]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
iommu/amd: Fix nested domain leak
authorTycho Andersen (AMD) <tycho@kernel.org>
Thu, 9 Jul 2026 19:57:36 +0000 (13:57 -0600)
committerWill Deacon <will@kernel.org>
Wed, 15 Jul 2026 11:28:04 +0000 (12:28 +0100)
A couple of runs of different AI tools have generated something like the
following bug report:

    In nested_domain_free(), when refcount_dec_and_test() returns false
    (other nested domains still reference the same gdom_info), the function
    returns without calling kfree(ndom), leaking the nested_domain
    structure. This problem wasn't introduced by this patch, but exists in
    the code from commit 757d2b1fdf5b that the patch modifies. Each
    nested_domain (ndom) is allocated individually in
    amd_iommu_alloc_domain_nested() via kzalloc_obj(*ndom). The .free
    callback is the sole point responsible for freeing this domain. When
    the refcount is > 0, only the xa_unlock_irqrestore is performed and the
    function returns, leaving ndom permanently allocated. This leak occurs
    every time a nested domain sharing a gDomID is destroyed while other
    domains still use that gDomID.

There is a similar leak later in this function in the WARN_ON() test when
the mapping is already NULL. Switch to a RAII-based cleanup for ndom, since
it should always be freed in this function.

Fixes: 757d2b1fdf5b ("iommu/amd: Introduce gDomID-to-hDomID Mapping and handle parent domain invalidation")
Signed-off-by: Tycho Andersen (AMD) <tycho@kernel.org>
Reviewed-by: Ankit Soni <Ankit.Soni@amd.com>
Signed-off-by: Will Deacon <will@kernel.org>
drivers/iommu/amd/nested.c

index 5c9405223f91152b16878724f00158481e1a8ca1..63b53b29e02989118dd7447cd9a3a9829e73bef9 100644 (file)
@@ -263,7 +263,7 @@ static void nested_domain_free(struct iommu_domain *dom)
 {
        unsigned long irqflags;
        struct guest_domain_mapping_info *curr;
-       struct nested_domain *ndom = to_ndomain(dom);
+       struct nested_domain *ndom __free(kfree) = to_ndomain(dom);
        struct amd_iommu_viommu *aviommu = ndom->viommu;
 
        xa_lock_irqsave(&aviommu->gdomid_array, irqflags);
@@ -290,7 +290,6 @@ static void nested_domain_free(struct iommu_domain *dom)
 
        amd_iommu_pdom_id_free(ndom->gdom_info->hdom_id);
        kfree(curr);
-       kfree(ndom);
 }
 
 static const struct iommu_domain_ops nested_domain_ops = {