[PATCH v1 2/4] iommu: Unpublish the attach handle before the PASID detach callback

From: Nicolin Chen

Date: Tue Sep 29 2026 - 17:54:22 EST


iommu_detach_device_pasid() erases the group->pasid_array entry only once
__iommu_remove_group_pasid() has returned, so the detaching handle stays
visible to iommu_attach_handle_get() for the whole of that callback, and
the caller frees it as soon as the detach returns.

Erase the entry ahead of the callback, for the same reason the group path
does: a fault raised in the meantime must not resolve to a domain that is
on its way out.

Fixes: 16603704559c ("iommu: Add attach/detach_dev_pasid iommu interfaces")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Nicolin Chen <nicolinc@xxxxxxxxxx>
---
drivers/iommu/iommu.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/iommu/iommu.c b/drivers/iommu/iommu.c
index a062a84686c29..19b880d23314b 100644
--- a/drivers/iommu/iommu.c
+++ b/drivers/iommu/iommu.c
@@ -3818,8 +3818,12 @@ void iommu_detach_device_pasid(struct iommu_domain *domain, struct device *dev,
struct iommu_group *group = dev->iommu_group;

mutex_lock(&group->mutex);
- __iommu_remove_group_pasid(group, pasid, domain);
+ /*
+ * Unpublish the handle first, so it would not resolve to the detaching
+ * domain once the driver is detaching it.
+ */
xa_erase(&group->pasid_array, pasid);
+ __iommu_remove_group_pasid(group, pasid, domain);
mutex_unlock(&group->mutex);
}
EXPORT_SYMBOL_GPL(iommu_detach_device_pasid);
--
2.43.0