From: Nicolin Chen <nicolinc@nvidia.com>
To: Mostafa Saleh <smostafa@google.com>
Cc: <linux-kernel@vger.kernel.org>, <iommu@lists.linux.dev>,
<linux-arm-kernel@lists.infradead.org>, <will@kernel.org>,
<robin.murphy@arm.com>, <joro@8bytes.org>, <jgg@ziepe.ca>,
<praan@google.com>
Subject: Re: [PATCH 1/7] iommu/arm-smmu-v3: Ensure L2 tables are visible before L1 ptrs
Date: Fri, 28 Aug 2026 09:03:33 -0700 [thread overview]
Message-ID: <apGxVTbjoyD2kD5G@nvidia.com> (raw)
In-Reply-To: <20260828125409.1921538-2-smostafa@google.com>
On Fri, Aug 28, 2026 at 12:53:36PM +0000, Mostafa Saleh wrote:
> Commit 6fabce53f6b9 ("iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update")
> adds a dma_wmb() to arm_smmu_write_entry() to make sure stream tables
> and context descriptors are observed first.
>
> However, STE L1 table descriptors are configured directly
> via WRITE_ONCE(), where before that they were zeroed with memset()
> inside dma_direct_alloc() then written to abort in via memset() also
> in arm_smmu_init_initial_stes() without a barrier in both cases which
> means that the SMMUv3 can observe the allocated table before the
> written descriptors causing it to fetch random data.
>
> Similarly in arm_smmu_write_cd_l1_desc() where the L1 CD is written
> after dma_alloc_coherent() with no barriers.
>
> Add dma_wmb() in both cases.
>
> Fixes: 48ec83bcbcf5 ("iommu/arm-smmu: Add initial driver support for ARM SMMUv3 devices")
> Reported-by: Sashiko <>
> Signed-off-by: Mostafa Saleh <smostafa@google.com>
Reviewed-by: Nicolin Chen <nicolinc@nvidia.com>
next prev parent reply other threads:[~2026-08-28 16:04 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 12:53 [PATCH 0/7] iommu/arm-smmu-v3: Fixes reported by Sashiko Mostafa Saleh
2026-08-28 12:53 ` [PATCH 1/7] iommu/arm-smmu-v3: Ensure L2 tables are visible before L1 ptrs Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 16:03 ` Nicolin Chen [this message]
2026-08-28 12:53 ` [PATCH 2/7] iommu/arm-smmu-v3: Prevent rbtree corruption from duplicate streams Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 15:51 ` Nicolin Chen
2026-08-28 12:53 ` [PATCH 3/7] iommu/arm-smmu-v3-iommufd: Fix error path in arm_vsmmu_cache_invalidate() Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 12:53 ` [PATCH 4/7] iommu/arm-smmu-v3-test: Fix arm_smmu_v3_test_debug_print_used_bits() Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 16:12 ` Nicolin Chen
2026-08-28 12:53 ` [PATCH 5/7] iommu/arm-smmu-v3-test: Add missing error checks for inv array Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 12:53 ` [PATCH 6/7] iommu/arm-smmu-v3-test: Fix OOB in arm_smmu_v3_invs_test_verify() Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 16:14 ` Nicolin Chen
2026-08-28 12:53 ` [PATCH 7/7] iommu/arm-smmu-v3-test: Fix UBSAN error Mostafa Saleh
2026-08-28 14:27 ` Jason Gunthorpe
2026-08-28 16:14 ` Nicolin Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apGxVTbjoyD2kD5G@nvidia.com \
--to=nicolinc@nvidia.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=praan@google.com \
--cc=robin.murphy@arm.com \
--cc=smostafa@google.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.