On Sun, Jan 11, 2026 at 12:56 AM Michael S. Tsirkin <[email protected]> wrote:
>
> On Fri, Jan 09, 2026 at 04:24:28PM +0100, Eugenio Pérez wrote:
> > The next patch adds new ioctl with the ASID member per entry.  Abstract
> > these two so it can be build on top easily.
> >
> > Signed-off-by: Eugenio Pérez <[email protected]>
> > ---
> > v11: New in v11
> > ---
> >  drivers/vdpa/vdpa_user/vduse_dev.c | 101 ++++++++++++++++-------------
> >  1 file changed, 55 insertions(+), 46 deletions(-)
> >
> > diff --git a/drivers/vdpa/vdpa_user/vduse_dev.c 
> > b/drivers/vdpa/vdpa_user/vduse_dev.c
> > index 675da1465e0e..bf437816fd7d 100644
> > --- a/drivers/vdpa/vdpa_user/vduse_dev.c
> > +++ b/drivers/vdpa/vdpa_user/vduse_dev.c
> > @@ -1247,6 +1247,50 @@ static void vduse_vq_update_effective_cpu(struct 
> > vduse_virtqueue *vq)
> >       vq->irq_effective_cpu = curr_cpu;
> >  }
> >
> > +static int vduse_dev_iotlb_entry(struct vduse_dev *dev,
> > +                              struct vduse_iotlb_entry *entry,
> > +                              struct file **f, uint64_t *capability)
> > +{
> > +     int r = -EINVAL;
> > +     struct vhost_iotlb_map *map;
> > +     const struct vdpa_map_file *map_file;
> > +
> > +     if (entry->start > entry->last)
> > +             return -EINVAL;
> > +
> > +     mutex_lock(&dev->domain_lock);
> > +     if (!dev->domain)
> > +             goto out;
> > +
> > +     spin_lock(&dev->domain->iotlb_lock);
> > +     map = vhost_iotlb_itree_first(dev->domain->iotlb, entry->start,
> > +                                   entry->last);
> > +     if (map) {
> > +             if (f) {
> > +                     map_file = (struct vdpa_map_file *)map->opaque;
>
> map_file assigned value when f != NULL here ...
>
> > +                     *f = get_file(map_file->file);
> > +             }
> > +             entry->offset = map_file->offset;
>
> but dereferenced unconditionally here.
>

Fixing in the next version, thanks!

> > +             entry->start = map->start;
> > +             entry->last = map->last;
> > +             entry->perm = map->perm;
> > +             if (capability) {
> > +                     *capability = 0;
> > +
> > +                     if (dev->domain->bounce_map && map->start == 0 &&
> > +                         map->last == dev->domain->bounce_size - 1)
> > +                             *capability |= VDUSE_IOVA_CAP_UMEM;
> > +             }
> > +
> > +             r = 0;
> > +     }
> > +     spin_unlock(&dev->domain->iotlb_lock);
> > +
> > +out:
> > +     mutex_unlock(&dev->domain_lock);
> > +     return r;
> > +}
> > +
> >  static long vduse_dev_ioctl(struct file *file, unsigned int cmd,
> >                           unsigned long arg)
> >  {
>


Reply via email to