* Re: [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices()
2026-09-16 7:42 [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices() Wentao Liang
@ 2026-09-16 7:47 ` sashiko-bot
2026-09-16 14:27 ` Deucher, Alexander
2026-09-17 2:20 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-16 7:47 UTC (permalink / raw)
To: Wentao Liang; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/amdkfd: uninitialized pointer dereference in criu_restore_devices()
--
commit 40984d73f07608e70e87d6e7d3692de70675fb26
Author: Wentao Liang <vulab@iscas.ac.cn>
drm/amdkfd: Fix file reference leak in criu_restore_devices()
This commit attempts to fix a file reference count leak in
criu_restore_devices() by calling fput() when a drm_file is already set
on the process device data structure.
Cc: stable@vger.kernel.org
> diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> --- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> +++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> @@ -2380,6 +2380,7 @@ static int criu_restore_devices(struct kfd_process *p,
> }
>
> if (pdd->drm_file) {
> + fput(drm_file);
[Severity: High]
Could this lead to an uninitialized pointer dereference?
Looking at criu_restore_devices(), the variable drm_file is declared as an
uninitialized local variable inside the loop:
for (i = 0; i < args->num_devices; i++) {
...
struct file *drm_file;
...
if (pdd->drm_file) {
fput(drm_file);
...
}
...
drm_file = fget(device_buckets[i].drm_fd);
}
At the point where fput(drm_file) is called in this new error path, drm_file
has not yet been assigned a value via fget().
If this error path is taken on the first iteration, it seems like fput()
would be called on uninitialized stack memory. If it happens on a subsequent
iteration, could this result in a double-free of the reference from the
previous iteration?
> ret = -EINVAL;
> goto exit;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916074216.1973191-1-vulab@iscas.ac.cn?part=1
^ permalink raw reply [flat|nested] 4+ messages in thread* RE: [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices()
2026-09-16 7:42 [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices() Wentao Liang
2026-09-16 7:47 ` sashiko-bot
@ 2026-09-16 14:27 ` Deucher, Alexander
2026-09-17 2:20 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: Deucher, Alexander @ 2026-09-16 14:27 UTC (permalink / raw)
To: Wentao Liang, Kuehling, Felix
Cc: airlied@gmail.com, amd-gfx@lists.freedesktop.org,
Koenig, Christian, Yat Sin, David,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
Bhardwaj, Rajneesh, simona@ffwll.ch, stable@vger.kernel.org
Public
> -----Original Message-----
> From: Wentao Liang <vulab@iscas.ac.cn>
> Sent: Wednesday, September 16, 2026 3:42 AM
> To: Kuehling, Felix <Felix.Kuehling@amd.com>
> Cc: airlied@gmail.com; Deucher, Alexander <Alexander.Deucher@amd.com>;
> amd-gfx@lists.freedesktop.org; Koenig, Christian
> <Christian.Koenig@amd.com>; Yat Sin, David <David.YatSin@amd.com>; dri-
> devel@lists.freedesktop.org; linux-kernel@vger.kernel.org; Bhardwaj,
> Rajneesh <Rajneesh.Bhardwaj@amd.com>; simona@ffwll.ch; Wentao Liang
> <vulab@iscas.ac.cn>; stable@vger.kernel.org
> Subject: [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices()
>
> In criu_restore_devices(), drm_file is obtained using fget(drm_fd). If
> pdd->drm_file is already set, the function returns -EINVAL without
> releasing the acquired reference via fput(drm_file), leading to a file reference
> count leak.
>
> Fix this by adding fput(drm_file) before returning -EINVAL.
>
> Fixes: bef153b70c6e ("drm/amdkfd: CRIU implement gpu_id remapping")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
This was already fixed.
Alex
> ---
> drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> index 03b266b26738..5453fa4ce4fd 100644
> --- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> +++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> @@ -2311,6 +2311,7 @@ static int criu_restore_devices(struct kfd_process
> *p,
> }
>
> if (pdd->drm_file) {
> + fput(drm_file);
> ret = -EINVAL;
> goto exit;
> }
> --
> 2.34.1
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices()
2026-09-16 7:42 [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices() Wentao Liang
2026-09-16 7:47 ` sashiko-bot
2026-09-16 14:27 ` Deucher, Alexander
@ 2026-09-17 2:20 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-09-17 2:20 UTC (permalink / raw)
To: Wentao Liang, Felix.Kuehling
Cc: oe-kbuild-all, airlied, alexander.deucher, amd-gfx,
christian.koenig, david.yatsin, dri-devel, linux-kernel,
rajneesh.bhardwaj, simona, Wentao Liang, stable
Hi Wentao,
kernel test robot noticed the following build warnings:
[auto build test WARNING on drm-misc/drm-misc-next]
[also build test WARNING on linus/master v7.3-rc3 next-20260916]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Wentao-Liang/drm-amdkfd-Fix-file-reference-leak-in-criu_restore_devices/20260916-074216
base: https://gitlab.freedesktop.org/drm/misc/kernel.git drm-misc-next
patch link: https://lore.kernel.org/r/20260916074216.1973191-1-vulab%40iscas.ac.cn
patch subject: [PATCH] drm/amdkfd: Fix file reference leak in criu_restore_devices()
config: x86_64-randconfig-1300-20260917 (https://download.01.org/0day-ci/archive/20260917/202609171036.aewbdced-lkp@intel.com/config)
compiler: clang version 22.1.3 (https://github.com/llvm/llvm-project e9846648fd6183ee6d8cbdb4502213fcf902a211)
sparse: v0.6.5-rc1
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260917/202609171036.aewbdced-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202609171036.aewbdced-lkp@intel.com/
All warnings (new ones prefixed by >>):
>> drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_chardev.c:2383:9: warning: variable 'drm_file' is uninitialized when used here [-Wuninitialized]
2383 | fput(drm_file);
| ^~~~~~~~
drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_chardev.c:2356:24: note: initialize the variable 'drm_file' to silence this warning
2356 | struct file *drm_file;
| ^
| = NULL
1 warning generated.
vim +/drm_file +2383 drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_chardev.c
2330
2331 static int criu_restore_devices(struct kfd_process *p,
2332 struct kfd_ioctl_criu_args *args,
2333 uint64_t *priv_offset,
2334 uint64_t max_priv_data_size)
2335 {
2336 struct kfd_criu_device_bucket *device_buckets;
2337 struct kfd_criu_device_priv_data *device_privs;
2338 int ret = 0;
2339 uint32_t i;
2340
2341 if (args->num_devices != p->n_pdds)
2342 return -EINVAL;
2343
2344 if (*priv_offset + (args->num_devices * sizeof(*device_privs)) > max_priv_data_size)
2345 return -EINVAL;
2346
2347 device_buckets = memdup_array_user((void *)args->devices,
2348 args->num_devices, sizeof(*device_buckets));
2349
2350 if (IS_ERR(device_buckets))
2351 return PTR_ERR(device_buckets);
2352
2353 for (i = 0; i < args->num_devices; i++) {
2354 struct kfd_node *dev;
2355 struct kfd_process_device *pdd;
2356 struct file *drm_file;
2357
2358 /* device private data is not currently used */
2359
2360 if (!device_buckets[i].user_gpu_id) {
2361 pr_err("Invalid user gpu_id\n");
2362 ret = -EINVAL;
2363 goto exit;
2364 }
2365
2366 dev = kfd_device_by_id(device_buckets[i].actual_gpu_id);
2367 if (!dev) {
2368 pr_err("Failed to find device with gpu_id = %x\n",
2369 device_buckets[i].actual_gpu_id);
2370 ret = -EINVAL;
2371 goto exit;
2372 }
2373
2374 pdd = kfd_get_process_device_data(dev, p);
2375 if (!pdd) {
2376 pr_err("Failed to get pdd for gpu_id = %x\n",
2377 device_buckets[i].actual_gpu_id);
2378 ret = -EINVAL;
2379 goto exit;
2380 }
2381
2382 if (pdd->drm_file) {
> 2383 fput(drm_file);
2384 ret = -EINVAL;
2385 goto exit;
2386 }
2387 pdd->user_gpu_id = device_buckets[i].user_gpu_id;
2388
2389 drm_file = fget(device_buckets[i].drm_fd);
2390 if (!drm_file) {
2391 pr_err("Invalid render node file descriptor sent from plugin (%d)\n",
2392 device_buckets[i].drm_fd);
2393 ret = -EINVAL;
2394 goto exit;
2395 }
2396
2397 /* create the vm using render nodes for kfd pdd */
2398 if (kfd_process_device_init_vm(pdd, drm_file)) {
2399 pr_err("could not init vm for given pdd\n");
2400 /* On success, the PDD keeps the drm_file reference */
2401 fput(drm_file);
2402 ret = -EINVAL;
2403 goto exit;
2404 }
2405 /*
2406 * pdd now already has the vm bound to render node so below api won't create a new
2407 * exclusive kfd mapping but use existing one with renderDXXX but is still needed
2408 * for iommu v2 binding and runtime pm.
2409 */
2410 pdd = kfd_bind_process_to_device(dev, p);
2411 if (IS_ERR(pdd)) {
2412 ret = PTR_ERR(pdd);
2413 goto exit;
2414 }
2415
2416 if (!pdd->qpd.proc_doorbells) {
2417 ret = kfd_alloc_process_doorbells(dev->kfd, pdd);
2418 if (ret)
2419 goto exit;
2420 }
2421 }
2422
2423 /*
2424 * We are not copying device private data from user as we are not using the data for now,
2425 * but we still adjust for its private data.
2426 */
2427 *priv_offset += args->num_devices * sizeof(*device_privs);
2428
2429 exit:
2430 kfree(device_buckets);
2431 return ret;
2432 }
2433
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread