From: sashiko-bot@kernel.org
To: "Matthew Brost" <matthew.brost@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v8 17/24] drm/xe: Add device flag to enable PT mirroring across tiles
Date: Fri, 25 Sep 2026 20:46:45 +0000 [thread overview]
Message-ID: <20260925204646.519811F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925201526.1355279-18-matthew.brost@intel.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] drm/xe: Silent drop of PT updates and zaps causing UAF when mirroring is disabled
- [Medium] drm/xe: Resource leak allocating unreachable PT roots when mirroring is disabled
--
commit e6be828aa99db4551a34cd6134379dab648693b1
Author: Matthew Brost <matthew.brost@intel.com>
drm/xe: Add device flag to enable PT mirroring across tiles
This commit introduces a device flag has_pt_mirror to enable or disable
page-table mirroring across tiles for multi-tile devices. It updates VM
creation, page table operations, and rebind logic to accommodate disabled
mirroring.
> diff --git a/drivers/gpu/drm/xe/xe_pt.c b/drivers/gpu/drm/xe/xe_pt.c
> index fbefcfc52dcac..dcef29b56d636 100644
> --- a/drivers/gpu/drm/xe/xe_pt.c
> +++ b/drivers/gpu/drm/xe/xe_pt.c
[ ... ]
> @@ -1046,6 +1051,9 @@ bool xe_pt_zap_ptes(struct xe_tile *tile, struct xe_vma *vma)
> if (!(pt_mask & BIT(tile->id)))
> return false;
>
> + if (pt_mirroring_disabled_for_tile(xe_vma_vm(vma), tile->id))
> + return true;
> +
> (void)xe_pt_walk_shared(&pt->base, pt->level, xe_vma_start(vma),
> xe_vma_end(vma), &xe_walk.base);
[Severity: Critical]
If vma->tile_present excludes tile 0 (e.g., mask is 0x2), calls for tile 0
will return false early, and calls for tile 1 will return true here because
mirroring is disabled.
Could this prevent the PTEs from being zapped in the shared root, potentially
causing a use-after-free if pt_root[0] points to freed memory?
[ ... ]
> @@ -2539,9 +2550,21 @@ int xe_pt_update_ops_prepare(struct xe_device *xe, struct xe_vma_ops *vops)
> int id, err;
>
> for_each_tile(tile, xe, id) {
> + struct xe_vm_pgtable_update_ops *pt_update_ops =
> + &vops->pt_update_ops[id];
> +
> if (!vops->pt_update_ops[id].num_ops)
> continue;
>
> + if (pt_mirroring_disabled_for_tile(vops->vm, id)) {
> + struct xe_page_reclaim_list *prl = &pt_update_ops->prl;
> +
> + /* Transfer root PT update ops PRL to current */
> + *prl = vops->pt_update_ops[0].prl;
> + xe_page_reclaim_entries_get(prl->entries);
> + continue;
> + }
> +
[Severity: Critical]
Similarly, if a PT update operation processes a VMA whose mask excludes tile 0,
tile 0 is skipped because its num_ops is 0, and tile 1 is skipped here
because mirroring is disabled.
This appears to happen in xe_vm_rebind() in drivers/gpu/drm/xe/xe_vm.c, which
was not updated to use adjust_rebind_tile_mask() and still passes
vma->tile_present directly:
drivers/gpu/drm/xe/xe_vm.c:xe_vm_rebind() {
...
err = xe_vm_ops_add_rebind(&vops, vma,
vma->tile_present);
...
}
Could this cause PT updates and invalidations to be silently dropped entirely,
leaving stale page tables?
> diff --git a/drivers/gpu/drm/xe/xe_vm.c b/drivers/gpu/drm/xe/xe_vm.c
> index 0f542f47b9a84..f450e1c6f7500 100644
> --- a/drivers/gpu/drm/xe/xe_vm.c
> +++ b/drivers/gpu/drm/xe/xe_vm.c
[ ... ]
> @@ -1739,7 +1749,8 @@ struct xe_vm *xe_vm_create(struct xe_device *xe, u32 flags, struct xe_file *xef)
>
> for_each_tile(tile, xe, id) {
> if (flags & XE_VM_FLAG_MIGRATION &&
> - tile->id != XE_VM_FLAG_TILE_ID(flags))
> + tile->id != XE_VM_FLAG_TILE_ID(flags) &&
> + (vm->xe->info.has_pt_mirror || id))
> continue;
>
> vm->pt_root[id] = xe_pt_create(vm, tile, xe->info.vm_max_level,
> &exec);
[Severity: Medium]
For normal (non-migration) VMs, this loop seems to allocate pt_root[id] and
associated scratch buffers for all tiles, even when PT mirroring is disabled.
Since xe_vm_pt_root(vm, id) will always return pt_root[0] when
!has_pt_mirror, does this leak VRAM and system memory by allocating orphaned
PT roots and scratch buffers for id > 0?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925201526.1355279-1-matthew.brost@intel.com?part=17
next prev parent reply other threads:[~2026-09-25 20:46 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 20:15 [PATCH v8 00/24] CPU binds and ULLS on migration queue Matthew Brost
2026-09-25 20:15 ` [PATCH v8 01/24] drm/xe: reference VM from PT BOs Matthew Brost
2026-09-25 20:15 ` [PATCH v8 02/24] drm/xe: Drop struct xe_migrate_pt_update argument from populate/clear vfuns Matthew Brost
2026-09-25 20:15 ` [PATCH v8 03/24] drm/xe: Add xe_migrate_update_pgtables_cpu_execute helper Matthew Brost
2026-09-25 20:15 ` [PATCH v8 04/24] drm/xe: Decouple exec queue idle check from LRC Matthew Brost
2026-09-25 20:15 ` [PATCH v8 05/24] drm/xe: Add job count to GuC exec queue snapshot Matthew Brost
2026-09-25 20:15 ` [PATCH v8 06/24] drm/xe: Update xe_bo_put_deferred arguments to include writeback flag Matthew Brost
2026-09-25 20:15 ` [PATCH v8 07/24] drm/xe: Update scheduler job layer to support PT jobs Matthew Brost
2026-09-25 20:15 ` [PATCH v8 08/24] drm/xe: Add helpers to access PT ops Matthew Brost
2026-09-25 20:15 ` [PATCH v8 09/24] drm/xe: Add struct xe_pt_job_ops Matthew Brost
2026-09-25 20:15 ` [PATCH v8 10/24] drm/xe: Update GuC submission backend to run PT jobs Matthew Brost
2026-09-25 20:38 ` sashiko-bot
2026-09-25 23:20 ` Ghimiray, Himal Prasad
2026-09-25 20:15 ` [PATCH v8 11/24] drm/xe: Store level in struct xe_vm_pgtable_update Matthew Brost
2026-09-25 20:15 ` [PATCH v8 12/24] drm/xe: Don't use migrate exec queue for page fault binds Matthew Brost
2026-09-25 20:15 ` [PATCH v8 13/24] drm/xe: Enable CPU binds for jobs Matthew Brost
2026-09-25 20:39 ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 14/24] drm/xe: Remove unused arguments from xe_migrate_pt_update_ops Matthew Brost
2026-09-25 20:15 ` [PATCH v8 15/24] drm/xe: Make bind queues operate cross-tile Matthew Brost
2026-09-25 20:15 ` [PATCH v8 16/24] drm/xe: Add CPU bind layer Matthew Brost
2026-09-25 20:15 ` [PATCH v8 17/24] drm/xe: Add device flag to enable PT mirroring across tiles Matthew Brost
2026-09-25 20:46 ` sashiko-bot [this message]
2026-09-25 20:15 ` [PATCH v8 18/24] drm/xe: Add ULLS support to LRC Matthew Brost
2026-09-25 20:15 ` [PATCH v8 19/24] drm/xe: Add ULLS migration job support to migration layer Matthew Brost
2026-09-25 20:41 ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 20/24] drm/xe: Add ULLS migration job support to ring ops Matthew Brost
2026-09-25 20:48 ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 21/24] drm/xe: Add ULLS migration job support to GuC submission Matthew Brost
2026-09-25 20:45 ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 22/24] drm/xe: Enter ULLS for migration jobs upon page fault or SVM prefetch Matthew Brost
2026-09-25 20:15 ` [PATCH v8 23/24] drm/xe: add migrate ULLS period configfs attribute Matthew Brost
2026-09-25 20:15 ` [PATCH v8 24/24] drm/xe: Document ULLS for migration jobs Matthew Brost
2026-09-25 21:02 ` ✗ CI.checkpatch: warning for CPU binds and ULLS on migration queue (rev10) Patchwork
2026-09-25 21:04 ` ✓ CI.KUnit: success " Patchwork
2026-09-25 22:12 ` ✓ Xe.CI.BAT: " Patchwork
2026-09-26 7:40 ` ✗ Xe.CI.FULL: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925204646.519811F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=matthew.brost@intel.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox