Re: [PATCH] accel/amdxdna: return early from a zero-length flush

Lizhi Hou <[email protected]>
Newsgroups gmane.linux.kernel,gmane.comp.video.dri.devel
Message-ID <[email protected]>
On 8/17/26 16:06, Taimuraz Kaitmazov wrote:
> SYNC_BO does not constrain its size, so a request for zero bytes reaches
> drm_clflush_virt_range(), which ends with an unconditional
> clflushopt(end - 1). For an empty range that is the byte before the
> mapping, and abo->mem.kva comes from vmap(), so the access lands in the
> guard page below the vmalloc area and faults:
>
>    BUG: unable to handle page fault for address: ffffd16fbbc70fff
>    #PF: supervisor read access in kernel mode
>    Oops: Oops: 0000 [#1] SMP NOPTI
>    CPU: 7 UID: 1000 Comm: sync_bo_probe
>    RIP: 0010:drm_clflush_virt_range+0x3c/0x70
>    Call Trace:
>     amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna]
>     drm_ioctl+0x301/0x4c0
>     __x64_sys_ioctl+0x115/0x2f0
>     do_syscall_64+0xa6/0x3d0
>
> Any process that can open the render node can do this. Reproduced 3 of 3
> times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on
> an AMDXDNA_BO_SHARE object. The import arm takes the same request but
> flushes the whole scatterlist, so it survives it.
>
> Nothing needs flushing for an empty range, so answer before choosing a
> path.
>
> Fixes: e252e3f3488a ("accel/amdxdna: Revise device bo creation and free")
> Cc: [email protected]
> Signed-off-by: Taimuraz Kaitmazov <[email protected]>
> ---
> Trees before amdxdna_flush_bo() existed carry the same call inline in
> amdxdna_drm_sync_bo_ioctl(), with args->size passed to
> drm_clflush_virt_range() unclamped, so a backport wants the guard at that
> call site instead.
>
>   drivers/accel/amdxdna/amdxdna_gem.c | 3 +++
>   1 file changed, 3 insertions(+)
>
> diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/amdxdna_gem.c
> index 1c63eff0a4a8..2a16de96e6a4 100644
> --- a/drivers/accel/amdxdna/amdxdna_gem.c
> +++ b/drivers/accel/amdxdna/amdxdna_gem.c
> @@ -1247,6 +1247,9 @@ static int amdxdna_flush_bo(struct amdxdna_gem_obj *abo, u64 offset, u64 size)
>   		return -EINVAL;
>   
>   	size = min(abo->mem.size, end) - offset;
> +	if (!size)
> +		return 0;
> +
Reviewed-by: Lizhi Hou <[email protected]>
>   	if (is_import_bo(abo))
>   		drm_clflush_sg(abo->base.sgt);
>   	else if (amdxdna_gem_vmap(abo))
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.