[PATCH v2 00/11] iommu/tegra241-cmdqv: Fix error-interrupt races and VINTF lifecycle bugs

Nicolin Chen posted 11 patches 1 week, 3 days ago
.../iommu/arm/arm-smmu-v3/tegra241-cmdqv.c    | 224 ++++++++++++------
1 file changed, 156 insertions(+), 68 deletions(-)
[PATCH v2 00/11] iommu/tegra241-cmdqv: Fix error-interrupt races and VINTF lifecycle bugs
Posted by Nicolin Chen 1 week, 3 days ago
These fix a cluster of bugs reported by Sashiko during patch reviews. The
patches are ordered roughly most-critical-first, so some later ones fix
smaller pre-existing issues in the same functions that earlier patches
touch.

Issues fixed:
  - the error ISR racing VINTF (de)init and reading a NULL, freed, or not
    yet fully initialized slot
  - the probe fallback dereferencing an smmu freed by devm_krealloc()
  - a guest vSID programmed without validating its width or the device's
    Stream ID count
  - VINTF0 leaked on an init-failure path
  - error-map index/bounds handling and a VCMDQ base above the 48-bit limit
  - the error ISR flooding the kernel log under repeated guest errors

False positives raised by Sashiko:
  - a viommu outliving an SMMU unbind and touching freed memory on close: a
    physical IOMMU is not a pluggable device, so iommufd holds no reference
    on the one behind a viommu, and this teardown cannot arise.
  - the ISR running after cmdqv is freed on probe failure: free_irq() runs
    first from tegra241_cmdqv_remove(), the devm device_remove action,
    which devres invokes before the cmdqv allocation is released.
  - a guest never acking its VCMDQ error wedging the shared interrupt: the
    interrupt is edge-signaled per event, and the host ISR only snapshots
    the error map into the guest's bounded vEVENTQ, never depending on a
    guest-side GERRORN ack.
  - the ISR accessing a de-assigned LVCMDQ page after a VINTF hw_init()
    failure: the page remains a mapped MMIO region backed by empty
    registers, so reads are benign and writes are dropped.

In parallel to Shameer's Tegra241 CMDQV CMD_SYNC use-after-free fix:
https://lore.kernel.org/all/20260629094106.251694-1-skolothumtho@nvidia.com/

This is on github:
https://github.com/nicolinc/iommufd/commits/fix_cmdqv_sashiko-v2

Changelog
v2
 * Return -EOPNOTSUPP in tegra241_vintf_init_vsid
v1
 https://lore.kernel.org/all/cover.1783054570.git.nicolinc@nvidia.com/

Nicolin Chen (11):
  iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully
    initialized
  iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init
  iommu/tegra241-cmdqv: Harden error-map index handling in the error ISR
  iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up
    vintfs
  iommu/tegra241-cmdqv: Don't fall back to a freed smmu after
    devm_krealloc()
  iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
  iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
  iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
  iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path
  iommu/tegra241-cmdqv: Warn on a VCMDQ base above the 48-bit hardware
    limit
  iommu/tegra241-cmdqv: Rate-limit the error ISR's log message

 .../iommu/arm/arm-smmu-v3/tegra241-cmdqv.c    | 224 ++++++++++++------
 1 file changed, 156 insertions(+), 68 deletions(-)

-- 
2.43.0
Re: [PATCH v2 00/11] iommu/tegra241-cmdqv: Fix error-interrupt races and VINTF lifecycle bugs
Posted by Nicolin Chen 1 week, 3 days ago
On Tue, Jul 14, 2026 at 01:54:57PM -0700, Nicolin Chen wrote:
> False positives raised by Sashiko:
>   - a viommu outliving an SMMU unbind and touching freed memory on close: a
>     physical IOMMU is not a pluggable device, so iommufd holds no reference
>     on the one behind a viommu, and this teardown cannot arise.
>   - the ISR running after cmdqv is freed on probe failure: free_irq() runs
>     first from tegra241_cmdqv_remove(), the devm device_remove action,
>     which devres invokes before the cmdqv allocation is released.
>   - a guest never acking its VCMDQ error wedging the shared interrupt: the
>     interrupt is edge-signaled per event, and the host ISR only snapshots
>     the error map into the guest's bounded vEVENTQ, never depending on a
>     guest-side GERRORN ack.
>   - the ISR accessing a de-assigned LVCMDQ page after a VINTF hw_init()
>     failure: the page remains a mapped MMIO region backed by empty
>     registers, so reads are benign and writes are dropped.

Adding one more false positive:

Sashiko reported against this v2 a critical issue stating that
CMDQV is level-triggered and could cause trouble in kdump case.

But CMDQV is edge-triggered; one of the ISR patches noted very
clearly.

Nicolin