* [PATCH] drm/xe/pf: clear pending packet on header init failure
@ 2026-07-08 7:15 Guangshuo Li
2026-08-05 6:03 ` kernel test robot
0 siblings, 1 reply; 2+ messages in thread
From: Guangshuo Li @ 2026-07-08 7:15 UTC (permalink / raw)
To: Matthew Brost, Thomas Hellström, Rodrigo Vivi, David Airlie,
Simona Vetter, Michal Wajdeczko, Michał Winiarski, intel-xe,
dri-devel, linux-kernel
Cc: Guangshuo Li
xe_sriov_packet_write_single() keeps a partially written restore packet
in the per-VF pending slot across write() calls.
When the header becomes complete, xe_sriov_packet_init_from_hdr() sets
data->remaining from the user supplied header before initializing the
packet backing storage. If that initialization fails, for example because
the header contains an invalid gt_id, pkt_hdr_write() returns an error
but the pending slot is left pointing at the partially initialized packet.
A later write then reuses that packet, skips the header path because
hdr_remaining is already zero, and reaches pkt_data_write() without
backing storage installed. This can dereference data->vaddr while it is
still NULL.
Drop the pending packet when header initialization fails after the header
has been fully consumed, so the next write starts from a fresh packet.
Fixes: 1ed30397c0b9 ("drm/xe/pf: Add support for encap/decap of bitstream to/from packet")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
drivers/gpu/drm/xe/xe_sriov_packet.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_sriov_packet.c b/drivers/gpu/drm/xe/xe_sriov_packet.c
index 2ae9eff2a7c0..e9c92019862e 100644
--- a/drivers/gpu/drm/xe/xe_sriov_packet.c
+++ b/drivers/gpu/drm/xe/xe_sriov_packet.c
@@ -323,8 +323,9 @@ ssize_t xe_sriov_packet_write_single(struct xe_device *xe, unsigned int vfid,
const char __user *buf, size_t len)
{
struct xe_sriov_packet **data = pf_pick_pending(xe, vfid);
- int ret;
ssize_t copied;
+ bool writing_hdr;
+ int ret;
if (IS_ERR_OR_NULL(*data)) {
*data = xe_sriov_packet_alloc(xe);
@@ -332,11 +333,21 @@ ssize_t xe_sriov_packet_write_single(struct xe_device *xe, unsigned int vfid,
return -ENOMEM;
}
- if ((*data)->hdr_remaining)
+ writing_hdr = (*data)->hdr_remaining;
+ if (writing_hdr)
copied = pkt_hdr_write(*data, buf, len);
else
copied = pkt_data_write(*data, buf, len);
+ if (copied < 0) {
+ if (writing_hdr && !(*data)->hdr_remaining) {
+ kfree(*data);
+ *data = NULL;
+ }
+
+ rturn copied;
+ }
+
if ((*data)->hdr_remaining == 0 && (*data)->remaining == 0) {
ret = xe_sriov_pf_migration_restore_produce(xe, vfid, *data);
if (ret) {
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] drm/xe/pf: clear pending packet on header init failure
2026-07-08 7:15 [PATCH] drm/xe/pf: clear pending packet on header init failure Guangshuo Li
@ 2026-08-05 6:03 ` kernel test robot
0 siblings, 0 replies; 2+ messages in thread
From: kernel test robot @ 2026-08-05 6:03 UTC (permalink / raw)
To: Guangshuo Li, Matthew Brost, Thomas Hellström, Rodrigo Vivi,
David Airlie, Simona Vetter, Michal Wajdeczko,
Michał Winiarski, intel-xe, dri-devel, linux-kernel
Cc: oe-kbuild-all, Guangshuo Li
Hi Guangshuo,
kernel test robot noticed the following build errors:
[auto build test ERROR on drm-xe/drm-xe-next]
[also build test ERROR on linus/master v7.2-rc6 next-20260804]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Guangshuo-Li/drm-xe-pf-clear-pending-packet-on-header-init-failure/20260805-104621
base: https://gitlab.freedesktop.org/drm/xe/kernel.git drm-xe-next
patch link: https://lore.kernel.org/r/20260708071502.722393-1-lgs201920130244%40gmail.com
patch subject: [PATCH] drm/xe/pf: clear pending packet on header init failure
config: powerpc-allmodconfig (https://download.01.org/0day-ci/archive/20260805/202608051326.aRuRqBCC-lkp@intel.com/config)
compiler: powerpc64-linux-gcc (GCC) 16.1.0
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260805/202608051326.aRuRqBCC-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202608051326.aRuRqBCC-lkp@intel.com/
All error/warnings (new ones prefixed by >>):
drivers/gpu/drm/xe/xe_sriov_packet.c: In function 'xe_sriov_packet_write_single':
>> drivers/gpu/drm/xe/xe_sriov_packet.c:350:17: error: unknown type name 'rturn'
350 | rturn copied;
| ^~~~~
>> drivers/gpu/drm/xe/xe_sriov_packet.c:350:23: warning: unused variable 'copied' [-Wunused-variable]
350 | rturn copied;
| ^~~~~~
vim +/rturn +350 drivers/gpu/drm/xe/xe_sriov_packet.c
313
314 /**
315 * xe_sriov_packet_write_single() - Write migration data to a single packet.
316 * @xe: the &xe_device
317 * @vfid: the VF identifier
318 * @buf: start address of userspace buffer
319 * @len: requested write size from userspace
320 *
321 * Return: number of bytes that has been successfully written,
322 * -errno on failure.
323 */
324 ssize_t xe_sriov_packet_write_single(struct xe_device *xe, unsigned int vfid,
325 const char __user *buf, size_t len)
326 {
327 struct xe_sriov_packet **data = pf_pick_pending(xe, vfid);
328 ssize_t copied;
329 bool writing_hdr;
330 int ret;
331
332 if (IS_ERR_OR_NULL(*data)) {
333 *data = xe_sriov_packet_alloc(xe);
334 if (!*data)
335 return -ENOMEM;
336 }
337
338 writing_hdr = (*data)->hdr_remaining;
339 if (writing_hdr)
340 copied = pkt_hdr_write(*data, buf, len);
341 else
342 copied = pkt_data_write(*data, buf, len);
343
344 if (copied < 0) {
345 if (writing_hdr && !(*data)->hdr_remaining) {
346 kfree(*data);
347 *data = NULL;
348 }
349
> 350 rturn copied;
351 }
352
353 if ((*data)->hdr_remaining == 0 && (*data)->remaining == 0) {
354 ret = xe_sriov_pf_migration_restore_produce(xe, vfid, *data);
355 if (ret) {
356 xe_sriov_packet_free(*data);
357 *data = NULL;
358
359 return ret;
360 }
361
362 *data = NULL;
363 }
364
365 return copied;
366 }
367
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-05 6:04 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-08 7:15 [PATCH] drm/xe/pf: clear pending packet on header init failure Guangshuo Li
2026-08-05 6:03 ` kernel test robot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox