* [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate
@ 2026-04-22 12:34 hongyan Xu
2026-04-22 12:35 ` hongyan Xu
0 siblings, 1 reply; 5+ messages in thread
From: hongyan Xu @ 2026-04-22 12:34 UTC (permalink / raw)
To: alexander.deucher
Cc: christian.koenig, airlied, simona, amd-gfx, dri-devel,
linux-kernel, jianhao.xu, 220245772, Hongyan Xu
From: Hongyan Xu <getshell@seu.edu.cn>
When new_addition is true, amdgpu_userq_vm_validate() calls
drm_exec_fini(&exec) before iterating over the collected HMM ranges and
calling amdgpu_ttm_tt_get_user_pages().
If amdgpu_ttm_tt_get_user_pages() fails in that path, the code jumps to
unlock_all and calls drm_exec_fini(&exec) a second time on the same
exec object. drm_exec_fini() is not idempotent: it frees exec->objects
and may also drop exec->contended and finalize the ww acquire context.
Route that error path directly to the range cleanup once exec has
already been finalized.
Fixes: 42f148788469 ("drm/amdgpu/userqueue: validate userptrs for userqueues")
Issue found using a prototype static analysis tool
and confirmed by code review.
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
index 9d67b770bcc2..fe49108fabbd 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
@@ -1193,7 +1193,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
bo = range->bo;
ret = amdgpu_ttm_tt_get_user_pages(bo, range);
if (ret)
- goto unlock_all;
+ goto free_ranges;
}
invalidated = true;
@@ -1220,6 +1220,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
unlock_all:
drm_exec_fini(&exec);
+free_ranges:
xa_for_each(&xa, tmp_key, range) {
if (!range)
continue;
--
2.50.1.windows.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate
2026-04-22 12:34 [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate hongyan Xu
@ 2026-04-22 12:35 ` hongyan Xu
0 siblings, 0 replies; 5+ messages in thread
From: hongyan Xu @ 2026-04-22 12:35 UTC (permalink / raw)
To: alexander.deucher
Cc: christian.koenig, airlied, simona, amd-gfx, dri-devel,
linux-kernel, jianhao.xu, 220245772
Please ignore the patch I sent previously. It was sent in error.
Sorry for the noise.
Thanks,
hongyan Xu
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate
2026-04-22 12:41 ` Christian König
@ 2026-04-22 15:21 ` Alex Deucher
0 siblings, 0 replies; 5+ messages in thread
From: Alex Deucher @ 2026-04-22 15:21 UTC (permalink / raw)
To: Christian König
Cc: Hongyan Xu, alexander.deucher, airlied, simona, amd-gfx,
dri-devel, linux-kernel, jianhao.xu, 220245772
Applied. Thanks!
On Wed, Apr 22, 2026 at 8:59 AM Christian König
<christian.koenig@amd.com> wrote:
>
> On 4/22/26 14:38, Hongyan Xu wrote:
> > When new_addition is true, amdgpu_userq_vm_validate() calls
> > drm_exec_fini(&exec) before iterating over the collected HMM ranges and
> > calling amdgpu_ttm_tt_get_user_pages().
> >
> > If amdgpu_ttm_tt_get_user_pages() fails in that path, the code jumps to
> > unlock_all and calls drm_exec_fini(&exec) a second time on the same
> > exec object. drm_exec_fini() is not idempotent: it frees exec->objects
> > and may also drop exec->contended and finalize the ww acquire context.
> >
> > Route that error path directly to the range cleanup once exec has
> > already been finalized.
> >
> > Fixes: 42f148788469 ("drm/amdgpu/userqueue: validate userptrs for userqueues")
> > Issue found using a prototype static analysis tool
> > and confirmed by code review.
> >
> > Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
> > Signed-off-by: Slavin Liu <220245772@seu.edu.cn>
>
> Good catch, Reviewed-by: Christian König <christian.koenig@amd.com>
>
> > ---
> > drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 3 ++-
> > 1 file changed, 2 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
> > index 9d67b770bcc2..fe49108fabbd 100644
> > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
> > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
> > @@ -1193,7 +1193,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
> > bo = range->bo;
> > ret = amdgpu_ttm_tt_get_user_pages(bo, range);
> > if (ret)
> > - goto unlock_all;
> > + goto free_ranges;
> > }
> >
> > invalidated = true;
> > @@ -1220,6 +1220,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
> >
> > unlock_all:
> > drm_exec_fini(&exec);
> > +free_ranges:
> > xa_for_each(&xa, tmp_key, range) {
> > if (!range)
> > continue;
> > --
> > 2.50.1.windows.1
> >
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate
2026-04-22 12:38 Hongyan Xu
@ 2026-04-22 12:41 ` Christian König
2026-04-22 15:21 ` Alex Deucher
0 siblings, 1 reply; 5+ messages in thread
From: Christian König @ 2026-04-22 12:41 UTC (permalink / raw)
To: Hongyan Xu, alexander.deucher
Cc: airlied, simona, amd-gfx, dri-devel, linux-kernel, jianhao.xu, 220245772
On 4/22/26 14:38, Hongyan Xu wrote:
> When new_addition is true, amdgpu_userq_vm_validate() calls
> drm_exec_fini(&exec) before iterating over the collected HMM ranges and
> calling amdgpu_ttm_tt_get_user_pages().
>
> If amdgpu_ttm_tt_get_user_pages() fails in that path, the code jumps to
> unlock_all and calls drm_exec_fini(&exec) a second time on the same
> exec object. drm_exec_fini() is not idempotent: it frees exec->objects
> and may also drop exec->contended and finalize the ww acquire context.
>
> Route that error path directly to the range cleanup once exec has
> already been finalized.
>
> Fixes: 42f148788469 ("drm/amdgpu/userqueue: validate userptrs for userqueues")
> Issue found using a prototype static analysis tool
> and confirmed by code review.
>
> Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
> Signed-off-by: Slavin Liu <220245772@seu.edu.cn>
Good catch, Reviewed-by: Christian König <christian.koenig@amd.com>
> ---
> drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
> index 9d67b770bcc2..fe49108fabbd 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
> @@ -1193,7 +1193,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
> bo = range->bo;
> ret = amdgpu_ttm_tt_get_user_pages(bo, range);
> if (ret)
> - goto unlock_all;
> + goto free_ranges;
> }
>
> invalidated = true;
> @@ -1220,6 +1220,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
>
> unlock_all:
> drm_exec_fini(&exec);
> +free_ranges:
> xa_for_each(&xa, tmp_key, range) {
> if (!range)
> continue;
> --
> 2.50.1.windows.1
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate
@ 2026-04-22 12:38 Hongyan Xu
2026-04-22 12:41 ` Christian König
0 siblings, 1 reply; 5+ messages in thread
From: Hongyan Xu @ 2026-04-22 12:38 UTC (permalink / raw)
To: alexander.deucher
Cc: christian.koenig, airlied, simona, amd-gfx, dri-devel,
linux-kernel, jianhao.xu, 220245772, Hongyan Xu
When new_addition is true, amdgpu_userq_vm_validate() calls
drm_exec_fini(&exec) before iterating over the collected HMM ranges and
calling amdgpu_ttm_tt_get_user_pages().
If amdgpu_ttm_tt_get_user_pages() fails in that path, the code jumps to
unlock_all and calls drm_exec_fini(&exec) a second time on the same
exec object. drm_exec_fini() is not idempotent: it frees exec->objects
and may also drop exec->contended and finalize the ww acquire context.
Route that error path directly to the range cleanup once exec has
already been finalized.
Fixes: 42f148788469 ("drm/amdgpu/userqueue: validate userptrs for userqueues")
Issue found using a prototype static analysis tool
and confirmed by code review.
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Signed-off-by: Slavin Liu <220245772@seu.edu.cn>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
index 9d67b770bcc2..fe49108fabbd 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
@@ -1193,7 +1193,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
bo = range->bo;
ret = amdgpu_ttm_tt_get_user_pages(bo, range);
if (ret)
- goto unlock_all;
+ goto free_ranges;
}
invalidated = true;
@@ -1220,6 +1220,7 @@ amdgpu_userq_vm_validate(struct amdgpu_userq_mgr *uq_mgr)
unlock_all:
drm_exec_fini(&exec);
+free_ranges:
xa_for_each(&xa, tmp_key, range) {
if (!range)
continue;
--
2.50.1.windows.1
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-04-22 15:21 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-04-22 12:34 [PATCH] drm/amdgpu: avoid double drm_exec_fini() in userq validate hongyan Xu
2026-04-22 12:35 ` hongyan Xu
2026-04-22 12:38 Hongyan Xu
2026-04-22 12:41 ` Christian König
2026-04-22 15:21 ` Alex Deucher
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®