RE: [PATCH v2 1/4] vfio: Reject a second cdev open before mutating shared device state

From: Tian, Kevin

Date: Wed Sep 16 2026 - 03:05:14 EST


> From: Alex Williamson <alex.williamson@xxxxxxxxxx>
> Sent: Saturday, September 12, 2026 1:04 AM
>
> The cdev single-open check lives in vfio_df_open(), which runs at the
> end of the bind ioctl, after vfio_df_ioctl_bind_iommufd() has already
> updated state shared across all opens: vfio_df_check_token() can set
> the PF vf_token and vfio_df_get_kvm_safe() records the caller's KVM
> pointer in device->kvm and takes a reference.
>
> A second cdev bind of an already-open device runs both, only to be
> rejected in vfio_df_open(). The error path clears device->kvm and
> drops the reference, tearing down the current opener's KVM association
> and potentially resulting in an unbalanced reference on close or
> premature release, while the vf_token remains clobbered.
>
> Move the single-open check into vfio_df_ioctl_bind_iommufd() ahead of
> both mutations, so a bind that cannot complete leaves the current
> opener's state untouched. df->group is NULL on this path, so a
> non-zero open_count is exactly what vfio_df_open() rejected. The test
> in vfio_df_open() becomes redundant and is removed.
>
> Return -EBUSY rather than -EINVAL here. The arguments are not invalid,
> the device is in use, which could be a transient condition due to a
> delayed fput if the prior user is terminated. This provides
> compatibility with the group path, where a group open returns -EBUSY,
> and users may choose bounded polling to detect such a transient
> condition.
>
> Fixes: 839e692fa4eb ("vfio: Make vfio_df_open() single open for device cdev
> path")
> Fixes: 5fcc26969a16 ("vfio: Add VFIO_DEVICE_BIND_IOMMUFD")
> Fixes: 86624ba3b522 ("vfio/pci: Do vf_token checks for
> VFIO_DEVICE_BIND_IOMMUFD")
> Assisted-by: LLM
> Reviewed-by: Jason Gunthorpe <jgg@xxxxxxxxxx>
> Signed-off-by: Alex Williamson <alex.williamson@xxxxxxxxxx>

Reviewed-by: Kevin Tian <kevin.tian@xxxxxxxxx>