From: sashiko-bot@kernel.org
To: "Pranjal Shrivastava" <praan@google.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v11 11/16] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions
Date: Tue, 29 Sep 2026 05:55:59 +0000 [thread overview]
Message-ID: <20260929055600.374E01F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929034510.2023173-12-praan@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] iommu/arm-smmu-v3: memory corruption from dropped ATC_INV when SMMU is suspended
--
commit 1d62496e7c0326798403d88bba79adbf58c43810
Author: Pranjal Shrivastava <praan@google.com>
iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions
This commit introduces a CMDQ_PROD_STOP_FLAG to safely gate command queue
submissions during device suspension. It checks this flag in the cmpxchg
loop to avoid abandoning batches and indefinite polling during drains.
> diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
> --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
> +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
[ ... ]
> @@ -726,13 +727,42 @@ int __arm_smmu_cmdq_issue_cmdlist(struct arm_smmu_device *smmu,
> do {
> u64 old;
>
> + /*
> + * If the SMMU is suspended/suspending, any new CMDs are elided.
> + * This loop is the Point of Commitment. If we haven't cmpxchg'd
> + * our new indices yet, we can safely bail. Once the indices are
> + * committed, we MUST write valid commands to those slots to
> + * avoid indefinite polling in the drain function.
> + */
> + if (Q_STOP(llq.prod)) {
> + local_irq_restore(flags);
> + return 0;
> + }
[Severity: High]
Can this early return cause memory corruption by silently dropping ATC
invalidations?
When the SMMU suspends, Q_STOP(llq.prod) becomes true. If a driver or
background thread then calls dma_unmap() to free a buffer while a PCIe
endpoint (with ATS enabled) is suspended to a state like D0, the SMMU
driver will observe the stop flag here in __arm_smmu_cmdq_issue_cmdlist().
By bailing out and returning 0 (success) without actually submitting the
CMDQ_OP_ATC_INV command to the hardware, the IOMMU core is misled into
freeing the memory while the PCIe endpoint's Address Translation Cache
(ATC) retains the stale translation. When the PCI device resumes, or if
it issues a TLP while in D0, it could use the stale ATC entry to access
the now-freed memory, bypassing IOMMU protections.
Are we assuming endpoint drivers clear their own ATC or that a hardware
reset handles it? Client endpoint drivers typically lack an API to
manually clear the ATC, and SMMU hardware resets do not broadcast ATC
invalidations to endpoints.
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929034510.2023173-1-praan@google.com?part=11
next prev parent reply other threads:[~2026-09-29 5:56 UTC|newest]
Thread overview: 55+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 3:44 [PATCH v11 00/16] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-09-29 3:44 ` [PATCH v11 01/16] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-09-29 3:59 ` sashiko-bot
2026-10-07 14:06 ` Will Deacon
2026-09-29 3:44 ` [PATCH v11 02/16] iommu/arm-smmu-v3: Add Q_POS() macro Pranjal Shrivastava
2026-09-29 4:01 ` sashiko-bot
2026-09-29 3:44 ` [PATCH v11 03/16] iommu/arm-smmu-v3: Add arm_smmu_drain_queue() helper Pranjal Shrivastava
2026-09-29 4:11 ` sashiko-bot
2026-09-30 18:24 ` Nicolin Chen
2026-09-30 20:17 ` Pranjal Shrivastava
2026-09-29 3:44 ` [PATCH v11 04/16] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-09-29 4:24 ` sashiko-bot
2026-09-29 3:44 ` [PATCH v11 05/16] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-09-29 4:31 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 06/16] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-09-29 4:42 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 07/16] genirq/msi: Cache MSI message in irq_chip_write_msi_msg() Pranjal Shrivastava
2026-09-29 5:07 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 08/16] genirq/msi: Provide msi_device_domain_restore_msi_msgs() Pranjal Shrivastava
2026-09-29 5:22 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 09/16] iommu/arm-smmu-v3: Restore MSI config on resume Pranjal Shrivastava
2026-09-29 5:31 ` sashiko-bot
2026-10-07 14:07 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 10/16] iommu/arm-smmu-v3: Factor out arm_smmu_handle_gerror() Pranjal Shrivastava
2026-09-29 5:37 ` sashiko-bot
2026-09-30 18:34 ` Nicolin Chen
2026-09-30 20:00 ` Pranjal Shrivastava
2026-09-30 20:12 ` Nicolin Chen
2026-09-30 20:03 ` Pranjal Shrivastava
2026-10-07 14:07 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 11/16] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-09-29 5:55 ` sashiko-bot [this message]
2026-09-30 20:33 ` Nicolin Chen
2026-10-01 5:40 ` Pranjal Shrivastava
2026-10-01 18:03 ` Nicolin Chen
2026-10-02 16:47 ` Jason Gunthorpe
2026-10-02 21:11 ` Pranjal Shrivastava
2026-10-06 17:26 ` Nicolin Chen
2026-10-07 14:08 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 12/16] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-09-29 6:05 ` sashiko-bot
2026-09-30 19:02 ` Nicolin Chen
2026-09-30 19:57 ` Pranjal Shrivastava
2026-09-30 20:03 ` Nicolin Chen
2026-09-29 3:45 ` [PATCH v11 13/16] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-09-29 6:17 ` sashiko-bot
2026-10-01 20:22 ` Nicolin Chen
2026-10-07 14:08 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 14/16] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-09-29 6:32 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-09-29 6:41 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 16/16] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-09-29 6:48 ` sashiko-bot
2026-10-01 19:12 ` Nicolin Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929055600.374E01F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=praan@google.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox