From: Mikko Perttunen <mperttunen@nvidia.com>
To: dri-devel@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org, sashiko-reviews@lists.linux.dev
Subject: Re: [PATCH 08/11] iommu/tegra-smmu: Defer display client translation to driver handover
Date: Tue, 15 Sep 2026 15:02:04 +0900 [thread overview]
Message-ID: <-oA14QdsQIqZ-_tQLk7vdw@nvidia.com> (raw)
In-Reply-To: <20260915023209.B70BD1F000FF@smtp.kernel.org>
On Tuesday, September 15, 2026 11:32 AM sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Critical] iommu/tegra-smmu: type confusion in tegra_smmu_enable_translation() on ARM SMMU
> --
>
> commit 35f909bd1b8b88cf1f8f29602efafacdd3b66778
> Author: Mikko Perttunen <mperttunen@nvidia.com>
>
> iommu/tegra-smmu: Defer display client translation to driver handover
>
> Bootloaders may leave display controllers scanning out a boot splash
> while the kernel boots. Enabling translation for them without special
> care during that time would cause translation faults. This patch
> defers enabling translation until the display controller is reset.
>
> > diff --git a/drivers/gpu/drm/tegra/dc.c b/drivers/gpu/drm/tegra/dc.c
> > index 0b3fcc7011b35..2ae4da07bbc99 100644
> > --- a/drivers/gpu/drm/tegra/dc.c
> > +++ b/drivers/gpu/drm/tegra/dc.c
> [ ... ]
> > @@ -2751,6 +2752,13 @@ static int tegra_dc_init(struct host1x_client *client)
> > return err;
> > }
> >
> > + /*
> > + * Enable translation now that the final domain is attached.
> > + * The hardware was reset at probe and has not been programmed
> > + * since.
> > + */
> > + tegra_smmu_enable_translation(client->dev);
>
> [Severity: Critical]
> Does this code call the Tegra SMMU API unconditionally on all Tegra display
> controllers? Newer SoC generations (Tegra186 and later) use the ARM SMMU
> instead of the Tegra SMMU, which means this could pass a device managed by
> the ARM SMMU driver into a Tegra SMMU specific function.
Thanks, will fix.
Mikko
>
> [ ... ]
> > diff --git a/drivers/iommu/tegra-smmu.c b/drivers/iommu/tegra-smmu.c
> > index 67e7a7b925f0c..6636a044905f6 100644
> > --- a/drivers/iommu/tegra-smmu.c
> > +++ b/drivers/iommu/tegra-smmu.c
> [ ... ]
> > @@ -417,6 +423,49 @@ static void tegra_smmu_disable(struct tegra_smmu *smmu, unsigned int swgroup,
> > }
> > }
> >
> > +/**
> > + * tegra_smmu_enable_translation - Release a client's swgroups to translation
> > + * @dev: memory client device, already quiesced by its driver
> > + *
> > + * Enables translation for swgroups which were left in bypass at attach time
> > + * because the client could still have been running from a pre-kernel
> > + * configuration. Must be called after @dev has been attached to the domain it
> > + * will use. Safe to call for any device; clients which were not deferred are
> > + * unaffected.
> > + */
> > +void tegra_smmu_enable_translation(struct device *dev)
> > +{
> > + struct iommu_fwspec *fwspec = dev_iommu_fwspec_get(dev);
> > + struct tegra_smmu *smmu = dev_iommu_priv_get(dev);
>
> [Severity: Critical]
> Is it safe to blindly retrieve the IOMMU private data via
> dev_iommu_priv_get() and cast it to a struct tegra_smmu pointer without
> validating that the device is actually managed by the Tegra SMMU driver?
>
> On ARM SMMU systems, this private data actually points to a completely
> different structure (like struct arm_smmu_master_cfg or
> struct arm_smmu_master) that is significantly smaller.
>
> > + struct iommu_domain *domain;
> > + unsigned int i;
> > +
> > + if (!fwspec || !smmu)
> > + return;
> > +
> > + domain = iommu_get_domain_for_dev(dev);
> > + if (!domain || !(domain->type & __IOMMU_DOMAIN_PAGING))
> > + return;
> > +
> > + mutex_lock(&smmu->lock);
>
> [Severity: Critical]
> Because lock is at a large offset in struct tegra_smmu, could dereferencing
> this type-confused pointer to acquire the mutex access memory out of bounds
> of the ARM SMMU configuration structure? This looks like it would lead to
> heap corruption and a kernel oops during the display controller probe path.
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260915-b4-arm32-iommu-dma-cookie-v1-0-ba4f9d33a2b8@nvidia.com?part=8
next prev parent reply other threads:[~2026-09-15 6:02 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <CGME20260915021542eucas1p254addab18c10cb117f42ccf3d3522883@eucas1p2.samsung.com>
2026-09-15 2:14 ` [PATCH 00/11] Make the 32-bit ARM DMA API work with normal IOMMU DMA default domains (+ Tegra PoC) Mikko Perttunen
2026-09-15 2:14 ` [PATCH 01/11] iommu: Add iommu_teardown_dma_ops Mikko Perttunen
2026-09-15 2:14 ` [PATCH 02/11] iommu: Add cookie type for ARM_DMA_USE_IOMMU Mikko Perttunen
2026-09-15 2:14 ` [PATCH 03/11] ARM: dma-mapping: Split mapping allocation from domain allocation Mikko Perttunen
2026-09-15 2:14 ` [PATCH 04/11] ARM: dma-mapping: Implement and expose DMA setup functions Mikko Perttunen
2026-09-15 2:15 ` [PATCH 05/11] ARM: dma-mapping: Bypass the legacy path for core-owned DMA API domains Mikko Perttunen
2026-09-15 2:29 ` sashiko-bot
2026-09-15 5:59 ` Mikko Perttunen
2026-09-15 2:15 ` [PATCH 06/11] ARM: dma-mapping: Handle foreign buffers in arm_iommu_get_sgtable Mikko Perttunen
2026-09-15 2:15 ` [PATCH 07/11] iommu: Let 32-bit ARM drivers opt into a DMA API default domain Mikko Perttunen
2026-09-15 2:15 ` [PATCH 08/11] iommu/tegra-smmu: Defer display client translation to driver handover Mikko Perttunen
2026-09-15 2:32 ` sashiko-bot
2026-09-15 6:02 ` Mikko Perttunen [this message]
2026-09-15 2:15 ` [PATCH 09/11] gpu: host1x: Drop release of legacy 32-bit ARM DMA domain Mikko Perttunen
2026-09-15 2:15 ` [PATCH 10/11] drm/tegra: " Mikko Perttunen
2026-09-15 2:15 ` [PATCH 11/11] iommu/tegra-smmu: Use a DMA API default domain per swgroup Mikko Perttunen
2026-09-25 15:20 ` [PATCH 00/11] Make the 32-bit ARM DMA API work with normal IOMMU DMA default domains (+ Tegra PoC) Marek Szyprowski
2026-09-29 7:28 ` Mikko Perttunen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=-oA14QdsQIqZ-_tQLk7vdw@nvidia.com \
--to=mperttunen@nvidia.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox