From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 89113CA6007 for ; Thu, 8 Oct 2026 06:01:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: MIME-Version:References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From: Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=yTQQuV4psRKvxDzTdLOJZ4uuToh0Wf4kSUXnRgYJ2U0=; b=2VveNbg4VjaiDHReq2BaqH51QR USEpbR1sH+fPuPITgMbP8uEPXgPSQ6Bn6sO67IfYT92DNAR5nkIDy1HwYaEgeFYtQcTJe5eHL00K+ ibKe1s0SuQJ6uQZH+g+53fnzZdJyFCnFVyPRpGi7sMu3YFw37AL93a2ywiaOB/6pH9QgpvZbeTDEn TfOhHkd/h47Jn/wJ3bRpI9W0oduuXOXD0lGuE47B/46Fhnv0aVqaEYoIn+b6fDDn9NKcTwvTk3UWv oqmG8nNv1qqAmjxuXWO0HTZfh1TefbuIgbcQtZTQtjaVW9P0/Xet1ZVRS2L8rrMuoxQLsolthrDzM Zc4x4J9w==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1xEhCG-00000003atN-00FN; Thu, 08 Oct 2026 06:01:40 +0000 Received: from tor.source.kernel.org ([172.105.4.254]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1xEhCE-00000003asg-38On for linux-arm-kernel@lists.infradead.org; Thu, 08 Oct 2026 06:01:38 +0000 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by tor.source.kernel.org (Postfix) with ESMTP id EF0AB6025A; Thu, 8 Oct 2026 06:01:37 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8A9B31F00893; Thu, 8 Oct 2026 06:01:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1791439297; bh=yTQQuV4psRKvxDzTdLOJZ4uuToh0Wf4kSUXnRgYJ2U0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DIqCJia77E1xwebKyTUEfNu5o1GRv3n6EjQP/mTqcVZMaMmZwPXF1cKbiFsq746ar EiHkTqLWyb7yC7LuYx63O+hFO1Xffql/3qNAtg1T9g4MmwWA7+gBCYnsMov0Y15oYm W25HgD6qvVEQ0pjEMvl+x1RZ+d5WofEDNT7j9uMCiwS4u56NRcpOh6OXK7jXhvxJF5 c1xBlvXpYh9v8EgHRbIBoiUeYHCgrxpqL6Cgb1anryjErZSF7FWxNKLbdLu8h3TE39 28bEemiip6lnOivD4nPZjpdEur0KirrtpyMjz677wUIpOahlOsWTbnDgYs/jidk+1R /nwxRcCoD4eyA== From: "Aneesh Kumar K.V (Arm)" To: iommu@lists.linux.dev Cc: "Aneesh Kumar K.V (Arm)" , Alex Williamson , Alexey Kardashevskiy , Bjorn Helgaas , Catalin Marinas , Jacob Pan , Jason Gunthorpe , Joerg Roedel , Jonathan Cameron , Jonathan Hunter , Kevin Tian , Krishna Reddy , Lukas Wunner , Nicolin Chen , Robin Murphy , Samuel Ortiz , Shameer Kolothum , Steven Price , Suravee Suthikulpanit , Suzuki K Poulose , Thierry Reding , Vasant Hegde , Will Deacon , Xu Yilun , kvm@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-tegra@vger.kernel.org Subject: [PATCH v7 09/16] tsm: Remove the device from lookup before PCI teardown Date: Thu, 8 Oct 2026 11:29:48 +0530 Message-ID: <20261008055955.4014342-10-aneesh.kumar@kernel.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20261008055955.4014342-1-aneesh.kumar@kernel.org> References: <20261008055955.4014342-1-aneesh.kumar@kernel.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org PCI connect looks up a TSM by ID under pci_tsm_rwsem. Previously, tsm_unregister() released that lock after tearing down PCI state while the TSM was still in the class lookup. A racing connect could then attach a new PCI context that the teardown would never see. Remove the device from the class lookup first, then take the PCI write lock to drain in-flight operations and destroy their contexts. Drop the device reference only after PCI teardown completes. Signed-off-by: Aneesh Kumar K.V (Arm) --- drivers/virt/coco/tsm-core.c | 22 ++++++++++++++-------- 1 file changed, 14 insertions(+), 8 deletions(-) diff --git a/drivers/virt/coco/tsm-core.c b/drivers/virt/coco/tsm-core.c index e784993353d8..f79135986102 100644 --- a/drivers/virt/coco/tsm-core.c +++ b/drivers/virt/coco/tsm-core.c @@ -56,26 +56,25 @@ static struct tsm_dev *alloc_tsm_dev(struct device *parent) return no_free_ptr(tsm_dev); } -static struct tsm_dev *tsm_register_pci_or_reset(struct tsm_dev *tsm_dev, - struct pci_tsm_ops *pci_ops) +static int tsm_register_pci(struct tsm_dev *tsm_dev, struct pci_tsm_ops *pci_ops) { int rc; if (!pci_ops) - return tsm_dev; + return 0; tsm_dev->pci_ops = pci_ops; rc = pci_tsm_register(tsm_dev); if (rc) { + tsm_dev->pci_ops = NULL; dev_err(tsm_dev->dev.parent, "PCI/TSM registration failure: %d\n", rc); - device_unregister(&tsm_dev->dev); - return ERR_PTR(rc); + return rc; } /* Notify TSM userspace that PCI/TSM operations are now possible */ kobject_uevent(&tsm_dev->dev.kobj, KOBJ_CHANGE); - return tsm_dev; + return 0; } struct tsm_dev *tsm_register(struct device *parent, struct pci_tsm_ops *pci_ops) @@ -96,15 +95,22 @@ struct tsm_dev *tsm_register(struct device *parent, struct pci_tsm_ops *pci_ops) if (rc) return ERR_PTR(rc); - return tsm_register_pci_or_reset(no_free_ptr(tsm_dev), pci_ops); + rc = tsm_register_pci(tsm_dev, pci_ops); + if (rc) { + device_del(dev); + return ERR_PTR(rc); + } + return no_free_ptr(tsm_dev); } EXPORT_SYMBOL_GPL(tsm_register); void tsm_unregister(struct tsm_dev *tsm_dev) { + /* Remove the class lookup first. */ + device_del(&tsm_dev->dev); if (tsm_dev->pci_ops) pci_tsm_unregister(tsm_dev); - device_unregister(&tsm_dev->dev); + put_device(&tsm_dev->dev); } EXPORT_SYMBOL_GPL(tsm_unregister); -- 2.43.0