From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id BD30CC4345F for ; Thu, 2 May 2024 15:52:28 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id B4728112532; Thu, 2 May 2024 15:52:27 +0000 (UTC) Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by gabe.freedesktop.org (Postfix) with ESMTP id C1FEE112532 for ; Thu, 2 May 2024 15:52:26 +0000 (UTC) Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id C51E8339; Thu, 2 May 2024 08:52:51 -0700 (PDT) Received: from [10.1.36.41] (e122027.cambridge.arm.com [10.1.36.41]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 6D72C3F793; Thu, 2 May 2024 08:52:25 -0700 (PDT) Message-ID: Date: Thu, 2 May 2024 16:52:24 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v3 4/5] drm/panthor: Fix an off-by-one in the heap context retrieval logic To: Boris Brezillon , Liviu Dudau , =?UTF-8?Q?Adri=C3=A1n_Larumbe?= Cc: dri-devel@lists.freedesktop.org, kernel@collabora.com, Eric Smith References: <20240502154025.1425278-1-boris.brezillon@collabora.com> <20240502154025.1425278-5-boris.brezillon@collabora.com> From: Steven Price Content-Language: en-GB In-Reply-To: <20240502154025.1425278-5-boris.brezillon@collabora.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-BeenThere: dri-devel@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Direct Rendering Infrastructure - Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" On 02/05/2024 16:40, Boris Brezillon wrote: > The heap ID is used to index the heap context pool, and allocating > in the [1:MAX_HEAPS_PER_POOL] leads to an off-by-one. This was > originally to avoid returning a zero heap handle, but given the handle > is formed with (vm_id << 16) | heap_id, with vm_id > 0, we already can't > end up with a valid heap handle that's zero. > > v3: > - Allocate in the [0:MAX_HEAPS_PER_POOL-1] range > > v2: > - New patch > > Fixes: 9cca48fa4f89 ("drm/panthor: Add the heap logical block") > Reported-by: Eric Smith > Signed-off-by: Boris Brezillon > Tested-by: Eric Smith Don't we also need to change the xa_init_flags() in panthor_heap_pool_create()? Steve > --- > drivers/gpu/drm/panthor/panthor_heap.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/drivers/gpu/drm/panthor/panthor_heap.c b/drivers/gpu/drm/panthor/panthor_heap.c > index 683bb94761bc..252332f5390f 100644 > --- a/drivers/gpu/drm/panthor/panthor_heap.c > +++ b/drivers/gpu/drm/panthor/panthor_heap.c > @@ -323,7 +323,8 @@ int panthor_heap_create(struct panthor_heap_pool *pool, > if (!pool->vm) { > ret = -EINVAL; > } else { > - ret = xa_alloc(&pool->xa, &id, heap, XA_LIMIT(1, MAX_HEAPS_PER_POOL), GFP_KERNEL); > + ret = xa_alloc(&pool->xa, &id, heap, > + XA_LIMIT(0, MAX_HEAPS_PER_POOL - 1), GFP_KERNEL); > if (!ret) { > void *gpu_ctx = panthor_get_heap_ctx(pool, id); >