From: Evanshenf <archwse@gmail.com>
To: dri-devel@lists.freedesktop.org
Cc: Jianmin Lv <lvjianmin@loongson.cn>,
Qianhai Wu <wuqianhai@loongson.cn>,
Huacai Chen <chenhuacai@kernel.org>,
Mingcong Bai <jeffbai@aosc.io>, Xi Ruoyao <xry111@xry111.site>,
Icenowy Zheng <zhengxingda@iscas.ac.cn>,
Sui Jingfeng <suijingfeng@loongson.cn>,
stable@vger.kernel.org, linux-kernel@vger.kernel.org,
Evanshenf <archwse@gmail.com>
Subject: [PATCH 1/2] drm/loongson: Fix double free on BO initialization failure
Date: Sat, 3 Oct 2026 09:34:58 +0000 [thread overview]
Message-ID: <20261003093415.e64386de1e64-1-archwse@gmail.com> (raw)
If ttm_bo_init_validate() fails, it drops the buffer object's reference
and cleans it up through the supplied destroy callback. lsdc_bo_destroy()
releases the GEM object and frees the enclosing lsdc_bo, so freeing it
again in lsdc_bo_create() causes a double free on a synchronous failure
path.
Let TTM own the cleanup after initialization has started and return the
error directly. Keep the explicit free on drm_gem_object_init() failure,
which occurs before ownership is passed to TTM.
Tested on LS7A2000 by making drm_vma_offset_add() return -ENOSPC for one
selected dumb-buffer creation. The error reached userspace, the destroy
callback ran once, and no handle was published or tracked BO retained.
Normal buffer creation, zeroing, mapping, readback and release passed.
AI assistance was used for the ownership analysis, fix, fault-injection
tools, build and test execution.
Fixes: f39db26c5428 ("drm: Add kms driver for loongson display controller")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Evanshenf <archwse@gmail.com>
---
drivers/gpu/drm/loongson/lsdc_ttm.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/loongson/lsdc_ttm.c b/drivers/gpu/drm/loongson/lsdc_ttm.c
index d7441d9..88536e2 100644
--- a/drivers/gpu/drm/loongson/lsdc_ttm.c
+++ b/drivers/gpu/drm/loongson/lsdc_ttm.c
@@ -475,10 +475,8 @@ struct lsdc_bo *lsdc_bo_create(struct drm_device *ddev,
ret = ttm_bo_init_validate(bdev, tbo, bo_type, &lbo->placement, 0,
false, sg, resv, lsdc_bo_destroy);
- if (ret) {
- kfree(lbo);
+ if (ret)
return ERR_PTR(ret);
- }
return lbo;
}
base-commit: bca45af5998a05f34b13a2ef11e639bac9c62643
--
2.43.0
next reply other threads:[~2026-10-03 9:35 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 9:34 Evanshenf [this message]
2026-10-03 9:34 ` [PATCH 2/2] drm/loongson: Handle buffer mapping failures when clearing a BO Evanshenf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003093415.e64386de1e64-1-archwse@gmail.com \
--to=archwse@gmail.com \
--cc=chenhuacai@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=jeffbai@aosc.io \
--cc=linux-kernel@vger.kernel.org \
--cc=lvjianmin@loongson.cn \
--cc=stable@vger.kernel.org \
--cc=suijingfeng@loongson.cn \
--cc=wuqianhai@loongson.cn \
--cc=xry111@xry111.site \
--cc=zhengxingda@iscas.ac.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®