public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Jason Gunthorpe <jgg@nvidia.com>
To: Nicolin Chen <nicolinc@nvidia.com>
Cc: kevin.tian@intel.com, will@kernel.org, joro@8bytes.org,
	suravee.suthikulpanit@amd.com, robin.murphy@arm.com,
	dwmw2@infradead.org, baolu.lu@linux.intel.com, shuah@kernel.org,
	linux-kernel@vger.kernel.org, iommu@lists.linux.dev,
	linux-arm-kernel@lists.infradead.org,
	linux-kselftest@vger.kernel.org, eric.auger@redhat.com,
	jean-philippe@linaro.org, mdf@kernel.org, mshavit@google.com,
	shameerali.kolothum.thodi@huawei.com, smostafa@google.com,
	yi.l.liu@intel.com, aik@amd.com, zhangfei.gao@linaro.org,
	patches@lists.linux.dev
Subject: Re: [PATCH v5 03/13] iommufd: Add iommufd_verify_unfinalized_object
Date: Tue, 29 Oct 2024 15:55:58 -0300	[thread overview]
Message-ID: <20241029185558.GZ6956@nvidia.com> (raw)
In-Reply-To: <ZyEKvcpgUsS1nCEg@Asurada-Nvidia>

On Tue, Oct 29, 2024 at 09:18:05AM -0700, Nicolin Chen wrote:
> On Tue, Oct 29, 2024 at 11:49:07AM -0300, Jason Gunthorpe wrote:
> > On Fri, Oct 25, 2024 at 04:49:43PM -0700, Nicolin Chen wrote:
> > > To support driver-allocated vIOMMU objects, it's suggested to call the
> > > allocator helper in IOMMU dirvers. However, there is no guarantee that
> > > drivers will all use it and allocate objects properly.
> > > 
> > > Add a helper for iommufd core to verify if an unfinalized object is at
> > > least reserved in the ictx.
> > 
> > I don't think we need this..
> > 
> > iommufd_object_finalize() already does:
> > 
> > 	old = xa_store(&ictx->objects, obj->id, obj, GFP_KERNEL);
> > 	/* obj->id was returned from xa_alloc() so the xa_store() cannot fail */
> > 	WARN_ON(old);
> 
> It feels unsafe to carry on the iommufd_viommu_alloc_ioctl() until
> iommufd_object_finalize() as the function would touch the returned
> faulty viommu pointer? E.g. what if the viommu has an even smaller
> size than struct iommufd_viommu?

This is Linux just because the output came from a driver doesn't mean
we have to validate it somehow. It is reasonable to be helpful and
detect driver bugs, but if the driver is buggy it is still OK to
crash.

So you don't *have* to check any of this, if the driver didn't use the
right function to allocate the memory then it will go bad pretty fast.

Improving the xa_store() is something that will detect more kinds of
bugs everywhere, so seems more worthwhile

> I think we'd need the same change in iommufd_object_abort() too.

Makes sense

Jason

  reply	other threads:[~2024-10-29 18:56 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-10-25 23:49 [PATCH v5 00/13] iommufd: Add vIOMMU infrastructure (Part-1) Nicolin Chen
2024-10-25 23:49 ` [PATCH v5 01/13] iommufd: Move struct iommufd_object to public iommufd header Nicolin Chen
2024-10-25 23:49 ` [PATCH v5 02/13] iommufd: Introduce IOMMUFD_OBJ_VIOMMU and its related struct Nicolin Chen
2024-10-28  2:41   ` Tian, Kevin
2024-10-29 14:42   ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 03/13] iommufd: Add iommufd_verify_unfinalized_object Nicolin Chen
2024-10-29 14:49   ` Jason Gunthorpe
2024-10-29 16:18     ` Nicolin Chen
2024-10-29 18:55       ` Jason Gunthorpe [this message]
2024-10-29 19:32         ` Nicolin Chen
2024-10-30  4:05         ` Nicolin Chen
2024-10-30 12:53           ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 04/13] iommufd/viommu: Add IOMMU_VIOMMU_ALLOC ioctl Nicolin Chen
2024-10-28  2:43   ` Tian, Kevin
2024-10-29 14:54   ` Jason Gunthorpe
2024-10-29 15:36     ` Jason Gunthorpe
2024-10-29 15:46       ` Nicolin Chen
2024-10-29 15:59         ` Jason Gunthorpe
2024-10-29 16:03           ` Nicolin Chen
2024-10-29 15:37     ` Nicolin Chen
2024-10-25 23:49 ` [PATCH v5 05/13] iommufd: Add alloc_domain_nested op to iommufd_viommu_ops Nicolin Chen
2024-10-29 15:25   ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 06/13] iommufd: Allow pt_id to carry viommu_id for IOMMU_HWPT_ALLOC Nicolin Chen
2024-10-28  2:46   ` Tian, Kevin
2024-10-28  3:24   ` Zhangfei Gao
2024-10-28 13:03     ` Jason Gunthorpe
2024-10-28 14:52       ` Nicolin Chen
2024-10-28 21:08         ` Nicolin Chen
2024-10-29 15:27         ` Jason Gunthorpe
2024-10-29 16:07           ` Nicolin Chen
2024-10-29 18:53             ` Jason Gunthorpe
2024-10-28 14:53     ` Zhangfei Gao
2024-10-28 15:01       ` Nicolin Chen
2024-10-25 23:49 ` [PATCH v5 07/13] iommufd/selftest: Add container_of helpers Nicolin Chen
2024-10-28  2:46   ` Tian, Kevin
2024-10-29 15:28   ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 08/13] iommufd/selftest: Prepare for mock_viommu_alloc_domain_nested() Nicolin Chen
2024-10-28  2:48   ` Tian, Kevin
2024-10-29 15:30   ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 09/13] iommufd/selftest: Add refcount to mock_iommu_device Nicolin Chen
2024-10-28  2:49   ` Tian, Kevin
2024-10-29 15:34   ` Jason Gunthorpe
2024-10-29 16:02     ` Nicolin Chen
2024-10-29 18:53       ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 10/13] iommufd/selftest: Add IOMMU_VIOMMU_TYPE_SELFTEST Nicolin Chen
2024-10-28  2:51   ` Tian, Kevin
2024-10-29 15:41   ` Jason Gunthorpe
2024-10-25 23:49 ` [PATCH v5 11/13] iommufd/selftest: Add IOMMU_VIOMMU_ALLOC test coverage Nicolin Chen
2024-10-28  2:52   ` Tian, Kevin
2024-10-25 23:49 ` [PATCH v5 12/13] Documentation: userspace-api: iommufd: Update vIOMMU Nicolin Chen
2024-10-30  6:16   ` Nicolin Chen
2024-10-25 23:49 ` [PATCH v5 13/13] iommu/arm-smmu-v3: Add IOMMU_VIOMMU_TYPE_ARM_SMMUV3 support Nicolin Chen
2024-10-28  2:54   ` Tian, Kevin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20241029185558.GZ6956@nvidia.com \
    --to=jgg@nvidia.com \
    --cc=aik@amd.com \
    --cc=baolu.lu@linux.intel.com \
    --cc=dwmw2@infradead.org \
    --cc=eric.auger@redhat.com \
    --cc=iommu@lists.linux.dev \
    --cc=jean-philippe@linaro.org \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=mdf@kernel.org \
    --cc=mshavit@google.com \
    --cc=nicolinc@nvidia.com \
    --cc=patches@lists.linux.dev \
    --cc=robin.murphy@arm.com \
    --cc=shameerali.kolothum.thodi@huawei.com \
    --cc=shuah@kernel.org \
    --cc=smostafa@google.com \
    --cc=suravee.suthikulpanit@amd.com \
    --cc=will@kernel.org \
    --cc=yi.l.liu@intel.com \
    --cc=zhangfei.gao@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox