mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 13:14:02 +02:00
iommufd: Avoid locking internal accesses during unmap
iommufd_access_notify_unmap() skips internal accesses because they do
not have an external unmap callback to invoke.
However, the current test calls iommufd_lock_obj() before checking
whether the access is internal. If iommufd_lock_obj() succeeds, the loop
then sees the internal access and continues, bypassing the matching
iommufd_put_object() used by the normal unmap path. This leaks the
object reference taken by iommufd_lock_obj().
Check for internal accesses first so skipped entries are never locked.
Fixes: 27b77ea5fe ("iommufd/access: Bypass access->ops->unmap for internal use")
Cc: stable@vger.kernel.org
Assisted-by: Qoder:Qwen-3.8-MAX-Preview
Signed-off-by: Shuai Xue <xueshuai@linux.alibaba.com>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
This commit is contained in:
parent
530f8f9c35
commit
0dbcdf4473
|
|
@ -1307,8 +1307,8 @@ void iommufd_access_notify_unmap(struct io_pagetable *iopt, unsigned long iova,
|
|||
|
||||
xa_lock(&ioas->iopt.access_list);
|
||||
xa_for_each(&ioas->iopt.access_list, index, access) {
|
||||
if (!iommufd_lock_obj(&access->obj) ||
|
||||
iommufd_access_is_internal(access))
|
||||
if (iommufd_access_is_internal(access) ||
|
||||
!iommufd_lock_obj(&access->obj))
|
||||
continue;
|
||||
xa_unlock(&ioas->iopt.access_list);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user