]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
authorLizhi Hou <lizhi.hou@amd.com>
Thu, 23 Jul 2026 07:42:56 +0000 (00:42 -0700)
committerLizhi Hou <lizhi.hou@amd.com>
Fri, 31 Jul 2026 18:09:19 +0000 (11:09 -0700)
commit8d51e0fd3e698919d2adeff71936377f0c0d4aa0
treec9cd44ae5479876f428237bd51e6108cce241090
parent20697ecb299cd77b4cf8b28f655e56606b0472d8
accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()

Two error paths in amdxdna_insert_pages() called vma->vm_ops->close(vma)
before returning an error code to the caller.  This is incorrect:
amdxdna_gem_obj_mmap() registers an HMM interval notifier before calling
amdxdna_insert_pages(), and on a hard error it jumps to hmm_unreg to undo
that registration.  Calling vm_ops->close() manually — which drops the
shmem pages_pin_count and the GEM object reference that backs the VMA —
before the mmap syscall has even returned causes those resources to be
released while the VMA is still alive.  The kernel VMA teardown will call
vm_ops->close() a second time when the process later unmaps the range,
producing a reference count underflow.

Replace both hard-error returns with a deferred-fault approach that keeps
the VMA alive and retries page insertion through the HMM range-fault path.

Fixes: e486147c912f ("accel/amdxdna: Add BO import and export")
Reviewed-by: Max Zhen <max.zhen@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260723074256.2435143-1-lizhi.hou@amd.com
drivers/accel/amdxdna/amdxdna_gem.c