From: sashiko-bot@kernel.org
To: "Tales A. Mendonça" <talesam@gmail.com>
Cc: dri-devel@lists.freedesktop.org, intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v3 1/3] drm/xe: Capture devcoredump on TLB invalidation timeout
Date: Mon, 24 Aug 2026 14:19:49 +0000 [thread overview]
Message-ID: <20260824141949.958861F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260824140748.54974-2-talesam@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Uncancelled deferred devcoredump work on the global workqueue leads to UAF if the driver is unbound/unloaded before the work executes.
--
--- Patch [1]: [PATCH v3 1/3] drm/xe: Capture devcoredump on TLB invalidation timeout ---
commit e17a9749756454a4d7c32af8d34a73ac7b919a3e
Author: Tales A. Mendonça <talesam@gmail.com>
drm/xe: Capture devcoredump on TLB invalidation timeout
This commit adds xe_devcoredump_gt() to capture GuC log and CT state
for hangs that are not tied to an exec queue or job. It also hooks
this mechanism up to the TLB invalidation timeout path.
Link: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8678
> diff --git a/drivers/gpu/drm/xe/xe_devcoredump.c b/drivers/gpu/drm/xe/xe_devcoredump.c
> --- a/drivers/gpu/drm/xe/xe_devcoredump.c
> +++ b/drivers/gpu/drm/xe/xe_devcoredump.c
[ ... ]
> @@ -323,40 +318,44 @@ static void devcoredump_snapshot(struct xe_devcoredump *coredump,
[ ... ]
> + if (q) {
> + ss->ge = xe_guc_exec_queue_snapshot_capture(q);
> + if (job)
> + ss->job = xe_sched_job_snapshot_capture(job);
> + ss->vm = xe_vm_snapshot_capture(q->vm);
> +
> + xe_engine_snapshot_capture_for_queue(q);
> + }
>
> queue_work(system_dfl_wq, &ss->work);
[Severity: High]
This is a pre-existing issue, but does this deferred work item on the global
system_dfl_wq cause a use-after-free if the driver is unbound before it
executes?
During teardown, xe_driver_devcoredump_fini() calls dev_coredump_put(). If
the work hasn't run yet, the coredump device hasn't been registered by the
deferred worker.
Consequently, dev_coredump_put() finds no device, returns silently, and
never invokes xe_devcoredump_free(). The work remains uncanceled on
system_dfl_wq and will eventually execute using a freed xe_device.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260824140748.54974-1-talesam@gmail.com?part=1
next prev parent reply other threads:[~2026-08-24 14:19 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 14:07 [PATCH v3 0/3] drm/xe: fix GuC TLB invalidation ack stalls on ARL (Wa_22016122933) Tales A. Mendonça
2026-08-24 14:07 ` [PATCH v3 1/3] drm/xe: Capture devcoredump on TLB invalidation timeout Tales A. Mendonça
2026-08-24 14:19 ` sashiko-bot [this message]
2026-08-24 14:07 ` [PATCH v3 2/3] drm/xe: Log when a timed out TLB invalidation ack finally arrives Tales A. Mendonça
2026-08-24 14:07 ` [PATCH v3 3/3] drm/xe: Implement Wa_22016122933 Tales A. Mendonça
2026-08-25 6:23 ` ✗ CI.checkpatch: warning for drm/xe: fix GuC TLB invalidation ack stalls on ARL (Wa_22016122933) (rev2) Patchwork
2026-08-25 6:24 ` ✓ CI.KUnit: success " Patchwork
2026-08-31 16:00 ` [PATCH v3 0/3] drm/xe: fix GuC TLB invalidation ack stalls on ARL (Wa_22016122933) Tales A. Mendonça
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824141949.958861F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=talesam@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.