Skip to content

Commit 1d0adf2

Browse files
ShuichengLinrodrigovivi
authored andcommitted
drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked()
When XE_BO_FLAG_GGTT_ALL is set without XE_BO_FLAG_GGTT, the function returns an error without freeing a caller-provided bo, violating the documented contract that bo is freed on failure. Add xe_bo_free(bo) before returning the error. Fixes: 5a3b0df ("drm/xe: Allow bo mapping on multiple ggtts") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Matthew Brost <matthew.brost@intel.com> Link: https://patch.msgid.link/20260408175255.3402838-3-shuicheng.lin@intel.com Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com> (cherry picked from commit 3fbd6cf) Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
1 parent 09a8f3c commit 1d0adf2

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

drivers/gpu/drm/xe/xe_bo.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2322,8 +2322,10 @@ struct xe_bo *xe_bo_init_locked(struct xe_device *xe, struct xe_bo *bo,
23222322
}
23232323

23242324
/* XE_BO_FLAG_GGTTx requires XE_BO_FLAG_GGTT also be set */
2325-
if ((flags & XE_BO_FLAG_GGTT_ALL) && !(flags & XE_BO_FLAG_GGTT))
2325+
if ((flags & XE_BO_FLAG_GGTT_ALL) && !(flags & XE_BO_FLAG_GGTT)) {
2326+
xe_bo_free(bo);
23262327
return ERR_PTR(-EINVAL);
2328+
}
23272329

23282330
if (flags & (XE_BO_FLAG_VRAM_MASK | XE_BO_FLAG_STOLEN) &&
23292331
!(flags & XE_BO_FLAG_IGNORE_MIN_PAGE_SIZE) &&

0 commit comments

Comments
 (0)