All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Christian König" <ckoenig.leichtzumerken@gmail.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH 2/2] drm/sched: document the RCU dependency
Date: Mon, 14 Sep 2026 18:48:45 +0000	[thread overview]
Message-ID: <20260914184846.4ADC41F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260914182740.1587-2-christian.koenig@amd.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The documented RCU grace period requirement for scheduler teardown is insufficient to prevent Use-After-Free, and the underlying UAF remains reachable from userspace.
--

commit 5a72d906ede5cec7818892f2331889b7b0dd6420
Author: Christian König <ckoenig.leichtzumerken@gmail.com>

drm/sched: document the RCU dependency

This commit documents the requirement to wait for an RCU grace period
between signaling the last hardware fence and tearing down the scheduler.

> diff --git a/drivers/gpu/drm/scheduler/sched_main.c b/drivers/gpu/drm/scheduler/sched_main.c
> --- a/drivers/gpu/drm/scheduler/sched_main.c
> +++ b/drivers/gpu/drm/scheduler/sched_main.c
> @@ -1203,6 +1203,11 @@ static void drm_sched_cancel_remaining_jobs(struct drm_gpu_scheduler *sched)
>   * is implemented, all jobs will be canceled through it and afterwards cleaned
>   * up through &struct drm_sched_backend_ops.free_job. If cancel_job is not
>   * implemented, memory could leak.
> + *
> + * The user must wait one RCU grace period between signaling the last hardware-
> + * fence and calling this function because the timeline name returned by
> + * scheduler fences must stay valid until all readers have exited their RCU read
> + * side critical section.
>   */
>  void drm_sched_fini(struct drm_gpu_scheduler *sched)

[Severity: High]
This is a pre-existing issue, but is waiting a single RCU grace period before
calling drm_sched_fini() actually sufficient to prevent a use-after-free here?

If a user submits a job to obtain a sync_file fd for the scheduler fence, and
then the GPU queue or context is destroyed while jobs are pending (leaving
fences unsignaled), drivers like xe will tear down the scheduler and often
free the embedding structure without waiting for an RCU grace period:

drivers/gpu/drm/xe/xe_execlist.c:execlist_exec_queue_fini() {
    ...
    drm_sched_fini(&exl->sched);
    ...
    kfree(exl);
}

Since the fence doesn't detach from the scheduler, a subsequent userspace
query via SYNC_IOC_FILE_INFO will enter a new RCU read-side critical section
and access the timeline name on a fence that has outlived its scheduler:

drivers/dma-buf/sync_file.c:sync_fill_fence_info() {
    ...
    rcu_read_lock();
    ...
    timeline = dma_fence_timeline_name(fence);
    ...
}

Which then blindly dereferences the freed scheduler pointer:

drivers/gpu/drm/scheduler/sched_fence.c:drm_sched_fence_get_timeline_name() {
    ...
    return (const char *)fence->sched->name;
}

Even if the driver waited for an RCU grace period before calling
drm_sched_fini(), couldn't new RCU readers still start querying the
unsignaled fence through sync_file long after the scheduler is freed?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260914182740.1587-1-christian.koenig@amd.com?part=2

  reply	other threads:[~2026-09-14 18:48 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14 18:27 [PATCH 1/2] dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v2 Christian König
2026-09-14 18:27 ` [PATCH 2/2] drm/sched: document the RCU dependency Christian König
2026-09-14 18:48   ` sashiko-bot [this message]
2026-09-15  7:20   ` Philipp Stanner
2026-09-15  7:02 ` [PATCH 1/2] dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v2 Philipp Stanner
  -- strict thread matches above, loose matches on Subject: below --
2026-09-09 13:14 Fix dma_fence use after free regression Christian König
2026-09-09 13:14 ` [PATCH 2/2] drm/sched: document the RCU dependency Christian König
2026-09-09 13:29   ` sashiko-bot
2026-09-09 13:55   ` Philipp Stanner
2026-09-09 13:57     ` Christian König

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914184846.4ADC41F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=ckoenig.leichtzumerken@gmail.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.