From: Matthew Brost <matthew.brost@intel.com>
To: Francois Dugast <francois.dugast@intel.com>
Cc: <intel-xe@lists.freedesktop.org>
Subject: Re: [PATCH v7 01/24] drm/xe: reference VM from PT BOs
Date: Fri, 25 Sep 2026 09:10:41 -0700 [thread overview]
Message-ID: <aradAY+S0rWaAsen@gsse-cloud1.jf.intel.com> (raw)
In-Reply-To: <arZiVjq3XJHWFpyM@fdugast-desk>
On Fri, Sep 25, 2026 at 02:00:22PM +0200, Francois Dugast wrote:
> Nit: first letter of the commit title is usually capitalized.
>
> On Thu, Sep 24, 2026 at 09:52:57PM -0700, Matthew Brost wrote:
> > PT BOs share the VM's dma-resv and therefore must keep the VM alive
> > until all PT BOs are destroyed.
> >
> > Take a VM reference from PT BOs to ensure the shared dma-resv remains
> > valid for the lifetime of the BOs. Scope the change to PT BOs rather
> > than all kernel BOs to minimize risk and avoid extending VM lifetimes
> > unnecessarily.
> >
> > Signed-off-by: Matthew Brost <matthew.brost@intel.com>
>
> Did you observe any side effect without this change in earlier versions
> of this series?
No, just Sashiko (correctly) complaining. The kmalloc in
individualization step would have to fail to get a UAF, thus pretty hard
for issues to show up. We might have issues here in other existing code
path if that happens but wanted to keep this change minimal rather than
auditing the entire driver.
Again Christian's series to ref count dma-resv is the real fix for
memory safety around dma-resv sharing. Hopefully we gets that in soon -
I basically gave him my ack to merge it but subsystem wide change so
might get held up.
Matt
>
> Reviewed-by: Francois Dugast <francois.dugast@intel.com>
>
> > ---
> > drivers/gpu/drm/xe/xe_bo.c | 4 ++--
> > 1 file changed, 2 insertions(+), 2 deletions(-)
> >
> > diff --git a/drivers/gpu/drm/xe/xe_bo.c b/drivers/gpu/drm/xe/xe_bo.c
> > index f2ab9bf43a86..6921b6967330 100644
> > --- a/drivers/gpu/drm/xe/xe_bo.c
> > +++ b/drivers/gpu/drm/xe/xe_bo.c
> > @@ -1879,7 +1879,7 @@ static void xe_ttm_bo_destroy(struct ttm_buffer_object *ttm_bo)
> > xe_drm_client_remove_bo(bo);
> > #endif
> >
> > - if (bo->vm && xe_bo_is_user(bo))
> > + if (bo->vm && (xe_bo_is_user(bo) || bo->flags & XE_BO_FLAG_PAGETABLE))
> > xe_vm_put(bo->vm);
> >
> > if (bo->parent_obj)
> > @@ -2575,7 +2575,7 @@ __xe_bo_create_locked(struct xe_device *xe,
> > * by having all the vm's bo refereferences released at vm close
> > * time.
> > */
> > - if (vm && xe_bo_is_user(bo))
> > + if (vm && (xe_bo_is_user(bo) || bo->flags & XE_BO_FLAG_PAGETABLE))
> > xe_vm_get(vm);
> > bo->vm = vm;
> >
> > --
> > 2.34.1
> >
next prev parent reply other threads:[~2026-09-25 16:10 UTC|newest]
Thread overview: 54+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 4:52 [PATCH v7 00/24] CPU binds and ULLS on migration queue Matthew Brost
2026-09-25 4:52 ` [PATCH v7 01/24] drm/xe: reference VM from PT BOs Matthew Brost
2026-09-25 12:00 ` Francois Dugast
2026-09-25 16:10 ` Matthew Brost [this message]
2026-09-25 4:52 ` [PATCH v7 02/24] drm/xe: Drop struct xe_migrate_pt_update argument from populate/clear vfuns Matthew Brost
2026-09-25 4:52 ` [PATCH v7 03/24] drm/xe: Add xe_migrate_update_pgtables_cpu_execute helper Matthew Brost
2026-09-25 4:53 ` [PATCH v7 04/24] drm/xe: Decouple exec queue idle check from LRC Matthew Brost
2026-09-25 4:53 ` [PATCH v7 05/24] drm/xe: Add job count to GuC exec queue snapshot Matthew Brost
2026-09-25 4:53 ` [PATCH v7 06/24] drm/xe: Update xe_bo_put_deferred arguments to include writeback flag Matthew Brost
2026-09-25 4:53 ` [PATCH v7 07/24] drm/xe: Update scheduler job layer to support PT jobs Matthew Brost
2026-09-25 11:23 ` Francois Dugast
2026-09-25 4:53 ` [PATCH v7 08/24] drm/xe: Add helpers to access PT ops Matthew Brost
2026-09-25 4:53 ` [PATCH v7 09/24] drm/xe: Add struct xe_pt_job_ops Matthew Brost
2026-09-25 4:53 ` [PATCH v7 10/24] drm/xe: Update GuC submission backend to run PT jobs Matthew Brost
2026-09-25 5:39 ` sashiko-bot
2026-09-25 5:58 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 11/24] drm/xe: Store level in struct xe_vm_pgtable_update Matthew Brost
2026-09-25 4:53 ` [PATCH v7 12/24] drm/xe: Don't use migrate exec queue for page fault binds Matthew Brost
2026-09-25 4:53 ` [PATCH v7 13/24] drm/xe: Enable CPU binds for jobs Matthew Brost
2026-09-25 6:03 ` sashiko-bot
2026-09-25 6:54 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 14/24] drm/xe: Remove unused arguments from xe_migrate_pt_update_ops Matthew Brost
2026-09-25 4:53 ` [PATCH v7 15/24] drm/xe: Make bind queues operate cross-tile Matthew Brost
2026-09-25 4:53 ` [PATCH v7 16/24] drm/xe: Add CPU bind layer Matthew Brost
2026-09-25 4:53 ` [PATCH v7 17/24] drm/xe: Add device flag to enable PT mirroring across tiles Matthew Brost
2026-09-25 6:25 ` sashiko-bot
2026-09-25 7:21 ` Matthew Brost
2026-09-25 9:51 ` Francois Dugast
2026-09-25 4:53 ` [PATCH v7 18/24] drm/xe: Add ULLS support to LRC Matthew Brost
2026-09-25 4:53 ` [PATCH v7 19/24] drm/xe: Add ULLS migration job support to migration layer Matthew Brost
2026-09-25 6:34 ` sashiko-bot
2026-09-25 7:17 ` Matthew Brost
2026-09-25 20:10 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 20/24] drm/xe: Add ULLS migration job support to ring ops Matthew Brost
2026-09-25 6:38 ` sashiko-bot
2026-09-25 7:02 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 21/24] drm/xe: Add ULLS migration job support to GuC submission Matthew Brost
2026-09-25 6:48 ` sashiko-bot
2026-09-25 7:08 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 22/24] drm/xe: Enter ULLS for migration jobs upon page fault or SVM prefetch Matthew Brost
2026-09-25 17:49 ` Maarten Lankhorst
2026-09-25 18:17 ` Matthew Brost
2026-09-25 18:26 ` Maarten Lankhorst
2026-09-25 19:38 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 23/24] drm/xe: add migrate ULLS period configfs attribute Matthew Brost
2026-09-25 6:51 ` sashiko-bot
2026-09-25 7:08 ` Matthew Brost
2026-09-25 4:53 ` [PATCH v7 24/24] drm/xe: Document ULLS for migration jobs Matthew Brost
2026-09-25 5:02 ` ✗ CI.checkpatch: warning for CPU binds and ULLS on migration queue (rev9) Patchwork
2026-09-25 5:04 ` ✓ CI.KUnit: success " Patchwork
2026-09-25 5:47 ` ✓ Xe.CI.BAT: " Patchwork
2026-09-25 15:05 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-09-25 16:01 ` Matthew Brost
2026-09-25 18:08 ` [PATCH v7 00/24] CPU binds and ULLS on migration queue Maarten Lankhorst
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aradAY+S0rWaAsen@gsse-cloud1.jf.intel.com \
--to=matthew.brost@intel.com \
--cc=francois.dugast@intel.com \
--cc=intel-xe@lists.freedesktop.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox