-bot
2024-03-02  0:08 Jason Gunthorpe
2024-03-02  1:31 ` pr-tracker-bot
2024-02-22 13:23 Jason Gunthorpe
2024-02-22 20:03 ` pr-tracker-bot
2024-01-12 17:49 Jason Gunthorpe
2024-01-18 23:35 ` pr-tracker-bot
2023-12-04 19:35 Jason Gunthorpe
2023-12-04 21:59 ` pr-tracker-bot
2023-10-31 13:14 Jason Gunthorpe
2023-11-02  2:51 ` pr-tracker-bot
2023-08-30 23:40 Jason Gunthorpe
2023-08-31  3:50 ` pr-tracker-bot
2023-08-31  3:59 ` Linus Torvalds
2023-08-31 16:43   ` Jason Gunthorpe
2023-07-28 13:48 Jason Gunthorpe
2023-07-28 18:39 ` pr-tracker-bot
2023-06-28 14:04 Jason Gunthorpe
2023-06-30  4:16 ` pr-tracker-bot
2023-04-25 14:46 Jason Gunthorpe
2023-04-27 17:15 ` pr-tracker-bot
2023-04-06 13:34 Jason Gunthorpe
2023-04-06 18:46 ` pr-tracker-bot
2023-02-21 15:39 Jason Gunthorpe
2023-02-24 22:50 ` Linus Torvalds
2023-02-25  0:02   ` Jason Gunthorpe
2023-02-25  0:50     ` Linus Torvalds
2023-02-24 23:27 ` pr-tracker-bot
2022-12-12 18:30 Jason Gunthorpe
2022-12-14 18:04 ` pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amvDg1M6+Wu3HwSr@nvidia.com \
    --to=jgg@nvidia.com \
    --cc=iommu@lists.linux.dev \
    --cc=kevin.tian@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.