All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rob Clark" <robin.clark@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 04/17] drm/msm: Synchronize set_sysprof on ctxlock
Date: Wed, 29 Jul 2026 16:12:49 +0000	[thread overview]
Message-ID: <20260729161249.906E71F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260729155609.20190-5-robin.clark@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Direct access to uninitialized `ctx->vm` allows userspace to enable VM_BIND on hardware lacking per-process page tables.
--

--- Patch [4]: [PATCH v7 04/17] drm/msm: Synchronize set_sysprof on ctxlock ---
commit 80ad21c966f9ce52663d9bf52f28781c4e97e7e0
Author: Rob Clark <robin.clark@oss.qualcomm.com>

drm/msm: Synchronize set_sysprof on ctxlock

A user that was perfmon_capable() could try to race setting SYSPROF
param on multiple threads to trigger a reference leak.

> diff --git a/drivers/gpu/drm/msm/msm_submitqueue.c b/drivers/gpu/drm/msm/msm_submitqueue.c
> index 8b5980d5a6a79..233c4f35ab121 100644
> --- a/drivers/gpu/drm/msm/msm_submitqueue.c
> +++ b/drivers/gpu/drm/msm/msm_submitqueue.c
> @@ -9,6 +9,8 @@
>  
>  int msm_context_set_sysprof(struct msm_context *ctx, struct msm_gpu *gpu, int sysprof)
>  {
> +	guard(rwsem_write)(&ctx->ctxlock);
> +
>  	/*
>  	 * Since pm_runtime and sysprof_active are both refcounts, we
>  	 * call apply the new value first, and then unwind the previous

[Severity: High]
This isn't a bug introduced by this patch, but there is a pre-existing issue in
adreno_set_param() when handling MSM_PARAM_EN_VM_BIND:

drivers/gpu/drm/msm/adreno/adreno_gpu.c:adreno_set_param() {
    ...
	case MSM_PARAM_EN_VM_BIND: {
		guard(rwsem_read)(&ctx->ctxlock);

		/* We can only support VM_BIND with per-process pgtables: */
		if (ctx->vm == gpu->vm)
			return UERR(EINVAL, drm, "requires per-process pgtables");
    ...
}

Does this direct comparison against an uninitialized (NULL) ctx->vm fail to
reject the VM_BIND enablement on GPUs without per-process page tables?

If a userspace program calls the MSM_PARAM_EN_VM_BIND ioctl early, ctx->vm is
NULL due to lazy initialization. The check if (ctx->vm == gpu->vm) in
adreno_set_param() evaluates to false, bypassing the hardware capability
check and incorrectly setting ctx->userspace_managed_vm = true.

Later, when msm_context_vm() is called, msm_gpu_create_private_vm() returns
the global gpu->vm because the hardware lacks support for private VMs.
Userspace can then use the MSM_VM_BIND ioctl to map memory directly in the
global GPU VM.

Could a malicious userspace program exploit this to map and unmap arbitrary
memory in the global GPU page tables, potentially overwriting mappings of
other contexts and the kernel?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260729155609.20190-1-robin.clark@oss.qualcomm.com?part=4

  reply	other threads:[~2026-07-29 16:12 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29 15:55 [PATCH v7 00/17] drm/msm: A couple lazy-vm fixes Rob Clark
2026-07-29 15:55 ` [PATCH v7 01/17] drm/msm: Fix barriers accessing ctx vm Rob Clark
2026-07-29 16:15   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 02/17] drm/msm: Rework queuelock Rob Clark
2026-07-29 16:21   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 03/17] drm/msm: Synchronize VM creation on ctxlock Rob Clark
2026-07-29 16:10   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 04/17] drm/msm: Synchronize set_sysprof " Rob Clark
2026-07-29 16:12   ` sashiko-bot [this message]
2026-07-29 15:55 ` [PATCH v7 05/17] drm/msm: Move nr_cmds initialization Rob Clark
2026-07-29 18:14   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 06/17] drm/msm: Remove redundant SIZE_MAX check Rob Clark
2026-07-29 16:09   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 07/17] drm/msm/a6xx: Access VM directly in submit path Rob Clark
2026-07-29 16:12   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 08/17] drm/msm: Add helper to check for per-process pgtables VM Rob Clark
2026-07-29 16:11   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 09/17] drm/msm/gem: Fix dma_buf import error paths Rob Clark
2026-07-29 15:55 ` [PATCH v7 10/17] drm/msm/gem: Remove useless locking in GEM import Rob Clark
2026-07-29 16:11   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 11/17] drm/msm/gem: Extract bookkeeping init helper Rob Clark
2026-07-29 15:55 ` [PATCH v7 12/17] drm/msm/gem: Set resv before exposing obj Rob Clark
2026-07-29 16:25   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 13/17] drm/msm/gem: Validate lazy VM in GEM_NEW Rob Clark
2026-07-29 16:26   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 14/17] drm/msm: Allow lazy VM creation to fail Rob Clark
2026-07-29 16:21   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 15/17] drm/msm: Don't fallback to shared VM for VM_BIND Rob Clark
2026-07-29 16:27   ` sashiko-bot
2026-07-29 15:55 ` [PATCH v7 16/17] drm/msm: Fix per-process-pgtables check Rob Clark
2026-07-29 15:55 ` [PATCH v7 17/17] drm/msm: Fixup invalid overflow check Rob Clark

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260729161249.906E71F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=robin.clark@oss.qualcomm.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.