RE: [PATCH] iommufd: Reject DMABUF pages from the access pin path

From: Tian, Kevin

Date: Mon Jul 13 2026 - 02:11:47 EST


> From: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>
> Sent: Thursday, July 9, 2026 1:08 PM
>
> DMABUF pages are not supported for iommufd access pinning.
> iommufd_access_pin_pages() returns struct page pointers for
> in-kernel CPU access, but DMABUF-backed iopt_pages do not carry
> a userspace address that can be passed to the GUP path.
>
> iopt_pages_rw_access() already rejects IOPT_ADDRESS_DMABUF before
> doing
> CPU access. Apply the same rejection to iopt_area_add_access() before it
> takes pages->mutex and calls iopt_pages_fill_xarray().
> Otherwise a DMABUF-backed iopt_pages can reach the hole-fill path, where
> pfn_reader_user_pin() interprets the union as uptr and
> calls pin_user_pages_fast()/pin_user_pages_remote().
>
> This fix also avoids the lockdep warning reported from that path, where
> pages_dmabuf_mutex_key is held while gup_fast_fallback() may acquire
> mmap_lock.
>
> Reported-by: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>

this is not required when you are the author

> Closes: https://lore.kernel.org/all/E8540D7D05768C91+8b2ef227-3368-494e-
> 909d-7b28e1489dfb@xxxxxxxxxxxxxxxx/
> Fixes: 71db84a092c3 ("iommufd: Add DMABUF to iopt_pages")
> Cc: stable@xxxxxxxxxxxxxxx
> Tested-by: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>
> Signed-off-by: Peiyang He <peiyang_he@xxxxxxxxxxxxxxxx>

Reviewed-by: Kevin Tian <kevin.tian@xxxxxxxxx>