The uapi says a VM_BIND context must not pass a submit_bo table to
MSM_GEM_SUBMIT and that one will be rejected, but nothing checks
nr_bos. A VM_BIND context which passes one anyway runs the legacy BO
handling against its userspace managed VM:
- submit_lock_objects_vmbind() only locks the objects mapped in the
VM, yet submit_pin_objects() calls msm_gem_get_vma_locked() on every
submit BO. For a BO not mapped in the VM that walks and modifies the
object's gpuva list without its resv held, and has the kernel
allocate a VMA spanning [0, U64_MAX) in a VM whose address space
belongs to userspace.
- Every submit BO holds a vm_bo reference which msm_submit_retire()
drops with only the object's resv held. If userspace unmaps the BO
with VM_BIND while the submit is in flight, that is the last
reference, and drm_gpuvm_bo_destroy() runs without the VM's resv.
Reject nr_bos != 0 on VM_BIND contexts, as documented. Mesa only passes
a submit_bo table when VM_BIND is not enabled.
Fixes: 2e6a8a1fe2b2 ("drm/msm: Add VM_BIND ioctl")
Cc: Abhinav Kumar <[email protected]>
Cc: Alice Ryhl <[email protected]>
Cc: Anna Maniscalco <[email protected]>
Cc: Antonino Maniscalco <[email protected]>
Cc: Boris Brezillon <[email protected]>
Cc: Danilo Krummrich <[email protected]>
Cc: David Airlie <[email protected]>
Cc: Dmitry Baryshkov <[email protected]>
Cc: Jessica Zhang <[email protected]>
Cc: Jonathan Corbet <[email protected]>
Cc: Liviu Dudau <[email protected]>
Cc: Lyude Paul <[email protected]>
Cc: Maarten Lankhorst <[email protected]>
Cc: Marijn Suijten <[email protected]>
Cc: Maxime Ripard <[email protected]>
Cc: Randy Dunlap <[email protected]>
Cc: Rob Clark <[email protected]>
Cc: Rodrigo Vivi <[email protected]>
Cc: Sean Paul <[email protected]>
Cc: Shuah Khan <[email protected]>
Cc: Simona Vetter <[email protected]>
Cc: Steven Price <[email protected]>
Cc: Thomas Hellström <[email protected]>
Cc: Thomas Zimmermann <[email protected]>
Cc: [email protected]
Signed-off-by: Matthew Brost <[email protected]>
Assisted-by: LLM
---
v3:
- New patch (Sashiko)
---
drivers/gpu/drm/msm/msm_gem_submit.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/gpu/drm/msm/msm_gem_submit.c
b/drivers/gpu/drm/msm/msm_gem_submit.c
index 5862db05297a..1215b388cb40 100644
--- a/drivers/gpu/drm/msm/msm_gem_submit.c
+++ b/drivers/gpu/drm/msm/msm_gem_submit.c
@@ -598,6 +598,12 @@ int msm_ioctl_gem_submit(struct drm_device *dev, void
*data,
goto out_post_unlock;
}
+ /* The resident set of a VM_BIND context comes from its VM_BIND ops */
+ if (msm_context_is_vmbind(ctx) && args->nr_bos) {
+ ret = UERR(EINVAL, dev, "submit_bo table not allowed with
VM_BIND");
+ goto out_post_unlock;
+ }
+
ring = gpu->rb[queue->ring_nr];
if (args->flags & MSM_SUBMIT_FENCE_FD_OUT) {
--
2.34.1