From nobody Sat Jun 13 20:20:16 2026 Received: from mx0b-00082601.pphosted.com (mx0b-00082601.pphosted.com [67.231.153.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 07EC149251A; Tue, 5 May 2026 17:39:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=67.231.153.30 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778002768; cv=none; b=BfWG+z62B78SLsQtHnIC0FNTWEeSgnmhw1ecukGEt967OsAjgaF0W03RNtcBMt8ZPHCitnPTWAxX53Nv7oMzDHBxCcwwRNQ4T8gvVZtufhFkn8CXNI9utXYs0Hgrm5tFJuGMat7gp+AAmVmlx1c/3tg4JmjfThltouWDx7vOj8Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778002768; c=relaxed/simple; bh=cdIbyasj3bE8oaLmSjNsZSSPQso4bqF1HQNzAL50cF4=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=BikQ3szbJcjO+i/zozVLpflrkQbVpQzBNcPFWEvww63CZ4ar9UXQhxYP6RaYpAOgmFenh0aQkF4azwZjVbYUBt9vPJu9MVmOuN8aX8XOpSI+H+FIhgEKcjVlhS4cUld/LFVrOiJUHjDql9pzgO2PTJdbo9yLTYjEKX604qr8fCw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com; spf=pass smtp.mailfrom=meta.com; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b=JREfTG8q; arc=none smtp.client-ip=67.231.153.30 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=meta.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b="JREfTG8q" Received: from pps.filterd (m0109332.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 645EFpe63475823; Tue, 5 May 2026 10:39:16 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=s2048-2025-q2; bh=eAzBiKS6rhPKrlXRfIUEzHJ+MYgbJC8zmQmMJ/NUXZA=; b=JREfTG8qKzZ9 IeRl0IF2RuUEmVADQFl+zly9/pi/tSuMrHGEkn+0EfQPTKYBv+WQRMg5sadfntBK PjpPDzIPMyHG03tMIRMP1MJCG4Wf/rNAbS+kNSwzMkNTEtBowJNyX3fV9y5xlIer +KHBj8DC7ayzs1KQI1IQLfcfg9UBCx4d4OXLr2lDgoD0bobdhpRXE+BKXCwfSyvR x2cCX+cglYrYLEidGHcFbu8yRQo5YGukm0ZTjVekplLz0IBg5KN4tedNmVV3ngha mSVe+yhNKqBWmcF+UU+zpkOxm+LGf7xxdc1C9lpukY6jWLYFr1+fsWQRBNcyAcY3 LUD73DrJmg== Received: from maileast.thefacebook.com ([163.114.135.16]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4dwf0da7en-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT); Tue, 05 May 2026 10:39:16 -0700 (PDT) Received: from localhost (2620:10d:c0a8:1c::11) by mail.thefacebook.com (2620:10d:c0a9:6f::237c) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.2562.37; Tue, 5 May 2026 17:39:02 +0000 From: Matt Evans To: Alex Williamson , Kevin Tian , Jason Gunthorpe , Ankit Agrawal , Alistair Popple , Leon Romanovsky , Kees Cook , Shameer Kolothum , Yishai Hadas CC: Alexey Kardashevskiy , Eric Auger , Peter Xu , Vivek Kasireddy , Zhi Wang , , , Subject: [PATCH v4 1/3] vfio/pci: Set up BAR resources and maps in vfio_pci_core_enable() Date: Tue, 5 May 2026 10:38:29 -0700 Message-ID: <20260505173835.2324179-2-mattev@meta.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260505173835.2324179-1-mattev@meta.com> References: <20260505173835.2324179-1-mattev@meta.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=Y7LIdBeN c=1 sm=1 tr=0 ts=69fa2b44 cx=c_pps a=MfjaFnPeirRr97d5FC5oHw==:117 a=MfjaFnPeirRr97d5FC5oHw==:17 a=NGcC8JguVDcA:10 a=VkNPw1HP01LnGYTKEx00:22 a=7x6HtfJdh03M6CCDgxCd:22 a=xtH7KyWI9dI7BmFOsl-x:22 a=VabnemYjAAAA:8 a=Lb-xxqHfFU9yCMAFiGgA:9 a=gKebqoRLp9LExxC7YDUY:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTA1MDE3MSBTYWx0ZWRfXx/2HVgpJlSGu p0N/PTee24IBpy36Gxv6qPoRLGVay8WVEy+y7q3a3QezY/T2rjFeNtU4shIERjSsNnJUKsvLNZ/ KOMhnysXS2hU0qxD6J66x2137oUeedZfYq+xFJuJjTuxtV5m4I9g335pElgMTUb3gI9PK3NWbta Voa8OPHnMBCnEaV8SihPDSCgleH/3UbNJJZvK1LvOjko5/8YQh8FitEfPc65cRpgD7AewKcjG4X sZLmzTyoQgdi6SViiFZjdznExir7VeWycM45ttUBJv+L+3BmvFLY1rrWPY5RUhm5TbpISJWOzeL qnL26xcbXBW3LJe6tCuBs91mQysbepC+nE3vMaI1vwH8s5McTr/+V4BiA/7WT79M8B0v2why2t3 0XgKhNa2xz/5uzSEUBrJw3ViOKs9WPS5a20/6xJooH3Ld0/En0EdJCScC9seKLs4D5T3kNyECuq abKfgYk+pfK+rj1G2FQ== X-Proofpoint-ORIG-GUID: 63jDhWEiX67aPNdyIvX9abbKanKiFK8I X-Proofpoint-GUID: 63jDhWEiX67aPNdyIvX9abbKanKiFK8I X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-05_02,2026-04-30_02,2025-10-01_01 Content-Type: text/plain; charset="utf-8" Previously BAR resource requests and the corresponding pci_iomap() were performed on-demand and without synchronisation, which was racy. Rather than add synchronisation, it's simplest to address this by doing both activities from vfio_pci_core_enable(). The resource allocation and/or pci_iomap() can still fail; their status is tracked and existing calls to vfio_pci_core_setup_barmap() will fail in a similar way to before. This keeps the point of failure as observed by userspace the same, i.e. failures to request/map unused BARs are benign. Fixes: 89e1f7d4c66d ("vfio: Add PCI device driver") Signed-off-by: Matt Evans --- drivers/vfio/pci/vfio_pci_core.c | 36 +++++++++++++++++++++++++++++++- drivers/vfio/pci/vfio_pci_rdwr.c | 26 +++++++---------------- 2 files changed, 42 insertions(+), 20 deletions(-) diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_c= ore.c index 3f8d093aacf8..62931dc381d8 100644 --- a/drivers/vfio/pci/vfio_pci_core.c +++ b/drivers/vfio/pci/vfio_pci_core.c @@ -482,6 +482,39 @@ static int vfio_pci_core_runtime_resume(struct device = *dev) } #endif /* CONFIG_PM */ =20 +/* + * Eager-request BAR resources, and iomap them. Soft failures are + * allowed, and consumers must check the barmap before use in order to + * give compatible user-visible behaviour with the previous on-demand + * allocation method. + */ +static void vfio_pci_core_map_bars(struct vfio_pci_core_device *vdev) +{ + struct pci_dev *pdev =3D vdev->pdev; + int i; + + for (i =3D 0; i < PCI_STD_NUM_BARS; i++) { + int bar =3D i + PCI_STD_RESOURCES; + + vdev->barmap[bar] =3D ERR_PTR(-ENODEV); + + if (!pci_resource_len(pdev, i)) + continue; + + if (pci_request_selected_regions(pdev, 1 << bar, "vfio")) { + pci_dbg(vdev->pdev, "Failed to reserve region %d\n", bar); + vdev->barmap[bar] =3D ERR_PTR(-EBUSY); + continue; + } + + vdev->barmap[bar] =3D pci_iomap(pdev, bar, 0); + if (!vdev->barmap[bar]) { + pci_dbg(vdev->pdev, "Failed to iomap region %d\n", bar); + vdev->barmap[bar] =3D ERR_PTR(-ENOMEM); + } + } +} + /* * The pci-driver core runtime PM routines always save the device state * before going into suspended state. If the device is going into low power @@ -568,6 +601,7 @@ int vfio_pci_core_enable(struct vfio_pci_core_device *v= dev) if (!vfio_vga_disabled() && vfio_pci_is_vga(pdev)) vdev->has_vga =3D true; =20 + vfio_pci_core_map_bars(vdev); =20 return 0; =20 @@ -648,7 +682,7 @@ void vfio_pci_core_disable(struct vfio_pci_core_device = *vdev) =20 for (i =3D 0; i < PCI_STD_NUM_BARS; i++) { bar =3D i + PCI_STD_RESOURCES; - if (!vdev->barmap[bar]) + if (IS_ERR_OR_NULL(vdev->barmap[bar])) continue; pci_iounmap(pdev, vdev->barmap[bar]); pci_release_selected_regions(pdev, 1 << bar); diff --git a/drivers/vfio/pci/vfio_pci_rdwr.c b/drivers/vfio/pci/vfio_pci_r= dwr.c index 4251ee03e146..3bfbb879a005 100644 --- a/drivers/vfio/pci/vfio_pci_rdwr.c +++ b/drivers/vfio/pci/vfio_pci_rdwr.c @@ -198,27 +198,15 @@ ssize_t vfio_pci_core_do_io_rw(struct vfio_pci_core_d= evice *vdev, bool test_mem, } EXPORT_SYMBOL_GPL(vfio_pci_core_do_io_rw); =20 +/* + * The barmap is set up in vfio_pci_core_enable(). Callers use this + * function to check that the BAR resources are requested or that the + * pci_iomap() was done. + */ int vfio_pci_core_setup_barmap(struct vfio_pci_core_device *vdev, int bar) { - struct pci_dev *pdev =3D vdev->pdev; - int ret; - void __iomem *io; - - if (vdev->barmap[bar]) - return 0; - - ret =3D pci_request_selected_regions(pdev, 1 << bar, "vfio"); - if (ret) - return ret; - - io =3D pci_iomap(pdev, bar, 0); - if (!io) { - pci_release_selected_regions(pdev, 1 << bar); - return -ENOMEM; - } - - vdev->barmap[bar] =3D io; - + if (IS_ERR(vdev->barmap[bar])) + return PTR_ERR(vdev->barmap[bar]); return 0; } EXPORT_SYMBOL_GPL(vfio_pci_core_setup_barmap); --=20 2.47.3 From nobody Sat Jun 13 20:20:16 2026 Received: from mx0b-00082601.pphosted.com (mx0b-00082601.pphosted.com [67.231.153.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF77949251F; Tue, 5 May 2026 17:39:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=67.231.153.30 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778002768; cv=none; b=WFIO8gHOVJfl9LDucmNJgTQ+MN6uTIusuQ/RaBRbNmEC8/3wHD04GxYYXD8sHodaVAt6unAV3DEv3tpFxLJIQoKKQwgf8zwRSH/m53mJ4Q1ZK5wjEPQ02Na1EA6fy+hE1lUZqSiPrkk5Yn7/lZtBD5vuDUCTqmu8O4LVT32y1R4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778002768; c=relaxed/simple; bh=U9AZqRqsPkBEbLgz08qAx/7KNRXfInRn/Yp7MxLBCbk=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=DeqG38OiP2h9iQqjiK3vbHAHT4gXaIxYA66/Jvd7ZibiKSUf1eXDfwonvL7iEROcIB2JbsL6ODneQyOXiB5bmaJsSjxEdIExV+ER45+v7OfSFn/K2Pl6Q4asoF5s3hbYveVwKEn5Jz3D1LE0aeKcxlggovivh9qTfQdg1kvsADc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com; spf=pass smtp.mailfrom=meta.com; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b=GGr7++A8; arc=none smtp.client-ip=67.231.153.30 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=meta.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b="GGr7++A8" Received: from pps.filterd (m0109332.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 645EFpeA3475823; Tue, 5 May 2026 10:39:17 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=s2048-2025-q2; bh=uh/fqGrNa5e0eFsOnebd5OIY5cvCMtHB5nxwnWVPhv8=; b=GGr7++A8eaag bPEWiB1rUuHM2UXtPUJe8A7RnxJ0xj/zZVZY0HThM/tBQrdTf84i8I0IGdkY8wQb 4vrlLtzKfCHrvFU1iGSHLjyRGnCNqiYrz7jYvWIsymzpgU4Ke9hJqbIBm3fh9+PT 1f/unDIB9ftHcroUImMojhqrfHkag6ZFOwUBMseOcWE4YAf/qIeJujpSJBk1RNlG IK9BrJSewaiJ0S0mZjDzHny+Lhplw+7Ki8+ULVb0J9ObsIXl9Ss8HGyy1ZjxCNAJ Nj/l3Z1AVorMw+9TC4aZAWcwvexrdBO8pjxhUKqDFJvzmrVapRgvOYvnsXTorE/0 sI2G1iFibA== Received: from maileast.thefacebook.com ([163.114.135.16]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4dwf0da7en-5 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT); Tue, 05 May 2026 10:39:17 -0700 (PDT) Received: from localhost (2620:10d:c0a8:1b::2d) by mail.thefacebook.com (2620:10d:c0a9:6f::237c) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.2562.37; Tue, 5 May 2026 17:39:07 +0000 From: Matt Evans To: Alex Williamson , Kevin Tian , Jason Gunthorpe , Ankit Agrawal , Alistair Popple , Leon Romanovsky , Kees Cook , Shameer Kolothum , Yishai Hadas CC: Alexey Kardashevskiy , Eric Auger , Peter Xu , Vivek Kasireddy , Zhi Wang , , , Subject: [PATCH v4 2/3] vfio/pci: Check BAR resources before exporting a DMABUF Date: Tue, 5 May 2026 10:38:30 -0700 Message-ID: <20260505173835.2324179-3-mattev@meta.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260505173835.2324179-1-mattev@meta.com> References: <20260505173835.2324179-1-mattev@meta.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=Y7LIdBeN c=1 sm=1 tr=0 ts=69fa2b45 cx=c_pps a=MfjaFnPeirRr97d5FC5oHw==:117 a=MfjaFnPeirRr97d5FC5oHw==:17 a=NGcC8JguVDcA:10 a=VkNPw1HP01LnGYTKEx00:22 a=7x6HtfJdh03M6CCDgxCd:22 a=xtH7KyWI9dI7BmFOsl-x:22 a=VabnemYjAAAA:8 a=Cv6RvFvLZYHFA_XSKfkA:9 a=gKebqoRLp9LExxC7YDUY:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTA1MDE3MSBTYWx0ZWRfX3fLIfbWENDof m8sQu9kI4FPzR81dqAI671KOuotCmCluSrwAtTOCjxgZsbZaTrrmdW2G3znMQ9ZEdNh7dzv1Swd 31/zsgHNi38VOomhYZnZRzKco2eQeZzfahbu6nVgv8DHJXBtWnhvgMuJ7lkQf5bdmeo5RsmauvE 6EpvchfRzBOXi9G616LHH1N1M3Dif43TIS2unx4k9b3HkBX/GqTFL91PwLUzfe8jdx+gJigcQkr W2txnyT/+LV8OeaG3slLsZbELo1Ek9iLyxf7KCa47R6hXLnNpz5LQz4izSOf3Pa1HIzJL6DlX6O Apb8JGjoPcWtJOF2bT6LmmxDR9y61QasAJkY2pr0rz4MBr8pXdHDGEt2YAg65OdPNPbmhCtqRa7 CYlrzwjqmp3JiBWsS0b14hB6yiMpeWsroJ+v6iANLNagw5tGRocn2h9//i+FYOScW/626Hr5RL8 XSiS1Gu3GdycgV2k12w== X-Proofpoint-ORIG-GUID: K9nT45ckwPQPQtlToE3rEdpGmMpP9lEr X-Proofpoint-GUID: K9nT45ckwPQPQtlToE3rEdpGmMpP9lEr X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-05_02,2026-04-30_02,2025-10-01_01 Content-Type: text/plain; charset="utf-8" A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. Otherwise, it's possible to access unreserved resources through the export. Add a check to the DMABUF-creation path. Fixes: 5d74781ebc86c ("vfio/pci: Add dma-buf export support for MMIO region= s") Signed-off-by: Matt Evans --- drivers/vfio/pci/vfio_pci_dmabuf.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/vfio/pci/vfio_pci_dmabuf.c b/drivers/vfio/pci/vfio_pci= _dmabuf.c index f87fd32e4a01..69a5c2d511e6 100644 --- a/drivers/vfio/pci/vfio_pci_dmabuf.c +++ b/drivers/vfio/pci/vfio_pci_dmabuf.c @@ -244,9 +244,11 @@ int vfio_pci_core_feature_dma_buf(struct vfio_pci_core= _device *vdev, u32 flags, return -EINVAL; =20 /* - * For PCI the region_index is the BAR number like everything else. + * For PCI the region_index is the BAR number like everything + * else. Check that PCI resources have been claimed for it. */ - if (get_dma_buf.region_index >=3D VFIO_PCI_ROM_REGION_INDEX) + if (get_dma_buf.region_index >=3D VFIO_PCI_ROM_REGION_INDEX || + vfio_pci_core_setup_barmap(vdev, get_dma_buf.region_index)) return -ENODEV; =20 dma_ranges =3D memdup_array_user(&arg->dma_ranges, get_dma_buf.nr_ranges, --=20 2.47.3 From nobody Sat Jun 13 20:20:16 2026 Received: from mx0a-00082601.pphosted.com (mx0a-00082601.pphosted.com [67.231.145.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8DF2B4A2E18; Tue, 5 May 2026 17:39:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=67.231.145.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778002770; cv=none; b=sgIDyDjxWOUKqV6qmHwQG803Es5UqjWuwDQgilAQplOcTTcDdf3UupcZBYNOjk2kndHCBp/AYaJjAfR3jyK1tmauTT1y8+vRHh0ZHdIIHcTiizm8Fd4bWFqNpj3Ghl74pFKG7vDWEgL21nMMreoSA6wC+v8HwfBKGr9pj92gNyo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778002770; c=relaxed/simple; bh=cXP0cw/vmuIMezt8OaMspQhvQNflx32gyCTCp9IxP/I=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=UgZtYXUjsK4WnHng4I6w/08sx3wquAmM/3jZOkbeVMRBAq0y45cA7Ekt9FXNpAfleoTsDWAlLMyf0pElCl7sW2tglLgeJF1HfmrF9MpDLhr12m4QqO50WvM4d++Q3PSiksXa0wVNvZtCGV83FpCEzn0WS1oNRfPx9DYUD44W/vE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com; spf=pass smtp.mailfrom=meta.com; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b=u+b7VA0T; arc=none smtp.client-ip=67.231.145.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=meta.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b="u+b7VA0T" Received: from pps.filterd (m0528009.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 645EFdWl3822354; Tue, 5 May 2026 10:39:17 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=s2048-2025-q2; bh=vVj7iQqkLu0ZHUU3VP6G/UKN+KzbLFcMnwbEARkqGyg=; b=u+b7VA0TcHa/ EWiEAlceVAvVuGSJXz35BhMmoyd3yFudutrCdE/7eoSJfuQ2rQqSXbVdEMlu1UMI PRVBu5ftRHT/S47fol74FcOigQDF9nGSRsYMGVouMo5DTDI2gLadmgYenEgjzKez q8S1V2A4GBtJ8UM3hb1dJtClHcE7O7sJUEdT+vcihYt/UnNTWFU6coNtsdR4rJqO rAtItLw+KTXnORkaWyMD4S7vXuH8ulMmbibbZEECj09UuM24HDJsqPRM86YORbd/ i+w2zKPDWmwWxWWUdUY38JMjOuLaTvAw8VIPYUK6bJ3/WoNFvV9EnkGh4LAJAdO1 nCNzCHeNFA== Received: from mail.thefacebook.com ([163.114.134.16]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4dx315emrv-9 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT); Tue, 05 May 2026 10:39:16 -0700 (PDT) Received: from localhost (2620:10d:c085:208::f) by mail.thefacebook.com (2620:10d:c08b:78::2ac9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.2562.37; Tue, 5 May 2026 17:39:10 +0000 From: Matt Evans To: Alex Williamson , Kevin Tian , Jason Gunthorpe , Ankit Agrawal , Alistair Popple , Leon Romanovsky , Kees Cook , Shameer Kolothum , Yishai Hadas CC: Alexey Kardashevskiy , Eric Auger , Peter Xu , Vivek Kasireddy , Zhi Wang , , , Subject: [PATCH v4 3/3] vfio/pci: Replace vfio_pci_core_setup_barmap() with vfio_pci_core_get_iomap() Date: Tue, 5 May 2026 10:38:31 -0700 Message-ID: <20260505173835.2324179-4-mattev@meta.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260505173835.2324179-1-mattev@meta.com> References: <20260505173835.2324179-1-mattev@meta.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-GUID: ML9YU2Aop1nPcm5xoJ2AUZ9vPWs0J4Da X-Proofpoint-ORIG-GUID: ML9YU2Aop1nPcm5xoJ2AUZ9vPWs0J4Da X-Authority-Analysis: v=2.4 cv=K4AS2SWI c=1 sm=1 tr=0 ts=69fa2b44 cx=c_pps a=CB4LiSf2rd0gKozIdrpkBw==:117 a=CB4LiSf2rd0gKozIdrpkBw==:17 a=NGcC8JguVDcA:10 a=VkNPw1HP01LnGYTKEx00:22 a=7x6HtfJdh03M6CCDgxCd:22 a=U_y8lYiYyhHBU5rMqhb2:22 a=VabnemYjAAAA:8 a=srd7E2Gw4o7griR4iQgA:9 a=gKebqoRLp9LExxC7YDUY:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTA1MDE3MSBTYWx0ZWRfXxgI3IWl/HNCJ SE2+2HTq4XsO6vr5MYejJ3IyXAokK/hSkDc39rH+wGbme3IjZIv5gWpU5iMUChr76BBUC/KG0aN K0DppaqZd131Zg8bDh4r9ewsyidVFVM+oHFmaO7Brbb9rxeVBKS0lW6SHuat+HIMoecG1ICgeZF ZPXcV8rnxszpQKZAOWAzdgCras9CV2cy8gL7FlkWhZOY6pAygM9BRNrZe686tjXipbJW8NnTug0 ZbgisY/gxC9pBfZdmLDkpXUKxfRMnG+BehX+GD9O2i6y+BLtNnzZj7WWSp2Bt/OVrwQSz2HCgPh bEH0YUAx6NlE+0oFfgXbakIfWC0l8mNPxO/4vMI2vfncq0onJwSiSR4aMZ6Y5H8rZ/c5SqrQwa3 mtGPLoQvM6mH91VAYc1KGu0eaAUF6ZCM4UtrseyYeSgnYcfQU2uaEUrNbCh5LrKOUe00OurS47J spmbFySOeanIm2lLxmA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-05_02,2026-04-30_02,2025-10-01_01 Content-Type: text/plain; charset="utf-8" Since "vfio/pci: Set up barmap in vfio_pci_core_enable()", the resource request and iomap for the BARs was performed early, and vfio_pci_core_setup_barmap() just checks those actions succeeded. Move this logic to a new helper that checks success and returns the iomap address, replacing the various bare vdev->barmap[] lookups. This maintains the error behaviour of the previous on-demand vfio_pci_core_setup_barmap() scheme. Signed-off-by: Matt Evans --- drivers/vfio/pci/nvgrace-gpu/main.c | 11 ++++------- drivers/vfio/pci/vfio_pci_core.c | 11 +++++------ drivers/vfio/pci/vfio_pci_dmabuf.c | 2 +- drivers/vfio/pci/vfio_pci_rdwr.c | 30 ++++++++--------------------- drivers/vfio/pci/virtio/legacy_io.c | 13 ++++++------- include/linux/vfio_pci_core.h | 20 ++++++++++++++++++- 6 files changed, 43 insertions(+), 44 deletions(-) diff --git a/drivers/vfio/pci/nvgrace-gpu/main.c b/drivers/vfio/pci/nvgrace= -gpu/main.c index fa056b69f899..e153002258ce 100644 --- a/drivers/vfio/pci/nvgrace-gpu/main.c +++ b/drivers/vfio/pci/nvgrace-gpu/main.c @@ -184,13 +184,10 @@ static int nvgrace_gpu_open_device(struct vfio_device= *core_vdev) =20 /* * GPU readiness is checked by reading the BAR0 registers. - * - * ioremap BAR0 to ensure that the BAR0 mapping is present before - * register reads on first fault before establishing any GPU - * memory mapping. + * The BAR map was just set up by vfio_pci_core_enable(), so + * check that was successful and bail early if not: */ - ret =3D vfio_pci_core_setup_barmap(vdev, 0); - if (ret) + if (IS_ERR(vfio_pci_core_get_iomap(vdev, 0))) goto error_exit; =20 if (nvdev->resmem.memlength) { @@ -275,7 +272,7 @@ nvgrace_gpu_check_device_ready(struct nvgrace_gpu_pci_c= ore_device *nvdev) if (!__vfio_pci_memory_enabled(vdev)) return -EIO; =20 - ret =3D nvgrace_gpu_wait_device_ready(vdev->barmap[0]); + ret =3D nvgrace_gpu_wait_device_ready(vfio_pci_core_get_iomap(vdev, 0)); if (ret) return ret; =20 diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_c= ore.c index 62931dc381d8..5c8bd13f10d0 100644 --- a/drivers/vfio/pci/vfio_pci_core.c +++ b/drivers/vfio/pci/vfio_pci_core.c @@ -1761,7 +1761,7 @@ int vfio_pci_core_mmap(struct vfio_device *core_vdev,= struct vm_area_struct *vma struct pci_dev *pdev =3D vdev->pdev; unsigned int index; u64 phys_len, req_len, pgoff, req_start; - int ret; + void __iomem *bar_io; =20 index =3D vma->vm_pgoff >> (VFIO_PCI_OFFSET_SHIFT - PAGE_SHIFT); =20 @@ -1795,12 +1795,11 @@ int vfio_pci_core_mmap(struct vfio_device *core_vde= v, struct vm_area_struct *vma return -EINVAL; =20 /* - * Even though we don't make use of the barmap for the mmap, - * we need to request the region and the barmap tracks that. + * Ensure the BAR resource region is reserved for use. */ - ret =3D vfio_pci_core_setup_barmap(vdev, index); - if (ret) - return ret; + bar_io =3D vfio_pci_core_get_iomap(vdev, index); + if (IS_ERR(bar_io)) + return PTR_ERR(bar_io); =20 vma->vm_private_data =3D vdev; vma->vm_page_prot =3D pgprot_noncached(vma->vm_page_prot); diff --git a/drivers/vfio/pci/vfio_pci_dmabuf.c b/drivers/vfio/pci/vfio_pci= _dmabuf.c index 69a5c2d511e6..46cd44b22c9c 100644 --- a/drivers/vfio/pci/vfio_pci_dmabuf.c +++ b/drivers/vfio/pci/vfio_pci_dmabuf.c @@ -248,7 +248,7 @@ int vfio_pci_core_feature_dma_buf(struct vfio_pci_core_= device *vdev, u32 flags, * else. Check that PCI resources have been claimed for it. */ if (get_dma_buf.region_index >=3D VFIO_PCI_ROM_REGION_INDEX || - vfio_pci_core_setup_barmap(vdev, get_dma_buf.region_index)) + IS_ERR(vfio_pci_core_get_iomap(vdev, get_dma_buf.region_index))) return -ENODEV; =20 dma_ranges =3D memdup_array_user(&arg->dma_ranges, get_dma_buf.nr_ranges, diff --git a/drivers/vfio/pci/vfio_pci_rdwr.c b/drivers/vfio/pci/vfio_pci_r= dwr.c index 3bfbb879a005..7f14dd46de17 100644 --- a/drivers/vfio/pci/vfio_pci_rdwr.c +++ b/drivers/vfio/pci/vfio_pci_rdwr.c @@ -198,19 +198,6 @@ ssize_t vfio_pci_core_do_io_rw(struct vfio_pci_core_de= vice *vdev, bool test_mem, } EXPORT_SYMBOL_GPL(vfio_pci_core_do_io_rw); =20 -/* - * The barmap is set up in vfio_pci_core_enable(). Callers use this - * function to check that the BAR resources are requested or that the - * pci_iomap() was done. - */ -int vfio_pci_core_setup_barmap(struct vfio_pci_core_device *vdev, int bar) -{ - if (IS_ERR(vdev->barmap[bar])) - return PTR_ERR(vdev->barmap[bar]); - return 0; -} -EXPORT_SYMBOL_GPL(vfio_pci_core_setup_barmap); - ssize_t vfio_pci_bar_rw(struct vfio_pci_core_device *vdev, char __user *bu= f, size_t count, loff_t *ppos, bool iswrite) { @@ -262,13 +249,11 @@ ssize_t vfio_pci_bar_rw(struct vfio_pci_core_device *= vdev, char __user *buf, */ max_width =3D VFIO_PCI_IO_WIDTH_4; } else { - int ret =3D vfio_pci_core_setup_barmap(vdev, bar); - if (ret) { - done =3D ret; + io =3D vfio_pci_core_get_iomap(vdev, bar); + if (IS_ERR(io)) { + done =3D PTR_ERR(io); goto out; } - - io =3D vdev->barmap[bar]; } =20 if (bar =3D=3D vdev->msix_bar) { @@ -423,6 +408,7 @@ int vfio_pci_ioeventfd(struct vfio_pci_core_device *vde= v, loff_t offset, loff_t pos =3D offset & VFIO_PCI_OFFSET_MASK; int ret, bar =3D VFIO_PCI_OFFSET_TO_INDEX(offset); struct vfio_pci_ioeventfd *ioeventfd; + void __iomem *io; =20 /* Only support ioeventfds into BARs */ if (bar > VFIO_PCI_BAR5_REGION_INDEX) @@ -440,9 +426,9 @@ int vfio_pci_ioeventfd(struct vfio_pci_core_device *vde= v, loff_t offset, if (count =3D=3D 8) return -EINVAL; =20 - ret =3D vfio_pci_core_setup_barmap(vdev, bar); - if (ret) - return ret; + io =3D vfio_pci_core_get_iomap(vdev, bar); + if (IS_ERR(io)) + return PTR_ERR(io); =20 mutex_lock(&vdev->ioeventfds_lock); =20 @@ -479,7 +465,7 @@ int vfio_pci_ioeventfd(struct vfio_pci_core_device *vde= v, loff_t offset, } =20 ioeventfd->vdev =3D vdev; - ioeventfd->addr =3D vdev->barmap[bar] + pos; + ioeventfd->addr =3D io + pos; ioeventfd->data =3D data; ioeventfd->pos =3D pos; ioeventfd->bar =3D bar; diff --git a/drivers/vfio/pci/virtio/legacy_io.c b/drivers/vfio/pci/virtio/= legacy_io.c index 1ed349a55629..c868b2177310 100644 --- a/drivers/vfio/pci/virtio/legacy_io.c +++ b/drivers/vfio/pci/virtio/legacy_io.c @@ -299,19 +299,18 @@ int virtiovf_pci_ioctl_get_region_info(struct vfio_de= vice *core_vdev, static int virtiovf_set_notify_addr(struct virtiovf_pci_core_device *virtv= dev) { struct vfio_pci_core_device *core_device =3D &virtvdev->core_device; - int ret; + void __iomem *io; =20 /* * Setup the BAR where the 'notify' exists to be used by vfio as well * This will let us mmap it only once and use it when needed. */ - ret =3D vfio_pci_core_setup_barmap(core_device, - virtvdev->notify_bar); - if (ret) - return ret; + io =3D vfio_pci_core_get_iomap(core_device, + virtvdev->notify_bar); + if (IS_ERR(io)) + return PTR_ERR(io); =20 - virtvdev->notify_addr =3D core_device->barmap[virtvdev->notify_bar] + - virtvdev->notify_offset; + virtvdev->notify_addr =3D io + virtvdev->notify_offset; return 0; } =20 diff --git a/include/linux/vfio_pci_core.h b/include/linux/vfio_pci_core.h index 2ebba746c18f..ffd67e25bf3f 100644 --- a/include/linux/vfio_pci_core.h +++ b/include/linux/vfio_pci_core.h @@ -188,7 +188,6 @@ int vfio_pci_core_match_token_uuid(struct vfio_device *= core_vdev, int vfio_pci_core_enable(struct vfio_pci_core_device *vdev); void vfio_pci_core_disable(struct vfio_pci_core_device *vdev); void vfio_pci_core_finish_enable(struct vfio_pci_core_device *vdev); -int vfio_pci_core_setup_barmap(struct vfio_pci_core_device *vdev, int bar); pci_ers_result_t vfio_pci_core_aer_err_detected(struct pci_dev *pdev, pci_channel_state_t state); ssize_t vfio_pci_core_do_io_rw(struct vfio_pci_core_device *vdev, bool tes= t_mem, @@ -234,6 +233,25 @@ static inline bool is_aligned_for_order(struct vm_area= _struct *vma, !IS_ALIGNED(pfn, 1 << order))); } =20 +/* + * Returns a BAR's iomap base or an ERR_PTR() if, for example, the + * BAR isn't valid, its resource wasn't acquired, or its iomap + * failed. This shall only be used after vfio_pci_core_enable() + * has set up the BAR maps and before vfio_pci_core_disable() + * tears them down. + */ +static inline void __iomem __must_check * +vfio_pci_core_get_iomap(struct vfio_pci_core_device *vdev, int bar) +{ + if (WARN_ON_ONCE(bar < 0 || bar >=3D PCI_STD_NUM_BARS)) + return ERR_PTR(-EINVAL); + + if (WARN_ON_ONCE(!vdev->barmap[bar])) + return ERR_PTR(-ENODEV); + + return vdev->barmap[bar]; +} + int vfio_pci_dma_buf_iommufd_map(struct dma_buf_attachment *attachment, struct phys_vec *phys); =20 --=20 2.47.3