mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
When prefetch region is DRM_XE_CONSULT_MEM_ADVISE_PREF_LOC for a BO VMA,
the code used it as an index into region_to_mem_type[], causing an
out-of-bounds access since the value is -1.
Resolve the preferred location for BO VMAs directly: local VRAM on dGFX
(using the BO's tile placement) or system memory on iGPU.
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
v2:
-Fix null dereference
Reported-by: Martin Hodo <martin.hodo@intel.com>
Fixes: c1bb69a2e8 ("drm/xe/svm: Consult madvise preferred location in prefetch")
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: stable@vger.kernel.org
Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20260624174943.2808767-2-himal.prasad.ghimiray@intel.com
Signed-off-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
(cherry picked from commit d9a4906ac03be9f6ed3f3b45c56c866b867fd75b)
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
This commit is contained in:
parent
a13c140cc2
commit
7bc597ce74
|
|
@ -3255,11 +3255,26 @@ static int op_lock_and_prep(struct drm_exec *exec, struct xe_vm *vm,
|
|||
.request_decompress = false,
|
||||
.check_purged = true,
|
||||
});
|
||||
if (!err && !xe_vma_has_no_bo(vma))
|
||||
err = xe_bo_migrate(xe_vma_bo(vma),
|
||||
region_to_mem_type[region],
|
||||
NULL,
|
||||
exec);
|
||||
if (!err && !xe_vma_has_no_bo(vma)) {
|
||||
struct xe_bo *bo = xe_vma_bo(vma);
|
||||
u32 mem_type;
|
||||
|
||||
if (region == DRM_XE_CONSULT_MEM_ADVISE_PREF_LOC) {
|
||||
unsigned int i;
|
||||
|
||||
mem_type = XE_PL_TT;
|
||||
for (i = 0; i < bo->placement.num_placement; i++) {
|
||||
if (mem_type_is_vram(bo->placements[i].mem_type)) {
|
||||
mem_type = bo->placements[i].mem_type;
|
||||
break;
|
||||
}
|
||||
}
|
||||
} else {
|
||||
mem_type = region_to_mem_type[region];
|
||||
}
|
||||
|
||||
err = xe_bo_migrate(bo, mem_type, NULL, exec);
|
||||
}
|
||||
break;
|
||||
}
|
||||
default:
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user