accel/ivpu: Use dma_resv_lock() instead of a custom mutex

commit 98d3f772ca7d6822bdfc8c960f5f909574db97c9 upstream.

This fixes a potential race conditions in:
 - ivpu_bo_unbind_locked() where we modified the shmem->sgt without
   holding the dma_resv_lock().
 - ivpu_bo_print_info() where we read the shmem->pages without
   holding the dma_resv_lock().

Using dma_resv_lock() also protects against future syncronisation
issues that may arise when accessing drm_gem_shmem_object or
drm_gem_object members.

Fixes: 42328003ec ("accel/ivpu: Refactor BO creation functions")
Cc: stable@vger.kernel.org # v6.9+
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
Signed-off-by: Jacek Lawrynowicz <jacek.lawrynowicz@linux.intel.com>
Link: https://lore.kernel.org/r/20250528154325.500684-1-jacek.lawrynowicz@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Jacek Lawrynowicz
2025-05-28 17:43:25 +02:00
committed by Greg Kroah-Hartman
parent 954b190106
commit d2551a6178
2 changed files with 35 additions and 31 deletions
+35 -30
View File
@@ -31,6 +31,16 @@ static inline void ivpu_dbg_bo(struct ivpu_device *vdev, struct ivpu_bo *bo, con
(bool)bo->base.base.import_attach); (bool)bo->base.base.import_attach);
} }
static inline int ivpu_bo_lock(struct ivpu_bo *bo)
{
return dma_resv_lock(bo->base.base.resv, NULL);
}
static inline void ivpu_bo_unlock(struct ivpu_bo *bo)
{
dma_resv_unlock(bo->base.base.resv);
}
/* /*
* ivpu_bo_pin() - pin the backing physical pages and map them to VPU. * ivpu_bo_pin() - pin the backing physical pages and map them to VPU.
* *
@@ -41,22 +51,22 @@ static inline void ivpu_dbg_bo(struct ivpu_device *vdev, struct ivpu_bo *bo, con
int __must_check ivpu_bo_pin(struct ivpu_bo *bo) int __must_check ivpu_bo_pin(struct ivpu_bo *bo)
{ {
struct ivpu_device *vdev = ivpu_bo_to_vdev(bo); struct ivpu_device *vdev = ivpu_bo_to_vdev(bo);
struct sg_table *sgt;
int ret = 0; int ret = 0;
mutex_lock(&bo->lock);
ivpu_dbg_bo(vdev, bo, "pin"); ivpu_dbg_bo(vdev, bo, "pin");
drm_WARN_ON(&vdev->drm, !bo->ctx);
sgt = drm_gem_shmem_get_pages_sgt(&bo->base);
if (IS_ERR(sgt)) {
ret = PTR_ERR(sgt);
ivpu_err(vdev, "Failed to map BO in IOMMU: %d\n", ret);
return ret;
}
ivpu_bo_lock(bo);
if (!bo->mmu_mapped) { if (!bo->mmu_mapped) {
struct sg_table *sgt = drm_gem_shmem_get_pages_sgt(&bo->base); drm_WARN_ON(&vdev->drm, !bo->ctx);
if (IS_ERR(sgt)) {
ret = PTR_ERR(sgt);
ivpu_err(vdev, "Failed to map BO in IOMMU: %d\n", ret);
goto unlock;
}
ret = ivpu_mmu_context_map_sgt(vdev, bo->ctx, bo->vpu_addr, sgt, ret = ivpu_mmu_context_map_sgt(vdev, bo->ctx, bo->vpu_addr, sgt,
ivpu_bo_is_snooped(bo)); ivpu_bo_is_snooped(bo));
if (ret) { if (ret) {
@@ -67,7 +77,7 @@ int __must_check ivpu_bo_pin(struct ivpu_bo *bo)
} }
unlock: unlock:
mutex_unlock(&bo->lock); ivpu_bo_unlock(bo);
return ret; return ret;
} }
@@ -82,7 +92,7 @@ ivpu_bo_alloc_vpu_addr(struct ivpu_bo *bo, struct ivpu_mmu_context *ctx,
if (!drm_dev_enter(&vdev->drm, &idx)) if (!drm_dev_enter(&vdev->drm, &idx))
return -ENODEV; return -ENODEV;
mutex_lock(&bo->lock); ivpu_bo_lock(bo);
ret = ivpu_mmu_context_insert_node(ctx, range, ivpu_bo_size(bo), &bo->mm_node); ret = ivpu_mmu_context_insert_node(ctx, range, ivpu_bo_size(bo), &bo->mm_node);
if (!ret) { if (!ret) {
@@ -92,7 +102,7 @@ ivpu_bo_alloc_vpu_addr(struct ivpu_bo *bo, struct ivpu_mmu_context *ctx,
ivpu_err(vdev, "Failed to add BO to context %u: %d\n", ctx->id, ret); ivpu_err(vdev, "Failed to add BO to context %u: %d\n", ctx->id, ret);
} }
mutex_unlock(&bo->lock); ivpu_bo_unlock(bo);
drm_dev_exit(idx); drm_dev_exit(idx);
@@ -103,7 +113,7 @@ static void ivpu_bo_unbind_locked(struct ivpu_bo *bo)
{ {
struct ivpu_device *vdev = ivpu_bo_to_vdev(bo); struct ivpu_device *vdev = ivpu_bo_to_vdev(bo);
lockdep_assert(lockdep_is_held(&bo->lock) || !kref_read(&bo->base.base.refcount)); lockdep_assert(dma_resv_held(bo->base.base.resv) || !kref_read(&bo->base.base.refcount));
if (bo->mmu_mapped) { if (bo->mmu_mapped) {
drm_WARN_ON(&vdev->drm, !bo->ctx); drm_WARN_ON(&vdev->drm, !bo->ctx);
@@ -121,14 +131,12 @@ static void ivpu_bo_unbind_locked(struct ivpu_bo *bo)
if (bo->base.base.import_attach) if (bo->base.base.import_attach)
return; return;
dma_resv_lock(bo->base.base.resv, NULL);
if (bo->base.sgt) { if (bo->base.sgt) {
dma_unmap_sgtable(vdev->drm.dev, bo->base.sgt, DMA_BIDIRECTIONAL, 0); dma_unmap_sgtable(vdev->drm.dev, bo->base.sgt, DMA_BIDIRECTIONAL, 0);
sg_free_table(bo->base.sgt); sg_free_table(bo->base.sgt);
kfree(bo->base.sgt); kfree(bo->base.sgt);
bo->base.sgt = NULL; bo->base.sgt = NULL;
} }
dma_resv_unlock(bo->base.base.resv);
} }
void ivpu_bo_unbind_all_bos_from_context(struct ivpu_device *vdev, struct ivpu_mmu_context *ctx) void ivpu_bo_unbind_all_bos_from_context(struct ivpu_device *vdev, struct ivpu_mmu_context *ctx)
@@ -140,12 +148,12 @@ void ivpu_bo_unbind_all_bos_from_context(struct ivpu_device *vdev, struct ivpu_m
mutex_lock(&vdev->bo_list_lock); mutex_lock(&vdev->bo_list_lock);
list_for_each_entry(bo, &vdev->bo_list, bo_list_node) { list_for_each_entry(bo, &vdev->bo_list, bo_list_node) {
mutex_lock(&bo->lock); ivpu_bo_lock(bo);
if (bo->ctx == ctx) { if (bo->ctx == ctx) {
ivpu_dbg_bo(vdev, bo, "unbind"); ivpu_dbg_bo(vdev, bo, "unbind");
ivpu_bo_unbind_locked(bo); ivpu_bo_unbind_locked(bo);
} }
mutex_unlock(&bo->lock); ivpu_bo_unlock(bo);
} }
mutex_unlock(&vdev->bo_list_lock); mutex_unlock(&vdev->bo_list_lock);
} }
@@ -165,7 +173,6 @@ struct drm_gem_object *ivpu_gem_create_object(struct drm_device *dev, size_t siz
bo->base.pages_mark_dirty_on_put = true; /* VPU can dirty a BO anytime */ bo->base.pages_mark_dirty_on_put = true; /* VPU can dirty a BO anytime */
INIT_LIST_HEAD(&bo->bo_list_node); INIT_LIST_HEAD(&bo->bo_list_node);
mutex_init(&bo->lock);
return &bo->base.base; return &bo->base.base;
} }
@@ -243,8 +250,6 @@ static void ivpu_gem_bo_free(struct drm_gem_object *obj)
drm_WARN_ON(&vdev->drm, bo->mmu_mapped); drm_WARN_ON(&vdev->drm, bo->mmu_mapped);
drm_WARN_ON(&vdev->drm, bo->ctx); drm_WARN_ON(&vdev->drm, bo->ctx);
mutex_destroy(&bo->lock);
drm_WARN_ON(obj->dev, bo->base.pages_use_count > 1); drm_WARN_ON(obj->dev, bo->base.pages_use_count > 1);
drm_gem_shmem_free(&bo->base); drm_gem_shmem_free(&bo->base);
} }
@@ -327,9 +332,9 @@ ivpu_bo_create(struct ivpu_device *vdev, struct ivpu_mmu_context *ctx,
goto err_put; goto err_put;
if (flags & DRM_IVPU_BO_MAPPABLE) { if (flags & DRM_IVPU_BO_MAPPABLE) {
dma_resv_lock(bo->base.base.resv, NULL); ivpu_bo_lock(bo);
ret = drm_gem_shmem_vmap(&bo->base, &map); ret = drm_gem_shmem_vmap(&bo->base, &map);
dma_resv_unlock(bo->base.base.resv); ivpu_bo_unlock(bo);
if (ret) if (ret)
goto err_put; goto err_put;
@@ -352,9 +357,9 @@ void ivpu_bo_free(struct ivpu_bo *bo)
struct iosys_map map = IOSYS_MAP_INIT_VADDR(bo->base.vaddr); struct iosys_map map = IOSYS_MAP_INIT_VADDR(bo->base.vaddr);
if (bo->flags & DRM_IVPU_BO_MAPPABLE) { if (bo->flags & DRM_IVPU_BO_MAPPABLE) {
dma_resv_lock(bo->base.base.resv, NULL); ivpu_bo_lock(bo);
drm_gem_shmem_vunmap(&bo->base, &map); drm_gem_shmem_vunmap(&bo->base, &map);
dma_resv_unlock(bo->base.base.resv); ivpu_bo_unlock(bo);
} }
drm_gem_object_put(&bo->base.base); drm_gem_object_put(&bo->base.base);
@@ -373,12 +378,12 @@ int ivpu_bo_info_ioctl(struct drm_device *dev, void *data, struct drm_file *file
bo = to_ivpu_bo(obj); bo = to_ivpu_bo(obj);
mutex_lock(&bo->lock); ivpu_bo_lock(bo);
args->flags = bo->flags; args->flags = bo->flags;
args->mmap_offset = drm_vma_node_offset_addr(&obj->vma_node); args->mmap_offset = drm_vma_node_offset_addr(&obj->vma_node);
args->vpu_addr = bo->vpu_addr; args->vpu_addr = bo->vpu_addr;
args->size = obj->size; args->size = obj->size;
mutex_unlock(&bo->lock); ivpu_bo_unlock(bo);
drm_gem_object_put(obj); drm_gem_object_put(obj);
return ret; return ret;
@@ -412,7 +417,7 @@ int ivpu_bo_wait_ioctl(struct drm_device *dev, void *data, struct drm_file *file
static void ivpu_bo_print_info(struct ivpu_bo *bo, struct drm_printer *p) static void ivpu_bo_print_info(struct ivpu_bo *bo, struct drm_printer *p)
{ {
mutex_lock(&bo->lock); ivpu_bo_lock(bo);
drm_printf(p, "%-9p %-3u 0x%-12llx %-10lu 0x%-8x %-4u", drm_printf(p, "%-9p %-3u 0x%-12llx %-10lu 0x%-8x %-4u",
bo, bo->ctx_id, bo->vpu_addr, bo->base.base.size, bo, bo->ctx_id, bo->vpu_addr, bo->base.base.size,
@@ -429,7 +434,7 @@ static void ivpu_bo_print_info(struct ivpu_bo *bo, struct drm_printer *p)
drm_printf(p, "\n"); drm_printf(p, "\n");
mutex_unlock(&bo->lock); ivpu_bo_unlock(bo);
} }
void ivpu_bo_list(struct drm_device *dev, struct drm_printer *p) void ivpu_bo_list(struct drm_device *dev, struct drm_printer *p)
-1
View File
@@ -17,7 +17,6 @@ struct ivpu_bo {
struct list_head bo_list_node; struct list_head bo_list_node;
struct drm_mm_node mm_node; struct drm_mm_node mm_node;
struct mutex lock; /* Protects: ctx, mmu_mapped, vpu_addr */
u64 vpu_addr; u64 vpu_addr;
u32 flags; u32 flags;
u32 job_status; /* Valid only for command buffer */ u32 job_status; /* Valid only for command buffer */