public inbox for linux-arm-kernel@lists.infradead.org 
 help / color / mirror / Atom feed
From: Pranjal Shrivastava <praan@google•com>
To: iommu@lists•linux.dev, linux-pci@vger•kernel.org,
	 linux-arm-kernel@lists•infradead.org,
	linux-kernel@vger•kernel.org
Cc: Joerg Roedel <joro@8bytes•org>, Will Deacon <will@kernel•org>,
	 Bjorn Helgaas <bhelgaas@google•com>,
	David Woodhouse <dwmw2@infradead•org>,
	 Lu Baolu <baolu.lu@linux•intel.com>,
	Robin Murphy <robin.murphy@arm•com>,
	 Suravee Suthikulpanit <suravee.suthikulpanit@amd•com>,
	Jason Gunthorpe <jgg@ziepe•ca>,
	 Nicolin Chen <nicolinc@nvidia•com>,
	David Matlack <dmatlack@google•com>,
	 Samiullah Khawaja <skhawaja@google•com>,
	Daniel Mentz <danielmentz@google•com>,
	 Pasha Tatashin <pasha.tatashin@soleen•com>,
	Mostafa Saleh <smostafa@google•com>,
	 Pranjal Shrivastava <praan@google•com>
Subject: [PATCH v6 6/6] iommu/amd: Fail probe on ATS configuration failure
Date: Fri, 29 May 2026 11:12:08 +0000	[thread overview]
Message-ID: <20260529111208.387412-7-praan@google.com> (raw)
In-Reply-To: <20260529111208.387412-1-praan@google.com>

Update the AMD IOMMU driver to handle ATS configuration and enablement
more strictly. Specifically, update the device probe to fail if
pci_prepare_ats() returns an error. This ensures that any ATS-capable
master reaching the attach phase is guaranteed to have a valid config.

Additionally, update pdev_enable_cap_ats() to WARN_ON() if pci_enable_ats
fails. Since earlier checks in the probe phase preclude config-related
failures, any failure during hardware enablement is considered a kernel
bug.

Fix a pre-existing Use-After-Free risk by ensuring iommu_ignore_device()
is called on all probe failures after iommu_init_device().

Signed-off-by: Pranjal Shrivastava <praan@google•com>
---
 drivers/iommu/amd/iommu.c | 30 ++++++++++++++++++++++++------
 1 file changed, 24 insertions(+), 6 deletions(-)

diff --git a/drivers/iommu/amd/iommu.c b/drivers/iommu/amd/iommu.c
index 84cad43dc188..b74c4504bee3 100644
--- a/drivers/iommu/amd/iommu.c
+++ b/drivers/iommu/amd/iommu.c
@@ -570,10 +570,16 @@ static inline int pdev_enable_cap_ats(struct pci_dev *pdev)
 	if (amd_iommu_iotlb_sup &&
 	    (dev_data->flags & AMD_IOMMU_DEVICE_FLAG_ATS_SUP)) {
 		ret = pci_enable_ats(pdev, PAGE_SHIFT);
-		if (!ret) {
-			dev_data->ats_enabled = 1;
-			dev_data->ats_qdep    = pci_ats_queue_depth(pdev);
-		}
+		/*
+		 * pci_enable_ats() should not fail here because earlier checks
+		 * have already verified support and configuration.
+		 */
+		if (WARN_ON(ret))
+			return ret;
+
+		dev_data->ats_enabled = 1;
+		dev_data->ats_qdep    = pci_ats_queue_depth(pdev);
+		ret = 0;
 	}
 
 	return ret;
@@ -2502,10 +2508,22 @@ static struct iommu_device *amd_iommu_probe_device(struct device *dev)
 	else
 		dev_data->max_irqs = MAX_IRQS_PER_TABLE_512;
 
-	if (dev_is_pci(dev))
-		pci_prepare_ats(to_pci_dev(dev), PAGE_SHIFT);
+	if (dev_is_pci(dev)) {
+		struct pci_dev *pdev = to_pci_dev(dev);
+
+		if (pci_ats_supported(pdev)) {
+			ret = pci_prepare_ats(pdev, PAGE_SHIFT);
+			if (ret) {
+				iommu_dev = ERR_PTR(ret);
+				goto out_err;
+			}
+		}
+	}
 
 out_err:
+	if (IS_ERR(iommu_dev))
+		iommu_ignore_device(iommu, dev);
+
 	return iommu_dev;
 }
 
-- 
2.54.0.823.g6e5bcc1fc9-goog



  parent reply	other threads:[~2026-05-29 11:12 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-29 11:12 [PATCH v6 0/6] iommu: Standardize ATS robustness and state tracking Pranjal Shrivastava
2026-05-29 11:12 ` [PATCH v6 1/6] PCI/ATS: Ensure pci_ats_supported() is PF-aware for VFs Pranjal Shrivastava
2026-05-29 11:12 ` [PATCH v6 2/6] PCI/ATS: Validate STU for VFs in pci_prepare_ats() Pranjal Shrivastava
2026-05-29 11:12 ` [PATCH v6 3/6] PCI/ATS: Mandate checking pci_ats_supported() before pci_prepare_ats() Pranjal Shrivastava
2026-05-29 21:56   ` Nicolin Chen
2026-05-31 17:06     ` Pranjal Shrivastava
2026-05-29 11:12 ` [PATCH v6 4/6] iommu/arm-smmu-v3: Standardize ATS enablement failure reporting Pranjal Shrivastava
2026-05-29 21:51   ` Nicolin Chen
2026-05-31 17:13     ` Pranjal Shrivastava
2026-05-29 11:12 ` [PATCH v6 5/6] iommu/vt-d: Fail probe on ATS configuration failure Pranjal Shrivastava
2026-05-29 11:12 ` Pranjal Shrivastava [this message]
2026-06-01  6:00   ` [PATCH v6 6/6] iommu/amd: " Ankit Soni
2026-06-01  6:20     ` Pranjal Shrivastava
2026-06-01  8:17       ` Ankit Soni
2026-06-01 10:35         ` Pranjal Shrivastava
2026-06-01  9:28       ` Vasant Hegde
2026-06-01 10:41         ` Pranjal Shrivastava

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260529111208.387412-7-praan@google.com \
    --to=praan@google$(echo .)com \
    --cc=baolu.lu@linux$(echo .)intel.com \
    --cc=bhelgaas@google$(echo .)com \
    --cc=danielmentz@google$(echo .)com \
    --cc=dmatlack@google$(echo .)com \
    --cc=dwmw2@infradead$(echo .)org \
    --cc=iommu@lists$(echo .)linux.dev \
    --cc=jgg@ziepe$(echo .)ca \
    --cc=joro@8bytes$(echo .)org \
    --cc=linux-arm-kernel@lists$(echo .)infradead.org \
    --cc=linux-kernel@vger$(echo .)kernel.org \
    --cc=linux-pci@vger$(echo .)kernel.org \
    --cc=nicolinc@nvidia$(echo .)com \
    --cc=pasha.tatashin@soleen$(echo .)com \
    --cc=robin.murphy@arm$(echo .)com \
    --cc=skhawaja@google$(echo .)com \
    --cc=smostafa@google$(echo .)com \
    --cc=suravee.suthikulpanit@amd$(echo .)com \
    --cc=will@kernel$(echo .)org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox