mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] fix: dma-buf: unwrap_merge_order: success path leaks chain and array   fence references
@ 2026-06-26 12:21 WenTao Liang
  2026-06-26 12:42 ` Christian König
  0 siblings, 1 reply; 2+ messages in thread
From: WenTao Liang @ 2026-06-26 12:21 UTC (permalink / raw)
  To: sumit.semwal, christian.koenig
  Cc: linux-media, dri-devel, linaro-mm-sig, linux-kernel,
	WenTao Liang, stable

The success path only releases a2 via dma_fence_put but does not release
  a1, c1, or c2. The dma_fence_get calls at lines 440 and 445 were intended
  to pass references to mock_chain, but mock_chain already acquires its own
  references internally, making these extra gets surplus and permanently
  leaked.

Cc: stable@vger.kernel.org
Fixes: b1cce631e61f ("dma-buf: add selftest for fence order after merge")
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
---
 drivers/dma-buf/st-dma-fence-unwrap.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/dma-buf/st-dma-fence-unwrap.c b/drivers/dma-buf/st-dma-fence-unwrap.c
index 9c74195f47fd..72ca632e3981 100644
--- a/drivers/dma-buf/st-dma-fence-unwrap.c
+++ b/drivers/dma-buf/st-dma-fence-unwrap.c
@@ -472,6 +472,8 @@ static int unwrap_merge_order(void *arg)
 	}
 
 	dma_fence_put(a2);
+	dma_fence_put(c2);
+	dma_fence_put(a1);
 	return err;
 
 error_put_a1:
-- 
2.39.5 (Apple Git-154)


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] fix: dma-buf: unwrap_merge_order: success path leaks chain and array fence references
  2026-06-26 12:21 [PATCH] fix: dma-buf: unwrap_merge_order: success path leaks chain and array fence references WenTao Liang
@ 2026-06-26 12:42 ` Christian König
  0 siblings, 0 replies; 2+ messages in thread
From: Christian König @ 2026-06-26 12:42 UTC (permalink / raw)
  To: WenTao Liang, sumit.semwal
  Cc: linux-media, dri-devel, linaro-mm-sig, linux-kernel, stable

On 6/26/26 14:21, WenTao Liang wrote:
> The success path only releases a2 via dma_fence_put but does not release
>   a1, c1, or c2. The dma_fence_get calls at lines 440 and 445 were intended
>   to pass references to mock_chain, but mock_chain already acquires its own
>   references internally, making these extra gets surplus and permanently
>   leaked.
> 

> Cc: stable@vger.kernel.org
> Fixes: b1cce631e61f ("dma-buf: add selftest for fence order after merge")

Please drop that, this is a minor issue in a unit test and not anything which needs backporting.

> Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
> ---
>  drivers/dma-buf/st-dma-fence-unwrap.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/dma-buf/st-dma-fence-unwrap.c b/drivers/dma-buf/st-dma-fence-unwrap.c
> index 9c74195f47fd..72ca632e3981 100644
> --- a/drivers/dma-buf/st-dma-fence-unwrap.c
> +++ b/drivers/dma-buf/st-dma-fence-unwrap.c
> @@ -472,6 +472,8 @@ static int unwrap_merge_order(void *arg)
>  	}
>  
>  	dma_fence_put(a2);
> +	dma_fence_put(c2);
> +	dma_fence_put(a1);

That looks correct to me, but the error handler below is incorrect as well.

When c2 allocation fails we also need to release c1.

Regards,
Christian.

>  	return err;
>  
>  error_put_a1:


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-06-26 12:43 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-26 12:21 [PATCH] fix: dma-buf: unwrap_merge_order: success path leaks chain and array fence references WenTao Liang
2026-06-26 12:42 ` Christian König

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®