From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Emily Deng <Emily.Deng@amd.com>,
Felix Kuehling <felix.kuehling@amd.com>,
Alex Deucher <alexander.deucher@amd.com>,
Sasha Levin <sashal@kernel.org>,
Felix.Kuehling@amd.com, christian.koenig@amd.com,
airlied@gmail.com, simona@ffwll.ch,
amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org
Subject: [PATCH AUTOSEL 6.12 25/33] drm/amdgpu: Fix the race condition for draining retry fault
Date: Thu, 3 Apr 2025 15:16:48 -0400 [thread overview]
Message-ID: <20250403191656.2680995-25-sashal@kernel.org> (raw)
In-Reply-To: <20250403191656.2680995-1-sashal@kernel.org>
From: Emily Deng <Emily.Deng@amd.com>
[ Upstream commit f844732e3ad9c4b78df7436232949b8d2096d1a6 ]
Issue:
In the scenario where svm_range_restore_pages is called, but
svm->checkpoint_ts has not been set and the retry fault has not been
drained, svm_range_unmap_from_cpu is triggered and calls svm_range_free.
Meanwhile, svm_range_restore_pages continues execution and reaches
svm_range_from_addr. This results in a "failed to find prange..." error,
causing the page recovery to fail.
How to fix:
Move the timestamp check code under the protection of svm->lock.
v2:
Make sure all right locks are released before go out.
v3:
Directly goto out_unlock_svms, and return -EAGAIN.
v4:
Refine code.
Signed-off-by: Emily Deng <Emily.Deng@amd.com>
Reviewed-by: Felix Kuehling <felix.kuehling@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_svm.c | 31 +++++++++++++++-------------
1 file changed, 17 insertions(+), 14 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_svm.c b/drivers/gpu/drm/amd/amdkfd/kfd_svm.c
index 8c61dee5ca0db..b50283864dcd2 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_svm.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_svm.c
@@ -2992,19 +2992,6 @@ svm_range_restore_pages(struct amdgpu_device *adev, unsigned int pasid,
goto out;
}
- /* check if this page fault time stamp is before svms->checkpoint_ts */
- if (svms->checkpoint_ts[gpuidx] != 0) {
- if (amdgpu_ih_ts_after(ts, svms->checkpoint_ts[gpuidx])) {
- pr_debug("draining retry fault, drop fault 0x%llx\n", addr);
- r = 0;
- goto out;
- } else
- /* ts is after svms->checkpoint_ts now, reset svms->checkpoint_ts
- * to zero to avoid following ts wrap around give wrong comparing
- */
- svms->checkpoint_ts[gpuidx] = 0;
- }
-
if (!p->xnack_enabled) {
pr_debug("XNACK not enabled for pasid 0x%x\n", pasid);
r = -EFAULT;
@@ -3024,6 +3011,21 @@ svm_range_restore_pages(struct amdgpu_device *adev, unsigned int pasid,
mmap_read_lock(mm);
retry_write_locked:
mutex_lock(&svms->lock);
+
+ /* check if this page fault time stamp is before svms->checkpoint_ts */
+ if (svms->checkpoint_ts[gpuidx] != 0) {
+ if (amdgpu_ih_ts_after(ts, svms->checkpoint_ts[gpuidx])) {
+ pr_debug("draining retry fault, drop fault 0x%llx\n", addr);
+ r = -EAGAIN;
+ goto out_unlock_svms;
+ } else {
+ /* ts is after svms->checkpoint_ts now, reset svms->checkpoint_ts
+ * to zero to avoid following ts wrap around give wrong comparing
+ */
+ svms->checkpoint_ts[gpuidx] = 0;
+ }
+ }
+
prange = svm_range_from_addr(svms, addr, NULL);
if (!prange) {
pr_debug("failed to find prange svms 0x%p address [0x%llx]\n",
@@ -3148,7 +3150,8 @@ svm_range_restore_pages(struct amdgpu_device *adev, unsigned int pasid,
mutex_unlock(&svms->lock);
mmap_read_unlock(mm);
- svm_range_count_fault(node, p, gpuidx);
+ if (r != -EAGAIN)
+ svm_range_count_fault(node, p, gpuidx);
mmput(mm);
out:
--
2.39.5
next prev parent reply other threads:[~2025-04-03 19:17 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-03 19:16 [PATCH AUTOSEL 6.12 01/33] drm: allow encoder mode_set even when connectors change for crtc Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 02/33] drm/xe/bmg: Add new PCI IDs Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 03/33] drm/xe/vf: Don't try to trigger a full GT reset if VF Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 04/33] drm/amd/display: Update Cursor request mode to the beginning prefetch always Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 05/33] drm/amdgpu: Unlocked unmap only clear page table leaves Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 06/33] drm: panel-orientation-quirks: Add support for AYANEO 2S Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 07/33] drm: panel-orientation-quirks: Add quirks for AYA NEO Flip DS and KB Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 08/33] drm: panel-orientation-quirks: Add quirk for AYA NEO Slide Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 09/33] drm: panel-orientation-quirks: Add new quirk for GPD Win 2 Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 10/33] drm: panel-orientation-quirks: Add quirk for OneXPlayer Mini (Intel) Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 11/33] drm/debugfs: fix printk format for bridge index Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 12/33] drm/bridge: panel: forbid initializing a panel with unknown connector type Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 13/33] drm/amd/display: stop DML2 from removing pipes based on planes Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 14/33] drivers: base: devres: Allow to release group on device release Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 15/33] drm/amdkfd: clamp queue size to minimum Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 16/33] drm/amdkfd: Fix mode1 reset crash issue Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 17/33] drm/amdkfd: Fix pqm_destroy_queue race with GPU reset Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 18/33] drm/amdkfd: debugfs hang_hws skip GPU with MES Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 19/33] drm/xe/xelp: Move Wa_16011163337 from tunings to workarounds Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 20/33] drm/mediatek: mtk_dpi: Move the input_2p_en bit to platform data Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 21/33] drm/mediatek: mtk_dpi: Explicitly manage TVD clock in power on/off Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 22/33] PCI: Add Rockchip Vendor ID Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 23/33] drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 24/33] PCI: Enable Configuration RRS SV early Sasha Levin
2025-04-03 19:16 ` Sasha Levin [this message]
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 26/33] PCI: Check BAR index for validity Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 27/33] PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 28/33] drm/amdgpu: grab an additional reference on the gang fence v2 Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 29/33] fbdev: omapfb: Add 'plane' value check Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 30/33] tracing: probe-events: Add comments about entry data storing code Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 31/33] ktest: Fix Test Failures Due to Missing LOG_FILE Directories Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 32/33] tpm, tpm_tis: Workaround failed command reception on Infineon devices Sasha Levin
2025-04-03 19:16 ` [PATCH AUTOSEL 6.12 33/33] tpm: End any active auth session before shutdown Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250403191656.2680995-25-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=Emily.Deng@amd.com \
--cc=airlied@gmail.com \
--cc=alexander.deucher@amd.com \
--cc=amd-gfx@lists.freedesktop.org \
--cc=christian.koenig@amd.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=felix.kuehling@amd.com \
--cc=linux-kernel@vger.kernel.org \
--cc=simona@ffwll.ch \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox