mirror of
https://github.com/raspberrypi/linux.git
synced 2025-12-06 18:09:56 +00:00
vfio: Fix container device registration life cycle
In vfio_device_open(), vfio_device_container_register() is always called
when open_count == 1. On error, vfio_device_container_unregister() is
only called when open_count == 1 and close_device is set. This leaks a
registration for devices without a close_device implementation.
In vfio_device_fops_release(), vfio_device_container_unregister() is
called unconditionally. This can cause a device to be unregistered
multiple times.
Treating container device registration/unregistration uniformly (always
when open_count == 1) fixes both issues.
Fixes: ce4b4657ff ("vfio: Replace the DMA unmapping notifier with a callback")
Signed-off-by: Anthony DeRossi <ajderossi@gmail.com>
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Reviewed-by: Yi Liu <yi.l.liu@intel.com>
Link: https://lore.kernel.org/r/20221110014027.28780-2-ajderossi@gmail.com
Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
This commit is contained in:
committed by
Alex Williamson
parent
f0c4d9fc9c
commit
7fdba00111
@@ -801,7 +801,8 @@ static struct file *vfio_device_open(struct vfio_device *device)
|
|||||||
err_close_device:
|
err_close_device:
|
||||||
mutex_lock(&device->dev_set->lock);
|
mutex_lock(&device->dev_set->lock);
|
||||||
mutex_lock(&device->group->group_lock);
|
mutex_lock(&device->group->group_lock);
|
||||||
if (device->open_count == 1 && device->ops->close_device) {
|
if (device->open_count == 1) {
|
||||||
|
if (device->ops->close_device)
|
||||||
device->ops->close_device(device);
|
device->ops->close_device(device);
|
||||||
|
|
||||||
vfio_device_container_unregister(device);
|
vfio_device_container_unregister(device);
|
||||||
@@ -1017,10 +1018,12 @@ static int vfio_device_fops_release(struct inode *inode, struct file *filep)
|
|||||||
mutex_lock(&device->dev_set->lock);
|
mutex_lock(&device->dev_set->lock);
|
||||||
vfio_assert_device_open(device);
|
vfio_assert_device_open(device);
|
||||||
mutex_lock(&device->group->group_lock);
|
mutex_lock(&device->group->group_lock);
|
||||||
if (device->open_count == 1 && device->ops->close_device)
|
if (device->open_count == 1) {
|
||||||
|
if (device->ops->close_device)
|
||||||
device->ops->close_device(device);
|
device->ops->close_device(device);
|
||||||
|
|
||||||
vfio_device_container_unregister(device);
|
vfio_device_container_unregister(device);
|
||||||
|
}
|
||||||
mutex_unlock(&device->group->group_lock);
|
mutex_unlock(&device->group->group_lock);
|
||||||
device->open_count--;
|
device->open_count--;
|
||||||
if (device->open_count == 0)
|
if (device->open_count == 0)
|
||||||
|
|||||||
Reference in New Issue
Block a user