* [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE
@ 2025-12-12 13:02 Karol Wachowski
2025-12-12 13:06 ` Christian König
0 siblings, 1 reply; 3+ messages in thread
From: Karol Wachowski @ 2025-12-12 13:02 UTC (permalink / raw)
To: David.Francis
Cc: felix.kuehling, christian.koenig, maarten.lankhorst, mripard,
tzimmermann, airlied, simona, sumit.semwal, andrzej.kacprowski,
maciej.falkowski, dri-devel, linux-media, linaro-mm-sig, stable,
Karol Wachowski
Add missing drm_gem_object_put() call when drm_gem_object_lookup()
successfully returns an object. This fixes a GEM object reference
leak that can prevent driver modules from unloading when using
prime buffers.
Fixes: 53096728b891 ("drm: Add DRM prime interface to reassign GEM handle")
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
---
drivers/gpu/drm/drm_gem.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
index ca1956608261..e150bc1ce65a 100644
--- a/drivers/gpu/drm/drm_gem.c
+++ b/drivers/gpu/drm/drm_gem.c
@@ -1001,7 +1001,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
{
struct drm_gem_change_handle *args = data;
struct drm_gem_object *obj;
- int ret;
+ int ret = 0;
if (!drm_core_check_feature(dev, DRIVER_GEM))
return -EOPNOTSUPP;
@@ -1011,7 +1011,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
return -ENOENT;
if (args->handle == args->new_handle)
- return 0;
+ goto out;
mutex_lock(&file_priv->prime.lock);
@@ -1043,6 +1043,8 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
out_unlock:
mutex_unlock(&file_priv->prime.lock);
+out:
+ drm_gem_object_put(obj);
return ret;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE
2025-12-12 13:02 [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE Karol Wachowski
@ 2025-12-12 13:06 ` Christian König
2025-12-12 13:21 ` Karol Wachowski
0 siblings, 1 reply; 3+ messages in thread
From: Christian König @ 2025-12-12 13:06 UTC (permalink / raw)
To: Karol Wachowski, David.Francis
Cc: felix.kuehling, maarten.lankhorst, mripard, tzimmermann, airlied,
simona, sumit.semwal, andrzej.kacprowski, maciej.falkowski,
dri-devel, linux-media, linaro-mm-sig, stable
On 12/12/25 14:02, Karol Wachowski wrote:
> Add missing drm_gem_object_put() call when drm_gem_object_lookup()
> successfully returns an object. This fixes a GEM object reference
> leak that can prevent driver modules from unloading when using
> prime buffers.
Good catch.
> Fixes: 53096728b891 ("drm: Add DRM prime interface to reassign GEM handle")
> Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
CC: stable 6.18?
> ---
> drivers/gpu/drm/drm_gem.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
> index ca1956608261..e150bc1ce65a 100644
> --- a/drivers/gpu/drm/drm_gem.c
> +++ b/drivers/gpu/drm/drm_gem.c
> @@ -1001,7 +1001,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
> {
> struct drm_gem_change_handle *args = data;
> struct drm_gem_object *obj;
> - int ret;
> + int ret = 0;
Please set ret explicitly in the if branch below.
Always initializing return values is usually considered bad coding style.
Apart from that looks good to me.
Thanks,
Christian.
>
> if (!drm_core_check_feature(dev, DRIVER_GEM))
> return -EOPNOTSUPP;
> @@ -1011,7 +1011,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
> return -ENOENT;
>
> if (args->handle == args->new_handle)
> - return 0;
> + goto out;
>
> mutex_lock(&file_priv->prime.lock);
>
> @@ -1043,6 +1043,8 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>
> out_unlock:
> mutex_unlock(&file_priv->prime.lock);
> +out:
> + drm_gem_object_put(obj);
>
> return ret;
> }
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE
2025-12-12 13:06 ` Christian König
@ 2025-12-12 13:21 ` Karol Wachowski
0 siblings, 0 replies; 3+ messages in thread
From: Karol Wachowski @ 2025-12-12 13:21 UTC (permalink / raw)
To: Christian König, David.Francis
Cc: felix.kuehling, maarten.lankhorst, mripard, tzimmermann, airlied,
simona, sumit.semwal, andrzej.kacprowski, maciej.falkowski,
dri-devel, linux-media, linaro-mm-sig, stable
On 12/12/2025 2:06 PM, Christian König wrote:
> On 12/12/25 14:02, Karol Wachowski wrote:
>> Add missing drm_gem_object_put() call when drm_gem_object_lookup()
>> successfully returns an object. This fixes a GEM object reference
>> leak that can prevent driver modules from unloading when using
>> prime buffers.
>
> Good catch.
>
>> Fixes: 53096728b891 ("drm: Add DRM prime interface to reassign GEM handle")
>> Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
>
> CC: stable 6.18?
Good idea - added CC: stable in v2.
>
>> ---
>> drivers/gpu/drm/drm_gem.c | 6 ++++--
>> 1 file changed, 4 insertions(+), 2 deletions(-)
>>
>> diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
>> index ca1956608261..e150bc1ce65a 100644
>> --- a/drivers/gpu/drm/drm_gem.c
>> +++ b/drivers/gpu/drm/drm_gem.c
>> @@ -1001,7 +1001,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>> {
>> struct drm_gem_change_handle *args = data;
>> struct drm_gem_object *obj;
>> - int ret;
>> + int ret = 0;
>
> Please set ret explicitly in the if branch below.
>
> Always initializing return values is usually considered bad coding style.
Totally agree, moved setting to suggested place in v2.
>
> Apart from that looks good to me.
>
> Thanks,
> Christian.
Thanks,
Karol.>
>>
>> if (!drm_core_check_feature(dev, DRIVER_GEM))
>> return -EOPNOTSUPP;
>> @@ -1011,7 +1011,7 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>> return -ENOENT;
>>
>> if (args->handle == args->new_handle)
>> - return 0;
>> + goto out;
>>
>> mutex_lock(&file_priv->prime.lock);
>>
>> @@ -1043,6 +1043,8 @@ int drm_gem_change_handle_ioctl(struct drm_device *dev, void *data,
>>
>> out_unlock:
>> mutex_unlock(&file_priv->prime.lock);
>> +out:
>> + drm_gem_object_put(obj);
>>
>> return ret;
>> }
>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-12-12 13:21 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-12-12 13:02 [PATCH] drm: Fix object leak in DRM_IOCTL_GEM_CHANGE_HANDLE Karol Wachowski
2025-12-12 13:06 ` Christian König
2025-12-12 13:21 ` Karol Wachowski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).