From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 5C8FBC9830E for ; Wed, 30 Sep 2026 05:20:43 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id D98F110F199; Wed, 30 Sep 2026 05:20:42 +0000 (UTC) Authentication-Results: gabe.freedesktop.org; dkim=pass (2048-bit key; unprotected) header.d=intel.com header.i=@intel.com header.b="Lg9KxJ4d"; dkim-atps=neutral Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.15]) by gabe.freedesktop.org (Postfix) with ESMTPS id 6835810F189 for ; Wed, 30 Sep 2026 05:20:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1790745640; x=1822281640; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=zpaOycWoHI/caTiUFAVXCIAChwKflxBC2AoZNI+qqqo=; b=Lg9KxJ4dWELyFx4awiehczTuAMEq/yXxIXC9W8DEMKs0EqNt97dx/VEq HHHiAbtvWTbKBDst9pX0mC8RWiRbd0k7K8Ih7+d9fz387sPVZx8O65sqw u5pWFyRvJQgWxrKanK3/1ADz4px/N7uJYJ9nVWFivu/2mkZ7Y1Nhg26bP +bLJzCNSYvY+jy/PO/A07VedoS9AY5gHfRvASL/uwNQhyqUI4UR10K7ls 0tVBuX+5Dp80GlkGcWzlpiI6F8QT8YbajPLu7aWah+YMdY55IAISMZTEc E8jG8CVmvdQMPel/IO4xMVn4H2j5vFvVZb45IOme6MJhFxCeXk9V8SfVu w==; X-CSE-ConnectionGUID: 4QE5sZzaQrO7loYXymylcQ== X-CSE-MsgGUID: QeWA6RjRQIa6qbPNgrAssA== X-IronPort-AV: E=McAfee;i="6800,10657,11920"; a="94187501" X-IronPort-AV: E=Sophos;i="6.27,132,1787036400"; d="scan'208";a="94187501" Received: from orviesa009.jf.intel.com ([10.64.159.149]) by orvoesa107.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Sep 2026 22:20:40 -0700 X-CSE-ConnectionGUID: FHoZL5q0QISKPrbgW/HY3g== X-CSE-MsgGUID: RNg7YQWCSwStxEubb2yBjA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,132,1787036400"; d="scan'208";a="275614874" Received: from gfx-coremm-kmd02.iind.intel.com ([10.190.238.86]) by orviesa009.jf.intel.com with ESMTP; 29 Sep 2026 22:20:39 -0700 From: Bommu Krishnaiah To: intel-gfx@lists.freedesktop.org Cc: Bommu Krishnaiah , Ashutosh Dixit , Umesh Nerlige Ramappa Subject: [PATCH 1/1] drm/xe/oa: Zero OA buffer at allocation Date: Wed, 30 Sep 2026 11:02:02 +0530 Message-ID: <20260930053202.2232908-2-krishnaiah.bommu@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260930053202.2232908-1-krishnaiah.bommu@intel.com> References: <20260930053202.2232908-1-krishnaiah.bommu@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: intel-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Intel graphics driver community testing & development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: intel-gfx-bounces@lists.freedesktop.org Sender: "Intel-gfx" Zero the OA buffer immediately after allocation because kernel BO pages are not guaranteed to be initialized. This prevents stale data exposure through mmap and fixes the xe_oa tail-address-wrap test. Fixes: 392bf22238ff ("drm/xe/oa/uapi: OA buffer mmap") Assisted-by: GitHub Copilot Cc: Ashutosh Dixit Cc: Umesh Nerlige Ramappa Signed-off-by: Bommu Krishnaiah --- drivers/gpu/drm/xe/xe_oa.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/gpu/drm/xe/xe_oa.c b/drivers/gpu/drm/xe/xe_oa.c index a3484e943c55..3bb8bbef4c37 100644 --- a/drivers/gpu/drm/xe/xe_oa.c +++ b/drivers/gpu/drm/xe/xe_oa.c @@ -914,6 +914,13 @@ static int xe_oa_alloc_oa_buffer(struct xe_oa_stream *stream, size_t size) if (IS_ERR(bo)) return PTR_ERR(bo); + /* + * ttm_bo_type_kernel BOs are not zeroed on allocation, so the buffer can + * hold stale data from previously freed pages. Since the OA buffer is + * mmap'able by userspace, clear it here to avoid leaking kernel memory. + */ + xe_map_memset(stream->oa->xe, &bo->vmap, 0, 0, xe_bo_size(bo)); + stream->oa_buffer.bo = bo; stream->oa_buffer.bounce = kmalloc(stream->oa_buffer.format->size, GFP_KERNEL); -- 2.43.0