Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "Huang, Honglei" <honghuan@amd.com>
To: Matthew Brost <matthew.brost@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v4 0/3] drm/gpusvm: fix IOVA/DMA unmap leaks in __drm_gpusvm_unmap_pages()
Date: Tue, 14 Jul 2026 10:04:37 +0800	[thread overview]
Message-ID: <7ab95b89-9efb-4bbd-bac2-2e6df069f340@amd.com> (raw)
In-Reply-To: <alULRxMpL8x4A9VM@gsse-cloud1.jf.intel.com>



On 7/13/2026 11:59 PM, Matthew Brost wrote:
> On Mon, Jul 06, 2026 at 10:46:39AM +0800, Honglei Huang wrote:
>> Three small fixes for the IOVA/DMA unmap path in
>> __drm_gpusvm_unmap_pages() and the get_pages() error path, all spotted by
>> AI review:
>>
>>    - Free the whole IOVA reservation on unmap. In a mixed range only the
>>      system pages are linked, so freeing just the linked part leaks the
>>      IOVA reserved for the device pages. Unlink the linked portion and
>>      free the whole reservation. On the get_pages() error path
>>      state_offset is 0, so skip the unlink, also avoiding the
>>      uninitialised dma_addr[0].dir read, allocate dma_addr with the
>>      zeroing kvzalloc_objs().
>>    - Do not route system pages to device_unmap() on the IOVA path. Branch
>>      off addr->proto so only real device pages reach device_unmap().
>>    - Publish dpagemap early to avoid leaking device mappings on the
>>      get_pages() error path. It was only stored on success, so a mid-way
>>      failure left svm_pages->dpagemap NULL and skipped device_unmap().
>>      Assign it when the first device page is mapped.
>>
>> All three issues are preexisting and independent of the gpusvm MM/device
>> state split series; they were surfaced by the AI review of that series,
>> so this series addresses them separately.
>>
>> V4:
>>    - Add reviewed-by for Matt's review.
> 
> Thanks for the patches, going to merge this to drm-misc-fixes by EOD.
> 

Really thanks for the review and merging!

Regards,
Honglei

> Matt
> 
>>
>> V3:
>>    - Add fixes for all patches, add Cc stable.
>>    - Add reviewed by in patch 1.
>>    - Move AI review note into commit message instead of reported by.
>>
>> V2:
>>    - patch 1: extend the uninitialized dma_addr[0].dir fix into freeing
>>      the whole IOVA reservation, fixing the IOVA leak for mixed ranges
>>      (the earlier version only guarded the direction argument).
>>    - add patch 3: publish dpagemap early to fix the device-mapping leak on
>>      the get_pages() error path.
>>
>> Honglei Huang (3):
>>    drm/gpusvm: free the whole IOVA reservation on unmap
>>    drm/gpusvm: do not route system pages to device_unmap() on IOVA unmap
>>    drm/gpusvm: publish dpagemap early to avoid device mapping leak on
>>      error
>>
>>   drivers/gpu/drm/drm_gpusvm.c | 53 +++++++++++++++++++++++++-----------
>>   1 file changed, 37 insertions(+), 16 deletions(-)
>>
>> -- 
>> 2.34.1
>>


  reply	other threads:[~2026-07-14  2:04 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-06  2:46 [PATCH v4 0/3] drm/gpusvm: fix IOVA/DMA unmap leaks in __drm_gpusvm_unmap_pages() Honglei Huang
2026-07-06  2:46 ` [PATCH v4 1/3] drm/gpusvm: free the whole IOVA reservation on unmap Honglei Huang
2026-07-06  2:46 ` [PATCH v4 2/3] drm/gpusvm: do not route system pages to device_unmap() on IOVA unmap Honglei Huang
2026-07-06  2:46 ` [PATCH v4 3/3] drm/gpusvm: publish dpagemap early to avoid device mapping leak on error Honglei Huang
2026-07-06  2:54 ` ✓ CI.KUnit: success for drm/gpusvm: fix IOVA/DMA unmap leaks in __drm_gpusvm_unmap_pages() (rev5) Patchwork
2026-07-06  3:30 ` ✓ Xe.CI.BAT: " Patchwork
2026-07-06  4:55 ` ✓ Xe.CI.FULL: " Patchwork
2026-07-13 15:59 ` [PATCH v4 0/3] drm/gpusvm: fix IOVA/DMA unmap leaks in __drm_gpusvm_unmap_pages() Matthew Brost
2026-07-14  2:04   ` Huang, Honglei [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-07-01  6:27 Honglei Huang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7ab95b89-9efb-4bbd-bac2-2e6df069f340@amd.com \
    --to=honghuan@amd.com \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=matthew.brost@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox