On Fri, 4 Nov 2022 15:27:13 -0600 Alex Williamson <alex.williamson@xxxxxxxxxx> wrote: > On Tue, 25 Oct 2022 15:12:09 -0300 > Jason Gunthorpe <jgg@xxxxxxxxxx> wrote: > > > [ > > At this point everything is done and I will start putting this work into a > > git tree and into linux-next with the intention of sending it during the > > next merge window. > > > > I intend to focus the next several weeks on more intensive QA to look at > > error flows and other things. Hopefully including syzkaller if I'm lucky > > ] > > In case this one hasn't been reported yet (with IOMMUFD_VFIO_CONTAINER): And... ------------[ cut here ]------------ WARNING: CPU: 4 PID: 1736 at drivers/iommu/iommufd/io_pagetable.c:660 iopt_destroy_table+0x91/0xc0 [iommufd] Modules linked in: scsi_transport_iscsi(E) xt_CHECKSUM(E) xt_MASQUERADE(E) xt_conntrack(E) ipt_REJECT(E) nf_nat_tftp(E) nft_objref(E) nf_conntrack_tftp(E) nft_fib_inet(E) nft_fib_ipv4(E) nft_fib_ipv6(E) nft_fib(E) nft_reject_inet(E) nf_reject_ipv4(E) nf_reject_ipv6(E) nft_reject(E) nft_ct(E) nft_chain_nat(E) nf_tables(E) bridge(E) stp(E) llc(E) ebtable_nat(E) ebtable_broute(E) ip6table_nat(E) ip6table_mangle(E) ip6table_raw(E) ip6table_security(E) iptable_nat(E) nf_nat(E) nf_conntrack(E) nf_defrag_ipv6(E) nf_defrag_ipv4(E) iptable_mangle(E) iptable_raw(E) iptable_security(E) ip_set(E) nfnetlink(E) ebtable_filter(E) ebtables(E) ip6table_filter(E) ip6_tables(E) iptable_filter(E) sunrpc(E) intel_rapl_msr(E) intel_rapl_common(E) x86_pkg_temp_thermal(E) intel_powerclamp(E) coretemp(E) snd_hda_intel(E) snd_intel_dspcfg(E) kvm_intel(E) snd_hda_codec(E) snd_hwdep(E) bcache(E) iTCO_wdt(E) snd_hda_core(E) kvm(E) mei_hdcp(E) intel_pmc_bxt(E) at24(E) snd_seq(E) iTCO_vendor_support(E) eeepc_wmi(E) snd_seq_device(E) asus_wmi(E) rapl(E) snd_pcm(E) ledtrig_audio(E) intel_cstate(E) sparse_keymap(E) intel_uncore(E) mei_me(E) snd_timer(E) platform_profile(E) i2c_i801(E) rfkill(E) wmi_bmof(E) snd(E) i2c_smbus(E) soundcore(E) mei(E) lpc_ich(E) ip_tables(E) i915(E) crct10dif_pclmul(E) crc32_pclmul(E) crc32c_intel(E) ghash_clmulni_intel(E) vfio_pci(E) vfio_pci_core(E) irqbypass(E) vfio_virqfd(E) serio_raw(E) i2c_algo_bit(E) drm_buddy(E) drm_display_helper(E) drm_kms_helper(E) cec(E) ttm(E) r8169(E) e1000e(E) drm(E) video(E) wmi(E) mtty(E) mdev(E) vfio(E) iommufd(E) macvtap(E) macvlan(E) tap(E) CPU: 4 PID: 1736 Comm: qemu-system-x86 Tainted: G E 6.1.0-rc3+ #133 Hardware name: System manufacturer System Product Name/P8H67-M PRO, BIOS 3904 04/27/2013 RIP: 0010:iopt_destroy_table+0x91/0xc0 [iommufd] Code: a8 01 00 00 48 85 c0 75 21 49 83 bc 24 e0 00 00 00 00 75 23 49 8b 84 24 88 01 00 00 48 85 c0 75 25 5b 5d 41 5c c3 cc cc cc cc <0f> 0b 49 83 bc 24 e0 00 00 00 00 74 dd 0f 0b 49 8b 84 24 88 01 00 RSP: 0018:ffff9c8dc1c63cb0 EFLAGS: 00010282 RAX: ffff90d454863a80 RBX: ffff90d3f5fe3e40 RCX: 0000000000000000 RDX: ffffffffffffffff RSI: 0000000000000000 RDI: ffff90d3f5fe3e40 RBP: 0000000000000000 R08: 0000000000000001 R09: ffff90d43234b240 R10: 0000000000000000 R11: ffff90d42c703000 R12: ffff90d3f5fe3ca8 R13: 0000000000000001 R14: ffff90d43ca32138 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff90d7df700000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f3fba3c6000 CR3: 000000009ba26005 CR4: 00000000001726e0 Call Trace: <TASK> iommufd_ioas_destroy+0x2b/0x60 [iommufd] iommufd_fops_release+0x8b/0xe0 [iommufd] __fput+0x94/0x250 task_work_run+0x59/0x90 do_exit+0x374/0xbd0 ? rcu_read_lock_sched_held+0x12/0x70 do_group_exit+0x33/0xa0 get_signal+0xaf4/0xb20 arch_do_signal_or_restart+0x36/0x780 ? do_futex+0x126/0x1c0 exit_to_user_mode_prepare+0x181/0x260 syscall_exit_to_user_mode+0x16/0x50 do_syscall_64+0x48/0x90 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7fd1ef7a3750 Code: Unable to access opcode bytes at 0x7fd1ef7a3726. RSP: 002b:00007fd1e21fb5d8 EFLAGS: 00000282 ORIG_RAX: 00000000000000ca RAX: fffffffffffffe00 RBX: 0000000000000000 RCX: 00007fd1ef7a3750 RDX: 0000000000000002 RSI: 0000000000000080 RDI: 00005571b8cf38c0 RBP: 00007fd1e21fb630 R08: 0000000000000000 R09: 000000000000000b R10: 0000000000000000 R11: 0000000000000282 R12: 00007ffd9787d1ae R13: 00007ffd9787d1af R14: 00007ffd9787d270 R15: 00007fd1e2200700 </TASK> irq event stamp: 202 hardirqs last enabled at (201): [<ffffffffa7e235a2>] syscall_enter_from_user_mode+0x22/0xb0 hardirqs last disabled at (202): [<ffffffffa7e2da5d>] __schedule+0x7ed/0xd30 softirqs last enabled at (0): [<ffffffffa70e2241>] copy_process+0x9f1/0x1e90 softirqs last disabled at (0): [<0000000000000000>] 0x0 ---[ end trace 0000000000000000 ]---