From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F033A2F7445 for ; Mon, 3 Aug 2026 18:19:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785781183; cv=none; b=qFVnbu8XzM45W4vqsHOaPbz2PkAswdBsmmk8pFs0St7rq6Ve5oh5dvh4juPdTFETllRVMn6nTE/jQSIlyt9j1zECDV+h7m9cjAjEc1PgGOxKC6qJ2C1QpuGKvy5FPZ/x4DRyzmh6yNM1KXdL1Ncqzy0ehzXxrcyAxGtIGi1dIds= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785781183; c=relaxed/simple; bh=dT3CK7NGp5t69RaPY8skYZh7DTJ8Ou8/q30Q/gQN4VE=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=JexUMYSlq5uU91y1MdL6ZIoH9PzQjbO+/EV9y/19RGkDA9wBjCtlwJB6S241Iqy182pLBgJ5Fzgdi0e6AoPHVNaFB8716qWI62ulQw7Kj4SkaPtcMCAO+X2si264rb8np5cRW+raubvmdiDKnhPnVammgEU/k04x5FZBr/XRQ/k= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Vm7TMaE1; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Vm7TMaE1" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2cede6375caso17385ad.0 for ; Mon, 03 Aug 2026 11:19:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785781181; x=1786385981; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=dT3CK7NGp5t69RaPY8skYZh7DTJ8Ou8/q30Q/gQN4VE=; b=Vm7TMaE1J4M0QK8KuIJsExmWt+oIxRkO8ZcPqDgOLtSz8RTtLw0OJtYsAoM51DzZ8P xV74ez+IwdNm1eeT8StvchYGjJSaOZ2Pd0i7pK1Ipnzyq9mgzVyqK5ZBTgKMr8TbNUpg MRpWsz+QbEPefWWXjpwTIsyoszZzvfRo3EToqaDjbDpS2iK/optTHYAJe09JYE9etq7J 6QC3A35guRnRobMEGhuMTpCFi7gbe2SGnesTtbhw48y3CI7xK3w9wTBwYz1fVZ1Y/ZiJ bb0ejAbQ49y9Cn6RKVDamB7fMd89skQqOikcCCnuFTMXpaCn6pg4WXoINNurZ6rHMvVR fUtQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785781181; x=1786385981; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=dT3CK7NGp5t69RaPY8skYZh7DTJ8Ou8/q30Q/gQN4VE=; b=Xe5zRtnUZytd/46tFGp8AwV5jjJICWkFHB2jr974Z7no0MZAQx9dK/azKuUqOvLgR/ D/ZHjZwHmdlhetSB3bxy5IhL/bcUVCRI+2IxDQJ4iguO/y2I1rILshrZ7ktwa6cfXvj5 jKMw0FfwRbTTIK+8ypDKdS6wcfssAjg1h1ip2mm8EqEUjpB8UNhEPVioHJKmFyZD7vSB eP1oAERr985wnENY0ZzjnttWpBc/gUsAwsrZNnbJEOAUcbfl4SbvS3QgUx1TK5KxgjFR PJkqS9xqCSU61UgGEVGDOViXAXAripOYAG/EK7j/RWqiDc9bvYfd8glfxgLyIOQE4+nO 6pkg== X-Forwarded-Encrypted: i=1; AHgh+RoSYG4h650a9dHryJ6oLJ+RdUy/N0uxczID/zDWBu7Z2b5JdnxUgJy1kYonYyHheXNxegTCxHppxesYLB8=@vger.kernel.org X-Gm-Message-State: AOJu0YzJCl+BNTSRQ0cbs07xQ7w2Hs2GVlZnEAe96ootXJ8Y2p/orxqD +tcoE/4+g4fDAXj5UEVzlyG7+TI2rCyKZVWe3Yo937dSRao1xEoUNrf/seIC8jFOEA== X-Gm-Gg: AR+sD13zb8IjC+XKfkqA2zpPUjgV/m3NgsAE3Y40ZMhZPkybgPTneEJ1yjFrNmJ7Y4p mXpQ35hE7jN2dLcfjmmc9xTE5goqrN8GdD5NmF7bYTpW+9lzSJski63OirnrOmRGVlODPHk0led ewYN7ce3v/4OPTLWip/eKpbSJrCzZwmx6GqkYCbwI6NnAZqwKp22gTvKv0ZvE1ndfkZG69Dt80D 2XC4HkFEI0yjHerCEEfXlf1USTl4IWnvEElxsV431X8y8UBHj2vceVHd1OmLnV59d3viIs0h5tr 0mOU8hpeRMH32b0N9WzUScu6+jQkyauhlegkASHebo7nEEOWIuwcBXS/KZf/Cu1pKvNZv3fhVWP pmFdPTNLGdkKvonT8H5r8KVJikZjFFbbdonPAOL8c8rxsf/xRZMapf6bKEspCW326nMnY7X19oE WZY0KgjJX9lVbnLUj/ThJiVMrxsG3c6iXv/w5paV+c92SjxxC57W2K3URLWtbmv68V9vRV3WptV ndKr+QL0dYavF7LGQ9H9EEUVsIPsy1qD7vJvBm6sBRbhIakeZDeUgJxveg= X-Received: by 2002:a17:903:8cd:b0:2c0:defb:557e with SMTP id d9443c01a7336-2d08cda9b92mr1073765ad.1.1785781180682; Mon, 03 Aug 2026 11:19:40 -0700 (PDT) Received: from google.com (210.87.127.34.bc.googleusercontent.com. [34.127.87.210]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04b165e99sm41804515ad.83.2026.08.03.11.19.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 11:19:40 -0700 (PDT) Date: Mon, 3 Aug 2026 18:19:36 +0000 From: Samiullah Khawaja To: Lu Baolu Cc: Joerg Roedel , Will Deacon , Robin Murphy , Jason Gunthorpe , Kevin Tian , iommu@lists.linux.dev, linux-kernel@vger.kernel.org, Sashiko Subject: Re: [PATCH 5/5] iommu/vt-d: Flush context cache with correct SID when tearing down aliases Message-ID: References: <20260731054329.2948252-1-baolu.lu@linux.intel.com> <20260731054329.2948252-6-baolu.lu@linux.intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20260731054329.2948252-6-baolu.lu@linux.intel.com> On Fri, Jul 31, 2026 at 01:43:29PM +0800, Lu Baolu wrote: >domain_context_clear_one() and device_pasid_table_teardown() are both >invoked once per DMA alias of a device. Each function locates the context >entry using the bus/devfn pair provided by the pci_for_each_dma_alias() >callback, then calls intel_context_flush_no_pasid(), which constructs a >device-selective context-cache invalidation from info->bus and >info->devfn (that is, always the requester ID of the device itself). > >As a result, for every alias other than the device’s own RID, the context >entry that was just cleared in memory is never invalidated in the context >cache. Hardware may continue using that stale cached entry. In the >scalable-mode teardown path, intel_pasid_free_table() can then free the >PASID directory still referenced by that stale entry, allowing the IOMMU >to walk freed memory. > >Fix this by passing the source ID of the entry being torn down to >intel_context_flush_no_pasid(), instead of deriving it from @info. > >Fixes: f90584f4beb84 ("iommu/vt-d: Add helper to flush caches for context change") >Reported-by: Sashiko >Closes: https://sashiko.dev/#/patchset/20260602233426.357499-1-baolu.lu%40linux.intel.com >Assisted-by: Claude:claude-opus-5 >Signed-off-by: Lu Baolu >--- > drivers/iommu/intel/iommu.h | 2 +- > drivers/iommu/intel/iommu.c | 2 +- > drivers/iommu/intel/pasid.c | 9 ++++++--- > 3 files changed, 8 insertions(+), 5 deletions(-) > Reviewed-by: Samiullah Khawaja Sami