From: Jason Gunthorpe <jgg@nvidia.com>
To: Nicolin Chen <nicolinc@nvidia.com>
Cc: Will Deacon <will@kernel.org>, Kevin Tian <kevin.tian@intel.com>,
Robin Murphy <robin.murphy@arm.com>,
Joerg Roedel <joro@8bytes.org>, Shuah Khan <shuah@kernel.org>,
Pranjal Shrivastava <praan@google.com>,
Kees Cook <kees@kernel.org>, Yi Liu <yi.l.liu@intel.com>,
Eric Auger <eric.auger@redhat.com>,
linux-arm-kernel@lists.infradead.org, iommu@lists.linux.dev,
linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org
Subject: Re: [PATCH v1 4/4] iommu/arm-smmu-v3: Process vIOMMU invalidations in batches
Date: Fri, 12 Jun 2026 10:54:09 -0300 [thread overview]
Message-ID: <20260612135409.GI1962447@nvidia.com> (raw)
In-Reply-To: <00748c5cbea95a938d032269001a598203b06bbc.1780521606.git.nicolinc@nvidia.com>
On Wed, Jun 03, 2026 at 02:26:56PM -0700, Nicolin Chen wrote:
> +int arm_vsmmu_cache_invalidate(struct iommufd_viommu *viommu,
> + struct iommu_user_data_array *array)
> +{
> + struct arm_vsmmu *vsmmu = container_of(viommu, struct arm_vsmmu, core);
> + u32 issued = 0;
> + int ret = 0;
> +
> + if (array->type != IOMMU_VIOMMU_INVALIDATE_DATA_ARM_SMMUV3) {
> + array->entry_num = 0;
> + return -EINVAL;
> + }
> +
> + while (issued != array->entry_num) {
> + /* Process and issue the command(s) in batch */
> + ret = arm_vsmmu_cache_invalidate_batch(vsmmu, array, &issued);
> + if (ret)
> + break;
> + }
> +
> + array->entry_num = issued;
> return ret;
I think every driver will have this same problem, how about lifting
this loop to the core code?
Also not sure I like the validation flow, I think it will be easier to
understand for everything if either num is 0 and nothing was done with
an error code
Or num is non zero and no error code.
Like it doesn't make sense to fail immediately if zero pad is nonzero
in iommu_copy_struct_from_full_user_array() but then to try to
partially continue if arm_vsmmu_convert_user_cmd() finds illegal data
in the very same buffer. Be consistent, validate the user buffer, if
it is not valid fail immeidately. Then execute a fully valid user buffer.
Jason
next prev parent reply other threads:[~2026-06-12 13:54 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-03 21:26 [PATCH v1 0/4] iommufd: Cache invalidation hardening and SMMUv3 batching rework Nicolin Chen
2026-06-03 21:26 ` [PATCH v1 1/4] iommufd: Set upper bounds on cache invalidation entry_num and entry_len Nicolin Chen
2026-06-10 3:16 ` Baolu Lu
2026-06-03 21:26 ` [PATCH v1 2/4] iommufd/selftest: Add invalidation entry_num and entry_len boundary tests Nicolin Chen
2026-06-10 3:18 ` Baolu Lu
2026-06-03 21:26 ` [PATCH v1 3/4] iommu: Avoid copying the user array twice in the full-array copy helper Nicolin Chen
2026-06-10 3:21 ` Baolu Lu
2026-06-03 21:26 ` [PATCH v1 4/4] iommu/arm-smmu-v3: Process vIOMMU invalidations in batches Nicolin Chen
2026-06-12 13:54 ` Jason Gunthorpe [this message]
2026-06-12 13:54 ` [PATCH v1 0/4] iommufd: Cache invalidation hardening and SMMUv3 batching rework Jason Gunthorpe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260612135409.GI1962447@nvidia.com \
--to=jgg@nvidia.com \
--cc=eric.auger@redhat.com \
--cc=iommu@lists.linux.dev \
--cc=joro@8bytes.org \
--cc=kees@kernel.org \
--cc=kevin.tian@intel.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=nicolinc@nvidia.com \
--cc=praan@google.com \
--cc=robin.murphy@arm.com \
--cc=shuah@kernel.org \
--cc=will@kernel.org \
--cc=yi.l.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox