mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 15:22:21 -04:00
iommu/dma: Restore locking around msi_page_list
Unlike a group's default domain, which is always freshly allocated and privately owned (iommu_group_alloc_default_domain()), VFIO type1's legacy container merges any newly attached group into an existing domain whenever their iommu_ops and cache-coherency enforcement match. iommu_dma_get_msi_page() only asserts the caller's own group mutex is held (iommu_group_mutex_assert()). On an IOMMU that publishes IOMMU_RESV_SW_MSI, e.g. ARM SMMU, a VM with two such devices assigned through the legacy container can have their guest drivers probe and allocate MSIs in parallel; each host-side VFIO_DEVICE_SET_IRQS lands on a different device fd and group mutex, but both devices' domains are the same merged domain, so both can enter iommu_dma_get_msi_page() concurrently and corrupt msi_page_list. commit288683c92b("iommu: Make iommu_dma_prepare_msi() into a generic operation") dropped the prior msi_prepare_lock on the reasoning that "each iommu_domain is unique to a group," which holds for default domains but not this VFIO type1 case. Restore the static lock, since it's only guarding a corner case and will likely never be contended. iommufd avoids the equivalent problem by having its own callers (iommufd_sw_map_msi()) take a ctx-wide sw_msi_lock before ever reaching the shared list. VFIO type1 can't mirror that since it dispatches to iommu_dma_sw_msi() which is outside VFIO's jurisdiction. Fixes:288683c92b("iommu: Make iommu_dma_prepare_msi() into a generic operation") Signed-off-by: Andrew Jones <andrew.jones@oss.qualcomm.com> Reviewed-by: Jason Gunthorpe <jgg@nvidia.com> Reviewed-by: Nutty Liu <nutty.liu@hotmail.com> Reviewed-by: Robin Murphy <robin.murphy@arm.com> Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
This commit is contained in:
committed by
Joerg Roedel
parent
41cdc2a3d4
commit
5a9e89ea34
@@ -2204,6 +2204,19 @@ static struct iommu_dma_msi_page *iommu_dma_get_msi_page(struct device *dev,
|
||||
dma_addr_t iova;
|
||||
int prot = IOMMU_WRITE | IOMMU_NOEXEC | IOMMU_MMIO;
|
||||
size_t size = cookie_msi_granule(domain);
|
||||
static DEFINE_MUTEX(msi_prepare_lock);
|
||||
|
||||
/*
|
||||
* Normally a device's default domain is only ever attached to that
|
||||
* device's own group, and the group mutex held by
|
||||
* iommu_group_mutex_assert()'s callers is enough on its own. A VFIO
|
||||
* type1 container is the one case that breaks that assumption: it
|
||||
* can merge devices from different groups onto one domain, so two
|
||||
* devices' group mutexes don't serialize each other here. A static
|
||||
* lock is sufficient due to the expectation that this is a corner
|
||||
* case that will never be contended in practice.
|
||||
*/
|
||||
guard(mutex)(&msi_prepare_lock);
|
||||
|
||||
msi_addr &= ~(phys_addr_t)(size - 1);
|
||||
list_for_each_entry(msi_page, msi_page_list, list)
|
||||
|
||||
Reference in New Issue
Block a user