Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] RFC: drm/xe: Fix pinned list UAF panic
@ 2026-10-06 17:57 FNU VISHWANATHA
  2026-10-06 17:57 ` [PATCH 2/2] RFC: drm/xe: Prevent pinned_link double add FNU VISHWANATHA
                   ` (5 more replies)
  0 siblings, 6 replies; 8+ messages in thread
From: FNU VISHWANATHA @ 2026-10-06 17:57 UTC (permalink / raw)
  To: intel-xe; +Cc: dri-devel, Kornel Dulęba

From: Kornel Dulęba <korneld@google.com>

A kernel panic caused by a list corruption was observed when the IPU6
driver is running under heavy load. The panic would reproduce
consistently within a few minutes of the test suite running, though
never during the same test. The corruption would always happen in
list_add_tail called from xe_bo_pin_external:

list_add corruption. prev->next should be next (ffff8bb9862912c8), but was ffff8bb9e811e2a8. (prev=ffff8bb9e811e2a8)

Having prev->next == prev, suggests that node was re-initialized without
being removed from the list first. This indicates that the BO might have
been destroyed while it was still pinned.
Looking into xe_ttm_bo_destroy and its caller ttm_bo_release, reveals
that the latter supports a case where bo->pin_count > 0, albeit with a
WARN_ON_ONCE. Since ttm_bo_release sets bo->pin_count to 0 in that case,
add a complementary change to also remove bo->pinned_link from the list.
With this applied, the test progresses much further, with the newly
added warning seen in dmesg.

Test: atest CtsCameraTestCases

Signed-off-by: Kornel Dulęba <korneld@google.com>
---
 drivers/gpu/drm/xe/xe_bo.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/gpu/drm/xe/xe_bo.c b/drivers/gpu/drm/xe/xe_bo.c
index f2634d048cd4..c5989db950f7 100644
--- a/drivers/gpu/drm/xe/xe_bo.c
+++ b/drivers/gpu/drm/xe/xe_bo.c
@@ -1688,6 +1688,11 @@ static void xe_ttm_bo_destroy(struct ttm_buffer_object *ttm_bo)
 	if (bo->parent_obj)
 		xe_bo_put(bo->parent_obj);
 
+	spin_lock(&xe->pinned.lock);
+	if (WARN_ON_ONCE(!list_empty(&bo->pinned_link)))
+		list_del_init(&bo->pinned_link);
+	spin_unlock(&xe->pinned.lock);
+
 	mutex_lock(&xe->mem_access.vram_userfault.lock);
 	if (!list_empty(&bo->vram_userfault_link))
 		list_del(&bo->vram_userfault_link);
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-10-07  1:17 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-06 17:57 [PATCH 1/2] RFC: drm/xe: Fix pinned list UAF panic FNU VISHWANATHA
2026-10-06 17:57 ` [PATCH 2/2] RFC: drm/xe: Prevent pinned_link double add FNU VISHWANATHA
2026-10-06 18:16   ` sashiko-bot
2026-10-06 18:15 ` [PATCH 1/2] RFC: drm/xe: Fix pinned list UAF panic sashiko-bot
2026-10-06 18:37 ` ✗ CI.checkpatch: warning for series starting with [1/2] " Patchwork
2026-10-06 18:39 ` ✓ CI.KUnit: success " Patchwork
2026-10-06 19:38 ` ✓ Xe.CI.BAT: " Patchwork
2026-10-07  1:17 ` ✗ Xe.CI.FULL: failure " Patchwork

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox