From: Samiullah Khawaja <skhawaja@google.com>
To: Lu Baolu <baolu.lu@linux.intel.com>
Cc: Joerg Roedel <joro@8bytes.org>, Will Deacon <will@kernel.org>,
Robin Murphy <robin.murphy@arm.com>,
Jason Gunthorpe <jgg@ziepe.ca>,
Kevin Tian <kevin.tian@intel.com>,
iommu@lists.linux.dev, linux-kernel@vger.kernel.org,
Sashiko <sashiko-bot@kernel.org>
Subject: Re: [PATCH 5/5] iommu/vt-d: Flush context cache with correct SID when tearing down aliases
Date: Mon, 3 Aug 2026 18:19:36 +0000 [thread overview]
Message-ID: <anDbfCdtFJ7SViYU@google.com> (raw)
In-Reply-To: <20260731054329.2948252-6-baolu.lu@linux.intel.com>
On Fri, Jul 31, 2026 at 01:43:29PM +0800, Lu Baolu wrote:
>domain_context_clear_one() and device_pasid_table_teardown() are both
>invoked once per DMA alias of a device. Each function locates the context
>entry using the bus/devfn pair provided by the pci_for_each_dma_alias()
>callback, then calls intel_context_flush_no_pasid(), which constructs a
>device-selective context-cache invalidation from info->bus and
>info->devfn (that is, always the requester ID of the device itself).
>
>As a result, for every alias other than the device’s own RID, the context
>entry that was just cleared in memory is never invalidated in the context
>cache. Hardware may continue using that stale cached entry. In the
>scalable-mode teardown path, intel_pasid_free_table() can then free the
>PASID directory still referenced by that stale entry, allowing the IOMMU
>to walk freed memory.
>
>Fix this by passing the source ID of the entry being torn down to
>intel_context_flush_no_pasid(), instead of deriving it from @info.
>
>Fixes: f90584f4beb84 ("iommu/vt-d: Add helper to flush caches for context change")
>Reported-by: Sashiko <sashiko-bot@kernel.org>
>Closes: https://sashiko.dev/#/patchset/20260602233426.357499-1-baolu.lu%40linux.intel.com
>Assisted-by: Claude:claude-opus-5
>Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
>---
> drivers/iommu/intel/iommu.h | 2 +-
> drivers/iommu/intel/iommu.c | 2 +-
> drivers/iommu/intel/pasid.c | 9 ++++++---
> 3 files changed, 8 insertions(+), 5 deletions(-)
>
Reviewed-by: Samiullah Khawaja <skhawaja@google.com>
Sami
next prev parent reply other threads:[~2026-08-03 18:19 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 5:43 [PATCH 0/5] iommu/vt-d: Fixes for issues reported by Sashiko Lu Baolu
2026-07-31 5:43 ` [PATCH 1/5] iommu/vt-d: Fix shift overflow in qi_desc_dev_iotlb_pasid() Lu Baolu
2026-08-03 18:28 ` Samiullah Khawaja
2026-07-31 5:43 ` [PATCH 2/5] iommu/vt-d: Clear Present bit before tearing down copied context entry Lu Baolu
2026-07-31 5:43 ` [PATCH 3/5] iommu/vt-d: Fix iopf_refcount leak on RID domain replacement Lu Baolu
2026-07-31 5:43 ` [PATCH 4/5] iommu/vt-d: Tear down scalable-mode context on probe failure Lu Baolu
2026-07-31 5:43 ` [PATCH 5/5] iommu/vt-d: Flush context cache with correct SID when tearing down aliases Lu Baolu
2026-08-03 18:19 ` Samiullah Khawaja [this message]
2026-08-04 2:28 ` [PATCH 0/5] iommu/vt-d: Fixes for issues reported by Sashiko Baolu Lu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anDbfCdtFJ7SViYU@google.com \
--to=skhawaja@google.com \
--cc=baolu.lu@linux.intel.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=kevin.tian@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=robin.murphy@arm.com \
--cc=sashiko-bot@kernel.org \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.