From nobody Wed Sep 30 12:08:51 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A3E67313E38 for ; Sun, 9 Aug 2026 05:13:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252389; cv=none; b=kZscu/NatZBLfS7u1TPl2qkGCMIEotK++23WeVhdRh77xTVDJr5mzdtvUjgr2fuJ932PmMtJxkJJF4VJDIwoze/Cg+OuNwdlF6UqcGmamkxtI+jR5XoqKXEBcT6mz7lD6TWvxhBWCXuvPfxqNmUtGSDCOM5jPRJqymx+fuewvbg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252389; c=relaxed/simple; bh=aDj5aLG7NStNslfYhTIl3YYv6XZgFNUFXK8u7qYzlf0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=t2pWntEg+jRkazSnbEIzsT5ax3hiLrOsz41q2uXh6VWRx4H0TZ+mOPLC2AtDEhiYRjlyH9tyMzaPN7AnyyM4ylzE01VUk+Nocn7xp9+Z11w91w5RXmeffUH6uB78uzGioNwGlNlr7akwsI5cVvJ5TzfuaZV9BbDoVZifplghUzU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Wy07lA7Z; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Wy07lA7Z" Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2cee9b74ee1so6906665ad.3 for ; Sat, 08 Aug 2026 22:13:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786252388; x=1786857188; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=A3BeIAtfJ2/omVu82I5VMk45uIa8CTiHrIT/44X40ds=; b=Wy07lA7Z6SdoTXQHoRxg3TsA0mvR1G1JD/6HOD0mNNmX3wqpqNbepSmltG5Rwz50UW x2U728Ci2IWafVVr4FlgpliMSRZezoXn9oov7rIWjH/qeU8DIh+wvY28pz9HGshngzbj 1Hvo0U5Sv+qdnJQ7GCZgY1fAIAHxGcesuy6Ebg8R5IE/37YxIz9h+VSz32nsxb8Vm+4P Eeef+XddLV05mrIjnnvpAu7iK4R7x1CGhHgxyzHjv0rYql05aIv+jf+x/zbnfCp4Jvp7 zMhuUfg5v9uQxymfvhMGYhmGK3Gte1Ku6UgCU3UCuHSmJ4eUdYImv4uQ0ySXZzoU+x00 A2Wg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786252388; x=1786857188; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=A3BeIAtfJ2/omVu82I5VMk45uIa8CTiHrIT/44X40ds=; b=U1yzhN1GlTm/vxD1OpZI2b7A0YbPRPhz9hZqI7QXUd4cC84Vk2XLKEa9NEoEZqt6zC YIcSRYsTx4Fi3Xu30QMzLkiLqeQU3oE4tXZFC0TIFMiJ2pGuDON+lLINebZdM2iEdUBR vYAIBbgyGeLgHiBg13ljDak2tyAXI6VX1VZ5fiupgt7t7obh3+pYh2yHD5ekDtMGU8BW ULadanUbhQhemQCiGNdm79Al/jmOVQvNbwKsp5vcZeTNc1dLEKnGU/zm7tY1s9FsEDgd cFabueMe9CABCNYdnKmSMHg2dmC4+FEKqRlCBFm8fhOWaFh3Lkek6wpChiUoESaqyzN6 zkww== X-Forwarded-Encrypted: i=1; AHgh+RpoRmZs0gby+/Ow7eA1DhgTEEnrpaLZ/ZG9E34MSPZVjdQptagLNRLTXQDwIjG7hM7BLrjt1Wir32LpxD8=@vger.kernel.org X-Gm-Message-State: AOJu0YzYMJcjWBkvRjA6X/ax8SgVUKSTpoggBvtwtYR90dL8bT19q+LR b1CWA+LtvxRv2slnveonx5ErpOP5saayFU1JhjImeZlYdjNe48pHBFvu X-Gm-Gg: AR+sD10DlHh/0XRDDo4LbPqPnOaoa0SHjqZEICEcSqILaKgbgmDogxHsLBnaIz+rpla CnZnt477TzLGUJf3tFrwy3KJndsh/CYwhUFH95EGOhveVkLlPW/aHpDuqHgc2mgbWCp82rHN1/C iy/uTuWKTjbYRENawo4khqkp2rNrLn8HsaAmztXxDKn5r4ad4syVumsrFaGlpR1FeQ0m6nSrLDP uPupDi/x0POA3LLFHyLGiaipExEuyavvjedQMGnjsmUIaF3Sdg1xhewDhApZ9KITY8G2s5+iZMd eR5+H//pJGdf7H9w7cU31tbo4eVe9dQ5B0RpBJMkv1+mVNnn0vkG/Nz9podN60kHnf3rSAh5Yy4 IFVEKNX9UUuYkvSv7fr1pq6PMGVoj/EQ2EuLwK4tTVc+j7nC2M30SDx2evhyWYa5tYKeOWSSgbY usCC7I+6A3qleR5lrLyYCv2CaYTs+zlix/+7rE+4rVOcHbkH8MsKL0QYaWtmFql3tNH0r0+C4Wc lSaZS/ZG/xx X-Received: by 2002:a05:6a21:a38d:b0:3bf:6fb1:ce0d with SMTP id adf61e73a8af0-3cb85ea3663mr41867421637.21.1786252387800; Sat, 08 Aug 2026 22:13:07 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.108]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8a7395sm27095702eec.9.2026.08.08.22.13.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 22:13:07 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v3 1/6] drm/amdgpu/aca: Fix race condition and UAF in error cache logging Date: Sun, 9 Aug 2026 05:11:55 +0000 Message-ID: <20260809051200.3276-2-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809051200.3276-1-sreekuttan2156239@gmail.com> References: <20260809051200.3276-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In aca_error_cache_log_bank_error(), find_bank_error() released aerr->lock prior to returning bank_error. This created a time-of-check to time-of-use (TOCTOU) race window where a concurrent caller of aca_log_aca_error() could acquire aerr->lock and free the bank_error node via aca_bank_error_remove(). When execution returned to aca_error_cache_log_bank_error(), incrementing bank_error->count resulted in a Use-After-Free and potential kernel memory corruption. Additionally, bank_error->count was updated outside mutex lock protection. Fix this by acquiring aerr->lock at the start of aca_error_cache_log_bank_error() and holding it continuously across lookup, creation, and counter updates, while removing redundant internal lock acquisitions in helper functions. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 18 +++++++----------- 1 file changed, 7 insertions(+), 11 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_aca.c index db7858fe0c3d..d0d473082431 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c @@ -237,10 +237,8 @@ static struct aca_bank_error *new_bank_error(struct ac= a_error *aerr, struct aca_ INIT_LIST_HEAD(&bank_error->node); memcpy(&bank_error->info, info, sizeof(*info)); =20 - mutex_lock(&aerr->lock); list_add_tail(&bank_error->node, &aerr->list); aerr->nr_errors++; - mutex_unlock(&aerr->lock); =20 return bank_error; } @@ -249,22 +247,16 @@ static struct aca_bank_error *find_bank_error(struct = aca_error *aerr, struct aca { struct aca_bank_error *bank_error =3D NULL; struct aca_bank_info *tmp_info; - bool found =3D false; =20 - mutex_lock(&aerr->lock); list_for_each_entry(bank_error, &aerr->list, node) { tmp_info =3D &bank_error->info; if (tmp_info->socket_id =3D=3D info->socket_id && tmp_info->die_id =3D=3D info->die_id) { - found =3D true; - goto out_unlock; + return bank_error; } } =20 -out_unlock: - mutex_unlock(&aerr->lock); - - return found ? bank_error : NULL; + return NULL; } =20 static void aca_bank_error_remove(struct aca_error *aerr, struct aca_bank_= error *bank_error) @@ -306,11 +298,15 @@ int aca_error_cache_log_bank_error(struct aca_handle = *handle, struct aca_bank_in return 0; =20 aerr =3D &error_cache->errors[type]; + mutex_lock(&aerr->lock); bank_error =3D get_bank_error(aerr, info); - if (!bank_error) + if (!bank_error) { + mutex_unlock(&aerr->lock); return -ENOMEM; + } =20 bank_error->count +=3D count; + mutex_unlock(&aerr->lock); =20 return 0; } --=20 2.54.0 From nobody Wed Sep 30 12:08:51 2026 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7F30037A840 for ; Sun, 9 Aug 2026 05:13:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252395; cv=none; b=qetonFTL8hQb5UYQL+xBF0D/acDDPwv+ZngwPNvX1w/cNcj0MzNsBFd1ixR1PxvRyQL+3bi9y3ZOag8HP5Nvtdtw1E8OEE27OgDz4dE67BX2ryAENVmvIO/EGYtFj11yfRW90TQSdDfBETJprPv+qnJfOUkwPSQk5eKcDhkDtnQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252395; c=relaxed/simple; bh=weRrChkTJgmtJ7e7uWxoKD+8+f+Z6NRdCPQ7Z7d8o5s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=akborF99LgO5mOTQ/HuZuMyOHa56GPkEzicPAL7fHHADMbP3NEa5OAt9xt/dTswnRpirAX77NbgjdpA2rhtbK7BN0WcAjk2/Oeqx3D8x8A5VaFWKg6VkkI9WcrbzHmsTQM+KiZAUTxWdjry9x05U6lCVrvtZGmtFmcNq+DqlMJk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=G73NUjDz; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="G73NUjDz" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-2cacb8416a1so7718675ad.1 for ; Sat, 08 Aug 2026 22:13:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786252393; x=1786857193; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=deoqn41jn4hqxaXBU0LER8gLC0cAyHmrQg56bcVPpQA=; b=G73NUjDzAM+8ywqX0G1L+oyuZkMG7BRm3WhiC6ifrJUVoHi/atM3M4ijSk7g7qBmhu klI+2DijRnwNKqUUf6Yjr4oYZrCken8EgCmzV8HdmNZ059WJ9VMlDfJPRgJl2v69r+/I 3sRPNZSclWCGogohEqlisc5TD3fGwPQXZtdG96s5tEpzNczGSEoHU3oOB9RKOx7Uugc4 El2VeyT7fjbsonx6JfTiYHsIyHxqL+72F2V++BrdlgjTjQ5TL6K7oTzREecYe56vEt6N 4dXyM1Z6XVSPwn4u4Yp8lEFoKd773idQm7LijgTq0v2XrRDJdUhqwTmoW5DTvMCN3K1x 0ZaQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786252393; x=1786857193; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=deoqn41jn4hqxaXBU0LER8gLC0cAyHmrQg56bcVPpQA=; b=J9EmDdsgWl3RqG+eAXyeO18iHafzoD6tWIBq6VBYAB3+sn41DQoVeKgM8uXQA+LBYK VJE/Nl4qQB0i7FcbPQOaQSX4y4zg93bHCyy3HLIJ9BzcJ8DsY35gvF7GPNZLzrRyn60O MMPvb3FDNs8iXrdIgLgSQgQUxVQE56gDAGoTrSi7ED10UmNSTPQsYbnwlJVC7kNlQ4LN vNL8M/o4zj+c46R8doF1s1qxAWNXh6FjXvOh3TUN9GFgQVTxBBud8FENaFr++fdFiZVA ZbuCick6ALrZTOOj1EDw3e2VCIe6KNMWSiB9QuF/7g40D1GCMuGm1rRx6c6c0alLSEhX pQHQ== X-Forwarded-Encrypted: i=1; AHgh+RpcWJNInNstpKe7+igLV0ShHevigdi/ZRuOWoG1S7xUCSg5uBS8rKbO8AhnJVzVIAqW8UL0uoBMI7fp/OM=@vger.kernel.org X-Gm-Message-State: AOJu0YzGrVi6GAXXLZkO2liiHmkxmyTgQ1MdHG7bT/Z4m7MBz1s1e5lP G2yeDsEW0gmEMNaF0l/F/ccNLL8jejuVvKqcqHav/EHUPHjdyOHOe3Yr X-Gm-Gg: AR+sD12olzA4wU+iHBCXQpcji4Ed+ELPx+WnNA4pp132AslAAFwLXk8SBKVxVYATDvc MSlCoGAeevkKbcIfkAK48Rvwks0z06g6EK51zJ5TwTUIdcF1kGLi4X0CwQrT5jVRtXXtL5D2/8w 1uJBPxLMCF8g7xg1mUcW1k5k1u0tR80FQRsmJRjIF73O4WkRhKzBYPHT28BkSvjyy8X4ZO4Qqzr CGZv2PbZ0gvPPVkqZgYWQU8m9+KikfGFop0ozuSyrDLXIqSyPSEyRb1enZwe+bWUEjqx3UlAF4R DHDmdqvm9g2LfTz7Ke1q6TJWgBTj3LmS7hDrRx4HI4YS2fV6f7AlNSLKjEy8tDUhhB2UFkf3hp0 PTWhgZQM2rUXhNECGcf0zlzBgFFU80xlhuytLd3QKPcE3Vm04/iXBZf+8lfvWbf50iIyGJ69DtA X0n3wQ6iRKcVCn2Bmhq26xeVumeFeUUQA7u5RgSWvKD58IVtB8ehlqQ1BluXwwfMvUjlQ6YaqFZ Qi0LKvusfE64F+dZcGX2ynI X-Received: by 2002:a17:902:f608:b0:2ce:d957:59c4 with SMTP id d9443c01a7336-2d2a8692dfamr135589535ad.6.1786252393509; Sat, 08 Aug 2026 22:13:13 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.108]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8a7395sm27095702eec.9.2026.08.08.22.13.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 22:13:13 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v3 2/6] drm/amdgpu/aca: Add upper bounds check in aca_bank_hwip_is_matched Date: Sun, 9 Aug 2026 05:11:56 +0000 Message-ID: <20260809051200.3276-3-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809051200.3276-1-sreekuttan2156239@gmail.com> References: <20260809051200.3276-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In aca_bank_hwip_is_matched(), the 'type' parameter is used directly as an array index into aca_hwid_mcatypes[]. The function previously checked whether 'type' was equal to ACA_HWIP_TYPE_UNKNOW, but did not validate whether 'type' was less than ACA_HWIP_TYPE_COUNT or negative. If an invalid or out-of-bounds enum value is passed, an out-of-bounds memory read occurs on the aca_hwid_mcatypes array. Fix this by validating that 'type' is strictly greater than ACA_HWIP_TYPE_UNKNOW and less than ACA_HWIP_TYPE_COUNT before performing the array lookup. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_aca.c index d0d473082431..c76664af9902 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c @@ -138,7 +138,7 @@ static bool aca_bank_hwip_is_matched(struct aca_bank *b= ank, enum aca_hwip_type t int hwid, mcatype; u64 ipid; =20 - if (!bank || type =3D=3D ACA_HWIP_TYPE_UNKNOW) + if (!bank || type <=3D ACA_HWIP_TYPE_UNKNOW || type >=3D ACA_HWIP_TYPE_CO= UNT) return false; =20 hwip =3D &aca_hwid_mcatypes[type]; --=20 2.54.0 From nobody Wed Sep 30 12:08:51 2026 Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DE1E7378839 for ; Sun, 9 Aug 2026 05:13:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252403; cv=none; b=ZerZMVJpU1dfumpcsIvCYl9L+G55PZ5lvcPKkhG7lgiyum3R9C0GftdJeNdQpdaGcB4PqkVi20HRlyemEcS45fzbQRItAUNUirZTB4GZPaoetl22dbcAn+eQbMJPdaSxGe6jaf68k8F94pGA3yoaA4kMCLnLIEobrTiM4FS5ttM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252403; c=relaxed/simple; bh=CdRaoqrf4mitwqnuTmZg9JiSXp90MrPDsPBYyNFz4iQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fft8dZpGL4/Jk+kGq8JbwCjCBumKazxGSTph0QZrpqtL99g3JWFjZET9CwurJzdQJPZ7p7Lnblg8JPO8ONHtQXz7uPYvDjsPG7B2Yax4TVe83JuLFzWYghtZvQvhHhPT5hHRIrBsfCZuOUXYwW7nrRWG7EP+GarKwY4qiB084qw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JdXCmKdJ; arc=none smtp.client-ip=209.85.214.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JdXCmKdJ" Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2cace91f112so7880995ad.0 for ; Sat, 08 Aug 2026 22:13:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786252401; x=1786857201; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Mqhs7Zhem08+gKWpC13qqFjQ+/RUK8tqoU89vwfPtBM=; b=JdXCmKdJBhODRHiK/VUfoP+okcYnVMAyPfLHlD5cSx1AdJVM8/up/C1iNnuorzkoWE C9JDERpRlbkuVJQgPAINqEeH1p4n6ck/1+pepMcTiebtCxQqkemU8iboHYC4F2nJ3nE6 JtbPsnsGJPjQZC7hJpeU9HUNyiLeVhZYSI/7WNJc5JQq+Sd3rRBBwmpYu8HGl8kZ0fTy nn+xAky1oi1tCUOZkaebwSgEtA1tdIVLUJsU3NNLPMZwCIa1lKbXpqDNmBeIGFiZl8Ao OT/c53NC1Nn374zvFa3/HysNE5ccV8LsPtX5xlr7/GbcIAcLJL3Rjn99iukR1uNE2x8N u1Jg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786252401; x=1786857201; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Mqhs7Zhem08+gKWpC13qqFjQ+/RUK8tqoU89vwfPtBM=; b=r4iTRqfM3JvgrKp2XXviZ+GjnDiNKZHRHw15o8NNTKFZy9qTQjEVXnDe8MRb8MZCAJ ruYFi4uN9VIxqU+iXHdm4Dr3f+ipepBdUP14/vozSBhKIeJSuxM+pyq7IOWEJ8ThF79w odQYkzMaIcOkbRthKDVR9bBkipqpO1zITzQGhIUtBc2XOkm0hRQwODfJpwyPLysc8ItR 3IOOnD0a19cb7AJ3bAcurEKdRY+yh3WNgaAnTADGWyjjli2n+vYU5TAskMqW81d4bqLc KrD6ceQwyhQeszvsbPR8qpAvFjKr5p1hSTQIwnLT3R4vO6C1pSxJaJngYMjwdCaFC/EM ekCw== X-Forwarded-Encrypted: i=1; AHgh+Rp88W44tJ3WTokE58ydQ06jHD3LJXLDPtzMpf/FIClooJZEmz8HZmbBpEWRY7PapuhJJQSa0M/yGOZpLNY=@vger.kernel.org X-Gm-Message-State: AOJu0YwUPUtBvHLgfXFh8vgThfan27w+OtK2fHaPkq08qylhMaluU6ig 6oHkKUVc0HoerYeTgoAxGAGySUYE7aoNueVkbCv400Xp0p0X7MsfabVi X-Gm-Gg: AR+sD13E5xt2uqCzfADZAgeNxvMeeJBUyQINc/uRzKmek8tDitysIvEbeIb5/yb8eBm 9jlXomQy6jJvi3HcOAWcTBGqcnYHgdEhGfjXGZMWU9xyVnJCV+tFCUAp3bjkiepndTVMSrAOzDU e/G3vV0iKYeb5GUr3TyB/Tll/+/Br42METVeQ90+faDGP7RNjnqWAtu6KWaeHjQSRMb3RWZjtjs XHusB1FNVWHnwHICTfxFmKPFgge1w3P31V1IduWbTOdRlcIuUezDdA986OlqJ70py0GXiWfiizP NlMhK5bXSsESvrs+bUFPrlO6APIXfX69ipkJfN9xyoZA/4Qg25GLma9Chr1KLAGYXiSGh5SvPAo 7t7e/9o/Up+Qjsow2OLKKcT9VCU3OniWvqYxUSNdrkYSw5kmMP3gpI5qCgsmYBYrRriAW+CwRB4 WFmZofD0SAI/58VSeVQKrvg3769JBzGkyXFC24QJFImqAACPFeoh6SJE5P5b6qO0paFRsI7dH9a Pc9FIohNmW7PzP7GMsrRa8= X-Received: by 2002:a05:6a20:9e0e:b0:3c3:66c5:68cc with SMTP id adf61e73a8af0-3cb85efa4f9mr43331123637.21.1786252401232; Sat, 08 Aug 2026 22:13:21 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.108]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8a7395sm27095702eec.9.2026.08.08.22.13.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 22:13:20 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v3 3/6] drm/amdgpu/aca: Fix inverted validation logic and list cleanup Date: Sun, 9 Aug 2026 05:11:57 +0000 Message-ID: <20260809051200.3276-4-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809051200.3276-1-sreekuttan2156239@gmail.com> References: <20260809051200.3276-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" aca_handle_is_valid() returned false if !list_empty(&handle->node) evaluated to true. Because active registered handles have non-empty nodes in the handle list, valid handles evaluated as invalid. Consequently, amdgpu_aca_get_error_data() returned -EOPNOTSUPP whenever aca_handle_is_valid() evaluated to true. Fix the logic in aca_handle_is_valid() to verify that the handle is non-NULL, contains a valid mask, and is currently registered in the list. Update amdgpu_aca_get_error_data() to check for invalid handles and return 0 instead of -EOPNOTSUPP so non-ACA blocks in global RAS queries pass through safely without breaking error telemetry. Additionally, update remove_aca_handle() to use list_del_init() instead of list_del(). Standard list_del() leaves node pointers poisoned, which causes !list_empty() in aca_handle_is_valid() to evaluate to true for removed handles, leading to a potential use-after-free during device teardown. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_aca.c index c76664af9902..06cb3ad1ce62 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c @@ -586,10 +586,7 @@ static int __aca_get_error_data(struct amdgpu_device *= adev, struct aca_handle *h =20 static bool aca_handle_is_valid(struct aca_handle *handle) { - if (!handle->mask || !list_empty(&handle->node)) - return false; - - return true; + return handle && handle->mask && !list_empty(&handle->node); } =20 int amdgpu_aca_get_error_data(struct amdgpu_device *adev, struct aca_handl= e *handle, @@ -599,8 +596,8 @@ int amdgpu_aca_get_error_data(struct amdgpu_device *ade= v, struct aca_handle *han if (!handle || !err_data) return -EINVAL; =20 - if (aca_handle_is_valid(handle)) - return -EOPNOTSUPP; + if (!aca_handle_is_valid(handle)) + return 0; =20 if ((type < 0) || (!(BIT(type) & handle->mask))) return 0; @@ -717,7 +714,7 @@ static void remove_aca_handle(struct aca_handle *handle) struct aca_handle_manager *mgr =3D handle->mgr; =20 aca_fini_error_cache(handle); - list_del(&handle->node); + list_del_init(&handle->node); mgr->nr_handles--; } =20 --=20 2.54.0 From nobody Wed Sep 30 12:08:51 2026 Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0CF8B37AA96 for ; Sun, 9 Aug 2026 05:13:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252412; cv=none; b=uKsdtK0YsNNyB+YYqrD46A19TYXK50xxS5CZOuAZhHpZxxtH7Ozjw2l/V1WgplA4dGzAVl5tX1pw328UTVTPvX4rw9M3JAGEnLDp1UZMYxORwObZyOBVdAp6NyXjlASZJDu0uyVIuyo60acfhdnfpWcdkqKzTZnrAtbdnfn8WmE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252412; c=relaxed/simple; bh=HM3bIsBWx6Kxbvo0xciiKgwouz3z/aGaJ1b7nxjummU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ukRhp9Z3imn8ezenyAGk3MDHo5d+74JAHg56FgorRgpun4nh1G1+f34EpLsgAgykE9jdrLbspXNCAT5prPHwsgMew/Q/iIHZWCTi75tLy9gdhv0ZPmZUYrTriAqnis7NpzwojU8Bmn1qWDko869GWGGDGH4ESmY4quEBRCkHqnA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Dy6xakmR; arc=none smtp.client-ip=209.85.210.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Dy6xakmR" Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-84862b0d5f8so566711b3a.3 for ; Sat, 08 Aug 2026 22:13:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786252410; x=1786857210; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=C8on5LBVsYqwWr9ndoV0oVFp6EULFueLmmkrZV0DJAg=; b=Dy6xakmRHOSMoWoFNK9h4rs/t+bs8l2w1LBko7Q7uttcTCcSHJE1PdQR5eY+XFibc1 lAaC5ZEufV030Sk7jMy95gOkVyvP7YK4n+a/Y05AG5m3eb3Xfv+8wHxROsPnARzkCLJb eeG5EF80Rqpu/sRnD4UwZ9trc71ZDbQ4l8nwHgbA3cZoOB86kzBqyXgAOxhg6ESjT9QD XgSTNSMELULqoVVwrOZYXU655aWB3oS7bIwjUQf8h1QiZNjtegGjJBShSM/VmW8KrMhO 7vbLZBX2/HZkNhPme1DxJO2uEV32l57h+xdWbj6jJ5XBrWs36o4xEpzLAYfeX7sTHGhj AxyQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786252410; x=1786857210; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=C8on5LBVsYqwWr9ndoV0oVFp6EULFueLmmkrZV0DJAg=; b=mPPgb5v1axMiB2MYsAxJE2yOI3foMjl/38wGTS6cE1YpoyMcNhNDF/a3o+KoWVeoTi 4a+5E7XO1LOVscxkdSUdwwfJFIKLE6AqXhog9JZiyZSlZ8/6vHhyLu6kU+zxwfgjm3uL NCQcKJWrtyu+ETnE1ETuFgQuFs2ddeFlEnOiIkSgZG0zvV0AQT+o8aRw4w/3nadjLWNY 01JlXJZ6nWrozvWpQ4L59+ycgO8HcaMo+lD/M0pOqPetS+QmKZLRG6R7/acykWuEEwkM Ncrk0RR27gPDpImzwJtOaUI+3U4fUhdevXKUtzCh46KeT6CSJgeyyOga6u3dZ9jtYdl7 OOog== X-Forwarded-Encrypted: i=1; AHgh+RqvbxuJ4JTHexZQKeT8GwrMxSm+MJnPi2MLnuUwbQycA4CaTYr6DUtHEntpah8cAeNg/nR76r4ShOotz9g=@vger.kernel.org X-Gm-Message-State: AOJu0Yzlbi/ihvF6yryita1zhYC+Q2Tqt/FfFXUzMpmUn6dUcR0dozp1 bvt6vgnyq+1aGtJEF8FrnNSj4DDg6QJRkaEa0zIRQk2bGOJOtS6s1CYUtXabgn2d X-Gm-Gg: AR+sD133kRn/iyAmc6CUF1nAZLJqozg4736c/Qx2TQsoO5OI6hDvxZPfk3ej04Y7BG3 +JLTI2ipndgqagePLEBqEr+Fnw917L5jQy4/2Da4n6UqU+Gf0tPyIxy+9wGovnbCA5DWnlmqjNZ panozqsBx8tgyLPHCaR6YBSadCOpNMFqZCZFARiTBemCuwZJhnLtlmTOv9UyksIUh/0oqsKh8H7 5HqAXibPwJj4WS8HtM+bwpXh6gWORroBq53V0BpEo5dpFwP6NBO+j1x2ehxXkj8XGITnZoGdybD 2zKRs1P9ilvqxx3BaMSAT3jEOhOfViUMd75IlnddipYnXuk0KWUEu7/3myPzRXvK/ptqbbcQlui aIz5s6qFbd9uTdVoZmBrdojGQ6kmuBmYFE6pGnLrgtEpqbowk/wScc1o9oLeZREhd5IS1ZfHmBB KXCM5BzWrIU2kpuytX3s9r6n7RoF9kjnqP6vN+x6RtSdrJAPZZulNQ3303d62sp7Qq+TuywdHlY o/ELBSB0oh4 X-Received: by 2002:a05:6a21:3117:b0:3b5:489c:7bb5 with SMTP id adf61e73a8af0-3cbadc97c22mr27425139637.28.1786252410244; Sat, 08 Aug 2026 22:13:30 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.108]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8a7395sm27095702eec.9.2026.08.08.22.13.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 22:13:29 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v3 4/6] drm/amdgpu/aca: Add missing NULL check for banks parameter in aca_banks_add_bank Date: Sun, 9 Aug 2026 05:11:58 +0000 Message-ID: <20260809051200.3276-5-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809051200.3276-1-sreekuttan2156239@gmail.com> References: <20260809051200.3276-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" aca_banks_add_bank() verified that the 'bank' parameter was non-NULL, but passed 'banks' directly into list_add_tail(&node->node, &banks->list) and incremented 'banks->nr_banks' without validating whether 'banks' was NULL. Add a NULL check for 'banks' to prevent a kernel NULL pointer dereference if an invalid pointer is passed by a caller. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_aca.c index 06cb3ad1ce62..79326389d75c 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c @@ -49,7 +49,7 @@ static int aca_banks_add_bank(struct aca_banks *banks, st= ruct aca_bank *bank) { struct aca_bank_node *node; =20 - if (!bank) + if (!banks || !bank) return -EINVAL; =20 node =3D kvzalloc_obj(*node); --=20 2.54.0 From nobody Wed Sep 30 12:08:51 2026 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E570137A840 for ; Sun, 9 Aug 2026 05:13:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252421; cv=none; b=GDgm7kEvMUCHy3118XysU9Oy0639DuyfnYL/8IcoS7fsrqWmVXvcLT0HqPo5UurDfXbB4jJsPWnaBFbvXOlLUfJ5dheQY2mXq8SoSmAJNmxcTBLAt1qec7Rd0iJU8zEULGjFnaFY1onxrC1iJgNKwdvBdw8+2Ky7cPfW7II4ylM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252421; c=relaxed/simple; bh=y0zMskDwVEjMDQcAHD6HmVFV4GEVmq+PJEhAepuOUOY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iNZxSLR526hvzZHOm8dWzL4s4YtSni2boVrz4zs6H8wRxwUx9QEXN9nRSewZJX9jqJJdOcGRlxx1IDFd5D7p9tiiPdX3V1w+iDjbHGdyVNbJr0oorl/hjHr13IOUamWKQib9u/Y7jmK+XzgCEkS307CVqBmoZe7r9aeoCd09oZo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=kSWjT95u; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="kSWjT95u" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2caced6038eso7520265ad.0 for ; Sat, 08 Aug 2026 22:13:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786252419; x=1786857219; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3uV1jDlXdjYzrBZ5UiAE52SxJwX6HGbMM4vfraaFeu8=; b=kSWjT95uPnCo3RQuf+yIZ2JPtY3fYAJXJJWGQQnk7dTf6agH+p2rHe/4m8ijKyZX3R liQ+ehSJBkjWUJmZ52YwGSkgSeyMR1PbqbwoYxpJcLxJRGPyyuf1Oi6FD/RVkJNAjzr5 YwK8CRW5iZNnFx36QYy5RmH4El6JFPxZ/tIXllq+Vl1xjgyxRs/U9HrcmO+0vYmjIOjR uaihcKW1on+VqrZBENxS48NlY7v5nNGWPEcqrxKp3IUJpkDJI/R7n659fKAPghPfNIMC OkCpKwKS4VftjNhv3QuZ2X9gcQoxnomg2q5tu02wftr6xMCGu1IZiycBr3/crC5cLU/f sH7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786252419; x=1786857219; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3uV1jDlXdjYzrBZ5UiAE52SxJwX6HGbMM4vfraaFeu8=; b=MmCdSFIpQ+cyHbZ9s5Jp2yZAhK9kwzcRVgSdCWkB5gtTjspsf5gtwmySawOI39QBg7 +W9cjTdpF6aqy8Qd7FHrPyGB/9pS2/rjZWPu3GlrXGvCks7c0Mzn1GGGVqh89H0TNN6w vhjS+Vy1FUCncJsaa1cTUwpiiMpMkMdbzJqSMnf4mxB/zUBDDyS8X34+TRCeCzirsZuH itxYcLNupYtcZ+Wd5KtQOE9YUrbcD8MYnh3DMil4hppf4WtBlQBlGghrxISO4E+v/mhj bFxXaqVi9xhXpjAZcbGiLml/dF4KaLaRPU7xJo6QK9Mkx+BBjpWC8dqaNW/WwcD8oRR8 XlUw== X-Forwarded-Encrypted: i=1; AHgh+Rq8SUi3efhcdclCDV7SusSB1vzhtdli0XH8oz8B8h6ZdNouPCw3vQ3AiRDjUGvRVAtaftCFmCPb/5V633o=@vger.kernel.org X-Gm-Message-State: AOJu0YzXIQniHw1qkSQKhe+qS1soMh401N24ixSK5/DP18yPYbKVkrYk uhCI10Ea72hHobe7+WqyjVnxmKxb+npXg/UVETBOxgKeZg4YodNqXYEV X-Gm-Gg: AR+sD10XzBM1f+vzIwLyvsFhdjGqSRynltxvF+fmyFX+PTQT6RO7+gIr9LuUopFxg1X clXumfFr10QmL7qWbXVEY1IDFdW0zL8nbnXmgWW0cDvXdFRXckrw5sUEIlGeaEwyhQ/IHbnhclF 6tkt99ljmAC/V7H+xicyJu8v69Ap/022Hj17bCDmvajOoGP0SranQT4cbUs7kd4F74bV6ggscJ0 VrIk+CIqyqMP1CKb3oTWVAcIjCLbq4s9srD1W/OusdR2gHhPoXuA7A18HMosCX2GxGww3Hkke9h TO3jcaTOlSpcDSnlUcyX59baSpKz+sbGcWJwQOt1rMAl0Toosym/JPJd0Dadk8TjnnpaNUFbV0L pkIenDJcvgnvbbOJHVCG+/eq57iBcC9YwBtr7oVEFa21maV7J6ME5T1S8xi6NOneU3xFYteYUK3 wMxtHk3KkfLlPHqRqAya17wbuzrvwU0y9QvRrmR0i/xQP+fOOPbrinfSo2a+sWi1m/wlM19Lvl9 X2OCpUIroii X-Received: by 2002:a17:902:f612:b0:2d2:a982:a388 with SMTP id d9443c01a7336-2d2b2eb169fmr124489795ad.15.1786252418944; Sat, 08 Aug 2026 22:13:38 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.108]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8a7395sm27095702eec.9.2026.08.08.22.13.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 22:13:38 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v3 5/6] drm/amdgpu/aca: Fix off-by-one buffer size parameter in add_aca_sysfs Date: Sun, 9 Aug 2026 05:11:59 +0000 Message-ID: <20260809051200.3276-6-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809051200.3276-1-sreekuttan2156239@gmail.com> References: <20260809051200.3276-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" snprintf() guarantees NUL-termination within the size limit specified by its second argument. Passing 'sizeof(handle->attr_name) - 1' unnecessarily reduces the usable buffer capacity by one byte, causing sysfs attribute names to be truncated early. Pass 'sizeof(handle->attr_name)' directly to snprintf() in add_aca_sysfs() to allow full use of the allocated buffer space. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_aca.c index 79326389d75c..4305092f134b 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c @@ -682,7 +682,7 @@ static int add_aca_sysfs(struct amdgpu_device *adev, st= ruct aca_handle *handle) { struct device_attribute *aca_attr =3D &handle->aca_attr; =20 - snprintf(handle->attr_name, sizeof(handle->attr_name) - 1, "aca_%s", hand= le->name); + snprintf(handle->attr_name, sizeof(handle->attr_name), "aca_%s", handle->= name); aca_attr->show =3D aca_sysfs_read; aca_attr->attr.name =3D handle->attr_name; aca_attr->attr.mode =3D S_IRUGO; --=20 2.54.0 From nobody Wed Sep 30 12:08:51 2026 Received: from mail-pl1-f182.google.com (mail-pl1-f182.google.com [209.85.214.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A052837A833 for ; Sun, 9 Aug 2026 05:13:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252427; cv=none; b=IT421O6XvRzIkd758lY2lJYerBMGsP9NeLgwefMezivs78H+I9RJeUGop7Xo64o4M53dpKAis62d0tyJb/YNLVKxBvuDiEcqeDeQPXbUKwAVujKj9i4MJevtXnmHI5Zy8vvB6u2l6cLv/exAWXtUgfMUucoGpq67HEpe6pk04V0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786252427; c=relaxed/simple; bh=6dvuqsiO+YdPjPwRh19aCBcWaR+23zUclPcA+B2P6Dg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mCVcIc3Ulcg8fHyPSNGQWbgt3fDmSz8qE290UGRafP3zcytRPPEUy84OFu7vnMTG8XWYrFOwAPreuZ6+LPPBCM/6q4nMfZs3A2PyrE4VgY0Wh63Sw6sKTdIAiIhmsMlurZEayy/Q/iytnXyZsDWFf+xoSRkfblAu1XnE0igZPdQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=dBDLj/bL; arc=none smtp.client-ip=209.85.214.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dBDLj/bL" Received: by mail-pl1-f182.google.com with SMTP id d9443c01a7336-2cf52d15d88so5967855ad.2 for ; Sat, 08 Aug 2026 22:13:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786252425; x=1786857225; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Jxy36nydTdeDBb8ceeDdse8qoQ8B4JIq+QDkrcZSSIw=; b=dBDLj/bLXv+2dsIvrDLTpf17GSosidU0YlW2IZo8ww03ino1uSCNqfZUymy67F1lfy AGF8oUtuepmu75bEFNVzvW7b805IpL2rYt/KTm2b25T8ff1Tn+k/QzJZjiBRg6DX2Xq3 lf9HiP50ql1fWSOTWqqoqmKNghZU6Xtxl1nmJujUQXSAzpue7zUIuh178iq34PskBk8L L3D1j0jGhFbe4627Pu/30rlgLpiVOZuydl+pcD+X35CufNFbxhjKoABogLcPpdPGZkdI v88xXUrPy8NYDml2yQ1o/z98wHVpbK1srp7shC0b3ghAzprIBr9VXphhGz+Ayfb35vt8 xFgA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786252425; x=1786857225; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Jxy36nydTdeDBb8ceeDdse8qoQ8B4JIq+QDkrcZSSIw=; b=Od3Ngs+cauVztnXcxymZLdnPYozo8F7/1reyK1Al9TUnzWvGieWg9bxgkyUfW4Em9W aqKTm75wp4NbROSrGEnTdS1rXta+OQ5zwEBDZOvnhzw10obdFawMJCMhBvwtvlmhSN6t WiveSrBBgVtH7ERmyQW53oq/rVWgqKgfJ0VyQuQc/HGTNEo1I/h3sBy9koHtqgCK5I3X qi8HoEU+OyMinSYjxEV+W2+T3BVNBCl5k9qWPxoqOTtxGMmfVC1wnI4+gilPhp5x8QrB lL3qRTFnwoAK5a1EzxU16fzrYejgl5WEb7N9rqZNcARM61nAHpVT4mkbebOgMa1+W4GE 9qNg== X-Forwarded-Encrypted: i=1; AHgh+RrhtXE++iO6iG6ZKePvj4buB+u1bQ9Tizj5lMJFdonZIzmarbWbTGzxUBSqdm0uqOlyy/wPinIvMZPdMgE=@vger.kernel.org X-Gm-Message-State: AOJu0Yz+knIb85VTvslklEzI9TgcAeM5bI3GcFJpoGRvEIV/ke7ggG7q Vn9MK4rnmQk2aUbK9Vt2zfUfJ9mDFnf0HSj/H294jbSrvsyhens/OWMy X-Gm-Gg: AR+sD11EzMj/JbWjWLwRFQDl7MoSqK0JPk8huUQE9qG9+93of1yhs/MAxUNQyVXRwIt cYv6HRNSsZmRtdXwVZdFqLrFbkS3/CUuMTk+Me9tt4j2062faWCUxHCTL7LC8EgYUV8+vMY4k/F FZ9c5yQVzxVhYx43nBS1T/TZgpbdYBZwbPlzAMQFK3AhuDUtrAK8vjSkzLy818tV8oyUsqRoXZB EjQdoYOKq9706zRXGP2dlsv7sBu7hS8/MffkVKSKiQ3j1Qe5XKVvXkjxeD9AO9oRPfmFU6uiTLj 59DPfUNCag9/TArb0ORLJstojJt5QMDbrqv5QOs910msgq7qydwWORxJmeDrAud4vTmG+Fnr89W Nj/HQmQH1jzdwKsKKaUuhEZxPQqclKtIgjasKeoZwnK6gnYvSh4jR5GQGAZ5EDrEtWuuGo6+OaO 5/y4KFmyqOOPpxrERxWG9fsEdU4vm3t0HBwotzn4IYxW4CuKvowYioaD/rAuUf/gOIdz/DAKTfc MnbsRKas6r9 X-Received: by 2002:a05:6a21:69a:b0:3c8:e313:8d42 with SMTP id adf61e73a8af0-3cbce96f6dcmr12821608637.31.1786252424949; Sat, 08 Aug 2026 22:13:44 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.108]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8a7395sm27095702eec.9.2026.08.08.22.13.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 22:13:44 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v3 6/6] drm/amdgpu/ras: Cancel delayed work before ACA teardown in amdgpu_ras_fini Date: Sun, 9 Aug 2026 05:12:00 +0000 Message-ID: <20260809051200.3276-7-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809051200.3276-1-sreekuttan2156239@gmail.com> References: <20260809051200.3276-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In amdgpu_ras_fini(), cancel_delayed_work_sync() is currently called after ACA subsystems and locks are destroyed. If the delayed work (ras_counte_delay_work) runs concurrently during teardown, it can evaluate aca_handle_is_valid() right before remove_aca_handle() frees the handle and destroys its mutex, resulting in a use-after-free and locking violation. Move cancel_delayed_work_sync() to the beginning of amdgpu_ras_fini() to ensure all pending work is flushed and stopped before resource deallocation starts. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_ras.c index 764cd4950408..118716ad0437 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c @@ -4751,6 +4751,7 @@ int amdgpu_ras_fini(struct amdgpu_device *adev) if (!adev->ras_enabled || !con) return 0; =20 + cancel_delayed_work_sync(&con->ras_counte_delay_work); amdgpu_ras_critical_region_fini(adev); mutex_destroy(&con->critical_region_lock); =20 @@ -4785,8 +4786,6 @@ int amdgpu_ras_fini(struct amdgpu_device *adev) if (AMDGPU_RAS_GET_FEATURES(con->features)) amdgpu_ras_disable_all_features(adev, 0); =20 - cancel_delayed_work_sync(&con->ras_counte_delay_work); - amdgpu_ras_set_context(adev, NULL); kfree(con); =20 --=20 2.54.0