Skip to content

Commit 9f7c689

Browse files
jgunthorpewilldeacon
authored andcommitted
iommu/arm-smmu-v3: Hold arm_smmu_asid_lock during all of attach_dev
The BTM support wants to be able to change the ASID of any smmu_domain. When it goes to do this it holds the arm_smmu_asid_lock and iterates over the target domain's devices list. During attach of a S1 domain we must ensure that the devices list and CD are in sync, otherwise we could miss CD updates or a parallel CD update could push an out of date CD. This is pretty complicated, and almost works today because arm_smmu_detach_dev() removes the master from the linked list before working on the CD entries, preventing parallel update of the CD. However, it does have an issue where the CD can remain programed while the domain appears to be unattached. arm_smmu_share_asid() will then not clear any CD entriess and install its own CD entry with the same ASID concurrently. This creates a small race window where the IOMMU can see two ASIDs pointing to different translations. CPU0 CPU1 arm_smmu_attach_dev() arm_smmu_detach_dev() spin_lock_irqsave(&smmu_domain->devices_lock, flags); list_del(&master->domain_head); spin_unlock_irqrestore(&smmu_domain->devices_lock, flags); arm_smmu_mmu_notifier_get() arm_smmu_alloc_shared_cd() arm_smmu_share_asid(): // Does nothing due to list_del above arm_smmu_update_ctx_desc_devices() arm_smmu_tlb_inv_asid() arm_smmu_write_ctx_desc() ** Now the ASID is in two CDs with different translation arm_smmu_write_ctx_desc(master, IOMMU_NO_PASID, NULL); Solve this by wrapping most of the attach flow in the arm_smmu_asid_lock. This locks more than strictly needed to prepare for the next patch which will reorganize the order of the linked list, STE and CD changes. Move arm_smmu_detach_dev() till after we have initialized the domain so the lock can be held for less time. Reviewed-by: Michael Shavit <[email protected]> Reviewed-by: Nicolin Chen <[email protected]> Reviewed-by: Mostafa Saleh <[email protected]> Tested-by: Shameer Kolothum <[email protected]> Tested-by: Nicolin Chen <[email protected]> Tested-by: Moritz Fischer <[email protected]> Signed-off-by: Jason Gunthorpe <[email protected]> Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Will Deacon <[email protected]>
1 parent 71b0aa1 commit 9f7c689

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2586,8 +2586,6 @@ static int arm_smmu_attach_dev(struct iommu_domain *domain, struct device *dev)
25862586
return -EBUSY;
25872587
}
25882588

2589-
arm_smmu_detach_dev(master);
2590-
25912589
mutex_lock(&smmu_domain->init_mutex);
25922590

25932591
if (!smmu_domain->smmu) {
@@ -2602,6 +2600,16 @@ static int arm_smmu_attach_dev(struct iommu_domain *domain, struct device *dev)
26022600
if (ret)
26032601
return ret;
26042602

2603+
/*
2604+
* Prevent arm_smmu_share_asid() from trying to change the ASID
2605+
* of either the old or new domain while we are working on it.
2606+
* This allows the STE and the smmu_domain->devices list to
2607+
* be inconsistent during this routine.
2608+
*/
2609+
mutex_lock(&arm_smmu_asid_lock);
2610+
2611+
arm_smmu_detach_dev(master);
2612+
26052613
master->domain = smmu_domain;
26062614

26072615
/*
@@ -2627,13 +2635,7 @@ static int arm_smmu_attach_dev(struct iommu_domain *domain, struct device *dev)
26272635
}
26282636
}
26292637

2630-
/*
2631-
* Prevent SVA from concurrently modifying the CD or writing to
2632-
* the CD entry
2633-
*/
2634-
mutex_lock(&arm_smmu_asid_lock);
26352638
ret = arm_smmu_write_ctx_desc(master, IOMMU_NO_PASID, &smmu_domain->cd);
2636-
mutex_unlock(&arm_smmu_asid_lock);
26372639
if (ret) {
26382640
master->domain = NULL;
26392641
goto out_list_del;
@@ -2643,13 +2645,15 @@ static int arm_smmu_attach_dev(struct iommu_domain *domain, struct device *dev)
26432645
arm_smmu_install_ste_for_dev(master);
26442646

26452647
arm_smmu_enable_ats(master);
2646-
return 0;
2648+
goto out_unlock;
26472649

26482650
out_list_del:
26492651
spin_lock_irqsave(&smmu_domain->devices_lock, flags);
26502652
list_del(&master->domain_head);
26512653
spin_unlock_irqrestore(&smmu_domain->devices_lock, flags);
26522654

2655+
out_unlock:
2656+
mutex_unlock(&arm_smmu_asid_lock);
26532657
return ret;
26542658
}
26552659

0 commit comments

Comments
 (0)