Hi Tvrtko,
On 2026-09-25 at 09:01:10 +0100, Tvrtko Ursulin wrote:
> 
> On 17/09/2026 18:01, Kamil Konieczny wrote:
> > Hi Tvrtko,
> > On 2026-09-17 at 11:12:03 +0100, Tvrtko Ursulin wrote:
> > > A new test to roughly simulate the VK CTS suite where
> > > dEQP-VK.wsi.android.swapchain.render.* is hitting an use after free when a
> > > sync file is accessed after the xe submission queue has been destroyed.
> > > 
> > > Abbreviated KASAN report:
> > > 
> > >   [IGT] xe_sync_file: starting subtest sync_file_race
> > >   ==================================================================
> > >   BUG: KASAN: slab-use-after-free in 
> > > drm_sched_fence_get_timeline_name+0xa1/0xb0 [gpu_sched]
> > >   Read of size 8 at addr ffff888126726020 by task xe_sync_file/2931
> > >   ...
> > >   Call Trace:
> > >    <TASK>
> > >    kasan_report+0xeb/0x130
> > >    drm_sched_fence_get_timeline_name+0xa1/0xb0 [gpu_sched]
> > >    sync_file_ioctl+0x3cb/0xb00
> > >   ...
> > >   Allocated by task 2931:
> > >    __kmalloc_cache_noprof+0x1c2/0x410
> > >    guc_exec_queue_init+0x1a8/0x1240 [xe]
> > >    xe_exec_queue_create+0xe72/0x13b0 [xe]
> > >    xe_exec_queue_create_ioctl+0x10d9/0x1770 [xe]
> > >    drm_ioctl_kernel+0x179/0x300
> > >    drm_ioctl+0x58f/0xcf0
> > >    xe_drm_ioctl+0xe8/0x140 [xe]
> > >   ...
> > >   Freed by task 1689:
> > >    kfree+0x106/0x3e0
> > >    __guc_exec_queue_fini_async+0x144/0x2d0 [xe]
> > >    process_one_work+0x610/0xdf0
> > >    worker_thread+0x7c8/0x14b0
> > > 
> > > Without KASAN this of course turns into a plain null pointer dereference.
> > > 
> > > Signed-off-by: Tvrtko Ursulin <[email protected]>
> > > Cc: Lucas De Marchi <[email protected]>
> > > Cc: Matthew Brost <[email protected]>
> > > Cc: Rodrigo Vivi <[email protected]>
> > > Cc: Thomas Hellström <[email protected]>
> > > Cc: Christian König <[email protected]>
> > > Cc: [email protected]
> > > Reviewed-by: Rodrigo Vivi <[email protected]> # v2
> > LGTM
> > Acked-by: Kamil Konieczny <[email protected]>
> 
> Thank you - okay if I push or Intel will do it?
> 
> Regards,
> 
> Tvrtko

I was blind, sorry, you already got r-b, I will merge it.

Regards,
Kamil

> 
> > 
> > Regards,
> > Kamil
> > 
> > > ---
> > > v2:
> > >   - igt_main and igt_fixture tweaks. (Rodrigo)
> > > 
> > > v3:
> > >   - Add driver name checks.
> > > 
> > > v4:
> > >   - Restore alphabetical ordering in the makefile. (Kamil)
> > > ---
> > >   tests/intel/xe_sync_file.c | 154 +++++++++++++++++++++++++++++++++++++
> > >   tests/meson.build          |   1 +
> > >   2 files changed, 155 insertions(+)
> > >   create mode 100644 tests/intel/xe_sync_file.c
> > > 
[cut]

Reply via email to