From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 24CAB12B94 for ; Sun, 9 Aug 2026 08:48:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786265341; cv=none; b=WAyQ89Vkbgv/24sdy9JFQf1VmrJ9/f6O4u1E2XlJ97AUNlxwSNpOGc2+eNycMBVXU0ZtzNdTMB3h5hOooKxLK+MjplhVii+WZyK5Ci39C/g1FgqpVK+55yIOJ8m9MMTVl5kfoB6oZ+/r7ZRuCdLDRHyq+hDH51gFWZVfaD1o91w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786265341; c=relaxed/simple; bh=FV6+Pv0UBIgAPxhy8/KIbv1035RM2RlBW0la8XqlHAo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=CyRn0KankTKvpfscOFhGTC2Pz2EAWwO/2mVAtbvudgLF0UcXPFWkwd+MtF5N3Yie6JV/LzkCCjBLjdIgC8kqrHE9ox6j4nVQQyLN5VFAI2/FtCfJvwo4z3XK3yfuSrazKAbxJIlDW4mefgufStDr4qsoacsVEPuVOMvm4jF9tMo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ISUUwkqk; arc=none smtp.client-ip=209.85.216.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ISUUwkqk" Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-38a0c7e841fso1248281a91.2 for ; Sun, 09 Aug 2026 01:48:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786265339; x=1786870139; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=qSsyx07rdbg9BS6CDdvM5aa6FHTdoOSpWof0piChyTs=; b=ISUUwkqk3Kp253Bx/XFVDOU6E0SnAcS8ApnqQg2u2wb9tSbSrleY4E18KDwtMtbgWF MiLbnKd4qOZRWB5GtLsTJaamIgpheOMuQbb2nZYMMbqxJ2yyNAH82SjG1vZYeh5zzWuY gP/MeAhq1BhtXAvNWaGM7qUovYD1Wj5lO6dQ2dIznG8rJgpfnutUhh7StGNh0EcHlLLW 1m20eGELWwTVpH8Kq4/49F9x0DQfgakpD+YMA7slwZ1ZdAQntggvgseuONNtqkSLIQXf XG4HBRg6KgPZqtSltUqYctLLihu9UT4nDpV9GwJ5+KmPiqEjZQpC8MlMPTME4ZKVjgur p/aQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786265339; x=1786870139; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qSsyx07rdbg9BS6CDdvM5aa6FHTdoOSpWof0piChyTs=; b=pFQBPXyal8DfSRGZxtMvURviylFlwu3LFr0gpVbGbCCzsmR114jKhvlBFD+blxzYGg gymwewtdUrAMotrDs7Do8mNA1XcMTM2FwPtYmVRqHXncQT2DubRE1F0P6O/9qjVvPnHC FFpzDTzyMtdAA697jetUX7iDy320stmuweTuGbpKxRHf+xBVt8y51Gbs87C51WsMaSzq 7dbz5msuQMLWEiqN5bMWwqmc6MsLkYHYCYW0L4bmsgMmgtwZl2WRG4AxetzADpRWLt0Q oo/qZZUtHE5xERlLT2oyNo+OVdtER+qef1DlxbOVFsGXvH/f0KCvTdAbW1/SpmawzHg1 Rn6w== X-Forwarded-Encrypted: i=1; AHgh+RrYGZnfBuNN6aIRgwK4NUEJ+IP/xjRo5Wsk26yfuk/efingZt/F+KXEylQZAEZRjGC28QXkbVG8ilaX5sQ=@vger.kernel.org X-Gm-Message-State: AOJu0YxCh0IU0dmWaAfl6jIIFEif8gY8eh7oqhOxKC4PNEjkp5m21hAw eHo9sC0k+Z/vq1sFK9lr1qBjGOY1WMdlWG+JxxVBngxG7V2ivjP7KXhk X-Gm-Gg: AR+sD10qnoA3iAvbyZZoJc4hx9Go33ImobvLcsDRGtnbxSVfNeJz6c/uixbfxWyhdwh mDXrBxNJryYou1Eki8thkbYLEwO6Xo6h/VlsXRQxVdvNWCksx2edGYAwhlajjjLkSw87dT3vGwI 9Ml3FBSesAq68BuFhmAVix5K7RHCXIMNkBjRQfRYJD7sy221vK6cBHbiTApAlUiq+L5QmdkgspG O39M3CdCubTH1d/DthVqUz/d8pa039l3eaf61SUnO2c6c0mkN8ekMVEkkuVbPj+UUBnkLHNiPP2 6p3kSXd5PrXfjforzk13ojqPH2CCUFcuZFuDhjJ+7+HqsCTEgEJomSLDbGucNhEww57X/BPryC0 NVTn97Zqrdwd2Ds4DArYeUDGTDXWgxUyV0z2kGuiSLS86K0Tc4DPirfikA4wwuYwl0ybXljZ4ME lbJcbI5/XTcMo9rXtOt9mBBVSLaa8R9Y0VLf0g3lgKwjQAVPA2HpW0ufGOJUKLAegYm39ebDkbB 9yoohSCxO4= X-Received: by 2002:a17:90b:2585:b0:38e:bbf1:de34 with SMTP id 98e67ed59e1d1-39261fdab5amr18507599a91.7.1786265339360; Sun, 09 Aug 2026 01:48:59 -0700 (PDT) Received: from localhost.localdomain ([103.178.205.91]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be86fc7bsm28800025eec.1.2026.08.09.01.48.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 01:48:58 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v4 0/6] drm/amdgpu: Robustness and safety fixes for ACA and RAS drivers Date: Sun, 9 Aug 2026 08:47:29 +0000 Message-ID: <20260809084735.9743-1-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This patch series addresses several race conditions, boundary check bugs, logic inversions, NULL pointer checks, and buffer size parameters across the AMDGPU ACA (Accelerated Compute Architecture) and RAS driver subsystems. v3 -> v4: - Patch 3: Wrapped list_del_init() inside mgr->lock in remove_aca_handle() and moved node unlinking prior to aca_fini_error_cache(). This prevents infinite loops during concurrent list traversal and stops background queries from referencing destroyed error cache mutexes during teardown. - Patch 6: Updated subject and moved cancel_work_sync() and cancel_delayed_work_sync() prior to mutex_destroy(&con->page_rsv_lock) in amdgpu_ras_recovery_fini() to prevent work executing after lock destruction. v2 -> v3: - Patch 3: Updated amdgpu_aca_get_error_data() to return 0 instead of -EOPNOTSUPP for invalid handles, ensuring global RAS error queries safely pass through non-ACA blocks without breaking telemetry. - Patch 6: Moved cancel_delayed_work_sync() in amdgpu_ras_fini() prior to ACA subsystem and lock cleanup to avoid teardown races and UAF. v1 -> v2: - Patch 3: Updated remove_aca_handle() to use list_del_init() instead of list_del(), ensuring list_empty() properly evaluates removed handles and avoiding potential UAF during device teardown. Sreeraj S Kurup (6): drm/amdgpu/aca: Fix race condition and UAF in error cache logging drm/amdgpu/aca: Add upper bounds check in aca_bank_hwip_is_matched drm/amdgpu/aca: Fix inverted validation logic and list cleanup drm/amdgpu/aca: Add missing NULL check for banks parameter in aca_banks_add_bank drm/amdgpu/aca: Fix off-by-one buffer size parameter in add_aca_sysfs drm/amdgpu/ras: Fix delayed work cancellation order during teardown drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 41 ++++++++++++------------- drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c | 11 +++---- 2 files changed, 24 insertions(+), 28 deletions(-) -- 2.54.0