aca_handle_is_valid() returned false if !list_empty(&handle->node) evaluated to true. Because active registered handles have non-empty nodes in the handle list, valid handles evaluated as invalid. Consequently, amdgpu_aca_get_error_data() returned -EOPNOTSUPP whenever aca_handle_is_valid() evaluated to true.
Fix the logic in aca_handle_is_valid() to verify that the handle is non-NULL, contains a valid mask, and is currently registered in the list. Negate the check in amdgpu_aca_get_error_data() so valid handles are processed properly. Additionally, update remove_aca_handle() to use list_del_init() instead of list_del(). Standard list_del() leaves node pointers poisoned, which causes !list_empty() in aca_handle_is_valid() to evaluate to true for removed handles, leading to a potential use-after-free during device teardown. Signed-off-by: Sreeraj S Kurup <[email protected]> --- drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c index c76664af9902..b4c1438a56d8 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_aca.c @@ -586,10 +586,7 @@ static int __aca_get_error_data(struct amdgpu_device *adev, struct aca_handle *h static bool aca_handle_is_valid(struct aca_handle *handle) { - if (!handle->mask || !list_empty(&handle->node)) - return false; - - return true; + return handle && handle->mask && !list_empty(&handle->node); } int amdgpu_aca_get_error_data(struct amdgpu_device *adev, struct aca_handle *handle, @@ -599,7 +596,7 @@ int amdgpu_aca_get_error_data(struct amdgpu_device *adev, struct aca_handle *han if (!handle || !err_data) return -EINVAL; - if (aca_handle_is_valid(handle)) + if (!aca_handle_is_valid(handle)) return -EOPNOTSUPP; if ((type < 0) || (!(BIT(type) & handle->mask))) @@ -717,7 +714,7 @@ static void remove_aca_handle(struct aca_handle *handle) struct aca_handle_manager *mgr = handle->mgr; aca_fini_error_cache(handle); - list_del(&handle->node); + list_del_init(&handle->node); mgr->nr_handles--; } -- 2.54.0
