mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
drm/amdkfd: fix UAF race in destroy_queue_cpsch
wait_on_destroy_queue() drops locks to wait for queue resume, allowing
a concurrent destroy to free the queue. Use is_being_destroyed flag to
serialize destruction.
Reviewed-by: Amir Shetaia <Amir.Shetaia@amd.com>
Signed-off-by: Alysa Liu <Alysa.Liu@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit ac081deaf1)
This commit is contained in:
parent
ff287df16a
commit
181eda5549
|
|
@ -2502,6 +2502,9 @@ static int wait_on_destroy_queue(struct device_queue_manager *dqm,
|
|||
if (pdd->qpd.is_debug)
|
||||
return ret;
|
||||
|
||||
if (q->properties.is_being_destroyed)
|
||||
return -EBUSY;
|
||||
|
||||
q->properties.is_being_destroyed = true;
|
||||
|
||||
if (pdd->process->debug_trap_enabled && q->properties.is_suspended) {
|
||||
|
|
@ -2514,6 +2517,9 @@ static int wait_on_destroy_queue(struct device_queue_manager *dqm,
|
|||
dqm_lock(dqm);
|
||||
}
|
||||
|
||||
if (ret)
|
||||
q->properties.is_being_destroyed = false;
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
|
@ -2607,7 +2613,7 @@ static int destroy_queue_cpsch(struct device_queue_manager *dqm,
|
|||
return retval;
|
||||
|
||||
failed_try_destroy_debugged_queue:
|
||||
|
||||
q->properties.is_being_destroyed = false;
|
||||
dqm_unlock(dqm);
|
||||
return retval;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user