Re: [RFC PATCH v6 00/11] iommufd: Infrastructure for vIOMMU creation for confidential guests and guest TSM requests
From: Jason Gunthorpe
Date: Mon Sep 28 2026 - 09:29:22 EST
On Mon, Sep 28, 2026 at 03:35:29AM +0000, Tian, Kevin wrote:
> Looks there are some resource shared between the untrust and
> trust invalidation paths, as iommu->qi->q_lock is also acquired
> in the trust path. I still need to understand the motivation behind,
> but this can be resolved properly by exporting a helper to the
> TSM driver even if it's truly required.
That seems a bit suspicious from a security POV.. The secure side
shouldn't be sharing anything like this with the insecure side, that's
just inviting invalidation integrity attacks???
Jason