* [PATCH 0/2] drm/syncobj: fix sync_file import into timeline points
@ 2026-10-10 18:07 Julian Orth
2026-10-10 18:07 ` [PATCH 1/2] drm/syncobj: fix fence and syncobj leak in drm_syncobj_import_sync_file_fence Julian Orth
2026-10-10 18:07 ` [PATCH 2/2] drm/syncobj: flatten chains when importing sync_file into timeline point Julian Orth
0 siblings, 2 replies; 3+ messages in thread
From: Julian Orth @ 2026-10-10 18:07 UTC (permalink / raw)
To: Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann,
David Airlie, Simona Vetter, Sumit Semwal, Christian König,
Dmitry Osipenko, Rob Clark
Cc: dri-devel, linux-kernel, linux-media, linaro-mm-sig, Julian Orth
Importing a sync_file into a timeline point
(DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_IMPORT_SYNC_FILE |
DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_TIMELINE) has two bugs since
c2d3a7300695:
1. The fence and syncobj references leak if dma_fence_chain_alloc()
fails.
2. A sync_file that contains a dma_fence_chain (e.g. one exported from a
timeline point) is wrapped in another chain and triggers the
WARN_ON in dma_fence_chain_init(). I reported this on 2026-05-20.
These patches were developed completely autonomously by AI. I have
reviewed them, but they have not been tested at runtime. They are only
compile-tested.
Julian Orth (2):
drm/syncobj: fix fence and syncobj leak in
drm_syncobj_import_sync_file_fence
drm/syncobj: flatten chains when importing sync_file into timeline
point
drivers/gpu/drm/drm_syncobj.c | 20 +++++++++++++++++---
1 file changed, 17 insertions(+), 3 deletions(-)
base-commit: 6ccf996a0dec1852dab94ad865f27b4904750e12
--
2.56.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 1/2] drm/syncobj: fix fence and syncobj leak in drm_syncobj_import_sync_file_fence
2026-10-10 18:07 [PATCH 0/2] drm/syncobj: fix sync_file import into timeline points Julian Orth
@ 2026-10-10 18:07 ` Julian Orth
2026-10-10 18:07 ` [PATCH 2/2] drm/syncobj: flatten chains when importing sync_file into timeline point Julian Orth
1 sibling, 0 replies; 3+ messages in thread
From: Julian Orth @ 2026-10-10 18:07 UTC (permalink / raw)
To: Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann,
David Airlie, Simona Vetter, Sumit Semwal, Christian König,
Dmitry Osipenko, Rob Clark
Cc: dri-devel, linux-kernel, linux-media, linaro-mm-sig, Julian Orth
If dma_fence_chain_alloc() fails, the function returns -ENOMEM without
dropping the references to the imported fence and the syncobj.
Fixes: c2d3a7300695 ("drm/syncobj: Extend EXPORT_SYNC_FILE for timeline syncobjs")
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Julian Orth <ju.orth@gmail.com>
---
drivers/gpu/drm/drm_syncobj.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/drm_syncobj.c b/drivers/gpu/drm/drm_syncobj.c
index c23a5de27..5ca5163d0 100644
--- a/drivers/gpu/drm/drm_syncobj.c
+++ b/drivers/gpu/drm/drm_syncobj.c
@@ -730,6 +730,7 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private,
{
struct dma_fence *fence = sync_file_get_fence(fd);
struct drm_syncobj *syncobj;
+ int ret = 0;
if (!fence)
return -EINVAL;
@@ -743,17 +744,20 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private,
if (point) {
struct dma_fence_chain *chain = dma_fence_chain_alloc();
- if (!chain)
- return -ENOMEM;
+ if (!chain) {
+ ret = -ENOMEM;
+ goto out;
+ }
drm_syncobj_add_point(syncobj, chain, fence, point);
} else {
drm_syncobj_replace_fence(syncobj, fence);
}
+out:
dma_fence_put(fence);
drm_syncobj_put(syncobj);
- return 0;
+ return ret;
}
static int drm_syncobj_export_sync_file(struct drm_file *file_private,
--
2.56.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 2/2] drm/syncobj: flatten chains when importing sync_file into timeline point
2026-10-10 18:07 [PATCH 0/2] drm/syncobj: fix sync_file import into timeline points Julian Orth
2026-10-10 18:07 ` [PATCH 1/2] drm/syncobj: fix fence and syncobj leak in drm_syncobj_import_sync_file_fence Julian Orth
@ 2026-10-10 18:07 ` Julian Orth
1 sibling, 0 replies; 3+ messages in thread
From: Julian Orth @ 2026-10-10 18:07 UTC (permalink / raw)
To: Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann,
David Airlie, Simona Vetter, Sumit Semwal, Christian König,
Dmitry Osipenko, Rob Clark
Cc: dri-devel, linux-kernel, linux-media, linaro-mm-sig, Julian Orth
A sync_file exported from a timeline point can contain a dma_fence_chain.
Importing such a sync_file into a timeline point with
DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_IMPORT_SYNC_FILE |
DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_TIMELINE passes the chain directly to
dma_fence_chain_init() and triggers
WARNING: drivers/dma-buf/dma-fence-chain.c:286 at dma_fence_chain_init
because chain fences must not be wrapped in other chain fences.
Flatten the fence with dma_fence_unwrap_merge() before adding it to the
timeline, as drm_syncobj_transfer_to_timeline() already does.
Reproducer:
1. Export a sync_file from a point > 0 of a timeline syncobj with
DRM_IOCTL_SYNCOBJ_HANDLE_TO_FD.
2. Import it into a point > 0 of another timeline syncobj with
DRM_IOCTL_SYNCOBJ_FD_TO_HANDLE.
Fixes: c2d3a7300695 ("drm/syncobj: Extend EXPORT_SYNC_FILE for timeline syncobjs")
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Julian Orth <ju.orth@gmail.com>
---
drivers/gpu/drm/drm_syncobj.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/drm_syncobj.c b/drivers/gpu/drm/drm_syncobj.c
index 5ca5163d0..c545af77e 100644
--- a/drivers/gpu/drm/drm_syncobj.c
+++ b/drivers/gpu/drm/drm_syncobj.c
@@ -742,8 +742,18 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private,
}
if (point) {
- struct dma_fence_chain *chain = dma_fence_chain_alloc();
+ struct dma_fence_chain *chain;
+ struct dma_fence *tmp;
+
+ tmp = dma_fence_unwrap_merge(fence);
+ dma_fence_put(fence);
+ fence = tmp;
+ if (!fence) {
+ drm_syncobj_put(syncobj);
+ return -ENOMEM;
+ }
+ chain = dma_fence_chain_alloc();
if (!chain) {
ret = -ENOMEM;
goto out;
--
2.56.0
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-10 18:07 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10 18:07 [PATCH 0/2] drm/syncobj: fix sync_file import into timeline points Julian Orth
2026-10-10 18:07 ` [PATCH 1/2] drm/syncobj: fix fence and syncobj leak in drm_syncobj_import_sync_file_fence Julian Orth
2026-10-10 18:07 ` [PATCH 2/2] drm/syncobj: flatten chains when importing sync_file into timeline point Julian Orth
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®