The uapi says a VM_BIND context must not pass a submit_bo table to
MSM_GEM_SUBMIT and that one will be rejected, but nothing checks
nr_bos. A VM_BIND context which passes one anyway runs the legacy BO
handling against its userspace managed VM:

 - submit_lock_objects_vmbind() only locks the objects mapped in the
   VM, yet submit_pin_objects() calls msm_gem_get_vma_locked() on every
   submit BO. For a BO not mapped in the VM that walks and modifies the
   object's gpuva list without its resv held, and has the kernel
   allocate a VMA spanning [0, U64_MAX) in a VM whose address space
   belongs to userspace.

 - Every submit BO holds a vm_bo reference which msm_submit_retire()
   drops with only the object's resv held. If userspace unmaps the BO
   with VM_BIND while the submit is in flight, that is the last
   reference, and drm_gpuvm_bo_destroy() runs without the VM's resv.

Reject nr_bos != 0 on VM_BIND contexts, as documented. Mesa only passes
a submit_bo table when VM_BIND is not enabled.

Fixes: 2e6a8a1fe2b2 ("drm/msm: Add VM_BIND ioctl")
Cc: Abhinav Kumar <[email protected]>
Cc: Alice Ryhl <[email protected]>
Cc: Anna Maniscalco <[email protected]>
Cc: Antonino Maniscalco <[email protected]>
Cc: Boris Brezillon <[email protected]>
Cc: Danilo Krummrich <[email protected]>
Cc: David Airlie <[email protected]>
Cc: Dmitry Baryshkov <[email protected]>
Cc: Jessica Zhang <[email protected]>
Cc: Jonathan Corbet <[email protected]>
Cc: Liviu Dudau <[email protected]>
Cc: Lyude Paul <[email protected]>
Cc: Maarten Lankhorst <[email protected]>
Cc: Marijn Suijten <[email protected]>
Cc: Maxime Ripard <[email protected]>
Cc: Randy Dunlap <[email protected]>
Cc: Rob Clark <[email protected]>
Cc: Rodrigo Vivi <[email protected]>
Cc: Sean Paul <[email protected]>
Cc: Shuah Khan <[email protected]>
Cc: Simona Vetter <[email protected]>
Cc: Steven Price <[email protected]>
Cc: Thomas Hellström <[email protected]>
Cc: Thomas Zimmermann <[email protected]>
Cc: [email protected]
Signed-off-by: Matthew Brost <[email protected]>
Assisted-by: LLM
---
v3:
 - New patch (Sashiko)
---
 drivers/gpu/drm/msm/msm_gem_submit.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/gpu/drm/msm/msm_gem_submit.c 
b/drivers/gpu/drm/msm/msm_gem_submit.c
index 5862db05297a..1215b388cb40 100644
--- a/drivers/gpu/drm/msm/msm_gem_submit.c
+++ b/drivers/gpu/drm/msm/msm_gem_submit.c
@@ -598,6 +598,12 @@ int msm_ioctl_gem_submit(struct drm_device *dev, void 
*data,
                goto out_post_unlock;
        }
 
+       /* The resident set of a VM_BIND context comes from its VM_BIND ops */
+       if (msm_context_is_vmbind(ctx) && args->nr_bos) {
+               ret = UERR(EINVAL, dev, "submit_bo table not allowed with 
VM_BIND");
+               goto out_post_unlock;
+       }
+
        ring = gpu->rb[queue->ring_nr];
 
        if (args->flags & MSM_SUBMIT_FENCE_FD_OUT) {
-- 
2.34.1

Reply via email to