From: "Thomas Hellström" <thomas.hellstrom@linux.intel.com>
To: intel-xe@lists.freedesktop.org
Cc: "Thomas Hellström" <thomas.hellstrom@linux.intel.com>,
"Matthew Brost" <matthew.brost@intel.com>,
"Matthew Auld" <matthew.auld@intel.com>
Subject: [PATCH v2 0/2] drm/xe: Fix two bo pin/unpin accounting bugs
Date: Thu, 1 Oct 2026 15:40:16 +0200 [thread overview]
Message-ID: <20261001134018.111553-1-thomas.hellstrom@linux.intel.com> (raw)
Two independent fixes uncovered while auditing the bo pin/unpin and
shrinker accounting paths:
1/2 fixes a double-subtraction of the shrinker's page/object
accounting on nested xe_bo_pin_external()/xe_bo_unpin_external()
calls, which can desynchronize the shrinker's counts from reality and,
due to a signed-to-unsigned interpretation in xe_shrinker_count(),
turn into a huge bogus shrinkable/purgeable page count that causes the
shrinker to be invoked excessively under memory pressure.
2/2 fixes a stale xe->pinned.late.external list entry left behind when
a bo pinned both externally and as an fb has its final unpin performed
via the fb-pin path, which bypasses pinned_link maintenance and can
lead to list corruption or a use-after-free once the bo is freed.
Both are tagged for stable.
Thomas Hellström (2):
drm/xe: Fix shrinker accounting double-subtraction on nested external
pins
drm/xe: Fix stale pinned_link entry when fb-pin performs the final
unpin
drivers/gpu/drm/xe/display/xe_fb_pin.c | 6 +-
drivers/gpu/drm/xe/xe_bo.c | 110 +++++++++++++++++++------
drivers/gpu/drm/xe/xe_bo.h | 2 +
3 files changed, 90 insertions(+), 28 deletions(-)
--
2.55.0
next reply other threads:[~2026-10-01 13:41 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 13:40 Thomas Hellström [this message]
2026-10-01 13:40 ` [PATCH v2 1/2] drm/xe: Fix shrinker accounting double-subtraction on nested external pins Thomas Hellström
2026-10-01 13:56 ` sashiko-bot
2026-10-01 17:34 ` Matthew Auld
2026-10-01 13:40 ` [PATCH v2 2/2] drm/xe: Fix stale pinned_link entry when fb-pin performs the final unpin Thomas Hellström
2026-10-01 17:26 ` Matthew Auld
2026-10-02 9:52 ` Thomas Hellström
2026-10-02 11:59 ` Matthew Auld
2026-10-01 17:44 ` Matthew Auld
2026-10-01 13:50 ` ✓ CI.KUnit: success for drm/xe: Fix two bo pin/unpin accounting bugs Patchwork
2026-10-01 18:11 ` ✓ Xe.CI.BAT: " Patchwork
2026-10-01 22:58 ` ✗ Xe.CI.FULL: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001134018.111553-1-thomas.hellstrom@linux.intel.com \
--to=thomas.hellstrom@linux.intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=matthew.auld@intel.com \
--cc=matthew.brost@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.