[PATCH] iommu/amd: allow identity domain during device release
From: Kevin Mitchell
Date: Thu Oct 08 2026 - 16:29:19 EST
A warning is triggered in amd_iommu_release_device() on removal of a
device with an IOMMU_RESV_DIRECT region. The warning is based on the
false assumption that correct attachment to the release_domain will
always result in a NULL dev_data->domain pointer. For devices with
IOMMU_RESV_DIRECT (and consequently dev->iommu->require_direct), the
release domain is the permanent identity_domain which sets
itself to dev_data->domain on attach.
This behaviour was added in commit e94160488e65 ("iommu: Generic support
for RMRs during device release"). Commit c21b34762e2f ("iommu/amd: Set
release_domain to blocked_domain") caused it to take effect for AMD
IOMMU.
Explicitly allow the identity domain pointer to be set. Keep the warning
for any other non-NULL domain.
The warning was observed for a device with direct mapped region:
/sys/bus/pci/devices/0000:04:00.0/iommu_group/reserved_regions:
0x00000000fee00000 0x00000000feefffff msi
0x000000fd00000000 0x000000ffffffffff reserved
0x0000fffd00000000 0x0000ffffffffffff direct
Upon hotunplug:
[ 28.715475] pcieport 0000:00:03.1: pciehp: Slot(0-3): Link Down
[ 28.715482] pcieport 0000:00:03.1: pciehp: Slot(0-3): Card not present
[ 28.715601] ------------[ cut here ]------------
[ 28.715603] WARNING: drivers/iommu/amd/iommu.c:2521 at amd_iommu_release_device+0x5d/0x70, CPU#4: irq/29-pciehp/99
[ 28.715657] RIP: 0010:amd_iommu_release_device+0x5d/0x70
[ 28.715687] Call Trace:
[ 28.715689] <TASK>
[ 28.715694] iommu_deinit_device+0x84/0x110
[ 28.715699] __iommu_group_remove_device+0xa8/0xd0
[ 28.715703] iommu_bus_notifier+0x48/0x70
[ 28.715707] notifier_call_chain+0x48/0xe0
[ 28.715712] blocking_notifier_call_chain+0x45/0x60
[ 28.715716] bus_notify+0x3b/0x60
[ 28.715720] device_del+0x259/0x3b0
[ 28.715730] pci_remove_bus_device+0x85/0x100
[ 28.715735] pciehp_unconfigure_device+0x9d/0x180
[ 28.715743] __pciehp_disable_slot+0x47/0xe0
[ 28.715747] pciehp_handle_presence_or_link_change+0x80/0x5e0
[ 28.715753] pciehp_ist+0x162/0x290
Fixes: c21b34762e2f ("iommu/amd: Set release_domain to blocked_domain")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Kevin Mitchell <kevmitch@xxxxxxxxxx>
---
drivers/iommu/amd/iommu.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/iommu/amd/iommu.c b/drivers/iommu/amd/iommu.c
index 56262f6b1f70..770717e36333 100644
--- a/drivers/iommu/amd/iommu.c
+++ b/drivers/iommu/amd/iommu.c
@@ -2548,11 +2548,17 @@ static struct iommu_device *amd_iommu_probe_device(struct device *dev)
return iommu_dev;
}
+static struct protection_domain identity_domain;
+
static void amd_iommu_release_device(struct device *dev)
{
struct iommu_dev_data *dev_data = dev_iommu_priv_get(dev);
- WARN_ON(dev_data->domain);
+ /*
+ * Devices with direct mapped regions are attached to the
+ * identity_domain as their release_domain.
+ */
+ WARN_ON(dev_data->domain && dev_data->domain != &identity_domain);
/*
* We keep dev_data around for unplugged devices and reuse it when the
@@ -2953,8 +2959,6 @@ static struct iommu_domain blocked_domain = {
}
};
-static struct protection_domain identity_domain;
-
static int amd_iommu_identity_attach(struct iommu_domain *dom, struct device *dev,
struct iommu_domain *old)
{
--
2.51.0