[PATCH 0/4] iommu: Fix SVA, iommufd, and iommupt error paths
Shuai Xue <[email protected]> Sun, 26 Jul 2026 15:43:28 +0800
| Newsgroups | dev.linux.lists.iommu,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
This series fixes four independent error-path/lifetime issues in the IOMMU core helpers, iommufd, and generic page table code. Patch 1 fixes an SVA race where an attach handle becomes visible before handle->dev is initialized. A racing bind can reuse the handle and later unbind can dereference a NULL handle->dev. Patches 2 and 3 fix iommufd reference/lock leaks. Patch 2 avoids taking an object reference for internal accesses that are skipped by the unmap notification path. Patch 3 releases the current IOAS rwsem and object reference if xa_store() fails before the IOAS is inserted into the unwind list. Patch 4 fixes the generic page table iova_to_phys() op to return 0 on range validation failures. Returning a negative errno from a phys_addr_t function can make callers consume a bogus physical address. All patches are small fixes with Fixes tags and Cc: stable. Shuai Xue (4): iommu/sva: Set handle->dev before the SVA handle is visible iommufd: Avoid locking internal accesses during unmap iommufd: Release current IOAS on xa_store() failure iommupt: Return zero for invalid iova_to_phys() ranges drivers/iommu/generic_pt/iommu_pt.h | 2 +- drivers/iommu/iommu-sva.c | 2 +- drivers/iommu/iommufd/device.c | 4 ++-- drivers/iommu/iommufd/ioas.c | 2 ++ 4 files changed, 6 insertions(+), 4 deletions(-) -- 2.39.3