[PATCH 4/9] iommufd: Track the domains of pages that are not pinned

From: Fred Griffoul

Date: Tue Oct 06 2026 - 14:36:43 EST


From: Fred Griffoul <fgriffo@xxxxxxxxxxxx>

Memory provider pages, added in the next patch, are not pinned and can
change under the domains that map them, as a dma-buf can. They need the
same list of (area, domain) pairs that the dma-buf revoke uses.

Move that list from struct iopt_pages_dmabuf to struct iopt_pages.

No functional change.

Signed-off-by: Fred Griffoul <fgriffo@xxxxxxxxxxxx>
---
drivers/iommu/iommufd/io_pagetable.c | 24 +++++-----
drivers/iommu/iommufd/io_pagetable.h | 33 +++++++++-----
drivers/iommu/iommufd/pages.c | 67 ++++++++++++++--------------
3 files changed, 67 insertions(+), 57 deletions(-)

diff --git a/drivers/iommu/iommufd/io_pagetable.c b/drivers/iommu/iommufd/io_pagetable.c
index 24d4917105d9..bcd531acc9dd 100644
--- a/drivers/iommu/iommufd/io_pagetable.c
+++ b/drivers/iommu/iommufd/io_pagetable.c
@@ -1008,14 +1008,14 @@ static void iopt_unfill_domain(struct io_pagetable *iopt,
WARN_ON(!area->storage_domain);
if (area->storage_domain == domain)
area->storage_domain = storage_domain;
- if (iopt_is_dmabuf(pages)) {
+ if (iopt_pages_tracked(pages)) {
if (!iopt_dmabuf_revoked(pages))
iopt_area_unmap_domain(area, domain);
- iopt_dmabuf_untrack_domain(pages, area, domain);
+ iopt_pages_untrack_domain(pages, area, domain);
}
mutex_unlock(&pages->mutex);

- if (!iopt_is_dmabuf(pages))
+ if (!iopt_pages_tracked(pages))
iopt_area_unmap_domain(area, domain);
}
return;
@@ -1033,8 +1033,8 @@ static void iopt_unfill_domain(struct io_pagetable *iopt,
WARN_ON(area->storage_domain != domain);
area->storage_domain = NULL;
iopt_area_unfill_domain(area, pages, domain);
- if (iopt_is_dmabuf(pages))
- iopt_dmabuf_untrack_domain(pages, area, domain);
+ if (iopt_pages_tracked(pages))
+ iopt_pages_untrack_domain(pages, area, domain);
mutex_unlock(&pages->mutex);
}
}
@@ -1065,15 +1065,15 @@ static int iopt_fill_domain(struct io_pagetable *iopt,
continue;

guard(mutex)(&pages->mutex);
- if (iopt_is_dmabuf(pages)) {
- rc = iopt_dmabuf_track_domain(pages, area, domain);
+ if (iopt_pages_tracked(pages)) {
+ rc = iopt_pages_track_domain(pages, area, domain);
if (rc)
goto out_unfill;
}
rc = iopt_area_fill_domain(area, domain);
if (rc) {
- if (iopt_is_dmabuf(pages))
- iopt_dmabuf_untrack_domain(pages, area, domain);
+ if (iopt_pages_tracked(pages))
+ iopt_pages_untrack_domain(pages, area, domain);
goto out_unfill;
}
if (!area->storage_domain) {
@@ -1102,8 +1102,8 @@ static int iopt_fill_domain(struct io_pagetable *iopt,
area->storage_domain = NULL;
}
iopt_area_unfill_domain(area, pages, domain);
- if (iopt_is_dmabuf(pages))
- iopt_dmabuf_untrack_domain(pages, area, domain);
+ if (iopt_pages_tracked(pages))
+ iopt_pages_untrack_domain(pages, area, domain);
mutex_unlock(&pages->mutex);
}
return rc;
@@ -1315,7 +1315,7 @@ static int iopt_area_split(struct iopt_area *area, unsigned long iova)
return -EBUSY;

/* Maintaining the domains_itree below is a bit complicated */
- if (iopt_is_dmabuf(pages))
+ if (iopt_pages_tracked(pages))
return -EOPNOTSUPP;

if (new_start & (alignment - 1) ||
diff --git a/drivers/iommu/iommufd/io_pagetable.h b/drivers/iommu/iommufd/io_pagetable.h
index 887ed94474c7..5389227eb6ff 100644
--- a/drivers/iommu/iommufd/io_pagetable.h
+++ b/drivers/iommu/iommufd/io_pagetable.h
@@ -70,15 +70,14 @@ void iopt_area_unfill_domain(struct iopt_area *area, struct iopt_pages *pages,
void iopt_area_unmap_domain(struct iopt_area *area,
struct iommu_domain *domain);

-int iopt_dmabuf_track_domain(struct iopt_pages *pages, struct iopt_area *area,
- struct iommu_domain *domain);
-void iopt_dmabuf_untrack_domain(struct iopt_pages *pages,
- struct iopt_area *area,
- struct iommu_domain *domain);
-int iopt_dmabuf_track_all_domains(struct iopt_area *area,
- struct iopt_pages *pages);
-void iopt_dmabuf_untrack_all_domains(struct iopt_area *area,
- struct iopt_pages *pages);
+int iopt_pages_track_domain(struct iopt_pages *pages, struct iopt_area *area,
+ struct iommu_domain *domain);
+void iopt_pages_untrack_domain(struct iopt_pages *pages, struct iopt_area *area,
+ struct iommu_domain *domain);
+int iopt_pages_track_all_domains(struct iopt_area *area,
+ struct iopt_pages *pages);
+void iopt_pages_untrack_all_domains(struct iopt_area *area,
+ struct iopt_pages *pages);

static inline unsigned long iopt_area_index(struct iopt_area *area)
{
@@ -194,7 +193,8 @@ enum iopt_address_type {
IOPT_ADDRESS_DMABUF,
};

-struct iopt_pages_dmabuf_track {
+/* An area of the pages mapped into a domain, for pages that are not pinned. */
+struct iopt_pages_track {
struct iommu_domain *domain;
struct iopt_area *area;
struct list_head elm;
@@ -205,7 +205,6 @@ struct iopt_pages_dmabuf {
struct phys_vec phys;
/* Always PAGE_SIZE aligned */
unsigned long start;
- struct list_head tracker;
/*
* true if the exporter's phys is CPU RAM (map with IOMMU_CACHE, no
* IOMMU_MMIO); false for MMIO/BAR memory (map with IOMMU_MMIO). Set
@@ -253,6 +252,12 @@ struct iopt_pages {
struct rb_root_cached access_itree;
/* Of iopt_area::pages_node */
struct rb_root_cached domains_itree;
+ /*
+ * Of iopt_pages_track::elm. Pages that are not pinned can change
+ * under the domains that map them, so every (area, domain) that maps
+ * them is listed here. See iopt_pages_tracked().
+ */
+ struct list_head tracker;
};

static inline bool iopt_is_dmabuf(struct iopt_pages *pages)
@@ -262,6 +267,12 @@ static inline bool iopt_is_dmabuf(struct iopt_pages *pages)
return pages->type == IOPT_ADDRESS_DMABUF;
}

+/* The pages are not pinned, so their domains are tracked in pages->tracker. */
+static inline bool iopt_pages_tracked(struct iopt_pages *pages)
+{
+ return iopt_is_dmabuf(pages);
+}
+
static inline bool iopt_dmabuf_revoked(struct iopt_pages *pages)
{
lockdep_assert_held(&pages->mutex);
diff --git a/drivers/iommu/iommufd/pages.c b/drivers/iommu/iommufd/pages.c
index f9b2ae6d7e96..d68f6eea836d 100644
--- a/drivers/iommu/iommufd/pages.c
+++ b/drivers/iommu/iommufd/pages.c
@@ -1392,6 +1392,7 @@ static struct iopt_pages *iopt_alloc_pages(unsigned long start_byte,
pages->npages = DIV_ROUND_UP(length + start_byte, PAGE_SIZE);
pages->access_itree = RB_ROOT_CACHED;
pages->domains_itree = RB_ROOT_CACHED;
+ INIT_LIST_HEAD(&pages->tracker);
pages->writable = writable;
if (capable(CAP_IPC_LOCK))
pages->account_mode = IOPT_PAGES_ACCOUNT_NONE;
@@ -1442,13 +1443,13 @@ struct iopt_pages *iopt_alloc_file_pages(struct file *file,
static void iopt_revoke_notify(struct dma_buf_attachment *attach)
{
struct iopt_pages *pages = attach->importer_priv;
- struct iopt_pages_dmabuf_track *track;
+ struct iopt_pages_track *track;

guard(mutex)(&pages->mutex);
if (iopt_dmabuf_revoked(pages))
return;

- list_for_each_entry(track, &pages->dmabuf.tracker, elm) {
+ list_for_each_entry(track, &pages->tracker, elm) {
struct iopt_area *area = track->area;

iopt_area_unmap_domain_range(area, track->domain,
@@ -1598,7 +1599,6 @@ struct iopt_pages *iopt_alloc_dmabuf_pages(struct iommufd_ctx *ictx,
pages->account_mode = IOPT_PAGES_ACCOUNT_NONE;
pages->type = IOPT_ADDRESS_DMABUF;
pages->dmabuf.start = start - start_byte;
- INIT_LIST_HEAD(&pages->dmabuf.tracker);

rc = iopt_map_dmabuf(ictx, pages, dmabuf);
if (rc) {
@@ -1609,16 +1609,16 @@ struct iopt_pages *iopt_alloc_dmabuf_pages(struct iommufd_ctx *ictx,
return pages;
}

-int iopt_dmabuf_track_domain(struct iopt_pages *pages, struct iopt_area *area,
- struct iommu_domain *domain)
+int iopt_pages_track_domain(struct iopt_pages *pages, struct iopt_area *area,
+ struct iommu_domain *domain)
{
- struct iopt_pages_dmabuf_track *track;
+ struct iopt_pages_track *track;

lockdep_assert_held(&pages->mutex);
- if (WARN_ON(!iopt_is_dmabuf(pages)))
+ if (WARN_ON(!iopt_pages_tracked(pages)))
return -EINVAL;

- list_for_each_entry(track, &pages->dmabuf.tracker, elm)
+ list_for_each_entry(track, &pages->tracker, elm)
if (WARN_ON(track->domain == domain && track->area == area))
return -EINVAL;

@@ -1627,21 +1627,20 @@ int iopt_dmabuf_track_domain(struct iopt_pages *pages, struct iopt_area *area,
return -ENOMEM;
track->domain = domain;
track->area = area;
- list_add_tail(&track->elm, &pages->dmabuf.tracker);
+ list_add_tail(&track->elm, &pages->tracker);

return 0;
}

-void iopt_dmabuf_untrack_domain(struct iopt_pages *pages,
- struct iopt_area *area,
- struct iommu_domain *domain)
+void iopt_pages_untrack_domain(struct iopt_pages *pages, struct iopt_area *area,
+ struct iommu_domain *domain)
{
- struct iopt_pages_dmabuf_track *track;
+ struct iopt_pages_track *track;

lockdep_assert_held(&pages->mutex);
- WARN_ON(!iopt_is_dmabuf(pages));
+ WARN_ON(!iopt_pages_tracked(pages));

- list_for_each_entry(track, &pages->dmabuf.tracker, elm) {
+ list_for_each_entry(track, &pages->tracker, elm) {
if (track->domain == domain && track->area == area) {
list_del(&track->elm);
kfree(track);
@@ -1651,36 +1650,36 @@ void iopt_dmabuf_untrack_domain(struct iopt_pages *pages,
WARN_ON(true);
}

-int iopt_dmabuf_track_all_domains(struct iopt_area *area,
- struct iopt_pages *pages)
+int iopt_pages_track_all_domains(struct iopt_area *area,
+ struct iopt_pages *pages)
{
- struct iopt_pages_dmabuf_track *track;
+ struct iopt_pages_track *track;
struct iommu_domain *domain;
unsigned long index;
int rc;

- list_for_each_entry(track, &pages->dmabuf.tracker, elm)
+ list_for_each_entry(track, &pages->tracker, elm)
if (WARN_ON(track->area == area))
return -EINVAL;

xa_for_each(&area->iopt->domains, index, domain) {
- rc = iopt_dmabuf_track_domain(pages, area, domain);
+ rc = iopt_pages_track_domain(pages, area, domain);
if (rc)
goto err_untrack;
}
return 0;
err_untrack:
- iopt_dmabuf_untrack_all_domains(area, pages);
+ iopt_pages_untrack_all_domains(area, pages);
return rc;
}

-void iopt_dmabuf_untrack_all_domains(struct iopt_area *area,
- struct iopt_pages *pages)
+void iopt_pages_untrack_all_domains(struct iopt_area *area,
+ struct iopt_pages *pages)
{
- struct iopt_pages_dmabuf_track *track;
- struct iopt_pages_dmabuf_track *tmp;
+ struct iopt_pages_track *track;
+ struct iopt_pages_track *tmp;

- list_for_each_entry_safe(track, tmp, &pages->dmabuf.tracker,
+ list_for_each_entry_safe(track, tmp, &pages->tracker,
elm) {
if (track->area == area) {
list_del(&track->elm);
@@ -1697,6 +1696,7 @@ void iopt_release_pages(struct kref *kref)
WARN_ON(!RB_EMPTY_ROOT(&pages->domains_itree.rb_root));
WARN_ON(pages->npinned);
WARN_ON(!xa_empty(&pages->pinned_pfns));
+ WARN_ON(!list_empty(&pages->tracker));
if (iopt_is_dmabuf(pages) && pages->dmabuf.attach) {
struct dma_buf *dmabuf = pages->dmabuf.attach->dmabuf;

@@ -1705,7 +1705,6 @@ void iopt_release_pages(struct kref *kref)
dma_resv_unlock(dmabuf->resv);
dma_buf_detach(dmabuf, pages->dmabuf.attach);
dma_buf_put(dmabuf);
- WARN_ON(!list_empty(&pages->dmabuf.tracker));
} else if (pages->type == IOPT_ADDRESS_FILE) {
fput(pages->file);
}
@@ -1790,7 +1789,7 @@ static void __iopt_area_unfill_domain(struct iopt_area *area,

lockdep_assert_held(&pages->mutex);

- if (iopt_is_dmabuf(pages)) {
+ if (iopt_pages_tracked(pages)) {
if (WARN_ON(iopt_dmabuf_revoked(pages)))
return;
iopt_area_unmap_domain_range(area, domain, start_index,
@@ -1958,8 +1957,8 @@ int iopt_area_fill_domains(struct iopt_area *area, struct iopt_pages *pages)
return 0;

mutex_lock(&pages->mutex);
- if (iopt_is_dmabuf(pages)) {
- rc = iopt_dmabuf_track_all_domains(area, pages);
+ if (iopt_pages_tracked(pages)) {
+ rc = iopt_pages_track_all_domains(area, pages);
if (rc)
goto out_unlock;
}
@@ -2024,8 +2023,8 @@ int iopt_area_fill_domains(struct iopt_area *area, struct iopt_pages *pages)
}
pfn_reader_destroy(&pfns);
out_untrack:
- if (iopt_is_dmabuf(pages))
- iopt_dmabuf_untrack_all_domains(area, pages);
+ if (iopt_pages_tracked(pages))
+ iopt_pages_untrack_all_domains(area, pages);
out_unlock:
mutex_unlock(&pages->mutex);
return rc;
@@ -2065,8 +2064,8 @@ void iopt_area_unfill_domains(struct iopt_area *area, struct iopt_pages *pages)
WARN_ON(RB_EMPTY_NODE(&area->pages_node.rb));
interval_tree_remove(&area->pages_node, &pages->domains_itree);
iopt_area_unfill_domain(area, pages, area->storage_domain);
- if (iopt_is_dmabuf(pages))
- iopt_dmabuf_untrack_all_domains(area, pages);
+ if (iopt_pages_tracked(pages))
+ iopt_pages_untrack_all_domains(area, pages);
area->storage_domain = NULL;
out_unlock:
mutex_unlock(&pages->mutex);