Re: [PATCH v3 0/9] Don't whitelist OA registers unconditionally
Rodrigo Vivi <[email protected]>
| Newsgroups | org.freedesktop.lists.intel-xe |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Aug 10, 2026 at 04:45:07PM -0700, Dixit, Ashutosh wrote: > On Mon, 22 Jun 2026 19:10:14 -0700, Dixit, Ashutosh wrote: > > > > On Mon, 22 Jun 2026 17:48:12 -0700, Dixit, Ashutosh wrote: > > > > > > On Mon, 15 Jun 2026 15:42:18 -0700, Ashutosh Dixit wrote: > > > > > > > > Whitelisting OA registers unconditionally is a security violation. In this > > > > series we resolve this issue as follows: > > > > > > > > * Set the 'deny' bit (bit 30) for all OA registers, ensuring OA registers > > > > are not whitelisted by default after probe/reset/restart > > > > * Reset the 'deny' bit when an OA stream is opened and certain conditions > > > > are met, whitelisting OA registers only for the duration when OA streams > > > > are open for a gt > > > > * Set the 'deny' bit again, when OA streams are closed > > > > * To manage this scheme, separate out OA whitelists from non-OA whitelists > > > > (into separate save-restore lists) > > > > > > > > v2: Address code review from Umesh. Patches changed in v2 have changelog > > > > appended to commit message > > > > v3: Minor change to Patch 3 > > > > > > > > Ashutosh Dixit (9): > > > > drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists > > > > drm/xe/rtp: Maintain OA whitelists separately > > > > drm/xe/rtp: Keep track of non-OA nonpriv slots > > > > drm/xe/rtp: Generalize whitelist_apply_to_hwe > > > > drm/xe/rtp: Save OA nonpriv registers to register save/restore lists > > > > drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs > > > > drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt > > > > drm/xe/oa: (De-)whitelist OA registers on OA stream open/release > > > > drm/xe/rtp: Ensure locking/ref counting for OA whitelists > > > > > > I have added the following to all the patches here and merge this series: > > > > > > Cc: [email protected] # v6.12+ > > > Signed-off-by: Ashutosh Dixit <[email protected]> > > > > Sorry I meant: > > > > Fixes: 828a8eaf37c3 ("drm/xe/oa: Add MMIO trigger support") > > Cc: [email protected] # v6.12+ > > > > > > > > So the plan is to propagate this series to the previous LTS kernel versions > > > too, in order to plug this security violation related to unconditional OA > > > register whitelisting. > > > > > > I am preparing v6.12 and v6.18 stable kernel version series, based on this > > > series. Since these are a bit old, this series needs porting to these old > > > kernel versions. These will be sent after this series reaches Linus' > > > master. > > > > This is needed for patches to be added to stable versions. > > The series has now been applied to all existing stable branches. Awesome! Thank you so much for all the great work and the follow-up. > The > version appied to the branches can be seen at the links below: > > Remote: > https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git > > Branches: > > stable/linux-6.12.y: > https://lore.kernel.org/stable/[email protected]/ > > stable/linux-6.18.y: > https://lore.kernel.org/stable/[email protected]/ > > stable/linux-7.1.y: > https://lore.kernel.org/stable/[email protected]/ > > Thanks. > -- > Ashutosh