From: Greg Kroah-Hartman Date: Wed, 5 Aug 2026 12:13:51 +0000 (+0200) Subject: 6.6-stable patches X-Git-Tag: v5.10.263~30 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=66586a35842c6345dcff202d1ef8450c604f38d8;p=thirdparty%2Fkernel%2Fstable-queue.git 6.6-stable patches added patches: drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch --- diff --git a/queue-6.6/drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch b/queue-6.6/drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch new file mode 100644 index 0000000000..f143eb7f3b --- /dev/null +++ b/queue-6.6/drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch @@ -0,0 +1,43 @@ +From 99b2fe4f19e3be0a8d0a0b5ea98d855970889653 Mon Sep 17 00:00:00 2001 +From: Gang Ba +Date: Tue, 14 Jul 2026 15:08:57 -0400 +Subject: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE + +From: Gang Ba + +commit 99b2fe4f19e3be0a8d0a0b5ea98d855970889653 upstream. + +Prevent unauthorized termination of active GPU debug sessions. +Previously, users with /dev/kfd access could terminate another process's +debug session without proper ownership or ptrace authorization. + +Signed-off-by: Gang Ba +Reviewed-by: Kent Russell +Signed-off-by: Alex Deucher +(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 10 +++++++--- + 1 file changed, 7 insertions(+), 3 deletions(-) + +--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c ++++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c +@@ -2977,10 +2977,14 @@ static int kfd_ioctl_set_debug_trap(stru + goto out; + } + +- /* Check if target is still PTRACED. */ ++ /* ++ * Verify debugger has permission to debug target process. ++ * For cross-process debugging, require active ptrace relationship. ++ * This applies to ALL operations to prevent unauthorized interference. ++ */ + rcu_read_lock(); +- if (target != p && args->op != KFD_IOC_DBG_TRAP_DISABLE +- && ptrace_parent(target->lead_thread) != current) { ++ if (target != p && ptrace_parent(target->lead_thread) != current ++ && target->debugger_process != p) { + pr_err("PID %i is not PTRACED and cannot be debugged\n", args->pid); + r = -EPERM; + } diff --git a/queue-6.6/drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch b/queue-6.6/drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch new file mode 100644 index 0000000000..2c5a018066 --- /dev/null +++ b/queue-6.6/drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch @@ -0,0 +1,47 @@ +From 38b73293f38658a4685ffcea666462024f858ad9 Mon Sep 17 00:00:00 2001 +From: Vladimir Marioukhine +Date: Mon, 20 Jul 2026 11:53:30 -0400 +Subject: drm/amdkfd: fix QID bit leak in pqm_create_queue() + +From: Vladimir Marioukhine + +commit 38b73293f38658a4685ffcea666462024f858ad9 upstream. + +When MES is enabled and amdgpu_amdkfd_alloc_kernel_mem() fails during +the first queue creation for a process, pqm_create_queue() returns +early via 'return retval' without going through the err_create_queue +cleanup label. + +This means clear_bit(*qid, pqm->queue_slot_bitmap) is never called, +leaving the reserved QID bit permanently set in queue_slot_bitmap. +Over time this leaks QID slots, potentially exhausting all available +queue slots. + +Fix this by replacing 'return retval' with 'goto err_allocate_pqn' +so that clear_bit() is always called on the error path without +touching the uninitialized pqn pointer. + +AILIKFD-813 + +Reported-by: Deucher, Alexander +Signed-off-by: Vladimir Marioukhine +Reviewed-by: Kent Russell +Signed-off-by: Alex Deucher +(cherry picked from commit a107f74c38edbb80d6ab64dcaeeb292c14e9779f) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c ++++ b/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c +@@ -344,7 +344,7 @@ int pqm_create_queue(struct process_queu + false); + if (retval) { + dev_err(dev->adev->dev, "failed to allocate process context bo\n"); +- return retval; ++ goto err_allocate_pqn; + } + memset(pdd->proc_ctx_cpu_ptr, 0, AMDGPU_MES_PROC_CTX_SIZE); + } diff --git a/queue-6.6/drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch b/queue-6.6/drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch new file mode 100644 index 0000000000..5f4b3e859e --- /dev/null +++ b/queue-6.6/drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch @@ -0,0 +1,37 @@ +From a9cdc85839e4fe2c760aa4ca6cc341c31ad1918a Mon Sep 17 00:00:00 2001 +From: David Francis +Date: Tue, 21 Jul 2026 09:30:07 -0400 +Subject: drm/amdkfd: Handle invalid event type in CRIU event restore + +From: David Francis + +commit a9cdc85839e4fe2c760aa4ca6cc341c31ad1918a upstream. + +In kfd_criu_restore_event, there was no handling for +the event priv data having an invalid event type. The priv +data here is untrusted and can be invalid. + +In that case, fail with EINVAL. + +Signed-off-by: David Francis +Reviewed-by: Kent Russell +Signed-off-by: Alex Deucher +(cherry picked from commit 2e8e9963cd5c41aa14fd5316bf9ec92e7a0e3097) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdkfd/kfd_events.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c ++++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c +@@ -520,6 +520,9 @@ int kfd_criu_restore_event(struct file * + + ret = create_other_event(p, ev, &ev_priv->event_id); + break; ++ default: ++ ret = -EINVAL; ++ break; + } + mutex_unlock(&p->event_mutex); + diff --git a/queue-6.6/drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch b/queue-6.6/drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch new file mode 100644 index 0000000000..542d30df63 --- /dev/null +++ b/queue-6.6/drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch @@ -0,0 +1,83 @@ +From ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2 Mon Sep 17 00:00:00 2001 +From: William Palacek +Date: Wed, 22 Jul 2026 11:20:56 -0400 +Subject: drm/amdkfd: hold event_mutex while checkpointing CRIU events + +From: William Palacek + +commit ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2 upstream. + +kfd_criu_checkpoint_events() counts the entries in p->event_idr via +kfd_get_num_events(), allocates an array sized to that count, and then +walks the same IDR to fill it. Neither the count nor the walk holds +p->event_mutex. + +The CRIU checkpoint caller holds only p->mutex. Event create and destroy +(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not +take p->mutex, so a second thread in the same process can insert or remove +events between the count and the walk. If an event is inserted, the walk +iterates more entries than were counted and writes past the end of the +ev_privs allocation; if an event is removed, the walk dereferences an +entry that is being freed. + +Hold p->event_mutex across the count and the walk so both observe a +consistent view of p->event_idr. The lock is released before +copy_to_user(), which only touches the local buffer. The caller already +holds p->mutex and the create/destroy paths never take p->mutex, so the +p->mutex -> p->event_mutex order is not inverted and no deadlock is +introduced. + +Fixes: 40e8a766a761 ("drm/amdkfd: CRIU checkpoint and restore events") +Signed-off-by: William Palacek +Reviewed-by: Alysa Liu +Signed-off-by: Alex Deucher +(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdkfd/kfd_events.c | 22 ++++++++++++++++++---- + 1 file changed, 18 insertions(+), 4 deletions(-) + +--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c ++++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c +@@ -544,15 +544,27 @@ int kfd_criu_checkpoint_events(struct kf + int ret = 0; + struct kfd_event *ev; + uint32_t ev_id; ++ uint32_t num_events; + +- uint32_t num_events = kfd_get_num_events(p); +- +- if (!num_events) ++ /* Serialize the count and the walk below against concurrent event ++ * create/destroy. Those paths take only p->event_mutex, not the ++ * p->mutex held by the CRIU checkpoint caller, so without this the ++ * event_idr can grow between kfd_get_num_events() and the loop and the ++ * walk writes past the ev_privs allocation. ++ */ ++ mutex_lock(&p->event_mutex); ++ ++ num_events = kfd_get_num_events(p); ++ if (!num_events) { ++ mutex_unlock(&p->event_mutex); + return 0; ++ } + + ev_privs = kvzalloc(num_events * sizeof(*ev_privs), GFP_KERNEL); +- if (!ev_privs) ++ if (!ev_privs) { ++ mutex_unlock(&p->event_mutex); + return -ENOMEM; ++ } + + + idr_for_each_entry(&p->event_idr, ev, ev_id) { +@@ -593,6 +605,8 @@ int kfd_criu_checkpoint_events(struct kf + i++; + } + ++ mutex_unlock(&p->event_mutex); ++ + ret = copy_to_user(user_priv_data + *priv_data_offset, + ev_privs, num_events * sizeof(*ev_privs)); + if (ret) { diff --git a/queue-6.6/series b/queue-6.6/series index 4e4e0283a3..0790c38388 100644 --- a/queue-6.6/series +++ b/queue-6.6/series @@ -190,3 +190,7 @@ drm-vc4-zero-the-tile-state-data-array-before-each-bin-job.patch drm-mediatek-ovl_adaptor-balance-component-registrations.patch drm-amdgpu-restore-umd-profile-pstate-after-runtime-resume.patch drm-amdgpu-cap-gtt-size-to-physical-ram-on-apus.patch +drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch +drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch +drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch +drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch