* [PATCH v4] drm/sched: Create a fake device for KUnit tests
@ 2026-09-08 5:59 oushixiong1025
2026-09-08 6:07 ` sashiko-bot
2026-09-08 12:29 ` Philipp Stanner
0 siblings, 2 replies; 3+ messages in thread
From: oushixiong1025 @ 2026-09-08 5:59 UTC (permalink / raw)
To: Matthew Brost
Cc: Danilo Krummrich, Philipp Stanner, Christian König,
Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann, David Airlie,
Simona Vetter, dri-devel, linux-kernel, Shixiong Ou, stable
From: Shixiong Ou <oushixiong@kylinos.cn>
The DRM scheduler KUnit tests pass NULL for the dev field in
drm_sched_init_args, which NULL-pointer dereferences in the drm_sched_job
trace event via dev_name() on sched->dev.
Give the mock scheduler a device with kunit_device_register(), which is
also cleaned up at test exit. A per-function counter keeps the device
names unique, since some tests create several mock schedulers.
Fixes: 5a99350794fe ("drm/sched: Add scheduler unit testing infrastructure and some basic tests")
Cc: stable@vger.kernel.org
Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
Acked-by: Maxime Ripard <mripard@kernel.org>
---
v3->v4:
- Initialize the instance counter explicitly
v2->v3:
- Start the mock scheduler device numbering at 0, using
instance++ instead of ++instance
v1->v2:
- Switch from faux_device_create() to kunit_device_register(), which also
cleans the device up automatically at test exit (Maxime Ripard)
- Build the device name on top of args.name (Philipp Stanner)
- Make the instance counter a static unsigned int local to
drm_mock_sched_new() (Philipp Stanner)
- Add a Fixes: tag and Cc: stable for the NULL dev dereference
drivers/gpu/drm/scheduler/tests/mock_scheduler.c | 11 ++++++++
1 file changed, 11 insertions(+)
diff --git a/drivers/gpu/drm/scheduler/tests/mock_scheduler.c b/drivers/gpu/drm/scheduler/tests/mock_scheduler.c
index 8e9ae7d980eb..12dc61f56192 100644
--- a/drivers/gpu/drm/scheduler/tests/mock_scheduler.c
+++ b/drivers/gpu/drm/scheduler/tests/mock_scheduler.c
@@ -1,6 +1,8 @@
// SPDX-License-Identifier: GPL-2.0
/* Copyright (c) 2025 Valve Corporation */
+#include <kunit/device.h>
+
#include "sched_tests.h"
/*
@@ -288,6 +290,7 @@ static const struct drm_sched_backend_ops drm_mock_scheduler_ops = {
*/
struct drm_mock_scheduler *drm_mock_sched_new(struct kunit *test, long timeout)
{
+ static unsigned int instance = 0;
struct drm_sched_init_args args = {
.ops = &drm_mock_scheduler_ops,
.num_rqs = DRM_SCHED_PRIORITY_COUNT,
@@ -297,11 +300,19 @@ struct drm_mock_scheduler *drm_mock_sched_new(struct kunit *test, long timeout)
.name = "drm-mock-scheduler",
};
struct drm_mock_scheduler *sched;
+ struct device *dev;
+ char name[64];
int ret;
sched = kunit_kzalloc(test, sizeof(*sched), GFP_KERNEL);
KUNIT_ASSERT_NOT_NULL(test, sched);
+ snprintf(name, sizeof(name), "%s-%u", args.name, instance++);
+ dev = kunit_device_register(test, name);
+ KUNIT_ASSERT_NOT_ERR_OR_NULL(test, dev);
+
+ args.dev = dev;
+
ret = drm_sched_init(&sched->base, &args);
KUNIT_ASSERT_EQ(test, ret, 0);
--
2.43.0
No virus found
Checked by Hillstone Network AntiVirus
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH v4] drm/sched: Create a fake device for KUnit tests
2026-09-08 5:59 [PATCH v4] drm/sched: Create a fake device for KUnit tests oushixiong1025
@ 2026-09-08 6:07 ` sashiko-bot
2026-09-08 12:29 ` Philipp Stanner
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-08 6:07 UTC (permalink / raw)
To: oushixiong1025; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Pre-existing UAF in KUnit tests due to un-canceled background work on test failure.
--
commit a8f2ea9fa48640427fb6cda0751abea77a6dd44f
Author: Shixiong Ou <oushixiong@kylinos.cn>
drm/sched: Create a fake device for KUnit tests
The DRM scheduler KUnit tests pass NULL for the dev field in
drm_sched_init_args, which causes a NULL-pointer dereference in the
drm_sched_job trace event. This patch gives the mock scheduler a fake
device with kunit_device_register(), ensuring it is cleaned up at test
exit.
> diff --git a/drivers/gpu/drm/scheduler/tests/mock_scheduler.c b/drivers/gpu/drm/scheduler/tests/mock_scheduler.c
> index 8e9ae7d980eb2..6a21e0b40c6d7 100644
> --- a/drivers/gpu/drm/scheduler/tests/mock_scheduler.c
> +++ b/drivers/gpu/drm/scheduler/tests/mock_scheduler.c
> @@ -297,11 +300,19 @@ struct drm_mock_scheduler *drm_mock_sched_new(struct kunit *test, long timeout)
> .name = "drm-mock-scheduler",
> };
> struct drm_mock_scheduler *sched;
> + struct device *dev;
> + char name[64];
> int ret;
>
> sched = kunit_kzalloc(test, sizeof(*sched), GFP_KERNEL);
[Severity: High]
This isn't a bug introduced by this patch, but I noticed a pre-existing
use-after-free issue in the KUnit tests due to uncanceled background work
on test failure.
Because sched is allocated with kunit_kzalloc() here, KUnit's automatic
garbage collection frees the memory when a test exits or aborts on failure.
However, tests in tests_basic.c use assertions that abort immediately:
drivers/gpu/drm/scheduler/tests/tests_basic.c:drm_sched_basic_cancel() {
...
done = drm_mock_sched_job_wait_scheduled(job, HZ);
KUNIT_ASSERT_TRUE(test, done);
drm_mock_sched_entity_free(entity);
drm_mock_sched_fini(sched);
}
If the KUNIT_ASSERT_TRUE() assertion fails, drm_mock_sched_fini() is skipped.
The sched memory is freed by KUnit, but the background work items
(work_run_job, work_tdr) and workqueues queued by drm_sched_init() are never
canceled.
Could these work items eventually execute, accessing the freed sched memory
and causing a kernel crash?
This same unhandled cleanup path appears in other tests, such as
drm_sched_test_credits():
drivers/gpu/drm/scheduler/tests/tests_basic.c:drm_sched_test_credits() {
...
done = drm_mock_sched_job_wait_scheduled(job[0], HZ);
KUNIT_ASSERT_TRUE(test, done);
...
drm_mock_sched_fini(sched);
}
> KUNIT_ASSERT_NOT_NULL(test, sched);
>
> + snprintf(name, sizeof(name), "%s-%u", args.name, instance++);
> + dev = kunit_device_register(test, name);
> + KUNIT_ASSERT_NOT_ERR_OR_NULL(test, dev);
> +
> + args.dev = dev;
> +
> ret = drm_sched_init(&sched->base, &args);
> KUNIT_ASSERT_EQ(test, ret, 0);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260908055941.351486-1-oushixiong1025@163.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH v4] drm/sched: Create a fake device for KUnit tests
2026-09-08 5:59 [PATCH v4] drm/sched: Create a fake device for KUnit tests oushixiong1025
2026-09-08 6:07 ` sashiko-bot
@ 2026-09-08 12:29 ` Philipp Stanner
1 sibling, 0 replies; 3+ messages in thread
From: Philipp Stanner @ 2026-09-08 12:29 UTC (permalink / raw)
To: oushixiong1025, Matthew Brost
Cc: Danilo Krummrich, Philipp Stanner, Christian König,
Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann, David Airlie,
Simona Vetter, dri-devel, linux-kernel, Shixiong Ou, stable
On Tue, 2026-09-08 at 13:59 +0800, oushixiong1025@163.com wrote:
> From: Shixiong Ou <oushixiong@kylinos.cn>
>
> The DRM scheduler KUnit tests pass NULL for the dev field in
> drm_sched_init_args, which NULL-pointer dereferences in the drm_sched_job
> trace event via dev_name() on sched->dev.
>
> Give the mock scheduler a device with kunit_device_register(), which is
> also cleaned up at test exit. A per-function counter keeps the device
> names unique, since some tests create several mock schedulers.
>
> Fixes: 5a99350794fe ("drm/sched: Add scheduler unit testing infrastructure and some basic tests")
> Cc: stable@vger.kernel.org
> Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
> Acked-by: Maxime Ripard <mripard@kernel.org>
>
> ---
> v3->v4:
> - Initialize the instance counter explicitly
You learn something new every day – apparently that must not be done,
according to the DRM rules.
My bad.
I reverted it locally and pushed to drm-misc-fixes
Thx Shixiong.
P.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-08 12:29 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-08 5:59 [PATCH v4] drm/sched: Create a fake device for KUnit tests oushixiong1025
2026-09-08 6:07 ` sashiko-bot
2026-09-08 12:29 ` Philipp Stanner
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.