adev->isolation[] has one slot per partition, but a ring that is not
assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing
the array with it is out of bounds. SDMA submissions hit this on both
the isolation enforcement and the VM flush path and trip UBSAN.
Fall back to the first slot the way the cleaner shader path already
does, and stop taking the address before the ring type check that makes
it relevant.
Cc: stable@vger.kernel.org
Signed-off-by: Xiang Liu <xiang.liu@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
struct amdgpu_ring *ring,
struct amdgpu_job *job)
{
- struct amdgpu_isolation *isolation = &adev->isolation[ring->xcp_id];
struct drm_sched_fence *f = job->base.s_fence;
+ struct amdgpu_isolation *isolation;
struct dma_fence *dep;
void *owner;
int r;
ring->funcs->type != AMDGPU_RING_TYPE_COMPUTE)
return NULL;
+ isolation = &adev->isolation[ring->xcp_id == AMDGPU_XCP_NO_PARTITION ?
+ 0 : ring->xcp_id];
+
/*
* All submissions where enforce isolation is false are handled as if
* they come from a single client. Use ~0l as the owner to distinct it
bool *emit_gds_needed)
{
struct amdgpu_device *adev = ring->adev;
- struct amdgpu_isolation *isolation = &adev->isolation[ring->xcp_id];
+ struct amdgpu_isolation *isolation =
+ &adev->isolation[ring->xcp_id == AMDGPU_XCP_NO_PARTITION ?
+ 0 : ring->xcp_id];
unsigned vmhub = ring->vm_hub;
struct amdgpu_vmid_mgr *id_mgr = &adev->vm_manager.id_mgr[vmhub];
struct amdgpu_vmid *id = &id_mgr->ids[job->vmid];