From: Stuart Summers <stuart.summers@intel.com>
Cc: intel-xe@lists.freedesktop.org, rodrigo.vivi@intel.com,
matthew.brost@intel.com, umesh.nerlige.ramappa@intel.com,
gustavo.sousa@intel.com, matthew.d.roper@intel.com,
daniele.ceraolospurio@intel.com, shuicheng.lin@intel.com,
Stuart Summers <stuart.summers@intel.com>
Subject: [PATCH 03/15] drm/xe/configfs: Copy wa_bb out under the configfs lock
Date: Mon, 5 Oct 2026 22:06:39 +0000 [thread overview]
Message-ID: <20261005220636.602826-20-stuart.summers@intel.com> (raw)
In-Reply-To: <20261005220636.602826-17-stuart.summers@intel.com>
The ctx_restore_{mid,post}_bb getters handed the caller a pointer into
storage owned by the configfs group and then dropped both the lock and
the group reference. A concurrent store can krealloc() that buffer and
an rmdir can free it outright, leaving the caller in xe_lrc.c to
memcpy() from freed memory. Copy the batch into a caller supplied
buffer while the lock is still held instead, which also folds the
length check the callers were doing into the getters.
Fixes: 6c6988c5e03d ("drm/xe/lrc: Allow to add user commands on context switch")
Fixes: 39ac06f70062 ("drm/xe/configfs: Add post context restore bb")
Signed-off-by: Stuart Summers <stuart.summers@intel.com>
Assisted-by: LLM
---
drivers/gpu/drm/xe/xe_configfs.c | 52 ++++++++++++++++++++++----------
drivers/gpu/drm/xe/xe_configfs.h | 24 +++++++--------
drivers/gpu/drm/xe/xe_lrc.c | 38 +++++++----------------
3 files changed, 59 insertions(+), 55 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_configfs.c b/drivers/gpu/drm/xe/xe_configfs.c
index 1c7a096aa046..6e62fdccb4c4 100644
--- a/drivers/gpu/drm/xe/xe_configfs.c
+++ b/drivers/gpu/drm/xe/xe_configfs.c
@@ -1441,25 +1441,34 @@ bool xe_configfs_get_disable_vram_page_offline(struct pci_dev *pdev)
* xe_configfs_get_ctx_restore_mid_bb - get configfs ctx_restore_mid_bb setting
* @pdev: pci device
* @class: hw engine class
- * @cs: pointer to the bb to use - only valid during probe
+ * @cs: destination buffer for the batch, or NULL to only query the length
+ * @max_len: capacity of @cs, in dwords
*
- * Return: Number of dwords used in the mid_ctx_restore setting in configfs
+ * Copy the configured batch into @cs while holding the configfs lock, so the
+ * caller never gets a pointer to storage owned by the configfs group.
+ *
+ * Return: Number of dwords used in the mid_ctx_restore setting in configfs, or
+ * -ENOSPC if it does not fit in @max_len
*/
-u32 xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
- enum xe_engine_class class,
- const u32 **cs)
+ssize_t xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
+ enum xe_engine_class class,
+ u32 *cs, size_t max_len)
{
struct xe_config_group_device *dev = find_xe_config_group_device(pdev);
- u32 len;
+ ssize_t len;
if (!dev)
return 0;
scoped_guard(mutex, &dev->lock) {
- if (cs)
- *cs = dev->config.ctx_restore_mid_bb[class].cs;
-
len = dev->config.ctx_restore_mid_bb[class].len;
+ if (cs && len) {
+ if (len > max_len)
+ len = -ENOSPC;
+ else
+ memcpy(cs, dev->config.ctx_restore_mid_bb[class].cs,
+ len * sizeof(u32));
+ }
}
config_group_put(&dev->group);
@@ -1470,23 +1479,34 @@ u32 xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
* xe_configfs_get_ctx_restore_post_bb - get configfs ctx_restore_post_bb setting
* @pdev: pci device
* @class: hw engine class
- * @cs: pointer to the bb to use - only valid during probe
+ * @cs: destination buffer for the batch, or NULL to only query the length
+ * @max_len: capacity of @cs, in dwords
*
- * Return: Number of dwords used in the post_ctx_restore setting in configfs
+ * Copy the configured batch into @cs while holding the configfs lock, so the
+ * caller never gets a pointer to storage owned by the configfs group.
+ *
+ * Return: Number of dwords used in the post_ctx_restore setting in configfs, or
+ * -ENOSPC if it does not fit in @max_len
*/
-u32 xe_configfs_get_ctx_restore_post_bb(struct pci_dev *pdev,
- enum xe_engine_class class,
- const u32 **cs)
+ssize_t xe_configfs_get_ctx_restore_post_bb(struct pci_dev *pdev,
+ enum xe_engine_class class,
+ u32 *cs, size_t max_len)
{
struct xe_config_group_device *dev = find_xe_config_group_device(pdev);
- u32 len;
+ ssize_t len;
if (!dev)
return 0;
scoped_guard(mutex, &dev->lock) {
- *cs = dev->config.ctx_restore_post_bb[class].cs;
len = dev->config.ctx_restore_post_bb[class].len;
+ if (cs && len) {
+ if (len > max_len)
+ len = -ENOSPC;
+ else
+ memcpy(cs, dev->config.ctx_restore_post_bb[class].cs,
+ len * sizeof(u32));
+ }
}
config_group_put(&dev->group);
diff --git a/drivers/gpu/drm/xe/xe_configfs.h b/drivers/gpu/drm/xe/xe_configfs.h
index 10a00d6bbf8f..14e49f23306f 100644
--- a/drivers/gpu/drm/xe/xe_configfs.h
+++ b/drivers/gpu/drm/xe/xe_configfs.h
@@ -26,12 +26,12 @@ bool xe_configfs_get_psmi_enabled(struct pci_dev *pdev);
bool xe_configfs_get_enable_multi_queue(struct pci_dev *pdev);
u32 xe_configfs_get_migrate_ulls_period_ms(struct pci_dev *pdev);
bool xe_configfs_get_disable_vram_page_offline(struct pci_dev *pdev);
-u32 xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
- enum xe_engine_class class,
- const u32 **cs);
-u32 xe_configfs_get_ctx_restore_post_bb(struct pci_dev *pdev,
- enum xe_engine_class class,
- const u32 **cs);
+ssize_t xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
+ enum xe_engine_class class,
+ u32 *cs, size_t max_len);
+ssize_t xe_configfs_get_ctx_restore_post_bb(struct pci_dev *pdev,
+ enum xe_engine_class class,
+ u32 *cs, size_t max_len);
#ifdef CONFIG_PCI_IOV
unsigned int xe_configfs_get_max_vfs(struct pci_dev *pdev);
bool xe_configfs_admin_only_pf(struct pci_dev *pdev);
@@ -48,12 +48,12 @@ static inline bool xe_configfs_get_psmi_enabled(struct pci_dev *pdev) { return f
static inline bool xe_configfs_get_enable_multi_queue(struct pci_dev *pdev) { return true; }
static inline u32 xe_configfs_get_migrate_ulls_period_ms(struct pci_dev *pdev) { return 5; }
static inline bool xe_configfs_get_disable_vram_page_offline(struct pci_dev *pdev) { return false; }
-static inline u32 xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
- enum xe_engine_class class,
- const u32 **cs) { return 0; }
-static inline u32 xe_configfs_get_ctx_restore_post_bb(struct pci_dev *pdev,
- enum xe_engine_class class,
- const u32 **cs) { return 0; }
+static inline ssize_t xe_configfs_get_ctx_restore_mid_bb(struct pci_dev *pdev,
+ enum xe_engine_class class,
+ u32 *cs, size_t max_len) { return 0; }
+static inline ssize_t xe_configfs_get_ctx_restore_post_bb(struct pci_dev *pdev,
+ enum xe_engine_class class,
+ u32 *cs, size_t max_len) { return 0; }
#ifdef CONFIG_PCI_IOV
static inline unsigned int xe_configfs_get_max_vfs(struct pci_dev *pdev)
{
diff --git a/drivers/gpu/drm/xe/xe_lrc.c b/drivers/gpu/drm/xe/xe_lrc.c
index de9a9560ecf3..f751687dc568 100644
--- a/drivers/gpu/drm/xe/xe_lrc.c
+++ b/drivers/gpu/drm/xe/xe_lrc.c
@@ -94,7 +94,7 @@ gt_engine_needs_indirect_ctx(struct xe_gt *gt, enum xe_engine_class class)
return true;
if (xe_configfs_get_ctx_restore_mid_bb(to_pci_dev(xe->drm.dev),
- class, NULL))
+ class, NULL, 0) > 0)
return true;
if (gt->ring_ops[class]->emit_aux_table_inv)
@@ -1186,17 +1186,12 @@ static ssize_t setup_configfs_post_ctx_restore_bb(struct xe_lrc *lrc,
bool indirect)
{
struct xe_device *xe = gt_to_xe(lrc->gt);
- const u32 *user_batch;
- u32 *cmd = batch;
- u32 count;
+ ssize_t count;
count = xe_configfs_get_ctx_restore_post_bb(to_pci_dev(xe->drm.dev),
- hwe->class, &user_batch);
- if (!count)
- return 0;
-
- if (count > max_len)
- return -ENOSPC;
+ hwe->class, batch, max_len);
+ if (count <= 0)
+ return count;
/*
* This should be used only for tests and validation. Taint the kernel
@@ -1204,10 +1199,7 @@ static ssize_t setup_configfs_post_ctx_restore_bb(struct xe_lrc *lrc,
*/
add_taint(TAINT_TEST, LOCKDEP_STILL_OK);
- memcpy(cmd, user_batch, count * sizeof(u32));
- cmd += count;
-
- return cmd - batch;
+ return count;
}
static ssize_t setup_configfs_mid_ctx_restore_bb(struct xe_lrc *lrc,
@@ -1216,17 +1208,12 @@ static ssize_t setup_configfs_mid_ctx_restore_bb(struct xe_lrc *lrc,
bool indirect)
{
struct xe_device *xe = gt_to_xe(lrc->gt);
- const u32 *user_batch;
- u32 *cmd = batch;
- u32 count;
+ ssize_t count;
count = xe_configfs_get_ctx_restore_mid_bb(to_pci_dev(xe->drm.dev),
- hwe->class, &user_batch);
- if (!count)
- return 0;
-
- if (count > max_len)
- return -ENOSPC;
+ hwe->class, batch, max_len);
+ if (count <= 0)
+ return count;
/*
* This should be used only for tests and validation. Taint the kernel
@@ -1234,10 +1221,7 @@ static ssize_t setup_configfs_mid_ctx_restore_bb(struct xe_lrc *lrc,
*/
add_taint(TAINT_TEST, LOCKDEP_STILL_OK);
- memcpy(cmd, user_batch, count * sizeof(u32));
- cmd += count;
-
- return cmd - batch;
+ return count;
}
static ssize_t setup_invalidate_state_cache_wa(struct xe_lrc *lrc,
--
2.43.0
next prev parent reply other threads:[~2026-10-05 22:06 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 22:06 [PATCH 00/15] Add new debug infrastructure for configfs Stuart Summers
2026-10-05 22:06 ` [PATCH 01/15] drm/xe: Guard configfs attribute reads in getters Stuart Summers
2026-10-05 22:06 ` [PATCH 02/15] drm/xe/configfs: Fix out-of-bounds read in parse_wa_bb_lines() Stuart Summers
2026-10-05 22:06 ` Stuart Summers [this message]
2026-10-05 22:06 ` [PATCH 04/15] drm/xe: Invert vram_page_offline configfs attribute Stuart Summers
2026-10-05 22:06 ` [PATCH 05/15] drm/xe: Make survivability_mode configfs attribute a bitmap Stuart Summers
2026-10-05 22:06 ` [PATCH 06/15] drm/xe: Sort xe_config_device fields Stuart Summers
2026-10-05 22:06 ` [PATCH 07/15] drm/xe: Split out configfs data structures Stuart Summers
2026-10-05 22:06 ` [PATCH 08/15] drm/xe: Add a new debug focused configfs group Stuart Summers
2026-10-05 22:06 ` [PATCH 09/15] drm/xe: Move debug configfs entries to xe_configfs_debug.c Stuart Summers
2026-10-05 22:06 ` [PATCH 10/15] drm/xe/guc: Add configfs support for guc_log_level Stuart Summers
2026-10-05 22:06 ` [PATCH 11/15] drm/xe/guc: Add support for NPK as a GuC log target Stuart Summers
2026-10-05 22:06 ` [PATCH 12/15] drm/xe: Add infrastructure for debug configfs parameters Stuart Summers
2026-10-05 22:06 ` [PATCH 13/15] drm/xe: Migrate existing debug configfs entries to params infrastructure Stuart Summers
2026-10-05 22:06 ` [PATCH 14/15] drm/xe: Taint kernel when debug configfs parameters are set Stuart Summers
2026-10-05 22:06 ` [PATCH 15/15] drm/xe: Add enable_media module parameter Stuart Summers
2026-10-05 22:13 ` ✗ CI.checkpatch: warning for Add new debug infrastructure for configfs (rev10) Patchwork
2026-10-05 22:15 ` ✓ CI.KUnit: success " Patchwork
2026-10-05 23:17 ` ✓ Xe.CI.BAT: " Patchwork
2026-10-06 6:22 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-10-07 19:13 ` Summers, Stuart
-- strict thread matches above, loose matches on Subject: below --
2026-10-05 19:06 [PATCH 00/15] Add new debug infrastructure for configfs Stuart Summers
2026-10-05 19:06 ` [PATCH 03/15] drm/xe/configfs: Copy wa_bb out under the configfs lock Stuart Summers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005220636.602826-20-stuart.summers@intel.com \
--to=stuart.summers@intel.com \
--cc=daniele.ceraolospurio@intel.com \
--cc=gustavo.sousa@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=matthew.brost@intel.com \
--cc=matthew.d.roper@intel.com \
--cc=rodrigo.vivi@intel.com \
--cc=shuicheng.lin@intel.com \
--cc=umesh.nerlige.ramappa@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox