From: Matthew Auld <matthew.auld@intel.com>
To: "Thomas Hellström" <thomas.hellstrom@linux.intel.com>,
intel-xe@lists.freedesktop.org
Cc: Matthew Brost <matthew.brost@intel.com>,
Rodrigo Vivi <rodrigo.vivi@intel.com>
Subject: Re: [PATCH] drm/xe/vm: Avoid reserving zero fences
Date: Thu, 8 Feb 2024 15:05:20 +0000 [thread overview]
Message-ID: <4d058e2e-dd9b-4765-b579-c1cdca71ca41@intel.com> (raw)
In-Reply-To: <20240208132115.3132-1-thomas.hellstrom@linux.intel.com>
On 08/02/2024 13:21, Thomas Hellström wrote:
> The function xe_vm_prepare_vma was blindly accepting zero as the
> number of fences and forwarded that to drm_exec_prepare_obj.
>
> However, that leads to an out-of-bounds shift in the
> dma_resv_reserve_fences() and while one could argue that the
> dma_resv code should be robust against that, avoid attempting
> to reserve zero fences.
>
> Relevant stack trace:
>
> [773.183188] ------------[ cut here ]------------
> [773.183199] UBSAN: shift-out-of-bounds in ../include/linux/log2.h:57:13
> [773.183241] shift exponent 64 is too large for 64-bit type 'long unsigned int'
> [773.183254] CPU: 2 PID: 1816 Comm: xe_evict Tainted: G U 6.8.0-rc3-xe #1
> [773.183256] Hardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 2014 10/14/2022
> [773.183257] Call Trace:
> [773.183258] <TASK>
> [773.183260] dump_stack_lvl+0xaf/0xd0
> [773.183266] dump_stack+0x10/0x20
> [773.183283] ubsan_epilogue+0x9/0x40
> [773.183286] __ubsan_handle_shift_out_of_bounds+0x10f/0x170
> [773.183293] dma_resv_reserve_fences.cold+0x2b/0x48
> [773.183295] ? ww_mutex_lock+0x3c/0x110
> [773.183301] drm_exec_prepare_obj+0x45/0x60 [drm_exec]
> [773.183313] xe_vm_prepare_vma+0x33/0x70 [xe]
> [773.183375] xe_vma_destroy_unlocked+0x55/0xa0 [xe]
> [773.183427] xe_vm_close_and_put+0x526/0x940 [xe]
>
> Fixes: 2714d5093620 ("drm/xe: Convert pagefaulting code to use drm_exec")
> Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
> Cc: Matthew Brost <matthew.brost@intel.com>
> Cc: Rodrigo Vivi <rodrigo.vivi@intel.com>
> Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
next prev parent reply other threads:[~2024-02-08 15:05 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-02-08 13:21 [PATCH] drm/xe/vm: Avoid reserving zero fences Thomas Hellström
2024-02-08 13:31 ` ✓ CI.Patch_applied: success for " Patchwork
2024-02-08 13:31 ` ✗ CI.checkpatch: warning " Patchwork
2024-02-08 13:32 ` ✓ CI.KUnit: success " Patchwork
2024-02-08 13:43 ` ✓ CI.Build: " Patchwork
2024-02-08 13:43 ` ✓ CI.Hooks: " Patchwork
2024-02-08 13:45 ` ✓ CI.checksparse: " Patchwork
2024-02-08 14:30 ` ✓ CI.BAT: " Patchwork
2024-02-08 15:05 ` Matthew Auld [this message]
2024-02-08 15:19 ` [PATCH] " Thomas Hellström
2024-02-08 16:57 ` Matthew Brost
2024-02-08 18:19 ` Matthew Auld
2024-02-08 21:33 ` Thomas Hellström
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4d058e2e-dd9b-4765-b579-c1cdca71ca41@intel.com \
--to=matthew.auld@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=matthew.brost@intel.com \
--cc=rodrigo.vivi@intel.com \
--cc=thomas.hellstrom@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox