Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Leon Romanovsky" <leon@kernel.org>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v2 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk
Date: Thu, 06 Aug 2026 11:44:32 +0000	[thread overview]
Message-ID: <20260806114433.D9FA81F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260806-fix-p2p-acs-v2-12-0cec14812965@nvidia.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] pci_p2pdma_release() skips synchronize_rcu() when p2pdma->pool is NULL, leading to a Use-After-Free of the pci_p2pdma struct and its XArray inside RCU read-side critical sections.
--

--- Patch [12]: [PATCH v2 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk ---
commit c4a68b62f4ec894cc35240eda46bf42dc5f562d9
Author: Leon Romanovsky <leon@kernel.org>

PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk

Extend the ACS KUnit suite with end-to-end coverage of
calc_map_type_and_dist(), the provider-to-client hierarchy walk.

> diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
> index c7680964d8a64..18e5339bc49e9 100644
> --- a/drivers/pci/p2pdma.c
> +++ b/drivers/pci/p2pdma.c
[ ... ]
> @@ -859,6 +859,7 @@ calc_map_type_and_dist(struct pci_dev *provider, struct pci_dev *client,
>  	rcu_read_unlock();
>  	return map_type;
>  }
> +EXPORT_SYMBOL_IF_KUNIT(calc_map_type_and_dist);

[Severity: High]
This is a pre-existing issue, but does this code have a race condition
leading to a use-after-free when interacting with pci_p2pdma_release()?

If a device acts as a P2PDMA provider without setting up an allocator pool
(for example, via vfio-pci or mlx5), pci_p2pdma_release() skips
synchronize_rcu() because p2pdma->pool is NULL:

drivers/pci/p2pdma.c:pci_p2pdma_release() {
        ...
        if (p2pdma->pool)
                synchronize_rcu();
        ...
}

When the provider driver is unbound, devres frees the pci_p2pdma structure
and destroys the XArray. Concurrently, calc_map_type_and_dist() executing
here inside its RCU read-side critical section can dereference the freed
p2pdma pointer and call xa_store() on the destroyed XArray.

Should synchronize_rcu() be called during release regardless of whether
the allocator pool is set up?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-fix-p2p-acs-v2-0-0cec14812965@nvidia.com?part=12

  reply	other threads:[~2026-08-06 11:44 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 11:24 [PATCH v2 00/13] PCI/P2PDMA: Fix ACS egress control handling Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 01/13] PCI/P2PDMA: Safely terminate ACS redirect lists Leon Romanovsky
2026-08-06 11:32   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 02/13] PCI/P2PDMA: Report ACS ports when the paths share no upstream bridge Leon Romanovsky
2026-08-06 11:37   ` sashiko-bot
2026-08-07 14:35     ` Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 03/13] PCI/P2PDMA: Document the Address Type assumption Leon Romanovsky
2026-08-06 11:28   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 04/13] PCI: Account for Direct Translated P2P in ACS isolation checks Leon Romanovsky
2026-08-06 11:35   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 05/13] PCI: Add ACS egress control vector accessor Leon Romanovsky
2026-08-06 11:39   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 06/13] PCI: Account for ACS egress control in isolation checks Leon Romanovsky
2026-08-06 11:40   ` sashiko-bot
2026-08-07 16:07     ` Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 07/13] PCI/P2PDMA: Derive peer-to-peer routing from ACS control bits Leon Romanovsky
2026-08-06 11:33   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 08/13] PCI/P2PDMA: Honor ACS egress control vectors Leon Romanovsky
2026-08-06 11:47   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 09/13] PCI/P2PDMA: Document ACS egress control handling Leon Romanovsky
2026-08-06 11:29   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 10/13] PCI/P2PDMA: Extract pure ACS routing decision helpers Leon Romanovsky
2026-08-06 11:34   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 11/13] PCI/P2PDMA: Add KUnit tests for ACS routing decisions Leon Romanovsky
2026-08-06 11:34   ` sashiko-bot
2026-08-06 11:24 ` [PATCH v2 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk Leon Romanovsky
2026-08-06 11:44   ` sashiko-bot [this message]
2026-08-07 13:02     ` Leon Romanovsky
2026-08-06 11:24 ` [PATCH v2 13/13] PCI: Add KUnit coverage for ACS isolation checks Leon Romanovsky
2026-08-06 11:37   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260806114433.D9FA81F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=leon@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox