Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1669387 > unrolled thread

[PATCH 4.9 19/60] drm/vc4: Fix OOPSes from trying to cache a partially constructed BO.

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-06-19 18:00 +0200
Last post2017-06-19 18:00 +0200
Articles 1 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 4.9 19/60] drm/vc4: Fix OOPSes from trying to cache a partially constructed BO. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-19 18:00 +0200

#1669387 — [PATCH 4.9 19/60] drm/vc4: Fix OOPSes from trying to cache a partially constructed BO.

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-06-19 18:00 +0200
Subject[PATCH 4.9 19/60] drm/vc4: Fix OOPSes from trying to cache a partially constructed BO.
Message-ID<tU7fQ-4Bo-25@gated-at.bofh.it>
4.9-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Anholt <eric@anholt.net>

commit ca39b449f6d03e8235969f12f5dd25b8eb4304d6 upstream.

If a CMA allocation failed, the partially constructed BO would be
unreferenced through the normal path, and we might choose to put it in
the BO cache.  If we then reused it before it expired from the cache,
the kernel would OOPS.

Signed-off-by: Eric Anholt <eric@anholt.net>
Fixes: c826a6e10644 ("drm/vc4: Add a BO cache.")
Reviewed-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Link: http://patchwork.freedesktop.org/patch/msgid/20170301185602.6873-2-eric@anholt.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/gpu/drm/vc4/vc4_bo.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/drivers/gpu/drm/vc4/vc4_bo.c
+++ b/drivers/gpu/drm/vc4/vc4_bo.c
@@ -313,6 +313,14 @@ void vc4_free_object(struct drm_gem_obje
 		goto out;
 	}
 
+	/* If this object was partially constructed but CMA allocation
+	 * had failed, just free it.
+	 */
+	if (!bo->base.vaddr) {
+		vc4_bo_destroy(bo);
+		goto out;
+	}
+
 	cache_list = vc4_get_cache_list_for_size(dev, gem_bo->size);
 	if (!cache_list) {
 		vc4_bo_destroy(bo);

[toc] | [standalone]


Back to top | Article view | linux.kernel


csiph-web