Hi Andi,
On 2026-09-30 at 02:54:02 +0200, Andi Shyti wrote:
> Hi Krzysztof,
>
> On Fri, Sep 11, 2026 at 06:11:45AM +0000, Krzysztof Karas wrote:
> > It is possible for eb_relocate_parse_slow() to call kvfree() on
> > entries outside the original exec array during following
> > scenario inside eb_relocate_parse_slow():
> >
> > 1) eb_copy_relocations() allocates as many as eb->buffer_count
> > copies for exec entries;
> > 2) eb_parse() appends up to two VMAs, right after incrementing
> > eb->buffer_count;
> > 3) cleanup under "out" label uses this incremented buffer_count
> > to release relocation pointers from exec array via kvfree(),
> > not from VMA array.
> >
> > To amend this problem, ensure that relocation cleanup uses the
> > original exec object count, excluding the VMAs appended by the
> > command parser.
> >
> > Fixes: 8e4ba491b0ba ("drm/i915: Parse command buffer earlier in
> > eb_relocate(slow)")
> > Cc: [email protected] # 5.10+
> > Assisted-by: GitHub-Copilot:gpt-6-astra
> > Signed-off-by: Krzysztof Karas <[email protected]>
>
> pushed to drm-intel-gt-next.
Thanks!
>
> Thanks,
> Andi
--
Best Regards,
Krzysztof