From: Paul Menzel <pmenzel@molgen.mpg.de>
To: Kees Cook <keescook@chromium.org>
Cc: "Mazin Rezk" <mnrzk@protonmail.com>,
linux-kernel@vger.kernel.org, amd-gfx@lists.freedesktop.org,
dri-devel@lists.freedesktop.org,
"Andrew Morton" <akpm@linux-foundation.org>,
"Christian König" <christian.koenig@amd.com>,
"Harry Wentland" <Harry.Wentland@amd.com>,
"Nicholas Kazlauskas" <nicholas.kazlauskas@amd.com>,
sunpeng.li@amd.com,
"Alexander Deucher" <Alexander.Deucher@amd.com>,
1i5t5.duncan@cox.net, mphantomx@yahoo.com.br,
regressions@leemhuis.info, anthony.ruhier@gmail.com
Subject: Re: [PATCH] amdgpu_dm: fix nonblocking atomic commit use-after-free
Date: Fri, 24 Jul 2020 23:19:59 +0200 [thread overview]
Message-ID: <3c92db94-3b62-a70b-8ace-f5e34e8f268f@molgen.mpg.de> (raw)
In-Reply-To: <202007241016.922B094AAA@keescook>
Dear Kees,
Am 24.07.20 um 19:33 schrieb Kees Cook:
> On Fri, Jul 24, 2020 at 09:45:18AM +0200, Paul Menzel wrote:
>> Am 24.07.20 um 00:32 schrieb Kees Cook:
>>> On Thu, Jul 23, 2020 at 09:10:15PM +0000, Mazin Rezk wrote:
>> As Linux 5.8-rc7 is going to be released this Sunday, I wonder, if commit
>> 3202fa62f ("slub: relocate freelist pointer to middle of object") should be
>> reverted for now to fix the regression for the users according to Linux’ no
>> regression policy. Once the AMDGPU/DRM driver issue is fixed, it can be
>> reapplied. I know it’s not optimal, but as some testing is going to be
>> involved for the fix, I’d argue it’s the best option for the users.
>
> Well, the SLUB defense was already released in v5.7, so I'm not sure it
> really helps for amdgpu_dm users seeing it there too.
In my opinion, it would help, as the stable release could pick up the
revert, ones it’s in Linus’ master branch.
> There was a fix to disable the async path for this driver that worked
> around the bug too, yes? That seems like a safer and more focused
> change that doesn't revert the SLUB defense for all users, and would
> actually provide a complete, I think, workaround whereas reverting
> the SLUB change means the race still exists. For example, it would be
> hit with slab poisoning, etc.
I do not know. If there is such a fix, that would be great. But if you
do not know, how should a normal user? ;-)
Kind regards,
Paul
Kind regards,
Paul
next prev parent reply other threads:[~2020-07-24 21:20 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-23 21:10 [PATCH] amdgpu_dm: fix nonblocking atomic commit use-after-free Mazin Rezk
2020-07-23 22:16 ` Kazlauskas, Nicholas
2020-07-23 22:57 ` Mazin Rezk
2020-07-24 21:09 ` Mazin Rezk
2020-07-23 22:32 ` Kees Cook
2020-07-23 22:58 ` Mazin Rezk
2020-07-24 7:26 ` Christian König
2020-07-24 7:45 ` Paul Menzel
2020-07-24 17:33 ` Kees Cook
2020-07-24 21:19 ` Paul Menzel [this message]
2020-07-25 3:03 ` Mazin Rezk
2020-07-25 4:59 ` Duncan
2020-07-25 5:20 ` Mazin Rezk
2020-07-28 9:22 ` Paul Menzel
2020-07-28 17:07 ` Kazlauskas, Nicholas
2020-07-28 21:58 ` daniel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3c92db94-3b62-a70b-8ace-f5e34e8f268f@molgen.mpg.de \
--to=pmenzel@molgen.mpg.de \
--cc=1i5t5.duncan@cox.net \
--cc=Alexander.Deucher@amd.com \
--cc=Harry.Wentland@amd.com \
--cc=akpm@linux-foundation.org \
--cc=amd-gfx@lists.freedesktop.org \
--cc=anthony.ruhier@gmail.com \
--cc=christian.koenig@amd.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=keescook@chromium.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mnrzk@protonmail.com \
--cc=mphantomx@yahoo.com.br \
--cc=nicholas.kazlauskas@amd.com \
--cc=regressions@leemhuis.info \
--cc=sunpeng.li@amd.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).