drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC

When prefetch region is DRM_XE_CONSULT_MEM_ADVISE_PREF_LOC for a BO VMA,
the code used it as an index into region_to_mem_type[], causing an
out-of-bounds access since the value is -1.

Resolve the preferred location for BO VMAs directly: local VRAM on dGFX
(using the BO's tile placement) or system memory on iGPU.

Discovered using AI-assisted static analysis confirmed by Intel Product
Security.

v2:
-Fix null dereference

Reported-by: Martin Hodo <martin.hodo@intel.com>
Fixes: c1bb69a2e8 ("drm/xe/svm: Consult madvise preferred location in prefetch")
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: stable@vger.kernel.org
Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20260624174943.2808767-2-himal.prasad.ghimiray@intel.com
Signed-off-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
(cherry picked from commit d9a4906ac03be9f6ed3f3b45c56c866b867fd75b)
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
This commit is contained in:
Himal Prasad Ghimiray 2026-06-24 23:19:44 +05:30 committed by Thomas Hellström
parent a13c140cc2
commit 7bc597ce74

View File

@ -3255,11 +3255,26 @@ static int op_lock_and_prep(struct drm_exec *exec, struct xe_vm *vm,
.request_decompress = false,
.check_purged = true,
});
if (!err && !xe_vma_has_no_bo(vma))
err = xe_bo_migrate(xe_vma_bo(vma),
region_to_mem_type[region],
NULL,
exec);
if (!err && !xe_vma_has_no_bo(vma)) {
struct xe_bo *bo = xe_vma_bo(vma);
u32 mem_type;
if (region == DRM_XE_CONSULT_MEM_ADVISE_PREF_LOC) {
unsigned int i;
mem_type = XE_PL_TT;
for (i = 0; i < bo->placement.num_placement; i++) {
if (mem_type_is_vram(bo->placements[i].mem_type)) {
mem_type = bo->placements[i].mem_type;
break;
}
}
} else {
mem_type = region_to_mem_type[region];
}
err = xe_bo_migrate(bo, mem_type, NULL, exec);
}
break;
}
default: