From: Marek Czernohous <mczernohous@gmail.com>
To: nouveau@lists.freedesktop.org, dri-devel@lists.freedesktop.org
Cc: linux-kernel@vger.kernel.org, Danilo Krummrich <dakr@kernel.org>,
Simona Vetter <simona@ffwll.ch>
Subject: Re: [PATCH v2] drm/nouveau: disable the fence uevent work instead of just cancelling it
Date: Sun, 16 Aug 2026 15:21:52 +0200 [thread overview]
Message-ID: <178688651234.533102.4891184749713137564@gmail.com> (raw)
In-Reply-To: <178688513268.513871.3468844663561639695@gmail.com>
One correction to a trailer in this patch, before anyone picks it up.
The Closes: line points at the cover of the series the bot was reviewing:
https://lore.kernel.org/nouveau/20260812231330.705425-1-mczernohous@gmail.com/
That URL resolves, but it is the nouveau view of the thread, and the
bot's replies are not in it: that view has five messages and none of
them is the report. The bot posts to dri-devel only, so /nouveau/
returns 404 for its message-id. A tag that sends the reader somewhere
the report demonstrably is not seems worse than no tag, so it should be
Closes: https://lore.kernel.org/all/20260812233022.159301F000E9@smtp.kernel.org/
which is the report itself:
"[High] Canceling `uevent_work` before destroying `fctx->event` in
`nouveau_fence_context_del` leaves a window for use-after-free."
That also fits this version of the commit message better than the cover
link did, since the report says use-after-free and so does the patch now.
I can send a v3 with the corrected trailer if you would rather have it
right in the patch than fixed up on apply. The diff is the same one
word either way, and it did not seem worth a respin without asking.
WARNING: multiple messages have this Message-ID (diff)
From: Marek Czernohous <mczernohous@gmail.com>
To: nouveau@lists.freedesktop.org, dri-devel@lists.freedesktop.org
Cc: linux-kernel@vger.kernel.org, Danilo Krummrich <dakr@kernel.org>,
Lyude Paul <lyude@redhat.com>, David Airlie <airlied@gmail.com>,
Simona Vetter <simona@ffwll.ch>
Subject: Re: [PATCH v2] drm/nouveau: disable the fence uevent work instead of just cancelling it
Date: Sun, 16 Aug 2026 15:21:52 +0200 [thread overview]
Message-ID: <178688651234.533102.4891184749713137564@gmail.com> (raw)
In-Reply-To: <178688513268.513871.3468844663561639695@gmail.com>
One correction to a trailer in this patch, before anyone picks it up.
The Closes: line points at the cover of the series the bot was reviewing:
https://lore.kernel.org/nouveau/20260812231330.705425-1-mczernohous@gmail.com/
That URL resolves, but it is the nouveau view of the thread, and the
bot's replies are not in it: that view has five messages and none of
them is the report. The bot posts to dri-devel only, so /nouveau/
returns 404 for its message-id. A tag that sends the reader somewhere
the report demonstrably is not seems worse than no tag, so it should be
Closes: https://lore.kernel.org/all/20260812233022.159301F000E9@smtp.kernel.org/
which is the report itself:
"[High] Canceling `uevent_work` before destroying `fctx->event` in
`nouveau_fence_context_del` leaves a window for use-after-free."
That also fits this version of the commit message better than the cover
link did, since the report says use-after-free and so does the patch now.
I can send a v3 with the corrected trailer if you would rather have it
right in the patch than fixed up on apply. The diff is the same one
word either way, and it did not seem worth a respin without asking.
next prev parent reply other threads:[~2026-08-16 13:22 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-15 19:54 [PATCH 0/3] drm/nouveau: teardown ordering fixes for events and work Marek Czernohous
2026-08-15 19:54 ` Marek Czernohous
2026-08-15 19:54 ` [PATCH 3/3] drm/nouveau: don't dereference outp before checking it in nouveau_dp_irq Marek Czernohous
2026-08-15 19:54 ` Marek Czernohous
2026-08-20 18:28 ` lyude
2026-08-20 18:28 ` lyude
2026-08-15 19:54 ` [PATCH 1/3] drm/nouveau: destroy the fence event before cancelling its work Marek Czernohous
2026-08-15 19:54 ` Marek Czernohous
2026-08-15 20:09 ` sashiko-bot
2026-08-15 20:25 ` Marek Czernohous
2026-08-15 20:25 ` Marek Czernohous
2026-08-16 12:58 ` [PATCH v2] drm/nouveau: disable the fence uevent work instead of just cancelling it Marek Czernohous
2026-08-16 12:58 ` Marek Czernohous
2026-08-16 13:21 ` Marek Czernohous [this message]
2026-08-16 13:21 ` Marek Czernohous
2026-08-20 17:55 ` lyude
2026-08-20 17:55 ` lyude
2026-08-20 18:08 ` lyude
2026-08-20 18:08 ` lyude
2026-08-15 19:54 ` [PATCH 2/3] drm/nouveau: cancel the DP IRQ work before freeing the connector Marek Czernohous
2026-08-15 19:54 ` Marek Czernohous
2026-08-15 20:11 ` sashiko-bot
2026-08-15 20:42 ` Marek Czernohous
2026-08-15 20:42 ` Marek Czernohous
2026-08-20 18:26 ` lyude
2026-08-20 18:26 ` lyude
2026-08-20 18:36 ` lyude
2026-08-20 18:36 ` lyude
2026-08-20 18:13 ` lyude
2026-08-20 18:13 ` lyude
2026-08-20 18:27 ` lyude
2026-08-20 18:27 ` lyude
2026-08-18 23:58 ` [PATCH 0/3] drm/nouveau: teardown ordering fixes for events and work lyude
2026-08-18 23:58 ` lyude
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178688651234.533102.4891184749713137564@gmail.com \
--to=mczernohous@gmail.com \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nouveau@lists.freedesktop.org \
--cc=simona@ffwll.ch \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.