Skip to content

Commit 93a528f

Browse files
ShuichengLinrodrigovivi
authored andcommitted
drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure
When drm_gpuvm_resv_object_alloc() fails, the pre-allocated storage bo is not freed. Add xe_bo_free(storage) before returning the error. xe_dma_buf_init_obj() calls xe_bo_init_locked(), which frees the bo on error. Therefore, xe_dma_buf_init_obj() must also free the bo on its own error paths. Otherwise, since xe_gem_prime_import() cannot distinguish whether the failure originated from xe_dma_buf_init_obj() or from xe_bo_init_locked(), it cannot safely decide whether the bo should be freed. Add comments documenting the ownership semantics: on success, ownership of storage is transferred to the returned drm_gem_object; on failure, storage is freed before returning. v2: Add comments to explain the free logic. Fixes: eb289a5 ("drm/xe: Convert xe_dma_buf.c for exhaustive eviction") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Matthew Brost <matthew.brost@intel.com> Link: https://patch.msgid.link/20260408175255.3402838-4-shuicheng.lin@intel.com Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com> (cherry picked from commit 78a6c5f) Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
1 parent 1d0adf2 commit 93a528f

1 file changed

Lines changed: 11 additions & 1 deletion

File tree

drivers/gpu/drm/xe/xe_dma_buf.c

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -258,6 +258,13 @@ struct dma_buf *xe_gem_prime_export(struct drm_gem_object *obj, int flags)
258258
return ERR_PTR(ret);
259259
}
260260

261+
/*
262+
* Takes ownership of @storage: on success it is transferred to the returned
263+
* drm_gem_object; on failure it is freed before returning the error.
264+
* This matches the contract of xe_bo_init_locked() which frees @storage on
265+
* its error paths, so callers need not (and must not) free @storage after
266+
* this call.
267+
*/
261268
static struct drm_gem_object *
262269
xe_dma_buf_init_obj(struct drm_device *dev, struct xe_bo *storage,
263270
struct dma_buf *dma_buf)
@@ -271,8 +278,10 @@ xe_dma_buf_init_obj(struct drm_device *dev, struct xe_bo *storage,
271278
int ret = 0;
272279

273280
dummy_obj = drm_gpuvm_resv_object_alloc(&xe->drm);
274-
if (!dummy_obj)
281+
if (!dummy_obj) {
282+
xe_bo_free(storage);
275283
return ERR_PTR(-ENOMEM);
284+
}
276285

277286
dummy_obj->resv = resv;
278287
xe_validation_guard(&ctx, &xe->val, &exec, (struct xe_val_flags) {}, ret) {
@@ -281,6 +290,7 @@ xe_dma_buf_init_obj(struct drm_device *dev, struct xe_bo *storage,
281290
if (ret)
282291
break;
283292

293+
/* xe_bo_init_locked() frees storage on error */
284294
bo = xe_bo_init_locked(xe, storage, NULL, resv, NULL, dma_buf->size,
285295
0, /* Will require 1way or 2way for vm_bind */
286296
ttm_bo_type_sg, XE_BO_FLAG_SYSTEM, &exec);

0 commit comments

Comments
 (0)