Intel-GFX Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] drm/i915/gvt: Fix mm reference leak in handle_g2v_notification()
@ 2026-09-16 17:37 Wentao Liang
  2026-09-16 18:04 ` sashiko-bot
                   ` (4 more replies)
  0 siblings, 5 replies; 6+ messages in thread
From: Wentao Liang @ 2026-09-16 17:37 UTC (permalink / raw)
  To: airlied
  Cc: changbin.du, dri-devel, intel-gfx, jani.nikula, joonas.lahtinen,
	linux-kernel, rodrigo.vivi, simona, tursulin, zhenyuw.linux,
	zhi.wang.linux, Wentao Liang, stable

intel_vgpu_get_ppgtt_mm() returns a reference the caller must drop, but
the PPGTT page table create path only inspected the result. A page
table that is already tracked gained an extra reference which nothing
would ever drop. Skip the lookup-get for an already registered mm; a
newly created mm keeps its initial registration reference.

Fixes: e6e9c46fd235 ("drm/i915/gvt: Factor out intel_vgpu_{get, put}_ppgtt_mm interface")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 drivers/gpu/drm/i915/gvt/handlers.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/gvt/handlers.c b/drivers/gpu/drm/i915/gvt/handlers.c
index a34f56630af9..3d7aae6c5cf1 100644
--- a/drivers/gpu/drm/i915/gvt/handlers.c
+++ b/drivers/gpu/drm/i915/gvt/handlers.c
@@ -1506,7 +1506,17 @@ static int handle_g2v_notification(struct intel_vgpu *vgpu, int notification)
 		root_entry_type = GTT_TYPE_PPGTT_ROOT_L3_ENTRY;
 		fallthrough;
 	case VGT_G2V_PPGTT_L4_PAGE_TABLE_CREATE:
-		mm = intel_vgpu_get_ppgtt_mm(vgpu, root_entry_type, pdps);
+		/*
+		 * A newly created mm keeps its initial reference as the
+		 * registration reference, dropped by the DESTROY
+		 * notification. A duplicate CREATE for an already tracked
+		 * mm must not take an extra reference that nothing drops.
+		 */
+		mm = intel_vgpu_find_ppgtt_mm(vgpu, pdps);
+		if (mm)
+			return 0;
+
+		mm = intel_vgpu_create_ppgtt_mm(vgpu, root_entry_type, pdps);
 		return PTR_ERR_OR_ZERO(mm);
 	case VGT_G2V_PPGTT_L3_PAGE_TABLE_DESTROY:
 	case VGT_G2V_PPGTT_L4_PAGE_TABLE_DESTROY:
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-25  5:29 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 17:37 [PATCH] drm/i915/gvt: Fix mm reference leak in handle_g2v_notification() Wentao Liang
2026-09-16 18:04 ` sashiko-bot
2026-09-18  0:59 ` ✗ LGCI.VerificationFailed: failure for " Patchwork
2026-09-23 21:16 ` ✓ i915.CI.BAT: success for drm/i915/gvt: Fix mm reference leak in handle_g2v_notification() (rev3) Patchwork
2026-09-24 19:05 ` ✓ i915.CI.Full: " Patchwork
2026-09-25  5:28 ` [PATCH] drm/i915/gvt: Fix mm reference leak in handle_g2v_notification() Zhenyu Wang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox