From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f170.google.com (mail-pl1-f170.google.com [209.85.214.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4E4E942CB02 for ; Tue, 7 Jul 2026 15:06:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783436769; cv=none; b=DcPMMs6fkOa/NroBqz5heRTOq3B5rHNOIamwQlZu+ZC9Na9Ga4a6kff0xhyxibj1jtFSdW1rQuYIVSFOFvVoP44Wo7rMaEmlVaqbBZMI0x+LOveFnuzf2hy7wFtgCrN3GSTJkE33CFQDdHZbDVdMg/2YOGVI3sI8+u9yMqRMYdU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783436769; c=relaxed/simple; bh=BzrL/EAVn+7c7EnGhtqySqUw9NxIgUyOB5BPuDLL4vw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=gDnjUHWz75WxYkvj6H4487GnoAYvaGubkaEOlUjgp5iF169tJiLh/xC/5eDZ/madlOph7Z9cDv1alPdKQcH6ygB96o6MvGg49xhzqd5kodj/NNmjkfxFAFG+JxB7Vd5xeXrYoFDx1ZPj3XukYHsOuplkSFmAUFrSRYPn2PMiKq8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Dok3zCxP; arc=none smtp.client-ip=209.85.214.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Dok3zCxP" Received: by mail-pl1-f170.google.com with SMTP id d9443c01a7336-2ca64c3ce5fso47431255ad.3 for ; Tue, 07 Jul 2026 08:06:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783436766; x=1784041566; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=ECigN/vOXEtjui4ch8BDCR2M2DmfXoIRQNpruIQx7/M=; b=Dok3zCxPrnNDdk211CxYWyyQzpPOYs+BHC+KmpOFXzLlzKFLTxNzUwCMdwjh7F3nzr vnc7AKf34++6+rW6wOoagzYB7JdxsYPd4k/6naiCt3xlEtean8JKxz/va3YcgHKwgrDz DT2hkPivpnzUoKC3F7y2qTquMfEeEviwp7/SeCwkmxqhrF2wmt5d+r0t9CPNxxPmScj7 IRUoPPLOZGgKcx+zrJV06VBdecjWNCgS2XCPv+OpeN66cGk9z0TmkjxeKDDgL7y31t/A pJ3GDixZbgM96LF59KWa2jr+/CEM2q635t0EMIMLx16wilFyiEXK6aMVw9DCeCzcaHEC exLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783436766; x=1784041566; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ECigN/vOXEtjui4ch8BDCR2M2DmfXoIRQNpruIQx7/M=; b=Tr+Yq+u9eEGj4THk0/infwV2qJkAuQWF2OLWhggewlWV+m7hE5TFPZYICegIjsxVMu 7DOriQhrhls4yjrJlw/sBe6ofRAUsPCMy1pVqsQK+KQHw0jFG4Fc+Whq98RQlHKPfBYu U36SxjgaXUW5hiHlPJC0Qjlp24f8+o/4reOmwlhR8ht0LzGV9F1DUBU8z0EDJz5L2+o6 7qjbz+H1VWncyWid1czipfxJz8pOipMEqFUY3chhge0nkitTmLEC7lBFIjrZSFSBGczf ebEvJO51wHCZPyI7Oj/khU15nvkKBPB0nkCClyluMHRGKTC1PJERg+qthJYA2aPIuweT /fWQ== X-Forwarded-Encrypted: i=1; AHgh+Rp1h40ktIQ0+Ja3N9/a5gH45k94KjEhB550uG8UumgnhbKqwfxt4VlwDaVyiQCr4/Y7geIdcka9yD3J54U=@vger.kernel.org X-Gm-Message-State: AOJu0Yz9udfri/PFqTgSJm7s6tccMAMH1dD5FPrExXaEtW/F4haW+zXR Ithn17Iq8xSeZUfYlYw55TIofebpsgoxXWmlXXu70IH+aqX8XaVR3Cj6 X-Gm-Gg: AfdE7cnFGZWp+JqJQTkfIl+phwNNbkMzZsaehXOn1sJZPbIMOiR7HVRJYWBjAiX3pCB yxGe4+BI+xjsibUKbJOjBU2sXqd03hjes5ioaIJI7GExP9VlziHbUFYEqWCkA9flgw1cRj+uObP c8xpt87S2RNFRlZPpn5kYAnyTdl8HlFGqvRKJgigD7ARZ+pXucOMBgA5S3/E4ouL0ZTeM7HpQm0 H2EyEva8/FgfpB58KYIe0i71N2WymjkLrT4Ja5gi/oSumxNrByWdZwWfrrMbdgWv069FmKr+npY R6nxJSGCxtXV/sngaciwSIs8wdci7iraA4pjSXz0hFWC3S5FuGAHyJDS3h2+Cf4xqAAiqosBx64 eaHm+oX7LIhgikT/JJolBuX/KIGzTZdQbf68k9cPcqA0D+AoRyRd4eY1Xm/sdrxvG4Uf3R9Yocb LOE+foY5KACIuIK+HWqGW571RZ4xOXWQr2 X-Received: by 2002:a17:903:98f:b0:2c9:ff29:3f73 with SMTP id d9443c01a7336-2ccbf00d8eemr56727535ad.28.1783436766121; Tue, 07 Jul 2026 08:06:06 -0700 (PDT) Received: from haichao.tail057a43.ts.net ([2001:da8:e000:1206:239e:a31b:1d0d:374f]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ccc9d3b906sm13966655ad.56.2026.07.07.08.06.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 08:06:05 -0700 (PDT) From: Ruoyu Wang To: matthew.brost@intel.com, thomas.hellstrom@linux.intel.com, rodrigo.vivi@intel.com, airlied@gmail.com, simona@ffwll.ch Cc: michal.winiarski@intel.com, michal.wajdeczko@intel.com, intel-xe@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Ruoyu Wang Subject: [PATCH] drm/xe/lmtt: Unpublish page tables on allocation failure Date: Tue, 7 Jul 2026 23:05:59 +0800 Message-ID: <20260707150559.2274875-1-ruoyuw560@gmail.com> X-Mailer: git-send-email 2.51.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit LMTT allocation publishes a newly allocated child page table before recursing into the next level. If a lower-level allocation fails, the error path freed the page table directly but left the parent's software entry and hardware PTE pointing at it. The caller's failure cleanup then calls xe_lmtt_drop_pages(), which can walk the stale entry and destroy the same subtree again. The stale PTE also remains visible until the next invalidation. Clear the parent software entry, write an invalid PTE, invalidate the hardware view, and then destroy the partially allocated subtree. This issue was found by a static analysis checker and confirmed by manual source review. Fixes: b1d204058218 ("drm/xe/pf: Introduce Local Memory Translation Table") Signed-off-by: Ruoyu Wang --- drivers/gpu/drm/xe/xe_lmtt.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/xe/xe_lmtt.c b/drivers/gpu/drm/xe/xe_lmtt.c index 0c726eda93906..9b0f8d4b26abc 100644 --- a/drivers/gpu/drm/xe/xe_lmtt.c +++ b/drivers/gpu/drm/xe/xe_lmtt.c @@ -406,8 +406,13 @@ static int __lmtt_alloc_range(struct xe_lmtt *lmtt, struct xe_lmtt_pt *pd, if (pt->level != 0) { err = __lmtt_alloc_range(lmtt, pt, offset, next); - if (err) + if (err) { + pd->entries[idx] = NULL; + lmtt_write_pte(lmtt, pd, LMTT_PTE_INVALID, idx); + lmtt_invalidate_hw(lmtt); + lmtt_destroy_pt(lmtt, pt); return err; + } } offset = next; @@ -453,7 +458,10 @@ static int lmtt_alloc_range(struct xe_lmtt *lmtt, unsigned int vfid, u64 start, return 0; out_free_pt: - lmtt_pt_free(pt); + pd->entries[vfid] = NULL; + lmtt_write_pte(lmtt, pd, LMTT_PTE_INVALID, vfid); + lmtt_invalidate_hw(lmtt); + lmtt_destroy_pt(lmtt, pt); return err; } -- 2.51.0