From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f170.google.com (mail-yw1-f170.google.com [209.85.128.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93567344044 for ; Thu, 25 Jun 2026 13:54:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782395646; cv=none; b=pN3OxswxaYLAH97erD80GulsbLUH3nJUIGu7QxMDuBQ+4td+Z2TqeIEqEe4zJQnO91vRyaQCFKD+YItJuIQW3hmdFAGH7WNUwErzT86EXfVe0wpC+5fCETeBSd1UzuPTtOq6cZMRg4WAxuYbi276JdElQh1vJEIL2qbDOQiys2I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782395646; c=relaxed/simple; bh=F4InaXynWP9uL0dTS5lFpjC6sBUwjBh0QLB4AMca4hM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=dpHafjwsloGCE6NJOJqHu+0LdbuGF4XABGZgTpyWGM+8/ksqJrTsXeTHM6+knJaVNlzjr6EUTx5n8fgWfjU7IfI1Aezpj2T/GOYigfTaqNqgAaDvOnTyvlFXpUH03B0MNMPsJXIVfvjBYzbbQVJ+YE75wqRZLuIlbAYj0YJU8Og= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mpY8q38Y; arc=none smtp.client-ip=209.85.128.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mpY8q38Y" Received: by mail-yw1-f170.google.com with SMTP id 00721157ae682-7dfceeaf168so25892937b3.0 for ; Thu, 25 Jun 2026 06:54:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782395645; x=1783000445; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=m9aAmr8/iGyamwXOE0x+7nRWzrQLtbEEZ6iUw+t3oT4=; b=mpY8q38YOD53fT21HrWNnW9x1NtptQlnrtl6LbQIAwhFcB1Q0XBrTqEXTEfAIzsDJI AaIatpV6PUcLmDYf/gFDmbpwxRq8ZOsu3wf5iVD52u/KMQco3qw6ViGq+Osb/4Ef5SKY bNzTx3RDOWn/0NJuuVNd4AncVPbFWEcxzh1vYSW4qDkdDx7zRgoO0Kq74Lujj9Irpw9k 1oz5NzpAAsV4zTk956QxyX2oDJBbraHs6nmmriJzsA+dvrcx5RVRNrR1cSaYjRabVBnJ 6CQYhpxWvRs/BDfh2GQkmUWqVS44M313DJyxxOn2TLG9Aq9HWZcCBCyNHDx3qqv4fEOJ j3dg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782395645; x=1783000445; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=m9aAmr8/iGyamwXOE0x+7nRWzrQLtbEEZ6iUw+t3oT4=; b=rHYnlGCwybOnI4i5F+Cf39FbCX/CjgzV8Sbjd5dthoGWRN7eatHz4MqoeNQO8oomZd NVmKiPvb3XEXCMzJDwV5rxxSnoegFhYyFSPnvonePdLsiD99PKaM896C+m7vnHXt51Cb 1UjpnqO7OecX6K/7mDIEV+l/CtkOpx3TXuVgOyH7SY3Zfbx0M/eDalIi1h8mHuVtKc3C kpJ5gvVGLtd3t9zB3PGKMr5eHAppWsQz8MAWxMVbQz/zukM3JjnQUJV2tnPicv3esI3v YziRA8pwlWF/VxpRd6SW0k9MD0WZKiCNL1fKnTVxYTSplBAjgKRe0CuqxoZMz9aYTwN1 9Qog== X-Forwarded-Encrypted: i=1; AHgh+RpPR7nOPP1sc4aY4FCOIcUXIxN5zbdmxwxV44sBaKEECi08CAwfBzePKdmyICNRPWAAJbiZJu73oQgSFP0=@vger.kernel.org X-Gm-Message-State: AOJu0Yy2zo2wGw+vvLL5msQSQ9lgWhqIG5TwcKNHNH1KvOGEwXWuP/Hx ckKc9oglcv8zj16wnfT6W6epT3Qn7852faYYrnpVCTShehpG2A7VXhtx X-Gm-Gg: AfdE7cmihk1Xwjx9DegCkGD0HLKqHPaD8bpNnUiYa30ceynYqcS8iduhVsnkl0ctTw3 KctVadmJJULEpV+lldyMtKZ26ryajQXnrJkHpMNKmVODcUdiQA+MrJtso5SCkCYGqZWT4ElaXMG P4ajMrCChbfaMeeMrtKEl+zgLWz3rORDq04ttCKGGVQalq/iHY9B82BNud3EiDaDtEbRPKqs0Y1 l0Uif7eYR8SxmWGoCOWEYMtr0rdrTxDmHeyEVHLG0FhPwZ//XOjFJ1gnh/FyNQr0jvihI1R6+C6 Jo/KrITz+XcUCXS5ntfIz+mN4YM9dnsM1R6z4fLVwobbitlyLEaZj+RsJMdSxORU8d13+9UeNTn yG2Sh5ymiojZW/mSlt1ywcr6EsUlZbbTQ129tM5TLJb4CLsF8uEIMNiROBQORKHPQzIdIuJjdPx FKH/TvGbw5DbUwwIbIus9x1BG5ncRg+0rponoc X-Received: by 2002:a05:690c:6e02:b0:7f8:7e31:28ab with SMTP id 00721157ae682-80a6b898733mr25315367b3.51.1782395644452; Thu, 25 Jun 2026 06:54:04 -0700 (PDT) Received: from Dev-Null-MSI ([2a0d:3344:52ac:a808:98a4:4381:be45:536f]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8025f8da5fbsm72143407b3.30.2026.06.25.06.54.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 25 Jun 2026 06:54:04 -0700 (PDT) From: Yousef Alhouseen To: Alex Deucher , =?UTF-8?q?Christian=20K=C3=B6nig?= Cc: David Airlie , Simona Vetter , amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Yousef Alhouseen Subject: [PATCH v2] drm/amdgpu: reject mapping info when BO VA is gone Date: Thu, 25 Jun 2026 15:53:41 +0200 Message-ID: <20260625135341.1159-1-alhouseenyousef@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260624172029.2508-1-alhouseenyousef@gmail.com> References: <20260624172029.2508-1-alhouseenyousef@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit AMDGPU_GEM_OP_GET_MAPPING_INFO looks up the GEM object from the file handle and then locks the object and VM before resolving the BO-VA. The GEM object reference keeps the BO alive, but it does not keep the per-file handle open. If a racing close drops the last handle reference in that window, amdgpu_gem_object_close() can remove the BO-VA before amdgpu_vm_bo_find() runs. The ioctl then walks the BO-VA mapping lists unconditionally. Return -EINVAL if the BO is no longer associated with this VM. Suggested-by: Christian König Signed-off-by: Yousef Alhouseen --- Changes in v2: - Describe the handle-close race instead of an initially unmapped BO. - Return -EINVAL instead of -ENOENT. drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c index 212c14d99..6f5b6f4c2 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c @@ -1087,6 +1087,12 @@ int amdgpu_gem_op_ioctl(struct drm_device *dev, void *data, struct drm_amdgpu_gem_vm_entry *vm_entries; struct amdgpu_bo_va_mapping *mapping; int num_mappings = 0; + + if (!bo_va) { + r = -EINVAL; + goto out_exec; + } + /* * num_entries is set as an input to the size of the user-allocated array of * drm_amdgpu_gem_vm_entry stored at args->value. -- 2.54.0