From: Matthew Brost <matthew.brost@intel.com>
To: <sashiko-reviews@lists.linux.dev>
Cc: <intel-xe@lists.freedesktop.org>
Subject: Re: [PATCH v4 06/25] drm/xe: Add XE_BO_FLAG_PUT_VM_ASYNC
Date: Thu, 3 Sep 2026 17:41:02 -0700 [thread overview]
Message-ID: <apoTnkuBJBRZp2t6@gsse-cloud1.jf.intel.com> (raw)
In-Reply-To: <20260904001827.6B0BD1F00A3E@smtp.kernel.org>
On Fri, Sep 04, 2026 at 12:18:26AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
> - [High] The XE_BO_FLAG_PUT_VM_ASYNC mechanism causes VM reference leaks if xe_bo_put_async() is called when the BO's refcount is greater than 1.
> - [High] Dropping the VM reference synchronously in xe_bo_put_commit causes a Use-After-Free of the shared dma_resv object if TTM defers destruction.
> --
>
> commit 73ce65401a8053bf565b7b064086594d1dafb49a
> Author: Matthew Brost <matthew.brost@intel.com>
>
> drm/xe: Add XE_BO_FLAG_PUT_VM_ASYNC
>
> This commit introduces XE_BO_FLAG_PUT_VM_ASYNC, which indicates that an
> async BO put must also drop an additional reference to the BO's VM. This
> ensures the shared dma-resv object does not disappear before the BO when
> a kernel BO is put asynchronously.
>
> Link: https://patch.msgid.link/20260228013501.106680-7-matthew.brost@intel.com
>
> > diff --git a/drivers/gpu/drm/xe/xe_bo.c b/drivers/gpu/drm/xe/xe_bo.c
> > index dde309821237b..5cde5dff2d481 100644
> > --- a/drivers/gpu/drm/xe/xe_bo.c
> > +++ b/drivers/gpu/drm/xe/xe_bo.c
> > @@ -3989,8 +3989,14 @@ void xe_bo_put_commit(struct llist_head *deferred)
> > if (!freed)
> > return;
> >
> > - llist_for_each_entry_safe(bo, next, freed, freed)
> > + llist_for_each_entry_safe(bo, next, freed, freed) {
> > + struct xe_vm *vm = bo->vm;
> > + bool async = bo->flags & XE_BO_FLAG_PUT_VM_ASYNC;
> > +
> > drm_gem_object_free(&bo->ttm.base.refcount);
> > + if (async)
> > + xe_vm_put(vm);
>
> [Severity: High]
> Does this code leak the VM reference if xe_bo_put_async() is called when the
> BO's refcount is greater than 1?
>
> If xe_bo_put_async() is called while concurrent paths (like show_meminfo or
> xe_bo_evict_all) hold a temporary reference, the BO won't be added to the
> async_list.
>
> Later, when the temporary reference is dropped via a synchronous xe_bo_put(),
> the BO is destroyed by xe_ttm_bo_destroy(), which only drops bo->vm if
> xe_bo_is_user(bo) is true (which is false for kernel PT BOs). Thus, the VM
> reference could be permanently leaked.
>
> [Severity: High]
> Can dropping the VM reference synchronously here cause a use-after-free of
> the shared dma_resv object if TTM defers destruction?
>
> In xe_bo_put_commit(), drm_gem_object_free() drops the GEM reference. If TTM
> concurrently holds an extra reference to the BO (e.g., via
> ttm_bo_get_unless_zero() during an LRU walk), the BO will not be immediately
> destroyed.
>
> However, xe_bo_put_commit() continues and calls xe_vm_put(vm). If this drops
> the last reference to the VM, the VM and its embedded resv are freed.
> Because the BO is still alive and bo->ttm.base.resv points to the freed
> vm->resv, TTM might later attempt to use the freed reservation object.
>
I don't think this reasoning is 100% correct, but the reinit of the ref
count is indeed dangerous. I'll rework this part.
Matt
> > + }
> > }
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260903235842.3401722-1-matthew.brost@intel.com?part=6
next prev parent reply other threads:[~2026-09-04 0:41 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 23:58 [PATCH v4 00/25] CPU binds and ULLS on migration queue Matthew Brost
2026-09-03 23:58 ` [PATCH v4 01/25] drm/xe: Drop struct xe_migrate_pt_update argument from populate/clear vfuns Matthew Brost
2026-09-03 23:58 ` [PATCH v4 02/25] drm/xe: Add xe_migrate_update_pgtables_cpu_execute helper Matthew Brost
2026-09-04 0:15 ` sashiko-bot
2026-09-03 23:58 ` [PATCH v4 03/25] drm/xe: Decouple exec queue idle check from LRC Matthew Brost
2026-09-03 23:58 ` [PATCH v4 04/25] drm/xe: Add job count to GuC exec queue snapshot Matthew Brost
2026-09-03 23:58 ` [PATCH v4 05/25] drm/xe: Update xe_bo_put_deferred arguments to include writeback flag Matthew Brost
2026-09-03 23:58 ` [PATCH v4 06/25] drm/xe: Add XE_BO_FLAG_PUT_VM_ASYNC Matthew Brost
2026-09-04 0:18 ` sashiko-bot
2026-09-04 0:41 ` Matthew Brost [this message]
2026-09-03 23:58 ` [PATCH v4 07/25] drm/xe: Update scheduler job layer to support PT jobs Matthew Brost
2026-09-04 0:25 ` sashiko-bot
2026-09-03 23:58 ` [PATCH v4 08/25] drm/xe: Add helpers to access PT ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 09/25] drm/xe: Add struct xe_pt_job_ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 10/25] drm/xe: Update GuC submission backend to run PT jobs Matthew Brost
2026-09-04 0:36 ` sashiko-bot
2026-09-04 0:57 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 11/25] drm/xe: Store level in struct xe_vm_pgtable_update Matthew Brost
2026-09-04 0:19 ` sashiko-bot
2026-09-03 23:58 ` [PATCH v4 12/25] drm/xe: Don't use migrate exec queue for page fault binds Matthew Brost
2026-09-03 23:58 ` [PATCH v4 13/25] drm/xe: Enable CPU binds for jobs Matthew Brost
2026-09-04 0:31 ` sashiko-bot
2026-09-04 1:04 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 14/25] drm/xe: Remove unused arguments from xe_migrate_pt_update_ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 15/25] drm/xe: Make bind queues operate cross-tile Matthew Brost
2026-09-03 23:58 ` [PATCH v4 16/25] drm/xe: Add CPU bind layer Matthew Brost
2026-09-04 0:31 ` sashiko-bot
2026-09-04 1:18 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 17/25] drm/xe: Add device flag to enable PT mirroring across tiles Matthew Brost
2026-09-04 0:29 ` sashiko-bot
2026-09-04 1:33 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 18/25] drm/xe: Add xe_hw_engine_write_ring_tail Matthew Brost
2026-09-03 23:58 ` [PATCH v4 19/25] drm/xe: Add ULLS support to LRC Matthew Brost
2026-09-03 23:58 ` [PATCH v4 20/25] drm/xe: Add ULLS migration job support to migration layer Matthew Brost
2026-09-04 0:27 ` sashiko-bot
2026-09-04 1:35 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 21/25] drm/xe: Add ULLS migration job support to ring ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 22/25] drm/xe: Add ULLS migration job support to GuC submission Matthew Brost
2026-09-04 0:38 ` sashiko-bot
2026-09-04 1:41 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 23/25] drm/xe: Enter ULLS for migration jobs upon page fault or SVM prefetch Matthew Brost
2026-09-04 0:28 ` sashiko-bot
2026-09-04 1:32 ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 24/25] drm/xe: Add modparam to enable / disable ULLS on migrate queue Matthew Brost
2026-09-03 23:58 ` [PATCH v4 25/25] drm/xe: Document ULLS for migration jobs Matthew Brost
2026-09-04 0:47 ` ✗ CI.checkpatch: warning for CPU binds and ULLS on migration queue (rev6) Patchwork
2026-09-04 0:49 ` ✓ CI.KUnit: success " Patchwork
2026-09-04 1:33 ` ✓ Xe.CI.BAT: " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apoTnkuBJBRZp2t6@gsse-cloud1.jf.intel.com \
--to=matthew.brost@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.