From patchwork Fri Sep 5 16:53:23 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michel Thierry X-Patchwork-Id: 4853191 Return-Path: X-Original-To: patchwork-intel-gfx@patchwork.kernel.org Delivered-To: patchwork-parsemail@patchwork2.web.kernel.org Received: from mail.kernel.org (mail.kernel.org [198.145.19.201]) by patchwork2.web.kernel.org (Postfix) with ESMTP id 753B4C0338 for ; Fri, 5 Sep 2014 16:53:35 +0000 (UTC) Received: from mail.kernel.org (localhost [127.0.0.1]) by mail.kernel.org (Postfix) with ESMTP id 9B4E5201FA for ; Fri, 5 Sep 2014 16:53:34 +0000 (UTC) Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) by mail.kernel.org (Postfix) with ESMTP id D1E99201F7 for ; Fri, 5 Sep 2014 16:53:32 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 08EF96E3F2; Fri, 5 Sep 2014 09:53:32 -0700 (PDT) X-Original-To: intel-gfx@lists.freedesktop.org Delivered-To: intel-gfx@lists.freedesktop.org Received: from mga11.intel.com (mga11.intel.com [192.55.52.93]) by gabe.freedesktop.org (Postfix) with ESMTP id 8E2E26E3F2 for ; Fri, 5 Sep 2014 09:53:30 -0700 (PDT) Received: from fmsmga003.fm.intel.com ([10.253.24.29]) by fmsmga102.fm.intel.com with ESMTP; 05 Sep 2014 09:53:24 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="4.97,862,1389772800"; d="scan'208";a="382002370" Received: from michelth-linux.isw.intel.com ([10.102.226.151]) by FMSMGA003.fm.intel.com with ESMTP; 05 Sep 2014 09:48:37 -0700 From: Michel Thierry To: intel-gfx@lists.freedesktop.org Date: Fri, 5 Sep 2014 17:53:23 +0100 Message-Id: <1409936003-9341-1-git-send-email-michel.thierry@intel.com> X-Mailer: git-send-email 2.0.3 Cc: Daniel Vetter Subject: [Intel-gfx] [PATCH] drm/i915: fix use-after-free in i915_drop_caches_set X-BeenThere: intel-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: Intel graphics driver community testing & development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: intel-gfx-bounces@lists.freedesktop.org Sender: "Intel-gfx" X-Spam-Status: No, score=-5.9 required=5.0 tests=BAYES_00, RCVD_IN_DNSWL_MED, RP_MATCHES_RCVD, UNPARSEABLE_RELAY autolearn=unavailable version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mail.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP With the new vma/ppgtt lifetime rules, the ppgtt (vm) could be removed after i915_vma_unbind. Use list_for_each_entry_safe() to prevent this use-after-free. Found with gem_persistent_relocs and gem_evict_everything igt tests. Cc: Daniel Vetter Signed-off-by: Michel Thierry --- drivers/gpu/drm/i915/i915_debugfs.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/drivers/gpu/drm/i915/i915_debugfs.c b/drivers/gpu/drm/i915/i915_debugfs.c index dd736c0..4b05cd8 100644 --- a/drivers/gpu/drm/i915/i915_debugfs.c +++ b/drivers/gpu/drm/i915/i915_debugfs.c @@ -3820,8 +3820,8 @@ i915_drop_caches_set(void *data, u64 val) struct drm_device *dev = data; struct drm_i915_private *dev_priv = dev->dev_private; struct drm_i915_gem_object *obj, *next; - struct i915_address_space *vm; - struct i915_vma *vma, *x; + struct i915_address_space *vm, *x; + struct i915_vma *vma, *y; int ret; DRM_DEBUG("Dropping caches: 0x%08llx\n", val); @@ -3842,8 +3842,9 @@ i915_drop_caches_set(void *data, u64 val) i915_gem_retire_requests(dev); if (val & DROP_BOUND) { - list_for_each_entry(vm, &dev_priv->vm_list, global_link) { - list_for_each_entry_safe(vma, x, &vm->inactive_list, + list_for_each_entry_safe(vm, x, &dev_priv->vm_list, + global_link) { + list_for_each_entry_safe(vma, y, &vm->inactive_list, mm_list) { if (vma->pin_count) continue;