Skip to content

Commit dc372e5

Browse files
liming011davejiang
authored andcommitted
cxl/pci: Hold memdev lock in cxl_event_trace_record()
cxl_event_config() invokes cxl_mem_get_event_record() to get remain event logs from CXL device during cxl_pci_probe(). If CXL memdev probing failed before that, it is possible to access an invalid endpoint. So adding a cxlmd->driver binding status checking inside cxl_dpa_to_region() to ensure the corresponding endpoint is valid. Besides, cxl_event_trace_record() needs to hold memdev lock to invoke cxl_dpa_to_region() to ensure the memdev probing completed. It is possible that cxl_event_trace_record() is invoked during the CXL memdev probing, especially user or cxl_acpi triggers CXL memdev re-probing. Suggested-by: Dan Williams <dan.j.williams@intel.com> Reviewed-by: Dan Williams <dan.j.williams@intel.com> Reviewed-by: Dave Jiang <dave.jiang@intel.com> Signed-off-by: Li Ming <ming.li@zohomail.com> Link: https://patch.msgid.link/20260314-fix_access_endpoint_without_drv_check-v2-3-4c09edf2e1db@zohomail.com Signed-off-by: Dave Jiang <dave.jiang@intel.com>
1 parent e5564e3 commit dc372e5

3 files changed

Lines changed: 9 additions & 6 deletions

File tree

drivers/cxl/core/mbox.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -893,7 +893,7 @@ int cxl_enumerate_cmds(struct cxl_memdev_state *mds)
893893
}
894894
EXPORT_SYMBOL_NS_GPL(cxl_enumerate_cmds, "CXL");
895895

896-
void cxl_event_trace_record(const struct cxl_memdev *cxlmd,
896+
void cxl_event_trace_record(struct cxl_memdev *cxlmd,
897897
enum cxl_event_log_type type,
898898
enum cxl_event_type event_type,
899899
const uuid_t *uuid, union cxl_event *evt)
@@ -920,6 +920,7 @@ void cxl_event_trace_record(const struct cxl_memdev *cxlmd,
920920
* translations. Take topology mutation locks and lookup
921921
* { HPA, REGION } from { DPA, MEMDEV } in the event record.
922922
*/
923+
guard(device)(&cxlmd->dev);
923924
guard(rwsem_read)(&cxl_rwsem.region);
924925
guard(rwsem_read)(&cxl_rwsem.dpa);
925926

@@ -968,7 +969,7 @@ void cxl_event_trace_record(const struct cxl_memdev *cxlmd,
968969
}
969970
EXPORT_SYMBOL_NS_GPL(cxl_event_trace_record, "CXL");
970971

971-
static void __cxl_event_trace_record(const struct cxl_memdev *cxlmd,
972+
static void __cxl_event_trace_record(struct cxl_memdev *cxlmd,
972973
enum cxl_event_log_type type,
973974
struct cxl_event_record_raw *record)
974975
{

drivers/cxl/core/region.c

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2950,13 +2950,15 @@ static int __cxl_dpa_to_region(struct device *dev, void *arg)
29502950
struct cxl_region *cxl_dpa_to_region(const struct cxl_memdev *cxlmd, u64 dpa)
29512951
{
29522952
struct cxl_dpa_to_region_context ctx;
2953-
struct cxl_port *port;
2953+
struct cxl_port *port = cxlmd->endpoint;
2954+
2955+
if (!cxlmd->dev.driver)
2956+
return NULL;
29542957

29552958
ctx = (struct cxl_dpa_to_region_context) {
29562959
.dpa = dpa,
29572960
};
2958-
port = cxlmd->endpoint;
2959-
if (port && is_cxl_endpoint(port) && cxl_num_decoders_committed(port))
2961+
if (cxl_num_decoders_committed(port))
29602962
device_for_each_child(&port->dev, &ctx, __cxl_dpa_to_region);
29612963

29622964
return ctx.cxlr;

drivers/cxl/cxlmem.h

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -864,7 +864,7 @@ void set_exclusive_cxl_commands(struct cxl_memdev_state *mds,
864864
void clear_exclusive_cxl_commands(struct cxl_memdev_state *mds,
865865
unsigned long *cmds);
866866
void cxl_mem_get_event_records(struct cxl_memdev_state *mds, u32 status);
867-
void cxl_event_trace_record(const struct cxl_memdev *cxlmd,
867+
void cxl_event_trace_record(struct cxl_memdev *cxlmd,
868868
enum cxl_event_log_type type,
869869
enum cxl_event_type event_type,
870870
const uuid_t *uuid, union cxl_event *evt);

0 commit comments

Comments
 (0)