]> git.hungrycats.org Git - linux/commitdiff
drm/amdgpu: reject mapping a reserved doorbell to a new queue
authorZhu Lingshan <lingshan.zhu@amd.com>
Wed, 24 Jun 2026 07:52:35 +0000 (15:52 +0800)
committerAlex Deucher <alexander.deucher@amd.com>
Wed, 1 Jul 2026 15:28:50 +0000 (11:28 -0400)
When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.

However current implementation using xa_store_irq()
to store a doorbell, which allows a later queue created
with the same BO and offset parameters to overwrite an
existing queue and doorbell mapping.

This can cause problems like misrouting fence IRQ
processing to a wrong queue, and mislead the cleanup
process of one queue erasing the mapping of another queue.

This commit fixes this issue by replacing xa_store_irq with
xa_insert_irq, which rejects mapping a reserved
doorbell to a newly created queue

Signed-off-by: Zhu Lingshan <lingshan.zhu@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c

index fb4cc6bfb5ac0ce39e58391710c99df2f4d8b625..82c8809d1d9c257bdb4e4bf01e60f11080cee577 100644 (file)
@@ -702,8 +702,8 @@ amdgpu_userq_create(struct drm_file *filp, union drm_amdgpu_userq *args)
        /* Update VM owner at userq submit-time for page-fault attribution. */
        amdgpu_vm_set_task_info(&fpriv->vm);
 
-       r = xa_err(xa_store_irq(&adev->userq_doorbell_xa, index, queue,
-                               GFP_KERNEL));
+       r = xa_insert_irq(&adev->userq_doorbell_xa, index, queue,
+                         GFP_KERNEL);
        if (r)
                goto clean_mqd;