Series is:
Reviewed-by: Alex Deucher <[email protected]>

On Thu, Aug 13, 2026 at 1:15 PM Marioukhine, Vladimir
<[email protected]> wrote:
>
> AMD General
>
>
> Both create_queue_cpsch() and create_queue_nocpsch() unconditionally
>
> call mqd_mgr->restore_mqd() when a CRIU restore is in progress
>
> (qd != NULL), with no NULL guard. On any system where restore_mqd is
>
> not implemented, a user holding CAP_CHECKPOINT_RESTORE can trigger a
>
> kernel NULL pointer dereference and panic the machine by issuing
>
> KFD_IOC_CRIU_OP_RESTORE with a crafted queue restore object.
>
>
>
> Add a NULL guard for restore_mqd right after mqd_mgr is resolved,
>
> before any resource allocations, returning -EOPNOTSUPP if the callback
>
> is not implemented. This avoids complex error unwinding and is
>
> consistent with the existing checkpoint_mqd guard.
>
>
>
> Fixes: 48f0bdf4e38e ("drm/amdkfd: Added MQD manager files for GFX12.")
>
> Fixes: 01bbc4a4b947 ("drm/amdkfd: Add MQD manager for GFX 12.1.0")
>
> Cc: [email protected]
>
> Signed-off-by: Vladimir Marioukhine <[email protected]>
>
> ---
>
> drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c | 10 ++++++++++
>
> 1 file changed, 10 insertions(+)
>
>
>
> diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c 
> b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
>
> index ea9d87450eae..25b738200e7e 100644
>
> --- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
>
> +++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
>
> @@ -769,6 +769,11 @@ static int create_queue_nocpsch(struct 
> device_queue_manager *dqm,
>
>                mqd_mgr = dqm->mqd_mgrs[get_mqd_type_from_queue_type(
>
>                                             q->properties.type)];
>
> +            if (qd && !mqd_mgr->restore_mqd) {
>
> +                           pr_debug("restore_mqd not implemented for this 
> GPU\n");
>
> +                           retval = -EOPNOTSUPP;
>
> +                           goto deallocate_vmid;
>
> +            }
>
>               if (q->properties.type == KFD_QUEUE_TYPE_COMPUTE) {
>
>                              retval = allocate_hqd(dqm, q);
>
>                              if (retval)
>
> @@ -2134,6 +2139,11 @@ static int create_queue_cpsch(struct 
> device_queue_manager *dqm, struct queue *q,
>
>                mqd_mgr = dqm->mqd_mgrs[get_mqd_type_from_queue_type(
>
>                                             q->properties.type)];
>
> +            if (qd && !mqd_mgr->restore_mqd) {
>
> +                           pr_debug("restore_mqd not implemented for this 
> GPU\n");
>
> +                           retval = -EOPNOTSUPP;
>
> +                           goto out_deallocate_sdma_queue;
>
> +            }
>
>                if (q->properties.type == KFD_QUEUE_TYPE_SDMA ||
>
>                              q->properties.type == KFD_QUEUE_TYPE_SDMA_XGMI)
>
>

Reply via email to