From: Jason Gunthorpe <jgg@nvidia.com>
To: Pranjal Shrivastava <praan@google.com>
Cc: iommu@lists.linux.dev, Will Deacon <will@kernel.org>,
Joerg Roedel <joro@8bytes.org>,
Robin Murphy <robin.murphy@arm.com>,
Jason Gunthorpe <jgg@ziepe.ca>,
Mostafa Saleh <smostafa@google.com>,
Nicolin Chen <nicolinc@nvidia.com>,
Daniel Mentz <danielmentz@google.com>,
linux-arm-kernel@lists.infradead.org
Subject: Re: [PATCH v9 09/12] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops
Date: Tue, 25 Aug 2026 13:36:11 -0300 [thread overview]
Message-ID: <178767577113.3356902.28128835506777632.b4-review@b4> (raw)
In-Reply-To: <20260728210928.1050849-10-praan@google.com>
> [ ... 80 lines skipped ... ]
> @@ -730,10 +770,58 @@ int __arm_smmu_cmdq_issue_cmdlist(struct arm_smmu_device *smmu,
>
> /*
> * If the SMMU is suspended/suspending, any new CMDs are elided.
> - * This loop is the Point of Commitment. If we haven't cmpxchg'd
> - * our new indices yet, we can safely bail. Once the indices are
> - * committed, we MUST write valid commands to those slots to
> - * avoid indefinite polling in the drain function.
> + *
> + * This loop acts as the Point of Commitment.
> + * The CMDQ_PROD_STOP_FLAG ensures that no new commands are
> + * committed once the SMMU begins to suspend. The synchronization
> + * relies on the following observability invariants:
> + *
> + * 1. Other CPUs observe the STOP_FLAG only *after* the SMMU is
> + * disabled. This is enforced in arm_smmu_runtime_suspend()
[Severity: Critical]
If an ATC invalidation (CMDQ_OP_ATC_INV) is issued (e.g., during iommu_unmap
from a background thread) while the SMMU is suspended, the command appears
to be silently dropped here.
Since ATC caches inside PCIe endpoints might not be globally invalidated
during resume, could the endpoint retain stale ATC entries upon wake-up?
Would this allow the endpoint to DMA into freed memory?
I agree.. I think there are only two options?
1) After GBPA=Abort ATS requests are blocked, so you could full
invalidate all the device ATC's and now it is safe to ignore
ATC_INV
2) Just don't perform suspend once ATS is activated
--
Jason
next prev parent reply other threads:[~2026-08-25 16:36 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 21:09 [PATCH v9 00/12] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 01/12] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 17:35 ` Pranjal Shrivastava
2026-08-25 18:47 ` Nicolin Chen
2026-08-25 19:01 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 02/12] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 17:37 ` Pranjal Shrivastava
2026-08-25 18:20 ` Nicolin Chen
2026-08-25 18:57 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 03/12] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 04/12] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 05/12] iommu/arm-smmu-v3: Cache and restore MSI config Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:01 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 06/12] iommu/arm-smmu-v3: Handle gerror during suspend Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:06 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 07/12] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:38 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 08/12] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:46 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 09/12] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe [this message]
2026-08-25 18:53 ` Pranjal Shrivastava
2026-08-25 20:17 ` Jason Gunthorpe
2026-08-26 11:51 ` Pranjal Shrivastava
2026-08-26 13:47 ` Jason Gunthorpe
2026-08-26 14:17 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 10/12] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 11/12] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 12/12] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-08-25 13:33 ` [PATCH v9 00/12] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Jason Gunthorpe
2026-08-25 18:50 ` Pranjal Shrivastava
2026-08-25 20:14 ` Jason Gunthorpe
2026-08-26 11:55 ` Pranjal Shrivastava
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178767577113.3356902.28128835506777632.b4-review@b4 \
--to=jgg@nvidia.com \
--cc=danielmentz@google.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=nicolinc@nvidia.com \
--cc=praan@google.com \
--cc=robin.murphy@arm.com \
--cc=smostafa@google.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox