在 2026-10-03六的 09:34 +0000,Evanshenf写道:
> If ttm_bo_init_validate() fails, it drops the buffer object's
> reference
> and cleans it up through the supplied destroy callback.
> lsdc_bo_destroy()
> releases the GEM object and frees the enclosing lsdc_bo, so freeing
> it
> again in lsdc_bo_create() causes a double free on a synchronous
> failure
> path.
> 
> Let TTM own the cleanup after initialization has started and return
> the
> error directly. Keep the explicit free on drm_gem_object_init()
> failure,
> which occurs before ownership is passed to TTM.
> 
> Tested on LS7A2000 by making drm_vma_offset_add() return -ENOSPC for
> one
> selected dumb-buffer creation. The error reached userspace, the
> destroy
> callback ran once, and no handle was published or tracked BO
> retained.
> Normal buffer creation, zeroing, mapping, readback and release
> passed.
> 
> AI assistance was used for the ownership analysis, fix, fault-
> injection
> tools, build and test execution.
> 
> Fixes: f39db26c5428 ("drm: Add kms driver for loongson display
> controller")
> Cc: [email protected]
> Assisted-by: LLM
> Signed-off-by: Evanshenf <[email protected]>
> ---
>  drivers/gpu/drm/loongson/lsdc_ttm.c | 4 +---
>  1 file changed, 1 insertion(+), 3 deletions(-)
> 
> diff --git a/drivers/gpu/drm/loongson/lsdc_ttm.c
> b/drivers/gpu/drm/loongson/lsdc_ttm.c
> index d7441d9..88536e2 100644
> --- a/drivers/gpu/drm/loongson/lsdc_ttm.c
> +++ b/drivers/gpu/drm/loongson/lsdc_ttm.c
> @@ -475,10 +475,8 @@ struct lsdc_bo *lsdc_bo_create(struct drm_device
> *ddev,
>  
>       ret = ttm_bo_init_validate(bdev, tbo, bo_type, &lbo-
> >placement, 0,
>                                  false, sg, resv,
> lsdc_bo_destroy);
> -     if (ret) {
> -             kfree(lbo);
> +     if (ret)
>               return ERR_PTR(ret);

It looks like this fix is valid, ttm_bo_init_reserved() (called by
ttm_bo_init_validate() ) will do a ttm_bo_put() operation when failure,
which leads to calling the destroy callback.

```
Reviewed-by: Icenowy Zheng <[email protected]>
```

Thanks,
Icenowy

> -     }
>  
>       return lbo;
>  }
> 
> base-commit: bca45af5998a05f34b13a2ef11e639bac9c62643

Reply via email to