nvidia: free the GSP TSG when channel group construction fails after the alloc RPC - #1398
Open
SammyTourani wants to merge 1 commit into
Open
SammyTourani wants to merge 1 commit into
SammyTourani wants to merge 1 commit into
Conversation
…the alloc RPC kchangrpapiConstruct_IMPL() sends the TSG alloc RPC and can still fail afterwards: ctxBufPoolReserve() running out of vidmem, the PROMOTE_FAULT_METHOD_BUFFERS control, or listAppendValue(). A failed constructor is never destructed, so the RPC free that bRpcFree asks for never happens and GSP-RM keeps the TSG after kernel-RM has released its handle and grpID. Since 615.71.09 kernel-RM passes its grpID to GSP-RM, so every later TSG or bare channel allocation that gets the leaked grpID fails on GSP-RM with NV_ERR_STATE_IN_USE, and the client reusing the handle fails with NV_ERR_INSERT_DUPLICATE_NAME, until the leaking client exits. Free the object on GSP/host in the failure path once the alloc RPC has succeeded, as kchannelConstruct_IMPL() already does for channels.
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1379
In
kchangrpapiConstruct_IMPL(), record that the alloc RPC succeeded (bRpcAllocated, the same waykchannelConstruct_IMPL()tracks its channel RPC). In the failure path, free the object on GSP-RM (or the vGPU host) with
NV_RM_RPC_FREE:kchangrpDestroy()releases the grpID on the kernel-RM side, which is the same order as a normal free(RPC free, then destructor).
ctxBufPoolReserve()path re-acquires it beforegoto failed.handle, that object belongs to someone else.
NV_RM_RPC_FREE_ON_ERRORbecause it assigns to a variable namedstatus, which this function does not have.NV_RM_RPC_FREEwith a local status is the patternvideo_mem.cuses in its constructor failure path.One file, +17 lines.
Verification
There was no NVIDIA GPU available, so this is not tested on hardware.
I used a userspace harness that compiles these unmodified driver sources natively, with the RM include paths and defines from
src/nvidia/Makefile:kernel_channel_group_api.c;g_kernel_channel_group_api_nvoc.c, the NVOC objCreate/ctor thatresservResourceFactory()goes through;kernel_fifo.c, forkfifoChidMgrAllocChannelGroupHwID()andkfifoChidMgrFreeChannelGroupHwID();base_utils.c,nvassert.candnvstatus.c.Everything else is faked:
kchangrpInit/kchangrpDestroy, reduced to their grpID handling on the real allocator;kfifoChidMgrAllocChannelGroupHwID()with the grpID frominternalFlags.ctxBufPoolReserve(), which returnsNV_ERR_NO_MEMORYon demand.Any other external symbol aborts if it is called (135 stubs, none hit). The build uses AddressSanitizer, and every GSP-RM RPC
must be issued with the GPU lock held.
The scenario:
Command:
./verify.sh /Volumes/SammyDisk/oss-contrib-work/nvidia__open-gpu-kernel-modules@1379 61dcc937 fix/issue-1379(builds and runs the harness on
git archiveof 615.71.09 and of the patched commit)Result (excerpt of the output; each run has 15 checks):
bug report.
Compile check: I compiled the patched file with the exact command from
make -n -C src/nvidia TARGET_ARCH=x86_64 CC=clang, plusclang --target=x86_64-linux-gnu -Werror. It returned rc=0 with nowarnings, and the unmodified file gives the same result. GCC was not available locally.