]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
vfio: Fix unbalanced vfio_df_close call in no-iommu mode
authorJacob Pan <jacob.pan@linux.microsoft.com>
Wed, 18 Jun 2025 23:46:17 +0000 (16:46 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 15 Aug 2025 10:14:02 +0000 (12:14 +0200)
[ Upstream commit b25e271b377999191b12f0afbe1861edcf57e3fe ]

For devices with no-iommu enabled in IOMMUFD VFIO compat mode, the group open
path skips vfio_df_open(), leaving open_count at 0. This causes a warning in
vfio_assert_device_open(device) when vfio_df_close() is called during group
close.

The correct behavior is to skip only the IOMMUFD bind in the device open path
for no-iommu devices. Commit 6086efe73498 omitted vfio_df_open(), which was
too broad. This patch restores the previous behavior, ensuring
the vfio_df_open is called in the group open path.

Fixes: 6086efe73498 ("vfio-iommufd: Move noiommu compat validation out of vfio_iommufd_bind()")
Suggested-by: Alex Williamson <alex.williamson@redhat.com>
Suggested-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Jacob Pan <jacob.pan@linux.microsoft.com>
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Link: https://lore.kernel.org/r/20250618234618.1910456-1-jacob.pan@linux.microsoft.com
Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/vfio/group.c
drivers/vfio/iommufd.c

index 95b336de8a1732c53f76f57f921d4ae6ecd1ee4f..5f2b2c950bbc1d818fa96a5e9d018bceb241967d 100644 (file)
@@ -194,11 +194,10 @@ static int vfio_df_group_open(struct vfio_device_file *df)
                 * implies they expected translation to exist
                 */
                if (!capable(CAP_SYS_RAWIO) ||
-                   vfio_iommufd_device_has_compat_ioas(device, df->iommufd))
+                   vfio_iommufd_device_has_compat_ioas(device, df->iommufd)) {
                        ret = -EPERM;
-               else
-                       ret = 0;
-               goto out_put_kvm;
+                       goto out_put_kvm;
+               }
        }
 
        ret = vfio_df_open(df);
index 82eba6966fa508d827c4f1b6f628db0d63d7d6a4..02852899c2aee4543406567ecccadf09b301b5d7 100644 (file)
@@ -25,6 +25,10 @@ int vfio_df_iommufd_bind(struct vfio_device_file *df)
 
        lockdep_assert_held(&vdev->dev_set->lock);
 
+       /* Returns 0 to permit device opening under noiommu mode */
+       if (vfio_device_is_noiommu(vdev))
+               return 0;
+
        return vdev->ops->bind_iommufd(vdev, ictx, &df->devid);
 }