[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20190815194621.GF22970@mellanox.com>
Date: Thu, 15 Aug 2019 19:46:26 +0000
From: Jason Gunthorpe <jgg@...lanox.com>
To: "christian.koenig@....com" <christian.koenig@....com>
CC: "linux-mm@...ck.org" <linux-mm@...ck.org>,
Andrea Arcangeli <aarcange@...hat.com>,
"David (ChunMing) Zhou" <David1.Zhou@....com>,
Ralph Campbell <rcampbell@...dia.com>,
Dimitri Sivanich <sivanich@....com>,
Gavin Shan <shangw@...ux.vnet.ibm.com>,
Andrea Righi <andrea@...terlinux.com>,
"linux-rdma@...r.kernel.org" <linux-rdma@...r.kernel.org>,
John Hubbard <jhubbard@...dia.com>,
"Kuehling, Felix" <Felix.Kuehling@....com>,
"linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>,
"dri-devel@...ts.freedesktop.org" <dri-devel@...ts.freedesktop.org>,
Jérôme Glisse <jglisse@...hat.com>,
"iommu@...ts.linux-foundation.org" <iommu@...ts.linux-foundation.org>,
"amd-gfx@...ts.freedesktop.org" <amd-gfx@...ts.freedesktop.org>,
Alex Deucher <alexander.deucher@....com>,
"intel-gfx@...ts.freedesktop.org" <intel-gfx@...ts.freedesktop.org>,
Christoph Hellwig <hch@....de>
Subject: Re: [PATCH v3 hmm 08/11] drm/radeon: use mmu_notifier_get/put for
struct radeon_mn
On Thu, Aug 15, 2019 at 10:28:21AM +0200, Christian König wrote:
> Am 07.08.19 um 01:15 schrieb Jason Gunthorpe:
> > From: Jason Gunthorpe <jgg@...lanox.com>
> >
> > radeon is using a device global hash table to track what mmu_notifiers
> > have been registered on struct mm. This is better served with the new
> > get/put scheme instead.
> >
> > radeon has a bug where it was not blocking notifier release() until all
> > the BO's had been invalidated. This could result in a use after free of
> > pages the BOs. This is tied into a second bug where radeon left the
> > notifiers running endlessly even once the interval tree became
> > empty. This could result in a use after free with module unload.
> >
> > Both are fixed by changing the lifetime model, the BOs exist in the
> > interval tree with their natural lifetimes independent of the mm_struct
> > lifetime using the get/put scheme. The release runs synchronously and just
> > does invalidate_start across the entire interval tree to create the
> > required DMA fence.
> >
> > Additions to the interval tree after release are already impossible as
> > only current->mm is used during the add.
> >
> > Signed-off-by: Jason Gunthorpe <jgg@...lanox.com>
>
> Acked-by: Christian König <christian.koenig@....com>
Thanks!
> But I'm wondering if we shouldn't completely drop radeon userptr support.
> It's just to buggy,
I would not object :)
Jason
Powered by blists - more mailing lists