From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 727A747012F for ; Wed, 12 Aug 2026 23:13:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786576417; cv=none; b=ZL+Xp4Y2poAwRN1wpSh0r6Ra0zxB+rqAFT9XPkYhzObdMUNKns+SFLm3ZgyTwArD9TAScYV0pVBLOw1ugeXKrvNqs1psF43BEnxBMHlfFkpKFoLdlp7TvrlICqsMrKAsSTC57XMGAJMhiw6q0VdbQ+NYOcd4xFj0DmMWoMqE4Og= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786576417; c=relaxed/simple; bh=TC/Xzr2z2LXiSDb6I+9W0aw4iSzSEPX8CBnDpuBex/k=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=r19O9PrS7/eMSAjMZrmgp30ew4cmETKp+p6dZ6nTcx7w8KxVOIKTYxKhKKoO9sCzWR5ImB0XTiV+Duj9bo0ryEn5eSUy1aQCSARXKFGR/BybI0I4ULy2H9+0EQd3MHsXT66op86JWnSqGz/hj/Xw9Ua23QsxFDqvPwKIdfACgCc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=T0kssy4z; arc=none smtp.client-ip=209.85.128.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="T0kssy4z" Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4954b3c5cbeso1341015e9.1 for ; Wed, 12 Aug 2026 16:13:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786576414; x=1787181214; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AEqCe/HJ702G2+cOJ6AJfXRuzYV9ZGHajSHLyVpChGo=; b=T0kssy4zWZKOZ/QBpgjkJFNhrq4l7t1tm9lhrNPqfNH/SVUXKtcEbVIp64tHSmgpzz v5efFB5XhrD4gHaRYl4DdvuKZL71VTf8/VaX8+Gv4UGLPq+K2btYmgShJwkfwvnFYvNQ n118v4ngZW8nH4o/ZopQ4FQatnGtKkprg07ZOo5T+lHTFXCSEqDHBqyYtFuQ3iWlxBJ8 l5b/uMkwBOqIWyVcnlkxRU0ePZta+olXN4QFmM/tr94tp5uwxijiUIsL+OEerlDJqfKI R1GXgkkmCmN/LOgEZePQ/ve3ei4ZvOmgm5N+2aJ1zfbn78+Yigjn7BJ6XoRbJZfsgHso 7PMA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786576414; x=1787181214; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=AEqCe/HJ702G2+cOJ6AJfXRuzYV9ZGHajSHLyVpChGo=; b=qoylDPJ8o7WcBOCvMYGEPpyJqM+EBqEWOye25RbNhkM35qpDAAgCfQo1H2HPNaDZ36 YOKluwv/c6XAmVykBbcLQ2hBFHO9y/30fMgkClDcX4VuBMcHIryORF9SoKNZyOYIs+4N L4tOJyqnyZ54FsTO1ErF3ABEI+8jVHVAVonNPA+H/B4n7g9+Z3Re8/JTxXd00eHXwnUY Oj9lWlya2RURgbYOlWrtLUcW6LV1i+0hSFgSVRrPDRXDZ2qXPXo3e/Cgcq+tXJT3Bome vzadKC89CMwsszQwkSs5g2MNB1+cbd67YuunhVBZTl0QlsNMd3IZ1yBYXwanERn42IBL D4Cw== X-Gm-Message-State: AOJu0YxTUy1+c0NmAZGQ/ra6wRWiTGEMbF+nAohKVTZuKzBuiNLYSd49 7pK6Wtp+eGAntH2o4LtmRnYzVF3wE9ceSmIgWD1ppBc66xGXsEArr1vy X-Gm-Gg: AR+sD10+tpWeFnNeUjdqtQm9kuyoaTtJkpDeU7sSJBQOA6yxs0iCEjrfYzhopDFyMQj TCBfd6+G7z1WdrkaXqPTjgFOOJLV4NB1ahd2OXyXkDYj8MKrc8c2iTm/5+7dDWh8KHf6mAlnrNE +2+jpZNaK0F5AOZvKvlXtZZjt/7gEJSEEw+zN0j2xYJOVsYYp6EfMkCnAWI/icjH3itBuz8Li1f oyOs8hexiAgm6pZzFF4kwJj8CTOForcpfIK+/hPA05Xx3GW6gvyAs5uxqKvMCQyJsFoUo0TGPVb gKot3kvPDtkZ0Rq92GP5pswVkajJilUzamP33vayY9eXaeQdp97uR3dqduYHyEfX1ZDGQzFwBgs 24JceVboJH+4wWMOnSsCubPcbsUtyDrsICAhrkjq6HNlH6MxNrucFwaaP9+qctiGlYjjmH7cEch TvD8OdyXeQbqsrpSnPeaBgRv7I7oECH4cyl3oc6DXb1Mw1sCftad8OU5el4kxioGlaAlTUuKRoj cVR9GFgUDERNUTYdo6ImBQGVArwFed4HEp4jAn7Eq5JOIkE5zQ2d0y7QS4lLkpfbQ== X-Received: by 2002:a05:600c:a05:b0:495:7561:a9cc with SMTP id 5b1f17b1804b1-499821e762dmr6690785e9.4.1786576413605; Wed, 12 Aug 2026 16:13:33 -0700 (PDT) Received: from Neo.taile6b6ba.ts.net (ip-109-193-028-127.um39.pools.vodafone-ip.de. [109.193.28.127]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49981b631c1sm44532245e9.14.2026.08.12.16.13.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 16:13:33 -0700 (PDT) From: Marek Czernohous To: nouveau@lists.freedesktop.org, dri-devel@lists.freedesktop.org Cc: linux-kernel@vger.kernel.org, Danilo Krummrich , Lyude Paul , David Airlie , Simona Vetter , Ben Skeggs Subject: [PATCH v3 1/4] drm/nouveau: unsubscribe the channel-kill event before the fence context Date: Thu, 13 Aug 2026 01:13:27 +0200 Message-ID: <20260812231330.705425-2-mczernohous@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812231330.705425-1-mczernohous@gmail.com> References: <20260812231330.705425-1-mczernohous@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Marek Czernohous nouveau_channel_del() tears the fence context down first and only drops the channel-kill subscription later, in the middle of the nvif object teardown: if (chan->fence) nouveau_fence(chan->cli->drm)->context_del(chan); ... nvif_object_dtor(&chan->vram); nvif_event_dtor(&chan->kill); The subscribed handler is nouveau_channel_killed(), which calls nouveau_channel_kill() and from there nouveau_fence_context_kill() on chan->fence. A kill event delivered in that window takes fctx->lock and walks fctx->pending on a fence context that context_del() has already freed. Nothing reaches this below Fermi today, because the subscription is gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On Fermi and newer the window is real but narrow, since a kill has to land exactly while the channel is being destroyed. That is reason enough on its own, which is why this carries a Fixes: tag. The last patch in this series subscribes Tesla channels as well; nothing kills those today, so it does not widen the exposure now, but it is the groundwork for a recovery path that would, and the ordering is better fixed before that lands than alongside it. Drop the subscription before anything it depends on is torn down. Fixes: ea13e5abf807 ("drm/nouveau: signal pending fences when channel has been killed") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Marek Czernohous --- drivers/gpu/drm/nouveau/nouveau_chan.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_chan.c b/drivers/gpu/drm/nouveau/nouveau_chan.c index 598513f60449..f142f6310596 100644 --- a/drivers/gpu/drm/nouveau/nouveau_chan.c +++ b/drivers/gpu/drm/nouveau/nouveau_chan.c @@ -90,6 +90,14 @@ nouveau_channel_del(struct nouveau_channel **pchan) { struct nouveau_channel *chan = *pchan; if (chan) { + /* + * Drop the kill-event subscription first. Its handler + * dereferences chan->fence, which the fence context teardown + * below frees, so leaving it armed across the teardown leaves + * a window for a use-after-free. + */ + nvif_event_dtor(&chan->kill); + if (chan->fence) nouveau_fence(chan->cli->drm)->context_del(chan); @@ -100,7 +108,6 @@ nouveau_channel_del(struct nouveau_channel **pchan) nvif_object_dtor(&chan->nvsw); nvif_object_dtor(&chan->gart); nvif_object_dtor(&chan->vram); - nvif_event_dtor(&chan->kill); nvif_object_dtor(&chan->user); nvif_mem_dtor(&chan->mem_userd); nouveau_vma_del(&chan->sema.vma); -- 2.54.0