[RFC PATCH v2 05/16] vfio/pci: Fail BAR faults while access is blocked
From: Shameer Kolothum
Date: Tue Sep 29 2026 - 13:36:00 EST
Hold access_srcu across PFN insertion in the BAR fault handler. This
ensures recovery waits for an insertion before revoking the mapping.
Return VM_FAULT_SIGBUS rather than wait for recovery in the fault
handler when access is blocked. Whether userspace can handle the
resulting failure depends on the architecture and KVM fault-reporting
path.
Assisted-by: LLM
Signed-off-by: Shameer Kolothum <skolothumtho@xxxxxxxxxx>
---
drivers/vfio/pci/vfio_pci_core.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
index 323038cd0ca5..1c8e39f3f509 100644
--- a/drivers/vfio/pci/vfio_pci_core.c
+++ b/drivers/vfio/pci/vfio_pci_core.c
@@ -1842,8 +1842,19 @@ static vm_fault_t vfio_pci_mmap_huge_fault(struct vm_fault *vmf,
vm_fault_t ret = VM_FAULT_FALLBACK;
if (is_aligned_for_order(vma, addr, pfn, order)) {
+ int idx;
+
+ /*
+ * Hold access_srcu across PFN insertion so recovery cannot
+ * finish revoking mappings before this insertion completes.
+ */
+ idx = vfio_pci_core_access_begin(vdev);
+ if (idx < 0)
+ return VM_FAULT_SIGBUS;
+
scoped_guard(rwsem_read, &vdev->memory_lock)
ret = vfio_pci_vmf_insert_pfn(vdev, vmf, pfn, order);
+ vfio_pci_core_access_end(vdev, idx);
}
dev_dbg_ratelimited(&vdev->pdev->dev,
--
2.43.0