From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 60189C2C8 for ; Sun, 9 Aug 2026 14:46:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786286778; cv=none; b=BEx4EUQrDUkx8ZT/Q819yApUWSiWL0g6Zs3d+rqhmAjeWCrQ1szCA5/yKZ5c5zcmeV45OPKgmiGp75ra4uF2vm5Q9RWRMTGas5lrVf8+Ow8cyrVB2SClhUo2ULrvt0C47Cm4LVqp8oGDp9ORBXsozYgH5RqIOYxEK/4+5lmgfLw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786286778; c=relaxed/simple; bh=7IigkM9Gh9svg931O7jcUl7TDuyeyr+mF2opgB00wGo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=AqnHXvWXgG4R1Oyns4ks1PX8UpIQQjGYFiw2P4cAN3blUSyxIYfx9Jkaa7GYpyV7kykypFAZc79IXGSy1QxV2NHaDj+EKeUDny9Yqq+cT3v9RkSJOLdC8sCudykVpkG6hYrt6l7ieHUjVeFX6KQ/PmFDD8cxCzzb9Dv39BuwlSk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ilewNH68; arc=none smtp.client-ip=209.85.215.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ilewNH68" Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-c9ef3e1337fso713680a12.2 for ; Sun, 09 Aug 2026 07:46:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786286777; x=1786891577; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=sLtiiUZZXVNzDzJlTEnHgJIHbIC7FJbLG16BtntNSAU=; b=ilewNH685cuxVHjD+06n64DOOoGb1nbZp3DkWcvL5r4gheMQkNngkTpFdOZDXGIP8V PbLPlmMbsmt9Wq2Nm6hl0akj23IVOlgArnmQj7wjQpuMwfcNpcZ8H55fgkNVSbNVj9cV HaDKtLzyy2k5M/1vltNiWZY5RpBPqF7Wy9vUI/jZ4JAYTYlAJdAYwMsZwiHoZNZOjhJI kgX8JP8Yw5tzfRum3RiAl4iBXnVcvkmiOM3721gOIVu2QNGwz4Vg21Ja3gyTq4FVCP3K 54IPbyR3tKUQwm/3VNs3cXH9pcta5dV+d/AQvjqQVI5/3X+NV4rA+53U3e3lfFcf372V vi9w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786286777; x=1786891577; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sLtiiUZZXVNzDzJlTEnHgJIHbIC7FJbLG16BtntNSAU=; b=lcGFUYFe4f3EAq9uHz7dK4Q0GLHP4lwz5yrsBc/rbJy3a1Wp9SPQr1SmdXBJeU3apE wyTz7hCLmOupo9m/yx9pemAeLSgCIgcbqOSyONdzNrAoEemK0cxFJ/NRA9K4uLBDVuDT HFDOiua9cZaHXR0afrdSHz9BKFzuE/AS1XqVCPhm+7ePLuBNBZYuAkAvF5VwFhDCcixO TGYgqXc1HOnlApb2dcd3pfjuSC/sLPHr1V5GWgjP5TvUzlgxjcz6abm1Frquo7PaPtTM AFJMKuMiOgYkH6++Nxvf1OyJoEnWZpDsXZGG2AHIADzGr83tXa/GBbLCM9II7NnkEEKo msXQ== X-Forwarded-Encrypted: i=1; AHgh+RqnJs7/rz+eMW40sZ4U93ER4xuox0BuqnKG1puSmy1/L8bSYa8k/hotUwhlMMPOkAv7meSeZOAD4G+SRG0=@vger.kernel.org X-Gm-Message-State: AOJu0YzB/zvXeoo6tMSYznQ4Ck0vrnPF++wFBInd2zESk+NdaVJHm5ih auyC7lovumwMFQAa417IK38kvxs7K8/zqqhwTm2NgNkfYuYsxcINRz4w X-Gm-Gg: AR+sD13lbXW5DqDC6SjwllJU3DLry6AnZg1qdg+aKgZKSUPePaO1ZH16bGeHXvaRAT8 fNha65a44eOyqhqQllPFPauoyPEGQ0FaEO9eiGI84fGEm7WMu7natjaF66KmcPQO7zbibCmfx++ XN/oHBps+HUnR4UZX63NZ37FC2j0X8rbtiptN++WyiZaeOwz8TddB2/i5faI7GfM7k8HBMrvJgw NH2Y6pgYXMVJI908uVet1G+Q6BMGO8UkDRp+INQG65loBJ+wWg0YF0tajiLSxzFMllG51SBbJvY Rj8x58SOE0oOFDo+p4kIMRXn4tfCJGiLHRYFdfWK5t/qDaKDJ8UirrwztF4CHciT5ZPoXD2BrG/ fCD0HWnPeqnBN+N/NZ8kInCrJFG6w9RDaUvejGvc5XVdQVzgol2orjUuieF+8F/1kEmx1LmadsB AAujb/CvZA7gLbcRLl0YPhWwFb9H3GmdKmRtV+buQd3SZ5i4DpbeOWbdAlvEicpd/XFLerhJEh1 MlGHyDRH1c= X-Received: by 2002:a05:6a20:4309:b0:3c8:ead5:bf7b with SMTP id adf61e73a8af0-3cb85ded991mr39942065637.4.1786286776550; Sun, 09 Aug 2026 07:46:16 -0700 (PDT) Received: from localhost.localdomain ([103.178.205.91]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-14101b7ad29sm25911224c88.13.2026.08.09.07.46.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 07:46:16 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v5 0/4] drm/amdgpu: Robustness and safety fixes for ACA and RAS drivers Date: Sun, 9 Aug 2026 14:44:47 +0000 Message-ID: <20260809144451.35431-1-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This patch series addresses race conditions, boundary check bugs, logic inversions, and teardown ordering in the AMDGPU ACA (Accelerated Compute Architecture) and RAS driver subsystems. v4 -> v5: - Dropped former Patch 4 (NULL check on banks parameter) and Patch 5 (snprintf buffer size adjustment) from v5. - Patch 3: Dropped invalid kfree(handle) from remove_aca_handle() since ACA handles can be embedded in ras_manager. Removed non-existent mgr->lock references and retained list_del_init() prior to aca_fini_error_cache(). - Patch 4 (formerly Patch 6): Retained the original work cancellation order in amdgpu_ras_fini() to prevent work re-queueing, while moving cancellation prior to mutex_destroy(&con->page_rsv_lock) in amdgpu_ras_recovery_fini(). v3 -> v4: - Patch 3: Moved node unlinking prior to aca_fini_error_cache(). - Patch 4 (formerly Patch 6): Updated the subject and moved cancel_work_sync() and cancel_delayed_work_sync() prior to mutex_destroy(&con->page_rsv_lock) in amdgpu_ras_recovery_fini(). v2 -> v3: - Patch 3: Updated amdgpu_aca_get_error_data() to return 0 instead of -EOPNOTSUPP for invalid handles, allowing global RAS error queries to safely pass through non-ACA blocks. v1 -> v2: - Patch 3: Updated remove_aca_handle() to use list_del_init() instead of list_del(), ensuring list_empty() correctly evaluates removed handles. Sreeraj S Kurup (4): drm/amdgpu/aca: Fix race condition and UAF in error cache logging drm/amdgpu/aca: Add upper bounds check in aca_bank_hwip_is_matched drm/amdgpu/aca: Fix inverted validation logic and list cleanup drm/amdgpu/ras: Fix delayed work cancellation order during teardown drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 34 ++++++++++--------------- drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c | 7 +++-- 2 files changed, 17 insertions(+), 24 deletions(-) -- 2.54.0