From: Kevin Tian <kevin.tian@intel.com> mainline inclusion from mainline-v7.3-rc1 commit 607432b2618b61df81134be0ef2562b8300c1216 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18838 CVE: CVE-2026-89448 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?i... -------------------------------- Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu(). Fix it by checking tboot in detect_intel_iommu(). Fixes: 5d990b627537 ("PCI: add pci_request_acs") Cc: stable@vger.kernel.org Signed-off-by: Kevin Tian <kevin.tian@intel.com> Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com> Signed-off-by: Joerg Roedel <joerg.roedel@amd.com> Conflicts: drivers/iommu/intel/dmar.c drivers/iommu/intel/iommu.h include/linux/intel-iommu.h [1. Context conflicts in drivers/iommu/intel/dmar.c. 2. The upstream patch stores the Intel IOMMU header at drivers/iommu/intel/iommu.h; this tree keeps it at include/linux/intel-iommu.h. Move the extern int intel_iommu_tboot_noforce declaration and the intel_iommu_tboot_noforce (0) fallback there and drop the drivers/iommu/intel/iommu.h change.] Signed-off-by: Jiacheng Yu <yujiacheng3@huawei.com> --- drivers/iommu/intel/dmar.c | 15 +++++++++++++-- drivers/iommu/intel/iommu.c | 2 +- include/linux/intel-iommu.h | 2 ++ 3 files changed, 16 insertions(+), 3 deletions(-) diff --git a/drivers/iommu/intel/dmar.c b/drivers/iommu/intel/dmar.c index fde7eb3d8103..80b997c5c0d3 100644 --- a/drivers/iommu/intel/dmar.c +++ b/drivers/iommu/intel/dmar.c @@ -919,6 +919,18 @@ dmar_validate_one_drhd(struct acpi_dmar_header *entry, void *arg) return 0; } +static bool dmar_required(void) +{ + /* tboot supersedes any user/platform opt */ + if (!intel_iommu_tboot_noforce && tboot_enabled()) + return true; + + if (!no_iommu && (!dmar_disabled || dmar_platform_optin())) + return true; + + return false; +} + int __init detect_intel_iommu(void) { int ret; @@ -932,8 +944,7 @@ int __init detect_intel_iommu(void) if (!ret) ret = dmar_walk_dmar_table((struct acpi_table_dmar *)dmar_tbl, &validate_drhd_cb); - if (!ret && !no_iommu && !iommu_detected && - (!dmar_disabled || dmar_platform_optin())) { + if (!ret && !iommu_detected && dmar_required()) { iommu_detected = 1; /* Make sure ACS will be enabled */ pci_request_acs(); diff --git a/drivers/iommu/intel/iommu.c b/drivers/iommu/intel/iommu.c index 245fef1026c3..c8889eccf3bf 100644 --- a/drivers/iommu/intel/iommu.c +++ b/drivers/iommu/intel/iommu.c @@ -179,7 +179,7 @@ static int rwbf_quirk; * (used when kernel is launched w/ TXT) */ static int force_on = 0; -static int intel_iommu_tboot_noforce; +int intel_iommu_tboot_noforce; static int no_platform_optin; #define ROOT_ENTRY_NR (VTD_PAGE_SIZE/sizeof(struct root_entry)) diff --git a/include/linux/intel-iommu.h b/include/linux/intel-iommu.h index a05221cb9e11..454094815d88 100644 --- a/include/linux/intel-iommu.h +++ b/include/linux/intel-iommu.h @@ -811,6 +811,7 @@ extern int iommu_calculate_max_sagaw(struct intel_iommu *iommu); extern int dmar_disabled; extern int intel_iommu_enabled; extern int intel_iommu_gfx_mapped; +extern int intel_iommu_tboot_noforce; #else static inline int iommu_calculate_agaw(struct intel_iommu *iommu) { @@ -822,6 +823,7 @@ static inline int iommu_calculate_max_sagaw(struct intel_iommu *iommu) } #define dmar_disabled (1) #define intel_iommu_enabled (0) +#define intel_iommu_tboot_noforce (0) #endif #endif -- 2.34.1