* (no subject)
@ 2024-10-07 13:26 Yonatan Maman
2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman
0 siblings, 2 replies; 5+ messages in thread
From: Yonatan Maman @ 2024-10-07 13:26 UTC (permalink / raw)
To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
dri-devel, nouveau
Cc: Yonatan Maman, linux-kernel, stable
From: Yonatan Maman <Ymaman@Nvidia.com>
Date: Mon, 7 Oct 2024 14:48:26 +0300
Subject: [PATCH v2 0/2] drm/nouveau/dmem: Fix Memory Leaking and Device Channels configuration
This patch series addresses two critical issues in the Nouveau driver
related to device channels, error handling, and memory leaks.
- Memory Leak in migrate_to_ram: The migrate_to_ram function was
identified as leaking memory when a copy push command fails. This
results in the function returning a dirty HIGH_USER page, which can
expose sensitive information and pose a security risk. To mitigate
this vulnerability, the patch ensures that a zero page is allocated for
the destination page, thereby preventing memory leaks and enhancing
driver security in case of failure.
- Privileged Error in Copy Engine Channel: An error was observed when
the nouveau_dmem_copy_one function is executed, leading to a Host Copy
Engine Privileged error on channel 1. The patch resolves this by
adjusting the Copy Engine channel configuration to permit privileged
push commands, resolving the error.
Changes since V1:
- Fixed version according to Danilo Krummrich's comments.
Yonatan Maman (2):
nouveau/dmem: Fix privileged error in copy engine channel
nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error
drivers/gpu/drm/nouveau/nouveau_dmem.c | 2 +-
drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
2024-10-07 13:26 Yonatan Maman
@ 2024-10-07 13:26 ` Yonatan Maman
2024-10-07 13:31 ` kernel test robot
2024-10-07 13:53 ` Danilo Krummrich
2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman
1 sibling, 2 replies; 5+ messages in thread
From: Yonatan Maman @ 2024-10-07 13:26 UTC (permalink / raw)
To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
dri-devel, nouveau
Cc: Yonatan Maman, linux-kernel, stable, Gal Shalom
From: Yonatan Maman <Ymaman@Nvidia.com>
When `nouveau_dmem_copy_one` is called, the following error occurs:
[272146.675156] nouveau 0000:06:00.0: fifo: PBDMA9: 00000004 [HCE_PRIV]
ch 1 00000300 00003386
This indicates that a copy push command triggered a Host Copy Engine
Privileged error on channel 1 (Copy Engine channel). To address this
issue, modify the Copy Engine channel to allow privileged push commands
Fixes: 6de125383a5c ("drm/nouveau/fifo: expose runlist topology info on all chipsets")
Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com>
Signed-off-by: Gal Shalom <GalShalom@Nvidia.com>
Reviewed-by: Ben Skeggs <bskeggs@nvidia.com>
---
drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c
index a58c31089613..0a75ce4c5021 100644
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -356,7 +356,7 @@ nouveau_accel_ce_init(struct nouveau_drm *drm)
return;
}
- ret = nouveau_channel_new(drm, device, false, runm, NvDmaFB, NvDmaTT, &drm->cechan);
+ ret = nouveau_channel_new(drm, device, true, runm, NvDmaFB, NvDmaTT, &drm->cechan);
if (ret)
NV_ERROR(drm, "failed to create ce channel, %d\n", ret);
}
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error
2024-10-07 13:26 Yonatan Maman
2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
@ 2024-10-07 13:27 ` Yonatan Maman
1 sibling, 0 replies; 5+ messages in thread
From: Yonatan Maman @ 2024-10-07 13:27 UTC (permalink / raw)
To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
dri-devel, nouveau
Cc: Yonatan Maman, linux-kernel, stable, Gal Shalom
From: Yonatan Maman <Ymaman@Nvidia.com>
A copy push command might fail, causing `migrate_to_ram` to return a
dirty HIGH_USER page to the user.
This exposes a security vulnerability in the nouveau driver. To prevent
memory leaks in `migrate_to_ram` upon a copy error, allocate a zero
page for the destination page.
Fixes: 5be73b690875 ("drm/nouveau/dmem: device memory helpers for SVM")
Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com>
Signed-off-by: Gal Shalom <GalShalom@Nvidia.com>
Reviewed-by: Ben Skeggs <bskeggs@nvidia.com>
---
drivers/gpu/drm/nouveau/nouveau_dmem.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_dmem.c b/drivers/gpu/drm/nouveau/nouveau_dmem.c
index 6fb65b01d778..097bd3af0719 100644
--- a/drivers/gpu/drm/nouveau/nouveau_dmem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_dmem.c
@@ -193,7 +193,7 @@ static vm_fault_t nouveau_dmem_migrate_to_ram(struct vm_fault *vmf)
if (!spage || !(src & MIGRATE_PFN_MIGRATE))
goto done;
- dpage = alloc_page_vma(GFP_HIGHUSER, vmf->vma, vmf->address);
+ dpage = alloc_page_vma(GFP_HIGHUSER | __GFP_ZERO, vmf->vma, vmf->address);
if (!dpage)
goto done;
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
@ 2024-10-07 13:31 ` kernel test robot
2024-10-07 13:53 ` Danilo Krummrich
1 sibling, 0 replies; 5+ messages in thread
From: kernel test robot @ 2024-10-07 13:31 UTC (permalink / raw)
To: Yonatan Maman; +Cc: stable, oe-kbuild-all
Hi,
Thanks for your patch.
FYI: kernel test robot notices the stable kernel rule is not satisfied.
The check is based on https://www.kernel.org/doc/html/latest/process/stable-kernel-rules.html#option-1
Rule: add the tag "Cc: stable@vger.kernel.org" in the sign-off area to have the patch automatically included in the stable tree.
Subject: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
Link: https://lore.kernel.org/stable/20241007132700.982800-2-ymaman%40nvidia.com
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
2024-10-07 13:31 ` kernel test robot
@ 2024-10-07 13:53 ` Danilo Krummrich
1 sibling, 0 replies; 5+ messages in thread
From: Danilo Krummrich @ 2024-10-07 13:53 UTC (permalink / raw)
To: Yonatan Maman
Cc: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
dri-devel, nouveau, linux-kernel, stable, Gal Shalom
On Mon, Oct 07, 2024 at 04:26:59PM +0300, Yonatan Maman wrote:
> From: Yonatan Maman <Ymaman@Nvidia.com>
>
> When `nouveau_dmem_copy_one` is called, the following error occurs:
>
> [272146.675156] nouveau 0000:06:00.0: fifo: PBDMA9: 00000004 [HCE_PRIV]
> ch 1 00000300 00003386
>
> This indicates that a copy push command triggered a Host Copy Engine
> Privileged error on channel 1 (Copy Engine channel). To address this
> issue, modify the Copy Engine channel to allow privileged push commands
>
> Fixes: 6de125383a5c ("drm/nouveau/fifo: expose runlist topology info on all chipsets")
> Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com>
> Signed-off-by: Gal Shalom <GalShalom@Nvidia.com>
Again, why is this signed-off by Gal? If he's a co-author, please add the
corresponding tag.
Please also see my reply to the previous version.
> Reviewed-by: Ben Skeggs <bskeggs@nvidia.com>
> ---
> drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c
> index a58c31089613..0a75ce4c5021 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_drm.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
> @@ -356,7 +356,7 @@ nouveau_accel_ce_init(struct nouveau_drm *drm)
> return;
> }
>
> - ret = nouveau_channel_new(drm, device, false, runm, NvDmaFB, NvDmaTT, &drm->cechan);
> + ret = nouveau_channel_new(drm, device, true, runm, NvDmaFB, NvDmaTT, &drm->cechan);
> if (ret)
> NV_ERROR(drm, "failed to create ce channel, %d\n", ret);
> }
> --
> 2.34.1
>
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2024-10-07 13:54 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-10-07 13:26 Yonatan Maman
2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
2024-10-07 13:31 ` kernel test robot
2024-10-07 13:53 ` Danilo Krummrich
2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.