mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-23 07:15:57 -04:00
drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so the function returns early instead of proceeding with an invalid pointer. XE_WARN_ON is kept to help root cause the issue, but we now bail instead of crashing the driver. v2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost) Fixes:dd08ebf6c3("drm/xe: Introduce a new DRM driver for Intel GPUs") Cc: Matthew Brost <matthew.brost@intel.com> Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com> Reviewed-by: Matthew Brost <matthew.brost@intel.com> Link: https://lore.kernel.org/r/20260616081756.286918-1-francois.dugast@intel.com Signed-off-by: Francois Dugast <francois.dugast@intel.com> (cherry picked from commitb9297d19d9) Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
This commit is contained in:
committed by
Thomas Hellström
parent
d42df9dce7
commit
3feeb66719
@@ -885,12 +885,20 @@ static int xe_pt_zap_ptes_entry(struct xe_ptw *parent, pgoff_t offset,
|
||||
{
|
||||
struct xe_pt_zap_ptes_walk *xe_walk =
|
||||
container_of(walk, typeof(*xe_walk), base);
|
||||
struct xe_pt *xe_child = container_of(*child, typeof(*xe_child), base);
|
||||
struct xe_pt *xe_child;
|
||||
pgoff_t end_offset;
|
||||
|
||||
XE_WARN_ON(!*child);
|
||||
XE_WARN_ON(!level);
|
||||
|
||||
/*
|
||||
* Below would be unexpected behavior that needs to be root caused
|
||||
* but better warn and bail than crash the driver.
|
||||
*/
|
||||
if (XE_WARN_ON(!*child))
|
||||
return 0;
|
||||
|
||||
xe_child = container_of(*child, typeof(*xe_child), base);
|
||||
|
||||
/*
|
||||
* Note that we're called from an entry callback, and we're dealing
|
||||
* with the child of that entry rather than the parent, so need to
|
||||
|
||||
Reference in New Issue
Block a user