Re: [PATCH RFC v3 1/3] iommu/arm-smmu-v3: Support shared SIDs in insert/remove_master
From: Peng Fan
Date: Thu Oct 01 2026 - 08:59:00 EST
On Wed, Sep 30, 2026 at 11:11:51AM -0700, Nicolin Chen wrote:
>On Wed, Sep 30, 2026 at 07:25:01PM +0800, Peng Fan (OSS) wrote:
>> @@ -4115,7 +4128,10 @@ static int arm_smmu_insert_master(struct arm_smmu_device *smmu,
>>
>> new_stream->id = fwspec->ids[i];
>> new_stream->master = master;
>> + new_stream->ste_installed = false;
>
>ste_installed is zero-ed.
Fix in V4.
>
>> @@ -4136,23 +4152,29 @@ static int arm_smmu_insert_master(struct arm_smmu_device *smmu,
>> existing = rb_find_add(&new_stream->node, &smmu->streams,
....
>>
>> kfree(master->streams);
>
>.. when the owner stream gets freed with the master_a, the shared
>stream would UAF:
>
> master_b->stream[0] --> new shared stream (SID=X) {shared_masters}
> |
> ---------------- shared_masters_elm ----------|
> v
> {freed}
>
>This should be changed to the model that I suggested in v2:
>
> |---------------------------------------------------------|
> | |
> | |----------- shared_masters_elm --------| |
> v | | |
> master_a->stream[0] --| v |
> |--> stream (SID=X) {shared_masters; master;}
> master_b->stream[0] --| ^
> | |
> |----------- shared_masters_elm --------|
>
>When any master is removed:
> * Delink its shared_masters_elm
> * Free the shared stream when its shared_masters is empty
>
>If shared_masters isn't empty but the owner is removed:
> * Give the ownership (stream->master pointer) to the next master
Thanks for detailed explanation. I just posted out v4, hope v4
is well following your suggestion if I not miss-understand anything.
Thanks,
Peng
>
>Nicolin
>
>