From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id C16DBCA600B for ; Thu, 8 Oct 2026 13:21:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:In-Reply-To:From:References:Cc:To:Subject:MIME-Version:Date: Message-ID:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=56QQPOUrdJeTXlAaDAtYda9lVSqpM7bnPzz0/eQbUGw=; b=RMlweO7myPWaNjmdncBAgI7e47 Jw0rfzsJz830JU7yQr3SC4jh+N6qbGAb11wC3QfESQRjIbzQPo+aAFFabeWOwK7cFvF+aA6X+P1eM hhWe338osuhBrCM48CRzkDNlv2UsqrCQQ1wPLmA/TYQxv2u2RFrZPghPQedWAKT+SYdX3ot+lXqDw RPrFdTccdAJCX/GQCtrus+PhJNRZv0ma2czYhewpOxFKMzVmIHDRbZ4ee8n7nizp8v63yD57hEu89 Xdsng08a37LvqAGrgwPpzwkcutReDPu9rrBKW4CrjqgS2GvHaLBWlVD8VEKbZeEN/w8E150hdgeLC OXaMxa7w==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1xEo4F-00000004S9S-2PhB; Thu, 08 Oct 2026 13:21:51 +0000 Received: from foss.arm.com ([217.140.110.172]) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1xEo4D-00000004S8l-19FJ for linux-arm-kernel@lists.infradead.org; Thu, 08 Oct 2026 13:21:50 +0000 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id C42CE1477; Thu, 8 Oct 2026 06:21:44 -0700 (PDT) Received: from [10.2.212.23] (e121345-lin.cambridge.arm.com [10.2.212.23]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 76A0F3F763; Thu, 8 Oct 2026 06:21:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1791465708; bh=L3pt2PT/hPwrXq7LAfWVr+hh3Nacq9R0SABfPWeBcZg=; h=Date:Subject:To:Cc:References:From:In-Reply-To:From; b=Hqci3iIQjlR0pfAzB9UXRgbrh5jmECHpljbCK3qydteadihdACwdJg2UVciO4Y/yy P8+Nhln78zg8nk3oUdWtTFuNcsOkcZf3rZ0RBrtF0pCnEMPQ2IYqCDAj+7JHDvVnzf TnzE6K/QUcbkAE+fQrQH8zCkItpqT1QNlpwvX1Pc= Message-ID: <7626c1be-305e-478a-a017-548341d25419@arm.com> Date: Thu, 8 Oct 2026 14:21:43 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH RFC v5 2/6] iommu/arm-smmu-v3: Allocate streams individually To: Nicolin Chen , "Peng Fan (OSS)" Cc: Will Deacon , "Joerg Roedel (AMD)" , Jean-Philippe Brucker , Jason Gunthorpe , Thierry Reding , Krishna Reddy , Jonathan Hunter , linux-arm-kernel@lists.infradead.org, iommu@lists.linux.dev, linux-kernel@vger.kernel.org, linux-tegra@vger.kernel.org, Peng Fan References: <20261006-smmu-shared-sid-v5-0-169a59c671d3@nxp.com> <20261006-smmu-shared-sid-v5-2-169a59c671d3@nxp.com> From: Robin Murphy Content-Language: en-GB In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20261008_062149_412771_27B59981 X-CRM114-Status: GOOD ( 13.91 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On 08/10/2026 12:17 am, Nicolin Chen wrote: > On Tue, Oct 06, 2026 at 08:19:08PM +0800, Peng Fan (OSS) wrote: >> From: Peng Fan >> >> Change master->streams from an embedded array of struct arm_smmu_stream >> to an array of pointers, with each stream individually allocated. >> >> Prepare for shared-SID support where multiple masters will point to the >> same stream object. With embedded structs, sharing requires duplicating >> stream state and manually keeping fields like ste_installed in sync. >> With individually allocated streams, a sharing master can simply point to >> the existing stream. >> >> The sort comparator is updated to dereference the pointer indirection. >> >> No functional change. >> >> Suggested-by: Nicolin Chen >> Link: https://lore.kernel.org/linux-iommu/arG6hmng3NddGEHm@nvidia.com/ >> Assisted-by: LLM >> Signed-off-by: Peng Fan > > Reviewed-by: Nicolin Chen > >> diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c >> index 6644075c1431e..bc62a3d5a63f9 100644 >> --- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c >> +++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c >> @@ -1257,7 +1257,7 @@ static int tegra241_vintf_init_vsid(struct iommufd_vdevice *vdev) >> struct arm_smmu_master *master = dev_iommu_priv_get(dev); >> struct tegra241_vintf *vintf = viommu_to_vintf(vdev->viommu); >> struct tegra241_vintf_sid *vsid = vdev_to_vsid(vdev); >> - struct arm_smmu_stream *stream = &master->streams[0]; >> + struct arm_smmu_stream *stream = master->streams[0]; > > Sashiko raised a concern of an out-of-bounds pointer dereference. > > Though it's practically not possible, probably it would be safer > to move this behind the check: > > if (master->num_streams != 1) > return -EOPNOTSUPP; The IORT path unconditionally adds 1 ID via acpi_iommu_fwspec_init(), so num_streams==0 could only potentially happen with DT if a fwspec was parsed using #iommu-cells==0, except arm_smmu_device_dt_probe() would refuse to probe the entire SMMU if that was anything other than 1, so no, this definitely cannot ever be out of bounds. Thanks, Robin.