mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink
@ 2026-09-02 18:09 Lizhi Hou
  2026-09-02 18:09 ` [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks Lizhi Hou
  2026-09-02 18:48 ` [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Max Zhen
  0 siblings, 2 replies; 6+ messages in thread
From: Lizhi Hou @ 2026-09-02 18:09 UTC (permalink / raw)
  To: ogabbay, quic_jhugo, dri-devel, mario.limonciello, karol.wachowski
  Cc: Lizhi Hou, linux-kernel, max.zhen, sonal.santan

Accessing abo->client in amdxdna_gem_del_bo_usage() may result in a
use-after-free when the BO is imported via flink.

Disable flink import by verifing that filp->driver_priv matches the client
stored in abo->client before accessing the client.

Fixes: 3cc5d7a59519 ("accel/amdxdna: Add carveout memory support for non-IOMMU systems")
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
---
 drivers/accel/amdxdna/amdxdna_gem.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/amdxdna_gem.c
index 476649685e5a..1353393194e2 100644
--- a/drivers/accel/amdxdna/amdxdna_gem.c
+++ b/drivers/accel/amdxdna/amdxdna_gem.c
@@ -697,6 +697,8 @@ static int amdxdna_gem_obj_open(struct drm_gem_object *gobj, struct drm_file *fi
 	int ret;
 
 	guard(mutex)(&abo->lock);
+	if (abo->open_ref > 0 && filp->driver_priv != abo->client)
+		return -EPERM;
 	abo->open_ref++;
 	if (abo->open_ref > 1)
 		return 0;
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks
  2026-09-02 18:09 [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Lizhi Hou
@ 2026-09-02 18:09 ` Lizhi Hou
  2026-09-02 18:51   ` Max Zhen
  2026-09-02 18:48 ` [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Max Zhen
  1 sibling, 1 reply; 6+ messages in thread
From: Lizhi Hou @ 2026-09-02 18:09 UTC (permalink / raw)
  To: ogabbay, quic_jhugo, dri-devel, mario.limonciello, karol.wachowski
  Cc: Lizhi Hou, linux-kernel, max.zhen, sonal.santan

In amdxdna_gem_obj_open(), abo->lock is held when calling
amdxdna_gem_add_bo_usage(), which then acquires client->mm_lock.

However, the heap update path may acquire these locks in the reverse
order, creating a potential deadlock.

Fix this by saving the client pointer locally before acquiring abo->lock,
and releasing abo->lock before calling amdxdna_gem_add_bo_usage().

Apply the same change to amdxdna_gem_obj_close().

Fixes: 1f513a3ec3a9 ("accel/amdxdna: Add per-process BO memory usage query support")
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
---
 drivers/accel/amdxdna/amdxdna_gem.c | 34 +++++++++++++++++++----------
 1 file changed, 22 insertions(+), 12 deletions(-)

diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/amdxdna_gem.c
index 1353393194e2..0d165b66c1fc 100644
--- a/drivers/accel/amdxdna/amdxdna_gem.c
+++ b/drivers/accel/amdxdna/amdxdna_gem.c
@@ -641,10 +641,8 @@ amdxdna_gem_skip_bo_usage(struct amdxdna_gem_obj *abo)
 }
 
 static void
-amdxdna_gem_add_bo_usage(struct amdxdna_gem_obj *abo)
+amdxdna_gem_add_bo_usage(struct amdxdna_client *client, struct amdxdna_gem_obj *abo)
 {
-	struct amdxdna_client *client = abo->client;
-
 	if (amdxdna_gem_skip_bo_usage(abo))
 		return;
 
@@ -656,10 +654,8 @@ amdxdna_gem_add_bo_usage(struct amdxdna_gem_obj *abo)
 }
 
 static void
-amdxdna_gem_del_bo_usage(struct amdxdna_gem_obj *abo)
+amdxdna_gem_del_bo_usage(struct amdxdna_client *client, struct amdxdna_gem_obj *abo)
 {
-	struct amdxdna_client *client = abo->client;
-
 	if (amdxdna_gem_skip_bo_usage(abo))
 		return;
 
@@ -694,14 +690,20 @@ static int amdxdna_gem_obj_open(struct drm_gem_object *gobj, struct drm_file *fi
 {
 	struct amdxdna_dev *xdna = to_xdna_dev(gobj->dev);
 	struct amdxdna_gem_obj *abo = to_xdna_obj(gobj);
+	struct amdxdna_client *client;
 	int ret;
 
-	guard(mutex)(&abo->lock);
-	if (abo->open_ref > 0 && filp->driver_priv != abo->client)
+	mutex_lock(&abo->lock);
+	if (abo->open_ref > 0 && filp->driver_priv != abo->client) {
+		mutex_unlock(&abo->lock);
 		return -EPERM;
+	}
+
 	abo->open_ref++;
-	if (abo->open_ref > 1)
+	if (abo->open_ref > 1) {
+		mutex_unlock(&abo->lock);
 		return 0;
+	}
 
 	/* Attached to the client when first opened by it. */
 	abo->client = filp->driver_priv;
@@ -712,26 +714,34 @@ static int amdxdna_gem_obj_open(struct drm_gem_object *gobj, struct drm_file *fi
 		if (ret) {
 			abo->open_ref--;
 			abo->client = NULL;
+			mutex_unlock(&abo->lock);
 			return ret;
 		}
 	}
+	client = abo->client;
+	mutex_unlock(&abo->lock);
 
-	amdxdna_gem_add_bo_usage(abo);
+	amdxdna_gem_add_bo_usage(client, abo);
 	return 0;
 }
 
 static void amdxdna_gem_obj_close(struct drm_gem_object *gobj, struct drm_file *filp)
 {
 	struct amdxdna_gem_obj *abo = to_xdna_obj(gobj);
+	struct amdxdna_client *client = NULL;
 
-	guard(mutex)(&abo->lock);
+	mutex_lock(&abo->lock);
 	abo->open_ref--;
 
 	if (abo->open_ref == 0) {
-		amdxdna_gem_del_bo_usage(abo);
 		/* Detach from the client when last closed by it. */
+		client = abo->client;
 		abo->client = NULL;
 	}
+	mutex_unlock(&abo->lock);
+
+	if (client)
+		amdxdna_gem_del_bo_usage(client, abo);
 }
 
 static int amdxdna_gem_obj_vmap(struct drm_gem_object *obj, struct iosys_map *map)
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink
  2026-09-02 18:09 [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Lizhi Hou
  2026-09-02 18:09 ` [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks Lizhi Hou
@ 2026-09-02 18:48 ` Max Zhen
  2026-09-11 15:24   ` Lizhi Hou
  1 sibling, 1 reply; 6+ messages in thread
From: Max Zhen @ 2026-09-02 18:48 UTC (permalink / raw)
  To: Lizhi Hou, ogabbay, quic_jhugo, dri-devel, mario.limonciello,
	karol.wachowski
  Cc: linux-kernel, sonal.santan



On 9/2/2026 Wed 11:09, Lizhi Hou wrote:
> Accessing abo->client in amdxdna_gem_del_bo_usage() may result in a
> use-after-free when the BO is imported via flink.
> 
> Disable flink import by verifing that filp->driver_priv matches the client
> stored in abo->client before accessing the client.
> 
> Fixes: 3cc5d7a59519 ("accel/amdxdna: Add carveout memory support for non-IOMMU systems")
> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Reviewed-by: Max Zhen <max.zhen@amd.com>
> ---
>   drivers/accel/amdxdna/amdxdna_gem.c | 2 ++
>   1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/amdxdna_gem.c
> index 476649685e5a..1353393194e2 100644
> --- a/drivers/accel/amdxdna/amdxdna_gem.c
> +++ b/drivers/accel/amdxdna/amdxdna_gem.c
> @@ -697,6 +697,8 @@ static int amdxdna_gem_obj_open(struct drm_gem_object *gobj, struct drm_file *fi
>   	int ret;
>   
>   	guard(mutex)(&abo->lock);
> +	if (abo->open_ref > 0 && filp->driver_priv != abo->client)
> +		return -EPERM;
>   	abo->open_ref++;
>   	if (abo->open_ref > 1)
>   		return 0;


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks
  2026-09-02 18:09 ` [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks Lizhi Hou
@ 2026-09-02 18:51   ` Max Zhen
  2026-09-11 15:25     ` Lizhi Hou
  0 siblings, 1 reply; 6+ messages in thread
From: Max Zhen @ 2026-09-02 18:51 UTC (permalink / raw)
  To: Lizhi Hou, ogabbay, quic_jhugo, dri-devel, mario.limonciello,
	karol.wachowski
  Cc: linux-kernel, sonal.santan



On 9/2/2026 Wed 11:09, Lizhi Hou wrote:
> In amdxdna_gem_obj_open(), abo->lock is held when calling
> amdxdna_gem_add_bo_usage(), which then acquires client->mm_lock.
> 
> However, the heap update path may acquire these locks in the reverse
> order, creating a potential deadlock.
> 
> Fix this by saving the client pointer locally before acquiring abo->lock,
> and releasing abo->lock before calling amdxdna_gem_add_bo_usage().
> 
> Apply the same change to amdxdna_gem_obj_close().
> 
> Fixes: 1f513a3ec3a9 ("accel/amdxdna: Add per-process BO memory usage query support")
> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Reviewed-by: Max Zhen <max.zhen@amd.com>
> ---
>   drivers/accel/amdxdna/amdxdna_gem.c | 34 +++++++++++++++++++----------
>   1 file changed, 22 insertions(+), 12 deletions(-)
> 
> diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/amdxdna_gem.c
> index 1353393194e2..0d165b66c1fc 100644
> --- a/drivers/accel/amdxdna/amdxdna_gem.c
> +++ b/drivers/accel/amdxdna/amdxdna_gem.c
> @@ -641,10 +641,8 @@ amdxdna_gem_skip_bo_usage(struct amdxdna_gem_obj *abo)
>   }
>   
>   static void
> -amdxdna_gem_add_bo_usage(struct amdxdna_gem_obj *abo)
> +amdxdna_gem_add_bo_usage(struct amdxdna_client *client, struct amdxdna_gem_obj *abo)
>   {
> -	struct amdxdna_client *client = abo->client;
> -
>   	if (amdxdna_gem_skip_bo_usage(abo))
>   		return;
>   
> @@ -656,10 +654,8 @@ amdxdna_gem_add_bo_usage(struct amdxdna_gem_obj *abo)
>   }
>   
>   static void
> -amdxdna_gem_del_bo_usage(struct amdxdna_gem_obj *abo)
> +amdxdna_gem_del_bo_usage(struct amdxdna_client *client, struct amdxdna_gem_obj *abo)
>   {
> -	struct amdxdna_client *client = abo->client;
> -
>   	if (amdxdna_gem_skip_bo_usage(abo))
>   		return;
>   
> @@ -694,14 +690,20 @@ static int amdxdna_gem_obj_open(struct drm_gem_object *gobj, struct drm_file *fi
>   {
>   	struct amdxdna_dev *xdna = to_xdna_dev(gobj->dev);
>   	struct amdxdna_gem_obj *abo = to_xdna_obj(gobj);
> +	struct amdxdna_client *client;
>   	int ret;
>   
> -	guard(mutex)(&abo->lock);
> -	if (abo->open_ref > 0 && filp->driver_priv != abo->client)
> +	mutex_lock(&abo->lock);
> +	if (abo->open_ref > 0 && filp->driver_priv != abo->client) {
> +		mutex_unlock(&abo->lock);
>   		return -EPERM;
> +	}
> +
>   	abo->open_ref++;
> -	if (abo->open_ref > 1)
> +	if (abo->open_ref > 1) {
> +		mutex_unlock(&abo->lock);
>   		return 0;
> +	}
>   
>   	/* Attached to the client when first opened by it. */
>   	abo->client = filp->driver_priv;
> @@ -712,26 +714,34 @@ static int amdxdna_gem_obj_open(struct drm_gem_object *gobj, struct drm_file *fi
>   		if (ret) {
>   			abo->open_ref--;
>   			abo->client = NULL;
> +			mutex_unlock(&abo->lock);
>   			return ret;
>   		}
>   	}
> +	client = abo->client;
> +	mutex_unlock(&abo->lock);
>   
> -	amdxdna_gem_add_bo_usage(abo);
> +	amdxdna_gem_add_bo_usage(client, abo);
>   	return 0;
>   }
>   
>   static void amdxdna_gem_obj_close(struct drm_gem_object *gobj, struct drm_file *filp)
>   {
>   	struct amdxdna_gem_obj *abo = to_xdna_obj(gobj);
> +	struct amdxdna_client *client = NULL;
>   
> -	guard(mutex)(&abo->lock);
> +	mutex_lock(&abo->lock);
>   	abo->open_ref--;
>   
>   	if (abo->open_ref == 0) {
> -		amdxdna_gem_del_bo_usage(abo);
>   		/* Detach from the client when last closed by it. */
> +		client = abo->client;
>   		abo->client = NULL;
>   	}
> +	mutex_unlock(&abo->lock);
> +
> +	if (client)
> +		amdxdna_gem_del_bo_usage(client, abo);
>   }
>   
>   static int amdxdna_gem_obj_vmap(struct drm_gem_object *obj, struct iosys_map *map)


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink
  2026-09-02 18:48 ` [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Max Zhen
@ 2026-09-11 15:24   ` Lizhi Hou
  0 siblings, 0 replies; 6+ messages in thread
From: Lizhi Hou @ 2026-09-11 15:24 UTC (permalink / raw)
  To: Max Zhen, ogabbay, quic_jhugo, dri-devel, mario.limonciello,
	karol.wachowski
  Cc: linux-kernel, sonal.santan

Applied to drm-misc-next

On 9/2/26 11:48, Max Zhen wrote:
>
>
> On 9/2/2026 Wed 11:09, Lizhi Hou wrote:
>> Accessing abo->client in amdxdna_gem_del_bo_usage() may result in a
>> use-after-free when the BO is imported via flink.
>>
>> Disable flink import by verifing that filp->driver_priv matches the 
>> client
>> stored in abo->client before accessing the client.
>>
>> Fixes: 3cc5d7a59519 ("accel/amdxdna: Add carveout memory support for 
>> non-IOMMU systems")
>> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
> Reviewed-by: Max Zhen <max.zhen@amd.com>
>> ---
>>   drivers/accel/amdxdna/amdxdna_gem.c | 2 ++
>>   1 file changed, 2 insertions(+)
>>
>> diff --git a/drivers/accel/amdxdna/amdxdna_gem.c 
>> b/drivers/accel/amdxdna/amdxdna_gem.c
>> index 476649685e5a..1353393194e2 100644
>> --- a/drivers/accel/amdxdna/amdxdna_gem.c
>> +++ b/drivers/accel/amdxdna/amdxdna_gem.c
>> @@ -697,6 +697,8 @@ static int amdxdna_gem_obj_open(struct 
>> drm_gem_object *gobj, struct drm_file *fi
>>       int ret;
>>         guard(mutex)(&abo->lock);
>> +    if (abo->open_ref > 0 && filp->driver_priv != abo->client)
>> +        return -EPERM;
>>       abo->open_ref++;
>>       if (abo->open_ref > 1)
>>           return 0;
>

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks
  2026-09-02 18:51   ` Max Zhen
@ 2026-09-11 15:25     ` Lizhi Hou
  0 siblings, 0 replies; 6+ messages in thread
From: Lizhi Hou @ 2026-09-11 15:25 UTC (permalink / raw)
  To: Max Zhen, ogabbay, quic_jhugo, dri-devel, mario.limonciello,
	karol.wachowski
  Cc: linux-kernel, sonal.santan

Applied to drm-misc-next

On 9/2/26 11:51, Max Zhen wrote:
>
>
> On 9/2/2026 Wed 11:09, Lizhi Hou wrote:
>> In amdxdna_gem_obj_open(), abo->lock is held when calling
>> amdxdna_gem_add_bo_usage(), which then acquires client->mm_lock.
>>
>> However, the heap update path may acquire these locks in the reverse
>> order, creating a potential deadlock.
>>
>> Fix this by saving the client pointer locally before acquiring 
>> abo->lock,
>> and releasing abo->lock before calling amdxdna_gem_add_bo_usage().
>>
>> Apply the same change to amdxdna_gem_obj_close().
>>
>> Fixes: 1f513a3ec3a9 ("accel/amdxdna: Add per-process BO memory usage 
>> query support")
>> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
> Reviewed-by: Max Zhen <max.zhen@amd.com>
>> ---
>>   drivers/accel/amdxdna/amdxdna_gem.c | 34 +++++++++++++++++++----------
>>   1 file changed, 22 insertions(+), 12 deletions(-)
>>
>> diff --git a/drivers/accel/amdxdna/amdxdna_gem.c 
>> b/drivers/accel/amdxdna/amdxdna_gem.c
>> index 1353393194e2..0d165b66c1fc 100644
>> --- a/drivers/accel/amdxdna/amdxdna_gem.c
>> +++ b/drivers/accel/amdxdna/amdxdna_gem.c
>> @@ -641,10 +641,8 @@ amdxdna_gem_skip_bo_usage(struct amdxdna_gem_obj 
>> *abo)
>>   }
>>     static void
>> -amdxdna_gem_add_bo_usage(struct amdxdna_gem_obj *abo)
>> +amdxdna_gem_add_bo_usage(struct amdxdna_client *client, struct 
>> amdxdna_gem_obj *abo)
>>   {
>> -    struct amdxdna_client *client = abo->client;
>> -
>>       if (amdxdna_gem_skip_bo_usage(abo))
>>           return;
>>   @@ -656,10 +654,8 @@ amdxdna_gem_add_bo_usage(struct 
>> amdxdna_gem_obj *abo)
>>   }
>>     static void
>> -amdxdna_gem_del_bo_usage(struct amdxdna_gem_obj *abo)
>> +amdxdna_gem_del_bo_usage(struct amdxdna_client *client, struct 
>> amdxdna_gem_obj *abo)
>>   {
>> -    struct amdxdna_client *client = abo->client;
>> -
>>       if (amdxdna_gem_skip_bo_usage(abo))
>>           return;
>>   @@ -694,14 +690,20 @@ static int amdxdna_gem_obj_open(struct 
>> drm_gem_object *gobj, struct drm_file *fi
>>   {
>>       struct amdxdna_dev *xdna = to_xdna_dev(gobj->dev);
>>       struct amdxdna_gem_obj *abo = to_xdna_obj(gobj);
>> +    struct amdxdna_client *client;
>>       int ret;
>>   -    guard(mutex)(&abo->lock);
>> -    if (abo->open_ref > 0 && filp->driver_priv != abo->client)
>> +    mutex_lock(&abo->lock);
>> +    if (abo->open_ref > 0 && filp->driver_priv != abo->client) {
>> +        mutex_unlock(&abo->lock);
>>           return -EPERM;
>> +    }
>> +
>>       abo->open_ref++;
>> -    if (abo->open_ref > 1)
>> +    if (abo->open_ref > 1) {
>> +        mutex_unlock(&abo->lock);
>>           return 0;
>> +    }
>>         /* Attached to the client when first opened by it. */
>>       abo->client = filp->driver_priv;
>> @@ -712,26 +714,34 @@ static int amdxdna_gem_obj_open(struct 
>> drm_gem_object *gobj, struct drm_file *fi
>>           if (ret) {
>>               abo->open_ref--;
>>               abo->client = NULL;
>> +            mutex_unlock(&abo->lock);
>>               return ret;
>>           }
>>       }
>> +    client = abo->client;
>> +    mutex_unlock(&abo->lock);
>>   -    amdxdna_gem_add_bo_usage(abo);
>> +    amdxdna_gem_add_bo_usage(client, abo);
>>       return 0;
>>   }
>>     static void amdxdna_gem_obj_close(struct drm_gem_object *gobj, 
>> struct drm_file *filp)
>>   {
>>       struct amdxdna_gem_obj *abo = to_xdna_obj(gobj);
>> +    struct amdxdna_client *client = NULL;
>>   -    guard(mutex)(&abo->lock);
>> +    mutex_lock(&abo->lock);
>>       abo->open_ref--;
>>         if (abo->open_ref == 0) {
>> -        amdxdna_gem_del_bo_usage(abo);
>>           /* Detach from the client when last closed by it. */
>> +        client = abo->client;
>>           abo->client = NULL;
>>       }
>> +    mutex_unlock(&abo->lock);
>> +
>> +    if (client)
>> +        amdxdna_gem_del_bo_usage(client, abo);
>>   }
>>     static int amdxdna_gem_obj_vmap(struct drm_gem_object *obj, 
>> struct iosys_map *map)
>

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-11 15:25 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-02 18:09 [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Lizhi Hou
2026-09-02 18:09 ` [PATCH V1 2/2] accel/amdxdna: Fix potential deadlock in BO open and close callbacks Lizhi Hou
2026-09-02 18:51   ` Max Zhen
2026-09-11 15:25     ` Lizhi Hou
2026-09-02 18:48 ` [PATCH V1 1/2] accel/amdxdna: Disable BO import via flink Max Zhen
2026-09-11 15:24   ` Lizhi Hou

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®