Re: [PATCH RFC v5 2/6] iommu/arm-smmu-v3: Allocate streams individually

From: Robin Murphy

Date: Thu Oct 08 2026 - 09:26:16 EST


On 08/10/2026 12:17 am, Nicolin Chen wrote:
On Tue, Oct 06, 2026 at 08:19:08PM +0800, Peng Fan (OSS) wrote:
From: Peng Fan <peng.fan@xxxxxxx>

Change master->streams from an embedded array of struct arm_smmu_stream
to an array of pointers, with each stream individually allocated.

Prepare for shared-SID support where multiple masters will point to the
same stream object. With embedded structs, sharing requires duplicating
stream state and manually keeping fields like ste_installed in sync.
With individually allocated streams, a sharing master can simply point to
the existing stream.

The sort comparator is updated to dereference the pointer indirection.

No functional change.

Suggested-by: Nicolin Chen <nicolinc@xxxxxxxxxx>
Link: https://lore.kernel.org/linux-iommu/arG6hmng3NddGEHm@xxxxxxxxxx/
Assisted-by: LLM
Signed-off-by: Peng Fan <peng.fan@xxxxxxx>

Reviewed-by: Nicolin Chen <nicolinc@xxxxxxxxxx>

diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index 6644075c1431e..bc62a3d5a63f9 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -1257,7 +1257,7 @@ static int tegra241_vintf_init_vsid(struct iommufd_vdevice *vdev)
struct arm_smmu_master *master = dev_iommu_priv_get(dev);
struct tegra241_vintf *vintf = viommu_to_vintf(vdev->viommu);
struct tegra241_vintf_sid *vsid = vdev_to_vsid(vdev);
- struct arm_smmu_stream *stream = &master->streams[0];
+ struct arm_smmu_stream *stream = master->streams[0];

Sashiko raised a concern of an out-of-bounds pointer dereference.

Though it's practically not possible, probably it would be safer
to move this behind the check:

if (master->num_streams != 1)
return -EOPNOTSUPP;

The IORT path unconditionally adds 1 ID via acpi_iommu_fwspec_init(), so num_streams==0 could only potentially happen with DT if a fwspec was parsed using #iommu-cells==0, except arm_smmu_device_dt_probe() would refuse to probe the entire SMMU if that was anything other than 1, so no, this definitely cannot ever be out of bounds.

Thanks,
Robin.