[PATCH v1 0/4] iommu: Fix attach handle publication ordering
From: Nicolin Chen
Date: Tue Sep 29 2026 - 17:54:20 EST
Jason pointed out an issue in the attach handle replacing path:
https://lore.kernel.org/linux-iommu/20260923233920.GJ2545495@xxxxxxxxxx/
When an attachment is detached or replaced, the IOMMU core can still leave
the outgoing attach handle published while calling into the driver. A fault
report looks up the handle without the group mutex, so it can find the old
handle after the driver's fault flush and just before the caller frees it.
These four patches unpublish the outgoing handle before a driver callback
for both group and PASID detach and replace operations. Both replace paths
store XA_ZERO_ENTRY to reserve the slot and restore the old entry on error.
This blocks new lookups, but does not retire a fault that already obtained
the old handle. The driver must still synchronize those readers before the
handle is freed. A same-domain replacement skips the driver callback, so it
still needs a separate lifetime mechanism or fence.
This is on GitHub:
https://github.com/nicolinc/iommufd/commits/fix_iommu_attach_handle-v1
Nicolin Chen (4):
iommu: Unpublish the attach handle before the group detach callback
iommu: Unpublish the attach handle before the PASID detach callback
iommu: Unpublish the old attach handle before the group replace
callback
iommu: Unpublish the old attach handle before the PASID replace
callback
drivers/iommu/iommu.c | 54 ++++++++++++++++++++++++++++---------------
1 file changed, 35 insertions(+), 19 deletions(-)
base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
--
2.43.0