From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D1CF1EE7C6 for ; Mon, 10 Aug 2026 22:16:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.13 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786400163; cv=none; b=nNCt0ceNQzeOzUG3B5dtr6Pglp8jXBz6B3U6rMNupjJ1N+82WXdkvsOkMHtV3uCClH2vo8Db7/1IMw9TI6wecyA73eOsmB0KZVyio6O0h+mi3QwirXLJcAzvarn/Kez/HF9YE7C1DiueIUSQjxSQQrvCMUNDLswkjNBkeENlaSM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786400163; c=relaxed/simple; bh=Mg9+rWZJqMT4VsDDv6qLubBa3t5NA3/vgbk/FrvAbfk=; h=Date:Message-ID:From:To:Cc:Subject:In-Reply-To:References: MIME-Version:Content-Type; b=pSB0wcJr+GmqY5zsi0PeO+8hvqhxx81Ll7OjDXrgNCGqMsxV9vuWkhVLGxH84RQtqBrHE4PHU/KpavS+VD8oPQcHwkPhlXEHSL3q9R3B88ymQys4oDNkvhDSWJocVsmOUBAlRWd6w2nTYacPvNLZLqRX+Se5IYp5JtzGkcXDDA0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=Wi/E9QIJ; arc=none smtp.client-ip=198.175.65.13 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="Wi/E9QIJ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1786400160; x=1817936160; h=date:message-id:from:to:cc:subject:in-reply-to: references:mime-version; bh=Mg9+rWZJqMT4VsDDv6qLubBa3t5NA3/vgbk/FrvAbfk=; b=Wi/E9QIJW72Gt21cswGAyymXBUVuG2ZfurGKYlVl9vvYXC1fMU69D/GY C1lqoafvL2LRbaTc90yoM/YZG2CUUeaZt0No+RRw3cj/jMB+rPli+Nsio S2e3xFMYkYyXMZLGeNJuBaDFG3LTSEGmt36HjQDAU3491CJW00VOhJzc4 Ex9m+y2qGnycKOwaeZCq/xV00D3r93O2htfe8JoE64tOJLexDiO431LJu PPSZ/cIpgLGcIRrBm6HNLlElHg5siu5ckvncmApbnTbXicP4m2wIg+hNu m13I6S9jKK5qtzwUbsxCq6mY2qeLg0sYitCHcwD5YXU9varLT7O1Qi70e g==; X-CSE-ConnectionGUID: YAvgGhuQQeWp3behHjrBUg== X-CSE-MsgGUID: rzmw1TvPS5qe/lYsAkUQkQ== X-IronPort-AV: E=McAfee;i="6800,10657,11871"; a="98075402" X-IronPort-AV: E=Sophos;i="6.25,216,1779174000"; d="scan'208";a="98075402" Received: from orviesa005.jf.intel.com ([10.64.159.145]) by orvoesa105.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 10 Aug 2026 15:15:59 -0700 X-CSE-ConnectionGUID: IX7Dd6bfTrKrNSJgSJRUFw== X-CSE-MsgGUID: UD++CGDsQXqJW3xUJ4FLGw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,216,1779174000"; d="scan'208";a="267436655" Received: from unknown (HELO adixit-MOBL3.intel.com) ([10.241.243.70]) by orviesa005-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 10 Aug 2026 15:16:01 -0700 Date: Mon, 10 Aug 2026 15:15:59 -0700 Message-ID: <87fr0lhba8.wl-ashutosh.dixit@intel.com> From: "Dixit, Ashutosh" To: Linmao Li Cc: Matthew Brost , Thomas =?ISO-8859-1?Q?Hellstr?= =?ISO-8859-1?Q?=F6m?= , Rodrigo Vivi , David Airlie , Simona Vetter , =?ISO-8859-1?Q?Jos=E9?= Roberto de Souza , "Umesh Nerlige Ramappa" ,, , Subject: Re: [PATCH v2] drm/xe/oa: Fix sync entry leak on OA config emit failure In-Reply-To: <20260731011932.3426219-1-lilinmao@kylinos.cn> References: <20260715023332.391298-1-lilinmao@kylinos.cn> <20260731011932.3426219-1-lilinmao@kylinos.cn> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM-LB/1.14.9 (=?ISO-8859-4?Q?Goj=F2?=) APEL-LB/10.8 EasyPG/1.0.0 Emacs/30.2 (x86_64-pc-linux-gnu) MULE/6.0 (HANACHIRUSATO) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") Content-Type: text/plain; charset=US-ASCII On Thu, 30 Jul 2026 18:19:32 -0700, Linmao Li wrote: > > xe_oa_emit_oa_config() releases the sync entries and the syncs array > only on its success path. When it fails before the point of no return > (fence allocation, config buffer allocation or batch submission), it > returns without touching stream->syncs. > > The stream open path handles such failures in the caller, but > xe_oa_config_locked() propagates the error without any cleanup, so the > syncs array and the fence references held by the parsed entries are > leaked. The next config ioctl overwrites stream->syncs, making the > memory unreachable for good. > > Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching > the cleanup done by the stream open error path. > > Fixes: 9920c8b88c5c ("drm/xe/oa: Add syncs support to OA config ioctl") > Signed-off-by: Linmao Li > --- > v2: > - drop the stream->syncs/num_syncs reset; nothing dereferences them > before they are overwritten or the stream is destroyed (Ashutosh Dixit) > > drivers/gpu/drm/xe/xe_oa.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/drivers/gpu/drm/xe/xe_oa.c b/drivers/gpu/drm/xe/xe_oa.c > index b3acbcd678b7c..d334ce8fed1c2 100644 > --- a/drivers/gpu/drm/xe/xe_oa.c > +++ b/drivers/gpu/drm/xe/xe_oa.c > @@ -1594,6 +1594,10 @@ static long xe_oa_config_locked(struct xe_oa_stream *stream, u64 arg) > config = xchg(&stream->oa_config, config); > drm_dbg(&stream->oa->xe->drm, "changed to oa config uuid=%s\n", > stream->oa_config->uuid); > + } else { > + while (param.num_syncs--) > + xe_sync_entry_cleanup(¶m.syncs[param.num_syncs]); > + kfree(param.syncs); > } Reviewed-by: Ashutosh Dixit Thanks for the patch Linmao, we'll get it merged. Thanks. -- Ashutosh > > err_config_put: > -- > 2.25.1 >