Re: [PATCH v2 0/3] iommufd: Fix vDEVICE allocation lifecycle bugs
From: Pranjal Shrivastava
Date: Tue Jul 14 2026 - 10:35:26 EST
On Tue, Jul 14, 2026 at 11:06:07AM -0300, Jason Gunthorpe wrote:
> On Sun, Jul 05, 2026 at 10:36:08PM -0700, Nicolin Chen wrote:
> > Sashiko flagged a few bugs in how IOMMU_VDEVICE_ALLOC creates and validates
> > a vDEVICE on a vIOMMU:
> >
> > - the core publishes a vDEVICE into the vIOMMU xarray before the driver's
> > vdevice_init() runs, so a concurrent invalidation can reach one it has
> > not yet accepted;
> > - the undersized-vdevice_size guard returns holding the igroup mutex,
> > deadlocking later vDEVICE operations on that group;
> > - the Arm SMMUv3 vIOMMU accepts a device without exactly one Stream ID:
> > an out-of-bounds streams[] read for none, stale ATC/IOTLB for several.
> >
> > Fix each of them properly.
> >
> > This is on Github:
> > https://github.com/nicolinc/iommufd/commits/fix_vdevice_sashiko-v2
> >
> > Changelog
> > v2
> > * Add "Reviewed-by" from Kevin
> > * Patch-2: Add "Cc stable"; drop the out_release label by inlining the
> > xa_release() call
> > * Patch-2: Note that the reserved slot is hidden only via xa_* helpers
> > * Patch-3: Return -EOPNOTSUPP instead of -EINVAL
> > v1
> > https://lore.kernel.org/all/cover.1782767110.git.nicolinc@xxxxxxxxxx/
> >
> > Nicolin Chen (3):
> > iommufd/viommu: Release the igroup lock on the vdevice_size error path
> > iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
> > iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
> >
> > .../arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 15 +++++++++++++
> > drivers/iommu/iommufd/viommu.c | 22 ++++++++++++++-----
> > 2 files changed, 31 insertions(+), 6 deletions(-)
>
> Applied to for-rc
>
Oops, sorry. I missed this while looking at patches in mutt. Feel free
to ignore my R-b if I'm too late.
Thanks,
Praan