All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] dma-buf/sync_file: Always increment refcount when merging fences.
@ 2016-09-13 23:24 Rafael Antognolli
  2016-09-13 23:41 ` Gustavo Padovan
  2016-09-14 10:05 ` Chris Wilson
  0 siblings, 2 replies; 8+ messages in thread
From: Rafael Antognolli @ 2016-09-13 23:24 UTC (permalink / raw)
  To: dri-devel; +Cc: gustavo.padovan

The refcount of a fence should be increased whenever it is added to a merged
fence, since it will later be decreased when the merged fence is destroyed.
Failing to do so will cause the original fence to be freed if the merged fence
gets freed, but other places still referencing won't know about it.

This patch fixes a kernel panic that can be triggered by creating a fence that
is expired (or increasing the timeline until it expires), then creating a
merged fence out of it, and deleting the merged fence. This will make the
original expired fence's refcount go to zero.

Signed-off-by: Rafael Antognolli <rafael.antognolli@intel.com>
---

Sample code to trigger the mentioned kernel panic (might need to be executed a
couple times before it actually breaks everything):

static void test_sync_expired_merge(void)
{
       int iterations = 1 << 20;
       int timeline;
       int i;
       int fence_expired, fence_merged;

       timeline = sw_sync_timeline_create();

       sw_sync_timeline_inc(timeline, 100);
       fence_expired = sw_sync_fence_create(timeline, 1);
       fence_merged = sw_sync_merge(fence_expired, fence_expired);
       sw_sync_fence_destroy(fence_merged);

       for (i = 0; i < iterations; i++) {
               int fence = sw_sync_merge(fence_expired, fence_expired);

               igt_assert_f(sw_sync_wait(fence, -1) > 0,
                                    "Failure waiting on fence\n");
               sw_sync_fence_destroy(fence);
       }

       sw_sync_fence_destroy(fence_expired);
}

 drivers/dma-buf/sync_file.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/drivers/dma-buf/sync_file.c b/drivers/dma-buf/sync_file.c
index 486d29c..6ce6b8f 100644
--- a/drivers/dma-buf/sync_file.c
+++ b/drivers/dma-buf/sync_file.c
@@ -178,11 +178,8 @@ static struct fence **get_fences(struct sync_file *sync_file, int *num_fences)
 static void add_fence(struct fence **fences, int *i, struct fence *fence)
 {
 	fences[*i] = fence;
-
-	if (!fence_is_signaled(fence)) {
-		fence_get(fence);
-		(*i)++;
-	}
+	fence_get(fence);
+	(*i)++;
 }
 
 /**
-- 
2.7.4

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply related	[flat|nested] 8+ messages in thread
* [PATCH] dma-buf/sync_file: Always increment refcount when merging fences.
@ 2016-09-13 23:19 Rafael Antognolli
  0 siblings, 0 replies; 8+ messages in thread
From: Rafael Antognolli @ 2016-09-13 23:19 UTC (permalink / raw)
  To: intel-gfx; +Cc: gustavo.padovan

The refcount of a fence should be increased whenever it is added to a merged
fence, since it will later be decreased when the merged fence is destroyed.
Failing to do so will cause the original fence to be freed if the merged fence
gets freed, but other places still referencing won't know about it.

This patch fixes a kernel panic that can be triggered by creating a fence that
is expired (or increasing the timeline until it expires), then creating a
merged fence out of it, and deleting the merged fence. This will make the
original expired fence's refcount go to zero.

Signed-off-by: Rafael Antognolli <rafael.antognolli@intel.com>
---

Sample code to trigger the mentioned kernel panic (might need to be executed a
couple times before it actually breaks everything):

static void test_sync_expired_merge(void)
{
       int iterations = 1 << 20;
       int timeline;
       int i;
       int fence_expired, fence_merged;

       timeline = sw_sync_timeline_create();

       sw_sync_timeline_inc(timeline, 100);
       fence_expired = sw_sync_fence_create(timeline, 1);
       fence_merged = sw_sync_merge(fence_expired, fence_expired);
       sw_sync_fence_destroy(fence_merged);

       for (i = 0; i < iterations; i++) {
               int fence = sw_sync_merge(fence_expired, fence_expired);

               igt_assert_f(sw_sync_wait(fence, -1) > 0,
                                    "Failure waiting on fence\n");
               sw_sync_fence_destroy(fence);
       }

       sw_sync_fence_destroy(fence_expired);
}

 drivers/dma-buf/sync_file.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/drivers/dma-buf/sync_file.c b/drivers/dma-buf/sync_file.c
index 486d29c..6ce6b8f 100644
--- a/drivers/dma-buf/sync_file.c
+++ b/drivers/dma-buf/sync_file.c
@@ -178,11 +178,8 @@ static struct fence **get_fences(struct sync_file *sync_file, int *num_fences)
 static void add_fence(struct fence **fences, int *i, struct fence *fence)
 {
 	fences[*i] = fence;
-
-	if (!fence_is_signaled(fence)) {
-		fence_get(fence);
-		(*i)++;
-	}
+	fence_get(fence);
+	(*i)++;
 }
 
 /**
-- 
2.7.4

_______________________________________________
Intel-gfx mailing list
Intel-gfx@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/intel-gfx

^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2016-09-14 17:57 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-09-13 23:24 [PATCH] dma-buf/sync_file: Always increment refcount when merging fences Rafael Antognolli
2016-09-13 23:41 ` Gustavo Padovan
2016-09-14 10:05 ` Chris Wilson
2016-09-14 14:04   ` Gustavo Padovan
2016-09-14 15:45     ` Rafael Antognolli
2016-09-14 16:38       ` Gustavo Padovan
2016-09-14 17:57     ` Chris Wilson
  -- strict thread matches above, loose matches on Subject: below --
2016-09-13 23:19 Rafael Antognolli

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.