From: Matthew Brost <matthew.brost@intel.com>
To: intel-xe@lists.freedesktop.org, dri-devel@lists.freedesktop.org
Cc: freedreno@lists.freedesktop.org, linux-arm-msm@vger.kernel.org,
"Abhinav Kumar" <abhinav.kumar@linux.dev>,
"Alice Ryhl" <aliceryhl@google.com>,
"Anna Maniscalco" <anna.maniscalco2000@gmail.com>,
"Antonino Maniscalco" <antomani103@gmail.com>,
"Boris Brezillon" <boris.brezillon@collabora.com>,
"Danilo Krummrich" <dakr@kernel.org>,
"David Airlie" <airlied@gmail.com>,
"Dmitry Baryshkov" <lumag@kernel.org>,
"Jessica Zhang" <jesszhan0024@gmail.com>,
"Jonathan Corbet" <corbet@lwn.net>,
"Liviu Dudau" <liviu.dudau@arm.com>,
"Lyude Paul" <lyude@redhat.com>,
"Maarten Lankhorst" <maarten.lankhorst@linux.intel.com>,
"Marijn Suijten" <marijn.suijten@somainline.org>,
"Maxime Ripard" <mripard@kernel.org>,
"Randy Dunlap" <rdunlap@infradead.org>,
"Rob Clark" <robin.clark@oss.qualcomm.com>,
"Rodrigo Vivi" <rodrigo.vivi@intel.com>,
"Sean Paul" <sean@poorly.run>,
"Shuah Khan" <skhan@linuxfoundation.org>,
"Simona Vetter" <simona@ffwll.ch>,
"Steven Price" <steven.price@arm.com>,
"Thomas Hellström" <thomas.hellstrom@linux.intel.com>,
"Thomas Zimmermann" <tzimmermann@suse.de>,
stable@vger.kernel.org
Subject: [PATCH v3 4/8] drm/msm: reject a submit_bo table on VM_BIND contexts
Date: Thu, 1 Oct 2026 15:06:28 -0700 [thread overview]
Message-ID: <20261001220632.3190896-5-matthew.brost@intel.com> (raw)
In-Reply-To: <20261001220632.3190896-1-matthew.brost@intel.com>
The uapi says a VM_BIND context must not pass a submit_bo table to
MSM_GEM_SUBMIT and that one will be rejected, but nothing checks
nr_bos. A VM_BIND context which passes one anyway runs the legacy BO
handling against its userspace managed VM:
- submit_lock_objects_vmbind() only locks the objects mapped in the
VM, yet submit_pin_objects() calls msm_gem_get_vma_locked() on every
submit BO. For a BO not mapped in the VM that walks and modifies the
object's gpuva list without its resv held, and has the kernel
allocate a VMA spanning [0, U64_MAX) in a VM whose address space
belongs to userspace.
- Every submit BO holds a vm_bo reference which msm_submit_retire()
drops with only the object's resv held. If userspace unmaps the BO
with VM_BIND while the submit is in flight, that is the last
reference, and drm_gpuvm_bo_destroy() runs without the VM's resv.
Reject nr_bos != 0 on VM_BIND contexts, as documented. Mesa only passes
a submit_bo table when VM_BIND is not enabled.
Fixes: 2e6a8a1fe2b2 ("drm/msm: Add VM_BIND ioctl")
Cc: Abhinav Kumar <abhinav.kumar@linux.dev>
Cc: Alice Ryhl <aliceryhl@google.com>
Cc: Anna Maniscalco <anna.maniscalco2000@gmail.com>
Cc: Antonino Maniscalco <antomani103@gmail.com>
Cc: Boris Brezillon <boris.brezillon@collabora.com>
Cc: Danilo Krummrich <dakr@kernel.org>
Cc: David Airlie <airlied@gmail.com>
Cc: Dmitry Baryshkov <lumag@kernel.org>
Cc: Jessica Zhang <jesszhan0024@gmail.com>
Cc: Jonathan Corbet <corbet@lwn.net>
Cc: Liviu Dudau <liviu.dudau@arm.com>
Cc: Lyude Paul <lyude@redhat.com>
Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
Cc: Marijn Suijten <marijn.suijten@somainline.org>
Cc: Maxime Ripard <mripard@kernel.org>
Cc: Randy Dunlap <rdunlap@infradead.org>
Cc: Rob Clark <robin.clark@oss.qualcomm.com>
Cc: Rodrigo Vivi <rodrigo.vivi@intel.com>
Cc: Sean Paul <sean@poorly.run>
Cc: Shuah Khan <skhan@linuxfoundation.org>
Cc: Simona Vetter <simona@ffwll.ch>
Cc: Steven Price <steven.price@arm.com>
Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Thomas Zimmermann <tzimmermann@suse.de>
Cc: stable@vger.kernel.org
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Assisted-by: LLM
---
v3:
- New patch (Sashiko)
---
drivers/gpu/drm/msm/msm_gem_submit.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/gpu/drm/msm/msm_gem_submit.c b/drivers/gpu/drm/msm/msm_gem_submit.c
index 5862db05297a..1215b388cb40 100644
--- a/drivers/gpu/drm/msm/msm_gem_submit.c
+++ b/drivers/gpu/drm/msm/msm_gem_submit.c
@@ -598,6 +598,12 @@ int msm_ioctl_gem_submit(struct drm_device *dev, void *data,
goto out_post_unlock;
}
+ /* The resident set of a VM_BIND context comes from its VM_BIND ops */
+ if (msm_context_is_vmbind(ctx) && args->nr_bos) {
+ ret = UERR(EINVAL, dev, "submit_bo table not allowed with VM_BIND");
+ goto out_post_unlock;
+ }
+
ring = gpu->rb[queue->ring_nr];
if (args->flags & MSM_SUBMIT_FENCE_FD_OUT) {
--
2.34.1
next prev parent reply other threads:[~2026-10-01 22:06 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 22:06 [PATCH v3 0/8] drm/gpuvm: two pass locking for exec Matthew Brost
2026-10-01 22:06 ` [PATCH v3 1/8] drm/gpuvm: allow locking external objects in two passes Matthew Brost
2026-10-04 19:56 ` Anna Maniscalco
2026-10-01 22:06 ` [PATCH v3 2/8] drm/xe: lock the resident BOs of an exec last Matthew Brost
2026-10-01 22:06 ` [PATCH v3 3/8] drm/panthor: lock the resident BOs of a submit last Matthew Brost
2026-10-05 9:39 ` Boris Brezillon
2026-10-01 22:06 ` Matthew Brost [this message]
2026-10-01 22:06 ` [PATCH v3 5/8] drm/msm: use DRM_GPUVM_RESV_PROTECTED for VM_BIND VMs Matthew Brost
2026-10-01 22:06 ` [PATCH v3 6/8] drm/msm: lock the resident BOs of a VM_BIND submit last Matthew Brost
2026-10-04 20:29 ` Anna Maniscalco
2026-10-01 22:06 ` [PATCH v3 7/8] drm/nouveau: use DRM_GPUVM_RESV_PROTECTED Matthew Brost
2026-10-02 0:06 ` Matthew Brost
2026-10-02 20:17 ` Matthew Brost
2026-10-02 9:13 ` sashiko-bot
2026-10-06 16:50 ` Liviu Dudau
2026-10-01 22:06 ` [PATCH v3 8/8] drm/nouveau: lock the resident BOs of an exec last Matthew Brost
2026-10-01 22:29 ` ✓ CI.KUnit: success for drm/gpuvm: two pass locking for exec (rev3) Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001220632.3190896-5-matthew.brost@intel.com \
--to=matthew.brost@intel.com \
--cc=abhinav.kumar@linux.dev \
--cc=airlied@gmail.com \
--cc=aliceryhl@google.com \
--cc=anna.maniscalco2000@gmail.com \
--cc=antomani103@gmail.com \
--cc=boris.brezillon@collabora.com \
--cc=corbet@lwn.net \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=freedreno@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=jesszhan0024@gmail.com \
--cc=linux-arm-msm@vger.kernel.org \
--cc=liviu.dudau@arm.com \
--cc=lumag@kernel.org \
--cc=lyude@redhat.com \
--cc=maarten.lankhorst@linux.intel.com \
--cc=marijn.suijten@somainline.org \
--cc=mripard@kernel.org \
--cc=rdunlap@infradead.org \
--cc=robin.clark@oss.qualcomm.com \
--cc=rodrigo.vivi@intel.com \
--cc=sean@poorly.run \
--cc=simona@ffwll.ch \
--cc=skhan@linuxfoundation.org \
--cc=stable@vger.kernel.org \
--cc=steven.price@arm.com \
--cc=thomas.hellstrom@linux.intel.com \
--cc=tzimmermann@suse.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox