From: Steven Price <steven.price@arm.com>
To: Simona Vetter <simona.vetter@ffwll.ch>,
DRI Development <dri-devel@lists.freedesktop.org>
Cc: "Intel Xe Development" <intel-xe@lists.freedesktop.org>,
"Adrián Larumbe" <adrian.larumbe@collabora.com>,
"Boris Brezillon" <boris.brezillon@collabora.com>,
"Liviu Dudau" <liviu.dudau@arm.com>,
"Simona Vetter" <simona.vetter@intel.com>
Subject: Re: [PATCH] drm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code
Date: Wed, 9 Jul 2025 16:48:21 +0100 [thread overview]
Message-ID: <6fe2409f-b561-4546-92e1-dd7f8d45ef12@arm.com> (raw)
In-Reply-To: <20250709135220.1428931-1-simona.vetter@ffwll.ch>
On 09/07/2025 14:52, Simona Vetter wrote:
> The object is potentially already gone after the drm_gem_object_put().
> In general the object should be fully constructed before calling
> drm_gem_handle_create(), except the debugfs tracking uses a separate
> lock and list and separate flag to denotate whether the object is
> actually initilized.
>
> Since I'm touching this all anyway simplify this by only adding the
> object to the debugfs when it's ready for that, which allows us to
> delete that separate flag. panthor_gem_debugfs_bo_rm() already checks
> whether we've actually been added to the list or this is some error
> path cleanup.
>
> v2: Fix build issues for !CONFIG_DEBUGFS (Adrián)
>
> v3: Add linebreak and remove outdated comment (Liviu)
>
> Fixes: a3707f53eb3f ("drm/panthor: show device-wide list of DRM GEM objects over DebugFS")
> Cc: Adrián Larumbe <adrian.larumbe@collabora.com>
> Cc: Boris Brezillon <boris.brezillon@collabora.com>
> Cc: Steven Price <steven.price@arm.com>
> Cc: Liviu Dudau <liviu.dudau@arm.com>
> Reviewed-by: Liviu Dudau <liviu.dudau@arm.com>
> Signed-off-by: Simona Vetter <simona.vetter@intel.com>
> Signed-off-by: Simona Vetter <simona.vetter@ffwll.ch>
Reviewed-by: Steven Price <steven.price@arm.com>
Although a nit on the email subject - you're missing the "v3" tag ;)
Steve
> ---
> drivers/gpu/drm/panthor/panthor_gem.c | 31 +++++++++++++--------------
> drivers/gpu/drm/panthor/panthor_gem.h | 3 ---
> 2 files changed, 15 insertions(+), 19 deletions(-)
>
> diff --git a/drivers/gpu/drm/panthor/panthor_gem.c b/drivers/gpu/drm/panthor/panthor_gem.c
> index 7c00fd77758b..a123bc740ba1 100644
> --- a/drivers/gpu/drm/panthor/panthor_gem.c
> +++ b/drivers/gpu/drm/panthor/panthor_gem.c
> @@ -16,10 +16,15 @@
> #include "panthor_mmu.h"
>
> #ifdef CONFIG_DEBUG_FS
> -static void panthor_gem_debugfs_bo_add(struct panthor_device *ptdev,
> - struct panthor_gem_object *bo)
> +static void panthor_gem_debugfs_bo_init(struct panthor_gem_object *bo)
> {
> INIT_LIST_HEAD(&bo->debugfs.node);
> +}
> +
> +static void panthor_gem_debugfs_bo_add(struct panthor_gem_object *bo)
> +{
> + struct panthor_device *ptdev = container_of(bo->base.base.dev,
> + struct panthor_device, base);
>
> bo->debugfs.creator.tgid = current->group_leader->pid;
> get_task_comm(bo->debugfs.creator.process_name, current->group_leader);
> @@ -44,14 +49,13 @@ static void panthor_gem_debugfs_bo_rm(struct panthor_gem_object *bo)
>
> static void panthor_gem_debugfs_set_usage_flags(struct panthor_gem_object *bo, u32 usage_flags)
> {
> - bo->debugfs.flags = usage_flags | PANTHOR_DEBUGFS_GEM_USAGE_FLAG_INITIALIZED;
> + bo->debugfs.flags = usage_flags;
> + panthor_gem_debugfs_bo_add(bo);
> }
> #else
> -static void panthor_gem_debugfs_bo_add(struct panthor_device *ptdev,
> - struct panthor_gem_object *bo)
> -{}
> static void panthor_gem_debugfs_bo_rm(struct panthor_gem_object *bo) {}
> static void panthor_gem_debugfs_set_usage_flags(struct panthor_gem_object *bo, u32 usage_flags) {}
> +static void panthor_gem_debugfs_bo_init(struct panthor_gem_object *bo) {}
> #endif
>
> static void panthor_gem_free_object(struct drm_gem_object *obj)
> @@ -246,7 +250,7 @@ struct drm_gem_object *panthor_gem_create_object(struct drm_device *ddev, size_t
> drm_gem_gpuva_set_lock(&obj->base.base, &obj->gpuva_list_lock);
> mutex_init(&obj->label.lock);
>
> - panthor_gem_debugfs_bo_add(ptdev, obj);
> + panthor_gem_debugfs_bo_init(obj);
>
> return &obj->base.base;
> }
> @@ -285,6 +289,8 @@ panthor_gem_create_with_handle(struct drm_file *file,
> bo->base.base.resv = bo->exclusive_vm_root_gem->resv;
> }
>
> + panthor_gem_debugfs_set_usage_flags(bo, 0);
> +
> /*
> * Allocate an id of idr table where the obj is registered
> * and handle has the id what user can see.
> @@ -296,12 +302,6 @@ panthor_gem_create_with_handle(struct drm_file *file,
> /* drop reference from allocate - handle holds it now. */
> drm_gem_object_put(&shmem->base);
>
> - /*
> - * No explicit flags are needed in the call below, since the
> - * function internally sets the INITIALIZED bit for us.
> - */
> - panthor_gem_debugfs_set_usage_flags(bo, 0);
> -
> return ret;
> }
>
> @@ -387,7 +387,7 @@ static void panthor_gem_debugfs_bo_print(struct panthor_gem_object *bo,
> unsigned int refcount = kref_read(&bo->base.base.refcount);
> char creator_info[32] = {};
> size_t resident_size;
> - u32 gem_usage_flags = bo->debugfs.flags & (u32)~PANTHOR_DEBUGFS_GEM_USAGE_FLAG_INITIALIZED;
> + u32 gem_usage_flags = bo->debugfs.flags;
> u32 gem_state_flags = 0;
>
> /* Skip BOs being destroyed. */
> @@ -436,8 +436,7 @@ void panthor_gem_debugfs_print_bos(struct panthor_device *ptdev,
>
> scoped_guard(mutex, &ptdev->gems.lock) {
> list_for_each_entry(bo, &ptdev->gems.node, debugfs.node) {
> - if (bo->debugfs.flags & PANTHOR_DEBUGFS_GEM_USAGE_FLAG_INITIALIZED)
> - panthor_gem_debugfs_bo_print(bo, m, &totals);
> + panthor_gem_debugfs_bo_print(bo, m, &totals);
> }
> }
>
> diff --git a/drivers/gpu/drm/panthor/panthor_gem.h b/drivers/gpu/drm/panthor/panthor_gem.h
> index 4dd732dcd59f..8fc7215e9b90 100644
> --- a/drivers/gpu/drm/panthor/panthor_gem.h
> +++ b/drivers/gpu/drm/panthor/panthor_gem.h
> @@ -35,9 +35,6 @@ enum panthor_debugfs_gem_usage_flags {
>
> /** @PANTHOR_DEBUGFS_GEM_USAGE_FLAG_FW_MAPPED: BO is mapped on the FW VM. */
> PANTHOR_DEBUGFS_GEM_USAGE_FLAG_FW_MAPPED = BIT(PANTHOR_DEBUGFS_GEM_USAGE_FW_MAPPED_BIT),
> -
> - /** @PANTHOR_DEBUGFS_GEM_USAGE_FLAG_INITIALIZED: BO is ready for DebugFS display. */
> - PANTHOR_DEBUGFS_GEM_USAGE_FLAG_INITIALIZED = BIT(31),
> };
>
> /**
next prev parent reply other threads:[~2025-07-09 15:48 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-07 15:18 [PATCH 1/2] drm/gem: Fix race in drm_gem_handle_create_tail() Simona Vetter
2025-07-07 15:18 ` [PATCH 2/2] drm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code Simona Vetter
2025-07-08 9:21 ` Liviu Dudau
2025-07-09 13:17 ` Simona Vetter
2025-07-09 13:52 ` [PATCH] " Simona Vetter
2025-07-09 15:48 ` Steven Price [this message]
2025-07-10 8:53 ` Simona Vetter
2025-07-10 9:23 ` Steven Price
2025-07-07 16:03 ` ✗ CI.checkpatch: warning for series starting with [1/2] drm/gem: Fix race in drm_gem_handle_create_tail() Patchwork
2025-07-07 16:04 ` ✓ CI.KUnit: success " Patchwork
2025-07-07 16:19 ` ✗ CI.checksparse: warning " Patchwork
2025-07-07 16:58 ` ✓ Xe.CI.BAT: success " Patchwork
2025-07-07 19:19 ` ✓ Xe.CI.Full: " Patchwork
2025-07-09 13:54 ` [PATCH 1/2] " Simona Vetter
2025-07-09 13:57 ` ✗ CI.checkpatch: warning for series starting with [1/2] drm/gem: Fix race in drm_gem_handle_create_tail() (rev2) Patchwork
2025-07-09 13:58 ` ✓ CI.KUnit: success " Patchwork
2025-07-09 14:13 ` ✗ CI.checksparse: warning " Patchwork
2025-07-09 14:38 ` ✓ Xe.CI.BAT: success " Patchwork
2025-07-09 17:11 ` ✗ Xe.CI.Full: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6fe2409f-b561-4546-92e1-dd7f8d45ef12@arm.com \
--to=steven.price@arm.com \
--cc=adrian.larumbe@collabora.com \
--cc=boris.brezillon@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=liviu.dudau@arm.com \
--cc=simona.vetter@ffwll.ch \
--cc=simona.vetter@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox