Re: [PATCH v1 2/2] iommu/amd: Fix nested domain leak

From: Ankit Soni

Date: Fri Jul 10 2026 - 11:14:42 EST


On Thu, Jul 09, 2026 at 01:57:36PM -0600, Tycho Andersen wrote:
> From: "Tycho Andersen (AMD)" <tycho@xxxxxxxxxx>
>
> A couple of runs of different AI tools have generated something like the
> following bug report:
>
> In nested_domain_free(), when refcount_dec_and_test() returns false
> (other nested domains still reference the same gdom_info), the function
> returns without calling kfree(ndom), leaking the nested_domain
> structure. This problem wasn't introduced by this patch, but exists in
> the code from commit 757d2b1fdf5b that the patch modifies. Each
> nested_domain (ndom) is allocated individually in
> amd_iommu_alloc_domain_nested() via kzalloc_obj(*ndom). The .free
> callback is the sole point responsible for freeing this domain. When
> the refcount is > 0, only the xa_unlock_irqrestore is performed and the
> function returns, leaving ndom permanently allocated. This leak occurs
> every time a nested domain sharing a gDomID is destroyed while other
> domains still use that gDomID.
>
> There is a similar leak later in this function in the WARN_ON() test when
> the mapping is already NULL. Switch to a RAII-based cleanup for ndom, since
> it should always be freed in this function.
>
> Fixes: 757d2b1fdf5b ("iommu/amd: Introduce gDomID-to-hDomID Mapping and handle parent domain invalidation")
> Signed-off-by: Tycho Andersen (AMD) <tycho@xxxxxxxxxx>

Reviewed-by: Ankit Soni <Ankit.Soni@xxxxxxx>