]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
authorPeiyang He <peiyang_he@smail.nju.edu.cn>
Fri, 10 Jul 2026 12:29:52 +0000 (20:29 +0800)
committerJason Gunthorpe <jgg@nvidia.com>
Mon, 13 Jul 2026 16:52:41 +0000 (13:52 -0300)
iommufd_hwpt_replace_device() calls:

iommufd_auto_response_faults(hwpt, old_handle);

passing the *new* hwpt together with the handle of
the device's *old* domain. This should be a parameter mismatch:

1. Semantically, iommufd_auto_response_faults(x, handle) scans
   x->fault's deliver list and response xarray for groups matching
   "handle". A group is queued under the hwpt that was attached at
   fault-delivery time. old_handle is fetched *before* the domain switch,
   so its group lives on old->fault, not on the new hwpt->fault.

2. Historically, the first argument was "old". The routine was
   introduced by commit b7d8833677ba ("iommufd: Fault-capable hwpt
   attach/detach/replace") as __fault_domain_replace_dev() in
   fault.c, correctly calling iommufd_auto_response_faults(old, curr).
   Commit fb21b1568ada ("iommufd: Make attach_handle generic than
   fault specific") moved this into iommufd_hwpt_replace_device() in
   device.c and swapped it to "hwpt". This should be a refactor regression,
   not an intentional change.

Fix this by passing "old" instead.

Link: https://patch.msgid.link/r/9D652384339C69D5+20260710122952.885325-1-peiyang_he@smail.nju.edu.cn
Fixes: fb21b1568ada ("iommufd: Make attach_handle generic than fault specific")
Cc: stable@vger.kernel.org
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
drivers/iommu/iommufd/device.c

index 170a7005f0bc84048369e30eeac144773b98c089..2895e5370910feb4a5ba14802e025915f007f02b 100644 (file)
@@ -589,7 +589,7 @@ static int iommufd_hwpt_replace_device(struct iommufd_device *idev,
        if (rc)
                goto out_free_handle;
 
-       iommufd_auto_response_faults(hwpt, old_handle);
+       iommufd_auto_response_faults(old, old_handle);
        kfree(old_handle);
 
        return 0;