* [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback
@ 2026-05-29 15:28 Lizhi Hou
2026-05-31 14:18 ` Mario Limonciello
0 siblings, 1 reply; 5+ messages in thread
From: Lizhi Hou @ 2026-05-29 15:28 UTC (permalink / raw)
To: ogabbay, quic_jhugo, dri-devel, mario.limonciello,
karol.wachowski
Cc: Lizhi Hou, linux-kernel, max.zhen, sonal.santan
aie2_sched_job_free() accesses job->drv_cmd for tracing purposes. However,
job->drv_cmd is owned by the caller and may already have been freed when
the job free callback runs, leading to a potential use-after-free.
Remove the job->drv_cmd access from aie2_sched_job_free().
Fixes: 8711eb2dde2e ("accel/amdxdna: Improve tracing for job lifecycle and mailbox RX worker")
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
---
drivers/accel/amdxdna/aie2_ctx.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/amdxdna/aie2_ctx.c
index 658a5fb1fda6..2ad343728782 100644
--- a/drivers/accel/amdxdna/aie2_ctx.c
+++ b/drivers/accel/amdxdna/aie2_ctx.c
@@ -437,8 +437,9 @@ static void aie2_sched_job_free(struct drm_sched_job *sched_job)
struct amdxdna_sched_job *job = drm_job_to_xdna_job(sched_job);
struct amdxdna_hwctx *hwctx = job->hwctx;
+ /* job->drv_cmd could be freed, so use DEFAULT_IO */
trace_xdna_job(sched_job, hwctx->name, "job free",
- job->seq, job->drv_cmd ? job->drv_cmd->opcode : DEFAULT_IO);
+ job->seq, DEFAULT_IO);
if (!job->job_done)
up(&hwctx->priv->job_sem);
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback
2026-05-29 15:28 [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback Lizhi Hou
@ 2026-05-31 14:18 ` Mario Limonciello
2026-06-01 15:18 ` Lizhi Hou
0 siblings, 1 reply; 5+ messages in thread
From: Mario Limonciello @ 2026-05-31 14:18 UTC (permalink / raw)
To: Lizhi Hou, ogabbay, quic_jhugo, dri-devel, karol.wachowski
Cc: linux-kernel, max.zhen, sonal.santan
On 5/29/26 17:28, Lizhi Hou wrote:
> aie2_sched_job_free() accesses job->drv_cmd for tracing purposes. However,
> job->drv_cmd is owned by the caller and may already have been freed when
> the job free callback runs, leading to a potential use-after-free.
>
> Remove the job->drv_cmd access from aie2_sched_job_free().
>
> Fixes: 8711eb2dde2e ("accel/amdxdna: Improve tracing for job lifecycle and mailbox RX worker")
> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
> ---
> drivers/accel/amdxdna/aie2_ctx.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/amdxdna/aie2_ctx.c
> index 658a5fb1fda6..2ad343728782 100644
> --- a/drivers/accel/amdxdna/aie2_ctx.c
> +++ b/drivers/accel/amdxdna/aie2_ctx.c
> @@ -437,8 +437,9 @@ static void aie2_sched_job_free(struct drm_sched_job *sched_job)
> struct amdxdna_sched_job *job = drm_job_to_xdna_job(sched_job);
> struct amdxdna_hwctx *hwctx = job->hwctx;
>
> + /* job->drv_cmd could be freed, so use DEFAULT_IO */
> trace_xdna_job(sched_job, hwctx->name, "job free",
> - job->seq, job->drv_cmd ? job->drv_cmd->opcode : DEFAULT_IO);
> + job->seq, DEFAULT_IO);
Could this still be a race with dov->drv_cmd being valid when the first
part of the expression is evaluated (job->drv_cmd) but invalid when
job->drv_cmd->opcode is accessed?
> if (!job->job_done)
> up(&hwctx->priv->job_sem);
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback
2026-05-31 14:18 ` Mario Limonciello
@ 2026-06-01 15:18 ` Lizhi Hou
2026-06-03 18:34 ` Mario Limonciello
0 siblings, 1 reply; 5+ messages in thread
From: Lizhi Hou @ 2026-06-01 15:18 UTC (permalink / raw)
To: Mario Limonciello, ogabbay, quic_jhugo, dri-devel,
karol.wachowski
Cc: linux-kernel, max.zhen, sonal.santan
On 5/31/26 07:18, Mario Limonciello wrote:
>
>
> On 5/29/26 17:28, Lizhi Hou wrote:
>> aie2_sched_job_free() accesses job->drv_cmd for tracing purposes.
>> However,
>> job->drv_cmd is owned by the caller and may already have been freed when
>> the job free callback runs, leading to a potential use-after-free.
>>
>> Remove the job->drv_cmd access from aie2_sched_job_free().
>>
>> Fixes: 8711eb2dde2e ("accel/amdxdna: Improve tracing for job
>> lifecycle and mailbox RX worker")
>> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
>> ---
>> drivers/accel/amdxdna/aie2_ctx.c | 3 ++-
>> 1 file changed, 2 insertions(+), 1 deletion(-)
>>
>> diff --git a/drivers/accel/amdxdna/aie2_ctx.c
>> b/drivers/accel/amdxdna/aie2_ctx.c
>> index 658a5fb1fda6..2ad343728782 100644
>> --- a/drivers/accel/amdxdna/aie2_ctx.c
>> +++ b/drivers/accel/amdxdna/aie2_ctx.c
>> @@ -437,8 +437,9 @@ static void aie2_sched_job_free(struct
>> drm_sched_job *sched_job)
>> struct amdxdna_sched_job *job = drm_job_to_xdna_job(sched_job);
>> struct amdxdna_hwctx *hwctx = job->hwctx;
>> + /* job->drv_cmd could be freed, so use DEFAULT_IO */
>> trace_xdna_job(sched_job, hwctx->name, "job free",
>> - job->seq, job->drv_cmd ? job->drv_cmd->opcode :
>> DEFAULT_IO);
>> + job->seq, DEFAULT_IO);
>
> Could this still be a race with dov->drv_cmd being valid when the
> first part of the expression is evaluated (job->drv_cmd) but invalid
> when job->drv_cmd->opcode is accessed?
When aie2_sched_job_free() is called, the job->drv_cmd could already be
freed. So it should never access job->drv_cmd at all. The entire
expression "job->drv_cmd ? job->drv_cmd->opcode : DEFAULT_IO" is removed.
Lizhi
>
>> if (!job->job_done)
>> up(&hwctx->priv->job_sem);
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback
2026-06-01 15:18 ` Lizhi Hou
@ 2026-06-03 18:34 ` Mario Limonciello
2026-06-03 20:17 ` Lizhi Hou
0 siblings, 1 reply; 5+ messages in thread
From: Mario Limonciello @ 2026-06-03 18:34 UTC (permalink / raw)
To: Lizhi Hou, ogabbay, quic_jhugo, dri-devel, karol.wachowski
Cc: linux-kernel, max.zhen, sonal.santan
On 6/1/26 10:18, Lizhi Hou wrote:
>
> On 5/31/26 07:18, Mario Limonciello wrote:
>>
>>
>> On 5/29/26 17:28, Lizhi Hou wrote:
>>> aie2_sched_job_free() accesses job->drv_cmd for tracing purposes.
>>> However,
>>> job->drv_cmd is owned by the caller and may already have been freed when
>>> the job free callback runs, leading to a potential use-after-free.
>>>
>>> Remove the job->drv_cmd access from aie2_sched_job_free().
>>>
>>> Fixes: 8711eb2dde2e ("accel/amdxdna: Improve tracing for job
>>> lifecycle and mailbox RX worker")
>>> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
>>> ---
>>> drivers/accel/amdxdna/aie2_ctx.c | 3 ++-
>>> 1 file changed, 2 insertions(+), 1 deletion(-)
>>>
>>> diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/
>>> amdxdna/aie2_ctx.c
>>> index 658a5fb1fda6..2ad343728782 100644
>>> --- a/drivers/accel/amdxdna/aie2_ctx.c
>>> +++ b/drivers/accel/amdxdna/aie2_ctx.c
>>> @@ -437,8 +437,9 @@ static void aie2_sched_job_free(struct
>>> drm_sched_job *sched_job)
>>> struct amdxdna_sched_job *job = drm_job_to_xdna_job(sched_job);
>>> struct amdxdna_hwctx *hwctx = job->hwctx;
>>> + /* job->drv_cmd could be freed, so use DEFAULT_IO */
>>> trace_xdna_job(sched_job, hwctx->name, "job free",
>>> - job->seq, job->drv_cmd ? job->drv_cmd->opcode :
>>> DEFAULT_IO);
>>> + job->seq, DEFAULT_IO);
>>
>> Could this still be a race with dov->drv_cmd being valid when the
>> first part of the expression is evaluated (job->drv_cmd) but invalid
>> when job->drv_cmd->opcode is accessed?
>
> When aie2_sched_job_free() is called, the job->drv_cmd could already be
> freed. So it should never access job->drv_cmd at all. The entire
> expression "job->drv_cmd ? job->drv_cmd->opcode : DEFAULT_IO" is removed.
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
>
> Lizhi
>
>>
>>> if (!job->job_done)
>>> up(&hwctx->priv->job_sem);
>>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback
2026-06-03 18:34 ` Mario Limonciello
@ 2026-06-03 20:17 ` Lizhi Hou
0 siblings, 0 replies; 5+ messages in thread
From: Lizhi Hou @ 2026-06-03 20:17 UTC (permalink / raw)
To: Mario Limonciello, ogabbay, quic_jhugo, dri-devel,
karol.wachowski
Cc: linux-kernel, max.zhen, sonal.santan
Applied to drm-misc-next-fixes
On 6/3/26 11:34, Mario Limonciello wrote:
>
>
> On 6/1/26 10:18, Lizhi Hou wrote:
>>
>> On 5/31/26 07:18, Mario Limonciello wrote:
>>>
>>>
>>> On 5/29/26 17:28, Lizhi Hou wrote:
>>>> aie2_sched_job_free() accesses job->drv_cmd for tracing purposes.
>>>> However,
>>>> job->drv_cmd is owned by the caller and may already have been freed
>>>> when
>>>> the job free callback runs, leading to a potential use-after-free.
>>>>
>>>> Remove the job->drv_cmd access from aie2_sched_job_free().
>>>>
>>>> Fixes: 8711eb2dde2e ("accel/amdxdna: Improve tracing for job
>>>> lifecycle and mailbox RX worker")
>>>> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
>>>> ---
>>>> drivers/accel/amdxdna/aie2_ctx.c | 3 ++-
>>>> 1 file changed, 2 insertions(+), 1 deletion(-)
>>>>
>>>> diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/
>>>> amdxdna/aie2_ctx.c
>>>> index 658a5fb1fda6..2ad343728782 100644
>>>> --- a/drivers/accel/amdxdna/aie2_ctx.c
>>>> +++ b/drivers/accel/amdxdna/aie2_ctx.c
>>>> @@ -437,8 +437,9 @@ static void aie2_sched_job_free(struct
>>>> drm_sched_job *sched_job)
>>>> struct amdxdna_sched_job *job = drm_job_to_xdna_job(sched_job);
>>>> struct amdxdna_hwctx *hwctx = job->hwctx;
>>>> + /* job->drv_cmd could be freed, so use DEFAULT_IO */
>>>> trace_xdna_job(sched_job, hwctx->name, "job free",
>>>> - job->seq, job->drv_cmd ? job->drv_cmd->opcode :
>>>> DEFAULT_IO);
>>>> + job->seq, DEFAULT_IO);
>>>
>>> Could this still be a race with dov->drv_cmd being valid when the
>>> first part of the expression is evaluated (job->drv_cmd) but invalid
>>> when job->drv_cmd->opcode is accessed?
>>
>> When aie2_sched_job_free() is called, the job->drv_cmd could already
>> be freed. So it should never access job->drv_cmd at all. The entire
>> expression "job->drv_cmd ? job->drv_cmd->opcode : DEFAULT_IO" is
>> removed.
> Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
>>
>> Lizhi
>>
>>>
>>>> if (!job->job_done)
>>>> up(&hwctx->priv->job_sem);
>>>
>
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-06-03 20:17 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-05-29 15:28 [PATCH V1] accel/amdxdna: Remove drv_cmd tracing from job free callback Lizhi Hou
2026-05-31 14:18 ` Mario Limonciello
2026-06-01 15:18 ` Lizhi Hou
2026-06-03 18:34 ` Mario Limonciello
2026-06-03 20:17 ` Lizhi Hou
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox