From: Jason Gunthorpe <jgg@nvidia.com> To: unlisted-recipients:; (no To-header on input) Cc: Anthony Krowiak <akrowiak@linux.ibm.com>, Alex Williamson <alex.williamson@redhat.com>, Bagas Sanjaya <bagasdotme@gmail.com>, Lu Baolu <baolu.lu@linux.intel.com>, Chaitanya Kulkarni <chaitanyak@nvidia.com>, Cornelia Huck <cohuck@redhat.com>, Jonathan Corbet <corbet@lwn.net>, Daniel Jordan <daniel.m.jordan@oracle.com>, David Gibson <david@gibson.dropbear.id.au>, Eric Auger <eric.auger@redhat.com>, Eric Farman <farman@linux.ibm.com>, iommu@lists.linux.dev, Jason Wang <jasowang@redhat.com>, Jean-Philippe Brucker <jean-philippe@linaro.org>, Jason Herne <jjherne@linux.ibm.com>, Joao Martins <joao.m.martins@oracle.com>, Kevin Tian <kevin.tian@intel.com>, kvm@vger.kernel.org, Lixiao Yang <lixiao.yang@intel.com>, Matthew Rosato <mjrosato@linux.ibm.com>, "Michael S. Tsirkin" <mst@redhat.com>, Nicolin Chen <nicolinc@nvidia.com>, Halil Pasic <pasic@linux.ibm.com>, Niklas Schnelle <schnelle@linux.ibm.com>, Shameerali Kolothum Thodi <shameerali.kolothum.thodi@huawei.com>, Yi Liu <yi.l.liu@intel.com>, Yu He <yu.he@intel.com>, Keqian Zhu <zhukeqian1@huawei.com> Subject: [PATCH v6 17/19] iommufd: Add some fault injection points Date: Tue, 29 Nov 2022 16:29:40 -0400 [thread overview] Message-ID: <17-v6-a196d26f289e+11787-iommufd_jgg@nvidia.com> (raw) In-Reply-To: <0-v6-a196d26f289e+11787-iommufd_jgg@nvidia.com> This increases the coverage the fail_nth test gets, as well as via syzkaller. Tested-by: Matthew Rosato <mjrosato@linux.ibm.com> # s390 Signed-off-by: Jason Gunthorpe <jgg@nvidia.com> --- drivers/iommu/iommufd/main.c | 3 +++ drivers/iommu/iommufd/pages.c | 26 ++++++++++++++++++++++++++ 2 files changed, 29 insertions(+) diff --git a/drivers/iommu/iommufd/main.c b/drivers/iommu/iommufd/main.c index 7c8f40bc8d98d5..bcb463e581009c 100644 --- a/drivers/iommu/iommufd/main.c +++ b/drivers/iommu/iommufd/main.c @@ -102,6 +102,9 @@ struct iommufd_object *iommufd_get_object(struct iommufd_ctx *ictx, u32 id, { struct iommufd_object *obj; + if (iommufd_should_fail()) + return ERR_PTR(-ENOENT); + xa_lock(&ictx->objects); obj = xa_load(&ictx->objects, id); if (!obj || (type != IOMMUFD_OBJ_ANY && obj->type != type) || diff --git a/drivers/iommu/iommufd/pages.c b/drivers/iommu/iommufd/pages.c index 640331b8a07919..c5d2d9a8c56203 100644 --- a/drivers/iommu/iommufd/pages.c +++ b/drivers/iommu/iommufd/pages.c @@ -80,6 +80,10 @@ static void *temp_kmalloc(size_t *size, void *backup, size_t backup_len) if (*size < backup_len) return backup; + + if (!backup && iommufd_should_fail()) + return NULL; + *size = min_t(size_t, *size, TEMP_MEMORY_LIMIT); res = kmalloc(*size, GFP_KERNEL | __GFP_NOWARN | __GFP_NORETRY); if (res) @@ -544,6 +548,7 @@ static int pages_to_xarray(struct xarray *xa, unsigned long start_index, unsigned long last_index, struct page **pages) { struct page **end_pages = pages + (last_index - start_index) + 1; + struct page **half_pages = pages + (end_pages - pages) / 2; XA_STATE(xas, xa, start_index); do { @@ -551,6 +556,15 @@ static int pages_to_xarray(struct xarray *xa, unsigned long start_index, xas_lock(&xas); while (pages != end_pages) { + /* xarray does not participate in fault injection */ + if (pages == half_pages && iommufd_should_fail()) { + xas_set_err(&xas, -EINVAL); + xas_unlock(&xas); + /* aka xas_destroy() */ + xas_nomem(&xas, GFP_KERNEL); + goto err_clear; + } + old = xas_store(&xas, xa_mk_value(page_to_pfn(*pages))); if (xas_error(&xas)) break; @@ -561,6 +575,7 @@ static int pages_to_xarray(struct xarray *xa, unsigned long start_index, xas_unlock(&xas); } while (xas_nomem(&xas, GFP_KERNEL)); +err_clear: if (xas_error(&xas)) { if (xas.xa_index != start_index) clear_xarray(xa, start_index, xas.xa_index - 1); @@ -728,6 +743,10 @@ static int pfn_reader_user_pin(struct pfn_reader_user *user, npages = min_t(unsigned long, last_index - start_index + 1, user->upages_len / sizeof(*user->upages)); + + if (iommufd_should_fail()) + return -EFAULT; + uptr = (uintptr_t)(pages->uptr + start_index * PAGE_SIZE); if (!remote_mm) rc = pin_user_pages_fast(uptr, npages, user->gup_flags, @@ -872,6 +891,8 @@ static int pfn_reader_user_update_pinned(struct pfn_reader_user *user, npages = pages->last_npinned - pages->npinned; inc = false; } else { + if (iommufd_should_fail()) + return -ENOMEM; npages = pages->npinned - pages->last_npinned; inc = true; } @@ -1721,6 +1742,11 @@ static int iopt_pages_rw_page(struct iopt_pages *pages, unsigned long index, return iopt_pages_rw_slow(pages, index, index, offset, data, length, flags); + if (iommufd_should_fail()) { + rc = -EINVAL; + goto out_mmput; + } + mmap_read_lock(pages->source_mm); rc = pin_user_pages_remote( pages->source_mm, (uintptr_t)(pages->uptr + index * PAGE_SIZE), -- 2.38.1
WARNING: multiple messages have this Message-ID (diff)
From: Jason Gunthorpe <jgg@nvidia.com> Cc: Anthony Krowiak <akrowiak@linux.ibm.com>, Alex Williamson <alex.williamson@redhat.com>, Bagas Sanjaya <bagasdotme@gmail.com>, Lu Baolu <baolu.lu@linux.intel.com>, Chaitanya Kulkarni <chaitanyak@nvidia.com>, Cornelia Huck <cohuck@redhat.com>, Jonathan Corbet <corbet@lwn.net>, Daniel Jordan <daniel.m.jordan@oracle.com>, David Gibson <david@gibson.dropbear.id.au>, Eric Auger <eric.auger@redhat.com>, Eric Farman <farman@linux.ibm.com>, iommu@lists.linux.dev, Jason Wang <jasowang@redhat.com>, Jean-Philippe Brucker <jean-philippe@linaro.org>, Jason Herne <jjherne@linux.ibm.com>, Joao Martins <joao.m.martins@oracle.com>, Kevin Tian <kevin.tian@intel.com>, kvm@vger.kernel.org, Lixiao Yang <lixiao.yang@intel.com>, Matthew Rosato <mjrosato@linux.ibm.com>, "Michael S. Tsirkin" <mst@redhat.com>, Nicolin Chen <nicolinc@nvidia.com>, Halil Pasic <pasic@linux.ibm.com>, Niklas Schnelle <schnelle@linux.ibm.com>, Shameerali Kolothum Thodi <shameerali.kolothum.thodi@huawei.com>, Yi Liu <yi.l.liu@intel.com>, Yu He <yu.he@intel.com>, Keqian Zhu <zhukeqian1@huawei.com> Subject: [PATCH v6 17/19] iommufd: Add some fault injection points Date: Tue, 29 Nov 2022 16:29:40 -0400 [thread overview] Message-ID: <17-v6-a196d26f289e+11787-iommufd_jgg@nvidia.com> (raw) In-Reply-To: <0-v6-a196d26f289e+11787-iommufd_jgg@nvidia.com> This increases the coverage the fail_nth test gets, as well as via syzkaller. Tested-by: Matthew Rosato <mjrosato@linux.ibm.com> # s390 Signed-off-by: Jason Gunthorpe <jgg@nvidia.com> --- drivers/iommu/iommufd/main.c | 3 +++ drivers/iommu/iommufd/pages.c | 26 ++++++++++++++++++++++++++ 2 files changed, 29 insertions(+) diff --git a/drivers/iommu/iommufd/main.c b/drivers/iommu/iommufd/main.c index 7c8f40bc8d98d5..bcb463e581009c 100644 --- a/drivers/iommu/iommufd/main.c +++ b/drivers/iommu/iommufd/main.c @@ -102,6 +102,9 @@ struct iommufd_object *iommufd_get_object(struct iommufd_ctx *ictx, u32 id, { struct iommufd_object *obj; + if (iommufd_should_fail()) + return ERR_PTR(-ENOENT); + xa_lock(&ictx->objects); obj = xa_load(&ictx->objects, id); if (!obj || (type != IOMMUFD_OBJ_ANY && obj->type != type) || diff --git a/drivers/iommu/iommufd/pages.c b/drivers/iommu/iommufd/pages.c index 640331b8a07919..c5d2d9a8c56203 100644 --- a/drivers/iommu/iommufd/pages.c +++ b/drivers/iommu/iommufd/pages.c @@ -80,6 +80,10 @@ static void *temp_kmalloc(size_t *size, void *backup, size_t backup_len) if (*size < backup_len) return backup; + + if (!backup && iommufd_should_fail()) + return NULL; + *size = min_t(size_t, *size, TEMP_MEMORY_LIMIT); res = kmalloc(*size, GFP_KERNEL | __GFP_NOWARN | __GFP_NORETRY); if (res) @@ -544,6 +548,7 @@ static int pages_to_xarray(struct xarray *xa, unsigned long start_index, unsigned long last_index, struct page **pages) { struct page **end_pages = pages + (last_index - start_index) + 1; + struct page **half_pages = pages + (end_pages - pages) / 2; XA_STATE(xas, xa, start_index); do { @@ -551,6 +556,15 @@ static int pages_to_xarray(struct xarray *xa, unsigned long start_index, xas_lock(&xas); while (pages != end_pages) { + /* xarray does not participate in fault injection */ + if (pages == half_pages && iommufd_should_fail()) { + xas_set_err(&xas, -EINVAL); + xas_unlock(&xas); + /* aka xas_destroy() */ + xas_nomem(&xas, GFP_KERNEL); + goto err_clear; + } + old = xas_store(&xas, xa_mk_value(page_to_pfn(*pages))); if (xas_error(&xas)) break; @@ -561,6 +575,7 @@ static int pages_to_xarray(struct xarray *xa, unsigned long start_index, xas_unlock(&xas); } while (xas_nomem(&xas, GFP_KERNEL)); +err_clear: if (xas_error(&xas)) { if (xas.xa_index != start_index) clear_xarray(xa, start_index, xas.xa_index - 1); @@ -728,6 +743,10 @@ static int pfn_reader_user_pin(struct pfn_reader_user *user, npages = min_t(unsigned long, last_index - start_index + 1, user->upages_len / sizeof(*user->upages)); + + if (iommufd_should_fail()) + return -EFAULT; + uptr = (uintptr_t)(pages->uptr + start_index * PAGE_SIZE); if (!remote_mm) rc = pin_user_pages_fast(uptr, npages, user->gup_flags, @@ -872,6 +891,8 @@ static int pfn_reader_user_update_pinned(struct pfn_reader_user *user, npages = pages->last_npinned - pages->npinned; inc = false; } else { + if (iommufd_should_fail()) + return -ENOMEM; npages = pages->npinned - pages->last_npinned; inc = true; } @@ -1721,6 +1742,11 @@ static int iopt_pages_rw_page(struct iopt_pages *pages, unsigned long index, return iopt_pages_rw_slow(pages, index, index, offset, data, length, flags); + if (iommufd_should_fail()) { + rc = -EINVAL; + goto out_mmput; + } + mmap_read_lock(pages->source_mm); rc = pin_user_pages_remote( pages->source_mm, (uintptr_t)(pages->uptr + index * PAGE_SIZE), -- 2.38.1
next prev parent reply other threads:[~2022-11-29 20:30 UTC|newest] Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top 2022-11-29 20:29 [PATCH v6 00/19] IOMMUFD Generic interface Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 01/19] iommu: Add IOMMU_CAP_ENFORCE_CACHE_COHERENCY Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 02/19] iommu: Add device-centric DMA ownership interfaces Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 03/19] interval-tree: Add a utility to iterate over spans in an interval tree Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 04/19] scripts/kernel-doc: support EXPORT_SYMBOL_NS_GPL() with -export Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 05/19] iommufd: Document overview of iommufd Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 06/19] iommufd: File descriptor, context, kconfig and makefiles Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-30 14:02 ` Eric Auger 2022-12-04 10:58 ` Binbin Wu 2022-11-29 20:29 ` [PATCH v6 07/19] kernel/user: Allow user::locked_vm to be usable for iommufd Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:42 ` Michael S. Tsirkin 2022-11-29 20:48 ` Jason Gunthorpe 2022-11-29 21:10 ` Michael S. Tsirkin 2022-11-29 20:29 ` [PATCH v6 08/19] iommufd: PFN handling for iopt_pages Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-12-05 15:58 ` Binbin Wu 2022-12-06 20:53 ` Jason Gunthorpe 2022-12-06 12:36 ` Binbin Wu 2022-12-06 20:57 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 09/19] iommufd: Algorithms for PFN storage Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 10/19] iommufd: Data structure to provide IOVA to PFN mapping Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 11/19] iommufd: IOCTLs for the io_pagetable Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-30 14:04 ` Eric Auger 2022-11-29 20:29 ` [PATCH v6 12/19] iommufd: Add a HW pagetable object Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 13/19] iommufd: Add kAPI toward external drivers for physical devices Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 14/19] iommufd: Add kAPI toward external drivers for kernel access Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 15/19] iommufd: vfio container FD ioctl compatibility Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 16/19] iommufd: Add kernel support for testing iommufd Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2024-04-22 7:27 ` Geert Uytterhoeven 2024-04-22 11:54 ` Jason Gunthorpe 2024-04-22 12:48 ` Geert Uytterhoeven 2024-04-22 12:50 ` Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe [this message] 2022-11-29 20:29 ` [PATCH v6 17/19] iommufd: Add some fault injection points Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 18/19] iommufd: Add additional invariant assertions Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-29 20:29 ` [PATCH v6 19/19] iommufd: Add a selftest Jason Gunthorpe 2022-11-29 20:29 ` Jason Gunthorpe 2022-11-30 7:14 ` Yi Liu 2022-11-30 13:51 ` Jason Gunthorpe 2022-11-30 17:18 ` Eric Auger 2022-12-01 0:13 ` Jason Gunthorpe 2022-12-01 4:59 ` Yi Liu
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=17-v6-a196d26f289e+11787-iommufd_jgg@nvidia.com \ --to=jgg@nvidia.com \ --cc=akrowiak@linux.ibm.com \ --cc=alex.williamson@redhat.com \ --cc=bagasdotme@gmail.com \ --cc=baolu.lu@linux.intel.com \ --cc=chaitanyak@nvidia.com \ --cc=cohuck@redhat.com \ --cc=corbet@lwn.net \ --cc=daniel.m.jordan@oracle.com \ --cc=david@gibson.dropbear.id.au \ --cc=eric.auger@redhat.com \ --cc=farman@linux.ibm.com \ --cc=iommu@lists.linux.dev \ --cc=jasowang@redhat.com \ --cc=jean-philippe@linaro.org \ --cc=jjherne@linux.ibm.com \ --cc=joao.m.martins@oracle.com \ --cc=kevin.tian@intel.com \ --cc=kvm@vger.kernel.org \ --cc=lixiao.yang@intel.com \ --cc=mjrosato@linux.ibm.com \ --cc=mst@redhat.com \ --cc=nicolinc@nvidia.com \ --cc=pasic@linux.ibm.com \ --cc=schnelle@linux.ibm.com \ --cc=shameerali.kolothum.thodi@huawei.com \ --cc=yi.l.liu@intel.com \ --cc=yu.he@intel.com \ --cc=zhukeqian1@huawei.com \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.