[PATCH openEuler-1.0-LTS] [Backport] iommu/vt-d: Force requesting ACS when tboot is enabled
From: Kevin Tian <kevin.tian@intel.com> mainline inclusion from mainline-v7.3-rc1 commit 607432b2618b61df81134be0ef2562b8300c1216 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18838 CVE: CVE-2026-89448 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?i... -------------------------------- Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu(). Fix it by checking tboot in detect_intel_iommu(). Fixes: 5d990b627537 ("PCI: add pci_request_acs") Cc: stable@vger.kernel.org Signed-off-by: Kevin Tian <kevin.tian@intel.com> Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com> Signed-off-by: Joerg Roedel <joerg.roedel@amd.com> Conflicts: drivers/iommu/intel/dmar.c drivers/iommu/dmar.c drivers/iommu/intel/iommu.c drivers/iommu/intel/iommu.h include/linux/dma_remapping.h [1. The upstream patch lives under drivers/iommu/intel/; this tree keeps the Intel IOMMU code at drivers/iommu/dmar.c and drivers/iommu/intel-iommu.c. 2. This tree has no dmar_platform_optin() in the detect_intel_iommu() condition, so dmar_required() keeps only the !dmar_disabled check to preserve the original behavior. 3. intel_iommu_tboot_noforce is already non-static in intel-iommu.c, so the drivers/iommu/intel/iommu.c change is dropped. 4. The extern int intel_iommu_tboot_noforce and the intel_iommu_tboot_noforce (0) fallback live in include/linux/dma_remapping.h instead of the upstream Intel IOMMU header.] Signed-off-by: Jiacheng Yu <yujiacheng3@huawei.com> --- drivers/iommu/dmar.c | 14 +++++++++++++- include/linux/dma_remapping.h | 1 + 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/drivers/iommu/dmar.c b/drivers/iommu/dmar.c index 6d608f71867c..27fdd4f220db 100644 --- a/drivers/iommu/dmar.c +++ b/drivers/iommu/dmar.c @@ -898,6 +898,18 @@ dmar_validate_one_drhd(struct acpi_dmar_header *entry, void *arg) return 0; } +static bool dmar_required(void) +{ + /* tboot supersedes any user/platform opt */ + if (!intel_iommu_tboot_noforce && tboot_enabled()) + return true; + + if (!no_iommu && !dmar_disabled) + return true; + + return false; +} + int __init detect_intel_iommu(void) { int ret; @@ -911,7 +923,7 @@ int __init detect_intel_iommu(void) if (!ret) ret = dmar_walk_dmar_table((struct acpi_table_dmar *)dmar_tbl, &validate_drhd_cb); - if (!ret && !no_iommu && !iommu_detected && !dmar_disabled) { + if (!ret && !iommu_detected && dmar_required()) { iommu_detected = 1; /* Make sure ACS will be enabled */ pci_request_acs(); diff --git a/include/linux/dma_remapping.h b/include/linux/dma_remapping.h index 21b3e7d33d68..5ce02d0f4688 100644 --- a/include/linux/dma_remapping.h +++ b/include/linux/dma_remapping.h @@ -52,6 +52,7 @@ static inline int iommu_calculate_max_sagaw(struct intel_iommu *iommu) } #define dmar_disabled (1) #define intel_iommu_enabled (0) +#define intel_iommu_tboot_noforce (0) #endif -- 2.34.1
反馈: 您发送到kernel@openeuler.org的补丁/补丁集,已成功转换为PR! PR链接地址: https://gitcode.com/openeuler/kernel/merge_requests/29420 邮件列表地址:https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/message/MJB... FeedBack: The patch(es) which you have sent to kernel@openeuler.org mailing list has been converted to a pull request successfully! Pull request link: https://gitcode.com/openeuler/kernel/merge_requests/29420 Mailing list address: https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/message/MJB...
participants (2)
-
Jiacheng Yu -
patchwork bot