From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EFBF12D8796 for ; Fri, 28 Aug 2026 12:54:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921659; cv=none; b=hvKRDBPfD8gOIPcIpddNf3NvNhlyEIBodlpDpJYc6r3+otWg3D0BILhoS2ZG9e5vzapMN/cOpoeV8DiDxifvAwZPvOtzT55OnYSeXJxcousN2uWCt+iealETqeXWs70d432NSpLvmdgt/e8Hpuw9LwhvVp4D+utAAf/wtbsf/Bg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921659; c=relaxed/simple; bh=upXdKvag3PQjFo+u20Yny7ckLbyRjOxAi0c3fKM7W+0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=HyQFgVAIMQrQBh5J8EfWt+eIGr5wzgFJwbloG8tI2+/Ctmt8JzI0aldpBfvhBUuqfX8793zt1WcWRy9k0OyjqpDHpqRrEupoTOETWjWDezTnZj7FXWK8reBotUbbShB9P+Ltqi3xb4aDRpHfz2K8cvLAzUxyyN/iBIF4qMi2ZXo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=X/gZX8Ag; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="X/gZX8Ag" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-499a7993a9bso8290405e9.1 for ; Fri, 28 Aug 2026 05:54:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921656; x=1788526456; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TIbaVf3ZrMQ638kyQmo2xKF0JXdpiB0/s407XZc/gcU=; b=X/gZX8AgbW93lkHaHVcDwj2PGU4Qkfek7QcVUaR/i7HjV4AULTG54/BKK3gmJetOZk 8Oq/1hxVwizgg3vvq0g3wBUN8rGrg+o5Gehdyo6sB/IJdQBJ6e/AqiXseTbFsnOnZNRq n+CINrCwhiEw/XGYSMJsqDu5E4mjzK4iWr3/ljhZsddMr4Noz9YdCeatAB/0NP5Jnon+ BbODFwBAo9v6jBflH+k/tyr/+jtIn9K1tx3R89+YyR/ddzC6RNv04fuLtIT56bEDfNUy AobAjMLnpvp9G1XL44SjHJ8ZCyes0fMBG7lVAB1kcMght9yHlhIi7JFBLqemutGvFuR+ Oq9Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921656; x=1788526456; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TIbaVf3ZrMQ638kyQmo2xKF0JXdpiB0/s407XZc/gcU=; b=RsLPiTufZKBSlpvxxZAKfdfivo1ohpaWzHXhj6gd9xFMEhYJvLGY+GJiRDb7Xr/36m paixl/xZfrwuIg3M96AiV+U9qrKMzFZovDdWuZ3AhugaqcxTio0lDwkTn7ReWTsx3pCY NZKgs+512muozj9KXzST3+tvcxy+wKUMuNRsoapKSy28jUW0t64Rd4ZLIftC1/kAUwNI M//yNXDUybRP+YbUltcVizHjkzVkj+K/O6jPC0BgnwWiWLQfEv5OE8V405yff+Ar60nD jIBGeGU5NXg74RQFi23gDQuy35C98rhA8U/GE1YjEEy5AVPo0mJL0Oc9n8tvBClLQWSq f4Ww== X-Gm-Message-State: AFuF++mlVwTreYaAJCEKLpjr5cVqcYHs2wjOdyqjjghHxzfOOmyyGRCQ BQ9Yj1WuyOVsEkdCCo1Cdm4mz++yK/tTjG+OeE2jr8xIoiul6Z66j/jHLmJFtbAk8TiwlddJuy8 D1gpHL1pb8lxsJ8OhGzyd/63jgZmjTkli4oeABGCj1zvKBWlVAljymajlOt12gvbhtjhLb5kdGB kHokzBoBE+Gbc+GGbt5qQ2BwmMHTKpWHR0QML0l1Bkfyx7L2v8Q5s5PnI= X-Received: from wmof19.prod.google.com ([2002:a05:600c:44d3:b0:493:beda:c864]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:4453:b0:499:8777:ccba with SMTP id 5b1f17b1804b1-49b91c486abmr88157945e9.12.1787921655833; Fri, 28 Aug 2026 05:54:15 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:36 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-2-smostafa@google.com> Subject: [PATCH 1/7] iommu/arm-smmu-v3: Ensure L2 tables are visible before L1 ptrs From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Commit 6fabce53f6b9 ("iommu/arm-smmu-v3: Add a missing dma_wmb() for hitles= s STE update") adds a dma_wmb() to arm_smmu_write_entry() to make sure stream tables and context descriptors are observed first. However, STE L1 table descriptors are configured directly via WRITE_ONCE(), where before that they were zeroed with memset() inside dma_direct_alloc() then written to abort in via memset() also in arm_smmu_init_initial_stes() without a barrier in both cases which means that the SMMUv3 can observe the allocated table before the written descriptors causing it to fetch random data. Similarly in arm_smmu_write_cd_l1_desc() where the L1 CD is written after dma_alloc_coherent() with no barriers. Add dma_wmb() in both cases. Fixes: 48ec83bcbcf5 ("iommu/arm-smmu: Add initial driver support for ARM SM= MUv3 devices") Reported-by: Sashiko <> Signed-off-by: Mostafa Saleh Reviewed-by: Jason Gunthorpe Reviewed-by: Nicolin Chen --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/ar= m/arm-smmu-v3/arm-smmu-v3.c index 5732f3ba0122..494bbfd2869f 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c @@ -1515,6 +1515,9 @@ static void arm_smmu_write_cd_l1_desc(struct arm_smmu= _cdtab_l1 *dst, { u64 val =3D (l2ptr_dma & CTXDESC_L1_DESC_L2PTR_MASK) | CTXDESC_L1_DESC_V; =20 + /* Ensure the zero-cleared L2 table is fully visible. */ + dma_wmb(); + /* The HW has 64 bit atomicity with stores to the L2 CD table */ WRITE_ONCE(dst->l2ptr, cpu_to_le64(val)); } @@ -1804,6 +1807,9 @@ static void arm_smmu_write_strtab_l1_desc(struct arm_= smmu_strtab_l1 *dst, val |=3D FIELD_PREP(STRTAB_L1_DESC_SPAN, STRTAB_SPLIT + 1); val |=3D l2ptr_dma & STRTAB_L1_DESC_L2PTR_MASK; =20 + /* Ensure the new L2 table is fully visible. */ + dma_wmb(); + /* The HW has 64 bit atomicity with stores to the L2 STE table */ WRITE_ONCE(dst->l2ptr, cpu_to_le64(val)); } --=20 2.55.0.897.gb25b4bd76c-goog From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 37247410D3D for ; Fri, 28 Aug 2026 12:54:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921660; cv=none; b=UBtRDj72cCP2n2PNYj+cBvZfbTQNmwqPOWJApD1I52aiH7cdH2fs3iiko4p+k6tTOmYfaxc/tN8nUvjr5JqX45jcFehlJUZF8V5w0NW47qkHK2TKYnWm43KlUEm2ashQIabPDWh6s38E/yXQA/fOnLwt3FUu43BokWSkSb6JN7g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921660; c=relaxed/simple; bh=5aBJVTFNtKdzt7V9kiKFCTKnRo+Q44vjxsSxWUMylcM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=quhFxMaNB2TiMFM1IVHzu19Yoh05jBRE9DCp3N5psvXiVB6qmrOIShfZhWbp5eQv0pQeQt6KD9KlJBTaijvejT4qOKTPXj5gndW/sDeZcmVunjxHOuM/woTT/8uh+DgwFQnUmDiWCgSN5/k+XhcZzxJDemwx2O0p5UfwaADKDkk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=smr909eK; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="smr909eK" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-49545071724so6921825e9.0 for ; Fri, 28 Aug 2026 05:54:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921657; x=1788526457; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=EtQo4uL9ciRrWrgSm+7tcMPkQTLbUYsP8Kt9QCNYgXs=; b=smr909eKsz2PUfHEuJZZSpXxJxCHuoYWy4BaDC0kTDwp3Y1v2+hFl6DsUZ5bB1IrV8 aLMX35xciBQ345436sTbtub03Wnz1CN7W5O4JzGcYLn+TpPdDfBSXUNYr6t1HOjG+c8p 7xocVqmQLCa4lF5/EmHrsvexPVXAV+m6uNq9P9vC7NVlKtsBWP8+CYs3h3h40cLvpQ0R CJPJQkXZ+tcnOQCU9/qEQBKOxWUVZYgQDzXGqzVknztTlMzluMNYSFUrEdQPg2i2nHEu h10SsAjqoQ23RD0HPMPaGRNC8VHULQR9dVgEwcYox7rFQvwJ3qSBGeGMwP0MQSuDOwMF 9zEQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921657; x=1788526457; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EtQo4uL9ciRrWrgSm+7tcMPkQTLbUYsP8Kt9QCNYgXs=; b=m75XI/s9QHQjVJ3VdG0uBsdexpSZ5mreqHEChlkyPunuTlQHqDD7af6uYomU/mbvoU DGYs4rbUBc4dCzqfabDH8BMzWkM9m/y/qC3G8u21cMiWBrORql/TySb7e/7P27t76zHi qW+sHQmXf6hE/zhuZ6JaMU838YIX5Vkaw4MBVTIrx10g6pvK90sinjdcNU5cwEbNJdRb Cq+f0g7BrKC7AH9oTzLrk/r/bS9Zb2dFsZF0xLShEvEes1PUN8jwOl4nvEhxc7Bb9HIo JKUjbbqGRvEYwVYIWHroBOIUSpHBJlJNwEVb8aZbeJsbtr4bLuKtYnhU5/OuAE74iaDd Y8WA== X-Gm-Message-State: AFuF++naokbnQ97avuFIxE2nqcgfTVONYXWR3330YGqO+s6w45/Rqk8C wxsnxfa/MDzpdezBj93Gx3lor38u2+hNjLY7C3BrD+kuYa3RSwK8aNjqLGvriFRy7BRoDiXcAKI 6qnCbnbYi9grNcStOepZgQs+XunPgZWSfJYogWfou58sdx8m2PgoK3WfgrsAfyzTH/Xs5AjV+6x 94oVn7AMRiLHMNEH2iXOLvfO0z57784rvlldkeEvcdjXJYuIywJxVNsio= X-Received: from wmbgx10.prod.google.com ([2002:a05:600c:858a:b0:49a:d4b6:42fc]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:c0cf:b0:499:726b:7375 with SMTP id 5b1f17b1804b1-49b91c51e62mr90214355e9.14.1787921657014; Fri, 28 Aug 2026 05:54:17 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:37 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-3-smostafa@google.com> Subject: [PATCH 2/7] iommu/arm-smmu-v3: Prevent rbtree corruption from duplicate streams From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In handling PCI devices with duplicate IDs, arm_smmu_insert_master() will continue the loop skipping the duplicate sids insertion in the rbtree. However, in the error path of arm_smmu_insert_master() and in arm_smmu_remove_master(), the code loops over all fwspec->num_ids and calls rb_erase() unconditionally. For the duplicate streams, the node is zero allocated including the parent pointer "__rb_parent_color". That means rb_erase() will think that this node is root and it will corrupt the tree which includes other masters not being removed. Fix this by initializing those nodes with RB_CLEAR_NODE() and check if they are empty before erasing. Fixes: cdf315f907d4 ("iommu/arm-smmu-v3: Maintain a SID->device structure") Reported-by: Sashiko <> Signed-off-by: Mostafa Saleh Reviewed-by: Jason Gunthorpe --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/ar= m/arm-smmu-v3/arm-smmu-v3.c index 494bbfd2869f..36e3778c971e 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c @@ -4147,8 +4147,10 @@ static int arm_smmu_insert_master(struct arm_smmu_de= vice *smmu, ->master; =20 /* Bridged PCI devices may end up with duplicated IDs */ - if (existing_master =3D=3D master) + if (existing_master =3D=3D master) { + RB_CLEAR_NODE(&new_stream->node); continue; + } =20 dev_warn(master->dev, "Aliasing StreamID 0x%x (from %s) unsupported, expect DMA to be broke= n\n", @@ -4159,8 +4161,10 @@ static int arm_smmu_insert_master(struct arm_smmu_de= vice *smmu, } =20 if (ret) { - for (i--; i >=3D 0; i--) - rb_erase(&master->streams[i].node, &smmu->streams); + for (i--; i >=3D 0; i--) { + if (!RB_EMPTY_NODE(&master->streams[i].node)) + rb_erase(&master->streams[i].node, &smmu->streams); + } kfree(master->streams); kfree(master->build_invs); } @@ -4179,8 +4183,10 @@ static void arm_smmu_remove_master(struct arm_smmu_m= aster *master) return; =20 mutex_lock(&smmu->streams_mutex); - for (i =3D 0; i < fwspec->num_ids; i++) - rb_erase(&master->streams[i].node, &smmu->streams); + for (i =3D 0; i < fwspec->num_ids; i++) { + if (!RB_EMPTY_NODE(&master->streams[i].node)) + rb_erase(&master->streams[i].node, &smmu->streams); + } mutex_unlock(&smmu->streams_mutex); =20 kfree(master->streams); --=20 2.55.0.897.gb25b4bd76c-goog From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E4D1F4519A6 for ; Fri, 28 Aug 2026 12:54:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921663; cv=none; b=fG2UuaErw6iIPFeiIHHqN5cq3RqPKJCSq8EPqjHt9eZMm9j7mytxs0Xx+bkaRKoSu7qKeb2PZJ1B5TwKuLDZfpHtzGFCuxthfnW9TrKV2cSDhjCTTsrbLZipf3VhImH1rkxWvBar5GoPse8YqHMIFbAEE1/Llmb/kix701wzLEE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921663; c=relaxed/simple; bh=oK0J178nG2/SnhSd8NbdANj5bxRiyctq80z3lFJEcFk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=MZEj5nQKfVMtifI4l/+S7k+da5q0efkVIlo2sT/e5IDqKaACsIU3dmU5QegCkqtY3trPES7A7VuHWx+RzkUtuv/Ql0A5u2/vpNdrZjHLiOAhSZCiv4ehUDoF2pEPIRccyd8vFayc4TOYMcvJOmzxR7XH36DH3pRdlnQ8ZlrN5rc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=mXKOf0od; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="mXKOf0od" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-495474a5fbcso7800045e9.1 for ; Fri, 28 Aug 2026 05:54:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921660; x=1788526460; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=RAMHtBFkdmGbuLyv/P0Pos4ZoeExbNjIBs0ygiScewk=; b=mXKOf0odwCt39nUsMqBgUiVCuCf5MSa6up04tS/3X14hAs7PU1GQ+0C4PUPtqlQKcZ XJvs+CcAsyRZxHH119nXPiKweJEiiwre6bG3nBJIaeq/LhWe/7fq1kBMNVKW9L8HhTWL 4vddLS+JWGWbn+pPw7YqfbxFM8C029l8kfwNJTlztnAGiYfjOKA5VYyiSUtVdc9ahvgR I0fStlWb5k9ih1dRnJG2o+Yoj+aQakUlmLQnOs7lwqPuGTISIdxfHxgZqKOSHzp7+Vrw qDg9lTOLbI3OVXwmIK56uDFWJlzr6urrlGDiA3cik8/aiDRo+smCeBuqBIVHjdVMKljy Va6A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921660; x=1788526460; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=RAMHtBFkdmGbuLyv/P0Pos4ZoeExbNjIBs0ygiScewk=; b=EKWZT7ZJ5SWjQEYihjAP9iTmKl+syHRfsL7iMJdsq3xZ4BDtXzqJKCoAqOk2A5iBz6 Ij8vkWOkyF3ScHP5KjHO4hbUkZM8eyVHdJ4n4LW+kyb6wBErTepaOepIhy2cTEG+2cbI BuooqNGxv6iM9jnWzh/sdd0E4qYxDsWbU8zRjPiMpu/MDSOjS0h/U/EBJlzCyjVFmqst x9dRrFzrm/mmPyo+MIDPdkN3SpOea15Cg5F2sLEifOt1R5MYdQgGfaIy4b9y0mhZ3aFe uP8ADoYK/udSQTILOeWv62xyH122XJT6+uDkAagZNaGzDP75c3erZvgtMzJR14x4gjt2 e4nQ== X-Gm-Message-State: AFuF++kbzGLz/JeKadIVUcyx5qzwGBYpnmc19aX2FHPaN6KWokUQOwua FCotYXuph8wolqcZ309McwwUlXfijqaPwcMt+Oro1v/WsZ2yphSwt9m7Rkqy61+vtQOHj18JOtw UZo2JOn0f1vGyk+jVa2znZF6pcLPMO9P4RkcwqmOSxZh50hQTV408V7we2fqHjv9AhW8zDfp9bX VGM2J93lkY9igTngkOQF/dpolXle9IHrn5qELdH1D2E3E34pFm4QC0mD8= X-Received: from wmbe18.prod.google.com ([2002:a05:600c:5912:b0:495:5edc:795b]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:8b6b:b0:49b:c8e:8e6 with SMTP id 5b1f17b1804b1-49b91bd99b7mr113262645e9.0.1787921659759; Fri, 28 Aug 2026 05:54:19 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:38 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-4-smostafa@google.com> Subject: [PATCH 3/7] iommu/arm-smmu-v3-iommufd: Fix error path in arm_vsmmu_cache_invalidate() From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" arm_vsmmu_cache_invalidate() issues commands in batch size. However, if arm_vsmmu_convert_user_cmd() fails, it will return to the user that it processed "cur - cmds" which may be part of a batch not issued yet. Fix this by calculating the returned entry_num solely based on the "last" that tracks the last batch that was successfully issued. Also, fix the number of commands for early failing condition. Fixes: d68beb276ba2 ("iommu/arm-smmu-v3: Support IOMMU_HWPT_INVALIDATE usin= g a VIOMMU object") Reported-by: Sashiko <> Signed-off-by: Mostafa Saleh --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c b/drivers/= iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c index 25982bdbcbd9..91776c555f0e 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c @@ -379,10 +379,13 @@ int arm_vsmmu_cache_invalidate(struct iommufd_viommu = *viommu, int ret; =20 cmds =3D kzalloc_objs(*cmds, array->entry_num); - if (!cmds) + if (!cmds) { + array->entry_num =3D 0; return -ENOMEM; + } cur =3D cmds; end =3D cmds + array->entry_num; + last =3D cmds; =20 static_assert(sizeof(*cmds) =3D=3D 2 * sizeof(u64)); ret =3D iommu_copy_struct_from_full_user_array( @@ -391,7 +394,6 @@ int arm_vsmmu_cache_invalidate(struct iommufd_viommu *v= iommu, if (ret) goto out; =20 - last =3D cmds; while (cur !=3D end) { ret =3D arm_vsmmu_convert_user_cmd(vsmmu, cur); if (ret) @@ -405,14 +407,12 @@ int arm_vsmmu_cache_invalidate(struct iommufd_viommu = *viommu, /* FIXME always uses the main cmdq rather than trying to group by type */ ret =3D __arm_smmu_cmdq_issue_cmdlist(smmu, &smmu->cmdq, &last->cmd, cur - last, true); - if (ret) { - cur--; + if (ret) goto out; - } last =3D cur; } out: - array->entry_num =3D cur - cmds; + array->entry_num =3D last - cmds; kfree(cmds); return ret; } --=20 2.55.0.897.gb25b4bd76c-goog From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D737B453A22 for ; Fri, 28 Aug 2026 12:54:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921666; cv=none; b=JH6CKhWIwJWsY2ry9CgMo93m3xdWI+DKrzxQQF5+ikJgnI4KKGHXNveLasGRe/yiuon75h9/1XLbiK4QrF8QAeyTCPW5brFBnsU3/ZcUXUk0+e4bqzIfPihrmX24IpEBMvzv6+IVNeR0Bnj0qICH8KtSxOCadUQJncutVxrAvBc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921666; c=relaxed/simple; bh=mQ3kcP+CyWgZPZ1iBtlnF8x6qcpBHJaX3wA7zCjENuI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=djLeSTw3sQ1LfOdHin5/a6JsMpBDlo56H4/feJ5ogQz1C7STE6tRqAuyLC6dyvowdf7qhGdnUJ0gJrjPspjOmnPsU2Orr66XYhnZhsupRSq2xbBdxxpg4/r+Ke5YfI1etd6Q5fChjUS4kf7JVgJIkt1/+moz5HyKGonquNlFkMw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=aeM6ha1i; arc=none smtp.client-ip=209.85.221.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="aeM6ha1i" Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-47f835ac1aeso543773f8f.3 for ; Fri, 28 Aug 2026 05:54:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921663; x=1788526463; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=hfku0lPz7WJB8aIdUHoXK+mnPfY4Qn0hLLaeSPnv6F8=; b=aeM6ha1ieERoKvzzs5OwR2Urym8ymZzDeN+srtTZNn9P/mnLDeDfSPw0ePwkkfzBO9 F91VLN2M44wDw0gu/WOk2sCTWDsgVMAifqHl3rnPRteZSoGWAUarDWUymiOadDEETaBz e/IYRI8xdBLggxC28VNwTDgZNFKG1XYlLKvJHsNv08Q5OXmSn0ZbsZLLI+6VriOoN/6F N3SkRad+e5jAlDF6qF0MSyvqEt75EUiHn5Y5xxrQRlwlWgYzY+eVQm0o4t1qXWzblkRt JEVpRwe/OQ0YWYl8DUzz7+SqYjuDH9OAwXwrQQKkUJDXrbY6Cg82eg0CTVSbX4CMYObb mAxA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921663; x=1788526463; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hfku0lPz7WJB8aIdUHoXK+mnPfY4Qn0hLLaeSPnv6F8=; b=A4p7ADCVDDv3Gr/oDorpPQeB5ymliPsWkRR5L9EsXpLZmcYV0T0kk2TLTby2PRRzUt 2NflrOpKraCO0d0j3GlSSCX8R8DWC0Rxt0dticUYzIcOhbr7NV5xYezt0G86g+8PPar0 oV0p3uBGR1gzfP3OvcXWY0nbz5gsGK5IrULzdTnaTmHdj/fikgHIbcyF+dKCdNStEaYV dlnHb/Cf7k2W82G3AIqPKSOPCVQjyO+TvHyZRNm31STF9gIB1onrJbb2UrLlZ3GD44rg CCz/DIWJSiqA6sv+sUrJP3X+otK3/lrbSsnbcCBp3ESdc2q05aOWRgMxAFgDWVN9l69T xNjA== X-Gm-Message-State: AFuF++nK3cBqQopk6YZd5Lv87rxRJ/yQvdPkU5VtweUweReVSr7Ec5XR wSElJ/5u9kjxQ8zTXAff9DcG8s2LVoruFvH2ccpoCB4DWnGJO2ghx69+WTNj7ZaFEInCsASchHF TJfZt8GHYcE1RNB8wKwXcDM6e9XBda+0hAMgznYWyNaeJNj+6wBT4oEhwKJl+VgXiGl/LHK67le 2Aue61sQELjjoFtZqioznnad/TH35XCW/dqFsxmGWijN61FeOpWdXqRjw= X-Received: from wmqt17.prod.google.com ([2002:a05:600c:1991:b0:49b:8f1d:7d3a]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:4e86:b0:499:db6d:bc97 with SMTP id 5b1f17b1804b1-49b91bd43a7mr86485665e9.0.1787921662708; Fri, 28 Aug 2026 05:54:22 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:39 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-5-smostafa@google.com> Subject: [PATCH 4/7] iommu/arm-smmu-v3-test: Fix arm_smmu_v3_test_debug_print_used_bits() From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" arm_smmu_v3_test_debug_print_used_bits() hardcodes arm_smmu_get_ste_used() instead of using the provided writer->ops->get_used() callback. This caused Context Descriptors to be incorrectly parsed as STEs. Fixes: 56e1a4cc2588 ("iommu/arm-smmu-v3: Add unit tests for arm_smmu_write_= entry") Reported-by: Sashiko <> Signed-off-by: Mostafa Saleh Reviewed-by: Jason Gunthorpe Reviewed-by: Nicolin Chen --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c b/drivers/iom= mu/arm/arm-smmu-v3/arm-smmu-v3-test.c index add671363c82..eae08d4d77ec 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c @@ -125,8 +125,8 @@ arm_smmu_v3_test_debug_print_used_bits(struct arm_smmu_= entry_writer *writer, { __le64 used_bits[NUM_ENTRY_QWORDS] =3D {}; =20 - arm_smmu_get_ste_used(ste, used_bits); - pr_debug("STE used bits: "); + writer->ops->get_used(ste, used_bits); + pr_debug("Entry used bits: "); print_hex_dump_debug(" ", DUMP_PREFIX_NONE, 16, 8, used_bits, sizeof(used_bits), false); } --=20 2.55.0.897.gb25b4bd76c-goog From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B19854503E3 for ; Fri, 28 Aug 2026 12:54:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921675; cv=none; b=dz6agG3C1e+btC8NcWF2lg83bn1fUtReZLGMtflqeaRSag/jNafaSIV/fcgWc3r5Dese8/od4PWjlTZ1e3nnFXdtR1A8wnahCgZn3LlHiMDChlkfWC4CVbXeEU2OBX4hfuu9P9IVvJ/GziYe6/jAn/GE1KjiwMRn98e1g1Gs/rQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921675; c=relaxed/simple; bh=Y19wC9aROH0p2C0YhyoiBj7Iw1xMl80M5dB6Vw2JHjE=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=HBj3wU08XaVsthHRTKQjqRh4j+hWWz6C0wsEwB9BZgyv7GEq7yYMYP0hTrLqa4ATyZWXWGXNXwjYROquvuuHt92mwS5WHFoQT24uN/oOaW9rtasORu2sofpL9tpXHoHUbFEf8JrNjUTg5iCiD2os6fPVSH2Q9o+n0RiRRkMxASU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=KB3FMHrF; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="KB3FMHrF" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-49b0e6638e3so6267325e9.2 for ; Fri, 28 Aug 2026 05:54:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921672; x=1788526472; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Y3t59Cwp3hUZ2CzdmTE2YwsjNcWIkkKVh96IkZiq53c=; b=KB3FMHrFIYjsfaOXN+B/5JVcDtejppnkd8l8yKD67890c2U910C+9/Job2f9E9/uif ks+dOqtK/+MVuDhyYkY/oO4UmClRHERmkqyNkfJufXge64fZBJgSuqsLiwyeB5fpZWzn ppB15FAR2viwr28K56LTkdX2tZWPKCrRyo4kUAZE6f5AshB0Dg+UwI34LBBW7qojD/XD WqPyYvG8dQSt6qA31olUnAo42Cc/C2kWQewiCO2tpsfvm/Kt/y/WLSM8Sxi8KWhvDE9K u60DkZpRl+FDhs6eTMmh1+R8YWe3nTKglOSV8KHpuij2HUj+X2uHo2xXPCf5+yCXEEkD QWJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921672; x=1788526472; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Y3t59Cwp3hUZ2CzdmTE2YwsjNcWIkkKVh96IkZiq53c=; b=SOn9EjY3qaVSpwFI9QJJ6VqR5RGbsEz75nPgWW9zSd3BEknsqHo7I+12jM3g2wf4Js V71Kx7mFf/rrMV9MIly1Dpx8R0j2cbclpW6FQKOMdhggySTe5r3l33Ud2oF+yP8VMxgb Ob9w/p/28OlCWcm13u76N5qN7BuEtKY12/ubpvNrAgOLl3L6Dh97uBK0gdHiJXqP0o7v 9C5kQB90z2kBhdu0jn1FBUbUzEv2szSzytACfN9dAiZhZrRKqDAR/R3m4Fg7n+94hV+w CBf68dCvUdSoWgf1JSvitRIyjUUJp6DCS4mVLqwG4EeGBh86sY5rQd5OX6oPvqUVb+9R 5eMA== X-Gm-Message-State: AFuF++mOVnl2SW969VtouHsAx63geZUJ9IxWOp5t6QQeiz6s5QFpmGhv qm0943f2AkoMuEXLFjinYzmOgofOZV+VCGVpkF38CmLhx33upACNMtJ6ObWWHgEqw63YDRSfOug ROxBwL0R6gc/H7q+O9zsNRvGcL9u3H3DDcooTtpOMsK3D+Mo9HV1L3fNsA7Jc/kFw5YAD8/yeOc Iejv1RBtqQ/S3gg6YqS6ouGW6AE05P7zVO3vzu8L+HqJC3r6ZVTFNHBPs= X-Received: from wmsm23.prod.google.com ([2002:a05:600c:3b17:b0:495:6261:8954]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:1c02:b0:499:8ff5:8ec4 with SMTP id 5b1f17b1804b1-49b91c2e11dmr109166555e9.3.1787921671689; Fri, 28 Aug 2026 05:54:31 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:40 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-6-smostafa@google.com> Subject: [PATCH 5/7] iommu/arm-smmu-v3-test: Add missing error checks for inv array From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" arm_smmu_invs_merge() and arm_smmu_invs_alloc() can return NULL or errors which are checked by the driver but not the test. Add KUNIT_ASSERT_NOT_ERR_OR_NULL() after calling them to fail the test instead of accessing NULL or ERR pointers. Fixes: 15a2a5645ad7 ("iommu/arm-smmu-v3: Introduce a per-domain arm_smmu_in= vs array") Reported-by: Sashiko <> Signed-off-by: Mostafa Saleh --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c b/drivers/iom= mu/arm/arm-smmu-v3/arm-smmu-v3-test.c index eae08d4d77ec..366dcb2b5554 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c @@ -704,17 +704,20 @@ static void arm_smmu_v3_invs_test(struct kunit *test) =20 /* New array */ test_a =3D arm_smmu_invs_alloc(0); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_a); KUNIT_EXPECT_EQ(test, test_a->num_invs, 0); =20 /* Test1: merge invs1 (new array) */ test_b =3D arm_smmu_invs_merge(test_a, &invs1); kfree(test_a); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_b); arm_smmu_v3_invs_test_verify(test, test_b, ARRAY_SIZE(results1[0]), 0, results1[0], results1[1], results1[2]); =20 /* Test2: merge invs2 (new array) */ test_a =3D arm_smmu_invs_merge(test_b, &invs2); kfree(test_b); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_a); arm_smmu_v3_invs_test_verify(test, test_a, ARRAY_SIZE(results2[0]), 0, results2[0], results2[1], results2[2]); =20 @@ -726,6 +729,7 @@ static void arm_smmu_v3_invs_test(struct kunit *test) /* Test4: merge invs3 (new array) */ test_b =3D arm_smmu_invs_merge(test_a, &invs3); kfree(test_a); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_b); arm_smmu_v3_invs_test_verify(test, test_b, ARRAY_SIZE(results4[0]), 0, results4[0], results4[1], results4[2]); =20 @@ -737,6 +741,7 @@ static void arm_smmu_v3_invs_test(struct kunit *test) /* Test6: purge test_b (new array) */ test_a =3D arm_smmu_invs_purge(test_b); kfree(test_b); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_a); arm_smmu_v3_invs_test_verify(test, test_a, ARRAY_SIZE(results6[0]), 0, results6[0], results6[1], results6[2]); =20 @@ -748,12 +753,14 @@ static void arm_smmu_v3_invs_test(struct kunit *test) /* Test8: merge invs4 (new array) */ test_b =3D arm_smmu_invs_merge(test_a, &invs4); kfree(test_a); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_b); arm_smmu_v3_invs_test_verify(test, test_b, ARRAY_SIZE(results7[0]), 0, results7[0], results7[1], results7[2]); =20 /* Test9: merge invs5 (new array) */ test_a =3D arm_smmu_invs_merge(test_b, &invs5); kfree(test_b); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_a); arm_smmu_v3_invs_test_verify(test, test_a, ARRAY_SIZE(results8[0]), 0, results8[0], results8[1], results8[2]); =20 @@ -765,6 +772,7 @@ static void arm_smmu_v3_invs_test(struct kunit *test) /* Test11: purge test_a (new array) */ test_b =3D arm_smmu_invs_purge(test_a); kfree(test_a); + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, test_b); arm_smmu_v3_invs_test_verify(test, test_b, ARRAY_SIZE(results10[0]), 0, results10[0], results10[1], results10[2]); =20 --=20 2.55.0.897.gb25b4bd76c-goog From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2168444E675 for ; Fri, 28 Aug 2026 12:54:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921677; cv=none; b=BPTvwTstEd2VwBBMnKudea3xrBmUcd8Mx78pyYJzEgq8kq+qk1VkuF2salQu/JGBTgZO9OpFXqRH1t7YpJHryh5XYE/MXwFLbSA9Av/1PU3VOrytnVbpYMB9xOJo1y4uku25iKsWRHbw3zx8RM5WZqp3u81iSOqpTe+I6aS381M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921677; c=relaxed/simple; bh=cDjSIu32aBcSz8TdWp61j1qcW7QdeCw7abPmRtNMq4o=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=lEOMlX+6OCJD6/tBGVzqj15Zu+FFkuswHDjqRxLPIQIlW8+sBDkVtA14RaMHC/CDApUewQdY9/3btKOD4cWZ3L95gRvL5PTopp3sYBHkfaBj2kk5HvVFV7wGsC8QEhCsxkBfeGLV60QG6ZLr05VDjwkrVsRkVf1MOe0lLRQ5TAs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=M2RSLXSm; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="M2RSLXSm" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-490a767b782so6665975e9.2 for ; Fri, 28 Aug 2026 05:54:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921673; x=1788526473; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ecFwLqLiGFgZXlWDMNOiqsl5/zZT7jnAo8maGJSVqdA=; b=M2RSLXSmYjqKL6bwwqew9yOnh+wtvUlTXQUL1DIpXsPvMDe3l8HLsKGjAhLVRtLPPb 0x4JABQia1dqW3sxmhqVaRySGoottzFNKCrNGRV+k7JgX+Rksb6dcWtkKYGbIWm32E31 b9T5wu1zEhG3ypFAb6kY9O8Q6gUOqf3Uwq3+qPIme9zjKqHc8Tr7RpJlL6PTb+ZAKjre HlZpwIYYW+MbnHE6FZ3Uw4NT2eQMOiyrKpjCS1+DoORflSC0ooe2UuTKDq0jmIw7kwTw kRbMqDlnHiRODDpfeBItUPqlJGsuObxv7TRiFiAn9IEoOTOyV7BbKv/LwYvR1F9PgJnG 9Pew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921673; x=1788526473; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ecFwLqLiGFgZXlWDMNOiqsl5/zZT7jnAo8maGJSVqdA=; b=YRhIRpRnanHRJ8R4omfJAEwEr2k5wAw1GxIXNkCs8RhtLPOELdG9coElkMhrrIsS9z eHWKAojS4486uWrQ/qt3KnwVIcatU4i0dlk2JRhZgQX3wKJU6wgYQ/MkhCi2E4HwI+tg o81UcFqAi8n2K85iZLcA5Eorw6TJv9rZ5G7G1DhoYq4nSSOUFvI/FCVNauoMItg4ApWj 9LMR4iaG5nNPmOcOCxBjEW8KrX6fei5dg/+mbvSvOXq2qyrWirpL/C5eQJDEth1G58Vg 46GRRpkh5ZGhEvToY777w5IEtaffmh3jL+gHvTAk6KxDH4Pmn6ZIhTNjmxjL7LTSMViH sR8A== X-Gm-Message-State: AFuF++l9JkcVbqxYyDGGH3TyR3A/QDKXyVgo6NFhMyI+CaHHp63H0X6B IXsT+E2O29Fp7aOTAtOr9aDwomArwfUTY7NXfzgGy8MlhtpVM/RD7oypT2HVP1cuBNNHl/Cj0Cm GEbqRDceEjFbrOIYoUx0dFCjJLFHOUsb3n8eXmrdUEgrCeibRAr2SYQ7wDC9HgU/t3bGCdcHvf1 QpA5cqlsBgzqEQkLeHAI/dL2Giwkf1Iro/fgHnjjfFfifY3mibG7cwMiU= X-Received: from wmlv9.prod.google.com ([2002:a05:600c:2149:b0:49b:8f4c:fc2e]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:6088:b0:49b:2796:be30 with SMTP id 5b1f17b1804b1-49b91c433a4mr103156005e9.11.1787921672987; Fri, 28 Aug 2026 05:54:32 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:41 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-7-smostafa@google.com> Subject: [PATCH 6/7] iommu/arm-smmu-v3-test: Fix OOB in arm_smmu_v3_invs_test_verify() From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" arm_smmu_v3_invs_test_verify() validates the array bounds using KUNIT_EXPECT_EQ(), which triggers a failure and continues execution. If invs->num_invs was smaller than expected, the next loop over num_invs would blindly read past the end of the invs->inv[] array. Switch to KUNIT_ASSERT_EQ() to fail and stop the test on bound errors. Fixes: 15a2a5645ad7 ("iommu/arm-smmu-v3: Introduce a per-domain arm_smmu_in= vs array") Reported-by: Sashiko <> Signed-off-by: Mostafa Saleh Reviewed-by: Jason Gunthorpe Reviewed-by: Nicolin Chen --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c b/drivers/iom= mu/arm/arm-smmu-v3/arm-smmu-v3-test.c index 366dcb2b5554..244cf34e5a0b 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c @@ -643,7 +643,7 @@ static void arm_smmu_v3_invs_test_verify(struct kunit *= test, const int *ids, const int *users, const int *ssids) { - KUNIT_EXPECT_EQ(test, invs->num_invs, num_invs); + KUNIT_ASSERT_EQ(test, invs->num_invs, num_invs); KUNIT_EXPECT_EQ(test, invs->num_trashes, num_trashes); while (num_invs--) { KUNIT_EXPECT_EQ(test, invs->inv[num_invs].id, ids[num_invs]); --=20 2.55.0.897.gb25b4bd76c-goog From nobody Sat Sep 26 23:32:26 2026 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0C7BA4519A3 for ; Fri, 28 Aug 2026 12:54:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921678; cv=none; b=QM3NouhEJGItsTKFilnf3i2Nn4f6Q2ApFuOOVJs7vrKm0xjZA04H53KI7fyU/F6MbkRJSqjjv8b2n8wbMPAlVLXABDrKZG2DAUKlPqDATKpZydVSQQJKuUm2HuMqH5LKHbr2ibJtz91CU2vu+j7gSdqqP9j2huIP/hieDg+JBoQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787921678; c=relaxed/simple; bh=gVQ7u5jDgJkCL3SN8F3pewl83SUruus2jM9vNu3Da/8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=u18NhMNbApTva6SL9h0SvXOGSCRJ+fprk8QYZLhbHNMADaG/Oedc7WAEjWkjShn3TaU/RdRS0wkE2naiV84lQkXt6TpK24uJVo1m0ZB80/28Q6J8D37676TwZKo+79xe2mBC2t98ATF1AxgB3+97Jh5c8Ot+YukkwNdnwCVj9FM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=qtlcCd4a; arc=none smtp.client-ip=209.85.128.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="qtlcCd4a" Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-495474a5fbcso7802375e9.1 for ; Fri, 28 Aug 2026 05:54:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787921675; x=1788526475; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=yqE2RL7ob83hHe4LCs/SgOtsDWUwdfHdO0PxSusQVD0=; b=qtlcCd4a2swfJH9NDM01OViJToD4WTo72UlaKUzV+RSqvHw6W4MEfMKhiX6+nKC0fs AkIHnUr2i8fXr2fchrZgTltVZkGVkW/UQCVQELHCAdhybm5d86p76GmViHuxXyv9BmEz 5xgmyJ65V245e0gOvzN6SCndkYErVn2BpUcz1JCqi+mkeFnY0LOMK/V29B1dC2Md7IO7 teT77TYh4RQZhUD/VdsojxqdoTTn241/q0++sY48x0e4vda7u9Uk2Bjx8pN9l33DjRqH TI51+nPW4woUgDYqq+RG4NdAXQ8auzHebEosvXTbPh6wIwU7YUg4HI/Yw0gaLsxB9N1D +tKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787921675; x=1788526475; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yqE2RL7ob83hHe4LCs/SgOtsDWUwdfHdO0PxSusQVD0=; b=XMN4n6hr/NCQhnUtNQFOhZKjQb8xDh10FaYmm6uWM9LFC2rJnFkoepb/5iuQmJPgZz Lp/Eqoo2fq2lv95+lFoTCcop12+RNzLFhPPJ6e9BNTXjW3MrUnyz+JzxOa02beR61BFC qfvP2PH7Ye46YwBOhg7LDamOZVZszzQKjWbBjTq3NDDSC4TYQMe4/19Heq2IeSNwEgiR PFYqzn/0lepZnQ9eZl34ePSkZBqgDzFFMF4iEp53rH0BK6SdUdrC6kYYeWdxW3yo6G4e la/rmIiyMSno/D0Y5jurUsFZsAg3YYrGGKKt/PMOJxM9LjvFDn8JA9g0sXCvrORoHr4D uDzQ== X-Gm-Message-State: AFuF++m0qx97gn2Ocux764gnVkTwdx1w40cuJfYyhr9WobG6/7Wv8f2N Ehla/2IJ2znl5V1HP6IP+fTMEJpvfrUbKrSZpBfoY3KchHL+Pg7X+35tSeH4GUM1WGf19QKc3iE delNBn8pKgQoCdFQ75QBYzHcyvLWWy6+Y8hoVicrd5Piakb+KEomO5TXzD3a5Z2sLh0CKO76L7r fsyaTlfOqQ6VTB8VjP7dEuOFAfata1jW5ggTTXse1Q7vvrcsJmN4kswYM= X-Received: from wmlf1.prod.google.com ([2002:a7b:c8c1:0:b0:493:bd51:5095]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:8b6b:b0:49b:c8e:8e6 with SMTP id 5b1f17b1804b1-49b91bd99b7mr113293015e9.0.1787921674606; Fri, 28 Aug 2026 05:54:34 -0700 (PDT) Date: Fri, 28 Aug 2026 12:53:42 +0000 In-Reply-To: <20260828125409.1921538-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260828125409.1921538-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260828125409.1921538-8-smostafa@google.com> Subject: [PATCH 7/7] iommu/arm-smmu-v3-test: Fix UBSAN error From: Mostafa Saleh To: linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: will@kernel.org, robin.murphy@arm.com, joro@8bytes.org, jgg@ziepe.ca, nicolinc@nvidia.com, praan@google.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" struct arm_smmu_invs marks its flexible array member inv[] with the __counted_by(max_invs). arm_smmu_v3_invs_test() uses invs1 to invs5 which has num_invs =3D 3 but omit max_invs. This causes the following UBSAN error: [ 2.333240] UBSAN: array-index-out-of-bounds in drivers/iommu/arm/arm-sm= mu-v3/arm-smmu-v3.c:1116:21 [ 2.333604] # arm_smmu_v3_invs_test: lib/ubsan.c:228: array-index-ou= t-of-bounds in drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c [ 2.334129] index 1 is out of range for type 'struct arm_smmu_inv[] __co= unted_by(max_invs)' (aka 'struct arm_smmu_inv[]') [ 2.335375] CPU: 6 UID: 0 PID: 155 Comm: kunit_try_catch Tainted: G = N 7.2.0-g8dcb331fbb72 #2 PREEMPT [ 2.335759] Tainted: [N]=3DTEST [ 2.335791] Hardware name: linux,dummy-virt (DT) [ 2.336254] Call trace: [ 2.336932] show_stack+0x18/0x24 (C) [ 2.338443] __dump_stack+0x28/0x38 [ 2.338494] dump_stack_lvl+0x54/0x6c [ 2.338518] dump_stack+0x18/0x24 [ 2.338541] ubsan_epilogue+0x10/0x44 [ 2.338565] __ubsan_handle_out_of_bounds+0xb8/0xbc [ 2.338834] arm_smmu_invs_merge+0x688/0x8ac [ 2.338862] arm_smmu_v3_invs_test+0xd4/0x598 [ 2.338890] kunit_try_run_case+0x64/0x160 [ 2.338914] kunit_generic_run_threadfn_adapter+0x28/0x4c [ 2.338955] kthread+0x10c/0x12c [ 2.338984] ret_from_fork+0x10/0x20 [ 2.339433] ---[ end trace ]--- Explicitly set max_invs =3D 3 on the test arrays to match the number of elements. Fixes: 15a2a5645ad7 ("iommu/arm-smmu-v3: Introduce a per-domain arm_smmu_in= vs array") Signed-off-by: Mostafa Saleh Reviewed-by: Jason Gunthorpe Reviewed-by: Nicolin Chen --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c b/drivers/iom= mu/arm/arm-smmu-v3/arm-smmu-v3-test.c index 244cf34e5a0b..e52a7d95c919 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-test.c @@ -654,6 +654,7 @@ static void arm_smmu_v3_invs_test_verify(struct kunit *= test, } =20 static struct arm_smmu_invs invs1 =3D { + .max_invs =3D 3, .num_invs =3D 3, .inv =3D { { .type =3D INV_TYPE_S2_VMID, .id =3D 1, }, { .type =3D INV_TYPE_S2_VMID_S1_CLEAR, .id =3D 1, }, @@ -661,6 +662,7 @@ static struct arm_smmu_invs invs1 =3D { }; =20 static struct arm_smmu_invs invs2 =3D { + .max_invs =3D 3, .num_invs =3D 3, .inv =3D { { .type =3D INV_TYPE_S2_VMID, .id =3D 1, }, /* duplicated */ { .type =3D INV_TYPE_ATS, .id =3D 4, }, @@ -668,6 +670,7 @@ static struct arm_smmu_invs invs2 =3D { }; =20 static struct arm_smmu_invs invs3 =3D { + .max_invs =3D 3, .num_invs =3D 3, .inv =3D { { .type =3D INV_TYPE_S2_VMID, .id =3D 1, }, /* duplicated */ { .type =3D INV_TYPE_ATS, .id =3D 5, }, /* recover a trash */ @@ -675,6 +678,7 @@ static struct arm_smmu_invs invs3 =3D { }; =20 static struct arm_smmu_invs invs4 =3D { + .max_invs =3D 3, .num_invs =3D 3, .inv =3D { { .type =3D INV_TYPE_ATS, .id =3D 10, .ssid =3D 1 }, { .type =3D INV_TYPE_ATS, .id =3D 10, .ssid =3D 3 }, @@ -682,6 +686,7 @@ static struct arm_smmu_invs invs4 =3D { }; =20 static struct arm_smmu_invs invs5 =3D { + .max_invs =3D 3, .num_invs =3D 3, .inv =3D { { .type =3D INV_TYPE_ATS, .id =3D 10, .ssid =3D 2 }, { .type =3D INV_TYPE_ATS, .id =3D 10, .ssid =3D 3 }, /* duplicate */ --=20 2.55.0.897.gb25b4bd76c-goog