dri-devel.lists.freedesktop.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE
@ 2025-12-12 13:02 Karol Wachowski
  2025-12-12 13:06 ` Christian König
  0 siblings, 1 reply; 3+ messages in thread
From: Karol Wachowski @ 2025-12-12 13:02 UTC (permalink / raw)
  To: David.Francis
  Cc: felix.kuehling, christian.koenig, maarten.lankhorst, mripard,
	tzimmermann, airlied, simona, sumit.semwal, andrzej.kacprowski,
	maciej.falkowski, dri-devel, linux-media, linaro-mm-sig, stable,
	Karol Wachowski

Add missing drm_gem_object_put() call when drm_gem_object_lookup()
successfully returns an object. This fixes a GEM object reference
leak that can prevent driver modules from unloading when using
prime buffers.

Fixes: 53096728b891 ("drm: Add DRM prime interface to reassign GEM handle")
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
---
 drivers/gpu/drm/drm_gem.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
index ca1956608261..e150bc1ce65a 100644
--- a/drivers/gpu/drm/drm_gem.c
+++ b/drivers/gpu/drm/drm_gem.c
@@ -1001,7 +1001,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
 {
 	struct drm_gem_change_handle *args = data;
 	struct drm_gem_object *obj;
-	int ret;
+	int ret = 0;
 
 	if (!drm_core_check_feature(dev, DRIVER_GEM))
 		return -EOPNOTSUPP;
@@ -1011,7 +1011,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
 		return -ENOENT;
 
 	if (args->handle == args->new_handle)
-		return 0;
+		goto out;
 
 	mutex_lock(&file_priv->prime.lock);
 
@@ -1043,6 +1043,8 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
 
 out_unlock:
 	mutex_unlock(&file_priv->prime.lock);
+out:
+	drm_gem_object_put(obj);
 
 	return ret;
 }
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE
  2025-12-12 13:02 [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE Karol Wachowski
@ 2025-12-12 13:06 ` Christian König
  2025-12-12 13:21   ` Karol Wachowski
  0 siblings, 1 reply; 3+ messages in thread
From: Christian König @ 2025-12-12 13:06 UTC (permalink / raw)
  To: Karol Wachowski, David.Francis
  Cc: felix.kuehling, maarten.lankhorst, mripard, tzimmermann, airlied,
	simona, sumit.semwal, andrzej.kacprowski, maciej.falkowski,
	dri-devel, linux-media, linaro-mm-sig, stable

On 12/12/25 14:02, Karol Wachowski wrote:
> Add missing drm_gem_object_put() call when drm_gem_object_lookup()
> successfully returns an object. This fixes a GEM object reference
> leak that can prevent driver modules from unloading when using
> prime buffers.

Good catch.

> Fixes: 53096728b891 ("drm: Add DRM prime interface to reassign GEM handle")
> Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>

CC: stable 6.18?

> ---
>  drivers/gpu/drm/drm_gem.c | 6 ++++--
>  1 file changed, 4 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
> index ca1956608261..e150bc1ce65a 100644
> --- a/drivers/gpu/drm/drm_gem.c
> +++ b/drivers/gpu/drm/drm_gem.c
> @@ -1001,7 +1001,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>  {
>  	struct drm_gem_change_handle *args = data;
>  	struct drm_gem_object *obj;
> -	int ret;
> +	int ret = 0;

Please set ret explicitly in the if branch below.

Always initializing return values is usually considered bad coding style.

Apart from that looks good to me.

Thanks,
Christian.

>  
>  	if (!drm_core_check_feature(dev, DRIVER_GEM))
>  		return -EOPNOTSUPP;
> @@ -1011,7 +1011,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>  		return -ENOENT;
>  
>  	if (args->handle == args->new_handle)
> -		return 0;
> +		goto out;
>  
>  	mutex_lock(&file_priv->prime.lock);
>  
> @@ -1043,6 +1043,8 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>  
>  out_unlock:
>  	mutex_unlock(&file_priv->prime.lock);
> +out:
> +	drm_gem_object_put(obj);
>  
>  	return ret;
>  }


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE
  2025-12-12 13:06 ` Christian König
@ 2025-12-12 13:21   ` Karol Wachowski
  0 siblings, 0 replies; 3+ messages in thread
From: Karol Wachowski @ 2025-12-12 13:21 UTC (permalink / raw)
  To: Christian König, David.Francis
  Cc: felix.kuehling, maarten.lankhorst, mripard, tzimmermann, airlied,
	simona, sumit.semwal, andrzej.kacprowski, maciej.falkowski,
	dri-devel, linux-media, linaro-mm-sig, stable

On 12/12/2025 2:06 PM, Christian König wrote:
> On 12/12/25 14:02, Karol Wachowski wrote:
>> Add missing drm_gem_object_put() call when drm_gem_object_lookup()
>> successfully returns an object. This fixes a GEM object reference
>> leak that can prevent driver modules from unloading when using
>> prime buffers.
> 
> Good catch.
> 
>> Fixes: 53096728b891 ("drm: Add DRM prime interface to reassign GEM handle")
>> Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
> 
> CC: stable 6.18?

Good idea - added CC: stable in v2.

> 
>> ---
>>  drivers/gpu/drm/drm_gem.c | 6 ++++--
>>  1 file changed, 4 insertions(+), 2 deletions(-)
>>
>> diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
>> index ca1956608261..e150bc1ce65a 100644
>> --- a/drivers/gpu/drm/drm_gem.c
>> +++ b/drivers/gpu/drm/drm_gem.c
>> @@ -1001,7 +1001,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>>  {
>>  	struct drm_gem_change_handle *args = data;
>>  	struct drm_gem_object *obj;
>> -	int ret;
>> +	int ret = 0;
> 
> Please set ret explicitly in the if branch below.
> 
> Always initializing return values is usually considered bad coding style.

Totally agree, moved setting to suggested place in v2.

> 
> Apart from that looks good to me.
> 
> Thanks,
> Christian.

Thanks,
Karol.>
>>  
>>  	if (!drm_core_check_feature(dev, DRIVER_GEM))
>>  		return -EOPNOTSUPP;
>> @@ -1011,7 +1011,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>>  		return -ENOENT;
>>  
>>  	if (args->handle == args->new_handle)
>> -		return 0;
>> +		goto out;
>>  
>>  	mutex_lock(&file_priv->prime.lock);
>>  
>> @@ -1043,6 +1043,8 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>>  
>>  out_unlock:
>>  	mutex_unlock(&file_priv->prime.lock);
>> +out:
>> +	drm_gem_object_put(obj);
>>  
>>  	return ret;
>>  }
> 


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2025-12-12 13:21 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-12-12 13:02 [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE Karol Wachowski
2025-12-12 13:06 ` Christian König
2025-12-12 13:21   ` Karol Wachowski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).