]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
6.6-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 5 Aug 2026 12:13:51 +0000 (14:13 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 5 Aug 2026 12:13:51 +0000 (14:13 +0200)
added patches:
drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch
drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch
drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch
drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch

queue-6.6/drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch [new file with mode: 0644]
queue-6.6/drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch [new file with mode: 0644]
queue-6.6/drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch [new file with mode: 0644]
queue-6.6/drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch [new file with mode: 0644]
queue-6.6/series

diff --git a/queue-6.6/drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch b/queue-6.6/drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch
new file mode 100644 (file)
index 0000000..f143eb7
--- /dev/null
@@ -0,0 +1,43 @@
+From 99b2fe4f19e3be0a8d0a0b5ea98d855970889653 Mon Sep 17 00:00:00 2001
+From: Gang Ba <Gang.Ba@amd.com>
+Date: Tue, 14 Jul 2026 15:08:57 -0400
+Subject: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
+
+From: Gang Ba <Gang.Ba@amd.com>
+
+commit 99b2fe4f19e3be0a8d0a0b5ea98d855970889653 upstream.
+
+Prevent unauthorized termination of active GPU debug sessions.
+Previously, users with /dev/kfd access could terminate another process's
+debug session without proper ownership or ptrace authorization.
+
+Signed-off-by: Gang Ba <Gang.Ba@amd.com>
+Reviewed-by: Kent Russell <kent.russell@amd.com>
+Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
+(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)
+Cc: stable@vger.kernel.org
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/amd/amdkfd/kfd_chardev.c |   10 +++++++---
+ 1 file changed, 7 insertions(+), 3 deletions(-)
+
+--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
++++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
+@@ -2977,10 +2977,14 @@ static int kfd_ioctl_set_debug_trap(stru
+               goto out;
+       }
+-      /* Check if target is still PTRACED. */
++      /*
++       * Verify debugger has permission to debug target process.
++       * For cross-process debugging, require active ptrace relationship.
++       * This applies to ALL operations to prevent unauthorized interference.
++       */
+       rcu_read_lock();
+-      if (target != p && args->op != KFD_IOC_DBG_TRAP_DISABLE
+-                              && ptrace_parent(target->lead_thread) != current) {
++      if (target != p && ptrace_parent(target->lead_thread) != current
++                      && target->debugger_process != p) {
+               pr_err("PID %i is not PTRACED and cannot be debugged\n", args->pid);
+               r = -EPERM;
+       }
diff --git a/queue-6.6/drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch b/queue-6.6/drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch
new file mode 100644 (file)
index 0000000..2c5a018
--- /dev/null
@@ -0,0 +1,47 @@
+From 38b73293f38658a4685ffcea666462024f858ad9 Mon Sep 17 00:00:00 2001
+From: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
+Date: Mon, 20 Jul 2026 11:53:30 -0400
+Subject: drm/amdkfd: fix QID bit leak in pqm_create_queue()
+
+From: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
+
+commit 38b73293f38658a4685ffcea666462024f858ad9 upstream.
+
+When MES is enabled and amdgpu_amdkfd_alloc_kernel_mem() fails during
+the first queue creation for a process, pqm_create_queue() returns
+early via 'return retval' without going through the err_create_queue
+cleanup label.
+
+This means clear_bit(*qid, pqm->queue_slot_bitmap) is never called,
+leaving the reserved QID bit permanently set in queue_slot_bitmap.
+Over time this leaks QID slots, potentially exhausting all available
+queue slots.
+
+Fix this by replacing 'return retval' with 'goto err_allocate_pqn'
+so that clear_bit() is always called on the error path without
+touching the uninitialized pqn pointer.
+
+AILIKFD-813
+
+Reported-by: Deucher, Alexander <alexander.deucher@amd.com>
+Signed-off-by: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
+Reviewed-by: Kent Russell <kent.russell@amd.com>
+Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
+(cherry picked from commit a107f74c38edbb80d6ab64dcaeeb292c14e9779f)
+Cc: stable@vger.kernel.org
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c
++++ b/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c
+@@ -344,7 +344,7 @@ int pqm_create_queue(struct process_queu
+                                                    false);
+               if (retval) {
+                       dev_err(dev->adev->dev, "failed to allocate process context bo\n");
+-                      return retval;
++                      goto err_allocate_pqn;
+               }
+               memset(pdd->proc_ctx_cpu_ptr, 0, AMDGPU_MES_PROC_CTX_SIZE);
+       }
diff --git a/queue-6.6/drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch b/queue-6.6/drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch
new file mode 100644 (file)
index 0000000..5f4b3e8
--- /dev/null
@@ -0,0 +1,37 @@
+From a9cdc85839e4fe2c760aa4ca6cc341c31ad1918a Mon Sep 17 00:00:00 2001
+From: David Francis <David.Francis@amd.com>
+Date: Tue, 21 Jul 2026 09:30:07 -0400
+Subject: drm/amdkfd: Handle invalid event type in CRIU event restore
+
+From: David Francis <David.Francis@amd.com>
+
+commit a9cdc85839e4fe2c760aa4ca6cc341c31ad1918a upstream.
+
+In kfd_criu_restore_event, there was no handling for
+the event priv data having an invalid event type. The priv
+data here is untrusted and can be invalid.
+
+In that case, fail with EINVAL.
+
+Signed-off-by: David Francis <David.Francis@amd.com>
+Reviewed-by: Kent Russell <kent.russell@amd.com>
+Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
+(cherry picked from commit 2e8e9963cd5c41aa14fd5316bf9ec92e7a0e3097)
+Cc: stable@vger.kernel.org
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/amd/amdkfd/kfd_events.c |    3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
++++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+@@ -520,6 +520,9 @@ int kfd_criu_restore_event(struct file *
+               ret = create_other_event(p, ev, &ev_priv->event_id);
+               break;
++      default:
++              ret = -EINVAL;
++              break;
+       }
+       mutex_unlock(&p->event_mutex);
diff --git a/queue-6.6/drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch b/queue-6.6/drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch
new file mode 100644 (file)
index 0000000..542d30d
--- /dev/null
@@ -0,0 +1,83 @@
+From ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2 Mon Sep 17 00:00:00 2001
+From: William Palacek <William.Palacek@amd.com>
+Date: Wed, 22 Jul 2026 11:20:56 -0400
+Subject: drm/amdkfd: hold event_mutex while checkpointing CRIU events
+
+From: William Palacek <William.Palacek@amd.com>
+
+commit ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2 upstream.
+
+kfd_criu_checkpoint_events() counts the entries in p->event_idr via
+kfd_get_num_events(), allocates an array sized to that count, and then
+walks the same IDR to fill it. Neither the count nor the walk holds
+p->event_mutex.
+
+The CRIU checkpoint caller holds only p->mutex. Event create and destroy
+(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not
+take p->mutex, so a second thread in the same process can insert or remove
+events between the count and the walk. If an event is inserted, the walk
+iterates more entries than were counted and writes past the end of the
+ev_privs allocation; if an event is removed, the walk dereferences an
+entry that is being freed.
+
+Hold p->event_mutex across the count and the walk so both observe a
+consistent view of p->event_idr. The lock is released before
+copy_to_user(), which only touches the local buffer. The caller already
+holds p->mutex and the create/destroy paths never take p->mutex, so the
+p->mutex -> p->event_mutex order is not inverted and no deadlock is
+introduced.
+
+Fixes: 40e8a766a761 ("drm/amdkfd: CRIU checkpoint and restore events")
+Signed-off-by: William Palacek <William.Palacek@amd.com>
+Reviewed-by: Alysa Liu <Alysa.Liu@amd.com>
+Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
+(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)
+Cc: stable@vger.kernel.org
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/amd/amdkfd/kfd_events.c |   22 ++++++++++++++++++----
+ 1 file changed, 18 insertions(+), 4 deletions(-)
+
+--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
++++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+@@ -544,15 +544,27 @@ int kfd_criu_checkpoint_events(struct kf
+       int ret =  0;
+       struct kfd_event *ev;
+       uint32_t ev_id;
++      uint32_t num_events;
+-      uint32_t num_events = kfd_get_num_events(p);
+-
+-      if (!num_events)
++      /* Serialize the count and the walk below against concurrent event
++       * create/destroy. Those paths take only p->event_mutex, not the
++       * p->mutex held by the CRIU checkpoint caller, so without this the
++       * event_idr can grow between kfd_get_num_events() and the loop and the
++       * walk writes past the ev_privs allocation.
++       */
++      mutex_lock(&p->event_mutex);
++
++      num_events = kfd_get_num_events(p);
++      if (!num_events) {
++              mutex_unlock(&p->event_mutex);
+               return 0;
++      }
+       ev_privs = kvzalloc(num_events * sizeof(*ev_privs), GFP_KERNEL);
+-      if (!ev_privs)
++      if (!ev_privs) {
++              mutex_unlock(&p->event_mutex);
+               return -ENOMEM;
++      }
+       idr_for_each_entry(&p->event_idr, ev, ev_id) {
+@@ -593,6 +605,8 @@ int kfd_criu_checkpoint_events(struct kf
+               i++;
+       }
++      mutex_unlock(&p->event_mutex);
++
+       ret = copy_to_user(user_priv_data + *priv_data_offset,
+                          ev_privs, num_events * sizeof(*ev_privs));
+       if (ret) {
index 4e4e0283a3717811382526b28f0c101d945af2b9..0790c383883dca9857b74e9b458669e366ec8356 100644 (file)
@@ -190,3 +190,7 @@ drm-vc4-zero-the-tile-state-data-array-before-each-bin-job.patch
 drm-mediatek-ovl_adaptor-balance-component-registrations.patch
 drm-amdgpu-restore-umd-profile-pstate-after-runtime-resume.patch
 drm-amdgpu-cap-gtt-size-to-physical-ram-on-apus.patch
+drm-amdkfd-fix-missing-authorization-check-in-kfd_ioc_dbg_trap_disable.patch
+drm-amdkfd-fix-qid-bit-leak-in-pqm_create_queue.patch
+drm-amdkfd-handle-invalid-event-type-in-criu-event-restore.patch
+drm-amdkfd-hold-event_mutex-while-checkpointing-criu-events.patch