Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Matthew Brost" <matthew.brost@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v8 17/24] drm/xe: Add device flag to enable PT mirroring across tiles
Date: Fri, 25 Sep 2026 20:46:45 +0000	[thread overview]
Message-ID: <20260925204646.519811F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925201526.1355279-18-matthew.brost@intel.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] drm/xe: Silent drop of PT updates and zaps causing UAF when mirroring is disabled
- [Medium] drm/xe: Resource leak allocating unreachable PT roots when mirroring is disabled
--

commit e6be828aa99db4551a34cd6134379dab648693b1
Author: Matthew Brost <matthew.brost@intel.com>

drm/xe: Add device flag to enable PT mirroring across tiles

This commit introduces a device flag has_pt_mirror to enable or disable
page-table mirroring across tiles for multi-tile devices. It updates VM
creation, page table operations, and rebind logic to accommodate disabled
mirroring.

> diff --git a/drivers/gpu/drm/xe/xe_pt.c b/drivers/gpu/drm/xe/xe_pt.c
> index fbefcfc52dcac..dcef29b56d636 100644
> --- a/drivers/gpu/drm/xe/xe_pt.c
> +++ b/drivers/gpu/drm/xe/xe_pt.c
[ ... ]
> @@ -1046,6 +1051,9 @@ bool xe_pt_zap_ptes(struct xe_tile *tile, struct xe_vma *vma)
>  	if (!(pt_mask & BIT(tile->id)))
>  		return false;
>  
> +	if (pt_mirroring_disabled_for_tile(xe_vma_vm(vma), tile->id))
> +		return true;
> +
>  	(void)xe_pt_walk_shared(&pt->base, pt->level, xe_vma_start(vma),
>  				xe_vma_end(vma), &xe_walk.base);

[Severity: Critical]
If vma->tile_present excludes tile 0 (e.g., mask is 0x2), calls for tile 0
will return false early, and calls for tile 1 will return true here because
mirroring is disabled.

Could this prevent the PTEs from being zapped in the shared root, potentially
causing a use-after-free if pt_root[0] points to freed memory?

[ ... ]
> @@ -2539,9 +2550,21 @@ int xe_pt_update_ops_prepare(struct xe_device *xe, struct xe_vma_ops *vops)
>  	int id, err;
>  
>  	for_each_tile(tile, xe, id) {
> +		struct xe_vm_pgtable_update_ops *pt_update_ops =
> +			&vops->pt_update_ops[id];
> +
>  		if (!vops->pt_update_ops[id].num_ops)
>  			continue;
>  
> +		if (pt_mirroring_disabled_for_tile(vops->vm, id)) {
> +			struct xe_page_reclaim_list *prl = &pt_update_ops->prl;
> +
> +			/* Transfer root PT update ops PRL to current */
> +			*prl = vops->pt_update_ops[0].prl;
> +			xe_page_reclaim_entries_get(prl->entries);
> +			continue;
> +		}
> +

[Severity: Critical]
Similarly, if a PT update operation processes a VMA whose mask excludes tile 0,
tile 0 is skipped because its num_ops is 0, and tile 1 is skipped here
because mirroring is disabled.

This appears to happen in xe_vm_rebind() in drivers/gpu/drm/xe/xe_vm.c, which
was not updated to use adjust_rebind_tile_mask() and still passes
vma->tile_present directly:

drivers/gpu/drm/xe/xe_vm.c:xe_vm_rebind() {
    ...
		err = xe_vm_ops_add_rebind(&vops, vma,
					   vma->tile_present);
    ...
}

Could this cause PT updates and invalidations to be silently dropped entirely,
leaving stale page tables?

> diff --git a/drivers/gpu/drm/xe/xe_vm.c b/drivers/gpu/drm/xe/xe_vm.c
> index 0f542f47b9a84..f450e1c6f7500 100644
> --- a/drivers/gpu/drm/xe/xe_vm.c
> +++ b/drivers/gpu/drm/xe/xe_vm.c
[ ... ]
> @@ -1739,7 +1749,8 @@ struct xe_vm *xe_vm_create(struct xe_device *xe, u32 flags, struct xe_file *xef)
>  
>  		for_each_tile(tile, xe, id) {
>  			if (flags & XE_VM_FLAG_MIGRATION &&
> -			    tile->id != XE_VM_FLAG_TILE_ID(flags))
> +			    tile->id != XE_VM_FLAG_TILE_ID(flags) &&
> +			    (vm->xe->info.has_pt_mirror || id))
>  				continue;
>  
>  			vm->pt_root[id] = xe_pt_create(vm, tile, xe->info.vm_max_level,
>  						       &exec);

[Severity: Medium]
For normal (non-migration) VMs, this loop seems to allocate pt_root[id] and
associated scratch buffers for all tiles, even when PT mirroring is disabled.

Since xe_vm_pt_root(vm, id) will always return pt_root[0] when
!has_pt_mirror, does this leak VRAM and system memory by allocating orphaned
PT roots and scratch buffers for id > 0?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925201526.1355279-1-matthew.brost@intel.com?part=17

  reply	other threads:[~2026-09-25 20:46 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 20:15 [PATCH v8 00/24] CPU binds and ULLS on migration queue Matthew Brost
2026-09-25 20:15 ` [PATCH v8 01/24] drm/xe: reference VM from PT BOs Matthew Brost
2026-09-25 20:15 ` [PATCH v8 02/24] drm/xe: Drop struct xe_migrate_pt_update argument from populate/clear vfuns Matthew Brost
2026-09-25 20:15 ` [PATCH v8 03/24] drm/xe: Add xe_migrate_update_pgtables_cpu_execute helper Matthew Brost
2026-09-25 20:15 ` [PATCH v8 04/24] drm/xe: Decouple exec queue idle check from LRC Matthew Brost
2026-09-25 20:15 ` [PATCH v8 05/24] drm/xe: Add job count to GuC exec queue snapshot Matthew Brost
2026-09-25 20:15 ` [PATCH v8 06/24] drm/xe: Update xe_bo_put_deferred arguments to include writeback flag Matthew Brost
2026-09-25 20:15 ` [PATCH v8 07/24] drm/xe: Update scheduler job layer to support PT jobs Matthew Brost
2026-09-25 20:15 ` [PATCH v8 08/24] drm/xe: Add helpers to access PT ops Matthew Brost
2026-09-25 20:15 ` [PATCH v8 09/24] drm/xe: Add struct xe_pt_job_ops Matthew Brost
2026-09-25 20:15 ` [PATCH v8 10/24] drm/xe: Update GuC submission backend to run PT jobs Matthew Brost
2026-09-25 20:38   ` sashiko-bot
2026-09-25 23:20   ` Ghimiray, Himal Prasad
2026-09-25 20:15 ` [PATCH v8 11/24] drm/xe: Store level in struct xe_vm_pgtable_update Matthew Brost
2026-09-25 20:15 ` [PATCH v8 12/24] drm/xe: Don't use migrate exec queue for page fault binds Matthew Brost
2026-09-25 20:15 ` [PATCH v8 13/24] drm/xe: Enable CPU binds for jobs Matthew Brost
2026-09-25 20:39   ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 14/24] drm/xe: Remove unused arguments from xe_migrate_pt_update_ops Matthew Brost
2026-09-25 20:15 ` [PATCH v8 15/24] drm/xe: Make bind queues operate cross-tile Matthew Brost
2026-09-25 20:15 ` [PATCH v8 16/24] drm/xe: Add CPU bind layer Matthew Brost
2026-09-25 20:15 ` [PATCH v8 17/24] drm/xe: Add device flag to enable PT mirroring across tiles Matthew Brost
2026-09-25 20:46   ` sashiko-bot [this message]
2026-09-25 20:15 ` [PATCH v8 18/24] drm/xe: Add ULLS support to LRC Matthew Brost
2026-09-25 20:15 ` [PATCH v8 19/24] drm/xe: Add ULLS migration job support to migration layer Matthew Brost
2026-09-25 20:41   ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 20/24] drm/xe: Add ULLS migration job support to ring ops Matthew Brost
2026-09-25 20:48   ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 21/24] drm/xe: Add ULLS migration job support to GuC submission Matthew Brost
2026-09-25 20:45   ` sashiko-bot
2026-09-25 20:15 ` [PATCH v8 22/24] drm/xe: Enter ULLS for migration jobs upon page fault or SVM prefetch Matthew Brost
2026-09-25 20:15 ` [PATCH v8 23/24] drm/xe: add migrate ULLS period configfs attribute Matthew Brost
2026-09-25 20:15 ` [PATCH v8 24/24] drm/xe: Document ULLS for migration jobs Matthew Brost
2026-09-25 21:02 ` ✗ CI.checkpatch: warning for CPU binds and ULLS on migration queue (rev10) Patchwork
2026-09-25 21:04 ` ✓ CI.KUnit: success " Patchwork
2026-09-25 22:12 ` ✓ Xe.CI.BAT: " Patchwork
2026-09-26  7:40 ` ✗ Xe.CI.FULL: failure " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925204646.519811F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=matthew.brost@intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox