From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EA78E3DA7DC for ; Thu, 30 Jul 2026 22:20:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.11 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785450021; cv=none; b=toH5FiWcQWF7FgiS5alzqI5TiVChK81OO80Coyiz5sWhm0dxxdw2TyrXDyL5OpxcL7UwolZDTH+gKhxpFUumk/4661cqzJQJDLuGjQmirtEvygG64Ygwu5YaR4xi5VbQDmkIb4RA/l3dQ/C7LgHk097P+DANenae8MpjNirMcE8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785450021; c=relaxed/simple; bh=KyURgAO0iXKGnMmlHUqjHQn2SIg5SHEa+R3HRpxzAB8=; h=Date:Message-ID:From:To:Cc:Subject:In-Reply-To:References: MIME-Version:Content-Type; b=hEVGAt2S7gOv+v5fN84Vt/mW/efhOmTp7Zl5TswNCPoi+PE0X5U8t4rk/zl0/2bbT+Cwqfw3rNxjbxlyvvocorOPiNak7PLyJpD9dMqaiHnPwAlFSj9ws3V9NhJBj4pXjEgu3SXoAVdHGBlYnBVhN7NEsFQJnNqfEMVnof+nJKg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=P6nRwHSh; arc=none smtp.client-ip=192.198.163.11 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="P6nRwHSh" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785450020; x=1816986020; h=date:message-id:from:to:cc:subject:in-reply-to: references:mime-version; bh=KyURgAO0iXKGnMmlHUqjHQn2SIg5SHEa+R3HRpxzAB8=; b=P6nRwHShy0HI0jNyNIctUkUk/a0323rI54+ZuruIHfanJOtawAuVbk2k XD7C/C/ycHYsCUesJRTjzNvn2RKyYdvYnvRd2eAnr1kofVZTkXg6uGREp 9u2W3BAqrFbP+cpw5cpOl2XR/n2iIzQCbjzsRbdT2/i7z9Ul2HPQqk5dK tyo0k/cXhecub/FHVaN/uXIpMVQziMCd+tY7HEQaxo4pzH3W8dDkpUjgb Vt8GDwmOe7kyQ0KlgjN2X8TJVjz5o7qA1pT1gdhSC/luO8JRfcobYEZiq FHYFhxKjBQIPUz1y4LPddWm4P+lpSbphDeauwO2CPeE6pmiYXHHY/OqNY g==; X-CSE-ConnectionGUID: MQP4P8bsTKi74kYvkvemMQ== X-CSE-MsgGUID: d9PA4+WpQXShnfs/z5qk1Q== X-IronPort-AV: E=McAfee;i="6800,10657,11860"; a="96665283" X-IronPort-AV: E=Sophos;i="6.25,195,1779174000"; d="scan'208";a="96665283" Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa105.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Jul 2026 15:20:19 -0700 X-CSE-ConnectionGUID: 0b3kzplpRuWZtojK6qh0qQ== X-CSE-MsgGUID: UYakIgFRTPmRNszMya+6bw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,195,1779174000"; d="scan'208";a="254095012" Received: from mcapezzu-mobl1.amr.corp.intel.com (HELO adixit-MOBL3.intel.com) ([10.125.38.25]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Jul 2026 15:20:19 -0700 Date: Thu, 30 Jul 2026 15:20:18 -0700 Message-ID: <875x1wglwd.wl-ashutosh.dixit@intel.com> From: "Dixit, Ashutosh" To: Linmao Li Cc: Matthew Brost , Thomas =?ISO-8859-1?Q?Hellstr?= =?ISO-8859-1?Q?=F6m?= , Rodrigo Vivi , David Airlie , Simona Vetter , =?ISO-8859-1?Q?Jos=E9?= Roberto de Souza , "Umesh Nerlige Ramappa" ,, , Subject: Re: [PATCH] drm/xe/oa: Fix sync entry leak on OA config emit failure In-Reply-To: <20260715023332.391298-1-lilinmao@kylinos.cn> References: <20260715023332.391298-1-lilinmao@kylinos.cn> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM-LB/1.14.9 (=?ISO-8859-4?Q?Goj=F2?=) APEL-LB/10.8 EasyPG/1.0.0 Emacs/30.2 (x86_64-pc-linux-gnu) MULE/6.0 (HANACHIRUSATO) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") Content-Type: text/plain; charset=US-ASCII On Tue, 14 Jul 2026 19:33:32 -0700, Linmao Li wrote: > Hi Linmao, Sorry for the delay in responding to this patch. > xe_oa_emit_oa_config() releases the sync entries and the syncs array > only on its success path. When it fails before the point of no return > (fence allocation, config buffer allocation or batch submission), it > returns without touching stream->syncs. > > The stream open path handles such failures in the caller, but > xe_oa_config_locked() propagates the error without any cleanup, so the > syncs array and the fence references held by the parsed entries are > leaked. The next config ioctl overwrites stream->syncs, making the > memory unreachable for good. > > Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching > the cleanup done by the stream open error path, and reset the stream > sync state so it does not point at freed entries. > > Fixes: 9920c8b88c5c ("drm/xe/oa: Add syncs support to OA config ioctl") > Signed-off-by: Linmao Li > --- > drivers/gpu/drm/xe/xe_oa.c | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/drivers/gpu/drm/xe/xe_oa.c b/drivers/gpu/drm/xe/xe_oa.c > index 2dce6a47202c..b1ce312ea97a 100644 > --- a/drivers/gpu/drm/xe/xe_oa.c > +++ b/drivers/gpu/drm/xe/xe_oa.c > @@ -1594,6 +1594,12 @@ static long xe_oa_config_locked(struct xe_oa_stream *stream, u64 arg) > config = xchg(&stream->oa_config, config); > drm_dbg(&stream->oa->xe->drm, "changed to oa config uuid=%s\n", > stream->oa_config->uuid); > + } else { > + while (param.num_syncs--) > + xe_sync_entry_cleanup(¶m.syncs[param.num_syncs]); > + kfree(param.syncs); > + stream->num_syncs = 0; > + stream->syncs = NULL; Yes this looks correct to me. Except that we don't need the two lines above. Can you please resend a v2 deleting the above two lines. Thanks for the patch, Ashutosh > } > > err_config_put: > -- > 2.25.1 >