All of lore.kernel.org
 help / color / mirror / Atom feed
* (no subject)
@ 2024-10-07 13:26 Yonatan Maman
  2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
  2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman
  0 siblings, 2 replies; 5+ messages in thread
From: Yonatan Maman @ 2024-10-07 13:26 UTC (permalink / raw)
  To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
	dri-devel, nouveau
  Cc: Yonatan Maman, linux-kernel, stable

From: Yonatan Maman <Ymaman@Nvidia.com>

Date: Mon, 7 Oct 2024 14:48:26 +0300
Subject: [PATCH v2 0/2] drm/nouveau/dmem: Fix Memory Leaking and Device Channels configuration

This patch series addresses two critical issues in the Nouveau driver
related to device channels, error handling, and memory leaks.

- Memory Leak in migrate_to_ram: The migrate_to_ram function was
  identified as leaking memory when a copy push command fails. This
  results in the function returning a dirty HIGH_USER page, which can
  expose sensitive information and pose a security risk. To mitigate
  this vulnerability, the patch ensures that a zero page is allocated for
  the destination page, thereby preventing memory leaks and enhancing
  driver security in case of failure.

- Privileged Error in Copy Engine Channel: An error was observed when
  the nouveau_dmem_copy_one function is executed, leading to a Host Copy
  Engine Privileged error on channel 1. The patch resolves this by
  adjusting the Copy Engine channel configuration to permit privileged
  push commands, resolving the error.

Changes since V1:
- Fixed version according to Danilo Krummrich's comments.

Yonatan Maman (2):
  nouveau/dmem: Fix privileged error in copy engine channel
  nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error

 drivers/gpu/drm/nouveau/nouveau_dmem.c | 2 +-
 drivers/gpu/drm/nouveau/nouveau_drm.c  | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
  2024-10-07 13:26 Yonatan Maman
@ 2024-10-07 13:26 ` Yonatan Maman
  2024-10-07 13:31   ` kernel test robot
  2024-10-07 13:53   ` Danilo Krummrich
  2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman
  1 sibling, 2 replies; 5+ messages in thread
From: Yonatan Maman @ 2024-10-07 13:26 UTC (permalink / raw)
  To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
	dri-devel, nouveau
  Cc: Yonatan Maman, linux-kernel, stable, Gal Shalom

From: Yonatan Maman <Ymaman@Nvidia.com>

When `nouveau_dmem_copy_one` is called, the following error occurs:

[272146.675156] nouveau 0000:06:00.0: fifo: PBDMA9: 00000004 [HCE_PRIV]
ch 1 00000300 00003386

This indicates that a copy push command triggered a Host Copy Engine
Privileged error on channel 1 (Copy Engine channel). To address this
issue, modify the Copy Engine channel to allow privileged push commands

Fixes: 6de125383a5c ("drm/nouveau/fifo: expose runlist topology info on all chipsets")
Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com>
Signed-off-by: Gal Shalom <GalShalom@Nvidia.com>
Reviewed-by: Ben Skeggs <bskeggs@nvidia.com>
---
 drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c
index a58c31089613..0a75ce4c5021 100644
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -356,7 +356,7 @@ nouveau_accel_ce_init(struct nouveau_drm *drm)
 		return;
 	}
 
-	ret = nouveau_channel_new(drm, device, false, runm, NvDmaFB, NvDmaTT, &drm->cechan);
+	ret = nouveau_channel_new(drm, device, true, runm, NvDmaFB, NvDmaTT, &drm->cechan);
 	if (ret)
 		NV_ERROR(drm, "failed to create ce channel, %d\n", ret);
 }
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error
  2024-10-07 13:26 Yonatan Maman
  2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
@ 2024-10-07 13:27 ` Yonatan Maman
  1 sibling, 0 replies; 5+ messages in thread
From: Yonatan Maman @ 2024-10-07 13:27 UTC (permalink / raw)
  To: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
	dri-devel, nouveau
  Cc: Yonatan Maman, linux-kernel, stable, Gal Shalom

From: Yonatan Maman <Ymaman@Nvidia.com>

A copy push command might fail, causing `migrate_to_ram` to return a
dirty HIGH_USER page to the user.

This exposes a security vulnerability in the nouveau driver. To prevent
memory leaks in `migrate_to_ram` upon a copy error, allocate a zero
page for the destination page.

Fixes: 5be73b690875 ("drm/nouveau/dmem: device memory helpers for SVM")
Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com>
Signed-off-by: Gal Shalom <GalShalom@Nvidia.com>
Reviewed-by: Ben Skeggs <bskeggs@nvidia.com>
---
 drivers/gpu/drm/nouveau/nouveau_dmem.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_dmem.c b/drivers/gpu/drm/nouveau/nouveau_dmem.c
index 6fb65b01d778..097bd3af0719 100644
--- a/drivers/gpu/drm/nouveau/nouveau_dmem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_dmem.c
@@ -193,7 +193,7 @@ static vm_fault_t nouveau_dmem_migrate_to_ram(struct vm_fault *vmf)
 	if (!spage || !(src & MIGRATE_PFN_MIGRATE))
 		goto done;
 
-	dpage = alloc_page_vma(GFP_HIGHUSER, vmf->vma, vmf->address);
+	dpage = alloc_page_vma(GFP_HIGHUSER | __GFP_ZERO, vmf->vma, vmf->address);
 	if (!dpage)
 		goto done;
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
  2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
@ 2024-10-07 13:31   ` kernel test robot
  2024-10-07 13:53   ` Danilo Krummrich
  1 sibling, 0 replies; 5+ messages in thread
From: kernel test robot @ 2024-10-07 13:31 UTC (permalink / raw)
  To: Yonatan Maman; +Cc: stable, oe-kbuild-all

Hi,

Thanks for your patch.

FYI: kernel test robot notices the stable kernel rule is not satisfied.

The check is based on https://www.kernel.org/doc/html/latest/process/stable-kernel-rules.html#option-1

Rule: add the tag "Cc: stable@vger.kernel.org" in the sign-off area to have the patch automatically included in the stable tree.
Subject: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
Link: https://lore.kernel.org/stable/20241007132700.982800-2-ymaman%40nvidia.com

-- 
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki




^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel
  2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
  2024-10-07 13:31   ` kernel test robot
@ 2024-10-07 13:53   ` Danilo Krummrich
  1 sibling, 0 replies; 5+ messages in thread
From: Danilo Krummrich @ 2024-10-07 13:53 UTC (permalink / raw)
  To: Yonatan Maman
  Cc: kherbst, lyude, dakr, airlied, daniel, bskeggs, jglisse,
	dri-devel, nouveau, linux-kernel, stable, Gal Shalom

On Mon, Oct 07, 2024 at 04:26:59PM +0300, Yonatan Maman wrote:
> From: Yonatan Maman <Ymaman@Nvidia.com>
> 
> When `nouveau_dmem_copy_one` is called, the following error occurs:
> 
> [272146.675156] nouveau 0000:06:00.0: fifo: PBDMA9: 00000004 [HCE_PRIV]
> ch 1 00000300 00003386
> 
> This indicates that a copy push command triggered a Host Copy Engine
> Privileged error on channel 1 (Copy Engine channel). To address this
> issue, modify the Copy Engine channel to allow privileged push commands
> 
> Fixes: 6de125383a5c ("drm/nouveau/fifo: expose runlist topology info on all chipsets")
> Signed-off-by: Yonatan Maman <Ymaman@Nvidia.com>
> Signed-off-by: Gal Shalom <GalShalom@Nvidia.com>

Again, why is this signed-off by Gal? If he's a co-author, please add the
corresponding tag.

Please also see my reply to the previous version.

> Reviewed-by: Ben Skeggs <bskeggs@nvidia.com>
> ---
>  drivers/gpu/drm/nouveau/nouveau_drm.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c
> index a58c31089613..0a75ce4c5021 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_drm.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
> @@ -356,7 +356,7 @@ nouveau_accel_ce_init(struct nouveau_drm *drm)
>  		return;
>  	}
>  
> -	ret = nouveau_channel_new(drm, device, false, runm, NvDmaFB, NvDmaTT, &drm->cechan);
> +	ret = nouveau_channel_new(drm, device, true, runm, NvDmaFB, NvDmaTT, &drm->cechan);
>  	if (ret)
>  		NV_ERROR(drm, "failed to create ce channel, %d\n", ret);
>  }
> -- 
> 2.34.1
> 

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2024-10-07 13:54 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-10-07 13:26 Yonatan Maman
2024-10-07 13:26 ` [PATCH v2 1/2] nouveau/dmem: Fix privileged error in copy engine channel Yonatan Maman
2024-10-07 13:31   ` kernel test robot
2024-10-07 13:53   ` Danilo Krummrich
2024-10-07 13:27 ` [PATCH v2 2/2] nouveau/dmem: Fix memory leak in `migrate_to_ram` upon copy error Yonatan Maman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.