* (no subject) @ 2024-10-07 13:26 Yonatan Maman 2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman 2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman 0 siblings, 2 replies; 5+ messages in thread From: Yonatan Maman @ 2024-10-07 13:26 UTC (permalink / raw) To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse, dri-devel, nouveau Cc: Yonatan Maman, linux-kernel, stable From: Yonatan Maman <Ymaman@Nvidia.com> Date: Mon, 7 Oct 2024 14:48:26 +0300 Subject: [PATCH v2 0/2] drm/nouveau/dmem: Fix Memory Leaking and Device Channels configuration This patch series addresses two critical issues in the Nouveau driver related to device channels, error handling, and memory leaks. - Memory Leak in migrate_to_ram: The migrate_to_ram function was identified as leaking memory when a copy push command fails. This results in the function returning a dirty HIGH_USER page, which can expose sensitive information and pose a security risk. To mitigate this vulnerability, the patch ensures that a zero page is allocated for the destination page, thereby preventing memory leaks and enhancing driver security in case of failure. - Privileged Error in Copy Engine Channel: An error was observed when the nouveau_dmem_copy_one function is executed, leading to a Host Copy Engine Privileged error on channel 1. The patch resolves this by adjusting the Copy Engine channel configuration to permit privileged push commands, resolving the error. Changes since V1: - Fixed version according to Danilo Krummrich's comments. Yonatan Maman (2): nouveau/dmem: Fix privileged error in copy engine channel nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error drivers/gpu/drm/nouveau/nouveau_dmem.c | 2 +- drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) -- 2.34.1 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel 2024-10-07 13:26 Yonatan Maman @ 2024-10-07 13:26 ` Yonatan Maman 2024-10-07 13:31 ` kernel test robot 2024-10-07 13:53 ` Danilo Krummrich 2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman 1 sibling, 2 replies; 5+ messages in thread From: Yonatan Maman @ 2024-10-07 13:26 UTC (permalink / raw) To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse, dri-devel, nouveau Cc: Yonatan Maman, linux-kernel, stable, Gal Shalom From: Yonatan Maman <Ymaman@Nvidia.com> When `nouveau_dmem_copy_one` is called, the following error occurs: [272146.675156] nouveau 0000:06:00.0: fifo: PBDMA9: 00000004 [HCE_PRIV] ch 1 00000300 00003386 This indicates that a copy push command triggered a Host Copy Engine Privileged error on channel 1 (Copy Engine channel). To address this issue, modify the Copy Engine channel to allow privileged push commands Fixes: 6de125383a5c ("drm/nouveau/fifo: expose runlist topology info on all chipsets") Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com> Signed-off-by: Gal Shalom <GalShalom@Nvidia.com> Reviewed-by: Ben Skeggs <bskeggs@nvidia.com> --- drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c index a58c31089613..0a75ce4c5021 100644 --- a/drivers/gpu/drm/nouveau/nouveau_drm.c +++ b/drivers/gpu/drm/nouveau/nouveau_drm.c @@ -356,7 +356,7 @@ nouveau_accel_ce_init(struct nouveau_drm *drm) return; } - ret = nouveau_channel_new(drm, device, false, runm, NvDmaFB, NvDmaTT, &drm->cechan); + ret = nouveau_channel_new(drm, device, true, runm, NvDmaFB, NvDmaTT, &drm->cechan); if (ret) NV_ERROR(drm, "failed to create ce channel, %d\n", ret); } -- 2.34.1 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel 2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman @ 2024-10-07 13:31 ` kernel test robot 2024-10-07 13:53 ` Danilo Krummrich 1 sibling, 0 replies; 5+ messages in thread From: kernel test robot @ 2024-10-07 13:31 UTC (permalink / raw) To: Yonatan Maman; +Cc: stable, oe-kbuild-all Hi, Thanks for your patch. FYI: kernel test robot notices the stable kernel rule is not satisfied. The check is based on https://www.kernel.org/doc/html/latest/process/stable-kernel-rules.html#option-1 Rule: add the tag "Cc: stable@vger.kernel.org" in the sign-off area to have the patch automatically included in the stable tree. Subject: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Link: https://lore.kernel.org/stable/20241007132700.982800-2-ymaman%40nvidia.com -- 0-DAY CI Kernel Test Service https://github.com/intel/lkp-tests/wiki ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel 2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman 2024-10-07 13:31 ` kernel test robot @ 2024-10-07 13:53 ` Danilo Krummrich 1 sibling, 0 replies; 5+ messages in thread From: Danilo Krummrich @ 2024-10-07 13:53 UTC (permalink / raw) To: Yonatan Maman Cc: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse, dri-devel, nouveau, linux-kernel, stable, Gal Shalom On Mon, Oct 07, 2024 at 04:26:59PM +0300, Yonatan Maman wrote: > From: Yonatan Maman <Ymaman@Nvidia.com> > > When `nouveau_dmem_copy_one` is called, the following error occurs: > > [272146.675156] nouveau 0000:06:00.0: fifo: PBDMA9: 00000004 [HCE_PRIV] > ch 1 00000300 00003386 > > This indicates that a copy push command triggered a Host Copy Engine > Privileged error on channel 1 (Copy Engine channel). To address this > issue, modify the Copy Engine channel to allow privileged push commands > > Fixes: 6de125383a5c ("drm/nouveau/fifo: expose runlist topology info on all chipsets") > Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com> > Signed-off-by: Gal Shalom <GalShalom@Nvidia.com> Again, why is this signed-off by Gal? If he's a co-author, please add the corresponding tag. Please also see my reply to the previous version. > Reviewed-by: Ben Skeggs <bskeggs@nvidia.com> > --- > drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c > index a58c31089613..0a75ce4c5021 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_drm.c > +++ b/drivers/gpu/drm/nouveau/nouveau_drm.c > @@ -356,7 +356,7 @@ nouveau_accel_ce_init(struct nouveau_drm *drm) > return; > } > > - ret = nouveau_channel_new(drm, device, false, runm, NvDmaFB, NvDmaTT, &drm->cechan); > + ret = nouveau_channel_new(drm, device, true, runm, NvDmaFB, NvDmaTT, &drm->cechan); > if (ret) > NV_ERROR(drm, "failed to create ce channel, %d\n", ret); > } > -- > 2.34.1 > ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error 2024-10-07 13:26 Yonatan Maman 2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman @ 2024-10-07 13:27 ` Yonatan Maman 1 sibling, 0 replies; 5+ messages in thread From: Yonatan Maman @ 2024-10-07 13:27 UTC (permalink / raw) To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse, dri-devel, nouveau Cc: Yonatan Maman, linux-kernel, stable, Gal Shalom From: Yonatan Maman <Ymaman@Nvidia.com> A copy push command might fail, causing `migrate_to_ram` to return a dirty HIGH_USER page to the user. This exposes a security vulnerability in the nouveau driver. To prevent memory leaks in `migrate_to_ram` upon a copy error, allocate a zero page for the destination page. Fixes: 5be73b690875 ("drm/nouveau/dmem: device memory helpers for SVM") Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com> Signed-off-by: Gal Shalom <GalShalom@Nvidia.com> Reviewed-by: Ben Skeggs <bskeggs@nvidia.com> --- drivers/gpu/drm/nouveau/nouveau_dmem.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_dmem.c b/drivers/gpu/drm/nouveau/nouveau_dmem.c index 6fb65b01d778..097bd3af0719 100644 --- a/drivers/gpu/drm/nouveau/nouveau_dmem.c +++ b/drivers/gpu/drm/nouveau/nouveau_dmem.c @@ -193,7 +193,7 @@ static vm_fault_t nouveau_dmem_migrate_to_ram(struct vm_fault *vmf) if (!spage || !(src & MIGRATE_PFN_MIGRATE)) goto done; - dpage = alloc_page_vma(GFP_HIGHUSER, vmf->vma, vmf->address); + dpage = alloc_page_vma(GFP_HIGHUSER | __GFP_ZERO, vmf->vma, vmf->address); if (!dpage) goto done; -- 2.34.1 ^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2024-10-07 13:54 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2024-10-07 13:26 Yonatan Maman 2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman 2024-10-07 13:31 ` kernel test robot 2024-10-07 13:53 ` Danilo Krummrich 2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.