if an entry has non inclusive overlap with the notifier, print warning
message and do not do notification for it.
Out of scope mapping/unmapping would cause problem, as in below case:
1. initially there are two notifiers with ranges
0-0xfedfffff, 0xfef00000-0xffffffffffffffff,
IOVAs from 0x3c000000 - 0x3c1fffff is in shadow page table.
2. in vfio, memory_region_register_iommu_notifier() is followed by
memory_region_iommu_replay(), which will first call address space
unmap,
and walk and add back all entries in vtd shadow page table. e.g.
(1) for notifier 0-0xfedfffff,
IOVAs from 0 - 0xffffffff get unmapped,
and IOVAs from 0x3c000000 - 0x3c1fffff get mapped
(2) for notifier 0xfef00000-0xffffffffffffffff
IOVAs from 0 - 0x7fffffffff get unmapped,
but IOVAs from 0x3c000000 - 0x3c1fffff cannot get mapped back.
Cc: Eric Auger <eric.auger@redhat.com>
Cc: Peter Xu <peterx@redhat.com>
Signed-off-by: Yan Zhao <yan.y.zhao@intel.com>
---
v5:
1. still using warn_report instead of "assert"
2. returning at the end to refuse notification for entry which has non
inclusive overlap with the notifier.
3. updated commit title and warning message.
v4:
1. modified commit title
2. using "assert" instead of printing warning message
v3:
refined code style and message format
v2:
1. added a local variable entry_end (Eric Auger)
2. using PRIx64 as format for address range in warning message
(Eric Auger)
---
memory.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/memory.c b/memory.c
index 0a089a7..fe0d08d 100644
--- a/memory.c
+++ b/memory.c
@@ -1937,13 +1937,13 @@ void memory_region_notify_one(IOMMUNotifier *notifier,
IOMMUTLBEntry *entry)
{
IOMMUNotifierFlag request_flags;
+ hwaddr entry_end = entry->iova + entry->addr_mask;
/*
* Skip the notification if the notification does not overlap
* with registered range.
*/
- if (notifier->start > entry->iova + entry->addr_mask ||
- notifier->end < entry->iova) {
+ if (notifier->start > entry_end || notifier->end < entry->iova) {
return;
}
@@ -1953,6 +1953,18 @@ void memory_region_notify_one(IOMMUNotifier *notifier,
request_flags = IOMMU_NOTIFIER_UNMAP;
}
+ if (entry->iova < notifier->start || entry_end > notifier->end) {
+ warn_report("IOMMUTLBEntry 0x%" PRIx64 " - 0x%" PRIx64
+ " has non inclusive overlap with notifier 0x%" PRIx64
+ " - 0x%" PRIx64 ". %s is not allowed."
+ " Try to divide it into smaller sections.",
+ entry->iova, entry_end,
+ notifier->start, notifier->end,
+ (request_flags == IOMMU_NOTIFIER_MAP) ?
+ "Mapping" : "Unmapping");
+ return;
+ }
+
if (notifier->notifier_flags & request_flags) {
notifier->notify(notifier, entry);
}
--
2.7.4
Hi Yan, On 6/29/19 12:19 AM, Yan Zhao wrote: > if an entry has non inclusive overlap with the notifier, print warning > message and do not do notification for it. > > Out of scope mapping/unmapping would cause problem, as in below case: > > 1. initially there are two notifiers with ranges > 0-0xfedfffff, 0xfef00000-0xffffffffffffffff, > IOVAs from 0x3c000000 - 0x3c1fffff is in shadow page table. > > 2. in vfio, memory_region_register_iommu_notifier() is followed by > memory_region_iommu_replay(), which will first call address space > unmap, > and walk and add back all entries in vtd shadow page table. e.g. > (1) for notifier 0-0xfedfffff, > IOVAs from 0 - 0xffffffff get unmapped, > and IOVAs from 0x3c000000 - 0x3c1fffff get mapped > (2) for notifier 0xfef00000-0xffffffffffffffff > IOVAs from 0 - 0x7fffffffff get unmapped, > but IOVAs from 0x3c000000 - 0x3c1fffff cannot get mapped back. > > Cc: Eric Auger <eric.auger@redhat.com> > Cc: Peter Xu <peterx@redhat.com> > Signed-off-by: Yan Zhao <yan.y.zhao@intel.com> Reviewed-by: Eric Auger <eric.auger@redhat.com> Thanks Eric > > --- > v5: > 1. still using warn_report instead of "assert" > 2. returning at the end to refuse notification for entry which has non > inclusive overlap with the notifier. > 3. updated commit title and warning message. > > v4: > 1. modified commit title > 2. using "assert" instead of printing warning message > > v3: > refined code style and message format > > v2: > 1. added a local variable entry_end (Eric Auger) > 2. using PRIx64 as format for address range in warning message > (Eric Auger) > --- > memory.c | 16 ++++++++++++++-- > 1 file changed, 14 insertions(+), 2 deletions(-) > > diff --git a/memory.c b/memory.c > index 0a089a7..fe0d08d 100644 > --- a/memory.c > +++ b/memory.c > @@ -1937,13 +1937,13 @@ void memory_region_notify_one(IOMMUNotifier *notifier, > IOMMUTLBEntry *entry) > { > IOMMUNotifierFlag request_flags; > + hwaddr entry_end = entry->iova + entry->addr_mask; > > /* > * Skip the notification if the notification does not overlap > * with registered range. > */ > - if (notifier->start > entry->iova + entry->addr_mask || > - notifier->end < entry->iova) { > + if (notifier->start > entry_end || notifier->end < entry->iova) { > return; > } > > @@ -1953,6 +1953,18 @@ void memory_region_notify_one(IOMMUNotifier *notifier, > request_flags = IOMMU_NOTIFIER_UNMAP; > } > > + if (entry->iova < notifier->start || entry_end > notifier->end) { > + warn_report("IOMMUTLBEntry 0x%" PRIx64 " - 0x%" PRIx64 > + " has non inclusive overlap with notifier 0x%" PRIx64 > + " - 0x%" PRIx64 ". %s is not allowed." > + " Try to divide it into smaller sections.", > + entry->iova, entry_end, > + notifier->start, notifier->end, > + (request_flags == IOMMU_NOTIFIER_MAP) ? > + "Mapping" : "Unmapping"); > + return; > + } > + > if (notifier->notifier_flags & request_flags) { > notifier->notify(notifier, entry); > } >
On Mon, Jul 01, 2019 at 06:10:33PM +0800, Auger Eric wrote: > Hi Yan, > > On 6/29/19 12:19 AM, Yan Zhao wrote: > > if an entry has non inclusive overlap with the notifier, print warning > > message and do not do notification for it. > > > > Out of scope mapping/unmapping would cause problem, as in below case: > > > > 1. initially there are two notifiers with ranges > > 0-0xfedfffff, 0xfef00000-0xffffffffffffffff, > > IOVAs from 0x3c000000 - 0x3c1fffff is in shadow page table. > > > > 2. in vfio, memory_region_register_iommu_notifier() is followed by > > memory_region_iommu_replay(), which will first call address space > > unmap, > > and walk and add back all entries in vtd shadow page table. e.g. > > (1) for notifier 0-0xfedfffff, > > IOVAs from 0 - 0xffffffff get unmapped, > > and IOVAs from 0x3c000000 - 0x3c1fffff get mapped > > (2) for notifier 0xfef00000-0xffffffffffffffff > > IOVAs from 0 - 0x7fffffffff get unmapped, > > but IOVAs from 0x3c000000 - 0x3c1fffff cannot get mapped back. > > > > Cc: Eric Auger <eric.auger@redhat.com> > > Cc: Peter Xu <peterx@redhat.com> > > Signed-off-by: Yan Zhao <yan.y.zhao@intel.com> > Reviewed-by: Eric Auger <eric.auger@redhat.com> > > Thanks > > Eric Thank you, Eric :) Yan > > > > --- > > v5: > > 1. still using warn_report instead of "assert" > > 2. returning at the end to refuse notification for entry which has non > > inclusive overlap with the notifier. > > 3. updated commit title and warning message. > > > > v4: > > 1. modified commit title > > 2. using "assert" instead of printing warning message > > > > v3: > > refined code style and message format > > > > v2: > > 1. added a local variable entry_end (Eric Auger) > > 2. using PRIx64 as format for address range in warning message > > (Eric Auger) > > --- > > memory.c | 16 ++++++++++++++-- > > 1 file changed, 14 insertions(+), 2 deletions(-) > > > > diff --git a/memory.c b/memory.c > > index 0a089a7..fe0d08d 100644 > > --- a/memory.c > > +++ b/memory.c > > @@ -1937,13 +1937,13 @@ void memory_region_notify_one(IOMMUNotifier *notifier, > > IOMMUTLBEntry *entry) > > { > > IOMMUNotifierFlag request_flags; > > + hwaddr entry_end = entry->iova + entry->addr_mask; > > > > /* > > * Skip the notification if the notification does not overlap > > * with registered range. > > */ > > - if (notifier->start > entry->iova + entry->addr_mask || > > - notifier->end < entry->iova) { > > + if (notifier->start > entry_end || notifier->end < entry->iova) { > > return; > > } > > > > @@ -1953,6 +1953,18 @@ void memory_region_notify_one(IOMMUNotifier *notifier, > > request_flags = IOMMU_NOTIFIER_UNMAP; > > } > > > > + if (entry->iova < notifier->start || entry_end > notifier->end) { > > + warn_report("IOMMUTLBEntry 0x%" PRIx64 " - 0x%" PRIx64 > > + " has non inclusive overlap with notifier 0x%" PRIx64 > > + " - 0x%" PRIx64 ". %s is not allowed." > > + " Try to divide it into smaller sections.", > > + entry->iova, entry_end, > > + notifier->start, notifier->end, > > + (request_flags == IOMMU_NOTIFIER_MAP) ? > > + "Mapping" : "Unmapping"); > > + return; > > + } > > + > > if (notifier->notifier_flags & request_flags) { > > notifier->notify(notifier, entry); > > } > >
© 2016 - 2024 Red Hat, Inc.